NFC: pn533: Fix div by zero while stopping polling
[linux-2.6-block.git] / drivers / nfc / pn533.c
CommitLineData
c46ee386
AAJ
1/*
2 * Copyright (C) 2011 Instituto Nokia de Tecnologia
3 *
4 * Authors:
5 * Lauro Ramos Venancio <lauro.venancio@openbossa.org>
6 * Aloisio Almeida Jr <aloisio.almeida@openbossa.org>
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 2 of the License, or
11 * (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the
20 * Free Software Foundation, Inc.,
21 * 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
22 */
23
24#include <linux/device.h>
25#include <linux/kernel.h>
26#include <linux/module.h>
27#include <linux/slab.h>
28#include <linux/usb.h>
29#include <linux/nfc.h>
30#include <linux/netdevice.h>
55eb94f9 31#include <net/nfc/nfc.h>
c46ee386
AAJ
32
33#define VERSION "0.1"
34
35#define PN533_VENDOR_ID 0x4CC
36#define PN533_PRODUCT_ID 0x2533
37
38#define SCM_VENDOR_ID 0x4E6
39#define SCL3711_PRODUCT_ID 0x5591
40
5c7b0531
SO
41#define SONY_VENDOR_ID 0x054c
42#define PASORI_PRODUCT_ID 0x02e1
43
5c7b0531
SO
44#define PN533_DEVICE_STD 0x1
45#define PN533_DEVICE_PASORI 0x2
46
01d719a2
SO
47#define PN533_ALL_PROTOCOLS (NFC_PROTO_JEWEL_MASK | NFC_PROTO_MIFARE_MASK |\
48 NFC_PROTO_FELICA_MASK | NFC_PROTO_ISO14443_MASK |\
49 NFC_PROTO_NFC_DEP_MASK |\
50 NFC_PROTO_ISO14443_B_MASK)
5c7b0531
SO
51
52#define PN533_NO_TYPE_B_PROTOCOLS (NFC_PROTO_JEWEL_MASK | \
53 NFC_PROTO_MIFARE_MASK | \
54 NFC_PROTO_FELICA_MASK | \
01d719a2 55 NFC_PROTO_ISO14443_MASK | \
5c7b0531
SO
56 NFC_PROTO_NFC_DEP_MASK)
57
c46ee386 58static const struct usb_device_id pn533_table[] = {
5c7b0531
SO
59 { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
60 .idVendor = PN533_VENDOR_ID,
61 .idProduct = PN533_PRODUCT_ID,
62 .driver_info = PN533_DEVICE_STD,
63 },
64 { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
65 .idVendor = SCM_VENDOR_ID,
66 .idProduct = SCL3711_PRODUCT_ID,
67 .driver_info = PN533_DEVICE_STD,
68 },
69 { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
70 .idVendor = SONY_VENDOR_ID,
71 .idProduct = PASORI_PRODUCT_ID,
72 .driver_info = PN533_DEVICE_PASORI,
73 },
c46ee386
AAJ
74 { }
75};
76MODULE_DEVICE_TABLE(usb, pn533_table);
77
6fbbdc16
SO
78/* How much time we spend listening for initiators */
79#define PN533_LISTEN_TIME 2
80
63123108
WR
81/* Standard pn533 frame definitions */
82#define PN533_STD_FRAME_HEADER_LEN (sizeof(struct pn533_std_frame) \
b1bb290a 83 + 2) /* data[0] TFI, data[1] CC */
63123108 84#define PN533_STD_FRAME_TAIL_LEN 2 /* data[len] DCS, data[len + 1] postamble*/
82dec34d 85
15461aeb
WR
86/*
87 * Max extended frame payload len, excluding TFI and CC
88 * which are already in PN533_FRAME_HEADER_LEN.
89 */
63123108 90#define PN533_STD_FRAME_MAX_PAYLOAD_LEN 263
15461aeb 91
63123108 92#define PN533_STD_FRAME_ACK_SIZE 6 /* Preamble (1), SoPC (2), ACK Code (2),
5b5a4437 93 Postamble (1) */
63123108
WR
94#define PN533_STD_FRAME_CHECKSUM(f) (f->data[f->datalen])
95#define PN533_STD_FRAME_POSTAMBLE(f) (f->data[f->datalen + 1])
c46ee386
AAJ
96
97/* start of frame */
63123108 98#define PN533_STD_FRAME_SOF 0x00FF
c46ee386 99
63123108
WR
100/* standard frame identifier: in/out/error */
101#define PN533_STD_FRAME_IDENTIFIER(f) (f->data[0]) /* TFI */
102#define PN533_STD_FRAME_DIR_OUT 0xD4
103#define PN533_STD_FRAME_DIR_IN 0xD5
c46ee386
AAJ
104
105/* PN533 Commands */
63123108 106#define PN533_STD_FRAME_CMD(f) (f->data[1])
c46ee386
AAJ
107
108#define PN533_CMD_GET_FIRMWARE_VERSION 0x02
109#define PN533_CMD_RF_CONFIGURATION 0x32
110#define PN533_CMD_IN_DATA_EXCHANGE 0x40
5c7b0531 111#define PN533_CMD_IN_COMM_THRU 0x42
c46ee386
AAJ
112#define PN533_CMD_IN_LIST_PASSIVE_TARGET 0x4A
113#define PN533_CMD_IN_ATR 0x50
114#define PN533_CMD_IN_RELEASE 0x52
361f3cb7 115#define PN533_CMD_IN_JUMP_FOR_DEP 0x56
c46ee386 116
ad3823ce 117#define PN533_CMD_TG_INIT_AS_TARGET 0x8c
103b34cf 118#define PN533_CMD_TG_GET_DATA 0x86
dadb06f2 119#define PN533_CMD_TG_SET_DATA 0x8e
aada17ac 120#define PN533_CMD_UNDEF 0xff
ad3823ce 121
c46ee386
AAJ
122#define PN533_CMD_RESPONSE(cmd) (cmd + 1)
123
124/* PN533 Return codes */
125#define PN533_CMD_RET_MASK 0x3F
126#define PN533_CMD_MI_MASK 0x40
127#define PN533_CMD_RET_SUCCESS 0x00
128
129struct pn533;
130
0c33d262 131typedef int (*pn533_cmd_complete_t) (struct pn533 *dev, void *arg, int status);
c46ee386 132
aada17ac
WR
133typedef int (*pn533_send_async_complete_t) (struct pn533 *dev, void *arg,
134 struct sk_buff *resp);
135
c46ee386
AAJ
136/* structs for pn533 commands */
137
138/* PN533_CMD_GET_FIRMWARE_VERSION */
139struct pn533_fw_version {
140 u8 ic;
141 u8 ver;
142 u8 rev;
143 u8 support;
144};
145
146/* PN533_CMD_RF_CONFIGURATION */
34a85bfc 147#define PN533_CFGITEM_TIMING 0x02
c46ee386 148#define PN533_CFGITEM_MAX_RETRIES 0x05
5c7b0531 149#define PN533_CFGITEM_PASORI 0x82
c46ee386 150
34a85bfc
SO
151#define PN533_CONFIG_TIMING_102 0xb
152#define PN533_CONFIG_TIMING_204 0xc
153#define PN533_CONFIG_TIMING_409 0xd
154#define PN533_CONFIG_TIMING_819 0xe
155
c46ee386
AAJ
156#define PN533_CONFIG_MAX_RETRIES_NO_RETRY 0x00
157#define PN533_CONFIG_MAX_RETRIES_ENDLESS 0xFF
158
159struct pn533_config_max_retries {
160 u8 mx_rty_atr;
161 u8 mx_rty_psl;
162 u8 mx_rty_passive_act;
163} __packed;
164
34a85bfc
SO
165struct pn533_config_timing {
166 u8 rfu;
167 u8 atr_res_timeout;
168 u8 dep_timeout;
169} __packed;
170
c46ee386
AAJ
171/* PN533_CMD_IN_LIST_PASSIVE_TARGET */
172
173/* felica commands opcode */
174#define PN533_FELICA_OPC_SENSF_REQ 0
175#define PN533_FELICA_OPC_SENSF_RES 1
176/* felica SENSF_REQ parameters */
177#define PN533_FELICA_SENSF_SC_ALL 0xFFFF
178#define PN533_FELICA_SENSF_RC_NO_SYSTEM_CODE 0
179#define PN533_FELICA_SENSF_RC_SYSTEM_CODE 1
180#define PN533_FELICA_SENSF_RC_ADVANCED_PROTOCOL 2
181
182/* type B initiator_data values */
183#define PN533_TYPE_B_AFI_ALL_FAMILIES 0
184#define PN533_TYPE_B_POLL_METHOD_TIMESLOT 0
185#define PN533_TYPE_B_POLL_METHOD_PROBABILISTIC 1
186
187union pn533_cmd_poll_initdata {
188 struct {
189 u8 afi;
190 u8 polling_method;
191 } __packed type_b;
192 struct {
193 u8 opcode;
194 __be16 sc;
195 u8 rc;
196 u8 tsn;
197 } __packed felica;
198};
199
200/* Poll modulations */
201enum {
202 PN533_POLL_MOD_106KBPS_A,
203 PN533_POLL_MOD_212KBPS_FELICA,
204 PN533_POLL_MOD_424KBPS_FELICA,
205 PN533_POLL_MOD_106KBPS_JEWEL,
206 PN533_POLL_MOD_847KBPS_B,
6fbbdc16 207 PN533_LISTEN_MOD,
c46ee386
AAJ
208
209 __PN533_POLL_MOD_AFTER_LAST,
210};
211#define PN533_POLL_MOD_MAX (__PN533_POLL_MOD_AFTER_LAST - 1)
212
213struct pn533_poll_modulations {
214 struct {
215 u8 maxtg;
216 u8 brty;
217 union pn533_cmd_poll_initdata initiator_data;
218 } __packed data;
219 u8 len;
220};
221
ef3d56e1 222static const struct pn533_poll_modulations poll_mod[] = {
c46ee386
AAJ
223 [PN533_POLL_MOD_106KBPS_A] = {
224 .data = {
225 .maxtg = 1,
226 .brty = 0,
227 },
228 .len = 2,
229 },
230 [PN533_POLL_MOD_212KBPS_FELICA] = {
231 .data = {
232 .maxtg = 1,
233 .brty = 1,
234 .initiator_data.felica = {
235 .opcode = PN533_FELICA_OPC_SENSF_REQ,
236 .sc = PN533_FELICA_SENSF_SC_ALL,
237 .rc = PN533_FELICA_SENSF_RC_NO_SYSTEM_CODE,
238 .tsn = 0,
239 },
240 },
241 .len = 7,
242 },
243 [PN533_POLL_MOD_424KBPS_FELICA] = {
244 .data = {
245 .maxtg = 1,
246 .brty = 2,
247 .initiator_data.felica = {
248 .opcode = PN533_FELICA_OPC_SENSF_REQ,
249 .sc = PN533_FELICA_SENSF_SC_ALL,
250 .rc = PN533_FELICA_SENSF_RC_NO_SYSTEM_CODE,
251 .tsn = 0,
252 },
253 },
254 .len = 7,
255 },
256 [PN533_POLL_MOD_106KBPS_JEWEL] = {
257 .data = {
258 .maxtg = 1,
259 .brty = 4,
260 },
261 .len = 2,
262 },
263 [PN533_POLL_MOD_847KBPS_B] = {
264 .data = {
265 .maxtg = 1,
266 .brty = 8,
267 .initiator_data.type_b = {
268 .afi = PN533_TYPE_B_AFI_ALL_FAMILIES,
269 .polling_method =
270 PN533_TYPE_B_POLL_METHOD_TIMESLOT,
271 },
272 },
273 .len = 3,
274 },
6fbbdc16
SO
275 [PN533_LISTEN_MOD] = {
276 .len = 0,
277 },
c46ee386
AAJ
278};
279
280/* PN533_CMD_IN_ATR */
281
c46ee386
AAJ
282struct pn533_cmd_activate_response {
283 u8 status;
284 u8 nfcid3t[10];
285 u8 didt;
286 u8 bst;
287 u8 brt;
288 u8 to;
289 u8 ppt;
290 /* optional */
291 u8 gt[];
292} __packed;
293
361f3cb7
SO
294struct pn533_cmd_jump_dep_response {
295 u8 status;
296 u8 tg;
297 u8 nfcid3t[10];
298 u8 didt;
299 u8 bst;
300 u8 brt;
301 u8 to;
302 u8 ppt;
303 /* optional */
304 u8 gt[];
305} __packed;
c46ee386 306
ad3823ce
SO
307
308/* PN533_TG_INIT_AS_TARGET */
309#define PN533_INIT_TARGET_PASSIVE 0x1
310#define PN533_INIT_TARGET_DEP 0x2
311
fc40a8c1
SO
312#define PN533_INIT_TARGET_RESP_FRAME_MASK 0x3
313#define PN533_INIT_TARGET_RESP_ACTIVE 0x1
314#define PN533_INIT_TARGET_RESP_DEP 0x4
315
c46ee386
AAJ
316struct pn533 {
317 struct usb_device *udev;
318 struct usb_interface *interface;
319 struct nfc_dev *nfc_dev;
320
321 struct urb *out_urb;
c46ee386 322 struct urb *in_urb;
c46ee386 323
6ff73fd2
SO
324 struct sk_buff_head resp_q;
325
4849f85e
SO
326 struct workqueue_struct *wq;
327 struct work_struct cmd_work;
5d50b364 328 struct work_struct cmd_complete_work;
6fbbdc16 329 struct work_struct poll_work;
