KEYS: add missing permission check for request_key() destination
[linux/fpc-iii.git] / net / nfc / nci / ntf.c
blobf8f6af231381b336b111a9c01ce0ccb2dfc72856
1 /*
2 * The NFC Controller Interface is the communication protocol between an
3 * NFC Controller (NFCC) and a Device Host (DH).
5 * Copyright (C) 2011 Texas Instruments, Inc.
7 * Written by Ilan Elias <ilane@ti.com>
9 * Acknowledgements:
10 * This file is based on hci_event.c, which was written
11 * by Maxim Krasnyansky.
13 * This program is free software; you can redistribute it and/or modify
14 * it under the terms of the GNU General Public License version 2
15 * as published by the Free Software Foundation
17 * This program is distributed in the hope that it will be useful,
18 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20 * GNU General Public License for more details.
22 * You should have received a copy of the GNU General Public License
23 * along with this program; if not, see <http://www.gnu.org/licenses/>.
27 #define pr_fmt(fmt) KBUILD_MODNAME ": %s: " fmt, __func__
29 #include <linux/types.h>
30 #include <linux/interrupt.h>
31 #include <linux/bitops.h>
32 #include <linux/skbuff.h>
34 #include "../nfc.h"
35 #include <net/nfc/nci.h>
36 #include <net/nfc/nci_core.h>
37 #include <linux/nfc.h>
39 /* Handle NCI Notification packets */
41 static void nci_core_conn_credits_ntf_packet(struct nci_dev *ndev,
42 struct sk_buff *skb)
44 struct nci_core_conn_credit_ntf *ntf = (void *) skb->data;
45 int i;
47 pr_debug("num_entries %d\n", ntf->num_entries);
49 if (ntf->num_entries > NCI_MAX_NUM_CONN)
50 ntf->num_entries = NCI_MAX_NUM_CONN;
52 /* update the credits */
53 for (i = 0; i < ntf->num_entries; i++) {
54 ntf->conn_entries[i].conn_id =
55 nci_conn_id(&ntf->conn_entries[i].conn_id);
57 pr_debug("entry[%d]: conn_id %d, credits %d\n",
58 i, ntf->conn_entries[i].conn_id,
59 ntf->conn_entries[i].credits);
61 if (ntf->conn_entries[i].conn_id == NCI_STATIC_RF_CONN_ID) {
62 /* found static rf connection */
63 atomic_add(ntf->conn_entries[i].credits,
64 &ndev->credits_cnt);
68 /* trigger the next tx */
69 if (!skb_queue_empty(&ndev->tx_q))
70 queue_work(ndev->tx_wq, &ndev->tx_work);
73 static void nci_core_generic_error_ntf_packet(struct nci_dev *ndev,
74 struct sk_buff *skb)
76 __u8 status = skb->data[0];
78 pr_debug("status 0x%x\n", status);
80 if (atomic_read(&ndev->state) == NCI_W4_HOST_SELECT) {
81 /* Activation failed, so complete the request
82 (the state remains the same) */
83 nci_req_complete(ndev, status);
87 static void nci_core_conn_intf_error_ntf_packet(struct nci_dev *ndev,
88 struct sk_buff *skb)
90 struct nci_core_intf_error_ntf *ntf = (void *) skb->data;
92 ntf->conn_id = nci_conn_id(&ntf->conn_id);
94 pr_debug("status 0x%x, conn_id %d\n", ntf->status, ntf->conn_id);
96 /* complete the data exchange transaction, if exists */
97 if (test_bit(NCI_DATA_EXCHANGE, &ndev->flags))
98 nci_data_exchange_complete(ndev, NULL, -EIO);
