btbcm.c 14.0 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
/*
 *
 *  Bluetooth support for Broadcom devices
 *
 *  Copyright (C) 2015  Intel Corporation
 *
 *
 *  This program is free software; you can redistribute it and/or modify
 *  it under the terms of the GNU General Public License as published by
 *  the Free Software Foundation; either version 2 of the License, or
 *  (at your option) any later version.
 *
 *  This program is distributed in the hope that it will be useful,
 *  but WITHOUT ANY WARRANTY; without even the implied warranty of
 *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 *  GNU General Public License for more details.
 *
 *  You should have received a copy of the GNU General Public License
 *  along with this program; if not, write to the Free Software
 *  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
 *
 */

#include <linux/module.h>
25 26
#include <linux/firmware.h>
#include <asm/unaligned.h>
27 28 29 30 31 32 33 34 35

#include <net/bluetooth/bluetooth.h>
#include <net/bluetooth/hci_core.h>

#include "btbcm.h"

#define VERSION "0.1"

#define BDADDR_BCM20702A0 (&(bdaddr_t) {{0x00, 0xa0, 0x02, 0x70, 0x20, 0x00}})
36
#define BDADDR_BCM4324B3 (&(bdaddr_t) {{0x00, 0x00, 0x00, 0xb3, 0x24, 0x43}})
37
#define BDADDR_BCM4330B1 (&(bdaddr_t) {{0x00, 0x00, 0x00, 0xb1, 0x30, 0x43}})
38 39 40 41 42 43 44 45 46 47

int btbcm_check_bdaddr(struct hci_dev *hdev)
{
	struct hci_rp_read_bd_addr *bda;
	struct sk_buff *skb;

	skb = __hci_cmd_sync(hdev, HCI_OP_READ_BD_ADDR, 0, NULL,
			     HCI_INIT_TIMEOUT);
	if (IS_ERR(skb)) {
		int err = PTR_ERR(skb);
48
		bt_dev_err(hdev, "BCM: Reading device address failed (%d)", err);
49 50 51 52
		return err;
	}

	if (skb->len != sizeof(*bda)) {
53
		bt_dev_err(hdev, "BCM: Device address length mismatch");
54 55 56 57 58 59
		kfree_skb(skb);
		return -EIO;
	}

	bda = (struct hci_rp_read_bd_addr *)skb->data;

60 61 62 63 64
	/* Check if the address indicates a controller with either an
	 * invalid or default address. In both cases the device needs
	 * to be marked as not having a valid address.
	 *
	 * The address 00:20:70:02:A0:00 indicates a BCM20702A0 controller
65
	 * with no configured address.
66 67 68
	 *
	 * The address 43:24:B3:00:00:00 indicates a BCM4324B3 controller
	 * with waiting for configuration state.
69 70 71
	 *
	 * The address 43:30:B1:00:00:00 indicates a BCM4330B1 controller
	 * with waiting for configuration state.
72
	 */
73
	if (!bacmp(&bda->bdaddr, BDADDR_BCM20702A0) ||
74 75
	    !bacmp(&bda->bdaddr, BDADDR_BCM4324B3) ||
	    !bacmp(&bda->bdaddr, BDADDR_BCM4330B1)) {
76 77
		bt_dev_info(hdev, "BCM: Using default device address (%pMR)",
			    &bda->bdaddr);
78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94
		set_bit(HCI_QUIRK_INVALID_BDADDR, &hdev->quirks);
	}

	kfree_skb(skb);

	return 0;
}
EXPORT_SYMBOL_GPL(btbcm_check_bdaddr);

int btbcm_set_bdaddr(struct hci_dev *hdev, const bdaddr_t *bdaddr)
{
	struct sk_buff *skb;
	int err;

	skb = __hci_cmd_sync(hdev, 0xfc01, 6, bdaddr, HCI_INIT_TIMEOUT);
	if (IS_ERR(skb)) {
		err = PTR_ERR(skb);
95
		bt_dev_err(hdev, "BCM: Change address command failed (%d)", err);
96 97 98 99 100 101 102 103
		return err;
	}
	kfree_skb(skb);

	return 0;
}
EXPORT_SYMBOL_GPL(btbcm_set_bdaddr);

104
int btbcm_patchram(struct hci_dev *hdev, const struct firmware *fw)
105 106 107 108 109 110
{
	const struct hci_command_hdr *cmd;
	const u8 *fw_ptr;
	size_t fw_size;
	struct sk_buff *skb;
	u16 opcode;
111
	int err = 0;
112 113 114 115 116

