1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3 *
4 * Bluetooth HCI UART driver
5 *
6 * Copyright (C) 2000-2001 Qualcomm Incorporated
7 * Copyright (C) 2002-2003 Maxim Krasnyansky <maxk@qualcomm.com>
8 * Copyright (C) 2004-2005 Marcel Holtmann <marcel@holtmann.org>
9 */
10
11 #include <linux/module.h>
12
13 #include <linux/kernel.h>
14 #include <linux/init.h>
15 #include <linux/types.h>
16 #include <linux/fcntl.h>
17 #include <linux/interrupt.h>
18 #include <linux/ptrace.h>
19 #include <linux/poll.h>
20
21 #include <linux/slab.h>
22 #include <linux/tty.h>
23 #include <linux/errno.h>
24 #include <linux/string.h>
25 #include <linux/signal.h>
26 #include <linux/ioctl.h>
27 #include <linux/skbuff.h>
28 #include <linux/firmware.h>
29 #include <linux/serdev.h>
30
31 #include <net/bluetooth/bluetooth.h>
32 #include <net/bluetooth/hci_core.h>
33
34 #include "btintel.h"
35 #include "btbcm.h"
36 #include "hci_uart.h"
37
38 #define VERSION "2.3"
39
40 static const struct hci_uart_proto *hup[HCI_UART_MAX_PROTO];
41
hci_uart_register_proto(const struct hci_uart_proto * p)42 int hci_uart_register_proto(const struct hci_uart_proto *p)
43 {
44 if (p->id >= HCI_UART_MAX_PROTO)
45 return -EINVAL;
46
47 if (hup[p->id])
48 return -EEXIST;
49
50 hup[p->id] = p;
51
52 BT_INFO("HCI UART protocol %s registered", p->name);
53
54 return 0;
55 }
56
hci_uart_unregister_proto(const struct hci_uart_proto * p)57 int hci_uart_unregister_proto(const struct hci_uart_proto *p)
58 {
59 if (p->id >= HCI_UART_MAX_PROTO)
60 return -EINVAL;
61
62 if (!hup[p->id])
63 return -EINVAL;
64
65 hup[p->id] = NULL;
66
67 return 0;
68 }
69
hci_uart_get_proto(unsigned int id)70 static const struct hci_uart_proto *hci_uart_get_proto(unsigned int id)
71 {
72 if (id >= HCI_UART_MAX_PROTO)
73 return NULL;
74
75 return hup[id];
76 }
77
hci_uart_tx_complete(struct hci_uart * hu,int pkt_type)78 static inline void hci_uart_tx_complete(struct hci_uart *hu, int pkt_type)
79 {
80 struct hci_dev *hdev = hu->hdev;
81
82 /* Update HCI stat counters */
83 switch (pkt_type) {
84 case HCI_COMMAND_PKT:
85 hdev->stat.cmd_tx++;
86 break;
87
88 case HCI_ACLDATA_PKT:
89 hdev->stat.acl_tx++;
90 break;
91
92 case HCI_SCODATA_PKT:
93 hdev->stat.sco_tx++;
94 break;
95 }
96 }
97
hci_uart_dequeue(struct hci_uart * hu)98 static inline struct sk_buff *hci_uart_dequeue(struct hci_uart *hu)
99 {
100 struct sk_buff *skb = hu->tx_skb;
101
102 if (!skb) {
103 percpu_down_read(&hu->proto_lock);
104
105 if (test_bit(HCI_UART_PROTO_READY, &hu->flags) ||
106 test_bit(HCI_UART_PROTO_INIT, &hu->flags))
107 skb = hu->proto->dequeue(hu);
108
109 percpu_up_read(&hu->proto_lock);
110 } else {
111 hu->tx_skb = NULL;
112 }
113
114 return skb;
115 }
116
hci_uart_tx_wakeup(struct hci_uart * hu)117 int hci_uart_tx_wakeup(struct hci_uart *hu)
118 {
119 /* This may be called in an IRQ context, so we can't sleep. Therefore
120 * we try to acquire the lock only, and if that fails we assume the
121 * tty is being closed because that is the only time the write lock is
122 * acquired. If, however, at some point in the future the write lock
123 * is also acquired in other situations, then this must be revisited.
