pn533.c 68 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965
  1. /*
  2. * Copyright (C) 2011 Instituto Nokia de Tecnologia
  3. * Copyright (C) 2012-2013 Tieto Poland
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation; either version 2 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program; if not, write to the
  17. * Free Software Foundation, Inc.,
  18. * 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
  19. */
  20. #include <linux/device.h>
  21. #include <linux/kernel.h>
  22. #include <linux/module.h>
  23. #include <linux/slab.h>
  24. #include <linux/usb.h>
  25. #include <linux/nfc.h>
  26. #include <linux/netdevice.h>
  27. #include <net/nfc/nfc.h>
  28. #define VERSION "0.2"
  29. #define PN533_VENDOR_ID 0x4CC
  30. #define PN533_PRODUCT_ID 0x2533
  31. #define SCM_VENDOR_ID 0x4E6
  32. #define SCL3711_PRODUCT_ID 0x5591
  33. #define SONY_VENDOR_ID 0x054c
  34. #define PASORI_PRODUCT_ID 0x02e1
  35. #define ACS_VENDOR_ID 0x072f
  36. #define ACR122U_PRODUCT_ID 0x2200
  37. #define PN533_DEVICE_STD 0x1
  38. #define PN533_DEVICE_PASORI 0x2
  39. #define PN533_DEVICE_ACR122U 0x3
  40. #define PN533_ALL_PROTOCOLS (NFC_PROTO_JEWEL_MASK | NFC_PROTO_MIFARE_MASK |\
  41. NFC_PROTO_FELICA_MASK | NFC_PROTO_ISO14443_MASK |\
  42. NFC_PROTO_NFC_DEP_MASK |\
  43. NFC_PROTO_ISO14443_B_MASK)
  44. #define PN533_NO_TYPE_B_PROTOCOLS (NFC_PROTO_JEWEL_MASK | \
  45. NFC_PROTO_MIFARE_MASK | \
  46. NFC_PROTO_FELICA_MASK | \
  47. NFC_PROTO_ISO14443_MASK | \
  48. NFC_PROTO_NFC_DEP_MASK)
  49. static const struct usb_device_id pn533_table[] = {
  50. { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
  51. .idVendor = PN533_VENDOR_ID,
  52. .idProduct = PN533_PRODUCT_ID,
  53. .driver_info = PN533_DEVICE_STD,
  54. },
  55. { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
  56. .idVendor = SCM_VENDOR_ID,
  57. .idProduct = SCL3711_PRODUCT_ID,
  58. .driver_info = PN533_DEVICE_STD,
  59. },
  60. { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
  61. .idVendor = SONY_VENDOR_ID,
  62. .idProduct = PASORI_PRODUCT_ID,
  63. .driver_info = PN533_DEVICE_PASORI,
  64. },
  65. { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
  66. .idVendor = ACS_VENDOR_ID,
  67. .idProduct = ACR122U_PRODUCT_ID,
  68. .driver_info = PN533_DEVICE_ACR122U,
  69. },
  70. { }
  71. };
  72. MODULE_DEVICE_TABLE(usb, pn533_table);
  73. /* How much time we spend listening for initiators */
  74. #define PN533_LISTEN_TIME 2
  75. /* Standard pn533 frame definitions (standard and extended)*/
  76. #define PN533_STD_FRAME_HEADER_LEN (sizeof(struct pn533_std_frame) \
  77. + 2) /* data[0] TFI, data[1] CC */
  78. #define PN533_STD_FRAME_TAIL_LEN 2 /* data[len] DCS, data[len + 1] postamble*/
  79. #define PN533_EXT_FRAME_HEADER_LEN (sizeof(struct pn533_ext_frame) \
  80. + 2) /* data[0] TFI, data[1] CC */
  81. #define PN533_CMD_DATAEXCH_DATA_MAXLEN 262
  82. #define PN533_CMD_DATAFRAME_MAXLEN 240 /* max data length (send) */
  83. /*
  84. * Max extended frame payload len, excluding TFI and CC
  85. * which are already in PN533_FRAME_HEADER_LEN.
  86. */
  87. #define PN533_STD_FRAME_MAX_PAYLOAD_LEN 263
  88. #define PN533_STD_FRAME_ACK_SIZE 6 /* Preamble (1), SoPC (2), ACK Code (2),
  89. Postamble (1) */
  90. #define PN533_STD_FRAME_CHECKSUM(f) (f->data[f->datalen])
  91. #define PN533_STD_FRAME_POSTAMBLE(f) (f->data[f->datalen + 1])
  92. /* Half start code (3), LEN (4) should be 0xffff for extended frame */
  93. #define PN533_STD_IS_EXTENDED(hdr) ((hdr)->datalen == 0xFF \
  94. && (hdr)->datalen_checksum == 0xFF)
  95. #define PN533_EXT_FRAME_CHECKSUM(f) (f->data[be16_to_cpu(f->datalen)])
  96. /* start of frame */
  97. #define PN533_STD_FRAME_SOF 0x00FF
  98. /* standard frame identifier: in/out/error */
  99. #define PN533_STD_FRAME_IDENTIFIER(f) (f->data[0]) /* TFI */
  100. #define PN533_STD_FRAME_DIR_OUT 0xD4
  101. #define PN533_STD_FRAME_DIR_IN 0xD5
  102. /* ACS ACR122 pn533 frame definitions */
  103. #define PN533_ACR122_TX_FRAME_HEADER_LEN (sizeof(struct pn533_acr122_tx_frame) \
  104. + 2)
  105. #define PN533_ACR122_TX_FRAME_TAIL_LEN 0
  106. #define PN533_ACR122_RX_FRAME_HEADER_LEN (sizeof(struct pn533_acr122_rx_frame) \
  107. + 2)
  108. #define PN533_ACR122_RX_FRAME_TAIL_LEN 2
  109. #define PN533_ACR122_FRAME_MAX_PAYLOAD_LEN PN533_STD_FRAME_MAX_PAYLOAD_LEN
  110. /* CCID messages types */
  111. #define PN533_ACR122_PC_TO_RDR_ICCPOWERON 0x62
  112. #define PN533_ACR122_PC_TO_RDR_ESCAPE 0x6B
  113. #define PN533_ACR122_RDR_TO_PC_ESCAPE 0x83
  114. /* PN533 Commands */
  115. #define PN533_FRAME_CMD(f) (f->data[1])
  116. #define PN533_CMD_GET_FIRMWARE_VERSION 0x02
  117. #define PN533_CMD_RF_CONFIGURATION 0x32
  118. #define PN533_CMD_IN_DATA_EXCHANGE 0x40
  119. #define PN533_CMD_IN_COMM_THRU 0x42
  120. #define PN533_CMD_IN_LIST_PASSIVE_TARGET 0x4A
  121. #define PN533_CMD_IN_ATR 0x50
  122. #define PN533_CMD_IN_RELEASE 0x52
  123. #define PN533_CMD_IN_JUMP_FOR_DEP 0x56
  124. #define PN533_CMD_TG_INIT_AS_TARGET 0x8c
  125. #define PN533_CMD_TG_GET_DATA 0x86
  126. #define PN533_CMD_TG_SET_DATA 0x8e
  127. #define PN533_CMD_UNDEF 0xff
  128. #define PN533_CMD_RESPONSE(cmd) (cmd + 1)
  129. /* PN533 Return codes */
  130. #define PN533_CMD_RET_MASK 0x3F
  131. #define PN533_CMD_MI_MASK 0x40
  132. #define PN533_CMD_RET_SUCCESS 0x00
  133. struct pn533;
  134. typedef int (*pn533_send_async_complete_t) (struct pn533 *dev, void *arg,
  135. struct sk_buff *resp);
  136. /* structs for pn533 commands */
  137. /* PN533_CMD_GET_FIRMWARE_VERSION */
  138. struct pn533_fw_version {
  139. u8 ic;
  140. u8 ver;
  141. u8 rev;
  142. u8 support;
  143. };
  144. /* PN533_CMD_RF_CONFIGURATION */
  145. #define PN533_CFGITEM_RF_FIELD 0x01
  146. #define PN533_CFGITEM_TIMING 0x02
  147. #define PN533_CFGITEM_MAX_RETRIES 0x05
  148. #define PN533_CFGITEM_PASORI 0x82
  149. #define PN533_CFGITEM_RF_FIELD_AUTO_RFCA 0x2
  150. #define PN533_CFGITEM_RF_FIELD_ON 0x1
  151. #define PN533_CFGITEM_RF_FIELD_OFF 0x0
  152. #define PN533_CONFIG_TIMING_102 0xb
  153. #define PN533_CONFIG_TIMING_204 0xc
  154. #define PN533_CONFIG_TIMING_409 0xd
  155. #define PN533_CONFIG_TIMING_819 0xe
  156. #define PN533_CONFIG_MAX_RETRIES_NO_RETRY 0x00
  157. #define PN533_CONFIG_MAX_RETRIES_ENDLESS 0xFF
  158. struct pn533_config_max_retries {
  159. u8 mx_rty_atr;
  160. u8 mx_rty_psl;
  161. u8 mx_rty_passive_act;
  162. } __packed;
  163. struct pn533_config_timing {
  164. u8 rfu;
  165. u8 atr_res_timeout;
  166. u8 dep_timeout;
  167. } __packed;
  168. /* PN533_CMD_IN_LIST_PASSIVE_TARGET */
  169. /* felica commands opcode */
  170. #define PN533_FELICA_OPC_SENSF_REQ 0
  171. #define PN533_FELICA_OPC_SENSF_RES 1
  172. /* felica SENSF_REQ parameters */
  173. #define PN533_FELICA_SENSF_SC_ALL 0xFFFF
  174. #define PN533_FELICA_SENSF_RC_NO_SYSTEM_CODE 0
  175. #define PN533_FELICA_SENSF_RC_SYSTEM_CODE 1
  176. #define PN533_FELICA_SENSF_RC_ADVANCED_PROTOCOL 2
  177. /* type B initiator_data values */
  178. #define PN533_TYPE_B_AFI_ALL_FAMILIES 0
  179. #define PN533_TYPE_B_POLL_METHOD_TIMESLOT 0
  180. #define PN533_TYPE_B_POLL_METHOD_PROBABILISTIC 1
  181. union pn533_cmd_poll_initdata {
  182. struct {
  183. u8 afi;
  184. u8 polling_method;
  185. } __packed type_b;
  186. struct {
  187. u8 opcode;
  188. __be16 sc;
  189. u8 rc;
  190. u8 tsn;
  191. } __packed felica;
  192. };
  193. /* Poll modulations */
  194. enum {
  195. PN533_POLL_MOD_106KBPS_A,
  196. PN533_POLL_MOD_212KBPS_FELICA,
  197. PN533_POLL_MOD_424KBPS_FELICA,
  198. PN533_POLL_MOD_106KBPS_JEWEL,
  199. PN533_POLL_MOD_847KBPS_B,
  200. PN533_LISTEN_MOD,
  201. __PN533_POLL_MOD_AFTER_LAST,
  202. };
  203. #define PN533_POLL_MOD_MAX (__PN533_POLL_MOD_AFTER_LAST - 1)
  204. struct pn533_poll_modulations {
  205. struct {
  206. u8 maxtg;
  207. u8 brty;
  208. union pn533_cmd_poll_initdata initiator_data;
  209. } __packed data;
  210. u8 len;
  211. };
  212. static const struct pn533_poll_modulations poll_mod[] = {
  213. [PN533_POLL_MOD_106KBPS_A] = {
  214. .data = {
  215. .maxtg = 1,
  216. .brty = 0,
  217. },
  218. .len = 2,
  219. },
  220. [PN533_POLL_MOD_212KBPS_FELICA] = {
  221. .data = {
  222. .maxtg = 1,
  223. .brty = 1,
  224. .initiator_data.felica = {
  225. .opcode = PN533_FELICA_OPC_SENSF_REQ,
  226. .sc = PN533_FELICA_SENSF_SC_ALL,
  227. .rc = PN533_FELICA_SENSF_RC_SYSTEM_CODE,
  228. .tsn = 0x03,
  229. },
  230. },
  231. .len = 7,
  232. },
  233. [PN533_POLL_MOD_424KBPS_FELICA] = {
  234. .data = {
  235. .maxtg = 1,
  236. .brty = 2,
  237. .initiator_data.felica = {
  238. .opcode = PN533_FELICA_OPC_SENSF_REQ,
  239. .sc = PN533_FELICA_SENSF_SC_ALL,
  240. .rc = PN533_FELICA_SENSF_RC_SYSTEM_CODE,
  241. .tsn = 0x03,
  242. },
  243. },
  244. .len = 7,
  245. },
  246. [PN533_POLL_MOD_106KBPS_JEWEL] = {
  247. .data = {
  248. .maxtg = 1,
  249. .brty = 4,
  250. },
  251. .len = 2,
  252. },
  253. [PN533_POLL_MOD_847KBPS_B] = {
  254. .data = {
  255. .maxtg = 1,
  256. .brty = 8,
  257. .initiator_data.type_b = {
  258. .afi = PN533_TYPE_B_AFI_ALL_FAMILIES,
  259. .polling_method =
  260. PN533_TYPE_B_POLL_METHOD_TIMESLOT,
  261. },
  262. },
  263. .len = 3,
  264. },
  265. [PN533_LISTEN_MOD] = {
  266. .len = 0,
  267. },
  268. };
  269. /* PN533_CMD_IN_ATR */
  270. struct pn533_cmd_activate_response {
  271. u8 status;
  272. u8 nfcid3t[10];
  273. u8 didt;
  274. u8 bst;
  275. u8 brt;
  276. u8 to;
  277. u8 ppt;
  278. /* optional */
  279. u8 gt[];
  280. } __packed;
  281. struct pn533_cmd_jump_dep_response {
  282. u8 status;
  283. u8 tg;
  284. u8 nfcid3t[10];
  285. u8 didt;
  286. u8 bst;
  287. u8 brt;
  288. u8 to;
  289. u8 ppt;
  290. /* optional */
  291. u8 gt[];
  292. } __packed;
  293. /* PN533_TG_INIT_AS_TARGET */
  294. #define PN533_INIT_TARGET_PASSIVE 0x1
  295. #define PN533_INIT_TARGET_DEP 0x2
  296. #define PN533_INIT_TARGET_RESP_FRAME_MASK 0x3
  297. #define PN533_INIT_TARGET_RESP_ACTIVE 0x1
  298. #define PN533_INIT_TARGET_RESP_DEP 0x4
  299. enum pn533_protocol_type {
  300. PN533_PROTO_REQ_ACK_RESP = 0,
  301. PN533_PROTO_REQ_RESP
  302. };
  303. struct pn533 {
  304. struct usb_device *udev;
  305. struct usb_interface *interface;
  306. struct nfc_dev *nfc_dev;
  307. u32 device_type;
  308. enum pn533_protocol_type protocol_type;
  309. struct urb *out_urb;
  310. struct urb *in_urb;
  311. struct sk_buff_head resp_q;
