1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-only
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * The NFC Controller Interface is the communication protocol between an
4*4882a593Smuzhiyun * NFC Controller (NFCC) and a Device Host (DH).
5*4882a593Smuzhiyun *
6*4882a593Smuzhiyun * Copyright (C) 2011 Texas Instruments, Inc.
7*4882a593Smuzhiyun * Copyright (C) 2014 Marvell International Ltd.
8*4882a593Smuzhiyun *
9*4882a593Smuzhiyun * Written by Ilan Elias <ilane@ti.com>
10*4882a593Smuzhiyun */
11*4882a593Smuzhiyun
12*4882a593Smuzhiyun #define pr_fmt(fmt) KBUILD_MODNAME ": %s: " fmt, __func__
13*4882a593Smuzhiyun
14*4882a593Smuzhiyun #include <linux/types.h>
15*4882a593Smuzhiyun #include <linux/interrupt.h>
16*4882a593Smuzhiyun #include <linux/wait.h>
17*4882a593Smuzhiyun #include <linux/bitops.h>
18*4882a593Smuzhiyun #include <linux/skbuff.h>
19*4882a593Smuzhiyun
20*4882a593Smuzhiyun #include "../nfc.h"
21*4882a593Smuzhiyun #include <net/nfc/nci.h>
22*4882a593Smuzhiyun #include <net/nfc/nci_core.h>
23*4882a593Smuzhiyun #include <linux/nfc.h>
24*4882a593Smuzhiyun
25*4882a593Smuzhiyun /* Complete data exchange transaction and forward skb to nfc core */
nci_data_exchange_complete(struct nci_dev * ndev,struct sk_buff * skb,__u8 conn_id,int err)26*4882a593Smuzhiyun void nci_data_exchange_complete(struct nci_dev *ndev, struct sk_buff *skb,
27*4882a593Smuzhiyun __u8 conn_id, int err)
28*4882a593Smuzhiyun {
29*4882a593Smuzhiyun struct nci_conn_info *conn_info;
30*4882a593Smuzhiyun data_exchange_cb_t cb;
31*4882a593Smuzhiyun void *cb_context;
32*4882a593Smuzhiyun
33*4882a593Smuzhiyun conn_info = nci_get_conn_info_by_conn_id(ndev, conn_id);
34*4882a593Smuzhiyun if (!conn_info) {
35*4882a593Smuzhiyun kfree_skb(skb);
36*4882a593Smuzhiyun goto exit;
37*4882a593Smuzhiyun }
38*4882a593Smuzhiyun
39*4882a593Smuzhiyun cb = conn_info->data_exchange_cb;
40*4882a593Smuzhiyun cb_context = conn_info->data_exchange_cb_context;
41*4882a593Smuzhiyun
42*4882a593Smuzhiyun pr_debug("len %d, err %d\n", skb ? skb->len : 0, err);
43*4882a593Smuzhiyun
44*4882a593Smuzhiyun /* data exchange is complete, stop the data timer */
45*4882a593Smuzhiyun del_timer_sync(&ndev->data_timer);
46*4882a593Smuzhiyun clear_bit(NCI_DATA_EXCHANGE_TO, &ndev->flags);
47*4882a593Smuzhiyun
48*4882a593Smuzhiyun if (cb) {
49*4882a593Smuzhiyun /* forward skb to nfc core */
50*4882a593Smuzhiyun cb(cb_context, skb, err);
51*4882a593Smuzhiyun } else if (skb) {
52*4882a593Smuzhiyun pr_err("no rx callback, dropping rx data...\n");
53*4882a593Smuzhiyun
54*4882a593Smuzhiyun /* no waiting callback, free skb */
55*4882a593Smuzhiyun kfree_skb(skb);
56*4882a593Smuzhiyun }
57*4882a593Smuzhiyun
58*4882a593Smuzhiyun exit:
59*4882a593Smuzhiyun clear_bit(NCI_DATA_EXCHANGE, &ndev->flags);
60*4882a593Smuzhiyun }
61*4882a593Smuzhiyun
62*4882a593Smuzhiyun /* ----------------- NCI TX Data ----------------- */
63*4882a593Smuzhiyun
nci_push_data_hdr(struct nci_dev * ndev,__u8 conn_id,struct sk_buff * skb,__u8 pbf)64*4882a593Smuzhiyun static inline void nci_push_data_hdr(struct nci_dev *ndev,
