libertas: convert 802_11_SCAN to a direct command
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / drivers / net / wireless / libertas / scan.c
CommitLineData
876c9d3a
MT
1/**
2 * Functions implementing wlan scan IOCTL and firmware command APIs
3 *
4 * IOCTL handlers as well as command preperation and response routines
5 * for sending scan commands to the firmware.
6 */
7#include <linux/ctype.h>
8#include <linux/if.h>
9#include <linux/netdevice.h>
10#include <linux/wireless.h>
fcdb53db 11#include <linux/etherdevice.h>
876c9d3a
MT
12
13#include <net/ieee80211.h>
14#include <net/iw_handler.h>
15
ac630c2b
VD
16#include <asm/unaligned.h>
17
876c9d3a
MT
18#include "host.h"
19#include "decl.h"
20#include "dev.h"
21#include "scan.h"
8c512765 22#include "join.h"
fa62f99c 23#include "cmd.h"
876c9d3a
MT
24
25//! Approximate amount of data needed to pass a scan result back to iwlist
26#define MAX_SCAN_CELL_SIZE (IW_EV_ADDR_LEN \
27 + IW_ESSID_MAX_SIZE \
28 + IW_EV_UINT_LEN \
29 + IW_EV_FREQ_LEN \
30 + IW_EV_QUAL_LEN \
31 + IW_ESSID_MAX_SIZE \
32 + IW_EV_PARAM_LEN \
33 + 40) /* 40 for WPAIE */
34
35//! Memory needed to store a max sized channel List TLV for a firmware scan
36#define CHAN_TLV_MAX_SIZE (sizeof(struct mrvlietypesheader) \
37 + (MRVDRV_MAX_CHANNELS_PER_SCAN \
38 * sizeof(struct chanscanparamset)))
39
40//! Memory needed to store a max number/size SSID TLV for a firmware scan
41#define SSID_TLV_MAX_SIZE (1 * sizeof(struct mrvlietypes_ssidparamset))
42
fa62f99c
DW
43//! Maximum memory needed for a cmd_ds_802_11_scan with all TLVs at max
44#define MAX_SCAN_CFG_ALLOC (sizeof(struct cmd_ds_802_11_scan) \
45 + CHAN_TLV_MAX_SIZE + SSID_TLV_MAX_SIZE)
876c9d3a
MT
46
47//! The maximum number of channels the firmware can scan per command
48#define MRVDRV_MAX_CHANNELS_PER_SCAN 14
49
50/**
51 * @brief Number of channels to scan per firmware scan command issuance.
52 *
53 * Number restricted to prevent hitting the limit on the amount of scan data
54 * returned in a single firmware scan command.
55 */
56#define MRVDRV_CHANNELS_PER_SCAN_CMD 4
57
58//! Scan time specified in the channel TLV for each channel for passive scans
59#define MRVDRV_PASSIVE_SCAN_CHAN_TIME 100
60
61//! Scan time specified in the channel TLV for each channel for active scans
62#define MRVDRV_ACTIVE_SCAN_CHAN_TIME 100
63
123e0e04
DW
64static const u8 zeromac[ETH_ALEN] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 };
65static const u8 bcastmac[ETH_ALEN] = { 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF };
eb8f7330 66
fa62f99c
DW
67static int lbs_ret_80211_scan(struct lbs_private *priv, unsigned long dummy,
68 struct cmd_header *resp);
e56188ac
HS
69
70/*********************************************************************/
71/* */
72/* Misc helper functions */
73/* */
74/*********************************************************************/
75
23ff5036
HS
76/**
77 * @brief Unsets the MSB on basic rates
78 *
79 * Scan through an array and unset the MSB for basic data rates.
80 *
81 * @param rates buffer of data rates
82 * @param len size of buffer
83 */
84static void lbs_unset_basic_rate_flags(u8 *rates, size_t len)
85{
86 int i;
87
88 for (i = 0; i < len; i++)
89 rates[i] &= 0x7f;
90}
91
92
fcdb53db
DW
93static inline void clear_bss_descriptor (struct bss_descriptor * bss)
94{
95 /* Don't blow away ->list, just BSS data */
96 memset(bss, 0, offsetof(struct bss_descriptor, list));
97}
98
ffd074fc
HS
99/**
100 * @brief Compare two SSIDs
101 *
102 * @param ssid1 A pointer to ssid to compare
103 * @param ssid2 A pointer to ssid to compare
104 *
105 * @return 0: ssid is same, otherwise is different
106 */
107int lbs_ssid_cmp(u8 *ssid1, u8 ssid1_len, u8 *ssid2, u8 ssid2_len)
108{
109 if (ssid1_len != ssid2_len)
110 return -1;
111
112 return memcmp(ssid1, ssid2, ssid1_len);
113}
114
10078321 115static inline int match_bss_no_security(struct lbs_802_11_security *secinfo,
fcdb53db
DW
116 struct bss_descriptor * match_bss)
117{
118 if ( !secinfo->wep_enabled
119 && !secinfo->WPAenabled
120 && !secinfo->WPA2enabled
ab617971
DW
121 && match_bss->wpa_ie[0] != MFIE_TYPE_GENERIC
122 && match_bss->rsn_ie[0] != MFIE_TYPE_RSN
0c9ca690 123 && !(match_bss->capability & WLAN_CAPABILITY_PRIVACY)) {
fcdb53db
DW
124 return 1;
125 }
126 return 0;
127}
128
10078321 129static inline int match_bss_static_wep(struct lbs_802_11_security *secinfo,
fcdb53db
DW
130 struct bss_descriptor * match_bss)
131{
132 if ( secinfo->wep_enabled
133 && !secinfo->WPAenabled
134 && !secinfo->WPA2enabled
0c9ca690 135 && (match_bss->capability & WLAN_CAPABILITY_PRIVACY)) {
fcdb53db
DW
136 return 1;
137 }
138 return 0;
139}
140
10078321 141static inline int match_bss_wpa(struct lbs_802_11_security *secinfo,
fcdb53db
DW
142 struct bss_descriptor * match_bss)
143{
144 if ( !secinfo->wep_enabled
145 && secinfo->WPAenabled
ab617971 146 && (match_bss->wpa_ie[0] == MFIE_TYPE_GENERIC)
fcdb53db 147 /* privacy bit may NOT be set in some APs like LinkSys WRT54G
0c9ca690
DW
148 && (match_bss->capability & WLAN_CAPABILITY_PRIVACY)) {
149 */
fcdb53db
DW
150 ) {
151 return 1;
152 }
153 return 0;
154}
155
10078321 156static inline int match_bss_wpa2(struct lbs_802_11_security *secinfo,
fcdb53db
DW
157 struct bss_descriptor * match_bss)
158{
159 if ( !secinfo->wep_enabled
fcdb53db 160 && secinfo->WPA2enabled
ab617971 161 && (match_bss->rsn_ie[0] == MFIE_TYPE_RSN)
fcdb53db 162 /* privacy bit may NOT be set in some APs like LinkSys WRT54G
0c9ca690
DW
163 && (match_bss->capability & WLAN_CAPABILITY_PRIVACY)) {
164 */
fcdb53db
DW
165 ) {
166 return 1;
167 }
168 return 0;
169}
170
10078321 171static inline int match_bss_dynamic_wep(struct lbs_802_11_security *secinfo,
fcdb53db
DW
172 struct bss_descriptor * match_bss)
173{
174 if ( !secinfo->wep_enabled
175 && !secinfo->WPAenabled
176 && !secinfo->WPA2enabled
ab617971
DW
177 && (match_bss->wpa_ie[0] != MFIE_TYPE_GENERIC)
178 && (match_bss->rsn_ie[0] != MFIE_TYPE_RSN)
0c9ca690 179 && (match_bss->capability & WLAN_CAPABILITY_PRIVACY)) {
fcdb53db
DW
180 return 1;
181 }
182 return 0;
183}
876c9d3a 184
ffd074fc
HS
185static inline int is_same_network(struct bss_descriptor *src,
186 struct bss_descriptor *dst)
187{
188 /* A network is only a duplicate if the channel, BSSID, and ESSID
189 * all match. We treat all <hidden> with the same BSSID and channel
190 * as one network */
191 return ((src->ssid_len == dst->ssid_len) &&
192 (src->channel == dst->channel) &&
193 !compare_ether_addr(src->bssid, dst->bssid) &&
194 !memcmp(src->ssid, dst->ssid, src->ssid_len));
195}
196
876c9d3a
MT
197/**
198 * @brief Check if a scanned network compatible with the driver settings
199 *
200 * WEP WPA WPA2 ad-hoc encrypt Network
201 * enabled enabled enabled AES mode privacy WPA WPA2 Compatible
202 * 0 0 0 0 NONE 0 0 0 yes No security
203 * 1 0 0 0 NONE 1 0 0 yes Static WEP
204 * 0 1 0 0 x 1x 1 x yes WPA
205 * 0 0 1 0 x 1x x 1 yes WPA2
206 * 0 0 0 1 NONE 1 0 0 yes Ad-hoc AES
207 * 0 0 0 0 !=NONE 1 0 0 yes Dynamic WEP
208 *
209 *
aa21c004 210 * @param priv A pointer to struct lbs_private
876c9d3a
MT
211 * @param index Index in scantable to check against current driver settings
212 * @param mode Network mode: Infrastructure or IBSS
213 *
214 * @return Index in scantable, or error code if negative
215 */
aa21c004 216static int is_network_compatible(struct lbs_private *priv,
fcdb53db 217 struct bss_descriptor * bss, u8 mode)
876c9d3a 218{
fcdb53db
DW
219 int matched = 0;
220
e56188ac 221 lbs_deb_enter(LBS_DEB_SCAN);
876c9d3a 222
fcdb53db
DW
223 if (bss->mode != mode)
224 goto done;
876c9d3a 225
aa21c004 226 if ((matched = match_bss_no_security(&priv->secinfo, bss))) {
fcdb53db 227 goto done;
aa21c004 228 } else if ((matched = match_bss_static_wep(&priv->secinfo, bss))) {
fcdb53db 229 goto done;
aa21c004 230 } else if ((matched = match_bss_wpa(&priv->secinfo, bss))) {
fcdb53db 231 lbs_deb_scan(
ffd074fc
