pn533.c 66 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903
  1. /*
  2. * Copyright (C) 2011 Instituto Nokia de Tecnologia
  3. * Copyright (C) 2012-2013 Tieto Poland
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation; either version 2 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program; if not, write to the
  17. * Free Software Foundation, Inc.,
  18. * 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
  19. */
  20. #include <linux/device.h>
  21. #include <linux/kernel.h>
  22. #include <linux/module.h>
  23. #include <linux/slab.h>
  24. #include <linux/usb.h>
  25. #include <linux/nfc.h>
  26. #include <linux/netdevice.h>
  27. #include <net/nfc/nfc.h>
  28. #define VERSION "0.2"
  29. #define PN533_VENDOR_ID 0x4CC
  30. #define PN533_PRODUCT_ID 0x2533
  31. #define SCM_VENDOR_ID 0x4E6
  32. #define SCL3711_PRODUCT_ID 0x5591
  33. #define SONY_VENDOR_ID 0x054c
  34. #define PASORI_PRODUCT_ID 0x02e1
  35. #define ACS_VENDOR_ID 0x072f
  36. #define ACR122U_PRODUCT_ID 0x2200
  37. #define PN533_DEVICE_STD 0x1
  38. #define PN533_DEVICE_PASORI 0x2
  39. #define PN533_DEVICE_ACR122U 0x3
  40. #define PN533_ALL_PROTOCOLS (NFC_PROTO_JEWEL_MASK | NFC_PROTO_MIFARE_MASK |\
  41. NFC_PROTO_FELICA_MASK | NFC_PROTO_ISO14443_MASK |\
  42. NFC_PROTO_NFC_DEP_MASK |\
  43. NFC_PROTO_ISO14443_B_MASK)
  44. #define PN533_NO_TYPE_B_PROTOCOLS (NFC_PROTO_JEWEL_MASK | \
  45. NFC_PROTO_MIFARE_MASK | \
  46. NFC_PROTO_FELICA_MASK | \
  47. NFC_PROTO_ISO14443_MASK | \
  48. NFC_PROTO_NFC_DEP_MASK)
  49. static const struct usb_device_id pn533_table[] = {
  50. { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
  51. .idVendor = PN533_VENDOR_ID,
  52. .idProduct = PN533_PRODUCT_ID,
  53. .driver_info = PN533_DEVICE_STD,
  54. },
  55. { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
  56. .idVendor = SCM_VENDOR_ID,
  57. .idProduct = SCL3711_PRODUCT_ID,
  58. .driver_info = PN533_DEVICE_STD,
  59. },
  60. { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
  61. .idVendor = SONY_VENDOR_ID,
  62. .idProduct = PASORI_PRODUCT_ID,
  63. .driver_info = PN533_DEVICE_PASORI,
  64. },
  65. { .match_flags = USB_DEVICE_ID_MATCH_DEVICE,
  66. .idVendor = ACS_VENDOR_ID,
  67. .idProduct = ACR122U_PRODUCT_ID,
  68. .driver_info = PN533_DEVICE_ACR122U,
  69. },
  70. { }
  71. };
  72. MODULE_DEVICE_TABLE(usb, pn533_table);
  73. /* How much time we spend listening for initiators */
  74. #define PN533_LISTEN_TIME 2
  75. /* Standard pn533 frame definitions */
  76. #define PN533_STD_FRAME_HEADER_LEN (sizeof(struct pn533_std_frame) \
  77. + 2) /* data[0] TFI, data[1] CC */
  78. #define PN533_STD_FRAME_TAIL_LEN 2 /* data[len] DCS, data[len + 1] postamble*/
  79. /*
  80. * Max extended frame payload len, excluding TFI and CC
  81. * which are already in PN533_FRAME_HEADER_LEN.
  82. */
  83. #define PN533_STD_FRAME_MAX_PAYLOAD_LEN 263
  84. #define PN533_STD_FRAME_ACK_SIZE 6 /* Preamble (1), SoPC (2), ACK Code (2),
  85. Postamble (1) */
  86. #define PN533_STD_FRAME_CHECKSUM(f) (f->data[f->datalen])
  87. #define PN533_STD_FRAME_POSTAMBLE(f) (f->data[f->datalen + 1])
  88. /* start of frame */
  89. #define PN533_STD_FRAME_SOF 0x00FF
  90. /* standard frame identifier: in/out/error */
  91. #define PN533_STD_FRAME_IDENTIFIER(f) (f->data[0]) /* TFI */
  92. #define PN533_STD_FRAME_DIR_OUT 0xD4
  93. #define PN533_STD_FRAME_DIR_IN 0xD5
  94. /* ACS ACR122 pn533 frame definitions */
  95. #define PN533_ACR122_TX_FRAME_HEADER_LEN (sizeof(struct pn533_acr122_tx_frame) \
  96. + 2)
  97. #define PN533_ACR122_TX_FRAME_TAIL_LEN 0
  98. #define PN533_ACR122_RX_FRAME_HEADER_LEN (sizeof(struct pn533_acr122_rx_frame) \
  99. + 2)
  100. #define PN533_ACR122_RX_FRAME_TAIL_LEN 2
  101. #define PN533_ACR122_FRAME_MAX_PAYLOAD_LEN PN533_STD_FRAME_MAX_PAYLOAD_LEN
  102. /* CCID messages types */
  103. #define PN533_ACR122_PC_TO_RDR_ICCPOWERON 0x62
  104. #define PN533_ACR122_PC_TO_RDR_ESCAPE 0x6B
  105. #define PN533_ACR122_RDR_TO_PC_ESCAPE 0x83
  106. /* PN533 Commands */
  107. #define PN533_STD_FRAME_CMD(f) (f->data[1])
  108. #define PN533_CMD_GET_FIRMWARE_VERSION 0x02
  109. #define PN533_CMD_RF_CONFIGURATION 0x32
  110. #define PN533_CMD_IN_DATA_EXCHANGE 0x40
  111. #define PN533_CMD_IN_COMM_THRU 0x42
  112. #define PN533_CMD_IN_LIST_PASSIVE_TARGET 0x4A
  113. #define PN533_CMD_IN_ATR 0x50
  114. #define PN533_CMD_IN_RELEASE 0x52
  115. #define PN533_CMD_IN_JUMP_FOR_DEP 0x56
  116. #define PN533_CMD_TG_INIT_AS_TARGET 0x8c
  117. #define PN533_CMD_TG_GET_DATA 0x86
  118. #define PN533_CMD_TG_SET_DATA 0x8e
  119. #define PN533_CMD_UNDEF 0xff
  120. #define PN533_CMD_RESPONSE(cmd) (cmd + 1)
  121. /* PN533 Return codes */
  122. #define PN533_CMD_RET_MASK 0x3F
  123. #define PN533_CMD_MI_MASK 0x40
  124. #define PN533_CMD_RET_SUCCESS 0x00
  125. struct pn533;
  126. typedef int (*pn533_send_async_complete_t) (struct pn533 *dev, void *arg,
  127. struct sk_buff *resp);
  128. /* structs for pn533 commands */
  129. /* PN533_CMD_GET_FIRMWARE_VERSION */
  130. struct pn533_fw_version {
  131. u8 ic;
  132. u8 ver;
  133. u8 rev;
  134. u8 support;
  135. };
  136. /* PN533_CMD_RF_CONFIGURATION */
  137. #define PN533_CFGITEM_RF_FIELD 0x01
  138. #define PN533_CFGITEM_TIMING 0x02
  139. #define PN533_CFGITEM_MAX_RETRIES 0x05
  140. #define PN533_CFGITEM_PASORI 0x82
  141. #define PN533_CFGITEM_RF_FIELD_ON 0x1
  142. #define PN533_CFGITEM_RF_FIELD_OFF 0x0
  143. #define PN533_CONFIG_TIMING_102 0xb
  144. #define PN533_CONFIG_TIMING_204 0xc
  145. #define PN533_CONFIG_TIMING_409 0xd
  146. #define PN533_CONFIG_TIMING_819 0xe
  147. #define PN533_CONFIG_MAX_RETRIES_NO_RETRY 0x00
  148. #define PN533_CONFIG_MAX_RETRIES_ENDLESS 0xFF
  149. struct pn533_config_max_retries {
  150. u8 mx_rty_atr;
  151. u8 mx_rty_psl;
  152. u8 mx_rty_passive_act;
  153. } __packed;
  154. struct pn533_config_timing {
  155. u8 rfu;
  156. u8 atr_res_timeout;
  157. u8 dep_timeout;
  158. } __packed;
  159. /* PN533_CMD_IN_LIST_PASSIVE_TARGET */
  160. /* felica commands opcode */
  161. #define PN533_FELICA_OPC_SENSF_REQ 0
  162. #define PN533_FELICA_OPC_SENSF_RES 1
  163. /* felica SENSF_REQ parameters */
  164. #define PN533_FELICA_SENSF_SC_ALL 0xFFFF
  165. #define PN533_FELICA_SENSF_RC_NO_SYSTEM_CODE 0
  166. #define PN533_FELICA_SENSF_RC_SYSTEM_CODE 1
  167. #define PN533_FELICA_SENSF_RC_ADVANCED_PROTOCOL 2
  168. /* type B initiator_data values */
  169. #define PN533_TYPE_B_AFI_ALL_FAMILIES 0
  170. #define PN533_TYPE_B_POLL_METHOD_TIMESLOT 0
  171. #define PN533_TYPE_B_POLL_METHOD_PROBABILISTIC 1
  172. union pn533_cmd_poll_initdata {
  173. struct {
  174. u8 afi;
  175. u8 polling_method;
  176. } __packed type_b;
  177. struct {
  178. u8 opcode;
  179. __be16 sc;
  180. u8 rc;
  181. u8 tsn;
  182. } __packed felica;
  183. };
  184. /* Poll modulations */
  185. enum {
  186. PN533_POLL_MOD_106KBPS_A,
  187. PN533_POLL_MOD_212KBPS_FELICA,
  188. PN533_POLL_MOD_424KBPS_FELICA,
  189. PN533_POLL_MOD_106KBPS_JEWEL,
  190. PN533_POLL_MOD_847KBPS_B,
  191. PN533_LISTEN_MOD,
  192. __PN533_POLL_MOD_AFTER_LAST,
  193. };
  194. #define PN533_POLL_MOD_MAX (__PN533_POLL_MOD_AFTER_LAST - 1)
  195. struct pn533_poll_modulations {
  196. struct {
  197. u8 maxtg;
  198. u8 brty;
  199. union pn533_cmd_poll_initdata initiator_data;
  200. } __packed data;
  201. u8 len;
  202. };
  203. static const struct pn533_poll_modulations poll_mod[] = {
  204. [PN533_POLL_MOD_106KBPS_A] = {
  205. .data = {
  206. .maxtg = 1,
  207. .brty = 0,
  208. },
  209. .len = 2,
  210. },
  211. [PN533_POLL_MOD_212KBPS_FELICA] = {
  212. .data = {
  213. .maxtg = 1,
  214. .brty = 1,
  215. .initiator_data.felica = {
  216. .opcode = PN533_FELICA_OPC_SENSF_REQ,
  217. .sc = PN533_FELICA_SENSF_SC_ALL,
  218. .rc = PN533_FELICA_SENSF_RC_SYSTEM_CODE,
  219. .tsn = 0x03,
  220. },
  221. },
  222. .len = 7,
  223. },
  224. [PN533_POLL_MOD_424KBPS_FELICA] = {
  225. .data = {
  226. .maxtg = 1,
  227. .brty = 2,
  228. .initiator_data.felica = {
  229. .opcode = PN533_FELICA_OPC_SENSF_REQ,
  230. .sc = PN533_FELICA_SENSF_SC_ALL,
  231. .rc = PN533_FELICA_SENSF_RC_SYSTEM_CODE,
  232. .tsn = 0x03,
  233. },
  234. },
  235. .len = 7,
  236. },
  237. [PN533_POLL_MOD_106KBPS_JEWEL] = {
  238. .data = {
  239. .maxtg = 1,
  240. .brty = 4,
  241. },
  242. .len = 2,
  243. },
  244. [PN533_POLL_MOD_847KBPS_B] = {
  245. .data = {
  246. .maxtg = 1,
  247. .brty = 8,
  248. .initiator_data.type_b = {
  249. .afi = PN533_TYPE_B_AFI_ALL_FAMILIES,
  250. .polling_method =
  251. PN533_TYPE_B_POLL_METHOD_TIMESLOT,
  252. },
  253. },
  254. .len = 3,
  255. },
  256. [PN533_LISTEN_MOD] = {
  257. .len = 0,
  258. },
  259. };
  260. /* PN533_CMD_IN_ATR */
  261. struct pn533_cmd_activate_response {
  262. u8 status;
  263. u8 nfcid3t[10];
  264. u8 didt;
  265. u8 bst;
  266. u8 brt;
  267. u8 to;
  268. u8 ppt;
  269. /* optional */
  270. u8 gt[];
  271. } __packed;
  272. struct pn533_cmd_jump_dep_response {
  273. u8 status;
  274. u8 tg;
  275. u8 nfcid3t[10];
  276. u8 didt;
  277. u8 bst;
  278. u8 brt;
  279. u8 to;
  280. u8 ppt;
  281. /* optional */
  282. u8 gt[];
  283. } __packed;
  284. /* PN533_TG_INIT_AS_TARGET */
  285. #define PN533_INIT_TARGET_PASSIVE 0x1
  286. #define PN533_INIT_TARGET_DEP 0x2
  287. #define PN533_INIT_TARGET_RESP_FRAME_MASK 0x3
  288. #define PN533_INIT_TARGET_RESP_ACTIVE 0x1
  289. #define PN533_INIT_TARGET_RESP_DEP 0x4
  290. enum pn533_protocol_type {
  291. PN533_PROTO_REQ_ACK_RESP = 0,
  292. PN533_PROTO_REQ_RESP
  293. };
  294. struct pn533 {
  295. struct usb_device *udev;
  296. struct usb_interface *interface;
  297. struct nfc_dev *nfc_dev;
  298. u32 device_type;
  299. enum pn533_protocol_type protocol_type;
  300. struct urb *out_urb;
  301. struct urb *in_urb;
  302. struct sk_buff_head resp_q;
  303. struct workqueue_struct *wq;
