xref: /freebsd/sys/compat/linuxkpi/common/src/linux_usb.c (revision 5ac01ce026aa871e24065f931b5b5c36024c96f9)
1 /* $FreeBSD$ */
2 /*-
3  * Copyright (c) 2007 Luigi Rizzo - Universita` di Pisa. All rights reserved.
4  * Copyright (c) 2007 Hans Petter Selasky. All rights reserved.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions
8  * are met:
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice, this list of conditions and the following disclaimer.
11  * 2. Redistributions in binary form must reproduce the above copyright
12  *    notice, this list of conditions and the following disclaimer in the
13  *    documentation and/or other materials provided with the distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
16  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
19  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
25  * SUCH DAMAGE.
26  */
27 
28 #ifdef USB_GLOBAL_INCLUDE_FILE
29 #include USB_GLOBAL_INCLUDE_FILE
30 #else
31 #include <sys/stdint.h>
32 #include <sys/stddef.h>
33 #include <sys/param.h>
34 #include <sys/queue.h>
35 #include <sys/types.h>
36 #include <sys/systm.h>
37 #include <sys/kernel.h>
38 #include <sys/bus.h>
39 #include <sys/module.h>
40 #include <sys/lock.h>
41 #include <sys/mutex.h>
42 #include <sys/condvar.h>
43 #include <sys/sysctl.h>
44 #include <sys/sx.h>
45 #include <sys/unistd.h>
46 #include <sys/callout.h>
47 #include <sys/malloc.h>
48 #include <sys/priv.h>
49 
50 #include <dev/usb/usb.h>
51 #include <dev/usb/usbdi.h>
52 #include <dev/usb/usbdi_util.h>
53 
54 #define	USB_DEBUG_VAR usb_debug
55 
56 #include <dev/usb/usb_core.h>
57 #include <linux/usb.h>
58 #include <dev/usb/usb_process.h>
59 #include <dev/usb/usb_device.h>
60 #include <dev/usb/usb_util.h>
61 #include <dev/usb/usb_busdma.h>
62 #include <dev/usb/usb_transfer.h>
63 #include <dev/usb/usb_hub.h>
64 #include <dev/usb/usb_request.h>
65 #include <dev/usb/usb_debug.h>
66 #include <dev/usb/usb_dynamic.h>
67 #endif			/* USB_GLOBAL_INCLUDE_FILE */
68 
69 struct usb_linux_softc {
70 	LIST_ENTRY(usb_linux_softc) sc_attached_list;
71 
72 	device_t sc_fbsd_dev;
73 	struct usb_device *sc_fbsd_udev;
74 	struct usb_interface *sc_ui;
75 	struct usb_driver *sc_udrv;
76 };
77 
78 /* prototypes */
79 static device_probe_t usb_linux_probe;
80 static device_attach_t usb_linux_attach;
81 static device_detach_t usb_linux_detach;
82 static device_suspend_t usb_linux_suspend;
83 static device_resume_t usb_linux_resume;
84 
85 static usb_callback_t usb_linux_isoc_callback;
86 static usb_callback_t usb_linux_non_isoc_callback;
87 
88 static usb_complete_t usb_linux_wait_complete;
89 
90 static uint16_t	usb_max_isoc_frames(struct usb_device *);
91 static int	usb_start_wait_urb(struct urb *, usb_timeout_t, uint16_t *);
92 static const struct usb_device_id *usb_linux_lookup_id(
93 		    const struct usb_device_id *, struct usb_attach_arg *);
94 static struct	usb_driver *usb_linux_get_usb_driver(struct usb_linux_softc *);
95 static int	usb_linux_create_usb_device(struct usb_device *, device_t);
96 static void	usb_linux_cleanup_interface(struct usb_device *,
97 		    struct usb_interface *);
98 static void	usb_linux_complete(struct usb_xfer *);
99 static int	usb_unlink_urb_sub(struct urb *, uint8_t);
100 
101 /*------------------------------------------------------------------------*
102  * FreeBSD USB interface
103  *------------------------------------------------------------------------*/
104 
105 static LIST_HEAD(, usb_linux_softc) usb_linux_attached_list;
106 static LIST_HEAD(, usb_driver) usb_linux_driver_list;
107 
108 static device_method_t usb_linux_methods[] = {
109 	/* Device interface */
110 	DEVMETHOD(device_probe, usb_linux_probe),
111 	DEVMETHOD(device_attach, usb_linux_attach),
112 	DEVMETHOD(device_detach, usb_linux_detach),
113 	DEVMETHOD(device_suspend, usb_linux_suspend),
114 	DEVMETHOD(device_resume, usb_linux_resume),
115 
116 	DEVMETHOD_END
117 };
118 
119 static driver_t usb_linux_driver = {
120 	.name = "usb_linux",
121 	.methods = usb_linux_methods,
122 	.size = sizeof(struct usb_linux_softc),
123 };
124 
125 static devclass_t usb_linux_devclass;
126 
127 DRIVER_MODULE(usb_linux, uhub, usb_linux_driver, usb_linux_devclass, NULL, 0);
128 MODULE_VERSION(usb_linux, 1);
129 
130 /*------------------------------------------------------------------------*
131  *	usb_linux_lookup_id
132  *
133  * This functions takes an array of "struct usb_device_id" and tries
134  * to match the entries with the information in "struct usb_attach_arg".
135  * If it finds a match the matching entry will be returned.
136  * Else "NULL" will be returned.
137  *------------------------------------------------------------------------*/
138 static const struct usb_device_id *
139 usb_linux_lookup_id(const struct usb_device_id *id, struct usb_attach_arg *uaa)
140 {
141 	if (id == NULL) {
142 		goto done;
143 	}
144 	/*
145 	 * Keep on matching array entries until we find one with
146 	 * "match_flags" equal to zero, which indicates the end of the
147 	 * array:
148 	 */
149 	for (; id->match_flags; id++) {
150 
151 		if ((id->match_flags & USB_DEVICE_ID_MATCH_VENDOR) &&
152 		    (id->idVendor != uaa->info.idVendor)) {
153 			continue;
154 		}
155 		if ((id->match_flags & USB_DEVICE_ID_MATCH_PRODUCT) &&
156 		    (id->idProduct != uaa->info.idProduct)) {
157 			continue;
158 		}
159 		if ((id->match_flags & USB_DEVICE_ID_MATCH_DEV_LO) &&
160 		    (id->bcdDevice_lo > uaa->info.bcdDevice)) {
161 			continue;
162 		}
163 		if ((id->match_flags & USB_DEVICE_ID_MATCH_DEV_HI) &&
164 		    (id->bcdDevice_hi < uaa->info.bcdDevice)) {
165 			continue;
166 		}
167 		if ((id->match_flags & USB_DEVICE_ID_MATCH_DEV_CLASS) &&
168 		    (id->bDeviceClass != uaa->info.bDeviceClass)) {
169 			continue;
170 		}
171 		if ((id->match_flags & USB_DEVICE_ID_MATCH_DEV_SUBCLASS) &&
172 		    (id->bDeviceSubClass != uaa->info.bDeviceSubClass)) {
173 			continue;
174 		}
175 		if ((id->match_flags & USB_DEVICE_ID_MATCH_DEV_PROTOCOL) &&
176 		    (id->bDeviceProtocol != uaa->info.bDeviceProtocol)) {
177 			continue;
178 		}
179 		if ((uaa->info.bDeviceClass == 0xFF) &&
180 		    !(id->match_flags & USB_DEVICE_ID_MATCH_VENDOR) &&
181 		    (id->match_flags & (USB_DEVICE_ID_MATCH_INT_CLASS |
182 		    USB_DEVICE_ID_MATCH_INT_SUBCLASS |
183 		    USB_DEVICE_ID_MATCH_INT_PROTOCOL))) {
184 			continue;
185 		}
186 		if ((id->match_flags & USB_DEVICE_ID_MATCH_INT_CLASS) &&
187 		    (id->bInterfaceClass != uaa->info.bInterfaceClass)) {
188 			continue;
189 		}
190 		if ((id->match_flags & USB_DEVICE_ID_MATCH_INT_SUBCLASS) &&
191 		    (id->bInterfaceSubClass != uaa->info.bInterfaceSubClass)) {
192 			continue;
193 		}
194 		if ((id->match_flags & USB_DEVICE_ID_MATCH_INT_PROTOCOL) &&
195 		    (id->bInterfaceProtocol != uaa->info.bInterfaceProtocol)) {
196 			continue;
197 		}
198 		/* we found a match! */
199 		return (id);
200 	}
201 
202 done:
203 	return (NULL);
204 }
205 
206 /*------------------------------------------------------------------------*
207  *	usb_linux_probe
208  *
209  * This function is the FreeBSD probe callback. It is called from the
210  * FreeBSD USB stack through the "device_probe_and_attach()" function.