124 */
125 if (!percpu_down_read_trylock(&hu->proto_lock))
126 return 0;
127
128 if (!test_bit(HCI_UART_PROTO_READY, &hu->flags) &&
129 !test_bit(HCI_UART_PROTO_INIT, &hu->flags))
130 goto no_schedule;
131
132 set_bit(HCI_UART_TX_WAKEUP, &hu->tx_state);
133 if (test_and_set_bit(HCI_UART_SENDING, &hu->tx_state))
134 goto no_schedule;
135
136 BT_DBG("");
137
138 schedule_work(&hu->write_work);
139
140 no_schedule:
141 percpu_up_read(&hu->proto_lock);
142
143 return 0;
144 }
145 EXPORT_SYMBOL_GPL(hci_uart_tx_wakeup);
146
hci_uart_write_work(struct work_struct * work)147 static void hci_uart_write_work(struct work_struct *work)
148 {
149 struct hci_uart *hu = container_of(work, struct hci_uart, write_work);
150 struct tty_struct *tty = hu->tty;
151 struct hci_dev *hdev = hu->hdev;
152 struct sk_buff *skb;
153
154 /* REVISIT: should we cope with bad skbs or ->write() returning
155 * and error value ?
156 */
157
158 restart:
159 clear_bit(HCI_UART_TX_WAKEUP, &hu->tx_state);
160
161 while ((skb = hci_uart_dequeue(hu))) {
162 int len;
163
164 set_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
165 len = tty->ops->write(tty, skb->data, skb->len);
166 if (len < 0 || len > skb->len) {
167 hdev->stat.err_tx++;
168 kfree_skb(skb);
169 continue;
170 }
171
172 hdev->stat.byte_tx += len;
173
174 skb_pull(skb, len);
175 if (skb->len) {
176 hu->tx_skb = skb;
177 break;
178 }
179
180 hci_uart_tx_complete(hu, hci_skb_pkt_type(skb));
181 kfree_skb(skb);
182 }
183
184 clear_bit(HCI_UART_SENDING, &hu->tx_state);
185 if (test_bit(HCI_UART_TX_WAKEUP, &hu->tx_state))
186 goto restart;
187
188 wake_up_bit(&hu->tx_state, HCI_UART_SENDING);
189 }
190
hci_uart_init_work(struct work_struct * work)191 void hci_uart_init_work(struct work_struct *work)
192 {
193 struct hci_uart *hu = container_of(work, struct hci_uart, init_ready);
194 int err;
195 struct hci_dev *hdev;
196
197 if (!test_and_clear_bit(HCI_UART_INIT_PENDING, &hu->hdev_flags))
198 return;
199
200 err = hci_register_dev(hu->hdev);
201 if (err < 0) {
202 BT_ERR("Can't register HCI device");
203
204 percpu_down_write(&hu->proto_lock);
205 clear_bit(HCI_UART_PROTO_READY, &hu->flags);
206 percpu_up_write(&hu->proto_lock);
207
208 /* Safely cancel work after clearing flags */
209 cancel_work_sync(&hu->write_work);
210
211 /* Close protocol before freeing hdev */
212 hu->proto->close(hu);
213 hdev = hu->hdev;
214 hu->hdev = NULL;
215 hci_free_dev(hdev);
216 return;
217 }
218
219 set_bit(HCI_UART_REGISTERED, &hu->flags);
220 }
221
hci_uart_init_ready(struct hci_uart * hu)222 int hci_uart_init_ready(struct hci_uart *hu)
223 {
224 if (!test_bit(HCI_UART_INIT_PENDING, &hu->hdev_flags))
225 return -EALREADY;
226
227 schedule_work(&hu->init_ready);
228
229 return 0;
230 }
231
hci_uart_wait_until_sent(struct hci_uart * hu)232 int hci_uart_wait_until_sent(struct hci_uart *hu)
233 {
234 return wait_on_bit_timeout(&hu->tx_state, HCI_UART_SENDING,
235 TASK_INTERRUPTIBLE,
236 msecs_to_jiffies(2000));
237 }
238
239 /* ------- Interface to HCI layer ------ */
240 /* Reset device */
hci_uart_flush(struct hci_dev * hdev)241 static int hci_uart_flush(struct hci_dev *hdev)
242 {
243 struct hci_uart *hu = hci_get_drvdata(hdev);
244 struct tty_struct *tty = hu->tty;
245
246 BT_DBG("hdev %p tty %p", hdev, tty);
247
248 disable_work_sync(&hu->write_work);
249
250 if (hu->tx_skb) {
251 kfree_skb(hu->tx_skb); hu->tx_skb = NULL;
252 }
253
254 /* Flush any pending characters in the driver and discipline. */
255 tty_ldisc_flush(tty);
256 tty_driver_flush_buffer(tty);
257
258 percpu_down_read(&hu->proto_lock);
259
260 if (test_bit(HCI_UART_PROTO_READY, &hu->flags))
261 hu->proto->flush(hu);
262
263 percpu_up_read(&hu->proto_lock);
264
265 /* Resume TX. Also reschedule in case work was queued concurrently;
266 * this may schedule write_work although there's nothing to do.
