tizen 2.3.1 release
[framework/connectivity/bluez.git] / android / handsfree.c
1 /*
2  *
3  *  BlueZ - Bluetooth protocol stack for Linux
4  *
5  *  Copyright (C) 2013-2014  Intel Corporation. All rights reserved.
6  *
7  *
8  *  This library is free software; you can redistribute it and/or
9  *  modify it under the terms of the GNU Lesser General Public
10  *  License as published by the Free Software Foundation; either
11  *  version 2.1 of the License, or (at your option) any later version.
12  *
13  *  This library is distributed in the hope that it will be useful,
14  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
15  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
16  *  Lesser General Public License for more details.
17  *
18  *  You should have received a copy of the GNU Lesser General Public
19  *  License along with this library; if not, write to the Free Software
20  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
21  *
22  */
23
24 #ifdef HAVE_CONFIG_H
25 #include <config.h>
26 #endif
27
28 #include <stdlib.h>
29 #include <stdbool.h>
30 #include <errno.h>
31 #include <unistd.h>
32 #include <glib.h>
33
34 #include "lib/bluetooth.h"
35 #include "lib/sdp.h"
36 #include "lib/sdp_lib.h"
37 #include "src/sdp-client.h"
38 #include "src/uuid-helper.h"
39 #include "src/shared/hfp.h"
40 #include "src/shared/queue.h"
41 #include "src/shared/util.h"
42 #include "btio/btio.h"
43 #include "hal-msg.h"
44 #include "ipc-common.h"
45 #include "ipc.h"
46 #include "handsfree.h"
47 #include "bluetooth.h"
48 #include "src/log.h"
49 #include "utils.h"
50 #include "sco-msg.h"
51 #include "sco.h"
52
53 #define HSP_AG_CHANNEL 12
54 #define HFP_AG_CHANNEL 13
55
56 #define HFP_AG_FEAT_3WAY        0x00000001
57 #define HFP_AG_FEAT_ECNR        0x00000002
58 #define HFP_AG_FEAT_VR          0x00000004
59 #define HFP_AG_FEAT_INBAND      0x00000008
60 #define HFP_AG_FEAT_VTAG        0x00000010
61 #define HFP_AG_FEAT_REJ_CALL    0x00000020
62 #define HFP_AG_FEAT_ECS         0x00000040
63 #define HFP_AG_FEAT_ECC         0x00000080
64 #define HFP_AG_FEAT_EXT_ERR     0x00000100
65 #define HFP_AG_FEAT_CODEC       0x00000200
66
67 #define HFP_HF_FEAT_ECNR        0x00000001
68 #define HFP_HF_FEAT_3WAY        0x00000002
69 #define HFP_HF_FEAT_CLI         0x00000004
70 #define HFP_HF_FEAT_VR          0x00000008
71 #define HFP_HF_FEAT_RVC         0x00000010
72 #define HFP_HF_FEAT_ECS         0x00000020
73 #define HFP_HF_FEAT_ECC         0x00000040
74 #define HFP_HF_FEAT_CODEC       0x00000080
75
76 #define HFP_AG_FEATURES (HFP_AG_FEAT_3WAY | HFP_AG_FEAT_ECNR |\
77                                 HFP_AG_FEAT_VR | HFP_AG_FEAT_REJ_CALL |\
78                                 HFP_AG_FEAT_ECS | HFP_AG_FEAT_EXT_ERR)
79
80 #define HFP_AG_CHLD "0,1,2,3"
81
82 /* offsets in indicators table, should be incremented when sending CIEV */
83 #define IND_SERVICE     0
84 #define IND_CALL        1
85 #define IND_CALLSETUP   2
86 #define IND_CALLHELD    3
87 #define IND_SIGNAL      4
88 #define IND_ROAM        5
89 #define IND_BATTCHG     6
90 #define IND_COUNT       (IND_BATTCHG + 1)
91
92 #define RING_TIMEOUT 2
93
94 #define CVSD_OFFSET 0
95 #define MSBC_OFFSET 1
96 #define CODECS_COUNT (MSBC_OFFSET + 1)
97
98 #define CODEC_ID_CVSD 0x01
99 #define CODEC_ID_MSBC 0x02
100
101 struct indicator {
102         const char *name;
103         int min;
104         int max;
105         int val;
106         bool always_active;
107         bool active;
108 };
109
110 struct hfp_codec {
111         uint8_t type;
112         bool local_supported;
113         bool remote_supported;
114 };
115
116 struct hf_device {
117         bdaddr_t bdaddr;
118         uint8_t state;
119         uint8_t audio_state;
120         uint32_t features;
121
122         bool clip_enabled;
123         bool cmee_enabled;
124         bool ccwa_enabled;
125         bool indicators_enabled;
126         struct indicator inds[IND_COUNT];
127         int num_active;
128         int num_held;
129         int setup_state;
130         guint call_hanging_up;
131
132         uint8_t negotiated_codec;
133         uint8_t proposed_codec;
134         struct hfp_codec codecs[CODECS_COUNT];
135
136         guint ring;
137         char *clip;
138         bool hsp;
139
140         struct hfp_gw *gw;
141         guint delay_sco;
142 };
143
144 static const struct indicator inds_defaults[] = {
145                 { "service",   0, 1, 0, false, true },
146                 { "call",      0, 1, 0, true, true },
147                 { "callsetup", 0, 3, 0, true, true },
148                 { "callheld",  0, 2, 0, true, true },
149                 { "signal",    0, 5, 0, false, true },
150                 { "roam",      0, 1, 0, false, true },
151                 { "battchg",   0, 5, 0, false, true },
152 };
153
154 static const struct hfp_codec codecs_defaults[] = {
155         { CODEC_ID_CVSD, true, false},
156         { CODEC_ID_MSBC, false, false},
157 };
158
159 static struct queue *devices = NULL;
160
161 static uint32_t hfp_ag_features = 0;
162
163 static bdaddr_t adapter_addr;
164
165 static struct ipc *hal_ipc = NULL;
166 static struct ipc *sco_ipc = NULL;
167
168 static uint32_t hfp_record_id = 0;
169 static GIOChannel *hfp_server = NULL;
170
171 static uint32_t hsp_record_id = 0;
172 static GIOChannel *hsp_server = NULL;
173
174 static struct bt_sco *sco = NULL;
175
176 static unsigned int max_hfp_clients = 0;
177
178 static void set_state(struct hf_device *dev, uint8_t state)
179 {
180         struct hal_ev_handsfree_conn_state ev;
181         char address[18];
182
183         if (dev->state == state)
184                 return;
185
186         dev->state = state;
187
188         ba2str(&dev->bdaddr, address);
189         DBG("device %s state %u", address, state);
190
191         bdaddr2android(&dev->bdaddr, ev.bdaddr);
192         ev.state = state;
193
194         ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
195                                 HAL_EV_HANDSFREE_CONN_STATE, sizeof(ev), &ev);
196 }
197
198 static void set_audio_state(struct hf_device *dev, uint8_t state)
199 {
200         struct hal_ev_handsfree_audio_state ev;
201         char address[18];
202
203         if (dev->audio_state == state)
204                 return;
205
206         dev->audio_state = state;
207
208         ba2str(&dev->bdaddr, address);
209         DBG("device %s audio state %u", address, state);
210
211         bdaddr2android(&dev->bdaddr, ev.bdaddr);
212         ev.state = state;
213
214         ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
215                                 HAL_EV_HANDSFREE_AUDIO_STATE, sizeof(ev), &ev);
216 }
217
218 static void init_codecs(struct hf_device *dev)
219 {
220         memcpy(dev->codecs, codecs_defaults, sizeof(dev->codecs));
221
222         if (hfp_ag_features & HFP_AG_FEAT_CODEC)
223                 dev->codecs[MSBC_OFFSET].local_supported = true;
224 }
225
226 static struct hf_device *device_create(const bdaddr_t *bdaddr)
227 {
228         struct hf_device *dev;
229
230         dev = new0(struct hf_device, 1);
231         if (!dev)
232                 return NULL;
233
234         bacpy(&dev->bdaddr, bdaddr);
235         dev->setup_state = HAL_HANDSFREE_CALL_STATE_IDLE;
236         dev->state = HAL_EV_HANDSFREE_CONN_STATE_DISCONNECTED;
237         dev->audio_state = HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTED;
238
239         memcpy(dev->inds, inds_defaults, sizeof(dev->inds));
240
241         init_codecs(dev);
242
243         if (!queue_push_head(devices, dev)) {
244                 free(dev);
245                 return NULL;
246         }
247
248         return dev;
249 }
250
251 static void device_destroy(struct hf_device *dev)
252 {
253         hfp_gw_unref(dev->gw);
254
255         if (dev->delay_sco)
256                 g_source_remove(dev->delay_sco);
257
258         if (dev->audio_state == HAL_EV_HANDSFREE_AUDIO_STATE_CONNECTED)
259                 bt_sco_disconnect(sco);
260
261         if (dev->ring)
262                 g_source_remove(dev->ring);
263
264         g_free(dev->clip);
265
266         if (dev->call_hanging_up)
267                 g_source_remove(dev->call_hanging_up);
268
269         set_audio_state(dev, HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTED);
270         set_state(dev, HAL_EV_HANDSFREE_CONN_STATE_DISCONNECTED);
271
272         queue_remove(devices, dev);
273         free(dev);
274 }
275
276 static bool match_by_bdaddr(const void *data, const void *match_data)
277 {
278         const struct hf_device *dev = data;
279         const bdaddr_t *addr = match_data;
280
281         return !bacmp(&dev->bdaddr, addr);
282 }
283
284 static struct hf_device *find_device(const bdaddr_t *bdaddr)
285 {
286         if (!bacmp(bdaddr, BDADDR_ANY))
287                 return queue_peek_head(devices);
288
289         return queue_find(devices, match_by_bdaddr, bdaddr);
290 }
291
292 static struct hf_device *get_device(const bdaddr_t *bdaddr)
293 {
294         struct hf_device *dev;
295
296         dev = find_device(bdaddr);
297         if (dev)
298                 return dev;
299
300         if (queue_length(devices) == max_hfp_clients)
301                 return NULL;
302
303         return device_create(bdaddr);
304 }
305
306 static void disconnect_watch(void *user_data)
307 {
308         struct hf_device *dev = user_data;
309
310         DBG("");
311
312         device_destroy(dev);
313 }
314
315 static void at_cmd_unknown(const char *command, void *user_data)
316 {
317         struct hf_device *dev = user_data;
318         uint8_t buf[IPC_MTU];
319         struct hal_ev_handsfree_unknown_at *ev = (void *) buf;
320
321         bdaddr2android(&dev->bdaddr, ev->bdaddr);
322
323         /* copy while string including terminating NULL */
324         ev->len = strlen(command) + 1;
325
326         if (ev->len > IPC_MTU - sizeof(*ev)) {
327                 hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
328                 return;
329         }
330
331         memcpy(ev->buf, command, ev->len);
332
333         ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
334                         HAL_EV_HANDSFREE_UNKNOWN_AT, sizeof(*ev) + ev->len, ev);
335 }
336
337 static void at_cmd_vgm(struct hfp_context *context,
338                                 enum hfp_gw_cmd_type type, void *user_data)
339 {
340         struct hf_device *dev = user_data;
341         struct hal_ev_handsfree_volume ev;
342         unsigned int val;
343
344         DBG("");
345
346         switch (type) {
347         case HFP_GW_CMD_TYPE_SET:
348                 if (!hfp_context_get_number(context, &val) || val > 15)
349                         break;
350
351                 if (hfp_context_has_next(context))
352                         break;
353
354                 ev.type = HAL_HANDSFREE_VOLUME_TYPE_MIC;
355                 ev.volume = val;
356                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
357
358                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
359                                 HAL_EV_HANDSFREE_VOLUME, sizeof(ev), &ev);
360
361                 /* Framework is not replying with result for AT+VGM */
362                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
363                 return;
364         case HFP_GW_CMD_TYPE_READ:
365         case HFP_GW_CMD_TYPE_TEST:
366         case HFP_GW_CMD_TYPE_COMMAND:
367                 break;
368         }
369
370         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
371 }
372
373 static void at_cmd_vgs(struct hfp_context *context,
374                                 enum hfp_gw_cmd_type type, void *user_data)
375 {
376         struct hf_device *dev = user_data;
377         struct hal_ev_handsfree_volume ev;
378         unsigned int val;
379
380         DBG("");
381
382         switch (type) {
383         case HFP_GW_CMD_TYPE_SET:
384                 if (!hfp_context_get_number(context, &val) || val > 15)
385                         break;
386
387                 if (hfp_context_has_next(context))
388                         break;
389
390                 ev.type = HAL_HANDSFREE_VOLUME_TYPE_SPEAKER;
391                 ev.volume = val;
392                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
393
394                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
395                                 HAL_EV_HANDSFREE_VOLUME, sizeof(ev), &ev);
396
397                 /* Framework is not replying with result for AT+VGS */
398                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
399                 return;
400         case HFP_GW_CMD_TYPE_READ:
401         case HFP_GW_CMD_TYPE_TEST:
402         case HFP_GW_CMD_TYPE_COMMAND:
403                 break;
404         }
405
406         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
407 }
408
409 static void at_cmd_cops(struct hfp_context *context,
410                                 enum hfp_gw_cmd_type type, void *user_data)
411 {
412         struct hf_device *dev = user_data;
413         struct hal_ev_handsfree_cops ev;
414         unsigned int val;
415
416         switch (type) {
417         case HFP_GW_CMD_TYPE_SET:
418                 if (!hfp_context_get_number(context, &val) || val != 3)
419                         break;
420
421                 if (!hfp_context_get_number(context, &val) || val != 0)
422                         break;
423
424                 if (hfp_context_has_next(context))
425                         break;
426
427                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
428                 return;
429         case HFP_GW_CMD_TYPE_READ:
430                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
431
432                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
433                                         HAL_EV_HANDSFREE_COPS, sizeof(ev), &ev);
434                 return;
435         case HFP_GW_CMD_TYPE_TEST:
436         case HFP_GW_CMD_TYPE_COMMAND:
437                 break;
438         }
439
440         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
441 }
442
443 static void at_cmd_bia(struct hfp_context *context,
444                                 enum hfp_gw_cmd_type type, void *user_data)
445 {
446         struct hf_device *dev = user_data;
447         unsigned int val, i, def;
448         bool tmp[IND_COUNT];
