]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - drivers/bluetooth/btusb.c
Bluetooth: ath3k: don't use stack memory for DMA
[mirror_ubuntu-bionic-kernel.git] / drivers / bluetooth / btusb.c
CommitLineData
5e23b923
MH
1/*
2 *
3 * Generic Bluetooth USB driver
4 *
9bfa35fe 5 * Copyright (C) 2005-2008 Marcel Holtmann <marcel@holtmann.org>
5e23b923
MH
6 *
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 2 of the License, or
11 * (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
21 *
22 */
23
5e23b923 24#include <linux/module.h>
5e23b923 25#include <linux/usb.h>
dffd30ee 26#include <linux/firmware.h>
5e23b923
MH
27
28#include <net/bluetooth/bluetooth.h>
29#include <net/bluetooth/hci_core.h>
30
7bee549e 31#define VERSION "0.6"
cfeb4145 32
90ab5ee9
RR
33static bool ignore_dga;
34static bool ignore_csr;
35static bool ignore_sniffer;
36static bool disable_scofix;
37static bool force_scofix;
7a9d4020 38
90ab5ee9 39static bool reset = 1;
cfeb4145
MH
40
41static struct usb_driver btusb_driver;
42
43#define BTUSB_IGNORE 0x01
7a9d4020
MH
44#define BTUSB_DIGIANSWER 0x02
45#define BTUSB_CSR 0x04
46#define BTUSB_SNIFFER 0x08
47#define BTUSB_BCM92035 0x10
48#define BTUSB_BROKEN_ISOC 0x20
49#define BTUSB_WRONG_SCO_MTU 0x40
2d25f8b4 50#define BTUSB_ATH3012 0x80
dffd30ee 51#define BTUSB_INTEL 0x100
5e23b923
MH
52
53static struct usb_device_id btusb_table[] = {
54 /* Generic Bluetooth USB device */
55 { USB_DEVICE_INFO(0xe0, 0x01, 0x01) },
56
1fa6535f
HR
57 /* Apple-specific (Broadcom) devices */
58 { USB_VENDOR_AND_INTERFACE_INFO(0x05ac, 0xff, 0x01, 0x01) },
59
c510eae3 60 /* Broadcom SoftSailing reporting vendor specific */
2e8b5063 61 { USB_DEVICE(0x0a5c, 0x21e1) },
c510eae3 62
3cd01976
NI
63 /* Apple MacBookPro 7,1 */
64 { USB_DEVICE(0x05ac, 0x8213) },
65
0a79f674
CL
66 /* Apple iMac11,1 */
67 { USB_DEVICE(0x05ac, 0x8215) },
68
9c047157
NI
69 /* Apple MacBookPro6,2 */
70 { USB_DEVICE(0x05ac, 0x8218) },
71
3e3ede7d
EH
72 /* Apple MacBookAir3,1, MacBookAir3,2 */
73 { USB_DEVICE(0x05ac, 0x821b) },
74
a63b723d
PAVM
75 /* Apple MacBookAir4,1 */
76 { USB_DEVICE(0x05ac, 0x821f) },
77
88d377b6
MAP
78 /* Apple MacBookPro8,2 */
79 { USB_DEVICE(0x05ac, 0x821a) },
80
f78b6826
JK
81 /* Apple MacMini5,1 */
82 { USB_DEVICE(0x05ac, 0x8281) },
83
cfeb4145
MH
84 /* AVM BlueFRITZ! USB v2.0 */
85 { USB_DEVICE(0x057c, 0x3800) },
86
87 /* Bluetooth Ultraport Module from IBM */
88 { USB_DEVICE(0x04bf, 0x030a) },
89
90 /* ALPS Modules with non-standard id */
91 { USB_DEVICE(0x044e, 0x3001) },
92 { USB_DEVICE(0x044e, 0x3002) },
93
94 /* Ericsson with non-standard id */
95 { USB_DEVICE(0x0bdb, 0x1002) },
96
97 /* Canyon CN-BTU1 with HID interfaces */
7a9d4020 98 { USB_DEVICE(0x0c10, 0x0000) },
cfeb4145 99
d13431ca 100 /* Broadcom BCM20702A0 */
1ee3ff61 101 { USB_DEVICE(0x0b05, 0x17b5) },
0c1abbd1 102 { USB_DEVICE(0x04ca, 0x2003) },
79cd7602 103 { USB_DEVICE(0x0489, 0xe042) },
d13431ca
WJS
104 { USB_DEVICE(0x413c, 0x8197) },
105
98514036 106 /* Foxconn - Hon Hai */
ee66401b 107 { USB_VENDOR_AND_INTERFACE_INFO(0x0489, 0xff, 0x01, 0x01) },
98514036 108
92c385f4
GP
109 /*Broadcom devices with vendor specific id */
110 { USB_VENDOR_AND_INTERFACE_INFO(0x0a5c, 0xff, 0x01, 0x01) },
111
5e23b923
MH
112 { } /* Terminating entry */
113};
114
115MODULE_DEVICE_TABLE(usb, btusb_table);
116
117static struct usb_device_id blacklist_table[] = {
cfeb4145
MH
118 /* CSR BlueCore devices */
119 { USB_DEVICE(0x0a12, 0x0001), .driver_info = BTUSB_CSR },
120
121 /* Broadcom BCM2033 without firmware */
122 { USB_DEVICE(0x0a5c, 0x2033), .driver_info = BTUSB_IGNORE },
123
be93112a
BS
124 /* Atheros 3011 with sflash firmware */
125 { USB_DEVICE(0x0cf3, 0x3002), .driver_info = BTUSB_IGNORE },
6eda541d 126 { USB_DEVICE(0x0cf3, 0xe019), .driver_info = BTUSB_IGNORE },
2a7bcccc 127 { USB_DEVICE(0x13d3, 0x3304), .driver_info = BTUSB_IGNORE },
8e7c3d2e 128 { USB_DEVICE(0x0930, 0x0215), .driver_info = BTUSB_IGNORE },
6b6ba88b 129 { USB_DEVICE(0x0489, 0xe03d), .driver_info = BTUSB_IGNORE },
acd94544 130 { USB_DEVICE(0x0489, 0xe027), .driver_info = BTUSB_IGNORE },
be93112a 131
509e7861
CYC
132 /* Atheros AR9285 Malbec with sflash firmware */
133 { USB_DEVICE(0x03f0, 0x311d), .driver_info = BTUSB_IGNORE },
134
d9f51b51 135 /* Atheros 3012 with sflash firmware */
d66629c1 136 { USB_DEVICE(0x0cf3, 0x0036), .driver_info = BTUSB_ATH3012 },
2d25f8b4 137 { USB_DEVICE(0x0cf3, 0x3004), .driver_info = BTUSB_ATH3012 },
94a32d10 138 { USB_DEVICE(0x0cf3, 0x3008), .driver_info = BTUSB_ATH3012 },
07c0ea87 139 { USB_DEVICE(0x0cf3, 0x311d), .driver_info = BTUSB_ATH3012 },
ebaf5795 140 { USB_DEVICE(0x0cf3, 0x817a), .driver_info = BTUSB_ATH3012 },
9498ba7a 141 { USB_DEVICE(0x13d3, 0x3375), .driver_info = BTUSB_ATH3012 },
3f63c340 142 { USB_DEVICE(0x04ca, 0x3004), .driver_info = BTUSB_ATH3012 },
55ed7d4d 143 { USB_DEVICE(0x04ca, 0x3005), .driver_info = BTUSB_ATH3012 },
2c262b2a 144 { USB_DEVICE(0x04ca, 0x3006), .driver_info = BTUSB_ATH3012 },
f4d6f7dc 145 { USB_DEVICE(0x04ca, 0x3008), .driver_info = BTUSB_ATH3012 },
87522a43 146 { USB_DEVICE(0x13d3, 0x3362), .driver_info = BTUSB_ATH3012 },
ac71311e 147 { USB_DEVICE(0x0cf3, 0xe004), .driver_info = BTUSB_ATH3012 },
6c4ae5c2 148 { USB_DEVICE(0x0930, 0x0219), .driver_info = BTUSB_ATH3012 },
2096ae6c 149 { USB_DEVICE(0x0489, 0xe057), .driver_info = BTUSB_ATH3012 },
eed307e2 150 { USB_DEVICE(0x13d3, 0x3393), .driver_info = BTUSB_ATH3012 },
3a61eda8 151 { USB_DEVICE(0x0489, 0xe04e), .driver_info = BTUSB_ATH3012 },
2582d529 152 { USB_DEVICE(0x0489, 0xe056), .driver_info = BTUSB_ATH3012 },
0fc110f4 153 { USB_DEVICE(0x0489, 0xe04d), .driver_info = BTUSB_ATH3012 },
84eb2ae1 154 { USB_DEVICE(0x04c5, 0x1330), .driver_info = BTUSB_ATH3012 },
d9f51b51 155
e9036e33
CYC
156 /* Atheros AR5BBU12 with sflash firmware */
157 { USB_DEVICE(0x0489, 0xe02c), .driver_info = BTUSB_IGNORE },
158
85d59726
MG
159 /* Atheros AR5BBU12 with sflash firmware */
160 { USB_DEVICE(0x0489, 0xe03c), .driver_info = BTUSB_ATH3012 },
bc21fde2 161 { USB_DEVICE(0x0489, 0xe036), .driver_info = BTUSB_ATH3012 },
85d59726 162
cfeb4145 163 /* Broadcom BCM2035 */
7a9d4020
MH
164 { USB_DEVICE(0x0a5c, 0x2035), .driver_info = BTUSB_WRONG_SCO_MTU },
