pn533.c 54 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314
  1. /*
  2. * Copyright (C) 2011 Instituto Nokia de Tecnologia
  3. *
  4. * Authors:
  5. * Lauro Ramos Venancio <lauro.venancio@openbossa.org>
  6. * Aloisio Almeida Jr <aloisio.almeida@openbossa.org>
  7. *
  8. * This program is free software; you can redistribute it and/or modify
  9. * it under the terms of the GNU General Public License as published by
  10. * the Free Software Foundation; either version 2 of the License, or
  11. * (at your option) any later version.
  12. *
  13. * This program is distributed in the hope that it will be useful,
  14. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. * GNU General Public License for more details.
  17. *
  18. * You should have received a copy of the GNU General Public License
  19. * along with this program; if not, write to the
  20. * Free Software Foundation, Inc.,
  21. * 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
  22. */
  23. #include <linux/device.h>
  24. #include <linux/kernel.h>
  25. #include <linux/module.h>
  26. #include <linux/slab.h>
  27. #include <linux/usb.h>
  28. #include <linux/nfc.h>
  29. #include <linux/netdevice.h>
  30. #include <net/nfc/nfc.h>
  31. #define VERSION "0.1"
  32. #define PN533_VENDOR_ID 0x4CC
  33. #define PN533_PRODUCT_ID 0x2533
  34. #define SCM_VENDOR_ID 0x4E6
  35. #define SCL3711_PRODUCT_ID 0x5591
  36. static const struct usb_device_id pn533_table[] = {
  37. { USB_DEVICE(PN533_VENDOR_ID, PN533_PRODUCT_ID) },
  38. { USB_DEVICE(SCM_VENDOR_ID, SCL3711_PRODUCT_ID) },
  39. { }
  40. };
  41. MODULE_DEVICE_TABLE(usb, pn533_table);
  42. /* How much time we spend listening for initiators */
  43. #define PN533_LISTEN_TIME 2
  44. /* frame definitions */
  45. #define PN533_FRAME_TAIL_SIZE 2
  46. #define PN533_FRAME_SIZE(f) (sizeof(struct pn533_frame) + f->datalen + \
  47. PN533_FRAME_TAIL_SIZE)
  48. #define PN533_FRAME_ACK_SIZE (sizeof(struct pn533_frame) + 1)
  49. #define PN533_FRAME_CHECKSUM(f) (f->data[f->datalen])
  50. #define PN533_FRAME_POSTAMBLE(f) (f->data[f->datalen + 1])
  51. /* start of frame */
  52. #define PN533_SOF 0x00FF
  53. /* frame identifier: in/out/error */
  54. #define PN533_FRAME_IDENTIFIER(f) (f->data[0])
  55. #define PN533_DIR_OUT 0xD4
  56. #define PN533_DIR_IN 0xD5
  57. /* PN533 Commands */
  58. #define PN533_FRAME_CMD(f) (f->data[1])
  59. #define PN533_FRAME_CMD_PARAMS_PTR(f) (&f->data[2])
  60. #define PN533_FRAME_CMD_PARAMS_LEN(f) (f->datalen - 2)
  61. #define PN533_CMD_GET_FIRMWARE_VERSION 0x02
  62. #define PN533_CMD_RF_CONFIGURATION 0x32
  63. #define PN533_CMD_IN_DATA_EXCHANGE 0x40
  64. #define PN533_CMD_IN_LIST_PASSIVE_TARGET 0x4A
  65. #define PN533_CMD_IN_ATR 0x50
  66. #define PN533_CMD_IN_RELEASE 0x52
  67. #define PN533_CMD_IN_JUMP_FOR_DEP 0x56
  68. #define PN533_CMD_TG_INIT_AS_TARGET 0x8c
  69. #define PN533_CMD_TG_GET_DATA 0x86
  70. #define PN533_CMD_TG_SET_DATA 0x8e
  71. #define PN533_CMD_RESPONSE(cmd) (cmd + 1)
  72. /* PN533 Return codes */
  73. #define PN533_CMD_RET_MASK 0x3F
  74. #define PN533_CMD_MI_MASK 0x40
  75. #define PN533_CMD_RET_SUCCESS 0x00
  76. /* PN533 status codes */
  77. #define PN533_STATUS_TARGET_RELEASED 0x29
  78. struct pn533;
  79. typedef int (*pn533_cmd_complete_t) (struct pn533 *dev, void *arg,
  80. u8 *params, int params_len);
  81. /* structs for pn533 commands */
  82. /* PN533_CMD_GET_FIRMWARE_VERSION */
  83. struct pn533_fw_version {
  84. u8 ic;
  85. u8 ver;
  86. u8 rev;
  87. u8 support;
  88. };
  89. /* PN533_CMD_RF_CONFIGURATION */
  90. #define PN533_CFGITEM_TIMING 0x02
  91. #define PN533_CFGITEM_MAX_RETRIES 0x05
  92. #define PN533_CONFIG_TIMING_102 0xb
  93. #define PN533_CONFIG_TIMING_204 0xc
  94. #define PN533_CONFIG_TIMING_409 0xd
  95. #define PN533_CONFIG_TIMING_819 0xe
  96. #define PN533_CONFIG_MAX_RETRIES_NO_RETRY 0x00
  97. #define PN533_CONFIG_MAX_RETRIES_ENDLESS 0xFF
  98. struct pn533_config_max_retries {
  99. u8 mx_rty_atr;
  100. u8 mx_rty_psl;
  101. u8 mx_rty_passive_act;
  102. } __packed;
  103. struct pn533_config_timing {
  104. u8 rfu;
  105. u8 atr_res_timeout;
  106. u8 dep_timeout;
  107. } __packed;
  108. /* PN533_CMD_IN_LIST_PASSIVE_TARGET */
  109. /* felica commands opcode */
  110. #define PN533_FELICA_OPC_SENSF_REQ 0
  111. #define PN533_FELICA_OPC_SENSF_RES 1
  112. /* felica SENSF_REQ parameters */
  113. #define PN533_FELICA_SENSF_SC_ALL 0xFFFF
  114. #define PN533_FELICA_SENSF_RC_NO_SYSTEM_CODE 0
  115. #define PN533_FELICA_SENSF_RC_SYSTEM_CODE 1
  116. #define PN533_FELICA_SENSF_RC_ADVANCED_PROTOCOL 2
  117. /* type B initiator_data values */
  118. #define PN533_TYPE_B_AFI_ALL_FAMILIES 0
  119. #define PN533_TYPE_B_POLL_METHOD_TIMESLOT 0
  120. #define PN533_TYPE_B_POLL_METHOD_PROBABILISTIC 1
  121. union pn533_cmd_poll_initdata {
  122. struct {
  123. u8 afi;
  124. u8 polling_method;
  125. } __packed type_b;
  126. struct {
  127. u8 opcode;
  128. __be16 sc;
  129. u8 rc;
  130. u8 tsn;
  131. } __packed felica;
  132. };
  133. /* Poll modulations */
  134. enum {
  135. PN533_POLL_MOD_106KBPS_A,
  136. PN533_POLL_MOD_212KBPS_FELICA,
  137. PN533_POLL_MOD_424KBPS_FELICA,
  138. PN533_POLL_MOD_106KBPS_JEWEL,
  139. PN533_POLL_MOD_847KBPS_B,
  140. PN533_LISTEN_MOD,
  141. __PN533_POLL_MOD_AFTER_LAST,
  142. };
  143. #define PN533_POLL_MOD_MAX (__PN533_POLL_MOD_AFTER_LAST - 1)
  144. struct pn533_poll_modulations {
  145. struct {
  146. u8 maxtg;
  147. u8 brty;
  148. union pn533_cmd_poll_initdata initiator_data;
  149. } __packed data;
  150. u8 len;
  151. };
  152. const struct pn533_poll_modulations poll_mod[] = {
  153. [PN533_POLL_MOD_106KBPS_A] = {
  154. .data = {
  155. .maxtg = 1,
  156. .brty = 0,
  157. },
  158. .len = 2,
  159. },
  160. [PN533_POLL_MOD_212KBPS_FELICA] = {
  161. .data = {
  162. .maxtg = 1,
  163. .brty = 1,
  164. .initiator_data.felica = {
  165. .opcode = PN533_FELICA_OPC_SENSF_REQ,
  166. .sc = PN533_FELICA_SENSF_SC_ALL,
  167. .rc = PN533_FELICA_SENSF_RC_NO_SYSTEM_CODE,
  168. .tsn = 0,
  169. },
  170. },
  171. .len = 7,
  172. },
  173. [PN533_POLL_MOD_424KBPS_FELICA] = {
  174. .data = {
  175. .maxtg = 1,
  176. .brty = 2,
  177. .initiator_data.felica = {
  178. .opcode = PN533_FELICA_OPC_SENSF_REQ,
  179. .sc = PN533_FELICA_SENSF_SC_ALL,
  180. .rc = PN533_FELICA_SENSF_RC_NO_SYSTEM_CODE,
  181. .tsn = 0,
  182. },
  183. },
  184. .len = 7,
  185. },
  186. [PN533_POLL_MOD_106KBPS_JEWEL] = {
  187. .data = {
  188. .maxtg = 1,
  189. .brty = 4,
  190. },
  191. .len = 2,
  192. },
  193. [PN533_POLL_MOD_847KBPS_B] = {
  194. .data = {
  195. .maxtg = 1,
  196. .brty = 8,
  197. .initiator_data.type_b = {
  198. .afi = PN533_TYPE_B_AFI_ALL_FAMILIES,
  199. .polling_method =
  200. PN533_TYPE_B_POLL_METHOD_TIMESLOT,
  201. },
  202. },
  203. .len = 3,
  204. },
  205. [PN533_LISTEN_MOD] = {
  206. .len = 0,
  207. },
  208. };
  209. /* PN533_CMD_IN_ATR */
  210. struct pn533_cmd_activate_param {
  211. u8 tg;
  212. u8 next;
  213. } __packed;
  214. struct pn533_cmd_activate_response {
  215. u8 status;
  216. u8 nfcid3t[10];
  217. u8 didt;
  218. u8 bst;
  219. u8 brt;
  220. u8 to;
  221. u8 ppt;
  222. /* optional */
  223. u8 gt[];
  224. } __packed;
  225. /* PN533_CMD_IN_JUMP_FOR_DEP */
  226. struct pn533_cmd_jump_dep {
  227. u8 active;
  228. u8 baud;
  229. u8 next;
  230. u8 data[];
  231. } __packed;
  232. struct pn533_cmd_jump_dep_response {
  233. u8 status;
  234. u8 tg;
  235. u8 nfcid3t[10];
  236. u8 didt;
  237. u8 bst;
  238. u8 brt;
  239. u8 to;
  240. u8 ppt;
  241. /* optional */
  242. u8 gt[];
  243. } __packed;
  244. /* PN533_TG_INIT_AS_TARGET */
  245. #define PN533_INIT_TARGET_PASSIVE 0x1
  246. #define PN533_INIT_TARGET_DEP 0x2
  247. #define PN533_INIT_TARGET_RESP_FRAME_MASK 0x3
  248. #define PN533_INIT_TARGET_RESP_ACTIVE 0x1
  249. #define PN533_INIT_TARGET_RESP_DEP 0x4
  250. struct pn533_cmd_init_target {
  251. u8 mode;
  252. u8 mifare[6];
  253. u8 felica[18];
  254. u8 nfcid3[10];
  255. u8 gb_len;
  256. u8 gb[];
  257. } __packed;
  258. struct pn533_cmd_init_target_response {
  259. u8 mode;
  260. u8 cmd[];
  261. } __packed;
