Commit | Line | Data |
---|---|---|
45051539 | 1 | // SPDX-License-Identifier: GPL-2.0-only |
83e81961 BYTK |
2 | /* |
3 | * Bluetooth supports for Qualcomm Atheros chips | |
4 | * | |
5 | * Copyright (c) 2015 The Linux Foundation. All rights reserved. | |
83e81961 BYTK |
6 | */ |
7 | #include <linux/module.h> | |
8 | #include <linux/firmware.h> | |
b6459415 | 9 | #include <linux/vmalloc.h> |
83e81961 BYTK |
10 | |
11 | #include <net/bluetooth/bluetooth.h> | |
12 | #include <net/bluetooth/hci_core.h> | |
13 | ||
14 | #include "btqca.h" | |
15 | ||
059924fd | 16 | int qca_read_soc_version(struct hci_dev *hdev, struct qca_btsoc_version *ver, |
7d250a06 | 17 | enum qca_btsoc_type soc_type) |
83e81961 BYTK |
18 | { |
19 | struct sk_buff *skb; | |
20 | struct edl_event_hdr *edl; | |
83e81961 BYTK |
21 | char cmd; |
22 | int err = 0; | |
7d250a06 BG |
23 | u8 event_type = HCI_EV_VENDOR; |
24 | u8 rlen = sizeof(*edl) + sizeof(*ver); | |
25 | u8 rtype = EDL_APP_VER_RES_EVT; | |
83e81961 | 26 | |
ba493d4f | 27 | bt_dev_dbg(hdev, "QCA Version Request"); |
83e81961 | 28 | |
7d250a06 BG |
29 | /* Unlike other SoC's sending version command response as payload to |
30 | * VSE event. WCN3991 sends version command response as a payload to | |
31 | * command complete event. | |
32 | */ | |
e5d6468f | 33 | if (soc_type >= QCA_WCN3991) { |
7d250a06 BG |
34 | event_type = 0; |
35 | rlen += 1; | |
36 | rtype = EDL_PATCH_VER_REQ_CMD; | |
37 | } | |
38 | ||
83e81961 BYTK |
39 | cmd = EDL_PATCH_VER_REQ_CMD; |
40 | skb = __hci_cmd_sync_ev(hdev, EDL_PATCH_CMD_OPCODE, EDL_PATCH_CMD_LEN, | |
7d250a06 | 41 | &cmd, event_type, HCI_INIT_TIMEOUT); |
83e81961 BYTK |
42 | if (IS_ERR(skb)) { |
43 | err = PTR_ERR(skb); | |
ba493d4f BG |
44 | bt_dev_err(hdev, "Reading QCA version information failed (%d)", |
45 | err); | |
83e81961 BYTK |
46 | return err; |
47 | } | |
48 | ||
7d250a06 | 49 | if (skb->len != rlen) { |
ba493d4f | 50 | bt_dev_err(hdev, "QCA Version size mismatch len %d", skb->len); |
83e81961 BYTK |
51 | err = -EILSEQ; |
52 | goto out; | |
53 | } | |
54 | ||
55 | edl = (struct edl_event_hdr *)(skb->data); | |
83e81961 BYTK |
56 | |
57 | if (edl->cresp != EDL_CMD_REQ_RES_EVT || | |
7d250a06 | 58 | edl->rtype != rtype) { |
ba493d4f BG |
59 | bt_dev_err(hdev, "QCA Wrong packet received %d %d", edl->cresp, |
60 | edl->rtype); | |
83e81961 BYTK |
61 | err = -EIO; |
62 | goto out; | |
63 | } | |
64 | ||
e5d6468f | 65 | if (soc_type >= QCA_WCN3991) |
059924fd VLNG |
66 | memcpy(ver, edl->data + 1, sizeof(*ver)); |
67 | else | |
68 | memcpy(ver, &edl->data, sizeof(*ver)); | |
83e81961 | 69 | |
4942857b ZH |
70 | bt_dev_info(hdev, "QCA Product ID :0x%08x", |
71 | le32_to_cpu(ver->product_id)); | |
72 | bt_dev_info(hdev, "QCA SOC Version :0x%08x", | |
73 | le32_to_cpu(ver->soc_id)); | |
74 | bt_dev_info(hdev, "QCA ROM Version :0x%08x", | |
75 | le16_to_cpu(ver->rom_ver)); | |
76 | bt_dev_info(hdev, "QCA Patch Version:0x%08x", | |
77 | le16_to_cpu(ver->patch_ver)); | |
83e81961 | 78 | |
059924fd | 79 | if (ver->soc_id == 0 || ver->rom_ver == 0) |
aadebac4 | 80 | err = -EILSEQ; |
83e81961 BYTK |
81 | |
82 | out: | |
83 | kfree_skb(skb); | |
aadebac4 BG |
84 | if (err) |
85 | bt_dev_err(hdev, "QCA Failed to get version (%d)", err); | |
83e81961 BYTK |
86 | |
87 | return err; | |
88 | } | |
ba493d4f | 89 | EXPORT_SYMBOL_GPL(qca_read_soc_version); |
83e81961 | 90 | |
c0187b0b VLNG |
91 | static int qca_read_fw_build_info(struct hci_dev *hdev) |
92 | { | |
93 | struct sk_buff *skb; | |
94 | struct edl_event_hdr *edl; | |
cda0d6a1 JH |
95 | char *build_label; |
96 | char cmd; | |
c0187b0b VLNG |
97 | int build_lbl_len, err = 0; |
98 | ||
99 | bt_dev_dbg(hdev, "QCA read fw build info"); | |
100 | ||
101 | cmd = EDL_GET_BUILD_INFO_CMD; | |
102 | skb = __hci_cmd_sync_ev(hdev, EDL_PATCH_CMD_OPCODE, EDL_PATCH_CMD_LEN, | |
103 | &cmd, 0, HCI_INIT_TIMEOUT); | |
104 | if (IS_ERR(skb)) { | |
105 | err = PTR_ERR(skb); | |
106 | bt_dev_err(hdev, "Reading QCA fw build info failed (%d)", | |
107 | err); | |
108 | return err; | |
109 | } | |
110 | ||
cda0d6a1 JH |
111 | if (skb->len < sizeof(*edl)) { |
112 | err = -EILSEQ; | |
113 | goto out; | |
114 | } | |
115 | ||
c0187b0b | 116 | edl = (struct edl_event_hdr *)(skb->data); |
c0187b0b VLNG |
117 | |