449
450         DBG("");
451
452         switch (type) {
453         case HFP_GW_CMD_TYPE_SET:
454                 for (i = 0; i < IND_COUNT; i++)
455                         tmp[i] = dev->inds[i].active;
456
457                 i = 0;
458
459                 do {
460                         def = (i < IND_COUNT) ? dev->inds[i].active : 0;
461
462                         if (!hfp_context_get_number_default(context, &val, def))
463                                 goto failed;
464
465                         if (val > 1)
466                                 goto failed;
467
468                         if (i < IND_COUNT) {
469                                 tmp[i] = val || dev->inds[i].always_active;
470                                 i++;
471                         }
472                 } while (hfp_context_has_next(context));
473
474                 for (i = 0; i < IND_COUNT; i++)
475                         dev->inds[i].active = tmp[i];
476
477                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
478                 return;
479         case HFP_GW_CMD_TYPE_TEST:
480         case HFP_GW_CMD_TYPE_READ:
481         case HFP_GW_CMD_TYPE_COMMAND:
482                 break;
483         }
484
485 failed:
486         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
487 }
488
489 static void at_cmd_a(struct hfp_context *context,
490                                 enum hfp_gw_cmd_type type, void *user_data)
491 {
492         struct hf_device *dev = user_data;
493         struct hal_ev_handsfree_answer ev;
494
495         DBG("");
496
497         switch (type) {
498         case HFP_GW_CMD_TYPE_COMMAND:
499                 if (hfp_context_has_next(context))
500                         break;
501
502                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
503
504                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
505                                 HAL_EV_HANDSFREE_ANSWER, sizeof(ev), &ev);
506
507                 /* Framework is not replying with result for ATA */
508                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
509                 return;
510         case HFP_GW_CMD_TYPE_SET:
511         case HFP_GW_CMD_TYPE_READ:
512         case HFP_GW_CMD_TYPE_TEST:
513                 break;
514         }
515
516         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
517 }
518
519 static void at_cmd_d(struct hfp_context *context,
520                                 enum hfp_gw_cmd_type type, void *user_data)
521 {
522         struct hf_device *dev = user_data;
523         char buf[IPC_MTU];
524         struct hal_ev_handsfree_dial *ev = (void *) buf;
525         int cnt;
526
527         DBG("");
528
529         switch (type) {
530         case HFP_GW_CMD_TYPE_SET:
531                 if (!hfp_context_get_unquoted_string(context,
532                                                 (char *) ev->number, 255))
533                         break;
534
535                 bdaddr2android(&dev->bdaddr, ev->bdaddr);
536
537                 ev->number_len = strlen((char *) ev->number);
538
539                 if (ev->number[ev->number_len - 1] != ';')
540                         break;
541
542                 if (ev->number[0] == '>')
543                         cnt = strspn((char *) ev->number + 1, "0123456789") + 1;
544                 else
545                         cnt = strspn((char *) ev->number, "0123456789ABC*#+");
546
547                 if (cnt != ev->number_len - 1)
548                         break;
549
550                 ev->number_len++;
551
552                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
553                                         HAL_EV_HANDSFREE_DIAL,
554                                         sizeof(*ev) + ev->number_len, ev);
555                 return;
556         case HFP_GW_CMD_TYPE_READ:
557         case HFP_GW_CMD_TYPE_TEST:
558         case HFP_GW_CMD_TYPE_COMMAND:
559                 break;
560         }
561
562         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
563 }
564
565 static void at_cmd_ccwa(struct hfp_context *context,
566                                 enum hfp_gw_cmd_type type, void *user_data)
567 {
568         struct hf_device *dev = user_data;
569         unsigned int val;
570
571         DBG("");
572
573         switch (type) {
574         case HFP_GW_CMD_TYPE_SET:
575                 if (!hfp_context_get_number(context, &val) || val > 1)
576                         break;
577
578                 if (hfp_context_has_next(context))
579                         break;
580
581                 dev->ccwa_enabled = val;
582
583                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
584                 return;
585         case HFP_GW_CMD_TYPE_READ:
586         case HFP_GW_CMD_TYPE_TEST:
587         case HFP_GW_CMD_TYPE_COMMAND:
588                 break;
589         }
590
591         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
592 }
593
594 static void at_cmd_chup(struct hfp_context *context,
595                                 enum hfp_gw_cmd_type type, void *user_data)
596 {
597         struct hf_device *dev = user_data;
598         struct hal_ev_handsfree_hangup ev;
599
600         DBG("");
601
602         switch (type) {
603         case HFP_GW_CMD_TYPE_COMMAND:
604                 if (hfp_context_has_next(context))
605                         break;
606
607                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
608
609                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
610                                 HAL_EV_HANDSFREE_HANGUP, sizeof(ev), &ev);
611
612                 /* Framework is not replying with result for AT+CHUP */
613                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
614                 return;
615         case HFP_GW_CMD_TYPE_READ:
616         case HFP_GW_CMD_TYPE_TEST:
617         case HFP_GW_CMD_TYPE_SET:
618                 break;
619         }
620
621         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
622 }
623
624 static void at_cmd_clcc(struct hfp_context *context,
625                                 enum hfp_gw_cmd_type type, void *user_data)
626 {
627         struct hf_device *dev = user_data;
628         struct hal_ev_handsfree_clcc ev;
629
630         DBG("");
631
632         switch (type) {
633         case HFP_GW_CMD_TYPE_COMMAND:
634                 if (hfp_context_has_next(context))
635                         break;
636
637                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
638
639                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
640                                         HAL_EV_HANDSFREE_CLCC, sizeof(ev), &ev);
641                 return;
642         case HFP_GW_CMD_TYPE_READ:
643         case HFP_GW_CMD_TYPE_TEST:
644         case HFP_GW_CMD_TYPE_SET:
645                 break;
646         }
647
648         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
649 }
650
651 static void at_cmd_cmee(struct hfp_context *context,
652                                 enum hfp_gw_cmd_type type, void *user_data)
653 {
654         struct hf_device *dev = user_data;
655         unsigned int val;
656
657         DBG("");
658
659         switch (type) {
660         case HFP_GW_CMD_TYPE_SET:
661                 if (!hfp_context_get_number(context, &val) || val > 1)
662                         break;
663
664                 if (hfp_context_has_next(context))
665                         break;
666
667                 dev->cmee_enabled = val;
668
669                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
670                 return;
671         case HFP_GW_CMD_TYPE_READ:
672         case HFP_GW_CMD_TYPE_TEST:
673         case HFP_GW_CMD_TYPE_COMMAND:
674                 break;
675         }
676
677         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
678 }
679
680 static void at_cmd_clip(struct hfp_context *context,
681                                 enum hfp_gw_cmd_type type, void *user_data)
682 {
683         struct hf_device *dev = user_data;
684         unsigned int val;
685
686         DBG("");
687
688         switch (type) {
689         case HFP_GW_CMD_TYPE_SET:
690                 if (!hfp_context_get_number(context, &val) || val > 1)
691                         break;
692
693                 if (hfp_context_has_next(context))
694                         break;
695
696                 dev->clip_enabled = val;
697
698                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
699                 return;
700         case HFP_GW_CMD_TYPE_READ:
701         case HFP_GW_CMD_TYPE_TEST:
702         case HFP_GW_CMD_TYPE_COMMAND:
703                 break;
704         }
705
706         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
707 }
708
709 static void at_cmd_vts(struct hfp_context *context,
710                                 enum hfp_gw_cmd_type type, void *user_data)
711 {
712         struct hf_device *dev = user_data;
713         struct hal_ev_handsfree_dtmf ev;
714         char str[2];
715
716         DBG("");
717
718         switch (type) {
719         case HFP_GW_CMD_TYPE_SET:
720                 if (!hfp_context_get_unquoted_string(context, str, 2))
721                         break;
722
723                 if (!((str[0] >= '0' && str[0] <= '9') ||
724                                 (str[0] >= 'A' && str[0] <= 'D') ||
725                                 str[0] == '*' || str[0] == '#'))
726                         break;
727
728                 if (hfp_context_has_next(context))
729                         break;
730
731                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
732                 ev.tone = str[0];
733
734                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
735                                         HAL_EV_HANDSFREE_DTMF, sizeof(ev), &ev);
736
737                 /* Framework is not replying with result for AT+VTS */
738                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
739                 return;
740         case HFP_GW_CMD_TYPE_READ:
741         case HFP_GW_CMD_TYPE_TEST:
742         case HFP_GW_CMD_TYPE_COMMAND:
743                 break;
744         }
745
746         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
747 }
748
749 static void at_cmd_cnum(struct hfp_context *context,
750                                 enum hfp_gw_cmd_type type, void *user_data)
751 {
752         struct hf_device *dev = user_data;
753         struct hal_ev_handsfree_cnum ev;
754
755         DBG("");
756
757         switch (type) {
758         case HFP_GW_CMD_TYPE_COMMAND:
759                 if (hfp_context_has_next(context))
760                         break;
761
762                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
763
764                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
765                                         HAL_EV_HANDSFREE_CNUM, sizeof(ev), &ev);
766                 return;
767         case HFP_GW_CMD_TYPE_SET:
768         case HFP_GW_CMD_TYPE_READ:
769         case HFP_GW_CMD_TYPE_TEST:
770                 break;
771         }
772
773         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
774 }
775
776 static void at_cmd_binp(struct hfp_context *context,
777                                 enum hfp_gw_cmd_type type, void *user_data)
778 {
779         struct hf_device *dev = user_data;
780
781         DBG("");
782
783         /* TODO */
784
785         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
786 }
787
788 static void at_cmd_bldn(struct hfp_context *context,
789                                 enum hfp_gw_cmd_type type, void *user_data)
790 {
791         struct hf_device *dev = user_data;
792         struct hal_ev_handsfree_dial ev;
793
794         DBG("");
795
796         switch (type) {
797         case HFP_GW_CMD_TYPE_COMMAND:
798                 if (hfp_context_has_next(context))
799                         break;
800
801                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
802                 ev.number_len = 0;
803
804                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
805                                         HAL_EV_HANDSFREE_DIAL, sizeof(ev), &ev);
806                 return;
807         case HFP_GW_CMD_TYPE_READ:
808         case HFP_GW_CMD_TYPE_TEST:
809         case HFP_GW_CMD_TYPE_SET:
810                 break;
811         }
812
813         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
814 }
815
816 static void at_cmd_bvra(struct hfp_context *context,
817                                 enum hfp_gw_cmd_type type, void *user_data)
818 {
819         struct hf_device *dev = user_data;
820         struct hal_ev_handsfree_vr_state ev;
821         unsigned int val;
822
823         DBG("");
824
825         switch (type) {
826         case HFP_GW_CMD_TYPE_SET:
827                 if (!hfp_context_get_number(context, &val) || val > 1)
828                         break;
829
830                 if (hfp_context_has_next(context))
831                         break;
832
833                 if (val)
834                         ev.state = HAL_HANDSFREE_VR_STARTED;
835                 else
836                         ev.state = HAL_HANDSFREE_VR_STOPPED;
837
838                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
839
840                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
841                                         HAL_EV_HANDSFREE_VR, sizeof(ev), &ev);
842                 return;
843         case HFP_GW_CMD_TYPE_READ:
844         case HFP_GW_CMD_TYPE_TEST:
845         case HFP_GW_CMD_TYPE_COMMAND:
846                 break;
847         }
848
849         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
850 }
851
852 static void at_cmd_nrec(struct hfp_context *context,
853                                 enum hfp_gw_cmd_type type, void *user_data)
854 {
855         struct hf_device *dev = user_data;
856         struct hal_ev_handsfree_nrec ev;
857         unsigned int val;
858
859         DBG("");
860
861         switch (type) {
862         case HFP_GW_CMD_TYPE_SET:
863                 /*
864                  * Android HAL defines start and stop parameter for NREC
865                  * callback, but spec allows HF to only disable AG's NREC
866                  * feature for SLC duration. Follow spec here.
