1 // SPDX-License-Identifier: GPL-2.0-or-later
4 * Bluetooth HCI UART driver
6 * Copyright (C) 2000-2001 Qualcomm Incorporated
7 * Copyright (C) 2002-2003 Maxim Krasnyansky <maxk@qualcomm.com>
8 * Copyright (C) 2004-2005 Marcel Holtmann <marcel@holtmann.org>
11 #include <linux/module.h>
13 #include <linux/kernel.h>
14 #include <linux/init.h>
15 #include <linux/types.h>
16 #include <linux/fcntl.h>
17 #include <linux/interrupt.h>
18 #include <linux/ptrace.h>
19 #include <linux/poll.h>
21 #include <linux/slab.h>
22 #include <linux/tty.h>
23 #include <linux/errno.h>
24 #include <linux/string.h>
25 #include <linux/signal.h>
26 #include <linux/ioctl.h>
27 #include <linux/skbuff.h>
28 #include <linux/firmware.h>
29 #include <linux/serdev.h>
31 #include <net/bluetooth/bluetooth.h>
32 #include <net/bluetooth/hci_core.h>
40 static const struct hci_uart_proto *hup[HCI_UART_MAX_PROTO];
42 int hci_uart_register_proto(const struct hci_uart_proto *p)
44 if (p->id >= HCI_UART_MAX_PROTO)
52 BT_INFO("HCI UART protocol %s registered", p->name);
57 int hci_uart_unregister_proto(const struct hci_uart_proto *p)
59 if (p->id >= HCI_UART_MAX_PROTO)
70 static const struct hci_uart_proto *hci_uart_get_proto(unsigned int id)
72 if (id >= HCI_UART_MAX_PROTO)
78 static inline void hci_uart_tx_complete(struct hci_uart *hu, int pkt_type)
80 struct hci_dev *hdev = hu->hdev;
82 /* Update HCI stat counters */
98 static inline struct sk_buff *hci_uart_dequeue(struct hci_uart *hu)
100 struct sk_buff *skb = hu->tx_skb;
103 percpu_down_read(&hu->proto_lock);
105 if (test_bit(HCI_UART_PROTO_READY, &hu->flags) ||
106 test_bit(HCI_UART_PROTO_INIT, &hu->flags))
107 skb = hu->proto->dequeue(hu);
109 percpu_up_read(&hu->proto_lock);
117 int hci_uart_tx_wakeup(struct hci_uart *hu)
119 /* This may be called in an IRQ context, so we can't sleep. Therefore
120 * we try to acquire the lock only, and if that fails we assume the
121 * tty is being closed because that is the only time the write lock is
122 * acquired. If, however, at some point in the future the write lock
123 * is also acquired in other situations, then this must be revisited.
125 if (!percpu_down_read_trylock(&hu->proto_lock))
128 if (!test_bit(HCI_UART_PROTO_READY, &hu->flags) &&
129 !test_bit(HCI_UART_PROTO_INIT, &hu->flags))
132 set_bit(HCI_UART_TX_WAKEUP, &hu->tx_state);
133 if (test_and_set_bit(HCI_UART_SENDING, &hu->tx_state))
138 schedule_work(&hu->write_work);
141 percpu_up_read(&hu->proto_lock);
145 EXPORT_SYMBOL_GPL(hci_uart_tx_wakeup);
147 static void hci_uart_write_work(struct work_struct *work)
149 struct hci_uart *hu = container_of(work, struct hci_uart, write_work);
150 struct tty_struct *tty = hu->tty;
151 struct hci_dev *hdev = hu->hdev;
154 /* REVISIT: should we cope with bad skbs or ->write() returning
159 clear_bit(HCI_UART_TX_WAKEUP, &hu->tx_state);
161 while ((skb = hci_uart_dequeue(hu))) {
164 set_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
165 len = tty->ops->write(tty, skb->data, skb->len);
166 hdev->stat.byte_tx += len;
174 hci_uart_tx_complete(hu, hci_skb_pkt_type(skb));
178 clear_bit(HCI_UART_SENDING, &hu->tx_state);
