18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later
28c2ecf20Sopenharmony_ci/*
38c2ecf20Sopenharmony_ci *
48c2ecf20Sopenharmony_ci *  Bluetooth HCI UART driver
58c2ecf20Sopenharmony_ci *
68c2ecf20Sopenharmony_ci *  Copyright (C) 2000-2001  Qualcomm Incorporated
78c2ecf20Sopenharmony_ci *  Copyright (C) 2002-2003  Maxim Krasnyansky <maxk@qualcomm.com>
88c2ecf20Sopenharmony_ci *  Copyright (C) 2004-2005  Marcel Holtmann <marcel@holtmann.org>
98c2ecf20Sopenharmony_ci */
108c2ecf20Sopenharmony_ci
118c2ecf20Sopenharmony_ci#include <linux/module.h>
128c2ecf20Sopenharmony_ci
138c2ecf20Sopenharmony_ci#include <linux/kernel.h>
148c2ecf20Sopenharmony_ci#include <linux/init.h>
158c2ecf20Sopenharmony_ci#include <linux/types.h>
168c2ecf20Sopenharmony_ci#include <linux/fcntl.h>
178c2ecf20Sopenharmony_ci#include <linux/interrupt.h>
188c2ecf20Sopenharmony_ci#include <linux/ptrace.h>
198c2ecf20Sopenharmony_ci#include <linux/poll.h>
208c2ecf20Sopenharmony_ci
218c2ecf20Sopenharmony_ci#include <linux/slab.h>
228c2ecf20Sopenharmony_ci#include <linux/tty.h>
238c2ecf20Sopenharmony_ci#include <linux/errno.h>
248c2ecf20Sopenharmony_ci#include <linux/string.h>
258c2ecf20Sopenharmony_ci#include <linux/signal.h>
268c2ecf20Sopenharmony_ci#include <linux/ioctl.h>
278c2ecf20Sopenharmony_ci#include <linux/skbuff.h>
288c2ecf20Sopenharmony_ci#include <asm/unaligned.h>
298c2ecf20Sopenharmony_ci
308c2ecf20Sopenharmony_ci#include <net/bluetooth/bluetooth.h>
318c2ecf20Sopenharmony_ci#include <net/bluetooth/hci_core.h>
328c2ecf20Sopenharmony_ci
338c2ecf20Sopenharmony_ci#include "hci_uart.h"
348c2ecf20Sopenharmony_ci
358c2ecf20Sopenharmony_cistruct h4_struct {
368c2ecf20Sopenharmony_ci	struct sk_buff *rx_skb;
378c2ecf20Sopenharmony_ci	struct sk_buff_head txq;
388c2ecf20Sopenharmony_ci};
398c2ecf20Sopenharmony_ci
408c2ecf20Sopenharmony_ci/* Initialize protocol */
418c2ecf20Sopenharmony_cistatic int h4_open(struct hci_uart *hu)
428c2ecf20Sopenharmony_ci{
438c2ecf20Sopenharmony_ci	struct h4_struct *h4;
448c2ecf20Sopenharmony_ci
458c2ecf20Sopenharmony_ci	BT_DBG("hu %p", hu);
468c2ecf20Sopenharmony_ci
478c2ecf20Sopenharmony_ci	h4 = kzalloc(sizeof(*h4), GFP_KERNEL);
488c2ecf20Sopenharmony_ci	if (!h4)
498c2ecf20Sopenharmony_ci		return -ENOMEM;
508c2ecf20Sopenharmony_ci
518c2ecf20Sopenharmony_ci	skb_queue_head_init(&h4->txq);
528c2ecf20Sopenharmony_ci
538c2ecf20Sopenharmony_ci	hu->priv = h4;
548c2ecf20Sopenharmony_ci	return 0;
558c2ecf20Sopenharmony_ci}
568c2ecf20Sopenharmony_ci
578c2ecf20Sopenharmony_ci/* Flush protocol data */