165 { USB_DEVICE(0x0a5c, 0x200a), .driver_info = BTUSB_WRONG_SCO_MTU },
166 { USB_DEVICE(0x0a5c, 0x2009), .driver_info = BTUSB_BCM92035 },
cfeb4145
MH
167
168 /* Broadcom BCM2045 */
7a9d4020
MH
169 { USB_DEVICE(0x0a5c, 0x2039), .driver_info = BTUSB_WRONG_SCO_MTU },
170 { USB_DEVICE(0x0a5c, 0x2101), .driver_info = BTUSB_WRONG_SCO_MTU },
bdbef3d6 171
cfeb4145 172 /* IBM/Lenovo ThinkPad with Broadcom chip */
7a9d4020
MH
173 { USB_DEVICE(0x0a5c, 0x201e), .driver_info = BTUSB_WRONG_SCO_MTU },
174 { USB_DEVICE(0x0a5c, 0x2110), .driver_info = BTUSB_WRONG_SCO_MTU },
cfeb4145
MH
175
176 /* HP laptop with Broadcom chip */
7a9d4020 177 { USB_DEVICE(0x03f0, 0x171d), .driver_info = BTUSB_WRONG_SCO_MTU },
cfeb4145
MH
178
179 /* Dell laptop with Broadcom chip */
7a9d4020 180 { USB_DEVICE(0x413c, 0x8126), .driver_info = BTUSB_WRONG_SCO_MTU },
cfeb4145 181
5ddd4a60 182 /* Dell Wireless 370 and 410 devices */
7a9d4020 183 { USB_DEVICE(0x413c, 0x8152), .driver_info = BTUSB_WRONG_SCO_MTU },
5ddd4a60 184 { USB_DEVICE(0x413c, 0x8156), .driver_info = BTUSB_WRONG_SCO_MTU },
cfeb4145 185
7a9d4020
MH
186 /* Belkin F8T012 and F8T013 devices */
187 { USB_DEVICE(0x050d, 0x0012), .driver_info = BTUSB_WRONG_SCO_MTU },
188 { USB_DEVICE(0x050d, 0x0013), .driver_info = BTUSB_WRONG_SCO_MTU },
cfeb4145 189
5ddd4a60
MH
190 /* Asus WL-BTD202 device */
191 { USB_DEVICE(0x0b05, 0x1715), .driver_info = BTUSB_WRONG_SCO_MTU },
192
193 /* Kensington Bluetooth USB adapter */
194 { USB_DEVICE(0x047d, 0x105e), .driver_info = BTUSB_WRONG_SCO_MTU },
195
cfeb4145
MH
196 /* RTX Telecom based adapters with buggy SCO support */
197 { USB_DEVICE(0x0400, 0x0807), .driver_info = BTUSB_BROKEN_ISOC },
198 { USB_DEVICE(0x0400, 0x080a), .driver_info = BTUSB_BROKEN_ISOC },
199
200 /* CONWISE Technology based adapters with buggy SCO support */
201 { USB_DEVICE(0x0e5e, 0x6622), .driver_info = BTUSB_BROKEN_ISOC },
202
cfeb4145
MH
203 /* Digianswer devices */
204 { USB_DEVICE(0x08fd, 0x0001), .driver_info = BTUSB_DIGIANSWER },
205 { USB_DEVICE(0x08fd, 0x0002), .driver_info = BTUSB_IGNORE },
206
207 /* CSR BlueCore Bluetooth Sniffer */
208 { USB_DEVICE(0x0a12, 0x0002), .driver_info = BTUSB_SNIFFER },
209
210 /* Frontline ComProbe Bluetooth Sniffer */
211 { USB_DEVICE(0x16d3, 0x0002), .driver_info = BTUSB_SNIFFER },
212
dffd30ee
THJA
213 /* Intel Bluetooth device */
214 { USB_DEVICE(0x8087, 0x07dc), .driver_info = BTUSB_INTEL },
215
5e23b923
MH
216 { } /* Terminating entry */
217};
218
9bfa35fe
MH
219#define BTUSB_MAX_ISOC_FRAMES 10
220
5e23b923
MH
221#define BTUSB_INTR_RUNNING 0
222#define BTUSB_BULK_RUNNING 1
9bfa35fe 223#define BTUSB_ISOC_RUNNING 2
7bee549e 224#define BTUSB_SUSPENDING 3
08b8b6c4 225#define BTUSB_DID_ISO_RESUME 4
5e23b923
MH
226
227struct btusb_data {
228 struct hci_dev *hdev;
229 struct usb_device *udev;
5fbcd260 230 struct usb_interface *intf;
9bfa35fe 231 struct usb_interface *isoc;
5e23b923
MH
232
233 spinlock_t lock;
234
235 unsigned long flags;
236
237 struct work_struct work;
7bee549e 238 struct work_struct waker;
5e23b923
MH
239
240 struct usb_anchor tx_anchor;
241 struct usb_anchor intr_anchor;
242 struct usb_anchor bulk_anchor;
9bfa35fe 243 struct usb_anchor isoc_anchor;
7bee549e
ON
244 struct usb_anchor deferred;
245 int tx_in_flight;
246 spinlock_t txlock;
5e23b923
MH
247
248 struct usb_endpoint_descriptor *intr_ep;
249 struct usb_endpoint_descriptor *bulk_tx_ep;
250 struct usb_endpoint_descriptor *bulk_rx_ep;
9bfa35fe
MH
251 struct usb_endpoint_descriptor *isoc_tx_ep;
252 struct usb_endpoint_descriptor *isoc_rx_ep;
253
7a9d4020
MH
254 __u8 cmdreq_type;
255
43c2e57f 256 unsigned int sco_num;
9bfa35fe 257 int isoc_altsetting;
6a88adf2 258 int suspend_count;
5e23b923
MH
259};
260
7bee549e
ON
261static int inc_tx(struct btusb_data *data)
262{
263 unsigned long flags;
264 int rv;
265
266 spin_lock_irqsave(&data->txlock, flags);
267 rv = test_bit(BTUSB_SUSPENDING, &data->flags);
268 if (!rv)
269 data->tx_in_flight++;
270 spin_unlock_irqrestore(&data->txlock, flags);
271
272 return rv;
273}
274
5e23b923
MH
275static void btusb_intr_complete(struct urb *urb)
276{
277 struct hci_dev *hdev = urb->context;
155961e8 278 struct btusb_data *data = hci_get_drvdata(hdev);
5e23b923
MH
279 int err;
280
281 BT_DBG("%s urb %p status %d count %d", hdev->name,
282 urb, urb->status, urb->actual_length);
283
284 if (!test_bit(HCI_RUNNING, &hdev->flags))
285 return;
286
287 if (urb->status == 0) {
9bfa35fe
MH
288 hdev->stat.byte_rx += urb->actual_length;
289
5e23b923
MH
290 if (hci_recv_fragment(hdev, HCI_EVENT_PKT,
291 urb->transfer_buffer,
292 urb->actual_length) < 0) {
293 BT_ERR("%s corrupted event packet", hdev->name);
294 hdev->stat.err_rx++;
295 }
296 }
297
298 if (!test_bit(BTUSB_INTR_RUNNING, &data->flags))
299 return;
300
7bee549e 301 usb_mark_last_busy(data->udev);
5e23b923
MH
302 usb_anchor_urb(urb, &data->intr_anchor);
303
304 err = usb_submit_urb(urb, GFP_ATOMIC);
305 if (err < 0) {
4935f1c1
PB
306 /* -EPERM: urb is being killed;
307 * -ENODEV: device got disconnected */
308 if (err != -EPERM && err != -ENODEV)
61faddf6 309 BT_ERR("%s urb %p failed to resubmit (%d)",
5e23b923
MH
310 hdev->name, urb, -err);
311 usb_unanchor_urb(urb);
312 }
313}
314
2eda66f4 315static int btusb_submit_intr_urb(struct hci_dev *hdev, gfp_t mem_flags)
5e23b923 316{
155961e8 317 struct btusb_data *data = hci_get_drvdata(hdev);
5e23b923
MH
318 struct urb *urb;
319 unsigned char *buf;
320 unsigned int pipe;
321 int err, size;
322
323 BT_DBG("%s", hdev->name);
324
9bfa35fe
MH
325 if (!data->intr_ep)
326 return -ENODEV;
327
2eda66f4 328 urb = usb_alloc_urb(0, mem_flags);
5e23b923
MH
329 if (!urb)
330 return -ENOMEM;
331
332 size = le16_to_cpu(data->intr_ep->wMaxPacketSize);
333
2eda66f4 334 buf = kmalloc(size, mem_flags);
5e23b923
MH
335 if (!buf) {
336 usb_free_urb(urb);
337 return -ENOMEM;
338 }
339
340 pipe = usb_rcvintpipe(data->udev, data->intr_ep->bEndpointAddress);
341
342 usb_fill_int_urb(urb, data->udev, pipe, buf, size,
343 btusb_intr_complete, hdev,
344 data->intr_ep->bInterval);
345
346 urb->transfer_flags |= URB_FREE_BUFFER;
347
348 usb_anchor_urb(urb, &data->intr_anchor);
349
2eda66f4 350 err = usb_submit_urb(urb, mem_flags);
