xref: /OK3568_Linux_fs/external/rkwifibt/drivers/rtl8852bs/os_dep/linux/ioctl_linux.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2019 Realtek Corporation.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  *****************************************************************************/
15 #define _IOCTL_LINUX_C_
16 
17 #include <drv_types.h>
18 #include <rtw_mp.h>
19 
20 
21 #if (LINUX_VERSION_CODE < KERNEL_VERSION(2, 6, 27))
22 #define  iwe_stream_add_event(a, b, c, d, e)  iwe_stream_add_event(b, c, d, e)
23 #define  iwe_stream_add_point(a, b, c, d, e)  iwe_stream_add_point(b, c, d, e)
24 #endif
25 
26 #ifdef CONFIG_80211N_HT
27 extern int rtw_ht_enable;
28 #endif
29 
30 
31 #define RTL_IOCTL_WPA_SUPPLICANT	(SIOCIWFIRSTPRIV+30)
32 
33 #define SCAN_ITEM_SIZE 768
34 #define MAX_CUSTOM_LEN 64
35 #define RATE_COUNT 4
36 #define MAX_SCAN_BUFFER_LEN 65535
37 
38 #ifdef CONFIG_GLOBAL_UI_PID
39 extern int ui_pid[3];
40 #endif
41 
42 /* combo scan */
43 #define WEXT_CSCAN_AMOUNT 9
44 #define WEXT_CSCAN_BUF_LEN		360
45 #define WEXT_CSCAN_HEADER		"CSCAN S\x01\x00\x00S\x00"
46 #define WEXT_CSCAN_HEADER_SIZE		12
47 #define WEXT_CSCAN_SSID_SECTION		'S'
48 #define WEXT_CSCAN_CHANNEL_SECTION	'C'
49 #define WEXT_CSCAN_NPROBE_SECTION	'N'
50 #define WEXT_CSCAN_ACTV_DWELL_SECTION	'A'
51 #define WEXT_CSCAN_PASV_DWELL_SECTION	'P'
52 #define WEXT_CSCAN_HOME_DWELL_SECTION	'H'
53 #define WEXT_CSCAN_TYPE_SECTION		'T'
54 
55 
56 extern u8 key_2char2num(u8 hch, u8 lch);
57 extern u8 str_2char2num(u8 hch, u8 lch);
58 extern void macstr2num(u8 *dst, u8 *src);
59 extern u8 convert_ip_addr(u8 hch, u8 mch, u8 lch);
60 
61 u32 rtw_rates[] = {1000000, 2000000, 5500000, 11000000,
62 	6000000, 9000000, 12000000, 18000000, 24000000, 36000000, 48000000, 54000000};
63 
64 /**
65  * hwaddr_aton - Convert ASCII string to MAC address
66  * @txt: MAC address as a string (e.g., "00:11:22:33:44:55")
67  * @addr: Buffer for the MAC address (ETH_ALEN = 6 bytes)
68  * Returns: 0 on success, -1 on failure (e.g., string not a MAC address)
69  */
hwaddr_aton_i(const char * txt,u8 * addr)70 static int hwaddr_aton_i(const char *txt, u8 *addr)
71 {
72 	int i;
73 
74 	for (i = 0; i < 6; i++) {
75 		int a, b;
76 
77 		a = hex2num_i(*txt++);
78 		if (a < 0)
79 			return -1;
80 		b = hex2num_i(*txt++);
81 		if (b < 0)
82 			return -1;
83 		*addr++ = (a << 4) | b;
84 		if (i < 5 && *txt++ != ':')
85 			return -1;
86 	}
87 
88 	return 0;
89 }
90 #ifdef CONFIG_RTW_ANDROID
indicate_wx_custom_event(_adapter * padapter,char * msg)91 static void indicate_wx_custom_event(_adapter *padapter, char *msg)
92 {
93 	u8 *buff;
94 	union iwreq_data wrqu;
95 
96 	if (strlen(msg) > IW_CUSTOM_MAX) {
97 		RTW_INFO("%s strlen(msg):%zu > IW_CUSTOM_MAX:%u\n", __FUNCTION__ , strlen(msg), IW_CUSTOM_MAX);
98 		return;
99 	}
100 
101 	buff = rtw_zmalloc(IW_CUSTOM_MAX + 1);
102 	if (!buff)
103 		return;
104 
105 	_rtw_memcpy(buff, msg, strlen(msg));
106 
107 	_rtw_memset(&wrqu, 0, sizeof(wrqu));
108 	wrqu.data.length = strlen(msg);
109 
110 	RTW_INFO("%s %s\n", __FUNCTION__, buff);
111 #ifndef CONFIG_IOCTL_CFG80211
112 	wireless_send_event(padapter->pnetdev, IWEVCUSTOM, &wrqu, buff);
113 #endif
114 
115 	rtw_mfree(buff, IW_CUSTOM_MAX + 1);
116 
117 }
118 #endif
119 
120 #if 0
121 static void request_wps_pbc_event(_adapter *padapter)
122 {
123 	u8 *buff, *p;
124 	union iwreq_data wrqu;
125 
126 
127 	buff = rtw_malloc(IW_CUSTOM_MAX);
128 	if (!buff)
129 		return;
130 
131 	_rtw_memset(buff, 0, IW_CUSTOM_MAX);
132 
133 	p = buff;
134 
135 	p += sprintf(p, "WPS_PBC_START.request=TRUE");
136 
137 	_rtw_memset(&wrqu, 0, sizeof(wrqu));
138 
139 	wrqu.data.length = p - buff;
140 
141 	wrqu.data.length = (wrqu.data.length < IW_CUSTOM_MAX) ? wrqu.data.length : IW_CUSTOM_MAX;
142 
143 	RTW_INFO("%s\n", __FUNCTION__);
144 
145 #ifndef CONFIG_IOCTL_CFG80211
146 	wireless_send_event(padapter->pnetdev, IWEVCUSTOM, &wrqu, buff);
147 #endif
148 
149 	if (buff)
150 		rtw_mfree(buff, IW_CUSTOM_MAX);
151 
152 }
153 #endif
154 
155 #ifdef CONFIG_SUPPORT_HW_WPS_PBC
rtw_request_wps_pbc_event(_adapter * padapter)156 void rtw_request_wps_pbc_event(_adapter *padapter)
157 {
158 #ifdef RTK_DMP_PLATFORM
159 #if (LINUX_VERSION_CODE > KERNEL_VERSION(2, 6, 12))
160 	kobject_uevent(&padapter->pnetdev->dev.kobj, KOBJ_NET_PBC);
161 #else
162 	kobject_hotplug(&padapter->pnetdev->class_dev.kobj, KOBJ_NET_PBC);
163 #endif
164 #else
165 
166 	if (padapter->pid[0] == 0) {
167 		/*	0 is the default value and it means the application monitors the HW PBC doesn't privde its pid to driver. */
168 		return;
169 	}
170 
171 	rtw_signal_process(padapter->pid[0], SIGUSR1);
172 
173 #endif
174 
175 	rtw_led_control(padapter, LED_CTL_START_WPS_BOTTON);
176 }
177 #endif/* #ifdef CONFIG_SUPPORT_HW_WPS_PBC */
178 
indicate_wx_scan_complete_event(_adapter * padapter)179 void indicate_wx_scan_complete_event(_adapter *padapter)
180 {
181 	union iwreq_data wrqu;
182 
183 	_rtw_memset(&wrqu, 0, sizeof(union iwreq_data));
184 
185 	/* RTW_INFO("+rtw_indicate_wx_scan_complete_event\n"); */
186 #ifndef CONFIG_IOCTL_CFG80211
187 	wireless_send_event(padapter->pnetdev, SIOCGIWSCAN, &wrqu, NULL);
188 #endif
189 }
190 
191 
rtw_indicate_wx_assoc_event(_adapter * padapter)192 void rtw_indicate_wx_assoc_event(_adapter *padapter)
193 {
194 	union iwreq_data wrqu;
195 	struct	mlme_priv *pmlmepriv = &padapter->mlmepriv;
196 	struct mlme_ext_priv	*pmlmeext = &padapter->mlmeextpriv;
197 	struct mlme_ext_info	*pmlmeinfo = &(pmlmeext->mlmext_info);
198 	WLAN_BSSID_EX		*pnetwork = (WLAN_BSSID_EX *)(&(pmlmeinfo->network));
199 
200 	_rtw_memset(&wrqu, 0, sizeof(union iwreq_data));
201 
202 	wrqu.ap_addr.sa_family = ARPHRD_ETHER;
203 
204 	if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == _TRUE)
205 		_rtw_memcpy(wrqu.ap_addr.sa_data, pnetwork->MacAddress, ETH_ALEN);
206 	else
207 		_rtw_memcpy(wrqu.ap_addr.sa_data, pmlmepriv->cur_network.network.MacAddress, ETH_ALEN);
208 
209 	RTW_PRINT("assoc success\n");
210 #ifndef CONFIG_IOCTL_CFG80211
211 	wireless_send_event(padapter->pnetdev, SIOCGIWAP, &wrqu, NULL);
212 #endif
213 }
214 
rtw_indicate_wx_disassoc_event(_adapter * padapter)215 void rtw_indicate_wx_disassoc_event(_adapter *padapter)
216 {
217 	union iwreq_data wrqu;
218 
219 	_rtw_memset(&wrqu, 0, sizeof(union iwreq_data));
220 
221 	wrqu.ap_addr.sa_family = ARPHRD_ETHER;
222 	_rtw_memset(wrqu.ap_addr.sa_data, 0, ETH_ALEN);
223 
224 #ifndef CONFIG_IOCTL_CFG80211
225 	RTW_PRINT("indicate disassoc\n");
226 	wireless_send_event(padapter->pnetdev, SIOCGIWAP, &wrqu, NULL);
227 #endif
228 }
229 
230 /*
231 uint	rtw_is_cckrates_included(u8 *rate)
232 {
233 		u32	i = 0;
234 
235 		while(rate[i]!=0)
236 		{
237 			if  (  (((rate[i]) & 0x7f) == 2)	|| (((rate[i]) & 0x7f) == 4) ||
238 			(((rate[i]) & 0x7f) == 11)  || (((rate[i]) & 0x7f) == 22) )
239 			return _TRUE;
240 			i++;
241 		}
242 
243 		return _FALSE;
244 }
245 
246 uint	rtw_is_cckratesonly_included(u8 *rate)
247 {
248 	u32 i = 0;
249 
250 	while(rate[i]!=0)
251 	{
252 			if  (  (((rate[i]) & 0x7f) != 2) && (((rate[i]) & 0x7f) != 4) &&
253 				(((rate[i]) & 0x7f) != 11)  && (((rate[i]) & 0x7f) != 22) )
254 			return _FALSE;
255 			i++;
256 	}
257 
258 	return _TRUE;
259 }
260 */
261 
iwe_stream_mac_addr_proess(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)262 static inline char *iwe_stream_mac_addr_proess(_adapter *padapter,
263 		struct iw_request_info *info, struct wlan_network *pnetwork,
264 		char *start, char *stop, struct iw_event *iwe)
265 {
266 	/*  AP MAC address */
267 	iwe->cmd = SIOCGIWAP;
268 	iwe->u.ap_addr.sa_family = ARPHRD_ETHER;
269 
270 	_rtw_memcpy(iwe->u.ap_addr.sa_data, pnetwork->network.MacAddress, ETH_ALEN);
271 	start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_ADDR_LEN);
272 	return start;
273 }
iwe_stream_essid_proess(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)274 static inline char *iwe_stream_essid_proess(_adapter *padapter,
275 		struct iw_request_info *info, struct wlan_network *pnetwork,
276 		char *start, char *stop, struct iw_event *iwe)
277 {
278 
279 	/* Add the ESSID */
280 	iwe->cmd = SIOCGIWESSID;
281 	iwe->u.data.flags = 1;
282 	iwe->u.data.length = min((u16)pnetwork->network.Ssid.SsidLength, (u16)32);
283 	start = iwe_stream_add_point(info, start, stop, iwe, pnetwork->network.Ssid.Ssid);
284 	return start;
285 }
286 
iwe_stream_chan_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)287 static inline char *iwe_stream_chan_process(_adapter *padapter,
288 		struct iw_request_info *info, struct wlan_network *pnetwork,
289 		char *start, char *stop, struct iw_event *iwe)
290 {
291 	if (pnetwork->network.Configuration.DSConfig < 1 /*|| pnetwork->network.Configuration.DSConfig>14*/)
292 		pnetwork->network.Configuration.DSConfig = 1;
293 
294 	/* Add frequency/channel */
295 	iwe->cmd = SIOCGIWFREQ;
296 	iwe->u.freq.m = rtw_ch2freq(pnetwork->network.Configuration.DSConfig) * 100000;
297 	iwe->u.freq.e = 1;
298 	iwe->u.freq.i = pnetwork->network.Configuration.DSConfig;
299 	start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_FREQ_LEN);
300 	return start;
301 }
iwe_stream_mode_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe,u16 cap)302 static inline char *iwe_stream_mode_process(_adapter *padapter,
303 		struct iw_request_info *info, struct wlan_network *pnetwork,
304 		char *start, char *stop, struct iw_event *iwe, u16 cap)
305 {
306 	/* Add mode */
307 	if (cap & (WLAN_CAPABILITY_IBSS | WLAN_CAPABILITY_BSS)) {
308 		iwe->cmd = SIOCGIWMODE;
309 		if (cap & WLAN_CAPABILITY_BSS)
310 			iwe->u.mode = IW_MODE_MASTER;
311 		else
312 			iwe->u.mode = IW_MODE_ADHOC;
313 
314 		start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_UINT_LEN);
315 	}
316 	return start;
317 }
iwe_stream_encryption_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe,u16 cap)318 static inline char *iwe_stream_encryption_process(_adapter *padapter,
319 		struct iw_request_info *info, struct wlan_network *pnetwork,
320 		char *start, char *stop, struct iw_event *iwe, u16 cap)
321 {
322 
323 	/* Add encryption capability */
324 	iwe->cmd = SIOCGIWENCODE;
325 	if (cap & WLAN_CAPABILITY_PRIVACY)
326 		iwe->u.data.flags = IW_ENCODE_ENABLED | IW_ENCODE_NOKEY;
327 	else
328 		iwe->u.data.flags = IW_ENCODE_DISABLED;
329 	iwe->u.data.length = 0;
330 	start = iwe_stream_add_point(info, start, stop, iwe, pnetwork->network.Ssid.Ssid);
331 	return start;
332 
333 }
334 
iwe_stream_protocol_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)335 static inline char *iwe_stream_protocol_process(_adapter *padapter,
336 		struct iw_request_info *info, struct wlan_network *pnetwork,
337 		char *start, char *stop, struct iw_event *iwe)
338 {
339 	u16 ht_cap = _FALSE, vht_cap = _FALSE;
340 	u32 ht_ielen = 0, vht_ielen = 0;
341 	char *p;
342 	u8 ie_offset = (pnetwork->network.Reserved[0] == BSS_TYPE_PROB_REQ ? 0 : 12); /* Probe Request	 */
343 
344 #ifdef CONFIG_80211N_HT
345 	/* parsing HT_CAP_IE	 */
346 	if(padapter->registrypriv.ht_enable && is_supported_ht(padapter->registrypriv.wireless_mode)) {
347 		p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength - ie_offset);
348 		if (p && ht_ielen > 0)
349 			ht_cap = _TRUE;
350 	}
351 #endif
352 
353 #ifdef CONFIG_80211AC_VHT
354 	/* parsing VHT_CAP_IE */
355 	if(is_supported_vht(padapter->registrypriv.wireless_mode)) {
356 		p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], EID_VHTCapability, &vht_ielen, pnetwork->network.IELength - ie_offset);
357 		if (p && vht_ielen > 0)
358 			vht_cap = _TRUE;
359 	}
360 #endif
361 	/* Add the protocol name */
362 	iwe->cmd = SIOCGIWNAME;
363 	if ((rtw_is_cckratesonly_included((u8 *)&pnetwork->network.SupportedRates)) == _TRUE) {
364 		if (ht_cap == _TRUE)
365 			snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11bn");
366 		else
367 			snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11b");
368 	} else if ((rtw_is_cckrates_included((u8 *)&pnetwork->network.SupportedRates)) == _TRUE) {
369 		if (ht_cap == _TRUE)
370 			snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11bgn");
371 		else
372 			snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11bg");
373 	} else {
374 		if (pnetwork->network.Configuration.DSConfig > 14) {
375 			#ifdef CONFIG_80211AC_VHT
376 			if (vht_cap == _TRUE)
377 				snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11AC");
378 			else
379 			#endif
380 			{
381 				if (ht_cap == _TRUE)
382 					snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11an");
383 				else
384 					snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11a");
385 			}
386 		} else {
387 			if (ht_cap == _TRUE)
388 				snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11gn");
389 			else
390 				snprintf(iwe->u.name, IFNAMSIZ, "IEEE 802.11g");
391 		}
392 	}
393 	start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_CHAR_LEN);
394 	return start;
395 }
396 
iwe_stream_rate_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)397 static inline char *iwe_stream_rate_process(_adapter *padapter,
398 		struct iw_request_info *info, struct wlan_network *pnetwork,
399 		char *start, char *stop, struct iw_event *iwe)
400 {
401 	u32 ht_ielen = 0, vht_ielen = 0;
402 	char *p;
403 	u16 max_rate = 0, rate, ht_cap = _FALSE, vht_cap = _FALSE;
404 	u32 i = 0;
405 	u8 bw_40MHz = 0, short_GI = 0, bw_160MHz = 0, vht_highest_rate = 0;
406 	u16 mcs_rate = 0, vht_data_rate = 0;
407 	char custom[MAX_CUSTOM_LEN] = {0};
408 	u8 ie_offset = (pnetwork->network.Reserved[0] == BSS_TYPE_PROB_REQ ? 0 : 12); /* Probe Request	 */
409 
410 	/* parsing HT_CAP_IE	 */
411 	if(is_supported_ht(padapter->registrypriv.wireless_mode)) {
412 		p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength - ie_offset);
413 		if (p && ht_ielen > 0) {
414 			struct rtw_ieee80211_ht_cap *pht_capie;
415 			ht_cap = _TRUE;
416 			pht_capie = (struct rtw_ieee80211_ht_cap *)(p + 2);
417 			_rtw_memcpy(&mcs_rate , pht_capie->supp_mcs_set, 2);
418 			bw_40MHz = (pht_capie->cap_info & IEEE80211_HT_CAP_SUP_WIDTH) ? 1 : 0;
419 			short_GI = (pht_capie->cap_info & (IEEE80211_HT_CAP_SGI_20 | IEEE80211_HT_CAP_SGI_40)) ? 1 : 0;
420 		}
421 	}
422 #ifdef CONFIG_80211AC_VHT
423 	/* parsing VHT_CAP_IE */
424 	if(is_supported_vht(padapter->registrypriv.wireless_mode)){
425 		p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], EID_VHTCapability, &vht_ielen, pnetwork->network.IELength - ie_offset);
426 		if (p && vht_ielen > 0) {
427 			u8	mcs_map[2];
428 
429 			vht_cap = _TRUE;
430 			bw_160MHz = GET_VHT_CAPABILITY_ELE_CHL_WIDTH(p + 2);
431 			if (bw_160MHz)
432 				short_GI = GET_VHT_CAPABILITY_ELE_SHORT_GI160M(p + 2);
433 			else
434 				short_GI = GET_VHT_CAPABILITY_ELE_SHORT_GI80M(p + 2);
435 
436 			_rtw_memcpy(mcs_map, GET_VHT_CAPABILITY_ELE_TX_MCS(p + 2), 2);
437 
438 			vht_highest_rate = rtw_get_vht_highest_rate(mcs_map);
439 			vht_data_rate = rtw_vht_mcs_to_data_rate(CHANNEL_WIDTH_80, short_GI, vht_highest_rate);
440 		}
441 	}
442 #endif
443 
444 	/*Add basic and extended rates */
445 	p = custom;
446 	p += snprintf(p, MAX_CUSTOM_LEN - (p - custom), " Rates (Mb/s): ");
447 	while (pnetwork->network.SupportedRates[i] != 0) {
448 		rate = pnetwork->network.SupportedRates[i] & 0x7F;
449 		if (rate > max_rate)
450 			max_rate = rate;
451 		p += snprintf(p, MAX_CUSTOM_LEN - (p - custom),
452 			      "%d%s ", rate >> 1, (rate & 1) ? ".5" : "");
453 		i++;
454 	}
455 #ifdef CONFIG_80211AC_VHT
456 	if (vht_cap == _TRUE)
457 		max_rate = vht_data_rate;
458 	else
459 #endif
460 		if (ht_cap == _TRUE) {
461 			if (mcs_rate & 0x8000) /* MCS15 */
462 				max_rate = (bw_40MHz) ? ((short_GI) ? 300 : 270) : ((short_GI) ? 144 : 130);
463 
464 			else if (mcs_rate & 0x0080) /* MCS7 */
465 				max_rate = (bw_40MHz) ? ((short_GI) ? 150 : 135) : ((short_GI) ? 72 : 65);
466 			else { /* default MCS7 */
467 				/* RTW_INFO("wx_get_scan, mcs_rate_bitmap=0x%x\n", mcs_rate); */
468 				max_rate = (bw_40MHz) ? ((short_GI) ? 150 : 135) : ((short_GI) ? 72 : 65);
469 			}
470 
471 			max_rate = max_rate * 2; /* Mbps/2;		 */
472 		}
473 
474 	iwe->cmd = SIOCGIWRATE;
475 	iwe->u.bitrate.fixed = iwe->u.bitrate.disabled = 0;
476 	iwe->u.bitrate.value = max_rate * 500000;
477 	start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_PARAM_LEN);
478 	return start ;
479 }
480 
iwe_stream_wpa_wpa2_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)481 static inline char *iwe_stream_wpa_wpa2_process(_adapter *padapter,
482 		struct iw_request_info *info, struct wlan_network *pnetwork,
483 		char *start, char *stop, struct iw_event *iwe)
484 {
485 	int buf_size = MAX_WPA_IE_LEN * 2;
486 	/* u8 pbuf[buf_size]={0};	 */
487 	u8 *pbuf = rtw_zmalloc(buf_size);
488 
489 	u8 wpa_ie[255] = {0}, rsn_ie[255] = {0};
490 	u16 i, wpa_len = 0, rsn_len = 0;
491 	u8 *p;
492 	sint out_len = 0;
493 
494 
495 	if (pbuf) {
496 		p = pbuf;
497 
498 		/* parsing WPA/WPA2 IE */
499 		if (pnetwork->network.Reserved[0] != BSS_TYPE_PROB_REQ) { /* Probe Request */
500 			out_len = rtw_get_sec_ie(pnetwork->network.IEs , pnetwork->network.IELength, rsn_ie, &rsn_len, wpa_ie, &wpa_len);
501 
502 			if (wpa_len > 0) {
503 
504 				_rtw_memset(pbuf, 0, buf_size);
505 				p += sprintf(p, "wpa_ie=");
506 				for (i = 0; i < wpa_len; i++)
507 					p += sprintf(p, "%02x", wpa_ie[i]);
508 
509 				if (wpa_len > 100) {
510 					printk("-----------------Len %d----------------\n", wpa_len);
511 					for (i = 0; i < wpa_len; i++)
512 						printk("%02x ", wpa_ie[i]);
513 					printk("\n");
514 					printk("-----------------Len %d----------------\n", wpa_len);
515 				}
516 
517 				_rtw_memset(iwe, 0, sizeof(*iwe));
518 				iwe->cmd = IWEVCUSTOM;
519 				iwe->u.data.length = strlen(pbuf);
520 				start = iwe_stream_add_point(info, start, stop, iwe, pbuf);
521 
522 				_rtw_memset(iwe, 0, sizeof(*iwe));
523 				iwe->cmd = IWEVGENIE;
524 				iwe->u.data.length = wpa_len;
525 				start = iwe_stream_add_point(info, start, stop, iwe, wpa_ie);
526 			}
527 			if (rsn_len > 0) {
528 
529 				_rtw_memset(pbuf, 0, buf_size);
530 				p += sprintf(p, "rsn_ie=");
531 				for (i = 0; i < rsn_len; i++)
532 					p += sprintf(p, "%02x", rsn_ie[i]);
533 				_rtw_memset(iwe, 0, sizeof(*iwe));
534 				iwe->cmd = IWEVCUSTOM;
535 				iwe->u.data.length = strlen(pbuf);
536 				start = iwe_stream_add_point(info, start, stop, iwe, pbuf);
537 
538 				_rtw_memset(iwe, 0, sizeof(*iwe));
539 				iwe->cmd = IWEVGENIE;
540 				iwe->u.data.length = rsn_len;
541 				start = iwe_stream_add_point(info, start, stop, iwe, rsn_ie);
542 			}
543 		}
544 
545 		rtw_mfree(pbuf, buf_size);
546 	}
547 	return start;
548 }
549 
iwe_stream_wps_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)550 static inline char *iwe_stream_wps_process(_adapter *padapter,
551 		struct iw_request_info *info, struct wlan_network *pnetwork,
552 		char *start, char *stop, struct iw_event *iwe)
553 {
554 	/* parsing WPS IE */
555 	uint cnt = 0, total_ielen;
556 	u8 *wpsie_ptr = NULL;
557 	uint wps_ielen = 0;
558 	u8 ie_offset = (pnetwork->network.Reserved[0] == BSS_TYPE_PROB_REQ ? 0 : 12);
559 
560 	u8 *ie_ptr = pnetwork->network.IEs + ie_offset;
561 	total_ielen = pnetwork->network.IELength - ie_offset;
562 
563 	if (pnetwork->network.Reserved[0] == BSS_TYPE_PROB_REQ) { /* Probe Request */
564 		ie_ptr = pnetwork->network.IEs;
565 		total_ielen = pnetwork->network.IELength;
566 	} else { /* Beacon or Probe Respones */
567 		ie_ptr = pnetwork->network.IEs + _FIXED_IE_LENGTH_;
568 		total_ielen = pnetwork->network.IELength - _FIXED_IE_LENGTH_;
569 	}
570 	while (cnt < total_ielen) {
571 		if (rtw_is_wps_ie(&ie_ptr[cnt], &wps_ielen) && (wps_ielen > 2)) {
572 			wpsie_ptr = &ie_ptr[cnt];
573 			iwe->cmd = IWEVGENIE;
574 			iwe->u.data.length = (u16)wps_ielen;
575 			start = iwe_stream_add_point(info, start, stop, iwe, wpsie_ptr);
576 		}
577 		cnt += ie_ptr[cnt + 1] + 2; /* goto next */
578 	}
579 	return start;
580 }
581 
iwe_stream_wapi_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)582 static inline char *iwe_stream_wapi_process(_adapter *padapter,
583 		struct iw_request_info *info, struct wlan_network *pnetwork,
584 		char *start, char *stop, struct iw_event *iwe)
585 {
586 #ifdef CONFIG_WAPI_SUPPORT
587 	char *p;
588 
589 	if (pnetwork->network.Reserved[0] != BSS_TYPE_PROB_REQ) { /* Probe Request */
590 		sint out_len_wapi = 0;
591 		/* here use static for stack size */
592 		static u8 buf_wapi[MAX_WAPI_IE_LEN * 2] = {0};
593 		static u8 wapi_ie[MAX_WAPI_IE_LEN] = {0};
594 		u16 wapi_len = 0;
595 		u16  i;
596 
597 		out_len_wapi = rtw_get_wapi_ie(pnetwork->network.IEs , pnetwork->network.IELength, wapi_ie, &wapi_len);
598 
599 		RTW_INFO("rtw_wx_get_scan: %s ", pnetwork->network.Ssid.Ssid);
600 		RTW_INFO("rtw_wx_get_scan: ssid = %d ", wapi_len);
601 
602 
603 		if (wapi_len > 0) {
604 			p = buf_wapi;
605 			/* _rtw_memset(buf_wapi, 0, MAX_WAPI_IE_LEN*2); */
606 			p += sprintf(p, "wapi_ie=");
607 			for (i = 0; i < wapi_len; i++)
608 				p += sprintf(p, "%02x", wapi_ie[i]);
609 
610 			_rtw_memset(iwe, 0, sizeof(*iwe));
611 			iwe->cmd = IWEVCUSTOM;
612 			iwe->u.data.length = strlen(buf_wapi);
613 			start = iwe_stream_add_point(info, start, stop, iwe, buf_wapi);
614 
615 			_rtw_memset(iwe, 0, sizeof(*iwe));
616 			iwe->cmd = IWEVGENIE;
617 			iwe->u.data.length = wapi_len;
618 			start = iwe_stream_add_point(info, start, stop, iwe, wapi_ie);
619 		}
620 	}
621 #endif/* #ifdef CONFIG_WAPI_SUPPORT */
622 	return start;
623 }
624 
iwe_stream_rssi_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)625 static inline char   *iwe_stream_rssi_process(_adapter *padapter,
626 		struct iw_request_info *info, struct wlan_network *pnetwork,
627 		char *start, char *stop, struct iw_event *iwe)
628 {
629 	u8 ss, sq;
630 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
631 
632 	/* Add quality statistics */
633 	iwe->cmd = IWEVQUAL;
634 	iwe->u.qual.updated = IW_QUAL_QUAL_UPDATED | IW_QUAL_LEVEL_UPDATED
635 #if 0 /*def CONFIG_BACKGROUND_NOISE_MONITOR*/
636 			      | IW_QUAL_NOISE_UPDATED
637 #else
638 			      | IW_QUAL_NOISE_INVALID
639 #endif
640 #ifdef CONFIG_SIGNAL_DISPLAY_DBM
641 			      | IW_QUAL_DBM
642 #endif
643 			      ;
644 
645 	if (check_fwstate(pmlmepriv, WIFI_ASOC_STATE) == _TRUE &&
646 	    is_same_network(&pmlmepriv->cur_network.network, &pnetwork->network)) {
647 		ss = padapter->recvinfo.signal_strength;
648 		sq = padapter->recvinfo.signal_qual;
649 	} else {
650 		ss = pnetwork->network.PhyInfo.SignalStrength;
651 		sq = pnetwork->network.PhyInfo.SignalQuality;
652 	}
653 
654 
655 #ifdef CONFIG_SIGNAL_DISPLAY_DBM
656 	iwe->u.qual.level = (u8) rtw_phl_rssi_to_dbm(ss); /* dbm */
657 #else
658 	iwe->u.qual.level = (u8)ss; /* % */
659 #endif
660 
661 	iwe->u.qual.qual = (u8)sq;   /* signal quality */
662 
663 #ifdef CONFIG_PLATFORM_ROCKCHIPS
664 	iwe->u.qual.noise = -100; /* noise level suggest by zhf@rockchips */
665 #else
666 	iwe->u.qual.noise = 0; /* noise level */
667 #endif /* CONFIG_PLATFORM_ROCKCHIPS */
668 
669 	/* RTW_INFO("iqual=%d, ilevel=%d, inoise=%d, iupdated=%d\n", iwe.u.qual.qual, iwe.u.qual.level , iwe.u.qual.noise, iwe.u.qual.updated); */
670 
671 	start = iwe_stream_add_event(info, start, stop, iwe, IW_EV_QUAL_LEN);
672 	return start;
673 }
674 
iwe_stream_net_rsv_process(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop,struct iw_event * iwe)675 static inline char   *iwe_stream_net_rsv_process(_adapter *padapter,
676 		struct iw_request_info *info, struct wlan_network *pnetwork,
677 		char *start, char *stop, struct iw_event *iwe)
678 {
679 	u8 buf[32] = {0};
680 	u8 *p, *pos;
681 	p = buf;
682 	pos = pnetwork->network.Reserved;
683 
684 	p += sprintf(p, "fm=%02X%02X", pos[1], pos[0]);
685 	_rtw_memset(iwe, 0, sizeof(*iwe));
686 	iwe->cmd = IWEVCUSTOM;
687 	iwe->u.data.length = strlen(buf);
688 	start = iwe_stream_add_point(info, start, stop, iwe, buf);
689 	return start;
690 }
691 
translate_scan(_adapter * padapter,struct iw_request_info * info,struct wlan_network * pnetwork,char * start,char * stop)692 static char *translate_scan(_adapter *padapter,
693 		struct iw_request_info *info, struct wlan_network *pnetwork,
694 		char *start, char *stop)
695 {
696 	struct iw_event iwe;
697 	u16 cap = 0;
698 	_rtw_memset(&iwe, 0, sizeof(iwe));
699 
700 	start = iwe_stream_mac_addr_proess(padapter, info, pnetwork, start, stop, &iwe);
701 	start = iwe_stream_essid_proess(padapter, info, pnetwork, start, stop, &iwe);
702 	start = iwe_stream_protocol_process(padapter, info, pnetwork, start, stop, &iwe);
703 	if (pnetwork->network.Reserved[0] == BSS_TYPE_PROB_REQ) /* Probe Request */
704 		cap = 0;
705 	else {
706 		_rtw_memcpy((u8 *)&cap, rtw_get_capability_from_ie(pnetwork->network.IEs), 2);
707 		cap = le16_to_cpu(cap);
708 	}
709 
710 	start = iwe_stream_mode_process(padapter, info, pnetwork, start, stop, &iwe, cap);
711 	start = iwe_stream_chan_process(padapter, info, pnetwork, start, stop, &iwe);
712 	start = iwe_stream_encryption_process(padapter, info, pnetwork, start, stop, &iwe, cap);
713 	start = iwe_stream_rate_process(padapter, info, pnetwork, start, stop, &iwe);
714 	start = iwe_stream_wpa_wpa2_process(padapter, info, pnetwork, start, stop, &iwe);
715 	start = iwe_stream_wps_process(padapter, info, pnetwork, start, stop, &iwe);
716 	start = iwe_stream_wapi_process(padapter, info, pnetwork, start, stop, &iwe);
717 	start = iwe_stream_rssi_process(padapter, info, pnetwork, start, stop, &iwe);
718 	start = iwe_stream_net_rsv_process(padapter, info, pnetwork, start, stop, &iwe);
719 
720 	return start;
721 }
722 
wpa_set_auth_algs(struct net_device * dev,u32 value)723 static int wpa_set_auth_algs(struct net_device *dev, u32 value)
724 {
725 	_adapter *padapter = (_adapter *) rtw_netdev_priv(dev);
726 	int ret = 0;
727 
728 	if ((value & AUTH_ALG_SHARED_KEY) && (value & AUTH_ALG_OPEN_SYSTEM)) {
729 		RTW_INFO("wpa_set_auth_algs, AUTH_ALG_SHARED_KEY and  AUTH_ALG_OPEN_SYSTEM [value:0x%x]\n", value);
730 		padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
731 		padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
732 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
733 	} else if (value & AUTH_ALG_SHARED_KEY) {
734 		RTW_INFO("wpa_set_auth_algs, AUTH_ALG_SHARED_KEY  [value:0x%x]\n", value);
735 		padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
736 
737 #ifdef CONFIG_PLATFORM_MT53XX
738 		padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
739 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
740 #else
741 		padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeShared;
742 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Shared;
743 #endif
744 	} else if (value & AUTH_ALG_OPEN_SYSTEM) {
745 		RTW_INFO("wpa_set_auth_algs, AUTH_ALG_OPEN_SYSTEM\n");
746 		/* padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled; */
747 		if (padapter->securitypriv.ndisauthtype < Ndis802_11AuthModeWPAPSK) {
748 #ifdef CONFIG_PLATFORM_MT53XX
749 			padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
750 			padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
751 #else
752 			padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeOpen;
753 			padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
754 #endif
755 		}
756 
757 	} else if (value & AUTH_ALG_LEAP)
758 		RTW_INFO("wpa_set_auth_algs, AUTH_ALG_LEAP\n");
759 	else {
760 		RTW_INFO("wpa_set_auth_algs, error!\n");
761 		ret = -EINVAL;
762 	}
763 
764 	return ret;
765 
766 }
767 
wpa_set_encryption(struct net_device * dev,struct ieee_param * param,u32 param_len)768 static int wpa_set_encryption(struct net_device *dev, struct ieee_param *param, u32 param_len)
769 {
770 	int ret = 0;
771 	u32 wep_key_idx, wep_key_len;
772 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
773 	struct mlme_priv	*pmlmepriv = &padapter->mlmepriv;
774 	struct security_priv *psecuritypriv = &padapter->securitypriv;
775 #ifdef CONFIG_P2P
776 	struct wifidirect_info *pwdinfo = &padapter->wdinfo;
777 #endif /* CONFIG_P2P */
778 
779 
780 	param->u.crypt.err = 0;
781 	param->u.crypt.alg[IEEE_CRYPT_ALG_NAME_LEN - 1] = '\0';
782 
783 	if (param_len < (u32)((u8 *) param->u.crypt.key - (u8 *) param) + param->u.crypt.key_len) {
784 		ret =  -EINVAL;
785 		goto exit;
786 	}
787 
788 	if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
789 	    param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
790 	    param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) {
791 
792 		if (param->u.crypt.idx >= WEP_KEYS
793 #ifdef CONFIG_IEEE80211W
794 		    && param->u.crypt.idx > BIP_MAX_KEYID
795 #endif /* CONFIG_IEEE80211W */
796 		   ) {
797 			ret = -EINVAL;
798 			goto exit;
799 		}
800 	} else {
801 #ifdef CONFIG_WAPI_SUPPORT
802 		if (strcmp(param->u.crypt.alg, "SMS4"))
803 #endif
804 		{
805 			ret = -EINVAL;
806 			goto exit;
807 		}
808 	}
809 
810 	if (strcmp(param->u.crypt.alg, "WEP") == 0) {
811 		RTW_INFO("wpa_set_encryption, crypt.alg = WEP\n");
812 
813 		wep_key_idx = param->u.crypt.idx;
814 		wep_key_len = param->u.crypt.key_len;
815 
816 		if ((wep_key_idx >= WEP_KEYS) || (wep_key_len <= 0)) {
817 			ret = -EINVAL;
818 			goto exit;
819 		}
820 
821 		if (psecuritypriv->bWepDefaultKeyIdxSet == 0) {
822 			/* wep default key has not been set, so use this key index as default key.*/
823 
824 			wep_key_len = wep_key_len <= 5 ? 5 : 13;
825 
826 			psecuritypriv->ndisencryptstatus = Ndis802_11Encryption1Enabled;
827 			psecuritypriv->dot11PrivacyAlgrthm = _WEP40_;
828 			psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
829 
830 			if (wep_key_len == 13) {
831 				psecuritypriv->dot11PrivacyAlgrthm = _WEP104_;
832 				psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
833 			}
834 
835 			psecuritypriv->dot11PrivacyKeyIndex = wep_key_idx;
836 		}
837 
838 		_rtw_memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), param->u.crypt.key, wep_key_len);
839 
840 		psecuritypriv->dot11DefKeylen[wep_key_idx] = wep_key_len;
841 
842 		psecuritypriv->key_mask |= BIT(wep_key_idx);
843 
844 		padapter->mlmeextpriv.mlmext_info.key_index = wep_key_idx;
845 		goto exit;
846 	}
847 
848 	if (padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) { /* 802_1x */
849 		struct sta_info *psta, *pbcmc_sta;
850 		struct sta_priv *pstapriv = &padapter->stapriv;
851 
852 		if (MLME_IS_STA(padapter) || MLME_IS_MP(padapter)) { /* sta mode */
853 			psta = rtw_get_stainfo(pstapriv, get_bssid(pmlmepriv));
854 			if (psta == NULL) {
855 				/* DEBUG_ERR( ("Set wpa_set_encryption: Obtain Sta_info fail\n")); */
856 			} else {
857 				/* Jeff: don't disable ieee8021x_blocked while clearing key */
858 				if (strcmp(param->u.crypt.alg, "none") != 0)
859 					psta->ieee8021x_blocked = _FALSE;
860 
861 				if ((padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption2Enabled) ||
862 				    (padapter->securitypriv.ndisencryptstatus ==  Ndis802_11Encryption3Enabled))
863 					psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
864 
865 				if (param->u.crypt.set_tx == 1) { /* pairwise key */
866 					RTW_INFO(FUNC_ADPT_FMT" set %s PTK idx:%u, len:%u\n"
867 						, FUNC_ADPT_ARG(padapter), param->u.crypt.alg, param->u.crypt.idx, param->u.crypt.key_len);
868 					_rtw_memcpy(psta->dot118021x_UncstKey.skey,  param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
869 					if (strcmp(param->u.crypt.alg, "TKIP") == 0) { /* set mic key */
870 						_rtw_memcpy(psta->dot11tkiptxmickey.skey, &(param->u.crypt.key[16]), 8);
871 						_rtw_memcpy(psta->dot11tkiprxmickey.skey, &(param->u.crypt.key[24]), 8);
872 						padapter->securitypriv.busetkipkey = _FALSE;
873 					}
874 					psta->dot11txpn.val = RTW_GET_LE64(param->u.crypt.seq);
875 					psta->dot11rxpn.val = RTW_GET_LE64(param->u.crypt.seq);
876 					psta->bpairwise_key_installed = _TRUE;
877 					rtw_setstakey_cmd(padapter, psta, UNICAST_KEY, _TRUE);
878 
879 				} else { /* group key */
880 					if (strcmp(param->u.crypt.alg, "TKIP") == 0 || strcmp(param->u.crypt.alg, "CCMP") == 0) {
881 						RTW_INFO(FUNC_ADPT_FMT" set %s GTK idx:%u, len:%u\n"
882 							, FUNC_ADPT_ARG(padapter), param->u.crypt.alg, param->u.crypt.idx, param->u.crypt.key_len);
883 						_rtw_memcpy(padapter->securitypriv.dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key,
884 							(param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
885 						/* only TKIP group key need to install this */
886 						if (param->u.crypt.key_len > 16) {
887 							_rtw_memcpy(padapter->securitypriv.dot118021XGrptxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[16]), 8);
888 							_rtw_memcpy(padapter->securitypriv.dot118021XGrprxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[24]), 8);
889 						}
890 						padapter->securitypriv.binstallGrpkey = _TRUE;
891 						if (param->u.crypt.idx < 4)
892 							_rtw_memcpy(padapter->securitypriv.iv_seq[param->u.crypt.idx], param->u.crypt.seq, 8);
893 						padapter->securitypriv.dot118021XGrpKeyid = param->u.crypt.idx;
894 						rtw_set_key(padapter, &padapter->securitypriv, param->u.crypt.idx, 1, _TRUE);
895 
896 					#ifdef CONFIG_IEEE80211W
897 					} else if (strcmp(param->u.crypt.alg, "BIP") == 0) {
898 						RTW_INFO(FUNC_ADPT_FMT" set IGTK idx:%u, len:%u\n"
899 							, FUNC_ADPT_ARG(padapter), param->u.crypt.idx, param->u.crypt.key_len);
900 						_rtw_memcpy(padapter->securitypriv.dot11wBIPKey[param->u.crypt.idx].skey,  param->u.crypt.key,
901 							(param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
902 						psecuritypriv->dot11wBIPKeyid = param->u.crypt.idx;
903 						psecuritypriv->dot11wBIPrxpn.val = RTW_GET_LE64(param->u.crypt.seq);
904 						psecuritypriv->binstallBIPkey = _TRUE;
905 						rtw_set_key(padapter, &padapter->securitypriv, param->u.crypt.idx, 1, _TRUE);
906 					#endif /* CONFIG_IEEE80211W */
907 
908 					}
909 
910 					/* WPA/WPA2 key-handshake has completed */
911 					clr_fwstate(pmlmepriv, WIFI_UNDER_KEY_HANDSHAKE);
912 				}
913 			}
914 
915 			pbcmc_sta = rtw_get_bcmc_stainfo(padapter);
916 			if (pbcmc_sta == NULL) {
917 				/* DEBUG_ERR( ("Set OID_802_11_ADD_KEY: bcmc stainfo is null\n")); */
918 			} else {
919 				/* Jeff: don't disable ieee8021x_blocked while clearing key */
920 				if (strcmp(param->u.crypt.alg, "none") != 0)
921 					pbcmc_sta->ieee8021x_blocked = _FALSE;
922 
923 				if ((padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption2Enabled) ||
924 				    (padapter->securitypriv.ndisencryptstatus ==  Ndis802_11Encryption3Enabled))
925 					pbcmc_sta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
926 			}
927 		} else if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) { /* adhoc mode */
928 		}
929 	}
930 
931 #ifdef CONFIG_WAPI_SUPPORT
932 	if (strcmp(param->u.crypt.alg, "SMS4") == 0)
933 		rtw_wapi_set_set_encryption(padapter, param);
934 #endif
935 
936 exit:
937 
938 
939 	return ret;
940 }
941 
rtw_set_wpa_ie(_adapter * padapter,char * pie,unsigned short ielen)942 static int rtw_set_wpa_ie(_adapter *padapter, char *pie, unsigned short ielen)
943 {
944 	u8 *buf = NULL, *pos = NULL;
945 	int group_cipher = 0, pairwise_cipher = 0;
946 	u8 mfp_opt = MFP_NO;
947 	int ret = 0;
948 	u8 null_addr[] = {0, 0, 0, 0, 0, 0};
949 #ifdef CONFIG_P2P
950 	struct wifidirect_info *pwdinfo = &padapter->wdinfo;
951 #endif /* CONFIG_P2P */
952 
953 	if ((ielen > MAX_WPA_IE_LEN) || (pie == NULL)) {
954 		_clr_fwstate_(&padapter->mlmepriv, WIFI_UNDER_WPS);
955 		if (pie == NULL)
956 			return ret;
957 		else
958 			return -EINVAL;
959 	}
960 
961 	if (ielen) {
962 		buf = rtw_zmalloc(ielen);
963 		if (buf == NULL) {
964 			ret =  -ENOMEM;
965 			goto exit;
966 		}
967 
968 		_rtw_memcpy(buf, pie , ielen);
969 
970 		/* dump */
971 		{
972 			int i;
973 			RTW_INFO("\n wpa_ie(length:%d):\n", ielen);
974 			for (i = 0; i < ielen; i = i + 8)
975 				RTW_INFO("0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x\n", buf[i], buf[i + 1], buf[i + 2], buf[i + 3], buf[i + 4], buf[i + 5], buf[i + 6], buf[i + 7]);
976 		}
977 
978 		pos = buf;
979 		if (ielen < RSN_HEADER_LEN) {
980 			ret  = -1;
981 			goto exit;
982 		}
983 
984 		if (rtw_parse_wpa_ie(buf, ielen, &group_cipher, &pairwise_cipher, NULL) == _SUCCESS) {
985 			padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_8021X;
986 			padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPAPSK;
987 			_rtw_memcpy(padapter->securitypriv.supplicant_ie, &buf[0], ielen);
988 		}
989 
990 		if (rtw_parse_wpa2_ie(buf, ielen, &group_cipher, &pairwise_cipher, NULL, NULL, &mfp_opt, NULL) == _SUCCESS) {
991 			padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_8021X;
992 			padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPA2PSK;
993 			_rtw_memcpy(padapter->securitypriv.supplicant_ie, &buf[0], ielen);
994 		}
995 
996 		if (group_cipher == 0)
