WiFi: add rtl8189es/etv support, Optimization wifi configuration.
[firefly-linux-kernel-4.4.55.git] / drivers / net / wireless / rockchip_wlan / rtl8189es / os_dep / linux / ioctl_linux.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2007 - 2012 Realtek Corporation. All rights reserved.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of version 2 of the GNU General Public License as
7  * published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope that it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
12  * more details.
13  *
14  * You should have received a copy of the GNU General Public License along with
15  * this program; if not, write to the Free Software Foundation, Inc.,
16  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
17  *
18  *
19  ******************************************************************************/
20 #define _IOCTL_LINUX_C_
21
22 #include <drv_types.h>
23
24 //#ifdef CONFIG_MP_INCLUDED
25 #include <rtw_mp_ioctl.h>
26 #include "../../hal/OUTSRC/odm_precomp.h"
27 //#endif
28
29 #if defined(CONFIG_RTL8723A)
30 #include "rtl8723a_hal.h"
31 #include <rtw_bt_mp.h>
32 #endif
33
34 #if defined(CONFIG_RTL8723B)
35 #include <rtw_bt_mp.h>
36 #endif
37
38 #if (LINUX_VERSION_CODE < KERNEL_VERSION(2,6,27))
39 #define  iwe_stream_add_event(a, b, c, d, e)  iwe_stream_add_event(b, c, d, e)
40 #define  iwe_stream_add_point(a, b, c, d, e)  iwe_stream_add_point(b, c, d, e)
41 #endif
42
43
44 #define RTL_IOCTL_WPA_SUPPLICANT        SIOCIWFIRSTPRIV+30
45
46 #define SCAN_ITEM_SIZE 768
47 #define MAX_CUSTOM_LEN 64
48 #define RATE_COUNT 4
49
50 #ifdef CONFIG_GLOBAL_UI_PID
51 extern int ui_pid[3];
52 #endif
53
54 // combo scan
55 #define WEXT_CSCAN_AMOUNT 9
56 #define WEXT_CSCAN_BUF_LEN              360
57 #define WEXT_CSCAN_HEADER               "CSCAN S\x01\x00\x00S\x00"
58 #define WEXT_CSCAN_HEADER_SIZE          12
59 #define WEXT_CSCAN_SSID_SECTION         'S'
60 #define WEXT_CSCAN_CHANNEL_SECTION      'C'
61 #define WEXT_CSCAN_NPROBE_SECTION       'N'
62 #define WEXT_CSCAN_ACTV_DWELL_SECTION   'A'
63 #define WEXT_CSCAN_PASV_DWELL_SECTION   'P'
64 #define WEXT_CSCAN_HOME_DWELL_SECTION   'H'
65 #define WEXT_CSCAN_TYPE_SECTION         'T'
66
67
68 extern u8 key_2char2num(u8 hch, u8 lch);
69 extern u8 str_2char2num(u8 hch, u8 lch);
70 extern void macstr2num(u8 *dst, u8 *src);
71 extern u8 convert_ip_addr(u8 hch, u8 mch, u8 lch);
72
73 u32 rtw_rates[] = {1000000,2000000,5500000,11000000,
74         6000000,9000000,12000000,18000000,24000000,36000000,48000000,54000000};
75
76 static const char * const iw_operation_mode[] = 
77
78         "Auto", "Ad-Hoc", "Managed",  "Master", "Repeater", "Secondary", "Monitor" 
79 };
80
81 static int hex2num_i(char c)
82 {
83         if (c >= '0' && c <= '9')
84                 return c - '0';
85         if (c >= 'a' && c <= 'f')
86                 return c - 'a' + 10;
87         if (c >= 'A' && c <= 'F')
88                 return c - 'A' + 10;
89         return -1;
90 }
91
92 static int hex2byte_i(const char *hex)
93 {
94         int a, b;
95         a = hex2num_i(*hex++);
96         if (a < 0)
97                 return -1;
98         b = hex2num_i(*hex++);
99         if (b < 0)
100                 return -1;
101         return (a << 4) | b;
102 }
103
104 /**
105  * hwaddr_aton - Convert ASCII string to MAC address
106  * @txt: MAC address as a string (e.g., "00:11:22:33:44:55")
107  * @addr: Buffer for the MAC address (ETH_ALEN = 6 bytes)
108  * Returns: 0 on success, -1 on failure (e.g., string not a MAC address)
109  */
110 static int hwaddr_aton_i(const char *txt, u8 *addr)
111 {
112         int i;
113
114         for (i = 0; i < 6; i++) {
115                 int a, b;
116
117                 a = hex2num_i(*txt++);
118                 if (a < 0)
119                         return -1;
120                 b = hex2num_i(*txt++);
121                 if (b < 0)
122                         return -1;
123                 *addr++ = (a << 4) | b;
124                 if (i < 5 && *txt++ != ':')
125                         return -1;
126         }
127
128         return 0;
129 }
130
131 static void indicate_wx_custom_event(_adapter *padapter, char *msg)
132 {
133         u8 *buff, *p;
134         union iwreq_data wrqu;
135
136         if (strlen(msg) > IW_CUSTOM_MAX) {
137                 DBG_871X("%s strlen(msg):%zu > IW_CUSTOM_MAX:%u\n", __FUNCTION__ , strlen(msg), IW_CUSTOM_MAX);
138                 return;
139         }
140
141         buff = rtw_zmalloc(IW_CUSTOM_MAX+1);
142         if(!buff)
143                 return;
144
145         _rtw_memcpy(buff, msg, strlen(msg));
146                 
147         _rtw_memset(&wrqu,0,sizeof(wrqu));
148         wrqu.data.length = strlen(msg);
149
150         DBG_871X("%s %s\n", __FUNCTION__, buff);        
151 #ifndef CONFIG_IOCTL_CFG80211
152         wireless_send_event(padapter->pnetdev, IWEVCUSTOM, &wrqu, buff);
153 #endif
154
155         rtw_mfree(buff, IW_CUSTOM_MAX+1);
156
157 }
158
159
160 static void request_wps_pbc_event(_adapter *padapter)
161 {
162         u8 *buff, *p;
163         union iwreq_data wrqu;
164
165
166         buff = rtw_malloc(IW_CUSTOM_MAX);
167         if(!buff)
168                 return;
169                 
170         _rtw_memset(buff, 0, IW_CUSTOM_MAX);
171                 
172         p=buff;
173                 
174         p+=sprintf(p, "WPS_PBC_START.request=TRUE");
175                 
176         _rtw_memset(&wrqu,0,sizeof(wrqu));
177                 
178         wrqu.data.length = p-buff;
179                 
180         wrqu.data.length = (wrqu.data.length<IW_CUSTOM_MAX) ? wrqu.data.length:IW_CUSTOM_MAX;
181
182         DBG_871X("%s\n", __FUNCTION__);
183                 
184 #ifndef CONFIG_IOCTL_CFG80211
185         wireless_send_event(padapter->pnetdev, IWEVCUSTOM, &wrqu, buff);
186 #endif
187
188         if(buff)
189         {
190                 rtw_mfree(buff, IW_CUSTOM_MAX);
191         }
192
193 }
194
195 #ifdef CONFIG_SUPPORT_HW_WPS_PBC
196 void rtw_request_wps_pbc_event(_adapter *padapter)
197 {
198 #ifdef RTK_DMP_PLATFORM
199 #if (LINUX_VERSION_CODE > KERNEL_VERSION(2,6,12))
200         kobject_uevent(&padapter->pnetdev->dev.kobj, KOBJ_NET_PBC);
201 #else
202         kobject_hotplug(&padapter->pnetdev->class_dev.kobj, KOBJ_NET_PBC);
203 #endif
204 #else
205
206         if ( padapter->pid[0] == 0 )
207         {       //      0 is the default value and it means the application monitors the HW PBC doesn't privde its pid to driver.
208                 return;
209         }
210
211         rtw_signal_process(padapter->pid[0], SIGUSR1);
212
213 #endif
214
215         rtw_led_control(padapter, LED_CTL_START_WPS_BOTTON);
216 }
217 #endif//#ifdef CONFIG_SUPPORT_HW_WPS_PBC
218
219 void indicate_wx_scan_complete_event(_adapter *padapter)
220 {       
221         union iwreq_data wrqu;
222         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;     
223
224         _rtw_memset(&wrqu, 0, sizeof(union iwreq_data));
225
226         //DBG_871X("+rtw_indicate_wx_scan_complete_event\n");
227 #ifndef CONFIG_IOCTL_CFG80211
228         wireless_send_event(padapter->pnetdev, SIOCGIWSCAN, &wrqu, NULL);
229 #endif
230 }
231
232
233 void rtw_indicate_wx_assoc_event(_adapter *padapter)
234 {       
235         union iwreq_data wrqu;
236         struct  mlme_priv *pmlmepriv = &padapter->mlmepriv;
237         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
238         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
239         WLAN_BSSID_EX           *pnetwork = (WLAN_BSSID_EX*)(&(pmlmeinfo->network));
240
241         _rtw_memset(&wrqu, 0, sizeof(union iwreq_data));
242         
243         wrqu.ap_addr.sa_family = ARPHRD_ETHER;  
244         
245         if(check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)==_TRUE )
246                 _rtw_memcpy(wrqu.ap_addr.sa_data, pnetwork->MacAddress, ETH_ALEN);
247         else
248                 _rtw_memcpy(wrqu.ap_addr.sa_data, pmlmepriv->cur_network.network.MacAddress, ETH_ALEN);
249
250         DBG_871X_LEVEL(_drv_always_, "assoc success\n");
251 #ifndef CONFIG_IOCTL_CFG80211
252         wireless_send_event(padapter->pnetdev, SIOCGIWAP, &wrqu, NULL);
253 #endif
254 }
255
256 void rtw_indicate_wx_disassoc_event(_adapter *padapter)
257 {       
258         union iwreq_data wrqu;
259
260         _rtw_memset(&wrqu, 0, sizeof(union iwreq_data));
261
262         wrqu.ap_addr.sa_family = ARPHRD_ETHER;
263         _rtw_memset(wrqu.ap_addr.sa_data, 0, ETH_ALEN);
264
265 #ifndef CONFIG_IOCTL_CFG80211
266         DBG_871X_LEVEL(_drv_always_, "indicate disassoc\n");
267         wireless_send_event(padapter->pnetdev, SIOCGIWAP, &wrqu, NULL);
268 #endif
269 }
270
271 /*
272 uint    rtw_is_cckrates_included(u8 *rate)
273 {       
274                 u32     i = 0;                  
275
276                 while(rate[i]!=0)
277                 {               
278                         if  (  (((rate[i]) & 0x7f) == 2)        || (((rate[i]) & 0x7f) == 4) ||         
279                         (((rate[i]) & 0x7f) == 11)  || (((rate[i]) & 0x7f) == 22) )             
280                         return _TRUE;   
281                         i++;
282                 }
283                 
284                 return _FALSE;
285 }
286
287 uint    rtw_is_cckratesonly_included(u8 *rate)
288 {
289         u32 i = 0;
290
291         while(rate[i]!=0)
292         {
293                         if  (  (((rate[i]) & 0x7f) != 2) && (((rate[i]) & 0x7f) != 4) &&
294                                 (((rate[i]) & 0x7f) != 11)  && (((rate[i]) & 0x7f) != 22) )
295                         return _FALSE;          
296                         i++;
297         }
298         
299         return _TRUE;
300 }
301 */
302
303 static char *translate_scan(_adapter *padapter, 
304                                 struct iw_request_info* info, struct wlan_network *pnetwork,
305                                 char *start, char *stop)
306 {
307         struct iw_event iwe;
308         u16 cap;
309         u32 ht_ielen = 0, vht_ielen = 0;
310         char custom[MAX_CUSTOM_LEN];
311         char *p;
312         u16 max_rate=0, rate, ht_cap=_FALSE, vht_cap = _FALSE;
313         u32 i = 0;      
314         char    *current_val;
315         long rssi;
316         u8 bw_40MHz=0, short_GI=0, bw_160MHz=0, vht_highest_rate = 0;
317         u16 mcs_rate=0, vht_data_rate=0;
318         u8 ie_offset = (pnetwork->network.Reserved[0] == 2? 0:12);
319         struct registry_priv *pregpriv = &padapter->registrypriv;
320 #ifdef CONFIG_P2P
321         struct wifidirect_info  *pwdinfo = &padapter->wdinfo;
322 #endif //CONFIG_P2P
323
324 #ifdef CONFIG_P2P
325 #ifdef CONFIG_WFD
326         if ( SCAN_RESULT_ALL == pwdinfo->wfd_info->scan_result_type )
327         {
328
329         }
330         else if ( ( SCAN_RESULT_P2P_ONLY == pwdinfo->wfd_info->scan_result_type ) || 
331                       ( SCAN_RESULT_WFD_TYPE == pwdinfo->wfd_info->scan_result_type ) )
332 #endif // CONFIG_WFD
333         {
334                 if(!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
335                 {
336                         u32     blnGotP2PIE = _FALSE;
337                         
338                         //      User is doing the P2P device discovery
339                         //      The prefix of SSID should be "DIRECT-" and the IE should contains the P2P IE.
340                         //      If not, the driver should ignore this AP and go to the next AP.
341
342                         //      Verifying the SSID
343                         if ( _rtw_memcmp( pnetwork->network.Ssid.Ssid, pwdinfo->p2p_wildcard_ssid, P2P_WILDCARD_SSID_LEN ) )
344                         {
345                                 u32     p2pielen = 0;
346
347                                 //      Verifying the P2P IE
348                                 if (rtw_get_p2p_ie_from_scan_queue(&pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])) 
349                                 {
350                                         blnGotP2PIE = _TRUE;
351                                 }
352                         }
353
354                         if ( blnGotP2PIE == _FALSE )
355                         {
356                                 return start;
357                         }
358                         
359                 }
360         }
361
362 #ifdef CONFIG_WFD
363         if ( SCAN_RESULT_WFD_TYPE == pwdinfo->wfd_info->scan_result_type )
364         {
365                 u32     blnGotWFD = _FALSE;
366                 u8      wfd_ie[ 128 ] = { 0x00 };
367                 uint    wfd_ielen = 0;
368                 
369                 if ( rtw_get_wfd_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength,  wfd_ie, &wfd_ielen, pnetwork->network.Reserved[0]) )
370                 {
371                         u8      wfd_devinfo[ 6 ] = { 0x00 };
372                         uint    wfd_devlen = 6;
373                         
374                         if ( rtw_get_wfd_attr_content( wfd_ie, wfd_ielen, WFD_ATTR_DEVICE_INFO, wfd_devinfo, &wfd_devlen) )
375                         {
376                                 if ( pwdinfo->wfd_info->wfd_device_type == WFD_DEVINFO_PSINK )
377                                 {
378                                         //      the first two bits will indicate the WFD device type
379                                         if ( ( wfd_devinfo[ 1 ] & 0x03 ) == WFD_DEVINFO_SOURCE )
380                                         {
381                                                 //      If this device is Miracast PSink device, the scan reuslt should just provide the Miracast source.
382                                                 blnGotWFD = _TRUE;
383                                         }
384                                 }
385                                 else if ( pwdinfo->wfd_info->wfd_device_type == WFD_DEVINFO_SOURCE )
386                                 {
387                                         //      the first two bits will indicate the WFD device type
388                                         if ( ( wfd_devinfo[ 1 ] & 0x03 ) == WFD_DEVINFO_PSINK )
389                                         {
390                                                 //      If this device is Miracast source device, the scan reuslt should just provide the Miracast PSink.
391                                                 //      Todo: How about the SSink?!
392                                                 blnGotWFD = _TRUE;
393                                         }
394                                 }
395                         }
396                 }
397                 
398                 if ( blnGotWFD == _FALSE )
399                 {
400                         return start;
401                 }
402         }
403 #endif // CONFIG_WFD
404
405 #endif //CONFIG_P2P
406
407         /*  AP MAC address  */
408         iwe.cmd = SIOCGIWAP;
409         iwe.u.ap_addr.sa_family = ARPHRD_ETHER;
410
411         _rtw_memcpy(iwe.u.ap_addr.sa_data, pnetwork->network.MacAddress, ETH_ALEN);
412         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_ADDR_LEN);
413
414         /* Add the ESSID */
415         iwe.cmd = SIOCGIWESSID;
416         iwe.u.data.flags = 1;   
417         iwe.u.data.length = min((u16)pnetwork->network.Ssid.SsidLength, (u16)32);
418         start = iwe_stream_add_point(info, start, stop, &iwe, pnetwork->network.Ssid.Ssid);
419
420         //parsing HT_CAP_IE
421         if (pnetwork->network.Reserved[0] == 2) // Probe Request
422         {
423                 p = rtw_get_ie(&pnetwork->network.IEs[0], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength);
424         }
425         else
426         {
427                 p = rtw_get_ie(&pnetwork->network.IEs[12], _HT_CAPABILITY_IE_, &ht_ielen, pnetwork->network.IELength-12);
428         }
429         if(p && ht_ielen>0)
430         {
431                 struct rtw_ieee80211_ht_cap *pht_capie;
432                 ht_cap = _TRUE;                 
433                 pht_capie = (struct rtw_ieee80211_ht_cap *)(p+2);               
434                 _rtw_memcpy(&mcs_rate , pht_capie->supp_mcs_set, 2);
435                 bw_40MHz = (pht_capie->cap_info&IEEE80211_HT_CAP_SUP_WIDTH) ? 1:0;
436                 short_GI = (pht_capie->cap_info&(IEEE80211_HT_CAP_SGI_20|IEEE80211_HT_CAP_SGI_40)) ? 1:0;
437         }
438
439 #ifdef CONFIG_80211AC_VHT
440         //parsing VHT_CAP_IE
441         p = rtw_get_ie(&pnetwork->network.IEs[ie_offset], EID_VHTCapability, &vht_ielen, pnetwork->network.IELength-ie_offset);
442         if(p && vht_ielen>0)
443         {
444                 u8      mcs_map[2];
445
446                 vht_cap = _TRUE;                
447                 bw_160MHz = GET_VHT_CAPABILITY_ELE_CHL_WIDTH(p+2);
448                 if(bw_160MHz)
449                         short_GI = GET_VHT_CAPABILITY_ELE_SHORT_GI160M(p+2);
450                 else
451                         short_GI = GET_VHT_CAPABILITY_ELE_SHORT_GI80M(p+2);
452
453                 _rtw_memcpy(mcs_map, GET_VHT_CAPABILITY_ELE_TX_MCS(p+2), 2);
454
455                 vht_highest_rate = rtw_get_vht_highest_rate(mcs_map);
456                 vht_data_rate = rtw_vht_mcs_to_data_rate(CHANNEL_WIDTH_80, short_GI, vht_highest_rate);
457         }
458 #endif
459
460         /* Add the protocol name */
461         iwe.cmd = SIOCGIWNAME;
462         if ((rtw_is_cckratesonly_included((u8*)&pnetwork->network.SupportedRates)) == _TRUE)            
463         {
464                 if(ht_cap == _TRUE)
465                         snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11bn");
466                 else
467                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11b");
468         }       
469         else if ((rtw_is_cckrates_included((u8*)&pnetwork->network.SupportedRates)) == _TRUE)   
470         {
471                 if(ht_cap == _TRUE)
472                         snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11bgn");
473                 else
474                         snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11bg");
475         }       
476         else
477         {
478                 if(pnetwork->network.Configuration.DSConfig > 14)
479                 {
480                         if(vht_cap == _TRUE)
481                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11AC");
482                         else if(ht_cap == _TRUE)
483                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11an");
484                         else
485                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11a");
486                 }
487                 else
488                 {
489                         if(ht_cap == _TRUE)
490                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11gn");
491                         else
492                                 snprintf(iwe.u.name, IFNAMSIZ, "IEEE 802.11g");
493                 }
494         }       
495
496         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_CHAR_LEN);
497
498           /* Add mode */
499         if (pnetwork->network.Reserved[0] == 2) // Probe Request
500         {
501                 cap = 0;
502         }
503         else
504         {
505         iwe.cmd = SIOCGIWMODE;
506                 _rtw_memcpy((u8 *)&cap, rtw_get_capability_from_ie(pnetwork->network.IEs), 2);
507                 cap = le16_to_cpu(cap);
508         }
509
510         if(cap & (WLAN_CAPABILITY_IBSS |WLAN_CAPABILITY_BSS)){
511                 if (cap & WLAN_CAPABILITY_BSS)
512                         iwe.u.mode = IW_MODE_MASTER;
513                 else
514                         iwe.u.mode = IW_MODE_ADHOC;
515
516                 start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_UINT_LEN);
517         }
518
519         if(pnetwork->network.Configuration.DSConfig<1 /*|| pnetwork->network.Configuration.DSConfig>14*/)
520                 pnetwork->network.Configuration.DSConfig = 1;
521
522          /* Add frequency/channel */
523         iwe.cmd = SIOCGIWFREQ;
524         iwe.u.freq.m = rtw_ch2freq(pnetwork->network.Configuration.DSConfig) * 100000;
525         iwe.u.freq.e = 1;
526         iwe.u.freq.i = pnetwork->network.Configuration.DSConfig;
527         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_FREQ_LEN);
528
529         /* Add encryption capability */
530         iwe.cmd = SIOCGIWENCODE;
531         if (cap & WLAN_CAPABILITY_PRIVACY)
532                 iwe.u.data.flags = IW_ENCODE_ENABLED | IW_ENCODE_NOKEY;
533         else
534                 iwe.u.data.flags = IW_ENCODE_DISABLED;
535         iwe.u.data.length = 0;
536         start = iwe_stream_add_point(info, start, stop, &iwe, pnetwork->network.Ssid.Ssid);
537
538         /*Add basic and extended rates */
539         max_rate = 0;
540         p = custom;
541         p += snprintf(p, MAX_CUSTOM_LEN - (p - custom), " Rates (Mb/s): ");
542         while(pnetwork->network.SupportedRates[i]!=0)
543         {
544                 rate = pnetwork->network.SupportedRates[i]&0x7F; 
545                 if (rate > max_rate)
546                         max_rate = rate;
547                 p += snprintf(p, MAX_CUSTOM_LEN - (p - custom),
548                               "%d%s ", rate >> 1, (rate & 1) ? ".5" : "");
549                 i++;
550         }
551
552         if(vht_cap == _TRUE) {
553                 max_rate = vht_data_rate;
554         }
555         else if(ht_cap == _TRUE)
556         {
557                 if(mcs_rate&0x8000)//MCS15
558                 {
559                         max_rate = (bw_40MHz) ? ((short_GI)?300:270):((short_GI)?144:130);
560                         
561                 }
562                 else if(mcs_rate&0x0080)//MCS7
563                 {
564                         max_rate = (bw_40MHz) ? ((short_GI)?150:135):((short_GI)?72:65);
565                 }
566                 else//default MCS7
567                 {
568                         //DBG_871X("wx_get_scan, mcs_rate_bitmap=0x%x\n", mcs_rate);
569                         max_rate = (bw_40MHz) ? ((short_GI)?150:135):((short_GI)?72:65);
570                 }
571
572                 max_rate = max_rate*2;//Mbps/2;         
573         }
574
575         iwe.cmd = SIOCGIWRATE;
576         iwe.u.bitrate.fixed = iwe.u.bitrate.disabled = 0;
577         iwe.u.bitrate.value = max_rate * 500000;
578         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_PARAM_LEN);
579
580         //parsing WPA/WPA2 IE
581         if (pnetwork->network.Reserved[0] != 2) // Probe Request
582         {
583                 u8 buf[MAX_WPA_IE_LEN*2];
584                 u8 wpa_ie[255],rsn_ie[255];
585                 u16 wpa_len=0,rsn_len=0;
586                 u8 *p;
587                 sint out_len=0;
588                 out_len=rtw_get_sec_ie(pnetwork->network.IEs ,pnetwork->network.IELength,rsn_ie,&rsn_len,wpa_ie,&wpa_len);
589                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: ssid=%s\n",pnetwork->network.Ssid.Ssid));
590                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: wpa_len=%d rsn_len=%d\n",wpa_len,rsn_len));
591
592                 if (wpa_len > 0)
593                 {
594                         p=buf;
595                         _rtw_memset(buf, 0, MAX_WPA_IE_LEN*2);
596                         p += sprintf(p, "wpa_ie=");
597                         for (i = 0; i < wpa_len; i++) {
598                                 p += sprintf(p, "%02x", wpa_ie[i]);
599                         }
600
601                         if (wpa_len > 100) {
602                                 printk("-----------------Len %d----------------\n", wpa_len);
603                                 for (i = 0; i < wpa_len; i++) {
604                                         printk("%02x ", wpa_ie[i]);
605                                 }
606                                 printk("\n");
607                                 printk("-----------------Len %d----------------\n", wpa_len);
608                         }
609         
610                         _rtw_memset(&iwe, 0, sizeof(iwe));
611                         iwe.cmd = IWEVCUSTOM;
612                         iwe.u.data.length = strlen(buf);
613                         start = iwe_stream_add_point(info, start, stop, &iwe,buf);
614                         
615                         _rtw_memset(&iwe, 0, sizeof(iwe));
616                         iwe.cmd =IWEVGENIE;
617                         iwe.u.data.length = wpa_len;
618                         start = iwe_stream_add_point(info, start, stop, &iwe, wpa_ie);                  
619                 }
620                 if (rsn_len > 0)
621                 {
622                         p = buf;
623                         _rtw_memset(buf, 0, MAX_WPA_IE_LEN*2);
624                         p += sprintf(p, "rsn_ie=");
625                         for (i = 0; i < rsn_len; i++) {
626                                 p += sprintf(p, "%02x", rsn_ie[i]);
627                         }
628                         _rtw_memset(&iwe, 0, sizeof(iwe));
629                         iwe.cmd = IWEVCUSTOM;
630                         iwe.u.data.length = strlen(buf);
631                         start = iwe_stream_add_point(info, start, stop, &iwe,buf);
632                 
633                         _rtw_memset(&iwe, 0, sizeof(iwe));
634                         iwe.cmd =IWEVGENIE;
635                         iwe.u.data.length = rsn_len;
636                         start = iwe_stream_add_point(info, start, stop, &iwe, rsn_ie);          
637                 }
638         }
639
640         { //parsing WPS IE
641                 uint cnt = 0,total_ielen;       
642                 u8 *wpsie_ptr=NULL;
643                 uint wps_ielen = 0;             
644
645                 u8 *ie_ptr = pnetwork->network.IEs + ie_offset;
646                 total_ielen= pnetwork->network.IELength - ie_offset;
647
648                 if (pnetwork->network.Reserved[0] == 2) // Probe Request
649                 {
650                         ie_ptr = pnetwork->network.IEs;
651                         total_ielen = pnetwork->network.IELength;
652                 }
653                 else     // Beacon or Probe Respones
654                 {
655                         ie_ptr = pnetwork->network.IEs + _FIXED_IE_LENGTH_;
656                         total_ielen = pnetwork->network.IELength - _FIXED_IE_LENGTH_;
657                 }
658         
659                 while(cnt < total_ielen)
660                 {
661                         if(rtw_is_wps_ie(&ie_ptr[cnt], &wps_ielen) && (wps_ielen>2))                    
662                         {
663                                 wpsie_ptr = &ie_ptr[cnt];
664                                 iwe.cmd =IWEVGENIE;
665                                 iwe.u.data.length = (u16)wps_ielen;
666                                 start = iwe_stream_add_point(info, start, stop, &iwe, wpsie_ptr);                                               
667                         }                       
668                         cnt+=ie_ptr[cnt+1]+2; //goto next
669                 }
670         }
671
672 #ifdef CONFIG_WAPI_SUPPORT
673         if (pnetwork->network.Reserved[0] != 2) // Probe Request
674         {
675                 sint out_len_wapi=0;
676                 /* here use static for stack size */
677                 static u8 buf_wapi[MAX_WAPI_IE_LEN*2];
678                 static u8 wapi_ie[MAX_WAPI_IE_LEN];
679                 u16 wapi_len=0;
680                 u16  i;
681
682                 _rtw_memset(buf_wapi, 0, MAX_WAPI_IE_LEN);
683                 _rtw_memset(wapi_ie, 0, MAX_WAPI_IE_LEN);
684
685                 out_len_wapi=rtw_get_wapi_ie(pnetwork->network.IEs ,pnetwork->network.IELength,wapi_ie,&wapi_len);
686                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: ssid=%s\n",pnetwork->network.Ssid.Ssid));
687                 RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan: wapi_len=%d \n",wapi_len));
688
689                 DBG_871X("rtw_wx_get_scan: %s ",pnetwork->network.Ssid.Ssid);
690                 DBG_871X("rtw_wx_get_scan: ssid = %d ",wapi_len);
691
692
693                 if (wapi_len > 0)
694                 {
695                         p=buf_wapi;
696                         _rtw_memset(buf_wapi, 0, MAX_WAPI_IE_LEN*2);
697                         p += sprintf(p, "wapi_ie=");
698                         for (i = 0; i < wapi_len; i++) {
699                                 p += sprintf(p, "%02x", wapi_ie[i]);
700                         }
701
702                         _rtw_memset(&iwe, 0, sizeof(iwe));
703                         iwe.cmd = IWEVCUSTOM;
704                         iwe.u.data.length = strlen(buf_wapi);
705                         start = iwe_stream_add_point(info, start, stop, &iwe,buf_wapi);
706
707                         _rtw_memset(&iwe, 0, sizeof(iwe));
708                         iwe.cmd =IWEVGENIE;
709                         iwe.u.data.length = wapi_len;
710                         start = iwe_stream_add_point(info, start, stop, &iwe, wapi_ie);
711                 }
712         }
713 #endif
714
715 {
716         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
717         u8 ss, sq;
718         
719         /* Add quality statistics */
720         iwe.cmd = IWEVQUAL;
721         iwe.u.qual.updated = IW_QUAL_QUAL_UPDATED | IW_QUAL_LEVEL_UPDATED | IW_QUAL_NOISE_INVALID
722         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
723                 | IW_QUAL_DBM
724         #endif
725         ;
726
727         if ( check_fwstate(pmlmepriv, _FW_LINKED)== _TRUE &&
728                 is_same_network(&pmlmepriv->cur_network.network, &pnetwork->network, 0)){
729                 ss = padapter->recvpriv.signal_strength;
730                 sq = padapter->recvpriv.signal_qual;
731         } else {
732                 ss = pnetwork->network.PhyInfo.SignalStrength;
733                 sq = pnetwork->network.PhyInfo.SignalQuality;
734         }
735         
736         
737         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
738         iwe.u.qual.level = (u8) translate_percentage_to_dbm(ss);//dbm
739         #else
740         iwe.u.qual.level = (u8)ss;//%
741         #endif
742         
743         iwe.u.qual.qual = (u8)sq;   // signal quality
744
745         #ifdef CONFIG_PLATFORM_ROCKCHIPS
746         iwe.u.qual.noise = -100; // noise level suggest by zhf@rockchips
747         #else 
748         iwe.u.qual.noise = 0; // noise level
749         #endif //CONFIG_PLATFORM_ROCKCHIPS
750         
751         //DBG_871X("iqual=%d, ilevel=%d, inoise=%d, iupdated=%d\n", iwe.u.qual.qual, iwe.u.qual.level , iwe.u.qual.noise, iwe.u.qual.updated);
752
753         start = iwe_stream_add_event(info, start, stop, &iwe, IW_EV_QUAL_LEN);
754 }
755
756         {
757                 u8 buf[MAX_WPA_IE_LEN];
758                 u8 * p,*pos;
759                 int len;
760                 p = buf;
761                 pos = pnetwork->network.Reserved;
762                 _rtw_memset(buf, 0, MAX_WPA_IE_LEN);
763                 p += sprintf(p, "fm=%02X%02X", pos[1], pos[0]);
764                 _rtw_memset(&iwe, 0, sizeof(iwe));
765                 iwe.cmd = IWEVCUSTOM;
766                 iwe.u.data.length = strlen(buf);
767                 start = iwe_stream_add_point(info, start, stop, &iwe, buf);
768         }
769         
770         return start;   
771 }
772
773 static int wpa_set_auth_algs(struct net_device *dev, u32 value)
774 {       
775         _adapter *padapter = (_adapter *) rtw_netdev_priv(dev);
776         int ret = 0;
777
778         if ((value & AUTH_ALG_SHARED_KEY)&&(value & AUTH_ALG_OPEN_SYSTEM))
779         {
780                 DBG_871X("wpa_set_auth_algs, AUTH_ALG_SHARED_KEY and  AUTH_ALG_OPEN_SYSTEM [value:0x%x]\n",value);
781                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
782                 padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
783                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
784         } 
785         else if (value & AUTH_ALG_SHARED_KEY)
786         {
787                 DBG_871X("wpa_set_auth_algs, AUTH_ALG_SHARED_KEY  [value:0x%x]\n",value);
788                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
789
790 #ifdef CONFIG_PLATFORM_MT53XX
791                 padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
792                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
793 #else
794                 padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeShared;
795                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Shared;
796 #endif
797         } 
798         else if(value & AUTH_ALG_OPEN_SYSTEM)
799         {
800                 DBG_871X("wpa_set_auth_algs, AUTH_ALG_OPEN_SYSTEM\n");
801                 //padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
802                 if(padapter->securitypriv.ndisauthtype < Ndis802_11AuthModeWPAPSK)
803                 {
804 #ifdef CONFIG_PLATFORM_MT53XX
805                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeAutoSwitch;
806                         padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
807 #else
808                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeOpen;
809                         padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
810 #endif
811                 }
812                 
813         }
814         else if(value & AUTH_ALG_LEAP)
815         {
816                 DBG_871X("wpa_set_auth_algs, AUTH_ALG_LEAP\n");
817         }
818         else
819         {
820                 DBG_871X("wpa_set_auth_algs, error!\n");
821                 ret = -EINVAL;
822         }
823
824         return ret;
825         
826 }
827
828 static int wpa_set_encryption(struct net_device *dev, struct ieee_param *param, u32 param_len)
829 {
830         int ret = 0;
831         u32 wep_key_idx, wep_key_len,wep_total_len;
832         NDIS_802_11_WEP  *pwep = NULL;  
833         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
834         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;               
835         struct security_priv *psecuritypriv = &padapter->securitypriv;
836 #ifdef CONFIG_P2P
837         struct wifidirect_info* pwdinfo = &padapter->wdinfo;
838 #endif //CONFIG_P2P
839
840 _func_enter_;
841
842         param->u.crypt.err = 0;
843         param->u.crypt.alg[IEEE_CRYPT_ALG_NAME_LEN - 1] = '\0';
844
845         if (param_len < (u32) ((u8 *) param->u.crypt.key - (u8 *) param) + param->u.crypt.key_len)
846         {
847                 ret =  -EINVAL;
848                 goto exit;
849         }
850
851         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
852             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
853             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
854         {
855
856                 if (param->u.crypt.idx >= WEP_KEYS
857 #ifdef CONFIG_IEEE80211W
858                         && param->u.crypt.idx > BIP_MAX_KEYID
859 #endif //CONFIG_IEEE80211W
860                         )
861                 {
862                         ret = -EINVAL;
863                         goto exit;
864                 }
865         } 
866         else 
867         {
868 #ifdef CONFIG_WAPI_SUPPORT
869                 if (strcmp(param->u.crypt.alg, "SMS4"))
870 #endif
871                 {
872                         ret = -EINVAL;
873                         goto exit;
874                 }
875         }
876
877         if (strcmp(param->u.crypt.alg, "WEP") == 0)
878         {
879                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("wpa_set_encryption, crypt.alg = WEP\n"));
880                 DBG_871X("wpa_set_encryption, crypt.alg = WEP\n");
881
882                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
883                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP40_;
884                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP40_;
885
886                 wep_key_idx = param->u.crypt.idx;
887                 wep_key_len = param->u.crypt.key_len;
888
889                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("(1)wep_key_idx=%d\n", wep_key_idx));
890                 DBG_871X("(1)wep_key_idx=%d\n", wep_key_idx);
891
892                 if (wep_key_idx > WEP_KEYS)
893                         return -EINVAL;
894
895                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("(2)wep_key_idx=%d\n", wep_key_idx));
896
897                 if (wep_key_len > 0) 
898                 {
899                         wep_key_len = wep_key_len <= 5 ? 5 : 13;
900                         wep_total_len = wep_key_len + FIELD_OFFSET(NDIS_802_11_WEP, KeyMaterial);
901                         pwep =(NDIS_802_11_WEP   *) rtw_malloc(wep_total_len);
902                         if(pwep == NULL){
903                                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,(" wpa_set_encryption: pwep allocate fail !!!\n"));
904                                 goto exit;
905                         }
906
907                         _rtw_memset(pwep, 0, wep_total_len);
908
909                         pwep->KeyLength = wep_key_len;
910                         pwep->Length = wep_total_len;
911
912                         if(wep_key_len==13)
913                         {
914                                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP104_;
915                                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP104_;
916                         }
917                 }
918                 else {          
919                         ret = -EINVAL;
920                         goto exit;
921                 }
922
923                 pwep->KeyIndex = wep_key_idx;
924                 pwep->KeyIndex |= 0x80000000;
925
926                 _rtw_memcpy(pwep->KeyMaterial,  param->u.crypt.key, pwep->KeyLength);
927
928                 if(param->u.crypt.set_tx)
929                 {
930                         DBG_871X("wep, set_tx=1\n");
931
932                         if(rtw_set_802_11_add_wep(padapter, pwep) == (u8)_FAIL)
933                         {
934                                 ret = -EOPNOTSUPP ;
935                         }
936                 }
937                 else
938                 {
939                         DBG_871X("wep, set_tx=0\n");
940                         
941                         //don't update "psecuritypriv->dot11PrivacyAlgrthm" and 
942                         //"psecuritypriv->dot11PrivacyKeyIndex=keyid", but can rtw_set_key to fw/cam
943                         
944                         if (wep_key_idx >= WEP_KEYS) {
945                                 ret = -EOPNOTSUPP ;
946                                 goto exit;
947                         }                               
948                         
949                       _rtw_memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
950                         psecuritypriv->dot11DefKeylen[wep_key_idx]=pwep->KeyLength;     
951                         rtw_set_key(padapter, psecuritypriv, wep_key_idx, 0, _TRUE);
952                 }
953
954                 goto exit;              
955         }
956
957         if(padapter->securitypriv.dot11AuthAlgrthm == dot11AuthAlgrthm_8021X) // 802_1x
958         {
959                 struct sta_info * psta,*pbcmc_sta;
960                 struct sta_priv * pstapriv = &padapter->stapriv;
961
962                 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE | WIFI_MP_STATE) == _TRUE) //sta mode
963                 {
964                         psta = rtw_get_stainfo(pstapriv, get_bssid(pmlmepriv));                         
965                         if (psta == NULL) {
966                                 //DEBUG_ERR( ("Set wpa_set_encryption: Obtain Sta_info fail \n"));
967                         }
968                         else
969                         {
970                                 //Jeff: don't disable ieee8021x_blocked while clearing key
971                                 if (strcmp(param->u.crypt.alg, "none") != 0) 
972                                         psta->ieee8021x_blocked = _FALSE;
973                                 
974                                 if((padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption2Enabled)||
975                                                 (padapter->securitypriv.ndisencryptstatus ==  Ndis802_11Encryption3Enabled))
976                                 {
977                                         psta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
978                                 }               
979
980                                 if(param->u.crypt.set_tx ==1)//pairwise key
981                                 { 
982                                         _rtw_memcpy(psta->dot118021x_UncstKey.skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
983                                         
984                                         if(strcmp(param->u.crypt.alg, "TKIP") == 0)//set mic key
985                                         {                                               
986                                                 //DEBUG_ERR(("\nset key length :param->u.crypt.key_len=%d\n", param->u.crypt.key_len));
987                                                 _rtw_memcpy(psta->dot11tkiptxmickey.skey, &(param->u.crypt.key[16]), 8);
988                                                 _rtw_memcpy(psta->dot11tkiprxmickey.skey, &(param->u.crypt.key[24]), 8);
989
990                                                 padapter->securitypriv.busetkipkey=_FALSE;
991                                                 //_set_timer(&padapter->securitypriv.tkip_timer, 50);                                           
992                                         }
993
994                                         //DEBUG_ERR((" param->u.crypt.key_len=%d\n",param->u.crypt.key_len));
995                                         DBG_871X(" ~~~~set sta key:unicastkey\n");
996                                         
997                                         rtw_setstakey_cmd(padapter, psta, _TRUE, _TRUE);
998                                 }
999                                 else//group key
1000                                 {                                       
1001                                         if(strcmp(param->u.crypt.alg, "TKIP") == 0 || strcmp(param->u.crypt.alg, "CCMP") == 0)
1002                                         {
1003                                                 _rtw_memcpy(padapter->securitypriv.dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key,(param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
1004                                                 //only TKIP group key need to install this
1005                                                 if(param->u.crypt.key_len > 16)
1006                                                 {
1007                                                         _rtw_memcpy(padapter->securitypriv.dot118021XGrptxmickey[param->u.crypt.idx].skey,&(param->u.crypt.key[16]),8);
1008                                                         _rtw_memcpy(padapter->securitypriv.dot118021XGrprxmickey[param->u.crypt.idx].skey,&(param->u.crypt.key[24]),8);
1009                                                 }
1010                                                 padapter->securitypriv.binstallGrpkey = _TRUE;  
1011                                                 //DEBUG_ERR((" param->u.crypt.key_len=%d\n", param->u.crypt.key_len));
1012                                                 DBG_871X(" ~~~~set sta key:groupkey\n");
1013         
1014                                                 padapter->securitypriv.dot118021XGrpKeyid = param->u.crypt.idx;
1015         
1016                                                 rtw_set_key(padapter,&padapter->securitypriv,param->u.crypt.idx, 1, _TRUE);
1017                                         }
1018 #ifdef CONFIG_IEEE80211W
1019                                         else if(strcmp(param->u.crypt.alg, "BIP") == 0)
1020                                         {
1021                                                 int no;
1022                                                 //printk("BIP key_len=%d , index=%d @@@@@@@@@@@@@@@@@@\n", param->u.crypt.key_len, param->u.crypt.idx);
1023                                                 //save the IGTK key, length 16 bytes
1024                                                 _rtw_memcpy(padapter->securitypriv.dot11wBIPKey[param->u.crypt.idx].skey,  param->u.crypt.key,(param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
1025                                                 /*printk("IGTK key below:\n");
1026                                                 for(no=0;no<16;no++)
1027                                                         printk(" %02x ", padapter->securitypriv.dot11wBIPKey[param->u.crypt.idx].skey[no]);
1028                                                 printk("\n");*/
1029                                                 padapter->securitypriv.dot11wBIPKeyid = param->u.crypt.idx;
1030                                                 padapter->securitypriv.binstallBIPkey = _TRUE;
1031                                                 DBG_871X(" ~~~~set sta key:IGKT\n");
1032                                         }
1033 #endif //CONFIG_IEEE80211W
1034                                         
1035 #ifdef CONFIG_P2P
1036                                         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_PROVISIONING_ING))
1037                                         {
1038                                                 rtw_p2p_set_state(pwdinfo, P2P_STATE_PROVISIONING_DONE);
1039                                         }
1040 #endif //CONFIG_P2P
1041                                         
1042                                 }                                               
1043                         }
1044
1045                         pbcmc_sta=rtw_get_bcmc_stainfo(padapter);
1046                         if(pbcmc_sta==NULL)
1047                         {
1048                                 //DEBUG_ERR( ("Set OID_802_11_ADD_KEY: bcmc stainfo is null \n"));
1049                         }
1050                         else
1051                         {
1052                                 //Jeff: don't disable ieee8021x_blocked while clearing key
1053                                 if (strcmp(param->u.crypt.alg, "none") != 0) 
1054                                         pbcmc_sta->ieee8021x_blocked = _FALSE;
1055                                 
1056                                 if((padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption2Enabled)||
1057                                                 (padapter->securitypriv.ndisencryptstatus ==  Ndis802_11Encryption3Enabled))
1058                                 {                                                       
1059                                         pbcmc_sta->dot118021XPrivacy = padapter->securitypriv.dot11PrivacyAlgrthm;
1060                                 }                                       
1061                         }                               
1062                 }
1063                 else if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) //adhoc mode
1064                 {               
1065                 }                       
1066         }
1067
1068 #ifdef CONFIG_WAPI_SUPPORT
1069         if (strcmp(param->u.crypt.alg, "SMS4") == 0)
1070         {
1071                 PRT_WAPI_T                      pWapiInfo = &padapter->wapiInfo;
1072                 PRT_WAPI_STA_INFO       pWapiSta;
1073                 u8                                      WapiASUEPNInitialValueSrc[16] = {0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C} ;
1074                 u8                                      WapiAEPNInitialValueSrc[16] = {0x37,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C} ;
1075                 u8                                      WapiAEMultiCastPNInitialValueSrc[16] = {0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C,0x36,0x5C} ;
1076
1077                 if(param->u.crypt.set_tx == 1)
1078                 {
1079                         list_for_each_entry(pWapiSta, &pWapiInfo->wapiSTAUsedList, list) {
1080                                 if(_rtw_memcmp(pWapiSta->PeerMacAddr,param->sta_addr,6))
1081                                 {
1082                                         _rtw_memcpy(pWapiSta->lastTxUnicastPN,WapiASUEPNInitialValueSrc,16);
1083
1084                                         pWapiSta->wapiUsk.bSet = true;
1085                                         _rtw_memcpy(pWapiSta->wapiUsk.dataKey,param->u.crypt.key,16);
1086                                         _rtw_memcpy(pWapiSta->wapiUsk.micKey,param->u.crypt.key+16,16);
1087                                         pWapiSta->wapiUsk.keyId = param->u.crypt.idx ;
1088                                         pWapiSta->wapiUsk.bTxEnable = true;
1089
1090                                         _rtw_memcpy(pWapiSta->lastRxUnicastPNBEQueue,WapiAEPNInitialValueSrc,16);
1091                                         _rtw_memcpy(pWapiSta->lastRxUnicastPNBKQueue,WapiAEPNInitialValueSrc,16);
1092                                         _rtw_memcpy(pWapiSta->lastRxUnicastPNVIQueue,WapiAEPNInitialValueSrc,16);
1093                                         _rtw_memcpy(pWapiSta->lastRxUnicastPNVOQueue,WapiAEPNInitialValueSrc,16);
1094                                         _rtw_memcpy(pWapiSta->lastRxUnicastPN,WapiAEPNInitialValueSrc,16);
1095                                         pWapiSta->wapiUskUpdate.bTxEnable = false;
1096                                         pWapiSta->wapiUskUpdate.bSet = false;
1097
1098                                         if (psecuritypriv->sw_encrypt== false || psecuritypriv->sw_decrypt == false)
1099                                         {
1100                                                 //set unicast key for ASUE
1101                                                 rtw_wapi_set_key(padapter, &pWapiSta->wapiUsk, pWapiSta, false, false);
1102                                         }
1103                                 }
1104                         }
1105                 }
1106                 else
1107                 {
1108                         list_for_each_entry(pWapiSta, &pWapiInfo->wapiSTAUsedList, list) {
1109                                 if(_rtw_memcmp(pWapiSta->PeerMacAddr,get_bssid(pmlmepriv),6))
1110                                 {
1111                                         pWapiSta->wapiMsk.bSet = true;
1112                                         _rtw_memcpy(pWapiSta->wapiMsk.dataKey,param->u.crypt.key,16);
1113                                         _rtw_memcpy(pWapiSta->wapiMsk.micKey,param->u.crypt.key+16,16);
1114                                         pWapiSta->wapiMsk.keyId = param->u.crypt.idx ;
1115                                         pWapiSta->wapiMsk.bTxEnable = false;
1116                                         if(!pWapiSta->bSetkeyOk)
1117                                                 pWapiSta->bSetkeyOk = true;
1118                                         pWapiSta->bAuthenticateInProgress = false;
1119
1120                                         _rtw_memcpy(pWapiSta->lastRxMulticastPN, WapiAEMultiCastPNInitialValueSrc, 16);
1121
1122                                         if (psecuritypriv->sw_decrypt == false)
1123                                         {
1124                                                 //set rx broadcast key for ASUE
1125                                                 rtw_wapi_set_key(padapter, &pWapiSta->wapiMsk, pWapiSta, true, false);
1126                                         }
1127                                 }
1128
1129                         }
1130                 }
1131         }
1132 #endif
1133
1134 exit:
1135         
1136         if (pwep) {
1137                 rtw_mfree((u8 *)pwep, wep_total_len);           
1138         }       
1139         
1140 _func_exit_;
1141
1142         return ret;     
1143 }
1144
1145 static int rtw_set_wpa_ie(_adapter *padapter, char *pie, unsigned short ielen)
1146 {
1147         u8 *buf=NULL, *pos=NULL;        
1148         u32 left;       
1149         int group_cipher = 0, pairwise_cipher = 0;
1150         int ret = 0;
1151         u8 null_addr[]= {0,0,0,0,0,0};
1152 #ifdef CONFIG_P2P
1153         struct wifidirect_info* pwdinfo = &padapter->wdinfo;
1154 #endif //CONFIG_P2P
1155
1156         if((ielen > MAX_WPA_IE_LEN) || (pie == NULL)){
1157                 _clr_fwstate_(&padapter->mlmepriv, WIFI_UNDER_WPS);
1158                 if(pie == NULL) 
1159                         return ret;
1160                 else
1161                         return -EINVAL;
1162         }
1163
1164         if(ielen)
1165         {               
1166                 buf = rtw_zmalloc(ielen);
1167                 if (buf == NULL){
1168                         ret =  -ENOMEM;
1169                         goto exit;
1170                 }
1171         
1172                 _rtw_memcpy(buf, pie , ielen);
1173
1174                 //dump
1175                 {
1176                         int i;
1177                         DBG_871X("\n wpa_ie(length:%d):\n", ielen);
1178                         for(i=0;i<ielen;i=i+8)
1179                                 DBG_871X("0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x \n",buf[i],buf[i+1],buf[i+2],buf[i+3],buf[i+4],buf[i+5],buf[i+6],buf[i+7]);
1180                 }
1181         
1182                 pos = buf;
1183                 if(ielen < RSN_HEADER_LEN){
1184                         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("Ie len too short %d\n", ielen));
1185                         ret  = -1;
1186                         goto exit;
1187                 }
1188
1189 #if 0
1190                 pos += RSN_HEADER_LEN;
1191                 left  = ielen - RSN_HEADER_LEN;
1192                 
1193                 if (left >= RSN_SELECTOR_LEN){
1194                         pos += RSN_SELECTOR_LEN;
1195                         left -= RSN_SELECTOR_LEN;
1196                 }               
1197                 else if (left > 0){
1198                         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("Ie length mismatch, %u too much \n", left));
1199                         ret =-1;
1200                         goto exit;
1201                 }
1202 #endif          
1203                 
1204                 if(rtw_parse_wpa_ie(buf, ielen, &group_cipher, &pairwise_cipher, NULL) == _SUCCESS)
1205                 {
1206                         padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_8021X;
1207                         padapter->securitypriv.ndisauthtype=Ndis802_11AuthModeWPAPSK;
1208                         _rtw_memcpy(padapter->securitypriv.supplicant_ie, &buf[0], ielen);      
1209                 }
1210         
1211                 if(rtw_parse_wpa2_ie(buf, ielen, &group_cipher, &pairwise_cipher, NULL) == _SUCCESS)
1212                 {
1213                         padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_8021X;
1214                         padapter->securitypriv.ndisauthtype=Ndis802_11AuthModeWPA2PSK;  
1215                         _rtw_memcpy(padapter->securitypriv.supplicant_ie, &buf[0], ielen);      
1216                 }
1217                         
1218                 if (group_cipher == 0)
1219                 {
1220                         group_cipher = WPA_CIPHER_NONE;
1221                 }
1222                 if (pairwise_cipher == 0)
1223                 {
1224                         pairwise_cipher = WPA_CIPHER_NONE;
1225                 }
1226                         
1227                 switch(group_cipher)
1228                 {
1229                         case WPA_CIPHER_NONE:
1230                                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
1231                                 padapter->securitypriv.ndisencryptstatus=Ndis802_11EncryptionDisabled;
1232                                 break;
1233                         case WPA_CIPHER_WEP40:
1234                                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP40_;
1235                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1236                                 break;
1237                         case WPA_CIPHER_TKIP:
1238                                 padapter->securitypriv.dot118021XGrpPrivacy=_TKIP_;
1239                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
1240                                 break;
1241                         case WPA_CIPHER_CCMP:
1242                                 padapter->securitypriv.dot118021XGrpPrivacy=_AES_;
1243                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
1244                                 break;
1245                         case WPA_CIPHER_WEP104: 
1246                                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP104_;
1247                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1248                                 break;
1249                 }
1250
1251                 switch(pairwise_cipher)
1252                 {
1253                         case WPA_CIPHER_NONE:
1254                                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
1255                                 padapter->securitypriv.ndisencryptstatus=Ndis802_11EncryptionDisabled;
1256                                 break;
1257                         case WPA_CIPHER_WEP40:
1258                                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP40_;
1259                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1260                                 break;
1261                         case WPA_CIPHER_TKIP:
1262                                 padapter->securitypriv.dot11PrivacyAlgrthm=_TKIP_;
1263                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
1264                                 break;
1265                         case WPA_CIPHER_CCMP:
1266                                 padapter->securitypriv.dot11PrivacyAlgrthm=_AES_;
1267                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
1268                                 break;
1269                         case WPA_CIPHER_WEP104: 
1270                                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP104_;
1271                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
1272                                 break;
1273                 }
1274                 
1275                 _clr_fwstate_(&padapter->mlmepriv, WIFI_UNDER_WPS);
1276                 {//set wps_ie   
1277                         u16 cnt = 0;    
1278                         u8 eid, wps_oui[4]={0x0,0x50,0xf2,0x04};
1279                          
1280                         while( cnt < ielen )
1281                         {
1282                                 eid = buf[cnt];
1283                 
1284                                 if((eid==_VENDOR_SPECIFIC_IE_)&&(_rtw_memcmp(&buf[cnt+2], wps_oui, 4)==_TRUE))
1285                                 {
1286                                         DBG_871X("SET WPS_IE\n");
1287
1288                                         padapter->securitypriv.wps_ie_len = ((buf[cnt+1]+2) < MAX_WPS_IE_LEN) ? (buf[cnt+1]+2):MAX_WPS_IE_LEN;
1289
1290                                         _rtw_memcpy(padapter->securitypriv.wps_ie, &buf[cnt], padapter->securitypriv.wps_ie_len);
1291                                         
1292                                         set_fwstate(&padapter->mlmepriv, WIFI_UNDER_WPS);
1293                                         
1294 #ifdef CONFIG_P2P
1295                                         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_GONEGO_OK))
1296                                         {
1297                                                 rtw_p2p_set_state(pwdinfo, P2P_STATE_PROVISIONING_ING);
1298                                         }
1299 #endif //CONFIG_P2P
1300                                         cnt += buf[cnt+1]+2;
1301                                         
1302                                         break;
1303                                 } else {
1304                                         cnt += buf[cnt+1]+2; //goto next        
1305                                 }                               
1306                         }                       
1307                 }               
1308         }
1309         
1310         //TKIP and AES disallow multicast packets until installing group key
1311         if(padapter->securitypriv.dot11PrivacyAlgrthm == _TKIP_
1312                 || padapter->securitypriv.dot11PrivacyAlgrthm == _TKIP_WTMIC_
1313                 || padapter->securitypriv.dot11PrivacyAlgrthm == _AES_)
1314                 //WPS open need to enable multicast
1315                 //|| check_fwstate(&padapter->mlmepriv, WIFI_UNDER_WPS) == _TRUE)
1316                 rtw_hal_set_hwreg(padapter, HW_VAR_OFF_RCR_AM, null_addr);
1317         
1318         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
1319                  ("rtw_set_wpa_ie: pairwise_cipher=0x%08x padapter->securitypriv.ndisencryptstatus=%d padapter->securitypriv.ndisauthtype=%d\n",
1320                   pairwise_cipher, padapter->securitypriv.ndisencryptstatus, padapter->securitypriv.ndisauthtype));
1321         
1322 exit:
1323
1324         if (buf) rtw_mfree(buf, ielen);
1325
1326         return ret;
1327 }
1328
1329 static int rtw_wx_get_name(struct net_device *dev, 
1330                              struct iw_request_info *info, 
1331                              union iwreq_data *wrqu, char *extra)
1332 {
1333         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1334         u16 cap;
1335         u32 ht_ielen = 0;
1336         char *p;
1337         u8 ht_cap=_FALSE, vht_cap=_FALSE;
1338         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
1339         WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
1340         NDIS_802_11_RATES_EX* prates = NULL;
1341
1342         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("cmd_code=%x\n", info->cmd));
1343
1344         _func_enter_;   
1345
1346         if (check_fwstate(pmlmepriv, _FW_LINKED|WIFI_ADHOC_MASTER_STATE) == _TRUE)
1347         {
1348                 //parsing HT_CAP_IE
1349                 p = rtw_get_ie(&pcur_bss->IEs[12], _HT_CAPABILITY_IE_, &ht_ielen, pcur_bss->IELength-12);
1350                 if(p && ht_ielen>0)
1351                 {
1352                         ht_cap = _TRUE;
1353                 }
1354
1355 #ifdef CONFIG_80211AC_VHT
1356                 if(pmlmepriv->vhtpriv.vht_option == _TRUE)
1357                         vht_cap = _TRUE;
1358 #endif
1359
1360                 prates = &pcur_bss->SupportedRates;
1361
1362                 if (rtw_is_cckratesonly_included((u8*)prates) == _TRUE)
1363                 {
1364                         if(ht_cap == _TRUE)
1365                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bn");
1366                         else
1367                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11b");
1368                 }
1369                 else if ((rtw_is_cckrates_included((u8*)prates)) == _TRUE)
1370                 {
1371                         if(ht_cap == _TRUE)
1372                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bgn");
1373                         else
1374                                 snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11bg");
1375                 }
1376                 else
1377                 {
1378                         if(pcur_bss->Configuration.DSConfig > 14)
1379                         {
1380                                 if(vht_cap == _TRUE)
1381                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11AC");
1382                                 else if(ht_cap == _TRUE)
1383                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11an");
1384                                 else
1385                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11a");
1386                         }
1387                         else
1388                         {
1389                                 if(ht_cap == _TRUE)
1390                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11gn");
1391                                 else
1392                                         snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11g");
1393                         }
1394                 }
1395         }
1396         else
1397         {
1398                 //prates = &padapter->registrypriv.dev_network.SupportedRates;
1399                 //snprintf(wrqu->name, IFNAMSIZ, "IEEE 802.11g");
1400                 snprintf(wrqu->name, IFNAMSIZ, "unassociated");
1401         }
1402
1403         _func_exit_;
1404
1405         return 0;
1406 }
1407
1408 static int rtw_wx_set_freq(struct net_device *dev, 
1409                              struct iw_request_info *info, 
1410                              union iwreq_data *wrqu, char *extra)
1411 {       
1412         _func_enter_;
1413
1414         RT_TRACE(_module_rtl871x_mlme_c_, _drv_notice_, ("+rtw_wx_set_freq\n"));
1415
1416         _func_exit_;
1417         
1418         return 0;
1419 }
1420
1421 static int rtw_wx_get_freq(struct net_device *dev, 
1422                              struct iw_request_info *info, 
1423                              union iwreq_data *wrqu, char *extra)
1424 {
1425         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1426         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
1427         WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
1428         
1429         if(check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE)
1430         {
1431                 //wrqu->freq.m = ieee80211_wlan_frequencies[pcur_bss->Configuration.DSConfig-1] * 100000;
1432                 wrqu->freq.m = rtw_ch2freq(pcur_bss->Configuration.DSConfig) * 100000;
1433                 wrqu->freq.e = 1;
1434                 wrqu->freq.i = pcur_bss->Configuration.DSConfig;
1435
1436         }
1437         else{
1438                 wrqu->freq.m = rtw_ch2freq(padapter->mlmeextpriv.cur_channel) * 100000;
1439                 wrqu->freq.e = 1;
1440                 wrqu->freq.i = padapter->mlmeextpriv.cur_channel;
1441         }
1442
1443         return 0;
1444 }
1445
1446 static int rtw_wx_set_mode(struct net_device *dev, struct iw_request_info *a,
1447                              union iwreq_data *wrqu, char *b)
1448 {
1449         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1450         NDIS_802_11_NETWORK_INFRASTRUCTURE networkType ;
1451         int ret = 0;
1452         
1453         _func_enter_;
1454         
1455         if(_FAIL == rtw_pwr_wakeup(padapter)) {
1456                 ret= -EPERM;
1457                 goto exit;
1458         }
1459
1460         if (padapter->hw_init_completed==_FALSE){
1461                 ret = -EPERM;
1462                 goto exit;
1463         }
1464         
1465         switch(wrqu->mode)
1466         {
1467                 case IW_MODE_AUTO:
1468                         networkType = Ndis802_11AutoUnknown;
1469                         DBG_871X("set_mode = IW_MODE_AUTO\n");  
1470                         break;                          
1471                 case IW_MODE_ADHOC:             
1472                         networkType = Ndis802_11IBSS;
1473                         DBG_871X("set_mode = IW_MODE_ADHOC\n");                 
1474                         break;
1475                 case IW_MODE_MASTER:            
1476                         networkType = Ndis802_11APMode;
1477                         DBG_871X("set_mode = IW_MODE_MASTER\n");
1478                         //rtw_setopmode_cmd(padapter, networkType,_TRUE);       
1479                         break;                          
1480                 case IW_MODE_INFRA:
1481                         networkType = Ndis802_11Infrastructure;
1482                         DBG_871X("set_mode = IW_MODE_INFRA\n");                 
1483                         break;
1484         
1485                 default :
1486                         ret = -EINVAL;;
1487                         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("\n Mode: %s is not supported  \n", iw_operation_mode[wrqu->mode]));
1488                         goto exit;
1489         }
1490         
1491 /*      
1492         if(Ndis802_11APMode == networkType)
1493         {
1494                 rtw_setopmode_cmd(padapter, networkType,_TRUE);
1495         }       
1496         else
1497         {
1498                 rtw_setopmode_cmd(padapter, Ndis802_11AutoUnknown,_TRUE);       
1499         }
1500 */
1501         
1502         if (rtw_set_802_11_infrastructure_mode(padapter, networkType) ==_FALSE){
1503
1504                 ret = -EPERM;
1505                 goto exit;
1506
1507         }
1508
1509         rtw_setopmode_cmd(padapter, networkType,_TRUE);
1510
1511 exit:
1512         
1513         _func_exit_;
1514         
1515         return ret;
1516         
1517 }
1518
1519 static int rtw_wx_get_mode(struct net_device *dev, struct iw_request_info *a,
1520                              union iwreq_data *wrqu, char *b)
1521 {
1522         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1523         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
1524         
1525         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,(" rtw_wx_get_mode \n"));
1526
1527         _func_enter_;
1528         
1529         if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) == _TRUE)
1530         {
1531                 wrqu->mode = IW_MODE_INFRA;
1532         }
1533         else if  ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == _TRUE) ||
1534                        (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE))
1535                 
1536         {
1537                 wrqu->mode = IW_MODE_ADHOC;
1538         }
1539         else if(check_fwstate(pmlmepriv, WIFI_AP_STATE) == _TRUE)
1540         {
1541                 wrqu->mode = IW_MODE_MASTER;
1542         }
1543         else
1544         {
1545                 wrqu->mode = IW_MODE_AUTO;
1546         }
1547
1548         _func_exit_;
1549         
1550         return 0;
1551         
1552 }
1553
1554
1555 static int rtw_wx_set_pmkid(struct net_device *dev,
1556                              struct iw_request_info *a,
1557                              union iwreq_data *wrqu, char *extra)
1558 {
1559         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1560         u8          j,blInserted = _FALSE;
1561         int         intReturn = _FALSE;
1562         struct mlme_priv  *pmlmepriv = &padapter->mlmepriv;
1563         struct security_priv *psecuritypriv = &padapter->securitypriv;
1564         struct iw_pmksa*  pPMK = ( struct iw_pmksa* ) extra;
1565         u8     strZeroMacAddress[ ETH_ALEN ] = { 0x00 };
1566         u8     strIssueBssid[ ETH_ALEN ] = { 0x00 };
1567         
1568 /*
1569         struct iw_pmksa
1570         {
1571             __u32   cmd;
1572             struct sockaddr bssid;
1573             __u8    pmkid[IW_PMKID_LEN];   //IW_PMKID_LEN=16
1574         }
1575         There are the BSSID information in the bssid.sa_data array.
1576         If cmd is IW_PMKSA_FLUSH, it means the wpa_suppplicant wants to clear all the PMKID information.
1577         If cmd is IW_PMKSA_ADD, it means the wpa_supplicant wants to add a PMKID/BSSID to driver.
1578         If cmd is IW_PMKSA_REMOVE, it means the wpa_supplicant wants to remove a PMKID/BSSID from driver.
1579         */
1580
1581         _rtw_memcpy( strIssueBssid, pPMK->bssid.sa_data, ETH_ALEN);
1582         if ( pPMK->cmd == IW_PMKSA_ADD )
1583         {
1584                 DBG_871X( "[rtw_wx_set_pmkid] IW_PMKSA_ADD!\n" );
1585                 if ( _rtw_memcmp( strIssueBssid, strZeroMacAddress, ETH_ALEN ) == _TRUE )
1586                 {
1587                     return( intReturn );
1588                 }
1589                 else
1590                 {
1591                     intReturn = _TRUE;
1592                 }
1593                 blInserted = _FALSE;
1594                 
1595                 //overwrite PMKID
1596                 for(j=0 ; j<NUM_PMKID_CACHE; j++)
1597                 {
1598                         if( _rtw_memcmp( psecuritypriv->PMKIDList[j].Bssid, strIssueBssid, ETH_ALEN) ==_TRUE )
1599                         { // BSSID is matched, the same AP => rewrite with new PMKID.
1600                                 
1601                                 DBG_871X( "[rtw_wx_set_pmkid] BSSID exists in the PMKList.\n" );
1602
1603                                 _rtw_memcpy( psecuritypriv->PMKIDList[j].PMKID, pPMK->pmkid, IW_PMKID_LEN);
1604                                 psecuritypriv->PMKIDList[ j ].bUsed = _TRUE;
1605                                 psecuritypriv->PMKIDIndex = j+1;
1606                                 blInserted = _TRUE;
1607                                 break;
1608                         }       
1609                 }
1610
1611                 if(!blInserted)
1612                 {
1613                     // Find a new entry
1614                     DBG_871X( "[rtw_wx_set_pmkid] Use the new entry index = %d for this PMKID.\n",
1615                             psecuritypriv->PMKIDIndex );
1616
1617                     _rtw_memcpy(psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].Bssid, strIssueBssid, ETH_ALEN);
1618                     _rtw_memcpy(psecuritypriv->PMKIDList[psecuritypriv->PMKIDIndex].PMKID, pPMK->pmkid, IW_PMKID_LEN);
1619
1620                     psecuritypriv->PMKIDList[ psecuritypriv->PMKIDIndex ].bUsed = _TRUE;
1621                     psecuritypriv->PMKIDIndex++ ;
1622                     if(psecuritypriv->PMKIDIndex==16)
1623                     {
1624                         psecuritypriv->PMKIDIndex =0;
1625                     }
1626                 }
1627         }
1628         else if ( pPMK->cmd == IW_PMKSA_REMOVE )
1629         {
1630                 DBG_871X( "[rtw_wx_set_pmkid] IW_PMKSA_REMOVE!\n" );
1631                 intReturn = _TRUE;
1632                 for(j=0 ; j<NUM_PMKID_CACHE; j++)
1633                 {
1634                         if( _rtw_memcmp( psecuritypriv->PMKIDList[j].Bssid, strIssueBssid, ETH_ALEN) ==_TRUE )
1635                         { // BSSID is matched, the same AP => Remove this PMKID information and reset it. 
1636                                 _rtw_memset( psecuritypriv->PMKIDList[ j ].Bssid, 0x00, ETH_ALEN );
1637                                 psecuritypriv->PMKIDList[ j ].bUsed = _FALSE;
1638                                 break;
1639                         }       
1640                 }
1641         }
1642         else if ( pPMK->cmd == IW_PMKSA_FLUSH ) 
1643         {
1644             DBG_871X( "[rtw_wx_set_pmkid] IW_PMKSA_FLUSH!\n" );
1645             _rtw_memset( &psecuritypriv->PMKIDList[ 0 ], 0x00, sizeof( RT_PMKID_LIST ) * NUM_PMKID_CACHE );
1646             psecuritypriv->PMKIDIndex = 0;
1647             intReturn = _TRUE;
1648         }
1649     return( intReturn );
1650 }
1651
1652 static int rtw_wx_get_sens(struct net_device *dev, 
1653                              struct iw_request_info *info, 
1654                              union iwreq_data *wrqu, char *extra)
1655 {
1656         #ifdef CONFIG_PLATFORM_ROCKCHIPS
1657         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1658         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv); 
1659         
1660         /*
1661         *  20110311 Commented by Jeff
1662         *  For rockchip platform's wpa_driver_wext_get_rssi
1663         */
1664         if(check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE) {
1665                 //wrqu->sens.value=-padapter->recvpriv.signal_strength;
1666                 wrqu->sens.value=-padapter->recvpriv.rssi;
1667                 //DBG_871X("%s: %d\n", __FUNCTION__, wrqu->sens.value);
1668                 wrqu->sens.fixed = 0; /* no auto select */ 
1669         } else 
1670         #endif
1671         {
1672                 wrqu->sens.value = 0;
1673                 wrqu->sens.fixed = 0;   /* no auto select */
1674                 wrqu->sens.disabled = 1;
1675         }
1676         return 0;
1677 }
1678
1679 static int rtw_wx_get_range(struct net_device *dev, 
1680                                 struct iw_request_info *info, 
1681                                 union iwreq_data *wrqu, char *extra)
1682 {
1683         struct iw_range *range = (struct iw_range *)extra;
1684         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1685         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
1686
1687         u16 val;
1688         int i;
1689         
1690         _func_enter_;
1691         
1692         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_range. cmd_code=%x\n", info->cmd));
1693
1694         wrqu->data.length = sizeof(*range);
1695         _rtw_memset(range, 0, sizeof(*range));
1696
1697         /* Let's try to keep this struct in the same order as in
1698          * linux/include/wireless.h
1699          */
1700
1701         /* TODO: See what values we can set, and remove the ones we can't
1702          * set, or fill them with some default data.
1703          */
1704
1705         /* ~5 Mb/s real (802.11b) */
1706         range->throughput = 5 * 1000 * 1000;     
1707
1708         // TODO: Not used in 802.11b?
1709 //      range->min_nwid;        /* Minimal NWID we are able to set */
1710         // TODO: Not used in 802.11b?
1711 //      range->max_nwid;        /* Maximal NWID we are able to set */
1712
1713         /* Old Frequency (backward compat - moved lower ) */
1714 //      range->old_num_channels; 
1715 //      range->old_num_frequency;
1716 //      range->old_freq[6]; /* Filler to keep "version" at the same offset */
1717
1718         /* signal level threshold range */
1719
1720         //percent values between 0 and 100.
1721         range->max_qual.qual = 100;     
1722         range->max_qual.level = 100;
1723         range->max_qual.noise = 100;
1724         range->max_qual.updated = 7; /* Updated all three */
1725
1726
1727         range->avg_qual.qual = 92; /* > 8% missed beacons is 'bad' */
1728         /* TODO: Find real 'good' to 'bad' threshol value for RSSI */
1729         range->avg_qual.level = 20 + -98;
1730         range->avg_qual.noise = 0;
1731         range->avg_qual.updated = 7; /* Updated all three */
1732
1733         range->num_bitrates = RATE_COUNT;
1734
1735         for (i = 0; i < RATE_COUNT && i < IW_MAX_BITRATES; i++) {
1736                 range->bitrate[i] = rtw_rates[i];
1737         }
1738
1739         range->min_frag = MIN_FRAG_THRESHOLD;
1740         range->max_frag = MAX_FRAG_THRESHOLD;
1741
1742         range->pm_capa = 0;
1743
1744         range->we_version_compiled = WIRELESS_EXT;
1745         range->we_version_source = 16;
1746
1747 //      range->retry_capa;      /* What retry options are supported */
1748 //      range->retry_flags;     /* How to decode max/min retry limit */
1749 //      range->r_time_flags;    /* How to decode max/min retry life */
1750 //      range->min_retry;       /* Minimal number of retries */
1751 //      range->max_retry;       /* Maximal number of retries */
1752 //      range->min_r_time;      /* Minimal retry lifetime */
1753 //      range->max_r_time;      /* Maximal retry lifetime */
1754
1755         for (i = 0, val = 0; i < MAX_CHANNEL_NUM; i++) {
1756
1757                 // Include only legal frequencies for some countries
1758                 if(pmlmeext->channel_set[i].ChannelNum != 0)
1759                 {
1760                         range->freq[val].i = pmlmeext->channel_set[i].ChannelNum;
1761                         range->freq[val].m = rtw_ch2freq(pmlmeext->channel_set[i].ChannelNum) * 100000;
1762                         range->freq[val].e = 1;
1763                         val++;
1764                 }
1765
1766                 if (val == IW_MAX_FREQUENCIES)
1767                         break;
1768         }
1769
1770         range->num_channels = val;
1771         range->num_frequency = val;
1772
1773 // Commented by Albert 2009/10/13
1774 // The following code will proivde the security capability to network manager.