118 | if (edl->cresp != EDL_CMD_REQ_RES_EVT || | |
119 | edl->rtype != EDL_GET_BUILD_INFO_CMD) { | |
120 | bt_dev_err(hdev, "QCA Wrong packet received %d %d", edl->cresp, | |
121 | edl->rtype); | |
122 | err = -EIO; | |
123 | goto out; | |
124 | } | |
125 | ||
cda0d6a1 JH |
126 | if (skb->len < sizeof(*edl) + 1) { |
127 | err = -EILSEQ; | |
128 | goto out; | |
129 | } | |
130 | ||
c0187b0b | 131 | build_lbl_len = edl->data[0]; |
cda0d6a1 JH |
132 | |
133 | if (skb->len < sizeof(*edl) + 1 + build_lbl_len) { | |
134 | err = -EILSEQ; | |
135 | goto out; | |
c0187b0b VLNG |
136 | } |
137 | ||
cda0d6a1 JH |
138 | build_label = kstrndup(&edl->data[1], build_lbl_len, GFP_KERNEL); |
139 | if (!build_label) | |
140 | goto out; | |
141 | ||
c0187b0b VLNG |
142 | hci_set_fw_info(hdev, "%s", build_label); |
143 | ||
cda0d6a1 | 144 | kfree(build_label); |
c0187b0b VLNG |
145 | out: |
146 | kfree_skb(skb); | |
147 | return err; | |
148 | } | |
149 | ||
4fac8a7a STA |
150 | static int qca_send_patch_config_cmd(struct hci_dev *hdev) |
151 | { | |
152 | const u8 cmd[] = { EDL_PATCH_CONFIG_CMD, 0x01, 0, 0, 0 }; | |
153 | struct sk_buff *skb; | |
154 | struct edl_event_hdr *edl; | |
155 | int err; | |
156 | ||
157 | bt_dev_dbg(hdev, "QCA Patch config"); | |
158 | ||
159 | skb = __hci_cmd_sync_ev(hdev, EDL_PATCH_CMD_OPCODE, sizeof(cmd), | |
c0dbc560 | 160 | cmd, 0, HCI_INIT_TIMEOUT); |
4fac8a7a STA |
161 | if (IS_ERR(skb)) { |
162 | err = PTR_ERR(skb); | |
163 | bt_dev_err(hdev, "Sending QCA Patch config failed (%d)", err); | |
164 | return err; | |
165 | } | |
166 | ||
167 | if (skb->len != 2) { | |
168 | bt_dev_err(hdev, "QCA Patch config cmd size mismatch len %d", skb->len); | |
169 | err = -EILSEQ; | |
170 | goto out; | |
171 | } | |
172 | ||
173 | edl = (struct edl_event_hdr *)(skb->data); | |
4fac8a7a STA |
174 | |
175 | if (edl->cresp != EDL_PATCH_CONFIG_RES_EVT || edl->rtype != EDL_PATCH_CONFIG_CMD) { | |
176 | bt_dev_err(hdev, "QCA Wrong packet received %d %d", edl->cresp, | |
177 | edl->rtype); | |
178 | err = -EIO; | |
179 | goto out; | |
180 | } | |
181 | ||
182 | err = 0; | |
183 | ||
184 | out: | |
185 | kfree_skb(skb); | |
186 | return err; | |
187 | } | |
188 | ||
ba493d4f | 189 | static int qca_send_reset(struct hci_dev *hdev) |
83e81961 BYTK |
190 | { |
191 | struct sk_buff *skb; | |
192 | int err; | |
193 | ||
ba493d4f | 194 | bt_dev_dbg(hdev, "QCA HCI_RESET"); |
83e81961 BYTK |
195 | |
196 | skb = __hci_cmd_sync(hdev, HCI_OP_RESET, 0, NULL, HCI_INIT_TIMEOUT); | |
197 | if (IS_ERR(skb)) { | |
198 | err = PTR_ERR(skb); | |
ba493d4f | 199 | bt_dev_err(hdev, "QCA Reset failed (%d)", err); |
83e81961 BYTK |
200 | return err; |
201 | } | |
202 | ||
203 | kfree_skb(skb); | |
204 | ||
205 | return 0; | |
206 | } | |
207 | ||
a7f8dedb TJ |
208 | static int qca_read_fw_board_id(struct hci_dev *hdev, u16 *bid) |
209 | { | |
210 | u8 cmd; | |
211 | struct sk_buff *skb; | |
212 | struct edl_event_hdr *edl; | |
213 | int err = 0; | |
214 | ||
215 | cmd = EDL_GET_BID_REQ_CMD; | |
216 | skb = __hci_cmd_sync_ev(hdev, EDL_PATCH_CMD_OPCODE, EDL_PATCH_CMD_LEN, | |
217 | &cmd, 0, HCI_INIT_TIMEOUT); | |
218 | if (IS_ERR(skb)) { | |
219 | err = PTR_ERR(skb); | |
220 | bt_dev_err(hdev, "Reading QCA board ID failed (%d)", err); | |
221 | return err; | |
222 | } | |
223 | ||
224 | edl = skb_pull_data(skb, sizeof(*edl)); | |
225 | if (!edl) { | |
226 | bt_dev_err(hdev, "QCA read board ID with no header"); | |
227 | err = -EILSEQ; | |
228 | goto out; | |
229 | } | |
230 | ||
231 | if (edl->cresp != EDL_CMD_REQ_RES_EVT || | |
232 | edl->rtype != EDL_GET_BID_REQ_CMD) { | |
233 | bt_dev_err(hdev, "QCA Wrong packet: %d %d", edl->cresp, edl->rtype); | |
234 | err = -EIO; | |
235 | goto out; | |
236 | } | |
237 | ||
0adcf6be JH |
238 | if (skb->len < 3) { |
239 | err = -EILSEQ; | |
240 | goto out; | |
241 | } | |
242 | ||
a7f8dedb TJ |
243 | *bid = (edl->data[1] << 8) + edl->data[2]; |
244 | bt_dev_dbg(hdev, "%s: bid = %x", __func__, *bid); | |
245 | ||
246 | out: | |
247 | kfree_skb(skb); | |
248 | return err; | |
249 | } | |
250 | ||
a2780889 HB |
251 | int qca_send_pre_shutdown_cmd(struct hci_dev *hdev) |
252 | { | |
253 | struct sk_buff *skb; | |
254 | int err; | |
255 | ||
256 | bt_dev_dbg(hdev, "QCA pre shutdown cmd"); | |
257 | ||