997 			group_cipher = WPA_CIPHER_NONE;
998 		if (pairwise_cipher == 0)
999 			pairwise_cipher = WPA_CIPHER_NONE;
1000 
1001 		switch (group_cipher) {
1002 		case WPA_CIPHER_NONE:
1003 			padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
1004 			padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
1005 			break;
1006 		case WPA_CIPHER_WEP40:
1007 			padapter->securitypriv.dot118021XGrpPrivacy = _WEP40_;
1008 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1009 			break;
1010 		case WPA_CIPHER_TKIP:
1011 			padapter->securitypriv.dot118021XGrpPrivacy = _TKIP_;
1012 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
1013 			break;
1014 		case WPA_CIPHER_CCMP:
1015 			padapter->securitypriv.dot118021XGrpPrivacy = _AES_;
1016 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
1017 			break;
1018 		case WPA_CIPHER_WEP104:
1019 			padapter->securitypriv.dot118021XGrpPrivacy = _WEP104_;
1020 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1021 			break;
1022 		}
1023 
1024 		switch (pairwise_cipher) {
1025 		case WPA_CIPHER_NONE:
1026 			padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
1027 			padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
1028 			break;
1029 		case WPA_CIPHER_WEP40:
1030 			padapter->securitypriv.dot11PrivacyAlgrthm = _WEP40_;
1031 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1032 			break;
1033 		case WPA_CIPHER_TKIP:
1034 			padapter->securitypriv.dot11PrivacyAlgrthm = _TKIP_;
1035 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
1036 			break;
1037 		case WPA_CIPHER_CCMP:
1038 			padapter->securitypriv.dot11PrivacyAlgrthm = _AES_;
1039 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
1040 			break;
1041 		case WPA_CIPHER_WEP104:
1042 			padapter->securitypriv.dot11PrivacyAlgrthm = _WEP104_;
1043 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1044 			break;
1045 		}
1046 
1047 		if (mfp_opt == MFP_INVALID) {
1048 			RTW_INFO(FUNC_ADPT_FMT" invalid MFP setting\n", FUNC_ADPT_ARG(padapter));
1049 			ret = -EINVAL;
1050 			goto exit;
1051 		}
1052 		padapter->securitypriv.mfp_opt = mfp_opt;
1053 
1054 		_clr_fwstate_(&padapter->mlmepriv, WIFI_UNDER_WPS);
1055 		{/* set wps_ie	 */
1056 			u16 cnt = 0;
1057 			u8 eid, wps_oui[4] = {0x0, 0x50, 0xf2, 0x04};
1058 
1059 			while (cnt < ielen) {
1060 				eid = buf[cnt];
1061 
1062 				if ((eid == _VENDOR_SPECIFIC_IE_) && (_rtw_memcmp(&buf[cnt + 2], wps_oui, 4) == _TRUE)) {
1063 					RTW_INFO("SET WPS_IE\n");
1064 
1065 					padapter->securitypriv.wps_ie_len = ((buf[cnt + 1] + 2) < MAX_WPS_IE_LEN) ? (buf[cnt + 1] + 2) : MAX_WPS_IE_LEN;
1066 
1067 					_rtw_memcpy(padapter->securitypriv.wps_ie, &buf[cnt], padapter->securitypriv.wps_ie_len);
1068 
1069 					set_fwstate(&padapter->mlmepriv, WIFI_UNDER_WPS);
1070 
1071 					cnt += buf[cnt + 1] + 2;
1072 
1073 					break;
1074 				} else {
1075 					cnt += buf[cnt + 1] + 2; /* goto next	 */
1076 				}
1077 			}
1078 		}
1079 
1080 		#ifdef CONFIG_RTW_MULTI_AP
1081 		padapter->multi_ap = rtw_get_multi_ap_ie_ext(buf, ielen) & MULTI_AP_BACKHAUL_STA;
1082 		if (padapter->multi_ap)
1083 			adapter_set_use_wds(padapter, 1);
1084 		#endif
1085 	}
1086 
1087 	/* TKIP and AES disallow multicast packets until installing group key */
1088 	if (padapter->securitypriv.dot11PrivacyAlgrthm == _TKIP_
1089 	    || padapter->securitypriv.dot11PrivacyAlgrthm == _TKIP_WTMIC_
1090 	    || padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
1091 		/* WPS open need to enable multicast
1092 		 * || check_fwstate(&padapter->mlmepriv, WIFI_UNDER_WPS) == _TRUE) */
1093 		rtw_hal_set_hwreg(padapter, HW_VAR_OFF_RCR_AM, null_addr);
1094 
1095 
1096 exit:
1097 
1098 	if (buf)
1099 		rtw_mfree(buf, ielen);
1100 
1101 	return ret;
1102 }
1103 
rtw_wx_get_name(struct net_device * dev,struct iw_request_info * info,union iwreq_data * wrqu,char * extra)1104 static int rtw_wx_get_name(struct net_device *dev,
1105 			   struct iw_request_info *info,
1106 			   union iwreq_data *wrqu, char *extra)
1107 {
1108 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1109 	u32 ht_ielen = 0;
1110 	char *p;
1111 	u8 ht_cap = _FALSE, vht_cap = _FALSE, he_cap = _FALSE;
1112 	struct	mlme_priv	*pmlmepriv = &(padapter->mlmepriv);
1113 	WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
1114 	NDIS_802_11_RATES_EX *prates = NULL;
1115 
1116 
1117 
1118 	if (check_fwstate(pmlmepriv, WIFI_ASOC_STATE | WIFI_ADHOC_MASTER_STATE) == _TRUE) {
1119 		/* parsing HT_CAP_IE */
1120 		if( is_supported_ht(padapter->registrypriv.wireless_mode)&&(padapter->registrypriv.ht_enable)) {
1121 			p = rtw_get_ie(&pcur_bss->IEs[12], _HT_CAPABILITY_IE_, &ht_ielen, pcur_bss->IELength - 12);
1122 			if (p && ht_ielen > 0 )
1123 				ht_cap = _TRUE;
1124 		}
1125 #ifdef CONFIG_80211AC_VHT
1126 		if (is_supported_vht(padapter->registrypriv.wireless_mode) &&
1127 			(pmlmepriv->vhtpriv.vht_option == _TRUE))
1128 			vht_cap = _TRUE;
1129 #endif
1130 #ifdef CONFIG_80211AX_HE
1131 		if (is_supported_he(padapter->registrypriv.wireless_mode) &&
1132 			(pmlmepriv->hepriv.he_option == _TRUE))
1133 			he_cap = _TRUE;
1134 #endif
1135 
1136 		prates = &pcur_bss->SupportedRates;
1137 #ifdef CONFIG_80211AX_HE
1138 		if (he_cap == _TRUE)
1139 			snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11AX");
1140 		else
1141 #endif
1142 		if (rtw_is_cckratesonly_included((u8 *)prates) == _TRUE) {
1143 			if (ht_cap == _TRUE)
1144 				snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bn");
1145 			else
1146 				snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11b");
1147 		} else if ((rtw_is_cckrates_included((u8 *)prates)) == _TRUE) {
1148 			if (ht_cap == _TRUE)
1149 				snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bgn");
1150 			else {
1151 				if(padapter->registrypriv.wireless_mode & WLAN_MD_11G)
1152 					snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bg");
1153 				else
1154 					snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11b");
1155 			}
1156 		} else {
1157 			if (pcur_bss->Configuration.DSConfig > 14) {
1158 #ifdef CONFIG_80211AC_VHT
1159 				if (vht_cap == _TRUE)
1160 					snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11AC");
1161 				else
1162 #endif
1163 				{
1164 					if (ht_cap == _TRUE)
1165 						snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11an");
1166 					else
1167 						snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11a");
1168 				}
1169 			} else {
1170 				if (ht_cap == _TRUE)
1171 					snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11gn");
1172 				else
1173 					snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11g");
1174 			}
1175 		}
1176 	} else {
1177 		/* prates = &padapter->registrypriv.dev_network.SupportedRates; */
1178 		/* snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11g"); */
1179 		snprintf(wrqu->name, IFNAMSIZ, "unassociated");
1180 	}
1181 
1182 
1183 	return 0;
1184 }
1185 
rtw_wx_set_freq(struct net_device * dev,struct iw_request_info * info,union iwreq_data * wrqu,char * extra)1186 static int rtw_wx_set_freq(struct net_device *dev,
1187 			   struct iw_request_info *info,
1188 			   union iwreq_data *wrqu, char *extra)
1189 {
1190 
1191 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1192 	int exp = 1, freq = 0, div = 0;
1193 
1194 	rtw_ps_deny(padapter, PS_DENY_IOCTL);
1195 	if (rtw_pwr_wakeup(padapter) == _FALSE)
1196 		goto exit;
1197 	if (wrqu->freq.m <= 1000) {
1198 		if (wrqu->freq.flags == IW_FREQ_AUTO) {
1199 			if (rtw_chset_search_ch(adapter_to_chset(padapter), wrqu->freq.m) > 0) {
1200 				padapter->mlmeextpriv.chandef.chan = wrqu->freq.m;
1201 				RTW_INFO("%s: channel is auto, set to channel %d\n", __func__, wrqu->freq.m);
1202 			} else {
1203 				padapter->mlmeextpriv.chandef.chan = 1;
1204 				RTW_INFO("%s: channel is auto, Channel Plan don't match just set to channel 1\n", __func__);
1205 			}
1206 		} else {
1207 			padapter->mlmeextpriv.chandef.chan = wrqu->freq.m;
1208 			RTW_INFO("%s: set to channel %d\n", __func__, padapter->mlmeextpriv.chandef.chan);
1209 		}
1210 	} else {
1211 		while (wrqu->freq.e) {
1212 			exp *= 10;
1213 			wrqu->freq.e--;
1214 		}
1215 
1216 		freq = wrqu->freq.m;
1217 
1218 		while (!(freq % 10)) {
1219 			freq /= 10;
1220 			exp *= 10;
1221 		}
1222 
1223 		/* freq unit is MHz here */
1224 		div = 1000000 / exp;
1225 
1226 		if (div)
1227 			freq /= div;
1228 		else {
1229 			div = exp / 1000000;
1230 			freq *= div;
1231 		}
1232 
1233 		/* If freq is invalid, rtw_freq2ch() will return channel 1 */
1234 		padapter->mlmeextpriv.chandef.chan = rtw_freq2ch(freq);
1235 		RTW_INFO("%s: set to channel %d\n", __func__, padapter->mlmeextpriv.chandef.chan);
1236 	}
1237 	set_channel_bwmode(padapter,
1238 				padapter->mlmeextpriv.chandef.chan,
1239 				CHAN_OFFSET_NO_EXT,
1240 				CHANNEL_WIDTH_20,
1241 				_FALSE);
1242 exit:
1243 	rtw_ps_deny_cancel(padapter, PS_DENY_IOCTL);
1244 
1245 	return 0;
1246 }
1247 
rtw_wx_get_freq(struct net_device * dev,struct iw_request_info * info,union iwreq_data * wrqu,char * extra)1248 static int rtw_wx_get_freq(struct net_device *dev,
1249 			   struct iw_request_info *info,
1250 			   union iwreq_data *wrqu, char *extra)
1251 {
1252 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1253 	struct	mlme_priv	*pmlmepriv = &(padapter->mlmepriv);
1254 	WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
1255 
1256 	if (check_fwstate(pmlmepriv, WIFI_ASOC_STATE) == _TRUE && check_fwstate(pmlmepriv, WIFI_MONITOR_STATE) != _TRUE) {
1257 
1258 		wrqu->freq.m = rtw_ch2freq(pcur_bss->Configuration.DSConfig) * 100000;
1259 		wrqu->freq.e = 1;
1260 		wrqu->freq.i = pcur_bss->Configuration.DSConfig;
1261 
1262 	} else {
1263 		wrqu->freq.m = rtw_ch2freq(padapter->mlmeextpriv.chandef.chan) * 100000;
1264 		wrqu->freq.e = 1;
1265 		wrqu->freq.i = padapter->mlmeextpriv.chandef.chan;
1266 	}
1267 
1268 	return 0;
1269 }
1270 
wext_mode_to_rtw_mlme_state(union iwreq_data * wrqu)1271 u32 wext_mode_to_rtw_mlme_state(union iwreq_data *wrqu)
1272 {
1273 	switch (wrqu->mode) {
1274 	#ifdef CONFIG_WIFI_MONITOR
1275 	case IW_MODE_MONITOR:
1276 		return WIFI_MONITOR_STATE;
1277 	#endif
1278 	case IW_MODE_ADHOC:
1279 		return WIFI_ADHOC_STATE;
1280 	#ifdef CONFIG_AP_MODE
1281 	case IW_MODE_MASTER:
1282 		return WIFI_AP_STATE;
1283 	#endif
1284 	case IW_MODE_INFRA:
1285 		return WIFI_STATION_STATE;
1286 
1287 	#ifdef CONFIG_RTW_MESH
1288 	case IW_MODE_MESH:
1289 		return WIFI_MESH_STATE;
1290 	#endif
1291 
1292 	case IW_MODE_AUTO:
1293 	default:
1294 		return WIFI_STATION_STATE;
1295 	}
1296 }
1297 
rtw_wx_set_mode(struct net_device * dev,struct iw_request_info * a,union iwreq_data * wrqu,char * b)1298 static int rtw_wx_set_mode(struct net_device *dev, struct iw_request_info *a,
1299 			   union iwreq_data *wrqu, char *b)
1300 {
1301 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1302 	struct	mlme_priv	*pmlmepriv = &(padapter->mlmepriv);
1303 	NDIS_802_11_NETWORK_INFRASTRUCTURE networkType ;
1304 	int ret = 0;
1305 
1306 
1307 	if (_FAIL == rtw_pwr_wakeup(padapter)) {
1308 		ret = -EPERM;
1309 		goto exit;
1310 	}
1311 
1312 	if (!rtw_hw_is_init_completed(adapter_to_dvobj(padapter))) {
1313 		ret = -EPERM;
1314 		goto exit;
1315 	}
1316 
1317 	/* initial default type */
1318 	dev->type = ARPHRD_ETHER;
1319 
1320 	if (wrqu->mode != IW_MODE_MONITOR) {
1321 		rtw_ps_deny_cancel(padapter, PS_DENY_MONITOR_MODE);
1322 	}
1323 
1324 	switch (wrqu->mode) {
1325 #ifdef CONFIG_WIFI_MONITOR
1326 	case IW_MODE_MONITOR:
1327 		networkType = Ndis802_11Monitor;
1328 
1329 		rtw_ps_deny(padapter, PS_DENY_MONITOR_MODE);
1330 		LeaveAllPowerSaveMode(padapter);
1331 
1332 #if 0
1333 		dev->type = ARPHRD_IEEE80211; /* IEEE 802.11 : 801 */
1334 #endif
1335 
1336 #if (LINUX_VERSION_CODE >= KERNEL_VERSION(2, 6, 24))
1337 		dev->type = ARPHRD_IEEE80211_RADIOTAP; /* IEEE 802.11 + radiotap header : 803 */
1338 		RTW_INFO("set_mode = IW_MODE_MONITOR\n");
1339 #else
1340 		RTW_INFO("kernel version < 2.6.24 not support IW_MODE_MONITOR\n");
1341 #endif
1342 		break;
1343 #endif /* CONFIG_WIFI_MONITOR */
1344 	case IW_MODE_AUTO:
1345 		networkType = Ndis802_11AutoUnknown;
1346 		RTW_INFO("set_mode = IW_MODE_AUTO\n");
1347 		break;
1348 	case IW_MODE_ADHOC:
1349 		networkType = Ndis802_11IBSS;
1350 		RTW_INFO("set_mode = IW_MODE_ADHOC\n");
1351 		break;
1352 	case IW_MODE_MASTER:
1353 		networkType = Ndis802_11APMode;
1354 		RTW_INFO("set_mode = IW_MODE_MASTER\n");
1355 		break;
1356 	case IW_MODE_INFRA:
1357 		networkType = Ndis802_11Infrastructure;
1358 		RTW_INFO("set_mode = IW_MODE_INFRA\n");
1359 		break;
1360 
1361 	default:
1362 		ret = -EINVAL;;
1363 		goto exit;
1364 	}
1365 
1366 	if (rtw_set_802_11_infrastructure_mode(padapter, networkType, 0) == _FALSE) {
1367 
1368 		ret = -EPERM;
1369 		goto exit;
1370 
1371 	}
1372 
1373 	rtw_setopmode_cmd(padapter, networkType, RTW_CMDF_WAIT_ACK);
1374 
1375 	if (check_fwstate(pmlmepriv, WIFI_MONITOR_STATE) == _TRUE)
1376 		rtw_indicate_connect(padapter);
1377 
1378 exit:
1379 
1380 
1381 	return ret;
1382 
1383 }
1384 
rtw_wx_get_mode(struct net_device * dev,struct iw_request_info * a,union iwreq_data * wrqu,char * b)1385 static int rtw_wx_get_mode(struct net_device *dev, struct iw_request_info *a,
1386 			   union iwreq_data *wrqu, char *b)
1387 {
1388 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1389 	struct	mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1390 
1391 	if (MLME_IS_STA(padapter))
1392 		wrqu->mode = IW_MODE_INFRA;
1393 	else if (MLME_IS_ADHOC(padapter) || MLME_IS_ADHOC_MASTER(padapter))
1394 		wrqu->mode = IW_MODE_ADHOC;
1395 	else if (MLME_IS_AP(padapter))
1396 		wrqu->mode = IW_MODE_MASTER;
1397 	else if (MLME_IS_MONITOR(padapter))
1398 		wrqu->mode = IW_MODE_MONITOR;
1399 	else
1400 		wrqu->mode = IW_MODE_AUTO;
1401 
1402 
1403 	return 0;
1404 
1405 }
1406 
1407 
rtw_wx_set_pmkid(struct net_device * dev,struct iw_request_info * a,union iwreq_data * wrqu,char * extra)1408 static int rtw_wx_set_pmkid(struct net_device *dev,
1409 			    struct iw_request_info *a,
1410 			    union iwreq_data *wrqu, char *extra)
1411 {
1412 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1413 	u8          j, blInserted = _FALSE;
1414 	int         intReturn = _FALSE;
1415 	struct security_priv *psecuritypriv = &padapter->securitypriv;
1416 	struct iw_pmksa  *pPMK = (struct iw_pmksa *) extra;
1417 	u8     strZeroMacAddress[ETH_ALEN] = { 0x00 };
1418 	u8     strIssueBssid[ETH_ALEN] = { 0x00 };
1419 
1420 #if 0
1421 	struct iw_pmksa {
1422 		__u32   cmd;
1423 		struct sockaddr bssid;
1424 		__u8    pmkid[IW_PMKID_LEN];   /* IW_PMKID_LEN=16 */
1425 	}
1426 	There are the BSSID information in the bssid.sa_data array.
1427 	If cmd is IW_PMKSA_FLUSH, it means the wpa_suppplicant wants to clear all the PMKID information.
1428 	If cmd is IW_PMKSA_ADD, it means the wpa_supplicant wants to add a PMKID / BSSID to driver.
1429 	If cmd is IW_PMKSA_REMOVE, it means the wpa_supplicant wants to remove a PMKID / BSSID from driver.
1430 #endif
1431 
1432 	_rtw_memcpy(strIssueBssid, pPMK->bssid.sa_data, ETH_ALEN);
1433 	if (pPMK->cmd == IW_PMKSA_ADD) {
1434 		RTW_INFO("[rtw_wx_set_pmkid] IW_PMKSA_ADD!\n");
1435 		if (_rtw_memcmp(strIssueBssid, strZeroMacAddress, ETH_ALEN) == _TRUE)
1436 			return intReturn ;
1437 		else
1438 			intReturn = _TRUE;
1439 		blInserted = _FALSE;
1440 
1441 		/* overwrite PMKID */
1442 		for (j = 0 ; j < NUM_PMKID_CACHE; j++) {
1443 			if (_rtw_memcmp(psecuritypriv->PMKIDList[j].Bssid, strIssueBssid, ETH_ALEN) == _TRUE) {
1444 				/* BSSID is matched, the same AP => rewrite with new PMKID. */
1445 
1446 				RTW_INFO("[rtw_wx_set_pmkid] BSSID exists in the PMKList.\n");
1447 
1448 				_rtw_memcpy(psecuritypriv->PMKIDList[j].PMKID, pPMK->pmkid, IW_PMKID_LEN);
1449 				psecuritypriv->PMKIDList[j].bUsed = _TRUE;
1450 				blInserted = _TRUE;
1451 				break;
1452 			}
1453 		}
1454 
1455 		if (!blInserted) {
1456 			/* Find a new entry */
1457 			RTW_INFO("[rtw_wx_set_pmkid] Use the new entry index = %d for this PMKID.\n",
1458 				 psecuritypriv->PMKIDIndex);
1459 
1460 			_rtw_memcpy(psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].Bssid, strIssueBssid, ETH_ALEN);
1461 			_rtw_memcpy(psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].PMKID, pPMK->pmkid, IW_PMKID_LEN);
1462 
1463 			psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].bUsed = _TRUE;
1464 			psecuritypriv->PMKIDIndex++ ;
1465 			if (psecuritypriv->PMKIDIndex == 16)
1466 				psecuritypriv->PMKIDIndex = 0;
1467 		}
1468 	} else if (pPMK->cmd == IW_PMKSA_REMOVE) {
1469 		RTW_INFO("[rtw_wx_set_pmkid] IW_PMKSA_REMOVE!\n");
1470 		intReturn = _TRUE;
1471 		for (j = 0 ; j < NUM_PMKID_CACHE; j++) {
1472 			if (_rtw_memcmp(psecuritypriv->PMKIDList[j].Bssid, strIssueBssid, ETH_ALEN) == _TRUE) {
1473 				/* BSSID is matched, the same AP => Remove this PMKID information and reset it. */
1474 				_rtw_memset(psecuritypriv->PMKIDList[j].Bssid, 0x00, ETH_ALEN);
1475 				psecuritypriv->PMKIDList[j].bUsed = _FALSE;
1476 				break;
1477 			}
1478 		}
1479 	} else if (pPMK->cmd == IW_PMKSA_FLUSH) {
1480 		RTW_INFO("[rtw_wx_set_pmkid] IW_PMKSA_FLUSH!\n");
1481 		_rtw_memset(&psecuritypriv->PMKIDList[0], 0x00, sizeof(RT_PMKID_LIST) * NUM_PMKID_CACHE);
1482 		psecuritypriv->PMKIDIndex = 0;
1483 		intReturn = _TRUE;
1484 	}
1485 	return intReturn ;
1486 }
1487 
rtw_wx_get_sens(struct net_device * dev,struct iw_request_info * info,union iwreq_data * wrqu,char * extra)1488 static int rtw_wx_get_sens(struct net_device *dev,
1489 			   struct iw_request_info *info,
1490 			   union iwreq_data *wrqu, char *extra)
1491 {
1492 #ifdef CONFIG_PLATFORM_ROCKCHIPS
1493 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1494 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
1495 
1496 	/*
1497 	*  20110311 Commented by Jeff
1498 	*  For rockchip platform's wpa_driver_wext_get_rssi
1499 	*/
1500 	if (check_fwstate(pmlmepriv, WIFI_ASOC_STATE) == _TRUE) {
1501 		/* wrqu->sens.value=-padapter->recvinfo.signal_strength; */
1502 		wrqu->sens.value = -padapter->recvinfo.rssi;
1503 		/* RTW_INFO("%s: %d\n", __FUNCTION__, wrqu->sens.value); */
1504 		wrqu->sens.fixed = 0; /* no auto select */
1505 	} else
1506 #endif
1507 	{
1508 		wrqu->sens.value = 0;
1509 		wrqu->sens.fixed = 0;	/* no auto select */
1510 		wrqu->sens.disabled = 1;
1511 	}
1512 	return 0;
1513 }
1514 
rtw_wx_get_range(struct net_device * dev,struct iw_request_info * info,union iwreq_data * wrqu,char * extra)1515 static int rtw_wx_get_range(struct net_device *dev,
1516 			    struct iw_request_info *info,
1517 			    union iwreq_data *wrqu, char *extra)
1518 {
1519 	struct iw_range *range = (struct iw_range *)extra;
1520 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1521 	struct rf_ctl_t *rfctl = adapter_to_rfctl(padapter);
1522 	u16 val;
1523 	int i;
1524 
1525 
1526 
1527 	wrqu->data.length = sizeof(*range);
1528 	_rtw_memset(range, 0, sizeof(*range));
1529 
1530 	/* Let's try to keep this struct in the same order as in
1531 	 * linux/include/wireless.h
1532 	 */
1533 
1534 	/* TODO: See what values we can set, and remove the ones we can't
1535 	 * set, or fill them with some default data.
1536 	 */
1537 
1538 	/* ~5 Mb/s real (802.11b) */
1539 	range->throughput = 5 * 1000 * 1000;
1540 
1541 	/* TODO: Not used in 802.11b?
1542 	*	range->min_nwid;	 Minimal NWID we are able to set  */
1543 	/* TODO: Not used in 802.11b?
1544 	*	range->max_nwid;	 Maximal NWID we are able to set  */
1545 
1546 	/* Old Frequency (backward compat - moved lower ) */
1547 	/*	range->old_num_channels;
1548 	 *	range->old_num_frequency;
1549 	 * 	range->old_freq[6];  Filler to keep "version" at the same offset  */
1550 
1551 	/* signal level threshold range */
1552 
1553 	/* Quality of link & SNR stuff */
1554 	/* Quality range (link, level, noise)
1555 	 * If the quality is absolute, it will be in the range [0 ; max_qual],
1556 	 * if the quality is dBm, it will be in the range [max_qual ; 0].
1557 	 * Don't forget that we use 8 bit arithmetics...
1558 	 *
1559 	 * If percentage range is 0~100
1560 	 * Signal strength dbm range logical is -100 ~ 0
1561 	 * but usually value is -90 ~ -20
1562 	 */
1563 	range->max_qual.qual = 100;
1564 #ifdef CONFIG_SIGNAL_DISPLAY_DBM
1565 	range->max_qual.level = (u8)-100;
1566 	range->max_qual.noise = (u8)-100;
1567 	range->max_qual.updated = IW_QUAL_ALL_UPDATED; /* Updated all three */
1568 	range->max_qual.updated |= IW_QUAL_DBM;
1569 #else /* !CONFIG_SIGNAL_DISPLAY_DBM */
1570 	/* percent values between 0 and 100. */
1571 	range->max_qual.level = 100;
1572 	range->max_qual.noise = 100;
1573 	range->max_qual.updated = IW_QUAL_ALL_UPDATED; /* Updated all three */
1574 #endif /* !CONFIG_SIGNAL_DISPLAY_DBM */
1575 
1576 	/* This should contain the average/typical values of the quality
1577 	 * indicator. This should be the threshold between a "good" and
1578 	 * a "bad" link (example : monitor going from green to orange).
1579 	 * Currently, user space apps like quality monitors don't have any
1580 	 * way to calibrate the measurement. With this, they can split
1581 	 * the range between 0 and max_qual in different quality level
1582 	 * (using a geometric subdivision centered on the average).
1583 	 * I expect that people doing the user space apps will feedback
1584 	 * us on which value we need to put in each driver... */
1585 	range->avg_qual.qual = 92; /* > 8% missed beacons is 'bad' */
1586 #ifdef CONFIG_SIGNAL_DISPLAY_DBM
1587 	/* TODO: Find real 'good' to 'bad' threshold value for RSSI */
1588 	range->avg_qual.level = (u8)-70;
1589 	range->avg_qual.noise = 0;
1590 	range->avg_qual.updated = IW_QUAL_ALL_UPDATED; /* Updated all three */
1591 	range->avg_qual.updated |= IW_QUAL_DBM;
1592 #else /* !CONFIG_SIGNAL_DISPLAY_DBM */
1593 	/* TODO: Find real 'good' to 'bad' threshol value for RSSI */
1594 	range->avg_qual.level = 30;
1595 	range->avg_qual.noise = 100;
1596 	range->avg_qual.updated = IW_QUAL_ALL_UPDATED; /* Updated all three */
1597 #endif /* !CONFIG_SIGNAL_DISPLAY_DBM */
1598 
1599 	range->num_bitrates = RATE_COUNT;
1600 
1601 	for (i = 0; i < RATE_COUNT && i < IW_MAX_BITRATES; i++)
1602 		range->bitrate[i] = rtw_rates[i];
1603 
1604 	range->min_frag = MIN_FRAG_THRESHOLD;
1605 	range->max_frag = MAX_FRAG_THRESHOLD;
1606 
1607 	range->pm_capa = 0;
1608 
1609 	range->we_version_compiled = WIRELESS_EXT;
1610 	range->we_version_source = 16;
1611 
1612 	/*	range->retry_capa;	 What retry options are supported
1613 	 *	range->retry_flags;	 How to decode max/min retry limit
1614 	 *	range->r_time_flags;	 How to decode max/min retry life
1615 	 *	range->min_retry;	 Minimal number of retries
1616 	 *	range->max_retry;	 Maximal number of retries
1617 	 *	range->min_r_time;	 Minimal retry lifetime
1618 	 *	range->max_r_time;	 Maximal retry lifetime  */
1619 
1620 	for (i = 0, val = 0; i < rfctl->max_chan_nums; i++) {
1621 
1622 		/* Include only legal frequencies for some countries */
1623 		if (rfctl->channel_set[i].ChannelNum != 0) {
1624 			range->freq[val].i = rfctl->channel_set[i].ChannelNum;
1625 			range->freq[val].m = rtw_ch2freq(rfctl->channel_set[i].ChannelNum) * 100000;
1626 			range->freq[val].e = 1;
1627 			val++;
1628 		}
1629 
1630 		if (val == IW_MAX_FREQUENCIES)
1631 			break;
1632 	}
1633 
1634 	range->num_channels = val;
1635 	range->num_frequency = val;
1636 
1637 	/* Commented by Albert 2009/10/13
1638 	 * The following code will proivde the security capability to network manager.
1639 	 * If the driver doesn't provide this capability to network manager,
1640 	 * the WPA/WPA2 routers can't be choosen in the network manager. */
1641 
1642 	/*
1643 	#define IW_SCAN_CAPA_NONE		0x00
1644 	#define IW_SCAN_CAPA_ESSID		0x01
1645 	#define IW_SCAN_CAPA_BSSID		0x02
1646 	#define IW_SCAN_CAPA_CHANNEL	0x04
1647 	#define IW_SCAN_CAPA_MODE		0x08
1648 	#define IW_SCAN_CAPA_RATE		0x10
1649 	#define IW_SCAN_CAPA_TYPE		0x20
1650 	#define IW_SCAN_CAPA_TIME		0x40
1651 	*/
1652 
1653 #if WIRELESS_EXT > 17
1654 	range->enc_capa = IW_ENC_CAPA_WPA | IW_ENC_CAPA_WPA2 |
1655 			  IW_ENC_CAPA_CIPHER_TKIP | IW_ENC_CAPA_CIPHER_CCMP;
1656 #endif
1657 
1658 #ifdef IW_SCAN_CAPA_ESSID /* WIRELESS_EXT > 21 */
1659 	range->scan_capa = IW_SCAN_CAPA_ESSID | IW_SCAN_CAPA_TYPE | IW_SCAN_CAPA_BSSID |
1660 		   IW_SCAN_CAPA_CHANNEL | IW_SCAN_CAPA_MODE | IW_SCAN_CAPA_RATE;
1661 #endif
1662 
1663 
1664 
1665 	return 0;
1666 
1667 }
1668 
1669 /* set bssid flow
1670  * s1. rtw_set_802_11_infrastructure_mode()
1671  * s2. rtw_set_802_11_authentication_mode()
1672  * s3. set_802_11_encryption_mode()
1673  * s4. rtw_set_802_11_bssid() */
rtw_wx_set_wap(struct net_device * dev,struct iw_request_info * info,union iwreq_data * awrq,char * extra)1674 static int rtw_wx_set_wap(struct net_device *dev,
1675 			  struct iw_request_info *info,
1676 			  union iwreq_data *awrq,
1677 			  char *extra)
1678 {
1679 	uint ret = 0;
1680 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1681 	struct sockaddr *temp = (struct sockaddr *)awrq;
1682 	struct	mlme_priv	*pmlmepriv = &(padapter->mlmepriv);
1683 	_list	*phead;
1684 	u8 *dst_bssid, *src_bssid;
1685 	_queue	*queue	= &(pmlmepriv->scanned_queue);
1686 	struct	wlan_network	*pnetwork = NULL;
1687 	NDIS_802_11_AUTHENTICATION_MODE	authmode;
1688 
1689 	/*
1690 	#ifdef CONFIG_CONCURRENT_MODE
1691 		if(padapter->adapter_type > PRIMARY_IFACE)
1692 		{
1693 			ret = -EINVAL;
1694 			goto exit;
1695 		}
1696 	#endif
1697 	*/
1698 
1699 #ifdef CONFIG_CONCURRENT_MODE
1700 	if (rtw_mi_buddy_check_fwstate(padapter, WIFI_UNDER_SURVEY | WIFI_UNDER_LINKING) == _TRUE) {
1701 		RTW_INFO("set bssid, but buddy_intf is under scanning or linking\n");
1702 
1703 		ret = -EINVAL;
1704 
1705 		goto exit;
1706 	}
1707 #endif
1708 
1709 	rtw_ps_deny(padapter, PS_DENY_JOIN);
1710 	if (_FAIL == rtw_pwr_wakeup(padapter)) {
1711 		ret = -1;
1712 		goto cancel_ps_deny;
1713 	}
1714 
1715 	if (!padapter->netif_up) {
1716 		ret = -1;
1717 		goto cancel_ps_deny;
1718 	}
1719 
1720 
1721 	if (temp->sa_family != ARPHRD_ETHER) {
1722 		ret = -EINVAL;
1723 		goto cancel_ps_deny;
1724 	}
1725 
1726 	authmode = padapter->securitypriv.ndisauthtype;
1727 	_rtw_spinlock_bh(&queue->lock);
1728 	phead = get_list_head(queue);
1729 	pmlmepriv->pscanned = get_next(phead);
1730 
1731 	while (1) {
1732 
1733 		if ((rtw_end_of_queue_search(phead, pmlmepriv->pscanned)) == _TRUE) {
1734 #if 0
1735 			ret = -EINVAL;
1736 			goto cancel_ps_deny;
1737 
1738 			if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE) {
1739 				rtw_set_802_11_bssid(padapter, temp->sa_data);
1740 				goto cancel_ps_deny;
1741 			} else {
1742 				ret = -EINVAL;
1743 				goto cancel_ps_deny;
1744 			}
1745 #endif
1746 
1747 			break;
1748 		}
1749 
1750 		pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
1751 
1752 		pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
1753 
1754 		dst_bssid = pnetwork->network.MacAddress;
1755 
1756 		src_bssid = temp->sa_data;
1757 
1758 		if ((_rtw_memcmp(dst_bssid, src_bssid, ETH_ALEN)) == _TRUE) {
1759 			if (!rtw_set_802_11_infrastructure_mode(padapter, pnetwork->network.InfrastructureMode, 0)) {
1760 				ret = -1;
1761 				_rtw_spinunlock_bh(&queue->lock);
1762 				goto cancel_ps_deny;
1763 			}
1764 
1765 			break;
1766 		}
1767 
1768 	}
1769 	_rtw_spinunlock_bh(&queue->lock);
1770 
1771 	rtw_set_802_11_authentication_mode(padapter, authmode);
1772 	/* set_802_11_encryption_mode(padapter, padapter->securitypriv.ndisencryptstatus); */
1773 	if (rtw_set_802_11_bssid(padapter, temp->sa_data) == _FALSE) {
1774 		ret = -1;
1775 		goto cancel_ps_deny;
1776 	}
1777 
1778 cancel_ps_deny:
1779 	rtw_ps_deny_cancel(padapter, PS_DENY_JOIN);
1780 
1781 #ifdef CONFIG_CONCURRENT_MODE
1782 exit:
1783 #endif
1784 	return ret;
1785 }
1786 
rtw_wx_get_wap(struct net_device * dev,struct iw_request_info * info,union iwreq_data * wrqu,char * extra)1787 static int rtw_wx_get_wap(struct net_device *dev,
1788 			  struct iw_request_info *info,
1789 			  union iwreq_data *wrqu, char *extra)
1790 {
1791 
1792 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1793 	struct	mlme_priv	*pmlmepriv = &(padapter->mlmepriv);
1794 	WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
1795 
1796 	wrqu->ap_addr.sa_family = ARPHRD_ETHER;
1797 
1798 	_rtw_memset(wrqu->ap_addr.sa_data, 0, ETH_ALEN);
1799 
1800 
1801 
1802 	if (((check_fwstate(pmlmepriv, WIFI_ASOC_STATE)) == _TRUE) ||
1803 	    ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == _TRUE) ||
1804 	    ((check_fwstate(pmlmepriv, WIFI_AP_STATE)) == _TRUE))
1805 
1806 		_rtw_memcpy(wrqu->ap_addr.sa_data, pcur_bss->MacAddress, ETH_ALEN);
1807 	else
1808 		_rtw_memset(wrqu->ap_addr.sa_data, 0, ETH_ALEN);
1809 
1810 
1811 	return 0;
1812 
1813 }
1814 
rtw_wx_set_mlme(struct net_device * dev,struct iw_request_info * info,union iwreq_data * wrqu,char * extra)1815 static int rtw_wx_set_mlme(struct net_device *dev,
1816 			   struct iw_request_info *info,
1817 			   union iwreq_data *wrqu, char *extra)
1818 {
1819 #if 0
1820 	/* SIOCSIWMLME data */
1821 	struct	iw_mlme {
1822 		__u16		cmd; /* IW_MLME_* */
1823 		__u16		reason_code;
1824 		struct sockaddr	addr;
1825 	};
1826 #endif
1827 
1828 	int ret = 0;
1829 	u16 reason;
1830 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1831 	struct iw_mlme *mlme = (struct iw_mlme *) extra;
1832 
1833 
1834 	if (mlme == NULL)
1835 		return -1;
1836 
1837 	RTW_INFO("%s\n", __FUNCTION__);
1838 
1839 	reason = cpu_to_le16(mlme->reason_code);
1840 
1841 
1842 	RTW_INFO("%s, cmd=%d, reason=%d\n", __FUNCTION__, mlme->cmd, reason);
1843 
1844 
1845 	switch (mlme->cmd) {
1846 	case IW_MLME_DEAUTH:
1847 		if (!rtw_set_802_11_disassociate(padapter))
1848 			ret = -1;
1849 		break;
1850 
1851 	case IW_MLME_DISASSOC:
1852 		if (!rtw_set_802_11_disassociate(padapter))
1853 			ret = -1;
1854 
1855 		break;
1856 
1857 	default:
1858 		return -EOPNOTSUPP;
1859 	}
1860 	return ret;
1861 }
1862 
rtw_wx_set_scan(struct net_device * dev,struct iw_request_info * a,union iwreq_data * wrqu,char * extra)1863 static int rtw_wx_set_scan(struct net_device *dev, struct iw_request_info *a,
1864 			   union iwreq_data *wrqu, char *extra)
1865 {
1866 	u8 _status = _FALSE;
1867 	int ret = 0;
1868 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1869 	/*struct mlme_priv *pmlmepriv = &padapter->mlmepriv;*/
1870 	struct sitesurvey_parm parm;
1871 	u8 ssc_chk;
1872 #ifdef CONFIG_P2P
1873 	struct wifidirect_info *pwdinfo = &(padapter->wdinfo);
1874 #endif /* CONFIG_P2P */
1875 
1876 #ifdef DBG_IOCTL
1877 	RTW_INFO("DBG_IOCTL %s:%d\n", __FUNCTION__, __LINE__);
1878 #endif
1879 
1880 #if 1
1881 	ssc_chk = rtw_sitesurvey_condition_check(padapter, _FALSE);
1882 
1883 	#ifdef CONFIG_DOSCAN_IN_BUSYTRAFFIC
1884 	if ((ssc_chk != SS_ALLOW) && (ssc_chk != SS_DENY_BUSY_TRAFFIC))
1885 	#else
1886 	/* When Busy Traffic, driver do not site survey. So driver return success. */
1887 	/* wpa_supplicant will not issue SIOCSIWSCAN cmd again after scan timeout. */
1888 	/* modify by thomas 2011-02-22. */
1889 	if (ssc_chk != SS_ALLOW)
1890 	#endif
1891 	{
1892 		if (ssc_chk == SS_DENY_MP_MODE)
1893 			ret = -EPERM;
1894 		#ifdef DBG_LA_MODE
1895 		else if (ssc_chk == SS_DENY_LA_MODE)
1896 			ret = -EPERM;
1897 		#endif
1898 		else
1899 			indicate_wx_scan_complete_event(padapter);
1900 
1901 		goto exit;
1902 	} else
1903 		RTW_INFO(FUNC_ADPT_FMT"\n", FUNC_ADPT_ARG(padapter));
1904 
1905 	rtw_ps_deny(padapter, PS_DENY_SCAN);
1906 	if (_FAIL == rtw_pwr_wakeup(padapter)) {
1907 		ret = -1;
1908 		goto cancel_ps_deny;
1909 	}
1910 	if (!rtw_is_adapter_up(padapter)) {
1911 		ret = -1;
1912 		goto cancel_ps_deny;
1913 	}
1914 #else
1915 
1916 #ifdef CONFIG_MP_INCLUDED
1917 	if (rtw_mp_mode_check(padapter)) {
1918 		RTW_INFO("MP mode block Scan request\n");
1919 		ret = -EPERM;
1920 		goto exit;
1921 	}
1922 #endif
1923 	if (rtw_is_scan_deny(padapter)) {
1924 		indicate_wx_scan_complete_event(padapter);
1925 		goto exit;
1926 	}
1927 
1928 	rtw_ps_deny(padapter, PS_DENY_SCAN);
1929 	if (_FAIL == rtw_pwr_wakeup(padapter)) {
1930 		ret = -1;
1931 		goto cancel_ps_deny;
1932 	}
1933 
1934 	if (!rtw_is_adapter_up(padapter)) {
1935 		ret = -1;
1936 		goto cancel_ps_deny;
1937 	}
1938 
1939 #ifndef CONFIG_DOSCAN_IN_BUSYTRAFFIC
1940 	/* When Busy Traffic, driver do not site survey. So driver return success. */
1941 	/* wpa_supplicant will not issue SIOCSIWSCAN cmd again after scan timeout. */
1942 	/* modify by thomas 2011-02-22. */
1943 	if (rtw_mi_busy_traffic_check(padapter)) {
1944 		indicate_wx_scan_complete_event(padapter);
1945 		goto cancel_ps_deny;
1946 	}
1947 #endif
1948 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE) && check_fwstate(pmlmepriv, WIFI_UNDER_WPS)) {
1949 		RTW_INFO("AP mode process WPS\n");
1950 		indicate_wx_scan_complete_event(padapter);
1951 		goto cancel_ps_deny;
1952 	}
1953 
1954 	if (check_fwstate(pmlmepriv, WIFI_UNDER_SURVEY | WIFI_UNDER_LINKING) == _TRUE) {
1955 		indicate_wx_scan_complete_event(padapter);
1956 		goto cancel_ps_deny;
1957 	}
1958 
1959 #ifdef CONFIG_CONCURRENT_MODE
1960 	if (rtw_mi_buddy_check_fwstate(padapter,
1961 		       WIFI_UNDER_SURVEY | WIFI_UNDER_LINKING | WIFI_UNDER_WPS)) {
1962 
1963 		indicate_wx_scan_complete_event(padapter);
1964 		goto cancel_ps_deny;
1965 	}
1966 #endif
1967 #endif
1968 
1969 #if WIRELESS_EXT >= 17
1970 	if (wrqu->data.length == sizeof(struct iw_scan_req)) {
1971 		struct iw_scan_req *req = (struct iw_scan_req *)extra;
1972 
1973 		if (wrqu->data.flags & IW_SCAN_THIS_ESSID) {
1974 			int len = min((int)req->essid_len, IW_ESSID_MAX_SIZE);
1975 
1976 			rtw_init_sitesurvey_parm(padapter, &parm);
1977 			_rtw_memcpy(&parm.ssid[0].Ssid, &req->essid, len);
1978 			parm.ssid[0].SsidLength = len;
1979 			parm.ssid_num = 1;
1980 
1981 			RTW_INFO("IW_SCAN_THIS_ESSID, ssid=%s, len=%d\n", req->essid, req->essid_len);
1982 
1983 			_status = rtw_sitesurvey_cmd(padapter, &parm);
1984 
1985 		} else if (req->scan_type == IW_SCAN_TYPE_PASSIVE)
1986 			RTW_INFO("rtw_wx_set_scan, req->scan_type == IW_SCAN_TYPE_PASSIVE\n");
1987 
1988 	} else
1989 #endif
1990 
1991 		if (wrqu->data.length >= WEXT_CSCAN_HEADER_SIZE
1992 		    && _rtw_memcmp(extra, WEXT_CSCAN_HEADER, WEXT_CSCAN_HEADER_SIZE) == _TRUE
1993 		   ) {
1994 			int len = wrqu->data.length - WEXT_CSCAN_HEADER_SIZE;
1995 			char *pos = extra + WEXT_CSCAN_HEADER_SIZE;
1996 			char section;
1997 			char sec_len;
1998 			int ssid_index = 0;
1999 
2000 			/* RTW_INFO("%s COMBO_SCAN header is recognized\n", __FUNCTION__); */
2001 			rtw_init_sitesurvey_parm(padapter, &parm);
2002 
2003 			while (len >= 1) {
2004 				section = *(pos++);
2005 				len -= 1;
2006 
2007 				switch (section) {
2008 				case WEXT_CSCAN_SSID_SECTION:
2009 					/* RTW_INFO("WEXT_CSCAN_SSID_SECTION\n"); */
2010 					if (len < 1) {
2011 						len = 0;
2012 						break;
2013 					}
2014 
2015 					sec_len = *(pos++);
2016 					len -= 1;
2017 
2018 					if (sec_len > 0 && sec_len <= len) {
2019 
2020 						parm.ssid[ssid_index].SsidLength = sec_len;
2021 						_rtw_memcpy(&parm.ssid[ssid_index].Ssid, pos, sec_len);
2022 
2023 						/* RTW_INFO("%s COMBO_SCAN with specific parm.ssid:%s, %d\n", __FUNCTION__ */
2024 						/*	, parm.ssid[ssid_index].Ssid, parm.ssid[ssid_index].SsidLength); */
2025 						ssid_index++;
2026 					}
2027 
2028 					pos += sec_len;
2029 					len -= sec_len;
2030 					break;
2031 
2032 
2033 				case WEXT_CSCAN_CHANNEL_SECTION:
2034 					/* RTW_INFO("WEXT_CSCAN_CHANNEL_SECTION\n"); */
2035 					pos += 1;
2036 					len -= 1;
2037 					break;
2038 				case WEXT_CSCAN_ACTV_DWELL_SECTION:
2039 					/* RTW_INFO("WEXT_CSCAN_ACTV_DWELL_SECTION\n"); */
2040 					pos += 2;
2041 					len -= 2;
2042 					break;
2043 				case WEXT_CSCAN_PASV_DWELL_SECTION:
2044 					/* RTW_INFO("WEXT_CSCAN_PASV_DWELL_SECTION\n"); */
2045 					pos += 2;
2046 					len -= 2;
2047 					break;
2048 				case WEXT_CSCAN_HOME_DWELL_SECTION:
2049 					/* RTW_INFO("WEXT_CSCAN_HOME_DWELL_SECTION\n"); */
2050 					pos += 2;
2051 					len -= 2;
2052 					break;
2053 				case WEXT_CSCAN_TYPE_SECTION:
2054 					/* RTW_INFO("WEXT_CSCAN_TYPE_SECTION\n"); */
2055 					pos += 1;
2056 					len -= 1;
2057 					break;
2058 #if 0
2059 				case WEXT_CSCAN_NPROBE_SECTION:
2060 					RTW_INFO("WEXT_CSCAN_NPROBE_SECTION\n");
2061 					break;
2062 #endif
2063 
2064 				default:
2065 					/* RTW_INFO("Unknown CSCAN section %c\n", section); */
2066 					len = 0; /* stop parsing */
2067 				}
2068 				/* RTW_INFO("len:%d\n", len); */
2069 
2070 			}
2071 			parm.ssid_num = ssid_index;
2072 
2073 			/* jeff: it has still some scan paramater to parse, we only do this now... */
2074 			_status = rtw_sitesurvey_cmd(padapter, &parm);
2075 
2076 		} else
