btbcm.c 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491
  1. /*
  2. *
  3. * Bluetooth support for Broadcom devices
  4. *
  5. * Copyright (C) 2015 Intel Corporation
  6. *
  7. *
  8. * This program is free software; you can redistribute it and/or modify
  9. * it under the terms of the GNU General Public License as published by
  10. * the Free Software Foundation; either version 2 of the License, or
  11. * (at your option) any later version.
  12. *
  13. * This program is distributed in the hope that it will be useful,
  14. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. * GNU General Public License for more details.
  17. *
  18. * You should have received a copy of the GNU General Public License
  19. * along with this program; if not, write to the Free Software
  20. * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  21. *
  22. */
  23. #include <linux/module.h>
  24. #include <linux/firmware.h>
  25. #include <asm/unaligned.h>
  26. #include <net/bluetooth/bluetooth.h>
  27. #include <net/bluetooth/hci_core.h>
  28. #include "btbcm.h"
  29. #define VERSION "0.1"
  30. #define BDADDR_BCM20702A0 (&(bdaddr_t) {{0x00, 0xa0, 0x02, 0x70, 0x20, 0x00}})
  31. #define BDADDR_BCM4324B3 (&(bdaddr_t) {{0x00, 0x00, 0x00, 0xb3, 0x24, 0x43}})
  32. int btbcm_check_bdaddr(struct hci_dev *hdev)
  33. {
  34. struct hci_rp_read_bd_addr *bda;
  35. struct sk_buff *skb;
  36. skb = __hci_cmd_sync(hdev, HCI_OP_READ_BD_ADDR, 0, NULL,
  37. HCI_INIT_TIMEOUT);
  38. if (IS_ERR(skb)) {
  39. int err = PTR_ERR(skb);
  40. BT_ERR("%s: BCM: Reading device address failed (%d)",
  41. hdev->name, err);
  42. return err;
  43. }
  44. if (skb->len != sizeof(*bda)) {
  45. BT_ERR("%s: BCM: Device address length mismatch", hdev->name);
  46. kfree_skb(skb);
  47. return -EIO;
  48. }
  49. bda = (struct hci_rp_read_bd_addr *)skb->data;
  50. /* Check if the address indicates a controller with either an
  51. * invalid or default address. In both cases the device needs
  52. * to be marked as not having a valid address.
  53. *
  54. * The address 00:20:70:02:A0:00 indicates a BCM20702A0 controller
  55. * with no configured address.
  56. *
  57. * The address 43:24:B3:00:00:00 indicates a BCM4324B3 controller
  58. * with waiting for configuration state.
  59. */
  60. if (!bacmp(&bda->bdaddr, BDADDR_BCM20702A0) ||
  61. !bacmp(&bda->bdaddr, BDADDR_BCM4324B3)) {
  62. BT_INFO("%s: BCM: Using default device address (%pMR)",
  63. hdev->name, &bda->bdaddr);
  64. set_bit(HCI_QUIRK_INVALID_BDADDR, &hdev->quirks);
  65. }
  66. kfree_skb(skb);
  67. return 0;
  68. }
  69. EXPORT_SYMBOL_GPL(btbcm_check_bdaddr);
  70. int btbcm_set_bdaddr(struct hci_dev *hdev, const bdaddr_t *bdaddr)
  71. {
  72. struct sk_buff *skb;
  73. int err;
  74. skb = __hci_cmd_sync(hdev, 0xfc01, 6, bdaddr, HCI_INIT_TIMEOUT);
  75. if (IS_ERR(skb)) {
  76. err = PTR_ERR(skb);
  77. BT_ERR("%s: BCM: Change address command failed (%d)",
  78. hdev->name, err);
  79. return err;
  80. }
  81. kfree_skb(skb);
  82. return 0;
  83. }
  84. EXPORT_SYMBOL_GPL(btbcm_set_bdaddr);
  85. int btbcm_patchram(struct hci_dev *hdev, const struct firmware *fw)
  86. {
  87. const struct hci_command_hdr *cmd;
  88. const u8 *fw_ptr;
  89. size_t fw_size;
  90. struct sk_buff *skb;
  91. u16 opcode;
  92. int err = 0;
  93. /* Start Download */
  94. skb = __hci_cmd_sync(hdev, 0xfc2e, 0, NULL, HCI_INIT_TIMEOUT);