1775 // If the driver doesn't provide this capability to network manager,
1776 // the WPA/WPA2 routers can't be choosen in the network manager.
1777
1778 /*
1779 #define IW_SCAN_CAPA_NONE               0x00
1780 #define IW_SCAN_CAPA_ESSID              0x01
1781 #define IW_SCAN_CAPA_BSSID              0x02
1782 #define IW_SCAN_CAPA_CHANNEL    0x04
1783 #define IW_SCAN_CAPA_MODE               0x08
1784 #define IW_SCAN_CAPA_RATE               0x10
1785 #define IW_SCAN_CAPA_TYPE               0x20
1786 #define IW_SCAN_CAPA_TIME               0x40
1787 */
1788
1789 #if WIRELESS_EXT > 17
1790         range->enc_capa = IW_ENC_CAPA_WPA|IW_ENC_CAPA_WPA2|
1791                           IW_ENC_CAPA_CIPHER_TKIP|IW_ENC_CAPA_CIPHER_CCMP;
1792 #endif
1793
1794 #ifdef IW_SCAN_CAPA_ESSID //WIRELESS_EXT > 21
1795         range->scan_capa = IW_SCAN_CAPA_ESSID | IW_SCAN_CAPA_TYPE |IW_SCAN_CAPA_BSSID|
1796                                         IW_SCAN_CAPA_CHANNEL|IW_SCAN_CAPA_MODE|IW_SCAN_CAPA_RATE;
1797 #endif
1798
1799
1800         _func_exit_;
1801
1802         return 0;
1803
1804 }
1805
1806 //set bssid flow
1807 //s1. rtw_set_802_11_infrastructure_mode()
1808 //s2. rtw_set_802_11_authentication_mode()
1809 //s3. set_802_11_encryption_mode()
1810 //s4. rtw_set_802_11_bssid()
1811 static int rtw_wx_set_wap(struct net_device *dev,
1812                          struct iw_request_info *info,
1813                          union iwreq_data *awrq,
1814                          char *extra)
1815 {
1816         _irqL   irqL;
1817         uint ret = 0;
1818         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1819         struct sockaddr *temp = (struct sockaddr *)awrq;
1820         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
1821         _list   *phead;
1822         u8 *dst_bssid, *src_bssid;
1823         _queue  *queue  = &(pmlmepriv->scanned_queue);
1824         struct  wlan_network    *pnetwork = NULL;
1825         NDIS_802_11_AUTHENTICATION_MODE authmode;
1826
1827         _func_enter_;
1828 /*
1829 #ifdef CONFIG_CONCURRENT_MODE
1830         if(padapter->iface_type > PRIMARY_IFACE)
1831         {
1832                 ret = -EINVAL;
1833                 goto exit;
1834         }
1835 #endif  
1836 */      
1837
1838 #ifdef CONFIG_CONCURRENT_MODE
1839         if (check_buddy_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE)
1840         {
1841                 DBG_871X("set bssid, but buddy_intf is under scanning or linking\n");
1842
1843                 ret = -EINVAL;
1844
1845                 goto exit;
1846         }
1847 #endif
1848
1849 #ifdef CONFIG_DUALMAC_CONCURRENT
1850         if (dc_check_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING)== _TRUE)
1851         {
1852                 DBG_871X("set bssid, but buddy_intf is under scanning or linking\n");
1853                 ret = -EINVAL;
1854                 goto exit;
1855         }
1856 #endif
1857
1858         rtw_ps_deny(padapter, PS_DENY_JOIN);
1859         if(_FAIL == rtw_pwr_wakeup(padapter))
1860         {
1861                 ret= -1;
1862                 goto exit;
1863         }
1864         
1865         if(!padapter->bup){
1866                 ret = -1;
1867                 goto exit;
1868         }
1869
1870         
1871         if (temp->sa_family != ARPHRD_ETHER){
1872                 ret = -EINVAL;
1873                 goto exit;
1874         }
1875
1876         authmode = padapter->securitypriv.ndisauthtype;
1877         _enter_critical_bh(&queue->lock, &irqL);
1878        phead = get_list_head(queue);
1879        pmlmepriv->pscanned = get_next(phead);
1880
1881         while (1)
1882          {
1883                         
1884                 if ((rtw_end_of_queue_search(phead, pmlmepriv->pscanned)) == _TRUE)
1885                 {
1886 #if 0           
1887                         ret = -EINVAL;
1888                         goto exit;
1889
1890                         if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE)
1891                         {
1892                                 rtw_set_802_11_bssid(padapter, temp->sa_data);
1893                                 goto exit;                    
1894                         }
1895                         else
1896                         {
1897                                 ret = -EINVAL;
1898                                 goto exit;
1899                         }
1900 #endif
1901
1902                         break;
1903                 }
1904         
1905                 pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
1906
1907                 pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
1908
1909                 dst_bssid = pnetwork->network.MacAddress;
1910
1911                 src_bssid = temp->sa_data;
1912
1913                 if ((_rtw_memcmp(dst_bssid, src_bssid, ETH_ALEN)) == _TRUE)
1914                 {                       
1915                         if(!rtw_set_802_11_infrastructure_mode(padapter, pnetwork->network.InfrastructureMode))
1916                         {
1917                                 ret = -1;
1918                                 _exit_critical_bh(&queue->lock, &irqL);
1919                                 goto exit;
1920                         }
1921
1922                                 break;                  
1923                 }
1924
1925         }               
1926         _exit_critical_bh(&queue->lock, &irqL);
1927         
1928         rtw_set_802_11_authentication_mode(padapter, authmode);
1929         //set_802_11_encryption_mode(padapter, padapter->securitypriv.ndisencryptstatus);
1930         if (rtw_set_802_11_bssid(padapter, temp->sa_data) == _FALSE) {
1931                 ret = -1;
1932                 goto exit;              
1933         }       
1934         
1935 exit:
1936         
1937         rtw_ps_deny_cancel(padapter, PS_DENY_JOIN);
1938
1939         _func_exit_;
1940         
1941         return ret;     
1942 }
1943
1944 static int rtw_wx_get_wap(struct net_device *dev, 
1945                             struct iw_request_info *info, 
1946                             union iwreq_data *wrqu, char *extra)
1947 {
1948
1949         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
1950         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
1951         WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;     
1952         
1953         wrqu->ap_addr.sa_family = ARPHRD_ETHER;
1954         
1955         _rtw_memset(wrqu->ap_addr.sa_data, 0, ETH_ALEN);
1956         
1957         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_wap\n"));
1958
1959         _func_enter_;
1960
1961         if  ( ((check_fwstate(pmlmepriv, _FW_LINKED)) == _TRUE) || 
1962                         ((check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) == _TRUE) ||
1963                         ((check_fwstate(pmlmepriv, WIFI_AP_STATE)) == _TRUE) )
1964         {
1965
1966                 _rtw_memcpy(wrqu->ap_addr.sa_data, pcur_bss->MacAddress, ETH_ALEN);
1967         }
1968         else
1969         {
1970                 _rtw_memset(wrqu->ap_addr.sa_data, 0, ETH_ALEN);
1971         }               
1972
1973         _func_exit_;
1974         
1975         return 0;
1976         
1977 }
1978
1979 static int rtw_wx_set_mlme(struct net_device *dev, 
1980                              struct iw_request_info *info, 
1981                              union iwreq_data *wrqu, char *extra)
1982 {
1983 #if 0
1984 /* SIOCSIWMLME data */
1985 struct  iw_mlme
1986 {
1987         __u16           cmd; /* IW_MLME_* */
1988         __u16           reason_code;
1989         struct sockaddr addr;
1990 };
1991 #endif
1992
1993         int ret=0;
1994         u16 reason;
1995         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
1996         struct iw_mlme *mlme = (struct iw_mlme *) extra;
1997
1998
1999         if(mlme==NULL)
2000                 return -1;
2001
2002         DBG_871X("%s\n", __FUNCTION__);
2003
2004         reason = cpu_to_le16(mlme->reason_code);
2005
2006
2007         DBG_871X("%s, cmd=%d, reason=%d\n", __FUNCTION__, mlme->cmd, reason);
2008         
2009
2010         switch (mlme->cmd) 
2011         {
2012                 case IW_MLME_DEAUTH:
2013                                 if(!rtw_set_802_11_disassociate(padapter))
2014                                 ret = -1;
2015                                 break;
2016
2017                 case IW_MLME_DISASSOC:
2018                                 if(!rtw_set_802_11_disassociate(padapter))
2019                                                 ret = -1;
2020
2021                                 break;
2022
2023                 default:
2024                         return -EOPNOTSUPP;
2025         }
2026
2027         return ret;
2028 }
2029
2030 static int rtw_wx_set_scan(struct net_device *dev, struct iw_request_info *a,
2031                              union iwreq_data *wrqu, char *extra)
2032 {
2033         u8 _status = _FALSE;
2034         int ret = 0;    
2035         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2036         struct mlme_priv *pmlmepriv= &padapter->mlmepriv;
2037         NDIS_802_11_SSID ssid[RTW_SSID_SCAN_AMOUNT];
2038         _irqL   irqL;
2039 #ifdef CONFIG_P2P
2040         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);   
2041 #endif //CONFIG_P2P
2042         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_set_scan\n"));
2043
2044 _func_enter_;
2045
2046         #ifdef DBG_IOCTL
2047         DBG_871X("DBG_IOCTL %s:%d\n",__FUNCTION__, __LINE__);
2048         #endif
2049 /*
2050 #ifdef CONFIG_CONCURRENT_MODE
2051         if(padapter->iface_type > PRIMARY_IFACE)
2052         {
2053                 ret = -1;
2054                 goto exit;
2055         }
2056 #endif
2057 */
2058 #ifdef CONFIG_MP_INCLUDED
2059                 if (padapter->registrypriv.mp_mode == 1)
2060                 {
2061                                 DBG_871X(FUNC_ADPT_FMT ": MP mode block Scan request\n", FUNC_ADPT_ARG(padapter));      
2062                                 ret = -1;
2063                                 goto exit;
2064                 }
2065 #ifdef CONFIG_CONCURRENT_MODE
2066                         if (padapter->pbuddy_adapter) {
2067                                 if (padapter->pbuddy_adapter->registrypriv.mp_mode == 1)
2068                                 {
2069                                         DBG_871X(FUNC_ADPT_FMT ": MP mode block Scan request\n", FUNC_ADPT_ARG(padapter->pbuddy_adapter));
2070                                         ret = -1;
2071                                         goto exit;
2072                                 }
2073                         }
2074 #endif //CONFIG_CONCURRENT_MODE
2075 #endif
2076
2077         rtw_ps_deny(padapter, PS_DENY_SCAN);
2078         if(_FAIL == rtw_pwr_wakeup(padapter))
2079         {
2080                 ret= -1;
2081                 goto exit;
2082         }
2083
2084         if(padapter->bDriverStopped){
2085            DBG_871X("bDriverStopped=%d\n", padapter->bDriverStopped);
2086                 ret= -1;
2087                 goto exit;
2088         }
2089         
2090         if(!padapter->bup){
2091                 ret = -1;
2092                 goto exit;
2093         }
2094         
2095         if (padapter->hw_init_completed==_FALSE){
2096                 ret = -1;
2097                 goto exit;
2098         }
2099
2100         // When Busy Traffic, driver do not site survey. So driver return success.
2101         // wpa_supplicant will not issue SIOCSIWSCAN cmd again after scan timeout.
2102         // modify by thomas 2011-02-22.
2103         if (pmlmepriv->LinkDetectInfo.bBusyTraffic == _TRUE
2104 #ifdef CONFIG_CONCURRENT_MODE
2105         || rtw_get_buddy_bBusyTraffic(padapter) == _TRUE
2106 #endif //CONFIG_CONCURRENT_MODE
2107         )
2108         {
2109                 indicate_wx_scan_complete_event(padapter);
2110                 goto exit;
2111         }
2112
2113         if (check_fwstate(pmlmepriv, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE)
2114         {
2115                 indicate_wx_scan_complete_event(padapter);
2116                 goto exit;
2117         } 
2118
2119 #ifdef CONFIG_CONCURRENT_MODE
2120         if (check_buddy_fwstate(padapter,
2121                 _FW_UNDER_SURVEY|_FW_UNDER_LINKING|WIFI_UNDER_WPS) == _TRUE)
2122         {
2123                 indicate_wx_scan_complete_event(padapter);
2124                 goto exit;
2125         }
2126 #endif
2127
2128 #ifdef CONFIG_DUALMAC_CONCURRENT
2129         if (dc_check_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING)== _TRUE)
2130         {
2131                 indicate_wx_scan_complete_event(padapter);
2132                 goto exit;
2133         }
2134 #endif
2135
2136 #ifdef CONFIG_P2P
2137         if ( pwdinfo->p2p_state != P2P_STATE_NONE )
2138         {
2139                 rtw_p2p_set_pre_state( pwdinfo, rtw_p2p_state( pwdinfo ) );
2140                 rtw_p2p_set_state(pwdinfo, P2P_STATE_FIND_PHASE_SEARCH);
2141                 rtw_p2p_findphase_ex_set(pwdinfo, P2P_FINDPHASE_EX_FULL);
2142                 rtw_free_network_queue(padapter, _TRUE);
2143         }
2144 #endif //CONFIG_P2P
2145
2146         _rtw_memset(ssid, 0, sizeof(NDIS_802_11_SSID)*RTW_SSID_SCAN_AMOUNT);
2147
2148 #if WIRELESS_EXT >= 17
2149         if (wrqu->data.length == sizeof(struct iw_scan_req)) 
2150         {
2151                 struct iw_scan_req *req = (struct iw_scan_req *)extra;
2152         
2153                 if (wrqu->data.flags & IW_SCAN_THIS_ESSID)
2154                 {
2155                         int len = min((int)req->essid_len, IW_ESSID_MAX_SIZE);
2156
2157                         _rtw_memcpy(ssid[0].Ssid, req->essid, len);
2158                         ssid[0].SsidLength = len;       
2159
2160                         DBG_871X("IW_SCAN_THIS_ESSID, ssid=%s, len=%d\n", req->essid, req->essid_len);
2161                 
2162                         _enter_critical_bh(&pmlmepriv->lock, &irqL);                            
2163                 
2164                         _status = rtw_sitesurvey_cmd(padapter, ssid, 1, NULL, 0);
2165                 
2166                         _exit_critical_bh(&pmlmepriv->lock, &irqL);
2167                         
2168                 }
2169                 else if (req->scan_type == IW_SCAN_TYPE_PASSIVE)
2170                 {
2171                         DBG_871X("rtw_wx_set_scan, req->scan_type == IW_SCAN_TYPE_PASSIVE\n");
2172                 }
2173                 
2174         }
2175         else
2176 #endif
2177
2178         if(     wrqu->data.length >= WEXT_CSCAN_HEADER_SIZE
2179                 && _rtw_memcmp(extra, WEXT_CSCAN_HEADER, WEXT_CSCAN_HEADER_SIZE) == _TRUE
2180         )
2181         {
2182                 int len = wrqu->data.length -WEXT_CSCAN_HEADER_SIZE;
2183                 char *pos = extra+WEXT_CSCAN_HEADER_SIZE;
2184                 char section;
2185                 char sec_len;
2186                 int ssid_index = 0;
2187
2188                 //DBG_871X("%s COMBO_SCAN header is recognized\n", __FUNCTION__);
2189                 
2190                 while(len >= 1) {
2191                         section = *(pos++); len-=1;
2192
2193                         switch(section) {
2194                                 case WEXT_CSCAN_SSID_SECTION:
2195                                         //DBG_871X("WEXT_CSCAN_SSID_SECTION\n");
2196                                         if(len < 1) {
2197                                                 len = 0;
2198                                                 break;
2199                                         }
2200                                         
2201                                         sec_len = *(pos++); len-=1;
2202
2203                                         if(sec_len>0 && sec_len<=len) {
2204                                                 ssid[ssid_index].SsidLength = sec_len;
2205                                                 _rtw_memcpy(ssid[ssid_index].Ssid, pos, ssid[ssid_index].SsidLength);
2206                                                 //DBG_871X("%s COMBO_SCAN with specific ssid:%s, %d\n", __FUNCTION__
2207                                                 //      , ssid[ssid_index].Ssid, ssid[ssid_index].SsidLength);
2208                                                 ssid_index++;
2209                                         }
2210                                         
2211                                         pos+=sec_len; len-=sec_len;
2212                                         break;
2213                                         
2214                                 
2215                                 case WEXT_CSCAN_CHANNEL_SECTION:
2216                                         //DBG_871X("WEXT_CSCAN_CHANNEL_SECTION\n");
2217                                         pos+=1; len-=1;
2218                                         break;
2219                                 case WEXT_CSCAN_ACTV_DWELL_SECTION:
2220                                         //DBG_871X("WEXT_CSCAN_ACTV_DWELL_SECTION\n");
2221                                         pos+=2; len-=2;
2222                                         break;
2223                                 case WEXT_CSCAN_PASV_DWELL_SECTION:
2224                                         //DBG_871X("WEXT_CSCAN_PASV_DWELL_SECTION\n");
2225                                         pos+=2; len-=2;                                 
2226                                         break;
2227                                 case WEXT_CSCAN_HOME_DWELL_SECTION:
2228                                         //DBG_871X("WEXT_CSCAN_HOME_DWELL_SECTION\n");
2229                                         pos+=2; len-=2;
2230                                         break;
2231                                 case WEXT_CSCAN_TYPE_SECTION:
2232                                         //DBG_871X("WEXT_CSCAN_TYPE_SECTION\n");
2233                                         pos+=1; len-=1;
2234                                         break;
2235                                 #if 0
2236                                 case WEXT_CSCAN_NPROBE_SECTION:
2237                                         DBG_871X("WEXT_CSCAN_NPROBE_SECTION\n");
2238                                         break;
2239                                 #endif
2240                                 
2241                                 default:
2242                                         //DBG_871X("Unknown CSCAN section %c\n", section);
2243                                         len = 0; // stop parsing
2244                         }
2245                         //DBG_871X("len:%d\n", len);
2246                         
2247                 }
2248                 
2249                 //jeff: it has still some scan paramater to parse, we only do this now...
2250                 _status = rtw_set_802_11_bssid_list_scan(padapter, ssid, RTW_SSID_SCAN_AMOUNT);
2251                 
2252         } else
2253         
2254         {
2255                 _status = rtw_set_802_11_bssid_list_scan(padapter, NULL, 0);
2256         }
2257
2258         if(_status == _FALSE)
2259                 ret = -1;
2260
2261 exit:
2262
2263         rtw_ps_deny_cancel(padapter, PS_DENY_SCAN);
2264
2265         #ifdef DBG_IOCTL
2266         DBG_871X("DBG_IOCTL %s:%d return %d\n",__FUNCTION__, __LINE__, ret);
2267         #endif
2268
2269 _func_exit_;
2270
2271         return ret;     
2272 }
2273
2274 static int rtw_wx_get_scan(struct net_device *dev, struct iw_request_info *a,
2275                              union iwreq_data *wrqu, char *extra)
2276 {
2277         _irqL   irqL;
2278         _list                                   *plist, *phead;
2279         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2280         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
2281         _queue                          *queue  = &(pmlmepriv->scanned_queue);
2282         struct  wlan_network    *pnetwork = NULL;
2283         char *ev = extra;
2284         char *stop = ev + wrqu->data.length;
2285         u32 ret = 0;
2286         u32 cnt=0;
2287         u32 wait_for_surveydone;
2288         sint wait_status;
2289 #ifdef CONFIG_CONCURRENT_MODE
2290         //PADAPTER pbuddy_adapter = padapter->pbuddy_adapter;
2291         //struct mlme_priv *pbuddy_mlmepriv = &(pbuddy_adapter->mlmepriv);      
2292 #endif
2293 #ifdef CONFIG_P2P
2294         struct  wifidirect_info*        pwdinfo = &padapter->wdinfo;
2295 #endif //CONFIG_P2P
2296         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_scan\n"));
2297         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_, (" Start of Query SIOCGIWSCAN .\n"));
2298
2299         _func_enter_;
2300
2301         #ifdef DBG_IOCTL
2302         DBG_871X("DBG_IOCTL %s:%d\n",__FUNCTION__, __LINE__);
2303         #endif
2304 /*
2305 #ifdef CONFIG_CONCURRENT_MODE
2306         if(padapter->iface_type > PRIMARY_IFACE)
2307         {
2308                 ret = -EINVAL;
2309                 goto exit;
2310         }
2311 #endif
2312 */      
2313         if(adapter_to_pwrctl(padapter)->brfoffbyhw && padapter->bDriverStopped)
2314         {
2315                 ret = -EINVAL;
2316                 goto exit;
2317         }
2318   
2319 #ifdef CONFIG_P2P
2320         if(!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
2321         {
2322                 //      P2P is enabled
2323                 if ( padapter->chip_type == RTL8192D )
2324                         wait_for_surveydone = 300;      //      Because the 8192du supports more channels.
2325                 else
2326                         wait_for_surveydone = 200;
2327         }
2328         else
2329         {
2330                 //      P2P is disabled
2331                 wait_for_surveydone = 100;
2332         }
2333 #else
2334         {
2335                 wait_for_surveydone = 100;
2336         }
2337 #endif //CONFIG_P2P
2338
2339 #if 1 // Wireless Extension use EAGAIN to try
2340         wait_status = _FW_UNDER_SURVEY
2341 #ifndef CONFIG_ANDROID
2342                 | _FW_UNDER_LINKING
2343 #endif
2344         ;
2345
2346         while (check_fwstate(pmlmepriv, wait_status) == _TRUE)
2347         {
2348                 return -EAGAIN;
2349         }
2350 #else
2351         wait_status = _FW_UNDER_SURVEY
2352                 #ifndef CONFIG_ANDROID
2353                 |_FW_UNDER_LINKING
2354                 #endif
2355         ;
2356
2357 #ifdef CONFIG_DUALMAC_CONCURRENT
2358         while(dc_check_fwstate(padapter, wait_status)== _TRUE)
2359         {
2360                 rtw_msleep_os(30);
2361                 cnt++;
2362                 if(cnt > wait_for_surveydone )
2363                         break;
2364         }
2365 #endif // CONFIG_DUALMAC_CONCURRENT
2366
2367         while(check_fwstate(pmlmepriv, wait_status) == _TRUE)
2368         {       
2369                 rtw_msleep_os(30);
2370                 cnt++;
2371                 if(cnt > wait_for_surveydone )
2372                         break;
2373         }
2374 #endif
2375         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2376
2377         phead = get_list_head(queue);
2378         plist = get_next(phead);
2379        
2380         while(1)
2381         {
2382                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
2383                         break;
2384
2385                 if((stop - ev) < SCAN_ITEM_SIZE) {
2386                         ret = -E2BIG;
2387                         break;
2388                 }
2389
2390                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
2391
2392                 //report network only if the current channel set contains the channel to which this network belongs
2393                 if(rtw_ch_set_search_ch(padapter->mlmeextpriv.channel_set, pnetwork->network.Configuration.DSConfig) >= 0
2394                         && rtw_mlme_band_check(padapter, pnetwork->network.Configuration.DSConfig) == _TRUE
2395                         && _TRUE == rtw_validate_ssid(&(pnetwork->network.Ssid))
2396                 )
2397                 {
2398                         ev=translate_scan(padapter, a, pnetwork, ev, stop);
2399                 }
2400
2401                 plist = get_next(plist);
2402         
2403         }        
2404
2405         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
2406
2407        wrqu->data.length = ev-extra;
2408         wrqu->data.flags = 0;
2409         
2410 exit:           
2411         
2412         _func_exit_;    
2413         
2414         #ifdef DBG_IOCTL
2415         DBG_871X("DBG_IOCTL %s:%d return %d\n",__FUNCTION__, __LINE__, ret);
2416         #endif
2417         
2418         return ret ;
2419         
2420 }
2421
2422 //set ssid flow
2423 //s1. rtw_set_802_11_infrastructure_mode()
2424 //s2. set_802_11_authenticaion_mode()
2425 //s3. set_802_11_encryption_mode()
2426 //s4. rtw_set_802_11_ssid()
2427 static int rtw_wx_set_essid(struct net_device *dev, 
2428                               struct iw_request_info *a,
2429                               union iwreq_data *wrqu, char *extra)
2430 {
2431         _irqL irqL;
2432         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2433         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2434         _queue *queue = &pmlmepriv->scanned_queue;
2435         _list *phead;
2436         s8 status = _TRUE;
2437         struct wlan_network *pnetwork = NULL;
2438         NDIS_802_11_AUTHENTICATION_MODE authmode;       
2439         NDIS_802_11_SSID ndis_ssid;     
2440         u8 *dst_ssid, *src_ssid;
2441
2442         uint ret = 0, len;
2443
2444         _func_enter_;
2445         
2446         #ifdef DBG_IOCTL
2447         DBG_871X("DBG_IOCTL %s:%d\n",__FUNCTION__, __LINE__);
2448         #endif
2449         
2450 /*
2451 #ifdef CONFIG_CONCURRENT_MODE
2452         if(padapter->iface_type > PRIMARY_IFACE)
2453         {
2454                 ret = -EINVAL;
2455                 goto exit;
2456         }
2457 #endif
2458 */
2459
2460 #ifdef CONFIG_CONCURRENT_MODE
2461         if (check_buddy_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING) == _TRUE)
2462         {               
2463                 DBG_871X("set ssid, but buddy_intf is under scanning or linking\n");
2464                 
2465                 ret = -EINVAL;
2466                 
2467                 goto exit;
2468         }
2469 #endif
2470
2471 #ifdef CONFIG_DUALMAC_CONCURRENT
2472         if (dc_check_fwstate(padapter, _FW_UNDER_SURVEY|_FW_UNDER_LINKING)== _TRUE)
2473         {
2474                 DBG_871X("set bssid, but buddy_intf is under scanning or linking\n");
2475                 ret = -EINVAL;
2476                 goto exit;
2477         }
2478 #endif
2479
2480         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
2481                  ("+rtw_wx_set_essid: fw_state=0x%08x\n", get_fwstate(pmlmepriv)));
2482
2483         rtw_ps_deny(padapter, PS_DENY_JOIN);
2484         if(_FAIL == rtw_pwr_wakeup(padapter))
2485         {               
2486                 ret = -1;
2487                 goto exit;
2488         }
2489
2490         if(!padapter->bup){
2491                 ret = -1;
2492                 goto exit;
2493         }
2494
2495 #if WIRELESS_EXT <= 20
2496         if ((wrqu->essid.length-1) > IW_ESSID_MAX_SIZE){
2497 #else
2498         if (wrqu->essid.length > IW_ESSID_MAX_SIZE){
2499 #endif
2500                 ret= -E2BIG;
2501                 goto exit;
2502         }
2503         
2504         if(check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
2505                 ret = -1;
2506                 goto exit;
2507         }               
2508         
2509         authmode = padapter->securitypriv.ndisauthtype;
2510         DBG_871X("=>%s\n",__FUNCTION__);
2511         if (wrqu->essid.flags && wrqu->essid.length)
2512         {
2513                 // Commented by Albert 20100519
2514                 // We got the codes in "set_info" function of iwconfig source code.
2515                 //      =========================================
2516                 //      wrq.u.essid.length = strlen(essid) + 1;
2517                 //      if(we_kernel_version > 20)
2518                 //              wrq.u.essid.length--;
2519                 //      =========================================
2520                 //      That means, if the WIRELESS_EXT less than or equal to 20, the correct ssid len should subtract 1.
2521 #if WIRELESS_EXT <= 20
2522                 len = ((wrqu->essid.length-1) < IW_ESSID_MAX_SIZE) ? (wrqu->essid.length-1) : IW_ESSID_MAX_SIZE;
2523 #else
2524                 len = (wrqu->essid.length < IW_ESSID_MAX_SIZE) ? wrqu->essid.length : IW_ESSID_MAX_SIZE;
2525 #endif
2526
2527                 if( wrqu->essid.length != 33 )
2528                         DBG_871X("ssid=%s, len=%d\n", extra, wrqu->essid.length);
2529
2530                 _rtw_memset(&ndis_ssid, 0, sizeof(NDIS_802_11_SSID));
2531                 ndis_ssid.SsidLength = len;
2532                 _rtw_memcpy(ndis_ssid.Ssid, extra, len);                
2533                 src_ssid = ndis_ssid.Ssid;
2534                 
2535                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_, ("rtw_wx_set_essid: ssid=[%s]\n", src_ssid));
2536                 _enter_critical_bh(&queue->lock, &irqL);
2537                phead = get_list_head(queue);
2538               pmlmepriv->pscanned = get_next(phead);
2539
2540                 while (1)
2541                 {                       
2542                         if (rtw_end_of_queue_search(phead, pmlmepriv->pscanned) == _TRUE)
2543                         {
2544 #if 0                   
2545                                 if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE)
2546                                 {
2547                                         rtw_set_802_11_ssid(padapter, &ndis_ssid);
2548
2549                                         goto exit;                    
2550                                 }
2551                                 else
2552                                 {
2553                                         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("rtw_wx_set_ssid(): scanned_queue is empty\n"));
2554                                         ret = -EINVAL;
2555                                         goto exit;
2556                                 }
2557 #endif                  
2558                                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_warning_,
2559                                          ("rtw_wx_set_essid: scan_q is empty, set ssid to check if scanning again!\n"));
2560
2561                                 break;
2562                         }
2563         
2564                         pnetwork = LIST_CONTAINOR(pmlmepriv->pscanned, struct wlan_network, list);
2565
2566                         pmlmepriv->pscanned = get_next(pmlmepriv->pscanned);
2567
2568                         dst_ssid = pnetwork->network.Ssid.Ssid;
2569
2570                         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
2571                                  ("rtw_wx_set_essid: dst_ssid=%s\n",
2572                                   pnetwork->network.Ssid.Ssid));
2573
2574                         if ((_rtw_memcmp(dst_ssid, src_ssid, ndis_ssid.SsidLength) == _TRUE) &&
2575                                 (pnetwork->network.Ssid.SsidLength==ndis_ssid.SsidLength))
2576                         {
2577                                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
2578                                          ("rtw_wx_set_essid: find match, set infra mode\n"));
2579                                 
2580                                 if(check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) == _TRUE)
2581                                 {
2582                                         if(pnetwork->network.InfrastructureMode != pmlmepriv->cur_network.network.InfrastructureMode)
2583                                                 continue;
2584                                 }       
2585                                         
2586                                 if (rtw_set_802_11_infrastructure_mode(padapter, pnetwork->network.InfrastructureMode) == _FALSE)
2587                                 {
2588                                         ret = -1;
2589                                         _exit_critical_bh(&queue->lock, &irqL);
2590                                         goto exit;
2591                                 }
2592
2593                                 break;                  
2594                         }
2595                 }
2596                 _exit_critical_bh(&queue->lock, &irqL);
2597                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
2598                          ("set ssid: set_802_11_auth. mode=%d\n", authmode));
2599                 rtw_set_802_11_authentication_mode(padapter, authmode);
2600                 //set_802_11_encryption_mode(padapter, padapter->securitypriv.ndisencryptstatus);
2601                 if (rtw_set_802_11_ssid(padapter, &ndis_ssid) == _FALSE) {
2602                         ret = -1;
2603                         goto exit;
2604                 }       
2605         }                       
2606         
2607 exit:
2608
2609         rtw_ps_deny_cancel(padapter, PS_DENY_JOIN);
2610
2611         DBG_871X("<=%s, ret %d\n",__FUNCTION__, ret);
2612         
2613         #ifdef DBG_IOCTL
2614         DBG_871X("DBG_IOCTL %s:%d return %d\n",__FUNCTION__, __LINE__, ret);
2615         #endif
2616         
2617         _func_exit_;
2618         
2619         return ret;     
2620 }
2621
2622 static int rtw_wx_get_essid(struct net_device *dev, 
2623                               struct iw_request_info *a,
2624                               union iwreq_data *wrqu, char *extra)
2625 {
2626         u32 len,ret = 0;
2627         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2628         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
2629         WLAN_BSSID_EX  *pcur_bss = &pmlmepriv->cur_network.network;
2630
2631         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,("rtw_wx_get_essid\n"));
2632
2633         _func_enter_;
2634
2635         if ( (check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE) ||
2636               (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) == _TRUE))
2637         {
2638                 len = pcur_bss->Ssid.SsidLength;
2639
2640                 wrqu->essid.length = len;
2641                         
2642                 _rtw_memcpy(extra, pcur_bss->Ssid.Ssid, len);
2643
2644                 wrqu->essid.flags = 1;
2645         }
2646         else
2647         {
2648                 ret = -1;
2649                 goto exit;
2650         }
2651
2652 exit:
2653
2654         _func_exit_;
2655         
2656         return ret;
2657         
2658 }
2659
2660 static int rtw_wx_set_rate(struct net_device *dev, 
2661                               struct iw_request_info *a,
2662                               union iwreq_data *wrqu, char *extra)
2663 {
2664         int     i, ret = 0;
2665         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2666         u8      datarates[NumRates];
2667         u32     target_rate = wrqu->bitrate.value;
2668         u32     fixed = wrqu->bitrate.fixed;
2669         u32     ratevalue = 0;
2670          u8 mpdatarate[NumRates]={11, 10, 9, 8, 7, 6, 5, 4, 3, 2, 1, 0, 0xff};
2671
2672 _func_enter_;
2673
2674         RT_TRACE(_module_rtl871x_mlme_c_,_drv_info_,(" rtw_wx_set_rate \n"));
2675         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("target_rate = %d, fixed = %d\n",target_rate,fixed));
2676         
2677         if(target_rate == -1){
2678                 ratevalue = 11;
2679                 goto set_rate;
2680         }
2681         target_rate = target_rate/100000;
2682
2683         switch(target_rate){
2684                 case 10:
2685                         ratevalue = 0;
2686                         break;
2687                 case 20:
2688                         ratevalue = 1;
2689                         break;
2690                 case 55:
2691                         ratevalue = 2;
2692                         break;
2693                 case 60:
2694                         ratevalue = 3;
2695                         break;
2696                 case 90:
2697                         ratevalue = 4;
2698                         break;
2699                 case 110:
2700                         ratevalue = 5;
2701                         break;
2702                 case 120:
2703                         ratevalue = 6;
2704                         break;
2705                 case 180:
2706                         ratevalue = 7;
2707                         break;
2708                 case 240:
2709                         ratevalue = 8;
2710                         break;
2711                 case 360:
2712                         ratevalue = 9;
2713                         break;
2714                 case 480:
2715                         ratevalue = 10;
2716                         break;
2717                 case 540:
2718                         ratevalue = 11;
2719                         break;
2720                 default:
2721                         ratevalue = 11;
2722                         break;
2723         }
2724
2725 set_rate:
2726
2727         for(i=0; i<NumRates; i++)
2728         {
2729                 if(ratevalue==mpdatarate[i])
2730                 {
2731                         datarates[i] = mpdatarate[i];
2732                         if(fixed == 0)
2733                                 break;
2734                 }
2735                 else{
2736                         datarates[i] = 0xff;
2737                 }
2738
2739                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("datarate_inx=%d\n",datarates[i]));
2740         }
2741
2742         if( rtw_setdatarate_cmd(padapter, datarates) !=_SUCCESS){
2743                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("rtw_wx_set_rate Fail!!!\n"));
2744                 ret = -1;
2745         }
2746
2747 _func_exit_;
2748
2749         return ret;
2750 }
2751
2752 static int rtw_wx_get_rate(struct net_device *dev, 
2753                              struct iw_request_info *info, 
2754                              union iwreq_data *wrqu, char *extra)
2755 {       
2756         u16 max_rate = 0;
2757
2758         max_rate = rtw_get_cur_max_rate((_adapter *)rtw_netdev_priv(dev));
2759
2760         if(max_rate == 0)
2761                 return -EPERM;
2762         
2763         wrqu->bitrate.fixed = 0;        /* no auto select */
2764         wrqu->bitrate.value = max_rate * 100000;
2765
2766         return 0;
2767 }
2768
2769 static int rtw_wx_set_rts(struct net_device *dev, 
2770                              struct iw_request_info *info, 
2771                              union iwreq_data *wrqu, char *extra)
2772 {
2773         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2774
2775         _func_enter_;
2776         
2777         if (wrqu->rts.disabled)
2778                 padapter->registrypriv.rts_thresh = 2347;
2779         else {
2780                 if (wrqu->rts.value < 0 ||
2781                     wrqu->rts.value > 2347)
2782                         return -EINVAL;
2783                 
2784                 padapter->registrypriv.rts_thresh = wrqu->rts.value;
2785         }
2786
2787         DBG_871X("%s, rts_thresh=%d\n", __func__, padapter->registrypriv.rts_thresh);
2788         
2789         _func_exit_;
2790         
2791         return 0;
2792
2793 }
2794
2795 static int rtw_wx_get_rts(struct net_device *dev, 
2796                              struct iw_request_info *info, 
2797                              union iwreq_data *wrqu, char *extra)
2798 {
2799         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2800         
2801         _func_enter_;
2802
2803         DBG_871X("%s, rts_thresh=%d\n", __func__, padapter->registrypriv.rts_thresh);   
2804         
2805         wrqu->rts.value = padapter->registrypriv.rts_thresh;
2806         wrqu->rts.fixed = 0;    /* no auto select */
2807         //wrqu->rts.disabled = (wrqu->rts.value == DEFAULT_RTS_THRESHOLD);
2808         
2809         _func_exit_;
2810         
2811         return 0;
2812 }
2813
2814 static int rtw_wx_set_frag(struct net_device *dev, 
2815                              struct iw_request_info *info, 
2816                              union iwreq_data *wrqu, char *extra)
2817 {
2818         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2819
2820         _func_enter_;
2821         
2822         if (wrqu->frag.disabled)
2823                 padapter->xmitpriv.frag_len = MAX_FRAG_THRESHOLD;
2824         else {
2825                 if (wrqu->frag.value < MIN_FRAG_THRESHOLD ||
2826                     wrqu->frag.value > MAX_FRAG_THRESHOLD)
2827                         return -EINVAL;
2828                 
2829                 padapter->xmitpriv.frag_len = wrqu->frag.value & ~0x1;
2830         }
2831
2832         DBG_871X("%s, frag_len=%d\n", __func__, padapter->xmitpriv.frag_len);
2833         
2834         _func_exit_;
2835         
2836         return 0;
2837         
2838 }
2839
2840 static int rtw_wx_get_frag(struct net_device *dev, 
2841                              struct iw_request_info *info, 
2842                              union iwreq_data *wrqu, char *extra)
2843 {
2844         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2845         
2846         _func_enter_;
2847
2848         DBG_871X("%s, frag_len=%d\n", __func__, padapter->xmitpriv.frag_len);
2849         
2850         wrqu->frag.value = padapter->xmitpriv.frag_len;
2851         wrqu->frag.fixed = 0;   /* no auto select */
2852         //wrqu->frag.disabled = (wrqu->frag.value == DEFAULT_FRAG_THRESHOLD);
2853         
2854         _func_exit_;
2855         
2856         return 0;
2857 }
2858
2859 static int rtw_wx_get_retry(struct net_device *dev, 
2860                              struct iw_request_info *info, 
2861                              union iwreq_data *wrqu, char *extra)
2862 {
2863         //_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2864
2865         
2866         wrqu->retry.value = 7;
2867         wrqu->retry.fixed = 0;  /* no auto select */
2868         wrqu->retry.disabled = 1;
2869         
2870         return 0;
2871
2872 }       
2873
2874 #if 0
2875 #define IW_ENCODE_INDEX         0x00FF  /* Token index (if needed) */
2876 #define IW_ENCODE_FLAGS         0xFF00  /* Flags defined below */
2877 #define IW_ENCODE_MODE          0xF000  /* Modes defined below */
2878 #define IW_ENCODE_DISABLED      0x8000  /* Encoding disabled */
2879 #define IW_ENCODE_ENABLED       0x0000  /* Encoding enabled */
2880 #define IW_ENCODE_RESTRICTED    0x4000  /* Refuse non-encoded packets */
2881 #define IW_ENCODE_OPEN          0x2000  /* Accept non-encoded packets */
2882 #define IW_ENCODE_NOKEY         0x0800  /* Key is write only, so not present */
2883 #define IW_ENCODE_TEMP          0x0400  /* Temporary key */
2884 /*
2885 iwconfig wlan0 key on -> flags = 0x6001 -> maybe it means auto
2886 iwconfig wlan0 key off -> flags = 0x8800
2887 iwconfig wlan0 key open -> flags = 0x2800
2888 iwconfig wlan0 key open 1234567890 -> flags = 0x2000
2889 iwconfig wlan0 key restricted -> flags = 0x4800
2890 iwconfig wlan0 key open [3] 1234567890 -> flags = 0x2003
2891 iwconfig wlan0 key restricted [2] 1234567890 -> flags = 0x4002
2892 iwconfig wlan0 key open [3] -> flags = 0x2803
2893 iwconfig wlan0 key restricted [2] -> flags = 0x4802
2894 */
2895 #endif
2896
2897 static int rtw_wx_set_enc(struct net_device *dev, 
2898                             struct iw_request_info *info, 
2899                             union iwreq_data *wrqu, char *keybuf)
2900 {       
2901         u32 key, ret = 0;
2902         u32 keyindex_provided;
2903         NDIS_802_11_WEP  wep;   
2904         NDIS_802_11_AUTHENTICATION_MODE authmode;
2905
2906         struct iw_point *erq = &(wrqu->encoding);
2907         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
2908         struct pwrctrl_priv *pwrpriv = adapter_to_pwrctl(padapter);
2909         DBG_871X("+rtw_wx_set_enc, flags=0x%x\n", erq->flags);
2910
2911         _rtw_memset(&wep, 0, sizeof(NDIS_802_11_WEP));
2912         
2913         key = erq->flags & IW_ENCODE_INDEX;
2914         
2915         _func_enter_;   
2916
2917         if (erq->flags & IW_ENCODE_DISABLED)
2918         {
2919                 DBG_871X("EncryptionDisabled\n");
2920                 padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
2921                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
2922                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
2923                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Open; //open system
2924                 authmode = Ndis802_11AuthModeOpen;
2925                 padapter->securitypriv.ndisauthtype=authmode;
2926                 
2927                 goto exit;
2928         }
2929
2930         if (key) {
2931                 if (key > WEP_KEYS)
2932                         return -EINVAL;
2933                 key--;
2934                 keyindex_provided = 1;
2935         } 
2936         else
2937         {
2938                 keyindex_provided = 0;
2939                 key = padapter->securitypriv.dot11PrivacyKeyIndex;
2940                 DBG_871X("rtw_wx_set_enc, key=%d\n", key);
2941         }
2942         
2943         //set authentication mode       
2944         if(erq->flags & IW_ENCODE_OPEN)
2945         {
2946                 DBG_871X("rtw_wx_set_enc():IW_ENCODE_OPEN\n");
2947                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;//Ndis802_11EncryptionDisabled;
2948
2949 #ifdef CONFIG_PLATFORM_MT53XX
2950                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
2951 #else
2952                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Open;
2953 #endif
2954
2955                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
2956                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
2957                 authmode = Ndis802_11AuthModeOpen;
2958                 padapter->securitypriv.ndisauthtype=authmode;
2959         }       
2960         else if(erq->flags & IW_ENCODE_RESTRICTED)
2961         {               
2962                 DBG_871X("rtw_wx_set_enc():IW_ENCODE_RESTRICTED\n");
2963                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;
2964
2965 #ifdef CONFIG_PLATFORM_MT53XX
2966                 padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
2967 #else
2968                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Shared;
2969 #endif
2970
2971                 padapter->securitypriv.dot11PrivacyAlgrthm=_WEP40_;
2972                 padapter->securitypriv.dot118021XGrpPrivacy=_WEP40_;                    
2973                 authmode = Ndis802_11AuthModeShared;
2974                 padapter->securitypriv.ndisauthtype=authmode;
2975         }
2976         else
2977         {
2978                 DBG_871X("rtw_wx_set_enc():erq->flags=0x%x\n", erq->flags);
2979
2980                 padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption1Enabled;//Ndis802_11EncryptionDisabled;
2981                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Open; //open system
2982                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
2983                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
2984                 authmode = Ndis802_11AuthModeOpen;
2985                 padapter->securitypriv.ndisauthtype=authmode;
2986         }
2987         
2988         wep.KeyIndex = key;
2989         if (erq->length > 0)
2990         {
2991                 wep.KeyLength = erq->length <= 5 ? 5 : 13;
2992
2993                 wep.Length = wep.KeyLength + FIELD_OFFSET(NDIS_802_11_WEP, KeyMaterial);
2994         }
2995         else
2996         {
2997                 wep.KeyLength = 0 ;
2998                 
2999                 if(keyindex_provided == 1)// set key_id only, no given KeyMaterial(erq->length==0).
3000                 {
3001                         padapter->securitypriv.dot11PrivacyKeyIndex = key;
3002
3003                         DBG_871X("(keyindex_provided == 1), keyid=%d, key_len=%d\n", key, padapter->securitypriv.dot11DefKeylen[key]);
3004
3005                         switch(padapter->securitypriv.dot11DefKeylen[key])
3006                         {
3007                                 case 5:
3008                                         padapter->securitypriv.dot11PrivacyAlgrthm=_WEP40_;                                     
3009                                         break;
3010                                 case 13:
3011                                         padapter->securitypriv.dot11PrivacyAlgrthm=_WEP104_;                                    
3012                                         break;
3013                                 default:
3014                                         padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;                                        
3015                                         break;
3016                         }
3017                                 
3018                         goto exit;
3019                         
3020                 }
3021                 
3022         }
3023
3024         wep.KeyIndex |= 0x80000000;
3025
3026         _rtw_memcpy(wep.KeyMaterial, keybuf, wep.KeyLength);
3027         
3028         if (rtw_set_802_11_add_wep(padapter, &wep) == _FALSE) {
3029                 if(rf_on == pwrpriv->rf_pwrstate )
3030                         ret = -EOPNOTSUPP;
3031                 goto exit;
3032         }       
3033
3034 exit:
3035         
3036         _func_exit_;
3037         
3038         return ret;
3039         
3040 }
3041
3042 static int rtw_wx_get_enc(struct net_device *dev, 
3043                             struct iw_request_info *info, 
3044                             union iwreq_data *wrqu, char *keybuf)
3045 {
3046         uint key, ret =0;
3047         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3048         struct iw_point *erq = &(wrqu->encoding);
3049         struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);
3050
3051         _func_enter_;
3052         
3053         if(check_fwstate(pmlmepriv, _FW_LINKED) != _TRUE)
3054         {
3055                  if(check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) != _TRUE)
3056                  {
3057                 erq->length = 0;
3058                 erq->flags |= IW_ENCODE_DISABLED;
3059                 return 0;
3060         }       
3061         }       
3062
3063         
3064         key = erq->flags & IW_ENCODE_INDEX;
3065
3066         if (key) {
3067                 if (key > WEP_KEYS)
3068                         return -EINVAL;
3069                 key--;
3070         } else
3071         {
3072                 key = padapter->securitypriv.dot11PrivacyKeyIndex;
3073         }       
3074
3075         erq->flags = key + 1;
3076
3077         //if(padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeOpen)
3078         //{
3079         //      erq->flags |= IW_ENCODE_OPEN;
3080         //}       
3081         
3082         switch(padapter->securitypriv.ndisencryptstatus)
3083         {
3084                 case Ndis802_11EncryptionNotSupported:
3085                 case Ndis802_11EncryptionDisabled:
3086
3087                 erq->length = 0;
3088                 erq->flags |= IW_ENCODE_DISABLED;
3089         
3090                 break;
3091                 
3092                 case Ndis802_11Encryption1Enabled:                                      
3093                 
3094                 erq->length = padapter->securitypriv.dot11DefKeylen[key];               
3095
3096                 if(erq->length)
3097                 {
3098                         _rtw_memcpy(keybuf, padapter->securitypriv.dot11DefKey[key].skey, padapter->securitypriv.dot11DefKeylen[key]);
3099                 
3100                 erq->flags |= IW_ENCODE_ENABLED;
3101
3102                         if(padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeOpen)
3103                         {
3104                                 erq->flags |= IW_ENCODE_OPEN;
3105                         }
3106                         else if(padapter->securitypriv.ndisauthtype == Ndis802_11AuthModeShared)
3107                         {
3108                 erq->flags |= IW_ENCODE_RESTRICTED;
3109                         }       
3110                 }       
3111                 else
3112                 {
3113                         erq->length = 0;
3114                         erq->flags |= IW_ENCODE_DISABLED;
3115                 }
3116
3117                 break;
3118
3119                 case Ndis802_11Encryption2Enabled:
3120                 case Ndis802_11Encryption3Enabled:
3121
3122                 erq->length = 16;
3123                 erq->flags |= (IW_ENCODE_ENABLED | IW_ENCODE_OPEN | IW_ENCODE_NOKEY);
3124
3125                 break;
3126         
3127                 default:
3128                 erq->length = 0;
3129                 erq->flags |= IW_ENCODE_DISABLED;
3130
3131                 break;
3132                 
3133         }
3134         
3135         _func_exit_;
3136         
3137         return ret;
3138         
3139 }                                    
3140
3141 static int rtw_wx_get_power(struct net_device *dev, 
3142                              struct iw_request_info *info, 
3143                              union iwreq_data *wrqu, char *extra)
3144 {
3145         //_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3146         
3147         wrqu->power.value = 0;
3148         wrqu->power.fixed = 0;  /* no auto select */
3149         wrqu->power.disabled = 1;
3150         
3151         return 0;
3152
3153 }
3154
3155 static int rtw_wx_set_gen_ie(struct net_device *dev, 
3156                              struct iw_request_info *info, 
3157                              union iwreq_data *wrqu, char *extra)
3158 {
3159         int ret;
3160         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3161         
3162        ret = rtw_set_wpa_ie(padapter, extra, wrqu->data.length);
3163            
3164         return ret;
3165 }       
3166
3167 static int rtw_wx_set_auth(struct net_device *dev, 
3168                              struct iw_request_info *info, 
3169                              union iwreq_data *wrqu, char *extra)
3170 {
3171         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3172         struct iw_param *param = (struct iw_param*)&(wrqu->param);
3173         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
3174         struct security_priv *psecuritypriv = &padapter->securitypriv;
3175         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
3176         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
3177         u32 value = param->value;
3178         int ret = 0;
3179         
3180         switch (param->flags & IW_AUTH_INDEX) {
3181
3182         case IW_AUTH_WPA_VERSION:
3183 #ifdef CONFIG_WAPI_SUPPORT
3184 #ifndef CONFIG_IOCTL_CFG80211
3185                  padapter->wapiInfo.bWapiEnable = false;
3186                  if(value == IW_AUTH_WAPI_VERSION_1)
3187                  {
3188                         padapter->wapiInfo.bWapiEnable = true;
3189                         psecuritypriv->dot11PrivacyAlgrthm = _SMS4_;
3190                         psecuritypriv->dot118021XGrpPrivacy = _SMS4_;
3191                         psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_WAPI;
3192                         pmlmeinfo->auth_algo = psecuritypriv->dot11AuthAlgrthm;
3193                         padapter->wapiInfo.extra_prefix_len = WAPI_EXT_LEN;
3194                         padapter->wapiInfo.extra_postfix_len = SMS4_MIC_LEN;
3195                 }
3196 #endif
3197 #endif
3198                 break;
3199         case IW_AUTH_CIPHER_PAIRWISE:
3200                 
3201                 break;
3202         case IW_AUTH_CIPHER_GROUP:
3203                 
3204                 break;
3205         case IW_AUTH_KEY_MGMT:
3206 #ifdef CONFIG_WAPI_SUPPORT
3207 #ifndef CONFIG_IOCTL_CFG80211
3208                 DBG_871X("rtw_wx_set_auth: IW_AUTH_KEY_MGMT case \n");
3209                 if(value == IW_AUTH_KEY_MGMT_WAPI_PSK)
3210                         padapter->wapiInfo.bWapiPSK = true;
3211                 else
3212                         padapter->wapiInfo.bWapiPSK = false;
3213                 DBG_871X("rtw_wx_set_auth: IW_AUTH_KEY_MGMT bwapipsk %d \n",padapter->wapiInfo.bWapiPSK);
3214 #endif
3215 #endif
3216                 /*
3217                  *  ??? does not use these parameters
3218                  */
3219                 break;
3220
3221         case IW_AUTH_TKIP_COUNTERMEASURES:
3222         {
3223             if ( param->value )
3224             {  // wpa_supplicant is enabling the tkip countermeasure.
3225                padapter->securitypriv.btkip_countermeasure = _TRUE; 
3226             }
3227             else
3228             {  // wpa_supplicant is disabling the tkip countermeasure.
3229                padapter->securitypriv.btkip_countermeasure = _FALSE; 
3230             }
3231                 break;
3232         }
3233         case IW_AUTH_DROP_UNENCRYPTED:
3234                 {
3235                         /* HACK:
3236                          *
3237                          * wpa_supplicant calls set_wpa_enabled when the driver
3238                          * is loaded and unloaded, regardless of if WPA is being
3239                          * used.  No other calls are made which can be used to
3240                          * determine if encryption will be used or not prior to
3241                          * association being expected.  If encryption is not being
3242                          * used, drop_unencrypted is set to false, else true -- we
3243                          * can use this to determine if the CAP_PRIVACY_ON bit should
3244                          * be set.
3245                          */
3246
3247                         if(padapter->securitypriv.ndisencryptstatus == Ndis802_11Encryption1Enabled)
3248                         {
3249                                 break;//it means init value, or using wep, ndisencryptstatus = Ndis802_11Encryption1Enabled, 
3250                                                 // then it needn't reset it;
3251                         }
3252                         
3253                         if(param->value){
3254                                 padapter->securitypriv.ndisencryptstatus = Ndis802_11EncryptionDisabled;
3255                                 padapter->securitypriv.dot11PrivacyAlgrthm=_NO_PRIVACY_;
3256                                 padapter->securitypriv.dot118021XGrpPrivacy=_NO_PRIVACY_;
3257                                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_Open; //open system
3258                                 padapter->securitypriv.ndisauthtype=Ndis802_11AuthModeOpen;
3259                         }
3260                         
3261                         break;
3262                 }
3263
3264         case IW_AUTH_80211_AUTH_ALG:
3265
3266                 #if defined(CONFIG_ANDROID) || 1
3267                 /*
3268                  *  It's the starting point of a link layer connection using wpa_supplicant
3269                 */
3270                 if(check_fwstate(&padapter->mlmepriv, _FW_LINKED)) {
3271                         LeaveAllPowerSaveMode(padapter);
3272                         rtw_disassoc_cmd(padapter, 500, _FALSE);
3273                         DBG_871X("%s...call rtw_indicate_disconnect\n ",__FUNCTION__);
3274                         rtw_indicate_disconnect(padapter);
3275                         rtw_free_assoc_resources(padapter, 1);
3276                 }
3277                 #endif
3278
3279
3280                 ret = wpa_set_auth_algs(dev, (u32)param->value);                
3281         
3282                 break;
3283
3284         case IW_AUTH_WPA_ENABLED:
3285
3286                 //if(param->value)
3287                 //      padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_8021X; //802.1x
3288                 //else
3289                 //      padapter->securitypriv.dot11AuthAlgrthm = dot11AuthAlgrthm_Open;//open system
3290                 
3291                 //_disassociate(priv);
3292                 
3293                 break;
3294
3295         case IW_AUTH_RX_UNENCRYPTED_EAPOL:
3296                 //ieee->ieee802_1x = param->value;
3297                 break;
3298
3299         case IW_AUTH_PRIVACY_INVOKED:
3300                 //ieee->privacy_invoked = param->value;
3301                 break;
3302
3303 #ifdef CONFIG_WAPI_SUPPORT
3304 #ifndef CONFIG_IOCTL_CFG80211
3305         case IW_AUTH_WAPI_ENABLED:
3306                 break;
3307 #endif
3308 #endif
3309
3310         default:
3311                 return -EOPNOTSUPP;
3312                 
3313         }
3314         
3315         return ret;
3316         
3317 }
3318
3319 static int rtw_wx_set_enc_ext(struct net_device *dev, 
3320                              struct iw_request_info *info, 
3321                              union iwreq_data *wrqu, char *extra)
3322 {
3323         char *alg_name;
3324         u32 param_len;
3325         struct ieee_param *param = NULL;
3326         struct iw_point *pencoding = &wrqu->encoding;
3327         struct iw_encode_ext *pext = (struct iw_encode_ext *)extra;
3328         int ret=0;
3329
3330         param_len = sizeof(struct ieee_param) + pext->key_len;
3331         param = (struct ieee_param *)rtw_malloc(param_len);
3332         if (param == NULL)
3333                 return -1;
3334         
3335         _rtw_memset(param, 0, param_len);
3336
3337         param->cmd = IEEE_CMD_SET_ENCRYPTION;
3338         _rtw_memset(param->sta_addr, 0xff, ETH_ALEN);
3339
3340
3341         switch (pext->alg) {
3342         case IW_ENCODE_ALG_NONE:
3343                 //todo: remove key 
3344                 //remove = 1;   
3345                 alg_name = "none";
3346                 break;
3347         case IW_ENCODE_ALG_WEP:
3348                 alg_name = "WEP";
3349                 break;
3350         case IW_ENCODE_ALG_TKIP:
3351                 alg_name = "TKIP";
3352                 break;
3353         case IW_ENCODE_ALG_CCMP:
3354                 alg_name = "CCMP";
3355                 break;
3356 #ifdef CONFIG_IEEE80211W
3357         case IW_ENCODE_ALG_AES_CMAC:
3358                 alg_name = "BIP";
3359                 break;
3360 #endif //CONFIG_IEEE80211W
3361 #ifdef CONFIG_WAPI_SUPPORT
3362 #ifndef CONFIG_IOCTL_CFG80211
3363         case IW_ENCODE_ALG_SM4:
3364                 alg_name= "SMS4";
3365                 _rtw_memcpy(param->sta_addr, pext->addr.sa_data, ETH_ALEN);
3366                 DBG_871X("rtw_wx_set_enc_ext: SMS4 case \n");
3367                 break;
3368 #endif
3369 #endif
3370         default:
3371                 ret = -1;
3372                 goto exit;
3373         }
3374
3375         strncpy((char *)param->u.crypt.alg, alg_name, IEEE_CRYPT_ALG_NAME_LEN);
3376
3377         if (pext->ext_flags & IW_ENCODE_EXT_SET_TX_KEY)
3378         {
3379                 param->u.crypt.set_tx = 1;
3380         }
3381
3382         /* cliW: WEP does not have group key
3383          * just not checking GROUP key setting 
3384          */
3385         if ((pext->alg != IW_ENCODE_ALG_WEP) &&
3386                 ((pext->ext_flags & IW_ENCODE_EXT_GROUP_KEY)
3387 #ifdef CONFIG_IEEE80211W
3388                 || (pext->ext_flags & IW_ENCODE_ALG_AES_CMAC)
3389 #endif //CONFIG_IEEE80211W
3390         ))
3391         {
3392                 param->u.crypt.set_tx = 0;
3393         }
3394
3395         param->u.crypt.idx = (pencoding->flags&0x00FF) -1 ;
3396
3397         if (pext->ext_flags & IW_ENCODE_EXT_RX_SEQ_VALID)
3398         {
3399 #ifdef CONFIG_WAPI_SUPPORT
3400 #ifndef CONFIG_IOCTL_CFG80211
3401                 if(pext->alg == IW_ENCODE_ALG_SM4)
3402                         _rtw_memcpy(param->u.crypt.seq, pext->rx_seq, 16);
3403                 else
3404 #endif //CONFIG_IOCTL_CFG80211
3405 #endif //CONFIG_WAPI_SUPPORT
3406                 _rtw_memcpy(param->u.crypt.seq, pext->rx_seq, 8);
3407         }
3408
3409         if(pext->key_len)
3410         {
3411                 param->u.crypt.key_len = pext->key_len;
3412                 //_rtw_memcpy(param + 1, pext + 1, pext->key_len);
3413                 _rtw_memcpy(param->u.crypt.key, pext + 1, pext->key_len);
3414         }
3415
3416         if (pencoding->flags & IW_ENCODE_DISABLED)
3417         {
3418                 //todo: remove key 
3419                 //remove = 1;
3420         }
3421
3422         ret =  wpa_set_encryption(dev, param, param_len);
3423
3424 exit:
3425         if(param)
3426         {
3427                 rtw_mfree((u8*)param, param_len);
3428         }
3429
3430         return ret;
3431 }
3432
3433
3434 static int rtw_wx_get_nick(struct net_device *dev, 
3435                              struct iw_request_info *info, 
3436                              union iwreq_data *wrqu, char *extra)
3437 {       
3438         //_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3439          //struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3440          //struct security_priv *psecuritypriv = &padapter->securitypriv;
3441
3442         if(extra)
3443         {
3444                 wrqu->data.length = 14;
3445                 wrqu->data.flags = 1;
3446                 _rtw_memcpy(extra, "<WIFI@REALTEK>", 14);
3447         }
3448
3449         //rtw_signal_process(pid, SIGUSR1); //for test
3450
3451         //dump debug info here  
3452 /*
3453         u32 dot11AuthAlgrthm;           // 802.11 auth, could be open, shared, and 8021x
3454         u32 dot11PrivacyAlgrthm;        // This specify the privacy for shared auth. algorithm.
3455         u32 dot118021XGrpPrivacy;       // This specify the privacy algthm. used for Grp key 
3456         u32 ndisauthtype;
3457         u32 ndisencryptstatus;
3458 */
3459
3460         //DBG_871X("auth_alg=0x%x, enc_alg=0x%x, auth_type=0x%x, enc_type=0x%x\n", 
3461         //              psecuritypriv->dot11AuthAlgrthm, psecuritypriv->dot11PrivacyAlgrthm,
3462         //              psecuritypriv->ndisauthtype, psecuritypriv->ndisencryptstatus);
3463         
3464         //DBG_871X("enc_alg=0x%x\n", psecuritypriv->dot11PrivacyAlgrthm);
3465         //DBG_871X("auth_type=0x%x\n", psecuritypriv->ndisauthtype);
3466         //DBG_871X("enc_type=0x%x\n", psecuritypriv->ndisencryptstatus);
3467
3468 #if 0
3469         DBG_871X("dbg(0x210)=0x%x\n", rtw_read32(padapter, 0x210));
3470         DBG_871X("dbg(0x608)=0x%x\n", rtw_read32(padapter, 0x608));
3471         DBG_871X("dbg(0x280)=0x%x\n", rtw_read32(padapter, 0x280));
3472         DBG_871X("dbg(0x284)=0x%x\n", rtw_read32(padapter, 0x284));
3473         DBG_871X("dbg(0x288)=0x%x\n", rtw_read32(padapter, 0x288));
3474         
3475         DBG_871X("dbg(0x664)=0x%x\n", rtw_read32(padapter, 0x664));
3476
3477
3478         DBG_871X("\n");
3479
3480         DBG_871X("dbg(0x430)=0x%x\n", rtw_read32(padapter, 0x430));
3481         DBG_871X("dbg(0x438)=0x%x\n", rtw_read32(padapter, 0x438));
3482
3483         DBG_871X("dbg(0x440)=0x%x\n", rtw_read32(padapter, 0x440));
3484         
3485         DBG_871X("dbg(0x458)=0x%x\n", rtw_read32(padapter, 0x458));
3486         
3487         DBG_871X("dbg(0x484)=0x%x\n", rtw_read32(padapter, 0x484));
3488         DBG_871X("dbg(0x488)=0x%x\n", rtw_read32(padapter, 0x488));
3489         
3490         DBG_871X("dbg(0x444)=0x%x\n", rtw_read32(padapter, 0x444));
3491         DBG_871X("dbg(0x448)=0x%x\n", rtw_read32(padapter, 0x448));
3492         DBG_871X("dbg(0x44c)=0x%x\n", rtw_read32(padapter, 0x44c));
3493         DBG_871X("dbg(0x450)=0x%x\n", rtw_read32(padapter, 0x450));
3494 #endif
3495         
3496         return 0;
3497
3498 }
3499
3500 static int rtw_wx_read32(struct net_device *dev,
3501                             struct iw_request_info *info,
3502                             union iwreq_data *wrqu, char *extra)
3503 {
3504         PADAPTER padapter;
3505         struct iw_point *p;
3506         u16 len;
3507         u32 addr;
3508         u32 data32;
3509         u32 bytes;
3510         u8 *ptmp;
3511         int ret;
3512
3513
3514         ret = 0;
3515         padapter = (PADAPTER)rtw_netdev_priv(dev);
3516         p = &wrqu->data;
3517         len = p->length;
3518         if (0 == len)
3519                 return -EINVAL;
3520
3521         ptmp = (u8*)rtw_malloc(len);
3522         if (NULL == ptmp)
3523                 return -ENOMEM;
3524
3525         if (copy_from_user(ptmp, p->pointer, len)) {
3526                 ret = -EFAULT;
3527                 goto exit;
3528         }
3529
3530         bytes = 0;
3531         addr = 0;
3532         sscanf(ptmp, "%d,%x", &bytes, &addr);
3533
3534         switch (bytes) {
3535                 case 1:
3536                         data32 = rtw_read8(padapter, addr);
3537                         sprintf(extra, "0x%02X", data32);
3538                         break;
3539                 case 2:
3540                         data32 = rtw_read16(padapter, addr);
3541                         sprintf(extra, "0x%04X", data32);
3542                         break;
3543                 case 4:
3544                         data32 = rtw_read32(padapter, addr);
3545                         sprintf(extra, "0x%08X", data32);
3546                         break;
3547                 default:
3548                         DBG_871X(KERN_INFO "%s: usage> read [bytes],[address(hex)]\n", __func__);
3549                         ret = -EINVAL;
3550                         goto exit;
3551         }
3552         DBG_871X(KERN_INFO "%s: addr=0x%08X data=%s\n", __func__, addr, extra);
3553
3554 exit:
3555         rtw_mfree(ptmp, len);
3556
3557         return 0;
3558 }
3559
3560 static int rtw_wx_write32(struct net_device *dev,
3561                             struct iw_request_info *info,
3562                             union iwreq_data *wrqu, char *extra)
3563 {
3564         PADAPTER padapter = (PADAPTER)rtw_netdev_priv(dev);
3565
3566         u32 addr;
3567         u32 data32;
3568         u32 bytes;
3569
3570
3571         bytes = 0;
3572         addr = 0;
3573         data32 = 0;
3574         sscanf(extra, "%d,%x,%x", &bytes, &addr, &data32);
3575
3576         switch (bytes) {
3577                 case 1:
3578                         rtw_write8(padapter, addr, (u8)data32);
3579                         DBG_871X(KERN_INFO "%s: addr=0x%08X data=0x%02X\n", __func__, addr, (u8)data32);
3580                         break;
3581                 case 2:
3582                         rtw_write16(padapter, addr, (u16)data32);
3583                         DBG_871X(KERN_INFO "%s: addr=0x%08X data=0x%04X\n", __func__, addr, (u16)data32);
3584                         break;
3585                 case 4:
3586                         rtw_write32(padapter, addr, data32);
3587                         DBG_871X(KERN_INFO "%s: addr=0x%08X data=0x%08X\n", __func__, addr, data32);
3588                         break;
3589                 default:
3590                         DBG_871X(KERN_INFO "%s: usage> write [bytes],[address(hex)],[data(hex)]\n", __func__);
3591                         return -EINVAL;
3592         }
3593
3594         return 0;
3595 }
3596
3597 static int rtw_wx_read_rf(struct net_device *dev,
3598                             struct iw_request_info *info,
3599                             union iwreq_data *wrqu, char *extra)
3600 {
3601         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3602         u32 path, addr, data32;
3603
3604
3605         path = *(u32*)extra;
3606         addr = *((u32*)extra + 1);
3607         data32 = rtw_hal_read_rfreg(padapter, path, addr, 0xFFFFF);
3608 //      DBG_871X("%s: path=%d addr=0x%02x data=0x%05x\n", __func__, path, addr, data32);
3609         /*
3610          * IMPORTANT!!
3611          * Only when wireless private ioctl is at odd order,
3612          * "extra" would be copied to user space.
3613          */
3614         sprintf(extra, "0x%05x", data32);
3615
3616         return 0;
3617 }
3618
3619 static int rtw_wx_write_rf(struct net_device *dev,
3620                             struct iw_request_info *info,
3621                             union iwreq_data *wrqu, char *extra)
3622 {
3623         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3624         u32 path, addr, data32;
3625
3626
3627         path = *(u32*)extra;
3628         addr = *((u32*)extra + 1);
3629         data32 = *((u32*)extra + 2);
3630 //      DBG_871X("%s: path=%d addr=0x%02x data=0x%05x\n", __func__, path, addr, data32);
3631         rtw_hal_write_rfreg(padapter, path, addr, 0xFFFFF, data32);
3632
3633         return 0;
3634 }
3635
3636 static int rtw_wx_priv_null(struct net_device *dev, struct iw_request_info *a,
3637                  union iwreq_data *wrqu, char *b)
3638 {
3639         return -1;
3640 }
3641
3642 static int dummy(struct net_device *dev, struct iw_request_info *a,
3643                  union iwreq_data *wrqu, char *b)
3644 {
3645         //_adapter *padapter = (_adapter *)rtw_netdev_priv(dev);        
3646         //struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
3647
3648         //DBG_871X("cmd_code=%x, fwstate=0x%x\n", a->cmd, get_fwstate(pmlmepriv));
3649         
3650         return -1;
3651         
3652 }
3653
3654 static int rtw_wx_set_channel_plan(struct net_device *dev,
3655                                struct iw_request_info *info,
3656                                union iwreq_data *wrqu, char *extra)
3657 {
3658         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3659         struct registry_priv *pregistrypriv = &padapter->registrypriv;
3660         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3661         extern int rtw_channel_plan;
3662         u8 channel_plan_req = (u8) (*((int *)wrqu));
3663
3664         #if 0
3665         rtw_channel_plan = (int)wrqu->data.pointer;
3666         pregistrypriv->channel_plan = rtw_channel_plan;
3667         pmlmepriv->ChannelPlan = pregistrypriv->channel_plan;
3668         #endif
3669
3670         if (_SUCCESS == rtw_set_chplan_cmd(padapter, channel_plan_req, 1, 1)) {
3671                 DBG_871X("%s set channel_plan = 0x%02X\n", __func__, pmlmepriv->ChannelPlan);
3672         } else 
3673                 return -EPERM;
3674
3675         return 0;
3676 }
3677
3678 static int rtw_wx_set_mtk_wps_probe_ie(struct net_device *dev,
3679                 struct iw_request_info *a,
3680                 union iwreq_data *wrqu, char *b)
3681 {
3682 #ifdef CONFIG_PLATFORM_MT53XX
3683         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3684         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
3685
3686         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_notice_,
3687                  ("WLAN IOCTL: cmd_code=%x, fwstate=0x%x\n",
3688                   a->cmd, get_fwstate(pmlmepriv)));
3689 #endif
3690         return 0;
3691 }
3692
3693 static int rtw_wx_get_sensitivity(struct net_device *dev,
3694                                 struct iw_request_info *info,
3695                                 union iwreq_data *wrqu, char *buf)
3696 {
3697 #ifdef CONFIG_PLATFORM_MT53XX
3698         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3699
3700         //      Modified by Albert 20110914
3701         //      This is in dbm format for MTK platform.
3702         wrqu->qual.level = padapter->recvpriv.rssi;
3703         DBG_871X(" level = %u\n",  wrqu->qual.level );
3704 #endif
3705         return 0;
3706 }
3707
3708 static int rtw_wx_set_mtk_wps_ie(struct net_device *dev,
3709                                 struct iw_request_info *info,
3710                                 union iwreq_data *wrqu, char *extra)
3711 {
3712 #ifdef CONFIG_PLATFORM_MT53XX
3713         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3714
3715         return rtw_set_wpa_ie(padapter, wrqu->data.pointer, wrqu->data.length);
3716 #else
3717         return 0;
3718 #endif
3719 }
3720
3721 /*
3722 typedef int (*iw_handler)(struct net_device *dev, struct iw_request_info *info,
3723                           union iwreq_data *wrqu, char *extra);
3724 */
3725 /*
3726  *      For all data larger than 16 octets, we need to use a
3727  *      pointer to memory allocated in user space.