867                  */
868                 if (!hfp_context_get_number(context, &val) || val != 0)
869                         break;
870
871                 if (hfp_context_has_next(context))
872                         break;
873
874                 ev.nrec = HAL_HANDSFREE_NREC_STOP;
875                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
876
877                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
878                                         HAL_EV_HANDSFREE_NREC, sizeof(ev), &ev);
879
880                 /* Framework is not replying with context for AT+NREC */
881                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
882                 return;
883         case HFP_GW_CMD_TYPE_READ:
884         case HFP_GW_CMD_TYPE_TEST:
885         case HFP_GW_CMD_TYPE_COMMAND:
886                 break;
887         }
888
889         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
890 }
891
892 static void at_cmd_bsir(struct hfp_context *context,
893                                 enum hfp_gw_cmd_type type, void *user_data)
894 {
895         struct hf_device *dev = user_data;
896
897         DBG("");
898
899         /* TODO */
900
901         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
902 }
903
904 static void at_cmd_btrh(struct hfp_context *context,
905                                 enum hfp_gw_cmd_type type, void *user_data)
906 {
907         struct hf_device *dev = user_data;
908
909         DBG("");
910
911         /* TODO */
912
913         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
914 }
915
916 static void disconnect_sco_cb(const bdaddr_t *addr)
917 {
918         struct hf_device *dev;
919
920         DBG("");
921
922         dev = find_device(addr);
923         if (!dev) {
924                 error("handsfree: Could not find device");
925                 return;
926         }
927
928         set_audio_state(dev, HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTED);
929 }
930
931 static void select_codec(struct hf_device *dev, uint8_t codec_type)
932 {
933         uint8_t type = CODEC_ID_CVSD;
934         int i;
935
936         if (codec_type > 0) {
937                 type = codec_type;
938                 goto done;
939         }
940
941         for (i = CODECS_COUNT - 1; i >= CVSD_OFFSET; i--) {
942                 if (!dev->codecs[i].local_supported)
943                         continue;
944
945                 if (!dev->codecs[i].remote_supported)
946                         continue;
947
948                 type = dev->codecs[i].type;
949                 break;
950         }
951
952 done:
953         dev->proposed_codec = type;
954
955         hfp_gw_send_info(dev->gw, "+BCS: %u", type);
956 }
957
958 static bool codec_negotiation_supported(struct hf_device *dev)
959 {
960         return (dev->features & HFP_HF_FEAT_CODEC) &&
961                         (hfp_ag_features & HFP_AG_FEAT_CODEC);
962 }
963
964 static void connect_sco_cb(enum sco_status status, const bdaddr_t *addr)
965 {
966         struct hf_device *dev;
967
968         dev = find_device(addr);
969         if (!dev) {
970                 error("handsfree: Connect sco failed, no device?");
971                 return;
972         }
973
974         if (status == SCO_STATUS_OK) {
975                 set_audio_state(dev, HAL_EV_HANDSFREE_AUDIO_STATE_CONNECTED);
976                 return;
977         }
978
979         /* Try fallback to CVSD first */
980         if (codec_negotiation_supported(dev) &&
981                                 dev->negotiated_codec != CODEC_ID_CVSD) {
982                 info("handsfree: trying fallback with CVSD");
983                 select_codec(dev, CODEC_ID_CVSD);
984                 return;
985         }
986
987         error("handsfree: audio connect failed");
988         set_audio_state(dev, HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTED);
989 }
990
991 static bool connect_sco(struct hf_device *dev)
992 {
993         uint16_t voice_settings;
994
995         if (codec_negotiation_supported(dev) &&
996                         dev->negotiated_codec != CODEC_ID_CVSD)
997                 voice_settings = BT_VOICE_TRANSPARENT;
998         else
999                 voice_settings = BT_VOICE_CVSD_16BIT;
1000
1001         if (!bt_sco_connect(sco, &dev->bdaddr, voice_settings))
1002                 return false;
1003
1004         set_audio_state(dev, HAL_EV_HANDSFREE_AUDIO_STATE_CONNECTING);
1005
1006         return true;
1007 }
1008
1009 static gboolean connect_sco_delayed(void *data)
1010 {
1011         struct hf_device *dev = data;
1012
1013         DBG("");
1014
1015         dev->delay_sco = 0;
1016
1017         if (connect_sco(dev))
1018                 return FALSE;
1019
1020         /*
1021          * we try connect to negotiated codec. If it fails, and it isn't
1022          * CVSD codec, try connect CVSD
1023          */
1024         if (dev->negotiated_codec != CODEC_ID_CVSD)
1025                 select_codec(dev, CODEC_ID_CVSD);
1026
1027         return FALSE;
1028 }
1029
1030 static void at_cmd_bcc(struct hfp_context *result, enum hfp_gw_cmd_type type,
1031                                                                 void *user_data)
1032 {
1033         struct hf_device *dev = user_data;
1034
1035         DBG("");
1036
1037         switch (type) {
1038         case HFP_GW_CMD_TYPE_COMMAND:
1039                 if (!codec_negotiation_supported(dev))
1040                         break;
1041
1042                 if (hfp_context_has_next(result))
1043                         break;
1044
1045                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
1046
1047                 /* we haven't negotiated codec, start selection */
1048                 if (!dev->negotiated_codec) {
1049                         select_codec(dev, 0);
1050                         return;
1051                 }
1052
1053                 /* Delay SCO connection so that OK response is send first */
1054                 if (dev->delay_sco == 0)
1055                         dev->delay_sco = g_idle_add(connect_sco_delayed, dev);
1056                 return;
1057         case HFP_GW_CMD_TYPE_READ:
1058         case HFP_GW_CMD_TYPE_TEST:
1059         case HFP_GW_CMD_TYPE_SET:
1060                 break;
1061         }
1062
1063         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
1064 }
1065
1066 static void at_cmd_bcs(struct hfp_context *result, enum hfp_gw_cmd_type type,
1067                                                                 void *user_data)
1068 {
1069         struct hf_device *dev = user_data;
1070         unsigned int val;
1071
1072         DBG("");
1073
1074         switch (type) {
1075         case HFP_GW_CMD_TYPE_SET:
1076                 if (!hfp_context_get_number(result, &val))
1077                         break;
1078
1079                 if (hfp_context_has_next(result))
1080                         break;
1081
1082                 /* Remote replied with other codec. Reply with error */
1083                 if (dev->proposed_codec != val) {
1084                         dev->proposed_codec = 0;
1085                         break;
1086                 }
1087
1088                 dev->proposed_codec = 0;
1089                 dev->negotiated_codec = val;
1090
1091                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
1092
1093                 /*
1094                  * Delay SCO connection so that OK response is send first,
1095                  * then connect with negotiated parameters.
1096                  */
1097                 if (dev->delay_sco == 0)
1098                         dev->delay_sco = g_idle_add(connect_sco_delayed, dev);
1099                 return;
1100         case HFP_GW_CMD_TYPE_READ:
1101         case HFP_GW_CMD_TYPE_TEST:
1102         case HFP_GW_CMD_TYPE_COMMAND:
1103                 break;
1104         }
1105
1106         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
1107 }
1108
1109 static void at_cmd_ckpd(struct hfp_context *result, enum hfp_gw_cmd_type type,
1110                                                                 void *user_data)
1111 {
1112         struct hf_device *dev = user_data;
1113         struct hal_ev_handsfree_hsp_key_press ev;
1114         unsigned int val;
1115
1116         DBG("");
1117
1118         switch (type) {
1119         case HFP_GW_CMD_TYPE_SET:
1120                 if (!hfp_context_get_number(result, &val) || val != 200)
1121                         break;
1122
1123                 if (hfp_context_has_next(result))
1124                         break;
1125
1126                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
1127
1128                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1129                                                 HAL_EV_HANDSFREE_HSP_KEY_PRESS,
1130                                                 sizeof(ev), &ev);
1131
1132                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
1133                 return;
1134         case HFP_GW_CMD_TYPE_READ:
1135         case HFP_GW_CMD_TYPE_TEST:
1136         case HFP_GW_CMD_TYPE_COMMAND:
1137                 break;
1138         }
1139
1140         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
1141 }
1142
1143 static void register_post_slc_at(struct hf_device *dev)
1144 {
1145         hfp_gw_set_command_handler(dev->gw, at_cmd_unknown, dev, NULL);
1146
1147         if (dev->hsp) {
1148                 hfp_gw_register(dev->gw, at_cmd_ckpd, "+CKPD", dev, NULL);
1149                 hfp_gw_register(dev->gw, at_cmd_vgs, "+VGS", dev, NULL);
1150                 hfp_gw_register(dev->gw, at_cmd_vgm, "+VGM", dev, NULL);
1151                 return;
1152         }
1153
1154         hfp_gw_register(dev->gw, at_cmd_a, "A", dev, NULL);
1155         hfp_gw_register(dev->gw, at_cmd_d, "D", dev, NULL);
1156         hfp_gw_register(dev->gw, at_cmd_ccwa, "+CCWA", dev, NULL);
1157         hfp_gw_register(dev->gw, at_cmd_chup, "+CHUP", dev, NULL);
1158         hfp_gw_register(dev->gw, at_cmd_clcc, "+CLCC", dev, NULL);
1159         hfp_gw_register(dev->gw, at_cmd_cops, "+COPS", dev, NULL);
1160         hfp_gw_register(dev->gw, at_cmd_cmee, "+CMEE", dev, NULL);
1161         hfp_gw_register(dev->gw, at_cmd_clip, "+CLIP", dev, NULL);
1162         hfp_gw_register(dev->gw, at_cmd_vts, "+VTS", dev, NULL);
1163         hfp_gw_register(dev->gw, at_cmd_cnum, "+CNUM", dev, NULL);
1164         hfp_gw_register(dev->gw, at_cmd_bia, "+BIA", dev, NULL);
1165         hfp_gw_register(dev->gw, at_cmd_binp, "+BINP", dev, NULL);
1166         hfp_gw_register(dev->gw, at_cmd_bldn, "+BLDN", dev, NULL);
1167         hfp_gw_register(dev->gw, at_cmd_bvra, "+BVRA", dev, NULL);
1168         hfp_gw_register(dev->gw, at_cmd_nrec, "+NREC", dev, NULL);
1169         hfp_gw_register(dev->gw, at_cmd_vgs, "+VGS", dev, NULL);
1170         hfp_gw_register(dev->gw, at_cmd_vgm, "+VGM", dev, NULL);
1171         hfp_gw_register(dev->gw, at_cmd_bsir, "+BSIR", dev, NULL);
1172         hfp_gw_register(dev->gw, at_cmd_btrh, "+BTRH", dev, NULL);
1173         hfp_gw_register(dev->gw, at_cmd_bcc, "+BCC", dev, NULL);
1174         hfp_gw_register(dev->gw, at_cmd_bcs, "+BCS", dev, NULL);
1175 }
1176
1177 static void at_cmd_cmer(struct hfp_context *result, enum hfp_gw_cmd_type type,
1178                                                                 void *user_data)
1179 {
1180         struct hf_device *dev = user_data;
1181         unsigned int val;
1182
1183         switch (type) {
1184         case HFP_GW_CMD_TYPE_SET:
1185                 /* mode must be =3 */
1186                 if (!hfp_context_get_number(result, &val) || val != 3)
1187                         break;
1188
1189                 /* keyp is don't care */
1190                 if (!hfp_context_get_number(result, &val))
1191                         break;
1192
1193                 /* disp is don't care */
1194                 if (!hfp_context_get_number(result, &val))
1195                         break;
1196
1197                 /* ind must be 0 or 1 */
1198                 if (!hfp_context_get_number(result, &val) || val > 1)
1199                         break;
1200
1201                 dev->indicators_enabled = val;
1202
1203                 /* skip bfr if present */
1204                 hfp_context_get_number(result, &val);
1205
1206                 if (hfp_context_has_next(result))
1207                         break;
1208
1209                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
1210
1211                 if (dev->features & HFP_HF_FEAT_3WAY)
1212                         return;
1213
1214                 register_post_slc_at(dev);
1215                 set_state(dev, HAL_EV_HANDSFREE_CONN_STATE_SLC_CONNECTED);
1216                 return;
1217         case HFP_GW_CMD_TYPE_TEST:
1218         case HFP_GW_CMD_TYPE_READ:
1219         case HFP_GW_CMD_TYPE_COMMAND:
1220                 break;
1221         }
1222
1223         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
1224
1225         if (dev->state != HAL_EV_HANDSFREE_CONN_STATE_SLC_CONNECTED)
1226                 hfp_gw_disconnect(dev->gw);
1227 }
1228
1229 static void at_cmd_cind(struct hfp_context *result, enum hfp_gw_cmd_type type,
1230                                                                 void *user_data)
1231 {
1232         struct hf_device *dev = user_data;
1233         struct hal_ev_handsfree_cind ev;
1234         char *buf, *ptr;
1235         int len;
1236         unsigned int i;
1237
1238         switch (type) {
1239         case HFP_GW_CMD_TYPE_TEST:
1240
1241                 /*
1242                  * If device supports Codec Negotiation, AT+BAC should be
1243                  * received first
1244                  */
1245                 if (codec_negotiation_supported(dev) &&
1246                                 !dev->codecs[CVSD_OFFSET].remote_supported)
1247                         break;
1248
1249                 len = strlen("+CIND:") + 1;
1250
1251                 for (i = 0; i < IND_COUNT; i++) {
1252                         len += strlen("(\"\",(X,X)),");
1253                         len += strlen(dev->inds[i].name);
1254                 }
1255
1256                 buf = g_malloc(len);
1257
1258                 ptr = buf + sprintf(buf, "+CIND:");
1259
