Bluetooth: Fix socket not getting freed if l2cap channel create fails
[linux-2.6-block.git] / drivers / bluetooth / btusb.c
... / ...
CommitLineData
1/*
2 *
3 * Generic Bluetooth USB driver
4 *
5 * Copyright (C) 2005-2008 Marcel Holtmann <marcel@holtmann.org>
6 *
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 2 of the License, or
11 * (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
21 *
22 */
23
24#include <linux/module.h>
25#include <linux/usb.h>
26
27#include <net/bluetooth/bluetooth.h>
28#include <net/bluetooth/hci_core.h>
29
30#define VERSION "0.6"
31
32static bool ignore_dga;
33static bool ignore_csr;
34static bool ignore_sniffer;
35static bool disable_scofix;
36static bool force_scofix;
37
38static bool reset = 1;
39
40static struct usb_driver btusb_driver;
41
42#define BTUSB_IGNORE 0x01
43#define BTUSB_DIGIANSWER 0x02
44#define BTUSB_CSR 0x04
45#define BTUSB_SNIFFER 0x08
46#define BTUSB_BCM92035 0x10
47#define BTUSB_BROKEN_ISOC 0x20
48#define BTUSB_WRONG_SCO_MTU 0x40
49#define BTUSB_ATH3012 0x80
50
51static struct usb_device_id btusb_table[] = {
52 /* Generic Bluetooth USB device */
53 { USB_DEVICE_INFO(0xe0, 0x01, 0x01) },
54
55 /* Broadcom SoftSailing reporting vendor specific */
56 { USB_DEVICE(0x0a5c, 0x21e1) },
57
58 /* Apple MacBookPro 7,1 */
59 { USB_DEVICE(0x05ac, 0x8213) },
60
61 /* Apple iMac11,1 */
62 { USB_DEVICE(0x05ac, 0x8215) },
63
64 /* Apple MacBookPro6,2 */
65 { USB_DEVICE(0x05ac, 0x8218) },
66
67 /* Apple MacBookAir3,1, MacBookAir3,2 */
68 { USB_DEVICE(0x05ac, 0x821b) },
69
70 /* Apple MacBookAir4,1 */
71 { USB_DEVICE(0x05ac, 0x821f) },
72
73 /* Apple MacBookPro8,2 */
74 { USB_DEVICE(0x05ac, 0x821a) },
75
76 /* Apple MacMini5,1 */
77 { USB_DEVICE(0x05ac, 0x8281) },
78
79 /* AVM BlueFRITZ! USB v2.0 */
80 { USB_DEVICE(0x057c, 0x3800) },
81
82 /* Bluetooth Ultraport Module from IBM */
83 { USB_DEVICE(0x04bf, 0x030a) },
84
85 /* ALPS Modules with non-standard id */
86 { USB_DEVICE(0x044e, 0x3001) },
87 { USB_DEVICE(0x044e, 0x3002) },
88
89 /* Ericsson with non-standard id */
90 { USB_DEVICE(0x0bdb, 0x1002) },
91
92 /* Canyon CN-BTU1 with HID interfaces */
93 { USB_DEVICE(0x0c10, 0x0000) },
94
95 /* Broadcom BCM20702A0 */
96 { USB_DEVICE(0x0489, 0xe042) },
97 { USB_DEVICE(0x0a5c, 0x21e3) },
98 { USB_DEVICE(0x0a5c, 0x21e6) },
99 { USB_DEVICE(0x0a5c, 0x21e8) },
100 { USB_DEVICE(0x0a5c, 0x21f3) },
101 { USB_DEVICE(0x0a5c, 0x21f4) },
102 { USB_DEVICE(0x413c, 0x8197) },
103
104 /* Foxconn - Hon Hai */
105 { USB_DEVICE(0x0489, 0xe033) },
106
107 { } /* Terminating entry */
108};
109
110MODULE_DEVICE_TABLE(usb, btusb_table);
111
112static struct usb_device_id blacklist_table[] = {
113 /* CSR BlueCore devices */
114 { USB_DEVICE(0x0a12, 0x0001), .driver_info = BTUSB_CSR },
115
116 /* Broadcom BCM2033 without firmware */
117 { USB_DEVICE(0x0a5c, 0x2033), .driver_info = BTUSB_IGNORE },
118
119 /* Atheros 3011 with sflash firmware */
120 { USB_DEVICE(0x0cf3, 0x3002), .driver_info = BTUSB_IGNORE },
121 { USB_DEVICE(0x0cf3, 0xe019), .driver_info = BTUSB_IGNORE },
122 { USB_DEVICE(0x13d3, 0x3304), .driver_info = BTUSB_IGNORE },
123 { USB_DEVICE(0x0930, 0x0215), .driver_info = BTUSB_IGNORE },
124 { USB_DEVICE(0x0489, 0xe03d), .driver_info = BTUSB_IGNORE },
125
126 /* Atheros AR9285 Malbec with sflash firmware */
127 { USB_DEVICE(0x03f0, 0x311d), .driver_info = BTUSB_IGNORE },
128
129 /* Atheros 3012 with sflash firmware */
130 { USB_DEVICE(0x0cf3, 0x3004), .driver_info = BTUSB_ATH3012 },
131 { USB_DEVICE(0x0cf3, 0x311d), .driver_info = BTUSB_ATH3012 },
132 { USB_DEVICE(0x13d3, 0x3375), .driver_info = BTUSB_ATH3012 },
133 { USB_DEVICE(0x04ca, 0x3005), .driver_info = BTUSB_ATH3012 },
134 { USB_DEVICE(0x13d3, 0x3362), .driver_info = BTUSB_ATH3012 },
135 { USB_DEVICE(0x0cf3, 0xe004), .driver_info = BTUSB_ATH3012 },
136 { USB_DEVICE(0x0930, 0x0219), .driver_info = BTUSB_ATH3012 },
137
138 /* Atheros AR5BBU12 with sflash firmware */
139 { USB_DEVICE(0x0489, 0xe02c), .driver_info = BTUSB_IGNORE },
140
141 /* Atheros AR5BBU12 with sflash firmware */
142 { USB_DEVICE(0x0489, 0xe03c), .driver_info = BTUSB_ATH3012 },
143
144 /* Broadcom BCM2035 */