2077 
2078 			_status = rtw_sitesurvey_cmd(padapter, NULL);
2079 
2080 	if (_status == _FALSE)
2081 		ret = -1;
2082 
2083 cancel_ps_deny:
2084 	rtw_ps_deny_cancel(padapter, PS_DENY_SCAN);
2085 
2086 exit:
2087 #ifdef DBG_IOCTL
2088 	RTW_INFO("DBG_IOCTL %s:%d return %d\n", __FUNCTION__, __LINE__, ret);
2089 #endif
2090 
2091 	return ret;
2092 }
2093 
rtw_wx_get_scan(struct net_device * dev,struct iw_request_info * a,union iwreq_data * wrqu,char * extra)2094 static int rtw_wx_get_scan(struct net_device *dev, struct iw_request_info *a,
2095 			   union iwreq_data *wrqu, char *extra)
2096 {
2097 	_list					*plist, *phead;
2098 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2099 	struct rf_ctl_t *rfctl = adapter_to_rfctl(padapter);
2100 	RT_CHANNEL_INFO *chset = rfctl->channel_set;
2101 	struct	mlme_priv	*pmlmepriv = &(padapter->mlmepriv);
2102 	_queue				*queue	= &(pmlmepriv->scanned_queue);
2103 	struct	wlan_network	*pnetwork = NULL;
2104 	char *ev = extra;
2105 	char *stop = ev + wrqu->data.length;
2106 	u32 ret = 0;
2107 	u32 wait_for_surveydone;
2108 	sint wait_status;
2109 	u8 ch;
2110 
2111 #ifdef CONFIG_P2P
2112 	struct	wifidirect_info	*pwdinfo = &padapter->wdinfo;
2113 #endif /* CONFIG_P2P */
2114 
2115 
2116 #ifdef DBG_IOCTL
2117 	RTW_INFO("DBG_IOCTL %s:%d\n", __FUNCTION__, __LINE__);
2118 #endif
2119 
2120 	if (adapter_to_pwrctl(padapter)->brfoffbyhw && dev_is_drv_stopped(adapter_to_dvobj(padapter))) {
2121 		ret = -EINVAL;
2122 		goto exit;
2123 	}
2124 
2125 	wait_for_surveydone = 100;
2126 
2127 #if 1 /* Wireless Extension use EAGAIN to try */
2128 	wait_status = WIFI_UNDER_SURVEY
2129 #ifndef CONFIG_RTW_ANDROID
2130 		      | WIFI_UNDER_LINKING
2131 #endif
2132 		      ;
2133 
2134 	while (check_fwstate(pmlmepriv, wait_status) == _TRUE)
2135 		return -EAGAIN;
2136 #else
2137 	wait_status = WIFI_UNDER_SURVEY
2138 #ifndef CONFIG_RTW_ANDROID
2139 		      | WIFI_UNDER_LINKING
2140 #endif
2141 		      ;
2142 
2143 	while (check_fwstate(pmlmepriv, wait_status) == _TRUE) {
2144 		rtw_msleep_os(30);
2145 		cnt++;
2146 		if (cnt > wait_for_surveydone)
2147 			break;
2148 	}
2149 #endif
2150 	_rtw_spinlock_bh(&(pmlmepriv->scanned_queue.lock));
2151 
2152 	phead = get_list_head(queue);
2153 	plist = get_next(phead);
2154 
2155 	while (1) {
2156 		if (rtw_end_of_queue_search(phead, plist) == _TRUE)
2157 			break;
2158 
2159 		if ((stop - ev) < SCAN_ITEM_SIZE) {
2160 			if(wrqu->data.length == MAX_SCAN_BUFFER_LEN){ /*max buffer len defined by iwlist*/
2161 				ret = 0;
2162 				RTW_INFO("%s: Scan results incomplete\n", __FUNCTION__);
2163 				break;
2164 			}
2165 			ret = -E2BIG;
2166 			break;
2167 		}
2168 
2169 		pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
2170 		ch = pnetwork->network.Configuration.DSConfig;
2171 
2172 		/* report network only if the current channel set contains the channel to which this network belongs */
2173 		if (rtw_chset_search_ch(chset, ch) >= 0
2174 			&& rtw_mlme_band_check(padapter, ch) == _TRUE
2175 			&& _TRUE == rtw_validate_ssid(&(pnetwork->network.Ssid))
2176 			&& (!IS_DFS_SLAVE_WITH_RD(rfctl)
2177 				|| rtw_rfctl_dfs_domain_unknown(rfctl)
2178 				|| !rtw_chset_is_ch_non_ocp(chset, ch))
2179 		)
2180 			ev = translate_scan(padapter, a, pnetwork, ev, stop);
2181 
2182 		plist = get_next(plist);
2183 
2184 	}
2185 
2186 	_rtw_spinunlock_bh(&(pmlmepriv->scanned_queue.lock));
2187 
2188 	wrqu->data.length = ev - extra;
2189 	wrqu->data.flags = 0;
2190 
2191 exit:
2192 
2193 
2194 #ifdef DBG_IOCTL
2195 	RTW_INFO("DBG_IOCTL %s:%d return %d\n", __FUNCTION__, __LINE__, ret);
2196 #endif
2197 
2198 	return ret ;
2199 
2200 }
2201 
2202 /* set ssid flow
2203  * s1. rtw_set_802_11_infrastructure_mode()
2204  * s2. set_802_11_authenticaion_mode()
2205  * s3. set_802_11_encryption_mode()
2206  * s4. rtw_set_802_11_ssid() */
rtw_wx_set_essid(struct net_device * dev,struct iw_request_info * a,union iwreq_data * wrqu,char * extra)2207 static int rtw_wx_set_essid(struct net_device *dev,
2208 			    struct iw_request_info *a,
2209 			    union iwreq_data *wrqu, char *extra)
2210 {
2211 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2212 	struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2213 	_queue *queue = &pmlmepriv->scanned_queue;
2214 	_list *phead;
2215 	struct wlan_network *pnetwork = NULL;
2216 	NDIS_802_11_AUTHENTICATION_MODE authmode;
2217 	NDIS_802_11_SSID ndis_ssid;
2218 	u8 *dst_ssid, *src_ssid;
2219 
2220 	uint ret = 0, len;
2221 
2222 
2223 #ifdef DBG_IOCTL
2224 	RTW_INFO("DBG_IOCTL %s:%d\n", __FUNCTION__, __LINE__);
2225 #endif
2226 #ifdef CONFIG_WEXT_DONT_JOIN_BYSSID
2227 	RTW_INFO("%s: CONFIG_WEXT_DONT_JOIN_BYSSID be defined!! only allow bssid joining\n", __func__);
2228 	return -EPERM;
2229 #endif
2230 
2231 #if WIRELESS_EXT <= 20
2232 	if ((wrqu->essid.length - 1) > IW_ESSID_MAX_SIZE) {
2233 #else
2234 	if (wrqu->essid.length > IW_ESSID_MAX_SIZE) {
2235 #endif
2236 		ret = -E2BIG;
2237 		goto exit;
2238 	}
2239 
2240 
2241 
2242 	rtw_ps_deny(padapter, PS_DENY_JOIN);
2243 	if (_FAIL == rtw_pwr_wakeup(padapter)) {
2244 		ret = -1;
2245 		goto cancel_ps_deny;
2246 	}
2247 
2248 	if (!padapter->netif_up) {
2249 		ret = -1;
2250 		goto cancel_ps_deny;
2251 	}
2252 
2253 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
2254 		ret = -1;
2255 		goto cancel_ps_deny;
2256 	}
2257 
2258 #ifdef CONFIG_CONCURRENT_MODE
2259 	if (rtw_mi_buddy_check_fwstate(padapter, WIFI_UNDER_SURVEY | WIFI_UNDER_LINKING)) {
2260 		RTW_INFO("set ssid, but buddy_intf is under scanning or linking\n");
2261 		ret = -EINVAL;
2262 		goto cancel_ps_deny;
2263 	}
2264 #endif
2265 	authmode = padapter->securitypriv.ndisauthtype;
2266 	RTW_INFO("=>%s\n", __FUNCTION__);
2267 	if (wrqu->essid.flags && wrqu->essid.length) {
2268 		/* Commented by Albert 20100519 */
2269 		/* We got the codes in "set_info" function of iwconfig source code. */
2270 		/*	========================================= */
2271 		/*	wrq.u.essid.length = strlen(essid) + 1; */
2272 		/*	if(we_kernel_version > 20) */
2273 		/*		wrq.u.essid.length--; */
2274 		/*	========================================= */
2275 		/*	That means, if the WIRELESS_EXT less than or equal to 20, the correct ssid len should subtract 1. */
2276 #if WIRELESS_EXT <= 20
2277 		len = ((wrqu->essid.length - 1) < IW_ESSID_MAX_SIZE) ? (wrqu->essid.length - 1) : IW_ESSID_MAX_SIZE;
2278 #else
2279 		len = (wrqu->essid.length < IW_ESSID_MAX_SIZE) ? wrqu->essid.length : IW_ESSID_MAX_SIZE;
2280 #endif
2281 
2282 		if (wrqu->essid.length != 33)
2283 			RTW_INFO("ssid=%s, len=%d\n", extra, wrqu->essid.length);
2284 
2285 		_rtw_memset(&ndis_ssid, 0, sizeof(NDIS_802_11_SSID));
2286 		ndis_ssid.SsidLength = len;
2287 		_rtw_memcpy(ndis_ssid.Ssid, extra, len);
2288 		src_ssid = ndis_ssid.Ssid;
2289 
2290 		_rtw_spinlock_bh(&queue->lock);
2291 		phead = get_list_head(queue);
2292 		pmlmepriv->pscanned = get_next(phead);
2293 
2294 		while (1) {
2295 			if (rtw_end_of_queue_search(phead, pmlmepriv->pscanned) == _TRUE) {
2296 #if 0
2297 				if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE) {
2298 					rtw_set_802_11_ssid(padapter, &ndis_ssid);
2299 
2300 					goto cancel_ps_deny;
2301 				} else {
2302 					ret = -EINVAL;
2303 					goto cancel_ps_deny;
2304 				}
2305 #endif
2306 
2307 				break;
2308 			}
2309 
2310 			pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
2311 
2312 			pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
2313 
2314 			dst_ssid = pnetwork->network.Ssid.Ssid;
2315 
2316 
2317 			if ((_rtw_memcmp(dst_ssid, src_ssid, ndis_ssid.SsidLength) == _TRUE) &&
2318 			    (pnetwork->network.Ssid.SsidLength == ndis_ssid.SsidLength)) {
2319 
2320 				if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE) {
2321 					if (pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
2322 						continue;
2323 				}
2324 
2325 				if (rtw_set_802_11_infrastructure_mode(padapter, pnetwork->network.InfrastructureMode, 0) == _FALSE) {
2326 					ret = -1;
2327 					_rtw_spinunlock_bh(&queue->lock);
2328 					goto cancel_ps_deny;
2329 				}
2330 
2331 				break;
2332 			}
2333 		}
2334 		_rtw_spinunlock_bh(&queue->lock);
2335 		rtw_set_802_11_authentication_mode(padapter, authmode);
2336 		/* set_802_11_encryption_mode(padapter, padapter->securitypriv.ndisencryptstatus); */
2337 		if (rtw_set_802_11_ssid(padapter, &ndis_ssid) == _FALSE) {
2338 			ret = -1;
2339 			goto cancel_ps_deny;
2340 		}
2341 	}
2342 
2343 cancel_ps_deny:
2344 	rtw_ps_deny_cancel(padapter, PS_DENY_JOIN);
2345 
2346 exit:
2347 	RTW_INFO("<=%s, ret %d\n", __FUNCTION__, ret);
2348 
2349 #ifdef DBG_IOCTL
2350 	RTW_INFO("DBG_IOCTL %s:%d return %d\n", __FUNCTION__, __LINE__, ret);
2351 #endif
2352 
2353 
2354 	return ret;
2355 }
2356 
2357 static int rtw_wx_get_essid(struct net_device *dev,
2358 			    struct iw_request_info *a,
2359 			    union iwreq_data *wrqu, char *extra)
2360 {
2361 	u32 len, ret = 0;
2362 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2363 	struct	mlme_priv	*pmlmepriv = &(padapter->mlmepriv);
2364 	WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
2365 
2366 
2367 
2368 	if ((check_fwstate(pmlmepriv, WIFI_ASOC_STATE) == _TRUE) ||
2369 	    (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == _TRUE)) {
2370 		len = pcur_bss->Ssid.SsidLength;
2371 
2372 		wrqu->essid.length = len;
2373 
2374 		_rtw_memcpy(extra, pcur_bss->Ssid.Ssid, len);
2375 
2376 		wrqu->essid.flags = 1;
2377 	} else {
2378 		ret = -1;
2379 		goto exit;
2380 	}
2381 
2382 exit:
2383 
2384 
2385 	return ret;
2386 
2387 }
2388 
2389 static int rtw_wx_set_rate(struct net_device *dev,
2390 			   struct iw_request_info *a,
2391 			   union iwreq_data *wrqu, char *extra)
2392 {
2393 	int ret = 0;
2394 #if 0
2395 	int i;
2396 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2397 	u8	datarates[NumRates];
2398 	u32	target_rate = wrqu->bitrate.value;
2399 	u32	fixed = wrqu->bitrate.fixed;
2400 	u32	ratevalue = 0;
2401 	u8 mpdatarate[NumRates] = {11, 10, 9, 8, 7, 6, 5, 4, 3, 2, 1, 0, 0xff};
2402 
2403 
2404 
2405 	if (target_rate == -1) {
2406 		ratevalue = 11;
2407 		goto set_rate;
2408 	}
2409 	target_rate = target_rate / 100000;
2410 
2411 	switch (target_rate) {
2412 	case 10:
2413 		ratevalue = 0;
2414 		break;
2415 	case 20:
2416 		ratevalue = 1;
2417 		break;
2418 	case 55:
2419 		ratevalue = 2;
2420 		break;
2421 	case 60:
2422 		ratevalue = 3;
2423 		break;
2424 	case 90:
2425 		ratevalue = 4;
2426 		break;
2427 	case 110:
2428 		ratevalue = 5;
2429 		break;
2430 	case 120:
2431 		ratevalue = 6;
2432 		break;
2433 	case 180:
2434 		ratevalue = 7;
2435 		break;
2436 	case 240:
2437 		ratevalue = 8;
2438 		break;
2439 	case 360:
2440 		ratevalue = 9;
2441 		break;
2442 	case 480:
2443 		ratevalue = 10;
2444 		break;
2445 	case 540:
2446 		ratevalue = 11;
2447 		break;
2448 	default:
2449 		ratevalue = 11;
2450 		break;
2451 	}
2452 
2453 set_rate:
2454 
2455 	for (i = 0; i < NumRates; i++) {
2456 		if (ratevalue == mpdatarate[i]) {
2457 			datarates[i] = mpdatarate[i];
2458 			if (fixed == 0)
2459 				break;
2460 		} else
2461 			datarates[i] = 0xff;
2462 
2463 	}
2464 
2465 	if (rtw_setdatarate_cmd(padapter, datarates) != _SUCCESS) {
2466 		ret = -1;
2467 	}
2468 
2469 #endif
2470 	return ret;
2471 }
2472 
2473 static int rtw_wx_get_rate(struct net_device *dev,
2474 			   struct iw_request_info *info,
2475 			   union iwreq_data *wrqu, char *extra)
2476 {
2477 	u16 max_rate = 0;
2478 
2479 	max_rate = rtw_get_cur_max_rate((_adapter *)rtw_netdev_priv(dev));
2480 
2481 	if (max_rate == 0)
2482 		return -EPERM;
2483 
2484 	wrqu->bitrate.fixed = 0;	/* no auto select */
2485 	wrqu->bitrate.value = max_rate * 100000;
2486 
2487 	return 0;
2488 }
2489 
2490 static int rtw_wx_set_rts(struct net_device *dev,
2491 			  struct iw_request_info *info,
2492 			  union iwreq_data *wrqu, char *extra)
2493 {
2494 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2495 
2496 
2497 	if (wrqu->rts.disabled)
2498 		padapter->registrypriv.rts_thresh = 2347;
2499 	else {
2500 		if (wrqu->rts.value < 0 ||
2501 		    wrqu->rts.value > 2347)
2502 			return -EINVAL;
2503 
2504 		padapter->registrypriv.rts_thresh = wrqu->rts.value;
2505 	}
2506 
2507 	RTW_INFO("%s, rts_thresh=%d\n", __func__, padapter->registrypriv.rts_thresh);
2508 
2509 
2510 	return 0;
2511 
2512 }
2513 
2514 static int rtw_wx_get_rts(struct net_device *dev,
2515 			  struct iw_request_info *info,
2516 			  union iwreq_data *wrqu, char *extra)
2517 {
2518 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2519 
2520 
2521 	RTW_INFO("%s, rts_thresh=%d\n", __func__, padapter->registrypriv.rts_thresh);
2522 
2523 	wrqu->rts.value = padapter->registrypriv.rts_thresh;
2524 	wrqu->rts.fixed = 0;	/* no auto select */
2525 	/* wrqu->rts.disabled = (wrqu->rts.value == DEFAULT_RTS_THRESHOLD); */
2526 
2527 
2528 	return 0;
2529 }
2530 
2531 static int rtw_wx_set_frag(struct net_device *dev,
2532 			   struct iw_request_info *info,
2533 			   union iwreq_data *wrqu, char *extra)
2534 {
2535 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2536 
2537 
2538 	if (wrqu->frag.disabled)
2539 		padapter->xmitpriv.frag_len = MAX_FRAG_THRESHOLD;
2540 	else {
2541 		if (wrqu->frag.value < MIN_FRAG_THRESHOLD ||
2542 		    wrqu->frag.value > MAX_FRAG_THRESHOLD)
2543 			return -EINVAL;
2544 
2545 		padapter->xmitpriv.frag_len = wrqu->frag.value & ~0x1;
2546 	}
2547 
2548 	RTW_INFO("%s, frag_len=%d\n", __func__, padapter->xmitpriv.frag_len);
2549 
2550 
2551 	return 0;
2552 
2553 }
2554 
2555 static int rtw_wx_get_frag(struct net_device *dev,
2556 			   struct iw_request_info *info,
2557 			   union iwreq_data *wrqu, char *extra)
2558 {
2559 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2560 
2561 
2562 	RTW_INFO("%s, frag_len=%d\n", __func__, padapter->xmitpriv.frag_len);
2563 
2564 	wrqu->frag.value = padapter->xmitpriv.frag_len;
2565 	wrqu->frag.fixed = 0;	/* no auto select */
2566 	/* wrqu->frag.disabled = (wrqu->frag.value == DEFAULT_FRAG_THRESHOLD); */
2567 
2568 
2569 	return 0;
2570 }
2571 
2572 static int rtw_wx_get_retry(struct net_device *dev,
2573 			    struct iw_request_info *info,
2574 			    union iwreq_data *wrqu, char *extra)
2575 {
2576 	/* _adapter *padapter = (_adapter *)rtw_netdev_priv(dev); */
2577 
2578 
2579 	wrqu->retry.value = 7;
2580 	wrqu->retry.fixed = 0;	/* no auto select */
2581 	wrqu->retry.disabled = 1;
2582 
2583 	return 0;
2584 
2585 }
2586 
2587 #if 0
2588 	#define IW_ENCODE_INDEX		0x00FF	/* Token index (if needed) */
2589 	#define IW_ENCODE_FLAGS		0xFF00	/* Flags defined below */
2590 	#define IW_ENCODE_MODE		0xF000	/* Modes defined below */
2591 	#define IW_ENCODE_DISABLED	0x8000	/* Encoding disabled */
2592 	#define IW_ENCODE_ENABLED	0x0000	/* Encoding enabled */
2593 	#define IW_ENCODE_RESTRICTED	0x4000	/* Refuse non-encoded packets */
2594 	#define IW_ENCODE_OPEN		0x2000	/* Accept non-encoded packets */
2595 	#define IW_ENCODE_NOKEY		0x0800  /* Key is write only, so not present */
2596 	#define IW_ENCODE_TEMP		0x0400  /* Temporary key */
2597 	/*
2598 	iwconfig wlan0 key on->flags = 0x6001->maybe it means auto
2599 	iwconfig wlan0 key off->flags = 0x8800
2600 	iwconfig wlan0 key open->flags = 0x2800
2601 	iwconfig wlan0 key open 1234567890->flags = 0x2000
2602 	iwconfig wlan0 key restricted->flags = 0x4800
2603 	iwconfig wlan0 key open [3] 1234567890->flags = 0x2003
2604 	iwconfig wlan0 key restricted [2] 1234567890->flags = 0x4002
2605 	iwconfig wlan0 key open [3] -> flags = 0x2803
2606 	iwconfig wlan0 key restricted [2] -> flags = 0x4802
2607 	*/
2608 #endif
2609 
2610 static int rtw_wx_set_enc(struct net_device *dev,
2611 			  struct iw_request_info *info,
2612 			  union iwreq_data *wrqu, char *keybuf)
2613 {
2614 	u32 key, ret = 0;
2615 	u32 keyindex_provided;
2616 	NDIS_802_11_WEP	 wep;
2617 	NDIS_802_11_AUTHENTICATION_MODE authmode;
2618 
2619 	struct iw_point *erq = &(wrqu->encoding);
2620 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2621 	struct pwrctrl_priv *pwrpriv = adapter_to_pwrctl(padapter);
2622 	RTW_INFO("+rtw_wx_set_enc, flags=0x%x\n", erq->flags);
2623 
2624 	_rtw_memset(&wep, 0, sizeof(NDIS_802_11_WEP));
2625 
2626 	key = erq->flags & IW_ENCODE_INDEX;
2627 
2628 
2629 	if (erq->flags & IW_ENCODE_DISABLED) {
2630 		RTW_INFO("EncryptionDisabled\n");
2631 		padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
2632 		padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
2633 		padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
2634 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open; /* open system */
2635 		authmode = Ndis802_11AuthModeOpen;
2636 		padapter->securitypriv.ndisauthtype = authmode;
2637 
2638 		goto exit;
2639 	}
2640 
2641 	if (key) {
2642 		if (key > WEP_KEYS)
2643 			return -EINVAL;
2644 		key--;
2645 		keyindex_provided = 1;
2646 	} else {
2647 		keyindex_provided = 0;
2648 		key = padapter->securitypriv.dot11PrivacyKeyIndex;
2649 		RTW_INFO("rtw_wx_set_enc, key=%d\n", key);
2650 	}
2651 
2652 	/* set authentication mode	 */
2653 	if (erq->flags & IW_ENCODE_OPEN) {
2654 		RTW_INFO("rtw_wx_set_enc():IW_ENCODE_OPEN\n");
2655 		padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;/* Ndis802_11EncryptionDisabled; */
2656 
2657 #ifdef CONFIG_PLATFORM_MT53XX
2658 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
2659 #else
2660 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
2661 #endif
2662 
2663 		padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
2664 		padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
2665 		authmode = Ndis802_11AuthModeOpen;
2666 		padapter->securitypriv.ndisauthtype = authmode;
2667 	} else if (erq->flags & IW_ENCODE_RESTRICTED) {
2668 		RTW_INFO("rtw_wx_set_enc():IW_ENCODE_RESTRICTED\n");
2669 		padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
2670 
2671 #ifdef CONFIG_PLATFORM_MT53XX
2672 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
2673 #else
2674 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Shared;
2675 #endif
2676 
2677 		padapter->securitypriv.dot11PrivacyAlgrthm = _WEP40_;
2678 		padapter->securitypriv.dot118021XGrpPrivacy = _WEP40_;
2679 		authmode = Ndis802_11AuthModeShared;
2680 		padapter->securitypriv.ndisauthtype = authmode;
2681 	} else {
2682 		RTW_INFO("rtw_wx_set_enc():erq->flags=0x%x\n", erq->flags);
2683 
2684 		padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;/* Ndis802_11EncryptionDisabled; */
2685 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open; /* open system */
2686 		padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
2687 		padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
2688 		authmode = Ndis802_11AuthModeOpen;
2689 		padapter->securitypriv.ndisauthtype = authmode;
2690 	}
2691 
2692 	wep.KeyIndex = key;
2693 	if (erq->length > 0) {
2694 		wep.KeyLength = erq->length <= 5 ? 5 : 13;
2695 
2696 		wep.Length = wep.KeyLength + FIELD_OFFSET(NDIS_802_11_WEP, KeyMaterial);
2697 	} else {
2698 		wep.KeyLength = 0 ;
2699 
2700 		if (keyindex_provided == 1) { /* set key_id only, no given KeyMaterial(erq->length==0). */
2701 			padapter->securitypriv.dot11PrivacyKeyIndex = key;
2702 
2703 			RTW_INFO("(keyindex_provided == 1), keyid=%d, key_len=%d\n", key, padapter->securitypriv.dot11DefKeylen[key]);
2704 
2705 			switch (padapter->securitypriv.dot11DefKeylen[key]) {
2706 			case 5:
2707 				padapter->securitypriv.dot11PrivacyAlgrthm = _WEP40_;
2708 				break;
2709 			case 13:
2710 				padapter->securitypriv.dot11PrivacyAlgrthm = _WEP104_;
2711 				break;
2712 			default:
2713 				padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
2714 				break;
2715 			}
2716 
2717 			goto exit;
2718 
2719 		}
2720 
2721 	}
2722 
2723 	wep.KeyIndex |= 0x80000000;
2724 
2725 	_rtw_memcpy(wep.KeyMaterial, keybuf, wep.KeyLength);
2726 
2727 	if (rtw_set_802_11_add_wep(padapter, &wep) == _FALSE) {
2728 		if (rf_on == pwrpriv->rf_pwrstate)
2729 			ret = -EOPNOTSUPP;
2730 		goto exit;
2731 	}
2732 
2733 exit:
2734 
2735 
2736 	return ret;
2737 
2738 }
2739 
2740 static int rtw_wx_get_enc(struct net_device *dev,
2741 			  struct iw_request_info *info,
2742 			  union iwreq_data *wrqu, char *keybuf)
2743 {
2744 	uint key, ret = 0;
2745 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2746 	struct iw_point *erq = &(wrqu->encoding);
2747 	struct	mlme_priv	*pmlmepriv = &(padapter->mlmepriv);
2748 
2749 
2750 	if (check_fwstate(pmlmepriv, WIFI_ASOC_STATE) != _TRUE) {
2751 		if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) != _TRUE) {
2752 			erq->length = 0;
2753 			erq->flags |= IW_ENCODE_DISABLED;
2754 			return 0;
2755 		}
2756 	}
2757 
2758 
2759 	key = erq->flags & IW_ENCODE_INDEX;
2760 
2761 	if (key) {
2762 		if (key > WEP_KEYS)
2763 			return -EINVAL;
2764 		key--;
2765 	} else
2766 		key = padapter->securitypriv.dot11PrivacyKeyIndex;
2767 
2768 	erq->flags = key + 1;
2769 
2770 	/* if(padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeOpen) */
2771 	/* { */
2772 	/* erq->flags |= IW_ENCODE_OPEN; */
2773 	/* }	  */
2774 
2775 	switch (padapter->securitypriv.ndisencryptstatus) {
2776 	case Ndis802_11EncryptionNotSupported:
2777 	case Ndis802_11EncryptionDisabled:
2778 
2779 		erq->length = 0;
2780 		erq->flags |= IW_ENCODE_DISABLED;
2781 
2782 		break;
2783 
2784 	case Ndis802_11Encryption1Enabled:
2785 
2786 		erq->length = padapter->securitypriv.dot11DefKeylen[key];
2787 
2788 		if (erq->length) {
2789 			_rtw_memcpy(keybuf, padapter->securitypriv.dot11DefKey[key].skey, padapter->securitypriv.dot11DefKeylen[key]);
2790 
2791 			erq->flags |= IW_ENCODE_ENABLED;
2792 
2793 			if (padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeOpen)
2794 				erq->flags |= IW_ENCODE_OPEN;
2795 			else if (padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeShared)
2796 				erq->flags |= IW_ENCODE_RESTRICTED;
2797 		} else {
2798 			erq->length = 0;
2799 			erq->flags |= IW_ENCODE_DISABLED;
2800 		}
2801 
2802 		break;
2803 
2804 	case Ndis802_11Encryption2Enabled:
2805 	case Ndis802_11Encryption3Enabled:
2806 
2807 		erq->length = 16;
2808 		erq->flags |= (IW_ENCODE_ENABLED | IW_ENCODE_OPEN | IW_ENCODE_NOKEY);
2809 
2810 		break;
2811 
2812 	default:
2813 		erq->length = 0;
2814 		erq->flags |= IW_ENCODE_DISABLED;
2815 
2816 		break;
2817 
2818 	}
2819 
2820 
2821 	return ret;
2822 
2823 }
2824 
2825 static int rtw_wx_get_power(struct net_device *dev,
2826 			    struct iw_request_info *info,
2827 			    union iwreq_data *wrqu, char *extra)
2828 {
2829 	/* _adapter *padapter = (_adapter *)rtw_netdev_priv(dev); */
2830 
2831 	wrqu->power.value = 0;
2832 	wrqu->power.fixed = 0;	/* no auto select */
2833 	wrqu->power.disabled = 1;
2834 
2835 	return 0;
2836 
2837 }
2838 
2839 static int rtw_wx_set_gen_ie(struct net_device *dev,
2840 			     struct iw_request_info *info,
2841 			     union iwreq_data *wrqu, char *extra)
2842 {
2843 	int ret;
2844 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2845 
2846 	ret = rtw_set_wpa_ie(padapter, extra, wrqu->data.length);
2847 
2848 	return ret;
2849 }
2850 
2851 static int rtw_wx_set_auth(struct net_device *dev,
2852 			   struct iw_request_info *info,
2853 			   union iwreq_data *wrqu, char *extra)
2854 {
2855 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2856 	struct iw_param *param = (struct iw_param *)&(wrqu->param);
2857 	struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
2858 	struct mlme_ext_info *pmlmeinfo = &pmlmeext->mlmext_info;
2859 #ifdef CONFIG_WAPI_SUPPORT
2860 #ifndef CONFIG_IOCTL_CFG80211
2861 	struct security_priv *psecuritypriv = &padapter->securitypriv;
2862 	u32 value = param->value;
2863 #endif
2864 #endif
2865 	int ret = 0;
2866 
2867 	switch (param->flags & IW_AUTH_INDEX) {
2868 
2869 	case IW_AUTH_WPA_VERSION:
2870 #ifdef CONFIG_WAPI_SUPPORT
2871 #ifndef CONFIG_IOCTL_CFG80211
2872 		padapter->wapiInfo.bWapiEnable = false;
2873 		if (value == IW_AUTH_WAPI_VERSION_1) {
2874 			padapter->wapiInfo.bWapiEnable = true;
2875 			psecuritypriv->dot11PrivacyAlgrthm = _SMS4_;
2876 			psecuritypriv->dot118021XGrpPrivacy = _SMS4_;
2877 			psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_WAPI;
2878 			pmlmeinfo->auth_algo = psecuritypriv->dot11AuthAlgrthm;
2879 			padapter->wapiInfo.extra_prefix_len = WAPI_EXT_LEN;
2880 			padapter->wapiInfo.extra_postfix_len = SMS4_MIC_LEN;
2881 		}
2882 #endif
2883 #endif
2884 		break;
2885 	case IW_AUTH_CIPHER_PAIRWISE:
2886 
2887 		break;
2888 	case IW_AUTH_CIPHER_GROUP:
2889 
2890 		break;
2891 	case IW_AUTH_KEY_MGMT:
2892 #ifdef CONFIG_WAPI_SUPPORT
2893 #ifndef CONFIG_IOCTL_CFG80211
2894 		RTW_INFO("rtw_wx_set_auth: IW_AUTH_KEY_MGMT case\n");
2895 		if (value == IW_AUTH_KEY_MGMT_WAPI_PSK)
2896 			padapter->wapiInfo.bWapiPSK = true;
2897 		else
2898 			padapter->wapiInfo.bWapiPSK = false;
2899 		RTW_INFO("rtw_wx_set_auth: IW_AUTH_KEY_MGMT bwapipsk %d\n", padapter->wapiInfo.bWapiPSK);
2900 #endif
2901 #endif
2902 		/*
2903 		 *  ??? does not use these parameters
2904 		 */
2905 		break;
2906 
2907 	case IW_AUTH_TKIP_COUNTERMEASURES: {
2908 		if (param->value) {
2909 			/* wpa_supplicant is enabling the tkip countermeasure. */
2910 			padapter->securitypriv.btkip_countermeasure = _TRUE;
2911 		} else {
2912 			/* wpa_supplicant is disabling the tkip countermeasure. */
2913 			padapter->securitypriv.btkip_countermeasure = _FALSE;
2914 		}
2915 		break;
2916 	}
2917 	case IW_AUTH_DROP_UNENCRYPTED: {
2918 		/* HACK:
2919 		 *
2920 		 * wpa_supplicant calls set_wpa_enabled when the driver
2921 		 * is loaded and unloaded, regardless of if WPA is being
2922 		 * used.  No other calls are made which can be used to
2923 		 * determine if encryption will be used or not prior to
2924 		 * association being expected.  If encryption is not being
2925 		 * used, drop_unencrypted is set to false, else true -- we
2926 		 * can use this to determine if the CAP_PRIVACY_ON bit should
2927 		 * be set.
2928 		 */
2929 
2930 		if (padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption1Enabled) {
2931 			break;/* it means init value, or using wep, ndisencryptstatus = Ndis802_11Encryption1Enabled, */
2932 			/* then it needn't reset it; */
2933 		}
2934 
2935 		if (param->value) {
2936 			padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
2937 			padapter->securitypriv.dot11PrivacyAlgrthm = _NO_PRIVACY_;
2938 			padapter->securitypriv.dot118021XGrpPrivacy = _NO_PRIVACY_;
2939 			padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open; /* open system */
2940 			padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeOpen;
2941 		}
2942 
2943 		break;
2944 	}
2945 
2946 	case IW_AUTH_80211_AUTH_ALG:
2947 
2948 #if defined(CONFIG_RTW_ANDROID) || 1
2949 		/*
2950 		 *  It's the starting point of a link layer connection using wpa_supplicant
2951 		*/
2952 		if (check_fwstate(&padapter->mlmepriv, WIFI_ASOC_STATE)) {
2953 			LeaveAllPowerSaveMode(padapter);
2954 			rtw_disassoc_cmd(padapter, 500, RTW_CMDF_WAIT_ACK);
2955 			if (1
2956 #ifdef CONFIG_STA_CMD_DISPR
2957 			    && (MLME_IS_STA(padapter) == _FALSE)
2958 #endif /* CONFIG_STA_CMD_DISPR */
2959 			    )
2960 				rtw_free_assoc_resources_cmd(padapter, _TRUE, RTW_CMDF_WAIT_ACK);
2961 			RTW_INFO("%s...call rtw_indicate_disconnect\n ", __FUNCTION__);
2962 			rtw_indicate_disconnect(padapter, 0, _FALSE);
2963 
2964 			pmlmeinfo->disconnect_occurred_time = rtw_systime_to_ms(rtw_get_current_time());
2965 			pmlmeinfo->disconnect_code = DISCONNECTION_BY_SYSTEM_DUE_TO_HIGH_LAYER_COMMAND;
2966 			pmlmeinfo->wifi_reason_code = WLAN_REASON_UNSPECIFIED;
2967 		}
2968 #endif
2969 
2970 
2971 		ret = wpa_set_auth_algs(dev, (u32)param->value);
2972 
2973 		break;
2974 
2975 	case IW_AUTH_WPA_ENABLED:
2976 
2977 		/* if(param->value) */
2978 		/* padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_8021X; */ /* 802.1x */
2979 		/* else */
2980 		/* padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open; */ /* open system */
2981 
2982 		/* _disassociate(priv); */
2983 
2984 		break;
2985 
2986 	case IW_AUTH_RX_UNENCRYPTED_EAPOL:
2987 		/* ieee->ieee802_1x = param->value; */
2988 		break;
2989 
2990 	case IW_AUTH_PRIVACY_INVOKED:
2991 		/* ieee->privacy_invoked = param->value; */
2992 		break;
2993 
2994 #ifdef CONFIG_WAPI_SUPPORT
2995 #ifndef CONFIG_IOCTL_CFG80211
2996 	case IW_AUTH_WAPI_ENABLED:
2997 		break;
2998 #endif
2999 #endif
3000 
3001 	default:
3002 		return -EOPNOTSUPP;
3003 
3004 	}
3005 
3006 	return ret;
3007 
3008 }
3009 
3010 static int rtw_wx_set_enc_ext(struct net_device *dev,
3011 			      struct iw_request_info *info,
3012 			      union iwreq_data *wrqu, char *extra)
3013 {
3014 	char *alg_name;
3015 	u32 param_len;
3016 	struct ieee_param *param = NULL;
3017 	struct iw_point *pencoding = &wrqu->encoding;
3018 	struct iw_encode_ext *pext = (struct iw_encode_ext *)extra;
3019 	int ret = 0;
3020 
3021 	param_len = sizeof(struct ieee_param) + pext->key_len;
3022 	param = (struct ieee_param *)rtw_malloc(param_len);
3023 	if (param == NULL)
3024 		return -1;
3025 
3026 	_rtw_memset(param, 0, param_len);
3027 
3028 	param->cmd = IEEE_CMD_SET_ENCRYPTION;
3029 	_rtw_memset(param->sta_addr, 0xff, ETH_ALEN);
3030 
3031 
3032 	switch (pext->alg) {
3033 	case IW_ENCODE_ALG_NONE:
3034 		/* todo: remove key */
3035 		/* remove = 1;	 */
3036 		alg_name = "none";
3037 		break;
3038 	case IW_ENCODE_ALG_WEP:
3039 		alg_name = "WEP";
3040 		break;
3041 	case IW_ENCODE_ALG_TKIP:
3042 		alg_name = "TKIP";
3043 		break;
3044 	case IW_ENCODE_ALG_CCMP:
3045 		alg_name = "CCMP";
3046 		break;
3047 #ifdef CONFIG_IEEE80211W
3048 	case IW_ENCODE_ALG_AES_CMAC:
3049 		alg_name = "BIP";
3050 		break;
3051 #endif /* CONFIG_IEEE80211W */
3052 #ifdef CONFIG_WAPI_SUPPORT
3053 #ifndef CONFIG_IOCTL_CFG80211
3054 	case IW_ENCODE_ALG_SM4:
3055 		alg_name = "SMS4";
3056 		_rtw_memcpy(param->sta_addr, pext->addr.sa_data, ETH_ALEN);
3057 		RTW_INFO("rtw_wx_set_enc_ext: SMS4 case\n");
3058 		break;
3059 #endif
3060 #endif
3061 	default:
3062 		ret = -1;
3063 		goto exit;
3064 	}
3065 
3066 	strncpy((char *)param->u.crypt.alg, alg_name, IEEE_CRYPT_ALG_NAME_LEN);
3067 
3068 	if (pext->ext_flags & IW_ENCODE_EXT_SET_TX_KEY)
3069 		param->u.crypt.set_tx = 1;
3070 
3071 	/* cliW: WEP does not have group key
3072 	 * just not checking GROUP key setting
3073 	 */
3074 	if ((pext->alg != IW_ENCODE_ALG_WEP) &&
3075 	    ((pext->ext_flags & IW_ENCODE_EXT_GROUP_KEY)
3076 #ifdef CONFIG_IEEE80211W
3077 	     || (pext->ext_flags & IW_ENCODE_ALG_AES_CMAC)
3078 #endif /* CONFIG_IEEE80211W */
3079 	    ))
3080 		param->u.crypt.set_tx = 0;
3081 
3082 	param->u.crypt.idx = (pencoding->flags & 0x00FF) - 1 ;
3083 
3084 	if (pext->ext_flags & IW_ENCODE_EXT_RX_SEQ_VALID) {
3085 #ifdef CONFIG_WAPI_SUPPORT
3086 #ifndef CONFIG_IOCTL_CFG80211
3087 		if (pext->alg == IW_ENCODE_ALG_SM4)
3088 			_rtw_memcpy(param->u.crypt.seq, pext->rx_seq, 16);
3089 		else
3090 #endif /* CONFIG_IOCTL_CFG80211 */
3091 #endif /* CONFIG_WAPI_SUPPORT */
3092 			_rtw_memcpy(param->u.crypt.seq, pext->rx_seq, 8);
3093 	}
3094 
3095 	if (pext->key_len) {
3096 		param->u.crypt.key_len = pext->key_len;
3097 		/* _rtw_memcpy(param + 1, pext + 1, pext->key_len); */
3098 		_rtw_memcpy(param->u.crypt.key, pext + 1, pext->key_len);
3099 	}
3100 
3101 	if (pencoding->flags & IW_ENCODE_DISABLED) {
3102 		/* todo: remove key */
3103 		/* remove = 1; */
3104 	}
3105 
3106 	ret =  wpa_set_encryption(dev, param, param_len);
3107 
3108 exit:
3109 	if (param)
3110 		rtw_mfree((u8 *)param, param_len);
3111 
3112 	return ret;
3113 }
3114 
3115 
3116 static int rtw_wx_get_nick(struct net_device *dev,
3117 			   struct iw_request_info *info,
3118 			   union iwreq_data *wrqu, char *extra)
3119 {
3120 	/* _adapter *padapter = (_adapter *)rtw_netdev_priv(dev); */
3121 	/* struct mlme_priv *pmlmepriv = &(padapter->mlmepriv); */
3122 	/* struct security_priv *psecuritypriv = &padapter->securitypriv; */
3123 
3124 	if (extra) {
3125 		wrqu->data.length = 14;
3126 		wrqu->data.flags = 1;
3127 		_rtw_memcpy(extra, "<WIFI@REALTEK>", 14);
3128 	}
3129 
3130 	/* rtw_signal_process(pid, SIGUSR1); */ /* for test */
3131 
3132 	/* dump debug info here	 */
3133 #if 0
3134 	u32 dot11AuthAlgrthm;		/*  802.11 auth, could be open, shared, and 8021x */
3135 	u32 dot11PrivacyAlgrthm;	/*  This specify the privacy for shared auth. algorithm. */
3136 	u32 dot118021XGrpPrivacy;	/*  This specify the privacy algthm. used for Grp key */
3137 	u32 ndisauthtype;
3138 	u32 ndisencryptstatus;
3139 #endif
3140 
3141 	/* RTW_INFO("auth_alg=0x%x, enc_alg=0x%x, auth_type=0x%x, enc_type=0x%x\n",  */
3142 	/*		psecuritypriv->dot11AuthAlgrthm, psecuritypriv->dot11PrivacyAlgrthm, */
3143 	/*		psecuritypriv->ndisauthtype, psecuritypriv->ndisencryptstatus); */
3144 
3145 	/* RTW_INFO("enc_alg=0x%x\n", psecuritypriv->dot11PrivacyAlgrthm); */
3146 	/* RTW_INFO("auth_type=0x%x\n", psecuritypriv->ndisauthtype); */
3147 	/* RTW_INFO("enc_type=0x%x\n", psecuritypriv->ndisencryptstatus); */
3148 
3149 	return 0;
3150 
3151 }
3152 
3153 static int rtw_wx_read32(struct net_device *dev,
3154 			 struct iw_request_info *info,
3155 			 union iwreq_data *wrqu, char *extra)
3156 {
3157 
3158 	_adapter *padapter;
3159 	struct dvobj_priv *dvobj;
3160 	struct iw_point *p;
3161 	u16 len;
3162 	u32 addr;
3163 	u32 data32;
3164 	u32 bytes;
3165 	u8 *ptmp;
3166 	int ret;
3167 
3168 
3169 	ret = 0;
3170 	padapter = (_adapter *)rtw_netdev_priv(dev);
3171 	dvobj = adapter_to_dvobj(padapter);
3172 	p = &wrqu->data;
3173 	len = p->length;
3174 	if (0 == len)
3175 		return -EINVAL;
3176 
3177 	ptmp = (u8 *)rtw_malloc(len);
3178 	if (NULL == ptmp)
3179 		return -ENOMEM;
3180 
3181 	if (copy_from_user(ptmp, p->pointer, len)) {
3182 		ret = -EFAULT;
3183 		goto exit;
3184 	}
3185 
3186 	bytes = 0;
3187 	addr = 0;
3188 	sscanf(ptmp, "%d,%x", &bytes, &addr);
3189 
3190 	switch (bytes) {
3191 	case 1:
3192 		data32 = rtw_phl_read8(dvobj->phl, addr);
3193 		sprintf(extra, "0x%02X", data32);
3194 		break;
3195 	case 2:
3196 		data32 = rtw_phl_read16(dvobj->phl, addr);
3197 		sprintf(extra, "0x%04X", data32);
3198 		break;
3199 	case 4:
3200 		data32 = rtw_phl_read32(dvobj->phl, addr);
3201 		sprintf(extra, "0x%08X", data32);
3202 		break;
3203 #if 0
3204 	#if defined(CONFIG_SDIO_HCI) && defined(CONFIG_SDIO_INDIRECT_ACCESS) && defined(DBG_SDIO_INDIRECT_ACCESS)
3205 	case 11:
3206 		data32 = rtw_sd_iread8(padapter, addr);
3207 		sprintf(extra, "0x%02X", data32);
3208 		break;
3209 	case 12:
3210 		data32 = rtw_sd_iread16(padapter, addr);
3211 		sprintf(extra, "0x%04X", data32);
3212 		break;
3213 	case 14:
3214 		data32 = rtw_sd_iread32(padapter, addr);
3215 		sprintf(extra, "0x%08X", data32);
3216 		break;
3217 	#endif
3218 #endif
3219 	default:
3220 		RTW_INFO("%s: usage> read [bytes],[address(hex)]\n", __func__);
3221 		ret = -EINVAL;
3222 		goto exit;
3223 	}
3224 	RTW_INFO("%s: addr=0x%08X data=%s\n", __func__, addr, extra);
3225 
3226 exit:
3227 	rtw_mfree(ptmp, len);
3228 	return 0;
3229 }
3230 
3231 static int rtw_wx_write32(struct net_device *dev,
3232 			  struct iw_request_info *info,
3233 			  union iwreq_data *wrqu, char *extra)
3234 {
3235 
3236 
3237 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3238 	struct dvobj_priv *dvobj = adapter_to_dvobj(padapter);
3239 
3240 	u32 addr;
3241 	u32 data32;
3242 	u32 bytes;
3243 
3244 
3245 	bytes = 0;
3246 	addr = 0;
3247 	data32 = 0;
3248 	sscanf(extra, "%d,%x,%x", &bytes, &addr, &data32);
3249 
3250 	switch (bytes) {
3251 	case 1:
3252 		rtw_phl_write8(dvobj->phl, addr, (u8)data32);
3253 		RTW_INFO("%s: addr=0x%08X data=0x%02X\n", __func__, addr, (u8)data32);
3254 		break;
3255 	case 2:
3256 		rtw_phl_write16(dvobj->phl, addr, (u16)data32);
3257 		RTW_INFO("%s: addr=0x%08X data=0x%04X\n", __func__, addr, (u16)data32);
3258 		break;
3259 	case 4:
3260 		rtw_phl_write32(dvobj->phl, addr, data32);
3261 		RTW_INFO("%s: addr=0x%08X data=0x%08X\n", __func__, addr, data32);
3262 		break;
3263 	default:
3264 		RTW_INFO("%s: usage> write [bytes],[address(hex)],[data(hex)]\n", __func__);
3265 		return -EINVAL;
3266 	}
3267 
3268 	return 0;
3269 }
3270 
3271 static int rtw_wx_read_rf(struct net_device *dev,
3272 			  struct iw_request_info *info,
3273 			  union iwreq_data *wrqu, char *extra)
3274 {
3275 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3276 	struct dvobj_priv *dvobj = adapter_to_dvobj(padapter);
3277 	u32 path, addr, data32;
3278 
3279 
3280 	path = *(u32 *)extra;
3281 	addr = *((u32 *)extra + 1);
3282 	data32 = rtw_phl_read_rfreg(GET_PHL_INFO(dvobj), path, addr, 0xFFFFF);
3283 	/*	RTW_INFO("%s: path=%d addr=0x%02x data=0x%05x\n", __func__, path, addr, data32); */
3284 	/*
3285 	 * IMPORTANT!!
3286 	 * Only when wireless private ioctl is at odd order,
3287 	 * "extra" would be copied to user space.