  262. struct pn533 {
  263. struct usb_device *udev;
  264. struct usb_interface *interface;
  265. struct nfc_dev *nfc_dev;
  266. struct urb *out_urb;
  267. int out_maxlen;
  268. struct pn533_frame *out_frame;
  269. struct urb *in_urb;
  270. int in_maxlen;
  271. struct pn533_frame *in_frame;
  272. struct sk_buff_head resp_q;
  273. struct workqueue_struct *wq;
  274. struct work_struct cmd_work;
  275. struct work_struct poll_work;
  276. struct work_struct mi_work;
  277. struct work_struct tg_work;
  278. struct timer_list listen_timer;
  279. struct pn533_frame *wq_in_frame;
  280. int wq_in_error;
  281. int cancel_listen;
  282. pn533_cmd_complete_t cmd_complete;
  283. void *cmd_complete_arg;
  284. struct mutex cmd_lock;
  285. u8 cmd;
  286. struct pn533_poll_modulations *poll_mod_active[PN533_POLL_MOD_MAX + 1];
  287. u8 poll_mod_count;
  288. u8 poll_mod_curr;
  289. u32 poll_protocols;
  290. u32 listen_protocols;
  291. u8 *gb;
  292. size_t gb_len;
  293. u8 tgt_available_prots;
  294. u8 tgt_active_prot;
  295. u8 tgt_mode;
  296. };
  297. struct pn533_frame {
  298. u8 preamble;
  299. __be16 start_frame;
  300. u8 datalen;
  301. u8 datalen_checksum;
  302. u8 data[];
  303. } __packed;
  304. /* The rule: value + checksum = 0 */
  305. static inline u8 pn533_checksum(u8 value)
  306. {
  307. return ~value + 1;
  308. }
  309. /* The rule: sum(data elements) + checksum = 0 */
  310. static u8 pn533_data_checksum(u8 *data, int datalen)
  311. {
  312. u8 sum = 0;
  313. int i;
  314. for (i = 0; i < datalen; i++)
  315. sum += data[i];
  316. return pn533_checksum(sum);
  317. }
  318. /**
  319. * pn533_tx_frame_ack - create a ack frame
  320. * @frame: The frame to be set as ack
  321. *
  322. * Ack is different type of standard frame. As a standard frame, it has
  323. * preamble and start_frame. However the checksum of this frame must fail,
  324. * i.e. datalen + datalen_checksum must NOT be zero. When the checksum test
  325. * fails and datalen = 0 and datalen_checksum = 0xFF, the frame is a ack.
  326. * After datalen_checksum field, the postamble is placed.
  327. */
  328. static void pn533_tx_frame_ack(struct pn533_frame *frame)
  329. {
  330. frame->preamble = 0;
  331. frame->start_frame = cpu_to_be16(PN533_SOF);
  332. frame->datalen = 0;
  333. frame->datalen_checksum = 0xFF;
  334. /* data[0] is used as postamble */
  335. frame->data[0] = 0;
  336. }
  337. static void pn533_tx_frame_init(struct pn533_frame *frame, u8 cmd)
  338. {
  339. frame->preamble = 0;
  340. frame->start_frame = cpu_to_be16(PN533_SOF);
  341. PN533_FRAME_IDENTIFIER(frame) = PN533_DIR_OUT;
  342. PN533_FRAME_CMD(frame) = cmd;
  343. frame->datalen = 2;
  344. }
  345. static void pn533_tx_frame_finish(struct pn533_frame *frame)
  346. {
  347. frame->datalen_checksum = pn533_checksum(frame->datalen);
  348. PN533_FRAME_CHECKSUM(frame) =
  349. pn533_data_checksum(frame->data, frame->datalen);
  350. PN533_FRAME_POSTAMBLE(frame) = 0;
  351. }
  352. static bool pn533_rx_frame_is_valid(struct pn533_frame *frame)
  353. {
  354. u8 checksum;
  355. if (frame->start_frame != cpu_to_be16(PN533_SOF))
  356. return false;
  357. checksum = pn533_checksum(frame->datalen);
  358. if (checksum != frame->datalen_checksum)
  359. return false;
  360. checksum = pn533_data_checksum(frame->data, frame->datalen);
  361. if (checksum != PN533_FRAME_CHECKSUM(frame))
  362. return false;
  363. return true;
  364. }
  365. static bool pn533_rx_frame_is_ack(struct pn533_frame *frame)
  366. {
  367. if (frame->start_frame != cpu_to_be16(PN533_SOF))
  368. return false;
  369. if (frame->datalen != 0 || frame->datalen_checksum != 0xFF)
  370. return false;
  371. return true;
  372. }
  373. static bool pn533_rx_frame_is_cmd_response(struct pn533_frame *frame, u8 cmd)
  374. {
  375. return (PN533_FRAME_CMD(frame) == PN533_CMD_RESPONSE(cmd));
  376. }
  377. static void pn533_wq_cmd_complete(struct work_struct *work)
  378. {
  379. struct pn533 *dev = container_of(work, struct pn533, cmd_work);
  380. struct pn533_frame *in_frame;
  381. int rc;
  382. in_frame = dev->wq_in_frame;
  383. if (dev->wq_in_error)
  384. rc = dev->cmd_complete(dev, dev->cmd_complete_arg, NULL,
  385. dev->wq_in_error);
  386. else
  387. rc = dev->cmd_complete(dev, dev->cmd_complete_arg,
  388. PN533_FRAME_CMD_PARAMS_PTR(in_frame),
  389. PN533_FRAME_CMD_PARAMS_LEN(in_frame));
  390. if (rc != -EINPROGRESS)
  391. mutex_unlock(&dev->cmd_lock);
  392. }
  393. static void pn533_recv_response(struct urb *urb)
  394. {
  395. struct pn533 *dev = urb->context;
  396. struct pn533_frame *in_frame;
  397. dev->wq_in_frame = NULL;
  398. switch (urb->status) {
  399. case 0:
  400. /* success */
  401. break;
  402. case -ECONNRESET:
  403. case -ENOENT:
  404. case -ESHUTDOWN:
  405. nfc_dev_dbg(&dev->interface->dev, "Urb shutting down with"
  406. " status: %d", urb->status);
  407. dev->wq_in_error = urb->status;
  408. goto sched_wq;
  409. default:
  410. nfc_dev_err(&dev->interface->dev, "Nonzero urb status received:"
  411. " %d", urb->status);
  412. dev->wq_in_error = urb->status;
  413. goto sched_wq;
  414. }
  415. in_frame = dev->in_urb->transfer_buffer;
  416. if (!pn533_rx_frame_is_valid(in_frame)) {
  417. nfc_dev_err(&dev->interface->dev, "Received an invalid frame");
  418. dev->wq_in_error = -EIO;
  419. goto sched_wq;
  420. }
  421. if (!pn533_rx_frame_is_cmd_response(in_frame, dev->cmd)) {
  422. nfc_dev_err(&dev->interface->dev, "The received frame is not "
  423. "response to the last command");
  424. dev->wq_in_error = -EIO;
  425. goto sched_wq;
  426. }
  427. nfc_dev_dbg(&dev->interface->dev, "Received a valid frame");
  428. dev->wq_in_error = 0;
  429. dev->wq_in_frame = in_frame;
  430. sched_wq:
  431. queue_work(dev->wq, &dev->cmd_work);
  432. }
  433. static int pn533_submit_urb_for_response(struct pn533 *dev, gfp_t flags)
  434. {
  435. dev->in_urb->complete = pn533_recv_response;
  436. return usb_submit_urb(dev->in_urb, flags);
  437. }
  438. static void pn533_recv_ack(struct urb *urb)
  439. {
  440. struct pn533 *dev = urb->context;
  441. struct pn533_frame *in_frame;
  442. int rc;
  443. switch (urb->status) {
  444. case 0:
  445. /* success */
  446. break;
  447. case -ECONNRESET:
  448. case -ENOENT:
  449. case -ESHUTDOWN:
  450. nfc_dev_dbg(&dev->interface->dev, "Urb shutting down with"
  451. " status: %d", urb->status);
  452. dev->wq_in_error = urb->status;
  453. goto sched_wq;
  454. default:
  455. nfc_dev_err(&dev->interface->dev, "Nonzero urb status received:"
  456. " %d", urb->status);
  457. dev->wq_in_error = urb->status;
  458. goto sched_wq;
  459. }
  460. in_frame = dev->in_urb->transfer_buffer;
  461. if (!pn533_rx_frame_is_ack(in_frame)) {
  462. nfc_dev_err(&dev->interface->dev, "Received an invalid ack");
  463. dev->wq_in_error = -EIO;
  464. goto sched_wq;
  465. }
  466. nfc_dev_dbg(&dev->interface->dev, "Received a valid ack");
  467. rc = pn533_submit_urb_for_response(dev, GFP_ATOMIC);
  468. if (rc) {
  469. nfc_dev_err(&dev->interface->dev, "usb_submit_urb failed with"
  470. " result %d", rc);
  471. dev->wq_in_error = rc;
  472. goto sched_wq;
  473. }
  474. return;
  475. sched_wq:
  476. dev->wq_in_frame = NULL;
  477. queue_work(dev->wq, &dev->cmd_work);
  478. }
  479. static int pn533_submit_urb_for_ack(struct pn533 *dev, gfp_t flags)
  480. {
  481. dev->in_urb->complete = pn533_recv_ack;
  482. return usb_submit_urb(dev->in_urb, flags);
  483. }
  484. static int pn533_send_ack(struct pn533 *dev, gfp_t flags)
  485. {
  486. int rc;
  487. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  488. pn533_tx_frame_ack(dev->out_frame);
  489. dev->out_urb->transfer_buffer = dev->out_frame;
  490. dev->out_urb->transfer_buffer_length = PN533_FRAME_ACK_SIZE;
  491. rc = usb_submit_urb(dev->out_urb, flags);
  492. return rc;
  493. }
  494. static int __pn533_send_cmd_frame_async(struct pn533 *dev,
  495. struct pn533_frame *out_frame,
  496. struct pn533_frame *in_frame,
  497. int in_frame_len,
  498. pn533_cmd_complete_t cmd_complete,
  499. void *arg, gfp_t flags)
  500. {
  501. int rc;