  304. struct work_struct cmd_work;
  305. struct work_struct cmd_complete_work;
  306. struct work_struct poll_work;
  307. struct work_struct mi_work;
  308. struct work_struct tg_work;
  309. struct work_struct rf_work;
  310. struct list_head cmd_queue;
  311. struct pn533_cmd *cmd;
  312. u8 cmd_pending;
  313. struct mutex cmd_lock; /* protects cmd queue */
  314. void *cmd_complete_mi_arg;
  315. struct pn533_poll_modulations *poll_mod_active[PN533_POLL_MOD_MAX + 1];
  316. u8 poll_mod_count;
  317. u8 poll_mod_curr;
  318. u32 poll_protocols;
  319. u32 listen_protocols;
  320. struct timer_list listen_timer;
  321. int cancel_listen;
  322. u8 *gb;
  323. size_t gb_len;
  324. u8 tgt_available_prots;
  325. u8 tgt_active_prot;
  326. u8 tgt_mode;
  327. struct pn533_frame_ops *ops;
  328. };
  329. struct pn533_cmd {
  330. struct list_head queue;
  331. u8 code;
  332. int status;
  333. struct sk_buff *req;
  334. struct sk_buff *resp;
  335. int resp_len;
  336. pn533_send_async_complete_t complete_cb;
  337. void *complete_cb_context;
  338. };
  339. struct pn533_std_frame {
  340. u8 preamble;
  341. __be16 start_frame;
  342. u8 datalen;
  343. u8 datalen_checksum;
  344. u8 data[];
  345. } __packed;
  346. struct pn533_frame_ops {
  347. void (*tx_frame_init)(void *frame, u8 cmd_code);
  348. void (*tx_frame_finish)(void *frame);
  349. void (*tx_update_payload_len)(void *frame, int len);
  350. int tx_header_len;
  351. int tx_tail_len;
  352. bool (*rx_is_frame_valid)(void *frame);
  353. int (*rx_frame_size)(void *frame);
  354. int rx_header_len;
  355. int rx_tail_len;
  356. int max_payload_len;
  357. u8 (*get_cmd_code)(void *frame);
  358. };
  359. struct pn533_acr122_ccid_hdr {
  360. u8 type;
  361. u32 datalen;
  362. u8 slot;
  363. u8 seq;
  364. u8 params[3]; /* 3 msg specific bytes or status, error and 1 specific
  365. byte for reposnse msg */
  366. u8 data[]; /* payload */
  367. } __packed;
  368. struct pn533_acr122_apdu_hdr {
  369. u8 class;
  370. u8 ins;
  371. u8 p1;
  372. u8 p2;
  373. } __packed;
  374. struct pn533_acr122_tx_frame {
  375. struct pn533_acr122_ccid_hdr ccid;
  376. struct pn533_acr122_apdu_hdr apdu;
  377. u8 datalen;
  378. u8 data[]; /* pn533 frame: TFI ... */
  379. } __packed;
  380. struct pn533_acr122_rx_frame {
  381. struct pn533_acr122_ccid_hdr ccid;
  382. u8 data[]; /* pn533 frame : TFI ... */
  383. } __packed;
  384. static void pn533_acr122_tx_frame_init(void *_frame, u8 cmd_code)
  385. {
  386. struct pn533_acr122_tx_frame *frame = _frame;
  387. frame->ccid.type = PN533_ACR122_PC_TO_RDR_ESCAPE;
  388. frame->ccid.datalen = sizeof(frame->apdu) + 1; /* sizeof(apdu_hdr) +
  389. sizeof(datalen) */
  390. frame->ccid.slot = 0;
  391. frame->ccid.seq = 0;
  392. frame->ccid.params[0] = 0;
  393. frame->ccid.params[1] = 0;
  394. frame->ccid.params[2] = 0;
  395. frame->data[0] = PN533_STD_FRAME_DIR_OUT;
  396. frame->data[1] = cmd_code;
  397. frame->datalen = 2; /* data[0] + data[1] */
  398. frame->apdu.class = 0xFF;
  399. frame->apdu.ins = 0;
  400. frame->apdu.p1 = 0;
  401. frame->apdu.p2 = 0;
  402. }
  403. static void pn533_acr122_tx_frame_finish(void *_frame)
  404. {
  405. struct pn533_acr122_tx_frame *frame = _frame;
  406. frame->ccid.datalen += frame->datalen;
  407. }
  408. static void pn533_acr122_tx_update_payload_len(void *_frame, int len)
  409. {
  410. struct pn533_acr122_tx_frame *frame = _frame;
  411. frame->datalen += len;
  412. }
  413. static bool pn533_acr122_is_rx_frame_valid(void *_frame)
  414. {
  415. struct pn533_acr122_rx_frame *frame = _frame;
  416. if (frame->ccid.type != 0x83)
  417. return false;
  418. if (frame->data[frame->ccid.datalen - 2] == 0x63)
  419. return false;
  420. return true;
  421. }
  422. static int pn533_acr122_rx_frame_size(void *frame)
  423. {
  424. struct pn533_acr122_rx_frame *f = frame;
  425. /* f->ccid.datalen already includes tail length */
  426. return sizeof(struct pn533_acr122_rx_frame) + f->ccid.datalen;
  427. }
  428. static u8 pn533_acr122_get_cmd_code(void *frame)
  429. {
  430. struct pn533_acr122_rx_frame *f = frame;
  431. return PN533_STD_FRAME_CMD(f);
  432. }
  433. static struct pn533_frame_ops pn533_acr122_frame_ops = {
  434. .tx_frame_init = pn533_acr122_tx_frame_init,
  435. .tx_frame_finish = pn533_acr122_tx_frame_finish,
  436. .tx_update_payload_len = pn533_acr122_tx_update_payload_len,
  437. .tx_header_len = PN533_ACR122_TX_FRAME_HEADER_LEN,
  438. .tx_tail_len = PN533_ACR122_TX_FRAME_TAIL_LEN,
  439. .rx_is_frame_valid = pn533_acr122_is_rx_frame_valid,
  440. .rx_header_len = PN533_ACR122_RX_FRAME_HEADER_LEN,
  441. .rx_tail_len = PN533_ACR122_RX_FRAME_TAIL_LEN,
  442. .rx_frame_size = pn533_acr122_rx_frame_size,
  443. .max_payload_len = PN533_ACR122_FRAME_MAX_PAYLOAD_LEN,
  444. .get_cmd_code = pn533_acr122_get_cmd_code,
  445. };
  446. /* The rule: value + checksum = 0 */
  447. static inline u8 pn533_std_checksum(u8 value)
  448. {
  449. return ~value + 1;
  450. }
  451. /* The rule: sum(data elements) + checksum = 0 */
  452. static u8 pn533_std_data_checksum(u8 *data, int datalen)
  453. {
  454. u8 sum = 0;
  455. int i;
  456. for (i = 0; i < datalen; i++)
  457. sum += data[i];
  458. return pn533_std_checksum(sum);
  459. }
  460. static void pn533_std_tx_frame_init(void *_frame, u8 cmd_code)
  461. {
  462. struct pn533_std_frame *frame = _frame;
  463. frame->preamble = 0;
  464. frame->start_frame = cpu_to_be16(PN533_STD_FRAME_SOF);
  465. PN533_STD_FRAME_IDENTIFIER(frame) = PN533_STD_FRAME_DIR_OUT;
  466. PN533_STD_FRAME_CMD(frame) = cmd_code;
  467. frame->datalen = 2;
  468. }
  469. static void pn533_std_tx_frame_finish(void *_frame)
  470. {
  471. struct pn533_std_frame *frame = _frame;
  472. frame->datalen_checksum = pn533_std_checksum(frame->datalen);
  473. PN533_STD_FRAME_CHECKSUM(frame) =
  474. pn533_std_data_checksum(frame->data, frame->datalen);
  475. PN533_STD_FRAME_POSTAMBLE(frame) = 0;
  476. }
  477. static void pn533_std_tx_update_payload_len(void *_frame, int len)
  478. {
  479. struct pn533_std_frame *frame = _frame;
  480. frame->datalen += len;
  481. }
  482. static bool pn533_std_rx_frame_is_valid(void *_frame)
  483. {
  484. u8 checksum;
  485. struct pn533_std_frame *frame = _frame;
  486. if (frame->start_frame != cpu_to_be16(PN533_STD_FRAME_SOF))
  487. return false;
  488. checksum = pn533_std_checksum(frame->datalen);
  489. if (checksum != frame->datalen_checksum)
  490. return false;
  491. checksum = pn533_std_data_checksum(frame->data, frame->datalen);
  492. if (checksum != PN533_STD_FRAME_CHECKSUM(frame))
  493. return false;
  494. return true;
  495. }
  496. static bool pn533_std_rx_frame_is_ack(struct pn533_std_frame *frame)
  497. {
  498. if (frame->start_frame != cpu_to_be16(PN533_STD_FRAME_SOF))
  499. return false;
  500. if (frame->datalen != 0 || frame->datalen_checksum != 0xFF)
  501. return false;
  502. return true;
  503. }
  504. static inline int pn533_std_rx_frame_size(void *frame)
  505. {
  506. struct pn533_std_frame *f = frame;
  507. return sizeof(struct pn533_std_frame) + f->datalen +
  508. PN533_STD_FRAME_TAIL_LEN;
  509. }
  510. static u8 pn533_std_get_cmd_code(void *frame)
  511. {
  512. struct pn533_std_frame *f = frame;
  513. return PN533_STD_FRAME_CMD(f);
  514. }
  515. static struct pn533_frame_ops pn533_std_frame_ops = {
  516. .tx_frame_init = pn533_std_tx_frame_init,
  517. .tx_frame_finish = pn533_std_tx_frame_finish,
  518. .tx_update_payload_len = pn533_std_tx_update_payload_len,
  519. .tx_header_len = PN533_STD_FRAME_HEADER_LEN,
  520. .tx_tail_len = PN533_STD_FRAME_TAIL_LEN,
  521. .rx_is_frame_valid = pn533_std_rx_frame_is_valid,
  522. .rx_frame_size = pn533_std_rx_frame_size,
  523. .rx_header_len = PN533_STD_FRAME_HEADER_LEN,
  524. .rx_tail_len = PN533_STD_FRAME_TAIL_LEN,
  525. .max_payload_len = PN533_STD_FRAME_MAX_PAYLOAD_LEN,
  526. .get_cmd_code = pn533_std_get_cmd_code,
  527. };
  528. static bool pn533_rx_frame_is_cmd_response(struct pn533 *dev, void *frame)
  529. {
  530. return (dev->ops->get_cmd_code(frame) ==
  531. PN533_CMD_RESPONSE(dev->cmd->code));
  532. }
  533. static void pn533_recv_response(struct urb *urb)
  534. {
  535. struct pn533 *dev = urb->context;
  536. struct pn533_cmd *cmd = dev->cmd;
  537. u8 *in_frame;
  538. cmd->status = urb->status;
  539. switch (urb->status) {
  540. case 0:
  541. break; /* success */
  542. case -ECONNRESET:
  543. case -ENOENT:
  544. nfc_dev_dbg(&dev->interface->dev,
  545. "The urb has been canceled (status %d)",
  546. urb->status);
  547. goto sched_wq;
  548. case -ESHUTDOWN:
  549. default:
  550. nfc_dev_err(&dev->interface->dev,
  551. "Urb failure (status %d)", urb->status);
  552. goto sched_wq;
  553. }
  554. in_frame = dev->in_urb->transfer_buffer;
  555. nfc_dev_dbg(&dev->interface->dev, "Received a frame.");
  556. print_hex_dump_debug("PN533 RX: ", DUMP_PREFIX_NONE, 16, 1, in_frame,
  557. dev->ops->rx_frame_size(in_frame), false);
  558. if (!dev->ops->rx_is_frame_valid(in_frame)) {
  559. nfc_dev_err(&dev->interface->dev, "Received an invalid frame");
  560. cmd->status = -EIO;
  561. goto sched_wq;
  562. }
  563. if (!pn533_rx_frame_is_cmd_response(dev, in_frame)) {
  564. nfc_dev_err(&dev->interface->dev,
  565. "It it not the response to the last command");
  566. cmd->status = -EIO;
  567. goto sched_wq;
  568. }
  569. sched_wq:
  570. queue_work(dev->wq, &dev->cmd_complete_work);
  571. }
  572. static int pn533_submit_urb_for_response(struct pn533 *dev, gfp_t flags)
  573. {
  574. dev->in_urb->complete = pn533_recv_response;
  575. return usb_submit_urb(dev->in_urb, flags);
  576. }
  577. static void pn533_recv_ack(struct urb *urb)
  578. {
  579. struct pn533 *dev = urb->context;
  580. struct pn533_cmd *cmd = dev->cmd;
  581. struct pn533_std_frame *in_frame;
  582. int rc;