179 if (test_bit(HCI_UART_TX_WAKEUP, &hu->tx_state))
182 wake_up_bit(&hu->tx_state, HCI_UART_SENDING);
185 void hci_uart_init_work(struct work_struct *work)
187 struct hci_uart *hu = container_of(work, struct hci_uart, init_ready);
189 struct hci_dev *hdev;
191 if (!test_and_clear_bit(HCI_UART_INIT_PENDING, &hu->hdev_flags))
194 err = hci_register_dev(hu->hdev);
196 BT_ERR("Can't register HCI device");
197 clear_bit(HCI_UART_PROTO_READY, &hu->flags);
198 hu->proto->close(hu);
205 set_bit(HCI_UART_REGISTERED, &hu->flags);
208 int hci_uart_init_ready(struct hci_uart *hu)
210 if (!test_bit(HCI_UART_INIT_PENDING, &hu->hdev_flags))
213 schedule_work(&hu->init_ready);
218 int hci_uart_wait_until_sent(struct hci_uart *hu)
220 return wait_on_bit_timeout(&hu->tx_state, HCI_UART_SENDING,
222 msecs_to_jiffies(2000));
225 /* ------- Interface to HCI layer ------ */
227 static int hci_uart_flush(struct hci_dev *hdev)
229 struct hci_uart *hu = hci_get_drvdata(hdev);
230 struct tty_struct *tty = hu->tty;
232 BT_DBG("hdev %p tty %p", hdev, tty);
235 kfree_skb(hu->tx_skb); hu->tx_skb = NULL;
238 /* Flush any pending characters in the driver and discipline. */
239 tty_ldisc_flush(tty);
240 tty_driver_flush_buffer(tty);
242 percpu_down_read(&hu->proto_lock);
244 if (test_bit(HCI_UART_PROTO_READY, &hu->flags))
245 hu->proto->flush(hu);
247 percpu_up_read(&hu->proto_lock);
252 /* Initialize device */
253 static int hci_uart_open(struct hci_dev *hdev)
255 BT_DBG("%s %p", hdev->name, hdev);
257 /* Undo clearing this from hci_uart_close() */
258 hdev->flush = hci_uart_flush;
264 static int hci_uart_close(struct hci_dev *hdev)
266 BT_DBG("hdev %p", hdev);
268 hci_uart_flush(hdev);
273 /* Send frames from HCI layer */
274 static int hci_uart_send_frame(struct hci_dev *hdev, struct sk_buff *skb)
276 struct hci_uart *hu = hci_get_drvdata(hdev);
278 BT_DBG("%s: type %d len %d", hdev->name, hci_skb_pkt_type(skb),
281 percpu_down_read(&hu->proto_lock);
283 if (!test_bit(HCI_UART_PROTO_READY, &hu->flags) &&
284 !test_bit(HCI_UART_PROTO_INIT, &hu->flags)) {
285 percpu_up_read(&hu->proto_lock);
289 hu->proto->enqueue(hu, skb);
290 percpu_up_read(&hu->proto_lock);
292 hci_uart_tx_wakeup(hu);
297 /* Check the underlying device or tty has flow control support */
298 bool hci_uart_has_flow_control(struct hci_uart *hu)
300 /* serdev nodes check if the needed operations are present */
304 if (hu->tty->driver->ops->tiocmget && hu->tty->driver->ops->tiocmset)
310 /* Flow control or un-flow control the device */
311 void hci_uart_set_flow_control(struct hci_uart *hu, bool enable)
313 struct tty_struct *tty = hu->tty;
314 struct ktermios ktermios;
316 unsigned int set = 0;
317 unsigned int clear = 0;
320 serdev_device_set_flow_control(hu->serdev, !enable);
321 serdev_device_set_rts(hu->serdev, !enable);
326 /* Disable hardware flow control */
327 ktermios = tty->termios;
328 ktermios.c_cflag &= ~CRTSCTS;
329 tty_set_termios(tty, &ktermios);
330 BT_DBG("Disabling hardware flow control: %s",
331 (tty->termios.c_cflag & CRTSCTS) ? "failed" : "success");
333 /* Clear RTS to prevent the device from sending */
334 /* Most UARTs need OUT2 to enable interrupts */