588c2ecf20Sopenharmony_cistatic int h4_flush(struct hci_uart *hu)
598c2ecf20Sopenharmony_ci{
608c2ecf20Sopenharmony_ci	struct h4_struct *h4 = hu->priv;
618c2ecf20Sopenharmony_ci
628c2ecf20Sopenharmony_ci	BT_DBG("hu %p", hu);
638c2ecf20Sopenharmony_ci
648c2ecf20Sopenharmony_ci	skb_queue_purge(&h4->txq);
658c2ecf20Sopenharmony_ci
668c2ecf20Sopenharmony_ci	return 0;
678c2ecf20Sopenharmony_ci}
688c2ecf20Sopenharmony_ci
698c2ecf20Sopenharmony_ci/* Close protocol */
708c2ecf20Sopenharmony_cistatic int h4_close(struct hci_uart *hu)
718c2ecf20Sopenharmony_ci{
728c2ecf20Sopenharmony_ci	struct h4_struct *h4 = hu->priv;
738c2ecf20Sopenharmony_ci
748c2ecf20Sopenharmony_ci	BT_DBG("hu %p", hu);
758c2ecf20Sopenharmony_ci
768c2ecf20Sopenharmony_ci	skb_queue_purge(&h4->txq);
778c2ecf20Sopenharmony_ci
788c2ecf20Sopenharmony_ci	kfree_skb(h4->rx_skb);
798c2ecf20Sopenharmony_ci
808c2ecf20Sopenharmony_ci	hu->priv = NULL;
818c2ecf20Sopenharmony_ci	kfree(h4);
828c2ecf20Sopenharmony_ci
838c2ecf20Sopenharmony_ci	return 0;
848c2ecf20Sopenharmony_ci}
858c2ecf20Sopenharmony_ci
868c2ecf20Sopenharmony_ci/* Enqueue frame for transmission (padding, crc, etc) */
878c2ecf20Sopenharmony_cistatic int h4_enqueue(struct hci_uart *hu, struct sk_buff *skb)
888c2ecf20Sopenharmony_ci{
898c2ecf20Sopenharmony_ci	struct h4_struct *h4 = hu->priv;
908c2ecf20Sopenharmony_ci
918c2ecf20Sopenharmony_ci	BT_DBG("hu %p skb %p", hu, skb);
928c2ecf20Sopenharmony_ci
938c2ecf20Sopenharmony_ci	/* Prepend skb with frame type */
948c2ecf20Sopenharmony_ci	memcpy(skb_push(skb, 1), &hci_skb_pkt_type(skb), 1);
958c2ecf20Sopenharmony_ci	skb_queue_tail(&h4->txq, skb);
968c2ecf20Sopenharmony_ci
978c2ecf20Sopenharmony_ci	return 0;
988c2ecf20Sopenharmony_ci}
998c2ecf20Sopenharmony_ci
1008c2ecf20Sopenharmony_cistatic const struct h4_recv_pkt h4_recv_pkts[] = {
1018c2ecf20Sopenharmony_ci	{ H4_RECV_ACL,   .recv = hci_recv_frame },
1028c2ecf20Sopenharmony_ci	{ H4_RECV_SCO,   .recv = hci_recv_frame },
1038c2ecf20Sopenharmony_ci	{ H4_RECV_EVENT, .recv = hci_recv_frame },
1048c2ecf20Sopenharmony_ci	{ H4_RECV_ISO,   .recv = hci_recv_frame },
1058c2ecf20Sopenharmony_ci};
1068c2ecf20Sopenharmony_ci
1078c2ecf20Sopenharmony_ci/* Recv data */
1088c2ecf20Sopenharmony_cistatic int h4_recv(struct hci_uart *hu, const void *data, int count)
1098c2ecf20Sopenharmony_ci{
1108c2ecf20Sopenharmony_ci	struct h4_struct *h4 = hu->priv;
1118c2ecf20Sopenharmony_ci
1128c2ecf20Sopenharmony_ci	if (!test_bit(HCI_UART_REGISTERED, &hu->flags))