  583. cmd->status = urb->status;
  584. switch (urb->status) {
  585. case 0:
  586. break; /* success */
  587. case -ECONNRESET:
  588. case -ENOENT:
  589. nfc_dev_dbg(&dev->interface->dev,
  590. "The urb has been stopped (status %d)",
  591. urb->status);
  592. goto sched_wq;
  593. case -ESHUTDOWN:
  594. default:
  595. nfc_dev_err(&dev->interface->dev,
  596. "Urb failure (status %d)", urb->status);
  597. goto sched_wq;
  598. }
  599. in_frame = dev->in_urb->transfer_buffer;
  600. if (!pn533_std_rx_frame_is_ack(in_frame)) {
  601. nfc_dev_err(&dev->interface->dev, "Received an invalid ack");
  602. cmd->status = -EIO;
  603. goto sched_wq;
  604. }
  605. rc = pn533_submit_urb_for_response(dev, GFP_ATOMIC);
  606. if (rc) {
  607. nfc_dev_err(&dev->interface->dev,
  608. "usb_submit_urb failed with result %d", rc);
  609. cmd->status = rc;
  610. goto sched_wq;
  611. }
  612. return;
  613. sched_wq:
  614. queue_work(dev->wq, &dev->cmd_complete_work);
  615. }
  616. static int pn533_submit_urb_for_ack(struct pn533 *dev, gfp_t flags)
  617. {
  618. dev->in_urb->complete = pn533_recv_ack;
  619. return usb_submit_urb(dev->in_urb, flags);
  620. }
  621. static int pn533_send_ack(struct pn533 *dev, gfp_t flags)
  622. {
  623. u8 ack[PN533_STD_FRAME_ACK_SIZE] = {0x00, 0x00, 0xff, 0x00, 0xff, 0x00};
  624. /* spec 7.1.1.3: Preamble, SoPC (2), ACK Code (2), Postamble */
  625. int rc;
  626. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  627. dev->out_urb->transfer_buffer = ack;
  628. dev->out_urb->transfer_buffer_length = sizeof(ack);
  629. rc = usb_submit_urb(dev->out_urb, flags);
  630. return rc;
  631. }
  632. static int __pn533_send_frame_async(struct pn533 *dev,
  633. struct sk_buff *out,
  634. struct sk_buff *in,
  635. int in_len)
  636. {
  637. int rc;
  638. dev->out_urb->transfer_buffer = out->data;
  639. dev->out_urb->transfer_buffer_length = out->len;
  640. dev->in_urb->transfer_buffer = in->data;
  641. dev->in_urb->transfer_buffer_length = in_len;
  642. print_hex_dump_debug("PN533 TX: ", DUMP_PREFIX_NONE, 16, 1,
  643. out->data, out->len, false);
  644. rc = usb_submit_urb(dev->out_urb, GFP_KERNEL);
  645. if (rc)
  646. return rc;
  647. if (dev->protocol_type == PN533_PROTO_REQ_RESP) {
  648. /* request for response for sent packet directly */
  649. rc = pn533_submit_urb_for_response(dev, GFP_ATOMIC);
  650. if (rc)
  651. goto error;
  652. } else if (dev->protocol_type == PN533_PROTO_REQ_ACK_RESP) {
  653. /* request for ACK if that's the case */
  654. rc = pn533_submit_urb_for_ack(dev, GFP_KERNEL);
  655. if (rc)
  656. goto error;
  657. }
  658. return 0;
  659. error:
  660. usb_unlink_urb(dev->out_urb);
  661. return rc;
  662. }
  663. static void pn533_build_cmd_frame(struct pn533 *dev, u8 cmd_code,
  664. struct sk_buff *skb)
  665. {
  666. /* payload is already there, just update datalen */
  667. int payload_len = skb->len;
  668. struct pn533_frame_ops *ops = dev->ops;
  669. skb_push(skb, ops->tx_header_len);
  670. skb_put(skb, ops->tx_tail_len);
  671. ops->tx_frame_init(skb->data, cmd_code);
  672. ops->tx_update_payload_len(skb->data, payload_len);
  673. ops->tx_frame_finish(skb->data);
  674. }
  675. static int pn533_send_async_complete(struct pn533 *dev)
  676. {
  677. struct pn533_cmd *cmd = dev->cmd;
  678. int status = cmd->status;
  679. struct sk_buff *req = cmd->req;
  680. struct sk_buff *resp = cmd->resp;
  681. int rc;
  682. dev_kfree_skb(req);
  683. if (status < 0) {
  684. rc = cmd->complete_cb(dev, cmd->complete_cb_context,
  685. ERR_PTR(status));
  686. dev_kfree_skb(resp);
  687. goto done;
  688. }
  689. skb_put(resp, dev->ops->rx_frame_size(resp->data));
  690. skb_pull(resp, dev->ops->rx_header_len);
  691. skb_trim(resp, resp->len - dev->ops->rx_tail_len);
  692. rc = cmd->complete_cb(dev, cmd->complete_cb_context, resp);
  693. done:
  694. kfree(cmd);
  695. dev->cmd = NULL;
  696. return rc;
  697. }
  698. static int __pn533_send_async(struct pn533 *dev, u8 cmd_code,
  699. struct sk_buff *req, struct sk_buff *resp,
  700. int resp_len,
  701. pn533_send_async_complete_t complete_cb,
  702. void *complete_cb_context)
  703. {
  704. struct pn533_cmd *cmd;
  705. int rc = 0;
  706. nfc_dev_dbg(&dev->interface->dev, "Sending command 0x%x", cmd_code);
  707. cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
  708. if (!cmd)
  709. return -ENOMEM;
  710. cmd->code = cmd_code;
  711. cmd->req = req;
  712. cmd->resp = resp;
  713. cmd->resp_len = resp_len;
  714. cmd->complete_cb = complete_cb;
  715. cmd->complete_cb_context = complete_cb_context;
  716. pn533_build_cmd_frame(dev, cmd_code, req);
  717. mutex_lock(&dev->cmd_lock);
  718. if (!dev->cmd_pending) {
  719. rc = __pn533_send_frame_async(dev, req, resp, resp_len);
  720. if (rc)
  721. goto error;
  722. dev->cmd_pending = 1;
  723. dev->cmd = cmd;
  724. goto unlock;
  725. }
  726. nfc_dev_dbg(&dev->interface->dev, "%s Queueing command 0x%x", __func__,
  727. cmd_code);
  728. INIT_LIST_HEAD(&cmd->queue);
  729. list_add_tail(&cmd->queue, &dev->cmd_queue);
  730. goto unlock;
  731. error:
  732. kfree(cmd);
  733. unlock:
  734. mutex_unlock(&dev->cmd_lock);
  735. return rc;
  736. }
  737. static int pn533_send_data_async(struct pn533 *dev, u8 cmd_code,
  738. struct sk_buff *req,
  739. pn533_send_async_complete_t complete_cb,
  740. void *complete_cb_context)
  741. {
  742. struct sk_buff *resp;
  743. int rc;
  744. int resp_len = dev->ops->rx_header_len +
  745. dev->ops->max_payload_len +
  746. dev->ops->rx_tail_len;
  747. resp = nfc_alloc_recv_skb(resp_len, GFP_KERNEL);
  748. if (!resp)
  749. return -ENOMEM;
  750. rc = __pn533_send_async(dev, cmd_code, req, resp, resp_len, complete_cb,
  751. complete_cb_context);
  752. if (rc)
  753. dev_kfree_skb(resp);
  754. return rc;
  755. }
  756. static int pn533_send_cmd_async(struct pn533 *dev, u8 cmd_code,
  757. struct sk_buff *req,
  758. pn533_send_async_complete_t complete_cb,
  759. void *complete_cb_context)
  760. {
  761. struct sk_buff *resp;
  762. int rc;
  763. int resp_len = dev->ops->rx_header_len +
  764. dev->ops->max_payload_len +
  765. dev->ops->rx_tail_len;
  766. resp = alloc_skb(resp_len, GFP_KERNEL);
  767. if (!resp)
  768. return -ENOMEM;
  769. rc = __pn533_send_async(dev, cmd_code, req, resp, resp_len, complete_cb,
  770. complete_cb_context);
  771. if (rc)
  772. dev_kfree_skb(resp);
  773. return rc;
  774. }
  775. /*
  776. * pn533_send_cmd_direct_async
  777. *
  778. * The function sends a piority cmd directly to the chip omiting the cmd
  779. * queue. It's intended to be used by chaining mechanism of received responses
  780. * where the host has to request every single chunk of data before scheduling
  781. * next cmd from the queue.
  782. */
  783. static int pn533_send_cmd_direct_async(struct pn533 *dev, u8 cmd_code,
  784. struct sk_buff *req,
  785. pn533_send_async_complete_t complete_cb,
  786. void *complete_cb_context)
  787. {
  788. struct sk_buff *resp;
  789. struct pn533_cmd *cmd;
  790. int rc;
  791. int resp_len = dev->ops->rx_header_len +
  792. dev->ops->max_payload_len +
  793. dev->ops->rx_tail_len;
  794. resp = alloc_skb(resp_len, GFP_KERNEL);
  795. if (!resp)
  796. return -ENOMEM;
  797. cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
  798. if (!cmd) {
  799. dev_kfree_skb(resp);
  800. return -ENOMEM;
  801. }
  802. cmd->code = cmd_code;
  803. cmd->req = req;
  804. cmd->resp = resp;
  805. cmd->resp_len = resp_len;
  806. cmd->complete_cb = complete_cb;
  807. cmd->complete_cb_context = complete_cb_context;
  808. pn533_build_cmd_frame(dev, cmd_code, req);
  809. rc = __pn533_send_frame_async(dev, req, resp, resp_len);
  810. if (rc < 0) {
  811. dev_kfree_skb(resp);
  812. kfree(cmd);
  813. } else {
  814. dev->cmd = cmd;
  815. }
  816. return rc;
  817. }
  818. static void pn533_wq_cmd_complete(struct work_struct *work)
  819. {
  820. struct pn533 *dev = container_of(work, struct pn533, cmd_complete_work);
  821. int rc;
  822. rc = pn533_send_async_complete(dev);
  823. if (rc != -EINPROGRESS)
  824. queue_work(dev->wq, &dev->cmd_work);
  825. }
  826. static void pn533_wq_cmd(struct work_struct *work)
  827. {
  828. struct pn533 *dev = container_of(work, struct pn533, cmd_work);
  829. struct pn533_cmd *cmd;
  830. int rc;
  831. mutex_lock(&dev->cmd_lock);
  832. if (list_empty(&dev->cmd_queue)) {
  833. dev->cmd_pending = 0;
  834. mutex_unlock(&dev->cmd_lock);
  835. return;
  836. }
  837. cmd = list_first_entry(&dev->cmd_queue, struct pn533_cmd, queue);
  838. list_del(&cmd->queue);
  839. mutex_unlock(&dev->cmd_lock);
  840. rc = __pn533_send_frame_async(dev, cmd->req, cmd->resp, cmd->resp_len);
  841. if (rc < 0) {
  842. dev_kfree_skb(cmd->req);
  843. dev_kfree_skb(cmd->resp);
  844. kfree(cmd);
  845. return;
  846. }
  847. dev->cmd = cmd;
  848. }
  849. struct pn533_sync_cmd_response {
  850. struct sk_buff *resp;
  851. struct completion done;
  852. };
  853. static int pn533_send_sync_complete(struct pn533 *dev, void *_arg,
  854. struct sk_buff *resp)
  855. {
  856. struct pn533_sync_cmd_response *arg = _arg;
  857. arg->resp = resp;
  858. complete(&arg->done);
  859. return 0;
  860. }
  861. /* pn533_send_cmd_sync
  862. *
  863. * Please note the req parameter is freed inside the function to
  864. * limit a number of return value interpretations by the caller.
  865. *
  866. * 1. negative in case of error during TX path -> req should be freed
  867. *
  868. * 2. negative in case of error during RX path -> req should not be freed
  869. * as it's been already freed at the begining of RX path by
  870. * async_complete_cb.
  871. *
  872. * 3. valid pointer in case of succesfult RX path
  873. *
  874. * A caller has to check a return value with IS_ERR macro. If the test pass,
  875. * the returned pointer is valid.
