consider HEVC like video
[dvblast.git] / en50221.c
blob792d48a67cd8a39f43d00fdd2fe19cea27cb8ea2
1 /*****************************************************************************
2 * en50221.c : implementation of the transport, session and applications
3 * layers of EN 50 221
4 *****************************************************************************
5 * Copyright (C) 2004-2005, 2010, 2015 VideoLAN
7 * Authors: Christophe Massiot <massiot@via.ecp.fr>
8 * Based on code from libdvbci Copyright (C) 2000 Klaus Schmidinger
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License as published by
12 * the Free Software Foundation; either version 2 of the License, or
13 * (at your option) any later version.
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
20 * You should have received a copy of the GNU General Public License
21 * along with this program; if not, write to the Free Software
22 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston MA 02110-1301, USA.
23 *****************************************************************************/
24 #include "config.h"
26 #ifdef HAVE_DVB_SUPPORT
28 #include <stdlib.h>
29 #include <stdint.h>
30 #include <stdbool.h>
31 #include <stddef.h>
32 #include <stdio.h>
33 #include <unistd.h>
34 #include <string.h>
35 #include <inttypes.h>
36 #include <sys/types.h>
37 #include <sys/stat.h>
38 #include <fcntl.h>
39 #include <sys/ioctl.h>
40 #include <sys/socket.h>
41 #include <netinet/in.h>
42 #include <arpa/inet.h>
43 #include <poll.h>
44 #include <errno.h>
45 #include <time.h>
46 #include <ev.h>
48 /* DVB Card Drivers */
49 #include <linux/dvb/version.h>
50 #include <linux/dvb/dmx.h>
51 #include <linux/dvb/frontend.h>
52 #include <linux/dvb/ca.h>
54 #include <bitstream/mpeg/psi.h>
55 #include <bitstream/dvb/ci.h>
56 #include <bitstream/dvb/si.h>
58 #include "dvblast.h"
59 #include "en50221.h"
60 #include "comm.h"
62 #define TAB_APPEND( count, tab, p ) \
63 if( (count) > 0 ) \
64 { \
65 (tab) = realloc( tab, sizeof( void ** ) * ( (count) + 1 ) ); \
66 } \
67 else \
68 { \
69 (tab) = malloc( sizeof( void ** ) ); \
70 } \
71 (tab)[count] = (p); \
72 (count)++
74 /*****************************************************************************
75 * Local declarations
76 *****************************************************************************/
77 #undef DEBUG_TPDU
78 #define CAM_INIT_TIMEOUT 15000000 /* 15 s */
79 #undef HLCI_WAIT_CAM_READY
80 #define CAPMT_WAIT 100 /* ms */
81 #define CA_POLL_PERIOD 100000 /* 100 ms */
83 typedef struct en50221_msg_t
85 uint8_t *p_data;
86 int i_size;
87 struct en50221_msg_t *p_next;
88 } en50221_msg_t;
90 typedef struct en50221_session_t
92 int i_slot;
93 int i_resource_id;
94 void (* pf_handle)( access_t *, int, uint8_t *, int );
95 void (* pf_close)( access_t *, int );
96 void (* pf_manage)( access_t *, int );
97 void *p_sys;
98 } en50221_session_t;
100 typedef struct ci_slot_t
102 bool b_active;
103 bool b_expect_answer;
104 bool b_has_data;
105 bool b_mmi_expected;
106 bool b_mmi_undisplayed;
108 /* TPDU reception */
109 en50221_msg_t *p_recv;
111 /* TPDU emission */
112 en50221_msg_t *p_send;
113 en50221_msg_t **pp_send_last;
114 uint8_t *p;
116 /* InitSlot timer */
117 struct ev_timer init_watcher;
119 /* SPDUSend callback, if p_spdu is not NULL */
120 /* SessionOpen callback, if not 0 */
121 int i_pending_session_id;
122 } ci_slot_t;
124 int i_ca_handle = 0;
125 int i_ca_type = -1;
127 static struct ev_io cam_watcher;
128 static struct ev_timer slot_watcher;
129 static int i_nb_slots = 0;
130 static ci_slot_t p_slots[MAX_CI_SLOTS];
131 static en50221_session_t p_sessions[MAX_SESSIONS];
133 /*****************************************************************************
134 * Local prototypes
135 *****************************************************************************/
136 static void SessionOpenCb( access_t *p_access, uint8_t i_slot );
137 static void SPDUHandle( access_t * p_access, uint8_t i_slot,
138 uint8_t *p_spdu, int i_size );
140 static void ResourceManagerOpen( access_t * p_access, int i_session_id );
141 static void ApplicationInformationOpen( access_t * p_access, int i_session_id );
142 static void ConditionalAccessOpen( access_t * p_access, int i_session_id );
143 static void DateTimeOpen( access_t * p_access, int i_session_id );
144 static void ResetSlotCb(struct ev_loop *loop, struct ev_timer *w, int revents);
145 static void en50221_Read(struct ev_loop *loop, struct ev_io *w, int revents);
146 static void en50221_Poll(struct ev_loop *loop, struct ev_timer *w, int revents);
147 static void MMIOpen( access_t * p_access, int i_session_id );
149 /*****************************************************************************
150 * Utility functions
151 *****************************************************************************/
152 #define SIZE_INDICATOR 0x80
154 static uint8_t *GetLength( uint8_t *p_data, int *pi_length )
156 *pi_length = *p_data++;
158 if ( (*pi_length & SIZE_INDICATOR) != 0 )
160 int l = *pi_length & ~SIZE_INDICATOR;
161 int i;
163 *pi_length = 0;
164 for ( i = 0; i < l; i++ )
165 *pi_length = (*pi_length << 8) | *p_data++;
168 return p_data;
171 static uint8_t *SetLength( uint8_t *p_data, int i_length )
173 uint8_t *p = p_data;
175 if ( i_length < 128 )
177 *p++ = i_length;
179 else if ( i_length < 256 )
181 *p++ = SIZE_INDICATOR | 0x1;
182 *p++ = i_length;
184 else if ( i_length < 65536 )
186 *p++ = SIZE_INDICATOR | 0x2;
187 *p++ = i_length >> 8;
188 *p++ = i_length & 0xff;
190 else if ( i_length < 16777216 )
192 *p++ = SIZE_INDICATOR | 0x3;
193 *p++ = i_length >> 16;
194 *p++ = (i_length >> 8) & 0xff;
195 *p++ = i_length & 0xff;
197 else
199 *p++ = SIZE_INDICATOR | 0x4;
200 *p++ = i_length >> 24;
201 *p++ = (i_length >> 16) & 0xff;
202 *p++ = (i_length >> 8) & 0xff;
203 *p++ = i_length & 0xff;
206 return p;
211 * Transport layer
214 #define MAX_TPDU_SIZE 4096
215 #define MAX_TPDU_DATA (MAX_TPDU_SIZE - 7)
217 #define DATA_INDICATOR 0x80
219 #define T_SB 0x80
220 #define T_RCV 0x81
221 #define T_CREATE_TC 0x82
222 #define T_CTC_REPLY 0x83
223 #define T_DELETE_TC 0x84
224 #define T_DTC_REPLY 0x85
225 #define T_REQUEST_TC 0x86
226 #define T_NEW_TC 0x87
227 #define T_TC_ERROR 0x88
228 #define T_DATA_LAST 0xA0
229 #define T_DATA_MORE 0xA1
231 static void Dump( bool b_outgoing, uint8_t *p_data, int i_size )
233 #ifdef DEBUG_TPDU
234 int i;
235 #define MAX_DUMP 256
236 fprintf(stderr, "%s ", b_outgoing ? "-->" : "<--");
237 for ( i = 0; i < i_size && i < MAX_DUMP; i++)
238 fprintf(stderr, "%02X ", p_data[i]);
239 fprintf(stderr, "%s\n", i_size >= MAX_DUMP ? "..." : "");
240 #endif
243 /*****************************************************************************
244 * TPDUWrite
245 *****************************************************************************/
246 static int TPDUWrite( access_t * p_access, uint8_t i_slot )
248 ci_slot_t *p_slot = &p_slots[i_slot];
249 en50221_msg_t *p_send = p_slot->p_send;
251 if ( p_slot->b_expect_answer )
252 msg_Warn( p_access,
253 "en50221: writing while expecting an answer on slot %u",
254 i_slot );
255 if ( p_send == NULL )
257 msg_Warn( p_access, "en50221: no data to write on slot %u !", i_slot );
258 return -1;
260 p_slot->p_send = p_send->p_next;
261 if ( p_slot->p_send == NULL )
262 p_slot->pp_send_last = &p_slot->p_send;
264 Dump( true, p_send->p_data, p_send->i_size );
266 if ( write( i_ca_handle, p_send->p_data, p_send->i_size )
267 != p_send->i_size )
269 msg_Err( p_access, "en50221: cannot write to CAM device (%m)" );
270 free( p_send->p_data );
271 free( p_send );
272 return -1;
275 free( p_send->p_data );
276 free( p_send );
277 p_slot->b_expect_answer = true;
279 return 0;
282 /*****************************************************************************
283 * TPDUSend
284 *****************************************************************************/
285 static int TPDUSend( access_t * p_access, uint8_t i_slot, uint8_t i_tag,
286 const uint8_t *p_content, int i_length )
288 ci_slot_t *p_slot = &p_slots[i_slot];
289 uint8_t i_tcid = i_slot + 1;
290 en50221_msg_t *p_send = malloc( sizeof(en50221_msg_t) );
291 uint8_t *p_data = malloc( MAX_TPDU_SIZE );
292 int i_size;
294 i_size = 0;
295 p_data[0] = i_slot;
296 p_data[1] = i_tcid;
297 p_data[2] = i_tag;
299 switch ( i_tag )
301 case T_RCV:
302 case T_CREATE_TC:
303 case T_CTC_REPLY:
304 case T_DELETE_TC:
305 case T_DTC_REPLY:
306 case T_REQUEST_TC:
307 p_data[3] = 1; /* length */
308 p_data[4] = i_tcid;
309 i_size = 5;
310 break;
312 case T_NEW_TC:
313 case T_TC_ERROR:
314 p_data[3] = 2; /* length */
315 p_data[4] = i_tcid;
316 p_data[5] = p_content[0];
317 i_size = 6;
318 break;
320 case T_DATA_LAST:
321 case T_DATA_MORE:
323 /* i_length <= MAX_TPDU_DATA */
324 uint8_t *p = p_data + 3;
325 p = SetLength( p, i_length + 1 );
326 *p++ = i_tcid;
328 if ( i_length )
329 memcpy( p, p_content, i_length );
