net: wireless: rockchip_wlan: add rtl8188fu support
[firefly-linux-kernel-4.4.55.git] / drivers / net / wireless / rockchip_wlan / rtl8188fu / core / rtw_tdls.c
diff --git a/drivers/net/wireless/rockchip_wlan/rtl8188fu/core/rtw_tdls.c b/drivers/net/wireless/rockchip_wlan/rtl8188fu/core/rtw_tdls.c
new file mode 100644 (file)
index 0000000..a31a3da
--- /dev/null
@@ -0,0 +1,3368 @@
+/******************************************************************************\r
+ *\r
+ * Copyright(c) 2007 - 2011 Realtek Corporation. All rights reserved.\r
+ *                                        \r
+ * This program is free software; you can redistribute it and/or modify it\r
+ * under the terms of version 2 of the GNU General Public License as\r
+ * published by the Free Software Foundation.\r
+ *\r
+ * This program is distributed in the hope that it will be useful, but WITHOUT\r
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or\r
+ * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for\r
+ * more details.\r
+ *\r
+ * You should have received a copy of the GNU General Public License along with\r
+ * this program; if not, write to the Free Software Foundation, Inc.,\r
+ * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA\r
+ *\r
+ *\r
+ ******************************************************************************/\r
+#define _RTW_TDLS_C_\r
+\r
+#include <drv_types.h>\r
+#include <hal_data.h>\r
+\r
+#ifdef CONFIG_TDLS\r
+#define ONE_SEC        1000 /* 1000 ms */\r
+\r
+extern unsigned char MCS_rate_2R[16];\r
+extern unsigned char MCS_rate_1R[16];\r
+extern void process_wmmps_data(_adapter *padapter, union recv_frame *precv_frame);\r
+\r
+void rtw_reset_tdls_info(_adapter* padapter)\r
+{\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+\r
+       ptdlsinfo->ap_prohibited = _FALSE;\r
+       \r
+       /* For TDLS channel switch, currently we only allow it to work in wifi logo test mode */\r
+       if (padapter->registrypriv.wifi_spec == 1)\r
+       {\r
+               ptdlsinfo->ch_switch_prohibited = _FALSE;\r
+       }\r
+       else\r
+       {\r
+               ptdlsinfo->ch_switch_prohibited = _TRUE;\r
+       }\r
+\r
+       ptdlsinfo->link_established = _FALSE;\r
+       ptdlsinfo->sta_cnt = 0;\r
+       ptdlsinfo->sta_maximum = _FALSE;\r
+\r
+#ifdef CONFIG_TDLS_CH_SW\r
+       ptdlsinfo->chsw_info.ch_sw_state = TDLS_STATE_NONE;\r
+       ATOMIC_SET(&ptdlsinfo->chsw_info.chsw_on, _FALSE);\r
+       ptdlsinfo->chsw_info.off_ch_num = 0;\r
+       ptdlsinfo->chsw_info.ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;\r
+       ptdlsinfo->chsw_info.cur_time = 0;\r
+       ptdlsinfo->chsw_info.delay_switch_back = _FALSE;\r
+       ptdlsinfo->chsw_info.dump_stack = _FALSE;\r
+#endif\r
+       \r
+       ptdlsinfo->ch_sensing = 0;\r
+       ptdlsinfo->watchdog_count = 0;\r
+       ptdlsinfo->dev_discovered = _FALSE;\r
+\r
+#ifdef CONFIG_WFD\r
+       ptdlsinfo->wfd_info = &padapter->wfd_info;\r
+#endif\r
+}\r
+\r
+int rtw_init_tdls_info(_adapter* padapter)\r
+{\r
+       int     res = _SUCCESS;\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+\r
+       rtw_reset_tdls_info(padapter);\r
+\r
+       ptdlsinfo->tdls_enable = _TRUE;\r
+#ifdef CONFIG_TDLS_DRIVER_SETUP\r
+       ptdlsinfo->driver_setup = _TRUE;\r
+#else\r
+       ptdlsinfo->driver_setup = _FALSE;\r
+#endif /* CONFIG_TDLS_DRIVER_SETUP */\r
+\r
+       _rtw_spinlock_init(&ptdlsinfo->cmd_lock);\r
+       _rtw_spinlock_init(&ptdlsinfo->hdl_lock);\r
+\r
+       return res;\r
+\r
+}\r
+\r
+void rtw_free_tdls_info(struct tdls_info *ptdlsinfo)\r
+{\r
+       _rtw_spinlock_free(&ptdlsinfo->cmd_lock);\r
+       _rtw_spinlock_free(&ptdlsinfo->hdl_lock);\r
+\r
+       _rtw_memset(ptdlsinfo, 0, sizeof(struct tdls_info) );\r
+\r
+}\r
+\r
+int check_ap_tdls_prohibited(u8 *pframe, u8 pkt_len)\r
+{\r
+       u8 tdls_prohibited_bit = 0x40; /* bit(38); TDLS_prohibited */\r
+\r
+       if (pkt_len < 5) {\r
+               return _FALSE;\r
+       }\r
+\r
+       pframe += 4;\r
+       if ((*pframe) & tdls_prohibited_bit)\r
+               return _TRUE;\r
+\r
+       return _FALSE;\r
+}\r
+\r
+int check_ap_tdls_ch_switching_prohibited(u8 *pframe, u8 pkt_len)\r
+{\r
+       u8 tdls_ch_swithcing_prohibited_bit = 0x80; /* bit(39); TDLS_channel_switching prohibited */\r
+\r
+       if (pkt_len < 5) {\r
+               return _FALSE;\r
+       }\r
+\r
+       pframe += 4;\r
+       if ((*pframe) & tdls_ch_swithcing_prohibited_bit)\r
+               return _TRUE;\r
+\r
+       return _FALSE;\r
+}\r
+\r
+u8 rtw_tdls_is_setup_allowed(_adapter *padapter)\r
+{\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+\r
+       if (ptdlsinfo->ap_prohibited == _TRUE)\r
+               return _FALSE;\r
+\r
+       return _TRUE;\r
+}\r
+\r
+#ifdef CONFIG_TDLS_CH_SW\r
+u8 rtw_tdls_is_chsw_allowed(_adapter *padapter)\r
+{\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+\r
+       if (ptdlsinfo->ch_switch_prohibited == _TRUE)\r
+               return _FALSE;\r
+\r
+       if (padapter->registrypriv.wifi_spec == 0)\r
+               return _FALSE;\r
+\r
+       return _TRUE;\r
+}\r
+#endif\r
+\r
+int _issue_nulldata_to_TDLS_peer_STA(_adapter *padapter, unsigned char *da, unsigned int power_mode, int wait_ack)\r
+{\r
+       int ret = _FAIL;\r
+       struct xmit_frame                       *pmgntframe;\r
+       struct pkt_attrib                       *pattrib;\r
+       unsigned char                                   *pframe;\r
+       struct rtw_ieee80211_hdr        *pwlanhdr;\r
+       unsigned short                          *fctrl, *qc;\r
+       struct xmit_priv                        *pxmitpriv = &(padapter->xmitpriv);\r
+       struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);\r
+       struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+       update_mgntframe_attrib(padapter, pattrib);\r
+\r
+       pattrib->hdrlen +=2;\r
+       pattrib->qos_en = _TRUE;\r
+       pattrib->eosp = 1;\r
+       pattrib->ack_policy = 0;\r
+       pattrib->mdata = 0;     \r
+       pattrib->retry_ctrl = _FALSE;\r
+\r
+       _rtw_memset(pmgntframe->buf_addr, 0, WLANHDR_OFFSET + TXDESC_OFFSET);\r
+\r
+       pframe = (u8 *)(pmgntframe->buf_addr) + TXDESC_OFFSET;\r
+       pwlanhdr = (struct rtw_ieee80211_hdr *)pframe;\r
+\r
+       fctrl = &(pwlanhdr->frame_ctl);\r
+       *(fctrl) = 0;\r
+\r
+       if (power_mode)\r
+               SetPwrMgt(fctrl);\r
+\r
+       qc = (unsigned short *)(pframe + pattrib->hdrlen - 2);\r
+       \r
+       SetPriority(qc, 7);     /* Set priority to VO */\r
+\r
+       SetEOSP(qc, pattrib->eosp);\r
+\r
+       SetAckpolicy(qc, pattrib->ack_policy);\r
+\r
+       _rtw_memcpy(pwlanhdr->addr1, da, ETH_ALEN);\r
+       _rtw_memcpy(pwlanhdr->addr2, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pwlanhdr->addr3, get_my_bssid(&(pmlmeinfo->network)), ETH_ALEN);\r
+\r
+       SetSeqNum(pwlanhdr, pmlmeext->mgnt_seq);\r
+       pmlmeext->mgnt_seq++;\r
+       SetFrameSubType(pframe, WIFI_QOS_DATA_NULL);\r
+\r
+       pframe += sizeof(struct rtw_ieee80211_hdr_3addr_qos);\r
+       pattrib->pktlen = sizeof(struct rtw_ieee80211_hdr_3addr_qos);\r
+\r
+       pattrib->last_txcmdsz = pattrib->pktlen;\r
+\r
+       if (wait_ack)\r
+               ret = dump_mgntframe_and_wait_ack(padapter, pmgntframe);\r
+       else {\r
+               dump_mgntframe(padapter, pmgntframe);\r
+               ret = _SUCCESS;\r
+       }\r
+\r
+exit:\r
+       return ret;\r
+\r
+}\r
+\r
+/*
+ *wait_ms == 0 means that there is no need to wait ack through C2H_CCX_TX_RPT
+ *wait_ms > 0 means you want to wait ack through C2H_CCX_TX_RPT, and the value of wait_ms means the interval between each TX
+ *try_cnt means the maximal TX count to try
+ */
+int issue_nulldata_to_TDLS_peer_STA(_adapter *padapter, unsigned char *da, unsigned int power_mode, int try_cnt, int wait_ms)\r
+{\r
+       int ret;\r
+       int i = 0;\r
+       u32 start = rtw_get_current_time();\r
+       struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);\r
+       struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);\r
+\r
+       #if 0\r
+       psta = rtw_get_stainfo(&padapter->stapriv, da);\r
+       if (psta) {\r
+               if (power_mode)\r
+                       rtw_hal_macid_sleep(padapter, psta->mac_id);\r
+               else\r
+                       rtw_hal_macid_wakeup(padapter, psta->mac_id);\r
+       } else {\r
+               DBG_871X(FUNC_ADPT_FMT ": Can't find sta info for " MAC_FMT ", skip macid %s!!\n",\r
+                       FUNC_ADPT_ARG(padapter), MAC_ARG(da), power_mode?"sleep":"wakeup");\r
+               rtw_warn_on(1);\r
+       }\r
+       #endif\r
+\r
+       do {\r
+               ret = _issue_nulldata_to_TDLS_peer_STA(padapter, da, power_mode, wait_ms>0 ? _TRUE : _FALSE);\r
+\r
+               i++;\r
+\r
+               if (RTW_CANNOT_RUN(padapter))\r
+                       break;\r
+\r
+               if (i < try_cnt && wait_ms > 0 && ret == _FAIL)\r
+                       rtw_msleep_os(wait_ms);\r
+\r
+       } while ((i < try_cnt) && (ret==_FAIL || wait_ms==0));\r
+\r
+       if (ret != _FAIL) {\r
+               ret = _SUCCESS;\r
+               #ifndef DBG_XMIT_ACK\r
+               goto exit;\r
+               #endif\r
+       }\r
+\r
+       if (try_cnt && wait_ms) {\r
+               if (da)\r
+                       DBG_871X(FUNC_ADPT_FMT" to "MAC_FMT", ch:%u%s, %d/%d in %u ms\n",\r
+                               FUNC_ADPT_ARG(padapter), MAC_ARG(da), rtw_get_oper_ch(padapter),\r
+                               ret==_SUCCESS?", acked":"", i, try_cnt, rtw_get_passing_time_ms(start));\r
+               else\r
+                       DBG_871X(FUNC_ADPT_FMT", ch:%u%s, %d/%d in %u ms\n",\r
+                               FUNC_ADPT_ARG(padapter), rtw_get_oper_ch(padapter),\r
+                               ret==_SUCCESS?", acked":"", i, try_cnt, rtw_get_passing_time_ms(start));\r
+       }\r
+exit:\r
+       return ret;\r
+}\r
+\r
+void free_tdls_sta(_adapter *padapter, struct sta_info *ptdls_sta)\r
+{\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       _irqL irqL;\r
+       \r
+       /* free peer sta_info */\r
+       _enter_critical_bh(&(pstapriv->sta_hash_lock), &irqL);\r
+       if (ptdlsinfo->sta_cnt != 0)\r
+               ptdlsinfo->sta_cnt--;\r
+       _exit_critical_bh(&(pstapriv->sta_hash_lock), &irqL);\r
+       /* -2: AP + BC/MC sta, -4: default key */\r
+       if (ptdlsinfo->sta_cnt < MAX_ALLOWED_TDLS_STA_NUM) {\r
+               ptdlsinfo->sta_maximum = _FALSE;\r
+               _rtw_memset( &ptdlsinfo->ss_record, 0x00, sizeof(struct tdls_ss_record) );\r
+       }\r
+\r
+       /* clear cam */\r
+       rtw_clearstakey_cmd(padapter, ptdls_sta, _TRUE);\r
+\r
+       if (ptdlsinfo->sta_cnt == 0) {\r
+               rtw_tdls_cmd(padapter, NULL, TDLS_RS_RCR);\r
+               ptdlsinfo->link_established = _FALSE;\r
+       }\r
+       else\r
+               DBG_871X("Remain tdls sta:%02x\n", ptdlsinfo->sta_cnt);\r
+\r
+       rtw_free_stainfo(padapter,  ptdls_sta);\r
+       \r
+}\r
+\r
+\r
+/* TDLS encryption(if needed) will always be CCMP */\r
+void rtw_tdls_set_key(_adapter *padapter, struct sta_info *ptdls_sta)\r
+{\r
+       ptdls_sta->dot118021XPrivacy=_AES_;\r
+       rtw_setstakey_cmd(padapter, ptdls_sta, TDLS_KEY, _TRUE);\r
+}\r
+\r
+#ifdef CONFIG_80211N_HT\r
+void rtw_tdls_process_ht_cap(_adapter *padapter, struct sta_info *ptdls_sta, u8 *data, u8 Length)\r
+{\r
+       struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;\r
+       struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);\r
+       struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;\r
+       struct ht_priv                  *phtpriv = &pmlmepriv->htpriv;\r
+       u8      max_AMPDU_len, min_MPDU_spacing;\r
+       u8      cur_ldpc_cap = 0, cur_stbc_cap = 0, cur_beamform_cap = 0;\r
+       \r
+       /* Save HT capabilities in the sta object */\r
+       _rtw_memset(&ptdls_sta->htpriv.ht_cap, 0, sizeof(struct rtw_ieee80211_ht_cap));\r
+       if (data && Length >= sizeof(struct rtw_ieee80211_ht_cap)) {\r
+               ptdls_sta->flags |= WLAN_STA_HT;\r
+               ptdls_sta->flags |= WLAN_STA_WME;\r
+\r
+               _rtw_memcpy(&ptdls_sta->htpriv.ht_cap, data, sizeof(struct rtw_ieee80211_ht_cap));                      \r
+       } else\r
+               ptdls_sta->flags &= ~WLAN_STA_HT;\r
+\r
+       if (ptdls_sta->flags & WLAN_STA_HT) {\r
+               if (padapter->registrypriv.ht_enable == _TRUE) {\r
+                       ptdls_sta->htpriv.ht_option = _TRUE;\r
+                       ptdls_sta->qos_option = _TRUE;\r
+               } else {\r
+                       ptdls_sta->htpriv.ht_option = _FALSE;\r
+                       ptdls_sta->qos_option = _FALSE;\r
+               }\r
+       }\r
+\r
+       /* HT related cap */\r
+       if (ptdls_sta->htpriv.ht_option) {\r
+               /* Check if sta supports rx ampdu */\r
+               if (padapter->registrypriv.ampdu_enable == 1)\r
+                       ptdls_sta->htpriv.ampdu_enable = _TRUE;\r
+\r
+               /* AMPDU Parameters field */\r
+               /* Get MIN of MAX AMPDU Length Exp */\r
+               if ((pmlmeinfo->HT_caps.u.HT_cap_element.AMPDU_para & 0x3) > (data[2] & 0x3))\r
+                       max_AMPDU_len = (data[2] & 0x3);\r
+               else\r
+                       max_AMPDU_len = (pmlmeinfo->HT_caps.u.HT_cap_element.AMPDU_para & 0x3);\r
+               /* Get MAX of MIN MPDU Start Spacing */\r
+               if ((pmlmeinfo->HT_caps.u.HT_cap_element.AMPDU_para & 0x1c) > (data[2] & 0x1c))\r
+                       min_MPDU_spacing = (pmlmeinfo->HT_caps.u.HT_cap_element.AMPDU_para & 0x1c);\r
+               else\r
+                       min_MPDU_spacing = (data[2] & 0x1c);\r
+               ptdls_sta->htpriv.rx_ampdu_min_spacing = max_AMPDU_len | min_MPDU_spacing;\r
+\r
+               /* Check if sta support s Short GI 20M */\r
+               if (ptdls_sta->htpriv.ht_cap.cap_info & cpu_to_le16(IEEE80211_HT_CAP_SGI_20))\r
+                       ptdls_sta->htpriv.sgi_20m = _TRUE;\r
+\r
+               /* Check if sta support s Short GI 40M */\r
+               if (ptdls_sta->htpriv.ht_cap.cap_info & cpu_to_le16(IEEE80211_HT_CAP_SGI_40))\r
+                       ptdls_sta->htpriv.sgi_40m = _TRUE;\r
+\r
+               /* Bwmode would still followed AP's setting */\r
+               if (ptdls_sta->htpriv.ht_cap.cap_info & cpu_to_le16(IEEE80211_HT_CAP_SUP_WIDTH)) {\r
+                       if (padapter->mlmeextpriv.cur_bwmode >= CHANNEL_WIDTH_40)\r
+                               ptdls_sta->bw_mode = CHANNEL_WIDTH_40;\r
+                       ptdls_sta->htpriv.ch_offset = padapter->mlmeextpriv.cur_ch_offset;\r
+               }\r
+\r
+               /* Config LDPC Coding Capability */\r
+               if (TEST_FLAG(phtpriv->ldpc_cap, LDPC_HT_ENABLE_TX) && GET_HT_CAP_ELE_LDPC_CAP(data)) {\r
+                       SET_FLAG(cur_ldpc_cap, (LDPC_HT_ENABLE_TX | LDPC_HT_CAP_TX));
+                       DBG_871X("Enable HT Tx LDPC!\n");
+               }
+               ptdls_sta->htpriv.ldpc_cap = cur_ldpc_cap;\r
+
+               /* Config STBC setting */\r
+               if (TEST_FLAG(phtpriv->stbc_cap, STBC_HT_ENABLE_TX) && GET_HT_CAP_ELE_RX_STBC(data)) {\r
+                       SET_FLAG(cur_stbc_cap, (STBC_HT_ENABLE_TX | STBC_HT_CAP_TX));\r
+                       DBG_871X("Enable HT Tx STBC!\n");
+               }
+               ptdls_sta->htpriv.stbc_cap = cur_stbc_cap;\r
+
+#ifdef CONFIG_BEAMFORMING
+               /* Config Tx beamforming setting */\r
+               if (TEST_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE) && 
+                       GET_HT_CAP_TXBF_EXPLICIT_COMP_STEERING_CAP(data)) {\r
+                       SET_FLAG(cur_beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE);
+               }
+
+               if (TEST_FLAG(phtpriv->beamform_cap, BEAMFORMING_HT_BEAMFORMER_ENABLE) &&
+                       GET_HT_CAP_TXBF_EXPLICIT_COMP_FEEDBACK_CAP(data)) {\r
+                       SET_FLAG(cur_beamform_cap, BEAMFORMING_HT_BEAMFORMEE_ENABLE);
+               }
+               ptdls_sta->htpriv.beamform_cap = cur_beamform_cap;\r
+               if (cur_beamform_cap)\r
+                       DBG_871X("Client HT Beamforming Cap = 0x%02X\n", cur_beamform_cap);\r
+#endif /* CONFIG_BEAMFORMING */\r
+       }\r
+\r
+}\r
+\r
+u8 *rtw_tdls_set_ht_cap(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       rtw_ht_use_default_setting(padapter);\r
+\r
+       rtw_restructure_ht_ie(padapter, NULL, pframe, 0, &(pattrib->pktlen), padapter->mlmeextpriv.cur_channel);\r
+\r
+       return pframe + pattrib->pktlen;\r
+}\r
+#endif\r
+\r
+#ifdef CONFIG_80211AC_VHT\r
+void rtw_tdls_process_vht_cap(_adapter *padapter, struct sta_info *ptdls_sta, u8 *data, u8 Length)\r
+{\r