  876. *
  877. * */
  878. static struct sk_buff *pn533_send_cmd_sync(struct pn533 *dev, u8 cmd_code,
  879. struct sk_buff *req)
  880. {
  881. int rc;
  882. struct pn533_sync_cmd_response arg;
  883. init_completion(&arg.done);
  884. rc = pn533_send_cmd_async(dev, cmd_code, req,
  885. pn533_send_sync_complete, &arg);
  886. if (rc) {
  887. dev_kfree_skb(req);
  888. return ERR_PTR(rc);
  889. }
  890. wait_for_completion(&arg.done);
  891. return arg.resp;
  892. }
  893. static void pn533_send_complete(struct urb *urb)
  894. {
  895. struct pn533 *dev = urb->context;
  896. switch (urb->status) {
  897. case 0:
  898. break; /* success */
  899. case -ECONNRESET:
  900. case -ENOENT:
  901. nfc_dev_dbg(&dev->interface->dev,
  902. "The urb has been stopped (status %d)",
  903. urb->status);
  904. break;
  905. case -ESHUTDOWN:
  906. default:
  907. nfc_dev_err(&dev->interface->dev,
  908. "Urb failure (status %d)", urb->status);
  909. }
  910. }
  911. static void pn533_abort_cmd(struct pn533 *dev, gfp_t flags)
  912. {
  913. /* ACR122U does not support any command which aborts last
  914. * issued command i.e. as ACK for standard PN533. Additionally,
  915. * it behaves stange, sending broken or incorrect responses,
  916. * when we cancel urb before the chip will send response.
  917. */
  918. if (dev->device_type == PN533_DEVICE_ACR122U)
  919. return;
  920. /* An ack will cancel the last issued command */
  921. pn533_send_ack(dev, flags);
  922. /* cancel the urb request */
  923. usb_kill_urb(dev->in_urb);
  924. }
  925. static struct sk_buff *pn533_alloc_skb(struct pn533 *dev, unsigned int size)
  926. {
  927. struct sk_buff *skb;
  928. skb = alloc_skb(dev->ops->tx_header_len +
  929. size +
  930. dev->ops->tx_tail_len, GFP_KERNEL);
  931. if (skb)
  932. skb_reserve(skb, dev->ops->tx_header_len);
  933. return skb;
  934. }
  935. struct pn533_target_type_a {
  936. __be16 sens_res;
  937. u8 sel_res;
  938. u8 nfcid_len;
  939. u8 nfcid_data[];
  940. } __packed;
  941. #define PN533_TYPE_A_SENS_RES_NFCID1(x) ((u8)((be16_to_cpu(x) & 0x00C0) >> 6))
  942. #define PN533_TYPE_A_SENS_RES_SSD(x) ((u8)((be16_to_cpu(x) & 0x001F) >> 0))
  943. #define PN533_TYPE_A_SENS_RES_PLATCONF(x) ((u8)((be16_to_cpu(x) & 0x0F00) >> 8))
  944. #define PN533_TYPE_A_SENS_RES_SSD_JEWEL 0x00
  945. #define PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL 0x0C
  946. #define PN533_TYPE_A_SEL_PROT(x) (((x) & 0x60) >> 5)
  947. #define PN533_TYPE_A_SEL_CASCADE(x) (((x) & 0x04) >> 2)
  948. #define PN533_TYPE_A_SEL_PROT_MIFARE 0
  949. #define PN533_TYPE_A_SEL_PROT_ISO14443 1
  950. #define PN533_TYPE_A_SEL_PROT_DEP 2
  951. #define PN533_TYPE_A_SEL_PROT_ISO14443_DEP 3
  952. static bool pn533_target_type_a_is_valid(struct pn533_target_type_a *type_a,
  953. int target_data_len)
  954. {
  955. u8 ssd;
  956. u8 platconf;
  957. if (target_data_len < sizeof(struct pn533_target_type_a))
  958. return false;
  959. /* The lenght check of nfcid[] and ats[] are not being performed because
  960. the values are not being used */
  961. /* Requirement 4.6.3.3 from NFC Forum Digital Spec */
  962. ssd = PN533_TYPE_A_SENS_RES_SSD(type_a->sens_res);
  963. platconf = PN533_TYPE_A_SENS_RES_PLATCONF(type_a->sens_res);
  964. if ((ssd == PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  965. platconf != PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL) ||
  966. (ssd != PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  967. platconf == PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL))
  968. return false;
  969. /* Requirements 4.8.2.1, 4.8.2.3, 4.8.2.5 and 4.8.2.7 from NFC Forum */
  970. if (PN533_TYPE_A_SEL_CASCADE(type_a->sel_res) != 0)
  971. return false;
  972. return true;
  973. }
  974. static int pn533_target_found_type_a(struct nfc_target *nfc_tgt, u8 *tgt_data,
  975. int tgt_data_len)
  976. {
  977. struct pn533_target_type_a *tgt_type_a;
  978. tgt_type_a = (struct pn533_target_type_a *)tgt_data;
  979. if (!pn533_target_type_a_is_valid(tgt_type_a, tgt_data_len))
  980. return -EPROTO;
  981. switch (PN533_TYPE_A_SEL_PROT(tgt_type_a->sel_res)) {
  982. case PN533_TYPE_A_SEL_PROT_MIFARE:
  983. nfc_tgt->supported_protocols = NFC_PROTO_MIFARE_MASK;
  984. break;
  985. case PN533_TYPE_A_SEL_PROT_ISO14443:
  986. nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_MASK;
  987. break;
  988. case PN533_TYPE_A_SEL_PROT_DEP:
  989. nfc_tgt->supported_protocols = NFC_PROTO_NFC_DEP_MASK;
  990. break;
  991. case PN533_TYPE_A_SEL_PROT_ISO14443_DEP:
  992. nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_MASK |
  993. NFC_PROTO_NFC_DEP_MASK;
  994. break;
  995. }
  996. nfc_tgt->sens_res = be16_to_cpu(tgt_type_a->sens_res);
  997. nfc_tgt->sel_res = tgt_type_a->sel_res;
  998. nfc_tgt->nfcid1_len = tgt_type_a->nfcid_len;
  999. memcpy(nfc_tgt->nfcid1, tgt_type_a->nfcid_data, nfc_tgt->nfcid1_len);
  1000. return 0;
  1001. }
  1002. struct pn533_target_felica {
  1003. u8 pol_res;
  1004. u8 opcode;
  1005. u8 nfcid2[NFC_NFCID2_MAXSIZE];
  1006. u8 pad[8];
  1007. /* optional */
  1008. u8 syst_code[];
  1009. } __packed;
  1010. #define PN533_FELICA_SENSF_NFCID2_DEP_B1 0x01
  1011. #define PN533_FELICA_SENSF_NFCID2_DEP_B2 0xFE
  1012. static bool pn533_target_felica_is_valid(struct pn533_target_felica *felica,
  1013. int target_data_len)
  1014. {
  1015. if (target_data_len < sizeof(struct pn533_target_felica))
  1016. return false;
  1017. if (felica->opcode != PN533_FELICA_OPC_SENSF_RES)
  1018. return false;
  1019. return true;
  1020. }
  1021. static int pn533_target_found_felica(struct nfc_target *nfc_tgt, u8 *tgt_data,
  1022. int tgt_data_len)
  1023. {
  1024. struct pn533_target_felica *tgt_felica;
  1025. tgt_felica = (struct pn533_target_felica *)tgt_data;
  1026. if (!pn533_target_felica_is_valid(tgt_felica, tgt_data_len))
  1027. return -EPROTO;
  1028. if ((tgt_felica->nfcid2[0] == PN533_FELICA_SENSF_NFCID2_DEP_B1) &&
  1029. (tgt_felica->nfcid2[1] == PN533_FELICA_SENSF_NFCID2_DEP_B2))
  1030. nfc_tgt->supported_protocols = NFC_PROTO_NFC_DEP_MASK;
  1031. else
  1032. nfc_tgt->supported_protocols = NFC_PROTO_FELICA_MASK;
  1033. memcpy(nfc_tgt->sensf_res, &tgt_felica->opcode, 9);
  1034. nfc_tgt->sensf_res_len = 9;
  1035. memcpy(nfc_tgt->nfcid2, tgt_felica->nfcid2, NFC_NFCID2_MAXSIZE);
  1036. nfc_tgt->nfcid2_len = NFC_NFCID2_MAXSIZE;
  1037. return 0;
  1038. }
  1039. struct pn533_target_jewel {
  1040. __be16 sens_res;
  1041. u8 jewelid[4];
  1042. } __packed;
  1043. static bool pn533_target_jewel_is_valid(struct pn533_target_jewel *jewel,
  1044. int target_data_len)
  1045. {
  1046. u8 ssd;
  1047. u8 platconf;
  1048. if (target_data_len < sizeof(struct pn533_target_jewel))
  1049. return false;
  1050. /* Requirement 4.6.3.3 from NFC Forum Digital Spec */
  1051. ssd = PN533_TYPE_A_SENS_RES_SSD(jewel->sens_res);
  1052. platconf = PN533_TYPE_A_SENS_RES_PLATCONF(jewel->sens_res);
  1053. if ((ssd == PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  1054. platconf != PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL) ||
  1055. (ssd != PN533_TYPE_A_SENS_RES_SSD_JEWEL &&
  1056. platconf == PN533_TYPE_A_SENS_RES_PLATCONF_JEWEL))
  1057. return false;
  1058. return true;
  1059. }
  1060. static int pn533_target_found_jewel(struct nfc_target *nfc_tgt, u8 *tgt_data,
  1061. int tgt_data_len)
  1062. {
  1063. struct pn533_target_jewel *tgt_jewel;
  1064. tgt_jewel = (struct pn533_target_jewel *)tgt_data;
  1065. if (!pn533_target_jewel_is_valid(tgt_jewel, tgt_data_len))
  1066. return -EPROTO;
  1067. nfc_tgt->supported_protocols = NFC_PROTO_JEWEL_MASK;
  1068. nfc_tgt->sens_res = be16_to_cpu(tgt_jewel->sens_res);
  1069. nfc_tgt->nfcid1_len = 4;
  1070. memcpy(nfc_tgt->nfcid1, tgt_jewel->jewelid, nfc_tgt->nfcid1_len);
  1071. return 0;
  1072. }
  1073. struct pn533_type_b_prot_info {
  1074. u8 bitrate;
  1075. u8 fsci_type;
  1076. u8 fwi_adc_fo;
  1077. } __packed;
  1078. #define PN533_TYPE_B_PROT_FCSI(x) (((x) & 0xF0) >> 4)
  1079. #define PN533_TYPE_B_PROT_TYPE(x) (((x) & 0x0F) >> 0)
  1080. #define PN533_TYPE_B_PROT_TYPE_RFU_MASK 0x8
  1081. struct pn533_type_b_sens_res {
  1082. u8 opcode;
  1083. u8 nfcid[4];
  1084. u8 appdata[4];
  1085. struct pn533_type_b_prot_info prot_info;
  1086. } __packed;
  1087. #define PN533_TYPE_B_OPC_SENSB_RES 0x50
  1088. struct pn533_target_type_b {
  1089. struct pn533_type_b_sens_res sensb_res;
  1090. u8 attrib_res_len;
  1091. u8 attrib_res[];
  1092. } __packed;
  1093. static bool pn533_target_type_b_is_valid(struct pn533_target_type_b *type_b,
  1094. int target_data_len)
  1095. {
  1096. if (target_data_len < sizeof(struct pn533_target_type_b))
  1097. return false;
  1098. if (type_b->sensb_res.opcode != PN533_TYPE_B_OPC_SENSB_RES)
  1099. return false;
  1100. if (PN533_TYPE_B_PROT_TYPE(type_b->sensb_res.prot_info.fsci_type) &
  1101. PN533_TYPE_B_PROT_TYPE_RFU_MASK)
  1102. return false;
  1103. return true;
  1104. }
  1105. static int pn533_target_found_type_b(struct nfc_target *nfc_tgt, u8 *tgt_data,
  1106. int tgt_data_len)
  1107. {
  1108. struct pn533_target_type_b *tgt_type_b;
  1109. tgt_type_b = (struct pn533_target_type_b *)tgt_data;
  1110. if (!pn533_target_type_b_is_valid(tgt_type_b, tgt_data_len))
  1111. return -EPROTO;
  1112. nfc_tgt->supported_protocols = NFC_PROTO_ISO14443_B_MASK;
  1113. return 0;
  1114. }
  1115. static int pn533_target_found(struct pn533 *dev, u8 tg, u8 *tgdata,
  1116. int tgdata_len)
  1117. {
  1118. struct nfc_target nfc_tgt;
  1119. int rc;
  1120. nfc_dev_dbg(&dev->interface->dev, "%s - modulation=%d", __func__,
  1121. dev->poll_mod_curr);
  1122. if (tg != 1)
  1123. return -EPROTO;
  1124. memset(&nfc_tgt, 0, sizeof(struct nfc_target));
  1125. switch (dev->poll_mod_curr) {
  1126. case PN533_POLL_MOD_106KBPS_A:
  1127. rc = pn533_target_found_type_a(&nfc_tgt, tgdata, tgdata_len);
  1128. break;
  1129. case PN533_POLL_MOD_212KBPS_FELICA:
  1130. case PN533_POLL_MOD_424KBPS_FELICA:
  1131. rc = pn533_target_found_felica(&nfc_tgt, tgdata, tgdata_len);