010376ab HB |
258 | skb = __hci_cmd_sync_ev(hdev, QCA_PRE_SHUTDOWN_CMD, 0, |
259 | NULL, HCI_EV_CMD_COMPLETE, HCI_INIT_TIMEOUT); | |
260 | ||
a2780889 HB |
261 | if (IS_ERR(skb)) { |
262 | err = PTR_ERR(skb); | |
263 | bt_dev_err(hdev, "QCA preshutdown_cmd failed (%d)", err); | |
264 | return err; | |
265 | } | |
266 | ||
267 | kfree_skb(skb); | |
268 | ||
269 | return 0; | |
270 | } | |
271 | EXPORT_SYMBOL_GPL(qca_send_pre_shutdown_cmd); | |
272 | ||
2e4edfa1 | 273 | static int qca_tlv_check_data(struct hci_dev *hdev, |
ecf6b2d9 | 274 | struct qca_fw_config *config, |
2e4edfa1 JH |
275 | u8 *fw_data, size_t fw_size, |
276 | enum qca_btsoc_type soc_type) | |
83e81961 BYTK |
277 | { |
278 | const u8 *data; | |
279 | u32 type_len; | |
280 | u16 tag_id, tag_len; | |
281 | int idx, length; | |
282 | struct tlv_type_hdr *tlv; | |
283 | struct tlv_type_patch *tlv_patch; | |
284 | struct tlv_type_nvm *tlv_nvm; | |
b6388254 | 285 | uint8_t nvm_baud_rate = config->user_baud_rate; |
a112d3c7 | 286 | u8 type; |
83e81961 | 287 | |
e303d124 BG |
288 | config->dnld_mode = QCA_SKIP_EVT_NONE; |
289 | config->dnld_type = QCA_SKIP_EVT_NONE; | |
6e03126a | 290 | |
83e81961 | 291 | switch (config->type) { |
ecf6b2d9 | 292 | case ELF_TYPE_PATCH: |
2e4edfa1 JH |
293 | if (fw_size < 7) |
294 | return -EINVAL; | |
295 | ||
ecf6b2d9 VLNG |
296 | config->dnld_mode = QCA_SKIP_EVT_VSE_CC; |
297 | config->dnld_type = QCA_SKIP_EVT_VSE_CC; | |
298 | ||
299 | bt_dev_dbg(hdev, "File Class : 0x%x", fw_data[4]); | |
300 | bt_dev_dbg(hdev, "Data Encoding : 0x%x", fw_data[5]); | |
301 | bt_dev_dbg(hdev, "File version : 0x%x", fw_data[6]); | |
302 | break; | |
83e81961 | 303 | case TLV_TYPE_PATCH: |
2e4edfa1 JH |
304 | if (fw_size < sizeof(struct tlv_type_hdr) + sizeof(struct tlv_type_patch)) |
305 | return -EINVAL; | |
306 | ||
ecf6b2d9 VLNG |
307 | tlv = (struct tlv_type_hdr *)fw_data; |
308 | type_len = le32_to_cpu(tlv->type_len); | |
83e81961 | 309 | tlv_patch = (struct tlv_type_patch *)tlv->data; |
6e03126a LP |
310 | |
311 | /* For Rome version 1.1 to 3.1, all segment commands | |
312 | * are acked by a vendor specific event (VSE). | |
313 | * For Rome >= 3.2, the download mode field indicates | |
314 | * if VSE is skipped by the controller. | |
315 | * In case VSE is skipped, only the last segment is acked. | |
316 | */ | |
317 | config->dnld_mode = tlv_patch->download_mode; | |
32646db8 | 318 | config->dnld_type = config->dnld_mode; |
6e03126a | 319 | |
ecf6b2d9 | 320 | BT_DBG("TLV Type\t\t : 0x%x", type_len & 0x000000ff); |
6e03126a | 321 | BT_DBG("Total Length : %d bytes", |
83e81961 | 322 | le32_to_cpu(tlv_patch->total_size)); |
6e03126a | 323 | BT_DBG("Patch Data Length : %d bytes", |
83e81961 BYTK |
324 | le32_to_cpu(tlv_patch->data_length)); |
325 | BT_DBG("Signing Format Version : 0x%x", | |
326 | tlv_patch->format_version); | |
6e03126a | 327 | BT_DBG("Signature Algorithm : 0x%x", |
83e81961 | 328 | tlv_patch->signature); |
6e03126a LP |
329 | BT_DBG("Download mode : 0x%x", |
330 | tlv_patch->download_mode); | |
331 | BT_DBG("Reserved : 0x%x", | |
332 | tlv_patch->reserved1); | |
333 | BT_DBG("Product ID : 0x%04x", | |
83e81961 | 334 | le16_to_cpu(tlv_patch->product_id)); |
6e03126a | 335 | BT_DBG("Rom Build Version : 0x%04x", |
83e81961 | 336 | le16_to_cpu(tlv_patch->rom_build)); |
6e03126a | 337 | BT_DBG("Patch Version : 0x%04x", |
83e81961 | 338 | le16_to_cpu(tlv_patch->patch_version)); |
6e03126a | 339 | BT_DBG("Reserved : 0x%x", |
83e81961 | 340 | le16_to_cpu(tlv_patch->reserved2)); |
6e03126a | 341 | BT_DBG("Patch Entry Address : 0x%x", |
83e81961 BYTK |
342 | le32_to_cpu(tlv_patch->entry)); |
343 | break; | |
344 | ||
345 | case TLV_TYPE_NVM: | |
2e4edfa1 JH |
346 | if (fw_size < sizeof(struct tlv_type_hdr)) |
347 | return -EINVAL; | |
348 | ||
ecf6b2d9 VLNG |
349 | tlv = (struct tlv_type_hdr *)fw_data; |
350 | ||
351 | type_len = le32_to_cpu(tlv->type_len); | |
a112d3c7 JH |
352 | length = type_len >> 8; |
353 | type = type_len & 0xff; | |
ecf6b2d9 | 354 | |
a112d3c7 JH |
355 | /* Some NVM files have more than one set of tags, only parse |
356 | * the first set when it has type 2 for now. When there is | |
357 | * more than one set there is an enclosing header of type 4. | |
358 | */ | |
359 | if (type == 4) { | |