5e23b923 351 if (err < 0) {
d4b8d1c9
PB
352 if (err != -EPERM && err != -ENODEV)
353 BT_ERR("%s urb %p submission failed (%d)",
5e23b923
MH
354 hdev->name, urb, -err);
355 usb_unanchor_urb(urb);
5e23b923
MH
356 }
357
358 usb_free_urb(urb);
359
360 return err;
361}
362
363static void btusb_bulk_complete(struct urb *urb)
364{
365 struct hci_dev *hdev = urb->context;
155961e8 366 struct btusb_data *data = hci_get_drvdata(hdev);
5e23b923
MH
367 int err;
368
369 BT_DBG("%s urb %p status %d count %d", hdev->name,
370 urb, urb->status, urb->actual_length);
371
372 if (!test_bit(HCI_RUNNING, &hdev->flags))
373 return;
374
375 if (urb->status == 0) {
9bfa35fe
MH
376 hdev->stat.byte_rx += urb->actual_length;
377
5e23b923
MH
378 if (hci_recv_fragment(hdev, HCI_ACLDATA_PKT,
379 urb->transfer_buffer,
380 urb->actual_length) < 0) {
381 BT_ERR("%s corrupted ACL packet", hdev->name);
382 hdev->stat.err_rx++;
383 }
384 }
385
386 if (!test_bit(BTUSB_BULK_RUNNING, &data->flags))
387 return;
388
389 usb_anchor_urb(urb, &data->bulk_anchor);
652fd781 390 usb_mark_last_busy(data->udev);
5e23b923
MH
391
392 err = usb_submit_urb(urb, GFP_ATOMIC);
393 if (err < 0) {
4935f1c1
PB
394 /* -EPERM: urb is being killed;
395 * -ENODEV: device got disconnected */
396 if (err != -EPERM && err != -ENODEV)
61faddf6 397 BT_ERR("%s urb %p failed to resubmit (%d)",
5e23b923
MH
398 hdev->name, urb, -err);
399 usb_unanchor_urb(urb);
400 }
401}
402
2eda66f4 403static int btusb_submit_bulk_urb(struct hci_dev *hdev, gfp_t mem_flags)
5e23b923 404{
155961e8 405 struct btusb_data *data = hci_get_drvdata(hdev);
5e23b923
MH
406 struct urb *urb;
407 unsigned char *buf;
408 unsigned int pipe;
290ba200 409 int err, size = HCI_MAX_FRAME_SIZE;
5e23b923
MH
410
411 BT_DBG("%s", hdev->name);
412
9bfa35fe
MH
413 if (!data->bulk_rx_ep)
414 return -ENODEV;
415
2eda66f4 416 urb = usb_alloc_urb(0, mem_flags);
5e23b923
MH
417 if (!urb)
418 return -ENOMEM;
419
2eda66f4 420 buf = kmalloc(size, mem_flags);
5e23b923
MH
421 if (!buf) {
422 usb_free_urb(urb);
423 return -ENOMEM;
424 }
425
426 pipe = usb_rcvbulkpipe(data->udev, data->bulk_rx_ep->bEndpointAddress);
427
428 usb_fill_bulk_urb(urb, data->udev, pipe,
429 buf, size, btusb_bulk_complete, hdev);
430
431 urb->transfer_flags |= URB_FREE_BUFFER;
432
7bee549e 433 usb_mark_last_busy(data->udev);
5e23b923
MH
434 usb_anchor_urb(urb, &data->bulk_anchor);
435
2eda66f4 436 err = usb_submit_urb(urb, mem_flags);
5e23b923 437 if (err < 0) {
d4b8d1c9
PB
438 if (err != -EPERM && err != -ENODEV)
439 BT_ERR("%s urb %p submission failed (%d)",
5e23b923
MH
440 hdev->name, urb, -err);
441 usb_unanchor_urb(urb);
5e23b923
MH
442 }
443
444 usb_free_urb(urb);
445
446 return err;
447}
448
9bfa35fe
MH
449static void btusb_isoc_complete(struct urb *urb)
450{
451 struct hci_dev *hdev = urb->context;
155961e8 452 struct btusb_data *data = hci_get_drvdata(hdev);
9bfa35fe
MH
453 int i, err;
454
455 BT_DBG("%s urb %p status %d count %d", hdev->name,
456 urb, urb->status, urb->actual_length);
457
458 if (!test_bit(HCI_RUNNING, &hdev->flags))
459 return;
460
461 if (urb->status == 0) {
462 for (i = 0; i < urb->number_of_packets; i++) {
463 unsigned int offset = urb->iso_frame_desc[i].offset;
464 unsigned int length = urb->iso_frame_desc[i].actual_length;
465
466 if (urb->iso_frame_desc[i].status)
467 continue;
468
469 hdev->stat.byte_rx += length;
470
471 if (hci_recv_fragment(hdev, HCI_SCODATA_PKT,
472 urb->transfer_buffer + offset,
473 length) < 0) {
474 BT_ERR("%s corrupted SCO packet", hdev->name);
475 hdev->stat.err_rx++;
476 }
477 }
478 }
479
480 if (!test_bit(BTUSB_ISOC_RUNNING, &data->flags))
481 return;
482
483 usb_anchor_urb(urb, &data->isoc_anchor);
484
485 err = usb_submit_urb(urb, GFP_ATOMIC);
486 if (err < 0) {
4935f1c1
PB
487 /* -EPERM: urb is being killed;
488 * -ENODEV: device got disconnected */
489 if (err != -EPERM && err != -ENODEV)
61faddf6 490 BT_ERR("%s urb %p failed to resubmit (%d)",
9bfa35fe
MH
491 hdev->name, urb, -err);
492 usb_unanchor_urb(urb);
493 }
494}
495
42b16b3f 496static inline void __fill_isoc_descriptor(struct urb *urb, int len, int mtu)
9bfa35fe
MH
497{
498 int i, offset = 0;
499
500 BT_DBG("len %d mtu %d", len, mtu);
501
502 for (i = 0; i < BTUSB_MAX_ISOC_FRAMES && len >= mtu;
503 i++, offset += mtu, len -= mtu) {
504 urb->iso_frame_desc[i].offset = offset;
505 urb->iso_frame_desc[i].length = mtu;
506 }
507
508 if (len && i < BTUSB_MAX_ISOC_FRAMES) {
509 urb->iso_frame_desc[i].offset = offset;
510 urb->iso_frame_desc[i].length = len;
511 i++;
512 }
513
514 urb->number_of_packets = i;
515}
516
2eda66f4 517static int btusb_submit_isoc_urb(struct hci_dev *hdev, gfp_t mem_flags)
9bfa35fe 518{
155961e8 519 struct btusb_data *data = hci_get_drvdata(hdev);
9bfa35fe
MH
520 struct urb *urb;
521 unsigned char *buf;
522 unsigned int pipe;
523 int err, size;
524
525 BT_DBG("%s", hdev->name);
526
527 if (!data->isoc_rx_ep)
528 return -ENODEV;
529
2eda66f4 530 urb = usb_alloc_urb(BTUSB_MAX_ISOC_FRAMES, mem_flags);
9bfa35fe
MH
531 if (!urb)
532 return -ENOMEM;
533
534 size = le16_to_cpu(data->isoc_rx_ep->wMaxPacketSize) *
535 BTUSB_MAX_ISOC_FRAMES;
536
2eda66f4 537 buf = kmalloc(size, mem_flags);
9bfa35fe
MH
538 if (!buf) {
539 usb_free_urb(urb);
540 return -ENOMEM;
541 }
542
543 pipe = usb_rcvisocpipe(data->udev, data->isoc_rx_ep->bEndpointAddress);
544
fa0fb93f
BZ
545 usb_fill_int_urb(urb, data->udev, pipe, buf, size, btusb_isoc_complete,
546 hdev, data->isoc_rx_ep->bInterval);
9bfa35fe
MH
547
548 urb->transfer_flags = URB_FREE_BUFFER | URB_ISO_ASAP;
9bfa35fe
MH
549
550 __fill_isoc_descriptor(urb, size,
551 le16_to_cpu(data->isoc_rx_ep->wMaxPacketSize));
552
553 usb_anchor_urb(urb, &data->isoc_anchor);
554
2eda66f4 555 err = usb_submit_urb(urb, mem_flags);
9bfa35fe 556 if (err < 0) {
d4b8d1c9
PB
557 if (err != -EPERM && err != -ENODEV)
558 BT_ERR("%s urb %p submission failed (%d)",
9bfa35fe
MH
559 hdev->name, urb, -err);
560 usb_unanchor_urb(urb);
9bfa35fe
MH
561 }
562
563 usb_free_urb(urb);
564
565 return err;
566}
567
5e23b923 568static void btusb_tx_complete(struct urb *urb)
7bee549e
ON
569{
570 struct sk_buff *skb = urb->context;