3728  */
3729 static  int rtw_drvext_hdl(struct net_device *dev, struct iw_request_info *info,
3730                                                 union iwreq_data *wrqu, char *extra)
3731 {
3732
3733  #if 0
3734 struct  iw_point
3735 {
3736   void __user   *pointer;       /* Pointer to the data  (in user space) */
3737   __u16         length;         /* number of fields or size in bytes */
3738   __u16         flags;          /* Optional params */
3739 };
3740  #endif
3741
3742 #ifdef CONFIG_DRVEXT_MODULE
3743         u8 res;
3744         struct drvext_handler *phandler;        
3745         struct drvext_oidparam *poidparam;              
3746         int ret;
3747         u16 len;
3748         u8 *pparmbuf, bset;
3749         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
3750         struct iw_point *p = &wrqu->data;
3751
3752         if( (!p->length) || (!p->pointer)){
3753                 ret = -EINVAL;
3754                 goto _rtw_drvext_hdl_exit;
3755         }
3756         
3757         
3758         bset = (u8)(p->flags&0xFFFF);
3759         len = p->length;
3760         pparmbuf = (u8*)rtw_malloc(len);
3761         if (pparmbuf == NULL){
3762                 ret = -ENOMEM;
3763                 goto _rtw_drvext_hdl_exit;
3764         }
3765         
3766         if(bset)//set info
3767         {
3768                 if (copy_from_user(pparmbuf, p->pointer,len)) {
3769                         rtw_mfree(pparmbuf, len);
3770                         ret = -EFAULT;
3771                         goto _rtw_drvext_hdl_exit;
3772                 }               
3773         }
3774         else//query info
3775         {
3776         
3777         }
3778
3779         
3780         //
3781         poidparam = (struct drvext_oidparam *)pparmbuf; 
3782         
3783         RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("drvext set oid subcode [%d], len[%d], InformationBufferLength[%d]\r\n",
3784                                                  poidparam->subcode, poidparam->len, len));
3785
3786
3787         //check subcode 
3788         if ( poidparam->subcode >= MAX_DRVEXT_HANDLERS)
3789         {
3790                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("no matching drvext handlers\r\n"));             
3791                 ret = -EINVAL;
3792                 goto _rtw_drvext_hdl_exit;
3793         }
3794
3795
3796         if ( poidparam->subcode >= MAX_DRVEXT_OID_SUBCODES)
3797         {
3798                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("no matching drvext subcodes\r\n"));             
3799                 ret = -EINVAL;
3800                 goto _rtw_drvext_hdl_exit;
3801         }
3802
3803
3804         phandler = drvextoidhandlers + poidparam->subcode;
3805
3806         if (poidparam->len != phandler->parmsize)
3807         {
3808                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_err_,("no matching drvext param size %d vs %d\r\n",                    
3809                                                 poidparam->len , phandler->parmsize));          
3810                 ret = -EINVAL;          
3811                 goto _rtw_drvext_hdl_exit;
3812         }
3813
3814
3815         res = phandler->handler(&padapter->drvextpriv, bset, poidparam->data);
3816
3817         if(res==0)
3818         {
3819                 ret = 0;
3820                         
3821                 if (bset == 0x00) {//query info
3822                         //_rtw_memcpy(p->pointer, pparmbuf, len);
3823                         if (copy_to_user(p->pointer, pparmbuf, len))
3824                                 ret = -EFAULT;
3825                 }               
3826         }               
3827         else
3828                 ret = -EFAULT;
3829
3830         
3831 _rtw_drvext_hdl_exit:   
3832         
3833         return ret;     
3834         
3835 #endif
3836
3837         return 0;
3838
3839 }
3840
3841 static void rtw_dbg_mode_hdl(_adapter *padapter, u32 id, u8 *pdata, u32 len)
3842 {
3843         pRW_Reg         RegRWStruct;
3844         struct rf_reg_param *prfreg;
3845         u8 path;
3846         u8 offset;
3847         u32 value;
3848
3849         DBG_871X("%s\n", __FUNCTION__);
3850
3851         switch(id)
3852         {
3853                 case GEN_MP_IOCTL_SUBCODE(MP_START):
3854                         DBG_871X("871x_driver is only for normal mode, can't enter mp mode\n");
3855                         break;
3856                 case GEN_MP_IOCTL_SUBCODE(READ_REG):
3857                         RegRWStruct = (pRW_Reg)pdata;
3858                         switch (RegRWStruct->width)
3859                         {
3860                                 case 1:
3861                                         RegRWStruct->value = rtw_read8(padapter, RegRWStruct->offset);
3862                                         break;
3863                                 case 2:
3864                                         RegRWStruct->value = rtw_read16(padapter, RegRWStruct->offset);
3865                                         break;
3866                                 case 4:
3867                                         RegRWStruct->value = rtw_read32(padapter, RegRWStruct->offset);
3868                                         break;
3869                                 default:
3870                                         break;
3871                         }
3872                 
3873                         break;
3874                 case GEN_MP_IOCTL_SUBCODE(WRITE_REG):
3875                         RegRWStruct = (pRW_Reg)pdata;
3876                         switch (RegRWStruct->width)
3877                         {
3878                                 case 1:
3879                                         rtw_write8(padapter, RegRWStruct->offset, (u8)RegRWStruct->value);
3880                                         break;
3881                                 case 2:
3882                                         rtw_write16(padapter, RegRWStruct->offset, (u16)RegRWStruct->value);
3883                                         break;
3884                                 case 4:
3885                                         rtw_write32(padapter, RegRWStruct->offset, (u32)RegRWStruct->value);
3886                                         break;
3887                                 default:                                        
3888                                 break;
3889                         }
3890                                 
3891                         break;
3892                 case GEN_MP_IOCTL_SUBCODE(READ_RF_REG):
3893
3894                         prfreg = (struct rf_reg_param *)pdata;
3895
3896                         path = (u8)prfreg->path;                
3897                         offset = (u8)prfreg->offset;    
3898
3899                         value = rtw_hal_read_rfreg(padapter, path, offset, 0xffffffff);
3900
3901                         prfreg->value = value;
3902
3903                         break;                  
3904                 case GEN_MP_IOCTL_SUBCODE(WRITE_RF_REG):
3905
3906                         prfreg = (struct rf_reg_param *)pdata;
3907
3908                         path = (u8)prfreg->path;
3909                         offset = (u8)prfreg->offset;    
3910                         value = prfreg->value;
3911
3912                         rtw_hal_write_rfreg(padapter, path, offset, 0xffffffff, value);
3913                         
3914                         break;                  
3915                 case GEN_MP_IOCTL_SUBCODE(TRIGGER_GPIO):
3916                         DBG_871X("==> trigger gpio 0\n");
3917                         rtw_hal_set_hwreg(padapter, HW_VAR_TRIGGER_GPIO_0, 0);
3918                         break;  
3919 #ifdef CONFIG_BT_COEXIST
3920                 case GEN_MP_IOCTL_SUBCODE(SET_DM_BT):                   
3921                         DBG_871X("==> set dm_bt_coexist:%x\n",*(u8 *)pdata);
3922                         rtw_hal_set_hwreg(padapter, HW_VAR_BT_SET_COEXIST, pdata);
3923                         break;
3924                 case GEN_MP_IOCTL_SUBCODE(DEL_BA):
3925                         DBG_871X("==> delete ba:%x\n",*(u8 *)pdata);
3926                         rtw_hal_set_hwreg(padapter, HW_VAR_BT_ISSUE_DELBA, pdata);
3927                         break;
3928 #endif
3929 #ifdef DBG_CONFIG_ERROR_DETECT
3930                 case GEN_MP_IOCTL_SUBCODE(GET_WIFI_STATUS):                                                     
3931                         *pdata = rtw_hal_sreset_get_wifi_status(padapter);                   
3932                         break;
3933 #endif
3934         
3935                 default:
3936                         break;
3937         }
3938         
3939 }
3940
3941 static int rtw_mp_ioctl_hdl(struct net_device *dev, struct iw_request_info *info,
3942                                                 union iwreq_data *wrqu, char *extra)
3943 {
3944         int ret = 0;
3945         u32 BytesRead, BytesWritten, BytesNeeded;
3946         struct oid_par_priv     oid_par;
3947         struct mp_ioctl_handler *phandler;
3948         struct mp_ioctl_param   *poidparam;
3949         uint status=0;
3950         u16 len;
3951         u8 *pparmbuf = NULL, bset;
3952         PADAPTER padapter = (PADAPTER)rtw_netdev_priv(dev);
3953         struct iw_point *p = &wrqu->data;
3954
3955         //DBG_871X("+rtw_mp_ioctl_hdl\n");
3956
3957         //mutex_lock(&ioctl_mutex);
3958
3959         if ((!p->length) || (!p->pointer)) {
3960                 ret = -EINVAL;
3961                 goto _rtw_mp_ioctl_hdl_exit;
3962         }
3963
3964         pparmbuf = NULL;
3965         bset = (u8)(p->flags & 0xFFFF);
3966         len = p->length;
3967         pparmbuf = (u8*)rtw_malloc(len);
3968         if (pparmbuf == NULL){
3969                 ret = -ENOMEM;
3970                 goto _rtw_mp_ioctl_hdl_exit;
3971         }
3972
3973         if (copy_from_user(pparmbuf, p->pointer, len)) {
3974                 ret = -EFAULT;
3975                 goto _rtw_mp_ioctl_hdl_exit;
3976         }
3977
3978         poidparam = (struct mp_ioctl_param *)pparmbuf;
3979         RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_info_,
3980                  ("rtw_mp_ioctl_hdl: subcode [%d], len[%d], buffer_len[%d]\r\n",
3981                   poidparam->subcode, poidparam->len, len));
3982
3983         if (poidparam->subcode >= MAX_MP_IOCTL_SUBCODE) {
3984                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_err_, ("no matching drvext subcodes\r\n"));
3985                 ret = -EINVAL;
3986                 goto _rtw_mp_ioctl_hdl_exit;
3987         }
3988
3989         //DBG_871X("%s: %d\n", __func__, poidparam->subcode);
3990 #ifdef CONFIG_MP_INCLUDED 
3991 if (padapter->registrypriv.mp_mode == 1)
3992 {       
3993         phandler = mp_ioctl_hdl + poidparam->subcode;
3994
3995         if ((phandler->paramsize != 0) && (poidparam->len < phandler->paramsize))
3996         {
3997                 RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_err_,
3998                          ("no matching drvext param size %d vs %d\r\n",
3999                           poidparam->len, phandler->paramsize));
4000                 ret = -EINVAL;
4001                 goto _rtw_mp_ioctl_hdl_exit;
4002         }
4003
4004         if (phandler->handler)
4005         {
4006                 oid_par.adapter_context = padapter;
4007                 oid_par.oid = phandler->oid;
4008                 oid_par.information_buf = poidparam->data;
4009                 oid_par.information_buf_len = poidparam->len;
4010                 oid_par.dbg = 0;
4011
4012                 BytesWritten = 0;
4013                 BytesNeeded = 0;
4014
4015                 if (bset) {
4016                         oid_par.bytes_rw = &BytesRead;
4017                         oid_par.bytes_needed = &BytesNeeded;
4018                         oid_par.type_of_oid = SET_OID;
4019                 } else {
4020                         oid_par.bytes_rw = &BytesWritten;
4021                         oid_par.bytes_needed = &BytesNeeded;
4022                         oid_par.type_of_oid = QUERY_OID;
4023                 }
4024
4025                 status = phandler->handler(&oid_par);
4026
4027                 //todo:check status, BytesNeeded, etc.
4028         }
4029         else {
4030                 DBG_871X("rtw_mp_ioctl_hdl(): err!, subcode=%d, oid=%d, handler=%p\n", 
4031                         poidparam->subcode, phandler->oid, phandler->handler);
4032                 ret = -EFAULT;
4033                 goto _rtw_mp_ioctl_hdl_exit;
4034         }
4035 }
4036 else
4037 #endif
4038 {
4039         rtw_dbg_mode_hdl(padapter, poidparam->subcode, poidparam->data, poidparam->len);
4040 }
4041
4042         if (bset == 0x00) {//query info
4043                 if (copy_to_user(p->pointer, pparmbuf, len))
4044                         ret = -EFAULT;
4045         }
4046
4047         if (status) {
4048                 ret = -EFAULT;
4049                 goto _rtw_mp_ioctl_hdl_exit;
4050         }
4051
4052 _rtw_mp_ioctl_hdl_exit:
4053
4054         if (pparmbuf)
4055                 rtw_mfree(pparmbuf, len);
4056
4057         //mutex_unlock(&ioctl_mutex);
4058
4059         return ret;
4060 }
4061
4062 static int rtw_get_ap_info(struct net_device *dev,
4063                                struct iw_request_info *info,
4064                                union iwreq_data *wrqu, char *extra)
4065 {
4066         int bssid_match, ret = 0;
4067         u32 cnt=0, wpa_ielen;
4068         _irqL   irqL;
4069         _list   *plist, *phead;
4070         unsigned char *pbuf;
4071         u8 bssid[ETH_ALEN];
4072         char data[32];
4073         struct wlan_network *pnetwork = NULL;
4074         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4075         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
4076         _queue *queue = &(pmlmepriv->scanned_queue);
4077         struct iw_point *pdata = &wrqu->data;   
4078
4079         DBG_871X("+rtw_get_aplist_info\n");
4080
4081         if((padapter->bDriverStopped) || (pdata==NULL))
4082         {                
4083                 ret= -EINVAL;
4084                 goto exit;
4085         }               
4086   
4087         while((check_fwstate(pmlmepriv, (_FW_UNDER_SURVEY|_FW_UNDER_LINKING))) == _TRUE)
4088         {       
4089                 rtw_msleep_os(30);
4090                 cnt++;
4091                 if(cnt > 100)
4092                         break;
4093         }
4094         
4095
4096         //pdata->length = 0;//? 
4097         pdata->flags = 0;
4098         if(pdata->length>=32)
4099         {
4100                 if(copy_from_user(data, pdata->pointer, 32))
4101                 {
4102                         ret= -EINVAL;
4103                         goto exit;
4104                 }
4105         }       
4106         else
4107         {
4108                 ret= -EINVAL;
4109                 goto exit;
4110         }       
4111
4112         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4113         
4114         phead = get_list_head(queue);
4115         plist = get_next(phead);
4116        
4117         while(1)
4118         {
4119                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
4120                         break;
4121
4122
4123                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
4124
4125                 //if(hwaddr_aton_i(pdata->pointer, bssid)) 
4126                 if(hwaddr_aton_i(data, bssid)) 
4127                 {                       
4128                         DBG_871X("Invalid BSSID '%s'.\n", (u8*)data);
4129                         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4130                         return -EINVAL;
4131                 }               
4132                 
4133         
4134                 if(_rtw_memcmp(bssid, pnetwork->network.MacAddress, ETH_ALEN) == _TRUE)//BSSID match, then check if supporting wpa/wpa2
4135                 {
4136                         DBG_871X("BSSID:" MAC_FMT "\n", MAC_ARG(bssid));
4137                         
4138                         pbuf = rtw_get_wpa_ie(&pnetwork->network.IEs[12], &wpa_ielen, pnetwork->network.IELength-12);                           
4139                         if(pbuf && (wpa_ielen>0))
4140                         {
4141                                 pdata->flags = 1;
4142                                 break;
4143                         }
4144
4145                         pbuf = rtw_get_wpa2_ie(&pnetwork->network.IEs[12], &wpa_ielen, pnetwork->network.IELength-12);
4146                         if(pbuf && (wpa_ielen>0))
4147                         {
4148                                 pdata->flags = 2;
4149                                 break;
4150                         }
4151                         
4152                 }
4153
4154                 plist = get_next(plist);                
4155         
4156         }        
4157
4158         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4159
4160         if(pdata->length>=34)
4161         {
4162                 if(copy_to_user((u8*)pdata->pointer+32, (u8*)&pdata->flags, 1))
4163                 {
4164                         ret= -EINVAL;
4165                         goto exit;
4166                 }
4167         }       
4168         
4169 exit:
4170         
4171         return ret;
4172                 
4173 }
4174
4175 static int rtw_set_pid(struct net_device *dev,
4176                                struct iw_request_info *info,
4177                                union iwreq_data *wrqu, char *extra)
4178 {
4179         
4180         int ret = 0;    
4181         _adapter *padapter = rtw_netdev_priv(dev);      
4182         int *pdata = (int *)wrqu;
4183         int selector;
4184
4185         if((padapter->bDriverStopped) || (pdata==NULL))
4186         {                
4187                 ret= -EINVAL;
4188                 goto exit;
4189         }               
4190   
4191         selector = *pdata;
4192         if(selector < 3 && selector >=0) {
4193                 padapter->pid[selector] = *(pdata+1);
4194                 #ifdef CONFIG_GLOBAL_UI_PID
4195                 ui_pid[selector] = *(pdata+1);
4196                 #endif
4197                 DBG_871X("%s set pid[%d]=%d\n", __FUNCTION__, selector ,padapter->pid[selector]);
4198         }
4199         else
4200                 DBG_871X("%s selector %d error\n", __FUNCTION__, selector);
4201
4202 exit:
4203         
4204         return ret;
4205                 
4206 }
4207
4208 static int rtw_wps_start(struct net_device *dev,
4209                                struct iw_request_info *info,
4210                                union iwreq_data *wrqu, char *extra)
4211 {
4212         
4213         int ret = 0;    
4214         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4215         struct iw_point *pdata = &wrqu->data;
4216         u32   u32wps_start = 0;
4217         unsigned int uintRet = 0;
4218
4219         if((_TRUE == padapter->bDriverStopped) ||(_TRUE==padapter->bSurpriseRemoved) || (NULL== pdata))
4220         {                
4221                 ret= -EINVAL;
4222                 goto exit;
4223         }               
4224
4225         uintRet = copy_from_user( ( void* ) &u32wps_start, pdata->pointer, 4 );
4226         if ( u32wps_start == 0 )
4227         {
4228                 u32wps_start = *extra;
4229         }
4230
4231         DBG_871X( "[%s] wps_start = %d\n", __FUNCTION__, u32wps_start );
4232
4233         if ( u32wps_start == 1 ) // WPS Start
4234         {
4235                 rtw_led_control(padapter, LED_CTL_START_WPS);
4236         }
4237         else if ( u32wps_start == 2 ) // WPS Stop because of wps success
4238         {
4239                 rtw_led_control(padapter, LED_CTL_STOP_WPS);
4240         }
4241         else if ( u32wps_start == 3 ) // WPS Stop because of wps fail
4242         {
4243                 rtw_led_control(padapter, LED_CTL_STOP_WPS_FAIL);
4244         }
4245
4246 #ifdef CONFIG_INTEL_WIDI
4247         process_intel_widi_wps_status(padapter, u32wps_start);
4248 #endif //CONFIG_INTEL_WIDI
4249         
4250 exit:
4251         
4252         return ret;
4253                 
4254 }
4255
4256 #ifdef CONFIG_P2P
4257 static int rtw_wext_p2p_enable(struct net_device *dev,
4258                                struct iw_request_info *info,
4259                                union iwreq_data *wrqu, char *extra)
4260 {
4261         
4262         int ret = 0;    
4263         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4264         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
4265         struct iw_point *pdata = &wrqu->data;
4266         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4267         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
4268         enum P2P_ROLE init_role = P2P_ROLE_DISABLE;
4269
4270         if(*extra == '0' )
4271                 init_role = P2P_ROLE_DISABLE;
4272         else if(*extra == '1')
4273                 init_role = P2P_ROLE_DEVICE;
4274         else if(*extra == '2')
4275                 init_role = P2P_ROLE_CLIENT;
4276         else if(*extra == '3')
4277                 init_role = P2P_ROLE_GO;
4278
4279         if(_FAIL == rtw_p2p_enable(padapter, init_role))
4280         {
4281                 ret = -EFAULT;
4282                 goto exit;
4283         }
4284
4285         //set channel/bandwidth
4286         if(init_role != P2P_ROLE_DISABLE) 
4287         {       
4288                 u8 channel, ch_offset;
4289                 u16 bwmode;
4290
4291                 if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_LISTEN))
4292                 {
4293                         //      Stay at the listen state and wait for discovery.
4294                         channel = pwdinfo->listen_channel;
4295                         pwdinfo->operating_channel = pwdinfo->listen_channel;
4296                         ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;
4297                         bwmode = CHANNEL_WIDTH_20;
4298                 }
4299 #ifdef CONFIG_CONCURRENT_MODE
4300                 else if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_IDLE))
4301                 {
4302                         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
4303                         //struct wifidirect_info        *pbuddy_wdinfo = &pbuddy_adapter->wdinfo;
4304                         struct mlme_priv                *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
4305                         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
4306                         
4307                         _set_timer( &pwdinfo->ap_p2p_switch_timer, pwdinfo->ext_listen_interval );
4308                         if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
4309                         {
4310                                 pwdinfo->operating_channel = pbuddy_mlmeext->cur_channel;
4311                                 //      How about the ch_offset and bwmode ??
4312                         }
4313                         else
4314                         {
4315                                 pwdinfo->operating_channel = pwdinfo->listen_channel;
4316                         }
4317
4318                         channel = pbuddy_mlmeext->cur_channel;
4319                         ch_offset = pbuddy_mlmeext->cur_ch_offset;
4320                         bwmode = pbuddy_mlmeext->cur_bwmode;
4321                 }
4322 #endif
4323                 else
4324                 {
4325                         pwdinfo->operating_channel = pmlmeext->cur_channel;
4326                 
4327                         channel = pwdinfo->operating_channel;
4328                         ch_offset = pmlmeext->cur_ch_offset;
4329                         bwmode = pmlmeext->cur_bwmode;                                          
4330                 }
4331
4332                 set_channel_bwmode(padapter, channel, ch_offset, bwmode);
4333         }
4334
4335 exit:
4336         return ret;
4337                 
4338 }
4339
4340 static int rtw_p2p_set_go_nego_ssid(struct net_device *dev,
4341                                struct iw_request_info *info,
4342                                union iwreq_data *wrqu, char *extra)
4343 {
4344         
4345         int ret = 0;    
4346         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4347         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
4348         struct iw_point *pdata = &wrqu->data;
4349         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4350
4351         DBG_871X( "[%s] ssid = %s, len = %zu\n", __FUNCTION__, extra, strlen( extra ) );
4352         _rtw_memcpy( pwdinfo->nego_ssid, extra, strlen( extra ) );
4353         pwdinfo->nego_ssidlen = strlen( extra );
4354         
4355         return ret;
4356                 
4357 }
4358
4359
4360 static int rtw_p2p_set_intent(struct net_device *dev,
4361                                struct iw_request_info *info,
4362                                union iwreq_data *wrqu, char *extra)
4363 {
4364         int                                                     ret = 0;
4365         _adapter                                                *padapter = (_adapter *)rtw_netdev_priv(dev);
4366         struct wifidirect_info                  *pwdinfo= &(padapter->wdinfo);
4367         u8                                                      intent = pwdinfo->intent;
4368
4369         extra[ wrqu->data.length ] = 0x00;
4370
4371         intent = rtw_atoi( extra );
4372
4373         if ( intent <= 15 )
4374         {
4375                 pwdinfo->intent= intent;
4376         }
4377         else
4378         {
4379                 ret = -1;
4380         }
4381         
4382         DBG_871X( "[%s] intent = %d\n", __FUNCTION__, intent);
4383
4384         return ret;
4385                 
4386 }
4387
4388 static int rtw_p2p_set_listen_ch(struct net_device *dev,
4389                                struct iw_request_info *info,
4390                                union iwreq_data *wrqu, char *extra)
4391 {
4392         
4393         int ret = 0;    
4394         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4395         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4396         u8      listen_ch = pwdinfo->listen_channel;    //      Listen channel number
4397
4398         extra[ wrqu->data.length ] = 0x00;
4399         listen_ch = rtw_atoi( extra );
4400
4401         if ( ( listen_ch == 1 ) || ( listen_ch == 6 ) || ( listen_ch == 11 ) )
4402         {
4403                 pwdinfo->listen_channel = listen_ch;
4404                 set_channel_bwmode(padapter, pwdinfo->listen_channel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
4405         }
4406         else
4407         {
4408                 ret = -1;
4409         }
4410         
4411         DBG_871X( "[%s] listen_ch = %d\n", __FUNCTION__, pwdinfo->listen_channel );
4412         
4413         return ret;
4414                 
4415 }
4416
4417 static int rtw_p2p_set_op_ch(struct net_device *dev,
4418                                struct iw_request_info *info,
4419                                union iwreq_data *wrqu, char *extra)
4420 {
4421 //      Commented by Albert 20110524
4422 //      This function is used to set the operating channel if the driver will become the group owner
4423
4424         int ret = 0;    
4425         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4426         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4427         u8      op_ch = pwdinfo->operating_channel;     //      Operating channel number
4428
4429         extra[ wrqu->data.length ] = 0x00;
4430
4431         op_ch = ( u8 ) rtw_atoi( extra );
4432         if ( op_ch > 0 )
4433         {
4434                 pwdinfo->operating_channel = op_ch;
4435         }
4436         else
4437         {
4438                 ret = -1;
4439         }
4440         
4441         DBG_871X( "[%s] op_ch = %d\n", __FUNCTION__, pwdinfo->operating_channel );
4442         
4443         return ret;
4444
4445 }
4446
4447
4448 static int rtw_p2p_profilefound(struct net_device *dev,
4449                                struct iw_request_info *info,
4450                                union iwreq_data *wrqu, char *extra)
4451 {
4452         
4453         int ret = 0;    
4454         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4455         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4456
4457         //      Comment by Albert 2010/10/13
4458         //      Input data format:
4459         //      Ex:  0
4460         //      Ex:  1XX:XX:XX:XX:XX:XXYYSSID
4461         //      0 => Reflush the profile record list.
4462         //      1 => Add the profile list
4463         //      XX:XX:XX:XX:XX:XX => peer's MAC Address ( ex: 00:E0:4C:00:00:01 )
4464         //      YY => SSID Length
4465         //      SSID => SSID for persistence group
4466
4467         DBG_871X( "[%s] In value = %s, len = %d \n", __FUNCTION__, extra, wrqu->data.length -1);
4468
4469         
4470         //      The upper application should pass the SSID to driver by using this rtw_p2p_profilefound function.
4471         if(!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
4472         {
4473                 if ( extra[ 0 ] == '0' )
4474                 {
4475                         //      Remove all the profile information of wifidirect_info structure.
4476                         _rtw_memset( &pwdinfo->profileinfo[ 0 ], 0x00, sizeof( struct profile_info ) * P2P_MAX_PERSISTENT_GROUP_NUM );
4477                         pwdinfo->profileindex = 0;
4478                 }
4479                 else
4480                 {
4481                         if ( pwdinfo->profileindex >= P2P_MAX_PERSISTENT_GROUP_NUM )
4482                 {
4483                                 ret = -1;
4484                 }
4485                 else
4486                 {
4487                                 int jj, kk;
4488                                 
4489                                 //      Add this profile information into pwdinfo->profileinfo
4490                                 //      Ex:  1XX:XX:XX:XX:XX:XXYYSSID
4491                                 for( jj = 0, kk = 1; jj < ETH_ALEN; jj++, kk += 3 )
4492                                 {
4493                                         pwdinfo->profileinfo[ pwdinfo->profileindex ].peermac[ jj ] = key_2char2num(extra[ kk ], extra[ kk+ 1 ]);
4494                                 }
4495
4496                                 //pwdinfo->profileinfo[ pwdinfo->profileindex ].ssidlen = ( extra[18] - '0' ) * 10 + ( extra[ 19 ] - '0' );
4497                                 //_rtw_memcpy( pwdinfo->profileinfo[ pwdinfo->profileindex ].ssid, &extra[ 20 ], pwdinfo->profileinfo[ pwdinfo->profileindex ].ssidlen );
4498                                 pwdinfo->profileindex++;
4499                         }
4500                 }
4501         }       
4502         
4503         return ret;
4504                 
4505 }
4506
4507 static int rtw_p2p_setDN(struct net_device *dev,
4508                                struct iw_request_info *info,
4509                                union iwreq_data *wrqu, char *extra)
4510 {
4511         
4512         int ret = 0;    
4513         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4514         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
4515
4516
4517         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
4518         _rtw_memset( pwdinfo->device_name, 0x00, WPS_MAX_DEVICE_NAME_LEN );
4519         _rtw_memcpy( pwdinfo->device_name, extra, wrqu->data.length - 1 );
4520         pwdinfo->device_name_len = wrqu->data.length - 1;
4521
4522         return ret;
4523                 
4524 }
4525
4526
4527 static int rtw_p2p_get_status(struct net_device *dev,
4528                                struct iw_request_info *info,
4529                                union iwreq_data *wrqu, char *extra)
4530 {
4531         
4532         int ret = 0;    
4533         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4534         struct iw_point *pdata = &wrqu->data;
4535         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4536 #ifdef CONFIG_CONCURRENT_MODE
4537         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
4538         struct wifidirect_info  *pbuddy_wdinfo = &pbuddy_adapter->wdinfo;
4539         struct mlme_priv                *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
4540         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv; 
4541 #endif
4542         
4543         if ( padapter->bShowGetP2PState )
4544         {
4545                 DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
4546                                 pwdinfo->p2p_peer_interface_addr[ 0 ], pwdinfo->p2p_peer_interface_addr[ 1 ], pwdinfo->p2p_peer_interface_addr[ 2 ],
4547                                 pwdinfo->p2p_peer_interface_addr[ 3 ], pwdinfo->p2p_peer_interface_addr[ 4 ], pwdinfo->p2p_peer_interface_addr[ 5 ]);
4548         }
4549
4550         //      Commented by Albert 2010/10/12
4551         //      Because of the output size limitation, I had removed the "Role" information.
4552         //      About the "Role" information, we will use the new private IOCTL to get the "Role" information.
4553         sprintf( extra, "\n\nStatus=%.2d\n", rtw_p2p_state(pwdinfo) );
4554         wrqu->data.length = strlen( extra );
4555
4556         return ret;
4557                 
4558 }
4559
4560 //      Commented by Albert 20110520
4561 //      This function will return the config method description 
4562 //      This config method description will show us which config method the remote P2P device is intented to use
4563 //      by sending the provisioning discovery request frame.
4564
4565 static int rtw_p2p_get_req_cm(struct net_device *dev,
4566                                struct iw_request_info *info,
4567                                union iwreq_data *wrqu, char *extra)
4568 {
4569         
4570         int ret = 0;    
4571         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4572         struct iw_point *pdata = &wrqu->data;
4573         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4574
4575         sprintf( extra, "\n\nCM=%s\n", pwdinfo->rx_prov_disc_info.strconfig_method_desc_of_prov_disc_req );
4576         wrqu->data.length = strlen( extra );
4577         return ret;
4578                 
4579 }
4580
4581
4582 static int rtw_p2p_get_role(struct net_device *dev,
4583                                struct iw_request_info *info,
4584                                union iwreq_data *wrqu, char *extra)
4585 {
4586         
4587         int ret = 0;    
4588         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4589         struct iw_point *pdata = &wrqu->data;
4590         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4591
4592         
4593         DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
4594                         pwdinfo->p2p_peer_interface_addr[ 0 ], pwdinfo->p2p_peer_interface_addr[ 1 ], pwdinfo->p2p_peer_interface_addr[ 2 ],
4595                         pwdinfo->p2p_peer_interface_addr[ 3 ], pwdinfo->p2p_peer_interface_addr[ 4 ], pwdinfo->p2p_peer_interface_addr[ 5 ]);
4596
4597         sprintf( extra, "\n\nRole=%.2d\n", rtw_p2p_role(pwdinfo) );
4598         wrqu->data.length = strlen( extra );
4599         return ret;
4600                 
4601 }
4602
4603
4604 static int rtw_p2p_get_peer_ifaddr(struct net_device *dev,
4605                                struct iw_request_info *info,
4606                                union iwreq_data *wrqu, char *extra)
4607 {
4608         
4609         int ret = 0;    
4610         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4611         struct iw_point *pdata = &wrqu->data;
4612         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4613
4614
4615         DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
4616                         pwdinfo->p2p_peer_interface_addr[ 0 ], pwdinfo->p2p_peer_interface_addr[ 1 ], pwdinfo->p2p_peer_interface_addr[ 2 ],
4617                         pwdinfo->p2p_peer_interface_addr[ 3 ], pwdinfo->p2p_peer_interface_addr[ 4 ], pwdinfo->p2p_peer_interface_addr[ 5 ]);
4618
4619         sprintf( extra, "\nMAC %.2X:%.2X:%.2X:%.2X:%.2X:%.2X",
4620                         pwdinfo->p2p_peer_interface_addr[ 0 ], pwdinfo->p2p_peer_interface_addr[ 1 ], pwdinfo->p2p_peer_interface_addr[ 2 ],
4621                         pwdinfo->p2p_peer_interface_addr[ 3 ], pwdinfo->p2p_peer_interface_addr[ 4 ], pwdinfo->p2p_peer_interface_addr[ 5 ]);
4622         wrqu->data.length = strlen( extra );
4623         return ret;
4624                 
4625 }
4626
4627 static int rtw_p2p_get_peer_devaddr(struct net_device *dev,
4628                                struct iw_request_info *info,
4629                                union iwreq_data *wrqu, char *extra)
4630
4631 {
4632         
4633         int ret = 0;    
4634         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4635         struct iw_point *pdata = &wrqu->data;
4636         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4637
4638         DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
4639                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 0 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 1 ], 
4640                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 2 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 3 ],
4641                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 4 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 5 ]);
4642         sprintf( extra, "\n%.2X%.2X%.2X%.2X%.2X%.2X",
4643                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 0 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 1 ], 
4644                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 2 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 3 ],
4645                         pwdinfo->rx_prov_disc_info.peerDevAddr[ 4 ], pwdinfo->rx_prov_disc_info.peerDevAddr[ 5 ]);
4646         wrqu->data.length = strlen( extra );    
4647         return ret;
4648                 
4649 }
4650
4651 static int rtw_p2p_get_peer_devaddr_by_invitation(struct net_device *dev,
4652                                struct iw_request_info *info,
4653                                union iwreq_data *wrqu, char *extra)
4654
4655 {
4656         
4657         int ret = 0;    
4658         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4659         struct iw_point *pdata = &wrqu->data;
4660         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4661
4662         DBG_871X( "[%s] Role = %d, Status = %d, peer addr = %.2X:%.2X:%.2X:%.2X:%.2X:%.2X\n", __FUNCTION__, rtw_p2p_role(pwdinfo), rtw_p2p_state(pwdinfo),
4663                         pwdinfo->p2p_peer_device_addr[ 0 ], pwdinfo->p2p_peer_device_addr[ 1 ], 
4664                         pwdinfo->p2p_peer_device_addr[ 2 ], pwdinfo->p2p_peer_device_addr[ 3 ],
4665                         pwdinfo->p2p_peer_device_addr[ 4 ], pwdinfo->p2p_peer_device_addr[ 5 ]);
4666         sprintf( extra, "\nMAC %.2X:%.2X:%.2X:%.2X:%.2X:%.2X",
4667                         pwdinfo->p2p_peer_device_addr[ 0 ], pwdinfo->p2p_peer_device_addr[ 1 ], 
4668                         pwdinfo->p2p_peer_device_addr[ 2 ], pwdinfo->p2p_peer_device_addr[ 3 ],
4669                         pwdinfo->p2p_peer_device_addr[ 4 ], pwdinfo->p2p_peer_device_addr[ 5 ]);
4670         wrqu->data.length = strlen( extra );    
4671         return ret;
4672                 
4673 }
4674
4675 static int rtw_p2p_get_groupid(struct net_device *dev,
4676                                struct iw_request_info *info,
4677                                union iwreq_data *wrqu, char *extra)
4678
4679 {
4680         
4681         int ret = 0;    
4682         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4683         struct iw_point *pdata = &wrqu->data;
4684         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4685
4686         sprintf( extra, "\n%.2X:%.2X:%.2X:%.2X:%.2X:%.2X %s",
4687                         pwdinfo->groupid_info.go_device_addr[ 0 ], pwdinfo->groupid_info.go_device_addr[ 1 ], 
4688                         pwdinfo->groupid_info.go_device_addr[ 2 ], pwdinfo->groupid_info.go_device_addr[ 3 ],
4689                         pwdinfo->groupid_info.go_device_addr[ 4 ], pwdinfo->groupid_info.go_device_addr[ 5 ],
4690                         pwdinfo->groupid_info.ssid);
4691         wrqu->data.length = strlen( extra );    
4692         return ret;
4693                 
4694 }
4695
4696 static int rtw_p2p_get_op_ch(struct net_device *dev,
4697                                struct iw_request_info *info,
4698                                union iwreq_data *wrqu, char *extra)
4699
4700 {
4701         
4702         int ret = 0;    
4703         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4704         struct iw_point *pdata = &wrqu->data;
4705         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4706
4707         
4708         DBG_871X( "[%s] Op_ch = %02x\n", __FUNCTION__, pwdinfo->operating_channel);
4709         
4710         sprintf( extra, "\n\nOp_ch=%.2d\n", pwdinfo->operating_channel );
4711         wrqu->data.length = strlen( extra );
4712         return ret;
4713                 
4714 }
4715
4716 static int rtw_p2p_get_wps_configmethod(struct net_device *dev,
4717                                                                                 struct iw_request_info *info,
4718                                                                                 union iwreq_data *wrqu, char *extra, char *subcmd)
4719
4720         
4721         int ret = 0;
4722         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4723         u8 peerMAC[ETH_ALEN] = { 0x00 };
4724         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
4725         _irqL irqL;
4726         _list * plist,*phead;
4727         _queue *queue = &(pmlmepriv->scanned_queue);
4728         struct wlan_network *pnetwork = NULL;
4729         u8 blnMatch = 0;
4730         u16     attr_content = 0;
4731         uint attr_contentlen = 0;
4732         u8      attr_content_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };
4733
4734         //      Commented by Albert 20110727
4735         //      The input data is the MAC address which the application wants to know its WPS config method.
4736         //      After knowing its WPS config method, the application can decide the config method for provisioning discovery.
4737         //      Format: iwpriv wlanx p2p_get_wpsCM 00:E0:4C:00:00:05
4738
4739         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
4740
4741         macstr2num(peerMAC, subcmd);
4742
4743         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4744
4745         phead = get_list_head(queue);
4746         plist = get_next(phead);
4747
4748         while (1)
4749         {
4750                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
4751
4752                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
4753                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
4754                 {
4755                         u8 *wpsie;
4756                         uint    wpsie_len = 0;
4757
4758                         //      The mac address is matched.
4759
4760                         if ( (wpsie=rtw_get_wps_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &wpsie_len, pnetwork->network.Reserved[0])) )
4761                         {
4762                                 rtw_get_wps_attr_content(wpsie, wpsie_len, WPS_ATTR_CONF_METHOD, (u8 *)&attr_content, &attr_contentlen);
4763                                 if (attr_contentlen)
4764                                 {
4765                                         attr_content = be16_to_cpu(attr_content);
4766                                         sprintf(attr_content_str, "\n\nM=%.4d", attr_content);
4767                                         blnMatch = 1;
4768                                 }
4769                         }
4770
4771                         break;
4772                 }
4773
4774                 plist = get_next(plist);
4775
4776         }
4777
4778         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4779
4780         if (!blnMatch)
4781         {
4782                 sprintf(attr_content_str, "\n\nM=0000");
4783         }
4784
4785         wrqu->data.length = strlen(attr_content_str);
4786         _rtw_memcpy(extra, attr_content_str, wrqu->data.length);
4787
4788         return ret; 
4789                 
4790 }
4791
4792 #ifdef CONFIG_WFD
4793 static int rtw_p2p_get_peer_wfd_port(struct net_device *dev,
4794                                struct iw_request_info *info,
4795                                union iwreq_data *wrqu, char *extra)
4796 {
4797         
4798         int ret = 0;    
4799         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4800         struct iw_point *pdata = &wrqu->data;
4801         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4802
4803         DBG_871X( "[%s] p2p_state = %d\n", __FUNCTION__, rtw_p2p_state(pwdinfo) );
4804
4805         sprintf( extra, "\n\nPort=%d\n", pwdinfo->wfd_info->peer_rtsp_ctrlport );
4806         DBG_871X( "[%s] remote port = %d\n", __FUNCTION__, pwdinfo->wfd_info->peer_rtsp_ctrlport );
4807         
4808         wrqu->data.length = strlen( extra );
4809         return ret;
4810                 
4811 }
4812
4813 static int rtw_p2p_get_peer_wfd_preferred_connection(struct net_device *dev,
4814                                struct iw_request_info *info,
4815                                union iwreq_data *wrqu, char *extra)
4816 {
4817         
4818         int ret = 0;    
4819         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4820         struct iw_point *pdata = &wrqu->data;
4821         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4822
4823         sprintf( extra, "\n\nwfd_pc=%d\n", pwdinfo->wfd_info->wfd_pc );
4824         DBG_871X( "[%s] wfd_pc = %d\n", __FUNCTION__, pwdinfo->wfd_info->wfd_pc );
4825
4826         wrqu->data.length = strlen( extra );
4827         pwdinfo->wfd_info->wfd_pc = _FALSE;     //      Reset the WFD preferred connection to P2P
4828         return ret;
4829                 
4830 }
4831
4832 static int rtw_p2p_get_peer_wfd_session_available(struct net_device *dev,
4833                                struct iw_request_info *info,
4834                                union iwreq_data *wrqu, char *extra)
4835 {
4836         
4837         int ret = 0;    
4838         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
4839         struct iw_point *pdata = &wrqu->data;
4840         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
4841
4842         sprintf( extra, "\n\nwfd_sa=%d\n", pwdinfo->wfd_info->peer_session_avail );
4843         DBG_871X( "[%s] wfd_sa = %d\n", __FUNCTION__, pwdinfo->wfd_info->peer_session_avail );
4844
4845         wrqu->data.length = strlen( extra );
4846         pwdinfo->wfd_info->peer_session_avail = _TRUE;  //      Reset the WFD session available
4847         return ret;
4848                 
4849 }
4850
4851 #endif // CONFIG_WFD
4852
4853 static int rtw_p2p_get_go_device_address(struct net_device *dev,
4854                                                                                  struct iw_request_info *info,
4855                                                                                  union iwreq_data *wrqu, char *extra, char *subcmd)
4856 {
4857
4858         int ret = 0;    
4859         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4860         u8 peerMAC[ETH_ALEN] = { 0x00 };
4861         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
4862         _irqL irqL;
4863         _list *plist, *phead;
4864         _queue *queue   = &(pmlmepriv->scanned_queue);
4865         struct wlan_network *pnetwork = NULL;
4866         u8 blnMatch = 0;
4867         u8 *p2pie;
4868         uint p2pielen = 0, attr_contentlen = 0;
4869         u8 attr_content[100] = { 0x00 };
4870         u8 go_devadd_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };
4871
4872         //      Commented by Albert 20121209
4873         //      The input data is the GO's interface address which the application wants to know its device address.
4874         //      Format: iwpriv wlanx p2p_get2 go_devadd=00:E0:4C:00:00:05
4875
4876         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
4877
4878         macstr2num(peerMAC, subcmd);
4879
4880         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4881
4882         phead = get_list_head(queue);
4883         plist = get_next(phead);
4884
4885         while (1)
4886         {
4887                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
4888
4889                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
4890                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
4891                 {
4892                         //      Commented by Albert 2011/05/18
4893                         //      Match the device address located in the P2P IE
4894                         //      This is for the case that the P2P device address is not the same as the P2P interface address.
4895
4896                         if ((p2pie = rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
4897                         {
4898                                 while (p2pie)
4899                                 {
4900                                         //      The P2P Device ID attribute is included in the Beacon frame.
4901                                         //      The P2P Device Info attribute is included in the probe response frame.
4902
4903                                         _rtw_memset(attr_content, 0x00, 100);
4904                                         if (rtw_get_p2p_attr_content(p2pie, p2pielen, P2P_ATTR_DEVICE_ID, attr_content, &attr_contentlen))
4905                                         {
4906                                                 //      Handle the P2P Device ID attribute of Beacon first
4907                                                 blnMatch = 1;
4908                                                 break;
4909
4910                                         } else if (rtw_get_p2p_attr_content(p2pie, p2pielen, P2P_ATTR_DEVICE_INFO, attr_content, &attr_contentlen))
4911                                         {
4912                                                 //      Handle the P2P Device Info attribute of probe response
4913                                                 blnMatch = 1;
4914                                                 break;
4915                                         }
4916
4917                                         //Get the next P2P IE
4918                                         p2pie = rtw_get_p2p_ie(p2pie + p2pielen, pnetwork->network.IELength - 12 - (p2pie - &pnetwork->network.IEs[12] + p2pielen), NULL, &p2pielen);
4919                                 }
4920                         }
4921                 }
4922
4923                 plist = get_next(plist);
4924
4925         }
4926
4927         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4928
4929         if (!blnMatch)
4930         {
4931                 sprintf(go_devadd_str, "\n\ndev_add=NULL");
4932         } else
4933         {
4934                 sprintf(go_devadd_str, "\n\ndev_add=%.2X:%.2X:%.2X:%.2X:%.2X:%.2X",
4935                                 attr_content[0], attr_content[1], attr_content[2], attr_content[3], attr_content[4], attr_content[5]);
4936         }
4937
4938         wrqu->data.length = strlen(go_devadd_str);
4939         _rtw_memcpy(extra, go_devadd_str, wrqu->data.length);
4940
4941         return ret; 
4942                 
4943 }
4944
4945 static int rtw_p2p_get_device_type(struct net_device *dev,
4946                                                                    struct iw_request_info *info,
4947                                                                    union iwreq_data *wrqu, char *extra, char *subcmd)
4948
4949         
4950         int ret = 0;
4951         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
4952         u8 peerMAC[ETH_ALEN] = { 0x00 };
4953         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
4954         _irqL irqL;
4955         _list *plist, *phead;
4956         _queue *queue = &(pmlmepriv->scanned_queue);
4957         struct wlan_network *pnetwork = NULL;
4958         u8 blnMatch = 0;
4959         u8 dev_type[8] = { 0x00 };
4960         uint dev_type_len = 0;
4961         u8 dev_type_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };    // +9 is for the str "dev_type=", we have to clear it at wrqu->data.pointer
4962
4963         //      Commented by Albert 20121209
4964         //      The input data is the MAC address which the application wants to know its device type.
4965         //      Such user interface could know the device type.
4966         //      Format: iwpriv wlanx p2p_get2 dev_type=00:E0:4C:00:00:05
4967
4968         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
4969
4970         macstr2num(peerMAC, subcmd);
4971
4972         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
4973
4974         phead = get_list_head(queue);
4975         plist = get_next(phead);
4976
4977         while (1)
4978         {
4979                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
4980
4981                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
4982                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
4983                 {
4984                         u8 *wpsie;
4985                         uint    wpsie_len = 0;
4986
4987                         //      The mac address is matched.
4988
4989                         if ( (wpsie=rtw_get_wps_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &wpsie_len, pnetwork->network.Reserved[0])) )
4990                         {
4991                                 rtw_get_wps_attr_content(wpsie, wpsie_len, WPS_ATTR_PRIMARY_DEV_TYPE, dev_type, &dev_type_len);
4992                                 if (dev_type_len)
4993                                 {
4994                                         u16     type = 0;
4995
4996                                         _rtw_memcpy(&type, dev_type, 2);
4997                                         type = be16_to_cpu(type);
4998                                         sprintf(dev_type_str, "\n\nN=%.2d", type);
4999                                         blnMatch = 1;
5000                                 }
5001                         }
5002                         break;
5003                 }
5004
5005                 plist = get_next(plist);
5006
5007         }
5008
5009         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5010
5011         if (!blnMatch)
5012         {
5013                 sprintf(dev_type_str, "\n\nN=00");
5014         }
5015
5016         wrqu->data.length = strlen(dev_type_str);
5017         _rtw_memcpy(extra, dev_type_str, wrqu->data.length);
5018
5019         return ret; 
5020                 
5021 }
5022
5023 static int rtw_p2p_get_device_name(struct net_device *dev,
5024                                                                    struct iw_request_info *info,
5025                                                                    union iwreq_data *wrqu, char *extra, char *subcmd)
5026
5027         
5028         int ret = 0;
5029         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5030         u8 peerMAC[ETH_ALEN] = { 0x00 };
5031         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5032         _irqL irqL;
5033         _list *plist, *phead;
5034         _queue *queue = &(pmlmepriv->scanned_queue);
5035         struct wlan_network *pnetwork = NULL;
5036         u8 blnMatch = 0;
5037         u8 dev_name[WPS_MAX_DEVICE_NAME_LEN] = { 0x00 };
5038         uint dev_len = 0;
5039         u8 dev_name_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };
5040
5041         //      Commented by Albert 20121225
5042         //      The input data is the MAC address which the application wants to know its device name.
5043         //      Such user interface could show peer device's device name instead of ssid.
5044         //      Format: iwpriv wlanx p2p_get2 devN=00:E0:4C:00:00:05
5045
5046         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
5047
5048         macstr2num(peerMAC, subcmd);
5049
5050         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5051
5052         phead = get_list_head(queue);
5053         plist = get_next(phead);
5054
5055         while (1)
5056         {
5057                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
5058
5059                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5060                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
5061                 {
5062                         u8 *wpsie;
5063                         uint    wpsie_len = 0;
5064
5065                         //      The mac address is matched.
5066
5067                         if ( (wpsie=rtw_get_wps_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &wpsie_len, pnetwork->network.Reserved[0])) )
5068                         {
5069                                 rtw_get_wps_attr_content(wpsie, wpsie_len, WPS_ATTR_DEVICE_NAME, dev_name, &dev_len);
5070                                 if (dev_len)
5071                                 {
5072                                         sprintf(dev_name_str, "\n\nN=%s", dev_name);
5073                                         blnMatch = 1;
5074                                 }
5075                         }
5076                         break;
5077                 }
5078
5079                 plist = get_next(plist);
5080
5081         }
5082
5083         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5084
5085         if (!blnMatch)
5086         {
5087                 sprintf(dev_name_str, "\n\nN=0000");
5088         }
5089
5090         wrqu->data.length = strlen(dev_name_str);
5091         _rtw_memcpy(extra, dev_name_str, wrqu->data.length);
5092
5093         return ret; 
5094                 
5095 }
5096
5097 static int rtw_p2p_get_invitation_procedure(struct net_device *dev,
5098                                                                                         struct iw_request_info *info,
5099                                                                                         union iwreq_data *wrqu, char *extra, char *subcmd)
5100 {
5101
5102         int ret = 0;    
5103         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5104         u8 peerMAC[ETH_ALEN] = { 0x00 };
5105         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
5106         _irqL irqL;
5107         _list *plist, *phead;
5108         _queue *queue   = &(pmlmepriv->scanned_queue);
5109         struct wlan_network *pnetwork = NULL;
5110         u8 blnMatch = 0;
5111         u8 *p2pie;
5112         uint p2pielen = 0, attr_contentlen = 0;
5113         u8 attr_content[2] = { 0x00 };
5114         u8 inv_proc_str[P2P_PRIVATE_IOCTL_SET_LEN] = { 0x00 };
5115
5116         //      Commented by Ouden 20121226
5117         //      The application wants to know P2P initation procedure is support or not.
5118         //      Format: iwpriv wlanx p2p_get2 InvProc=00:E0:4C:00:00:05
5119
5120         DBG_871X("[%s] data = %s\n", __FUNCTION__, subcmd);
5121
5122         macstr2num(peerMAC, subcmd);
5123
5124         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5125
5126         phead = get_list_head(queue);
5127         plist = get_next(phead);
5128
5129         while (1)
5130         {
5131                 if (rtw_end_of_queue_search(phead, plist) == _TRUE) break;
5132
5133                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5134                 if (_rtw_memcmp(pnetwork->network.MacAddress, peerMAC, ETH_ALEN))
5135                 {
5136                         //      Commented by Albert 20121226
5137                         //      Match the device address located in the P2P IE
5138                         //      This is for the case that the P2P device address is not the same as the P2P interface address.
5139
5140                         if ((p2pie = rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
5141                         {
5142                                 while (p2pie)
5143                                 {
5144                                         //_rtw_memset( attr_content, 0x00, 2);
5145                                         if (rtw_get_p2p_attr_content(p2pie, p2pielen, P2P_ATTR_CAPABILITY, attr_content, &attr_contentlen))
5146                                         {
5147                                                 //      Handle the P2P capability attribute
5148                                                 blnMatch = 1;
5149                                                 break;
5150
5151                                         }
5152
5153                                         //Get the next P2P IE
5154                                         p2pie = rtw_get_p2p_ie(p2pie + p2pielen, pnetwork->network.IELength - 12 - (p2pie - &pnetwork->network.IEs[12] + p2pielen), NULL, &p2pielen);
5155                                 }
5156                         }
5157                 }
5158
5159                 plist = get_next(plist);
5160
5161         }
5162
5163         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5164
5165         if (!blnMatch)
5166         {
5167                 sprintf(inv_proc_str, "\nIP=-1");
5168         } else
5169         {
5170                 if (attr_content[0] && 0x20)
5171                 {
5172                         sprintf(inv_proc_str, "\nIP=1");
5173                 } else
5174                 {
5175                         sprintf(inv_proc_str, "\nIP=0");
5176                 }
5177         }
5178
5179         wrqu->data.length = strlen(inv_proc_str);
5180         _rtw_memcpy(extra, inv_proc_str, wrqu->data.length);
5181
5182         return ret; 
5183                 
5184 }
5185
5186 static int rtw_p2p_connect(struct net_device *dev,
5187                                struct iw_request_info *info,
5188                                union iwreq_data *wrqu, char *extra)
5189 {
5190         
5191         int ret = 0;    
5192         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);   
5193         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5194         u8                                      peerMAC[ ETH_ALEN ] = { 0x00 };
5195         int                                     jj,kk;
5196         u8                                      peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
5197         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
5198         _irqL                           irqL;
5199         _list                                   *plist, *phead;
5200         _queue                          *queue  = &(pmlmepriv->scanned_queue);
5201         struct  wlan_network    *pnetwork = NULL;
5202         uint                                    uintPeerChannel = 0;
5203 #ifdef CONFIG_CONCURRENT_MODE
5204         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
5205         struct mlme_priv                *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
5206         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
5207 #endif // CONFIG_CONCURRENT_MODE        
5208
5209         //      Commented by Albert 20110304
5210         //      The input data contains two informations.
5211         //      1. First information is the MAC address which wants to formate with
5212         //      2. Second information is the WPS PINCode or "pbc" string for push button method
5213         //      Format: 00:E0:4C:00:00:05
5214         //      Format: 00:E0:4C:00:00:05
5215
5216         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
5217
5218         if ( pwdinfo->p2p_state == P2P_STATE_NONE )
5219         {
5220                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
5221                 return ret;
5222         }
5223         
5224         if ( pwdinfo->ui_got_wps_info == P2P_NO_WPSINFO )
5225         {
5226                 return -1;
5227         }
5228         
5229         for( jj = 0, kk = 0; jj < ETH_ALEN; jj++, kk += 3 )
5230         {
5231                 peerMAC[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
5232         }
5233
5234         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5235
5236         phead = get_list_head(queue);
5237         plist = get_next(phead);
5238        
5239         while(1)
5240         {
5241                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
5242                         break;
5243
5244                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5245                 if ( _rtw_memcmp( pnetwork->network.MacAddress, peerMAC, ETH_ALEN ) )
5246                 {
5247                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
5248                         break;
5249                 }
5250
5251                 plist = get_next(plist);
5252         
5253         }
5254
5255         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5256
5257         if ( uintPeerChannel )
5258         {
5259 #ifdef CONFIG_CONCURRENT_MODE
5260                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
5261                 {
5262                         _cancel_timer_ex( &pwdinfo->ap_p2p_switch_timer );
5263                 }
5264 #endif // CONFIG_CONCURRENT_MODE
5265
5266                 _rtw_memset( &pwdinfo->nego_req_info, 0x00, sizeof( struct tx_nego_req_info ) );
5267                 _rtw_memset( &pwdinfo->groupid_info, 0x00, sizeof( struct group_id_info ) );
5268                 
5269                 pwdinfo->nego_req_info.peer_channel_num[ 0 ] = uintPeerChannel;
5270                 _rtw_memcpy( pwdinfo->nego_req_info.peerDevAddr, pnetwork->network.MacAddress, ETH_ALEN );
5271                 pwdinfo->nego_req_info.benable = _TRUE;
5272
5273                 _cancel_timer_ex( &pwdinfo->restore_p2p_state_timer );
5274                 if ( rtw_p2p_state(pwdinfo) != P2P_STATE_GONEGO_OK )
5275                 {
5276                         //      Restore to the listen state if the current p2p state is not nego OK
5277                         rtw_p2p_set_state(pwdinfo, P2P_STATE_LISTEN );
5278                 }
5279
5280                 rtw_p2p_set_pre_state(pwdinfo, rtw_p2p_state(pwdinfo));
5281                 rtw_p2p_set_state(pwdinfo, P2P_STATE_GONEGO_ING);
5282
5283 #ifdef CONFIG_CONCURRENT_MODE
5284                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
5285                 {
5286                         //      Have to enter the power saving with the AP
5287                         set_channel_bwmode(padapter, pbuddy_mlmeext->cur_channel, pbuddy_mlmeext->cur_ch_offset, pbuddy_mlmeext->cur_bwmode);
5288                         
5289                         issue_nulldata(pbuddy_adapter, NULL, 1, 3, 500);
5290                 }
5291 #endif // CONFIG_CONCURRENT_MODE
5292
5293                 DBG_871X( "[%s] Start PreTx Procedure!\n", __FUNCTION__ );
5294                 _set_timer( &pwdinfo->pre_tx_scan_timer, P2P_TX_PRESCAN_TIMEOUT );
5295 #ifdef CONFIG_CONCURRENT_MODE
5296                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
5297                 {
5298                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_CONCURRENT_GO_NEGO_TIMEOUT );
5299                 }
5300                 else
5301                 {
5302                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_GO_NEGO_TIMEOUT );
5303                 }
5304 #else
5305                 _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_GO_NEGO_TIMEOUT );
5306 #endif // CONFIG_CONCURRENT_MODE                
5307
5308         }
5309         else
5310         {
5311                 DBG_871X( "[%s] Not Found in Scanning Queue~\n", __FUNCTION__ );
5312                 ret = -1;
5313         }
5314 exit:   
5315         return ret;
5316 }
5317
5318 static int rtw_p2p_invite_req(struct net_device *dev,
5319                                struct iw_request_info *info,
5320                                union iwreq_data *wrqu, char *extra)
5321 {
5322         
5323         int ret = 0;    
5324         _adapter                                        *padapter = (_adapter *)rtw_netdev_priv(dev);   
5325         struct iw_point                         *pdata = &wrqu->data;
5326         struct wifidirect_info          *pwdinfo = &( padapter->wdinfo );
5327         int                                             jj,kk;
5328         u8                                              peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
5329         struct mlme_priv                        *pmlmepriv = &padapter->mlmepriv;
5330         _list                                           *plist, *phead;
5331         _queue                                  *queue  = &(pmlmepriv->scanned_queue);
5332         struct  wlan_network            *pnetwork = NULL;
5333         uint                                            uintPeerChannel = 0;
5334         u8                                              attr_content[50] = { 0x00 }, _status = 0;
5335         u8                                              *p2pie;
5336         uint                                            p2pielen = 0, attr_contentlen = 0;
5337         _irqL                                   irqL;
5338         struct tx_invite_req_info*      pinvite_req_info = &pwdinfo->invitereq_info;
5339         u8 ie_offset = 12;
5340 #ifdef CONFIG_CONCURRENT_MODE
5341         _adapter                                        *pbuddy_adapter = padapter->pbuddy_adapter;
5342         struct mlme_priv                        *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
5343         struct mlme_ext_priv            *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
5344 #endif // CONFIG_CONCURRENT_MODE
5345
5346 #ifdef CONFIG_WFD
5347         struct wifi_display_info*       pwfd_info = pwdinfo->wfd_info;
5348 #endif // CONFIG_WFD
5349         
5350         //      Commented by Albert 20120321
5351         //      The input data contains two informations.
5352         //      1. First information is the P2P device address which you want to send to.       
5353         //      2. Second information is the group id which combines with GO's mac address, space and GO's ssid.
5354         //      Command line sample: iwpriv wlan0 p2p_set invite="00:11:22:33:44:55 00:E0:4C:00:00:05 DIRECT-xy"
5355         //      Format: 00:11:22:33:44:55 00:E0:4C:00:00:05 DIRECT-xy
5356
5357         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
5358
5359         if ( wrqu->data.length <=  37 )
5360         {
5361                 DBG_871X( "[%s] Wrong format!\n", __FUNCTION__ );
5362                 return ret;
5363         }
5364
5365         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
5366         {
5367                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
5368                 return ret;
5369         }
5370         else
5371         {
5372                 //      Reset the content of struct tx_invite_req_info
5373                 pinvite_req_info->benable = _FALSE;
5374                 _rtw_memset( pinvite_req_info->go_bssid, 0x00, ETH_ALEN );
5375                 _rtw_memset( pinvite_req_info->go_ssid, 0x00, WLAN_SSID_MAXLEN );
5376                 pinvite_req_info->ssidlen = 0x00;
5377                 pinvite_req_info->operating_ch = pwdinfo->operating_channel;
5378                 _rtw_memset( pinvite_req_info->peer_macaddr, 0x00, ETH_ALEN );
5379                 pinvite_req_info->token = 3;
5380         }
5381         
5382         for( jj = 0, kk = 0; jj < ETH_ALEN; jj++, kk += 3 )
5383         {
5384                 pinvite_req_info->peer_macaddr[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
5385         }
5386
5387         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5388
5389         phead = get_list_head(queue);
5390         plist = get_next(phead);
5391        
5392         while(1)
5393         {
5394                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
5395                         break;
5396
5397                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5398
5399                 //      Commented by Albert 2011/05/18
5400                 //      Match the device address located in the P2P IE
5401                 //      This is for the case that the P2P device address is not the same as the P2P interface address.
5402
5403                 ie_offset = (pnetwork->network.Reserved[0] == 2? 0:12);
5404                 if ( (p2pie=rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
5405                 {
5406                         //      The P2P Device ID attribute is included in the Beacon frame.
5407                         //      The P2P Device Info attribute is included in the probe response frame.
5408
5409                         if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_ID, attr_content, &attr_contentlen) )
5410                         {
5411                                 //      Handle the P2P Device ID attribute of Beacon first
5412                                 if ( _rtw_memcmp( attr_content, pinvite_req_info->peer_macaddr, ETH_ALEN ) )
5413                                 {
5414                                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
5415                                         break;
5416                                 }
5417                         }
5418                         else if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_INFO, attr_content, &attr_contentlen) )
5419                         {
5420                                 //      Handle the P2P Device Info attribute of probe response
5421                                 if ( _rtw_memcmp( attr_content, pinvite_req_info->peer_macaddr, ETH_ALEN ) )
5422                                 {
5423                                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
5424                                         break;
5425                                 }                                       
5426                         }
5427
5428                 }
5429
5430                 plist = get_next(plist);
5431         
5432         }
5433
5434         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5435
5436 #ifdef CONFIG_WFD
5437         if ( uintPeerChannel )
5438         {
5439                 u8      wfd_ie[ 128 ] = { 0x00 };
5440                 uint    wfd_ielen = 0;
5441                 
5442                 if ( rtw_get_wfd_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength,  wfd_ie, &wfd_ielen, pnetwork->network.Reserved[0]) )
5443                 {
5444                         u8      wfd_devinfo[ 6 ] = { 0x00 };
5445                         uint    wfd_devlen = 6;
5446
5447                         DBG_871X( "[%s] Found WFD IE!\n", __FUNCTION__ );
5448                         if ( rtw_get_wfd_attr_content( wfd_ie, wfd_ielen, WFD_ATTR_DEVICE_INFO, wfd_devinfo, &wfd_devlen ) )
5449                         {
5450                                 u16     wfd_devinfo_field = 0;
5451                                 
5452                                 //      Commented by Albert 20120319
5453                                 //      The first two bytes are the WFD device information field of WFD device information subelement.
5454                                 //      In big endian format.
5455                                 wfd_devinfo_field = RTW_GET_BE16(wfd_devinfo);
5456                                 if ( wfd_devinfo_field & WFD_DEVINFO_SESSION_AVAIL )
5457                                 {
5458                                         pwfd_info->peer_session_avail = _TRUE;
5459                                 }
5460                                 else
5461                                 {
5462                                         pwfd_info->peer_session_avail = _FALSE;
5463                                 }
5464                         }
5465                 }
5466                 
5467                 if ( _FALSE == pwfd_info->peer_session_avail )
5468                 {
5469                         DBG_871X( "[%s] WFD Session not avaiable!\n", __FUNCTION__ );
5470                         goto exit;
5471                 }
5472         }
5473 #endif // CONFIG_WFD
5474
5475         if ( uintPeerChannel )
5476         {
5477 #ifdef CONFIG_CONCURRENT_MODE
5478                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
5479                 {
5480                         _cancel_timer_ex( &pwdinfo->ap_p2p_switch_timer );
5481                 }
5482 #endif // CONFIG_CONCURRENT_MODE
5483
5484                 //      Store the GO's bssid
5485                 for( jj = 0, kk = 18; jj < ETH_ALEN; jj++, kk += 3 )
5486                 {
5487                         pinvite_req_info->go_bssid[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
5488                 }
5489
5490                 //      Store the GO's ssid
5491                 pinvite_req_info->ssidlen = wrqu->data.length - 36;
5492                 _rtw_memcpy( pinvite_req_info->go_ssid, &extra[ 36 ], (u32) pinvite_req_info->ssidlen );
5493                 pinvite_req_info->benable = _TRUE;
5494                 pinvite_req_info->peer_ch = uintPeerChannel;
5495
5496                 rtw_p2p_set_pre_state(pwdinfo, rtw_p2p_state(pwdinfo));
5497                 rtw_p2p_set_state(pwdinfo, P2P_STATE_TX_INVITE_REQ);
5498
5499 #ifdef CONFIG_CONCURRENT_MODE
5500                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
5501                 {
5502                         //      Have to enter the power saving with the AP
5503                         set_channel_bwmode(padapter, pbuddy_mlmeext->cur_channel, pbuddy_mlmeext->cur_ch_offset, pbuddy_mlmeext->cur_bwmode);
5504                         
5505                         issue_nulldata(pbuddy_adapter, NULL, 1, 3, 500);
5506                 }
5507                 else
5508                 {
5509                         set_channel_bwmode(padapter, uintPeerChannel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
5510                 }
5511 #else
5512                 set_channel_bwmode(padapter, uintPeerChannel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
5513 #endif
5514
5515                 _set_timer( &pwdinfo->pre_tx_scan_timer, P2P_TX_PRESCAN_TIMEOUT );
5516                 
5517 #ifdef CONFIG_CONCURRENT_MODE
5518                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
5519                 {
5520                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_CONCURRENT_INVITE_TIMEOUT );
5521                 }
5522                 else
5523                 {
5524                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_INVITE_TIMEOUT );
5525                 }
5526 #else
5527                 _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_INVITE_TIMEOUT );
5528 #endif // CONFIG_CONCURRENT_MODE                
5529
5530                 
5531         }
5532         else
5533         {
5534                 DBG_871X( "[%s] NOT Found in the Scanning Queue!\n", __FUNCTION__ );
5535         }
5536 exit:
5537         
5538         return ret;
5539                 
5540 }
5541
5542 static int rtw_p2p_set_persistent(struct net_device *dev,
5543                                struct iw_request_info *info,
5544                                union iwreq_data *wrqu, char *extra)
5545 {
5546         
5547         int ret = 0;    
5548         _adapter                                        *padapter = (_adapter *)rtw_netdev_priv(dev);   
5549         struct iw_point                         *pdata = &wrqu->data;
5550         struct wifidirect_info          *pwdinfo = &( padapter->wdinfo );
5551         int                                             jj,kk;
5552         u8                                              peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
5553         struct mlme_priv                        *pmlmepriv = &padapter->mlmepriv;
5554         _list                                           *plist, *phead;
5555         _queue                                  *queue  = &(pmlmepriv->scanned_queue);
5556         struct  wlan_network            *pnetwork = NULL;
5557         uint                                            uintPeerChannel = 0;
5558         u8                                              attr_content[50] = { 0x00 }, _status = 0;
5559         u8                                              *p2pie;
5560         uint                                            p2pielen = 0, attr_contentlen = 0;
5561         _irqL                                   irqL;
5562         struct tx_invite_req_info*      pinvite_req_info = &pwdinfo->invitereq_info;
5563 #ifdef CONFIG_CONCURRENT_MODE
5564         _adapter                                        *pbuddy_adapter = padapter->pbuddy_adapter;
5565         struct mlme_priv                        *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
5566         struct mlme_ext_priv            *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
5567 #endif // CONFIG_CONCURRENT_MODE
5568
5569 #ifdef CONFIG_WFD
5570         struct wifi_display_info*       pwfd_info = pwdinfo->wfd_info;
5571 #endif // CONFIG_WFD
5572         
5573         //      Commented by Albert 20120328
5574         //      The input data is 0 or 1
5575         //      0: disable persistent group functionality
5576         //      1: enable persistent group founctionality
5577         
5578         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
5579
5580         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
5581         {
5582                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
5583                 return ret;
5584         }
5585         else
5586         {
5587                 if ( extra[ 0 ] == '0' )        //      Disable the persistent group function.
5588                 {
5589                         pwdinfo->persistent_supported = _FALSE;
5590                 }
5591                 else if ( extra[ 0 ] == '1' )   //      Enable the persistent group function.
5592                 {
5593                         pwdinfo->persistent_supported = _TRUE;
5594                 }
5595                 else
5596                 {
5597                         pwdinfo->persistent_supported = _FALSE;
5598                 }
5599         }
5600         printk( "[%s] persistent_supported = %d\n", __FUNCTION__, pwdinfo->persistent_supported );
5601         
5602 exit:
5603         
5604         return ret;
5605                 
5606 }
5607
5608 static int hexstr2bin(const char *hex, u8 *buf, size_t len)
5609 {
5610         size_t i;
5611         int a;
5612         const char *ipos = hex;
5613         u8 *opos = buf;
5614
5615         for (i = 0; i < len; i++) {
5616                 a = hex2byte_i(ipos);
5617                 if (a < 0)
5618                         return -1;
5619                 *opos++ = a;
5620                 ipos += 2;
5621         }
5622         return 0;
5623 }
5624
5625 static int uuid_str2bin(const char *str, u8 *bin)
5626 {
5627         const char *pos;
5628         u8 *opos;
5629
5630         pos = str;
5631         opos = bin;
5632
5633         if (hexstr2bin(pos, opos, 4))
5634                 return -1;
5635         pos += 8;
5636         opos += 4;
5637
5638         if (*pos++ != '-' || hexstr2bin(pos, opos, 2))
5639                 return -1;
5640         pos += 4;
5641         opos += 2;
5642
5643         if (*pos++ != '-' || hexstr2bin(pos, opos, 2))
5644                 return -1;
5645         pos += 4;
5646         opos += 2;
5647
5648         if (*pos++ != '-' || hexstr2bin(pos, opos, 2))
5649                 return -1;
5650         pos += 4;
5651         opos += 2;
5652
5653         if (*pos++ != '-' || hexstr2bin(pos, opos, 6))
5654                 return -1;
5655
5656         return 0;
5657 }
5658
5659 static int rtw_p2p_set_wps_uuid(struct net_device *dev,
5660         struct iw_request_info *info,
5661         union iwreq_data *wrqu, char *extra)
5662 {
5663
5664         int ret = 0;
5665         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);
5666         struct wifidirect_info                  *pwdinfo = &(padapter->wdinfo);
5667
5668         DBG_871X("[%s] data = %s\n", __FUNCTION__, extra);
5669
5670         if ((36 == strlen(extra)) && (uuid_str2bin(extra, pwdinfo->uuid) == 0)) 
5671         {
5672                 pwdinfo->external_uuid = 1;
5673         } else {
5674                 pwdinfo->external_uuid = 0;
5675                 ret = -EINVAL;
5676         }
5677
5678         return ret;
5679
5680 }
5681 #ifdef CONFIG_WFD
5682 static int rtw_p2p_set_pc(struct net_device *dev,
5683                                struct iw_request_info *info,
5684                                union iwreq_data *wrqu, char *extra)
5685 {
5686         
5687         int ret = 0;    
5688         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);   
5689         struct iw_point                 *pdata = &wrqu->data;
5690         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5691         u8                                      peerMAC[ ETH_ALEN ] = { 0x00 };
5692         int                                     jj,kk;
5693         u8                                      peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
5694         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
5695         _list                                   *plist, *phead;
5696         _queue                          *queue  = &(pmlmepriv->scanned_queue);
5697         struct  wlan_network    *pnetwork = NULL;
5698         u8                                      attr_content[50] = { 0x00 }, _status = 0;
5699         u8 *p2pie;
5700         uint                                    p2pielen = 0, attr_contentlen = 0;
5701         _irqL                           irqL;
5702         uint                                    uintPeerChannel = 0;
5703 #ifdef CONFIG_CONCURRENT_MODE
5704         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
5705         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
5706 #endif // CONFIG_CONCURRENT_MODE        
5707         
5708         struct wifi_display_info*       pwfd_info = pwdinfo->wfd_info;
5709         
5710         //      Commented by Albert 20120512
5711         //      1. Input information is the MAC address which wants to know the Preferred Connection bit (PC bit)
5712         //      Format: 00:E0:4C:00:00:05
5713
5714         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
5715
5716         if(rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE))
5717         {
5718                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
5719                 return ret;
5720         }
5721         
5722         for( jj = 0, kk = 0; jj < ETH_ALEN; jj++, kk += 3 )
5723         {
5724                 peerMAC[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
5725         }
5726
5727         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5728
5729         phead = get_list_head(queue);
5730         plist = get_next(phead);
5731        
5732         while(1)
5733         {
5734                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
5735                         break;
5736
5737                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
5738
5739                 //      Commented by Albert 2011/05/18
5740                 //      Match the device address located in the P2P IE
5741                 //      This is for the case that the P2P device address is not the same as the P2P interface address.
5742
5743                 if ( (p2pie=rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
5744                 {
5745                         //      The P2P Device ID attribute is included in the Beacon frame.