211  *------------------------------------------------------------------------*/
212 static int
213 usb_linux_probe(device_t dev)
214 {
215 	struct usb_attach_arg *uaa = device_get_ivars(dev);
216 	struct usb_driver *udrv;
217 	int err = ENXIO;
218 
219 	if (uaa->usb_mode != USB_MODE_HOST) {
220 		return (ENXIO);
221 	}
222 	mtx_lock(&Giant);
223 	LIST_FOREACH(udrv, &usb_linux_driver_list, linux_driver_list) {
224 		if (usb_linux_lookup_id(udrv->id_table, uaa)) {
225 			err = 0;
226 			break;
227 		}
228 	}
229 	mtx_unlock(&Giant);
230 
231 	return (err);
232 }
233 
234 /*------------------------------------------------------------------------*
235  *	usb_linux_get_usb_driver
236  *
237  * This function returns the pointer to the "struct usb_driver" where
238  * the Linux USB device driver "struct usb_device_id" match was found.
239  * We apply a lock before reading out the pointer to avoid races.
240  *------------------------------------------------------------------------*/
241 static struct usb_driver *
242 usb_linux_get_usb_driver(struct usb_linux_softc *sc)
243 {
244 	struct usb_driver *udrv;
245 
246 	mtx_lock(&Giant);
247 	udrv = sc->sc_udrv;
248 	mtx_unlock(&Giant);
249 	return (udrv);
250 }
251 
252 /*------------------------------------------------------------------------*
253  *	usb_linux_attach
254  *
255  * This function is the FreeBSD attach callback. It is called from the
256  * FreeBSD USB stack through the "device_probe_and_attach()" function.
257  * This function is called when "usb_linux_probe()" returns zero.
258  *------------------------------------------------------------------------*/
259 static int
260 usb_linux_attach(device_t dev)
261 {
262 	struct usb_attach_arg *uaa = device_get_ivars(dev);
263 	struct usb_linux_softc *sc = device_get_softc(dev);
264 	struct usb_driver *udrv;
265 	const struct usb_device_id *id = NULL;
266 
267 	mtx_lock(&Giant);
268 	LIST_FOREACH(udrv, &usb_linux_driver_list, linux_driver_list) {
269 		id = usb_linux_lookup_id(udrv->id_table, uaa);
270 		if (id)
271 			break;
272 	}
273 	mtx_unlock(&Giant);
274 
275 	if (id == NULL) {
276 		return (ENXIO);
277 	}
278 	if (usb_linux_create_usb_device(uaa->device, dev) != 0)
279 		return (ENOMEM);
280 	device_set_usb_desc(dev);
281 
282 	sc->sc_fbsd_udev = uaa->device;
283 	sc->sc_fbsd_dev = dev;
284 	sc->sc_udrv = udrv;
285 	sc->sc_ui = usb_ifnum_to_if(uaa->device, uaa->info.bIfaceNum);
286 	if (sc->sc_ui == NULL) {
287 		return (EINVAL);
288 	}
289 	if (udrv->probe) {
290 		if ((udrv->probe) (sc->sc_ui, id)) {
291 			return (ENXIO);
292 		}
293 	}
294 	mtx_lock(&Giant);
295 	LIST_INSERT_HEAD(&usb_linux_attached_list, sc, sc_attached_list);
296 	mtx_unlock(&Giant);
297 
298 	/* success */
299 	return (0);
300 }
301 
302 /*------------------------------------------------------------------------*
303  *	usb_linux_detach
304  *
305  * This function is the FreeBSD detach callback. It is called from the
306  * FreeBSD USB stack through the "device_detach()" function.
307  *------------------------------------------------------------------------*/
308 static int
309 usb_linux_detach(device_t dev)
310 {
311 	struct usb_linux_softc *sc = device_get_softc(dev);
312 	struct usb_driver *udrv = NULL;
313 
314 	mtx_lock(&Giant);
315 	if (sc->sc_attached_list.le_prev) {
316 		LIST_REMOVE(sc, sc_attached_list);
317 		sc->sc_attached_list.le_prev = NULL;
318 		udrv = sc->sc_udrv;
319 		sc->sc_udrv = NULL;
320 	}
321 	mtx_unlock(&Giant);
322 
323 	if (udrv && udrv->disconnect) {
324 		(udrv->disconnect) (sc->sc_ui);
325 	}
326 	/*
327 	 * Make sure that we free all FreeBSD USB transfers belonging to
328 	 * this Linux "usb_interface", hence they will most likely not be
329 	 * needed any more.
330 	 */
331 	usb_linux_cleanup_interface(sc->sc_fbsd_udev, sc->sc_ui);
332 	return (0);
333 }
334 
335 /*------------------------------------------------------------------------*
336  *	usb_linux_suspend
337  *
338  * This function is the FreeBSD suspend callback. Usually it does nothing.
339  *------------------------------------------------------------------------*/
340 static int
341 usb_linux_suspend(device_t dev)
342 {
343 	struct usb_linux_softc *sc = device_get_softc(dev);
344 	struct usb_driver *udrv = usb_linux_get_usb_driver(sc);
345 	int err;
346 
347 	if (udrv && udrv->suspend) {
348 		err = (udrv->suspend) (sc->sc_ui, 0);
349 	}
350 	return (0);
351 }
352 
353 /*------------------------------------------------------------------------*
354  *	usb_linux_resume
355  *
356  * This function is the FreeBSD resume callback. Usually it does nothing.
357  *------------------------------------------------------------------------*/
358 static int
359 usb_linux_resume(device_t dev)
360 {
361 	struct usb_linux_softc *sc = device_get_softc(dev);
362 	struct usb_driver *udrv = usb_linux_get_usb_driver(sc);
363 	int err;
364 
365 	if (udrv && udrv->resume) {
366 		err = (udrv->resume) (sc->sc_ui);
367 	}
368 	return (0);
369 }
370 
371 /*------------------------------------------------------------------------*
372  * Linux emulation layer
373  *------------------------------------------------------------------------*/
374 
375 /*------------------------------------------------------------------------*
376  *	usb_max_isoc_frames
377  *
378  * The following function returns the maximum number of isochronous
379  * frames that we support per URB. It is not part of the Linux USB API.
380  *------------------------------------------------------------------------*/
381 static uint16_t
382 usb_max_isoc_frames(struct usb_device *dev)
383 {
384 	;				/* indent fix */
385 	switch (usbd_get_speed(dev)) {
386 	case USB_SPEED_LOW:
387 	case USB_SPEED_FULL:
388 		return (USB_MAX_FULL_SPEED_ISOC_FRAMES);
389 	default:
390 		return (USB_MAX_HIGH_SPEED_ISOC_FRAMES);
391 	}
392 }
393 
394 /*------------------------------------------------------------------------*
395  *	usb_submit_urb
396  *
397  * This function is used to queue an URB after that it has been
398  * initialized. If it returns non-zero, it means that the URB was not
399  * queued.
400  *------------------------------------------------------------------------*/
401 int
402 usb_submit_urb(struct urb *urb, uint16_t mem_flags)
403 {
404 	struct usb_host_endpoint *uhe;
405 	uint8_t do_unlock;
406 	int err;
407 
408 	if (urb == NULL)
409 		return (-EINVAL);
410 
411 	do_unlock = mtx_owned(&Giant) ? 0 : 1;
412 	if (do_unlock)
413 		mtx_lock(&Giant);
414 
415 	if (urb->endpoint == NULL) {
416 		err = -EINVAL;
417 		goto done;
418 	}
419 
420 	/*
421 	 * Check to see if the urb is in the process of being killed
422 	 * and stop a urb that is in the process of being killed from
423 	 * being re-submitted (e.g. from its completion callback
424 	 * function).