335 status = tty->driver->ops->tiocmget(tty);
336 BT_DBG("Current tiocm 0x%x", status);
338 set &= ~(TIOCM_OUT2 | TIOCM_RTS);
340 set &= TIOCM_DTR | TIOCM_RTS | TIOCM_OUT1 |
341 TIOCM_OUT2 | TIOCM_LOOP;
342 clear &= TIOCM_DTR | TIOCM_RTS | TIOCM_OUT1 |
343 TIOCM_OUT2 | TIOCM_LOOP;
344 status = tty->driver->ops->tiocmset(tty, set, clear);
345 BT_DBG("Clearing RTS: %s", status ? "failed" : "success");
347 /* Set RTS to allow the device to send again */
348 status = tty->driver->ops->tiocmget(tty);
349 BT_DBG("Current tiocm 0x%x", status);
351 set |= (TIOCM_OUT2 | TIOCM_RTS);
353 set &= TIOCM_DTR | TIOCM_RTS | TIOCM_OUT1 |
354 TIOCM_OUT2 | TIOCM_LOOP;
355 clear &= TIOCM_DTR | TIOCM_RTS | TIOCM_OUT1 |
356 TIOCM_OUT2 | TIOCM_LOOP;
357 status = tty->driver->ops->tiocmset(tty, set, clear);
358 BT_DBG("Setting RTS: %s", status ? "failed" : "success");
360 /* Re-enable hardware flow control */
361 ktermios = tty->termios;
362 ktermios.c_cflag |= CRTSCTS;
363 tty_set_termios(tty, &ktermios);
364 BT_DBG("Enabling hardware flow control: %s",
365 !(tty->termios.c_cflag & CRTSCTS) ? "failed" : "success");
369 void hci_uart_set_speeds(struct hci_uart *hu, unsigned int init_speed,
370 unsigned int oper_speed)
372 hu->init_speed = init_speed;
373 hu->oper_speed = oper_speed;
376 void hci_uart_set_baudrate(struct hci_uart *hu, unsigned int speed)
378 struct tty_struct *tty = hu->tty;
379 struct ktermios ktermios;
381 ktermios = tty->termios;
382 ktermios.c_cflag &= ~CBAUD;
383 tty_termios_encode_baud_rate(&ktermios, speed, speed);
385 /* tty_set_termios() return not checked as it is always 0 */
386 tty_set_termios(tty, &ktermios);
388 BT_DBG("%s: New tty speeds: %d/%d", hu->hdev->name,
389 tty->termios.c_ispeed, tty->termios.c_ospeed);
392 static int hci_uart_setup(struct hci_dev *hdev)
394 struct hci_uart *hu = hci_get_drvdata(hdev);
395 struct hci_rp_read_local_version *ver;
400 /* Init speed if any */
402 speed = hu->init_speed;
403 else if (hu->proto->init_speed)
404 speed = hu->proto->init_speed;
409 hci_uart_set_baudrate(hu, speed);
411 /* Operational speed if any */
413 speed = hu->oper_speed;
414 else if (hu->proto->oper_speed)
415 speed = hu->proto->oper_speed;
419 if (hu->proto->set_baudrate && speed) {
420 err = hu->proto->set_baudrate(hu, speed);
422 hci_uart_set_baudrate(hu, speed);
425 if (hu->proto->setup)
426 return hu->proto->setup(hu);
428 if (!test_bit(HCI_UART_VND_DETECT, &hu->hdev_flags))
431 skb = __hci_cmd_sync(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL,
434 BT_ERR("%s: Reading local version information failed (%ld)",
435 hdev->name, PTR_ERR(skb));
439 if (skb->len != sizeof(*ver)) {
440 BT_ERR("%s: Event length mismatch for version information",
445 ver = (struct hci_rp_read_local_version *)skb->data;
447 switch (le16_to_cpu(ver->manufacturer)) {
448 #ifdef CONFIG_BT_HCIUART_INTEL
450 hdev->set_bdaddr = btintel_set_bdaddr;
451 btintel_check_bdaddr(hdev);
454 #ifdef CONFIG_BT_HCIUART_BCM
456 hdev->set_bdaddr = btbcm_set_bdaddr;
457 btbcm_check_bdaddr(hdev);
469 /* ------ LDISC part ------ */
472 * Called when line discipline changed to HCI_UART.