	/* Start Download */
	skb = __hci_cmd_sync(hdev, 0xfc2e, 0, NULL, HCI_INIT_TIMEOUT);
	if (IS_ERR(skb)) {
		err = PTR_ERR(skb);
117 118
		bt_dev_err(hdev, "BCM: Download Minidrv command failed (%d)",
			   err);
119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136
		goto done;
	}
	kfree_skb(skb);

	/* 50 msec delay after Download Minidrv completes */
	msleep(50);

	fw_ptr = fw->data;
	fw_size = fw->size;

	while (fw_size >= sizeof(*cmd)) {
		const u8 *cmd_param;

		cmd = (struct hci_command_hdr *)fw_ptr;
		fw_ptr += sizeof(*cmd);
		fw_size -= sizeof(*cmd);

		if (fw_size < cmd->plen) {
137
			bt_dev_err(hdev, "BCM: Patch is corrupted");
138 139 140 141 142 143 144 145 146 147 148 149 150 151
			err = -EINVAL;
			goto done;
		}

		cmd_param = fw_ptr;
		fw_ptr += cmd->plen;
		fw_size -= cmd->plen;

		opcode = le16_to_cpu(cmd->opcode);

		skb = __hci_cmd_sync(hdev, opcode, cmd->plen, cmd_param,
				     HCI_INIT_TIMEOUT);
		if (IS_ERR(skb)) {
			err = PTR_ERR(skb);
152 153
			bt_dev_err(hdev, "BCM: Patch command %04x failed (%d)",
				   opcode, err);
154 155 156 157 158 159 160 161 162 163 164 165 166
			goto done;
		}
		kfree_skb(skb);
	}

	/* 250 msec delay after Launch Ram completes */
	msleep(250);

done:
	return err;
}
EXPORT_SYMBOL(btbcm_patchram);

167 168 169 170 171 172 173
static int btbcm_reset(struct hci_dev *hdev)
{
	struct sk_buff *skb;

	skb = __hci_cmd_sync(hdev, HCI_OP_RESET, 0, NULL, HCI_INIT_TIMEOUT);
	if (IS_ERR(skb)) {
		int err = PTR_ERR(skb);
174
		bt_dev_err(hdev, "BCM: Reset failed (%d)", err);
175 176 177 178
		return err;
	}
	kfree_skb(skb);

179 180 181
	/* 100 msec delay for module to complete reset process */
	msleep(100);

182 183 184
	return 0;
}

185 186 187 188 189 190 191
static struct sk_buff *btbcm_read_local_name(struct hci_dev *hdev)
{
	struct sk_buff *skb;

	skb = __hci_cmd_sync(hdev, HCI_OP_READ_LOCAL_NAME, 0, NULL,
			     HCI_INIT_TIMEOUT);
	if (IS_ERR(skb)) {
192 193
		bt_dev_err(hdev, "BCM: Reading local name failed (%ld)",
			   PTR_ERR(skb));
194 195 196 197
		return skb;
	}

	if (skb->len != sizeof(struct hci_rp_read_local_name)) {
198
		bt_dev_err(hdev, "BCM: Local name length mismatch");
199 200 201 202 203 204 205
		kfree_skb(skb);
		return ERR_PTR(-EIO);
	}

	return skb;
}

206 207 208 209 210 211 212
static struct sk_buff *btbcm_read_local_version(struct hci_dev *hdev)
{
	struct sk_buff *skb;

	skb = __hci_cmd_sync(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL,
			     HCI_INIT_TIMEOUT);
	if (IS_ERR(skb)) {
213 214
		bt_dev_err(hdev, "BCM: Reading local version info failed (%ld)",
			   PTR_ERR(skb));
215 216 217 218
		return skb;
	}

	if (skb->len != sizeof(struct hci_rp_read_local_version)) {
219
		bt_dev_err(hdev, "BCM: Local version length mismatch");
220 221 222 223 224 225 226 227 228 229 230 231 232
		kfree_skb(skb);
		return ERR_PTR(-EIO);
	}

	return skb;
}

static struct sk_buff *btbcm_read_verbose_config(struct hci_dev *hdev)
{
	struct sk_buff *skb;

	skb = __hci_cmd_sync(hdev, 0xfc79, 0, NULL, HCI_INIT_TIMEOUT);
	if (IS_ERR(skb)) {
233 234
		bt_dev_err(hdev, "BCM: Read verbose config info failed (%ld)",
			   PTR_ERR(skb));
235 236 237 238
		return skb;
	}

	if (skb->len != 7) {
239
		bt_dev_err(hdev, "BCM: Verbose config length mismatch");
240 241 242 243 244 245 246
		kfree_skb(skb);
		return ERR_PTR(-EIO);
	}