+       struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;\r
+       struct vht_priv                 *pvhtpriv = &pmlmepriv->vhtpriv;\r
+       u8      cur_ldpc_cap = 0, cur_stbc_cap = 0, cur_beamform_cap = 0, rf_type = RF_1T1R;\r
+       u8      *pcap_mcs;\r
+       u8      vht_mcs[2];\r
+       \r
+       _rtw_memset(&ptdls_sta->vhtpriv, 0, sizeof(struct vht_priv));\r
+       if (data && Length == 12) {\r
+               ptdls_sta->flags |= WLAN_STA_VHT;\r
+
+               _rtw_memcpy(ptdls_sta->vhtpriv.vht_cap, data, 12);\r
+\r
+#if 0\r
+               if (elems.vht_op_mode_notify && elems.vht_op_mode_notify_len == 1) {
+                       _rtw_memcpy(&pstat->vhtpriv.vht_op_mode_notify, elems.vht_op_mode_notify, 1);
+               } else /* for Frame without Operating Mode notify ie; default: 80M */ {\r
+                       pstat->vhtpriv.vht_op_mode_notify = CHANNEL_WIDTH_80;
+               }
+#else\r
+               ptdls_sta->vhtpriv.vht_op_mode_notify = CHANNEL_WIDTH_80;\r
+#endif\r
+       } else\r
+               ptdls_sta->flags &= ~WLAN_STA_VHT;\r
+\r
+       if (ptdls_sta->flags & WLAN_STA_VHT) {\r
+               if (REGSTY_IS_11AC_ENABLE(&padapter->registrypriv)\r
+                       && hal_chk_proto_cap(padapter, PROTO_CAP_11AC)\r
+                       && (!pmlmepriv->country_ent || COUNTRY_CHPLAN_EN_11AC(pmlmepriv->country_ent)))\r
+                       ptdls_sta->vhtpriv.vht_option = _TRUE;\r
+               else \r
+                       ptdls_sta->vhtpriv.vht_option = _FALSE;\r
+       }\r
+\r
+       /* B4 Rx LDPC */\r
+       if (TEST_FLAG(pvhtpriv->ldpc_cap, LDPC_VHT_ENABLE_TX) && 
+               GET_VHT_CAPABILITY_ELE_RX_LDPC(data)) {\r
+               SET_FLAG(cur_ldpc_cap, (LDPC_VHT_ENABLE_TX | LDPC_VHT_CAP_TX));
+               DBG_871X("Current VHT LDPC Setting = %02X\n", cur_ldpc_cap);
+       }
+       ptdls_sta->vhtpriv.ldpc_cap = cur_ldpc_cap;\r
+
+       /* B5 Short GI for 80 MHz */\r
+       ptdls_sta->vhtpriv.sgi_80m = (GET_VHT_CAPABILITY_ELE_SHORT_GI80M(data) & pvhtpriv->sgi_80m) ? _TRUE : _FALSE;\r
+\r
+       /* B8 B9 B10 Rx STBC */\r
+       if (TEST_FLAG(pvhtpriv->stbc_cap, STBC_VHT_ENABLE_TX) && 
+               GET_VHT_CAPABILITY_ELE_RX_STBC(data)) {\r
+               SET_FLAG(cur_stbc_cap, (STBC_VHT_ENABLE_TX | STBC_VHT_CAP_TX)); 
+               DBG_871X("Current VHT STBC Setting = %02X\n", cur_stbc_cap);
+       }
+       ptdls_sta->vhtpriv.stbc_cap = cur_stbc_cap;\r
+
+       /* B11 SU Beamformer Capable, the target supports Beamformer and we are Beamformee */\r
+       if (TEST_FLAG(pvhtpriv->beamform_cap, BEAMFORMING_VHT_BEAMFORMER_ENABLE) && 
+               GET_VHT_CAPABILITY_ELE_SU_BFEE(data)) {\r
+               SET_FLAG(cur_beamform_cap, BEAMFORMING_VHT_BEAMFORMEE_ENABLE);
+       }
+
+       /* B12 SU Beamformee Capable, the target supports Beamformee and we are Beamformer */\r
+       if (TEST_FLAG(pvhtpriv->beamform_cap, BEAMFORMING_VHT_BEAMFORMEE_ENABLE) &&
+               GET_VHT_CAPABILITY_ELE_SU_BFER(data)) {\r
+               SET_FLAG(cur_beamform_cap, BEAMFORMING_VHT_BEAMFORMER_ENABLE);
+       }
+       ptdls_sta->vhtpriv.beamform_cap = cur_beamform_cap;\r
+       if (cur_beamform_cap)\r
+               DBG_871X("Current VHT Beamforming Setting = %02X\n", cur_beamform_cap);
+\r
+       /* B23 B24 B25 Maximum A-MPDU Length Exponent */\r
+       ptdls_sta->vhtpriv.ampdu_len = GET_VHT_CAPABILITY_ELE_MAX_RXAMPDU_FACTOR(data);\r
+
+       pcap_mcs = GET_VHT_CAPABILITY_ELE_RX_MCS(data);\r
+       _rtw_memcpy(vht_mcs, pcap_mcs, 2);
+
+       rtw_hal_get_hwreg(padapter, HW_VAR_RF_TYPE, (u8 *)(&rf_type));
+       if ((rf_type == RF_1T1R) || (rf_type == RF_1T2R))
+               vht_mcs[0] |= 0xfc;
+       else if (rf_type == RF_2T2R)
+               vht_mcs[0] |= 0xf0;
+       else if (rf_type == RF_3T3R)
+               vht_mcs[0] |= 0xc0;
+
+       _rtw_memcpy(ptdls_sta->vhtpriv.vht_mcs_map, vht_mcs, 2);\r
+
+       ptdls_sta->vhtpriv.vht_highest_rate = rtw_get_vht_highest_rate(ptdls_sta->vhtpriv.vht_mcs_map);\r
+}\r
+\r
+u8 *rtw_tdls_set_aid(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       return rtw_set_ie(pframe, EID_AID, 2, (u8 *)&(padapter->mlmepriv.cur_network.aid), &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_vht_cap(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       u32 ie_len = 0;\r
+       \r
+       rtw_vht_use_default_setting(padapter);\r
+\r
+       ie_len = rtw_build_vht_cap_ie(padapter, pframe);\r
+       pattrib->pktlen += ie_len;\r
+       \r
+       return pframe + ie_len;\r
+}\r
+\r
+u8 *rtw_tdls_set_vht_operation(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib, u8 channel)\r
+{\r
+       u32 ie_len = 0;\r
+\r
+       ie_len = rtw_build_vht_operation_ie(padapter, pframe, channel);\r
+       pattrib->pktlen += ie_len;\r
+       \r
+       return pframe + ie_len;\r
+}\r
+\r
+u8 *rtw_tdls_set_vht_op_mode_notify(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib, u8 bw)\r
+{\r
+       u32 ie_len = 0;\r
+       \r
+       ie_len = rtw_build_vht_op_mode_notify_ie(padapter, pframe, bw);\r
+       pattrib->pktlen += ie_len;\r
+\r
+       return pframe + ie_len;\r
+}\r
+#endif\r
+\r
+\r
+u8 *rtw_tdls_set_sup_ch(struct mlme_ext_priv *pmlmeext, u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       u8 sup_ch[30 * 2] = {0x00}, ch_set_idx = 0, sup_ch_idx = 2;     \r
+\r
+       do {\r
+               if (pmlmeext->channel_set[ch_set_idx].ChannelNum <= 14) {\r
+                       sup_ch[0] = 1;  /* First channel number */\r
+                       sup_ch[1] = pmlmeext->channel_set[ch_set_idx].ChannelNum;       /* Number of channel */\r
+               } else {\r
+                       sup_ch[sup_ch_idx++] = pmlmeext->channel_set[ch_set_idx].ChannelNum;\r
+                       sup_ch[sup_ch_idx++] = 1;\r
+               }\r
+               ch_set_idx++;\r
+       } while (pmlmeext->channel_set[ch_set_idx].ChannelNum != 0 && ch_set_idx < MAX_CHANNEL_NUM);\r
+\r
+       return rtw_set_ie(pframe, _SUPPORTED_CH_IE_, sup_ch_idx, sup_ch, &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_rsnie(struct tdls_txmgmt *ptxmgmt, u8 *pframe, struct pkt_attrib *pattrib,  int init, struct sta_info *ptdls_sta)\r
+{\r
+       u8 *p = NULL;\r
+       int len = 0;\r
+\r
+       if (ptxmgmt->len > 0)\r
+               p = rtw_get_ie(ptxmgmt->buf, _RSN_IE_2_, &len, ptxmgmt->len);\r
+\r
+       if (p != NULL)\r
+               return rtw_set_ie(pframe, _RSN_IE_2_, len, p+2, &(pattrib->pktlen));\r
+       else\r
+               if (init == _TRUE)\r
+                       return rtw_set_ie(pframe, _RSN_IE_2_, sizeof(TDLS_RSNIE), TDLS_RSNIE, &(pattrib->pktlen));\r
+               else\r
+                       return rtw_set_ie(pframe, _RSN_IE_2_, sizeof(ptdls_sta->TDLS_RSNIE), ptdls_sta->TDLS_RSNIE, &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_ext_cap(u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       return rtw_set_ie(pframe, _EXT_CAP_IE_ , sizeof(TDLS_EXT_CAPIE), TDLS_EXT_CAPIE, &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_qos_cap(u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       return rtw_set_ie(pframe, _VENDOR_SPECIFIC_IE_, sizeof(TDLS_WMMIE), TDLS_WMMIE,  &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_ftie(struct tdls_txmgmt *ptxmgmt, u8 *pframe, struct pkt_attrib *pattrib, u8 *ANonce, u8 *SNonce)\r
+{\r
+       struct wpa_tdls_ftie FTIE = {0};\r
+       u8 *p = NULL;\r
+       int len = 0;\r
+\r
+       if (ptxmgmt->len > 0)\r
+               p = rtw_get_ie(ptxmgmt->buf, _FTIE_, &len, ptxmgmt->len);\r
+\r
+       if (p != NULL)\r
+               return rtw_set_ie(pframe, _FTIE_, len, p+2, &(pattrib->pktlen));\r
+       else {\r
+               if (ANonce != NULL)\r
+                       _rtw_memcpy(FTIE.Anonce, ANonce, WPA_NONCE_LEN);\r
+               if (SNonce != NULL)\r
+                       _rtw_memcpy(FTIE.Snonce, SNonce, WPA_NONCE_LEN);\r
+               return rtw_set_ie(pframe, _FTIE_ , 82, (u8 *)FTIE.mic_ctrl, &(pattrib->pktlen));\r
+       }\r
+}\r
+\r
+u8 *rtw_tdls_set_timeout_interval(struct tdls_txmgmt *ptxmgmt, u8 *pframe, struct pkt_attrib *pattrib, int init, struct sta_info *ptdls_sta)\r
+{\r
+       u8 timeout_itvl[5];     /* set timeout interval to maximum value */\r
+       u32 timeout_interval= TDLS_TPK_RESEND_COUNT;\r
+       u8 *p = NULL;\r
+       int len = 0;\r
+\r
+       if (ptxmgmt->len > 0)\r
+               p = rtw_get_ie(ptxmgmt->buf, _TIMEOUT_ITVL_IE_, &len, ptxmgmt->len);\r
+\r
+       if (p != NULL)\r
+               return rtw_set_ie(pframe, _TIMEOUT_ITVL_IE_, len, p+2, &(pattrib->pktlen));\r
+       else {\r
+               /* Timeout interval */\r
+               timeout_itvl[0]=0x02;\r
+               if (init == _TRUE)\r
+                       _rtw_memcpy(timeout_itvl+1, &timeout_interval, 4);\r
+               else\r
+                       _rtw_memcpy(timeout_itvl+1, (u8 *)(&ptdls_sta->TDLS_PeerKey_Lifetime), 4);\r
+\r
+               return rtw_set_ie(pframe, _TIMEOUT_ITVL_IE_, 5, timeout_itvl, &(pattrib->pktlen));\r
+       }\r
+}\r
+\r
+u8 *rtw_tdls_set_bss_coexist(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       u8 iedata=0;\r
+\r
+       if (padapter->mlmepriv.num_FortyMHzIntolerant > 0)\r
+               iedata |= BIT(2);       /* 20 MHz BSS Width Request */\r
+\r
+       /* Information Bit should be set by TDLS test plan 5.9 */\r
+       iedata |= BIT(0);\r
+       return rtw_set_ie(pframe, EID_BSSCoexistence, 1, &iedata, &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_payload_type(u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       u8 payload_type = 0x02;\r
+       return rtw_set_fixed_ie(pframe, 1, &(payload_type), &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_category(u8 *pframe, struct pkt_attrib *pattrib, u8 category)\r
+{\r
+       return rtw_set_fixed_ie(pframe, 1, &(category), &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_action(u8 *pframe, struct pkt_attrib *pattrib, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       return rtw_set_fixed_ie(pframe, 1, &(ptxmgmt->action_code), &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_status_code(u8 *pframe, struct pkt_attrib *pattrib, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       return rtw_set_fixed_ie(pframe, 2, (u8 *)&(ptxmgmt->status_code), &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_dialog(u8 *pframe, struct pkt_attrib *pattrib, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       u8 dialogtoken = 1;\r
+       if (ptxmgmt->dialog_token)\r
+               return rtw_set_fixed_ie(pframe, 1, &(ptxmgmt->dialog_token), &(pattrib->pktlen));\r
+       else\r
+               return rtw_set_fixed_ie(pframe, 1, &(dialogtoken), &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_reg_class(u8 *pframe, struct pkt_attrib *pattrib, struct sta_info *ptdls_sta)\r
+{\r
+       u8 reg_class = 22;\r
+       return rtw_set_fixed_ie(pframe, 1, &(reg_class), &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_second_channel_offset(u8 *pframe, struct pkt_attrib *pattrib, u8 ch_offset)\r
+{\r
+       return rtw_set_ie(pframe, EID_SecondaryChnlOffset , 1, &ch_offset, &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_capability(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;\r
+       struct mlme_ext_info    *pmlmeinfo = &pmlmeext->mlmext_info;\r
+       u8 cap_from_ie[2] = {0};\r
+\r
+       _rtw_memcpy(cap_from_ie, rtw_get_capability_from_ie(pmlmeinfo->network.IEs), 2);\r
+\r
+       return rtw_set_fixed_ie(pframe, 2, cap_from_ie, &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_supported_rate(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       u8 bssrate[NDIS_802_11_LENGTH_RATES_EX];\r
+       int bssrate_len = 0;\r
+       u8 more_supportedrates = 0;\r
+\r
+       rtw_set_supported_rate(bssrate, (padapter->registrypriv.wireless_mode == WIRELESS_MODE_MAX) ? padapter->mlmeextpriv.cur_wireless_mode : padapter->registrypriv.wireless_mode); \r
+       bssrate_len = rtw_get_rateset_len(bssrate);\r
+\r
+       if (bssrate_len > 8) {\r
+               pframe = rtw_set_ie(pframe, _SUPPORTEDRATES_IE_ , 8, bssrate, &(pattrib->pktlen));\r
+               more_supportedrates = 1;\r
+       } else {\r
+               pframe = rtw_set_ie(pframe, _SUPPORTEDRATES_IE_ , bssrate_len , bssrate, &(pattrib->pktlen));\r
+       }\r
+\r
+       /* extended supported rates */\r
+       if (more_supportedrates == 1) {\r
+               pframe = rtw_set_ie(pframe, _EXT_SUPPORTEDRATES_IE_ , (bssrate_len - 8), (bssrate + 8), &(pattrib->pktlen));\r
+       }\r
+\r
+       return pframe;\r
+}\r
+\r
+u8 *rtw_tdls_set_sup_reg_class(u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       return rtw_set_ie(pframe, _SRC_IE_ , sizeof(TDLS_SRC), TDLS_SRC, &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_linkid(u8 *pframe, struct pkt_attrib *pattrib, u8 init)\r
+{\r
+       u8 link_id_addr[18] = {0};\r
+       if (init == _TRUE) {\r
+               _rtw_memcpy(link_id_addr, pattrib->ra, 6);\r
+               _rtw_memcpy((link_id_addr+6), pattrib->src, 6);\r
+               _rtw_memcpy((link_id_addr+12), pattrib->dst, 6);\r
+       } else {\r
+               _rtw_memcpy(link_id_addr, pattrib->ra, 6);\r
+               _rtw_memcpy((link_id_addr+6), pattrib->dst, 6);\r
+               _rtw_memcpy((link_id_addr+12), pattrib->src, 6);\r
+       }\r
+       return rtw_set_ie(pframe, _LINK_ID_IE_, 18, link_id_addr, &(pattrib->pktlen));\r
+}\r
+\r
+#ifdef CONFIG_TDLS_CH_SW\r
+u8 *rtw_tdls_set_target_ch(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       u8 target_ch = 1;\r
+       if (padapter->tdlsinfo.chsw_info.off_ch_num)\r
+               return rtw_set_fixed_ie(pframe, 1, &(padapter->tdlsinfo.chsw_info.off_ch_num), &(pattrib->pktlen));\r
+       else\r
+               return rtw_set_fixed_ie(pframe, 1, &(target_ch), &(pattrib->pktlen));\r
+}\r
+\r
+u8 *rtw_tdls_set_ch_sw(u8 *pframe, struct pkt_attrib *pattrib, struct sta_info *ptdls_sta)\r
+{\r
+       u8 ch_switch_timing[4] = {0};\r
+       u16 switch_time = (ptdls_sta->ch_switch_time >= TDLS_CH_SWITCH_TIME * 1000) ? \r
+               ptdls_sta->ch_switch_time : TDLS_CH_SWITCH_TIME;\r
+       u16 switch_timeout = (ptdls_sta->ch_switch_timeout >= TDLS_CH_SWITCH_TIMEOUT * 1000) ? \r
+               ptdls_sta->ch_switch_timeout : TDLS_CH_SWITCH_TIMEOUT;\r
+\r
+       _rtw_memcpy(ch_switch_timing, &switch_time, 2);\r
+       _rtw_memcpy(ch_switch_timing + 2, &switch_timeout, 2);\r
+\r
+       return rtw_set_ie(pframe, _CH_SWITCH_TIMING_,  4, ch_switch_timing, &(pattrib->pktlen));\r
+}\r
+\r
+void rtw_tdls_set_ch_sw_oper_control(_adapter *padapter, u8 enable)\r
+{\r
+       if (ATOMIC_READ(&padapter->tdlsinfo.chsw_info.chsw_on) != enable)\r
+               ATOMIC_SET(&padapter->tdlsinfo.chsw_info.chsw_on, enable);\r
+\r
+       rtw_hal_set_hwreg(padapter, HW_VAR_TDLS_BCN_EARLY_C2H_RPT, &enable);\r
+       DBG_871X("[TDLS] %s Bcn Early C2H Report\n", (enable == _TRUE) ? "Start" : "Stop");\r
+}\r
+\r
+void rtw_tdls_ch_sw_back_to_base_chnl(_adapter *padapter)\r
+{\r
+       struct mlme_priv *pmlmepriv;\r
+       struct tdls_ch_switch *pchsw_info = &padapter->tdlsinfo.chsw_info;\r
+\r
+       pmlmepriv = &padapter->mlmepriv;\r
+\r
+       if ((ATOMIC_READ(&pchsw_info->chsw_on) == _TRUE) &&\r
+       /* Sometimes we receive multiple interrupts in very little time period, use the follow condition test to filter */\r
+       //(pchsw_info->cur_time - last_time > padapter->mlmeextpriv.mlmext_info.bcn_interval - 5) &&\r
+       (padapter->mlmeextpriv.cur_channel != rtw_get_oper_ch(padapter))) {\r
+               //if(pchsw_info->ch_sw_state & TDLS_CH_SW_INITIATOR_STATE)                              \r
+               rtw_tdls_cmd(padapter, pchsw_info->addr, TDLS_CH_SW_TO_BASE_CHNL_UNSOLICITED);\r
+       }                       \r
+}\r
+\r
+static void rtw_tdls_chsw_oper_init(_adapter* padapter, u32 timeout_ms)\r
+{\r
+       struct submit_ctx       *chsw_sctx = &padapter->tdlsinfo.chsw_info.chsw_sctx;\r
+       \r
+       rtw_sctx_init(chsw_sctx, timeout_ms);\r
+}\r
+\r
+static int rtw_tdls_chsw_oper_wait(_adapter* padapter)\r
+{\r
+       struct submit_ctx       *chsw_sctx = &padapter->tdlsinfo.chsw_info.chsw_sctx;\r
+\r
+       return rtw_sctx_wait(chsw_sctx, __func__);\r
+}\r
+\r
+void rtw_tdls_chsw_oper_done(_adapter* padapter)\r
+{\r
+       struct submit_ctx       *chsw_sctx = &padapter->tdlsinfo.chsw_info.chsw_sctx;\r
+       \r
+       rtw_sctx_done(&chsw_sctx);\r
+}\r
+\r
+s32 rtw_tdls_do_ch_sw(_adapter *padapter, struct sta_info *ptdls_sta, u8 chnl_type, u8 channel, u8 channel_offset, u16 bwmode, u16 ch_switch_time)\r
+{\r
+       HAL_DATA_TYPE *pHalData = GET_HAL_DATA(padapter);\r
+       u8 center_ch, chnl_offset80 = HAL_PRIME_CHNL_OFFSET_DONT_CARE;\r
+       u32 ch_sw_time_start, ch_sw_time_spent, wait_time;\r
