1 // SPDX-License-Identifier: GPL-2.0
2 /******************************************************************************
3  *
4  * Copyright(c) 2007 - 2012 Realtek Corporation. All rights reserved.
5  *
6  ******************************************************************************/
7 #include <drv_types.h>
8 #include <rtw_debug.h>
9 #include <hal_btcoex.h>
10 #include <linux/jiffies.h>
11 
12 static struct _cmd_callback rtw_cmd_callback[] = {
13 	{GEN_CMD_CODE(_Read_MACREG), NULL}, /*0*/
14 	{GEN_CMD_CODE(_Write_MACREG), NULL},
15 	{GEN_CMD_CODE(_Read_BBREG), &rtw_getbbrfreg_cmdrsp_callback},
16 	{GEN_CMD_CODE(_Write_BBREG), NULL},
17 	{GEN_CMD_CODE(_Read_RFREG), &rtw_getbbrfreg_cmdrsp_callback},
18 	{GEN_CMD_CODE(_Write_RFREG), NULL}, /*5*/
19 	{GEN_CMD_CODE(_Read_EEPROM), NULL},
20 	{GEN_CMD_CODE(_Write_EEPROM), NULL},
21 	{GEN_CMD_CODE(_Read_EFUSE), NULL},
22 	{GEN_CMD_CODE(_Write_EFUSE), NULL},
23 
24 	{GEN_CMD_CODE(_Read_CAM),	NULL},	/*10*/
25 	{GEN_CMD_CODE(_Write_CAM),	 NULL},
26 	{GEN_CMD_CODE(_setBCNITV), NULL},
27 	{GEN_CMD_CODE(_setMBIDCFG), NULL},
28 	{GEN_CMD_CODE(_JoinBss), &rtw_joinbss_cmd_callback},  /*14*/
29 	{GEN_CMD_CODE(_DisConnect), &rtw_disassoc_cmd_callback}, /*15*/
30 	{GEN_CMD_CODE(_CreateBss), &rtw_createbss_cmd_callback},
31 	{GEN_CMD_CODE(_SetOpMode), NULL},
32 	{GEN_CMD_CODE(_SiteSurvey), &rtw_survey_cmd_callback}, /*18*/
33 	{GEN_CMD_CODE(_SetAuth), NULL},
34 
35 	{GEN_CMD_CODE(_SetKey), NULL},	/*20*/
36 	{GEN_CMD_CODE(_SetStaKey), &rtw_setstaKey_cmdrsp_callback},
37 	{GEN_CMD_CODE(_SetAssocSta), &rtw_setassocsta_cmdrsp_callback},
38 	{GEN_CMD_CODE(_DelAssocSta), NULL},
39 	{GEN_CMD_CODE(_SetStaPwrState), NULL},
40 	{GEN_CMD_CODE(_SetBasicRate), NULL}, /*25*/
41 	{GEN_CMD_CODE(_GetBasicRate), NULL},
42 	{GEN_CMD_CODE(_SetDataRate), NULL},
43 	{GEN_CMD_CODE(_GetDataRate), NULL},
44 	{GEN_CMD_CODE(_SetPhyInfo), NULL},
45 
46 	{GEN_CMD_CODE(_GetPhyInfo), NULL}, /*30*/
47 	{GEN_CMD_CODE(_SetPhy), NULL},
48 	{GEN_CMD_CODE(_GetPhy), NULL},
49 	{GEN_CMD_CODE(_readRssi), NULL},
50 	{GEN_CMD_CODE(_readGain), NULL},
51 	{GEN_CMD_CODE(_SetAtim), NULL}, /*35*/
52 	{GEN_CMD_CODE(_SetPwrMode), NULL},
53 	{GEN_CMD_CODE(_JoinbssRpt), NULL},
54 	{GEN_CMD_CODE(_SetRaTable), NULL},
55 	{GEN_CMD_CODE(_GetRaTable), NULL},
56 
57 	{GEN_CMD_CODE(_GetCCXReport), NULL}, /*40*/
58 	{GEN_CMD_CODE(_GetDTMReport),	NULL},
59 	{GEN_CMD_CODE(_GetTXRateStatistics), NULL},
60 	{GEN_CMD_CODE(_SetUsbSuspend), NULL},
61 	{GEN_CMD_CODE(_SetH2cLbk), NULL},
62 	{GEN_CMD_CODE(_AddBAReq), NULL}, /*45*/
63 	{GEN_CMD_CODE(_SetChannel), NULL},		/*46*/
64 	{GEN_CMD_CODE(_SetTxPower), NULL},
65 	{GEN_CMD_CODE(_SwitchAntenna), NULL},
66 	{GEN_CMD_CODE(_SetCrystalCap), NULL},
67 	{GEN_CMD_CODE(_SetSingleCarrierTx), NULL},	/*50*/
68 
69 	{GEN_CMD_CODE(_SetSingleToneTx), NULL}, /*51*/
70 	{GEN_CMD_CODE(_SetCarrierSuppressionTx), NULL},
71 	{GEN_CMD_CODE(_SetContinuousTx), NULL},
72 	{GEN_CMD_CODE(_SwitchBandwidth), NULL},		/*54*/
73 	{GEN_CMD_CODE(_TX_Beacon), NULL},/*55*/
74 
75 	{GEN_CMD_CODE(_Set_MLME_EVT), NULL},/*56*/
76 	{GEN_CMD_CODE(_Set_Drv_Extra), NULL},/*57*/
77 	{GEN_CMD_CODE(_Set_H2C_MSG), NULL},/*58*/
78 	{GEN_CMD_CODE(_SetChannelPlan), NULL},/*59*/
79 
80 	{GEN_CMD_CODE(_SetChannelSwitch), NULL},/*60*/
81 	{GEN_CMD_CODE(_TDLS), NULL},/*61*/
82 	{GEN_CMD_CODE(_ChkBMCSleepq), NULL}, /*62*/
83 
84 	{GEN_CMD_CODE(_RunInThreadCMD), NULL},/*63*/
85 };
86 
87 static struct cmd_hdl wlancmds[] = {
88 	GEN_DRV_CMD_HANDLER(0, NULL) /*0*/
89 	GEN_DRV_CMD_HANDLER(0, NULL)
90 	GEN_DRV_CMD_HANDLER(0, NULL)
91 	GEN_DRV_CMD_HANDLER(0, NULL)
92 	GEN_DRV_CMD_HANDLER(0, NULL)
93 	GEN_DRV_CMD_HANDLER(0, NULL)
94 	GEN_MLME_EXT_HANDLER(0, NULL)
95 	GEN_MLME_EXT_HANDLER(0, NULL)
96 	GEN_MLME_EXT_HANDLER(0, NULL)
97 	GEN_MLME_EXT_HANDLER(0, NULL)
98 	GEN_MLME_EXT_HANDLER(0, NULL) /*10*/
99 	GEN_MLME_EXT_HANDLER(0, NULL)
100 	GEN_MLME_EXT_HANDLER(0, NULL)
101 	GEN_MLME_EXT_HANDLER(0, NULL)
102 	GEN_MLME_EXT_HANDLER(sizeof(struct joinbss_parm), join_cmd_hdl) /*14*/
103 	GEN_MLME_EXT_HANDLER(sizeof(struct disconnect_parm), disconnect_hdl)
104 	GEN_MLME_EXT_HANDLER(sizeof(struct createbss_parm), createbss_hdl)
105 	GEN_MLME_EXT_HANDLER(sizeof(struct setopmode_parm), setopmode_hdl)
106 	GEN_MLME_EXT_HANDLER(sizeof(struct sitesurvey_parm), sitesurvey_cmd_hdl) /*18*/
107 	GEN_MLME_EXT_HANDLER(sizeof(struct setauth_parm), setauth_hdl)
108 	GEN_MLME_EXT_HANDLER(sizeof(struct setkey_parm), setkey_hdl) /*20*/
109 	GEN_MLME_EXT_HANDLER(sizeof(struct set_stakey_parm), set_stakey_hdl)
110 	GEN_MLME_EXT_HANDLER(sizeof(struct set_assocsta_parm), NULL)
111 	GEN_MLME_EXT_HANDLER(sizeof(struct del_assocsta_parm), NULL)
112 	GEN_MLME_EXT_HANDLER(sizeof(struct setstapwrstate_parm), NULL)
113 	GEN_MLME_EXT_HANDLER(sizeof(struct setbasicrate_parm), NULL)
114 	GEN_MLME_EXT_HANDLER(sizeof(struct getbasicrate_parm), NULL)
115 	GEN_MLME_EXT_HANDLER(sizeof(struct setdatarate_parm), NULL)
116 	GEN_MLME_EXT_HANDLER(sizeof(struct getdatarate_parm), NULL)
117 	GEN_MLME_EXT_HANDLER(sizeof(struct setphyinfo_parm), NULL)
118 	GEN_MLME_EXT_HANDLER(sizeof(struct getphyinfo_parm), NULL)  /*30*/
119 	GEN_MLME_EXT_HANDLER(sizeof(struct setphy_parm), NULL)
120 	GEN_MLME_EXT_HANDLER(sizeof(struct getphy_parm), NULL)
121 	GEN_MLME_EXT_HANDLER(0, NULL)
122 	GEN_MLME_EXT_HANDLER(0, NULL)
123 	GEN_MLME_EXT_HANDLER(0, NULL)
124 	GEN_MLME_EXT_HANDLER(0, NULL)
125 	GEN_MLME_EXT_HANDLER(0, NULL)
126 	GEN_MLME_EXT_HANDLER(0, NULL)
127 	GEN_MLME_EXT_HANDLER(0, NULL)
128 	GEN_MLME_EXT_HANDLER(0, NULL)	/*40*/
129 	GEN_MLME_EXT_HANDLER(0, NULL)
130 	GEN_MLME_EXT_HANDLER(0, NULL)
131 	GEN_MLME_EXT_HANDLER(0, NULL)
132 	GEN_MLME_EXT_HANDLER(0, NULL)
133 	GEN_MLME_EXT_HANDLER(sizeof(struct addBaReq_parm), add_ba_hdl)
134 	GEN_MLME_EXT_HANDLER(sizeof(struct set_ch_parm), set_ch_hdl) /* 46 */
135 	GEN_MLME_EXT_HANDLER(0, NULL)
136 	GEN_MLME_EXT_HANDLER(0, NULL)
137 	GEN_MLME_EXT_HANDLER(0, NULL)
138 	GEN_MLME_EXT_HANDLER(0, NULL) /*50*/
139 	GEN_MLME_EXT_HANDLER(0, NULL)
140 	GEN_MLME_EXT_HANDLER(0, NULL)
141 	GEN_MLME_EXT_HANDLER(0, NULL)
142 	GEN_MLME_EXT_HANDLER(0, NULL)
143 	GEN_MLME_EXT_HANDLER(sizeof(struct Tx_Beacon_param), tx_beacon_hdl) /*55*/
144 
145 	GEN_MLME_EXT_HANDLER(0, mlme_evt_hdl) /*56*/
146 	GEN_MLME_EXT_HANDLER(0, rtw_drvextra_cmd_hdl) /*57*/
147 
148 	GEN_MLME_EXT_HANDLER(0, h2c_msg_hdl) /*58*/
149 	GEN_MLME_EXT_HANDLER(sizeof(struct SetChannelPlan_param), set_chplan_hdl) /*59*/
150 
151 	GEN_MLME_EXT_HANDLER(sizeof(struct SetChannelSwitch_param), set_csa_hdl) /*60*/
152 	GEN_MLME_EXT_HANDLER(sizeof(struct TDLSoption_param), tdls_hdl) /*61*/
153 	GEN_MLME_EXT_HANDLER(0, chk_bmc_sleepq_hdl) /*62*/
154 	GEN_MLME_EXT_HANDLER(sizeof(struct RunInThread_param), run_in_thread_hdl) /*63*/
155 };
156 
157 /*
158  * Caller and the rtw_cmd_thread can protect cmd_q by spin_lock.
