2 * QEMU Bluetooth HCI USB Transport Layer v1.0
4 * Copyright (C) 2007 OpenMoko, Inc.
5 * Copyright (C) 2008 Andrzej Zaborowski <balrog@zabor.org>
7 * This program is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU General Public License as
9 * published by the Free Software Foundation; either version 2 or
10 * (at your option) version 3 of the License.
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
17 * You should have received a copy of the GNU General Public License along
18 * with this program; if not, see <http://www.gnu.org/licenses/>.
21 #include "qemu-common.h"
23 #include "hw/usb/desc.h"
24 #include "sysemu/bt.h"
34 #define CFIFO_LEN_MASK 255
35 #define DFIFO_LEN_MASK 4095
36 struct usb_hci_in_fifo_s {
37 uint8_t data[(DFIFO_LEN_MASK + 1) * 2];
41 } fifo[CFIFO_LEN_MASK + 1];
42 int dstart, dlen, dsize, start, len;
45 struct usb_hci_out_fifo_s {
48 } outcmd, outacl, outsco;
60 static const USBDescStrings desc_strings = {
61 [STR_MANUFACTURER] = "QEMU",
62 [STR_SERIALNUMBER] = "1",
65 static const USBDescIface desc_iface_bluetooth[] = {
67 .bInterfaceNumber = 0,
69 .bInterfaceClass = 0xe0, /* Wireless */
70 .bInterfaceSubClass = 0x01, /* Radio Frequency */
71 .bInterfaceProtocol = 0x01, /* Bluetooth */
72 .eps = (USBDescEndpoint[]) {
74 .bEndpointAddress = USB_DIR_IN | USB_EVT_EP,
75 .bmAttributes = USB_ENDPOINT_XFER_INT,
76 .wMaxPacketSize = 0x10,
80 .bEndpointAddress = USB_DIR_OUT | USB_ACL_EP,
81 .bmAttributes = USB_ENDPOINT_XFER_BULK,
82 .wMaxPacketSize = 0x40,
86 .bEndpointAddress = USB_DIR_IN | USB_ACL_EP,
87 .bmAttributes = USB_ENDPOINT_XFER_BULK,
88 .wMaxPacketSize = 0x40,
93 .bInterfaceNumber = 1,
94 .bAlternateSetting = 0,
96 .bInterfaceClass = 0xe0, /* Wireless */
97 .bInterfaceSubClass = 0x01, /* Radio Frequency */
98 .bInterfaceProtocol = 0x01, /* Bluetooth */
99 .eps = (USBDescEndpoint[]) {
101 .bEndpointAddress = USB_DIR_OUT | USB_SCO_EP,
102 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
107 .bEndpointAddress = USB_DIR_IN | USB_SCO_EP,
108 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
114 .bInterfaceNumber = 1,
115 .bAlternateSetting = 1,
117 .bInterfaceClass = 0xe0, /* Wireless */
118 .bInterfaceSubClass = 0x01, /* Radio Frequency */
119 .bInterfaceProtocol = 0x01, /* Bluetooth */
120 .eps = (USBDescEndpoint[]) {
122 .bEndpointAddress = USB_DIR_OUT | USB_SCO_EP,
123 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
124 .wMaxPacketSize = 0x09,
128 .bEndpointAddress = USB_DIR_IN | USB_SCO_EP,
129 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
130 .wMaxPacketSize = 0x09,
135 .bInterfaceNumber = 1,
136 .bAlternateSetting = 2,
138 .bInterfaceClass = 0xe0, /* Wireless */
139 .bInterfaceSubClass = 0x01, /* Radio Frequency */
140 .bInterfaceProtocol = 0x01, /* Bluetooth */
141 .eps = (USBDescEndpoint[]) {
143 .bEndpointAddress = USB_DIR_OUT | USB_SCO_EP,
144 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
145 .wMaxPacketSize = 0x11,
149 .bEndpointAddress = USB_DIR_IN | USB_SCO_EP,
150 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
151 .wMaxPacketSize = 0x11,
156 .bInterfaceNumber = 1,
157 .bAlternateSetting = 3,
159 .bInterfaceClass = 0xe0, /* Wireless */
160 .bInterfaceSubClass = 0x01, /* Radio Frequency */
161 .bInterfaceProtocol = 0x01, /* Bluetooth */
162 .eps = (USBDescEndpoint[]) {
164 .bEndpointAddress = USB_DIR_OUT | USB_SCO_EP,
165 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
166 .wMaxPacketSize = 0x19,
170 .bEndpointAddress = USB_DIR_IN | USB_SCO_EP,
171 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
172 .wMaxPacketSize = 0x19,
177 .bInterfaceNumber = 1,
178 .bAlternateSetting = 4,
180 .bInterfaceClass = 0xe0, /* Wireless */