HS
232 "is_network_compatible() WPA: wpa_ie 0x%x "
233 "wpa2_ie 0x%x WEP %s WPA %s WPA2 %s "
234 "privacy 0x%x\n", bss->wpa_ie[0], bss->rsn_ie[0],
aa21c004
DW
235 priv->secinfo.wep_enabled ? "e" : "d",
236 priv->secinfo.WPAenabled ? "e" : "d",
237 priv->secinfo.WPA2enabled ? "e" : "d",
0c9ca690 238 (bss->capability & WLAN_CAPABILITY_PRIVACY));
fcdb53db 239 goto done;
aa21c004 240 } else if ((matched = match_bss_wpa2(&priv->secinfo, bss))) {
fcdb53db 241 lbs_deb_scan(
ffd074fc
HS
242 "is_network_compatible() WPA2: wpa_ie 0x%x "
243 "wpa2_ie 0x%x WEP %s WPA %s WPA2 %s "
244 "privacy 0x%x\n", bss->wpa_ie[0], bss->rsn_ie[0],
aa21c004
DW
245 priv->secinfo.wep_enabled ? "e" : "d",
246 priv->secinfo.WPAenabled ? "e" : "d",
247 priv->secinfo.WPA2enabled ? "e" : "d",
0c9ca690 248 (bss->capability & WLAN_CAPABILITY_PRIVACY));
fcdb53db 249 goto done;
aa21c004 250 } else if ((matched = match_bss_dynamic_wep(&priv->secinfo, bss))) {
fcdb53db
DW
251 lbs_deb_scan(
252 "is_network_compatible() dynamic WEP: "
ffd074fc 253 "wpa_ie 0x%x wpa2_ie 0x%x privacy 0x%x\n",
0c9ca690
DW
254 bss->wpa_ie[0], bss->rsn_ie[0],
255 (bss->capability & WLAN_CAPABILITY_PRIVACY));
9012b28a 256 goto done;
876c9d3a
MT
257 }
258
fcdb53db
DW
259 /* bss security settings don't match those configured on card */
260 lbs_deb_scan(
ffd074fc
HS
261 "is_network_compatible() FAILED: wpa_ie 0x%x "
262 "wpa2_ie 0x%x WEP %s WPA %s WPA2 %s privacy 0x%x\n",
fcdb53db 263 bss->wpa_ie[0], bss->rsn_ie[0],
aa21c004
DW
264 priv->secinfo.wep_enabled ? "e" : "d",
265 priv->secinfo.WPAenabled ? "e" : "d",
266 priv->secinfo.WPA2enabled ? "e" : "d",
0c9ca690 267 (bss->capability & WLAN_CAPABILITY_PRIVACY));
9012b28a
HS
268
269done:
e56188ac 270 lbs_deb_leave_args(LBS_DEB_SCAN, "matched: %d", matched);
fcdb53db 271 return matched;
876c9d3a
MT
272}
273
e56188ac
HS
274
275
276
277/*********************************************************************/
278/* */
279/* Main scanning support */
280/* */
281/*********************************************************************/
282
ffd074fc
HS
283void lbs_scan_worker(struct work_struct *work)
284{
285 struct lbs_private *priv =
286 container_of(work, struct lbs_private, scan_work.work);
287
288 lbs_deb_enter(LBS_DEB_SCAN);
289 lbs_scan_networks(priv, NULL, 0);
290 lbs_deb_leave(LBS_DEB_SCAN);
291}
292
e56188ac 293
876c9d3a
MT
294/**
295 * @brief Create a channel list for the driver to scan based on region info
296 *
10078321 297 * Only used from lbs_scan_setup_scan_config()
e56188ac 298 *
876c9d3a
MT
299 * Use the driver region/band information to construct a comprehensive list
300 * of channels to scan. This routine is used for any scan that is not
301 * provided a specific channel list to scan.
302 *
69f9032d 303 * @param priv A pointer to struct lbs_private structure
876c9d3a
MT
304 * @param scanchanlist Output parameter: resulting channel list to scan
305 * @param filteredscan Flag indicating whether or not a BSSID or SSID filter
306 * is being sent in the command to firmware. Used to
307 * increase the number of channels sent in a scan
308 * command and to disable the firmware channel scan
309 * filter.
310 *
311 * @return void
312 */
ffd074fc 313static int lbs_scan_create_channel_list(struct lbs_private *priv,
876c9d3a
MT
314 struct chanscanparamset * scanchanlist,
315 u8 filteredscan)
316{
317
876c9d3a
MT
318 struct region_channel *scanregion;
319 struct chan_freq_power *cfp;
320 int rgnidx;
321 int chanidx;
322 int nextchan;
323 u8 scantype;
324
325 chanidx = 0;
326
327 /* Set the default scan type to the user specified type, will later
328 * be changed to passive on a per channel basis if restricted by
329 * regulatory requirements (11d or 11h)
330 */
4f2fdaaf 331 scantype = CMD_SCAN_TYPE_ACTIVE;
876c9d3a 332
aa21c004
DW
333 for (rgnidx = 0; rgnidx < ARRAY_SIZE(priv->region_channel); rgnidx++) {
334 if (priv->enable11d &&
335 (priv->connect_status != LBS_CONNECTED) &&
336 (priv->mesh_connect_status != LBS_CONNECTED)) {
876c9d3a 337 /* Scan all the supported chan for the first scan */
aa21c004 338 if (!priv->universal_channel[rgnidx].valid)
876c9d3a 339 continue;
aa21c004 340 scanregion = &priv->universal_channel[rgnidx];
876c9d3a
MT
341
342 /* clear the parsed_region_chan for the first scan */
aa21c004
DW
343 memset(&priv->parsed_region_chan, 0x00,
344 sizeof(priv->parsed_region_chan));
876c9d3a 345 } else {
aa21c004 346 if (!priv->region_channel[rgnidx].valid)
876c9d3a 347 continue;
aa21c004 348 scanregion = &priv->region_channel[rgnidx];
876c9d3a
MT
349 }
350
351 for (nextchan = 0;
352 nextchan < scanregion->nrcfp; nextchan++, chanidx++) {
353
354 cfp = scanregion->CFP + nextchan;
355
aa21c004 356 if (priv->enable11d) {
876c9d3a 357 scantype =
10078321 358 lbs_get_scan_type_11d(cfp->channel,
aa21c004 359 &priv->
876c9d3a
MT
360 parsed_region_chan);
361 }
362
363 switch (scanregion->band) {
364 case BAND_B:
365 case BAND_G:
366 default:
367 scanchanlist[chanidx].radiotype =
0aef64d7 368 CMD_SCAN_RADIO_TYPE_BG;
876c9d3a
MT
369 break;
370 }
371
0aef64d7 372 if (scantype == CMD_SCAN_TYPE_PASSIVE) {
876c9d3a 373 scanchanlist[chanidx].maxscantime =
981f187b 374 cpu_to_le16(MRVDRV_PASSIVE_SCAN_CHAN_TIME);
876c9d3a
MT
375 scanchanlist[chanidx].chanscanmode.passivescan =
376 1;
377 } else {
378 scanchanlist[chanidx].maxscantime =
981f187b 379 cpu_to_le16(MRVDRV_ACTIVE_SCAN_CHAN_TIME);
876c9d3a
MT
380 scanchanlist[chanidx].chanscanmode.passivescan =
381 0;
382 }
383
384 scanchanlist[chanidx].channumber = cfp->channel;
385
386 if (filteredscan) {
387 scanchanlist[chanidx].chanscanmode.
388 disablechanfilt = 1;
389 }
390 }
391 }
ffd074fc 392 return chanidx;
876c9d3a
MT
393}
394
2afc0c5d 395
ffd074fc
HS
396/*
397 * Add SSID TLV of the form:
398 *
399 * TLV-ID SSID 00 00
400 * length 06 00
401 * ssid 4d 4e 54 45 53 54
402 */
403static int lbs_scan_add_ssid_tlv(u8 *tlv,
404 const struct lbs_ioctl_user_scan_cfg *user_cfg)
2afc0c5d 405{
ffd074fc
HS
406 struct mrvlietypes_ssidparamset *ssid_tlv =
407 (struct mrvlietypes_ssidparamset *)tlv;
408 ssid_tlv->header.type = cpu_to_le16(TLV_TYPE_SSID);
409 ssid_tlv->header.len = cpu_to_le16(user_cfg->ssid_len);
410 memcpy(ssid_tlv->ssid, user_cfg->ssid, user_cfg->ssid_len);
411 return sizeof(ssid_tlv->header) + user_cfg->ssid_len;
2afc0c5d
DW
412}
413
414
ffd074fc
HS
415/*
416 * Add CHANLIST TLV of the form
876c9d3a 417 *
ffd074fc
HS
418 * TLV-ID CHANLIST 01 01
419 * length 5b 00
420 * channel 1 00 01 00 00 00 64 00
421 * radio type 00
422 * channel 01
423 * scan type 00
424 * min scan time 00 00
425 * max scan time 64 00
426 * channel 2 00 02 00 00 00 64 00
427 * channel 3 00 03 00 00 00 64 00
428 * channel 4 00 04 00 00 00 64 00
429 * channel 5 00 05 00 00 00 64 00
430 * channel 6 00 06 00 00 00 64 00
431 * channel 7 00 07 00 00 00 64 00
432 * channel 8 00 08 00 00 00 64 00
433 * channel 9 00 09 00 00 00 64 00
434 * channel 10 00 0a 00 00 00 64 00
435 * channel 11 00 0b 00 00 00 64 00
436 * channel 12 00 0c 00 00 00 64 00
437 * channel 13 00 0d 00 00 00 64 00
876c9d3a 438 *
876c9d3a 439 */
ffd074fc
HS
440static int lbs_scan_add_chanlist_tlv(u8 *tlv,
441 struct chanscanparamset *chan_list,
442 int chan_count)
876c9d3a 443{
ffd074fc
HS
444 size_t size = sizeof(struct chanscanparamset) * chan_count;
445 struct mrvlietypes_chanlistparamset *chan_tlv =
446 (struct mrvlietypes_chanlistparamset *) tlv;
447
448 chan_tlv->header.type = cpu_to_le16(TLV_TYPE_CHANLIST);
449 memcpy(chan_tlv->chanscanparam, chan_list, size);
450 chan_tlv->header.len = cpu_to_le16(size);
451 return sizeof(chan_tlv->header) + size;
876c9d3a
MT
452}
453
ffd074fc
HS
454
455/*
456 * Add RATES TLV of the form
876c9d3a 457 *
ffd074fc
HS
458 * TLV-ID RATES 01 00
459 * length 0e 00
460 * rates 82 84 8b 96 0c 12 18 24 30 48 60 6c
876c9d3a 461 *
ffd074fc
HS
462 * The rates are in lbs_bg_rates[], but for the 802.11b
463 * rates the high bit isn't set.