360 | if (fw_size < 2 * sizeof(struct tlv_type_hdr)) | |
361 | return -EINVAL; | |
362 | ||
363 | tlv++; | |
364 | ||
365 | type_len = le32_to_cpu(tlv->type_len); | |
366 | length = type_len >> 8; | |
367 | type = type_len & 0xff; | |
368 | } | |
369 | ||
370 | BT_DBG("TLV Type\t\t : 0x%x", type); | |
ecf6b2d9 VLNG |
371 | BT_DBG("Length\t\t : %d bytes", length); |
372 | ||
a112d3c7 JH |
373 | if (type != 2) |
374 | break; | |
375 | ||
2e4edfa1 JH |
376 | if (fw_size < length + (tlv->data - fw_data)) |
377 | return -EINVAL; | |
378 | ||
83e81961 BYTK |
379 | idx = 0; |
380 | data = tlv->data; | |
2e4edfa1 | 381 | while (idx < length - sizeof(struct tlv_type_nvm)) { |
83e81961 BYTK |
382 | tlv_nvm = (struct tlv_type_nvm *)(data + idx); |
383 | ||
384 | tag_id = le16_to_cpu(tlv_nvm->tag_id); | |
385 | tag_len = le16_to_cpu(tlv_nvm->tag_len); | |
386 | ||
2e4edfa1 JH |
387 | if (length < idx + sizeof(struct tlv_type_nvm) + tag_len) |
388 | return -EINVAL; | |
389 | ||
83e81961 BYTK |
390 | /* Update NVM tags as needed */ |
391 | switch (tag_id) { | |
dd336649 JH |
392 | case EDL_TAG_ID_BD_ADDR: |
393 | if (tag_len != sizeof(bdaddr_t)) | |
394 | return -EINVAL; | |
395 | ||
396 | memcpy(&config->bdaddr, tlv_nvm->data, sizeof(bdaddr_t)); | |
397 | ||
398 | break; | |
399 | ||
83e81961 | 400 | case EDL_TAG_ID_HCI: |
2e4edfa1 JH |
401 | if (tag_len < 3) |
402 | return -EINVAL; | |
403 | ||
83e81961 BYTK |
404 | /* HCI transport layer parameters |
405 | * enabling software inband sleep | |
406 | * onto controller side. | |
407 | */ | |
408 | tlv_nvm->data[0] |= 0x80; | |
409 | ||
410 | /* UART Baud Rate */ | |
e5d6468f | 411 | if (soc_type >= QCA_WCN3991) |
b6388254 RL |
412 | tlv_nvm->data[1] = nvm_baud_rate; |
413 | else | |
414 | tlv_nvm->data[2] = nvm_baud_rate; | |
83e81961 BYTK |
415 | |
416 | break; | |
417 | ||
418 | case EDL_TAG_ID_DEEP_SLEEP: | |
2e4edfa1 JH |
419 | if (tag_len < 1) |
420 | return -EINVAL; | |
421 | ||
83e81961 BYTK |
422 | /* Sleep enable mask |
423 | * enabling deep sleep feature on controller. | |
424 | */ | |
425 | tlv_nvm->data[0] |= 0x01; | |
426 | ||
427 | break; | |
428 | } | |
429 | ||
2e4edfa1 | 430 | idx += sizeof(struct tlv_type_nvm) + tag_len; |
83e81961 BYTK |
431 | } |
432 | break; | |
433 | ||
434 | default: | |
435 | BT_ERR("Unknown TLV type %d", config->type); | |
2e4edfa1 | 436 | return -EINVAL; |
83e81961 | 437 | } |
2e4edfa1 JH |
438 | |
439 | return 0; | |
83e81961 BYTK |
440 | } |
441 | ||
ba493d4f | 442 | static int qca_tlv_send_segment(struct hci_dev *hdev, int seg_size, |
7d250a06 BG |
443 | const u8 *data, enum qca_tlv_dnld_mode mode, |
444 | enum qca_btsoc_type soc_type) | |
83e81961 BYTK |
445 | { |
446 | struct sk_buff *skb; | |
447 | struct edl_event_hdr *edl; | |
448 | struct tlv_seg_resp *tlv_resp; | |
449 | u8 cmd[MAX_SIZE_PER_TLV_SEGMENT + 2]; | |
450 | int err = 0; | |
7d250a06 BG |
451 | u8 event_type = HCI_EV_VENDOR; |
452 | u8 rlen = (sizeof(*edl) + sizeof(*tlv_resp)); | |
453 | u8 rtype = EDL_TVL_DNLD_RES_EVT; | |
83e81961 | 454 | |
83e81961 BYTK |
455 | cmd[0] = EDL_PATCH_TLV_REQ_CMD; |
456 | cmd[1] = seg_size; | |
457 | memcpy(cmd + 2, data, seg_size); | |
458 | ||
e303d124 | 459 | if (mode == QCA_SKIP_EVT_VSE_CC || mode == QCA_SKIP_EVT_VSE) |
6e03126a LP |
460 | return __hci_cmd_send(hdev, EDL_PATCH_CMD_OPCODE, seg_size + 2, |
461 | cmd); | |
462 | ||
7d250a06 BG |
463 | /* Unlike other SoC's sending version command response as payload to |
464 | * VSE event. WCN3991 sends version command response as a payload to | |
465 | * command complete event. | |
466 | */ | |
e5d6468f | 467 | if (soc_type >= QCA_WCN3991) { |
7d250a06 BG |
468 | event_type = 0; |
469 | rlen = sizeof(*edl); | |
470 | rtype = EDL_PATCH_TLV_REQ_CMD; | |
471 | } | |
472 | ||
83e81961 | 473 | skb = __hci_cmd_sync_ev(hdev, EDL_PATCH_CMD_OPCODE, seg_size + 2, cmd, |
7d250a06 | 474 | event_type, HCI_INIT_TIMEOUT); |
83e81961 BYTK |
475 | if (IS_ERR(skb)) { |
476 | err = PTR_ERR(skb); | |
ba493d4f | 477 | bt_dev_err(hdev, "QCA Failed to send TLV segment (%d)", err); |
83e81961 BYTK |
478 | return err; |
479 | } | |
480 | ||
7d250a06 | 481 | if (skb->len != rlen) { |
ba493d4f | 482 | bt_dev_err(hdev, "QCA TLV response size mismatch"); |
83e81961 BYTK |
483 | err = -EILSEQ; |