6ff73fd2 330 struct work_struct mi_work;
103b34cf 331 struct work_struct tg_work;
6fbbdc16 332 struct timer_list listen_timer;
4849f85e 333 int wq_in_error;
6fbbdc16 334 int cancel_listen;
c46ee386
AAJ
335
336 pn533_cmd_complete_t cmd_complete;
337 void *cmd_complete_arg;
b1e666f5 338 void *cmd_complete_mi_arg;
0201ed03 339 struct mutex cmd_lock;
c46ee386
AAJ
340 u8 cmd;
341
342 struct pn533_poll_modulations *poll_mod_active[PN533_POLL_MOD_MAX + 1];
343 u8 poll_mod_count;
344 u8 poll_mod_curr;
345 u32 poll_protocols;
6fbbdc16
SO
346 u32 listen_protocols;
347
348 u8 *gb;
349 size_t gb_len;
c46ee386
AAJ
350
351 u8 tgt_available_prots;
352 u8 tgt_active_prot;
51ad304c 353 u8 tgt_mode;
5c7b0531
SO
354
355 u32 device_type;
5d50b364
SO
356
357 struct list_head cmd_queue;
358 u8 cmd_pending;
9e2d493e
WR
359
360 struct pn533_frame_ops *ops;
5d50b364
SO
361};
362
363struct pn533_cmd {
364 struct list_head queue;
aada17ac
WR
365 u8 cmd_code;
366 struct sk_buff *req;
367 struct sk_buff *resp;
9e2d493e 368 int resp_len;
5d50b364 369 void *arg;
c46ee386
AAJ
370};
371
63123108 372struct pn533_std_frame {
c46ee386
AAJ
373 u8 preamble;
374 __be16 start_frame;
375 u8 datalen;
376 u8 datalen_checksum;
377 u8 data[];
378} __packed;
379
9e2d493e
WR
380struct pn533_frame_ops {
381 void (*tx_frame_init)(void *frame, u8 cmd_code);
382 void (*tx_frame_finish)(void *frame);
383 void (*tx_update_payload_len)(void *frame, int len);
384 int tx_header_len;
385 int tx_tail_len;
386
387 bool (*rx_is_frame_valid)(void *frame);
388 int (*rx_frame_size)(void *frame);
389 int rx_header_len;
390 int rx_tail_len;
391
392 int max_payload_len;
393 u8 (*get_cmd_code)(void *frame);
394};
395
c46ee386 396/* The rule: value + checksum = 0 */
63123108 397static inline u8 pn533_std_checksum(u8 value)
c46ee386
AAJ
398{
399 return ~value + 1;
400}
401
402/* The rule: sum(data elements) + checksum = 0 */
63123108 403static u8 pn533_std_data_checksum(u8 *data, int datalen)
c46ee386
AAJ
404{
405 u8 sum = 0;
406 int i;
407
408 for (i = 0; i < datalen; i++)
409 sum += data[i];
410
63123108 411 return pn533_std_checksum(sum);
c46ee386
AAJ
412}
413
63123108 414static void pn533_std_tx_frame_init(void *_frame, u8 cmd_code)
c46ee386 415{
63123108 416 struct pn533_std_frame *frame = _frame;
9e2d493e 417
c46ee386 418 frame->preamble = 0;
63123108
WR
419 frame->start_frame = cpu_to_be16(PN533_STD_FRAME_SOF);
420 PN533_STD_FRAME_IDENTIFIER(frame) = PN533_STD_FRAME_DIR_OUT;
421 PN533_STD_FRAME_CMD(frame) = cmd_code;
c46ee386
AAJ
422 frame->datalen = 2;
423}
424
63123108 425static void pn533_std_tx_frame_finish(void *_frame)
c46ee386 426{
63123108 427 struct pn533_std_frame *frame = _frame;
9e2d493e 428
63123108 429 frame->datalen_checksum = pn533_std_checksum(frame->datalen);
c46ee386 430
63123108
WR
431 PN533_STD_FRAME_CHECKSUM(frame) =
432 pn533_std_data_checksum(frame->data, frame->datalen);
c46ee386 433
63123108 434 PN533_STD_FRAME_POSTAMBLE(frame) = 0;
c46ee386
AAJ
435}
436
63123108 437static void pn533_std_tx_update_payload_len(void *_frame, int len)
9e2d493e 438{
63123108 439 struct pn533_std_frame *frame = _frame;
9e2d493e
WR
440
441 frame->datalen += len;
442}
443
63123108 444static bool pn533_std_rx_frame_is_valid(void *_frame)
c46ee386
AAJ
445{
446 u8 checksum;
63123108 447 struct pn533_std_frame *frame = _frame;
c46ee386 448
63123108 449 if (frame->start_frame != cpu_to_be16(PN533_STD_FRAME_SOF))
c46ee386
AAJ
450 return false;
451
63123108 452 checksum = pn533_std_checksum(frame->datalen);
c46ee386
AAJ
453 if (checksum != frame->datalen_checksum)
454 return false;
455
63123108
WR
456 checksum = pn533_std_data_checksum(frame->data, frame->datalen);
457 if (checksum != PN533_STD_FRAME_CHECKSUM(frame))
c46ee386
AAJ
458 return false;
459
460 return true;
461}
462
63123108 463static bool pn533_std_rx_frame_is_ack(struct pn533_std_frame *frame)
c46ee386 464{
63123108 465 if (frame->start_frame != cpu_to_be16(PN533_STD_FRAME_SOF))
c46ee386
AAJ
466 return false;
467
468 if (frame->datalen != 0 || frame->datalen_checksum != 0xFF)
469 return false;
470
471 return true;
472}
473
63123108 474static inline int pn533_std_rx_frame_size(void *frame)
9e2d493e 475{
63123108 476 struct pn533_std_frame *f = frame;
9e2d493e 477
63123108
WR
478 return sizeof(struct pn533_std_frame) + f->datalen +
479 PN533_STD_FRAME_TAIL_LEN;
9e2d493e
WR
480}
481
63123108 482static u8 pn533_std_get_cmd_code(void *frame)
9e2d493e 483{
63123108 484 struct pn533_std_frame *f = frame;
9e2d493e 485
63123108 486 return PN533_STD_FRAME_CMD(f);
9e2d493e
WR
487}
488
ef3d56e1 489static struct pn533_frame_ops pn533_std_frame_ops = {
63123108
WR
490 .tx_frame_init = pn533_std_tx_frame_init,
491 .tx_frame_finish = pn533_std_tx_frame_finish,
492 .tx_update_payload_len = pn533_std_tx_update_payload_len,
493 .tx_header_len = PN533_STD_FRAME_HEADER_LEN,
494 .tx_tail_len = PN533_STD_FRAME_TAIL_LEN,
495
496 .rx_is_frame_valid = pn533_std_rx_frame_is_valid,
497 .rx_frame_size = pn533_std_rx_frame_size,
498 .rx_header_len = PN533_STD_FRAME_HEADER_LEN,
499 .rx_tail_len = PN533_STD_FRAME_TAIL_LEN,
500
501 .max_payload_len = PN533_STD_FRAME_MAX_PAYLOAD_LEN,
502 .get_cmd_code = pn533_std_get_cmd_code,
9e2d493e
WR
503};
504
505static bool pn533_rx_frame_is_cmd_response(struct pn533 *dev, void *frame)
c46ee386 506{
9e2d493e 507 return (dev->ops->get_cmd_code(frame) == PN533_CMD_RESPONSE(dev->cmd));
c46ee386
AAJ
508}
509
4849f85e
SO
510
511static void pn533_wq_cmd_complete(struct work_struct *work)
c46ee386 512{
5d50b364 513 struct pn533 *dev = container_of(work, struct pn533, cmd_complete_work);
c46ee386
AAJ
514 int rc;
515
0c33d262 516 rc = dev->cmd_complete(dev, dev->cmd_complete_arg, dev->wq_in_error);
c46ee386 517 if (rc != -EINPROGRESS)
5d50b364 518 queue_work(dev->wq, &dev->cmd_work);
c46ee386
AAJ
519}
520
521static void pn533_recv_response(struct urb *urb)
522{
523 struct pn533 *dev = urb->context;
9e2d493e 524 u8 *in_frame;
c46ee386 525
c46ee386
AAJ
526 switch (urb->status) {
527 case 0:
f8f99171 528 break; /* success */
c46ee386
AAJ
529 case -ECONNRESET:
530 case -ENOENT:
6ca55372 531 nfc_dev_dbg(&dev->interface->dev,
f8f99171
WR
532 "The urb has been canceled (status %d)",
533 urb->status);
4849f85e
SO
534 dev->wq_in_error = urb->status;
535 goto sched_wq;
f8f99171 536 case -ESHUTDOWN:
c46ee386 537 default:
6ca55372 538 nfc_dev_err(&dev->interface->dev,
f8f99171 539 "Urb failure (status %d)", urb->status);
4849f85e
SO
540 dev->wq_in_error = urb->status;
541 goto sched_wq;
c46ee386
AAJ
542 }
543
544 in_frame = dev->in_urb->transfer_buffer;
545
fcfafc76 546 nfc_dev_dbg(&dev->interface->dev, "Received a frame.");
e279f84f
SO
547 print_hex_dump_debug("PN533 RX: ", DUMP_PREFIX_NONE, 16, 1, in_frame,
548 dev->ops->rx_frame_size(in_frame), false);
99e591be 549
9e2d493e 550 if (!dev->ops->rx_is_frame_valid(in_frame)) {
c46ee386 551 nfc_dev_err(&dev->interface->dev, "Received an invalid frame");
4849f85e
SO
552 dev->wq_in_error = -EIO;
553 goto sched_wq;
c46ee386
AAJ
554 }
555
9e2d493e 556 if (!pn533_rx_frame_is_cmd_response(dev, in_frame)) {
6ca55372
WR
557 nfc_dev_err(&dev->interface->dev,
558 "It it not the response to the last command");
4849f85e
SO
559 dev->wq_in_error = -EIO;
560 goto sched_wq;
c46ee386
AAJ
561 }
562
4849f85e 563 dev->wq_in_error = 0;
c46ee386 564
4849f85e 565sched_wq:
5d50b364 566 queue_work(dev->wq, &dev->cmd_complete_work);
c46ee386
AAJ
567}
568
569static int pn533_submit_urb_for_response(struct pn533 *dev, gfp_t flags)
570{
571 dev->in_urb->complete = pn533_recv_response;
572
573 return usb_submit_urb(dev->in_urb, flags);
574}
575
576static void pn533_recv_ack(struct urb *urb)
577{
578 struct pn533 *dev = urb->context;
63123108 579 struct pn533_std_frame *in_frame;
c46ee386
AAJ
580 int rc;
581
582 switch (urb->status) {
583 case 0:
f8f99171 584 break; /* success */
c46ee386
AAJ
585 case -ECONNRESET:
586 case -ENOENT:
6ca55372 587 nfc_dev_dbg(&dev->interface->dev,
f8f99171
WR
588 "The urb has been stopped (status %d)",
589 urb->status);
4849f85e
SO
590 dev->wq_in_error = urb->status;
591 goto sched_wq;
f8f99171 592 case -ESHUTDOWN:
c46ee386 593 default:
6ca55372 594 nfc_dev_err(&dev->interface->dev,
f8f99171 595 "Urb failure (status %d)", urb->status);
4849f85e
SO
596 dev->wq_in_error = urb->status;
597 goto sched_wq;
c46ee386
AAJ
598 }
599
600 in_frame = dev->in_urb->transfer_buffer;
601
63123108 602 if (!pn533_std_rx_frame_is_ack(in_frame)) {
c46ee386 603 nfc_dev_err(&dev->interface->dev, "Received an invalid ack");
4849f85e
SO
604 dev->wq_in_error = -EIO;
605 goto sched_wq;
c46ee386
AAJ
606 }
607
c46ee386
AAJ
608 rc = pn533_submit_urb_for_response(dev, GFP_ATOMIC);
609 if (rc) {
6ca55372
WR
610 nfc_dev_err(&dev->interface->dev,
611 "usb_submit_urb failed with result %d", rc);
4849f85e
SO
612 dev->wq_in_error = rc;
613 goto sched_wq;
c46ee386
AAJ
614 }
615
616 return;
617
4849f85e 618sched_wq:
5d50b364 619 queue_work(dev->wq, &dev->cmd_complete_work);
c46ee386
AAJ
620}
621
622static int pn533_submit_urb_for_ack(struct pn533 *dev, gfp_t flags)
623{
624 dev->in_urb->complete = pn533_recv_ack;
625
