blob: 54410479f2f596250889a7dccbc89fe228d8150e [file] [log] [blame]
Marcel Holtmann48f0ed12015-04-06 00:52:11 -07001/*
2 *
3 * Bluetooth support for Intel devices
4 *
5 * Copyright (C) 2015 Intel Corporation
6 *
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 2 of the License, or
11 * (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
21 *
22 */
23
24#include <linux/module.h>
Loic Poulain145f2362015-09-04 17:54:34 +020025#include <linux/firmware.h>
Loic Poulaind06f1072015-10-01 18:16:21 +020026#include <linux/regmap.h>
Marcel Holtmann48f0ed12015-04-06 00:52:11 -070027
28#include <net/bluetooth/bluetooth.h>
29#include <net/bluetooth/hci_core.h>
30
31#include "btintel.h"
32
33#define VERSION "0.1"
34
35#define BDADDR_INTEL (&(bdaddr_t) {{0x00, 0x8b, 0x9e, 0x19, 0x03, 0x00}})
36
37int btintel_check_bdaddr(struct hci_dev *hdev)
38{
39 struct hci_rp_read_bd_addr *bda;
40 struct sk_buff *skb;
41
42 skb = __hci_cmd_sync(hdev, HCI_OP_READ_BD_ADDR, 0, NULL,
43 HCI_INIT_TIMEOUT);
44 if (IS_ERR(skb)) {
45 int err = PTR_ERR(skb);
46 BT_ERR("%s: Reading Intel device address failed (%d)",
47 hdev->name, err);
48 return err;
49 }
50
51 if (skb->len != sizeof(*bda)) {
52 BT_ERR("%s: Intel device address length mismatch", hdev->name);
53 kfree_skb(skb);
54 return -EIO;
55 }
56
57 bda = (struct hci_rp_read_bd_addr *)skb->data;
Marcel Holtmann48f0ed12015-04-06 00:52:11 -070058
59 /* For some Intel based controllers, the default Bluetooth device
60 * address 00:03:19:9E:8B:00 can be found. These controllers are
61 * fully operational, but have the danger of duplicate addresses
62 * and that in turn can cause problems with Bluetooth operation.
63 */
64 if (!bacmp(&bda->bdaddr, BDADDR_INTEL)) {
65 BT_ERR("%s: Found Intel default device address (%pMR)",
66 hdev->name, &bda->bdaddr);
67 set_bit(HCI_QUIRK_INVALID_BDADDR, &hdev->quirks);
68 }
69
70 kfree_skb(skb);
71
72 return 0;
73}
74EXPORT_SYMBOL_GPL(btintel_check_bdaddr);
75
Loic Poulain28dc4b92015-12-03 16:10:22 +010076int btintel_enter_mfg(struct hci_dev *hdev)
77{
78 const u8 param[] = { 0x01, 0x00 };
79 struct sk_buff *skb;
80
81 skb = __hci_cmd_sync(hdev, 0xfc11, 2, param, HCI_CMD_TIMEOUT);
82 if (IS_ERR(skb)) {
83 bt_dev_err(hdev, "Entering manufacturer mode failed (%ld)",
84 PTR_ERR(skb));
85 return PTR_ERR(skb);
86 }
87 kfree_skb(skb);
88
89 return 0;
90}
91EXPORT_SYMBOL_GPL(btintel_enter_mfg);
92
93int btintel_exit_mfg(struct hci_dev *hdev, bool reset, bool patched)
94{
95 u8 param[] = { 0x00, 0x00 };
96 struct sk_buff *skb;
97
98 /* The 2nd command parameter specifies the manufacturing exit method:
99 * 0x00: Just disable the manufacturing mode (0x00).
100 * 0x01: Disable manufacturing mode and reset with patches deactivated.
101 * 0x02: Disable manufacturing mode and reset with patches activated.