101 static __u8 *nci_extract_rf_params_nfca_passive_poll(struct nci_dev *ndev,
102 struct rf_tech_specific_params_nfca_poll *nfca_poll,
103 __u8 *data)
105 nfca_poll->sens_res = __le16_to_cpu(*((__u16 *)data));
106 data += 2;
108 nfca_poll->nfcid1_len = min_t(__u8, *data++, NFC_NFCID1_MAXSIZE);
110 pr_debug("sens_res 0x%x, nfcid1_len %d\n",
111 nfca_poll->sens_res, nfca_poll->nfcid1_len);
113 memcpy(nfca_poll->nfcid1, data, nfca_poll->nfcid1_len);
114 data += nfca_poll->nfcid1_len;
116 nfca_poll->sel_res_len = *data++;
118 if (nfca_poll->sel_res_len != 0)
119 nfca_poll->sel_res = *data++;
121 pr_debug("sel_res_len %d, sel_res 0x%x\n",
122 nfca_poll->sel_res_len,
123 nfca_poll->sel_res);
125 return data;
128 static __u8 *nci_extract_rf_params_nfcb_passive_poll(struct nci_dev *ndev,
129 struct rf_tech_specific_params_nfcb_poll *nfcb_poll,
130 __u8 *data)
132 nfcb_poll->sensb_res_len = min_t(__u8, *data++, NFC_SENSB_RES_MAXSIZE);
134 pr_debug("sensb_res_len %d\n", nfcb_poll->sensb_res_len);
136 memcpy(nfcb_poll->sensb_res, data, nfcb_poll->sensb_res_len);
137 data += nfcb_poll->sensb_res_len;
139 return data;
142 static __u8 *nci_extract_rf_params_nfcf_passive_poll(struct nci_dev *ndev,
143 struct rf_tech_specific_params_nfcf_poll *nfcf_poll,
144 __u8 *data)
146 nfcf_poll->bit_rate = *data++;
147 nfcf_poll->sensf_res_len = min_t(__u8, *data++, NFC_SENSF_RES_MAXSIZE);
149 pr_debug("bit_rate %d, sensf_res_len %d\n",
150 nfcf_poll->bit_rate, nfcf_poll->sensf_res_len);
152 memcpy(nfcf_poll->sensf_res, data, nfcf_poll->sensf_res_len);
153 data += nfcf_poll->sensf_res_len;
155 return data;
158 static int nci_add_new_protocol(struct nci_dev *ndev,
159 struct nfc_target *target,
160 __u8 rf_protocol,
161 __u8 rf_tech_and_mode,
162 void *params)
164 struct rf_tech_specific_params_nfca_poll *nfca_poll;
165 struct rf_tech_specific_params_nfcb_poll *nfcb_poll;
166 struct rf_tech_specific_params_nfcf_poll *nfcf_poll;
167 __u32 protocol;
169 if (rf_protocol == NCI_RF_PROTOCOL_T2T)
170 protocol = NFC_PROTO_MIFARE_MASK;
171 else if (rf_protocol == NCI_RF_PROTOCOL_ISO_DEP)
172 if (rf_tech_and_mode == NCI_NFC_A_PASSIVE_POLL_MODE)
173 protocol = NFC_PROTO_ISO14443_MASK;
174 else
175 protocol = NFC_PROTO_ISO14443_B_MASK;
176 else if (rf_protocol == NCI_RF_PROTOCOL_T3T)
177 protocol = NFC_PROTO_FELICA_MASK;
178 else if (rf_protocol == NCI_RF_PROTOCOL_NFC_DEP)
179 protocol = NFC_PROTO_NFC_DEP_MASK;
180 else
181 protocol = 0;
183 if (!(protocol & ndev->poll_prots)) {
184 pr_err("the target found does not have the desired protocol\n");
185 return -EPROTO;
188 if (rf_tech_and_mode == NCI_NFC_A_PASSIVE_POLL_MODE) {
189 nfca_poll = (struct rf_tech_specific_params_nfca_poll *)params;
191 target->sens_res = nfca_poll->sens_res;
192 target->sel_res = nfca_poll->sel_res;
193 target->nfcid1_len = nfca_poll->nfcid1_len;
194 if (target->nfcid1_len > 0) {
195 memcpy(target->nfcid1, nfca_poll->nfcid1,
196 target->nfcid1_len);