5746                         //      The P2P Device Info attribute is included in the probe response frame.
5747                         printk( "[%s] Got P2P IE\n", __FUNCTION__ );
5748                         if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_ID, attr_content, &attr_contentlen) )
5749                         {
5750                                 //      Handle the P2P Device ID attribute of Beacon first
5751                                 printk( "[%s] P2P_ATTR_DEVICE_ID \n", __FUNCTION__ );
5752                                 if ( _rtw_memcmp( attr_content, peerMAC, ETH_ALEN ) )
5753                                 {
5754                                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
5755                                         break;
5756                                 }
5757                         }
5758                         else if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_INFO, attr_content, &attr_contentlen) )
5759                         {
5760                                 //      Handle the P2P Device Info attribute of probe response
5761                                 printk( "[%s] P2P_ATTR_DEVICE_INFO \n", __FUNCTION__ );
5762                                 if ( _rtw_memcmp( attr_content, peerMAC, ETH_ALEN ) )
5763                                 {
5764                                         uintPeerChannel = pnetwork->network.Configuration.DSConfig;
5765                                         break;
5766                                 }                                       
5767                         }
5768
5769                 }
5770
5771                 plist = get_next(plist);
5772         
5773         }
5774
5775         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
5776         printk( "[%s] channel = %d\n", __FUNCTION__, uintPeerChannel );
5777
5778         if ( uintPeerChannel )
5779         {
5780                 u8      wfd_ie[ 128 ] = { 0x00 };
5781                 uint    wfd_ielen = 0;
5782                 u8 ie_offset = (pnetwork->network.Reserved[0] == 2 ? 0:12);
5783
5784                 if ( rtw_get_wfd_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength,  wfd_ie, &wfd_ielen, pnetwork->network.Reserved[0]) )
5785                 {
5786                         u8      wfd_devinfo[ 6 ] = { 0x00 };
5787                         uint    wfd_devlen = 6;
5788
5789                         DBG_871X( "[%s] Found WFD IE!\n", __FUNCTION__ );
5790                         if ( rtw_get_wfd_attr_content( wfd_ie, wfd_ielen, WFD_ATTR_DEVICE_INFO, wfd_devinfo, &wfd_devlen ) )
5791                         {
5792                                 u16     wfd_devinfo_field = 0;
5793                                 
5794                                 //      Commented by Albert 20120319
5795                                 //      The first two bytes are the WFD device information field of WFD device information subelement.
5796                                 //      In big endian format.
5797                                 wfd_devinfo_field = RTW_GET_BE16(wfd_devinfo);
5798                                 if ( wfd_devinfo_field & WFD_DEVINFO_PC_TDLS )
5799                                 {
5800                                         pwfd_info->wfd_pc = _TRUE;
5801                                 }
5802                                 else
5803                                 {
5804                                         pwfd_info->wfd_pc = _FALSE;
5805                                 }
5806                         }
5807                 }
5808         }       
5809         else
5810         {
5811                 DBG_871X( "[%s] NOT Found in the Scanning Queue!\n", __FUNCTION__ );
5812         }
5813
5814 exit:
5815         
5816         return ret;
5817                 
5818 }
5819
5820 static int rtw_p2p_set_wfd_device_type(struct net_device *dev,
5821                                struct iw_request_info *info,
5822                                union iwreq_data *wrqu, char *extra)
5823 {
5824         
5825         int ret = 0;    
5826         _adapter                                        *padapter = (_adapter *)rtw_netdev_priv(dev);   
5827         struct iw_point                         *pdata = &wrqu->data;
5828         struct wifidirect_info          *pwdinfo = &( padapter->wdinfo );
5829         struct wifi_display_info                *pwfd_info = pwdinfo->wfd_info;
5830         
5831         //      Commented by Albert 20120328
5832         //      The input data is 0 or 1
5833         //      0: specify to Miracast source device
5834         //      1 or others: specify to Miracast sink device (display device)
5835         
5836         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
5837
5838         if ( extra[ 0 ] == '0' )        //      Set to Miracast source device.
5839         {
5840                 pwfd_info->wfd_device_type = WFD_DEVINFO_SOURCE;
5841         }
5842         else                                    //      Set to Miracast sink device.
5843         {
5844                 pwfd_info->wfd_device_type = WFD_DEVINFO_PSINK;
5845         }
5846
5847 exit:
5848         
5849         return ret;
5850                 
5851 }
5852
5853 static int rtw_p2p_set_wfd_enable(struct net_device *dev,
5854                                struct iw_request_info *info,
5855                                union iwreq_data *wrqu, char *extra)
5856 {
5857 //      Commented by Kurt 20121206
5858 //      This function is used to set wfd enabled
5859
5860         int ret = 0;    
5861         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5862         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
5863
5864         if(*extra == '0' )
5865                 pwdinfo->wfd_info->wfd_enable = _FALSE;
5866         else if(*extra == '1')
5867                 pwdinfo->wfd_info->wfd_enable = _TRUE;
5868
5869         DBG_871X( "[%s] wfd_enable = %d\n", __FUNCTION__, pwdinfo->wfd_info->wfd_enable );
5870         
5871         return ret;
5872                 
5873 }
5874
5875 static int rtw_p2p_set_driver_iface(struct net_device *dev,
5876                                struct iw_request_info *info,
5877                                union iwreq_data *wrqu, char *extra)
5878 {
5879 //      Commented by Kurt 20121206
5880 //      This function is used to set driver iface is WEXT or CFG80211
5881         int ret = 0;    
5882         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
5883         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
5884
5885         if(*extra == '1' )
5886         {
5887                 pwdinfo->driver_interface = DRIVER_WEXT;
5888                 DBG_871X( "[%s] driver_interface = WEXT\n", __FUNCTION__);
5889         }
5890         else if(*extra == '2')
5891         {
5892                 pwdinfo->driver_interface = DRIVER_CFG80211;
5893                 DBG_871X( "[%s] driver_interface = CFG80211\n", __FUNCTION__);
5894         }
5895         
5896         return ret;
5897                 
5898 }
5899
5900 //      To set the WFD session available to enable or disable
5901 static int rtw_p2p_set_sa(struct net_device *dev,
5902                                struct iw_request_info *info,
5903                                union iwreq_data *wrqu, char *extra)
5904 {
5905         
5906         int ret = 0;    
5907         _adapter                                        *padapter = (_adapter *)rtw_netdev_priv(dev);   
5908         struct iw_point                         *pdata = &wrqu->data;
5909         struct wifidirect_info          *pwdinfo = &( padapter->wdinfo );
5910         struct wifi_display_info                *pwfd_info = pwdinfo->wfd_info;
5911         
5912         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
5913
5914         if( 0 )
5915         {
5916                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
5917                 return ret;
5918         }
5919         else
5920         {
5921                 if ( extra[ 0 ] == '0' )        //      Disable the session available.
5922                 {
5923                         pwdinfo->session_available = _FALSE;
5924                 }
5925                 else if ( extra[ 0 ] == '1' )   //      Enable the session available.
5926                 {
5927                         pwdinfo->session_available = _TRUE;
5928                 }
5929                 else
5930                 {
5931                         pwdinfo->session_available = _FALSE;
5932                 }
5933         }
5934         printk( "[%s] session available = %d\n", __FUNCTION__, pwdinfo->session_available );
5935         
5936 exit:
5937         
5938         return ret;
5939                 
5940 }
5941 #endif // CONFIG_WFD
5942
5943 static int rtw_p2p_prov_disc(struct net_device *dev,
5944                                struct iw_request_info *info,
5945                                union iwreq_data *wrqu, char *extra)
5946 {
5947         int ret = 0;    
5948         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);   
5949         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
5950         u8                                      peerMAC[ ETH_ALEN ] = { 0x00 };
5951         int                                     jj,kk;
5952         u8                                      peerMACStr[ ETH_ALEN * 2 ] = { 0x00 };
5953         struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;
5954         _list                                   *plist, *phead;
5955         _queue                          *queue  = &(pmlmepriv->scanned_queue);
5956         struct  wlan_network    *pnetwork = NULL;
5957         uint                                    uintPeerChannel = 0;
5958         u8                                      attr_content[100] = { 0x00 }, _status = 0;
5959         u8 *p2pie;
5960         uint                                    p2pielen = 0, attr_contentlen = 0;
5961         _irqL                           irqL;
5962         u8                                      ie_offset = 12;
5963 #ifdef CONFIG_CONCURRENT_MODE
5964         _adapter                                *pbuddy_adapter = padapter->pbuddy_adapter;
5965         struct mlme_priv                *pbuddy_mlmepriv = &pbuddy_adapter->mlmepriv;
5966         struct mlme_ext_priv    *pbuddy_mlmeext = &pbuddy_adapter->mlmeextpriv;
5967 #endif // CONFIG_CONCURRENT_MODE        
5968 #ifdef CONFIG_WFD
5969         struct wifi_display_info*       pwfd_info = pwdinfo->wfd_info;
5970 #endif // CONFIG_WFD
5971
5972         //      Commented by Albert 20110301
5973         //      The input data contains two informations.
5974         //      1. First information is the MAC address which wants to issue the provisioning discovery request frame.
5975         //      2. Second information is the WPS configuration method which wants to discovery
5976         //      Format: 00:E0:4C:00:00:05_display
5977         //      Format: 00:E0:4C:00:00:05_keypad
5978         //      Format: 00:E0:4C:00:00:05_pbc
5979         //      Format: 00:E0:4C:00:00:05_label
5980
5981         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
5982
5983         if ( pwdinfo->p2p_state == P2P_STATE_NONE )
5984         {
5985                 DBG_871X( "[%s] WiFi Direct is disable!\n", __FUNCTION__ );
5986                 return ret;
5987         }
5988         else
5989         {
5990 #ifdef CONFIG_INTEL_WIDI
5991                 if(check_fwstate(pmlmepriv, _FW_UNDER_SURVEY) == _TRUE){
5992                         DBG_871X( "[%s] WiFi is under survey!\n", __FUNCTION__ );
5993                         return ret;
5994                 }
5995 #endif //CONFIG_INTEL_WIDI
5996
5997                 //      Reset the content of struct tx_provdisc_req_info excluded the wps_config_method_request.
5998                 _rtw_memset( pwdinfo->tx_prov_disc_info.peerDevAddr, 0x00, ETH_ALEN );
5999                 _rtw_memset( pwdinfo->tx_prov_disc_info.peerIFAddr, 0x00, ETH_ALEN );
6000                 _rtw_memset( &pwdinfo->tx_prov_disc_info.ssid, 0x00, sizeof( NDIS_802_11_SSID ) );              
6001                 pwdinfo->tx_prov_disc_info.peer_channel_num[ 0 ] = 0;
6002                 pwdinfo->tx_prov_disc_info.peer_channel_num[ 1 ] = 0;
6003                 pwdinfo->tx_prov_disc_info.benable = _FALSE;
6004         }
6005         
6006         for( jj = 0, kk = 0; jj < ETH_ALEN; jj++, kk += 3 )
6007         {
6008                 peerMAC[ jj ] = key_2char2num( extra[kk], extra[kk+ 1] );
6009         }
6010
6011         if ( _rtw_memcmp( &extra[ 18 ], "display", 7 ) )
6012         {
6013                 pwdinfo->tx_prov_disc_info.wps_config_method_request = WPS_CM_DISPLYA;
6014         }
6015         else if ( _rtw_memcmp( &extra[ 18 ], "keypad", 7 ) )
6016         {
6017                 pwdinfo->tx_prov_disc_info.wps_config_method_request = WPS_CM_KEYPAD;
6018         }
6019         else if ( _rtw_memcmp( &extra[ 18 ], "pbc", 3 ) )
6020         {
6021                 pwdinfo->tx_prov_disc_info.wps_config_method_request = WPS_CM_PUSH_BUTTON;
6022         }
6023         else if ( _rtw_memcmp( &extra[ 18 ], "label", 5 ) )
6024         {
6025                 pwdinfo->tx_prov_disc_info.wps_config_method_request = WPS_CM_LABEL;
6026         }
6027         else
6028         {
6029                 DBG_871X( "[%s] Unknown WPS config methodn", __FUNCTION__ );
6030                 return( ret );
6031         }
6032
6033         _enter_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
6034
6035         phead = get_list_head(queue);
6036         plist = get_next(phead);
6037        
6038         while(1)
6039         {
6040                 if (rtw_end_of_queue_search(phead,plist)== _TRUE)
6041                         break;
6042
6043                 if( uintPeerChannel != 0 )
6044                         break;
6045
6046                 pnetwork = LIST_CONTAINOR(plist, struct wlan_network, list);
6047
6048                 //      Commented by Albert 2011/05/18
6049                 //      Match the device address located in the P2P IE
6050                 //      This is for the case that the P2P device address is not the same as the P2P interface address.
6051
6052                 ie_offset = (pnetwork->network.Reserved[0] == 2? 0:12);
6053                 if ( (p2pie=rtw_get_p2p_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength, NULL, &p2pielen, pnetwork->network.Reserved[0])))
6054                 {
6055                         while ( p2pie )
6056                         {
6057                                 //      The P2P Device ID attribute is included in the Beacon frame.
6058                                 //      The P2P Device Info attribute is included in the probe response frame.
6059
6060                                 if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_ID, attr_content, &attr_contentlen) )
6061                                 {
6062                                         //      Handle the P2P Device ID attribute of Beacon first
6063                                         if ( _rtw_memcmp( attr_content, peerMAC, ETH_ALEN ) )
6064                                         {
6065                                                 uintPeerChannel = pnetwork->network.Configuration.DSConfig;
6066                                                 break;
6067                                         }
6068                                 }
6069                                 else if ( rtw_get_p2p_attr_content( p2pie, p2pielen, P2P_ATTR_DEVICE_INFO, attr_content, &attr_contentlen) )
6070                                 {
6071                                         //      Handle the P2P Device Info attribute of probe response
6072                                         if ( _rtw_memcmp( attr_content, peerMAC, ETH_ALEN ) )
6073                                         {
6074                                                 uintPeerChannel = pnetwork->network.Configuration.DSConfig;
6075                                                 break;
6076                                         }                                       
6077                                 }
6078
6079                                 //Get the next P2P IE
6080                                 p2pie = rtw_get_p2p_ie(p2pie+p2pielen, pnetwork->network.IELength - ie_offset -(p2pie -&pnetwork->network.IEs[ie_offset] + p2pielen), NULL, &p2pielen);
6081                         }
6082
6083                 }
6084
6085 #ifdef CONFIG_INTEL_WIDI
6086                 // Some Intel WiDi source may not provide P2P IE, 
6087                 // so we could only compare mac addr by 802.11 Source Address
6088                 if( pmlmepriv->widi_state == INTEL_WIDI_STATE_WFD_CONNECTION 
6089                         && uintPeerChannel == 0 )
6090                 {
6091                         if ( _rtw_memcmp( pnetwork->network.MacAddress, peerMAC, ETH_ALEN ) )
6092                         {
6093                                 uintPeerChannel = pnetwork->network.Configuration.DSConfig;
6094                                 break;
6095                         }
6096                 }
6097 #endif //CONFIG_INTEL_WIDI
6098
6099                 plist = get_next(plist);
6100         
6101         }
6102
6103         _exit_critical_bh(&(pmlmepriv->scanned_queue.lock), &irqL);
6104
6105         if ( uintPeerChannel )
6106         {
6107 #ifdef CONFIG_WFD
6108                 {
6109                         u8      wfd_ie[ 128 ] = { 0x00 };
6110                         uint    wfd_ielen = 0;
6111                         
6112                         if ( rtw_get_wfd_ie_from_scan_queue( &pnetwork->network.IEs[0], pnetwork->network.IELength,  wfd_ie, &wfd_ielen, pnetwork->network.Reserved[0]) )
6113                         {
6114                                 u8      wfd_devinfo[ 6 ] = { 0x00 };
6115                                 uint    wfd_devlen = 6;
6116
6117                                 DBG_871X( "[%s] Found WFD IE!\n", __FUNCTION__ );
6118                                 if ( rtw_get_wfd_attr_content( wfd_ie, wfd_ielen, WFD_ATTR_DEVICE_INFO, wfd_devinfo, &wfd_devlen ) )
6119                                 {
6120                                         u16     wfd_devinfo_field = 0;
6121                                         
6122                                         //      Commented by Albert 20120319
6123                                         //      The first two bytes are the WFD device information field of WFD device information subelement.
6124                                         //      In big endian format.
6125                                         wfd_devinfo_field = RTW_GET_BE16(wfd_devinfo);
6126                                         if ( wfd_devinfo_field & WFD_DEVINFO_SESSION_AVAIL )
6127                                         {
6128                                                 pwfd_info->peer_session_avail = _TRUE;
6129                                         }
6130                                         else
6131                                         {
6132                                                 pwfd_info->peer_session_avail = _FALSE;
6133                                         }
6134                                 }
6135                         }
6136                         
6137                         if ( _FALSE == pwfd_info->peer_session_avail )
6138                         {
6139                                 DBG_871X( "[%s] WFD Session not avaiable!\n", __FUNCTION__ );
6140                                 goto exit;
6141                         }
6142                 }
6143 #endif // CONFIG_WFD
6144                 
6145                 DBG_871X( "[%s] peer channel: %d!\n", __FUNCTION__, uintPeerChannel );
6146 #ifdef CONFIG_CONCURRENT_MODE
6147                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
6148                 {
6149                         _cancel_timer_ex( &pwdinfo->ap_p2p_switch_timer );
6150                 }
6151 #endif // CONFIG_CONCURRENT_MODE
6152                 _rtw_memcpy( pwdinfo->tx_prov_disc_info.peerIFAddr, pnetwork->network.MacAddress, ETH_ALEN );
6153                 _rtw_memcpy( pwdinfo->tx_prov_disc_info.peerDevAddr, peerMAC, ETH_ALEN );
6154                 pwdinfo->tx_prov_disc_info.peer_channel_num[0] = ( u16 ) uintPeerChannel;
6155                 pwdinfo->tx_prov_disc_info.benable = _TRUE;
6156                 rtw_p2p_set_pre_state(pwdinfo, rtw_p2p_state(pwdinfo));
6157                 rtw_p2p_set_state(pwdinfo, P2P_STATE_TX_PROVISION_DIS_REQ);
6158
6159                 if(rtw_p2p_chk_role(pwdinfo, P2P_ROLE_CLIENT))
6160                 {
6161                         _rtw_memcpy( &pwdinfo->tx_prov_disc_info.ssid, &pnetwork->network.Ssid, sizeof( NDIS_802_11_SSID ) );
6162                 }
6163                 else if(rtw_p2p_chk_role(pwdinfo, P2P_ROLE_DEVICE) || rtw_p2p_chk_role(pwdinfo, P2P_ROLE_GO))
6164                 {
6165                         _rtw_memcpy( pwdinfo->tx_prov_disc_info.ssid.Ssid, pwdinfo->p2p_wildcard_ssid, P2P_WILDCARD_SSID_LEN );
6166                         pwdinfo->tx_prov_disc_info.ssid.SsidLength= P2P_WILDCARD_SSID_LEN;
6167                 }
6168
6169 #ifdef CONFIG_CONCURRENT_MODE
6170                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
6171                 {
6172                         //      Have to enter the power saving with the AP
6173                         set_channel_bwmode(padapter, pbuddy_mlmeext->cur_channel, pbuddy_mlmeext->cur_ch_offset, pbuddy_mlmeext->cur_bwmode);
6174                         
6175                         issue_nulldata(pbuddy_adapter, NULL, 1, 3, 500);
6176                 }
6177                 else
6178                 {
6179                         set_channel_bwmode(padapter, uintPeerChannel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
6180                 }
6181 #else
6182                 set_channel_bwmode(padapter, uintPeerChannel, HAL_PRIME_CHNL_OFFSET_DONT_CARE, CHANNEL_WIDTH_20);
6183 #endif
6184
6185                 _set_timer( &pwdinfo->pre_tx_scan_timer, P2P_TX_PRESCAN_TIMEOUT );
6186                 
6187 #ifdef CONFIG_CONCURRENT_MODE
6188                 if ( check_fwstate( pbuddy_mlmepriv, _FW_LINKED ) )
6189                 {
6190                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_CONCURRENT_PROVISION_TIMEOUT );
6191                 }
6192                 else
6193                 {
6194                         _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_PROVISION_TIMEOUT );
6195                 }
6196 #else
6197                 _set_timer( &pwdinfo->restore_p2p_state_timer, P2P_PROVISION_TIMEOUT );
6198 #endif // CONFIG_CONCURRENT_MODE                
6199                 
6200         }
6201         else
6202         {
6203                 DBG_871X( "[%s] NOT Found in the Scanning Queue!\n", __FUNCTION__ );
6204 #ifdef CONFIG_INTEL_WIDI
6205                 rtw_p2p_set_state(pwdinfo, P2P_STATE_FIND_PHASE_SEARCH);
6206                 rtw_p2p_findphase_ex_set(pwdinfo, P2P_FINDPHASE_EX_NONE);
6207                 rtw_free_network_queue(padapter, _TRUE);                
6208                 _enter_critical_bh(&pmlmepriv->lock, &irqL);                            
6209                 rtw_sitesurvey_cmd(padapter, NULL, 0, NULL, 0);
6210                 _exit_critical_bh(&pmlmepriv->lock, &irqL);
6211 #endif //CONFIG_INTEL_WIDI
6212         }
6213 exit:
6214         
6215         return ret;
6216                 
6217 }
6218
6219 //      Added by Albert 20110328
6220 //      This function is used to inform the driver the user had specified the pin code value or pbc
6221 //      to application.
6222
6223 static int rtw_p2p_got_wpsinfo(struct net_device *dev,
6224                                struct iw_request_info *info,
6225                                union iwreq_data *wrqu, char *extra)
6226 {
6227         
6228         int ret = 0;    
6229         _adapter                                *padapter = (_adapter *)rtw_netdev_priv(dev);   
6230         struct wifidirect_info  *pwdinfo = &( padapter->wdinfo );
6231         
6232
6233         DBG_871X( "[%s] data = %s\n", __FUNCTION__, extra );
6234         //      Added by Albert 20110328
6235         //      if the input data is P2P_NO_WPSINFO -> reset the wpsinfo
6236         //      if the input data is P2P_GOT_WPSINFO_PEER_DISPLAY_PIN -> the utility just input the PIN code got from the peer P2P device.
6237         //      if the input data is P2P_GOT_WPSINFO_SELF_DISPLAY_PIN -> the utility just got the PIN code from itself.
6238         //      if the input data is P2P_GOT_WPSINFO_PBC -> the utility just determine to use the PBC
6239         
6240         if ( *extra == '0' )
6241         {
6242                 pwdinfo->ui_got_wps_info = P2P_NO_WPSINFO;
6243         }
6244         else if ( *extra == '1' )
6245         {
6246                 pwdinfo->ui_got_wps_info = P2P_GOT_WPSINFO_PEER_DISPLAY_PIN;
6247         }
6248         else if ( *extra == '2' )
6249         {
6250                 pwdinfo->ui_got_wps_info = P2P_GOT_WPSINFO_SELF_DISPLAY_PIN;
6251         }
6252         else if ( *extra == '3' )
6253         {
6254                 pwdinfo->ui_got_wps_info = P2P_GOT_WPSINFO_PBC;
6255         }
6256         else
6257         {
6258                 pwdinfo->ui_got_wps_info = P2P_NO_WPSINFO;
6259         }
6260         
6261         return ret;
6262                 
6263 }
6264
6265 #endif //CONFIG_P2P
6266
6267 static int rtw_p2p_set(struct net_device *dev,
6268                                struct iw_request_info *info,
6269                                union iwreq_data *wrqu, char *extra)
6270 {
6271         
6272         int ret = 0;
6273 #ifdef CONFIG_P2P
6274
6275         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6276         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
6277         struct iw_point *pdata = &wrqu->data;
6278         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
6279         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
6280
6281         DBG_871X( "[%s] extra = %s\n", __FUNCTION__, extra );
6282
6283         if ( _rtw_memcmp( extra, "enable=", 7 ) )
6284         {
6285                 rtw_wext_p2p_enable( dev, info, wrqu, &extra[7] );
6286         }
6287         else if ( _rtw_memcmp( extra, "setDN=", 6 ) )
6288         {
6289                 wrqu->data.length -= 6;
6290                 rtw_p2p_setDN( dev, info, wrqu, &extra[6] );
6291         }
6292         else if ( _rtw_memcmp( extra, "profilefound=", 13 ) )
6293         {
6294                 wrqu->data.length -= 13;
6295                 rtw_p2p_profilefound( dev, info, wrqu, &extra[13] );
6296         }
6297         else if ( _rtw_memcmp( extra, "prov_disc=", 10 ) )
6298         {
6299                 wrqu->data.length -= 10;
6300                 rtw_p2p_prov_disc( dev, info, wrqu, &extra[10] );
6301         }
6302         else if ( _rtw_memcmp( extra, "nego=", 5 ) )
6303         {
6304                 wrqu->data.length -= 5;
6305                 rtw_p2p_connect( dev, info, wrqu, &extra[5] );
6306         }
6307         else if ( _rtw_memcmp( extra, "intent=", 7 ) )
6308         {
6309                 //      Commented by Albert 2011/03/23
6310                 //      The wrqu->data.length will include the null character
6311                 //      So, we will decrease 7 + 1
6312                 wrqu->data.length -= 8;
6313                 rtw_p2p_set_intent( dev, info, wrqu, &extra[7] );
6314         }
6315         else if ( _rtw_memcmp( extra, "ssid=", 5 ) )
6316         {
6317                 wrqu->data.length -= 5;
6318                 rtw_p2p_set_go_nego_ssid( dev, info, wrqu, &extra[5] );
6319         }
6320         else if ( _rtw_memcmp( extra, "got_wpsinfo=", 12 ) )
6321         {
6322                 wrqu->data.length -= 12;
6323                 rtw_p2p_got_wpsinfo( dev, info, wrqu, &extra[12] );
6324         }
6325         else if ( _rtw_memcmp( extra, "listen_ch=", 10 ) )
6326         {
6327                 //      Commented by Albert 2011/05/24
6328                 //      The wrqu->data.length will include the null character
6329                 //      So, we will decrease (10 + 1)   
6330                 wrqu->data.length -= 11;
6331                 rtw_p2p_set_listen_ch( dev, info, wrqu, &extra[10] );
6332         }
6333         else if ( _rtw_memcmp( extra, "op_ch=", 6 ) )
6334         {
6335                 //      Commented by Albert 2011/05/24
6336                 //      The wrqu->data.length will include the null character
6337                 //      So, we will decrease (6 + 1)    
6338                 wrqu->data.length -= 7;
6339                 rtw_p2p_set_op_ch( dev, info, wrqu, &extra[6] );
6340         }
6341         else if ( _rtw_memcmp( extra, "invite=", 7 ) )
6342         {
6343                 wrqu->data.length -= 8;
6344                 rtw_p2p_invite_req( dev, info, wrqu, &extra[7] );
6345         }
6346         else if ( _rtw_memcmp( extra, "persistent=", 11 ) )
6347         {
6348                 wrqu->data.length -= 11;
6349                 rtw_p2p_set_persistent( dev, info, wrqu, &extra[11] );
6350         }
6351         else if ( _rtw_memcmp ( extra, "uuid=", 5) )
6352         {
6353                 wrqu->data.length -= 5;
6354                 ret = rtw_p2p_set_wps_uuid( dev, info, wrqu, &extra[5] );
6355         }
6356 #ifdef CONFIG_WFD
6357         else if ( _rtw_memcmp( extra, "sa=", 3 ) )
6358         {
6359                 //      sa: WFD Session Available information
6360                 wrqu->data.length -= 3;
6361                 rtw_p2p_set_sa( dev, info, wrqu, &extra[3] );
6362         }
6363         else if ( _rtw_memcmp( extra, "pc=", 3 ) )
6364         {
6365                 //      pc: WFD Preferred Connection
6366                 wrqu->data.length -= 3;
6367                 rtw_p2p_set_pc( dev, info, wrqu, &extra[3] );
6368         }
6369         else if ( _rtw_memcmp( extra, "wfd_type=", 9 ) )
6370         {
6371                 //      pc: WFD Preferred Connection
6372                 wrqu->data.length -= 9;
6373                 rtw_p2p_set_wfd_device_type( dev, info, wrqu, &extra[9] );
6374         }
6375         else if ( _rtw_memcmp( extra, "wfd_enable=", 11 ) )
6376         {
6377                 wrqu->data.length -= 11;
6378                 rtw_p2p_set_wfd_enable( dev, info, wrqu, &extra[11] );
6379         }
6380         else if ( _rtw_memcmp( extra, "driver_iface=", 13 ) )
6381         {
6382                 wrqu->data.length -= 13;
6383                 rtw_p2p_set_driver_iface( dev, info, wrqu, &extra[13] );
6384         }
6385 #endif //CONFIG_WFD
6386
6387 #endif //CONFIG_P2P
6388
6389         return ret;
6390                 
6391 }
6392
6393 static int rtw_p2p_get(struct net_device *dev,
6394                                struct iw_request_info *info,
6395                                union iwreq_data *wrqu, char *extra)
6396 {
6397         
6398         int ret = 0;    
6399         
6400 #ifdef CONFIG_P2P
6401
6402         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6403         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
6404         struct iw_point *pdata = &wrqu->data;
6405         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
6406         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
6407
6408         if ( padapter->bShowGetP2PState )
6409         {
6410                 DBG_871X( "[%s] extra = %s\n", __FUNCTION__, (char*) wrqu->data.pointer );
6411         }
6412
6413         if ( _rtw_memcmp( wrqu->data.pointer, "status", 6 ) )
6414         {
6415                 rtw_p2p_get_status( dev, info, wrqu, extra );
6416         }
6417         else if ( _rtw_memcmp( wrqu->data.pointer, "role", 4 ) )
6418         {
6419                 rtw_p2p_get_role( dev, info, wrqu, extra);
6420         }
6421         else if ( _rtw_memcmp( wrqu->data.pointer, "peer_ifa", 8 ) )
6422         {
6423                 rtw_p2p_get_peer_ifaddr( dev, info, wrqu, extra);
6424         }
6425         else if ( _rtw_memcmp( wrqu->data.pointer, "req_cm", 6 ) )
6426         {
6427                 rtw_p2p_get_req_cm( dev, info, wrqu, extra);
6428         }
6429         else if ( _rtw_memcmp( wrqu->data.pointer, "peer_deva", 9 ) )
6430         {
6431                 //      Get the P2P device address when receiving the provision discovery request frame.
6432                 rtw_p2p_get_peer_devaddr( dev, info, wrqu, extra);
6433         }
6434         else if ( _rtw_memcmp( wrqu->data.pointer, "group_id", 8 ) )
6435         {
6436                 rtw_p2p_get_groupid( dev, info, wrqu, extra);
6437         }
6438         else if ( _rtw_memcmp( wrqu->data.pointer, "inv_peer_deva", 13 ) )
6439         {
6440                 //      Get the P2P device address when receiving the P2P Invitation request frame.
6441                 rtw_p2p_get_peer_devaddr_by_invitation( dev, info, wrqu, extra);
6442         }
6443         else if ( _rtw_memcmp( wrqu->data.pointer, "op_ch", 5 ) )
6444         {
6445                 rtw_p2p_get_op_ch( dev, info, wrqu, extra);
6446         }
6447 #ifdef CONFIG_WFD
6448         else if ( _rtw_memcmp( wrqu->data.pointer, "peer_port", 9 ) )
6449         {
6450                 rtw_p2p_get_peer_wfd_port( dev, info, wrqu, extra );
6451         }
6452         else if ( _rtw_memcmp( wrqu->data.pointer, "wfd_sa", 6 ) )
6453         {
6454                 rtw_p2p_get_peer_wfd_session_available( dev, info, wrqu, extra );
6455         }
6456         else if ( _rtw_memcmp( wrqu->data.pointer, "wfd_pc", 6 ) )
6457         {
6458                 rtw_p2p_get_peer_wfd_preferred_connection( dev, info, wrqu, extra );
6459         }
6460 #endif // CONFIG_WFD    
6461         
6462 #endif //CONFIG_P2P
6463
6464         return ret;
6465                 
6466 }
6467
6468 static int rtw_p2p_get2(struct net_device *dev,
6469                                                 struct iw_request_info *info,
6470                                                 union iwreq_data *wrqu, char *extra)
6471 {
6472
6473         int ret = 0;
6474
6475 #ifdef CONFIG_P2P
6476
6477         int length = wrqu->data.length;
6478         char *buffer = (u8 *)rtw_malloc(length);
6479
6480         if (buffer == NULL)
6481         {
6482                 ret = -ENOMEM;
6483                 goto bad;
6484         }
6485
6486         if (copy_from_user(buffer, wrqu->data.pointer, wrqu->data.length))
6487         {
6488                 ret - EFAULT;
6489                 goto bad;
6490         }
6491
6492         DBG_871X("[%s] buffer = %s\n", __FUNCTION__, buffer);
6493
6494         if (_rtw_memcmp(buffer, "wpsCM=", 6))
6495         {
6496                 ret = rtw_p2p_get_wps_configmethod(dev, info, wrqu, extra, &buffer[6]);
6497         } else if (_rtw_memcmp(buffer, "devN=", 5))
6498         {
6499                 ret = rtw_p2p_get_device_name(dev, info, wrqu, extra, &buffer[5]);
6500         } else if (_rtw_memcmp(buffer, "dev_type=", 9))
6501         {
6502                 ret = rtw_p2p_get_device_type(dev, info, wrqu, extra, &buffer[9]);
6503         } else if (_rtw_memcmp(buffer, "go_devadd=", 10))
6504         {
6505                 ret = rtw_p2p_get_go_device_address(dev, info, wrqu, extra, &buffer[10]);
6506         } else if (_rtw_memcmp(buffer, "InvProc=", 8))
6507         {
6508                 ret = rtw_p2p_get_invitation_procedure(dev, info, wrqu, extra, &buffer[8]);
6509         } else
6510         {
6511                 snprintf(extra, sizeof("Command not found."), "Command not found.");
6512                 wrqu->data.length = strlen(extra);
6513         }
6514
6515 bad:
6516         if (buffer)
6517         {
6518                 rtw_mfree(buffer, length);
6519         }
6520
6521 #endif //CONFIG_P2P
6522
6523         return ret;
6524
6525 }
6526
6527 static int rtw_cta_test_start(struct net_device *dev,
6528                                                            struct iw_request_info *info,
6529                                                            union iwreq_data *wrqu, char *extra)
6530 {
6531         int ret = 0;
6532         _adapter        *padapter = (_adapter *)rtw_netdev_priv(dev);
6533         DBG_871X("%s %s\n", __func__, extra);
6534         if (!strcmp(extra, "1"))
6535                 padapter->in_cta_test = 1;
6536         else
6537                 padapter->in_cta_test = 0;
6538
6539         if(padapter->in_cta_test)
6540         {
6541                 u32 v = rtw_read32(padapter, REG_RCR);
6542                 v &= ~(RCR_CBSSID_DATA | RCR_CBSSID_BCN );//| RCR_ADF
6543                 rtw_write32(padapter, REG_RCR, v);
6544                 DBG_871X("enable RCR_ADF\n");
6545         }
6546         else
6547         {
6548                 u32 v = rtw_read32(padapter, REG_RCR);
6549                 v |= RCR_CBSSID_DATA | RCR_CBSSID_BCN ;//| RCR_ADF
6550                 rtw_write32(padapter, REG_RCR, v);
6551                 DBG_871X("disable RCR_ADF\n");
6552         }
6553         return ret;
6554 }
6555
6556
6557 extern int rtw_change_ifname(_adapter *padapter, const char *ifname);
6558 static int rtw_rereg_nd_name(struct net_device *dev,
6559                                struct iw_request_info *info,
6560                                union iwreq_data *wrqu, char *extra)
6561 {
6562         int ret = 0;    
6563         _adapter *padapter = rtw_netdev_priv(dev);
6564         struct rereg_nd_name_data *rereg_priv = &padapter->rereg_nd_name_priv;
6565         char new_ifname[IFNAMSIZ];
6566
6567         if(rereg_priv->old_ifname[0] == 0) {
6568                 char *reg_ifname;
6569 #ifdef CONFIG_CONCURRENT_MODE 
6570                 if (padapter->isprimary)
6571                         reg_ifname = padapter->registrypriv.ifname;
6572                 else
6573 #endif
6574                 reg_ifname = padapter->registrypriv.if2name;
6575
6576                 strncpy(rereg_priv->old_ifname, reg_ifname, IFNAMSIZ);
6577                 rereg_priv->old_ifname[IFNAMSIZ-1] = 0;
6578         }
6579
6580         //DBG_871X("%s wrqu->data.length:%d\n", __FUNCTION__, wrqu->data.length);
6581         if(wrqu->data.length > IFNAMSIZ)
6582                 return -EFAULT;
6583
6584         if ( copy_from_user(new_ifname, wrqu->data.pointer, IFNAMSIZ) ) {
6585                 return -EFAULT;
6586         }
6587
6588         if( 0 == strcmp(rereg_priv->old_ifname, new_ifname) ) {
6589                 return ret;
6590         }
6591
6592         DBG_871X("%s new_ifname:%s\n", __FUNCTION__, new_ifname);
6593         if( 0 != (ret = rtw_change_ifname(padapter, new_ifname)) ) {
6594                 goto exit;
6595         }
6596
6597         if(_rtw_memcmp(rereg_priv->old_ifname, "disable%d", 9) == _TRUE) {
6598                 padapter->ledpriv.bRegUseLed= rereg_priv->old_bRegUseLed;
6599                 rtw_hal_sw_led_init(padapter);
6600                 //rtw_ips_mode_req(&padapter->pwrctrlpriv, rereg_priv->old_ips_mode);
6601         }
6602
6603         strncpy(rereg_priv->old_ifname, new_ifname, IFNAMSIZ);
6604         rereg_priv->old_ifname[IFNAMSIZ-1] = 0;
6605         
6606         if(_rtw_memcmp(new_ifname, "disable%d", 9) == _TRUE) {
6607
6608                 DBG_871X("%s disable\n", __FUNCTION__);
6609                 // free network queue for Android's timming issue
6610                 rtw_free_network_queue(padapter, _TRUE);
6611                 
6612                 // close led
6613                 rtw_led_control(padapter, LED_CTL_POWER_OFF);
6614                 rereg_priv->old_bRegUseLed = padapter->ledpriv.bRegUseLed;
6615                 padapter->ledpriv.bRegUseLed= _FALSE;
6616                 rtw_hal_sw_led_deinit(padapter);
6617                 
6618                 // the interface is being "disabled", we can do deeper IPS
6619                 //rereg_priv->old_ips_mode = rtw_get_ips_mode_req(&padapter->pwrctrlpriv);
6620                 //rtw_ips_mode_req(&padapter->pwrctrlpriv, IPS_NORMAL);
6621         }
6622 exit:
6623         return ret;
6624
6625 }
6626
6627 #ifdef CONFIG_IOL
6628 #include <rtw_iol.h>
6629 #endif
6630 static int rtw_dbg_port(struct net_device *dev,
6631                                struct iw_request_info *info,
6632                                union iwreq_data *wrqu, char *extra)
6633 {       
6634         _irqL irqL;
6635         int ret = 0;
6636         u8 major_cmd, minor_cmd;
6637         u16 arg;
6638         u32 extra_arg, *pdata, val32;
6639         struct sta_info *psta;                                          
6640         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
6641         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
6642         struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;
6643         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
6644         struct security_priv *psecuritypriv = &padapter->securitypriv;
6645         struct wlan_network *cur_network = &(pmlmepriv->cur_network);
6646         struct sta_priv *pstapriv = &padapter->stapriv;
6647         
6648
6649         pdata = (u32*)&wrqu->data;      
6650
6651         val32 = *pdata;
6652         arg = (u16)(val32&0x0000ffff);
6653         major_cmd = (u8)(val32>>24);
6654         minor_cmd = (u8)((val32>>16)&0x00ff);
6655
6656         extra_arg = *(pdata+1);
6657         
6658         switch(major_cmd)
6659         {
6660                 case 0x70://read_reg
6661                         switch(minor_cmd)
6662                         {
6663                                 case 1:
6664                                         DBG_871X("rtw_read8(0x%x)=0x%02x\n", arg, rtw_read8(padapter, arg));
6665                                         break;
6666                                 case 2:
6667                                         DBG_871X("rtw_read16(0x%x)=0x%04x\n", arg, rtw_read16(padapter, arg));
6668                                         break;
6669                                 case 4:
6670                                         DBG_871X("rtw_read32(0x%x)=0x%08x\n", arg, rtw_read32(padapter, arg));
6671                                         break;
6672                         }                       
6673                         break;
6674                 case 0x71://write_reg
6675                         switch(minor_cmd)
6676                         {
6677                                 case 1:
6678                                         rtw_write8(padapter, arg, extra_arg);
6679                                         DBG_871X("rtw_write8(0x%x)=0x%02x\n", arg, rtw_read8(padapter, arg));
6680                                         break;
6681                                 case 2:
6682                                         rtw_write16(padapter, arg, extra_arg);
6683                                         DBG_871X("rtw_write16(0x%x)=0x%04x\n", arg, rtw_read16(padapter, arg));
6684                                         break;
6685                                 case 4:
6686                                         rtw_write32(padapter, arg, extra_arg);
6687                                         DBG_871X("rtw_write32(0x%x)=0x%08x\n", arg, rtw_read32(padapter, arg));
6688                                         break;
6689                         }                       
6690                         break;
6691                 case 0x72://read_bb
6692                         DBG_871X("read_bbreg(0x%x)=0x%x\n", arg, rtw_hal_read_bbreg(padapter, arg, 0xffffffff));
6693                         break;
6694                 case 0x73://write_bb
6695                         rtw_hal_write_bbreg(padapter, arg, 0xffffffff, extra_arg);
6696                         DBG_871X("write_bbreg(0x%x)=0x%x\n", arg, rtw_hal_read_bbreg(padapter, arg, 0xffffffff));
6697                         break;
6698                 case 0x74://read_rf
6699                         DBG_871X("read RF_reg path(0x%02x),offset(0x%x),value(0x%08x)\n",minor_cmd,arg,rtw_hal_read_rfreg(padapter, minor_cmd, arg, 0xffffffff));       
6700                         break;
6701                 case 0x75://write_rf
6702                         rtw_hal_write_rfreg(padapter, minor_cmd, arg, 0xffffffff, extra_arg);
6703                         DBG_871X("write RF_reg path(0x%02x),offset(0x%x),value(0x%08x)\n",minor_cmd,arg, rtw_hal_read_rfreg(padapter, minor_cmd, arg, 0xffffffff));
6704                         break;  
6705
6706                 case 0x76:
6707                         switch(minor_cmd)
6708                         {
6709                                 case 0x00: //normal mode, 
6710                                         padapter->recvpriv.is_signal_dbg = 0;
6711                                         break;
6712                                 case 0x01: //dbg mode
6713                                         padapter->recvpriv.is_signal_dbg = 1;
6714                                         extra_arg = extra_arg>100?100:extra_arg;
6715                                         extra_arg = extra_arg<0?0:extra_arg;
6716                                         padapter->recvpriv.signal_strength_dbg=extra_arg;
6717                                         break;
6718                         }
6719                         break;
6720                 case 0x78: //IOL test
6721                         switch(minor_cmd)
6722                         {
6723                                 #ifdef CONFIG_IOL
6724                                 case 0x04: //LLT table initialization test
6725                                 {
6726                                         u8 page_boundary = 0xf9;
6727                                         {
6728                                                 struct xmit_frame       *xmit_frame;
6729
6730                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
6731                                                         ret = -ENOMEM;  
6732                                                         break;
6733                                                 }
6734                                                 
6735                                                 rtw_IOL_append_LLT_cmd(xmit_frame, page_boundary);
6736
6737
6738                                                 if(_SUCCESS != rtw_IOL_exec_cmds_sync(padapter, xmit_frame, 500,0) )
6739                                                         ret = -EPERM;
6740                                         }
6741                                 }
6742                                         break;
6743                                 case 0x05: //blink LED test
6744                                 {
6745                                         u16 reg = 0x4c;
6746                                         u32 blink_num = 50;
6747                                         u32 blink_delay_ms = 200;
6748                                         int i;
6749                                         
6750                                         {
6751                                                 struct xmit_frame       *xmit_frame;
6752
6753                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
6754                                                         ret = -ENOMEM;  
6755                                                         break;
6756                                                 }
6757
6758                                                 for(i=0;i<blink_num;i++){
6759                                                         #ifdef CONFIG_IOL_NEW_GENERATION
6760                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, 0x00,0xff);
6761                                                         rtw_IOL_append_DELAY_MS_cmd(xmit_frame, blink_delay_ms);
6762                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, 0x08,0xff);
6763                                                         rtw_IOL_append_DELAY_MS_cmd(xmit_frame, blink_delay_ms);
6764                                                         #else
6765                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, 0x00);
6766                                                         rtw_IOL_append_DELAY_MS_cmd(xmit_frame, blink_delay_ms);
6767                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, 0x08);
6768                                                         rtw_IOL_append_DELAY_MS_cmd(xmit_frame, blink_delay_ms);
6769                                                         #endif
6770                                                 }
6771                                                 if(_SUCCESS != rtw_IOL_exec_cmds_sync(padapter, xmit_frame, (blink_delay_ms*blink_num*2)+200,0) )
6772                                                         ret = -EPERM;
6773                                         }
6774                                 }
6775                                         break;
6776                                         
6777                                 case 0x06: //continuous wirte byte test
6778                                 {
6779                                         u16 reg = arg;
6780                                         u16 start_value = 0;
6781                                         u32 write_num = extra_arg;
6782                                         int i;
6783                                         u8 final;
6784                                         
6785                                         {
6786                                                 struct xmit_frame       *xmit_frame;
6787
6788                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
6789                                                         ret = -ENOMEM;  
6790                                                         break;
6791                                                 }
6792
6793                                                 for(i=0;i<write_num;i++){
6794                                                         #ifdef CONFIG_IOL_NEW_GENERATION
6795                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, i+start_value,0xFF);
6796                                                         #else
6797                                                         rtw_IOL_append_WB_cmd(xmit_frame, reg, i+start_value);
6798                                                         #endif
6799                                                 }
6800                                                 if(_SUCCESS != rtw_IOL_exec_cmds_sync(padapter, xmit_frame, 5000,0))
6801                                                         ret = -EPERM;
6802                                         }
6803
6804                                         if(start_value+write_num-1 == (final=rtw_read8(padapter, reg)) ) {
6805                                                 DBG_871X("continuous IOL_CMD_WB_REG to 0x%x %u times Success, start:%u, final:%u\n", reg, write_num, start_value, final);
6806                                         } else {
6807                                                 DBG_871X("continuous IOL_CMD_WB_REG to 0x%x %u times Fail, start:%u, final:%u\n", reg, write_num, start_value, final);
6808                                         }
6809                                 }
6810                                         break;
6811                                         
6812                                 case 0x07: //continuous wirte word test
6813                                 {
6814                                         u16 reg = arg;
6815                                         u16 start_value = 200;
6816                                         u32 write_num = extra_arg;
6817                                 
6818                                         int i;
6819                                         u16 final;
6820
6821                                         {
6822                                                 struct xmit_frame       *xmit_frame;
6823
6824                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
6825                                                         ret = -ENOMEM;  
6826                                                         break;
6827                                                 }
6828
6829                                                 for(i=0;i<write_num;i++){
6830                                                         #ifdef CONFIG_IOL_NEW_GENERATION
6831                                                         rtw_IOL_append_WW_cmd(xmit_frame, reg, i+start_value,0xFFFF);
6832                                                         #else
6833                                                         rtw_IOL_append_WW_cmd(xmit_frame, reg, i+start_value);
6834                                                         #endif
6835                                                 }
6836                                                 if(_SUCCESS !=rtw_IOL_exec_cmds_sync(padapter, xmit_frame, 5000,0))
6837                                                         ret = -EPERM;
6838                                         }
6839
6840                                         if(start_value+write_num-1 == (final=rtw_read16(padapter, reg)) ) {
6841                                                 DBG_871X("continuous IOL_CMD_WW_REG to 0x%x %u times Success, start:%u, final:%u\n", reg, write_num, start_value, final);
6842                                         } else {
6843                                                 DBG_871X("continuous IOL_CMD_WW_REG to 0x%x %u times Fail, start:%u, final:%u\n", reg, write_num, start_value, final);
6844                                         }
6845                                 }
6846                                         break;
6847                                         
6848                                 case 0x08: //continuous wirte dword test
6849                                 {
6850                                         u16 reg = arg;
6851                                         u32 start_value = 0x110000c7;
6852                                         u32 write_num = extra_arg;
6853                                 
6854                                         int i;
6855                                         u32 final;
6856
6857                                         {
6858                                                 struct xmit_frame       *xmit_frame;
6859
6860                                                 if((xmit_frame=rtw_IOL_accquire_xmit_frame(padapter)) == NULL) {
6861                                                         ret = -ENOMEM;  
6862                                                         break;
6863                                                 }
6864
6865                                                 for(i=0;i<write_num;i++){
6866                                                         #ifdef CONFIG_IOL_NEW_GENERATION
6867                                                         rtw_IOL_append_WD_cmd(xmit_frame, reg, i+start_value,0xFFFFFFFF);
6868                                                         #else
6869                                                         rtw_IOL_append_WD_cmd(xmit_frame, reg, i+start_value);
6870                                                         #endif
6871                                                 }
6872                                                 if(_SUCCESS !=rtw_IOL_exec_cmds_sync(padapter, xmit_frame, 5000,0))
6873                                                         ret = -EPERM;
6874                                                         
6875                                         }
6876
6877                                         if(start_value+write_num-1 == (final=rtw_read32(padapter, reg)) ) {
6878                                                 DBG_871X("continuous IOL_CMD_WD_REG to 0x%x %u times Success, start:%u, final:%u\n", reg, write_num, start_value, final);
6879                                         } else {
6880                                                 DBG_871X("continuous IOL_CMD_WD_REG to 0x%x %u times Fail, start:%u, final:%u\n", reg, write_num, start_value, final);
6881                                         }
6882                                 }
6883                                         break;
6884                                 #endif //CONFIG_IOL
6885                         }
6886                         break;
6887                 case 0x79:
6888                         {
6889                                 /*
6890                                 * dbg 0x79000000 [value], set RESP_TXAGC to + value, value:0~15
6891                                 * dbg 0x79010000 [value], set RESP_TXAGC to - value, value:0~15
6892                                 */
6893                                 u8 value =  extra_arg & 0x0f;
6894                                 u8 sign = minor_cmd;
6895                                 u16 write_value = 0;
6896
6897                                 DBG_871X("%s set RESP_TXAGC to %s %u\n", __func__, sign?"minus":"plus", value);
6898
6899                                 if (sign)
6900                                         value = value | 0x10;
6901
6902                                 write_value = value | (value << 5);
6903                                 rtw_write16(padapter, 0x6d9, write_value);
6904                         }
6905                         break;
6906                 case 0x7a:
6907                         receive_disconnect(padapter, pmlmeinfo->network.MacAddress
6908                                 , WLAN_REASON_EXPIRATION_CHK);
6909                         break;
6910                 case 0x7F:
6911                         switch(minor_cmd)
6912                         {
6913                                 case 0x0:
6914                                         DBG_871X("fwstate=0x%x\n", get_fwstate(pmlmepriv));
6915                                         break;
6916                                 case 0x01:
6917                                         DBG_871X("auth_alg=0x%x, enc_alg=0x%x, auth_type=0x%x, enc_type=0x%x\n", 
6918                                                 psecuritypriv->dot11AuthAlgrthm, psecuritypriv->dot11PrivacyAlgrthm,
6919                                                 psecuritypriv->ndisauthtype, psecuritypriv->ndisencryptstatus);
6920                                         break;
6921                                 case 0x02:
6922                                         DBG_871X("pmlmeinfo->state=0x%x\n", pmlmeinfo->state);
6923                                         DBG_871X("DrvBcnEarly=%d\n", pmlmeext->DrvBcnEarly);
6924                                         DBG_871X("DrvBcnTimeOut=%d\n", pmlmeext->DrvBcnTimeOut);
6925                                         break;
6926                                 case 0x03:
6927                                         DBG_871X("qos_option=%d\n", pmlmepriv->qospriv.qos_option);
6928 #ifdef CONFIG_80211N_HT
6929                                         DBG_871X("ht_option=%d\n", pmlmepriv->htpriv.ht_option);
6930 #endif //CONFIG_80211N_HT
6931                                         break;
6932                                 case 0x04:
6933                                         DBG_871X("cur_ch=%d\n", pmlmeext->cur_channel);
6934                                         DBG_871X("cur_bw=%d\n", pmlmeext->cur_bwmode);
6935                                         DBG_871X("cur_ch_off=%d\n", pmlmeext->cur_ch_offset);
6936
6937                                         DBG_871X("oper_ch=%d\n", rtw_get_oper_ch(padapter));
6938                                         DBG_871X("oper_bw=%d\n", rtw_get_oper_bw(padapter));
6939                                         DBG_871X("oper_ch_offet=%d\n", rtw_get_oper_choffset(padapter));
6940                                 
6941                                         break;
6942                                 case 0x05:
6943                                         psta = rtw_get_stainfo(pstapriv, cur_network->network.MacAddress);
6944                                         if(psta)
6945                                         {
6946                                                 int i;
6947                                                 struct recv_reorder_ctrl *preorder_ctrl;
6948                                         
6949                                                 DBG_871X("SSID=%s\n", cur_network->network.Ssid.Ssid);
6950                                                 DBG_871X("sta's macaddr:" MAC_FMT "\n", MAC_ARG(psta->hwaddr));
6951                                                 DBG_871X("cur_channel=%d, cur_bwmode=%d, cur_ch_offset=%d\n", pmlmeext->cur_channel, pmlmeext->cur_bwmode, pmlmeext->cur_ch_offset);
6952                                                 DBG_871X("rtsen=%d, cts2slef=%d\n", psta->rtsen, psta->cts2self);
6953                                                 DBG_871X("state=0x%x, aid=%d, macid=%d, raid=%d\n", psta->state, psta->aid, psta->mac_id, psta->raid);
6954 #ifdef CONFIG_80211N_HT
6955                                                 DBG_871X("qos_en=%d, ht_en=%d, init_rate=%d\n", psta->qos_option, psta->htpriv.ht_option, psta->init_rate);
6956                                                 DBG_871X("bwmode=%d, ch_offset=%d, sgi_20m=%d,sgi_40m=%d\n", psta->bw_mode, psta->htpriv.ch_offset, psta->htpriv.sgi_20m, psta->htpriv.sgi_40m);
6957                                                 DBG_871X("ampdu_enable = %d\n", psta->htpriv.ampdu_enable);     
6958                                                 DBG_871X("agg_enable_bitmap=%x, candidate_tid_bitmap=%x\n", psta->htpriv.agg_enable_bitmap, psta->htpriv.candidate_tid_bitmap);
6959 #endif //CONFIG_80211N_HT
6960                                                 
6961                                                 for(i=0;i<16;i++)
6962                                                 {                                                       
6963                                                         preorder_ctrl = &psta->recvreorder_ctrl[i];
6964                                                         if(preorder_ctrl->enable)
6965                                                         {
6966                                                                 DBG_871X("tid=%d, indicate_seq=%d\n", i, preorder_ctrl->indicate_seq);
6967                                                         }
6968                                                 }       
6969                                                         
6970                                         }
6971                                         else
6972                                         {                                                       
6973                                                 DBG_871X("can't get sta's macaddr, cur_network's macaddr:" MAC_FMT "\n", MAC_ARG(cur_network->network.MacAddress));
6974                                         }                                       
6975                                         break;
6976                                 case 0x06:
6977                                         {
6978                                                 u32     ODMFlag;
6979                                                 rtw_hal_get_hwreg(padapter, HW_VAR_DM_FLAG, (u8*)(&ODMFlag));
6980                                                 DBG_871X("(B)DMFlag=0x%x, arg=0x%x\n", ODMFlag, arg);
6981                                                 ODMFlag = (u32)(0x0f&arg);
6982                                                 DBG_871X("(A)DMFlag=0x%x\n", ODMFlag);
6983                                                 rtw_hal_set_hwreg(padapter, HW_VAR_DM_FLAG, (u8 *)(&ODMFlag));
6984                                         }
6985                                         break;
6986                                 case 0x07:
6987                                         DBG_871X("bSurpriseRemoved=%d, bDriverStopped=%d\n", 
6988                                                 padapter->bSurpriseRemoved, padapter->bDriverStopped);
6989                                         break;
6990                                 case 0x08:
6991                                         {
6992                                                 struct xmit_priv *pxmitpriv = &padapter->xmitpriv;
6993                                                 struct recv_priv  *precvpriv = &padapter->recvpriv;
6994                                                 
6995                                                 DBG_871X("free_xmitbuf_cnt=%d, free_xmitframe_cnt=%d"
6996                                                         ", free_xmit_extbuf_cnt=%d, free_xframe_ext_cnt=%d"
6997                                                         ", free_recvframe_cnt=%d\n",
6998                                                         pxmitpriv->free_xmitbuf_cnt, pxmitpriv->free_xmitframe_cnt,
6999                                                         pxmitpriv->free_xmit_extbuf_cnt, pxmitpriv->free_xframe_ext_cnt,
7000                                                         precvpriv->free_recvframe_cnt);
7001                                                 #ifdef CONFIG_USB_HCI
7002                                                 DBG_871X("rx_urb_pending_cn=%d\n", precvpriv->rx_pending_cnt);
7003                                                 #endif
7004                                         }
7005                                         break;  
7006                                 case 0x09:
7007                                         {
7008                                                 int i, j;
7009                                                 _list   *plist, *phead;
7010                                                 struct recv_reorder_ctrl *preorder_ctrl;
7011                                                 
7012 #ifdef CONFIG_AP_MODE
7013                                                 DBG_871X("sta_dz_bitmap=0x%x, tim_bitmap=0x%x\n", pstapriv->sta_dz_bitmap, pstapriv->tim_bitmap);
7014 #endif                                          
7015                                                 _enter_critical_bh(&pstapriv->sta_hash_lock, &irqL);
7016
7017                                                 for(i=0; i< NUM_STA; i++)
7018                                                 {
7019                                                         phead = &(pstapriv->sta_hash[i]);
7020                                                         plist = get_next(phead);
7021                 
7022                                                         while ((rtw_end_of_queue_search(phead, plist)) == _FALSE)
7023                                                         {
7024                                                                 psta = LIST_CONTAINOR(plist, struct sta_info, hash_list);
7025
7026                                                                 plist = get_next(plist);
7027
7028                                                                 if(extra_arg == psta->aid)
7029                                                                 {
7030                                                                         DBG_871X("sta's macaddr:" MAC_FMT "\n", MAC_ARG(psta->hwaddr));
7031                                                                         DBG_871X("rtsen=%d, cts2slef=%d\n", psta->rtsen, psta->cts2self);
7032                                                                         DBG_871X("state=0x%x, aid=%d, macid=%d, raid=%d\n", psta->state, psta->aid, psta->mac_id, psta->raid);
7033 #ifdef CONFIG_80211N_HT
7034                                                                         DBG_871X("qos_en=%d, ht_en=%d, init_rate=%d\n", psta->qos_option, psta->htpriv.ht_option, psta->init_rate);     
7035                                                                         DBG_871X("bwmode=%d, ch_offset=%d, sgi_20m=%d,sgi_40m=%d\n", psta->bw_mode, psta->htpriv.ch_offset, psta->htpriv.sgi_20m, psta->htpriv.sgi_40m);
7036                                                                         DBG_871X("ampdu_enable = %d\n", psta->htpriv.ampdu_enable);                                                                     
7037                                                                         DBG_871X("agg_enable_bitmap=%x, candidate_tid_bitmap=%x\n", psta->htpriv.agg_enable_bitmap, psta->htpriv.candidate_tid_bitmap);
7038 #endif //CONFIG_80211N_HT
7039                                                                         
7040 #ifdef CONFIG_AP_MODE
7041                                                                         DBG_871X("capability=0x%x\n", psta->capability);
7042                                                                         DBG_871X("flags=0x%x\n", psta->flags);
7043                                                                         DBG_871X("wpa_psk=0x%x\n", psta->wpa_psk);
7044                                                                         DBG_871X("wpa2_group_cipher=0x%x\n", psta->wpa2_group_cipher);
7045                                                                         DBG_871X("wpa2_pairwise_cipher=0x%x\n", psta->wpa2_pairwise_cipher);
7046                                                                         DBG_871X("qos_info=0x%x\n", psta->qos_info);
7047 #endif
7048                                                                         DBG_871X("dot118021XPrivacy=0x%x\n", psta->dot118021XPrivacy);
7049                                                                         
7050                                                                         
7051                                                 
7052                                                                         for(j=0;j<16;j++)
7053                                                                         {                                                       
7054                                                                                 preorder_ctrl = &psta->recvreorder_ctrl[j];
7055                                                                                 if(preorder_ctrl->enable)
7056                                                                                 {
7057                                                                                         DBG_871X("tid=%d, indicate_seq=%d\n", j, preorder_ctrl->indicate_seq);
7058                                                                                 }
7059                                                                         }               
7060                                                                         
7061                                                                 }                                                       
7062                         
7063                                                         }
7064                                                 }
7065         
7066                                                 _exit_critical_bh(&pstapriv->sta_hash_lock, &irqL);
7067
7068                                         }
7069                                         break;
7070                                 case 0x0a:
7071                                         {
7072                                                 int max_mac_id = 0;
7073                                                 max_mac_id = rtw_search_max_mac_id( padapter);
7074                                                 printk("%s ==> max_mac_id = %d \n",__FUNCTION__,max_mac_id);
7075                                         }       
7076                                         break;
7077                                 case 0x0c://dump rx/tx packet
7078                                         {
7079                                                 if(arg == 0){
7080                                                         DBG_871X("dump rx packet (%d)\n",extra_arg);                                            
7081                                                         //pHalData->bDumpRxPkt =extra_arg;                                              
7082                                                         rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DUMP_RXPKT, &(extra_arg));
7083                                                 }
7084                                                 else if(arg==1){
7085                                                         DBG_871X("dump tx packet (%d)\n",extra_arg);                                            
7086                                                         rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DUMP_TXPKT, &(extra_arg));
7087                                                 }
7088                                         }
7089                                         break;
7090 #if 0                           
7091                                 case 0x0d://dump cam
7092                                         {
7093                                                 //u8 entry = (u8) extra_arg;
7094                                                 u8 entry=0;
7095                                                 //dump cam
7096                                                 for(entry=0;entry<32;entry++)
7097                                                         read_cam(padapter,entry);
7098                                         }                               
7099                                         break;
7100 #endif
7101                 #ifdef DBG_CONFIG_ERROR_DETECT
7102                                 case 0x0f:
7103                                                 {
7104                                                         if(extra_arg == 0){     
7105                                                                 DBG_871X("###### silent reset test.......#####\n");
7106                                                                 rtw_hal_sreset_reset(padapter);                                         
7107                                                         } else {
7108                                                                 HAL_DATA_TYPE   *pHalData = GET_HAL_DATA(padapter);
7109                                                                 struct sreset_priv *psrtpriv = &pHalData->srestpriv;
7110                                                                 psrtpriv->dbg_trigger_point = extra_arg;
7111                                                         }
7112                                                         
7113                                                 }
7114                                         break;
7115                                 case 0x15:
7116                                         {
7117                                                 struct pwrctrl_priv *pwrpriv = adapter_to_pwrctl(padapter);
7118                                                 DBG_871X("==>silent resete cnts:%d\n",pwrpriv->ips_enter_cnts);
7119                                         }
7120                                         break;  
7121                                         
7122                 #endif  
7123
7124                                 case 0x10:// driver version display
7125                                         dump_drv_version(RTW_DBGDUMP);
7126                                         break;
7127                                 case 0x11://dump linked status
7128                                         {
7129                                                  linked_info_dump(padapter,extra_arg);
7130                                         }                                       
7131                                         break;
7132 #ifdef CONFIG_80211N_HT
7133                                 case 0x12: //set rx_stbc
7134                                 {
7135                                         struct registry_priv    *pregpriv = &padapter->registrypriv;
7136                                         // 0: disable, bit(0):enable 2.4g, bit(1):enable 5g, 0x3: enable both 2.4g and 5g
7137                                         //default is set to enable 2.4GHZ for IOT issue with bufflao's AP at 5GHZ
7138                                         if( pregpriv && (extra_arg == 0 || extra_arg == 1|| extra_arg == 2 || extra_arg == 3))
7139                                         {
7140                                                 pregpriv->rx_stbc= extra_arg;
7141                                                 DBG_871X("set rx_stbc=%d\n",pregpriv->rx_stbc);
7142                                         }
7143                                         else
7144                                                 DBG_871X("get rx_stbc=%d\n",pregpriv->rx_stbc);
7145                                         
7146                                 }
7147                                 break;
7148                                 case 0x13: //set ampdu_enable
7149                                 {
7150                                         struct registry_priv    *pregpriv = &padapter->registrypriv;
7151                                         // 0: disable, 0x1:enable (but wifi_spec should be 0), 0x2: force enable (don't care wifi_spec)
7152                                         if( pregpriv && extra_arg < 3 )
7153                                         {
7154                                                 pregpriv->ampdu_enable= extra_arg;
7155                                                 DBG_871X("set ampdu_enable=%d\n",pregpriv->ampdu_enable);
7156                                         }
7157                                         else
7158                                                 DBG_871X("get ampdu_enable=%d\n",pregpriv->ampdu_enable);
7159                                         
7160                                 }
7161                                 break;
7162 #endif
7163                                 case 0x14: //get wifi_spec
7164                                 {
7165                                         struct registry_priv    *pregpriv = &padapter->registrypriv;
7166                                         DBG_871X("get wifi_spec=%d\n",pregpriv->wifi_spec);
7167                                         
7168                                 }
7169                                 break;
7170                                 case 0x16:
7171                                 {
7172                                         if(arg == 0xff){
7173                                                 rtw_odm_dbg_comp_msg(RTW_DBGDUMP,padapter);
7174                                         }
7175                                         else{
7176                                                 u64 dbg_comp = (u64)extra_arg;
7177                                                 rtw_odm_dbg_comp_set(padapter, dbg_comp);
7178                                         }
7179                                 }
7180                                         break;
7181 #ifdef DBG_FIXED_CHAN
7182                                 case 0x17:
7183                                         {
7184                                                 struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);                                           
7185                                                 printk("===>  Fixed channel to %d \n",extra_arg);
7186                                                 pmlmeext->fixed_chan = extra_arg;       
7187                                                 
7188                                         }
7189                                         break;
7190 #endif
7191                                 case 0x18:
7192                                         {
7193                                                 printk("===>  Switch USB Mode %d \n",extra_arg);
7194                                                 rtw_hal_set_hwreg(padapter, HW_VAR_USB_MODE, (u8 *)&extra_arg);
7195                                         }
7196                                         break;
7197                                 case 0x23:
7198                                         {
7199                                                 DBG_871X("turn %s the bNotifyChannelChange Variable\n",(extra_arg==1)?"on":"off");
7200                                                 padapter->bNotifyChannelChange = extra_arg;
7201                                                 break;
7202                                         }
7203                                 case 0x24:
7204                                         {
7205 #ifdef CONFIG_P2P
7206                                                 DBG_871X("turn %s the bShowGetP2PState Variable\n",(extra_arg==1)?"on":"off");
7207                                                 padapter->bShowGetP2PState = extra_arg;
7208 #endif // CONFIG_P2P
7209                                                 break;                                          
7210                                         }
7211 #ifdef CONFIG_GPIO_API              
7212                             case 0x25: //Get GPIO register
7213                                     {
7214                                             /*
7215                                             * dbg 0x7f250000 [gpio_num], Get gpio value, gpio_num:0~7
7216                                             */                
7217                               
7218                                             int value;
7219                                             DBG_871X("Read GPIO Value  extra_arg = %d\n",extra_arg);
7220                                             value = rtw_get_gpio(dev,extra_arg);
7221                                             DBG_871X("Read GPIO Value = %d\n",value);                                        
7222                                             break;
7223                                     }
7224                             case 0x26: //Set GPIO direction
7225                                     {
7226                                                                                 
7227                                             /* dbg 0x7f26000x [y], Set gpio direction, 
7228                                             * x: gpio_num,4~7  y: indicate direction, 0~1  
7229                                             */ 
7230                                         
7231                                             int value;
7232                                             DBG_871X("Set GPIO Direction! arg = %d ,extra_arg=%d\n",arg ,extra_arg);
7233                                             value = rtw_config_gpio(dev, arg, extra_arg);
7234                                             DBG_871X("Set GPIO Direction %s \n",(value==-1)?"Fail!!!":"Success");
7235                                             break;
7236                                         }
7237                                 case 0x27: //Set GPIO output direction value
7238                                         {
7239                                                 /*
7240                                                 * dbg 0x7f27000x [y], Set gpio output direction value, 
7241                                                 * x: gpio_num,4~7  y: indicate direction, 0~1  
7242                                                 */ 
7243                                         
7244                                                 int value;
7245                                                 DBG_871X("Set GPIO Value! arg = %d ,extra_arg=%d\n",arg ,extra_arg);
7246                                                 value = rtw_set_gpio_output_value(dev,arg,extra_arg);
7247                                                 DBG_871X("Set GPIO Value %s \n",(value==-1)?"Fail!!!":"Success");
7248                                                 break;
7249                                         }
7250 #endif                            
7251                                 case 0xaa:
7252                                         {
7253                                                 if((extra_arg & 0x7F)> 0x3F) extra_arg = 0xFF;
7254                                                 DBG_871X("chang data rate to :0x%02x\n",extra_arg);
7255                                                 padapter->fix_rate = extra_arg;
7256                                         }
7257                                         break;  
7258                                 case 0xdd://registers dump , 0 for mac reg,1 for bb reg, 2 for rf reg
7259                                         {
7260                                                 if(extra_arg==0){
7261                                                         mac_reg_dump(RTW_DBGDUMP, padapter);
7262                                                 }
7263                                                 else if(extra_arg==1){
7264                                                         bb_reg_dump(RTW_DBGDUMP, padapter);
7265                                                 }
7266                                                 else if(extra_arg==2){
7267                                                         rf_reg_dump(RTW_DBGDUMP, padapter);
7268                                                 }
7269                                         }
7270                                         break;          
7271
7272                                 case 0xee://turn on/off dynamic funcs
7273                                         {
7274                                                 u32 odm_flag;
7275
7276                                                 if(0xf==extra_arg){
7277                                                         rtw_hal_get_def_var(padapter, HAL_DEF_DBG_DM_FUNC,&odm_flag);                                                   
7278                                                         DBG_871X(" === DMFlag(0x%08x) === \n",odm_flag);
7279                                                         DBG_871X("extra_arg = 0  - disable all dynamic func \n");
7280                                                         DBG_871X("extra_arg = 1  - disable DIG- BIT(0)\n");
7281                                                         DBG_871X("extra_arg = 2  - disable High power - BIT(1)\n");
7282                                                         DBG_871X("extra_arg = 3  - disable tx power tracking - BIT(2)\n");
7283                                                         DBG_871X("extra_arg = 4  - disable BT coexistence - BIT(3)\n");
7284                                                         DBG_871X("extra_arg = 5  - disable antenna diversity - BIT(4)\n");
7285                                                         DBG_871X("extra_arg = 6  - enable all dynamic func \n");                                                        
7286                                                 }
7287                                                 else{
7288                                                         /*      extra_arg = 0  - disable all dynamic func
7289                                                                 extra_arg = 1  - disable DIG
7290                                                                 extra_arg = 2  - disable tx power tracking
7291                                                                 extra_arg = 3  - turn on all dynamic func
7292                                                         */                      
7293                                                         rtw_hal_set_def_var(padapter, HAL_DEF_DBG_DM_FUNC, &(extra_arg));
7294                                                         rtw_hal_get_def_var(padapter, HAL_DEF_DBG_DM_FUNC,&odm_flag);                                                   
7295                                                         DBG_871X(" === DMFlag(0x%08x) === \n",odm_flag);
7296                                                 }
7297                                         }
7298                                         break;
7299
7300                                 case 0xfd:
7301                                         rtw_write8(padapter, 0xc50, arg);
7302                                         DBG_871X("wr(0xc50)=0x%x\n", rtw_read8(padapter, 0xc50));
7303                                         rtw_write8(padapter, 0xc58, arg);
7304                                         DBG_871X("wr(0xc58)=0x%x\n", rtw_read8(padapter, 0xc58));
7305                                         break;
7306                                 case 0xfe:
7307                                         DBG_871X("rd(0xc50)=0x%x\n", rtw_read8(padapter, 0xc50));
7308                                         DBG_871X("rd(0xc58)=0x%x\n", rtw_read8(padapter, 0xc58));
7309                                         break;
7310                                 case 0xff:
7311                                         {
7312                                                 DBG_871X("dbg(0x210)=0x%x\n", rtw_read32(padapter, 0x210));
7313                                                 DBG_871X("dbg(0x608)=0x%x\n", rtw_read32(padapter, 0x608));
7314                                                 DBG_871X("dbg(0x280)=0x%x\n", rtw_read32(padapter, 0x280));
7315                                                 DBG_871X("dbg(0x284)=0x%x\n", rtw_read32(padapter, 0x284));
7316                                                 DBG_871X("dbg(0x288)=0x%x\n", rtw_read32(padapter, 0x288));
7317         
7318                                                 DBG_871X("dbg(0x664)=0x%x\n", rtw_read32(padapter, 0x664));
7319
7320
7321                                                 DBG_871X("\n");
7322                 
7323                                                 DBG_871X("dbg(0x430)=0x%x\n", rtw_read32(padapter, 0x430));
7324                                                 DBG_871X("dbg(0x438)=0x%x\n", rtw_read32(padapter, 0x438));
7325
7326                                                 DBG_871X("dbg(0x440)=0x%x\n", rtw_read32(padapter, 0x440));
7327         
7328                                                 DBG_871X("dbg(0x458)=0x%x\n", rtw_read32(padapter, 0x458));
7329         
7330                                                 DBG_871X("dbg(0x484)=0x%x\n", rtw_read32(padapter, 0x484));
7331                                                 DBG_871X("dbg(0x488)=0x%x\n", rtw_read32(padapter, 0x488));
7332         
7333                                                 DBG_871X("dbg(0x444)=0x%x\n", rtw_read32(padapter, 0x444));
7334                                                 DBG_871X("dbg(0x448)=0x%x\n", rtw_read32(padapter, 0x448));
7335                                                 DBG_871X("dbg(0x44c)=0x%x\n", rtw_read32(padapter, 0x44c));
7336                                                 DBG_871X("dbg(0x450)=0x%x\n", rtw_read32(padapter, 0x450));
7337                                         }
7338                                         break;
7339                         }                       
7340                         break;
7341                 default:
7342                         DBG_871X("error dbg cmd!\n");
7343                         break;  
7344         }
7345         
7346
7347         return ret;
7348
7349 }
7350
7351 static int wpa_set_param(struct net_device *dev, u8 name, u32 value)
7352 {
7353         uint ret=0;
7354         u32 flags;
7355         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7356         
7357         switch (name){
7358         case IEEE_PARAM_WPA_ENABLED:
7359
7360                 padapter->securitypriv.dot11AuthAlgrthm= dot11AuthAlgrthm_8021X; //802.1x
7361                 
7362                 //ret = ieee80211_wpa_enable(ieee, value);
7363                 
7364                 switch((value)&0xff)
7365                 {
7366                         case 1 : //WPA
7367                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPAPSK; //WPA_PSK
7368                         padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption2Enabled;
7369                                 break;
7370                         case 2: //WPA2
7371                         padapter->securitypriv.ndisauthtype = Ndis802_11AuthModeWPA2PSK; //WPA2_PSK
7372                         padapter->securitypriv.ndisencryptstatus = Ndis802_11Encryption3Enabled;
7373                                 break;
7374                 }
7375                 
7376                 RT_TRACE(_module_rtl871x_ioctl_os_c,_drv_info_,("wpa_set_param:padapter->securitypriv.ndisauthtype=%d\n", padapter->securitypriv.ndisauthtype));
7377                 
7378                 break;
7379
7380         case IEEE_PARAM_TKIP_COUNTERMEASURES:
7381                 //ieee->tkip_countermeasures=value;
7382                 break;
7383
7384         case IEEE_PARAM_DROP_UNENCRYPTED: 
7385         {
7386                 /* HACK:
7387                  *
7388                  * wpa_supplicant calls set_wpa_enabled when the driver
7389                  * is loaded and unloaded, regardless of if WPA is being
7390                  * used.  No other calls are made which can be used to
7391                  * determine if encryption will be used or not prior to
7392                  * association being expected.  If encryption is not being
7393                  * used, drop_unencrypted is set to false, else true -- we
7394                  * can use this to determine if the CAP_PRIVACY_ON bit should
7395                  * be set.