3288 	 */
3289 	sprintf(extra, "0x%05x", data32);
3290 
3291 	return 0;
3292 }
3293 
3294 static int rtw_wx_write_rf(struct net_device *dev,
3295 			   struct iw_request_info *info,
3296 			   union iwreq_data *wrqu, char *extra)
3297 {
3298 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3299 	struct dvobj_priv *dvobj = adapter_to_dvobj(padapter);
3300 	u32 path, addr, data32;
3301 
3302 
3303 	path = *(u32 *)extra;
3304 	addr = *((u32 *)extra + 1);
3305 	data32 = *((u32 *)extra + 2);
3306 	/*	RTW_INFO("%s: path=%d addr=0x%02x data=0x%05x\n", __func__, path, addr, data32); */
3307 	rtw_phl_write_rfreg(GET_PHL_INFO(dvobj), path, addr, 0xFFFFF, data32);
3308 
3309 	return 0;
3310 }
3311 
3312 static int rtw_wx_priv_null(struct net_device *dev, struct iw_request_info *a,
3313 			    union iwreq_data *wrqu, char *b)
3314 {
3315 	return -1;
3316 }
3317 
3318 #ifdef CONFIG_RTW_80211K
3319 extern void rm_dbg_cmd(_adapter *padapter, char *s);
3320 static int rtw_wx_priv_rrm(struct net_device *dev, struct iw_request_info *a,
3321 			    union iwreq_data *wrqu, char *b)
3322 {
3323 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3324 	u32 path, addr, data32;
3325 
3326 
3327 	rm_dbg_cmd(padapter, b);
3328 	wrqu->data.length = strlen(b);
3329 
3330 	return 0;
3331 }
3332 #endif
3333 
3334 static int dummy(struct net_device *dev, struct iw_request_info *a,
3335 		 union iwreq_data *wrqu, char *b)
3336 {
3337 	/* _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);	 */
3338 	/* struct mlme_priv *pmlmepriv = &(padapter->mlmepriv); */
3339 
3340 	/* RTW_INFO("cmd_code=%x, fwstate=0x%x\n", a->cmd, get_fwstate(pmlmepriv)); */
3341 
3342 	return -1;
3343 
3344 }
3345 
3346 static int rtw_wx_set_channel_plan(struct net_device *dev,
3347 				   struct iw_request_info *info,
3348 				   union iwreq_data *wrqu, char *extra)
3349 {
3350 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3351 	u16 channel_plan_req = (u16)(*((int *)wrqu));
3352 
3353 	rtw_chplan_ioctl_input_mapping(&channel_plan_req, NULL);
3354 
3355 	if (_SUCCESS != rtw_set_channel_plan(padapter, channel_plan_req, RTW_CHPLAN_6G_UNSPECIFIED, RTW_REGD_SET_BY_USER))
3356 		return -EPERM;
3357 
3358 	return 0;
3359 }
3360 
3361 static int rtw_wx_set_mtk_wps_probe_ie(struct net_device *dev,
3362 				       struct iw_request_info *a,
3363 				       union iwreq_data *wrqu, char *b)
3364 {
3365 #ifdef CONFIG_PLATFORM_MT53XX
3366 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3367 	struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3368 
3369 #endif
3370 	return 0;
3371 }
3372 
3373 static int rtw_wx_get_sensitivity(struct net_device *dev,
3374 				  struct iw_request_info *info,
3375 				  union iwreq_data *wrqu, char *buf)
3376 {
3377 #ifdef CONFIG_PLATFORM_MT53XX
3378 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3379 
3380 	/*	Modified by Albert 20110914 */
3381 	/*	This is in dbm format for MTK platform. */
3382 	wrqu->qual.level = padapter->recvinfo.rssi;
3383 	RTW_INFO(" level = %u\n",  wrqu->qual.level);
3384 #endif
3385 	return 0;
3386 }
3387 
3388 static int rtw_wx_set_mtk_wps_ie(struct net_device *dev,
3389 				 struct iw_request_info *info,
3390 				 union iwreq_data *wrqu, char *extra)
3391 {
3392 #ifdef CONFIG_PLATFORM_MT53XX
3393 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3394 
3395 	return rtw_set_wpa_ie(padapter, wrqu->data.pointer, wrqu->data.length);
3396 #else
3397 	return 0;
3398 #endif
3399 }
3400 
3401 #ifdef MP_IOCTL_HDL
3402 static void rtw_dbg_mode_hdl(_adapter *padapter, u32 id, u8 *pdata, u32 len)
3403 {
3404 	pRW_Reg	RegRWStruct;
3405 	struct rf_reg_param *prfreg;
3406 	struct dvobj_priv dvobj = adapter_to_dvobj(padapter);
3407 	u8 path;
3408 	u8 offset;
3409 	u32 value;
3410 
3411 	RTW_INFO("%s\n", __FUNCTION__);
3412 
3413 	switch (id) {
3414 	case GEN_MP_IOCTL_SUBCODE(MP_START):
3415 		RTW_INFO("871x_driver is only for normal mode, can't enter mp mode\n");
3416 		break;
3417 	case GEN_MP_IOCTL_SUBCODE(READ_REG):
3418 		RegRWStruct = (pRW_Reg)pdata;
3419 		switch (RegRWStruct->width) {
3420 		case 1:
3421 			RegRWStruct->value = rtw_read8(padapter, RegRWStruct->offset);
3422 			break;
3423 		case 2:
3424 			RegRWStruct->value = rtw_read16(padapter, RegRWStruct->offset);
3425 			break;
3426 		case 4:
3427 			RegRWStruct->value = rtw_read32(padapter, RegRWStruct->offset);
3428 			break;
3429 		default:
3430 			break;
3431 		}
3432 
3433 		break;
3434 	case GEN_MP_IOCTL_SUBCODE(WRITE_REG):
3435 		RegRWStruct = (pRW_Reg)pdata;
3436 		switch (RegRWStruct->width) {
3437 		case 1:
3438 			rtw_write8(padapter, RegRWStruct->offset, (u8)RegRWStruct->value);
3439 			break;
3440 		case 2:
3441 			rtw_write16(padapter, RegRWStruct->offset, (u16)RegRWStruct->value);
3442 			break;
3443 		case 4:
3444 			rtw_write32(padapter, RegRWStruct->offset, (u32)RegRWStruct->value);
3445 			break;
3446 		default:
3447 			break;
3448 		}
3449 
3450 		break;
3451 	case GEN_MP_IOCTL_SUBCODE(READ_RF_REG):
3452 
3453 		prfreg = (struct rf_reg_param *)pdata;
3454 
3455 		path = (u8)prfreg->path;
3456 		offset = (u8)prfreg->offset;
3457 
3458 		value = rtw_phl_read_rfreg(GET_PHL_INFO(dvobj), path, offset, 0xffffffff);
3459 
3460 		prfreg->value = value;
3461 
3462 		break;
3463 	case GEN_MP_IOCTL_SUBCODE(WRITE_RF_REG):
3464 
3465 		prfreg = (struct rf_reg_param *)pdata;
3466 
3467 		path = (u8)prfreg->path;
3468 		offset = (u8)prfreg->offset;
3469 		value = prfreg->value;
3470 
3471 		rtw_phl_write_rfreg(GET_PHL_INFO(dvobj), path, offset, 0xffffffff, value);
3472 
3473 		break;
3474 	case GEN_MP_IOCTL_SUBCODE(TRIGGER_GPIO):
3475 		RTW_INFO("==> trigger gpio 0\n");
3476 		rtw_hal_set_hwreg(padapter, HW_VAR_TRIGGER_GPIO_0, 0);
3477 		break;
3478 #ifdef CONFIG_BTC
3479 	case GEN_MP_IOCTL_SUBCODE(SET_DM_BT):
3480 		RTW_INFO("==> set dm_bt_coexist:%x\n", *(u8 *)pdata);
3481 		rtw_hal_set_hwreg(padapter, HW_VAR_BT_SET_COEXIST, pdata);
3482 		break;
3483 	case GEN_MP_IOCTL_SUBCODE(DEL_BA):
3484 		RTW_INFO("==> delete ba:%x\n", *(u8 *)pdata);
3485 		rtw_hal_set_hwreg(padapter, HW_VAR_BT_ISSUE_DELBA, pdata);
3486 		break;
3487 #endif
3488 #ifdef DBG_CONFIG_ERROR_DETECT
3489 	case GEN_MP_IOCTL_SUBCODE(GET_WIFI_STATUS):
3490 		*pdata = rtw_hal_sreset_get_wifi_status(padapter);
3491 		break;
3492 #endif
3493 
3494 	default:
3495 		break;
3496 	}
3497 
3498 }
3499 static int rtw_mp_ioctl_hdl(struct net_device *dev, struct iw_request_info *info,
3500 			    union iwreq_data *wrqu, char *extra)
3501 {
3502 	int ret = 0;
3503 	u32 BytesRead, BytesWritten, BytesNeeded;
3504 	struct oid_par_priv	oid_par;
3505 	struct mp_ioctl_handler	*phandler;
3506 	struct mp_ioctl_param	*poidparam;
3507 	uint status = 0;
3508 	u16 len;
3509 	u8 *pparmbuf = NULL, bset;
3510 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3511 	struct iw_point *p = &wrqu->data;
3512 
3513 	/* RTW_INFO("+rtw_mp_ioctl_hdl\n"); */
3514 
3515 	/* mutex_lock(&ioctl_mutex); */
3516 
3517 	if ((!p->length) || (!p->pointer)) {
3518 		ret = -EINVAL;
3519 		goto _rtw_mp_ioctl_hdl_exit;
3520 	}
3521 
3522 	pparmbuf = NULL;
3523 	bset = (u8)(p->flags & 0xFFFF);
3524 	len = p->length;
3525 	pparmbuf = (u8 *)rtw_malloc(len);
3526 	if (pparmbuf == NULL) {
3527 		ret = -ENOMEM;
3528 		goto _rtw_mp_ioctl_hdl_exit;
3529 	}
3530 
3531 	if (copy_from_user(pparmbuf, p->pointer, len)) {
3532 		ret = -EFAULT;
3533 		goto _rtw_mp_ioctl_hdl_exit;
3534 	}
3535 
3536 	poidparam = (struct mp_ioctl_param *)pparmbuf;
3537 
3538 	if (poidparam->subcode >= MAX_MP_IOCTL_SUBCODE) {
3539 		ret = -EINVAL;
3540 		goto _rtw_mp_ioctl_hdl_exit;
3541 	}
3542 
3543 	/* RTW_INFO("%s: %d\n", __func__, poidparam->subcode); */
3544 #ifdef CONFIG_MP_INCLUDED
3545 	if (padapter->registrypriv.mp_mode == 1) {
3546 		phandler = mp_ioctl_hdl + poidparam->subcode;
3547 
3548 		if ((phandler->paramsize != 0) && (poidparam->len < phandler->paramsize)) {
3549 			ret = -EINVAL;
3550 			goto _rtw_mp_ioctl_hdl_exit;
3551 		}
3552 
3553 		if (phandler->handler) {
3554 			oid_par.adapter_context = padapter;
3555 			oid_par.oid = phandler->oid;
3556 			oid_par.information_buf = poidparam->data;
3557 			oid_par.information_buf_len = poidparam->len;
3558 			oid_par.dbg = 0;
3559 
3560 			BytesWritten = 0;
3561 			BytesNeeded = 0;
3562 
3563 			if (bset) {
3564 				oid_par.bytes_rw = &BytesRead;
3565 				oid_par.bytes_needed = &BytesNeeded;
3566 				oid_par.type_of_oid = SET_OID;
3567 			} else {
3568 				oid_par.bytes_rw = &BytesWritten;
3569 				oid_par.bytes_needed = &BytesNeeded;
3570 				oid_par.type_of_oid = QUERY_OID;
3571 			}
3572 
3573 			status = phandler->handler(&oid_par);
3574 
3575 			/* todo:check status, BytesNeeded, etc. */
3576 		} else {
3577 			RTW_INFO("rtw_mp_ioctl_hdl(): err!, subcode=%d, oid=%d, handler=%p\n",
3578 				poidparam->subcode, phandler->oid, phandler->handler);
3579 			ret = -EFAULT;
3580 			goto _rtw_mp_ioctl_hdl_exit;
3581 		}
3582 	} else
3583 #endif
3584 	{
3585 		rtw_dbg_mode_hdl(padapter, poidparam->subcode, poidparam->data, poidparam->len);
3586 	}
3587 
3588 	if (bset == 0x00) {/* query info */
3589 		if (copy_to_user(p->pointer, pparmbuf, len))
3590 			ret = -EFAULT;
3591 	}
3592 
3593 	if (status) {
3594 		ret = -EFAULT;
3595 		goto _rtw_mp_ioctl_hdl_exit;
3596 	}
3597 
3598 _rtw_mp_ioctl_hdl_exit:
3599 
3600 	if (pparmbuf)
3601 		rtw_mfree(pparmbuf, len);
3602 
3603 	/* mutex_unlock(&ioctl_mutex); */
3604 
3605 	return ret;
3606 }
3607 #endif /*MP_IOCTL_HDL*/
3608 static int rtw_get_ap_info(struct net_device *dev,
3609 			   struct iw_request_info *info,
3610 			   union iwreq_data *wrqu, char *extra)
3611 {
3612 	int ret = 0;
3613 	u32 cnt = 0, wpa_ielen;
3614 	_list	*plist, *phead;
3615 	unsigned char *pbuf;
3616 	u8 bssid[ETH_ALEN];
3617 	char data[32];
3618 	struct wlan_network *pnetwork = NULL;
3619 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3620 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3621 	_queue *queue = &(pmlmepriv->scanned_queue);
3622 	struct iw_point *pdata = &wrqu->data;
3623 
3624 	RTW_INFO("+rtw_get_aplist_info\n");
3625 
3626 	if (dev_is_drv_stopped(adapter_to_dvobj(padapter)) || (pdata == NULL)) {
3627 		ret = -EINVAL;
3628 		goto exit;
3629 	}
3630 
3631 	while ((check_fwstate(pmlmepriv, (WIFI_UNDER_SURVEY | WIFI_UNDER_LINKING))) == _TRUE) {
3632 		rtw_msleep_os(30);
3633 		cnt++;
3634 		if (cnt > 100)
3635 			break;
3636 	}
3637 
3638 
3639 	/* pdata->length = 0; */ /* ?	 */
3640 	pdata->flags = 0;
3641 	if (pdata->length >= 32) {
3642 		if (copy_from_user(data, pdata->pointer, 32)) {
3643 			ret = -EINVAL;
3644 			goto exit;
3645 		}
3646 	} else {
3647 		ret = -EINVAL;
3648 		goto exit;
3649 	}
3650 
3651 	_rtw_spinlock_bh(&(pmlmepriv->scanned_queue.lock));
3652 
3653 	phead = get_list_head(queue);
3654 	plist = get_next(phead);
3655 
3656 	while (1) {
3657 		if (rtw_end_of_queue_search(phead, plist) == _TRUE)
3658 			break;
3659 
3660 
3661 		pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
3662 
3663 		/* if(hwaddr_aton_i(pdata->pointer, bssid)) */
3664 		if (hwaddr_aton_i(data, bssid)) {
3665 			RTW_INFO("Invalid BSSID '%s'.\n", (u8 *)data);
3666 			_rtw_spinunlock_bh(&(pmlmepriv->scanned_queue.lock));
3667 			return -EINVAL;
3668 		}
3669 
3670 
3671 		if (_rtw_memcmp(bssid, pnetwork->network.MacAddress, ETH_ALEN) == _TRUE) { /* BSSID match, then check if supporting wpa/wpa2 */
3672 			RTW_INFO("BSSID:" MAC_FMT "\n", MAC_ARG(bssid));
3673 
3674 			pbuf = rtw_get_wpa_ie(&pnetwork->network.IEs[12], &wpa_ielen, pnetwork->network.IELength - 12);
3675 			if (pbuf && (wpa_ielen > 0)) {
3676 				pdata->flags = 1;
3677 				break;
3678 			}
3679 
3680 			pbuf = rtw_get_wpa2_ie(&pnetwork->network.IEs[12], &wpa_ielen, pnetwork->network.IELength - 12);
3681 			if (pbuf && (wpa_ielen > 0)) {
3682 				pdata->flags = 2;
3683 				break;
3684 			}
3685 
3686 		}
3687 
3688 		plist = get_next(plist);
3689 
3690 	}
3691 
3692 	_rtw_spinunlock_bh(&(pmlmepriv->scanned_queue.lock));
3693 
3694 	if (pdata->length >= 34) {
3695 		if (copy_to_user((u8 *)pdata->pointer + 32, (u8 *)&pdata->flags, 1)) {
3696 			ret = -EINVAL;
3697 			goto exit;
3698 		}
3699 	}
3700 
3701 exit:
3702 
3703 	return ret;
3704 
3705 }
3706 
3707 static int rtw_set_pid(struct net_device *dev,
3708 		       struct iw_request_info *info,
3709 		       union iwreq_data *wrqu, char *extra)
3710 {
3711 
3712 	int ret = 0;
3713 	_adapter *padapter = rtw_netdev_priv(dev);
3714 	int *pdata = (int *)wrqu;
3715 	int selector;
3716 
3717 	if (dev_is_drv_stopped(adapter_to_dvobj(padapter)) || (pdata == NULL)) {
3718 		ret = -EINVAL;
3719 		goto exit;
3720 	}
3721 
3722 	selector = *pdata;
3723 	if (selector < 3 && selector >= 0) {
3724 		padapter->pid[selector] = *(pdata + 1);
3725 #ifdef CONFIG_GLOBAL_UI_PID
3726 		ui_pid[selector] = *(pdata + 1);
3727 #endif
3728 		RTW_INFO("%s set pid[%d]=%d\n", __FUNCTION__, selector , padapter->pid[selector]);
3729 	} else
3730 		RTW_INFO("%s selector %d error\n", __FUNCTION__, selector);
3731 
3732 exit:
3733 
3734 	return ret;
3735 
3736 }
3737 
3738 static int rtw_wps_start(struct net_device *dev,
3739 			 struct iw_request_info *info,
3740 			 union iwreq_data *wrqu, char *extra)
3741 {
3742 
3743 	int ret = 0;
3744 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3745 	struct iw_point *pdata = &wrqu->data;
3746 	u32   u32wps_start = 0;
3747 	unsigned int uintRet = 0;
3748 
3749 	if (RTW_CANNOT_RUN(adapter_to_dvobj(padapter)) || (NULL == pdata)) {
3750 		ret = -EINVAL;
3751 		goto exit;
3752 	}
3753 
3754 	uintRet = copy_from_user((void *) &u32wps_start, pdata->pointer, 4);
3755 	if (u32wps_start == 0)
3756 		u32wps_start = *extra;
3757 
3758 	RTW_INFO("[%s] wps_start = %d\n", __FUNCTION__, u32wps_start);
3759 
3760 	if (u32wps_start == 1)   /* WPS Start */
3761 		rtw_led_control(padapter, LED_CTL_START_WPS);
3762 	else if (u32wps_start == 2)   /* WPS Stop because of wps success */
3763 		rtw_led_control(padapter, LED_CTL_STOP_WPS);
3764 	else if (u32wps_start == 3)   /* WPS Stop because of wps fail */
3765 		rtw_led_control(padapter, LED_CTL_STOP_WPS_FAIL);
3766 
3767 exit:
3768 
3769 	return ret;
3770 
3771 }
3772 
3773 extern int rtw_change_ifname(_adapter *padapter, const char *ifname);
3774 static int rtw_rereg_nd_name(struct net_device *dev,
3775 			     struct iw_request_info *info,
3776 			     union iwreq_data *wrqu, char *extra)
3777 {
3778 	int ret = 0;
3779 	_adapter *padapter = rtw_netdev_priv(dev);
3780 	struct dvobj_priv *dvobj = adapter_to_dvobj(padapter);
3781 	struct rereg_nd_name_data *rereg_priv = &padapter->rereg_nd_name_priv;
3782 	char new_ifname[IFNAMSIZ];
3783 
3784 	if (rereg_priv->old_ifname[0] == 0) {
3785 		char *reg_ifname;
3786 #ifdef CONFIG_CONCURRENT_MODE
3787 		if (padapter->isprimary)
3788 			reg_ifname = padapter->registrypriv.ifname;
3789 		else
3790 #endif
3791 			reg_ifname = padapter->registrypriv.if2name;
3792 
3793 		strncpy(rereg_priv->old_ifname, reg_ifname, IFNAMSIZ);
3794 		rereg_priv->old_ifname[IFNAMSIZ - 1] = 0;
3795 	}
3796 
3797 	/* RTW_INFO("%s wrqu->data.length:%d\n", __FUNCTION__, wrqu->data.length); */
3798 	if (wrqu->data.length > IFNAMSIZ)
3799 		return -EFAULT;
3800 
3801 	if (copy_from_user(new_ifname, wrqu->data.pointer, IFNAMSIZ))
3802 		return -EFAULT;
3803 
3804 	if (0 == strcmp(rereg_priv->old_ifname, new_ifname))
3805 		return ret;
3806 
3807 	RTW_INFO("%s new_ifname:%s\n", __FUNCTION__, new_ifname);
3808 	rtw_set_rtnl_lock_holder(dvobj, current);
3809 	ret = rtw_change_ifname(padapter, new_ifname);
3810 	rtw_set_rtnl_lock_holder(dvobj, NULL);
3811 	if (0 != ret)
3812 		goto exit;
3813 
3814 	if (_rtw_memcmp(rereg_priv->old_ifname, "disable%d", 9) == _TRUE) {
3815 		/* rtw_ips_mode_req(&padapter->pwrctrlpriv, rereg_priv->old_ips_mode); */
3816 	}
3817 
3818 	strncpy(rereg_priv->old_ifname, new_ifname, IFNAMSIZ);
3819 	rereg_priv->old_ifname[IFNAMSIZ - 1] = 0;
3820 
3821 	if (_rtw_memcmp(new_ifname, "disable%d", 9) == _TRUE) {
3822 
3823 		RTW_INFO("%s disable\n", __FUNCTION__);
3824 		/* free network queue for Android's timming issue */
3825 		rtw_free_network_queue(padapter, _TRUE);
3826 
3827 		/* the interface is being "disabled", we can do deeper IPS */
3828 		/* rereg_priv->old_ips_mode = rtw_get_ips_mode_req(&padapter->pwrctrlpriv); */
3829 		/* rtw_ips_mode_req(&padapter->pwrctrlpriv, IPS_NORMAL); */
3830 	}
3831 exit:
3832 	return ret;
3833 
3834 }
3835 
3836 #ifdef DBG_CMD_QUEUE
3837 u8 dump_cmd_id = 0;
3838 #endif
3839 
3840 #if 1
3841 static int rtw_dbg_port(struct net_device *dev,
3842 			struct iw_request_info *info,
3843 			union iwreq_data *wrqu, char *extra)
3844 {
3845 	int ret = 0;
3846 
3847 	return ret;
3848 }
3849 #else
3850 static int rtw_dbg_port(struct net_device *dev,
3851 			struct iw_request_info *info,
3852 			union iwreq_data *wrqu, char *extra)
3853 {
3854 	int ret = 0;
3855 	u8 major_cmd, minor_cmd;
3856 	u16 arg;
3857 	u32 extra_arg, *pdata, val32;
3858 	struct sta_info *psta;
3859 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3860 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3861 	struct mlme_ext_priv	*pmlmeext = &padapter->mlmeextpriv;
3862 	struct mlme_ext_info	*pmlmeinfo = &(pmlmeext->mlmext_info);
3863 	struct security_priv *psecuritypriv = &padapter->securitypriv;
3864 	struct wlan_network *cur_network = &(pmlmepriv->cur_network);
3865 	struct sta_priv *pstapriv = &padapter->stapriv;
3866 
3867 
3868 	pdata = (u32 *)&wrqu->data;
3869 
3870 	val32 = *pdata;
3871 	arg = (u16)(val32 & 0x0000ffff);
3872 	major_cmd = (u8)(val32 >> 24);
3873 	minor_cmd = (u8)((val32 >> 16) & 0x00ff);
3874 
3875 	extra_arg = *(pdata + 1);
3876 
3877 	switch (major_cmd) {
3878 	case 0x70: /* read_reg */
3879 		switch (minor_cmd) {
3880 		case 1:
3881 			RTW_INFO("rtw_read8(0x%x)=0x%02x\n", arg, rtw_read8(padapter, arg));
3882 			break;
3883 		case 2:
3884 			RTW_INFO("rtw_read16(0x%x)=0x%04x\n", arg, rtw_read16(padapter, arg));
3885 			break;
3886 		case 4:
3887 			RTW_INFO("rtw_read32(0x%x)=0x%08x\n", arg, rtw_read32(padapter, arg));
3888 			break;
3889 		}
3890 		break;
3891 	case 0x71: /* write_reg */
3892 		switch (minor_cmd) {
3893 		case 1:
3894 			rtw_write8(padapter, arg, extra_arg);
3895 			RTW_INFO("rtw_write8(0x%x)=0x%02x\n", arg, rtw_read8(padapter, arg));
3896 			break;
3897 		case 2:
3898 			rtw_write16(padapter, arg, extra_arg);
3899 			RTW_INFO("rtw_write16(0x%x)=0x%04x\n", arg, rtw_read16(padapter, arg));
3900 			break;
3901 		case 4:
3902 			rtw_write32(padapter, arg, extra_arg);
3903 			RTW_INFO("rtw_write32(0x%x)=0x%08x\n", arg, rtw_read32(padapter, arg));
3904 			break;
3905 		}
3906 		break;
3907 	case 0x72: /* read_bb */
3908 		RTW_INFO("read_bbreg(0x%x)=0x%x\n", arg, rtw_phl_read_bbreg(padapter, arg, 0xffffffff));
3909 		break;
3910 	case 0x73: /* write_bb */
3911 		rtw_phl_write_bbreg(padapter, arg, 0xffffffff, extra_arg);
3912 		RTW_INFO("write_bbreg(0x%x)=0x%x\n", arg, rtw_phl_read_bbreg(padapter, arg, 0xffffffff));
3913 		break;
3914 	case 0x74: /* read_rf */
3915 		RTW_INFO("read RF_reg path(0x%02x),offset(0x%x),value(0x%08x)\n", minor_cmd, arg, rtw_hal_read_rfreg(padapter, minor_cmd, arg, 0xffffffff));
3916 		break;
3917 	case 0x75: /* write_rf */
3918 		rtw_phl_write_rfreg(GET_PHL_INFO(dvobj), minor_cmd, arg, 0xffffffff, extra_arg);
3919 		RTW_INFO("write RF_reg path(0x%02x),offset(0x%x),value(0x%08x)\n", minor_cmd, arg, rtw_hal_read_rfreg(padapter, minor_cmd, arg, 0xffffffff));
3920 		break;
3921 
3922 	case 0x76:
3923 		switch (minor_cmd) {
3924 		case 0x00: /* normal mode, */
3925 			padapter->recvinfo.is_signal_dbg = 0;
3926 			break;
3927 		case 0x01: /* dbg mode */
3928 			padapter->recvinfo.is_signal_dbg = 1;
3929 			extra_arg = extra_arg > 100 ? 100 : extra_arg;
3930 			padapter->recvinfo.signal_strength_dbg = extra_arg;
3931 			break;
3932 		}
3933 		break;
3934 	case 0x78:
3935 		break;
3936 	case 0x79: {
3937 		/*
3938 		* dbg 0x79000000 [value], set RESP_TXAGC to + value, value:0~15
3939 		* dbg 0x79010000 [value], set RESP_TXAGC to - value, value:0~15
3940 		*/
3941 		u8 value =  extra_arg & 0x0f;
3942 		u8 sign = minor_cmd;
3943 		u16 write_value = 0;
3944 
3945 		RTW_INFO("%s set RESP_TXAGC to %s %u\n", __func__, sign ? "minus" : "plus", value);
3946 
3947 		if (sign)
3948 			value = value | 0x10;
3949 
3950 		write_value = value | (value << 5);
3951 		rtw_write16(padapter, 0x6d9, write_value);
3952 	}
3953 		break;
3954 	case 0x7a:
3955 		receive_disconnect(padapter, pmlmeinfo->network.MacAddress
3956 				   , WLAN_REASON_EXPIRATION_CHK, _FALSE);
3957 		pmlmeinfo->disconnect_occurred_time = rtw_systime_to_ms(rtw_get_current_time());
3958 		pmlmeinfo->disconnect_code = DISCONNECTION_BY_DRIVER_DUE_TO_IOCTL_DBG_PORT;
3959 		pmlmeinfo->wifi_reason_code = WLAN_REASON_UNSPECIFIED;
3960 		break;
3961 	case 0x7F:
3962 		switch (minor_cmd) {
3963 		case 0x0:
3964 			RTW_INFO("fwstate=0x%x\n", get_fwstate(pmlmepriv));
3965 			break;
3966 		case 0x01:
3967 			RTW_INFO("auth_alg=0x%x, enc_alg=0x%x, auth_type=0x%x, enc_type=0x%x\n",
3968 				psecuritypriv->dot11AuthAlgrthm, psecuritypriv->dot11PrivacyAlgrthm,
3969 				psecuritypriv->ndisauthtype, psecuritypriv->ndisencryptstatus);
3970 			break;
3971 		case 0x03:
3972 			RTW_INFO("qos_option=%d\n", pmlmepriv->qospriv.qos_option);
3973 #ifdef CONFIG_80211N_HT
3974 			RTW_INFO("ht_option=%d\n", pmlmepriv->htpriv.ht_option);
3975 #endif /* CONFIG_80211N_HT */
3976 			break;
3977 		case 0x04:
3978 			RTW_INFO("cur_ch=%d\n", pmlmeext->chandef.chan);
3979 			RTW_INFO("cur_bw=%d\n", pmlmeext->chandef.bw);
3980 			RTW_INFO("cur_ch_off=%d\n", pmlmeext->chandef.offset);
3981 
3982 			RTW_INFO("oper_ch=%d\n", rtw_get_oper_ch(padapter));
3983 			RTW_INFO("oper_bw=%d\n", rtw_get_oper_bw(padapter));
3984 			RTW_INFO("oper_ch_offet=%d\n", rtw_get_oper_choffset(padapter));
3985 
3986 			break;
3987 		case 0x05:
3988 			psta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
3989 			if (psta) {
3990 				RTW_INFO("SSID=%s\n", cur_network->network.Ssid.Ssid);
3991 				RTW_INFO("sta's macaddr:" MAC_FMT "\n", MAC_ARG(psta->phl_sta->mac_addr));
3992 				RTW_INFO("cur_channel=%d, cur_bwmode=%d, cur_ch_offset=%d\n",
3993 					pmlmeext->chandef.chan, pmlmeext->chandef.bw, pmlmeext->chandef.offset);
3994 				RTW_INFO("rtsen=%d, cts2slef=%d\n", psta->rtsen, psta->cts2self);
3995 				RTW_INFO("state=0x%x, aid=%d, macid=%d, raid=%d\n",
3996 					psta->state, psta->phl_sta->aid, psta->phl_sta->macid, psta->phl_sta->ra_info.rate_id);
3997 #ifdef CONFIG_80211N_HT
3998 				RTW_INFO("qos_en=%d, ht_en=%d, init_rate=%d\n", psta->qos_option, psta->htpriv.ht_option, psta->init_rate);
3999 				RTW_INFO("bwmode=%d, ch_offset=%d, sgi_20m=%d,sgi_40m=%d\n"
4000 					, psta->phl_sta->chandef.bw, psta->htpriv.ch_offset, psta->htpriv.sgi_20m, psta->htpriv.sgi_40m);
4001 				RTW_INFO("ampdu_enable = %d\n", psta->htpriv.ampdu_enable);
4002 				RTW_INFO("agg_enable_bitmap=%x, candidate_tid_bitmap=%x\n", psta->htpriv.agg_enable_bitmap, psta->htpriv.candidate_tid_bitmap);
4003 #endif /* CONFIG_80211N_HT */
4004 
4005 				sta_rx_reorder_ctl_dump(RTW_DBGDUMP, psta);
4006 			} else
4007 				RTW_INFO("can't get sta's macaddr, cur_network's macaddr:" MAC_FMT "\n", MAC_ARG(cur_network->network.MacAddress));
4008 			break;
4009 		case 0x06: {
4010 				u64 tsf = 0;
4011 
4012 				tsf = rtw_hal_get_tsftr_by_port(padapter, extra_arg);
4013 				RTW_INFO(" PORT-%d TSF :%21lld\n", extra_arg, tsf);
4014 		}
4015 			break;
4016 		case 0x07:
4017 			RTW_INFO("bSurpriseRemoved=%s, bDriverStopped=%s\n"
4018 				, dev_is_surprise_removed(adapter_to_dvobj(padapter)) ? "True" : "False"
4019 				, dev_is_drv_stopped(adapter_to_dvobj(padapter)) ? "True" : "False");
4020 			break;
4021 		case 0x08: {
4022 			struct xmit_priv *pxmitpriv = &padapter->xmitpriv;
4023 			struct recv_priv  *precvpriv = &adapter_to_dvobj(padapter)->recvpriv;
4024 
4025 			RTW_INFO("free_xmitbuf_cnt=%d, free_xmitframe_cnt=%d"
4026 				", free_xmit_extbuf_cnt=%d, free_xframe_ext_cnt=%d"
4027 				 ", free_recvframe_cnt=%d\n",
4028 				pxmitpriv->free_xmitbuf_cnt, pxmitpriv->free_xmitframe_cnt,
4029 				pxmitpriv->free_xmit_extbuf_cnt, pxmitpriv->free_xframe_ext_cnt,
4030 				 precvpriv->free_recvframe_cnt);
4031 		}
4032 			break;
4033 		case 0x09: {
4034 			int i;
4035 			_list	*plist, *phead;
4036 
4037 #ifdef CONFIG_AP_MODE
4038 			RTW_INFO_DUMP("sta_dz_bitmap:", pstapriv->sta_dz_bitmap, pstapriv->aid_bmp_len);
4039 			RTW_INFO_DUMP("tim_bitmap:", pstapriv->tim_bitmap, pstapriv->aid_bmp_len);
4040 #endif
4041 			_rtw_spinlock_bh(&pstapriv->sta_hash_lock);
4042 
4043 			for (i = 0; i < NUM_STA; i++) {
4044 				phead = &(pstapriv->sta_hash[i]);
4045 				plist = get_next(phead);
4046 
4047 				while ((rtw_end_of_queue_search(phead, plist)) == _FALSE) {
4048 					psta = LIST_CONTAINOR(plist, struct sta_info, hash_list);
4049 
4050 					plist = get_next(plist);
4051 
4052 					if (extra_arg == psta->phl_sta->aid) {
4053 						RTW_INFO("sta's macaddr:" MAC_FMT "\n", MAC_ARG(psta->phl_sta->mac_addr));
4054 						RTW_INFO("rtsen=%d, cts2slef=%d\n", psta->rtsen, psta->cts2self);
4055 						RTW_INFO("state=0x%x, aid=%d, macid=%d, raid=%d\n",
4056 							psta->state, psta->phl_sta->aid, psta->phl_sta->macid, psta->phl_sta->ra_info.rate_id);
4057 #ifdef CONFIG_80211N_HT
4058 						RTW_INFO("qos_en=%d, ht_en=%d, init_rate=%d\n", psta->qos_option, psta->htpriv.ht_option, psta->init_rate);
4059 						RTW_INFO("bwmode=%d, ch_offset=%d, sgi_20m=%d,sgi_40m=%d\n",
4060 							psta->phl_sta->chandef.bw, psta->htpriv.ch_offset, psta->htpriv.sgi_20m,
4061 							psta->htpriv.sgi_40m);
4062 						RTW_INFO("ampdu_enable = %d\n", psta->htpriv.ampdu_enable);
4063 						RTW_INFO("agg_enable_bitmap=%x, candidate_tid_bitmap=%x\n", psta->htpriv.agg_enable_bitmap, psta->htpriv.candidate_tid_bitmap);
4064 #endif /* CONFIG_80211N_HT */
4065 
4066 #ifdef CONFIG_AP_MODE
4067 						RTW_INFO("capability=0x%x\n", psta->capability);
4068 						RTW_INFO("flags=0x%x\n", psta->flags);
4069 						RTW_INFO("wpa_psk=0x%x\n", psta->wpa_psk);
4070 						RTW_INFO("wpa2_group_cipher=0x%x\n", psta->wpa2_group_cipher);
4071 						RTW_INFO("wpa2_pairwise_cipher=0x%x\n", psta->wpa2_pairwise_cipher);
4072 						RTW_INFO("qos_info=0x%x\n", psta->qos_info);
4073 #endif
4074 						RTW_INFO("dot118021XPrivacy=0x%x\n", psta->dot118021XPrivacy);
4075 
4076 						sta_rx_reorder_ctl_dump(RTW_DBGDUMP, psta);
4077 					}
4078 
4079 				}
4080 			}
4081 
4082 			_rtw_spinunlock_bh(&pstapriv->sta_hash_lock);
4083 
4084 		}
4085 			break;
4086 
4087 		case 0x0b: { /* Enable=1, Disable=0 driver control vrtl_carrier_sense. */
4088 			/* u8 driver_vcs_en; */ /* Enable=1, Disable=0 driver control vrtl_carrier_sense. */
4089 			/* u8 driver_vcs_type; */ /* force 0:disable VCS, 1:RTS-CTS, 2:CTS-to-self when vcs_en=1. */
4090 
4091 			if (arg == 0) {
4092 				RTW_INFO("disable driver ctrl vcs\n");
4093 				padapter->driver_vcs_en = 0;
4094 			} else if (arg == 1) {
4095 				RTW_INFO("enable driver ctrl vcs = %d\n", extra_arg);
4096 				padapter->driver_vcs_en = 1;
4097 
4098 				if (extra_arg > 2)
4099 					padapter->driver_vcs_type = 1;
4100 				else
4101 					padapter->driver_vcs_type = extra_arg;
4102 			}
4103 		}
4104 			break;
4105 		case 0x0c: { /* dump rx/tx packet */
4106 			if (arg == 0) {
4107 				RTW_INFO("dump rx packet (%d)\n", extra_arg);
4108 				/* pHalData->bDumpRxPkt =extra_arg;						 */
4109 				rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DUMP_RXPKT, &(extra_arg));
4110 			} else if (arg == 1) {
4111 				RTW_INFO("dump tx packet (%d)\n", extra_arg);
4112 				rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DUMP_TXPKT, &(extra_arg));
4113 			}
4114 		}
4115 			break;
4116 		case 0x0e: {
4117 			if (arg == 0) {
4118 				RTW_INFO("disable driver ctrl rx_ampdu_factor\n");
4119 				padapter->driver_rx_ampdu_factor = 0xFF;
4120 			} else if (arg == 1) {
4121 
4122 				RTW_INFO("enable driver ctrl rx_ampdu_factor = %d\n", extra_arg);
4123 
4124 				if (extra_arg > 0x03)
4125 					padapter->driver_rx_ampdu_factor = 0xFF;
4126 				else
4127 					padapter->driver_rx_ampdu_factor = extra_arg;
4128 			}
4129 		}
4130 			break;
4131 		#ifdef DBG_CONFIG_ERROR_DETECT
4132 		case 0x0f: {
4133 			if (extra_arg == 0) {
4134 				RTW_INFO("###### silent reset test.......#####\n");
4135 				rtw_hal_sreset_reset(padapter);
4136 			} else {
4137 				struct rtw_phl_com_t *phl_com = GET_PHL_COM(padapter);
4138 				struct sreset_priv *psrtpriv = &pHalData->srestpriv;
4139 				psrtpriv->dbg_trigger_point = extra_arg;
4140 			}
4141 
4142 		}
4143 			break;
4144 		case 0x15: {
4145 			struct pwrctrl_priv *pwrpriv = adapter_to_pwrctl(padapter);
4146 			RTW_INFO("==>silent resete cnts:%d\n", pwrpriv->ips_enter_cnts);
4147 		}
4148 			break;
4149 
4150 		#endif
4151 
4152 		case 0x10: /* driver version display */
4153 			dump_drv_version(RTW_DBGDUMP);
4154 			break;
4155 		case 0x11: { /* dump linked status */
4156 			int pre_mode;
4157 			pre_mode = padapter->bLinkInfoDump;
4158 			/* rtw_hal_linked_info_dump(padapter,extra_arg); */
4159 			if (extra_arg == 1 || (extra_arg == 0 && pre_mode == 1)) /* not consider pwr_saving 0: */
4160 				padapter->bLinkInfoDump = extra_arg;
4161 
4162 			else if ((extra_arg == 2) || (extra_arg == 0 && pre_mode == 2)) { /* consider power_saving */
4163 				/* RTW_INFO("rtw_hal_linked_info_dump =%s\n", (padapter->bLinkInfoDump)?"enable":"disable") */
4164 				rtw_hal_linked_info_dump(padapter, extra_arg);
4165 			}
4166 
4167 
4168 
4169 		}
4170 			break;
4171 #ifdef CONFIG_80211N_HT
4172 		case 0x12: { /* set rx_stbc */
4173 			struct registry_priv	*pregpriv = &padapter->registrypriv;
4174 			/* 0: disable, bit(0):enable 2.4g, bit(1):enable 5g, 0x3: enable both 2.4g and 5g */
4175 			/* default is set to enable 2.4GHZ for IOT issue with bufflao's AP at 5GHZ */
4176 			if (extra_arg == 0 || extra_arg == 1 || extra_arg == 2 || extra_arg == 3) {
4177 				pregpriv->rx_stbc = extra_arg;
4178 				RTW_INFO("set rx_stbc=%d\n", pregpriv->rx_stbc);
4179 			} else {
4180 				RTW_INFO("get rx_stbc=%d\n", pregpriv->rx_stbc);
4181 			}
4182 		}
4183 			break;
4184 		case 0x13: { /* set ampdu_enable */
4185 			struct registry_priv	*pregpriv = &padapter->registrypriv;
4186 			/* 0: disable, 0x1:enable */
4187 			if (extra_arg < 2) {
4188 				pregpriv->ampdu_enable = extra_arg;
4189 				RTW_INFO("set ampdu_enable=%d\n", pregpriv->ampdu_enable);
4190 			} else {
4191 				RTW_INFO("get ampdu_enable=%d\n", pregpriv->ampdu_enable);
4192 			}
4193 		}
4194 			break;
4195 #endif
4196 		case 0x14: { /* get wifi_spec */
4197 			struct registry_priv	*pregpriv = &padapter->registrypriv;
4198 			RTW_INFO("get wifi_spec=%d\n", pregpriv->wifi_spec);
4199 
4200 		}
4201 			break;
4202 
4203 #ifdef DBG_FIXED_CHAN
4204 		case 0x17: {
4205 			struct mlme_ext_priv	*pmlmeext = &(padapter->mlmeextpriv);
4206 			printk("===>  Fixed channel to %d\n", extra_arg);
4207 			pmlmeext->fixed_chan = extra_arg;
4208 
4209 		}
4210 			break;
4211 #endif
4212 #ifdef CONFIG_80211N_HT
4213 		case 0x19: {
4214 			struct registry_priv	*pregistrypriv = &padapter->registrypriv;
4215 			/* extra_arg : */
4216 			/* BIT0: Enable VHT LDPC Rx, BIT1: Enable VHT LDPC Tx, */
4217 			/* BIT4: Enable HT LDPC Rx, BIT5: Enable HT LDPC Tx */
4218 			if (arg == 0) {
4219 				RTW_INFO("driver disable LDPC\n");
4220 				pregistrypriv->ldpc_cap = 0x00;
4221 			} else if (arg == 1) {
4222 				RTW_INFO("driver set LDPC cap = 0x%x\n", extra_arg);
4223 				pregistrypriv->ldpc_cap = (u8)(extra_arg & 0x33);
4224 			}
4225 		}
4226 			break;
4227 		case 0x1a: {
4228 			struct registry_priv	*pregistrypriv = &padapter->registrypriv;
4229 			/* extra_arg : */
4230 			/* BIT0: Enable VHT STBC Rx, BIT1: Enable VHT STBC Tx, */
4231 			/* BIT4: Enable HT STBC Rx, BIT5: Enable HT STBC Tx */
4232 			if (arg == 0) {
4233 				RTW_INFO("driver disable STBC\n");
4234 				pregistrypriv->stbc_cap = 0x00;
4235 			} else if (arg == 1) {
4236 				RTW_INFO("driver set STBC cap = 0x%x\n", extra_arg);
4237 				pregistrypriv->stbc_cap = (u8)(extra_arg & 0x33);
4238 			}
4239 		}
4240 			break;
4241 #endif /* CONFIG_80211N_HT */
4242 		case 0x1b: {
4243 			struct registry_priv	*pregistrypriv = &padapter->registrypriv;
4244 
4245 			if (arg == 0) {
4246 				RTW_INFO("disable driver ctrl max_rx_rate, reset to default_rate_set\n");
4247 				init_mlme_default_rate_set(padapter);
4248 #ifdef CONFIG_80211N_HT
4249 				pregistrypriv->ht_enable = (u8)rtw_ht_enable;
4250 #endif /* CONFIG_80211N_HT */
4251 			} else if (arg == 1) {
4252 
4253 				int i;
4254 				u8 max_rx_rate;
4255 
4256 				RTW_INFO("enable driver ctrl max_rx_rate = 0x%x\n", extra_arg);
4257 
4258 				max_rx_rate = (u8)extra_arg;
4259 
4260 				if (max_rx_rate < 0xc) { /* max_rx_rate < MSC0->B or G -> disable HT */
4261 #ifdef CONFIG_80211N_HT
4262 					pregistrypriv->ht_enable = 0;
4263 #endif /* CONFIG_80211N_HT */
4264 					for (i = 0; i < NumRates; i++) {
4265 						if (pmlmeext->datarate[i] > max_rx_rate)
4266 							pmlmeext->datarate[i] = 0xff;
4267 					}
4268 
4269 				}
4270 #ifdef CONFIG_80211N_HT
4271 				else if (max_rx_rate < 0x1c) { /* mcs0~mcs15 */
4272 					u32 mcs_bitmap = 0x0;
4273 
4274 					for (i = 0; i < ((max_rx_rate + 1) - 0xc); i++)
4275 						mcs_bitmap |= BIT(i);
4276 
4277 					set_mcs_rate_by_mask(pmlmeext->default_supported_mcs_set, mcs_bitmap);
4278 				}
4279 #endif /* CONFIG_80211N_HT							 */
4280 			}
4281 		}
4282 			break;
4283 		case 0x1c: { /* enable/disable driver control AMPDU Density for peer sta's rx */
4284 			if (arg == 0) {
4285 				RTW_INFO("disable driver ctrl ampdu density\n");
4286 				padapter->driver_ampdu_spacing = 0xFF;
4287 			} else if (arg == 1) {
4288 
4289 				RTW_INFO("enable driver ctrl ampdu density = %d\n", extra_arg);
4290 
4291 				if (extra_arg > 0x07)
4292 					padapter->driver_ampdu_spacing = 0xFF;
4293 				else
4294 					padapter->driver_ampdu_spacing = extra_arg;
4295 			}
4296 		}
4297 			break;
4298 
4299 
4300 #if defined(CONFIG_SDIO_HCI) && defined(CONFIG_SDIO_INDIRECT_ACCESS) && defined(DBG_SDIO_INDIRECT_ACCESS)
4301 		case 0x1f:
4302 			{
4303 				int i, j = 0, test_cnts = 0;
4304 				static u8 test_code = 0x5A;
4305 				static u32 data_misatch_cnt = 0, d_acc_err_cnt = 0;
4306 
4307 				u32 d_data, i_data;
4308 				u32 imr;
4309 
4310 				test_cnts = extra_arg;
4311 				for (i = 0; i < test_cnts; i++) {
4312 					if (RTW_CANNOT_IO(adapter_to_dvobj(padapter)))
4313 						break;
4314 
4315 					rtw_write8(padapter, 0x07, test_code);
4316 
4317 					d_data = rtw_read32(padapter, 0x04);
4318 					imr =  rtw_read32(padapter, 0x10250014);
4319 					rtw_write32(padapter, 0x10250014, 0);
4320 					rtw_msleep_os(50);
4321 
4322 					i_data = rtw_sd_iread32(padapter, 0x04);
4323 
4324 					rtw_write32(padapter, 0x10250014, imr);
4325 
4326 					if (d_data != i_data) {
4327 						data_misatch_cnt++;
4328 						RTW_ERR("d_data :0x%08x, i_data : 0x%08x\n", d_data, i_data);
4329 					}
4330 
4331 					if (test_code != (i_data >> 24)) {
4332 						d_acc_err_cnt++;
4333 						rtw_write8(padapter, 0x07, 0xAA);
4334 						RTW_ERR("test_code :0x%02x, i_data : 0x%08x\n", test_code, i_data);
4335 					}
4336 					if ((j++) == 100) {
4337 						rtw_msleep_os(2000);
4338 						RTW_INFO(" Indirect access testing..........%d/%d\n", i, test_cnts);
4339 						j = 0;
4340 					}
4341 
4342 					test_code = ~test_code;
4343 					rtw_msleep_os(50);
4344 				}
4345 				RTW_INFO("========Indirect access test=========\n");
4346 				RTW_INFO(" test_cnts = %d\n", test_cnts);
4347 				RTW_INFO(" direct & indirect read32 data missatch cnts = %d\n", data_misatch_cnt);
4348 				RTW_INFO(" indirect rdata is not equal to wdata cnts = %d\n", d_acc_err_cnt);
4349 				RTW_INFO("========Indirect access test=========\n\n");
4350 				data_misatch_cnt = d_acc_err_cnt = 0;
4351 
4352 			}
4353 			break;
4354 #endif
4355 		case 0x20:
4356 			{
4357 				if (arg == 0xAA) {
4358 					u8 page_offset, page_num;
4359 
4360 					page_offset = (u8)(extra_arg >> 16);
4361 					page_num = (u8)(extra_arg & 0xFF);
4362 					rtw_hal_dump_rsvd_page(RTW_DBGDUMP, padapter, page_offset, page_num);
4363 				}
4364 #ifdef CONFIG_SUPPORT_FIFO_DUMP
4365 				else {
4366 					u8 fifo_sel;
4367 					u32 addr, size;
4368 
4369 					fifo_sel = (u8)(arg & 0x0F);
4370 					addr = (extra_arg >> 16) & 0xFFFF;
4371 					size = extra_arg & 0xFFFF;
4372 					rtw_dump_fifo(RTW_DBGDUMP, padapter, fifo_sel, addr, size);
4373 				}
4374 #endif
4375 			}
4376 			break;
4377 
4378 		case 0x23: {
4379 			RTW_INFO("turn %s the bNotifyChannelChange Variable\n", (extra_arg == 1) ? "on" : "off");
4380 			padapter->bNotifyChannelChange = extra_arg;
4381 			break;
4382 		}
4383 		case 0x24: {
4384 #ifdef CONFIG_P2P
4385 			RTW_INFO("turn %s the bShowGetP2PState Variable\n", (extra_arg == 1) ? "on" : "off");
4386 			padapter->bShowGetP2PState = extra_arg;
4387 #endif /* CONFIG_P2P */
4388 			break;
4389 		}
4390 #ifdef CONFIG_GPIO_API
4391 		case 0x25: { /* Get GPIO register */
4392 			/*
4393 			* dbg 0x7f250000 [gpio_num], Get gpio value, gpio_num:0~7
4394 			*/
4395 
4396 			u8 value;
4397 			RTW_INFO("Read GPIO Value  extra_arg = %d\n", extra_arg);
4398 			value = rtw_hal_get_gpio(padapter, extra_arg);
4399 			RTW_INFO("Read GPIO Value = %d\n", value);
4400 			break;
4401 		}
4402 		case 0x26: { /* Set GPIO direction */
4403 
4404 			/* dbg 0x7f26000x [y], Set gpio direction,
4405 			* x: gpio_num,4~7  y: indicate direction, 0~1
4406 			*/
4407 
4408 			int value;
4409 			RTW_INFO("Set GPIO Direction! arg = %d ,extra_arg=%d\n", arg , extra_arg);
4410 			value = rtw_hal_config_gpio(padapter, arg, extra_arg);
4411 			RTW_INFO("Set GPIO Direction %s\n", (value == -1) ? "Fail!!!" : "Success");
4412 			break;
4413 		}
4414 		case 0x27: { /* Set GPIO output direction value */
4415 			/*
4416 			* dbg 0x7f27000x [y], Set gpio output direction value,
4417 			* x: gpio_num,4~7  y: indicate direction, 0~1
4418 			*/
4419 
4420 			int value;
4421 			RTW_INFO("Set GPIO Value! arg = %d ,extra_arg=%d\n", arg , extra_arg);
4422 			value = rtw_hal_set_gpio_output_value(padapter, arg, extra_arg);
4423 			RTW_INFO("Set GPIO Value %s\n", (value == -1) ? "Fail!!!" : "Success");
4424 			break;
4425 		}
4426 #endif
4427 #ifdef DBG_CMD_QUEUE
4428 		case 0x28: {
4429 			dump_cmd_id = extra_arg;
4430 			RTW_INFO("dump_cmd_id:%d\n", dump_cmd_id);
4431 		}
4432 			break;
4433 #endif /* DBG_CMD_QUEUE */
4434 		case 0xaa: {
4435 			if ((extra_arg & 0x7F) > 0x3F)
4436 				extra_arg = 0xFF;
4437 			RTW_INFO("chang data rate to :0x%02x\n", extra_arg);
4438 			padapter->fix_rate = extra_arg;
4439 		}
4440 			break;
4441 		case 0xdd: { /* registers dump , 0 for mac reg,1 for bb reg, 2 for rf reg */
4442 			if (extra_arg == 0)
4443 				mac_reg_dump(RTW_DBGDUMP, padapter);
4444 			else if (extra_arg == 1)
4445 				bb_reg_dump(RTW_DBGDUMP, padapter);
4446 			else if (extra_arg == 2)
4447 				rf_reg_dump(RTW_DBGDUMP, padapter);
4448 			else if (extra_arg == 11)
4449 				bb_reg_dump_ex(RTW_DBGDUMP, padapter);
4450 		}
4451 			break;
4452 
4453 		case 0xee: {
4454 			RTW_INFO(" === please control /proc  to trun on/off PHYDM func ===\n");
4455 		}
4456 			break;
4457 
4458 		case 0xfd:
4459 			rtw_write8(padapter, 0xc50, arg);
4460 			RTW_INFO("wr(0xc50)=0x%x\n", rtw_read8(padapter, 0xc50));
4461 			rtw_write8(padapter, 0xc58, arg);
4462 			RTW_INFO("wr(0xc58)=0x%x\n", rtw_read8(padapter, 0xc58));
4463 			break;
4464 		case 0xfe:
4465 			RTW_INFO("rd(0xc50)=0x%x\n", rtw_read8(padapter, 0xc50));
4466 			RTW_INFO("rd(0xc58)=0x%x\n", rtw_read8(padapter, 0xc58));
4467 			break;
4468 		case 0xff: {
4469 			RTW_INFO("dbg(0x210)=0x%x\n", rtw_read32(padapter, 0x210));
4470 			RTW_INFO("dbg(0x608)=0x%x\n", rtw_read32(padapter, 0x608));
4471 			RTW_INFO("dbg(0x280)=0x%x\n", rtw_read32(padapter, 0x280));
4472 			RTW_INFO("dbg(0x284)=0x%x\n", rtw_read32(padapter, 0x284));
4473 			RTW_INFO("dbg(0x288)=0x%x\n", rtw_read32(padapter, 0x288));
4474 
4475 			RTW_INFO("dbg(0x664)=0x%x\n", rtw_read32(padapter, 0x664));
4476 
4477 
4478 			RTW_INFO("\n");
4479 
4480 			RTW_INFO("dbg(0x430)=0x%x\n", rtw_read32(padapter, 0x430));
4481 			RTW_INFO("dbg(0x438)=0x%x\n", rtw_read32(padapter, 0x438));
4482 
4483 			RTW_INFO("dbg(0x440)=0x%x\n", rtw_read32(padapter, 0x440));
4484 
4485 			RTW_INFO("dbg(0x458)=0x%x\n", rtw_read32(padapter, 0x458));
4486 
4487 			RTW_INFO("dbg(0x484)=0x%x\n", rtw_read32(padapter, 0x484));
4488 			RTW_INFO("dbg(0x488)=0x%x\n", rtw_read32(padapter, 0x488));
4489 
4490 			RTW_INFO("dbg(0x444)=0x%x\n", rtw_read32(padapter, 0x444));
4491 			RTW_INFO("dbg(0x448)=0x%x\n", rtw_read32(padapter, 0x448));
4492 			RTW_INFO("dbg(0x44c)=0x%x\n", rtw_read32(padapter, 0x44c));
4493 			RTW_INFO("dbg(0x450)=0x%x\n", rtw_read32(padapter, 0x450));
4494 		}
4495 			break;
4496 		}
4497 		break;
4498 	default:
4499 		RTW_INFO("error dbg cmd!\n");
4500 		break;
4501 	}
4502 
4503 
4504 	return ret;
4505 
4506 }
4507 #endif
4508 
4509 static int wpa_set_param(struct net_device *dev, u8 name, u32 value)
4510 {
4511 	uint ret = 0;
4512 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4513 
4514 	switch (name) {
4515 	case IEEE_PARAM_WPA_ENABLED:
4516 
4517 		padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_8021X; /* 802.1x */
4518 
4519 		/* ret = ieee80211_wpa_enable(ieee, value); */
4520 
4521 		switch ((value) & 0xff) {
4522 		case 1: /* WPA */
4523 			padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPAPSK; /* WPA_PSK */
4524 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
4525 			break;
4526 		case 2: /* WPA2 */
4527 			padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPA2PSK; /* WPA2_PSK */
4528 			padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
4529 			break;
4530 		}
4531 
4532 
4533 		break;
4534 
4535 	case IEEE_PARAM_TKIP_COUNTERMEASURES:
4536 		/* ieee->tkip_countermeasures=value; */
4537 		break;
4538 
4539 	case IEEE_PARAM_DROP_UNENCRYPTED: {
4540 		/* HACK:
4541 		 *
4542 		 * wpa_supplicant calls set_wpa_enabled when the driver
4543 		 * is loaded and unloaded, regardless of if WPA is being
4544 		 * used.  No other calls are made which can be used to
4545 		 * determine if encryption will be used or not prior to
4546 		 * association being expected.  If encryption is not being
4547 		 * used, drop_unencrypted is set to false, else true -- we
4548 		 * can use this to determine if the CAP_PRIVACY_ON bit should
4549 		 * be set.