  312. struct workqueue_struct *wq;
  313. struct work_struct cmd_work;
  314. struct work_struct cmd_complete_work;
  315. struct work_struct poll_work;
  316. struct work_struct mi_work;
  317. struct work_struct tg_work;
  318. struct work_struct rf_work;
  319. struct list_head cmd_queue;
  320. struct pn533_cmd *cmd;
  321. u8 cmd_pending;
  322. struct mutex cmd_lock; /* protects cmd queue */
  323. void *cmd_complete_mi_arg;
  324. struct pn533_poll_modulations *poll_mod_active[PN533_POLL_MOD_MAX + 1];
  325. u8 poll_mod_count;
  326. u8 poll_mod_curr;
  327. u32 poll_protocols;
  328. u32 listen_protocols;
  329. struct timer_list listen_timer;
  330. int cancel_listen;
  331. u8 *gb;
  332. size_t gb_len;
  333. u8 tgt_available_prots;
  334. u8 tgt_active_prot;
  335. u8 tgt_mode;
  336. struct pn533_frame_ops *ops;
  337. };
  338. struct pn533_cmd {
  339. struct list_head queue;
  340. u8 code;
  341. int status;
  342. struct sk_buff *req;
  343. struct sk_buff *resp;
  344. int resp_len;
  345. pn533_send_async_complete_t complete_cb;
  346. void *complete_cb_context;
  347. };
  348. struct pn533_std_frame {
  349. u8 preamble;
  350. __be16 start_frame;
  351. u8 datalen;
  352. u8 datalen_checksum;
  353. u8 data[];
  354. } __packed;
  355. struct pn533_ext_frame { /* Extended Information frame */
  356. u8 preamble;
  357. __be16 start_frame;
  358. __be16 eif_flag; /* fixed to 0xFFFF */
  359. __be16 datalen;
  360. u8 datalen_checksum;
  361. u8 data[];
  362. } __packed;
  363. struct pn533_frame_ops {
  364. void (*tx_frame_init)(void *frame, u8 cmd_code);
  365. void (*tx_frame_finish)(void *frame);
  366. void (*tx_update_payload_len)(void *frame, int len);
  367. int tx_header_len;
  368. int tx_tail_len;
  369. bool (*rx_is_frame_valid)(void *frame);
  370. int (*rx_frame_size)(void *frame);
  371. int rx_header_len;
  372. int rx_tail_len;
  373. int max_payload_len;
  374. u8 (*get_cmd_code)(void *frame);
  375. };
  376. struct pn533_acr122_ccid_hdr {
  377. u8 type;
  378. u32 datalen;
  379. u8 slot;
  380. u8 seq;
  381. u8 params[3]; /* 3 msg specific bytes or status, error and 1 specific
  382. byte for reposnse msg */
  383. u8 data[]; /* payload */
  384. } __packed;
  385. struct pn533_acr122_apdu_hdr {
  386. u8 class;
  387. u8 ins;
  388. u8 p1;
  389. u8 p2;
  390. } __packed;
  391. struct pn533_acr122_tx_frame {
  392. struct pn533_acr122_ccid_hdr ccid;
  393. struct pn533_acr122_apdu_hdr apdu;
  394. u8 datalen;
  395. u8 data[]; /* pn533 frame: TFI ... */
  396. } __packed;
  397. struct pn533_acr122_rx_frame {
  398. struct pn533_acr122_ccid_hdr ccid;
  399. u8 data[]; /* pn533 frame : TFI ... */
  400. } __packed;
  401. static void pn533_acr122_tx_frame_init(void *_frame, u8 cmd_code)
  402. {
  403. struct pn533_acr122_tx_frame *frame = _frame;
  404. frame->ccid.type = PN533_ACR122_PC_TO_RDR_ESCAPE;
  405. frame->ccid.datalen = sizeof(frame->apdu) + 1; /* sizeof(apdu_hdr) +
  406. sizeof(datalen) */
  407. frame->ccid.slot = 0;
  408. frame->ccid.seq = 0;
  409. frame->ccid.params[0] = 0;
  410. frame->ccid.params[1] = 0;
  411. frame->ccid.params[2] = 0;
  412. frame->data[0] = PN533_STD_FRAME_DIR_OUT;
  413. frame->data[1] = cmd_code;
  414. frame->datalen = 2; /* data[0] + data[1] */
  415. frame->apdu.class = 0xFF;
  416. frame->apdu.ins = 0;
  417. frame->apdu.p1 = 0;
  418. frame->apdu.p2 = 0;
  419. }
  420. static void pn533_acr122_tx_frame_finish(void *_frame)
  421. {
  422. struct pn533_acr122_tx_frame *frame = _frame;
  423. frame->ccid.datalen += frame->datalen;
  424. }
  425. static void pn533_acr122_tx_update_payload_len(void *_frame, int len)
  426. {
  427. struct pn533_acr122_tx_frame *frame = _frame;
  428. frame->datalen += len;
  429. }
  430. static bool pn533_acr122_is_rx_frame_valid(void *_frame)
  431. {
  432. struct pn533_acr122_rx_frame *frame = _frame;
  433. if (frame->ccid.type != 0x83)
  434. return false;
  435. if (frame->data[frame->ccid.datalen - 2] == 0x63)
  436. return false;
  437. return true;
  438. }
  439. static int pn533_acr122_rx_frame_size(void *frame)
  440. {
  441. struct pn533_acr122_rx_frame *f = frame;
  442. /* f->ccid.datalen already includes tail length */
  443. return sizeof(struct pn533_acr122_rx_frame) + f->ccid.datalen;
  444. }
  445. static u8 pn533_acr122_get_cmd_code(void *frame)
  446. {
  447. struct pn533_acr122_rx_frame *f = frame;
  448. return PN533_FRAME_CMD(f);
  449. }
  450. static struct pn533_frame_ops pn533_acr122_frame_ops = {
  451. .tx_frame_init = pn533_acr122_tx_frame_init,
  452. .tx_frame_finish = pn533_acr122_tx_frame_finish,
  453. .tx_update_payload_len = pn533_acr122_tx_update_payload_len,
  454. .tx_header_len = PN533_ACR122_TX_FRAME_HEADER_LEN,
  455. .tx_tail_len = PN533_ACR122_TX_FRAME_TAIL_LEN,
  456. .rx_is_frame_valid = pn533_acr122_is_rx_frame_valid,
  457. .rx_header_len = PN533_ACR122_RX_FRAME_HEADER_LEN,
  458. .rx_tail_len = PN533_ACR122_RX_FRAME_TAIL_LEN,
  459. .rx_frame_size = pn533_acr122_rx_frame_size,
  460. .max_payload_len = PN533_ACR122_FRAME_MAX_PAYLOAD_LEN,
  461. .get_cmd_code = pn533_acr122_get_cmd_code,
  462. };
  463. /* The rule: value(high byte) + value(low byte) + checksum = 0 */
  464. static inline u8 pn533_ext_checksum(u16 value)
  465. {
  466. return ~(u8)(((value & 0xFF00) >> 8) + (u8)(value & 0xFF)) + 1;
  467. }
  468. /* The rule: value + checksum = 0 */
  469. static inline u8 pn533_std_checksum(u8 value)
  470. {
  471. return ~value + 1;
  472. }
  473. /* The rule: sum(data elements) + checksum = 0 */
  474. static u8 pn533_std_data_checksum(u8 *data, int datalen)
  475. {
  476. u8 sum = 0;
  477. int i;
  478. for (i = 0; i < datalen; i++)
  479. sum += data[i];
  480. return pn533_std_checksum(sum);
  481. }
  482. static void pn533_std_tx_frame_init(void *_frame, u8 cmd_code)
  483. {
  484. struct pn533_std_frame *frame = _frame;
  485. frame->preamble = 0;
  486. frame->start_frame = cpu_to_be16(PN533_STD_FRAME_SOF);
  487. PN533_STD_FRAME_IDENTIFIER(frame) = PN533_STD_FRAME_DIR_OUT;
  488. PN533_FRAME_CMD(frame) = cmd_code;
  489. frame->datalen = 2;
  490. }
  491. static void pn533_std_tx_frame_finish(void *_frame)
  492. {
  493. struct pn533_std_frame *frame = _frame;
  494. frame->datalen_checksum = pn533_std_checksum(frame->datalen);
  495. PN533_STD_FRAME_CHECKSUM(frame) =
  496. pn533_std_data_checksum(frame->data, frame->datalen);
  497. PN533_STD_FRAME_POSTAMBLE(frame) = 0;
  498. }
  499. static void pn533_std_tx_update_payload_len(void *_frame, int len)
  500. {
  501. struct pn533_std_frame *frame = _frame;
  502. frame->datalen += len;
  503. }
  504. static bool pn533_std_rx_frame_is_valid(void *_frame)
  505. {
  506. u8 checksum;
  507. struct pn533_std_frame *stdf = _frame;
  508. if (stdf->start_frame != cpu_to_be16(PN533_STD_FRAME_SOF))
  509. return false;
  510. if (likely(!PN533_STD_IS_EXTENDED(stdf))) {
  511. /* Standard frame code */
  512. checksum = pn533_std_checksum(stdf->datalen);
  513. if (checksum != stdf->datalen_checksum)
  514. return false;
  515. checksum = pn533_std_data_checksum(stdf->data, stdf->datalen);
  516. if (checksum != PN533_STD_FRAME_CHECKSUM(stdf))
  517. return false;
  518. } else {
  519. /* Extended */
  520. struct pn533_ext_frame *eif = _frame;
  521. checksum = pn533_ext_checksum(be16_to_cpu(eif->datalen));
  522. if (checksum != eif->datalen_checksum)
  523. return false;
  524. /* check data checksum */
  525. checksum = pn533_std_data_checksum(eif->data,
  526. be16_to_cpu(eif->datalen));
  527. if (checksum != PN533_EXT_FRAME_CHECKSUM(eif))
  528. return false;
  529. }
  530. return true;
  531. }
  532. static bool pn533_std_rx_frame_is_ack(struct pn533_std_frame *frame)
  533. {
  534. if (frame->start_frame != cpu_to_be16(PN533_STD_FRAME_SOF))
  535. return false;
  536. if (frame->datalen != 0 || frame->datalen_checksum != 0xFF)
  537. return false;
  538. return true;
  539. }
  540. static inline int pn533_std_rx_frame_size(void *frame)
  541. {
  542. struct pn533_std_frame *f = frame;
  543. /* check for Extended Information frame */
  544. if (PN533_STD_IS_EXTENDED(f)) {
  545. struct pn533_ext_frame *eif = frame;
  546. return sizeof(struct pn533_ext_frame)
  547. + be16_to_cpu(eif->datalen) + PN533_STD_FRAME_TAIL_LEN;
  548. }
  549. return sizeof(struct pn533_std_frame) + f->datalen +
  550. PN533_STD_FRAME_TAIL_LEN;
  551. }
  552. static u8 pn533_std_get_cmd_code(void *frame)
  553. {
  554. struct pn533_std_frame *f = frame;
  555. struct pn533_ext_frame *eif = frame;
  556. if (PN533_STD_IS_EXTENDED(f))
  557. return PN533_FRAME_CMD(eif);
  558. else
  559. return PN533_FRAME_CMD(f);
  560. }
  561. static struct pn533_frame_ops pn533_std_frame_ops = {
  562. .tx_frame_init = pn533_std_tx_frame_init,
  563. .tx_frame_finish = pn533_std_tx_frame_finish,
  564. .tx_update_payload_len = pn533_std_tx_update_payload_len,
  565. .tx_header_len = PN533_STD_FRAME_HEADER_LEN,
  566. .tx_tail_len = PN533_STD_FRAME_TAIL_LEN,
  567. .rx_is_frame_valid = pn533_std_rx_frame_is_valid,
  568. .rx_frame_size = pn533_std_rx_frame_size,
  569. .rx_header_len = PN533_STD_FRAME_HEADER_LEN,
  570. .rx_tail_len = PN533_STD_FRAME_TAIL_LEN,
  571. .max_payload_len = PN533_STD_FRAME_MAX_PAYLOAD_LEN,
  572. .get_cmd_code = pn533_std_get_cmd_code,
  573. };
  574. static bool pn533_rx_frame_is_cmd_response(struct pn533 *dev, void *frame)
  575. {
  576. return (dev->ops->get_cmd_code(frame) ==
  577. PN533_CMD_RESPONSE(dev->cmd->code));
  578. }
  579. static void pn533_recv_response(struct urb *urb)
  580. {
  581. struct pn533 *dev = urb->context;
  582. struct pn533_cmd *cmd = dev->cmd;
  583. u8 *in_frame;
  584. cmd->status = urb->status;
  585. switch (urb->status) {
  586. case 0:
  587. break; /* success */
  588. case -ECONNRESET:
  589. case -ENOENT:
  590. nfc_dev_dbg(&dev->interface->dev,
  591. "The urb has been canceled (status %d)",
  592. urb->status);
  593. goto sched_wq;
  594. case -ESHUTDOWN:
  595. default:
  596. nfc_dev_err(&dev->interface->dev,
  597. "Urb failure (status %d)", urb->status);
  598. goto sched_wq;
  599. }
  600. in_frame = dev->in_urb->transfer_buffer;
  601. nfc_dev_dbg(&dev->interface->dev, "Received a frame.");
  602. print_hex_dump_debug("PN533 RX: ", DUMP_PREFIX_NONE, 16, 1, in_frame,
  603. dev->ops->rx_frame_size(in_frame), false);
  604. if (!dev->ops->rx_is_frame_valid(in_frame)) {
