Staging: rt2860: prepare for rt28[67]0/sta/*.[ch] merge
[linux-2.6] / drivers / staging / rt2860 / sta / assoc.c
1 /*
2  *************************************************************************
3  * Ralink Tech Inc.
4  * 5F., No.36, Taiyuan St., Jhubei City,
5  * Hsinchu County 302,
6  * Taiwan, R.O.C.
7  *
8  * (c) Copyright 2002-2007, Ralink Technology, Inc.
9  *
10  * This program is free software; you can redistribute it and/or modify  *
11  * it under the terms of the GNU General Public License as published by  *
12  * the Free Software Foundation; either version 2 of the License, or     *
13  * (at your option) any later version.                                   *
14  *                                                                       *
15  * This program is distributed in the hope that it will be useful,       *
16  * but WITHOUT ANY WARRANTY; without even the implied warranty of        *
17  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the         *
18  * GNU General Public License for more details.                          *
19  *                                                                       *
20  * You should have received a copy of the GNU General Public License     *
21  * along with this program; if not, write to the                         *
22  * Free Software Foundation, Inc.,                                       *
23  * 59 Temple Place - Suite 330, Boston, MA  02111-1307, USA.             *
24  *                                                                       *
25  *************************************************************************
26
27         Module Name:
28         assoc.c
29
30         Abstract:
31
32         Revision History:
33         Who                     When                    What
34         --------        ----------              ----------------------------------------------
35         John            2004-9-3                porting from RT2500
36 */
37 #include "../rt_config.h"
38
39 UCHAR   CipherWpaTemplate[] = {
40                 0xdd,                                   // WPA IE
41                 0x16,                                   // Length
42                 0x00, 0x50, 0xf2, 0x01, // oui
43                 0x01, 0x00,                             // Version
44                 0x00, 0x50, 0xf2, 0x02, // Multicast
45                 0x01, 0x00,                             // Number of unicast
46                 0x00, 0x50, 0xf2, 0x02, // unicast
47                 0x01, 0x00,                             // number of authentication method
48                 0x00, 0x50, 0xf2, 0x01  // authentication
49                 };
50
51 UCHAR   CipherWpa2Template[] = {
52                 0x30,                                   // RSN IE
53                 0x14,                                   // Length
54                 0x01, 0x00,                             // Version
55                 0x00, 0x0f, 0xac, 0x02, // group cipher, TKIP
56                 0x01, 0x00,                             // number of pairwise
57                 0x00, 0x0f, 0xac, 0x02, // unicast
58                 0x01, 0x00,                             // number of authentication method
59                 0x00, 0x0f, 0xac, 0x02, // authentication
60                 0x00, 0x00,                             // RSN capability
61                 };
62
63 UCHAR   Ccx2IeInfo[] = { 0x00, 0x40, 0x96, 0x03, 0x02};
64
65 /*
66         ==========================================================================
67         Description:
68                 association state machine init, including state transition and timer init
69         Parameters:
70                 S - pointer to the association state machine
71
72         IRQL = PASSIVE_LEVEL
73
74         ==========================================================================
75  */
76 VOID AssocStateMachineInit(
77         IN      PRTMP_ADAPTER   pAd,
78         IN  STATE_MACHINE *S,
79         OUT STATE_MACHINE_FUNC Trans[])
80 {
81         StateMachineInit(S, Trans, MAX_ASSOC_STATE, MAX_ASSOC_MSG, (STATE_MACHINE_FUNC)Drop, ASSOC_IDLE, ASSOC_MACHINE_BASE);
82
83         // first column
84         StateMachineSetAction(S, ASSOC_IDLE, MT2_MLME_ASSOC_REQ, (STATE_MACHINE_FUNC)MlmeAssocReqAction);
85         StateMachineSetAction(S, ASSOC_IDLE, MT2_MLME_REASSOC_REQ, (STATE_MACHINE_FUNC)MlmeReassocReqAction);
86         StateMachineSetAction(S, ASSOC_IDLE, MT2_MLME_DISASSOC_REQ, (STATE_MACHINE_FUNC)MlmeDisassocReqAction);
87         StateMachineSetAction(S, ASSOC_IDLE, MT2_PEER_DISASSOC_REQ, (STATE_MACHINE_FUNC)PeerDisassocAction);
88
89         // second column
90         StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_MLME_ASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenAssoc);
91         StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_MLME_REASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenReassoc);
92         StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_MLME_DISASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenDisassociate);
93         StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_PEER_DISASSOC_REQ, (STATE_MACHINE_FUNC)PeerDisassocAction);
94         StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_PEER_ASSOC_RSP, (STATE_MACHINE_FUNC)PeerAssocRspAction);
95         //
96         // Patch 3Com AP MOde:3CRWE454G72
97         // We send Assoc request frame to this AP, it always send Reassoc Rsp not Associate Rsp.
98         //
99         StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_PEER_REASSOC_RSP, (STATE_MACHINE_FUNC)PeerAssocRspAction);
100         StateMachineSetAction(S, ASSOC_WAIT_RSP, MT2_ASSOC_TIMEOUT, (STATE_MACHINE_FUNC)AssocTimeoutAction);
101
102         // third column
103         StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_MLME_ASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenAssoc);
104         StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_MLME_REASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenReassoc);
105         StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_MLME_DISASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenDisassociate);
106         StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_PEER_DISASSOC_REQ, (STATE_MACHINE_FUNC)PeerDisassocAction);
107         StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_PEER_REASSOC_RSP, (STATE_MACHINE_FUNC)PeerReassocRspAction);
108         //
109         // Patch, AP doesn't send Reassociate Rsp frame to Station.
110         //
111         StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_PEER_ASSOC_RSP, (STATE_MACHINE_FUNC)PeerReassocRspAction);
112         StateMachineSetAction(S, REASSOC_WAIT_RSP, MT2_REASSOC_TIMEOUT, (STATE_MACHINE_FUNC)ReassocTimeoutAction);
113
114         // fourth column
115         StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_MLME_ASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenAssoc);
116         StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_MLME_REASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenReassoc);
117         StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_MLME_DISASSOC_REQ, (STATE_MACHINE_FUNC)InvalidStateWhenDisassociate);
118         StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_PEER_DISASSOC_REQ, (STATE_MACHINE_FUNC)PeerDisassocAction);
119         StateMachineSetAction(S, DISASSOC_WAIT_RSP, MT2_DISASSOC_TIMEOUT, (STATE_MACHINE_FUNC)DisassocTimeoutAction);
120
121         // initialize the timer
122         RTMPInitTimer(pAd, &pAd->MlmeAux.AssocTimer, GET_TIMER_FUNCTION(AssocTimeout), pAd, FALSE);
123         RTMPInitTimer(pAd, &pAd->MlmeAux.ReassocTimer, GET_TIMER_FUNCTION(ReassocTimeout), pAd, FALSE);
124         RTMPInitTimer(pAd, &pAd->MlmeAux.DisassocTimer, GET_TIMER_FUNCTION(DisassocTimeout), pAd, FALSE);
125 }
126
127 /*
128         ==========================================================================
129         Description:
130                 Association timeout procedure. After association timeout, this function
131                 will be called and it will put a message into the MLME queue
132         Parameters:
133                 Standard timer parameters
134
135         IRQL = DISPATCH_LEVEL
136
137         ==========================================================================
138  */
139 VOID AssocTimeout(IN PVOID SystemSpecific1,
140                                  IN PVOID FunctionContext,
141                                  IN PVOID SystemSpecific2,
142                                  IN PVOID SystemSpecific3)
143 {
144         RTMP_ADAPTER *pAd = (RTMP_ADAPTER *)FunctionContext;
145
146         // Do nothing if the driver is starting halt state.
147         // This might happen when timer already been fired before cancel timer with mlmehalt
148         if (RTMP_TEST_FLAG(pAd, fRTMP_ADAPTER_HALT_IN_PROGRESS | fRTMP_ADAPTER_NIC_NOT_EXIST))
149                 return;
150
151         MlmeEnqueue(pAd, ASSOC_STATE_MACHINE, MT2_ASSOC_TIMEOUT, 0, NULL);
152         RT28XX_MLME_HANDLER(pAd);
153 }
154
155 /*
156         ==========================================================================
157         Description:
158                 Reassociation timeout procedure. After reassociation timeout, this
159                 function will be called and put a message into the MLME queue
160         Parameters:
161                 Standard timer parameters
162
163         IRQL = DISPATCH_LEVEL
164
165         ==========================================================================
166  */
167 VOID ReassocTimeout(IN PVOID SystemSpecific1,
168                                         IN PVOID FunctionContext,
169                                         IN PVOID SystemSpecific2,
170                                         IN PVOID SystemSpecific3)
171 {
172         RTMP_ADAPTER *pAd = (RTMP_ADAPTER *)FunctionContext;
173
174         // Do nothing if the driver is starting halt state.
175         // This might happen when timer already been fired before cancel timer with mlmehalt
176         if (RTMP_TEST_FLAG(pAd, fRTMP_ADAPTER_HALT_IN_PROGRESS | fRTMP_ADAPTER_NIC_NOT_EXIST))
177                 return;
178
179         MlmeEnqueue(pAd, ASSOC_STATE_MACHINE, MT2_REASSOC_TIMEOUT, 0, NULL);
180         RT28XX_MLME_HANDLER(pAd);
181 }
182
183 /*
184         ==========================================================================
185         Description:
186                 Disassociation timeout procedure. After disassociation timeout, this
187                 function will be called and put a message into the MLME queue
188         Parameters:
189                 Standard timer parameters
190
191         IRQL = DISPATCH_LEVEL
192
193         ==========================================================================
194  */
195 VOID DisassocTimeout(IN PVOID SystemSpecific1,
196                                         IN PVOID FunctionContext,
197                                         IN PVOID SystemSpecific2,
198                                         IN PVOID SystemSpecific3)
199 {
200         RTMP_ADAPTER *pAd = (RTMP_ADAPTER *)FunctionContext;
201
202         // Do nothing if the driver is starting halt state.