159  * No irqsave is necessary.
160  */
161 
162 int rtw_init_cmd_priv(struct	cmd_priv *pcmdpriv)
163 {
164 	int res = 0;
165 
166 	init_completion(&pcmdpriv->cmd_queue_comp);
167 	init_completion(&pcmdpriv->terminate_cmdthread_comp);
168 
169 	INIT_LIST_HEAD(&pcmdpriv->cmd_queue.queue);
170 	spin_lock_init(&pcmdpriv->cmd_queue.lock);
171 
172 	/* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
173 
174 	pcmdpriv->cmd_seq = 1;
175 
176 	pcmdpriv->cmd_allocated_buf = rtw_zmalloc(MAX_CMDSZ + CMDBUFF_ALIGN_SZ);
177 
178 	if (!pcmdpriv->cmd_allocated_buf) {
179 		res = -ENOMEM;
180 		goto exit;
181 	}
182 
183 	pcmdpriv->cmd_buf = pcmdpriv->cmd_allocated_buf  +  CMDBUFF_ALIGN_SZ - ((SIZE_PTR)(pcmdpriv->cmd_allocated_buf) & (CMDBUFF_ALIGN_SZ-1));
184 
185 	pcmdpriv->rsp_allocated_buf = rtw_zmalloc(MAX_RSPSZ + 4);
186 
187 	if (!pcmdpriv->rsp_allocated_buf) {
188 		res = -ENOMEM;
189 		goto exit;
190 	}
191 
192 	pcmdpriv->rsp_buf = pcmdpriv->rsp_allocated_buf  +  4 - ((SIZE_PTR)(pcmdpriv->rsp_allocated_buf) & 3);
193 
194 	pcmdpriv->cmd_issued_cnt = 0;
195 	pcmdpriv->cmd_done_cnt = 0;
196 	pcmdpriv->rsp_cnt = 0;
197 
198 	mutex_init(&pcmdpriv->sctx_mutex);
199 exit:
200 	return res;
201 }
202 
203 static void c2h_wk_callback(struct work_struct *work);
204 int rtw_init_evt_priv(struct evt_priv *pevtpriv)
205 {
206 	/* allocate DMA-able/Non-Page memory for cmd_buf and rsp_buf */
207 	atomic_set(&pevtpriv->event_seq, 0);
208 	pevtpriv->evt_done_cnt = 0;
209 
210 	_init_workitem(&pevtpriv->c2h_wk, c2h_wk_callback, NULL);
211 	pevtpriv->c2h_wk_alive = false;
212 	pevtpriv->c2h_queue = rtw_cbuf_alloc(C2H_QUEUE_MAX_LEN+1);
213 	if (!pevtpriv->c2h_queue)
214 		return -ENOMEM;
215 
216 	return 0;
217 }
218 
219 void _rtw_free_evt_priv(struct	evt_priv *pevtpriv)
220 {
221 	_cancel_workitem_sync(&pevtpriv->c2h_wk);
222 	while (pevtpriv->c2h_wk_alive)
223 		msleep(10);
224 
225 	while (!rtw_cbuf_empty(pevtpriv->c2h_queue)) {
226 		void *c2h = rtw_cbuf_pop(pevtpriv->c2h_queue);
227 
228 		if (c2h && c2h != (void *)pevtpriv)
229 			kfree(c2h);
230 	}
231 	kfree(pevtpriv->c2h_queue);
232 }
233 
234 void _rtw_free_cmd_priv(struct	cmd_priv *pcmdpriv)
235 {
236 	if (pcmdpriv) {
237 		kfree(pcmdpriv->cmd_allocated_buf);
238 
239 		kfree(pcmdpriv->rsp_allocated_buf);
240 
241 		mutex_destroy(&pcmdpriv->sctx_mutex);
242 	}
243 }
244 
245 /*
246  * Calling Context:
247  *
248  * rtw_enqueue_cmd can only be called between kernel thread,
249  * since only spin_lock is used.
250  *
251  * ISR/Call-Back functions can't call this sub-function.
252  *
253  */
254 
255 int _rtw_enqueue_cmd(struct __queue *queue, struct cmd_obj *obj)
256 {
257 	unsigned long irqL;
258 
259 	if (!obj)
260 		goto exit;
261 
262 	/* spin_lock_bh(&queue->lock); */
263 	spin_lock_irqsave(&queue->lock, irqL);
264 
265 	list_add_tail(&obj->list, &queue->queue);
266 
267 	/* spin_unlock_bh(&queue->lock); */
268 	spin_unlock_irqrestore(&queue->lock, irqL);
269 
270 exit:
271 	return _SUCCESS;
272 }
273 
274 struct	cmd_obj	*_rtw_dequeue_cmd(struct __queue *queue)
275 {
276 	unsigned long irqL;
277 	struct cmd_obj *obj;
278 
279 	/* spin_lock_bh(&(queue->lock)); */
280 	spin_lock_irqsave(&queue->lock, irqL);
281 	if (list_empty(&queue->queue))
282 		obj = NULL;
283 	else {
284 		obj = container_of(get_next(&queue->queue), struct cmd_obj, list);
285 		list_del_init(&obj->list);
286 	}
287 
288 	/* spin_unlock_bh(&(queue->lock)); */
289 	spin_unlock_irqrestore(&queue->lock, irqL);
290 
291 	return obj;
292 }
293 
294 void rtw_free_evt_priv(struct	evt_priv *pevtpriv)
295 {
296 	_rtw_free_evt_priv(pevtpriv);
297 }
298 
299 void rtw_free_cmd_priv(struct	cmd_priv *pcmdpriv)
300 {
301 	_rtw_free_cmd_priv(pcmdpriv);
302 }
303 
304 int rtw_cmd_filter(struct cmd_priv *pcmdpriv, struct cmd_obj *cmd_obj);
305 int rtw_cmd_filter(struct cmd_priv *pcmdpriv, struct cmd_obj *cmd_obj)
306 {
307 	u8 bAllow = false; /* set to true to allow enqueuing cmd when hw_init_completed is false */
308 
309 	if (cmd_obj->cmdcode == GEN_CMD_CODE(_SetChannelPlan))
310 		bAllow = true;
311 
312 	if ((!pcmdpriv->padapter->hw_init_completed && !bAllow) ||
313 		!atomic_read(&pcmdpriv->cmdthd_running))	/* com_thread not running */
314 		return _FAIL;
315 
316 	return _SUCCESS;
317 }
318 
319 int rtw_enqueue_cmd(struct cmd_priv *pcmdpriv, struct cmd_obj *cmd_obj)
320 {
321 	int res = _FAIL;
322 	struct adapter *padapter = pcmdpriv->padapter;
323 
324 	if (!cmd_obj)
325 		goto exit;
326 
327 	cmd_obj->padapter = padapter;
328 
329 	res = rtw_cmd_filter(pcmdpriv, cmd_obj);
330 	if (res == _FAIL) {
331 		rtw_free_cmd_obj(cmd_obj);
332 		goto exit;
333 	}
334 
335 	res = _rtw_enqueue_cmd(&pcmdpriv->cmd_queue, cmd_obj);
336 
337 	if (res == _SUCCESS)
338 		complete(&pcmdpriv->cmd_queue_comp);
339 
340 exit:
341 	return res;
342 }
343 
344 struct	cmd_obj	*rtw_dequeue_cmd(struct cmd_priv *pcmdpriv)
345 {
346 	return _rtw_dequeue_cmd(&pcmdpriv->cmd_queue);
347 }
348 
349 void rtw_free_cmd_obj(struct cmd_obj *pcmd)
350 {
351 	if ((pcmd->cmdcode != _JoinBss_CMD_) &&
352 	    (pcmd->cmdcode != _CreateBss_CMD_)) {
353 		/* free parmbuf in cmd_obj */
354 		kfree(pcmd->parmbuf);
355 	}
356 
357 	if (pcmd->rsp) {
358 		if (pcmd->rspsz != 0) {
359 			/* free rsp in cmd_obj */
360 			kfree(pcmd->rsp);
361 		}
362 	}
363 
364 	/* free cmd_obj */
365 	kfree(pcmd);
366 }
367 
368 void rtw_stop_cmd_thread(struct adapter *adapter)
369 {
370 	if (adapter->cmdThread &&
371 		atomic_read(&adapter->cmdpriv.cmdthd_running) &&
372 		adapter->cmdpriv.stop_req == 0) {
373 		adapter->cmdpriv.stop_req = 1;
374 		complete(&adapter->cmdpriv.cmd_queue_comp);
375 		wait_for_completion(&adapter->cmdpriv.terminate_cmdthread_comp);
376 	}
377 }
378 
379 int rtw_cmd_thread(void *context)
380 {
381 	u8 ret;
382 	struct cmd_obj *pcmd;
383 	u8 *pcmdbuf;
384 	u8 (*cmd_hdl)(struct adapter *padapter, u8 *pbuf);
385 	void (*pcmd_callback)(struct adapter *dev, struct cmd_obj *pcmd);
386 	struct adapter *padapter = context;
387 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
388 	struct drvextra_cmd_parm *extra_parm = NULL;
389 
390 	thread_enter("RTW_CMD_THREAD");
391 
392 	pcmdbuf = pcmdpriv->cmd_buf;
393 
394 	pcmdpriv->stop_req = 0;
395 	atomic_set(&pcmdpriv->cmdthd_running, true);
396 	complete(&pcmdpriv->terminate_cmdthread_comp);
397 
398 	while (1) {
399 		if (wait_for_completion_interruptible(&pcmdpriv->cmd_queue_comp)) {
400 			netdev_dbg(padapter->pnetdev,
401 				   FUNC_ADPT_FMT " wait_for_completion_interruptible(&pcmdpriv->cmd_queue_comp) return != 0, break\n",
402 				   FUNC_ADPT_ARG(padapter));
403 			break;
404 		}
405 
406 		if (padapter->bDriverStopped || padapter->bSurpriseRemoved) {
407 			netdev_dbg(padapter->pnetdev,
408 				   "%s: DriverStopped(%d) SurpriseRemoved(%d) break at line %d\n",
409 				   __func__, padapter->bDriverStopped,
410 				   padapter->bSurpriseRemoved, __LINE__);
411 			break;
412 		}
413 
414 		if (pcmdpriv->stop_req) {
415 			netdev_dbg(padapter->pnetdev,
416 				   FUNC_ADPT_FMT " stop_req:%u, break\n",
417 				   FUNC_ADPT_ARG(padapter),
418 				   pcmdpriv->stop_req);
419 			break;
420 		}
421 
422 		if (list_empty(&pcmdpriv->cmd_queue.queue))
423 			continue;
424 
425 		if (rtw_register_cmd_alive(padapter) != _SUCCESS)
426 			continue;
427 
428 _next:
429 		if (padapter->bDriverStopped || padapter->bSurpriseRemoved) {
430 			netdev_dbg(padapter->pnetdev,
431 				   "%s: DriverStopped(%d) SurpriseRemoved(%d) break at line %d\n",
432 				   __func__, padapter->bDriverStopped,
433 				   padapter->bSurpriseRemoved, __LINE__);
434 			break;
435 		}
436 
437 		pcmd = rtw_dequeue_cmd(pcmdpriv);
438 		if (!pcmd) {
439 			rtw_unregister_cmd_alive(padapter);
440 			continue;
441 		}
442 
443 		if (rtw_cmd_filter(pcmdpriv, pcmd) == _FAIL) {
444 			pcmd->res = H2C_DROPPED;
445 			goto post_process;
446 		}
447 
448 		pcmdpriv->cmd_issued_cnt++;
449 
450 		pcmd->cmdsz = round_up((pcmd->cmdsz), 4);
451 
452 		memcpy(pcmdbuf, pcmd->parmbuf, pcmd->cmdsz);
453 
454 		if (pcmd->cmdcode < ARRAY_SIZE(wlancmds)) {
455 			cmd_hdl = wlancmds[pcmd->cmdcode].h2cfuns;
456 
