1 // SPDX-License-Identifier: GPL-2.0-only 2 /* 3 * The NFC Controller Interface is the communication protocol between an 4 * NFC Controller (NFCC) and a Device Host (DH). 5 * 6 * Copyright (C) 2011 Texas Instruments, Inc. 7 * Copyright (C) 2014 Marvell International Ltd. 8 * 9 * Written by Ilan Elias <ilane@ti.com> 10 * 11 * Acknowledgements: 12 * This file is based on hci_core.c, which was written 13 * by Maxim Krasnyansky. 14 */ 15 16 #define pr_fmt(fmt) KBUILD_MODNAME ": %s: " fmt, __func__ 17 18 #include <linux/module.h> 19 #include <linux/kernel.h> 20 #include <linux/types.h> 21 #include <linux/workqueue.h> 22 #include <linux/completion.h> 23 #include <linux/export.h> 24 #include <linux/sched.h> 25 #include <linux/bitops.h> 26 #include <linux/skbuff.h> 27 #include <linux/kcov.h> 28 29 #include "../nfc.h" 30 #include <net/nfc/nci.h> 31 #include <net/nfc/nci_core.h> 32 #include <linux/nfc.h> 33 34 struct core_conn_create_data { 35 int length; 36 struct nci_core_conn_create_cmd *cmd; 37 }; 38 39 static void nci_cmd_work(struct work_struct *work); 40 static void nci_rx_work(struct work_struct *work); 41 static void nci_tx_work(struct work_struct *work); 42 43 struct nci_conn_info *nci_get_conn_info_by_conn_id(struct nci_dev *ndev, 44 int conn_id) 45 { 46 struct nci_conn_info *conn_info; 47 48 list_for_each_entry(conn_info, &ndev->conn_info_list, list) { 49 if (conn_info->conn_id == conn_id) 50 return conn_info; 51 } 52 53 return NULL; 54 } 55 56 int nci_get_conn_info_by_dest_type_params(struct nci_dev *ndev, u8 dest_type, 57 const struct dest_spec_params *params) 58 { 59 const struct nci_conn_info *conn_info; 60 61 list_for_each_entry(conn_info, &ndev->conn_info_list, list) { 62 if (conn_info->dest_type == dest_type) { 63 if (!params) 64 return conn_info->conn_id; 65 66 if (params->id == conn_info->dest_params->id && 67 params->protocol == conn_info->dest_params->protocol) 68 return conn_info->conn_id; 69 } 70 } 71 72 return -EINVAL; 73 } 74 EXPORT_SYMBOL(nci_get_conn_info_by_dest_type_params); 75 76 /* ---- NCI requests ---- */ 77 78 void nci_req_complete(struct nci_dev *ndev, int result) 79 { 80 if (ndev->req_status == NCI_REQ_PEND) { 81 ndev->req_result = result; 82 ndev->req_status = NCI_REQ_DONE; 83 complete(&ndev->req_completion); 84 } 85 } 86 EXPORT_SYMBOL(nci_req_complete); 87 88 static void nci_req_cancel(struct nci_dev *ndev, int err) 89 { 90 if (ndev->req_status == NCI_REQ_PEND) { 91 ndev->req_result = err; 92 ndev->req_status = NCI_REQ_CANCELED; 93 complete(&ndev->req_completion); 94 } 95 } 96 97 /* Execute request and wait for completion. */ 98 static int __nci_request(struct nci_dev *ndev, 99 void (*req)(struct nci_dev *ndev, const void *opt), 100 const void *opt, __u32 timeout) 101 { 102 int rc = 0; 103 long completion_rc; 104 105 ndev->req_status = NCI_REQ_PEND; 106 107 reinit_completion(&ndev->req_completion); 108 req(ndev, opt); 109 completion_rc = 110 wait_for_completion_interruptible_timeout(&ndev->req_completion, 111 timeout); 112 113 pr_debug("wait_for_completion return %ld\n", completion_rc); 114 115 if (completion_rc > 0) { 116 switch (ndev->req_status) { 117 case NCI_REQ_DONE: 118 rc = nci_to_errno(ndev->req_result); 119 break; 120 121 case NCI_REQ_CANCELED: 122 rc = -ndev->req_result; 123 break; 124 125 default: 126 rc = -ETIMEDOUT; 127 break; 128 } 129 } else { 130 pr_err("wait_for_completion_interruptible_timeout failed %ld\n", 131 completion_rc); 132 133 rc = ((completion_rc == 0) ? (-ETIMEDOUT) : (completion_rc)); 134 } 135 136 ndev->req_status = ndev->req_result = 0; 137 138 return rc; 139 } 140 141 inline int nci_request(struct nci_dev *ndev, 142 void (*req)(struct nci_dev *ndev, 143 const void *opt), 144 const void *opt, __u32 timeout) 145 { 146 int rc; 147 148 /* Serialize all requests */ 149 mutex_lock(&ndev->req_lock); 150 /* check the state after obtaing the lock against any races 151 * from nci_close_device when the device gets removed. 152 */ 153 if (test_bit(NCI_UP, &ndev->flags)) 154 rc = __nci_request(ndev, req, opt, timeout); 155 else 156 rc = -ENETDOWN; 157 mutex_unlock(&ndev->req_lock); 158 159 return rc; 160 } 161 162 static void nci_reset_req(struct nci_dev *ndev, const void *opt) 163 { 164 struct nci_core_reset_cmd cmd; 165 166 cmd.reset_type = NCI_RESET_TYPE_RESET_CONFIG; 167 nci_send_cmd(ndev, NCI_OP_CORE_RESET_CMD, 1, &cmd); 168 } 169 170 static void nci_init_req(struct nci_dev *ndev, const void *opt) 171 { 172 u8 plen = 0; 173 174 if (opt) 175 plen = sizeof(struct nci_core_init_v2_cmd); 176 177 nci_send_cmd(ndev, NCI_OP_CORE_INIT_CMD, plen, opt); 178 } 179 180 static void nci_init_complete_req(struct nci_dev *ndev, const void *opt) 181 { 182 struct nci_rf_disc_map_cmd cmd; 183 struct disc_map_config *cfg = cmd.mapping_configs; 184 __u8 *num = &cmd.num_mapping_configs; 185 int i; 186 187 /* set rf mapping configurations */ 188 *num = 0; 189 190 /* by default mapping is set to NCI_RF_INTERFACE_FRAME */ 191 for (i = 0; i < ndev->num_supported_rf_interfaces; i++) { 192 if (ndev->supported_rf_interfaces[i] == 193 NCI_RF_INTERFACE_ISO_DEP) { 194 cfg[*num].rf_protocol = NCI_RF_PROTOCOL_ISO_DEP; 195 cfg[*num].mode = NCI_DISC_MAP_MODE_POLL | 196 NCI_DISC_MAP_MODE_LISTEN; 197 cfg[*num].rf_interface = NCI_RF_INTERFACE_ISO_DEP; 198 (*num)++; 199 } else if (ndev->supported_rf_interfaces[i] == 200 NCI_RF_INTERFACE_NFC_DEP) { 201 cfg[*num].rf_protocol = NCI_RF_PROTOCOL_NFC_DEP; 202 cfg[*num].mode = NCI_DISC_MAP_MODE_POLL | 203 NCI_DISC_MAP_MODE_LISTEN; 204 cfg[*num].rf_interface = NCI_RF_INTERFACE_NFC_DEP; 205 (*num)++; 206 } 207 208 if (*num == NCI_MAX_NUM_MAPPING_CONFIGS) 