	return skb;
}

247 248 249 250 251 252
static struct sk_buff *btbcm_read_controller_features(struct hci_dev *hdev)
{
	struct sk_buff *skb;

	skb = __hci_cmd_sync(hdev, 0xfc6e, 0, NULL, HCI_INIT_TIMEOUT);
	if (IS_ERR(skb)) {
253 254
		bt_dev_err(hdev, "BCM: Read controller features failed (%ld)",
			   PTR_ERR(skb));
255 256 257 258
		return skb;
	}

	if (skb->len != 9) {
259
		bt_dev_err(hdev, "BCM: Controller features length mismatch");
260 261 262 263 264 265 266
		kfree_skb(skb);
		return ERR_PTR(-EIO);
	}

	return skb;
}

267 268 269 270 271 272
static struct sk_buff *btbcm_read_usb_product(struct hci_dev *hdev)
{
	struct sk_buff *skb;

	skb = __hci_cmd_sync(hdev, 0xfc5a, 0, NULL, HCI_INIT_TIMEOUT);
	if (IS_ERR(skb)) {
273 274
		bt_dev_err(hdev, "BCM: Read USB product info failed (%ld)",
			   PTR_ERR(skb));
275 276 277 278
		return skb;
	}

	if (skb->len != 5) {
279
		bt_dev_err(hdev, "BCM: USB product length mismatch");
280 281 282 283 284 285 286
		kfree_skb(skb);
		return ERR_PTR(-EIO);
	}

	return skb;
}

287 288 289 290 291 292 293 294 295
static int btbcm_read_info(struct hci_dev *hdev)
{
	struct sk_buff *skb;

	/* Read Verbose Config Version Info */
	skb = btbcm_read_verbose_config(hdev);
	if (IS_ERR(skb))
		return PTR_ERR(skb);

296
	bt_dev_info(hdev, "BCM: chip id %u", skb->data[1]);
297 298 299 300 301 302 303
	kfree_skb(skb);

	/* Read Controller Features */
	skb = btbcm_read_controller_features(hdev);
	if (IS_ERR(skb))
		return PTR_ERR(skb);

304
	bt_dev_info(hdev, "BCM: features 0x%2.2x", skb->data[1]);
305 306 307 308 309 310 311
	kfree_skb(skb);

	/* Read Local Name */
	skb = btbcm_read_local_name(hdev);
	if (IS_ERR(skb))
		return PTR_ERR(skb);

312
	bt_dev_info(hdev, "%s", (char *)(skb->data + 1));
313 314 315 316 317
	kfree_skb(skb);

	return 0;
}

318 319 320
static const struct {
	u16 subver;
	const char *name;
321
} bcm_uart_subver_table[] = {
322
	{ 0x4103, "BCM4330B1"	},	/* 002.001.003 */
323
	{ 0x410e, "BCM43341B0"	},	/* 002.001.014 */
324
	{ 0x4406, "BCM4324B3"	},	/* 002.004.006 */
325
	{ 0x610c, "BCM4354"	},	/* 003.001.012 */
326
	{ 0x2122, "BCM4343A0"	},	/* 001.001.034 */
327
	{ 0x2209, "BCM43430A1"  },	/* 001.002.009 */
328
	{ 0x6119, "BCM4345C0"	},	/* 003.001.025 */
329
	{ 0x230f, "BCM4356A2"	},	/* 001.003.015 */
330 331 332
	{ }
};

333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355
int btbcm_initialize(struct hci_dev *hdev, char *fw_name, size_t len)
{
	u16 subver, rev;
	const char *hw_name = NULL;
	struct sk_buff *skb;
	struct hci_rp_read_local_version *ver;
	int i, err;

	/* Reset */
	err = btbcm_reset(hdev);
	if (err)
		return err;

	/* Read Local Version Info */
	skb = btbcm_read_local_version(hdev);
	if (IS_ERR(skb))
		return PTR_ERR(skb);

	ver = (struct hci_rp_read_local_version *)skb->data;
	rev = le16_to_cpu(ver->hci_rev);
	subver = le16_to_cpu(ver->lmp_subver);
	kfree_skb(skb);

356 357 358 359
	/* Read controller information */
	err = btbcm_read_info(hdev);
	if (err)
		return err;
360 361 362

	switch ((rev & 0xf000) >> 12) {
	case 0:
363
	case 1:
364
	case 2:
365 366 367 368 369 370 371 372 373 374 375 376 377 378
	case 3:
		for (i = 0; bcm_uart_subver_table[i].name; i++) {
			if (subver == bcm_uart_subver_table[i].subver) {
				hw_name = bcm_uart_subver_table[i].name;
				break;
			}
		}

		snprintf(fw_name, len, "brcm/%s.hcd", hw_name ? : "BCM");
		break;
	default:
		return 0;
	}