  605. nfc_dev_err(&dev->interface->dev, "Received an invalid frame");
  606. cmd->status = -EIO;
  607. goto sched_wq;
  608. }
  609. if (!pn533_rx_frame_is_cmd_response(dev, in_frame)) {
  610. nfc_dev_err(&dev->interface->dev,
  611. "It it not the response to the last command");
  612. cmd->status = -EIO;
  613. goto sched_wq;
  614. }
  615. if (PN533_STD_IS_EXTENDED((struct pn533_std_frame *)in_frame))
  616. dev->ops->rx_header_len = PN533_EXT_FRAME_HEADER_LEN;
  617. else
  618. dev->ops->rx_header_len = PN533_STD_FRAME_HEADER_LEN;
  619. sched_wq:
  620. queue_work(dev->wq, &dev->cmd_complete_work);
  621. }
  622. static int pn533_submit_urb_for_response(struct pn533 *dev, gfp_t flags)
  623. {
  624. dev->in_urb->complete = pn533_recv_response;
  625. return usb_submit_urb(dev->in_urb, flags);
  626. }
  627. static void pn533_recv_ack(struct urb *urb)
  628. {
  629. struct pn533 *dev = urb->context;
  630. struct pn533_cmd *cmd = dev->cmd;
  631. struct pn533_std_frame *in_frame;
  632. int rc;
  633. cmd->status = urb->status;
  634. switch (urb->status) {
  635. case 0:
  636. break; /* success */
  637. case -ECONNRESET:
  638. case -ENOENT:
  639. nfc_dev_dbg(&dev->interface->dev,
  640. "The urb has been stopped (status %d)",
  641. urb->status);
  642. goto sched_wq;
  643. case -ESHUTDOWN:
  644. default:
  645. nfc_dev_err(&dev->interface->dev,
  646. "Urb failure (status %d)", urb->status);
  647. goto sched_wq;
  648. }
  649. in_frame = dev->in_urb->transfer_buffer;
  650. if (!pn533_std_rx_frame_is_ack(in_frame)) {
  651. nfc_dev_err(&dev->interface->dev, "Received an invalid ack");
  652. cmd->status = -EIO;
  653. goto sched_wq;
  654. }
  655. rc = pn533_submit_urb_for_response(dev, GFP_ATOMIC);
  656. if (rc) {
  657. nfc_dev_err(&dev->interface->dev,
  658. "usb_submit_urb failed with result %d", rc);
  659. cmd->status = rc;
  660. goto sched_wq;
  661. }
  662. return;
  663. sched_wq:
  664. queue_work(dev->wq, &dev->cmd_complete_work);
  665. }
  666. static int pn533_submit_urb_for_ack(struct pn533 *dev, gfp_t flags)
  667. {
  668. dev->in_urb->complete = pn533_recv_ack;
  669. return usb_submit_urb(dev->in_urb, flags);
  670. }
  671. static int pn533_send_ack(struct pn533 *dev, gfp_t flags)
  672. {
  673. u8 ack[PN533_STD_FRAME_ACK_SIZE] = {0x00, 0x00, 0xff, 0x00, 0xff, 0x00};
  674. /* spec 7.1.1.3: Preamble, SoPC (2), ACK Code (2), Postamble */
  675. int rc;
  676. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  677. dev->out_urb->transfer_buffer = ack;
  678. dev->out_urb->transfer_buffer_length = sizeof(ack);
  679. rc = usb_submit_urb(dev->out_urb, flags);
  680. return rc;
  681. }
  682. static int __pn533_send_frame_async(struct pn533 *dev,
  683. struct sk_buff *out,
  684. struct sk_buff *in,
  685. int in_len)
  686. {
  687. int rc;
  688. dev->out_urb->transfer_buffer = out->data;
  689. dev->out_urb->transfer_buffer_length = out->len;
  690. dev->in_urb->transfer_buffer = in->data;
  691. dev->in_urb->transfer_buffer_length = in_len;
  692. print_hex_dump_debug("PN533 TX: ", DUMP_PREFIX_NONE, 16, 1,
  693. out->data, out->len, false);
  694. rc = usb_submit_urb(dev->out_urb, GFP_KERNEL);
  695. if (rc)
  696. return rc;
  697. if (dev->protocol_type == PN533_PROTO_REQ_RESP) {
  698. /* request for response for sent packet directly */
  699. rc = pn533_submit_urb_for_response(dev, GFP_ATOMIC);
  700. if (rc)
  701. goto error;
  702. } else if (dev->protocol_type == PN533_PROTO_REQ_ACK_RESP) {
  703. /* request for ACK if that's the case */
  704. rc = pn533_submit_urb_for_ack(dev, GFP_KERNEL);
  705. if (rc)
  706. goto error;
  707. }
  708. return 0;
  709. error:
  710. usb_unlink_urb(dev->out_urb);
  711. return rc;
  712. }
  713. static void pn533_build_cmd_frame(struct pn533 *dev, u8 cmd_code,
  714. struct sk_buff *skb)
  715. {
  716. /* payload is already there, just update datalen */
  717. int payload_len = skb->len;
  718. struct pn533_frame_ops *ops = dev->ops;
  719. skb_push(skb, ops->tx_header_len);
  720. skb_put(skb, ops->tx_tail_len);
  721. ops->tx_frame_init(skb->data, cmd_code);
  722. ops->tx_update_payload_len(skb->data, payload_len);
  723. ops->tx_frame_finish(skb->data);
  724. }
  725. static int pn533_send_async_complete(struct pn533 *dev)
  726. {
  727. struct pn533_cmd *cmd = dev->cmd;
  728. int status = cmd->status;
  729. struct sk_buff *req = cmd->req;
  730. struct sk_buff *resp = cmd->resp;
  731. int rc;
  732. dev_kfree_skb(req);
  733. if (status < 0) {
  734. rc = cmd->complete_cb(dev, cmd->complete_cb_context,
  735. ERR_PTR(status));
  736. dev_kfree_skb(resp);
  737. goto done;
  738. }
  739. skb_put(resp, dev->ops->rx_frame_size(resp->data));
  740. skb_pull(resp, dev->ops->rx_header_len);
  741. skb_trim(resp, resp->len - dev->ops->rx_tail_len);
  742. rc = cmd->complete_cb(dev, cmd->complete_cb_context, resp);
  743. done:
  744. kfree(cmd);
  745. dev->cmd = NULL;
  746. return rc;
  747. }
  748. static int __pn533_send_async(struct pn533 *dev, u8 cmd_code,
  749. struct sk_buff *req, struct sk_buff *resp,
  750. int resp_len,
  751. pn533_send_async_complete_t complete_cb,
  752. void *complete_cb_context)
  753. {
  754. struct pn533_cmd *cmd;
  755. int rc = 0;
  756. nfc_dev_dbg(&dev->interface->dev, "Sending command 0x%x", cmd_code);
  757. cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
  758. if (!cmd)
  759. return -ENOMEM;
  760. cmd->code = cmd_code;
  761. cmd->req = req;
  762. cmd->resp = resp;
  763. cmd->resp_len = resp_len;
  764. cmd->complete_cb = complete_cb;
  765. cmd->complete_cb_context = complete_cb_context;
  766. pn533_build_cmd_frame(dev, cmd_code, req);
  767. mutex_lock(&dev->cmd_lock);
  768. if (!dev->cmd_pending) {
  769. rc = __pn533_send_frame_async(dev, req, resp, resp_len);
  770. if (rc)
  771. goto error;
  772. dev->cmd_pending = 1;
  773. dev->cmd = cmd;
  774. goto unlock;
  775. }
  776. nfc_dev_dbg(&dev->interface->dev, "%s Queueing command 0x%x", __func__,
  777. cmd_code);
  778. INIT_LIST_HEAD(&cmd->queue);
  779. list_add_tail(&cmd->queue, &dev->cmd_queue);
  780. goto unlock;
  781. error:
  782. kfree(cmd);
  783. unlock:
  784. mutex_unlock(&dev->cmd_lock);
  785. return rc;
  786. }
  787. static int pn533_send_data_async(struct pn533 *dev, u8 cmd_code,
  788. struct sk_buff *req,
  789. pn533_send_async_complete_t complete_cb,
  790. void *complete_cb_context)
  791. {
  792. struct sk_buff *resp;
  793. int rc;
  794. int resp_len = dev->ops->rx_header_len +
  795. dev->ops->max_payload_len +
  796. dev->ops->rx_tail_len;
  797. resp = nfc_alloc_recv_skb(resp_len, GFP_KERNEL);
  798. if (!resp)
  799. return -ENOMEM;
  800. rc = __pn533_send_async(dev, cmd_code, req, resp, resp_len, complete_cb,
  801. complete_cb_context);
  802. if (rc)
  803. dev_kfree_skb(resp);
  804. return rc;
  805. }
  806. static int pn533_send_cmd_async(struct pn533 *dev, u8 cmd_code,
  807. struct sk_buff *req,
  808. pn533_send_async_complete_t complete_cb,
  809. void *complete_cb_context)
  810. {
  811. struct sk_buff *resp;
  812. int rc;
  813. int resp_len = dev->ops->rx_header_len +
  814. dev->ops->max_payload_len +
  815. dev->ops->rx_tail_len;
  816. resp = alloc_skb(resp_len, GFP_KERNEL);
  817. if (!resp)
  818. return -ENOMEM;
  819. rc = __pn533_send_async(dev, cmd_code, req, resp, resp_len, complete_cb,
  820. complete_cb_context);
  821. if (rc)
  822. dev_kfree_skb(resp);
  823. return rc;
  824. }
  825. /*
  826. * pn533_send_cmd_direct_async
  827. *
  828. * The function sends a piority cmd directly to the chip omiting the cmd
  829. * queue. It's intended to be used by chaining mechanism of received responses
  830. * where the host has to request every single chunk of data before scheduling
  831. * next cmd from the queue.
  832. */
  833. static int pn533_send_cmd_direct_async(struct pn533 *dev, u8 cmd_code,
  834. struct sk_buff *req,
  835. pn533_send_async_complete_t complete_cb,
  836. void *complete_cb_context)
  837. {
  838. struct sk_buff *resp;
  839. struct pn533_cmd *cmd;
  840. int rc;
  841. int resp_len = dev->ops->rx_header_len +
  842. dev->ops->max_payload_len +
  843. dev->ops->rx_tail_len;
  844. resp = alloc_skb(resp_len, GFP_KERNEL);
  845. if (!resp)
  846. return -ENOMEM;
  847. cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
  848. if (!cmd) {
  849. dev_kfree_skb(resp);
  850. return -ENOMEM;
  851. }
  852. cmd->code = cmd_code;
  853. cmd->req = req;
  854. cmd->resp = resp;
  855. cmd->resp_len = resp_len;
  856. cmd->complete_cb = complete_cb;
  857. cmd->complete_cb_context = complete_cb_context;
  858. pn533_build_cmd_frame(dev, cmd_code, req);
  859. rc = __pn533_send_frame_async(dev, req, resp, resp_len);
  860. if (rc < 0) {
  861. dev_kfree_skb(resp);
  862. kfree(cmd);
  863. } else {
  864. dev->cmd = cmd;
  865. }
  866. return rc;
  867. }
  868. static void pn533_wq_cmd_complete(struct work_struct *work)
  869. {
  870. struct pn533 *dev = container_of(work, struct pn533, cmd_complete_work);
  871. int rc;
  872. rc = pn533_send_async_complete(dev);
  873. if (rc != -EINPROGRESS)
  874. queue_work(dev->wq, &dev->cmd_work);
  875. }
  876. static void pn533_wq_cmd(struct work_struct *work)
  877. {
  878. struct pn533 *dev = container_of(work, struct pn533, cmd_work);
  879. struct pn533_cmd *cmd;
  880. int rc;
  881. mutex_lock(&dev->cmd_lock);
  882. if (list_empty(&dev->cmd_queue)) {
  883. dev->cmd_pending = 0;
  884. mutex_unlock(&dev->cmd_lock);
  885. return;
  886. }
  887. cmd = list_first_entry(&dev->cmd_queue, struct pn533_cmd, queue);
  888. list_del(&cmd->queue);
  889. mutex_unlock(&dev->cmd_lock);
  890. rc = __pn533_send_frame_async(dev, cmd->req, cmd->resp, cmd->resp_len);
  891. if (rc < 0) {
  892. dev_kfree_skb(cmd->req);
  893. dev_kfree_skb(cmd->resp);
  894. kfree(cmd);
  895. return;
  896. }
  897. dev->cmd = cmd;
  898. }
  899. struct pn533_sync_cmd_response {
  900. struct sk_buff *resp;
  901. struct completion done;
  902. };
  903. static int pn533_send_sync_complete(struct pn533 *dev, void *_arg,
  904. struct sk_buff *resp)
  905. {
  906. struct pn533_sync_cmd_response *arg = _arg;
  907. arg->resp = resp;
  908. complete(&arg->done);
  909. return 0;
  910. }
  911. /* pn533_send_cmd_sync
  912. *
  913. * Please note the req parameter is freed inside the function to
  914. * limit a number of return value interpretations by the caller.