425 	 */
426 	if (urb->kill_count != 0) {
427 		err = -EPERM;
428 		goto done;
429 	}
430 
431 	uhe = urb->endpoint;
432 
433 	/*
434 	 * Check that we have got a FreeBSD USB transfer that will dequeue
435 	 * the URB structure and do the real transfer. If there are no USB
436 	 * transfers, then we return an error.
437 	 */
438 	if (uhe->bsd_xfer[0] ||
439 	    uhe->bsd_xfer[1]) {
440 		/* we are ready! */
441 
442 		TAILQ_INSERT_TAIL(&uhe->bsd_urb_list, urb, bsd_urb_list);
443 
444 		urb->status = -EINPROGRESS;
445 
446 		usbd_transfer_start(uhe->bsd_xfer[0]);
447 		usbd_transfer_start(uhe->bsd_xfer[1]);
448 		err = 0;
449 	} else {
450 		/* no pipes have been setup yet! */
451 		urb->status = -EINVAL;
452 		err = -EINVAL;
453 	}
454 done:
455 	if (do_unlock)
456 		mtx_unlock(&Giant);
457 	return (err);
458 }
459 
460 /*------------------------------------------------------------------------*
461  *	usb_unlink_urb
462  *
463  * This function is used to stop an URB after that it is been
464  * submitted, but before the "complete" callback has been called. On
465  *------------------------------------------------------------------------*/
466 int
467 usb_unlink_urb(struct urb *urb)
468 {
469 	return (usb_unlink_urb_sub(urb, 0));
470 }
471 
472 static void
473 usb_unlink_bsd(struct usb_xfer *xfer,
474     struct urb *urb, uint8_t drain)
475 {
476 	if (xfer == NULL)
477 		return;
478 	if (!usbd_transfer_pending(xfer))
479 		return;
480 	if (xfer->priv_fifo == (void *)urb) {
481 		if (drain) {
482 			mtx_unlock(&Giant);
483 			usbd_transfer_drain(xfer);
484 			mtx_lock(&Giant);
485 		} else {
486 			usbd_transfer_stop(xfer);
487 		}
488 		usbd_transfer_start(xfer);
489 	}
490 }
491 
492 static int
493 usb_unlink_urb_sub(struct urb *urb, uint8_t drain)
494 {
495 	struct usb_host_endpoint *uhe;
496 	uint16_t x;
497 	uint8_t do_unlock;
498 	int err;
499 
500 	if (urb == NULL)
501 		return (-EINVAL);
502 
503 	do_unlock = mtx_owned(&Giant) ? 0 : 1;
504 	if (do_unlock)
505 		mtx_lock(&Giant);
506 	if (drain)
507 		urb->kill_count++;
508 
509 	if (urb->endpoint == NULL) {
510 		err = -EINVAL;
511 		goto done;
512 	}
513 	uhe = urb->endpoint;
514 
515 	if (urb->bsd_urb_list.tqe_prev) {
516 
517 		/* not started yet, just remove it from the queue */
518 		TAILQ_REMOVE(&uhe->bsd_urb_list, urb, bsd_urb_list);
519 		urb->bsd_urb_list.tqe_prev = NULL;
520 		urb->status = -ECONNRESET;
521 		urb->actual_length = 0;
522 
523 		for (x = 0; x < urb->number_of_packets; x++) {
524 			urb->iso_frame_desc[x].actual_length = 0;
525 		}
526 
527 		if (urb->complete) {
528 			(urb->complete) (urb);
529 		}
530 	} else {
531 
532 		/*
533 		 * If the URB is not on the URB list, then check if one of
534 		 * the FreeBSD USB transfer are processing the current URB.
535 		 * If so, re-start that transfer, which will lead to the
536 		 * termination of that URB:
537 		 */
538 		usb_unlink_bsd(uhe->bsd_xfer[0], urb, drain);
539 		usb_unlink_bsd(uhe->bsd_xfer[1], urb, drain);
540 	}
541 	err = 0;
542 done:
543 	if (drain)
544 		urb->kill_count--;
545 	if (do_unlock)
546 		mtx_unlock(&Giant);
547 	return (err);
548 }
549 
550 /*------------------------------------------------------------------------*
551  *	usb_clear_halt
552  *
553  * This function must always be used to clear the stall. Stall is when
554  * an USB endpoint returns a stall message to the USB host controller.
555  * Until the stall is cleared, no data can be transferred.
556  *------------------------------------------------------------------------*/
557 int
558 usb_clear_halt(struct usb_device *dev, struct usb_host_endpoint *uhe)
559 {
560 	struct usb_config cfg[1];
561 	struct usb_endpoint *ep;
562 	uint8_t type;
563 	uint8_t addr;
564 
565 	if (uhe == NULL)
566 		return (-EINVAL);
567 
568 	type = uhe->desc.bmAttributes & UE_XFERTYPE;
569 	addr = uhe->desc.bEndpointAddress;
570 
571 	memset(cfg, 0, sizeof(cfg));
572 
573 	cfg[0].type = type;
574 	cfg[0].endpoint = addr & UE_ADDR;
575 	cfg[0].direction = addr & (UE_DIR_OUT | UE_DIR_IN);
576 
577 	ep = usbd_get_endpoint(dev, uhe->bsd_iface_index, cfg);
578 	if (ep == NULL)
579 		return (-EINVAL);
580 
581 	usbd_clear_data_toggle(dev, ep);
582 
583 	return (usb_control_msg(dev, &dev->ep0,
584 	    UR_CLEAR_FEATURE, UT_WRITE_ENDPOINT,
585 	    UF_ENDPOINT_HALT, addr, NULL, 0, 1000));
586 }
587 
588 /*------------------------------------------------------------------------*
589  *	usb_start_wait_urb
590  *
591  * This is an internal function that is used to perform synchronous
592  * Linux USB transfers.
593  *------------------------------------------------------------------------*/
594 static int
595 usb_start_wait_urb(struct urb *urb, usb_timeout_t timeout, uint16_t *p_actlen)
596 {
597 	int err;
598 	uint8_t do_unlock;
599 
600 	/* you must have a timeout! */
601 	if (timeout == 0) {
602 		timeout = 1;
603 	}
604 	urb->complete = &usb_linux_wait_complete;
605 	urb->timeout = timeout;
606 	urb->transfer_flags |= URB_WAIT_WAKEUP;
607 	urb->transfer_flags &= ~URB_IS_SLEEPING;
608 
609 	do_unlock = mtx_owned(&Giant) ? 0 : 1;
610 	if (do_unlock)
611 		mtx_lock(&Giant);
612 	err = usb_submit_urb(urb, 0);
613 	if (err)
614 		goto done;
615 
616 	/*
617 	 * the URB might have completed before we get here, so check that by
618 	 * using some flags!
619 	 */
620 	while (urb->transfer_flags & URB_WAIT_WAKEUP) {
621 		urb->transfer_flags |= URB_IS_SLEEPING;
622 		cv_wait(&urb->cv_wait, &Giant);
623 		urb->transfer_flags &= ~URB_IS_SLEEPING;
624 	}
625 
626 	err = urb->status;
627 
628 done:
629 	if (do_unlock)
630 		mtx_unlock(&Giant);
631 	if (p_actlen != NULL) {
632 		if (err)
633 			*p_actlen = 0;
634 		else
635 			*p_actlen = urb->actual_length;
636 	}
637 	return (err);
638 }
639 
640 /*------------------------------------------------------------------------*
641  *	usb_control_msg
642  *
643  * The following function performs a control transfer sequence one any
644  * control, bulk or interrupt endpoint, specified by "uhe". A control
645  * transfer means that you transfer an 8-byte header first followed by
646  * a data-phase as indicated by the 8-byte header. The "timeout" is
647  * given in milliseconds.