876c9d3a 464 */
ffd074fc 465static int lbs_scan_add_rates_tlv(u8 *tlv)
876c9d3a 466{
ffd074fc
HS
467 int i;
468 struct mrvlietypes_ratesparamset *rate_tlv =
469 (struct mrvlietypes_ratesparamset *) tlv;
470
471 rate_tlv->header.type = cpu_to_le16(TLV_TYPE_RATES);
472 tlv += sizeof(rate_tlv->header);
473 for (i = 0; i < MAX_RATES; i++) {
474 *tlv = lbs_bg_rates[i];
475 if (*tlv == 0)
476 break;
477 /* This code makes sure that the 802.11b rates (1 MBit/s, 2
478 MBit/s, 5.5 MBit/s and 11 MBit/s get's the high bit set.
479 Note that the values are MBit/s * 2, to mark them as
480 basic rates so that the firmware likes it better */
481 if (*tlv == 0x02 || *tlv == 0x04 ||
482 *tlv == 0x0b || *tlv == 0x16)
483 *tlv |= 0x80;
484 tlv++;
2afc0c5d 485 }
ffd074fc
HS
486 rate_tlv->header.len = cpu_to_le16(i);
487 return sizeof(rate_tlv->header) + i;
876c9d3a
MT
488}
489
ffd074fc 490
e56188ac 491/*
ffd074fc
HS
492 * Generate the CMD_802_11_SCAN command with the proper tlv
493 * for a bunch of channels.
494 */
fa62f99c
DW
495static int lbs_do_scan(struct lbs_private *priv, uint8_t bsstype,
496 struct chanscanparamset *chan_list, int chan_count,
497 const struct lbs_ioctl_user_scan_cfg *user_cfg)
eb8f7330 498{
ffd074fc 499 int ret = -ENOMEM;
fa62f99c
DW
500 struct cmd_ds_802_11_scan *scan_cmd;
501 uint8_t *tlv; /* pointer into our current, growing TLV storage area */
eb8f7330 502
fa62f99c
DW
503 lbs_deb_enter_args(LBS_DEB_SCAN, "bsstype %d, chanlist[].chan %d, chan_count %d",
504 bsstype, chan_list[0].channumber, chan_count);
e56188ac 505
ffd074fc
HS
506 /* create the fixed part for scan command */
507 scan_cmd = kzalloc(MAX_SCAN_CFG_ALLOC, GFP_KERNEL);
508 if (scan_cmd == NULL)
e56188ac 509 goto out;
fa62f99c 510
ffd074fc
HS
511 tlv = scan_cmd->tlvbuffer;
512 if (user_cfg)
513 memcpy(scan_cmd->bssid, user_cfg->bssid, ETH_ALEN);
514 scan_cmd->bsstype = bsstype;
515
516 /* add TLVs */
517 if (user_cfg && user_cfg->ssid_len)
518 tlv += lbs_scan_add_ssid_tlv(tlv, user_cfg);
519 if (chan_list && chan_count)
520 tlv += lbs_scan_add_chanlist_tlv(tlv, chan_list, chan_count);
521 tlv += lbs_scan_add_rates_tlv(tlv);
522
523 /* This is the final data we are about to send */
fa62f99c
DW
524 scan_cmd->hdr.size = cpu_to_le16(tlv - (uint8_t *)scan_cmd);
525 lbs_deb_hex(LBS_DEB_SCAN, "SCAN_CMD", (void *)scan_cmd,
526 sizeof(*scan_cmd));
ffd074fc 527 lbs_deb_hex(LBS_DEB_SCAN, "SCAN_TLV", scan_cmd->tlvbuffer,
fa62f99c
DW
528 tlv - scan_cmd->tlvbuffer);
529
530 ret = __lbs_cmd(priv, CMD_802_11_SCAN, &scan_cmd->hdr,
531 le16_to_cpu(scan_cmd->hdr.size),
532 lbs_ret_80211_scan, 0);
ffd074fc 533
e56188ac 534out:
ffd074fc
HS
535 kfree(scan_cmd);
536 lbs_deb_leave_args(LBS_DEB_SCAN, "ret %d", ret);
537 return ret;
eb8f7330
DW
538}
539
540
876c9d3a
MT
541/**
542 * @brief Internal function used to start a scan based on an input config
543 *
e56188ac
HS
544 * Also used from debugfs
545 *
876c9d3a
MT
546 * Use the input user scan configuration information when provided in
547 * order to send the appropriate scan commands to firmware to populate or
548 * update the internal driver scan table
549 *
69f9032d 550 * @param priv A pointer to struct lbs_private structure
876c9d3a
MT
551 * @param puserscanin Pointer to the input configuration for the requested
552 * scan.
553 *
554 * @return 0 or < 0 if error
555 */
69f9032d 556int lbs_scan_networks(struct lbs_private *priv,
ffd074fc 557 const struct lbs_ioctl_user_scan_cfg *user_cfg,
2afc0c5d 558 int full_scan)
876c9d3a 559{
ffd074fc
HS
560 int ret = -ENOMEM;
561 struct chanscanparamset *chan_list;
562 struct chanscanparamset *curr_chans;
563 int chan_count;
564 u8 bsstype = CMD_BSS_TYPE_ANY;
565 int numchannels = MRVDRV_CHANNELS_PER_SCAN_CMD;
566 int filteredscan = 0;
567 union iwreq_data wrqu;
f8f55108 568#ifdef CONFIG_LIBERTAS_DEBUG
ffd074fc 569 struct bss_descriptor *iter;
f8f55108 570 int i = 0;
0795af57 571 DECLARE_MAC_BUF(mac);
f8f55108 572#endif
876c9d3a 573
ffd074fc
HS
574 lbs_deb_enter_args(LBS_DEB_SCAN, "full_scan %d",
575 full_scan);
2afc0c5d
DW
576
577 /* Cancel any partial outstanding partial scans if this scan
578 * is a full scan.