1260                 for (i = 0; i < IND_COUNT; i++) {
1261                         ptr += sprintf(ptr, "(\"%s\",(%d%c%d)),",
1262                                         dev->inds[i].name,
1263                                         dev->inds[i].min,
1264                                         dev->inds[i].max == 1 ? ',' : '-',
1265                                         dev->inds[i].max);
1266                 }
1267
1268                 ptr--;
1269                 *ptr = '\0';
1270
1271                 hfp_gw_send_info(dev->gw, "%s", buf);
1272                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
1273
1274                 g_free(buf);
1275                 return;
1276         case HFP_GW_CMD_TYPE_READ:
1277                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
1278
1279                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1280                                         HAL_EV_HANDSFREE_CIND, sizeof(ev), &ev);
1281                 return;
1282         case HFP_GW_CMD_TYPE_SET:
1283         case HFP_GW_CMD_TYPE_COMMAND:
1284                 break;
1285         }
1286
1287         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
1288
1289         if (dev->state != HAL_EV_HANDSFREE_CONN_STATE_SLC_CONNECTED)
1290                 hfp_gw_disconnect(dev->gw);
1291 }
1292
1293 static void at_cmd_brsf(struct hfp_context *result, enum hfp_gw_cmd_type type,
1294                                                                 void *user_data)
1295 {
1296         struct hf_device *dev = user_data;
1297         unsigned int feat;
1298
1299         switch (type) {
1300         case HFP_GW_CMD_TYPE_SET:
1301                 if (!hfp_context_get_number(result, &feat))
1302                         break;
1303
1304                 if (hfp_context_has_next(result))
1305                         break;
1306
1307                 /* TODO verify features */
1308                 dev->features = feat;
1309
1310                 hfp_gw_send_info(dev->gw, "+BRSF: %u", hfp_ag_features);
1311                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
1312                 return;
1313         case HFP_GW_CMD_TYPE_READ:
1314         case HFP_GW_CMD_TYPE_TEST:
1315         case HFP_GW_CMD_TYPE_COMMAND:
1316                 break;
1317         }
1318
1319         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
1320
1321         if (dev->state != HAL_EV_HANDSFREE_CONN_STATE_SLC_CONNECTED)
1322                 hfp_gw_disconnect(dev->gw);
1323 }
1324
1325 static void at_cmd_chld(struct hfp_context *result, enum hfp_gw_cmd_type type,
1326                                                                 void *user_data)
1327 {
1328         struct hf_device *dev = user_data;
1329         struct hal_ev_handsfree_chld ev;
1330         unsigned int val;
1331
1332         DBG("");
1333
1334         switch (type) {
1335         case HFP_GW_CMD_TYPE_SET:
1336                 if (!hfp_context_get_number(result, &val) || val > 3)
1337                         break;
1338
1339                 /* No ECC support */
1340                 if (hfp_context_has_next(result))
1341                         break;
1342
1343                 /* value match HAL type */
1344                 ev.chld = val;
1345                 bdaddr2android(&dev->bdaddr, ev.bdaddr);
1346
1347                 ipc_send_notif(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1348                                         HAL_EV_HANDSFREE_CHLD, sizeof(ev), &ev);
1349                 return;
1350         case HFP_GW_CMD_TYPE_TEST:
1351                 hfp_gw_send_info(dev->gw, "+CHLD: (%s)", HFP_AG_CHLD);
1352                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
1353
1354                 register_post_slc_at(dev);
1355                 set_state(dev, HAL_EV_HANDSFREE_CONN_STATE_SLC_CONNECTED);
1356                 return;
1357         case HFP_GW_CMD_TYPE_READ:
1358         case HFP_GW_CMD_TYPE_COMMAND:
1359                 break;
1360         }
1361
1362         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
1363
1364         if (dev->state != HAL_EV_HANDSFREE_CONN_STATE_SLC_CONNECTED)
1365                 hfp_gw_disconnect(dev->gw);
1366 }
1367
1368 static struct hfp_codec *find_codec_by_type(struct hf_device *dev, uint8_t type)
1369 {
1370         int i;
1371
1372         for (i = 0; i < CODECS_COUNT; i++)
1373                 if (type == dev->codecs[i].type)
1374                         return &dev->codecs[i];
1375
1376         return NULL;
1377 }
1378
1379 static void at_cmd_bac(struct hfp_context *result, enum hfp_gw_cmd_type type,
1380                                                                 void *user_data)
1381 {
1382         struct hf_device *dev = user_data;
1383         unsigned int val;
1384
1385         DBG("");
1386
1387         switch (type) {
1388         case HFP_GW_CMD_TYPE_SET:
1389                 if (!codec_negotiation_supported(dev))
1390                         goto failed;
1391
1392                 /* set codecs to defaults */
1393                 init_codecs(dev);
1394                 dev->negotiated_codec = 0;
1395
1396                 /*
1397                  * At least CVSD mandatory codec must exist
1398                  * HFP V1.6 4.34.1
1399                  */
1400                 if (!hfp_context_get_number(result, &val) ||
1401                                                         val != CODEC_ID_CVSD)
1402                         goto failed;
1403
1404                 dev->codecs[CVSD_OFFSET].remote_supported = true;
1405
1406                 if (hfp_context_get_number(result, &val)) {
1407                         if (val != CODEC_ID_MSBC)
1408                                 goto failed;
1409
1410                         dev->codecs[MSBC_OFFSET].remote_supported = true;
1411                 }
1412
1413                 while (hfp_context_has_next(result)) {
1414                         struct hfp_codec *codec;
1415
1416                         if (!hfp_context_get_number(result, &val))
1417                                 goto failed;
1418
1419                         codec = find_codec_by_type(dev, val);
1420                         if (!codec)
1421                                 continue;
1422
1423                         codec->remote_supported = true;
1424                 }
1425
1426                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
1427
1428                 if (dev->proposed_codec)
1429                         select_codec(dev, 0);
1430                 return;
1431         case HFP_GW_CMD_TYPE_TEST:
1432         case HFP_GW_CMD_TYPE_READ:
1433         case HFP_GW_CMD_TYPE_COMMAND:
1434                 break;
1435         }
1436
1437 failed:
1438         hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
1439
1440         if (dev->state != HAL_EV_HANDSFREE_CONN_STATE_SLC_CONNECTED)
1441                 hfp_gw_disconnect(dev->gw);
1442 }
1443
1444 static void register_slc_at(struct hf_device *dev)
1445 {
1446         hfp_gw_register(dev->gw, at_cmd_brsf, "+BRSF", dev, NULL);
1447         hfp_gw_register(dev->gw, at_cmd_cind, "+CIND", dev, NULL);
1448         hfp_gw_register(dev->gw, at_cmd_cmer, "+CMER", dev, NULL);
1449         hfp_gw_register(dev->gw, at_cmd_chld, "+CHLD", dev, NULL);
1450         hfp_gw_register(dev->gw, at_cmd_bac, "+BAC", dev, NULL);
1451 }
1452
1453 static void connect_cb(GIOChannel *chan, GError *err, gpointer user_data)
1454 {
1455         struct hf_device *dev = user_data;
1456
1457         DBG("");
1458
1459         if (err) {
1460                 error("handsfree: connect failed (%s)", err->message);
1461                 goto failed;
1462         }
1463
1464         dev->gw = hfp_gw_new(g_io_channel_unix_get_fd(chan));
1465         if (!dev->gw)
1466                 goto failed;
1467
1468         g_io_channel_set_close_on_unref(chan, FALSE);
1469
1470         hfp_gw_set_close_on_unref(dev->gw, true);
1471         hfp_gw_set_disconnect_handler(dev->gw, disconnect_watch, dev, NULL);
1472
1473         if (dev->hsp) {
1474                 register_post_slc_at(dev);
1475                 set_state(dev, HAL_EV_HANDSFREE_CONN_STATE_CONNECTED);
1476                 set_state(dev, HAL_EV_HANDSFREE_CONN_STATE_SLC_CONNECTED);
1477                 return;
1478         }
1479
1480         register_slc_at(dev);
1481         set_state(dev, HAL_EV_HANDSFREE_CONN_STATE_CONNECTED);
1482         return;
1483
1484 failed:
1485         g_io_channel_shutdown(chan, TRUE, NULL);
1486         device_destroy(dev);
1487 }
1488
1489 static void confirm_cb(GIOChannel *chan, gpointer data)
1490 {
1491         char address[18];
1492         bdaddr_t bdaddr;
1493         GError *err = NULL;
1494         struct hf_device *dev;
1495
1496         bt_io_get(chan, &err,
1497                         BT_IO_OPT_DEST, address,
1498                         BT_IO_OPT_DEST_BDADDR, &bdaddr,
1499                         BT_IO_OPT_INVALID);
1500         if (err) {
1501                 error("handsfree: confirm failed (%s)", err->message);
1502                 g_error_free(err);
1503                 goto drop;
1504         }
1505
1506         DBG("incoming connect from %s", address);
1507
1508         dev = get_device(&bdaddr);
1509         if (!dev) {
1510                 error("handsfree: Failed to get device object for %s", address);
1511                 goto drop;
1512         }
1513
1514         if (dev->state != HAL_EV_HANDSFREE_CONN_STATE_DISCONNECTED) {
1515                 info("handsfree: refusing connection from %s", address);
1516                 goto drop;
1517         }
1518
1519         if (!bt_io_accept(chan, connect_cb, dev, NULL, NULL)) {
1520                 error("handsfree: failed to accept connection");
1521                 device_destroy(dev);
1522                 goto drop;
1523         }
1524
1525         dev->hsp = GPOINTER_TO_INT(data);
1526
1527         set_state(dev, HAL_EV_HANDSFREE_CONN_STATE_CONNECTING);
1528
1529         return;
1530
1531 drop:
1532         g_io_channel_shutdown(chan, TRUE, NULL);
1533 }
1534
1535 static void sdp_hsp_search_cb(sdp_list_t *recs, int err, gpointer data)
1536 {
1537         struct hf_device *dev = data;
1538         sdp_list_t *protos;
1539         GError *gerr = NULL;
1540         GIOChannel *io;
1541         uuid_t class;
1542         int channel;
1543
1544         DBG("");
1545
1546         if (err < 0) {
1547                 error("handsfree: unable to get SDP record: %s",
1548                                                                 strerror(-err));
1549                 goto fail;
1550         }
1551
1552         sdp_uuid16_create(&class, HEADSET_SVCLASS_ID);
1553
1554         /* Find record with proper service class */
1555         for (; recs; recs = recs->next) {
1556                 sdp_record_t *rec = recs->data;
1557
1558                 if (rec && !sdp_uuid_cmp(&rec->svclass, &class))
1559                         break;
1560         }
1561
1562         if (!recs || !recs->data) {
1563                 info("handsfree: no valid HSP SDP records found");
1564                 goto fail;
1565         }
1566
1567         if (sdp_get_access_protos(recs->data, &protos) < 0) {
1568                 error("handsfree: unable to get access protocols from record");
1569                 goto fail;
1570         }
1571
1572         /* TODO read remote version? */
1573         /* TODO read volume control support */
1574
1575         channel = sdp_get_proto_port(protos, RFCOMM_UUID);
1576         sdp_list_foreach(protos, (sdp_list_func_t) sdp_list_free, NULL);
1577         sdp_list_free(protos, NULL);
1578         if (channel <= 0) {
1579                 error("handsfree: unable to get RFCOMM channel from record");
1580                 goto fail;
1581         }
1582
1583         io = bt_io_connect(connect_cb, dev, NULL, &gerr,
1584                                 BT_IO_OPT_SOURCE_BDADDR, &adapter_addr,
1585                                 BT_IO_OPT_DEST_BDADDR, &dev->bdaddr,
1586                                 BT_IO_OPT_SEC_LEVEL, BT_IO_SEC_MEDIUM,
1587                                 BT_IO_OPT_CHANNEL, channel,
1588                                 BT_IO_OPT_INVALID);
1589         if (!io) {
1590                 error("handsfree: unable to connect: %s", gerr->message);
1591                 g_error_free(gerr);
1592                 goto fail;
1593         }
1594
1595         dev->hsp = true;
1596
1597         g_io_channel_unref(io);
1598         return;
1599
1600 fail:
1601         device_destroy(dev);
1602 }
1603
1604 static int sdp_search_hsp(struct hf_device *dev)
1605 {
1606         uuid_t uuid;
1607
1608         sdp_uuid16_create(&uuid, HEADSET_SVCLASS_ID);
1609
1610         return bt_search_service(&adapter_addr, &dev->bdaddr, &uuid,
1611                                         sdp_hsp_search_cb, dev, NULL, 0);
1612 }
1613
1614 static void sdp_hfp_search_cb(sdp_list_t *recs, int err, gpointer data)
1615 {
1616         struct hf_device *dev = data;
1617         sdp_list_t *protos;
1618         GError *gerr = NULL;
1619         GIOChannel *io;
1620         uuid_t class;
1621         int channel;
1622
1623         DBG("");
1624
1625         if (err < 0) {
1626                 error("handsfree: unable to get SDP record: %s",
1627                                                                 strerror(-err));
1628                 goto fail;
1629         }
1630
1631         sdp_uuid16_create(&class, HANDSFREE_SVCLASS_ID);
1632
1633         /* Find record with proper service class */
1634         for (; recs; recs = recs->next) {
1635                 sdp_record_t *rec = recs->data;
1636
1637                 if (rec && !sdp_uuid_cmp(&rec->svclass, &class))
1638                         break;
1639         }
1640
1641         if (!recs || !recs->data) {
1642                 info("handsfree: no HFP SDP records found, trying HSP");
1643
1644                 if (sdp_search_hsp(dev) < 0) {
1645                         error("handsfree: HSP SDP search failed");
1646                         goto fail;
1647                 }
1648
1649                 return;
1650         }
1651
1652         if (sdp_get_access_protos(recs->data, &protos) < 0) {
1653                 error("handsfree: unable to get access protocols from record");