  502. nfc_dev_dbg(&dev->interface->dev, "Sending command 0x%x",
  503. PN533_FRAME_CMD(out_frame));
  504. dev->cmd = PN533_FRAME_CMD(out_frame);
  505. dev->cmd_complete = cmd_complete;
  506. dev->cmd_complete_arg = arg;
  507. dev->out_urb->transfer_buffer = out_frame;
  508. dev->out_urb->transfer_buffer_length =
  509. PN533_FRAME_SIZE(out_frame);
  510. dev->in_urb->transfer_buffer = in_frame;
  511. dev->in_urb->transfer_buffer_length = in_frame_len;
  512. rc = usb_submit_urb(dev->out_urb, flags);
  513. if (rc)
  514. return rc;
  515. rc = pn533_submit_urb_for_ack(dev, flags);
  516. if (rc)
  517. goto error;
  518. return 0;
  519. error:
  520. usb_unlink_urb(dev->out_urb);
  521. return rc;
  522. }
  523. static int pn533_send_cmd_frame_async(struct pn533 *dev,
  524. struct pn533_frame *out_frame,
  525. struct pn533_frame *in_frame,
  526. int in_frame_len,
  527. pn533_cmd_complete_t cmd_complete,
  528. void *arg, gfp_t flags)
  529. {
  530. int rc;
  531. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  532. if (!mutex_trylock(&dev->cmd_lock))
  533. return -EBUSY;
  534. rc = __pn533_send_cmd_frame_async(dev, out_frame, in_frame,
  535. in_frame_len, cmd_complete, arg, flags);
  536. if (rc)
  537. goto error;
  538. return 0;
  539. error:
  540. mutex_unlock(&dev->cmd_lock);
  541. return rc;
  542. }
  543. struct pn533_sync_cmd_response {
  544. int rc;
  545. struct completion done;
  546. };
  547. static int pn533_sync_cmd_complete(struct pn533 *dev, void *_arg,
  548. u8 *params, int params_len)
  549. {
  550. struct pn533_sync_cmd_response *arg = _arg;
  551. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  552. arg->rc = 0;
  553. if (params_len < 0) /* error */
  554. arg->rc = params_len;
  555. complete(&arg->done);
  556. return 0;
  557. }
  558. static int pn533_send_cmd_frame_sync(struct pn533 *dev,
  559. struct pn533_frame *out_frame,
  560. struct pn533_frame *in_frame,
  561. int in_frame_len)
  562. {
  563. int rc;
  564. struct pn533_sync_cmd_response arg;
  565. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  566. init_completion(&arg.done);
  567. rc = pn533_send_cmd_frame_async(dev, out_frame, in_frame, in_frame_len,
  568. pn533_sync_cmd_complete, &arg, GFP_KERNEL);
  569. if (rc)
  570. return rc;
  571. wait_for_completion(&arg.done);
  572. return arg.rc;
  573. }
  574. static void pn533_send_complete(struct urb *urb)
  575. {
  576. struct pn533 *dev = urb->context;
  577. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  578. switch (urb->status) {
  579. case 0:
  580. /* success */
  581. break;
  582. case -ECONNRESET:
  583. case -ENOENT:
  584. case -ESHUTDOWN:
  585. nfc_dev_dbg(&dev->interface->dev, "Urb shutting down with"
  586. " status: %d", urb->status);
  587. break;
  588. default:
  589. nfc_dev_dbg(&dev->interface->dev, "Nonzero urb status received:"
  590. " %d", urb->status);
  591. }
  592. }
  593. struct pn533_target_type_a {
  594. __be16 sens_res;
  595. u8 sel_res;
  596. u8 nfcid_len;
  597. u8 nfcid_data[];
  598. } __packed;
  599. #define PN533_TYPE_A_SENS_RES_NFCID1(x) ((u8)((be16_to_cpu(x) & 0x00C0) >> 6))
  600. #define PN533_TYPE_A_SENS_RES_SSD(x) ((u8)((be16_to_cpu(x) & 0x001F) >> 0))
  601. #define PN533_TYPE_A_SENS_RES_PLATCONF(x) ((u8)((be16_to_cpu(x) & 0x0F00) >> 8))
  602. #define PN533_TYPE_A_SENS_RES_SSD_JEWEL 0x00
  603. #define PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL 0x0C
  604. #define PN533_TYPE_A_SEL_PROT(x) (((x) & 0x60) >> 5)
  605. #define PN533_TYPE_A_SEL_CASCADE(x) (((x) & 0x04) >> 2)
  606. #define PN533_TYPE_A_SEL_PROT_MIFARE 0
  607. #define PN533_TYPE_A_SEL_PROT_ISO14443 1
  608. #define PN533_TYPE_A_SEL_PROT_DEP 2
  609. #define PN533_TYPE_A_SEL_PROT_ISO14443_DEP 3
  610. static bool pn533_target_type_a_is_valid(struct pn533_target_type_a *type_a,
  611. int target_data_len)
  612. {
  613. u8 ssd;
  614. u8 platconf;
  615. if (target_data_len < sizeof(struct pn533_target_type_a))
  616. return false;
  617. /* The lenght check of nfcid[] and ats[] are not being performed because
  618. the values are not being used */
  619. /* Requirement 4.6.3.3 from NFC Forum Digital Spec */
  620. ssd = PN533_TYPE_A_SENS_RES_SSD(type_a->sens_res);
  621. platconf = PN533_TYPE_A_SENS_RES_PLATCONF(type_a->sens_res);
  622. if ((ssd == PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  623. platconf != PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL) ||
  624. (ssd != PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  625. platconf == PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL))
  626. return false;
  627. /* Requirements 4.8.2.1, 4.8.2.3, 4.8.2.5 and 4.8.2.7 from NFC Forum */
  628. if (PN533_TYPE_A_SEL_CASCADE(type_a->sel_res) != 0)
  629. return false;
  630. return true;
  631. }
  632. static int pn533_target_found_type_a(struct nfc_target *nfc_tgt, u8 *tgt_data,
  633. int tgt_data_len)
  634. {
  635. struct pn533_target_type_a *tgt_type_a;
  636. tgt_type_a = (struct pn533_target_type_a *) tgt_data;
  637. if (!pn533_target_type_a_is_valid(tgt_type_a, tgt_data_len))
  638. return -EPROTO;
  639. switch (PN533_TYPE_A_SEL_PROT(tgt_type_a->sel_res)) {
  640. case PN533_TYPE_A_SEL_PROT_MIFARE:
  641. nfc_tgt->supported_protocols = NFC_PROTO_MIFARE_MASK;
  642. break;
  643. case PN533_TYPE_A_SEL_PROT_ISO14443:
  644. nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_MASK;
  645. break;
  646. case PN533_TYPE_A_SEL_PROT_DEP:
  647. nfc_tgt->supported_protocols = NFC_PROTO_NFC_DEP_MASK;
  648. break;
  649. case PN533_TYPE_A_SEL_PROT_ISO14443_DEP:
  650. nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_MASK |
  651. NFC_PROTO_NFC_DEP_MASK;
  652. break;
  653. }
  654. nfc_tgt->sens_res = be16_to_cpu(tgt_type_a->sens_res);
  655. nfc_tgt->sel_res = tgt_type_a->sel_res;
  656. nfc_tgt->nfcid1_len = tgt_type_a->nfcid_len;
  657. memcpy(nfc_tgt->nfcid1, tgt_type_a->nfcid_data, nfc_tgt->nfcid1_len);
  658. return 0;
  659. }
  660. struct pn533_target_felica {
  661. u8 pol_res;
  662. u8 opcode;
  663. u8 nfcid2[8];
  664. u8 pad[8];
  665. /* optional */
  666. u8 syst_code[];
  667. } __packed;
  668. #define PN533_FELICA_SENSF_NFCID2_DEP_B1 0x01
  669. #define PN533_FELICA_SENSF_NFCID2_DEP_B2 0xFE
  670. static bool pn533_target_felica_is_valid(struct pn533_target_felica *felica,
  671. int target_data_len)
  672. {
  673. if (target_data_len < sizeof(struct pn533_target_felica))
  674. return false;
  675. if (felica->opcode != PN533_FELICA_OPC_SENSF_RES)
  676. return false;
  677. return true;
  678. }
  679. static int pn533_target_found_felica(struct nfc_target *nfc_tgt, u8 *tgt_data,
  680. int tgt_data_len)
  681. {
  682. struct pn533_target_felica *tgt_felica;
  683. tgt_felica = (struct pn533_target_felica *) tgt_data;
  684. if (!pn533_target_felica_is_valid(tgt_felica, tgt_data_len))
  685. return -EPROTO;
  686. if (tgt_felica->nfcid2[0] == PN533_FELICA_SENSF_NFCID2_DEP_B1 &&
  687. tgt_felica->nfcid2[1] ==
  688. PN533_FELICA_SENSF_NFCID2_DEP_B2)
  689. nfc_tgt->supported_protocols = NFC_PROTO_NFC_DEP_MASK;
  690. else
  691. nfc_tgt->supported_protocols = NFC_PROTO_FELICA_MASK;
  692. memcpy(nfc_tgt->sensf_res, &tgt_felica->opcode, 9);
  693. nfc_tgt->sensf_res_len = 9;
  694. return 0;
  695. }
  696. struct pn533_target_jewel {
  697. __be16 sens_res;
  698. u8 jewelid[4];
  699. } __packed;
  700. static bool pn533_target_jewel_is_valid(struct pn533_target_jewel *jewel,
  701. int target_data_len)
  702. {
  703. u8 ssd;
  704. u8 platconf;
  705. if (target_data_len < sizeof(struct pn533_target_jewel))
  706. return false;
  707. /* Requirement 4.6.3.3 from NFC Forum Digital Spec */
  708. ssd = PN533_TYPE_A_SENS_RES_SSD(jewel->sens_res);
  709. platconf = PN533_TYPE_A_SENS_RES_PLATCONF(jewel->sens_res);
  710. if ((ssd == PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  711. platconf != PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL) ||
  712. (ssd != PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  713. platconf == PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL))
  714. return false;
  715. return true;
  716. }