267 */
268 enable_work(&hu->write_work);
269 clear_bit(HCI_UART_SENDING, &hu->tx_state);
270 if (test_bit(HCI_UART_TX_WAKEUP, &hu->tx_state))
271 hci_uart_tx_wakeup(hu);
272
273 return 0;
274 }
275
276 /* Initialize device */
hci_uart_open(struct hci_dev * hdev)277 static int hci_uart_open(struct hci_dev *hdev)
278 {
279 BT_DBG("%s %p", hdev->name, hdev);
280
281 /* Undo clearing this from hci_uart_close() */
282 hdev->flush = hci_uart_flush;
283
284 return 0;
285 }
286
287 /* Close device */
hci_uart_close(struct hci_dev * hdev)288 static int hci_uart_close(struct hci_dev *hdev)
289 {
290 BT_DBG("hdev %p", hdev);
291
292 hci_uart_flush(hdev);
293 hdev->flush = NULL;
294 return 0;
295 }
296
297 /* Send frames from HCI layer */
hci_uart_send_frame(struct hci_dev * hdev,struct sk_buff * skb)298 static int hci_uart_send_frame(struct hci_dev *hdev, struct sk_buff *skb)
299 {
300 struct hci_uart *hu = hci_get_drvdata(hdev);
301
302 BT_DBG("%s: type %d len %d", hdev->name, hci_skb_pkt_type(skb),
303 skb->len);
304
305 percpu_down_read(&hu->proto_lock);
306
307 if (!test_bit(HCI_UART_PROTO_READY, &hu->flags) &&
308 !test_bit(HCI_UART_PROTO_INIT, &hu->flags)) {
309 percpu_up_read(&hu->proto_lock);
310 return -EUNATCH;
311 }
312
313 hu->proto->enqueue(hu, skb);
314 percpu_up_read(&hu->proto_lock);
315
316 hci_uart_tx_wakeup(hu);
317
318 return 0;
319 }
320
321 /* Check the underlying device or tty has flow control support */
hci_uart_has_flow_control(struct hci_uart * hu)322 bool hci_uart_has_flow_control(struct hci_uart *hu)
323 {
324 /* serdev nodes check if the needed operations are present */
325 if (hu->serdev)
326 return true;
327
328 if (hu->tty->driver->ops->tiocmget && hu->tty->driver->ops->tiocmset)
329 return true;
330
331 return false;
332 }
333
334 /* Flow control or un-flow control the device */
hci_uart_set_flow_control(struct hci_uart * hu,bool enable)335 void hci_uart_set_flow_control(struct hci_uart *hu, bool enable)
336 {
337 struct tty_struct *tty = hu->tty;
338 struct ktermios ktermios;
339 int status;
340 unsigned int set = 0;
341 unsigned int clear = 0;
342
343 if (hu->serdev) {
344 serdev_device_set_flow_control(hu->serdev, !enable);
345 serdev_device_set_rts(hu->serdev, !enable);
346 return;
347 }
348
349 if (enable) {
350 /* Disable hardware flow control */
351 ktermios = tty->termios;
352 ktermios.c_cflag &= ~CRTSCTS;
353 tty_set_termios(tty, &ktermios);
354 BT_DBG("Disabling hardware flow control: %s",
355 (tty->termios.c_cflag & CRTSCTS) ? "failed" : "success");
356
357 /* Clear RTS to prevent the device from sending */
358 /* Most UARTs need OUT2 to enable interrupts */
359 status = tty->driver->ops->tiocmget(tty);
360 BT_DBG("Current tiocm 0x%x", status);
361
362 set &= ~(TIOCM_OUT2 | TIOCM_RTS);
363 clear = ~set;
364 set &= TIOCM_DTR | TIOCM_RTS | TIOCM_OUT1 |
365 TIOCM_OUT2 | TIOCM_LOOP;
366 clear &= TIOCM_DTR | TIOCM_RTS | TIOCM_OUT1 |
367 TIOCM_OUT2 | TIOCM_LOOP;
368 status = tty->driver->ops->tiocmset(tty, set, clear);
369 BT_DBG("Clearing RTS: %s", status ? "failed" : "success");
370 } else {
371 /* Set RTS to allow the device to send again */
372 status = tty->driver->ops->tiocmget(tty);
373 BT_DBG("Current tiocm 0x%x", status);
374
375 set |= (TIOCM_OUT2 | TIOCM_RTS);
376 clear = ~set;
377 set &= TIOCM_DTR | TIOCM_RTS | TIOCM_OUT1 |