626 return usb_submit_urb(dev->in_urb, flags);
627}
628
629static int pn533_send_ack(struct pn533 *dev, gfp_t flags)
630{
63123108 631 u8 ack[PN533_STD_FRAME_ACK_SIZE] = {0x00, 0x00, 0xff, 0x00, 0xff, 0x00};
5b5a4437 632 /* spec 7.1.1.3: Preamble, SoPC (2), ACK Code (2), Postamble */
c46ee386
AAJ
633 int rc;
634
635 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
636
5b5a4437
WR
637 dev->out_urb->transfer_buffer = ack;
638 dev->out_urb->transfer_buffer_length = sizeof(ack);
c46ee386
AAJ
639 rc = usb_submit_urb(dev->out_urb, flags);
640
641 return rc;
642}
643
e8f40531
WR
644static int __pn533_send_frame_async(struct pn533 *dev,
645 struct sk_buff *out,
646 struct sk_buff *in,
647 int in_len,
c46ee386 648 pn533_cmd_complete_t cmd_complete,
d94ea4f5 649 void *arg)
c46ee386
AAJ
650{
651 int rc;
652
9e2d493e 653 dev->cmd = dev->ops->get_cmd_code(out->data);
c46ee386
AAJ
654 dev->cmd_complete = cmd_complete;
655 dev->cmd_complete_arg = arg;
656
e8f40531
WR
657 dev->out_urb->transfer_buffer = out->data;
658 dev->out_urb->transfer_buffer_length = out->len;
c46ee386 659
e8f40531
WR
660 dev->in_urb->transfer_buffer = in->data;
661 dev->in_urb->transfer_buffer_length = in_len;
c46ee386 662
e279f84f
SO
663 print_hex_dump_debug("PN533 TX: ", DUMP_PREFIX_NONE, 16, 1,
664 out->data, out->len, false);
99e591be 665
d94ea4f5 666 rc = usb_submit_urb(dev->out_urb, GFP_KERNEL);
c46ee386
AAJ
667 if (rc)
668 return rc;
669
d94ea4f5 670 rc = pn533_submit_urb_for_ack(dev, GFP_KERNEL);
c46ee386
AAJ
671 if (rc)
672 goto error;
673
674 return 0;
675
676error:
677 usb_unlink_urb(dev->out_urb);
678 return rc;
679}
680
9e2d493e
WR
681static void pn533_build_cmd_frame(struct pn533 *dev, u8 cmd_code,
682 struct sk_buff *skb)
aada17ac 683{
aada17ac
WR
684 /* payload is already there, just update datalen */
685 int payload_len = skb->len;
9e2d493e 686 struct pn533_frame_ops *ops = dev->ops;
aada17ac 687
aada17ac 688
9e2d493e
WR
689 skb_push(skb, ops->tx_header_len);
690 skb_put(skb, ops->tx_tail_len);
aada17ac 691
9e2d493e
WR
692 ops->tx_frame_init(skb->data, cmd_code);
693 ops->tx_update_payload_len(skb->data, payload_len);
694 ops->tx_frame_finish(skb->data);
aada17ac
WR
695}
696
697struct pn533_send_async_complete_arg {
698 pn533_send_async_complete_t complete_cb;
699 void *complete_cb_context;
700 struct sk_buff *resp;
701 struct sk_buff *req;
702};
703
0c33d262 704static int pn533_send_async_complete(struct pn533 *dev, void *_arg, int status)
aada17ac
WR
705{
706 struct pn533_send_async_complete_arg *arg = _arg;
707
708 struct sk_buff *req = arg->req;
709 struct sk_buff *resp = arg->resp;
710
aada17ac
WR
711 int rc;
712
713 dev_kfree_skb(req);
714
0c33d262 715 if (status < 0) {
aada17ac 716 arg->complete_cb(dev, arg->complete_cb_context,
0c33d262 717 ERR_PTR(status));
aada17ac 718 dev_kfree_skb(resp);
0c33d262
WR
719 kfree(arg);
720 return status;
aada17ac
WR
721 }
722
9e2d493e
WR
723 skb_put(resp, dev->ops->rx_frame_size(resp->data));
724 skb_pull(resp, dev->ops->rx_header_len);
725 skb_trim(resp, resp->len - dev->ops->rx_tail_len);
aada17ac
WR
726
727 rc = arg->complete_cb(dev, arg->complete_cb_context, resp);
728
aada17ac
WR
729 kfree(arg);
730 return rc;
731}
732
733static int __pn533_send_async(struct pn533 *dev, u8 cmd_code,
734 struct sk_buff *req, struct sk_buff *resp,
735 int resp_len,
736 pn533_send_async_complete_t complete_cb,
737 void *complete_cb_context)
738{
739 struct pn533_cmd *cmd;
740 struct pn533_send_async_complete_arg *arg;
741 int rc = 0;
742
fcfafc76 743 nfc_dev_dbg(&dev->interface->dev, "Sending command 0x%x", cmd_code);
aada17ac 744
858ce022 745 arg = kzalloc(sizeof(*arg), GFP_KERNEL);
aada17ac
WR
746 if (!arg)
747 return -ENOMEM;
748
749 arg->complete_cb = complete_cb;
750 arg->complete_cb_context = complete_cb_context;
751 arg->resp = resp;
752 arg->req = req;
753
9e2d493e 754 pn533_build_cmd_frame(dev, cmd_code, req);
aada17ac
WR
755
756 mutex_lock(&dev->cmd_lock);
757
758 if (!dev->cmd_pending) {
e8f40531
WR
759 rc = __pn533_send_frame_async(dev, req, resp, resp_len,
760 pn533_send_async_complete, arg);
aada17ac
WR
761 if (rc)
762 goto error;
763
764 dev->cmd_pending = 1;
765 goto unlock;
766 }
767
fcfafc76
WR
768 nfc_dev_dbg(&dev->interface->dev, "%s Queueing command 0x%x", __func__,
769 cmd_code);
aada17ac
WR
770
771 cmd = kzalloc(sizeof(struct pn533_cmd), GFP_KERNEL);
772 if (!cmd) {
773 rc = -ENOMEM;
774 goto error;
775 }
776
777 INIT_LIST_HEAD(&cmd->queue);
778 cmd->cmd_code = cmd_code;
779 cmd->req = req;
780 cmd->resp = resp;
9e2d493e 781 cmd->resp_len = resp_len;
aada17ac
WR
782 cmd->arg = arg;
783
784 list_add_tail(&cmd->queue, &dev->cmd_queue);
785
786 goto unlock;
787
788error:
789 kfree(arg);
790unlock:
791 mutex_unlock(&dev->cmd_lock);
792 return rc;
15461aeb
WR
793}
794
795static int pn533_send_data_async(struct pn533 *dev, u8 cmd_code,
796 struct sk_buff *req,
797 pn533_send_async_complete_t complete_cb,
798 void *complete_cb_context)
799{
800 struct sk_buff *resp;
801 int rc;
9e2d493e
WR
802 int resp_len = dev->ops->rx_header_len +
803 dev->ops->max_payload_len +
804 dev->ops->rx_tail_len;
15461aeb 805
15461aeb
WR
806 resp = nfc_alloc_recv_skb(resp_len, GFP_KERNEL);
807 if (!resp)
808 return -ENOMEM;
809
810 rc = __pn533_send_async(dev, cmd_code, req, resp, resp_len, complete_cb,
811 complete_cb_context);
812 if (rc)
813 dev_kfree_skb(resp);
814
815 return rc;
aada17ac
WR
816}
817
818static int pn533_send_cmd_async(struct pn533 *dev, u8 cmd_code,
819 struct sk_buff *req,
820 pn533_send_async_complete_t complete_cb,
821 void *complete_cb_context)
822{
823 struct sk_buff *resp;
824 int rc;
9e2d493e
WR
825 int resp_len = dev->ops->rx_header_len +
826 dev->ops->max_payload_len +
827 dev->ops->rx_tail_len;
aada17ac 828
9e2d493e 829 resp = alloc_skb(resp_len, GFP_KERNEL);
aada17ac
WR
830 if (!resp)
831 return -ENOMEM;
832
9e2d493e
WR
833 rc = __pn533_send_async(dev, cmd_code, req, resp, resp_len, complete_cb,
834 complete_cb_context);
aada17ac
WR
835 if (rc)
836 dev_kfree_skb(resp);
837
838 return rc;
839}
840
b1e666f5
WR
841/*
842 * pn533_send_cmd_direct_async
843 *
844 * The function sends a piority cmd directly to the chip omiting the cmd
845 * queue. It's intended to be used by chaining mechanism of received responses
846 * where the host has to request every single chunk of data before scheduling
847 * next cmd from the queue.
848 */
849static int pn533_send_cmd_direct_async(struct pn533 *dev, u8 cmd_code,
850 struct sk_buff *req,
851 pn533_send_async_complete_t complete_cb,
852 void *complete_cb_context)
853{
854 struct pn533_send_async_complete_arg *arg;
855 struct sk_buff *resp;
856 int rc;
9e2d493e
WR
857 int resp_len = dev->ops->rx_header_len +
858 dev->ops->max_payload_len +
859 dev->ops->rx_tail_len;
b1e666f5 860
b1e666f5
WR
861 resp = alloc_skb(resp_len, GFP_KERNEL);
862 if (!resp)
863 return -ENOMEM;
864
858ce022 865 arg = kzalloc(sizeof(*arg), GFP_KERNEL);
b1e666f5
WR
866 if (!arg) {
867 dev_kfree_skb(resp);
868 return -ENOMEM;
869 }
870
871 arg->complete_cb = complete_cb;
872 arg->complete_cb_context = complete_cb_context;
873 arg->resp = resp;
874 arg->req = req;
875
9e2d493e 876 pn533_build_cmd_frame(dev, cmd_code, req);
b1e666f5 877
e8f40531
WR
878 rc = __pn533_send_frame_async(dev, req, resp, resp_len,
879 pn533_send_async_complete, arg);
b1e666f5
WR
880 if (rc < 0) {
881 dev_kfree_skb(resp);
882 kfree(arg);
883 }
884
885 return rc;
886}
887
5d50b364
SO
888static void pn533_wq_cmd(struct work_struct *work)
889{
890 struct pn533 *dev = container_of(work, struct pn533, cmd_work);
891 struct pn533_cmd *cmd;
892
893 mutex_lock(&dev->cmd_lock);
894
895 if (list_empty(&dev->cmd_queue)) {
896 dev->cmd_pending = 0;
897 mutex_unlock(&dev->cmd_lock);
898 return;
899 }
900
901 cmd = list_first_entry(&dev->cmd_queue, struct pn533_cmd, queue);
902
60ad07ab
SJ
903 list_del(&cmd->queue);
904
5d50b364
SO
905 mutex_unlock(&dev->cmd_lock);
906
9e2d493e
WR
907 __pn533_send_frame_async(dev, cmd->req, cmd->resp, cmd->resp_len,
908 pn533_send_async_complete, cmd->arg);
5d50b364 909
5d50b364
SO
910 kfree(cmd);
911}
912
c46ee386 913struct pn533_sync_cmd_response {
94c5c156 914 struct sk_buff *resp;
c46ee386
AAJ
915 struct completion done;
916};
917
94c5c156
WR
918static int pn533_send_sync_complete(struct pn533 *dev, void *_arg,
919 struct sk_buff *resp)
920{
921 struct pn533_sync_cmd_response *arg = _arg;
922
94c5c156
WR
923 arg->resp = resp;
924 complete(&arg->done);
925
926 return 0;
927}
928
929/* pn533_send_cmd_sync
930 *
931 * Please note the req parameter is freed inside the function to
932 * limit a number of return value interpretations by the caller.
933 *
934 * 1. negative in case of error during TX path -> req should be freed
935 *
936 * 2. negative in case of error during RX path -> req should not be freed
937 * as it's been already freed at the begining of RX path by
938 * async_complete_cb.
939 *
940 * 3. valid pointer in case of succesfult RX path
941 *
942 * A caller has to check a return value with IS_ERR macro. If the test pass,
943 * the returned pointer is valid.