209 break; 210 } 211 212 nci_send_cmd(ndev, NCI_OP_RF_DISCOVER_MAP_CMD, 213 (1 + ((*num) * sizeof(struct disc_map_config))), &cmd); 214 } 215 216 struct nci_set_config_param { 217 __u8 id; 218 size_t len; 219 const __u8 *val; 220 }; 221 222 static void nci_set_config_req(struct nci_dev *ndev, const void *opt) 223 { 224 const struct nci_set_config_param *param = opt; 225 struct nci_core_set_config_cmd cmd; 226 227 BUG_ON(param->len > NCI_MAX_PARAM_LEN); 228 229 cmd.num_params = 1; 230 cmd.param.id = param->id; 231 cmd.param.len = param->len; 232 memcpy(cmd.param.val, param->val, param->len); 233 234 nci_send_cmd(ndev, NCI_OP_CORE_SET_CONFIG_CMD, (3 + param->len), &cmd); 235 } 236 237 struct nci_rf_discover_param { 238 __u32 im_protocols; 239 __u32 tm_protocols; 240 }; 241 242 static void nci_rf_discover_req(struct nci_dev *ndev, const void *opt) 243 { 244 const struct nci_rf_discover_param *param = opt; 245 struct nci_rf_disc_cmd cmd; 246 247 cmd.num_disc_configs = 0; 248 249 if ((cmd.num_disc_configs < NCI_MAX_NUM_RF_CONFIGS) && 250 (param->im_protocols & NFC_PROTO_JEWEL_MASK || 251 param->im_protocols & NFC_PROTO_MIFARE_MASK || 252 param->im_protocols & NFC_PROTO_ISO14443_MASK || 253 param->im_protocols & NFC_PROTO_NFC_DEP_MASK)) { 254 cmd.disc_configs[cmd.num_disc_configs].rf_tech_and_mode = 255 NCI_NFC_A_PASSIVE_POLL_MODE; 256 cmd.disc_configs[cmd.num_disc_configs].frequency = 1; 257 cmd.num_disc_configs++; 258 } 259 260 if ((cmd.num_disc_configs < NCI_MAX_NUM_RF_CONFIGS) && 261 (param->im_protocols & NFC_PROTO_ISO14443_B_MASK)) { 262 cmd.disc_configs[cmd.num_disc_configs].rf_tech_and_mode = 263 NCI_NFC_B_PASSIVE_POLL_MODE; 264 cmd.disc_configs[cmd.num_disc_configs].frequency = 1; 265 cmd.num_disc_configs++; 266 } 267 268 if ((cmd.num_disc_configs < NCI_MAX_NUM_RF_CONFIGS) && 269 (param->im_protocols & NFC_PROTO_FELICA_MASK || 270 param->im_protocols & NFC_PROTO_NFC_DEP_MASK)) { 271 cmd.disc_configs[cmd.num_disc_configs].rf_tech_and_mode = 272 NCI_NFC_F_PASSIVE_POLL_MODE; 273 cmd.disc_configs[cmd.num_disc_configs].frequency = 1; 274 cmd.num_disc_configs++; 275 } 276 277 if ((cmd.num_disc_configs < NCI_MAX_NUM_RF_CONFIGS) && 278 (param->im_protocols & NFC_PROTO_ISO15693_MASK)) { 279 cmd.disc_configs[cmd.num_disc_configs].rf_tech_and_mode = 280 NCI_NFC_V_PASSIVE_POLL_MODE; 281 cmd.disc_configs[cmd.num_disc_configs].frequency = 1; 282 cmd.num_disc_configs++; 283 } 284 285 if ((cmd.num_disc_configs < NCI_MAX_NUM_RF_CONFIGS - 1) && 286 (param->tm_protocols & NFC_PROTO_NFC_DEP_MASK)) { 287 cmd.disc_configs[cmd.num_disc_configs].rf_tech_and_mode = 288 NCI_NFC_A_PASSIVE_LISTEN_MODE; 289 cmd.disc_configs[cmd.num_disc_configs].frequency = 1; 290 cmd.num_disc_configs++; 291 cmd.disc_configs[cmd.num_disc_configs].rf_tech_and_mode = 292 NCI_NFC_F_PASSIVE_LISTEN_MODE; 293 cmd.disc_configs[cmd.num_disc_configs].frequency = 1; 294 cmd.num_disc_configs++; 295 } 296 297 nci_send_cmd(ndev, NCI_OP_RF_DISCOVER_CMD, 298 (1 + (cmd.num_disc_configs * sizeof(struct disc_config))), 299 &cmd); 300 } 301 302 struct nci_rf_discover_select_param { 303 __u8 rf_discovery_id; 304 __u8 rf_protocol; 305 }; 306 307 static void nci_rf_discover_select_req(struct nci_dev *ndev, const void *opt) 308 { 309 const struct nci_rf_discover_select_param *param = opt; 310 struct nci_rf_discover_select_cmd cmd; 311 312 cmd.rf_discovery_id = param->rf_discovery_id; 313 cmd.rf_protocol = param->rf_protocol; 314 315 switch (cmd.rf_protocol) { 316 case NCI_RF_PROTOCOL_ISO_DEP: 317 cmd.rf_interface = NCI_RF_INTERFACE_ISO_DEP; 318 break; 319 320 case NCI_RF_PROTOCOL_NFC_DEP: 321 cmd.rf_interface = NCI_RF_INTERFACE_NFC_DEP; 322 break; 323 324 default: 325 cmd.rf_interface = NCI_RF_INTERFACE_FRAME; 326 break; 327 } 328 329 nci_send_cmd(ndev, NCI_OP_RF_DISCOVER_SELECT_CMD, 330 sizeof(struct nci_rf_discover_select_cmd), &cmd); 331 } 332 333 static void nci_rf_deactivate_req(struct nci_dev *ndev, const void *opt) 334 { 335 struct nci_rf_deactivate_cmd cmd; 336 337 cmd.type = (unsigned long)opt; 338 339 nci_send_cmd(ndev, NCI_OP_RF_DEACTIVATE_CMD, 340 sizeof(struct nci_rf_deactivate_cmd), &cmd); 341 } 342 343 struct nci_cmd_param { 344 __u16 opcode; 345 size_t len; 346 const __u8 *payload; 347 }; 348 349 static void nci_generic_req(struct nci_dev *ndev, const void *opt) 350 { 351 const struct nci_cmd_param *param = opt; 352 353 nci_send_cmd(ndev, param->opcode, param->len, param->payload); 354 } 355 356 int nci_prop_cmd(struct nci_dev *ndev, __u8 oid, size_t len, const __u8 *payload) 357 { 358 struct nci_cmd_param param; 359 360 param.opcode = nci_opcode_pack(NCI_GID_PROPRIETARY, oid); 361 param.len = len; 362 param.payload = payload; 363 364 return __nci_request(ndev, nci_generic_req, ¶m, 365 msecs_to_jiffies(NCI_CMD_TIMEOUT)); 366 } 367 EXPORT_SYMBOL(nci_prop_cmd); 368 369 int nci_core_cmd(struct nci_dev *ndev, __u16 opcode, size_t len, 370 const __u8 *payload) 371 { 372 struct nci_cmd_param param; 373 374 param.opcode = opcode; 375 param.len = len; 376 param.payload = payload; 377 378 return __nci_request(ndev, nci_generic_req, ¶m, 379 msecs_to_jiffies(NCI_CMD_TIMEOUT)); 380 } 381 EXPORT_SYMBOL(nci_core_cmd); 382 383 int nci_core_reset(struct nci_dev *ndev) 384 { 385 return __nci_request(ndev, nci_reset_req, (void *)0, 386 msecs_to_jiffies(NCI_RESET_TIMEOUT)); 387 } 388 EXPORT_SYMBOL(nci_core_reset); 389 390 int nci_core_init(struct nci_dev *ndev) 391 { 392 return __nci_request(ndev, nci_init_req, (void *)0, 393 msecs_to_jiffies(NCI_INIT_TIMEOUT)); 394 } 395 EXPORT_SYMBOL(nci_core_init); 396 397 struct nci_loopback_data { 398 u8 conn_id; 399 struct sk_buff *data; 