330 i_size = i_length + (p - p_data);
331 break;
334 default:
335 break;
338 p_send->p_data = p_data;
339 p_send->i_size = i_size;
340 p_send->p_next = NULL;
342 *p_slot->pp_send_last = p_send;
343 p_slot->pp_send_last = &p_send->p_next;
345 if ( !p_slot->b_expect_answer )
346 return TPDUWrite( p_access, i_slot );
348 return 0;
352 /*****************************************************************************
353 * TPDURecv
354 *****************************************************************************/
355 static int TPDURecv( access_t * p_access )
357 ci_slot_t *p_slot;
358 uint8_t i_tag, i_slot;
359 uint8_t p_data[MAX_TPDU_SIZE];
360 int i_size;
361 bool b_last = false;
365 i_size = read( i_ca_handle, p_data, MAX_TPDU_SIZE );
367 while ( i_size < 0 && errno == EINTR );
369 if ( i_size < 5 )
371 msg_Err( p_access, "en50221: cannot read from CAM device (%d:%m)",
372 i_size );
373 return -1;
376 Dump( false, p_data, i_size );
378 i_slot = p_data[1] - 1;
379 i_tag = p_data[2];
381 if ( i_slot >= i_nb_slots )
383 msg_Warn( p_access, "en50221: TPDU is from an unknown slot %u",
384 i_slot );
385 return -1;
387 p_slot = &p_slots[i_slot];
389 p_slot->b_has_data = !!(p_data[i_size - 4] == T_SB
390 && p_data[i_size - 3] == 2
391 && (p_data[i_size - 1] & DATA_INDICATOR));
392 p_slot->b_expect_answer = false;
394 switch ( i_tag )
396 case T_CTC_REPLY:
397 p_slot->b_active = true;
398 ev_timer_stop(event_loop, &p_slot->init_watcher);
399 msg_Dbg( p_access, "CI slot %d is active", i_slot );
400 break;
402 case T_SB:
403 break;
405 case T_DATA_LAST:
406 b_last = true;
407 /* intended pass-through */
408 case T_DATA_MORE:
410 en50221_msg_t *p_recv;
411 int i_session_size;
412 uint8_t *p_session = GetLength( &p_data[3], &i_session_size );
414 if ( i_session_size <= 1 )
415 break;
416 p_session++;
417 i_session_size--;
419 if ( p_slot->p_recv == NULL )
421 p_slot->p_recv = malloc( sizeof(en50221_msg_t) );
422 p_slot->p_recv->p_data = NULL;
423 p_slot->p_recv->i_size = 0;
426 p_recv = p_slot->p_recv;
427 p_recv->p_data = realloc( p_recv->p_data,
428 p_recv->i_size + i_session_size );
429 memcpy( &p_recv->p_data[ p_recv->i_size ], p_session, i_session_size );
430 p_recv->i_size += i_session_size;
432 if ( b_last )
434 SPDUHandle( p_access, i_slot, p_recv->p_data, p_recv->i_size );
435 free( p_recv->p_data );
436 free( p_recv );
437 p_slot->p_recv = NULL;
439 break;
442 default:
443 msg_Warn( p_access, "en50221: unhandled R_TPDU tag %u slot %u", i_tag,
444 i_slot );
445 break;
448 if ( !p_slot->b_expect_answer && p_slot->p_send != NULL )
449 TPDUWrite( p_access, i_slot );
450 if ( !p_slot->b_expect_answer && p_slot->i_pending_session_id != 0 )
451 SessionOpenCb( p_access, i_slot );
452 if ( !p_slot->b_expect_answer && p_slot->b_has_data )
453 TPDUSend( p_access, i_slot, T_RCV, NULL, 0 );
455 return 0;
460 * Session layer
463 #define ST_SESSION_NUMBER 0x90
464 #define ST_OPEN_SESSION_REQUEST 0x91
465 #define ST_OPEN_SESSION_RESPONSE 0x92
466 #define ST_CREATE_SESSION 0x93
467 #define ST_CREATE_SESSION_RESPONSE 0x94
468 #define ST_CLOSE_SESSION_REQUEST 0x95
469 #define ST_CLOSE_SESSION_RESPONSE 0x96
471 #define SS_OK 0x00
472 #define SS_NOT_ALLOCATED 0xF0
474 #define RI_RESOURCE_MANAGER 0x00010041
475 #define RI_APPLICATION_INFORMATION 0x00020041
476 #define RI_CONDITIONAL_ACCESS_SUPPORT 0x00030041
477 #define RI_HOST_CONTROL 0x00200041
478 #define RI_DATE_TIME 0x00240041
479 #define RI_MMI 0x00400041
481 static int ResourceIdToInt( uint8_t *p_data )
483 return ((int)p_data[0] << 24) | ((int)p_data[1] << 16)
484 | ((int)p_data[2] << 8) | p_data[3];
487 /*****************************************************************************
488 * SPDUSend
489 *****************************************************************************/
490 static int SPDUSend( access_t *p_access, int i_session_id,
491 uint8_t *p_data, int i_size )
493 uint8_t *p_spdu = malloc( i_size + 4 );
494 uint8_t *p = p_spdu;
495 uint8_t i_slot = p_sessions[i_session_id - 1].i_slot;
497 *p++ = ST_SESSION_NUMBER;
498 *p++ = 0x02;
499 *p++ = (i_session_id >> 8);
500 *p++ = i_session_id & 0xff;
502 memcpy( p, p_data, i_size );
504 i_size += 4;
505 p = p_spdu;
507 while ( i_size > 0 )
509 if ( i_size > MAX_TPDU_DATA )
511 if ( TPDUSend( p_access, i_slot, T_DATA_MORE, p,
512 MAX_TPDU_DATA ) != 0 )
514 msg_Err( p_access, "couldn't send TPDU on session %d",
515 i_session_id );
516 free( p_spdu );
517 return -1;
519 p += MAX_TPDU_DATA;
520 i_size -= MAX_TPDU_DATA;
522 else
524 if ( TPDUSend( p_access, i_slot, T_DATA_LAST, p, i_size )
525 != 0 )
527 msg_Err( p_access, "couldn't send TPDU on session %d",
528 i_session_id );
529 free( p_spdu );
530 return -1;
532 i_size = 0;
536 free( p_spdu );
537 return 0;
540 /*****************************************************************************
541 * SessionOpen
542 *****************************************************************************/
543 static void SessionOpenCb( access_t *p_access, uint8_t i_slot )
545 ci_slot_t *p_slot = &p_slots[i_slot];
546 int i_session_id = p_slot->i_pending_session_id;
547 int i_resource_id = p_sessions[i_session_id - 1].i_resource_id;
549 p_slot->i_pending_session_id = 0;
551 switch ( i_resource_id )
553 case RI_RESOURCE_MANAGER:
554 ResourceManagerOpen( p_access, i_session_id ); break;
555 case RI_APPLICATION_INFORMATION:
556 ApplicationInformationOpen( p_access, i_session_id ); break;
557 case RI_CONDITIONAL_ACCESS_SUPPORT:
558 ConditionalAccessOpen( p_access, i_session_id ); break;
559 case RI_DATE_TIME:
560 DateTimeOpen( p_access, i_session_id ); break;
561 case RI_MMI:
562 MMIOpen( p_access, i_session_id ); break;
564 case RI_HOST_CONTROL:
565 default:
566 msg_Err( p_access, "unknown resource id (0x%x)", i_resource_id );
567 p_sessions[i_session_id - 1].i_resource_id = 0;
571 static void SessionOpen( access_t * p_access, uint8_t i_slot,
572 uint8_t *p_spdu, int i_size )
574 ci_slot_t *p_slot = &p_slots[i_slot];
575 int i_session_id;
576 int i_resource_id = ResourceIdToInt( &p_spdu[2] );
577 uint8_t p_response[16];
578 int i_status = SS_NOT_ALLOCATED;
580 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
582 if ( !p_sessions[i_session_id - 1].i_resource_id )
583 break;
585 if ( i_session_id > MAX_SESSIONS )
587 msg_Err( p_access, "too many sessions !" );
588 return;
590 p_sessions[i_session_id - 1].i_slot = i_slot;
591 p_sessions[i_session_id - 1].i_resource_id = i_resource_id;
592 p_sessions[i_session_id - 1].pf_close = NULL;
593 p_sessions[i_session_id - 1].pf_manage = NULL;
595 if ( i_resource_id == RI_RESOURCE_MANAGER
596 || i_resource_id == RI_APPLICATION_INFORMATION
597 || i_resource_id == RI_CONDITIONAL_ACCESS_SUPPORT
598 || i_resource_id == RI_DATE_TIME
599 || i_resource_id == RI_MMI )
601 i_status = SS_OK;
604 p_response[0] = ST_OPEN_SESSION_RESPONSE;
605 p_response[1] = 0x7;
606 p_response[2] = i_status;
607 p_response[3] = p_spdu[2];
608 p_response[4] = p_spdu[3];
609 p_response[5] = p_spdu[4];
610 p_response[6] = p_spdu[5];
611 p_response[7] = i_session_id >> 8;
612 p_response[8] = i_session_id & 0xff;
614 if ( TPDUSend( p_access, i_slot, T_DATA_LAST, p_response, 9 ) != 0 )
616 msg_Err( p_access,
617 "SessionOpen: couldn't send TPDU on slot %d", i_slot );
618 return;
621 if ( p_slot->i_pending_session_id != 0 )
622 msg_Warn( p_access, "overwriting pending session %d",
623 p_slot->i_pending_session_id );
624 p_slot->i_pending_session_id = i_session_id;
627 #if 0
628 /* unused code for the moment - commented out to keep gcc happy */
629 /*****************************************************************************
630 * SessionCreate
631 *****************************************************************************/
632 static void SessionCreate( access_t * p_access, int i_slot, int i_resource_id )
634 uint8_t p_response[16];
635 uint8_t i_tag;
636 int i_session_id;
638 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
640 if ( !p_sessions[i_session_id - 1].i_resource_id )
641 break;
643 if ( i_session_id > MAX_SESSIONS )
645 msg_Err( p_access, "too many sessions !" );
646 return;
648 p_sessions[i_session_id - 1].i_slot = i_slot;
649 p_sessions[i_session_id - 1].i_resource_id = i_resource_id;
650 p_sessions[i_session_id - 1].pf_close = NULL;
651 p_sessions[i_session_id - 1].pf_manage = NULL;
652 p_sessions[i_session_id - 1].p_sys = NULL;
654 p_response[0] = ST_CREATE_SESSION;
655 p_response[1] = 0x6;
656 p_response[2] = i_resource_id >> 24;
657 p_response[3] = (i_resource_id >> 16) & 0xff;
658 p_response[4] = (i_resource_id >> 8) & 0xff;
659 p_response[5] = i_resource_id & 0xff;
660 p_response[6] = i_session_id >> 8;
661 p_response[7] = i_session_id & 0xff;
663 if ( TPDUSend( p_access, i_slot, T_DATA_LAST, p_response, 4 ) !=
666 msg_Err( p_access,
667 "SessionCreate: couldn't send TPDU on slot %d", i_slot );
668 return;
671 #endif