  717. static int pn533_target_found_jewel(struct nfc_target *nfc_tgt, u8 *tgt_data,
  718. int tgt_data_len)
  719. {
  720. struct pn533_target_jewel *tgt_jewel;
  721. tgt_jewel = (struct pn533_target_jewel *) tgt_data;
  722. if (!pn533_target_jewel_is_valid(tgt_jewel, tgt_data_len))
  723. return -EPROTO;
  724. nfc_tgt->supported_protocols = NFC_PROTO_JEWEL_MASK;
  725. nfc_tgt->sens_res = be16_to_cpu(tgt_jewel->sens_res);
  726. nfc_tgt->nfcid1_len = 4;
  727. memcpy(nfc_tgt->nfcid1, tgt_jewel->jewelid, nfc_tgt->nfcid1_len);
  728. return 0;
  729. }
  730. struct pn533_type_b_prot_info {
  731. u8 bitrate;
  732. u8 fsci_type;
  733. u8 fwi_adc_fo;
  734. } __packed;
  735. #define PN533_TYPE_B_PROT_FCSI(x) (((x) & 0xF0) >> 4)
  736. #define PN533_TYPE_B_PROT_TYPE(x) (((x) & 0x0F) >> 0)
  737. #define PN533_TYPE_B_PROT_TYPE_RFU_MASK 0x8
  738. struct pn533_type_b_sens_res {
  739. u8 opcode;
  740. u8 nfcid[4];
  741. u8 appdata[4];
  742. struct pn533_type_b_prot_info prot_info;
  743. } __packed;
  744. #define PN533_TYPE_B_OPC_SENSB_RES 0x50
  745. struct pn533_target_type_b {
  746. struct pn533_type_b_sens_res sensb_res;
  747. u8 attrib_res_len;
  748. u8 attrib_res[];
  749. } __packed;
  750. static bool pn533_target_type_b_is_valid(struct pn533_target_type_b *type_b,
  751. int target_data_len)
  752. {
  753. if (target_data_len < sizeof(struct pn533_target_type_b))
  754. return false;
  755. if (type_b->sensb_res.opcode != PN533_TYPE_B_OPC_SENSB_RES)
  756. return false;
  757. if (PN533_TYPE_B_PROT_TYPE(type_b->sensb_res.prot_info.fsci_type) &
  758. PN533_TYPE_B_PROT_TYPE_RFU_MASK)
  759. return false;
  760. return true;
  761. }
  762. static int pn533_target_found_type_b(struct nfc_target *nfc_tgt, u8 *tgt_data,
  763. int tgt_data_len)
  764. {
  765. struct pn533_target_type_b *tgt_type_b;
  766. tgt_type_b = (struct pn533_target_type_b *) tgt_data;
  767. if (!pn533_target_type_b_is_valid(tgt_type_b, tgt_data_len))
  768. return -EPROTO;
  769. nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_MASK;
  770. return 0;
  771. }
  772. struct pn533_poll_response {
  773. u8 nbtg;
  774. u8 tg;
  775. u8 target_data[];
  776. } __packed;
  777. static int pn533_target_found(struct pn533 *dev,
  778. struct pn533_poll_response *resp, int resp_len)
  779. {
  780. int target_data_len;
  781. struct nfc_target nfc_tgt;
  782. int rc;
  783. nfc_dev_dbg(&dev->interface->dev, "%s - modulation=%d", __func__,
  784. dev->poll_mod_curr);
  785. if (resp->tg != 1)
  786. return -EPROTO;
  787. memset(&nfc_tgt, 0, sizeof(struct nfc_target));
  788. target_data_len = resp_len - sizeof(struct pn533_poll_response);
  789. switch (dev->poll_mod_curr) {
  790. case PN533_POLL_MOD_106KBPS_A:
  791. rc = pn533_target_found_type_a(&nfc_tgt, resp->target_data,
  792. target_data_len);
  793. break;
  794. case PN533_POLL_MOD_212KBPS_FELICA:
  795. case PN533_POLL_MOD_424KBPS_FELICA:
  796. rc = pn533_target_found_felica(&nfc_tgt, resp->target_data,
  797. target_data_len);
  798. break;
  799. case PN533_POLL_MOD_106KBPS_JEWEL:
  800. rc = pn533_target_found_jewel(&nfc_tgt, resp->target_data,
  801. target_data_len);
  802. break;
  803. case PN533_POLL_MOD_847KBPS_B:
  804. rc = pn533_target_found_type_b(&nfc_tgt, resp->target_data,
  805. target_data_len);
  806. break;
  807. default:
  808. nfc_dev_err(&dev->interface->dev, "Unknown current poll"
  809. " modulation");
  810. return -EPROTO;
  811. }
  812. if (rc)
  813. return rc;
  814. if (!(nfc_tgt.supported_protocols & dev->poll_protocols)) {
  815. nfc_dev_dbg(&dev->interface->dev, "The target found does not"
  816. " have the desired protocol");
  817. return -EAGAIN;
  818. }
  819. nfc_dev_dbg(&dev->interface->dev, "Target found - supported protocols: "
  820. "0x%x", nfc_tgt.supported_protocols);
  821. dev->tgt_available_prots = nfc_tgt.supported_protocols;
  822. nfc_targets_found(dev->nfc_dev, &nfc_tgt, 1);
  823. return 0;
  824. }
  825. static inline void pn533_poll_next_mod(struct pn533 *dev)
  826. {
  827. dev->poll_mod_curr = (dev->poll_mod_curr + 1) % dev->poll_mod_count;
  828. }
  829. static void pn533_poll_reset_mod_list(struct pn533 *dev)
  830. {
  831. dev->poll_mod_count = 0;
  832. }
  833. static void pn533_poll_add_mod(struct pn533 *dev, u8 mod_index)
  834. {
  835. dev->poll_mod_active[dev->poll_mod_count] =
  836. (struct pn533_poll_modulations *) &poll_mod[mod_index];
  837. dev->poll_mod_count++;
  838. }
  839. static void pn533_poll_create_mod_list(struct pn533 *dev,
  840. u32 im_protocols, u32 tm_protocols)
  841. {
  842. pn533_poll_reset_mod_list(dev);
  843. if (im_protocols & NFC_PROTO_MIFARE_MASK
  844. || im_protocols & NFC_PROTO_ISO14443_MASK
  845. || im_protocols & NFC_PROTO_NFC_DEP_MASK)
  846. pn533_poll_add_mod(dev, PN533_POLL_MOD_106KBPS_A);
  847. if (im_protocols & NFC_PROTO_FELICA_MASK
  848. || im_protocols & NFC_PROTO_NFC_DEP_MASK) {
  849. pn533_poll_add_mod(dev, PN533_POLL_MOD_212KBPS_FELICA);
  850. pn533_poll_add_mod(dev, PN533_POLL_MOD_424KBPS_FELICA);
  851. }
  852. if (im_protocols & NFC_PROTO_JEWEL_MASK)
  853. pn533_poll_add_mod(dev, PN533_POLL_MOD_106KBPS_JEWEL);
  854. if (im_protocols & NFC_PROTO_ISO14443_MASK)
  855. pn533_poll_add_mod(dev, PN533_POLL_MOD_847KBPS_B);
  856. if (tm_protocols)
  857. pn533_poll_add_mod(dev, PN533_LISTEN_MOD);
  858. }
  859. static int pn533_start_poll_complete(struct pn533 *dev, void *arg,
  860. u8 *params, int params_len)
  861. {
  862. struct pn533_poll_response *resp;
  863. int rc;
  864. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  865. resp = (struct pn533_poll_response *) params;
  866. if (resp->nbtg) {
  867. rc = pn533_target_found(dev, resp, params_len);
  868. /* We must stop the poll after a valid target found */
  869. if (rc == 0) {
  870. pn533_poll_reset_mod_list(dev);
  871. return 0;
  872. }
  873. }
  874. return -EAGAIN;
  875. }
  876. static int pn533_init_target_frame(struct pn533_frame *frame,
  877. u8 *gb, size_t gb_len)
  878. {
  879. struct pn533_cmd_init_target *cmd;
  880. size_t cmd_len;
  881. u8 felica_params[18] = {0x1, 0xfe, /* DEP */
  882. 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, /* random */
  883. 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0,
  884. 0xff, 0xff}; /* System code */
  885. u8 mifare_params[6] = {0x1, 0x1, /* SENS_RES */
  886. 0x0, 0x0, 0x0,
  887. 0x40}; /* SEL_RES for DEP */
  888. cmd_len = sizeof(struct pn533_cmd_init_target) + gb_len + 1;
  889. cmd = kzalloc(cmd_len, GFP_KERNEL);
  890. if (cmd == NULL)
  891. return -ENOMEM;
  892. pn533_tx_frame_init(frame, PN533_CMD_TG_INIT_AS_TARGET);
  893. /* DEP support only */
  894. cmd->mode |= PN533_INIT_TARGET_DEP;
  895. /* Felica params */
  896. memcpy(cmd->felica, felica_params, 18);
  897. get_random_bytes(cmd->felica + 2, 6);
  898. /* NFCID3 */
  899. memset(cmd->nfcid3, 0, 10);
  900. memcpy(cmd->nfcid3, cmd->felica, 8);
  901. /* MIFARE params */
  902. memcpy(cmd->mifare, mifare_params, 6);
  903. /* General bytes */
  904. cmd->gb_len = gb_len;
  905. memcpy(cmd->gb, gb, gb_len);
  906. /* Len Tk */
  907. cmd->gb[gb_len] = 0;
  908. memcpy(PN533_FRAME_CMD_PARAMS_PTR(frame), cmd, cmd_len);
  909. frame->datalen += cmd_len;
  910. pn533_tx_frame_finish(frame);
  911. kfree(cmd);
  912. return 0;
  913. }
  914. #define PN533_CMD_DATAEXCH_HEAD_LEN (sizeof(struct pn533_frame) + 3)
  915. #define PN533_CMD_DATAEXCH_DATA_MAXLEN 262
  916. static int pn533_tm_get_data_complete(struct pn533 *dev, void *arg,
  917. u8 *params, int params_len)
  918. {
  919. struct sk_buff *skb_resp = arg;
  920. struct pn533_frame *in_frame = (struct pn533_frame *) skb_resp->data;
  921. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  922. if (params_len < 0) {
  923. nfc_dev_err(&dev->interface->dev,
  924. "Error %d when starting as a target",
  925. params_len);
  926. return params_len;
  927. }
  928. if (params_len > 0 && params[0] != 0) {
  929. nfc_tm_deactivated(dev->nfc_dev);
  930. dev->tgt_mode = 0;
  931. kfree_skb(skb_resp);
  932. return 0;
  933. }
  934. skb_put(skb_resp, PN533_FRAME_SIZE(in_frame));
  935. skb_pull(skb_resp, PN533_CMD_DATAEXCH_HEAD_LEN);