+       u8 take_care_iqk;\r
+       s32 ret = _FAIL;\r
+\r
+       ch_sw_time_start = rtw_systime_to_ms(rtw_get_current_time());\r
+\r
+       rtw_tdls_chsw_oper_init(padapter, TDLS_CH_SWITCH_OPER_OFFLOAD_TIMEOUT);\r
+\r
+       /* set mac_id sleep before channel switch */\r
+       rtw_hal_macid_sleep(padapter, ptdls_sta->mac_id);\r
+       \r
+       /* channel switch IOs offload to FW */\r
+       if (rtw_hal_ch_sw_oper_offload(padapter, channel, channel_offset, bwmode) == _SUCCESS) {\r
+               if (rtw_tdls_chsw_oper_wait(padapter) == _SUCCESS) {\r
+                       /* set channel and bw related variables in driver */\r
+                       _enter_critical_mutex(&(adapter_to_dvobj(padapter)->setch_mutex), NULL);\r
+\r
+                       rtw_set_oper_ch(padapter, channel);     \r
+                       rtw_set_oper_choffset(padapter, channel_offset);\r
+                       rtw_set_oper_bw(padapter, bwmode);      \r
+\r
+                       center_ch = rtw_get_center_ch(channel, bwmode, channel_offset);\r
+                       pHalData->CurrentChannel = center_ch;\r
+                       pHalData->CurrentCenterFrequencyIndex1 = center_ch;\r
+                       pHalData->CurrentChannelBW = bwmode;\r
+                       pHalData->nCur40MhzPrimeSC = channel_offset;\r
+\r
+                       if (bwmode == CHANNEL_WIDTH_80) {\r
+                               if (center_ch > channel)\r
+                                       chnl_offset80 = HAL_PRIME_CHNL_OFFSET_LOWER;\r
+                               else if (center_ch < channel)\r
+                                       chnl_offset80 = HAL_PRIME_CHNL_OFFSET_UPPER;\r
+                               else\r
+                                       chnl_offset80 = HAL_PRIME_CHNL_OFFSET_DONT_CARE;\r
+                       }\r
+                       pHalData->nCur80MhzPrimeSC = chnl_offset80;\r
+\r
+                       pHalData->CurrentCenterFrequencyIndex1 = center_ch;\r
+                       \r
+                       _exit_critical_mutex(&(adapter_to_dvobj(padapter)->setch_mutex), NULL);\r
+\r
+                       rtw_hal_get_hwreg(padapter, HW_VAR_CH_SW_NEED_TO_TAKE_CARE_IQK_INFO, &take_care_iqk);\r
+                       if (take_care_iqk == _TRUE)\r
+                               rtw_hal_ch_sw_iqk_info_restore(padapter, CH_SW_USE_CASE_TDLS);\r
+\r
+                       ch_sw_time_spent = rtw_systime_to_ms(rtw_get_current_time()) - ch_sw_time_start;\r
+\r
+                       if (chnl_type == TDLS_CH_SW_OFF_CHNL) {\r
+                               if ((u32)ch_switch_time /1000 > ch_sw_time_spent)\r
+                                       wait_time = (u32)ch_switch_time /1000 - ch_sw_time_spent;\r
+                               else\r
+                                       wait_time = 0;\r
+\r
+                               if (wait_time > 0)\r
+                                       rtw_msleep_os(wait_time);\r
+                       }\r
+\r
+                       ret = _SUCCESS;\r
+               } else\r
+                       DBG_871X("[TDLS] chsw oper wait fail !!\n");\r
+       }               \r
+\r
+       /* set mac_id wakeup after channel switch */\r
+       rtw_hal_macid_wakeup(padapter, ptdls_sta->mac_id);\r
+\r
+       return ret;\r
+}\r
+#endif\r
+\r
+u8 *rtw_tdls_set_wmm_params(_adapter *padapter, u8 *pframe, struct pkt_attrib *pattrib)\r
+{\r
+       struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);   \r
+       struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);\r
+       u8 wmm_param_ele[24] = {0};\r
+\r
+       if (&pmlmeinfo->WMM_param) {\r
+               _rtw_memcpy(wmm_param_ele, WMM_PARA_OUI, 6);\r
+               if (_rtw_memcmp(&pmlmeinfo->WMM_param, &wmm_param_ele[6], 18) == _TRUE)\r
+                       /* Use default WMM Param */\r
+                       _rtw_memcpy(wmm_param_ele + 6, (u8 *)&TDLS_WMM_PARAM_IE, sizeof(TDLS_WMM_PARAM_IE));\r
+               else    \r
+                       _rtw_memcpy(wmm_param_ele + 6, (u8 *)&pmlmeinfo->WMM_param, sizeof(pmlmeinfo->WMM_param));\r
+               return rtw_set_ie(pframe, _VENDOR_SPECIFIC_IE_,  24, wmm_param_ele, &(pattrib->pktlen));                \r
+       }\r
+       else\r
+               return pframe;\r
+}\r
+\r
+#ifdef CONFIG_WFD\r
+void rtw_tdls_process_wfd_ie(struct tdls_info *ptdlsinfo, u8 *ptr, u8 length)\r
+{\r
+       u8 *wfd_ie;\r
+       u32     wfd_ielen = 0;\r
+\r
+       if (!hal_chk_wl_func(tdls_info_to_adapter(ptdlsinfo), WL_FUNC_MIRACAST))\r
+               return;\r
+\r
+       /* Try to get the TCP port information when receiving the negotiation response. */\r
+\r
+       wfd_ie = rtw_get_wfd_ie(ptr, length, NULL, &wfd_ielen);\r
+       while (wfd_ie) {\r
+               u8 *attr_content;\r
+               u32     attr_contentlen = 0;\r
+               int     i;\r
+\r
+               DBG_871X( "[%s] WFD IE Found!!\n", __FUNCTION__ );\r
+               attr_content = rtw_get_wfd_attr_content(wfd_ie, wfd_ielen, WFD_ATTR_DEVICE_INFO, NULL, &attr_contentlen);\r
+               if (attr_content && attr_contentlen) {\r
+                       ptdlsinfo->wfd_info->peer_rtsp_ctrlport = RTW_GET_BE16( attr_content + 2 );\r
+                       DBG_871X( "[%s] Peer PORT NUM = %d\n", __FUNCTION__, ptdlsinfo->wfd_info->peer_rtsp_ctrlport );\r
+               }\r
+\r
+               attr_content = rtw_get_wfd_attr_content(wfd_ie, wfd_ielen, WFD_ATTR_LOCAL_IP_ADDR, NULL, &attr_contentlen);\r
+               if (attr_content && attr_contentlen) {\r
+                       _rtw_memcpy(ptdlsinfo->wfd_info->peer_ip_address, ( attr_content + 1 ), 4);\r
+                       DBG_871X("[%s] Peer IP = %02u.%02u.%02u.%02u\n", __FUNCTION__, \r
+                               ptdlsinfo->wfd_info->peer_ip_address[0], ptdlsinfo->wfd_info->peer_ip_address[1],\r
+                               ptdlsinfo->wfd_info->peer_ip_address[2], ptdlsinfo->wfd_info->peer_ip_address[3]);\r
+               }\r
+\r
+               wfd_ie = rtw_get_wfd_ie(wfd_ie + wfd_ielen, (ptr + length) - (wfd_ie + wfd_ielen), NULL, &wfd_ielen);\r
+       }\r
+}\r
+\r
+int issue_tunneled_probe_req(_adapter *padapter)\r
+{\r
+       struct xmit_frame                       *pmgntframe;\r
+       struct pkt_attrib                       *pattrib;\r
+       struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;\r
+       struct xmit_priv                        *pxmitpriv = &(padapter->xmitpriv);\r
+       u8 baddr[ETH_ALEN] = {0xff, 0xff, 0xff, 0xff, 0xff, 0xff}; \r
+       struct tdls_txmgmt txmgmt;\r
+       int ret = _FAIL;\r
+\r
+       DBG_871X("[%s]\n", __FUNCTION__);\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       txmgmt.action_code = TUNNELED_PROBE_REQ;\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, baddr, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(pmlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, &txmgmt) != _SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;\r
+       }\r
+       dump_mgntframe(padapter, pmgntframe);\r
+       ret = _SUCCESS;\r
+exit:\r
+\r
+       return ret;\r
+}\r
+\r
+int issue_tunneled_probe_rsp(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct xmit_frame                       *pmgntframe;\r
+       struct pkt_attrib                       *pattrib;\r
+       struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;\r
+       struct xmit_priv                        *pxmitpriv = &(padapter->xmitpriv);\r
+       struct tdls_txmgmt txmgmt;\r
+       int ret = _FAIL;\r
+\r
+       DBG_871X("[%s]\n", __FUNCTION__);\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       txmgmt.action_code = TUNNELED_PROBE_RSP;\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, precv_frame->u.hdr.attrib.src, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(pmlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, &txmgmt) != _SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;\r
+       }\r
+       dump_mgntframe(padapter, pmgntframe);\r
+       ret = _SUCCESS;\r
+exit:\r
+\r
+       return ret;\r
+}\r
+#endif /* CONFIG_WFD */\r
+\r
+int issue_tdls_setup_req(_adapter *padapter, struct tdls_txmgmt *ptxmgmt, int wait_ack)\r
+{\r
+       struct tdls_info        *ptdlsinfo = &padapter->tdlsinfo;\r
+       struct xmit_frame                       *pmgntframe;\r
+       struct pkt_attrib                       *pattrib;\r
+       struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;\r
+       struct xmit_priv                        *pxmitpriv = &(padapter->xmitpriv);\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       struct sta_info *ptdls_sta= NULL;\r
+       _irqL irqL;\r
+       int ret = _FAIL;\r
+       /* Retry timer should be set at least 301 sec, using TPK_count counting 301 times. */\r
+       u32 timeout_interval= TDLS_TPK_RESEND_COUNT;\r
+\r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+\r
+       ptxmgmt->action_code = TDLS_SETUP_REQUEST;\r
+       if (rtw_tdls_is_setup_allowed(padapter) == _FALSE)\r
+               goto exit;\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, ptxmgmt->peer, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(pmlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+\r
+       /* init peer sta_info */\r
+       ptdls_sta = rtw_get_stainfo(pstapriv, ptxmgmt->peer);\r
+       if (ptdls_sta == NULL) {\r
+               ptdls_sta = rtw_alloc_stainfo(pstapriv, ptxmgmt->peer);\r
+               if (ptdls_sta == NULL) {\r
+                       DBG_871X("[%s] rtw_alloc_stainfo fail\n", __FUNCTION__);        \r
+                       rtw_free_xmitbuf(pxmitpriv,pmgntframe->pxmitbuf);\r
+                       rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+                       goto exit;\r
+               }\r
+       }\r
+       \r
+       if(!(ptdls_sta->tdls_sta_state & TDLS_LINKED_STATE))\r
+               ptdlsinfo->sta_cnt++;\r
+\r
+       if (ptdlsinfo->sta_cnt == MAX_ALLOWED_TDLS_STA_NUM)\r
+               ptdlsinfo->sta_maximum  = _TRUE;\r
+\r
+       ptdls_sta->tdls_sta_state |= TDLS_RESPONDER_STATE;\r
+\r
+       if (rtw_tdls_is_driver_setup(padapter) == _TRUE) {\r
+               ptdls_sta->TDLS_PeerKey_Lifetime = timeout_interval;\r
+               _set_timer(&ptdls_sta->handshake_timer, TDLS_HANDSHAKE_TIME);\r
+       }\r
+\r
+       pattrib->qsel = pattrib->priority;\r
+\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, ptxmgmt) !=_SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv,pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;\r
+       }\r
+\r
+       if (wait_ack) {\r
+               ret = dump_mgntframe_and_wait_ack(padapter, pmgntframe);\r
+       } else {\r
+               dump_mgntframe(padapter, pmgntframe);\r
+               ret = _SUCCESS;\r
+       }\r
+\r
+exit:\r
+\r
+       return ret;\r
+}\r
+\r
+int _issue_tdls_teardown(_adapter *padapter, struct tdls_txmgmt *ptxmgmt, u8 wait_ack)\r
+{\r
+       struct xmit_frame                       *pmgntframe;\r
+       struct pkt_attrib                       *pattrib;\r
+       struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;\r
+       struct xmit_priv                        *pxmitpriv = &(padapter->xmitpriv);\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       struct sta_info *ptdls_sta=NULL;\r
+       _irqL irqL;\r
+       int ret = _FAIL;\r
+\r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+\r
+       ptxmgmt->action_code = TDLS_TEARDOWN;\r
+       ptdls_sta = rtw_get_stainfo(pstapriv, ptxmgmt->peer);\r
+       if (ptdls_sta == NULL) {\r
+               DBG_871X("Np tdls_sta for tearing down\n");\r
+               goto exit;\r
+       }\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       rtw_set_scan_deny(padapter, 550);\r
+\r
+       rtw_scan_abort(padapter);\r
+#ifdef CONFIG_CONCURRENT_MODE          \r
+       if (rtw_buddy_adapter_up(padapter))     \r
+               rtw_scan_abort(padapter->pbuddy_adapter);\r
+#endif /* CONFIG_CONCURRENT_MODE */\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, ptxmgmt->peer, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(pmlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, ptxmgmt) != _SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;\r
+       }\r
+\r
+       if (rtw_tdls_is_driver_setup(padapter) == _TRUE) \r
+               if(ptdls_sta->tdls_sta_state & TDLS_LINKED_STATE)\r
+                       if (pattrib->encrypt) \r
+                               _cancel_timer_ex(&ptdls_sta->TPK_timer);\r
+\r
+       if (wait_ack) {\r
+               ret = dump_mgntframe_and_wait_ack(padapter, pmgntframe);\r
+       } else {\r
+               dump_mgntframe(padapter, pmgntframe);\r
+               ret = _SUCCESS;\r
+       }\r
+\r
+       if (rtw_tdls_is_driver_setup(padapter))\r
+               rtw_tdls_cmd(padapter, ptxmgmt->peer, TDLS_TEARDOWN_STA_LOCALLY);\r
+\r
+exit:\r
+\r
+       return ret;\r
+}\r
+\r
+int issue_tdls_teardown(_adapter *padapter, struct tdls_txmgmt *ptxmgmt, u8 wait_ack)\r
+{\r
+       int ret = _FAIL;\r
+       \r
+       ret = _issue_tdls_teardown(padapter, ptxmgmt, wait_ack);\r
+       if ((ptxmgmt->status_code == _RSON_TDLS_TEAR_UN_RSN_) && (ret == _FAIL)) {\r
+               /* Change status code and send teardown again via AP */\r
+               ptxmgmt->status_code = _RSON_TDLS_TEAR_TOOFAR_;\r
+               ret = _issue_tdls_teardown(padapter, ptxmgmt, wait_ack);\r
+       }\r
+\r
+       return ret;\r
+}\r
+\r
+int issue_tdls_dis_req(_adapter *padapter, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct xmit_frame                       *pmgntframe;\r
+       struct pkt_attrib                       *pattrib;\r
+       struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;\r
+       struct xmit_priv                        *pxmitpriv = &(padapter->xmitpriv);\r
+       int ret = _FAIL;\r
+       \r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+       \r
+       ptxmgmt->action_code = TDLS_DISCOVERY_REQUEST;\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, ptxmgmt->peer, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(pmlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, ptxmgmt) != _SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;\r
+       }\r
+       dump_mgntframe(padapter, pmgntframe);\r
+       DBG_871X("issue tdls dis req\n");\r
+\r
+       ret = _SUCCESS;\r
+exit:\r
+\r
+       return ret;\r
+}\r
+\r
+int issue_tdls_setup_rsp(_adapter *padapter, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct xmit_frame                       *pmgntframe;\r
+       struct pkt_attrib                       *pattrib;\r
+       struct xmit_priv                        *pxmitpriv = &(padapter->xmitpriv);\r
+       int ret = _FAIL;\r
+\r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+\r
+       ptxmgmt->action_code = TDLS_SETUP_RESPONSE;             \r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, ptxmgmt->peer, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(&(padapter->mlmepriv)), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, ptxmgmt) != _SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;\r
+       }\r
+\r
+       dump_mgntframe(padapter, pmgntframe);\r
+\r
+       ret = _SUCCESS;\r
+exit:\r
+\r
+       return ret;\r
+\r
+}\r
+\r
+int issue_tdls_setup_cfm(_adapter *padapter, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+       struct xmit_frame                       *pmgntframe;\r
+       struct pkt_attrib                       *pattrib;\r
+       struct xmit_priv                        *pxmitpriv = &(padapter->xmitpriv);\r
+       int ret = _FAIL;\r
+       \r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+       \r
+       ptxmgmt->action_code = TDLS_SETUP_CONFIRM;\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, ptxmgmt->peer, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(&padapter->mlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, ptxmgmt) != _SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;              \r
+       }\r
+\r
+       dump_mgntframe(padapter, pmgntframe);\r
+\r
+       ret = _SUCCESS;\r
+exit:\r
+\r
+       return ret;\r
+\r
+}\r
+\r
+/* TDLS Discovery Response frame is a management action frame */\r
+int issue_tdls_dis_rsp(_adapter *padapter, struct tdls_txmgmt *ptxmgmt, u8 privacy)\r
+{\r
+       struct xmit_frame               *pmgntframe;\r
+       struct pkt_attrib               *pattrib;\r
+       unsigned char                   *pframe;\r
+       struct rtw_ieee80211_hdr        *pwlanhdr;\r
+       unsigned short          *fctrl;\r
+       struct xmit_priv                *pxmitpriv = &(padapter->xmitpriv);\r
+       struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);\r
+       int ret = _FAIL;\r
+\r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+       update_mgntframe_attrib(padapter, pattrib);\r
+\r