1654                 goto fail;
1655         }
1656
1657         channel = sdp_get_proto_port(protos, RFCOMM_UUID);
1658         sdp_list_foreach(protos, (sdp_list_func_t) sdp_list_free, NULL);
1659         sdp_list_free(protos, NULL);
1660         if (channel <= 0) {
1661                 error("handsfree: unable to get RFCOMM channel from record");
1662                 goto fail;
1663         }
1664
1665         /* TODO read remote version? */
1666
1667         io = bt_io_connect(connect_cb, dev, NULL, &gerr,
1668                                 BT_IO_OPT_SOURCE_BDADDR, &adapter_addr,
1669                                 BT_IO_OPT_DEST_BDADDR, &dev->bdaddr,
1670                                 BT_IO_OPT_SEC_LEVEL, BT_IO_SEC_MEDIUM,
1671                                 BT_IO_OPT_CHANNEL, channel,
1672                                 BT_IO_OPT_INVALID);
1673         if (!io) {
1674                 error("handsfree: unable to connect: %s", gerr->message);
1675                 g_error_free(gerr);
1676                 goto fail;
1677         }
1678
1679         g_io_channel_unref(io);
1680         return;
1681
1682 fail:
1683         device_destroy(dev);
1684 }
1685
1686 static int sdp_search_hfp(struct hf_device *dev)
1687 {
1688         uuid_t uuid;
1689
1690         sdp_uuid16_create(&uuid, HANDSFREE_SVCLASS_ID);
1691
1692         return bt_search_service(&adapter_addr, &dev->bdaddr, &uuid,
1693                                         sdp_hfp_search_cb, dev, NULL, 0);
1694 }
1695
1696 static void handle_connect(const void *buf, uint16_t len)
1697 {
1698         const struct hal_cmd_handsfree_connect *cmd = buf;
1699         struct hf_device *dev;
1700         char addr[18];
1701         uint8_t status;
1702         bdaddr_t bdaddr;
1703         int ret;
1704
1705         DBG("");
1706
1707         android2bdaddr(&cmd->bdaddr, &bdaddr);
1708
1709         dev = get_device(&bdaddr);
1710         if (!dev) {
1711                 status = HAL_STATUS_FAILED;
1712                 goto failed;
1713         }
1714
1715         if (dev->state != HAL_EV_HANDSFREE_CONN_STATE_DISCONNECTED) {
1716                 status = HAL_STATUS_FAILED;
1717                 goto failed;
1718         }
1719
1720         ba2str(&bdaddr, addr);
1721         DBG("connecting to %s", addr);
1722
1723         /* prefer HFP over HSP */
1724         ret = hfp_server ? sdp_search_hfp(dev) : sdp_search_hsp(dev);
1725         if (ret < 0) {
1726                 error("handsfree: SDP search failed");
1727                 device_destroy(dev);
1728                 status = HAL_STATUS_FAILED;
1729                 goto failed;
1730         }
1731
1732         set_state(dev, HAL_EV_HANDSFREE_CONN_STATE_CONNECTING);
1733
1734         status = HAL_STATUS_SUCCESS;
1735
1736 failed:
1737         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1738                                         HAL_OP_HANDSFREE_CONNECT, status);
1739 }
1740
1741 static void handle_disconnect(const void *buf, uint16_t len)
1742 {
1743         const struct hal_cmd_handsfree_disconnect *cmd = buf;
1744         struct hf_device *dev;
1745         bdaddr_t bdaddr;
1746         uint8_t status;
1747
1748         DBG("");
1749
1750         android2bdaddr(cmd->bdaddr, &bdaddr);
1751
1752         dev = find_device(&bdaddr);
1753         if (!dev) {
1754                 status = HAL_STATUS_FAILED;
1755                 goto failed;
1756         }
1757
1758         if (dev->state == HAL_EV_HANDSFREE_CONN_STATE_DISCONNECTED) {
1759                 status = HAL_STATUS_FAILED;
1760                 goto failed;
1761         }
1762
1763         if (dev->state == HAL_EV_HANDSFREE_CONN_STATE_DISCONNECTING) {
1764                 status = HAL_STATUS_SUCCESS;
1765                 goto failed;
1766         }
1767
1768         if (dev->state == HAL_EV_HANDSFREE_CONN_STATE_CONNECTING) {
1769                 device_destroy(dev);
1770         } else {
1771                 set_state(dev, HAL_EV_HANDSFREE_CONN_STATE_DISCONNECTING);
1772                 hfp_gw_disconnect(dev->gw);
1773         }
1774
1775         status = HAL_STATUS_SUCCESS;
1776
1777 failed:
1778         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1779                                         HAL_OP_HANDSFREE_DISCONNECT, status);
1780 }
1781
1782 static bool disconnect_sco(struct hf_device *dev)
1783 {
1784         if (dev->audio_state == HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTED ||
1785                 dev->audio_state == HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTING)
1786                 return false;
1787
1788         bt_sco_disconnect(sco);
1789         set_audio_state(dev, HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTING);
1790
1791         return true;
1792 }
1793
1794 static bool connect_audio(struct hf_device *dev)
1795 {
1796         if (dev->audio_state != HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTED)
1797                 return false;
1798
1799         /* we haven't negotiated codec, start selection */
1800         if (codec_negotiation_supported(dev) && !dev->negotiated_codec) {
1801                 select_codec(dev, 0);
1802                 return true;
1803         }
1804
1805         return connect_sco(dev);
1806 }
1807
1808 static void handle_connect_audio(const void *buf, uint16_t len)
1809 {
1810         const struct hal_cmd_handsfree_connect_audio *cmd = buf;
1811         struct hf_device *dev;
1812         bdaddr_t bdaddr;
1813         uint8_t status;
1814
1815         DBG("");
1816
1817         android2bdaddr(cmd->bdaddr, &bdaddr);
1818
1819         dev = find_device(&bdaddr);
1820         if (!dev) {
1821                 status = HAL_STATUS_FAILED;
1822                 goto done;
1823         }
1824
1825         if (dev->audio_state != HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTED) {
1826                 status = HAL_STATUS_FAILED;
1827                 goto done;
1828         }
1829
1830         status = connect_audio(dev) ? HAL_STATUS_SUCCESS : HAL_STATUS_FAILED;
1831
1832 done:
1833         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1834                                 HAL_OP_HANDSFREE_CONNECT_AUDIO, status);
1835 }
1836
1837 static void handle_disconnect_audio(const void *buf, uint16_t len)
1838 {
1839         const struct hal_cmd_handsfree_disconnect_audio *cmd = buf;
1840         struct hf_device *dev;
1841         bdaddr_t bdaddr;
1842         uint8_t status;
1843
1844         DBG("");
1845
1846         android2bdaddr(cmd->bdaddr, &bdaddr);
1847
1848         dev = find_device(&bdaddr);
1849         if (!dev) {
1850                 status = HAL_STATUS_FAILED;
1851                 goto done;
1852         }
1853
1854         status = disconnect_sco(dev) ? HAL_STATUS_SUCCESS : HAL_STATUS_FAILED;
1855
1856 done:
1857         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1858                                 HAL_OP_HANDSFREE_DISCONNECT_AUDIO, status);
1859 }
1860
1861 static void handle_start_vr(const void *buf, uint16_t len)
1862 {
1863         const struct hal_cmd_handsfree_start_vr *cmd = buf;
1864         struct hf_device *dev;
1865         bdaddr_t bdaddr;
1866         uint8_t status;
1867
1868         DBG("");
1869
1870         android2bdaddr(cmd->bdaddr, &bdaddr);
1871
1872         dev = find_device(&bdaddr);
1873         if (!dev) {
1874                 status = HAL_STATUS_FAILED;
1875                 goto done;
1876         }
1877
1878         if (dev->features & HFP_HF_FEAT_VR) {
1879                 hfp_gw_send_info(dev->gw, "+BVRA: 1");
1880                 status = HAL_STATUS_SUCCESS;
1881         } else {
1882                 status = HAL_STATUS_FAILED;
1883         }
1884
1885 done:
1886         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1887                                         HAL_OP_HANDSFREE_START_VR, status);
1888 }
1889
1890 static void handle_stop_vr(const void *buf, uint16_t len)
1891 {
1892         const struct hal_cmd_handsfree_stop_vr *cmd = buf;
1893         struct hf_device *dev;
1894         bdaddr_t bdaddr;
1895         uint8_t status;
1896
1897         DBG("");
1898
1899         android2bdaddr(cmd->bdaddr, &bdaddr);
1900
1901         dev = find_device(&bdaddr);
1902         if (!dev) {
1903                 status = HAL_STATUS_FAILED;
1904                 goto done;
1905         }
1906
1907         if (dev->features & HFP_HF_FEAT_VR) {
1908                 hfp_gw_send_info(dev->gw, "+BVRA: 0");
1909                 status = HAL_STATUS_SUCCESS;
1910         } else {
1911                 status = HAL_STATUS_FAILED;
1912         }
1913
1914 done:
1915         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1916                                 HAL_OP_HANDSFREE_STOP_VR, status);
1917 }
1918
1919 static void handle_volume_control(const void *buf, uint16_t len)
1920 {
1921         const struct hal_cmd_handsfree_volume_control *cmd = buf;
1922         struct hf_device *dev;
1923         uint8_t status, volume;
1924         bdaddr_t bdaddr;
1925
1926         DBG("type=%u volume=%u", cmd->type, cmd->volume);
1927
1928         android2bdaddr(cmd->bdaddr, &bdaddr);
1929
1930         dev = find_device(&bdaddr);
1931         if (!dev) {
1932                 status = HAL_STATUS_FAILED;
1933                 goto done;
1934         }
1935
1936         volume = cmd->volume > 15 ? 15 : cmd->volume;
1937
1938         switch (cmd->type) {
1939         case HAL_HANDSFREE_VOLUME_TYPE_MIC:
1940                 hfp_gw_send_info(dev->gw, "+VGM: %u", volume);
1941
1942                 status = HAL_STATUS_SUCCESS;
1943                 break;
1944         case HAL_HANDSFREE_VOLUME_TYPE_SPEAKER:
1945                 hfp_gw_send_info(dev->gw, "+VGS: %u", volume);
1946
1947                 status = HAL_STATUS_SUCCESS;
1948                 break;
1949         default:
1950                 status = HAL_STATUS_FAILED;
1951                 break;
1952         }
1953
1954 done:
1955         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
1956                                 HAL_OP_HANDSFREE_VOLUME_CONTROL, status);
1957 }
1958
1959 static void update_indicator(struct hf_device *dev, int ind, uint8_t val)
1960 {
1961         DBG("ind=%u new=%u old=%u", ind, val, dev->inds[ind].val);
1962
1963         if (dev->inds[ind].val == val)
1964                 return;
1965
1966         dev->inds[ind].val = val;
1967
1968         if (!dev->indicators_enabled)
1969                 return;
1970
1971         if (!dev->inds[ind].active)
1972                 return;
1973
1974         /* indicator numbers in CIEV start from 1 */
1975         hfp_gw_send_info(dev->gw, "+CIEV: %u,%u", ind + 1, val);
1976 }
1977
1978 static void device_status_notif(void *data, void *user_data)
1979 {
1980         struct hf_device *dev = data;
1981         struct hal_cmd_handsfree_device_status_notif *cmd = user_data;
1982
1983         update_indicator(dev, IND_SERVICE, cmd->state);
1984         update_indicator(dev, IND_ROAM, cmd->type);
1985         update_indicator(dev, IND_SIGNAL, cmd->signal);
1986         update_indicator(dev, IND_BATTCHG, cmd->battery);
1987 }
1988
1989 static void handle_device_status_notif(const void *buf, uint16_t len)
1990 {
1991         const struct hal_cmd_handsfree_device_status_notif *cmd = buf;
1992         uint8_t status;
1993
1994         DBG("");
1995
1996         if (queue_isempty(devices)) {
1997                 status = HAL_STATUS_FAILED;
1998                 goto done;
1999         }
2000
2001         /* Cast cmd to void as queue api needs that */
2002         queue_foreach(devices, device_status_notif, (void *) cmd);
2003
2004         status = HAL_STATUS_SUCCESS;
2005
2006 done:
2007         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
2008                                 HAL_OP_HANDSFREE_DEVICE_STATUS_NOTIF, status);
2009 }
2010
2011 static void handle_cops(const void *buf, uint16_t len)
2012 {
2013         const struct hal_cmd_handsfree_cops_response *cmd = buf;
2014         struct hf_device *dev;
2015         bdaddr_t bdaddr;
2016         uint8_t status;
2017
2018         if (len != sizeof(*cmd) + cmd->len ||
2019                         (cmd->len != 0 && cmd->buf[cmd->len - 1] != '\0')) {
2020                 error("Invalid cops response command, terminating");
2021                 raise(SIGTERM);
2022                 return;
2023         }
2024
2025         DBG("");
2026
2027         android2bdaddr(cmd->bdaddr, &bdaddr);
2028
2029         dev = find_device(&bdaddr);
2030         if (!dev) {
2031                 status = HAL_STATUS_FAILED;
2032                 goto done;
2033         }
2034
2035         hfp_gw_send_info(dev->gw, "+COPS: 0,0,\"%.16s\"",
2036                                         cmd->len ? (char *) cmd->buf : "");
2037
2038         hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
2039
2040         status = HAL_STATUS_SUCCESS;
2041
2042 done:
2043         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
2044                                 HAL_OP_HANDSFREE_COPS_RESPONSE, status);
2045 }
2046
2047 static unsigned int get_callsetup(uint8_t state)
2048 {
2049         switch (state) {
2050         case HAL_HANDSFREE_CALL_STATE_INCOMING:
2051                 return 1;
2052         case HAL_HANDSFREE_CALL_STATE_DIALING:
2053                 return 2;
2054         case HAL_HANDSFREE_CALL_STATE_ALERTING:
2055                 return 3;
2056         default:
2057                 return 0;
2058         }
2059 }
2060
2061 static void handle_cind(const void *buf, uint16_t len)
2062 {
2063         const struct hal_cmd_handsfree_cind_response *cmd = buf;
2064         struct hf_device *dev;
2065         bdaddr_t bdaddr;
2066         uint8_t status;
2067
2068         DBG("");
2069
2070         android2bdaddr(cmd->bdaddr, &bdaddr);
2071
2072         dev = find_device(&bdaddr);
2073         if (!dev) {
2074                 status = HAL_STATUS_FAILED;
2075                 goto done;
2076         }
2077
2078         /* HAL doesn't provide indicators values so need to convert here */
2079         dev->inds[IND_SERVICE].val = cmd->svc;
2080         dev->inds[IND_CALL].val = !!(cmd->num_active + cmd->num_held);
2081         dev->inds[IND_CALLSETUP].val = get_callsetup(cmd->state);
2082         dev->inds[IND_CALLHELD].val = cmd->num_held ?