  936. skb_trim(skb_resp, skb_resp->len - PN533_FRAME_TAIL_SIZE);
  937. return nfc_tm_data_received(dev->nfc_dev, skb_resp);
  938. }
  939. static void pn533_wq_tg_get_data(struct work_struct *work)
  940. {
  941. struct pn533 *dev = container_of(work, struct pn533, tg_work);
  942. struct pn533_frame *in_frame;
  943. struct sk_buff *skb_resp;
  944. size_t skb_resp_len;
  945. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  946. skb_resp_len = PN533_CMD_DATAEXCH_HEAD_LEN +
  947. PN533_CMD_DATAEXCH_DATA_MAXLEN +
  948. PN533_FRAME_TAIL_SIZE;
  949. skb_resp = nfc_alloc_recv_skb(skb_resp_len, GFP_KERNEL);
  950. if (!skb_resp)
  951. return;
  952. in_frame = (struct pn533_frame *)skb_resp->data;
  953. pn533_tx_frame_init(dev->out_frame, PN533_CMD_TG_GET_DATA);
  954. pn533_tx_frame_finish(dev->out_frame);
  955. pn533_send_cmd_frame_async(dev, dev->out_frame, in_frame,
  956. skb_resp_len,
  957. pn533_tm_get_data_complete,
  958. skb_resp, GFP_KERNEL);
  959. return;
  960. }
  961. #define ATR_REQ_GB_OFFSET 17
  962. static int pn533_init_target_complete(struct pn533 *dev, void *arg,
  963. u8 *params, int params_len)
  964. {
  965. struct pn533_cmd_init_target_response *resp;
  966. u8 frame, comm_mode = NFC_COMM_PASSIVE, *gb;
  967. size_t gb_len;
  968. int rc;
  969. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  970. if (params_len < 0) {
  971. nfc_dev_err(&dev->interface->dev,
  972. "Error %d when starting as a target",
  973. params_len);
  974. return params_len;
  975. }
  976. if (params_len < ATR_REQ_GB_OFFSET + 1)
  977. return -EINVAL;
  978. resp = (struct pn533_cmd_init_target_response *) params;
  979. nfc_dev_dbg(&dev->interface->dev, "Target mode 0x%x param len %d\n",
  980. resp->mode, params_len);
  981. frame = resp->mode & PN533_INIT_TARGET_RESP_FRAME_MASK;
  982. if (frame == PN533_INIT_TARGET_RESP_ACTIVE)
  983. comm_mode = NFC_COMM_ACTIVE;
  984. /* Again, only DEP */
  985. if ((resp->mode & PN533_INIT_TARGET_RESP_DEP) == 0)
  986. return -EOPNOTSUPP;
  987. gb = resp->cmd + ATR_REQ_GB_OFFSET;
  988. gb_len = params_len - (ATR_REQ_GB_OFFSET + 1);
  989. rc = nfc_tm_activated(dev->nfc_dev, NFC_PROTO_NFC_DEP_MASK,
  990. comm_mode, gb, gb_len);
  991. if (rc < 0) {
  992. nfc_dev_err(&dev->interface->dev,
  993. "Error when signaling target activation");
  994. return rc;
  995. }
  996. dev->tgt_mode = 1;
  997. queue_work(dev->wq, &dev->tg_work);
  998. return 0;
  999. }
  1000. static void pn533_listen_mode_timer(unsigned long data)
  1001. {
  1002. struct pn533 *dev = (struct pn533 *) data;
  1003. nfc_dev_dbg(&dev->interface->dev, "Listen mode timeout");
  1004. /* An ack will cancel the last issued command (poll) */
  1005. pn533_send_ack(dev, GFP_ATOMIC);
  1006. dev->cancel_listen = 1;
  1007. mutex_unlock(&dev->cmd_lock);
  1008. pn533_poll_next_mod(dev);
  1009. queue_work(dev->wq, &dev->poll_work);
  1010. }
  1011. static int pn533_poll_complete(struct pn533 *dev, void *arg,
  1012. u8 *params, int params_len)
  1013. {
  1014. struct pn533_poll_modulations *cur_mod;
  1015. int rc;
  1016. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1017. if (params_len == -ENOENT) {
  1018. if (dev->poll_mod_count != 0)
  1019. return 0;
  1020. nfc_dev_err(&dev->interface->dev,
  1021. "Polling operation has been stopped");
  1022. goto stop_poll;
  1023. }
  1024. if (params_len < 0) {
  1025. nfc_dev_err(&dev->interface->dev,
  1026. "Error %d when running poll", params_len);
  1027. goto stop_poll;
  1028. }
  1029. cur_mod = dev->poll_mod_active[dev->poll_mod_curr];
  1030. if (cur_mod->len == 0) {
  1031. del_timer(&dev->listen_timer);
  1032. return pn533_init_target_complete(dev, arg, params, params_len);
  1033. } else {
  1034. rc = pn533_start_poll_complete(dev, arg, params, params_len);
  1035. if (!rc)
  1036. return rc;
  1037. }
  1038. pn533_poll_next_mod(dev);
  1039. queue_work(dev->wq, &dev->poll_work);
  1040. return 0;
  1041. stop_poll:
  1042. pn533_poll_reset_mod_list(dev);
  1043. dev->poll_protocols = 0;
  1044. return 0;
  1045. }
  1046. static void pn533_build_poll_frame(struct pn533 *dev,
  1047. struct pn533_frame *frame,
  1048. struct pn533_poll_modulations *mod)
  1049. {
  1050. nfc_dev_dbg(&dev->interface->dev, "mod len %d\n", mod->len);
  1051. if (mod->len == 0) {
  1052. /* Listen mode */
  1053. pn533_init_target_frame(frame, dev->gb, dev->gb_len);
  1054. } else {
  1055. /* Polling mode */
  1056. pn533_tx_frame_init(frame, PN533_CMD_IN_LIST_PASSIVE_TARGET);
  1057. memcpy(PN533_FRAME_CMD_PARAMS_PTR(frame), &mod->data, mod->len);
  1058. frame->datalen += mod->len;
  1059. pn533_tx_frame_finish(frame);
  1060. }
  1061. }
  1062. static int pn533_send_poll_frame(struct pn533 *dev)
  1063. {
  1064. struct pn533_poll_modulations *cur_mod;
  1065. int rc;
  1066. cur_mod = dev->poll_mod_active[dev->poll_mod_curr];
  1067. pn533_build_poll_frame(dev, dev->out_frame, cur_mod);
  1068. rc = pn533_send_cmd_frame_async(dev, dev->out_frame, dev->in_frame,
  1069. dev->in_maxlen, pn533_poll_complete,
  1070. NULL, GFP_KERNEL);
  1071. if (rc)
  1072. nfc_dev_err(&dev->interface->dev, "Polling loop error %d", rc);
  1073. return rc;
  1074. }
  1075. static void pn533_wq_poll(struct work_struct *work)
  1076. {
  1077. struct pn533 *dev = container_of(work, struct pn533, poll_work);
  1078. struct pn533_poll_modulations *cur_mod;
  1079. int rc;
  1080. cur_mod = dev->poll_mod_active[dev->poll_mod_curr];
  1081. nfc_dev_dbg(&dev->interface->dev,
  1082. "%s cancel_listen %d modulation len %d",
  1083. __func__, dev->cancel_listen, cur_mod->len);
  1084. if (dev->cancel_listen == 1) {
  1085. dev->cancel_listen = 0;
  1086. usb_kill_urb(dev->in_urb);
  1087. }
  1088. rc = pn533_send_poll_frame(dev);
  1089. if (rc)
  1090. return;
  1091. if (cur_mod->len == 0 && dev->poll_mod_count > 1)
  1092. mod_timer(&dev->listen_timer, jiffies + PN533_LISTEN_TIME * HZ);
  1093. return;
  1094. }
  1095. static int pn533_start_poll(struct nfc_dev *nfc_dev,
  1096. u32 im_protocols, u32 tm_protocols)
  1097. {
  1098. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1099. nfc_dev_dbg(&dev->interface->dev,
  1100. "%s: im protocols 0x%x tm protocols 0x%x",
  1101. __func__, im_protocols, tm_protocols);
  1102. if (dev->tgt_active_prot) {
  1103. nfc_dev_err(&dev->interface->dev,
  1104. "Cannot poll with a target already activated");
  1105. return -EBUSY;
  1106. }
  1107. if (dev->tgt_mode) {
  1108. nfc_dev_err(&dev->interface->dev,
  1109. "Cannot poll while already being activated");
  1110. return -EBUSY;
  1111. }
  1112. if (tm_protocols) {
  1113. dev->gb = nfc_get_local_general_bytes(nfc_dev, &dev->gb_len);
  1114. if (dev->gb == NULL)
  1115. tm_protocols = 0;
  1116. }
  1117. dev->poll_mod_curr = 0;
  1118. pn533_poll_create_mod_list(dev, im_protocols, tm_protocols);
  1119. dev->poll_protocols = im_protocols;
  1120. dev->listen_protocols = tm_protocols;
  1121. return pn533_send_poll_frame(dev);
  1122. }
  1123. static void pn533_stop_poll(struct nfc_dev *nfc_dev)
  1124. {
  1125. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1126. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1127. del_timer(&dev->listen_timer);
  1128. if (!dev->poll_mod_count) {
  1129. nfc_dev_dbg(&dev->interface->dev, "Polling operation was not"
  1130. " running");
  1131. return;
  1132. }
  1133. /* An ack will cancel the last issued command (poll) */
  1134. pn533_send_ack(dev, GFP_KERNEL);
  1135. /* prevent pn533_start_poll_complete to issue a new poll meanwhile */
  1136. usb_kill_urb(dev->in_urb);
  1137. pn533_poll_reset_mod_list(dev);
  1138. }
  1139. static int pn533_activate_target_nfcdep(struct pn533 *dev)
  1140. {
  1141. struct pn533_cmd_activate_param param;
  1142. struct pn533_cmd_activate_response *resp;
  1143. u16 gt_len;
  1144. int rc;
  1145. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1146. pn533_tx_frame_init(dev->out_frame, PN533_CMD_IN_ATR);
  1147. param.tg = 1;
  1148. param.next = 0;
  1149. memcpy(PN533_FRAME_CMD_PARAMS_PTR(dev->out_frame), &param,
  1150. sizeof(struct pn533_cmd_activate_param));