648  *
649  * Return values:
650  *   0: Success
651  * < 0: Failure
652  * > 0: Actual length
653  *------------------------------------------------------------------------*/
654 int
655 usb_control_msg(struct usb_device *dev, struct usb_host_endpoint *uhe,
656     uint8_t request, uint8_t requesttype,
657     uint16_t value, uint16_t index, void *data,
658     uint16_t size, usb_timeout_t timeout)
659 {
660 	struct usb_device_request req;
661 	struct urb *urb;
662 	int err;
663 	uint16_t actlen;
664 	uint8_t type;
665 	uint8_t addr;
666 
667 	req.bmRequestType = requesttype;
668 	req.bRequest = request;
669 	USETW(req.wValue, value);
670 	USETW(req.wIndex, index);
671 	USETW(req.wLength, size);
672 
673 	if (uhe == NULL) {
674 		return (-EINVAL);
675 	}
676 	type = (uhe->desc.bmAttributes & UE_XFERTYPE);
677 	addr = (uhe->desc.bEndpointAddress & UE_ADDR);
678 
679 	if (type != UE_CONTROL) {
680 		return (-EINVAL);
681 	}
682 	if (addr == 0) {
683 		/*
684 		 * The FreeBSD USB stack supports standard control
685 		 * transfers on control endpoint zero:
686 		 */
687 		err = usbd_do_request_flags(dev,
688 		    NULL, &req, data, USB_SHORT_XFER_OK,
689 		    &actlen, timeout);
690 		if (err) {
691 			err = -EPIPE;
692 		} else {
693 			err = actlen;
694 		}
695 		return (err);
696 	}
697 	if (dev->flags.usb_mode != USB_MODE_HOST) {
698 		/* not supported */
699 		return (-EINVAL);
700 	}
701 	err = usb_setup_endpoint(dev, uhe, 1 /* dummy */ );
702 
703 	/*
704 	 * NOTE: we need to allocate real memory here so that we don't
705 	 * transfer data to/from the stack!
706 	 *
707 	 * 0xFFFF is a FreeBSD specific magic value.
708 	 */
709 	urb = usb_alloc_urb(0xFFFF, size);
710 
711 	urb->dev = dev;
712 	urb->endpoint = uhe;
713 
714 	memcpy(urb->setup_packet, &req, sizeof(req));
715 
716 	if (size && (!(req.bmRequestType & UT_READ))) {
717 		/* move the data to a real buffer */
718 		memcpy(USB_ADD_BYTES(urb->setup_packet, sizeof(req)),
719 		    data, size);
720 	}
721 	err = usb_start_wait_urb(urb, timeout, &actlen);
722 
723 	if (req.bmRequestType & UT_READ) {
724 		if (actlen) {
725 			bcopy(USB_ADD_BYTES(urb->setup_packet,
726 			    sizeof(req)), data, actlen);
727 		}
728 	}
729 	usb_free_urb(urb);
730 
731 	if (err == 0) {
732 		err = actlen;
733 	}
734 	return (err);
735 }
736 
737 /*------------------------------------------------------------------------*
738  *	usb_set_interface
739  *
740  * The following function will select which alternate setting of an
741  * USB interface you plan to use. By default alternate setting with
742  * index zero is selected. Note that "iface_no" is not the interface
743  * index, but rather the value of "bInterfaceNumber".
744  *------------------------------------------------------------------------*/
745 int
746 usb_set_interface(struct usb_device *dev, uint8_t iface_no, uint8_t alt_index)
747 {
748 	struct usb_interface *p_ui = usb_ifnum_to_if(dev, iface_no);
749 	int err;
750 
751 	if (p_ui == NULL)
752 		return (-EINVAL);
753 	if (alt_index >= p_ui->num_altsetting)
754 		return (-EINVAL);
755 	usb_linux_cleanup_interface(dev, p_ui);
756 	err = -usbd_set_alt_interface_index(dev,
757 	    p_ui->bsd_iface_index, alt_index);
758 	if (err == 0) {
759 		p_ui->cur_altsetting = p_ui->altsetting + alt_index;
760 	}
761 	return (err);
762 }
763 
764 /*------------------------------------------------------------------------*
765  *	usb_setup_endpoint
766  *
767  * The following function is an extension to the Linux USB API that
768  * allows you to set a maximum buffer size for a given USB endpoint.
769  * The maximum buffer size is per URB. If you don't call this function
770  * to set a maximum buffer size, the endpoint will not be functional.
771  * Note that for isochronous endpoints the maximum buffer size must be
772  * a non-zero dummy, hence this function will base the maximum buffer
773  * size on "wMaxPacketSize".
774  *------------------------------------------------------------------------*/
775 int
776 usb_setup_endpoint(struct usb_device *dev,
777     struct usb_host_endpoint *uhe, usb_size_t bufsize)
778 {
779 	struct usb_config cfg[2];
780 	uint8_t type = uhe->desc.bmAttributes & UE_XFERTYPE;
781 	uint8_t addr = uhe->desc.bEndpointAddress;
782 
783 	if (uhe->fbsd_buf_size == bufsize) {
784 		/* optimize */
785 		return (0);
786 	}
787 	usbd_transfer_unsetup(uhe->bsd_xfer, 2);
788 
789 	uhe->fbsd_buf_size = bufsize;
790 
791 	if (bufsize == 0) {
792 		return (0);
793 	}
794 	memset(cfg, 0, sizeof(cfg));
795 
796 	if (type == UE_ISOCHRONOUS) {
797 
798 		/*
799 		 * Isochronous transfers are special in that they don't fit
800 		 * into the BULK/INTR/CONTROL transfer model.
801 		 */
802 
803 		cfg[0].type = type;
804 		cfg[0].endpoint = addr & UE_ADDR;
805 		cfg[0].direction = addr & (UE_DIR_OUT | UE_DIR_IN);
806 		cfg[0].callback = &usb_linux_isoc_callback;
807 		cfg[0].bufsize = 0;	/* use wMaxPacketSize */
808 		cfg[0].frames = usb_max_isoc_frames(dev);
809 		cfg[0].flags.proxy_buffer = 1;
810 #if 0
811 		/*
812 		 * The Linux USB API allows non back-to-back
813 		 * isochronous frames which we do not support. If the
814 		 * isochronous frames are not back-to-back we need to
815 		 * do a copy, and then we need a buffer for
816 		 * that. Enable this at your own risk.
817 		 */
818 		cfg[0].flags.ext_buffer = 1;
819 #endif
820 		cfg[0].flags.short_xfer_ok = 1;
821 
822 		bcopy(cfg, cfg + 1, sizeof(*cfg));
823 
824 		/* Allocate and setup two generic FreeBSD USB transfers */
825 
826 		if (usbd_transfer_setup(dev, &uhe->bsd_iface_index,
827 		    uhe->bsd_xfer, cfg, 2, uhe, &Giant)) {
828 			return (-EINVAL);
829 		}
830 	} else {
831 		if (bufsize > (1 << 22)) {
832 			/* limit buffer size */
833 			bufsize = (1 << 22);
834 		}
835 		/* Allocate and setup one generic FreeBSD USB transfer */
836 
837 		cfg[0].type = type;
838 		cfg[0].endpoint = addr & UE_ADDR;
839 		cfg[0].direction = addr & (UE_DIR_OUT | UE_DIR_IN);
840 		cfg[0].callback = &usb_linux_non_isoc_callback;
841 		cfg[0].bufsize = bufsize;
842 		cfg[0].flags.ext_buffer = 1;	/* enable zero-copy */
843 		cfg[0].flags.proxy_buffer = 1;
844 		cfg[0].flags.short_xfer_ok = 1;
845 
846 		if (usbd_transfer_setup(dev, &uhe->bsd_iface_index,
847 		    uhe->bsd_xfer, cfg, 1, uhe, &Giant)) {
848 			return (-EINVAL);
849 		}
850 	}
851 	return (0);
852 }
853 
854 /*------------------------------------------------------------------------*
855  *	usb_linux_create_usb_device
856  *
857  * The following function is used to build up a per USB device
858  * structure tree, that mimics the Linux one. The root structure
859  * is returned by this function.
860  *------------------------------------------------------------------------*/
861 static int
862 usb_linux_create_usb_device(struct usb_device *udev, device_t dev)
863 {
864 	struct usb_config_descriptor *cd = usbd_get_config_descriptor(udev);
865 	struct usb_descriptor *desc;
866 	struct usb_interface_descriptor *id;
867 	struct usb_endpoint_descriptor *ed;
868 	struct usb_interface *p_ui = NULL;
869 	struct usb_host_interface *p_uhi = NULL;
870 	struct usb_host_endpoint *p_uhe = NULL;
871 	usb_size_t size;
872 	uint16_t niface_total;
873 	uint16_t nedesc;
874 	uint16_t iface_no_curr;
875 	uint16_t iface_index;
876 	uint8_t pass;
877 	uint8_t iface_no;
878 
879 	/*
880 	 * We do two passes. One pass for computing necessary memory size
881 	 * and one pass to initialize all the allocated memory structures.