145 { USB_DEVICE(0x0a5c, 0x2035), .driver_info = BTUSB_WRONG_SCO_MTU },
146 { USB_DEVICE(0x0a5c, 0x200a), .driver_info = BTUSB_WRONG_SCO_MTU },
147 { USB_DEVICE(0x0a5c, 0x2009), .driver_info = BTUSB_BCM92035 },
148
149 /* Broadcom BCM2045 */
150 { USB_DEVICE(0x0a5c, 0x2039), .driver_info = BTUSB_WRONG_SCO_MTU },
151 { USB_DEVICE(0x0a5c, 0x2101), .driver_info = BTUSB_WRONG_SCO_MTU },
152
153 /* IBM/Lenovo ThinkPad with Broadcom chip */
154 { USB_DEVICE(0x0a5c, 0x201e), .driver_info = BTUSB_WRONG_SCO_MTU },
155 { USB_DEVICE(0x0a5c, 0x2110), .driver_info = BTUSB_WRONG_SCO_MTU },
156
157 /* HP laptop with Broadcom chip */
158 { USB_DEVICE(0x03f0, 0x171d), .driver_info = BTUSB_WRONG_SCO_MTU },
159
160 /* Dell laptop with Broadcom chip */
161 { USB_DEVICE(0x413c, 0x8126), .driver_info = BTUSB_WRONG_SCO_MTU },
162
163 /* Dell Wireless 370 and 410 devices */
164 { USB_DEVICE(0x413c, 0x8152), .driver_info = BTUSB_WRONG_SCO_MTU },
165 { USB_DEVICE(0x413c, 0x8156), .driver_info = BTUSB_WRONG_SCO_MTU },
166
167 /* Belkin F8T012 and F8T013 devices */
168 { USB_DEVICE(0x050d, 0x0012), .driver_info = BTUSB_WRONG_SCO_MTU },
169 { USB_DEVICE(0x050d, 0x0013), .driver_info = BTUSB_WRONG_SCO_MTU },
170
171 /* Asus WL-BTD202 device */
172 { USB_DEVICE(0x0b05, 0x1715), .driver_info = BTUSB_WRONG_SCO_MTU },
173
174 /* Kensington Bluetooth USB adapter */
175 { USB_DEVICE(0x047d, 0x105e), .driver_info = BTUSB_WRONG_SCO_MTU },
176
177 /* RTX Telecom based adapters with buggy SCO support */
178 { USB_DEVICE(0x0400, 0x0807), .driver_info = BTUSB_BROKEN_ISOC },
179 { USB_DEVICE(0x0400, 0x080a), .driver_info = BTUSB_BROKEN_ISOC },
180
181 /* CONWISE Technology based adapters with buggy SCO support */
182 { USB_DEVICE(0x0e5e, 0x6622), .driver_info = BTUSB_BROKEN_ISOC },
183
184 /* Digianswer devices */
185 { USB_DEVICE(0x08fd, 0x0001), .driver_info = BTUSB_DIGIANSWER },
186 { USB_DEVICE(0x08fd, 0x0002), .driver_info = BTUSB_IGNORE },
187
188 /* CSR BlueCore Bluetooth Sniffer */
189 { USB_DEVICE(0x0a12, 0x0002), .driver_info = BTUSB_SNIFFER },
190
191 /* Frontline ComProbe Bluetooth Sniffer */
192 { USB_DEVICE(0x16d3, 0x0002), .driver_info = BTUSB_SNIFFER },
193
194 { } /* Terminating entry */
195};
196
197#define BTUSB_MAX_ISOC_FRAMES 10
198
199#define BTUSB_INTR_RUNNING 0
200#define BTUSB_BULK_RUNNING 1
201#define BTUSB_ISOC_RUNNING 2
202#define BTUSB_SUSPENDING 3
203#define BTUSB_DID_ISO_RESUME 4
204
205struct btusb_data {
206 struct hci_dev *hdev;
207 struct usb_device *udev;
208 struct usb_interface *intf;
209 struct usb_interface *isoc;
210
211 spinlock_t lock;
212
213 unsigned long flags;
214
215 struct work_struct work;
216 struct work_struct waker;
217
218 struct usb_anchor tx_anchor;
219 struct usb_anchor intr_anchor;
220 struct usb_anchor bulk_anchor;
221 struct usb_anchor isoc_anchor;
222 struct usb_anchor deferred;
223 int tx_in_flight;
224 spinlock_t txlock;
225
226 struct usb_endpoint_descriptor *intr_ep;
227 struct usb_endpoint_descriptor *bulk_tx_ep;
228 struct usb_endpoint_descriptor *bulk_rx_ep;
229 struct usb_endpoint_descriptor *isoc_tx_ep;
230 struct usb_endpoint_descriptor *isoc_rx_ep;
231
232 __u8 cmdreq_type;
233
234 unsigned int sco_num;
235 int isoc_altsetting;
236 int suspend_count;
237};
238
239static int inc_tx(struct btusb_data *data)
240{
241 unsigned long flags;
242 int rv;
243
244 spin_lock_irqsave(&data->txlock, flags);
245 rv = test_bit(BTUSB_SUSPENDING, &data->flags);
246 if (!rv)
247 data->tx_in_flight++;
248 spin_unlock_irqrestore(&data->txlock, flags);
249
250 return rv;
251}
252
253static void btusb_intr_complete(struct urb *urb)
254{
255 struct hci_dev *hdev = urb->context;
256 struct btusb_data *data = hci_get_drvdata(hdev);
257 int err;
258
259 BT_DBG("%s urb %p status %d count %d", hdev->name,
260 urb, urb->status, urb->actual_length);
261
262 if (!test_bit(HCI_RUNNING, &hdev->flags))
263 return;
264
265 if (urb->status == 0) {
266 hdev->stat.byte_rx += urb->actual_length;
267
268 if (hci_recv_fragment(hdev, HCI_EVENT_PKT,
269 urb->transfer_buffer,
270 urb->actual_length) < 0) {
271 BT_ERR("%s corrupted event packet", hdev->name);
272 hdev->stat.err_rx++;
273 }
274 }
275
276 if (!test_bit(BTUSB_INTR_RUNNING, &data->flags))