4550 		 */
4551 
4552 #if 0
4553 		struct ieee80211_security sec = {
4554 			.flags = SEC_ENABLED,
4555 			.enabled = value,
4556 		};
4557 		ieee->drop_unencrypted = value;
4558 		/* We only change SEC_LEVEL for open mode. Others
4559 		 * are set by ipw_wpa_set_encryption.
4560 		 */
4561 		if (!value) {
4562 			sec.flags |= SEC_LEVEL;
4563 			sec.level = SEC_LEVEL_0;
4564 		} else {
4565 			sec.flags |= SEC_LEVEL;
4566 			sec.level = SEC_LEVEL_1;
4567 		}
4568 		if (ieee->set_security)
4569 			ieee->set_security(ieee->dev, &sec);
4570 #endif
4571 		break;
4572 
4573 	}
4574 	case IEEE_PARAM_PRIVACY_INVOKED:
4575 
4576 		/* ieee->privacy_invoked=value; */
4577 
4578 		break;
4579 
4580 	case IEEE_PARAM_AUTH_ALGS:
4581 
4582 		ret = wpa_set_auth_algs(dev, value);
4583 
4584 		break;
4585 
4586 	case IEEE_PARAM_IEEE_802_1X:
4587 
4588 		/* ieee->ieee802_1x=value;		 */
4589 
4590 		break;
4591 
4592 	case IEEE_PARAM_WPAX_SELECT:
4593 
4594 		/* added for WPA2 mixed mode */
4595 		/*RTW_WARN("------------------------>wpax value = %x\n", value);*/
4596 		/*
4597 		spin_lock_irqsave(&ieee->wpax_suitlist_lock,flags);
4598 		ieee->wpax_type_set = 1;
4599 		ieee->wpax_type_notify = value;
4600 		spin_unlock_irqrestore(&ieee->wpax_suitlist_lock,flags);
4601 		*/
4602 
4603 		break;
4604 
4605 	default:
4606 
4607 
4608 
4609 		ret = -EOPNOTSUPP;
4610 
4611 
4612 		break;
4613 
4614 	}
4615 
4616 	return ret;
4617 
4618 }
4619 
4620 static int wpa_mlme(struct net_device *dev, u32 command, u32 reason)
4621 {
4622 	int ret = 0;
4623 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4624 
4625 	switch (command) {
4626 	case IEEE_MLME_STA_DEAUTH:
4627 
4628 		if (!rtw_set_802_11_disassociate(padapter))
4629 			ret = -1;
4630 
4631 		break;
4632 
4633 	case IEEE_MLME_STA_DISASSOC:
4634 
4635 		if (!rtw_set_802_11_disassociate(padapter))
4636 			ret = -1;
4637 
4638 		break;
4639 
4640 	default:
4641 		ret = -EOPNOTSUPP;
4642 		break;
4643 	}
4644 	return ret;
4645 
4646 }
4647 
4648 static int wpa_supplicant_ioctl(struct net_device *dev, struct iw_point *p)
4649 {
4650 	struct ieee_param *param;
4651 	uint ret = 0;
4652 
4653 	/* down(&ieee->wx_sem);	 */
4654 
4655 	if (p->length < sizeof(struct ieee_param) || !p->pointer) {
4656 		ret = -EINVAL;
4657 		goto out;
4658 	}
4659 
4660 	param = (struct ieee_param *)rtw_malloc(p->length);
4661 	if (param == NULL) {
4662 		ret = -ENOMEM;
4663 		goto out;
4664 	}
4665 
4666 	if (copy_from_user(param, p->pointer, p->length)) {
4667 		rtw_mfree((u8 *)param, p->length);
4668 		ret = -EFAULT;
4669 		goto out;
4670 	}
4671 
4672 	switch (param->cmd) {
4673 
4674 	case IEEE_CMD_SET_WPA_PARAM:
4675 		ret = wpa_set_param(dev, param->u.wpa_param.name, param->u.wpa_param.value);
4676 		break;
4677 
4678 	case IEEE_CMD_SET_WPA_IE:
4679 		/* ret = wpa_set_wpa_ie(dev, param, p->length); */
4680 		ret =  rtw_set_wpa_ie((_adapter *)rtw_netdev_priv(dev), (char *)param->u.wpa_ie.data, (u16)param->u.wpa_ie.len);
4681 		break;
4682 
4683 	case IEEE_CMD_SET_ENCRYPTION:
4684 		ret = wpa_set_encryption(dev, param, p->length);
4685 		break;
4686 
4687 	case IEEE_CMD_MLME:
4688 		ret = wpa_mlme(dev, param->u.mlme.command, param->u.mlme.reason_code);
4689 		break;
4690 
4691 	default:
4692 		RTW_INFO("Unknown WPA supplicant request: %d\n", param->cmd);
4693 		ret = -EOPNOTSUPP;
4694 		break;
4695 
4696 	}
4697 
4698 	if (ret == 0 && copy_to_user(p->pointer, param, p->length))
4699 		ret = -EFAULT;
4700 
4701 	rtw_mfree((u8 *)param, p->length);
4702 
4703 out:
4704 
4705 	/* up(&ieee->wx_sem); */
4706 
4707 	return ret;
4708 
4709 }
4710 
4711 #ifdef CONFIG_AP_MODE
4712 static int rtw_set_encryption(struct net_device *dev, struct ieee_param *param, u32 param_len)
4713 {
4714 	int ret = 0;
4715 	u32 wep_key_idx, wep_key_len, wep_total_len = 0;
4716 	NDIS_802_11_WEP	*pwep = NULL;
4717 	struct sta_info *psta = NULL, *pbcmc_sta = NULL;
4718 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4719 	struct mlme_priv	*pmlmepriv = &padapter->mlmepriv;
4720 	struct security_priv *psecuritypriv = &(padapter->securitypriv);
4721 	struct sta_priv *pstapriv = &padapter->stapriv;
4722 
4723 	RTW_INFO("%s\n", __FUNCTION__);
4724 
4725 	param->u.crypt.err = 0;
4726 	param->u.crypt.alg[IEEE_CRYPT_ALG_NAME_LEN - 1] = '\0';
4727 
4728 	/* sizeof(struct ieee_param) = 64 bytes; */
4729 	/* if (param_len !=  (u32) ((u8 *) param->u.crypt.key - (u8 *) param) + param->u.crypt.key_len) */
4730 	if (param_len !=  sizeof(struct ieee_param) + param->u.crypt.key_len) {
4731 		ret =  -EINVAL;
4732 		goto exit;
4733 	}
4734 
4735 	if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
4736 	    param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
4737 	    param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) {
4738 		if (param->u.crypt.idx >= WEP_KEYS
4739 #ifdef CONFIG_IEEE80211W
4740 		    && param->u.crypt.idx > BIP_MAX_KEYID
4741 #endif /* CONFIG_IEEE80211W */
4742 		   ) {
4743 			ret = -EINVAL;
4744 			goto exit;
4745 		}
4746 	} else {
4747 		psta = rtw_get_stainfo(pstapriv, param->sta_addr);
4748 		if (!psta) {
4749 			/* ret = -EINVAL; */
4750 			RTW_INFO("rtw_set_encryption(), sta has already been removed or never been added\n");
4751 			goto exit;
4752 		}
4753 	}
4754 
4755 	if (strcmp(param->u.crypt.alg, "none") == 0 && (psta == NULL)) {
4756 		/* todo:clear default encryption keys */
4757 
4758 		psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
4759 		psecuritypriv->ndisencryptstatus = Ndis802_11EncryptionDisabled;
4760 		psecuritypriv->dot11PrivacyAlgrthm = _NO_PRIVACY_;
4761 		psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
4762 
4763 		RTW_INFO("clear default encryption keys, keyid=%d\n", param->u.crypt.idx);
4764 
4765 		goto exit;
4766 	}
4767 
4768 
4769 	if (strcmp(param->u.crypt.alg, "WEP") == 0 && (psta == NULL)) {
4770 		RTW_INFO("r871x_set_encryption, crypt.alg = WEP\n");
4771 
4772 		wep_key_idx = param->u.crypt.idx;
4773 		wep_key_len = param->u.crypt.key_len;
4774 
4775 		RTW_INFO("r871x_set_encryption, wep_key_idx=%d, len=%d\n", wep_key_idx, wep_key_len);
4776 
4777 		if ((wep_key_idx >= WEP_KEYS) || (wep_key_len <= 0)) {
4778 			ret = -EINVAL;
4779 			goto exit;
4780 		}
4781 
4782 
4783 		if (wep_key_len > 0) {
4784 			wep_key_len = wep_key_len <= 5 ? 5 : 13;
4785 			wep_total_len = wep_key_len + FIELD_OFFSET(NDIS_802_11_WEP, KeyMaterial);
4786 			pwep = (NDIS_802_11_WEP *)rtw_malloc(wep_total_len);
4787 			if (pwep == NULL) {
4788 				RTW_INFO(" r871x_set_encryption: pwep allocate fail !!!\n");
4789 				goto exit;
4790 			}
4791 
4792 			_rtw_memset(pwep, 0, wep_total_len);
4793 
4794 			pwep->KeyLength = wep_key_len;
4795 			pwep->Length = wep_total_len;
4796 
4797 		}
4798 
4799 		pwep->KeyIndex = wep_key_idx;
4800 
4801 		_rtw_memcpy(pwep->KeyMaterial,  param->u.crypt.key, pwep->KeyLength);
4802 
4803 		if (param->u.crypt.set_tx) {
4804 			RTW_INFO("wep, set_tx=1\n");
4805 
4806 			psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
4807 			psecuritypriv->ndisencryptstatus = Ndis802_11Encryption1Enabled;
4808 			psecuritypriv->dot11PrivacyAlgrthm = _WEP40_;
4809 			psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
4810 
4811 			if (pwep->KeyLength == 13) {
4812 				psecuritypriv->dot11PrivacyAlgrthm = _WEP104_;
4813 				psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
4814 			}
4815 
4816 
4817 			psecuritypriv->dot11PrivacyKeyIndex = wep_key_idx;
4818 
4819 			_rtw_memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
4820 
4821 			psecuritypriv->dot11DefKeylen[wep_key_idx] = pwep->KeyLength;
4822 
4823 			rtw_ap_set_wep_key(padapter, pwep->KeyMaterial, pwep->KeyLength, wep_key_idx, 1);
4824 		} else {
4825 			RTW_INFO("wep, set_tx=0\n");
4826 
4827 			/* don't update "psecuritypriv->dot11PrivacyAlgrthm" and  */
4828 			/* "psecuritypriv->dot11PrivacyKeyIndex=keyid", but can rtw_set_key to cam */
4829 
4830 			_rtw_memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
4831 
4832 			psecuritypriv->dot11DefKeylen[wep_key_idx] = pwep->KeyLength;
4833 
4834 			rtw_ap_set_wep_key(padapter, pwep->KeyMaterial, pwep->KeyLength, wep_key_idx, 0);
4835 		}
4836 
4837 		goto exit;
4838 
4839 	}
4840 
4841 
4842 	if (!psta && check_fwstate(pmlmepriv, WIFI_AP_STATE)) /*  */ { /* group key */
4843 		if (param->u.crypt.set_tx == 1) {
4844 			if (strcmp(param->u.crypt.alg, "WEP") == 0) {
4845 				RTW_INFO(FUNC_ADPT_FMT" set WEP TX GTK idx:%u, len:%u\n"
4846 					, FUNC_ADPT_ARG(padapter), param->u.crypt.idx, param->u.crypt.key_len);
4847 				_rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
4848 				psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
4849 				if (param->u.crypt.key_len == 13)
4850 					psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
4851 
4852 			} else if (strcmp(param->u.crypt.alg, "TKIP") == 0) {
4853 				RTW_INFO(FUNC_ADPT_FMT" set TKIP TX GTK idx:%u, len:%u\n"
4854 					, FUNC_ADPT_ARG(padapter), param->u.crypt.idx, param->u.crypt.key_len);
4855 				psecuritypriv->dot118021XGrpPrivacy = _TKIP_;
4856 				_rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
4857 				/* set mic key */
4858 				_rtw_memcpy(psecuritypriv->dot118021XGrptxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[16]), 8);
4859 				_rtw_memcpy(psecuritypriv->dot118021XGrprxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[24]), 8);
4860 				psecuritypriv->busetkipkey = _TRUE;
4861 
4862 			} else if (strcmp(param->u.crypt.alg, "CCMP") == 0) {
4863 				RTW_INFO(FUNC_ADPT_FMT" set CCMP TX GTK idx:%u, len:%u\n"
4864 					, FUNC_ADPT_ARG(padapter), param->u.crypt.idx, param->u.crypt.key_len);
4865 				psecuritypriv->dot118021XGrpPrivacy = _AES_;
4866 				_rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
4867 
4868 			#ifdef CONFIG_IEEE80211W
4869 			} else if (strcmp(param->u.crypt.alg, "BIP") == 0) {
4870 				RTW_INFO(FUNC_ADPT_FMT" set TX IGTK idx:%u, len:%u\n"
4871 					, FUNC_ADPT_ARG(padapter), param->u.crypt.idx, param->u.crypt.key_len);
4872 				_rtw_memcpy(padapter->securitypriv.dot11wBIPKey[param->u.crypt.idx].skey, param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
4873 				psecuritypriv->dot11wBIPKeyid = param->u.crypt.idx;
4874 				psecuritypriv->dot11wBIPtxpn.val = RTW_GET_LE64(param->u.crypt.seq);
4875 				psecuritypriv->binstallBIPkey = _TRUE;
4876 				goto exit;
4877 			#endif /* CONFIG_IEEE80211W */
4878 
4879 			} else if (strcmp(param->u.crypt.alg, "none") == 0) {
4880 				RTW_INFO(FUNC_ADPT_FMT" clear group key, idx:%u\n"
4881 					, FUNC_ADPT_ARG(padapter), param->u.crypt.idx);
4882 				psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
4883 			} else {
4884 				RTW_WARN(FUNC_ADPT_FMT" set group key, not support\n"
4885 					, FUNC_ADPT_ARG(padapter));
4886 				goto exit;
4887 			}
4888 
4889 			psecuritypriv->dot118021XGrpKeyid = param->u.crypt.idx;
4890 			pbcmc_sta = rtw_get_bcmc_stainfo(padapter);
4891 			if (pbcmc_sta) {
4892 				pbcmc_sta->dot11txpn.val = RTW_GET_LE64(param->u.crypt.seq);
4893 				pbcmc_sta->ieee8021x_blocked = _FALSE;
4894 				pbcmc_sta->dot118021XPrivacy = psecuritypriv->dot118021XGrpPrivacy; /* rx will use bmc_sta's dot118021XPrivacy			 */
4895 			}
4896 			psecuritypriv->binstallGrpkey = _TRUE;
4897 			psecuritypriv->dot11PrivacyAlgrthm = psecuritypriv->dot118021XGrpPrivacy;/* !!! */
4898 
4899 			rtw_ap_set_group_key(padapter, param->u.crypt.key, psecuritypriv->dot118021XGrpPrivacy, param->u.crypt.idx);
4900 		}
4901 
4902 		goto exit;
4903 
4904 	}
4905 
4906 	if (psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X && psta) { /* psk/802_1x */
4907 		if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
4908 			if (param->u.crypt.set_tx == 1) {
4909 				_rtw_memcpy(psta->dot118021x_UncstKey.skey,  param->u.crypt.key, (param->u.crypt.key_len > 16 ? 16 : param->u.crypt.key_len));
4910 
4911 				if (strcmp(param->u.crypt.alg, "WEP") == 0) {
4912 					RTW_INFO(FUNC_ADPT_FMT" set WEP PTK of "MAC_FMT" idx:%u, len:%u\n"
4913 						, FUNC_ADPT_ARG(padapter), MAC_ARG(psta->phl_sta->mac_addr)
4914 						, param->u.crypt.idx, param->u.crypt.key_len);
4915 					psta->dot118021XPrivacy = _WEP40_;
4916 					if (param->u.crypt.key_len == 13)
4917 						psta->dot118021XPrivacy = _WEP104_;
4918 
4919 				} else if (strcmp(param->u.crypt.alg, "TKIP") == 0) {
4920 					RTW_INFO(FUNC_ADPT_FMT" set TKIP PTK of "MAC_FMT" idx:%u, len:%u\n"
4921 						, FUNC_ADPT_ARG(padapter), MAC_ARG(psta->phl_sta->mac_addr)
4922 						, param->u.crypt.idx, param->u.crypt.key_len);
4923 					psta->dot118021XPrivacy = _TKIP_;
4924 					/* set mic key */
4925 					_rtw_memcpy(psta->dot11tkiptxmickey.skey, &(param->u.crypt.key[16]), 8);
4926 					_rtw_memcpy(psta->dot11tkiprxmickey.skey, &(param->u.crypt.key[24]), 8);
4927 					psecuritypriv->busetkipkey = _TRUE;
4928 
4929 				} else if (strcmp(param->u.crypt.alg, "CCMP") == 0) {
4930 					RTW_INFO(FUNC_ADPT_FMT" set CCMP PTK of "MAC_FMT" idx:%u, len:%u\n"
4931 						, FUNC_ADPT_ARG(padapter), MAC_ARG(psta->phl_sta->mac_addr)
4932 						, param->u.crypt.idx, param->u.crypt.key_len);
4933 					psta->dot118021XPrivacy = _AES_;
4934 
4935 				} else if (strcmp(param->u.crypt.alg, "none") == 0) {
4936 					RTW_INFO(FUNC_ADPT_FMT" clear pairwise key of "MAC_FMT" idx:%u\n"
4937 						, FUNC_ADPT_ARG(padapter), MAC_ARG(psta->phl_sta->mac_addr)
4938 						, param->u.crypt.idx);
4939 					psta->dot118021XPrivacy = _NO_PRIVACY_;
4940 
4941 				} else {
4942 					RTW_WARN(FUNC_ADPT_FMT" set pairwise key of "MAC_FMT", not support\n"
4943 						, FUNC_ADPT_ARG(padapter), MAC_ARG(psta->phl_sta->mac_addr));
4944 					goto exit;
4945 				}
4946 
4947 				psta->dot11txpn.val = RTW_GET_LE64(param->u.crypt.seq);
4948 				psta->dot11rxpn.val = RTW_GET_LE64(param->u.crypt.seq);
4949 				psta->ieee8021x_blocked = _FALSE;
4950 
4951 				if (psta->dot118021XPrivacy != _NO_PRIVACY_) {
4952 					psta->bpairwise_key_installed = _TRUE;
4953 
4954 					/* WPA2 key-handshake has completed */
4955 					if (psecuritypriv->ndisauthtype == Ndis802_11AuthModeWPA2PSK)
4956 						psta->state &= (~WIFI_UNDER_KEY_HANDSHAKE);
4957 				}
4958 
4959 				rtw_ap_set_pairwise_key(padapter, psta);
4960 			} else {
4961 				RTW_WARN(FUNC_ADPT_FMT" set group key of "MAC_FMT", not support\n"
4962 					, FUNC_ADPT_ARG(padapter), MAC_ARG(psta->phl_sta->mac_addr));
4963 				goto exit;
4964 			}
4965 
4966 		}
4967 
4968 	}
4969 
4970 exit:
4971 
4972 	if (pwep)
4973 		rtw_mfree((u8 *)pwep, wep_total_len);
4974 
4975 	return ret;
4976 
4977 }
4978 
4979 static int rtw_set_beacon(struct net_device *dev, struct ieee_param *param, int len)
4980 {
4981 	int ret = 0;
4982 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4983 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
4984 	struct sta_priv *pstapriv = &padapter->stapriv;
4985 	unsigned char *pbuf = param->u.bcn_ie.buf;
4986 
4987 
4988 	RTW_INFO("%s, len=%d\n", __FUNCTION__, len);
4989 
4990 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
4991 		return -EINVAL;
4992 
4993 	_rtw_memcpy(&pstapriv->max_num_sta, param->u.bcn_ie.reserved, 2);
4994 
4995 	if ((pstapriv->max_num_sta > NUM_STA) || (pstapriv->max_num_sta <= 0))
4996 		pstapriv->max_num_sta = NUM_STA;
4997 
4998 
4999 	if (rtw_check_beacon_data(padapter, pbuf, (len - 12 - 2)) == _SUCCESS) /* 12 = param header, 2:no packed */
5000 		ret = 0;
5001 	else
5002 		ret = -EINVAL;
5003 
5004 
5005 	return ret;
5006 
5007 }
5008 
5009 static int rtw_hostapd_sta_flush(struct net_device *dev)
5010 {
5011 	/* _list	*phead, *plist; */
5012 	int ret = 0;
5013 	/* struct sta_info *psta = NULL; */
5014 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5015 	/* struct sta_priv *pstapriv = &padapter->stapriv; */
5016 
5017 	RTW_INFO("%s\n", __FUNCTION__);
5018 
5019 	flush_all_cam_entry(padapter, PHL_CMD_WAIT, 50);	/* clear CAM */
5020 #ifdef CONFIG_AP_MODE
5021 	ret = rtw_sta_flush(padapter, _TRUE);
5022 #endif
5023 	return ret;
5024 
5025 }
5026 
5027 static int rtw_add_sta(struct net_device *dev, struct ieee_param *param)
5028 {
5029 	int ret = 0;
5030 	struct sta_info *psta = NULL;
5031 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5032 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5033 	struct sta_priv *pstapriv = &padapter->stapriv;
5034 
5035 	RTW_INFO("rtw_add_sta(aid=%d)=" MAC_FMT "\n", param->u.add_sta.aid, MAC_ARG(param->sta_addr));
5036 
5037 	if (check_fwstate(pmlmepriv, (WIFI_ASOC_STATE | WIFI_AP_STATE)) != _TRUE)
5038 		return -EINVAL;
5039 
5040 	if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
5041 	    param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
5042 	    param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff)
5043 		return -EINVAL;
5044 
5045 #if 0
5046 	psta = rtw_get_stainfo(pstapriv, param->sta_addr);
5047 	if (psta) {
5048 		RTW_INFO("rtw_add_sta(), free has been added psta=%p\n", psta);
5049 		/* _rtw_spinlock_bh(&(pstapriv->sta_hash_lock));		 */
5050 		rtw_free_stainfo(padapter,  psta);
5051 		/* _rtw_spinunlock_bh(&(pstapriv->sta_hash_lock)); */
5052 
5053 		psta = NULL;
5054 	}
5055 #endif
5056 	/* psta = rtw_alloc_stainfo(pstapriv, param->sta_addr); */
5057 	psta = rtw_get_stainfo(pstapriv, param->sta_addr);
5058 	if (psta) {
5059 		int flags = param->u.add_sta.flags;
5060 
5061 		/* RTW_INFO("rtw_add_sta(), init sta's variables, psta=%p\n", psta); */
5062 
5063 		psta->phl_sta->aid = param->u.add_sta.aid;/* aid=1~2007 */
5064 
5065 		_rtw_memcpy(psta->bssrateset, param->u.add_sta.tx_supp_rates, 16);
5066 
5067 
5068 		/* check wmm cap. */
5069 		if (WLAN_STA_WME & flags)
5070 			psta->qos_option = 1;
5071 		else
5072 			psta->qos_option = 0;
5073 
5074 		if (pmlmepriv->qospriv.qos_option == 0)
5075 			psta->qos_option = 0;
5076 
5077 
5078 #ifdef CONFIG_80211N_HT
5079 		/* chec 802.11n ht cap. */
5080 		if (padapter->registrypriv.ht_enable &&
5081 			is_supported_ht(padapter->registrypriv.wireless_mode) &&
5082 			(WLAN_STA_HT & flags)) {
5083 			psta->htpriv.ht_option = _TRUE;
5084 			psta->qos_option = 1;
5085 			_rtw_memcpy((void *)&psta->htpriv.ht_cap, (void *)&param->u.add_sta.ht_cap, sizeof(struct rtw_ieee80211_ht_cap));
5086 		} else
5087 			psta->htpriv.ht_option = _FALSE;
5088 
5089 		if (pmlmepriv->htpriv.ht_option == _FALSE)
5090 			psta->htpriv.ht_option = _FALSE;
5091 
5092 #endif
5093 
5094 
5095 		update_sta_info_apmode(padapter, psta);
5096 
5097 
5098 	} else
5099 		ret = -ENOMEM;
5100 
5101 	return ret;
5102 
5103 }
5104 
5105 static int rtw_del_sta(struct net_device *dev, struct ieee_param *param)
5106 {
5107 	int ret = 0;
5108 	struct sta_info *psta = NULL;
5109 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5110 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5111 	struct sta_priv *pstapriv = &padapter->stapriv;
5112 
5113 	RTW_INFO("rtw_del_sta=" MAC_FMT "\n", MAC_ARG(param->sta_addr));
5114 
5115 	if (check_fwstate(pmlmepriv, (WIFI_ASOC_STATE | WIFI_AP_STATE)) != _TRUE)
5116 		return -EINVAL;
5117 
5118 	if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
5119 	    param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
5120 	    param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff)
5121 		return -EINVAL;
5122 
5123 	psta = rtw_get_stainfo(pstapriv, param->sta_addr);
5124 	if (psta) {
5125 		u8 updated = _FALSE;
5126 
5127 		/* RTW_INFO("free psta=%p, aid=%d\n", psta, psta->phl_sta->aid); */
5128 
5129 		_rtw_spinlock_bh(&pstapriv->asoc_list_lock);
5130 		if (rtw_is_list_empty(&psta->asoc_list) == _FALSE) {
5131 			rtw_list_delete(&psta->asoc_list);
5132 			pstapriv->asoc_list_cnt--;
5133 			#ifdef CONFIG_RTW_TOKEN_BASED_XMIT
5134 			if (psta->tbtx_enable)
5135 				pstapriv->tbtx_asoc_list_cnt--;
5136 			#endif
5137 			updated = ap_free_sta(padapter, psta, _TRUE, WLAN_REASON_DEAUTH_LEAVING, _TRUE, _FALSE);
5138 
5139 		}
5140 		_rtw_spinunlock_bh(&pstapriv->asoc_list_lock);
5141 
5142 		associated_clients_update(padapter, updated, STA_INFO_UPDATE_ALL);
5143 
5144 		psta = NULL;
5145 
5146 	} else {
5147 		RTW_INFO("rtw_del_sta(), sta has already been removed or never been added\n");
5148 
5149 		/* ret = -1; */
5150 	}
5151 
5152 
5153 	return ret;
5154 
5155 }
5156 
5157 static int rtw_ioctl_get_sta_data(struct net_device *dev, struct ieee_param *param, int len)
5158 {
5159 	int ret = 0;
5160 	struct sta_info *psta = NULL;
5161 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5162 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5163 	struct sta_priv *pstapriv = &padapter->stapriv;
5164 	struct ieee_param_ex *param_ex = (struct ieee_param_ex *)param;
5165 	struct sta_data *psta_data = (struct sta_data *)param_ex->data;
5166 
5167 	RTW_INFO("rtw_ioctl_get_sta_info, sta_addr: " MAC_FMT "\n", MAC_ARG(param_ex->sta_addr));
5168 
5169 	if (check_fwstate(pmlmepriv, (WIFI_ASOC_STATE | WIFI_AP_STATE)) != _TRUE)
5170 		return -EINVAL;
5171 
5172 	if (param_ex->sta_addr[0] == 0xff && param_ex->sta_addr[1] == 0xff &&
5173 	    param_ex->sta_addr[2] == 0xff && param_ex->sta_addr[3] == 0xff &&
5174 	    param_ex->sta_addr[4] == 0xff && param_ex->sta_addr[5] == 0xff)
5175 		return -EINVAL;
5176 
5177 	psta = rtw_get_stainfo(pstapriv, param_ex->sta_addr);
5178 	if (psta) {
5179 #if 0
5180 		struct {
5181 			u16 aid;
5182 			u16 capability;
5183 			int flags;
5184 			u32 sta_set;
5185 			u8 tx_supp_rates[16];
5186 			u32 tx_supp_rates_len;
5187 			struct rtw_ieee80211_ht_cap ht_cap;
5188 			u64	rx_pkts;
5189 			u64	rx_bytes;
5190 			u64	rx_drops;
5191 			u64	tx_pkts;
5192 			u64	tx_bytes;
5193 			u64	tx_drops;
5194 		} get_sta;
5195 #endif
5196 		psta_data->aid = (u16)psta->phl_sta->aid;
5197 		psta_data->capability = psta->capability;
5198 		psta_data->flags = psta->flags;
5199 
5200 		/*
5201 				nonerp_set : BIT(0)
5202 				no_short_slot_time_set : BIT(1)
5203 				no_short_preamble_set : BIT(2)
5204 				no_ht_gf_set : BIT(3)
5205 				no_ht_set : BIT(4)
5206 				ht_20mhz_set : BIT(5)
5207 		*/
5208 
5209 		psta_data->sta_set = ((psta->nonerp_set) |
5210 				      (psta->no_short_slot_time_set << 1) |
5211 				      (psta->no_short_preamble_set << 2) |
5212 				      (psta->no_ht_gf_set << 3) |
5213 				      (psta->no_ht_set << 4) |
5214 				      (psta->ht_20mhz_set << 5));
5215 
5216 		psta_data->tx_supp_rates_len =  psta->bssratelen;
5217 		_rtw_memcpy(psta_data->tx_supp_rates, psta->bssrateset, psta->bssratelen);
5218 #ifdef CONFIG_80211N_HT
5219 		if(padapter->registrypriv.ht_enable && is_supported_ht(padapter->registrypriv.wireless_mode))
5220 			_rtw_memcpy(&psta_data->ht_cap, &psta->htpriv.ht_cap, sizeof(struct rtw_ieee80211_ht_cap));
5221 #endif /* CONFIG_80211N_HT */
5222 		psta_data->rx_pkts = psta->sta_stats.rx_data_pkts;
5223 		psta_data->rx_bytes = psta->sta_stats.rx_bytes;
5224 		psta_data->rx_drops = psta->sta_stats.rx_drops;
5225 
5226 		psta_data->tx_pkts = psta->sta_stats.tx_pkts;
5227 		psta_data->tx_bytes = psta->sta_stats.tx_bytes;
5228 		psta_data->tx_drops = psta->sta_stats.tx_drops;
5229 
5230 
5231 	} else
5232 		ret = -1;
5233 
5234 	return ret;
5235 
5236 }
5237 
5238 static int rtw_get_sta_wpaie(struct net_device *dev, struct ieee_param *param)
5239 {
5240 	int ret = 0;
5241 	struct sta_info *psta = NULL;
5242 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5243 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5244 	struct sta_priv *pstapriv = &padapter->stapriv;
5245 
5246 	RTW_INFO("rtw_get_sta_wpaie, sta_addr: " MAC_FMT "\n", MAC_ARG(param->sta_addr));
5247 
5248 	if (check_fwstate(pmlmepriv, (WIFI_ASOC_STATE | WIFI_AP_STATE)) != _TRUE)
5249 		return -EINVAL;
5250 
5251 	if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
5252 	    param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
5253 	    param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff)
5254 		return -EINVAL;
5255 
5256 	psta = rtw_get_stainfo(pstapriv, param->sta_addr);
5257 	if (psta) {
5258 		if ((psta->wpa_ie[0] == WLAN_EID_RSN) || (psta->wpa_ie[0] == WLAN_EID_GENERIC)) {
5259 			int wpa_ie_len;
5260 			int copy_len;
5261 
5262 			wpa_ie_len = psta->wpa_ie[1];
5263 
5264 			copy_len = ((wpa_ie_len + 2) > sizeof(psta->wpa_ie)) ? (sizeof(psta->wpa_ie)) : (wpa_ie_len + 2);
5265 
5266 			param->u.wpa_ie.len = copy_len;
5267 
5268 			_rtw_memcpy(param->u.wpa_ie.reserved, psta->wpa_ie, copy_len);
5269 		} else {
5270 			/* ret = -1; */
5271 			RTW_INFO("sta's wpa_ie is NONE\n");
5272 		}
5273 	} else
5274 		ret = -1;
5275 
5276 	return ret;
5277 
5278 }
5279 
5280 static int rtw_set_wps_beacon(struct net_device *dev, struct ieee_param *param, int len)
5281 {
5282 	int ret = 0;
5283 	unsigned char wps_oui[4] = {0x0, 0x50, 0xf2, 0x04};
5284 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5285 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5286 	struct mlme_ext_priv	*pmlmeext = &(padapter->mlmeextpriv);
5287 	int ie_len;
5288 
5289 	RTW_INFO("%s, len=%d\n", __FUNCTION__, len);
5290 
5291 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
5292 		return -EINVAL;
5293 
5294 	ie_len = len - 12 - 2; /* 12 = param header, 2:no packed */
5295 
5296 
5297 	if (pmlmepriv->wps_beacon_ie) {
5298 		rtw_mfree(pmlmepriv->wps_beacon_ie, pmlmepriv->wps_beacon_ie_len);
5299 		pmlmepriv->wps_beacon_ie = NULL;
5300 	}
5301 
5302 	if (ie_len > 0) {
5303 		pmlmepriv->wps_beacon_ie = rtw_malloc(ie_len);
5304 		pmlmepriv->wps_beacon_ie_len = ie_len;
5305 		if (pmlmepriv->wps_beacon_ie == NULL) {
5306 			RTW_INFO("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
5307 			return -EINVAL;
5308 		}
5309 
5310 		_rtw_memcpy(pmlmepriv->wps_beacon_ie, param->u.bcn_ie.buf, ie_len);
5311 
5312 		rtw_update_beacon(padapter, _VENDOR_SPECIFIC_IE_, wps_oui, _TRUE, 0);
5313 
5314 		pmlmeext->bstart_bss = _TRUE;
5315 
5316 	}
5317 
5318 
5319 	return ret;
5320 
5321 }
5322 
5323 static int rtw_set_wps_probe_resp(struct net_device *dev, struct ieee_param *param, int len)
5324 {
5325 	int ret = 0;
5326 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5327 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5328 	int ie_len;
5329 
5330 	RTW_INFO("%s, len=%d\n", __FUNCTION__, len);
5331 
5332 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
5333 		return -EINVAL;
5334 
5335 	ie_len = len - 12 - 2; /* 12 = param header, 2:no packed */
5336 
5337 
5338 	if (pmlmepriv->wps_probe_resp_ie) {
5339 		rtw_mfree(pmlmepriv->wps_probe_resp_ie, pmlmepriv->wps_probe_resp_ie_len);
5340 		pmlmepriv->wps_probe_resp_ie = NULL;
5341 	}
5342 
5343 	if (ie_len > 0) {
5344 		pmlmepriv->wps_probe_resp_ie = rtw_malloc(ie_len);
5345 		pmlmepriv->wps_probe_resp_ie_len = ie_len;
5346 		if (pmlmepriv->wps_probe_resp_ie == NULL) {
5347 			RTW_INFO("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
5348 			return -EINVAL;
5349 		}
5350 		_rtw_memcpy(pmlmepriv->wps_probe_resp_ie, param->u.bcn_ie.buf, ie_len);
5351 	}
5352 
5353 
5354 	return ret;
5355 
5356 }
5357 
5358 static int rtw_set_wps_assoc_resp(struct net_device *dev, struct ieee_param *param, int len)
5359 {
5360 	int ret = 0;
5361 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5362 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5363 	int ie_len;
5364 
5365 	RTW_INFO("%s, len=%d\n", __FUNCTION__, len);
5366 
5367 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
5368 		return -EINVAL;
5369 
5370 	ie_len = len - 12 - 2; /* 12 = param header, 2:no packed */
5371 
5372 
5373 	if (pmlmepriv->wps_assoc_resp_ie) {
5374 		rtw_mfree(pmlmepriv->wps_assoc_resp_ie, pmlmepriv->wps_assoc_resp_ie_len);
5375 		pmlmepriv->wps_assoc_resp_ie = NULL;
5376 	}
5377 
5378 	if (ie_len > 0) {
5379 		pmlmepriv->wps_assoc_resp_ie = rtw_malloc(ie_len);
5380 		pmlmepriv->wps_assoc_resp_ie_len = ie_len;
5381 		if (pmlmepriv->wps_assoc_resp_ie == NULL) {
5382 			RTW_INFO("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
5383 			return -EINVAL;
5384 		}
5385 
5386 		_rtw_memcpy(pmlmepriv->wps_assoc_resp_ie, param->u.bcn_ie.buf, ie_len);
5387 	}
5388 
5389 
5390 	return ret;
5391 
5392 }
5393 
5394 static int rtw_set_hidden_ssid(struct net_device *dev, struct ieee_param *param, int len)
5395 {
5396 	int ret = 0;
5397 	_adapter *adapter = (_adapter *)rtw_netdev_priv(dev);
5398 	struct mlme_priv *mlmepriv = &(adapter->mlmepriv);
5399 	struct mlme_ext_priv	*mlmeext = &(adapter->mlmeextpriv);
5400 	struct mlme_ext_info	*mlmeinfo = &(mlmeext->mlmext_info);
5401 	int ie_len;
5402 	u8 *ssid_ie;
5403 	char ssid[NDIS_802_11_LENGTH_SSID + 1];
5404 	sint ssid_len = 0;
5405 	u8 ignore_broadcast_ssid;
5406 
5407 	if (check_fwstate(mlmepriv, WIFI_AP_STATE) != _TRUE)
5408 		return -EPERM;
5409 
5410 	if (param->u.bcn_ie.reserved[0] != 0xea)
5411 		return -EINVAL;
5412 
5413 	mlmeinfo->hidden_ssid_mode = ignore_broadcast_ssid = param->u.bcn_ie.reserved[1];
5414 
5415 	ie_len = len - 12 - 2; /* 12 = param header, 2:no packed */
5416 	ssid_ie = rtw_get_ie(param->u.bcn_ie.buf,  WLAN_EID_SSID, &ssid_len, ie_len);
5417 
5418 	if (ssid_ie && ssid_len > 0 && ssid_len <= NDIS_802_11_LENGTH_SSID) {
5419 		WLAN_BSSID_EX *pbss_network = &mlmepriv->cur_network.network;
5420 		WLAN_BSSID_EX *pbss_network_ext = &mlmeinfo->network;
5421 
5422 		_rtw_memcpy(ssid, ssid_ie + 2, ssid_len);
5423 		ssid[ssid_len] = 0x0;
5424 
5425 		if (0)
5426 			RTW_INFO(FUNC_ADPT_FMT" ssid:(%s,%d), from ie:(%s,%d), (%s,%d)\n", FUNC_ADPT_ARG(adapter),
5427 				ssid, ssid_len,
5428 				pbss_network->Ssid.Ssid, pbss_network->Ssid.SsidLength,
5429 				pbss_network_ext->Ssid.Ssid, pbss_network_ext->Ssid.SsidLength);
5430 
5431 		_rtw_memcpy(pbss_network->Ssid.Ssid, (void *)ssid, ssid_len);
5432 		pbss_network->Ssid.SsidLength = ssid_len;
5433 		_rtw_memcpy(pbss_network_ext->Ssid.Ssid, (void *)ssid, ssid_len);
5434 		pbss_network_ext->Ssid.SsidLength = ssid_len;
5435 
5436 		if (0)
5437 			RTW_INFO(FUNC_ADPT_FMT" after ssid:(%s,%d), (%s,%d)\n", FUNC_ADPT_ARG(adapter),
5438 				pbss_network->Ssid.Ssid, pbss_network->Ssid.SsidLength,
5439 				pbss_network_ext->Ssid.Ssid, pbss_network_ext->Ssid.SsidLength);
5440 	}
5441 
5442 	RTW_INFO(FUNC_ADPT_FMT" ignore_broadcast_ssid:%d, %s,%d\n", FUNC_ADPT_ARG(adapter),
5443 		ignore_broadcast_ssid, ssid, ssid_len);
5444 
5445 	return ret;
5446 }
5447 
5448 #if CONFIG_RTW_MACADDR_ACL
5449 static int rtw_ioctl_acl_remove_sta(struct net_device *dev, struct ieee_param *param, int len)
5450 {
5451 	int ret = 0;
5452 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5453 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5454 
5455 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
5456 		return -EINVAL;
5457 
5458 	if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
5459 	    param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
5460 	    param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff)
5461 		return -EINVAL;
5462 
5463 	ret = rtw_acl_remove_sta(padapter, RTW_ACL_PERIOD_BSS, param->sta_addr);
5464 
5465 	return ret;
5466 
5467 }
5468 
5469 static int rtw_ioctl_acl_add_sta(struct net_device *dev, struct ieee_param *param, int len)
5470 {
5471 	int ret = 0;
5472 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5473 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5474 
5475 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
5476 		return -EINVAL;
5477 
5478 	if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
5479 	    param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
5480 	    param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff)
5481 		return -EINVAL;
5482 
5483 	ret = rtw_acl_add_sta(padapter, RTW_ACL_PERIOD_BSS, param->sta_addr);
5484 
5485 	return ret;
5486 
5487 }
5488 
5489 static int rtw_ioctl_set_macaddr_acl(struct net_device *dev, struct ieee_param *param, int len)
5490 {
5491 	int ret = 0;
5492 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5493 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5494 
5495 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
5496 		return -EINVAL;
5497 
5498 	rtw_set_macaddr_acl(padapter, RTW_ACL_PERIOD_BSS, param->u.mlme.command);
5499 
5500 	return ret;
5501 }
5502 #endif /* CONFIG_RTW_MACADDR_ACL */
5503 
5504 static int rtw_hostapd_ioctl(struct net_device *dev, struct iw_point *p)
5505 {
5506 	struct ieee_param *param;
5507 	int ret = 0;
5508 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5509 	struct dvobj_priv *dvobj = adapter_to_dvobj(padapter);
5510 
5511 	/* RTW_INFO("%s\n", __FUNCTION__); */
5512 
5513 	/*
5514 	* this function is expect to call in master mode, which allows no power saving
5515 	* so, we just check hw_init_completed
5516 	*/
5517 
5518 	if (!rtw_hw_is_init_completed(dvobj)) {
5519 		ret = -EPERM;
5520 		goto out;
5521 	}
5522 
5523 
5524 	/* if (p->length < sizeof(struct ieee_param) || !p->pointer){ */
5525 	if (!p->pointer) {
5526 		ret = -EINVAL;
5527 		goto out;
5528 	}
5529 
5530 	param = (struct ieee_param *)rtw_malloc(p->length);
5531 	if (param == NULL) {
5532 		ret = -ENOMEM;
5533 		goto out;
5534 	}
5535 
5536 	if (copy_from_user(param, p->pointer, p->length)) {
5537 		rtw_mfree((u8 *)param, p->length);
5538 		ret = -EFAULT;
5539 		goto out;
5540 	}
5541 
5542 	/* RTW_INFO("%s, cmd=%d\n", __FUNCTION__, param->cmd); */
5543 
5544 	switch (param->cmd) {
5545 	case RTL871X_HOSTAPD_FLUSH:
5546 
5547 		ret = rtw_hostapd_sta_flush(dev);
5548 
5549 		break;
5550 
5551 	case RTL871X_HOSTAPD_ADD_STA:
5552 
5553 		ret = rtw_add_sta(dev, param);
5554 
5555 		break;
5556 
5557 	case RTL871X_HOSTAPD_REMOVE_STA:
5558 
5559 		ret = rtw_del_sta(dev, param);
5560 
5561 		break;
5562 
5563 	case RTL871X_HOSTAPD_SET_BEACON:
5564 
5565 		ret = rtw_set_beacon(dev, param, p->length);
5566 
5567 		break;
5568 
5569 	case RTL871X_SET_ENCRYPTION:
5570 
5571 		ret = rtw_set_encryption(dev, param, p->length);
5572 
5573 		break;
5574 
5575 	case RTL871X_HOSTAPD_GET_WPAIE_STA:
5576 
5577 		ret = rtw_get_sta_wpaie(dev, param);
5578 
5579 		break;
5580 
5581 	case RTL871X_HOSTAPD_SET_WPS_BEACON:
5582 
5583 		ret = rtw_set_wps_beacon(dev, param, p->length);
5584 
5585 		break;
5586 
5587 	case RTL871X_HOSTAPD_SET_WPS_PROBE_RESP:
5588 
5589 		ret = rtw_set_wps_probe_resp(dev, param, p->length);
5590 
5591 		break;
5592 
5593 	case RTL871X_HOSTAPD_SET_WPS_ASSOC_RESP:
5594 
5595 		ret = rtw_set_wps_assoc_resp(dev, param, p->length);
5596 
5597 		break;
5598 
5599 	case RTL871X_HOSTAPD_SET_HIDDEN_SSID:
5600 
5601 		ret = rtw_set_hidden_ssid(dev, param, p->length);
5602 
5603 		break;
5604 
5605 	case RTL871X_HOSTAPD_GET_INFO_STA:
5606 
5607 		ret = rtw_ioctl_get_sta_data(dev, param, p->length);
5608 
5609 		break;
5610 
5611 #if CONFIG_RTW_MACADDR_ACL
5612 	case RTL871X_HOSTAPD_SET_MACADDR_ACL:
5613 		ret = rtw_ioctl_set_macaddr_acl(dev, param, p->length);
5614 		break;
5615 	case RTL871X_HOSTAPD_ACL_ADD_STA:
5616 		ret = rtw_ioctl_acl_add_sta(dev, param, p->length);
5617 		break;
5618 	case RTL871X_HOSTAPD_ACL_REMOVE_STA:
5619 		ret = rtw_ioctl_acl_remove_sta(dev, param, p->length);
5620 		break;
5621 #endif /* CONFIG_RTW_MACADDR_ACL */
5622 
5623 	default:
5624 		RTW_INFO("Unknown hostapd request: %d\n", param->cmd);
5625 		ret = -EOPNOTSUPP;
5626 		break;
5627 
5628 	}
5629 
5630 	if (ret == 0 && copy_to_user(p->pointer, param, p->length))
5631 		ret = -EFAULT;
5632 
5633 
5634 	rtw_mfree((u8 *)param, p->length);
5635 
5636 out:
5637 
5638 	return ret;
5639 
5640 }
5641 #endif
5642 
5643 static int rtw_wx_set_priv(struct net_device *dev,
5644 			   struct iw_request_info *info,
5645 			   union iwreq_data *awrq,
5646 			   char *extra)
5647 {
5648 
5649 #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
5650 	char *ext_dbg;
5651 #endif
5652 
5653 	int ret = 0;
5654 	int len = 0;
5655 	char *ext;
5656 #ifdef CONFIG_RTW_ANDROID
5657 	int i;
5658 #endif
5659 
5660 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5661 	struct iw_point *dwrq = (struct iw_point *)awrq;
5662 
5663 	if (dwrq->length == 0)
5664 		return -EFAULT;
5665 
5666 	len = dwrq->length;
5667 	ext = rtw_vmalloc(len);
5668 	if (!ext)
5669 		return -ENOMEM;
5670 
5671 	if (copy_from_user(ext, dwrq->pointer, len)) {
5672 		rtw_vmfree(ext, len);
5673 		return -EFAULT;
5674 	}
5675 
5676 
5677 
5678 #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
5679 	ext_dbg = rtw_vmalloc(len);
5680 	if (!ext_dbg) {
5681 		rtw_vmfree(ext, len);
5682 		return -ENOMEM;
5683 	}
5684 
5685 	_rtw_memcpy(ext_dbg, ext, len);
5686 #endif
5687 
5688 	/* added for wps2.0 @20110524 */
5689 	if (dwrq->flags == 0x8766 && len > 8) {
5690 		u32 cp_sz;
5691 		struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
5692 		u8 *probereq_wpsie = ext;
5693 		int probereq_wpsie_len = len;
5694 		u8 wps_oui[4] = {0x0, 0x50, 0xf2, 0x04};
5695 
5696 		if ((_VENDOR_SPECIFIC_IE_ == probereq_wpsie[0]) &&