882 	 */
883 	for (pass = 0; pass < 2; pass++) {
884 
885 		iface_no_curr = 0xFFFF;
886 		niface_total = 0;
887 		iface_index = 0;
888 		nedesc = 0;
889 		desc = NULL;
890 
891 		/*
892 		 * Iterate over all the USB descriptors. Use the USB config
893 		 * descriptor pointer provided by the FreeBSD USB stack.
894 		 */
895 		while ((desc = usb_desc_foreach(cd, desc))) {
896 
897 			/*
898 			 * Build up a tree according to the descriptors we
899 			 * find:
900 			 */
901 			switch (desc->bDescriptorType) {
902 			case UDESC_DEVICE:
903 				break;
904 
905 			case UDESC_ENDPOINT:
906 				ed = (void *)desc;
907 				if ((ed->bLength < sizeof(*ed)) ||
908 				    (iface_index == 0))
909 					break;
910 				if (p_uhe) {
911 					bcopy(ed, &p_uhe->desc, sizeof(p_uhe->desc));
912 					p_uhe->bsd_iface_index = iface_index - 1;
913 					TAILQ_INIT(&p_uhe->bsd_urb_list);
914 					p_uhe++;
915 				}
916 				if (p_uhi) {
917 					(p_uhi - 1)->desc.bNumEndpoints++;
918 				}
919 				nedesc++;
920 				break;
921 
922 			case UDESC_INTERFACE:
923 				id = (void *)desc;
924 				if (id->bLength < sizeof(*id))
925 					break;
926 				if (p_uhi) {
927 					bcopy(id, &p_uhi->desc, sizeof(p_uhi->desc));
928 					p_uhi->desc.bNumEndpoints = 0;
929 					p_uhi->endpoint = p_uhe;
930 					p_uhi->string = "";
931 					p_uhi->bsd_iface_index = iface_index;
932 					p_uhi++;
933 				}
934 				iface_no = id->bInterfaceNumber;
935 				niface_total++;
936 				if (iface_no_curr != iface_no) {
937 					if (p_ui) {
938 						p_ui->altsetting = p_uhi - 1;
939 						p_ui->cur_altsetting = p_uhi - 1;
940 						p_ui->num_altsetting = 1;
941 						p_ui->bsd_iface_index = iface_index;
942 						p_ui->linux_udev = udev;
943 						p_ui++;
944 					}
945 					iface_no_curr = iface_no;
946 					iface_index++;
947 				} else {
948 					if (p_ui) {
949 						(p_ui - 1)->num_altsetting++;
950 					}
951 				}
952 				break;
953 
954 			default:
955 				break;
956 			}
957 		}
958 
959 		if (pass == 0) {
960 
961 			size = (sizeof(*p_uhe) * nedesc) +
962 			    (sizeof(*p_ui) * iface_index) +
963 			    (sizeof(*p_uhi) * niface_total);
964 
965 			p_uhe = malloc(size, M_USBDEV, M_WAITOK | M_ZERO);
966 			p_ui = (void *)(p_uhe + nedesc);
967 			p_uhi = (void *)(p_ui + iface_index);
968 
969 			udev->linux_iface_start = p_ui;
970 			udev->linux_iface_end = p_ui + iface_index;
971 			udev->linux_endpoint_start = p_uhe;
972 			udev->linux_endpoint_end = p_uhe + nedesc;
973 			udev->devnum = device_get_unit(dev);
974 			bcopy(&udev->ddesc, &udev->descriptor,
975 			    sizeof(udev->descriptor));
976 			bcopy(udev->ctrl_ep.edesc, &udev->ep0.desc,
977 			    sizeof(udev->ep0.desc));
978 		}
979 	}
980 	return (0);
981 }
982 
983 /*------------------------------------------------------------------------*
984  *	usb_alloc_urb
985  *
986  * This function should always be used when you allocate an URB for
987  * use with the USB Linux stack. In case of an isochronous transfer
988  * you must specifiy the maximum number of "iso_packets" which you
989  * plan to transfer per URB. This function is always blocking, and
990  * "mem_flags" are not regarded like on Linux.
991  *------------------------------------------------------------------------*/
992 struct urb *
993 usb_alloc_urb(uint16_t iso_packets, uint16_t mem_flags)
994 {
995 	struct urb *urb;
996 	usb_size_t size;
997 
998 	if (iso_packets == 0xFFFF) {
999 		/*
1000 		 * FreeBSD specific magic value to ask for control transfer
1001 		 * memory allocation:
1002 		 */
1003 		size = sizeof(*urb) + sizeof(struct usb_device_request) + mem_flags;
1004 	} else {
1005 		size = sizeof(*urb) + (iso_packets * sizeof(urb->iso_frame_desc[0]));
1006 	}
1007 
1008 	urb = malloc(size, M_USBDEV, M_WAITOK | M_ZERO);
1009 
1010 	cv_init(&urb->cv_wait, "URBWAIT");
1011 	if (iso_packets == 0xFFFF) {
1012 		urb->setup_packet = (void *)(urb + 1);
1013 		urb->transfer_buffer = (void *)(urb->setup_packet +
1014 		    sizeof(struct usb_device_request));
1015 	} else {
1016 		urb->number_of_packets = iso_packets;
1017 	}
1018 	return (urb);
1019 }
1020 
1021 /*------------------------------------------------------------------------*
1022  *	usb_find_host_endpoint
1023  *
1024  * The following function will return the Linux USB host endpoint
1025  * structure that matches the given endpoint type and endpoint
1026  * value. If no match is found, NULL is returned. This function is not
1027  * part of the Linux USB API and is only used internally.
1028  *------------------------------------------------------------------------*/
1029 struct usb_host_endpoint *
1030 usb_find_host_endpoint(struct usb_device *dev, uint8_t type, uint8_t ep)
1031 {
1032 	struct usb_host_endpoint *uhe;
1033 	struct usb_host_endpoint *uhe_end;
1034 	struct usb_host_interface *uhi;
1035 	struct usb_interface *ui;
1036 	uint8_t ea;
1037 	uint8_t at;
1038 	uint8_t mask;
1039 
1040 	if (dev == NULL) {
1041 		return (NULL);
1042 	}
1043 	if (type == UE_CONTROL) {
1044 		mask = UE_ADDR;
1045 	} else {
1046 		mask = (UE_DIR_IN | UE_DIR_OUT | UE_ADDR);
1047 	}
1048 
1049 	ep &= mask;
1050 
1051 	/*
1052 	 * Iterate over all the interfaces searching the selected alternate
1053 	 * setting only, and all belonging endpoints.
1054 	 */
1055 	for (ui = dev->linux_iface_start;
1056 	    ui != dev->linux_iface_end;
1057 	    ui++) {
1058 		uhi = ui->cur_altsetting;
1059 		if (uhi) {
1060 			uhe_end = uhi->endpoint + uhi->desc.bNumEndpoints;
1061 			for (uhe = uhi->endpoint;
1062 			    uhe != uhe_end;
1063 			    uhe++) {
1064 				ea = uhe->desc.bEndpointAddress;
1065 				at = uhe->desc.bmAttributes;
1066 
1067 				if (((ea & mask) == ep) &&
1068 				    ((at & UE_XFERTYPE) == type)) {
1069 					return (uhe);
1070 				}
1071 			}
1072 		}
1073 	}
1074 
1075 	if ((type == UE_CONTROL) && ((ep & UE_ADDR) == 0)) {
1076 		return (&dev->ep0);
1077 	}
1078 	return (NULL);
1079 }
1080 
1081 /*------------------------------------------------------------------------*
1082  *	usb_altnum_to_altsetting
1083  *
1084  * The following function returns a pointer to an alternate setting by
1085  * index given a "usb_interface" pointer. If the alternate setting by
1086  * index does not exist, NULL is returned. And alternate setting is a
1087  * variant of an interface, but usually with slightly different
1088  * characteristics.