277 return;
278
279 usb_mark_last_busy(data->udev);
280 usb_anchor_urb(urb, &data->intr_anchor);
281
282 err = usb_submit_urb(urb, GFP_ATOMIC);
283 if (err < 0) {
284 /* -EPERM: urb is being killed;
285 * -ENODEV: device got disconnected */
286 if (err != -EPERM && err != -ENODEV)
287 BT_ERR("%s urb %p failed to resubmit (%d)",
288 hdev->name, urb, -err);
289 usb_unanchor_urb(urb);
290 }
291}
292
293static int btusb_submit_intr_urb(struct hci_dev *hdev, gfp_t mem_flags)
294{
295 struct btusb_data *data = hci_get_drvdata(hdev);
296 struct urb *urb;
297 unsigned char *buf;
298 unsigned int pipe;
299 int err, size;
300
301 BT_DBG("%s", hdev->name);
302
303 if (!data->intr_ep)
304 return -ENODEV;
305
306 urb = usb_alloc_urb(0, mem_flags);
307 if (!urb)
308 return -ENOMEM;
309
310 size = le16_to_cpu(data->intr_ep->wMaxPacketSize);
311
312 buf = kmalloc(size, mem_flags);
313 if (!buf) {
314 usb_free_urb(urb);
315 return -ENOMEM;
316 }
317
318 pipe = usb_rcvintpipe(data->udev, data->intr_ep->bEndpointAddress);
319
320 usb_fill_int_urb(urb, data->udev, pipe, buf, size,
321 btusb_intr_complete, hdev,
322 data->intr_ep->bInterval);
323
324 urb->transfer_flags |= URB_FREE_BUFFER;
325
326 usb_anchor_urb(urb, &data->intr_anchor);
327
328 err = usb_submit_urb(urb, mem_flags);
329 if (err < 0) {
330 if (err != -EPERM && err != -ENODEV)
331 BT_ERR("%s urb %p submission failed (%d)",
332 hdev->name, urb, -err);
333 usb_unanchor_urb(urb);
334 }
335
336 usb_free_urb(urb);
337
338 return err;
339}
340
341static void btusb_bulk_complete(struct urb *urb)
342{
343 struct hci_dev *hdev = urb->context;
344 struct btusb_data *data = hci_get_drvdata(hdev);
345 int err;
346
347 BT_DBG("%s urb %p status %d count %d", hdev->name,
348 urb, urb->status, urb->actual_length);
349
350 if (!test_bit(HCI_RUNNING, &hdev->flags))
351 return;
352
353 if (urb->status == 0) {
354 hdev->stat.byte_rx += urb->actual_length;
355
356 if (hci_recv_fragment(hdev, HCI_ACLDATA_PKT,
357 urb->transfer_buffer,
358 urb->actual_length) < 0) {
359 BT_ERR("%s corrupted ACL packet", hdev->name);
360 hdev->stat.err_rx++;
361 }
362 }
363
364 if (!test_bit(BTUSB_BULK_RUNNING, &data->flags))
365 return;
366
367 usb_anchor_urb(urb, &data->bulk_anchor);
368 usb_mark_last_busy(data->udev);
369
370 err = usb_submit_urb(urb, GFP_ATOMIC);
371 if (err < 0) {
372 /* -EPERM: urb is being killed;
373 * -ENODEV: device got disconnected */
374 if (err != -EPERM && err != -ENODEV)
375 BT_ERR("%s urb %p failed to resubmit (%d)",
376 hdev->name, urb, -err);
377 usb_unanchor_urb(urb);
378 }
379}
380
381static int btusb_submit_bulk_urb(struct hci_dev *hdev, gfp_t mem_flags)
382{
383 struct btusb_data *data = hci_get_drvdata(hdev);
384 struct urb *urb;
385 unsigned char *buf;
386 unsigned int pipe;
387 int err, size = HCI_MAX_FRAME_SIZE;
388
389 BT_DBG("%s", hdev->name);
390
391 if (!data->bulk_rx_ep)
392 return -ENODEV;
393
394 urb = usb_alloc_urb(0, mem_flags);
395 if (!urb)
396 return -ENOMEM;
397
398 buf = kmalloc(size, mem_flags);
399 if (!buf) {
400 usb_free_urb(urb);
401 return -ENOMEM;
402 }
403
404 pipe = usb_rcvbulkpipe(data->udev, data->bulk_rx_ep->bEndpointAddress);
405
406 usb_fill_bulk_urb(urb, data->udev, pipe,
407 buf, size, btusb_bulk_complete, hdev);
408
409 urb->transfer_flags |= URB_FREE_BUFFER;
410
411 usb_mark_last_busy(data->udev);
412 usb_anchor_urb(urb, &data->bulk_anchor);
413
414 err = usb_submit_urb(urb, mem_flags);
415 if (err < 0) {
416 if (err != -EPERM && err != -ENODEV)
417 BT_ERR("%s urb %p submission failed (%d)",
418 hdev->name, urb, -err);
419 usb_unanchor_urb(urb);
420 }
421
422 usb_free_urb(urb);
423
424 return err;
425}
426
427static void btusb_isoc_complete(struct urb *urb)
428{
429 struct hci_dev *hdev = urb->context;
430 struct btusb_data *data = hci_get_drvdata(hdev);
431 int i, err;
432
433 BT_DBG("%s urb %p status %d count %d", hdev->name,
434 urb, urb->status, urb->actual_length);
435
436 if (!test_bit(HCI_RUNNING, &hdev->flags))
437 return;
438
439 if (urb->status == 0) {
440 for (i = 0; i < urb->number_of_packets; i++) {
441 unsigned int offset = urb->iso_frame_desc[i].offset;