  1151. dev->out_frame->datalen += sizeof(struct pn533_cmd_activate_param);
  1152. pn533_tx_frame_finish(dev->out_frame);
  1153. rc = pn533_send_cmd_frame_sync(dev, dev->out_frame, dev->in_frame,
  1154. dev->in_maxlen);
  1155. if (rc)
  1156. return rc;
  1157. resp = (struct pn533_cmd_activate_response *)
  1158. PN533_FRAME_CMD_PARAMS_PTR(dev->in_frame);
  1159. rc = resp->status & PN533_CMD_RET_MASK;
  1160. if (rc != PN533_CMD_RET_SUCCESS)
  1161. return -EIO;
  1162. /* ATR_RES general bytes are located at offset 16 */
  1163. gt_len = PN533_FRAME_CMD_PARAMS_LEN(dev->in_frame) - 16;
  1164. rc = nfc_set_remote_general_bytes(dev->nfc_dev, resp->gt, gt_len);
  1165. return rc;
  1166. }
  1167. static int pn533_activate_target(struct nfc_dev *nfc_dev,
  1168. struct nfc_target *target, u32 protocol)
  1169. {
  1170. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1171. int rc;
  1172. nfc_dev_dbg(&dev->interface->dev, "%s - protocol=%u", __func__,
  1173. protocol);
  1174. if (dev->poll_mod_count) {
  1175. nfc_dev_err(&dev->interface->dev, "Cannot activate while"
  1176. " polling");
  1177. return -EBUSY;
  1178. }
  1179. if (dev->tgt_active_prot) {
  1180. nfc_dev_err(&dev->interface->dev, "There is already an active"
  1181. " target");
  1182. return -EBUSY;
  1183. }
  1184. if (!dev->tgt_available_prots) {
  1185. nfc_dev_err(&dev->interface->dev, "There is no available target"
  1186. " to activate");
  1187. return -EINVAL;
  1188. }
  1189. if (!(dev->tgt_available_prots & (1 << protocol))) {
  1190. nfc_dev_err(&dev->interface->dev, "The target does not support"
  1191. " the requested protocol %u", protocol);
  1192. return -EINVAL;
  1193. }
  1194. if (protocol == NFC_PROTO_NFC_DEP) {
  1195. rc = pn533_activate_target_nfcdep(dev);
  1196. if (rc) {
  1197. nfc_dev_err(&dev->interface->dev, "Error %d when"
  1198. " activating target with"
  1199. " NFC_DEP protocol", rc);
  1200. return rc;
  1201. }
  1202. }
  1203. dev->tgt_active_prot = protocol;
  1204. dev->tgt_available_prots = 0;
  1205. return 0;
  1206. }
  1207. static void pn533_deactivate_target(struct nfc_dev *nfc_dev,
  1208. struct nfc_target *target)
  1209. {
  1210. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1211. u8 tg;
  1212. u8 status;
  1213. int rc;
  1214. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1215. if (!dev->tgt_active_prot) {
  1216. nfc_dev_err(&dev->interface->dev, "There is no active target");
  1217. return;
  1218. }
  1219. dev->tgt_active_prot = 0;
  1220. skb_queue_purge(&dev->resp_q);
  1221. pn533_tx_frame_init(dev->out_frame, PN533_CMD_IN_RELEASE);
  1222. tg = 1;
  1223. memcpy(PN533_FRAME_CMD_PARAMS_PTR(dev->out_frame), &tg, sizeof(u8));
  1224. dev->out_frame->datalen += sizeof(u8);
  1225. pn533_tx_frame_finish(dev->out_frame);
  1226. rc = pn533_send_cmd_frame_sync(dev, dev->out_frame, dev->in_frame,
  1227. dev->in_maxlen);
  1228. if (rc) {
  1229. nfc_dev_err(&dev->interface->dev, "Error when sending release"
  1230. " command to the controller");
  1231. return;
  1232. }
  1233. status = PN533_FRAME_CMD_PARAMS_PTR(dev->in_frame)[0];
  1234. rc = status & PN533_CMD_RET_MASK;
  1235. if (rc != PN533_CMD_RET_SUCCESS)
  1236. nfc_dev_err(&dev->interface->dev, "Error 0x%x when releasing"
  1237. " the target", rc);
  1238. return;
  1239. }
  1240. static int pn533_in_dep_link_up_complete(struct pn533 *dev, void *arg,
  1241. u8 *params, int params_len)
  1242. {
  1243. struct pn533_cmd_jump_dep *cmd;
  1244. struct pn533_cmd_jump_dep_response *resp;
  1245. struct nfc_target nfc_target;
  1246. u8 target_gt_len;
  1247. int rc;
  1248. if (params_len == -ENOENT) {
  1249. nfc_dev_dbg(&dev->interface->dev, "");
  1250. return 0;
  1251. }
  1252. if (params_len < 0) {
  1253. nfc_dev_err(&dev->interface->dev,
  1254. "Error %d when bringing DEP link up",
  1255. params_len);
  1256. return 0;
  1257. }
  1258. if (dev->tgt_available_prots &&
  1259. !(dev->tgt_available_prots & (1 << NFC_PROTO_NFC_DEP))) {
  1260. nfc_dev_err(&dev->interface->dev,
  1261. "The target does not support DEP");
  1262. return -EINVAL;
  1263. }
  1264. resp = (struct pn533_cmd_jump_dep_response *) params;
  1265. cmd = (struct pn533_cmd_jump_dep *) arg;
  1266. rc = resp->status & PN533_CMD_RET_MASK;
  1267. if (rc != PN533_CMD_RET_SUCCESS) {
  1268. nfc_dev_err(&dev->interface->dev,
  1269. "Bringing DEP link up failed %d", rc);
  1270. return 0;
  1271. }
  1272. if (!dev->tgt_available_prots) {
  1273. nfc_dev_dbg(&dev->interface->dev, "Creating new target");
  1274. nfc_target.supported_protocols = NFC_PROTO_NFC_DEP_MASK;
  1275. nfc_target.nfcid1_len = 10;
  1276. memcpy(nfc_target.nfcid1, resp->nfcid3t, nfc_target.nfcid1_len);
  1277. rc = nfc_targets_found(dev->nfc_dev, &nfc_target, 1);
  1278. if (rc)
  1279. return 0;
  1280. dev->tgt_available_prots = 0;
  1281. }
  1282. dev->tgt_active_prot = NFC_PROTO_NFC_DEP;
  1283. /* ATR_RES general bytes are located at offset 17 */
  1284. target_gt_len = PN533_FRAME_CMD_PARAMS_LEN(dev->in_frame) - 17;
  1285. rc = nfc_set_remote_general_bytes(dev->nfc_dev,
  1286. resp->gt, target_gt_len);
  1287. if (rc == 0)
  1288. rc = nfc_dep_link_is_up(dev->nfc_dev,
  1289. dev->nfc_dev->targets[0].idx,
  1290. !cmd->active, NFC_RF_INITIATOR);
  1291. return 0;
  1292. }
  1293. static int pn533_mod_to_baud(struct pn533 *dev)
  1294. {
  1295. switch (dev->poll_mod_curr) {
  1296. case PN533_POLL_MOD_106KBPS_A:
  1297. return 0;
  1298. case PN533_POLL_MOD_212KBPS_FELICA:
  1299. return 1;
  1300. case PN533_POLL_MOD_424KBPS_FELICA:
  1301. return 2;
  1302. default:
  1303. return -EINVAL;
  1304. }
  1305. }
  1306. #define PASSIVE_DATA_LEN 5
  1307. static int pn533_dep_link_up(struct nfc_dev *nfc_dev, struct nfc_target *target,
  1308. u8 comm_mode, u8* gb, size_t gb_len)
  1309. {
  1310. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1311. struct pn533_cmd_jump_dep *cmd;
  1312. u8 cmd_len, *data_ptr;
  1313. u8 passive_data[PASSIVE_DATA_LEN] = {0x00, 0xff, 0xff, 0x00, 0x3};
  1314. int rc, baud;
  1315. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1316. if (dev->poll_mod_count) {
  1317. nfc_dev_err(&dev->interface->dev,
  1318. "Cannot bring the DEP link up while polling");
  1319. return -EBUSY;
  1320. }
  1321. if (dev->tgt_active_prot) {
  1322. nfc_dev_err(&dev->interface->dev,
  1323. "There is already an active target");
  1324. return -EBUSY;
  1325. }
  1326. baud = pn533_mod_to_baud(dev);
  1327. if (baud < 0) {
  1328. nfc_dev_err(&dev->interface->dev,
  1329. "Invalid curr modulation %d", dev->poll_mod_curr);
  1330. return baud;
  1331. }
  1332. cmd_len = sizeof(struct pn533_cmd_jump_dep) + gb_len;
  1333. if (comm_mode == NFC_COMM_PASSIVE)
  1334. cmd_len += PASSIVE_DATA_LEN;
  1335. cmd = kzalloc(cmd_len, GFP_KERNEL);
  1336. if (cmd == NULL)
  1337. return -ENOMEM;
  1338. pn533_tx_frame_init(dev->out_frame, PN533_CMD_IN_JUMP_FOR_DEP);
  1339. cmd->active = !comm_mode;
  1340. cmd->next = 0;
  1341. cmd->baud = baud;
  1342. data_ptr = cmd->data;
  1343. if (comm_mode == NFC_COMM_PASSIVE && cmd->baud > 0) {
  1344. memcpy(data_ptr, passive_data, PASSIVE_DATA_LEN);
  1345. cmd->next |= 1;
  1346. data_ptr += PASSIVE_DATA_LEN;
  1347. }
  1348. if (gb != NULL && gb_len > 0) {
  1349. cmd->next |= 4; /* We have some Gi */
  1350. memcpy(data_ptr, gb, gb_len);
  1351. } else {
  1352. cmd->next = 0;
  1353. }
  1354. memcpy(PN533_FRAME_CMD_PARAMS_PTR(dev->out_frame), cmd, cmd_len);
  1355. dev->out_frame->datalen += cmd_len;
  1356. pn533_tx_frame_finish(dev->out_frame);
  1357. rc = pn533_send_cmd_frame_async(dev, dev->out_frame, dev->in_frame,
  1358. dev->in_maxlen, pn533_in_dep_link_up_complete,
  1359. cmd, GFP_KERNEL);
  1360. if (rc)
  1361. goto out;
  1362. out:
  1363. kfree(cmd);
  1364. return rc;
  1365. }
  1366. static int pn533_dep_link_down(struct nfc_dev *nfc_dev)
  1367. {
  1368. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1369. pn533_poll_reset_mod_list(dev);
  1370. if (dev->tgt_mode || dev->tgt_active_prot) {
  1371. pn533_send_ack(dev, GFP_KERNEL);
  1372. usb_kill_urb(dev->in_urb);
  1373. }
  1374. dev->tgt_active_prot = 0;