2083                                                 (cmd->num_active ? 1 : 2) : 0;
2084         dev->inds[IND_SIGNAL].val = cmd->signal;
2085         dev->inds[IND_ROAM].val = cmd->roam;
2086         dev->inds[IND_BATTCHG].val = cmd->batt_chg;
2087
2088         /* Order must match indicators_defaults table */
2089         hfp_gw_send_info(dev->gw, "+CIND: %u,%u,%u,%u,%u,%u,%u",
2090                                                 dev->inds[IND_SERVICE].val,
2091                                                 dev->inds[IND_CALL].val,
2092                                                 dev->inds[IND_CALLSETUP].val,
2093                                                 dev->inds[IND_CALLHELD].val,
2094                                                 dev->inds[IND_SIGNAL].val,
2095                                                 dev->inds[IND_ROAM].val,
2096                                                 dev->inds[IND_BATTCHG].val);
2097
2098         hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
2099
2100         status = HAL_STATUS_SUCCESS;
2101
2102 done:
2103         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
2104                                 HAL_OP_HANDSFREE_CIND_RESPONSE, status);
2105 }
2106
2107 static void handle_formatted_at_resp(const void *buf, uint16_t len)
2108 {
2109         const struct hal_cmd_handsfree_formatted_at_response *cmd = buf;
2110         struct hf_device *dev;
2111         bdaddr_t bdaddr;
2112         uint8_t status;
2113
2114         DBG("");
2115
2116         if (len != sizeof(*cmd) + cmd->len ||
2117                         (cmd->len != 0 && cmd->buf[cmd->len - 1] != '\0')) {
2118                 error("Invalid formatted AT response command, terminating");
2119                 raise(SIGTERM);
2120                 return;
2121         }
2122
2123         android2bdaddr(cmd->bdaddr, &bdaddr);
2124
2125         dev = find_device(&bdaddr);
2126         if (!dev) {
2127                 status = HAL_STATUS_FAILED;
2128                 goto done;
2129         }
2130
2131         hfp_gw_send_info(dev->gw, "%s", cmd->len ? (char *) cmd->buf : "");
2132
2133         status = HAL_STATUS_SUCCESS;
2134
2135 done:
2136         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
2137                         HAL_OP_HANDSFREE_FORMATTED_AT_RESPONSE, status);
2138 }
2139
2140 static void handle_at_resp(const void *buf, uint16_t len)
2141 {
2142         const struct hal_cmd_handsfree_at_response *cmd = buf;
2143         struct hf_device *dev;
2144         bdaddr_t bdaddr;
2145         uint8_t status;
2146
2147         DBG("");
2148
2149         android2bdaddr(cmd->bdaddr, &bdaddr);
2150
2151         dev = find_device(&bdaddr);
2152         if (!dev) {
2153                 status = HAL_STATUS_FAILED;
2154                 goto done;
2155         }
2156
2157         if (cmd->response == HAL_HANDSFREE_AT_RESPONSE_OK)
2158                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
2159         else if (dev->cmee_enabled)
2160                 hfp_gw_send_error(dev->gw, cmd->error);
2161         else
2162                 hfp_gw_send_result(dev->gw, HFP_RESULT_ERROR);
2163
2164         status = HAL_STATUS_SUCCESS;
2165
2166 done:
2167         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
2168                                         HAL_OP_HANDSFREE_AT_RESPONSE, status);
2169 }
2170
2171 static void handle_clcc_resp(const void *buf, uint16_t len)
2172 {
2173         const struct hal_cmd_handsfree_clcc_response *cmd = buf;
2174         struct hf_device *dev;
2175         uint8_t status;
2176         bdaddr_t bdaddr;
2177         char *number;
2178
2179         if (len != sizeof(*cmd) + cmd->number_len || (cmd->number_len != 0 &&
2180                                 cmd->number[cmd->number_len - 1] != '\0')) {
2181                 error("Invalid CLCC response command, terminating");
2182                 raise(SIGTERM);
2183                 return;
2184         }
2185
2186         DBG("");
2187
2188         android2bdaddr(cmd->bdaddr, &bdaddr);
2189
2190         dev = find_device(&bdaddr);
2191         if (!dev) {
2192                 status = HAL_STATUS_FAILED;
2193                 goto done;
2194         }
2195
2196         if (!cmd->index) {
2197                 hfp_gw_send_result(dev->gw, HFP_RESULT_OK);
2198
2199                 status = HAL_STATUS_SUCCESS;
2200                 goto done;
2201         }
2202
2203         number = cmd->number_len ? (char *) cmd->number : "";
2204
2205         switch (cmd->state) {
2206         case HAL_HANDSFREE_CALL_STATE_INCOMING:
2207         case HAL_HANDSFREE_CALL_STATE_WAITING:
2208         case HAL_HANDSFREE_CALL_STATE_ACTIVE:
2209         case HAL_HANDSFREE_CALL_STATE_HELD:
2210         case HAL_HANDSFREE_CALL_STATE_DIALING:
2211         case HAL_HANDSFREE_CALL_STATE_ALERTING:
2212                 if (cmd->type == HAL_HANDSFREE_CALL_ADDRTYPE_INTERNATIONAL &&
2213                                                         number[0] != '+')
2214                         hfp_gw_send_info(dev->gw,
2215                                         "+CLCC: %u,%u,%u,%u,%u,\"+%s\",%u",
2216                                         cmd->index, cmd->dir, cmd->state,
2217                                         cmd->mode, cmd->mpty, number,
2218                                         cmd->type);
2219                 else
2220                         hfp_gw_send_info(dev->gw,
2221                                         "+CLCC: %u,%u,%u,%u,%u,\"%s\",%u",
2222                                         cmd->index, cmd->dir, cmd->state,
2223                                         cmd->mode, cmd->mpty, number,
2224                                         cmd->type);
2225
2226                 status = HAL_STATUS_SUCCESS;
2227                 break;
2228         case HAL_HANDSFREE_CALL_STATE_IDLE:
2229         default:
2230                 status = HAL_STATUS_FAILED;
2231                 break;
2232         }
2233
2234 done:
2235         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
2236                                 HAL_OP_HANDSFREE_CLCC_RESPONSE, status);
2237 }
2238
2239 static gboolean ring_cb(gpointer user_data)
2240 {
2241         struct hf_device *dev = user_data;
2242
2243         hfp_gw_send_info(dev->gw, "RING");
2244
2245         if (dev->clip_enabled && dev->clip)
2246                 hfp_gw_send_info(dev->gw, "%s", dev->clip);
2247
2248         return TRUE;
2249 }
2250
2251 static void phone_state_dialing(struct hf_device *dev, int num_active,
2252                                                                 int num_held)
2253 {
2254         if (dev->call_hanging_up) {
2255                 g_source_remove(dev->call_hanging_up);
2256                 dev->call_hanging_up = 0;
2257         }
2258
2259         update_indicator(dev, IND_CALLSETUP, 2);
2260
2261         if (num_active == 0 && num_held > 0)
2262                 update_indicator(dev, IND_CALLHELD, 2);
2263
2264         if (dev->num_active == 0 && dev->num_held == 0)
2265                 connect_audio(dev);
2266 }
2267
2268 static void phone_state_alerting(struct hf_device *dev, int num_active,
2269                                                                 int num_held)
2270 {
2271         if (dev->call_hanging_up) {
2272                 g_source_remove(dev->call_hanging_up);
2273                 dev->call_hanging_up = 0;
2274         }
2275
2276         update_indicator(dev, IND_CALLSETUP, 3);
2277 }
2278
2279 static void phone_state_waiting(struct hf_device *dev, int num_active,
2280                                         int num_held, uint8_t type,
2281                                         const uint8_t *number, int number_len)
2282 {
2283         char *num;
2284
2285         if (!dev->ccwa_enabled)
2286                 return;
2287
2288         num = number_len ? (char *) number : "";
2289
2290         if (type == HAL_HANDSFREE_CALL_ADDRTYPE_INTERNATIONAL && num[0] != '+')
2291                 hfp_gw_send_info(dev->gw, "+CCWA: \"+%s\",%u", num, type);
2292         else
2293                 hfp_gw_send_info(dev->gw, "+CCWA: \"%s\",%u", num, type);
2294
2295         update_indicator(dev, IND_CALLSETUP, 1);
2296 }
2297
2298 static void phone_state_incoming(struct hf_device *dev, int num_active,
2299                                         int num_held, uint8_t type,
2300                                         const uint8_t *number, int number_len)
2301 {
2302         char *num;
2303
2304         if (dev->setup_state == HAL_HANDSFREE_CALL_STATE_INCOMING) {
2305                 if (dev->num_active != num_active ||
2306                                                 dev->num_held != num_held) {
2307                         if (dev->num_active == num_held &&
2308                                                 dev->num_held == num_active)
2309                                 return;
2310                         /*
2311                          * calls changed while waiting call ie. due to
2312                          * termination of active call
2313                          */
2314                         update_indicator(dev, IND_CALLHELD,
2315                                         num_held ? (num_active ? 1 : 2) : 0);
2316                         update_indicator(dev, IND_CALL,
2317                                                 !!(num_active + num_held));
2318                 }
2319
2320                 return;
2321         }
2322
2323         if (dev->call_hanging_up)
2324                 return;
2325
2326         if (num_active > 0 || num_held > 0) {
2327                 phone_state_waiting(dev, num_active, num_held, type, number,
2328                                                                 number_len);
2329                 return;
2330         }
2331
2332         update_indicator(dev, IND_CALLSETUP, 1);
2333
2334         num = number_len ? (char *) number : "";
2335
2336         if (type == HAL_HANDSFREE_CALL_ADDRTYPE_INTERNATIONAL && num[0] != '+')
2337                 dev->clip = g_strdup_printf("+CLIP: \"+%s\",%u", num, type);
2338         else
2339                 dev->clip = g_strdup_printf("+CLIP: \"%s\",%u", num, type);
2340
2341         /* send first RING */
2342         ring_cb(dev);
2343
2344         dev->ring = g_timeout_add_seconds_full(G_PRIORITY_DEFAULT,
2345                                                         RING_TIMEOUT, ring_cb,
2346                                                         dev, NULL);
2347         if (!dev->ring) {
2348                 g_free(dev->clip);
2349                 dev->clip = NULL;
2350         }
2351 }
2352
2353 static gboolean hang_up_cb(gpointer user_data)
2354 {
2355         struct hf_device *dev = user_data;
2356
2357         DBG("");
2358
2359         dev->call_hanging_up = 0;
2360
2361         return FALSE;
2362 }
2363
2364 static void phone_state_idle(struct hf_device *dev, int num_active,
2365                                                                 int num_held)
2366 {
2367         if (dev->ring) {
2368                 g_source_remove(dev->ring);
2369                 dev->ring = 0;
2370
2371                 if (dev->clip) {
2372                         g_free(dev->clip);
2373                         dev->clip = NULL;
2374                 }
2375         }
2376
2377         switch (dev->setup_state) {
2378         case HAL_HANDSFREE_CALL_STATE_INCOMING:
2379                 if (num_active > dev->num_active) {
2380                         update_indicator(dev, IND_CALL, 1);
2381
2382                         if (dev->num_active == 0 && dev->num_held == 0)
2383                                 connect_audio(dev);
2384                 }
2385
2386                 if (num_held >= dev->num_held && num_held != 0)
2387                         update_indicator(dev, IND_CALLHELD, 1);
2388
2389                 update_indicator(dev, IND_CALLSETUP, 0);
2390
2391                 if (num_active == 0 && num_held == 0 &&
2392                                 num_active == dev->num_active &&
2393                                 num_held == dev->num_held)
2394                         dev->call_hanging_up = g_timeout_add(800, hang_up_cb,
2395                                                                         dev);
2396                 break;
2397         case HAL_HANDSFREE_CALL_STATE_DIALING:
2398         case HAL_HANDSFREE_CALL_STATE_ALERTING:
2399                 if (num_active > dev->num_active)
2400                         update_indicator(dev, IND_CALL, 1);
2401
2402                 update_indicator(dev, IND_CALLHELD,
2403                                         num_held ? (num_active ? 1 : 2) : 0);
2404
2405                 update_indicator(dev, IND_CALLSETUP, 0);
2406
2407                 /* disconnect SCO if we hang up while dialing or alerting */
2408                 if (num_active == 0 && num_held == 0)
2409                         disconnect_sco(dev);
2410                 break;
2411         case HAL_HANDSFREE_CALL_STATE_IDLE:
2412                 if (dev->call_hanging_up) {
2413                         g_source_remove(dev->call_hanging_up);
2414                         dev->call_hanging_up = 0;
2415                         return;
2416                 }
2417
2418                 /* check if calls swapped */
2419                 if (num_held != 0 && num_active != 0 &&
2420                                 dev->num_active == num_held &&
2421                                 dev->num_held == num_active) {
2422                         /* TODO better way for forcing indicator */
2423                         dev->inds[IND_CALLHELD].val = 0;
2424                 } else if ((num_active > 0 || num_held > 0) &&
2425                                                 dev->num_active == 0 &&
2426                                                 dev->num_held == 0) {
2427                         /*
2428                          * If number of active or held calls change but there
2429                          * was no call setup change this means that there were
2430                          * calls present when headset was connected.