571 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
155961e8 572 struct btusb_data *data = hci_get_drvdata(hdev);
7bee549e
ON
573
574 BT_DBG("%s urb %p status %d count %d", hdev->name,
575 urb, urb->status, urb->actual_length);
576
577 if (!test_bit(HCI_RUNNING, &hdev->flags))
578 goto done;
579
580 if (!urb->status)
581 hdev->stat.byte_tx += urb->transfer_buffer_length;
582 else
583 hdev->stat.err_tx++;
584
585done:
586 spin_lock(&data->txlock);
587 data->tx_in_flight--;
588 spin_unlock(&data->txlock);
589
590 kfree(urb->setup_packet);
591
592 kfree_skb(skb);
593}
594
595static void btusb_isoc_tx_complete(struct urb *urb)
5e23b923
MH
596{
597 struct sk_buff *skb = urb->context;
598 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
599
600 BT_DBG("%s urb %p status %d count %d", hdev->name,
601 urb, urb->status, urb->actual_length);
602
603 if (!test_bit(HCI_RUNNING, &hdev->flags))
604 goto done;
605
606 if (!urb->status)
607 hdev->stat.byte_tx += urb->transfer_buffer_length;
608 else
609 hdev->stat.err_tx++;
610
611done:
612 kfree(urb->setup_packet);
613
614 kfree_skb(skb);
615}
616
617static int btusb_open(struct hci_dev *hdev)
618{
155961e8 619 struct btusb_data *data = hci_get_drvdata(hdev);
5e23b923
MH
620 int err;
621
622 BT_DBG("%s", hdev->name);
623
7bee549e
ON
624 err = usb_autopm_get_interface(data->intf);
625 if (err < 0)
626 return err;
627
628 data->intf->needs_remote_wakeup = 1;
629
5e23b923 630 if (test_and_set_bit(HCI_RUNNING, &hdev->flags))
7bee549e 631 goto done;
5e23b923
MH
632
633 if (test_and_set_bit(BTUSB_INTR_RUNNING, &data->flags))
7bee549e 634 goto done;
5e23b923 635
2eda66f4 636 err = btusb_submit_intr_urb(hdev, GFP_KERNEL);
43c2e57f
MH
637 if (err < 0)
638 goto failed;
639
640 err = btusb_submit_bulk_urb(hdev, GFP_KERNEL);
5e23b923 641 if (err < 0) {
43c2e57f
MH
642 usb_kill_anchored_urbs(&data->intr_anchor);
643 goto failed;
5e23b923
MH
644 }
645
43c2e57f
MH
646 set_bit(BTUSB_BULK_RUNNING, &data->flags);
647 btusb_submit_bulk_urb(hdev, GFP_KERNEL);
648
7bee549e
ON
649done:
650 usb_autopm_put_interface(data->intf);
43c2e57f
MH
651 return 0;
652
653failed:
654 clear_bit(BTUSB_INTR_RUNNING, &data->flags);
655 clear_bit(HCI_RUNNING, &hdev->flags);
7bee549e 656 usb_autopm_put_interface(data->intf);
5e23b923
MH
657 return err;
658}
659
7bee549e
ON
660static void btusb_stop_traffic(struct btusb_data *data)
661{
662 usb_kill_anchored_urbs(&data->intr_anchor);
663 usb_kill_anchored_urbs(&data->bulk_anchor);
664 usb_kill_anchored_urbs(&data->isoc_anchor);
665}
666
5e23b923
MH
667static int btusb_close(struct hci_dev *hdev)
668{
155961e8 669 struct btusb_data *data = hci_get_drvdata(hdev);
7bee549e 670 int err;
5e23b923
MH
671
672 BT_DBG("%s", hdev->name);
673
674 if (!test_and_clear_bit(HCI_RUNNING, &hdev->flags))
675 return 0;
676
e8c3c3d2 677 cancel_work_sync(&data->work);
404291ac 678 cancel_work_sync(&data->waker);
e8c3c3d2 679
9bfa35fe 680 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
5e23b923 681 clear_bit(BTUSB_BULK_RUNNING, &data->flags);
5e23b923 682 clear_bit(BTUSB_INTR_RUNNING, &data->flags);
7bee549e
ON
683
684 btusb_stop_traffic(data);
685 err = usb_autopm_get_interface(data->intf);
686 if (err < 0)
7b8e2c1d 687 goto failed;
7bee549e
ON
688
689 data->intf->needs_remote_wakeup = 0;
690 usb_autopm_put_interface(data->intf);
5e23b923 691
7b8e2c1d
ON
692failed:
693 usb_scuttle_anchored_urbs(&data->deferred);
5e23b923
MH
694 return 0;
695}
696
697static int btusb_flush(struct hci_dev *hdev)
698{
155961e8 699 struct btusb_data *data = hci_get_drvdata(hdev);
5e23b923
MH
700
701 BT_DBG("%s", hdev->name);
702
703 usb_kill_anchored_urbs(&data->tx_anchor);
704
705 return 0;
706}
707
708static int btusb_send_frame(struct sk_buff *skb)
709{
710 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
155961e8 711 struct btusb_data *data = hci_get_drvdata(hdev);
5e23b923
MH
712 struct usb_ctrlrequest *dr;
713 struct urb *urb;
714 unsigned int pipe;
715 int err;
716
717 BT_DBG("%s", hdev->name);
718
719 if (!test_bit(HCI_RUNNING, &hdev->flags))
720 return -EBUSY;
721
722 switch (bt_cb(skb)->pkt_type) {
723 case HCI_COMMAND_PKT:
724 urb = usb_alloc_urb(0, GFP_ATOMIC);
725 if (!urb)
726 return -ENOMEM;
727
728 dr = kmalloc(sizeof(*dr), GFP_ATOMIC);
729 if (!dr) {
730 usb_free_urb(urb);
731 return -ENOMEM;
732 }
733
7a9d4020 734 dr->bRequestType = data->cmdreq_type;
5e23b923
MH
735 dr->bRequest = 0;
736 dr->wIndex = 0;
737 dr->wValue = 0;
738 dr->wLength = __cpu_to_le16(skb->len);
739
740 pipe = usb_sndctrlpipe(data->udev, 0x00);
741
742 usb_fill_control_urb(urb, data->udev, pipe, (void *) dr,
743 skb->data, skb->len, btusb_tx_complete, skb);
744
745 hdev->stat.cmd_tx++;
746 break;
747
748 case HCI_ACLDATA_PKT:
9fd481e0 749 if (!data->bulk_tx_ep)
9bfa35fe
MH
750 return -ENODEV;
751
5e23b923
MH
752 urb = usb_alloc_urb(0, GFP_ATOMIC);
753 if (!urb)
754 return -ENOMEM;
755
756 pipe = usb_sndbulkpipe(data->udev,
757 data->bulk_tx_ep->bEndpointAddress);
758
759 usb_fill_bulk_urb(urb, data->udev, pipe,
760 skb->data, skb->len, btusb_tx_complete, skb);
761
762 hdev->stat.acl_tx++;
763 break;
764
765 case HCI_SCODATA_PKT:
9bfa35fe
MH
766 if (!data->isoc_tx_ep || hdev->conn_hash.sco_num < 1)
767 return -ENODEV;
768
769 urb = usb_alloc_urb(BTUSB_MAX_ISOC_FRAMES, GFP_ATOMIC);
770 if (!urb)
771 return -ENOMEM;
772
773 pipe = usb_sndisocpipe(data->udev,
774 data->isoc_tx_ep->bEndpointAddress);
775
03c2d0e8
GP
776 usb_fill_int_urb(urb, data->udev, pipe,
777 skb->data, skb->len, btusb_isoc_tx_complete,
778 skb, data->isoc_tx_ep->bInterval);
9bfa35fe
MH
779
780 urb->transfer_flags = URB_ISO_ASAP;
9bfa35fe
MH
781
782 __fill_isoc_descriptor(urb, skb->len,
783 le16_to_cpu(data->isoc_tx_ep->wMaxPacketSize));
784
5e23b923 785 hdev->stat.sco_tx++;
7bee549e 786 goto skip_waking;
5e23b923
MH
787
788 default:
789 return -EILSEQ;
790 }
791
7bee549e
ON
792 err = inc_tx(data);
793 if (err) {
794 usb_anchor_urb(urb, &data->deferred);
795 schedule_work(&data->waker);
796 err = 0;
797 goto done;
798 }
799
800skip_waking:
5e23b923
MH
801 usb_anchor_urb(urb, &data->tx_anchor);
802
803 err = usb_submit_urb(urb, GFP_ATOMIC);
804 if (err < 0) {
5a9b80e2
PB
805 if (err != -EPERM && err != -ENODEV)