379 380 381
	bt_dev_info(hdev, "%s (%3.3u.%3.3u.%3.3u) build %4.4u",
		    hw_name ? : "BCM", (subver & 0xe000) >> 13,
		    (subver & 0x1f00) >> 8, (subver & 0x00ff), rev & 0x0fff);
382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408

	return 0;
}
EXPORT_SYMBOL_GPL(btbcm_initialize);

int btbcm_finalize(struct hci_dev *hdev)
{
	struct sk_buff *skb;
	struct hci_rp_read_local_version *ver;
	u16 subver, rev;
	int err;

	/* Reset */
	err = btbcm_reset(hdev);
	if (err)
		return err;

	/* Read Local Version Info */
	skb = btbcm_read_local_version(hdev);
	if (IS_ERR(skb))
		return PTR_ERR(skb);

	ver = (struct hci_rp_read_local_version *)skb->data;
	rev = le16_to_cpu(ver->hci_rev);
	subver = le16_to_cpu(ver->lmp_subver);
	kfree_skb(skb);

409 410 411
	bt_dev_info(hdev, "BCM (%3.3u.%3.3u.%3.3u) build %4.4u",
		    (subver & 0xe000) >> 13, (subver & 0x1f00) >> 8,
		    (subver & 0x00ff), rev & 0x0fff);
412 413 414 415 416 417 418 419 420

	btbcm_check_bdaddr(hdev);

	set_bit(HCI_QUIRK_STRICT_DUPLICATE_FILTER, &hdev->quirks);

	return 0;
}
EXPORT_SYMBOL_GPL(btbcm_finalize);

421 422 423 424
static const struct {
	u16 subver;
	const char *name;
} bcm_usb_subver_table[] = {
425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440
	{ 0x210b, "BCM43142A0"	},	/* 001.001.011 */
	{ 0x2112, "BCM4314A0"	},	/* 001.001.018 */
	{ 0x2118, "BCM20702A0"	},	/* 001.001.024 */
	{ 0x2126, "BCM4335A0"	},	/* 001.001.038 */
	{ 0x220e, "BCM20702A1"	},	/* 001.002.014 */
	{ 0x230f, "BCM4354A2"	},	/* 001.003.015 */
	{ 0x4106, "BCM4335B0"	},	/* 002.001.006 */
	{ 0x410e, "BCM20702B0"	},	/* 002.001.014 */
	{ 0x6109, "BCM4335C0"	},	/* 003.001.009 */
	{ 0x610c, "BCM4354"	},	/* 003.001.012 */
	{ }
};

int btbcm_setup_patchram(struct hci_dev *hdev)
{
	char fw_name[64];
441
	const struct firmware *fw;
442
	u16 subver, rev, pid, vid;
443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462
	const char *hw_name = NULL;
	struct sk_buff *skb;
	struct hci_rp_read_local_version *ver;
	int i, err;

	/* Reset */
	err = btbcm_reset(hdev);
	if (err)
		return err;

	/* Read Local Version Info */
	skb = btbcm_read_local_version(hdev);
	if (IS_ERR(skb))
		return PTR_ERR(skb);

	ver = (struct hci_rp_read_local_version *)skb->data;
	rev = le16_to_cpu(ver->hci_rev);
	subver = le16_to_cpu(ver->lmp_subver);
	kfree_skb(skb);

463 464 465 466
	/* Read controller information */
	err = btbcm_read_info(hdev);
	if (err)
		return err;
467

468 469 470 471 472
	/* Upper nibble of rev should be between 0 and 3? */
	if (((rev & 0xf000) >> 12) > 3)
		return 0;

	if (hdev->bus != HCI_USB) {
473 474 475 476 477 478
		for (i = 0; bcm_uart_subver_table[i].name; i++) {
			if (subver == bcm_uart_subver_table[i].subver) {
				hw_name = bcm_uart_subver_table[i].name;
				break;
			}
		}
479

480 481
		snprintf(fw_name, sizeof(fw_name), "brcm/%s.hcd",
			 hw_name ? : "BCM");
482
	} else {
483 484 485 486 487 488 489 490
		/* Read USB Product Info */
		skb = btbcm_read_usb_product(hdev);
		if (IS_ERR(skb))
			return PTR_ERR(skb);

		vid = get_unaligned_le16(skb->data + 1);
		pid = get_unaligned_le16(skb->data + 3);
		kfree_skb(skb);
491