673 /*****************************************************************************
674 * SessionCreateResponse
675 *****************************************************************************/
676 static void SessionCreateResponse( access_t * p_access, uint8_t i_slot,
677 uint8_t *p_spdu, int i_size )
679 int i_status = p_spdu[2];
680 int i_resource_id = ResourceIdToInt( &p_spdu[3] );
681 int i_session_id = ((int)p_spdu[7] << 8) | p_spdu[8];
683 if ( i_status != SS_OK )
685 msg_Err( p_access, "SessionCreateResponse: failed to open session %d"
686 " resource=0x%x status=0x%x", i_session_id, i_resource_id,
687 i_status );
688 p_sessions[i_session_id - 1].i_resource_id = 0;
689 return;
692 switch ( i_resource_id )
694 case RI_RESOURCE_MANAGER:
695 ResourceManagerOpen( p_access, i_session_id ); break;
696 case RI_APPLICATION_INFORMATION:
697 ApplicationInformationOpen( p_access, i_session_id ); break;
698 case RI_CONDITIONAL_ACCESS_SUPPORT:
699 ConditionalAccessOpen( p_access, i_session_id ); break;
700 case RI_DATE_TIME:
701 DateTimeOpen( p_access, i_session_id ); break;
702 case RI_MMI:
703 MMIOpen( p_access, i_session_id ); break;
705 case RI_HOST_CONTROL:
706 default:
707 msg_Err( p_access, "unknown resource id (0x%x)", i_resource_id );
708 p_sessions[i_session_id - 1].i_resource_id = 0;
712 /*****************************************************************************
713 * SessionSendClose
714 *****************************************************************************/
715 static void SessionSendClose( access_t * p_access, int i_session_id )
717 uint8_t p_response[16];
718 uint8_t i_slot = p_sessions[i_session_id - 1].i_slot;
720 p_response[0] = ST_CLOSE_SESSION_REQUEST;
721 p_response[1] = 0x2;
722 p_response[2] = i_session_id >> 8;
723 p_response[3] = i_session_id & 0xff;
725 if ( TPDUSend( p_access, i_slot, T_DATA_LAST, p_response, 4 ) !=
728 msg_Err( p_access,
729 "SessionSendClose: couldn't send TPDU on slot %d", i_slot );
730 return;
734 /*****************************************************************************
735 * SessionClose
736 *****************************************************************************/
737 static void SessionClose( access_t * p_access, int i_session_id )
739 uint8_t p_response[16];
740 uint8_t i_slot = p_sessions[i_session_id - 1].i_slot;
742 if ( p_sessions[i_session_id - 1].pf_close != NULL )
743 p_sessions[i_session_id - 1].pf_close( p_access, i_session_id );
744 p_sessions[i_session_id - 1].i_resource_id = 0;
746 p_response[0] = ST_CLOSE_SESSION_RESPONSE;
747 p_response[1] = 0x3;
748 p_response[2] = SS_OK;
749 p_response[3] = i_session_id >> 8;
750 p_response[4] = i_session_id & 0xff;
752 if ( TPDUSend( p_access, i_slot, T_DATA_LAST, p_response, 5 ) !=
755 msg_Err( p_access,
756 "SessionClose: couldn't send TPDU on slot %d", i_slot );
757 return;
761 /*****************************************************************************
762 * SPDUHandle
763 *****************************************************************************/
764 static void SPDUHandle( access_t * p_access, uint8_t i_slot,
765 uint8_t *p_spdu, int i_size )
767 int i_session_id;
769 switch ( p_spdu[0] )
771 case ST_SESSION_NUMBER:
772 if ( i_size <= 4 )
773 return;
774 i_session_id = (p_spdu[2] << 8) | p_spdu[3];
775 if ( i_session_id <= MAX_SESSIONS
776 && p_sessions[i_session_id - 1].pf_handle != NULL )
777 p_sessions[i_session_id - 1].pf_handle( p_access, i_session_id,
778 p_spdu + 4, i_size - 4 );
779 break;
781 case ST_OPEN_SESSION_REQUEST:
782 if ( i_size != 6 || p_spdu[1] != 0x4 )
783 return;
784 SessionOpen( p_access, i_slot, p_spdu, i_size );
785 break;
787 case ST_CREATE_SESSION_RESPONSE:
788 if ( i_size != 9 || p_spdu[1] != 0x7 )
789 return;
790 SessionCreateResponse( p_access, i_slot, p_spdu, i_size );
791 break;
793 case ST_CLOSE_SESSION_REQUEST:
794 if ( i_size != 4 || p_spdu[1] != 0x2 )
795 return;
796 i_session_id = ((int)p_spdu[2] << 8) | p_spdu[3];
797 SessionClose( p_access, i_session_id );
798 break;
800 case ST_CLOSE_SESSION_RESPONSE:
801 if ( i_size != 5 || p_spdu[1] != 0x3 )
802 return;
803 i_session_id = ((int)p_spdu[3] << 8) | p_spdu[4];
804 if ( p_spdu[2] )
806 msg_Err( p_access, "closing a session which is not allocated (%d)",
807 i_session_id );
809 else
811 if ( p_sessions[i_session_id - 1].pf_close != NULL )
812 p_sessions[i_session_id - 1].pf_close( p_access,
813 i_session_id );
814 p_sessions[i_session_id - 1].i_resource_id = 0;
816 break;
818 default:
819 msg_Err( p_access, "unexpected tag in SPDUHandle (%x)", p_spdu[0] );
820 break;
826 * Application layer
829 #define AOT_NONE 0x000000
830 #define AOT_PROFILE_ENQ 0x9F8010
831 #define AOT_PROFILE 0x9F8011
832 #define AOT_PROFILE_CHANGE 0x9F8012
833 #define AOT_APPLICATION_INFO_ENQ 0x9F8020
834 #define AOT_APPLICATION_INFO 0x9F8021
835 #define AOT_ENTER_MENU 0x9F8022
836 #define AOT_CA_INFO_ENQ 0x9F8030
837 #define AOT_CA_INFO 0x9F8031
838 #define AOT_CA_PMT 0x9F8032
839 #define AOT_CA_PMT_REPLY 0x9F8033
840 #define AOT_CA_UPDATE 0x9F8034
841 #define AOT_TUNE 0x9F8400
842 #define AOT_REPLACE 0x9F8401
843 #define AOT_CLEAR_REPLACE 0x9F8402
844 #define AOT_ASK_RELEASE 0x9F8403
845 #define AOT_DATE_TIME_ENQ 0x9F8440
846 #define AOT_DATE_TIME 0x9F8441
847 #define AOT_CLOSE_MMI 0x9F8800
848 #define AOT_DISPLAY_CONTROL 0x9F8801
849 #define AOT_DISPLAY_REPLY 0x9F8802
850 #define AOT_TEXT_LAST 0x9F8803
851 #define AOT_TEXT_MORE 0x9F8804
852 #define AOT_KEYPAD_CONTROL 0x9F8805
853 #define AOT_KEYPRESS 0x9F8806
854 #define AOT_ENQ 0x9F8807
855 #define AOT_ANSW 0x9F8808
856 #define AOT_MENU_LAST 0x9F8809
857 #define AOT_MENU_MORE 0x9F880A
858 #define AOT_MENU_ANSW 0x9F880B
859 #define AOT_LIST_LAST 0x9F880C
860 #define AOT_LIST_MORE 0x9F880D
861 #define AOT_SUBTITLE_SEGMENT_LAST 0x9F880E
862 #define AOT_SUBTITLE_SEGMENT_MORE 0x9F880F
863 #define AOT_DISPLAY_MESSAGE 0x9F8810
864 #define AOT_SCENE_END_MARK 0x9F8811
865 #define AOT_SCENE_DONE 0x9F8812
866 #define AOT_SCENE_CONTROL 0x9F8813
867 #define AOT_SUBTITLE_DOWNLOAD_LAST 0x9F8814
868 #define AOT_SUBTITLE_DOWNLOAD_MORE 0x9F8815
869 #define AOT_FLUSH_DOWNLOAD 0x9F8816
870 #define AOT_DOWNLOAD_REPLY 0x9F8817
871 #define AOT_COMMS_CMD 0x9F8C00
872 #define AOT_CONNECTION_DESCRIPTOR 0x9F8C01
873 #define AOT_COMMS_REPLY 0x9F8C02
874 #define AOT_COMMS_SEND_LAST 0x9F8C03
875 #define AOT_COMMS_SEND_MORE 0x9F8C04
876 #define AOT_COMMS_RCV_LAST 0x9F8C05
877 #define AOT_COMMS_RCV_MORE 0x9F8C06
879 /*****************************************************************************
880 * APDUGetTag
881 *****************************************************************************/
882 static int APDUGetTag( const uint8_t *p_apdu, int i_size )
884 if ( i_size >= 3 )
886 int i, t = 0;
887 for ( i = 0; i < 3; i++ )
888 t = (t << 8) | *p_apdu++;
889 return t;
892 return AOT_NONE;
895 /*****************************************************************************
896 * APDUGetLength
897 *****************************************************************************/
898 static uint8_t *APDUGetLength( uint8_t *p_apdu, int *pi_size )
900 return GetLength( &p_apdu[3], pi_size );
903 /*****************************************************************************
904 * APDUSend
905 *****************************************************************************/
906 static int APDUSend( access_t * p_access, int i_session_id, int i_tag,
907 uint8_t *p_data, int i_size )
909 uint8_t *p_apdu = malloc( i_size + 12 );
910 uint8_t *p = p_apdu;
911 ca_msg_t ca_msg;
912 int i_ret;
914 *p++ = (i_tag >> 16);
915 *p++ = (i_tag >> 8) & 0xff;
916 *p++ = i_tag & 0xff;
917 p = SetLength( p, i_size );
918 if ( i_size )
919 memcpy( p, p_data, i_size );
920 if ( i_ca_type == CA_CI_LINK )
922 i_ret = SPDUSend( p_access, i_session_id, p_apdu, i_size + p - p_apdu );
924 else
926 if ( i_size + p - p_apdu > 256 )
928 msg_Err( p_access, "CAM: apdu overflow" );
929 i_ret = -1;
931 else
933 ca_msg.length = i_size + p - p_apdu;
934 if ( i_size == 0 ) ca_msg.length=3;
935 memcpy( ca_msg.msg, p_apdu, i_size + p - p_apdu );
936 i_ret = ioctl(i_ca_handle, CA_SEND_MSG, &ca_msg );
937 if ( i_ret < 0 )
939 msg_Err( p_access, "Error sending to CAM: %m" );
940 i_ret = -1;
944 free( p_apdu );
945 return i_ret;
949 * Resource Manager
952 /*****************************************************************************
953 * ResourceManagerHandle
954 *****************************************************************************/
955 static void ResourceManagerHandle( access_t * p_access, int i_session_id,
956 uint8_t *p_apdu, int i_size )
958 int i_tag = APDUGetTag( p_apdu, i_size );
960 switch ( i_tag )
962 case AOT_PROFILE_ENQ:
964 int resources[] = { htonl(RI_RESOURCE_MANAGER),
965 htonl(RI_APPLICATION_INFORMATION),
966 htonl(RI_CONDITIONAL_ACCESS_SUPPORT),
967 htonl(RI_DATE_TIME),
968 htonl(RI_MMI)
970 APDUSend( p_access, i_session_id, AOT_PROFILE, (uint8_t*)resources,
971 sizeof(resources) );