442 unsigned int length = urb->iso_frame_desc[i].actual_length;
443
444 if (urb->iso_frame_desc[i].status)
445 continue;
446
447 hdev->stat.byte_rx += length;
448
449 if (hci_recv_fragment(hdev, HCI_SCODATA_PKT,
450 urb->transfer_buffer + offset,
451 length) < 0) {
452 BT_ERR("%s corrupted SCO packet", hdev->name);
453 hdev->stat.err_rx++;
454 }
455 }
456 }
457
458 if (!test_bit(BTUSB_ISOC_RUNNING, &data->flags))
459 return;
460
461 usb_anchor_urb(urb, &data->isoc_anchor);
462
463 err = usb_submit_urb(urb, GFP_ATOMIC);
464 if (err < 0) {
465 /* -EPERM: urb is being killed;
466 * -ENODEV: device got disconnected */
467 if (err != -EPERM && err != -ENODEV)
468 BT_ERR("%s urb %p failed to resubmit (%d)",
469 hdev->name, urb, -err);
470 usb_unanchor_urb(urb);
471 }
472}
473
474static inline void __fill_isoc_descriptor(struct urb *urb, int len, int mtu)
475{
476 int i, offset = 0;
477
478 BT_DBG("len %d mtu %d", len, mtu);
479
480 for (i = 0; i < BTUSB_MAX_ISOC_FRAMES && len >= mtu;
481 i++, offset += mtu, len -= mtu) {
482 urb->iso_frame_desc[i].offset = offset;
483 urb->iso_frame_desc[i].length = mtu;
484 }
485
486 if (len && i < BTUSB_MAX_ISOC_FRAMES) {
487 urb->iso_frame_desc[i].offset = offset;
488 urb->iso_frame_desc[i].length = len;
489 i++;
490 }
491
492 urb->number_of_packets = i;
493}
494
495static int btusb_submit_isoc_urb(struct hci_dev *hdev, gfp_t mem_flags)
496{
497 struct btusb_data *data = hci_get_drvdata(hdev);
498 struct urb *urb;
499 unsigned char *buf;
500 unsigned int pipe;
501 int err, size;
502
503 BT_DBG("%s", hdev->name);
504
505 if (!data->isoc_rx_ep)
506 return -ENODEV;
507
508 urb = usb_alloc_urb(BTUSB_MAX_ISOC_FRAMES, mem_flags);
509 if (!urb)
510 return -ENOMEM;
511
512 size = le16_to_cpu(data->isoc_rx_ep->wMaxPacketSize) *
513 BTUSB_MAX_ISOC_FRAMES;
514
515 buf = kmalloc(size, mem_flags);
516 if (!buf) {
517 usb_free_urb(urb);
518 return -ENOMEM;
519 }
520
521 pipe = usb_rcvisocpipe(data->udev, data->isoc_rx_ep->bEndpointAddress);
522
523 usb_fill_int_urb(urb, data->udev, pipe, buf, size, btusb_isoc_complete,
524 hdev, data->isoc_rx_ep->bInterval);
525
526 urb->transfer_flags = URB_FREE_BUFFER | URB_ISO_ASAP;
527
528 __fill_isoc_descriptor(urb, size,
529 le16_to_cpu(data->isoc_rx_ep->wMaxPacketSize));
530
531 usb_anchor_urb(urb, &data->isoc_anchor);
532
533 err = usb_submit_urb(urb, mem_flags);
534 if (err < 0) {
535 if (err != -EPERM && err != -ENODEV)
536 BT_ERR("%s urb %p submission failed (%d)",
537 hdev->name, urb, -err);
538 usb_unanchor_urb(urb);
539 }
540
541 usb_free_urb(urb);
542
543 return err;
544}
545
546static void btusb_tx_complete(struct urb *urb)
547{
548 struct sk_buff *skb = urb->context;
549 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
550 struct btusb_data *data = hci_get_drvdata(hdev);
551
552 BT_DBG("%s urb %p status %d count %d", hdev->name,
553 urb, urb->status, urb->actual_length);
554
555 if (!test_bit(HCI_RUNNING, &hdev->flags))
556 goto done;
557
558 if (!urb->status)
559 hdev->stat.byte_tx += urb->transfer_buffer_length;
560 else
561 hdev->stat.err_tx++;
562
563done:
564 spin_lock(&data->txlock);
565 data->tx_in_flight--;
566 spin_unlock(&data->txlock);
567
568 kfree(urb->setup_packet);
569
570 kfree_skb(skb);
571}
572
573static void btusb_isoc_tx_complete(struct urb *urb)
574{
575 struct sk_buff *skb = urb->context;
576 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
577
578 BT_DBG("%s urb %p status %d count %d", hdev->name,
579 urb, urb->status, urb->actual_length);
580
581 if (!test_bit(HCI_RUNNING, &hdev->flags))
582 goto done;
583
584 if (!urb->status)
585 hdev->stat.byte_tx += urb->transfer_buffer_length;
586 else
587 hdev->stat.err_tx++;
588
589done:
590 kfree(urb->setup_packet);
591
592 kfree_skb(skb);
593}
594
595static int btusb_open(struct hci_dev *hdev)
596{
597 struct btusb_data *data = hci_get_drvdata(hdev);
598 int err;
599
600 BT_DBG("%s", hdev->name);
601
602 err = usb_autopm_get_interface(data->intf);
603 if (err < 0)
604 return err;
605
606 data->intf->needs_remote_wakeup = 1;
607
608 if (test_and_set_bit(HCI_RUNNING, &hdev->flags))
609 goto done;
610
611 if (test_and_set_bit(BTUSB_INTR_RUNNING, &data->flags))