7396                  */
7397                  
7398 #if 0    
7399                 struct ieee80211_security sec = {
7400                         .flags = SEC_ENABLED,
7401                         .enabled = value,
7402                 };
7403                 ieee->drop_unencrypted = value;
7404                 /* We only change SEC_LEVEL for open mode. Others
7405                  * are set by ipw_wpa_set_encryption.
7406                  */
7407                 if (!value) {
7408                         sec.flags |= SEC_LEVEL;
7409                         sec.level = SEC_LEVEL_0;
7410                 }
7411                 else {
7412                         sec.flags |= SEC_LEVEL;
7413                         sec.level = SEC_LEVEL_1;
7414                 }
7415                 if (ieee->set_security)
7416                         ieee->set_security(ieee->dev, &sec);
7417 #endif          
7418                 break;
7419
7420         }
7421         case IEEE_PARAM_PRIVACY_INVOKED:        
7422                 
7423                 //ieee->privacy_invoked=value;
7424                 
7425                 break;
7426
7427         case IEEE_PARAM_AUTH_ALGS:
7428                 
7429                 ret = wpa_set_auth_algs(dev, value);
7430                 
7431                 break;
7432
7433         case IEEE_PARAM_IEEE_802_1X:
7434                 
7435                 //ieee->ieee802_1x=value;               
7436                 
7437                 break;
7438                 
7439         case IEEE_PARAM_WPAX_SELECT:
7440                 
7441                 // added for WPA2 mixed mode
7442                 //DBG_871X(KERN_WARNING "------------------------>wpax value = %x\n", value);
7443                 /*
7444                 spin_lock_irqsave(&ieee->wpax_suitlist_lock,flags);
7445                 ieee->wpax_type_set = 1;
7446                 ieee->wpax_type_notify = value;
7447                 spin_unlock_irqrestore(&ieee->wpax_suitlist_lock,flags);
7448                 */
7449                 
7450                 break;
7451
7452         default:                
7453
7454
7455                 
7456                 ret = -EOPNOTSUPP;
7457
7458                 
7459                 break;
7460         
7461         }
7462
7463         return ret;
7464         
7465 }
7466
7467 static int wpa_mlme(struct net_device *dev, u32 command, u32 reason)
7468 {       
7469         int ret = 0;
7470         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7471
7472         switch (command)
7473         {
7474                 case IEEE_MLME_STA_DEAUTH:
7475
7476                         if(!rtw_set_802_11_disassociate(padapter))
7477                                 ret = -1;               
7478                         
7479                         break;
7480
7481                 case IEEE_MLME_STA_DISASSOC:
7482                 
7483                         if(!rtw_set_802_11_disassociate(padapter))
7484                                 ret = -1;               
7485         
7486                         break;
7487
7488                 default:
7489                         ret = -EOPNOTSUPP;
7490                         break;
7491         }
7492
7493         return ret;
7494         
7495 }
7496
7497 static int wpa_supplicant_ioctl(struct net_device *dev, struct iw_point *p)
7498 {
7499         struct ieee_param *param;
7500         uint ret=0;
7501
7502         //down(&ieee->wx_sem);  
7503
7504         if (p->length < sizeof(struct ieee_param) || !p->pointer){
7505                 ret = -EINVAL;
7506                 goto out;
7507         }
7508         
7509         param = (struct ieee_param *)rtw_malloc(p->length);
7510         if (param == NULL)
7511         {
7512                 ret = -ENOMEM;
7513                 goto out;
7514         }
7515         
7516         if (copy_from_user(param, p->pointer, p->length))
7517         {
7518                 rtw_mfree((u8*)param, p->length);
7519                 ret = -EFAULT;
7520                 goto out;
7521         }
7522
7523         switch (param->cmd) {
7524
7525         case IEEE_CMD_SET_WPA_PARAM:
7526                 ret = wpa_set_param(dev, param->u.wpa_param.name, param->u.wpa_param.value);
7527                 break;
7528
7529         case IEEE_CMD_SET_WPA_IE:
7530                 //ret = wpa_set_wpa_ie(dev, param, p->length);
7531                 ret =  rtw_set_wpa_ie((_adapter *)rtw_netdev_priv(dev), (char*)param->u.wpa_ie.data, (u16)param->u.wpa_ie.len);
7532                 break;
7533
7534         case IEEE_CMD_SET_ENCRYPTION:
7535                 ret = wpa_set_encryption(dev, param, p->length);
7536                 break;
7537
7538         case IEEE_CMD_MLME:
7539                 ret = wpa_mlme(dev, param->u.mlme.command, param->u.mlme.reason_code);
7540                 break;
7541
7542         default:
7543                 DBG_871X("Unknown WPA supplicant request: %d\n", param->cmd);
7544                 ret = -EOPNOTSUPP;
7545                 break;
7546                 
7547         }
7548
7549         if (ret == 0 && copy_to_user(p->pointer, param, p->length))
7550                 ret = -EFAULT;
7551
7552         rtw_mfree((u8 *)param, p->length);
7553         
7554 out:
7555         
7556         //up(&ieee->wx_sem);
7557         
7558         return ret;
7559         
7560 }
7561
7562 #ifdef CONFIG_AP_MODE
7563 static int rtw_set_encryption(struct net_device *dev, struct ieee_param *param, u32 param_len)
7564 {
7565         int ret = 0;
7566         u32 wep_key_idx, wep_key_len,wep_total_len;
7567         NDIS_802_11_WEP  *pwep = NULL;
7568         struct sta_info *psta = NULL, *pbcmc_sta = NULL;        
7569         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7570         struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;
7571         struct security_priv* psecuritypriv=&(padapter->securitypriv);
7572         struct sta_priv *pstapriv = &padapter->stapriv;
7573
7574         DBG_871X("%s\n", __FUNCTION__);
7575
7576         param->u.crypt.err = 0;
7577         param->u.crypt.alg[IEEE_CRYPT_ALG_NAME_LEN - 1] = '\0';
7578
7579         //sizeof(struct ieee_param) = 64 bytes;
7580         //if (param_len !=  (u32) ((u8 *) param->u.crypt.key - (u8 *) param) + param->u.crypt.key_len)
7581         if (param_len !=  sizeof(struct ieee_param) + param->u.crypt.key_len)
7582         {
7583                 ret =  -EINVAL;
7584                 goto exit;
7585         }
7586
7587         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
7588             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
7589             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
7590         {
7591                 if (param->u.crypt.idx >= WEP_KEYS)
7592                 {
7593                         ret = -EINVAL;
7594                         goto exit;
7595                 }       
7596         }
7597         else 
7598         {               
7599                 psta = rtw_get_stainfo(pstapriv, param->sta_addr);
7600                 if(!psta)
7601                 {
7602                         //ret = -EINVAL;
7603                         DBG_871X("rtw_set_encryption(), sta has already been removed or never been added\n");
7604                         goto exit;
7605                 }                       
7606         }
7607
7608         if (strcmp(param->u.crypt.alg, "none") == 0 && (psta==NULL))
7609         {
7610                 //todo:clear default encryption keys
7611
7612                 psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_Open;
7613                 psecuritypriv->ndisencryptstatus = Ndis802_11EncryptionDisabled;
7614                 psecuritypriv->dot11PrivacyAlgrthm = _NO_PRIVACY_;
7615                 psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
7616
7617                 DBG_871X("clear default encryption keys, keyid=%d\n", param->u.crypt.idx);
7618                 
7619                 goto exit;
7620         }
7621
7622
7623         if (strcmp(param->u.crypt.alg, "WEP") == 0 && (psta==NULL))
7624         {               
7625                 DBG_871X("r871x_set_encryption, crypt.alg = WEP\n");
7626                 
7627                 wep_key_idx = param->u.crypt.idx;
7628                 wep_key_len = param->u.crypt.key_len;
7629                                         
7630                 DBG_871X("r871x_set_encryption, wep_key_idx=%d, len=%d\n", wep_key_idx, wep_key_len);
7631
7632                 if((wep_key_idx >= WEP_KEYS) || (wep_key_len<=0))
7633                 {
7634                         ret = -EINVAL;
7635                         goto exit;
7636                 }
7637                         
7638
7639                 if (wep_key_len > 0) 
7640                 {                       
7641                         wep_key_len = wep_key_len <= 5 ? 5 : 13;
7642                         wep_total_len = wep_key_len + FIELD_OFFSET(NDIS_802_11_WEP, KeyMaterial);
7643                         pwep =(NDIS_802_11_WEP *)rtw_malloc(wep_total_len);
7644                         if(pwep == NULL){
7645                                 DBG_871X(" r871x_set_encryption: pwep allocate fail !!!\n");
7646                                 goto exit;
7647                         }
7648                         
7649                         _rtw_memset(pwep, 0, wep_total_len);
7650                 
7651                         pwep->KeyLength = wep_key_len;
7652                         pwep->Length = wep_total_len;
7653                         
7654                 }
7655                 
7656                 pwep->KeyIndex = wep_key_idx;
7657
7658                 _rtw_memcpy(pwep->KeyMaterial,  param->u.crypt.key, pwep->KeyLength);
7659
7660                 if(param->u.crypt.set_tx)
7661                 {
7662                         DBG_871X("wep, set_tx=1\n");
7663
7664                         psecuritypriv->dot11AuthAlgrthm = dot11AuthAlgrthm_Auto;
7665                         psecuritypriv->ndisencryptstatus = Ndis802_11Encryption1Enabled;
7666                         psecuritypriv->dot11PrivacyAlgrthm=_WEP40_;
7667                         psecuritypriv->dot118021XGrpPrivacy=_WEP40_;
7668                         
7669                         if(pwep->KeyLength==13)
7670                         {
7671                                 psecuritypriv->dot11PrivacyAlgrthm=_WEP104_;
7672                                 psecuritypriv->dot118021XGrpPrivacy=_WEP104_;
7673                         }
7674
7675                 
7676                         psecuritypriv->dot11PrivacyKeyIndex = wep_key_idx;
7677                         
7678                         _rtw_memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
7679
7680                         psecuritypriv->dot11DefKeylen[wep_key_idx]=pwep->KeyLength;
7681
7682                         rtw_ap_set_wep_key(padapter, pwep->KeyMaterial, pwep->KeyLength, wep_key_idx, 1);
7683                 }
7684                 else
7685                 {
7686                         DBG_871X("wep, set_tx=0\n");
7687                         
7688                         //don't update "psecuritypriv->dot11PrivacyAlgrthm" and 
7689                         //"psecuritypriv->dot11PrivacyKeyIndex=keyid", but can rtw_set_key to cam
7690                                         
7691                       _rtw_memcpy(&(psecuritypriv->dot11DefKey[wep_key_idx].skey[0]), pwep->KeyMaterial, pwep->KeyLength);
7692
7693                         psecuritypriv->dot11DefKeylen[wep_key_idx] = pwep->KeyLength;                   
7694
7695                         rtw_ap_set_wep_key(padapter, pwep->KeyMaterial, pwep->KeyLength, wep_key_idx, 0);
7696                 }
7697
7698                 goto exit;
7699                 
7700         }
7701
7702         
7703         if(!psta && check_fwstate(pmlmepriv, WIFI_AP_STATE)) // //group key
7704         {
7705                 if(param->u.crypt.set_tx ==1)
7706                 {
7707                         if(strcmp(param->u.crypt.alg, "WEP") == 0)
7708                         {
7709                                 DBG_871X("%s, set group_key, WEP\n", __FUNCTION__);
7710                                 
7711                                 _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
7712                                         
7713                                 psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
7714                                 if(param->u.crypt.key_len==13)
7715                                 {                                               
7716                                                 psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
7717                                 }
7718                                 
7719                         }
7720                         else if(strcmp(param->u.crypt.alg, "TKIP") == 0)
7721                         {                                               
7722                                 DBG_871X("%s, set group_key, TKIP\n", __FUNCTION__);
7723                                 
7724                                 psecuritypriv->dot118021XGrpPrivacy = _TKIP_;
7725
7726                                 _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
7727                                 
7728                                 //DEBUG_ERR("set key length :param->u.crypt.key_len=%d\n", param->u.crypt.key_len);
7729                                 //set mic key
7730                                 _rtw_memcpy(psecuritypriv->dot118021XGrptxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[16]), 8);
7731                                 _rtw_memcpy(psecuritypriv->dot118021XGrprxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[24]), 8);
7732
7733                                 psecuritypriv->busetkipkey = _TRUE;
7734                                                                                         
7735                         }
7736                         else if(strcmp(param->u.crypt.alg, "CCMP") == 0)
7737                         {
7738                                 DBG_871X("%s, set group_key, CCMP\n", __FUNCTION__);
7739                         
7740                                 psecuritypriv->dot118021XGrpPrivacy = _AES_;
7741
7742                                 _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
7743                         }
7744                         else
7745                         {
7746                                 DBG_871X("%s, set group_key, none\n", __FUNCTION__);
7747                                 
7748                                 psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
7749                         }
7750
7751                         psecuritypriv->dot118021XGrpKeyid = param->u.crypt.idx;
7752
7753                         psecuritypriv->binstallGrpkey = _TRUE;
7754
7755                         psecuritypriv->dot11PrivacyAlgrthm = psecuritypriv->dot118021XGrpPrivacy;//!!!
7756                                                                 
7757                         rtw_ap_set_group_key(padapter, param->u.crypt.key, psecuritypriv->dot118021XGrpPrivacy, param->u.crypt.idx);
7758                         
7759                         pbcmc_sta=rtw_get_bcmc_stainfo(padapter);
7760                         if(pbcmc_sta)
7761                         {
7762                                 pbcmc_sta->ieee8021x_blocked = _FALSE;
7763                                 pbcmc_sta->dot118021XPrivacy= psecuritypriv->dot118021XGrpPrivacy;//rx will use bmc_sta's dot118021XPrivacy                     
7764                         }       
7765                                                 
7766                 }
7767
7768                 goto exit;
7769                 
7770         }       
7771
7772         if(psecuritypriv->dot11AuthAlgrthm == dot11AuthAlgrthm_8021X && psta) // psk/802_1x
7773         {
7774                 if(check_fwstate(pmlmepriv, WIFI_AP_STATE))
7775                 {
7776                         if(param->u.crypt.set_tx ==1)
7777                         { 
7778                                 _rtw_memcpy(psta->dot118021x_UncstKey.skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
7779                                 
7780                                 if(strcmp(param->u.crypt.alg, "WEP") == 0)
7781                                 {
7782                                         DBG_871X("%s, set pairwise key, WEP\n", __FUNCTION__);
7783                                         
7784                                         psta->dot118021XPrivacy = _WEP40_;
7785                                         if(param->u.crypt.key_len==13)
7786                                         {                                               
7787                                                 psta->dot118021XPrivacy = _WEP104_;
7788                                         }
7789                                 }
7790                                 else if(strcmp(param->u.crypt.alg, "TKIP") == 0)
7791                                 {                                               
7792                                         DBG_871X("%s, set pairwise key, TKIP\n", __FUNCTION__);
7793                                         
7794                                         psta->dot118021XPrivacy = _TKIP_;
7795                                 
7796                                         //DEBUG_ERR("set key length :param->u.crypt.key_len=%d\n", param->u.crypt.key_len);
7797                                         //set mic key
7798                                         _rtw_memcpy(psta->dot11tkiptxmickey.skey, &(param->u.crypt.key[16]), 8);
7799                                         _rtw_memcpy(psta->dot11tkiprxmickey.skey, &(param->u.crypt.key[24]), 8);
7800
7801                                         psecuritypriv->busetkipkey = _TRUE;
7802                                                                                         
7803                                 }
7804                                 else if(strcmp(param->u.crypt.alg, "CCMP") == 0)
7805                                 {
7806
7807                                         DBG_871X("%s, set pairwise key, CCMP\n", __FUNCTION__);
7808                                         
7809                                         psta->dot118021XPrivacy = _AES_;
7810                                 }
7811                                 else
7812                                 {
7813                                         DBG_871X("%s, set pairwise key, none\n", __FUNCTION__);
7814                                         
7815                                         psta->dot118021XPrivacy = _NO_PRIVACY_;
7816                                 }
7817                                                 
7818                                 rtw_ap_set_pairwise_key(padapter, psta);
7819                                         
7820                                 psta->ieee8021x_blocked = _FALSE;
7821                                         
7822                         }                       
7823                         else//group key???
7824                         { 
7825                                 if(strcmp(param->u.crypt.alg, "WEP") == 0)
7826                                 {
7827                                         _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
7828                                         
7829                                         psecuritypriv->dot118021XGrpPrivacy = _WEP40_;
7830                                         if(param->u.crypt.key_len==13)
7831                                         {                                               
7832                                                 psecuritypriv->dot118021XGrpPrivacy = _WEP104_;
7833                                         }
7834                                 }
7835                                 else if(strcmp(param->u.crypt.alg, "TKIP") == 0)
7836                                 {                                               
7837                                         psecuritypriv->dot118021XGrpPrivacy = _TKIP_;
7838
7839                                         _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
7840                                 
7841                                         //DEBUG_ERR("set key length :param->u.crypt.key_len=%d\n", param->u.crypt.key_len);
7842                                         //set mic key
7843                                         _rtw_memcpy(psecuritypriv->dot118021XGrptxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[16]), 8);
7844                                         _rtw_memcpy(psecuritypriv->dot118021XGrprxmickey[param->u.crypt.idx].skey, &(param->u.crypt.key[24]), 8);
7845
7846                                         psecuritypriv->busetkipkey = _TRUE;
7847                                                                                         
7848                                 }
7849                                 else if(strcmp(param->u.crypt.alg, "CCMP") == 0)
7850                                 {
7851                                         psecuritypriv->dot118021XGrpPrivacy = _AES_;
7852
7853                                         _rtw_memcpy(psecuritypriv->dot118021XGrpKey[param->u.crypt.idx].skey,  param->u.crypt.key, (param->u.crypt.key_len>16 ?16:param->u.crypt.key_len));
7854                                 }
7855                                 else
7856                                 {
7857                                         psecuritypriv->dot118021XGrpPrivacy = _NO_PRIVACY_;
7858                                 }
7859
7860                                 psecuritypriv->dot118021XGrpKeyid = param->u.crypt.idx;
7861
7862                                 psecuritypriv->binstallGrpkey = _TRUE;  
7863                                                                 
7864                                 psecuritypriv->dot11PrivacyAlgrthm = psecuritypriv->dot118021XGrpPrivacy;//!!!
7865                                                                 
7866                                 rtw_ap_set_group_key(padapter, param->u.crypt.key, psecuritypriv->dot118021XGrpPrivacy, param->u.crypt.idx);
7867                         
7868                                 pbcmc_sta=rtw_get_bcmc_stainfo(padapter);
7869                                 if(pbcmc_sta)
7870                                 {
7871                                         pbcmc_sta->ieee8021x_blocked = _FALSE;
7872                                         pbcmc_sta->dot118021XPrivacy= psecuritypriv->dot118021XGrpPrivacy;//rx will use bmc_sta's dot118021XPrivacy                     
7873                                 }                                       
7874
7875                         }
7876                         
7877                 }
7878                                 
7879         }
7880
7881 exit:
7882
7883         if(pwep)
7884         {
7885                 rtw_mfree((u8 *)pwep, wep_total_len);           
7886         }       
7887         
7888         return ret;
7889         
7890 }
7891
7892 static int rtw_set_beacon(struct net_device *dev, struct ieee_param *param, int len)
7893 {
7894         int ret=0;      
7895         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7896         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
7897         struct sta_priv *pstapriv = &padapter->stapriv;
7898         unsigned char *pbuf = param->u.bcn_ie.buf;
7899
7900
7901         DBG_871X("%s, len=%d\n", __FUNCTION__, len);
7902
7903         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
7904                 return -EINVAL;
7905
7906         _rtw_memcpy(&pstapriv->max_num_sta, param->u.bcn_ie.reserved, 2);
7907
7908         if((pstapriv->max_num_sta>NUM_STA) || (pstapriv->max_num_sta<=0))
7909                 pstapriv->max_num_sta = NUM_STA;
7910
7911
7912         if(rtw_check_beacon_data(padapter, pbuf,  (len-12-2)) == _SUCCESS)// 12 = param header, 2:no packed
7913                 ret = 0;
7914         else
7915                 ret = -EINVAL;
7916         
7917
7918         return ret;
7919         
7920 }
7921
7922 static int rtw_hostapd_sta_flush(struct net_device *dev)
7923 {
7924         //_irqL irqL;
7925         //_list *phead, *plist;
7926         int ret=0;      
7927         //struct sta_info *psta = NULL;
7928         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
7929         //struct sta_priv *pstapriv = &padapter->stapriv;
7930
7931         DBG_871X("%s\n", __FUNCTION__);
7932
7933         flush_all_cam_entry(padapter);  //clear CAM
7934
7935         ret = rtw_sta_flush(padapter);  
7936
7937         return ret;
7938
7939 }
7940
7941 static int rtw_add_sta(struct net_device *dev, struct ieee_param *param)
7942 {
7943         _irqL irqL;
7944         int ret=0;      
7945         struct sta_info *psta = NULL;
7946         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
7947         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
7948         struct sta_priv *pstapriv = &padapter->stapriv;
7949
7950         DBG_871X("rtw_add_sta(aid=%d)=" MAC_FMT "\n", param->u.add_sta.aid, MAC_ARG(param->sta_addr));
7951         
7952         if(check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != _TRUE)       
7953         {
7954                 return -EINVAL;         
7955         }
7956
7957         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
7958             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
7959             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
7960         {
7961                 return -EINVAL; 
7962         }
7963
7964 /*
7965         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
7966         if(psta)
7967         {
7968                 DBG_871X("rtw_add_sta(), free has been added psta=%p\n", psta);
7969                 _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);          
7970                 rtw_free_stainfo(padapter,  psta);              
7971                 _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL);
7972
7973                 psta = NULL;
7974         }       
7975 */
7976         //psta = rtw_alloc_stainfo(pstapriv, param->sta_addr);
7977         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
7978         if(psta)
7979         {
7980                 int flags = param->u.add_sta.flags;                     
7981                 
7982                 //DBG_871X("rtw_add_sta(), init sta's variables, psta=%p\n", psta);
7983                 
7984                 psta->aid = param->u.add_sta.aid;//aid=1~2007
7985
7986                 _rtw_memcpy(psta->bssrateset, param->u.add_sta.tx_supp_rates, 16);
7987                 
7988                 
7989                 //check wmm cap.
7990                 if(WLAN_STA_WME&flags)
7991                         psta->qos_option = 1;
7992                 else
7993                         psta->qos_option = 0;
7994
7995                 if(pmlmepriv->qospriv.qos_option == 0)  
7996                         psta->qos_option = 0;
7997
7998                 
7999 #ifdef CONFIG_80211N_HT         
8000                 //chec 802.11n ht cap.
8001                 if(WLAN_STA_HT&flags)
8002                 {
8003                         psta->htpriv.ht_option = _TRUE;
8004                         psta->qos_option = 1;
8005                         _rtw_memcpy((void*)&psta->htpriv.ht_cap, (void*)&param->u.add_sta.ht_cap, sizeof(struct rtw_ieee80211_ht_cap));
8006                 }
8007                 else            
8008                 {
8009                         psta->htpriv.ht_option = _FALSE;
8010                 }
8011                 
8012                 if(pmlmepriv->htpriv.ht_option == _FALSE)       
8013                         psta->htpriv.ht_option = _FALSE;
8014 #endif          
8015
8016
8017                 update_sta_info_apmode(padapter, psta);
8018                 
8019                 
8020         }
8021         else
8022         {
8023                 ret = -ENOMEM;
8024         }       
8025         
8026         return ret;
8027         
8028 }
8029
8030 static int rtw_del_sta(struct net_device *dev, struct ieee_param *param)
8031 {
8032         _irqL irqL;
8033         int ret=0;      
8034         struct sta_info *psta = NULL;
8035         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8036         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8037         struct sta_priv *pstapriv = &padapter->stapriv;
8038
8039         DBG_871X("rtw_del_sta=" MAC_FMT "\n", MAC_ARG(param->sta_addr));
8040                 
8041         if(check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != _TRUE)               
8042         {
8043                 return -EINVAL;         
8044         }
8045
8046         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
8047             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
8048             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
8049         {
8050                 return -EINVAL; 
8051         }
8052
8053         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
8054         if(psta)
8055         {
8056                 u8 updated=_FALSE;
8057         
8058                 //DBG_871X("free psta=%p, aid=%d\n", psta, psta->aid);
8059
8060                 _enter_critical_bh(&pstapriv->asoc_list_lock, &irqL);
8061                 if(rtw_is_list_empty(&psta->asoc_list)==_FALSE)
8062                 {                       
8063                         rtw_list_delete(&psta->asoc_list);
8064                         pstapriv->asoc_list_cnt--;
8065                         updated = ap_free_sta(padapter, psta, _TRUE, WLAN_REASON_DEAUTH_LEAVING);
8066
8067                 }
8068                 _exit_critical_bh(&pstapriv->asoc_list_lock, &irqL);
8069                 
8070                 associated_clients_update(padapter, updated);
8071         
8072                 psta = NULL;
8073                 
8074         }
8075         else
8076         {
8077                 DBG_871X("rtw_del_sta(), sta has already been removed or never been added\n");
8078                 
8079                 //ret = -1;
8080         }
8081         
8082         
8083         return ret;
8084         
8085 }
8086
8087 static int rtw_ioctl_get_sta_data(struct net_device *dev, struct ieee_param *param, int len)
8088 {
8089         int ret=0;      
8090         struct sta_info *psta = NULL;
8091         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8092         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8093         struct sta_priv *pstapriv = &padapter->stapriv;
8094         struct ieee_param_ex *param_ex = (struct ieee_param_ex *)param;
8095         struct sta_data *psta_data = (struct sta_data *)param_ex->data;
8096
8097         DBG_871X("rtw_ioctl_get_sta_info, sta_addr: " MAC_FMT "\n", MAC_ARG(param_ex->sta_addr));
8098
8099         if(check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != _TRUE)               
8100         {
8101                 return -EINVAL;         
8102         }
8103
8104         if (param_ex->sta_addr[0] == 0xff && param_ex->sta_addr[1] == 0xff &&
8105             param_ex->sta_addr[2] == 0xff && param_ex->sta_addr[3] == 0xff &&
8106             param_ex->sta_addr[4] == 0xff && param_ex->sta_addr[5] == 0xff) 
8107         {
8108                 return -EINVAL; 
8109         }
8110
8111         psta = rtw_get_stainfo(pstapriv, param_ex->sta_addr);
8112         if(psta)
8113         {
8114 #if 0
8115                 struct {
8116                         u16 aid;
8117                         u16 capability;
8118                         int flags;
8119                         u32 sta_set;
8120                         u8 tx_supp_rates[16];   
8121                         u32 tx_supp_rates_len;
8122                         struct rtw_ieee80211_ht_cap ht_cap;
8123                         u64     rx_pkts;
8124                         u64     rx_bytes;
8125                         u64     rx_drops;
8126                         u64     tx_pkts;
8127                         u64     tx_bytes;
8128                         u64     tx_drops;
8129                 } get_sta;              
8130 #endif
8131                 psta_data->aid = (u16)psta->aid;
8132                 psta_data->capability = psta->capability;
8133                 psta_data->flags = psta->flags;
8134
8135 /*
8136                 nonerp_set : BIT(0)
8137                 no_short_slot_time_set : BIT(1)
8138                 no_short_preamble_set : BIT(2)
8139                 no_ht_gf_set : BIT(3)
8140                 no_ht_set : BIT(4)
8141                 ht_20mhz_set : BIT(5)
8142 */
8143
8144                 psta_data->sta_set =((psta->nonerp_set) |
8145                                                         (psta->no_short_slot_time_set <<1) |
8146                                                         (psta->no_short_preamble_set <<2) |
8147                                                         (psta->no_ht_gf_set <<3) |
8148                                                         (psta->no_ht_set <<4) |
8149                                                         (psta->ht_20mhz_set <<5));
8150
8151                 psta_data->tx_supp_rates_len =  psta->bssratelen;
8152                 _rtw_memcpy(psta_data->tx_supp_rates, psta->bssrateset, psta->bssratelen);
8153 #ifdef CONFIG_80211N_HT
8154                 _rtw_memcpy(&psta_data->ht_cap, &psta->htpriv.ht_cap, sizeof(struct rtw_ieee80211_ht_cap));
8155 #endif //CONFIG_80211N_HT
8156                 psta_data->rx_pkts = psta->sta_stats.rx_data_pkts;
8157                 psta_data->rx_bytes = psta->sta_stats.rx_bytes;
8158                 psta_data->rx_drops = psta->sta_stats.rx_drops;
8159
8160                 psta_data->tx_pkts = psta->sta_stats.tx_pkts;
8161                 psta_data->tx_bytes = psta->sta_stats.tx_bytes;
8162                 psta_data->tx_drops = psta->sta_stats.tx_drops;
8163                 
8164
8165         }
8166         else
8167         {
8168                 ret = -1;
8169         }
8170
8171         return ret;
8172
8173 }
8174
8175 static int rtw_get_sta_wpaie(struct net_device *dev, struct ieee_param *param)
8176 {
8177         int ret=0;      
8178         struct sta_info *psta = NULL;
8179         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8180         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8181         struct sta_priv *pstapriv = &padapter->stapriv;
8182
8183         DBG_871X("rtw_get_sta_wpaie, sta_addr: " MAC_FMT "\n", MAC_ARG(param->sta_addr));
8184
8185         if(check_fwstate(pmlmepriv, (_FW_LINKED|WIFI_AP_STATE)) != _TRUE)               
8186         {
8187                 return -EINVAL;         
8188         }
8189
8190         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
8191             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
8192             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
8193         {
8194                 return -EINVAL; 
8195         }
8196
8197         psta = rtw_get_stainfo(pstapriv, param->sta_addr);
8198         if(psta)
8199         {
8200                 if((psta->wpa_ie[0] == WLAN_EID_RSN) || (psta->wpa_ie[0] == WLAN_EID_GENERIC))
8201                 {
8202                         int wpa_ie_len;
8203                         int copy_len;
8204
8205                         wpa_ie_len = psta->wpa_ie[1];
8206                         
8207                         copy_len = ((wpa_ie_len+2) > sizeof(psta->wpa_ie)) ? (sizeof(psta->wpa_ie)):(wpa_ie_len+2);
8208                                 
8209                         param->u.wpa_ie.len = copy_len;
8210
8211                         _rtw_memcpy(param->u.wpa_ie.reserved, psta->wpa_ie, copy_len);
8212                 }
8213                 else
8214                 {
8215                         //ret = -1;
8216                         DBG_871X("sta's wpa_ie is NONE\n");
8217                 }               
8218         }
8219         else
8220         {
8221                 ret = -1;
8222         }
8223
8224         return ret;
8225
8226 }
8227
8228 static int rtw_set_wps_beacon(struct net_device *dev, struct ieee_param *param, int len)
8229 {
8230         int ret=0;
8231         unsigned char wps_oui[4]={0x0,0x50,0xf2,0x04};
8232         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
8233         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8234         struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);
8235         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
8236         int ie_len;
8237
8238         DBG_871X("%s, len=%d\n", __FUNCTION__, len);
8239
8240         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
8241                 return -EINVAL;
8242
8243         ie_len = len-12-2;// 12 = param header, 2:no packed
8244
8245
8246         if(pmlmepriv->wps_beacon_ie)
8247         {
8248                 rtw_mfree(pmlmepriv->wps_beacon_ie, pmlmepriv->wps_beacon_ie_len);
8249                 pmlmepriv->wps_beacon_ie = NULL;                        
8250         }       
8251
8252         if(ie_len>0)
8253         {
8254                 pmlmepriv->wps_beacon_ie = rtw_malloc(ie_len);
8255                 pmlmepriv->wps_beacon_ie_len = ie_len;
8256                 if ( pmlmepriv->wps_beacon_ie == NULL) {
8257                         DBG_871X("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
8258                         return -EINVAL;
8259                 }
8260
8261                 _rtw_memcpy(pmlmepriv->wps_beacon_ie, param->u.bcn_ie.buf, ie_len);
8262
8263                 update_beacon(padapter, _VENDOR_SPECIFIC_IE_, wps_oui, _TRUE);
8264                 
8265                 pmlmeext->bstart_bss = _TRUE;
8266                 
8267         }
8268         
8269         
8270         return ret;             
8271
8272 }
8273
8274 static int rtw_set_wps_probe_resp(struct net_device *dev, struct ieee_param *param, int len)
8275 {
8276         int ret=0;
8277         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
8278         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8279         int ie_len;
8280
8281         DBG_871X("%s, len=%d\n", __FUNCTION__, len);
8282
8283         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
8284                 return -EINVAL;
8285
8286         ie_len = len-12-2;// 12 = param header, 2:no packed
8287
8288
8289         if(pmlmepriv->wps_probe_resp_ie)
8290         {
8291                 rtw_mfree(pmlmepriv->wps_probe_resp_ie, pmlmepriv->wps_probe_resp_ie_len);
8292                 pmlmepriv->wps_probe_resp_ie = NULL;                    
8293         }       
8294
8295         if(ie_len>0)
8296         {
8297                 pmlmepriv->wps_probe_resp_ie = rtw_malloc(ie_len);
8298                 pmlmepriv->wps_probe_resp_ie_len = ie_len;
8299                 if ( pmlmepriv->wps_probe_resp_ie == NULL) {
8300                         DBG_871X("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
8301                         return -EINVAL;
8302                 }
8303                 _rtw_memcpy(pmlmepriv->wps_probe_resp_ie, param->u.bcn_ie.buf, ie_len);         
8304         }
8305         
8306         
8307         return ret;
8308
8309 }
8310
8311 static int rtw_set_wps_assoc_resp(struct net_device *dev, struct ieee_param *param, int len)
8312 {
8313         int ret=0;
8314         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
8315         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8316         int ie_len;
8317
8318         DBG_871X("%s, len=%d\n", __FUNCTION__, len);
8319
8320         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
8321                 return -EINVAL;
8322
8323         ie_len = len-12-2;// 12 = param header, 2:no packed
8324
8325
8326         if(pmlmepriv->wps_assoc_resp_ie)
8327         {
8328                 rtw_mfree(pmlmepriv->wps_assoc_resp_ie, pmlmepriv->wps_assoc_resp_ie_len);
8329                 pmlmepriv->wps_assoc_resp_ie = NULL;                    
8330         }       
8331
8332         if(ie_len>0)
8333         {
8334                 pmlmepriv->wps_assoc_resp_ie = rtw_malloc(ie_len);
8335                 pmlmepriv->wps_assoc_resp_ie_len = ie_len;
8336                 if ( pmlmepriv->wps_assoc_resp_ie == NULL) {
8337                         DBG_871X("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
8338                         return -EINVAL;
8339                 }
8340                 
8341                 _rtw_memcpy(pmlmepriv->wps_assoc_resp_ie, param->u.bcn_ie.buf, ie_len);         
8342         }
8343         
8344         
8345         return ret;
8346
8347 }
8348
8349 static int rtw_set_hidden_ssid(struct net_device *dev, struct ieee_param *param, int len)
8350 {
8351         int ret=0;
8352         _adapter *adapter = (_adapter *)rtw_netdev_priv(dev);
8353         struct mlme_priv *mlmepriv = &(adapter->mlmepriv);
8354         struct mlme_ext_priv    *mlmeext = &(adapter->mlmeextpriv);
8355         struct mlme_ext_info    *mlmeinfo = &(mlmeext->mlmext_info);
8356         int ie_len;
8357         u8 *ssid_ie;
8358         char ssid[NDIS_802_11_LENGTH_SSID + 1];
8359         sint ssid_len;
8360         u8 ignore_broadcast_ssid;
8361
8362         if(check_fwstate(mlmepriv, WIFI_AP_STATE) != _TRUE)
8363                 return -EPERM;
8364
8365         if (param->u.bcn_ie.reserved[0] != 0xea)
8366                 return -EINVAL;
8367
8368         mlmeinfo->hidden_ssid_mode = ignore_broadcast_ssid = param->u.bcn_ie.reserved[1];
8369
8370         ie_len = len-12-2;// 12 = param header, 2:no packed
8371         ssid_ie = rtw_get_ie(param->u.bcn_ie.buf,  WLAN_EID_SSID, &ssid_len, ie_len);
8372
8373         if (ssid_ie && ssid_len > 0 && ssid_len <= NDIS_802_11_LENGTH_SSID) {
8374                 WLAN_BSSID_EX *pbss_network = &mlmepriv->cur_network.network;
8375                 WLAN_BSSID_EX *pbss_network_ext = &mlmeinfo->network;
8376
8377                 _rtw_memcpy(ssid, ssid_ie+2, ssid_len);
8378                 ssid[ssid_len] = 0x0;
8379
8380                 if(0)
8381                 DBG_871X(FUNC_ADPT_FMT" ssid:(%s,%d), from ie:(%s,%d), (%s,%d)\n", FUNC_ADPT_ARG(adapter),
8382                         ssid, ssid_len,
8383                         pbss_network->Ssid.Ssid, pbss_network->Ssid.SsidLength,
8384                         pbss_network_ext->Ssid.Ssid, pbss_network_ext->Ssid.SsidLength);
8385
8386                 _rtw_memcpy(pbss_network->Ssid.Ssid, (void *)ssid, ssid_len);
8387                 pbss_network->Ssid.SsidLength = ssid_len;
8388                 _rtw_memcpy(pbss_network_ext->Ssid.Ssid, (void *)ssid, ssid_len);
8389                 pbss_network_ext->Ssid.SsidLength = ssid_len;
8390
8391                 if(0)
8392                 DBG_871X(FUNC_ADPT_FMT" after ssid:(%s,%d), (%s,%d)\n", FUNC_ADPT_ARG(adapter),
8393                         pbss_network->Ssid.Ssid, pbss_network->Ssid.SsidLength,
8394                         pbss_network_ext->Ssid.Ssid, pbss_network_ext->Ssid.SsidLength);
8395         }
8396
8397         DBG_871X(FUNC_ADPT_FMT" ignore_broadcast_ssid:%d, %s,%d\n", FUNC_ADPT_ARG(adapter),
8398                 ignore_broadcast_ssid, ssid, ssid_len);
8399
8400         return ret;
8401 }
8402
8403 static int rtw_ioctl_acl_remove_sta(struct net_device *dev, struct ieee_param *param, int len)
8404 {
8405         int ret=0;
8406         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
8407         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);    
8408
8409         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
8410                 return -EINVAL;
8411
8412         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
8413             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
8414             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
8415         {
8416                 return -EINVAL; 
8417         }
8418
8419         ret = rtw_acl_remove_sta(padapter, param->sta_addr);    
8420
8421         return ret;             
8422
8423 }
8424
8425 static int rtw_ioctl_acl_add_sta(struct net_device *dev, struct ieee_param *param, int len)
8426 {
8427         int ret=0;
8428         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
8429         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8430         
8431         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
8432                 return -EINVAL;
8433
8434         if (param->sta_addr[0] == 0xff && param->sta_addr[1] == 0xff &&
8435             param->sta_addr[2] == 0xff && param->sta_addr[3] == 0xff &&
8436             param->sta_addr[4] == 0xff && param->sta_addr[5] == 0xff) 
8437         {
8438                 return -EINVAL; 
8439         }
8440
8441         ret = rtw_acl_add_sta(padapter, param->sta_addr);       
8442
8443         return ret;             
8444
8445 }
8446
8447 static int rtw_ioctl_set_macaddr_acl(struct net_device *dev, struct ieee_param *param, int len)
8448 {
8449         int ret=0;
8450         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);  
8451         struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8452         
8453         if(check_fwstate(pmlmepriv, WIFI_AP_STATE) != _TRUE)
8454                 return -EINVAL; 
8455         
8456         rtw_set_macaddr_acl(padapter, param->u.mlme.command);   
8457
8458         return ret;
8459 }
8460
8461 static int rtw_hostapd_ioctl(struct net_device *dev, struct iw_point *p)
8462 {
8463         struct ieee_param *param;
8464         int ret=0;
8465         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8466
8467         //DBG_871X("%s\n", __FUNCTION__);
8468
8469         /*
8470         * this function is expect to call in master mode, which allows no power saving
8471         * so, we just check hw_init_completed
8472         */
8473
8474         if (padapter->hw_init_completed==_FALSE){
8475                 ret = -EPERM;
8476                 goto out;
8477         }
8478
8479
8480         //if (p->length < sizeof(struct ieee_param) || !p->pointer){
8481         if(!p->pointer){
8482                 ret = -EINVAL;
8483                 goto out;
8484         }
8485         
8486         param = (struct ieee_param *)rtw_malloc(p->length);
8487         if (param == NULL)
8488         {
8489                 ret = -ENOMEM;
8490                 goto out;
8491         }
8492         
8493         if (copy_from_user(param, p->pointer, p->length))
8494         {
8495                 rtw_mfree((u8*)param, p->length);
8496                 ret = -EFAULT;
8497                 goto out;
8498         }
8499
8500         //DBG_871X("%s, cmd=%d\n", __FUNCTION__, param->cmd);
8501
8502         switch (param->cmd) 
8503         {       
8504                 case RTL871X_HOSTAPD_FLUSH:
8505
8506                         ret = rtw_hostapd_sta_flush(dev);
8507
8508                         break;
8509         
8510                 case RTL871X_HOSTAPD_ADD_STA:   
8511                         
8512                         ret = rtw_add_sta(dev, param);                                  
8513                         
8514                         break;
8515
8516                 case RTL871X_HOSTAPD_REMOVE_STA:
8517
8518                         ret = rtw_del_sta(dev, param);
8519
8520                         break;
8521         
8522                 case RTL871X_HOSTAPD_SET_BEACON:
8523
8524                         ret = rtw_set_beacon(dev, param, p->length);
8525
8526                         break;
8527                         
8528                 case RTL871X_SET_ENCRYPTION:
8529
8530                         ret = rtw_set_encryption(dev, param, p->length);
8531                         
8532                         break;
8533                         
8534                 case RTL871X_HOSTAPD_GET_WPAIE_STA:
8535
8536                         ret = rtw_get_sta_wpaie(dev, param);
8537         
8538                         break;
8539                         
8540                 case RTL871X_HOSTAPD_SET_WPS_BEACON:
8541
8542                         ret = rtw_set_wps_beacon(dev, param, p->length);
8543
8544                         break;
8545
8546                 case RTL871X_HOSTAPD_SET_WPS_PROBE_RESP:
8547
8548                         ret = rtw_set_wps_probe_resp(dev, param, p->length);
8549                         
8550                         break;
8551                         
8552                 case RTL871X_HOSTAPD_SET_WPS_ASSOC_RESP:
8553
8554                         ret = rtw_set_wps_assoc_resp(dev, param, p->length);
8555                         
8556                         break;
8557
8558                 case RTL871X_HOSTAPD_SET_HIDDEN_SSID:
8559
8560                         ret = rtw_set_hidden_ssid(dev, param, p->length);
8561
8562                         break;
8563
8564                 case RTL871X_HOSTAPD_GET_INFO_STA:
8565
8566                         ret = rtw_ioctl_get_sta_data(dev, param, p->length);
8567
8568                         break;
8569                         
8570                 case RTL871X_HOSTAPD_SET_MACADDR_ACL:
8571
8572                         ret = rtw_ioctl_set_macaddr_acl(dev, param, p->length);
8573
8574                         break;
8575
8576                 case RTL871X_HOSTAPD_ACL_ADD_STA:
8577
8578                         ret = rtw_ioctl_acl_add_sta(dev, param, p->length);
8579
8580                         break;
8581
8582                 case RTL871X_HOSTAPD_ACL_REMOVE_STA:
8583
8584                         ret = rtw_ioctl_acl_remove_sta(dev, param, p->length);
8585
8586                         break;
8587                         
8588                 default:
8589                         DBG_871X("Unknown hostapd request: %d\n", param->cmd);
8590                         ret = -EOPNOTSUPP;
8591                         break;
8592                 
8593         }
8594
8595         if (ret == 0 && copy_to_user(p->pointer, param, p->length))
8596                 ret = -EFAULT;
8597
8598
8599         rtw_mfree((u8 *)param, p->length);
8600         
8601 out:
8602                 
8603         return ret;
8604         
8605 }
8606 #endif
8607
8608 static int rtw_wx_set_priv(struct net_device *dev,
8609                                 struct iw_request_info *info,
8610                                 union iwreq_data *awrq,
8611                                 char *extra)
8612 {
8613
8614 #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
8615         char *ext_dbg;
8616 #endif
8617
8618         int ret = 0;
8619         int len = 0;
8620         char *ext;
8621         int i;
8622
8623         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8624         struct iw_point *dwrq = (struct iw_point*)awrq;
8625
8626         //RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_notice_, ("+rtw_wx_set_priv\n"));
8627         if(dwrq->length == 0)
8628                 return -EFAULT;
8629         
8630         len = dwrq->length;
8631         if (!(ext = rtw_vmalloc(len)))
8632                 return -ENOMEM;
8633
8634         if (copy_from_user(ext, dwrq->pointer, len)) {
8635                 rtw_vmfree(ext, len);
8636                 return -EFAULT;
8637         }
8638
8639
8640         //RT_TRACE(_module_rtl871x_ioctl_os_c, _drv_notice_,
8641         //       ("rtw_wx_set_priv: %s req=%s\n",
8642         //        dev->name, ext));
8643
8644         #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV     
8645         if (!(ext_dbg = rtw_vmalloc(len)))
8646         {
8647                 rtw_vmfree(ext, len);
8648                 return -ENOMEM;
8649         }       
8650         
8651         _rtw_memcpy(ext_dbg, ext, len);
8652         #endif
8653
8654         //added for wps2.0 @20110524
8655         if(dwrq->flags == 0x8766 && len > 8)
8656         {
8657                 u32 cp_sz;              
8658                 struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);
8659                 u8 *probereq_wpsie = ext;
8660                 int probereq_wpsie_len = len;
8661                 u8 wps_oui[4]={0x0,0x50,0xf2,0x04};             
8662         
8663                 if((_VENDOR_SPECIFIC_IE_ == probereq_wpsie[0]) &&
8664                         (_rtw_memcmp(&probereq_wpsie[2], wps_oui, 4) ==_TRUE))
8665                 {
8666                         cp_sz = probereq_wpsie_len>MAX_WPS_IE_LEN ? MAX_WPS_IE_LEN:probereq_wpsie_len;
8667
8668                         if(pmlmepriv->wps_probe_req_ie)
8669                         {
8670                                 u32 free_len = pmlmepriv->wps_probe_req_ie_len;
8671                                 pmlmepriv->wps_probe_req_ie_len = 0;
8672                                 rtw_mfree(pmlmepriv->wps_probe_req_ie, free_len);
8673                                 pmlmepriv->wps_probe_req_ie = NULL;                     
8674                         }       
8675
8676                         pmlmepriv->wps_probe_req_ie = rtw_malloc(cp_sz);
8677                         if ( pmlmepriv->wps_probe_req_ie == NULL) {
8678                                 printk("%s()-%d: rtw_malloc() ERROR!\n", __FUNCTION__, __LINE__);
8679                                 ret =  -EINVAL;
8680                                 goto FREE_EXT;
8681                         
8682                         }
8683                         
8684                         _rtw_memcpy(pmlmepriv->wps_probe_req_ie, probereq_wpsie, cp_sz);
8685                         pmlmepriv->wps_probe_req_ie_len = cp_sz;                                        
8686                         
8687                 }       
8688                 
8689                 goto FREE_EXT;
8690                 
8691         }
8692
8693         if(     len >= WEXT_CSCAN_HEADER_SIZE
8694                 && _rtw_memcmp(ext, WEXT_CSCAN_HEADER, WEXT_CSCAN_HEADER_SIZE) == _TRUE
8695         ){
8696                 ret = rtw_wx_set_scan(dev, info, awrq, ext);
8697                 goto FREE_EXT;
8698         }
8699         
8700 #ifdef CONFIG_ANDROID
8701         //DBG_871X("rtw_wx_set_priv: %s req=%s\n", dev->name, ext);
8702
8703         i = rtw_android_cmdstr_to_num(ext);
8704
8705         switch(i) {
8706                 case ANDROID_WIFI_CMD_START :
8707                         indicate_wx_custom_event(padapter, "START");
8708                         break;
8709                 case ANDROID_WIFI_CMD_STOP :
8710                         indicate_wx_custom_event(padapter, "STOP");
8711                         break;
8712                 case ANDROID_WIFI_CMD_RSSI :
8713                         {
8714                                 struct  mlme_priv       *pmlmepriv = &(padapter->mlmepriv);     
8715                                 struct  wlan_network    *pcur_network = &pmlmepriv->cur_network;
8716
8717                                 if(check_fwstate(pmlmepriv, _FW_LINKED) == _TRUE) {
8718                                         sprintf(ext, "%s rssi %d", pcur_network->network.Ssid.Ssid, padapter->recvpriv.rssi);
8719                                 } else {
8720                                         sprintf(ext, "OK");
8721                                 }
8722                         }
8723                         break;
8724                 case ANDROID_WIFI_CMD_LINKSPEED :
8725                         {
8726                                 u16 mbps = rtw_get_cur_max_rate(padapter)/10;
8727                                 sprintf(ext, "LINKSPEED %d", mbps);
8728                         }
8729                         break;
8730                 case ANDROID_WIFI_CMD_MACADDR :
8731                         sprintf(ext, "MACADDR = " MAC_FMT, MAC_ARG(dev->dev_addr));
8732                         break;
8733                 case ANDROID_WIFI_CMD_SCAN_ACTIVE :
8734                         {
8735                                 //rtw_set_scan_mode(padapter, SCAN_ACTIVE);
8736                                 sprintf(ext, "OK");
8737                         }
8738                         break;
8739                 case ANDROID_WIFI_CMD_SCAN_PASSIVE :
8740                         {
8741                                 //rtw_set_scan_mode(padapter, SCAN_PASSIVE);
8742                                 sprintf(ext, "OK");
8743                         }
8744                         break;
8745
8746                 case ANDROID_WIFI_CMD_COUNTRY :
8747                         {
8748                                 char country_code[10];
8749                                 sscanf(ext, "%*s %s", country_code);
8750                                 rtw_set_country(padapter, country_code);
8751                                 sprintf(ext, "OK");
8752                         }
8753                         break;
8754                 default :
8755                         #ifdef  CONFIG_DEBUG_RTW_WX_SET_PRIV
8756                         DBG_871X("%s: %s unknowned req=%s\n", __FUNCTION__,
8757                                 dev->name, ext_dbg);
8758                         #endif
8759
8760                         sprintf(ext, "OK");
8761                 
8762         }
8763
8764         if (copy_to_user(dwrq->pointer, ext, min(dwrq->length, (u16)(strlen(ext)+1)) ) )
8765                 ret = -EFAULT;
8766
8767         #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
8768         DBG_871X("%s: %s req=%s rep=%s dwrq->length=%d, strlen(ext)+1=%d\n", __FUNCTION__,
8769                 dev->name, ext_dbg ,ext, dwrq->length, (u16)(strlen(ext)+1));
8770         #endif
8771 #endif //end of CONFIG_ANDROID
8772
8773
8774 FREE_EXT:
8775
8776         rtw_vmfree(ext, len);
8777         #ifdef CONFIG_DEBUG_RTW_WX_SET_PRIV
8778         rtw_vmfree(ext_dbg, len);
8779         #endif
8780
8781         //DBG_871X("rtw_wx_set_priv: (SIOCSIWPRIV) %s ret=%d\n", 
8782         //              dev->name, ret);
8783
8784         return ret;
8785         
8786 }
8787
8788 #ifdef CONFIG_AP_WOWLAN
8789 static int rtw_ap_wowlan_ctrl(struct net_device *dev,
8790                                                 struct iw_request_info *info,
8791                                                 union iwreq_data *wrqu, char *extra)
8792 {
8793         _adapter *padapter =  (_adapter *)rtw_netdev_priv(dev);
8794         struct wowlan_ioctl_param poidparam;
8795         struct pwrctrl_priv *pwrctrlpriv = adapter_to_pwrctl(padapter);
8796         struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
8797         struct sta_info *psta = NULL;
8798         int ret = 0;
8799         u32 start_time = rtw_get_current_time();
8800         poidparam.subcode = 0;
8801
8802         DBG_871X("+rtw_ap_wowlan_ctrl: %s\n", extra);
8803
8804         if(pwrctrlpriv->bSupportRemoteWakeup==_FALSE){
8805                 ret = -EPERM;
8806                 DBG_871X("+rtw_wowlan_ctrl: Device didn't support the remote wakeup!!\n");
8807                 goto _rtw_ap_wowlan_ctrl_exit_free;
8808         }
8809
8810         if (!check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
8811                 DBG_871X("[%s] It is not AP mode!!\n", __func__);
8812                 goto _rtw_ap_wowlan_ctrl_exit_free;
8813         }
8814
8815         if (_rtw_memcmp( extra, "enable", 6 )) {
8816                 pwrctrlpriv->wowlan_ap_mode = _TRUE;
8817                 while (pwrctrlpriv->bips_processing == _TRUE)
8818                         rtw_msleep_os(1);
8819
8820                 rtw_cancel_all_timer(padapter);
8821
8822                 padapter->bDriverStopped = _TRUE;       //for stop thread
8823                 rtw_stop_drv_threads(padapter);
8824                 padapter->bDriverStopped = _FALSE;      //for 32k command
8825
8826 #ifdef CONFIG_LPS
8827                 LeaveAllPowerSaveModeDirect(padapter);
8828 #endif
8829                 rtw_hal_disable_interrupt(padapter); // It need wait for leaving 32K.