972 break;
974 case AOT_PROFILE:
975 APDUSend( p_access, i_session_id, AOT_PROFILE_CHANGE, NULL, 0 );
976 break;
978 default:
979 msg_Err( p_access, "unexpected tag in ResourceManagerHandle (0x%x)",
980 i_tag );
984 /*****************************************************************************
985 * ResourceManagerOpen
986 *****************************************************************************/
987 static void ResourceManagerOpen( access_t * p_access, int i_session_id )
990 msg_Dbg( p_access, "opening ResourceManager session (%d)", i_session_id );
992 p_sessions[i_session_id - 1].pf_handle = ResourceManagerHandle;
994 APDUSend( p_access, i_session_id, AOT_PROFILE_ENQ, NULL, 0 );
998 * Application Information
1001 /*****************************************************************************
1002 * ApplicationInformationEnterMenu
1003 *****************************************************************************/
1004 static void ApplicationInformationEnterMenu( access_t * p_access,
1005 int i_session_id )
1007 int i_slot = p_sessions[i_session_id - 1].i_slot;
1009 msg_Dbg( p_access, "entering MMI menus on session %d", i_session_id );
1010 APDUSend( p_access, i_session_id, AOT_ENTER_MENU, NULL, 0 );
1011 p_slots[i_slot].b_mmi_expected = true;
1014 /*****************************************************************************
1015 * ApplicationInformationHandle
1016 *****************************************************************************/
1017 static void ApplicationInformationHandle( access_t * p_access, int i_session_id,
1018 uint8_t *p_apdu, int i_size )
1020 int i_tag = APDUGetTag( p_apdu, i_size );
1022 switch ( i_tag )
1024 case AOT_APPLICATION_INFO:
1026 int i_type, i_manufacturer, i_code;
1027 int l = 0;
1028 uint8_t *d = APDUGetLength( p_apdu, &l );
1030 if ( l < 4 ) break;
1032 i_type = *d++;
1033 i_manufacturer = ((int)d[0] << 8) | d[1];
1034 d += 2;
1035 i_code = ((int)d[0] << 8) | d[1];
1036 d += 2;
1037 d = GetLength( d, &l );
1040 char *psz_name = malloc(l + 1);
1041 memcpy( psz_name, d, l );
1042 psz_name[l] = '\0';
1043 msg_Info( p_access, "CAM: %s, %02X, %04X, %04X",
1044 psz_name, i_type, i_manufacturer, i_code );
1045 switch (i_print_type)
1047 case PRINT_XML:
1048 psz_name = dvb_string_xml_escape(psz_name);
1049 fprintf(print_fh, "<STATUS type=\"cam\" status=\"1\" cam_name=\"%s\" cam_type=\"%d\" cam_manufacturer=\"%d\" cam_product=\"%d\" />\n",
1050 psz_name, i_type, i_manufacturer, i_code);
1051 break;
1052 case PRINT_TEXT:
1053 fprintf(print_fh, "CAM name: %s type: %d manufacturer: %d product: %d\n",
1054 psz_name, i_type, i_manufacturer, i_code);
1055 break;
1056 default:
1057 break;
1059 free(psz_name);
1061 break;
1063 default:
1064 msg_Err( p_access,
1065 "unexpected tag in ApplicationInformationHandle (0x%x)",
1066 i_tag );
1070 /*****************************************************************************
1071 * ApplicationInformationOpen
1072 *****************************************************************************/
1073 static void ApplicationInformationOpen( access_t * p_access, int i_session_id )
1076 msg_Dbg( p_access, "opening ApplicationInformation session (%d)", i_session_id );
1078 p_sessions[i_session_id - 1].pf_handle = ApplicationInformationHandle;
1080 APDUSend( p_access, i_session_id, AOT_APPLICATION_INFO_ENQ, NULL, 0 );
1084 * Conditional Access
1087 typedef struct
1089 int i_nb_system_ids;
1090 uint16_t *pi_system_ids;
1092 int i_selected_programs;
1093 int b_high_level;
1094 } system_ids_t;
1096 static bool CheckSystemID( system_ids_t *p_ids, uint16_t i_id )
1098 int i;
1099 if( p_ids == NULL ) return false;
1100 if( p_ids->b_high_level ) return true;
1102 for ( i = 0; i < p_ids->i_nb_system_ids; i++ )
1103 if ( p_ids->pi_system_ids[i] == i_id )
1104 return true;
1106 return false;
1109 /*****************************************************************************
1110 * CAPMTBuild
1111 *****************************************************************************/
1112 static bool HasCADescriptors( system_ids_t *p_ids, uint8_t *p_descs )
1114 const uint8_t *p_desc;
1115 uint16_t j = 0;
1117 while ( (p_desc = descs_get_desc( p_descs, j )) != NULL )
1119 uint8_t i_tag = desc_get_tag( p_desc );
1120 j++;
1122 if ( i_tag == 0x9 && desc09_validate( p_desc )
1123 && CheckSystemID( p_ids, desc09_get_sysid( p_desc ) ) )
1124 return true;
1127 return false;
1130 static void CopyCADescriptors( system_ids_t *p_ids, uint8_t i_cmd,
1131 uint8_t *p_infos, uint8_t *p_descs )
1133 const uint8_t *p_desc;
1134 uint16_t j = 0, k = 0;
1136 capmti_init( p_infos );
1137 capmti_set_length( p_infos, 0xfff );
1138 capmti_set_cmd( p_infos, i_cmd );
1140 while ( (p_desc = descs_get_desc( p_descs, j )) != NULL )
1142 uint8_t i_tag = desc_get_tag( p_desc );
1143 j++;
1145 if ( i_tag == 0x9 && desc09_validate( p_desc )
1146 && CheckSystemID( p_ids, desc09_get_sysid( p_desc ) ) )
1148 uint8_t *p_info = capmti_get_info( p_infos, k );
1149 k++;
1150 memcpy( p_info, p_desc,
1151 DESC_HEADER_SIZE + desc_get_length( p_desc ) );
1155 if ( k )
1157 uint8_t *p_info = capmti_get_info( p_infos, k );
1158 capmti_set_length( p_infos, p_info - p_infos - DESCS_HEADER_SIZE );
1160 else
1161 capmti_set_length( p_infos, 0 );
1164 static uint8_t *CAPMTBuild( access_t * p_access, int i_session_id,
1165 uint8_t *p_pmt, uint8_t i_list_mgt,
1166 uint8_t i_cmd, int *pi_capmt_size )
1168 system_ids_t *p_ids =
1169 (system_ids_t *)p_sessions[i_session_id - 1].p_sys;
1170 uint8_t *p_es;
1171 uint8_t *p_capmt, *p_capmt_n;
1172 uint16_t j, k;
1173 bool b_has_ca = HasCADescriptors( p_ids, pmt_get_descs( p_pmt ) );
1174 bool b_has_es = false;
1176 j = 0;
1177 while ( (p_es = pmt_get_es( p_pmt, j )) != NULL )
1179 uint16_t i_pid = pmtn_get_pid( p_es );
1180 j++;
1182 if ( demux_PIDIsSelected( i_pid ) )
1184 b_has_es = true;
1185 b_has_ca = b_has_ca
1186 || HasCADescriptors( p_ids, pmtn_get_descs( p_es ) );
1190 if ( !b_has_es )
1192 *pi_capmt_size = 0;
1193 return NULL;
1196 if ( !b_has_ca )
1198 msg_Warn( p_access,
1199 "no compatible scrambling system for SID %d on session %d",
1200 pmt_get_program( p_pmt ), i_session_id );
1201 *pi_capmt_size = 0;
1202 return NULL;
1205 p_capmt = capmt_allocate();
1206 capmt_init( p_capmt );
1207 capmt_set_listmanagement( p_capmt, i_list_mgt );
1208 capmt_set_program( p_capmt, pmt_get_program( p_pmt ) );
1209 capmt_set_version( p_capmt, psi_get_version( p_pmt ) );
1211 CopyCADescriptors( p_ids, i_cmd, capmt_get_infos( p_capmt ),
1212 pmt_get_descs( p_pmt ) );
1214 j = 0; k = 0;
1215 while ( (p_es = pmt_get_es( p_pmt, j )) != NULL )
1217 uint16_t i_pid = pmtn_get_pid( p_es );
1218 j++;
1220 if ( !demux_PIDIsSelected( i_pid ) )
1221 continue;
1223 p_capmt_n = capmt_get_es( p_capmt, k );
1224 k++;
1226 capmtn_init( p_capmt_n );
1227 capmtn_set_streamtype( p_capmt_n, pmtn_get_streamtype( p_es ) );
1228 capmtn_set_pid( p_capmt_n, pmtn_get_pid( p_es ) );
1230 CopyCADescriptors( p_ids, i_cmd, capmtn_get_infos( p_capmt_n ),
1231 pmtn_get_descs( p_es ) );
1234 p_capmt_n = capmt_get_es( p_capmt, k );
1235 *pi_capmt_size = p_capmt_n - p_capmt;
1237 return p_capmt;
1240 /*****************************************************************************
1241 * CAPMTFirst
1242 *****************************************************************************/
1243 static void CAPMTFirst( access_t * p_access, int i_session_id, uint8_t *p_pmt )
1245 uint8_t *p_capmt;
1246 int i_capmt_size;
1248 msg_Dbg( p_access, "adding first CAPMT for SID %d on session %d",
1249 pmt_get_program( p_pmt ), i_session_id );
1251 p_capmt = CAPMTBuild( p_access, i_session_id, p_pmt,
1252 0x3 /* only */, 0x1 /* ok_descrambling */,
1253 &i_capmt_size );
1255 if ( i_capmt_size )
1257 APDUSend( p_access, i_session_id, AOT_CA_PMT, p_capmt, i_capmt_size );
1258 free( p_capmt );
1262 /*****************************************************************************
1263 * CAPMTAdd
1264 *****************************************************************************/
1265 static void CAPMTAdd( access_t * p_access, int i_session_id, uint8_t *p_pmt )
1267 system_ids_t *p_ids =
1268 (system_ids_t *)p_sessions[i_session_id - 1].p_sys;
1269 uint8_t *p_capmt;
1270 int i_capmt_size;
1272 p_ids->i_selected_programs++;
1273 if( p_ids->i_selected_programs == 1 )
1275 CAPMTFirst( p_access, i_session_id, p_pmt );
1276 return;
1279 msg_Dbg( p_access, "adding CAPMT for SID %d on session %d",
1280 pmt_get_program( p_pmt ), i_session_id );
1282 p_capmt = CAPMTBuild( p_access, i_session_id, p_pmt,
1283 0x4 /* add */, 0x1 /* ok_descrambling */,
1284 &i_capmt_size );
1286 if ( i_capmt_size )
1288 APDUSend( p_access, i_session_id, AOT_CA_PMT, p_capmt, i_capmt_size );
1289 free( p_capmt );
1293 /*****************************************************************************
1294 * CAPMTUpdate
1295 *****************************************************************************/