+       _rtw_memset(pmgntframe->buf_addr, 0, WLANHDR_OFFSET + TXDESC_OFFSET);\r
+\r
+       pframe = (u8 *)(pmgntframe->buf_addr) + TXDESC_OFFSET;\r
+       pwlanhdr = (struct rtw_ieee80211_hdr *)pframe;\r
+\r
+       fctrl = &(pwlanhdr->frame_ctl);\r
+       *(fctrl) = 0;\r
+\r
+       /* unicast probe request frame */\r
+       _rtw_memcpy(pwlanhdr->addr1, ptxmgmt->peer, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->dst, pwlanhdr->addr1, ETH_ALEN);\r
+       _rtw_memcpy(pwlanhdr->addr2, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, pwlanhdr->addr2, ETH_ALEN);\r
+       _rtw_memcpy(pwlanhdr->addr3, get_bssid(&padapter->mlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, pwlanhdr->addr3, ETH_ALEN);\r
+\r
+       SetSeqNum(pwlanhdr, pmlmeext->mgnt_seq);\r
+       pmlmeext->mgnt_seq++;\r
+       SetFrameSubType(pframe, WIFI_ACTION);\r
+\r
+       pframe += sizeof (struct rtw_ieee80211_hdr_3addr);\r
+       pattrib->pktlen = sizeof (struct rtw_ieee80211_hdr_3addr);\r
+\r
+       rtw_build_tdls_dis_rsp_ies(padapter, pmgntframe, pframe, ptxmgmt, privacy);\r
+\r
+       pattrib->nr_frags = 1;\r
+       pattrib->last_txcmdsz = pattrib->pktlen;\r
+\r
+       dump_mgntframe(padapter, pmgntframe);\r
+       ret = _SUCCESS;\r
+\r
+exit:\r
+       return ret;\r
+}\r
+\r
+int issue_tdls_peer_traffic_rsp(_adapter *padapter, struct sta_info *ptdls_sta, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct xmit_frame       *pmgntframe;\r
+       struct pkt_attrib       *pattrib;\r
+       struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;\r
+       struct xmit_priv        *pxmitpriv = &(padapter->xmitpriv);\r
+       int ret = _FAIL;\r
+\r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+\r
+       ptxmgmt->action_code = TDLS_PEER_TRAFFIC_RESPONSE;\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, ptdls_sta->hwaddr, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(pmlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, ptxmgmt) !=_SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv,pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;      \r
+       }\r
+\r
+       dump_mgntframe(padapter, pmgntframe);\r
+       ret = _SUCCESS;\r
+\r
+exit:\r
+\r
+       return ret;\r
+}\r
+\r
+int issue_tdls_peer_traffic_indication(_adapter *padapter, struct sta_info *ptdls_sta)\r
+{\r
+       struct xmit_frame                       *pmgntframe;\r
+       struct pkt_attrib                       *pattrib;\r
+       struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;\r
+       struct xmit_priv                        *pxmitpriv = &(padapter->xmitpriv);\r
+       struct tdls_txmgmt txmgmt;\r
+       int ret = _FAIL;\r
+\r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       txmgmt.action_code = TDLS_PEER_TRAFFIC_INDICATION;\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, ptdls_sta->hwaddr, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(pmlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       /* PTI frame's priority should be AC_VO */\r
+       pattrib->priority = 7; \r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, &txmgmt) != _SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;\r
+       }\r
+\r
+       dump_mgntframe(padapter, pmgntframe);\r
+       ret = _SUCCESS;\r
+       \r
+exit:\r
+\r
+       return ret;\r
+}\r
+\r
+#ifdef CONFIG_TDLS_CH_SW\r
+int issue_tdls_ch_switch_req(_adapter *padapter, struct sta_info *ptdls_sta)\r
+{\r
+       struct xmit_frame       *pmgntframe;\r
+       struct pkt_attrib       *pattrib;\r
+       struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;\r
+       struct xmit_priv        *pxmitpriv = &(padapter->xmitpriv);\r
+       struct tdls_txmgmt txmgmt;\r
+       int ret = _FAIL;\r
+\r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+\r
+       if (rtw_tdls_is_chsw_allowed(padapter) == _FALSE)\r
+       {       DBG_871X("[TDLS] Ignore %s since channel switch is not allowed\n", __FUNCTION__);\r
+               goto exit;\r
+       }\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       txmgmt.action_code = TDLS_CHANNEL_SWITCH_REQUEST;\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, ptdls_sta->hwaddr, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, get_bssid(pmlmepriv), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, &txmgmt) !=_SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv,pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;\r
+       }\r
+\r
+       dump_mgntframe(padapter, pmgntframe);\r
+       ret = _SUCCESS;\r
+exit:\r
+\r
+       return ret;\r
+}\r
+\r
+int issue_tdls_ch_switch_rsp(_adapter *padapter, struct tdls_txmgmt *ptxmgmt, int wait_ack)\r
+{\r
+       struct xmit_frame       *pmgntframe;\r
+       struct pkt_attrib       *pattrib;\r
+       struct mlme_priv        *pmlmepriv = &padapter->mlmepriv;\r
+       struct xmit_priv        *pxmitpriv = &(padapter->xmitpriv);\r
+       int ret = _FAIL;\r
+\r
+       DBG_871X("[TDLS] %s\n", __FUNCTION__);\r
+\r
+       if (rtw_tdls_is_chsw_allowed(padapter) == _FALSE)\r
+       {       DBG_871X("[TDLS] Ignore %s since channel switch is not allowed\n", __FUNCTION__);\r
+               goto exit;\r
+       }\r
+\r
+       ptxmgmt->action_code = TDLS_CHANNEL_SWITCH_RESPONSE;\r
+\r
+       if ((pmgntframe = alloc_mgtxmitframe(pxmitpriv)) == NULL)\r
+               goto exit;\r
+\r
+       pattrib = &pmgntframe->attrib;\r
+\r
+       pmgntframe->frame_tag = DATA_FRAMETAG;\r
+       pattrib->ether_type = 0x890d;\r
+\r
+       _rtw_memcpy(pattrib->dst, ptxmgmt->peer, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->src, adapter_mac_addr(padapter), ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ra, ptxmgmt->peer, ETH_ALEN);\r
+       _rtw_memcpy(pattrib->ta, pattrib->src, ETH_ALEN);\r
+\r
+       update_tdls_attrib(padapter, pattrib);\r
+       pattrib->qsel = pattrib->priority;\r
+/*\r
+       _enter_critical_bh(&pxmitpriv->lock, &irqL);\r
+       if(xmitframe_enqueue_for_tdls_sleeping_sta(padapter, pmgntframe)==_TRUE){\r
+               _exit_critical_bh(&pxmitpriv->lock, &irqL);\r
+               return _FALSE;\r
+       }\r
+*/\r
+       if (rtw_xmit_tdls_coalesce(padapter, pmgntframe, ptxmgmt) !=_SUCCESS) {\r
+               rtw_free_xmitbuf(pxmitpriv,pmgntframe->pxmitbuf);\r
+               rtw_free_xmitframe(pxmitpriv, pmgntframe);\r
+               goto exit;\r
+       }\r
+\r
+       if (wait_ack) {\r
+               ret = dump_mgntframe_and_wait_ack_timeout(padapter, pmgntframe, 10);\r
+       } else {\r
+               dump_mgntframe(padapter, pmgntframe);\r
+               ret = _SUCCESS;\r
+       }\r
+exit:\r
+\r
+       return ret;\r
+}\r
+#endif\r
+\r
+int On_TDLS_Dis_Rsp(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct sta_info *ptdls_sta = NULL, *psta = rtw_get_stainfo(&(padapter->stapriv), get_bssid(&(padapter->mlmepriv)));\r
+       struct recv_priv *precvpriv = &(padapter->recvpriv);\r
+       u8 *ptr = precv_frame->u.hdr.rx_data, *psa;\r
+       struct rx_pkt_attrib *pattrib = &(precv_frame->u.hdr.attrib);\r
+       struct tdls_info *ptdlsinfo = &(padapter->tdlsinfo);\r
+       u8 empty_addr[ETH_ALEN] = { 0x00 };\r
+       int UndecoratedSmoothedPWDB;\r
+       struct tdls_txmgmt txmgmt;      \r
+       int ret = _SUCCESS;\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       /* WFDTDLS: for sigma test, not to setup direct link automatically */\r
+       ptdlsinfo->dev_discovered = _TRUE;\r
+\r
+       psa = get_sa(ptr);\r
+       ptdls_sta = rtw_get_stainfo(&(padapter->stapriv), psa);\r
+       if (ptdls_sta != NULL)\r
+               ptdls_sta->sta_stats.rx_tdls_disc_rsp_pkts++;\r
+\r
+#ifdef CONFIG_TDLS_AUTOSETUP\r
+       if (ptdls_sta != NULL) {\r
+               /* Record the tdls sta with lowest signal strength */\r
+               if (ptdlsinfo->sta_maximum == _TRUE && ptdls_sta->alive_count >= 1 ) {\r
+                       if (_rtw_memcmp(ptdlsinfo->ss_record.macaddr, empty_addr, ETH_ALEN)) {\r
+                               _rtw_memcpy(ptdlsinfo->ss_record.macaddr, psa, ETH_ALEN);\r
+                               ptdlsinfo->ss_record.RxPWDBAll = pattrib->phy_info.RxPWDBAll;\r
+                       } else {\r
+                               if (ptdlsinfo->ss_record.RxPWDBAll < pattrib->phy_info.RxPWDBAll) {\r
+                                       _rtw_memcpy(ptdlsinfo->ss_record.macaddr, psa, ETH_ALEN);\r
+                                       ptdlsinfo->ss_record.RxPWDBAll = pattrib->phy_info.RxPWDBAll;\r
+                               }\r
+                       }\r
+               }\r
+       } else {\r
+               if (ptdlsinfo->sta_maximum == _TRUE) {\r
+                       if (_rtw_memcmp( ptdlsinfo->ss_record.macaddr, empty_addr, ETH_ALEN)) {\r
+                               /* All traffics are busy, do not set up another direct link. */\r
+                               ret = _FAIL;\r
+                               goto exit;\r
+                       } else {\r
+                               if (pattrib->phy_info.RxPWDBAll > ptdlsinfo->ss_record.RxPWDBAll) {\r
+                                       _rtw_memcpy(txmgmt.peer, ptdlsinfo->ss_record.macaddr, ETH_ALEN);\r
+                                       /* issue_tdls_teardown(padapter, ptdlsinfo->ss_record.macaddr, _FALSE); */\r
+                               } else {\r
+                                       ret = _FAIL;\r
+                                       goto exit;\r
+                               }\r
+                       }\r
+               }\r
+\r
+               rtw_hal_get_def_var(padapter, HAL_DEF_UNDERCORATEDSMOOTHEDPWDB, &UndecoratedSmoothedPWDB);\r
+\r
+               if (pattrib->phy_info.RxPWDBAll + TDLS_SIGNAL_THRESH >= UndecoratedSmoothedPWDB) {\r
+                       DBG_871X("pattrib->RxPWDBAll=%d, pdmpriv->UndecoratedSmoothedPWDB=%d\n", pattrib->phy_info.RxPWDBAll, UndecoratedSmoothedPWDB);\r
+                       _rtw_memcpy(txmgmt.peer, psa, ETH_ALEN);\r
+                       issue_tdls_setup_req(padapter, &txmgmt, _FALSE);\r
+               }\r
+       }\r
+#endif /* CONFIG_TDLS_AUTOSETUP */\r
+\r
+exit:\r
+       return ret;\r
+\r
+}\r
+\r
+sint On_TDLS_Setup_Req(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+       u8 *psa, *pmyid;\r
+       struct sta_info *ptdls_sta= NULL;\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       u8 *ptr = precv_frame->u.hdr.rx_data;\r
+       struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);\r
+       struct security_priv *psecuritypriv = &padapter->securitypriv;\r
+       _irqL irqL;\r
+       struct rx_pkt_attrib    *prx_pkt_attrib = &precv_frame->u.hdr.attrib;\r
+       u8 *prsnie, *ppairwise_cipher;\r
+       u8 i, k;\r
+       u8 ccmp_included=0, rsnie_included=0;\r
+       u16 j, pairwise_count;\r
+       u8 SNonce[32];\r
+       u32 timeout_interval = TDLS_TPK_RESEND_COUNT;\r
+       sint parsing_length;    /* Frame body length, without icv_len */\r
+       PNDIS_802_11_VARIABLE_IEs       pIE;\r
+       u8 FIXED_IE = 5;\r
+       unsigned char           supportRate[16];\r
+       int                             supportRateNum = 0;\r
+       struct tdls_txmgmt txmgmt;\r
+\r
+       if (rtw_tdls_is_setup_allowed(padapter) == _FALSE)\r
+               goto exit;\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       psa = get_sa(ptr);\r
+       ptdls_sta = rtw_get_stainfo(pstapriv, psa);\r
+\r
+       pmyid = adapter_mac_addr(padapter);\r
+       ptr +=prx_pkt_attrib->hdrlen + prx_pkt_attrib->iv_len+LLC_HEADER_SIZE+ETH_TYPE_LEN+PAYLOAD_TYPE_LEN;\r
+       parsing_length= ((union recv_frame *)precv_frame)->u.hdr.len\r
+                       -prx_pkt_attrib->hdrlen\r
+                       -prx_pkt_attrib->iv_len\r
+                       -prx_pkt_attrib->icv_len\r
+                       -LLC_HEADER_SIZE\r
+                       -ETH_TYPE_LEN\r
+                       -PAYLOAD_TYPE_LEN\r
+                       -FIXED_IE;\r
+\r
+       if (ptdls_sta == NULL) {\r
+               ptdls_sta = rtw_alloc_stainfo(pstapriv, psa);\r
+       } else {\r
+               if (ptdls_sta->tdls_sta_state & TDLS_LINKED_STATE) {\r
+                       /* If the direct link is already set up */\r
+                       /* Process as re-setup after tear down */\r
+                       DBG_871X("re-setup a direct link\n");\r
+               }\r
+               /* Already receiving TDLS setup request */\r
+               else if (ptdls_sta->tdls_sta_state & TDLS_INITIATOR_STATE) {\r
+                       DBG_871X("receive duplicated TDLS setup request frame in handshaking\n");\r
+                       goto exit;\r
+               }\r
+               /* When receiving and sending setup_req to the same link at the same time */\r
+               /* STA with higher MAC_addr would be initiator */\r
+               else if (ptdls_sta->tdls_sta_state & TDLS_RESPONDER_STATE) {\r
+                       DBG_871X("receive setup_req after sending setup_req\n");\r
+                       for (i=0;i<6;i++){\r
+                               if(*(pmyid+i)==*(psa+i)){\r
+                               }\r
+                               else if(*(pmyid+i)>*(psa+i)){\r
+                                       ptdls_sta->tdls_sta_state = TDLS_INITIATOR_STATE;\r
+                                       break;\r
+                               }else if(*(pmyid+i)<*(psa+i)){\r
+                                       goto exit;\r
+                               }\r
+                       }\r
+               }\r
+       }\r
+\r
+       if (ptdls_sta) {\r
+               txmgmt.dialog_token = *(ptr+2); /* Copy dialog token */\r
+               txmgmt.status_code = _STATS_SUCCESSFUL_;\r
+\r
+               /* Parsing information element */\r
+               for (j=FIXED_IE; j<parsing_length;) {\r
+\r
+                       pIE = (PNDIS_802_11_VARIABLE_IEs)(ptr+ j);\r
+\r
+                       switch (pIE->ElementID) {\r
+                       case _SUPPORTEDRATES_IE_:\r
+                               _rtw_memcpy(supportRate, pIE->data, pIE->Length);\r
+                               supportRateNum = pIE->Length;\r
+                               break;\r
+                       case _COUNTRY_IE_:\r
+                               break;\r
+                       case _EXT_SUPPORTEDRATES_IE_:\r
+                               if (supportRateNum<=sizeof(supportRate)) {\r
+                                       _rtw_memcpy(supportRate+supportRateNum, pIE->data, pIE->Length);\r
+                                       supportRateNum += pIE->Length;\r
+                               }\r
+                               break;\r
+                       case _SUPPORTED_CH_IE_:\r
+                               break;\r
+                       case _RSN_IE_2_:\r
+                               rsnie_included=1;\r
+                               if (prx_pkt_attrib->encrypt) {\r
+                                       prsnie=(u8*)pIE;\r
+                                       /* Check CCMP pairwise_cipher presence. */\r
+                                       ppairwise_cipher=prsnie+10;\r
+                                       _rtw_memcpy(ptdls_sta->TDLS_RSNIE, pIE->data, pIE->Length);\r
+                                       pairwise_count = *(u16*)(ppairwise_cipher-2);\r
+                                       for (k=0; k<pairwise_count; k++) {\r
+                                               if (_rtw_memcmp( ppairwise_cipher+4*k, RSN_CIPHER_SUITE_CCMP, 4)==_TRUE)\r
+                                                       ccmp_included=1;\r
+                                       }\r
+\r
+                                       if (ccmp_included == 0)\r
+                                               txmgmt.status_code=_STATS_INVALID_RSNIE_;\r
+                               }\r
+                               break;\r
+                       case _EXT_CAP_IE_:\r
+                               break;\r
+                       case _VENDOR_SPECIFIC_IE_:\r
+                               break;\r
+                       case _FTIE_:\r
+                               if (prx_pkt_attrib->encrypt)\r
+                                       _rtw_memcpy(SNonce, (ptr+j+52), 32);\r
+                               break;\r
+                       case _TIMEOUT_ITVL_IE_:\r
+                               if (prx_pkt_attrib->encrypt)\r
+                                       timeout_interval = cpu_to_le32(*(u32*)(ptr+j+3));\r
+                               break;\r
+                       case _RIC_Descriptor_IE_:\r
+                               break;\r
+#ifdef CONFIG_80211N_HT                                \r
+                       case _HT_CAPABILITY_IE_:\r
+                               rtw_tdls_process_ht_cap(padapter, ptdls_sta, pIE->data, pIE->Length);\r
+                               break;\r
+#endif \r