203         // This might happen when timer already been fired before cancel timer with mlmehalt
204         if (RTMP_TEST_FLAG(pAd, fRTMP_ADAPTER_HALT_IN_PROGRESS | fRTMP_ADAPTER_NIC_NOT_EXIST))
205                 return;
206
207         MlmeEnqueue(pAd, ASSOC_STATE_MACHINE, MT2_DISASSOC_TIMEOUT, 0, NULL);
208         RT28XX_MLME_HANDLER(pAd);
209 }
210
211 /*
212         ==========================================================================
213         Description:
214                 mlme assoc req handling procedure
215         Parameters:
216                 Adapter - Adapter pointer
217                 Elem - MLME Queue Element
218         Pre:
219                 the station has been authenticated and the following information is stored in the config
220                         -# SSID
221                         -# supported rates and their length
222                         -# listen interval (Adapter->StaCfg.default_listen_count)
223                         -# Transmit power  (Adapter->StaCfg.tx_power)
224         Post  :
225                 -# An association request frame is generated and sent to the air
226                 -# Association timer starts
227                 -# Association state -> ASSOC_WAIT_RSP
228
229         IRQL = DISPATCH_LEVEL
230
231         ==========================================================================
232  */
233 VOID MlmeAssocReqAction(
234         IN PRTMP_ADAPTER pAd,
235         IN MLME_QUEUE_ELEM *Elem)
236 {
237         UCHAR                   ApAddr[6];
238         HEADER_802_11   AssocHdr;
239         UCHAR                   Ccx2Len = 5;
240         UCHAR                   WmeIe[9] = {IE_VENDOR_SPECIFIC, 0x07, 0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
241         USHORT                  ListenIntv;
242         ULONG                   Timeout;
243         USHORT                  CapabilityInfo;
244         BOOLEAN                 TimerCancelled;
245         PUCHAR                  pOutBuffer = NULL;
246         NDIS_STATUS             NStatus;
247         ULONG                   FrameLen = 0;
248         ULONG                   tmp;
249         USHORT                  VarIesOffset;
250         UCHAR                   CkipFlag;
251         UCHAR                   CkipNegotiationBuffer[CKIP_NEGOTIATION_LENGTH];
252         UCHAR                   AironetCkipIe = IE_AIRONET_CKIP;
253         UCHAR                   AironetCkipLen = CKIP_NEGOTIATION_LENGTH;
254         UCHAR                   AironetIPAddressIE = IE_AIRONET_IPADDRESS;
255         UCHAR                   AironetIPAddressLen = AIRONET_IPADDRESS_LENGTH;
256         UCHAR                   AironetIPAddressBuffer[AIRONET_IPADDRESS_LENGTH] = {0x00, 0x40, 0x96, 0x00, 0x00, 0x00, 0x00, 0x00, 0x02, 0x00};
257         USHORT                  Status;
258
259         // Block all authentication request durning WPA block period
260         if (pAd->StaCfg.bBlockAssoc == TRUE)
261         {
262                 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Block Assoc request durning WPA block period!\n"));
263                 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
264                 Status = MLME_STATE_MACHINE_REJECT;
265                 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
266         }
267         // check sanity first
268         else if (MlmeAssocReqSanity(pAd, Elem->Msg, Elem->MsgLen, ApAddr, &CapabilityInfo, &Timeout, &ListenIntv))
269         {
270                 RTMPCancelTimer(&pAd->MlmeAux.AssocTimer, &TimerCancelled);
271                 COPY_MAC_ADDR(pAd->MlmeAux.Bssid, ApAddr);
272
273                 // Get an unused nonpaged memory
274                 NStatus = MlmeAllocateMemory(pAd, &pOutBuffer);
275                 if (NStatus != NDIS_STATUS_SUCCESS)
276                 {
277                         DBGPRINT(RT_DEBUG_TRACE,("ASSOC - MlmeAssocReqAction() allocate memory failed \n"));
278                         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
279                         Status = MLME_FAIL_NO_RESOURCE;
280                         MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
281                         return;
282                 }
283
284                 // Add by James 03/06/27
285                 pAd->StaCfg.AssocInfo.Length = sizeof(NDIS_802_11_ASSOCIATION_INFORMATION);
286                 // Association don't need to report MAC address
287                 pAd->StaCfg.AssocInfo.AvailableRequestFixedIEs =
288                         NDIS_802_11_AI_REQFI_CAPABILITIES | NDIS_802_11_AI_REQFI_LISTENINTERVAL;
289                 pAd->StaCfg.AssocInfo.RequestFixedIEs.Capabilities = CapabilityInfo;
290                 pAd->StaCfg.AssocInfo.RequestFixedIEs.ListenInterval = ListenIntv;
291                 // Only reassociate need this
292                 //COPY_MAC_ADDR(pAd->StaCfg.AssocInfo.RequestFixedIEs.CurrentAPAddress, ApAddr);
293                 pAd->StaCfg.AssocInfo.OffsetRequestIEs = sizeof(NDIS_802_11_ASSOCIATION_INFORMATION);
294
295         NdisZeroMemory(pAd->StaCfg.ReqVarIEs, MAX_VIE_LEN);
296                 // First add SSID
297                 VarIesOffset = 0;
298                 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &SsidIe, 1);
299                 VarIesOffset += 1;
300                 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &pAd->MlmeAux.SsidLen, 1);
301                 VarIesOffset += 1;
302                 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, pAd->MlmeAux.Ssid, pAd->MlmeAux.SsidLen);
303                 VarIesOffset += pAd->MlmeAux.SsidLen;
304
305                 // Second add Supported rates
306                 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &SupRateIe, 1);
307                 VarIesOffset += 1;
308                 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &pAd->MlmeAux.SupRateLen, 1);
309                 VarIesOffset += 1;
310                 NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, pAd->MlmeAux.SupRate, pAd->MlmeAux.SupRateLen);
311                 VarIesOffset += pAd->MlmeAux.SupRateLen;
312                 // End Add by James
313
314         if ((pAd->CommonCfg.Channel > 14) &&
315             (pAd->CommonCfg.bIEEE80211H == TRUE))
316             CapabilityInfo |= 0x0100;
317
318                 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Send ASSOC request...\n"));
319                 MgtMacHeaderInit(pAd, &AssocHdr, SUBTYPE_ASSOC_REQ, 0, ApAddr, ApAddr);
320
321                 // Build basic frame first
322                 MakeOutgoingFrame(pOutBuffer,                           &FrameLen,
323                                                   sizeof(HEADER_802_11),        &AssocHdr,
324                                                   2,                                            &CapabilityInfo,
325                                                   2,                                            &ListenIntv,
326                                                   1,                                            &SsidIe,
327                                                   1,                                            &pAd->MlmeAux.SsidLen,
328                                                   pAd->MlmeAux.SsidLen,         pAd->MlmeAux.Ssid,
329                                                   1,                                            &SupRateIe,
330                                                   1,                                            &pAd->MlmeAux.SupRateLen,
331                                                   pAd->MlmeAux.SupRateLen,  pAd->MlmeAux.SupRate,
332                                                   END_OF_ARGS);
333
334                 if (pAd->MlmeAux.ExtRateLen != 0)
335                 {
336                         MakeOutgoingFrame(pOutBuffer + FrameLen,    &tmp,
337                                                           1,                        &ExtRateIe,
338                                                           1,                        &pAd->MlmeAux.ExtRateLen,
339                                                           pAd->MlmeAux.ExtRateLen,  pAd->MlmeAux.ExtRate,
340                                                           END_OF_ARGS);
341                         FrameLen += tmp;
342                 }
343
344                 // HT
345                 if ((pAd->MlmeAux.HtCapabilityLen > 0) && (pAd->CommonCfg.PhyMode >= PHY_11ABGN_MIXED))
346                 {
347                         ULONG TmpLen;
348                         UCHAR HtLen;
349                         UCHAR BROADCOM[4] = {0x0, 0x90, 0x4c, 0x33};
350                         if (pAd->StaActive.SupportedPhyInfo.bPreNHt == TRUE)
351                         {
352                                 HtLen = SIZE_HT_CAP_IE + 4;
353                                 MakeOutgoingFrame(pOutBuffer + FrameLen,            &TmpLen,
354                                                           1,                                &WpaIe,
355                                                           1,                                &HtLen,
356                                                           4,                                &BROADCOM[0],
357                                                          pAd->MlmeAux.HtCapabilityLen,          &pAd->MlmeAux.HtCapability,
358                                                           END_OF_ARGS);
359                         }
360                         else
361                         {
362                                 MakeOutgoingFrame(pOutBuffer + FrameLen,            &TmpLen,
363                                                           1,                                &HtCapIe,
364                                                           1,                                &pAd->MlmeAux.HtCapabilityLen,
365                                                          pAd->MlmeAux.HtCapabilityLen,          &pAd->MlmeAux.HtCapability,
366                                                           END_OF_ARGS);
367                         }
368                         FrameLen += TmpLen;
369                 }
370
371                 // add Ralink proprietary IE to inform AP this STA is going to use AGGREGATION or PIGGY-BACK+AGGREGATION
372                 // Case I: (Aggregation + Piggy-Back)
373                 // 1. user enable aggregation, AND
374                 // 2. Mac support piggy-back
375                 // 3. AP annouces it's PIGGY-BACK+AGGREGATION-capable in BEACON
376                 // Case II: (Aggregation)
377                 // 1. user enable aggregation, AND
378                 // 2. AP annouces it's AGGREGATION-capable in BEACON
379                 if (pAd->CommonCfg.bAggregationCapable)
380                 {
381                         if ((pAd->CommonCfg.bPiggyBackCapable) && ((pAd->MlmeAux.APRalinkIe & 0x00000003) == 3))
382                         {
383                                 ULONG TmpLen;
384                                 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x03, 0x00, 0x00, 0x00};
385                                 MakeOutgoingFrame(pOutBuffer+FrameLen,           &TmpLen,
386                                                                   9,                             RalinkIe,
387                                                                   END_OF_ARGS);
388                                 FrameLen += TmpLen;
389                         }
390                         else if (pAd->MlmeAux.APRalinkIe & 0x00000001)
391                         {
392                                 ULONG TmpLen;
393                                 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x01, 0x00, 0x00, 0x00};
394                                 MakeOutgoingFrame(pOutBuffer+FrameLen,           &TmpLen,
395                                                                   9,                             RalinkIe,
396                                                                   END_OF_ARGS);
397                                 FrameLen += TmpLen;
398                         }
399                 }
400                 else
401                 {
402                         ULONG TmpLen;
403                         UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x06, 0x00, 0x00, 0x00};
404                         MakeOutgoingFrame(pOutBuffer+FrameLen,           &TmpLen,
405                                                           9,                                             RalinkIe,
406                                                           END_OF_ARGS);
407                         FrameLen += TmpLen;
408                 }
409
410                 if (pAd->MlmeAux.APEdcaParm.bValid)
411                 {
412                         if (pAd->CommonCfg.bAPSDCapable && pAd->MlmeAux.APEdcaParm.bAPSDCapable)
413                         {
414                                 QBSS_STA_INFO_PARM QosInfo;
415
416                                 NdisZeroMemory(&QosInfo, sizeof(QBSS_STA_INFO_PARM));
417                                 QosInfo.UAPSD_AC_BE = pAd->CommonCfg.bAPSDAC_BE;
418                                 QosInfo.UAPSD_AC_BK = pAd->CommonCfg.bAPSDAC_BK;
419                                 QosInfo.UAPSD_AC_VI = pAd->CommonCfg.bAPSDAC_VI;
420                                 QosInfo.UAPSD_AC_VO = pAd->CommonCfg.bAPSDAC_VO;
421                                 QosInfo.MaxSPLength = pAd->CommonCfg.MaxSPLength;
422                                 WmeIe[8] |= *(PUCHAR)&QosInfo;
423                         }
424                         else
425                         {
426                 // The Parameter Set Count is set to Â¡Â§0¡¨ in the association request frames
427                 // WmeIe[8] |= (pAd->MlmeAux.APEdcaParm.EdcaUpdateCount & 0x0f);
428                         }
429
430                         MakeOutgoingFrame(pOutBuffer + FrameLen,    &tmp,
431                                                           9,                        &WmeIe[0],
432                                                           END_OF_ARGS);
433                         FrameLen += tmp;
434                 }
435
436                 //
437                 // Let WPA(#221) Element ID on the end of this association frame.
438                 // Otherwise some AP will fail on parsing Element ID and set status fail on Assoc Rsp.