1296 static void CAPMTUpdate( access_t * p_access, int i_session_id, uint8_t *p_pmt )
1298 uint8_t *p_capmt;
1299 int i_capmt_size;
1301 msg_Dbg( p_access, "updating CAPMT for SID %d on session %d",
1302 pmt_get_program( p_pmt ), i_session_id );
1304 p_capmt = CAPMTBuild( p_access, i_session_id, p_pmt,
1305 0x5 /* update */, 0x1 /* ok_descrambling */,
1306 &i_capmt_size );
1308 if ( i_capmt_size )
1310 APDUSend( p_access, i_session_id, AOT_CA_PMT, p_capmt, i_capmt_size );
1311 free( p_capmt );
1315 /*****************************************************************************
1316 * CAPMTDelete
1317 *****************************************************************************/
1318 static void CAPMTDelete( access_t * p_access, int i_session_id, uint8_t *p_pmt )
1320 system_ids_t *p_ids =
1321 (system_ids_t *)p_sessions[i_session_id - 1].p_sys;
1322 uint8_t *p_capmt;
1323 int i_capmt_size;
1325 p_ids->i_selected_programs--;
1326 msg_Dbg( p_access, "deleting CAPMT for SID %d on session %d",
1327 pmt_get_program( p_pmt ), i_session_id );
1329 p_capmt = CAPMTBuild( p_access, i_session_id, p_pmt,
1330 0x5 /* update */, 0x4 /* not selected */,
1331 &i_capmt_size );
1333 if ( i_capmt_size )
1335 APDUSend( p_access, i_session_id, AOT_CA_PMT, p_capmt, i_capmt_size );
1336 free( p_capmt );
1340 /*****************************************************************************
1341 * ConditionalAccessHandle
1342 *****************************************************************************/
1343 static void ConditionalAccessHandle( access_t * p_access, int i_session_id,
1344 uint8_t *p_apdu, int i_size )
1346 system_ids_t *p_ids =
1347 (system_ids_t *)p_sessions[i_session_id - 1].p_sys;
1348 int i_tag = APDUGetTag( p_apdu, i_size );
1350 switch ( i_tag )
1352 case AOT_CA_INFO:
1354 int i;
1355 int l = 0;
1356 uint8_t *d = APDUGetLength( p_apdu, &l );
1357 msg_Dbg( p_access, "CA system IDs supported by the application :" );
1359 if ( p_ids->i_nb_system_ids )
1360 free( p_ids->pi_system_ids );
1361 p_ids->i_nb_system_ids = l / 2;
1362 p_ids->pi_system_ids = malloc( p_ids->i_nb_system_ids
1363 * sizeof(uint16_t) );
1365 for ( i = 0; i < p_ids->i_nb_system_ids; i++ )
1367 p_ids->pi_system_ids[i] = ((uint16_t)d[0] << 8) | d[1];
1368 d += 2;
1369 msg_Dbg( p_access, "- 0x%x", p_ids->pi_system_ids[i] );
1372 demux_ResendCAPMTs();
1373 break;
1376 case AOT_CA_UPDATE:
1377 /* http://www.cablelabs.com/specifications/OC-SP-HOSTPOD-IF-I08-011221.pdf */
1378 case AOT_CA_PMT_REPLY:
1379 /* We do not care */
1380 break;
1382 default:
1383 msg_Err( p_access,
1384 "unexpected tag in ConditionalAccessHandle (0x%x)",
1385 i_tag );
1389 /*****************************************************************************
1390 * ConditionalAccessClose
1391 *****************************************************************************/
1392 static void ConditionalAccessClose( access_t * p_access, int i_session_id )
1395 msg_Dbg( p_access, "closing ConditionalAccess session (%d)", i_session_id );
1397 free( p_sessions[i_session_id - 1].p_sys );
1400 /*****************************************************************************
1401 * ConditionalAccessOpen
1402 *****************************************************************************/
1403 static void ConditionalAccessOpen( access_t * p_access, int i_session_id )
1406 msg_Dbg( p_access, "opening ConditionalAccess session (%d)", i_session_id );
1408 p_sessions[i_session_id - 1].pf_handle = ConditionalAccessHandle;
1409 p_sessions[i_session_id - 1].pf_close = ConditionalAccessClose;
1410 p_sessions[i_session_id - 1].p_sys = malloc(sizeof(system_ids_t));
1411 memset( p_sessions[i_session_id - 1].p_sys, 0,
1412 sizeof(system_ids_t) );
1414 APDUSend( p_access, i_session_id, AOT_CA_INFO_ENQ, NULL, 0 );
1418 * Date Time
1421 typedef struct
1423 int i_session_id;
1424 int i_interval;
1425 struct ev_timer watcher;
1426 } date_time_t;
1428 /*****************************************************************************
1429 * DateTimeSend
1430 *****************************************************************************/
1431 static void DateTimeSend( access_t * p_access, int i_session_id )
1433 date_time_t *p_date =
1434 (date_time_t *)p_sessions[i_session_id - 1].p_sys;
1436 time_t t = time(NULL);
1437 struct tm tm_gmt;
1438 struct tm tm_loc;
1440 if ( gmtime_r(&t, &tm_gmt) && localtime_r(&t, &tm_loc) )
1442 int Y = tm_gmt.tm_year;
1443 int M = tm_gmt.tm_mon + 1;
1444 int D = tm_gmt.tm_mday;
1445 int L = (M == 1 || M == 2) ? 1 : 0;
1446 int MJD = 14956 + D + (int)((Y - L) * 365.25)
1447 + (int)((M + 1 + L * 12) * 30.6001);
1448 uint8_t p_response[7];
1450 #define DEC2BCD(d) (((d / 10) << 4) + (d % 10))
1452 p_response[0] = htons(MJD) >> 8;
1453 p_response[1] = htons(MJD) & 0xff;
1454 p_response[2] = DEC2BCD(tm_gmt.tm_hour);
1455 p_response[3] = DEC2BCD(tm_gmt.tm_min);
1456 p_response[4] = DEC2BCD(tm_gmt.tm_sec);
1457 p_response[5] = htons(tm_loc.tm_gmtoff / 60) >> 8;
1458 p_response[6] = htons(tm_loc.tm_gmtoff / 60) & 0xff;
1460 APDUSend( p_access, i_session_id, AOT_DATE_TIME, p_response, 7 );
1462 ev_timer_again(event_loop, &p_date->watcher);
1466 static void _DateTimeSend(struct ev_loop *loop, struct ev_timer *w, int revents)
1468 date_time_t *p_date = container_of(w, date_time_t, watcher);
1469 DateTimeSend( NULL, p_date->i_session_id );
1472 /*****************************************************************************
1473 * DateTimeHandle
1474 *****************************************************************************/
1475 static void DateTimeHandle( access_t * p_access, int i_session_id,
1476 uint8_t *p_apdu, int i_size )
1478 date_time_t *p_date =
1479 (date_time_t *)p_sessions[i_session_id - 1].p_sys;
1481 int i_tag = APDUGetTag( p_apdu, i_size );
1483 switch ( i_tag )
1485 case AOT_DATE_TIME_ENQ:
1487 int l;
1488 const uint8_t *d = APDUGetLength( p_apdu, &l );
1490 if ( l > 0 )
1492 p_date->i_interval = *d;
1493 msg_Dbg( p_access, "DateTimeHandle : interval set to %d",
1494 p_date->i_interval );
1496 else
1497 p_date->i_interval = 0;
1499 ev_timer_stop(event_loop, &p_date->watcher);
1500 ev_timer_set(&p_date->watcher, p_date->i_interval,
1501 p_date->i_interval);
1502 DateTimeSend( p_access, i_session_id );
1503 break;
1505 default:
1506 msg_Err( p_access, "unexpected tag in DateTimeHandle (0x%x)", i_tag );
1510 /*****************************************************************************
1511 * DateTimeClose
1512 *****************************************************************************/
1513 static void DateTimeClose( access_t * p_access, int i_session_id )
1515 date_time_t *p_date =
1516 (date_time_t *)p_sessions[i_session_id - 1].p_sys;
1517 ev_timer_stop(event_loop, &p_date->watcher);
1519 msg_Dbg( p_access, "closing DateTime session (%d)", i_session_id );
1521 free( p_date );
1524 /*****************************************************************************
1525 * DateTimeOpen
1526 *****************************************************************************/
1527 static void DateTimeOpen( access_t * p_access, int i_session_id )
1529 msg_Dbg( p_access, "opening DateTime session (%d)", i_session_id );
1531 p_sessions[i_session_id - 1].pf_handle = DateTimeHandle;
1532 p_sessions[i_session_id - 1].pf_manage = NULL;
1533 p_sessions[i_session_id - 1].pf_close = DateTimeClose;
1534 p_sessions[i_session_id - 1].p_sys = malloc(sizeof(date_time_t));
1535 memset( p_sessions[i_session_id - 1].p_sys, 0, sizeof(date_time_t) );
1537 date_time_t *p_date =
1538 (date_time_t *)p_sessions[i_session_id - 1].p_sys;
1539 p_date->i_session_id = i_session_id;
1540 ev_timer_init(&p_date->watcher, _DateTimeSend, 0, 0);
1542 DateTimeSend( p_access, i_session_id );
1546 * MMI
1549 /* Display Control Commands */
1551 #define DCC_SET_MMI_MODE 0x01
1552 #define DCC_DISPLAY_CHARACTER_TABLE_LIST 0x02
1553 #define DCC_INPUT_CHARACTER_TABLE_LIST 0x03
1554 #define DCC_OVERLAY_GRAPHICS_CHARACTERISTICS 0x04
1555 #define DCC_FULL_SCREEN_GRAPHICS_CHARACTERISTICS 0x05
1557 /* MMI Modes */
1559 #define MM_HIGH_LEVEL 0x01
1560 #define MM_LOW_LEVEL_OVERLAY_GRAPHICS 0x02
1561 #define MM_LOW_LEVEL_FULL_SCREEN_GRAPHICS 0x03
1563 /* Display Reply IDs */
1565 #define DRI_MMI_MODE_ACK 0x01
1566 #define DRI_LIST_DISPLAY_CHARACTER_TABLES 0x02
1567 #define DRI_LIST_INPUT_CHARACTER_TABLES 0x03
1568 #define DRI_LIST_GRAPHIC_OVERLAY_CHARACTERISTICS 0x04
1569 #define DRI_LIST_FULL_SCREEN_GRAPHIC_CHARACTERISTICS 0x05
1570 #define DRI_UNKNOWN_DISPLAY_CONTROL_CMD 0xF0
1571 #define DRI_UNKNOWN_MMI_MODE 0xF1
1572 #define DRI_UNKNOWN_CHARACTER_TABLE 0xF2
1574 /* Enquiry Flags */
1576 #define EF_BLIND 0x01
1578 /* Answer IDs */
1580 #define AI_CANCEL 0x00
1581 #define AI_ANSWER 0x01
1583 typedef struct
1585 en50221_mmi_object_t last_object;
1586 } mmi_t;
1588 static inline void en50221_MMIFree( en50221_mmi_object_t *p_object )