944 *
945 * */
946static struct sk_buff *pn533_send_cmd_sync(struct pn533 *dev, u8 cmd_code,
947 struct sk_buff *req)
948{
949 int rc;
950 struct pn533_sync_cmd_response arg;
951
94c5c156
WR
952 init_completion(&arg.done);
953
954 rc = pn533_send_cmd_async(dev, cmd_code, req,
955 pn533_send_sync_complete, &arg);
956 if (rc) {
957 dev_kfree_skb(req);
958 return ERR_PTR(rc);
959 }
960
961 wait_for_completion(&arg.done);
962
963 return arg.resp;
964}
965
c46ee386
AAJ
966static void pn533_send_complete(struct urb *urb)
967{
968 struct pn533 *dev = urb->context;
969
c46ee386
AAJ
970 switch (urb->status) {
971 case 0:
f8f99171 972 break; /* success */
c46ee386
AAJ
973 case -ECONNRESET:
974 case -ENOENT:
6ca55372 975 nfc_dev_dbg(&dev->interface->dev,
f8f99171
WR
976 "The urb has been stopped (status %d)",
977 urb->status);
c46ee386 978 break;
f8f99171 979 case -ESHUTDOWN:
c46ee386 980 default:
f8f99171
WR
981 nfc_dev_err(&dev->interface->dev,
982 "Urb failure (status %d)", urb->status);
c46ee386
AAJ
983 }
984}
985
9e2d493e 986static struct sk_buff *pn533_alloc_skb(struct pn533 *dev, unsigned int size)
d22b2db6
WR
987{
988 struct sk_buff *skb;
989
9e2d493e 990 skb = alloc_skb(dev->ops->tx_header_len +
d22b2db6 991 size +
9e2d493e 992 dev->ops->tx_tail_len, GFP_KERNEL);
d22b2db6
WR
993
994 if (skb)
9e2d493e 995 skb_reserve(skb, dev->ops->tx_header_len);
d22b2db6
WR
996
997 return skb;
998}
999
c46ee386
AAJ
1000struct pn533_target_type_a {
1001 __be16 sens_res;
1002 u8 sel_res;
1003 u8 nfcid_len;
1004 u8 nfcid_data[];
1005} __packed;
1006
1007
1008#define PN533_TYPE_A_SENS_RES_NFCID1(x) ((u8)((be16_to_cpu(x) & 0x00C0) >> 6))
1009#define PN533_TYPE_A_SENS_RES_SSD(x) ((u8)((be16_to_cpu(x) & 0x001F) >> 0))
1010#define PN533_TYPE_A_SENS_RES_PLATCONF(x) ((u8)((be16_to_cpu(x) & 0x0F00) >> 8))
1011
1012#define PN533_TYPE_A_SENS_RES_SSD_JEWEL 0x00
1013#define PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL 0x0C
1014
1015#define PN533_TYPE_A_SEL_PROT(x) (((x) & 0x60) >> 5)
1016#define PN533_TYPE_A_SEL_CASCADE(x) (((x) & 0x04) >> 2)
1017
1018#define PN533_TYPE_A_SEL_PROT_MIFARE 0
1019#define PN533_TYPE_A_SEL_PROT_ISO14443 1
1020#define PN533_TYPE_A_SEL_PROT_DEP 2
1021#define PN533_TYPE_A_SEL_PROT_ISO14443_DEP 3
1022
1023static bool pn533_target_type_a_is_valid(struct pn533_target_type_a *type_a,
1024 int target_data_len)
1025{
1026 u8 ssd;
1027 u8 platconf;
1028
1029 if (target_data_len < sizeof(struct pn533_target_type_a))
1030 return false;
1031
1032 /* The lenght check of nfcid[] and ats[] are not being performed because
1033 the values are not being used */
1034
1035 /* Requirement 4.6.3.3 from NFC Forum Digital Spec */
1036 ssd = PN533_TYPE_A_SENS_RES_SSD(type_a->sens_res);
1037 platconf = PN533_TYPE_A_SENS_RES_PLATCONF(type_a->sens_res);
1038
1039 if ((ssd == PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
5d467742
WR
1040 platconf != PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL) ||
1041 (ssd != PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
1042 platconf == PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL))
c46ee386
AAJ
1043 return false;
1044
1045 /* Requirements 4.8.2.1, 4.8.2.3, 4.8.2.5 and 4.8.2.7 from NFC Forum */
1046 if (PN533_TYPE_A_SEL_CASCADE(type_a->sel_res) != 0)
1047 return false;
1048
1049 return true;
1050}
1051
1052static int pn533_target_found_type_a(struct nfc_target *nfc_tgt, u8 *tgt_data,
1053 int tgt_data_len)
1054{
1055 struct pn533_target_type_a *tgt_type_a;
1056
37cf4fc6 1057 tgt_type_a = (struct pn533_target_type_a *)tgt_data;
c46ee386
AAJ
1058
1059 if (!pn533_target_type_a_is_valid(tgt_type_a, tgt_data_len))
1060 return -EPROTO;
1061
1062 switch (PN533_TYPE_A_SEL_PROT(tgt_type_a->sel_res)) {
1063 case PN533_TYPE_A_SEL_PROT_MIFARE:
1064 nfc_tgt->supported_protocols = NFC_PROTO_MIFARE_MASK;
1065 break;
1066 case PN533_TYPE_A_SEL_PROT_ISO14443:
1067 nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_MASK;
1068 break;
1069 case PN533_TYPE_A_SEL_PROT_DEP:
1070 nfc_tgt->supported_protocols = NFC_PROTO_NFC_DEP_MASK;
1071 break;
1072 case PN533_TYPE_A_SEL_PROT_ISO14443_DEP:
1073 nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_MASK |
1074 NFC_PROTO_NFC_DEP_MASK;
1075 break;
1076 }
1077
1078 nfc_tgt->sens_res = be16_to_cpu(tgt_type_a->sens_res);
1079 nfc_tgt->sel_res = tgt_type_a->sel_res;
c3b1e1e8
SO
1080 nfc_tgt->nfcid1_len = tgt_type_a->nfcid_len;
1081 memcpy(nfc_tgt->nfcid1, tgt_type_a->nfcid_data, nfc_tgt->nfcid1_len);
c46ee386
AAJ
1082
1083 return 0;
1084}
1085
1086struct pn533_target_felica {
1087 u8 pol_res;
1088 u8 opcode;
1089 u8 nfcid2[8];
1090 u8 pad[8];
1091 /* optional */
1092 u8 syst_code[];
1093} __packed;
1094
1095#define PN533_FELICA_SENSF_NFCID2_DEP_B1 0x01
1096#define PN533_FELICA_SENSF_NFCID2_DEP_B2 0xFE
1097
1098static bool pn533_target_felica_is_valid(struct pn533_target_felica *felica,
1099 int target_data_len)
1100{
1101 if (target_data_len < sizeof(struct pn533_target_felica))
1102 return false;
1103
1104 if (felica->opcode != PN533_FELICA_OPC_SENSF_RES)
1105 return false;
1106
1107 return true;
1108}
1109
1110static int pn533_target_found_felica(struct nfc_target *nfc_tgt, u8 *tgt_data,
1111 int tgt_data_len)
1112{
1113 struct pn533_target_felica *tgt_felica;
1114
37cf4fc6 1115 tgt_felica = (struct pn533_target_felica *)tgt_data;
c46ee386
AAJ
1116
1117 if (!pn533_target_felica_is_valid(tgt_felica, tgt_data_len))
1118 return -EPROTO;
1119
5d467742
WR
1120 if ((tgt_felica->nfcid2[0] == PN533_FELICA_SENSF_NFCID2_DEP_B1) &&
1121 (tgt_felica->nfcid2[1] == PN533_FELICA_SENSF_NFCID2_DEP_B2))
c46ee386
AAJ
1122 nfc_tgt->supported_protocols = NFC_PROTO_NFC_DEP_MASK;
1123 else
1124 nfc_tgt->supported_protocols = NFC_PROTO_FELICA_MASK;
1125
7975754f
SO
1126 memcpy(nfc_tgt->sensf_res, &tgt_felica->opcode, 9);
1127 nfc_tgt->sensf_res_len = 9;
1128
c46ee386
AAJ
1129 return 0;
1130}
1131
1132struct pn533_target_jewel {
1133 __be16 sens_res;
1134 u8 jewelid[4];
1135} __packed;
1136
1137static bool pn533_target_jewel_is_valid(struct pn533_target_jewel *jewel,
1138 int target_data_len)
1139{
1140 u8 ssd;
1141 u8 platconf;
1142
1143 if (target_data_len < sizeof(struct pn533_target_jewel))
1144 return false;
1145
1146 /* Requirement 4.6.3.3 from NFC Forum Digital Spec */
1147 ssd = PN533_TYPE_A_SENS_RES_SSD(jewel->sens_res);
1148 platconf = PN533_TYPE_A_SENS_RES_PLATCONF(jewel->sens_res);
1149
1150 if ((ssd == PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
5d467742
WR
1151 platconf != PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL) ||
1152 (ssd != PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
1153 platconf == PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL))
c46ee386
AAJ
1154 return false;
1155
1156 return true;
1157}
1158
1159static int pn533_target_found_jewel(struct nfc_target *nfc_tgt, u8 *tgt_data,
1160 int tgt_data_len)
1161{
1162 struct pn533_target_jewel *tgt_jewel;
1163
37cf4fc6 1164 tgt_jewel = (struct pn533_target_jewel *)tgt_data;
c46ee386
AAJ
1165
1166 if (!pn533_target_jewel_is_valid(tgt_jewel, tgt_data_len))
1167 return -EPROTO;
1168
1169 nfc_tgt->supported_protocols = NFC_PROTO_JEWEL_MASK;
1170 nfc_tgt->sens_res = be16_to_cpu(tgt_jewel->sens_res);
d8dc1072
SO
1171 nfc_tgt->nfcid1_len = 4;
1172 memcpy(nfc_tgt->nfcid1, tgt_jewel->jewelid, nfc_tgt->nfcid1_len);
c46ee386
AAJ
1173
1174 return 0;
1175}
1176
1177struct pn533_type_b_prot_info {
1178 u8 bitrate;
1179 u8 fsci_type;
1180 u8 fwi_adc_fo;
1181} __packed;
1182
1183#define PN533_TYPE_B_PROT_FCSI(x) (((x) & 0xF0) >> 4)
1184#define PN533_TYPE_B_PROT_TYPE(x) (((x) & 0x0F) >> 0)
1185#define PN533_TYPE_B_PROT_TYPE_RFU_MASK 0x8
1186
1187struct pn533_type_b_sens_res {
1188 u8 opcode;
1189 u8 nfcid[4];
1190 u8 appdata[4];
1191 struct pn533_type_b_prot_info prot_info;
1192} __packed;
1193
1194#define PN533_TYPE_B_OPC_SENSB_RES 0x50
1195
1196struct pn533_target_type_b {
1197 struct pn533_type_b_sens_res sensb_res;
1198 u8 attrib_res_len;
1199 u8 attrib_res[];
1200} __packed;
1201
1202static bool pn533_target_type_b_is_valid(struct pn533_target_type_b *type_b,
1203 int target_data_len)
1204{
1205 if (target_data_len < sizeof(struct pn533_target_type_b))
1206 return false;
1207
1208 if (type_b->sensb_res.opcode != PN533_TYPE_B_OPC_SENSB_RES)
1209 return false;
1210
1211 if (PN533_TYPE_B_PROT_TYPE(type_b->sensb_res.prot_info.fsci_type) &
1212 PN533_TYPE_B_PROT_TYPE_RFU_MASK)
1213 return false;
1214
1215 return true;
1216}
1217
1218static int pn533_target_found_type_b(struct nfc_target *nfc_tgt, u8 *tgt_data,
1219 int tgt_data_len)
1220{
1221 struct pn533_target_type_b *tgt_type_b;
1222
37cf4fc6 1223 tgt_type_b = (struct pn533_target_type_b *)tgt_data;
c46ee386
AAJ
1224
1225 if (!pn533_target_type_b_is_valid(tgt_type_b, tgt_data_len))
1226 return -EPROTO;
1227
01d719a2 1228 nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_B_MASK;
c46ee386
AAJ
1229
1230 return 0;
1231}
1232
b5193e5d
WR
1233static int pn533_target_found(struct pn533 *dev, u8 tg, u8 *tgdata,
1234 int tgdata_len)
c46ee386 1235{
c46ee386
AAJ
1236 struct nfc_target nfc_tgt;
1237 int rc;
1238
1239 nfc_dev_dbg(&dev->interface->dev, "%s - modulation=%d", __func__,
b5193e5d 1240 dev->poll_mod_curr);
c46ee386 1241
b5193e5d 1242 if (tg != 1)
c46ee386
AAJ
1243 return -EPROTO;
1244
98b3ac1b
SO
1245 memset(&nfc_tgt, 0, sizeof(struct nfc_target));
1246
c46ee386
AAJ
1247 switch (dev->poll_mod_curr) {
1248 case PN533_POLL_MOD_106KBPS_A:
b5193e5d 1249 rc = pn533_target_found_type_a(&nfc_tgt, tgdata, tgdata_len);
c46ee386
AAJ
1250 break;
1251 case PN533_POLL_MOD_212KBPS_FELICA:
1252 case PN533_POLL_MOD_424KBPS_FELICA:
b5193e5d 1253 rc = pn533_target_found_felica(&nfc_tgt, tgdata, tgdata_len);
c46ee386
AAJ
1254 break;
1255 case PN533_POLL_MOD_106KBPS_JEWEL:
b5193e5d 1256 rc = pn533_target_found_jewel(&nfc_tgt, tgdata, tgdata_len);
c46ee386
AAJ
1257 break;
1258 case PN533_POLL_MOD_847KBPS_B:
b5193e5d 1259 rc = pn533_target_found_type_b(&nfc_tgt, tgdata, tgdata_len);
c46ee386
AAJ
1260 break;
1261 default:
b5193e5d
WR
1262 nfc_dev_err(&dev->interface->dev,
1263 "Unknown current poll modulation");
c46ee386
AAJ