612 goto done;
613
614 err = btusb_submit_intr_urb(hdev, GFP_KERNEL);
615 if (err < 0)
616 goto failed;
617
618 err = btusb_submit_bulk_urb(hdev, GFP_KERNEL);
619 if (err < 0) {
620 usb_kill_anchored_urbs(&data->intr_anchor);
621 goto failed;
622 }
623
624 set_bit(BTUSB_BULK_RUNNING, &data->flags);
625 btusb_submit_bulk_urb(hdev, GFP_KERNEL);
626
627done:
628 usb_autopm_put_interface(data->intf);
629 return 0;
630
631failed:
632 clear_bit(BTUSB_INTR_RUNNING, &data->flags);
633 clear_bit(HCI_RUNNING, &hdev->flags);
634 usb_autopm_put_interface(data->intf);
635 return err;
636}
637
638static void btusb_stop_traffic(struct btusb_data *data)
639{
640 usb_kill_anchored_urbs(&data->intr_anchor);
641 usb_kill_anchored_urbs(&data->bulk_anchor);
642 usb_kill_anchored_urbs(&data->isoc_anchor);
643}
644
645static int btusb_close(struct hci_dev *hdev)
646{
647 struct btusb_data *data = hci_get_drvdata(hdev);
648 int err;
649
650 BT_DBG("%s", hdev->name);
651
652 if (!test_and_clear_bit(HCI_RUNNING, &hdev->flags))
653 return 0;
654
655 cancel_work_sync(&data->work);
656 cancel_work_sync(&data->waker);
657
658 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
659 clear_bit(BTUSB_BULK_RUNNING, &data->flags);
660 clear_bit(BTUSB_INTR_RUNNING, &data->flags);
661
662 btusb_stop_traffic(data);
663 err = usb_autopm_get_interface(data->intf);
664 if (err < 0)
665 goto failed;
666
667 data->intf->needs_remote_wakeup = 0;
668 usb_autopm_put_interface(data->intf);
669
670failed:
671 usb_scuttle_anchored_urbs(&data->deferred);
672 return 0;
673}
674
675static int btusb_flush(struct hci_dev *hdev)
676{
677 struct btusb_data *data = hci_get_drvdata(hdev);
678
679 BT_DBG("%s", hdev->name);
680
681 usb_kill_anchored_urbs(&data->tx_anchor);
682
683 return 0;
684}
685
686static int btusb_send_frame(struct sk_buff *skb)
687{
688 struct hci_dev *hdev = (struct hci_dev *) skb->dev;
689 struct btusb_data *data = hci_get_drvdata(hdev);
690 struct usb_ctrlrequest *dr;
691 struct urb *urb;
692 unsigned int pipe;
693 int err;
694
695 BT_DBG("%s", hdev->name);
696
697 if (!test_bit(HCI_RUNNING, &hdev->flags))
698 return -EBUSY;
699
700 switch (bt_cb(skb)->pkt_type) {
701 case HCI_COMMAND_PKT:
702 urb = usb_alloc_urb(0, GFP_ATOMIC);
703 if (!urb)
704 return -ENOMEM;
705
706 dr = kmalloc(sizeof(*dr), GFP_ATOMIC);
707 if (!dr) {
708 usb_free_urb(urb);
709 return -ENOMEM;
710 }
711
712 dr->bRequestType = data->cmdreq_type;
713 dr->bRequest = 0;
714 dr->wIndex = 0;
715 dr->wValue = 0;
716 dr->wLength = __cpu_to_le16(skb->len);
717
718 pipe = usb_sndctrlpipe(data->udev, 0x00);
719
720 usb_fill_control_urb(urb, data->udev, pipe, (void *) dr,
721 skb->data, skb->len, btusb_tx_complete, skb);
722
723 hdev->stat.cmd_tx++;
724 break;
725
726 case HCI_ACLDATA_PKT:
727 if (!data->bulk_tx_ep)
728 return -ENODEV;
729
730 urb = usb_alloc_urb(0, GFP_ATOMIC);
731 if (!urb)
732 return -ENOMEM;
733
734 pipe = usb_sndbulkpipe(data->udev,
735 data->bulk_tx_ep->bEndpointAddress);
736
737 usb_fill_bulk_urb(urb, data->udev, pipe,
738 skb->data, skb->len, btusb_tx_complete, skb);
739
740 hdev->stat.acl_tx++;
741 break;
742
743 case HCI_SCODATA_PKT:
744 if (!data->isoc_tx_ep || hdev->conn_hash.sco_num < 1)
745 return -ENODEV;
746
747 urb = usb_alloc_urb(BTUSB_MAX_ISOC_FRAMES, GFP_ATOMIC);
748 if (!urb)
749 return -ENOMEM;
750
751 pipe = usb_sndisocpipe(data->udev,
752 data->isoc_tx_ep->bEndpointAddress);
753
754 usb_fill_int_urb(urb, data->udev, pipe,
755 skb->data, skb->len, btusb_isoc_tx_complete,
756 skb, data->isoc_tx_ep->bInterval);
757
758 urb->transfer_flags = URB_ISO_ASAP;
759
760 __fill_isoc_descriptor(urb, skb->len,
761 le16_to_cpu(data->isoc_tx_ep->wMaxPacketSize));
762
763 hdev->stat.sco_tx++;
764 goto skip_waking;
765
766 default:
767 return -EILSEQ;
768 }
769
770 err = inc_tx(data);
771 if (err) {
772 usb_anchor_urb(urb, &data->deferred);
773 schedule_work(&data->waker);
774 err = 0;
775 goto done;
776 }
777
778skip_waking:
779 usb_anchor_urb(urb, &data->tx_anchor);
780
781 err = usb_submit_urb(urb, GFP_ATOMIC);
782 if (err < 0) {
783 if (err != -EPERM && err != -ENODEV)
784 BT_ERR("%s urb %p submission failed (%d)",
785 hdev->name, urb, -err);