378 TIOCM_OUT2 | TIOCM_LOOP;
379 clear &= TIOCM_DTR | TIOCM_RTS | TIOCM_OUT1 |
380 TIOCM_OUT2 | TIOCM_LOOP;
381 status = tty->driver->ops->tiocmset(tty, set, clear);
382 BT_DBG("Setting RTS: %s", status ? "failed" : "success");
383
384 /* Re-enable hardware flow control */
385 ktermios = tty->termios;
386 ktermios.c_cflag |= CRTSCTS;
387 tty_set_termios(tty, &ktermios);
388 BT_DBG("Enabling hardware flow control: %s",
389 !(tty->termios.c_cflag & CRTSCTS) ? "failed" : "success");
390 }
391 }
392
hci_uart_set_speeds(struct hci_uart * hu,unsigned int init_speed,unsigned int oper_speed)393 void hci_uart_set_speeds(struct hci_uart *hu, unsigned int init_speed,
394 unsigned int oper_speed)
395 {
396 hu->init_speed = init_speed;
397 hu->oper_speed = oper_speed;
398 }
399
hci_uart_set_baudrate(struct hci_uart * hu,unsigned int speed)400 void hci_uart_set_baudrate(struct hci_uart *hu, unsigned int speed)
401 {
402 struct tty_struct *tty = hu->tty;
403 struct ktermios ktermios;
404
405 ktermios = tty->termios;
406 ktermios.c_cflag &= ~CBAUD;
407 tty_termios_encode_baud_rate(&ktermios, speed, speed);
408
409 /* tty_set_termios() return not checked as it is always 0 */
410 tty_set_termios(tty, &ktermios);
411
412 BT_DBG("%s: New tty speeds: %d/%d", hu->hdev->name,
413 tty->termios.c_ispeed, tty->termios.c_ospeed);
414 }
415
hci_uart_setup(struct hci_dev * hdev)416 static int hci_uart_setup(struct hci_dev *hdev)
417 {
418 struct hci_uart *hu = hci_get_drvdata(hdev);
419 struct hci_rp_read_local_version *ver;
420 struct sk_buff *skb;
421 unsigned int speed;
422 int err;
423
424 /* Init speed if any */
425 if (hu->init_speed)
426 speed = hu->init_speed;
427 else if (hu->proto->init_speed)
428 speed = hu->proto->init_speed;
429 else
430 speed = 0;
431
432 if (speed)
433 hci_uart_set_baudrate(hu, speed);
434
435 /* Operational speed if any */
436 if (hu->oper_speed)
437 speed = hu->oper_speed;
438 else if (hu->proto->oper_speed)
439 speed = hu->proto->oper_speed;
440 else
441 speed = 0;
442
443 if (hu->proto->set_baudrate && speed) {
444 err = hu->proto->set_baudrate(hu, speed);
445 if (!err)
446 hci_uart_set_baudrate(hu, speed);
447 }
448
449 if (hu->proto->setup)
450 return hu->proto->setup(hu);
451
452 if (!test_bit(HCI_UART_VND_DETECT, &hu->hdev_flags))
453 return 0;
454
455 skb = __hci_cmd_sync(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL,
456 HCI_INIT_TIMEOUT);
457 if (IS_ERR(skb)) {
458 BT_ERR("%s: Reading local version information failed (%ld)",
459 hdev->name, PTR_ERR(skb));
460 return PTR_ERR(skb);
461 }
462
463 if (skb->len != sizeof(*ver)) {
464 BT_ERR("%s: Event length mismatch for version information",
465 hdev->name);
466 goto done;
467 }
468
469 ver = (struct hci_rp_read_local_version *)skb->data;
470
471 switch (le16_to_cpu(ver->manufacturer)) {
472 #ifdef CONFIG_BT_HCIUART_INTEL
473 case 2:
474 hdev->set_bdaddr = btintel_set_bdaddr;
475 btintel_check_bdaddr(hdev);
476 break;
477 #endif
478 #ifdef CONFIG_BT_HCIUART_BCM
479 case 15:
480 hdev->set_bdaddr = btbcm_set_bdaddr;
481 btbcm_check_bdaddr(hdev);
482 break;
483 #endif
484 default:
485 break;
486 }
487
488 done:
489 kfree_skb(skb);
490 return 0;
491 }
492
493 /* ------ LDISC part ------ */
494 /* hci_uart_tty_open
495 *
496 * Called when line discipline changed to HCI_UART.