8830
8831                 // 2.1 clean interupt
8832                 if (padapter->HalFunc.clear_interrupt)
8833                         padapter->HalFunc.clear_interrupt(padapter);
8834
8835                 poidparam.subcode = WOWLAN_AP_ENABLE;
8836
8837                 rtw_hal_set_hwreg(padapter, HW_VAR_AP_WOWLAN,(u8 *)&poidparam);
8838         } else if (_rtw_memcmp( extra, "disable", 6 )) {
8839 #ifdef CONFIG_LPS
8840                 LeaveAllPowerSaveModeDirect(padapter);
8841 #endif //CONFIG_LPS
8842                 pwrctrlpriv->bFwCurrentInPSMode = _FALSE;
8843
8844                 rtw_hal_disable_interrupt(padapter);
8845
8846                 if (padapter->HalFunc.clear_interrupt)
8847                         padapter->HalFunc.clear_interrupt(padapter);
8848
8849                 poidparam.subcode = WOWLAN_AP_ENABLE;
8850
8851                 rtw_hal_set_hwreg(padapter, HW_VAR_AP_WOWLAN,(u8 *)&poidparam);
8852
8853                 pwrctrlpriv->wowlan_ap_mode = _FALSE;
8854
8855                 psta = rtw_get_stainfo(&padapter->stapriv, get_bssid(&padapter->mlmepriv));
8856                 if (psta) {
8857                         set_sta_rate(padapter, psta);
8858                 }
8859
8860                 padapter->bDriverStopped = _FALSE;
8861                 DBG_871X("%s: wowmode resuming, DriverStopped:%d\n", __func__, padapter->bDriverStopped);
8862                 rtw_start_drv_threads(padapter);
8863
8864                 rtw_hal_enable_interrupt(padapter);
8865
8866                 _set_timer(&padapter->mlmepriv.dynamic_chk_timer, 2000);
8867                 pwrctrlpriv->bips_processing = _FALSE;
8868                 rtw_set_pwr_state_check_timer(pwrctrlpriv);
8869
8870         } else {
8871                 DBG_871X("[%s] Invalid Parameter.\n", __func__);
8872                 goto _rtw_ap_wowlan_ctrl_exit_free;
8873         }
8874         //mutex_lock(&ioctl_mutex);
8875 _rtw_ap_wowlan_ctrl_exit_free:
8876         DBG_871X("-rtw_ap_wowlan_ctrl( subcode = %d)\n", poidparam.subcode);
8877         DBG_871X_LEVEL(_drv_always_, "%s in %d ms\n", __func__,
8878                         rtw_get_passing_time_ms(start_time));
8879 _rtw_ap_wowlan_ctrl_exit:
8880         return ret;
8881 }
8882 #endif //CONFIG_AP_WOWLAN
8883
8884 static int rtw_pm_set(struct net_device *dev,
8885                                struct iw_request_info *info,
8886                                union iwreq_data *wrqu, char *extra)
8887 {
8888         int ret = 0;
8889         unsigned        mode = 0;
8890         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
8891
8892         DBG_871X( "[%s] extra = %s\n", __FUNCTION__, extra );
8893
8894         if ( _rtw_memcmp( extra, "lps=", 4 ) )
8895         {
8896                 sscanf(extra+4, "%u", &mode);   
8897                 ret = rtw_pm_set_lps(padapter,mode);
8898         }
8899         else if ( _rtw_memcmp( extra, "ips=", 4 ) )
8900         {
8901                 sscanf(extra+4, "%u", &mode);
8902                 ret = rtw_pm_set_ips(padapter,mode);
8903         }
8904         else{
8905                 ret = -EINVAL;
8906         }
8907
8908         return ret;
8909 }
8910
8911 static int rtw_mp_efuse_get(struct net_device *dev,
8912                         struct iw_request_info *info,
8913                         union iwreq_data *wdata, char *extra)
8914 {
8915         PADAPTER padapter = rtw_netdev_priv(dev);
8916         EEPROM_EFUSE_PRIV *pEEPROM = GET_EEPROM_EFUSE_PRIV(padapter);
8917         PHAL_DATA_TYPE pHalData = GET_HAL_DATA(padapter);
8918         PEFUSE_HAL pEfuseHal;
8919         struct iw_point *wrqu;
8920         
8921         u8      *PROMContent = pEEPROM->efuse_eeprom_data;
8922         u8 ips_mode = IPS_NUM; // init invalid value
8923         u8 lps_mode = PS_MODE_NUM; // init invalid value
8924         struct pwrctrl_priv *pwrctrlpriv ;
8925         u8 *data = NULL;
8926         u8 *rawdata = NULL;
8927         char *pch, *ptmp, *token, *tmp[3]={0x00,0x00,0x00};
8928         u16 i=0, j=0, mapLen=0, addr=0, cnts=0;
8929         u16 max_available_size=0, raw_cursize=0, raw_maxsize=0;
8930         int err;
8931         #ifdef CONFIG_IOL
8932         u8 org_fw_iol = padapter->registrypriv.fw_iol;// 0:Disable, 1:enable, 2:by usb speed
8933         #endif
8934         
8935         wrqu = (struct iw_point*)wdata;
8936         pwrctrlpriv = adapter_to_pwrctl(padapter);
8937         pEfuseHal = &pHalData->EfuseHal;
8938
8939         err = 0;
8940         data = rtw_zmalloc(EFUSE_BT_MAX_MAP_LEN);
8941         if (data == NULL)
8942         {
8943                 err = -ENOMEM;
8944                 goto exit;
8945         }
8946         rawdata = rtw_zmalloc(EFUSE_BT_MAX_MAP_LEN);
8947         if (rawdata == NULL)
8948         {
8949                 err = -ENOMEM;
8950                 goto exit;
8951         }
8952
8953         if (copy_from_user(extra, wrqu->pointer, wrqu->length))
8954         {
8955                 err = -EFAULT;
8956                 goto exit;
8957         }
8958         #ifdef CONFIG_LPS
8959         lps_mode = pwrctrlpriv->power_mgnt;//keep org value
8960         rtw_pm_set_lps(padapter,PS_MODE_ACTIVE);
8961         #endif  
8962         
8963         #ifdef CONFIG_IPS       
8964         ips_mode = pwrctrlpriv->ips_mode;//keep org value
8965         rtw_pm_set_ips(padapter,IPS_NONE);
8966         #endif  
8967         
8968         pch = extra;
8969         DBG_871X("%s: in=%s\n", __FUNCTION__, extra);
8970
8971         i = 0;
8972         //mac 16 "00e04c871200" rmap,00,2
8973         while ((token = strsep(&pch, ",")) != NULL)
8974         {
8975                 if (i > 2) break;
8976                 tmp[i] = token;
8977                 i++;
8978         }
8979         #ifdef CONFIG_IOL
8980         padapter->registrypriv.fw_iol = 0;// 0:Disable, 1:enable, 2:by usb speed
8981         #endif
8982         
8983         if(strcmp(tmp[0], "status") == 0){
8984                 sprintf(extra, "Load File efuse=%s,Load File MAC=%s",(pEEPROM->bloadfile_fail_flag? "FAIL" : "OK"),(pEEPROM->bloadmac_fail_flag? "FAIL" : "OK"));
8985
8986                   goto exit;
8987         }
8988         else if (strcmp(tmp[0], "drvmap") == 0)
8989         {
8990                 mapLen = EFUSE_MAP_SIZE;
8991                 
8992                 sprintf(extra, "\n");
8993                 for (i = 0; i < EFUSE_MAP_SIZE; i += 16)
8994                 {
8995 //                      DBG_871X("0x%02x\t", i);
8996                         sprintf(extra, "%s0x%02x\t", extra, i);
8997                         for (j=0; j<8; j++) {
8998 //                              DBG_871X("%02X ", data[i+j]);
8999                                 sprintf(extra, "%s%02X ", extra, PROMContent[i+j]);
9000                         }
9001 //                      DBG_871X("\t");
9002                         sprintf(extra, "%s\t", extra);
9003                         for (; j<16; j++) {
9004 //                              DBG_871X("%02X ", data[i+j]);
9005                                 sprintf(extra, "%s%02X ", extra, PROMContent[i+j]);
9006                         }
9007 //                      DBG_871X("\n");
9008                         sprintf(extra,"%s\n",extra);
9009                 }
9010 //              DBG_871X("\n");
9011         }
9012         else if (strcmp(tmp[0], "realmap") == 0)
9013         {
9014                 mapLen = EFUSE_MAP_SIZE;
9015                 if (rtw_efuse_map_read(padapter, EFUSE_WIFI , mapLen, pEfuseHal->fakeEfuseInitMap) == _FAIL)
9016                 {
9017                         DBG_871X("%s: read realmap Fail!!\n", __FUNCTION__);
9018                         err = -EFAULT;
9019                         goto exit;
9020                 }
9021
9022 //              DBG_871X("OFFSET\tVALUE(hex)\n");
9023                 sprintf(extra, "\n");
9024                 for (i = 0; i < EFUSE_MAP_SIZE; i += 16)
9025                 {
9026 //                      DBG_871X("0x%02x\t", i);
9027                         sprintf(extra, "%s0x%02x\t", extra, i);
9028                         for (j=0; j<8; j++) {
9029 //                              DBG_871X("%02X ", data[i+j]);
9030                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeEfuseInitMap[i+j]);
9031                         }
9032 //                      DBG_871X("\t");
9033                         sprintf(extra, "%s\t", extra);
9034                         for (; j<16; j++) {
9035 //                              DBG_871X("%02X ", data[i+j]);
9036                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeEfuseInitMap[i+j]);
9037                         }
9038 //                      DBG_871X("\n");
9039                         sprintf(extra,"%s\n",extra);
9040                 }
9041 //              DBG_871X("\n");
9042         }
9043         else if (strcmp(tmp[0], "rmap") == 0)
9044         {
9045                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
9046                 {
9047                         DBG_871X("%s: rmap Fail!! Parameters error!\n", __FUNCTION__);
9048                         err = -EINVAL;
9049                         goto exit;
9050                 }
9051
9052                 // rmap addr cnts
9053                 addr = simple_strtoul(tmp[1], &ptmp, 16);
9054                 DBG_871X("%s: addr=%x\n", __FUNCTION__, addr);
9055
9056                 cnts = simple_strtoul(tmp[2], &ptmp, 10);
9057                 if (cnts == 0)
9058                 {
9059                         DBG_871X("%s: rmap Fail!! cnts error!\n", __FUNCTION__);
9060                         err = -EINVAL;
9061                         goto exit;
9062                 }
9063                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
9064
9065                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_EFUSE_MAP_LEN , (PVOID)&max_available_size, _FALSE);
9066                 if ((addr+ cnts) > max_available_size)
9067                 {
9068                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
9069                         err = -EINVAL;
9070                         goto exit;
9071                 }
9072
9073                 if (rtw_efuse_map_read(padapter, addr, cnts, data) == _FAIL)
9074                 {
9075                         DBG_871X("%s: rtw_efuse_map_read error!\n", __FUNCTION__);
9076                         err = -EFAULT;
9077                         goto exit;
9078                 }
9079
9080 //              DBG_871X("%s: data={", __FUNCTION__);
9081                 *extra = 0;
9082                 for (i=0; i<cnts; i++) {
9083 //                      DBG_871X("0x%02x ", data[i]);
9084                         sprintf(extra, "%s0x%02X ", extra, data[i]);
9085                 }
9086 //              DBG_871X("}\n");
9087         }
9088         else if (strcmp(tmp[0], "realraw") == 0)
9089         {
9090                 addr = 0;
9091                 mapLen = EFUSE_MAX_SIZE;
9092                 if (rtw_efuse_access(padapter, _FALSE, addr, mapLen, rawdata) == _FAIL)
9093                 {
9094                         DBG_871X("%s: rtw_efuse_access Fail!!\n", __FUNCTION__);
9095                         err = -EFAULT;
9096                         goto exit;
9097                 }
9098                 _rtw_memset(extra,'\0',strlen(extra));
9099                 //              DBG_871X("%s: realraw={\n", __FUNCTION__);
9100                                 sprintf(extra, "\n0x00\t");
9101                                 for (i=0; i< mapLen; i++)
9102                                 {
9103                 //                      DBG_871X("%02X", rawdata[i]);
9104                                         sprintf(extra, "%s%02X", extra, rawdata[i]);
9105                                         if ((i & 0xF) == 0xF) {
9106                 //                              DBG_871X("\n");
9107                                                 sprintf(extra, "%s\n", extra);
9108                                                 sprintf(extra, "%s0x%02x\t", extra, i+1);
9109                                         }
9110                                         else if ((i & 0x7) == 0x7){
9111                 //                              DBG_871X("\t");
9112                                                 sprintf(extra, "%s \t", extra);
9113                                         } else {
9114                 //                              DBG_871X(" ");
9115                                                 sprintf(extra, "%s ", extra);
9116                                         }
9117                                 }
9118                 //              DBG_871X("}\n");
9119         }
9120         else if (strcmp(tmp[0], "mac") == 0)
9121         {
9122                 #ifdef CONFIG_RTL8192C
9123                 addr = EEPROM_MAC_ADDR_92C;
9124                 #endif // CONFIG_RTL8192C
9125                 #ifdef CONFIG_RTL8192D
9126                         #ifdef CONFIG_USB_HCI
9127                         if (pHalData->interfaceIndex == 0)
9128                                 addr = EEPROM_MAC_ADDR_MAC0_92DU;
9129                         else
9130                                 addr = EEPROM_MAC_ADDR_MAC1_92DU;
9131                         #else
9132                         if (pHalData->interfaceIndex == 0)
9133                                 addr = EEPROM_MAC_ADDR_MAC0_92DE;
9134                         else
9135                                 addr = EEPROM_MAC_ADDR_MAC1_92DE;
9136                         #endif
9137                 #endif // CONFIG_RTL8192D
9138                 #ifdef CONFIG_RTL8723A
9139                         #ifdef CONFIG_SDIO_HCI
9140                         addr = EEPROM_MAC_ADDR_8723AS;
9141                         #endif
9142                         #ifdef CONFIG_GSPI_HCI
9143                         addr = EEPROM_MAC_ADDR_8723AS;
9144                         #endif
9145                         #ifdef CONFIG_USB_HCI
9146                         addr = EEPROM_MAC_ADDR_8723AU;
9147                         #endif
9148                 #endif // CONFIG_RTL8723A
9149                 #ifdef CONFIG_RTL8188E
9150                         #ifdef CONFIG_USB_HCI
9151                         addr = EEPROM_MAC_ADDR_88EU;
9152                         #endif
9153                         #ifdef CONFIG_SDIO_HCI
9154                         addr = EEPROM_MAC_ADDR_88ES;
9155                         #endif
9156                         #ifdef CONFIG_PCI_HCI
9157                         addr = EEPROM_MAC_ADDR_88EE;
9158                         #endif
9159                 #endif // CONFIG_RTL8188E
9160
9161                 #ifdef CONFIG_RTL8192E
9162                         #ifdef CONFIG_USB_HCI
9163                         addr = EEPROM_MAC_ADDR_8192EU;
9164                         #endif
9165                         #ifdef CONFIG_SDIO_HCI
9166                         addr = EEPROM_MAC_ADDR_8192ES;
9167                         #endif
9168                         #ifdef CONFIG_PCI_HCI
9169                         addr = EEPROM_MAC_ADDR_8192EE;
9170                         #endif
9171                 #endif
9172                 #ifdef CONFIG_RTL8723B
9173                 #ifdef CONFIG_SDIO_HCI
9174                 addr = EEPROM_MAC_ADDR_8723BS;
9175                 #endif
9176                 #ifdef CONFIG_GSPI_HCI
9177                 addr = EEPROM_MAC_ADDR_8723BS;
9178                 #endif
9179                 #ifdef CONFIG_USB_HCI
9180                 addr = EEPROM_MAC_ADDR_8723BU;
9181                 #endif
9182                 #endif // CONFIG_RTL8723B
9183                 cnts = 6;
9184
9185                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
9186                 if ((addr + cnts) > max_available_size) {
9187                         DBG_871X("%s: addr(0x%02x)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
9188                         err = -EFAULT;
9189                         goto exit;
9190                 }
9191
9192                 if (rtw_efuse_map_read(padapter, addr, cnts, data) == _FAIL)
9193                 {
9194                         DBG_871X("%s: rtw_efuse_map_read error!\n", __FUNCTION__);
9195                         err = -EFAULT;
9196                         goto exit;
9197                 }
9198
9199 //              DBG_871X("%s: MAC address={", __FUNCTION__);
9200                 *extra = 0;
9201                 for (i=0; i<cnts; i++)
9202                 {
9203 //                      DBG_871X("%02X", data[i]);
9204                         sprintf(extra, "%s%02X", extra, data[i]);
9205                         if (i != (cnts-1))
9206                         {
9207 //                              DBG_871X(":");
9208                                 sprintf(extra,"%s:",extra);
9209                         }
9210                 }
9211 //              DBG_871X("}\n");
9212         }
9213         else if (strcmp(tmp[0], "vidpid") == 0)
9214         {
9215                 #ifdef CONFIG_RTL8192C
9216                 addr = EEPROM_VID_92C;
9217                 #endif // CONFIG_RTL8192C
9218                 #ifdef CONFIG_RTL8192D
9219                         #ifdef CONFIG_USB_HCI
9220                         addr = EEPROM_VID_92DU;
9221                         #else
9222                         addr = EEPROM_VID_92DE;
9223                         #endif
9224                 #endif // CONFIG_RTL8192D
9225                 #ifdef CONFIG_RTL8723A
9226                         #ifdef CONFIG_USB_HCI
9227                         addr = EEPROM_VID_8723AU;
9228                         #endif
9229                 #endif // CONFIG_RTL8723A
9230                 #ifdef CONFIG_RTL8188E
9231                         #ifdef CONFIG_USB_HCI
9232                         addr = EEPROM_VID_88EU;
9233                         #endif
9234                         #ifdef CONFIG_PCI_HCI
9235                         addr = EEPROM_VID_88EE;
9236                         #endif
9237                 #endif // CONFIG_RTL8188E
9238
9239                 #ifdef CONFIG_RTL8192E
9240                         #ifdef CONFIG_USB_HCI
9241                         addr = EEPROM_VID_8192EU;
9242                         #endif
9243                         #ifdef CONFIG_PCI_HCI
9244                         addr = EEPROM_VID_8192EE;
9245                         #endif
9246                 #endif // CONFIG_RTL8192E
9247                 #ifdef CONFIG_RTL8723B
9248                 addr = EEPROM_VID_8723BU;
9249                 #endif // CONFIG_RTL8192E
9250                 cnts = 4;
9251
9252                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
9253                 if ((addr + cnts) > max_available_size)
9254                 {
9255                         DBG_871X("%s: addr(0x%02x)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
9256                         err = -EFAULT;
9257                         goto exit;
9258                 }
9259                 if (rtw_efuse_map_read(padapter, addr, cnts, data) == _FAIL)
9260                 {
9261                         DBG_871X("%s: rtw_efuse_access error!!\n", __FUNCTION__);
9262                         err = -EFAULT;
9263                         goto exit;
9264                 }
9265
9266 //              DBG_871X("%s: {VID,PID}={", __FUNCTION__);
9267                 *extra = 0;
9268                 for (i=0; i<cnts; i++)
9269                 {
9270 //                      DBG_871X("0x%02x", data[i]);
9271                         sprintf(extra, "%s0x%02X", extra, data[i]);
9272                         if (i != (cnts-1))
9273                         {
9274 //                              DBG_871X(",");
9275                                 sprintf(extra,"%s,",extra);
9276                         }
9277                 }
9278 //              DBG_871X("}\n");
9279         }
9280         else if (strcmp(tmp[0], "ableraw") == 0)
9281         {
9282                 efuse_GetCurrentSize(padapter,&raw_cursize);
9283                 raw_maxsize = efuse_GetMaxSize(padapter);
9284                 sprintf(extra, "[available raw size]= %d bytes", raw_maxsize-raw_cursize);
9285         }
9286         else if (strcmp(tmp[0], "btfmap") == 0)
9287         {
9288                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
9289                                 
9290                 mapLen = EFUSE_BT_MAX_MAP_LEN;
9291                 if (rtw_BT_efuse_map_read(padapter, 0, mapLen, pEfuseHal->BTEfuseInitMap) == _FAIL)
9292                 {
9293                         DBG_871X("%s: rtw_BT_efuse_map_read Fail!!\n", __FUNCTION__);
9294                         err = -EFAULT;
9295                         goto exit;
9296                 }
9297
9298 //              DBG_871X("OFFSET\tVALUE(hex)\n");
9299                 sprintf(extra, "\n");
9300                 for (i=0; i<512; i+=16) // set 512 because the iwpriv's extra size have limit 0x7FF
9301                 {
9302 //                      DBG_871X("0x%03x\t", i);
9303                         sprintf(extra, "%s0x%03x\t", extra, i);
9304                         for (j=0; j<8; j++) {
9305 //                              DBG_871X("%02X ", pEfuseHal->BTEfuseInitMap[i+j]);
9306                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->BTEfuseInitMap[i+j]);
9307                         }
9308 //                      DBG_871X("\t");
9309                         sprintf(extra,"%s\t",extra);
9310                         for (; j<16; j++) {
9311 //                              DBG_871X("%02X ", pEfuseHal->BTEfuseInitMap[i+j]);
9312                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->BTEfuseInitMap[i+j]);
9313                         }
9314 //                      DBG_871X("\n");
9315                         sprintf(extra, "%s\n", extra);
9316                 }
9317 //              DBG_871X("\n");
9318         }
9319         else if (strcmp(tmp[0],"btbmap") == 0)
9320         {
9321                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
9322                 
9323                 mapLen = EFUSE_BT_MAX_MAP_LEN;
9324                 if (rtw_BT_efuse_map_read(padapter, 0, mapLen, pEfuseHal->BTEfuseInitMap) == _FAIL)
9325                 {
9326                         DBG_871X("%s: rtw_BT_efuse_map_read Fail!!\n", __FUNCTION__);
9327                         err = -EFAULT;
9328                         goto exit;
9329                 }
9330
9331 //              DBG_871X("OFFSET\tVALUE(hex)\n");
9332                 sprintf(extra, "\n");
9333                 for (i=512; i<1024 ; i+=16)
9334                 {
9335 //                      DBG_871X("0x%03x\t", i);
9336                         sprintf(extra, "%s0x%03x\t", extra, i);
9337                         for (j=0; j<8; j++)
9338                         {
9339 //                              DBG_871X("%02X ", data[i+j]);
9340                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->BTEfuseInitMap[i+j]);
9341                         }
9342 //                      DBG_871X("\t");
9343                         sprintf(extra,"%s\t",extra);
9344                         for (; j<16; j++) {
9345 //                              DBG_871X("%02X ", data[i+j]);
9346                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->BTEfuseInitMap[i+j]);
9347                         }
9348 //                      DBG_871X("\n");
9349                         sprintf(extra, "%s\n", extra);
9350                 }
9351 //              DBG_871X("\n");
9352         }
9353         else if (strcmp(tmp[0],"btrmap") == 0)
9354         {
9355                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
9356                 {
9357                         err = -EINVAL;
9358                         goto exit;
9359                 }
9360
9361                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
9362                 
9363                 // rmap addr cnts
9364                 addr = simple_strtoul(tmp[1], &ptmp, 16);
9365                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
9366
9367                 cnts = simple_strtoul(tmp[2], &ptmp, 10);
9368                 if (cnts == 0)
9369                 {
9370                         DBG_871X("%s: btrmap Fail!! cnts error!\n", __FUNCTION__);
9371                         err = -EINVAL;
9372                         goto exit;
9373                 }
9374                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
9375
9376                 EFUSE_GetEfuseDefinition(padapter, EFUSE_BT, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
9377                 if ((addr + cnts) > max_available_size)
9378                 {
9379                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
9380                         err = -EFAULT;
9381                         goto exit;
9382                 }
9383
9384                 if (rtw_BT_efuse_map_read(padapter, addr, cnts, data) == _FAIL) 
9385                 {
9386                         DBG_871X("%s: rtw_BT_efuse_map_read error!!\n", __FUNCTION__);
9387                         err = -EFAULT;
9388                         goto exit;
9389                 }
9390
9391                 *extra = 0;
9392 //              DBG_871X("%s: bt efuse data={", __FUNCTION__);
9393                 for (i=0; i<cnts; i++)
9394                 {
9395 //                      DBG_871X("0x%02x ", data[i]);
9396                         sprintf(extra, "%s 0x%02X ", extra, data[i]);
9397                 }
9398 //              DBG_871X("}\n");
9399                 DBG_871X(FUNC_ADPT_FMT ": BT MAC=[%s]\n", FUNC_ADPT_ARG(padapter), extra);
9400         }
9401         else if (strcmp(tmp[0], "btffake") == 0)
9402         {
9403 //              DBG_871X("OFFSET\tVALUE(hex)\n");
9404                 sprintf(extra, "\n");
9405                 for (i=0; i<512; i+=16)
9406                 {
9407 //                      DBG_871X("0x%03x\t", i);
9408                         sprintf(extra, "%s0x%03x\t", extra, i);
9409                         for (j=0; j<8; j++) {
9410 //                              DBG_871X("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
9411                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
9412                         }
9413 //                      DBG_871X("\t");
9414                         sprintf(extra, "%s\t", extra);
9415                         for (; j<16; j++) {
9416 //                              DBG_871X("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
9417                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
9418                         }
9419 //                      DBG_871X("\n");
9420                         sprintf(extra, "%s\n", extra);
9421                 }
9422 //              DBG_871X("\n");
9423         }
9424         else if (strcmp(tmp[0],"btbfake") == 0)
9425         {
9426 //              DBG_871X("OFFSET\tVALUE(hex)\n");
9427                 sprintf(extra, "\n");
9428                 for (i=512; i<1024; i+=16)
9429                 {
9430 //                      DBG_871X("0x%03x\t", i);
9431                         sprintf(extra, "%s0x%03x\t", extra, i);
9432                         for (j=0; j<8; j++) {
9433 //                              DBG_871X("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
9434                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
9435                         }
9436 //                      DBG_871X("\t");
9437                         sprintf(extra, "%s\t", extra);
9438                         for (; j<16; j++) {
9439 //                              DBG_871X("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
9440                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
9441                         }
9442 //                      DBG_871X("\n");
9443                         sprintf(extra, "%s\n", extra);
9444                 }
9445 //              DBG_871X("\n");
9446         }
9447         else if (strcmp(tmp[0],"wlrfkmap")== 0)
9448         {
9449 //              DBG_871X("OFFSET\tVALUE(hex)\n");
9450                 sprintf(extra, "\n");
9451                 for (i=0; i<EFUSE_MAP_SIZE; i+=16)
9452                 {
9453 //                      DBG_871X("\t0x%02x\t", i);
9454                         sprintf(extra, "%s0x%02x\t", extra, i);
9455                         for (j=0; j<8; j++) {
9456 //                              DBG_871X("%02X ", pEfuseHal->fakeEfuseModifiedMap[i+j]);
9457                                 sprintf(extra, "%s%02X ", extra, pEfuseHal->fakeEfuseModifiedMap[i+j]);
9458                         }
9459 //                      DBG_871X("\t");
9460                         sprintf(extra, "%s\t", extra);
9461                         for (; j<16; j++) {
9462 //                              DBG_871X("%02X ", pEfuseHal->fakeEfuseModifiedMap[i+j]);
9463                                 sprintf(extra, "%s %02X", extra, pEfuseHal->fakeEfuseModifiedMap[i+j]);
9464                         }
9465 //                      DBG_871X("\n");
9466                         sprintf(extra, "%s\n", extra);
9467                 }
9468 //              DBG_871X("\n");
9469
9470         }
9471         else if (strcmp(tmp[0],"wlrfkrmap")== 0)
9472         {
9473                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
9474                                 {
9475                                         DBG_871X("%s: rmap Fail!! Parameters error!\n", __FUNCTION__);
9476                                         err = -EINVAL;
9477                                         goto exit;
9478                                 }
9479                                 // rmap addr cnts
9480                                 addr = simple_strtoul(tmp[1], &ptmp, 16);
9481                                 DBG_871X("%s: addr=%x\n", __FUNCTION__, addr);
9482                 
9483                                 cnts = simple_strtoul(tmp[2], &ptmp, 10);
9484                                 if (cnts == 0)
9485                                 {
9486                                         DBG_871X("%s: rmap Fail!! cnts error!\n", __FUNCTION__);
9487                                         err = -EINVAL;
9488                                         goto exit;
9489                                 }
9490                                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
9491                 
9492                 //              DBG_871X("%s: data={", __FUNCTION__);
9493                         *extra = 0;
9494                         for (i=0; i<cnts; i++) {
9495                                         DBG_871X("wlrfkrmap = 0x%02x \n", pEfuseHal->fakeEfuseModifiedMap[addr+i]);
9496                                         sprintf(extra, "%s0x%02X ", extra, pEfuseHal->fakeEfuseModifiedMap[addr+i]);
9497                         }
9498         }
9499         else if (strcmp(tmp[0],"btrfkrmap")== 0)
9500         {
9501                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
9502                                 {
9503                                         DBG_871X("%s: rmap Fail!! Parameters error!\n", __FUNCTION__);
9504                                         err = -EINVAL;
9505                                         goto exit;
9506                                 }
9507                                 // rmap addr cnts
9508                                 addr = simple_strtoul(tmp[1], &ptmp, 16);
9509                                 DBG_871X("%s: addr=%x\n", __FUNCTION__, addr);
9510                 
9511                                 cnts = simple_strtoul(tmp[2], &ptmp, 10);
9512                                 if (cnts == 0)
9513                                 {
9514                                         DBG_871X("%s: rmap Fail!! cnts error!\n", __FUNCTION__);
9515                                         err = -EINVAL;
9516                                         goto exit;
9517                                 }
9518                                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
9519                 
9520                 //              DBG_871X("%s: data={", __FUNCTION__);
9521                         *extra = 0;
9522                         for (i=0; i<cnts; i++) {
9523                                         DBG_871X("wlrfkrmap = 0x%02x \n", pEfuseHal->fakeBTEfuseModifiedMap[addr+i]);
9524                                         sprintf(extra, "%s0x%02X ", extra, pEfuseHal->fakeBTEfuseModifiedMap[addr+i]);
9525                         }
9526         }
9527         else
9528         {
9529                  sprintf(extra, "Command not found!");
9530         }
9531
9532 exit:
9533         if (data)
9534                 rtw_mfree(data, EFUSE_BT_MAX_MAP_LEN);
9535         if (rawdata)
9536                 rtw_mfree(rawdata, EFUSE_BT_MAX_MAP_LEN);
9537         if (!err)
9538                 wrqu->length = strlen(extra);
9539         
9540         if (padapter->registrypriv.mp_mode == 0)
9541         {
9542         #ifdef CONFIG_IPS               
9543         rtw_pm_set_ips(padapter, ips_mode);
9544 #endif // CONFIG_IPS
9545
9546         #ifdef CONFIG_LPS       
9547         rtw_pm_set_lps(padapter, lps_mode);
9548 #endif // CONFIG_LPS
9549         }
9550
9551         #ifdef CONFIG_IOL
9552         padapter->registrypriv.fw_iol = org_fw_iol;// 0:Disable, 1:enable, 2:by usb speed
9553         #endif
9554         return err;
9555 }
9556
9557 static int rtw_mp_efuse_set(struct net_device *dev,
9558                         struct iw_request_info *info,
9559                         union iwreq_data *wdata, char *extra)
9560 {
9561         struct iw_point *wrqu;
9562         PADAPTER padapter;
9563         struct pwrctrl_priv *pwrctrlpriv ;
9564         PHAL_DATA_TYPE pHalData;
9565         PEFUSE_HAL pEfuseHal;
9566
9567         u8 ips_mode = IPS_NUM; // init invalid value
9568         u8 lps_mode = PS_MODE_NUM; // init invalid value
9569         u32 i=0,j=0, jj, kk;
9570         u8 *setdata = NULL;
9571         u8 *ShadowMapBT = NULL;
9572         u8 *ShadowMapWiFi = NULL;
9573         u8 *setrawdata = NULL;
9574         char *pch, *ptmp, *token, *tmp[3]={0x00,0x00,0x00};
9575         u16 addr=0, cnts=0, BTStatus=0 , max_available_size=0;
9576         int err;
9577
9578         wrqu = (struct iw_point*)wdata;
9579         padapter = rtw_netdev_priv(dev);
9580         pwrctrlpriv = adapter_to_pwrctl(padapter);
9581         pHalData = GET_HAL_DATA(padapter);
9582         pEfuseHal = &pHalData->EfuseHal;
9583         err = 0;
9584         
9585         if (copy_from_user(extra, wrqu->pointer, wrqu->length))
9586                         return -EFAULT;
9587                         
9588         setdata = rtw_zmalloc(1024);
9589         if (setdata == NULL)
9590         {
9591                 err = -ENOMEM;
9592                 goto exit;
9593         }
9594         ShadowMapBT = rtw_malloc(EFUSE_BT_MAX_MAP_LEN);
9595         if (ShadowMapBT == NULL)
9596         {
9597                 err = -ENOMEM;
9598                 goto exit;
9599         }
9600         ShadowMapWiFi = rtw_malloc(EFUSE_MAP_SIZE);
9601         if (ShadowMapWiFi == NULL)
9602         {
9603                 err = -ENOMEM;
9604                 goto exit;
9605         }
9606         setrawdata = rtw_malloc(EFUSE_MAX_SIZE);
9607         if (setrawdata == NULL)
9608         {
9609                 err = -ENOMEM;
9610                 goto exit;
9611         }
9612
9613         #ifdef CONFIG_LPS
9614         lps_mode = pwrctrlpriv->power_mgnt;//keep org value
9615         rtw_pm_set_lps(padapter,PS_MODE_ACTIVE);
9616         #endif  
9617         
9618         #ifdef CONFIG_IPS       
9619         ips_mode = pwrctrlpriv->ips_mode;//keep org value
9620         rtw_pm_set_ips(padapter,IPS_NONE);
9621         #endif  
9622                         
9623         pch = extra;
9624         DBG_871X("%s: in=%s\n", __FUNCTION__, extra);
9625         
9626         i = 0;
9627         while ((token = strsep(&pch, ",")) != NULL)
9628         {
9629                 if (i > 2) break;
9630                 tmp[i] = token;
9631                 i++;
9632         }
9633
9634         // tmp[0],[1],[2]
9635         // wmap,addr,00e04c871200
9636         if (strcmp(tmp[0], "wmap") == 0)
9637         {
9638                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
9639                 {
9640                         err = -EINVAL;
9641                         goto exit;
9642                 }
9643
9644 #if 1
9645                 // unknown bug workaround, need to fix later
9646                 addr=0x1ff;
9647                 rtw_write8(padapter, EFUSE_CTRL+1, (addr & 0xff));
9648                 rtw_msleep_os(10);
9649                 rtw_write8(padapter, EFUSE_CTRL+2, ((addr >> 8) & 0x03));
9650                 rtw_msleep_os(10);
9651                 rtw_write8(padapter, EFUSE_CTRL+3, 0x72);
9652                 rtw_msleep_os(10);
9653                 rtw_read8(padapter, EFUSE_CTRL);
9654 #endif
9655
9656                 addr = simple_strtoul(tmp[1], &ptmp, 16);
9657                 addr &= 0xFFF;
9658
9659                 cnts = strlen(tmp[2]);
9660                 if (cnts%2)
9661                 {
9662                         err = -EINVAL;
9663                         goto exit;
9664                 }
9665                 cnts /= 2;
9666                 if (cnts == 0)
9667                 {
9668                         err = -EINVAL;
9669                         goto exit;
9670                 }
9671
9672                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
9673                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
9674                 DBG_871X("%s: map data=%s\n", __FUNCTION__, tmp[2]);
9675                                 
9676                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
9677                 {
9678                         setdata[jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
9679                 }
9680 #ifndef CONFIG_RTL8188E
9681                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
9682 #else
9683                 //Change to check TYPE_EFUSE_MAP_LEN ,beacuse 8188E raw 256,logic map over 256.
9684                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_EFUSE_MAP_LEN, (PVOID)&max_available_size, _FALSE);
9685 #endif
9686                 if ((addr+cnts) > max_available_size)
9687                 {
9688                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
9689                         err = -EFAULT;
9690                         goto exit;
9691                 }
9692
9693                 if (rtw_efuse_map_write(padapter, addr, cnts, setdata) == _FAIL)
9694                 {
9695                         DBG_871X("%s: rtw_efuse_map_write error!!\n", __FUNCTION__);
9696                         err = -EFAULT;
9697                         goto exit;
9698                 }
9699                 *extra = 0;
9700                 DBG_871X("%s: after rtw_BT_efuse_map_write to _rtw_memcmp \n", __FUNCTION__);
9701                 if ( (rtw_efuse_map_read(padapter, addr, cnts, ShadowMapWiFi) == _SUCCESS ) )
9702                 {
9703                         if (_rtw_memcmp((void*)ShadowMapWiFi ,(void*)setdata,cnts))
9704                         { 
9705                                 DBG_871X("%s: WiFi write map afterf compare success\n", __FUNCTION__);
9706                                 sprintf(extra, "WiFi write map compare OK\n");
9707                                 err = 0;
9708                                 goto exit;
9709                         }
9710                         else
9711                         {
9712                                 sprintf(extra, "WiFi write map compare FAIL\n");
9713                                 DBG_871X("%s: WiFi write map compare Fail\n", __FUNCTION__);
9714                                 err = 0;
9715                                 goto exit;
9716                         }
9717                 }
9718         }
9719         else if (strcmp(tmp[0], "wraw") == 0)
9720         {
9721                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
9722                 {
9723                         err = -EINVAL;
9724                         goto exit;
9725                 }
9726
9727                 addr = simple_strtoul( tmp[1], &ptmp, 16 );
9728                 addr &= 0xFFF;
9729
9730                 cnts = strlen(tmp[2]);
9731                 if (cnts%2)
9732                 {
9733                         err = -EINVAL;
9734                         goto exit;
9735                 }
9736                 cnts /= 2;
9737                 if (cnts == 0)
9738                 {
9739                         err = -EINVAL;
9740                         goto exit;
9741                 }
9742
9743                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
9744                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
9745                 DBG_871X("%s: raw data=%s\n", __FUNCTION__, tmp[2]);
9746
9747                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
9748                 {
9749                         setrawdata[jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
9750                 }
9751
9752                 if (rtw_efuse_access(padapter, _TRUE, addr, cnts, setrawdata) == _FAIL)
9753                 {
9754                         DBG_871X("%s: rtw_efuse_access error!!\n", __FUNCTION__);
9755                         err = -EFAULT;
9756                         goto exit;
9757                 }
9758         }
9759         else if (strcmp(tmp[0], "mac") == 0)
9760         {
9761                 if (tmp[1]==NULL)
9762                 {
9763                         err = -EINVAL;
9764                         goto exit;
9765                 }
9766
9767                 //mac,00e04c871200
9768                 #ifdef CONFIG_RTL8192C
9769                 addr = EEPROM_MAC_ADDR_92C;
9770                 #endif
9771                 #ifdef CONFIG_RTL8192D
9772                         #ifdef CONFIG_USB_HCI
9773                         if (pHalData->interfaceIndex == 0)
9774                                 addr = EEPROM_MAC_ADDR_MAC0_92DU;
9775                         else
9776                                 addr = EEPROM_MAC_ADDR_MAC1_92DU;
9777                         #else
9778                         if (pHalData->interfaceIndex == 0)
9779                                 addr = EEPROM_MAC_ADDR_MAC0_92DE;
9780                         else
9781                                 addr = EEPROM_MAC_ADDR_MAC1_92DE;
9782                         #endif
9783                 #endif
9784                 #ifdef CONFIG_RTL8723A
9785                 #ifdef CONFIG_SDIO_HCI
9786                 addr = EEPROM_MAC_ADDR_8723AS;
9787                 #endif
9788                 #ifdef CONFIG_GSPI_HCI
9789                 addr = EEPROM_MAC_ADDR_8723AS;
9790                 #endif
9791                 #ifdef CONFIG_USB_HCI
9792                 addr = EEPROM_MAC_ADDR_8723AU;
9793                 #endif
9794                 #endif // CONFIG_RTL8723A
9795                 #ifdef CONFIG_RTL8188E
9796                         #ifdef CONFIG_USB_HCI
9797                         addr = EEPROM_MAC_ADDR_88EU;
9798                         #endif
9799                         #ifdef CONFIG_SDIO_HCI
9800                         addr = EEPROM_MAC_ADDR_88ES;
9801                         #endif
9802                         #ifdef CONFIG_PCI_HCI
9803                         addr = EEPROM_MAC_ADDR_88EE;
9804                         #endif
9805                 #endif //#ifdef CONFIG_RTL8188E
9806
9807                 #ifdef CONFIG_RTL8192E
9808                         #ifdef CONFIG_USB_HCI
9809                         addr = EEPROM_MAC_ADDR_8192EU;
9810                         #endif
9811                         #ifdef CONFIG_SDIO_HCI
9812                         addr = EEPROM_MAC_ADDR_8192ES;
9813                         #endif
9814                         #ifdef CONFIG_PCI_HCI
9815                         addr = EEPROM_MAC_ADDR_8192EE;
9816                         #endif
9817                 #endif //#ifdef CONFIG_RTL8192E
9818                 
9819                 #ifdef CONFIG_RTL8723B
9820                 #ifdef CONFIG_SDIO_HCI
9821                 addr = EEPROM_MAC_ADDR_8723BS;
9822                 #endif
9823                 #ifdef CONFIG_GSPI_HCI
9824                 addr = EEPROM_MAC_ADDR_8723BS;
9825                 #endif
9826                 #ifdef CONFIG_USB_HCI
9827                 addr = EEPROM_MAC_ADDR_8723BU;
9828                 #endif
9829                 #endif // CONFIG_RTL8723B
9830
9831                 cnts = strlen(tmp[1]);
9832                 if (cnts%2)
9833                 {
9834                         err = -EINVAL;
9835                         goto exit;
9836                 }
9837                 cnts /= 2;
9838                 if (cnts == 0)
9839                 {
9840                         err = -EINVAL;
9841                         goto exit;
9842                 }
9843                 if (cnts > 6)
9844                 {
9845                         DBG_871X("%s: error data for mac addr=\"%s\"\n", __FUNCTION__, tmp[1]);
9846                         err = -EFAULT;
9847                         goto exit;
9848                 }
9849
9850                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
9851                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
9852                 DBG_871X("%s: MAC address=%s\n", __FUNCTION__, tmp[1]);
9853
9854                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
9855                 {
9856                         setdata[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
9857                 }
9858 #ifndef CONFIG_RTL8188E
9859                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
9860 #else
9861                 //Change to check TYPE_EFUSE_MAP_LEN ,beacuse 8188E raw 256,logic map over 256.
9862                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_EFUSE_MAP_LEN, (PVOID)&max_available_size, _FALSE);
9863 #endif
9864                 if ((addr+cnts) > max_available_size)
9865                 {
9866                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
9867                         err = -EFAULT;
9868                         goto exit;
9869                 }
9870
9871                 if (rtw_efuse_map_write(padapter, addr, cnts, setdata) == _FAIL)
9872                 {
9873                         DBG_871X("%s: rtw_efuse_map_write error!!\n", __FUNCTION__);
9874                         err = -EFAULT;
9875                         goto exit;
9876                 }
9877         }
9878         else if (strcmp(tmp[0], "vidpid") == 0)
9879         {
9880                 if (tmp[1]==NULL)
9881                 {
9882                         err = -EINVAL;
9883                         goto exit;
9884                 }
9885
9886                 // pidvid,da0b7881
9887                 #ifdef CONFIG_RTL8192C
9888                 addr = EEPROM_VID_92C;
9889                 #endif // CONFIG_RTL8192C
9890                 #ifdef CONFIG_RTL8192D
9891                         #ifdef CONFIG_USB_HCI
9892                         addr = EEPROM_VID_92DU;
9893                         #else
9894                         addr = EEPROM_VID_92DE;
9895                         #endif
9896                 #endif // CONFIG_RTL8192D
9897                 #ifdef CONFIG_RTL8723A
9898                         #ifdef CONFIG_USB_HCI
9899                         addr = EEPROM_VID_8723AU;
9900                         #endif
9901                 #endif // CONFIG_RTL8723A
9902                 #ifdef CONFIG_RTL8188E
9903                         #ifdef CONFIG_USB_HCI
9904                         addr = EEPROM_VID_88EU;
9905                         #endif
9906                         #ifdef CONFIG_PCI_HCI
9907                         addr = EEPROM_VID_88EE;
9908                         #endif
9909                 #endif // CONFIG_RTL8188E
9910
9911                 #ifdef CONFIG_RTL8192E
9912                         #ifdef CONFIG_USB_HCI
9913                         addr = EEPROM_VID_8192EU;
9914                         #endif
9915                         #ifdef CONFIG_PCI_HCI
9916                         addr = EEPROM_VID_8192EE;
9917                         #endif
9918                 #endif // CONFIG_RTL8188E
9919
9920                 #ifdef CONFIG_RTL8723B
9921                 addr = EEPROM_VID_8723BU;
9922                 #endif
9923                 
9924                 cnts = strlen(tmp[1]);
9925                 if (cnts%2)
9926                 {
9927                         err = -EINVAL;
9928                         goto exit;
9929                 }
9930                 cnts /= 2;
9931                 if (cnts == 0)
9932                 {
9933                         err = -EINVAL;
9934                         goto exit;
9935                 }
9936
9937                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
9938                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
9939                 DBG_871X("%s: VID/PID=%s\n", __FUNCTION__, tmp[1]);
9940
9941                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
9942                 {
9943                         setdata[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
9944                 }
9945
9946                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
9947                 if ((addr+cnts) > max_available_size)
9948                 {
9949                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
9950                         err = -EFAULT;
9951                         goto exit;
9952                 }
9953
9954                 if (rtw_efuse_map_write(padapter, addr, cnts, setdata) == _FAIL)
9955                 {
9956                         DBG_871X("%s: rtw_efuse_map_write error!!\n", __FUNCTION__);
9957                         err = -EFAULT;
9958                         goto exit;
9959                 }
9960         }
9961         else if (strcmp(tmp[0], "wldumpfake") == 0)
9962         {
9963                 if (rtw_efuse_map_read(padapter, 0, EFUSE_MAP_SIZE,  pEfuseHal->fakeEfuseModifiedMap) == _SUCCESS) {
9964                         DBG_871X("%s: WiFi hw efuse dump to Fake map success \n", __FUNCTION__); 
9965                 } else {
9966                         DBG_871X("%s: WiFi hw efuse dump to Fake map Fail \n", __FUNCTION__);
9967                         err = -EFAULT;
9968                 }
9969         }
9970         else if (strcmp(tmp[0], "btwmap") == 0)
9971         {
9972                 rtw_write8(padapter, 0xa3, 0x05); //For 8723AB ,8821S ?
9973                 BTStatus=rtw_read8(padapter, 0xa0);
9974                 DBG_871X("%s: btwmap before read 0xa0 BT Status =0x%x \n", __FUNCTION__,BTStatus);
9975                 if (BTStatus != 0x04)
9976                 {
9977                         sprintf(extra, "BT Status not Active Write FAIL\n");
9978                         goto exit;
9979                 }
9980
9981                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
9982                 {
9983                         err = -EINVAL;
9984                         goto exit;
9985                 }
9986                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
9987                 
9988                 addr=0x1ff;
9989                 rtw_write8(padapter, EFUSE_CTRL+1, (addr & 0xff));
9990                 rtw_msleep_os(10);
9991                 rtw_write8(padapter, EFUSE_CTRL+2, ((addr >> 8) & 0x03));
9992                 rtw_msleep_os(10);
9993                 rtw_write8(padapter, EFUSE_CTRL+3, 0x72);
9994                 rtw_msleep_os(10);
9995                 rtw_read8(padapter, EFUSE_CTRL);
9996
9997                 addr = simple_strtoul(tmp[1], &ptmp, 16);
9998                 addr &= 0xFFF;
9999
10000                 cnts = strlen(tmp[2]);
10001                 if (cnts%2)
10002                 {
10003                         err = -EINVAL;
10004                         goto exit;
10005                 }
10006                 cnts /= 2;
10007                 if (cnts == 0)
10008                 {
10009                         err = -EINVAL;
10010                         goto exit;
10011                 }
10012
10013                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10014                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10015                 DBG_871X("%s: BT data=%s\n", __FUNCTION__, tmp[2]);
10016
10017                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
10018                 {
10019                         setdata[jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
10020                 }
10021
10022                 EFUSE_GetEfuseDefinition(padapter, EFUSE_BT, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
10023                 if ((addr+cnts) > max_available_size)
10024                 {
10025                         DBG_871X("%s: addr(0x%X)+cnts(%d) parameter error!\n", __FUNCTION__, addr, cnts);
10026                         err = -EFAULT;
10027                         goto exit;
10028                 }
10029
10030                 if (rtw_BT_efuse_map_write(padapter, addr, cnts, setdata) == _FAIL)
10031                 {
10032                         DBG_871X("%s: rtw_BT_efuse_map_write error!!\n", __FUNCTION__);
10033                         err = -EFAULT;
10034                         goto exit;
10035                 }
10036                 *extra = 0;
10037                 DBG_871X("%s: after rtw_BT_efuse_map_write to _rtw_memcmp \n", __FUNCTION__);
10038                 if ( (rtw_BT_efuse_map_read(padapter, addr, cnts, ShadowMapBT ) == _SUCCESS ) )
10039                 {
10040                         if (_rtw_memcmp((void*)ShadowMapBT ,(void*)setdata,cnts))
10041                         { 
10042                                 DBG_871X("%s: BT write map compare OK BTStatus=0x%x\n", __FUNCTION__,BTStatus);
10043                                 sprintf(extra, "BT write map compare OK");
10044                                 err = 0;
10045                                 goto exit;
10046                         }
10047                         else
10048                         {
10049                                 sprintf(extra, "BT write map compare FAIL");
10050                                 DBG_871X("%s: BT write map compare FAIL BTStatus=0x%x\n", __FUNCTION__,BTStatus);
10051                                 err = 0;
10052                                 goto exit;
10053                         }
10054                 }
10055         }
10056         else if (strcmp(tmp[0], "btwfake") == 0)
10057         {
10058                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
10059                 {
10060                         err = -EINVAL;
10061                         goto exit;
10062                 }
10063
10064                 addr = simple_strtoul(tmp[1], &ptmp, 16);
10065                 addr &= 0xFFF;
10066
10067                 cnts = strlen(tmp[2]);
10068                 if (cnts%2)
10069                 {
10070                         err = -EINVAL;
10071                         goto exit;
10072                 }
10073                 cnts /= 2;
10074                 if (cnts == 0)
10075                 {
10076                         err = -EINVAL;
10077                         goto exit;
10078                 }
10079
10080                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10081                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10082                 DBG_871X("%s: BT tmp data=%s\n", __FUNCTION__, tmp[2]);
10083                                 
10084                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
10085                 {
10086                         pEfuseHal->fakeBTEfuseModifiedMap[addr+jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
10087                 }
10088         }
10089         else if (strcmp(tmp[0], "btdumpfake") == 0)
10090         {
10091                 if (rtw_BT_efuse_map_read(padapter, 0, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseModifiedMap) == _SUCCESS) {
10092                         DBG_871X("%s: BT read all map success\n", __FUNCTION__);
10093                 } else {
10094                         DBG_871X("%s: BT read all map Fail!\n", __FUNCTION__);
10095                         err = -EFAULT;
10096                 }
10097         }
10098         else if (strcmp(tmp[0], "btfk2map") == 0)
10099         {
10100                 rtw_write8(padapter, 0xa3, 0x05);
10101                 BTStatus=rtw_read8(padapter, 0xa0);
10102                 DBG_871X("%s: btwmap before read 0xa0 BT Status =0x%x \n", __FUNCTION__,BTStatus);
10103                 if (BTStatus != 0x04)
10104                 {
10105                         sprintf(extra, "BT Status not Active Write FAIL\n");
10106                         goto exit;
10107                 }
10108                 
10109                 BTEfuse_PowerSwitch(padapter,1,_TRUE);
10110
10111                 addr=0x1ff;
10112                 rtw_write8(padapter, EFUSE_CTRL+1, (addr & 0xff));
10113                 rtw_msleep_os(10);
10114                 rtw_write8(padapter, EFUSE_CTRL+2, ((addr >> 8) & 0x03));
10115                 rtw_msleep_os(10);
10116                 rtw_write8(padapter, EFUSE_CTRL+3, 0x72);
10117                 rtw_msleep_os(10);
10118                 rtw_read8(padapter, EFUSE_CTRL);
10119
10120                 _rtw_memcpy(pEfuseHal->BTEfuseModifiedMap, pEfuseHal->fakeBTEfuseModifiedMap, EFUSE_BT_MAX_MAP_LEN);
10121                         
10122                 EFUSE_GetEfuseDefinition(padapter, EFUSE_BT, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);     
10123                 if (max_available_size < 1)
10124                 {
10125                         err = -EFAULT;
10126                         goto exit;
10127                 }
10128
10129                 if (rtw_BT_efuse_map_write(padapter, 0x00, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseModifiedMap) == _FAIL)
10130                 {
10131                         DBG_871X("%s: rtw_BT_efuse_map_write error!\n", __FUNCTION__);
10132                         err = -EFAULT;
10133                         goto exit;
10134                 }
10135                 
10136                 DBG_871X("pEfuseHal->fakeBTEfuseModifiedMap OFFSET\tVALUE(hex)\n");
10137                 for (i = 0; i < EFUSE_BT_MAX_MAP_LEN; i += 16)
10138                 {
10139                         printk("0x%02x\t", i);
10140                         for (j=0; j<8; j++) {
10141                                 printk("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10142                         }
10143                         printk("\t");
10144
10145                         for (; j<16; j++) {
10146                                 printk("%02X ", pEfuseHal->fakeBTEfuseModifiedMap[i+j]);
10147                         }
10148                         printk("\n");
10149                 }
10150                 printk("\n");
10151 #if 1           
10152                 err = -EFAULT;
10153                 DBG_871X("%s: rtw_BT_efuse_map_read _rtw_memcmp \n", __FUNCTION__);
10154                 if ( (rtw_BT_efuse_map_read(padapter, 0x00, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseInitMap) == _SUCCESS ) )
10155                 { 
10156                         if (_rtw_memcmp((void*)pEfuseHal->fakeBTEfuseModifiedMap,(void*)pEfuseHal->fakeBTEfuseInitMap,EFUSE_BT_MAX_MAP_LEN))
10157                         { 
10158                                 sprintf(extra, "BT write map compare OK");
10159                                 DBG_871X("%s: BT write map afterf compare success BTStatus=0x%x \n", __FUNCTION__,BTStatus);
10160                                 err = 0;
10161                                 goto exit;
10162                         }
10163                         else
10164                         {
10165                                 sprintf(extra, "BT write map compare FAIL");
10166                                 if (rtw_BT_efuse_map_write(padapter, 0x00, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseModifiedMap) == _FAIL)
10167                                 {
10168                                         DBG_871X("%s: rtw_BT_efuse_map_write compare error,retry = %d!\n", __FUNCTION__,i);
10169                                 }
10170
10171                                 if (rtw_BT_efuse_map_read(padapter, EFUSE_BT, EFUSE_BT_MAX_MAP_LEN, pEfuseHal->fakeBTEfuseInitMap) == _SUCCESS)
10172                                 {
10173                                         DBG_871X("pEfuseHal->fakeBTEfuseInitMap OFFSET\tVALUE(hex)\n");
10174
10175                                         for (i = 0; i < EFUSE_BT_MAX_MAP_LEN; i += 16)
10176                                         {
10177                                                 printk("0x%02x\t", i);
10178                                                 for (j=0; j<8; j++) {
10179                                                         printk("%02X ", pEfuseHal->fakeBTEfuseInitMap[i+j]);
10180                                                 }
10181                                                 printk("\t");
10182                                                 for (; j<16; j++) {
10183                                                         printk("%02X ", pEfuseHal->fakeBTEfuseInitMap[i+j]);
10184                                                 }
10185                                                 printk("\n");
10186                                         }
10187                                         printk("\n"); 
10188                                 }
10189                                 DBG_871X("%s: BT write map afterf compare not match to write efuse try write Map again , BTStatus=0x%x\n", __FUNCTION__,BTStatus);      
10190                                 goto exit;
10191                         }
10192                 }
10193 #endif
10194
10195         }
10196         else if (strcmp(tmp[0], "wlfk2map") == 0)
10197         {
10198                 EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);                                   
10199                 if (max_available_size < 1)
10200                 {
10201                         err = -EFAULT;
10202                         goto exit;
10203                 }
10204                 if (rtw_efuse_map_write(padapter, 0x00, EFUSE_MAP_SIZE, pEfuseHal->fakeEfuseModifiedMap) == _FAIL)
10205                 {
10206                         DBG_871X("%s: rtw_efuse_map_write fakeEfuseModifiedMap error!\n", __FUNCTION__);
10207                         err = -EFAULT;
10208                         goto exit;
10209                 }
10210                 *extra = 0;
10211                 DBG_871X("%s: after rtw_BT_efuse_map_write to _rtw_memcmp \n", __FUNCTION__);
10212                 if ( (rtw_efuse_map_read(padapter, 0x00, EFUSE_MAP_SIZE, ShadowMapWiFi) == _SUCCESS ) )
10213                 {
10214                         if (_rtw_memcmp((void*)ShadowMapWiFi ,(void*)setdata,cnts))
10215                         {
10216                                 DBG_871X("%s: WiFi write map afterf compare OK\n", __FUNCTION__);
10217                                 sprintf(extra, "WiFi write map compare OK\n");
10218                                 err = 0;
10219                                 goto exit;
10220                         }
10221                         else
10222                         {
10223                                 sprintf(extra, "WiFi write map compare FAIL\n");
10224                                 DBG_871X("%s: WiFi write map compare Fail\n", __FUNCTION__);
10225                                 err = 0;
10226                                 goto exit;
10227                         }
10228                 }
10229         }
10230         else if (strcmp(tmp[0], "wlwfake") == 0)
10231         {
10232                 if ((tmp[1]==NULL) || (tmp[2]==NULL))
10233                 {
10234                         err = -EINVAL;
10235                         goto exit;
10236                 }
10237
10238                 addr = simple_strtoul(tmp[1], &ptmp, 16);
10239                 addr &= 0xFFF;
10240
10241                 cnts = strlen(tmp[2]);
10242                 if (cnts%2)
10243                 {
10244                         err = -EINVAL;
10245                         goto exit;
10246                 }
10247                 cnts /= 2;
10248                 if (cnts == 0)
10249                 {
10250                         err = -EINVAL;
10251                         goto exit;
10252                 }
10253
10254                 DBG_871X("%s: addr=0x%X\n", __FUNCTION__, addr);
10255                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
10256                 DBG_871X("%s: map tmp data=%s\n", __FUNCTION__, tmp[2]);
10257
10258                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
10259                 {
10260                         pEfuseHal->fakeEfuseModifiedMap[addr+jj] = key_2char2num(tmp[2][kk], tmp[2][kk+1]);
10261                 }
10262         }
10263
10264 exit:
10265         if (setdata)
10266                 rtw_mfree(setdata, 1024);
10267         if (ShadowMapBT)
10268                 rtw_mfree(ShadowMapBT, EFUSE_BT_MAX_MAP_LEN);
10269         if (ShadowMapWiFi)
10270                 rtw_mfree(ShadowMapWiFi, EFUSE_MAP_SIZE);
10271         if (setrawdata)
10272                 rtw_mfree(setrawdata, EFUSE_MAX_SIZE);
10273         
10274         wrqu->length = strlen(extra);
10275
10276         if (padapter->registrypriv.mp_mode == 0)
10277         {
10278         #ifdef CONFIG_IPS               
10279         rtw_pm_set_ips(padapter, ips_mode);
10280         #endif // CONFIG_IPS
10281
10282         #ifdef CONFIG_LPS       
10283         rtw_pm_set_lps(padapter, lps_mode);
10284         #endif // CONFIG_LPS
10285         }
10286
10287         return err;
10288 }
10289
10290 #if defined(CONFIG_MP_INCLUDED) && defined(CONFIG_MP_IWPRIV_SUPPORT)
10291 /*
10292  * Input Format: %s,%d,%d
10293  *      %s is width, could be
10294  *              "b" for 1 byte
10295  *              "w" for WORD (2 bytes)
10296  *              "dw" for DWORD (4 bytes)
10297  *      1st %d is address(offset)
10298  *      2st %d is data to write
10299  */
10300 static int rtw_mp_write_reg(struct net_device *dev,
10301                         struct iw_request_info *info,
10302                         struct iw_point *wrqu, char *extra)
10303 {
10304         char *pch, *pnext, *ptmp;
10305         char *width_str;
10306         char width;
10307         u32 addr, data;
10308         int ret;
10309         PADAPTER padapter = rtw_netdev_priv(dev);
10310         char input[wrqu->length];
10311
10312         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10313                                  return -EFAULT;
10314                                  
10315         _rtw_memset(extra, 0, wrqu->length);    
10316           
10317         pch = input;
10318
10319         pnext = strpbrk(pch, " ,.-");
10320         if (pnext == NULL) return -EINVAL;
10321         *pnext = 0;
10322         width_str = pch;
10323
10324         pch = pnext + 1;
10325         pnext = strpbrk(pch, " ,.-");
10326         if (pnext == NULL) return -EINVAL;
10327         *pnext = 0;
10328         addr = simple_strtoul(pch, &ptmp, 16);
10329         if (addr > 0x3FFF) return -EINVAL;
10330
10331         pch = pnext + 1;
10332         if ((pch - extra) >= wrqu->length) return -EINVAL;
10333         data = simple_strtoul(pch, &ptmp, 16);
10334
10335         ret = 0;
10336         width = width_str[0];
10337         switch (width) {
10338                 case 'b':
10339                         // 1 byte
10340                         if (data > 0xFF) {
10341                                 ret = -EINVAL;
10342                                 break;
10343                         }
10344                         rtw_write8(padapter, addr, data);
10345                         break;
10346                 case 'w':
10347                         // 2 bytes
10348                         if (data > 0xFFFF) {
10349                                 ret = -EINVAL;
10350                                 break;
10351                         }
10352                         rtw_write16(padapter, addr, data);
10353                         break;
10354                 case 'd':
10355                         // 4 bytes
10356                         rtw_write32(padapter, addr, data);
10357                         break;
10358                 default:
10359                         ret = -EINVAL;
10360                         break;
10361         }
10362
10363         return ret;
10364 }
10365
10366 /*
10367  * Input Format: %s,%d
10368  *      %s is width, could be
10369  *              "b" for 1 byte
10370  *              "w" for WORD (2 bytes)
10371  *              "dw" for DWORD (4 bytes)
10372  *      %d is address(offset)
10373  *
10374  * Return:
10375  *      %d for data readed
10376  */
10377 static int rtw_mp_read_reg(struct net_device *dev,
10378                         struct iw_request_info *info,
10379                         struct iw_point *wrqu, char *extra)
10380 {
10381         char input[wrqu->length];
10382         char *pch, *pnext, *ptmp;
10383         char *width_str;
10384         char width;
10385         char data[20],tmp[20];
10386         u32 addr;
10387         //u32 *data = (u32*)extra;
10388         u32 ret, i=0, j=0, strtout=0;
10389         PADAPTER padapter = rtw_netdev_priv(dev);
10390
10391
10392         if (wrqu->length > 128) 
10393                 return -EFAULT;
10394
10395         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10396                 return -EFAULT;
10397
10398         _rtw_memset(data, 0, 20);
10399         _rtw_memset(tmp, 0, 20);
10400         _rtw_memset(extra, 0, wrqu->length);
10401
10402         pch = input;
10403         pnext = strpbrk(pch, " ,.-");
10404         if (pnext == NULL) return -EINVAL;
10405         *pnext = 0;
10406         width_str = pch;
10407
10408         pch = pnext + 1;
10409         if ((pch - input) >= wrqu->length) return -EINVAL;
10410         
10411         addr = simple_strtoul(pch, &ptmp, 16);
10412         if (addr > 0x3FFF) return -EINVAL;
10413
10414         ret = 0;
10415         width = width_str[0];
10416         switch (width)
10417         {
10418                 case 'b':
10419                         // 1 byte
10420                         // *(u8*)data = rtw_read8(padapter, addr);
10421                         sprintf(extra, "%d\n",  rtw_read8(padapter, addr));
10422                         wrqu->length = strlen(extra);
10423                         break;
10424                 case 'w':
10425                         // 2 bytes
10426                         //*(u16*)data = rtw_read16(padapter, addr);
10427                         sprintf(data, "%04x\n", rtw_read16(padapter, addr));
10428                         for( i=0 ; i <= strlen(data) ; i++)
10429                                 {
10430                                           if( i%2==0 )
10431                                           {
10432                                                    tmp[j]=' ';
10433                                                    j++;
10434                                           }
10435                                           if ( data[i] != '\0' )
10436                                                  tmp[j] = data[i];
10437                                                 
10438                                                  j++;
10439                                 }
10440                                 pch = tmp;              
10441                                 DBG_871X("pch=%s",pch);
10442                                 
10443                                 while( *pch != '\0' )
10444                                 {
10445                                         pnext = strpbrk(pch, " ");
10446                                         if (!pnext)
10447                                                 break;
10448                                         
10449                                         pnext++;
10450                                         if ( *pnext != '\0' )
10451                                         {
10452                                                   strtout = simple_strtoul (pnext , &ptmp, 16);
10453                                                   sprintf( extra, "%s %d" ,extra ,strtout );
10454                                         }
10455                                         else{
10456                                                   break;
10457                                         }
10458                                         pch = pnext;
10459                                 }
10460                         wrqu->length = 7;
10461                         break;
10462                 case 'd':
10463                         // 4 bytes
10464                         //*data = rtw_read32(padapter, addr);
10465                         sprintf(data, "%08x", rtw_read32(padapter, addr));
10466                                 //add read data format blank
10467                                 for( i=0 ; i <= strlen(data) ; i++)
10468                                 {
10469                                           if( i%2==0 )
10470                                           {
10471                                                    tmp[j]=' ';
10472                                                    j++;
10473                                           }
10474                                           if ( data[i] != '\0' )
10475                                           tmp[j] = data[i];
10476                                           
10477                                           j++;
10478                                 }
10479                                 pch = tmp;              
10480                                 DBG_871X("pch=%s",pch);
10481                                 
10482                                 while( *pch != '\0' )
10483                                 {
10484                                         pnext = strpbrk(pch, " ");
10485                                         if (!pnext)
10486                                                 break;
10487                                         
10488                                         pnext++;
10489                                         if ( *pnext != '\0' )
10490                                         {
10491                                                   strtout = simple_strtoul (pnext , &ptmp, 16);
10492                                                   sprintf( extra, "%s %d" ,extra ,strtout );
10493                                         }
10494                                         else{
10495                         break;
10496                                         }
10497                                         pch = pnext;
10498                                 }
10499                         wrqu->length = strlen(extra);
10500                         break;
10501                         
10502                 default:
10503                         wrqu->length = 0;
10504                         ret = -EINVAL;
10505                         break;
10506                         
10507         }
10508
10509         return ret;
10510 }
10511
10512 /*
10513  * Input Format: %d,%x,%x
10514  *      %d is RF path, should be smaller than MAX_RF_PATH_NUMS
10515  *      1st %x is address(offset)
10516  *      2st %x is data to write
10517  */
10518  static int rtw_mp_write_rf(struct net_device *dev,
10519                         struct iw_request_info *info,
10520                         struct iw_point *wrqu, char *extra)
10521 {                       
10522 /*static int rtw_mp_write_rf(struct net_device *dev,
10523                         struct iw_request_info *info,
10524                         union iwreq_data *wrqu, char *extra)
10525 */
10526         u32 path, addr, data;
10527         int ret;
10528         PADAPTER padapter = rtw_netdev_priv(dev);
10529         char input[wrqu->length];
10530
10531         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10532                          return -EFAULT;
10533
10534
10535         ret = sscanf(input, "%d,%x,%x", &path, &addr, &data);
10536         if (ret < 3) return -EINVAL;
10537
10538         if (path >= GET_HAL_RFPATH_NUM(padapter)) return -EINVAL;
10539         if (addr > 0xFF) return -EINVAL;
10540         if (data > 0xFFFFF) return -EINVAL;
10541         
10542         _rtw_memset(extra, 0, wrqu->length);
10543         
10544         write_rfreg(padapter, path, addr, data);
10545         
10546         sprintf(extra, "write_rf completed \n");
10547         wrqu->length = strlen(extra);
10548         
10549         return 0;
10550 }
10551
10552 /*
10553  * Input Format: %d,%x
10554  *      %d is RF path, should be smaller than MAX_RF_PATH_NUMS
10555  *      %x is address(offset)
10556  *
10557  * Return:
10558  *      %d for data readed
10559  */
10560 static int rtw_mp_read_rf(struct net_device *dev,
10561                         struct iw_request_info *info,
10562                         struct iw_point *wrqu, char *extra)
10563 {
10564         char input[wrqu->length];
10565         char *pch, *pnext, *ptmp;
10566         char data[20],tmp[20];
10567         //u32 *data = (u32*)extra;
10568         u32 path, addr;
10569         u32 ret,i=0 ,j=0,strtou=0;
10570         PADAPTER padapter = rtw_netdev_priv(dev);
10571
10572
10573         if (wrqu->length > 128) return -EFAULT;
10574         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10575                 return -EFAULT;
10576
10577         ret = sscanf(input, "%d,%x", &path, &addr);
10578         if (ret < 2) return -EINVAL;
10579
10580         if (path >= GET_HAL_RFPATH_NUM(padapter)) return -EINVAL;
10581         if (addr > 0xFF) return -EINVAL;
10582         
10583         _rtw_memset(extra, 0, wrqu->length);
10584         
10585         //*data = read_rfreg(padapter, path, addr);
10586         sprintf(data, "%08x", read_rfreg(padapter, path, addr));
10587                                 //add read data format blank
10588                                 for( i=0 ; i <= strlen(data) ; i++)
10589                                 {
10590                                           if( i%2==0 )
10591                                           {
10592                                                    tmp[j]=' ';
10593                                                    j++;
10594                                           }
10595                                           tmp[j] = data[i];
10596                                           j++;
10597                                 }
10598                                 pch = tmp;              
10599                                 DBG_871X("pch=%s",pch);
10600                                 
10601                                 while( *pch != '\0' )
10602                                 {
10603                                         pnext = strpbrk(pch, " ");
10604                                         pnext++;
10605                                         if ( *pnext != '\0' )
10606                                         {
10607                                                   strtou = simple_strtoul (pnext , &ptmp, 16);
10608                                                   sprintf( extra, "%s %d" ,extra ,strtou );
10609                                         }
10610                                         else{
10611                                                   break;
10612                                         }
10613                                         pch = pnext;
10614                                 }
10615                         wrqu->length = strlen(extra);   
10616
10617         return 0;
10618 }
10619
10620 static int rtw_mp_start(struct net_device *dev,
10621                         struct iw_request_info *info,
10622                         struct iw_point *wrqu, char *extra)
10623 {
10624         u8 val8;
10625         PADAPTER padapter = rtw_netdev_priv(dev);
10626         HAL_DATA_TYPE   *pHalData = GET_HAL_DATA(padapter);
10627         struct dm_priv  *pdmpriv = &pHalData->dmpriv;
10628         struct hal_ops *pHalFunc = &padapter->HalFunc;
10629
10630         if(padapter->registrypriv.mp_mode ==0)
10631         {
10632                 #if (defined(CONFIG_RTL8723A) || defined(CONFIG_RTL8723B))
10633                 DBG_871X("_rtw_mp_xmit_priv for Download BT patch FW\n");
10634                 _rtw_mp_xmit_priv(&padapter->xmitpriv);
10635                 #endif
10636         
10637                 padapter->registrypriv.mp_mode =1;
10638
10639                 rtw_pm_set_ips(padapter,IPS_NONE);
10640                 LeaveAllPowerSaveMode(padapter);
10641
10642                 MPT_InitializeAdapter(padapter, 1);
10643 #ifdef CONFIG_BT_COEXIST
10644                 rtw_btcoex_HaltNotify(padapter);
10645                 rtw_btcoex_SetManualControl(padapter, _TRUE);
10646                 pdmpriv->DMFlag &= ~DYNAMIC_FUNC_BT;
10647                 // Force to switch Antenna to WiFi
10648                 padapter->registrypriv.mp_mode=0;
10649                 pHalFunc->hal_init(padapter);
10650                 padapter->registrypriv.mp_mode=1;
10651                 //rtw_btcoex_HaltNotify(padapter);
10652 #endif
10653         }
10654
10655         if (padapter->registrypriv.mp_mode == 0)
10656                 return -EPERM;
10657
10658         if (padapter->mppriv.mode == MP_OFF) {
10659                 if (mp_start_test(padapter) == _FAIL)
10660                         return -EPERM;
10661                 padapter->mppriv.mode = MP_ON;
10662                 MPT_PwrCtlDM(padapter,0);
10663         }
10664         padapter->mppriv.bmac_filter = _FALSE;
10665 #ifdef CONFIG_RTL8723B
10666         rtw_write8(padapter, 0x66, 0x27); //Open BT uart Log
10667         rtw_write8(padapter, 0xc50, 0x20); //for RX init Gain
10668 #endif  
10669         ODM_Write_DIG(&pHalData->odmpriv,0x20);
10670
10671         return 0;
10672 }
10673
10674 static int rtw_mp_stop(struct net_device *dev,
10675                         struct iw_request_info *info,
10676                         struct iw_point *wrqu, char *extra)
10677 {
10678         PADAPTER padapter = rtw_netdev_priv(dev);
10679         struct hal_ops *pHalFunc = &padapter->HalFunc;
10680
10681         if(padapter->registrypriv.mp_mode ==1)
10682         {
10683                 #if (defined(CONFIG_RTL8723A) || defined(CONFIG_RTL8723B))
10684                 DBG_871X("_rtw_mp_xmit_priv reinit for normal mode\n");
10685                 _rtw_mp_xmit_priv(&padapter->xmitpriv);
10686                 #endif
10687                 
10688                 MPT_DeInitAdapter(padapter);
10689                 pHalFunc->hal_deinit(padapter);
10690                 padapter->registrypriv.mp_mode=0;
10691                 pHalFunc->hal_init(padapter);
10692         }
10693         
10694         if (padapter->mppriv.mode != MP_OFF) {
10695                 mp_stop_test(padapter);
10696                 padapter->mppriv.mode = MP_OFF;
10697         }
10698
10699         return 0;
10700 }
10701
10702 extern int wifirate2_ratetbl_inx(unsigned char rate);
10703
10704 static int rtw_mp_rate(struct net_device *dev,
10705                         struct iw_request_info *info,
10706                         struct iw_point *wrqu, char *extra)
10707 {
10708         u32 rate = MPT_RATE_1M;
10709         u8              input[wrqu->length];
10710         PADAPTER padapter = rtw_netdev_priv(dev);
10711
10712         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10713                         return -EFAULT;
10714                         
10715         rate = rtw_atoi(input);
10716         sprintf( extra, "Set data rate to %d" , rate );
10717                 
10718         if(rate <= 0x7f)
10719                 rate = wifirate2_ratetbl_inx( (u8)rate);        
10720         else if (rate < 0x90)
10721         //HT  rate 0x80(MCS0)        ~ 0x8F(MCS15)       128~143
10722                 rate =(rate - 0x80 + MPT_RATE_MCS0);
10723         else 
10724                 //VHT rate 0x90(VHT1SS_MCS0) ~ 0x99(VHT1SS_MCS9) 144~153
10725                 rate =(rate - MPT_RATE_VHT1SS_MCS0); 
10726
10727         //DBG_871X("%s: rate=%d\n", __func__, rate);
10728         
10729         if (rate >= MPT_RATE_LAST )     
10730         return -EINVAL;
10731
10732         padapter->mppriv.rateidx = rate;
10733         Hal_SetDataRate(padapter);
10734         
10735         wrqu->length = strlen(extra) + 1;
10736         return 0;
10737 }
10738
10739 static int rtw_mp_channel(struct net_device *dev,
10740                         struct iw_request_info *info,
10741                         struct iw_point *wrqu, char *extra)
10742 {
10743
10744         PADAPTER padapter = rtw_netdev_priv(dev);
10745         HAL_DATA_TYPE   *pHalData       = GET_HAL_DATA(padapter);
10746         u8              input[wrqu->length];
10747         u32     channel = 1;
10748         int cur_ch_offset;
10749
10750         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10751                         return -EFAULT;
10752         
10753         channel = rtw_atoi(input);
10754         //DBG_871X("%s: channel=%d\n", __func__, channel);
10755         sprintf( extra, "Change channel %d to channel %d", padapter->mppriv.channel , channel );
10756         padapter->mppriv.channel = channel;
10757         pHalData->CurrentChannel = channel;
10758         Hal_SetChannel(padapter);
10759
10760         //cur_ch_offset =  rtw_get_offset_by_ch(padapter->mppriv.channel);
10761         //set_channel_bwmode(padapter, padapter->mppriv.channel, cur_ch_offset, padapter->mppriv.bandwidth);
10762         wrqu->length = strlen(extra) + 1;
10763         return 0;
10764 }
10765
10766 static int rtw_mp_bandwidth(struct net_device *dev,
10767                         struct iw_request_info *info,
10768                         struct iw_point *wrqu, char *extra)
10769 {
10770         u32 bandwidth=0, sg=0;
10771         int cur_ch_offset;
10772         //u8 buffer[40];
10773         PADAPTER padapter = rtw_netdev_priv(dev);
10774         HAL_DATA_TYPE   *pHalData       = GET_HAL_DATA(padapter);
10775         //if (copy_from_user(buffer, (void*)wrqu->data.pointer, wrqu->data.length))
10776     //            return -EFAULT;
10777                 
10778         //DBG_871X("%s:iwpriv in=%s\n", __func__, extra);
10779         
10780         sscanf(extra, "40M=%d,shortGI=%d", &bandwidth, &sg);
10781         
10782         if (bandwidth == 1)
10783                 bandwidth=CHANNEL_WIDTH_40;
10784         else if (bandwidth == 2)
10785                 bandwidth=CHANNEL_WIDTH_80;
10786         DBG_871X("%s: bw=%d sg=%d \n", __func__, bandwidth , sg);
10787         
10788         padapter->mppriv.bandwidth = (u8)bandwidth;
10789         pHalData->CurrentChannelBW = bandwidth;
10790         padapter->mppriv.preamble = sg;
10791         
10792         SetBandwidth(padapter);
10793         //cur_ch_offset =  rtw_get_offset_by_ch(padapter->mppriv.channel);
10794         //set_channel_bwmode(padapter, padapter->mppriv.channel, cur_ch_offset, bandwidth);
10795
10796         return 0;
10797 }
10798
10799
10800 static int rtw_mp_txpower_index(struct net_device *dev,
10801                         struct iw_request_info *info,
10802                         struct iw_point *wrqu, char *extra)
10803 {
10804         PADAPTER padapter = rtw_netdev_priv(dev);
10805         char input[wrqu->length];
10806         u32 rfpath;
10807         u32 txpower_inx;
10808
10809         if (wrqu->length > 128)
10810                 return -EFAULT;
10811