  95. if (IS_ERR(skb)) {
  96. err = PTR_ERR(skb);
  97. BT_ERR("%s: BCM: Download Minidrv command failed (%d)",
  98. hdev->name, err);
  99. goto done;
  100. }
  101. kfree_skb(skb);
  102. /* 50 msec delay after Download Minidrv completes */
  103. msleep(50);
  104. fw_ptr = fw->data;
  105. fw_size = fw->size;
  106. while (fw_size >= sizeof(*cmd)) {
  107. const u8 *cmd_param;
  108. cmd = (struct hci_command_hdr *)fw_ptr;
  109. fw_ptr += sizeof(*cmd);
  110. fw_size -= sizeof(*cmd);
  111. if (fw_size < cmd->plen) {
  112. BT_ERR("%s: BCM: Patch is corrupted", hdev->name);
  113. err = -EINVAL;
  114. goto done;
  115. }
  116. cmd_param = fw_ptr;
  117. fw_ptr += cmd->plen;
  118. fw_size -= cmd->plen;
  119. opcode = le16_to_cpu(cmd->opcode);
  120. skb = __hci_cmd_sync(hdev, opcode, cmd->plen, cmd_param,
  121. HCI_INIT_TIMEOUT);
  122. if (IS_ERR(skb)) {
  123. err = PTR_ERR(skb);
  124. BT_ERR("%s: BCM: Patch command %04x failed (%d)",
  125. hdev->name, opcode, err);
  126. goto done;
  127. }
  128. kfree_skb(skb);
  129. }
  130. /* 250 msec delay after Launch Ram completes */
  131. msleep(250);
  132. done:
  133. return err;
  134. }
  135. EXPORT_SYMBOL(btbcm_patchram);
  136. static int btbcm_reset(struct hci_dev *hdev)
  137. {
  138. struct sk_buff *skb;
  139. skb = __hci_cmd_sync(hdev, HCI_OP_RESET, 0, NULL, HCI_INIT_TIMEOUT);
  140. if (IS_ERR(skb)) {
  141. int err = PTR_ERR(skb);
  142. BT_ERR("%s: BCM: Reset failed (%d)", hdev->name, err);
  143. return err;
  144. }
  145. kfree_skb(skb);
  146. return 0;
  147. }
  148. static struct sk_buff *btbcm_read_local_version(struct hci_dev *hdev)
  149. {
  150. struct sk_buff *skb;
  151. skb = __hci_cmd_sync(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL,
  152. HCI_INIT_TIMEOUT);
  153. if (IS_ERR(skb)) {
  154. BT_ERR("%s: BCM: Reading local version info failed (%ld)",
  155. hdev->name, PTR_ERR(skb));
  156. return skb;
  157. }
  158. if (skb->len != sizeof(struct hci_rp_read_local_version)) {
  159. BT_ERR("%s: BCM: Local version length mismatch", hdev->name);
  160. kfree_skb(skb);
  161. return ERR_PTR(-EIO);
  162. }
  163. return skb;
  164. }
  165. static struct sk_buff *btbcm_read_verbose_config(struct hci_dev *hdev)
  166. {
  167. struct sk_buff *skb;
  168. skb = __hci_cmd_sync(hdev, 0xfc79, 0, NULL, HCI_INIT_TIMEOUT);
  169. if (IS_ERR(skb)) {
  170. BT_ERR("%s: BCM: Read verbose config info failed (%ld)",
  171. hdev->name, PTR_ERR(skb));
  172. return skb;
  173. }
  174. if (skb->len != 7) {
  175. BT_ERR("%s: BCM: Verbose config length mismatch", hdev->name);
  176. kfree_skb(skb);
  177. return ERR_PTR(-EIO);
  178. }
  179. return skb;
  180. }
  181. static struct sk_buff *btbcm_read_usb_product(struct hci_dev *hdev)
  182. {
  183. struct sk_buff *skb;
  184. skb = __hci_cmd_sync(hdev, 0xfc5a, 0, NULL, HCI_INIT_TIMEOUT);
  185. if (IS_ERR(skb)) {
  186. BT_ERR("%s: BCM: Read USB product info failed (%ld)",
  187. hdev->name, PTR_ERR(skb));
  188. return skb;
  189. }
  190. if (skb->len != 5) {
  191. BT_ERR("%s: BCM: USB product length mismatch", hdev->name);
  192. kfree_skb(skb);
  193. return ERR_PTR(-EIO);
  194. }
  195. return skb;
  196. }
  197. static const struct {
  198. u16 subver;
  199. const char *name;
  200. } bcm_uart_subver_table[] = {
  201. { 0x410e, "BCM43341B0" }, /* 002.001.014 */
  202. { 0x4406, "BCM4324B3" }, /* 002.004.006 */
