Blame tools/hciattach_qualcomm.c

Packit Service 8264ee
/*
Packit Service 8264ee
 *
Packit Service 8264ee
 *  BlueZ - Bluetooth protocol stack for Linux
Packit Service 8264ee
 *
Packit Service 8264ee
 *  Copyright (C) 2005-2010  Marcel Holtmann <marcel@holtmann.org>
Packit Service 8264ee
 *  Copyright (c) 2010, Code Aurora Forum. All rights reserved.
Packit Service 8264ee
 *
Packit Service 8264ee
 *
Packit Service 8264ee
 *  This program is free software; you can redistribute it and/or modify
Packit Service 8264ee
 *  it under the terms of the GNU General Public License as published by
Packit Service 8264ee
 *  the Free Software Foundation; either version 2 of the License, or
Packit Service 8264ee
 *  (at your option) any later version.
Packit Service 8264ee
 *
Packit Service 8264ee
 *  This program is distributed in the hope that it will be useful,
Packit Service 8264ee
 *  but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit Service 8264ee
 *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
Packit Service 8264ee
 *  GNU General Public License for more details.
Packit Service 8264ee
 *
Packit Service 8264ee
 *  You should have received a copy of the GNU General Public License
Packit Service 8264ee
 *  along with this program; if not, write to the Free Software
Packit Service 8264ee
 *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
Packit Service 8264ee
 *
Packit Service 8264ee
 */
Packit Service 8264ee
Packit Service 8264ee
#ifdef HAVE_CONFIG_H
Packit Service 8264ee
#include <config.h>
Packit Service 8264ee
#endif
Packit Service 8264ee
Packit Service 8264ee
#define _GNU_SOURCE
Packit Service 8264ee
#include <stdio.h>
Packit Service 8264ee
#include <errno.h>
Packit Service 8264ee
#include <fcntl.h>
Packit Service 8264ee
#include <unistd.h>
Packit Service 8264ee
#include <stdlib.h>
Packit Service 8264ee
#include <string.h>
Packit Service 8264ee
#include <signal.h>
Packit Service 8264ee
#include <syslog.h>
Packit Service 8264ee
#include <termios.h>
Packit Service 8264ee
#include <time.h>
Packit Service 8264ee
#include <poll.h>
Packit Service 8264ee
#include <sys/time.h>
Packit Service 8264ee
#include <sys/param.h>
Packit Service 8264ee
#include <sys/ioctl.h>
Packit Service 8264ee
#include <sys/uio.h>
Packit Service 8264ee
Packit Service 8264ee
#include "lib/bluetooth.h"
Packit Service 8264ee
#include "lib/hci.h"
Packit Service 8264ee
#include "lib/hci_lib.h"
Packit Service 8264ee
Packit Service 8264ee
#include "hciattach.h"
Packit Service 8264ee
Packit Service 8264ee
#define FAILIF(x, args...) do { \
Packit Service 8264ee
	if (x) { \
Packit Service 8264ee
		fprintf(stderr, ##args); \
Packit Service 8264ee
		return -1; \
Packit Service 8264ee
	} \
Packit Service 8264ee
} while (0)
Packit Service 8264ee
Packit Service 8264ee
typedef struct {
Packit Service 8264ee
	uint8_t uart_prefix;
Packit Service 8264ee
	hci_event_hdr hci_hdr;
Packit Service 8264ee
	evt_cmd_complete cmd_complete;
Packit Service 8264ee
	uint8_t status;
Packit Service 8264ee
	uint8_t data[16];
Packit Service 8264ee
} __attribute__((packed)) command_complete_t;
Packit Service 8264ee
Packit Service 8264ee