484 | goto out; | |
485 | } | |
486 | ||
487 | edl = (struct edl_event_hdr *)(skb->data); | |
83e81961 | 488 | |
7d250a06 BG |
489 | if (edl->cresp != EDL_CMD_REQ_RES_EVT || edl->rtype != rtype) { |
490 | bt_dev_err(hdev, "QCA TLV with error stat 0x%x rtype 0x%x", | |
491 | edl->cresp, edl->rtype); | |
492 | err = -EIO; | |
493 | } | |
83e81961 | 494 | |
e5d6468f | 495 | if (soc_type >= QCA_WCN3991) |
7d250a06 BG |
496 | goto out; |
497 | ||
498 | tlv_resp = (struct tlv_seg_resp *)(edl->data); | |
499 | if (tlv_resp->result) { | |
ba493d4f BG |
500 | bt_dev_err(hdev, "QCA TLV with error stat 0x%x rtype 0x%x (0x%x)", |
501 | edl->cresp, edl->rtype, tlv_resp->result); | |
83e81961 BYTK |
502 | } |
503 | ||
504 | out: | |
505 | kfree_skb(skb); | |
506 | ||
507 | return err; | |
508 | } | |
509 | ||
32646db8 BG |
510 | static int qca_inject_cmd_complete_event(struct hci_dev *hdev) |
511 | { | |
512 | struct hci_event_hdr *hdr; | |
513 | struct hci_ev_cmd_complete *evt; | |
514 | struct sk_buff *skb; | |
515 | ||
516 | skb = bt_skb_alloc(sizeof(*hdr) + sizeof(*evt) + 1, GFP_KERNEL); | |
517 | if (!skb) | |
518 | return -ENOMEM; | |
519 | ||
520 | hdr = skb_put(skb, sizeof(*hdr)); | |
521 | hdr->evt = HCI_EV_CMD_COMPLETE; | |
522 | hdr->plen = sizeof(*evt) + 1; | |
523 | ||
524 | evt = skb_put(skb, sizeof(*evt)); | |
525 | evt->ncmd = 1; | |
2fde6afb | 526 | evt->opcode = cpu_to_le16(QCA_HCI_CC_OPCODE); |
32646db8 BG |
527 | |
528 | skb_put_u8(skb, QCA_HCI_CC_SUCCESS); | |
529 | ||
530 | hci_skb_pkt_type(skb) = HCI_EVENT_PKT; | |
531 | ||
532 | return hci_recv_frame(hdev, skb); | |
533 | } | |
534 | ||
ba493d4f | 535 | static int qca_download_firmware(struct hci_dev *hdev, |
7d250a06 | 536 | struct qca_fw_config *config, |
ecf6b2d9 VLNG |
537 | enum qca_btsoc_type soc_type, |
538 | u8 rom_ver) | |
83e81961 BYTK |
539 | { |
540 | const struct firmware *fw; | |
b43ca511 | 541 | u8 *data; |
6e03126a | 542 | const u8 *segment; |
b43ca511 | 543 | int ret, size, remain, i = 0; |
83e81961 | 544 | |
ba493d4f | 545 | bt_dev_info(hdev, "QCA Downloading %s", config->fwname); |
83e81961 BYTK |
546 | |
547 | ret = request_firmware(&fw, config->fwname, &hdev->dev); | |
548 | if (ret) { | |
ecf6b2d9 VLNG |
549 | /* For WCN6750, if mbn file is not present then check for |
550 | * tlv file. | |
551 | */ | |
552 | if (soc_type == QCA_WCN6750 && config->type == ELF_TYPE_PATCH) { | |
553 | bt_dev_dbg(hdev, "QCA Failed to request file: %s (%d)", | |
554 | config->fwname, ret); | |
555 | config->type = TLV_TYPE_PATCH; | |
556 | snprintf(config->fwname, sizeof(config->fwname), | |
557 | "qca/msbtfw%02x.tlv", rom_ver); | |
558 | bt_dev_info(hdev, "QCA Downloading %s", config->fwname); | |
559 | ret = request_firmware(&fw, config->fwname, &hdev->dev); | |
560 | if (ret) { | |
561 | bt_dev_err(hdev, "QCA Failed to request file: %s (%d)", | |
562 | config->fwname, ret); | |
563 | return ret; | |
564 | } | |
565 | } else { | |
566 | bt_dev_err(hdev, "QCA Failed to request file: %s (%d)", | |
567 | config->fwname, ret); | |
568 | return ret; | |
569 | } | |
83e81961 BYTK |
570 | } |
571 | ||
b43ca511 CA |
572 | size = fw->size; |
573 | data = vmalloc(fw->size); | |
574 | if (!data) { | |
575 | bt_dev_err(hdev, "QCA Failed to allocate memory for file: %s", | |
576 | config->fwname); | |
577 | release_firmware(fw); | |
578 | return -ENOMEM; | |
579 | } | |
580 | ||
581 | memcpy(data, fw->data, size); | |
582 | release_firmware(fw); | |
583 | ||
2e4edfa1 JH |
584 | ret = qca_tlv_check_data(hdev, config, data, size, soc_type); |
585 | if (ret) | |
40d442f9 | 586 | goto out; |
83e81961 | 587 | |
b43ca511 CA |
588 | segment = data; |
589 | remain = size; | |
6e03126a LP |
590 | while (remain > 0) { |
591 | int segsize = min(MAX_SIZE_PER_TLV_SEGMENT, remain); | |
592 | ||
593 | bt_dev_dbg(hdev, "Send segment %d, size %d", i++, segsize); | |
594 | ||
595 | remain -= segsize; | |
596 | /* The last segment is always acked regardless download mode */ | |
597 | if (!remain || segsize < MAX_SIZE_PER_TLV_SEGMENT) | |
e303d124 | 598 | config->dnld_mode = QCA_SKIP_EVT_NONE; |
6e03126a | 599 | |
ba493d4f | 600 | ret = qca_tlv_send_segment(hdev, segsize, segment, |
7d250a06 | 601 | config->dnld_mode, soc_type); |
6e03126a | 602 | if (ret) |