400 }; 401 402 static void nci_send_data_req(struct nci_dev *ndev, const void *opt) 403 { 404 const struct nci_loopback_data *data = opt; 405 406 nci_send_data(ndev, data->conn_id, data->data); 407 } 408 409 static void nci_nfcc_loopback_cb(void *context, struct sk_buff *skb, int err) 410 { 411 struct nci_dev *ndev = (struct nci_dev *)context; 412 struct nci_conn_info *conn_info; 413 414 conn_info = nci_get_conn_info_by_conn_id(ndev, ndev->cur_conn_id); 415 if (!conn_info) { 416 nci_req_complete(ndev, NCI_STATUS_REJECTED); 417 return; 418 } 419 420 conn_info->rx_skb = skb; 421 422 nci_req_complete(ndev, NCI_STATUS_OK); 423 } 424 425 int nci_nfcc_loopback(struct nci_dev *ndev, const void *data, size_t data_len, 426 struct sk_buff **resp) 427 { 428 int r; 429 struct nci_loopback_data loopback_data; 430 struct nci_conn_info *conn_info; 431 struct sk_buff *skb; 432 int conn_id = nci_get_conn_info_by_dest_type_params(ndev, 433 NCI_DESTINATION_NFCC_LOOPBACK, NULL); 434 435 if (conn_id < 0) { 436 r = nci_core_conn_create(ndev, NCI_DESTINATION_NFCC_LOOPBACK, 437 0, 0, NULL); 438 if (r != NCI_STATUS_OK) 439 return r; 440 441 conn_id = nci_get_conn_info_by_dest_type_params(ndev, 442 NCI_DESTINATION_NFCC_LOOPBACK, 443 NULL); 444 } 445 446 conn_info = nci_get_conn_info_by_conn_id(ndev, conn_id); 447 if (!conn_info) 448 return -EPROTO; 449 450 /* store cb and context to be used on receiving data */ 451 conn_info->data_exchange_cb = nci_nfcc_loopback_cb; 452 conn_info->data_exchange_cb_context = ndev; 453 454 skb = nci_skb_alloc(ndev, NCI_DATA_HDR_SIZE + data_len, GFP_KERNEL); 455 if (!skb) 456 return -ENOMEM; 457 458 skb_reserve(skb, NCI_DATA_HDR_SIZE); 459 skb_put_data(skb, data, data_len); 460 461 loopback_data.conn_id = conn_id; 462 loopback_data.data = skb; 463 464 ndev->cur_conn_id = conn_id; 465 r = nci_request(ndev, nci_send_data_req, &loopback_data, 466 msecs_to_jiffies(NCI_DATA_TIMEOUT)); 467 if (r == NCI_STATUS_OK && resp) 468 *resp = conn_info->rx_skb; 469 470 return r; 471 } 472 EXPORT_SYMBOL(nci_nfcc_loopback); 473 474 static int nci_open_device(struct nci_dev *ndev) 475 { 476 int rc = 0; 477 478 mutex_lock(&ndev->req_lock); 479 480 if (test_bit(NCI_UNREG, &ndev->flags)) { 481 rc = -ENODEV; 482 goto done; 483 } 484 485 if (test_bit(NCI_UP, &ndev->flags)) { 486 rc = -EALREADY; 487 goto done; 488 } 489 490 if (ndev->ops->open(ndev)) { 491 rc = -EIO; 492 goto done; 493 } 494 495 atomic_set(&ndev->cmd_cnt, 1); 496 497 set_bit(NCI_INIT, &ndev->flags); 498 499 if (ndev->ops->init) 500 rc = ndev->ops->init(ndev); 501 502 if (!rc) { 503 rc = __nci_request(ndev, nci_reset_req, (void *)0, 504 msecs_to_jiffies(NCI_RESET_TIMEOUT)); 505 } 506 507 if (!rc && ndev->ops->setup) { 508 rc = ndev->ops->setup(ndev); 509 } 510 511 if (!rc) { 512 struct nci_core_init_v2_cmd nci_init_v2_cmd = { 513 .feature1 = NCI_FEATURE_DISABLE, 514 .feature2 = NCI_FEATURE_DISABLE 515 }; 516 const void *opt = NULL; 517 518 if (ndev->nci_ver & NCI_VER_2_MASK) 519 opt = &nci_init_v2_cmd; 520 521 rc = __nci_request(ndev, nci_init_req, opt, 522 msecs_to_jiffies(NCI_INIT_TIMEOUT)); 523 } 524 525 if (!rc && ndev->ops->post_setup) 526 rc = ndev->ops->post_setup(ndev); 527 528 if (!rc) { 529 rc = __nci_request(ndev, nci_init_complete_req, (void *)0, 530 msecs_to_jiffies(NCI_INIT_TIMEOUT)); 531 } 532 533 clear_bit(NCI_INIT, &ndev->flags); 534 535 if (!rc) { 536 set_bit(NCI_UP, &ndev->flags); 537 nci_clear_target_list(ndev); 538 atomic_set(&ndev->state, NCI_IDLE); 539 } else { 540 /* Init failed, cleanup */ 541 skb_queue_purge(&ndev->cmd_q); 542 skb_queue_purge(&ndev->rx_q); 543 skb_queue_purge(&ndev->tx_q); 544 545 ndev->ops->close(ndev); 546 ndev->flags &= BIT(NCI_UNREG); 547 } 548 549 done: 550 mutex_unlock(&ndev->req_lock); 551 return rc; 552 } 553 554 static int nci_close_device(struct nci_dev *ndev) 555 { 556 nci_req_cancel(ndev, ENODEV); 557 558 /* This mutex needs to be held as a barrier for 559 * caller nci_unregister_device 560 */ 561 mutex_lock(&ndev->req_lock); 562 563 if (!test_and_clear_bit(NCI_UP, &ndev->flags)) { 564 /* Need to flush the cmd wq in case 565 * there is a queued/running cmd_work 566 */ 567 flush_workqueue(ndev->cmd_wq); 568 timer_delete_sync(&ndev->cmd_timer); 569 timer_delete_sync(&ndev->data_timer); 570 if (test_bit(NCI_DATA_EXCHANGE, &ndev->flags)) 571 nci_data_exchange_complete(ndev, NULL, 572 ndev->cur_conn_id, 573 -ENODEV); 574 mutex_unlock(&ndev->req_lock); 575 return 0; 576 } 577 578 /* Drop RX and TX queues */ 579 skb_queue_purge(&ndev->rx_q); 580 skb_queue_purge(&ndev->tx_q); 581 582 /* Flush TX wq, RX wq flush can't be under the lock */ 583 flush_workqueue(ndev->tx_wq); 584 585 /* Reset device */ 586 skb_queue_purge(&ndev->cmd_q); 587 atomic_set(&ndev->cmd_cnt, 1); 588 589 set_bit(NCI_INIT, &ndev->flags); 590 __nci_request(ndev, nci_reset_req, (void *)0, 591 msecs_to_jiffies(NCI_RESET_TIMEOUT)); 592 593 /* After this point our queues are empty 594 * rx work may be running but will see that NCI_UP was cleared 595 */ 596 ndev->ops->close(ndev); 597 598 clear_bit(NCI_INIT, &ndev->flags); 599 600 /* Flush cmd and tx wq */ 601 flush_workqueue(ndev->cmd_wq); 602 603 timer_delete_sync(&ndev->cmd_timer); 604 timer_delete_sync(&ndev->data_timer); 605 606 if (test_bit(NCI_DATA_EXCHANGE, &ndev->flags)) 607 nci_data_exchange_complete(ndev, NULL, ndev->cur_conn_id, 608 -ENODEV); 609 610 /* Clear flags except NCI_UNREG */ 611 ndev->flags &= BIT(NCI_UNREG); 612 613 mutex_unlock(&ndev->req_lock); 614 615 /* rx_work may take req_lock via nci_deactivate_target */ 616 flush_workqueue(ndev->rx_wq); 617 618 return 0; 619 } 620 621 /* NCI