1264 return -EPROTO;
1265 }
1266
1267 if (rc)
1268 return rc;
1269
1270 if (!(nfc_tgt.supported_protocols & dev->poll_protocols)) {
b5193e5d
WR
1271 nfc_dev_dbg(&dev->interface->dev,
1272 "The Tg found doesn't have the desired protocol");
c46ee386
AAJ
1273 return -EAGAIN;
1274 }
1275
b5193e5d
WR
1276 nfc_dev_dbg(&dev->interface->dev,
1277 "Target found - supported protocols: 0x%x",
1278 nfc_tgt.supported_protocols);
c46ee386
AAJ
1279
1280 dev->tgt_available_prots = nfc_tgt.supported_protocols;
1281
1282 nfc_targets_found(dev->nfc_dev, &nfc_tgt, 1);
1283
1284 return 0;
1285}
1286
6fbbdc16
SO
1287static inline void pn533_poll_next_mod(struct pn533 *dev)
1288{
1289 dev->poll_mod_curr = (dev->poll_mod_curr + 1) % dev->poll_mod_count;
1290}
1291
c46ee386
AAJ
1292static void pn533_poll_reset_mod_list(struct pn533 *dev)
1293{
1294 dev->poll_mod_count = 0;
1295}
1296
1297static void pn533_poll_add_mod(struct pn533 *dev, u8 mod_index)
1298{
1299 dev->poll_mod_active[dev->poll_mod_count] =
37cf4fc6 1300 (struct pn533_poll_modulations *)&poll_mod[mod_index];
c46ee386
AAJ
1301 dev->poll_mod_count++;
1302}
1303
6fbbdc16
SO
1304static void pn533_poll_create_mod_list(struct pn533 *dev,
1305 u32 im_protocols, u32 tm_protocols)
c46ee386
AAJ
1306{
1307 pn533_poll_reset_mod_list(dev);
1308
b08e8603
WR
1309 if ((im_protocols & NFC_PROTO_MIFARE_MASK) ||
1310 (im_protocols & NFC_PROTO_ISO14443_MASK) ||
1311 (im_protocols & NFC_PROTO_NFC_DEP_MASK))
c46ee386
AAJ
1312 pn533_poll_add_mod(dev, PN533_POLL_MOD_106KBPS_A);
1313
b08e8603
WR
1314 if (im_protocols & NFC_PROTO_FELICA_MASK ||
1315 im_protocols & NFC_PROTO_NFC_DEP_MASK) {
c46ee386
AAJ
1316 pn533_poll_add_mod(dev, PN533_POLL_MOD_212KBPS_FELICA);
1317 pn533_poll_add_mod(dev, PN533_POLL_MOD_424KBPS_FELICA);
1318 }
1319
6fbbdc16 1320 if (im_protocols & NFC_PROTO_JEWEL_MASK)
c46ee386
AAJ
1321 pn533_poll_add_mod(dev, PN533_POLL_MOD_106KBPS_JEWEL);
1322
01d719a2 1323 if (im_protocols & NFC_PROTO_ISO14443_B_MASK)
c46ee386 1324 pn533_poll_add_mod(dev, PN533_POLL_MOD_847KBPS_B);
c46ee386 1325
6fbbdc16
SO
1326 if (tm_protocols)
1327 pn533_poll_add_mod(dev, PN533_LISTEN_MOD);
c46ee386
AAJ
1328}
1329
b5193e5d 1330static int pn533_start_poll_complete(struct pn533 *dev, struct sk_buff *resp)
c46ee386 1331{
b5193e5d
WR
1332 u8 nbtg, tg, *tgdata;
1333 int rc, tgdata_len;
c46ee386
AAJ
1334
1335 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
1336
b5193e5d
WR
1337 nbtg = resp->data[0];
1338 tg = resp->data[1];
1339 tgdata = &resp->data[2];
1340 tgdata_len = resp->len - 2; /* nbtg + tg */
1341
1342 if (nbtg) {
1343 rc = pn533_target_found(dev, tg, tgdata, tgdata_len);
c46ee386
AAJ
1344
1345 /* We must stop the poll after a valid target found */
6fbbdc16
SO
1346 if (rc == 0) {
1347 pn533_poll_reset_mod_list(dev);
1348 return 0;
1349 }
c46ee386
AAJ
1350 }
1351
6fbbdc16 1352 return -EAGAIN;
c46ee386
AAJ
1353}
1354
9e2d493e 1355static struct sk_buff *pn533_alloc_poll_tg_frame(struct pn533 *dev)
ad3823ce 1356{
b5193e5d
WR
1357 struct sk_buff *skb;
1358 u8 *felica, *nfcid3, *gb;
1359
9e2d493e
WR
1360 u8 *gbytes = dev->gb;
1361 size_t gbytes_len = dev->gb_len;
1362
51d9e803
SO
1363 u8 felica_params[18] = {0x1, 0xfe, /* DEP */
1364 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, /* random */
1365 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0,
1366 0xff, 0xff}; /* System code */
b5193e5d 1367
51d9e803
SO
1368 u8 mifare_params[6] = {0x1, 0x1, /* SENS_RES */
1369 0x0, 0x0, 0x0,
1370 0x40}; /* SEL_RES for DEP */
ad3823ce 1371
b5193e5d
WR
1372 unsigned int skb_len = 36 + /* mode (1), mifare (6),
1373 felica (18), nfcid3 (10), gb_len (1) */
1374 gbytes_len +
1375 1; /* len Tk*/
ad3823ce 1376
9e2d493e 1377 skb = pn533_alloc_skb(dev, skb_len);
b5193e5d
WR
1378 if (!skb)
1379 return NULL;
ad3823ce
SO
1380
1381 /* DEP support only */
52f2eaee 1382 *skb_put(skb, 1) = PN533_INIT_TARGET_DEP;
b5193e5d
WR
1383
1384 /* MIFARE params */
1385 memcpy(skb_put(skb, 6), mifare_params, 6);
51d9e803
SO
1386
1387 /* Felica params */
b5193e5d
WR
1388 felica = skb_put(skb, 18);
1389 memcpy(felica, felica_params, 18);
1390 get_random_bytes(felica + 2, 6);
51d9e803
SO
1391
1392 /* NFCID3 */
b5193e5d
WR
1393 nfcid3 = skb_put(skb, 10);
1394 memset(nfcid3, 0, 10);
1395 memcpy(nfcid3, felica, 8);
51d9e803
SO
1396
1397 /* General bytes */
b5193e5d 1398 *skb_put(skb, 1) = gbytes_len;
51d9e803 1399
b5193e5d
WR
1400 gb = skb_put(skb, gbytes_len);
1401 memcpy(gb, gbytes, gbytes_len);
ad3823ce 1402
b5193e5d
WR
1403 /* Len Tk */
1404 *skb_put(skb, 1) = 0;
51d9e803 1405
b5193e5d 1406 return skb;
ad3823ce
SO
1407}
1408
b1bb290a 1409#define PN533_CMD_DATAEXCH_HEAD_LEN 1
103b34cf
SO
1410#define PN533_CMD_DATAEXCH_DATA_MAXLEN 262
1411static int pn533_tm_get_data_complete(struct pn533 *dev, void *arg,
e4878823 1412 struct sk_buff *resp)
103b34cf 1413{
e4878823 1414 u8 status;
103b34cf
SO
1415
1416 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
1417
e4878823
WR
1418 if (IS_ERR(resp))
1419 return PTR_ERR(resp);
103b34cf 1420
e4878823
WR
1421 status = resp->data[0];
1422 skb_pull(resp, sizeof(status));
103b34cf 1423
e4878823 1424 if (status != 0) {
103b34cf 1425 nfc_tm_deactivated(dev->nfc_dev);
51ad304c 1426 dev->tgt_mode = 0;
e4878823 1427 dev_kfree_skb(resp);
103b34cf
SO
1428 return 0;
1429 }
1430
e4878823 1431 return nfc_tm_data_received(dev->nfc_dev, resp);
103b34cf
SO
1432}
1433
1434static void pn533_wq_tg_get_data(struct work_struct *work)
1435{
1436 struct pn533 *dev = container_of(work, struct pn533, tg_work);
103b34cf 1437
e4878823
WR
1438 struct sk_buff *skb;
1439 int rc;
103b34cf 1440
e4878823 1441 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
103b34cf 1442
9e2d493e 1443 skb = pn533_alloc_skb(dev, 0);
e4878823 1444 if (!skb)
103b34cf
SO
1445 return;
1446
e4878823
WR
1447 rc = pn533_send_data_async(dev, PN533_CMD_TG_GET_DATA, skb,
1448 pn533_tm_get_data_complete, NULL);
103b34cf 1449
e4878823
WR
1450 if (rc < 0)
1451 dev_kfree_skb(skb);
103b34cf
SO
1452
1453 return;
1454}
1455
fc40a8c1 1456#define ATR_REQ_GB_OFFSET 17
b5193e5d 1457static int pn533_init_target_complete(struct pn533 *dev, struct sk_buff *resp)
fe7c5800 1458{
b5193e5d 1459 u8 mode, *cmd, comm_mode = NFC_COMM_PASSIVE, *gb;
fc40a8c1 1460 size_t gb_len;
103b34cf 1461 int rc;
ad3823ce
SO
1462
1463 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
1464
b5193e5d 1465 if (resp->len < ATR_REQ_GB_OFFSET + 1)
fc40a8c1
SO
1466 return -EINVAL;
1467
b5193e5d
WR
1468 mode = resp->data[0];
1469 cmd = &resp->data[1];
ad3823ce 1470
b5193e5d
WR
1471 nfc_dev_dbg(&dev->interface->dev, "Target mode 0x%x len %d\n",
1472 mode, resp->len);
ad3823ce 1473
b5193e5d
WR
1474 if ((mode & PN533_INIT_TARGET_RESP_FRAME_MASK) ==
1475 PN533_INIT_TARGET_RESP_ACTIVE)
fc40a8c1
SO
1476 comm_mode = NFC_COMM_ACTIVE;
1477
b5193e5d 1478 if ((mode & PN533_INIT_TARGET_RESP_DEP) == 0) /* Only DEP supported */
fc40a8c1
SO
1479 return -EOPNOTSUPP;
1480
b5193e5d
WR
1481 gb = cmd + ATR_REQ_GB_OFFSET;
1482 gb_len = resp->len - (ATR_REQ_GB_OFFSET + 1);
fc40a8c1 1483
103b34cf
SO
1484 rc = nfc_tm_activated(dev->nfc_dev, NFC_PROTO_NFC_DEP_MASK,
1485 comm_mode, gb, gb_len);
1486 if (rc < 0) {
1487 nfc_dev_err(&dev->interface->dev,
1488 "Error when signaling target activation");
1489 return rc;
1490 }
1491
51ad304c 1492 dev->tgt_mode = 1;
103b34cf
SO
1493 queue_work(dev->wq, &dev->tg_work);
1494
1495 return 0;
fe7c5800
SO
1496}
1497
6fbbdc16 1498static void pn533_listen_mode_timer(unsigned long data)
ad3823ce 1499{
37cf4fc6 1500 struct pn533 *dev = (struct pn533 *)data;
6fbbdc16
SO
1501
1502 nfc_dev_dbg(&dev->interface->dev, "Listen mode timeout");
1503
1504 /* An ack will cancel the last issued command (poll) */
1505 pn533_send_ack(dev, GFP_ATOMIC);
1506
1507 dev->cancel_listen = 1;
1508
6fbbdc16
SO
1509 pn533_poll_next_mod(dev);
1510
1511 queue_work(dev->wq, &dev->poll_work);
1512}
1513
1514static int pn533_poll_complete(struct pn533 *dev, void *arg,
b5193e5d 1515 struct sk_buff *resp)
6fbbdc16
SO
1516{
1517 struct pn533_poll_modulations *cur_mod;
ad3823ce
SO
1518 int rc;
1519
6fbbdc16 1520 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
ad3823ce 1521
b5193e5d
WR
1522 if (IS_ERR(resp)) {
1523 rc = PTR_ERR(resp);
1524
1525 nfc_dev_err(&dev->interface->dev, "%s Poll complete error %d",
1526 __func__, rc);
1527
1528 if (rc == -ENOENT) {
1529 if (dev->poll_mod_count != 0)
1530 return rc;
1531 else
1532 goto stop_poll;
1533 } else if (rc < 0) {
1534 nfc_dev_err(&dev->interface->dev,
1535 "Error %d when running poll", rc);
1536 goto stop_poll;
1537 }
6fbbdc16 1538 }
ad3823ce 1539
6fbbdc16
SO
1540 cur_mod = dev->poll_mod_active[dev->poll_mod_curr];
1541
b5193e5d 1542 if (cur_mod->len == 0) { /* Target mode */
6fbbdc16 1543 del_timer(&dev->listen_timer);
b5193e5d
WR
1544 rc = pn533_init_target_complete(dev, resp);
1545 goto done;
6fbbdc16
SO
1546 }
1547
b5193e5d
WR
1548 /* Initiator mode */
1549 rc = pn533_start_poll_complete(dev, resp);
1550 if (!rc)
1551 goto done;
6fbbdc16 1552
95cb9e10
WR
1553 if (!dev->poll_mod_count) {
1554 nfc_dev_dbg(&dev->interface->dev, "Polling has been stoped.");
1555 goto done;
1556 }
1557
b5193e5d 1558 pn533_poll_next_mod(dev);
6fbbdc16
SO
1559 queue_work(dev->wq, &dev->poll_work);
1560
b5193e5d
WR
1561done:
1562 dev_kfree_skb(resp);
1563 return rc;
6fbbdc16
SO
1564
1565stop_poll:
b5193e5d
WR
1566 nfc_dev_err(&dev->interface->dev, "Polling operation has been stopped");
1567
6fbbdc16
SO
1568 pn533_poll_reset_mod_list(dev);
1569 dev->poll_protocols = 0;
b5193e5d 1570 return rc;
ad3823ce
SO
1571}
1572
9e2d493e
WR
1573static struct sk_buff *pn533_alloc_poll_in_frame(struct pn533 *dev,
1574 struct pn533_poll_modulations *mod)
c46ee386 1575{
b5193e5d 1576 struct sk_buff *skb;
c46ee386 1577
9e2d493e 1578 skb = pn533_alloc_skb(dev, mod->len);
b5193e5d
WR
1579 if (!skb)
1580 return NULL;
c46ee386 1581
b5193e5d 1582 memcpy(skb_put(skb, mod->len), &mod->data, mod->len);
c46ee386 1583
b5193e5d 1584 return skb;
6fbbdc16 1585}
c46ee386 1586
6fbbdc16
SO
1587static int pn533_send_poll_frame(struct pn533 *dev)
1588{
b5193e5d
WR
1589 struct pn533_poll_modulations *mod;