+#ifdef CONFIG_80211AC_VHT                              \r
+                       case EID_AID:\r
+                               break;\r
+                       case EID_VHTCapability:\r
+                               rtw_tdls_process_vht_cap(padapter, ptdls_sta, pIE->data, pIE->Length);\r
+                               break;\r
+#endif\r
+                       case EID_BSSCoexistence:\r
+                               break;\r
+                       case _LINK_ID_IE_:\r
+                               if (_rtw_memcmp(get_bssid(pmlmepriv), pIE->data, 6) == _FALSE)\r
+                                       txmgmt.status_code=_STATS_NOT_IN_SAME_BSS_;\r
+                               break;\r
+                       default:\r
+                               break;\r
+                       }\r
+\r
+                       j += (pIE->Length + 2);\r
+                       \r
+               }\r
+\r
+               /* Check status code */\r
+               /* If responder STA has/hasn't security on AP, but request hasn't/has RSNIE, it should reject */\r
+               if (txmgmt.status_code == _STATS_SUCCESSFUL_) {\r
+                       if (rsnie_included && prx_pkt_attrib->encrypt == 0)\r
+                               txmgmt.status_code = _STATS_SEC_DISABLED_;\r
+                       else if (rsnie_included==0 && prx_pkt_attrib->encrypt)\r
+                               txmgmt.status_code = _STATS_INVALID_PARAMETERS_;\r
+\r
+#ifdef CONFIG_WFD\r
+                       /* WFD test plan version 0.18.2 test item 5.1.5 */\r
+                       /* SoUT does not use TDLS if AP uses weak security */\r
+                       if (padapter->wdinfo.wfd_tdls_enable && (rsnie_included && prx_pkt_attrib->encrypt != _AES_))\r
+                                       txmgmt.status_code = _STATS_SEC_DISABLED_;\r
+#endif /* CONFIG_WFD */\r
+               }\r
+\r
+               ptdls_sta->tdls_sta_state|= TDLS_INITIATOR_STATE;\r
+               if (prx_pkt_attrib->encrypt) {\r
+                       _rtw_memcpy(ptdls_sta->SNonce, SNonce, 32);\r
+\r
+                       if (timeout_interval <= 300) \r
+                               ptdls_sta->TDLS_PeerKey_Lifetime = TDLS_TPK_RESEND_COUNT;\r
+                       else\r
+                               ptdls_sta->TDLS_PeerKey_Lifetime = timeout_interval;\r
+               }\r
+\r
+               /* Update station supportRate */\r
+               ptdls_sta->bssratelen = supportRateNum;\r
+               _rtw_memcpy(ptdls_sta->bssrateset, supportRate, supportRateNum);\r
+\r
+               if (!(ptdls_sta->tdls_sta_state & TDLS_LINKED_STATE))\r
+                       ptdlsinfo->sta_cnt++;\r
+               /* -2: AP + BC/MC sta, -4: default key */\r
+               if (ptdlsinfo->sta_cnt == MAX_ALLOWED_TDLS_STA_NUM)\r
+                       ptdlsinfo->sta_maximum = _TRUE;\r
+\r
+#ifdef CONFIG_WFD\r
+               rtw_tdls_process_wfd_ie(ptdlsinfo, ptr + FIXED_IE, parsing_length);\r
+#endif\r
+\r
+       }else {\r
+               goto exit;\r
+       }\r
+\r
+       _rtw_memcpy(txmgmt.peer, prx_pkt_attrib->src, ETH_ALEN);\r
+\r
+       if (rtw_tdls_is_driver_setup(padapter)) {\r
+               issue_tdls_setup_rsp(padapter, &txmgmt);\r
+\r
+               if (txmgmt.status_code==_STATS_SUCCESSFUL_) {\r
+                       _set_timer( &ptdls_sta->handshake_timer, TDLS_HANDSHAKE_TIME);\r
+               }else {\r
+                       free_tdls_sta(padapter, ptdls_sta);\r
+               }\r
+       }\r
+               \r
+exit:\r
+       \r
+       return _SUCCESS;\r
+}\r
+\r
+int On_TDLS_Setup_Rsp(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct registry_priv    *pregistrypriv = &padapter->registrypriv;\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+       struct sta_info *ptdls_sta= NULL;\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       u8 *ptr = precv_frame->u.hdr.rx_data;\r
+       _irqL irqL;\r
+       struct rx_pkt_attrib    *prx_pkt_attrib = &precv_frame->u.hdr.attrib;\r
+       u8 *psa;\r
+       u16 status_code=0;\r
+       sint parsing_length;    /* Frame body length, without icv_len */\r
+       PNDIS_802_11_VARIABLE_IEs       pIE;\r
+       u8 FIXED_IE =7;\r
+       u8 ANonce[32];\r
+       u8  *pftie=NULL, *ptimeout_ie=NULL, *plinkid_ie=NULL, *prsnie=NULL, *pftie_mic=NULL, *ppairwise_cipher=NULL;\r
+       u16 pairwise_count, j, k;\r
+       u8 verify_ccmp=0;\r
+       unsigned char           supportRate[16];\r
+       int                             supportRateNum = 0;\r
+       struct tdls_txmgmt txmgmt;\r
+       int ret = _SUCCESS;\r
+       u32 timeout_interval = TDLS_TPK_RESEND_COUNT;\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       psa = get_sa(ptr);\r
+       ptdls_sta = rtw_get_stainfo(pstapriv, psa);\r
+\r
+       if (ptdls_sta == NULL) {\r
+               DBG_871X("[%s] Direct Link Peer = "MAC_FMT" not found\n", __FUNCTION__, MAC_ARG(psa));\r
+               ret = _FAIL;\r
+               goto exit;\r
+       }\r
+\r
+       ptr +=prx_pkt_attrib->hdrlen + prx_pkt_attrib->iv_len+LLC_HEADER_SIZE+ETH_TYPE_LEN+PAYLOAD_TYPE_LEN;\r
+       parsing_length= ((union recv_frame *)precv_frame)->u.hdr.len\r
+                       -prx_pkt_attrib->hdrlen\r
+                       -prx_pkt_attrib->iv_len\r
+                       -prx_pkt_attrib->icv_len\r
+                       -LLC_HEADER_SIZE\r
+                       -ETH_TYPE_LEN\r
+                       -PAYLOAD_TYPE_LEN\r
+                       -FIXED_IE;\r
+\r
+       _rtw_memcpy(&status_code, ptr+2, 2);\r
+       \r
+       if (status_code != 0) {\r
+               DBG_871X( "[TDLS] %s status_code = %d, free_tdls_sta\n", __FUNCTION__, status_code );\r
+               free_tdls_sta(padapter, ptdls_sta);\r
+               ret = _FAIL;\r
+               goto exit;\r
+       }\r
+\r
+       status_code = 0;\r
+\r
+       /* parsing information element */\r
+       for (j = FIXED_IE; j<parsing_length;) {\r
+               pIE = (PNDIS_802_11_VARIABLE_IEs)(ptr+ j);\r
+\r
+               switch (pIE->ElementID) {\r
+               case _SUPPORTEDRATES_IE_:\r
+                       _rtw_memcpy(supportRate, pIE->data, pIE->Length);\r
+                       supportRateNum = pIE->Length;\r
+                       break;\r
+               case _COUNTRY_IE_:\r
+                       break;\r
+               case _EXT_SUPPORTEDRATES_IE_:\r
+                       if (supportRateNum<=sizeof(supportRate)) {\r
+                               _rtw_memcpy(supportRate+supportRateNum, pIE->data, pIE->Length);\r
+                               supportRateNum += pIE->Length;\r
+                       }\r
+                       break;\r
+               case _SUPPORTED_CH_IE_:\r
+                       break;\r
+               case _RSN_IE_2_:\r
+                       prsnie=(u8*)pIE;\r
+                       /* Check CCMP pairwise_cipher presence. */\r
+                       ppairwise_cipher=prsnie+10;\r
+                       _rtw_memcpy(&pairwise_count, (u16*)(ppairwise_cipher-2), 2);\r
+                       for (k=0;k<pairwise_count;k++) {\r
+                               if (_rtw_memcmp( ppairwise_cipher+4*k, RSN_CIPHER_SUITE_CCMP, 4) == _TRUE)\r
+                                       verify_ccmp=1;\r
+                       }\r
+               case _EXT_CAP_IE_:\r
+                       break;\r
+               case _VENDOR_SPECIFIC_IE_:\r
+                       if (_rtw_memcmp((u8 *)pIE + 2, WMM_INFO_OUI, 6) == _TRUE) {     \r
+                               /* WMM Info ID and OUI */\r
+                               if ((pregistrypriv->wmm_enable == _TRUE) || (padapter->mlmepriv.htpriv.ht_option == _TRUE))\r
+                                       ptdls_sta->qos_option = _TRUE;\r
+                       }\r
+                       break;\r
+               case _FTIE_:\r
+                       pftie=(u8*)pIE;\r
+                       _rtw_memcpy(ANonce, (ptr+j+20), 32);\r
+                       break;\r
+               case _TIMEOUT_ITVL_IE_:\r
+                       ptimeout_ie=(u8*)pIE;\r
+                       timeout_interval = cpu_to_le32(*(u32*)(ptimeout_ie+3));\r
+                       break;\r
+               case _RIC_Descriptor_IE_:\r
+                       break;\r
+#ifdef CONFIG_80211N_HT                        \r
+               case _HT_CAPABILITY_IE_:\r
+                       rtw_tdls_process_ht_cap(padapter, ptdls_sta, pIE->data, pIE->Length);\r
+                       break;\r
+#endif                 \r
+#ifdef CONFIG_80211AC_VHT\r
+               case EID_AID:\r
+                       /* todo in the future if necessary */\r
+                       break;\r
+               case EID_VHTCapability:\r
+                       rtw_tdls_process_vht_cap(padapter, ptdls_sta, pIE->data, pIE->Length);\r
+                       break;\r
+               case EID_OpModeNotification:\r
+                       rtw_process_vht_op_mode_notify(padapter, pIE->data, ptdls_sta);\r
+                       break;  \r
+#endif\r
+               case EID_BSSCoexistence:\r
+                       break;\r
+               case _LINK_ID_IE_:\r
+                       plinkid_ie=(u8*)pIE;\r
+                       break;\r
+               default:\r
+                       break;\r
+               }\r
+\r
+               j += (pIE->Length + 2);\r
+\r
+       }\r
+\r
+       ptdls_sta->bssratelen = supportRateNum;\r
+       _rtw_memcpy(ptdls_sta->bssrateset, supportRate, supportRateNum);\r
+       _rtw_memcpy(ptdls_sta->ANonce, ANonce, 32);\r
+\r
+#ifdef CONFIG_WFD\r
+       rtw_tdls_process_wfd_ie(ptdlsinfo, ptr + FIXED_IE, parsing_length);\r
+#endif\r
+\r
+       if (status_code != _STATS_SUCCESSFUL_) {\r
+               txmgmt.status_code = status_code;\r
+       } else {\r
+               if (prx_pkt_attrib->encrypt) {\r
+                       if (verify_ccmp == 1) {\r
+                               txmgmt.status_code = _STATS_SUCCESSFUL_;\r
+                               if (rtw_tdls_is_driver_setup(padapter) == _TRUE) {\r
+                                       wpa_tdls_generate_tpk(padapter, ptdls_sta);\r
+                                       if (tdls_verify_mic(ptdls_sta->tpk.kck, 2, plinkid_ie, prsnie, ptimeout_ie, pftie) == _FAIL) {\r
+                                               DBG_871X( "[TDLS] %s tdls_verify_mic fail, free_tdls_sta\n", __FUNCTION__);\r
+                                               free_tdls_sta(padapter, ptdls_sta);\r
+                                               ret = _FAIL;\r
+                                               goto exit;\r
+                                       }\r
+                                       ptdls_sta->TDLS_PeerKey_Lifetime = timeout_interval;\r
+                               }\r
+                       }\r
+                       else\r
+                       {\r
+                               txmgmt.status_code = _STATS_INVALID_RSNIE_;\r
+                       }\r
+\r
+               }else{\r
+                       txmgmt.status_code = _STATS_SUCCESSFUL_;\r
+               }\r
+       }\r
+\r
+       if (rtw_tdls_is_driver_setup(padapter) == _TRUE) {\r
+               _rtw_memcpy(txmgmt.peer, prx_pkt_attrib->src, ETH_ALEN);\r
+               issue_tdls_setup_cfm(padapter, &txmgmt);\r
+\r
+               if (txmgmt.status_code == _STATS_SUCCESSFUL_) {\r
+                       ptdlsinfo->link_established = _TRUE;\r
+\r
+                       if (ptdls_sta->tdls_sta_state & TDLS_RESPONDER_STATE) {\r
+                               ptdls_sta->tdls_sta_state |= TDLS_LINKED_STATE;\r
+                               ptdls_sta->state |= _FW_LINKED;\r
+                               _cancel_timer_ex( &ptdls_sta->handshake_timer);\r
+                       }\r
+\r
+                       if (prx_pkt_attrib->encrypt)\r
+                               rtw_tdls_set_key(padapter, ptdls_sta);\r
+\r
+                       rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_ESTABLISHED);\r
+\r
+               }\r
+       }\r
+\r
+exit:\r
+       if (rtw_tdls_is_driver_setup(padapter) == _TRUE)\r
+               return ret;\r
+       else\r
+               return _SUCCESS;\r
+\r
+}\r
+\r
+int On_TDLS_Setup_Cfm(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+       struct sta_info *ptdls_sta= NULL;\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       u8 *ptr = precv_frame->u.hdr.rx_data;\r
+       _irqL irqL;\r
+       struct rx_pkt_attrib    *prx_pkt_attrib = &precv_frame->u.hdr.attrib;\r
+       u8 *psa; \r
+       u16 status_code=0;\r
+       sint parsing_length;\r
+       PNDIS_802_11_VARIABLE_IEs       pIE;\r
+       u8 FIXED_IE =5;\r
+       u8  *pftie=NULL, *ptimeout_ie=NULL, *plinkid_ie=NULL, *prsnie=NULL, *pftie_mic=NULL, *ppairwise_cipher=NULL;\r
+       u16 j, pairwise_count;\r
+       int ret = _SUCCESS;\r
+\r
+       psa = get_sa(ptr);\r
+       ptdls_sta = rtw_get_stainfo(pstapriv, psa);\r
+\r
+       if (ptdls_sta == NULL) {\r
+               DBG_871X("[%s] Direct Link Peer = "MAC_FMT" not found\n", __FUNCTION__, MAC_ARG(psa));\r
+               ret = _FAIL;\r
+               goto exit;\r
+       }\r
+\r
+       ptr +=prx_pkt_attrib->hdrlen + prx_pkt_attrib->iv_len+LLC_HEADER_SIZE+ETH_TYPE_LEN+PAYLOAD_TYPE_LEN;\r
+       parsing_length= ((union recv_frame *)precv_frame)->u.hdr.len\r
+                       -prx_pkt_attrib->hdrlen\r
+                       -prx_pkt_attrib->iv_len\r
+                       -prx_pkt_attrib->icv_len\r
+                       -LLC_HEADER_SIZE\r
+                       -ETH_TYPE_LEN\r
+                       -PAYLOAD_TYPE_LEN\r
+                       -FIXED_IE;\r
+\r
+       _rtw_memcpy(&status_code, ptr+2, 2);\r
+\r
+       if (status_code!= 0) {\r
+               DBG_871X("[%s] status_code = %d\n, free_tdls_sta", __FUNCTION__, status_code);\r
+               free_tdls_sta(padapter, ptdls_sta);\r
+               ret = _FAIL;\r
+               goto exit;\r
+       }\r
+\r
+       /* Parsing information element */\r
+       for (j = FIXED_IE; j < parsing_length;) {\r
+\r
+               pIE = (PNDIS_802_11_VARIABLE_IEs)(ptr + j);\r
+\r
+               switch (pIE->ElementID) {\r
+                       case _RSN_IE_2_:\r
+                               prsnie = (u8 *)pIE;\r
+                               break;\r
+                       case _VENDOR_SPECIFIC_IE_:\r
+                               if (_rtw_memcmp((u8 *)pIE + 2, WMM_PARA_OUI, 6) == _TRUE) {     \r
+                                       /* WMM Parameter ID and OUI */\r
+                                       ptdls_sta->qos_option = _TRUE;\r
+                               }\r
+                               break;                          \r
+                       case _FTIE_:\r
+                               pftie = (u8 *)pIE;\r
+                               break;\r
+                       case _TIMEOUT_ITVL_IE_:\r
+                               ptimeout_ie = (u8 *)pIE;\r
+                               break;\r
+#ifdef CONFIG_80211N_HT                                \r
+                       case _HT_EXTRA_INFO_IE_:\r
+                               break;\r
+#endif\r
+#ifdef CONFIG_80211AC_VHT\r
+                       case EID_VHTOperation:\r
+                               break;\r
+                       case EID_OpModeNotification:\r
+                               rtw_process_vht_op_mode_notify(padapter, pIE->data, ptdls_sta);\r
+                               break;  \r
+#endif\r
+                       case _LINK_ID_IE_:\r
+                               plinkid_ie = (u8 *)pIE;\r
+                               break;\r
+                       default:\r
+                               break;\r
+               }\r
+\r
+               j += (pIE->Length + 2);\r
+               \r
+       }\r
+\r
+       if (prx_pkt_attrib->encrypt) {\r
+               /* Verify mic in FTIE MIC field */\r
+               if (rtw_tdls_is_driver_setup(padapter) &&\r
+                       (tdls_verify_mic(ptdls_sta->tpk.kck, 3, plinkid_ie, prsnie, ptimeout_ie, pftie) == _FAIL)) {\r
+                       free_tdls_sta(padapter, ptdls_sta);\r
+                       ret = _FAIL;\r
+                       goto exit;\r
+               }\r
+       }\r
+\r
+       if (rtw_tdls_is_driver_setup(padapter)) {\r
+               ptdlsinfo->link_established = _TRUE;\r
+\r
+               if (ptdls_sta->tdls_sta_state & TDLS_INITIATOR_STATE) {\r
+                       ptdls_sta->tdls_sta_state|=TDLS_LINKED_STATE;\r
+                       ptdls_sta->state |= _FW_LINKED;\r
+                       _cancel_timer_ex(&ptdls_sta->handshake_timer);\r
+               }\r
+\r
+               if (prx_pkt_attrib->encrypt) {\r
+                       rtw_tdls_set_key(padapter, ptdls_sta);\r
+\r
+                       /* Start  TPK timer */\r
+                       ptdls_sta->TPK_count = 0;\r