  1375. dev->tgt_mode = 0;
  1376. skb_queue_purge(&dev->resp_q);
  1377. return 0;
  1378. }
  1379. static int pn533_build_tx_frame(struct pn533 *dev, struct sk_buff *skb,
  1380. bool target)
  1381. {
  1382. int payload_len = skb->len;
  1383. struct pn533_frame *out_frame;
  1384. u8 tg;
  1385. nfc_dev_dbg(&dev->interface->dev, "%s - Sending %d bytes", __func__,
  1386. payload_len);
  1387. if (payload_len > PN533_CMD_DATAEXCH_DATA_MAXLEN) {
  1388. /* TODO: Implement support to multi-part data exchange */
  1389. nfc_dev_err(&dev->interface->dev, "Data length greater than the"
  1390. " max allowed: %d",
  1391. PN533_CMD_DATAEXCH_DATA_MAXLEN);
  1392. return -ENOSYS;
  1393. }
  1394. if (target == true) {
  1395. skb_push(skb, PN533_CMD_DATAEXCH_HEAD_LEN);
  1396. out_frame = (struct pn533_frame *) skb->data;
  1397. pn533_tx_frame_init(out_frame, PN533_CMD_IN_DATA_EXCHANGE);
  1398. tg = 1;
  1399. memcpy(PN533_FRAME_CMD_PARAMS_PTR(out_frame), &tg, sizeof(u8));
  1400. out_frame->datalen += sizeof(u8);
  1401. } else {
  1402. skb_push(skb, PN533_CMD_DATAEXCH_HEAD_LEN - 1);
  1403. out_frame = (struct pn533_frame *) skb->data;
  1404. pn533_tx_frame_init(out_frame, PN533_CMD_TG_SET_DATA);
  1405. }
  1406. /* The data is already in the out_frame, just update the datalen */
  1407. out_frame->datalen += payload_len;
  1408. pn533_tx_frame_finish(out_frame);
  1409. skb_put(skb, PN533_FRAME_TAIL_SIZE);
  1410. return 0;
  1411. }
  1412. struct pn533_data_exchange_arg {
  1413. struct sk_buff *skb_resp;
  1414. struct sk_buff *skb_out;
  1415. data_exchange_cb_t cb;
  1416. void *cb_context;
  1417. };
  1418. static struct sk_buff *pn533_build_response(struct pn533 *dev)
  1419. {
  1420. struct sk_buff *skb, *tmp, *t;
  1421. unsigned int skb_len = 0, tmp_len = 0;
  1422. nfc_dev_dbg(&dev->interface->dev, "%s\n", __func__);
  1423. if (skb_queue_empty(&dev->resp_q))
  1424. return NULL;
  1425. if (skb_queue_len(&dev->resp_q) == 1) {
  1426. skb = skb_dequeue(&dev->resp_q);
  1427. goto out;
  1428. }
  1429. skb_queue_walk_safe(&dev->resp_q, tmp, t)
  1430. skb_len += tmp->len;
  1431. nfc_dev_dbg(&dev->interface->dev, "%s total length %d\n",
  1432. __func__, skb_len);
  1433. skb = alloc_skb(skb_len, GFP_KERNEL);
  1434. if (skb == NULL)
  1435. goto out;
  1436. skb_put(skb, skb_len);
  1437. skb_queue_walk_safe(&dev->resp_q, tmp, t) {
  1438. memcpy(skb->data + tmp_len, tmp->data, tmp->len);
  1439. tmp_len += tmp->len;
  1440. }
  1441. out:
  1442. skb_queue_purge(&dev->resp_q);
  1443. return skb;
  1444. }
  1445. static int pn533_data_exchange_complete(struct pn533 *dev, void *_arg,
  1446. u8 *params, int params_len)
  1447. {
  1448. struct pn533_data_exchange_arg *arg = _arg;
  1449. struct sk_buff *skb = NULL, *skb_resp = arg->skb_resp;
  1450. struct pn533_frame *in_frame = (struct pn533_frame *) skb_resp->data;
  1451. int err = 0;
  1452. u8 status;
  1453. u8 cmd_ret;
  1454. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1455. dev_kfree_skb(arg->skb_out);
  1456. if (params_len < 0) { /* error */
  1457. err = params_len;
  1458. goto error;
  1459. }
  1460. status = params[0];
  1461. cmd_ret = status & PN533_CMD_RET_MASK;
  1462. if (cmd_ret != PN533_CMD_RET_SUCCESS) {
  1463. nfc_dev_err(&dev->interface->dev, "PN533 reported error %d when"
  1464. " exchanging data", cmd_ret);
  1465. err = -EIO;
  1466. goto error;
  1467. }
  1468. skb_put(skb_resp, PN533_FRAME_SIZE(in_frame));
  1469. skb_pull(skb_resp, PN533_CMD_DATAEXCH_HEAD_LEN);
  1470. skb_trim(skb_resp, skb_resp->len - PN533_FRAME_TAIL_SIZE);
  1471. skb_queue_tail(&dev->resp_q, skb_resp);
  1472. if (status & PN533_CMD_MI_MASK) {
  1473. queue_work(dev->wq, &dev->mi_work);
  1474. return -EINPROGRESS;
  1475. }
  1476. skb = pn533_build_response(dev);
  1477. if (skb == NULL)
  1478. goto error;
  1479. arg->cb(arg->cb_context, skb, 0);
  1480. kfree(arg);
  1481. return 0;
  1482. error:
  1483. skb_queue_purge(&dev->resp_q);
  1484. dev_kfree_skb(skb_resp);
  1485. arg->cb(arg->cb_context, NULL, err);
  1486. kfree(arg);
  1487. return 0;
  1488. }
  1489. static int pn533_transceive(struct nfc_dev *nfc_dev,
  1490. struct nfc_target *target, struct sk_buff *skb,
  1491. data_exchange_cb_t cb, void *cb_context)
  1492. {
  1493. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1494. struct pn533_frame *out_frame, *in_frame;
  1495. struct pn533_data_exchange_arg *arg;
  1496. struct sk_buff *skb_resp;
  1497. int skb_resp_len;
  1498. int rc;
  1499. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1500. if (!dev->tgt_active_prot) {
  1501. nfc_dev_err(&dev->interface->dev, "Cannot exchange data if"
  1502. " there is no active target");
  1503. rc = -EINVAL;
  1504. goto error;
  1505. }
  1506. rc = pn533_build_tx_frame(dev, skb, true);
  1507. if (rc)
  1508. goto error;
  1509. skb_resp_len = PN533_CMD_DATAEXCH_HEAD_LEN +
  1510. PN533_CMD_DATAEXCH_DATA_MAXLEN +
  1511. PN533_FRAME_TAIL_SIZE;
  1512. skb_resp = nfc_alloc_recv_skb(skb_resp_len, GFP_KERNEL);
  1513. if (!skb_resp) {
  1514. rc = -ENOMEM;
  1515. goto error;
  1516. }
  1517. in_frame = (struct pn533_frame *) skb_resp->data;
  1518. out_frame = (struct pn533_frame *) skb->data;
  1519. arg = kmalloc(sizeof(struct pn533_data_exchange_arg), GFP_KERNEL);
  1520. if (!arg) {
  1521. rc = -ENOMEM;
  1522. goto free_skb_resp;
  1523. }
  1524. arg->skb_resp = skb_resp;
  1525. arg->skb_out = skb;
  1526. arg->cb = cb;
  1527. arg->cb_context = cb_context;
  1528. rc = pn533_send_cmd_frame_async(dev, out_frame, in_frame, skb_resp_len,
  1529. pn533_data_exchange_complete, arg,
  1530. GFP_KERNEL);
  1531. if (rc) {
  1532. nfc_dev_err(&dev->interface->dev, "Error %d when trying to"
  1533. " perform data_exchange", rc);
  1534. goto free_arg;
  1535. }
  1536. return 0;
  1537. free_arg:
  1538. kfree(arg);
  1539. free_skb_resp:
  1540. kfree_skb(skb_resp);
  1541. error:
  1542. kfree_skb(skb);
  1543. return rc;
  1544. }
  1545. static int pn533_tm_send_complete(struct pn533 *dev, void *arg,
  1546. u8 *params, int params_len)
  1547. {
  1548. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1549. if (params_len < 0) {
  1550. nfc_dev_err(&dev->interface->dev,
  1551. "Error %d when sending data",
  1552. params_len);
  1553. return params_len;
  1554. }
  1555. if (params_len > 0 && params[0] != 0) {
  1556. nfc_tm_deactivated(dev->nfc_dev);
  1557. dev->tgt_mode = 0;
  1558. return 0;
  1559. }
  1560. queue_work(dev->wq, &dev->tg_work);
  1561. return 0;
  1562. }
  1563. static int pn533_tm_send(struct nfc_dev *nfc_dev, struct sk_buff *skb)
  1564. {
  1565. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1566. struct pn533_frame *out_frame;
  1567. int rc;
  1568. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1569. rc = pn533_build_tx_frame(dev, skb, false);
  1570. if (rc)
  1571. goto error;
  1572. out_frame = (struct pn533_frame *) skb->data;
  1573. rc = pn533_send_cmd_frame_async(dev, out_frame, dev->in_frame,
  1574. dev->in_maxlen, pn533_tm_send_complete,
  1575. NULL, GFP_KERNEL);
  1576. if (rc) {
  1577. nfc_dev_err(&dev->interface->dev,
  1578. "Error %d when trying to send data", rc);
  1579. goto error;
  1580. }
  1581. return 0;
  1582. error:
  1583. kfree_skb(skb);
  1584. return rc;
  1585. }
  1586. static void pn533_wq_mi_recv(struct work_struct *work)
  1587. {
  1588. struct pn533 *dev = container_of(work, struct pn533, mi_work);
  1589. struct sk_buff *skb_cmd;
  1590. struct pn533_data_exchange_arg *arg = dev->cmd_complete_arg;
  1591. struct pn533_frame *out_frame, *in_frame;
  1592. struct sk_buff *skb_resp;
  1593. int skb_resp_len;
  1594. int rc;
  1595. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1596. /* This is a zero payload size skb */
  1597. skb_cmd = alloc_skb(PN533_CMD_DATAEXCH_HEAD_LEN + PN533_FRAME_TAIL_SIZE,
  1598. GFP_KERNEL);
  1599. if (skb_cmd == NULL)
  1600. goto error_cmd;
  1601. skb_reserve(skb_cmd, PN533_CMD_DATAEXCH_HEAD_LEN);
  1602. rc = pn533_build_tx_frame(dev, skb_cmd, true);
  1603. if (rc)
  1604. goto error_frame;
  1605. skb_resp_len = PN533_CMD_DATAEXCH_HEAD_LEN +
  1606. PN533_CMD_DATAEXCH_DATA_MAXLEN +