475 * tty pointer to tty info structure
477 * 0 if success, otherwise error code
479 static int hci_uart_tty_open(struct tty_struct *tty)
483 BT_DBG("tty %p", tty);
485 if (!capable(CAP_NET_ADMIN))
488 /* Error if the tty has no write op instead of leaving an exploitable
491 if (tty->ops->write == NULL)
494 hu = kzalloc(sizeof(*hu), GFP_KERNEL);
496 BT_ERR("Can't allocate control structure");
499 if (percpu_init_rwsem(&hu->proto_lock)) {
500 BT_ERR("Can't allocate semaphore structure");
507 tty->receive_room = 65536;
509 /* disable alignment support by default */
513 /* Use serial port speed as oper_speed */
514 hu->oper_speed = tty->termios.c_ospeed;
516 INIT_WORK(&hu->init_ready, hci_uart_init_work);
517 INIT_WORK(&hu->write_work, hci_uart_write_work);
519 /* Flush any pending characters in the driver */
520 tty_driver_flush_buffer(tty);
525 /* hci_uart_tty_close()
527 * Called when the line discipline is changed to something
528 * else, the tty is closed, or the tty detects a hangup.
530 static void hci_uart_tty_close(struct tty_struct *tty)
532 struct hci_uart *hu = tty->disc_data;
533 struct hci_dev *hdev;
535 BT_DBG("tty %p", tty);
537 /* Detach from the tty */
538 tty->disc_data = NULL;
545 hci_uart_close(hdev);
547 if (test_bit(HCI_UART_PROTO_READY, &hu->flags)) {
548 percpu_down_write(&hu->proto_lock);
549 clear_bit(HCI_UART_PROTO_READY, &hu->flags);
550 percpu_up_write(&hu->proto_lock);
552 cancel_work_sync(&hu->init_ready);
553 cancel_work_sync(&hu->write_work);
556 if (test_bit(HCI_UART_REGISTERED, &hu->flags))
557 hci_unregister_dev(hdev);
560 hu->proto->close(hu);
562 clear_bit(HCI_UART_PROTO_SET, &hu->flags);
564 percpu_free_rwsem(&hu->proto_lock);
569 /* hci_uart_tty_wakeup()
571 * Callback for transmit wakeup. Called when low level
572 * device driver can accept more send data.