  915. *
  916. * 1. negative in case of error during TX path -> req should be freed
  917. *
  918. * 2. negative in case of error during RX path -> req should not be freed
  919. * as it's been already freed at the begining of RX path by
  920. * async_complete_cb.
  921. *
  922. * 3. valid pointer in case of succesfult RX path
  923. *
  924. * A caller has to check a return value with IS_ERR macro. If the test pass,
  925. * the returned pointer is valid.
  926. *
  927. * */
  928. static struct sk_buff *pn533_send_cmd_sync(struct pn533 *dev, u8 cmd_code,
  929. struct sk_buff *req)
  930. {
  931. int rc;
  932. struct pn533_sync_cmd_response arg;
  933. init_completion(&arg.done);
  934. rc = pn533_send_cmd_async(dev, cmd_code, req,
  935. pn533_send_sync_complete, &arg);
  936. if (rc) {
  937. dev_kfree_skb(req);
  938. return ERR_PTR(rc);
  939. }
  940. wait_for_completion(&arg.done);
  941. return arg.resp;
  942. }
  943. static void pn533_send_complete(struct urb *urb)
  944. {
  945. struct pn533 *dev = urb->context;
  946. switch (urb->status) {
  947. case 0:
  948. break; /* success */
  949. case -ECONNRESET:
  950. case -ENOENT:
  951. nfc_dev_dbg(&dev->interface->dev,
  952. "The urb has been stopped (status %d)",
  953. urb->status);
  954. break;
  955. case -ESHUTDOWN:
  956. default:
  957. nfc_dev_err(&dev->interface->dev,
  958. "Urb failure (status %d)", urb->status);
  959. }
  960. }
  961. static void pn533_abort_cmd(struct pn533 *dev, gfp_t flags)
  962. {
  963. /* ACR122U does not support any command which aborts last
  964. * issued command i.e. as ACK for standard PN533. Additionally,
  965. * it behaves stange, sending broken or incorrect responses,
  966. * when we cancel urb before the chip will send response.
  967. */
  968. if (dev->device_type == PN533_DEVICE_ACR122U)
  969. return;
  970. /* An ack will cancel the last issued command */
  971. pn533_send_ack(dev, flags);
  972. /* cancel the urb request */
  973. usb_kill_urb(dev->in_urb);
  974. }
  975. static struct sk_buff *pn533_alloc_skb(struct pn533 *dev, unsigned int size)
  976. {
  977. struct sk_buff *skb;
  978. skb = alloc_skb(dev->ops->tx_header_len +
  979. size +
  980. dev->ops->tx_tail_len, GFP_KERNEL);
  981. if (skb)
  982. skb_reserve(skb, dev->ops->tx_header_len);
  983. return skb;
  984. }
  985. struct pn533_target_type_a {
  986. __be16 sens_res;
  987. u8 sel_res;
  988. u8 nfcid_len;
  989. u8 nfcid_data[];
  990. } __packed;
  991. #define PN533_TYPE_A_SENS_RES_NFCID1(x) ((u8)((be16_to_cpu(x) & 0x00C0) >> 6))
  992. #define PN533_TYPE_A_SENS_RES_SSD(x) ((u8)((be16_to_cpu(x) & 0x001F) >> 0))
  993. #define PN533_TYPE_A_SENS_RES_PLATCONF(x) ((u8)((be16_to_cpu(x) & 0x0F00) >> 8))
  994. #define PN533_TYPE_A_SENS_RES_SSD_JEWEL 0x00
  995. #define PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL 0x0C
  996. #define PN533_TYPE_A_SEL_PROT(x) (((x) & 0x60) >> 5)
  997. #define PN533_TYPE_A_SEL_CASCADE(x) (((x) & 0x04) >> 2)
  998. #define PN533_TYPE_A_SEL_PROT_MIFARE 0
  999. #define PN533_TYPE_A_SEL_PROT_ISO14443 1
  1000. #define PN533_TYPE_A_SEL_PROT_DEP 2
  1001. #define PN533_TYPE_A_SEL_PROT_ISO14443_DEP 3
  1002. static bool pn533_target_type_a_is_valid(struct pn533_target_type_a *type_a,
  1003. int target_data_len)
  1004. {
  1005. u8 ssd;
  1006. u8 platconf;
  1007. if (target_data_len < sizeof(struct pn533_target_type_a))
  1008. return false;
  1009. /* The lenght check of nfcid[] and ats[] are not being performed because
  1010. the values are not being used */
  1011. /* Requirement 4.6.3.3 from NFC Forum Digital Spec */
  1012. ssd = PN533_TYPE_A_SENS_RES_SSD(type_a->sens_res);
  1013. platconf = PN533_TYPE_A_SENS_RES_PLATCONF(type_a->sens_res);
  1014. if ((ssd == PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  1015. platconf != PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL) ||
  1016. (ssd != PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  1017. platconf == PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL))
  1018. return false;
  1019. /* Requirements 4.8.2.1, 4.8.2.3, 4.8.2.5 and 4.8.2.7 from NFC Forum */
  1020. if (PN533_TYPE_A_SEL_CASCADE(type_a->sel_res) != 0)
  1021. return false;
  1022. return true;
  1023. }
  1024. static int pn533_target_found_type_a(struct nfc_target *nfc_tgt, u8 *tgt_data,
  1025. int tgt_data_len)
  1026. {
  1027. struct pn533_target_type_a *tgt_type_a;
  1028. tgt_type_a = (struct pn533_target_type_a *)tgt_data;
  1029. if (!pn533_target_type_a_is_valid(tgt_type_a, tgt_data_len))
  1030. return -EPROTO;
  1031. switch (PN533_TYPE_A_SEL_PROT(tgt_type_a->sel_res)) {
  1032. case PN533_TYPE_A_SEL_PROT_MIFARE:
  1033. nfc_tgt->supported_protocols = NFC_PROTO_MIFARE_MASK;
  1034. break;
  1035. case PN533_TYPE_A_SEL_PROT_ISO14443:
  1036. nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_MASK;
  1037. break;
  1038. case PN533_TYPE_A_SEL_PROT_DEP:
  1039. nfc_tgt->supported_protocols = NFC_PROTO_NFC_DEP_MASK;
  1040. break;
  1041. case PN533_TYPE_A_SEL_PROT_ISO14443_DEP:
  1042. nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_MASK |
  1043. NFC_PROTO_NFC_DEP_MASK;
  1044. break;
  1045. }
  1046. nfc_tgt->sens_res = be16_to_cpu(tgt_type_a->sens_res);
  1047. nfc_tgt->sel_res = tgt_type_a->sel_res;
  1048. nfc_tgt->nfcid1_len = tgt_type_a->nfcid_len;
  1049. memcpy(nfc_tgt->nfcid1, tgt_type_a->nfcid_data, nfc_tgt->nfcid1_len);
  1050. return 0;
  1051. }
  1052. struct pn533_target_felica {
  1053. u8 pol_res;
  1054. u8 opcode;
  1055. u8 nfcid2[NFC_NFCID2_MAXSIZE];
  1056. u8 pad[8];
  1057. /* optional */
  1058. u8 syst_code[];
  1059. } __packed;
  1060. #define PN533_FELICA_SENSF_NFCID2_DEP_B1 0x01
  1061. #define PN533_FELICA_SENSF_NFCID2_DEP_B2 0xFE
  1062. static bool pn533_target_felica_is_valid(struct pn533_target_felica *felica,
  1063. int target_data_len)
  1064. {
  1065. if (target_data_len < sizeof(struct pn533_target_felica))
  1066. return false;
  1067. if (felica->opcode != PN533_FELICA_OPC_SENSF_RES)
  1068. return false;
  1069. return true;
  1070. }
  1071. static int pn533_target_found_felica(struct nfc_target *nfc_tgt, u8 *tgt_data,
  1072. int tgt_data_len)
  1073. {
  1074. struct pn533_target_felica *tgt_felica;
  1075. tgt_felica = (struct pn533_target_felica *)tgt_data;
  1076. if (!pn533_target_felica_is_valid(tgt_felica, tgt_data_len))
  1077. return -EPROTO;
  1078. if ((tgt_felica->nfcid2[0] == PN533_FELICA_SENSF_NFCID2_DEP_B1) &&
  1079. (tgt_felica->nfcid2[1] == PN533_FELICA_SENSF_NFCID2_DEP_B2))
  1080. nfc_tgt->supported_protocols = NFC_PROTO_NFC_DEP_MASK;
  1081. else
  1082. nfc_tgt->supported_protocols = NFC_PROTO_FELICA_MASK;
  1083. memcpy(nfc_tgt->sensf_res, &tgt_felica->opcode, 9);
  1084. nfc_tgt->sensf_res_len = 9;
  1085. memcpy(nfc_tgt->nfcid2, tgt_felica->nfcid2, NFC_NFCID2_MAXSIZE);
  1086. nfc_tgt->nfcid2_len = NFC_NFCID2_MAXSIZE;
  1087. return 0;
  1088. }
  1089. struct pn533_target_jewel {
  1090. __be16 sens_res;
  1091. u8 jewelid[4];
  1092. } __packed;
  1093. static bool pn533_target_jewel_is_valid(struct pn533_target_jewel *jewel,
  1094. int target_data_len)
  1095. {
  1096. u8 ssd;
  1097. u8 platconf;
  1098. if (target_data_len < sizeof(struct pn533_target_jewel))
  1099. return false;
  1100. /* Requirement 4.6.3.3 from NFC Forum Digital Spec */
  1101. ssd = PN533_TYPE_A_SENS_RES_SSD(jewel->sens_res);
  1102. platconf = PN533_TYPE_A_SENS_RES_PLATCONF(jewel->sens_res);
  1103. if ((ssd == PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  1104. platconf != PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL) ||
  1105. (ssd != PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  1106. platconf == PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL))
  1107. return false;
  1108. return true;
  1109. }
  1110. static int pn533_target_found_jewel(struct nfc_target *nfc_tgt, u8 *tgt_data,
  1111. int tgt_data_len)
  1112. {
  1113. struct pn533_target_jewel *tgt_jewel;
  1114. tgt_jewel = (struct pn533_target_jewel *)tgt_data;
  1115. if (!pn533_target_jewel_is_valid(tgt_jewel, tgt_data_len))
  1116. return -EPROTO;
  1117. nfc_tgt->supported_protocols = NFC_PROTO_JEWEL_MASK;
  1118. nfc_tgt->sens_res = be16_to_cpu(tgt_jewel->sens_res);
  1119. nfc_tgt->nfcid1_len = 4;
  1120. memcpy(nfc_tgt->nfcid1, tgt_jewel->jewelid, nfc_tgt->nfcid1_len);
  1121. return 0;
  1122. }
  1123. struct pn533_type_b_prot_info {
  1124. u8 bitrate;
  1125. u8 fsci_type;
  1126. u8 fwi_adc_fo;
  1127. } __packed;
  1128. #define PN533_TYPE_B_PROT_FCSI(x) (((x) & 0xF0) >> 4)
  1129. #define PN533_TYPE_B_PROT_TYPE(x) (((x) & 0x0F) >> 0)
  1130. #define PN533_TYPE_B_PROT_TYPE_RFU_MASK 0x8
  1131. struct pn533_type_b_sens_res {
  1132. u8 opcode;
  1133. u8 nfcid[4];
  1134. u8 appdata[4];
  1135. struct pn533_type_b_prot_info prot_info;
  1136. } __packed;
  1137. #define PN533_TYPE_B_OPC_SENSB_RES 0x50
  1138. struct pn533_target_type_b {
  1139. struct pn533_type_b_sens_res sensb_res;
  1140. u8 attrib_res_len;
  1141. u8 attrib_res[];
  1142. } __packed;
  1143. static bool pn533_target_type_b_is_valid(struct pn533_target_type_b *type_b,
  1144. int target_data_len)
  1145. {
  1146. if (target_data_len < sizeof(struct pn533_target_type_b))
  1147. return false;
  1148. if (type_b->sensb_res.opcode != PN533_TYPE_B_OPC_SENSB_RES)
  1149. return false;
  1150. if (PN533_TYPE_B_PROT_TYPE(type_b->sensb_res.prot_info.fsci_type) &
  1151. PN533_TYPE_B_PROT_TYPE_RFU_MASK)
  1152. return false;
  1153. return true;
  1154. }
  1155. static int pn533_target_found_type_b(struct nfc_target *nfc_tgt, u8 *tgt_data,
  1156. int tgt_data_len)
  1157. {
  1158. struct pn533_target_type_b *tgt_type_b;
  1159. tgt_type_b = (struct pn533_target_type_b *)tgt_data;
  1160. if (!pn533_target_type_b_is_valid(tgt_type_b, tgt_data_len))
  1161. return -EPROTO;
  1162. nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_B_MASK;
  1163. return 0;
  1164. }
  1165. static int pn533_target_found(struct pn533 *dev, u8 tg, u8 *tgdata,
  1166. int tgdata_len)
  1167. {
  1168. struct nfc_target nfc_tgt;
  1169. int rc;
  1170. nfc_dev_dbg(&dev->interface->dev, "%s - modulation=%d", __func__,