1590 struct sk_buff *skb;
6fbbdc16 1591 int rc;
b5193e5d 1592 u8 cmd_code;
c46ee386 1593
b5193e5d 1594 mod = dev->poll_mod_active[dev->poll_mod_curr];
c46ee386 1595
b5193e5d
WR
1596 nfc_dev_dbg(&dev->interface->dev, "%s mod len %d\n",
1597 __func__, mod->len);
c46ee386 1598
b5193e5d
WR
1599 if (mod->len == 0) { /* Listen mode */
1600 cmd_code = PN533_CMD_TG_INIT_AS_TARGET;
9e2d493e 1601 skb = pn533_alloc_poll_tg_frame(dev);
b5193e5d
WR
1602 } else { /* Polling mode */
1603 cmd_code = PN533_CMD_IN_LIST_PASSIVE_TARGET;
9e2d493e 1604 skb = pn533_alloc_poll_in_frame(dev, mod);
b5193e5d
WR
1605 }
1606
1607 if (!skb) {
1608 nfc_dev_err(&dev->interface->dev, "Failed to allocate skb.");
1609 return -ENOMEM;
1610 }
1611
1612 rc = pn533_send_cmd_async(dev, cmd_code, skb, pn533_poll_complete,
1613 NULL);
1614 if (rc < 0) {
1615 dev_kfree_skb(skb);
6fbbdc16 1616 nfc_dev_err(&dev->interface->dev, "Polling loop error %d", rc);
b5193e5d 1617 }
c46ee386 1618
6fbbdc16
SO
1619 return rc;
1620}
1621
1622static void pn533_wq_poll(struct work_struct *work)
1623{
1624 struct pn533 *dev = container_of(work, struct pn533, poll_work);
1625 struct pn533_poll_modulations *cur_mod;
1626 int rc;
1627
1628 cur_mod = dev->poll_mod_active[dev->poll_mod_curr];
1629
1630 nfc_dev_dbg(&dev->interface->dev,
1631 "%s cancel_listen %d modulation len %d",
1632 __func__, dev->cancel_listen, cur_mod->len);
1633
1634 if (dev->cancel_listen == 1) {
1635 dev->cancel_listen = 0;
1636 usb_kill_urb(dev->in_urb);
c46ee386
AAJ
1637 }
1638
6fbbdc16
SO
1639 rc = pn533_send_poll_frame(dev);
1640 if (rc)
1641 return;
c46ee386 1642
6fbbdc16
SO
1643 if (cur_mod->len == 0 && dev->poll_mod_count > 1)
1644 mod_timer(&dev->listen_timer, jiffies + PN533_LISTEN_TIME * HZ);
c46ee386 1645
6fbbdc16 1646 return;
c46ee386
AAJ
1647}
1648
fe7c5800
SO
1649static int pn533_start_poll(struct nfc_dev *nfc_dev,
1650 u32 im_protocols, u32 tm_protocols)
1651{
1652 struct pn533 *dev = nfc_get_drvdata(nfc_dev);
1653
1654 nfc_dev_dbg(&dev->interface->dev,
1655 "%s: im protocols 0x%x tm protocols 0x%x",
1656 __func__, im_protocols, tm_protocols);
1657
1658 if (dev->tgt_active_prot) {
1659 nfc_dev_err(&dev->interface->dev,
1660 "Cannot poll with a target already activated");
1661 return -EBUSY;
1662 }
1663
51ad304c
SO
1664 if (dev->tgt_mode) {
1665 nfc_dev_err(&dev->interface->dev,
1666 "Cannot poll while already being activated");
1667 return -EBUSY;
1668 }
1669
6fbbdc16
SO
1670 if (tm_protocols) {
1671 dev->gb = nfc_get_local_general_bytes(nfc_dev, &dev->gb_len);
1672 if (dev->gb == NULL)
1673 tm_protocols = 0;
1674 }
ad3823ce 1675
6fbbdc16
SO
1676 dev->poll_mod_curr = 0;
1677 pn533_poll_create_mod_list(dev, im_protocols, tm_protocols);
1678 dev->poll_protocols = im_protocols;
1679 dev->listen_protocols = tm_protocols;
ad3823ce 1680
6fbbdc16 1681 return pn533_send_poll_frame(dev);
fe7c5800
SO
1682}
1683
c46ee386
AAJ
1684static void pn533_stop_poll(struct nfc_dev *nfc_dev)
1685{
1686 struct pn533 *dev = nfc_get_drvdata(nfc_dev);
1687
1688 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
1689
6fbbdc16
SO
1690 del_timer(&dev->listen_timer);
1691
c46ee386 1692 if (!dev->poll_mod_count) {
6ca55372
WR
1693 nfc_dev_dbg(&dev->interface->dev,
1694 "Polling operation was not running");
c46ee386
AAJ
1695 return;
1696 }
1697
1698 /* An ack will cancel the last issued command (poll) */
1699 pn533_send_ack(dev, GFP_KERNEL);
1700
1701 /* prevent pn533_start_poll_complete to issue a new poll meanwhile */
1702 usb_kill_urb(dev->in_urb);
7c2a04a9
SO
1703
1704 pn533_poll_reset_mod_list(dev);
c46ee386
AAJ
1705}
1706
1707static int pn533_activate_target_nfcdep(struct pn533 *dev)
1708{
cb950d93 1709 struct pn533_cmd_activate_response *rsp;
541d920b 1710 u16 gt_len;
c46ee386
AAJ
1711 int rc;
1712
cb950d93
WR
1713 struct sk_buff *skb;
1714 struct sk_buff *resp;
c46ee386 1715
cb950d93 1716 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
c46ee386 1717
9e2d493e 1718 skb = pn533_alloc_skb(dev, sizeof(u8) * 2); /*TG + Next*/
cb950d93
WR
1719 if (!skb)
1720 return -ENOMEM;
c46ee386 1721
cb950d93
WR
1722 *skb_put(skb, sizeof(u8)) = 1; /* TG */
1723 *skb_put(skb, sizeof(u8)) = 0; /* Next */
c46ee386 1724
cb950d93
WR
1725 resp = pn533_send_cmd_sync(dev, PN533_CMD_IN_ATR, skb);
1726 if (IS_ERR(resp))
1727 return PTR_ERR(resp);
c46ee386 1728
37cf4fc6 1729 rsp = (struct pn533_cmd_activate_response *)resp->data;
cb950d93 1730 rc = rsp->status & PN533_CMD_RET_MASK;
8a0ecfe7 1731 if (rc != PN533_CMD_RET_SUCCESS) {
a45e1c8d
WR
1732 nfc_dev_err(&dev->interface->dev,
1733 "Target activation failed (error 0x%x)", rc);
cb950d93 1734 dev_kfree_skb(resp);
c46ee386 1735 return -EIO;
8a0ecfe7 1736 }
c46ee386 1737
541d920b 1738 /* ATR_RES general bytes are located at offset 16 */
cb950d93
WR
1739 gt_len = resp->len - 16;
1740 rc = nfc_set_remote_general_bytes(dev->nfc_dev, rsp->gt, gt_len);
541d920b 1741
cb950d93 1742 dev_kfree_skb(resp);
541d920b 1743 return rc;
c46ee386
AAJ
1744}
1745
90099433
EL
1746static int pn533_activate_target(struct nfc_dev *nfc_dev,
1747 struct nfc_target *target, u32 protocol)
c46ee386
AAJ
1748{
1749 struct pn533 *dev = nfc_get_drvdata(nfc_dev);
1750 int rc;
1751
1752 nfc_dev_dbg(&dev->interface->dev, "%s - protocol=%u", __func__,
5d467742 1753 protocol);
c46ee386
AAJ
1754
1755 if (dev->poll_mod_count) {
6ca55372
WR
1756 nfc_dev_err(&dev->interface->dev,
1757 "Cannot activate while polling");
c46ee386
AAJ
1758 return -EBUSY;
1759 }
1760
1761 if (dev->tgt_active_prot) {
6ca55372
WR
1762 nfc_dev_err(&dev->interface->dev,
1763 "There is already an active target");
c46ee386
AAJ
1764 return -EBUSY;
1765 }
1766
1767 if (!dev->tgt_available_prots) {
6ca55372
WR
1768 nfc_dev_err(&dev->interface->dev,
1769 "There is no available target to activate");
c46ee386
AAJ
1770 return -EINVAL;
1771 }
1772
1773 if (!(dev->tgt_available_prots & (1 << protocol))) {
6ca55372
WR
1774 nfc_dev_err(&dev->interface->dev,
1775 "Target doesn't support requested proto %u",
1776 protocol);
c46ee386
AAJ
1777 return -EINVAL;
1778 }
1779
1780 if (protocol == NFC_PROTO_NFC_DEP) {
1781 rc = pn533_activate_target_nfcdep(dev);
1782 if (rc) {
6ca55372
WR
1783 nfc_dev_err(&dev->interface->dev,
1784 "Activating target with DEP failed %d", rc);
c46ee386
AAJ
1785 return rc;
1786 }
1787 }
1788
1789 dev->tgt_active_prot = protocol;
1790 dev->tgt_available_prots = 0;
1791
1792 return 0;
1793}
1794
90099433
EL
1795static void pn533_deactivate_target(struct nfc_dev *nfc_dev,
1796 struct nfc_target *target)
c46ee386
AAJ
1797{
1798 struct pn533 *dev = nfc_get_drvdata(nfc_dev);
cb950d93
WR
1799
1800 struct sk_buff *skb;
1801 struct sk_buff *resp;
1802
c46ee386
AAJ
1803 int rc;
1804
1805 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
1806
1807 if (!dev->tgt_active_prot) {
1808 nfc_dev_err(&dev->interface->dev, "There is no active target");
1809 return;
1810 }
1811
1812 dev->tgt_active_prot = 0;
6ff73fd2
SO
1813 skb_queue_purge(&dev->resp_q);
1814
9e2d493e 1815 skb = pn533_alloc_skb(dev, sizeof(u8));
cb950d93
WR
1816 if (!skb)
1817 return;
c46ee386 1818
cb950d93 1819 *skb_put(skb, 1) = 1; /* TG*/
c46ee386 1820
cb950d93
WR
1821 resp = pn533_send_cmd_sync(dev, PN533_CMD_IN_RELEASE, skb);
1822 if (IS_ERR(resp))
c46ee386 1823 return;
c46ee386 1824
cb950d93 1825 rc = resp->data[0] & PN533_CMD_RET_MASK;
c46ee386 1826 if (rc != PN533_CMD_RET_SUCCESS)
6ca55372
WR
1827 nfc_dev_err(&dev->interface->dev,
1828 "Error 0x%x when releasing the target", rc);
c46ee386 1829
cb950d93 1830 dev_kfree_skb(resp);
c46ee386
AAJ
1831 return;
1832}
1833
361f3cb7
SO
1834
1835static int pn533_in_dep_link_up_complete(struct pn533 *dev, void *arg,
13003649 1836 struct sk_buff *resp)
361f3cb7 1837{
13003649 1838 struct pn533_cmd_jump_dep_response *rsp;
361f3cb7
SO
1839 u8 target_gt_len;
1840 int rc;
13003649 1841 u8 active = *(u8 *)arg;
70418e6e
WR
1842
1843 kfree(arg);
361f3cb7 1844
13003649
WR
1845 if (IS_ERR(resp))
1846 return PTR_ERR(resp);
361f3cb7
SO
1847
1848 if (dev->tgt_available_prots &&
1849 !(dev->tgt_available_prots & (1 << NFC_PROTO_NFC_DEP))) {
1850 nfc_dev_err(&dev->interface->dev,
5d467742 1851 "The target does not support DEP");
13003649
WR
1852 rc = -EINVAL;
1853 goto error;
361f3cb7
SO
1854 }
1855
13003649
WR
1856 rsp = (struct pn533_cmd_jump_dep_response *)resp->data;
1857
1858 rc = rsp->status & PN533_CMD_RET_MASK;
361f3cb7
SO
1859 if (rc != PN533_CMD_RET_SUCCESS) {
1860 nfc_dev_err(&dev->interface->dev,
a45e1c8d 1861 "Bringing DEP link up failed (error 0x%x)", rc);
13003649 1862 goto error;
361f3cb7
SO
1863 }
1864
1865 if (!dev->tgt_available_prots) {
13003649
WR
1866 struct nfc_target nfc_target;
1867
361f3cb7
SO
1868 nfc_dev_dbg(&dev->interface->dev, "Creating new target");
1869
1870 nfc_target.supported_protocols = NFC_PROTO_NFC_DEP_MASK;
2fbabfa4 1871 nfc_target.nfcid1_len = 10;
13003649 1872 memcpy(nfc_target.nfcid1, rsp->nfcid3t, nfc_target.nfcid1_len);
361f3cb7
SO
1873 rc = nfc_targets_found(dev->nfc_dev, &nfc_target, 1);
1874 if (rc)
13003649 1875 goto error;
361f3cb7
SO
1876
1877 dev->tgt_available_prots = 0;
1878 }
1879
1880 dev->tgt_active_prot = NFC_PROTO_NFC_DEP;
1881
1882 /* ATR_RES general bytes are located at offset 17 */
13003649 1883 target_gt_len = resp->len - 17;
361f3cb7 1884 rc = nfc_set_remote_general_bytes(dev->nfc_dev,
13003649 1885 rsp->gt, target_gt_len);
361f3cb7
SO
1886 if (rc == 0)
1887 rc = nfc_dep_link_is_up(dev->nfc_dev,
13003649
WR
1888 dev->nfc_dev->targets[0].idx,
1889 !active, NFC_RF_INITIATOR);
361f3cb7 1890
13003649
WR
1891error:
1892 dev_kfree_skb(resp);
1893 return rc;
361f3cb7
SO
1894}
1895
41a8ec49
SO
1896static int pn533_mod_to_baud(struct pn533 *dev)
1897{
1898 switch (dev->poll_mod_curr) {
1899 case PN533_POLL_MOD_106KBPS_A:
1900 return 0;
1901 case PN533_POLL_MOD_212KBPS_FELICA:
1902 return 1;
1903 case PN533_POLL_MOD_424KBPS_FELICA:
1904 return 2;
1905 default:
1906 return -EINVAL;
1907 }
1908}
1909
d7f3345d 1910#define PASSIVE_DATA_LEN 5
90099433 1911static int pn533_dep_link_up(struct nfc_dev *nfc_dev, struct nfc_target *target,
37cf4fc6 1912 u8 comm_mode, u8 *gb, size_t gb_len)
361f3cb7
SO
1913{