1089  *------------------------------------------------------------------------*/
1090 struct usb_host_interface *
1091 usb_altnum_to_altsetting(const struct usb_interface *intf, uint8_t alt_index)
1092 {
1093 	if (alt_index >= intf->num_altsetting) {
1094 		return (NULL);
1095 	}
1096 	return (intf->altsetting + alt_index);
1097 }
1098 
1099 /*------------------------------------------------------------------------*
1100  *	usb_ifnum_to_if
1101  *
1102  * The following function searches up an USB interface by
1103  * "bInterfaceNumber". If no match is found, NULL is returned.
1104  *------------------------------------------------------------------------*/
1105 struct usb_interface *
1106 usb_ifnum_to_if(struct usb_device *dev, uint8_t iface_no)
1107 {
1108 	struct usb_interface *p_ui;
1109 
1110 	for (p_ui = dev->linux_iface_start;
1111 	    p_ui != dev->linux_iface_end;
1112 	    p_ui++) {
1113 		if ((p_ui->num_altsetting > 0) &&
1114 		    (p_ui->altsetting->desc.bInterfaceNumber == iface_no)) {
1115 			return (p_ui);
1116 		}
1117 	}
1118 	return (NULL);
1119 }
1120 
1121 /*------------------------------------------------------------------------*
1122  *	usb_buffer_alloc
1123  *------------------------------------------------------------------------*/
1124 void   *
1125 usb_buffer_alloc(struct usb_device *dev, usb_size_t size, uint16_t mem_flags, uint8_t *dma_addr)
1126 {
1127 	return (malloc(size, M_USBDEV, M_WAITOK | M_ZERO));
1128 }
1129 
1130 /*------------------------------------------------------------------------*
1131  *	usbd_get_intfdata
1132  *------------------------------------------------------------------------*/
1133 void   *
1134 usbd_get_intfdata(struct usb_interface *intf)
1135 {
1136 	return (intf->bsd_priv_sc);
1137 }
1138 
1139 /*------------------------------------------------------------------------*
1140  *	usb_linux_register
1141  *
1142  * The following function is used by the "USB_DRIVER_EXPORT()" macro,
1143  * and is used to register a Linux USB driver, so that its
1144  * "usb_device_id" structures gets searched a probe time. This
1145  * function is not part of the Linux USB API, and is for internal use
1146  * only.
1147  *------------------------------------------------------------------------*/
1148 void
1149 usb_linux_register(void *arg)
1150 {
1151 	struct usb_driver *drv = arg;
1152 
1153 	mtx_lock(&Giant);
1154 	LIST_INSERT_HEAD(&usb_linux_driver_list, drv, linux_driver_list);
1155 	mtx_unlock(&Giant);
1156 
1157 	usb_needs_explore_all();
1158 }
1159 
1160 /*------------------------------------------------------------------------*
1161  *	usb_linux_deregister
1162  *
1163  * The following function is used by the "USB_DRIVER_EXPORT()" macro,
1164  * and is used to deregister a Linux USB driver. This function will
1165  * ensure that all driver instances belonging to the Linux USB device
1166  * driver in question, gets detached before the driver is
1167  * unloaded. This function is not part of the Linux USB API, and is
1168  * for internal use only.
1169  *------------------------------------------------------------------------*/
1170 void
1171 usb_linux_deregister(void *arg)
1172 {
1173 	struct usb_driver *drv = arg;
1174 	struct usb_linux_softc *sc;
1175 
1176 repeat:
1177 	mtx_lock(&Giant);
1178 	LIST_FOREACH(sc, &usb_linux_attached_list, sc_attached_list) {
1179 		if (sc->sc_udrv == drv) {
1180 			mtx_unlock(&Giant);
1181 			device_detach(sc->sc_fbsd_dev);
1182 			goto repeat;
1183 		}
1184 	}
1185 	LIST_REMOVE(drv, linux_driver_list);
1186 	mtx_unlock(&Giant);
1187 }
1188 
1189 /*------------------------------------------------------------------------*
1190  *	usb_linux_free_device
1191  *
1192  * The following function is only used by the FreeBSD USB stack, to
1193  * cleanup and free memory after that a Linux USB device was attached.
1194  *------------------------------------------------------------------------*/
1195 void
1196 usb_linux_free_device(struct usb_device *dev)
1197 {
1198 	struct usb_host_endpoint *uhe;
1199 	struct usb_host_endpoint *uhe_end;
1200 	int err;
1201 
1202 	uhe = dev->linux_endpoint_start;
1203 	uhe_end = dev->linux_endpoint_end;
1204 	while (uhe != uhe_end) {
1205 		err = usb_setup_endpoint(dev, uhe, 0);
1206 		uhe++;
1207 	}
1208 	err = usb_setup_endpoint(dev, &dev->ep0, 0);
1209 	free(dev->linux_endpoint_start, M_USBDEV);
1210 }
1211 
1212 /*------------------------------------------------------------------------*
1213  *	usb_buffer_free
1214  *------------------------------------------------------------------------*/
1215 void
1216 usb_buffer_free(struct usb_device *dev, usb_size_t size,
1217     void *addr, uint8_t dma_addr)
1218 {
1219 	free(addr, M_USBDEV);
1220 }
1221 
1222 /*------------------------------------------------------------------------*
1223  *	usb_free_urb
1224  *------------------------------------------------------------------------*/
1225 void
1226 usb_free_urb(struct urb *urb)
1227 {
1228 	if (urb == NULL) {
1229 		return;
1230 	}
1231 	/* make sure that the current URB is not active */
1232 	usb_kill_urb(urb);
1233 
1234 	/* destroy condition variable */
1235 	cv_destroy(&urb->cv_wait);
1236 
1237 	/* just free it */
1238 	free(urb, M_USBDEV);
1239 }
1240 
1241 /*------------------------------------------------------------------------*
1242  *	usb_init_urb
1243  *
1244  * The following function can be used to initialize a custom URB. It
1245  * is not recommended to use this function. Use "usb_alloc_urb()"
1246  * instead.
1247  *------------------------------------------------------------------------*/
1248 void
1249 usb_init_urb(struct urb *urb)
1250 {
1251 	if (urb == NULL) {
1252 		return;
1253 	}
1254 	memset(urb, 0, sizeof(*urb));
1255 }
1256 
1257 /*------------------------------------------------------------------------*
1258  *	usb_kill_urb
1259  *------------------------------------------------------------------------*/
1260 void
1261 usb_kill_urb(struct urb *urb)
1262 {
1263 	usb_unlink_urb_sub(urb, 1);
1264 }
1265 
1266 /*------------------------------------------------------------------------*
1267  *	usb_set_intfdata
1268  *
1269  * The following function sets the per Linux USB interface private
1270  * data pointer. It is used by most Linux USB device drivers.
1271  *------------------------------------------------------------------------*/
1272 void
1273 usb_set_intfdata(struct usb_interface *intf, void *data)
1274 {
1275 	intf->bsd_priv_sc = data;
1276 }
1277 
1278 /*------------------------------------------------------------------------*
1279  *	usb_linux_cleanup_interface
1280  *
1281  * The following function will release all FreeBSD USB transfers
1282  * associated with a Linux USB interface. It is for internal use only.
1283  *------------------------------------------------------------------------*/
1284 static void
1285 usb_linux_cleanup_interface(struct usb_device *dev, struct usb_interface *iface)
1286 {
1287 	struct usb_host_interface *uhi;
1288 	struct usb_host_interface *uhi_end;
1289 	struct usb_host_endpoint *uhe;
1290 	struct usb_host_endpoint *uhe_end;
1291 	int err;
1292 
1293 	uhi = iface->altsetting;
1294 	uhi_end = iface->altsetting + iface->num_altsetting;
1295 	while (uhi != uhi_end) {
1296 		uhe = uhi->endpoint;
1297 		uhe_end = uhi->endpoint + uhi->desc.bNumEndpoints;
1298 		while (uhe != uhe_end) {
1299 			err = usb_setup_endpoint(dev, uhe, 0);
1300 			uhe++;
1301 		}
1302 		uhi++;
1303 	}
1304 }
1305 
1306 /*------------------------------------------------------------------------*
1307  *	usb_linux_wait_complete
1308  *
1309  * The following function is used by "usb_start_wait_urb()" to wake it
1310  * up, when an USB transfer has finished.