  1607. PN533_FRAME_TAIL_SIZE;
  1608. skb_resp = alloc_skb(skb_resp_len, GFP_KERNEL);
  1609. if (!skb_resp) {
  1610. rc = -ENOMEM;
  1611. goto error_frame;
  1612. }
  1613. in_frame = (struct pn533_frame *) skb_resp->data;
  1614. out_frame = (struct pn533_frame *) skb_cmd->data;
  1615. arg->skb_resp = skb_resp;
  1616. arg->skb_out = skb_cmd;
  1617. rc = __pn533_send_cmd_frame_async(dev, out_frame, in_frame,
  1618. skb_resp_len,
  1619. pn533_data_exchange_complete,
  1620. dev->cmd_complete_arg, GFP_KERNEL);
  1621. if (!rc)
  1622. return;
  1623. nfc_dev_err(&dev->interface->dev, "Error %d when trying to"
  1624. " perform data_exchange", rc);
  1625. kfree_skb(skb_resp);
  1626. error_frame:
  1627. kfree_skb(skb_cmd);
  1628. error_cmd:
  1629. pn533_send_ack(dev, GFP_KERNEL);
  1630. kfree(arg);
  1631. mutex_unlock(&dev->cmd_lock);
  1632. }
  1633. static int pn533_set_configuration(struct pn533 *dev, u8 cfgitem, u8 *cfgdata,
  1634. u8 cfgdata_len)
  1635. {
  1636. int rc;
  1637. u8 *params;
  1638. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1639. pn533_tx_frame_init(dev->out_frame, PN533_CMD_RF_CONFIGURATION);
  1640. params = PN533_FRAME_CMD_PARAMS_PTR(dev->out_frame);
  1641. params[0] = cfgitem;
  1642. memcpy(&params[1], cfgdata, cfgdata_len);
  1643. dev->out_frame->datalen += (1 + cfgdata_len);
  1644. pn533_tx_frame_finish(dev->out_frame);
  1645. rc = pn533_send_cmd_frame_sync(dev, dev->out_frame, dev->in_frame,
  1646. dev->in_maxlen);
  1647. return rc;
  1648. }
  1649. struct nfc_ops pn533_nfc_ops = {
  1650. .dev_up = NULL,
  1651. .dev_down = NULL,
  1652. .dep_link_up = pn533_dep_link_up,
  1653. .dep_link_down = pn533_dep_link_down,
  1654. .start_poll = pn533_start_poll,
  1655. .stop_poll = pn533_stop_poll,
  1656. .activate_target = pn533_activate_target,
  1657. .deactivate_target = pn533_deactivate_target,
  1658. .im_transceive = pn533_transceive,
  1659. .tm_send = pn533_tm_send,
  1660. };
  1661. static int pn533_probe(struct usb_interface *interface,
  1662. const struct usb_device_id *id)
  1663. {
  1664. struct pn533_fw_version *fw_ver;
  1665. struct pn533 *dev;
  1666. struct usb_host_interface *iface_desc;
  1667. struct usb_endpoint_descriptor *endpoint;
  1668. struct pn533_config_max_retries max_retries;
  1669. struct pn533_config_timing timing;
  1670. int in_endpoint = 0;
  1671. int out_endpoint = 0;
  1672. int rc = -ENOMEM;
  1673. int i;
  1674. u32 protocols;
  1675. dev = kzalloc(sizeof(*dev), GFP_KERNEL);
  1676. if (!dev)
  1677. return -ENOMEM;
  1678. dev->udev = usb_get_dev(interface_to_usbdev(interface));
  1679. dev->interface = interface;
  1680. mutex_init(&dev->cmd_lock);
  1681. iface_desc = interface->cur_altsetting;
  1682. for (i = 0; i < iface_desc->desc.bNumEndpoints; ++i) {
  1683. endpoint = &iface_desc->endpoint[i].desc;
  1684. if (!in_endpoint && usb_endpoint_is_bulk_in(endpoint)) {
  1685. dev->in_maxlen = le16_to_cpu(endpoint->wMaxPacketSize);
  1686. in_endpoint = endpoint->bEndpointAddress;
  1687. }
  1688. if (!out_endpoint && usb_endpoint_is_bulk_out(endpoint)) {
  1689. dev->out_maxlen =
  1690. le16_to_cpu(endpoint->wMaxPacketSize);
  1691. out_endpoint = endpoint->bEndpointAddress;
  1692. }
  1693. }
  1694. if (!in_endpoint || !out_endpoint) {
  1695. nfc_dev_err(&interface->dev, "Could not find bulk-in or"
  1696. " bulk-out endpoint");
  1697. rc = -ENODEV;
  1698. goto error;
  1699. }
  1700. dev->in_frame = kmalloc(dev->in_maxlen, GFP_KERNEL);
  1701. dev->in_urb = usb_alloc_urb(0, GFP_KERNEL);
  1702. dev->out_frame = kmalloc(dev->out_maxlen, GFP_KERNEL);
  1703. dev->out_urb = usb_alloc_urb(0, GFP_KERNEL);
  1704. if (!dev->in_frame || !dev->out_frame ||
  1705. !dev->in_urb || !dev->out_urb)
  1706. goto error;
  1707. usb_fill_bulk_urb(dev->in_urb, dev->udev,
  1708. usb_rcvbulkpipe(dev->udev, in_endpoint),
  1709. NULL, 0, NULL, dev);
  1710. usb_fill_bulk_urb(dev->out_urb, dev->udev,
  1711. usb_sndbulkpipe(dev->udev, out_endpoint),
  1712. NULL, 0,
  1713. pn533_send_complete, dev);
  1714. INIT_WORK(&dev->cmd_work, pn533_wq_cmd_complete);
  1715. INIT_WORK(&dev->mi_work, pn533_wq_mi_recv);
  1716. INIT_WORK(&dev->tg_work, pn533_wq_tg_get_data);
  1717. INIT_WORK(&dev->poll_work, pn533_wq_poll);
  1718. dev->wq = alloc_workqueue("pn533",
  1719. WQ_NON_REENTRANT | WQ_UNBOUND | WQ_MEM_RECLAIM,
  1720. 1);
  1721. if (dev->wq == NULL)
  1722. goto error;
  1723. init_timer(&dev->listen_timer);
  1724. dev->listen_timer.data = (unsigned long) dev;
  1725. dev->listen_timer.function = pn533_listen_mode_timer;
  1726. skb_queue_head_init(&dev->resp_q);
  1727. usb_set_intfdata(interface, dev);
  1728. pn533_tx_frame_init(dev->out_frame, PN533_CMD_GET_FIRMWARE_VERSION);
  1729. pn533_tx_frame_finish(dev->out_frame);
  1730. rc = pn533_send_cmd_frame_sync(dev, dev->out_frame, dev->in_frame,
  1731. dev->in_maxlen);
  1732. if (rc)
  1733. goto destroy_wq;
  1734. fw_ver = (struct pn533_fw_version *)
  1735. PN533_FRAME_CMD_PARAMS_PTR(dev->in_frame);
  1736. nfc_dev_info(&dev->interface->dev, "NXP PN533 firmware ver %d.%d now"
  1737. " attached", fw_ver->ver, fw_ver->rev);
  1738. protocols = NFC_PROTO_JEWEL_MASK
  1739. | NFC_PROTO_MIFARE_MASK | NFC_PROTO_FELICA_MASK
  1740. | NFC_PROTO_ISO14443_MASK
  1741. | NFC_PROTO_NFC_DEP_MASK;
  1742. dev->nfc_dev = nfc_allocate_device(&pn533_nfc_ops, protocols,
  1743. PN533_CMD_DATAEXCH_HEAD_LEN,
  1744. PN533_FRAME_TAIL_SIZE);
  1745. if (!dev->nfc_dev)
  1746. goto destroy_wq;
  1747. nfc_set_parent_dev(dev->nfc_dev, &interface->dev);
  1748. nfc_set_drvdata(dev->nfc_dev, dev);
  1749. rc = nfc_register_device(dev->nfc_dev);
  1750. if (rc)
  1751. goto free_nfc_dev;
  1752. max_retries.mx_rty_atr = PN533_CONFIG_MAX_RETRIES_ENDLESS;
  1753. max_retries.mx_rty_psl = 2;
  1754. max_retries.mx_rty_passive_act = PN533_CONFIG_MAX_RETRIES_NO_RETRY;
  1755. rc = pn533_set_configuration(dev, PN533_CFGITEM_MAX_RETRIES,
  1756. (u8 *) &max_retries, sizeof(max_retries));
  1757. if (rc) {
  1758. nfc_dev_err(&dev->interface->dev, "Error on setting MAX_RETRIES"
  1759. " config");
  1760. goto unregister_nfc_dev;
  1761. }
  1762. timing.rfu = PN533_CONFIG_TIMING_102;
  1763. timing.atr_res_timeout = PN533_CONFIG_TIMING_204;
  1764. timing.dep_timeout = PN533_CONFIG_TIMING_409;
  1765. rc = pn533_set_configuration(dev, PN533_CFGITEM_TIMING,
  1766. (u8 *) &timing, sizeof(timing));
  1767. if (rc) {
  1768. nfc_dev_err(&dev->interface->dev,
  1769. "Error on setting RF timings");
  1770. goto unregister_nfc_dev;
  1771. }
  1772. return 0;
  1773. unregister_nfc_dev:
  1774. nfc_unregister_device(dev->nfc_dev);
  1775. free_nfc_dev:
  1776. nfc_free_device(dev->nfc_dev);
  1777. destroy_wq:
  1778. destroy_workqueue(dev->wq);
  1779. error:
  1780. kfree(dev->in_frame);
  1781. usb_free_urb(dev->in_urb);
  1782. kfree(dev->out_frame);
  1783. usb_free_urb(dev->out_urb);
  1784. kfree(dev);
  1785. return rc;
  1786. }
  1787. static void pn533_disconnect(struct usb_interface *interface)
  1788. {
  1789. struct pn533 *dev;
  1790. dev = usb_get_intfdata(interface);
  1791. usb_set_intfdata(interface, NULL);
  1792. nfc_unregister_device(dev->nfc_dev);
  1793. nfc_free_device(dev->nfc_dev);
  1794. usb_kill_urb(dev->in_urb);
  1795. usb_kill_urb(dev->out_urb);
  1796. destroy_workqueue(dev->wq);
  1797. skb_queue_purge(&dev->resp_q);
  1798. del_timer(&dev->listen_timer);
  1799. kfree(dev->in_frame);
  1800. usb_free_urb(dev->in_urb);
  1801. kfree(dev->out_frame);
  1802. usb_free_urb(dev->out_urb);
  1803. kfree(dev);
  1804. nfc_dev_info(&interface->dev, "NXP PN533 NFC device disconnected");
  1805. }
  1806. static struct usb_driver pn533_driver = {
  1807. .name = "pn533",
  1808. .probe = pn533_probe,
  1809. .disconnect = pn533_disconnect,
  1810. .id_table = pn533_table,
  1811. };
  1812. module_usb_driver(pn533_driver);
  1813. MODULE_AUTHOR("Lauro Ramos Venancio <lauro.venancio@openbossa.org>,"
  1814. " Aloisio Almeida Jr <aloisio.almeida@openbossa.org>");
  1815. MODULE_DESCRIPTION("PN533 usb driver ver " VERSION);
  1816. MODULE_VERSION(VERSION);
  1817. MODULE_LICENSE("GPL");