2431                          */
2432                         connect_audio(dev);
2433                 } else if (num_active == 0 && num_held == 0) {
2434                         disconnect_sco(dev);
2435                 }
2436
2437                 update_indicator(dev, IND_CALLHELD,
2438                                         num_held ? (num_active ? 1 : 2) : 0);
2439                 update_indicator(dev, IND_CALL, !!(num_active + num_held));
2440                 update_indicator(dev, IND_CALLSETUP, 0);
2441
2442                 /* If call was terminated due to carrier lost send NO CARRIER */
2443                 if (num_active == 0 && num_held == 0 &&
2444                                 dev->inds[IND_SERVICE].val == 0 &&
2445                                 (dev->num_active > 0 || dev->num_held > 0))
2446                         hfp_gw_send_info(dev->gw, "NO CARRIER");
2447
2448                 break;
2449         default:
2450                 DBG("unhandled state %u", dev->setup_state);
2451                 break;
2452         }
2453 }
2454
2455 static void phone_state_change(void *data, void *user_data)
2456 {
2457         struct hf_device *dev = data;
2458         struct hal_cmd_handsfree_phone_state_change *cmd = user_data;
2459
2460         switch (cmd->state) {
2461         case HAL_HANDSFREE_CALL_STATE_DIALING:
2462                 phone_state_dialing(dev, cmd->num_active, cmd->num_held);
2463                 break;
2464         case HAL_HANDSFREE_CALL_STATE_ALERTING:
2465                 phone_state_alerting(dev, cmd->num_active, cmd->num_held);
2466                 break;
2467         case HAL_HANDSFREE_CALL_STATE_INCOMING:
2468                 phone_state_incoming(dev, cmd->num_active, cmd->num_held,
2469                                                 cmd->type, cmd->number,
2470                                                 cmd->number_len);
2471                 break;
2472         case HAL_HANDSFREE_CALL_STATE_IDLE:
2473                 phone_state_idle(dev, cmd->num_active, cmd->num_held);
2474                 break;
2475         default:
2476                 DBG("unhandled new state %u (current state %u)", cmd->state,
2477                                                         dev->setup_state);
2478
2479                 return;
2480         }
2481
2482         dev->num_active = cmd->num_active;
2483         dev->num_held = cmd->num_held;
2484         dev->setup_state = cmd->state;
2485
2486 }
2487
2488 static void handle_phone_state_change(const void *buf, uint16_t len)
2489 {
2490         const struct hal_cmd_handsfree_phone_state_change *cmd = buf;
2491         uint8_t status;
2492
2493         if (len != sizeof(*cmd) + cmd->number_len || (cmd->number_len != 0 &&
2494                                 cmd->number[cmd->number_len - 1] != '\0')) {
2495                 error("Invalid phone state change command, terminating");
2496                 raise(SIGTERM);
2497                 return;
2498         }
2499
2500         DBG("active=%u hold=%u state=%u", cmd->num_active, cmd->num_held,
2501                                                                 cmd->state);
2502
2503         if (queue_isempty(devices)) {
2504                 status = HAL_STATUS_FAILED;
2505                 goto failed;
2506         }
2507
2508         /* Cast cmd to void as queue api needs that */
2509         queue_foreach(devices, phone_state_change, (void *) cmd);
2510
2511         status = HAL_STATUS_SUCCESS;
2512
2513 failed:
2514         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
2515                                 HAL_OP_HANDSFREE_PHONE_STATE_CHANGE, status);
2516 }
2517
2518 static void handle_configure_wbs(const void *buf, uint16_t len)
2519 {
2520         const struct hal_cmd_handsfree_configure_wbs *cmd = buf;
2521         struct hf_device *dev;
2522         bdaddr_t bdaddr;
2523         uint8_t status;
2524
2525         if (!(hfp_ag_features & HFP_AG_FEAT_CODEC)) {
2526                 status = HAL_STATUS_FAILED;
2527                 goto done;
2528         }
2529
2530         android2bdaddr(cmd->bdaddr, &bdaddr);
2531
2532         dev = find_device(&bdaddr);
2533         if (!dev) {
2534                 status = HAL_STATUS_FAILED;
2535                 goto done;
2536         }
2537
2538         if (dev->audio_state != HAL_EV_HANDSFREE_AUDIO_STATE_DISCONNECTED) {
2539                 status = HAL_STATUS_FAILED;
2540                 goto done;
2541         }
2542
2543         switch (cmd->config) {
2544         case HAL_HANDSFREE_WBS_NO:
2545                 dev->codecs[MSBC_OFFSET].local_supported = false;
2546                 break;
2547         case HAL_HANDSFREE_WBS_YES:
2548                 dev->codecs[MSBC_OFFSET].local_supported = true;
2549                 break;
2550         case HAL_HANDSFREE_WBS_NONE:
2551                 /* TODO */
2552         default:
2553                 status = HAL_STATUS_FAILED;
2554                 goto done;
2555         }
2556
2557         /*
2558          * cleanup negotiated codec if WBS support was changed, it will be
2559          * renegotiated on next audio connection based on currently supported
2560          * codecs
2561          */
2562         dev->negotiated_codec = 0;
2563         status = HAL_STATUS_SUCCESS;
2564
2565 done:
2566         ipc_send_rsp(hal_ipc, HAL_SERVICE_ID_HANDSFREE,
2567                                         HAL_OP_HANDSFREE_CONFIGURE_WBS, status);
2568 }
2569
2570 static const struct ipc_handler cmd_handlers[] = {
2571         /* HAL_OP_HANDSFREE_CONNECT */
2572         { handle_connect, false,
2573                 sizeof(struct hal_cmd_handsfree_connect) },
2574         /* HAL_OP_HANDSFREE_DISCONNECT */
2575         { handle_disconnect, false,
2576                 sizeof(struct hal_cmd_handsfree_disconnect) },
2577         /* HAL_OP_HANDSFREE_CONNECT_AUDIO */
2578         { handle_connect_audio, false,
2579                 sizeof(struct hal_cmd_handsfree_connect_audio) },
2580         /* HAL_OP_HANDSFREE_DISCONNECT_AUDIO */
2581         { handle_disconnect_audio, false,
2582                 sizeof(struct hal_cmd_handsfree_disconnect_audio) },
2583         /* define HAL_OP_HANDSFREE_START_VR */
2584         { handle_start_vr, false, sizeof(struct hal_cmd_handsfree_start_vr) },
2585         /* define HAL_OP_HANDSFREE_STOP_VR */
2586         { handle_stop_vr, false, sizeof(struct hal_cmd_handsfree_stop_vr) },
2587         /* HAL_OP_HANDSFREE_VOLUME_CONTROL */
2588         { handle_volume_control, false,
2589                 sizeof(struct hal_cmd_handsfree_volume_control) },
2590         /* HAL_OP_HANDSFREE_DEVICE_STATUS_NOTIF */
2591         { handle_device_status_notif, false,
2592                 sizeof(struct hal_cmd_handsfree_device_status_notif) },
2593         /* HAL_OP_HANDSFREE_COPS_RESPONSE */
2594         { handle_cops, true,
2595                 sizeof(struct hal_cmd_handsfree_cops_response) },
2596         /* HAL_OP_HANDSFREE_CIND_RESPONSE */
2597         { handle_cind, false,
2598                 sizeof(struct hal_cmd_handsfree_cind_response) },
2599         /* HAL_OP_HANDSFREE_FORMATTED_AT_RESPONSE */
2600         { handle_formatted_at_resp, true,
2601                 sizeof(struct hal_cmd_handsfree_formatted_at_response) },
2602         /* HAL_OP_HANDSFREE_AT_RESPONSE */
2603         { handle_at_resp, false,
2604                 sizeof(struct hal_cmd_handsfree_at_response) },
2605         /* HAL_OP_HANDSFREE_CLCC_RESPONSE */
2606         { handle_clcc_resp, true,
2607                 sizeof(struct hal_cmd_handsfree_clcc_response) },
2608         /* HAL_OP_HANDSFREE_PHONE_STATE_CHANGE */
2609         { handle_phone_state_change, true,
2610                 sizeof(struct hal_cmd_handsfree_phone_state_change) },
2611         /* HAL_OP_HANDSFREE_CONFIGURE_WBS */
2612         { handle_configure_wbs, false,
2613                 sizeof(struct hal_cmd_handsfree_configure_wbs) },
2614 };
2615
2616 static sdp_record_t *headset_ag_record(void)
2617 {
2618         sdp_list_t *svclass_id, *pfseq, *apseq, *root;
2619         uuid_t root_uuid, svclass_uuid, ga_svclass_uuid;
2620         uuid_t l2cap_uuid, rfcomm_uuid;
2621         sdp_profile_desc_t profile;
2622         sdp_list_t *aproto, *proto[2];
2623         sdp_record_t *record;
2624         sdp_data_t *channel;
2625         uint8_t netid = 0x01;
2626         sdp_data_t *network;
2627         uint8_t ch = HSP_AG_CHANNEL;
2628
2629         record = sdp_record_alloc();
2630         if (!record)
2631                 return NULL;
2632
2633         network = sdp_data_alloc(SDP_UINT8, &netid);
2634         if (!network) {
2635                 sdp_record_free(record);
2636                 return NULL;
2637         }
2638
2639         sdp_uuid16_create(&root_uuid, PUBLIC_BROWSE_GROUP);
2640         root = sdp_list_append(NULL, &root_uuid);
2641         sdp_set_browse_groups(record, root);
2642
2643         sdp_uuid16_create(&svclass_uuid, HEADSET_AGW_SVCLASS_ID);
2644         svclass_id = sdp_list_append(NULL, &svclass_uuid);
2645         sdp_uuid16_create(&ga_svclass_uuid, GENERIC_AUDIO_SVCLASS_ID);
2646         svclass_id = sdp_list_append(svclass_id, &ga_svclass_uuid);
2647         sdp_set_service_classes(record, svclass_id);
2648
2649         sdp_uuid16_create(&profile.uuid, HEADSET_PROFILE_ID);
2650         profile.version = 0x0102;
2651         pfseq = sdp_list_append(NULL, &profile);
2652         sdp_set_profile_descs(record, pfseq);
2653
2654         sdp_uuid16_create(&l2cap_uuid, L2CAP_UUID);
2655         proto[0] = sdp_list_append(NULL, &l2cap_uuid);
2656         apseq = sdp_list_append(NULL, proto[0]);
2657
2658         sdp_uuid16_create(&rfcomm_uuid, RFCOMM_UUID);
2659         proto[1] = sdp_list_append(NULL, &rfcomm_uuid);
2660         channel = sdp_data_alloc(SDP_UINT8, &ch);
2661         proto[1] = sdp_list_append(proto[1], channel);
2662         apseq = sdp_list_append(apseq, proto[1]);
2663
2664         aproto = sdp_list_append(NULL, apseq);
2665         sdp_set_access_protos(record, aproto);
2666
2667         sdp_set_info_attr(record, "Voice Gateway", NULL, NULL);
2668
2669         sdp_attr_add(record, SDP_ATTR_EXTERNAL_NETWORK, network);
2670
2671         sdp_data_free(channel);
2672         sdp_list_free(proto[0], NULL);
2673         sdp_list_free(proto[1], NULL);
2674         sdp_list_free(apseq, NULL);
2675         sdp_list_free(pfseq, NULL);
2676         sdp_list_free(aproto, NULL);
2677         sdp_list_free(root, NULL);
2678         sdp_list_free(svclass_id, NULL);
2679
2680         return record;
2681 }
2682
2683 static bool confirm_sco_cb(const bdaddr_t *addr, uint16_t *voice_settings)
2684 {
2685         char address[18];
2686         struct hf_device *dev;
2687
2688         ba2str(addr, address);
2689
2690         DBG("incoming SCO connection from %s", address);
2691
2692         dev = find_device(addr);
2693         if (!dev || dev->state != HAL_EV_HANDSFREE_CONN_STATE_SLC_CONNECTED) {
2694                 error("handsfree: audio connection from %s rejected", address);
2695                 return false;
2696         }
2697