786 kfree(urb->setup_packet);
787 usb_unanchor_urb(urb);
788 } else {
789 usb_mark_last_busy(data->udev);
790 }
791
792done:
793 usb_free_urb(urb);
794 return err;
795}
796
797static void btusb_notify(struct hci_dev *hdev, unsigned int evt)
798{
799 struct btusb_data *data = hci_get_drvdata(hdev);
800
801 BT_DBG("%s evt %d", hdev->name, evt);
802
803 if (hdev->conn_hash.sco_num != data->sco_num) {
804 data->sco_num = hdev->conn_hash.sco_num;
805 schedule_work(&data->work);
806 }
807}
808
809static inline int __set_isoc_interface(struct hci_dev *hdev, int altsetting)
810{
811 struct btusb_data *data = hci_get_drvdata(hdev);
812 struct usb_interface *intf = data->isoc;
813 struct usb_endpoint_descriptor *ep_desc;
814 int i, err;
815
816 if (!data->isoc)
817 return -ENODEV;
818
819 err = usb_set_interface(data->udev, 1, altsetting);
820 if (err < 0) {
821 BT_ERR("%s setting interface failed (%d)", hdev->name, -err);
822 return err;
823 }
824
825 data->isoc_altsetting = altsetting;
826
827 data->isoc_tx_ep = NULL;
828 data->isoc_rx_ep = NULL;
829
830 for (i = 0; i < intf->cur_altsetting->desc.bNumEndpoints; i++) {
831 ep_desc = &intf->cur_altsetting->endpoint[i].desc;
832
833 if (!data->isoc_tx_ep && usb_endpoint_is_isoc_out(ep_desc)) {
834 data->isoc_tx_ep = ep_desc;
835 continue;
836 }
837
838 if (!data->isoc_rx_ep && usb_endpoint_is_isoc_in(ep_desc)) {
839 data->isoc_rx_ep = ep_desc;
840 continue;
841 }
842 }
843
844 if (!data->isoc_tx_ep || !data->isoc_rx_ep) {
845 BT_ERR("%s invalid SCO descriptors", hdev->name);
846 return -ENODEV;
847 }
848
849 return 0;
850}
851
852static void btusb_work(struct work_struct *work)
853{
854 struct btusb_data *data = container_of(work, struct btusb_data, work);
855 struct hci_dev *hdev = data->hdev;
856 int new_alts;
857 int err;
858
859 if (hdev->conn_hash.sco_num > 0) {
860 if (!test_bit(BTUSB_DID_ISO_RESUME, &data->flags)) {
861 err = usb_autopm_get_interface(data->isoc ? data->isoc : data->intf);
862 if (err < 0) {
863 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
864 usb_kill_anchored_urbs(&data->isoc_anchor);
865 return;
866 }
867
868 set_bit(BTUSB_DID_ISO_RESUME, &data->flags);
869 }
870
871 if (hdev->voice_setting & 0x0020) {
872 static const int alts[3] = { 2, 4, 5 };
873 new_alts = alts[hdev->conn_hash.sco_num - 1];
874 } else {
875 new_alts = hdev->conn_hash.sco_num;
876 }
877
878 if (data->isoc_altsetting != new_alts) {
879 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
880 usb_kill_anchored_urbs(&data->isoc_anchor);
881
882 if (__set_isoc_interface(hdev, new_alts) < 0)
883 return;
884 }
885
886 if (!test_and_set_bit(BTUSB_ISOC_RUNNING, &data->flags)) {
887 if (btusb_submit_isoc_urb(hdev, GFP_KERNEL) < 0)
888 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
889 else
890 btusb_submit_isoc_urb(hdev, GFP_KERNEL);
891 }
892 } else {
893 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
894 usb_kill_anchored_urbs(&data->isoc_anchor);
895
896 __set_isoc_interface(hdev, 0);
897 if (test_and_clear_bit(BTUSB_DID_ISO_RESUME, &data->flags))
898 usb_autopm_put_interface(data->isoc ? data->isoc : data->intf);
899 }
900}
901
902static void btusb_waker(struct work_struct *work)
903{
904 struct btusb_data *data = container_of(work, struct btusb_data, waker);
905 int err;
906
907 err = usb_autopm_get_interface(data->intf);
908 if (err < 0)
909 return;
910
911 usb_autopm_put_interface(data->intf);
912}
913
914static int btusb_probe(struct usb_interface *intf,
915 const struct usb_device_id *id)
916{
917 struct usb_endpoint_descriptor *ep_desc;
918 struct btusb_data *data;
919 struct hci_dev *hdev;
920 int i, err;
921
922 BT_DBG("intf %p id %p", intf, id);
923
924 /* interface numbers are hardcoded in the spec */
925 if (intf->cur_altsetting->desc.bInterfaceNumber != 0)
926 return -ENODEV;
927
928 if (!id->driver_info) {
929 const struct usb_device_id *match;
930 match = usb_match_id(intf, blacklist_table);
931 if (match)
932 id = match;
933 }
934
935 if (id->driver_info == BTUSB_IGNORE)
936 return -ENODEV;
937
938 if (ignore_dga && id->driver_info & BTUSB_DIGIANSWER)
939 return -ENODEV;
940
941 if (ignore_csr && id->driver_info & BTUSB_CSR)