  1171. dev->poll_mod_curr);
  1172. if (tg != 1)
  1173. return -EPROTO;
  1174. memset(&nfc_tgt, 0, sizeof(struct nfc_target));
  1175. switch (dev->poll_mod_curr) {
  1176. case PN533_POLL_MOD_106KBPS_A:
  1177. rc = pn533_target_found_type_a(&nfc_tgt, tgdata, tgdata_len);
  1178. break;
  1179. case PN533_POLL_MOD_212KBPS_FELICA:
  1180. case PN533_POLL_MOD_424KBPS_FELICA:
  1181. rc = pn533_target_found_felica(&nfc_tgt, tgdata, tgdata_len);
  1182. break;
  1183. case PN533_POLL_MOD_106KBPS_JEWEL:
  1184. rc = pn533_target_found_jewel(&nfc_tgt, tgdata, tgdata_len);
  1185. break;
  1186. case PN533_POLL_MOD_847KBPS_B:
  1187. rc = pn533_target_found_type_b(&nfc_tgt, tgdata, tgdata_len);
  1188. break;
  1189. default:
  1190. nfc_dev_err(&dev->interface->dev,
  1191. "Unknown current poll modulation");
  1192. return -EPROTO;
  1193. }
  1194. if (rc)
  1195. return rc;
  1196. if (!(nfc_tgt.supported_protocols & dev->poll_protocols)) {
  1197. nfc_dev_dbg(&dev->interface->dev,
  1198. "The Tg found doesn't have the desired protocol");
  1199. return -EAGAIN;
  1200. }
  1201. nfc_dev_dbg(&dev->interface->dev,
  1202. "Target found - supported protocols: 0x%x",
  1203. nfc_tgt.supported_protocols);
  1204. dev->tgt_available_prots = nfc_tgt.supported_protocols;
  1205. nfc_targets_found(dev->nfc_dev, &nfc_tgt, 1);
  1206. return 0;
  1207. }
  1208. static inline void pn533_poll_next_mod(struct pn533 *dev)
  1209. {
  1210. dev->poll_mod_curr = (dev->poll_mod_curr + 1) % dev->poll_mod_count;
  1211. }
  1212. static void pn533_poll_reset_mod_list(struct pn533 *dev)
  1213. {
  1214. dev->poll_mod_count = 0;
  1215. }
  1216. static void pn533_poll_add_mod(struct pn533 *dev, u8 mod_index)
  1217. {
  1218. dev->poll_mod_active[dev->poll_mod_count] =
  1219. (struct pn533_poll_modulations *)&poll_mod[mod_index];
  1220. dev->poll_mod_count++;
  1221. }
  1222. static void pn533_poll_create_mod_list(struct pn533 *dev,
  1223. u32 im_protocols, u32 tm_protocols)
  1224. {
  1225. pn533_poll_reset_mod_list(dev);
  1226. if ((im_protocols & NFC_PROTO_MIFARE_MASK) ||
  1227. (im_protocols & NFC_PROTO_ISO14443_MASK) ||
  1228. (im_protocols & NFC_PROTO_NFC_DEP_MASK))
  1229. pn533_poll_add_mod(dev, PN533_POLL_MOD_106KBPS_A);
  1230. if (im_protocols & NFC_PROTO_FELICA_MASK ||
  1231. im_protocols & NFC_PROTO_NFC_DEP_MASK) {
  1232. pn533_poll_add_mod(dev, PN533_POLL_MOD_212KBPS_FELICA);
  1233. pn533_poll_add_mod(dev, PN533_POLL_MOD_424KBPS_FELICA);
  1234. }
  1235. if (im_protocols & NFC_PROTO_JEWEL_MASK)
  1236. pn533_poll_add_mod(dev, PN533_POLL_MOD_106KBPS_JEWEL);
  1237. if (im_protocols & NFC_PROTO_ISO14443_B_MASK)
  1238. pn533_poll_add_mod(dev, PN533_POLL_MOD_847KBPS_B);
  1239. if (tm_protocols)
  1240. pn533_poll_add_mod(dev, PN533_LISTEN_MOD);
  1241. }
  1242. static int pn533_start_poll_complete(struct pn533 *dev, struct sk_buff *resp)
  1243. {
  1244. u8 nbtg, tg, *tgdata;
  1245. int rc, tgdata_len;
  1246. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1247. nbtg = resp->data[0];
  1248. tg = resp->data[1];
  1249. tgdata = &resp->data[2];
  1250. tgdata_len = resp->len - 2; /* nbtg + tg */
  1251. if (nbtg) {
  1252. rc = pn533_target_found(dev, tg, tgdata, tgdata_len);
  1253. /* We must stop the poll after a valid target found */
  1254. if (rc == 0) {
  1255. pn533_poll_reset_mod_list(dev);
  1256. return 0;
  1257. }
  1258. }
  1259. return -EAGAIN;
  1260. }
  1261. static struct sk_buff *pn533_alloc_poll_tg_frame(struct pn533 *dev)
  1262. {
  1263. struct sk_buff *skb;
  1264. u8 *felica, *nfcid3, *gb;
  1265. u8 *gbytes = dev->gb;
  1266. size_t gbytes_len = dev->gb_len;
  1267. u8 felica_params[18] = {0x1, 0xfe, /* DEP */
  1268. 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, /* random */
  1269. 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0,
  1270. 0xff, 0xff}; /* System code */
  1271. u8 mifare_params[6] = {0x1, 0x1, /* SENS_RES */
  1272. 0x0, 0x0, 0x0,
  1273. 0x40}; /* SEL_RES for DEP */
  1274. unsigned int skb_len = 36 + /* mode (1), mifare (6),
  1275. felica (18), nfcid3 (10), gb_len (1) */
  1276. gbytes_len +
  1277. 1; /* len Tk*/
  1278. skb = pn533_alloc_skb(dev, skb_len);
  1279. if (!skb)
  1280. return NULL;
  1281. /* DEP support only */
  1282. *skb_put(skb, 1) = PN533_INIT_TARGET_DEP;
  1283. /* MIFARE params */
  1284. memcpy(skb_put(skb, 6), mifare_params, 6);
  1285. /* Felica params */
  1286. felica = skb_put(skb, 18);
  1287. memcpy(felica, felica_params, 18);
  1288. get_random_bytes(felica + 2, 6);
  1289. /* NFCID3 */
  1290. nfcid3 = skb_put(skb, 10);
  1291. memset(nfcid3, 0, 10);
  1292. memcpy(nfcid3, felica, 8);
  1293. /* General bytes */
  1294. *skb_put(skb, 1) = gbytes_len;
  1295. gb = skb_put(skb, gbytes_len);
  1296. memcpy(gb, gbytes, gbytes_len);
  1297. /* Len Tk */
  1298. *skb_put(skb, 1) = 0;
  1299. return skb;
  1300. }
  1301. #define PN533_CMD_DATAEXCH_HEAD_LEN 1
  1302. #define PN533_CMD_DATAEXCH_DATA_MAXLEN 262
  1303. static int pn533_tm_get_data_complete(struct pn533 *dev, void *arg,
  1304. struct sk_buff *resp)
  1305. {
  1306. u8 status;
  1307. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1308. if (IS_ERR(resp))
  1309. return PTR_ERR(resp);
  1310. status = resp->data[0];
  1311. skb_pull(resp, sizeof(status));
  1312. if (status != 0) {
  1313. nfc_tm_deactivated(dev->nfc_dev);
  1314. dev->tgt_mode = 0;
  1315. dev_kfree_skb(resp);
  1316. return 0;
  1317. }
  1318. return nfc_tm_data_received(dev->nfc_dev, resp);
  1319. }
  1320. static void pn533_wq_tg_get_data(struct work_struct *work)
  1321. {
  1322. struct pn533 *dev = container_of(work, struct pn533, tg_work);
  1323. struct sk_buff *skb;
  1324. int rc;
  1325. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1326. skb = pn533_alloc_skb(dev, 0);
  1327. if (!skb)
  1328. return;
  1329. rc = pn533_send_data_async(dev, PN533_CMD_TG_GET_DATA, skb,
  1330. pn533_tm_get_data_complete, NULL);
  1331. if (rc < 0)
  1332. dev_kfree_skb(skb);
  1333. return;
  1334. }
  1335. #define ATR_REQ_GB_OFFSET 17
  1336. static int pn533_init_target_complete(struct pn533 *dev, struct sk_buff *resp)
  1337. {
  1338. u8 mode, *cmd, comm_mode = NFC_COMM_PASSIVE, *gb;
  1339. size_t gb_len;
  1340. int rc;
  1341. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1342. if (resp->len < ATR_REQ_GB_OFFSET + 1)
  1343. return -EINVAL;
  1344. mode = resp->data[0];
  1345. cmd = &resp->data[1];
  1346. nfc_dev_dbg(&dev->interface->dev, "Target mode 0x%x len %d\n",
  1347. mode, resp->len);
  1348. if ((mode & PN533_INIT_TARGET_RESP_FRAME_MASK) ==
  1349. PN533_INIT_TARGET_RESP_ACTIVE)
  1350. comm_mode = NFC_COMM_ACTIVE;
  1351. if ((mode & PN533_INIT_TARGET_RESP_DEP) == 0) /* Only DEP supported */
  1352. return -EOPNOTSUPP;
  1353. gb = cmd + ATR_REQ_GB_OFFSET;
  1354. gb_len = resp->len - (ATR_REQ_GB_OFFSET + 1);
  1355. rc = nfc_tm_activated(dev->nfc_dev, NFC_PROTO_NFC_DEP_MASK,
  1356. comm_mode, gb, gb_len);
  1357. if (rc < 0) {
  1358. nfc_dev_err(&dev->interface->dev,
  1359. "Error when signaling target activation");
  1360. return rc;
  1361. }
  1362. dev->tgt_mode = 1;
  1363. queue_work(dev->wq, &dev->tg_work);
  1364. return 0;
  1365. }
  1366. static void pn533_listen_mode_timer(unsigned long data)
  1367. {
  1368. struct pn533 *dev = (struct pn533 *)data;
  1369. nfc_dev_dbg(&dev->interface->dev, "Listen mode timeout");
  1370. dev->cancel_listen = 1;
  1371. pn533_poll_next_mod(dev);
  1372. queue_work(dev->wq, &dev->poll_work);
  1373. }
  1374. static int pn533_rf_complete(struct pn533 *dev, void *arg,
  1375. struct sk_buff *resp)
  1376. {
  1377. int rc = 0;
  1378. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1379. if (IS_ERR(resp)) {
  1380. rc = PTR_ERR(resp);
  1381. nfc_dev_err(&dev->interface->dev, "%s RF setting error %d",
  1382. __func__, rc);
  1383. return rc;
  1384. }
  1385. queue_work(dev->wq, &dev->poll_work);
  1386. dev_kfree_skb(resp);
  1387. return rc;
  1388. }
  1389. static void pn533_wq_rf(struct work_struct *work)
  1390. {
  1391. struct pn533 *dev = container_of(work, struct pn533, rf_work);
  1392. struct sk_buff *skb;
  1393. int rc;
  1394. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1395. skb = pn533_alloc_skb(dev, 2);
  1396. if (!skb)
  1397. return;
  1398. *skb_put(skb, 1) = PN533_CFGITEM_RF_FIELD;
  1399. *skb_put(skb, 1) = PN533_CFGITEM_RF_FIELD_AUTO_RFCA;
  1400. rc = pn533_send_cmd_async(dev, PN533_CMD_RF_CONFIGURATION, skb,
  1401. pn533_rf_complete, NULL);
  1402. if (rc < 0) {
  1403. dev_kfree_skb(skb);
  1404. nfc_dev_err(&dev->interface->dev, "RF setting error %d", rc);
  1405. }
  1406. return;
  1407. }
  1408. static int pn533_poll_complete(struct pn533 *dev, void *arg,
  1409. struct sk_buff *resp)
  1410. {
  1411. struct pn533_poll_modulations *cur_mod;
  1412. int rc;
  1413. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1414. if (IS_ERR(resp)) {
  1415. rc = PTR_ERR(resp);
  1416. nfc_dev_err(&dev->interface->dev, "%s Poll complete error %d",
  1417. __func__, rc);
  1418. if (rc == -ENOENT) {
  1419. if (dev->poll_mod_count != 0)
  1420. return rc;
  1421. else
  1422. goto stop_poll;
  1423. } else if (rc < 0) {
  1424. nfc_dev_err(&dev->interface->dev,
  1425. "Error %d when running poll", rc);
  1426. goto stop_poll;
  1427. }
  1428. }
  1429. cur_mod = dev->poll_mod_active[dev->poll_mod_curr];
  1430. if (cur_mod->len == 0) { /* Target mode */
  1431. del_timer(&dev->listen_timer);
  1432. rc = pn533_init_target_complete(dev, resp);
  1433. goto done;
  1434. }
  1435. /* Initiator mode */
  1436. rc = pn533_start_poll_complete(dev, resp);
  1437. if (!rc)
  1438. goto done;
  1439. if (!dev->poll_mod_count) {
  1440. nfc_dev_dbg(&dev->interface->dev, "Polling has been stopped.");
  1441. goto done;
  1442. }
  1443. pn533_poll_next_mod(dev);
  1444. /* Not target found, turn radio off */
  1445. queue_work(dev->wq, &dev->rf_work);
  1446. done:
  1447. dev_kfree_skb(resp);
  1448. return rc;
  1449. stop_poll:
  1450. nfc_dev_err(&dev->interface->dev, "Polling operation has been stopped");
  1451. pn533_poll_reset_mod_list(dev);
  1452. dev->poll_protocols = 0;
  1453. return rc;
  1454. }