+                       _set_timer(&ptdls_sta->TPK_timer, ONE_SEC);\r
+               }\r
+\r
+               rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_ESTABLISHED);\r
+       }\r
+\r
+exit:\r
+       return ret;\r
+\r
+}\r
+\r
+int On_TDLS_Dis_Req(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct rx_pkt_attrib    *prx_pkt_attrib = &precv_frame->u.hdr.attrib;\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       struct sta_info *psta_ap;\r
+       u8 *ptr = precv_frame->u.hdr.rx_data;\r
+       sint parsing_length;    /* Frame body length, without icv_len */\r
+       PNDIS_802_11_VARIABLE_IEs       pIE;\r
+       u8 FIXED_IE = 3, *dst;\r
+       u16 j;\r
+       struct tdls_txmgmt txmgmt;\r
+       int ret = _SUCCESS;\r
+\r
+       if (rtw_tdls_is_driver_setup(padapter) == _FALSE)\r
+               goto exit;\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       ptr +=prx_pkt_attrib->hdrlen + prx_pkt_attrib->iv_len+LLC_HEADER_SIZE+ETH_TYPE_LEN+PAYLOAD_TYPE_LEN;\r
+       txmgmt.dialog_token = *(ptr+2);\r
+       _rtw_memcpy(&txmgmt.peer, precv_frame->u.hdr.attrib.src, ETH_ALEN);\r
+       txmgmt.action_code = TDLS_DISCOVERY_RESPONSE;\r
+       parsing_length= ((union recv_frame *)precv_frame)->u.hdr.len\r
+                       -prx_pkt_attrib->hdrlen\r
+                       -prx_pkt_attrib->iv_len\r
+                       -prx_pkt_attrib->icv_len\r
+                       -LLC_HEADER_SIZE\r
+                       -ETH_TYPE_LEN\r
+                       -PAYLOAD_TYPE_LEN\r
+                       -FIXED_IE;\r
+\r
+       /* Parsing information element */\r
+       for (j=FIXED_IE; j<parsing_length;) {\r
+\r
+               pIE = (PNDIS_802_11_VARIABLE_IEs)(ptr+ j);\r
+\r
+               switch (pIE->ElementID) {\r
+               case _LINK_ID_IE_:\r
+                       psta_ap = rtw_get_stainfo(pstapriv, pIE->data);\r
+                       if (psta_ap == NULL)\r
+                               goto exit;\r
+                       dst = pIE->data + 12;\r
+                       if (MacAddr_isBcst(dst) == _FALSE && (_rtw_memcmp(adapter_mac_addr(padapter), dst, 6) == _FALSE))\r
+                               goto exit;\r
+                       break;\r
+               default:\r
+                       break;\r
+               }\r
+\r
+               j += (pIE->Length + 2);\r
+               \r
+       }\r
+\r
+       issue_tdls_dis_rsp(padapter, &txmgmt, prx_pkt_attrib->privacy);\r
+               \r
+exit:\r
+       return ret;\r
+       \r
+}\r
+\r
+int On_TDLS_Teardown(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       u8 *psa;\r
+       u8 *ptr = precv_frame->u.hdr.rx_data;\r
+       struct rx_pkt_attrib    *prx_pkt_attrib = &precv_frame->u.hdr.attrib;\r
+       struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);   \r
+       struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);\r
+       struct sta_priv         *pstapriv = &padapter->stapriv;\r
+       struct sta_info *ptdls_sta= NULL;\r
+       _irqL irqL;\r
+       u8 reason;\r
+\r
+       reason = *(ptr + prx_pkt_attrib->hdrlen + prx_pkt_attrib->iv_len + LLC_HEADER_SIZE + ETH_TYPE_LEN + PAYLOAD_TYPE_LEN + 2);\r
+       DBG_871X("[TDLS] %s Reason code(%d)\n", __FUNCTION__,reason);\r
+\r
+       psa = get_sa(ptr);\r
+\r
+       ptdls_sta = rtw_get_stainfo(pstapriv, psa);\r
+       if (ptdls_sta != NULL) {\r
+               if (rtw_tdls_is_driver_setup(padapter))\r
+                       rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_TEARDOWN_STA_LOCALLY);\r
+       }\r
+\r
+       return _SUCCESS;\r
+       \r
+}\r
+\r
+#if 0\r
+u8 TDLS_check_ch_state(uint state){\r
+       if (state & TDLS_CH_SWITCH_ON_STATE &&\r
+               state & TDLS_PEER_AT_OFF_STATE) {\r
+               if (state & TDLS_PEER_SLEEP_STATE)\r
+                       return 2;       /* U-APSD + ch. switch */\r
+               else\r
+                       return 1;       /* ch. switch */\r
+       }else\r
+               return 0;\r
+}\r
+#endif\r
+\r
+int On_TDLS_Peer_Traffic_Indication(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct rx_pkt_attrib    *pattrib = &precv_frame->u.hdr.attrib;\r
+       struct sta_info *ptdls_sta = rtw_get_stainfo(&padapter->stapriv, pattrib->src); \r
+       u8 *ptr = precv_frame->u.hdr.rx_data;\r
+       struct tdls_txmgmt txmgmt;\r
+\r
+       ptr +=pattrib->hdrlen + pattrib->iv_len+LLC_HEADER_SIZE+ETH_TYPE_LEN+PAYLOAD_TYPE_LEN;\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+\r
+       if (ptdls_sta != NULL) {\r
+               txmgmt.dialog_token = *(ptr+2);\r
+               issue_tdls_peer_traffic_rsp(padapter, ptdls_sta, &txmgmt);\r
+               //issue_nulldata_to_TDLS_peer_STA(padapter, ptdls_sta->hwaddr, 0, 0, 0);\r
+       } else {\r
+               DBG_871X("from unknown sta:"MAC_FMT"\n", MAC_ARG(pattrib->src));\r
+               return _FAIL;\r
+       }\r
+\r
+       return _SUCCESS;\r
+}\r
+\r
+/* We process buffered data for 1. U-APSD, 2. ch. switch, 3. U-APSD + ch. switch here */\r
+int On_TDLS_Peer_Traffic_Rsp(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+       struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;\r
+       struct rx_pkt_attrib    *pattrib = & precv_frame->u.hdr.attrib;\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       struct sta_info *ptdls_sta = rtw_get_stainfo(pstapriv, pattrib->src);\r
+       u8 wmmps_ac=0;\r
+       /* u8 state=TDLS_check_ch_state(ptdls_sta->tdls_sta_state); */\r
+       int i;\r
+       \r
+       ptdls_sta->sta_stats.rx_data_pkts++;\r
+\r
+       ptdls_sta->tdls_sta_state &= ~(TDLS_WAIT_PTR_STATE);\r
+\r
+       /* Check 4-AC queue bit */\r
+       if (ptdls_sta->uapsd_vo || ptdls_sta->uapsd_vi || ptdls_sta->uapsd_be || ptdls_sta->uapsd_bk)\r
+               wmmps_ac=1;\r
+\r
+       /* If it's a direct link and have buffered frame */\r
+       if (ptdls_sta->tdls_sta_state & TDLS_LINKED_STATE) {\r
+               if (wmmps_ac) {\r
+                       _irqL irqL;      \r
+                       _list   *xmitframe_plist, *xmitframe_phead;\r
+                       struct xmit_frame *pxmitframe=NULL;\r
+               \r
+                       _enter_critical_bh(&ptdls_sta->sleep_q.lock, &irqL);    \r
+\r
+                       xmitframe_phead = get_list_head(&ptdls_sta->sleep_q);\r
+                       xmitframe_plist = get_next(xmitframe_phead);\r
+\r
+                       /* transmit buffered frames */\r
+                       while (rtw_end_of_queue_search(xmitframe_phead, xmitframe_plist) == _FALSE) {\r
+                               pxmitframe = LIST_CONTAINOR(xmitframe_plist, struct xmit_frame, list);\r
+                               xmitframe_plist = get_next(xmitframe_plist);\r
+                               rtw_list_delete(&pxmitframe->list);\r
+\r
+                               ptdls_sta->sleepq_len--;\r
+                               ptdls_sta->sleepq_ac_len--;\r
+                               if (ptdls_sta->sleepq_len>0) {\r
+                                       pxmitframe->attrib.mdata = 1;\r
+                                       pxmitframe->attrib.eosp = 0;\r
+                               } else {\r
+                                       pxmitframe->attrib.mdata = 0;\r
+                                       pxmitframe->attrib.eosp = 1;\r
+                               }\r
+                               pxmitframe->attrib.triggered = 1;\r
+\r
+                               rtw_hal_xmitframe_enqueue(padapter, pxmitframe);\r
+                       }\r
+\r
+                       if (ptdls_sta->sleepq_len==0)\r
+                               DBG_871X("no buffered packets for tdls to xmit\n");\r
+                       else {\r
+                               DBG_871X("error!psta->sleepq_len=%d\n", ptdls_sta->sleepq_len);\r
+                               ptdls_sta->sleepq_len=0;\r
+                       }\r
+\r
+                       _exit_critical_bh(&ptdls_sta->sleep_q.lock, &irqL);                     \r
+               \r
+               }\r
+\r
+       }\r
+\r
+       return _SUCCESS;\r
+}\r
+\r
+#ifdef CONFIG_TDLS_CH_SW\r
+sint On_TDLS_Ch_Switch_Req(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct tdls_ch_switch *pchsw_info = &padapter->tdlsinfo.chsw_info;\r
+       struct sta_info *ptdls_sta= NULL;\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       u8 *ptr = precv_frame->u.hdr.rx_data;\r
+       struct rx_pkt_attrib    *prx_pkt_attrib = &precv_frame->u.hdr.attrib;\r
+       u8 *psa; \r
+       sint parsing_length;\r
+       PNDIS_802_11_VARIABLE_IEs       pIE;\r
+       u8 FIXED_IE = 4;\r
+       u16 j;\r
+       struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;\r
+       struct tdls_txmgmt txmgmt;\r
+       u8 zaddr[ETH_ALEN] = {0x00, 0x00, 0x00, 0x00, 0x00, 0x00};\r
+       u16 switch_time= TDLS_CH_SWITCH_TIME * 1000, switch_timeout=TDLS_CH_SWITCH_TIMEOUT * 1000;\r
+       u8 take_care_iqk;\r
+\r
+       if (rtw_tdls_is_chsw_allowed(padapter) == _FALSE)\r
+       {       DBG_871X("[TDLS] Ignore %s since channel switch is not allowed\n", __FUNCTION__);\r
+               return _FAIL;\r
+       }\r
+       \r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       psa = get_sa(ptr);\r
+       ptdls_sta = rtw_get_stainfo(pstapriv, psa);\r
+\r
+       if (ptdls_sta == NULL) {\r
+               DBG_871X("[%s] Direct Link Peer = "MAC_FMT" not found\n", __FUNCTION__, MAC_ARG(psa));\r
+               return _FAIL;\r
+       }\r
+               \r
+       ptdls_sta->ch_switch_time=switch_time;\r
+       ptdls_sta->ch_switch_timeout=switch_timeout;\r
+\r
+       ptr +=prx_pkt_attrib->hdrlen + prx_pkt_attrib->iv_len+LLC_HEADER_SIZE+ETH_TYPE_LEN+PAYLOAD_TYPE_LEN;\r
+       parsing_length= ((union recv_frame *)precv_frame)->u.hdr.len\r
+                       -prx_pkt_attrib->hdrlen\r
+                       -prx_pkt_attrib->iv_len\r
+                       -prx_pkt_attrib->icv_len\r
+                       -LLC_HEADER_SIZE\r
+                       -ETH_TYPE_LEN\r
+                       -PAYLOAD_TYPE_LEN\r
+                       -FIXED_IE;\r
+\r
+       pchsw_info->off_ch_num = *(ptr + 2);\r
+\r
+       if ((*(ptr + 2) == 2) && (hal_is_band_support(padapter, BAND_ON_5G))) {\r
+               pchsw_info->off_ch_num = 44;\r
+       }\r
+\r
+       if (pchsw_info->off_ch_num != pmlmeext->cur_channel) {\r
+               pchsw_info->delay_switch_back = _FALSE;\r
+       }\r
+\r
+       /* Parsing information element */\r
+       for (j=FIXED_IE; j<parsing_length;) {\r
+               pIE = (PNDIS_802_11_VARIABLE_IEs)(ptr+ j);\r
+\r
+               switch (pIE->ElementID) {\r
+               case EID_SecondaryChnlOffset:\r
+                       switch (*(pIE->data))\r
+                       {\r
+                               case EXTCHNL_OFFSET_UPPER:\r
+                                       pchsw_info->ch_offset = HAL_PRIME_CHNL_OFFSET_LOWER;\r
+                                       break;\r
+                               \r
+                               case EXTCHNL_OFFSET_LOWER:\r
+                                       pchsw_info->ch_offset = HAL_PRIME_CHNL_OFFSET_UPPER;\r
+                                       break;\r
+                                       \r
+                               default:\r
+                                       pchsw_info->ch_offset = HAL_PRIME_CHNL_OFFSET_DONT_CARE;\r
+                                       break;\r
+                       }\r
+                       break;\r
+               case _LINK_ID_IE_:\r
+                       break;\r
+               case _CH_SWITCH_TIMING_:\r
+                       ptdls_sta->ch_switch_time = (RTW_GET_LE16(pIE->data) >= TDLS_CH_SWITCH_TIME * 1000) ?\r
+                               RTW_GET_LE16(pIE->data) : TDLS_CH_SWITCH_TIME * 1000;\r
+                       ptdls_sta->ch_switch_timeout = (RTW_GET_LE16(pIE->data + 2) >= TDLS_CH_SWITCH_TIMEOUT * 1000) ?\r
+                               RTW_GET_LE16(pIE->data + 2) : TDLS_CH_SWITCH_TIMEOUT * 1000;\r
+                       DBG_871X("[TDLS] %s ch_switch_time:%d, ch_switch_timeout:%d\n"\r
+                               , __FUNCTION__, RTW_GET_LE16(pIE->data), RTW_GET_LE16(pIE->data + 2));\r
+               default:\r
+                       break;\r
+               }\r
+\r
+               j += (pIE->Length + 2);\r
+       }\r
+\r
+       rtw_hal_get_hwreg(padapter, HW_VAR_CH_SW_NEED_TO_TAKE_CARE_IQK_INFO, &take_care_iqk);\r
+       if (take_care_iqk == _TRUE) {\r
+               u8 central_chnl;\r
+               u8 bw_mode;\r
+\r
+               bw_mode = (pchsw_info->ch_offset) ? CHANNEL_WIDTH_40 : CHANNEL_WIDTH_20;\r
+               central_chnl = rtw_get_center_ch(pchsw_info->off_ch_num, bw_mode, pchsw_info->ch_offset);\r
+               if (rtw_hal_ch_sw_iqk_info_search(padapter, central_chnl, bw_mode) < 0) {\r
+                       if (!(pchsw_info->ch_sw_state & TDLS_CH_SWITCH_PREPARE_STATE))\r
+                               rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_CH_SW_PREPARE);\r
+\r
+                       return _FAIL;\r
+               }\r
+       }\r
+\r
+       /* cancel ch sw monitor timer for responder */\r
+       if (!(pchsw_info->ch_sw_state & TDLS_CH_SW_INITIATOR_STATE))\r
+               _cancel_timer_ex(&ptdls_sta->ch_sw_monitor_timer);\r
+\r
+       /* Todo: check status */\r
+       txmgmt.status_code = 0;\r
+       _rtw_memcpy(txmgmt.peer, psa, ETH_ALEN);\r
+\r
+       if (_rtw_memcmp(pchsw_info->addr, zaddr, ETH_ALEN) == _TRUE)\r
+               _rtw_memcpy(pchsw_info->addr, ptdls_sta->hwaddr, ETH_ALEN);\r
+\r
+       if (ATOMIC_READ(&pchsw_info->chsw_on) == _FALSE)\r
+               rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_CH_SW_START);\r
+       \r
+       rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_CH_SW_RESP);\r
+\r
+       return _SUCCESS;\r
+}\r
+\r
+sint On_TDLS_Ch_Switch_Rsp(_adapter *padapter, union recv_frame *precv_frame)\r
+{\r
+       struct tdls_ch_switch *pchsw_info = &padapter->tdlsinfo.chsw_info;\r
+       struct sta_info *ptdls_sta= NULL;\r
+       struct sta_priv *pstapriv = &padapter->stapriv;\r
+       u8 *ptr = precv_frame->u.hdr.rx_data;\r
+       struct rx_pkt_attrib    *prx_pkt_attrib = &precv_frame->u.hdr.attrib;\r
+       u8 *psa; \r
+       sint parsing_length;\r
+       PNDIS_802_11_VARIABLE_IEs       pIE;\r
+       u8 FIXED_IE = 4;\r
+       u16 status_code, j, switch_time, switch_timeout;\r
+       struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;\r
+       int ret = _SUCCESS;\r
+\r
+       if (rtw_tdls_is_chsw_allowed(padapter) == _FALSE)\r
+       {       DBG_871X("[TDLS] Ignore %s since channel switch is not allowed\n", __FUNCTION__);\r
+               return _SUCCESS;\r
+       }\r
+\r
+       psa = get_sa(ptr);\r
+       ptdls_sta = rtw_get_stainfo(pstapriv, psa);\r
+\r
+       if (ptdls_sta == NULL) {\r
+               DBG_871X("[%s] Direct Link Peer = "MAC_FMT" not found\n", __FUNCTION__, MAC_ARG(psa));\r
+               return _FAIL;\r
+       }\r
+\r
+       /* If we receive Unsolicited TDLS Channel Switch Response when channel switch is running, */\r
+       /* we will go back to base channel and terminate this channel switch procedure */\r
+       if (ATOMIC_READ(&pchsw_info->chsw_on) == _TRUE) {\r
+               if (pmlmeext->cur_channel != rtw_get_oper_ch(padapter)) {\r
+                       DBG_871X("[TDLS] Rx unsolicited channel switch response \n");\r
+                       rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_CH_SW_TO_BASE_CHNL);\r
+                       goto exit;\r
+               }\r
+       }\r
+\r
+       ptr +=prx_pkt_attrib->hdrlen + prx_pkt_attrib->iv_len + LLC_HEADER_SIZE+ETH_TYPE_LEN+PAYLOAD_TYPE_LEN;\r
+       parsing_length = ((union recv_frame *)precv_frame)->u.hdr.len\r
+                       -prx_pkt_attrib->hdrlen\r
+                       -prx_pkt_attrib->iv_len\r
+                       -prx_pkt_attrib->icv_len\r
+                       -LLC_HEADER_SIZE\r
+                       -ETH_TYPE_LEN\r
+                       -PAYLOAD_TYPE_LEN\r
+                       -FIXED_IE;\r
+\r
+       _rtw_memcpy(&status_code, ptr+2, 2);\r
+\r
+       if (status_code != 0) {\r
+               DBG_871X("[TDLS] %s status_code:%d\n", __FUNCTION__, status_code);\r
+               pchsw_info->ch_sw_state &= ~(TDLS_CH_SW_INITIATOR_STATE);\r
+               rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_CH_SW_END);\r
+               ret = _FAIL;\r
+               goto exit;\r
+       }\r
+       \r
+       /* Parsing information element */\r
+       for (j = FIXED_IE; j < parsing_length;) {\r
+               pIE = (PNDIS_802_11_VARIABLE_IEs)(ptr+ j);\r
+\r
+               switch (pIE->ElementID) {\r
+               case _LINK_ID_IE_:\r
+                       break;\r