457 			if (cmd_hdl) {
458 				ret = cmd_hdl(pcmd->padapter, pcmdbuf);
459 				pcmd->res = ret;
460 			}
461 
462 			pcmdpriv->cmd_seq++;
463 		} else {
464 			pcmd->res = H2C_PARAMETERS_ERROR;
465 		}
466 
467 		cmd_hdl = NULL;
468 
469 post_process:
470 
471 		if (mutex_lock_interruptible(&pcmd->padapter->cmdpriv.sctx_mutex) == 0) {
472 			if (pcmd->sctx) {
473 				netdev_dbg(padapter->pnetdev,
474 					   FUNC_ADPT_FMT " pcmd->sctx\n",
475 					   FUNC_ADPT_ARG(pcmd->padapter));
476 
477 				if (pcmd->res == H2C_SUCCESS)
478 					rtw_sctx_done(&pcmd->sctx);
479 				else
480 					rtw_sctx_done_err(&pcmd->sctx, RTW_SCTX_DONE_CMD_ERROR);
481 			}
482 			mutex_unlock(&pcmd->padapter->cmdpriv.sctx_mutex);
483 		}
484 
485 		/* call callback function for post-processed */
486 		if (pcmd->cmdcode < ARRAY_SIZE(rtw_cmd_callback)) {
487 			pcmd_callback = rtw_cmd_callback[pcmd->cmdcode].callback;
488 			if (!pcmd_callback) {
489 				rtw_free_cmd_obj(pcmd);
490 			} else {
491 				/* todo: !!! fill rsp_buf to pcmd->rsp if (pcmd->rsp!= NULL) */
492 				pcmd_callback(pcmd->padapter, pcmd);/* need consider that free cmd_obj in rtw_cmd_callback */
493 			}
494 		} else {
495 			rtw_free_cmd_obj(pcmd);
496 		}
497 		flush_signals_thread();
498 		goto _next;
499 	}
500 
501 	/*  free all cmd_obj resources */
502 	do {
503 		pcmd = rtw_dequeue_cmd(pcmdpriv);
504 		if (!pcmd) {
505 			rtw_unregister_cmd_alive(padapter);
506 			break;
507 		}
508 
509 		if (pcmd->cmdcode == GEN_CMD_CODE(_Set_Drv_Extra)) {
510 			extra_parm = (struct drvextra_cmd_parm *)pcmd->parmbuf;
511 			if (extra_parm->pbuf && extra_parm->size > 0)
512 				kfree(extra_parm->pbuf);
513 		}
514 
515 		rtw_free_cmd_obj(pcmd);
516 	} while (1);
517 
518 	complete(&pcmdpriv->terminate_cmdthread_comp);
519 	atomic_set(&pcmdpriv->cmdthd_running, false);
520 
521 	thread_exit();
522 }
523 
524 /*
525  * rtw_sitesurvey_cmd(~)
526  *	### NOTE:#### (!!!!)
527  *	MUST TAKE CARE THAT BEFORE CALLING THIS FUNC, YOU SHOULD HAVE LOCKED pmlmepriv->lock
528  */
529 
530 u8 rtw_sitesurvey_cmd(struct adapter  *padapter, struct ndis_802_11_ssid *ssid, int ssid_num,
531 	struct rtw_ieee80211_channel *ch, int ch_num)
532 {
533 	u8 res = _FAIL;
534 	struct cmd_obj		*ph2c;
535 	struct sitesurvey_parm	*psurveyPara;
536 	struct cmd_priv 	*pcmdpriv = &padapter->cmdpriv;
537 	struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
538 
539 	if (check_fwstate(pmlmepriv, _FW_LINKED))
540 		rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_SCAN, 1);
541 
542 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
543 	if (!ph2c)
544 		return _FAIL;
545 
546 	psurveyPara = rtw_zmalloc(sizeof(struct sitesurvey_parm));
547 	if (!psurveyPara) {
548 		kfree(ph2c);
549 		return _FAIL;
550 	}
551 
552 	rtw_free_network_queue(padapter, false);
553 
554 	init_h2fwcmd_w_parm_no_rsp(ph2c, psurveyPara, GEN_CMD_CODE(_SiteSurvey));
555 
556 	/* psurveyPara->bsslimit = 48; */
557 	psurveyPara->scan_mode = pmlmepriv->scan_mode;
558 
559 	/* prepare ssid list */
560 	if (ssid) {
561 		int i;
562 
563 		for (i = 0; i < ssid_num && i < RTW_SSID_SCAN_AMOUNT; i++) {
564 			if (ssid[i].ssid_length) {
565 				memcpy(&psurveyPara->ssid[i], &ssid[i], sizeof(struct ndis_802_11_ssid));
566 				psurveyPara->ssid_num++;
567 			}
568 		}
569 	}
570 
571 	/* prepare channel list */
572 	if (ch) {
573 		int i;
574 
575 		for (i = 0; i < ch_num && i < RTW_CHANNEL_SCAN_AMOUNT; i++) {
576 			if (ch[i].hw_value && !(ch[i].flags & RTW_IEEE80211_CHAN_DISABLED)) {
577 				memcpy(&psurveyPara->ch[i], &ch[i], sizeof(struct rtw_ieee80211_channel));
578 				psurveyPara->ch_num++;
579 			}
580 		}
581 	}
582 
583 	set_fwstate(pmlmepriv, _FW_UNDER_SURVEY);
584 
585 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
586 
587 	if (res == _SUCCESS) {
588 		pmlmepriv->scan_start_time = jiffies;
589 		_set_timer(&pmlmepriv->scan_to_timer, SCANNING_TIMEOUT);
590 	} else {
591 		_clr_fwstate_(pmlmepriv, _FW_UNDER_SURVEY);
592 	}
593 	return res;
594 }
595 
596 u8 rtw_setdatarate_cmd(struct adapter *padapter, u8 *rateset)
597 {
598 	struct cmd_obj *ph2c;
599 	struct setdatarate_parm *pbsetdataratepara;
600 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
601 	u8 res = _SUCCESS;
602 
603 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
604 	if (!ph2c) {
605 		res = _FAIL;
606 		goto exit;
607 	}
608 
609 	pbsetdataratepara = rtw_zmalloc(sizeof(struct setdatarate_parm));
610 	if (!pbsetdataratepara) {
611 		kfree(ph2c);
612 		res = _FAIL;
613 		goto exit;
614 	}
615 
616 	init_h2fwcmd_w_parm_no_rsp(ph2c, pbsetdataratepara, GEN_CMD_CODE(_SetDataRate));
617 	pbsetdataratepara->mac_id = 5;
618 	memcpy(pbsetdataratepara->datarates, rateset, NumRates);
619 
620 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
621 exit:
622 	return res;
623 }
624 
625 void rtw_getbbrfreg_cmdrsp_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
626 {
627 	/* rtw_free_cmd_obj(pcmd); */
628 	kfree(pcmd->parmbuf);
629 	kfree(pcmd);
630 }
631 
632 u8 rtw_createbss_cmd(struct adapter  *padapter)
633 {
634 	struct cmd_obj *pcmd;
635 	struct cmd_priv 			*pcmdpriv = &padapter->cmdpriv;
636 	struct wlan_bssid_ex		*pdev_network = &padapter->registrypriv.dev_network;
637 	u8 res = _SUCCESS;
638 
639 	pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
640 	if (!pcmd) {
641 		res = _FAIL;
642 		goto exit;
643 	}
644 
645 	INIT_LIST_HEAD(&pcmd->list);
646 	pcmd->cmdcode = _CreateBss_CMD_;
647 	pcmd->parmbuf = (unsigned char *)pdev_network;
648 	pcmd->cmdsz = get_wlan_bssid_ex_sz((struct wlan_bssid_ex *)pdev_network);
649 	pcmd->rsp = NULL;
650 	pcmd->rspsz = 0;
651 
652 	pdev_network->length = pcmd->cmdsz;
653 
654 	res = rtw_enqueue_cmd(pcmdpriv, pcmd);
655 
656 exit:
657 	return res;
658 }
659 
660 int rtw_startbss_cmd(struct adapter  *padapter, int flags)
661 {
662 	struct cmd_obj *pcmd;
663 	struct cmd_priv  *pcmdpriv = &padapter->cmdpriv;
664 	struct submit_ctx sctx;
665 	int res = _SUCCESS;
666 
667 	if (flags & RTW_CMDF_DIRECTLY) {
668 		/* no need to enqueue, do the cmd hdl directly and free cmd parameter */
669 		start_bss_network(padapter);
670 	} else {
671 		/* need enqueue, prepare cmd_obj and enqueue */
672 		pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
673 		if (!pcmd) {
674 			res = _FAIL;
675 			goto exit;
676 		}
677 
678 		INIT_LIST_HEAD(&pcmd->list);
679 		pcmd->cmdcode = GEN_CMD_CODE(_CreateBss);
680 		pcmd->parmbuf = NULL;
681 		pcmd->cmdsz =  0;
682 		pcmd->rsp = NULL;
683 		pcmd->rspsz = 0;
684 
685 		if (flags & RTW_CMDF_WAIT_ACK) {
686 			pcmd->sctx = &sctx;
687 			rtw_sctx_init(&sctx, 2000);
688 		}
689 
690 		res = rtw_enqueue_cmd(pcmdpriv, pcmd);
691 
692 		if (res == _SUCCESS && (flags & RTW_CMDF_WAIT_ACK)) {
693 			rtw_sctx_wait(&sctx);
694 			if (mutex_lock_interruptible(&pcmdpriv->sctx_mutex) == 0) {
695 				if (sctx.status == RTW_SCTX_SUBMITTED)
696 					pcmd->sctx = NULL;
697 				mutex_unlock(&pcmdpriv->sctx_mutex);
698 			}
699 		}
700 	}
701 
702 exit:
703 	return res;
704 }
705 
706 u8 rtw_joinbss_cmd(struct adapter  *padapter, struct wlan_network *pnetwork)
707 {
708 	u8 res = _SUCCESS;
709 	uint	t_len = 0;
710 	struct wlan_bssid_ex		*psecnetwork;
711 	struct cmd_obj		*pcmd;
712 	struct cmd_priv 	*pcmdpriv = &padapter->cmdpriv;
713 	struct mlme_priv 	*pmlmepriv = &padapter->mlmepriv;
714 	struct qos_priv 	*pqospriv = &pmlmepriv->qospriv;
715 	struct security_priv *psecuritypriv = &padapter->securitypriv;
716 	struct registry_priv *pregistrypriv = &padapter->registrypriv;
717 	struct ht_priv 		*phtpriv = &pmlmepriv->htpriv;
718 	enum ndis_802_11_network_infrastructure ndis_network_mode = pnetwork->network.infrastructure_mode;
719 	struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
720 	struct mlme_ext_info *pmlmeinfo = &pmlmeext->mlmext_info;
721 	u32 tmp_len;
722 	u8 *ptmp = NULL;
723 
724 	pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
725 	if (!pcmd) {
726 		res = _FAIL;
727 		goto exit;
728 	}
729 	/* for ies is fix buf size */
730 	t_len = sizeof(struct wlan_bssid_ex);
731 
732 
733 	/* for hidden ap to set fw_state here */