  1455. static struct sk_buff *pn533_alloc_poll_in_frame(struct pn533 *dev,
  1456. struct pn533_poll_modulations *mod)
  1457. {
  1458. struct sk_buff *skb;
  1459. skb = pn533_alloc_skb(dev, mod->len);
  1460. if (!skb)
  1461. return NULL;
  1462. memcpy(skb_put(skb, mod->len), &mod->data, mod->len);
  1463. return skb;
  1464. }
  1465. static int pn533_send_poll_frame(struct pn533 *dev)
  1466. {
  1467. struct pn533_poll_modulations *mod;
  1468. struct sk_buff *skb;
  1469. int rc;
  1470. u8 cmd_code;
  1471. mod = dev->poll_mod_active[dev->poll_mod_curr];
  1472. nfc_dev_dbg(&dev->interface->dev, "%s mod len %d\n",
  1473. __func__, mod->len);
  1474. if (mod->len == 0) { /* Listen mode */
  1475. cmd_code = PN533_CMD_TG_INIT_AS_TARGET;
  1476. skb = pn533_alloc_poll_tg_frame(dev);
  1477. } else { /* Polling mode */
  1478. cmd_code = PN533_CMD_IN_LIST_PASSIVE_TARGET;
  1479. skb = pn533_alloc_poll_in_frame(dev, mod);
  1480. }
  1481. if (!skb) {
  1482. nfc_dev_err(&dev->interface->dev, "Failed to allocate skb.");
  1483. return -ENOMEM;
  1484. }
  1485. rc = pn533_send_cmd_async(dev, cmd_code, skb, pn533_poll_complete,
  1486. NULL);
  1487. if (rc < 0) {
  1488. dev_kfree_skb(skb);
  1489. nfc_dev_err(&dev->interface->dev, "Polling loop error %d", rc);
  1490. }
  1491. return rc;
  1492. }
  1493. static void pn533_wq_poll(struct work_struct *work)
  1494. {
  1495. struct pn533 *dev = container_of(work, struct pn533, poll_work);
  1496. struct pn533_poll_modulations *cur_mod;
  1497. int rc;
  1498. cur_mod = dev->poll_mod_active[dev->poll_mod_curr];
  1499. nfc_dev_dbg(&dev->interface->dev,
  1500. "%s cancel_listen %d modulation len %d",
  1501. __func__, dev->cancel_listen, cur_mod->len);
  1502. if (dev->cancel_listen == 1) {
  1503. dev->cancel_listen = 0;
  1504. pn533_abort_cmd(dev, GFP_ATOMIC);
  1505. }
  1506. rc = pn533_send_poll_frame(dev);
  1507. if (rc)
  1508. return;
  1509. if (cur_mod->len == 0 && dev->poll_mod_count > 1)
  1510. mod_timer(&dev->listen_timer, jiffies + PN533_LISTEN_TIME * HZ);
  1511. return;
  1512. }
  1513. static int pn533_start_poll(struct nfc_dev *nfc_dev,
  1514. u32 im_protocols, u32 tm_protocols)
  1515. {
  1516. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1517. nfc_dev_dbg(&dev->interface->dev,
  1518. "%s: im protocols 0x%x tm protocols 0x%x",
  1519. __func__, im_protocols, tm_protocols);
  1520. if (dev->tgt_active_prot) {
  1521. nfc_dev_err(&dev->interface->dev,
  1522. "Cannot poll with a target already activated");
  1523. return -EBUSY;
  1524. }
  1525. if (dev->tgt_mode) {
  1526. nfc_dev_err(&dev->interface->dev,
  1527. "Cannot poll while already being activated");
  1528. return -EBUSY;
  1529. }
  1530. if (tm_protocols) {
  1531. dev->gb = nfc_get_local_general_bytes(nfc_dev, &dev->gb_len);
  1532. if (dev->gb == NULL)
  1533. tm_protocols = 0;
  1534. }
  1535. dev->poll_mod_curr = 0;
  1536. pn533_poll_create_mod_list(dev, im_protocols, tm_protocols);
  1537. dev->poll_protocols = im_protocols;
  1538. dev->listen_protocols = tm_protocols;
  1539. return pn533_send_poll_frame(dev);
  1540. }
  1541. static void pn533_stop_poll(struct nfc_dev *nfc_dev)
  1542. {
  1543. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1544. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1545. del_timer(&dev->listen_timer);
  1546. if (!dev->poll_mod_count) {
  1547. nfc_dev_dbg(&dev->interface->dev,
  1548. "Polling operation was not running");
  1549. return;
  1550. }
  1551. pn533_abort_cmd(dev, GFP_KERNEL);
  1552. pn533_poll_reset_mod_list(dev);
  1553. }
  1554. static int pn533_activate_target_nfcdep(struct pn533 *dev)
  1555. {
  1556. struct pn533_cmd_activate_response *rsp;
  1557. u16 gt_len;
  1558. int rc;
  1559. struct sk_buff *skb;
  1560. struct sk_buff *resp;
  1561. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1562. skb = pn533_alloc_skb(dev, sizeof(u8) * 2); /*TG + Next*/
  1563. if (!skb)
  1564. return -ENOMEM;
  1565. *skb_put(skb, sizeof(u8)) = 1; /* TG */
  1566. *skb_put(skb, sizeof(u8)) = 0; /* Next */
  1567. resp = pn533_send_cmd_sync(dev, PN533_CMD_IN_ATR, skb);
  1568. if (IS_ERR(resp))
  1569. return PTR_ERR(resp);
  1570. rsp = (struct pn533_cmd_activate_response *)resp->data;
  1571. rc = rsp->status & PN533_CMD_RET_MASK;
  1572. if (rc != PN533_CMD_RET_SUCCESS) {
  1573. nfc_dev_err(&dev->interface->dev,
  1574. "Target activation failed (error 0x%x)", rc);
  1575. dev_kfree_skb(resp);
  1576. return -EIO;
  1577. }
  1578. /* ATR_RES general bytes are located at offset 16 */
  1579. gt_len = resp->len - 16;
  1580. rc = nfc_set_remote_general_bytes(dev->nfc_dev, rsp->gt, gt_len);
  1581. dev_kfree_skb(resp);
  1582. return rc;
  1583. }
  1584. static int pn533_activate_target(struct nfc_dev *nfc_dev,
  1585. struct nfc_target *target, u32 protocol)
  1586. {
  1587. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1588. int rc;
  1589. nfc_dev_dbg(&dev->interface->dev, "%s - protocol=%u", __func__,
  1590. protocol);
  1591. if (dev->poll_mod_count) {
  1592. nfc_dev_err(&dev->interface->dev,
  1593. "Cannot activate while polling");
  1594. return -EBUSY;
  1595. }
  1596. if (dev->tgt_active_prot) {
  1597. nfc_dev_err(&dev->interface->dev,
  1598. "There is already an active target");
  1599. return -EBUSY;
  1600. }
  1601. if (!dev->tgt_available_prots) {
  1602. nfc_dev_err(&dev->interface->dev,
  1603. "There is no available target to activate");
  1604. return -EINVAL;
  1605. }
  1606. if (!(dev->tgt_available_prots & (1 << protocol))) {
  1607. nfc_dev_err(&dev->interface->dev,
  1608. "Target doesn't support requested proto %u",
  1609. protocol);
  1610. return -EINVAL;
  1611. }
  1612. if (protocol == NFC_PROTO_NFC_DEP) {
  1613. rc = pn533_activate_target_nfcdep(dev);
  1614. if (rc) {
  1615. nfc_dev_err(&dev->interface->dev,
  1616. "Activating target with DEP failed %d", rc);
  1617. return rc;
  1618. }
  1619. }
  1620. dev->tgt_active_prot = protocol;
  1621. dev->tgt_available_prots = 0;
  1622. return 0;
  1623. }
  1624. static void pn533_deactivate_target(struct nfc_dev *nfc_dev,
  1625. struct nfc_target *target)
  1626. {
  1627. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1628. struct sk_buff *skb;
  1629. struct sk_buff *resp;
  1630. int rc;
  1631. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1632. if (!dev->tgt_active_prot) {
  1633. nfc_dev_err(&dev->interface->dev, "There is no active target");
  1634. return;
  1635. }
  1636. dev->tgt_active_prot = 0;
  1637. skb_queue_purge(&dev->resp_q);
  1638. skb = pn533_alloc_skb(dev, sizeof(u8));
  1639. if (!skb)
  1640. return;
  1641. *skb_put(skb, 1) = 1; /* TG*/
  1642. resp = pn533_send_cmd_sync(dev, PN533_CMD_IN_RELEASE, skb);
  1643. if (IS_ERR(resp))
  1644. return;
  1645. rc = resp->data[0] & PN533_CMD_RET_MASK;
  1646. if (rc != PN533_CMD_RET_SUCCESS)
  1647. nfc_dev_err(&dev->interface->dev,
  1648. "Error 0x%x when releasing the target", rc);
  1649. dev_kfree_skb(resp);
  1650. return;
  1651. }
  1652. static int pn533_in_dep_link_up_complete(struct pn533 *dev, void *arg,
  1653. struct sk_buff *resp)
  1654. {
  1655. struct pn533_cmd_jump_dep_response *rsp;
  1656. u8 target_gt_len;
  1657. int rc;
  1658. u8 active = *(u8 *)arg;
  1659. kfree(arg);
  1660. if (IS_ERR(resp))
  1661. return PTR_ERR(resp);
  1662. if (dev->tgt_available_prots &&
  1663. !(dev->tgt_available_prots & (1 << NFC_PROTO_NFC_DEP))) {
  1664. nfc_dev_err(&dev->interface->dev,
  1665. "The target does not support DEP");
  1666. rc = -EINVAL;
  1667. goto error;
  1668. }
  1669. rsp = (struct pn533_cmd_jump_dep_response *)resp->data;
  1670. rc = rsp->status & PN533_CMD_RET_MASK;
  1671. if (rc != PN533_CMD_RET_SUCCESS) {
  1672. nfc_dev_err(&dev->interface->dev,
  1673. "Bringing DEP link up failed (error 0x%x)", rc);
  1674. goto error;
  1675. }
  1676. if (!dev->tgt_available_prots) {
  1677. struct nfc_target nfc_target;
  1678. nfc_dev_dbg(&dev->interface->dev, "Creating new target");
  1679. nfc_target.supported_protocols = NFC_PROTO_NFC_DEP_MASK;
  1680. nfc_target.nfcid1_len = 10;
  1681. memcpy(nfc_target.nfcid1, rsp->nfcid3t, nfc_target.nfcid1_len);
  1682. rc = nfc_targets_found(dev->nfc_dev, &nfc_target, 1);
  1683. if (rc)
  1684. goto error;
  1685. dev->tgt_available_prots = 0;
  1686. }
  1687. dev->tgt_active_prot = NFC_PROTO_NFC_DEP;
  1688. /* ATR_RES general bytes are located at offset 17 */
  1689. target_gt_len = resp->len - 17;
  1690. rc = nfc_set_remote_general_bytes(dev->nfc_dev,
  1691. rsp->gt, target_gt_len);
  1692. if (rc == 0)
  1693. rc = nfc_dep_link_is_up(dev->nfc_dev,
  1694. dev->nfc_dev->targets[0].idx,
  1695. !active, NFC_RF_INITIATOR);
  1696. error:
  1697. dev_kfree_skb(resp);
  1698. return rc;
  1699. }
  1700. static int pn533_rf_field(struct nfc_dev *nfc_dev, u8 rf);
  1701. #define PASSIVE_DATA_LEN 5
  1702. static int pn533_dep_link_up(struct nfc_dev *nfc_dev, struct nfc_target *target,
  1703. u8 comm_mode, u8 *gb, size_t gb_len)
  1704. {
  1705. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1706. struct sk_buff *skb;
  1707. int rc, skb_len;
  1708. u8 *next, *arg, nfcid3[NFC_NFCID3_MAXSIZE];
  1709. u8 passive_data[PASSIVE_DATA_LEN] = {0x00, 0xff, 0xff, 0x00, 0x3};
  1710. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1711. if (dev->poll_mod_count) {
  1712. nfc_dev_err(&dev->interface->dev,
  1713. "Cannot bring the DEP link up while polling");
  1714. return -EBUSY;
  1715. }
  1716. if (dev->tgt_active_prot) {
  1717. nfc_dev_err(&dev->interface->dev,
  1718. "There is already an active target");
  1719. return -EBUSY;
  1720. }
  1721. skb_len = 3 + gb_len; /* ActPass + BR + Next */
  1722. skb_len += PASSIVE_DATA_LEN;
  1723. /* NFCID3 */
  1724. skb_len += NFC_NFCID3_MAXSIZE;
  1725. if (target && !target->nfcid2_len) {
  1726. nfcid3[0] = 0x1;
  1727. nfcid3[1] = 0xfe;
  1728. get_random_bytes(nfcid3 + 2, 6);
  1729. }
  1730. skb = pn533_alloc_skb(dev, skb_len);
  1731. if (!skb)
  1732. return -ENOMEM;
  1733. *skb_put(skb, 1) = !comm_mode; /* ActPass */
  1734. *skb_put(skb, 1) = 0x02; /* 424 kbps */
  1735. next = skb_put(skb, 1); /* Next */
  1736. *next = 0;
