Home | History | Annotate | Line # | Download | only in netbt
hci_event.c revision 1.14.6.1
      1  1.14.6.1      mjf /*	$NetBSD: hci_event.c,v 1.14.6.1 2008/04/03 12:43:08 mjf Exp $	*/
      2       1.1  gdamore 
      3       1.1  gdamore /*-
      4       1.1  gdamore  * Copyright (c) 2005 Iain Hibbert.
      5       1.1  gdamore  * Copyright (c) 2006 Itronix Inc.
      6       1.1  gdamore  * All rights reserved.
      7       1.1  gdamore  *
      8       1.1  gdamore  * Redistribution and use in source and binary forms, with or without
      9       1.1  gdamore  * modification, are permitted provided that the following conditions
     10       1.1  gdamore  * are met:
     11       1.1  gdamore  * 1. Redistributions of source code must retain the above copyright
     12       1.1  gdamore  *    notice, this list of conditions and the following disclaimer.
     13       1.1  gdamore  * 2. Redistributions in binary form must reproduce the above copyright
     14       1.1  gdamore  *    notice, this list of conditions and the following disclaimer in the
     15       1.1  gdamore  *    documentation and/or other materials provided with the distribution.
     16       1.1  gdamore  * 3. The name of Itronix Inc. may not be used to endorse
     17       1.1  gdamore  *    or promote products derived from this software without specific
     18       1.1  gdamore  *    prior written permission.
     19       1.1  gdamore  *
     20       1.1  gdamore  * THIS SOFTWARE IS PROVIDED BY ITRONIX INC. ``AS IS'' AND
     21       1.1  gdamore  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     22       1.1  gdamore  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     23       1.1  gdamore  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL ITRONIX INC. BE LIABLE FOR ANY
     24       1.1  gdamore  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
     25       1.1  gdamore  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
     26       1.1  gdamore  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
     27       1.1  gdamore  * ON ANY THEORY OF LIABILITY, WHETHER IN
     28       1.1  gdamore  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     29       1.1  gdamore  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     30       1.1  gdamore  * POSSIBILITY OF SUCH DAMAGE.
     31       1.1  gdamore  */
     32       1.1  gdamore 
     33       1.1  gdamore #include <sys/cdefs.h>
     34  1.14.6.1      mjf __KERNEL_RCSID(0, "$NetBSD: hci_event.c,v 1.14.6.1 2008/04/03 12:43:08 mjf Exp $");
     35       1.1  gdamore 
     36       1.1  gdamore #include <sys/param.h>
     37       1.1  gdamore #include <sys/kernel.h>
     38       1.1  gdamore #include <sys/malloc.h>
     39       1.1  gdamore #include <sys/mbuf.h>
     40       1.1  gdamore #include <sys/proc.h>
     41       1.1  gdamore #include <sys/systm.h>
     42       1.1  gdamore 
     43       1.1  gdamore #include <netbt/bluetooth.h>
     44       1.1  gdamore #include <netbt/hci.h>
     45       1.1  gdamore #include <netbt/sco.h>
     46       1.1  gdamore 
     47       1.1  gdamore static void hci_event_inquiry_result(struct hci_unit *, struct mbuf *);
     48       1.8   plunky static void hci_event_rssi_result(struct hci_unit *, struct mbuf *);
     49       1.1  gdamore static void hci_event_command_status(struct hci_unit *, struct mbuf *);
     50       1.1  gdamore static void hci_event_command_compl(struct hci_unit *, struct mbuf *);
     51       1.1  gdamore static void hci_event_con_compl(struct hci_unit *, struct mbuf *);
     52       1.1  gdamore static void hci_event_discon_compl(struct hci_unit *, struct mbuf *);
     53       1.1  gdamore static void hci_event_con_req(struct hci_unit *, struct mbuf *);