1138c2ecf20Sopenharmony_ci		return -EUNATCH;
1148c2ecf20Sopenharmony_ci
1158c2ecf20Sopenharmony_ci	h4->rx_skb = h4_recv_buf(hu->hdev, h4->rx_skb, data, count,
1168c2ecf20Sopenharmony_ci				 h4_recv_pkts, ARRAY_SIZE(h4_recv_pkts));
1178c2ecf20Sopenharmony_ci	if (IS_ERR(h4->rx_skb)) {
1188c2ecf20Sopenharmony_ci		int err = PTR_ERR(h4->rx_skb);
1198c2ecf20Sopenharmony_ci		bt_dev_err(hu->hdev, "Frame reassembly failed (%d)", err);
1208c2ecf20Sopenharmony_ci		h4->rx_skb = NULL;
1218c2ecf20Sopenharmony_ci		return err;
1228c2ecf20Sopenharmony_ci	}
1238c2ecf20Sopenharmony_ci
1248c2ecf20Sopenharmony_ci	return count;
1258c2ecf20Sopenharmony_ci}
1268c2ecf20Sopenharmony_ci
1278c2ecf20Sopenharmony_cistatic struct sk_buff *h4_dequeue(struct hci_uart *hu)
1288c2ecf20Sopenharmony_ci{
1298c2ecf20Sopenharmony_ci	struct h4_struct *h4 = hu->priv;
1308c2ecf20Sopenharmony_ci	return skb_dequeue(&h4->txq);
1318c2ecf20Sopenharmony_ci}
1328c2ecf20Sopenharmony_ci
1338c2ecf20Sopenharmony_cistatic const struct hci_uart_proto h4p = {
1348c2ecf20Sopenharmony_ci	.id		= HCI_UART_H4,
1358c2ecf20Sopenharmony_ci	.name		= "H4",
1368c2ecf20Sopenharmony_ci	.open		= h4_open,
1378c2ecf20Sopenharmony_ci	.close		= h4_close,
1388c2ecf20Sopenharmony_ci	.recv		= h4_recv,
1398c2ecf20Sopenharmony_ci	.enqueue	= h4_enqueue,
1408c2ecf20Sopenharmony_ci	.dequeue	= h4_dequeue,
1418c2ecf20Sopenharmony_ci	.flush		= h4_flush,
1428c2ecf20Sopenharmony_ci};
1438c2ecf20Sopenharmony_ci
1448c2ecf20Sopenharmony_ciint __init h4_init(void)
1458c2ecf20Sopenharmony_ci{
1468c2ecf20Sopenharmony_ci	return hci_uart_register_proto(&h4p);
1478c2ecf20Sopenharmony_ci}
1488c2ecf20Sopenharmony_ci
1498c2ecf20Sopenharmony_ciint __exit h4_deinit(void)
1508c2ecf20Sopenharmony_ci{
1518c2ecf20Sopenharmony_ci	return hci_uart_unregister_proto(&h4p);
1528c2ecf20Sopenharmony_ci}
1538c2ecf20Sopenharmony_ci
1548c2ecf20Sopenharmony_cistruct sk_buff *h4_recv_buf(struct hci_dev *hdev, struct sk_buff *skb,
1558c2ecf20Sopenharmony_ci			    const unsigned char *buffer, int count,
1568c2ecf20Sopenharmony_ci			    const struct h4_recv_pkt *pkts, int pkts_count)
1578c2ecf20Sopenharmony_ci{
1588c2ecf20Sopenharmony_ci	struct hci_uart *hu = hci_get_drvdata(hdev);
1598c2ecf20Sopenharmony_ci	u8 alignment = hu->alignment ? hu->alignment : 1;
1608c2ecf20Sopenharmony_ci
1618c2ecf20Sopenharmony_ci	/* Check for error from previous call */
1628c2ecf20Sopenharmony_ci	if (IS_ERR(skb))
1638c2ecf20Sopenharmony_ci		skb = NULL;
1648c2ecf20Sopenharmony_ci
1658c2ecf20Sopenharmony_ci	while (count) {