439                 // For example: Put Vendor Specific IE on the front of WPA IE.
440                 // This happens on AP (Model No:Linksys WRK54G)
441                 //
442                 if (((pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPAPSK) ||
443             (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2PSK) ||
444             (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA) ||
445             (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2)
446                         )
447             )
448                 {
449                         UCHAR RSNIe = IE_WPA;
450
451                         if ((pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2PSK) ||
452                 (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2))
453                         {
454                                 RSNIe = IE_WPA2;
455                         }
456
457 #ifdef RT30xx
458 #ifdef SIOCSIWGENIE
459                         if (pAd->StaCfg.WpaSupplicantUP != 1)
460 #endif // SIOCSIWGENIE //
461 #endif
462             RTMPMakeRSNIE(pAd, pAd->StaCfg.AuthMode, pAd->StaCfg.WepStatus, BSS0);
463
464             // Check for WPA PMK cache list
465                         if (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2)
466                         {
467                             INT     idx;
468                 BOOLEAN FoundPMK = FALSE;
469                                 // Search chched PMKID, append it if existed
470                                 for (idx = 0; idx < PMKID_NO; idx++)
471                                 {
472                                         if (NdisEqualMemory(ApAddr, &pAd->StaCfg.SavedPMK[idx].BSSID, 6))
473                                         {
474                                                 FoundPMK = TRUE;
475                                                 break;
476                                         }
477                                 }
478
479                                 if (FoundPMK)
480                                 {
481                                         // Set PMK number
482                                         *(PUSHORT) &pAd->StaCfg.RSN_IE[pAd->StaCfg.RSNIE_Len] = 1;
483                                         NdisMoveMemory(&pAd->StaCfg.RSN_IE[pAd->StaCfg.RSNIE_Len + 2], &pAd->StaCfg.SavedPMK[idx].PMKID, 16);
484                     pAd->StaCfg.RSNIE_Len += 18;
485                                 }
486                         }
487
488 #ifdef RT30xx
489 #ifdef SIOCSIWGENIE
490                         if (pAd->StaCfg.WpaSupplicantUP == 1)
491                         {
492                                 MakeOutgoingFrame(pOutBuffer + FrameLen,                &tmp,
493                                                 pAd->StaCfg.RSNIE_Len,                  pAd->StaCfg.RSN_IE,
494                                                 END_OF_ARGS);
495                         }
496                         else
497 #endif
498 #endif
499                         {
500                                 MakeOutgoingFrame(pOutBuffer + FrameLen,                &tmp,
501                                                         1,                              &RSNIe,
502                                                 1,                              &pAd->StaCfg.RSNIE_Len,
503                                                 pAd->StaCfg.RSNIE_Len,                  pAd->StaCfg.RSN_IE,
504                                                 END_OF_ARGS);
505                         }
506
507                         FrameLen += tmp;
508
509 #ifdef RT30xx
510 #ifdef SIOCSIWGENIE
511                         if (pAd->StaCfg.WpaSupplicantUP != 1)
512 #endif
513 #endif
514                         {
515                     // Append Variable IE
516                     NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &RSNIe, 1);
517                     VarIesOffset += 1;
518                     NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, &pAd->StaCfg.RSNIE_Len, 1);
519                     VarIesOffset += 1;
520                         }
521                         NdisMoveMemory(pAd->StaCfg.ReqVarIEs + VarIesOffset, pAd->StaCfg.RSN_IE, pAd->StaCfg.RSNIE_Len);
522                         VarIesOffset += pAd->StaCfg.RSNIE_Len;
523
524                         // Set Variable IEs Length
525                         pAd->StaCfg.ReqVarIELen = VarIesOffset;
526                 }
527
528                 // We have update that at PeerBeaconAtJoinRequest()
529                 CkipFlag = pAd->StaCfg.CkipFlag;
530                 if (CkipFlag != 0)
531                 {
532                         NdisZeroMemory(CkipNegotiationBuffer, CKIP_NEGOTIATION_LENGTH);
533                         CkipNegotiationBuffer[2] = 0x66;
534                         // Make it try KP & MIC, since we have to follow the result from AssocRsp
535                         CkipNegotiationBuffer[8] = 0x18;
536                         CkipNegotiationBuffer[CKIP_NEGOTIATION_LENGTH - 1] = 0x22;
537                         CkipFlag = 0x18;
538
539                         MakeOutgoingFrame(pOutBuffer + FrameLen,        &tmp,
540                                                 1,                                                              &AironetCkipIe,
541                                                 1,                                                              &AironetCkipLen,
542                                                 AironetCkipLen,                                 CkipNegotiationBuffer,
543                                                 END_OF_ARGS);
544                         FrameLen += tmp;
545                 }
546
547                 // Add CCX v2 request if CCX2 admin state is on
548                 if (pAd->StaCfg.CCXControl.field.Enable == 1)
549                 {
550
551                         //
552                         // Add AironetIPAddressIE for Cisco CCX 2.X
553                         // Add CCX Version
554                         //
555                         MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
556                                                 1,                                                      &AironetIPAddressIE,
557                                                 1,                                                      &AironetIPAddressLen,
558                                                 AironetIPAddressLen,            AironetIPAddressBuffer,
559                                                 1,                                                      &Ccx2Ie,
560                                                 1,                                                      &Ccx2Len,
561                                                 Ccx2Len,                                    Ccx2IeInfo,
562                                                 END_OF_ARGS);
563                         FrameLen += tmp;
564
565                         // Add by James 03/06/27
566                         // Set Variable IEs Length
567                         pAd->StaCfg.ReqVarIELen = VarIesOffset;
568                         pAd->StaCfg.AssocInfo.RequestIELength = VarIesOffset;
569
570                         // OffsetResponseIEs follow ReqVarIE
571                         pAd->StaCfg.AssocInfo.OffsetResponseIEs = sizeof(NDIS_802_11_ASSOCIATION_INFORMATION) + pAd->StaCfg.ReqVarIELen;
572                         // End Add by James
573                 }
574
575
576                 MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
577                 MlmeFreeMemory(pAd, pOutBuffer);
578
579                 RTMPSetTimer(&pAd->MlmeAux.AssocTimer, Timeout);
580                 pAd->Mlme.AssocMachine.CurrState = ASSOC_WAIT_RSP;
581         }
582         else
583         {
584                 DBGPRINT(RT_DEBUG_TRACE,("ASSOC - MlmeAssocReqAction() sanity check failed. BUG!!!!!! \n"));
585                 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
586                 Status = MLME_INVALID_FORMAT;
587                 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
588         }
589
590 }
591
592 /*
593         ==========================================================================
594         Description:
595                 mlme reassoc req handling procedure
596         Parameters:
597                 Elem -
598         Pre:
599                 -# SSID  (Adapter->StaCfg.ssid[])
600                 -# BSSID (AP address, Adapter->StaCfg.bssid)
601                 -# Supported rates (Adapter->StaCfg.supported_rates[])
602                 -# Supported rates length (Adapter->StaCfg.supported_rates_len)
603                 -# Tx power (Adapter->StaCfg.tx_power)
604
605         IRQL = DISPATCH_LEVEL
606
607         ==========================================================================
608  */
609 VOID MlmeReassocReqAction(
610         IN PRTMP_ADAPTER pAd,
611         IN MLME_QUEUE_ELEM *Elem)
612 {
613         UCHAR                   ApAddr[6];
614         HEADER_802_11   ReassocHdr;
615         UCHAR                   Ccx2Len = 5;
616         UCHAR                   WmeIe[9] = {IE_VENDOR_SPECIFIC, 0x07, 0x00, 0x50, 0xf2, 0x02, 0x00, 0x01, 0x00};
617         USHORT                  CapabilityInfo, ListenIntv;
618         ULONG                   Timeout;
619         ULONG                   FrameLen = 0;
620         BOOLEAN                 TimerCancelled;
621         NDIS_STATUS             NStatus;
622         ULONG                   tmp;
623         PUCHAR                  pOutBuffer = NULL;
624         USHORT                  Status;
625
626         // Block all authentication request durning WPA block period
627         if (pAd->StaCfg.bBlockAssoc == TRUE)
628         {
629                 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Block ReAssoc request durning WPA block period!\n"));
630                 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
631                 Status = MLME_STATE_MACHINE_REJECT;
632                 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
633         }
634         // the parameters are the same as the association
635         else if(MlmeAssocReqSanity(pAd, Elem->Msg, Elem->MsgLen, ApAddr, &CapabilityInfo, &Timeout, &ListenIntv))
636         {
637                 RTMPCancelTimer(&pAd->MlmeAux.ReassocTimer, &TimerCancelled);
638
639                 NStatus = MlmeAllocateMemory(pAd, &pOutBuffer);  //Get an unused nonpaged memory
640                 if(NStatus != NDIS_STATUS_SUCCESS)
641                 {
642                         DBGPRINT(RT_DEBUG_TRACE,("ASSOC - MlmeReassocReqAction() allocate memory failed \n"));
643                         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
644                         Status = MLME_FAIL_NO_RESOURCE;
645                         MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
646                         return;
647                 }
648
649                 COPY_MAC_ADDR(pAd->MlmeAux.Bssid, ApAddr);
650
651                 // make frame, use bssid as the AP address??