65*4882a593Smuzhiyun __u8 conn_id,
66*4882a593Smuzhiyun struct sk_buff *skb,
67*4882a593Smuzhiyun __u8 pbf)
68*4882a593Smuzhiyun {
69*4882a593Smuzhiyun struct nci_data_hdr *hdr;
70*4882a593Smuzhiyun int plen = skb->len;
71*4882a593Smuzhiyun
72*4882a593Smuzhiyun hdr = skb_push(skb, NCI_DATA_HDR_SIZE);
73*4882a593Smuzhiyun hdr->conn_id = conn_id;
74*4882a593Smuzhiyun hdr->rfu = 0;
75*4882a593Smuzhiyun hdr->plen = plen;
76*4882a593Smuzhiyun
77*4882a593Smuzhiyun nci_mt_set((__u8 *)hdr, NCI_MT_DATA_PKT);
78*4882a593Smuzhiyun nci_pbf_set((__u8 *)hdr, pbf);
79*4882a593Smuzhiyun }
80*4882a593Smuzhiyun
nci_conn_max_data_pkt_payload_size(struct nci_dev * ndev,__u8 conn_id)81*4882a593Smuzhiyun int nci_conn_max_data_pkt_payload_size(struct nci_dev *ndev, __u8 conn_id)
82*4882a593Smuzhiyun {
83*4882a593Smuzhiyun struct nci_conn_info *conn_info;
84*4882a593Smuzhiyun
85*4882a593Smuzhiyun conn_info = nci_get_conn_info_by_conn_id(ndev, conn_id);
86*4882a593Smuzhiyun if (!conn_info)
87*4882a593Smuzhiyun return -EPROTO;
88*4882a593Smuzhiyun
89*4882a593Smuzhiyun return conn_info->max_pkt_payload_len;
90*4882a593Smuzhiyun }
91*4882a593Smuzhiyun EXPORT_SYMBOL(nci_conn_max_data_pkt_payload_size);
92*4882a593Smuzhiyun
nci_queue_tx_data_frags(struct nci_dev * ndev,__u8 conn_id,struct sk_buff * skb)93*4882a593Smuzhiyun static int nci_queue_tx_data_frags(struct nci_dev *ndev,
94*4882a593Smuzhiyun __u8 conn_id,
95*4882a593Smuzhiyun struct sk_buff *skb) {
96*4882a593Smuzhiyun struct nci_conn_info *conn_info;
97*4882a593Smuzhiyun int total_len = skb->len;
98*4882a593Smuzhiyun unsigned char *data = skb->data;
99*4882a593Smuzhiyun unsigned long flags;
100*4882a593Smuzhiyun struct sk_buff_head frags_q;
101*4882a593Smuzhiyun struct sk_buff *skb_frag;
102*4882a593Smuzhiyun int frag_len;
103*4882a593Smuzhiyun int rc = 0;
104*4882a593Smuzhiyun
105*4882a593Smuzhiyun pr_debug("conn_id 0x%x, total_len %d\n", conn_id, total_len);
106*4882a593Smuzhiyun
107*4882a593Smuzhiyun conn_info = nci_get_conn_info_by_conn_id(ndev, conn_id);
108*4882a593Smuzhiyun if (!conn_info) {
109*4882a593Smuzhiyun rc = -EPROTO;
110*4882a593Smuzhiyun goto exit;
111*4882a593Smuzhiyun }
112*4882a593Smuzhiyun
113*4882a593Smuzhiyun __skb_queue_head_init(&frags_q);
114*4882a593Smuzhiyun
115*4882a593Smuzhiyun while (total_len) {
116*4882a593Smuzhiyun frag_len =
117*4882a593Smuzhiyun min_t(int, total_len, conn_info->max_pkt_payload_len);
118*4882a593Smuzhiyun
119*4882a593Smuzhiyun skb_frag = nci_skb_alloc(ndev,
120*4882a593Smuzhiyun (NCI_DATA_HDR_SIZE + frag_len),
121*4882a593Smuzhiyun GFP_ATOMIC);
122*4882a593Smuzhiyun if (skb_frag == NULL) {
123*4882a593Smuzhiyun rc = -ENOMEM;
124*4882a593Smuzhiyun goto free_exit;
125*4882a593Smuzhiyun }
126*4882a593Smuzhiyun skb_reserve(skb_frag, NCI_DATA_HDR_SIZE);
127*4882a593Smuzhiyun
128*4882a593Smuzhiyun /* first, copy the data */
129*4882a593Smuzhiyun skb_put_data(skb_frag, data, frag_len);
130*4882a593Smuzhiyun
131*4882a593Smuzhiyun /* second, set the header */
132*4882a593Smuzhiyun nci_push_data_hdr(ndev, conn_id, skb_frag,
133*4882a593Smuzhiyun ((total_len == frag_len) ?