1668c2ecf20Sopenharmony_ci		int i, len;
1678c2ecf20Sopenharmony_ci
1688c2ecf20Sopenharmony_ci		/* remove padding bytes from buffer */
1698c2ecf20Sopenharmony_ci		for (; hu->padding && count > 0; hu->padding--) {
1708c2ecf20Sopenharmony_ci			count--;
1718c2ecf20Sopenharmony_ci			buffer++;
1728c2ecf20Sopenharmony_ci		}
1738c2ecf20Sopenharmony_ci		if (!count)
1748c2ecf20Sopenharmony_ci			break;
1758c2ecf20Sopenharmony_ci
1768c2ecf20Sopenharmony_ci		if (!skb) {
1778c2ecf20Sopenharmony_ci			for (i = 0; i < pkts_count; i++) {
1788c2ecf20Sopenharmony_ci				if (buffer[0] != (&pkts[i])->type)
1798c2ecf20Sopenharmony_ci					continue;
1808c2ecf20Sopenharmony_ci
1818c2ecf20Sopenharmony_ci				skb = bt_skb_alloc((&pkts[i])->maxlen,
1828c2ecf20Sopenharmony_ci						   GFP_ATOMIC);
1838c2ecf20Sopenharmony_ci				if (!skb)
1848c2ecf20Sopenharmony_ci					return ERR_PTR(-ENOMEM);
1858c2ecf20Sopenharmony_ci
1868c2ecf20Sopenharmony_ci				hci_skb_pkt_type(skb) = (&pkts[i])->type;
1878c2ecf20Sopenharmony_ci				hci_skb_expect(skb) = (&pkts[i])->hlen;
1888c2ecf20Sopenharmony_ci				break;
1898c2ecf20Sopenharmony_ci			}
1908c2ecf20Sopenharmony_ci
1918c2ecf20Sopenharmony_ci			/* Check for invalid packet type */
1928c2ecf20Sopenharmony_ci			if (!skb)
1938c2ecf20Sopenharmony_ci				return ERR_PTR(-EILSEQ);
1948c2ecf20Sopenharmony_ci
1958c2ecf20Sopenharmony_ci			count -= 1;
1968c2ecf20Sopenharmony_ci			buffer += 1;
1978c2ecf20Sopenharmony_ci		}
1988c2ecf20Sopenharmony_ci
1998c2ecf20Sopenharmony_ci		len = min_t(uint, hci_skb_expect(skb) - skb->len, count);
2008c2ecf20Sopenharmony_ci		skb_put_data(skb, buffer, len);
2018c2ecf20Sopenharmony_ci
2028c2ecf20Sopenharmony_ci		count -= len;
2038c2ecf20Sopenharmony_ci		buffer += len;
2048c2ecf20Sopenharmony_ci
2058c2ecf20Sopenharmony_ci		/* Check for partial packet */
2068c2ecf20Sopenharmony_ci		if (skb->len < hci_skb_expect(skb))
2078c2ecf20Sopenharmony_ci			continue;
2088c2ecf20Sopenharmony_ci
2098c2ecf20Sopenharmony_ci		for (i = 0; i < pkts_count; i++) {
2108c2ecf20Sopenharmony_ci			if (hci_skb_pkt_type(skb) == (&pkts[i])->type)
2118c2ecf20Sopenharmony_ci				break;
2128c2ecf20Sopenharmony_ci		}
2138c2ecf20Sopenharmony_ci
2148c2ecf20Sopenharmony_ci		if (i >= pkts_count) {
2158c2ecf20Sopenharmony_ci			kfree_skb(skb);
2168c2ecf20Sopenharmony_ci			return ERR_PTR(-EILSEQ);
2178c2ecf20Sopenharmony_ci		}
2188c2ecf20Sopenharmony_ci
2198c2ecf20Sopenharmony_ci		if (skb->len == (&pkts[i])->hlen) {
2208c2ecf20Sopenharmony_ci			u16 dlen;
2218c2ecf20Sopenharmony_ci