2698         /* If HF initiate SCO there must be no WBS used */
2699         *voice_settings = 0;
2700
2701         set_audio_state(dev, HAL_EV_HANDSFREE_AUDIO_STATE_CONNECTING);
2702         return true;
2703 }
2704
2705 static bool enable_hsp_ag(void)
2706 {
2707         sdp_record_t *rec;
2708         GError *err = NULL;
2709
2710         DBG("");
2711
2712         hsp_server =  bt_io_listen(NULL, confirm_cb, GINT_TO_POINTER(true),
2713                                         NULL, &err,
2714                                         BT_IO_OPT_SOURCE_BDADDR, &adapter_addr,
2715                                         BT_IO_OPT_CHANNEL, HSP_AG_CHANNEL,
2716                                         BT_IO_OPT_SEC_LEVEL, BT_IO_SEC_MEDIUM,
2717                                         BT_IO_OPT_INVALID);
2718         if (!hsp_server) {
2719                 error("Failed to listen on Headset rfcomm: %s", err->message);
2720                 g_error_free(err);
2721                 return false;
2722         }
2723
2724         rec = headset_ag_record();
2725         if (!rec) {
2726                 error("Failed to allocate Headset record");
2727                 goto failed;
2728         }
2729
2730         if (bt_adapter_add_record(rec, 0) < 0) {
2731                 error("Failed to register Headset record");
2732                 sdp_record_free(rec);
2733                 goto failed;
2734         }
2735
2736         hsp_record_id = rec->handle;
2737         return true;
2738
2739 failed:
2740         g_io_channel_shutdown(hsp_server, TRUE, NULL);
2741         g_io_channel_unref(hsp_server);
2742         hsp_server = NULL;
2743
2744         return false;
2745 }
2746
2747 static void cleanup_hsp_ag(void)
2748 {
2749         if (hsp_server) {
2750                 g_io_channel_shutdown(hsp_server, TRUE, NULL);
2751                 g_io_channel_unref(hsp_server);
2752                 hsp_server = NULL;
2753         }
2754
2755         if (hsp_record_id > 0) {
2756                 bt_adapter_remove_record(hsp_record_id);
2757                 hsp_record_id = 0;
2758         }
2759 }
2760
2761 static sdp_record_t *hfp_ag_record(void)
2762 {
2763         sdp_list_t *svclass_id, *pfseq, *apseq, *root;
2764         uuid_t root_uuid, svclass_uuid, ga_svclass_uuid;
2765         uuid_t l2cap_uuid, rfcomm_uuid;
2766         sdp_profile_desc_t profile;
2767         sdp_list_t *aproto, *proto[2];
2768         sdp_record_t *record;
2769         sdp_data_t *channel, *features;
2770         uint8_t netid = 0x01;
2771         uint16_t sdpfeat;
2772         sdp_data_t *network;
2773         uint8_t ch = HFP_AG_CHANNEL;
2774
2775         record = sdp_record_alloc();
2776         if (!record)
2777                 return NULL;
2778
2779         network = sdp_data_alloc(SDP_UINT8, &netid);
2780         if (!network) {
2781                 sdp_record_free(record);
2782                 return NULL;
2783         }
2784
2785         sdp_uuid16_create(&root_uuid, PUBLIC_BROWSE_GROUP);
2786         root = sdp_list_append(NULL, &root_uuid);
2787         sdp_set_browse_groups(record, root);
2788
2789         sdp_uuid16_create(&svclass_uuid, HANDSFREE_AGW_SVCLASS_ID);
2790         svclass_id = sdp_list_append(NULL, &svclass_uuid);
2791         sdp_uuid16_create(&ga_svclass_uuid, GENERIC_AUDIO_SVCLASS_ID);
2792         svclass_id = sdp_list_append(svclass_id, &ga_svclass_uuid);
2793         sdp_set_service_classes(record, svclass_id);
2794
2795         sdp_uuid16_create(&profile.uuid, HANDSFREE_PROFILE_ID);
2796         profile.version = 0x0106;
2797         pfseq = sdp_list_append(NULL, &profile);
2798         sdp_set_profile_descs(record, pfseq);
2799
2800         sdp_uuid16_create(&l2cap_uuid, L2CAP_UUID);
2801         proto[0] = sdp_list_append(NULL, &l2cap_uuid);
2802         apseq = sdp_list_append(NULL, proto[0]);
2803
2804         sdp_uuid16_create(&rfcomm_uuid, RFCOMM_UUID);
2805         proto[1] = sdp_list_append(NULL, &rfcomm_uuid);
2806         channel = sdp_data_alloc(SDP_UINT8, &ch);
2807         proto[1] = sdp_list_append(proto[1], channel);
2808         apseq = sdp_list_append(apseq, proto[1]);
2809
2810         /* Codec Negotiation bit in SDP feature is different then in BRSF */
2811         sdpfeat = hfp_ag_features & 0x0000003F;
2812         if (hfp_ag_features & HFP_AG_FEAT_CODEC)
2813                 sdpfeat |= 0x00000020;
2814         else
2815                 sdpfeat &= ~0x00000020;
2816
2817         features = sdp_data_alloc(SDP_UINT16, &sdpfeat);
2818         sdp_attr_add(record, SDP_ATTR_SUPPORTED_FEATURES, features);
2819
2820         aproto = sdp_list_append(NULL, apseq);
2821         sdp_set_access_protos(record, aproto);
2822
2823         sdp_set_info_attr(record, "Hands-Free Audio Gateway", NULL, NULL);
2824
2825         sdp_attr_add(record, SDP_ATTR_EXTERNAL_NETWORK, network);
2826
2827         sdp_data_free(channel);
2828         sdp_list_free(proto[0], NULL);
2829         sdp_list_free(proto[1], NULL);
2830         sdp_list_free(apseq, NULL);
2831         sdp_list_free(pfseq, NULL);
2832         sdp_list_free(aproto, NULL);
2833         sdp_list_free(root, NULL);
2834         sdp_list_free(svclass_id, NULL);
2835
2836         return record;
2837 }
2838
2839 static bool enable_hfp_ag(void)
2840 {
2841         sdp_record_t *rec;
2842         GError *err = NULL;
2843
2844         DBG("");
2845
2846         if (hfp_server)
2847                 return false;
2848
2849         hfp_server =  bt_io_listen(NULL, confirm_cb, GINT_TO_POINTER(false),
2850                                         NULL, &err,
2851                                         BT_IO_OPT_SOURCE_BDADDR, &adapter_addr,
2852                                         BT_IO_OPT_CHANNEL, HFP_AG_CHANNEL,
2853                                         BT_IO_OPT_SEC_LEVEL, BT_IO_SEC_MEDIUM,
2854                                         BT_IO_OPT_INVALID);
2855         if (!hfp_server) {
2856                 error("Failed to listen on Handsfree rfcomm: %s", err->message);
2857                 g_error_free(err);
2858                 return false;
2859         }
2860
2861         rec = hfp_ag_record();
2862         if (!rec) {
2863                 error("Failed to allocate Handsfree record");
2864                 goto failed;
2865         }
2866
2867         if (bt_adapter_add_record(rec, 0) < 0) {
2868                 error("Failed to register Handsfree record");
2869                 sdp_record_free(rec);
2870                 goto failed;
2871         }
2872
2873         hfp_record_id = rec->handle;
2874         return true;
2875
2876 failed:
2877         g_io_channel_shutdown(hfp_server, TRUE, NULL);
2878         g_io_channel_unref(hfp_server);
2879         hfp_server = NULL;
2880
2881         return false;
2882 }
2883
2884 static void cleanup_hfp_ag(void)
2885 {
2886         if (hfp_server) {
2887                 g_io_channel_shutdown(hfp_server, TRUE, NULL);
2888                 g_io_channel_unref(hfp_server);
2889                 hfp_server = NULL;
2890         }
2891
2892         if (hfp_record_id > 0) {
2893                 bt_adapter_remove_record(hfp_record_id);
2894                 hfp_record_id = 0;
2895         }
2896 }
2897
2898 static void bt_sco_get_fd(const void *buf, uint16_t len)
2899 {
2900         const struct sco_cmd_get_fd *cmd = buf;
2901         struct sco_rsp_get_fd rsp;
2902         struct hf_device *dev;
2903         bdaddr_t bdaddr;
2904         int fd;
2905
2906         DBG("");
2907
2908         android2bdaddr(cmd->bdaddr, &bdaddr);
2909
2910         dev = find_device(&bdaddr);
2911         if (!dev || !bt_sco_get_fd_and_mtu(sco, &fd, &rsp.mtu))
2912                 goto failed;
2913
2914         DBG("fd %d mtu %u", fd, rsp.mtu);
2915
2916         ipc_send_rsp_full(sco_ipc, SCO_SERVICE_ID, SCO_OP_GET_FD,
2917                                                         sizeof(rsp), &rsp, fd);
2918
2919         return;
2920
2921 failed:
2922         ipc_send_rsp(sco_ipc, SCO_SERVICE_ID, SCO_OP_STATUS, SCO_STATUS_FAILED);
2923 }
2924
2925 static const struct ipc_handler sco_handlers[] = {
2926         /* SCO_OP_GET_FD */
2927         { bt_sco_get_fd, false, 0 }
2928 };
2929
2930 static void bt_sco_unregister(void)
2931 {
2932         DBG("");
2933
2934         ipc_cleanup(sco_ipc);
2935         sco_ipc = NULL;
2936 }
2937
2938 static bool bt_sco_register(ipc_disconnect_cb disconnect)
2939 {
2940         DBG("");
2941
2942         sco_ipc = ipc_init(BLUEZ_SCO_SK_PATH, sizeof(BLUEZ_SCO_SK_PATH),
2943                                 SCO_SERVICE_ID, false, disconnect, NULL);
2944         if (!sco_ipc)
2945                 return false;
2946
2947         ipc_register(sco_ipc, SCO_SERVICE_ID, sco_handlers,
2948                                                 G_N_ELEMENTS(sco_handlers));
2949
2950         return true;
2951 }
2952
2953 bool bt_handsfree_register(struct ipc *ipc, const bdaddr_t *addr, uint8_t mode,
2954                                                                 int max_clients)
2955 {
2956         DBG("mode 0x%x max_clients %d", mode, max_clients);
2957
2958         bacpy(&adapter_addr, addr);
2959
2960         if (max_clients < 1)
2961                 return false;
2962
2963         devices = queue_new();
2964         if (!devices)
2965                 return false;
2966
2967         if (!enable_hsp_ag())
2968                 goto failed_queue;
2969
2970         sco = bt_sco_new(addr);
2971         if (!sco)
2972                 goto failed_hsp;
2973
2974         bt_sco_set_confirm_cb(sco, confirm_sco_cb);
2975         bt_sco_set_connect_cb(sco, connect_sco_cb);
2976         bt_sco_set_disconnect_cb(sco, disconnect_sco_cb);
2977
2978         if (mode == HAL_MODE_HANDSFREE_HSP_ONLY)
2979                 goto done;
2980
2981         hfp_ag_features = HFP_AG_FEATURES;
2982
2983         if (mode == HAL_MODE_HANDSFREE_HFP_WBS)
2984                 hfp_ag_features |= HFP_AG_FEAT_CODEC;
2985
2986         if (enable_hfp_ag())
2987                 goto done;
2988
2989         bt_sco_unref(sco);
2990         sco = NULL;
2991         hfp_ag_features = 0;
2992 failed_hsp:
2993         cleanup_hsp_ag();
2994 failed_queue:
2995         queue_destroy(devices, NULL);
2996         devices = NULL;
2997
2998         return false;
2999
3000 done:
3001         hal_ipc = ipc;
3002         ipc_register(hal_ipc, HAL_SERVICE_ID_HANDSFREE, cmd_handlers,
3003                                                 G_N_ELEMENTS(cmd_handlers));
3004
3005         bt_sco_register(NULL);
3006
3007         max_hfp_clients = max_clients;
3008
3009         return true;
3010 }
3011
3012 void bt_handsfree_unregister(void)
3013 {
3014         DBG("");
3015
3016         bt_sco_unregister();
3017         ipc_unregister(hal_ipc, HAL_SERVICE_ID_HANDSFREE);
3018         hal_ipc = NULL;
3019
3020         cleanup_hfp_ag();
3021         cleanup_hsp_ag();
3022         bt_sco_unref(sco);
3023         sco = NULL;
3024
3025         hfp_ag_features = 0;
3026
3027         queue_destroy(devices, (queue_destroy_func_t) device_destroy);
3028         devices = NULL;
3029
3030         max_hfp_clients = 0;
3031 }