652                 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Send RE-ASSOC request...\n"));
653                 MgtMacHeaderInit(pAd, &ReassocHdr, SUBTYPE_REASSOC_REQ, 0, ApAddr, ApAddr);
654                 MakeOutgoingFrame(pOutBuffer,               &FrameLen,
655                                                   sizeof(HEADER_802_11),    &ReassocHdr,
656                                                   2,                        &CapabilityInfo,
657                                                   2,                        &ListenIntv,
658                                                   MAC_ADDR_LEN,             ApAddr,
659                                                   1,                        &SsidIe,
660                                                   1,                        &pAd->MlmeAux.SsidLen,
661                                                   pAd->MlmeAux.SsidLen,     pAd->MlmeAux.Ssid,
662                                                   1,                        &SupRateIe,
663                                                   1,                                            &pAd->MlmeAux.SupRateLen,
664                                                   pAd->MlmeAux.SupRateLen,  pAd->MlmeAux.SupRate,
665                                                   END_OF_ARGS);
666
667                 if (pAd->MlmeAux.ExtRateLen != 0)
668                 {
669                         MakeOutgoingFrame(pOutBuffer + FrameLen,        &tmp,
670                                                           1,                            &ExtRateIe,
671                                                           1,                            &pAd->MlmeAux.ExtRateLen,
672                                                           pAd->MlmeAux.ExtRateLen,          pAd->MlmeAux.ExtRate,
673                                                           END_OF_ARGS);
674                         FrameLen += tmp;
675                 }
676
677                 if (pAd->MlmeAux.APEdcaParm.bValid)
678                 {
679                         if (pAd->CommonCfg.bAPSDCapable && pAd->MlmeAux.APEdcaParm.bAPSDCapable)
680                         {
681                                 QBSS_STA_INFO_PARM QosInfo;
682
683                                 NdisZeroMemory(&QosInfo, sizeof(QBSS_STA_INFO_PARM));
684                                 QosInfo.UAPSD_AC_BE = pAd->CommonCfg.bAPSDAC_BE;
685                                 QosInfo.UAPSD_AC_BK = pAd->CommonCfg.bAPSDAC_BK;
686                                 QosInfo.UAPSD_AC_VI = pAd->CommonCfg.bAPSDAC_VI;
687                                 QosInfo.UAPSD_AC_VO = pAd->CommonCfg.bAPSDAC_VO;
688                                 QosInfo.MaxSPLength = pAd->CommonCfg.MaxSPLength;
689                                 WmeIe[8] |= *(PUCHAR)&QosInfo;
690                         }
691
692                         MakeOutgoingFrame(pOutBuffer + FrameLen,    &tmp,
693                                                           9,                        &WmeIe[0],
694                                                           END_OF_ARGS);
695                         FrameLen += tmp;
696                 }
697
698                 // HT
699                 if ((pAd->MlmeAux.HtCapabilityLen > 0) && (pAd->CommonCfg.PhyMode >= PHY_11ABGN_MIXED))
700                 {
701                         ULONG TmpLen;
702                         UCHAR HtLen;
703                         UCHAR BROADCOM[4] = {0x0, 0x90, 0x4c, 0x33};
704                         if (pAd->StaActive.SupportedPhyInfo.bPreNHt == TRUE)
705                         {
706                                 HtLen = SIZE_HT_CAP_IE + 4;
707                                 MakeOutgoingFrame(pOutBuffer + FrameLen,            &TmpLen,
708                                                           1,                                &WpaIe,
709                                                           1,                                &HtLen,
710                                                           4,                                &BROADCOM[0],
711                                                          pAd->MlmeAux.HtCapabilityLen,          &pAd->MlmeAux.HtCapability,
712                                                           END_OF_ARGS);
713                         }
714                         else
715                         {
716                                 MakeOutgoingFrame(pOutBuffer + FrameLen,            &TmpLen,
717                                                           1,                                &HtCapIe,
718                                                           1,                                &pAd->MlmeAux.HtCapabilityLen,
719                                                          pAd->MlmeAux.HtCapabilityLen,          &pAd->MlmeAux.HtCapability,
720                                                           END_OF_ARGS);
721                         }
722                         FrameLen += TmpLen;
723                 }
724
725                 // add Ralink proprietary IE to inform AP this STA is going to use AGGREGATION or PIGGY-BACK+AGGREGATION
726                 // Case I: (Aggregation + Piggy-Back)
727                 // 1. user enable aggregation, AND
728                 // 2. Mac support piggy-back
729                 // 3. AP annouces it's PIGGY-BACK+AGGREGATION-capable in BEACON
730                 // Case II: (Aggregation)
731                 // 1. user enable aggregation, AND
732                 // 2. AP annouces it's AGGREGATION-capable in BEACON
733                 if (pAd->CommonCfg.bAggregationCapable)
734                 {
735                         if ((pAd->CommonCfg.bPiggyBackCapable) && ((pAd->MlmeAux.APRalinkIe & 0x00000003) == 3))
736                         {
737                                 ULONG TmpLen;
738                                 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x03, 0x00, 0x00, 0x00};
739                                 MakeOutgoingFrame(pOutBuffer+FrameLen,           &TmpLen,
740                                                                   9,                             RalinkIe,
741                                                                   END_OF_ARGS);
742                                 FrameLen += TmpLen;
743                         }
744                         else if (pAd->MlmeAux.APRalinkIe & 0x00000001)
745                         {
746                                 ULONG TmpLen;
747                                 UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x01, 0x00, 0x00, 0x00};
748                                 MakeOutgoingFrame(pOutBuffer+FrameLen,           &TmpLen,
749                                                                   9,                             RalinkIe,
750                                                                   END_OF_ARGS);
751                                 FrameLen += TmpLen;
752                         }
753                 }
754                 else
755                 {
756                         ULONG TmpLen;
757                         UCHAR RalinkIe[9] = {IE_VENDOR_SPECIFIC, 7, 0x00, 0x0c, 0x43, 0x04, 0x00, 0x00, 0x00};
758                         MakeOutgoingFrame(pOutBuffer+FrameLen,           &TmpLen,
759                                                           9,                                             RalinkIe,
760                                                           END_OF_ARGS);
761                         FrameLen += TmpLen;
762                 }
763
764                 // Add CCX v2 request if CCX2 admin state is on
765                 if (pAd->StaCfg.CCXControl.field.Enable == 1)
766                 {
767                         //
768                         // Add CCX Version
769                         //
770                         MakeOutgoingFrame(pOutBuffer + FrameLen, &tmp,
771                                                 1,                                                      &Ccx2Ie,
772                                                 1,                                                      &Ccx2Len,
773                                                 Ccx2Len,                                    Ccx2IeInfo,
774                                                 END_OF_ARGS);
775                         FrameLen += tmp;
776                 }
777
778                 MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
779                 MlmeFreeMemory(pAd, pOutBuffer);
780
781                 RTMPSetTimer(&pAd->MlmeAux.ReassocTimer, Timeout); /* in mSec */
782                 pAd->Mlme.AssocMachine.CurrState = REASSOC_WAIT_RSP;
783         }
784         else
785         {
786                 DBGPRINT(RT_DEBUG_TRACE,("ASSOC - MlmeReassocReqAction() sanity check failed. BUG!!!! \n"));
787                 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
788                 Status = MLME_INVALID_FORMAT;
789                 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
790         }
791 }
792
793 /*
794         ==========================================================================
795         Description:
796                 Upper layer issues disassoc request
797         Parameters:
798                 Elem -
799
800         IRQL = PASSIVE_LEVEL
801
802         ==========================================================================
803  */
804 VOID MlmeDisassocReqAction(
805         IN PRTMP_ADAPTER pAd,
806         IN MLME_QUEUE_ELEM *Elem)
807 {
808         PMLME_DISASSOC_REQ_STRUCT pDisassocReq;
809         HEADER_802_11         DisassocHdr;
810         PHEADER_802_11        pDisassocHdr;
811         PUCHAR                pOutBuffer = NULL;
812         ULONG                 FrameLen = 0;
813         NDIS_STATUS           NStatus;
814         BOOLEAN               TimerCancelled;
815         ULONG                 Timeout = 0;
816         USHORT                Status;
817
818         // skip sanity check
819         pDisassocReq = (PMLME_DISASSOC_REQ_STRUCT)(Elem->Msg);
820
821         NStatus = MlmeAllocateMemory(pAd, &pOutBuffer);  //Get an unused nonpaged memory
822         if (NStatus != NDIS_STATUS_SUCCESS)
823         {
824                 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - MlmeDisassocReqAction() allocate memory failed\n"));
825                 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
826                 Status = MLME_FAIL_NO_RESOURCE;
827                 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_DISASSOC_CONF, 2, &Status);
828                 return;
829         }
830
831
832
833         RTMPCancelTimer(&pAd->MlmeAux.DisassocTimer, &TimerCancelled);
834
835         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Send DISASSOC request[BSSID::%02x:%02x:%02x:%02x:%02x:%02x (Reason=%d)\n",
836                                 pDisassocReq->Addr[0], pDisassocReq->Addr[1], pDisassocReq->Addr[2],
837                                 pDisassocReq->Addr[3], pDisassocReq->Addr[4], pDisassocReq->Addr[5], pDisassocReq->Reason));
838         MgtMacHeaderInit(pAd, &DisassocHdr, SUBTYPE_DISASSOC, 0, pDisassocReq->Addr, pDisassocReq->Addr);       // patch peap ttls switching issue
839         MakeOutgoingFrame(pOutBuffer,           &FrameLen,
840                                           sizeof(HEADER_802_11),&DisassocHdr,
841                                           2,                    &pDisassocReq->Reason,
842                                           END_OF_ARGS);
843         MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
844
845         // To patch Instance and Buffalo(N) AP
846         // Driver has to send deauth to Instance AP, but Buffalo(N) needs to send disassoc to reset Authenticator's state machine
847         // Therefore, we send both of them.
848         pDisassocHdr = (PHEADER_802_11)pOutBuffer;
849         pDisassocHdr->FC.SubType = SUBTYPE_DEAUTH;
850         MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
851
852         MlmeFreeMemory(pAd, pOutBuffer);
853
854         pAd->StaCfg.DisassocReason = REASON_DISASSOC_STA_LEAVING;
855         COPY_MAC_ADDR(pAd->StaCfg.DisassocSta, pDisassocReq->Addr);
856
857         RTMPSetTimer(&pAd->MlmeAux.DisassocTimer, Timeout); /* in mSec */
858         pAd->Mlme.AssocMachine.CurrState = DISASSOC_WAIT_RSP;
859
860     {
861         union iwreq_data    wrqu;
862         memset(wrqu.ap_addr.sa_data, 0, MAC_ADDR_LEN);
863         wireless_send_event(pAd->net_dev, SIOCGIWAP, &wrqu, NULL);
864     }
865 }
866
867 /*
868         ==========================================================================
869         Description:
870                 peer sends assoc rsp back
871         Parameters:
872                 Elme - MLME message containing the received frame
873
874         IRQL = DISPATCH_LEVEL
875
876         ==========================================================================
877  */
878 VOID PeerAssocRspAction(
879         IN PRTMP_ADAPTER pAd,
880         IN MLME_QUEUE_ELEM *Elem)
881 {
882         USHORT        CapabilityInfo, Status, Aid;
883         UCHAR         SupRate[MAX_LEN_OF_SUPPORTED_RATES], SupRateLen;
884         UCHAR         ExtRate[MAX_LEN_OF_SUPPORTED_RATES], ExtRateLen;
885         UCHAR         Addr2[MAC_ADDR_LEN];
886         BOOLEAN       TimerCancelled;
887         UCHAR         CkipFlag;
888         EDCA_PARM     EdcaParm;
889         HT_CAPABILITY_IE                HtCapability;
890         ADD_HT_INFO_IE          AddHtInfo;      // AP might use this additional ht info IE
891         UCHAR                   HtCapabilityLen;
892         UCHAR                   AddHtInfoLen;
893         UCHAR                   NewExtChannelOffset = 0xff;
894
895         if (PeerAssocRspSanity(pAd, Elem->Msg, Elem->MsgLen, Addr2, &CapabilityInfo, &Status, &Aid, SupRate, &SupRateLen, ExtRate, &ExtRateLen,
896                 &HtCapability,&AddHtInfo, &HtCapabilityLen,&AddHtInfoLen,&NewExtChannelOffset, &EdcaParm, &CkipFlag))
897         {
898                 // The frame is for me ?