+               case _CH_SWITCH_TIMING_:\r
+                       _rtw_memcpy(&switch_time, pIE->data, 2);\r
+                       if (switch_time > ptdls_sta->ch_switch_time)\r
+                               _rtw_memcpy(&ptdls_sta->ch_switch_time, &switch_time, 2);\r
+\r
+                       _rtw_memcpy(&switch_timeout, pIE->data + 2, 2);\r
+                       if (switch_timeout > ptdls_sta->ch_switch_timeout)\r
+                               _rtw_memcpy(&ptdls_sta->ch_switch_timeout, &switch_timeout, 2);\r
+                       break;\r
+               default:\r
+                       break;\r
+               }\r
+\r
+               j += (pIE->Length + 2);\r
+       }\r
+\r
+       if ((pmlmeext->cur_channel == rtw_get_oper_ch(padapter)) &&\r
+               (pchsw_info->ch_sw_state & TDLS_WAIT_CH_RSP_STATE)) {\r
+               if (ATOMIC_READ(&pchsw_info->chsw_on) == _TRUE)\r
+                       rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_CH_SW_TO_OFF_CHNL);\r
+       }\r
+\r
+exit:\r
+       return ret;\r
+}\r
+#endif /* CONFIG_TDLS_CH_SW */\r
+\r
+#ifdef CONFIG_WFD\r
+void wfd_ie_tdls(_adapter * padapter, u8 *pframe, u32 *pktlen )\r
+{\r
+       struct mlme_priv                *pmlmepriv = &padapter->mlmepriv;\r
+       struct wifi_display_info        *pwfd_info = padapter->tdlsinfo.wfd_info;\r
+       u8 wfdie[ MAX_WFD_IE_LEN] = { 0x00 };\r
+       u32 wfdielen = 0;\r
+\r
+       if (!hal_chk_wl_func(padapter, WL_FUNC_MIRACAST))\r
+               return;\r
+\r
+       /* WFD OUI */\r
+       wfdielen = 0;\r
+       wfdie[ wfdielen++ ] = 0x50;\r
+       wfdie[ wfdielen++ ] = 0x6F;\r
+       wfdie[ wfdielen++ ] = 0x9A;\r
+       wfdie[ wfdielen++ ] = 0x0A;     /* WFA WFD v1.0 */\r
+\r
+       /*\r
+        *      Commented by Albert 20110825\r
+        *      According to the WFD Specification, the negotiation request frame should contain 3 WFD attributes\r
+        *      1. WFD Device Information\r
+        *      2. Associated BSSID ( Optional )\r
+        *      3. Local IP Adress ( Optional )\r
+        */\r
+\r
+       /* WFD Device Information ATTR */\r
+       /* Type: */\r
+       wfdie[ wfdielen++ ] = WFD_ATTR_DEVICE_INFO;\r
+\r
+       /* Length: */\r
+       /* Note: In the WFD specification, the size of length field is 2. */\r
+       RTW_PUT_BE16(wfdie + wfdielen, 0x0006);\r
+       wfdielen += 2;\r
+\r
+       /* Value1: */\r
+       /* WFD device information */\r
+       /* available for WFD session + Preferred TDLS + WSD ( WFD Service Discovery ) */\r
+       RTW_PUT_BE16(wfdie + wfdielen, pwfd_info->wfd_device_type | WFD_DEVINFO_SESSION_AVAIL \r
+                                                               | WFD_DEVINFO_PC_TDLS | WFD_DEVINFO_WSD);\r
+       wfdielen += 2;\r
+\r
+       /* Value2: */\r
+       /* Session Management Control Port */\r
+       /* Default TCP port for RTSP messages is 554 */\r
+       RTW_PUT_BE16(wfdie + wfdielen, pwfd_info->tdls_rtsp_ctrlport);
+       wfdielen += 2;\r
+\r
+       /* Value3: */\r
+       /* WFD Device Maximum Throughput */\r
+       /* 300Mbps is the maximum throughput */\r
+       RTW_PUT_BE16(wfdie + wfdielen, 300);\r
+       wfdielen += 2;\r
+\r
+       /* Associated BSSID ATTR */\r
+       /* Type: */\r
+       wfdie[ wfdielen++ ] = WFD_ATTR_ASSOC_BSSID;\r
+\r
+       /* Length: */\r
+       /* Note: In the WFD specification, the size of length field is 2. */\r
+       RTW_PUT_BE16(wfdie + wfdielen, 0x0006);\r
+       wfdielen += 2;\r
+\r
+       /* Value: */\r
+       /* Associated BSSID */\r
+       if (check_fwstate( pmlmepriv, _FW_LINKED) == _TRUE)\r
+               _rtw_memcpy(wfdie + wfdielen, &pmlmepriv->assoc_bssid[ 0 ], ETH_ALEN);\r
+       else\r
+               _rtw_memset(wfdie + wfdielen, 0x00, ETH_ALEN);\r
+\r
+       /* Local IP Address ATTR */\r
+       wfdie[ wfdielen++ ] = WFD_ATTR_LOCAL_IP_ADDR;\r
+\r
+       /* Length: */\r
+       /* Note: In the WFD specification, the size of length field is 2. */\r
+       RTW_PUT_BE16(wfdie + wfdielen, 0x0005);\r
+       wfdielen += 2;\r
+\r
+       /* Version: */\r
+       /* 0x01: Version1;IPv4 */\r
+       wfdie[ wfdielen++ ] = 0x01;     \r
+\r
+       /* IPv4 Address */\r
+       _rtw_memcpy( wfdie + wfdielen, pwfd_info->ip_address, 4 );\r
+       wfdielen += 4;\r
+       \r
+       pframe = rtw_set_ie(pframe, _VENDOR_SPECIFIC_IE_, wfdielen, (unsigned char *) wfdie, pktlen);\r
+       \r
+}\r
+#endif /* CONFIG_WFD */\r
+\r
+void rtw_build_tdls_setup_req_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct registry_priv    *pregistrypriv = &padapter->registrypriv;\r
+       struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       struct sta_info *ptdls_sta=rtw_get_stainfo( (&padapter->stapriv) , pattrib->dst);\r
+\r
+       int i = 0 ;\r
+       u32 time;\r
+       u8 *pframe_head;\r
+\r
+       /* SNonce */\r
+       if (pattrib->encrypt) {\r
+               for (i=0;i<8;i++) {\r
+                       time=rtw_get_current_time();\r
+                       _rtw_memcpy(&ptdls_sta->SNonce[4*i], (u8 *)&time, 4);\r
+               }\r
+       }\r
+\r
+       pframe_head = pframe;   /* For rtw_tdls_set_ht_cap() */\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_TDLS);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_dialog(pframe, pattrib, ptxmgmt);\r
+\r
+       pframe = rtw_tdls_set_capability(padapter, pframe, pattrib);\r
+       pframe = rtw_tdls_set_supported_rate(padapter, pframe, pattrib);\r
+       pframe = rtw_tdls_set_sup_ch(&(padapter->mlmeextpriv), pframe, pattrib);\r
+       pframe = rtw_tdls_set_sup_reg_class(pframe, pattrib);\r
+\r
+       if (pattrib->encrypt)\r
+               pframe = rtw_tdls_set_rsnie(ptxmgmt, pframe, pattrib,  _TRUE, ptdls_sta);\r
+\r
+       pframe = rtw_tdls_set_ext_cap(pframe, pattrib);\r
+\r
+       if (pattrib->encrypt) {\r
+               pframe = rtw_tdls_set_ftie(ptxmgmt\r
+                                                                       , pframe\r
+                                                                       , pattrib\r
+                                                                       , NULL\r
+                                                                       , ptdls_sta->SNonce);\r
+\r
+               pframe = rtw_tdls_set_timeout_interval(ptxmgmt, pframe, pattrib, _TRUE, ptdls_sta);\r
+       }\r
+\r
+#ifdef CONFIG_80211N_HT\r
+       /* Sup_reg_classes(optional) */\r
+       if (pregistrypriv->ht_enable == _TRUE)\r
+               pframe = rtw_tdls_set_ht_cap(padapter, pframe_head, pattrib);\r
+#endif\r
+\r
+       pframe = rtw_tdls_set_bss_coexist(padapter, pframe, pattrib);\r
+\r
+       pframe = rtw_tdls_set_linkid(pframe, pattrib, _TRUE);\r
+\r
+       if ((pregistrypriv->wmm_enable == _TRUE) || (padapter->mlmepriv.htpriv.ht_option == _TRUE))\r
+               pframe = rtw_tdls_set_qos_cap(pframe, pattrib);\r
+\r
+#ifdef CONFIG_80211AC_VHT\r
+       if ((padapter->mlmepriv.htpriv.ht_option == _TRUE) && (pmlmeext->cur_channel > 14)\r
+               && REGSTY_IS_11AC_ENABLE(pregistrypriv)\r
+               && hal_chk_proto_cap(padapter, PROTO_CAP_11AC)\r
+               && (!padapter->mlmepriv.country_ent || COUNTRY_CHPLAN_EN_11AC(padapter->mlmepriv.country_ent))\r
+       ) {\r
+               pframe = rtw_tdls_set_aid(padapter, pframe, pattrib);\r
+               pframe = rtw_tdls_set_vht_cap(padapter, pframe, pattrib);\r
+       }\r
+#endif\r
+\r
+#ifdef CONFIG_WFD\r
+       if (padapter->wdinfo.wfd_tdls_enable == 1)\r
+               wfd_ie_tdls(padapter, pframe, &(pattrib->pktlen));\r
+#endif\r
+\r
+}\r
+\r
+void rtw_build_tdls_setup_rsp_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct registry_priv    *pregistrypriv = &padapter->registrypriv;\r
+       struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       struct sta_info *ptdls_sta;\r
+       u8 k; /* for random ANonce */\r
+       u8  *pftie=NULL, *ptimeout_ie = NULL, *plinkid_ie = NULL, *prsnie = NULL, *pftie_mic = NULL;\r
+       u32 time;\r
+       u8 *pframe_head;\r
+\r
+       ptdls_sta = rtw_get_stainfo( &(padapter->stapriv) , pattrib->dst);\r
+\r
+       if (ptdls_sta == NULL)\r
+               DBG_871X("[%s] %d ptdls_sta is NULL\n", __FUNCTION__, __LINE__);\r
+\r
+       if (pattrib->encrypt && ptdls_sta != NULL) {\r
+               for (k=0;k<8;k++) {\r
+                       time = rtw_get_current_time();\r
+                       _rtw_memcpy(&ptdls_sta->ANonce[4*k], (u8*)&time, 4);\r
+               }\r
+       }\r
+\r
+       pframe_head = pframe;\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_TDLS);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_status_code(pframe, pattrib, ptxmgmt);\r
+\r
+       if (ptxmgmt->status_code != 0) {\r
+               DBG_871X("[%s] status_code:%04x \n", __FUNCTION__, ptxmgmt->status_code);\r
+               return;\r
+       }\r
+       \r
+       pframe = rtw_tdls_set_dialog(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_capability(padapter, pframe, pattrib);\r
+       pframe = rtw_tdls_set_supported_rate(padapter, pframe, pattrib);\r
+       pframe = rtw_tdls_set_sup_ch(&(padapter->mlmeextpriv), pframe, pattrib);\r
+       pframe = rtw_tdls_set_sup_reg_class(pframe, pattrib);\r
+\r
+       if (pattrib->encrypt) {\r
+               prsnie = pframe;\r
+               pframe = rtw_tdls_set_rsnie(ptxmgmt, pframe, pattrib,  _FALSE, ptdls_sta);\r
+       }\r
+\r
+       pframe = rtw_tdls_set_ext_cap(pframe, pattrib);\r
+\r
+       if (pattrib->encrypt) {\r
+               if (rtw_tdls_is_driver_setup(padapter) == _TRUE)\r
+                       wpa_tdls_generate_tpk(padapter, ptdls_sta);\r
+\r
+               pftie = pframe;\r
+               pftie_mic = pframe+4;\r
+               pframe = rtw_tdls_set_ftie(ptxmgmt\r
+                                                                       , pframe\r
+                                                                       , pattrib\r
+                                                                       , ptdls_sta->ANonce\r
+                                                                       , ptdls_sta->SNonce);\r
+\r
+               ptimeout_ie = pframe;\r
+               pframe = rtw_tdls_set_timeout_interval(ptxmgmt, pframe, pattrib, _FALSE, ptdls_sta);\r
+       }\r
+\r
+#ifdef CONFIG_80211N_HT\r
+       /* Sup_reg_classes(optional) */\r
+       if (pregistrypriv->ht_enable == _TRUE)\r
+               pframe = rtw_tdls_set_ht_cap(padapter, pframe_head, pattrib);\r
+#endif\r
+\r
+       pframe = rtw_tdls_set_bss_coexist(padapter, pframe, pattrib);\r
+\r
+       plinkid_ie = pframe;\r
+       pframe = rtw_tdls_set_linkid(pframe, pattrib, _FALSE);\r
+\r
+       /* Fill FTIE mic */\r
+       if (pattrib->encrypt && rtw_tdls_is_driver_setup(padapter) == _TRUE)\r
+               wpa_tdls_ftie_mic(ptdls_sta->tpk.kck, 2, plinkid_ie, prsnie, ptimeout_ie, pftie, pftie_mic);\r
+\r
+       if ((pregistrypriv->wmm_enable == _TRUE) || (padapter->mlmepriv.htpriv.ht_option == _TRUE))\r
+               pframe = rtw_tdls_set_qos_cap(pframe, pattrib);\r
+\r
+#ifdef CONFIG_80211AC_VHT\r
+       if ((padapter->mlmepriv.htpriv.ht_option == _TRUE) && (pmlmeext->cur_channel > 14)\r
+               && REGSTY_IS_11AC_ENABLE(pregistrypriv)\r
+               && hal_chk_proto_cap(padapter, PROTO_CAP_11AC)\r
+               && (!padapter->mlmepriv.country_ent || COUNTRY_CHPLAN_EN_11AC(padapter->mlmepriv.country_ent))\r
+       ) {\r
+               pframe = rtw_tdls_set_aid(padapter, pframe, pattrib);\r
+               pframe = rtw_tdls_set_vht_cap(padapter, pframe, pattrib);\r
+               pframe = rtw_tdls_set_vht_op_mode_notify(padapter, pframe, pattrib, pmlmeext->cur_bwmode);\r
+       }\r
+#endif\r
+\r
+#ifdef CONFIG_WFD\r
+       if (padapter->wdinfo.wfd_tdls_enable)\r
+               wfd_ie_tdls(padapter, pframe, &(pattrib->pktlen));\r
+#endif\r
+\r
+}\r
+\r
+void rtw_build_tdls_setup_cfm_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct registry_priv    *pregistrypriv = &padapter->registrypriv;\r
+       struct mlme_ext_priv    *pmlmeext = &(padapter->mlmeextpriv);\r
+       struct mlme_ext_info    *pmlmeinfo = &(pmlmeext->mlmext_info);\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       struct sta_info *ptdls_sta=rtw_get_stainfo( (&padapter->stapriv) , pattrib->dst);\r
+\r
+       unsigned int ie_len;\r
+       unsigned char *p;\r
+       u8 wmm_param_ele[24] = {0};\r
+       u8  *pftie=NULL, *ptimeout_ie=NULL, *plinkid_ie=NULL, *prsnie=NULL, *pftie_mic=NULL;\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_TDLS);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_status_code(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_dialog(pframe, pattrib, ptxmgmt);\r
+\r
+       if (ptxmgmt->status_code!=0)\r
+               return;\r
+       \r
+       if (pattrib->encrypt) {\r
+               prsnie = pframe;\r
+               pframe = rtw_tdls_set_rsnie(ptxmgmt, pframe, pattrib, _TRUE, ptdls_sta);\r
+       }\r
+       \r
+       if (pattrib->encrypt) {\r
+               pftie = pframe;\r
+               pftie_mic = pframe+4;\r
+               pframe = rtw_tdls_set_ftie(ptxmgmt\r
+                                                                       , pframe\r
+                                                                       , pattrib\r
+                                                                       , ptdls_sta->ANonce\r
+                                                                       , ptdls_sta->SNonce);\r
+\r
+               ptimeout_ie = pframe;\r
+               pframe = rtw_tdls_set_timeout_interval(ptxmgmt, pframe, pattrib, _TRUE, ptdls_sta);\r
+\r
+               if (rtw_tdls_is_driver_setup(padapter) == _TRUE) {\r
+                       /* Start TPK timer */\r
+                       ptdls_sta->TPK_count=0;\r
+                       _set_timer(&ptdls_sta->TPK_timer, ONE_SEC);\r
+               }\r
+       }\r
+\r
+       /* HT operation; todo */\r
+       \r
+       plinkid_ie = pframe;\r
+       pframe = rtw_tdls_set_linkid(pframe, pattrib, _TRUE);\r
+\r
+       if (pattrib->encrypt && (rtw_tdls_is_driver_setup(padapter) == _TRUE))\r
+               wpa_tdls_ftie_mic(ptdls_sta->tpk.kck, 3, plinkid_ie, prsnie, ptimeout_ie, pftie, pftie_mic);\r
+\r
+       if (ptdls_sta->qos_option == _TRUE)\r
+               pframe = rtw_tdls_set_wmm_params(padapter, pframe, pattrib);\r
+\r
+#ifdef CONFIG_80211AC_VHT\r
+       if ((padapter->mlmepriv.htpriv.ht_option == _TRUE)\r
+               && (ptdls_sta->vhtpriv.vht_option == _TRUE) && (pmlmeext->cur_channel > 14)\r
+               && REGSTY_IS_11AC_ENABLE(pregistrypriv)\r
+               && hal_chk_proto_cap(padapter, PROTO_CAP_11AC)\r
+               && (!padapter->mlmepriv.country_ent || COUNTRY_CHPLAN_EN_11AC(padapter->mlmepriv.country_ent))\r
+       ) {\r
+               pframe = rtw_tdls_set_vht_operation(padapter, pframe, pattrib, pmlmeext->cur_channel);\r
+               pframe = rtw_tdls_set_vht_op_mode_notify(padapter, pframe, pattrib, pmlmeext->cur_bwmode);\r
+       }\r
+#endif\r
+}\r
+\r
+void rtw_build_tdls_teardown_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       struct sta_info *ptdls_sta = rtw_get_stainfo( &(padapter->stapriv) , pattrib->dst);\r
+       u8  *pftie = NULL, *pftie_mic = NULL, *plinkid_ie = NULL;\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_TDLS);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_status_code(pframe, pattrib, ptxmgmt);\r
+\r
+       if (pattrib->encrypt) {\r
+               pftie = pframe;\r
+               pftie_mic = pframe + 4;\r
+               pframe = rtw_tdls_set_ftie(ptxmgmt\r
+                                                                       , pframe\r
+                                                                       , pattrib\r
+                                                                       , ptdls_sta->ANonce\r
+                                                                       , ptdls_sta->SNonce);\r
+       }\r
+\r
+       plinkid_ie = pframe;\r
+       if (ptdls_sta->tdls_sta_state & TDLS_INITIATOR_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _FALSE);\r
+       else if (ptdls_sta->tdls_sta_state & TDLS_RESPONDER_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _TRUE);\r
+\r
+       if (pattrib->encrypt && (rtw_tdls_is_driver_setup(padapter) == _TRUE))\r
+               wpa_tdls_teardown_ftie_mic(ptdls_sta->tpk.kck, plinkid_ie, ptxmgmt->status_code, 1, 4, pftie, pftie_mic);\r
+}\r
+\r
+void rtw_build_tdls_dis_req_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct pkt_attrib *pattrib = &pxmitframe->attrib;\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_TDLS);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_dialog(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_linkid(pframe, pattrib, _TRUE);\r
+\r
+}\r
+\r