2228c2ecf20Sopenharmony_ci			switch ((&pkts[i])->lsize) {
2238c2ecf20Sopenharmony_ci			case 0:
2248c2ecf20Sopenharmony_ci				/* No variable data length */
2258c2ecf20Sopenharmony_ci				dlen = 0;
2268c2ecf20Sopenharmony_ci				break;
2278c2ecf20Sopenharmony_ci			case 1:
2288c2ecf20Sopenharmony_ci				/* Single octet variable length */
2298c2ecf20Sopenharmony_ci				dlen = skb->data[(&pkts[i])->loff];
2308c2ecf20Sopenharmony_ci				hci_skb_expect(skb) += dlen;
2318c2ecf20Sopenharmony_ci
2328c2ecf20Sopenharmony_ci				if (skb_tailroom(skb) < dlen) {
2338c2ecf20Sopenharmony_ci					kfree_skb(skb);
2348c2ecf20Sopenharmony_ci					return ERR_PTR(-EMSGSIZE);
2358c2ecf20Sopenharmony_ci				}
2368c2ecf20Sopenharmony_ci				break;
2378c2ecf20Sopenharmony_ci			case 2:
2388c2ecf20Sopenharmony_ci				/* Double octet variable length */
2398c2ecf20Sopenharmony_ci				dlen = get_unaligned_le16(skb->data +
2408c2ecf20Sopenharmony_ci							  (&pkts[i])->loff);
2418c2ecf20Sopenharmony_ci				hci_skb_expect(skb) += dlen;
2428c2ecf20Sopenharmony_ci
2438c2ecf20Sopenharmony_ci				if (skb_tailroom(skb) < dlen) {
2448c2ecf20Sopenharmony_ci					kfree_skb(skb);
2458c2ecf20Sopenharmony_ci					return ERR_PTR(-EMSGSIZE);
2468c2ecf20Sopenharmony_ci				}
2478c2ecf20Sopenharmony_ci				break;
2488c2ecf20Sopenharmony_ci			default:
2498c2ecf20Sopenharmony_ci				/* Unsupported variable length */
2508c2ecf20Sopenharmony_ci				kfree_skb(skb);
2518c2ecf20Sopenharmony_ci				return ERR_PTR(-EILSEQ);
2528c2ecf20Sopenharmony_ci			}
2538c2ecf20Sopenharmony_ci
2548c2ecf20Sopenharmony_ci			if (!dlen) {
2558c2ecf20Sopenharmony_ci				hu->padding = (skb->len - 1) % alignment;
2568c2ecf20Sopenharmony_ci				hu->padding = (alignment - hu->padding) % alignment;
2578c2ecf20Sopenharmony_ci
2588c2ecf20Sopenharmony_ci				/* No more data, complete frame */
2598c2ecf20Sopenharmony_ci				(&pkts[i])->recv(hdev, skb);
2608c2ecf20Sopenharmony_ci				skb = NULL;
2618c2ecf20Sopenharmony_ci			}
2628c2ecf20Sopenharmony_ci		} else {
2638c2ecf20Sopenharmony_ci			hu->padding = (skb->len - 1) % alignment;
2648c2ecf20Sopenharmony_ci			hu->padding = (alignment - hu->padding) % alignment;
2658c2ecf20Sopenharmony_ci
2668c2ecf20Sopenharmony_ci			/* Complete frame */
2678c2ecf20Sopenharmony_ci			(&pkts[i])->recv(hdev, skb);
2688c2ecf20Sopenharmony_ci			skb = NULL;
2698c2ecf20Sopenharmony_ci		}
2708c2ecf20Sopenharmony_ci	}
2718c2ecf20Sopenharmony_ci
2728c2ecf20Sopenharmony_ci	return skb;
2738c2ecf20Sopenharmony_ci}
2748c2ecf20Sopenharmony_ciEXPORT_SYMBOL_GPL(h4_recv_buf);
275