899                 if(MAC_ADDR_EQUAL(Addr2, pAd->MlmeAux.Bssid))
900                 {
901                         DBGPRINT(RT_DEBUG_TRACE, ("PeerAssocRspAction():ASSOC - receive ASSOC_RSP to me (status=%d)\n", Status));
902                         DBGPRINT(RT_DEBUG_TRACE, ("PeerAssocRspAction():MacTable [%d].AMsduSize = %d. ClientStatusFlags = 0x%lx \n",Elem->Wcid, pAd->MacTab.Content[BSSID_WCID].AMsduSize, pAd->MacTab.Content[BSSID_WCID].ClientStatusFlags));
903                         RTMPCancelTimer(&pAd->MlmeAux.AssocTimer, &TimerCancelled);
904                         if(Status == MLME_SUCCESS)
905                         {
906 #ifdef RT2860
907                                 // go to procedure listed on page 376
908                                 AssocPostProc(pAd, Addr2, CapabilityInfo, Aid, SupRate, SupRateLen, ExtRate, ExtRateLen,
909                                         &EdcaParm, &HtCapability, HtCapabilityLen, &AddHtInfo);
910
911                 {
912                     union iwreq_data    wrqu;
913                     wext_notify_event_assoc(pAd);
914
915                     memset(wrqu.ap_addr.sa_data, 0, MAC_ADDR_LEN);
916                     memcpy(wrqu.ap_addr.sa_data, pAd->MlmeAux.Bssid, MAC_ADDR_LEN);
917                     wireless_send_event(pAd->net_dev, SIOCGIWAP, &wrqu, NULL);
918
919                 }
920 #endif
921 #ifdef RT2870
922                                 UCHAR                   MaxSupportedRateIn500Kbps = 0;
923                                 UCHAR                   idx;
924
925                                 // supported rates array may not be sorted. sort it and find the maximum rate
926                             for (idx=0; idx<SupRateLen; idx++)
927                 {
928                                 if (MaxSupportedRateIn500Kbps < (SupRate[idx] & 0x7f))
929                                     MaxSupportedRateIn500Kbps = SupRate[idx] & 0x7f;
930                             }
931
932                                 for (idx=0; idx<ExtRateLen; idx++)
933                             {
934                                 if (MaxSupportedRateIn500Kbps < (ExtRate[idx] & 0x7f))
935                                     MaxSupportedRateIn500Kbps = ExtRate[idx] & 0x7f;
936                 }
937                                 // go to procedure listed on page 376
938                                 AssocPostProc(pAd, Addr2, CapabilityInfo, Aid, SupRate, SupRateLen, ExtRate, ExtRateLen,
939                                         &EdcaParm, &HtCapability, HtCapabilityLen, &AddHtInfo);
940
941                                 StaAddMacTableEntry(pAd, &pAd->MacTab.Content[BSSID_WCID], MaxSupportedRateIn500Kbps, &HtCapability, HtCapabilityLen, CapabilityInfo);
942 #endif
943                                 pAd->StaCfg.CkipFlag = CkipFlag;
944                                 if (CkipFlag & 0x18)
945                                 {
946                                         NdisZeroMemory(pAd->StaCfg.TxSEQ, 4);
947                                         NdisZeroMemory(pAd->StaCfg.RxSEQ, 4);
948                                         NdisZeroMemory(pAd->StaCfg.CKIPMIC, 4);
949                                         pAd->StaCfg.GIV[0] = RandomByte(pAd);
950                                         pAd->StaCfg.GIV[1] = RandomByte(pAd);
951                                         pAd->StaCfg.GIV[2] = RandomByte(pAd);
952                                         pAd->StaCfg.bCkipOn = TRUE;
953                                         DBGPRINT(RT_DEBUG_TRACE, ("<CCX> pAd->StaCfg.CkipFlag = 0x%02x\n", pAd->StaCfg.CkipFlag));
954                                 }
955                         }
956                         else
957                         {
958                         }
959                         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
960                         MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
961                 }
962         }
963         else
964         {
965                 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerAssocRspAction() sanity check fail\n"));
966         }
967 }
968
969 /*
970         ==========================================================================
971         Description:
972                 peer sends reassoc rsp
973         Parametrs:
974                 Elem - MLME message cntaining the received frame
975
976         IRQL = DISPATCH_LEVEL
977
978         ==========================================================================
979  */
980 VOID PeerReassocRspAction(
981         IN PRTMP_ADAPTER pAd,
982         IN MLME_QUEUE_ELEM *Elem)
983 {
984         USHORT      CapabilityInfo;
985         USHORT      Status;
986         USHORT      Aid;
987         UCHAR       SupRate[MAX_LEN_OF_SUPPORTED_RATES], SupRateLen;
988         UCHAR       ExtRate[MAX_LEN_OF_SUPPORTED_RATES], ExtRateLen;
989         UCHAR       Addr2[MAC_ADDR_LEN];
990         UCHAR       CkipFlag;
991         BOOLEAN     TimerCancelled;
992         EDCA_PARM   EdcaParm;
993         HT_CAPABILITY_IE                HtCapability;
994         ADD_HT_INFO_IE          AddHtInfo;      // AP might use this additional ht info IE
995         UCHAR                   HtCapabilityLen;
996         UCHAR                   AddHtInfoLen;
997         UCHAR                   NewExtChannelOffset = 0xff;
998
999         if(PeerAssocRspSanity(pAd, Elem->Msg, Elem->MsgLen, Addr2, &CapabilityInfo, &Status, &Aid, SupRate, &SupRateLen, ExtRate, &ExtRateLen,
1000                                                                 &HtCapability,  &AddHtInfo, &HtCapabilityLen, &AddHtInfoLen,&NewExtChannelOffset, &EdcaParm, &CkipFlag))
1001         {
1002                 if(MAC_ADDR_EQUAL(Addr2, pAd->MlmeAux.Bssid)) // The frame is for me ?
1003                 {
1004                         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - receive REASSOC_RSP to me (status=%d)\n", Status));
1005                         RTMPCancelTimer(&pAd->MlmeAux.ReassocTimer, &TimerCancelled);
1006
1007                         if(Status == MLME_SUCCESS)
1008                         {
1009                                 // go to procedure listed on page 376
1010                                 AssocPostProc(pAd, Addr2, CapabilityInfo, Aid, SupRate, SupRateLen, ExtRate, ExtRateLen,
1011                                          &EdcaParm, &HtCapability, HtCapabilityLen, &AddHtInfo);
1012
1013                 {
1014                     union iwreq_data    wrqu;
1015                     wext_notify_event_assoc(pAd);
1016
1017                     memset(wrqu.ap_addr.sa_data, 0, MAC_ADDR_LEN);
1018                     memcpy(wrqu.ap_addr.sa_data, pAd->MlmeAux.Bssid, MAC_ADDR_LEN);
1019                     wireless_send_event(pAd->net_dev, SIOCGIWAP, &wrqu, NULL);
1020
1021                 }
1022
1023                         }
1024
1025                         {
1026                                 // CkipFlag is no use for reassociate
1027                                 pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1028                                 MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
1029                         }
1030                 }
1031         }
1032         else
1033         {
1034                 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerReassocRspAction() sanity check fail\n"));
1035         }
1036
1037 }
1038
1039 /*
1040         ==========================================================================
1041         Description:
1042                 procedures on IEEE 802.11/1999 p.376
1043         Parametrs:
1044
1045         IRQL = DISPATCH_LEVEL
1046
1047         ==========================================================================
1048  */
1049 VOID AssocPostProc(
1050         IN PRTMP_ADAPTER pAd,
1051         IN PUCHAR pAddr2,
1052         IN USHORT CapabilityInfo,
1053         IN USHORT Aid,
1054         IN UCHAR SupRate[],
1055         IN UCHAR SupRateLen,
1056         IN UCHAR ExtRate[],
1057         IN UCHAR ExtRateLen,
1058         IN PEDCA_PARM pEdcaParm,
1059         IN HT_CAPABILITY_IE             *pHtCapability,
1060         IN UCHAR HtCapabilityLen,
1061         IN ADD_HT_INFO_IE               *pAddHtInfo)    // AP might use this additional ht info IE
1062 {
1063         ULONG Idx;
1064
1065         pAd->MlmeAux.BssType = BSS_INFRA;
1066         COPY_MAC_ADDR(pAd->MlmeAux.Bssid, pAddr2);
1067         pAd->MlmeAux.Aid = Aid;
1068         pAd->MlmeAux.CapabilityInfo = CapabilityInfo & SUPPORTED_CAPABILITY_INFO;
1069
1070         // Some HT AP might lost WMM IE. We add WMM ourselves. beacuase HT requires QoS on.
1071         if ((HtCapabilityLen > 0) && (pEdcaParm->bValid == FALSE))
1072         {
1073                 pEdcaParm->bValid = TRUE;
1074                 pEdcaParm->Aifsn[0] = 3;
1075                 pEdcaParm->Aifsn[1] = 7;
1076                 pEdcaParm->Aifsn[2] = 2;
1077                 pEdcaParm->Aifsn[3] = 2;
1078
1079                 pEdcaParm->Cwmin[0] = 4;
1080                 pEdcaParm->Cwmin[1] = 4;
1081                 pEdcaParm->Cwmin[2] = 3;
1082                 pEdcaParm->Cwmin[3] = 2;
1083
1084                 pEdcaParm->Cwmax[0] = 10;
1085                 pEdcaParm->Cwmax[1] = 10;
1086                 pEdcaParm->Cwmax[2] = 4;
1087                 pEdcaParm->Cwmax[3] = 3;
1088
1089                 pEdcaParm->Txop[0]  = 0;
1090                 pEdcaParm->Txop[1]  = 0;
1091                 pEdcaParm->Txop[2]  = 96;
1092                 pEdcaParm->Txop[3]  = 48;
1093
1094         }
1095
1096         NdisMoveMemory(&pAd->MlmeAux.APEdcaParm, pEdcaParm, sizeof(EDCA_PARM));
1097
1098         // filter out un-supported rates
1099         pAd->MlmeAux.SupRateLen = SupRateLen;
1100         NdisMoveMemory(pAd->MlmeAux.SupRate, SupRate, SupRateLen);
1101         RTMPCheckRates(pAd, pAd->MlmeAux.SupRate, &pAd->MlmeAux.SupRateLen);
1102
1103         // filter out un-supported rates
1104         pAd->MlmeAux.ExtRateLen = ExtRateLen;
1105         NdisMoveMemory(pAd->MlmeAux.ExtRate, ExtRate, ExtRateLen);
1106         RTMPCheckRates(pAd, pAd->MlmeAux.ExtRate, &pAd->MlmeAux.ExtRateLen);
1107
1108         if (HtCapabilityLen > 0)
1109         {
1110                 RTMPCheckHt(pAd, BSSID_WCID, pHtCapability, pAddHtInfo);
1111         }
1112         DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===>  AP.AMsduSize = %d. ClientStatusFlags = 0x%lx \n", pAd->MacTab.Content[BSSID_WCID].AMsduSize, pAd->MacTab.Content[BSSID_WCID].ClientStatusFlags));
1113
1114         DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===>    (Mmps=%d, AmsduSize=%d, )\n",
1115                 pAd->MacTab.Content[BSSID_WCID].MmpsMode, pAd->MacTab.Content[BSSID_WCID].AMsduSize));
1116
1117         // Set New WPA information
1118         Idx = BssTableSearch(&pAd->ScanTab, pAddr2, pAd->MlmeAux.Channel);
1119         if (Idx == BSS_NOT_FOUND)
1120         {
1121                 DBGPRINT_ERR(("ASSOC - Can't find BSS after receiving Assoc response\n"));
1122         }
1123         else
1124         {
1125                 // Init variable
1126                 pAd->MacTab.Content[BSSID_WCID].RSNIE_Len = 0;