579 */
580 if (full_scan && delayed_work_pending(&priv->scan_work))
581 cancel_delayed_work(&priv->scan_work);
876c9d3a 582
ffd074fc
HS
583 /* Determine same scan parameters */
584 if (user_cfg) {
585 if (user_cfg->bsstype)
586 bsstype = user_cfg->bsstype;
587 if (compare_ether_addr(user_cfg->bssid, &zeromac[0]) != 0) {
588 numchannels = MRVDRV_MAX_CHANNELS_PER_SCAN;
589 filteredscan = 1;
590 }
876c9d3a 591 }
ffd074fc
HS
592 lbs_deb_scan("numchannels %d, bsstype %d, "
593 "filteredscan %d\n",
594 numchannels, bsstype, filteredscan);
876c9d3a 595
ffd074fc
HS
596 /* Create list of channels to scan */
597 chan_list = kzalloc(sizeof(struct chanscanparamset) *
598 LBS_IOCTL_USER_SCAN_CHAN_MAX, GFP_KERNEL);
599 if (!chan_list) {
600 lbs_pr_alert("SCAN: chan_list empty\n");
876c9d3a
MT
601 goto out;
602 }
603
ffd074fc
HS
604 /* We want to scan all channels */
605 chan_count = lbs_scan_create_channel_list(priv, chan_list,
606 filteredscan);
876c9d3a 607
ffd074fc
HS
608 netif_stop_queue(priv->dev);
609 netif_carrier_off(priv->dev);
610 if (priv->mesh_dev) {
a27b9f96
DW
611 netif_stop_queue(priv->mesh_dev);
612 netif_carrier_off(priv->mesh_dev);
876c9d3a
MT
613 }
614
ffd074fc 615 /* Prepare to continue an interrupted scan */
8816edce
HS
616 lbs_deb_scan("chan_count %d, scan_channel %d\n",
617 chan_count, priv->scan_channel);
ffd074fc
HS
618 curr_chans = chan_list;
619 /* advance channel list by already-scanned-channels */
8816edce
HS
620 if (priv->scan_channel > 0) {
621 curr_chans += priv->scan_channel;
622 chan_count -= priv->scan_channel;
ffd074fc
HS
623 }
624
625 /* Send scan command(s)
626 * numchannels contains the number of channels we should maximally scan
627 * chan_count is the total number of channels to scan
628 */
629
630 while (chan_count) {
631 int to_scan = min(numchannels, chan_count);
632 lbs_deb_scan("scanning %d of %d channels\n",
633 to_scan, chan_count);
634 ret = lbs_do_scan(priv, bsstype, curr_chans,
635 to_scan, user_cfg);
636 if (ret) {
637 lbs_pr_err("SCAN_CMD failed\n");
638 goto out2;
639 }
640 curr_chans += to_scan;
641 chan_count -= to_scan;
642
643 /* somehow schedule the next part of the scan */
644 if (chan_count &&
645 !full_scan &&
aa21c004 646 !priv->surpriseremoved) {
ffd074fc 647 /* -1 marks just that we're currently scanning */
8816edce
HS
648 if (priv->scan_channel < 0)
649 priv->scan_channel = to_scan;
ffd074fc 650 else
8816edce 651 priv->scan_channel += to_scan;
ffd074fc
HS
652 cancel_delayed_work(&priv->scan_work);
653 queue_delayed_work(priv->work_thread, &priv->scan_work,
654 msecs_to_jiffies(300));
655 /* skip over GIWSCAN event */
656 goto out;
657 }
658
659 }
660 memset(&wrqu, 0, sizeof(union iwreq_data));
661 wireless_send_event(priv->dev, SIOCGIWSCAN, &wrqu, NULL);
876c9d3a 662
f8f55108
DW
663#ifdef CONFIG_LIBERTAS_DEBUG
664 /* Dump the scan table */
aa21c004 665 mutex_lock(&priv->lock);
ffd074fc 666 lbs_deb_scan("scan table:\n");
aa21c004 667 list_for_each_entry(iter, &priv->network_list, list)
ffd074fc
HS
668 lbs_deb_scan("%02d: BSSID %s, RSSI %d, SSID '%s'\n",
669 i++, print_mac(mac, iter->bssid), (s32) iter->rssi,
670 escape_essid(iter->ssid, iter->ssid_len));
aa21c004 671 mutex_unlock(&priv->lock);
f8f55108 672#endif
876c9d3a 673
ffd074fc 674out2:
8816edce 675 priv->scan_channel = 0;
ffd074fc
HS
676
677out:
aa21c004 678 if (priv->connect_status == LBS_CONNECTED) {
634b8f49 679 netif_carrier_on(priv->dev);
a27b9f96
DW
680 if (!priv->tx_pending_len)
681 netif_wake_queue(priv->dev);
01d77d8d 682 }
aa21c004 683 if (priv->mesh_dev && (priv->mesh_connect_status == LBS_CONNECTED)) {
01d77d8d 684 netif_carrier_on(priv->mesh_dev);
a27b9f96
DW
685 if (!priv->tx_pending_len)
686 netif_wake_queue(priv->mesh_dev);
876c9d3a 687 }
ffd074fc 688 kfree(chan_list);
876c9d3a 689
9012b28a 690 lbs_deb_leave_args(LBS_DEB_SCAN, "ret %d", ret);
876c9d3a
MT
691 return ret;
692}
693
ffd074fc
HS
694
695
696
697/*********************************************************************/
698/* */
699/* Result interpretation */
700/* */
701/*********************************************************************/
702
876c9d3a
MT
703/**
704 * @brief Interpret a BSS scan response returned from the firmware
705 *
706 * Parse the various fixed fields and IEs passed back for a a BSS probe
ffd074fc
HS
707 * response or beacon from the scan command. Record information as needed
708 * in the scan table struct bss_descriptor for that entry.
876c9d3a 709 *
fcdb53db 710 * @param bss Output parameter: Pointer to the BSS Entry
876c9d3a
MT
711 *
712 * @return 0 or -1
713 */
10078321 714static int lbs_process_bss(struct bss_descriptor *bss,
fcdb53db 715 u8 ** pbeaconinfo, int *bytesleft)
876c9d3a 716{
876c9d3a
MT
717 struct ieeetypes_fhparamset *pFH;
718 struct ieeetypes_dsparamset *pDS;
719 struct ieeetypes_cfparamset *pCF;
720 struct ieeetypes_ibssparamset *pibss;
0795af57 721 DECLARE_MAC_BUF(mac);
876c9d3a 722 struct ieeetypes_countryinfoset *pcountryinfo;
8c512765
DW
723 u8 *pos, *end, *p;
724 u8 n_ex_rates = 0, got_basic_rates = 0, n_basic_rates = 0;
725 u16 beaconsize = 0;
726 int ret;
876c9d3a 727
e56188ac 728 lbs_deb_enter(LBS_DEB_SCAN);
876c9d3a 729
876c9d3a
MT
730 if (*bytesleft >= sizeof(beaconsize)) {
731 /* Extract & convert beacon size from the command buffer */
e7240aca 732 beaconsize = le16_to_cpu(get_unaligned((__le16 *)*pbeaconinfo));
876c9d3a
MT
733 *bytesleft -= sizeof(beaconsize);
734 *pbeaconinfo += sizeof(beaconsize);
735 }
736
737 if (beaconsize == 0 || beaconsize > *bytesleft) {
876c9d3a
MT
738 *pbeaconinfo += *bytesleft;
739 *bytesleft = 0;
e56188ac
HS
740 ret = -1;
741 goto done;
876c9d3a
MT
742 }
743
744 /* Initialize the current working beacon pointer for this BSS iteration */
ab617971
DW
745 pos = *pbeaconinfo;
746 end = pos + beaconsize;
876c9d3a
MT
747
748 /* Advance the return beacon pointer past the current beacon */
749 *pbeaconinfo += beaconsize;
750 *bytesleft -= beaconsize;
751
ab617971 752 memcpy(bss->bssid, pos, ETH_ALEN);
ffd074fc 753 lbs_deb_scan("process_bss: BSSID %s\n", print_mac(mac, bss->bssid));
ab617971 754 pos += ETH_ALEN;
876c9d3a 755
ab617971 756 if ((end - pos) < 12) {
fcdb53db 757 lbs_deb_scan("process_bss: Not enough bytes left\n");
e56188ac
HS
758 ret = -1;
759 goto done;
876c9d3a
MT
760 }
761
762 /*
763 * next 4 fields are RSSI, time stamp, beacon interval,
764 * and capability information
765 */
766
767 /* RSSI is 1 byte long */
ab617971 768 bss->rssi = *pos;
ffd074fc 769 lbs_deb_scan("process_bss: RSSI %d\n", *pos);
ab617971 770 pos++;
876c9d3a
MT
771
772 /* time stamp is 8 bytes long */
ab617971 773 pos += 8;
876c9d3a
MT
774
775 /* beacon interval is 2 bytes long */
ab617971
DW
776 bss->beaconperiod = le16_to_cpup((void *) pos);
777 pos += 2;
876c9d3a
MT
778
779 /* capability information is 2 bytes long */
ab617971 780 bss->capability = le16_to_cpup((void *) pos);
ffd074fc 781 lbs_deb_scan("process_bss: capabilities 0x%04x\n", bss->capability);
ab617971 782 pos += 2;
876c9d3a 783
0c9ca690 784 if (bss->capability & WLAN_CAPABILITY_PRIVACY)
ffd074fc 785 lbs_deb_scan("process_bss: WEP enabled\n");
0c9ca690
DW
786 if (bss->capability & WLAN_CAPABILITY_IBSS)
787 bss->mode = IW_MODE_ADHOC;
788 else
789 bss->mode = IW_MODE_INFRA;
790