574 * Arguments: tty pointer to associated tty instance data
577 static void hci_uart_tty_wakeup(struct tty_struct *tty)
579 struct hci_uart *hu = tty->disc_data;
586 clear_bit(TTY_DO_WRITE_WAKEUP, &tty->flags);
591 if (test_bit(HCI_UART_PROTO_READY, &hu->flags) ||
592 test_bit(HCI_UART_PROTO_INIT, &hu->flags))
593 hci_uart_tx_wakeup(hu);
596 /* hci_uart_tty_receive()
598 * Called by tty low level driver when receive data is
601 * Arguments: tty pointer to tty instance data
602 * data pointer to received data
603 * flags pointer to flags for data
604 * count count of received data in bytes
608 static void hci_uart_tty_receive(struct tty_struct *tty, const u8 *data,
609 const u8 *flags, size_t count)
611 struct hci_uart *hu = tty->disc_data;
613 if (!hu || tty != hu->tty)
616 percpu_down_read(&hu->proto_lock);
618 if (!test_bit(HCI_UART_PROTO_READY, &hu->flags) &&
619 !test_bit(HCI_UART_PROTO_INIT, &hu->flags)) {
620 percpu_up_read(&hu->proto_lock);
624 /* It does not need a lock here as it is already protected by a mutex in
627 hu->proto->recv(hu, data, count);
628 percpu_up_read(&hu->proto_lock);
631 hu->hdev->stat.byte_rx += count;
636 static int hci_uart_register_dev(struct hci_uart *hu)
638 struct hci_dev *hdev;
643 /* Initialize and register HCI device */
644 hdev = hci_alloc_dev();
646 BT_ERR("Can't allocate HCI device");
652 hdev->bus = HCI_UART;
653 hci_set_drvdata(hdev, hu);
655 /* Only when vendor specific setup callback is provided, consider
656 * the manufacturer information valid. This avoids filling in the
657 * value for Ericsson when nothing is specified.
659 if (hu->proto->setup)
660 hdev->manufacturer = hu->proto->manufacturer;
662 hdev->open = hci_uart_open;
663 hdev->close = hci_uart_close;
664 hdev->flush = hci_uart_flush;
665 hdev->send = hci_uart_send_frame;
666 hdev->setup = hci_uart_setup;
667 SET_HCIDEV_DEV(hdev, hu->tty->dev);
669 if (test_bit(HCI_UART_RAW_DEVICE, &hu->hdev_flags))
670 set_bit(HCI_QUIRK_RAW_DEVICE, &hdev->quirks);
672 if (test_bit(HCI_UART_EXT_CONFIG, &hu->hdev_flags))
673 set_bit(HCI_QUIRK_EXTERNAL_CONFIG, &hdev->quirks);
675 if (!test_bit(HCI_UART_RESET_ON_INIT, &hu->hdev_flags))
676 set_bit(HCI_QUIRK_RESET_ON_CLOSE, &hdev->quirks);
678 /* Only call open() for the protocol after hdev is fully initialized as
679 * open() (or a timer/workqueue it starts) may attempt to reference it.
681 err = hu->proto->open(hu);
688 if (test_bit(HCI_UART_INIT_PENDING, &hu->hdev_flags))
691 if (hci_register_dev(hdev) < 0) {
692 BT_ERR("Can't register HCI device");
693 hu->proto->close(hu);
699 set_bit(HCI_UART_REGISTERED, &hu->flags);
704 static int hci_uart_set_proto(struct hci_uart *hu, int id)
706 const struct hci_uart_proto *p;
709 p = hci_uart_get_proto(id);
711 return -EPROTONOSUPPORT;
715 set_bit(HCI_UART_PROTO_INIT, &hu->flags);
717 err = hci_uart_register_dev(hu);
722 set_bit(HCI_UART_PROTO_READY, &hu->flags);
723 clear_bit(HCI_UART_PROTO_INIT, &hu->flags);
728 static int hci_uart_set_flags(struct hci_uart *hu, unsigned long flags)
730 unsigned long valid_flags = BIT(HCI_UART_RAW_DEVICE) |
731 BIT(HCI_UART_RESET_ON_INIT) |
732 BIT(HCI_UART_INIT_PENDING) |
733 BIT(HCI_UART_EXT_CONFIG) |
734 BIT(HCI_UART_VND_DETECT);
736 if (flags & ~valid_flags)
739 hu->hdev_flags = flags;
744 /* hci_uart_tty_ioctl()
746 * Process IOCTL system call for the tty device.