102 */
103 if (reset)
104 param[1] |= patched ? 0x02 : 0x01;
105
106 skb = __hci_cmd_sync(hdev, 0xfc11, 2, param, HCI_CMD_TIMEOUT);
107 if (IS_ERR(skb)) {
108 bt_dev_err(hdev, "Exiting manufacturer mode failed (%ld)",
109 PTR_ERR(skb));
110 return PTR_ERR(skb);
111 }
112 kfree_skb(skb);
113
114 return 0;
115}
116EXPORT_SYMBOL_GPL(btintel_exit_mfg);
117
Marcel Holtmann48f0ed12015-04-06 00:52:11 -0700118int btintel_set_bdaddr(struct hci_dev *hdev, const bdaddr_t *bdaddr)
119{
120 struct sk_buff *skb;
121 int err;
122
123 skb = __hci_cmd_sync(hdev, 0xfc31, 6, bdaddr, HCI_INIT_TIMEOUT);
124 if (IS_ERR(skb)) {
125 err = PTR_ERR(skb);
126 BT_ERR("%s: Changing Intel device address failed (%d)",
127 hdev->name, err);
128 return err;
129 }
130 kfree_skb(skb);
131
132 return 0;
133}
134EXPORT_SYMBOL_GPL(btintel_set_bdaddr);
135
Marcel Holtmann6d2e50d2015-10-09 14:42:08 +0200136int btintel_set_diag(struct hci_dev *hdev, bool enable)
137{
138 struct sk_buff *skb;
139 u8 param[3];
140 int err;
141
Marcel Holtmann6d2e50d2015-10-09 14:42:08 +0200142 if (enable) {
143 param[0] = 0x03;
144 param[1] = 0x03;
145 param[2] = 0x03;
146 } else {
147 param[0] = 0x00;
148 param[1] = 0x00;
149 param[2] = 0x00;
150 }
151
152 skb = __hci_cmd_sync(hdev, 0xfc43, 3, param, HCI_INIT_TIMEOUT);
153 if (IS_ERR(skb)) {
154 err = PTR_ERR(skb);
Marcel Holtmannd8270fb2015-10-17 16:00:27 +0200155 if (err == -ENODATA)
Marcel Holtmann213445b2015-10-21 02:45:19 +0200156 goto done;
Marcel Holtmann6d2e50d2015-10-09 14:42:08 +0200157 BT_ERR("%s: Changing Intel diagnostic mode failed (%d)",
158 hdev->name, err);
159 return err;
160 }
161 kfree_skb(skb);
162
Marcel Holtmann213445b2015-10-21 02:45:19 +0200163done:
164 btintel_set_event_mask(hdev, enable);
Marcel Holtmann6d2e50d2015-10-09 14:42:08 +0200165 return 0;
166}
167EXPORT_SYMBOL_GPL(btintel_set_diag);
168
Marcel Holtmann3e247672015-10-17 16:00:28 +0200169int btintel_set_diag_mfg(struct hci_dev *hdev, bool enable)
170{
Loic Poulain28dc4b92015-12-03 16:10:22 +0100171 int err, ret;
Marcel Holtmann3e247672015-10-17 16:00:28 +0200172
Loic Poulain28dc4b92015-12-03 16:10:22 +0100173 err = btintel_enter_mfg(hdev);
174 if (err)
175 return err;
Marcel Holtmann3e247672015-10-17 16:00:28 +0200176
Loic Poulain28dc4b92015-12-03 16:10:22 +0100177 ret = btintel_set_diag(hdev, enable);
Marcel Holtmann3e247672015-10-17 16:00:28 +0200178
Loic Poulain28dc4b92015-12-03 16:10:22 +0100179 err = btintel_exit_mfg(hdev, false, false);
180 if (err)
181 return err;
Marcel Holtmann3e247672015-10-17 16:00:28 +0200182
Loic Poulain28dc4b92015-12-03 16:10:22 +0100183 return ret;
Marcel Holtmann3e247672015-10-17 16:00:28 +0200184}
185EXPORT_SYMBOL_GPL(btintel_set_diag_mfg);
186