876c9d3a 791 /* rest of the current buffer are IE's */
ffd074fc 792 lbs_deb_scan("process_bss: IE len %zd\n", end - pos);
ece56191 793 lbs_deb_hex(LBS_DEB_SCAN, "process_bss: IE info", pos, end - pos);
876c9d3a 794
876c9d3a 795 /* process variable IE */
ab617971
DW
796 while (pos <= end - 2) {
797 struct ieee80211_info_element * elem =
798 (struct ieee80211_info_element *) pos;
876c9d3a 799
ab617971 800 if (pos + elem->len > end) {
fcdb53db 801 lbs_deb_scan("process_bss: error in processing IE, "
876c9d3a 802 "bytes left < IE length\n");
ab617971 803 break;
876c9d3a
MT
804 }
805
ab617971
DW
806 switch (elem->id) {
807 case MFIE_TYPE_SSID:
808 bss->ssid_len = elem->len;
809 memcpy(bss->ssid, elem->data, elem->len);
ffd074fc 810 lbs_deb_scan("got SSID IE: '%s', len %u\n",
d8efea25
DW
811 escape_essid(bss->ssid, bss->ssid_len),
812 bss->ssid_len);
876c9d3a
MT
813 break;
814
ab617971 815 case MFIE_TYPE_RATES:
8c512765
DW
816 n_basic_rates = min_t(u8, MAX_RATES, elem->len);
817 memcpy(bss->rates, elem->data, n_basic_rates);
818 got_basic_rates = 1;
ffd074fc 819 lbs_deb_scan("got RATES IE\n");
876c9d3a
MT
820 break;
821
ab617971
DW
822 case MFIE_TYPE_FH_SET:
823 pFH = (struct ieeetypes_fhparamset *) pos;
fcdb53db 824 memmove(&bss->phyparamset.fhparamset, pFH,
876c9d3a 825 sizeof(struct ieeetypes_fhparamset));
ffd074fc 826 lbs_deb_scan("got FH IE\n");
876c9d3a
MT
827 break;
828
ab617971
DW
829 case MFIE_TYPE_DS_SET:
830 pDS = (struct ieeetypes_dsparamset *) pos;
fcdb53db
DW
831 bss->channel = pDS->currentchan;
832 memcpy(&bss->phyparamset.dsparamset, pDS,
876c9d3a 833 sizeof(struct ieeetypes_dsparamset));
ffd074fc 834 lbs_deb_scan("got DS IE, channel %d\n", bss->channel);
876c9d3a
MT
835 break;
836
ab617971
DW
837 case MFIE_TYPE_CF_SET:
838 pCF = (struct ieeetypes_cfparamset *) pos;
fcdb53db 839 memcpy(&bss->ssparamset.cfparamset, pCF,
876c9d3a 840 sizeof(struct ieeetypes_cfparamset));
ffd074fc 841 lbs_deb_scan("got CF IE\n");
876c9d3a
MT
842 break;
843
ab617971
DW
844 case MFIE_TYPE_IBSS_SET:
845 pibss = (struct ieeetypes_ibssparamset *) pos;
e7240aca 846 bss->atimwindow = le16_to_cpu(pibss->atimwindow);
fcdb53db 847 memmove(&bss->ssparamset.ibssparamset, pibss,
876c9d3a 848 sizeof(struct ieeetypes_ibssparamset));
ffd074fc 849 lbs_deb_scan("got IBSS IE\n");
876c9d3a
MT
850 break;
851
ab617971
DW
852 case MFIE_TYPE_COUNTRY:
853 pcountryinfo = (struct ieeetypes_countryinfoset *) pos;
ffd074fc 854 lbs_deb_scan("got COUNTRY IE\n");
fcdb53db 855 if (pcountryinfo->len < sizeof(pcountryinfo->countrycode)
876c9d3a 856 || pcountryinfo->len > 254) {
fcdb53db 857 lbs_deb_scan("process_bss: 11D- Err "
ffd074fc 858 "CountryInfo len %d, min %zd, max 254\n",
876c9d3a
MT
859 pcountryinfo->len,
860 sizeof(pcountryinfo->countrycode));
9012b28a
HS
861 ret = -1;
862 goto done;
876c9d3a
MT
863 }
864
fcdb53db 865 memcpy(&bss->countryinfo,
876c9d3a 866 pcountryinfo, pcountryinfo->len + 2);
ece56191 867 lbs_deb_hex(LBS_DEB_SCAN, "process_bss: 11d countryinfo",
876c9d3a
MT
868 (u8 *) pcountryinfo,
869 (u32) (pcountryinfo->len + 2));
870 break;
871
ab617971
DW
872 case MFIE_TYPE_RATES_EX:
873 /* only process extended supported rate if data rate is
874 * already found. Data rate IE should come before
876c9d3a
MT
875 * extended supported rate IE
876 */
ffd074fc
HS
877 lbs_deb_scan("got RATESEX IE\n");
878 if (!got_basic_rates) {
879 lbs_deb_scan("... but ignoring it\n");
ab617971 880 break;
ffd074fc 881 }
876c9d3a 882
8c512765
DW
883 n_ex_rates = elem->len;
884 if (n_basic_rates + n_ex_rates > MAX_RATES)
885 n_ex_rates = MAX_RATES - n_basic_rates;
876c9d3a 886
8c512765
DW
887 p = bss->rates + n_basic_rates;
888 memcpy(p, elem->data, n_ex_rates);
876c9d3a 889 break;
ab617971
DW
890
891 case MFIE_TYPE_GENERIC:
892 if (elem->len >= 4 &&
893 elem->data[0] == 0x00 &&
894 elem->data[1] == 0x50 &&
895 elem->data[2] == 0xf2 &&
896 elem->data[3] == 0x01) {
897 bss->wpa_ie_len = min(elem->len + 2,
898 MAX_WPA_IE_LEN);
899 memcpy(bss->wpa_ie, elem, bss->wpa_ie_len);
ffd074fc
HS
900 lbs_deb_scan("got WPA IE\n");
901 lbs_deb_hex(LBS_DEB_SCAN, "WPA IE", bss->wpa_ie,
ab617971 902 elem->len);
1e838bf3
LCC
903 } else if (elem->len >= MARVELL_MESH_IE_LENGTH &&
904 elem->data[0] == 0x00 &&
905 elem->data[1] == 0x50 &&
906 elem->data[2] == 0x43 &&
907 elem->data[3] == 0x04) {
ffd074fc 908 lbs_deb_scan("got mesh IE\n");
1e838bf3 909 bss->mesh = 1;
ffd074fc
HS
910 } else {
911 lbs_deb_scan("got generiec IE: "
912 "%02x:%02x:%02x:%02x, len %d\n",
913 elem->data[0], elem->data[1],
914 elem->data[2], elem->data[3],
915 elem->len);
ab617971 916 }
876c9d3a 917 break;
ab617971
DW
918
919 case MFIE_TYPE_RSN:
ffd074fc 920 lbs_deb_scan("got RSN IE\n");
ab617971
DW
921 bss->rsn_ie_len = min(elem->len + 2, MAX_WPA_IE_LEN);
922 memcpy(bss->rsn_ie, elem, bss->rsn_ie_len);
ffd074fc
HS
923 lbs_deb_hex(LBS_DEB_SCAN, "process_bss: RSN_IE",
924 bss->rsn_ie, elem->len);
876c9d3a
MT
925 break;
926
ab617971 927 default:
ffd074fc
HS
928 lbs_deb_scan("got IE 0x%04x, len %d\n",
929 elem->id, elem->len);
876c9d3a
MT
930 break;
931 }
932
ab617971
DW
933 pos += elem->len + 2;
934 }
fcdb53db
DW
935
936 /* Timestamp */
937 bss->last_scanned = jiffies;
10078321 938 lbs_unset_basic_rate_flags(bss->rates, sizeof(bss->rates));
fcdb53db 939
9012b28a 940 ret = 0;
876c9d3a 941
9012b28a
HS
942done:
943 lbs_deb_leave_args(LBS_DEB_SCAN, "ret %d", ret);
944 return ret;
876c9d3a
MT
945}
946
876c9d3a
MT
947/**
948 * @brief This function finds a specific compatible BSSID in the scan list
949 *
e56188ac
HS
950 * Used in association code
951 *
aa21c004 952 * @param priv A pointer to struct lbs_private
876c9d3a
MT
953 * @param bssid BSSID to find in the scan list
954 * @param mode Network mode: Infrastructure or IBSS
955 *
956 * @return index in BSSID list, or error return code (< 0)
957 */
aa21c004 958struct bss_descriptor *lbs_find_bssid_in_list(struct lbs_private *priv,
fcdb53db 959 u8 * bssid, u8 mode)
876c9d3a 960{
fcdb53db
DW
961 struct bss_descriptor * iter_bss;
962 struct bss_descriptor * found_bss = NULL;
876c9d3a 963
e56188ac
HS
964 lbs_deb_enter(LBS_DEB_SCAN);
965
876c9d3a 966 if (!bssid)
e56188ac 967 goto out;
876c9d3a 968
ece56191 969 lbs_deb_hex(LBS_DEB_SCAN, "looking for",
fcdb53db 970 bssid, ETH_ALEN);
876c9d3a 971
fcdb53db
DW
972 /* Look through the scan table for a compatible match. The loop will
973 * continue past a matched bssid that is not compatible in case there
974 * is an AP with multiple SSIDs assigned to the same BSSID
876c9d3a 975 */
aa21c004
DW
976 mutex_lock(&priv->lock);
977 list_for_each_entry (iter_bss, &priv->network_list, list) {
3cf20931 978 if (compare_ether_addr(iter_bss->bssid, bssid))
fcdb53db
DW
979 continue; /* bssid doesn't match */
980 switch (mode) {
981 case IW_MODE_INFRA:
982 case IW_MODE_ADHOC:
aa21c004 983 if (!is_network_compatible(priv, iter_bss, mode))
876c9d3a 984 break;
fcdb53db
DW
985 found_bss = iter_bss;
986 break;
987 default:
988 found_bss = iter_bss;
989 break;
876c9d3a
MT
990 }
991 }
aa21c004 992 mutex_unlock(&priv->lock);
876c9d3a 993
e56188ac
HS
994out:
995 lbs_deb_leave_args(LBS_DEB_SCAN, "found_bss %p", found_bss);
fcdb53db 996 return found_bss;
876c9d3a
MT
997}
998
999/**
1000 * @brief This function finds ssid in ssid list.