5697 		    (_rtw_memcmp(&probereq_wpsie[2], wps_oui, 4) == _TRUE)) {
5698 			cp_sz = probereq_wpsie_len > MAX_WPS_IE_LEN ? MAX_WPS_IE_LEN : probereq_wpsie_len;
5699 
5700 			if (pmlmepriv->wps_probe_req_ie) {
5701 				u32 free_len = pmlmepriv->wps_probe_req_ie_len;
5702 				pmlmepriv->wps_probe_req_ie_len = 0;
5703 				rtw_mfree(pmlmepriv->wps_probe_req_ie, free_len);
5704 				pmlmepriv->wps_probe_req_ie = NULL;
5705 			}
5706 
5707 			pmlmepriv->wps_probe_req_ie = rtw_malloc(cp_sz);
5708 			if (pmlmepriv->wps_probe_req_ie == NULL) {
5709 				printk("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
5710 				ret =  -EINVAL;
5711 				goto FREE_EXT;
5712 
5713 			}
5714 
5715 			_rtw_memcpy(pmlmepriv->wps_probe_req_ie, probereq_wpsie, cp_sz);
5716 			pmlmepriv->wps_probe_req_ie_len = cp_sz;
5717 
5718 		}
5719 
5720 		goto FREE_EXT;
5721 
5722 	}
5723 
5724 	if (len >= WEXT_CSCAN_HEADER_SIZE
5725 		&& _rtw_memcmp(ext, WEXT_CSCAN_HEADER, WEXT_CSCAN_HEADER_SIZE) == _TRUE
5726 	) {
5727 		ret = rtw_wx_set_scan(dev, info, awrq, ext);
5728 		goto FREE_EXT;
5729 	}
5730 
5731 #ifdef CONFIG_RTW_ANDROID
5732 	/* RTW_INFO("rtw_wx_set_priv: %s req=%s\n", dev->name, ext); */
5733 
5734 	i = rtw_android_cmdstr_to_num(ext);
5735 
5736 	switch (i) {
5737 	case ANDROID_WIFI_CMD_START:
5738 		indicate_wx_custom_event(padapter, "START");
5739 		break;
5740 	case ANDROID_WIFI_CMD_STOP:
5741 		indicate_wx_custom_event(padapter, "STOP");
5742 		break;
5743 	case ANDROID_WIFI_CMD_RSSI: {
5744 		struct	mlme_priv	*pmlmepriv = &(padapter->mlmepriv);
5745 		struct	wlan_network	*pcur_network = &pmlmepriv->cur_network;
5746 
5747 		if (check_fwstate(pmlmepriv, WIFI_ASOC_STATE) == _TRUE)
5748 			sprintf(ext, "%s rssi %d", pcur_network->network.Ssid.Ssid, padapter->recvinfo.rssi);
5749 		else
5750 			sprintf(ext, "OK");
5751 	}
5752 		break;
5753 	case ANDROID_WIFI_CMD_LINKSPEED: {
5754 		u16 mbps = rtw_get_cur_max_rate(padapter) / 10;
5755 		sprintf(ext, "LINKSPEED %d", mbps);
5756 	}
5757 		break;
5758 	case ANDROID_WIFI_CMD_MACADDR:
5759 		sprintf(ext, "MACADDR = " MAC_FMT, MAC_ARG(dev->dev_addr));
5760 		break;
5761 	case ANDROID_WIFI_CMD_SCAN_ACTIVE: {
5762 		/* rtw_set_scan_mode(padapter, SCAN_ACTIVE); */
5763 		sprintf(ext, "OK");
5764 	}
5765 		break;
5766 	case ANDROID_WIFI_CMD_SCAN_PASSIVE: {
5767 		/* rtw_set_scan_mode(padapter, SCAN_PASSIVE); */
5768 		sprintf(ext, "OK");
5769 	}
5770 		break;
5771 
5772 	case ANDROID_WIFI_CMD_COUNTRY: {
5773 		char country_code[10];
5774 		sscanf(ext, "%*s %s", country_code);
5775 		rtw_set_country(padapter, country_code, RTW_REGD_SET_BY_USER);
5776 		sprintf(ext, "OK");
5777 	}
5778 		break;
5779 	default:
5780 		#ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
5781 		RTW_INFO("%s: %s unknowned req=%s\n", __FUNCTION__,
5782 			dev->name, ext_dbg);
5783 		#endif
5784 
5785 		sprintf(ext, "OK");
5786 
5787 	}
5788 
5789 	if (copy_to_user(dwrq->pointer, ext, min(dwrq->length, (u16)(strlen(ext) + 1))))
5790 		ret = -EFAULT;
5791 
5792 #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
5793 	RTW_INFO("%s: %s req=%s rep=%s dwrq->length=%d, strlen(ext)+1=%d\n", __FUNCTION__,
5794 		dev->name, ext_dbg , ext, dwrq->length, (u16)(strlen(ext) + 1));
5795 #endif
5796 #endif /* end of CONFIG_ANDROID */
5797 
5798 
5799 FREE_EXT:
5800 
5801 	rtw_vmfree(ext, len);
5802 	#ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
5803 	rtw_vmfree(ext_dbg, len);
5804 	#endif
5805 
5806 	/* RTW_INFO("rtw_wx_set_priv: (SIOCSIWPRIV) %s ret=%d\n",  */
5807 	/*		dev->name, ret); */
5808 
5809 	return ret;
5810 
5811 }
5812 #ifdef CONFIG_WOWLAN
5813 static int rtw_wowlan_ctrl(struct net_device *dev,
5814 			   struct iw_request_info *info,
5815 			   union iwreq_data *wrqu, char *extra)
5816 {
5817 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5818 	struct pwrctrl_priv *pwrctrlpriv = adapter_to_pwrctl(padapter);
5819 	struct wow_priv *wowpriv = adapter_to_wowlan(padapter);
5820 	struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5821 	int ret = 0;
5822 	systime start_time = rtw_get_current_time();
5823 
5824 	RTW_INFO("+rtw_wowlan_ctrl: %s\n", extra);
5825 
5826 	if (!check_fwstate(pmlmepriv, WIFI_ASOC_STATE) &&
5827 		MLME_IS_STA(padapter) &&
5828 		!WOWLAN_IS_STA_MIX_MODE(padapter)) {
5829 #ifdef CONFIG_PNO_SUPPORT
5830 		if (wowpriv->wow_nlo.nlo_en) {
5831 			pwrctrlpriv->wowlan_pno_enable = _TRUE;
5832 		} else
5833 #endif
5834 		{
5835 			RTW_INFO("[%s] WARNING: Please Connect With AP First!!\n",
5836 				 __func__);
5837 			goto _rtw_wowlan_ctrl_exit_free;
5838 		}
5839 	}
5840 
5841 	if (check_fwstate(pmlmepriv, WIFI_UNDER_SURVEY))
5842 		rtw_scan_abort(padapter, 0);
5843 
5844 	if (_rtw_memcmp(extra, "enable", 6))
5845 
5846 
5847 		rtw_suspend_common(padapter);
5848 
5849 	else if (_rtw_memcmp(extra, "disable", 7)) {
5850 #ifdef CONFIG_USB_HCI
5851 		RTW_ENABLE_FUNC(adapter_to_dvobj(padapter), DF_RX_BIT);
5852 		RTW_ENABLE_FUNC(adapter_to_dvobj(padapter), DF_TX_BIT);
5853 #endif
5854 		rtw_resume_common(padapter);
5855 
5856 #ifdef CONFIG_PNO_SUPPORT
5857 		pwrctrlpriv->wowlan_pno_enable = _FALSE;
5858 #endif /* CONFIG_PNO_SUPPORT */
5859 
5860 	} else {
5861 		RTW_INFO("[%s] Invalid Parameter.\n", __func__);
5862 		goto _rtw_wowlan_ctrl_exit_free;
5863 	}
5864 	/* mutex_lock(&ioctl_mutex); */
5865 _rtw_wowlan_ctrl_exit_free:
5866 	RTW_PRINT("%s in %d ms\n", __func__,
5867 		  rtw_get_passing_time_ms(start_time));
5868 	return ret;
5869 }
5870 
5871 /*
5872  * IP filter This pattern if for a frame containing a ip packet:
5873  * AA:AA:AA:AA:AA:AA:BB:BB:BB:BB:BB:BB:CC:CC:DD:-:-:-:-:-:-:-:-:EE:-:-:FF:FF:FF:FF:GG:GG:GG:GG:HH:HH:II:II
5874  *
5875  * A: Ethernet destination address
5876  * B: Ethernet source address
5877  * C: Ethernet protocol type
5878  * D: IP header VER+Hlen, use: 0x45 (4 is for ver 4, 5 is for len 20)
5879  * E: IP protocol
5880  * F: IP source address ( 192.168.0.4: C0:A8:00:2C )
5881  * G: IP destination address ( 192.168.0.4: C0:A8:00:2C )
5882  * H: Source port (1024: 04:00)
5883  * I: Destination port (1024: 04:00)
5884  */
5885 
5886 static int rtw_wowlan_set_pattern(struct net_device *dev,
5887 				  struct iw_request_info *info,
5888 				  union iwreq_data *wrqu, char *extra)
5889 {
5890 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5891 	struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5892 	struct registry_priv  *registry_par = &padapter->registrypriv;
5893 	struct wow_priv *wowpriv = adapter_to_wowlan(padapter);
5894 	struct rtw_wowcam_upd_info wowcam_info = {0};
5895 	u8 input[wrqu->data.length];
5896 	int ret = 0;
5897 
5898 	if (!(registry_par->wakeup_event & BIT(3))) {
5899 		ret = -EOPNOTSUPP;
5900 		RTW_INFO("%s: customized pattern disabled, wakeup_event: %#2x\n",
5901 			 __func__, registry_par->wakeup_event);
5902 		goto _rtw_wowlan_set_pattern_exit;
5903 	}
5904 
5905 	if (!check_fwstate(pmlmepriv, WIFI_ASOC_STATE) &&
5906 	    MLME_IS_STA(padapter)) {
5907 		ret = -EOPNOTSUPP;
5908 		RTW_INFO("Please Connect With AP First!!\n");
5909 		goto _rtw_wowlan_set_pattern_exit;
5910 	}
5911 
5912 	if (wrqu->data.length <= 0) {
5913 		ret = -EINVAL;
5914 		RTW_INFO("ERROR: parameter length <= 0\n");
5915 		goto _rtw_wowlan_set_pattern_exit;
5916 	} else {
5917 		/* set pattern */
5918 		if (copy_from_user(input, wrqu->data.pointer, wrqu->data.length)) {
5919 			ret -EFAULT;
5920 			goto _rtw_wowlan_set_pattern_exit;
5921 		}
5922 
5923 		if (strncmp(input, "pattern=", 8) == 0) {
5924 			if (rtw_wowlan_parser_pattern_cmd(input,
5925 							  wowcam_info.ptrn,
5926 							  &wowcam_info.ptrn_len,
5927 							  wowcam_info.mask)) {
5928 				if (_FAIL == rtw_wow_pattern_set(padapter,
5929 								 &wowcam_info,
5930 								 RTW_CUSTOMIZED_PATTERN))
5931 					ret = -EFAULT;
5932 			} else {
5933 				ret = -EINVAL;
5934 			}
5935 		} else if (strncmp(input, "clean", 5) == 0) {
5936 			rtw_wow_pattern_clean(padapter, RTW_CUSTOMIZED_PATTERN);
5937 		} else if (strncmp(input, "show", 4) == 0) {
5938 			/* leave PS first */
5939 			rtw_ps_deny(padapter, PS_DENY_IOCTL);
5940 			LeaveAllPowerSaveModeDirect(padapter);
5941 			#if 0 /* WOW_ToDo */
5942 			rtw_wow_pattern_cam_dump(padapter);
5943 			rtw_wow_pattern_sw_dump(padapter);
5944 			#endif
5945 			rtw_ps_deny_cancel(padapter, PS_DENY_IOCTL);
5946 		} else {
5947 			RTW_INFO("ERROR: incorrect parameter!\n");
5948 			ret = -EINVAL;
5949 		}
5950 	}
5951 _rtw_wowlan_set_pattern_exit:
5952 	return ret;
5953 }
5954 #endif /* CONFIG_WOWLAN */
5955 
5956 #ifdef CONFIG_AP_WOWLAN
5957 static int rtw_ap_wowlan_ctrl(struct net_device *dev,
5958 			      struct iw_request_info *info,
5959 			      union iwreq_data *wrqu, char *extra)
5960 {
5961 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5962 	struct wowlan_ioctl_param poidparam;
5963 	struct pwrctrl_priv *pwrctrlpriv = adapter_to_pwrctl(padapter);
5964 	struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5965 	struct sta_info	*psta = NULL;
5966 	int ret = 0;
5967 	systime start_time = rtw_get_current_time();
5968 	poidparam.subcode = 0;
5969 
5970 	RTW_INFO("+rtw_ap_wowlan_ctrl: %s\n", extra);
5971 
5972 	if (!check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
5973 		RTW_INFO("[%s] It is not AP mode!!\n", __func__);
5974 		goto _rtw_ap_wowlan_ctrl_exit_free;
5975 	}
5976 
5977 	if (_rtw_memcmp(extra, "enable", 6)) {
5978 
5979 		pwrctrlpriv->wowlan_ap_mode = _TRUE;
5980 
5981 		rtw_suspend_common(padapter);
5982 	} else if (_rtw_memcmp(extra, "disable", 7)) {
5983 #ifdef CONFIG_USB_HCI
5984 		RTW_ENABLE_FUNC(adapter_to_dvobj(padapter), DF_RX_BIT);
5985 		RTW_ENABLE_FUNC(adapter_to_dvobj(padapter), DF_TX_BIT);
5986 #endif
5987 		rtw_resume_common(padapter);
5988 	} else {
5989 		RTW_INFO("[%s] Invalid Parameter.\n", __func__);
5990 		goto _rtw_ap_wowlan_ctrl_exit_free;
5991 	}
5992 	/* mutex_lock(&ioctl_mutex); */
5993 _rtw_ap_wowlan_ctrl_exit_free:
5994 	RTW_INFO("-rtw_ap_wowlan_ctrl( subcode = %d)\n", poidparam.subcode);
5995 	RTW_PRINT("%s in %d ms\n", __func__,
5996 		  rtw_get_passing_time_ms(start_time));
5997 	return ret;
5998 }
5999 #endif /* CONFIG_AP_WOWLAN */
6000 
6001 static int rtw_pm_set(struct net_device *dev,
6002 		      struct iw_request_info *info,
6003 		      union iwreq_data *wrqu, char *extra)
6004 {
6005 	int ret = 0;
6006 	unsigned	mode = 0;
6007 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6008 
6009 	RTW_INFO("[%s] extra = %s\n", __FUNCTION__, extra);
6010 
6011 	if (_rtw_memcmp(extra, "lps=", 4)) {
6012 		sscanf(extra + 4, "%u", &mode);
6013 		ret = rtw_pm_set_lps(padapter, mode);
6014 	} else if (_rtw_memcmp(extra, "ips=", 4)) {
6015 		sscanf(extra + 4, "%u", &mode);
6016 		ret = rtw_pm_set_ips(padapter, mode);
6017 	} else if (_rtw_memcmp(extra, "lps_level=", 10)) {
6018 		if (sscanf(extra + 10, "%u", &mode) > 0)
6019 			ret = rtw_pm_set_lps_level(padapter, mode);
6020 #ifdef CONFIG_LPS_1T1R
6021 	} else if (_rtw_memcmp(extra, "lps_1t1r=", 9)) {
6022 		if (sscanf(extra + 9, "%u", &mode) > 0)
6023 			ret = rtw_pm_set_lps_1t1r(padapter, mode);
6024 #endif
6025 	}
6026 #ifdef CONFIG_WOWLAN
6027 	else if (_rtw_memcmp(extra, "wow_lps=", 8)) {
6028 		sscanf(extra + 8, "%u", &mode);
6029 		ret = rtw_pm_set_wow_lps(padapter, mode);
6030 	} else if (_rtw_memcmp(extra, "wow_lps_level=", 14)) {
6031 		if (sscanf(extra + 14, "%u", &mode) > 0)
6032 			ret = rtw_pm_set_wow_lps_level(padapter, mode);
6033 	#ifdef CONFIG_LPS_1T1R
6034 	} else if (_rtw_memcmp(extra, "wow_lps_1t1r=", 13)) {
6035 		if (sscanf(extra + 13, "%u", &mode) > 0)
6036 			ret = rtw_pm_set_wow_lps_1t1r(padapter, mode);
6037 	#endif
6038 	}
6039 #endif /* CONFIG_WOWLAN */
6040 	else
6041 		ret = -EINVAL;
6042 
6043 	return ret;
6044 }
6045 #ifdef CONFIG_APPEND_VENDOR_IE_ENABLE
6046 
6047 int rtw_vendor_ie_get_raw_data(struct net_device *dev, u32 vendor_ie_num,
6048 							   char *extra, u32 length)
6049 {
6050 	int j;
6051 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6052 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
6053 	u32 vendor_ie_mask = 0;
6054 	char *pstring;
6055 
6056 	if (vendor_ie_num >= WLAN_MAX_VENDOR_IE_NUM) {
6057 		RTW_INFO("[%s] only support %d vendor ie\n", __func__ ,
6058 				 WLAN_MAX_VENDOR_IE_NUM);
6059 		return -EFAULT;
6060 	}
6061 
6062 	if (pmlmepriv->vendor_ielen[vendor_ie_num] == 0) {
6063 		RTW_INFO("[%s]  Fail, vendor_ie_num: %d is not set\n", __func__,
6064 				 vendor_ie_num);
6065 		return -EFAULT;
6066 	}
6067 
6068 	if (length < 2 * pmlmepriv->vendor_ielen[vendor_ie_num] + 5) {
6069 		RTW_INFO("[%s]  Fail, buffer size is too small\n", __func__);
6070 		return -EFAULT;
6071 	}
6072 
6073 	vendor_ie_mask = pmlmepriv->vendor_ie_mask[vendor_ie_num];
6074 	_rtw_memset(extra, 0, length);
6075 
6076 	pstring = extra;
6077 	pstring += sprintf(pstring, "%d,%x,", vendor_ie_num, vendor_ie_mask);
6078 
6079 	for (j = 0; j < pmlmepriv->vendor_ielen[vendor_ie_num]; j++)
6080 		pstring += sprintf(pstring, "%02x", pmlmepriv->vendor_ie[vendor_ie_num][j]);
6081 
6082 	length = pstring - extra;
6083 	return length;
6084 }
6085 
6086 int rtw_vendor_ie_get_data(struct net_device *dev, int vendor_ie_num, char *extra)
6087 {
6088 	int j;
6089 	char *pstring;
6090 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6091 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
6092 	u32 vendor_ie_mask = 0;
6093 	__u16 length = 0;
6094 
6095 	vendor_ie_mask = pmlmepriv->vendor_ie_mask[vendor_ie_num];
6096 	pstring = extra;
6097 	pstring += sprintf(pstring , "\nVendor IE num %d , Mask:%x " , vendor_ie_num , vendor_ie_mask);
6098 
6099 	if (vendor_ie_mask & WIFI_BEACON_VENDOR_IE_BIT)
6100 		pstring += sprintf(pstring , "[Beacon]");
6101 	if (vendor_ie_mask & WIFI_PROBEREQ_VENDOR_IE_BIT)
6102 		pstring += sprintf(pstring , "[Probe Req]");
6103 	if (vendor_ie_mask & WIFI_PROBERESP_VENDOR_IE_BIT)
6104 		pstring += sprintf(pstring , "[Probe Resp]");
6105 	if (vendor_ie_mask & WIFI_ASSOCREQ_VENDOR_IE_BIT)
6106 		pstring += sprintf(pstring , "[Assoc Req]");
6107 	if (vendor_ie_mask & WIFI_ASSOCRESP_VENDOR_IE_BIT)
6108 		pstring += sprintf(pstring , "[Assoc Resp]");
6109 #ifdef CONFIG_P2P
6110 	if (vendor_ie_mask & WIFI_P2P_PROBEREQ_VENDOR_IE_BIT)
6111 		pstring += sprintf(pstring , "[P2P_Probe Req]");
6112 	if (vendor_ie_mask & WIFI_P2P_PROBERESP_VENDOR_IE_BIT)
6113 		pstring += sprintf(pstring , "[P2P_Probe Resp]");
6114 #endif
6115 
6116 	pstring += sprintf(pstring , "\nVendor IE:\n");
6117 	for (j = 0 ; j < pmlmepriv->vendor_ielen[vendor_ie_num]  ; j++)
6118 		pstring += sprintf(pstring , "%02x" , pmlmepriv->vendor_ie[vendor_ie_num][j]);
6119 
6120 	length = pstring - extra;
6121 	return length;
6122 
6123 }
6124 
6125 int rtw_vendor_ie_get(struct net_device *dev, struct iw_request_info *info, union iwreq_data *wrqu, char *extra)
6126 {
6127 	int ret = 0, vendor_ie_num = 0, cmdlen;
6128 	struct iw_point *p;
6129 	u8 *ptmp;
6130 
6131 	p = &wrqu->data;
6132 	cmdlen = p->length;
6133 	if (0 == cmdlen)
6134 		return -EINVAL;
6135 
6136 	ptmp = (u8 *)rtw_malloc(cmdlen);
6137 	if (NULL == ptmp)
6138 		return -ENOMEM;
6139 
6140 	if (copy_from_user(ptmp, p->pointer, cmdlen)) {
6141 		ret = -EFAULT;
6142 		goto exit;
6143 	}
6144 	ret = sscanf(ptmp , "%d", &vendor_ie_num);
6145 	if (vendor_ie_num > WLAN_MAX_VENDOR_IE_NUM - 1) {
6146 		ret = -EFAULT;
6147 		goto exit;
6148 	}
6149 
6150 	wrqu->data.length = rtw_vendor_ie_get_data(dev, vendor_ie_num, extra);
6151 
6152 exit:
6153 	rtw_mfree(ptmp, cmdlen);
6154 
6155 	return 0;
6156 }
6157 
6158 int rtw_vendor_ie_set(struct net_device *dev, struct iw_request_info *info, union iwreq_data *wrqu, char *extra)
6159 {
6160 	int ret = 0, i , len = 0 , totoal_ie_len = 0 , total_ie_len_byte = 0;
6161 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6162 	struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
6163 	u32 vendor_ie_mask = 0;
6164 	u32 vendor_ie_num = 0;
6165 	u32 vendor_ie_mask_max = BIT(WLAN_MAX_VENDOR_IE_MASK_MAX) - 1;
6166 	u32 id, elen;
6167 
6168 	ret = sscanf(extra, "%d,%x,%*s", &vendor_ie_num , &vendor_ie_mask);
6169 	if (strrchr(extra , ','))
6170 		extra = strrchr(extra , ',') + 1;
6171 	else
6172 		return -EINVAL;
6173 	totoal_ie_len = strlen(extra);
6174 	RTW_INFO("[%s] vendor_ie_num = %d , vendor_ie_mask = 0x%x , vendor_ie = %s , len = %d\n", __func__ , vendor_ie_num , vendor_ie_mask , extra  , totoal_ie_len);
6175 
6176 	if (vendor_ie_num  > WLAN_MAX_VENDOR_IE_NUM - 1) {
6177 		RTW_INFO("[%s] Fail, only support %d vendor ie\n", __func__ , WLAN_MAX_VENDOR_IE_NUM);
6178 		return -EFAULT;
6179 	}
6180 
6181 	if (totoal_ie_len > WLAN_MAX_VENDOR_IE_LEN) {
6182 		RTW_INFO("[%s] Fail , not support ie length extend %d\n", __func__ , WLAN_MAX_VENDOR_IE_LEN);
6183 		return -EFAULT;
6184 	}
6185 
6186 	if (vendor_ie_mask > vendor_ie_mask_max) {
6187 		RTW_INFO("[%s] Fail, not support vendor_ie_mask more than 0x%x\n", __func__ , vendor_ie_mask_max);
6188 		return -EFAULT;
6189 	}
6190 
6191 	if (vendor_ie_mask == 0) {
6192 		RTW_INFO("[%s] Clear vendor_ie_num %d group\n", __func__ , vendor_ie_num);
6193 		goto _clear_path;
6194 	}
6195 
6196 	if (totoal_ie_len % 2 != 0) {
6197 		RTW_INFO("[%s]  Fail , IE length = %zu is odd\n" , __func__ , strlen(extra));
6198 		return -EFAULT;
6199 	}
6200 
6201 	if (totoal_ie_len > 0) {
6202 		for (i = 0  ; i < strlen(extra) ; i += 2) {
6203 			pmlmepriv->vendor_ie[vendor_ie_num][len] = key_2char2num(extra[i] , extra[i + 1]);
6204 			if (len == 0) {
6205 				id = pmlmepriv->vendor_ie[vendor_ie_num][len];
6206 				if (id != WLAN_EID_VENDOR_SPECIFIC) {
6207 					RTW_INFO("[%s] Fail , VENDOR SPECIFIC IE ID \"%x\" was not correct\n", __func__ , id);
6208 					goto _clear_path;
6209 				}
6210 			} else if (len == 1) {
6211 				total_ie_len_byte = (totoal_ie_len / 2) - 2;
6212 				elen = pmlmepriv->vendor_ie[vendor_ie_num][len];
6213 				if (elen != total_ie_len_byte) {
6214 					RTW_INFO("[%s] Fail , Input IE length = \"%d\"(hex:%x) bytes , not match input total IE context length \"%d\" bytes\n", __func__ , elen , elen ,
6215 						 total_ie_len_byte);
6216 					goto _clear_path;
6217 				}
6218 			}
6219 			len++;
6220 		}
6221 		pmlmepriv->vendor_ielen[vendor_ie_num] = len;
6222 	} else
6223 		pmlmepriv->vendor_ielen[vendor_ie_num] = 0;
6224 
6225 
6226 
6227 	if (vendor_ie_mask & WIFI_BEACON_VENDOR_IE_BIT)
6228 		RTW_INFO("[%s] Beacon append vendor ie\n", __func__);
6229 	if (vendor_ie_mask & WIFI_PROBEREQ_VENDOR_IE_BIT)
6230 		RTW_INFO("[%s] Probe Req append vendor ie\n", __func__);
6231 	if (vendor_ie_mask & WIFI_PROBERESP_VENDOR_IE_BIT)
6232 		RTW_INFO("[%s] Probe Resp append vendor ie\n", __func__);
6233 	if (vendor_ie_mask & WIFI_ASSOCREQ_VENDOR_IE_BIT)
6234 		RTW_INFO("[%s] Assoc Req append vendor ie\n", __func__);
6235 	if (vendor_ie_mask & WIFI_ASSOCRESP_VENDOR_IE_BIT)
6236 		RTW_INFO("[%s] Assoc Resp append vendor ie\n", __func__);
6237 #ifdef CONFIG_P2P
6238 	if (vendor_ie_mask & WIFI_P2P_PROBEREQ_VENDOR_IE_BIT)
6239 		RTW_INFO("[%s] P2P Probe Req append vendor ie\n", __func__);
6240 	if (vendor_ie_mask & WIFI_P2P_PROBERESP_VENDOR_IE_BIT)
6241 		RTW_INFO("[%s] P2P Probe Resp append vendor ie\n", __func__);
6242 #endif
6243 
6244 	pmlmepriv->vendor_ie_mask[vendor_ie_num] = vendor_ie_mask;
6245 
6246 	return ret;
6247 
6248 _clear_path:
6249 	_rtw_memset(pmlmepriv->vendor_ie[vendor_ie_num] , 0 , sizeof(u32) * WLAN_MAX_VENDOR_IE_LEN);
6250 	pmlmepriv->vendor_ielen[vendor_ie_num] = 0;
6251 	pmlmepriv->vendor_ie_mask[vendor_ie_num] = 0;
6252 	return -EFAULT;
6253 }
6254 #endif
6255 
6256 #if defined(RTW_PHL_TX) || defined(RTW_PHL_RX) || defined(CONFIG_PHL_TEST_SUITE)
6257 int rtw_phl_test_set(struct net_device *dev,
6258 	struct iw_request_info *info, union iwreq_data *wrqu, char *extra)
6259 {
6260 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6261 	u32 mode = 0;
6262 	u32 bytes = 0;
6263 	int ret = 0;
6264 
6265 #if defined(RTW_PHL_DBG_CMD)
6266 	core_cmd_phl_handler(padapter, extra);
6267 #endif
6268 
6269 exit:
6270 	return 0;
6271 }
6272 #endif
6273 
6274 
6275 #ifdef CONFIG_RTW_CUSTOMER_STR
6276 static int rtw_mp_customer_str(
6277 	struct net_device *dev,
6278 	struct iw_request_info *info,
6279 	union iwreq_data *wrqu, char *extra)
6280 {
6281 	_adapter *adapter = rtw_netdev_priv(dev);
6282 	u32 len;
6283 	u8 *pbuf = NULL, *pch;
6284 	char *ptmp;
6285 	u8 param[RTW_CUSTOMER_STR_LEN];
6286 	u8 count = 0;
6287 	u8 tmp;
6288 	u8 i;
6289 	u32 pos;
6290 	u8 ret;
6291 	u8 read = 0;
6292 
6293 	if (adapter->registrypriv.mp_mode != 1
6294 		|| !adapter->registrypriv.mp_customer_str)
6295 		return -EFAULT;
6296 
6297 	len = wrqu->data.length + 1;
6298 
6299 	pbuf = (u8 *)rtw_zmalloc(len);
6300 	if (pbuf == NULL) {
6301 		RTW_WARN("%s: no memory!\n", __func__);
6302 		return -ENOMEM;
6303 	}
6304 
6305 	if (copy_from_user(pbuf, wrqu->data.pointer, wrqu->data.length)) {
6306 		rtw_mfree(pbuf, len);
6307 		RTW_WARN("%s: copy from user fail!\n", __func__);
6308 		return -EFAULT;
6309 	}
6310 	RTW_INFO("%s: string=\"%s\"\n", __func__, pbuf);
6311 
6312 	ptmp = (char *)pbuf;
6313 	pch = strsep(&ptmp, ",");
6314 	if ((pch == NULL) || (strlen(pch) == 0)) {
6315 		rtw_mfree(pbuf, len);
6316 		RTW_INFO("%s: parameter error(no cmd)!\n", __func__);
6317 		return -EFAULT;
6318 	}
6319 
6320 	_rtw_memset(param, 0xFF, RTW_CUSTOMER_STR_LEN);
6321 
6322 	if (strcmp(pch, "read") == 0) {
6323 		read = 1;
6324 		ret = rtw_hal_customer_str_read(adapter, param);
6325 
6326 	} else if (strcmp(pch, "write") == 0) {
6327 		do {
6328 			pch = strsep(&ptmp, ":");
6329 			if ((pch == NULL) || (strlen(pch) == 0))
6330 				break;
6331 			if (strlen(pch) != 2
6332 				|| IsHexDigit(*pch) == _FALSE
6333 				|| IsHexDigit(*(pch + 1)) == _FALSE
6334 				|| sscanf(pch, "%hhx", &tmp) != 1
6335 			) {
6336 				RTW_WARN("%s: invalid 8-bit hex!\n", __func__);
6337 				rtw_mfree(pbuf, len);
6338 				return -EFAULT;
6339 			}
6340 
6341 			param[count++] = tmp;
6342 
6343 		} while (count < RTW_CUSTOMER_STR_LEN);
6344 
6345 		if (count == 0) {
6346 			rtw_mfree(pbuf, len);
6347 			RTW_WARN("%s: no input!\n", __func__);
6348 			return -EFAULT;
6349 		}
6350 		ret = rtw_hal_customer_str_write(adapter, param);
6351 	} else {
6352 		rtw_mfree(pbuf, len);
6353 		RTW_INFO("%s: parameter error(unknown cmd)!\n", __func__);
6354 		return -EFAULT;
6355 	}
6356 
6357 	pos = sprintf(extra, "%s: ", read ? "read" : "write");
6358 	if (read == 0 || ret == _SUCCESS) {
6359 		for (i = 0; i < RTW_CUSTOMER_STR_LEN; i++)
6360 			pos += sprintf(extra + pos, "%02x:", param[i]);
6361 		extra[pos] = 0;
6362 		pos--;
6363 	}
6364 	pos += sprintf(extra + pos, " %s", ret == _SUCCESS ? "OK" : "FAIL");
6365 
6366 	wrqu->data.length = strlen(extra) + 1;
6367 
6368 	rtw_mfree(pbuf, len);
6369 	return 0;
6370 }
6371 #endif /* CONFIG_RTW_CUSTOMER_STR */
6372 #if 0 /*defined(CONFIG_MP_INCLUDED)*/
6373 static int rtw_cta_test_start(struct net_device *dev,
6374 			      struct iw_request_info *info,
6375 			      union iwreq_data *wrqu, char *extra)
6376 {
6377 	int ret = 0;
6378 	_adapter	*padapter = (_adapter *)rtw_netdev_priv(dev);
6379 	struct rtw_phl_com_t *phl_com = GET_PHL_COM(adapter_to_dvobj(padapter));
6380 
6381 	RTW_INFO("%s %s\n", __func__, extra);
6382 #if 0
6383 	if (!strcmp(extra, "1"))
6384 		hal_data->in_cta_test = 1;
6385 	else
6386 		hal_data->in_cta_test = 0;
6387 #endif
6388 	rtw_hal_rcr_set_chk_bssid(padapter, MLME_ACTION_NONE);
6389 
6390 	return ret;
6391 }
6392 #endif /*#if defined(CONFIG_MP_INCLUDED)*/
6393 
6394 
6395 #ifdef CONFIG_SDIO_INDIRECT_ACCESS
6396 #define DBG_MP_SDIO_INDIRECT_ACCESS 1
6397 static int rtw_mp_sd_iread(struct net_device *dev
6398 			   , struct iw_request_info *info
6399 			   , struct iw_point *wrqu
6400 			   , char *extra)
6401 {
6402 	char input[16];
6403 	u8 width;
6404 	unsigned long addr;
6405 	u32 ret = 0;
6406 	_adapter *padapter = rtw_netdev_priv(dev);
6407 
6408 	if (wrqu->length > 16) {
6409 		RTW_INFO(FUNC_ADPT_FMT" wrqu->length:%d\n", FUNC_ADPT_ARG(padapter), wrqu->length);
6410 		ret = -EINVAL;
6411 		goto exit;
6412 	}
6413 
6414 	if (copy_from_user(input, wrqu->pointer, wrqu->length)) {
6415 		RTW_INFO(FUNC_ADPT_FMT" copy_from_user fail\n", FUNC_ADPT_ARG(padapter));
6416 		ret = -EFAULT;
6417 		goto exit;
6418 	}
6419 
6420 	_rtw_memset(extra, 0, wrqu->length);
6421 
6422 	if (sscanf(input, "%hhu,%lx", &width, &addr) != 2) {
6423 		RTW_INFO(FUNC_ADPT_FMT" sscanf fail\n", FUNC_ADPT_ARG(padapter));
6424 		ret = -EINVAL;
6425 		goto exit;
6426 	}
6427 
6428 	if (addr > 0x3FFF) {
6429 		RTW_INFO(FUNC_ADPT_FMT" addr:0x%lx\n", FUNC_ADPT_ARG(padapter), addr);
6430 		ret = -EINVAL;
6431 		goto exit;
6432 	}
6433 
6434 	if (DBG_MP_SDIO_INDIRECT_ACCESS)
6435 		RTW_INFO(FUNC_ADPT_FMT" width:%u, addr:0x%lx\n", FUNC_ADPT_ARG(padapter), width, addr);
6436 
6437 	switch (width) {
6438 	case 1:
6439 		sprintf(extra, "0x%02x", rtw_sd_iread8(padapter, addr));
6440 		wrqu->length = strlen(extra);
6441 		break;
6442 	case 2:
6443 		sprintf(extra, "0x%04x", rtw_sd_iread16(padapter, addr));
6444 		wrqu->length = strlen(extra);
6445 		break;
6446 	case 4:
6447 		sprintf(extra, "0x%08x", rtw_sd_iread32(padapter, addr));
6448 		wrqu->length = strlen(extra);
6449 		break;
6450 	default:
6451 		wrqu->length = 0;
6452 		ret = -EINVAL;
6453 		break;
6454 	}
6455 
6456 exit:
6457 	return ret;
6458 }
6459 
6460 static int rtw_mp_sd_iwrite(struct net_device *dev
6461 			    , struct iw_request_info *info
6462 			    , struct iw_point *wrqu
6463 			    , char *extra)
6464 {
6465 	char width;
6466 	unsigned long addr, data;
6467 	int ret = 0;
6468 	_adapter *padapter = rtw_netdev_priv(dev);
6469 	char input[32];
6470 
6471 	if (wrqu->length > 32) {
6472 		RTW_INFO(FUNC_ADPT_FMT" wrqu->length:%d\n", FUNC_ADPT_ARG(padapter), wrqu->length);
6473 		ret = -EINVAL;
6474 		goto exit;
6475 	}
6476 
6477 	if (copy_from_user(input, wrqu->pointer, wrqu->length)) {
6478 		RTW_INFO(FUNC_ADPT_FMT" copy_from_user fail\n", FUNC_ADPT_ARG(padapter));
6479 		ret = -EFAULT;
6480 		goto exit;
6481 	}
6482 
6483 	_rtw_memset(extra, 0, wrqu->length);
6484 
6485 	if (sscanf(input, "%hhu,%lx,%lx", &width, &addr, &data) != 3) {
6486 		RTW_INFO(FUNC_ADPT_FMT" sscanf fail\n", FUNC_ADPT_ARG(padapter));
6487 		ret = -EINVAL;
6488 		goto exit;
6489 	}
6490 
6491 	if (addr > 0x3FFF) {
6492 		RTW_INFO(FUNC_ADPT_FMT" addr:0x%lx\n", FUNC_ADPT_ARG(padapter), addr);
6493 		ret = -EINVAL;
6494 		goto exit;
6495 	}
6496 
6497 	if (DBG_MP_SDIO_INDIRECT_ACCESS)
6498 		RTW_INFO(FUNC_ADPT_FMT" width:%u, addr:0x%lx, data:0x%lx\n", FUNC_ADPT_ARG(padapter), width, addr, data);
6499 
6500 	switch (width) {
6501 	case 1:
6502 		if (data > 0xFF) {
6503 			ret = -EINVAL;
6504 			break;
6505 		}
6506 		rtw_sd_iwrite8(padapter, addr, data);
6507 		break;
6508 	case 2:
6509 		if (data > 0xFFFF) {
6510 			ret = -EINVAL;
6511 			break;
6512 		}
6513 		rtw_sd_iwrite16(padapter, addr, data);
6514 		break;
6515 	case 4:
6516 		rtw_sd_iwrite32(padapter, addr, data);
6517 		break;
6518 	default:
6519 		wrqu->length = 0;
6520 		ret = -EINVAL;
6521 		break;
6522 	}
6523 
6524 exit:
6525 	return ret;
6526 }
6527 #endif /* CONFIG_SDIO_INDIRECT_ACCESS */
6528 
6529 static int rtw_priv_set(struct net_device *dev,
6530 			struct iw_request_info *info,
6531 			union iwreq_data *wdata, char *extra)
6532 {
6533 	struct iw_point *wrqu = (struct iw_point *)wdata;
6534 	u32 subcmd = wrqu->flags;
6535 	_adapter *padapter = rtw_netdev_priv(dev);
6536 
6537 	if (padapter == NULL)
6538 		return -ENETDOWN;
6539 
6540 	if (padapter->netif_up == _FALSE) {
6541 		RTW_INFO(" %s fail =>(padapter->netif_up == _FALSE )\n", __FUNCTION__);
6542 		return -ENETDOWN;
6543 	}
6544 
6545 	if (RTW_CANNOT_RUN(adapter_to_dvobj(padapter))) {
6546 		RTW_INFO("%s fail =>(bSurpriseRemoved == _TRUE) || ( bDriverStopped == _TRUE)\n", __func__);
6547 		return -ENETDOWN;
6548 	}
6549 
6550 	if (extra == NULL) {
6551 		wrqu->length = 0;
6552 		return -EIO;
6553 	}
6554 
6555 	if (subcmd < MP_NULL) {
6556 #ifdef CONFIG_MP_INCLUDED
6557 		rtw_priv_mp_set(dev, info, wdata, extra);
6558 #endif
6559 		return 0;
6560 	}
6561 
6562 	switch (subcmd) {
6563 #ifdef CONFIG_WOWLAN
6564 	case MP_WOW_ENABLE:
6565 		RTW_INFO("set case MP_WOW_ENABLE: %s\n", extra);
6566 
6567 		rtw_wowlan_ctrl(dev, info, wdata, extra);
6568 		break;
6569 	case MP_WOW_SET_PATTERN:
6570 		RTW_INFO("set case MP_WOW_SET_PATTERN: %s\n", extra);
6571 		rtw_wowlan_set_pattern(dev, info, wdata, extra);
6572 		break;
6573 #endif
6574 #ifdef CONFIG_AP_WOWLAN
6575 	case MP_AP_WOW_ENABLE:
6576 		RTW_INFO("set case MP_AP_WOW_ENABLE: %s\n", extra);
6577 		rtw_ap_wowlan_ctrl(dev, info, wdata, extra);
6578 		break;
6579 #endif
6580 #ifdef CONFIG_APPEND_VENDOR_IE_ENABLE
6581 	case VENDOR_IE_SET:
6582 		RTW_INFO("set case VENDOR_IE_SET\n");
6583 		rtw_vendor_ie_set(dev , info , wdata , extra);
6584 		break;
6585 #endif
6586 #if defined(RTW_PHL_TX) || defined(RTW_PHL_RX) || defined(CONFIG_PHL_TEST_SUITE)
6587 	case PHL_TEST_SET:
6588 		RTW_INFO("set case PHL_TEST_SET\n");
6589 		rtw_phl_test_set(dev , info , wdata , extra);
6590 		break;
6591 #endif
6592 	default:
6593 		return -EIO;
6594 	}
6595 
6596 	return 0;
6597 }
6598 
6599 static int rtw_priv_get(struct net_device *dev,
6600 			struct iw_request_info *info,
6601 			union iwreq_data *wdata, char *extra)
6602 {
6603 	struct iw_point *wrqu = (struct iw_point *)wdata;
6604 	u32 subcmd = wrqu->flags;
6605 	_adapter *padapter = rtw_netdev_priv(dev);
6606 	int status = 0 ;
6607 #ifndef CONFIG_MP_INCLUDED
6608 
6609 	if (padapter == NULL)
6610 		return -ENETDOWN;
6611 
6612 	if (padapter->netif_up == _FALSE) {
6613 		RTW_INFO(" %s fail =>(padapter->netif_up == _FALSE )\n", __FUNCTION__);
6614 		return -ENETDOWN;
6615 	}
6616 
6617 	if (RTW_CANNOT_RUN(adapter_to_dvobj(padapter))) {
6618 		RTW_INFO("%s fail =>(padapter->bSurpriseRemoved == _TRUE) || ( padapter->bDriverStopped == _TRUE)\n", __func__);
6619 		return -ENETDOWN;
6620 	}
6621 
6622 	if (extra == NULL) {
6623 		wrqu->length = 0;
6624 		return -EIO;
6625 	}
6626 #endif
6627 	if (subcmd < MP_NULL) {
6628 #ifdef CONFIG_MP_INCLUDED
6629 		status = rtw_priv_mp_get(dev, info, wdata, extra);
6630 		rtw_msleep_os(10); /* delay 5ms for sending pkt before exit adb shell operation */
6631 #endif
6632 
6633 	} else {
6634 			switch (subcmd) {
6635 #ifdef CONFIG_SDIO_INDIRECT_ACCESS
6636 			case MP_SD_IREAD:
6637 				status = rtw_mp_sd_iread(dev, info, wrqu, extra);
6638 				break;
6639 			case MP_SD_IWRITE:
6640 				status = rtw_mp_sd_iwrite(dev, info, wrqu, extra);
6641 				break;
6642 #endif
6643 #ifdef CONFIG_APPEND_VENDOR_IE_ENABLE
6644 			case VENDOR_IE_GET:
6645 				RTW_INFO("get case VENDOR_IE_GET\n");
6646 				status = rtw_vendor_ie_get(dev , info , wdata , extra);
6647 				break;
6648 #endif
6649 			default:
6650 				return -EIO;
6651 			}
6652 		}
6653 
6654 	return status;
6655 }
6656 
6657 
6658 #ifdef CONFIG_TDLS
6659 static int rtw_wx_tdls_wfd_enable(struct net_device *dev,
6660 				  struct iw_request_info *info,
6661 				  union iwreq_data *wrqu, char *extra)
6662 {
6663 	int ret = 0;
6664 
6665 #ifdef CONFIG_WFD
6666 
6667 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6668 
6669 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
6670 
6671 	if (extra[0] == '0')
6672 		rtw_tdls_wfd_enable(padapter, 0);
6673 	else
6674 		rtw_tdls_wfd_enable(padapter, 1);
6675 
6676 #endif /* CONFIG_WFD */
6677 
6678 	return ret;
6679 }
6680 
6681 static int rtw_tdls_weaksec(struct net_device *dev,
6682 			    struct iw_request_info *info,
6683 			    union iwreq_data *wrqu, char *extra)
6684 {
6685 	int ret = 0;
6686 
6687 #ifdef CONFIG_TDLS
6688 
6689 	u8 i, j;
6690 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6691 
6692 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
6693 
6694 	if (extra[0] == '0')
6695 		padapter->wdinfo.wfd_tdls_weaksec = 0;
6696 	else
6697 		padapter->wdinfo.wfd_tdls_weaksec = 1;
6698 
6699 #endif /* CONFIG_TDLS */
6700 
6701 	return ret;
6702 }
6703 
6704 
6705 static int rtw_tdls_enable(struct net_device *dev,
6706 			   struct iw_request_info *info,
6707 			   union iwreq_data *wrqu, char *extra)
6708 {
6709 	int ret = 0;
6710 
6711 #ifdef CONFIG_TDLS
6712 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6713 
6714 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
6715 
6716 	if (extra[0] == '0')
6717 		rtw_disable_tdls_func(padapter, _TRUE);
6718 	else if (extra[0] == '1')
6719 		rtw_enable_tdls_func(padapter);
6720 #endif /* CONFIG_TDLS */
6721 
6722 	return ret;
6723 }
6724 
6725 static int rtw_tdls_setup(struct net_device *dev,
6726 			  struct iw_request_info *info,
6727 			  union iwreq_data *wrqu, char *extra)
6728 {
6729 	int ret = 0;
6730 #ifdef CONFIG_TDLS
6731 	u8 i, j;
6732 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6733 	struct tdls_txmgmt txmgmt;
6734 #ifdef CONFIG_WFD
6735 	struct wifidirect_info *pwdinfo = &(padapter->wdinfo);
6736 #endif /* CONFIG_WFD */
6737 
6738 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
6739 
6740 	if (wrqu->data.length - 1 != 17) {
6741 		RTW_INFO("[%s] length:%d != 17\n", __FUNCTION__, (wrqu->data.length - 1));
6742 		return ret;
6743 	}
6744 
6745 	_rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
6746 	for (i = 0, j = 0 ; i < ETH_ALEN; i++, j += 3)
6747 		txmgmt.peer[i] = key_2char2num(*(extra + j), *(extra + j + 1));
6748 
6749 #ifdef CONFIG_WFD
6750 	if (_AES_ != padapter->securitypriv.dot11PrivacyAlgrthm) {
6751 		/* Weak Security situation with AP. */
6752 		if (0 == pwdinfo->wfd_tdls_weaksec)	{
6753 			/* Can't send the tdls setup request out!! */
6754 			RTW_INFO("[%s] Current link is not AES, "
6755 				"SKIP sending the tdls setup request!!\n", __FUNCTION__);
6756 		} else
6757 			issue_tdls_setup_req(padapter, &txmgmt, _TRUE);
6758 	} else
6759 #endif /* CONFIG_WFD */
6760 	{
6761 		issue_tdls_setup_req(padapter, &txmgmt, _TRUE);
6762 	}
6763 #endif /* CONFIG_TDLS */
6764 
6765 	return ret;
6766 }
6767 
6768 static int rtw_tdls_teardown(struct net_device *dev,
6769 			     struct iw_request_info *info,
6770 			     union iwreq_data *wrqu, char *extra)
6771 {
6772 	int ret = 0;
6773 
6774 #ifdef CONFIG_TDLS
6775 
6776 	u8 i, j;
6777 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6778 	struct sta_info *ptdls_sta = NULL;
6779 	struct tdls_txmgmt txmgmt;
6780 
6781 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
6782 
6783 	if (wrqu->data.length - 1 != 17 && wrqu->data.length - 1 != 19) {
6784 		RTW_INFO("[%s] length:%d != 17 or 19\n",
6785 			 __FUNCTION__, (wrqu->data.length - 1));
6786 		return ret;
6787 	}
6788 
6789 	_rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
6790 	for (i = 0, j = 0; i < ETH_ALEN; i++, j += 3)
6791 		txmgmt.peer[i] = key_2char2num(*(extra + j), *(extra + j + 1));
6792 
6793 	ptdls_sta = rtw_get_stainfo(&(padapter->stapriv), txmgmt.peer);
6794 
6795 	if (ptdls_sta != NULL) {
6796 		txmgmt.status_code = _RSON_TDLS_TEAR_UN_RSN_;
6797 		if (wrqu->data.length - 1 == 19)
6798 			issue_tdls_teardown(padapter, &txmgmt, _FALSE);
6799 		else
6800 			issue_tdls_teardown(padapter, &txmgmt, _TRUE);
6801 	} else
6802 		RTW_INFO("TDLS peer not found\n");
6803 #endif /* CONFIG_TDLS */
6804 
6805 	return ret;
6806 }
6807 
6808 static int rtw_tdls_discovery(struct net_device *dev,
6809 			      struct iw_request_info *info,
6810 			      union iwreq_data *wrqu, char *extra)
6811 {
6812 	int ret = 0;
6813 
6814 #ifdef CONFIG_TDLS
6815 
6816 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6817 	struct tdls_txmgmt	txmgmt;
6818 	int i = 0, j = 0;
6819 
6820 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
6821 
6822 	_rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
6823 	for (i = 0, j = 0 ; i < ETH_ALEN; i++, j += 3)
6824 		txmgmt.peer[i] = key_2char2num(*(extra + j), *(extra + j + 1));
6825 
6826 	issue_tdls_dis_req(padapter, &txmgmt);
6827 
6828 #endif /* CONFIG_TDLS */
6829 
6830 	return ret;
6831 }
6832 
6833 static int rtw_tdls_ch_switch(struct net_device *dev,
6834 			      struct iw_request_info *info,
6835 			      union iwreq_data *wrqu, char *extra)
6836 {
6837 	int ret = 0;
6838 
6839 #ifdef CONFIG_TDLS
6840 #ifdef CONFIG_TDLS_CH_SW
6841 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6842 	struct tdls_ch_switch *pchsw_info = &padapter->tdlsinfo.chsw_info;
6843 	u8 i, j;
6844 	struct sta_info *ptdls_sta = NULL;
6845 	u8 take_care_iqk;
6846 
6847 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
6848 
6849 	if (rtw_tdls_is_chsw_allowed(padapter) == _FALSE) {
6850 		RTW_INFO("TDLS channel switch is not allowed\n");
6851 		return ret;
6852 	}
6853 
6854 	for (i = 0, j = 0 ; i < ETH_ALEN; i++, j += 3)
6855 		pchsw_info->addr[i] = key_2char2num(*(extra + j), *(extra + j + 1));