1127                 NdisZeroMemory(pAd->MacTab.Content[BSSID_WCID].RSN_IE, MAX_LEN_OF_RSNIE);
1128
1129                 // Store appropriate RSN_IE for WPA SM negotiation later
1130                 if ((pAd->StaCfg.AuthMode >= Ndis802_11AuthModeWPA) && (pAd->ScanTab.BssEntry[Idx].VarIELen != 0))
1131                 {
1132                         PUCHAR              pVIE;
1133                         USHORT              len;
1134                         PEID_STRUCT         pEid;
1135
1136                         pVIE = pAd->ScanTab.BssEntry[Idx].VarIEs;
1137                         len      = pAd->ScanTab.BssEntry[Idx].VarIELen;
1138
1139                         while (len > 0)
1140                         {
1141                                 pEid = (PEID_STRUCT) pVIE;
1142                                 // For WPA/WPAPSK
1143                                 if ((pEid->Eid == IE_WPA) && (NdisEqualMemory(pEid->Octet, WPA_OUI, 4))
1144                                         && (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA || pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPAPSK))
1145                                 {
1146                                         NdisMoveMemory(pAd->MacTab.Content[BSSID_WCID].RSN_IE, pVIE, (pEid->Len + 2));
1147                                         pAd->MacTab.Content[BSSID_WCID].RSNIE_Len = (pEid->Len + 2);
1148                                         DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===> Store RSN_IE for WPA SM negotiation \n"));
1149                                 }
1150                                 // For WPA2/WPA2PSK
1151                                 else if ((pEid->Eid == IE_RSN) && (NdisEqualMemory(pEid->Octet + 2, RSN_OUI, 3))
1152                                         && (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2 || pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPA2PSK))
1153                                 {
1154                                         NdisMoveMemory(pAd->MacTab.Content[BSSID_WCID].RSN_IE, pVIE, (pEid->Len + 2));
1155                                         pAd->MacTab.Content[BSSID_WCID].RSNIE_Len = (pEid->Len + 2);
1156                                         DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===> Store RSN_IE for WPA2 SM negotiation \n"));
1157                                 }
1158
1159                                 pVIE += (pEid->Len + 2);
1160                                 len  -= (pEid->Len + 2);
1161                         }
1162                 }
1163
1164                 if (pAd->MacTab.Content[BSSID_WCID].RSNIE_Len == 0)
1165                 {
1166                         DBGPRINT(RT_DEBUG_TRACE, ("AssocPostProc===> no RSN_IE \n"));
1167                 }
1168                 else
1169                 {
1170                         hex_dump("RSN_IE", pAd->MacTab.Content[BSSID_WCID].RSN_IE, pAd->MacTab.Content[BSSID_WCID].RSNIE_Len);
1171                 }
1172         }
1173 }
1174
1175 /*
1176         ==========================================================================
1177         Description:
1178                 left part of IEEE 802.11/1999 p.374
1179         Parameters:
1180                 Elem - MLME message containing the received frame
1181
1182         IRQL = DISPATCH_LEVEL
1183
1184         ==========================================================================
1185  */
1186 VOID PeerDisassocAction(
1187         IN PRTMP_ADAPTER pAd,
1188         IN MLME_QUEUE_ELEM *Elem)
1189 {
1190         UCHAR         Addr2[MAC_ADDR_LEN];
1191         USHORT        Reason;
1192
1193         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerDisassocAction()\n"));
1194         if(PeerDisassocSanity(pAd, Elem->Msg, Elem->MsgLen, Addr2, &Reason))
1195         {
1196                 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerDisassocAction() Reason = %d\n", Reason));
1197                 if (INFRA_ON(pAd) && MAC_ADDR_EQUAL(pAd->CommonCfg.Bssid, Addr2))
1198                 {
1199
1200                         if (pAd->CommonCfg.bWirelessEvent)
1201                         {
1202                                 RTMPSendWirelessEvent(pAd, IW_DISASSOC_EVENT_FLAG, pAd->MacTab.Content[BSSID_WCID].Addr, BSS0, 0);
1203                         }
1204
1205                         //
1206                         // Get Current System time and Turn on AdjacentAPReport
1207                         //
1208                         NdisGetSystemUpTime(&pAd->StaCfg.CCXAdjacentAPLinkDownTime);
1209                         pAd->StaCfg.CCXAdjacentAPReportFlag = TRUE;
1210                         LinkDown(pAd, TRUE);
1211                         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1212
1213             {
1214                 union iwreq_data    wrqu;
1215                 memset(wrqu.ap_addr.sa_data, 0, MAC_ADDR_LEN);
1216                 wireless_send_event(pAd->net_dev, SIOCGIWAP, &wrqu, NULL);
1217             }
1218                 }
1219         }
1220         else
1221         {
1222                 DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - PeerDisassocAction() sanity check fail\n"));
1223         }
1224
1225 }
1226
1227 /*
1228         ==========================================================================
1229         Description:
1230                 what the state machine will do after assoc timeout
1231         Parameters:
1232                 Elme -
1233
1234         IRQL = DISPATCH_LEVEL
1235
1236         ==========================================================================
1237  */
1238 VOID AssocTimeoutAction(
1239         IN PRTMP_ADAPTER pAd,
1240         IN MLME_QUEUE_ELEM *Elem)
1241 {
1242         USHORT  Status;
1243         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - AssocTimeoutAction\n"));
1244         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1245         Status = MLME_REJ_TIMEOUT;
1246         MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
1247 }
1248
1249 /*
1250         ==========================================================================
1251         Description:
1252                 what the state machine will do after reassoc timeout
1253
1254         IRQL = DISPATCH_LEVEL
1255
1256         ==========================================================================
1257  */
1258 VOID ReassocTimeoutAction(
1259         IN PRTMP_ADAPTER pAd,
1260         IN MLME_QUEUE_ELEM *Elem)
1261 {
1262         USHORT  Status;
1263         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - ReassocTimeoutAction\n"));
1264         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1265         Status = MLME_REJ_TIMEOUT;
1266         MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
1267 }
1268
1269 /*
1270         ==========================================================================
1271         Description:
1272                 what the state machine will do after disassoc timeout
1273
1274         IRQL = DISPATCH_LEVEL
1275
1276         ==========================================================================
1277  */
1278 VOID DisassocTimeoutAction(
1279         IN PRTMP_ADAPTER pAd,
1280         IN MLME_QUEUE_ELEM *Elem)
1281 {
1282         USHORT  Status;
1283         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - DisassocTimeoutAction\n"));
1284         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1285         Status = MLME_SUCCESS;
1286         MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_DISASSOC_CONF, 2, &Status);
1287 }
1288
1289 VOID InvalidStateWhenAssoc(
1290         IN PRTMP_ADAPTER pAd,
1291         IN MLME_QUEUE_ELEM *Elem)
1292 {
1293         USHORT  Status;
1294         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - InvalidStateWhenAssoc(state=%ld), reset ASSOC state machine\n",
1295                 pAd->Mlme.AssocMachine.CurrState));
1296         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1297         Status = MLME_STATE_MACHINE_REJECT;
1298         MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_ASSOC_CONF, 2, &Status);
1299 }
1300
1301 VOID InvalidStateWhenReassoc(
1302         IN PRTMP_ADAPTER pAd,
1303         IN MLME_QUEUE_ELEM *Elem)
1304 {
1305         USHORT Status;
1306         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - InvalidStateWhenReassoc(state=%ld), reset ASSOC state machine\n",
1307                 pAd->Mlme.AssocMachine.CurrState));
1308         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1309         Status = MLME_STATE_MACHINE_REJECT;
1310         MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_REASSOC_CONF, 2, &Status);
1311 }
1312
1313 VOID InvalidStateWhenDisassociate(
1314         IN PRTMP_ADAPTER pAd,
1315         IN MLME_QUEUE_ELEM *Elem)
1316 {
1317         USHORT Status;
1318         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - InvalidStateWhenDisassoc(state=%ld), reset ASSOC state machine\n",
1319                 pAd->Mlme.AssocMachine.CurrState));
1320         pAd->Mlme.AssocMachine.CurrState = ASSOC_IDLE;
1321         Status = MLME_STATE_MACHINE_REJECT;
1322         MlmeEnqueue(pAd, MLME_CNTL_STATE_MACHINE, MT2_DISASSOC_CONF, 2, &Status);
1323 }
1324
1325 /*
1326         ==========================================================================
1327         Description:
1328                 right part of IEEE 802.11/1999 page 374
1329         Note:
1330                 This event should never cause ASSOC state machine perform state
1331                 transition, and has no relationship with CNTL machine. So we separate
1332                 this routine as a service outside of ASSOC state transition table.
1333
1334         IRQL = DISPATCH_LEVEL
1335
1336         ==========================================================================
1337  */
1338 VOID Cls3errAction(
1339         IN PRTMP_ADAPTER pAd,
1340         IN PUCHAR        pAddr)
1341 {
1342         HEADER_802_11         DisassocHdr;
1343         PHEADER_802_11        pDisassocHdr;
1344         PUCHAR                pOutBuffer = NULL;
1345         ULONG                 FrameLen = 0;
1346         NDIS_STATUS           NStatus;
1347         USHORT                Reason = REASON_CLS3ERR;
1348
1349         NStatus = MlmeAllocateMemory(pAd, &pOutBuffer);  //Get an unused nonpaged memory
1350         if (NStatus != NDIS_STATUS_SUCCESS)
1351                 return;
1352
1353         DBGPRINT(RT_DEBUG_TRACE, ("ASSOC - Class 3 Error, Send DISASSOC frame\n"));
1354         MgtMacHeaderInit(pAd, &DisassocHdr, SUBTYPE_DISASSOC, 0, pAddr, pAd->CommonCfg.Bssid);  // patch peap ttls switching issue
1355         MakeOutgoingFrame(pOutBuffer,           &FrameLen,
1356                                           sizeof(HEADER_802_11),&DisassocHdr,
1357                                           2,                    &Reason,
1358                                           END_OF_ARGS);
1359         MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
1360
1361         // To patch Instance and Buffalo(N) AP
1362         // Driver has to send deauth to Instance AP, but Buffalo(N) needs to send disassoc to reset Authenticator's state machine
1363         // Therefore, we send both of them.