734 	if (check_fwstate(pmlmepriv, WIFI_STATION_STATE|WIFI_ADHOC_STATE) != true) {
735 		switch (ndis_network_mode) {
736 		case Ndis802_11IBSS:
737 			set_fwstate(pmlmepriv, WIFI_ADHOC_STATE);
738 			break;
739 
740 		case Ndis802_11Infrastructure:
741 			set_fwstate(pmlmepriv, WIFI_STATION_STATE);
742 			break;
743 
744 		case Ndis802_11APMode:
745 		case Ndis802_11AutoUnknown:
746 		case Ndis802_11InfrastructureMax:
747 			break;
748 		}
749 	}
750 
751 	psecnetwork = (struct wlan_bssid_ex *)&psecuritypriv->sec_bss;
752 
753 	memset(psecnetwork, 0, t_len);
754 
755 	memcpy(psecnetwork, &pnetwork->network, get_wlan_bssid_ex_sz(&pnetwork->network));
756 
757 	psecuritypriv->authenticator_ie[0] = (unsigned char)psecnetwork->ie_length;
758 
759 	if ((psecnetwork->ie_length-12) < (256-1))
760 		memcpy(&psecuritypriv->authenticator_ie[1], &psecnetwork->ies[12], psecnetwork->ie_length-12);
761 	else
762 		memcpy(&psecuritypriv->authenticator_ie[1], &psecnetwork->ies[12], (256-1));
763 
764 	psecnetwork->ie_length = 0;
765 	/*  Added by Albert 2009/02/18 */
766 	/*  If the driver wants to use the bssid to create the connection. */
767 	/*  If not,  we have to copy the connecting AP's MAC address to it so that */
768 	/*  the driver just has the bssid information for PMKIDList searching. */
769 
770 	if (!pmlmepriv->assoc_by_bssid)
771 		memcpy(&pmlmepriv->assoc_bssid[0], &pnetwork->network.mac_address[0], ETH_ALEN);
772 
773 	psecnetwork->ie_length = rtw_restruct_sec_ie(padapter, &pnetwork->network.ies[0], &psecnetwork->ies[0], pnetwork->network.ie_length);
774 
775 
776 	pqospriv->qos_option = 0;
777 
778 	if (pregistrypriv->wmm_enable) {
779 		tmp_len = rtw_restruct_wmm_ie(padapter, &pnetwork->network.ies[0], &psecnetwork->ies[0], pnetwork->network.ie_length, psecnetwork->ie_length);
780 
781 		if (psecnetwork->ie_length != tmp_len) {
782 			psecnetwork->ie_length = tmp_len;
783 			pqospriv->qos_option = 1; /* There is WMM IE in this corresp. beacon */
784 		} else {
785 			pqospriv->qos_option = 0;/* There is no WMM IE in this corresp. beacon */
786 		}
787 	}
788 
789 	phtpriv->ht_option = false;
790 	ptmp = rtw_get_ie(&pnetwork->network.ies[12], WLAN_EID_HT_CAPABILITY, &tmp_len, pnetwork->network.ie_length-12);
791 	if (pregistrypriv->ht_enable && ptmp && tmp_len > 0) {
792 		/* 	Added by Albert 2010/06/23 */
793 		/* 	For the WEP mode, we will use the bg mode to do the connection to avoid some IOT issue. */
794 		/* 	Especially for Realtek 8192u SoftAP. */
795 		if ((padapter->securitypriv.dot11PrivacyAlgrthm != _WEP40_) &&
796 			(padapter->securitypriv.dot11PrivacyAlgrthm != _WEP104_) &&
797 			(padapter->securitypriv.dot11PrivacyAlgrthm != _TKIP_)) {
798 			rtw_ht_use_default_setting(padapter);
799 
800 			rtw_build_wmm_ie_ht(padapter, &psecnetwork->ies[12], &psecnetwork->ie_length);
801 
802 			/* rtw_restructure_ht_ie */
803 			rtw_restructure_ht_ie(padapter, &pnetwork->network.ies[12], &psecnetwork->ies[0],
804 									pnetwork->network.ie_length-12, &psecnetwork->ie_length,
805 									pnetwork->network.configuration.ds_config);
806 		}
807 	}
808 
809 	rtw_append_exented_cap(padapter, &psecnetwork->ies[0], &psecnetwork->ie_length);
810 
811 	pmlmeinfo->assoc_AP_vendor = check_assoc_AP(pnetwork->network.ies, pnetwork->network.ie_length);
812 
813 	pcmd->cmdsz = get_wlan_bssid_ex_sz(psecnetwork);/* get cmdsz before endian conversion */
814 
815 	INIT_LIST_HEAD(&pcmd->list);
816 	pcmd->cmdcode = _JoinBss_CMD_;/* GEN_CMD_CODE(_JoinBss) */
817 	pcmd->parmbuf = (unsigned char *)psecnetwork;
818 	pcmd->rsp = NULL;
819 	pcmd->rspsz = 0;
820 
821 	res = rtw_enqueue_cmd(pcmdpriv, pcmd);
822 
823 exit:
824 	return res;
825 }
826 
827 u8 rtw_disassoc_cmd(struct adapter *padapter, u32 deauth_timeout_ms, bool enqueue) /* for sta_mode */
828 {
829 	struct cmd_obj *cmdobj = NULL;
830 	struct disconnect_parm *param = NULL;
831 	struct cmd_priv *cmdpriv = &padapter->cmdpriv;
832 	u8 res = _SUCCESS;
833 
834 	/* prepare cmd parameter */
835 	param = rtw_zmalloc(sizeof(*param));
836 	if (!param) {
837 		res = _FAIL;
838 		goto exit;
839 	}
840 	param->deauth_timeout_ms = deauth_timeout_ms;
841 
842 	if (enqueue) {
843 		/* need enqueue, prepare cmd_obj and enqueue */
844 		cmdobj = rtw_zmalloc(sizeof(*cmdobj));
845 		if (!cmdobj) {
846 			res = _FAIL;
847 			kfree(param);
848 			goto exit;
849 		}
850 		init_h2fwcmd_w_parm_no_rsp(cmdobj, param, _DisConnect_CMD_);
851 		res = rtw_enqueue_cmd(cmdpriv, cmdobj);
852 	} else {
853 		/* no need to enqueue, do the cmd hdl directly and free cmd parameter */
854 		if (disconnect_hdl(padapter, (u8 *)param) != H2C_SUCCESS)
855 			res = _FAIL;
856 		kfree(param);
857 	}
858 
859 exit:
860 	return res;
861 }
862 
863 u8 rtw_setopmode_cmd(struct adapter  *padapter, enum ndis_802_11_network_infrastructure networktype, bool enqueue)
864 {
865 	struct	cmd_obj *ph2c;
866 	struct	setopmode_parm *psetop;
867 
868 	struct	cmd_priv   *pcmdpriv = &padapter->cmdpriv;
869 	u8 res = _SUCCESS;
870 
871 	psetop = rtw_zmalloc(sizeof(struct setopmode_parm));
872 
873 	if (!psetop) {
874 		res = _FAIL;
875 		goto exit;
876 	}
877 	psetop->mode = (u8)networktype;
878 
879 	if (enqueue) {
880 		ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
881 		if (!ph2c) {
882 			kfree(psetop);
883 			res = _FAIL;
884 			goto exit;
885 		}
886 
887 		init_h2fwcmd_w_parm_no_rsp(ph2c, psetop, _SetOpMode_CMD_);
888 		res = rtw_enqueue_cmd(pcmdpriv, ph2c);
889 	} else {
890 		setopmode_hdl(padapter, (u8 *)psetop);
891 		kfree(psetop);
892 	}
893 exit:
894 	return res;
895 }
896 
897 u8 rtw_setstakey_cmd(struct adapter *padapter, struct sta_info *sta, u8 unicast_key, bool enqueue)
898 {
899 	struct cmd_obj *ph2c;
900 	struct set_stakey_parm	*psetstakey_para;
901 	struct cmd_priv 			*pcmdpriv = &padapter->cmdpriv;
902 	struct set_stakey_rsp		*psetstakey_rsp = NULL;
903 
904 	struct mlme_priv 		*pmlmepriv = &padapter->mlmepriv;
905 	struct security_priv 	*psecuritypriv = &padapter->securitypriv;
906 	u8 res = _SUCCESS;
907 
908 	psetstakey_para = rtw_zmalloc(sizeof(struct set_stakey_parm));
909 	if (!psetstakey_para) {
910 		res = _FAIL;
911 		goto exit;
912 	}
913 
914 	memcpy(psetstakey_para->addr, sta->hwaddr, ETH_ALEN);
915 
916 	if (check_fwstate(pmlmepriv, WIFI_STATION_STATE))
917 		psetstakey_para->algorithm = (unsigned char)psecuritypriv->dot11PrivacyAlgrthm;
918 	else
919 		GET_ENCRY_ALGO(psecuritypriv, sta, psetstakey_para->algorithm, false);
920 
921 	if (unicast_key)
922 		memcpy(&psetstakey_para->key, &sta->dot118021x_UncstKey, 16);
923 	else
924 		memcpy(&psetstakey_para->key, &psecuritypriv->dot118021XGrpKey[psecuritypriv->dot118021XGrpKeyid].skey, 16);
925 
926 	/* jeff: set this because at least sw key is ready */
927 	padapter->securitypriv.busetkipkey = true;
928 
929 	if (enqueue) {
930 		ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
931 		if (!ph2c) {
932 			kfree(psetstakey_para);
933 			res = _FAIL;
934 			goto exit;
935 		}
936 
937 		psetstakey_rsp = rtw_zmalloc(sizeof(struct set_stakey_rsp));
938 		if (!psetstakey_rsp) {
939 			kfree(ph2c);
940 			kfree(psetstakey_para);
941 			res = _FAIL;
942 			goto exit;
943 		}
944 
945 		init_h2fwcmd_w_parm_no_rsp(ph2c, psetstakey_para, _SetStaKey_CMD_);
946 		ph2c->rsp = (u8 *)psetstakey_rsp;
947 		ph2c->rspsz = sizeof(struct set_stakey_rsp);
948 		res = rtw_enqueue_cmd(pcmdpriv, ph2c);
949 	} else {
950 		set_stakey_hdl(padapter, (u8 *)psetstakey_para);
951 		kfree(psetstakey_para);
952 	}
953 exit:
954 	return res;
955 }
956 
957 u8 rtw_clearstakey_cmd(struct adapter *padapter, struct sta_info *sta, u8 enqueue)
958 {
959 	struct cmd_obj *ph2c;
960 	struct set_stakey_parm	*psetstakey_para;
961 	struct cmd_priv 			*pcmdpriv = &padapter->cmdpriv;
962 	struct set_stakey_rsp		*psetstakey_rsp = NULL;
963 	s16 cam_id = 0;
964 	u8 res = _SUCCESS;
965 
966 	if (!enqueue) {
967 		while ((cam_id = rtw_camid_search(padapter, sta->hwaddr, -1)) >= 0) {
968 			netdev_dbg(padapter->pnetdev,
969 				   "clear key for addr:%pM, camid:%d\n",
970 				   MAC_ARG(sta->hwaddr), cam_id);
971 			clear_cam_entry(padapter, cam_id);