static int read_command_complete(int fd,
Packit Service 8264ee
					unsigned short opcode,
Packit Service 8264ee
					unsigned char len)
Packit Service 8264ee
{
Packit Service 8264ee
	command_complete_t resp;
Packit Service 8264ee
	unsigned char vsevent[512];
Packit Service 8264ee
	int n;
Packit Service 8264ee
Packit Service 8264ee
	/* Read reply. */
Packit Service 8264ee
	n = read_hci_event(fd, vsevent, sizeof(vsevent));
Packit Service 8264ee
	FAILIF(n < 0, "Failed to read response");
Packit Service 8264ee
Packit Service 8264ee
	FAILIF(vsevent[1] != 0xFF, "Failed to read response");
Packit Service 8264ee
Packit Service 8264ee
	n = read_hci_event(fd, (unsigned char *)&resp, sizeof(resp));
Packit Service 8264ee
	FAILIF(n < 0, "Failed to read response");
Packit Service 8264ee
Packit Service 8264ee
	/* event must be event-complete */
Packit Service 8264ee
	FAILIF(resp.hci_hdr.evt != EVT_CMD_COMPLETE,
Packit Service 8264ee
		"Error in response: not a cmd-complete event, "
Packit Service 8264ee
		"but 0x%02x!\n", resp.hci_hdr.evt);
Packit Service 8264ee
Packit Service 8264ee
	FAILIF(resp.hci_hdr.plen < 4, /* plen >= 4 for EVT_CMD_COMPLETE */
Packit Service 8264ee
		"Error in response: plen is not >= 4, but 0x%02x!\n",
Packit Service 8264ee
		resp.hci_hdr.plen);
Packit Service 8264ee
Packit Service 8264ee
	/* cmd-complete event: opcode */
Packit Service 8264ee
	FAILIF(resp.cmd_complete.opcode != 0,
Packit Service 8264ee
		"Error in response: opcode is 0x%04x, not 0!",
Packit Service 8264ee
		resp.cmd_complete.opcode);
Packit Service 8264ee
Packit Service 8264ee
	return resp.status == 0 ? 0 : -1;
Packit Service 8264ee
}
Packit Service 8264ee
Packit Service 8264ee
static int qualcomm_load_firmware(int fd, const char *firmware, const char *bdaddr_s)
Packit Service 8264ee
{
Packit Service 8264ee
Packit Service 8264ee
	int fw = open(firmware, O_RDONLY);
Packit Service 8264ee
Packit Service 8264ee
	fprintf(stdout, "Opening firmware file: %s\n", firmware);
Packit Service 8264ee
Packit Service 8264ee
	FAILIF(fw < 0,
Packit Service 8264ee
		"Could not open firmware file %s: %s (%d).\n",
Packit Service 8264ee
		firmware, strerror(errno), errno);
Packit Service 8264ee
Packit Service 8264ee
	fprintf(stdout, "Uploading firmware...\n");
Packit Service 8264ee
	do {
Packit Service 8264ee
		/* Read each command and wait for a response. */
Packit Service 8264ee
		unsigned char data[1024];
Packit Service 8264ee
		unsigned char cmdp[1 + sizeof(hci_command_hdr)];
Packit Service 8264ee
		hci_command_hdr *cmd = (hci_command_hdr *) (cmdp + 1);
Packit Service 8264ee
		int nr;
Packit Service 8264ee
Packit Service 8264ee
		nr = read(fw, cmdp, sizeof(cmdp));
Packit Service 8264ee
		if (!nr)
Packit Service 8264ee
			break;
Packit Service 8264ee
Packit Service 8264ee
		FAILIF(nr != sizeof(cmdp),
Packit Service 8264ee
			"Could not read H4 + HCI header!\n");
Packit Service 8264ee
		FAILIF(*cmdp != HCI_COMMAND_PKT,
Packit Service 8264ee
			"Command is not an H4 command packet!\n");
Packit Service 8264ee
Packit Service 8264ee
		FAILIF(read(fw, data, cmd->plen) != cmd->plen,
Packit Service 8264ee