806 BT_ERR("%s urb %p submission failed (%d)",
807 hdev->name, urb, -err);
5e23b923
MH
808 kfree(urb->setup_packet);
809 usb_unanchor_urb(urb);
7bee549e
ON
810 } else {
811 usb_mark_last_busy(data->udev);
5e23b923
MH
812 }
813
7bee549e 814done:
54a8a79c 815 usb_free_urb(urb);
5e23b923
MH
816 return err;
817}
818
5e23b923
MH
819static void btusb_notify(struct hci_dev *hdev, unsigned int evt)
820{
155961e8 821 struct btusb_data *data = hci_get_drvdata(hdev);
5e23b923
MH
822
823 BT_DBG("%s evt %d", hdev->name, evt);
824
43c2e57f
MH
825 if (hdev->conn_hash.sco_num != data->sco_num) {
826 data->sco_num = hdev->conn_hash.sco_num;
827 schedule_work(&data->work);
a780efa8 828 }
5e23b923
MH
829}
830
42b16b3f 831static inline int __set_isoc_interface(struct hci_dev *hdev, int altsetting)
9bfa35fe 832{
155961e8 833 struct btusb_data *data = hci_get_drvdata(hdev);
9bfa35fe
MH
834 struct usb_interface *intf = data->isoc;
835 struct usb_endpoint_descriptor *ep_desc;
836 int i, err;
837
838 if (!data->isoc)
839 return -ENODEV;
840
841 err = usb_set_interface(data->udev, 1, altsetting);
842 if (err < 0) {
843 BT_ERR("%s setting interface failed (%d)", hdev->name, -err);
844 return err;
845 }
846
847 data->isoc_altsetting = altsetting;
848
849 data->isoc_tx_ep = NULL;
850 data->isoc_rx_ep = NULL;
851
852 for (i = 0; i < intf->cur_altsetting->desc.bNumEndpoints; i++) {
853 ep_desc = &intf->cur_altsetting->endpoint[i].desc;
854
855 if (!data->isoc_tx_ep && usb_endpoint_is_isoc_out(ep_desc)) {
856 data->isoc_tx_ep = ep_desc;
857 continue;
858 }
859
860 if (!data->isoc_rx_ep && usb_endpoint_is_isoc_in(ep_desc)) {
861 data->isoc_rx_ep = ep_desc;
862 continue;
863 }
864 }
865
866 if (!data->isoc_tx_ep || !data->isoc_rx_ep) {
867 BT_ERR("%s invalid SCO descriptors", hdev->name);
868 return -ENODEV;
869 }
870
871 return 0;
872}
873
5e23b923
MH
874static void btusb_work(struct work_struct *work)
875{
876 struct btusb_data *data = container_of(work, struct btusb_data, work);
877 struct hci_dev *hdev = data->hdev;
f4001d28 878 int new_alts;
7bee549e 879 int err;
5e23b923 880
9bfa35fe 881 if (hdev->conn_hash.sco_num > 0) {
08b8b6c4 882 if (!test_bit(BTUSB_DID_ISO_RESUME, &data->flags)) {
8efdd0cd 883 err = usb_autopm_get_interface(data->isoc ? data->isoc : data->intf);
7bee549e
ON
884 if (err < 0) {
885 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
886 usb_kill_anchored_urbs(&data->isoc_anchor);
887 return;
888 }
889
08b8b6c4 890 set_bit(BTUSB_DID_ISO_RESUME, &data->flags);
7bee549e 891 }
f4001d28
MA
892
893 if (hdev->voice_setting & 0x0020) {
894 static const int alts[3] = { 2, 4, 5 };
895 new_alts = alts[hdev->conn_hash.sco_num - 1];
896 } else {
897 new_alts = hdev->conn_hash.sco_num;
898 }
899
900 if (data->isoc_altsetting != new_alts) {
9bfa35fe
MH
901 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
902 usb_kill_anchored_urbs(&data->isoc_anchor);
903
f4001d28 904 if (__set_isoc_interface(hdev, new_alts) < 0)
9bfa35fe
MH
905 return;
906 }
907
908 if (!test_and_set_bit(BTUSB_ISOC_RUNNING, &data->flags)) {
2eda66f4 909 if (btusb_submit_isoc_urb(hdev, GFP_KERNEL) < 0)
9bfa35fe
MH
910 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
911 else
2eda66f4 912 btusb_submit_isoc_urb(hdev, GFP_KERNEL);
9bfa35fe
MH
913 }
914 } else {
915 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
916 usb_kill_anchored_urbs(&data->isoc_anchor);
917
918 __set_isoc_interface(hdev, 0);
08b8b6c4 919 if (test_and_clear_bit(BTUSB_DID_ISO_RESUME, &data->flags))
8efdd0cd 920 usb_autopm_put_interface(data->isoc ? data->isoc : data->intf);
5e23b923
MH
921 }
922}
923
7bee549e
ON
924static void btusb_waker(struct work_struct *work)
925{
926 struct btusb_data *data = container_of(work, struct btusb_data, waker);
927 int err;
928
929 err = usb_autopm_get_interface(data->intf);
930 if (err < 0)
931 return;
932
933 usb_autopm_put_interface(data->intf);
934}
935
9f8f962c
MH
936static int btusb_setup_bcm92035(struct hci_dev *hdev)
937{
938 struct sk_buff *skb;
939 u8 val = 0x00;
940
941 BT_DBG("%s", hdev->name);
942
943 skb = __hci_cmd_sync(hdev, 0xfc3b, 1, &val, HCI_INIT_TIMEOUT);
944 if (IS_ERR(skb))
945 BT_ERR("BCM92035 command failed (%ld)", -PTR_ERR(skb));
946 else
947 kfree_skb(skb);
948
949 return 0;
950}
951
dffd30ee
THJA
952struct intel_version {
953 u8 status;
954 u8 hw_platform;
955 u8 hw_variant;
956 u8 hw_revision;
957 u8 fw_variant;
958 u8 fw_revision;
959 u8 fw_build_num;
960 u8 fw_build_ww;
961 u8 fw_build_yy;
962 u8 fw_patch_num;
963} __packed;
964
965static const struct firmware *btusb_setup_intel_get_fw(struct hci_dev *hdev,
966 struct intel_version *ver)
967{
968 const struct firmware *fw;
969 char fwname[64];
970 int ret;
971
972 snprintf(fwname, sizeof(fwname),
973 "intel/ibt-hw-%x.%x.%x-fw-%x.%x.%x.%x.%x.bseq",
974 ver->hw_platform, ver->hw_variant, ver->hw_revision,
975 ver->fw_variant, ver->fw_revision, ver->fw_build_num,
976 ver->fw_build_ww, ver->fw_build_yy);
977
978 ret = request_firmware(&fw, fwname, &hdev->dev);
979 if (ret < 0) {
980 if (ret == -EINVAL) {
981 BT_ERR("%s Intel firmware file request failed (%d)",
982 hdev->name, ret);
983 return NULL;
984 }
985
986 BT_ERR("%s failed to open Intel firmware file: %s(%d)",
987 hdev->name, fwname, ret);
988
989 /* If the correct firmware patch file is not found, use the
990 * default firmware patch file instead
991 */
992 snprintf(fwname, sizeof(fwname), "intel/ibt-hw-%x.%x.bseq",
993 ver->hw_platform, ver->hw_variant);
994 if (request_firmware(&fw, fwname, &hdev->dev) < 0) {
995 BT_ERR("%s failed to open default Intel fw file: %s",
996 hdev->name, fwname);
997 return NULL;
998 }
999 }
1000
1001 BT_INFO("%s: Intel Bluetooth firmware file: %s", hdev->name, fwname);
1002
1003 return fw;
1004}
1005
1006static int btusb_setup_intel_patching(struct hci_dev *hdev,
1007 const struct firmware *fw,
1008 const u8 **fw_ptr, int *disable_patch)
1009{
1010 struct sk_buff *skb;
1011 struct hci_command_hdr *cmd;
1012 const u8 *cmd_param;
1013 struct hci_event_hdr *evt = NULL;
1014 const u8 *evt_param = NULL;
1015 int remain = fw->size - (*fw_ptr - fw->data);
1016
1017 /* The first byte indicates the types of the patch command or event.