134*4882a593Smuzhiyun (NCI_PBF_LAST) : (NCI_PBF_CONT)));
135*4882a593Smuzhiyun
136*4882a593Smuzhiyun __skb_queue_tail(&frags_q, skb_frag);
137*4882a593Smuzhiyun
138*4882a593Smuzhiyun data += frag_len;
139*4882a593Smuzhiyun total_len -= frag_len;
140*4882a593Smuzhiyun
141*4882a593Smuzhiyun pr_debug("frag_len %d, remaining total_len %d\n",
142*4882a593Smuzhiyun frag_len, total_len);
143*4882a593Smuzhiyun }
144*4882a593Smuzhiyun
145*4882a593Smuzhiyun /* queue all fragments atomically */
146*4882a593Smuzhiyun spin_lock_irqsave(&ndev->tx_q.lock, flags);
147*4882a593Smuzhiyun
148*4882a593Smuzhiyun while ((skb_frag = __skb_dequeue(&frags_q)) != NULL)
149*4882a593Smuzhiyun __skb_queue_tail(&ndev->tx_q, skb_frag);
150*4882a593Smuzhiyun
151*4882a593Smuzhiyun spin_unlock_irqrestore(&ndev->tx_q.lock, flags);
152*4882a593Smuzhiyun
153*4882a593Smuzhiyun /* free the original skb */
154*4882a593Smuzhiyun kfree_skb(skb);
155*4882a593Smuzhiyun
156*4882a593Smuzhiyun goto exit;
157*4882a593Smuzhiyun
158*4882a593Smuzhiyun free_exit:
159*4882a593Smuzhiyun while ((skb_frag = __skb_dequeue(&frags_q)) != NULL)
160*4882a593Smuzhiyun kfree_skb(skb_frag);
161*4882a593Smuzhiyun
162*4882a593Smuzhiyun exit:
163*4882a593Smuzhiyun return rc;
164*4882a593Smuzhiyun }
165*4882a593Smuzhiyun
166*4882a593Smuzhiyun /* Send NCI data */
nci_send_data(struct nci_dev * ndev,__u8 conn_id,struct sk_buff * skb)167*4882a593Smuzhiyun int nci_send_data(struct nci_dev *ndev, __u8 conn_id, struct sk_buff *skb)
168*4882a593Smuzhiyun {
169*4882a593Smuzhiyun struct nci_conn_info *conn_info;
170*4882a593Smuzhiyun int rc = 0;
171*4882a593Smuzhiyun
172*4882a593Smuzhiyun pr_debug("conn_id 0x%x, plen %d\n", conn_id, skb->len);
173*4882a593Smuzhiyun
174*4882a593Smuzhiyun conn_info = nci_get_conn_info_by_conn_id(ndev, conn_id);
175*4882a593Smuzhiyun if (!conn_info) {
176*4882a593Smuzhiyun rc = -EPROTO;
177*4882a593Smuzhiyun goto free_exit;
178*4882a593Smuzhiyun }
179*4882a593Smuzhiyun
180*4882a593Smuzhiyun /* check if the packet need to be fragmented */
181*4882a593Smuzhiyun if (skb->len <= conn_info->max_pkt_payload_len) {
182*4882a593Smuzhiyun /* no need to fragment packet */
183*4882a593Smuzhiyun nci_push_data_hdr(ndev, conn_id, skb, NCI_PBF_LAST);
184*4882a593Smuzhiyun
185*4882a593Smuzhiyun skb_queue_tail(&ndev->tx_q, skb);
186*4882a593Smuzhiyun } else {
187*4882a593Smuzhiyun /* fragment packet and queue the fragments */
188*4882a593Smuzhiyun rc = nci_queue_tx_data_frags(ndev, conn_id, skb);
189*4882a593Smuzhiyun if (rc) {