1914 struct pn533 *dev = nfc_get_drvdata(nfc_dev);
13003649
WR
1915 struct sk_buff *skb;
1916 int rc, baud, skb_len;
1917 u8 *next, *arg;
1918
d7f3345d 1919 u8 passive_data[PASSIVE_DATA_LEN] = {0x00, 0xff, 0xff, 0x00, 0x3};
361f3cb7
SO
1920
1921 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
1922
361f3cb7
SO
1923 if (dev->poll_mod_count) {
1924 nfc_dev_err(&dev->interface->dev,
5d467742 1925 "Cannot bring the DEP link up while polling");
361f3cb7
SO
1926 return -EBUSY;
1927 }
1928
1929 if (dev->tgt_active_prot) {
1930 nfc_dev_err(&dev->interface->dev,
5d467742 1931 "There is already an active target");
361f3cb7
SO
1932 return -EBUSY;
1933 }
1934
41a8ec49
SO
1935 baud = pn533_mod_to_baud(dev);
1936 if (baud < 0) {
1937 nfc_dev_err(&dev->interface->dev,
1938 "Invalid curr modulation %d", dev->poll_mod_curr);
1939 return baud;
1940 }
1941
13003649 1942 skb_len = 3 + gb_len; /* ActPass + BR + Next */
d7f3345d 1943 if (comm_mode == NFC_COMM_PASSIVE)
13003649 1944 skb_len += PASSIVE_DATA_LEN;
d7f3345d 1945
9e2d493e 1946 skb = pn533_alloc_skb(dev, skb_len);
13003649 1947 if (!skb)
361f3cb7
SO
1948 return -ENOMEM;
1949
13003649
WR
1950 *skb_put(skb, 1) = !comm_mode; /* ActPass */
1951 *skb_put(skb, 1) = baud; /* Baud rate */
1952
1953 next = skb_put(skb, 1); /* Next */
1954 *next = 0;
361f3cb7 1955
13003649
WR
1956 if (comm_mode == NFC_COMM_PASSIVE && baud > 0) {
1957 memcpy(skb_put(skb, PASSIVE_DATA_LEN), passive_data,
1958 PASSIVE_DATA_LEN);
1959 *next |= 1;
d7f3345d
SO
1960 }
1961
47807d3d 1962 if (gb != NULL && gb_len > 0) {
13003649
WR
1963 memcpy(skb_put(skb, gb_len), gb, gb_len);
1964 *next |= 4; /* We have some Gi */
361f3cb7 1965 } else {
13003649 1966 *next = 0;
361f3cb7
SO
1967 }
1968
13003649
WR
1969 arg = kmalloc(sizeof(*arg), GFP_KERNEL);
1970 if (!arg) {
1971 dev_kfree_skb(skb);
1972 return -ENOMEM;
1973 }
361f3cb7 1974
13003649 1975 *arg = !comm_mode;
361f3cb7 1976
13003649
WR
1977 rc = pn533_send_cmd_async(dev, PN533_CMD_IN_JUMP_FOR_DEP, skb,
1978 pn533_in_dep_link_up_complete, arg);
1979
1980 if (rc < 0) {
1981 dev_kfree_skb(skb);
1982 kfree(arg);
1983 }
361f3cb7
SO
1984
1985 return rc;
1986}
1987
1988static int pn533_dep_link_down(struct nfc_dev *nfc_dev)
1989{
6fbbdc16
SO
1990 struct pn533 *dev = nfc_get_drvdata(nfc_dev);
1991
fcfafc76
WR
1992 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
1993
6fbbdc16
SO
1994 pn533_poll_reset_mod_list(dev);
1995
51ad304c
SO
1996 if (dev->tgt_mode || dev->tgt_active_prot) {
1997 pn533_send_ack(dev, GFP_KERNEL);
1998 usb_kill_urb(dev->in_urb);
1999 }
2000
2001 dev->tgt_active_prot = 0;
2002 dev->tgt_mode = 0;
2003
2004 skb_queue_purge(&dev->resp_q);
361f3cb7
SO
2005
2006 return 0;
2007}
2008
c46ee386 2009struct pn533_data_exchange_arg {
c46ee386
AAJ
2010 data_exchange_cb_t cb;
2011 void *cb_context;
2012};
2013
6ff73fd2
SO
2014static struct sk_buff *pn533_build_response(struct pn533 *dev)
2015{
2016 struct sk_buff *skb, *tmp, *t;
2017 unsigned int skb_len = 0, tmp_len = 0;
2018
fcfafc76 2019 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
6ff73fd2
SO
2020
2021 if (skb_queue_empty(&dev->resp_q))
2022 return NULL;
2023
2024 if (skb_queue_len(&dev->resp_q) == 1) {
2025 skb = skb_dequeue(&dev->resp_q);
2026 goto out;
2027 }
2028
2029 skb_queue_walk_safe(&dev->resp_q, tmp, t)
2030 skb_len += tmp->len;
2031
2032 nfc_dev_dbg(&dev->interface->dev, "%s total length %d\n",
2033 __func__, skb_len);
2034
2035 skb = alloc_skb(skb_len, GFP_KERNEL);
2036 if (skb == NULL)
2037 goto out;
2038
2039 skb_put(skb, skb_len);
2040
2041 skb_queue_walk_safe(&dev->resp_q, tmp, t) {
2042 memcpy(skb->data + tmp_len, tmp->data, tmp->len);
2043 tmp_len += tmp->len;
2044 }
2045
2046out:
2047 skb_queue_purge(&dev->resp_q);
2048
2049 return skb;
2050}
2051
c46ee386 2052static int pn533_data_exchange_complete(struct pn533 *dev, void *_arg,
b1e666f5 2053 struct sk_buff *resp)
c46ee386
AAJ
2054{
2055 struct pn533_data_exchange_arg *arg = _arg;
b1e666f5
WR
2056 struct sk_buff *skb;
2057 int rc = 0;
2058 u8 status, ret, mi;
c46ee386
AAJ
2059
2060 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
2061
b1e666f5
WR
2062 if (IS_ERR(resp)) {
2063 rc = PTR_ERR(resp);
2064 goto _error;
c46ee386
AAJ
2065 }
2066
b1e666f5
WR
2067 status = resp->data[0];
2068 ret = status & PN533_CMD_RET_MASK;
2069 mi = status & PN533_CMD_MI_MASK;
2070
2071 skb_pull(resp, sizeof(status));
c46ee386 2072
b1e666f5
WR
2073 if (ret != PN533_CMD_RET_SUCCESS) {
2074 nfc_dev_err(&dev->interface->dev,
a45e1c8d 2075 "Exchanging data failed (error 0x%x)", ret);
b1e666f5 2076 rc = -EIO;
c46ee386
AAJ
2077 goto error;
2078 }
2079
b1e666f5 2080 skb_queue_tail(&dev->resp_q, resp);
6ff73fd2 2081
b1e666f5
WR
2082 if (mi) {
2083 dev->cmd_complete_mi_arg = arg;
6ff73fd2
SO
2084 queue_work(dev->wq, &dev->mi_work);
2085 return -EINPROGRESS;
c46ee386
AAJ
2086 }
2087
6ff73fd2 2088 skb = pn533_build_response(dev);
b1e666f5 2089 if (!skb)
6ff73fd2 2090 goto error;
c46ee386 2091
6ff73fd2 2092 arg->cb(arg->cb_context, skb, 0);
c46ee386
AAJ
2093 kfree(arg);
2094 return 0;
2095
2096error:
b1e666f5
WR
2097 dev_kfree_skb(resp);
2098_error:
6ff73fd2 2099 skb_queue_purge(&dev->resp_q);
b1e666f5 2100 arg->cb(arg->cb_context, NULL, rc);
c46ee386 2101 kfree(arg);
b1e666f5 2102 return rc;
c46ee386
AAJ
2103}
2104
be9ae4ce
SO
2105static int pn533_transceive(struct nfc_dev *nfc_dev,
2106 struct nfc_target *target, struct sk_buff *skb,
2107 data_exchange_cb_t cb, void *cb_context)
c46ee386
AAJ
2108{
2109 struct pn533 *dev = nfc_get_drvdata(nfc_dev);
b1e666f5 2110 struct pn533_data_exchange_arg *arg = NULL;
c46ee386
AAJ
2111 int rc;
2112
2113 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
2114
b1e666f5
WR
2115 if (skb->len > PN533_CMD_DATAEXCH_DATA_MAXLEN) {
2116 /* TODO: Implement support to multi-part data exchange */
2117 nfc_dev_err(&dev->interface->dev,
2118 "Data length greater than the max allowed: %d",
2119 PN533_CMD_DATAEXCH_DATA_MAXLEN);
2120 rc = -ENOSYS;
2121 goto error;
2122 }
2123
c46ee386 2124 if (!dev->tgt_active_prot) {
6ca55372
WR
2125 nfc_dev_err(&dev->interface->dev,
2126 "Can't exchange data if there is no active target");
c46ee386
AAJ
2127 rc = -EINVAL;
2128 goto error;
2129 }
2130
b1e666f5 2131 arg = kmalloc(sizeof(*arg), GFP_KERNEL);
c46ee386
AAJ
2132 if (!arg) {
2133 rc = -ENOMEM;
b1e666f5 2134 goto error;
c46ee386
AAJ
2135 }
2136
c46ee386
AAJ
2137 arg->cb = cb;
2138 arg->cb_context = cb_context;
2139
b1e666f5
WR
2140 switch (dev->device_type) {
2141 case PN533_DEVICE_PASORI:
2142 if (dev->tgt_active_prot == NFC_PROTO_FELICA) {
2143 rc = pn533_send_data_async(dev, PN533_CMD_IN_COMM_THRU,
2144 skb,
2145 pn533_data_exchange_complete,
2146 arg);
2147
2148 break;
2149 }
2150 default:
2151 *skb_push(skb, sizeof(u8)) = 1; /*TG*/
2152
2153 rc = pn533_send_data_async(dev, PN533_CMD_IN_DATA_EXCHANGE,
2154 skb, pn533_data_exchange_complete,
2155 arg);
2156
2157 break;
c46ee386
AAJ
2158 }
2159
b1e666f5
WR
2160 if (rc < 0) /* rc from send_async */
2161 goto error;
2162
c46ee386
AAJ
2163 return 0;
2164
c46ee386 2165error:
b1e666f5
WR
2166 kfree(arg);
2167 dev_kfree_skb(skb);
c46ee386
AAJ
2168 return rc;
2169}
2170
dadb06f2 2171static int pn533_tm_send_complete(struct pn533 *dev, void *arg,
e4878823 2172 struct sk_buff *resp)
dadb06f2 2173{
e4878823 2174 u8 status;
5b412fd1 2175
dadb06f2
SO
2176 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
2177
e4878823
WR
2178 if (IS_ERR(resp))
2179 return PTR_ERR(resp);
5b412fd1 2180
e4878823 2181 status = resp->data[0];
dadb06f2 2182
e4878823 2183 dev_kfree_skb(resp);
dadb06f2 2184
e4878823 2185 if (status != 0) {
dadb06f2
SO
2186 nfc_tm_deactivated(dev->nfc_dev);
2187
51ad304c
SO
2188 dev->tgt_mode = 0;
2189
dadb06f2
SO
2190 return 0;
2191 }
2192
2193 queue_work(dev->wq, &dev->tg_work);
2194
2195 return 0;
2196}
2197
2198static int pn533_tm_send(struct nfc_dev *nfc_dev, struct sk_buff *skb)
2199{
2200 struct pn533 *dev = nfc_get_drvdata(nfc_dev);
dadb06f2
SO
2201 int rc;
2202
2203 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
2204
e4878823 2205 if (skb->len > PN533_CMD_DATAEXCH_DATA_MAXLEN) {
dadb06f2 2206 nfc_dev_err(&dev->interface->dev,
e4878823
WR
2207 "Data length greater than the max allowed: %d",
2208 PN533_CMD_DATAEXCH_DATA_MAXLEN);
2209 return -ENOSYS;
dadb06f2
SO
2210 }
2211
e4878823
WR
2212 rc = pn533_send_data_async(dev, PN533_CMD_TG_SET_DATA, skb,
2213 pn533_tm_send_complete, NULL);
2214 if (rc < 0)
2215 dev_kfree_skb(skb);
dadb06f2
SO
2216
2217 return rc;
2218}
2219
6ff73fd2
SO
2220static void pn533_wq_mi_recv(struct work_struct *work)
2221{
2222 struct pn533 *dev = container_of(work, struct pn533, mi_work);
b1e666f5
WR
2223
2224 struct sk_buff *skb;
6ff73fd2
SO
2225 int rc;
2226
2227 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
2228
9e2d493e 2229 skb = pn533_alloc_skb(dev, PN533_CMD_DATAEXCH_HEAD_LEN);
b1e666f5
WR
2230 if (!skb)
2231 goto error;
6ff73fd2 2232
b1e666f5
WR
2233 switch (dev->device_type) {
2234 case PN533_DEVICE_PASORI:
2235 if (dev->tgt_active_prot == NFC_PROTO_FELICA) {
2236 rc = pn533_send_cmd_direct_async(dev,
2237 PN533_CMD_IN_COMM_THRU,
2238 skb,
2239 pn533_data_exchange_complete,
2240 dev->cmd_complete_mi_arg);
6ff73fd2 2241
b1e666f5
WR
2242 break;
2243 }
2244 default:
2245 *skb_put(skb, sizeof(u8)) = 1; /*TG*/
6ff73fd2 2246
b1e666f5
WR
2247 rc = pn533_send_cmd_direct_async(dev,
2248 PN533_CMD_IN_DATA_EXCHANGE,
2249 skb,
2250 pn533_data_exchange_complete,
2251 dev->cmd_complete_mi_arg);
b1bb290a 2252
b1e666f5 2253 break;
6ff73fd2
SO
2254 }
2255
b1e666f5 2256 if (rc == 0) /* success */
6ff73fd2
SO
2257 return;
2258
b1e666f5
WR
2259 nfc_dev_err(&dev->interface->dev,
2260 "Error %d when trying to perform data_exchange", rc);
6ff73fd2 2261
b1e666f5
WR
2262 dev_kfree_skb(skb);
2263 kfree(dev->cmd_complete_arg);
6ff73fd2 2264
b1e666f5 2265error:
6ff73fd2 2266 pn533_send_ack(dev, GFP_KERNEL);
5d50b364 2267 queue_work(dev->wq, &dev->cmd_work);
6ff73fd2
SO
2268}
2269
c46ee386
AAJ
2270static int pn533_set_configuration(struct pn533 *dev, u8 cfgitem, u8 *cfgdata,
2271 u8 cfgdata_len)
2272{
cb950d93
WR
2273 struct sk_buff *skb;
2274 struct sk_buff *resp;