Marcel Holtmann973bb972015-07-05 14:37:38 +0200187void btintel_hw_error(struct hci_dev *hdev, u8 code)
188{
189 struct sk_buff *skb;
190 u8 type = 0x00;
191
192 BT_ERR("%s: Hardware error 0x%2.2x", hdev->name, code);
193
194 skb = __hci_cmd_sync(hdev, HCI_OP_RESET, 0, NULL, HCI_INIT_TIMEOUT);
195 if (IS_ERR(skb)) {
196 BT_ERR("%s: Reset after hardware error failed (%ld)",
197 hdev->name, PTR_ERR(skb));
198 return;
199 }
200 kfree_skb(skb);
201
202 skb = __hci_cmd_sync(hdev, 0xfc22, 1, &type, HCI_INIT_TIMEOUT);
203 if (IS_ERR(skb)) {
204 BT_ERR("%s: Retrieving Intel exception info failed (%ld)",
205 hdev->name, PTR_ERR(skb));
206 return;
207 }
208
209 if (skb->len != 13) {
210 BT_ERR("%s: Exception info size mismatch", hdev->name);
211 kfree_skb(skb);
212 return;
213 }
214
215 BT_ERR("%s: Exception info %s", hdev->name, (char *)(skb->data + 1));
216
217 kfree_skb(skb);
218}
219EXPORT_SYMBOL_GPL(btintel_hw_error);
220
Marcel Holtmann7feb99e2015-07-05 15:02:07 +0200221void btintel_version_info(struct hci_dev *hdev, struct intel_version *ver)
222{
223 const char *variant;
224
225 switch (ver->fw_variant) {
226 case 0x06:
227 variant = "Bootloader";
228 break;
229 case 0x23:
230 variant = "Firmware";
231 break;
232 default:
233 return;
234 }
235
236 BT_INFO("%s: %s revision %u.%u build %u week %u %u", hdev->name,
237 variant, ver->fw_revision >> 4, ver->fw_revision & 0x0f,
238 ver->fw_build_num, ver->fw_build_ww, 2000 + ver->fw_build_yy);
239}
240EXPORT_SYMBOL_GPL(btintel_version_info);
241
Marcel Holtmann09df1232015-07-05 14:55:36 +0200242int btintel_secure_send(struct hci_dev *hdev, u8 fragment_type, u32 plen,
243 const void *param)
244{
245 while (plen > 0) {
246 struct sk_buff *skb;
247 u8 cmd_param[253], fragment_len = (plen > 252) ? 252 : plen;
248
249 cmd_param[0] = fragment_type;
250 memcpy(cmd_param + 1, param, fragment_len);
251
252 skb = __hci_cmd_sync(hdev, 0xfc09, fragment_len + 1,
253 cmd_param, HCI_INIT_TIMEOUT);
254 if (IS_ERR(skb))
255 return PTR_ERR(skb);
256
257 kfree_skb(skb);
258
259 plen -= fragment_len;
260 param += fragment_len;
261 }
262
263 return 0;
264}
265EXPORT_SYMBOL_GPL(btintel_secure_send);
266
Loic Poulain145f2362015-09-04 17:54:34 +0200267int btintel_load_ddc_config(struct hci_dev *hdev, const char *ddc_name)
268{
269 const struct firmware *fw;
270 struct sk_buff *skb;
271 const u8 *fw_ptr;
272 int err;
273
274 err = request_firmware_direct(&fw, ddc_name, &hdev->dev);
275 if (err < 0) {
276 bt_dev_err(hdev, "Failed to load Intel DDC file %s (%d)",
277 ddc_name, err);
278 return err;
279 }
280
281 bt_dev_info(hdev, "Found Intel DDC parameters: %s", ddc_name);
282
283 fw_ptr = fw->data;
284
285 /* DDC file contains one or more DDC structure which has
286 * Length (1 byte), DDC ID (2 bytes), and DDC value (Length - 2).