972 			rtw_camid_free(padapter, cam_id);
973 		}
974 	} else {
975 		ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
976 		if (!ph2c) {
977 			res = _FAIL;
978 			goto exit;
979 		}
980 
981 		psetstakey_para = rtw_zmalloc(sizeof(struct set_stakey_parm));
982 		if (!psetstakey_para) {
983 			kfree(ph2c);
984 			res = _FAIL;
985 			goto exit;
986 		}
987 
988 		psetstakey_rsp = rtw_zmalloc(sizeof(struct set_stakey_rsp));
989 		if (!psetstakey_rsp) {
990 			kfree(ph2c);
991 			kfree(psetstakey_para);
992 			res = _FAIL;
993 			goto exit;
994 		}
995 
996 		init_h2fwcmd_w_parm_no_rsp(ph2c, psetstakey_para, _SetStaKey_CMD_);
997 		ph2c->rsp = (u8 *)psetstakey_rsp;
998 		ph2c->rspsz = sizeof(struct set_stakey_rsp);
999 
1000 		memcpy(psetstakey_para->addr, sta->hwaddr, ETH_ALEN);
1001 
1002 		psetstakey_para->algorithm = _NO_PRIVACY_;
1003 
1004 		res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1005 	}
1006 exit:
1007 	return res;
1008 }
1009 
1010 u8 rtw_addbareq_cmd(struct adapter *padapter, u8 tid, u8 *addr)
1011 {
1012 	struct cmd_priv 	*pcmdpriv = &padapter->cmdpriv;
1013 	struct cmd_obj *ph2c;
1014 	struct addBaReq_parm	*paddbareq_parm;
1015 
1016 	u8 res = _SUCCESS;
1017 
1018 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1019 	if (!ph2c) {
1020 		res = _FAIL;
1021 		goto exit;
1022 	}
1023 
1024 	paddbareq_parm = rtw_zmalloc(sizeof(struct addBaReq_parm));
1025 	if (!paddbareq_parm) {
1026 		kfree(ph2c);
1027 		res = _FAIL;
1028 		goto exit;
1029 	}
1030 
1031 	paddbareq_parm->tid = tid;
1032 	memcpy(paddbareq_parm->addr, addr, ETH_ALEN);
1033 
1034 	init_h2fwcmd_w_parm_no_rsp(ph2c, paddbareq_parm, GEN_CMD_CODE(_AddBAReq));
1035 
1036 	/* rtw_enqueue_cmd(pcmdpriv, ph2c); */
1037 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1038 
1039 exit:
1040 	return res;
1041 }
1042 /* add for CONFIG_IEEE80211W, none 11w can use it */
1043 u8 rtw_reset_securitypriv_cmd(struct adapter *padapter)
1044 {
1045 	struct cmd_obj *ph2c;
1046 	struct drvextra_cmd_parm  *pdrvextra_cmd_parm;
1047 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1048 	u8 res = _SUCCESS;
1049 
1050 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1051 	if (!ph2c) {
1052 		res = _FAIL;
1053 		goto exit;
1054 	}
1055 
1056 	pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1057 	if (!pdrvextra_cmd_parm) {
1058 		kfree(ph2c);
1059 		res = _FAIL;
1060 		goto exit;
1061 	}
1062 
1063 	pdrvextra_cmd_parm->ec_id = RESET_SECURITYPRIV;
1064 	pdrvextra_cmd_parm->type = 0;
1065 	pdrvextra_cmd_parm->size = 0;
1066 	pdrvextra_cmd_parm->pbuf = NULL;
1067 
1068 	init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1069 
1070 
1071 	/* rtw_enqueue_cmd(pcmdpriv, ph2c); */
1072 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1073 exit:
1074 	return res;
1075 }
1076 
1077 u8 rtw_free_assoc_resources_cmd(struct adapter *padapter)
1078 {
1079 	struct cmd_obj *ph2c;
1080 	struct drvextra_cmd_parm  *pdrvextra_cmd_parm;
1081 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1082 	u8 res = _SUCCESS;
1083 
1084 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1085 	if (!ph2c) {
1086 		res = _FAIL;
1087 		goto exit;
1088 	}
1089 
1090 	pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1091 	if (!pdrvextra_cmd_parm) {
1092 		kfree(ph2c);
1093 		res = _FAIL;
1094 		goto exit;
1095 	}
1096 
1097 	pdrvextra_cmd_parm->ec_id = FREE_ASSOC_RESOURCES;
1098 	pdrvextra_cmd_parm->type = 0;
1099 	pdrvextra_cmd_parm->size = 0;
1100 	pdrvextra_cmd_parm->pbuf = NULL;
1101 
1102 	init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1103 
1104 	/* rtw_enqueue_cmd(pcmdpriv, ph2c); */
1105 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1106 exit:
1107 	return res;
1108 }
1109 
1110 u8 rtw_dynamic_chk_wk_cmd(struct adapter *padapter)
1111 {
1112 	struct cmd_obj *ph2c;
1113 	struct drvextra_cmd_parm  *pdrvextra_cmd_parm;
1114 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1115 	u8 res = _SUCCESS;
1116 
1117 	/* only  primary padapter does this cmd */
1118 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1119 	if (!ph2c) {
1120 		res = _FAIL;
1121 		goto exit;
1122 	}
1123 
1124 	pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1125 	if (!pdrvextra_cmd_parm) {
1126 		kfree(ph2c);
1127 		res = _FAIL;
1128 		goto exit;
1129 	}
1130 
1131 	pdrvextra_cmd_parm->ec_id = DYNAMIC_CHK_WK_CID;
1132 	pdrvextra_cmd_parm->type = 0;
1133 	pdrvextra_cmd_parm->size = 0;
1134 	pdrvextra_cmd_parm->pbuf = NULL;
1135 	init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1136 
1137 
1138 	/* rtw_enqueue_cmd(pcmdpriv, ph2c); */
1139 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1140 exit:
1141 	return res;
1142 }
1143 
1144 u8 rtw_set_chplan_cmd(struct adapter *padapter, u8 chplan, u8 enqueue, u8 swconfig)
1145 {
1146 	struct	cmd_obj *pcmdobj;
1147 	struct	SetChannelPlan_param *setChannelPlan_param;
1148 	struct	cmd_priv   *pcmdpriv = &padapter->cmdpriv;
1149 
1150 	u8 res = _SUCCESS;
1151 
1152 	/*  check if allow software config */
1153 	if (swconfig && rtw_hal_is_disable_sw_channel_plan(padapter)) {
1154 		res = _FAIL;
1155 		goto exit;
1156 	}
1157 
1158 	/* check input parameter */
1159 	if (!rtw_is_channel_plan_valid(chplan)) {
1160 		res = _FAIL;
1161 		goto exit;
1162 	}
1163 
1164 	/* prepare cmd parameter */
1165 	setChannelPlan_param = rtw_zmalloc(sizeof(struct SetChannelPlan_param));
1166 	if (!setChannelPlan_param) {
1167 		res = _FAIL;
1168 		goto exit;
1169 	}
1170 	setChannelPlan_param->channel_plan = chplan;
1171 
1172 	if (enqueue) {
1173 		/* need enqueue, prepare cmd_obj and enqueue */
1174 		pcmdobj = rtw_zmalloc(sizeof(struct cmd_obj));
1175 		if (!pcmdobj) {
1176 			kfree(setChannelPlan_param);
1177 			res = _FAIL;
1178 			goto exit;
1179 		}
1180 
1181 		init_h2fwcmd_w_parm_no_rsp(pcmdobj, setChannelPlan_param, GEN_CMD_CODE(_SetChannelPlan));
1182 		res = rtw_enqueue_cmd(pcmdpriv, pcmdobj);
1183 	} else {
1184 		/* no need to enqueue, do the cmd hdl directly and free cmd parameter */
1185 		if (set_chplan_hdl(padapter, (unsigned char *)setChannelPlan_param) != H2C_SUCCESS)
1186 			res = _FAIL;
1187 
1188 		kfree(setChannelPlan_param);
1189 	}
1190 
1191 	/* do something based on res... */
1192 	if (res == _SUCCESS)
1193 		padapter->mlmepriv.ChannelPlan = chplan;
1194 
1195 exit:
1196 	return res;
1197 }
1198 
1199 static void collect_traffic_statistics(struct adapter *padapter)
1200 {
1201 	struct dvobj_priv *pdvobjpriv = adapter_to_dvobj(padapter);
1202 
1203 	/*  Tx */
1204 	pdvobjpriv->traffic_stat.tx_bytes = padapter->xmitpriv.tx_bytes;
1205 	pdvobjpriv->traffic_stat.tx_pkts = padapter->xmitpriv.tx_pkts;
1206 	pdvobjpriv->traffic_stat.tx_drop = padapter->xmitpriv.tx_drop;
1207 
1208 	/*  Rx */
1209 	pdvobjpriv->traffic_stat.rx_bytes = padapter->recvpriv.rx_bytes;
1210 	pdvobjpriv->traffic_stat.rx_pkts = padapter->recvpriv.rx_pkts;
1211 	pdvobjpriv->traffic_stat.rx_drop = padapter->recvpriv.rx_drop;
1212 
1213 	/*  Calculate throughput in last interval */
1214 	pdvobjpriv->traffic_stat.cur_tx_bytes = pdvobjpriv->traffic_stat.tx_bytes - pdvobjpriv->traffic_stat.last_tx_bytes;
1215 	pdvobjpriv->traffic_stat.cur_rx_bytes = pdvobjpriv->traffic_stat.rx_bytes - pdvobjpriv->traffic_stat.last_rx_bytes;
1216 	pdvobjpriv->traffic_stat.last_tx_bytes = pdvobjpriv->traffic_stat.tx_bytes;
1217 	pdvobjpriv->traffic_stat.last_rx_bytes = pdvobjpriv->traffic_stat.rx_bytes;
1218 
1219 	pdvobjpriv->traffic_stat.cur_tx_tp = (u32)(pdvobjpriv->traffic_stat.cur_tx_bytes * 8/2/1024/1024);
1220 	pdvobjpriv->traffic_stat.cur_rx_tp = (u32)(pdvobjpriv->traffic_stat.cur_rx_bytes * 8/2/1024/1024);
1221 }
1222 
1223 u8 traffic_status_watchdog(struct adapter *padapter, u8 from_timer)
1224 {
1225 	u8 bEnterPS = false;
1226 	u16 BusyThresholdHigh = 25;
1227 	u16 BusyThresholdLow = 10;
1228 	u16 BusyThreshold = BusyThresholdHigh;
1229 	u8 bBusyTraffic = false, bTxBusyTraffic = false, bRxBusyTraffic = false;
1230 	u8 bHigherBusyTraffic = false, bHigherBusyRxTraffic = false, bHigherBusyTxTraffic = false;
1231 
1232 	struct mlme_priv 	*pmlmepriv = &padapter->mlmepriv;
1233 
1234 	collect_traffic_statistics(padapter);