  1132. break;
  1133. case PN533_POLL_MOD_106KBPS_JEWEL:
  1134. rc = pn533_target_found_jewel(&nfc_tgt, tgdata, tgdata_len);
  1135. break;
  1136. case PN533_POLL_MOD_847KBPS_B:
  1137. rc = pn533_target_found_type_b(&nfc_tgt, tgdata, tgdata_len);
  1138. break;
  1139. default:
  1140. nfc_dev_err(&dev->interface->dev,
  1141. "Unknown current poll modulation");
  1142. return -EPROTO;
  1143. }
  1144. if (rc)
  1145. return rc;
  1146. if (!(nfc_tgt.supported_protocols & dev->poll_protocols)) {
  1147. nfc_dev_dbg(&dev->interface->dev,
  1148. "The Tg found doesn't have the desired protocol");
  1149. return -EAGAIN;
  1150. }
  1151. nfc_dev_dbg(&dev->interface->dev,
  1152. "Target found - supported protocols: 0x%x",
  1153. nfc_tgt.supported_protocols);
  1154. dev->tgt_available_prots = nfc_tgt.supported_protocols;
  1155. nfc_targets_found(dev->nfc_dev, &nfc_tgt, 1);
  1156. return 0;
  1157. }
  1158. static inline void pn533_poll_next_mod(struct pn533 *dev)
  1159. {
  1160. dev->poll_mod_curr = (dev->poll_mod_curr + 1) % dev->poll_mod_count;
  1161. }
  1162. static void pn533_poll_reset_mod_list(struct pn533 *dev)
  1163. {
  1164. dev->poll_mod_count = 0;
  1165. }
  1166. static void pn533_poll_add_mod(struct pn533 *dev, u8 mod_index)
  1167. {
  1168. dev->poll_mod_active[dev->poll_mod_count] =
  1169. (struct pn533_poll_modulations *)&poll_mod[mod_index];
  1170. dev->poll_mod_count++;
  1171. }
  1172. static void pn533_poll_create_mod_list(struct pn533 *dev,
  1173. u32 im_protocols, u32 tm_protocols)
  1174. {
  1175. pn533_poll_reset_mod_list(dev);
  1176. if ((im_protocols & NFC_PROTO_MIFARE_MASK) ||
  1177. (im_protocols & NFC_PROTO_ISO14443_MASK) ||
  1178. (im_protocols & NFC_PROTO_NFC_DEP_MASK))
  1179. pn533_poll_add_mod(dev, PN533_POLL_MOD_106KBPS_A);
  1180. if (im_protocols & NFC_PROTO_FELICA_MASK ||
  1181. im_protocols & NFC_PROTO_NFC_DEP_MASK) {
  1182. pn533_poll_add_mod(dev, PN533_POLL_MOD_212KBPS_FELICA);
  1183. pn533_poll_add_mod(dev, PN533_POLL_MOD_424KBPS_FELICA);
  1184. }
  1185. if (im_protocols & NFC_PROTO_JEWEL_MASK)
  1186. pn533_poll_add_mod(dev, PN533_POLL_MOD_106KBPS_JEWEL);
  1187. if (im_protocols & NFC_PROTO_ISO14443_B_MASK)
  1188. pn533_poll_add_mod(dev, PN533_POLL_MOD_847KBPS_B);
  1189. if (tm_protocols)
  1190. pn533_poll_add_mod(dev, PN533_LISTEN_MOD);
  1191. }
  1192. static int pn533_start_poll_complete(struct pn533 *dev, struct sk_buff *resp)
  1193. {
  1194. u8 nbtg, tg, *tgdata;
  1195. int rc, tgdata_len;
  1196. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1197. nbtg = resp->data[0];
  1198. tg = resp->data[1];
  1199. tgdata = &resp->data[2];
  1200. tgdata_len = resp->len - 2; /* nbtg + tg */
  1201. if (nbtg) {
  1202. rc = pn533_target_found(dev, tg, tgdata, tgdata_len);
  1203. /* We must stop the poll after a valid target found */
  1204. if (rc == 0) {
  1205. pn533_poll_reset_mod_list(dev);
  1206. return 0;
  1207. }
  1208. }
  1209. return -EAGAIN;
  1210. }
  1211. static struct sk_buff *pn533_alloc_poll_tg_frame(struct pn533 *dev)
  1212. {
  1213. struct sk_buff *skb;
  1214. u8 *felica, *nfcid3, *gb;
  1215. u8 *gbytes = dev->gb;
  1216. size_t gbytes_len = dev->gb_len;
  1217. u8 felica_params[18] = {0x1, 0xfe, /* DEP */
  1218. 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, /* random */
  1219. 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0,
  1220. 0xff, 0xff}; /* System code */
  1221. u8 mifare_params[6] = {0x1, 0x1, /* SENS_RES */
  1222. 0x0, 0x0, 0x0,
  1223. 0x40}; /* SEL_RES for DEP */
  1224. unsigned int skb_len = 36 + /* mode (1), mifare (6),
  1225. felica (18), nfcid3 (10), gb_len (1) */
  1226. gbytes_len +
  1227. 1; /* len Tk*/
  1228. skb = pn533_alloc_skb(dev, skb_len);
  1229. if (!skb)
  1230. return NULL;
  1231. /* DEP support only */
  1232. *skb_put(skb, 1) = PN533_INIT_TARGET_DEP;
  1233. /* MIFARE params */
  1234. memcpy(skb_put(skb, 6), mifare_params, 6);
  1235. /* Felica params */
  1236. felica = skb_put(skb, 18);
  1237. memcpy(felica, felica_params, 18);
  1238. get_random_bytes(felica + 2, 6);
  1239. /* NFCID3 */
  1240. nfcid3 = skb_put(skb, 10);
  1241. memset(nfcid3, 0, 10);
  1242. memcpy(nfcid3, felica, 8);
  1243. /* General bytes */
  1244. *skb_put(skb, 1) = gbytes_len;
  1245. gb = skb_put(skb, gbytes_len);
  1246. memcpy(gb, gbytes, gbytes_len);
  1247. /* Len Tk */
  1248. *skb_put(skb, 1) = 0;
  1249. return skb;
  1250. }
  1251. #define PN533_CMD_DATAEXCH_HEAD_LEN 1
  1252. #define PN533_CMD_DATAEXCH_DATA_MAXLEN 262
  1253. static int pn533_tm_get_data_complete(struct pn533 *dev, void *arg,
  1254. struct sk_buff *resp)
  1255. {
  1256. u8 status;
  1257. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1258. if (IS_ERR(resp))
  1259. return PTR_ERR(resp);
  1260. status = resp->data[0];
  1261. skb_pull(resp, sizeof(status));
  1262. if (status != 0) {
  1263. nfc_tm_deactivated(dev->nfc_dev);
  1264. dev->tgt_mode = 0;
  1265. dev_kfree_skb(resp);
  1266. return 0;
  1267. }
  1268. return nfc_tm_data_received(dev->nfc_dev, resp);
  1269. }
  1270. static void pn533_wq_tg_get_data(struct work_struct *work)
  1271. {
  1272. struct pn533 *dev = container_of(work, struct pn533, tg_work);
  1273. struct sk_buff *skb;
  1274. int rc;
  1275. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1276. skb = pn533_alloc_skb(dev, 0);
  1277. if (!skb)
  1278. return;
  1279. rc = pn533_send_data_async(dev, PN533_CMD_TG_GET_DATA, skb,
  1280. pn533_tm_get_data_complete, NULL);
  1281. if (rc < 0)
  1282. dev_kfree_skb(skb);
  1283. return;
  1284. }
  1285. #define ATR_REQ_GB_OFFSET 17
  1286. static int pn533_init_target_complete(struct pn533 *dev, struct sk_buff *resp)
  1287. {
  1288. u8 mode, *cmd, comm_mode = NFC_COMM_PASSIVE, *gb;
  1289. size_t gb_len;
  1290. int rc;
  1291. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1292. if (resp->len < ATR_REQ_GB_OFFSET + 1)
  1293. return -EINVAL;
  1294. mode = resp->data[0];
  1295. cmd = &resp->data[1];
  1296. nfc_dev_dbg(&dev->interface->dev, "Target mode 0x%x len %d\n",
  1297. mode, resp->len);
  1298. if ((mode & PN533_INIT_TARGET_RESP_FRAME_MASK) ==
  1299. PN533_INIT_TARGET_RESP_ACTIVE)
  1300. comm_mode = NFC_COMM_ACTIVE;
  1301. if ((mode & PN533_INIT_TARGET_RESP_DEP) == 0) /* Only DEP supported */
  1302. return -EOPNOTSUPP;
  1303. gb = cmd + ATR_REQ_GB_OFFSET;
  1304. gb_len = resp->len - (ATR_REQ_GB_OFFSET + 1);
  1305. rc = nfc_tm_activated(dev->nfc_dev, NFC_PROTO_NFC_DEP_MASK,
  1306. comm_mode, gb, gb_len);
  1307. if (rc < 0) {
  1308. nfc_dev_err(&dev->interface->dev,
  1309. "Error when signaling target activation");
  1310. return rc;
  1311. }
  1312. dev->tgt_mode = 1;
  1313. queue_work(dev->wq, &dev->tg_work);
  1314. return 0;
  1315. }
  1316. static void pn533_listen_mode_timer(unsigned long data)
  1317. {
  1318. struct pn533 *dev = (struct pn533 *)data;
  1319. nfc_dev_dbg(&dev->interface->dev, "Listen mode timeout");
  1320. dev->cancel_listen = 1;
  1321. pn533_poll_next_mod(dev);
  1322. queue_work(dev->wq, &dev->poll_work);
  1323. }
  1324. static int pn533_rf_complete(struct pn533 *dev, void *arg,
  1325. struct sk_buff *resp)
  1326. {
  1327. int rc = 0;
  1328. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1329. if (IS_ERR(resp)) {
  1330. rc = PTR_ERR(resp);
  1331. nfc_dev_err(&dev->interface->dev, "%s RF setting error %d",
  1332. __func__, rc);
  1333. return rc;
  1334. }
  1335. queue_work(dev->wq, &dev->poll_work);
  1336. dev_kfree_skb(resp);
  1337. return rc;
  1338. }
  1339. static void pn533_wq_rf(struct work_struct *work)
  1340. {
  1341. struct pn533 *dev = container_of(work, struct pn533, rf_work);
  1342. struct sk_buff *skb;
  1343. int rc;
  1344. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1345. skb = pn533_alloc_skb(dev, 2);
  1346. if (!skb)
  1347. return;
  1348. *skb_put(skb, 1) = PN533_CFGITEM_RF_FIELD;
  1349. *skb_put(skb, 1) = 0;
  1350. rc = pn533_send_cmd_async(dev, PN533_CMD_RF_CONFIGURATION, skb,
  1351. pn533_rf_complete, NULL);
  1352. if (rc < 0) {
  1353. dev_kfree_skb(skb);
  1354. nfc_dev_err(&dev->interface->dev, "RF setting error %d", rc);
  1355. }
  1356. return;
  1357. }
  1358. static int pn533_poll_complete(struct pn533 *dev, void *arg,
  1359. struct sk_buff *resp)
  1360. {
  1361. struct pn533_poll_modulations *cur_mod;
  1362. int rc;
  1363. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1364. if (IS_ERR(resp)) {
  1365. rc = PTR_ERR(resp);
  1366. nfc_dev_err(&dev->interface->dev, "%s Poll complete error %d",
  1367. __func__, rc);
  1368. if (rc == -ENOENT) {
  1369. if (dev->poll_mod_count != 0)
  1370. return rc;
  1371. else
  1372. goto stop_poll;
  1373. } else if (rc < 0) {
  1374. nfc_dev_err(&dev->interface->dev,
  1375. "Error %d when running poll", rc);
  1376. goto stop_poll;
  1377. }
  1378. }
  1379. cur_mod = dev->poll_mod_active[dev->poll_mod_curr];
  1380. if (cur_mod->len == 0) { /* Target mode */
  1381. del_timer(&dev->listen_timer);
  1382. rc = pn533_init_target_complete(dev, resp);
  1383. goto done;
  1384. }
  1385. /* Initiator mode */
  1386. rc = pn533_start_poll_complete(dev, resp);
  1387. if (!rc)
  1388. goto done;
  1389. if (!dev->poll_mod_count) {
  1390. nfc_dev_dbg(&dev->interface->dev, "Polling has been stopped.");
  1391. goto done;
  1392. }
  1393. pn533_poll_next_mod(dev);
  1394. /* Not target found, turn radio off */
  1395. queue_work(dev->wq, &dev->rf_work);
  1396. done:
  1397. dev_kfree_skb(resp);
  1398. return rc;
  1399. stop_poll:
  1400. nfc_dev_err(&dev->interface->dev, "Polling operation has been stopped");
  1401. pn533_poll_reset_mod_list(dev);
  1402. dev->poll_protocols = 0;
  1403. return rc;
  1404. }
  1405. static struct sk_buff *pn533_alloc_poll_in_frame(struct pn533 *dev,
  1406. struct pn533_poll_modulations *mod)
  1407. {
  1408. struct sk_buff *skb;
  1409. skb = pn533_alloc_skb(dev, mod->len);
  1410. if (!skb)
  1411. return NULL;
  1412. memcpy(skb_put(skb, mod->len), &mod->data, mod->len);
  1413. return skb;
  1414. }