497 *
498 * Arguments:
499 * tty pointer to tty info structure
500 * Return Value:
501 * 0 if success, otherwise error code
502 */
hci_uart_tty_open(struct tty_struct * tty)503 static int hci_uart_tty_open(struct tty_struct *tty)
504 {
505 struct hci_uart *hu;
506
507 BT_DBG("tty %p", tty);
508
509 if (!capable(CAP_NET_ADMIN))
510 return -EPERM;
511
512 /* Error if the tty has no write op instead of leaving an exploitable
513 * hole
514 */
515 if (tty->ops->write == NULL)
516 return -EOPNOTSUPP;
517
518 hu = kzalloc_obj(*hu);
519 if (!hu) {
520 BT_ERR("Can't allocate control structure");
521 return -ENFILE;
522 }
523 if (percpu_init_rwsem(&hu->proto_lock)) {
524 BT_ERR("Can't allocate semaphore structure");
525 kfree(hu);
526 return -ENOMEM;
527 }
528
529 tty->disc_data = hu;
530 hu->tty = tty;
531 tty->receive_room = 65536;
532
533 /* disable alignment support by default */
534 hu->alignment = 1;
535 hu->padding = 0;
536
537 /* Use serial port speed as oper_speed */
538 hu->oper_speed = tty->termios.c_ospeed;
539
540 INIT_WORK(&hu->init_ready, hci_uart_init_work);
541 INIT_WORK(&hu->write_work, hci_uart_write_work);
542
543 /* Flush any pending characters in the driver */
544 tty_driver_flush_buffer(tty);
545
546 return 0;
547 }
548
549 /* hci_uart_tty_close()
550 *
551 * Called when the line discipline is changed to something
552 * else, the tty is closed, or the tty detects a hangup.
553 */
hci_uart_tty_close(struct tty_struct * tty)554 static void hci_uart_tty_close(struct tty_struct *tty)
555 {
556 struct hci_uart *hu = tty->disc_data;
557 struct hci_dev *hdev;
558 bool proto_ready;
559
560 BT_DBG("tty %p", tty);
561
562 /* Detach from the tty */
563 tty->disc_data = NULL;
564
565 if (!hu)
566 return;
567
568 /* Wait for init_ready to finish to prevent registration races */
569 cancel_work_sync(&hu->init_ready);
570
571 proto_ready = test_bit(HCI_UART_PROTO_READY, &hu->flags);
572 if (proto_ready) {
573 percpu_down_write(&hu->proto_lock);
574 clear_bit(HCI_UART_PROTO_READY, &hu->flags);
575 percpu_up_write(&hu->proto_lock);
576 }
577
578 /*
579 * Unconditionally cancel write_work AFTER clearing PROTO_READY.
580 * This ensures that concurrent protocol timers cannot requeue
581 * write_work via hci_uart_tx_wakeup(), permanently preventing
582 * double-free races and UAFs.
583 */
584 cancel_work_sync(&hu->write_work);
585
586 hdev = hu->hdev;
587 if (hdev)
588 hci_uart_close(hdev); /* proto->flush is safely skipped */
589
590 if (proto_ready) {
591 if (hdev) {
592 if (test_bit(HCI_UART_REGISTERED, &hu->flags))
593 hci_unregister_dev(hdev);
594 }
595 /* Close protocol before freeing hdev (intrinsically purges queues) */
596 hu->proto->close(hu);
597
598 if (hdev)
599 hci_free_dev(hdev);
600 }
601 clear_bit(HCI_UART_PROTO_SET, &hu->flags);
602
603 percpu_free_rwsem(&hu->proto_lock);
604
605 kfree(hu);
606 }
607
608 /* hci_uart_tty_wakeup()
609 *
610 * Callback for transmit wakeup. Called when low level
611 * device driver can accept more send data.