1001 *
e56188ac
HS
1002 * Used in association code
1003 *
aa21c004 1004 * @param priv A pointer to struct lbs_private
876c9d3a
MT
1005 * @param ssid SSID to find in the list
1006 * @param bssid BSSID to qualify the SSID selection (if provided)
1007 * @param mode Network mode: Infrastructure or IBSS
1008 *
1009 * @return index in BSSID list
1010 */
aa21c004 1011struct bss_descriptor *lbs_find_ssid_in_list(struct lbs_private *priv,
d8efea25 1012 u8 *ssid, u8 ssid_len, u8 * bssid, u8 mode,
aeea0ab4 1013 int channel)
876c9d3a 1014{
876c9d3a 1015 u8 bestrssi = 0;
fcdb53db
DW
1016 struct bss_descriptor * iter_bss = NULL;
1017 struct bss_descriptor * found_bss = NULL;
1018 struct bss_descriptor * tmp_oldest = NULL;
876c9d3a 1019
e56188ac
HS
1020 lbs_deb_enter(LBS_DEB_SCAN);
1021
aa21c004 1022 mutex_lock(&priv->lock);
fcdb53db 1023
aa21c004 1024 list_for_each_entry (iter_bss, &priv->network_list, list) {
fcdb53db
DW
1025 if ( !tmp_oldest
1026 || (iter_bss->last_scanned < tmp_oldest->last_scanned))
1027 tmp_oldest = iter_bss;
1028
10078321 1029 if (lbs_ssid_cmp(iter_bss->ssid, iter_bss->ssid_len,
d8efea25 1030 ssid, ssid_len) != 0)
fcdb53db 1031 continue; /* ssid doesn't match */
3cf20931 1032 if (bssid && compare_ether_addr(iter_bss->bssid, bssid) != 0)
fcdb53db 1033 continue; /* bssid doesn't match */
aeea0ab4
DW
1034 if ((channel > 0) && (iter_bss->channel != channel))
1035 continue; /* channel doesn't match */
fcdb53db
DW
1036
1037 switch (mode) {
1038 case IW_MODE_INFRA:
1039 case IW_MODE_ADHOC:
aa21c004 1040 if (!is_network_compatible(priv, iter_bss, mode))
876c9d3a 1041 break;
fcdb53db
DW
1042
1043 if (bssid) {
1044 /* Found requested BSSID */
1045 found_bss = iter_bss;
1046 goto out;
1047 }
1048
1049 if (SCAN_RSSI(iter_bss->rssi) > bestrssi) {
1050 bestrssi = SCAN_RSSI(iter_bss->rssi);
1051 found_bss = iter_bss;
1052 }
1053 break;
1054 case IW_MODE_AUTO:
1055 default:
1056 if (SCAN_RSSI(iter_bss->rssi) > bestrssi) {
1057 bestrssi = SCAN_RSSI(iter_bss->rssi);
1058 found_bss = iter_bss;
876c9d3a 1059 }
fcdb53db 1060 break;
876c9d3a
MT
1061 }
1062 }
1063
fcdb53db 1064out:
aa21c004 1065 mutex_unlock(&priv->lock);
e56188ac 1066 lbs_deb_leave_args(LBS_DEB_SCAN, "found_bss %p", found_bss);
fcdb53db 1067 return found_bss;
876c9d3a
MT
1068}
1069
1070/**
1071 * @brief This function finds the best SSID in the Scan List
1072 *
1073 * Search the scan table for the best SSID that also matches the current
1074 * adapter network preference (infrastructure or adhoc)
1075 *
aa21c004 1076 * @param priv A pointer to struct lbs_private
876c9d3a
MT
1077 *
1078 * @return index in BSSID list
1079 */
69f9032d 1080static struct bss_descriptor *lbs_find_best_ssid_in_list(
aa21c004 1081 struct lbs_private *priv,
69f9032d 1082 u8 mode)
876c9d3a 1083{
876c9d3a 1084 u8 bestrssi = 0;
fcdb53db
DW
1085 struct bss_descriptor * iter_bss;
1086 struct bss_descriptor * best_bss = NULL;
876c9d3a 1087
e56188ac
HS
1088 lbs_deb_enter(LBS_DEB_SCAN);
1089
aa21c004 1090 mutex_lock(&priv->lock);
876c9d3a 1091
aa21c004 1092 list_for_each_entry (iter_bss, &priv->network_list, list) {
876c9d3a 1093 switch (mode) {
0dc5a290
DW
1094 case IW_MODE_INFRA:
1095 case IW_MODE_ADHOC:
aa21c004 1096 if (!is_network_compatible(priv, iter_bss, mode))
fcdb53db
DW
1097 break;
1098 if (SCAN_RSSI(iter_bss->rssi) <= bestrssi)
1099 break;
1100 bestrssi = SCAN_RSSI(iter_bss->rssi);
1101 best_bss = iter_bss;
876c9d3a 1102 break;
0dc5a290 1103 case IW_MODE_AUTO:
876c9d3a 1104 default:
fcdb53db
DW
1105 if (SCAN_RSSI(iter_bss->rssi) <= bestrssi)
1106 break;
1107 bestrssi = SCAN_RSSI(iter_bss->rssi);
1108 best_bss = iter_bss;
876c9d3a
MT
1109 break;
1110 }
1111 }
1112
aa21c004 1113 mutex_unlock(&priv->lock);
e56188ac 1114 lbs_deb_leave_args(LBS_DEB_SCAN, "best_bss %p", best_bss);
fcdb53db 1115 return best_bss;
876c9d3a
MT
1116}
1117
1118/**
1119 * @brief Find the AP with specific ssid in the scan list
1120 *
e56188ac
HS
1121 * Used from association worker.
1122 *
69f9032d 1123 * @param priv A pointer to struct lbs_private structure
876c9d3a
MT
1124 * @param pSSID A pointer to AP's ssid
1125 *
1126 * @return 0--success, otherwise--fail
1127 */
69f9032d 1128int lbs_find_best_network_ssid(struct lbs_private *priv,
d8efea25 1129 u8 *out_ssid, u8 *out_ssid_len, u8 preferred_mode, u8 *out_mode)
876c9d3a 1130{
fcdb53db
DW
1131 int ret = -1;
1132 struct bss_descriptor * found;
876c9d3a 1133
e56188ac 1134 lbs_deb_enter(LBS_DEB_SCAN);
876c9d3a 1135
10078321 1136 lbs_scan_networks(priv, NULL, 1);
aa21c004 1137 if (priv->surpriseremoved)
e56188ac 1138 goto out;
876c9d3a 1139
aa21c004 1140 found = lbs_find_best_ssid_in_list(priv, preferred_mode);
d8efea25
DW
1141 if (found && (found->ssid_len > 0)) {
1142 memcpy(out_ssid, &found->ssid, IW_ESSID_MAX_SIZE);
1143 *out_ssid_len = found->ssid_len;
fcdb53db
DW
1144 *out_mode = found->mode;
1145 ret = 0;
876c9d3a
MT
1146 }
1147
e56188ac 1148out:
9012b28a 1149 lbs_deb_leave_args(LBS_DEB_SCAN, "ret %d", ret);
876c9d3a
MT
1150 return ret;
1151}
1152
e56188ac 1153
876c9d3a
MT
1154/**
1155 * @brief Send a scan command for all available channels filtered on a spec
1156 *
e56188ac
HS
1157 * Used in association code and from debugfs
1158 *
69f9032d 1159 * @param priv A pointer to struct lbs_private structure
e56188ac
HS
1160 * @param ssid A pointer to the SSID to scan for
1161 * @param ssid_len Length of the SSID
1162 * @param clear_ssid Should existing scan results with this SSID
1163 * be cleared?
876c9d3a
MT
1164 *
1165 * @return 0-success, otherwise fail
1166 */
69f9032d 1167int lbs_send_specific_ssid_scan(struct lbs_private *priv,
d8efea25 1168 u8 *ssid, u8 ssid_len, u8 clear_ssid)
876c9d3a 1169{
10078321 1170 struct lbs_ioctl_user_scan_cfg scancfg;
eb8f7330 1171 int ret = 0;
876c9d3a 1172
e56188ac
HS
1173 lbs_deb_enter_args(LBS_DEB_SCAN, "SSID '%s', clear %d",
1174 escape_essid(ssid, ssid_len), clear_ssid);
876c9d3a 1175
d8efea25 1176 if (!ssid_len)
eb8f7330 1177 goto out;
876c9d3a
MT
1178
1179 memset(&scancfg, 0x00, sizeof(scancfg));
d8efea25
DW
1180 memcpy(scancfg.ssid, ssid, ssid_len);
1181 scancfg.ssid_len = ssid_len;
eb8f7330 1182 scancfg.clear_ssid = clear_ssid;
876c9d3a 1183
10078321 1184 lbs_scan_networks(priv, &scancfg, 1);
aa21c004 1185 if (priv->surpriseremoved) {
e56188ac
HS
1186 ret = -1;
1187 goto out;
1188 }
876c9d3a 1189
eb8f7330 1190out:
e56188ac 1191 lbs_deb_leave_args(LBS_DEB_SCAN, "ret %d", ret);
eb8f7330 1192 return ret;
876c9d3a
MT
1193}
1194
e56188ac
HS
1195
1196
1197
1198/*********************************************************************/
1199/* */
1200/* Support for Wireless Extensions */
1201/* */
1202/*********************************************************************/
1203
ffd074fc 1204
00af0157
DW
1205#define MAX_CUSTOM_LEN 64
1206
69f9032d 1207static inline char *lbs_translate_scan(struct lbs_private *priv,
fcdb53db
DW
1208 char *start, char *stop,
1209 struct bss_descriptor *bss)
876c9d3a 1210{
876c9d3a 1211 struct chan_freq_power *cfp;
876c9d3a
MT
1212 char *current_val; /* For rates */
1213 struct iw_event iwe; /* Temporary buffer */
876c9d3a 1214 int j;
876c9d3a
MT
1215#define PERFECT_RSSI ((u8)50)
1216#define WORST_RSSI ((u8)0)
1217#define RSSI_DIFF ((u8)(PERFECT_RSSI - WORST_RSSI))
1218 u8 rssi;
1219
e56188ac
HS
1220 lbs_deb_enter(LBS_DEB_SCAN);
1221
aa21c004 1222 cfp = lbs_find_cfp_by_band_and_channel(priv, 0, bss->channel);
fcdb53db
DW
1223 if (!cfp) {
1224 lbs_deb_scan("Invalid channel number %d\n", bss->channel);
e56188ac
HS
1225 start = NULL;
1226 goto out;
2be92196 1227 }
876c9d3a 1228
ffd074fc 1229 /* First entry *MUST* be the BSSID */
fcdb53db
DW
1230 iwe.cmd = SIOCGIWAP;
1231 iwe.u.ap_addr.sa_family = ARPHRD_ETHER;
1232 memcpy(iwe.u.ap_addr.sa_data, &bss->bssid, ETH_ALEN);
1233 start = iwe_stream_add_event(start, stop, &iwe, IW_EV_ADDR_LEN);
1234
1235 /* SSID */
1236 iwe.cmd = SIOCGIWESSID;
1237 iwe.u.data.flags = 1;
d8efea25
DW
1238 iwe.u.data.length = min((u32) bss->ssid_len, (u32) IW_ESSID_MAX_SIZE);
1239 start = iwe_stream_add_point(start, stop, &iwe, bss->ssid);
fcdb53db
DW
1240
1241 /* Mode */
1242 iwe.cmd = SIOCGIWMODE;
1243 iwe.u.mode = bss->mode;
1244 start = iwe_stream_add_event(start, stop, &iwe, IW_EV_UINT_LEN);
1245
1246 /* Frequency */
1247 iwe.cmd = SIOCGIWFREQ;
1248 iwe.u.freq.m = (long)cfp->freq * 100000;
1249 iwe.u.freq.e = 1;
1250 start = iwe_stream_add_event(start, stop, &iwe, IW_EV_FREQ_LEN);
1251
1252 /* Add quality statistics */
1253 iwe.cmd = IWEVQUAL;
1254 iwe.u.qual.updated = IW_QUAL_ALL_UPDATED;
1255 iwe.u.qual.level = SCAN_RSSI(bss->rssi);
1256
1257 rssi = iwe.u.qual.level - MRVDRV_NF_DEFAULT_SCAN_VALUE;
1258 iwe.u.qual.qual =
1259 (100 * RSSI_DIFF * RSSI_DIFF - (PERFECT_RSSI - rssi) *
1260 (15 * (RSSI_DIFF) + 62 * (PERFECT_RSSI - rssi))) /
1261 (RSSI_DIFF * RSSI_DIFF);
1262 if (iwe.u.qual.qual > 100)
1263 iwe.u.qual.qual = 100;
1264
aa21c004 1265 if (priv->NF[TYPE_BEACON][TYPE_NOAVG] == 0) {
fcdb53db
DW
1266 iwe.u.qual.noise = MRVDRV_NF_DEFAULT_SCAN_VALUE;
1267 } else {
1268 iwe.u.qual.noise =
aa21c004 1269 CAL_NF(priv->NF[TYPE_BEACON][TYPE_NOAVG]);
fcdb53db 1270 }
80e78ef7
DW
1271
1272 /* Locally created ad-hoc BSSs won't have beacons if this is the
1273 * only station in the adhoc network; so get signal strength
1274 * from receive statistics.