181 .bInterfaceSubClass = 0x01, /* Radio Frequency */
182 .bInterfaceProtocol = 0x01, /* Bluetooth */
183 .eps = (USBDescEndpoint[]) {
185 .bEndpointAddress = USB_DIR_OUT | USB_SCO_EP,
186 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
187 .wMaxPacketSize = 0x21,
191 .bEndpointAddress = USB_DIR_IN | USB_SCO_EP,
192 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
193 .wMaxPacketSize = 0x21,
198 .bInterfaceNumber = 1,
199 .bAlternateSetting = 5,
201 .bInterfaceClass = 0xe0, /* Wireless */
202 .bInterfaceSubClass = 0x01, /* Radio Frequency */
203 .bInterfaceProtocol = 0x01, /* Bluetooth */
204 .eps = (USBDescEndpoint[]) {
206 .bEndpointAddress = USB_DIR_OUT | USB_SCO_EP,
207 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
208 .wMaxPacketSize = 0x31,
212 .bEndpointAddress = USB_DIR_IN | USB_SCO_EP,
213 .bmAttributes = USB_ENDPOINT_XFER_ISOC,
214 .wMaxPacketSize = 0x31,
221 static const USBDescDevice desc_device_bluetooth = {
223 .bDeviceClass = 0xe0, /* Wireless */
224 .bDeviceSubClass = 0x01, /* Radio Frequency */
225 .bDeviceProtocol = 0x01, /* Bluetooth */
226 .bMaxPacketSize0 = 64,
227 .bNumConfigurations = 1,
228 .confs = (USBDescConfig[]) {
231 .bConfigurationValue = 1,
232 .bmAttributes = 0xc0,
234 .nif = ARRAY_SIZE(desc_iface_bluetooth),
235 .ifs = desc_iface_bluetooth,
240 static const USBDesc desc_bluetooth = {
245 .iManufacturer = STR_MANUFACTURER,
247 .iSerialNumber = STR_SERIALNUMBER,
249 .full = &desc_device_bluetooth,
253 static void usb_bt_fifo_reset(struct usb_hci_in_fifo_s *fifo)
257 fifo->dsize = DFIFO_LEN_MASK + 1;
262 static void usb_bt_fifo_enqueue(struct usb_hci_in_fifo_s *fifo,
263 const uint8_t *data, int len)
265 int off = fifo->dstart + fifo->dlen;
269 if (off <= DFIFO_LEN_MASK) {
270 if (off + len > DFIFO_LEN_MASK + 1 &&
271 (fifo->dsize = off + len) > (DFIFO_LEN_MASK + 1) * 2) {
272 fprintf(stderr, "%s: can't alloc %i bytes\n", __FUNCTION__, len);
275 buf = fifo->data + off;
277 if (fifo->dlen > fifo->dsize) {
278 fprintf(stderr, "%s: can't alloc %i bytes\n", __FUNCTION__, len);
281 buf = fifo->data + off - fifo->dsize;
284 off = (fifo->start + fifo->len ++) & CFIFO_LEN_MASK;
285 fifo->fifo[off].data = memcpy(buf, data, len);
286 fifo->fifo[off].len = len;
289 static inline void usb_bt_fifo_dequeue(struct usb_hci_in_fifo_s *fifo,
294 assert(fifo->len != 0);
296 len = MIN(p->iov.size, fifo->fifo[fifo->start].len);
297 usb_packet_copy(p, fifo->fifo[fifo->start].data, len);
298 if (len == p->iov.size) {
299 fifo->fifo[fifo->start].len -= len;
300 fifo->fifo[fifo->start].data += len;
303 fifo->start &= CFIFO_LEN_MASK;
309 if (fifo->dstart >= fifo->dsize) {
311 fifo->dsize = DFIFO_LEN_MASK + 1;
315 static inline void usb_bt_fifo_out_enqueue(struct USBBtState *s,
316 struct usb_hci_out_fifo_s *fifo,
317 void (*send)(struct HCIInfo *, const uint8_t *, int),
318 int (*complete)(const uint8_t *, int),
321 usb_packet_copy(p, fifo->data + fifo->len, p->iov.size);
322 fifo->len += p->iov.size;
323 if (complete(fifo->data, fifo->len)) {
324 send(s->hci, fifo->data, fifo->len);
328 /* TODO: do we need to loop? */
331 static int usb_bt_hci_cmd_complete(const uint8_t *data, int len)
333 len -= HCI_COMMAND_HDR_SIZE;
335 len >= ((struct hci_command_hdr *) data)->plen;
338 static int usb_bt_hci_acl_complete(const uint8_t *data, int len)
340 len -= HCI_ACL_HDR_SIZE;
342 len >= le16_to_cpu(((struct hci_acl_hdr *) data)->dlen);
345 static int usb_bt_hci_sco_complete(const uint8_t *data, int len)
347 len -= HCI_SCO_HDR_SIZE;
349 len >= ((struct hci_sco_hdr *) data)->dlen;
352 static void usb_bt_handle_reset(USBDevice *dev)
354 struct USBBtState *s = (struct USBBtState *) dev->opaque;
356 usb_bt_fifo_reset(&s->evt);