1590 int i;
1592 switch ( p_object->i_object_type )
1594 case EN50221_MMI_ENQ:
1595 free( p_object->u.enq.psz_text );
1596 break;
1598 case EN50221_MMI_ANSW:
1599 if ( p_object->u.answ.b_ok )
1601 free( p_object->u.answ.psz_answ );
1603 break;
1605 case EN50221_MMI_MENU:
1606 case EN50221_MMI_LIST:
1607 free( p_object->u.menu.psz_title );
1608 free( p_object->u.menu.psz_subtitle );
1609 free( p_object->u.menu.psz_bottom );
1610 for ( i = 0; i < p_object->u.menu.i_choices; i++ )
1612 free( p_object->u.menu.ppsz_choices[i] );
1614 free( p_object->u.menu.ppsz_choices );
1615 break;
1617 default:
1618 break;
1622 /*****************************************************************************
1623 * MMISendObject
1624 *****************************************************************************/
1625 static void MMISendObject( access_t *p_access, int i_session_id,
1626 en50221_mmi_object_t *p_object )
1628 int i_slot = p_sessions[i_session_id - 1].i_slot;
1629 uint8_t *p_data;
1630 int i_size, i_tag;
1632 switch ( p_object->i_object_type )
1634 case EN50221_MMI_ANSW:
1635 i_tag = AOT_ANSW;
1636 i_size = 1 + strlen( p_object->u.answ.psz_answ );
1637 p_data = malloc( i_size );
1638 p_data[0] = (p_object->u.answ.b_ok == true) ? 0x1 : 0x0;
1639 strncpy( (char *)&p_data[1], p_object->u.answ.psz_answ, i_size - 1 );
1640 break;
1642 case EN50221_MMI_MENU_ANSW:
1643 i_tag = AOT_MENU_ANSW;
1644 i_size = 1;
1645 p_data = malloc( i_size );
1646 p_data[0] = p_object->u.menu_answ.i_choice;
1647 break;
1649 default:
1650 msg_Err( p_access, "unknown MMI object %d", p_object->i_object_type );
1651 return;
1654 APDUSend( p_access, i_session_id, i_tag, p_data, i_size );
1655 free( p_data );
1657 p_slots[i_slot].b_mmi_expected = true;
1660 /*****************************************************************************
1661 * MMISendClose
1662 *****************************************************************************/
1663 static void MMISendClose( access_t *p_access, int i_session_id )
1665 int i_slot = p_sessions[i_session_id - 1].i_slot;
1667 APDUSend( p_access, i_session_id, AOT_CLOSE_MMI, NULL, 0 );
1669 p_slots[i_slot].b_mmi_expected = true;
1672 /*****************************************************************************
1673 * MMIDisplayReply
1674 *****************************************************************************/
1675 static void MMIDisplayReply( access_t *p_access, int i_session_id )
1677 uint8_t p_response[2];
1679 p_response[0] = DRI_MMI_MODE_ACK;
1680 p_response[1] = MM_HIGH_LEVEL;
1682 APDUSend( p_access, i_session_id, AOT_DISPLAY_REPLY, p_response, 2 );
1684 msg_Dbg( p_access, "sending DisplayReply on session (%d)", i_session_id );
1687 /*****************************************************************************
1688 * MMIGetText
1689 *****************************************************************************/
1690 static char *MMIGetText( access_t *p_access, uint8_t **pp_apdu, int *pi_size )
1692 int i_tag = APDUGetTag( *pp_apdu, *pi_size );
1693 int l;
1694 uint8_t *d;
1696 if ( i_tag != AOT_TEXT_LAST )
1698 msg_Err( p_access, "unexpected text tag: %06x", i_tag );
1699 *pi_size = 0;
1700 return strdup( "" );
1703 d = APDUGetLength( *pp_apdu, &l );
1705 *pp_apdu += l + 4;
1706 *pi_size -= l + 4;
1708 return dvb_string_get( d, l, demux_Iconv, p_access );
1711 /*****************************************************************************
1712 * MMIHandleEnq
1713 *****************************************************************************/
1714 static void MMIHandleEnq( access_t *p_access, int i_session_id,
1715 uint8_t *p_apdu, int i_size )
1717 mmi_t *p_mmi = (mmi_t *)p_sessions[i_session_id - 1].p_sys;
1718 int i_slot = p_sessions[i_session_id - 1].i_slot;
1719 int l;
1720 uint8_t *d = APDUGetLength( p_apdu, &l );
1722 en50221_MMIFree( &p_mmi->last_object );
1723 p_mmi->last_object.i_object_type = EN50221_MMI_ENQ;
1724 p_mmi->last_object.u.enq.b_blind = (*d & 0x1) ? true : false;
1725 d += 2; /* skip answer_text_length because it is not mandatory */
1726 l -= 2;
1727 p_mmi->last_object.u.enq.psz_text = malloc( l + 1 );
1728 strncpy( p_mmi->last_object.u.enq.psz_text, (char *)d, l );
1729 p_mmi->last_object.u.enq.psz_text[l] = '\0';
1731 msg_Dbg( p_access, "MMI enq: %s%s", p_mmi->last_object.u.enq.psz_text,
1732 p_mmi->last_object.u.enq.b_blind == true ? " (blind)" : "" );
1734 p_slots[i_slot].b_mmi_expected = false;
1735 p_slots[i_slot].b_mmi_undisplayed = true;
1738 /*****************************************************************************
1739 * MMIHandleMenu
1740 *****************************************************************************/
1741 static void MMIHandleMenu( access_t *p_access, int i_session_id, int i_tag,
1742 uint8_t *p_apdu, int i_size )
1744 mmi_t *p_mmi = (mmi_t *)p_sessions[i_session_id - 1].p_sys;
1745 int i_slot = p_sessions[i_session_id - 1].i_slot;
1746 int l;
1747 uint8_t *d = APDUGetLength( p_apdu, &l );
1749 en50221_MMIFree( &p_mmi->last_object );
1750 p_mmi->last_object.i_object_type = (i_tag == AOT_MENU_LAST) ?
1751 EN50221_MMI_MENU : EN50221_MMI_LIST;
1752 p_mmi->last_object.u.menu.i_choices = 0;
1753 p_mmi->last_object.u.menu.ppsz_choices = NULL;
1755 if ( l > 0 )
1757 l--; d++; /* choice_nb */
1759 #define GET_FIELD( x ) \
1760 if ( l > 0 ) \
1762 p_mmi->last_object.u.menu.psz_##x \
1763 = MMIGetText( p_access, &d, &l ); \
1764 msg_Dbg( p_access, "MMI " STRINGIFY( x ) ": %s", \
1765 p_mmi->last_object.u.menu.psz_##x ); \
1768 GET_FIELD( title );
1769 GET_FIELD( subtitle );
1770 GET_FIELD( bottom );
1771 #undef GET_FIELD
1773 while ( l > 0 )
1775 char *psz_text = MMIGetText( p_access, &d, &l );
1776 TAB_APPEND( p_mmi->last_object.u.menu.i_choices,
1777 p_mmi->last_object.u.menu.ppsz_choices,
1778 psz_text );
1779 msg_Dbg( p_access, "MMI choice: %s", psz_text );
1783 p_slots[i_slot].b_mmi_expected = false;
1784 p_slots[i_slot].b_mmi_undisplayed = true;
1787 /*****************************************************************************
1788 * MMIHandle
1789 *****************************************************************************/
1790 static void MMIHandle( access_t *p_access, int i_session_id,
1791 uint8_t *p_apdu, int i_size )
1793 int i_tag = APDUGetTag( p_apdu, i_size );
1795 switch ( i_tag )
1797 case AOT_DISPLAY_CONTROL:
1799 int l;
1800 uint8_t *d = APDUGetLength( p_apdu, &l );
1802 if ( l > 0 )
1804 switch ( *d )
1806 case DCC_SET_MMI_MODE:
1807 if ( l == 2 && d[1] == MM_HIGH_LEVEL )
1808 MMIDisplayReply( p_access, i_session_id );
1809 else
1810 msg_Err( p_access, "unsupported MMI mode %02x", d[1] );
1811 break;
1813 default:
1814 msg_Err( p_access, "unsupported display control command %02x",
1815 *d );
1816 break;
1819 break;
1822 case AOT_ENQ:
1823 MMIHandleEnq( p_access, i_session_id, p_apdu, i_size );
1824 break;
1826 case AOT_LIST_LAST:
1827 case AOT_MENU_LAST:
1828 MMIHandleMenu( p_access, i_session_id, i_tag, p_apdu, i_size );
1829 break;
1831 case AOT_CLOSE_MMI:
1832 SessionSendClose( p_access, i_session_id );
1833 break;
1835 default:
1836 msg_Err( p_access, "unexpected tag in MMIHandle (0x%x)", i_tag );
1840 /*****************************************************************************
1841 * MMIClose
1842 *****************************************************************************/
1843 static void MMIClose( access_t *p_access, int i_session_id )
1845 int i_slot = p_sessions[i_session_id - 1].i_slot;
1846 mmi_t *p_mmi = (mmi_t *)p_sessions[i_session_id - 1].p_sys;
1848 en50221_MMIFree( &p_mmi->last_object );
1849 free( p_sessions[i_session_id - 1].p_sys );
1851 msg_Dbg( p_access, "closing MMI session (%d)", i_session_id );
1853 p_slots[i_slot].b_mmi_expected = false;
1854 p_slots[i_slot].b_mmi_undisplayed = true;
1857 /*****************************************************************************
1858 * MMIOpen
1859 *****************************************************************************/
1860 static void MMIOpen( access_t *p_access, int i_session_id )
1862 mmi_t *p_mmi;
1864 msg_Dbg( p_access, "opening MMI session (%d)", i_session_id );
1866 p_sessions[i_session_id - 1].pf_handle = MMIHandle;
1867 p_sessions[i_session_id - 1].pf_close = MMIClose;
1868 p_sessions[i_session_id - 1].p_sys = malloc(sizeof(mmi_t));
1869 p_mmi = (mmi_t *)p_sessions[i_session_id - 1].p_sys;
1870 p_mmi->last_object.i_object_type = EN50221_MMI_NONE;
1875 * Hardware handling
1878 /*****************************************************************************
1879 * InitSlot: Open the transport layer
1880 *****************************************************************************/
1881 static void InitSlot( access_t * p_access, int i_slot )
1883 if ( TPDUSend( p_access, i_slot, T_CREATE_TC, NULL, 0 ) != 0 )
1884 msg_Err( p_access, "en50221_Init: couldn't send TPDU on slot %d",
1885 i_slot );
1888 /*****************************************************************************