1275 */
aa21c004
DW
1276 if ((priv->mode == IW_MODE_ADHOC)
1277 && priv->adhoccreate
1278 && !lbs_ssid_cmp(priv->curbssparams.ssid,
1279 priv->curbssparams.ssid_len,
d8efea25 1280 bss->ssid, bss->ssid_len)) {
80e78ef7 1281 int snr, nf;
aa21c004
DW
1282 snr = priv->SNR[TYPE_RXPD][TYPE_AVG] / AVG_SCALE;
1283 nf = priv->NF[TYPE_RXPD][TYPE_AVG] / AVG_SCALE;
80e78ef7 1284 iwe.u.qual.level = CAL_RSSI(snr, nf);
fcdb53db
DW
1285 }
1286 start = iwe_stream_add_event(start, stop, &iwe, IW_EV_QUAL_LEN);
876c9d3a 1287
fcdb53db
DW
1288 /* Add encryption capability */
1289 iwe.cmd = SIOCGIWENCODE;
0c9ca690 1290 if (bss->capability & WLAN_CAPABILITY_PRIVACY) {
fcdb53db
DW
1291 iwe.u.data.flags = IW_ENCODE_ENABLED | IW_ENCODE_NOKEY;
1292 } else {
1293 iwe.u.data.flags = IW_ENCODE_DISABLED;
1294 }
1295 iwe.u.data.length = 0;
d8efea25 1296 start = iwe_stream_add_point(start, stop, &iwe, bss->ssid);
876c9d3a 1297
fcdb53db 1298 current_val = start + IW_EV_LCP_LEN;
876c9d3a 1299
fcdb53db
DW
1300 iwe.cmd = SIOCGIWRATE;
1301 iwe.u.bitrate.fixed = 0;
1302 iwe.u.bitrate.disabled = 0;
1303 iwe.u.bitrate.value = 0;
876c9d3a 1304
8c512765
DW
1305 for (j = 0; bss->rates[j] && (j < sizeof(bss->rates)); j++) {
1306 /* Bit rate given in 500 kb/s units */
1307 iwe.u.bitrate.value = bss->rates[j] * 500000;
fcdb53db
DW
1308 current_val = iwe_stream_add_value(start, current_val,
1309 stop, &iwe, IW_EV_PARAM_LEN);
1310 }
1311 if ((bss->mode == IW_MODE_ADHOC)
aa21c004
DW
1312 && !lbs_ssid_cmp(priv->curbssparams.ssid,
1313 priv->curbssparams.ssid_len,
d8efea25 1314 bss->ssid, bss->ssid_len)
aa21c004 1315 && priv->adhoccreate) {
fcdb53db
DW
1316 iwe.u.bitrate.value = 22 * 500000;
1317 current_val = iwe_stream_add_value(start, current_val,
1318 stop, &iwe, IW_EV_PARAM_LEN);
1319 }
1320 /* Check if we added any event */
1321 if((current_val - start) > IW_EV_LCP_LEN)
1322 start = current_val;
1323
1324 memset(&iwe, 0, sizeof(iwe));
1325 if (bss->wpa_ie_len) {
1326 char buf[MAX_WPA_IE_LEN];
1327 memcpy(buf, bss->wpa_ie, bss->wpa_ie_len);
1328 iwe.cmd = IWEVGENIE;
1329 iwe.u.data.length = bss->wpa_ie_len;
1330 start = iwe_stream_add_point(start, stop, &iwe, buf);
1331 }
876c9d3a 1332
fcdb53db
DW
1333 memset(&iwe, 0, sizeof(iwe));
1334 if (bss->rsn_ie_len) {
1335 char buf[MAX_WPA_IE_LEN];
1336 memcpy(buf, bss->rsn_ie, bss->rsn_ie_len);
1337 iwe.cmd = IWEVGENIE;
1338 iwe.u.data.length = bss->rsn_ie_len;
1339 start = iwe_stream_add_point(start, stop, &iwe, buf);
1340 }
876c9d3a 1341
00af0157
DW
1342 if (bss->mesh) {
1343 char custom[MAX_CUSTOM_LEN];
1344 char *p = custom;
1345
1346 iwe.cmd = IWEVCUSTOM;
1347 p += snprintf(p, MAX_CUSTOM_LEN - (p - custom),
1348 "mesh-type: olpc");
1349 iwe.u.data.length = p - custom;
1350 if (iwe.u.data.length)
1351 start = iwe_stream_add_point(start, stop, &iwe, custom);
1352 }
1353
e56188ac
HS
1354out:
1355 lbs_deb_leave_args(LBS_DEB_SCAN, "start %p", start);
fcdb53db
DW
1356 return start;
1357}
876c9d3a 1358
ffd074fc
HS
1359
1360/**
1361 * @brief Handle Scan Network ioctl
1362 *
1363 * @param dev A pointer to net_device structure
1364 * @param info A pointer to iw_request_info structure
1365 * @param vwrq A pointer to iw_param structure
1366 * @param extra A pointer to extra data buf
1367 *
1368 * @return 0 --success, otherwise fail
1369 */
1370int lbs_set_scan(struct net_device *dev, struct iw_request_info *info,
1371 struct iw_param *wrqu, char *extra)
1372{
1373 struct lbs_private *priv = dev->priv;
ffd074fc
HS
1374
1375 lbs_deb_enter(LBS_DEB_SCAN);
1376
1377 if (!netif_running(dev))
1378 return -ENETDOWN;
1379
1380 /* mac80211 does this:
1381 struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
1382 if (sdata->type != IEEE80211_IF_TYPE_xxx)
1383 return -EOPNOTSUPP;
1384
1385 if (wrqu->data.length == sizeof(struct iw_scan_req) &&
1386 wrqu->data.flags & IW_SCAN_THIS_ESSID) {
1387 req = (struct iw_scan_req *)extra;
1388 ssid = req->essid;
1389 ssid_len = req->essid_len;
1390 }
1391 */
1392
1393 if (!delayed_work_pending(&priv->scan_work))
1394 queue_delayed_work(priv->work_thread, &priv->scan_work,
1395 msecs_to_jiffies(50));
1396 /* set marker that currently a scan is taking place */
8816edce 1397 priv->scan_channel = -1;
ffd074fc 1398
aa21c004 1399 if (priv->surpriseremoved)
ffd074fc
HS
1400 return -EIO;
1401
1402 lbs_deb_leave(LBS_DEB_SCAN);
1403 return 0;
1404}
1405
1406
fcdb53db 1407/**
e56188ac 1408 * @brief Handle Retrieve scan table ioctl
fcdb53db
DW
1409 *
1410 * @param dev A pointer to net_device structure
1411 * @param info A pointer to iw_request_info structure
1412 * @param dwrq A pointer to iw_point structure
1413 * @param extra A pointer to extra data buf
1414 *
1415 * @return 0 --success, otherwise fail
1416 */
10078321 1417int lbs_get_scan(struct net_device *dev, struct iw_request_info *info,
fcdb53db
DW
1418 struct iw_point *dwrq, char *extra)
1419{
1420#define SCAN_ITEM_SIZE 128
69f9032d 1421 struct lbs_private *priv = dev->priv;
fcdb53db
DW
1422 int err = 0;
1423 char *ev = extra;
1424 char *stop = ev + dwrq->length;
1425 struct bss_descriptor * iter_bss;
1426 struct bss_descriptor * safe;
876c9d3a 1427
e56188ac 1428 lbs_deb_enter(LBS_DEB_SCAN);
876c9d3a 1429
ffd074fc 1430 /* iwlist should wait until the current scan is finished */
8816edce 1431 if (priv->scan_channel)
ffd074fc
HS
1432 return -EAGAIN;
1433
80e78ef7 1434 /* Update RSSI if current BSS is a locally created ad-hoc BSS */
aa21c004 1435 if ((priv->mode == IW_MODE_ADHOC) && priv->adhoccreate) {
10078321 1436 lbs_prepare_and_send_command(priv, CMD_802_11_RSSI, 0,
0aef64d7 1437 CMD_OPTION_WAITFORRSP, 0, NULL);
80e78ef7
DW
1438 }
1439
aa21c004
DW
1440 mutex_lock(&priv->lock);
1441 list_for_each_entry_safe (iter_bss, safe, &priv->network_list, list) {
fcdb53db
DW
1442 char * next_ev;
1443 unsigned long stale_time;
876c9d3a 1444
fcdb53db
DW
1445 if (stop - ev < SCAN_ITEM_SIZE) {
1446 err = -E2BIG;
1447 break;
876c9d3a 1448 }
876c9d3a 1449
1e838bf3
LCC
1450 /* For mesh device, list only mesh networks */
1451 if (dev == priv->mesh_dev && !iter_bss->mesh)
1452 continue;
1453
fcdb53db
DW
1454 /* Prune old an old scan result */
1455 stale_time = iter_bss->last_scanned + DEFAULT_MAX_SCAN_AGE;
1456 if (time_after(jiffies, stale_time)) {
1457 list_move_tail (&iter_bss->list,
aa21c004 1458 &priv->network_free_list);
fcdb53db
DW
1459 clear_bss_descriptor(iter_bss);
1460 continue;
876c9d3a
MT
1461 }
1462
fcdb53db 1463 /* Translate to WE format this entry */
10078321 1464 next_ev = lbs_translate_scan(priv, ev, stop, iter_bss);
fcdb53db
DW
1465 if (next_ev == NULL)
1466 continue;
1467 ev = next_ev;
876c9d3a 1468 }
aa21c004 1469 mutex_unlock(&priv->lock);
876c9d3a 1470
fcdb53db 1471 dwrq->length = (ev - extra);
876c9d3a
MT
1472 dwrq->flags = 0;
1473
e56188ac 1474 lbs_deb_leave_args(LBS_DEB_SCAN, "ret %d", err);
fcdb53db 1475 return err;
876c9d3a
MT
1476}
1477
e56188ac
HS
1478
1479
1480
1481/*********************************************************************/
1482/* */
1483/* Command execution */
1484/* */
1485/*********************************************************************/
1486
1487
876c9d3a
MT
1488/**
1489 * @brief This function handles the command response of scan
1490 *
e56188ac
HS
1491 * Called from handle_cmd_response() in cmdrespc.