1364         pDisassocHdr = (PHEADER_802_11)pOutBuffer;
1365         pDisassocHdr->FC.SubType = SUBTYPE_DEAUTH;
1366         MiniportMMRequest(pAd, 0, pOutBuffer, FrameLen);
1367
1368         MlmeFreeMemory(pAd, pOutBuffer);
1369
1370         pAd->StaCfg.DisassocReason = REASON_CLS3ERR;
1371         COPY_MAC_ADDR(pAd->StaCfg.DisassocSta, pAddr);
1372 }
1373
1374  /*
1375          ==========================================================================
1376          Description:
1377                  Switch between WEP and CKIP upon new association up.
1378          Parameters:
1379
1380          IRQL = DISPATCH_LEVEL
1381
1382          ==========================================================================
1383   */
1384 VOID SwitchBetweenWepAndCkip(
1385         IN PRTMP_ADAPTER pAd)
1386 {
1387         int            i;
1388         SHAREDKEY_MODE_STRUC  csr1;
1389
1390         // if KP is required. change the CipherAlg in hardware shard key table from WEP
1391         // to CKIP. else remain as WEP
1392         if (pAd->StaCfg.bCkipOn && (pAd->StaCfg.CkipFlag & 0x10))
1393         {
1394                 // modify hardware key table so that MAC use correct algorithm to decrypt RX
1395                 RTMP_IO_READ32(pAd, SHARED_KEY_MODE_BASE, &csr1.word);
1396                 if (csr1.field.Bss0Key0CipherAlg == CIPHER_WEP64)
1397                         csr1.field.Bss0Key0CipherAlg = CIPHER_CKIP64;
1398                 else if (csr1.field.Bss0Key0CipherAlg == CIPHER_WEP128)
1399                         csr1.field.Bss0Key0CipherAlg = CIPHER_CKIP128;
1400
1401                 if (csr1.field.Bss0Key1CipherAlg == CIPHER_WEP64)
1402                         csr1.field.Bss0Key1CipherAlg = CIPHER_CKIP64;
1403                 else if (csr1.field.Bss0Key1CipherAlg == CIPHER_WEP128)
1404                         csr1.field.Bss0Key1CipherAlg = CIPHER_CKIP128;
1405
1406                 if (csr1.field.Bss0Key2CipherAlg == CIPHER_WEP64)
1407                         csr1.field.Bss0Key2CipherAlg = CIPHER_CKIP64;
1408                 else if (csr1.field.Bss0Key2CipherAlg == CIPHER_WEP128)
1409                         csr1.field.Bss0Key2CipherAlg = CIPHER_CKIP128;
1410
1411                 if (csr1.field.Bss0Key3CipherAlg == CIPHER_WEP64)
1412                         csr1.field.Bss0Key3CipherAlg = CIPHER_CKIP64;
1413                 else if (csr1.field.Bss0Key3CipherAlg == CIPHER_WEP128)
1414                         csr1.field.Bss0Key3CipherAlg = CIPHER_CKIP128;
1415                 RTMP_IO_WRITE32(pAd, SHARED_KEY_MODE_BASE, csr1.word);
1416                 DBGPRINT(RT_DEBUG_TRACE, ("SwitchBetweenWepAndCkip: modify BSS0 cipher to %s\n", CipherName[csr1.field.Bss0Key0CipherAlg]));
1417
1418                 // modify software key table so that driver can specify correct algorithm in TXD upon TX
1419                 for (i=0; i<SHARE_KEY_NUM; i++)
1420                 {
1421                         if (pAd->SharedKey[BSS0][i].CipherAlg == CIPHER_WEP64)
1422                                 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_CKIP64;
1423                         else if (pAd->SharedKey[BSS0][i].CipherAlg == CIPHER_WEP128)
1424                                 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_CKIP128;
1425                 }
1426         }
1427
1428         // else if KP NOT inused. change the CipherAlg in hardware shard key table from CKIP
1429         // to WEP.
1430         else
1431         {
1432                 // modify hardware key table so that MAC use correct algorithm to decrypt RX
1433                 RTMP_IO_READ32(pAd, SHARED_KEY_MODE_BASE, &csr1.word);
1434                 if (csr1.field.Bss0Key0CipherAlg == CIPHER_CKIP64)
1435                         csr1.field.Bss0Key0CipherAlg = CIPHER_WEP64;
1436                 else if (csr1.field.Bss0Key0CipherAlg == CIPHER_CKIP128)
1437                         csr1.field.Bss0Key0CipherAlg = CIPHER_WEP128;
1438
1439                 if (csr1.field.Bss0Key1CipherAlg == CIPHER_CKIP64)
1440                         csr1.field.Bss0Key1CipherAlg = CIPHER_WEP64;
1441                 else if (csr1.field.Bss0Key1CipherAlg == CIPHER_CKIP128)
1442                         csr1.field.Bss0Key1CipherAlg = CIPHER_WEP128;
1443
1444                 if (csr1.field.Bss0Key2CipherAlg == CIPHER_CKIP64)
1445                         csr1.field.Bss0Key2CipherAlg = CIPHER_WEP64;
1446                 else if (csr1.field.Bss0Key2CipherAlg == CIPHER_CKIP128)
1447                         csr1.field.Bss0Key2CipherAlg = CIPHER_WEP128;
1448
1449                 if (csr1.field.Bss0Key3CipherAlg == CIPHER_CKIP64)
1450                         csr1.field.Bss0Key3CipherAlg = CIPHER_WEP64;
1451                 else if (csr1.field.Bss0Key3CipherAlg == CIPHER_CKIP128)
1452                         csr1.field.Bss0Key3CipherAlg = CIPHER_WEP128;
1453
1454                 // modify software key table so that driver can specify correct algorithm in TXD upon TX
1455                 for (i=0; i<SHARE_KEY_NUM; i++)
1456                 {
1457                         if (pAd->SharedKey[BSS0][i].CipherAlg == CIPHER_CKIP64)
1458                                 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_WEP64;
1459                         else if (pAd->SharedKey[BSS0][i].CipherAlg == CIPHER_CKIP128)
1460                                 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_WEP128;
1461                 }
1462
1463                 //
1464                 // On WPA-NONE, must update CipherAlg.
1465                 // Because the OID_802_11_WEP_STATUS was been set after OID_802_11_ADD_KEY
1466                 // and CipherAlg will be CIPHER_NONE by Windows ZeroConfig.
1467                 // So we need to update CipherAlg after connect.
1468                 //
1469                 if (pAd->StaCfg.AuthMode == Ndis802_11AuthModeWPANone)
1470                 {
1471                         for (i = 0; i < SHARE_KEY_NUM; i++)
1472                         {
1473                                 if (pAd->SharedKey[BSS0][i].KeyLen != 0)
1474                                 {
1475                                         if (pAd->StaCfg.WepStatus == Ndis802_11Encryption2Enabled)
1476                                         {
1477                                                 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_TKIP;
1478                                         }
1479                                         else if (pAd->StaCfg.WepStatus == Ndis802_11Encryption3Enabled)
1480                                         {
1481                                                 pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_AES;
1482                                         }
1483                                 }
1484                                 else
1485                                 {
1486                                         pAd->SharedKey[BSS0][i].CipherAlg = CIPHER_NONE;
1487                                 }
1488                         }
1489
1490                         csr1.field.Bss0Key0CipherAlg = pAd->SharedKey[BSS0][0].CipherAlg;
1491                         csr1.field.Bss0Key1CipherAlg = pAd->SharedKey[BSS0][1].CipherAlg;
1492                         csr1.field.Bss0Key2CipherAlg = pAd->SharedKey[BSS0][2].CipherAlg;
1493                         csr1.field.Bss0Key3CipherAlg = pAd->SharedKey[BSS0][3].CipherAlg;
1494                 }
1495                 RTMP_IO_WRITE32(pAd, SHARED_KEY_MODE_BASE, csr1.word);
1496                 DBGPRINT(RT_DEBUG_TRACE, ("SwitchBetweenWepAndCkip: modify BSS0 cipher to %s\n", CipherName[csr1.field.Bss0Key0CipherAlg]));
1497         }
1498 }
1499
1500 int wext_notify_event_assoc(
1501         IN  RTMP_ADAPTER *pAd)
1502 {
1503     union iwreq_data    wrqu;
1504     char custom[IW_CUSTOM_MAX] = {0};
1505
1506 #if WIRELESS_EXT > 17
1507     if (pAd->StaCfg.ReqVarIELen <= IW_CUSTOM_MAX)
1508     {
1509         wrqu.data.length = pAd->StaCfg.ReqVarIELen;
1510         memcpy(custom, pAd->StaCfg.ReqVarIEs, pAd->StaCfg.ReqVarIELen);
1511         wireless_send_event(pAd->net_dev, IWEVASSOCREQIE, &wrqu, custom);
1512     }
1513     else
1514         DBGPRINT(RT_DEBUG_TRACE, ("pAd->StaCfg.ReqVarIELen > MAX_CUSTOM_LEN\n"));
1515 #else
1516     if (((pAd->StaCfg.ReqVarIELen*2) + 17) <= IW_CUSTOM_MAX)
1517     {
1518         UCHAR   idx;
1519         wrqu.data.length = (pAd->StaCfg.ReqVarIELen*2) + 17;
1520         sprintf(custom, "ASSOCINFO(ReqIEs=");
1521         for (idx=0; idx<pAd->StaCfg.ReqVarIELen; idx++)
1522                 sprintf(custom + strlen(custom), "%02x", pAd->StaCfg.ReqVarIEs[idx]);
1523         wireless_send_event(pAd->net_dev, IWEVCUSTOM, &wrqu, custom);
1524     }
1525     else
1526         DBGPRINT(RT_DEBUG_TRACE, ("(pAd->StaCfg.ReqVarIELen*2) + 17 > MAX_CUSTOM_LEN\n"));
1527 #endif
1528
1529         return 0;
1530
1531 }
1532
1533 #ifdef RT2870
1534 BOOLEAN StaAddMacTableEntry(
1535         IN  PRTMP_ADAPTER               pAd,
1536         IN  PMAC_TABLE_ENTRY    pEntry,
1537         IN  UCHAR                               MaxSupportedRateIn500Kbps,
1538         IN  HT_CAPABILITY_IE    *pHtCapability,
1539         IN  UCHAR                               HtCapabilityLen,
1540         IN  USHORT                      CapabilityInfo)
1541 {
1542         UCHAR            MaxSupportedRate = RATE_11;
1543
1544         if (ADHOC_ON(pAd))
1545                 CLIENT_STATUS_CLEAR_FLAG(pEntry, fCLIENT_STATUS_WMM_CAPABLE);
1546
1547         switch (MaxSupportedRateIn500Kbps)
1548     {
1549         case 108: MaxSupportedRate = RATE_54;   break;
1550         case 96:  MaxSupportedRate = RATE_48;   break;
1551         case 72:  MaxSupportedRate = RATE_36;   break;
1552         case 48:  MaxSupportedRate = RATE_24;   break;
1553         case 36:  MaxSupportedRate = RATE_18;   break;
1554         case 24:  MaxSupportedRate = RATE_12;   break;
1555         case 18:  MaxSupportedRate = RATE_9;    break;
1556         case 12:  MaxSupportedRate = RATE_6;    break;
1557         case 22:  MaxSupportedRate = RATE_11;   break;
1558         case 11:  MaxSupportedRate = RATE_5_5;  break;
1559         case 4:   MaxSupportedRate = RATE_2;    break;
1560         case 2:   MaxSupportedRate = RATE_1;    break;
1561         default:  MaxSupportedRate = RATE_11;   break;
1562     }
1563
1564     if ((pAd->CommonCfg.PhyMode == PHY_11G) && (MaxSupportedRate < RATE_FIRST_OFDM_RATE))
1565         return FALSE;
1566
1567         // 11n only
1568         if (((pAd->CommonCfg.PhyMode == PHY_11N_2_4G) || (pAd->CommonCfg.PhyMode == PHY_11N_5G))&& (HtCapabilityLen == 0))
1569                 return FALSE;
1570
1571         if (!pEntry)
1572         return FALSE;
1573
1574         NdisAcquireSpinLock(&pAd->MacTabLock);
1575         if (pEntry)
1576         {
1577                 pEntry->PortSecured = WPA_802_1X_PORT_SECURED;
1578                 if ((MaxSupportedRate < RATE_FIRST_OFDM_RATE) ||
1579                         (pAd->CommonCfg.PhyMode == PHY_11B))
1580                 {
1581                         pEntry->RateLen = 4;
1582                         if (MaxSupportedRate >= RATE_FIRST_OFDM_RATE)
1583                                 MaxSupportedRate = RATE_11;
1584                 }
1585                 else
1586                         pEntry->RateLen = 12;
1587
1588                 pEntry->MaxHTPhyMode.word = 0;
1589                 pEntry->MinHTPhyMode.word = 0;
1590                 pEntry->HTPhyMode.word = 0;
1591                 pEntry->MaxSupportedRate = MaxSupportedRate;
1592                 if (pEntry->MaxSupportedRate < RATE_FIRST_OFDM_RATE)
1593                 {
1594                         pEntry->MaxHTPhyMode.field.MODE = MODE_CCK;
1595                         pEntry->MaxHTPhyMode.field.MCS = pEntry->MaxSupportedRate;
1596                         pEntry->MinHTPhyMode.field.MODE = MODE_CCK;
1597                         pEntry->MinHTPhyMode.field.MCS = pEntry->MaxSupportedRate;
1598                         pEntry->HTPhyMode.field.MODE = MODE_CCK;
1599                         pEntry->HTPhyMode.field.MCS = pEntry->MaxSupportedRate;
1600                 }
1601                 else
1602                 {
1603                         pEntry->MaxHTPhyMode.field.MODE = MODE_OFDM;
1604                         pEntry->MaxHTPhyMode.field.MCS = OfdmRateToRxwiMCS[pEntry->MaxSupportedRate];
1605                         pEntry->MinHTPhyMode.field.MODE = MODE_OFDM;
1606                         pEntry->MinHTPhyMode.field.MCS = OfdmRateToRxwiMCS[pEntry->MaxSupportedRate];
1607                         pEntry->HTPhyMode.field.MODE = MODE_OFDM;
1608                         pEntry->HTPhyMode.field.MCS = OfdmRateToRxwiMCS[pEntry->MaxSupportedRate];
1609                 }
1610                 pEntry->CapabilityInfo = CapabilityInfo;
1611                 CLIENT_STATUS_CLEAR_FLAG(pEntry, fCLIENT_STATUS_AGGREGATION_CAPABLE);
1612                 CLIENT_STATUS_CLEAR_FLAG(pEntry, fCLIENT_STATUS_PIGGYBACK_CAPABLE);
1613         }
1614
1615         // If this Entry supports 802.11n, upgrade to HT rate.