1889 * ResetSlot
1890 *****************************************************************************/
1891 static void ResetSlot( int i_slot )
1893 ci_slot_t *p_slot = &p_slots[i_slot];
1894 int i_session_id;
1896 switch (i_print_type)
1898 case PRINT_XML:
1899 fprintf(print_fh, "<STATUS type=\"cam\" status=\"0\" />\n");
1900 break;
1901 case PRINT_TEXT:
1902 fprintf(print_fh, "CAM none\n");
1903 break;
1904 default:
1905 break;
1908 if ( ioctl( i_ca_handle, CA_RESET, 1 << i_slot ) != 0 )
1909 msg_Err( NULL, "en50221_Poll: couldn't reset slot %d", i_slot );
1910 p_slot->b_active = false;
1911 ev_timer_init(&p_slot->init_watcher, ResetSlotCb,
1912 CAM_INIT_TIMEOUT / 1000000., 0);
1913 ev_timer_start(event_loop, &p_slot->init_watcher);
1914 p_slot->b_expect_answer = false;
1915 p_slot->b_mmi_expected = false;
1916 p_slot->b_mmi_undisplayed = false;
1917 if ( p_slot->p_recv != NULL )
1919 free( p_slot->p_recv->p_data );
1920 free( p_slot->p_recv );
1922 p_slot->p_recv = NULL;
1923 while ( p_slot->p_send != NULL )
1925 en50221_msg_t *p_next = p_slot->p_send->p_next;
1926 free( p_slot->p_send->p_data );
1927 free( p_slot->p_send );
1928 p_slot->p_send = p_next;
1930 p_slot->pp_send_last = &p_slot->p_send;
1932 /* Close all sessions for this slot. */
1933 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
1935 if ( p_sessions[i_session_id - 1].i_resource_id
1936 && p_sessions[i_session_id - 1].i_slot == i_slot )
1938 if ( p_sessions[i_session_id - 1].pf_close != NULL )
1940 p_sessions[i_session_id - 1].pf_close( NULL, i_session_id );
1942 p_sessions[i_session_id - 1].i_resource_id = 0;
1947 static void ResetSlotCb(struct ev_loop *loop, struct ev_timer *w, int revents)
1949 ci_slot_t *p_slot = container_of(w, ci_slot_t, init_watcher);
1950 int i_slot = p_slot - &p_slots[0];
1952 if ( p_slot->b_active || !p_slot->b_expect_answer )
1953 return;
1955 msg_Warn( NULL, "no answer from CAM, resetting slot %d",
1956 i_slot );
1957 switch (i_print_type) {
1958 case PRINT_XML:
1959 fprintf(print_fh,
1960 "<EVENT type=\"reset\" cause=\"cam_mute\" />\n");
1961 break;
1962 case PRINT_TEXT:
1963 fprintf(print_fh, "reset cause: cam_mute\n");
1964 break;
1965 default:
1966 break;
1969 ResetSlot( i_slot );
1974 * External entry points
1977 /*****************************************************************************
1978 * en50221_Init : Initialize the CAM for en50221
1979 *****************************************************************************/
1980 void en50221_Init( void )
1982 char psz_tmp[128];
1983 ca_caps_t caps;
1985 memset( &caps, 0, sizeof( ca_caps_t ));
1987 sprintf( psz_tmp, "/dev/dvb/adapter%d/ca%d", i_adapter, i_canum );
1988 if( (i_ca_handle = open(psz_tmp, O_RDWR | O_NONBLOCK)) < 0 )
1990 msg_Warn( NULL, "failed opening CAM device %s (%s)",
1991 psz_tmp, strerror(errno) );
1992 i_ca_handle = 0;
1993 return;
1996 if ( ioctl( i_ca_handle, CA_GET_CAP, &caps ) != 0 )
1998 msg_Err( NULL, "failed getting CAM capabilities (%s)",
1999 strerror(errno) );
2000 close( i_ca_handle );
2001 i_ca_handle = 0;
2002 return;
2005 /* Output CA capabilities */
2006 msg_Dbg( NULL, "CA interface with %d %s", caps.slot_num,
2007 caps.slot_num == 1 ? "slot" : "slots" );
2008 if ( caps.slot_type & CA_CI )
2009 msg_Dbg( NULL, " CI high level interface type" );
2010 if ( caps.slot_type & CA_CI_LINK )
2011 msg_Dbg( NULL, " CI link layer level interface type" );
2012 if ( caps.slot_type & CA_CI_PHYS )
2013 msg_Dbg( NULL, " CI physical layer level interface type (not supported) " );
2014 if ( caps.slot_type & CA_DESCR )
2015 msg_Dbg( NULL, " built-in descrambler detected" );
2016 if ( caps.slot_type & CA_SC )
2017 msg_Dbg( NULL, " simple smart card interface" );
2019 msg_Dbg( NULL, " %d available %s", caps.descr_num,
2020 caps.descr_num == 1 ? "descrambler (key)" : "descramblers (keys)" );
2021 if ( caps.descr_type & CA_ECD )
2022 msg_Dbg( NULL, " ECD scrambling system supported" );
2023 if ( caps.descr_type & CA_NDS )
2024 msg_Dbg( NULL, " NDS scrambling system supported" );
2025 if ( caps.descr_type & CA_DSS )
2026 msg_Dbg( NULL, " DSS scrambling system supported" );
2028 if ( caps.slot_num == 0 )
2030 msg_Err( NULL, "CAM module with no slots" );
2031 close( i_ca_handle );
2032 i_ca_handle = 0;
2033 return;
2036 if( caps.slot_type & CA_CI_LINK )
2037 i_ca_type = CA_CI_LINK;
2038 else if( caps.slot_type & CA_CI )
2039 i_ca_type = CA_CI;
2040 else
2042 msg_Err( NULL, "Incompatible CAM interface" );
2043 close( i_ca_handle );
2044 i_ca_handle = 0;
2045 return;
2048 i_nb_slots = caps.slot_num;
2049 memset( p_sessions, 0, sizeof(en50221_session_t) * MAX_SESSIONS );
2051 if( i_ca_type & CA_CI_LINK )
2053 ev_io_init(&cam_watcher, en50221_Read, i_ca_handle, EV_READ);
2054 ev_io_start(event_loop, &cam_watcher);
2056 ev_timer_init(&slot_watcher, en50221_Poll, CA_POLL_PERIOD / 1000000.,
2057 CA_POLL_PERIOD / 1000000.);
2058 ev_timer_start(event_loop, &slot_watcher);
2061 en50221_Reset();
2064 /*****************************************************************************
2065 * en50221_Reset : Reset the CAM for en50221
2066 *****************************************************************************/
2067 void en50221_Reset( void )
2069 memset( p_slots, 0, sizeof(ci_slot_t) * MAX_CI_SLOTS );
2071 if( i_ca_type & CA_CI_LINK )
2073 int i_slot;
2074 for ( i_slot = 0; i_slot < i_nb_slots; i_slot++ )
2075 ResetSlot( i_slot );
2077 else
2079 struct ca_slot_info info;
2080 system_ids_t *p_ids;
2081 ca_msg_t ca_msg;
2082 info.num = 0;
2084 /* We don't reset the CAM in that case because it's done by the
2085 * ASIC. */
2086 if ( ioctl( i_ca_handle, CA_GET_SLOT_INFO, &info ) < 0 )
2088 msg_Err( NULL, "en50221_Init: couldn't get slot info" );
2089 close( i_ca_handle );
2090 i_ca_handle = 0;
2091 return;
2093 if( info.flags == 0 )
2095 msg_Err( NULL, "en50221_Init: no CAM inserted" );
2096 close( i_ca_handle );
2097 i_ca_handle = 0;
2098 return;
2101 /* Allocate a dummy sessions */
2102 p_sessions[0].i_resource_id = RI_CONDITIONAL_ACCESS_SUPPORT;
2103 p_sessions[0].pf_close = ConditionalAccessClose;
2104 if ( p_sessions[0].p_sys == NULL )
2105 p_sessions[0].p_sys = malloc(sizeof(system_ids_t));
2106 memset( p_sessions[0].p_sys, 0, sizeof(system_ids_t) );
2107 p_ids = (system_ids_t *)p_sessions[0].p_sys;
2108 p_ids->b_high_level = 1;
2110 /* Get application info to find out which cam we are using and make
2111 sure everything is ready to play */
2112 ca_msg.length=3;
2113 ca_msg.msg[0] = ( AOT_APPLICATION_INFO & 0xFF0000 ) >> 16;
2114 ca_msg.msg[1] = ( AOT_APPLICATION_INFO & 0x00FF00 ) >> 8;
2115 ca_msg.msg[2] = ( AOT_APPLICATION_INFO & 0x0000FF ) >> 0;
2116 memset( &ca_msg.msg[3], 0, 253 );
2117 APDUSend( NULL, 1, AOT_APPLICATION_INFO_ENQ, NULL, 0 );
2118 if ( ioctl( i_ca_handle, CA_GET_MSG, &ca_msg ) < 0 )
2120 msg_Err( NULL, "en50221_Init: failed getting message" );
2121 close( i_ca_handle );
2122 i_ca_handle = 0;
2123 return;
2126 #ifdef HLCI_WAIT_CAM_READY
2127 while( ca_msg.msg[8] == 0xff && ca_msg.msg[9] == 0xff )
2129 msleep(1);
2130 msg_Dbg( NULL, "CAM: please wait" );
2131 APDUSend( NULL, 1, AOT_APPLICATION_INFO_ENQ, NULL, 0 );
2132 ca_msg.length=3;
2133 ca_msg.msg[0] = ( AOT_APPLICATION_INFO & 0xFF0000 ) >> 16;
2134 ca_msg.msg[1] = ( AOT_APPLICATION_INFO & 0x00FF00 ) >> 8;
2135 ca_msg.msg[2] = ( AOT_APPLICATION_INFO & 0x0000FF ) >> 0;
2136 memset( &ca_msg.msg[3], 0, 253 );
2137 if ( ioctl( i_ca_handle, CA_GET_MSG, &ca_msg ) < 0 )
2139 msg_Err( NULL, "en50221_Init: failed getting message" );
2140 close( i_ca_handle );
2141 i_ca_handle = 0;
2142 return;
2144 msg_Dbg( NULL, "en50221_Init: Got length: %d, tag: 0x%x", ca_msg.length, APDUGetTag( ca_msg.msg, ca_msg.length ) );
2146 #else
2147 if( ca_msg.msg[8] == 0xff && ca_msg.msg[9] == 0xff )
2149 msg_Err( NULL, "CAM returns garbage as application info!" );
2150 close( i_ca_handle );
2151 i_ca_handle = 0;
2152 return;
2154 #endif
2155 msg_Dbg( NULL, "found CAM %s using id 0x%x", &ca_msg.msg[12],
2156 (ca_msg.msg[8]<<8)|ca_msg.msg[9] );
2160 /*****************************************************************************
2161 * en50221_Read : Read the CAM for a TPDU
2162 *****************************************************************************/
2163 static void en50221_Read(struct ev_loop *loop, struct ev_io *w, int revents)
2165 TPDURecv( NULL );
2167 ev_timer_again(event_loop, &slot_watcher);
2170 /*****************************************************************************
2171 * en50221_Poll : Send a poll TPDU to the CAM
2172 *****************************************************************************/
2173 static void en50221_Poll(struct ev_loop *loop, struct ev_timer *w, int revents)
2175 int i_slot;
2176 int i_session_id;
2178 /* Check module status */
2179 for ( i_slot = 0; i_slot < i_nb_slots; i_slot++ )
2181 ci_slot_t *p_slot = &p_slots[i_slot];
2182 ca_slot_info_t sinfo;
