1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * Copyright (C) 2012 Intel Corporation. All rights reserved.
4*4882a593Smuzhiyun */
5*4882a593Smuzhiyun
6*4882a593Smuzhiyun #define pr_fmt(fmt) "hci: %s: " fmt, __func__
7*4882a593Smuzhiyun
8*4882a593Smuzhiyun #include <linux/init.h>
9*4882a593Smuzhiyun #include <linux/kernel.h>
10*4882a593Smuzhiyun #include <linux/module.h>
11*4882a593Smuzhiyun
12*4882a593Smuzhiyun #include <net/nfc/hci.h>
13*4882a593Smuzhiyun
14*4882a593Smuzhiyun #include "hci.h"
15*4882a593Smuzhiyun
16*4882a593Smuzhiyun /*
17*4882a593Smuzhiyun * Payload is the HCP message data only. Instruction will be prepended.
18*4882a593Smuzhiyun * Guarantees that cb will be called upon completion or timeout delay
19*4882a593Smuzhiyun * counted from the moment the cmd is sent to the transport.
20*4882a593Smuzhiyun */
nfc_hci_hcp_message_tx(struct nfc_hci_dev * hdev,u8 pipe,u8 type,u8 instruction,const u8 * payload,size_t payload_len,data_exchange_cb_t cb,void * cb_context,unsigned long completion_delay)21*4882a593Smuzhiyun int nfc_hci_hcp_message_tx(struct nfc_hci_dev *hdev, u8 pipe,
22*4882a593Smuzhiyun u8 type, u8 instruction,
23*4882a593Smuzhiyun const u8 *payload, size_t payload_len,
24*4882a593Smuzhiyun data_exchange_cb_t cb, void *cb_context,
25*4882a593Smuzhiyun unsigned long completion_delay)
26*4882a593Smuzhiyun {
27*4882a593Smuzhiyun struct nfc_dev *ndev = hdev->ndev;
28*4882a593Smuzhiyun struct hci_msg *cmd;
29*4882a593Smuzhiyun const u8 *ptr = payload;
30*4882a593Smuzhiyun int hci_len, err;
31*4882a593Smuzhiyun bool firstfrag = true;
32*4882a593Smuzhiyun
33*4882a593Smuzhiyun cmd = kzalloc(sizeof(struct hci_msg), GFP_KERNEL);
34*4882a593Smuzhiyun if (cmd == NULL)
35*4882a593Smuzhiyun return -ENOMEM;
36*4882a593Smuzhiyun
37*4882a593Smuzhiyun INIT_LIST_HEAD(&cmd->msg_l);
38*4882a593Smuzhiyun skb_queue_head_init(&cmd->msg_frags);
39*4882a593Smuzhiyun cmd->wait_response = (type == NFC_HCI_HCP_COMMAND) ? true : false;
40*4882a593Smuzhiyun cmd->cb = cb;
41*4882a593Smuzhiyun cmd->cb_context = cb_context;
42*4882a593Smuzhiyun cmd->completion_delay = completion_delay;
43*4882a593Smuzhiyun
44*4882a593Smuzhiyun hci_len = payload_len + 1;
45*4882a593Smuzhiyun while (hci_len > 0) {
46*4882a593Smuzhiyun struct sk_buff *skb;
47*4882a593Smuzhiyun int skb_len, data_link_len;
48*4882a593Smuzhiyun struct hcp_packet *packet;
49*4882a593Smuzhiyun
50*4882a593Smuzhiyun if (NFC_HCI_HCP_PACKET_HEADER_LEN + hci_len <=
51*4882a593Smuzhiyun hdev->max_data_link_payload)
52*4882a593Smuzhiyun data_link_len = hci_len;
53*4882a593Smuzhiyun else
54*4882a593Smuzhiyun data_link_len = hdev->max_data_link_payload -
55*4882a593Smuzhiyun NFC_HCI_HCP_PACKET_HEADER_LEN;
56*4882a593Smuzhiyun
57*4882a593Smuzhiyun skb_len = ndev->tx_headroom + NFC_HCI_HCP_PACKET_HEADER_LEN +
58*4882a593Smuzhiyun data_link_len + ndev->tx_tailroom;
59*4882a593Smuzhiyun hci_len -= data_link_len;
60*4882a593Smuzhiyun
61*4882a593Smuzhiyun skb = alloc_skb(skb_len, GFP_KERNEL);
62*4882a593Smuzhiyun if (skb == NULL) {
63*4882a593Smuzhiyun err = -ENOMEM;
64*4882a593Smuzhiyun goto out_skb_err;
65*4882a593Smuzhiyun }
66*4882a593Smuzhiyun skb_reserve(skb, ndev->tx_headroom);