612 *
613 * Arguments: tty pointer to associated tty instance data
614 * Return Value: None
615 */
hci_uart_tty_wakeup(struct tty_struct * tty)616 static void hci_uart_tty_wakeup(struct tty_struct *tty)
617 {
618 struct hci_uart *hu = tty->disc_data;
619
620 BT_DBG("");
621
622 if (!hu)
623 return;
624
625 clear_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
626
627 if (tty != hu->tty)
628 return;
629
630 if (test_bit(HCI_UART_PROTO_READY, &hu->flags) ||
631 test_bit(HCI_UART_PROTO_INIT, &hu->flags))
632 hci_uart_tx_wakeup(hu);
633 }
634
635 /* hci_uart_tty_receive()
636 *
637 * Called by tty low level driver when receive data is
638 * available.
639 *
640 * Arguments: tty pointer to tty instance data
641 * data pointer to received data
642 * flags pointer to flags for data
643 * count count of received data in bytes
644 *
645 * Return Value: None
646 */
hci_uart_tty_receive(struct tty_struct * tty,const u8 * data,const u8 * flags,size_t count)647 static void hci_uart_tty_receive(struct tty_struct *tty, const u8 *data,
648 const u8 *flags, size_t count)
649 {
650 struct hci_uart *hu = tty->disc_data;
651
652 if (!hu || tty != hu->tty)
653 return;
654
655 percpu_down_read(&hu->proto_lock);
656
657 if (!test_bit(HCI_UART_PROTO_READY, &hu->flags) &&
658 !test_bit(HCI_UART_PROTO_INIT, &hu->flags)) {
659 percpu_up_read(&hu->proto_lock);
660 return;
661 }
662
663 /* It does not need a lock here as it is already protected by a mutex in
664 * tty caller
665 */
666 hu->proto->recv(hu, data, count);
667
668 if (hu->hdev)
669 hu->hdev->stat.byte_rx += count;
670
671 percpu_up_read(&hu->proto_lock);
672
673 tty_unthrottle(tty);
674 }
675
hci_uart_register_dev(struct hci_uart * hu)676 static int hci_uart_register_dev(struct hci_uart *hu)
677 {
678 struct hci_dev *hdev;
679 int err;
680
681 BT_DBG("");
682
683 /* Initialize and register HCI device */
684 hdev = hci_alloc_dev();
685 if (!hdev) {
686 BT_ERR("Can't allocate HCI device");
687 return -ENOMEM;
688 }
689
690 hu->hdev = hdev;
691
692 hdev->bus = HCI_UART;
693 hci_set_drvdata(hdev, hu);
694
695 /* Only when vendor specific setup callback is provided, consider
696 * the manufacturer information valid. This avoids filling in the
697 * value for Ericsson when nothing is specified.
698 */
699 if (hu->proto->setup)
700 hdev->manufacturer = hu->proto->manufacturer;
701
702 hdev->open = hci_uart_open;
703 hdev->close = hci_uart_close;
704 hdev->flush = hci_uart_flush;
705 hdev->send = hci_uart_send_frame;
706 hdev->setup = hci_uart_setup;
707 SET_HCIDEV_DEV(hdev, hu->tty->dev);
708
709 if (test_bit(HCI_UART_RAW_DEVICE, &hu->hdev_flags))
710 hci_set_quirk(hdev, HCI_QUIRK_RAW_DEVICE);
711
712 if (test_bit(HCI_UART_EXT_CONFIG, &hu->hdev_flags))
713 hci_set_quirk(hdev, HCI_QUIRK_EXTERNAL_CONFIG);
714
715 if (!test_bit(HCI_UART_RESET_ON_INIT, &hu->hdev_flags))
716 hci_set_quirk(hdev, HCI_QUIRK_RESET_ON_CLOSE);
717
718 /* Only call open() for the protocol after hdev is fully initialized as
719 * open() (or a timer/workqueue it starts) may attempt to reference it.