				"Could not read %d bytes of data \
Packit Service 8264ee
				for command with opcode %04x!\n",
Packit Service 8264ee
				cmd->plen, cmd->opcode);
Packit Service 8264ee
Packit Service 8264ee
		if ((data[0] == 1) && (data[1] == 2) && (data[2] == 6)) {
Packit Service 8264ee
			bdaddr_t bdaddr;
Packit Service 8264ee
			if (bdaddr_s != NULL) {
Packit Service 8264ee
				str2ba(bdaddr_s, &bdaddr);
Packit Service 8264ee
				memcpy(&data[3], &bdaddr, sizeof(bdaddr_t));
Packit Service 8264ee
			}
Packit Service 8264ee
		}
Packit Service 8264ee
Packit Service 8264ee
		{
Packit Service 8264ee
			int nw;
Packit Service 8264ee
			struct iovec iov_cmd[2];
Packit Service 8264ee
			iov_cmd[0].iov_base = cmdp;
Packit Service 8264ee
			iov_cmd[0].iov_len = sizeof(cmdp);
Packit Service 8264ee
			iov_cmd[1].iov_base = data;
Packit Service 8264ee
			iov_cmd[1].iov_len = cmd->plen;
Packit Service 8264ee
			nw = writev(fd, iov_cmd, 2);
Packit Service 8264ee
			FAILIF(nw != (int) sizeof(cmdp) + cmd->plen,
Packit Service 8264ee
				"Could not send entire command \
Packit Service 8264ee
				(sent only %d bytes)!\n",
Packit Service 8264ee
				nw);
Packit Service 8264ee
		}
Packit Service 8264ee
Packit Service 8264ee
		/* Wait for response */
Packit Service 8264ee
		if (read_command_complete(fd, cmd->opcode, cmd->plen) < 0)
Packit Service 8264ee
			return -1;
Packit Service 8264ee
	} while (1);
Packit Service 8264ee
	fprintf(stdout, "Firmware upload successful.\n");
Packit Service 8264ee
Packit Service 8264ee
	close(fw);
Packit Service 8264ee
Packit Service 8264ee
	return 0;
Packit Service 8264ee
}
Packit Service 8264ee
Packit Service 8264ee
int qualcomm_init(int fd, int speed, struct termios *ti, const char *bdaddr)
Packit Service 8264ee
{
Packit Service 8264ee
	struct timespec tm = {0, 50000};
Packit Service 8264ee
	char cmd[5];
Packit Service 8264ee
	unsigned char resp[100];		/* Response */
Packit Service 8264ee
	char fw[100];
Packit Service 8264ee
	int n;
Packit Service 8264ee
Packit Service 8264ee
	memset(resp, 0, 100);
Packit Service 8264ee
Packit Service 8264ee
	/* Get Manufacturer and LMP version */
Packit Service 8264ee
	cmd[0] = HCI_COMMAND_PKT;
Packit Service 8264ee
	cmd[1] = 0x01;
Packit Service 8264ee
	cmd[2] = 0x10;
Packit Service 8264ee
	cmd[3] = 0x00;
Packit Service 8264ee
Packit Service 8264ee
	do {
Packit Service 8264ee
		n = write(fd, cmd, 4);
Packit Service 8264ee
		if (n < 4) {
Packit Service 8264ee
			perror("Failed to write init command");
Packit Service 8264ee
			return -1;
Packit Service 8264ee
		}
Packit Service 8264ee
Packit Service 8264ee
		/* Read reply. */
Packit Service 8264ee
		if (read_hci_event(fd, resp, 100) < 0) {
Packit Service 8264ee
			perror("Failed to read init response");
Packit Service 8264ee
			return -1;
Packit Service 8264ee
		}
Packit Service 8264ee
Packit Service 8264ee
		/* Wait for command complete event for our Opcode */
Packit Service 8264ee
	} while (resp[4] != cmd[1] && resp[5] != cmd[2]);
Packit Service 8264ee
Packit Service 8264ee
	/* Verify manufacturer */
Packit Service 8264ee
	if ((resp[11] & 0xFF) != 0x1d)
Packit Service 8264ee
		fprintf(stderr,
Packit Service 8264ee