  1415. static int pn533_send_poll_frame(struct pn533 *dev)
  1416. {
  1417. struct pn533_poll_modulations *mod;
  1418. struct sk_buff *skb;
  1419. int rc;
  1420. u8 cmd_code;
  1421. mod = dev->poll_mod_active[dev->poll_mod_curr];
  1422. nfc_dev_dbg(&dev->interface->dev, "%s mod len %d\n",
  1423. __func__, mod->len);
  1424. if (mod->len == 0) { /* Listen mode */
  1425. cmd_code = PN533_CMD_TG_INIT_AS_TARGET;
  1426. skb = pn533_alloc_poll_tg_frame(dev);
  1427. } else { /* Polling mode */
  1428. cmd_code = PN533_CMD_IN_LIST_PASSIVE_TARGET;
  1429. skb = pn533_alloc_poll_in_frame(dev, mod);
  1430. }
  1431. if (!skb) {
  1432. nfc_dev_err(&dev->interface->dev, "Failed to allocate skb.");
  1433. return -ENOMEM;
  1434. }
  1435. rc = pn533_send_cmd_async(dev, cmd_code, skb, pn533_poll_complete,
  1436. NULL);
  1437. if (rc < 0) {
  1438. dev_kfree_skb(skb);
  1439. nfc_dev_err(&dev->interface->dev, "Polling loop error %d", rc);
  1440. }
  1441. return rc;
  1442. }
  1443. static void pn533_wq_poll(struct work_struct *work)
  1444. {
  1445. struct pn533 *dev = container_of(work, struct pn533, poll_work);
  1446. struct pn533_poll_modulations *cur_mod;
  1447. int rc;
  1448. cur_mod = dev->poll_mod_active[dev->poll_mod_curr];
  1449. nfc_dev_dbg(&dev->interface->dev,
  1450. "%s cancel_listen %d modulation len %d",
  1451. __func__, dev->cancel_listen, cur_mod->len);
  1452. if (dev->cancel_listen == 1) {
  1453. dev->cancel_listen = 0;
  1454. pn533_abort_cmd(dev, GFP_ATOMIC);
  1455. }
  1456. rc = pn533_send_poll_frame(dev);
  1457. if (rc)
  1458. return;
  1459. if (cur_mod->len == 0 && dev->poll_mod_count > 1)
  1460. mod_timer(&dev->listen_timer, jiffies + PN533_LISTEN_TIME * HZ);
  1461. return;
  1462. }
  1463. static int pn533_start_poll(struct nfc_dev *nfc_dev,
  1464. u32 im_protocols, u32 tm_protocols)
  1465. {
  1466. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1467. nfc_dev_dbg(&dev->interface->dev,
  1468. "%s: im protocols 0x%x tm protocols 0x%x",
  1469. __func__, im_protocols, tm_protocols);
  1470. if (dev->tgt_active_prot) {
  1471. nfc_dev_err(&dev->interface->dev,
  1472. "Cannot poll with a target already activated");
  1473. return -EBUSY;
  1474. }
  1475. if (dev->tgt_mode) {
  1476. nfc_dev_err(&dev->interface->dev,
  1477. "Cannot poll while already being activated");
  1478. return -EBUSY;
  1479. }
  1480. if (tm_protocols) {
  1481. dev->gb = nfc_get_local_general_bytes(nfc_dev, &dev->gb_len);
  1482. if (dev->gb == NULL)
  1483. tm_protocols = 0;
  1484. }
  1485. dev->poll_mod_curr = 0;
  1486. pn533_poll_create_mod_list(dev, im_protocols, tm_protocols);
  1487. dev->poll_protocols = im_protocols;
  1488. dev->listen_protocols = tm_protocols;
  1489. return pn533_send_poll_frame(dev);
  1490. }
  1491. static void pn533_stop_poll(struct nfc_dev *nfc_dev)
  1492. {
  1493. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1494. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1495. del_timer(&dev->listen_timer);
  1496. if (!dev->poll_mod_count) {
  1497. nfc_dev_dbg(&dev->interface->dev,
  1498. "Polling operation was not running");
  1499. return;
  1500. }
  1501. pn533_abort_cmd(dev, GFP_KERNEL);
  1502. pn533_poll_reset_mod_list(dev);
  1503. }
  1504. static int pn533_activate_target_nfcdep(struct pn533 *dev)
  1505. {
  1506. struct pn533_cmd_activate_response *rsp;
  1507. u16 gt_len;
  1508. int rc;
  1509. struct sk_buff *skb;
  1510. struct sk_buff *resp;
  1511. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1512. skb = pn533_alloc_skb(dev, sizeof(u8) * 2); /*TG + Next*/
  1513. if (!skb)
  1514. return -ENOMEM;
  1515. *skb_put(skb, sizeof(u8)) = 1; /* TG */
  1516. *skb_put(skb, sizeof(u8)) = 0; /* Next */
  1517. resp = pn533_send_cmd_sync(dev, PN533_CMD_IN_ATR, skb);
  1518. if (IS_ERR(resp))
  1519. return PTR_ERR(resp);
  1520. rsp = (struct pn533_cmd_activate_response *)resp->data;
  1521. rc = rsp->status & PN533_CMD_RET_MASK;
  1522. if (rc != PN533_CMD_RET_SUCCESS) {
  1523. nfc_dev_err(&dev->interface->dev,
  1524. "Target activation failed (error 0x%x)", rc);
  1525. dev_kfree_skb(resp);
  1526. return -EIO;
  1527. }
  1528. /* ATR_RES general bytes are located at offset 16 */
  1529. gt_len = resp->len - 16;
  1530. rc = nfc_set_remote_general_bytes(dev->nfc_dev, rsp->gt, gt_len);
  1531. dev_kfree_skb(resp);
  1532. return rc;
  1533. }
  1534. static int pn533_activate_target(struct nfc_dev *nfc_dev,
  1535. struct nfc_target *target, u32 protocol)
  1536. {
  1537. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1538. int rc;
  1539. nfc_dev_dbg(&dev->interface->dev, "%s - protocol=%u", __func__,
  1540. protocol);
  1541. if (dev->poll_mod_count) {
  1542. nfc_dev_err(&dev->interface->dev,
  1543. "Cannot activate while polling");
  1544. return -EBUSY;
  1545. }
  1546. if (dev->tgt_active_prot) {
  1547. nfc_dev_err(&dev->interface->dev,
  1548. "There is already an active target");
  1549. return -EBUSY;
  1550. }
  1551. if (!dev->tgt_available_prots) {
  1552. nfc_dev_err(&dev->interface->dev,
  1553. "There is no available target to activate");
  1554. return -EINVAL;
  1555. }
  1556. if (!(dev->tgt_available_prots & (1 << protocol))) {
  1557. nfc_dev_err(&dev->interface->dev,
  1558. "Target doesn't support requested proto %u",
  1559. protocol);
  1560. return -EINVAL;
  1561. }
  1562. if (protocol == NFC_PROTO_NFC_DEP) {
  1563. rc = pn533_activate_target_nfcdep(dev);
  1564. if (rc) {
  1565. nfc_dev_err(&dev->interface->dev,
  1566. "Activating target with DEP failed %d", rc);
  1567. return rc;
  1568. }
  1569. }
  1570. dev->tgt_active_prot = protocol;
  1571. dev->tgt_available_prots = 0;
  1572. return 0;
  1573. }
  1574. static void pn533_deactivate_target(struct nfc_dev *nfc_dev,
  1575. struct nfc_target *target)
  1576. {
  1577. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1578. struct sk_buff *skb;
  1579. struct sk_buff *resp;
  1580. int rc;
  1581. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1582. if (!dev->tgt_active_prot) {
  1583. nfc_dev_err(&dev->interface->dev, "There is no active target");
  1584. return;
  1585. }
  1586. dev->tgt_active_prot = 0;
  1587. skb_queue_purge(&dev->resp_q);
  1588. skb = pn533_alloc_skb(dev, sizeof(u8));
  1589. if (!skb)
  1590. return;
  1591. *skb_put(skb, 1) = 1; /* TG*/
  1592. resp = pn533_send_cmd_sync(dev, PN533_CMD_IN_RELEASE, skb);
  1593. if (IS_ERR(resp))
  1594. return;
  1595. rc = resp->data[0] & PN533_CMD_RET_MASK;
  1596. if (rc != PN533_CMD_RET_SUCCESS)
  1597. nfc_dev_err(&dev->interface->dev,
  1598. "Error 0x%x when releasing the target", rc);
  1599. dev_kfree_skb(resp);
  1600. return;
  1601. }
  1602. static int pn533_in_dep_link_up_complete(struct pn533 *dev, void *arg,
  1603. struct sk_buff *resp)
  1604. {
  1605. struct pn533_cmd_jump_dep_response *rsp;
  1606. u8 target_gt_len;
  1607. int rc;
  1608. u8 active = *(u8 *)arg;
  1609. kfree(arg);
  1610. if (IS_ERR(resp))
  1611. return PTR_ERR(resp);
  1612. if (dev->tgt_available_prots &&
  1613. !(dev->tgt_available_prots & (1 << NFC_PROTO_NFC_DEP))) {
  1614. nfc_dev_err(&dev->interface->dev,
  1615. "The target does not support DEP");
  1616. rc = -EINVAL;
  1617. goto error;
  1618. }
  1619. rsp = (struct pn533_cmd_jump_dep_response *)resp->data;
  1620. rc = rsp->status & PN533_CMD_RET_MASK;
  1621. if (rc != PN533_CMD_RET_SUCCESS) {
  1622. nfc_dev_err(&dev->interface->dev,
  1623. "Bringing DEP link up failed (error 0x%x)", rc);
  1624. goto error;
  1625. }
  1626. if (!dev->tgt_available_prots) {
  1627. struct nfc_target nfc_target;
  1628. nfc_dev_dbg(&dev->interface->dev, "Creating new target");
  1629. nfc_target.supported_protocols = NFC_PROTO_NFC_DEP_MASK;
  1630. nfc_target.nfcid1_len = 10;
  1631. memcpy(nfc_target.nfcid1, rsp->nfcid3t, nfc_target.nfcid1_len);
  1632. rc = nfc_targets_found(dev->nfc_dev, &nfc_target, 1);
  1633. if (rc)
  1634. goto error;
  1635. dev->tgt_available_prots = 0;
  1636. }
  1637. dev->tgt_active_prot = NFC_PROTO_NFC_DEP;
  1638. /* ATR_RES general bytes are located at offset 17 */
  1639. target_gt_len = resp->len - 17;
  1640. rc = nfc_set_remote_general_bytes(dev->nfc_dev,
  1641. rsp->gt, target_gt_len);
  1642. if (rc == 0)
  1643. rc = nfc_dep_link_is_up(dev->nfc_dev,
  1644. dev->nfc_dev->targets[0].idx,
  1645. !active, NFC_RF_INITIATOR);
  1646. error:
  1647. dev_kfree_skb(resp);
  1648. return rc;
  1649. }
  1650. static int pn533_rf_field(struct nfc_dev *nfc_dev, u8 rf);
  1651. #define PASSIVE_DATA_LEN 5
  1652. static int pn533_dep_link_up(struct nfc_dev *nfc_dev, struct nfc_target *target,
  1653. u8 comm_mode, u8 *gb, size_t gb_len)
  1654. {
  1655. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1656. struct sk_buff *skb;
  1657. int rc, skb_len;
  1658. u8 *next, *arg, nfcid3[NFC_NFCID3_MAXSIZE];
  1659. u8 passive_data[PASSIVE_DATA_LEN] = {0x00, 0xff, 0xff, 0x00, 0x3};
  1660. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1661. if (dev->poll_mod_count) {
  1662. nfc_dev_err(&dev->interface->dev,
  1663. "Cannot bring the DEP link up while polling");
  1664. return -EBUSY;
  1665. }
  1666. if (dev->tgt_active_prot) {
  1667. nfc_dev_err(&dev->interface->dev,
  1668. "There is already an active target");
  1669. return -EBUSY;
  1670. }
  1671. skb_len = 3 + gb_len; /* ActPass + BR + Next */
  1672. skb_len += PASSIVE_DATA_LEN;
  1673. /* NFCID3 */
  1674. skb_len += NFC_NFCID3_MAXSIZE;
  1675. if (target && !target->nfcid2_len) {
  1676. nfcid3[0] = 0x1;
  1677. nfcid3[1] = 0xfe;
  1678. get_random_bytes(nfcid3 + 2, 6);
  1679. }
  1680. skb = pn533_alloc_skb(dev, skb_len);
  1681. if (!skb)
  1682. return -ENOMEM;
  1683. *skb_put(skb, 1) = !comm_mode; /* ActPass */
  1684. *skb_put(skb, 1) = 0x02; /* 424 kbps */
  1685. next = skb_put(skb, 1); /* Next */
  1686. *next = 0;
  1687. /* Copy passive data */
  1688. memcpy(skb_put(skb, PASSIVE_DATA_LEN), passive_data, PASSIVE_DATA_LEN);
  1689. *next |= 1;
  1690. /* Copy NFCID3 (which is NFCID2 from SENSF_RES) */