32646db8 | 603 | goto out; |
6e03126a LP |
604 | |
605 | segment += segsize; | |
83e81961 BYTK |
606 | } |
607 | ||
32646db8 BG |
608 | /* Latest qualcomm chipsets are not sending a command complete event |
609 | * for every fw packet sent. They only respond with a vendor specific | |
610 | * event for the last packet. This optimization in the chip will | |
611 | * decrease the BT in initialization time. Here we will inject a command | |
612 | * complete event to avoid a command timeout error message. | |
613 | */ | |
e303d124 BG |
614 | if (config->dnld_type == QCA_SKIP_EVT_VSE_CC || |
615 | config->dnld_type == QCA_SKIP_EVT_VSE) | |
c7c5ae29 | 616 | ret = qca_inject_cmd_complete_event(hdev); |
32646db8 BG |
617 | |
618 | out: | |
b43ca511 | 619 | vfree(data); |
83e81961 BYTK |
620 | |
621 | return ret; | |
622 | } | |
623 | ||
590deccf BG |
624 | static int qca_disable_soc_logging(struct hci_dev *hdev) |
625 | { | |
626 | struct sk_buff *skb; | |
627 | u8 cmd[2]; | |
628 | int err; | |
629 | ||
630 | cmd[0] = QCA_DISABLE_LOGGING_SUB_OP; | |
631 | cmd[1] = 0x00; | |
632 | skb = __hci_cmd_sync_ev(hdev, QCA_DISABLE_LOGGING, sizeof(cmd), cmd, | |
633 | HCI_EV_CMD_COMPLETE, HCI_INIT_TIMEOUT); | |
634 | if (IS_ERR(skb)) { | |
635 | err = PTR_ERR(skb); | |
636 | bt_dev_err(hdev, "QCA Failed to disable soc logging(%d)", err); | |
637 | return err; | |
638 | } | |
639 | ||
640 | kfree_skb(skb); | |
641 | ||
642 | return 0; | |
643 | } | |
644 | ||
83e81961 BYTK |
645 | int qca_set_bdaddr_rome(struct hci_dev *hdev, const bdaddr_t *bdaddr) |
646 | { | |
647 | struct sk_buff *skb; | |
648 | u8 cmd[9]; | |
649 | int err; | |
650 | ||
651 | cmd[0] = EDL_NVM_ACCESS_SET_REQ_CMD; | |
652 | cmd[1] = 0x02; /* TAG ID */ | |
653 | cmd[2] = sizeof(bdaddr_t); /* size */ | |
654 | memcpy(cmd + 3, bdaddr, sizeof(bdaddr_t)); | |
655 | skb = __hci_cmd_sync_ev(hdev, EDL_NVM_ACCESS_OPCODE, sizeof(cmd), cmd, | |
e4cc5a18 | 656 | HCI_EV_VENDOR, HCI_INIT_TIMEOUT); |
83e81961 BYTK |
657 | if (IS_ERR(skb)) { |
658 | err = PTR_ERR(skb); | |
ba493d4f | 659 | bt_dev_err(hdev, "QCA Change address command failed (%d)", err); |
83e81961 BYTK |
660 | return err; |
661 | } | |
662 | ||
663 | kfree_skb(skb); | |
664 | ||
665 | return 0; | |
666 | } | |
667 | EXPORT_SYMBOL_GPL(qca_set_bdaddr_rome); | |
668 | ||
dd336649 | 669 | static int qca_check_bdaddr(struct hci_dev *hdev, const struct qca_fw_config *config) |
32868e12 JH |
670 | { |
671 | struct hci_rp_read_bd_addr *bda; | |
672 | struct sk_buff *skb; | |
673 | int err; | |
674 | ||
675 | if (bacmp(&hdev->public_addr, BDADDR_ANY)) | |
676 | return 0; | |
677 | ||
678 | skb = __hci_cmd_sync(hdev, HCI_OP_READ_BD_ADDR, 0, NULL, | |
679 | HCI_INIT_TIMEOUT); | |
680 | if (IS_ERR(skb)) { | |
681 | err = PTR_ERR(skb); | |
682 | bt_dev_err(hdev, "Failed to read device address (%d)", err); | |
683 | return err; | |
684 | } | |
685 | ||
686 | if (skb->len != sizeof(*bda)) { | |
687 | bt_dev_err(hdev, "Device address length mismatch"); | |
688 | kfree_skb(skb); | |
689 | return -EIO; | |
690 | } | |
691 | ||
692 | bda = (struct hci_rp_read_bd_addr *)skb->data; | |
dd336649 | 693 | if (!bacmp(&bda->bdaddr, &config->bdaddr)) |
32868e12 JH |
694 | set_bit(HCI_QUIRK_USE_BDADDR_PROPERTY, &hdev->quirks); |
695 | ||
696 | kfree_skb(skb); | |
697 | ||
698 | return 0; | |
699 | } | |
700 | ||
a7f8dedb TJ |
701 | static void qca_generate_hsp_nvm_name(char *fwname, size_t max_size, |
702 | struct qca_btsoc_version ver, u8 rom_ver, u16 bid) | |
703 | { | |
704 | const char *variant; | |
705 | ||
706 | /* hsp gf chip */ | |
707 | if ((le32_to_cpu(ver.soc_id) & QCA_HSP_GF_SOC_MASK) == QCA_HSP_GF_SOC_ID) | |
708 | variant = "g"; | |
709 | else | |
710 | variant = ""; | |
711 | ||
712 | if (bid == 0x0) | |
713 | snprintf(fwname, max_size, "qca/hpnv%02x%s.bin", rom_ver, variant); | |
714 | else | |
715 | snprintf(fwname, max_size, "qca/hpnv%02x%s.%x", rom_ver, variant, bid); | |
716 | } | |
717 | ||
e41137d8 ZH |
718 | static inline void qca_get_nvm_name_generic(struct qca_fw_config *cfg, |
719 | const char *stem, u8 rom_ver, u16 bid) | |
720 | { | |
721 | if (bid == 0x0) | |
722 | snprintf(cfg->fwname, sizeof(cfg->fwname), "qca/%snv%02x.bin", stem, rom_ver); | |
723 | else if (bid & 0xff00) | |
724 | snprintf(cfg->fwname, sizeof(cfg->fwname), | |