10812         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10813                 return -EFAULT;
10814
10815         rfpath = rtw_atoi(input);
10816         txpower_inx = mpt_ProQueryCalTxPower(padapter, rfpath);
10817         sprintf(extra, " %d", txpower_inx);
10818         wrqu->length = strlen(extra) + 1;
10819
10820         return 0;
10821 }
10822
10823
10824 static int rtw_mp_txpower(struct net_device *dev,
10825                         struct iw_request_info *info,
10826                         struct iw_point *wrqu, char *extra)
10827 {
10828         u32             idx_a=0,idx_b=0,MsetPower=1;
10829         u8              input[wrqu->length];
10830
10831         PADAPTER padapter = rtw_netdev_priv(dev);
10832
10833         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10834                         return -EFAULT;
10835
10836         MsetPower = strncmp(input, "off", 3); 
10837         sscanf(input,"patha=%d,pathb=%d",&idx_a,&idx_b);
10838         //DBG_871X("%s: tx_pwr_idx_a=%x b=%x\n", __func__, idx_a, idx_b);
10839         if(MsetPower==0)
10840         {
10841                 padapter->mppriv.bSetTxPower = 0;
10842                 sprintf( extra, "MP Set power off");
10843         }
10844         else
10845         {
10846         sprintf( extra, "Set power level path_A:%d path_B:%d", idx_a , idx_b );
10847         padapter->mppriv.txpoweridx = (u8)idx_a;
10848         padapter->mppriv.txpoweridx_b = (u8)idx_b;
10849         padapter->mppriv.bSetTxPower = 1;
10850                 Hal_SetAntennaPathPower(padapter);
10851         }
10852         wrqu->length = strlen(extra) + 1;
10853         return 0;
10854 }
10855
10856 static int rtw_mp_ant_tx(struct net_device *dev,
10857                         struct iw_request_info *info,
10858                         struct iw_point *wrqu, char *extra)
10859 {
10860         u8 i;
10861         u8              input[wrqu->length];
10862         u16 antenna = 0;
10863         PADAPTER padapter = rtw_netdev_priv(dev);
10864
10865         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10866                         return -EFAULT;
10867                         
10868         //DBG_871X("%s: input=%s\n", __func__, input);  
10869         
10870         sprintf( extra, "switch Tx antenna to %s", input );
10871         
10872         for (i=0; i < strlen(input); i++)
10873         {
10874                 switch(input[i])
10875                         {
10876                                 case 'a' :
10877                                                                 antenna|=ANTENNA_A;
10878                                                                 break;
10879                                 case 'b':
10880                                                                 antenna|=ANTENNA_B;
10881                                                                 break;
10882                         }
10883         }
10884         //antenna |= BIT(extra[i]-'a');
10885         //DBG_871X("%s: antenna=0x%x\n", __func__, antenna);            
10886         padapter->mppriv.antenna_tx = antenna;
10887         //DBG_871X("%s:mppriv.antenna_rx=%d\n", __func__, padapter->mppriv.antenna_tx);
10888         
10889         Hal_SetAntenna(padapter);
10890
10891         wrqu->length = strlen(extra) + 1;
10892         return 0;
10893 }
10894
10895 static int rtw_mp_ant_rx(struct net_device *dev,
10896                         struct iw_request_info *info,
10897                         struct iw_point *wrqu, char *extra)
10898 {
10899         u8 i;
10900         u16 antenna = 0;
10901         u8              input[wrqu->length];
10902         PADAPTER padapter = rtw_netdev_priv(dev);
10903
10904         if (copy_from_user(input, wrqu->pointer, wrqu->length))
10905                         return -EFAULT;
10906         //DBG_871X("%s: input=%s\n", __func__, input);
10907         _rtw_memset(extra, 0, wrqu->length);
10908         
10909         sprintf( extra, "switch Rx antenna to %s", input );
10910         
10911         for (i=0; i < strlen(input); i++) {
10912         switch( input[i] )
10913                         {
10914                                 case 'a' :
10915                                                                 antenna|=ANTENNA_A;
10916                                                                 break;
10917                                 case 'b':
10918                                                                 antenna|=ANTENNA_B;
10919                                                                 break;
10920                                 case 'c' :
10921                                                                 antenna|=ANTENNA_C;
10922                                                                 break;
10923                         }
10924         }
10925         
10926         //DBG_871X("%s: antenna=0x%x\n", __func__, antenna);            
10927         padapter->mppriv.antenna_rx = antenna;
10928         //DBG_871X("%s:mppriv.antenna_rx=%d\n", __func__, padapter->mppriv.antenna_rx);
10929         Hal_SetAntenna(padapter);
10930         wrqu->length = strlen(extra);
10931         
10932         return 0;
10933 }
10934
10935 static int rtw_mp_ctx(struct net_device *dev,
10936                         struct iw_request_info *info,
10937                         struct iw_point *wrqu, char *extra)
10938 {
10939         u32 pkTx = 1, countPkTx = 1, cotuTx = 1, CarrSprTx = 1, scTx = 1, sgleTx = 1, stop = 1;
10940         u32 bStartTest = 1;
10941         u32 count = 0,pktinterval=0;
10942         struct mp_priv *pmp_priv;
10943         struct pkt_attrib *pattrib;
10944
10945         PADAPTER padapter = rtw_netdev_priv(dev);
10946
10947
10948         pmp_priv = &padapter->mppriv;
10949
10950         if (copy_from_user(extra, wrqu->pointer, wrqu->length))
10951                         return -EFAULT;
10952                         
10953         DBG_871X("%s: in=%s\n", __func__, extra);
10954
10955         countPkTx = strncmp(extra, "count=", 5); // strncmp TRUE is 0
10956         cotuTx = strncmp(extra, "background", 20);
10957         CarrSprTx = strncmp(extra, "background,cs", 20);
10958         scTx = strncmp(extra, "background,sc", 20);
10959         sgleTx = strncmp(extra, "background,stone", 20);
10960         pkTx = strncmp(extra, "background,pkt", 20);
10961         stop = strncmp(extra, "stop", 4);
10962         sscanf(extra, "count=%d,pkt", &count);
10963         sscanf(extra, "pktinterval=%d", &pktinterval);
10964         
10965         //DBG_871X("%s: count=%d countPkTx=%d cotuTx=%d CarrSprTx=%d scTx=%d sgleTx=%d pkTx=%d stop=%d\n", __func__, count, countPkTx, cotuTx, CarrSprTx, pkTx, sgleTx, scTx, stop);
10966         _rtw_memset(extra, '\0', sizeof(extra));
10967
10968         if( pktinterval !=0 )
10969         {
10970                 sprintf( extra, "Pkt Interval = %d",pktinterval);
10971                 padapter->mppriv.pktInterval = pktinterval;
10972                 
10973                 wrqu->length = strlen(extra);
10974                 return 0;
10975         }
10976         
10977         if (stop == 0) {
10978                 bStartTest = 0; // To set Stop
10979                 pmp_priv->tx.stop = 1;
10980                 sprintf( extra, "Stop continuous Tx");
10981         } else {
10982                 bStartTest = 1;
10983                 if (pmp_priv->mode != MP_ON) {
10984                         if (pmp_priv->tx.stop != 1) {
10985                                 DBG_871X("%s: MP_MODE != ON %d\n", __func__, pmp_priv->mode);
10986                                 return  -EFAULT;
10987                         }
10988                 }
10989         }
10990
10991         if (pkTx == 0 || countPkTx == 0)
10992                 pmp_priv->mode = MP_PACKET_TX;
10993         if (sgleTx == 0)
10994                 pmp_priv->mode = MP_SINGLE_TONE_TX;
10995         if (cotuTx == 0)
10996                 pmp_priv->mode = MP_CONTINUOUS_TX;
10997         if (CarrSprTx == 0)
10998                 pmp_priv->mode = MP_CARRIER_SUPPRISSION_TX;
10999         if (scTx == 0)
11000                 pmp_priv->mode = MP_SINGLE_CARRIER_TX;
11001
11002         switch (pmp_priv->mode)
11003         {
11004                 case MP_PACKET_TX:
11005                 
11006                         //DBG_871X("%s:pkTx %d\n", __func__,bStartTest);
11007                         if (bStartTest == 0)
11008                         {
11009                                 pmp_priv->tx.stop = 1;
11010                                 pmp_priv->mode = MP_ON;
11011                                 sprintf( extra, "Stop continuous Tx");
11012                         }
11013                         else if (pmp_priv->tx.stop == 1)
11014                         {
11015                                 sprintf( extra, "Start continuous DA=ffffffffffff len=1500 count=%u,\n",count);
11016                                 //DBG_871X("%s:countPkTx %d\n", __func__,count);
11017                                 pmp_priv->tx.stop = 0;
11018                                 pmp_priv->tx.count = count;
11019                                 pmp_priv->tx.payload = 2;
11020 #ifdef CONFIG_80211N_HT
11021                                 pmp_priv->tx.attrib.ht_en = 1;
11022 #endif
11023 #ifdef CONFIG_80211AC_VHT
11024                                 pmp_priv->tx.attrib.raid = RATEID_IDX_VHT_1SS; //10
11025 #endif
11026                                 pattrib = &pmp_priv->tx.attrib;
11027                                 pattrib->pktlen = 1000;
11028                                 _rtw_memset(pattrib->dst, 0xFF, ETH_ALEN);
11029                                 SetPacketTx(padapter);
11030                         } 
11031                         else {
11032                                 //DBG_871X("%s: pkTx not stop\n", __func__);
11033                                 return -EFAULT;
11034                         }
11035                                 wrqu->length = strlen(extra);
11036                                 return 0;
11037
11038                 case MP_SINGLE_TONE_TX:
11039                         //DBG_871X("%s: sgleTx %d \n", __func__, bStartTest);
11040                         if (bStartTest != 0){
11041                                 sprintf( extra, "Start continuous DA=ffffffffffff len=1500 \n infinite=yes.");
11042             }
11043                         Hal_SetSingleToneTx(padapter, (u8)bStartTest);
11044                         break;
11045
11046                 case MP_CONTINUOUS_TX:
11047                         //DBG_871X("%s: cotuTx %d\n", __func__, bStartTest);
11048                         if (bStartTest != 0){
11049                                 sprintf( extra, "Start continuous DA=ffffffffffff len=1500 \n infinite=yes.");
11050                          }
11051                 Hal_SetContinuousTx(padapter, (u8)bStartTest);
11052                         break;
11053
11054                 case MP_CARRIER_SUPPRISSION_TX:
11055                         //DBG_871X("%s: CarrSprTx %d\n", __func__, bStartTest);
11056                         if (bStartTest != 0){
11057                                 if( pmp_priv->rateidx <= MPT_RATE_11M ) 
11058                                 {
11059                                         sprintf( extra, "Start continuous DA=ffffffffffff len=1500 \n infinite=yes.");
11060                                         
11061                                 }else
11062                                         sprintf( extra, "Specify carrier suppression but not CCK rate");
11063                         }
11064                         Hal_SetCarrierSuppressionTx(padapter, (u8)bStartTest);
11065                         break;
11066
11067                 case MP_SINGLE_CARRIER_TX:
11068                         //DBG_871X("%s: scTx %d\n", __func__, bStartTest);
11069                         if (bStartTest != 0){
11070                                 sprintf( extra, "Start continuous DA=ffffffffffff len=1500 \n infinite=yes.");
11071                         }
11072                         Hal_SetSingleCarrierTx(padapter, (u8)bStartTest);
11073                         break;
11074
11075                 default:
11076                         //DBG_871X("%s:No Match MP_MODE\n", __func__);
11077                         sprintf( extra, "Error! Continuous-Tx is not on-going.");
11078                         return -EFAULT;
11079         }
11080
11081         if ( bStartTest==1 && pmp_priv->mode != MP_ON) {
11082                 struct mp_priv *pmp_priv = &padapter->mppriv;
11083                 if (pmp_priv->tx.stop == 0) {
11084                         pmp_priv->tx.stop = 1;
11085                         //DBG_871X("%s: pkt tx is running...\n", __func__);
11086                         rtw_msleep_os(5);
11087                 }
11088 #ifdef CONFIG_80211N_HT
11089                 pmp_priv->tx.attrib.ht_en = 1;
11090 #endif
11091 #ifdef CONFIG_80211AC_VHT
11092                 pmp_priv->tx.attrib.raid = RATEID_IDX_VHT_1SS; //10
11093 #endif
11094                 pmp_priv->tx.stop = 0;
11095                 pmp_priv->tx.count = 1;
11096                 SetPacketTx(padapter);
11097         } else {
11098                 pmp_priv->mode = MP_ON;
11099         }
11100
11101         wrqu->length = strlen(extra);
11102         return 0;
11103 }
11104
11105
11106 static int rtw_mp_disable_bt_coexist(struct net_device *dev,
11107                         struct iw_request_info *info,
11108                         union iwreq_data *wrqu, char *extra)
11109 {
11110         PADAPTER padapter = (PADAPTER)rtw_netdev_priv(dev);
11111         HAL_DATA_TYPE   *pHalData = GET_HAL_DATA(padapter);
11112         struct dm_priv  *pdmpriv = &pHalData->dmpriv;
11113         struct hal_ops *pHalFunc = &padapter->HalFunc;
11114         
11115         u8 input[wrqu->data.length];
11116         u32 bt_coexist;
11117
11118         if (copy_from_user(input, wrqu->data.pointer, wrqu->data.length))
11119                 return -EFAULT;
11120         
11121         bt_coexist = rtw_atoi(input);
11122         
11123         if( bt_coexist == 0 )
11124         {
11125                 RT_TRACE(_module_mp_, _drv_info_,
11126                         ("Set OID_RT_SET_DISABLE_BT_COEXIST: disable BT_COEXIST\n"));
11127                 DBG_871X("Set OID_RT_SET_DISABLE_BT_COEXIST: disable BT_COEXIST\n");
11128 #ifdef CONFIG_BT_COEXIST
11129                 rtw_btcoex_HaltNotify(padapter);
11130                 rtw_btcoex_SetManualControl(padapter, _TRUE);
11131                 pdmpriv->DMFlag &= ~DYNAMIC_FUNC_BT;
11132                 // Force to switch Antenna to WiFi
11133                 rtw_write16(padapter, 0x870, 0x300);
11134                 rtw_write16(padapter, 0x860, 0x110); 
11135 #endif // CONFIG_BT_COEXIST
11136         }
11137         else
11138         {
11139                 RT_TRACE(_module_mp_, _drv_info_,
11140                         ("Set OID_RT_SET_DISABLE_BT_COEXIST: enable BT_COEXIST\n"));
11141 #ifdef CONFIG_BT_COEXIST                
11142                 pdmpriv->DMFlag |= DYNAMIC_FUNC_BT;
11143                 rtw_btcoex_SetManualControl(padapter, _FALSE);
11144 #endif
11145         }
11146
11147         return 0;       
11148 }
11149
11150
11151 static int rtw_mp_arx(struct net_device *dev,
11152                         struct iw_request_info *info,
11153                         struct iw_point *wrqu, char *extra)
11154 {
11155         u8 bStartRx=0,bStopRx=0,bQueryPhy=0,bQueryMac=0,bSetBssid=0;
11156         u8 bmac_filter = 0,bfilter_init=0;
11157         u32 cckok=0,cckcrc=0,ofdmok=0,ofdmcrc=0,htok=0,htcrc=0,OFDM_FA=0,CCK_FA=0,DropPacket=0,vht_ok=0,vht_err=0;
11158         u32             mac_cck_ok=0, mac_ofdm_ok=0, mac_ht_ok=0, mac_vht_ok=0;
11159         u32             mac_cck_err=0, mac_ofdm_err=0, mac_ht_err=0, mac_vht_err=0;
11160         u8              input[wrqu->length];
11161         char *pch, *ptmp, *token, *tmp[2]={0x00,0x00};
11162         u32 i=0,ii=0,jj=0,kk=0,cnts=0;
11163         PADAPTER padapter = rtw_netdev_priv(dev);
11164         struct mp_priv *pmppriv = &padapter->mppriv;
11165
11166         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11167                         return -EFAULT;
11168
11169         DBG_871X("%s: %s\n", __func__, input);
11170
11171         bStartRx = (strncmp(input, "start", 5)==0)?1:0; // strncmp TRUE is 0
11172         bStopRx = (strncmp(input, "stop", 5)==0)?1:0; // strncmp TRUE is 0
11173         bQueryPhy = (strncmp(input, "phy", 3)==0)?1:0; // strncmp TRUE is 0
11174         bQueryMac = (strncmp(input, "mac", 3)==0)?1:0; // strncmp TRUE is 0
11175         bSetBssid = (strncmp(input, "setbssid=", 8)==0)?1:0; // strncmp TRUE is 0
11176         //bfilter_init = (strncmp(input, "filter_init",11)==0)?1:0;
11177         bmac_filter = (strncmp(input, "accept_mac",10)==0)?1:0;
11178
11179
11180         if(bSetBssid==1){
11181                 pch = input;
11182                 while ((token = strsep(&pch, "=")) != NULL)
11183                 {
11184                         if (i > 1) break;
11185                         tmp[i] = token;
11186                         i++;
11187                 }
11188                 if ((tmp[0]==NULL) && (tmp[1]==NULL)){
11189                         return -EFAULT;
11190                 }
11191                 else{
11192                         cnts = strlen(tmp[1])/2;
11193                         if (cnts<1) return -EFAULT;
11194                         DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
11195                         DBG_871X("%s: data=%s\n", __FUNCTION__, tmp[1]);
11196                         for (jj=0, kk=0; jj < cnts ; jj++, kk+=2){
11197                                          pmppriv->network_macaddr[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
11198                                         DBG_871X("network_macaddr[%d]=%x \n",jj, pmppriv->network_macaddr[jj]);
11199                         }
11200                 }
11201                 pmppriv->bSetRxBssid = _TRUE;
11202         }
11203
11204         if(bmac_filter)
11205         {
11206                 pmppriv->bmac_filter = bmac_filter;
11207                 pch = input;
11208                 while ((token = strsep(&pch, "=")) != NULL)
11209                 {
11210                         if (i > 1) break;
11211                         tmp[i] = token;
11212                         i++;
11213                 }
11214                 if ((tmp[0]==NULL) && (tmp[1]==NULL)){
11215                         return -EFAULT;
11216                 }
11217                 else{
11218                         cnts = strlen(tmp[1])/2;
11219                         if (cnts<1) return -EFAULT;
11220                         DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
11221                         DBG_871X("%s: data=%s\n", __FUNCTION__, tmp[1]);
11222                         for (jj=0, kk=0; jj < cnts ; jj++, kk+=2){
11223                                         pmppriv->mac_filter[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
11224                                         DBG_871X("%s mac_filter[%d]=%x \n",__FUNCTION__,jj, pmppriv->mac_filter[jj]);
11225                         }
11226                 }
11227         }
11228         
11229         if(bStartRx)
11230         {
11231                 sprintf( extra, "start");
11232                 SetPacketRx(padapter, bStartRx);
11233         }
11234         else if(bStopRx)
11235         {
11236                 SetPacketRx(padapter, 0);
11237                 pmppriv->bmac_filter = _FALSE;
11238                 sprintf( extra, "Received packet OK:%d CRC error:%d ,Filter out:%d",padapter->mppriv.rx_pktcount,padapter->mppriv.rx_crcerrpktcount,padapter->mppriv.rx_pktcount_filter_out);
11239         }
11240         else if(bQueryPhy)
11241         {          
11242
11243                 if (IS_HARDWARE_TYPE_JAGUAR(padapter)) 
11244                 {
11245                         cckok      = PHY_QueryBBReg(padapter, 0xF04, 0x3FFF);        // [13:0]  
11246                         ofdmok     = PHY_QueryBBReg(padapter, 0xF14, 0x3FFF);        // [13:0]  
11247                         htok       = PHY_QueryBBReg(padapter, 0xF10, 0x3FFF);     // [13:0]
11248                         vht_ok      = PHY_QueryBBReg(padapter, 0xF0C, 0x3FFF);     // [13:0]
11249                                                                   
11250                         cckcrc     = PHY_QueryBBReg(padapter, 0xF04, 0x3FFF0000); // [29:16]                                            
11251                         ofdmcrc    = PHY_QueryBBReg(padapter, 0xF14, 0x3FFF0000); // [29:16]
11252                         htcrc      = PHY_QueryBBReg(padapter, 0xF10, 0x3FFF0000); // [29:16]            
11253                         vht_err     = PHY_QueryBBReg(padapter, 0xF0C, 0x3FFF0000); // [29:16]           
11254                         
11255                         CCK_FA = PHY_QueryBBReg(padapter, 0xa5c, bMaskLWord);
11256                         OFDM_FA = PHY_QueryBBReg(padapter, 0xF48, bMaskLWord);
11257                 } 
11258                 else
11259                 {
11260                         cckok      = PHY_QueryBBReg(padapter, 0xF88, bMaskDWord);               
11261                         ofdmok     = PHY_QueryBBReg(padapter, 0xF94, bMaskLWord);               
11262                         htok       = PHY_QueryBBReg(padapter, 0xF90, bMaskLWord);
11263                         vht_ok      = 0;
11264                     
11265                         cckcrc     = PHY_QueryBBReg(padapter, 0xF84, bMaskDWord);                                               
11266                         ofdmcrc    = PHY_QueryBBReg(padapter, 0xF94, bMaskHWord);
11267                         htcrc      = PHY_QueryBBReg(padapter, 0xF90, bMaskHWord);               
11268                         vht_err     = 0;
11269                 
11270                 OFDM_FA = PHY_QueryBBReg(padapter, 0xCF0, bMaskLWord) + PHY_QueryBBReg(padapter, 0xCF2, bMaskLWord) + 
11271                                         PHY_QueryBBReg(padapter, 0xDA2, bMaskLWord)+ PHY_QueryBBReg(padapter, 0xDA4, bMaskLWord) + 
11272                                         PHY_QueryBBReg(padapter, 0xDA6, bMaskLWord) + PHY_QueryBBReg(padapter, 0xDA8, bMaskLWord);
11273                 
11274                 CCK_FA=(rtw_read8(padapter, 0xa5b )<<8 ) | (rtw_read8(padapter, 0xa5c));
11275                 }
11276                 DBG_871X("%s: OFDM_FA =%d\n", __FUNCTION__, OFDM_FA);
11277                 DBG_871X("%s: CCK_FA =%d\n", __FUNCTION__, CCK_FA);
11278                 sprintf( extra, "Phy Received packet OK:%d CRC error:%d FA Counter: %d",cckok+ofdmok+htok+vht_ok,cckcrc+ofdmcrc+htcrc+vht_err,OFDM_FA+CCK_FA);
11279         }
11280         else if(bQueryMac)
11281         {
11282                 // for 8723A
11283                 {
11284                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x3);
11285                         mac_cck_ok      = PHY_QueryMacReg(padapter, 0x664, bMaskLWord);      // [15:0]    
11286                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x0);
11287                         mac_ofdm_ok     = PHY_QueryMacReg(padapter, 0x664, bMaskLWord);      // [15:0]   
11288                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x6);
11289                         mac_ht_ok       = PHY_QueryMacReg(padapter, 0x664, bMaskLWord);     // [15:0]   
11290                         mac_vht_ok      = 0;
11291                         
11292                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x4);
11293                         mac_cck_err     = PHY_QueryMacReg(padapter, 0x664, bMaskLWord); // [15:0]       
11294                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x1);
11295                         mac_ofdm_err    = PHY_QueryMacReg(padapter, 0x664, bMaskLWord); // [15:0]       
11296                         PHY_SetMacReg(padapter, 0x664, BIT28|BIT29|BIT30|BIT31, 0x7);
11297                         mac_ht_err      = PHY_QueryMacReg(padapter, 0x664, bMaskLWord); // [15:0]               
11298                         mac_vht_err     = 0;
11299                         //Mac_DropPacket
11300                         rtw_write32(padapter, 0x664, (rtw_read32(padapter, 0x0664)& 0x0FFFFFFF)| Mac_DropPacket);
11301                         DropPacket = rtw_read32(padapter, 0x664)& 0x0000FFFF;
11302                 } 
11303                 
11304                 sprintf( extra, "Mac Received packet OK: %d , CRC error: %d , Drop Packets: %d\n",
11305                                 mac_cck_ok+mac_ofdm_ok+mac_ht_ok+mac_vht_ok,mac_cck_err+mac_ofdm_err+mac_ht_err+mac_vht_err,DropPacket);                        
11306         }
11307         wrqu->length = strlen(extra) + 1;
11308
11309         
11310         return 0;
11311 }
11312
11313 static int rtw_mp_trx_query(struct net_device *dev,
11314                         struct iw_request_info *info,
11315                         struct iw_point *wrqu, char *extra)
11316 {
11317         u32 txok,txfail,rxok,rxfail,rxfilterout;
11318         PADAPTER padapter = rtw_netdev_priv(dev);
11319         //if (copy_from_user(extra, wrqu->data.pointer, wrqu->data.length))
11320         //      return -EFAULT;
11321
11322         txok=padapter->mppriv.tx.sended;
11323         txfail=0;
11324         rxok = padapter->mppriv.rx_pktcount;
11325         rxfail = padapter->mppriv.rx_crcerrpktcount;
11326         rxfilterout = padapter->mppriv.rx_pktcount_filter_out;
11327
11328         _rtw_memset(extra, '\0', 128);
11329
11330         sprintf(extra, "Tx OK:%d, Tx Fail:%d, Rx OK:%d, CRC error:%d ,Rx Filter out:%d \n", txok, txfail,rxok,rxfail,rxfilterout);
11331
11332         wrqu->length=strlen(extra)+1;
11333
11334         return 0;
11335 }
11336
11337 static int rtw_mp_pwrtrk(struct net_device *dev,
11338                         struct iw_request_info *info,
11339                         struct iw_point *wrqu, char *extra)
11340 {
11341         u8 enable;
11342         u32 thermal;
11343         s32 ret;
11344         PADAPTER padapter = rtw_netdev_priv(dev);
11345         HAL_DATA_TYPE                   *pHalData = GET_HAL_DATA(padapter);
11346         u8              input[wrqu->length];
11347
11348         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11349                         return -EFAULT;
11350
11351         _rtw_memset(extra, 0, wrqu->length);
11352
11353         enable = 1;
11354         if (wrqu->length > 1) { // not empty string
11355                 if (strncmp(input, "stop", 4) == 0)
11356                 {       
11357                         enable = 0;
11358                         sprintf(extra, "mp tx power tracking stop");
11359                         pHalData->TxPowerTrackControl = _FALSE;
11360                 }
11361                 else if (sscanf(input, "ther=%d", &thermal)) {
11362                         pHalData->TxPowerTrackControl = _TRUE;
11363                                 ret = Hal_SetThermalMeter(padapter, (u8)thermal);
11364                                 if (ret == _FAIL) return -EPERM;
11365                                 sprintf(extra, "mp tx power tracking start,target value=%d ok ",thermal);
11366                 }else   {
11367                                 return -EINVAL;
11368                 }
11369         }
11370
11371         ret = Hal_SetPowerTracking(padapter, enable);
11372         if (ret == _FAIL) return -EPERM;
11373
11374         wrqu->length = strlen(extra);
11375
11376         return 0;
11377 }
11378
11379 static int rtw_mp_psd(struct net_device *dev,
11380                         struct iw_request_info *info,
11381                         struct iw_point *wrqu, char *extra)
11382 {
11383         PADAPTER padapter = rtw_netdev_priv(dev);
11384         u8              input[wrqu->length];
11385         
11386         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11387                 return -EFAULT;
11388         
11389         strcpy(extra,input);
11390         
11391         wrqu->length = mp_query_psd(padapter, extra);
11392         
11393         return 0;
11394 }
11395
11396 static int rtw_mp_thermal(struct net_device *dev,
11397                         struct iw_request_info *info,
11398                         struct iw_point *wrqu, char *extra)
11399 {
11400         u8 val;
11401         u16 bwrite=1;
11402         
11403         #ifdef CONFIG_RTL8192C
11404                         u16 addr=EEPROM_THERMAL_METER_92C;
11405         #endif
11406         #ifdef CONFIG_RTL8192D
11407                         u16 addr=EEPROM_THERMAL_METER_92D;
11408         #endif
11409         #ifdef CONFIG_RTL8723A
11410                         u16 addr=EEPROM_THERMAL_METER_8723A;
11411         #endif
11412         #ifdef CONFIG_RTL8188E
11413                         u16 addr=EEPROM_THERMAL_METER_88E;
11414         #endif
11415         #if defined(CONFIG_RTL8812A) || defined(CONFIG_RTL8821A)
11416                         u16 addr=EEPROM_THERMAL_METER_8812;
11417         #endif
11418         #ifdef CONFIG_RTL8192E
11419                         u16 addr=EEPROM_THERMAL_METER_8192E;
11420         #endif
11421         #ifdef CONFIG_RTL8723B
11422                         u16 addr=EEPROM_THERMAL_METER_8723B;
11423         #endif
11424         u16 cnt=1;
11425         u16 max_available_size=0;
11426         PADAPTER padapter = rtw_netdev_priv(dev);       
11427
11428         if (copy_from_user(extra, wrqu->pointer, wrqu->length))
11429                 return -EFAULT;
11430
11431         //DBG_871X("print extra %s \n",extra); 
11432          
11433          bwrite = strncmp(extra, "write", 6); // strncmp TRUE is 0
11434          
11435          Hal_GetThermalMeter(padapter, &val);
11436          
11437          if( bwrite == 0 )      
11438          {
11439                  //DBG_871X("to write val:%d",val);
11440                         EFUSE_GetEfuseDefinition(padapter, EFUSE_WIFI, TYPE_AVAILABLE_EFUSE_BYTES_TOTAL, (PVOID)&max_available_size, _FALSE);
11441                         if( 2 > max_available_size )
11442                         {                       
11443                                 DBG_871X("no available efuse!\n");
11444                                 return -EFAULT;
11445                         }       
11446                         if ( rtw_efuse_map_write(padapter, addr, cnt, &val) == _FAIL )
11447                         {
11448                                 DBG_871X("rtw_efuse_map_write error \n");                       
11449                                 return -EFAULT;
11450                         } 
11451                         else
11452                         {
11453                                  sprintf(extra, " efuse write ok :%d", val);    
11454                         }
11455           }
11456           else
11457           {
11458                          sprintf(extra, "%d", val);
11459           }
11460         wrqu->length = strlen(extra);
11461         
11462         return 0;
11463 }
11464
11465 static int rtw_mp_reset_stats(struct net_device *dev,
11466                         struct iw_request_info *info,
11467                         struct iw_point *wrqu, char *extra)
11468 {
11469         struct mp_priv *pmp_priv;
11470         struct pkt_attrib *pattrib;
11471         PADAPTER padapter = rtw_netdev_priv(dev);
11472         
11473         pmp_priv = &padapter->mppriv;
11474         
11475         pmp_priv->tx.sended = 0;
11476         pmp_priv->tx_pktcount = 0;
11477         pmp_priv->rx_pktcount = 0;
11478         pmp_priv->rx_pktcount_filter_out=0;
11479         pmp_priv->rx_crcerrpktcount = 0;
11480
11481         //reset phy counter
11482         if (IS_HARDWARE_TYPE_JAGUAR(padapter))
11483         {
11484                 write_bbreg(padapter, 0xB58, BIT0, 0x1);
11485                 write_bbreg(padapter, 0xB58, BIT0, 0x0);
11486
11487                 write_bbreg(padapter, 0x9A4, BIT17, 0x1);//reset  OFDA FA counter
11488                 write_bbreg(padapter, 0x9A4, BIT17, 0x0);
11489                 
11490                 write_bbreg(padapter, 0xA5C, BIT15, 0x0);//reset  CCK FA counter
11491                 write_bbreg(padapter, 0xA5C, BIT15, 0x1);
11492         }
11493         else
11494         {
11495                 write_bbreg(padapter, 0xF14, BIT16, 0x1);
11496                 rtw_msleep_os(10);
11497                 write_bbreg(padapter, 0xF14, BIT16, 0x0);
11498                 
11499                 write_bbreg(padapter, 0xD00, BIT27, 0x1);//reset  OFDA FA counter
11500                 write_bbreg(padapter, 0xC0C, BIT31, 0x1);//reset  OFDA FA counter
11501                 write_bbreg(padapter, 0xD00, BIT27, 0x0);
11502                 write_bbreg(padapter, 0xC0C, BIT31, 0x0);
11503                 
11504                 write_bbreg(padapter, 0xA2C, BIT15, 0x0);//reset  CCK FA counter
11505                 write_bbreg(padapter, 0xA2C, BIT15, 0x1);
11506         }
11507         //reset mac counter
11508         PHY_SetMacReg(padapter, 0x664, BIT27, 0x1); 
11509         PHY_SetMacReg(padapter, 0x664, BIT27, 0x0);
11510         return 0;
11511 }
11512
11513 static int rtw_mp_dump(struct net_device *dev,
11514                         struct iw_request_info *info,
11515                         struct iw_point *wrqu, char *extra)
11516 {
11517         struct mp_priv *pmp_priv;
11518         struct pkt_attrib *pattrib;
11519         u32 value;
11520     u8          input[wrqu->length];
11521         u8 rf_type,path_nums = 0;
11522         u32 i,j=1,path;
11523         PADAPTER padapter = rtw_netdev_priv(dev);
11524         
11525         pmp_priv = &padapter->mppriv;
11526
11527         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11528                 return -EFAULT;
11529         
11530         if ( strncmp(input, "all", 4)==0 )
11531         {
11532                 mac_reg_dump(RTW_DBGDUMP, padapter);
11533                 bb_reg_dump(RTW_DBGDUMP, padapter);
11534                 rf_reg_dump(RTW_DBGDUMP, padapter);
11535         }
11536         return 0;
11537 }
11538
11539 static int rtw_mp_phypara(struct net_device *dev,
11540                         struct iw_request_info *info,
11541                         struct iw_point *wrqu, char *extra)
11542 {
11543
11544         PADAPTER padapter = rtw_netdev_priv(dev);
11545         HAL_DATA_TYPE   *pHalData       = GET_HAL_DATA(padapter);
11546         char    input[wrqu->length];
11547         u32             valxcap;
11548         
11549         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11550                         return -EFAULT;
11551         
11552         DBG_871X("%s:iwpriv in=%s\n", __func__, input);
11553         
11554         sscanf(input, "xcap=%d", &valxcap);
11555
11556         pHalData->CrystalCap = (u8)valxcap;
11557         Hal_ProSetCrystalCap( padapter , valxcap );
11558
11559         sprintf( extra, "Set xcap=%d",valxcap );
11560         wrqu->length = strlen(extra) + 1;
11561         
11562 return 0;
11563
11564 }
11565
11566 static int rtw_mp_SetRFPath(struct net_device *dev,
11567                         struct iw_request_info *info,
11568                         union iwreq_data *wrqu, char *extra)
11569 {
11570         PADAPTER padapter = rtw_netdev_priv(dev);
11571         char    input[wrqu->data.length];
11572         s32             bMain=1,bTurnoff=1;
11573         
11574         if (copy_from_user(input, wrqu->data.pointer, wrqu->data.length))
11575                         return -EFAULT;
11576         DBG_871X("%s:iwpriv in=%s\n", __func__, input); 
11577         
11578         bMain = strncmp(input, "1", 2); // strncmp TRUE is 0
11579         bTurnoff = strncmp(input, "0", 3); // strncmp TRUE is 0
11580
11581         if(bMain==0)
11582         {
11583                 MP_PHY_SetRFPathSwitch(padapter,_TRUE);
11584                 DBG_871X("%s:PHY_SetRFPathSwitch=TRUE\n", __func__);    
11585         }
11586         else if(bTurnoff==0)
11587         {
11588                 MP_PHY_SetRFPathSwitch(padapter,_FALSE);
11589                 DBG_871X("%s:PHY_SetRFPathSwitch=FALSE\n", __func__);   
11590         }
11591         
11592         return 0;
11593 }
11594
11595 static int rtw_mp_QueryDrv(struct net_device *dev,
11596                         struct iw_request_info *info,
11597                         union iwreq_data *wrqu, char *extra)
11598 {
11599         PADAPTER padapter = rtw_netdev_priv(dev);
11600         char    input[wrqu->data.length];
11601         s32     qAutoLoad=1;
11602
11603         EEPROM_EFUSE_PRIV *pEEPROM = GET_EEPROM_EFUSE_PRIV(padapter);
11604         
11605         if (copy_from_user(input, wrqu->data.pointer, wrqu->data.length))
11606                         return -EFAULT;
11607         DBG_871X("%s:iwpriv in=%s\n", __func__, input); 
11608         
11609         qAutoLoad = strncmp(input, "autoload", 8); // strncmp TRUE is 0
11610
11611         if(qAutoLoad==0)
11612         {
11613                 DBG_871X("%s:qAutoLoad\n", __func__);
11614                 
11615                 if(pEEPROM->bautoload_fail_flag)
11616                         sprintf(extra, "fail");
11617                 else
11618                 sprintf(extra, "ok");      
11619         }
11620                 wrqu->data.length = strlen(extra) + 1;
11621         return 0;
11622 }
11623
11624 /* update Tx AGC offset */
11625 static int rtw_mp_antBdiff(struct net_device *dev,
11626                         struct iw_request_info *info,
11627                         struct iw_point *wrqu, char *extra)
11628 {
11629
11630
11631         // MPT_ProSetTxAGCOffset
11632         return 0;
11633 }
11634
11635
11636 static int rtw_mp_PwrCtlDM(struct net_device *dev,
11637                         struct iw_request_info *info,
11638                         struct iw_point *wrqu, char *extra)
11639 {
11640         PADAPTER padapter = rtw_netdev_priv(dev);
11641         u8              input[wrqu->length];
11642         u8              bstart=1;
11643         
11644         if (copy_from_user(input, wrqu->pointer, wrqu->length))
11645                         return -EFAULT;
11646
11647         bstart = strncmp(input, "start", 5); // strncmp TRUE is 0
11648         if(bstart==0){
11649                 sprintf(extra, "PwrCtlDM start \n");
11650                 MPT_PwrCtlDM(padapter,1);
11651         }else{
11652                 sprintf(extra, "PwrCtlDM stop \n");
11653                 MPT_PwrCtlDM(padapter,0);
11654         }
11655         wrqu->length = strlen(extra);
11656
11657         return 0;
11658 }
11659
11660 #if (defined(CONFIG_RTL8723A) || defined(CONFIG_RTL8723B))
11661 /* update Tx AGC offset */
11662 static int rtw_mp_SetBT(struct net_device *dev,
11663                         struct iw_request_info *info,
11664                         union iwreq_data *wrqu, char *extra)
11665 {
11666         PADAPTER padapter = rtw_netdev_priv(dev);
11667         struct hal_ops *pHalFunc = &padapter->HalFunc;
11668         HAL_DATA_TYPE   *pHalData = GET_HAL_DATA(padapter);
11669         
11670         BT_REQ_CMD      BtReq;
11671         PMPT_CONTEXT    pMptCtx=&(padapter->mppriv.MptCtx);
11672         PBT_RSP_CMD     pBtRsp=(PBT_RSP_CMD)&pMptCtx->mptOutBuf[0];
11673         char    input[128];
11674         char *pch, *ptmp, *token, *tmp[2]={0x00,0x00};
11675         u8 setdata[100];
11676         u8 resetbt=0x00;
11677         u8 tempval,BTStatus;
11678         u8 H2cSetbtmac[6];
11679         u8 u1H2CBtMpOperParm[4]={0x01};
11680         u16 testmode=1,ready=1,trxparam=1,setgen=1,getgen=1,testctrl=1,testbt=1,readtherm=1,setbtmac=1;
11681         u32 i=0,ii=0,jj=0,kk=0,cnts=0,status=0;
11682         PRT_MP_FIRMWARE pBTFirmware = NULL;
11683         
11684         if (copy_from_user(extra, wrqu->data.pointer, wrqu->data.length))
11685                         return -EFAULT;
11686         if(strlen(extra)<1) return -EFAULT;
11687         
11688         DBG_871X("%s:iwpriv in=%s\n", __FUNCTION__, extra); 
11689         ready = strncmp(extra, "ready", 5); 
11690         testmode = strncmp(extra, "testmode", 8); // strncmp TRUE is 0
11691         trxparam = strncmp(extra, "trxparam", 8); 
11692         setgen = strncmp(extra, "setgen", 6);
11693         getgen = strncmp(extra, "getgen", 6); 
11694         testctrl = strncmp(extra, "testctrl", 8);
11695         testbt = strncmp(extra, "testbt", 6);
11696         readtherm = strncmp(extra, "readtherm", 9);
11697         setbtmac = strncmp(extra, "setbtmac", 8);
11698
11699         if ( strncmp(extra, "dlbt", 4) == 0)
11700         {
11701                 pHalData->LastHMEBoxNum=0;
11702                 padapter->bBTFWReady = _FALSE;
11703                 rtw_write8(padapter, 0xa3, 0x05);
11704                 BTStatus=rtw_read8(padapter, 0xa0);
11705                 DBG_871X("%s: btwmap before read 0xa0 BT Status =0x%x \n", __FUNCTION__,BTStatus);
11706                 if (BTStatus != 0x04)
11707                 {
11708                         sprintf(extra, "BT Status not Active DLFW FAIL\n");
11709                         goto exit;
11710                 }
11711
11712                 tempval = rtw_read8(padapter, 0x6B);
11713                 tempval |= BIT7;
11714                 rtw_write8(padapter, 0x6B, tempval);
11715
11716                 // Attention!! Between 0x6A[14] and 0x6A[15] setting need 100us delay
11717                 // So don't wirte 0x6A[14]=1 and 0x6A[15]=0 together!
11718                 rtw_usleep_os(100);
11719                 // disable BT power cut
11720                 // 0x6A[14] = 0
11721                 tempval = rtw_read8(padapter, 0x6B);
11722                 tempval &= ~BIT6;
11723                 rtw_write8(padapter, 0x6B, tempval);
11724                 rtw_usleep_os(100);
11725                 MPT_PwrCtlDM(padapter,0);
11726                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)| 0x00000004));
11727                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)& 0xFFFFFFEF));
11728                 rtw_msleep_os(600);
11729                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)| 0x00000010));
11730                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)& 0xFFFFFFFB));
11731                 rtw_msleep_os(1200);            
11732                 pBTFirmware = (PRT_MP_FIRMWARE)rtw_zmalloc(sizeof(RT_MP_FIRMWARE));
11733                 if(pBTFirmware==NULL)
11734                         goto exit;
11735                 padapter->bBTFWReady = _FALSE;
11736                 FirmwareDownloadBT(padapter, pBTFirmware);
11737                 if (pBTFirmware)
11738                         rtw_mfree((u8*)pBTFirmware, sizeof(RT_MP_FIRMWARE));
11739                         
11740                 DBG_871X("Wait for FirmwareDownloadBT fw boot!\n");
11741                 rtw_msleep_os(2000);
11742                 _rtw_memset(extra,'\0', wrqu->data.length);
11743                 BtReq.opCodeVer = 1;
11744                 BtReq.OpCode = 0;
11745                 BtReq.paraLength = 0;
11746                 mptbt_BtControlProcess(padapter, &BtReq);
11747                 rtw_msleep_os(100);
11748
11749                 DBG_8192C("FirmwareDownloadBT ready = 0x%x 0x%x", pMptCtx->mptOutBuf[4],pMptCtx->mptOutBuf[5]);
11750                 if( (pMptCtx->mptOutBuf[4]==0x00) && (pMptCtx->mptOutBuf[5]==0x00))
11751                         {
11752                                 if(padapter->mppriv.bTxBufCkFail==_TRUE)
11753                                         sprintf(extra, "check TxBuf Fail.\n");
11754                                 else
11755                                         sprintf(extra, "download FW Fail.\n");
11756                         }
11757                         else
11758                         {
11759                                 sprintf(extra, "download FW OK.\n");
11760                                 goto exit;
11761                         }
11762                 goto exit;
11763                 goto exit;      
11764         }
11765         if ( strncmp(extra, "dlfw", 4) == 0)
11766         {
11767                 #ifdef CONFIG_BT_COEXIST
11768                 rtw_btcoex_HaltNotify(padapter);
11769                 //DBG_871X("SetBT bt1ant !\n");
11770                 //hal_btcoex1ant_SetAntPath(padapter);
11771                 rtw_btcoex_SetManualControl(padapter, _TRUE);
11772                 #endif
11773                 pHalData->LastHMEBoxNum=0;
11774                 padapter->bBTFWReady = _FALSE;
11775                 rtw_write8(padapter, 0xa3, 0x05);
11776                 BTStatus=rtw_read8(padapter, 0xa0);
11777                 DBG_871X("%s: btwmap before read 0xa0 BT Status =0x%x \n", __FUNCTION__,BTStatus);
11778                 if (BTStatus != 0x04)
11779                 {
11780                         sprintf(extra, "BT Status not Active DLFW FAIL\n");
11781                         goto exit;
11782                 }
11783
11784                 tempval = rtw_read8(padapter, 0x6B);
11785                 tempval |= BIT7;
11786                 rtw_write8(padapter, 0x6B, tempval);
11787
11788                 // Attention!! Between 0x6A[14] and 0x6A[15] setting need 100us delay
11789                 // So don't wirte 0x6A[14]=1 and 0x6A[15]=0 together!
11790                 rtw_usleep_os(100);
11791                 // disable BT power cut
11792                 // 0x6A[14] = 0
11793                 tempval = rtw_read8(padapter, 0x6B);
11794                 tempval &= ~BIT6;
11795                 rtw_write8(padapter, 0x6B, tempval);
11796                 rtw_usleep_os(100);
11797         
11798                 MPT_PwrCtlDM(padapter,0);
11799                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)| 0x00000004));
11800                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)& 0xFFFFFFEF));
11801                 rtw_msleep_os(600);
11802                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)| 0x00000010));
11803                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)& 0xFFFFFFFB));
11804                 rtw_msleep_os(1200);
11805
11806 #if defined(CONFIG_PLATFORM_SPRD) && (MP_DRIVER == 1)
11807                 // Pull up BT reset pin.
11808                 DBG_871X("%s: pull up BT reset pin when bt start mp test\n", __FUNCTION__);
11809                 rtw_wifi_gpio_wlan_ctrl(WLAN_BT_PWDN_ON);
11810 #endif
11811                 DBG_871X(" rtl8723a_FirmwareDownload!\n");
11812
11813 #ifdef CONFIG_RTL8723A
11814                 status = rtl8723a_FirmwareDownload(padapter);
11815 #elif defined(CONFIG_RTL8723B)
11816                 status = rtl8723b_FirmwareDownload(padapter, _FALSE);
11817 #endif
11818                 DBG_871X("Wait for FirmwareDownloadBT fw boot!\n");
11819                 rtw_msleep_os(1000);
11820                 _rtw_memset(extra,'\0', wrqu->data.length);
11821                 BtReq.opCodeVer = 1;
11822                 BtReq.OpCode = 0;
11823                 BtReq.paraLength = 0;
11824                 mptbt_BtControlProcess(padapter, &BtReq);
11825                 rtw_msleep_os(200);
11826
11827                 DBG_8192C("FirmwareDownloadBT ready = 0x%x 0x%x", pMptCtx->mptOutBuf[4],pMptCtx->mptOutBuf[5]);
11828                 if( (pMptCtx->mptOutBuf[4]==0x00) && (pMptCtx->mptOutBuf[5]==0x00))
11829                         {
11830                                 if(padapter->mppriv.bTxBufCkFail==_TRUE)
11831                                         sprintf(extra, "check TxBuf Fail.\n");
11832                                 else
11833                                         sprintf(extra, "download FW Fail.\n");
11834                         }
11835                         else
11836                         {
11837                                 #ifdef CONFIG_BT_COEXIST
11838                                 rtw_btcoex_SwitchGntBt(padapter);
11839                                 #endif
11840                                 rtw_msleep_os(200);
11841                                 sprintf(extra, "download FW OK.\n");
11842                                 goto exit;
11843                         }
11844                 goto exit;
11845         }
11846
11847         if ( strncmp(extra, "down", 4) == 0){
11848                 DBG_871X("SetBT down for to hal_init !\n");
11849                 mp_stop_test(padapter);
11850                 pHalFunc->hal_init(padapter);
11851                 mp_start_test(padapter);
11852                 MPT_PwrCtlDM(padapter,0);
11853                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)| 0x00000004));
11854                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)& 0xFFFFFFEF));
11855                 rtw_msleep_os(600);
11856                         //rtw_write32(padapter, 0x6a, (rtw_read32(padapter, 0x6a)& 0xFFFFFFFE));
11857                 rtw_write32(padapter, 0x6b, (rtw_read32(padapter, 0x6b)| 0x00000010));
11858                 rtw_write32(padapter, 0xcc, (rtw_read32(padapter, 0xcc)& 0xFFFFFFFB));
11859                 rtw_msleep_os(1200);
11860                 goto exit;
11861         }
11862         if ( strncmp(extra, "disable", 7) == 0){
11863                 DBG_871X("SetBT disable !\n");
11864                 rtw_write32(padapter, 0x6a, (rtw_read32(padapter, 0x6a)& 0xFFFFFFFB));
11865                 rtw_msleep_os(500);
11866                 goto exit;
11867                 }
11868         if ( strncmp(extra, "enable", 6) == 0){
11869                 DBG_871X("SetBT enable !\n");
11870                 rtw_write32(padapter, 0x6a, (rtw_read32(padapter, 0x6a)| 0x00000004));
11871                 rtw_msleep_os(500);
11872                 goto exit;
11873         }
11874         if ( strncmp(extra, "h2c", 3) == 0){
11875                         DBG_871X("SetBT h2c !\n");
11876                         padapter->bBTFWReady = _TRUE;
11877                         FillH2CCmd(padapter, 0x63, 1, u1H2CBtMpOperParm);
11878                         goto exit;
11879                 }
11880         if ( strncmp(extra, "2ant", 4) == 0){
11881                 DBG_871X("Set BT 2ant use!\n");
11882                 PHY_SetMacReg(padapter,0x67,BIT5,0x1);
11883                 rtw_write32(padapter, 0x948, 0000);
11884                 
11885                 goto exit;
11886         }
11887                 
11888         if( ready!=0 && testmode!=0 && trxparam!=0 && setgen!=0 && getgen!=0 && testctrl!=0 && testbt!=0 && readtherm!=0 &&setbtmac!=0)
11889                 return -EFAULT;
11890                 
11891         if( testbt==0 )
11892         {
11893                         BtReq.opCodeVer=1;
11894                         BtReq.OpCode=6;
11895                         BtReq.paraLength=cnts/2;
11896                         goto todo;
11897         }
11898         if( ready==0 )
11899         {
11900                 BtReq.opCodeVer=1;
11901                 BtReq.OpCode=0;
11902                 BtReq.paraLength=0; 
11903                 goto todo;
11904         }
11905
11906         pch = extra;    
11907         i = 0;
11908         while ((token = strsep(&pch, ",")) != NULL)
11909         {
11910                 if (i > 1) break;
11911                 tmp[i] = token;
11912                 i++;
11913         }
11914
11915         if ((tmp[0]==NULL) && (tmp[1]==NULL))
11916         {
11917                 return -EFAULT;
11918         }
11919         else
11920         {
11921                 cnts = strlen(tmp[1]);
11922                 if (cnts<1) return -EFAULT;
11923         
11924                 DBG_871X("%s: cnts=%d\n", __FUNCTION__, cnts);
11925                 DBG_871X("%s: data=%s\n", __FUNCTION__, tmp[1]);
11926                                 
11927                 for (jj=0, kk=0; jj<cnts; jj++, kk+=2)
11928                 {
11929                         BtReq.pParamStart[jj] = key_2char2num(tmp[1][kk], tmp[1][kk+1]);
11930 //                      DBG_871X("BtReq.pParamStart[%d]=0x%02x\n", jj, BtReq.pParamStart[jj]);
11931                 }
11932         }
11933         
11934         if( testmode==0 )       
11935         {
11936                 BtReq.opCodeVer=1;
11937                 BtReq.OpCode=1;
11938                 BtReq.paraLength=1; 
11939         }
11940         if( trxparam==0 )
11941         {
11942                 BtReq.opCodeVer=1;
11943                 BtReq.OpCode=2;
11944                 BtReq.paraLength=cnts/2; 
11945         }
11946         if( setgen==0 )
11947         {       
11948                 DBG_871X("%s: BT_SET_GENERAL \n", __func__); 
11949                 BtReq.opCodeVer=1;
11950                 BtReq.OpCode=3; //BT_SET_GENERAL        3
11951                 BtReq.paraLength=cnts/2;        
11952         }
11953         if( getgen==0 )
11954         {       
11955                 DBG_871X("%s: BT_GET_GENERAL \n", __func__); 
11956                 BtReq.opCodeVer=1;
11957                 BtReq.OpCode=4;         //BT_GET_GENERAL        4
11958                 BtReq.paraLength=cnts/2;        
11959         }
11960         if( readtherm==0 )
11961         {       
11962                 DBG_871X("%s: BT_GET_GENERAL \n", __func__); 
11963                 BtReq.opCodeVer=1;
11964                 BtReq.OpCode=4;         //BT_GET_GENERAL        4
11965                 BtReq.paraLength=cnts/2;        
11966         }
11967         
11968         if( testctrl==0 )
11969         {       
11970                 DBG_871X("%s: BT_TEST_CTRL \n", __func__);
11971                 BtReq.opCodeVer=1;
11972                 BtReq.OpCode=5;         //BT_TEST_CTRL  5
11973                 BtReq.paraLength=cnts/2;        
11974         }
11975
11976         DBG_871X("%s: Req opCodeVer=%d OpCode=%d paraLength=%d\n",
11977                 __FUNCTION__, BtReq.opCodeVer, BtReq.OpCode, BtReq.paraLength);
11978
11979         if(BtReq.paraLength<1)
11980                 goto todo;
11981         for (i=0; i<BtReq.paraLength; i++)
11982         {
11983                 DBG_871X("%s: BtReq.pParamStart[%d] = 0x%02x \n",
11984                         __FUNCTION__, i, BtReq.pParamStart[i]);
11985         }
11986         
11987 todo:
11988         _rtw_memset(extra,'\0', wrqu->data.length);
11989
11990         if (padapter->bBTFWReady == _FALSE)
11991         {
11992                 sprintf(extra, "BTFWReady = FALSE.\n");
11993                 goto exit;
11994         }
11995
11996         mptbt_BtControlProcess(padapter, &BtReq);
11997
11998         if (readtherm == 0)
11999         {
12000                 sprintf(extra, "BT thermal=");
12001                 for (i=4; i<pMptCtx->mptOutLen; i++)
12002                 {
12003                         if ((pMptCtx->mptOutBuf[i]==0x00) && (pMptCtx->mptOutBuf[i+1]==0x00))
12004                                 goto exit;
12005
12006 #ifdef CONFIG_RTL8723A
12007                         sprintf(extra, "%s %d ", extra, (pMptCtx->mptOutBuf[i]& 0x3f));
12008 #else
12009                         sprintf(extra, "%s %d ", extra, (pMptCtx->mptOutBuf[i]& 0x1f));
12010 #endif
12011                 }
12012         }
12013         else
12014         {
12015                 for (i=4; i<pMptCtx->mptOutLen; i++)
12016                 {
12017                         sprintf(extra, "%s 0x%x ", extra, pMptCtx->mptOutBuf[i]);
12018                 }
12019         }
12020         
12021 exit:
12022         wrqu->data.length = strlen(extra) + 1;
12023         DBG_871X("-%s: output len=%d data=%s\n", __FUNCTION__, wrqu->data.length, extra);
12024
12025         return status;
12026 }
12027
12028 #endif //#ifdef CONFIG_RTL8723A
12029
12030 static int rtw_mp_set(struct net_device *dev,
12031                         struct iw_request_info *info,
12032                         union iwreq_data *wdata, char *extra)
12033 {
12034         struct iw_point *wrqu = (struct iw_point *)wdata;
12035         u32 subcmd = wrqu->flags;
12036         PADAPTER padapter = rtw_netdev_priv(dev);
12037
12038         if (padapter == NULL)
12039         {
12040                 return -ENETDOWN;
12041         }
12042
12043         if((padapter->bup == _FALSE ))
12044         {
12045                 DBG_871X(" %s fail =>(padapter->bup == _FALSE )\n",__FUNCTION__);
12046                 return -ENETDOWN;
12047         }
12048
12049         if( (padapter->bSurpriseRemoved == _TRUE) || ( padapter->bDriverStopped == _TRUE))
12050        {        
12051         DBG_871X("%s fail =>(padapter->bSurpriseRemoved == _TRUE) || ( padapter->bDriverStopped == _TRUE) \n",__FUNCTION__);
12052              return -ENETDOWN;
12053        }
12054
12055         
12056         //_rtw_memset(extra, 0x00, IW_PRIV_SIZE_MASK);
12057
12058         if (extra == NULL)
12059         {
12060                 wrqu->length = 0;
12061                 return -EIO;
12062         }
12063
12064         switch(subcmd)
12065         {
12066         case MP_START:
12067                         DBG_871X("set case mp_start \n");
12068                         rtw_mp_start (dev,info,wrqu,extra);
12069                          break; 
12070                          
12071         case MP_STOP:
12072                         DBG_871X("set case mp_stop \n");
12073                         rtw_mp_stop (dev,info,wrqu,extra);
12074                          break; 
12075                          
12076         case MP_BANDWIDTH:
12077                         DBG_871X("set case mp_bandwidth \n");
12078                         rtw_mp_bandwidth (dev,info,wrqu,extra);
12079                         break;
12080                                 
12081         case MP_RESET_STATS:
12082                         DBG_871X("set case MP_RESET_STATS \n");
12083                         rtw_mp_reset_stats      (dev,info,wrqu,extra);
12084                         break;
12085         case MP_SetRFPathSwh:           
12086                         DBG_871X("set MP_SetRFPathSwitch \n");
12087                         rtw_mp_SetRFPath  (dev,info,wdata,extra);
12088                         break;
12089         case CTA_TEST:
12090                         DBG_871X("set CTA_TEST\n");
12091                         rtw_cta_test_start (dev, info, wdata, extra);
12092                         break;
12093         case MP_DISABLE_BT_COEXIST:
12094                         DBG_871X("set case MP_DISABLE_BT_COEXIST \n");
12095                         rtw_mp_disable_bt_coexist(dev, info, wdata, extra);
12096                 break;
12097 #ifdef CONFIG_AP_WOWLAN
12098         case MP_AP_WOW_ENABLE:
12099                         DBG_871X("set case MP_AP_WOW_ENABLE: %s \n", extra);
12100                         rtw_ap_wowlan_ctrl(dev, info, wdata, extra);
12101         break;
12102 #endif
12103         }
12104
12105           
12106         return 0;               
12107 }
12108
12109
12110 static int rtw_mp_get(struct net_device *dev,
12111                         struct iw_request_info *info,
12112                         union iwreq_data *wdata, char *extra)
12113 {
12114         struct iw_point *wrqu = (struct iw_point *)wdata;
12115         u32 subcmd = wrqu->flags;
12116         PADAPTER padapter = rtw_netdev_priv(dev);
12117
12118         //DBG_871X("in mp_get extra= %s \n",extra);
12119
12120         if (padapter == NULL)
12121         {
12122                 return -ENETDOWN;
12123         }
12124         if((padapter->bup == _FALSE ))
12125         {
12126                 DBG_871X(" %s fail =>(padapter->bup == _FALSE )\n",__FUNCTION__);
12127                 return -ENETDOWN;
12128         }
12129
12130         if( (padapter->bSurpriseRemoved == _TRUE) || ( padapter->bDriverStopped == _TRUE))
12131        {        
12132         DBG_871X("%s fail =>(padapter->bSurpriseRemoved == _TRUE) || ( padapter->bDriverStopped == _TRUE) \n",__FUNCTION__);
12133              return -ENETDOWN;
12134        }
12135         
12136         if (extra == NULL)
12137         {
12138                 wrqu->length = 0;
12139                 return -EIO;
12140         }
12141         
12142         switch(subcmd)
12143         {
12144         case WRITE_REG :
12145                         rtw_mp_write_reg (dev,info,wrqu,extra);
12146                          break;
12147                          
12148         case WRITE_RF:
12149                         rtw_mp_write_rf (dev,info,wrqu,extra);
12150                          break; 
12151                          
12152         case MP_PHYPARA:
12153                         DBG_871X("mp_get  MP_PHYPARA \n");
12154                         rtw_mp_phypara(dev,info,wrqu,extra);    
12155                         break;
12156
12157         case MP_CHANNEL:
12158                         DBG_871X("set case mp_channel \n");
12159                         rtw_mp_channel (dev,info,wrqu,extra);
12160                         break;
12161                         
12162         case READ_REG:
12163                         DBG_871X("mp_get  READ_REG \n");
12164                         rtw_mp_read_reg (dev,info,wrqu,extra);
12165                          break; 
12166         case READ_RF:
12167                         DBG_871X("mp_get  READ_RF \n");
12168                         rtw_mp_read_rf (dev,info,wrqu,extra);
12169                         break; 
12170                         
12171         case MP_RATE:
12172                         DBG_871X("set case mp_rate \n");
12173                         rtw_mp_rate (dev,info,wrqu,extra);
12174                         break;
12175                         
12176         case MP_TXPOWER:
12177                         DBG_871X("set case MP_TXPOWER \n");
12178                         rtw_mp_txpower (dev,info,wrqu,extra);
12179                         break;
12180                         
12181         case MP_ANT_TX:
12182                         DBG_871X("set case MP_ANT_TX \n");
12183                         rtw_mp_ant_tx (dev,info,wrqu,extra);
12184                         break;
12185                         
12186         case MP_ANT_RX:
12187                         DBG_871X("set case MP_ANT_RX \n");
12188                         rtw_mp_ant_rx (dev,info,wrqu,extra);
12189                         break;
12190                         
12191         case MP_QUERY:
12192                         //DBG_871X("mp_get mp_query MP_QUERY \n");
12193                         rtw_mp_trx_query(dev,info,wrqu,extra);
12194                         break;
12195                                         
12196         case MP_CTX:
12197                         DBG_871X("set case MP_CTX \n");
12198                         rtw_mp_ctx (dev,info,wrqu,extra);
12199                         break;
12200                         
12201         case MP_ARX:
12202                         DBG_871X("set case MP_ARX \n");
12203                         rtw_mp_arx (dev,info,wrqu,extra);
12204                         break;
12205                         
12206         case EFUSE_GET:
12207                         DBG_871X("efuse get EFUSE_GET \n");
12208                         rtw_mp_efuse_get(dev,info,wdata,extra);
12209                  break; 
12210                  
12211         case MP_DUMP:
12212                         DBG_871X("set case MP_DUMP \n");
12213                         rtw_mp_dump (dev,info,wrqu,extra);
12214                  break; 
12215         case MP_PSD:
12216                         DBG_871X("set case MP_PSD \n");
12217                         rtw_mp_psd (dev,info,wrqu,extra);
12218                  break;
12219         case MP_THER:
12220                         DBG_871X("set case MP_THER \n");
12221                         rtw_mp_thermal (dev,info,wrqu,extra);
12222                 break;
12223         case MP_PwrCtlDM:
12224                         DBG_871X("set MP_PwrCtlDM\n");
12225                         rtw_mp_PwrCtlDM (dev,info,wrqu,extra);
12226                 break;
12227         case MP_QueryDrvStats:          
12228                         DBG_871X("mp_get MP_QueryDrvStats \n");
12229                         rtw_mp_QueryDrv(dev,info,wdata,extra);
12230                         break;
12231                 case MP_PWRTRK:
12232                         DBG_871X("set case MP_PWRTRK \n");
12233                         rtw_mp_pwrtrk(dev,info,wrqu,extra);
12234                         break;                   
12235         case EFUSE_SET:
12236                         DBG_871X("set case efuse set \n");
12237                         rtw_mp_efuse_set(dev,info,wdata,extra);
12238                         break;                   
12239         case MP_GET_TXPOWER_INX:
12240                         DBG_871X("mp_get MP_GET_TXPOWER_INX \n");
12241                         rtw_mp_txpower_index(dev,info,wrqu,extra);
12242                 break;
12243
12244 #if defined(CONFIG_RTL8723A) || defined(CONFIG_RTL8723B)
12245         case MP_SetBT:          
12246                         DBG_871X("set MP_SetBT \n");
12247                         rtw_mp_SetBT(dev,info,wdata,extra);
12248                         break;           
12249 #endif
12250
12251         }
12252
12253         rtw_msleep_os(10); //delay 5ms for sending pkt before exit adb shell operation
12254 return 0;       
12255 }
12256
12257 #endif //#if defined(CONFIG_MP_INCLUDED) && defined(CONFIG_MP_IWPRIV_SUPPORT)
12258
12259 static int rtw_wfd_tdls_enable(struct net_device *dev,
12260                                 struct iw_request_info *info,
12261                                 union iwreq_data *wrqu, char *extra)
12262 {
12263         int ret = 0;
12264
12265 #ifdef CONFIG_TDLS
12266 #ifdef CONFIG_WFD
12267
12268         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12269
12270         printk( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12271
12272         if ( extra[ 0 ] == '0' )
12273         {
12274                 padapter->wdinfo.wfd_tdls_enable = 0;
12275         }
12276         else
12277         {
12278                 padapter->wdinfo.wfd_tdls_enable = 1;
12279         }
12280
12281 #endif //CONFIG_WFD
12282 #endif //CONFIG_TDLS
12283         
12284         return ret;
12285 }
12286
12287 static int rtw_tdls_weaksec(struct net_device *dev,
12288                                 struct iw_request_info *info,
12289                                 union iwreq_data *wrqu, char *extra)
12290 {
12291         int ret = 0;
12292
12293 #ifdef CONFIG_TDLS
12294
12295         u8 i, j;
12296         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12297
12298         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12299
12300         if ( extra[ 0 ] == '0' )
12301         {
12302                 padapter->wdinfo.wfd_tdls_weaksec = 0;
12303         }
12304         else
12305         {
12306                 padapter->wdinfo.wfd_tdls_weaksec = 1;
12307         }
12308 #endif
12309         
12310         return ret;
12311 }
12312
12313
12314 static int rtw_tdls_enable(struct net_device *dev,
12315                                 struct iw_request_info *info,
12316                                 union iwreq_data *wrqu, char *extra)
12317 {
12318         int ret = 0;
12319
12320 #ifdef CONFIG_TDLS
12321
12322         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12323         struct tdls_info        *ptdlsinfo = &padapter->tdlsinfo;
12324         _irqL    irqL;
12325         _list   *plist, *phead;
12326         s32     index;
12327         struct sta_info *psta = NULL;
12328         struct  sta_priv *pstapriv = &padapter->stapriv;
12329         u8 tdls_sta[NUM_STA][ETH_ALEN];
12330         u8 empty_hwaddr[ETH_ALEN] = { 0x00 };
12331         struct tdls_txmgmt txmgmt;
12332
12333         printk( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12334
12335         _rtw_memset(tdls_sta, 0x00, sizeof(tdls_sta));
12336         _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
12337
12338         if ( extra[ 0 ] == '0' )
12339         {
12340                 ptdlsinfo->tdls_enable = 0;
12341
12342                 if(pstapriv->asoc_sta_count==1)
12343                         return ret;
12344
12345                 _enter_critical_bh(&pstapriv->sta_hash_lock, &irqL);
12346                 for(index=0; index< NUM_STA; index++)
12347                 {
12348                         phead = &(pstapriv->sta_hash[index]);
12349                         plist = get_next(phead);
12350                         
12351                         while ((rtw_end_of_queue_search(phead, plist)) == _FALSE)
12352                         {
12353                                 psta = LIST_CONTAINOR(plist, struct sta_info ,hash_list);
12354
12355                                 plist = get_next(plist);
12356
12357                                 if(psta->tdls_sta_state != TDLS_STATE_NONE)
12358                                 {
12359                                         _rtw_memcpy(tdls_sta[index], psta->hwaddr, ETH_ALEN);
12360                                 }
12361                         }
12362                 }
12363                 _exit_critical_bh(&pstapriv->sta_hash_lock, &irqL);
12364
12365                 for(index=0; index< NUM_STA; index++)
12366                 {
12367                         if( !_rtw_memcmp(tdls_sta[index], empty_hwaddr, ETH_ALEN) )
12368                         {
12369                                 printk("issue tear down to "MAC_FMT"\n", MAC_ARG(tdls_sta[index]));
12370                                 txmgmt.status_code = _RSON_TDLS_TEAR_UN_RSN_;
12371                                 _rtw_memcpy(txmgmt.peer, tdls_sta[index], ETH_ALEN);
12372                                 issue_tdls_teardown(padapter, &txmgmt, _FALSE);
12373                         }
12374                 }
12375                 rtw_tdls_cmd(padapter, myid(&(padapter->eeprompriv)), TDLS_RS_RCR);
12376                 rtw_reset_tdls_info(padapter);
12377         }
12378         else if ( extra[ 0 ] == '1' )
12379         {
12380                 ptdlsinfo->tdls_enable = 1;
12381         }
12382 #endif //CONFIG_TDLS
12383         
12384         return ret;
12385 }
12386
12387 static int rtw_tdls_setup(struct net_device *dev,
12388                                 struct iw_request_info *info,
12389                                 union iwreq_data *wrqu, char *extra)
12390 {
12391         int ret = 0;
12392 #ifdef CONFIG_TDLS
12393         u8 i, j;
12394         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12395         struct tdls_txmgmt txmgmt;
12396 #ifdef CONFIG_WFD
12397         struct wifidirect_info *pwdinfo= &(padapter->wdinfo);
12398 #endif // CONFIG_WFD
12399
12400         printk( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12401
12402         if(wrqu->data.length - 1 != 17 )
12403         {
12404                 printk( "[%s] length:%d != 17\n", __FUNCTION__, (wrqu->data.length -1)  );
12405                 return ret;
12406         }
12407
12408         _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
12409         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
12410                 txmgmt.peer[i]=key_2char2num(*(extra+j), *(extra+j+1));
12411         }
12412
12413 #ifdef CONFIG_WFD
12414         if ( _AES_ != padapter->securitypriv.dot11PrivacyAlgrthm )
12415         {
12416                 //      Weak Security situation with AP.
12417                 if ( 0 == pwdinfo->wfd_tdls_weaksec )
12418                 {
12419                         //      Can't send the tdls setup request out!!
12420                         DBG_871X( "[%s] Current link is not AES, SKIP sending the tdls setup request!!\n", __FUNCTION__ );
12421                 }
12422                 else
12423                 {
12424                         issue_tdls_setup_req(padapter, &txmgmt, _TRUE);
12425                 }
12426         }
12427         else
12428 #endif // CONFIG_WFD
12429         {
12430                 issue_tdls_setup_req(padapter, &txmgmt, _TRUE);
12431         }
12432 #endif
12433         
12434         return ret;
12435 }
12436
12437 static int rtw_tdls_teardown(struct net_device *dev,
12438                                 struct iw_request_info *info,
12439                                 union iwreq_data *wrqu, char *extra)
12440 {
12441         int ret = 0;
12442
12443 #ifdef CONFIG_TDLS
12444
12445         u8 i,j;
12446         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12447         struct sta_info *ptdls_sta = NULL;
12448         struct tdls_txmgmt txmgmt;
12449
12450         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12451
12452         if(wrqu->data.length - 1 != 17 && wrqu->data.length - 1 != 19)
12453         {
12454                 printk( "[%s] length:%d != 17 or 19\n", __FUNCTION__, (wrqu->data.length -1)  );
12455                 return ret;
12456         }
12457
12458         _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
12459         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
12460                 txmgmt.peer[i]=key_2char2num(*(extra+j), *(extra+j+1));
12461         }
12462
12463         ptdls_sta = rtw_get_stainfo( &(padapter->stapriv), txmgmt.peer);
12464         
12465         if(ptdls_sta != NULL)
12466         {
12467                 txmgmt.status_code = _RSON_TDLS_TEAR_UN_RSN_;
12468                 if(wrqu->data.length - 1 == 17)
12469                         issue_tdls_teardown(padapter, &txmgmt, _FALSE);
12470                 else if(wrqu->data.length - 1 == 19)
12471                         issue_tdls_teardown(padapter, &txmgmt, _TRUE);
12472         }
12473         else
12474                 DBG_871X( "TDLS peer not found\n");
12475 #endif //CONFIG_TDLS
12476         
12477         return ret;
12478 }
12479
12480 static int rtw_tdls_discovery(struct net_device *dev,
12481                                 struct iw_request_info *info,
12482                                 union iwreq_data *wrqu, char *extra)
12483 {
12484         int ret = 0;
12485
12486 #ifdef CONFIG_TDLS
12487         
12488         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12489         struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);
12490         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
12491         struct tdls_txmgmt      txmgmt;
12492         int i = 0, j=0;
12493
12494         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12495
12496         _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));
12497         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
12498                 txmgmt.peer[i]=key_2char2num(*(extra+j), *(extra+j+1));
12499         }
12500
12501         issue_tdls_dis_req(padapter, &txmgmt);
12502
12503 #endif //CONFIG_TDLS
12504
12505         return ret;
12506 }
12507
12508 static int rtw_tdls_ch_switch(struct net_device *dev,
12509                                 struct iw_request_info *info,
12510                                 union iwreq_data *wrqu, char *extra)
12511 {
12512         int ret = 0;
12513
12514 #ifdef CONFIG_TDLS
12515         
12516         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12517         struct tdls_info        *ptdlsinfo = &padapter->tdlsinfo;
12518         u8 i, j, mac_addr[ETH_ALEN];
12519         struct sta_info *ptdls_sta = NULL;
12520
12521         DBG_8192C( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12522
12523         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
12524                 mac_addr[i]=key_2char2num(*(extra+j), *(extra+j+1));
12525         }
12526
12527         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
12528         if( ptdls_sta == NULL )
12529                 return ret;
12530
12531 //      ptdlsinfo->ch_sensing=1;
12532
12533 //      rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_INIT_CH_SEN);
12534
12535 #endif //CONFIG_TDLS
12536
12537                 return ret;
12538 }
12539         
12540 static int rtw_tdls_pson(struct net_device *dev,
12541                                 struct iw_request_info *info,
12542                                 union iwreq_data *wrqu, char *extra)
12543 {
12544         int ret = 0;
12545
12546 #ifdef CONFIG_TDLS
12547         
12548         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12549         struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);
12550         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
12551         u8 i, j, mac_addr[ETH_ALEN];
12552         struct sta_info *ptdls_sta = NULL;
12553
12554         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12555
12556         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
12557                 mac_addr[i]=key_2char2num(*(extra+j), *(extra+j+1));
12558         }
12559
12560         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
12561
12562         issue_nulldata_to_TDLS_peer_STA(padapter, ptdls_sta->hwaddr, 1, 3, 500);
12563
12564 #endif //CONFIG_TDLS
12565
12566                 return ret;
12567 }
12568         
12569 static int rtw_tdls_psoff(struct net_device *dev,
12570                                 struct iw_request_info *info,
12571                                 union iwreq_data *wrqu, char *extra)
12572 {
12573         int ret = 0;
12574
12575 #ifdef CONFIG_TDLS
12576         
12577         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12578         struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);
12579         struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);
12580         u8 i, j, mac_addr[ETH_ALEN];
12581         struct sta_info *ptdls_sta = NULL;
12582         
12583         DBG_8192C( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12584
12585         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
12586                 mac_addr[i]=key_2char2num(*(extra+j), *(extra+j+1));
12587         }
12588
12589         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
12590
12591         if(ptdls_sta)
12592         {
12593                 //issue_tdls_peer_traffic_rsp(padapter, ptdls_sta);
12594                 issue_nulldata_to_TDLS_peer_STA(padapter, ptdls_sta->hwaddr, 0, 3, 500);
12595         }
12596 #endif //CONFIG_TDLS
12597
12598         return ret;
12599 }
12600
12601 static int rtw_tdls_setip(struct net_device *dev,
12602                                 struct iw_request_info *info,
12603                                 union iwreq_data *wrqu, char *extra)
12604 {
12605         int ret = 0;
12606
12607 #ifdef CONFIG_TDLS
12608 #ifdef CONFIG_WFD
12609         
12610         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12611         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
12612         struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
12613         u8 i=0, j=0, k=0, tag=0, ip[3] = { 0xff }, *ptr = extra;
12614         
12615         printk( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length - 1  );
12616
12617
12618         while( i < 4 )
12619         {
12620                 for( j=0; j < 4; j++)
12621                 {
12622                         if( *( extra + j + tag ) == '.' || *( extra + j + tag ) == '\0' )
12623                         {
12624                                 if( j == 1 )
12625                                         pwfd_info->ip_address[i]=convert_ip_addr( '0', '0', *(extra+(j-1)+tag));
12626                                 if( j == 2 )
12627                                         pwfd_info->ip_address[i]=convert_ip_addr( '0', *(extra+(j-2)+tag), *(extra+(j-1)+tag));
12628                                 if( j == 3 )
12629                                         pwfd_info->ip_address[i]=convert_ip_addr( *(extra+(j-3)+tag), *(extra+(j-2)+tag), *(extra+(j-1)+tag));  
12630
12631                                 tag += j + 1;
12632                                 break;
12633                         }
12634                 }
12635                 i++;
12636         }
12637
12638         printk( "[%s] Set IP = %u.%u.%u.%u \n", __FUNCTION__, 
12639                 ptdlsinfo->wfd_info->ip_address[0], ptdlsinfo->wfd_info->ip_address[1],
12640                 ptdlsinfo->wfd_info->ip_address[2], ptdlsinfo->wfd_info->ip_address[3]
12641         );
12642
12643 #endif //CONFIG_WFD     
12644 #endif //CONFIG_TDLS
12645
12646         return ret;
12647 }
12648
12649 static int rtw_tdls_getip(struct net_device *dev,
12650                                 struct iw_request_info *info,
12651                                 union iwreq_data *wrqu, char *extra)
12652 {
12653         int ret = 0;
12654
12655 #ifdef CONFIG_TDLS
12656 #ifdef CONFIG_WFD
12657         
12658         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12659         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
12660         struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
12661         
12662         printk( "[%s]\n", __FUNCTION__);
12663
12664         sprintf( extra, "\n\n%u.%u.%u.%u\n", 
12665                 pwfd_info->peer_ip_address[0], pwfd_info->peer_ip_address[1], 
12666                 pwfd_info->peer_ip_address[2], pwfd_info->peer_ip_address[3]
12667                 );
12668
12669         printk( "[%s] IP=%u.%u.%u.%u\n", __FUNCTION__,
12670                 pwfd_info->peer_ip_address[0], pwfd_info->peer_ip_address[1], 
12671                 pwfd_info->peer_ip_address[2], pwfd_info->peer_ip_address[3]
12672                 );
12673         
12674         wrqu->data.length = strlen( extra );
12675
12676 #endif //CONFIG_WFD     
12677 #endif //CONFIG_TDLS
12678
12679         return ret;
12680 }
12681
12682 static int rtw_tdls_getport(struct net_device *dev,
12683                                struct iw_request_info *info,
12684                                union iwreq_data *wrqu, char *extra)
12685 {
12686         
12687         int ret = 0;    
12688
12689 #ifdef CONFIG_TDLS
12690 #ifdef CONFIG_WFD
12691
12692         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12693         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
12694         struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
12695
12696         printk( "[%s]\n", __FUNCTION__);
12697
12698         sprintf( extra, "\n\n%d\n", pwfd_info->peer_rtsp_ctrlport );
12699         printk( "[%s] remote port = %d\n", __FUNCTION__, pwfd_info->peer_rtsp_ctrlport );
12700         
12701         wrqu->data.length = strlen( extra );
12702
12703 #endif //CONFIG_WFD
12704 #endif //CONFIG_TDLS
12705
12706         return ret;
12707                 
12708 }
12709
12710 //WFDTDLS, for sigma test
12711 static int rtw_tdls_dis_result(struct net_device *dev,
12712                                struct iw_request_info *info,
12713                                union iwreq_data *wrqu, char *extra)
12714 {
12715         
12716         int ret = 0;    
12717
12718 #ifdef CONFIG_TDLS
12719 #ifdef CONFIG_WFD
12720
12721         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12722         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
12723         struct wifi_display_info *pwfd_info = ptdlsinfo->wfd_info;
12724
12725         printk( "[%s]\n", __FUNCTION__);
12726
12727         if(ptdlsinfo->dev_discovered == 1 )
12728         {
12729                 sprintf( extra, "\n\nDis=1\n" );
12730                 ptdlsinfo->dev_discovered = 0;
12731         }
12732         
12733         wrqu->data.length = strlen( extra );
12734
12735 #endif //CONFIG_WFD
12736 #endif //CONFIG_TDLS
12737
12738         return ret;
12739                 
12740 }
12741
12742 //WFDTDLS, for sigma test
12743 static int rtw_wfd_tdls_status(struct net_device *dev,
12744                                struct iw_request_info *info,
12745                                union iwreq_data *wrqu, char *extra)
12746 {
12747         
12748         int ret = 0;    
12749
12750 #ifdef CONFIG_TDLS
12751
12752         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12753         struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;
12754
12755         printk( "[%s]\n", __FUNCTION__);
12756
12757         sprintf( extra, "\nlink_established:0x%08x \n"
12758                 "sta_cnt:%d \n"
12759                 "sta_maximum:%d \n"
12760                 "cur_channel:%d \n"
12761                 "tdls_enable:%d",
12762                 ptdlsinfo->link_established, ptdlsinfo->sta_cnt, ptdlsinfo->sta_maximum,
12763                 ptdlsinfo->cur_channel, ptdlsinfo->tdls_enable
12764                 );
12765
12766         wrqu->data.length = strlen( extra );
12767
12768 #endif //CONFIG_TDLS
12769
12770         return ret;
12771                 
12772         }
12773
12774 static int rtw_tdls_getsta(struct net_device *dev,
12775                                struct iw_request_info *info,
12776                                union iwreq_data *wrqu, char *extra)
12777         {
12778         
12779         int ret = 0;
12780 #ifdef CONFIG_TDLS
12781         u8 i, j;
12782         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12783         u8 addr[ETH_ALEN] = {0};
12784         char charmac[17];
12785         struct sta_info *ptdls_sta = NULL;
12786
12787         printk( "[%s] %s %d\n", __FUNCTION__, (char *)wrqu->data.pointer, wrqu->data.length -1  );
12788
12789         if(copy_from_user(charmac, wrqu->data.pointer+9, 17)){
12790                 ret = -EFAULT;
12791                 goto exit;
12792         }
12793         
12794         printk("[%s] %d, charmac:%s\n", __FUNCTION__, __LINE__, charmac);
12795         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
12796                 addr[i]=key_2char2num(*(charmac+j), *(charmac+j+1));
12797         }
12798
12799         printk("[%s] %d, charmac:%s, addr:"MAC_FMT"\n", __FUNCTION__, __LINE__, charmac, MAC_ARG(addr));
12800         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, addr);  
12801         if(ptdls_sta) {
12802                 sprintf(extra, "\n\ntdls_sta_state=%d\n", ptdls_sta->tdls_sta_state);
12803                 printk("\n\ntdls_sta_state=%d\n", ptdls_sta->tdls_sta_state);
12804         }
12805         else {
12806                 sprintf(extra, "\n\nNot found this sta\n");
12807                 printk("\n\nNot found this sta\n");
12808         }
12809         wrqu->data.length = strlen( extra );
12810
12811 #endif //CONFIG_TDLS
12812 exit:
12813         return ret;
12814                 
12815 }
12816
12817 static int rtw_tdls_ch_switch_off(struct net_device *dev,
12818                                 struct iw_request_info *info,
12819                                 union iwreq_data *wrqu, char *extra)
12820 {
12821         int ret = 0;
12822
12823 #ifdef CONFIG_TDLS
12824         
12825         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12826         u8 i, j, mac_addr[ETH_ALEN];
12827         struct sta_info *ptdls_sta = NULL;
12828         
12829         DBG_871X( "[%s] %s %d\n", __FUNCTION__, extra, wrqu->data.length -1  );
12830
12831         for( i=0, j=0 ; i < ETH_ALEN; i++, j+=3 ){
12832                 mac_addr[i]=key_2char2num(*(extra+j), *(extra+j+1));
12833         }
12834
12835         ptdls_sta = rtw_get_stainfo(&padapter->stapriv, mac_addr);
12836
12837         ptdls_sta->tdls_sta_state |= TDLS_SW_OFF_STATE;
12838 /*
12839         if((ptdls_sta->tdls_sta_state & TDLS_AT_OFF_CH_STATE) && (ptdls_sta->tdls_sta_state & TDLS_PEER_AT_OFF_STATE)){
12840                 pmlmeinfo->tdls_candidate_ch= pmlmeext->cur_channel;
12841                 issue_tdls_ch_switch_req(padapter, mac_addr);
12842                 DBG_871X("issue tdls ch switch req back to base channel\n");
12843         }
12844 */
12845         
12846 #endif //CONFIG_TDLS
12847
12848         return ret;
12849 }
12850
12851 static int rtw_tdls(struct net_device *dev,
12852                                 struct iw_request_info *info,
12853                                 union iwreq_data *wrqu, char *extra)
12854 {
12855         int ret = 0;
12856
12857 #ifdef CONFIG_TDLS
12858         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12859
12860
12861
12862         DBG_871X( "[%s] extra = %s\n", __FUNCTION__, extra );
12863         //      WFD Sigma will use the tdls enable command to let the driver know we want to test the tdls now!