  1691. if (target && target->nfcid2_len)
  1692. memcpy(skb_put(skb, NFC_NFCID3_MAXSIZE), target->nfcid2,
  1693. target->nfcid2_len);
  1694. else
  1695. memcpy(skb_put(skb, NFC_NFCID3_MAXSIZE), nfcid3,
  1696. NFC_NFCID3_MAXSIZE);
  1697. *next |= 2;
  1698. if (gb != NULL && gb_len > 0) {
  1699. memcpy(skb_put(skb, gb_len), gb, gb_len);
  1700. *next |= 4; /* We have some Gi */
  1701. } else {
  1702. *next = 0;
  1703. }
  1704. arg = kmalloc(sizeof(*arg), GFP_KERNEL);
  1705. if (!arg) {
  1706. dev_kfree_skb(skb);
  1707. return -ENOMEM;
  1708. }
  1709. *arg = !comm_mode;
  1710. pn533_rf_field(dev->nfc_dev, 0);
  1711. rc = pn533_send_cmd_async(dev, PN533_CMD_IN_JUMP_FOR_DEP, skb,
  1712. pn533_in_dep_link_up_complete, arg);
  1713. if (rc < 0) {
  1714. dev_kfree_skb(skb);
  1715. kfree(arg);
  1716. }
  1717. return rc;
  1718. }
  1719. static int pn533_dep_link_down(struct nfc_dev *nfc_dev)
  1720. {
  1721. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1722. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1723. pn533_poll_reset_mod_list(dev);
  1724. if (dev->tgt_mode || dev->tgt_active_prot)
  1725. pn533_abort_cmd(dev, GFP_KERNEL);
  1726. dev->tgt_active_prot = 0;
  1727. dev->tgt_mode = 0;
  1728. skb_queue_purge(&dev->resp_q);
  1729. return 0;
  1730. }
  1731. struct pn533_data_exchange_arg {
  1732. data_exchange_cb_t cb;
  1733. void *cb_context;
  1734. };
  1735. static struct sk_buff *pn533_build_response(struct pn533 *dev)
  1736. {
  1737. struct sk_buff *skb, *tmp, *t;
  1738. unsigned int skb_len = 0, tmp_len = 0;
  1739. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1740. if (skb_queue_empty(&dev->resp_q))
  1741. return NULL;
  1742. if (skb_queue_len(&dev->resp_q) == 1) {
  1743. skb = skb_dequeue(&dev->resp_q);
  1744. goto out;
  1745. }
  1746. skb_queue_walk_safe(&dev->resp_q, tmp, t)
  1747. skb_len += tmp->len;
  1748. nfc_dev_dbg(&dev->interface->dev, "%s total length %d\n",
  1749. __func__, skb_len);
  1750. skb = alloc_skb(skb_len, GFP_KERNEL);
  1751. if (skb == NULL)
  1752. goto out;
  1753. skb_put(skb, skb_len);
  1754. skb_queue_walk_safe(&dev->resp_q, tmp, t) {
  1755. memcpy(skb->data + tmp_len, tmp->data, tmp->len);
  1756. tmp_len += tmp->len;
  1757. }
  1758. out:
  1759. skb_queue_purge(&dev->resp_q);
  1760. return skb;
  1761. }
  1762. static int pn533_data_exchange_complete(struct pn533 *dev, void *_arg,
  1763. struct sk_buff *resp)
  1764. {
  1765. struct pn533_data_exchange_arg *arg = _arg;
  1766. struct sk_buff *skb;
  1767. int rc = 0;
  1768. u8 status, ret, mi;
  1769. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1770. if (IS_ERR(resp)) {
  1771. rc = PTR_ERR(resp);
  1772. goto _error;
  1773. }
  1774. status = resp->data[0];
  1775. ret = status & PN533_CMD_RET_MASK;
  1776. mi = status & PN533_CMD_MI_MASK;
  1777. skb_pull(resp, sizeof(status));
  1778. if (ret != PN533_CMD_RET_SUCCESS) {
  1779. nfc_dev_err(&dev->interface->dev,
  1780. "Exchanging data failed (error 0x%x)", ret);
  1781. rc = -EIO;
  1782. goto error;
  1783. }
  1784. skb_queue_tail(&dev->resp_q, resp);
  1785. if (mi) {
  1786. dev->cmd_complete_mi_arg = arg;
  1787. queue_work(dev->wq, &dev->mi_work);
  1788. return -EINPROGRESS;
  1789. }
  1790. skb = pn533_build_response(dev);
  1791. if (!skb)
  1792. goto error;
  1793. arg->cb(arg->cb_context, skb, 0);
  1794. kfree(arg);
  1795. return 0;
  1796. error:
  1797. dev_kfree_skb(resp);
  1798. _error:
  1799. skb_queue_purge(&dev->resp_q);
  1800. arg->cb(arg->cb_context, NULL, rc);
  1801. kfree(arg);
  1802. return rc;
  1803. }
  1804. static int pn533_transceive(struct nfc_dev *nfc_dev,
  1805. struct nfc_target *target, struct sk_buff *skb,
  1806. data_exchange_cb_t cb, void *cb_context)
  1807. {
  1808. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1809. struct pn533_data_exchange_arg *arg = NULL;
  1810. int rc;
  1811. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1812. if (skb->len > PN533_CMD_DATAEXCH_DATA_MAXLEN) {
  1813. /* TODO: Implement support to multi-part data exchange */
  1814. nfc_dev_err(&dev->interface->dev,
  1815. "Data length greater than the max allowed: %d",
  1816. PN533_CMD_DATAEXCH_DATA_MAXLEN);
  1817. rc = -ENOSYS;
  1818. goto error;
  1819. }
  1820. if (!dev->tgt_active_prot) {
  1821. nfc_dev_err(&dev->interface->dev,
  1822. "Can't exchange data if there is no active target");
  1823. rc = -EINVAL;
  1824. goto error;
  1825. }
  1826. arg = kmalloc(sizeof(*arg), GFP_KERNEL);
  1827. if (!arg) {
  1828. rc = -ENOMEM;
  1829. goto error;
  1830. }
  1831. arg->cb = cb;
  1832. arg->cb_context = cb_context;
  1833. switch (dev->device_type) {
  1834. case PN533_DEVICE_PASORI:
  1835. if (dev->tgt_active_prot == NFC_PROTO_FELICA) {
  1836. rc = pn533_send_data_async(dev, PN533_CMD_IN_COMM_THRU,
  1837. skb,
  1838. pn533_data_exchange_complete,
  1839. arg);
  1840. break;
  1841. }
  1842. default:
  1843. *skb_push(skb, sizeof(u8)) = 1; /*TG*/
  1844. rc = pn533_send_data_async(dev, PN533_CMD_IN_DATA_EXCHANGE,
  1845. skb, pn533_data_exchange_complete,
  1846. arg);
  1847. break;
  1848. }
  1849. if (rc < 0) /* rc from send_async */
  1850. goto error;
  1851. return 0;
  1852. error:
  1853. kfree(arg);
  1854. dev_kfree_skb(skb);
  1855. return rc;
  1856. }
  1857. static int pn533_tm_send_complete(struct pn533 *dev, void *arg,
  1858. struct sk_buff *resp)
  1859. {
  1860. u8 status;
  1861. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1862. if (IS_ERR(resp))
  1863. return PTR_ERR(resp);
  1864. status = resp->data[0];
  1865. dev_kfree_skb(resp);
  1866. if (status != 0) {
  1867. nfc_tm_deactivated(dev->nfc_dev);
  1868. dev->tgt_mode = 0;
  1869. return 0;
  1870. }
  1871. queue_work(dev->wq, &dev->tg_work);
  1872. return 0;
  1873. }
  1874. static int pn533_tm_send(struct nfc_dev *nfc_dev, struct sk_buff *skb)
  1875. {
  1876. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  1877. int rc;
  1878. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1879. if (skb->len > PN533_CMD_DATAEXCH_DATA_MAXLEN) {
  1880. nfc_dev_err(&dev->interface->dev,
  1881. "Data length greater than the max allowed: %d",
  1882. PN533_CMD_DATAEXCH_DATA_MAXLEN);
  1883. return -ENOSYS;
  1884. }
  1885. rc = pn533_send_data_async(dev, PN533_CMD_TG_SET_DATA, skb,
  1886. pn533_tm_send_complete, NULL);
  1887. if (rc < 0)
  1888. dev_kfree_skb(skb);
  1889. return rc;
  1890. }
  1891. static void pn533_wq_mi_recv(struct work_struct *work)
  1892. {
  1893. struct pn533 *dev = container_of(work, struct pn533, mi_work);
  1894. struct sk_buff *skb;
  1895. int rc;
  1896. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1897. skb = pn533_alloc_skb(dev, PN533_CMD_DATAEXCH_HEAD_LEN);
  1898. if (!skb)
  1899. goto error;
  1900. switch (dev->device_type) {
  1901. case PN533_DEVICE_PASORI:
  1902. if (dev->tgt_active_prot == NFC_PROTO_FELICA) {
  1903. rc = pn533_send_cmd_direct_async(dev,
  1904. PN533_CMD_IN_COMM_THRU,
  1905. skb,
  1906. pn533_data_exchange_complete,
  1907. dev->cmd_complete_mi_arg);
  1908. break;
  1909. }
  1910. default:
  1911. *skb_put(skb, sizeof(u8)) = 1; /*TG*/
  1912. rc = pn533_send_cmd_direct_async(dev,
  1913. PN533_CMD_IN_DATA_EXCHANGE,
  1914. skb,
  1915. pn533_data_exchange_complete,
  1916. dev->cmd_complete_mi_arg);
  1917. break;
  1918. }
  1919. if (rc == 0) /* success */
  1920. return;
  1921. nfc_dev_err(&dev->interface->dev,
  1922. "Error %d when trying to perform data_exchange", rc);
  1923. dev_kfree_skb(skb);
  1924. kfree(dev->cmd_complete_mi_arg);
  1925. error:
  1926. pn533_send_ack(dev, GFP_KERNEL);
  1927. queue_work(dev->wq, &dev->cmd_work);
  1928. }
  1929. static int pn533_set_configuration(struct pn533 *dev, u8 cfgitem, u8 *cfgdata,
  1930. u8 cfgdata_len)
  1931. {
  1932. struct sk_buff *skb;
  1933. struct sk_buff *resp;
  1934. int skb_len;
  1935. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1936. skb_len = sizeof(cfgitem) + cfgdata_len; /* cfgitem + cfgdata */
  1937. skb = pn533_alloc_skb(dev, skb_len);
  1938. if (!skb)
  1939. return -ENOMEM;
  1940. *skb_put(skb, sizeof(cfgitem)) = cfgitem;
  1941. memcpy(skb_put(skb, cfgdata_len), cfgdata, cfgdata_len);
  1942. resp = pn533_send_cmd_sync(dev, PN533_CMD_RF_CONFIGURATION, skb);
  1943. if (IS_ERR(resp))
  1944. return PTR_ERR(resp);
  1945. dev_kfree_skb(resp);
  1946. return 0;
  1947. }
  1948. static int pn533_get_firmware_version(struct pn533 *dev,
  1949. struct pn533_fw_version *fv)
  1950. {
  1951. struct sk_buff *skb;
  1952. struct sk_buff *resp;
  1953. skb = pn533_alloc_skb(dev, 0);
  1954. if (!skb)
  1955. return -ENOMEM;
  1956. resp = pn533_send_cmd_sync(dev, PN533_CMD_GET_FIRMWARE_VERSION, skb);
  1957. if (IS_ERR(resp))
  1958. return PTR_ERR(resp);
  1959. fv->ic = resp->data[0];
  1960. fv->ver = resp->data[1];
  1961. fv->rev = resp->data[2];
  1962. fv->support = resp->data[3];
  1963. dev_kfree_skb(resp);
  1964. return 0;
  1965. }
  1966. static int pn533_pasori_fw_reset(struct pn533 *dev)
  1967. {
  1968. struct sk_buff *skb;
  1969. struct sk_buff *resp;
  1970. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  1971. skb = pn533_alloc_skb(dev, sizeof(u8));
  1972. if (!skb)
  1973. return -ENOMEM;
  1974. *skb_put(skb, sizeof(u8)) = 0x1;
  1975. resp = pn533_send_cmd_sync(dev, 0x18, skb);
  1976. if (IS_ERR(resp))
  1977. return PTR_ERR(resp);
  1978. dev_kfree_skb(resp);
  1979. return 0;
  1980. }
  1981. struct pn533_acr122_poweron_rdr_arg {
  1982. int rc;
  1983. struct completion done;
  1984. };
  1985. static void pn533_acr122_poweron_rdr_resp(struct urb *urb)
  1986. {
  1987. struct pn533_acr122_poweron_rdr_arg *arg = urb->context;
  1988. nfc_dev_dbg(&urb->dev->dev, "%s", __func__);
  1989. print_hex_dump_debug("ACR122 RX: ", DUMP_PREFIX_NONE, 16, 1,
  1990. urb->transfer_buffer, urb->transfer_buffer_length,
  1991. false);
  1992. arg->rc = urb->status;
  1993. complete(&arg->done);
  1994. }
  1995. static int pn533_acr122_poweron_rdr(struct pn533 *dev)
  1996. {
  1997. /* Power on th reader (CCID cmd) */