  1737. /* Copy passive data */
  1738. memcpy(skb_put(skb, PASSIVE_DATA_LEN), passive_data, PASSIVE_DATA_LEN);
  1739. *next |= 1;
  1740. /* Copy NFCID3 (which is NFCID2 from SENSF_RES) */
  1741. if (target && target->nfcid2_len)
  1742. memcpy(skb_put(skb, NFC_NFCID3_MAXSIZE), target->nfcid2,
  1743. target->nfcid2_len);
  1744. else
  1745. memcpy(skb_put(skb, NFC_NFCID3_MAXSIZE), nfcid3,
  1746. NFC_NFCID3_MAXSIZE);
  1747. *next |= 2;
  1748. if (gb != NULL && gb_len > 0) {
  1749. memcpy(skb_put(skb, gb_len), gb, gb_len);
  1750. *next |= 4; /* We have some Gi */
  1751. } else {
  1752. *next = 0;
  1753. }
  1754. arg = kmalloc(sizeof(*arg), GFP_KERNEL);
  1755. if (!arg) {
  1756. dev_kfree_skb(skb);
  1757. return -ENOMEM;
  1758. }
  1759. *arg = !comm_mode;
  1760. pn533_rf_field(dev->nfc_dev, 0);
  1761. rc = pn533_send_cmd_async(dev, PN533_CMD_IN_JUMP_FOR_DEP, skb,
  1762. pn533_in_dep_link_up_complete, arg);
  1763. if (rc < 0) {
  1764. dev_kfree_skb(skb);
  1765. kfree(arg);
  1766. }
  1767. return rc;
  1768. }
  1769. static int pn533_dep_link_down(struct nfc_dev *nfc_dev)
  1770. {
  1771. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1772. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1773. pn533_poll_reset_mod_list(dev);
  1774. if (dev->tgt_mode || dev->tgt_active_prot)
  1775. pn533_abort_cmd(dev, GFP_KERNEL);
  1776. dev->tgt_active_prot = 0;
  1777. dev->tgt_mode = 0;
  1778. skb_queue_purge(&dev->resp_q);
  1779. return 0;
  1780. }
  1781. struct pn533_data_exchange_arg {
  1782. data_exchange_cb_t cb;
  1783. void *cb_context;
  1784. };
  1785. static struct sk_buff *pn533_build_response(struct pn533 *dev)
  1786. {
  1787. struct sk_buff *skb, *tmp, *t;
  1788. unsigned int skb_len = 0, tmp_len = 0;
  1789. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1790. if (skb_queue_empty(&dev->resp_q))
  1791. return NULL;
  1792. if (skb_queue_len(&dev->resp_q) == 1) {
  1793. skb = skb_dequeue(&dev->resp_q);
  1794. goto out;
  1795. }
  1796. skb_queue_walk_safe(&dev->resp_q, tmp, t)
  1797. skb_len += tmp->len;
  1798. nfc_dev_dbg(&dev->interface->dev, "%s total length %d\n",
  1799. __func__, skb_len);
  1800. skb = alloc_skb(skb_len, GFP_KERNEL);
  1801. if (skb == NULL)
  1802. goto out;
  1803. skb_put(skb, skb_len);
  1804. skb_queue_walk_safe(&dev->resp_q, tmp, t) {
  1805. memcpy(skb->data + tmp_len, tmp->data, tmp->len);
  1806. tmp_len += tmp->len;
  1807. }
  1808. out:
  1809. skb_queue_purge(&dev->resp_q);
  1810. return skb;
  1811. }
  1812. static int pn533_data_exchange_complete(struct pn533 *dev, void *_arg,
  1813. struct sk_buff *resp)
  1814. {
  1815. struct pn533_data_exchange_arg *arg = _arg;
  1816. struct sk_buff *skb;
  1817. int rc = 0;
  1818. u8 status, ret, mi;
  1819. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1820. if (IS_ERR(resp)) {
  1821. rc = PTR_ERR(resp);
  1822. goto _error;
  1823. }
  1824. status = resp->data[0];
  1825. ret = status & PN533_CMD_RET_MASK;
  1826. mi = status & PN533_CMD_MI_MASK;
  1827. skb_pull(resp, sizeof(status));
  1828. if (ret != PN533_CMD_RET_SUCCESS) {
  1829. nfc_dev_err(&dev->interface->dev,
  1830. "Exchanging data failed (error 0x%x)", ret);
  1831. rc = -EIO;
  1832. goto error;
  1833. }
  1834. skb_queue_tail(&dev->resp_q, resp);
  1835. if (mi) {
  1836. dev->cmd_complete_mi_arg = arg;
  1837. queue_work(dev->wq, &dev->mi_work);
  1838. return -EINPROGRESS;
  1839. }
  1840. skb = pn533_build_response(dev);
  1841. if (!skb)
  1842. goto error;
  1843. arg->cb(arg->cb_context, skb, 0);
  1844. kfree(arg);
  1845. return 0;
  1846. error:
  1847. dev_kfree_skb(resp);
  1848. _error:
  1849. skb_queue_purge(&dev->resp_q);
  1850. arg->cb(arg->cb_context, NULL, rc);
  1851. kfree(arg);
  1852. return rc;
  1853. }
  1854. static int pn533_transceive(struct nfc_dev *nfc_dev,
  1855. struct nfc_target *target, struct sk_buff *skb,
  1856. data_exchange_cb_t cb, void *cb_context)
  1857. {
  1858. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1859. struct pn533_data_exchange_arg *arg = NULL;
  1860. int rc;
  1861. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1862. if (skb->len > PN533_CMD_DATAEXCH_DATA_MAXLEN) {
  1863. /* TODO: Implement support to multi-part data exchange */
  1864. nfc_dev_err(&dev->interface->dev,
  1865. "Data length greater than the max allowed: %d",
  1866. PN533_CMD_DATAEXCH_DATA_MAXLEN);
  1867. rc = -ENOSYS;
  1868. goto error;
  1869. }
  1870. if (!dev->tgt_active_prot) {
  1871. nfc_dev_err(&dev->interface->dev,
  1872. "Can't exchange data if there is no active target");
  1873. rc = -EINVAL;
  1874. goto error;
  1875. }
  1876. arg = kmalloc(sizeof(*arg), GFP_KERNEL);
  1877. if (!arg) {
  1878. rc = -ENOMEM;
  1879. goto error;
  1880. }
  1881. arg->cb = cb;
  1882. arg->cb_context = cb_context;
  1883. switch (dev->device_type) {
  1884. case PN533_DEVICE_PASORI:
  1885. if (dev->tgt_active_prot == NFC_PROTO_FELICA) {
  1886. rc = pn533_send_data_async(dev, PN533_CMD_IN_COMM_THRU,
  1887. skb,
  1888. pn533_data_exchange_complete,
  1889. arg);
  1890. break;
  1891. }
  1892. default:
  1893. *skb_push(skb, sizeof(u8)) = 1; /*TG*/
  1894. rc = pn533_send_data_async(dev, PN533_CMD_IN_DATA_EXCHANGE,
  1895. skb, pn533_data_exchange_complete,
  1896. arg);
  1897. break;
  1898. }
  1899. if (rc < 0) /* rc from send_async */
  1900. goto error;
  1901. return 0;
  1902. error:
  1903. kfree(arg);
  1904. dev_kfree_skb(skb);
  1905. return rc;
  1906. }
  1907. static int pn533_tm_send_complete(struct pn533 *dev, void *arg,
  1908. struct sk_buff *resp)
  1909. {
  1910. u8 status;
  1911. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1912. if (IS_ERR(resp))
  1913. return PTR_ERR(resp);
  1914. status = resp->data[0];
  1915. dev_kfree_skb(resp);
  1916. if (status != 0) {
  1917. nfc_tm_deactivated(dev->nfc_dev);
  1918. dev->tgt_mode = 0;
  1919. return 0;
  1920. }
  1921. queue_work(dev->wq, &dev->tg_work);
  1922. return 0;
  1923. }
  1924. static int pn533_tm_send(struct nfc_dev *nfc_dev, struct sk_buff *skb)
  1925. {
  1926. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1927. int rc;
  1928. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1929. if (skb->len > PN533_CMD_DATAEXCH_DATA_MAXLEN) {
  1930. nfc_dev_err(&dev->interface->dev,
  1931. "Data length greater than the max allowed: %d",
  1932. PN533_CMD_DATAEXCH_DATA_MAXLEN);
  1933. return -ENOSYS;
  1934. }
  1935. rc = pn533_send_data_async(dev, PN533_CMD_TG_SET_DATA, skb,
  1936. pn533_tm_send_complete, NULL);
  1937. if (rc < 0)
  1938. dev_kfree_skb(skb);
  1939. return rc;
  1940. }
  1941. static void pn533_wq_mi_recv(struct work_struct *work)
  1942. {
  1943. struct pn533 *dev = container_of(work, struct pn533, mi_work);
  1944. struct sk_buff *skb;
  1945. int rc;
  1946. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1947. skb = pn533_alloc_skb(dev, PN533_CMD_DATAEXCH_HEAD_LEN);
  1948. if (!skb)
  1949. goto error;
  1950. switch (dev->device_type) {
  1951. case PN533_DEVICE_PASORI:
  1952. if (dev->tgt_active_prot == NFC_PROTO_FELICA) {
  1953. rc = pn533_send_cmd_direct_async(dev,
  1954. PN533_CMD_IN_COMM_THRU,
  1955. skb,
  1956. pn533_data_exchange_complete,
  1957. dev->cmd_complete_mi_arg);
  1958. break;
  1959. }
  1960. default:
  1961. *skb_put(skb, sizeof(u8)) = 1; /*TG*/
  1962. rc = pn533_send_cmd_direct_async(dev,
  1963. PN533_CMD_IN_DATA_EXCHANGE,
  1964. skb,
  1965. pn533_data_exchange_complete,
  1966. dev->cmd_complete_mi_arg);
  1967. break;
  1968. }
  1969. if (rc == 0) /* success */
  1970. return;
  1971. nfc_dev_err(&dev->interface->dev,
  1972. "Error %d when trying to perform data_exchange", rc);
  1973. dev_kfree_skb(skb);
  1974. kfree(dev->cmd_complete_mi_arg);
  1975. error:
  1976. pn533_send_ack(dev, GFP_KERNEL);
  1977. queue_work(dev->wq, &dev->cmd_work);
  1978. }
  1979. static int pn533_set_configuration(struct pn533 *dev, u8 cfgitem, u8 *cfgdata,
  1980. u8 cfgdata_len)
  1981. {
  1982. struct sk_buff *skb;
  1983. struct sk_buff *resp;
  1984. int skb_len;
  1985. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1986. skb_len = sizeof(cfgitem) + cfgdata_len; /* cfgitem + cfgdata */
  1987. skb = pn533_alloc_skb(dev, skb_len);
  1988. if (!skb)
  1989. return -ENOMEM;
  1990. *skb_put(skb, sizeof(cfgitem)) = cfgitem;
  1991. memcpy(skb_put(skb, cfgdata_len), cfgdata, cfgdata_len);
  1992. resp = pn533_send_cmd_sync(dev, PN533_CMD_RF_CONFIGURATION, skb);
  1993. if (IS_ERR(resp))
  1994. return PTR_ERR(resp);
  1995. dev_kfree_skb(resp);
  1996. return 0;
  1997. }
  1998. static int pn533_get_firmware_version(struct pn533 *dev,
  1999. struct pn533_fw_version *fv)
  2000. {
  2001. struct sk_buff *skb;
  2002. struct sk_buff *resp;
  2003. skb = pn533_alloc_skb(dev, 0);
  2004. if (!skb)
  2005. return -ENOMEM;
  2006. resp = pn533_send_cmd_sync(dev, PN533_CMD_GET_FIRMWARE_VERSION, skb);
  2007. if (IS_ERR(resp))
  2008. return PTR_ERR(resp);
  2009. fv->ic = resp->data[0];
  2010. fv->ver = resp->data[1];
  2011. fv->rev = resp->data[2];
  2012. fv->support = resp->data[3];
  2013. dev_kfree_skb(resp);
  2014. return 0;
  2015. }
  2016. static int pn533_pasori_fw_reset(struct pn533 *dev)
  2017. {
  2018. struct sk_buff *skb;
  2019. struct sk_buff *resp;
  2020. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  2021. skb = pn533_alloc_skb(dev, sizeof(u8));
  2022. if (!skb)
  2023. return -ENOMEM;
  2024. *skb_put(skb, sizeof(u8)) = 0x1;
  2025. resp = pn533_send_cmd_sync(dev, 0x18, skb);
  2026. if (IS_ERR(resp))
  2027. return PTR_ERR(resp);
  2028. dev_kfree_skb(resp);
  2029. return 0;
  2030. }
  2031. struct pn533_acr122_poweron_rdr_arg {
  2032. int rc;
  2033. struct completion done;
  2034. };
  2035. static void pn533_acr122_poweron_rdr_resp(struct urb *urb)
  2036. {
  2037. struct pn533_acr122_poweron_rdr_arg *arg = urb->context;
  2038. nfc_dev_dbg(&urb->dev->dev, "%s", __func__);
  2039. print_hex_dump_debug("ACR122 RX: ", DUMP_PREFIX_NONE, 16, 1,
  2040. urb->transfer_buffer, urb->transfer_buffer_length,
  2041. false);
  2042. arg->rc = urb->status;
  2043. complete(&arg->done);
  2044. }