198 } else if (rf_tech_and_mode == NCI_NFC_B_PASSIVE_POLL_MODE) {
199 nfcb_poll = (struct rf_tech_specific_params_nfcb_poll *)params;
201 target->sensb_res_len = nfcb_poll->sensb_res_len;
202 if (target->sensb_res_len > 0) {
203 memcpy(target->sensb_res, nfcb_poll->sensb_res,
204 target->sensb_res_len);
206 } else if (rf_tech_and_mode == NCI_NFC_F_PASSIVE_POLL_MODE) {
207 nfcf_poll = (struct rf_tech_specific_params_nfcf_poll *)params;
209 target->sensf_res_len = nfcf_poll->sensf_res_len;
210 if (target->sensf_res_len > 0) {
211 memcpy(target->sensf_res, nfcf_poll->sensf_res,
212 target->sensf_res_len);
214 } else {
215 pr_err("unsupported rf_tech_and_mode 0x%x\n", rf_tech_and_mode);
216 return -EPROTO;
219 target->supported_protocols |= protocol;
221 pr_debug("protocol 0x%x\n", protocol);
223 return 0;
226 static void nci_add_new_target(struct nci_dev *ndev,
227 struct nci_rf_discover_ntf *ntf)
229 struct nfc_target *target;
230 int i, rc;
232 for (i = 0; i < ndev->n_targets; i++) {
233 target = &ndev->targets[i];
234 if (target->logical_idx == ntf->rf_discovery_id) {
235 /* This target already exists, add the new protocol */
236 nci_add_new_protocol(ndev, target, ntf->rf_protocol,
237 ntf->rf_tech_and_mode,
238 &ntf->rf_tech_specific_params);
239 return;
243 /* This is a new target, check if we've enough room */
244 if (ndev->n_targets == NCI_MAX_DISCOVERED_TARGETS) {
245 pr_debug("not enough room, ignoring new target...\n");
246 return;
249 target = &ndev->targets[ndev->n_targets];
251 rc = nci_add_new_protocol(ndev, target, ntf->rf_protocol,
252 ntf->rf_tech_and_mode,
253 &ntf->rf_tech_specific_params);
254 if (!rc) {
255 target->logical_idx = ntf->rf_discovery_id;
256 ndev->n_targets++;
258 pr_debug("logical idx %d, n_targets %d\n", target->logical_idx,
259 ndev->n_targets);
263 void nci_clear_target_list(struct nci_dev *ndev)
265 memset(ndev->targets, 0,
266 (sizeof(struct nfc_target)*NCI_MAX_DISCOVERED_TARGETS));
268 ndev->n_targets = 0;
271 static void nci_rf_discover_ntf_packet(struct nci_dev *ndev,
272 struct sk_buff *skb)
274 struct nci_rf_discover_ntf ntf;
275 __u8 *data = skb->data;
276 bool add_target = true;
278 ntf.rf_discovery_id = *data++;
279 ntf.rf_protocol = *data++;
280 ntf.rf_tech_and_mode = *data++;
281 ntf.rf_tech_specific_params_len = *data++;
283 pr_debug("rf_discovery_id %d\n", ntf.rf_discovery_id);
284 pr_debug("rf_protocol 0x%x\n", ntf.rf_protocol);
285 pr_debug("rf_tech_and_mode 0x%x\n", ntf.rf_tech_and_mode);
286 pr_debug("rf_tech_specific_params_len %d\n",
287 ntf.rf_tech_specific_params_len);
289 if (ntf.rf_tech_specific_params_len > 0) {
290 switch (ntf.rf_tech_and_mode) {
291 case NCI_NFC_A_PASSIVE_POLL_MODE:
292 data = nci_extract_rf_params_nfca_passive_poll(ndev,
293 &(ntf.rf_tech_specific_params.nfca_poll), data);
294 break;
296 case NCI_NFC_B_PASSIVE_POLL_MODE:
297 data = nci_extract_rf_params_nfcb_passive_poll(ndev,
298 &(ntf.rf_tech_specific_params.nfcb_poll), data);
299 break;