942 return -ENODEV;
943
944 if (ignore_sniffer && id->driver_info & BTUSB_SNIFFER)
945 return -ENODEV;
946
947 if (id->driver_info & BTUSB_ATH3012) {
948 struct usb_device *udev = interface_to_usbdev(intf);
949
950 /* Old firmware would otherwise let ath3k driver load
951 * patch and sysconfig files */
952 if (le16_to_cpu(udev->descriptor.bcdDevice) <= 0x0001)
953 return -ENODEV;
954 }
955
956 data = kzalloc(sizeof(*data), GFP_KERNEL);
957 if (!data)
958 return -ENOMEM;
959
960 for (i = 0; i < intf->cur_altsetting->desc.bNumEndpoints; i++) {
961 ep_desc = &intf->cur_altsetting->endpoint[i].desc;
962
963 if (!data->intr_ep && usb_endpoint_is_int_in(ep_desc)) {
964 data->intr_ep = ep_desc;
965 continue;
966 }
967
968 if (!data->bulk_tx_ep && usb_endpoint_is_bulk_out(ep_desc)) {
969 data->bulk_tx_ep = ep_desc;
970 continue;
971 }
972
973 if (!data->bulk_rx_ep && usb_endpoint_is_bulk_in(ep_desc)) {
974 data->bulk_rx_ep = ep_desc;
975 continue;
976 }
977 }
978
979 if (!data->intr_ep || !data->bulk_tx_ep || !data->bulk_rx_ep) {
980 kfree(data);
981 return -ENODEV;
982 }
983
984 data->cmdreq_type = USB_TYPE_CLASS;
985
986 data->udev = interface_to_usbdev(intf);
987 data->intf = intf;
988
989 spin_lock_init(&data->lock);
990
991 INIT_WORK(&data->work, btusb_work);
992 INIT_WORK(&data->waker, btusb_waker);
993 spin_lock_init(&data->txlock);
994
995 init_usb_anchor(&data->tx_anchor);
996 init_usb_anchor(&data->intr_anchor);
997 init_usb_anchor(&data->bulk_anchor);
998 init_usb_anchor(&data->isoc_anchor);
999 init_usb_anchor(&data->deferred);
1000
1001 hdev = hci_alloc_dev();
1002 if (!hdev) {
1003 kfree(data);
1004 return -ENOMEM;
1005 }
1006
1007 hdev->bus = HCI_USB;
1008 hci_set_drvdata(hdev, data);
1009
1010 data->hdev = hdev;
1011
1012 SET_HCIDEV_DEV(hdev, &intf->dev);
1013
1014 hdev->open = btusb_open;
1015 hdev->close = btusb_close;
1016 hdev->flush = btusb_flush;
1017 hdev->send = btusb_send_frame;
1018 hdev->notify = btusb_notify;
1019
1020 /* Interface numbers are hardcoded in the specification */
1021 data->isoc = usb_ifnum_to_if(data->udev, 1);
1022
1023 if (!reset)
1024 set_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks);
1025
1026 if (force_scofix || id->driver_info & BTUSB_WRONG_SCO_MTU) {
1027 if (!disable_scofix)
1028 set_bit(HCI_QUIRK_FIXUP_BUFFER_SIZE, &hdev->quirks);
1029 }
1030
1031 if (id->driver_info & BTUSB_BROKEN_ISOC)
1032 data->isoc = NULL;
1033
1034 if (id->driver_info & BTUSB_DIGIANSWER) {
1035 data->cmdreq_type = USB_TYPE_VENDOR;
1036 set_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks);
1037 }
1038
1039 if (id->driver_info & BTUSB_CSR) {
1040 struct usb_device *udev = data->udev;
1041
1042 /* Old firmware would otherwise execute USB reset */
1043 if (le16_to_cpu(udev->descriptor.bcdDevice) < 0x117)
1044 set_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks);
1045 }
1046
1047 if (id->driver_info & BTUSB_SNIFFER) {
1048 struct usb_device *udev = data->udev;
1049
1050 /* New sniffer firmware has crippled HCI interface */
1051 if (le16_to_cpu(udev->descriptor.bcdDevice) > 0x997)
1052 set_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks);
1053
1054 data->isoc = NULL;
1055 }
1056
1057 if (id->driver_info & BTUSB_BCM92035) {
1058 unsigned char cmd[] = { 0x3b, 0xfc, 0x01, 0x00 };
1059 struct sk_buff *skb;
1060
1061 skb = bt_skb_alloc(sizeof(cmd), GFP_KERNEL);
1062 if (skb) {
1063 memcpy(skb_put(skb, sizeof(cmd)), cmd, sizeof(cmd));
1064 skb_queue_tail(&hdev->driver_init, skb);
1065 }
1066 }
1067
1068 if (data->isoc) {
1069 err = usb_driver_claim_interface(&btusb_driver,
1070 data->isoc, data);
1071 if (err < 0) {
1072 hci_free_dev(hdev);
1073 kfree(data);
1074 return err;
1075 }
1076 }
1077
1078 err = hci_register_dev(hdev);
1079 if (err < 0) {
1080 hci_free_dev(hdev);
1081 kfree(data);
1082 return err;
1083 }
1084
1085 usb_set_intfdata(intf, data);
1086
1087 return 0;
1088}
1089
1090static void btusb_disconnect(struct usb_interface *intf)
1091{
1092 struct btusb_data *data = usb_get_intfdata(intf);
1093 struct hci_dev *hdev;
1094
1095 BT_DBG("intf %p", intf);
1096
1097 if (!data)
1098 return;
1099
1100 hdev = data->hdev;