190*4882a593Smuzhiyun pr_err("failed to fragment tx data packet\n");
191*4882a593Smuzhiyun goto free_exit;
192*4882a593Smuzhiyun }
193*4882a593Smuzhiyun }
194*4882a593Smuzhiyun
195*4882a593Smuzhiyun ndev->cur_conn_id = conn_id;
196*4882a593Smuzhiyun queue_work(ndev->tx_wq, &ndev->tx_work);
197*4882a593Smuzhiyun
198*4882a593Smuzhiyun goto exit;
199*4882a593Smuzhiyun
200*4882a593Smuzhiyun free_exit:
201*4882a593Smuzhiyun kfree_skb(skb);
202*4882a593Smuzhiyun
203*4882a593Smuzhiyun exit:
204*4882a593Smuzhiyun return rc;
205*4882a593Smuzhiyun }
206*4882a593Smuzhiyun EXPORT_SYMBOL(nci_send_data);
207*4882a593Smuzhiyun
208*4882a593Smuzhiyun /* ----------------- NCI RX Data ----------------- */
209*4882a593Smuzhiyun
nci_add_rx_data_frag(struct nci_dev * ndev,struct sk_buff * skb,__u8 pbf,__u8 conn_id,__u8 status)210*4882a593Smuzhiyun static void nci_add_rx_data_frag(struct nci_dev *ndev,
211*4882a593Smuzhiyun struct sk_buff *skb,
212*4882a593Smuzhiyun __u8 pbf, __u8 conn_id, __u8 status)
213*4882a593Smuzhiyun {
214*4882a593Smuzhiyun int reassembly_len;
215*4882a593Smuzhiyun int err = 0;
216*4882a593Smuzhiyun
217*4882a593Smuzhiyun if (status) {
218*4882a593Smuzhiyun err = status;
219*4882a593Smuzhiyun goto exit;
220*4882a593Smuzhiyun }
221*4882a593Smuzhiyun
222*4882a593Smuzhiyun if (ndev->rx_data_reassembly) {
223*4882a593Smuzhiyun reassembly_len = ndev->rx_data_reassembly->len;
224*4882a593Smuzhiyun
225*4882a593Smuzhiyun /* first, make enough room for the already accumulated data */
226*4882a593Smuzhiyun if (skb_cow_head(skb, reassembly_len)) {
227*4882a593Smuzhiyun pr_err("error adding room for accumulated rx data\n");
228*4882a593Smuzhiyun
229*4882a593Smuzhiyun kfree_skb(skb);
230*4882a593Smuzhiyun skb = NULL;
231*4882a593Smuzhiyun
232*4882a593Smuzhiyun kfree_skb(ndev->rx_data_reassembly);
233*4882a593Smuzhiyun ndev->rx_data_reassembly = NULL;
234*4882a593Smuzhiyun
235*4882a593Smuzhiyun err = -ENOMEM;
236*4882a593Smuzhiyun goto exit;
237*4882a593Smuzhiyun }
238*4882a593Smuzhiyun
239*4882a593Smuzhiyun /* second, combine the two fragments */
240*4882a593Smuzhiyun memcpy(skb_push(skb, reassembly_len),
241*4882a593Smuzhiyun ndev->rx_data_reassembly->data,
242*4882a593Smuzhiyun reassembly_len);
243*4882a593Smuzhiyun
244*4882a593Smuzhiyun /* third, free old reassembly */
245*4882a593Smuzhiyun kfree_skb(ndev->rx_data_reassembly);
246*4882a593Smuzhiyun ndev->rx_data_reassembly = NULL;
247*4882a593Smuzhiyun }
248*4882a593Smuzhiyun
249*4882a593Smuzhiyun if (pbf == NCI_PBF_CONT) {