  203. { 0x610c, "BCM4354" }, /* 003.001.012 */
  204. { }
  205. };
  206. int btbcm_initialize(struct hci_dev *hdev, char *fw_name, size_t len)
  207. {
  208. u16 subver, rev;
  209. const char *hw_name = NULL;
  210. struct sk_buff *skb;
  211. struct hci_rp_read_local_version *ver;
  212. int i, err;
  213. /* Reset */
  214. err = btbcm_reset(hdev);
  215. if (err)
  216. return err;
  217. /* Read Local Version Info */
  218. skb = btbcm_read_local_version(hdev);
  219. if (IS_ERR(skb))
  220. return PTR_ERR(skb);
  221. ver = (struct hci_rp_read_local_version *)skb->data;
  222. rev = le16_to_cpu(ver->hci_rev);
  223. subver = le16_to_cpu(ver->lmp_subver);
  224. kfree_skb(skb);
  225. /* Read Verbose Config Version Info */
  226. skb = btbcm_read_verbose_config(hdev);
  227. if (IS_ERR(skb))
  228. return PTR_ERR(skb);
  229. BT_INFO("%s: BCM: chip id %u", hdev->name, skb->data[1]);
  230. kfree_skb(skb);
  231. switch ((rev & 0xf000) >> 12) {
  232. case 0:
  233. case 1:
  234. case 3:
  235. for (i = 0; bcm_uart_subver_table[i].name; i++) {
  236. if (subver == bcm_uart_subver_table[i].subver) {
  237. hw_name = bcm_uart_subver_table[i].name;
  238. break;
  239. }
  240. }
  241. snprintf(fw_name, len, "brcm/%s.hcd", hw_name ? : "BCM");
  242. break;
  243. default:
  244. return 0;
  245. }
  246. BT_INFO("%s: %s (%3.3u.%3.3u.%3.3u) build %4.4u", hdev->name,
  247. hw_name ? : "BCM", (subver & 0x7000) >> 13,
  248. (subver & 0x1f00) >> 8, (subver & 0x00ff), rev & 0x0fff);
  249. return 0;
  250. }
  251. EXPORT_SYMBOL_GPL(btbcm_initialize);
  252. int btbcm_finalize(struct hci_dev *hdev)
  253. {
  254. struct sk_buff *skb;
  255. struct hci_rp_read_local_version *ver;
  256. u16 subver, rev;
  257. int err;
  258. /* Reset */
  259. err = btbcm_reset(hdev);
  260. if (err)
  261. return err;
  262. /* Read Local Version Info */
  263. skb = btbcm_read_local_version(hdev);
  264. if (IS_ERR(skb))
  265. return PTR_ERR(skb);
  266. ver = (struct hci_rp_read_local_version *)skb->data;
  267. rev = le16_to_cpu(ver->hci_rev);
  268. subver = le16_to_cpu(ver->lmp_subver);
  269. kfree_skb(skb);
  270. BT_INFO("%s: BCM (%3.3u.%3.3u.%3.3u) build %4.4u", hdev->name,
  271. (subver & 0x7000) >> 13, (subver & 0x1f00) >> 8,
  272. (subver & 0x00ff), rev & 0x0fff);
  273. btbcm_check_bdaddr(hdev);
  274. set_bit(HCI_QUIRK_STRICT_DUPLICATE_FILTER, &hdev->quirks);
  275. return 0;
  276. }
  277. EXPORT_SYMBOL_GPL(btbcm_finalize);
  278. static const struct {
  279. u16 subver;
  280. const char *name;
  281. } bcm_usb_subver_table[] = {
  282. { 0x210b, "BCM43142A0" }, /* 001.001.011 */
  283. { 0x2112, "BCM4314A0" }, /* 001.001.018 */
  284. { 0x2118, "BCM20702A0" }, /* 001.001.024 */
  285. { 0x2126, "BCM4335A0" }, /* 001.001.038 */
  286. { 0x220e, "BCM20702A1" }, /* 001.002.014 */
  287. { 0x230f, "BCM4354A2" }, /* 001.003.015 */
  288. { 0x4106, "BCM4335B0" }, /* 002.001.006 */
  289. { 0x410e, "BCM20702B0" }, /* 002.001.014 */
  290. { 0x6109, "BCM4335C0" }, /* 003.001.009 */
  291. { 0x610c, "BCM4354" }, /* 003.001.012 */
  292. { }
  293. };
  294. int btbcm_setup_patchram(struct hci_dev *hdev)
  295. {
  296. char fw_name[64];
  297. const struct firmware *fw;
  298. u16 subver, rev, pid, vid;
  299. const char *hw_name = NULL;
  300. struct sk_buff *skb;
  301. struct hci_rp_read_local_version *ver;
  302. int i, err;
  303. /* Reset */
  304. err = btbcm_reset(hdev);
  305. if (err)