			"WARNING : module's manufacturer is not Qualcomm\n");
Packit Service 8264ee
Packit Service 8264ee
	/* Print LMP version */
Packit Service 8264ee
	fprintf(stderr,
Packit Service 8264ee
		"Qualcomm module LMP version : 0x%02x\n", resp[10] & 0xFF);
Packit Service 8264ee
Packit Service 8264ee
	/* Print LMP subversion */
Packit Service 8264ee
	{
Packit Service 8264ee
		unsigned short lmp_subv = resp[13] | (resp[14] << 8);
Packit Service 8264ee
Packit Service 8264ee
		fprintf(stderr, "Qualcomm module LMP sub-version : 0x%04x\n",
Packit Service 8264ee
								lmp_subv);
Packit Service 8264ee
	}
Packit Service 8264ee
Packit Service 8264ee
	/* Get SoC type */
Packit Service 8264ee
	cmd[0] = HCI_COMMAND_PKT;
Packit Service 8264ee
	cmd[1] = 0x00;
Packit Service 8264ee
	cmd[2] = 0xFC;
Packit Service 8264ee
	cmd[3] = 0x01;
Packit Service 8264ee
	cmd[4] = 0x06;
Packit Service 8264ee
Packit Service 8264ee
	do {
Packit Service 8264ee
		n = write(fd, cmd, 5);
Packit Service 8264ee
		if (n < 5) {
Packit Service 8264ee
			perror("Failed to write vendor init command");
Packit Service 8264ee
			return -1;
Packit Service 8264ee
		}
Packit Service 8264ee
Packit Service 8264ee
		/* Read reply. */
Packit Service 8264ee
		if ((n = read_hci_event(fd, resp, 100)) < 0) {
Packit Service 8264ee
			perror("Failed to read vendor init response");
Packit Service 8264ee
			return -1;
Packit Service 8264ee
		}
Packit Service 8264ee
Packit Service 8264ee
	} while (resp[3] != 0 && resp[4] != 2);
Packit Service 8264ee
Packit Service 8264ee
	snprintf(fw, sizeof(fw), "/etc/firmware/%c%c%c%c%c%c_%c%c%c%c.bin",
Packit Service 8264ee
				resp[18], resp[19], resp[20], resp[21],
Packit Service 8264ee
				resp[22], resp[23],
Packit Service 8264ee
				resp[32], resp[33], resp[34], resp[35]);
Packit Service 8264ee
Packit Service 8264ee
	/* Wait for command complete event for our Opcode */
Packit Service 8264ee
	if (read_hci_event(fd, resp, 100) < 0) {
Packit Service 8264ee
		perror("Failed to read init response");
Packit Service 8264ee
		return -1;
Packit Service 8264ee
	}
Packit Service 8264ee
Packit Service 8264ee
	qualcomm_load_firmware(fd, fw, bdaddr);
Packit Service 8264ee
Packit Service 8264ee
	/* Reset */
Packit Service 8264ee
	cmd[0] = HCI_COMMAND_PKT;
Packit Service 8264ee
	cmd[1] = 0x03;
Packit Service 8264ee
	cmd[2] = 0x0C;
Packit Service 8264ee
	cmd[3] = 0x00;
Packit Service 8264ee
Packit Service 8264ee
	do {
Packit Service 8264ee
		n = write(fd, cmd, 4);
Packit Service 8264ee
		if (n < 4) {
Packit Service 8264ee
			perror("Failed to write reset command");
Packit Service 8264ee
			return -1;
Packit Service 8264ee
		}
Packit Service 8264ee
Packit Service 8264ee
		/* Read reply. */
Packit Service 8264ee
		if ((n = read_hci_event(fd, resp, 100)) < 0) {
Packit Service 8264ee
			perror("Failed to read reset response");
Packit Service 8264ee
			return -1;
Packit Service 8264ee
		}
Packit Service 8264ee
Packit Service 8264ee
	} while (resp[4] != cmd[1] && resp[5] != cmd[2]);
Packit Service 8264ee
Packit Service 8264ee
	nanosleep(&tm, NULL);
Packit Service 8264ee
Packit Service 8264ee
	return 0;
Packit Service 8264ee
}