6856 
6857 	ptdls_sta = rtw_get_stainfo(&padapter->stapriv, pchsw_info->addr);
6858 	if (ptdls_sta == NULL)
6859 		return ret;
6860 
6861 	pchsw_info->ch_sw_state |= TDLS_CH_SW_INITIATOR_STATE;
6862 
6863 	if (ptdls_sta != NULL) {
6864 		if (pchsw_info->off_ch_num == 0)
6865 			pchsw_info->off_ch_num = 11;
6866 	} else
6867 		RTW_INFO("TDLS peer not found\n");
6868 
6869 	rtw_pm_set_lps(padapter, PM_PS_MODE_ACTIVE);
6870 
6871 	rtw_hal_get_hwreg(padapter, HW_VAR_CH_SW_NEED_TO_TAKE_CARE_IQK_INFO, &take_care_iqk);
6872 	if (take_care_iqk == _TRUE) {
6873 		u8 central_chnl;
6874 		u8 bw_mode;
6875 
6876 		bw_mode = (pchsw_info->ch_offset) ? CHANNEL_WIDTH_40 : CHANNEL_WIDTH_20;
6877 		central_chnl = rtw_phl_get_center_ch(pchsw_info->off_ch_num, bw_mode, pchsw_info->ch_offset);
6878 		if (rtw_hal_ch_sw_iqk_info_search(padapter, central_chnl, bw_mode) >= 0)
6879 			rtw_tdls_cmd(padapter, ptdls_sta->phl_sta->mac_addr, TDLS_CH_SW_START);
6880 		else
6881 			rtw_tdls_cmd(padapter, ptdls_sta->phl_sta->mac_addr, TDLS_CH_SW_PREPARE);
6882 	} else
6883 		rtw_tdls_cmd(padapter, ptdls_sta->phl_sta->mac_addr, TDLS_CH_SW_START);
6884 
6885 	/* issue_tdls_ch_switch_req(padapter, ptdls_sta); */
6886 	/* RTW_INFO("issue tdls ch switch req\n"); */
6887 
6888 #endif /* CONFIG_TDLS_CH_SW */
6889 #endif /* CONFIG_TDLS */
6890 
6891 	return ret;
6892 }
6893 
6894 static int rtw_tdls_ch_switch_off(struct net_device *dev,
6895 				  struct iw_request_info *info,
6896 				  union iwreq_data *wrqu, char *extra)
6897 {
6898 	int ret = 0;
6899 
6900 #ifdef CONFIG_TDLS
6901 #ifdef CONFIG_TDLS_CH_SW
6902 
6903 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6904 	struct tdls_ch_switch *pchsw_info = &padapter->tdlsinfo.chsw_info;
6905 	u8 i, j, mac_addr[ETH_ALEN];
6906 	struct sta_info *ptdls_sta = NULL;
6907 	struct tdls_txmgmt txmgmt;
6908 
6909 	_rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
6910 
6911 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
6912 
6913 	if (rtw_tdls_is_chsw_allowed(padapter) == _FALSE) {
6914 		RTW_INFO("TDLS channel switch is not allowed\n");
6915 		return ret;
6916 	}
6917 
6918 	if (wrqu->data.length >= 17) {
6919 		for (i = 0, j = 0 ; i < ETH_ALEN; i++, j += 3)
6920 			mac_addr[i] = key_2char2num(*(extra + j), *(extra + j + 1));
6921 		ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
6922 	}
6923 
6924 	if (ptdls_sta == NULL)
6925 		return ret;
6926 
6927 	rtw_tdls_cmd(padapter, ptdls_sta->phl_sta->mac_addr, TDLS_CH_SW_END_TO_BASE_CHNL);
6928 
6929 	pchsw_info->ch_sw_state &= ~(TDLS_CH_SW_INITIATOR_STATE |
6930 				     TDLS_CH_SWITCH_ON_STATE |
6931 				     TDLS_PEER_AT_OFF_STATE);
6932 	_rtw_memset(pchsw_info->addr, 0x00, ETH_ALEN);
6933 
6934 	ptdls_sta->ch_switch_time = 0;
6935 	ptdls_sta->ch_switch_timeout = 0;
6936 	_cancel_timer_ex(&ptdls_sta->ch_sw_timer);
6937 	_cancel_timer_ex(&ptdls_sta->delay_timer);
6938 	_cancel_timer_ex(&ptdls_sta->stay_on_base_chnl_timer);
6939 	_cancel_timer_ex(&ptdls_sta->ch_sw_monitor_timer);
6940 
6941 	rtw_pm_set_lps(padapter, PM_PS_MODE_MAX);
6942 #endif /* CONFIG_TDLS_CH_SW */
6943 #endif /* CONFIG_TDLS */
6944 
6945 	return ret;
6946 }
6947 
6948 static int rtw_tdls_dump_ch(struct net_device *dev,
6949 			    struct iw_request_info *info,
6950 			    union iwreq_data *wrqu, char *extra)
6951 {
6952 	int ret = 0;
6953 
6954 #ifdef CONFIG_TDLS
6955 #ifdef CONFIG_TDLS_CH_SW
6956 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6957 	struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
6958 
6959 	RTW_INFO("[%s] dump_stack:%s\n", __FUNCTION__, extra);
6960 
6961 	extra[wrqu->data.length] = 0x00;
6962 	ptdlsinfo->chsw_info.dump_stack = rtw_atoi(extra);
6963 
6964 	return ret;
6965 
6966 #endif
6967 #endif /* CONFIG_TDLS */
6968 
6969 	return ret;
6970 }
6971 
6972 static int rtw_tdls_off_ch_num(struct net_device *dev,
6973 			       struct iw_request_info *info,
6974 			       union iwreq_data *wrqu, char *extra)
6975 {
6976 	int ret = 0;
6977 
6978 #ifdef CONFIG_TDLS
6979 #ifdef CONFIG_TDLS_CH_SW
6980 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6981 	struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
6982 
6983 	RTW_INFO("[%s] off_ch_num:%s\n", __FUNCTION__, extra);
6984 
6985 	extra[wrqu->data.length] = 0x00;
6986 	ptdlsinfo->chsw_info.off_ch_num = rtw_atoi(extra);
6987 
6988 	return ret;
6989 
6990 #endif
6991 #endif /* CONFIG_TDLS */
6992 
6993 	return ret;
6994 }
6995 
6996 static int rtw_tdls_ch_offset(struct net_device *dev,
6997 			      struct iw_request_info *info,
6998 			      union iwreq_data *wrqu, char *extra)
6999 {
7000 	int ret = 0;
7001 
7002 #ifdef CONFIG_TDLS
7003 #ifdef CONFIG_TDLS_CH_SW
7004 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7005 	struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
7006 
7007 	RTW_INFO("[%s] ch_offset:%s\n", __FUNCTION__, extra);
7008 
7009 	extra[wrqu->data.length] = 0x00;
7010 	switch (rtw_atoi(extra)) {
7011 	case IEEE80211_SCA:
7012 		ptdlsinfo->chsw_info.ch_offset = CHAN_OFFSET_UPPER;
7013 		break;
7014 
7015 	case IEEE80211_SCB:
7016 		ptdlsinfo->chsw_info.ch_offset = CHAN_OFFSET_LOWER;
7017 		break;
7018 
7019 	default:
7020 		ptdlsinfo->chsw_info.ch_offset = CHAN_OFFSET_NO_EXT;
7021 		break;
7022 	}
7023 
7024 	return ret;
7025 
7026 #endif
7027 #endif /* CONFIG_TDLS */
7028 
7029 	return ret;
7030 }
7031 
7032 static int rtw_tdls_pson(struct net_device *dev,
7033 			 struct iw_request_info *info,
7034 			 union iwreq_data *wrqu, char *extra)
7035 {
7036 	int ret = 0;
7037 
7038 #ifdef CONFIG_TDLS
7039 
7040 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7041 	u8 i, j, mac_addr[ETH_ALEN];
7042 	struct sta_info *ptdls_sta = NULL;
7043 
7044 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
7045 
7046 	for (i = 0, j = 0; i < ETH_ALEN; i++, j += 3)
7047 		mac_addr[i] = key_2char2num(*(extra + j), *(extra + j + 1));
7048 
7049 	ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
7050 
7051 	issue_nulldata_to_TDLS_peer_STA(padapter, ptdls_sta->phl_sta->mac_addr, 1, 3, 500);
7052 
7053 #endif /* CONFIG_TDLS */
7054 
7055 	return ret;
7056 }
7057 
7058 static int rtw_tdls_psoff(struct net_device *dev,
7059 			  struct iw_request_info *info,
7060 			  union iwreq_data *wrqu, char *extra)
7061 {
7062 	int ret = 0;
7063 
7064 #ifdef CONFIG_TDLS
7065 
7066 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7067 	u8 i, j, mac_addr[ETH_ALEN];
7068 	struct sta_info *ptdls_sta = NULL;
7069 
7070 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
7071 
7072 	for (i = 0, j = 0; i < ETH_ALEN; i++, j += 3)
7073 		mac_addr[i] = key_2char2num(*(extra + j), *(extra + j + 1));
7074 
7075 	ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
7076 
7077 	if (ptdls_sta)
7078 		issue_nulldata_to_TDLS_peer_STA(padapter, ptdls_sta->phl_sta->mac_addr, 0, 3, 500);
7079 
7080 #endif /* CONFIG_TDLS */
7081 
7082 	return ret;
7083 }
7084 
7085 static int rtw_tdls_setip(struct net_device *dev,
7086 			  struct iw_request_info *info,
7087 			  union iwreq_data *wrqu, char *extra)
7088 {
7089 	int ret = 0;
7090 
7091 #ifdef CONFIG_TDLS
7092 #ifdef CONFIG_WFD
7093 
7094 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7095 	struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
7096 	struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
7097 	u8 i = 0, j = 0, k = 0, tag = 0;
7098 
7099 	RTW_INFO("[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1);
7100 
7101 	while (i < 4) {
7102 		for (j = 0; j < 4; j++) {
7103 			if (*(extra + j + tag) == '.' || *(extra + j + tag) == '\0') {
7104 				if (j == 1)
7105 					pwfd_info->ip_address[i] = convert_ip_addr('0', '0', *(extra + (j - 1) + tag));
7106 				if (j == 2)
7107 					pwfd_info->ip_address[i] = convert_ip_addr('0', *(extra + (j - 2) + tag), *(extra + (j - 1) + tag));
7108 				if (j == 3)
7109 					pwfd_info->ip_address[i] = convert_ip_addr(*(extra + (j - 3) + tag), *(extra + (j - 2) + tag), *(extra + (j - 1) + tag));
7110 
7111 				tag += j + 1;
7112 				break;
7113 			}
7114 		}
7115 		i++;
7116 	}
7117 
7118 	RTW_INFO("[%s] Set IP = %u.%u.%u.%u\n", __FUNCTION__,
7119 		 ptdlsinfo->wfd_info->ip_address[0],
7120 		 ptdlsinfo->wfd_info->ip_address[1],
7121 		 ptdlsinfo->wfd_info->ip_address[2],
7122 		 ptdlsinfo->wfd_info->ip_address[3]);
7123 
7124 #endif /* CONFIG_WFD */
7125 #endif /* CONFIG_TDLS */
7126 
7127 	return ret;
7128 }
7129 
7130 static int rtw_tdls_getip(struct net_device *dev,
7131 			  struct iw_request_info *info,
7132 			  union iwreq_data *wrqu, char *extra)
7133 {
7134 	int ret = 0;
7135 
7136 #ifdef CONFIG_TDLS
7137 #ifdef CONFIG_WFD
7138 
7139 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7140 	struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
7141 	struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
7142 
7143 	RTW_INFO("[%s]\n", __FUNCTION__);
7144 
7145 	sprintf(extra, "\n\n%u.%u.%u.%u\n",
7146 		pwfd_info->peer_ip_address[0], pwfd_info->peer_ip_address[1],
7147 		pwfd_info->peer_ip_address[2], pwfd_info->peer_ip_address[3]);
7148 
7149 	RTW_INFO("[%s] IP=%u.%u.%u.%u\n", __FUNCTION__,
7150 		 pwfd_info->peer_ip_address[0], pwfd_info->peer_ip_address[1],
7151 		 pwfd_info->peer_ip_address[2], pwfd_info->peer_ip_address[3]);
7152 
7153 	wrqu->data.length = strlen(extra);
7154 
7155 #endif /* CONFIG_WFD */
7156 #endif /* CONFIG_TDLS */
7157 
7158 	return ret;
7159 }
7160 
7161 static int rtw_tdls_getport(struct net_device *dev,
7162 			    struct iw_request_info *info,
7163 			    union iwreq_data *wrqu, char *extra)
7164 {
7165 
7166 	int ret = 0;
7167 
7168 #ifdef CONFIG_TDLS
7169 #ifdef CONFIG_WFD
7170 
7171 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7172 	struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
7173 	struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
7174 
7175 	RTW_INFO("[%s]\n", __FUNCTION__);
7176 
7177 	sprintf(extra, "\n\n%d\n", pwfd_info->peer_rtsp_ctrlport);
7178 	RTW_INFO("[%s] remote port = %d\n",
7179 		 __FUNCTION__, pwfd_info->peer_rtsp_ctrlport);
7180 
7181 	wrqu->data.length = strlen(extra);
7182 
7183 #endif /* CONFIG_WFD */
7184 #endif /* CONFIG_TDLS */
7185 
7186 	return ret;
7187 
7188 }
7189 
7190 /* WFDTDLS, for sigma test */
7191 static int rtw_tdls_dis_result(struct net_device *dev,
7192 			       struct iw_request_info *info,
7193 			       union iwreq_data *wrqu, char *extra)
7194 {
7195 
7196 	int ret = 0;
7197 
7198 #ifdef CONFIG_TDLS
7199 #ifdef CONFIG_WFD
7200 
7201 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7202 	struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
7203 
7204 	RTW_INFO("[%s]\n", __FUNCTION__);
7205 
7206 	if (ptdlsinfo->dev_discovered == _TRUE) {
7207 		sprintf(extra, "\n\nDis=1\n");
7208 		ptdlsinfo->dev_discovered = _FALSE;
7209 	}
7210 
7211 	wrqu->data.length = strlen(extra);
7212 
7213 #endif /* CONFIG_WFD */
7214 #endif /* CONFIG_TDLS */
7215 
7216 	return ret;
7217 
7218 }
7219 
7220 /* WFDTDLS, for sigma test */
7221 static int rtw_wfd_tdls_status(struct net_device *dev,
7222 			       struct iw_request_info *info,
7223 			       union iwreq_data *wrqu, char *extra)
7224 {
7225 
7226 	int ret = 0;
7227 
7228 #ifdef CONFIG_TDLS
7229 
7230 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7231 	struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
7232 
7233 	RTW_INFO("[%s]\n", __FUNCTION__);
7234 
7235 	sprintf(extra, "\nlink_established:%d\n"
7236 		"sta_cnt:%d\n"
7237 		"sta_maximum:%d\n"
7238 		"cur_channel:%d\n"
7239 		"tdls_enable:%d"
7240 #ifdef CONFIG_TDLS_CH_SW
7241 		"ch_sw_state:%08x\n"
7242 		"chsw_on:%d\n"
7243 		"off_ch_num:%d\n"
7244 		"cur_time:%d\n"
7245 		"ch_offset:%d\n"
7246 		"delay_swtich_back:%d"
7247 #endif
7248 		,
7249 		ptdlsinfo->link_established, ptdlsinfo->sta_cnt,
7250 		ptdlsinfo->sta_maximum, ptdlsinfo->cur_channel,
7251 		rtw_is_tdls_enabled(padapter)
7252 #ifdef CONFIG_TDLS_CH_SW
7253 		,
7254 		ptdlsinfo->chsw_info.ch_sw_state,
7255 		ATOMIC_READ(&padapter->tdlsinfo.chsw_info.chsw_on),
7256 		ptdlsinfo->chsw_info.off_ch_num,
7257 		ptdlsinfo->chsw_info.cur_time,
7258 		ptdlsinfo->chsw_info.ch_offset,
7259 		ptdlsinfo->chsw_info.delay_switch_back
7260 #endif
7261 	       );
7262 
7263 	wrqu->data.length = strlen(extra);
7264 
7265 #endif /* CONFIG_TDLS */
7266 
7267 	return ret;
7268 
7269 }
7270 
7271 static int rtw_tdls_getsta(struct net_device *dev,
7272 			   struct iw_request_info *info,
7273 			   union iwreq_data *wrqu, char *extra)
7274 {
7275 
7276 	int ret = 0;
7277 #ifdef CONFIG_TDLS
7278 	u8 i, j;
7279 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7280 	u8 addr[ETH_ALEN] = {0};
7281 	char charmac[17];
7282 	struct sta_info *ptdls_sta = NULL;
7283 
7284 	RTW_INFO("[%s] %s %d\n", __FUNCTION__,
7285 		 (char *)wrqu->data.pointer, wrqu->data.length - 1);
7286 
7287 	if (copy_from_user(charmac, wrqu->data.pointer + 9, 17)) {
7288 		ret = -EFAULT;
7289 		goto exit;
7290 	}
7291 
7292 	RTW_INFO("[%s] %d, charmac:%s\n", __FUNCTION__, __LINE__, charmac);
7293 	for (i = 0, j = 0 ; i < ETH_ALEN; i++, j += 3)
7294 		addr[i] = key_2char2num(*(charmac + j), *(charmac + j + 1));
7295 
7296 	RTW_INFO("[%s] %d, charmac:%s, addr:"MAC_FMT"\n",
7297 		 __FUNCTION__, __LINE__, charmac, MAC_ARG(addr));
7298 	ptdls_sta = rtw_get_stainfo(&padapter->stapriv, addr);
7299 	if (ptdls_sta) {
7300 		sprintf(extra, "\n\ntdls_sta_state=0x%08x\n", ptdls_sta->tdls_sta_state);
7301 		RTW_INFO("\n\ntdls_sta_state=%d\n", ptdls_sta->tdls_sta_state);
7302 	} else {
7303 		sprintf(extra, "\n\nNot found this sta\n");
7304 		RTW_INFO("\n\nNot found this sta\n");
7305 	}
7306 	wrqu->data.length = strlen(extra);
7307 
7308 exit:
7309 #endif /* CONFIG_TDLS */
7310 	return ret;
7311 
7312 }
7313 
7314 static int rtw_tdls_get_best_ch(struct net_device *dev,
7315 				struct iw_request_info *info,
7316 				union iwreq_data *wrqu, char *extra)
7317 {
7318 #ifdef CONFIG_FIND_BEST_CHANNEL
7319 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7320 	struct rf_ctl_t *rfctl = adapter_to_rfctl(padapter);
7321 	u32 i, best_channel_24G = 1, best_channel_5G = 36, index_24G = 0, index_5G = 0;
7322 
7323 	for (i = 0; i < rfctl->max_chan_nums && rfctl->channel_set[i].ChannelNum != 0; i++) {
7324 		if (rfctl->channel_set[i].ChannelNum == 1)
7325 			index_24G = i;
7326 		if (rfctl->channel_set[i].ChannelNum == 36)
7327 			index_5G = i;
7328 	}
7329 
7330 	for (i = 0; i < rfctl->max_chan_nums && rfctl->channel_set[i].ChannelNum != 0; i++) {
7331 		/* 2.4G */
7332 		if (rfctl->channel_set[i].ChannelNum == 6 || rfctl->channel_set[i].ChannelNum == 11) {
7333 			if (rfctl->channel_set[i].rx_count < rfctl->channel_set[index_24G].rx_count) {
7334 				index_24G = i;
7335 				best_channel_24G = rfctl->channel_set[i].ChannelNum;
7336 			}
7337 		}
7338 
7339 		/* 5G */
7340 		if (rfctl->channel_set[i].ChannelNum >= 36
7341 		    && rfctl->channel_set[i].ChannelNum < 140) {
7342 			/* Find primary channel */
7343 			if (((rfctl->channel_set[i].ChannelNum - 36) % 8 == 0)
7344 			    && (rfctl->channel_set[i].rx_count < rfctl->channel_set[index_5G].rx_count)) {
7345 				index_5G = i;
7346 				best_channel_5G = rfctl->channel_set[i].ChannelNum;
7347 			}
7348 		}
7349 
7350 		if (rfctl->channel_set[i].ChannelNum >= 149
7351 		    && rfctl->channel_set[i].ChannelNum < 165) {
7352 			/* Find primary channel */
7353 			if (((rfctl->channel_set[i].ChannelNum - 149) % 8 == 0)
7354 			    && (rfctl->channel_set[i].rx_count < rfctl->channel_set[index_5G].rx_count)) {
7355 				index_5G = i;
7356 				best_channel_5G = rfctl->channel_set[i].ChannelNum;
7357 			}
7358 		}
7359 #if 1 /* debug */
7360 		RTW_INFO("The rx cnt of channel %3d = %d\n",
7361 			 rfctl->channel_set[i].ChannelNum,
7362 			 rfctl->channel_set[i].rx_count);
7363 #endif
7364 	}
7365 
7366 	sprintf(extra, "\nbest_channel_24G = %d\n", best_channel_24G);
7367 	RTW_INFO("best_channel_24G = %d\n", best_channel_24G);
7368 
7369 	if (index_5G != 0) {
7370 		sprintf(extra, "best_channel_5G = %d\n", best_channel_5G);
7371 		RTW_INFO("best_channel_5G = %d\n", best_channel_5G);
7372 	}
7373 
7374 	wrqu->data.length = strlen(extra);
7375 
7376 #endif
7377 
7378 	return 0;
7379 
7380 }
7381 #endif /*#ifdef CONFIG_TDLS*/
7382 static int rtw_tdls(struct net_device *dev,
7383 		    struct iw_request_info *info,
7384 		    union iwreq_data *wrqu, char *extra)
7385 {
7386 	int ret = 0;
7387 
7388 #ifdef CONFIG_TDLS
7389 
7390 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7391 
7392 	RTW_INFO("[%s] extra = %s\n", __FUNCTION__, extra);
7393 
7394 	if (rtw_hw_chk_wl_func(adapter_to_dvobj(padapter), WL_FUNC_TDLS) == _FALSE) {
7395 		RTW_INFO("Discard tdls oper since hal doesn't support tdls\n");
7396 		return 0;
7397 	}
7398 
7399 	if (rtw_is_tdls_enabled(padapter) == _FALSE) {
7400 		RTW_INFO("TDLS is not enabled\n");
7401 		return 0;
7402 	}
7403 
7404 	/* WFD Sigma will use the tdls enable command to let the driver know we want to test the tdls now! */
7405 
7406 	if (rtw_hw_chk_wl_func(adapter_to_dvobj(padapter), WL_FUNC_MIRACAST)) {
7407 		if (_rtw_memcmp(extra, "wfdenable=", 10)) {
7408 			wrqu->data.length -= 10;
7409 			rtw_wx_tdls_wfd_enable(dev, info, wrqu, &extra[10]);
7410 			return ret;
7411 		}
7412 	}
7413 
7414 	if (_rtw_memcmp(extra, "weaksec=", 8)) {
7415 		wrqu->data.length -= 8;
7416 		rtw_tdls_weaksec(dev, info, wrqu, &extra[8]);
7417 		return ret;
7418 	} else if (_rtw_memcmp(extra, "tdlsenable=", 11)) {
7419 		wrqu->data.length -= 11;
7420 		rtw_tdls_enable(dev, info, wrqu, &extra[11]);
7421 		return ret;
7422 	}
7423 
7424 	if (_rtw_memcmp(extra, "setup=", 6)) {
7425 		wrqu->data.length -= 6;
7426 		rtw_tdls_setup(dev, info, wrqu, &extra[6]);
7427 	} else if (_rtw_memcmp(extra, "tear=", 5)) {
7428 		wrqu->data.length -= 5;
7429 		rtw_tdls_teardown(dev, info, wrqu, &extra[5]);
7430 	} else if (_rtw_memcmp(extra, "dis=", 4)) {
7431 		wrqu->data.length -= 4;
7432 		rtw_tdls_discovery(dev, info, wrqu, &extra[4]);
7433 	} else if (_rtw_memcmp(extra, "swoff=", 6)) {
7434 		wrqu->data.length -= 6;
7435 		rtw_tdls_ch_switch_off(dev, info, wrqu, &extra[6]);
7436 	} else if (_rtw_memcmp(extra, "sw=", 3)) {
7437 		wrqu->data.length -= 3;
7438 		rtw_tdls_ch_switch(dev, info, wrqu, &extra[3]);
7439 	} else if (_rtw_memcmp(extra, "dumpstack=", 10)) {
7440 		wrqu->data.length -= 10;
7441 		rtw_tdls_dump_ch(dev, info, wrqu, &extra[10]);
7442 	} else if (_rtw_memcmp(extra, "offchnum=", 9)) {
7443 		wrqu->data.length -= 9;
7444 		rtw_tdls_off_ch_num(dev, info, wrqu, &extra[9]);
7445 	} else if (_rtw_memcmp(extra, "choffset=", 9)) {
7446 		wrqu->data.length -= 9;
7447 		rtw_tdls_ch_offset(dev, info, wrqu, &extra[9]);
7448 	} else if (_rtw_memcmp(extra, "pson=", 5)) {
7449 		wrqu->data.length -= 5;
7450 		rtw_tdls_pson(dev, info, wrqu, &extra[5]);
7451 	} else if (_rtw_memcmp(extra, "psoff=", 6)) {
7452 		wrqu->data.length -= 6;
7453 		rtw_tdls_psoff(dev, info, wrqu, &extra[6]);
7454 	}
7455 
7456 #ifdef CONFIG_WFD
7457 	if (rtw_hw_chk_wl_func(adapter_to_dvobj(padapter), WL_FUNC_MIRACAST)) {
7458 		if (_rtw_memcmp(extra, "setip=", 6)) {
7459 			wrqu->data.length -= 6;
7460 			rtw_tdls_setip(dev, info, wrqu, &extra[6]);
7461 		} else if (_rtw_memcmp(extra, "tprobe=", 6))
7462 			issue_tunneled_probe_req((_adapter *)rtw_netdev_priv(dev));
7463 	}
7464 #endif /* CONFIG_WFD */
7465 
7466 #endif /* CONFIG_TDLS */
7467 
7468 	return ret;
7469 }
7470 
7471 
7472 static int rtw_tdls_get(struct net_device *dev,
7473 			struct iw_request_info *info,
7474 			union iwreq_data *wrqu, char *extra)
7475 {
7476 	int ret = 0;
7477 
7478 #ifdef CONFIG_TDLS
7479 
7480 	RTW_INFO("[%s] extra = %s\n", __FUNCTION__, (char *) wrqu->data.pointer);
7481 
7482 	if (_rtw_memcmp(wrqu->data.pointer, "ip", 2))
7483 		rtw_tdls_getip(dev, info, wrqu, extra);
7484 	else if (_rtw_memcmp(wrqu->data.pointer, "port", 4))
7485 		rtw_tdls_getport(dev, info, wrqu, extra);
7486 	/* WFDTDLS, for sigma test */
7487 	else if (_rtw_memcmp(wrqu->data.pointer, "dis", 3))
7488 		rtw_tdls_dis_result(dev, info, wrqu, extra);
7489 	else if (_rtw_memcmp(wrqu->data.pointer, "status", 6))
7490 		rtw_wfd_tdls_status(dev, info, wrqu, extra);
7491 	else if (_rtw_memcmp(wrqu->data.pointer, "tdls_sta=", 9))
7492 		rtw_tdls_getsta(dev, info, wrqu, extra);
7493 	else if (_rtw_memcmp(wrqu->data.pointer, "best_ch", 7))
7494 		rtw_tdls_get_best_ch(dev, info, wrqu, extra);
7495 #endif /* CONFIG_TDLS */
7496 
7497 	return ret;
7498 }
7499 
7500 #if 0 /*#ifdef CONFIG_MAC_LOOPBACK_DRIVER*/
7501 static s32 initLoopback(_adapter *padapter)
7502 {
7503 	PLOOPBACKDATA ploopback;
7504 
7505 
7506 	if (padapter->ploopback == NULL) {
7507 		ploopback = (PLOOPBACKDATA)rtw_zmalloc(sizeof(LOOPBACKDATA));
7508 		if (ploopback == NULL)
7509 			return -ENOMEM;
7510 
7511 		_rtw_init_sema(&ploopback->sema, 0);
7512 		ploopback->bstop = _TRUE;
7513 		ploopback->cnt = 0;
7514 		ploopback->size = 300;
7515 		_rtw_memset(ploopback->msg, 0, sizeof(ploopback->msg));
7516 
7517 		padapter->ploopback = ploopback;
7518 	}
7519 
7520 	return 0;
7521 }
7522 
7523 static void freeLoopback(_adapter *padapter)
7524 {
7525 	PLOOPBACKDATA ploopback;
7526 
7527 
7528 	ploopback = padapter->ploopback;
7529 	if (ploopback) {
7530 		rtw_mfree((u8 *)ploopback, sizeof(LOOPBACKDATA));
7531 		padapter->ploopback = NULL;
7532 	}
7533 }
7534 
7535 static s32 initpseudoadhoc(_adapter *padapter)
7536 {
7537 	NDIS_802_11_NETWORK_INFRASTRUCTURE networkType;
7538 	s32 err;
7539 
7540 	networkType = Ndis802_11IBSS;
7541 	err = rtw_set_802_11_infrastructure_mode(padapter, networkType, 0);
7542 	if (err == _FALSE)
7543 		return _FAIL;
7544 
7545 	err = rtw_setopmode_cmd(padapter, networkType, RTW_CMDF_WAIT_ACK);
7546 	if (err == _FAIL)
7547 		return _FAIL;
7548 
7549 	return _SUCCESS;
7550 }
7551 
7552 static s32 createpseudoadhoc(_adapter *padapter)
7553 {
7554 	NDIS_802_11_AUTHENTICATION_MODE authmode;
7555 	struct mlme_priv *pmlmepriv;
7556 	NDIS_802_11_SSID *passoc_ssid;
7557 	WLAN_BSSID_EX *pdev_network;
7558 	u8 *pibss;
7559 	u8 ssid[] = "pseduo_ad-hoc";
7560 	s32 err;
7561 
7562 
7563 	pmlmepriv = &padapter->mlmepriv;
7564 
7565 	authmode = Ndis802_11AuthModeOpen;
7566 	err = rtw_set_802_11_authentication_mode(padapter, authmode);
7567 	if (err == _FALSE)
7568 		return _FAIL;
7569 
7570 	passoc_ssid = &pmlmepriv->assoc_ssid;
7571 	_rtw_memset(passoc_ssid, 0, sizeof(NDIS_802_11_SSID));
7572 	passoc_ssid->SsidLength = sizeof(ssid) - 1;
7573 	_rtw_memcpy(passoc_ssid->Ssid, ssid, passoc_ssid->SsidLength);
7574 
7575 	pdev_network = &padapter->registrypriv.dev_network;
7576 	pibss = padapter->registrypriv.dev_network.MacAddress;
7577 	_rtw_memcpy(&pdev_network->Ssid, passoc_ssid, sizeof(NDIS_802_11_SSID));
7578 
7579 	rtw_update_registrypriv_dev_network(padapter);
7580 	rtw_generate_random_ibss(pibss);
7581 
7582 	_rtw_spinlock_bh(&pmlmepriv->lock);
7583 	/*pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;*/
7584 	init_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE);
7585 
7586 	_rtw_spinunlock_bh(&pmlmepriv->lock);
7587 
7588 #if 0
7589 	err = rtw_create_ibss_cmd(padapter, 0);
7590 	if (err == _FAIL)
7591 		return _FAIL;
7592 #else
7593 	{
7594 		struct wlan_network *pcur_network;
7595 		struct sta_info *psta;
7596 
7597 		/* 3  create a new psta */
7598 		pcur_network = &pmlmepriv->cur_network;
7599 
7600 		/* clear psta in the cur_network, if any */
7601 		psta = rtw_get_stainfo(&padapter->stapriv, pcur_network->network.MacAddress);
7602 		if (psta)
7603 			rtw_free_stainfo(padapter, psta);
7604 
7605 		psta = rtw_alloc_stainfo(&padapter->stapriv, pibss);
7606 		if (psta == NULL)
7607 			return _FAIL;
7608 
7609 		/* 3  join psudo AdHoc */
7610 		pcur_network->join_res = 1;
7611 		pcur_network->aid = psta->phl_sta->aid = 1;
7612 		_rtw_memcpy(&pcur_network->network, pdev_network, get_WLAN_BSSID_EX_sz(pdev_network));
7613 
7614 	}
7615 #endif
7616 
7617 	return _SUCCESS;
7618 }
7619 /*GEORGIA_TODO_FIXIT_MOVE_TO_HAL*/
7620 static struct xmit_frame *createloopbackpkt(_adapter *padapter, u32 size)
7621 {
7622 	struct xmit_priv *pxmitpriv;
7623 	struct xmit_frame *pframe;
7624 	struct xmit_buf *pxmitbuf;
7625 	struct pkt_attrib *pattrib;
7626 	struct tx_desc *desc;
7627 	u8 *pkt_start, *pkt_end, *ptr;
7628 	struct rtw_ieee80211_hdr *hdr;
7629 	s32 bmcast;
7630 	struct dvobj_priv *dvobj = adapter_to_dvobj(padapter);
7631 	u16 xmitbuf_sz = GET_HAL_XMITBUF_SZ(dvobj);
7632 
7633 	if ((TXDESC_SIZE + WLANHDR_OFFSET + size) > xmitbuf_sz)
7634 		return NULL;
7635 
7636 	pxmitpriv = &padapter->xmitpriv;
7637 	pframe = NULL;
7638 
7639 	/* 2 1. allocate xmit frame */
7640 	pframe = rtw_alloc_xmitframe(pxmitpriv);
7641 	if (pframe == NULL)
7642 		return NULL;
7643 	pframe->padapter = padapter;
7644 
7645 	/* 2 2. allocate xmit buffer */
7646 	_rtw_spinlock_bh(&pxmitpriv->lock);
7647 	pxmitbuf = rtw_alloc_xmitbuf(pxmitpriv);
7648 	_rtw_spinunlock_bh(&pxmitpriv->lock);
7649 	if (pxmitbuf == NULL) {
7650 		rtw_free_xmitframe(pxmitpriv, pframe);
7651 		return NULL;
7652 	}
7653 
7654 	pframe->pxmitbuf = pxmitbuf;
7655 	pframe->buf_addr = pxmitbuf->pbuf;
7656 	pxmitbuf->priv_data = pframe;
7657 
7658 	/* 2 3. update_attrib() */
7659 	pattrib = &pframe->attrib;
7660 
7661 	/* init xmitframe attribute */
7662 	_rtw_memset(pattrib, 0, sizeof(struct pkt_attrib));
7663 
7664 	pattrib->ether_type = 0x8723;
7665 	_rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);
7666 	_rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);
7667 	_rtw_memset(pattrib->dst, 0xFF, ETH_ALEN);
7668 	_rtw_memcpy(pattrib->ra, pattrib->dst, ETH_ALEN);
7669 
7670 	/*	pattrib->dhcp_pkt = 0;
7671 	 *	pattrib->pktlen = 0; */
7672 	pattrib->ack_policy = 0;
7673 	/*	pattrib->pkt_hdrlen = ETH_HLEN; */
7674 	pattrib->hdrlen = WLAN_HDR_A3_LEN;
7675 	pattrib->subtype = WIFI_DATA;
7676 	pattrib->priority = 0;
7677 	pattrib->qsel = pattrib->priority;
7678 	/*	do_queue_select(padapter, pattrib); */
7679 	pattrib->nr_frags = 1;
7680 	pattrib->encrypt = 0;
7681 	pattrib->bswenc = _FALSE;
7682 	pattrib->qos_en = _FALSE;
7683 
7684 	bmcast = IS_MCAST(pattrib->ra);
7685 	if (bmcast)
7686 		pattrib->psta = rtw_get_bcmc_stainfo(padapter);
7687 	else
7688 		pattrib->psta = rtw_get_stainfo(&padapter->stapriv, get_bssid(&padapter->mlmepriv));
7689 
7690 	pattrib->mac_id = pattrib->psta->phl_sta->macid;
7691 	pattrib->pktlen = size;
7692 	pattrib->last_txcmdsz = pattrib->hdrlen + pattrib->pktlen;
7693 
7694 	/* 2 4. fill TX descriptor */
7695 	desc = (struct tx_desc *)pframe->buf_addr;
7696 	_rtw_memset(desc, 0, TXDESC_SIZE);
7697 
7698 	fill_default_txdesc(pframe, (u8 *)desc);
7699 
7700 	/* Hw set sequence number */
7701 	((PTXDESC)desc)->hwseq_en = 0; /* HWSEQ_EN, 0:disable, 1:enable
7702  * ((PTXDESC)desc)->hwseq_sel = 0;  */ /* HWSEQ_SEL */
7703 
7704 	((PTXDESC)desc)->disdatafb = 1;
7705 
7706 	/* convert to little endian */
7707 	desc->txdw0 = cpu_to_le32(desc->txdw0);
7708 	desc->txdw1 = cpu_to_le32(desc->txdw1);
7709 	desc->txdw2 = cpu_to_le32(desc->txdw2);
7710 	desc->txdw3 = cpu_to_le32(desc->txdw3);
7711 	desc->txdw4 = cpu_to_le32(desc->txdw4);
7712 	desc->txdw5 = cpu_to_le32(desc->txdw5);
7713 	desc->txdw6 = cpu_to_le32(desc->txdw6);
7714 	desc->txdw7 = cpu_to_le32(desc->txdw7);
7715 #ifdef CONFIG_PCI_HCI
7716 	desc->txdw8 = cpu_to_le32(desc->txdw8);
7717 	desc->txdw9 = cpu_to_le32(desc->txdw9);
7718 	desc->txdw10 = cpu_to_le32(desc->txdw10);
7719 	desc->txdw11 = cpu_to_le32(desc->txdw11);
7720 	desc->txdw12 = cpu_to_le32(desc->txdw12);
7721 	desc->txdw13 = cpu_to_le32(desc->txdw13);
7722 	desc->txdw14 = cpu_to_le32(desc->txdw14);
7723 	desc->txdw15 = cpu_to_le32(desc->txdw15);
7724 #endif
7725 
7726 	cal_txdesc_chksum(desc);
7727 
7728 	/* 2 5. coalesce */
7729 	pkt_start = pframe->buf_addr + TXDESC_SIZE;
7730 	pkt_end = pkt_start + pattrib->last_txcmdsz;
7731 
7732 	/* 3 5.1. make wlan header, make_wlanhdr() */
7733 	hdr = (struct rtw_ieee80211_hdr *)pkt_start;
7734 	set_frame_sub_type(&hdr->frame_ctl, pattrib->subtype);
7735 	_rtw_memcpy(hdr->addr1, pattrib->dst, ETH_ALEN); /* DA */
7736 	_rtw_memcpy(hdr->addr2, pattrib->src, ETH_ALEN); /* SA */
7737 	_rtw_memcpy(hdr->addr3, get_bssid(&padapter->mlmepriv), ETH_ALEN); /* RA, BSSID */
7738 
7739 	/* 3 5.2. make payload */
7740 	ptr = pkt_start + pattrib->hdrlen;
7741 	get_random_bytes(ptr, pkt_end - ptr);
7742 
7743 	pxmitbuf->len = TXDESC_SIZE + pattrib->last_txcmdsz;
7744 	pxmitbuf->ptail += pxmitbuf->len;
7745 
7746 	return pframe;
7747 }
7748 
7749 static void freeloopbackpkt(_adapter *padapter, struct xmit_frame *pframe)
7750 {
7751 	struct xmit_priv *pxmitpriv;
7752 	struct xmit_buf *pxmitbuf;
7753 
7754 
7755 	pxmitpriv = &padapter->xmitpriv;
7756 	pxmitbuf = pframe->pxmitbuf;
7757 
7758 	rtw_free_xmitframe(pxmitpriv, pframe);
7759 	rtw_free_xmitbuf(pxmitpriv, pxmitbuf);
7760 }
7761 
7762 static void printdata(u8 *pbuf, u32 len)
7763 {
7764 	u32 i, val;
7765 
7766 
7767 	for (i = 0; (i + 4) <= len; i += 4) {
7768 		printk("%08X", *(u32 *)(pbuf + i));
7769 		if ((i + 4) & 0x1F)
7770 			printk(" ");
7771 		else
7772 			printk("\n");
7773 	}
7774 
7775 	if (i < len) {
7776 #ifdef CONFIG_BIG_ENDIAN
7777 		for (; i < len, i++)
7778 			printk("%02X", pbuf + i);
7779 #else /* CONFIG_LITTLE_ENDIAN */
7780 #if 0
7781 		val = 0;
7782 		_rtw_memcpy(&val, pbuf + i, len - i);
7783 		printk("%8X", val);
7784 #else
7785 		u8 str[9];
7786 		u8 n;
7787 		val = 0;
7788 		n = len - i;
7789 		_rtw_memcpy(&val, pbuf + i, n);
7790 		sprintf(str, "%08X", val);
7791 		n = (4 - n) * 2;
7792 		printk("%8s", str + n);
7793 #endif
7794 #endif /* CONFIG_LITTLE_ENDIAN */
7795 	}
7796 	printk("\n");
7797 }
7798 
7799 static u8 pktcmp(_adapter *padapter, u8 *txbuf, u32 txsz, u8 *rxbuf, u32 rxsz)
7800 {
7801 	struct recv_stat *prxstat;
7802 	struct recv_stat report;
7803 	PRXREPORT prxreport;
7804 	u32 drvinfosize;
7805 	u32 rxpktsize;
7806 	u8 fcssize;
7807 	u8 ret = _FALSE;
7808 
7809 	prxstat = (struct recv_stat *)rxbuf;
7810 	report.rxdw0 = le32_to_cpu(prxstat->rxdw0);
7811 	report.rxdw1 = le32_to_cpu(prxstat->rxdw1);
7812 	report.rxdw2 = le32_to_cpu(prxstat->rxdw2);
7813 	report.rxdw3 = le32_to_cpu(prxstat->rxdw3);
7814 	report.rxdw4 = le32_to_cpu(prxstat->rxdw4);
7815 	report.rxdw5 = le32_to_cpu(prxstat->rxdw5);
7816 
7817 	prxreport = (PRXREPORT)&report;
7818 	drvinfosize = prxreport->drvinfosize << 3;
7819 	rxpktsize = prxreport->pktlen;
7820 
7821 	if (rtw_hal_rcr_check(padapter, RCR_APPFCS))
7822 		fcssize = IEEE80211_FCS_LEN;
7823 	else
7824 		fcssize = 0;
7825 
7826 	if ((txsz - TXDESC_SIZE) != (rxpktsize - fcssize)) {
7827 		RTW_INFO("%s: ERROR! size not match tx/rx=%d/%d !\n",
7828 			 __func__, txsz - TXDESC_SIZE, rxpktsize - fcssize);
7829 		ret = _FALSE;
7830 	} else {
7831 		ret = _rtw_memcmp(txbuf + TXDESC_SIZE, \
7832 				  rxbuf + RXDESC_SIZE + drvinfosize, \
7833 				  txsz - TXDESC_SIZE);
7834 		if (ret == _FALSE)
7835 			RTW_INFO("%s: ERROR! pkt content mismatch!\n", __func__);
7836 	}
7837 
7838 	if (ret == _FALSE) {
7839 		RTW_INFO("\n%s: TX PKT total=%d, desc=%d, content=%d\n",
7840 			 __func__, txsz, TXDESC_SIZE, txsz - TXDESC_SIZE);
7841 		RTW_INFO("%s: TX DESC size=%d\n", __func__, TXDESC_SIZE);
7842 		printdata(txbuf, TXDESC_SIZE);
7843 		RTW_INFO("%s: TX content size=%d\n", __func__, txsz - TXDESC_SIZE);
7844 		printdata(txbuf + TXDESC_SIZE, txsz - TXDESC_SIZE);
7845 
7846 		RTW_INFO("\n%s: RX PKT read=%d offset=%d(%d,%d) content=%d\n",
7847 			__func__, rxsz, RXDESC_SIZE + drvinfosize, RXDESC_SIZE, drvinfosize, rxpktsize);
7848 		if (rxpktsize != 0) {
7849 			RTW_INFO("%s: RX DESC size=%d\n", __func__, RXDESC_SIZE);
7850 			printdata(rxbuf, RXDESC_SIZE);
7851 			RTW_INFO("%s: RX drvinfo size=%d\n", __func__, drvinfosize);
7852 			printdata(rxbuf + RXDESC_SIZE, drvinfosize);
7853 			RTW_INFO("%s: RX content size=%d\n", __func__, rxpktsize);
7854 			printdata(rxbuf + RXDESC_SIZE + drvinfosize, rxpktsize);
7855 		} else {
7856 			RTW_INFO("%s: RX data size=%d\n", __func__, rxsz);
7857 			printdata(rxbuf, rxsz);
7858 		}
7859 	}
7860 
7861 	return ret;
7862 }
7863 
7864 thread_return lbk_thread(thread_context context)
7865 {
7866 #if 0
7867 	s32 err;
7868 	_adapter *padapter;
7869 	PLOOPBACKDATA ploopback;
7870 	struct xmit_frame *pxmitframe;
7871 	u32 cnt, ok, fail, headerlen;
7872 	u32 pktsize;
7873 	u32 ff_hwaddr;
7874 
7875 
7876 	padapter = (_adapter *)context;
7877 	ploopback = padapter->ploopback;
7878 	if (ploopback == NULL)
7879 		return -1;
7880 	cnt = 0;
7881 	ok = 0;
7882 	fail = 0;
7883 
7884 	daemonize("%s", "RTW_LBK_THREAD");
7885 	allow_signal(SIGTERM);
7886 
7887 	do {
7888 		if (ploopback->size == 0) {
7889 			get_random_bytes(&pktsize, 4);
7890 			pktsize = (pktsize % 1535) + 1; /* 1~1535 */
7891 		} else
7892 			pktsize = ploopback->size;
7893 
7894 		pxmitframe = createloopbackpkt(padapter, pktsize);
7895 		if (pxmitframe == NULL) {
7896 			sprintf(ploopback->msg, "loopback FAIL! 3. create Packet FAIL!");
7897 			break;
7898 		}
7899 
7900 		ploopback->txsize = TXDESC_SIZE + pxmitframe->attrib.last_txcmdsz;
7901 		_rtw_memcpy(ploopback->txbuf, pxmitframe->buf_addr, ploopback->txsize);
7902 		ff_hwaddr = rtw_get_ff_hwaddr(pxmitframe);
7903 		cnt++;
7904 		RTW_INFO("%s: wirte port cnt=%d size=%d\n", __func__, cnt, ploopback->txsize);
7905 		pxmitframe->pxmitbuf->pdata = ploopback->txbuf;
7906 		rtw_write_port(padapter, ff_hwaddr, ploopback->txsize, (u8 *)pxmitframe->pxmitbuf);
7907 
7908 		/* wait for rx pkt */
7909 		_rtw_down_sema(&ploopback->sema);
7910 
7911 		err = pktcmp(padapter, ploopback->txbuf, ploopback->txsize, ploopback->rxbuf, ploopback->rxsize);
7912 		if (err == _TRUE)
7913 			ok++;
7914 		else
7915 			fail++;
7916 
7917 		ploopback->txsize = 0;
7918 		_rtw_memset(ploopback->txbuf, 0, 0x8000);
7919 		ploopback->rxsize = 0;
7920 		_rtw_memset(ploopback->rxbuf, 0, 0x8000);
7921 
7922 		freeloopbackpkt(padapter, pxmitframe);
7923 		pxmitframe = NULL;
7924 
7925 		flush_signals_thread();
7926 
7927 		if ((ploopback->bstop == _TRUE) ||
7928 		    ((ploopback->cnt != 0) && (ploopback->cnt == cnt))) {
7929 			u32 ok_rate, fail_rate, all;
7930 			all = cnt;
7931 			ok_rate = (ok * 100) / all;
7932 			fail_rate = (fail * 100) / all;
7933 			sprintf(ploopback->msg, \
7934 				"loopback result: ok=%d%%(%d/%d),error=%d%%(%d/%d)", \
7935 				ok_rate, ok, all, fail_rate, fail, all);
7936 			break;
7937 		}
7938 	} while (1);
7939 
7940 	ploopback->bstop = _TRUE;
7941 
7942 	thread_exit(NULL);
7943 #endif
7944 	return 0;
7945 }
7946 
7947 static void loopbackTest(_adapter *padapter, u32 cnt, u32 size, u8 *pmsg)
7948 {
7949 	PLOOPBACKDATA ploopback;
7950 	u32 len;
7951 	s32 err;
7952 
7953 
7954 	ploopback = padapter->ploopback;
7955 
7956 	if (ploopback) {
7957 		if (ploopback->bstop == _FALSE) {
7958 			ploopback->bstop = _TRUE;
7959 			_rtw_up_sema(&ploopback->sema);
7960 		}
7961 		len = 0;
7962 		do {
7963 			len = strlen(ploopback->msg);
7964 			if (len)
7965 				break;
7966 			rtw_msleep_os(1);
7967 		} while (1);
7968 		_rtw_memcpy(pmsg, ploopback->msg, len + 1);
7969 		freeLoopback(padapter);
7970 
7971 		return;
7972 	}
7973 
7974 	/* disable dynamic algorithm	 */
7975 	rtw_phydm_ability_backup(padapter);
7976 	rtw_phydm_func_disable_all(padapter);
7977 
7978 	/* create pseudo ad-hoc connection */
7979 	err = initpseudoadhoc(padapter);
7980 	if (err == _FAIL) {
7981 		sprintf(pmsg, "loopback FAIL! 1.1 init ad-hoc FAIL!");
7982 		return;
7983 	}
7984 
7985 	err = createpseudoadhoc(padapter);
7986 	if (err == _FAIL) {
7987 		sprintf(pmsg, "loopback FAIL! 1.2 create ad-hoc master FAIL!");
7988 		return;
7989 	}
7990 
7991 	err = initLoopback(padapter);
7992 	if (err) {
7993 		sprintf(pmsg, "loopback FAIL! 2. init FAIL! error code=%d", err);
7994 		return;
7995 	}
7996 
7997 	ploopback = padapter->ploopback;
7998 
7999 	ploopback->bstop = _FALSE;
8000 	ploopback->cnt = cnt;
8001 	ploopback->size = size;
8002 	ploopback->lbkthread = rtw_thread_start(lbk_thread, padapter, "RTW_LBK_THREAD");
8003 	if (ploopback->lbkthread == NULL)) {
8004 		freeLoopback(padapter);
8005 		sprintf(pmsg, "loopback start FAIL! cnt=%d", cnt);
8006 		return;
8007 	}
8008 
8009 	sprintf(pmsg, "loopback start! cnt=%d", cnt);
8010 }
8011 #endif /* CONFIG_MAC_LOOPBACK_DRIVER */
8012 
8013 static int rtw_test(
8014 	struct net_device *dev,
8015 	struct iw_request_info *info,
8016 	union iwreq_data *wrqu, char *extra)
8017 {
8018 	u32 len;
8019 	u8 *pbuf, *pch;
8020 	char *ptmp;
8021 	u8 *delim = ",";
8022 	_adapter *padapter = rtw_netdev_priv(dev);
8023 
8024 
8025 	RTW_INFO("+%s\n", __func__);
8026 	len = wrqu->data.length;
8027 
8028 	pbuf = (u8 *)rtw_zmalloc(len + 1);
8029 	if (pbuf == NULL) {