+void rtw_build_tdls_dis_rsp_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt, u8 privacy)\r
+{\r
+       struct registry_priv    *pregistrypriv = &padapter->registrypriv;\r
+       struct mlme_ext_priv    *pmlmeext = &padapter->mlmeextpriv;\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       u8 *pframe_head, pktlen_index;\r
+\r
+       pktlen_index = pattrib->pktlen;\r
+       pframe_head = pframe;\r
+\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_PUBLIC);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_dialog(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_capability(padapter, pframe, pattrib);\r
+\r
+       pframe = rtw_tdls_set_supported_rate(padapter, pframe, pattrib);\r
+\r
+       pframe = rtw_tdls_set_sup_ch(pmlmeext, pframe, pattrib);\r
+\r
+       if (privacy)\r
+               pframe = rtw_tdls_set_rsnie(ptxmgmt, pframe, pattrib, _TRUE, NULL);\r
+\r
+       pframe = rtw_tdls_set_ext_cap(pframe, pattrib);\r
+\r
+       if (privacy) {\r
+               pframe = rtw_tdls_set_ftie(ptxmgmt, pframe, pattrib, NULL, NULL);\r
+               pframe = rtw_tdls_set_timeout_interval(ptxmgmt, pframe, pattrib,  _TRUE, NULL);\r
+       }\r
+\r
+#ifdef CONFIG_80211N_HT\r
+       if (pregistrypriv->ht_enable == _TRUE)\r
+               pframe = rtw_tdls_set_ht_cap(padapter, pframe_head - pktlen_index, pattrib);\r
+#endif\r
+\r
+       pframe = rtw_tdls_set_bss_coexist(padapter, pframe, pattrib);\r
+       pframe = rtw_tdls_set_linkid(pframe, pattrib, _FALSE);\r
+\r
+}\r
+\r
+\r
+void rtw_build_tdls_peer_traffic_indication_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       u8 AC_queue=0;\r
+       struct sta_info *ptdls_sta = rtw_get_stainfo(&padapter->stapriv, pattrib->dst);\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_TDLS);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_dialog(pframe, pattrib, ptxmgmt);\r
+\r
+       if (ptdls_sta->tdls_sta_state & TDLS_INITIATOR_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _FALSE);\r
+       else if (ptdls_sta->tdls_sta_state & TDLS_RESPONDER_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _TRUE);\r
+\r
+       /* PTI control */\r
+       /* PU buffer status */\r
+       if (ptdls_sta->uapsd_bk & BIT(1))\r
+               AC_queue=BIT(0);\r
+       if (ptdls_sta->uapsd_be & BIT(1))\r
+               AC_queue=BIT(1);\r
+       if (ptdls_sta->uapsd_vi & BIT(1))\r
+               AC_queue=BIT(2);\r
+       if (ptdls_sta->uapsd_vo & BIT(1))\r
+               AC_queue=BIT(3);\r
+       pframe = rtw_set_ie(pframe, _PTI_BUFFER_STATUS_, 1, &AC_queue, &(pattrib->pktlen));\r
+       \r
+}\r
+\r
+void rtw_build_tdls_peer_traffic_rsp_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       struct sta_info *ptdls_sta = rtw_get_stainfo(&padapter->stapriv, pattrib->dst);\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_TDLS);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_dialog(pframe, pattrib, ptxmgmt);\r
+\r
+       if (ptdls_sta->tdls_sta_state & TDLS_INITIATOR_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _FALSE);\r
+       else if (ptdls_sta->tdls_sta_state & TDLS_RESPONDER_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _TRUE);\r
+}\r
+\r
+#ifdef CONFIG_TDLS_CH_SW\r
+void rtw_build_tdls_ch_switch_req_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+       struct tdls_info *ptdlsinfo = &padapter->tdlsinfo;\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       struct sta_priv         *pstapriv = &padapter->stapriv;\r
+       struct sta_info *ptdls_sta = rtw_get_stainfo(pstapriv, pattrib->dst);\r
+       u16 switch_time= TDLS_CH_SWITCH_TIME * 1000, switch_timeout=TDLS_CH_SWITCH_TIMEOUT * 1000;\r
+\r
+       ptdls_sta->ch_switch_time=switch_time;\r
+       ptdls_sta->ch_switch_timeout=switch_timeout;\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_TDLS);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_target_ch(padapter, pframe, pattrib);\r
+       pframe = rtw_tdls_set_reg_class(pframe, pattrib, ptdls_sta);\r
+       \r
+       if (ptdlsinfo->chsw_info.ch_offset != HAL_PRIME_CHNL_OFFSET_DONT_CARE) {\r
+               switch (ptdlsinfo->chsw_info.ch_offset)\r
+               {\r
+                       case HAL_PRIME_CHNL_OFFSET_LOWER:\r
+                               pframe = rtw_tdls_set_second_channel_offset(pframe, pattrib, SCA);\r
+                               break;\r
+                       case HAL_PRIME_CHNL_OFFSET_UPPER:\r
+                               pframe = rtw_tdls_set_second_channel_offset(pframe, pattrib, SCB);\r
+                               break;\r
+               }\r
+       }\r
+       \r
+       if (ptdls_sta->tdls_sta_state & TDLS_INITIATOR_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _FALSE);\r
+       else if (ptdls_sta->tdls_sta_state & TDLS_RESPONDER_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _TRUE);\r
+\r
+       pframe = rtw_tdls_set_ch_sw(pframe, pattrib, ptdls_sta);\r
+\r
+}\r
+\r
+void rtw_build_tdls_ch_switch_rsp_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe, struct tdls_txmgmt *ptxmgmt)\r
+{\r
+\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       struct sta_priv         *pstapriv = &padapter->stapriv; \r
+       struct sta_info *ptdls_sta = rtw_get_stainfo(pstapriv, pattrib->dst);\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_tdls_set_category(pframe, pattrib, RTW_WLAN_CATEGORY_TDLS);\r
+       pframe = rtw_tdls_set_action(pframe, pattrib, ptxmgmt);\r
+       pframe = rtw_tdls_set_status_code(pframe, pattrib, ptxmgmt);\r
+\r
+       if (ptdls_sta->tdls_sta_state & TDLS_INITIATOR_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _FALSE);\r
+       else if (ptdls_sta->tdls_sta_state & TDLS_RESPONDER_STATE)\r
+               pframe = rtw_tdls_set_linkid(pframe, pattrib, _TRUE);\r
+\r
+       pframe = rtw_tdls_set_ch_sw(pframe, pattrib, ptdls_sta);\r
+}\r
+#endif\r
+\r
+#ifdef CONFIG_WFD\r
+void rtw_build_tunneled_probe_req_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe)\r
+{\r
+\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       struct wifidirect_info *pwdinfo = &padapter->wdinfo;\r
+       struct wifidirect_info *pbuddy_wdinfo = &padapter->pbuddy_adapter->wdinfo;\r
+       u8 category = RTW_WLAN_CATEGORY_P2P;\r
+       u8 WFA_OUI[3] = { 0x50, 0x6f, 0x9a};\r
+       u8 probe_req = 4;\r
+       u8 wfdielen = 0;\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_set_fixed_ie(pframe, 1, &(category), &(pattrib->pktlen));\r
+       pframe = rtw_set_fixed_ie(pframe, 3, WFA_OUI, &(pattrib->pktlen));\r
+       pframe = rtw_set_fixed_ie(pframe, 1, &(probe_req), &(pattrib->pktlen));\r
+\r
+       if (!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE)) {\r
+               wfdielen = build_probe_req_wfd_ie(pwdinfo, pframe);\r
+               pframe += wfdielen;\r
+               pattrib->pktlen += wfdielen;\r
+       } else if (!rtw_p2p_chk_state(pbuddy_wdinfo, P2P_STATE_NONE)) {\r
+               wfdielen = build_probe_req_wfd_ie(pbuddy_wdinfo, pframe);\r
+               pframe += wfdielen;\r
+               pattrib->pktlen += wfdielen;\r
+       }\r
+       \r
+}\r
+\r
+void rtw_build_tunneled_probe_rsp_ies(_adapter * padapter, struct xmit_frame * pxmitframe, u8 *pframe)\r
+{\r
+\r
+       struct pkt_attrib       *pattrib = &pxmitframe->attrib;\r
+       struct wifidirect_info *pwdinfo = &padapter->wdinfo;\r
+       struct wifidirect_info *pbuddy_wdinfo = &padapter->pbuddy_adapter->wdinfo;\r
+       u8 category = RTW_WLAN_CATEGORY_P2P;\r
+       u8 WFA_OUI[3] = { 0x50, 0x6f, 0x9a};\r
+       u8 probe_rsp = 5;\r
+       u8 wfdielen = 0;\r
+\r
+       pframe = rtw_tdls_set_payload_type(pframe, pattrib);\r
+       pframe = rtw_set_fixed_ie(pframe, 1, &(category), &(pattrib->pktlen));\r
+       pframe = rtw_set_fixed_ie(pframe, 3, WFA_OUI, &(pattrib->pktlen));\r
+       pframe = rtw_set_fixed_ie(pframe, 1, &(probe_rsp), &(pattrib->pktlen));\r
+\r
+       if (!rtw_p2p_chk_state(pwdinfo, P2P_STATE_NONE)) {\r
+               wfdielen = build_probe_resp_wfd_ie(pwdinfo, pframe, 1);\r
+               pframe += wfdielen;\r
+               pattrib->pktlen += wfdielen;\r
+       } else if (!rtw_p2p_chk_state(pbuddy_wdinfo, P2P_STATE_NONE)) {\r
+               wfdielen = build_probe_resp_wfd_ie(pbuddy_wdinfo, pframe, 1);\r
+               pframe += wfdielen;\r
+               pattrib->pktlen += wfdielen;\r
+       }\r
+\r
+}\r
+#endif /* CONFIG_WFD */\r
+\r
+void _tdls_tpk_timer_hdl(void *FunctionContext)\r
+{\r
+       struct sta_info *ptdls_sta = (struct sta_info *)FunctionContext;\r
+       struct tdls_txmgmt txmgmt;\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       ptdls_sta->TPK_count++;\r
+       /* TPK_timer expired in a second */\r
+       /* Retry timer should set at least 301 sec. */\r
+       if (ptdls_sta->TPK_count >= (ptdls_sta->TDLS_PeerKey_Lifetime - 3)) {\r
+               DBG_871X("[TDLS] %s, Re-Setup TDLS link with "MAC_FMT" since TPK lifetime expires!\n", __FUNCTION__, MAC_ARG(ptdls_sta->hwaddr));\r
+               ptdls_sta->TPK_count=0;\r
+               _rtw_memcpy(txmgmt.peer, ptdls_sta->hwaddr, ETH_ALEN);\r
+               issue_tdls_setup_req(ptdls_sta->padapter, &txmgmt, _FALSE);\r
+       }\r
+\r
+       _set_timer(&ptdls_sta->TPK_timer, ONE_SEC);\r
+}\r
+\r
+#ifdef CONFIG_TDLS_CH_SW\r
+void _tdls_ch_switch_timer_hdl(void *FunctionContext)\r
+{\r
+       struct sta_info *ptdls_sta = (struct sta_info *)FunctionContext;\r
+       _adapter *padapter = ptdls_sta->padapter;\r
+       struct tdls_ch_switch *pchsw_info = &padapter->tdlsinfo.chsw_info;\r
+\r
+       rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_CH_SW_END_TO_BASE_CHNL);\r
+       DBG_871X("[TDLS] %s, can't get traffic from op_ch:%d\n", __FUNCTION__, rtw_get_oper_ch(padapter));\r
+}\r
+\r
+void _tdls_delay_timer_hdl(void *FunctionContext)\r
+{\r
+       struct sta_info *ptdls_sta = (struct sta_info *)FunctionContext;\r
+       _adapter *padapter = ptdls_sta->padapter;\r
+       struct tdls_ch_switch *pchsw_info = &padapter->tdlsinfo.chsw_info;\r
+\r
+       DBG_871X("[TDLS] %s, op_ch:%d, tdls_state:0x%08x\n", __FUNCTION__, rtw_get_oper_ch(padapter), ptdls_sta->tdls_sta_state);\r
+       pchsw_info->delay_switch_back = _TRUE;\r
+}\r
+\r
+void _tdls_stay_on_base_chnl_timer_hdl(void *FunctionContext)\r
+{\r
+       struct sta_info *ptdls_sta = (struct sta_info *)FunctionContext;\r
+       _adapter *padapter = ptdls_sta->padapter;\r
+       struct tdls_ch_switch *pchsw_info = &padapter->tdlsinfo.chsw_info;\r
+\r
+       if (ptdls_sta != NULL) {\r
+               issue_tdls_ch_switch_req(padapter, ptdls_sta);\r
+               pchsw_info->ch_sw_state |= TDLS_WAIT_CH_RSP_STATE;\r
+       }\r
+}\r
+\r
+void _tdls_ch_switch_monitor_timer_hdl(void *FunctionContext)\r
+{\r
+       struct sta_info *ptdls_sta = (struct sta_info *)FunctionContext;\r
+       _adapter *padapter = ptdls_sta->padapter;\r
+       struct tdls_ch_switch *pchsw_info = &padapter->tdlsinfo.chsw_info;\r
+\r
+       rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_CH_SW_END);\r
+       DBG_871X("[TDLS] %s, does not receive ch sw req\n", __FUNCTION__);\r
+}\r
+\r
+#endif\r
+\r
+void _tdls_handshake_timer_hdl(void *FunctionContext)\r
+{\r
+       struct sta_info *ptdls_sta = (struct sta_info *)FunctionContext;\r
+       _adapter *padapter = ptdls_sta->padapter;\r
+       struct tdls_txmgmt txmgmt;\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       _rtw_memcpy(txmgmt.peer, ptdls_sta->hwaddr, ETH_ALEN);\r
+       txmgmt.status_code = _RSON_TDLS_TEAR_UN_RSN_;\r
+\r
+       if (ptdls_sta != NULL) {\r
+               DBG_871X("[TDLS] Handshake time out\n");\r
+               if (ptdls_sta->tdls_sta_state & TDLS_LINKED_STATE) \r
+               {\r
+                       rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_TEARDOWN_STA);\r
+               }\r
+               else\r
+               {\r
+                       rtw_tdls_cmd(padapter, ptdls_sta->hwaddr, TDLS_TEARDOWN_STA_LOCALLY);\r
+               }\r
+       }\r
+}\r
+\r
+void _tdls_pti_timer_hdl(void *FunctionContext)\r
+{\r
+       struct sta_info *ptdls_sta = (struct sta_info *)FunctionContext;\r
+       _adapter *padapter = ptdls_sta->padapter;\r
+       struct tdls_txmgmt txmgmt;\r
+\r
+       _rtw_memset(&txmgmt, 0x00, sizeof(struct tdls_txmgmt));\r
+       _rtw_memcpy(txmgmt.peer, ptdls_sta->hwaddr, ETH_ALEN);\r
+       txmgmt.status_code = _RSON_TDLS_TEAR_TOOFAR_;\r
+\r
+       if (ptdls_sta != NULL) {\r
+               if (ptdls_sta->tdls_sta_state & TDLS_WAIT_PTR_STATE) {\r
+                       DBG_871X("[TDLS] Doesn't receive PTR from peer dev:"MAC_FMT"; "\r
+                               "Send TDLS Tear Down\n", MAC_ARG(ptdls_sta->hwaddr));\r
+                       issue_tdls_teardown(padapter, &txmgmt, _FALSE);\r
+               }\r
+       }\r
+}\r
+\r
+void rtw_init_tdls_timer(_adapter *padapter, struct sta_info *psta)\r
+{\r
+       psta->padapter=padapter;\r
+       _init_timer(&psta->TPK_timer, padapter->pnetdev, _tdls_tpk_timer_hdl, psta);\r
+#ifdef CONFIG_TDLS_CH_SW       \r
+       _init_timer(&psta->ch_sw_timer, padapter->pnetdev, _tdls_ch_switch_timer_hdl, psta);\r
+       _init_timer(&psta->delay_timer, padapter->pnetdev, _tdls_delay_timer_hdl, psta);\r
+       _init_timer(&psta->stay_on_base_chnl_timer, padapter->pnetdev, _tdls_stay_on_base_chnl_timer_hdl, psta);\r
+       _init_timer(&psta->ch_sw_monitor_timer, padapter->pnetdev, _tdls_ch_switch_monitor_timer_hdl, psta);\r
+#endif\r
+       _init_timer(&psta->handshake_timer, padapter->pnetdev, _tdls_handshake_timer_hdl, psta);\r
+       _init_timer(&psta->pti_timer, padapter->pnetdev, _tdls_pti_timer_hdl, psta);\r
+}\r
+\r
+void rtw_free_tdls_timer(struct sta_info *psta)\r
+{\r
+       _cancel_timer_ex(&psta->TPK_timer);\r
+#ifdef CONFIG_TDLS_CH_SW       \r
+       _cancel_timer_ex(&psta->ch_sw_timer);\r
+       _cancel_timer_ex(&psta->delay_timer);   \r
+       _cancel_timer_ex(&psta->stay_on_base_chnl_timer);\r
+       _cancel_timer_ex(&psta->ch_sw_monitor_timer);\r
+#endif\r
+       _cancel_timer_ex(&psta->handshake_timer);\r
+       _cancel_timer_ex(&psta->pti_timer);\r
+}\r
+\r
+u8     update_sgi_tdls(_adapter *padapter, struct sta_info *psta)\r
+{\r
+       return query_ra_short_GI(psta);\r
+}\r
+\r
+u32 update_mask_tdls(_adapter *padapter, struct sta_info *psta)\r
+{\r
+       unsigned char sta_band = 0;\r
+       unsigned int tx_ra_bitmap=0;\r
+       struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);\r
+       WLAN_BSSID_EX *pcur_network = (WLAN_BSSID_EX *)&pmlmepriv->cur_network.network;\r
+\r
+       rtw_hal_update_sta_rate_mask(padapter, psta);\r
+       tx_ra_bitmap = psta->ra_mask;\r
+\r
+       if (pcur_network->Configuration.DSConfig > 14) {\r
+               if (tx_ra_bitmap & 0xffff000)\r
+                       sta_band |= WIRELESS_11_5N | WIRELESS_11A;\r
+               else\r
+                       sta_band |= WIRELESS_11A;\r
+       } else {\r
+               if (tx_ra_bitmap & 0xffff000)\r
+                       sta_band |= WIRELESS_11_24N | WIRELESS_11G | WIRELESS_11B;\r
+               else if (tx_ra_bitmap & 0xff0)\r
+                       sta_band |= WIRELESS_11G |WIRELESS_11B;\r
+               else\r
+                       sta_band |= WIRELESS_11B;\r
+       }\r
+\r
+       psta->wireless_mode = sta_band;\r
+\r
+       psta->raid = rtw_hal_networktype_to_raid(padapter,psta);\r
+       tx_ra_bitmap |= ((psta->raid<<28)&0xf0000000);\r
+       return tx_ra_bitmap;\r
+}\r
+\r
+int rtw_tdls_is_driver_setup(_adapter *padapter)\r
+{\r
+       return padapter->tdlsinfo.driver_setup;\r
+}\r
+\r
+const char * rtw_tdls_action_txt(enum TDLS_ACTION_FIELD action)\r
+{\r
+       switch (action) {\r
+       case TDLS_SETUP_REQUEST:\r
+               return "TDLS_SETUP_REQUEST";\r
+       case TDLS_SETUP_RESPONSE:\r
+               return "TDLS_SETUP_RESPONSE";\r
+       case TDLS_SETUP_CONFIRM:\r
+               return "TDLS_SETUP_CONFIRM";\r
+       case TDLS_TEARDOWN:\r
+               return "TDLS_TEARDOWN";\r
+       case TDLS_PEER_TRAFFIC_INDICATION:\r
+               return "TDLS_PEER_TRAFFIC_INDICATION";\r
+       case TDLS_CHANNEL_SWITCH_REQUEST:\r
+               return "TDLS_CHANNEL_SWITCH_REQUEST";\r
+       case TDLS_CHANNEL_SWITCH_RESPONSE:\r
+               return "TDLS_CHANNEL_SWITCH_RESPONSE";\r
+       case TDLS_PEER_PSM_REQUEST:\r
+               return "TDLS_PEER_PSM_REQUEST";\r
+       case TDLS_PEER_PSM_RESPONSE:\r
+               return "TDLS_PEER_PSM_RESPONSE";\r
+       case TDLS_PEER_TRAFFIC_RESPONSE:\r
+               return "TDLS_PEER_TRAFFIC_RESPONSE";\r
+       case TDLS_DISCOVERY_REQUEST:\r
+               return "TDLS_DISCOVERY_REQUEST";\r
+       case TDLS_DISCOVERY_RESPONSE:\r
+               return "TDLS_DISCOVERY_RESPONSE";\r
+       default:\r
+               return "UNKNOWN";\r
+       }\r
+}\r
+\r
+#endif /* CONFIG_TDLS */\r