1101 usb_set_intfdata(data->intf, NULL);
1102
1103 if (data->isoc)
1104 usb_set_intfdata(data->isoc, NULL);
1105
1106 hci_unregister_dev(hdev);
1107
1108 if (intf == data->isoc)
1109 usb_driver_release_interface(&btusb_driver, data->intf);
1110 else if (data->isoc)
1111 usb_driver_release_interface(&btusb_driver, data->isoc);
1112
1113 hci_free_dev(hdev);
1114 kfree(data);
1115}
1116
1117#ifdef CONFIG_PM
1118static int btusb_suspend(struct usb_interface *intf, pm_message_t message)
1119{
1120 struct btusb_data *data = usb_get_intfdata(intf);
1121
1122 BT_DBG("intf %p", intf);
1123
1124 if (data->suspend_count++)
1125 return 0;
1126
1127 spin_lock_irq(&data->txlock);
1128 if (!(PMSG_IS_AUTO(message) && data->tx_in_flight)) {
1129 set_bit(BTUSB_SUSPENDING, &data->flags);
1130 spin_unlock_irq(&data->txlock);
1131 } else {
1132 spin_unlock_irq(&data->txlock);
1133 data->suspend_count--;
1134 return -EBUSY;
1135 }
1136
1137 cancel_work_sync(&data->work);
1138
1139 btusb_stop_traffic(data);
1140 usb_kill_anchored_urbs(&data->tx_anchor);
1141
1142 return 0;
1143}
1144
1145static void play_deferred(struct btusb_data *data)
1146{
1147 struct urb *urb;
1148 int err;
1149
1150 while ((urb = usb_get_from_anchor(&data->deferred))) {
1151 err = usb_submit_urb(urb, GFP_ATOMIC);
1152 if (err < 0)
1153 break;
1154
1155 data->tx_in_flight++;
1156 }
1157 usb_scuttle_anchored_urbs(&data->deferred);
1158}
1159
1160static int btusb_resume(struct usb_interface *intf)
1161{
1162 struct btusb_data *data = usb_get_intfdata(intf);
1163 struct hci_dev *hdev = data->hdev;
1164 int err = 0;
1165
1166 BT_DBG("intf %p", intf);
1167
1168 if (--data->suspend_count)
1169 return 0;
1170
1171 if (!test_bit(HCI_RUNNING, &hdev->flags))
1172 goto done;
1173
1174 if (test_bit(BTUSB_INTR_RUNNING, &data->flags)) {
1175 err = btusb_submit_intr_urb(hdev, GFP_NOIO);
1176 if (err < 0) {
1177 clear_bit(BTUSB_INTR_RUNNING, &data->flags);
1178 goto failed;
1179 }
1180 }
1181
1182 if (test_bit(BTUSB_BULK_RUNNING, &data->flags)) {
1183 err = btusb_submit_bulk_urb(hdev, GFP_NOIO);
1184 if (err < 0) {
1185 clear_bit(BTUSB_BULK_RUNNING, &data->flags);
1186 goto failed;
1187 }
1188
1189 btusb_submit_bulk_urb(hdev, GFP_NOIO);
1190 }
1191
1192 if (test_bit(BTUSB_ISOC_RUNNING, &data->flags)) {
1193 if (btusb_submit_isoc_urb(hdev, GFP_NOIO) < 0)
1194 clear_bit(BTUSB_ISOC_RUNNING, &data->flags);
1195 else
1196 btusb_submit_isoc_urb(hdev, GFP_NOIO);
1197 }
1198
1199 spin_lock_irq(&data->txlock);
1200 play_deferred(data);
1201 clear_bit(BTUSB_SUSPENDING, &data->flags);
1202 spin_unlock_irq(&data->txlock);
1203 schedule_work(&data->work);
1204
1205 return 0;
1206
1207failed:
1208 usb_scuttle_anchored_urbs(&data->deferred);
1209done:
1210 spin_lock_irq(&data->txlock);
1211 clear_bit(BTUSB_SUSPENDING, &data->flags);
1212 spin_unlock_irq(&data->txlock);
1213
1214 return err;
1215}
1216#endif
1217
1218static struct usb_driver btusb_driver = {
1219 .name = "btusb",
1220 .probe = btusb_probe,
1221 .disconnect = btusb_disconnect,
1222#ifdef CONFIG_PM
1223 .suspend = btusb_suspend,
1224 .resume = btusb_resume,
1225#endif
1226 .id_table = btusb_table,
1227 .supports_autosuspend = 1,
1228 .disable_hub_initiated_lpm = 1,
1229};
1230
1231module_usb_driver(btusb_driver);
1232
1233module_param(ignore_dga, bool, 0644);
1234MODULE_PARM_DESC(ignore_dga, "Ignore devices with id 08fd:0001");
1235
1236module_param(ignore_csr, bool, 0644);
1237MODULE_PARM_DESC(ignore_csr, "Ignore devices with id 0a12:0001");
1238
1239module_param(ignore_sniffer, bool, 0644);
1240MODULE_PARM_DESC(ignore_sniffer, "Ignore devices with id 0a12:0002");
1241
1242module_param(disable_scofix, bool, 0644);
1243MODULE_PARM_DESC(disable_scofix, "Disable fixup of wrong SCO buffer size");
1244
1245module_param(force_scofix, bool, 0644);
1246MODULE_PARM_DESC(force_scofix, "Force fixup of wrong SCO buffers size");
1247
1248module_param(reset, bool, 0644);
1249MODULE_PARM_DESC(reset, "Send HCI reset command on initialization");
1250
1251MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
1252MODULE_DESCRIPTION("Generic Bluetooth USB driver ver " VERSION);
1253MODULE_VERSION(VERSION);
1254MODULE_LICENSE("GPL");