301 case NCI_NFC_F_PASSIVE_POLL_MODE:
302 data = nci_extract_rf_params_nfcf_passive_poll(ndev,
303 &(ntf.rf_tech_specific_params.nfcf_poll), data);
304 break;
306 default:
307 pr_err("unsupported rf_tech_and_mode 0x%x\n",
308 ntf.rf_tech_and_mode);
309 data += ntf.rf_tech_specific_params_len;
310 add_target = false;
314 ntf.ntf_type = *data++;
315 pr_debug("ntf_type %d\n", ntf.ntf_type);
317 if (add_target == true)
318 nci_add_new_target(ndev, &ntf);
320 if (ntf.ntf_type == NCI_DISCOVER_NTF_TYPE_MORE) {
321 atomic_set(&ndev->state, NCI_W4_ALL_DISCOVERIES);
322 } else {
323 atomic_set(&ndev->state, NCI_W4_HOST_SELECT);
324 nfc_targets_found(ndev->nfc_dev, ndev->targets,
325 ndev->n_targets);
329 static int nci_extract_activation_params_iso_dep(struct nci_dev *ndev,
330 struct nci_rf_intf_activated_ntf *ntf, __u8 *data)
332 struct activation_params_nfca_poll_iso_dep *nfca_poll;
333 struct activation_params_nfcb_poll_iso_dep *nfcb_poll;
335 switch (ntf->activation_rf_tech_and_mode) {
336 case NCI_NFC_A_PASSIVE_POLL_MODE:
337 nfca_poll = &ntf->activation_params.nfca_poll_iso_dep;
338 nfca_poll->rats_res_len = min_t(__u8, *data++, 20);
339 pr_debug("rats_res_len %d\n", nfca_poll->rats_res_len);
340 if (nfca_poll->rats_res_len > 0) {
341 memcpy(nfca_poll->rats_res,
342 data, nfca_poll->rats_res_len);
344 break;
346 case NCI_NFC_B_PASSIVE_POLL_MODE:
347 nfcb_poll = &ntf->activation_params.nfcb_poll_iso_dep;
348 nfcb_poll->attrib_res_len = min_t(__u8, *data++, 50);
349 pr_debug("attrib_res_len %d\n", nfcb_poll->attrib_res_len);
350 if (nfcb_poll->attrib_res_len > 0) {
351 memcpy(nfcb_poll->attrib_res,
352 data, nfcb_poll->attrib_res_len);
354 break;
356 default:
357 pr_err("unsupported activation_rf_tech_and_mode 0x%x\n",
358 ntf->activation_rf_tech_and_mode);
359 return NCI_STATUS_RF_PROTOCOL_ERROR;
362 return NCI_STATUS_OK;
365 static int nci_extract_activation_params_nfc_dep(struct nci_dev *ndev,
366 struct nci_rf_intf_activated_ntf *ntf, __u8 *data)
368 struct activation_params_poll_nfc_dep *poll;
370 switch (ntf->activation_rf_tech_and_mode) {
371 case NCI_NFC_A_PASSIVE_POLL_MODE:
372 case NCI_NFC_F_PASSIVE_POLL_MODE:
373 poll = &ntf->activation_params.poll_nfc_dep;
374 poll->atr_res_len = min_t(__u8, *data++, 63);
375 pr_debug("atr_res_len %d\n", poll->atr_res_len);
376 if (poll->atr_res_len > 0)
377 memcpy(poll->atr_res, data, poll->atr_res_len);
378 break;
380 default:
381 pr_err("unsupported activation_rf_tech_and_mode 0x%x\n",
382 ntf->activation_rf_tech_and_mode);
383 return NCI_STATUS_RF_PROTOCOL_ERROR;
386 return NCI_STATUS_OK;
389 static void nci_target_auto_activated(struct nci_dev *ndev,
390 struct nci_rf_intf_activated_ntf *ntf)
392 struct nfc_target *target;
393 int rc;
395 target = &ndev->targets[ndev->n_targets];
397 rc = nci_add_new_protocol(ndev, target, ntf->rf_protocol,
398 ntf->activation_rf_tech_and_mode,
399 &ntf->rf_tech_specific_params);
400 if (rc)
401 return;
403 target->logical_idx = ntf->rf_discovery_id;