720 */
721 err = hu->proto->open(hu);
722 if (err) {
723 hu->hdev = NULL;
724 hci_free_dev(hdev);
725 return err;
726 }
727
728 set_bit(HCI_UART_PROTO_INIT, &hu->flags);
729
730 if (test_bit(HCI_UART_INIT_PENDING, &hu->hdev_flags))
731 return 0;
732
733 if (hci_register_dev(hdev) < 0) {
734 BT_ERR("Can't register HCI device");
735 percpu_down_write(&hu->proto_lock);
736 clear_bit(HCI_UART_PROTO_INIT, &hu->flags);
737 percpu_up_write(&hu->proto_lock);
738 /* Cancel work after clearing flags */
739 cancel_work_sync(&hu->write_work);
740
741 /* Close protocol before freeing hdev */
742 hu->proto->close(hu);
743 hu->hdev = NULL;
744 hci_free_dev(hdev);
745 return -ENODEV;
746 }
747
748 set_bit(HCI_UART_REGISTERED, &hu->flags);
749
750 return 0;
751 }
752
hci_uart_set_proto(struct hci_uart * hu,int id)753 static int hci_uart_set_proto(struct hci_uart *hu, int id)
754 {
755 const struct hci_uart_proto *p;
756 int err;
757
758 p = hci_uart_get_proto(id);
759 if (!p)
760 return -EPROTONOSUPPORT;
761
762 hu->proto = p;
763
764 err = hci_uart_register_dev(hu);
765 if (err)
766 return err;
767
768
769 set_bit(HCI_UART_PROTO_READY, &hu->flags);
770 clear_bit(HCI_UART_PROTO_INIT, &hu->flags);
771
772 return 0;
773 }
774
hci_uart_set_flags(struct hci_uart * hu,unsigned long flags)775 static int hci_uart_set_flags(struct hci_uart *hu, unsigned long flags)
776 {
777 unsigned long valid_flags = BIT(HCI_UART_RAW_DEVICE) |
778 BIT(HCI_UART_RESET_ON_INIT) |
779 BIT(HCI_UART_INIT_PENDING) |
780 BIT(HCI_UART_EXT_CONFIG) |
781 BIT(HCI_UART_VND_DETECT);
782
783 if (flags & ~valid_flags)
784 return -EINVAL;
785
786 hu->hdev_flags = flags;
787
788 return 0;
789 }
790
791 /* hci_uart_tty_ioctl()
792 *
793 * Process IOCTL system call for the tty device.
794 *
795 * Arguments:
796 *
797 * tty pointer to tty instance data
798 * cmd IOCTL command code
799 * arg argument for IOCTL call (cmd dependent)
800 *
801 * Return Value: Command dependent
802 */
hci_uart_tty_ioctl(struct tty_struct * tty,unsigned int cmd,unsigned long arg)803 static int hci_uart_tty_ioctl(struct tty_struct *tty, unsigned int cmd,
804 unsigned long arg)
805 {
806 struct hci_uart *hu = tty->disc_data;
807 int err = 0;
808
809 BT_DBG("");
810
811 /* Verify the status of the device */
812 if (!hu)
813 return -EBADF;
814
815 switch (cmd) {
816 case HCIUARTSETPROTO:
817 if (!test_and_set_bit(HCI_UART_PROTO_SET, &hu->flags)) {
818 err = hci_uart_set_proto(hu, arg);
819 if (err)
820 clear_bit(HCI_UART_PROTO_SET, &hu->flags);
821 } else
822 err = -EBUSY;
823 break;
824
825 case HCIUARTGETPROTO:
826 if (test_bit(HCI_UART_PROTO_SET, &hu->flags) &&
827 test_bit(HCI_UART_PROTO_READY, &hu->flags))
828 err = hu->proto->id;
829 else
830 err = -EUNATCH;
831 break;
832
833 case HCIUARTGETDEVICE:
834 if (test_bit(HCI_UART_REGISTERED, &hu->flags))
835 err = hu->hdev->id;
836 else
837 err = -EUNATCH;
838 break;
839
840 case HCIUARTSETFLAGS:
841 if (test_bit(HCI_UART_PROTO_SET, &hu->flags))
842 err = -EBUSY;
843 else
844 err = hci_uart_set_flags(hu, arg);
845 break;
846
847 case HCIUARTGETFLAGS:
848 err = hu->hdev_flags;
849 break;
850
851 default:
852 err = n_tty_ioctl_helper(tty, cmd, arg);
853 break;
854 }
855
856 return err;
857 }
858
859 /*
860 * We don't provide read/write/poll interface for user space.