1235 
1236 	/*  */
1237 	/*  Determine if our traffic is busy now */
1238 	/*  */
1239 	if ((check_fwstate(pmlmepriv, _FW_LINKED))
1240 		/*&& !MgntInitAdapterInProgress(pMgntInfo)*/) {
1241 		/*  if we raise bBusyTraffic in last watchdog, using lower threshold. */
1242 		if (pmlmepriv->LinkDetectInfo.bBusyTraffic)
1243 				BusyThreshold = BusyThresholdLow;
1244 
1245 		if (pmlmepriv->LinkDetectInfo.NumRxOkInPeriod > BusyThreshold ||
1246 			pmlmepriv->LinkDetectInfo.NumTxOkInPeriod > BusyThreshold) {
1247 			bBusyTraffic = true;
1248 
1249 			if (pmlmepriv->LinkDetectInfo.NumRxOkInPeriod > pmlmepriv->LinkDetectInfo.NumTxOkInPeriod)
1250 				bRxBusyTraffic = true;
1251 			else
1252 				bTxBusyTraffic = true;
1253 		}
1254 
1255 		/*  Higher Tx/Rx data. */
1256 		if (pmlmepriv->LinkDetectInfo.NumRxOkInPeriod > 4000 ||
1257 			pmlmepriv->LinkDetectInfo.NumTxOkInPeriod > 4000) {
1258 			bHigherBusyTraffic = true;
1259 
1260 			if (pmlmepriv->LinkDetectInfo.NumRxOkInPeriod > pmlmepriv->LinkDetectInfo.NumTxOkInPeriod)
1261 				bHigherBusyRxTraffic = true;
1262 			else
1263 				bHigherBusyTxTraffic = true;
1264 		}
1265 
1266 		/*  check traffic for  powersaving. */
1267 		if (((pmlmepriv->LinkDetectInfo.NumRxUnicastOkInPeriod + pmlmepriv->LinkDetectInfo.NumTxOkInPeriod) > 8) ||
1268 			(pmlmepriv->LinkDetectInfo.NumRxUnicastOkInPeriod > 2)) {
1269 			bEnterPS = false;
1270 
1271 			if (bBusyTraffic) {
1272 				if (pmlmepriv->LinkDetectInfo.TrafficTransitionCount <= 4)
1273 					pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 4;
1274 
1275 				pmlmepriv->LinkDetectInfo.TrafficTransitionCount++;
1276 
1277 				if (pmlmepriv->LinkDetectInfo.TrafficTransitionCount > 30/*TrafficTransitionLevel*/)
1278 					pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 30;
1279 			}
1280 		} else {
1281 			if (pmlmepriv->LinkDetectInfo.TrafficTransitionCount >= 2)
1282 				pmlmepriv->LinkDetectInfo.TrafficTransitionCount -= 2;
1283 			else
1284 				pmlmepriv->LinkDetectInfo.TrafficTransitionCount = 0;
1285 
1286 			if (pmlmepriv->LinkDetectInfo.TrafficTransitionCount == 0)
1287 				bEnterPS = true;
1288 		}
1289 
1290 		/*  LeisurePS only work in infra mode. */
1291 		if (bEnterPS) {
1292 			if (!from_timer)
1293 				LPS_Enter(padapter, "TRAFFIC_IDLE");
1294 		} else {
1295 			if (!from_timer)
1296 				LPS_Leave(padapter, "TRAFFIC_BUSY");
1297 			else
1298 				rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_TRAFFIC_BUSY, 1);
1299 		}
1300 	} else {
1301 		struct dvobj_priv *dvobj = adapter_to_dvobj(padapter);
1302 		int n_assoc_iface = 0;
1303 
1304 		if (check_fwstate(&dvobj->padapters->mlmepriv, WIFI_ASOC_STATE))
1305 			n_assoc_iface++;
1306 
1307 		if (!from_timer && n_assoc_iface == 0)
1308 			LPS_Leave(padapter, "NON_LINKED");
1309 	}
1310 
1311 	pmlmepriv->LinkDetectInfo.NumRxOkInPeriod = 0;
1312 	pmlmepriv->LinkDetectInfo.NumTxOkInPeriod = 0;
1313 	pmlmepriv->LinkDetectInfo.NumRxUnicastOkInPeriod = 0;
1314 	pmlmepriv->LinkDetectInfo.bBusyTraffic = bBusyTraffic;
1315 	pmlmepriv->LinkDetectInfo.bTxBusyTraffic = bTxBusyTraffic;
1316 	pmlmepriv->LinkDetectInfo.bRxBusyTraffic = bRxBusyTraffic;
1317 	pmlmepriv->LinkDetectInfo.bHigherBusyTraffic = bHigherBusyTraffic;
1318 	pmlmepriv->LinkDetectInfo.bHigherBusyRxTraffic = bHigherBusyRxTraffic;
1319 	pmlmepriv->LinkDetectInfo.bHigherBusyTxTraffic = bHigherBusyTxTraffic;
1320 
1321 	return bEnterPS;
1322 
1323 }
1324 
1325 static void dynamic_chk_wk_hdl(struct adapter *padapter)
1326 {
1327 	struct mlme_priv *pmlmepriv;
1328 
1329 	pmlmepriv = &padapter->mlmepriv;
1330 
1331 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE))
1332 		expire_timeout_chk(padapter);
1333 
1334 	/* for debug purpose */
1335 	_linked_info_dump(padapter);
1336 	/* if (check_fwstate(pmlmepriv, _FW_UNDER_LINKING|_FW_UNDER_SURVEY) ==false) */
1337 	{
1338 		linked_status_chk(padapter);
1339 		traffic_status_watchdog(padapter, 0);
1340 	}
1341 	rtw_hal_dm_watchdog(padapter);
1342 
1343 	/* check_hw_pbc(padapter, pdrvextra_cmd->pbuf, pdrvextra_cmd->type); */
1344 
1345 	/*  */
1346 	/*  BT-Coexist */
1347 	/*  */
1348 	hal_btcoex_Handler(padapter);
1349 
1350 
1351 	/* always call rtw_ps_processor() at last one. */
1352 	if (is_primary_adapter(padapter))
1353 		rtw_ps_processor(padapter);
1354 }
1355 
1356 void lps_ctrl_wk_hdl(struct adapter *padapter, u8 lps_ctrl_type);
1357 void lps_ctrl_wk_hdl(struct adapter *padapter, u8 lps_ctrl_type)
1358 {
1359 	struct pwrctrl_priv *pwrpriv = adapter_to_pwrctl(padapter);
1360 	struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
1361 	u8 mstatus;
1362 
1363 	if (check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE) ||
1364 		check_fwstate(pmlmepriv, WIFI_ADHOC_STATE)) {
1365 		return;
1366 	}
1367 
1368 	switch (lps_ctrl_type) {
1369 	case LPS_CTRL_SCAN:
1370 		hal_btcoex_ScanNotify(padapter, true);
1371 
1372 		if (check_fwstate(pmlmepriv, _FW_LINKED)) {
1373 			/*  connect */
1374 			LPS_Leave(padapter, "LPS_CTRL_SCAN");
1375 		}
1376 		break;
1377 	case LPS_CTRL_JOINBSS:
1378 		LPS_Leave(padapter, "LPS_CTRL_JOINBSS");
1379 		break;
1380 	case LPS_CTRL_CONNECT:
1381 		mstatus = 1;/* connect */
1382 		/*  Reset LPS Setting */
1383 		pwrpriv->LpsIdleCount = 0;
1384 		rtw_hal_set_hwreg(padapter, HW_VAR_H2C_FW_JOINBSSRPT, (u8 *)(&mstatus));
1385 		rtw_btcoex_MediaStatusNotify(padapter, mstatus);
1386 		break;
1387 	case LPS_CTRL_DISCONNECT:
1388 		mstatus = 0;/* disconnect */
1389 		rtw_btcoex_MediaStatusNotify(padapter, mstatus);
1390 		LPS_Leave(padapter, "LPS_CTRL_DISCONNECT");
1391 		rtw_hal_set_hwreg(padapter, HW_VAR_H2C_FW_JOINBSSRPT, (u8 *)(&mstatus));
1392 		break;
1393 	case LPS_CTRL_SPECIAL_PACKET:
1394 		pwrpriv->DelayLPSLastTimeStamp = jiffies;
1395 		hal_btcoex_SpecialPacketNotify(padapter, PACKET_DHCP);
1396 		LPS_Leave(padapter, "LPS_CTRL_SPECIAL_PACKET");
1397 		break;
1398 	case LPS_CTRL_LEAVE:
1399 		LPS_Leave(padapter, "LPS_CTRL_LEAVE");
1400 		break;
1401 	case LPS_CTRL_TRAFFIC_BUSY:
1402 		LPS_Leave(padapter, "LPS_CTRL_TRAFFIC_BUSY");
1403 		break;
1404 	default:
1405 		break;
1406 	}
1407 }
1408 
1409 u8 rtw_lps_ctrl_wk_cmd(struct adapter *padapter, u8 lps_ctrl_type, u8 enqueue)
1410 {
1411 	struct cmd_obj	*ph2c;
1412 	struct drvextra_cmd_parm	*pdrvextra_cmd_parm;
1413 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1414 	/* struct pwrctrl_priv *pwrctrlpriv = adapter_to_pwrctl(padapter); */
1415 	u8 res = _SUCCESS;
1416 
1417 	/* if (!pwrctrlpriv->bLeisurePs) */
1418 	/* 	return res; */
1419 
1420 	if (enqueue) {
1421 		ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1422 		if (!ph2c) {
1423 			res = _FAIL;
1424 			goto exit;
1425 		}
1426 
1427 		pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1428 		if (!pdrvextra_cmd_parm) {
1429 			kfree(ph2c);
1430 			res = _FAIL;
1431 			goto exit;
1432 		}
1433 
1434 		pdrvextra_cmd_parm->ec_id = LPS_CTRL_WK_CID;
1435 		pdrvextra_cmd_parm->type = lps_ctrl_type;
1436 		pdrvextra_cmd_parm->size = 0;
1437 		pdrvextra_cmd_parm->pbuf = NULL;
1438 
1439 		init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1440 
1441 		res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1442 	} else {
1443 		lps_ctrl_wk_hdl(padapter, lps_ctrl_type);
1444 	}
1445 
1446 exit:
1447 	return res;
1448 }
1449 
1450 static void rtw_dm_in_lps_hdl(struct adapter *padapter)
1451 {
1452 	rtw_hal_set_hwreg(padapter, HW_VAR_DM_IN_LPS, NULL);
1453 }
1454 
1455 u8 rtw_dm_in_lps_wk_cmd(struct adapter *padapter)
1456 {
1457 	struct cmd_obj	*ph2c;
1458 	struct drvextra_cmd_parm	*pdrvextra_cmd_parm;
1459 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1460 	u8 res = _SUCCESS;
1461 
1462 
1463 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1464 	if (!ph2c) {
1465 		res = _FAIL;
1466 		goto exit;
1467 	}
1468 
1469 	pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1470 	if (!pdrvextra_cmd_parm) {
1471 		kfree(ph2c);
1472 		res = _FAIL;
1473 		goto exit;
1474 	}
1475 
1476 	pdrvextra_cmd_parm->ec_id = DM_IN_LPS_WK_CID;
1477 	pdrvextra_cmd_parm->type = 0;
1478 	pdrvextra_cmd_parm->size = 0;
1479 	pdrvextra_cmd_parm->pbuf = NULL;