2275
2276 int skb_len;
c46ee386
AAJ
2277
2278 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
2279
cb950d93 2280 skb_len = sizeof(cfgitem) + cfgdata_len; /* cfgitem + cfgdata */
c46ee386 2281
9e2d493e 2282 skb = pn533_alloc_skb(dev, skb_len);
cb950d93
WR
2283 if (!skb)
2284 return -ENOMEM;
c46ee386 2285
cb950d93
WR
2286 *skb_put(skb, sizeof(cfgitem)) = cfgitem;
2287 memcpy(skb_put(skb, cfgdata_len), cfgdata, cfgdata_len);
c46ee386 2288
cb950d93
WR
2289 resp = pn533_send_cmd_sync(dev, PN533_CMD_RF_CONFIGURATION, skb);
2290 if (IS_ERR(resp))
2291 return PTR_ERR(resp);
c46ee386 2292
cb950d93
WR
2293 dev_kfree_skb(resp);
2294 return 0;
2295}
2296
2297static int pn533_get_firmware_version(struct pn533 *dev,
2298 struct pn533_fw_version *fv)
2299{
2300 struct sk_buff *skb;
2301 struct sk_buff *resp;
2302
9e2d493e 2303 skb = pn533_alloc_skb(dev, 0);
cb950d93
WR
2304 if (!skb)
2305 return -ENOMEM;
2306
2307 resp = pn533_send_cmd_sync(dev, PN533_CMD_GET_FIRMWARE_VERSION, skb);
2308 if (IS_ERR(resp))
2309 return PTR_ERR(resp);
2310
2311 fv->ic = resp->data[0];
2312 fv->ver = resp->data[1];
2313 fv->rev = resp->data[2];
2314 fv->support = resp->data[3];
2315
2316 dev_kfree_skb(resp);
2317 return 0;
c46ee386
AAJ
2318}
2319
5c7b0531
SO
2320static int pn533_fw_reset(struct pn533 *dev)
2321{
cb950d93
WR
2322 struct sk_buff *skb;
2323 struct sk_buff *resp;
5c7b0531
SO
2324
2325 nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
2326
9e2d493e 2327 skb = pn533_alloc_skb(dev, sizeof(u8));
cb950d93
WR
2328 if (!skb)
2329 return -ENOMEM;
5c7b0531 2330
cb950d93 2331 *skb_put(skb, sizeof(u8)) = 0x1;
5c7b0531 2332
cb950d93
WR
2333 resp = pn533_send_cmd_sync(dev, 0x18, skb);
2334 if (IS_ERR(resp))
2335 return PTR_ERR(resp);
5c7b0531 2336
cb950d93 2337 dev_kfree_skb(resp);
5c7b0531 2338
94c5c156 2339 return 0;
5c7b0531
SO
2340}
2341
2342static struct nfc_ops pn533_nfc_ops = {
8b3fe7b5
IE
2343 .dev_up = NULL,
2344 .dev_down = NULL,
361f3cb7
SO
2345 .dep_link_up = pn533_dep_link_up,
2346 .dep_link_down = pn533_dep_link_down,
c46ee386
AAJ
2347 .start_poll = pn533_start_poll,
2348 .stop_poll = pn533_stop_poll,
2349 .activate_target = pn533_activate_target,
2350 .deactivate_target = pn533_deactivate_target,
be9ae4ce 2351 .im_transceive = pn533_transceive,
dadb06f2 2352 .tm_send = pn533_tm_send,
c46ee386
AAJ
2353};
2354
5c7b0531
SO
2355static int pn533_setup(struct pn533 *dev)
2356{
2357 struct pn533_config_max_retries max_retries;
2358 struct pn533_config_timing timing;
2359 u8 pasori_cfg[3] = {0x08, 0x01, 0x08};
2360 int rc;
2361
2362 switch (dev->device_type) {
2363 case PN533_DEVICE_STD:
2364 max_retries.mx_rty_atr = PN533_CONFIG_MAX_RETRIES_ENDLESS;
2365 max_retries.mx_rty_psl = 2;
2366 max_retries.mx_rty_passive_act =
2367 PN533_CONFIG_MAX_RETRIES_NO_RETRY;
2368
2369 timing.rfu = PN533_CONFIG_TIMING_102;
2370 timing.atr_res_timeout = PN533_CONFIG_TIMING_204;
2371 timing.dep_timeout = PN533_CONFIG_TIMING_409;
2372
2373 break;
2374
2375 case PN533_DEVICE_PASORI:
2376 max_retries.mx_rty_atr = 0x2;
2377 max_retries.mx_rty_psl = 0x1;
2378 max_retries.mx_rty_passive_act =
2379 PN533_CONFIG_MAX_RETRIES_NO_RETRY;
2380
2381 timing.rfu = PN533_CONFIG_TIMING_102;
2382 timing.atr_res_timeout = PN533_CONFIG_TIMING_102;
2383 timing.dep_timeout = PN533_CONFIG_TIMING_204;
2384
2385 break;
2386
2387 default:
2388 nfc_dev_err(&dev->interface->dev, "Unknown device type %d\n",
2389 dev->device_type);
2390 return -EINVAL;
2391 }
2392
2393 rc = pn533_set_configuration(dev, PN533_CFGITEM_MAX_RETRIES,
2394 (u8 *)&max_retries, sizeof(max_retries));
2395 if (rc) {
2396 nfc_dev_err(&dev->interface->dev,
2397 "Error on setting MAX_RETRIES config");
2398 return rc;
2399 }
2400
2401
2402 rc = pn533_set_configuration(dev, PN533_CFGITEM_TIMING,
2403 (u8 *)&timing, sizeof(timing));
2404 if (rc) {
2405 nfc_dev_err(&dev->interface->dev,
2406 "Error on setting RF timings");
2407 return rc;
2408 }
2409
2410 switch (dev->device_type) {
2411 case PN533_DEVICE_STD:
2412 break;
2413
2414 case PN533_DEVICE_PASORI:
2415 pn533_fw_reset(dev);
2416
2417 rc = pn533_set_configuration(dev, PN533_CFGITEM_PASORI,
2418 pasori_cfg, 3);
2419 if (rc) {
2420 nfc_dev_err(&dev->interface->dev,
2421 "Error while settings PASORI config");
2422 return rc;
2423 }
2424
2425 pn533_fw_reset(dev);
2426
2427 break;
2428 }
2429
2430 return 0;
2431}
2432
c46ee386
AAJ
2433static int pn533_probe(struct usb_interface *interface,
2434 const struct usb_device_id *id)
2435{
cb950d93 2436 struct pn533_fw_version fw_ver;
c46ee386
AAJ
2437 struct pn533 *dev;
2438 struct usb_host_interface *iface_desc;
2439 struct usb_endpoint_descriptor *endpoint;
c46ee386
AAJ
2440 int in_endpoint = 0;
2441 int out_endpoint = 0;
2442 int rc = -ENOMEM;
2443 int i;
2444 u32 protocols;
2445
2446 dev = kzalloc(sizeof(*dev), GFP_KERNEL);
2447 if (!dev)
2448 return -ENOMEM;
2449
2450 dev->udev = usb_get_dev(interface_to_usbdev(interface));
2451 dev->interface = interface;
0201ed03 2452 mutex_init(&dev->cmd_lock);
c46ee386
AAJ
2453
2454 iface_desc = interface->cur_altsetting;
2455 for (i = 0; i < iface_desc->desc.bNumEndpoints; ++i) {
2456 endpoint = &iface_desc->endpoint[i].desc;
2457
8d25ca79 2458 if (!in_endpoint && usb_endpoint_is_bulk_in(endpoint))
c46ee386 2459 in_endpoint = endpoint->bEndpointAddress;
c46ee386 2460
8d25ca79 2461 if (!out_endpoint && usb_endpoint_is_bulk_out(endpoint))
c46ee386 2462 out_endpoint = endpoint->bEndpointAddress;
c46ee386
AAJ
2463 }
2464
2465 if (!in_endpoint || !out_endpoint) {
6ca55372
WR
2466 nfc_dev_err(&interface->dev,
2467 "Could not find bulk-in or bulk-out endpoint");
c46ee386
AAJ
2468 rc = -ENODEV;
2469 goto error;
2470 }
2471
c46ee386 2472 dev->in_urb = usb_alloc_urb(0, GFP_KERNEL);
c46ee386
AAJ
2473 dev->out_urb = usb_alloc_urb(0, GFP_KERNEL);
2474
a5798094 2475 if (!dev->in_urb || !dev->out_urb)
c46ee386
AAJ
2476 goto error;
2477
2478 usb_fill_bulk_urb(dev->in_urb, dev->udev,
5d467742
WR
2479 usb_rcvbulkpipe(dev->udev, in_endpoint),
2480 NULL, 0, NULL, dev);
c46ee386 2481 usb_fill_bulk_urb(dev->out_urb, dev->udev,
5d467742
WR
2482 usb_sndbulkpipe(dev->udev, out_endpoint),
2483 NULL, 0, pn533_send_complete, dev);
c46ee386 2484
5d50b364
SO
2485 INIT_WORK(&dev->cmd_work, pn533_wq_cmd);
2486 INIT_WORK(&dev->cmd_complete_work, pn533_wq_cmd_complete);
6ff73fd2 2487 INIT_WORK(&dev->mi_work, pn533_wq_mi_recv);
103b34cf 2488 INIT_WORK(&dev->tg_work, pn533_wq_tg_get_data);
6fbbdc16 2489 INIT_WORK(&dev->poll_work, pn533_wq_poll);
58637c9b 2490 dev->wq = alloc_ordered_workqueue("pn533", 0);
4849f85e
SO
2491 if (dev->wq == NULL)
2492 goto error;
c46ee386 2493
6fbbdc16
SO
2494 init_timer(&dev->listen_timer);
2495 dev->listen_timer.data = (unsigned long) dev;
2496 dev->listen_timer.function = pn533_listen_mode_timer;
2497
6ff73fd2
SO
2498 skb_queue_head_init(&dev->resp_q);
2499
5d50b364
SO
2500 INIT_LIST_HEAD(&dev->cmd_queue);
2501
c46ee386
AAJ
2502 usb_set_intfdata(interface, dev);
2503
9e2d493e 2504 dev->ops = &pn533_std_frame_ops;
c46ee386 2505
5c7b0531
SO
2506 dev->device_type = id->driver_info;
2507 switch (dev->device_type) {
2508 case PN533_DEVICE_STD:
2509 protocols = PN533_ALL_PROTOCOLS;
2510 break;
2511
2512 case PN533_DEVICE_PASORI:
2513 protocols = PN533_NO_TYPE_B_PROTOCOLS;
2514 break;
2515
2516 default:
2517 nfc_dev_err(&dev->interface->dev, "Unknown device type %d\n",
2518 dev->device_type);
2519 rc = -EINVAL;
2520 goto destroy_wq;
2521 }
c46ee386 2522
9e2d493e
WR
2523 memset(&fw_ver, 0, sizeof(fw_ver));
2524 rc = pn533_get_firmware_version(dev, &fw_ver);
2525 if (rc < 0)
2526 goto destroy_wq;
2527
2528 nfc_dev_info(&dev->interface->dev,
2529 "NXP PN533 firmware ver %d.%d now attached",
2530 fw_ver.ver, fw_ver.rev);
2531
2532
e8753043 2533 dev->nfc_dev = nfc_allocate_device(&pn533_nfc_ops, protocols,
390a1bd8 2534 NFC_SE_NONE,
9e2d493e 2535 dev->ops->tx_header_len +
e8753043 2536 PN533_CMD_DATAEXCH_HEAD_LEN,
9e2d493e 2537 dev->ops->tx_tail_len);
c46ee386 2538 if (!dev->nfc_dev)
4849f85e 2539 goto destroy_wq;
c46ee386
AAJ
2540
2541 nfc_set_parent_dev(dev->nfc_dev, &interface->dev);
2542 nfc_set_drvdata(dev->nfc_dev, dev);
2543
2544 rc = nfc_register_device(dev->nfc_dev);
2545 if (rc)
2546 goto free_nfc_dev;
2547
5c7b0531
SO
2548 rc = pn533_setup(dev);
2549 if (rc)
34a85bfc 2550 goto unregister_nfc_dev;
34a85bfc 2551
c46ee386
AAJ
2552 return 0;
2553
9f2f8ba1
SO
2554unregister_nfc_dev:
2555 nfc_unregister_device(dev->nfc_dev);
2556
c46ee386
AAJ
2557free_nfc_dev:
2558 nfc_free_device(dev->nfc_dev);
9f2f8ba1 2559
4849f85e
SO
2560destroy_wq:
2561 destroy_workqueue(dev->wq);
c46ee386 2562error:
c46ee386 2563 usb_free_urb(dev->in_urb);
c46ee386
AAJ
2564 usb_free_urb(dev->out_urb);
2565 kfree(dev);
2566 return rc;
2567}
2568
2569static void pn533_disconnect(struct usb_interface *interface)
2570{
2571 struct pn533 *dev;
5d50b364 2572 struct pn533_cmd *cmd, *n;
c46ee386
AAJ
2573
2574 dev = usb_get_intfdata(interface);
2575 usb_set_intfdata(interface, NULL);
2576
2577 nfc_unregister_device(dev->nfc_dev);
2578 nfc_free_device(dev->nfc_dev);
2579
2580 usb_kill_urb(dev->in_urb);
2581 usb_kill_urb(dev->out_urb);
2582
4849f85e 2583 destroy_workqueue(dev->wq);
c46ee386 2584
6ff73fd2
SO
2585 skb_queue_purge(&dev->resp_q);
2586
6fbbdc16
SO
2587 del_timer(&dev->listen_timer);
2588
5d50b364
SO
2589 list_for_each_entry_safe(cmd, n, &dev->cmd_queue, queue) {
2590 list_del(&cmd->queue);
2591 kfree(cmd);
2592 }
2593
c46ee386 2594 usb_free_urb(dev->in_urb);
c46ee386
AAJ
2595 usb_free_urb(dev->out_urb);
2596 kfree(dev);
2597
276556db 2598 nfc_dev_info(&interface->dev, "NXP PN533 NFC device disconnected");
c46ee386
AAJ
2599}
2600
2601static struct usb_driver pn533_driver = {
2602 .name = "pn533",
2603 .probe = pn533_probe,
2604 .disconnect = pn533_disconnect,
2605 .id_table = pn533_table,
2606};
2607
fe748483 2608module_usb_driver(pn533_driver);
c46ee386
AAJ
2609
2610MODULE_AUTHOR("Lauro Ramos Venancio <lauro.venancio@openbossa.org>,"
2611 " Aloisio Almeida Jr <aloisio.almeida@openbossa.org>");
2612MODULE_DESCRIPTION("PN533 usb driver ver " VERSION);
2613MODULE_VERSION(VERSION);
2614MODULE_LICENSE("GPL");