861 */
hci_uart_tty_read(struct tty_struct * tty,struct file * file,u8 * buf,size_t nr,void ** cookie,unsigned long offset)862 static ssize_t hci_uart_tty_read(struct tty_struct *tty, struct file *file,
863 u8 *buf, size_t nr, void **cookie,
864 unsigned long offset)
865 {
866 return 0;
867 }
868
hci_uart_tty_write(struct tty_struct * tty,struct file * file,const u8 * data,size_t count)869 static ssize_t hci_uart_tty_write(struct tty_struct *tty, struct file *file,
870 const u8 *data, size_t count)
871 {
872 return 0;
873 }
874
875 static struct tty_ldisc_ops hci_uart_ldisc = {
876 .owner = THIS_MODULE,
877 .num = N_HCI,
878 .name = "n_hci",
879 .open = hci_uart_tty_open,
880 .close = hci_uart_tty_close,
881 .read = hci_uart_tty_read,
882 .write = hci_uart_tty_write,
883 .ioctl = hci_uart_tty_ioctl,
884 .compat_ioctl = hci_uart_tty_ioctl,
885 .receive_buf = hci_uart_tty_receive,
886 .write_wakeup = hci_uart_tty_wakeup,
887 };
888
hci_uart_init(void)889 static int __init hci_uart_init(void)
890 {
891 int err;
892
893 BT_INFO("HCI UART driver ver %s", VERSION);
894
895 /* Register the tty discipline */
896 err = tty_register_ldisc(&hci_uart_ldisc);
897 if (err) {
898 BT_ERR("HCI line discipline registration failed. (%d)", err);
899 return err;
900 }
901
902 #ifdef CONFIG_BT_HCIUART_H4
903 h4_init();
904 #endif
905 #ifdef CONFIG_BT_HCIUART_BCSP
906 bcsp_init();
907 #endif
908 #ifdef CONFIG_BT_HCIUART_LL
909 ll_init();
910 #endif
911 #ifdef CONFIG_BT_HCIUART_ATH3K
912 ath_init();
913 #endif
914 #ifdef CONFIG_BT_HCIUART_3WIRE
915 h5_init();
916 #endif
917 #ifdef CONFIG_BT_HCIUART_INTEL
918 intel_init();
919 #endif
920 #ifdef CONFIG_BT_HCIUART_BCM
921 bcm_init();
922 #endif
923 #ifdef CONFIG_BT_HCIUART_QCA
924 qca_init();
925 #endif
926 #ifdef CONFIG_BT_HCIUART_AG6XX
927 ag6xx_init();
928 #endif
929 #ifdef CONFIG_BT_HCIUART_MRVL
930 mrvl_init();
931 #endif
932 #ifdef CONFIG_BT_HCIUART_AML
933 aml_init();
934 #endif
935 return 0;
936 }
937
hci_uart_exit(void)938 static void __exit hci_uart_exit(void)
939 {
940 #ifdef CONFIG_BT_HCIUART_H4
941 h4_deinit();
942 #endif
943 #ifdef CONFIG_BT_HCIUART_BCSP
944 bcsp_deinit();
945 #endif
946 #ifdef CONFIG_BT_HCIUART_LL
947 ll_deinit();
948 #endif
949 #ifdef CONFIG_BT_HCIUART_ATH3K
950 ath_deinit();
951 #endif
952 #ifdef CONFIG_BT_HCIUART_3WIRE
953 h5_deinit();
954 #endif
955 #ifdef CONFIG_BT_HCIUART_INTEL
956 intel_deinit();
957 #endif
958 #ifdef CONFIG_BT_HCIUART_BCM
959 bcm_deinit();
960 #endif
961 #ifdef CONFIG_BT_HCIUART_QCA
962 qca_deinit();
963 #endif
964 #ifdef CONFIG_BT_HCIUART_AG6XX
965 ag6xx_deinit();
966 #endif
967 #ifdef CONFIG_BT_HCIUART_MRVL
968 mrvl_deinit();
969 #endif
970 #ifdef CONFIG_BT_HCIUART_AML
971 aml_deinit();
972 #endif
973 tty_unregister_ldisc(&hci_uart_ldisc);
974 }
975
976 module_init(hci_uart_init);
977 module_exit(hci_uart_exit);
978
979 MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
980 MODULE_DESCRIPTION("Bluetooth HCI UART driver ver " VERSION);
981 MODULE_VERSION(VERSION);
982 MODULE_LICENSE("GPL");
983 MODULE_ALIAS_LDISC(N_HCI);
984