492 493 494 495 496
		for (i = 0; bcm_usb_subver_table[i].name; i++) {
			if (subver == bcm_usb_subver_table[i].subver) {
				hw_name = bcm_usb_subver_table[i].name;
				break;
			}
497
		}
498 499 500

		snprintf(fw_name, sizeof(fw_name), "brcm/%s-%4.4x-%4.4x.hcd",
			 hw_name ? : "BCM", vid, pid);
501 502
	}

503 504 505
	bt_dev_info(hdev, "%s (%3.3u.%3.3u.%3.3u) build %4.4u",
		    hw_name ? : "BCM", (subver & 0xe000) >> 13,
		    (subver & 0x1f00) >> 8, (subver & 0x00ff), rev & 0x0fff);
506

507 508
	err = request_firmware(&fw, fw_name, &hdev->dev);
	if (err < 0) {
509
		bt_dev_info(hdev, "BCM: Patch %s not found", fw_name);
510
		goto done;
511 512 513 514 515
	}

	btbcm_patchram(hdev, fw);

	release_firmware(fw);
516 517 518 519

	/* Reset */
	err = btbcm_reset(hdev);
	if (err)
520
		return err;
521 522 523

	/* Read Local Version Info */
	skb = btbcm_read_local_version(hdev);
524 525
	if (IS_ERR(skb))
		return PTR_ERR(skb);
526 527 528 529 530 531

	ver = (struct hci_rp_read_local_version *)skb->data;
	rev = le16_to_cpu(ver->hci_rev);
	subver = le16_to_cpu(ver->lmp_subver);
	kfree_skb(skb);

532 533 534
	bt_dev_info(hdev, "%s (%3.3u.%3.3u.%3.3u) build %4.4u",
		    hw_name ? : "BCM", (subver & 0xe000) >> 13,
		    (subver & 0x1f00) >> 8, (subver & 0x00ff), rev & 0x0fff);
535

536 537 538 539 540
	/* Read Local Name */
	skb = btbcm_read_local_name(hdev);
	if (IS_ERR(skb))
		return PTR_ERR(skb);

541
	bt_dev_info(hdev, "%s", (char *)(skb->data + 1));
542 543
	kfree_skb(skb);

544
done:
545 546
	btbcm_check_bdaddr(hdev);

547 548
	set_bit(HCI_QUIRK_STRICT_DUPLICATE_FILTER, &hdev->quirks);

549
	return 0;
550 551 552 553 554 555
}
EXPORT_SYMBOL_GPL(btbcm_setup_patchram);

int btbcm_setup_apple(struct hci_dev *hdev)
{
	struct sk_buff *skb;
556 557 558 559 560 561
	int err;

	/* Reset */
	err = btbcm_reset(hdev);
	if (err)
		return err;
562 563 564

	/* Read Verbose Config Version Info */
	skb = btbcm_read_verbose_config(hdev);
565
	if (!IS_ERR(skb)) {
566 567
		bt_dev_info(hdev, "BCM: chip id %u build %4.4u",
			    skb->data[1], get_unaligned_le16(skb->data + 5));
568 569
		kfree_skb(skb);
	}
570

571 572 573
	/* Read USB Product Info */
	skb = btbcm_read_usb_product(hdev);
	if (!IS_ERR(skb)) {
574 575 576
		bt_dev_info(hdev, "BCM: product %4.4x:%4.4x",
			    get_unaligned_le16(skb->data + 1),
			    get_unaligned_le16(skb->data + 3));
577 578 579
		kfree_skb(skb);
	}

580 581 582
	/* Read Controller Features */
	skb = btbcm_read_controller_features(hdev);
	if (!IS_ERR(skb)) {
583
		bt_dev_info(hdev, "BCM: features 0x%2.2x", skb->data[1]);
584 585 586
		kfree_skb(skb);
	}

587 588 589
	/* Read Local Name */
	skb = btbcm_read_local_name(hdev);
	if (!IS_ERR(skb)) {
590
		bt_dev_info(hdev, "%s", (char *)(skb->data + 1));
591 592 593
		kfree_skb(skb);
	}

594 595
	set_bit(HCI_QUIRK_STRICT_DUPLICATE_FILTER, &hdev->quirks);

596 597 598 599
	return 0;
}
EXPORT_SYMBOL_GPL(btbcm_setup_apple);

600 601 602 603
MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
MODULE_DESCRIPTION("Bluetooth support for Broadcom devices ver " VERSION);
MODULE_VERSION(VERSION);
MODULE_LICENSE("GPL");