1018 * 0x01 means HCI command and 0x02 is HCI event. If the first bytes
1019 * in the current firmware buffer doesn't start with 0x01 or
1020 * the size of remain buffer is smaller than HCI command header,
1021 * the firmware file is corrupted and it should stop the patching
1022 * process.
1023 */
1024 if (remain > HCI_COMMAND_HDR_SIZE && *fw_ptr[0] != 0x01) {
1025 BT_ERR("%s Intel fw corrupted: invalid cmd read", hdev->name);
1026 return -EINVAL;
1027 }
1028 (*fw_ptr)++;
1029 remain--;
1030
1031 cmd = (struct hci_command_hdr *)(*fw_ptr);
1032 *fw_ptr += sizeof(*cmd);
1033 remain -= sizeof(*cmd);
1034
1035 /* Ensure that the remain firmware data is long enough than the length
1036 * of command parameter. If not, the firmware file is corrupted.
1037 */
1038 if (remain < cmd->plen) {
1039 BT_ERR("%s Intel fw corrupted: invalid cmd len", hdev->name);
1040 return -EFAULT;
1041 }
1042
1043 /* If there is a command that loads a patch in the firmware
1044 * file, then enable the patch upon success, otherwise just
1045 * disable the manufacturer mode, for example patch activation
1046 * is not required when the default firmware patch file is used
1047 * because there are no patch data to load.
1048 */
1049 if (*disable_patch && le16_to_cpu(cmd->opcode) == 0xfc8e)
1050 *disable_patch = 0;
1051
1052 cmd_param = *fw_ptr;
1053 *fw_ptr += cmd->plen;
1054 remain -= cmd->plen;
1055
1056 /* This reads the expected events when the above command is sent to the
1057 * device. Some vendor commands expects more than one events, for
1058 * example command status event followed by vendor specific event.
1059 * For this case, it only keeps the last expected event. so the command
1060 * can be sent with __hci_cmd_sync_ev() which returns the sk_buff of
1061 * last expected event.
1062 */
1063 while (remain > HCI_EVENT_HDR_SIZE && *fw_ptr[0] == 0x02) {
1064 (*fw_ptr)++;
1065 remain--;
1066
1067 evt = (struct hci_event_hdr *)(*fw_ptr);
1068 *fw_ptr += sizeof(*evt);
1069 remain -= sizeof(*evt);
1070
1071 if (remain < evt->plen) {
1072 BT_ERR("%s Intel fw corrupted: invalid evt len",
1073 hdev->name);
1074 return -EFAULT;
1075 }
1076
1077 evt_param = *fw_ptr;
1078 *fw_ptr += evt->plen;
1079 remain -= evt->plen;
1080 }
1081
1082 /* Every HCI commands in the firmware file has its correspond event.
1083 * If event is not found or remain is smaller than zero, the firmware
1084 * file is corrupted.
1085 */
1086 if (!evt || !evt_param || remain < 0) {
1087 BT_ERR("%s Intel fw corrupted: invalid evt read", hdev->name);
1088 return -EFAULT;
1089 }
1090
1091 skb = __hci_cmd_sync_ev(hdev, le16_to_cpu(cmd->opcode), cmd->plen,
1092 cmd_param, evt->evt, HCI_INIT_TIMEOUT);
1093 if (IS_ERR(skb)) {
1094 BT_ERR("%s sending Intel patch command (0x%4.4x) failed (%ld)",
1095 hdev->name, cmd->opcode, PTR_ERR(skb));
1096 return -PTR_ERR(skb);
1097 }
1098
1099 /* It ensures that the returned event matches the event data read from
1100 * the firmware file. At fist, it checks the length and then
1101 * the contents of the event.
1102 */
1103 if (skb->len != evt->plen) {
1104 BT_ERR("%s mismatch event length (opcode 0x%4.4x)", hdev->name,
1105 le16_to_cpu(cmd->opcode));
1106 kfree_skb(skb);
1107 return -EFAULT;
1108 }
1109
1110 if (memcmp(skb->data, evt_param, evt->plen)) {
1111 BT_ERR("%s mismatch event parameter (opcode 0x%4.4x)",
1112 hdev->name, le16_to_cpu(cmd->opcode));
1113 kfree_skb(skb);
1114 return -EFAULT;
1115 }
1116 kfree_skb(skb);
1117
1118 return 0;
1119}
1120
1121static int btusb_setup_intel(struct hci_dev *hdev)
1122{
1123 struct sk_buff *skb;
1124 const struct firmware *fw;
1125 const u8 *fw_ptr;
1126 int disable_patch;
1127 struct intel_version *ver;
1128
1129 const u8 mfg_enable[] = { 0x01, 0x00 };
1130 const u8 mfg_disable[] = { 0x00, 0x00 };
1131 const u8 mfg_reset_deactivate[] = { 0x00, 0x01 };
1132 const u8 mfg_reset_activate[] = { 0x00, 0x02 };
1133
1134 BT_DBG("%s", hdev->name);
1135
1136 /* The controller has a bug with the first HCI command sent to it
1137 * returning number of completed commands as zero. This would stall the
1138 * command processing in the Bluetooth core.
1139 *
1140 * As a workaround, send HCI Reset command first which will reset the
1141 * number of completed commands and allow normal command processing
1142 * from now on.
1143 */
1144 skb = __hci_cmd_sync(hdev, HCI_OP_RESET, 0, NULL, HCI_INIT_TIMEOUT);
1145 if (IS_ERR(skb)) {
1146 BT_ERR("%s sending initial HCI reset command failed (%ld)",
1147 hdev->name, PTR_ERR(skb));
1148 return -PTR_ERR(skb);
1149 }
1150 kfree_skb(skb);
1151
1152 /* Read Intel specific controller version first to allow selection of
1153 * which firmware file to load.
1154 *
1155 * The returned information are hardware variant and revision plus
1156 * firmware variant, revision and build number.
1157 */
1158 skb = __hci_cmd_sync(hdev, 0xfc05, 0, NULL, HCI_INIT_TIMEOUT);
1159 if (IS_ERR(skb)) {
1160 BT_ERR("%s reading Intel fw version command failed (%ld)",
1161 hdev->name, PTR_ERR(skb));
1162 return -PTR_ERR(skb);
1163 }
1164
1165 if (skb->len != sizeof(*ver)) {
1166 BT_ERR("%s Intel version event length mismatch", hdev->name);
1167 kfree_skb(skb);
1168 return -EIO;
1169 }
1170
1171 ver = (struct intel_version *)skb->data;
1172 if (ver->status) {
1173 BT_ERR("%s Intel fw version event failed (%02x)", hdev->name,
1174 ver->status);
1175 kfree_skb(skb);
1176 return -bt_to_errno(ver->status);
1177 }
1178
1179 BT_INFO("%s: read Intel version: %02x%02x%02x%02x%02x%02x%02x%02x%02x",
1180 hdev->name, ver->hw_platform, ver->hw_variant,
1181 ver->hw_revision, ver->fw_variant, ver->fw_revision,
1182 ver->fw_build_num, ver->fw_build_ww, ver->fw_build_yy,
1183 ver->fw_patch_num);
1184
1185 /* fw_patch_num indicates the version of patch the device currently
1186 * have. If there is no patch data in the device, it is always 0x00.
1187 * So, if it is other than 0x00, no need to patch the deivce again.
1188 */
1189 if (ver->fw_patch_num) {
1190 BT_INFO("%s: Intel device is already patched. patch num: %02x",
1191 hdev->name, ver->fw_patch_num);
1192 kfree_skb(skb);
1193 return 0;
1194 }
1195
1196 /* Opens the firmware patch file based on the firmware version read
1197 * from the controller. If it fails to open the matching firmware
1198 * patch file, it tries to open the default firmware patch file.
1199 * If no patch file is found, allow the device to operate without
1200 * a patch.
1201 */
1202 fw = btusb_setup_intel_get_fw(hdev, ver);
1203 if (!fw) {
1204 kfree_skb(skb);
1205 return 0;
1206 }
1207 fw_ptr = fw->data;
1208
1209 /* This Intel specific command enables the manufacturer mode of the
1210 * controller.
1211 *
1212 * Only while this mode is enabled, the driver can download the
1213 * firmware patch data and configuration parameters.