404 ndev->n_targets++;
406 pr_debug("logical idx %d, n_targets %d\n",
407 target->logical_idx, ndev->n_targets);
409 nfc_targets_found(ndev->nfc_dev, ndev->targets, ndev->n_targets);
412 static void nci_rf_intf_activated_ntf_packet(struct nci_dev *ndev,
413 struct sk_buff *skb)
415 struct nci_rf_intf_activated_ntf ntf;
416 __u8 *data = skb->data;
417 int err = NCI_STATUS_OK;
419 ntf.rf_discovery_id = *data++;
420 ntf.rf_interface = *data++;
421 ntf.rf_protocol = *data++;
422 ntf.activation_rf_tech_and_mode = *data++;
423 ntf.max_data_pkt_payload_size = *data++;
424 ntf.initial_num_credits = *data++;
425 ntf.rf_tech_specific_params_len = *data++;
427 pr_debug("rf_discovery_id %d\n", ntf.rf_discovery_id);
428 pr_debug("rf_interface 0x%x\n", ntf.rf_interface);
429 pr_debug("rf_protocol 0x%x\n", ntf.rf_protocol);
430 pr_debug("activation_rf_tech_and_mode 0x%x\n",
431 ntf.activation_rf_tech_and_mode);
432 pr_debug("max_data_pkt_payload_size 0x%x\n",
433 ntf.max_data_pkt_payload_size);
434 pr_debug("initial_num_credits 0x%x\n",
435 ntf.initial_num_credits);
436 pr_debug("rf_tech_specific_params_len %d\n",
437 ntf.rf_tech_specific_params_len);
439 if (ntf.rf_tech_specific_params_len > 0) {
440 switch (ntf.activation_rf_tech_and_mode) {
441 case NCI_NFC_A_PASSIVE_POLL_MODE:
442 data = nci_extract_rf_params_nfca_passive_poll(ndev,
443 &(ntf.rf_tech_specific_params.nfca_poll), data);
444 break;
446 case NCI_NFC_B_PASSIVE_POLL_MODE:
447 data = nci_extract_rf_params_nfcb_passive_poll(ndev,
448 &(ntf.rf_tech_specific_params.nfcb_poll), data);
449 break;
451 case NCI_NFC_F_PASSIVE_POLL_MODE:
452 data = nci_extract_rf_params_nfcf_passive_poll(ndev,
453 &(ntf.rf_tech_specific_params.nfcf_poll), data);
454 break;
456 default:
457 pr_err("unsupported activation_rf_tech_and_mode 0x%x\n",
458 ntf.activation_rf_tech_and_mode);
459 err = NCI_STATUS_RF_PROTOCOL_ERROR;
460 goto exit;
464 ntf.data_exch_rf_tech_and_mode = *data++;
465 ntf.data_exch_tx_bit_rate = *data++;
466 ntf.data_exch_rx_bit_rate = *data++;
467 ntf.activation_params_len = *data++;
469 pr_debug("data_exch_rf_tech_and_mode 0x%x\n",
470 ntf.data_exch_rf_tech_and_mode);
471 pr_debug("data_exch_tx_bit_rate 0x%x\n", ntf.data_exch_tx_bit_rate);
472 pr_debug("data_exch_rx_bit_rate 0x%x\n", ntf.data_exch_rx_bit_rate);
473 pr_debug("activation_params_len %d\n", ntf.activation_params_len);
475 if (ntf.activation_params_len > 0) {
476 switch (ntf.rf_interface) {
477 case NCI_RF_INTERFACE_ISO_DEP:
478 err = nci_extract_activation_params_iso_dep(ndev,
479 &ntf, data);
480 break;
482 case NCI_RF_INTERFACE_NFC_DEP:
483 err = nci_extract_activation_params_nfc_dep(ndev,
484 &ntf, data);
485 break;
487 case NCI_RF_INTERFACE_FRAME:
488 /* no activation params */
489 break;
491 default:
492 pr_err("unsupported rf_interface 0x%x\n",
493 ntf.rf_interface);
494 err = NCI_STATUS_RF_PROTOCOL_ERROR;
495 break;
499 exit:
500 if (err == NCI_STATUS_OK) {