12864         if ( _rtw_memcmp( extra, "wfdenable=", 10 ) )
12865         {
12866                 wrqu->data.length -=10;
12867                 rtw_wfd_tdls_enable( dev, info, wrqu, &extra[10] );
12868                 return ret;
12869         }
12870         else if ( _rtw_memcmp( extra, "weaksec=", 8 ) )
12871         {
12872                 wrqu->data.length -=8;
12873                 rtw_tdls_weaksec( dev, info, wrqu, &extra[8] );
12874                 return ret;
12875         }
12876         else if ( _rtw_memcmp( extra, "tdlsenable=", 11 ) )
12877         {
12878                 wrqu->data.length -=11;
12879                 rtw_tdls_enable( dev, info, wrqu, &extra[11] );
12880                 return ret;
12881         }
12882
12883         if( padapter->tdlsinfo.tdls_enable == 0 )
12884         {
12885                 printk("tdls haven't enabled\n");
12886                 return 0;
12887         }
12888
12889         if ( _rtw_memcmp( extra, "setup=", 6 ) )
12890         {
12891                 wrqu->data.length -=6;
12892                 rtw_tdls_setup( dev, info, wrqu, &extra[6] );
12893         }
12894         else if (_rtw_memcmp( extra, "tear=", 5 ) )
12895         {
12896                 wrqu->data.length -= 5;
12897                 rtw_tdls_teardown( dev, info, wrqu, &extra[5] );
12898         }
12899         else if (_rtw_memcmp( extra, "dis=", 4 ) )
12900         {
12901                 wrqu->data.length -= 4;
12902                 rtw_tdls_discovery( dev, info, wrqu, &extra[4] );
12903         }
12904         else if (_rtw_memcmp( extra, "sw=", 3 ) )
12905         {
12906                 wrqu->data.length -= 3;
12907                 rtw_tdls_ch_switch( dev, info, wrqu, &extra[3] );
12908         }
12909         else if (_rtw_memcmp( extra, "swoff=", 6 ) )
12910         {
12911                 wrqu->data.length -= 6;
12912                 rtw_tdls_ch_switch_off( dev, info, wrqu, &extra[6] );
12913         }       
12914         else if (_rtw_memcmp( extra, "pson=", 5 ) )
12915         {
12916                 wrqu->data.length -= 5;
12917                 rtw_tdls_pson( dev, info, wrqu, &extra[5] );
12918         }
12919         else if (_rtw_memcmp( extra, "psoff=", 6 ) )
12920         {
12921                 wrqu->data.length -= 6;
12922                 rtw_tdls_psoff( dev, info, wrqu, &extra[6] );
12923         }
12924 #ifdef CONFIG_WFD
12925         else if (_rtw_memcmp( extra, "setip=", 6 ) )
12926         {
12927                 wrqu->data.length -= 6;
12928                 rtw_tdls_setip( dev, info, wrqu, &extra[6] );
12929         }
12930         else if (_rtw_memcmp( extra, "tprobe=", 6 ) )
12931         {
12932                 issue_tunneled_probe_req((_adapter *)rtw_netdev_priv(dev));
12933         }
12934 #endif //CONFIG_WFD
12935
12936 #endif //CONFIG_TDLS
12937         
12938         return ret;
12939 }
12940
12941
12942 static int rtw_tdls_get(struct net_device *dev,
12943                                 struct iw_request_info *info,
12944                                 union iwreq_data *wrqu, char *extra)
12945 {
12946         int ret = 0;
12947
12948 #ifdef CONFIG_WFD
12949
12950         DBG_871X( "[%s] extra = %s\n", __FUNCTION__, (char*) wrqu->data.pointer );
12951
12952         if ( _rtw_memcmp( wrqu->data.pointer, "ip", 2 ) )
12953         {
12954                 rtw_tdls_getip( dev, info, wrqu, extra );
12955         }
12956         if ( _rtw_memcmp( wrqu->data.pointer, "port", 4 ) )
12957         {
12958                 rtw_tdls_getport( dev, info, wrqu, extra );
12959         }
12960         //WFDTDLS, for sigma test
12961         if ( _rtw_memcmp( wrqu->data.pointer, "dis", 3 ) )
12962         {
12963                 rtw_tdls_dis_result( dev, info, wrqu, extra );
12964         }
12965         if ( _rtw_memcmp( wrqu->data.pointer, "status", 6 ) )
12966         {
12967                 rtw_wfd_tdls_status( dev, info, wrqu, extra );
12968         }
12969         if ( _rtw_memcmp( wrqu->data.pointer, "tdls_sta=", 9 ) )
12970         {
12971                 rtw_tdls_getsta( dev, info, wrqu, extra );
12972         }
12973
12974 #endif //CONFIG_WFD
12975
12976         return ret;
12977 }
12978
12979
12980
12981
12982
12983 #ifdef CONFIG_INTEL_WIDI
12984 static int rtw_widi_set(struct net_device *dev,
12985                                struct iw_request_info *info,
12986                                union iwreq_data *wrqu, char *extra)
12987 {
12988         int ret = 0;
12989         _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
12990
12991         process_intel_widi_cmd(padapter, extra);
12992
12993         return ret;
12994 }
12995
12996 static int rtw_widi_set_probe_request(struct net_device *dev,
12997                                struct iw_request_info *info,
12998                                union iwreq_data *wrqu, char *extra)
12999 {
13000         int     ret = 0;
13001         u8      *pbuf = NULL;
13002         _adapter        *padapter = (_adapter *)rtw_netdev_priv(dev);
13003
13004         pbuf = rtw_malloc(sizeof(l2_msg_t));
13005         if(pbuf)
13006         {
13007                 if ( copy_from_user(pbuf, wrqu->data.pointer, wrqu->data.length) )
13008                         ret = -EFAULT;
13009                 //_rtw_memcpy(pbuf, wrqu->data.pointer, wrqu->data.length);
13010
13011                 if( wrqu->data.flags == 0 )
13012                         intel_widi_wk_cmd(padapter, INTEL_WIDI_ISSUE_PROB_WK, pbuf, sizeof(l2_msg_t));
13013                 else if( wrqu->data.flags == 1 )
13014                         rtw_set_wfd_rds_sink_info( padapter, (l2_msg_t *)pbuf );
13015         }
13016         return ret;
13017 }
13018 #endif // CONFIG_INTEL_WIDI
13019
13020 #ifdef CONFIG_MAC_LOOPBACK_DRIVER
13021
13022 #ifdef CONFIG_RTL8723A
13023 extern void rtl8723a_cal_txdesc_chksum(struct tx_desc *ptxdesc);
13024 #define cal_txdesc_chksum rtl8723a_cal_txdesc_chksum
13025 extern void rtl8723a_fill_default_txdesc(struct xmit_frame *pxmitframe, u8 *pbuf);
13026 #define fill_default_txdesc rtl8723a_fill_default_txdesc
13027 #endif
13028 #if defined(CONFIG_RTL8188E)
13029 #include <rtl8188e_hal.h>
13030 extern void rtl8188e_cal_txdesc_chksum(struct tx_desc *ptxdesc);
13031 #define cal_txdesc_chksum rtl8188e_cal_txdesc_chksum
13032 #ifdef CONFIG_SDIO_HCI || defined(CONFIG_GSPI_HCI)
13033 extern void rtl8188es_fill_default_txdesc(struct xmit_frame *pxmitframe, u8 *pbuf);
13034 #define fill_default_txdesc rtl8188es_fill_default_txdesc
13035 #endif // CONFIG_SDIO_HCI
13036 #endif // CONFIG_RTL8188E
13037 #if defined(CONFIG_RTL8723B)
13038 extern void rtl8723b_cal_txdesc_chksum(struct tx_desc *ptxdesc);
13039 #define cal_txdesc_chksum rtl8723b_cal_txdesc_chksum
13040 extern void rtl8723b_fill_default_txdesc(struct xmit_frame *pxmitframe, u8 *pbuf);
13041 #define fill_default_txdesc rtl8723b_fill_default_txdesc
13042 #endif // CONFIG_RTL8723B
13043
13044 static s32 initLoopback(PADAPTER padapter)
13045 {
13046         PLOOPBACKDATA ploopback;
13047
13048
13049         if (padapter->ploopback == NULL) {
13050                 ploopback = (PLOOPBACKDATA)rtw_zmalloc(sizeof(LOOPBACKDATA));
13051                 if (ploopback == NULL) return -ENOMEM;
13052
13053                 _rtw_init_sema(&ploopback->sema, 0);
13054                 ploopback->bstop = _TRUE;
13055                 ploopback->cnt = 0;
13056                 ploopback->size = 300;
13057                 _rtw_memset(ploopback->msg, 0, sizeof(ploopback->msg));
13058
13059                 padapter->ploopback = ploopback;
13060         }
13061
13062         return 0;
13063 }
13064
13065 static void freeLoopback(PADAPTER padapter)
13066 {
13067         PLOOPBACKDATA ploopback;
13068
13069
13070         ploopback = padapter->ploopback;
13071         if (ploopback) {
13072                 rtw_mfree((u8*)ploopback, sizeof(LOOPBACKDATA));
13073                 padapter->ploopback = NULL;
13074         }
13075 }
13076
13077 static s32 initpseudoadhoc(PADAPTER padapter)
13078 {
13079         NDIS_802_11_NETWORK_INFRASTRUCTURE networkType;
13080         s32 err;
13081
13082         networkType = Ndis802_11IBSS;
13083         err = rtw_set_802_11_infrastructure_mode(padapter, networkType);
13084         if (err == _FALSE) return _FAIL;
13085
13086         err = rtw_setopmode_cmd(padapter, networkType,_TRUE);
13087         if (err == _FAIL) return _FAIL;
13088
13089         return _SUCCESS;
13090 }
13091
13092 static s32 createpseudoadhoc(PADAPTER padapter)
13093 {
13094         NDIS_802_11_AUTHENTICATION_MODE authmode;
13095         struct mlme_priv *pmlmepriv;
13096         NDIS_802_11_SSID *passoc_ssid;
13097         WLAN_BSSID_EX *pdev_network;
13098         u8 *pibss;
13099         u8 ssid[] = "pseduo_ad-hoc";
13100         s32 err;
13101         _irqL irqL;
13102
13103
13104         pmlmepriv = &padapter->mlmepriv;
13105
13106         authmode = Ndis802_11AuthModeOpen;
13107         err = rtw_set_802_11_authentication_mode(padapter, authmode);
13108         if (err == _FALSE) return _FAIL;
13109
13110         passoc_ssid = &pmlmepriv->assoc_ssid;
13111         _rtw_memset(passoc_ssid, 0, sizeof(NDIS_802_11_SSID));
13112         passoc_ssid->SsidLength = sizeof(ssid) - 1;
13113         _rtw_memcpy(passoc_ssid->Ssid, ssid, passoc_ssid->SsidLength);
13114
13115         pdev_network = &padapter->registrypriv.dev_network;
13116         pibss = padapter->registrypriv.dev_network.MacAddress;
13117         _rtw_memcpy(&pdev_network->Ssid, passoc_ssid, sizeof(NDIS_802_11_SSID));
13118
13119         rtw_update_registrypriv_dev_network(padapter);
13120         rtw_generate_random_ibss(pibss);
13121
13122         _enter_critical_bh(&pmlmepriv->lock, &irqL);
13123         pmlmepriv->fw_state = WIFI_ADHOC_MASTER_STATE;
13124         _exit_critical_bh(&pmlmepriv->lock, &irqL);
13125
13126 #if 0
13127         err = rtw_createbss_cmd(padapter);
13128         if (err == _FAIL) return _FAIL;
13129 #else
13130 {
13131         struct wlan_network *pcur_network;
13132         struct sta_info *psta;
13133
13134         //3  create a new psta
13135         pcur_network = &pmlmepriv->cur_network;
13136
13137         //clear psta in the cur_network, if any
13138         psta = rtw_get_stainfo(&padapter->stapriv, pcur_network->network.MacAddress);
13139         if (psta) rtw_free_stainfo(padapter, psta);
13140
13141         psta = rtw_alloc_stainfo(&padapter->stapriv, pibss);
13142         if (psta == NULL) return _FAIL;
13143
13144         //3  join psudo AdHoc
13145         pcur_network->join_res = 1;
13146         pcur_network->aid = psta->aid = 1;
13147         _rtw_memcpy(&pcur_network->network, pdev_network, get_WLAN_BSSID_EX_sz(pdev_network));
13148
13149         // set msr to WIFI_FW_ADHOC_STATE
13150 #if 0
13151         Set_NETYPE0_MSR(padapter, WIFI_FW_ADHOC_STATE);
13152 #else
13153         {
13154                 u8 val8;
13155
13156                 val8 = rtw_read8(padapter, MSR);
13157                 val8 &= 0xFC; // clear NETYPE0
13158                 val8 |= WIFI_FW_ADHOC_STATE & 0x3;
13159                 rtw_write8(padapter, MSR, val8);
13160         }
13161 #endif
13162 }
13163 #endif
13164
13165         return _SUCCESS;
13166 }
13167
13168 static struct xmit_frame* createloopbackpkt(PADAPTER padapter, u32 size)
13169 {
13170         struct xmit_priv *pxmitpriv;
13171         struct xmit_frame *pframe;
13172         struct xmit_buf *pxmitbuf;
13173         struct pkt_attrib *pattrib;
13174         struct tx_desc *desc;
13175         u8 *pkt_start, *pkt_end, *ptr;
13176         struct rtw_ieee80211_hdr *hdr;
13177         s32 bmcast;
13178         _irqL irqL;
13179
13180
13181         if ((TXDESC_SIZE + WLANHDR_OFFSET + size) > MAX_XMITBUF_SZ) return NULL;
13182
13183         pxmitpriv = &padapter->xmitpriv;
13184         pframe = NULL;
13185
13186         //2 1. allocate xmit frame
13187         pframe = rtw_alloc_xmitframe(pxmitpriv);
13188         if (pframe == NULL) return NULL;
13189         pframe->padapter = padapter;
13190
13191         //2 2. allocate xmit buffer
13192         _enter_critical_bh(&pxmitpriv->lock, &irqL);
13193         pxmitbuf = rtw_alloc_xmitbuf(pxmitpriv);
13194         _exit_critical_bh(&pxmitpriv->lock, &irqL);
13195         if (pxmitbuf == NULL) {
13196                 rtw_free_xmitframe(pxmitpriv, pframe);
13197                 return NULL;
13198         }
13199
13200         pframe->pxmitbuf = pxmitbuf;
13201         pframe->buf_addr = pxmitbuf->pbuf;
13202         pxmitbuf->priv_data = pframe;
13203
13204         //2 3. update_attrib()
13205         pattrib = &pframe->attrib;
13206
13207         // init xmitframe attribute
13208         _rtw_memset(pattrib, 0, sizeof(struct pkt_attrib));
13209
13210         pattrib->ether_type = 0x8723;
13211         _rtw_memcpy(pattrib->src, padapter->eeprompriv.mac_addr, ETH_ALEN);
13212         _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);
13213         _rtw_memset(pattrib->dst, 0xFF, ETH_ALEN);
13214         _rtw_memcpy(pattrib->ra, pattrib->dst, ETH_ALEN);
13215
13216 //      pattrib->dhcp_pkt = 0;
13217 //      pattrib->pktlen = 0;
13218         pattrib->ack_policy = 0;
13219 //      pattrib->pkt_hdrlen = ETH_HLEN;
13220         pattrib->hdrlen = WLAN_HDR_A3_LEN;
13221         pattrib->subtype = WIFI_DATA;
13222         pattrib->priority = 0;
13223         pattrib->qsel = pattrib->priority;
13224 //      do_queue_select(padapter, pattrib);
13225         pattrib->nr_frags = 1;
13226         pattrib->encrypt = 0;
13227         pattrib->bswenc = _FALSE;
13228         pattrib->qos_en = _FALSE;
13229
13230         bmcast = IS_MCAST(pattrib->ra);
13231         if (bmcast) {
13232                 pattrib->mac_id = 1;
13233                 pattrib->psta = rtw_get_bcmc_stainfo(padapter);
13234         } else {
13235                 pattrib->mac_id = 0;
13236                 pattrib->psta = rtw_get_stainfo(&padapter->stapriv, get_bssid(&padapter->mlmepriv));
13237         }
13238
13239         pattrib->pktlen = size;
13240         pattrib->last_txcmdsz = pattrib->hdrlen + pattrib->pktlen;
13241
13242         //2 4. fill TX descriptor
13243         desc = (struct tx_desc*)pframe->buf_addr;
13244         _rtw_memset(desc, 0, TXDESC_SIZE);
13245
13246         fill_default_txdesc(pframe, (u8*)desc);
13247
13248         // Hw set sequence number
13249         ((PTXDESC)desc)->hwseq_en = 0; // HWSEQ_EN, 0:disable, 1:enable
13250 //      ((PTXDESC)desc)->hwseq_sel = 0; // HWSEQ_SEL
13251
13252         ((PTXDESC)desc)->disdatafb = 1;
13253
13254         // convert to little endian
13255         desc->txdw0 = cpu_to_le32(desc->txdw0);
13256         desc->txdw1 = cpu_to_le32(desc->txdw1);
13257         desc->txdw2 = cpu_to_le32(desc->txdw2);
13258         desc->txdw3 = cpu_to_le32(desc->txdw3);
13259         desc->txdw4 = cpu_to_le32(desc->txdw4);
13260         desc->txdw5 = cpu_to_le32(desc->txdw5);
13261         desc->txdw6 = cpu_to_le32(desc->txdw6);
13262         desc->txdw7 = cpu_to_le32(desc->txdw7);
13263 #ifdef CONFIG_PCI_HCI
13264         desc->txdw8 = cpu_to_le32(desc->txdw8);
13265         desc->txdw9 = cpu_to_le32(desc->txdw9);
13266         desc->txdw10 = cpu_to_le32(desc->txdw10);
13267         desc->txdw11 = cpu_to_le32(desc->txdw11);
13268         desc->txdw12 = cpu_to_le32(desc->txdw12);
13269         desc->txdw13 = cpu_to_le32(desc->txdw13);
13270         desc->txdw14 = cpu_to_le32(desc->txdw14);
13271         desc->txdw15 = cpu_to_le32(desc->txdw15);
13272 #endif
13273
13274         cal_txdesc_chksum(desc);
13275
13276         //2 5. coalesce
13277         pkt_start = pframe->buf_addr + TXDESC_SIZE;
13278         pkt_end = pkt_start + pattrib->last_txcmdsz;
13279
13280         //3 5.1. make wlan header, make_wlanhdr()
13281         hdr = (struct rtw_ieee80211_hdr *)pkt_start;
13282         SetFrameSubType(&hdr->frame_ctl, pattrib->subtype);
13283         _rtw_memcpy(hdr->addr1, pattrib->dst, ETH_ALEN); // DA
13284         _rtw_memcpy(hdr->addr2, pattrib->src, ETH_ALEN); // SA
13285         _rtw_memcpy(hdr->addr3, get_bssid(&padapter->mlmepriv), ETH_ALEN); // RA, BSSID
13286
13287         //3 5.2. make payload
13288         ptr = pkt_start + pattrib->hdrlen;
13289         get_random_bytes(ptr, pkt_end - ptr);
13290
13291         pxmitbuf->len = TXDESC_SIZE + pattrib->last_txcmdsz;
13292         pxmitbuf->ptail += pxmitbuf->len;
13293
13294         return pframe;
13295 }
13296
13297 static void freeloopbackpkt(PADAPTER padapter, struct xmit_frame *pframe)
13298 {
13299         struct xmit_priv *pxmitpriv;
13300         struct xmit_buf *pxmitbuf;
13301
13302
13303         pxmitpriv = &padapter->xmitpriv;
13304         pxmitbuf = pframe->pxmitbuf;
13305
13306         rtw_free_xmitframe(pxmitpriv, pframe);
13307         rtw_free_xmitbuf(pxmitpriv, pxmitbuf);
13308 }
13309
13310 static void printdata(u8 *pbuf, u32 len)
13311 {
13312         u32 i, val;
13313
13314
13315         for (i = 0; (i+4) <= len; i+=4) {
13316                 printk("%08X", *(u32*)(pbuf + i));
13317                 if ((i+4) & 0x1F) printk(" ");
13318                 else printk("\n");
13319         }
13320
13321         if (i < len)
13322         {
13323 #ifdef CONFIG_BIG_ENDIAN
13324                 for (; i < len, i++)
13325                         printk("%02X", pbuf+i);
13326 #else // CONFIG_LITTLE_ENDIAN
13327 #if 0
13328                 val = 0;
13329                 _rtw_memcpy(&val, pbuf + i, len - i);
13330                 printk("%8X", val);
13331 #else
13332                 u8 str[9];
13333                 u8 n;
13334                 val = 0;
13335                 n = len - i;
13336                 _rtw_memcpy(&val, pbuf+i, n);
13337                 sprintf(str, "%08X", val);
13338                 n = (4 - n) * 2;
13339                 printk("%8s", str+n);
13340 #endif
13341 #endif // CONFIG_LITTLE_ENDIAN
13342         }
13343         printk("\n");
13344 }
13345
13346 static u8 pktcmp(PADAPTER padapter, u8 *txbuf, u32 txsz, u8 *rxbuf, u32 rxsz)
13347 {
13348         PHAL_DATA_TYPE phal;
13349         struct recv_stat *prxstat;
13350         struct recv_stat report;
13351         PRXREPORT prxreport;
13352         u32 drvinfosize;
13353         u32 rxpktsize;
13354         u8 fcssize;
13355         u8 ret = _FALSE;
13356
13357         prxstat = (struct recv_stat*)rxbuf;
13358         report.rxdw0 = le32_to_cpu(prxstat->rxdw0);
13359         report.rxdw1 = le32_to_cpu(prxstat->rxdw1);
13360         report.rxdw2 = le32_to_cpu(prxstat->rxdw2);
13361         report.rxdw3 = le32_to_cpu(prxstat->rxdw3);
13362         report.rxdw4 = le32_to_cpu(prxstat->rxdw4);
13363         report.rxdw5 = le32_to_cpu(prxstat->rxdw5);
13364
13365         prxreport = (PRXREPORT)&report;
13366         drvinfosize = prxreport->drvinfosize << 3;
13367         rxpktsize = prxreport->pktlen;
13368
13369         phal = GET_HAL_DATA(padapter);
13370         if (phal->ReceiveConfig & RCR_APPFCS) fcssize = IEEE80211_FCS_LEN;
13371         else fcssize = 0;
13372
13373         if ((txsz - TXDESC_SIZE) != (rxpktsize - fcssize)) {
13374                 DBG_8192C("%s: ERROR! size not match tx/rx=%d/%d !\n",
13375                         __func__, txsz - TXDESC_SIZE, rxpktsize - fcssize);
13376                 ret = _FALSE;
13377         } else {
13378                 ret = _rtw_memcmp(txbuf + TXDESC_SIZE,\
13379                                                   rxbuf + RXDESC_SIZE + drvinfosize,\
13380                                                   txsz - TXDESC_SIZE);
13381                 if (ret == _FALSE) {
13382                         DBG_8192C("%s: ERROR! pkt content mismatch!\n", __func__);
13383                 }
13384         }
13385
13386         if (ret == _FALSE)
13387         {
13388                 DBG_8192C("\n%s: TX PKT total=%d, desc=%d, content=%d\n",
13389                         __func__, txsz, TXDESC_SIZE, txsz - TXDESC_SIZE);
13390                 DBG_8192C("%s: TX DESC size=%d\n", __func__, TXDESC_SIZE);
13391                 printdata(txbuf, TXDESC_SIZE);
13392                 DBG_8192C("%s: TX content size=%d\n", __func__, txsz - TXDESC_SIZE);
13393                 printdata(txbuf + TXDESC_SIZE, txsz - TXDESC_SIZE);
13394
13395                 DBG_8192C("\n%s: RX PKT read=%d offset=%d(%d,%d) content=%d\n",
13396                         __func__, rxsz, RXDESC_SIZE + drvinfosize, RXDESC_SIZE, drvinfosize, rxpktsize);
13397                 if (rxpktsize != 0)
13398                 {
13399                         DBG_8192C("%s: RX DESC size=%d\n", __func__, RXDESC_SIZE);
13400                         printdata(rxbuf, RXDESC_SIZE);
13401                         DBG_8192C("%s: RX drvinfo size=%d\n", __func__, drvinfosize);
13402                         printdata(rxbuf + RXDESC_SIZE, drvinfosize);
13403                         DBG_8192C("%s: RX content size=%d\n", __func__, rxpktsize);
13404                         printdata(rxbuf + RXDESC_SIZE + drvinfosize, rxpktsize);
13405                 } else {
13406                         DBG_8192C("%s: RX data size=%d\n", __func__, rxsz);
13407                         printdata(rxbuf, rxsz);
13408                 }
13409         }
13410
13411         return ret;
13412 }
13413
13414 thread_return lbk_thread(thread_context context)
13415 {
13416         s32 err;
13417         PADAPTER padapter;
13418         PLOOPBACKDATA ploopback;
13419         struct xmit_frame *pxmitframe;
13420         u32 cnt, ok, fail, headerlen;
13421         u32 pktsize;
13422         u32 ff_hwaddr;
13423
13424
13425         padapter = (PADAPTER)context;
13426         ploopback = padapter->ploopback;
13427         if (ploopback == NULL) return -1;
13428         cnt = 0;
13429         ok = 0;
13430         fail = 0;
13431
13432         daemonize("%s", "RTW_LBK_THREAD");
13433         allow_signal(SIGTERM);
13434
13435         do {
13436                 if (ploopback->size == 0) {
13437                         get_random_bytes(&pktsize, 4);
13438                         pktsize = (pktsize % 1535) + 1; // 1~1535
13439                 } else
13440                         pktsize = ploopback->size;
13441                 
13442                 pxmitframe = createloopbackpkt(padapter, pktsize);
13443                 if (pxmitframe == NULL) {
13444                         sprintf(ploopback->msg, "loopback FAIL! 3. create Packet FAIL!");
13445                         break;
13446                 }
13447
13448                 ploopback->txsize = TXDESC_SIZE + pxmitframe->attrib.last_txcmdsz;
13449                 _rtw_memcpy(ploopback->txbuf, pxmitframe->buf_addr, ploopback->txsize);
13450                 ff_hwaddr = rtw_get_ff_hwaddr(pxmitframe);
13451                 cnt++;
13452                 DBG_8192C("%s: wirte port cnt=%d size=%d\n", __func__, cnt, ploopback->txsize);
13453                 pxmitframe->pxmitbuf->pdata = ploopback->txbuf;
13454                 rtw_write_port(padapter, ff_hwaddr, ploopback->txsize, (u8 *)pxmitframe->pxmitbuf);
13455
13456                 // wait for rx pkt
13457                 _rtw_down_sema(&ploopback->sema);
13458
13459                 err = pktcmp(padapter, ploopback->txbuf, ploopback->txsize, ploopback->rxbuf, ploopback->rxsize);
13460                 if (err == _TRUE)
13461                         ok++;
13462                 else
13463                         fail++;
13464
13465                 ploopback->txsize = 0;
13466                 _rtw_memset(ploopback->txbuf, 0, 0x8000);
13467                 ploopback->rxsize = 0;
13468                 _rtw_memset(ploopback->rxbuf, 0, 0x8000);
13469
13470                 freeloopbackpkt(padapter, pxmitframe);
13471                 pxmitframe = NULL;
13472
13473                 if (signal_pending(current)) {
13474                         flush_signals(current);
13475                 }
13476
13477                 if ((ploopback->bstop == _TRUE) ||
13478                         ((ploopback->cnt != 0) && (ploopback->cnt == cnt)))
13479                 {
13480                         u32 ok_rate, fail_rate, all;
13481                         all = cnt;
13482                         ok_rate = (ok*100)/all;
13483                         fail_rate = (fail*100)/all;
13484                         sprintf(ploopback->msg,\
13485                                         "loopback result: ok=%d%%(%d/%d),error=%d%%(%d/%d)",\
13486                                         ok_rate, ok, all, fail_rate, fail, all);
13487                         break;
13488                 }
13489         } while (1);
13490
13491         ploopback->bstop = _TRUE;
13492
13493         thread_exit();
13494 }
13495
13496 static void loopbackTest(PADAPTER padapter, u32 cnt, u32 size, u8* pmsg)
13497 {
13498         PLOOPBACKDATA ploopback;
13499         u32 len;
13500         s32 err;
13501
13502
13503         ploopback = padapter->ploopback;
13504
13505         if (ploopback)
13506         {
13507                 if (ploopback->bstop == _FALSE) {
13508                         ploopback->bstop = _TRUE;
13509                         _rtw_up_sema(&ploopback->sema);
13510                 }
13511                 len = 0;
13512                 do {
13513                         len = strlen(ploopback->msg);
13514                         if (len) break;
13515                         rtw_msleep_os(1);
13516                 } while (1);
13517                 _rtw_memcpy(pmsg, ploopback->msg, len+1);
13518                 freeLoopback(padapter);
13519
13520                 return;
13521         }
13522
13523         // disable dynamic algorithm
13524         {
13525         u32 DMFlag = DYNAMIC_FUNC_DISABLE;
13526         rtw_hal_get_hwreg(padapter, HW_VAR_DM_FLAG, (u8*)&DMFlag);
13527         }
13528
13529         // create pseudo ad-hoc connection
13530         err = initpseudoadhoc(padapter);
13531         if (err == _FAIL) {
13532                 sprintf(pmsg, "loopback FAIL! 1.1 init ad-hoc FAIL!");
13533                 return;
13534         }
13535
13536         err = createpseudoadhoc(padapter);
13537         if (err == _FAIL) {
13538                 sprintf(pmsg, "loopback FAIL! 1.2 create ad-hoc master FAIL!");
13539                 return;
13540         }
13541
13542         err = initLoopback(padapter);
13543         if (err) {
13544                 sprintf(pmsg, "loopback FAIL! 2. init FAIL! error code=%d", err);
13545                 return;
13546         }
13547
13548         ploopback = padapter->ploopback;
13549
13550         ploopback->bstop = _FALSE;
13551         ploopback->cnt = cnt;
13552         ploopback->size = size;
13553         ploopback->lbkthread = kthread_run(lbk_thread, padapter, "RTW_LBK_THREAD");
13554         if (IS_ERR(padapter->lbkthread))
13555         {
13556                 freeLoopback(padapter);
13557                 sprintf(pmsg, "loopback start FAIL! cnt=%d", cnt);
13558                 return;
13559         }
13560
13561         sprintf(pmsg, "loopback start! cnt=%d", cnt);
13562 }
13563 #endif // CONFIG_MAC_LOOPBACK_DRIVER
13564
13565 static int rtw_test(
13566         struct net_device *dev,
13567         struct iw_request_info *info,
13568         union iwreq_data *wrqu, char *extra)
13569 {
13570         u32 len;
13571         u8 *pbuf, *pch;
13572         char *ptmp;
13573         u8 *delim = ",";
13574         PADAPTER padapter = rtw_netdev_priv(dev);
13575
13576
13577         DBG_871X("+%s\n", __func__);
13578         len = wrqu->data.length;
13579
13580         pbuf = (u8*)rtw_zmalloc(len);
13581         if (pbuf == NULL) {
13582                 DBG_871X("%s: no memory!\n", __func__);
13583                 return -ENOMEM;
13584         }
13585
13586         if (copy_from_user(pbuf, wrqu->data.pointer, len)) {
13587                 rtw_mfree(pbuf, len);
13588                 DBG_871X("%s: copy from user fail!\n", __func__);
13589                 return -EFAULT;
13590         }
13591         DBG_871X("%s: string=\"%s\"\n", __func__, pbuf);
13592
13593         ptmp = (char*)pbuf;
13594         pch = strsep(&ptmp, delim);
13595         if ((pch == NULL) || (strlen(pch) == 0)) {
13596                 rtw_mfree(pbuf, len);
13597                 DBG_871X("%s: parameter error(level 1)!\n", __func__);
13598                 return -EFAULT;
13599         }
13600
13601 #ifdef CONFIG_MAC_LOOPBACK_DRIVER
13602         if (strcmp(pch, "loopback") == 0)
13603         {
13604                 s32 cnt = 0;
13605                 u32 size = 64;
13606
13607                 pch = strsep(&ptmp, delim);
13608                 if ((pch == NULL) || (strlen(pch) == 0)) {
13609                         rtw_mfree(pbuf, len);
13610                         DBG_871X("%s: parameter error(level 2)!\n", __func__);
13611                         return -EFAULT;
13612                 }
13613
13614                 sscanf(pch, "%d", &cnt);
13615                 DBG_871X("%s: loopback cnt=%d\n", __func__, cnt);
13616
13617                 pch = strsep(&ptmp, delim);
13618                 if ((pch == NULL) || (strlen(pch) == 0)) {
13619                         rtw_mfree(pbuf, len);
13620                         DBG_871X("%s: parameter error(level 2)!\n", __func__);
13621                         return -EFAULT;
13622                 }
13623
13624                 sscanf(pch, "%d", &size);
13625                 DBG_871X("%s: loopback size=%d\n", __func__, size);
13626
13627                 loopbackTest(padapter, cnt, size, extra);
13628                 wrqu->data.length = strlen(extra) + 1;
13629
13630                 rtw_mfree(pbuf, len);
13631                 return 0;
13632         }
13633 #endif
13634
13635 #if 0
13636 //#ifdef CONFIG_RTL8723A
13637         if (strcmp(pch, "poweron") == 0)
13638         {
13639                 s32 ret;
13640
13641                 ret = _InitPowerOn(padapter);
13642                 DBG_871X("%s: power on %s\n", __func__, (_FAIL==ret) ? "FAIL!":"OK.");
13643                 sprintf(extra, "Power ON %s", (_FAIL==ret) ? "FAIL!":"OK.");
13644                 wrqu->data.length = strlen(extra) + 1;
13645
13646                 rtw_mfree(pbuf, len);
13647                 return 0;
13648         }
13649
13650         if (strcmp(pch, "dlfw") == 0)
13651         {
13652                 s32 ret;
13653
13654                 ret = rtl8723a_FirmwareDownload(padapter);
13655                 DBG_871X("%s: download FW %s\n", __func__, (_FAIL==ret) ? "FAIL!":"OK.");
13656                 sprintf(extra, "download FW %s", (_FAIL==ret) ? "FAIL!":"OK.");
13657                 wrqu->data.length = strlen(extra) + 1;
13658
13659                 rtw_mfree(pbuf, len);
13660                 return 0;
13661         }
13662 #endif
13663
13664 #ifdef CONFIG_BT_COEXIST
13665         if (strcmp(pch, "bton") == 0)
13666         {
13667                 rtw_btcoex_SetManualControl(padapter, _FALSE);
13668         }
13669
13670         if (strcmp(pch, "btoff") == 0)
13671         {
13672                 rtw_btcoex_SetManualControl(padapter, _TRUE);
13673         }
13674
13675         if (strcmp(pch, "h2c") == 0)
13676         {
13677                 u8 param[8];
13678                 u8 count = 0;
13679                 u32 tmp;
13680                 u8 i;
13681                 u32 pos;
13682                 s32 ret;
13683
13684
13685                 do {
13686                         pch = strsep(&ptmp, delim);
13687                         if ((pch == NULL) || (strlen(pch) == 0))
13688                                 break;
13689
13690                         sscanf(pch, "%x", &tmp);
13691                         param[count++] = (u8)tmp;
13692                 } while (count < 8);
13693
13694                 if (count == 0) {
13695                         rtw_mfree(pbuf, len);
13696                         DBG_871X("%s: parameter error(level 2)!\n", __func__);
13697                         return -EFAULT;
13698                 }
13699
13700                 ret = rtw_hal_fill_h2c_cmd(padapter, param[0], count-1, &param[1]);
13701
13702                 pos = sprintf(extra, "H2C ID=0x%02x content=", param[0]);
13703                 for (i=1; i<count; i++) {
13704                         pos += sprintf(extra+pos, "%02x,", param[i]);
13705                 }
13706                 extra[pos] = 0;
13707                 pos--;
13708                 pos += sprintf(extra+pos, " %s", ret==_FAIL?"FAIL":"OK");
13709
13710                 wrqu->data.length = strlen(extra) + 1;
13711         }
13712 #endif // CONFIG_BT_COEXIST
13713
13714         rtw_mfree(pbuf, len);
13715         return 0;
13716 }
13717
13718 static iw_handler rtw_handlers[] =
13719 {
13720         NULL,                                   /* SIOCSIWCOMMIT */
13721         rtw_wx_get_name,                /* SIOCGIWNAME */
13722         dummy,                                  /* SIOCSIWNWID */
13723         dummy,                                  /* SIOCGIWNWID */
13724         rtw_wx_set_freq,                /* SIOCSIWFREQ */
13725         rtw_wx_get_freq,                /* SIOCGIWFREQ */
13726         rtw_wx_set_mode,                /* SIOCSIWMODE */
13727         rtw_wx_get_mode,                /* SIOCGIWMODE */
13728         dummy,                                  /* SIOCSIWSENS */
13729         rtw_wx_get_sens,                /* SIOCGIWSENS */
13730         NULL,                                   /* SIOCSIWRANGE */
13731         rtw_wx_get_range,               /* SIOCGIWRANGE */
13732         rtw_wx_set_priv,                /* SIOCSIWPRIV */
13733         NULL,                                   /* SIOCGIWPRIV */
13734         NULL,                                   /* SIOCSIWSTATS */
13735         NULL,                                   /* SIOCGIWSTATS */
13736         dummy,                                  /* SIOCSIWSPY */
13737         dummy,                                  /* SIOCGIWSPY */
13738         NULL,                                   /* SIOCGIWTHRSPY */
13739         NULL,                                   /* SIOCWIWTHRSPY */
13740         rtw_wx_set_wap,         /* SIOCSIWAP */
13741         rtw_wx_get_wap,         /* SIOCGIWAP */
13742         rtw_wx_set_mlme,                /* request MLME operation; uses struct iw_mlme */
13743         dummy,                                  /* SIOCGIWAPLIST -- depricated */
13744         rtw_wx_set_scan,                /* SIOCSIWSCAN */
13745         rtw_wx_get_scan,                /* SIOCGIWSCAN */
13746         rtw_wx_set_essid,               /* SIOCSIWESSID */
13747         rtw_wx_get_essid,               /* SIOCGIWESSID */
13748         dummy,                                  /* SIOCSIWNICKN */
13749         rtw_wx_get_nick,                /* SIOCGIWNICKN */
13750         NULL,                                   /* -- hole -- */
13751         NULL,                                   /* -- hole -- */
13752         rtw_wx_set_rate,                /* SIOCSIWRATE */
13753         rtw_wx_get_rate,                /* SIOCGIWRATE */
13754         rtw_wx_set_rts,                 /* SIOCSIWRTS */
13755         rtw_wx_get_rts,                 /* SIOCGIWRTS */
13756         rtw_wx_set_frag,                /* SIOCSIWFRAG */
13757         rtw_wx_get_frag,                /* SIOCGIWFRAG */
13758         dummy,                                  /* SIOCSIWTXPOW */
13759         dummy,                                  /* SIOCGIWTXPOW */
13760         dummy,                                  /* SIOCSIWRETRY */
13761         rtw_wx_get_retry,               /* SIOCGIWRETRY */
13762         rtw_wx_set_enc,                 /* SIOCSIWENCODE */
13763         rtw_wx_get_enc,                 /* SIOCGIWENCODE */
13764         dummy,                                  /* SIOCSIWPOWER */
13765         rtw_wx_get_power,               /* SIOCGIWPOWER */
13766         NULL,                                   /*---hole---*/
13767         NULL,                                   /*---hole---*/
13768         rtw_wx_set_gen_ie,              /* SIOCSIWGENIE */
13769         NULL,                                   /* SIOCGWGENIE */
13770         rtw_wx_set_auth,                /* SIOCSIWAUTH */
13771         NULL,                                   /* SIOCGIWAUTH */
13772         rtw_wx_set_enc_ext,             /* SIOCSIWENCODEEXT */
13773         NULL,                                   /* SIOCGIWENCODEEXT */
13774         rtw_wx_set_pmkid,               /* SIOCSIWPMKSA */
13775         NULL,                                   /*---hole---*/
13776 }; 
13777
13778 #if 0
13779 //defined(CONFIG_MP_INCLUDED) && defined(CONFIG_MP_IWPRIV_SUPPORT)
13780 static const struct iw_priv_args rtw_private_args[] =
13781 {       
13782         { SIOCIWFIRSTPRIV + 0x00, IW_PRIV_TYPE_CHAR | 1024, 0 , ""},  //set 
13783         { SIOCIWFIRSTPRIV + 0x01, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , ""},//get
13784 /* --- sub-ioctls definitions --- */   
13785                 { MP_START , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_start" }, //set
13786                 { MP_PHYPARA, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_phypara" },//get
13787                 { MP_STOP , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_stop" }, //set
13788                 { MP_CHANNEL , IW_PRIV_TYPE_CHAR | 1024 , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_channel" },//get
13789                 { MP_BANDWIDTH , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_bandwidth"}, //set
13790                 { MP_RATE , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rate" },//get
13791                 { MP_RESET_STATS , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_reset_stats"},
13792                 { MP_QUERY , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , "mp_query"}, //get
13793                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13794                 { READ_REG , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "read_reg" },
13795                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13796                 { MP_RATE , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rate" },
13797                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13798                 { READ_RF , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "read_rf" },
13799                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13800                 { MP_PSD , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_psd"}, 
13801                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13802                 { MP_DUMP, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_dump" },
13803                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13804                 { MP_TXPOWER , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_txpower"},
13805                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13806                 { MP_ANT_TX , IW_PRIV_TYPE_CHAR | 1024,  IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ant_tx"},
13807                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13808                 { MP_ANT_RX , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ant_rx"},
13809                 { WRITE_REG, IW_PRIV_TYPE_CHAR | 1024, 0,"write_reg"},//set
13810                 { MP_NULL, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "NULL" },
13811                 { WRITE_RF, IW_PRIV_TYPE_CHAR | 1024, 0,"write_rf"},//set
13812                 { MP_NULL, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "NULL" },
13813                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13814                 { MP_CTX , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ctx"},
13815                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13816                 { MP_ARX , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_arx"},
13817                 { MP_NULL, IW_PRIV_TYPE_CHAR | 128, 0,"NULL"},//set
13818                 { MP_THER , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ther"},
13819                 { EFUSE_SET, IW_PRIV_TYPE_CHAR | 1024, 0, "efuse_set" },
13820                 { EFUSE_GET, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_get" },
13821                 { MP_PWRTRK , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_pwrtrk"},
13822                 { MP_QueryDrvStats, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_drvquery" },
13823                 { MP_IOCTL, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_ioctl"}, // mp_ioctl       
13824                 { MP_SetRFPathSwh, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_setrfpath" },
13825 #ifdef CONFIG_RTL8723A
13826                 { MP_SetBT, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_setbt" },
13827 #endif
13828         { SIOCIWFIRSTPRIV + 0x02, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , "test"},//set
13829 };
13830 static iw_handler rtw_private_handler[] = 
13831 {
13832         rtw_mp_set,
13833         rtw_mp_get,
13834 };
13835 #else // not inlucde MP
13836
13837 static const struct iw_priv_args rtw_private_args[] = {
13838         {
13839                 SIOCIWFIRSTPRIV + 0x0,
13840                 IW_PRIV_TYPE_CHAR | 0x7FF, 0, "write"
13841         },
13842         {
13843                 SIOCIWFIRSTPRIV + 0x1,
13844                 IW_PRIV_TYPE_CHAR | 0x7FF,
13845                 IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_FIXED | IFNAMSIZ, "read"
13846         },
13847         {
13848                 SIOCIWFIRSTPRIV + 0x2, 0, 0, "driver_ext"
13849         },
13850         {
13851                 SIOCIWFIRSTPRIV + 0x3, 0, 0, "mp_ioctl"
13852         },
13853         {
13854                 SIOCIWFIRSTPRIV + 0x4,
13855                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "apinfo"
13856         },
13857         {
13858                 SIOCIWFIRSTPRIV + 0x5,
13859                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, 0, "setpid"
13860         },
13861         {
13862                 SIOCIWFIRSTPRIV + 0x6,
13863                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_start"
13864         },
13865 //for PLATFORM_MT53XX   
13866         {
13867                 SIOCIWFIRSTPRIV + 0x7,
13868                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "get_sensitivity"
13869         },
13870         {
13871                 SIOCIWFIRSTPRIV + 0x8,
13872                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_prob_req_ie"
13873         },
13874         {
13875                 SIOCIWFIRSTPRIV + 0x9,
13876                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "wps_assoc_req_ie"
13877         },
13878
13879 //for RTK_DMP_PLATFORM  
13880         {
13881                 SIOCIWFIRSTPRIV + 0xA,
13882                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 1, 0, "channel_plan"
13883         },
13884
13885         {
13886                 SIOCIWFIRSTPRIV + 0xB,
13887                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, 0, "dbg"
13888         },      
13889         {
13890                 SIOCIWFIRSTPRIV + 0xC,
13891                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 3, 0, "rfw"
13892         },
13893         {
13894                 SIOCIWFIRSTPRIV + 0xD,
13895                 IW_PRIV_TYPE_INT | IW_PRIV_SIZE_FIXED | 2, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_FIXED | IFNAMSIZ, "rfr"
13896         },
13897 #if 0
13898         {
13899                 SIOCIWFIRSTPRIV + 0xE,0,0, "wowlan_ctrl"
13900         },
13901 #endif
13902         {
13903                 SIOCIWFIRSTPRIV + 0x10,
13904                 IW_PRIV_TYPE_CHAR | 1024, 0, "p2p_set"
13905         },
13906         {
13907                 SIOCIWFIRSTPRIV + 0x11,
13908                 IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , "p2p_get"
13909         },
13910         {
13911                 SIOCIWFIRSTPRIV + 0x12, 0, 0, "NULL"
13912         },
13913         {
13914                 SIOCIWFIRSTPRIV + 0x13,
13915                 IW_PRIV_TYPE_CHAR | 64, IW_PRIV_TYPE_CHAR | 64 , "p2p_get2"
13916         },      
13917         {
13918                 SIOCIWFIRSTPRIV + 0x14,
13919                 IW_PRIV_TYPE_CHAR  | 64, 0, "tdls"
13920         },
13921         {
13922                 SIOCIWFIRSTPRIV + 0x15,
13923                 IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | 1024 , "tdls_get"
13924         },      
13925         {
13926                 SIOCIWFIRSTPRIV + 0x16,
13927                 IW_PRIV_TYPE_CHAR | 64, 0, "pm_set"
13928         },
13929
13930         {SIOCIWFIRSTPRIV + 0x18, IW_PRIV_TYPE_CHAR | IFNAMSIZ , 0 , "rereg_nd_name"},
13931 #ifdef CONFIG_MP_INCLUDED
13932         {SIOCIWFIRSTPRIV + 0x1A, IW_PRIV_TYPE_CHAR | 1024, 0,  "NULL"},
13933         {SIOCIWFIRSTPRIV + 0x1B, IW_PRIV_TYPE_CHAR | 128, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "NULL"},
13934 #else
13935         {SIOCIWFIRSTPRIV + 0x1A, IW_PRIV_TYPE_CHAR | 1024, 0, "efuse_set"},
13936         {SIOCIWFIRSTPRIV + 0x1B, IW_PRIV_TYPE_CHAR | 128, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_get"},
13937 #endif
13938         {
13939                 SIOCIWFIRSTPRIV + 0x1D,
13940                 IW_PRIV_TYPE_CHAR | 40, IW_PRIV_TYPE_CHAR | 0x7FF, "test"
13941         },
13942
13943 #ifdef CONFIG_INTEL_WIDI
13944         {
13945                 SIOCIWFIRSTPRIV + 0x1E,
13946                 IW_PRIV_TYPE_CHAR | 1024, 0, "widi_set"
13947         },
13948         {
13949                 SIOCIWFIRSTPRIV + 0x1F,
13950                 IW_PRIV_TYPE_CHAR | 128, 0, "widi_prob_req"
13951         },
13952 #endif // CONFIG_INTEL_WIDI
13953
13954 #ifdef CONFIG_MP_INCLUDED
13955         { SIOCIWFIRSTPRIV + 0x0E, IW_PRIV_TYPE_CHAR | 1024, 0 , ""},  //set 
13956         { SIOCIWFIRSTPRIV + 0x0F, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , ""},//get
13957 /* --- sub-ioctls definitions --- */   
13958                 { MP_START , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_start" }, //set
13959                 { MP_PHYPARA, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_phypara" },//get
13960                 { MP_STOP , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_stop" }, //set
13961                 { MP_CHANNEL , IW_PRIV_TYPE_CHAR | 1024 , IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_channel" },//get
13962                 { MP_BANDWIDTH , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_bandwidth"}, //set
13963                 { MP_RATE , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rate" },//get
13964                 { MP_RESET_STATS , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_reset_stats"},
13965                 { MP_QUERY , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK , "mp_query"}, //get
13966                 { READ_REG , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "read_reg" },
13967                 { MP_RATE , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_rate" },
13968                 { READ_RF , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "read_rf" },
13969                 { MP_PSD , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_psd"}, 
13970                 { MP_DUMP, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_dump" },
13971                 { MP_TXPOWER , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_txpower"},
13972                 { MP_ANT_TX , IW_PRIV_TYPE_CHAR | 1024,  IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ant_tx"},
13973                 { MP_ANT_RX , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ant_rx"},
13974                 { WRITE_REG , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "write_reg" },
13975                 { WRITE_RF , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "write_rf" },
13976                 { MP_CTX , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ctx"},
13977                 { MP_ARX , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_arx"},
13978                 { MP_THER , IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_ther"},
13979                 { EFUSE_SET, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_set" },
13980                 { EFUSE_GET, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "efuse_get" },
13981                 { MP_PWRTRK , IW_PRIV_TYPE_CHAR | 1024, 0, "mp_pwrtrk"},
13982                 { MP_QueryDrvStats, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_drvquery" },
13983                 { MP_IOCTL, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_ioctl"}, // mp_ioctl       
13984                 { MP_SetRFPathSwh, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_setrfpath" },               
13985                 { MP_PwrCtlDM, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_pwrctldm" },                
13986                 { MP_GET_TXPOWER_INX, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_get_txpower" },
13987                 
13988 #if defined(CONFIG_RTL8723A) || defined(CONFIG_RTL8723B)
13989                 { MP_SetBT, IW_PRIV_TYPE_CHAR | 1024, IW_PRIV_TYPE_CHAR | IW_PRIV_SIZE_MASK, "mp_setbt" },
13990         { MP_DISABLE_BT_COEXIST, IW_PRIV_TYPE_CHAR | 1024, 0, "mp_disa_btcoex"},
13991 #endif
13992                 { CTA_TEST, IW_PRIV_TYPE_CHAR | 1024, 0, "cta_test"},
13993 #endif
13994 #ifdef CONFIG_AP_WOWLAN
13995                 { MP_AP_WOW_ENABLE , IW_PRIV_TYPE_CHAR | 1024, 0, "ap_wow_enable" }, //set 
13996 #endif
13997 };
13998
13999 static iw_handler rtw_private_handler[] = 
14000 {
14001         rtw_wx_write32,                                 //0x00
14002         rtw_wx_read32,                                  //0x01
14003         rtw_drvext_hdl,                                 //0x02
14004         rtw_mp_ioctl_hdl,                               //0x03
14005
14006 // for MM DTV platform
14007         rtw_get_ap_info,                                        //0x04
14008
14009         rtw_set_pid,                                            //0x05
14010         rtw_wps_start,                                  //0x06
14011
14012 // for PLATFORM_MT53XX
14013         rtw_wx_get_sensitivity,                 //0x07
14014         rtw_wx_set_mtk_wps_probe_ie,    //0x08
14015         rtw_wx_set_mtk_wps_ie,                  //0x09
14016
14017 // for RTK_DMP_PLATFORM
14018 // Set Channel depend on the country code
14019         rtw_wx_set_channel_plan,                //0x0A
14020
14021         rtw_dbg_port,                                   //0x0B
14022         rtw_wx_write_rf,                                        //0x0C
14023         rtw_wx_read_rf,                                 //0x0D
14024 #ifdef CONFIG_MP_INCLUDED
14025         rtw_mp_set,                                     //0x0E
14026         rtw_mp_get,                                     //0x0F
14027 #else
14028         rtw_wx_priv_null,                               //0x0E
14029         rtw_wx_priv_null,                               //0x0F
14030 #endif
14031         rtw_p2p_set,                                    //0x10
14032         rtw_p2p_get,                                    //0x11
14033         NULL,                                                   //0x12
14034         rtw_p2p_get2,                                   //0x13
14035
14036         rtw_tdls,                                               //0x14
14037         rtw_tdls_get,                                   //0x15
14038
14039         rtw_pm_set,                                             //0x16
14040         rtw_wx_priv_null,                               //0x17
14041         rtw_rereg_nd_name,                              //0x18
14042         rtw_wx_priv_null,                               //0x19
14043 #ifdef CONFIG_MP_INCLUDED
14044         rtw_wx_priv_null,                               //0x1A
14045         rtw_wx_priv_null,                               //0x1B
14046 #else
14047         rtw_mp_efuse_set,                               //0x1A
14048         rtw_mp_efuse_get,                               //0x1B
14049 #endif
14050         NULL,                                                   // 0x1C is reserved for hostapd
14051         rtw_test,                                               // 0x1D
14052 #ifdef CONFIG_INTEL_WIDI
14053         rtw_widi_set,                                   //0x1E
14054         rtw_widi_set_probe_request,             //0x1F
14055 #endif // CONFIG_INTEL_WIDI
14056 };
14057
14058 #endif // #if defined(CONFIG_MP_INCLUDED) && defined(CONFIG_MP_IWPRIV_SUPPORT)
14059
14060 #if WIRELESS_EXT >= 17  
14061 static struct iw_statistics *rtw_get_wireless_stats(struct net_device *dev)
14062 {
14063        _adapter *padapter = (_adapter *)rtw_netdev_priv(dev);
14064            struct iw_statistics *piwstats=&padapter->iwstats;
14065         int tmp_level = 0;
14066         int tmp_qual = 0;
14067         int tmp_noise = 0;
14068
14069         if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) != _TRUE)
14070         {
14071                 piwstats->qual.qual = 0;
14072                 piwstats->qual.level = 0;
14073                 piwstats->qual.noise = 0;
14074                 //DBG_871X("No link  level:%d, qual:%d, noise:%d\n", tmp_level, tmp_qual, tmp_noise);
14075         }
14076         else{
14077                 #ifdef CONFIG_SIGNAL_DISPLAY_DBM
14078                 tmp_level = translate_percentage_to_dbm(padapter->recvpriv.signal_strength); 
14079                 #else
14080                 tmp_level = padapter->recvpriv.signal_strength;
14081                 #endif
14082                 
14083                 tmp_qual = padapter->recvpriv.signal_qual;
14084                 tmp_noise =padapter->recvpriv.noise;            
14085                 //DBG_871X("level:%d, qual:%d, noise:%d, rssi (%d)\n", tmp_level, tmp_qual, tmp_noise,padapter->recvpriv.rssi);
14086
14087                 piwstats->qual.level = tmp_level;
14088                 piwstats->qual.qual = tmp_qual;
14089                 piwstats->qual.noise = tmp_noise;
14090         }
14091 #if (LINUX_VERSION_CODE >= KERNEL_VERSION(2,6,14))
14092         piwstats->qual.updated = IW_QUAL_ALL_UPDATED ;//|IW_QUAL_DBM;
14093 #else
14094 #ifdef RTK_DMP_PLATFORM
14095         //IW_QUAL_DBM= 0x8, if driver use this flag, wireless extension will show value of dbm.
14096         //remove this flag for show percentage 0~100
14097         piwstats->qual.updated = 0x07;
14098 #else
14099         piwstats->qual.updated = 0x0f;
14100 #endif
14101 #endif
14102
14103         #ifdef CONFIG_SIGNAL_DISPLAY_DBM
14104         piwstats->qual.updated = piwstats->qual.updated | IW_QUAL_DBM;
14105         #endif
14106
14107         return &padapter->iwstats;
14108 }
14109 #endif
14110
14111 #ifdef CONFIG_WIRELESS_EXT
14112 struct iw_handler_def rtw_handlers_def =
14113 {
14114         .standard = rtw_handlers,
14115         .num_standard = sizeof(rtw_handlers) / sizeof(iw_handler),
14116 #if (LINUX_VERSION_CODE < KERNEL_VERSION(2,6,33)) || defined(CONFIG_WEXT_PRIV)
14117         .private = rtw_private_handler,
14118         .private_args = (struct iw_priv_args *)rtw_private_args,
14119         .num_private = sizeof(rtw_private_handler) / sizeof(iw_handler),
14120         .num_private_args = sizeof(rtw_private_args) / sizeof(struct iw_priv_args),
14121 #endif
14122 #if WIRELESS_EXT >= 17
14123         .get_wireless_stats = rtw_get_wireless_stats,
14124 #endif
14125 };
14126 #endif
14127
14128 // copy from net/wireless/wext.c start
14129 /* ---------------------------------------------------------------- */
14130 /*
14131  * Calculate size of private arguments
14132  */
14133 static const char iw_priv_type_size[] = {
14134         0,                              /* IW_PRIV_TYPE_NONE */
14135         1,                              /* IW_PRIV_TYPE_BYTE */
14136         1,                              /* IW_PRIV_TYPE_CHAR */
14137         0,                              /* Not defined */
14138         sizeof(__u32),                  /* IW_PRIV_TYPE_INT */
14139         sizeof(struct iw_freq),         /* IW_PRIV_TYPE_FLOAT */
14140         sizeof(struct sockaddr),        /* IW_PRIV_TYPE_ADDR */
14141         0,                              /* Not defined */
14142 };
14143
14144 static int get_priv_size(__u16 args)
14145 {
14146         int num = args & IW_PRIV_SIZE_MASK;
14147         int type = (args & IW_PRIV_TYPE_MASK) >> 12;
14148
14149         return num * iw_priv_type_size[type];
14150 }
14151 // copy from net/wireless/wext.c end
14152
14153 static int rtw_ioctl_wext_private(struct net_device *dev, union iwreq_data *wrq_data)
14154 {
14155         int err = 0;
14156         u8 *input = NULL;
14157         u32 input_len = 0;
14158         const char delim[] = " ";
14159         u8 *output = NULL;
14160         u32 output_len = 0;
14161         u32 count = 0;
14162         u8 *buffer= NULL;
14163         u32 buffer_len = 0;
14164         char *ptr = NULL;
14165         u8 cmdname[17] = {0}; // IFNAMSIZ+1
14166         u32 cmdlen;
14167         s32 len;
14168         u8 *extra = NULL;
14169         u32 extra_size = 0;
14170
14171         s32 k;
14172         const iw_handler *priv;         /* Private ioctl */
14173         const struct iw_priv_args *priv_args;   /* Private ioctl description */
14174         u32 num_priv;                           /* Number of ioctl */
14175         u32 num_priv_args;                      /* Number of descriptions */
14176         iw_handler handler;
14177         int temp;
14178         int subcmd = 0;                         /* sub-ioctl index */
14179         int offset = 0;                         /* Space for sub-ioctl index */
14180
14181         union iwreq_data wdata;
14182
14183
14184         _rtw_memcpy(&wdata, wrq_data, sizeof(wdata));
14185
14186         input_len = wdata.data.length;
14187         input = rtw_zmalloc(input_len);
14188         if (NULL == input)
14189                 return -ENOMEM;
14190         if (copy_from_user(input, wdata.data.pointer, input_len)) {
14191                 err = -EFAULT;
14192                 goto exit;
14193         }
14194         ptr = input;
14195         len = input_len;
14196
14197         sscanf(ptr, "%16s", cmdname);
14198         cmdlen = strlen(cmdname);
14199         DBG_8192C("%s: cmd=%s\n", __func__, cmdname);
14200
14201         // skip command string
14202         if (cmdlen > 0)
14203                 cmdlen += 1; // skip one space
14204         ptr += cmdlen;
14205         len -= cmdlen;
14206         DBG_8192C("%s: parameters=%s\n", __func__, ptr);
14207
14208         priv = rtw_private_handler;
14209         priv_args = rtw_private_args;
14210         num_priv = sizeof(rtw_private_handler) / sizeof(iw_handler);
14211         num_priv_args = sizeof(rtw_private_args) / sizeof(struct iw_priv_args);
14212
14213         if (num_priv_args == 0) {
14214                 err = -EOPNOTSUPP;
14215                 goto exit;
14216         }
14217
14218         /* Search the correct ioctl */
14219         k = -1;
14220         while((++k < num_priv_args) && strcmp(priv_args[k].name, cmdname));
14221
14222         /* If not found... */
14223         if (k == num_priv_args) {
14224                 err = -EOPNOTSUPP;
14225                 goto exit;
14226         }
14227
14228         /* Watch out for sub-ioctls ! */
14229         if (priv_args[k].cmd < SIOCDEVPRIVATE)
14230         {
14231                 int j = -1;
14232
14233                 /* Find the matching *real* ioctl */
14234                 while ((++j < num_priv_args) && ((priv_args[j].name[0] != '\0') ||
14235                         (priv_args[j].set_args != priv_args[k].set_args) ||
14236                         (priv_args[j].get_args != priv_args[k].get_args)));
14237
14238                 /* If not found... */
14239                 if (j == num_priv_args) {
14240                         err = -EINVAL;
14241                         goto exit;
14242                 }
14243
14244                 /* Save sub-ioctl number */
14245                 subcmd = priv_args[k].cmd;
14246                 /* Reserve one int (simplify alignment issues) */
14247                 offset = sizeof(__u32);
14248                 /* Use real ioctl definition from now on */
14249                 k = j;
14250         }
14251
14252         buffer = rtw_zmalloc(4096);
14253         if (NULL == buffer) {
14254                 err = -ENOMEM;
14255                 goto exit;
14256         }
14257
14258         /* If we have to set some data */
14259         if ((priv_args[k].set_args & IW_PRIV_TYPE_MASK) &&
14260                 (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
14261         {
14262                 u8 *str;
14263
14264                 switch (priv_args[k].set_args & IW_PRIV_TYPE_MASK)
14265                 {
14266                         case IW_PRIV_TYPE_BYTE:
14267                                 /* Fetch args */
14268                                 count = 0;
14269                                 do {
14270                                         str = strsep(&ptr, delim);
14271                                         if (NULL == str) break;
14272                                         sscanf(str, "%i", &temp);
14273                                         buffer[count++] = (u8)temp;
14274                                 } while (1);
14275                                 buffer_len = count;
14276
14277                                 /* Number of args to fetch */
14278                                 wdata.data.length = count;
14279                                 if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
14280                                         wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
14281
14282                                 break;
14283
14284                         case IW_PRIV_TYPE_INT:
14285                                 /* Fetch args */
14286                                 count = 0;
14287                                 do {
14288                                         str = strsep(&ptr, delim);
14289                                         if (NULL == str) break;
14290                                         sscanf(str, "%i", &temp);
14291                                         ((s32*)buffer)[count++] = (s32)temp;
14292                                 } while (1);
14293                                 buffer_len = count * sizeof(s32);
14294
14295                                 /* Number of args to fetch */
14296                                 wdata.data.length = count;
14297                                 if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
14298                                         wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
14299
14300                                 break;
14301
14302                         case IW_PRIV_TYPE_CHAR:
14303                                 if (len > 0)
14304                                 {
14305                                         /* Size of the string to fetch */
14306                                         wdata.data.length = len;
14307                                         if (wdata.data.length > (priv_args[k].set_args & IW_PRIV_SIZE_MASK))
14308                                                 wdata.data.length = priv_args[k].set_args & IW_PRIV_SIZE_MASK;
14309
14310                                         /* Fetch string */
14311                                         _rtw_memcpy(buffer, ptr, wdata.data.length);
14312                                 }
14313                                 else
14314                                 {
14315                                         wdata.data.length = 1;
14316                                         buffer[0] = '\0';
14317                                 }
14318                                 buffer_len = wdata.data.length;
14319                                 break;
14320
14321                         default:
14322                                 DBG_8192C("%s: Not yet implemented...\n", __func__);
14323                                 err = -1;
14324                                 goto exit;
14325                 }
14326
14327                 if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
14328                         (wdata.data.length != (priv_args[k].set_args & IW_PRIV_SIZE_MASK)))
14329                 {
14330                         DBG_8192C("%s: The command %s needs exactly %d argument(s)...\n",
14331                                         __func__, cmdname, priv_args[k].set_args & IW_PRIV_SIZE_MASK);
14332                         err = -EINVAL;
14333                         goto exit;
14334                 }
14335         }   /* if args to set */
14336         else
14337         {
14338                 wdata.data.length = 0L;
14339         }
14340
14341         /* Those two tests are important. They define how the driver
14342         * will have to handle the data */
14343         if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
14344                 ((get_priv_size(priv_args[k].set_args) + offset) <= IFNAMSIZ))
14345         {
14346                 /* First case : all SET args fit within wrq */
14347                 if (offset)
14348                         wdata.mode = subcmd;
14349                 _rtw_memcpy(wdata.name + offset, buffer, IFNAMSIZ - offset);
14350         }
14351         else
14352         {
14353                 if ((priv_args[k].set_args == 0) &&
14354                         (priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
14355                         (get_priv_size(priv_args[k].get_args) <= IFNAMSIZ))
14356                 {
14357                         /* Second case : no SET args, GET args fit within wrq */
14358                         if (offset)
14359                                 wdata.mode = subcmd;
14360                 }
14361                 else
14362                 {
14363                         /* Third case : args won't fit in wrq, or variable number of args */
14364                         if (copy_to_user(wdata.data.pointer, buffer, buffer_len)) {
14365                                 err = -EFAULT;
14366                                 goto exit;
14367                         }
14368                         wdata.data.flags = subcmd;
14369                 }
14370         }
14371
14372         rtw_mfree(input, input_len);
14373         input = NULL;
14374
14375         extra_size = 0;
14376         if (IW_IS_SET(priv_args[k].cmd))
14377         {
14378                 /* Size of set arguments */
14379                 extra_size = get_priv_size(priv_args[k].set_args);
14380
14381                 /* Does it fits in iwr ? */
14382                 if ((priv_args[k].set_args & IW_PRIV_SIZE_FIXED) &&
14383                         ((extra_size + offset) <= IFNAMSIZ))
14384                         extra_size = 0;
14385         } else {
14386                 /* Size of get arguments */
14387                 extra_size = get_priv_size(priv_args[k].get_args);
14388
14389                 /* Does it fits in iwr ? */
14390                 if ((priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
14391                         (extra_size <= IFNAMSIZ))
14392                         extra_size = 0;
14393         }
14394
14395         if (extra_size == 0) {
14396                 extra = (u8*)&wdata;
14397                 rtw_mfree(buffer, 4096);
14398                 buffer = NULL;
14399         } else
14400                 extra = buffer;
14401
14402         handler = priv[priv_args[k].cmd - SIOCIWFIRSTPRIV];
14403         err = handler(dev, NULL, &wdata, extra);
14404
14405         /* If we have to get some data */
14406         if ((priv_args[k].get_args & IW_PRIV_TYPE_MASK) &&
14407                 (priv_args[k].get_args & IW_PRIV_SIZE_MASK))
14408         {
14409                 int j;
14410                 int n = 0;      /* number of args */
14411                 u8 str[20] = {0};
14412
14413                 /* Check where is the returned data */
14414                 if ((priv_args[k].get_args & IW_PRIV_SIZE_FIXED) &&
14415                         (get_priv_size(priv_args[k].get_args) <= IFNAMSIZ))
14416                         n = priv_args[k].get_args & IW_PRIV_SIZE_MASK;
14417                 else
14418                         n = wdata.data.length;
14419
14420                 output = rtw_zmalloc(4096);
14421                 if (NULL == output) {
14422                         err =  -ENOMEM;
14423                         goto exit;
14424                 }
14425
14426                 switch (priv_args[k].get_args & IW_PRIV_TYPE_MASK)
14427                 {
14428                         case IW_PRIV_TYPE_BYTE:
14429                                 /* Display args */
14430                                 for (j = 0; j < n; j++)
14431                                 {
14432                                         sprintf(str, "%d  ", extra[j]);
14433                                         len = strlen(str);
14434                                         output_len = strlen(output);
14435                                         if ((output_len + len + 1) > 4096) {
14436                                                 err = -E2BIG;
14437                                                 goto exit;
14438                                         }
14439                                         _rtw_memcpy(output+output_len, str, len);
14440                                 }
14441                                 break;
14442
14443                         case IW_PRIV_TYPE_INT:
14444                                 /* Display args */
14445                                 for (j = 0; j < n; j++)
14446                                 {
14447                                         sprintf(str, "%d  ", ((__s32*)extra)[j]);
14448                                         len = strlen(str);
14449                                         output_len = strlen(output);
14450                                         if ((output_len + len + 1) > 4096) {
14451                                                 err = -E2BIG;
14452                                                 goto exit;
14453                                         }
14454                                         _rtw_memcpy(output+output_len, str, len);
14455                                 }
14456                                 break;
14457
14458                         case IW_PRIV_TYPE_CHAR:
14459                                 /* Display args */
14460                                 _rtw_memcpy(output, extra, n);
14461                                 break;
14462
14463                         default:
14464                                 DBG_8192C("%s: Not yet implemented...\n", __func__);
14465                                 err = -1;
14466                                 goto exit;
14467                 }
14468
14469                 output_len = strlen(output) + 1;
14470                 wrq_data->data.length = output_len;
14471                 if (copy_to_user(wrq_data->data.pointer, output, output_len)) {
14472                         err = -EFAULT;
14473                         goto exit;
14474                 }
14475         }   /* if args to set */
14476         else
14477         {
14478                 wrq_data->data.length = 0;
14479         }
14480
14481 exit:
14482         if (input)
14483                 rtw_mfree(input, input_len);
14484         if (buffer)
14485                 rtw_mfree(buffer, 4096);
14486         if (output)
14487                 rtw_mfree(output, 4096);
14488
14489         return err;
14490 }
14491
14492 int rtw_ioctl(struct net_device *dev, struct ifreq *rq, int cmd)
14493 {
14494         struct iwreq *wrq = (struct iwreq *)rq;
14495         int ret=0;
14496
14497         switch (cmd)
14498         {
14499                 case RTL_IOCTL_WPA_SUPPLICANT:
14500                         ret = wpa_supplicant_ioctl(dev, &wrq->u.data);
14501                         break;
14502 #ifdef CONFIG_AP_MODE
14503                 case RTL_IOCTL_HOSTAPD:
14504                         ret = rtw_hostapd_ioctl(dev, &wrq->u.data);
14505                         break;
14506 #ifdef CONFIG_NO_WIRELESS_HANDLERS
14507                 case SIOCSIWMODE:
14508                         ret = rtw_wx_set_mode(dev, NULL, &wrq->u, NULL);
14509                         break;
14510 #endif
14511 #endif // CONFIG_AP_MODE
14512                 case SIOCDEVPRIVATE:
14513                         ret = rtw_ioctl_wext_private(dev, &wrq->u);
14514                         break;
14515                 case (SIOCDEVPRIVATE+1):
14516                         ret = rtw_android_priv_cmd(dev, rq, cmd);
14517                         break;
14518                 default:
14519                         ret = -EOPNOTSUPP;
14520                         break;
14521         }
14522
14523         return ret;
14524 }
14525
14526