command timer function */ 622 static void nci_cmd_timer(struct timer_list *t) 623 { 624 struct nci_dev *ndev = timer_container_of(ndev, t, cmd_timer); 625 626 atomic_set(&ndev->cmd_cnt, 1); 627 queue_work(ndev->cmd_wq, &ndev->cmd_work); 628 } 629 630 /* NCI data exchange timer function */ 631 static void nci_data_timer(struct timer_list *t) 632 { 633 struct nci_dev *ndev = timer_container_of(ndev, t, data_timer); 634 635 set_bit(NCI_DATA_EXCHANGE_TO, &ndev->flags); 636 queue_work(ndev->rx_wq, &ndev->rx_work); 637 } 638 639 static int nci_dev_up(struct nfc_dev *nfc_dev) 640 { 641 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 642 643 return nci_open_device(ndev); 644 } 645 646 static int nci_dev_down(struct nfc_dev *nfc_dev) 647 { 648 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 649 650 return nci_close_device(ndev); 651 } 652 653 int nci_set_config(struct nci_dev *ndev, __u8 id, size_t len, const __u8 *val) 654 { 655 struct nci_set_config_param param; 656 657 if (!val || !len) 658 return 0; 659 660 param.id = id; 661 param.len = len; 662 param.val = val; 663 664 return __nci_request(ndev, nci_set_config_req, ¶m, 665 msecs_to_jiffies(NCI_SET_CONFIG_TIMEOUT)); 666 } 667 EXPORT_SYMBOL(nci_set_config); 668 669 static void nci_nfcee_discover_req(struct nci_dev *ndev, const void *opt) 670 { 671 struct nci_nfcee_discover_cmd cmd; 672 __u8 action = (unsigned long)opt; 673 674 cmd.discovery_action = action; 675 676 nci_send_cmd(ndev, NCI_OP_NFCEE_DISCOVER_CMD, 1, &cmd); 677 } 678 679 int nci_nfcee_discover(struct nci_dev *ndev, u8 action) 680 { 681 unsigned long opt = action; 682 683 return __nci_request(ndev, nci_nfcee_discover_req, (void *)opt, 684 msecs_to_jiffies(NCI_CMD_TIMEOUT)); 685 } 686 EXPORT_SYMBOL(nci_nfcee_discover); 687 688 static void nci_nfcee_mode_set_req(struct nci_dev *ndev, const void *opt) 689 { 690 const struct nci_nfcee_mode_set_cmd *cmd = opt; 691 692 nci_send_cmd(ndev, NCI_OP_NFCEE_MODE_SET_CMD, 693 sizeof(struct nci_nfcee_mode_set_cmd), cmd); 694 } 695 696 int nci_nfcee_mode_set(struct nci_dev *ndev, u8 nfcee_id, u8 nfcee_mode) 697 { 698 struct nci_nfcee_mode_set_cmd cmd; 699 700 cmd.nfcee_id = nfcee_id; 701 cmd.nfcee_mode = nfcee_mode; 702 703 return __nci_request(ndev, nci_nfcee_mode_set_req, &cmd, 704 msecs_to_jiffies(NCI_CMD_TIMEOUT)); 705 } 706 EXPORT_SYMBOL(nci_nfcee_mode_set); 707 708 static void nci_core_conn_create_req(struct nci_dev *ndev, const void *opt) 709 { 710 const struct core_conn_create_data *data = opt; 711 712 nci_send_cmd(ndev, NCI_OP_CORE_CONN_CREATE_CMD, data->length, data->cmd); 713 } 714 715 int nci_core_conn_create(struct nci_dev *ndev, u8 destination_type, 716 u8 number_destination_params, 717 size_t params_len, 718 const struct core_conn_create_dest_spec_params *params) 719 { 720 int r; 721 struct nci_core_conn_create_cmd *cmd; 722 struct core_conn_create_data data; 723 724 data.length = params_len + sizeof(struct nci_core_conn_create_cmd); 725 cmd = kzalloc(data.length, GFP_KERNEL); 726 if (!cmd) 727 return -ENOMEM; 728 729 cmd->destination_type = destination_type; 730 cmd->number_destination_params = number_destination_params; 731 732 data.cmd = cmd; 733 734 if (params) { 735 memcpy(cmd->params, params, params_len); 736 if (params->length > 0) 737 memcpy(&ndev->cur_params, 738 ¶ms->value[DEST_SPEC_PARAMS_ID_INDEX], 739 sizeof(struct dest_spec_params)); 740 else 741 ndev->cur_params.id = 0; 742 } else { 743 ndev->cur_params.id = 0; 744 } 745 ndev->cur_dest_type = destination_type; 746 747 r = __nci_request(ndev, nci_core_conn_create_req, &data, 748 msecs_to_jiffies(NCI_CMD_TIMEOUT)); 749 kfree(cmd); 750 return r; 751 } 752 EXPORT_SYMBOL(nci_core_conn_create); 753 754 static void nci_core_conn_close_req(struct nci_dev *ndev, const void *opt) 755 { 756 __u8 conn_id = (unsigned long)opt; 757 758 nci_send_cmd(ndev, NCI_OP_CORE_CONN_CLOSE_CMD, 1, &conn_id); 759 } 760 761 int nci_core_conn_close(struct nci_dev *ndev, u8 conn_id) 762 { 763 unsigned long opt = conn_id; 764 765 ndev->cur_conn_id = conn_id; 766 return __nci_request(ndev, nci_core_conn_close_req, (void *)opt, 767 msecs_to_jiffies(NCI_CMD_TIMEOUT)); 768 } 769 EXPORT_SYMBOL(nci_core_conn_close); 770 771 static void nci_set_target_ats(struct nfc_target *target, struct nci_dev *ndev) 772 { 773 if (ndev->target_ats_len > 0) { 774 target->ats_len = ndev->target_ats_len; 775 memcpy(target->ats, ndev->target_ats, target->ats_len); 776 } 777 } 778 779 static int nci_set_local_general_bytes(struct nfc_dev *nfc_dev) 780 { 781 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 782 struct nci_set_config_param param; 783 int rc; 784 785 param.val = nfc_get_local_general_bytes(nfc_dev, ¶m.len); 786 if ((param.val == NULL) || (param.len == 0)) 787 return 0; 788 789 if (param.len > NFC_MAX_GT_LEN) 790 return -EINVAL; 791 792 param.id = NCI_PN_ATR_REQ_GEN_BYTES; 793 794 rc = nci_request(ndev, nci_set_config_req, ¶m, 795 msecs_to_jiffies(NCI_SET_CONFIG_TIMEOUT)); 796 if (rc) 797 return rc; 798 799 param.id = NCI_LN_ATR_RES_GEN_BYTES; 800 801 return nci_request(ndev, nci_set_config_req, ¶m, 802 msecs_to_jiffies(NCI_SET_CONFIG_TIMEOUT)); 803 } 804 805 static int nci_set_listen_parameters(struct nfc_dev *nfc_dev) 806 { 807 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 808 int rc; 809 __u8 val; 810 811 val = NCI_LA_SEL_INFO_NFC_DEP_MASK; 812 813 rc = nci_set_config(ndev, NCI_LA_SEL_INFO, 1, &val); 814 if (rc) 815 return rc; 816 817 val = NCI_LF_PROTOCOL_TYPE_NFC_DEP_MASK; 818 819 rc = nci_set_config(ndev, NCI_LF_PROTOCOL_TYPE, 1, &val); 820 if (rc) 821 return rc; 822 823 val = NCI_LF_CON_BITR_F_212 | NCI_LF_CON_BITR_F_424; 824 825 return nci_set_config(ndev, NCI_LF_CON_BITR_F, 1, &val); 826 } 827 828 static int nci_start_poll(struct nfc_dev *nfc_dev, 829 __u32 im_protocols, __u32 tm_protocols) 830 { 831 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 832 struct nci_rf_discover_param param; 833 int rc; 834 835 if ((atomic_read(&ndev->state) == NCI_DISCOVERY) || 836 (atomic_read(&ndev->state) == NCI_W4_ALL_DISCOVERIES)) { 837 pr_err("unable to start poll, since poll is already active\n"); 838 return -EBUSY; 839 } 840 841 if (ndev->target_active_prot) { 842 pr_err("there is an active target\n"); 843 return -EBUSY; 844 } 845 846 if ((atomic_read(&ndev->state) == NCI_W4_HOST_SELECT) || 847 (atomic_read(&ndev->state) == NCI_POLL_ACTIVE)) { 848 pr_debug("target active or w4 select, implicitly deactivate\n"); 849 850 rc = nci_request(ndev, nci_rf_deactivate_req, 851 (void *)NCI_DEACTIVATE_TYPE_IDLE_MODE, 852 msecs_to_jiffies(NCI_RF_DEACTIVATE_TIMEOUT)); 853 if (rc) 854 return -EBUSY; 855 } 856 857 if ((im_protocols | tm_protocols) & NFC_PROTO_NFC_DEP_MASK) { 858 rc = nci_set_local_general_bytes(nfc_dev); 859 if (rc) { 860 pr_err("failed to set local general bytes\n"); 861 return rc; 862 } 863 } 864 865 if (tm_protocols & NFC_PROTO_NFC_DEP_MASK) { 866 rc = nci_set_listen_parameters(nfc_dev); 867 if (rc) 868 pr_err("failed to set listen parameters\n"); 869 } 870 871 param.im_protocols = im_protocols; 872 param.tm_protocols = tm_protocols; 873 rc = nci_request(ndev, nci_rf_discover_req, ¶m, 874 msecs_to_jiffies(NCI_RF_DISC_TIMEOUT)); 875 876 if (!rc) 877 ndev->poll_prots = im_protocols; 878 879 return rc; 880 } 881 882 static void nci_stop_poll(struct nfc_dev *nfc_dev) 883 { 884 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 885 886 if ((atomic_read(&ndev->state) != NCI_DISCOVERY) && 887 (atomic_read(&ndev->state) != NCI_W4_ALL_DISCOVERIES)) { 888 pr_err("unable to stop poll, since poll is not active\n"); 889 return; 890 } 891 892 nci_request(ndev, nci_rf_deactivate_req, 893 (void *)NCI_DEACTIVATE_TYPE_IDLE_MODE, 894 msecs_to_jiffies(NCI_RF_DEACTIVATE_TIMEOUT)); 895 } 896 897 static int nci_activate_target(struct nfc_dev *nfc_dev, 898 struct nfc_target *target, __u32 protocol) 899 { 900 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 901 struct nci_rf_discover_select_param param; 902 const struct nfc_target *nci_target = NULL; 903 int i; 904 int rc = 0; 905 906 pr_debug("target_idx %d, protocol 0x%x\n", target->idx, protocol); 907 908 if ((atomic_read(&ndev->state) != NCI_W4_HOST_SELECT) && 909 (atomic_read(&ndev->state) != NCI_POLL_ACTIVE)) { 910 pr_err("there is no available target to activate\n"); 911 return -EINVAL; 912 } 913 914 if (ndev->target_active_prot) { 915 pr_err("there is already an active target\n"); 916 return -EBUSY; 917 } 918 919 for (i = 0; i < ndev->n_targets; i++) { 920 if (ndev->targets[i].idx == target->idx) { 921 nci_target = &ndev->targets[i]; 922 break; 923 } 924 } 925 926 if (!nci_target) { 927 pr_err("unable to find the selected target\n"); 928 return -EINVAL; 929 } 930 931 if (protocol >= NFC_PROTO_MAX) { 932 pr_err("the requested nfc protocol is invalid\n"); 933 return -EINVAL; 934 } 935 936 if (!(nci_target->supported_protocols & (1 << protocol))) { 937 pr_err("target does not support the requested protocol 0x%x\n", 938 protocol); 939 return -EINVAL; 940 } 941 942 if (atomic_read(&ndev->state) == NCI_W4_HOST_SELECT) { 943 param.rf_discovery_id = nci_target->logical_idx; 944 945 if (protocol == NFC_PROTO_JEWEL) 946 param.rf_protocol = NCI_RF_PROTOCOL_T1T; 947 else if (protocol == NFC_PROTO_MIFARE) 948 param.rf_protocol = NCI_RF_PROTOCOL_T2T; 949 else if (protocol == NFC_PROTO_FELICA) 950 param.rf_protocol = NCI_RF_PROTOCOL_T3T; 951 else if (protocol == NFC_PROTO_ISO14443 || 952 protocol == NFC_PROTO_ISO14443_B) 953 param.rf_protocol = NCI_RF_PROTOCOL_ISO_DEP; 954 else 955 param.rf_protocol = NCI_RF_PROTOCOL_NFC_DEP; 956 957 rc = nci_request(ndev, nci_rf_discover_select_req, ¶m, 958 msecs_to_jiffies(NCI_RF_DISC_SELECT_TIMEOUT)); 959 } 960 961 if (!rc) { 962 ndev->target_active_prot = protocol; 963 if (protocol == NFC_PROTO_ISO14443) 964 nci_set_target_ats(target, ndev); 965 } 966 967 return rc; 968 } 969 970 static void nci_deactivate_target(struct nfc_dev *nfc_dev, 971 struct nfc_target *target, 972 __u8 mode) 973 { 974 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 975 unsigned long nci_mode = NCI_DEACTIVATE_TYPE_IDLE_MODE; 976 977 if (!ndev->target_active_prot) { 978 pr_err("unable to deactivate target, no active target\n"); 979 return; 980 } 981 982 ndev->target_active_prot = 0; 983 984 switch (mode) { 985 case NFC_TARGET_MODE_SLEEP: 986 nci_mode = NCI_DEACTIVATE_TYPE_SLEEP_MODE; 987 break; 988 } 989 990 if (atomic_read(&ndev->state) == NCI_POLL_ACTIVE) { 991 nci_request(ndev, nci_rf_deactivate_req, (void *)nci_mode, 992 msecs_to_jiffies(NCI_RF_DEACTIVATE_TIMEOUT)); 993 } 994 } 995 996 static int nci_dep_link_up(struct nfc_dev *nfc_dev, struct nfc_target *target, 997 __u8 comm_mode, __u8 *gb, size_t gb_len) 998 { 999 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 1000 int rc; 1001 1002 pr_debug("target_idx %d, comm_mode %d\n", target->idx, comm_mode); 1003 1004 rc = nci_activate_target(nfc_dev, target, NFC_PROTO_NFC_DEP); 1005 if (rc) 1006 return rc; 1007 1008 rc = nfc_set_remote_general_bytes(nfc_dev, ndev->remote_gb, 1009 ndev->remote_gb_len); 1010 if (!rc) 1011 rc = nfc_dep_link_is_up(nfc_dev, target->idx, NFC_COMM_PASSIVE, 1012 NFC_RF_INITIATOR); 1013 1014 return rc; 1015 } 1016 1017 static int nci_dep_link_down(struct nfc_dev *nfc_dev) 1018 { 1019 