501 ndev->max_data_pkt_payload_size = ntf.max_data_pkt_payload_size;
502 ndev->initial_num_credits = ntf.initial_num_credits;
504 /* set the available credits to initial value */
505 atomic_set(&ndev->credits_cnt, ndev->initial_num_credits);
507 /* store general bytes to be reported later in dep_link_up */
508 if (ntf.rf_interface == NCI_RF_INTERFACE_NFC_DEP) {
509 ndev->remote_gb_len = 0;
511 if (ntf.activation_params_len > 0) {
512 /* ATR_RES general bytes at offset 15 */
513 ndev->remote_gb_len = min_t(__u8,
514 (ntf.activation_params
515 .poll_nfc_dep.atr_res_len
516 - NFC_ATR_RES_GT_OFFSET),
517 NFC_MAX_GT_LEN);
518 memcpy(ndev->remote_gb,
519 (ntf.activation_params.poll_nfc_dep
520 .atr_res + NFC_ATR_RES_GT_OFFSET),
521 ndev->remote_gb_len);
526 if (atomic_read(&ndev->state) == NCI_DISCOVERY) {
527 /* A single target was found and activated automatically */
528 atomic_set(&ndev->state, NCI_POLL_ACTIVE);
529 if (err == NCI_STATUS_OK)
530 nci_target_auto_activated(ndev, &ntf);
531 } else { /* ndev->state == NCI_W4_HOST_SELECT */
532 /* A selected target was activated, so complete the request */
533 atomic_set(&ndev->state, NCI_POLL_ACTIVE);
534 nci_req_complete(ndev, err);
538 static void nci_rf_deactivate_ntf_packet(struct nci_dev *ndev,
539 struct sk_buff *skb)
541 struct nci_rf_deactivate_ntf *ntf = (void *) skb->data;
543 pr_debug("entry, type 0x%x, reason 0x%x\n", ntf->type, ntf->reason);
545 /* drop tx data queue */
546 skb_queue_purge(&ndev->tx_q);
548 /* drop partial rx data packet */
549 if (ndev->rx_data_reassembly) {
550 kfree_skb(ndev->rx_data_reassembly);
551 ndev->rx_data_reassembly = NULL;
554 /* complete the data exchange transaction, if exists */
555 if (test_bit(NCI_DATA_EXCHANGE, &ndev->flags))
556 nci_data_exchange_complete(ndev, NULL, -EIO);
558 nci_clear_target_list(ndev);
559 atomic_set(&ndev->state, NCI_IDLE);
560 nci_req_complete(ndev, NCI_STATUS_OK);
563 void nci_ntf_packet(struct nci_dev *ndev, struct sk_buff *skb)
565 __u16 ntf_opcode = nci_opcode(skb->data);
567 pr_debug("NCI RX: MT=ntf, PBF=%d, GID=0x%x, OID=0x%x, plen=%d\n",
568 nci_pbf(skb->data),
569 nci_opcode_gid(ntf_opcode),
570 nci_opcode_oid(ntf_opcode),
571 nci_plen(skb->data));
573 /* strip the nci control header */
574 skb_pull(skb, NCI_CTRL_HDR_SIZE);
576 switch (ntf_opcode) {
577 case NCI_OP_CORE_CONN_CREDITS_NTF:
578 nci_core_conn_credits_ntf_packet(ndev, skb);
579 break;
581 case NCI_OP_CORE_GENERIC_ERROR_NTF:
582 nci_core_generic_error_ntf_packet(ndev, skb);
583 break;
585 case NCI_OP_CORE_INTF_ERROR_NTF:
586 nci_core_conn_intf_error_ntf_packet(ndev, skb);
587 break;
589 case NCI_OP_RF_DISCOVER_NTF:
590 nci_rf_discover_ntf_packet(ndev, skb);
591 break;
593 case NCI_OP_RF_INTF_ACTIVATED_NTF:
594 nci_rf_intf_activated_ntf_packet(ndev, skb);
595 break;
597 case NCI_OP_RF_DEACTIVATE_NTF:
598 nci_rf_deactivate_ntf_packet(ndev, skb);
599 break;
601 default:
602 pr_err("unknown ntf opcode 0x%x\n", ntf_opcode);
603 break;
606 kfree_skb(skb);