67*4882a593Smuzhiyun
68*4882a593Smuzhiyun skb_put(skb, NFC_HCI_HCP_PACKET_HEADER_LEN + data_link_len);
69*4882a593Smuzhiyun
70*4882a593Smuzhiyun /* Only the last fragment will have the cb bit set to 1 */
71*4882a593Smuzhiyun packet = (struct hcp_packet *)skb->data;
72*4882a593Smuzhiyun packet->header = pipe;
73*4882a593Smuzhiyun if (firstfrag) {
74*4882a593Smuzhiyun firstfrag = false;
75*4882a593Smuzhiyun packet->message.header = HCP_HEADER(type, instruction);
76*4882a593Smuzhiyun if (ptr) {
77*4882a593Smuzhiyun memcpy(packet->message.data, ptr,
78*4882a593Smuzhiyun data_link_len - 1);
79*4882a593Smuzhiyun ptr += data_link_len - 1;
80*4882a593Smuzhiyun }
81*4882a593Smuzhiyun } else {
82*4882a593Smuzhiyun memcpy(&packet->message, ptr, data_link_len);
83*4882a593Smuzhiyun ptr += data_link_len;
84*4882a593Smuzhiyun }
85*4882a593Smuzhiyun
86*4882a593Smuzhiyun /* This is the last fragment, set the cb bit */
87*4882a593Smuzhiyun if (hci_len == 0)
88*4882a593Smuzhiyun packet->header |= ~NFC_HCI_FRAGMENT;
89*4882a593Smuzhiyun
90*4882a593Smuzhiyun skb_queue_tail(&cmd->msg_frags, skb);
91*4882a593Smuzhiyun }
92*4882a593Smuzhiyun
93*4882a593Smuzhiyun mutex_lock(&hdev->msg_tx_mutex);
94*4882a593Smuzhiyun
95*4882a593Smuzhiyun if (hdev->shutting_down) {
96*4882a593Smuzhiyun err = -ESHUTDOWN;
97*4882a593Smuzhiyun mutex_unlock(&hdev->msg_tx_mutex);
98*4882a593Smuzhiyun goto out_skb_err;
99*4882a593Smuzhiyun }
100*4882a593Smuzhiyun
101*4882a593Smuzhiyun list_add_tail(&cmd->msg_l, &hdev->msg_tx_queue);
102*4882a593Smuzhiyun mutex_unlock(&hdev->msg_tx_mutex);
103*4882a593Smuzhiyun
104*4882a593Smuzhiyun schedule_work(&hdev->msg_tx_work);
105*4882a593Smuzhiyun
106*4882a593Smuzhiyun return 0;
107*4882a593Smuzhiyun
108*4882a593Smuzhiyun out_skb_err:
109*4882a593Smuzhiyun skb_queue_purge(&cmd->msg_frags);
110*4882a593Smuzhiyun kfree(cmd);
111*4882a593Smuzhiyun
112*4882a593Smuzhiyun return err;
113*4882a593Smuzhiyun }
114*4882a593Smuzhiyun
115*4882a593Smuzhiyun /*
116*4882a593Smuzhiyun * Receive hcp message for pipe, with type and cmd.
117*4882a593Smuzhiyun * skb contains optional message data only.
118*4882a593Smuzhiyun */
nfc_hci_hcp_message_rx(struct nfc_hci_dev * hdev,u8 pipe,u8 type,u8 instruction,struct sk_buff * skb)119*4882a593Smuzhiyun void nfc_hci_hcp_message_rx(struct nfc_hci_dev *hdev, u8 pipe, u8 type,
120*4882a593Smuzhiyun u8 instruction, struct sk_buff *skb)
121*4882a593Smuzhiyun {
122*4882a593Smuzhiyun switch (type) {
123*4882a593Smuzhiyun case NFC_HCI_HCP_RESPONSE:
124*4882a593Smuzhiyun nfc_hci_resp_received(hdev, instruction, skb);
125*4882a593Smuzhiyun break;
126*4882a593Smuzhiyun case NFC_HCI_HCP_COMMAND:
127*4882a593Smuzhiyun nfc_hci_cmd_received(hdev, pipe, instruction, skb);
128*4882a593Smuzhiyun break;
129*4882a593Smuzhiyun case NFC_HCI_HCP_EVENT:
130*4882a593Smuzhiyun nfc_hci_event_received(hdev, pipe, instruction, skb);
131*4882a593Smuzhiyun break;
132*4882a593Smuzhiyun default:
133*4882a593Smuzhiyun pr_err("UNKNOWN MSG Type %d, instruction=%d\n",
134*4882a593Smuzhiyun type, instruction);
135*4882a593Smuzhiyun kfree_skb(skb);
136*4882a593Smuzhiyun break;
137*4882a593Smuzhiyun }
138*4882a593Smuzhiyun }
139