1480 
1481 	init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1482 
1483 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1484 
1485 exit:
1486 	return res;
1487 }
1488 
1489 static void rtw_lps_change_dtim_hdl(struct adapter *padapter, u8 dtim)
1490 {
1491 	struct pwrctrl_priv *pwrpriv = adapter_to_pwrctl(padapter);
1492 
1493 	if (dtim <= 0 || dtim > 16)
1494 		return;
1495 
1496 	if (hal_btcoex_IsBtControlLps(padapter))
1497 		return;
1498 
1499 	mutex_lock(&pwrpriv->lock);
1500 
1501 	if (pwrpriv->dtim != dtim)
1502 		pwrpriv->dtim = dtim;
1503 
1504 	if (pwrpriv->fw_current_in_ps_mode && (pwrpriv->pwr_mode > PS_MODE_ACTIVE)) {
1505 		u8 ps_mode = pwrpriv->pwr_mode;
1506 
1507 		rtw_hal_set_hwreg(padapter, HW_VAR_H2C_FW_PWRMODE, (u8 *)(&ps_mode));
1508 	}
1509 
1510 	mutex_unlock(&pwrpriv->lock);
1511 }
1512 
1513 static void rtw_dm_ra_mask_hdl(struct adapter *padapter, struct sta_info *psta)
1514 {
1515 	if (psta)
1516 		set_sta_rate(padapter, psta);
1517 }
1518 
1519 u8 rtw_dm_ra_mask_wk_cmd(struct adapter *padapter, u8 *psta)
1520 {
1521 	struct cmd_obj	*ph2c;
1522 	struct drvextra_cmd_parm	*pdrvextra_cmd_parm;
1523 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1524 	u8 res = _SUCCESS;
1525 
1526 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1527 	if (!ph2c) {
1528 		res = _FAIL;
1529 		goto exit;
1530 	}
1531 
1532 	pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1533 	if (!pdrvextra_cmd_parm) {
1534 		kfree(ph2c);
1535 		res = _FAIL;
1536 		goto exit;
1537 	}
1538 
1539 	pdrvextra_cmd_parm->ec_id = DM_RA_MSK_WK_CID;
1540 	pdrvextra_cmd_parm->type = 0;
1541 	pdrvextra_cmd_parm->size = 0;
1542 	pdrvextra_cmd_parm->pbuf = psta;
1543 
1544 	init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1545 
1546 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1547 
1548 exit:
1549 
1550 	return res;
1551 
1552 }
1553 
1554 u8 rtw_ps_cmd(struct adapter *padapter)
1555 {
1556 	struct cmd_obj		*ppscmd;
1557 	struct drvextra_cmd_parm	*pdrvextra_cmd_parm;
1558 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1559 	u8 res = _SUCCESS;
1560 	ppscmd = rtw_zmalloc(sizeof(struct cmd_obj));
1561 	if (!ppscmd) {
1562 		res = _FAIL;
1563 		goto exit;
1564 	}
1565 
1566 	pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1567 	if (!pdrvextra_cmd_parm) {
1568 		kfree(ppscmd);
1569 		res = _FAIL;
1570 		goto exit;
1571 	}
1572 
1573 	pdrvextra_cmd_parm->ec_id = POWER_SAVING_CTRL_WK_CID;
1574 	pdrvextra_cmd_parm->type = 0;
1575 	pdrvextra_cmd_parm->size = 0;
1576 	pdrvextra_cmd_parm->pbuf = NULL;
1577 	init_h2fwcmd_w_parm_no_rsp(ppscmd, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1578 
1579 	res = rtw_enqueue_cmd(pcmdpriv, ppscmd);
1580 
1581 exit:
1582 	return res;
1583 }
1584 
1585 u32 g_wait_hiq_empty;
1586 
1587 static void rtw_chk_hi_queue_hdl(struct adapter *padapter)
1588 {
1589 	struct sta_info *psta_bmc;
1590 	struct sta_priv *pstapriv = &padapter->stapriv;
1591 	unsigned long start = jiffies;
1592 	u8 empty = false;
1593 
1594 	psta_bmc = rtw_get_bcmc_stainfo(padapter);
1595 	if (!psta_bmc)
1596 		return;
1597 
1598 	rtw_hal_get_hwreg(padapter, HW_VAR_CHK_HI_QUEUE_EMPTY, &empty);
1599 
1600 	while (!empty && jiffies_to_msecs(jiffies - start) < g_wait_hiq_empty) {
1601 		msleep(100);
1602 		rtw_hal_get_hwreg(padapter, HW_VAR_CHK_HI_QUEUE_EMPTY, &empty);
1603 	}
1604 
1605 	if (psta_bmc->sleepq_len == 0) {
1606 		if (empty == _SUCCESS) {
1607 			bool update_tim = false;
1608 
1609 			if (pstapriv->tim_bitmap & BIT(0))
1610 				update_tim = true;
1611 
1612 			pstapriv->tim_bitmap &= ~BIT(0);
1613 			pstapriv->sta_dz_bitmap &= ~BIT(0);
1614 
1615 			if (update_tim)
1616 				update_beacon(padapter, WLAN_EID_TIM, NULL, true);
1617 		} else {/* re check again */
1618 			rtw_chk_hi_queue_cmd(padapter);
1619 		}
1620 
1621 	}
1622 
1623 }
1624 
1625 u8 rtw_chk_hi_queue_cmd(struct adapter *padapter)
1626 {
1627 	struct cmd_obj	*ph2c;
1628 	struct drvextra_cmd_parm	*pdrvextra_cmd_parm;
1629 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1630 	u8 res = _SUCCESS;
1631 
1632 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1633 	if (!ph2c) {
1634 		res = _FAIL;
1635 		goto exit;
1636 	}
1637 
1638 	pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1639 	if (!pdrvextra_cmd_parm) {
1640 		kfree(ph2c);
1641 		res = _FAIL;
1642 		goto exit;
1643 	}
1644 
1645 	pdrvextra_cmd_parm->ec_id = CHECK_HIQ_WK_CID;
1646 	pdrvextra_cmd_parm->type = 0;
1647 	pdrvextra_cmd_parm->size = 0;
1648 	pdrvextra_cmd_parm->pbuf = NULL;
1649 
1650 	init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1651 
1652 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1653 
1654 exit:
1655 	return res;
1656 }
1657 
1658 struct btinfo {
1659 	u8 cid;
1660 	u8 len;
1661 
1662 	u8 bConnection:1;
1663 	u8 bSCOeSCO:1;
1664 	u8 bInQPage:1;
1665 	u8 bACLBusy:1;
1666 	u8 bSCOBusy:1;
1667 	u8 bHID:1;
1668 	u8 bA2DP:1;
1669 	u8 bFTP:1;
1670 
1671 	u8 retry_cnt:4;
1672 	u8 rsvd_34:1;
1673 	u8 rsvd_35:1;
1674 	u8 rsvd_36:1;
1675 	u8 rsvd_37:1;
1676 
1677 	u8 rssi;
1678 
1679 	u8 rsvd_50:1;
1680 	u8 rsvd_51:1;
1681 	u8 rsvd_52:1;
1682 	u8 rsvd_53:1;
1683 	u8 rsvd_54:1;
1684 	u8 rsvd_55:1;
1685 	u8 eSCO_SCO:1;
1686 	u8 Master_Slave:1;
1687 
1688 	u8 rsvd_6;
1689 	u8 rsvd_7;
1690 };
1691 
1692 static void rtw_btinfo_hdl(struct adapter *adapter, u8 *buf, u16 buf_len)
1693 {
1694 	#define BTINFO_WIFI_FETCH 0x23
1695 	#define BTINFO_BT_AUTO_RPT 0x27
1696 	struct btinfo *info = (struct btinfo *)buf;
1697 	u8 cmd_idx;
1698 	u8 len;
1699 
1700 	cmd_idx = info->cid;
1701 
1702 	if (info->len > buf_len-2) {
1703 		rtw_warn_on(1);
1704 		len = buf_len-2;
1705 	} else {
1706 		len = info->len;
1707 	}
1708 
1709 	/* transform BT-FW btinfo to WiFI-FW C2H format and notify */
1710 	if (cmd_idx == BTINFO_WIFI_FETCH)
1711 		buf[1] = 0;
1712 	else if (cmd_idx == BTINFO_BT_AUTO_RPT)
1713 		buf[1] = 2;
1714 	hal_btcoex_BtInfoNotify(adapter, len+1, &buf[1]);
1715 }
1716 
1717 u8 rtw_c2h_packet_wk_cmd(struct adapter *padapter, u8 *pbuf, u16 length)
1718 {
1719 	struct cmd_obj *ph2c;
1720 	struct drvextra_cmd_parm *pdrvextra_cmd_parm;
1721 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1722 	u8 res = _SUCCESS;
1723 
1724 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1725 	if (!ph2c) {
1726 		res = _FAIL;
1727 		goto exit;
1728 	}
1729 
1730 	pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1731 	if (!pdrvextra_cmd_parm) {
1732 		kfree(ph2c);
1733 		res = _FAIL;
1734 		goto exit;
1735 	}
1736 
1737 	pdrvextra_cmd_parm->ec_id = C2H_WK_CID;
1738 	pdrvextra_cmd_parm->type = 0;
1739 	pdrvextra_cmd_parm->size = length;
1740 	pdrvextra_cmd_parm->pbuf = pbuf;
1741 
1742 	init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1743 
1744 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1745 
1746 exit:
1747 	return res;
1748 }
1749 
1750 /* dont call R/W in this function, beucase SDIO interrupt have claim host */
1751 /* or deadlock will happen and cause special-systemserver-died in android */
1752 u8 rtw_c2h_wk_cmd(struct adapter *padapter, u8 *c2h_evt)
1753 {
1754 	struct cmd_obj *ph2c;
1755 	struct drvextra_cmd_parm *pdrvextra_cmd_parm;
1756 	struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
1757 	u8 res = _SUCCESS;
1758 
1759 	ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
1760 	if (!ph2c) {
1761 		res = _FAIL;
1762 		goto exit;
1763 	}
1764 
1765 	pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
1766 	if (!pdrvextra_cmd_parm) {
1767 		kfree(ph2c);
1768 		res = _FAIL;
1769 		goto exit;
1770 	}
1771 
1772 	pdrvextra_cmd_parm->ec_id = C2H_WK_CID;
1773 	pdrvextra_cmd_parm->type = 0;
1774 	pdrvextra_cmd_parm->size =  c2h_evt?16:0;
1775 	pdrvextra_cmd_parm->pbuf = c2h_evt;
1776 
1777 	init_h2fwcmd_w_parm_no_rsp(ph2c, pdrvextra_cmd_parm, GEN_CMD_CODE(_Set_Drv_Extra));
1778 
1779 	res = rtw_enqueue_cmd(pcmdpriv, ph2c);
1780 
1781 exit:
1782 
1783 	return res;
1784 }
1785 
1786 static void c2h_wk_callback(struct work_struct *work)
1787 {
1788 	struct evt_priv *evtpriv = container_of(work, struct evt_priv, c2h_wk);
1789 	struct adapter *adapter = container_of(evtpriv, struct adapter, evtpriv);