1311  *------------------------------------------------------------------------*/
1312 static void
1313 usb_linux_wait_complete(struct urb *urb)
1314 {
1315 	if (urb->transfer_flags & URB_IS_SLEEPING) {
1316 		cv_signal(&urb->cv_wait);
1317 	}
1318 	urb->transfer_flags &= ~URB_WAIT_WAKEUP;
1319 }
1320 
1321 /*------------------------------------------------------------------------*
1322  *	usb_linux_complete
1323  *------------------------------------------------------------------------*/
1324 static void
1325 usb_linux_complete(struct usb_xfer *xfer)
1326 {
1327 	struct urb *urb;
1328 
1329 	urb = usbd_xfer_get_priv(xfer);
1330 	usbd_xfer_set_priv(xfer, NULL);
1331 	if (urb->complete) {
1332 		(urb->complete) (urb);
1333 	}
1334 }
1335 
1336 /*------------------------------------------------------------------------*
1337  *	usb_linux_isoc_callback
1338  *
1339  * The following is the FreeBSD isochronous USB callback. Isochronous
1340  * frames are USB packets transferred 1000 or 8000 times per second,
1341  * depending on whether a full- or high- speed USB transfer is
1342  * used.
1343  *------------------------------------------------------------------------*/
1344 static void
1345 usb_linux_isoc_callback(struct usb_xfer *xfer, usb_error_t error)
1346 {
1347 	usb_frlength_t max_frame = xfer->max_frame_size;
1348 	usb_frlength_t offset;
1349 	usb_frcount_t x;
1350 	struct urb *urb = usbd_xfer_get_priv(xfer);
1351 	struct usb_host_endpoint *uhe = usbd_xfer_softc(xfer);
1352 	struct usb_iso_packet_descriptor *uipd;
1353 
1354 	DPRINTF("\n");
1355 
1356 	switch (USB_GET_STATE(xfer)) {
1357 	case USB_ST_TRANSFERRED:
1358 
1359 		if (urb->bsd_isread) {
1360 
1361 			/* copy in data with regard to the URB */
1362 
1363 			offset = 0;
1364 
1365 			for (x = 0; x < urb->number_of_packets; x++) {
1366 				uipd = urb->iso_frame_desc + x;
1367 				if (uipd->length > xfer->frlengths[x]) {
1368 					if (urb->transfer_flags & URB_SHORT_NOT_OK) {
1369 						/* XXX should be EREMOTEIO */
1370 						uipd->status = -EPIPE;
1371 					} else {
1372 						uipd->status = 0;
1373 					}
1374 				} else {
1375 					uipd->status = 0;
1376 				}
1377 				uipd->actual_length = xfer->frlengths[x];
1378 				if (!xfer->flags.ext_buffer) {
1379 					usbd_copy_out(xfer->frbuffers, offset,
1380 					    USB_ADD_BYTES(urb->transfer_buffer,
1381 					    uipd->offset), uipd->actual_length);
1382 				}
1383 				offset += max_frame;
1384 			}
1385 		} else {
1386 			for (x = 0; x < urb->number_of_packets; x++) {
1387 				uipd = urb->iso_frame_desc + x;
1388 				uipd->actual_length = xfer->frlengths[x];
1389 				uipd->status = 0;
1390 			}
1391 		}
1392 
1393 		urb->actual_length = xfer->actlen;
1394 
1395 		/* check for short transfer */
1396 		if (xfer->actlen < xfer->sumlen) {
1397 			/* short transfer */
1398 			if (urb->transfer_flags & URB_SHORT_NOT_OK) {
1399 				/* XXX should be EREMOTEIO */
1400 				urb->status = -EPIPE;
1401 			} else {
1402 				urb->status = 0;
1403 			}
1404 		} else {
1405 			/* success */
1406 			urb->status = 0;
1407 		}
1408 
1409 		/* call callback */
1410 		usb_linux_complete(xfer);
1411 
1412 	case USB_ST_SETUP:
1413 tr_setup:
1414 
1415 		if (xfer->priv_fifo == NULL) {
1416 
1417 			/* get next transfer */
1418 			urb = TAILQ_FIRST(&uhe->bsd_urb_list);
1419 			if (urb == NULL) {
1420 				/* nothing to do */
1421 				return;
1422 			}
1423 			TAILQ_REMOVE(&uhe->bsd_urb_list, urb, bsd_urb_list);
1424 			urb->bsd_urb_list.tqe_prev = NULL;
1425 
1426 			x = xfer->max_frame_count;
1427 			if (urb->number_of_packets > x) {
1428 				/* XXX simply truncate the transfer */
1429 				urb->number_of_packets = x;
1430 			}
1431 		} else {
1432 			DPRINTF("Already got a transfer\n");
1433 
1434 			/* already got a transfer (should not happen) */
1435 			urb = usbd_xfer_get_priv(xfer);
1436 		}
1437 
1438 		urb->bsd_isread = (uhe->desc.bEndpointAddress & UE_DIR_IN) ? 1 : 0;
1439 
1440 		if (xfer->flags.ext_buffer) {
1441 			/* set virtual address to load */
1442 			usbd_xfer_set_frame_data(xfer, 0, urb->transfer_buffer, 0);
1443 		}
1444 		if (!(urb->bsd_isread)) {
1445 
1446 			/* copy out data with regard to the URB */
1447 
1448 			offset = 0;
1449 
1450 			for (x = 0; x < urb->number_of_packets; x++) {
1451 				uipd = urb->iso_frame_desc + x;
1452 				usbd_xfer_set_frame_len(xfer, x, uipd->length);
1453 				if (!xfer->flags.ext_buffer) {
1454 					usbd_copy_in(xfer->frbuffers, offset,
1455 					    USB_ADD_BYTES(urb->transfer_buffer,
1456 					    uipd->offset), uipd->length);
1457 				}
1458 				offset += uipd->length;
1459 			}
1460 		} else {
1461 
1462 			/*
1463 			 * compute the transfer length into the "offset"
1464 			 * variable
1465 			 */
1466 
1467 			offset = urb->number_of_packets * max_frame;
1468 
1469 			/* setup "frlengths" array */
1470 
1471 			for (x = 0; x < urb->number_of_packets; x++) {
1472 				uipd = urb->iso_frame_desc + x;
1473 				usbd_xfer_set_frame_len(xfer, x, max_frame);
1474 			}
1475 		}
1476 		usbd_xfer_set_priv(xfer, urb);
1477 		xfer->flags.force_short_xfer = 0;
1478 		xfer->timeout = urb->timeout;
1479 		xfer->nframes = urb->number_of_packets;
1480 		usbd_transfer_submit(xfer);
1481 		return;
1482 
1483 	default:			/* Error */
1484 		if (xfer->error == USB_ERR_CANCELLED) {
1485 			urb->status = -ECONNRESET;
1486 		} else {
1487 			urb->status = -EPIPE;	/* stalled */
1488 		}
1489 
1490 		/* Set zero for "actual_length" */
1491 		urb->actual_length = 0;
1492 
1493 		/* Set zero for "actual_length" */
1494 		for (x = 0; x < urb->number_of_packets; x++) {
1495 			urb->iso_frame_desc[x].actual_length = 0;
1496 			urb->iso_frame_desc[x].status = urb->status;
1497 		}
1498 
1499 		/* call callback */
1500 		usb_linux_complete(xfer);
1501 
1502 		if (xfer->error == USB_ERR_CANCELLED) {
1503 			/* we need to return in this case */
1504 			return;
1505 		}
1506 		goto tr_setup;
1507 
1508 	}
1509 }
1510 
1511 /*------------------------------------------------------------------------*
1512  *	usb_linux_non_isoc_callback
1513  *
1514  * The following is the FreeBSD BULK/INTERRUPT and CONTROL USB
1515  * callback. It dequeues Linux USB stack compatible URB's, transforms
1516  * the URB fields into a FreeBSD USB transfer, and defragments the USB
1517  * transfer as required. When the transfer is complete the "complete"
1518  * callback is called.