1214 */
1215 skb = __hci_cmd_sync(hdev, 0xfc11, 2, mfg_enable, HCI_INIT_TIMEOUT);
1216 if (IS_ERR(skb)) {
1217 BT_ERR("%s entering Intel manufacturer mode failed (%ld)",
1218 hdev->name, PTR_ERR(skb));
1219 release_firmware(fw);
1220 return -PTR_ERR(skb);
1221 }
1222
1223 if (skb->data[0]) {
1224 u8 evt_status = skb->data[0];
1225 BT_ERR("%s enable Intel manufacturer mode event failed (%02x)",
1226 hdev->name, evt_status);
1227 kfree_skb(skb);
1228 release_firmware(fw);
1229 return -bt_to_errno(evt_status);
1230 }
1231 kfree_skb(skb);
1232
1233 disable_patch = 1;
1234
1235 /* The firmware data file consists of list of Intel specific HCI
1236 * commands and its expected events. The first byte indicates the
1237 * type of the message, either HCI command or HCI event.
1238 *
1239 * It reads the command and its expected event from the firmware file,
1240 * and send to the controller. Once __hci_cmd_sync_ev() returns,
1241 * the returned event is compared with the event read from the firmware
1242 * file and it will continue until all the messages are downloaded to
1243 * the controller.
1244 *
1245 * Once the firmware patching is completed successfully,
1246 * the manufacturer mode is disabled with reset and activating the
1247 * downloaded patch.
1248 *
1249 * If the firmware patching fails, the manufacturer mode is
1250 * disabled with reset and deactivating the patch.
1251 *
1252 * If the default patch file is used, no reset is done when disabling
1253 * the manufacturer.
1254 */
1255 while (fw->size > fw_ptr - fw->data) {
1256 int ret;
1257
1258 ret = btusb_setup_intel_patching(hdev, fw, &fw_ptr,
1259 &disable_patch);
1260 if (ret < 0)
1261 goto exit_mfg_deactivate;
1262 }
1263
1264 release_firmware(fw);
1265
1266 if (disable_patch)
1267 goto exit_mfg_disable;
1268
1269 /* Patching completed successfully and disable the manufacturer mode
1270 * with reset and activate the downloaded firmware patches.
1271 */
1272 skb = __hci_cmd_sync(hdev, 0xfc11, sizeof(mfg_reset_activate),
1273 mfg_reset_activate, HCI_INIT_TIMEOUT);
1274 if (IS_ERR(skb)) {
1275 BT_ERR("%s exiting Intel manufacturer mode failed (%ld)",
1276 hdev->name, PTR_ERR(skb));
1277 return -PTR_ERR(skb);
1278 }
1279 kfree_skb(skb);
1280
1281 BT_INFO("%s: Intel Bluetooth firmware patch completed and activated",
1282 hdev->name);
1283
1284 return 0;
1285
1286exit_mfg_disable:
1287 /* Disable the manufacturer mode without reset */
1288 skb = __hci_cmd_sync(hdev, 0xfc11, sizeof(mfg_disable), mfg_disable,
1289 HCI_INIT_TIMEOUT);
1290 if (IS_ERR(skb)) {
1291 BT_ERR("%s exiting Intel manufacturer mode failed (%ld)",
1292 hdev->name, PTR_ERR(skb));
1293 return -PTR_ERR(skb);
1294 }
1295 kfree_skb(skb);
1296
1297 BT_INFO("%s: Intel Bluetooth firmware patch completed", hdev->name);
1298 return 0;
1299
1300exit_mfg_deactivate:
1301 release_firmware(fw);
1302
1303 /* Patching failed. Disable the manufacturer mode with reset and
1304 * deactivate the downloaded firmware patches.
1305 */
1306 skb = __hci_cmd_sync(hdev, 0xfc11, sizeof(mfg_reset_deactivate),
1307 mfg_reset_deactivate, HCI_INIT_TIMEOUT);
1308 if (IS_ERR(skb)) {
1309 BT_ERR("%s exiting Intel manufacturer mode failed (%ld)",
1310 hdev->name, PTR_ERR(skb));
1311 return -PTR_ERR(skb);
1312 }
1313 kfree_skb(skb);
1314
1315 BT_INFO("%s: Intel Bluetooth firmware patch completed and deactivated",
1316 hdev->name);
1317
1318 return 0;
1319}
1320
5e23b923
MH
1321static int btusb_probe(struct usb_interface *intf,
1322 const struct usb_device_id *id)
1323{
1324 struct usb_endpoint_descriptor *ep_desc;
1325 struct btusb_data *data;
1326 struct hci_dev *hdev;
1327 int i, err;
1328
1329 BT_DBG("intf %p id %p", intf, id);
1330
cfeb4145 1331 /* interface numbers are hardcoded in the spec */
5e23b923
MH
1332 if (intf->cur_altsetting->desc.bInterfaceNumber != 0)
1333 return -ENODEV;
1334
1335 if (!id->driver_info) {
1336 const struct usb_device_id *match;
1337 match = usb_match_id(intf, blacklist_table);
1338 if (match)
1339 id = match;
1340 }
1341
cfeb4145
MH
1342 if (id->driver_info == BTUSB_IGNORE)
1343 return -ENODEV;
1344
1345 if (ignore_dga && id->driver_info & BTUSB_DIGIANSWER)
1346 return -ENODEV;
1347
1348 if (ignore_csr && id->driver_info & BTUSB_CSR)
1349 return -ENODEV;
1350
1351 if (ignore_sniffer && id->driver_info & BTUSB_SNIFFER)
1352 return -ENODEV;
1353
2d25f8b4
SL
1354 if (id->driver_info & BTUSB_ATH3012) {
1355 struct usb_device *udev = interface_to_usbdev(intf);
1356
1357 /* Old firmware would otherwise let ath3k driver load
1358 * patch and sysconfig files */
1359 if (le16_to_cpu(udev->descriptor.bcdDevice) <= 0x0001)
1360 return -ENODEV;
1361 }
1362
98921dbd 1363 data = devm_kzalloc(&intf->dev, sizeof(*data), GFP_KERNEL);
5e23b923
MH
1364 if (!data)
1365 return -ENOMEM;
1366
1367 for (i = 0; i < intf->cur_altsetting->desc.bNumEndpoints; i++) {
1368 ep_desc = &intf->cur_altsetting->endpoint[i].desc;
1369
1370 if (!data->intr_ep && usb_endpoint_is_int_in(ep_desc)) {
1371 data->intr_ep = ep_desc;
1372 continue;
1373 }
1374
1375 if (!data->bulk_tx_ep && usb_endpoint_is_bulk_out(ep_desc)) {
1376 data->bulk_tx_ep = ep_desc;
1377 continue;
1378 }
1379
1380 if (!data->bulk_rx_ep && usb_endpoint_is_bulk_in(ep_desc)) {
1381 data->bulk_rx_ep = ep_desc;
1382 continue;
1383 }
1384 }
1385
98921dbd 1386 if (!data->intr_ep || !data->bulk_tx_ep || !data->bulk_rx_ep)
5e23b923 1387 return -ENODEV;
5e23b923 1388
7a9d4020
MH
1389 data->cmdreq_type = USB_TYPE_CLASS;
1390
5e23b923 1391 data->udev = interface_to_usbdev(intf);
5fbcd260 1392 data->intf = intf;
5e23b923
MH
1393
1394 spin_lock_init(&data->lock);
1395
1396 INIT_WORK(&data->work, btusb_work);
7bee549e
ON
1397 INIT_WORK(&data->waker, btusb_waker);
1398 spin_lock_init(&data->txlock);
5e23b923
MH
1399
1400 init_usb_anchor(&data->tx_anchor);
1401 init_usb_anchor(&data->intr_anchor);
1402 init_usb_anchor(&data->bulk_anchor);
9bfa35fe 1403 init_usb_anchor(&data->isoc_anchor);
7bee549e 1404 init_usb_anchor(&data->deferred);
5e23b923
MH
1405
1406 hdev = hci_alloc_dev();
98921dbd 1407 if (!hdev)
5e23b923 1408 return -ENOMEM;
5e23b923 1409
c13854ce 1410 hdev->bus = HCI_USB;
155961e8 1411 hci_set_drvdata(hdev, data);
5e23b923
MH
1412
1413 data->hdev = hdev;
1414
1415 SET_HCIDEV_DEV(hdev, &intf->dev);
1416
9f8f962c
MH
1417 hdev->open = btusb_open;
1418 hdev->close = btusb_close;
1419 hdev->flush = btusb_flush;
1420 hdev->send = btusb_send_frame;
1421 hdev->notify = btusb_notify;
1422
1423 if (id->driver_info & BTUSB_BCM92035)
1424 hdev->setup = btusb_setup_bcm92035;
5e23b923 1425
dffd30ee
THJA
1426 if (id->driver_info & BTUSB_INTEL)
1427 hdev->setup = btusb_setup_intel;
1428