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 1020 int rc; 1021 1022 if (nfc_dev->rf_mode == NFC_RF_INITIATOR) { 1023 nci_deactivate_target(nfc_dev, NULL, NCI_DEACTIVATE_TYPE_IDLE_MODE); 1024 } else { 1025 if (atomic_read(&ndev->state) == NCI_LISTEN_ACTIVE || 1026 atomic_read(&ndev->state) == NCI_DISCOVERY) { 1027 nci_request(ndev, nci_rf_deactivate_req, (void *)0, 1028 msecs_to_jiffies(NCI_RF_DEACTIVATE_TIMEOUT)); 1029 } 1030 1031 rc = nfc_tm_deactivated(nfc_dev); 1032 if (rc) 1033 pr_err("error when signaling tm deactivation\n"); 1034 } 1035 1036 return 0; 1037 } 1038 1039 1040 static int nci_transceive(struct nfc_dev *nfc_dev, struct nfc_target *target, 1041 struct sk_buff *skb, 1042 data_exchange_cb_t cb, void *cb_context) 1043 { 1044 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 1045 int rc; 1046 struct nci_conn_info *conn_info; 1047 1048 conn_info = ndev->rf_conn_info; 1049 if (!conn_info) { 1050 kfree_skb(skb); 1051 return -EPROTO; 1052 } 1053 1054 pr_debug("target_idx %d, len %d\n", target->idx, skb->len); 1055 1056 if (!ndev->target_active_prot) { 1057 pr_err("unable to exchange data, no active target\n"); 1058 kfree_skb(skb); 1059 return -EINVAL; 1060 } 1061 1062 if (test_and_set_bit(NCI_DATA_EXCHANGE, &ndev->flags)) { 1063 kfree_skb(skb); 1064 return -EBUSY; 1065 } 1066 1067 /* store cb and context to be used on receiving data */ 1068 conn_info->data_exchange_cb = cb; 1069 conn_info->data_exchange_cb_context = cb_context; 1070 1071 rc = nci_send_data(ndev, NCI_STATIC_RF_CONN_ID, skb); 1072 if (rc) 1073 clear_bit(NCI_DATA_EXCHANGE, &ndev->flags); 1074 1075 return rc; 1076 } 1077 1078 static int nci_tm_send(struct nfc_dev *nfc_dev, struct sk_buff *skb) 1079 { 1080 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 1081 int rc; 1082 1083 rc = nci_send_data(ndev, NCI_STATIC_RF_CONN_ID, skb); 1084 if (rc) 1085 pr_err("unable to send data\n"); 1086 1087 return rc; 1088 } 1089 1090 static int nci_enable_se(struct nfc_dev *nfc_dev, u32 se_idx) 1091 { 1092 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 1093 1094 if (ndev->ops->enable_se) 1095 return ndev->ops->enable_se(ndev, se_idx); 1096 1097 return 0; 1098 } 1099 1100 static int nci_disable_se(struct nfc_dev *nfc_dev, u32 se_idx) 1101 { 1102 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 1103 1104 if (ndev->ops->disable_se) 1105 return ndev->ops->disable_se(ndev, se_idx); 1106 1107 return 0; 1108 } 1109 1110 static int nci_discover_se(struct nfc_dev *nfc_dev) 1111 { 1112 int r; 1113 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 1114 1115 if (ndev->ops->discover_se) { 1116 r = nci_nfcee_discover(ndev, NCI_NFCEE_DISCOVERY_ACTION_ENABLE); 1117 if (r != NCI_STATUS_OK) 1118 return -EPROTO; 1119 1120 return ndev->ops->discover_se(ndev); 1121 } 1122 1123 return 0; 1124 } 1125 1126 static int nci_se_io(struct nfc_dev *nfc_dev, u32 se_idx, 1127 u8 *apdu, size_t apdu_length, 1128 se_io_cb_t cb, void *cb_context) 1129 { 1130 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 1131 1132 if (ndev->ops->se_io) 1133 return ndev->ops->se_io(ndev, se_idx, apdu, 1134 apdu_length, cb, cb_context); 1135 1136 return 0; 1137 } 1138 1139 static int nci_fw_download(struct nfc_dev *nfc_dev, const char *firmware_name) 1140 { 1141 struct nci_dev *ndev = nfc_get_drvdata(nfc_dev); 1142 1143 if (!ndev->ops->fw_download) 1144 return -ENOTSUPP; 1145 1146 return ndev->ops->fw_download(ndev, firmware_name); 1147 } 1148 1149 static const struct nfc_ops nci_nfc_ops = { 1150 .dev_up = nci_dev_up, 1151 .dev_down = nci_dev_down, 1152 .start_poll = nci_start_poll, 1153 .stop_poll = nci_stop_poll, 1154 .dep_link_up = nci_dep_link_up, 1155 .dep_link_down = nci_dep_link_down, 1156 .activate_target = nci_activate_target, 1157 .deactivate_target = nci_deactivate_target, 1158 .im_transceive = nci_transceive, 1159 .tm_send = nci_tm_send, 1160 .enable_se = nci_enable_se, 1161 .disable_se = nci_disable_se, 1162 .discover_se = nci_discover_se, 1163 .se_io = nci_se_io, 1164 .fw_download = nci_fw_download, 1165 }; 1166 1167 /* ---- Interface to NCI drivers ---- */ 1168 /** 1169 * nci_allocate_device - allocate a new nci device 1170 * 1171 * @ops: device operations 1172 * @supported_protocols: NFC protocols supported by the device 1173 * @tx_headroom: Reserved space at beginning of skb 1174 * @tx_tailroom: Reserved space at end of skb 1175 */ 1176 struct nci_dev *nci_allocate_device(const struct nci_ops *ops, 1177 __u32 supported_protocols, 1178 int tx_headroom, int tx_tailroom) 1179 { 1180 struct nci_dev *ndev; 1181 1182 pr_debug("supported_protocols 0x%x\n", supported_protocols); 1183 1184 if (!ops->open || !ops->close || !ops->send) 1185 return NULL; 1186 1187 if (!supported_protocols) 1188 return NULL; 1189 1190 ndev = kzalloc_obj(struct nci_dev); 1191 if (!ndev) 1192 return NULL; 1193 1194 ndev->ops = ops; 1195 1196 if (ops->n_prop_ops > NCI_MAX_PROPRIETARY_CMD) { 1197 pr_err("Too many proprietary commands: %zd\n", 1198 ops->n_prop_ops); 1199 goto free_nci; 1200 } 1201 1202 ndev->tx_headroom = tx_headroom; 1203 ndev->tx_tailroom = tx_tailroom; 1204 init_completion(&ndev->req_completion); 1205 1206 ndev->nfc_dev = nfc_allocate_device(&nci_nfc_ops, 1207 supported_protocols, 1208 tx_headroom + NCI_DATA_HDR_SIZE, 1209 tx_tailroom); 1210 if (!ndev->nfc_dev) 1211 goto free_nci; 1212 1213 ndev->hci_dev = nci_hci_allocate(ndev); 1214 if (!ndev->hci_dev) 1215 goto free_nfc; 1216 1217 nfc_set_drvdata(ndev->nfc_dev, ndev); 1218 1219 return ndev; 1220 1221 free_nfc: 1222 nfc_free_device(ndev->nfc_dev); 1223 free_nci: 1224 kfree(ndev); 1225 return NULL; 1226 } 1227 EXPORT_SYMBOL(nci_allocate_device); 