750 * tty pointer to tty instance data
751 * cmd IOCTL command code
752 * arg argument for IOCTL call (cmd dependent)
754 * Return Value: Command dependent
756 static int hci_uart_tty_ioctl(struct tty_struct *tty, unsigned int cmd,
759 struct hci_uart *hu = tty->disc_data;
764 /* Verify the status of the device */
769 case HCIUARTSETPROTO:
770 if (!test_and_set_bit(HCI_UART_PROTO_SET, &hu->flags)) {
771 err = hci_uart_set_proto(hu, arg);
773 clear_bit(HCI_UART_PROTO_SET, &hu->flags);
778 case HCIUARTGETPROTO:
779 if (test_bit(HCI_UART_PROTO_SET, &hu->flags) &&
780 test_bit(HCI_UART_PROTO_READY, &hu->flags))
786 case HCIUARTGETDEVICE:
787 if (test_bit(HCI_UART_REGISTERED, &hu->flags))
793 case HCIUARTSETFLAGS:
794 if (test_bit(HCI_UART_PROTO_SET, &hu->flags))
797 err = hci_uart_set_flags(hu, arg);
800 case HCIUARTGETFLAGS:
801 err = hu->hdev_flags;
805 err = n_tty_ioctl_helper(tty, cmd, arg);
813 * We don't provide read/write/poll interface for user space.
815 static ssize_t hci_uart_tty_read(struct tty_struct *tty, struct file *file,
816 u8 *buf, size_t nr, void **cookie,
817 unsigned long offset)
822 static ssize_t hci_uart_tty_write(struct tty_struct *tty, struct file *file,
823 const u8 *data, size_t count)
828 static struct tty_ldisc_ops hci_uart_ldisc = {
829 .owner = THIS_MODULE,
832 .open = hci_uart_tty_open,
833 .close = hci_uart_tty_close,
834 .read = hci_uart_tty_read,
835 .write = hci_uart_tty_write,
836 .ioctl = hci_uart_tty_ioctl,
837 .compat_ioctl = hci_uart_tty_ioctl,
838 .receive_buf = hci_uart_tty_receive,
839 .write_wakeup = hci_uart_tty_wakeup,
842 static int __init hci_uart_init(void)
846 BT_INFO("HCI UART driver ver %s", VERSION);
848 /* Register the tty discipline */
849 err = tty_register_ldisc(&hci_uart_ldisc);
851 BT_ERR("HCI line discipline registration failed. (%d)", err);
855 #ifdef CONFIG_BT_HCIUART_H4
858 #ifdef CONFIG_BT_HCIUART_BCSP
861 #ifdef CONFIG_BT_HCIUART_LL
864 #ifdef CONFIG_BT_HCIUART_ATH3K
867 #ifdef CONFIG_BT_HCIUART_3WIRE
870 #ifdef CONFIG_BT_HCIUART_INTEL
873 #ifdef CONFIG_BT_HCIUART_BCM
876 #ifdef CONFIG_BT_HCIUART_QCA
879 #ifdef CONFIG_BT_HCIUART_AG6XX
882 #ifdef CONFIG_BT_HCIUART_MRVL
885 #ifdef CONFIG_BT_HCIUART_AML
891 static void __exit hci_uart_exit(void)
893 #ifdef CONFIG_BT_HCIUART_H4
896 #ifdef CONFIG_BT_HCIUART_BCSP
899 #ifdef CONFIG_BT_HCIUART_LL
902 #ifdef CONFIG_BT_HCIUART_ATH3K
905 #ifdef CONFIG_BT_HCIUART_3WIRE
908 #ifdef CONFIG_BT_HCIUART_INTEL
911 #ifdef CONFIG_BT_HCIUART_BCM
914 #ifdef CONFIG_BT_HCIUART_QCA
917 #ifdef CONFIG_BT_HCIUART_AG6XX
920 #ifdef CONFIG_BT_HCIUART_MRVL
923 #ifdef CONFIG_BT_HCIUART_AML
926 tty_unregister_ldisc(&hci_uart_ldisc);
929 module_init(hci_uart_init);
930 module_exit(hci_uart_exit);
932 MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
933 MODULE_DESCRIPTION("Bluetooth HCI UART driver ver " VERSION);
934 MODULE_VERSION(VERSION);
935 MODULE_LICENSE("GPL");
936 MODULE_ALIAS_LDISC(N_HCI);