287 */
288 while (fw->size > fw_ptr - fw->data) {
289 u8 cmd_plen = fw_ptr[0] + sizeof(u8);
290
291 skb = __hci_cmd_sync(hdev, 0xfc8b, cmd_plen, fw_ptr,
292 HCI_INIT_TIMEOUT);
293 if (IS_ERR(skb)) {
294 bt_dev_err(hdev, "Failed to send Intel_Write_DDC (%ld)",
295 PTR_ERR(skb));
296 release_firmware(fw);
297 return PTR_ERR(skb);
298 }
299
300 fw_ptr += cmd_plen;
301 kfree_skb(skb);
302 }
303
304 release_firmware(fw);
305
306 bt_dev_info(hdev, "Applying Intel DDC parameters completed");
307
308 return 0;
309}
310EXPORT_SYMBOL_GPL(btintel_load_ddc_config);
311
Marcel Holtmann213445b2015-10-21 02:45:19 +0200312int btintel_set_event_mask(struct hci_dev *hdev, bool debug)
313{
314 u8 mask[8] = { 0x87, 0x0c, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 };
315 struct sk_buff *skb;
316 int err;
317
318 if (debug)
319 mask[1] |= 0x62;
320
321 skb = __hci_cmd_sync(hdev, 0xfc52, 8, mask, HCI_INIT_TIMEOUT);
322 if (IS_ERR(skb)) {
323 err = PTR_ERR(skb);
324 BT_ERR("%s: Setting Intel event mask failed (%d)",
325 hdev->name, err);
326 return err;
327 }
328 kfree_skb(skb);
329
330 return 0;
331}
332EXPORT_SYMBOL_GPL(btintel_set_event_mask);
333
334int btintel_set_event_mask_mfg(struct hci_dev *hdev, bool debug)
335{
Loic Poulain28dc4b92015-12-03 16:10:22 +0100336 int err, ret;
Marcel Holtmann213445b2015-10-21 02:45:19 +0200337
Loic Poulain28dc4b92015-12-03 16:10:22 +0100338 err = btintel_enter_mfg(hdev);
339 if (err)
340 return err;
Marcel Holtmann213445b2015-10-21 02:45:19 +0200341
Loic Poulain28dc4b92015-12-03 16:10:22 +0100342 ret = btintel_set_event_mask(hdev, debug);
Marcel Holtmann213445b2015-10-21 02:45:19 +0200343
Loic Poulain28dc4b92015-12-03 16:10:22 +0100344 err = btintel_exit_mfg(hdev, false, false);
345 if (err)
346 return err;
Marcel Holtmann213445b2015-10-21 02:45:19 +0200347
Loic Poulain28dc4b92015-12-03 16:10:22 +0100348 return ret;
Marcel Holtmann213445b2015-10-21 02:45:19 +0200349}
350EXPORT_SYMBOL_GPL(btintel_set_event_mask_mfg);
351
Loic Poulaind06f1072015-10-01 18:16:21 +0200352/* ------- REGMAP IBT SUPPORT ------- */
353
354#define IBT_REG_MODE_8BIT 0x00
355#define IBT_REG_MODE_16BIT 0x01
356#define IBT_REG_MODE_32BIT 0x02
357
358struct regmap_ibt_context {
359 struct hci_dev *hdev;
360 __u16 op_write;
361 __u16 op_read;
362};
363
364struct ibt_cp_reg_access {
365 __le32 addr;
366 __u8 mode;
367 __u8 len;
368 __u8 data[0];
369} __packed;
370
371struct ibt_rp_reg_access {
372 __u8 status;
373 __le32 addr;
374 __u8 data[0];
375} __packed;
376
377static int regmap_ibt_read(void *context, const void *addr, size_t reg_size,
378 void *val, size_t val_size)
379{
380 struct regmap_ibt_context *ctx = context;
381 struct ibt_cp_reg_access cp;
382 struct ibt_rp_reg_access *rp;
383 struct sk_buff *skb;
384 int err = 0;
385
386 if (reg_size != sizeof(__le32))
387 return -EINVAL;
388
389 switch (val_size) {
390 case 1:
391 cp.mode = IBT_REG_MODE_8BIT;
392 break;
393 case 2:
394 cp.mode = IBT_REG_MODE_16BIT;
395 break;
396 case 4:
397 cp.mode = IBT_REG_MODE_32BIT;
398 break;
399 default:
400 return -EINVAL;
401 }
402
403 /* regmap provides a little-endian formatted addr */
404 cp.addr = *(__le32 *)addr;
405 cp.len = val_size;
406
407 bt_dev_dbg(ctx->hdev, "Register (0x%x) read", le32_to_cpu(cp.addr));
408
409 skb = hci_cmd_sync(ctx->hdev, ctx->op_read, sizeof(cp), &cp,
410 HCI_CMD_TIMEOUT);
411 if (IS_ERR(skb)) {
412 err = PTR_ERR(skb);
413 bt_dev_err(ctx->hdev, "regmap: Register (0x%x) read error (%d)",
414 le32_to_cpu(cp.addr), err);
415 return err;
416 }
417
418 if (skb->len != sizeof(*rp) + val_size) {