357 usb_bt_fifo_reset(&s->acl);
358 usb_bt_fifo_reset(&s->sco);
364 static void usb_bt_handle_control(USBDevice *dev, USBPacket *p,
365 int request, int value, int index, int length, uint8_t *data)
367 struct USBBtState *s = (struct USBBtState *) dev->opaque;
370 ret = usb_desc_handle_control(dev, p, request, value, index, length, data);
373 case DeviceRequest | USB_REQ_GET_CONFIGURATION:
376 case DeviceOutRequest | USB_REQ_SET_CONFIGURATION:
378 usb_bt_fifo_reset(&s->evt);
379 usb_bt_fifo_reset(&s->acl);
380 usb_bt_fifo_reset(&s->sco);
387 case InterfaceRequest | USB_REQ_GET_STATUS:
388 case EndpointRequest | USB_REQ_GET_STATUS:
391 p->actual_length = 2;
393 case InterfaceOutRequest | USB_REQ_CLEAR_FEATURE:
394 case EndpointOutRequest | USB_REQ_CLEAR_FEATURE:
396 case InterfaceOutRequest | USB_REQ_SET_FEATURE:
397 case EndpointOutRequest | USB_REQ_SET_FEATURE:
400 case ((USB_DIR_OUT | USB_TYPE_CLASS | USB_RECIP_DEVICE) << 8):
402 usb_bt_fifo_out_enqueue(s, &s->outcmd, s->hci->cmd_send,
403 usb_bt_hci_cmd_complete, p);
407 p->status = USB_RET_STALL;
412 static void usb_bt_handle_data(USBDevice *dev, USBPacket *p)
414 struct USBBtState *s = (struct USBBtState *) dev->opaque;
423 if (s->evt.len == 0) {
424 p->status = USB_RET_NAK;
427 usb_bt_fifo_dequeue(&s->evt, p);
431 if (s->evt.len == 0) {
432 p->status = USB_RET_STALL;
435 usb_bt_fifo_dequeue(&s->acl, p);
439 if (s->evt.len == 0) {
440 p->status = USB_RET_STALL;
443 usb_bt_fifo_dequeue(&s->sco, p);
454 usb_bt_fifo_out_enqueue(s, &s->outacl, s->hci->acl_send,
455 usb_bt_hci_acl_complete, p);
459 usb_bt_fifo_out_enqueue(s, &s->outsco, s->hci->sco_send,
460 usb_bt_hci_sco_complete, p);
470 p->status = USB_RET_STALL;
475 static void usb_bt_out_hci_packet_event(void *opaque,
476 const uint8_t *data, int len)
478 struct USBBtState *s = (struct USBBtState *) opaque;
480 if (s->evt.len == 0) {
481 usb_wakeup(s->intr, 0);
483 usb_bt_fifo_enqueue(&s->evt, data, len);
486 static void usb_bt_out_hci_packet_acl(void *opaque,
487 const uint8_t *data, int len)
489 struct USBBtState *s = (struct USBBtState *) opaque;
491 usb_bt_fifo_enqueue(&s->acl, data, len);
494 static void usb_bt_handle_destroy(USBDevice *dev)
496 struct USBBtState *s = (struct USBBtState *) dev->opaque;
498 s->hci->opaque = NULL;
499 s->hci->evt_recv = NULL;
500 s->hci->acl_recv = NULL;
503 static int usb_bt_initfn(USBDevice *dev)
505 struct USBBtState *s = DO_UPCAST(struct USBBtState, dev, dev);
507 usb_desc_create_serial(dev);
509 s->intr = usb_ep_get(dev, USB_TOKEN_IN, USB_EVT_EP);
514 USBDevice *usb_bt_init(USBBus *bus, HCIInfo *hci)
517 struct USBBtState *s;
521 dev = usb_create_simple(bus, "usb-bt-dongle");
525 s = DO_UPCAST(struct USBBtState, dev, dev);
530 s->hci->evt_recv = usb_bt_out_hci_packet_event;
531 s->hci->acl_recv = usb_bt_out_hci_packet_acl;
533 usb_bt_handle_reset(&s->dev);
538 static const VMStateDescription vmstate_usb_bt = {
543 static void usb_bt_class_initfn(ObjectClass *klass, void *data)
545 DeviceClass *dc = DEVICE_CLASS(klass);
546 USBDeviceClass *uc = USB_DEVICE_CLASS(klass);
548 uc->init = usb_bt_initfn;
549 uc->product_desc = "QEMU BT dongle";
550 uc->usb_desc = &desc_bluetooth;
551 uc->handle_reset = usb_bt_handle_reset;
552 uc->handle_control = usb_bt_handle_control;
553 uc->handle_data = usb_bt_handle_data;
554 uc->handle_destroy = usb_bt_handle_destroy;
555 dc->vmsd = &vmstate_usb_bt;
558 static const TypeInfo bt_info = {
559 .name = "usb-bt-dongle",
560 .parent = TYPE_USB_DEVICE,
561 .instance_size = sizeof(struct USBBtState),
562 .class_init = usb_bt_class_initfn,
565 static void usb_bt_register_types(void)
567 type_register_static(&bt_info);
570 type_init(usb_bt_register_types)