250*4882a593Smuzhiyun /* need to wait for next fragment, store skb and exit */
251*4882a593Smuzhiyun ndev->rx_data_reassembly = skb;
252*4882a593Smuzhiyun return;
253*4882a593Smuzhiyun }
254*4882a593Smuzhiyun
255*4882a593Smuzhiyun exit:
256*4882a593Smuzhiyun if (ndev->nfc_dev->rf_mode == NFC_RF_TARGET) {
257*4882a593Smuzhiyun /* Data received in Target mode, forward to nfc core */
258*4882a593Smuzhiyun err = nfc_tm_data_received(ndev->nfc_dev, skb);
259*4882a593Smuzhiyun if (err)
260*4882a593Smuzhiyun pr_err("unable to handle received data\n");
261*4882a593Smuzhiyun } else {
262*4882a593Smuzhiyun nci_data_exchange_complete(ndev, skb, conn_id, err);
263*4882a593Smuzhiyun }
264*4882a593Smuzhiyun }
265*4882a593Smuzhiyun
266*4882a593Smuzhiyun /* Rx Data packet */
nci_rx_data_packet(struct nci_dev * ndev,struct sk_buff * skb)267*4882a593Smuzhiyun void nci_rx_data_packet(struct nci_dev *ndev, struct sk_buff *skb)
268*4882a593Smuzhiyun {
269*4882a593Smuzhiyun __u8 pbf = nci_pbf(skb->data);
270*4882a593Smuzhiyun __u8 status = 0;
271*4882a593Smuzhiyun __u8 conn_id = nci_conn_id(skb->data);
272*4882a593Smuzhiyun struct nci_conn_info *conn_info;
273*4882a593Smuzhiyun
274*4882a593Smuzhiyun pr_debug("len %d\n", skb->len);
275*4882a593Smuzhiyun
276*4882a593Smuzhiyun pr_debug("NCI RX: MT=data, PBF=%d, conn_id=%d, plen=%d\n",
277*4882a593Smuzhiyun nci_pbf(skb->data),
278*4882a593Smuzhiyun nci_conn_id(skb->data),
279*4882a593Smuzhiyun nci_plen(skb->data));
280*4882a593Smuzhiyun
281*4882a593Smuzhiyun conn_info = nci_get_conn_info_by_conn_id(ndev, nci_conn_id(skb->data));
282*4882a593Smuzhiyun if (!conn_info) {
283*4882a593Smuzhiyun kfree_skb(skb);
284*4882a593Smuzhiyun return;
285*4882a593Smuzhiyun }
286*4882a593Smuzhiyun
287*4882a593Smuzhiyun /* strip the nci data header */
288*4882a593Smuzhiyun skb_pull(skb, NCI_DATA_HDR_SIZE);
289*4882a593Smuzhiyun
290*4882a593Smuzhiyun if (ndev->target_active_prot == NFC_PROTO_MIFARE ||
291*4882a593Smuzhiyun ndev->target_active_prot == NFC_PROTO_JEWEL ||
292*4882a593Smuzhiyun ndev->target_active_prot == NFC_PROTO_FELICA ||
293*4882a593Smuzhiyun ndev->target_active_prot == NFC_PROTO_ISO15693) {
294*4882a593Smuzhiyun /* frame I/F => remove the status byte */
295*4882a593Smuzhiyun pr_debug("frame I/F => remove the status byte\n");
296*4882a593Smuzhiyun status = skb->data[skb->len - 1];
297*4882a593Smuzhiyun skb_trim(skb, (skb->len - 1));
298*4882a593Smuzhiyun }
299*4882a593Smuzhiyun
300*4882a593Smuzhiyun nci_add_rx_data_frag(ndev, skb, pbf, conn_id, nci_to_errno(status));
301*4882a593Smuzhiyun }
302