1519  *------------------------------------------------------------------------*/
1520 static void
1521 usb_linux_non_isoc_callback(struct usb_xfer *xfer, usb_error_t error)
1522 {
1523 	enum {
1524 		REQ_SIZE = sizeof(struct usb_device_request)
1525 	};
1526 	struct urb *urb = usbd_xfer_get_priv(xfer);
1527 	struct usb_host_endpoint *uhe = usbd_xfer_softc(xfer);
1528 	uint8_t *ptr;
1529 	usb_frlength_t max_bulk = usbd_xfer_max_len(xfer);
1530 	uint8_t data_frame = xfer->flags_int.control_xfr ? 1 : 0;
1531 
1532 	DPRINTF("\n");
1533 
1534 	switch (USB_GET_STATE(xfer)) {
1535 	case USB_ST_TRANSFERRED:
1536 
1537 		if (xfer->flags_int.control_xfr) {
1538 
1539 			/* don't transfer the setup packet again: */
1540 
1541 			usbd_xfer_set_frame_len(xfer, 0, 0);
1542 		}
1543 		if (urb->bsd_isread && (!xfer->flags.ext_buffer)) {
1544 			/* copy in data with regard to the URB */
1545 			usbd_copy_out(xfer->frbuffers + data_frame, 0,
1546 			    urb->bsd_data_ptr, xfer->frlengths[data_frame]);
1547 		}
1548 		urb->bsd_length_rem -= xfer->frlengths[data_frame];
1549 		urb->bsd_data_ptr += xfer->frlengths[data_frame];
1550 		urb->actual_length += xfer->frlengths[data_frame];
1551 
1552 		/* check for short transfer */
1553 		if (xfer->actlen < xfer->sumlen) {
1554 			urb->bsd_length_rem = 0;
1555 
1556 			/* short transfer */
1557 			if (urb->transfer_flags & URB_SHORT_NOT_OK) {
1558 				urb->status = -EPIPE;
1559 			} else {
1560 				urb->status = 0;
1561 			}
1562 		} else {
1563 			/* check remainder */
1564 			if (urb->bsd_length_rem > 0) {
1565 				goto setup_bulk;
1566 			}
1567 			/* success */
1568 			urb->status = 0;
1569 		}
1570 
1571 		/* call callback */
1572 		usb_linux_complete(xfer);
1573 
1574 	case USB_ST_SETUP:
1575 tr_setup:
1576 		/* get next transfer */
1577 		urb = TAILQ_FIRST(&uhe->bsd_urb_list);
1578 		if (urb == NULL) {
1579 			/* nothing to do */
1580 			return;
1581 		}
1582 		TAILQ_REMOVE(&uhe->bsd_urb_list, urb, bsd_urb_list);
1583 		urb->bsd_urb_list.tqe_prev = NULL;
1584 
1585 		usbd_xfer_set_priv(xfer, urb);
1586 		xfer->flags.force_short_xfer = 0;
1587 		xfer->timeout = urb->timeout;
1588 
1589 		if (xfer->flags_int.control_xfr) {
1590 
1591 			/*
1592 			 * USB control transfers need special handling.
1593 			 * First copy in the header, then copy in data!
1594 			 */
1595 			if (!xfer->flags.ext_buffer) {
1596 				usbd_copy_in(xfer->frbuffers, 0,
1597 				    urb->setup_packet, REQ_SIZE);
1598 				usbd_xfer_set_frame_len(xfer, 0, REQ_SIZE);
1599 			} else {
1600 				/* set virtual address to load */
1601 				usbd_xfer_set_frame_data(xfer, 0,
1602 				    urb->setup_packet, REQ_SIZE);
1603 			}
1604 
1605 			ptr = urb->setup_packet;
1606 
1607 			/* setup data transfer direction and length */
1608 			urb->bsd_isread = (ptr[0] & UT_READ) ? 1 : 0;
1609 			urb->bsd_length_rem = ptr[6] | (ptr[7] << 8);
1610 
1611 		} else {
1612 
1613 			/* setup data transfer direction */
1614 
1615 			urb->bsd_length_rem = urb->transfer_buffer_length;
1616 			urb->bsd_isread = (uhe->desc.bEndpointAddress &
1617 			    UE_DIR_IN) ? 1 : 0;
1618 		}
1619 
1620 		urb->bsd_data_ptr = urb->transfer_buffer;
1621 		urb->actual_length = 0;
1622 
1623 setup_bulk:
1624 		if (max_bulk > urb->bsd_length_rem) {
1625 			max_bulk = urb->bsd_length_rem;
1626 		}
1627 		/* check if we need to force a short transfer */
1628 
1629 		if ((max_bulk == urb->bsd_length_rem) &&
1630 		    (urb->transfer_flags & URB_ZERO_PACKET) &&
1631 		    (!xfer->flags_int.control_xfr)) {
1632 			xfer->flags.force_short_xfer = 1;
1633 		}
1634 		/* check if we need to copy in data */
1635 
1636 		if (xfer->flags.ext_buffer) {
1637 			/* set virtual address to load */
1638 			usbd_xfer_set_frame_data(xfer, data_frame,
1639 			    urb->bsd_data_ptr, max_bulk);
1640 		} else if (!urb->bsd_isread) {
1641 			/* copy out data with regard to the URB */
1642 			usbd_copy_in(xfer->frbuffers + data_frame, 0,
1643 			    urb->bsd_data_ptr, max_bulk);
1644 			usbd_xfer_set_frame_len(xfer, data_frame, max_bulk);
1645 		}
1646 		if (xfer->flags_int.control_xfr) {
1647 			if (max_bulk > 0) {
1648 				xfer->nframes = 2;
1649 			} else {
1650 				xfer->nframes = 1;
1651 			}
1652 		} else {
1653 			xfer->nframes = 1;
1654 		}
1655 		usbd_transfer_submit(xfer);
1656 		return;
1657 
1658 	default:
1659 		if (xfer->error == USB_ERR_CANCELLED) {
1660 			urb->status = -ECONNRESET;
1661 		} else {
1662 			urb->status = -EPIPE;
1663 		}
1664 
1665 		/* Set zero for "actual_length" */
1666 		urb->actual_length = 0;
1667 
1668 		/* call callback */
1669 		usb_linux_complete(xfer);
1670 
1671 		if (xfer->error == USB_ERR_CANCELLED) {
1672 			/* we need to return in this case */
1673 			return;
1674 		}
1675 		goto tr_setup;
1676 	}
1677 }
1678 
1679 /*------------------------------------------------------------------------*
1680  *	usb_fill_bulk_urb
1681  *------------------------------------------------------------------------*/
1682 void
1683 usb_fill_bulk_urb(struct urb *urb, struct usb_device *udev,
1684     struct usb_host_endpoint *uhe, void *buf,
1685     int length, usb_complete_t callback, void *arg)
1686 {
1687 	urb->dev = udev;
1688 	urb->endpoint = uhe;
1689 	urb->transfer_buffer = buf;
1690 	urb->transfer_buffer_length = length;
1691 	urb->complete = callback;
1692 	urb->context = arg;
1693 }
1694 
1695 /*------------------------------------------------------------------------*
1696  *	usb_bulk_msg
1697  *
1698  * NOTE: This function can also be used for interrupt endpoints!
1699  *
1700  * Return values:
1701  *    0: Success
1702  * Else: Failure
1703  *------------------------------------------------------------------------*/
1704 int
1705 usb_bulk_msg(struct usb_device *udev, struct usb_host_endpoint *uhe,
1706     void *data, int len, uint16_t *pactlen, usb_timeout_t timeout)
1707 {
1708 	struct urb *urb;
1709 	int err;
1710 
1711 	if (uhe == NULL)
1712 		return (-EINVAL);
1713 	if (len < 0)
1714 		return (-EINVAL);
1715 
1716 	err = usb_setup_endpoint(udev, uhe, 4096 /* bytes */);
1717 	if (err)
1718 		return (err);
1719 
1720 	urb = usb_alloc_urb(0, 0);
1721 
1722 	usb_fill_bulk_urb(urb, udev, uhe, data, len,
1723 	    usb_linux_wait_complete, NULL);
1724 
1725 	err = usb_start_wait_urb(urb, timeout, pactlen);
1726 
1727 	usb_free_urb(urb);
1728 
1729 	return (err);
1730 }
1731 MODULE_DEPEND(linuxkpi, usb, 1, 1, 1);
1732 
1733 static void
1734 usb_linux_init(void *arg)
1735 {
1736 	/* register our function */
1737 	usb_linux_free_device_p = &usb_linux_free_device;
1738 }
1739 SYSINIT(usb_linux_init, SI_SUB_LOCK, SI_ORDER_FIRST, usb_linux_init, NULL);
1740 SYSUNINIT(usb_linux_unload, SI_SUB_LOCK, SI_ORDER_ANY, usb_linux_unload, NULL);
1741