  306. return err;
  307. /* Read Local Version Info */
  308. skb = btbcm_read_local_version(hdev);
  309. if (IS_ERR(skb))
  310. return PTR_ERR(skb);
  311. ver = (struct hci_rp_read_local_version *)skb->data;
  312. rev = le16_to_cpu(ver->hci_rev);
  313. subver = le16_to_cpu(ver->lmp_subver);
  314. kfree_skb(skb);
  315. /* Read Verbose Config Version Info */
  316. skb = btbcm_read_verbose_config(hdev);
  317. if (IS_ERR(skb))
  318. return PTR_ERR(skb);
  319. BT_INFO("%s: BCM: chip id %u", hdev->name, skb->data[1]);
  320. kfree_skb(skb);
  321. switch ((rev & 0xf000) >> 12) {
  322. case 0:
  323. case 3:
  324. for (i = 0; bcm_uart_subver_table[i].name; i++) {
  325. if (subver == bcm_uart_subver_table[i].subver) {
  326. hw_name = bcm_uart_subver_table[i].name;
  327. break;
  328. }
  329. }
  330. snprintf(fw_name, sizeof(fw_name), "brcm/%s.hcd",
  331. hw_name ? : "BCM");
  332. break;
  333. case 1:
  334. case 2:
  335. /* Read USB Product Info */
  336. skb = btbcm_read_usb_product(hdev);
  337. if (IS_ERR(skb))
  338. return PTR_ERR(skb);
  339. vid = get_unaligned_le16(skb->data + 1);
  340. pid = get_unaligned_le16(skb->data + 3);
  341. kfree_skb(skb);
  342. for (i = 0; bcm_usb_subver_table[i].name; i++) {
  343. if (subver == bcm_usb_subver_table[i].subver) {
  344. hw_name = bcm_usb_subver_table[i].name;
  345. break;
  346. }
  347. }
  348. snprintf(fw_name, sizeof(fw_name), "brcm/%s-%4.4x-%4.4x.hcd",
  349. hw_name ? : "BCM", vid, pid);
  350. break;
  351. default:
  352. return 0;
  353. }
  354. BT_INFO("%s: %s (%3.3u.%3.3u.%3.3u) build %4.4u", hdev->name,
  355. hw_name ? : "BCM", (subver & 0x7000) >> 13,
  356. (subver & 0x1f00) >> 8, (subver & 0x00ff), rev & 0x0fff);
  357. err = request_firmware(&fw, fw_name, &hdev->dev);
  358. if (err < 0) {
  359. BT_INFO("%s: BCM: Patch %s not found", hdev->name, fw_name);
  360. return 0;
  361. }
  362. btbcm_patchram(hdev, fw);
  363. release_firmware(fw);
  364. /* Reset */
  365. err = btbcm_reset(hdev);
  366. if (err)
  367. return err;
  368. /* Read Local Version Info */
  369. skb = btbcm_read_local_version(hdev);
  370. if (IS_ERR(skb))
  371. return PTR_ERR(skb);
  372. ver = (struct hci_rp_read_local_version *)skb->data;
  373. rev = le16_to_cpu(ver->hci_rev);
  374. subver = le16_to_cpu(ver->lmp_subver);
  375. kfree_skb(skb);
  376. BT_INFO("%s: %s (%3.3u.%3.3u.%3.3u) build %4.4u", hdev->name,
  377. hw_name ? : "BCM", (subver & 0x7000) >> 13,
  378. (subver & 0x1f00) >> 8, (subver & 0x00ff), rev & 0x0fff);
  379. btbcm_check_bdaddr(hdev);
  380. set_bit(HCI_QUIRK_STRICT_DUPLICATE_FILTER, &hdev->quirks);
  381. return 0;
  382. }
  383. EXPORT_SYMBOL_GPL(btbcm_setup_patchram);
  384. int btbcm_setup_apple(struct hci_dev *hdev)
  385. {
  386. struct sk_buff *skb;
  387. /* Read Verbose Config Version Info */
  388. skb = btbcm_read_verbose_config(hdev);
  389. if (IS_ERR(skb))
  390. return PTR_ERR(skb);
  391. BT_INFO("%s: BCM: chip id %u build %4.4u", hdev->name, skb->data[1],
  392. get_unaligned_le16(skb->data + 5));
  393. kfree_skb(skb);
  394. set_bit(HCI_QUIRK_STRICT_DUPLICATE_FILTER, &hdev->quirks);
  395. return 0;
  396. }
  397. EXPORT_SYMBOL_GPL(btbcm_setup_apple);
  398. MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
  399. MODULE_DESCRIPTION("Bluetooth support for Broadcom devices ver " VERSION);
  400. MODULE_VERSION(VERSION);
  401. MODULE_LICENSE("GPL");