1616         if ((HtCapabilityLen != 0) && (pAd->CommonCfg.PhyMode >= PHY_11ABGN_MIXED))
1617         {
1618                 UCHAR   j, bitmask; //k,bitmask;
1619                 CHAR    i;
1620
1621                 if (ADHOC_ON(pAd))
1622                         CLIENT_STATUS_SET_FLAG(pEntry, fCLIENT_STATUS_WMM_CAPABLE);
1623                 if ((pHtCapability->HtCapInfo.GF) && (pAd->CommonCfg.DesiredHtPhy.GF))
1624                 {
1625                         pEntry->MaxHTPhyMode.field.MODE = MODE_HTGREENFIELD;
1626                 }
1627                 else
1628                 {
1629                         pEntry->MaxHTPhyMode.field.MODE = MODE_HTMIX;
1630                         pAd->MacTab.fAnyStationNonGF = TRUE;
1631                         pAd->CommonCfg.AddHTInfo.AddHtInfo2.NonGfPresent = 1;
1632                 }
1633
1634                 if ((pHtCapability->HtCapInfo.ChannelWidth) && (pAd->CommonCfg.DesiredHtPhy.ChannelWidth))
1635                 {
1636                         pEntry->MaxHTPhyMode.field.BW= BW_40;
1637                         pEntry->MaxHTPhyMode.field.ShortGI = ((pAd->CommonCfg.DesiredHtPhy.ShortGIfor40)&(pHtCapability->HtCapInfo.ShortGIfor40));
1638                 }
1639                 else
1640                 {
1641                         pEntry->MaxHTPhyMode.field.BW = BW_20;
1642                         pEntry->MaxHTPhyMode.field.ShortGI = ((pAd->CommonCfg.DesiredHtPhy.ShortGIfor20)&(pHtCapability->HtCapInfo.ShortGIfor20));
1643                         pAd->MacTab.fAnyStation20Only = TRUE;
1644                 }
1645
1646                 // 3*3
1647                 if (pAd->MACVersion >= RALINK_2883_VERSION && pAd->MACVersion < RALINK_3070_VERSION)
1648                         pEntry->MaxHTPhyMode.field.TxBF = pAd->CommonCfg.RegTransmitSetting.field.TxBF;
1649
1650                 // find max fixed rate
1651                 for (i=23; i>=0; i--) // 3*3
1652                 {
1653                         j = i/8;
1654                         bitmask = (1<<(i-(j*8)));
1655                         if ((pAd->StaCfg.DesiredHtPhyInfo.MCSSet[j] & bitmask) && (pHtCapability->MCSSet[j] & bitmask))
1656                         {
1657                                 pEntry->MaxHTPhyMode.field.MCS = i;
1658                                 break;
1659                         }
1660                         if (i==0)
1661                                 break;
1662                 }
1663
1664
1665                 if (pAd->StaCfg.DesiredTransmitSetting.field.MCS != MCS_AUTO)
1666                 {
1667                         if (pAd->StaCfg.DesiredTransmitSetting.field.MCS == 32)
1668                         {
1669                                 // Fix MCS as HT Duplicated Mode
1670                                 pEntry->MaxHTPhyMode.field.BW = 1;
1671                                 pEntry->MaxHTPhyMode.field.MODE = MODE_HTMIX;
1672                                 pEntry->MaxHTPhyMode.field.STBC = 0;
1673                                 pEntry->MaxHTPhyMode.field.ShortGI = 0;
1674                                 pEntry->MaxHTPhyMode.field.MCS = 32;
1675                         }
1676                         else if (pEntry->MaxHTPhyMode.field.MCS > pAd->StaCfg.HTPhyMode.field.MCS)
1677                         {
1678                                 // STA supports fixed MCS
1679                                 pEntry->MaxHTPhyMode.field.MCS = pAd->StaCfg.HTPhyMode.field.MCS;
1680                         }
1681                 }
1682
1683                 pEntry->MaxHTPhyMode.field.STBC = (pHtCapability->HtCapInfo.RxSTBC & (pAd->CommonCfg.DesiredHtPhy.TxSTBC));
1684                 pEntry->MpduDensity = pHtCapability->HtCapParm.MpduDensity;
1685                 pEntry->MaxRAmpduFactor = pHtCapability->HtCapParm.MaxRAmpduFactor;
1686                 pEntry->MmpsMode = (UCHAR)pHtCapability->HtCapInfo.MimoPs;
1687                 pEntry->AMsduSize = (UCHAR)pHtCapability->HtCapInfo.AMsduSize;
1688                 pEntry->HTPhyMode.word = pEntry->MaxHTPhyMode.word;
1689
1690                 if (pAd->CommonCfg.DesiredHtPhy.AmsduEnable && (pAd->CommonCfg.REGBACapability.field.AutoBA == FALSE))
1691                         CLIENT_STATUS_SET_FLAG(pEntry, fCLIENT_STATUS_AMSDU_INUSED);
1692                 if (pHtCapability->HtCapInfo.ShortGIfor20)
1693                         CLIENT_STATUS_SET_FLAG(pEntry, fCLIENT_STATUS_SGI20_CAPABLE);
1694                 if (pHtCapability->HtCapInfo.ShortGIfor40)
1695                         CLIENT_STATUS_SET_FLAG(pEntry, fCLIENT_STATUS_SGI40_CAPABLE);
1696                 if (pHtCapability->HtCapInfo.TxSTBC)
1697                         CLIENT_STATUS_SET_FLAG(pEntry, fCLIENT_STATUS_TxSTBC_CAPABLE);
1698                 if (pHtCapability->HtCapInfo.RxSTBC)
1699                         CLIENT_STATUS_SET_FLAG(pEntry, fCLIENT_STATUS_RxSTBC_CAPABLE);
1700                 if (pHtCapability->ExtHtCapInfo.PlusHTC)
1701                         CLIENT_STATUS_SET_FLAG(pEntry, fCLIENT_STATUS_HTC_CAPABLE);
1702                 if (pAd->CommonCfg.bRdg && pHtCapability->ExtHtCapInfo.RDGSupport)
1703                         CLIENT_STATUS_SET_FLAG(pEntry, fCLIENT_STATUS_RDG_CAPABLE);
1704                 if (pHtCapability->ExtHtCapInfo.MCSFeedback == 0x03)
1705                         CLIENT_STATUS_SET_FLAG(pEntry, fCLIENT_STATUS_MCSFEEDBACK_CAPABLE);
1706         }
1707         else
1708         {
1709                 pAd->MacTab.fAnyStationIsLegacy = TRUE;
1710         }
1711
1712         NdisMoveMemory(&pEntry->HTCapability, pHtCapability, sizeof(HT_CAPABILITY_IE));
1713
1714         pEntry->HTPhyMode.word = pEntry->MaxHTPhyMode.word;
1715         pEntry->CurrTxRate = pEntry->MaxSupportedRate;
1716
1717         // Set asic auto fall back
1718         if (pAd->StaCfg.bAutoTxRateSwitch == TRUE)
1719         {
1720                 PUCHAR                                  pTable;
1721                 UCHAR                                   TableSize = 0;
1722
1723                 MlmeSelectTxRateTable(pAd, pEntry, &pTable, &TableSize, &pEntry->CurrTxRateIndex);
1724                 pEntry->bAutoTxRateSwitch = TRUE;
1725         }
1726         else
1727         {
1728                 pEntry->HTPhyMode.field.MODE    = pAd->StaCfg.HTPhyMode.field.MODE;
1729                 pEntry->HTPhyMode.field.MCS     = pAd->StaCfg.HTPhyMode.field.MCS;
1730                 pEntry->bAutoTxRateSwitch = FALSE;
1731
1732                 // If the legacy mode is set, overwrite the transmit setting of this entry.
1733                 RTMPUpdateLegacyTxSetting((UCHAR)pAd->StaCfg.DesiredTransmitSetting.field.FixedTxMode, pEntry);
1734         }
1735
1736         pEntry->PortSecured = WPA_802_1X_PORT_SECURED;
1737         pEntry->Sst = SST_ASSOC;
1738         pEntry->AuthState = AS_AUTH_OPEN;
1739         pEntry->AuthMode = pAd->StaCfg.AuthMode;
1740         pEntry->WepStatus = pAd->StaCfg.WepStatus;
1741
1742         NdisReleaseSpinLock(&pAd->MacTabLock);
1743
1744     {
1745         union iwreq_data    wrqu;
1746         wext_notify_event_assoc(pAd);
1747
1748         memset(wrqu.ap_addr.sa_data, 0, MAC_ADDR_LEN);
1749         memcpy(wrqu.ap_addr.sa_data, pAd->MlmeAux.Bssid, MAC_ADDR_LEN);
1750         wireless_send_event(pAd->net_dev, SIOCGIWAP, &wrqu, NULL);
1751
1752     }
1753         return TRUE;
1754 }
1755 #endif /* RT2870 */