1790 	u8 *c2h_evt;
1791 	c2h_id_filter ccx_id_filter = rtw_hal_c2h_id_filter_ccx(adapter);
1792 
1793 	evtpriv->c2h_wk_alive = true;
1794 
1795 	while (!rtw_cbuf_empty(evtpriv->c2h_queue)) {
1796 		c2h_evt = (u8 *)rtw_cbuf_pop(evtpriv->c2h_queue);
1797 		if (c2h_evt) {
1798 			/* This C2H event is read, clear it */
1799 			c2h_evt_clear(adapter);
1800 		} else {
1801 			c2h_evt = rtw_malloc(16);
1802 			if (c2h_evt) {
1803 				/* This C2H event is not read, read & clear now */
1804 				if (c2h_evt_read_88xx(adapter, c2h_evt) != _SUCCESS) {
1805 					kfree(c2h_evt);
1806 					continue;
1807 				}
1808 			}
1809 		}
1810 
1811 		/* Special pointer to trigger c2h_evt_clear only */
1812 		if ((void *)c2h_evt == (void *)evtpriv)
1813 			continue;
1814 
1815 		if (!rtw_hal_c2h_valid(adapter, c2h_evt)) {
1816 			kfree(c2h_evt);
1817 			continue;
1818 		}
1819 
1820 		if (ccx_id_filter(c2h_evt)) {
1821 			/* Handle CCX report here */
1822 			rtw_hal_c2h_handler(adapter, c2h_evt);
1823 			kfree(c2h_evt);
1824 		} else {
1825 			/* Enqueue into cmd_thread for others */
1826 			rtw_c2h_wk_cmd(adapter, c2h_evt);
1827 		}
1828 	}
1829 
1830 	evtpriv->c2h_wk_alive = false;
1831 }
1832 
1833 u8 rtw_drvextra_cmd_hdl(struct adapter *padapter, unsigned char *pbuf)
1834 {
1835 	struct drvextra_cmd_parm *pdrvextra_cmd;
1836 
1837 	if (!pbuf)
1838 		return H2C_PARAMETERS_ERROR;
1839 
1840 	pdrvextra_cmd = (struct drvextra_cmd_parm *)pbuf;
1841 
1842 	switch (pdrvextra_cmd->ec_id) {
1843 	case DYNAMIC_CHK_WK_CID:/* only  primary padapter go to this cmd, but execute dynamic_chk_wk_hdl() for two interfaces */
1844 		dynamic_chk_wk_hdl(padapter);
1845 		break;
1846 	case POWER_SAVING_CTRL_WK_CID:
1847 		rtw_ps_processor(padapter);
1848 		break;
1849 	case LPS_CTRL_WK_CID:
1850 		lps_ctrl_wk_hdl(padapter, (u8)pdrvextra_cmd->type);
1851 		break;
1852 	case DM_IN_LPS_WK_CID:
1853 		rtw_dm_in_lps_hdl(padapter);
1854 		break;
1855 	case LPS_CHANGE_DTIM_CID:
1856 		rtw_lps_change_dtim_hdl(padapter, (u8)pdrvextra_cmd->type);
1857 		break;
1858 	case CHECK_HIQ_WK_CID:
1859 		rtw_chk_hi_queue_hdl(padapter);
1860 		break;
1861 	/* add for CONFIG_IEEE80211W, none 11w can use it */
1862 	case RESET_SECURITYPRIV:
1863 		rtw_reset_securitypriv(padapter);
1864 		break;
1865 	case FREE_ASSOC_RESOURCES:
1866 		rtw_free_assoc_resources(padapter, 1);
1867 		break;
1868 	case C2H_WK_CID:
1869 		rtw_hal_set_hwreg_with_buf(padapter, HW_VAR_C2H_HANDLE, pdrvextra_cmd->pbuf, pdrvextra_cmd->size);
1870 		break;
1871 	case DM_RA_MSK_WK_CID:
1872 		rtw_dm_ra_mask_hdl(padapter, (struct sta_info *)pdrvextra_cmd->pbuf);
1873 		break;
1874 	case BTINFO_WK_CID:
1875 		rtw_btinfo_hdl(padapter, pdrvextra_cmd->pbuf, pdrvextra_cmd->size);
1876 		break;
1877 	default:
1878 		break;
1879 	}
1880 
1881 	if (pdrvextra_cmd->pbuf && pdrvextra_cmd->size > 0)
1882 		kfree(pdrvextra_cmd->pbuf);
1883 
1884 	return H2C_SUCCESS;
1885 }
1886 
1887 void rtw_survey_cmd_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
1888 {
1889 	struct	mlme_priv *pmlmepriv = &padapter->mlmepriv;
1890 
1891 	if (pcmd->res == H2C_DROPPED) {
1892 		/* TODO: cancel timer and do timeout handler directly... */
1893 		/* need to make timeout handlerOS independent */
1894 		_set_timer(&pmlmepriv->scan_to_timer, 1);
1895 	} else if (pcmd->res != H2C_SUCCESS) {
1896 		_set_timer(&pmlmepriv->scan_to_timer, 1);
1897 	}
1898 
1899 	/*  free cmd */
1900 	rtw_free_cmd_obj(pcmd);
1901 }
1902 
1903 void rtw_disassoc_cmd_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
1904 {
1905 	struct	mlme_priv *pmlmepriv = &padapter->mlmepriv;
1906 
1907 	if (pcmd->res != H2C_SUCCESS) {
1908 		spin_lock_bh(&pmlmepriv->lock);
1909 		set_fwstate(pmlmepriv, _FW_LINKED);
1910 		spin_unlock_bh(&pmlmepriv->lock);
1911 
1912 		return;
1913 	}
1914 	/*  free cmd */
1915 	rtw_free_cmd_obj(pcmd);
1916 }
1917 
1918 void rtw_joinbss_cmd_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
1919 {
1920 	struct	mlme_priv *pmlmepriv = &padapter->mlmepriv;
1921 
1922 	if (pcmd->res == H2C_DROPPED) {
1923 		/* TODO: cancel timer and do timeout handler directly... */
1924 		/* need to make timeout handlerOS independent */
1925 		_set_timer(&pmlmepriv->assoc_timer, 1);
1926 	} else if (pcmd->res != H2C_SUCCESS) {
1927 		_set_timer(&pmlmepriv->assoc_timer, 1);
1928 	}
1929 
1930 	rtw_free_cmd_obj(pcmd);
1931 }
1932 
1933 void rtw_createbss_cmd_callback(struct adapter *padapter, struct cmd_obj *pcmd)
1934 {
1935 	struct sta_info *psta = NULL;
1936 	struct wlan_network *pwlan = NULL;
1937 	struct	mlme_priv *pmlmepriv = &padapter->mlmepriv;
1938 	struct wlan_bssid_ex *pnetwork = (struct wlan_bssid_ex *)pcmd->parmbuf;
1939 	struct wlan_network *tgt_network = &pmlmepriv->cur_network;
1940 
1941 	if (!pcmd->parmbuf)
1942 		goto exit;
1943 
1944 	if (pcmd->res != H2C_SUCCESS)
1945 		_set_timer(&pmlmepriv->assoc_timer, 1);
1946 
1947 	del_timer_sync(&pmlmepriv->assoc_timer);
1948 
1949 	spin_lock_bh(&pmlmepriv->lock);
1950 
1951 
1952 	if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
1953 		psta = rtw_get_stainfo(&padapter->stapriv, pnetwork->mac_address);
1954 		if (!psta) {
1955 			psta = rtw_alloc_stainfo(&padapter->stapriv, pnetwork->mac_address);
1956 			if (!psta)
1957 				goto createbss_cmd_fail;
1958 		}
1959 
1960 		rtw_indicate_connect(padapter);
1961 	} else {
1962 		pwlan = rtw_alloc_network(pmlmepriv);
1963 		spin_lock_bh(&pmlmepriv->scanned_queue.lock);
1964 		if (!pwlan) {
1965 			pwlan = rtw_get_oldest_wlan_network(&pmlmepriv->scanned_queue);
1966 			if (!pwlan) {
1967 				spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1968 				goto createbss_cmd_fail;
1969 			}
1970 			pwlan->last_scanned = jiffies;
1971 		} else {
1972 			list_add_tail(&pwlan->list, &pmlmepriv->scanned_queue.queue);
1973 		}
1974 
1975 		pnetwork->length = get_wlan_bssid_ex_sz(pnetwork);
1976 		memcpy(&pwlan->network, pnetwork, pnetwork->length);
1977 		/* pwlan->fixed = true; */
1978 
1979 		/* list_add_tail(&(pwlan->list), &pmlmepriv->scanned_queue.queue); */
1980 
1981 		/*  copy pdev_network information to	pmlmepriv->cur_network */
1982 		memcpy(&tgt_network->network, pnetwork, (get_wlan_bssid_ex_sz(pnetwork)));
1983 
1984 		/*  reset ds_config */
1985 		/* tgt_network->network.configuration.ds_config = (u32)rtw_ch2freq(pnetwork->configuration.ds_config); */
1986 
1987 		_clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
1988 
1989 		spin_unlock_bh(&pmlmepriv->scanned_queue.lock);
1990 		/*  we will set _FW_LINKED when there is one more sat to join us (rtw_stassoc_event_callback) */
1991 
1992 	}
1993 
1994 createbss_cmd_fail:
1995 
1996 	spin_unlock_bh(&pmlmepriv->lock);
1997 exit:
1998 	rtw_free_cmd_obj(pcmd);
1999 }
2000 
2001 void rtw_setstaKey_cmdrsp_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
2002 {
2003 	struct sta_priv *pstapriv = &padapter->stapriv;
2004 	struct set_stakey_rsp *psetstakey_rsp = (struct set_stakey_rsp *)(pcmd->rsp);
2005 	struct sta_info *psta = rtw_get_stainfo(pstapriv, psetstakey_rsp->addr);
2006 
2007 	if (!psta)
2008 		goto exit;
2009 
2010 exit:
2011 	rtw_free_cmd_obj(pcmd);
2012 }
2013 
2014 void rtw_setassocsta_cmdrsp_callback(struct adapter *padapter,  struct cmd_obj *pcmd)
2015 {
2016 	struct sta_priv *pstapriv = &padapter->stapriv;
2017 	struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
2018 	struct set_assocsta_parm *passocsta_parm = (struct set_assocsta_parm *)(pcmd->parmbuf);
2019 	struct set_assocsta_rsp *passocsta_rsp = (struct set_assocsta_rsp *)(pcmd->rsp);
2020 	struct sta_info *psta = rtw_get_stainfo(pstapriv, passocsta_parm->addr);
2021 
2022 	if (!psta)
2023 		goto exit;
2024 
2025 	psta->aid = passocsta_rsp->cam_id;
2026 	psta->mac_id = passocsta_rsp->cam_id;
2027 
2028 	spin_lock_bh(&pmlmepriv->lock);
2029 
2030 	if (check_fwstate(pmlmepriv, WIFI_MP_STATE) && check_fwstate(pmlmepriv, _FW_UNDER_LINKING))
2031 		_clr_fwstate_(pmlmepriv, _FW_UNDER_LINKING);
2032 
2033 	set_fwstate(pmlmepriv, _FW_LINKED);
2034 	spin_unlock_bh(&pmlmepriv->lock);
2035 
2036 exit:
2037 	rtw_free_cmd_obj(pcmd);
2038 }
2039