1228 1229 /** 1230 * nci_free_device - deallocate nci device 1231 * 1232 * @ndev: The nci device to deallocate 1233 */ 1234 void nci_free_device(struct nci_dev *ndev) 1235 { 1236 nfc_free_device(ndev->nfc_dev); 1237 nci_hci_deallocate(ndev); 1238 1239 /* drop partial rx data packet if present */ 1240 if (ndev->rx_data_reassembly) 1241 kfree_skb(ndev->rx_data_reassembly); 1242 kfree(ndev); 1243 } 1244 EXPORT_SYMBOL(nci_free_device); 1245 1246 /** 1247 * nci_register_device - register a nci device in the nfc subsystem 1248 * 1249 * @ndev: The nci device to register 1250 */ 1251 int nci_register_device(struct nci_dev *ndev) 1252 { 1253 int rc; 1254 struct device *dev = &ndev->nfc_dev->dev; 1255 char name[32]; 1256 1257 ndev->flags = 0; 1258 1259 INIT_WORK(&ndev->cmd_work, nci_cmd_work); 1260 snprintf(name, sizeof(name), "%s_nci_cmd_wq", dev_name(dev)); 1261 ndev->cmd_wq = create_singlethread_workqueue(name); 1262 if (!ndev->cmd_wq) { 1263 rc = -ENOMEM; 1264 goto exit; 1265 } 1266 1267 INIT_WORK(&ndev->rx_work, nci_rx_work); 1268 snprintf(name, sizeof(name), "%s_nci_rx_wq", dev_name(dev)); 1269 ndev->rx_wq = create_singlethread_workqueue(name); 1270 if (!ndev->rx_wq) { 1271 rc = -ENOMEM; 1272 goto destroy_cmd_wq_exit; 1273 } 1274 1275 INIT_WORK(&ndev->tx_work, nci_tx_work); 1276 snprintf(name, sizeof(name), "%s_nci_tx_wq", dev_name(dev)); 1277 ndev->tx_wq = create_singlethread_workqueue(name); 1278 if (!ndev->tx_wq) { 1279 rc = -ENOMEM; 1280 goto destroy_rx_wq_exit; 1281 } 1282 1283 skb_queue_head_init(&ndev->cmd_q); 1284 skb_queue_head_init(&ndev->rx_q); 1285 skb_queue_head_init(&ndev->tx_q); 1286 1287 timer_setup(&ndev->cmd_timer, nci_cmd_timer, 0); 1288 timer_setup(&ndev->data_timer, nci_data_timer, 0); 1289 1290 mutex_init(&ndev->req_lock); 1291 INIT_LIST_HEAD(&ndev->conn_info_list); 1292 1293 rc = nfc_register_device(ndev->nfc_dev); 1294 if (rc) 1295 goto destroy_tx_wq_exit; 1296 1297 goto exit; 1298 1299 destroy_tx_wq_exit: 1300 destroy_workqueue(ndev->tx_wq); 1301 1302 destroy_rx_wq_exit: 1303 destroy_workqueue(ndev->rx_wq); 1304 1305 destroy_cmd_wq_exit: 1306 destroy_workqueue(ndev->cmd_wq); 1307 1308 exit: 1309 return rc; 1310 } 1311 EXPORT_SYMBOL(nci_register_device); 1312 1313 /** 1314 * nci_unregister_device - unregister a nci device in the nfc subsystem 1315 * 1316 * @ndev: The nci device to unregister 1317 */ 1318 void nci_unregister_device(struct nci_dev *ndev) 1319 { 1320 struct nci_conn_info *conn_info, *n; 1321 1322 nfc_unregister_rfkill(ndev->nfc_dev); 1323 1324 /* This set_bit is not protected with specialized barrier, 1325 * However, it is fine because the mutex_lock(&ndev->req_lock); 1326 * in nci_close_device() will help to emit one. 1327 */ 1328 set_bit(NCI_UNREG, &ndev->flags); 1329 1330 nci_close_device(ndev); 1331 1332 destroy_workqueue(ndev->cmd_wq); 1333 destroy_workqueue(ndev->rx_wq); 1334 destroy_workqueue(ndev->tx_wq); 1335 1336 list_for_each_entry_safe(conn_info, n, &ndev->conn_info_list, list) { 1337 list_del(&conn_info->list); 1338 /* conn_info is allocated with devm_kzalloc */ 1339 } 1340 1341 nfc_remove_device(ndev->nfc_dev); 1342 } 1343 EXPORT_SYMBOL(nci_unregister_device); 1344 1345 /** 1346 * nci_recv_frame - receive frame from NCI drivers 1347 * 1348 * @ndev: The nci device 1349 * @skb: The sk_buff to receive 1350 */ 1351 int nci_recv_frame(struct nci_dev *ndev, struct sk_buff *skb) 1352 { 1353 pr_debug("len %d\n", skb->len); 1354 1355 if (!ndev || (!test_bit(NCI_UP, &ndev->flags) && 1356 !test_bit(NCI_INIT, &ndev->flags))) { 1357 kfree_skb(skb); 1358 return -ENXIO; 1359 } 1360 1361 /* Queue frame for rx worker thread */ 1362 skb_queue_tail(&ndev->rx_q, skb); 1363 queue_work(ndev->rx_wq, &ndev->rx_work); 1364 1365 return 0; 1366 } 1367 EXPORT_SYMBOL(nci_recv_frame); 1368 1369 int nci_send_frame(struct nci_dev *ndev, struct sk_buff *skb) 1370 { 1371 pr_debug("len %d\n", skb->len); 1372 1373 if (!ndev) { 1374 kfree_skb(skb); 1375 return -ENODEV; 1376 } 1377 1378 /* Get rid of skb owner, prior to sending to the driver. */ 1379 skb_orphan(skb); 1380 1381 /* Send copy to sniffer */ 1382 nfc_send_to_raw_sock(ndev->nfc_dev, skb, 1383 RAW_PAYLOAD_NCI, NFC_DIRECTION_TX); 1384 1385 return ndev->ops->send(ndev, skb); 1386 } 1387 EXPORT_SYMBOL(nci_send_frame); 1388 1389 /* Send NCI command */ 1390 int nci_send_cmd(struct nci_dev *ndev, __u16 opcode, __u8 plen, const void *payload) 1391 { 1392 struct nci_ctrl_hdr *hdr; 1393 struct sk_buff *skb; 1394 1395 pr_debug("opcode 0x%x, plen %d\n", opcode, plen); 1396 1397 skb = nci_skb_alloc(ndev, (NCI_CTRL_HDR_SIZE + plen), GFP_KERNEL); 1398 if (!skb) { 1399 pr_err("no memory for command\n"); 1400 return -ENOMEM; 1401 } 1402 1403 hdr = skb_put(skb, NCI_CTRL_HDR_SIZE); 1404 hdr->gid = nci_opcode_gid(opcode); 1405 hdr->oid = nci_opcode_oid(opcode); 1406 hdr->plen = plen; 1407 1408 nci_mt_set((__u8 *)hdr, NCI_MT_CMD_PKT); 1409 nci_pbf_set((__u8 *)hdr, NCI_PBF_LAST); 1410 1411 if (plen) 1412 skb_put_data(skb, payload, plen); 1413 1414 skb_queue_tail(&ndev->cmd_q, skb); 1415 queue_work(ndev->cmd_wq, &ndev->cmd_work); 1416 1417 return 0; 1418 } 1419 EXPORT_SYMBOL(nci_send_cmd); 1420 1421 /* Proprietary commands API */ 1422 static const struct nci_driver_ops *ops_cmd_lookup(const struct nci_driver_ops *ops, 1423 size_t n_ops, 1424 __u16 opcode) 1425 { 1426 size_t i; 1427 const struct nci_driver_ops *op; 1428 1429 if (!ops || !n_ops) 1430 return NULL; 1431 1432 for (i = 0; i < n_ops; i++) { 1433 op = &ops[i]; 1434 if (op->opcode == opcode) 1435 return op; 1436 } 1437 1438 return NULL; 1439 } 1440 1441 static int nci_op_rsp_packet(struct