  1998. u8 cmd[10] = {PN533_ACR122_PC_TO_RDR_ICCPOWERON,
  1999. 0, 0, 0, 0, 0, 0, 3, 0, 0};
  2000. u8 buf[255];
  2001. int rc;
  2002. void *cntx;
  2003. struct pn533_acr122_poweron_rdr_arg arg;
  2004. nfc_dev_dbg(&dev->interface->dev, "%s", __func__);
  2005. init_completion(&arg.done);
  2006. cntx = dev->in_urb->context; /* backup context */
  2007. dev->in_urb->transfer_buffer = buf;
  2008. dev->in_urb->transfer_buffer_length = 255;
  2009. dev->in_urb->complete = pn533_acr122_poweron_rdr_resp;
  2010. dev->in_urb->context = &arg;
  2011. dev->out_urb->transfer_buffer = cmd;
  2012. dev->out_urb->transfer_buffer_length = sizeof(cmd);
  2013. print_hex_dump_debug("ACR122 TX: ", DUMP_PREFIX_NONE, 16, 1,
  2014. cmd, sizeof(cmd), false);
  2015. rc = usb_submit_urb(dev->out_urb, GFP_KERNEL);
  2016. if (rc) {
  2017. nfc_dev_err(&dev->interface->dev,
  2018. "Reader power on cmd error %d", rc);
  2019. return rc;
  2020. }
  2021. rc = usb_submit_urb(dev->in_urb, GFP_KERNEL);
  2022. if (rc) {
  2023. nfc_dev_err(&dev->interface->dev,
  2024. "Can't submit for reader power on cmd response %d",
  2025. rc);
  2026. return rc;
  2027. }
  2028. wait_for_completion(&arg.done);
  2029. dev->in_urb->context = cntx; /* restore context */
  2030. return arg.rc;
  2031. }
  2032. static int pn533_rf_field(struct nfc_dev *nfc_dev, u8 rf)
  2033. {
  2034. struct pn533 *dev = nfc_get_drvdata(nfc_dev);
  2035. u8 rf_field = !!rf;
  2036. int rc;
  2037. rc = pn533_set_configuration(dev, PN533_CFGITEM_RF_FIELD,
  2038. (u8 *)&rf_field, 1);
  2039. if (rc) {
  2040. nfc_dev_err(&dev->interface->dev,
  2041. "Error on setting RF field");
  2042. return rc;
  2043. }
  2044. return rc;
  2045. }
  2046. int pn533_dev_up(struct nfc_dev *nfc_dev)
  2047. {
  2048. return pn533_rf_field(nfc_dev, 1);
  2049. }
  2050. int pn533_dev_down(struct nfc_dev *nfc_dev)
  2051. {
  2052. return pn533_rf_field(nfc_dev, 0);
  2053. }
  2054. static struct nfc_ops pn533_nfc_ops = {
  2055. .dev_up = pn533_dev_up,
  2056. .dev_down = pn533_dev_down,
  2057. .dep_link_up = pn533_dep_link_up,
  2058. .dep_link_down = pn533_dep_link_down,
  2059. .start_poll = pn533_start_poll,
  2060. .stop_poll = pn533_stop_poll,
  2061. .activate_target = pn533_activate_target,
  2062. .deactivate_target = pn533_deactivate_target,
  2063. .im_transceive = pn533_transceive,
  2064. .tm_send = pn533_tm_send,
  2065. };
  2066. static int pn533_setup(struct pn533 *dev)
  2067. {
  2068. struct pn533_config_max_retries max_retries;
  2069. struct pn533_config_timing timing;
  2070. u8 pasori_cfg[3] = {0x08, 0x01, 0x08};
  2071. int rc;
  2072. switch (dev->device_type) {
  2073. case PN533_DEVICE_STD:
  2074. case PN533_DEVICE_PASORI:
  2075. case PN533_DEVICE_ACR122U:
  2076. max_retries.mx_rty_atr = 0x2;
  2077. max_retries.mx_rty_psl = 0x1;
  2078. max_retries.mx_rty_passive_act =
  2079. PN533_CONFIG_MAX_RETRIES_NO_RETRY;
  2080. timing.rfu = PN533_CONFIG_TIMING_102;
  2081. timing.atr_res_timeout = PN533_CONFIG_TIMING_102;
  2082. timing.dep_timeout = PN533_CONFIG_TIMING_204;
  2083. break;
  2084. default:
  2085. nfc_dev_err(&dev->interface->dev, "Unknown device type %d\n",
  2086. dev->device_type);
  2087. return -EINVAL;
  2088. }
  2089. rc = pn533_set_configuration(dev, PN533_CFGITEM_MAX_RETRIES,
  2090. (u8 *)&max_retries, sizeof(max_retries));
  2091. if (rc) {
  2092. nfc_dev_err(&dev->interface->dev,
  2093. "Error on setting MAX_RETRIES config");
  2094. return rc;
  2095. }
  2096. rc = pn533_set_configuration(dev, PN533_CFGITEM_TIMING,
  2097. (u8 *)&timing, sizeof(timing));
  2098. if (rc) {
  2099. nfc_dev_err(&dev->interface->dev,
  2100. "Error on setting RF timings");
  2101. return rc;
  2102. }
  2103. switch (dev->device_type) {
  2104. case PN533_DEVICE_STD:
  2105. break;
  2106. case PN533_DEVICE_PASORI:
  2107. pn533_pasori_fw_reset(dev);
  2108. rc = pn533_set_configuration(dev, PN533_CFGITEM_PASORI,
  2109. pasori_cfg, 3);
  2110. if (rc) {
  2111. nfc_dev_err(&dev->interface->dev,
  2112. "Error while settings PASORI config");
  2113. return rc;
  2114. }
  2115. pn533_pasori_fw_reset(dev);
  2116. break;
  2117. }
  2118. return 0;
  2119. }
  2120. static int pn533_probe(struct usb_interface *interface,
  2121. const struct usb_device_id *id)
  2122. {
  2123. struct pn533_fw_version fw_ver;
  2124. struct pn533 *dev;
  2125. struct usb_host_interface *iface_desc;
  2126. struct usb_endpoint_descriptor *endpoint;
  2127. int in_endpoint = 0;
  2128. int out_endpoint = 0;
  2129. int rc = -ENOMEM;
  2130. int i;
  2131. u32 protocols;
  2132. dev = kzalloc(sizeof(*dev), GFP_KERNEL);
  2133. if (!dev)
  2134. return -ENOMEM;
  2135. dev->udev = usb_get_dev(interface_to_usbdev(interface));
  2136. dev->interface = interface;
  2137. mutex_init(&dev->cmd_lock);
  2138. iface_desc = interface->cur_altsetting;
  2139. for (i = 0; i < iface_desc->desc.bNumEndpoints; ++i) {
  2140. endpoint = &iface_desc->endpoint[i].desc;
  2141. if (!in_endpoint && usb_endpoint_is_bulk_in(endpoint))
  2142. in_endpoint = endpoint->bEndpointAddress;
  2143. if (!out_endpoint && usb_endpoint_is_bulk_out(endpoint))
  2144. out_endpoint = endpoint->bEndpointAddress;
  2145. }
  2146. if (!in_endpoint || !out_endpoint) {
  2147. nfc_dev_err(&interface->dev,
  2148. "Could not find bulk-in or bulk-out endpoint");
  2149. rc = -ENODEV;
  2150. goto error;
  2151. }
  2152. dev->in_urb = usb_alloc_urb(0, GFP_KERNEL);
  2153. dev->out_urb = usb_alloc_urb(0, GFP_KERNEL);
  2154. if (!dev->in_urb || !dev->out_urb)
  2155. goto error;
  2156. usb_fill_bulk_urb(dev->in_urb, dev->udev,
  2157. usb_rcvbulkpipe(dev->udev, in_endpoint),
  2158. NULL, 0, NULL, dev);
  2159. usb_fill_bulk_urb(dev->out_urb, dev->udev,
  2160. usb_sndbulkpipe(dev->udev, out_endpoint),
  2161. NULL, 0, pn533_send_complete, dev);
  2162. INIT_WORK(&dev->cmd_work, pn533_wq_cmd);
  2163. INIT_WORK(&dev->cmd_complete_work, pn533_wq_cmd_complete);
  2164. INIT_WORK(&dev->mi_work, pn533_wq_mi_recv);
  2165. INIT_WORK(&dev->tg_work, pn533_wq_tg_get_data);
  2166. INIT_WORK(&dev->poll_work, pn533_wq_poll);
  2167. INIT_WORK(&dev->rf_work, pn533_wq_rf);
  2168. dev->wq = alloc_ordered_workqueue("pn533", 0);
  2169. if (dev->wq == NULL)
  2170. goto error;
  2171. init_timer(&dev->listen_timer);
  2172. dev->listen_timer.data = (unsigned long) dev;
  2173. dev->listen_timer.function = pn533_listen_mode_timer;
  2174. skb_queue_head_init(&dev->resp_q);
  2175. INIT_LIST_HEAD(&dev->cmd_queue);
  2176. usb_set_intfdata(interface, dev);
  2177. dev->ops = &pn533_std_frame_ops;
  2178. dev->protocol_type = PN533_PROTO_REQ_ACK_RESP;
  2179. dev->device_type = id->driver_info;
  2180. switch (dev->device_type) {
  2181. case PN533_DEVICE_STD:
  2182. protocols = PN533_ALL_PROTOCOLS;
  2183. break;
  2184. case PN533_DEVICE_PASORI:
  2185. protocols = PN533_NO_TYPE_B_PROTOCOLS;
  2186. break;
  2187. case PN533_DEVICE_ACR122U:
  2188. protocols = PN533_NO_TYPE_B_PROTOCOLS;
  2189. dev->ops = &pn533_acr122_frame_ops;
  2190. dev->protocol_type = PN533_PROTO_REQ_RESP,
  2191. rc = pn533_acr122_poweron_rdr(dev);
  2192. if (rc < 0) {
  2193. nfc_dev_err(&dev->interface->dev,
  2194. "Couldn't poweron the reader (error %d)",
  2195. rc);
  2196. goto destroy_wq;
  2197. }
  2198. break;
  2199. default:
  2200. nfc_dev_err(&dev->interface->dev, "Unknown device type %d\n",
  2201. dev->device_type);
  2202. rc = -EINVAL;
  2203. goto destroy_wq;
  2204. }
  2205. memset(&fw_ver, 0, sizeof(fw_ver));
  2206. rc = pn533_get_firmware_version(dev, &fw_ver);
  2207. if (rc < 0)
  2208. goto destroy_wq;
  2209. nfc_dev_info(&dev->interface->dev,
  2210. "NXP PN5%02X firmware ver %d.%d now attached",
  2211. fw_ver.ic, fw_ver.ver, fw_ver.rev);
  2212. dev->nfc_dev = nfc_allocate_device(&pn533_nfc_ops, protocols,
  2213. dev->ops->tx_header_len +
  2214. PN533_CMD_DATAEXCH_HEAD_LEN,
  2215. dev->ops->tx_tail_len);
  2216. if (!dev->nfc_dev) {
  2217. rc = -ENOMEM;
  2218. goto destroy_wq;
  2219. }
  2220. nfc_set_parent_dev(dev->nfc_dev, &interface->dev);
  2221. nfc_set_drvdata(dev->nfc_dev, dev);
  2222. rc = nfc_register_device(dev->nfc_dev);
  2223. if (rc)
  2224. goto free_nfc_dev;
  2225. rc = pn533_setup(dev);
  2226. if (rc)
  2227. goto unregister_nfc_dev;
  2228. return 0;
  2229. unregister_nfc_dev:
  2230. nfc_unregister_device(dev->nfc_dev);
  2231. free_nfc_dev:
  2232. nfc_free_device(dev->nfc_dev);
  2233. destroy_wq:
  2234. destroy_workqueue(dev->wq);
  2235. error:
  2236. usb_free_urb(dev->in_urb);
  2237. usb_free_urb(dev->out_urb);
  2238. usb_put_dev(dev->udev);
  2239. kfree(dev);
  2240. return rc;
  2241. }
  2242. static void pn533_disconnect(struct usb_interface *interface)
  2243. {
  2244. struct pn533 *dev;
  2245. struct pn533_cmd *cmd, *n;
  2246. dev = usb_get_intfdata(interface);
  2247. usb_set_intfdata(interface, NULL);
  2248. nfc_unregister_device(dev->nfc_dev);
  2249. nfc_free_device(dev->nfc_dev);
  2250. usb_kill_urb(dev->in_urb);
  2251. usb_kill_urb(dev->out_urb);
  2252. destroy_workqueue(dev->wq);
  2253. skb_queue_purge(&dev->resp_q);
  2254. del_timer(&dev->listen_timer);
  2255. list_for_each_entry_safe(cmd, n, &dev->cmd_queue, queue) {
  2256. list_del(&cmd->queue);
  2257. kfree(cmd);
  2258. }
  2259. usb_free_urb(dev->in_urb);
  2260. usb_free_urb(dev->out_urb);
  2261. kfree(dev);
  2262. nfc_dev_info(&interface->dev, "NXP PN533 NFC device disconnected");
  2263. }
  2264. static struct usb_driver pn533_driver = {
  2265. .name = "pn533",
  2266. .probe = pn533_probe,
  2267. .disconnect = pn533_disconnect,
  2268. .id_table = pn533_table,
  2269. };
  2270. module_usb_driver(pn533_driver);
  2271. MODULE_AUTHOR("Lauro Ramos Venancio <lauro.venancio@openbossa.org>");
  2272. MODULE_AUTHOR("Aloisio Almeida Jr <aloisio.almeida@openbossa.org>");
  2273. MODULE_AUTHOR("Waldemar Rymarkiewicz <waldemar.rymarkiewicz@tieto.com>");
  2274. MODULE_DESCRIPTION("PN533 usb driver ver " VERSION);
  2275. MODULE_VERSION(VERSION);
  2276. MODULE_LICENSE("GPL");