8030 		RTW_INFO("%s: no memory!\n", __func__);
8031 		return -ENOMEM;
8032 	}
8033 
8034 	if (copy_from_user(pbuf, wrqu->data.pointer, len)) {
8035 		rtw_mfree(pbuf, len + 1);
8036 		RTW_INFO("%s: copy from user fail!\n", __func__);
8037 		return -EFAULT;
8038 	}
8039 
8040 	pbuf[len] = '\0';
8041 
8042 	RTW_INFO("%s: string=\"%s\"\n", __func__, pbuf);
8043 
8044 	ptmp = (char *)pbuf;
8045 	pch = strsep(&ptmp, delim);
8046 	if ((pch == NULL) || (strlen(pch) == 0)) {
8047 		rtw_mfree(pbuf, len);
8048 		RTW_INFO("%s: parameter error(level 1)!\n", __func__);
8049 		return -EFAULT;
8050 	}
8051 
8052 #if 0 /*#ifdef CONFIG_MAC_LOOPBACK_DRIVER*/
8053 	if (strcmp(pch, "loopback") == 0) {
8054 		s32 cnt = 0;
8055 		u32 size = 64;
8056 
8057 		pch = strsep(&ptmp, delim);
8058 		if ((pch == NULL) || (strlen(pch) == 0)) {
8059 			rtw_mfree(pbuf, len);
8060 			RTW_INFO("%s: parameter error(level 2)!\n", __func__);
8061 			return -EFAULT;
8062 		}
8063 
8064 		sscanf(pch, "%d", &cnt);
8065 		RTW_INFO("%s: loopback cnt=%d\n", __func__, cnt);
8066 
8067 		pch = strsep(&ptmp, delim);
8068 		if ((pch == NULL) || (strlen(pch) == 0)) {
8069 			rtw_mfree(pbuf, len);
8070 			RTW_INFO("%s: parameter error(level 2)!\n", __func__);
8071 			return -EFAULT;
8072 		}
8073 
8074 		sscanf(pch, "%d", &size);
8075 		RTW_INFO("%s: loopback size=%d\n", __func__, size);
8076 
8077 		loopbackTest(padapter, cnt, size, extra);
8078 		wrqu->data.length = strlen(extra) + 1;
8079 
8080 		goto free_buf;
8081 	}
8082 #endif
8083 
8084 	if (strcmp(pch, "h2c") == 0) {
8085 		u8 param[8];
8086 		u8 count = 0;
8087 		u32 tmp;
8088 		u8 i;
8089 		u32 pos;
8090 		u8 ret;
8091 
8092 		do {
8093 			pch = strsep(&ptmp, delim);
8094 			if ((pch == NULL) || (strlen(pch) == 0))
8095 				break;
8096 
8097 			sscanf(pch, "%x", &tmp);
8098 			param[count++] = (u8)tmp;
8099 		} while (count < 8);
8100 
8101 		if (count == 0) {
8102 			rtw_mfree(pbuf, len);
8103 			RTW_INFO("%s: parameter error(level 2)!\n", __func__);
8104 			return -EFAULT;
8105 		}
8106 
8107 		ret = rtw_test_h2c_cmd(padapter, param, count);
8108 
8109 		pos = sprintf(extra, "H2C ID=0x%02x content=", param[0]);
8110 		for (i = 1; i < count; i++)
8111 			pos += sprintf(extra + pos, "%02x,", param[i]);
8112 		extra[pos] = 0;
8113 		pos--;
8114 		pos += sprintf(extra + pos, " %s", ret == _FAIL ? "FAIL" : "OK");
8115 
8116 		wrqu->data.length = strlen(extra) + 1;
8117 
8118 		goto free_buf;
8119 	}
8120 
8121 free_buf:
8122 	rtw_mfree(pbuf, len);
8123 	return 0;
8124 }
8125 
8126 static iw_handler rtw_handlers[] = {
8127 	NULL,					/* SIOCSIWCOMMIT */
8128 	rtw_wx_get_name,		/* SIOCGIWNAME */
8129 	dummy,					/* SIOCSIWNWID */
8130 	dummy,					/* SIOCGIWNWID */
8131 	rtw_wx_set_freq,		/* SIOCSIWFREQ */
8132 	rtw_wx_get_freq,		/* SIOCGIWFREQ */
8133 	rtw_wx_set_mode,		/* SIOCSIWMODE */
8134 	rtw_wx_get_mode,		/* SIOCGIWMODE */
8135 	dummy,					/* SIOCSIWSENS */
8136 	rtw_wx_get_sens,		/* SIOCGIWSENS */
8137 	NULL,					/* SIOCSIWRANGE */
8138 	rtw_wx_get_range,		/* SIOCGIWRANGE */
8139 	rtw_wx_set_priv,		/* SIOCSIWPRIV */
8140 	NULL,					/* SIOCGIWPRIV */
8141 	NULL,					/* SIOCSIWSTATS */
8142 	NULL,					/* SIOCGIWSTATS */
8143 	dummy,					/* SIOCSIWSPY */
8144 	dummy,					/* SIOCGIWSPY */
8145 	NULL,					/* SIOCGIWTHRSPY */
8146 	NULL,					/* SIOCWIWTHRSPY */
8147 	rtw_wx_set_wap,		/* SIOCSIWAP */
8148 	rtw_wx_get_wap,		/* SIOCGIWAP */
8149 	rtw_wx_set_mlme,		/* request MLME operation; uses struct iw_mlme */
8150 	dummy,					/* SIOCGIWAPLIST -- depricated */
8151 	rtw_wx_set_scan,		/* SIOCSIWSCAN */
8152 	rtw_wx_get_scan,		/* SIOCGIWSCAN */
8153 	rtw_wx_set_essid,		/* SIOCSIWESSID */
8154 	rtw_wx_get_essid,		/* SIOCGIWESSID */
8155 	dummy,					/* SIOCSIWNICKN */
8156 	rtw_wx_get_nick,		/* SIOCGIWNICKN */
8157 	NULL,					/* -- hole -- */
8158 	NULL,					/* -- hole -- */
8159 	rtw_wx_set_rate,		/* SIOCSIWRATE */
8160 	rtw_wx_get_rate,		/* SIOCGIWRATE */
8161 	rtw_wx_set_rts,			/* SIOCSIWRTS */
8162 	rtw_wx_get_rts,			/* SIOCGIWRTS */
8163 	rtw_wx_set_frag,		/* SIOCSIWFRAG */
8164 	rtw_wx_get_frag,		/* SIOCGIWFRAG */
8165 	dummy,					/* SIOCSIWTXPOW */
8166 	dummy,					/* SIOCGIWTXPOW */
8167 	dummy,					/* SIOCSIWRETRY */
8168 	rtw_wx_get_retry,		/* SIOCGIWRETRY */
8169 	rtw_wx_set_enc,			/* SIOCSIWENCODE */
8170 	rtw_wx_get_enc,			/* SIOCGIWENCODE */
8171 	dummy,					/* SIOCSIWPOWER */
8172 	rtw_wx_get_power,		/* SIOCGIWPOWER */
8173 	NULL,					/*---hole---*/
8174 	NULL,					/*---hole---*/
8175 	rtw_wx_set_gen_ie,		/* SIOCSIWGENIE */
8176 	NULL,					/* SIOCGWGENIE */
8177 	rtw_wx_set_auth,		/* SIOCSIWAUTH */
8178 	NULL,					/* SIOCGIWAUTH */
8179 	rtw_wx_set_enc_ext,		/* SIOCSIWENCODEEXT */
8180 	NULL,					/* SIOCGIWENCODEEXT */
8181 	rtw_wx_set_pmkid,		/* SIOCSIWPMKSA */
8182 	NULL,					/*---hole---*/
8183 };
8184 
8185 
8186 static const struct iw_priv_args rtw_private_args[] = {
8187 	{
8188 		SIOCIWFIRSTPRIV + 0x0,
8189 		IW_PRIV_TYPE_CHAR | 0x7FF, 0, "write"
8190 	},
8191 	{
8192 		SIOCIWFIRSTPRIV + 0x1,
8193 		IW_PRIV_TYPE_CHAR | 0x7FF,
8194 		IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_FIXED | IFNAMSIZ, "read"
8195 	},
8196 	{
8197 		SIOCIWFIRSTPRIV + 0x2, 0, 0, "driver_ext"
8198 	},
8199 	{
8200 		SIOCIWFIRSTPRIV + 0x3, 0, 0, "mp_ioctl"
8201 	},
8202 	{
8203 		SIOCIWFIRSTPRIV + 0x4,
8204 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "apinfo"
8205 	},
8206 	{
8207 		SIOCIWFIRSTPRIV + 0x5,
8208 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, 0, "setpid"
8209 	},
8210 	{
8211 		SIOCIWFIRSTPRIV + 0x6,
8212 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_start"
8213 	},
8214 	/* for PLATFORM_MT53XX	 */
8215 	{
8216 		SIOCIWFIRSTPRIV + 0x7,
8217 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "get_sensitivity"
8218 	},
8219 	{
8220 		SIOCIWFIRSTPRIV + 0x8,
8221 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_prob_req_ie"
8222 	},
8223 	{
8224 		SIOCIWFIRSTPRIV + 0x9,
8225 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_assoc_req_ie"
8226 	},
8227 
8228 	/* for RTK_DMP_PLATFORM	 */
8229 	{
8230 		SIOCIWFIRSTPRIV + 0xA,
8231 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "channel_plan"
8232 	},
8233 
8234 	{
8235 		SIOCIWFIRSTPRIV + 0xB,
8236 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, 0, "dbg"
8237 	},
8238 	{
8239 		SIOCIWFIRSTPRIV + 0xC,
8240 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 3, 0, "rfw"
8241 	},
8242 	{
8243 		SIOCIWFIRSTPRIV + 0xD,
8244 		IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_FIXED | IFNAMSIZ, "rfr"
8245 	},
8246 #if 0
8247 	{
8248 		SIOCIWFIRSTPRIV + 0xE, 0, 0, "wowlan_ctrl"
8249 	},
8250 #endif
8251 	{
8252 		SIOCIWFIRSTPRIV + 0x10,
8253 		IW_PRIV_TYPE_CHAR | 1024, 0, "p2p_set"
8254 	},
8255 	{
8256 		SIOCIWFIRSTPRIV + 0x11,
8257 		IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , "p2p_get"
8258 	},
8259 	{
8260 		SIOCIWFIRSTPRIV + 0x12, 0, 0, "NULL"
8261 	},
8262 	{
8263 		SIOCIWFIRSTPRIV + 0x13,
8264 		IW_PRIV_TYPE_CHAR | 64, IW_PRIV_TYPE_CHAR | 64 , "p2p_get2"
8265 	},
8266 	{
8267 		SIOCIWFIRSTPRIV + 0x14,
8268 		IW_PRIV_TYPE_CHAR  | 64, 0, "tdls"
8269 	},
8270 	{
8271 		SIOCIWFIRSTPRIV + 0x15,
8272 		IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | 1024 , "tdls_get"
8273 	},
8274 	{
8275 		SIOCIWFIRSTPRIV + 0x16,
8276 		IW_PRIV_TYPE_CHAR | 64, 0, "pm_set"
8277 	},
8278 #ifdef CONFIG_RTW_80211K
8279 	{
8280 		SIOCIWFIRSTPRIV + 0x17,
8281 		IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | 1024 , "rrm"
8282 	},
8283 #else
8284 	{SIOCIWFIRSTPRIV + 0x17, IW_PRIV_TYPE_CHAR | 1024 , 0 , "NULL"},
8285 #endif
8286 	{SIOCIWFIRSTPRIV + 0x18, IW_PRIV_TYPE_CHAR | IFNAMSIZ , 0 , "rereg_nd_name"},
8287 #ifdef CONFIG_MP_INCLUDED
8288 	{SIOCIWFIRSTPRIV + 0x1A, IW_PRIV_TYPE_CHAR | 1024, 0,  "NULL"},
8289 	{SIOCIWFIRSTPRIV + 0x1B, IW_PRIV_TYPE_CHAR | 128, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "NULL"},
8290 #else
8291 	{SIOCIWFIRSTPRIV + 0x1A, IW_PRIV_TYPE_CHAR | 1024, 0,  "NULL"},
8292 	{SIOCIWFIRSTPRIV + 0x1B, IW_PRIV_TYPE_CHAR | 128, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_get"},
8293 #endif
8294 	{
8295 		SIOCIWFIRSTPRIV + 0x1D,
8296 		IW_PRIV_TYPE_CHAR | 40, IW_PRIV_TYPE_CHAR | 0x7FF, "test"
8297 	},
8298 
8299 	{ SIOCIWFIRSTPRIV + 0x0E, IW_PRIV_TYPE_CHAR | 1024, 0 , ""},  /* set  */
8300 	{ SIOCIWFIRSTPRIV + 0x0F, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , ""},/* get
8301  * --- sub-ioctls definitions --- */
8302 
8303 #ifdef CONFIG_APPEND_VENDOR_IE_ENABLE
8304 	{ VENDOR_IE_SET, IW_PRIV_TYPE_CHAR | 1024 , 0 , "vendor_ie_set" },
8305 	{ VENDOR_IE_GET, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "vendor_ie_get" },
8306 #endif
8307 #if defined(RTW_PHL_TX) || defined(RTW_PHL_RX) || defined(CONFIG_PHL_TEST_SUITE)
8308 	{ PHL_TEST_SET, IW_PRIV_TYPE_CHAR | 1024 , 0 , "phl_test" },
8309 	{ PHL_TEST_GET, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "" },
8310 #endif
8311 #ifdef CONFIG_WOWLAN
8312 	{ MP_WOW_ENABLE , IW_PRIV_TYPE_CHAR | 1024, 0, "wow_mode" },
8313 	{ MP_WOW_SET_PATTERN , IW_PRIV_TYPE_CHAR | 1024, 0, "wow_set_pattern" },
8314 #endif
8315 #ifdef CONFIG_AP_WOWLAN
8316 	{ MP_AP_WOW_ENABLE , IW_PRIV_TYPE_CHAR | 1024, 0, "ap_wow_mode" }, /* set  */
8317 #endif
8318 #ifdef CONFIG_SDIO_INDIRECT_ACCESS
8319 	{ MP_SD_IREAD, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "sd_iread" },
8320 	{ MP_SD_IWRITE, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "sd_iwrite" },
8321 #endif
8322 #ifdef CONFIG_MP_INCLUDED
8323 	{ MP_GET_PHL_TEST, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "phl_get_io" },
8324 	{ MP_SET_PHL_TEST, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "phl_set_io" },
8325 #endif
8326 };
8327 
8328 /* --- sub-ioctls definitions --- */
8329 static const struct iw_priv_args rtw_mp_private_args[] = {
8330 #ifdef CONFIG_MP_INCLUDED
8331 	{ MP_START , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8332 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_start" },
8333 	{ MP_PHYPARA, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8334 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_phypara" },
8335 	{ MP_STOP , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8336 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_stop" },
8337 	{ MP_CHANNEL , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK ,
8338 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_channel" },
8339 	{ MP_TRXSC_OFFSET , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK ,
8340 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_trxsc" },
8341 	{ MP_BANDWIDTH , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8342 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_bandwidth"},
8343 	{ MP_RATE , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8344 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rate" },
8345 	{ MP_RESET_STATS , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8346 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_reset_stats"},
8347 	{ MP_QUERY , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8348 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , "mp_query"},
8349 	{ READ_REG , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8350 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "read_reg" },
8351 	{ MP_RATE , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8352 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rate" },
8353 	{ READ_RF , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8354 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "read_rf" },
8355 	{ MP_PSD , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8356 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_psd"},
8357 	{ MP_DUMP, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8358 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_dump" },
8359 	{ MP_TXPOWER , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8360 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_txpower"},
8361 	{ MP_ANT_TX , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8362 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ant_tx"},
8363 	{ MP_ANT_RX , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8364 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ant_rx"},
8365 	{ WRITE_REG , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8366 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "write_reg" },
8367 	{ WRITE_RF , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8368 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "write_rf" },
8369 	{ MP_CTX , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8370 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ctx"},
8371 	{ MP_ARX , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8372 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_arx"},
8373 	{ MP_THER , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8374 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ther"},
8375 	{ EFUSE_SET, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8376 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_set" },
8377 	{ EFUSE_GET, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8378 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_get" },
8379 	{ MP_PWRTRK , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8380 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_pwrtrk"},
8381 	{ MP_QueryDrvStats, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8382 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_drvquery" },
8383 	{ MP_SetRFPathSwh, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8384 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_setrfpath" },
8385 	{ MP_PwrCtlDM, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8386 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_pwrctldm" },
8387 	{ MP_GET_TXPOWER_INX, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8388 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_get_txpower" },
8389 	{ MP_GETVER, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8390 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_priv_ver" },
8391 	{ MP_MON, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8392 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_mon" },
8393 	{ EFUSE_BT_MASK, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8394 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_bt_mask" },
8395 	{ EFUSE_MASK, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8396 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_mask" },
8397 	{ EFUSE_FILE, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8398 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_file" },
8399 	{ EFUSE_FILE_STORE, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8400 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_store" },
8401 	{ MP_TX, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8402 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_tx" },
8403 	{ MP_RX, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8404 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rx" },
8405 	{ MP_HW_TX_MODE, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8406 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_hxtx" },
8407 	{ MP_PWRLMT, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8408 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_pwrlmt" },
8409 	{ MP_PWRBYRATE, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8410 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_pwrbyrate" },
8411 	{ CTA_TEST, IW_PRIV_TYPE_CHAR | 1024, 0, "cta_test"},
8412 	{ MP_IQK, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_iqk"},
8413 	{ MP_LCK, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_lck"},
8414 	{ BT_EFUSE_FILE, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8415 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "bt_efuse_file" },
8416 	{ MP_SWRFPath, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8417 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_swrfpath" },
8418 	{ MP_LINK, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8419 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_link" },
8420 	{ MP_DPK, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8421 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_dpk"},
8422 	{ MP_DPK_TRK, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8423 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_dpk_trk" },
8424 	{ MP_GET_TSSIDE, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8425 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_get_tsside" },
8426 	{ MP_SET_TSSIDE, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8427 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_set_tsside" },
8428 	{ MP_GET_PHL_TEST, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8429 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "phl_get_io" },
8430 	{ MP_SET_PHL_TEST, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8431 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "phl_set_io" },
8432 	{ MP_SET_PHL_TX_PATTERN, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8433 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_tx_patt" },
8434 	{ MP_SET_PHL_TX_METHOD, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8435 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "tx_method" },
8436 	{ MP_SET_PHL_CONIFG_PHY_NUM, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8437 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_phy" },
8438 	{ MP_SET_PHL_PLCP_TX_DATA, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8439 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_plcp_data" },
8440 	{ MP_SET_PHL_PLCP_TX_USER, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8441 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_plcp_user" },
8442 	{ MP_PHL_RFK, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8443 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rfk" },
8444 	{ MP_PHL_BTC_PATH, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8445 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_btc_path" },
8446 	{ MP_GET_HE, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8447 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_get_he" },
8448 #ifdef CONFIG_RTW_CUSTOMER_STR
8449 	{ MP_CUSTOMER_STR, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK,
8450 				IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "customer_str" },
8451 #endif
8452 
8453 #endif /* CONFIG_MP_INCLUDED */
8454 };
8455 
8456 static iw_handler rtw_private_handler[] = {
8457 	rtw_wx_write32,					/* 0x00 */
8458 	rtw_wx_read32,					/* 0x01 */
8459 	NULL,					/* 0x02 */
8460 #ifdef MP_IOCTL_HDL
8461 	rtw_mp_ioctl_hdl,				/* 0x03 */
8462 #else
8463 	rtw_wx_priv_null,
8464 #endif
8465 	/* for MM DTV platform */
8466 	rtw_get_ap_info,					/* 0x04 */
8467 
8468 	rtw_set_pid,						/* 0x05 */
8469 	rtw_wps_start,					/* 0x06 */
8470 
8471 	/* for PLATFORM_MT53XX */
8472 	rtw_wx_get_sensitivity,			/* 0x07 */
8473 	rtw_wx_set_mtk_wps_probe_ie,	/* 0x08 */
8474 	rtw_wx_set_mtk_wps_ie,			/* 0x09 */
8475 
8476 	/* for RTK_DMP_PLATFORM
8477 	 * Set Channel depend on the country code */
8478 	rtw_wx_set_channel_plan,		/* 0x0A */
8479 
8480 	rtw_dbg_port,					/* 0x0B */
8481 	rtw_wx_write_rf,					/* 0x0C */
8482 	rtw_wx_read_rf,					/* 0x0D */
8483 
8484 	rtw_priv_set,					/*0x0E*/
8485 	rtw_priv_get,					/*0x0F*/
8486 
8487 	NULL, 						/* 0x10 */
8488 	NULL,						/* 0x11 */
8489 	NULL,						/* 0x12 */
8490 	NULL,						/* 0x13 */
8491 
8492 	rtw_tdls,						/* 0x14 */
8493 	rtw_tdls_get,					/* 0x15 */
8494 
8495 	rtw_pm_set,						/* 0x16 */
8496 #ifdef CONFIG_RTW_80211K
8497 	rtw_wx_priv_rrm,				/* 0x17 */
8498 #else
8499 	rtw_wx_priv_null,				/* 0x17 */
8500 #endif
8501 	rtw_rereg_nd_name,				/* 0x18 */
8502 	rtw_wx_priv_null,				/* 0x19 */
8503 #ifdef CONFIG_MP_INCLUDED
8504 	rtw_wx_priv_null,				/* 0x1A */
8505 	rtw_wx_priv_null,				/* 0x1B */
8506 #else
8507 	rtw_wx_priv_null,				/* 0x1A */
8508 	/*rtw_mp_efuse_get,*/				/* 0x1B */
8509 #endif
8510 	NULL,							/* 0x1C is reserved for hostapd */
8511 	rtw_test,						/* 0x1D */
8512 };
8513 
8514 #if WIRELESS_EXT >= 17
8515 static struct iw_statistics *rtw_get_wireless_stats(struct net_device *dev)
8516 {
8517 	_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8518 	struct iw_statistics *piwstats = &padapter->iwstats;
8519 	int tmp_level = 0;
8520 	int tmp_qual = 0;
8521 	int tmp_noise = 0;
8522 
8523 	if (check_fwstate(&padapter->mlmepriv, WIFI_ASOC_STATE) != _TRUE) {
8524 		piwstats->qual.qual = 0;
8525 		piwstats->qual.level = 0;
8526 		piwstats->qual.noise = 0;
8527 		/* RTW_INFO("No link  level:%d, qual:%d, noise:%d\n", tmp_level, tmp_qual, tmp_noise); */
8528 	} else {
8529 #ifdef CONFIG_SIGNAL_DISPLAY_DBM
8530 		tmp_level = rtw_phl_rssi_to_dbm(padapter->recvinfo.signal_strength);
8531 #else
8532 		tmp_level = padapter->recvinfo.signal_strength;
8533 #endif
8534 
8535 		tmp_qual = padapter->recvinfo.signal_qual;
8536 		/* RTW_INFO("level:%d, qual:%d, noise:%d, rssi (%d)\n", tmp_level, tmp_qual, tmp_noise,padapter->recvinfo.rssi); */
8537 
8538 		piwstats->qual.level = tmp_level;
8539 		piwstats->qual.qual = tmp_qual;
8540 		piwstats->qual.noise = tmp_noise;
8541 	}
8542 #if (LINUX_VERSION_CODE >= KERNEL_VERSION(2, 6, 14))
8543 	piwstats->qual.updated = IW_QUAL_ALL_UPDATED ;/* |IW_QUAL_DBM; */
8544 #else
8545 #ifdef RTK_DMP_PLATFORM
8546 	/* IW_QUAL_DBM= 0x8, if driver use this flag, wireless extension will show value of dbm. */
8547 	/* remove this flag for show percentage 0~100 */
8548 	piwstats->qual.updated = 0x07;
8549 #else
8550 	piwstats->qual.updated = 0x0f;
8551 #endif
8552 #endif
8553 
8554 #ifdef CONFIG_SIGNAL_DISPLAY_DBM
8555 	piwstats->qual.updated = piwstats->qual.updated | IW_QUAL_DBM;
8556 #endif
8557 
8558 	return &padapter->iwstats;
8559 }
8560 #endif
8561 
8562 #ifdef CONFIG_WIRELESS_EXT
8563 struct iw_handler_def rtw_handlers_def = {
8564 	.standard = rtw_handlers,
8565 	.num_standard = sizeof(rtw_handlers) / sizeof(iw_handler),
8566 #if (LINUX_VERSION_CODE < KERNEL_VERSION(2, 6, 33)) || defined(CONFIG_WEXT_PRIV)
8567 	.private = rtw_private_handler,
8568 	.private_args = (struct iw_priv_args *)rtw_private_args,
8569 	.num_private = sizeof(rtw_private_handler) / sizeof(iw_handler),
8570 	.num_private_args = sizeof(rtw_private_args) / sizeof(struct iw_priv_args),
8571 #endif
8572 #if WIRELESS_EXT >= 17
8573 	.get_wireless_stats = rtw_get_wireless_stats,
8574 #endif
8575 };
8576 #endif
8577 
8578 /* copy from net/wireless/wext.c start
8579  * ----------------------------------------------------------------
8580  *
8581  * Calculate size of private arguments
8582  */
8583 static const char iw_priv_type_size[] = {
8584 	0,                              /* IW_PRIV_TYPE_NONE */
8585 	1,                              /* IW_PRIV_TYPE_BYTE */
8586 	1,                              /* IW_PRIV_TYPE_CHAR */
8587 	0,                              /* Not defined */
8588 	sizeof(__u32),                  /* IW_PRIV_TYPE_INT */
8589 	sizeof(struct iw_freq),         /* IW_PRIV_TYPE_FLOAT */
8590 	sizeof(struct sockaddr),        /* IW_PRIV_TYPE_ADDR */
8591 	0,                              /* Not defined */
8592 };
8593 
8594 static int get_priv_size(__u16 args)
8595 {
8596 	int num = args & IW_PRIV_SIZE_MASK;
8597 	int type = (args & IW_PRIV_TYPE_MASK) >> 12;
8598 
8599 	return num * iw_priv_type_size[type];
8600 }
8601 /* copy from net/wireless/wext.c end */
8602 
8603 
8604 static int _rtw_ioctl_wext_private(struct net_device *dev, union iwreq_data *wrq_data)
8605 {
8606 	int err = 0;
8607 	u8 *input = NULL;
8608 	u32 input_len = 0;
8609 	const char delim[] = " ";
8610 	u8 *output = NULL;
8611 	u32 output_len = 0;
8612 	u32 count = 0;
8613 	u8 *buffer = NULL;
8614 	u32 buffer_len = 0;
8615 	char *ptr = NULL;
8616 	u8 cmdname[17] = {0}; /* IFNAMSIZ+1 */
8617 	u32 cmdlen;
8618 	s32 len;
8619 	u8 *extra = NULL;
8620 	u32 extra_size = 0;
8621 
8622 	s32 k;
8623 	const iw_handler *priv;		/* Private ioctl */
8624 	const struct iw_priv_args *priv_args;	/* Private ioctl description */
8625 	const struct iw_priv_args *mp_priv_args;	/*MP Private ioctl description */
8626 	const struct iw_priv_args *sel_priv_args;	/*Selected Private ioctl description */
8627 	u32 num_priv;				/* Number of ioctl */
8628 	u32 num_priv_args;			/* Number of descriptions */
8629 	u32 num_mp_priv_args;			/*Number of MP descriptions */
8630 	u32 num_sel_priv_args;			/*Number of Selected descriptions */
8631 	iw_handler handler;
8632 	int temp;
8633 	int subcmd = 0;				/* sub-ioctl index */
8634 	int offset = 0;				/* Space for sub-ioctl index */
8635 
8636 	union iwreq_data wdata;
8637 
8638 	_rtw_memcpy(&wdata, wrq_data, sizeof(wdata));
8639 
8640 	input_len = wdata.data.length;
8641 	if (!input_len)
8642 		return -EINVAL;
8643 	input = rtw_zmalloc(input_len);
8644 
8645 	if (input == NULL) {
8646 		err = -EOPNOTSUPP;
8647 		goto exit;
8648 	}
8649 
8650 	if (copy_from_user(input, wdata.data.pointer, input_len)) {
8651 		err = -EFAULT;
8652 		goto exit;
8653 	}
8654 	input[input_len - 1] = '\0';
8655 	ptr = input;
8656 	len = input_len;
8657 
8658 	sscanf(ptr, "%16s", cmdname);
8659 	cmdlen = strlen(cmdname);
8660 	RTW_DBG("%s: cmd=%s\n", __func__, cmdname);
8661 
8662 	/* skip command string */
8663 	if (cmdlen > 0)
8664 		cmdlen += 1; /* skip one space */
8665 	ptr += cmdlen;
8666 	len -= cmdlen;
8667 	RTW_DBG("%s: parameters=%s\n", __func__, ptr);
8668 
8669 	priv = rtw_private_handler;
8670 	priv_args = rtw_private_args;
8671 	mp_priv_args = rtw_mp_private_args;
8672 	num_priv = sizeof(rtw_private_handler) / sizeof(iw_handler);
8673 	num_priv_args = sizeof(rtw_private_args) / sizeof(struct iw_priv_args);
8674 	num_mp_priv_args = sizeof(rtw_mp_private_args) / sizeof(struct iw_priv_args);
8675 
8676 	if (num_priv_args == 0) {
8677 		err = -EOPNOTSUPP;
8678 		goto exit;
8679 	}
8680 
8681 	/* Search the correct ioctl */
8682 	k = -1;
8683 	sel_priv_args = priv_args;
8684 	num_sel_priv_args = num_priv_args;
8685 	while
8686 	((++k < num_sel_priv_args) && strcmp(sel_priv_args[k].name, cmdname))
8687 		;
8688 
8689 	/* If not found... */
8690 	if (k == num_sel_priv_args) {
8691 		k = -1;
8692 		sel_priv_args = mp_priv_args;
8693 		num_sel_priv_args = num_mp_priv_args;
8694 		while
8695 		((++k < num_sel_priv_args) && strcmp(sel_priv_args[k].name, cmdname))
8696 			;
8697 
8698 		if (k == num_sel_priv_args) {
8699 			err = -EOPNOTSUPP;
8700 			goto exit;
8701 		}
8702 	}
8703 
8704 	/* Watch out for sub-ioctls ! */
8705 	if (sel_priv_args[k].cmd < SIOCDEVPRIVATE) {
8706 		int j = -1;
8707 
8708 		/* Find the matching *real* ioctl */
8709 		while ((++j < num_priv_args) && ((priv_args[j].name[0] != '\0') ||
8710 			 (priv_args[j].set_args != sel_priv_args[k].set_args) ||
8711 			 (priv_args[j].get_args != sel_priv_args[k].get_args)))
8712 			;
8713 
8714 		/* If not found... */
8715 		if (j == num_priv_args) {
8716 			err = -EINVAL;
8717 			goto exit;
8718 		}
8719 
8720 		/* Save sub-ioctl number */
8721 		subcmd = sel_priv_args[k].cmd;
8722 		/* Reserve one int (simplify alignment issues) */
8723 		offset = sizeof(__u32);
8724 		/* Use real ioctl definition from now on */
8725 		k = j;
8726 	}
8727 
8728 	buffer = rtw_zmalloc(4096);
8729 	if (NULL == buffer) {
8730 		err = -ENOMEM;
8731 		goto exit;
8732 	}
8733 
8734 	if (k >= num_priv_args) {
8735 		err = -EINVAL;
8736 		goto exit;
8737 	}
8738 
8739 	/* If we have to set some data */
8740 	if ((priv_args[k].set_args & IW_PRIV_TYPE_MASK) &&
8741 	    (priv_args[k].set_args & IW_PRIV_SIZE_MASK)) {
8742 		u8 *str;
8743 
8744 		switch (priv_args[k].set_args & IW_PRIV_TYPE_MASK) {
8745 		case IW_PRIV_TYPE_BYTE:
8746 			/* Fetch args */
8747 			count = 0;
8748 			do {
8749 				str = strsep(&ptr, delim);
8750 				if (NULL == str)
8751 					break;
8752 				sscanf(str, "%i", &temp);
8753 				buffer[count++] = (u8)temp;
8754 			} while (1);
8755 			buffer_len = count;
8756 
8757 			/* Number of args to fetch */
8758 			wdata.data.length = count;
8759 			if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
8760 				wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
8761 
8762 			break;
8763 
8764 		case IW_PRIV_TYPE_INT:
8765 			/* Fetch args */
8766 			count = 0;
8767 			do {
8768 				str = strsep(&ptr, delim);
8769 				if (NULL == str)
8770 					break;
8771 				sscanf(str, "%i", &temp);
8772 				((s32 *)buffer)[count++] = (s32)temp;
8773 			} while (1);
8774 			buffer_len = count * sizeof(s32);
8775 
8776 			/* Number of args to fetch */
8777 			wdata.data.length = count;
8778 			if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
8779 				wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
8780 
8781 			break;
8782 
8783 		case IW_PRIV_TYPE_CHAR:
8784 			if (len > 0) {
8785 				/* Size of the string to fetch */
8786 				wdata.data.length = len;
8787 				if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
8788 					wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
8789 
8790 				/* Fetch string */
8791 				_rtw_memcpy(buffer, ptr, wdata.data.length);
8792 			} else {
8793 				wdata.data.length = 1;
8794 				buffer[0] = '\0';
8795 			}
8796 			buffer_len = wdata.data.length;
8797 			break;
8798 
8799 		default:
8800 			RTW_INFO("%s: Not yet implemented...\n", __func__);
8801 			err = -1;
8802 			goto exit;
8803 		}
8804 
8805 		if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
8806 		    (wdata.data.length != (priv_args[k].set_args & IW_PRIV_SIZE_MASK))) {
8807 			RTW_INFO("%s: The command %s needs exactly %d argument(s)...\n",
8808 				__func__, cmdname, priv_args[k].set_args & IW_PRIV_SIZE_MASK);
8809 			err = -EINVAL;
8810 			goto exit;
8811 		}
8812 	}   /* if args to set */
8813 	else
8814 		wdata.data.length = 0L;
8815 
8816 	/* Those two tests are important. They define how the driver
8817 	* will have to handle the data */
8818 	if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
8819 	    ((get_priv_size(priv_args[k].set_args) + offset) <= IFNAMSIZ)) {
8820 		/* First case : all SET args fit within wrq */
8821 		if (offset)
8822 			wdata.mode = subcmd;
8823 		_rtw_memcpy(wdata.name + offset, buffer, IFNAMSIZ - offset);
8824 	} else {
8825 		if ((priv_args[k].set_args == 0) &&
8826 		    (priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
8827 		    (get_priv_size(priv_args[k].get_args) <= IFNAMSIZ)) {
8828 			/* Second case : no SET args, GET args fit within wrq */
8829 			if (offset)
8830 				wdata.mode = subcmd;
8831 		} else {
8832 			/* Third case : args won't fit in wrq, or variable number of args */
8833 			if (copy_to_user(wdata.data.pointer, buffer, buffer_len)) {
8834 				err = -EFAULT;
8835 				goto exit;
8836 			}
8837 			wdata.data.flags = subcmd;
8838 		}
8839 	}
8840 
8841 	rtw_mfree(input, input_len);
8842 	input = NULL;
8843 
8844 	extra_size = 0;
8845 	if (IW_IS_SET(priv_args[k].cmd)) {
8846 		/* Size of set arguments */
8847 		extra_size = get_priv_size(priv_args[k].set_args);
8848 
8849 		/* Does it fits in iwr ? */
8850 		if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
8851 		    ((extra_size + offset) <= IFNAMSIZ))
8852 			extra_size = 0;
8853 	} else {
8854 		/* Size of get arguments */
8855 		extra_size = get_priv_size(priv_args[k].get_args);
8856 
8857 		/* Does it fits in iwr ? */
8858 		if ((priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
8859 		    (extra_size <= IFNAMSIZ))
8860 			extra_size = 0;
8861 	}
8862 
8863 	if (extra_size == 0) {
8864 		extra = (u8 *)&wdata;
8865 		rtw_mfree(buffer, 4096);
8866 		buffer = NULL;
8867 	} else
8868 		extra = buffer;
8869 
8870 	handler = priv[priv_args[k].cmd - SIOCIWFIRSTPRIV];
8871 	err = handler(dev, NULL, &wdata, extra);
8872 
8873 	/* If we have to get some data */
8874 	if ((priv_args[k].get_args & IW_PRIV_TYPE_MASK) &&
8875 	    (priv_args[k].get_args & IW_PRIV_SIZE_MASK)) {
8876 		int j;
8877 		int n = 0;	/* number of args */
8878 		u8 str[20] = {0};
8879 
8880 		/* Check where is the returned data */
8881 		if ((priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
8882 		    (get_priv_size(priv_args[k].get_args) <= IFNAMSIZ))
8883 			n = priv_args[k].get_args & IW_PRIV_SIZE_MASK;
8884 		else
8885 			n = wdata.data.length;
8886 
8887 		output = rtw_zmalloc(4096);
8888 		if (NULL == output) {
8889 			err =  -ENOMEM;
8890 			goto exit;
8891 		}
8892 
8893 		switch (priv_args[k].get_args & IW_PRIV_TYPE_MASK) {
8894 		case IW_PRIV_TYPE_BYTE:
8895 			/* Display args */
8896 			for (j = 0; j < n; j++) {
8897 				sprintf(str, "%d  ", extra[j]);
8898 				len = strlen(str);
8899 				output_len = strlen(output);
8900 				if ((output_len + len + 1) > 4096) {
8901 					err = -E2BIG;
8902 					goto exit;
8903 				}
8904 				_rtw_memcpy(output + output_len, str, len);
8905 			}
8906 			break;
8907 
8908 		case IW_PRIV_TYPE_INT:
8909 			/* Display args */
8910 			for (j = 0; j < n; j++) {
8911 				sprintf(str, "%d  ", ((__s32 *)extra)[j]);
8912 				len = strlen(str);
8913 				output_len = strlen(output);
8914 				if ((output_len + len + 1) > 4096) {
8915 					err = -E2BIG;
8916 					goto exit;
8917 				}
8918 				_rtw_memcpy(output + output_len, str, len);
8919 			}
8920 			break;
8921 
8922 		case IW_PRIV_TYPE_CHAR:
8923 			/* Display args */
8924 			_rtw_memcpy(output, extra, n);
8925 			output_len = n;
8926 			break;
8927 
8928 		default:
8929 			RTW_INFO("%s: Not yet implemented...\n", __func__);
8930 			err = -1;
8931 			goto exit;
8932 		}
8933 
8934 		output_len ++;
8935 		wrq_data->data.length = output_len;
8936 		if (copy_to_user(wrq_data->data.pointer, output, output_len)) {
8937 			err = -EFAULT;
8938 			goto exit;
8939 		}
8940 	}   /* if args to set */
8941 	else
8942 		wrq_data->data.length = 0;
8943 
8944 exit:
8945 	if (input)
8946 		rtw_mfree(input, input_len);
8947 	if (buffer)
8948 		rtw_mfree(buffer, 4096);
8949 	if (output)
8950 		rtw_mfree(output, 4096);
8951 
8952 	return err;
8953 }
8954 
8955 #ifdef CONFIG_COMPAT
8956 static int rtw_ioctl_compat_wext_private(struct net_device *dev, struct ifreq *rq)
8957 {
8958 	struct compat_iw_point iwp_compat;
8959 	union iwreq_data wrq_data;
8960 	int err = 0;
8961 	RTW_DBG("%s:...\n", __func__);
8962 	if (copy_from_user(&iwp_compat, rq->ifr_ifru.ifru_data, sizeof(struct compat_iw_point)))
8963 		return -EFAULT;
8964 
8965 	wrq_data.data.pointer = compat_ptr(iwp_compat.pointer);
8966 	wrq_data.data.length = iwp_compat.length;
8967 	wrq_data.data.flags = iwp_compat.flags;
8968 
8969 	err = _rtw_ioctl_wext_private(dev, &wrq_data);
8970 
8971 	iwp_compat.pointer = ptr_to_compat(wrq_data.data.pointer);
8972 	iwp_compat.length = wrq_data.data.length;
8973 	iwp_compat.flags = wrq_data.data.flags;
8974 	if (copy_to_user(rq->ifr_ifru.ifru_data, &iwp_compat, sizeof(struct compat_iw_point)))
8975 		return -EFAULT;
8976 
8977 	return err;
8978 }
8979 #endif /* CONFIG_COMPAT */
8980 
8981 static int rtw_ioctl_standard_wext_private(struct net_device *dev, struct ifreq *rq)
8982 {
8983 	struct iw_point *iwp;
8984 	union iwreq_data wrq_data;
8985 	int err = 0;
8986 	iwp = &wrq_data.data;
8987 	RTW_DBG("%s:...\n", __func__);
8988 	if (copy_from_user(iwp, rq->ifr_ifru.ifru_data, sizeof(struct iw_point)))
8989 		return -EFAULT;
8990 
8991 	err = _rtw_ioctl_wext_private(dev, &wrq_data);
8992 
8993 	if (copy_to_user(rq->ifr_ifru.ifru_data, iwp, sizeof(struct iw_point)))
8994 		return -EFAULT;
8995 
8996 	return err;
8997 }
8998 
8999 static int rtw_ioctl_wext_private(struct net_device *dev, struct ifreq *rq)
9000 {
9001 #ifdef CONFIG_COMPAT
9002 #if (KERNEL_VERSION(4, 6, 0) > LINUX_VERSION_CODE)
9003 	if (is_compat_task())
9004 #else
9005 	if (in_compat_syscall())
9006 #endif
9007 		return rtw_ioctl_compat_wext_private(dev, rq);
9008 	else
9009 #endif /* CONFIG_COMPAT */
9010 		return rtw_ioctl_standard_wext_private(dev, rq);
9011 }
9012 
9013 int rtw_ioctl(struct net_device *dev, struct ifreq *rq, int cmd)
9014 {
9015 	struct iwreq *wrq = (struct iwreq *)rq;
9016 	int ret = 0;
9017 
9018 	switch (cmd) {
9019 	case RTL_IOCTL_WPA_SUPPLICANT:
9020 		ret = wpa_supplicant_ioctl(dev, &wrq->u.data);
9021 		break;
9022 #ifdef CONFIG_AP_MODE
9023 	case RTL_IOCTL_HOSTAPD:
9024 		ret = rtw_hostapd_ioctl(dev, &wrq->u.data);
9025 		break;
9026 #ifdef CONFIG_WIRELESS_EXT
9027 	case SIOCSIWMODE:
9028 		ret = rtw_wx_set_mode(dev, NULL, &wrq->u, NULL);
9029 		break;
9030 #endif
9031 #endif /* CONFIG_AP_MODE */
9032 	case SIOCDEVPRIVATE:
9033 		ret = rtw_ioctl_wext_private(dev, rq);
9034 		break;
9035 	case (SIOCDEVPRIVATE+1):
9036 		ret = rtw_android_priv_cmd(dev, rq, cmd);
9037 		break;
9038 	default:
9039 		ret = -EOPNOTSUPP;
9040 		break;
9041 	}
9042 
9043 	return ret;
9044 }
9045