nci_dev *ndev, __u16 rsp_opcode, 1442 struct sk_buff *skb, const struct nci_driver_ops *ops, 1443 size_t n_ops) 1444 { 1445 const struct nci_driver_ops *op; 1446 1447 op = ops_cmd_lookup(ops, n_ops, rsp_opcode); 1448 if (!op || !op->rsp) 1449 return -ENOTSUPP; 1450 1451 return op->rsp(ndev, skb); 1452 } 1453 1454 static int nci_op_ntf_packet(struct nci_dev *ndev, __u16 ntf_opcode, 1455 struct sk_buff *skb, const struct nci_driver_ops *ops, 1456 size_t n_ops) 1457 { 1458 const struct nci_driver_ops *op; 1459 1460 op = ops_cmd_lookup(ops, n_ops, ntf_opcode); 1461 if (!op || !op->ntf) 1462 return -ENOTSUPP; 1463 1464 return op->ntf(ndev, skb); 1465 } 1466 1467 int nci_prop_rsp_packet(struct nci_dev *ndev, __u16 opcode, 1468 struct sk_buff *skb) 1469 { 1470 return nci_op_rsp_packet(ndev, opcode, skb, ndev->ops->prop_ops, 1471 ndev->ops->n_prop_ops); 1472 } 1473 1474 int nci_prop_ntf_packet(struct nci_dev *ndev, __u16 opcode, 1475 struct sk_buff *skb) 1476 { 1477 return nci_op_ntf_packet(ndev, opcode, skb, ndev->ops->prop_ops, 1478 ndev->ops->n_prop_ops); 1479 } 1480 1481 int nci_core_rsp_packet(struct nci_dev *ndev, __u16 opcode, 1482 struct sk_buff *skb) 1483 { 1484 return nci_op_rsp_packet(ndev, opcode, skb, ndev->ops->core_ops, 1485 ndev->ops->n_core_ops); 1486 } 1487 1488 int nci_core_ntf_packet(struct nci_dev *ndev, __u16 opcode, 1489 struct sk_buff *skb) 1490 { 1491 return nci_op_ntf_packet(ndev, opcode, skb, ndev->ops->core_ops, 1492 ndev->ops->n_core_ops); 1493 } 1494 1495 static bool nci_valid_size(struct sk_buff *skb) 1496 { 1497 BUILD_BUG_ON(NCI_CTRL_HDR_SIZE != NCI_DATA_HDR_SIZE); 1498 unsigned int hdr_size = NCI_CTRL_HDR_SIZE; 1499 1500 if (skb->len < hdr_size || 1501 skb->len < hdr_size + nci_plen(skb->data)) { 1502 return false; 1503 } 1504 1505 if (!nci_plen(skb->data)) { 1506 /* Allow zero length in proprietary notifications (0x20 - 0x3F). */ 1507 if (nci_opcode_oid(nci_opcode(skb->data)) >= 0x20 && 1508 nci_mt(skb->data) == NCI_MT_NTF_PKT) 1509 return true; 1510 1511 /* Disallow zero length otherwise. */ 1512 return false; 1513 } 1514 1515 return true; 1516 } 1517 1518 /* ---- NCI TX Data worker thread ---- */ 1519 1520 static void nci_tx_work(struct work_struct *work) 1521 { 1522 struct nci_dev *ndev = container_of(work, struct nci_dev, tx_work); 1523 struct nci_conn_info *conn_info; 1524 struct sk_buff *skb; 1525 1526 conn_info = nci_get_conn_info_by_conn_id(ndev, ndev->cur_conn_id); 1527 if (!conn_info) 1528 return; 1529 1530 pr_debug("credits_cnt %d\n", atomic_read(&conn_info->credits_cnt)); 1531 1532 /* Send queued tx data */ 1533 while (atomic_read(&conn_info->credits_cnt)) { 1534 skb = skb_dequeue(&ndev->tx_q); 1535 if (!skb) 1536 return; 1537 kcov_remote_start_common(skb_get_kcov_handle(skb)); 1538 1539 /* Check if data flow control is used */ 1540 if (atomic_read(&conn_info->credits_cnt) != 1541 NCI_DATA_FLOW_CONTROL_NOT_USED) 1542 atomic_dec(&conn_info->credits_cnt); 1543 1544 pr_debug("NCI TX: MT=data, PBF=%d, conn_id=%d, plen=%d\n", 1545 nci_pbf(skb->data), 1546 nci_conn_id(skb->data), 1547 nci_plen(skb->data)); 1548 1549 nci_send_frame(ndev, skb); 1550 1551 mod_timer(&ndev->data_timer, 1552 jiffies + msecs_to_jiffies(NCI_DATA_TIMEOUT)); 1553 kcov_remote_stop(); 1554 } 1555 } 1556 1557 /* ----- NCI RX worker thread (data & control) ----- */ 1558 1559 static void nci_rx_work(struct work_struct *work) 1560 { 1561 struct nci_dev *ndev = container_of(work, struct nci_dev, rx_work); 1562 struct sk_buff *skb; 1563 1564 for (; (skb = skb_dequeue(&ndev->rx_q)); kcov_remote_stop()) { 1565 kcov_remote_start_common(skb_get_kcov_handle(skb)); 1566 1567 /* Send copy to sniffer */ 1568 nfc_send_to_raw_sock(ndev->nfc_dev, skb, 1569 RAW_PAYLOAD_NCI, NFC_DIRECTION_RX); 1570 1571 if (!nci_valid_size(skb)) { 1572 kfree_skb(skb); 1573 continue; 1574 } 1575 1576 /* Process frame */ 1577 switch (nci_mt(skb->data)) { 1578 case NCI_MT_RSP_PKT: 1579 nci_rsp_packet(ndev, skb); 1580 break; 1581 1582 case NCI_MT_NTF_PKT: 1583 nci_ntf_packet(ndev, skb); 1584 break; 1585 1586 case NCI_MT_DATA_PKT: 1587 nci_rx_data_packet(ndev, skb); 1588 break; 1589 1590 default: 1591 pr_err("unknown MT 0x%x\n", nci_mt(skb->data)); 1592 kfree_skb(skb); 1593 break; 1594 } 1595 } 1596 1597 /* check if a data exchange timeout has occurred */ 1598 if (test_bit(NCI_DATA_EXCHANGE_TO, &ndev->flags)) { 1599 /* complete the data exchange transaction, if exists */ 1600 if (test_bit(NCI_DATA_EXCHANGE, &ndev->flags)) 1601 nci_data_exchange_complete(ndev, NULL, 1602 ndev->cur_conn_id, 1603 -ETIMEDOUT); 1604 1605 clear_bit(NCI_DATA_EXCHANGE_TO, &ndev->flags); 1606 } 1607 } 1608 1609 /* ----- NCI TX CMD worker thread ----- */ 1610 1611 static void nci_cmd_work(struct work_struct *work) 1612 { 1613 struct nci_dev *ndev = container_of(work, struct nci_dev, cmd_work); 1614 struct sk_buff *skb; 1615 1616 pr_debug("cmd_cnt %d\n", atomic_read(&ndev->cmd_cnt)); 1617 1618 /* Send queued command */ 1619 if (atomic_read(&ndev->cmd_cnt)) { 1620 skb = skb_dequeue(&ndev->cmd_q); 1621 if (!skb) 1622 return; 1623 1624 kcov_remote_start_common(skb_get_kcov_handle(skb)); 1625 atomic_dec(&ndev->cmd_cnt); 1626 1627 pr_debug("NCI TX: MT=cmd, PBF=%d, GID=0x%x, OID=0x%x, plen=%d\n", 1628 nci_pbf(skb->data), 1629 nci_opcode_gid(nci_opcode(skb->data)), 1630 nci_opcode_oid(nci_opcode(skb->data)), 1631 nci_plen(skb->data)); 1632 1633 nci_send_frame(ndev, skb); 1634 1635 mod_timer(&ndev->cmd_timer, 1636 jiffies + msecs_to_jiffies(NCI_CMD_TIMEOUT)); 1637 kcov_remote_stop(); 1638 } 1639 } 1640 1641 MODULE_DESCRIPTION("NFC Controller Interface"); 1642 MODULE_LICENSE("GPL"); 1643