7a9d4020 1429 /* Interface numbers are hardcoded in the specification */
9bfa35fe
MH
1430 data->isoc = usb_ifnum_to_if(data->udev, 1);
1431
7a9d4020 1432 if (!reset)
a6c511c6 1433 set_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks);
cfeb4145
MH
1434
1435 if (force_scofix || id->driver_info & BTUSB_WRONG_SCO_MTU) {
1436 if (!disable_scofix)
1437 set_bit(HCI_QUIRK_FIXUP_BUFFER_SIZE, &hdev->quirks);
1438 }
1439
9bfa35fe
MH
1440 if (id->driver_info & BTUSB_BROKEN_ISOC)
1441 data->isoc = NULL;
1442
7a9d4020
MH
1443 if (id->driver_info & BTUSB_DIGIANSWER) {
1444 data->cmdreq_type = USB_TYPE_VENDOR;
a6c511c6 1445 set_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks);
7a9d4020
MH
1446 }
1447
1448 if (id->driver_info & BTUSB_CSR) {
1449 struct usb_device *udev = data->udev;
1450
1451 /* Old firmware would otherwise execute USB reset */
1452 if (le16_to_cpu(udev->descriptor.bcdDevice) < 0x117)
a6c511c6 1453 set_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks);
7a9d4020
MH
1454 }
1455
cfeb4145 1456 if (id->driver_info & BTUSB_SNIFFER) {
9bfa35fe 1457 struct usb_device *udev = data->udev;
cfeb4145 1458
7a9d4020 1459 /* New sniffer firmware has crippled HCI interface */
cfeb4145
MH
1460 if (le16_to_cpu(udev->descriptor.bcdDevice) > 0x997)
1461 set_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks);
9bfa35fe
MH
1462
1463 data->isoc = NULL;
cfeb4145
MH
1464 }
1465
9bfa35fe
MH
1466 if (data->isoc) {
1467 err = usb_driver_claim_interface(&btusb_driver,
5fbcd260 1468 data->isoc, data);
9bfa35fe
MH
1469 if (err < 0) {
1470 hci_free_dev(hdev);
9bfa35fe
MH
1471 return err;
1472 }
1473 }
1474
5e23b923
MH
1475 err = hci_register_dev(hdev);
1476 if (err < 0) {
1477 hci_free_dev(hdev);
5e23b923
MH
1478 return err;
1479 }
1480
1481 usb_set_intfdata(intf, data);
1482
1483 return 0;
1484}
1485
1486static void btusb_disconnect(struct usb_interface *intf)
1487{
1488 struct btusb_data *data = usb_get_intfdata(intf);
1489 struct hci_dev *hdev;
1490
1491 BT_DBG("intf %p", intf);
1492
1493 if (!data)
1494 return;
1495
1496 hdev = data->hdev;
5fbcd260
MH
1497 usb_set_intfdata(data->intf, NULL);
1498
1499 if (data->isoc)
1500 usb_set_intfdata(data->isoc, NULL);
5e23b923
MH
1501
1502 hci_unregister_dev(hdev);
1503
5fbcd260
MH
1504 if (intf == data->isoc)
1505 usb_driver_release_interface(&btusb_driver, data->intf);
1506 else if (data->isoc)
1507 usb_driver_release_interface(&btusb_driver, data->isoc);
1508
5e23b923
MH
1509 hci_free_dev(hdev);
1510}
1511
7bee549e 1512#ifdef CONFIG_PM
6a88adf2
MH
1513static int btusb_suspend(struct usb_interface *intf, pm_message_t message)
1514{
1515 struct btusb_data *data = usb_get_intfdata(intf);
1516
1517 BT_DBG("intf %p", intf);
1518
1519 if (data->suspend_count++)
1520 return 0;
1521
7bee549e 1522 spin_lock_irq(&data->txlock);
5b1b0b81 1523 if (!(PMSG_IS_AUTO(message) && data->tx_in_flight)) {
7bee549e
ON
1524 set_bit(BTUSB_SUSPENDING, &data->flags);
1525 spin_unlock_irq(&data->txlock);
1526 } else {
1527 spin_unlock_irq(&data->txlock);
1528 data->suspend_count--;
1529 return -EBUSY;
1530 }
1531
6a88adf2
MH
1532 cancel_work_sync(&data->work);
1533
7bee549e 1534 btusb_stop_traffic(data);
6a88adf2
MH
1535 usb_kill_anchored_urbs(&data->tx_anchor);
1536
6a88adf2
MH
1537 return 0;
1538}
1539
7bee549e
ON
1540static void play_deferred(struct btusb_data *data)
1541{
1542 struct urb *urb;
1543 int err;
1544
1545 while ((urb = usb_get_from_anchor(&data->deferred))) {
1546 err = usb_submit_urb(urb, GFP_ATOMIC);
1547 if (err < 0)
1548 break;
1549
1550 data->tx_in_flight++;
1551 }
1552 usb_scuttle_anchored_urbs(&data->deferred);
1553}
1554
6a88adf2
MH
1555static int btusb_resume(struct usb_interface *intf)
1556{
1557 struct btusb_data *data = usb_get_intfdata(intf);
1558 struct hci_dev *hdev = data->hdev;
7bee549e 1559 int err = 0;
6a88adf2
MH
1560
1561 BT_DBG("intf %p", intf);
1562
1563 if (--data->suspend_count)
1564 return 0;
1565
1566 if (!test_bit(HCI_RUNNING, &hdev->flags))
7bee549e 1567 goto done;
6a88adf2
MH
1568
1569 if (test_bit(BTUSB_INTR_RUNNING, &data->flags)) {
1570 err = btusb_submit_intr_urb(hdev, GFP_NOIO);
1571 if (err < 0) {
1572 clear_bit(BTUSB_INTR_RUNNING, &data->flags);
7bee549e 1573 goto failed;
6a88adf2
MH
1574 }
1575 }
1576
1577 if (test_bit(BTUSB_BULK_RUNNING, &data->flags)) {
43c2e57f
MH
1578 err = btusb_submit_bulk_urb(hdev, GFP_NOIO);
1579 if (err < 0) {
6a88adf2 1580 clear_bit(BTUSB_BULK_RUNNING, &data->flags);
7bee549e
ON
1581 goto failed;
1582 }
1583
1584 btusb_submit_bulk_urb(hdev, GFP_NOIO);
6a88adf2
MH
1585 }
1586
1587 if (test_bit(BTUSB_ISOC_RUNNING, &data->flags)) {
1588 if (btusb_submit_isoc_urb(hdev, GFP_NOIO) < 0)
1589 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
1590 else
1591 btusb_submit_isoc_urb(hdev, GFP_NOIO);
1592 }
1593
7bee549e
ON
1594 spin_lock_irq(&data->txlock);
1595 play_deferred(data);
1596 clear_bit(BTUSB_SUSPENDING, &data->flags);
1597 spin_unlock_irq(&data->txlock);
1598 schedule_work(&data->work);
1599
6a88adf2 1600 return 0;
7bee549e
ON
1601
1602failed:
1603 usb_scuttle_anchored_urbs(&data->deferred);
1604done:
1605 spin_lock_irq(&data->txlock);
1606 clear_bit(BTUSB_SUSPENDING, &data->flags);
1607 spin_unlock_irq(&data->txlock);
1608
1609 return err;
6a88adf2 1610}
7bee549e 1611#endif
6a88adf2 1612
5e23b923
MH
1613static struct usb_driver btusb_driver = {
1614 .name = "btusb",
1615 .probe = btusb_probe,
1616 .disconnect = btusb_disconnect,
7bee549e 1617#ifdef CONFIG_PM
6a88adf2
MH
1618 .suspend = btusb_suspend,
1619 .resume = btusb_resume,
7bee549e 1620#endif
5e23b923 1621 .id_table = btusb_table,
7bee549e 1622 .supports_autosuspend = 1,
e1f12eb6 1623 .disable_hub_initiated_lpm = 1,
5e23b923
MH
1624};
1625
93f1508c 1626module_usb_driver(btusb_driver);
5e23b923 1627
cfeb4145
MH
1628module_param(ignore_dga, bool, 0644);
1629MODULE_PARM_DESC(ignore_dga, "Ignore devices with id 08fd:0001");
1630
1631module_param(ignore_csr, bool, 0644);
1632MODULE_PARM_DESC(ignore_csr, "Ignore devices with id 0a12:0001");
1633
1634module_param(ignore_sniffer, bool, 0644);
1635MODULE_PARM_DESC(ignore_sniffer, "Ignore devices with id 0a12:0002");
1636
1637module_param(disable_scofix, bool, 0644);
1638MODULE_PARM_DESC(disable_scofix, "Disable fixup of wrong SCO buffer size");
1639
1640module_param(force_scofix, bool, 0644);
1641MODULE_PARM_DESC(force_scofix, "Force fixup of wrong SCO buffers size");
1642
1643module_param(reset, bool, 0644);
1644MODULE_PARM_DESC(reset, "Send HCI reset command on initialization");
1645
5e23b923
MH
1646MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
1647MODULE_DESCRIPTION("Generic Bluetooth USB driver ver " VERSION);
1648MODULE_VERSION(VERSION);
1649MODULE_LICENSE("GPL");