725 | "qca/%snv%02x.b%x", stem, rom_ver, bid); | |
726 | else | |
727 | snprintf(cfg->fwname, sizeof(cfg->fwname), | |
728 | "qca/%snv%02x.b%02x", stem, rom_ver, bid); | |
729 | } | |
730 | ||
aadebac4 | 731 | int qca_uart_setup(struct hci_dev *hdev, uint8_t baudrate, |
059924fd | 732 | enum qca_btsoc_type soc_type, struct qca_btsoc_version ver, |
99c905c6 | 733 | const char *firmware_name) |
83e81961 | 734 | { |
dd336649 | 735 | struct qca_fw_config config = {}; |
83e81961 | 736 | int err; |
523760b7 | 737 | u8 rom_ver = 0; |
059924fd | 738 | u32 soc_ver; |
a7f8dedb | 739 | u16 boardid = 0; |
83e81961 | 740 | |
ba493d4f | 741 | bt_dev_dbg(hdev, "QCA setup on UART"); |
83e81961 | 742 | |
059924fd VLNG |
743 | soc_ver = get_soc_ver(ver.soc_id, ver.rom_ver); |
744 | ||
745 | bt_dev_info(hdev, "QCA controller version 0x%08x", soc_ver); | |
746 | ||
83e81961 BYTK |
747 | config.user_baud_rate = baudrate; |
748 | ||
99fba8e3 VLNG |
749 | /* Firmware files to download are based on ROM version. |
750 | * ROM version is derived from last two bytes of soc_ver. | |
751 | */ | |
f904feef LW |
752 | if (soc_type == QCA_WCN3988) |
753 | rom_ver = ((soc_ver & 0x00000f00) >> 0x05) | (soc_ver & 0x0000000f); | |
754 | else | |
755 | rom_ver = ((soc_ver & 0x00000f00) >> 0x04) | (soc_ver & 0x0000000f); | |
99fba8e3 | 756 | |
4fac8a7a STA |
757 | if (soc_type == QCA_WCN6750) |
758 | qca_send_patch_config_cmd(hdev); | |
759 | ||
83e81961 BYTK |
760 | /* Download rampatch file */ |
761 | config.type = TLV_TYPE_PATCH; | |
691d54d0 NA |
762 | switch (soc_type) { |
763 | case QCA_WCN3990: | |
764 | case QCA_WCN3991: | |
765 | case QCA_WCN3998: | |
4219d468 BG |
766 | snprintf(config.fwname, sizeof(config.fwname), |
767 | "qca/crbtfw%02x.tlv", rom_ver); | |
691d54d0 NA |
768 | break; |
769 | case QCA_WCN3988: | |
770 | snprintf(config.fwname, sizeof(config.fwname), | |
771 | "qca/apbtfw%02x.tlv", rom_ver); | |
772 | break; | |
a7f8dedb TJ |
773 | case QCA_QCA2066: |
774 | snprintf(config.fwname, sizeof(config.fwname), | |
775 | "qca/hpbtfw%02x.tlv", rom_ver); | |
776 | break; | |
691d54d0 | 777 | case QCA_QCA6390: |
e5d6468f RL |
778 | snprintf(config.fwname, sizeof(config.fwname), |
779 | "qca/htbtfw%02x.tlv", rom_ver); | |
691d54d0 NA |
780 | break; |
781 | case QCA_WCN6750: | |
ecf6b2d9 VLNG |
782 | /* Choose mbn file by default.If mbn file is not found |
783 | * then choose tlv file | |
784 | */ | |
785 | config.type = ELF_TYPE_PATCH; | |
d8f97da1 | 786 | snprintf(config.fwname, sizeof(config.fwname), |
ecf6b2d9 | 787 | "qca/msbtfw%02x.mbn", rom_ver); |
691d54d0 NA |
788 | break; |
789 | case QCA_WCN6855: | |
095327fe SK |
790 | snprintf(config.fwname, sizeof(config.fwname), |
791 | "qca/hpbtfw%02x.tlv", rom_ver); | |
691d54d0 | 792 | break; |
e0c1278a NA |
793 | case QCA_WCN7850: |
794 | snprintf(config.fwname, sizeof(config.fwname), | |
795 | "qca/hmtbtfw%02x.tlv", rom_ver); | |
796 | break; | |
691d54d0 | 797 | default: |
4219d468 BG |
798 | snprintf(config.fwname, sizeof(config.fwname), |
799 | "qca/rampatch_%08x.bin", soc_ver); | |
800 | } | |
801 | ||
ecf6b2d9 | 802 | err = qca_download_firmware(hdev, &config, soc_type, rom_ver); |
83e81961 | 803 | if (err < 0) { |
ba493d4f | 804 | bt_dev_err(hdev, "QCA Failed to download patch (%d)", err); |
83e81961 BYTK |
805 | return err; |
806 | } | |
807 | ||
8059ba0b MK |
808 | /* Give the controller some time to get ready to receive the NVM */ |
809 | msleep(10); | |
810 | ||
e41137d8 | 811 | if (soc_type == QCA_QCA2066 || soc_type == QCA_WCN7850) |
a7f8dedb TJ |
812 | qca_read_fw_board_id(hdev, &boardid); |
813 | ||
83e81961 BYTK |
814 | /* Download NVM configuration */ |
815 | config.type = TLV_TYPE_NVM; | |
691d54d0 | 816 | if (firmware_name) { |
99c905c6 RL |
817 | snprintf(config.fwname, sizeof(config.fwname), |
818 | "qca/%s", firmware_name); | |
691d54d0 NA |
819 | } else { |
820 | switch (soc_type) { | |
821 | case QCA_WCN3990: | |
822 | case QCA_WCN3991: | |
823 | case QCA_WCN3998: | |
824 | if (le32_to_cpu(ver.soc_id) == QCA_WCN3991_SOC_ID) { | |
825 | snprintf(config.fwname, sizeof(config.fwname), | |
826 | "qca/crnv%02xu.bin", rom_ver); | |
827 | } else { | |
828 | snprintf(config.fwname, sizeof(config.fwname), | |
829 | "qca/crnv%02x.bin", rom_ver); | |