2184 sinfo.num = i_slot;
2185 if ( ioctl( i_ca_handle, CA_GET_SLOT_INFO, &sinfo ) != 0 )
2187 msg_Err( NULL, "en50221_Poll: couldn't get info on slot %d",
2188 i_slot );
2189 continue;
2192 if ( !(sinfo.flags & CA_CI_MODULE_READY) )
2194 if ( p_slot->b_active )
2196 msg_Dbg( NULL, "en50221_Poll: slot %d has been removed",
2197 i_slot );
2198 ResetSlot( i_slot );
2201 else if ( !p_slot->b_active )
2203 if ( !p_slot->b_expect_answer )
2204 InitSlot( NULL, i_slot );
2208 /* Check if applications have data to send */
2209 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
2211 en50221_session_t *p_session = &p_sessions[i_session_id - 1];
2212 if ( p_session->i_resource_id && p_session->pf_manage != NULL
2213 && !p_slots[ p_session->i_slot ].b_expect_answer )
2214 p_session->pf_manage( NULL, i_session_id );
2217 /* Now send the poll command to inactive slots */
2218 for ( i_slot = 0; i_slot < i_nb_slots; i_slot++ )
2220 ci_slot_t *p_slot = &p_slots[i_slot];
2222 if ( p_slot->b_active && !p_slot->b_expect_answer )
2224 if ( TPDUSend( NULL, i_slot, T_DATA_LAST, NULL, 0 ) != 0 )
2226 msg_Warn( NULL, "couldn't send TPDU, resetting slot %d",
2227 i_slot );
2228 switch (i_print_type) {
2229 case PRINT_XML:
2230 fprintf(print_fh,
2231 "<EVENT type=\"reset\" cause=\"cam_error\" />\n");
2232 break;
2233 case PRINT_TEXT:
2234 fprintf(print_fh, "reset cause: cam_error\n");
2235 break;
2236 default:
2237 break;
2239 ResetSlot( i_slot );
2245 /*****************************************************************************
2246 * en50221_AddPMT :
2247 *****************************************************************************/
2248 void en50221_AddPMT( uint8_t *p_pmt )
2250 int i_session_id;
2252 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
2253 if ( p_sessions[i_session_id - 1].i_resource_id
2254 == RI_CONDITIONAL_ACCESS_SUPPORT )
2255 CAPMTAdd( NULL, i_session_id, p_pmt );
2258 /*****************************************************************************
2259 * en50221_UpdatePMT :
2260 *****************************************************************************/
2261 void en50221_UpdatePMT( uint8_t *p_pmt )
2263 int i_session_id;
2265 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
2266 if ( p_sessions[i_session_id - 1].i_resource_id
2267 == RI_CONDITIONAL_ACCESS_SUPPORT )
2268 CAPMTUpdate( NULL, i_session_id, p_pmt );
2271 /*****************************************************************************
2272 * en50221_DeletePMT :
2273 *****************************************************************************/
2274 void en50221_DeletePMT( uint8_t *p_pmt )
2276 int i_session_id;
2278 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
2279 if ( p_sessions[i_session_id - 1].i_resource_id
2280 == RI_CONDITIONAL_ACCESS_SUPPORT )
2281 CAPMTDelete( NULL, i_session_id, p_pmt );
2284 /*****************************************************************************
2285 * en50221_StatusMMI :
2286 *****************************************************************************/
2287 uint8_t en50221_StatusMMI( uint8_t *p_answer, ssize_t *pi_size )
2289 struct ret_mmi_status *p_ret = (struct ret_mmi_status *)p_answer;
2291 if ( ioctl( i_ca_handle, CA_GET_CAP, &p_ret->caps ) != 0 )
2293 msg_Err( NULL, "ioctl CA_GET_CAP failed (%s)", strerror(errno) );
2294 return RET_ERR;
2297 *pi_size = sizeof(struct ret_mmi_status);
2298 return RET_MMI_STATUS;
2301 /*****************************************************************************
2302 * en50221_StatusMMISlot :
2303 *****************************************************************************/
2304 uint8_t en50221_StatusMMISlot( uint8_t *p_buffer, ssize_t i_size,
2305 uint8_t *p_answer, ssize_t *pi_size )
2307 int i_slot;
2308 struct ret_mmi_slot_status *p_ret = (struct ret_mmi_slot_status *)p_answer;
2310 if ( i_size != 1 ) return RET_HUH;
2311 i_slot = *p_buffer;
2313 p_ret->sinfo.num = i_slot;
2314 if ( ioctl( i_ca_handle, CA_GET_SLOT_INFO, &p_ret->sinfo ) != 0 )
2316 msg_Err( NULL, "ioctl CA_GET_SLOT_INFO failed (%s)", strerror(errno) );
2317 return RET_ERR;
2320 *pi_size = sizeof(struct ret_mmi_slot_status);
2321 return RET_MMI_SLOT_STATUS;
2324 /*****************************************************************************
2325 * en50221_OpenMMI :
2326 *****************************************************************************/
2327 uint8_t en50221_OpenMMI( uint8_t *p_buffer, ssize_t i_size )
2329 int i_slot;
2331 if ( i_size != 1 ) return RET_HUH;
2332 i_slot = *p_buffer;
2334 if( i_ca_type & CA_CI_LINK )
2336 int i_session_id;
2337 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
2339 if ( p_sessions[i_session_id - 1].i_resource_id == RI_MMI
2340 && p_sessions[i_session_id - 1].i_slot == i_slot )
2342 msg_Dbg( NULL,
2343 "MMI menu is already opened on slot %d (session=%d)",
2344 i_slot, i_session_id );
2345 return RET_OK;
2349 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
2351 if ( p_sessions[i_session_id - 1].i_resource_id
2352 == RI_APPLICATION_INFORMATION
2353 && p_sessions[i_session_id - 1].i_slot == i_slot )
2355 ApplicationInformationEnterMenu( NULL, i_session_id );
2356 return RET_OK;
2360 msg_Err( NULL, "no application information on slot %d", i_slot );
2361 return RET_ERR;
2363 else
2365 msg_Err( NULL, "MMI menu not supported" );
2366 return RET_ERR;
2370 /*****************************************************************************
2371 * en50221_CloseMMI :
2372 *****************************************************************************/
2373 uint8_t en50221_CloseMMI( uint8_t *p_buffer, ssize_t i_size )
2375 int i_slot;
2377 if ( i_size != 1 ) return RET_HUH;
2378 i_slot = *p_buffer;
2380 if( i_ca_type & CA_CI_LINK )
2382 int i_session_id;
2383 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
2385 if ( p_sessions[i_session_id - 1].i_resource_id == RI_MMI
2386 && p_sessions[i_session_id - 1].i_slot == i_slot )
2388 MMISendClose( NULL, i_session_id );
2389 return RET_OK;
2393 msg_Warn( NULL, "closing a non-existing MMI session on slot %d",
2394 i_slot );
2395 return RET_ERR;
2397 else
2399 msg_Err( NULL, "MMI menu not supported" );
2400 return RET_ERR;
2404 /*****************************************************************************
2405 * en50221_GetMMIObject :
2406 *****************************************************************************/
2407 uint8_t en50221_GetMMIObject( uint8_t *p_buffer, ssize_t i_size,
2408 uint8_t *p_answer, ssize_t *pi_size )
2410 int i_session_id, i_slot;
2411 struct ret_mmi_recv *p_ret = (struct ret_mmi_recv *)p_answer;
2413 if ( i_size != 1 ) return RET_HUH;
2414 i_slot = *p_buffer;
2416 if ( p_slots[i_slot].b_mmi_expected )
2417 return RET_MMI_WAIT; /* data not yet available */
2419 p_ret->object.i_object_type = EN50221_MMI_NONE;
2420 *pi_size = sizeof(struct ret_mmi_recv);
2422 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
2424 if ( p_sessions[i_session_id - 1].i_resource_id == RI_MMI
2425 && p_sessions[i_session_id - 1].i_slot == i_slot )
2427 mmi_t *p_mmi =
2428 (mmi_t *)p_sessions[i_session_id - 1].p_sys;
2429 if ( p_mmi == NULL )
2431 *pi_size = 0;
2432 return RET_ERR; /* should not happen */
2435 *pi_size = COMM_BUFFER_SIZE - COMM_HEADER_SIZE -
2436 ((void *)&p_ret->object - (void *)p_ret);
2437 if ( en50221_SerializeMMIObject( (uint8_t *)&p_ret->object,
2438 pi_size, &p_mmi->last_object ) == -1 )
2440 *pi_size = 0;
2441 msg_Err( NULL, "MMI structure too big" );
2442 return RET_ERR;
2444 *pi_size += ((void *)&p_ret->object - (void *)p_ret);
2445 break;
2449 return RET_MMI_RECV;
2453 /*****************************************************************************
2454 * en50221_SendMMIObject :
2455 *****************************************************************************/
2456 uint8_t en50221_SendMMIObject( uint8_t *p_buffer, ssize_t i_size )
2458 int i_session_id, i_slot;
2459 struct cmd_mmi_send *p_cmd = (struct cmd_mmi_send *)p_buffer;
2461 if ( i_size < sizeof(struct cmd_mmi_send))
2463 msg_Err( NULL, "command packet too short (%zd)\n", i_size );
2464 return RET_HUH;
2467 if ( en50221_UnserializeMMIObject( &p_cmd->object, i_size -
2468 ((void *)&p_cmd->object - (void *)p_cmd) ) == -1 )
2469 return RET_ERR;
2471 i_slot = p_cmd->i_slot;
2473 for ( i_session_id = 1; i_session_id <= MAX_SESSIONS; i_session_id++ )
2475 if ( p_sessions[i_session_id - 1].i_resource_id == RI_MMI
2476 && p_sessions[i_session_id - 1].i_slot == i_slot )
2478 MMISendObject( NULL, i_session_id, &p_cmd->object );
2479 return RET_OK;
2483 msg_Err( NULL, "SendMMIObject when no MMI session is opened !" );
2484 return RET_ERR;
2487 #else
2488 #include <inttypes.h>
2490 int i_ca_handle = 0;
2491 int i_ca_type = -1;
2493 void en50221_AddPMT( uint8_t *p_pmt ) { };
2494 void en50221_UpdatePMT( uint8_t *p_pmt ) { };
2495 void en50221_DeletePMT( uint8_t *p_pmt ) { };
2496 void en50221_Reset( void ) { };
2497 #endif