419 bt_dev_err(ctx->hdev, "regmap: Register (0x%x) read error, bad len",
420 le32_to_cpu(cp.addr));
421 err = -EINVAL;
422 goto done;
423 }
424
425 rp = (struct ibt_rp_reg_access *)skb->data;
426
427 if (rp->addr != cp.addr) {
428 bt_dev_err(ctx->hdev, "regmap: Register (0x%x) read error, bad addr",
429 le32_to_cpu(rp->addr));
430 err = -EINVAL;
431 goto done;
432 }
433
434 memcpy(val, rp->data, val_size);
435
436done:
437 kfree_skb(skb);
438 return err;
439}
440
441static int regmap_ibt_gather_write(void *context,
442 const void *addr, size_t reg_size,
443 const void *val, size_t val_size)
444{
445 struct regmap_ibt_context *ctx = context;
446 struct ibt_cp_reg_access *cp;
447 struct sk_buff *skb;
448 int plen = sizeof(*cp) + val_size;
449 u8 mode;
450 int err = 0;
451
452 if (reg_size != sizeof(__le32))
453 return -EINVAL;
454
455 switch (val_size) {
456 case 1:
457 mode = IBT_REG_MODE_8BIT;
458 break;
459 case 2:
460 mode = IBT_REG_MODE_16BIT;
461 break;
462 case 4:
463 mode = IBT_REG_MODE_32BIT;
464 break;
465 default:
466 return -EINVAL;
467 }
468
469 cp = kmalloc(plen, GFP_KERNEL);
470 if (!cp)
471 return -ENOMEM;
472
473 /* regmap provides a little-endian formatted addr/value */
474 cp->addr = *(__le32 *)addr;
475 cp->mode = mode;
476 cp->len = val_size;
477 memcpy(&cp->data, val, val_size);
478
479 bt_dev_dbg(ctx->hdev, "Register (0x%x) write", le32_to_cpu(cp->addr));
480
481 skb = hci_cmd_sync(ctx->hdev, ctx->op_write, plen, cp, HCI_CMD_TIMEOUT);
482 if (IS_ERR(skb)) {
483 err = PTR_ERR(skb);
484 bt_dev_err(ctx->hdev, "regmap: Register (0x%x) write error (%d)",
485 le32_to_cpu(cp->addr), err);
486 goto done;
487 }
488 kfree_skb(skb);
489
490done:
491 kfree(cp);
492 return err;
493}
494
495static int regmap_ibt_write(void *context, const void *data, size_t count)
496{
497 /* data contains register+value, since we only support 32bit addr,
498 * minimum data size is 4 bytes.
499 */
500 if (WARN_ONCE(count < 4, "Invalid register access"))
501 return -EINVAL;
502
503 return regmap_ibt_gather_write(context, data, 4, data + 4, count - 4);
504}
505
506static void regmap_ibt_free_context(void *context)
507{
508 kfree(context);
509}
510
511static struct regmap_bus regmap_ibt = {
512 .read = regmap_ibt_read,
513 .write = regmap_ibt_write,
514 .gather_write = regmap_ibt_gather_write,
515 .free_context = regmap_ibt_free_context,
516 .reg_format_endian_default = REGMAP_ENDIAN_LITTLE,
517 .val_format_endian_default = REGMAP_ENDIAN_LITTLE,
518};
519
520/* Config is the same for all register regions */
521static const struct regmap_config regmap_ibt_cfg = {
522 .name = "btintel_regmap",
523 .reg_bits = 32,
524 .val_bits = 32,
525};
526
527struct regmap *btintel_regmap_init(struct hci_dev *hdev, u16 opcode_read,
528 u16 opcode_write)
529{
530 struct regmap_ibt_context *ctx;
531
532 bt_dev_info(hdev, "regmap: Init R%x-W%x region", opcode_read,
533 opcode_write);
534
535 ctx = kzalloc(sizeof(*ctx), GFP_KERNEL);
536 if (!ctx)
537 return ERR_PTR(-ENOMEM);
538
539 ctx->op_read = opcode_read;
540 ctx->op_write = opcode_write;
541 ctx->hdev = hdev;
542
543 return regmap_init(&hdev->dev, &regmap_ibt, ctx, &regmap_ibt_cfg);
544}
545EXPORT_SYMBOL_GPL(btintel_regmap_init);
546
Marcel Holtmann48f0ed12015-04-06 00:52:11 -0700547MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
548MODULE_DESCRIPTION("Bluetooth support for Intel devices ver " VERSION);
549MODULE_VERSION(VERSION);
550MODULE_LICENSE("GPL");
Marcel Holtmann0ed97e82015-08-27 08:57:39 +0200551MODULE_FIRMWARE("intel/ibt-11-5.sfi");
552MODULE_FIRMWARE("intel/ibt-11-5.ddc");