830 | } | |
831 | break; | |
832 | case QCA_WCN3988: | |
059924fd | 833 | snprintf(config.fwname, sizeof(config.fwname), |
691d54d0 NA |
834 | "qca/apnv%02x.bin", rom_ver); |
835 | break; | |
a7f8dedb TJ |
836 | case QCA_QCA2066: |
837 | qca_generate_hsp_nvm_name(config.fwname, | |
838 | sizeof(config.fwname), ver, rom_ver, boardid); | |
839 | break; | |
691d54d0 NA |
840 | case QCA_QCA6390: |
841 | snprintf(config.fwname, sizeof(config.fwname), | |
842 | "qca/htnv%02x.bin", rom_ver); | |
843 | break; | |
844 | case QCA_WCN6750: | |
059924fd | 845 | snprintf(config.fwname, sizeof(config.fwname), |
691d54d0 NA |
846 | "qca/msnv%02x.bin", rom_ver); |
847 | break; | |
848 | case QCA_WCN6855: | |
849 | snprintf(config.fwname, sizeof(config.fwname), | |
850 | "qca/hpnv%02x.bin", rom_ver); | |
851 | break; | |
e0c1278a | 852 | case QCA_WCN7850: |
e41137d8 | 853 | qca_get_nvm_name_generic(&config, "hmt", rom_ver, boardid); |
e0c1278a | 854 | break; |
691d54d0 NA |
855 | |
856 | default: | |
857 | snprintf(config.fwname, sizeof(config.fwname), | |
858 | "qca/nvm_%08x.bin", soc_ver); | |
059924fd VLNG |
859 | } |
860 | } | |
4219d468 | 861 | |
ecf6b2d9 | 862 | err = qca_download_firmware(hdev, &config, soc_type, rom_ver); |
83e81961 | 863 | if (err < 0) { |
ba493d4f | 864 | bt_dev_err(hdev, "QCA Failed to download NVM (%d)", err); |
83e81961 BYTK |
865 | return err; |
866 | } | |
867 | ||
691d54d0 NA |
868 | switch (soc_type) { |
869 | case QCA_WCN3991: | |
a7f8dedb | 870 | case QCA_QCA2066: |
691d54d0 NA |
871 | case QCA_QCA6390: |
872 | case QCA_WCN6750: | |
873 | case QCA_WCN6855: | |
e0c1278a | 874 | case QCA_WCN7850: |
590deccf BG |
875 | err = qca_disable_soc_logging(hdev); |
876 | if (err < 0) | |
877 | return err; | |
691d54d0 NA |
878 | break; |
879 | default: | |
880 | break; | |
590deccf BG |
881 | } |
882 | ||
d8f97da1 | 883 | /* WCN399x and WCN6750 supports the Microsoft vendor extension with 0xFD70 as the |
eaf19b0c MC |
884 | * VsMsftOpCode. |
885 | */ | |
886 | switch (soc_type) { | |
691d54d0 | 887 | case QCA_WCN3988: |
eaf19b0c MC |
888 | case QCA_WCN3990: |
889 | case QCA_WCN3991: | |
890 | case QCA_WCN3998: | |
d8f97da1 | 891 | case QCA_WCN6750: |
eaf19b0c MC |
892 | hci_set_msft_opcode(hdev, 0xFD70); |
893 | break; | |
894 | default: | |
895 | break; | |
896 | } | |
897 | ||
83e81961 | 898 | /* Perform HCI reset */ |
ba493d4f | 899 | err = qca_send_reset(hdev); |
83e81961 | 900 | if (err < 0) { |
ba493d4f | 901 | bt_dev_err(hdev, "QCA Failed to run HCI_RESET (%d)", err); |
83e81961 BYTK |
902 | return err; |
903 | } | |
904 | ||
095327fe SK |
905 | switch (soc_type) { |
906 | case QCA_WCN3991: | |
907 | case QCA_WCN6750: | |
908 | case QCA_WCN6855: | |
e0c1278a | 909 | case QCA_WCN7850: |
c0187b0b VLNG |
910 | /* get fw build info */ |
911 | err = qca_read_fw_build_info(hdev); | |
912 | if (err < 0) | |
913 | return err; | |
095327fe SK |
914 | break; |
915 | default: | |
916 | break; | |
c0187b0b VLNG |
917 | } |
918 | ||
dd336649 | 919 | err = qca_check_bdaddr(hdev, &config); |
32868e12 JH |
920 | if (err) |
921 | return err; | |
922 | ||
ba493d4f | 923 | bt_dev_info(hdev, "QCA setup on UART is completed"); |
83e81961 BYTK |
924 | |
925 | return 0; | |
926 | } | |
ba493d4f | 927 | EXPORT_SYMBOL_GPL(qca_uart_setup); |
83e81961 | 928 | |
5c0a1001 BG |
929 | int qca_set_bdaddr(struct hci_dev *hdev, const bdaddr_t *bdaddr) |
930 | { | |
77f45cca | 931 | bdaddr_t bdaddr_swapped; |
5c0a1001 BG |
932 | struct sk_buff *skb; |
933 | int err; | |
934 | ||
77f45cca JH |
935 | baswap(&bdaddr_swapped, bdaddr); |
936 | ||
937 | skb = __hci_cmd_sync_ev(hdev, EDL_WRITE_BD_ADDR_OPCODE, 6, | |
938 | &bdaddr_swapped, HCI_EV_VENDOR, | |
939 | HCI_INIT_TIMEOUT); | |
5c0a1001 BG |
940 | if (IS_ERR(skb)) { |
941 | err = PTR_ERR(skb); | |
942 | bt_dev_err(hdev, "QCA Change address cmd failed (%d)", err); | |
943 | return err; | |
944 | } | |
945 | ||
946 | kfree_skb(skb); | |
947 | ||
948 | return 0; | |
949 | } | |
950 | EXPORT_SYMBOL_GPL(qca_set_bdaddr); | |
951 | ||
523760b7 | 952 | |
83e81961 | 953 | MODULE_AUTHOR("Ben Young Tae Kim <ytkim@qca.qualcomm.com>"); |
83d8e815 | 954 | MODULE_DESCRIPTION("Bluetooth support for Qualcomm Atheros family"); |
83e81961 | 955 | MODULE_LICENSE("GPL"); |