  2045. static int pn533_acr122_poweron_rdr(struct pn533 *dev)
  2046. {
  2047. /* Power on th reader (CCID cmd) */
  2048. u8 cmd[10] = {PN533_ACR122_PC_TO_RDR_ICCPOWERON,
  2049. 0, 0, 0, 0, 0, 0, 3, 0, 0};
  2050. u8 buf[255];
  2051. int rc;
  2052. void *cntx;
  2053. struct pn533_acr122_poweron_rdr_arg arg;
  2054. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  2055. init_completion(&arg.done);
  2056. cntx = dev->in_urb->context; /* backup context */
  2057. dev->in_urb->transfer_buffer = buf;
  2058. dev->in_urb->transfer_buffer_length = 255;
  2059. dev->in_urb->complete = pn533_acr122_poweron_rdr_resp;
  2060. dev->in_urb->context = &arg;
  2061. dev->out_urb->transfer_buffer = cmd;
  2062. dev->out_urb->transfer_buffer_length = sizeof(cmd);
  2063. print_hex_dump_debug("ACR122 TX: ", DUMP_PREFIX_NONE, 16, 1,
  2064. cmd, sizeof(cmd), false);
  2065. rc = usb_submit_urb(dev->out_urb, GFP_KERNEL);
  2066. if (rc) {
  2067. nfc_dev_err(&dev->interface->dev,
  2068. "Reader power on cmd error %d", rc);
  2069. return rc;
  2070. }
  2071. rc = usb_submit_urb(dev->in_urb, GFP_KERNEL);
  2072. if (rc) {
  2073. nfc_dev_err(&dev->interface->dev,
  2074. "Can't submit for reader power on cmd response %d",
  2075. rc);
  2076. return rc;
  2077. }
  2078. wait_for_completion(&arg.done);
  2079. dev->in_urb->context = cntx; /* restore context */
  2080. return arg.rc;
  2081. }
  2082. static int pn533_rf_field(struct nfc_dev *nfc_dev, u8 rf)
  2083. {
  2084. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  2085. u8 rf_field = !!rf;
  2086. int rc;
  2087. rf_field |= PN533_CFGITEM_RF_FIELD_AUTO_RFCA;
  2088. rc = pn533_set_configuration(dev, PN533_CFGITEM_RF_FIELD,
  2089. (u8 *)&rf_field, 1);
  2090. if (rc) {
  2091. nfc_dev_err(&dev->interface->dev,
  2092. "Error on setting RF field");
  2093. return rc;
  2094. }
  2095. return rc;
  2096. }
  2097. int pn533_dev_up(struct nfc_dev *nfc_dev)
  2098. {
  2099. return pn533_rf_field(nfc_dev, 1);
  2100. }
  2101. int pn533_dev_down(struct nfc_dev *nfc_dev)
  2102. {
  2103. return pn533_rf_field(nfc_dev, 0);
  2104. }
  2105. static struct nfc_ops pn533_nfc_ops = {
  2106. .dev_up = pn533_dev_up,
  2107. .dev_down = pn533_dev_down,
  2108. .dep_link_up = pn533_dep_link_up,
  2109. .dep_link_down = pn533_dep_link_down,
  2110. .start_poll = pn533_start_poll,
  2111. .stop_poll = pn533_stop_poll,
  2112. .activate_target = pn533_activate_target,
  2113. .deactivate_target = pn533_deactivate_target,
  2114. .im_transceive = pn533_transceive,
  2115. .tm_send = pn533_tm_send,
  2116. };
  2117. static int pn533_setup(struct pn533 *dev)
  2118. {
  2119. struct pn533_config_max_retries max_retries;
  2120. struct pn533_config_timing timing;
  2121. u8 pasori_cfg[3] = {0x08, 0x01, 0x08};
  2122. int rc;
  2123. switch (dev->device_type) {
  2124. case PN533_DEVICE_STD:
  2125. case PN533_DEVICE_PASORI:
  2126. case PN533_DEVICE_ACR122U:
  2127. max_retries.mx_rty_atr = 0x2;
  2128. max_retries.mx_rty_psl = 0x1;
  2129. max_retries.mx_rty_passive_act =
  2130. PN533_CONFIG_MAX_RETRIES_NO_RETRY;
  2131. timing.rfu = PN533_CONFIG_TIMING_102;
  2132. timing.atr_res_timeout = PN533_CONFIG_TIMING_102;
  2133. timing.dep_timeout = PN533_CONFIG_TIMING_204;
  2134. break;
  2135. default:
  2136. nfc_dev_err(&dev->interface->dev, "Unknown device type %d\n",
  2137. dev->device_type);
  2138. return -EINVAL;
  2139. }
  2140. rc = pn533_set_configuration(dev, PN533_CFGITEM_MAX_RETRIES,
  2141. (u8 *)&max_retries, sizeof(max_retries));
  2142. if (rc) {
  2143. nfc_dev_err(&dev->interface->dev,
  2144. "Error on setting MAX_RETRIES config");
  2145. return rc;
  2146. }
  2147. rc = pn533_set_configuration(dev, PN533_CFGITEM_TIMING,
  2148. (u8 *)&timing, sizeof(timing));
  2149. if (rc) {
  2150. nfc_dev_err(&dev->interface->dev,
  2151. "Error on setting RF timings");
  2152. return rc;
  2153. }
  2154. switch (dev->device_type) {
  2155. case PN533_DEVICE_STD:
  2156. break;
  2157. case PN533_DEVICE_PASORI:
  2158. pn533_pasori_fw_reset(dev);
  2159. rc = pn533_set_configuration(dev, PN533_CFGITEM_PASORI,
  2160. pasori_cfg, 3);
  2161. if (rc) {
  2162. nfc_dev_err(&dev->interface->dev,
  2163. "Error while settings PASORI config");
  2164. return rc;
  2165. }
  2166. pn533_pasori_fw_reset(dev);
  2167. break;
  2168. }
  2169. return 0;
  2170. }
  2171. static int pn533_probe(struct usb_interface *interface,
  2172. const struct usb_device_id *id)
  2173. {
  2174. struct pn533_fw_version fw_ver;
  2175. struct pn533 *dev;
  2176. struct usb_host_interface *iface_desc;
  2177. struct usb_endpoint_descriptor *endpoint;
  2178. int in_endpoint = 0;
  2179. int out_endpoint = 0;
  2180. int rc = -ENOMEM;
  2181. int i;
  2182. u32 protocols;
  2183. dev = kzalloc(sizeof(*dev), GFP_KERNEL);
  2184. if (!dev)
  2185. return -ENOMEM;
  2186. dev->udev = usb_get_dev(interface_to_usbdev(interface));
  2187. dev->interface = interface;
  2188. mutex_init(&dev->cmd_lock);
  2189. iface_desc = interface->cur_altsetting;
  2190. for (i = 0; i < iface_desc->desc.bNumEndpoints; ++i) {
  2191. endpoint = &iface_desc->endpoint[i].desc;
  2192. if (!in_endpoint && usb_endpoint_is_bulk_in(endpoint))
  2193. in_endpoint = endpoint->bEndpointAddress;
  2194. if (!out_endpoint && usb_endpoint_is_bulk_out(endpoint))
  2195. out_endpoint = endpoint->bEndpointAddress;
  2196. }
  2197. if (!in_endpoint || !out_endpoint) {
  2198. nfc_dev_err(&interface->dev,
  2199. "Could not find bulk-in or bulk-out endpoint");
  2200. rc = -ENODEV;
  2201. goto error;
  2202. }
  2203. dev->in_urb = usb_alloc_urb(0, GFP_KERNEL);
  2204. dev->out_urb = usb_alloc_urb(0, GFP_KERNEL);
  2205. if (!dev->in_urb || !dev->out_urb)
  2206. goto error;
  2207. usb_fill_bulk_urb(dev->in_urb, dev->udev,
  2208. usb_rcvbulkpipe(dev->udev, in_endpoint),
  2209. NULL, 0, NULL, dev);
  2210. usb_fill_bulk_urb(dev->out_urb, dev->udev,
  2211. usb_sndbulkpipe(dev->udev, out_endpoint),
  2212. NULL, 0, pn533_send_complete, dev);
  2213. INIT_WORK(&dev->cmd_work, pn533_wq_cmd);
  2214. INIT_WORK(&dev->cmd_complete_work, pn533_wq_cmd_complete);
  2215. INIT_WORK(&dev->mi_work, pn533_wq_mi_recv);
  2216. INIT_WORK(&dev->tg_work, pn533_wq_tg_get_data);
  2217. INIT_WORK(&dev->poll_work, pn533_wq_poll);
  2218. INIT_WORK(&dev->rf_work, pn533_wq_rf);
  2219. dev->wq = alloc_ordered_workqueue("pn533", 0);
  2220. if (dev->wq == NULL)
  2221. goto error;
  2222. init_timer(&dev->listen_timer);
  2223. dev->listen_timer.data = (unsigned long) dev;
  2224. dev->listen_timer.function = pn533_listen_mode_timer;
  2225. skb_queue_head_init(&dev->resp_q);
  2226. INIT_LIST_HEAD(&dev->cmd_queue);
  2227. usb_set_intfdata(interface, dev);
  2228. dev->ops = &pn533_std_frame_ops;
  2229. dev->protocol_type = PN533_PROTO_REQ_ACK_RESP;
  2230. dev->device_type = id->driver_info;
  2231. switch (dev->device_type) {
  2232. case PN533_DEVICE_STD:
  2233. protocols = PN533_ALL_PROTOCOLS;
  2234. break;
  2235. case PN533_DEVICE_PASORI:
  2236. protocols = PN533_NO_TYPE_B_PROTOCOLS;
  2237. break;
  2238. case PN533_DEVICE_ACR122U:
  2239. protocols = PN533_NO_TYPE_B_PROTOCOLS;
  2240. dev->ops = &pn533_acr122_frame_ops;
  2241. dev->protocol_type = PN533_PROTO_REQ_RESP,
  2242. rc = pn533_acr122_poweron_rdr(dev);
  2243. if (rc < 0) {
  2244. nfc_dev_err(&dev->interface->dev,
  2245. "Couldn't poweron the reader (error %d)",
  2246. rc);
  2247. goto destroy_wq;
  2248. }
  2249. break;
  2250. default:
  2251. nfc_dev_err(&dev->interface->dev, "Unknown device type %d\n",
  2252. dev->device_type);
  2253. rc = -EINVAL;
  2254. goto destroy_wq;
  2255. }
  2256. memset(&fw_ver, 0, sizeof(fw_ver));
  2257. rc = pn533_get_firmware_version(dev, &fw_ver);
  2258. if (rc < 0)
  2259. goto destroy_wq;
  2260. nfc_dev_info(&dev->interface->dev,
  2261. "NXP PN5%02X firmware ver %d.%d now attached",
  2262. fw_ver.ic, fw_ver.ver, fw_ver.rev);
  2263. dev->nfc_dev = nfc_allocate_device(&pn533_nfc_ops, protocols,
  2264. dev->ops->tx_header_len +
  2265. PN533_CMD_DATAEXCH_HEAD_LEN,
  2266. dev->ops->tx_tail_len);
  2267. if (!dev->nfc_dev) {
  2268. rc = -ENOMEM;
  2269. goto destroy_wq;
  2270. }
  2271. nfc_set_parent_dev(dev->nfc_dev, &interface->dev);
  2272. nfc_set_drvdata(dev->nfc_dev, dev);
  2273. rc = nfc_register_device(dev->nfc_dev);
  2274. if (rc)
  2275. goto free_nfc_dev;
  2276. rc = pn533_setup(dev);
  2277. if (rc)
  2278. goto unregister_nfc_dev;
  2279. return 0;
  2280. unregister_nfc_dev:
  2281. nfc_unregister_device(dev->nfc_dev);
  2282. free_nfc_dev:
  2283. nfc_free_device(dev->nfc_dev);
  2284. destroy_wq:
  2285. destroy_workqueue(dev->wq);
  2286. error:
  2287. usb_free_urb(dev->in_urb);
  2288. usb_free_urb(dev->out_urb);
  2289. usb_put_dev(dev->udev);
  2290. kfree(dev);
  2291. return rc;
  2292. }
  2293. static void pn533_disconnect(struct usb_interface *interface)
  2294. {
  2295. struct pn533 *dev;
  2296. struct pn533_cmd *cmd, *n;
  2297. dev = usb_get_intfdata(interface);
  2298. usb_set_intfdata(interface, NULL);
  2299. nfc_unregister_device(dev->nfc_dev);
  2300. nfc_free_device(dev->nfc_dev);
  2301. usb_kill_urb(dev->in_urb);
  2302. usb_kill_urb(dev->out_urb);
  2303. destroy_workqueue(dev->wq);
  2304. skb_queue_purge(&dev->resp_q);
  2305. del_timer(&dev->listen_timer);
  2306. list_for_each_entry_safe(cmd, n, &dev->cmd_queue, queue) {
  2307. list_del(&cmd->queue);
  2308. kfree(cmd);
  2309. }
  2310. usb_free_urb(dev->in_urb);
  2311. usb_free_urb(dev->out_urb);
  2312. kfree(dev);
  2313. nfc_dev_info(&interface->dev, "NXP PN533 NFC device disconnected");
  2314. }
  2315. static struct usb_driver pn533_driver = {
  2316. .name = "pn533",
  2317. .probe = pn533_probe,
  2318. .disconnect = pn533_disconnect,
  2319. .id_table = pn533_table,
  2320. };
  2321. module_usb_driver(pn533_driver);
  2322. MODULE_AUTHOR("Lauro Ramos Venancio <lauro.venancio@openbossa.org>");
  2323. MODULE_AUTHOR("Aloisio Almeida Jr <aloisio.almeida@openbossa.org>");
  2324. MODULE_AUTHOR("Waldemar Rymarkiewicz <waldemar.rymarkiewicz@tieto.com>");
  2325. MODULE_DESCRIPTION("PN533 usb driver ver " VERSION);
  2326. MODULE_VERSION(VERSION);
  2327. MODULE_LICENSE("GPL");