1492 *
876c9d3a
MT
1493 * The response buffer for the scan command has the following
1494 * memory layout:
1495 *
1496 * .-----------------------------------------------------------.
1497 * | header (4 * sizeof(u16)): Standard command response hdr |
1498 * .-----------------------------------------------------------.
1499 * | bufsize (u16) : sizeof the BSS Description data |
1500 * .-----------------------------------------------------------.
1501 * | NumOfSet (u8) : Number of BSS Descs returned |
1502 * .-----------------------------------------------------------.
1503 * | BSSDescription data (variable, size given in bufsize) |
1504 * .-----------------------------------------------------------.
1505 * | TLV data (variable, size calculated using header->size, |
1506 * | bufsize and sizeof the fixed fields above) |
1507 * .-----------------------------------------------------------.
1508 *
69f9032d 1509 * @param priv A pointer to struct lbs_private structure
876c9d3a
MT
1510 * @param resp A pointer to cmd_ds_command
1511 *
1512 * @return 0 or -1
1513 */
fa62f99c
DW
1514static int lbs_ret_80211_scan(struct lbs_private *priv, unsigned long dummy,
1515 struct cmd_header *resp)
876c9d3a 1516{
fa62f99c 1517 struct cmd_ds_802_11_scan_rsp *scanresp = (void *)resp;
fcdb53db
DW
1518 struct bss_descriptor * iter_bss;
1519 struct bss_descriptor * safe;
fa62f99c
DW
1520 uint8_t *bssinfo;
1521 uint16_t scanrespsize;
876c9d3a 1522 int bytesleft;
876c9d3a
MT
1523 int idx;
1524 int tlvbufsize;
9012b28a 1525 int ret;
876c9d3a 1526
e56188ac 1527 lbs_deb_enter(LBS_DEB_SCAN);
876c9d3a 1528
fcdb53db 1529 /* Prune old entries from scan table */
aa21c004 1530 list_for_each_entry_safe (iter_bss, safe, &priv->network_list, list) {
fcdb53db
DW
1531 unsigned long stale_time = iter_bss->last_scanned + DEFAULT_MAX_SCAN_AGE;
1532 if (time_before(jiffies, stale_time))
1533 continue;
aa21c004 1534 list_move_tail (&iter_bss->list, &priv->network_free_list);
fcdb53db
DW
1535 clear_bss_descriptor(iter_bss);
1536 }
1537
fa62f99c
DW
1538 if (scanresp->nr_sets > MAX_NETWORK_COUNT) {
1539 lbs_deb_scan("SCAN_RESP: too many scan results (%d, max %d)\n",
1540 scanresp->nr_sets, MAX_NETWORK_COUNT);
9012b28a
HS
1541 ret = -1;
1542 goto done;
876c9d3a
MT
1543 }
1544
fa62f99c 1545 bytesleft = le16_to_cpu(scanresp->bssdescriptsize);
9012b28a 1546 lbs_deb_scan("SCAN_RESP: bssdescriptsize %d\n", bytesleft);
876c9d3a 1547
e7240aca 1548 scanrespsize = le16_to_cpu(resp->size);
fa62f99c 1549 lbs_deb_scan("SCAN_RESP: scan results %d\n", scanresp->nr_sets);
876c9d3a 1550
fa62f99c 1551 bssinfo = scanresp->bssdesc_and_tlvbuffer;
876c9d3a
MT
1552
1553 /* The size of the TLV buffer is equal to the entire command response
1554 * size (scanrespsize) minus the fixed fields (sizeof()'s), the
1555 * BSS Descriptions (bssdescriptsize as bytesLef) and the command
1556 * response header (S_DS_GEN)
1557 */
fa62f99c
DW
1558 tlvbufsize = scanrespsize - (bytesleft + sizeof(scanresp->bssdescriptsize)
1559 + sizeof(scanresp->nr_sets)
876c9d3a
MT
1560 + S_DS_GEN);
1561
876c9d3a 1562 /*
fa62f99c 1563 * Process each scan response returned (scanresp->nr_sets). Save
876c9d3a
MT
1564 * the information in the newbssentry and then insert into the
1565 * driver scan table either as an update to an existing entry
1566 * or as an addition at the end of the table
1567 */
fa62f99c 1568 for (idx = 0; idx < scanresp->nr_sets && bytesleft; idx++) {
fcdb53db 1569 struct bss_descriptor new;
fa62f99c
DW
1570 struct bss_descriptor *found = NULL;
1571 struct bss_descriptor *oldest = NULL;
0795af57 1572 DECLARE_MAC_BUF(mac);
876c9d3a
MT
1573
1574 /* Process the data fields and IEs returned for this BSS */
fcdb53db 1575 memset(&new, 0, sizeof (struct bss_descriptor));
fa62f99c 1576 if (lbs_process_bss(&new, &bssinfo, &bytesleft) != 0) {
fcdb53db
DW
1577 /* error parsing the scan response, skipped */
1578 lbs_deb_scan("SCAN_RESP: process_bss returned ERROR\n");
1579 continue;
1580 }
876c9d3a 1581
fcdb53db 1582 /* Try to find this bss in the scan table */
aa21c004 1583 list_for_each_entry (iter_bss, &priv->network_list, list) {
fcdb53db
DW
1584 if (is_same_network(iter_bss, &new)) {
1585 found = iter_bss;
1586 break;
876c9d3a
MT
1587 }
1588
fcdb53db
DW
1589 if ((oldest == NULL) ||
1590 (iter_bss->last_scanned < oldest->last_scanned))
1591 oldest = iter_bss;
1592 }
876c9d3a 1593
fcdb53db
DW
1594 if (found) {
1595 /* found, clear it */
1596 clear_bss_descriptor(found);
aa21c004 1597 } else if (!list_empty(&priv->network_free_list)) {
fcdb53db 1598 /* Pull one from the free list */
aa21c004 1599 found = list_entry(priv->network_free_list.next,
fcdb53db 1600 struct bss_descriptor, list);
aa21c004 1601 list_move_tail(&found->list, &priv->network_list);
fcdb53db
DW
1602 } else if (oldest) {
1603 /* If there are no more slots, expire the oldest */
1604 found = oldest;
1605 clear_bss_descriptor(found);
aa21c004 1606 list_move_tail(&found->list, &priv->network_list);
876c9d3a 1607 } else {
fcdb53db
DW
1608 continue;
1609 }
876c9d3a 1610
fa62f99c 1611 lbs_deb_scan("SCAN_RESP: BSSID %s\n", print_mac(mac, new.bssid));
fcdb53db 1612
fcdb53db
DW
1613 /* Copy the locally created newbssentry to the scan table */
1614 memcpy(found, &new, offsetof(struct bss_descriptor, list));
1615 }
876c9d3a 1616
9012b28a 1617 ret = 0;
876c9d3a 1618
9012b28a
HS
1619done:
1620 lbs_deb_leave_args(LBS_DEB_SCAN, "ret %d", ret);
1621 return ret;
876c9d3a 1622}