     54       1.1  gdamore static void hci_event_num_compl_pkts(struct hci_unit *, struct mbuf *);
     55       1.6   plunky static void hci_event_auth_compl(struct hci_unit *, struct mbuf *);
     56       1.6   plunky static void hci_event_encryption_change(struct hci_unit *, struct mbuf *);
     57       1.6   plunky static void hci_event_change_con_link_key_compl(struct hci_unit *, struct mbuf *);
     58       1.9   plunky static void hci_event_read_clock_offset_compl(struct hci_unit *, struct mbuf *);
     59       1.1  gdamore static void hci_cmd_read_bdaddr(struct hci_unit *, struct mbuf *);
     60       1.1  gdamore static void hci_cmd_read_buffer_size(struct hci_unit *, struct mbuf *);
     61       1.1  gdamore static void hci_cmd_read_local_features(struct hci_unit *, struct mbuf *);
     62      1.13   plunky static void hci_cmd_read_local_ver(struct hci_unit *, struct mbuf *);
     63      1.13   plunky static void hci_cmd_read_local_commands(struct hci_unit *, struct mbuf *);
     64       1.1  gdamore static void hci_cmd_reset(struct hci_unit *, struct mbuf *);
     65  1.14.6.1      mjf static void hci_cmd_create_con(struct hci_unit *unit, uint8_t status);
     66       1.1  gdamore 
     67       1.1  gdamore #ifdef BLUETOOTH_DEBUG
     68       1.5   plunky int bluetooth_debug;
     69       1.1  gdamore 
     70       1.1  gdamore static const char *hci_eventnames[] = {
     71       1.1  gdamore /* 0x00 */ "NULL",
     72       1.1  gdamore /* 0x01 */ "INQUIRY COMPLETE",
     73       1.1  gdamore /* 0x02 */ "INQUIRY RESULT",
     74       1.1  gdamore /* 0x03 */ "CONN COMPLETE",
     75       1.1  gdamore /* 0x04 */ "CONN REQ",
     76       1.1  gdamore /* 0x05 */ "DISCONN COMPLETE",
     77       1.1  gdamore /* 0x06 */ "AUTH COMPLETE",
     78       1.1  gdamore /* 0x07 */ "REMOTE NAME REQ COMPLETE",
     79       1.1  gdamore /* 0x08 */ "ENCRYPTION CHANGE",
     80       1.1  gdamore /* 0x09 */ "CHANGE CONN LINK KEY COMPLETE",
     81       1.1  gdamore /* 0x0a */ "MASTER LINK KEY COMPLETE",
     82       1.1  gdamore /* 0x0b */ "READ REMOTE FEATURES COMPLETE",
     83       1.1  gdamore /* 0x0c */ "READ REMOTE VERSION INFO COMPLETE",
     84       1.1  gdamore /* 0x0d */ "QoS SETUP COMPLETE",
     85       1.1  gdamore /* 0x0e */ "COMMAND COMPLETE",
     86       1.1  gdamore /* 0x0f */ "COMMAND STATUS",
     87       1.1  gdamore /* 0x10 */ "HARDWARE ERROR",
     88       1.1  gdamore /* 0x11 */ "FLUSH OCCUR",
     89       1.1  gdamore /* 0x12 */ "ROLE CHANGE",
     90       1.1  gdamore /* 0x13 */ "NUM COMPLETED PACKETS",
     91       1.1  gdamore /* 0x14 */ "MODE CHANGE",
     92       1.1  gdamore /* 0x15 */ "RETURN LINK KEYS",
     93       1.1  gdamore /* 0x16 */ "PIN CODE REQ",
     94       1.1  gdamore /* 0x17 */ "LINK KEY REQ",
     95       1.1  gdamore /* 0x18 */ "LINK KEY NOTIFICATION",
     96       1.1  gdamore /* 0x19 */ "LOOPBACK COMMAND",
     97       1.1  gdamore /* 0x1a */ "DATA BUFFER OVERFLOW",
     98       1.1  gdamore /* 0x1b */ "MAX SLOT CHANGE",
     99       1.1  gdamore /* 0x1c */ "READ CLOCK OFFSET COMPLETE",
    100       1.1  gdamore /* 0x1d */ "CONN PKT TYPE CHANGED",
    101       1.1  gdamore /* 0x1e */ "QOS VIOLATION",
    102       1.1  gdamore /* 0x1f */ "PAGE SCAN MODE CHANGE",
    103       1.1  gdamore /* 0x20 */ "PAGE SCAN REP MODE CHANGE",
    104       1.1  gdamore /* 0x21 */ "FLOW SPECIFICATION COMPLETE",
    105       1.1  gdamore /* 0x22 */ "RSSI RESULT",
    106      1.14   plunky /* 0x23 */ "READ REMOTE EXT FEATURES",
    107      1.14   plunky /* 0x24 */ "UNKNOWN",
    108      1.14   plunky /* 0x25 */ "UNKNOWN",
    109      1.14   plunky /* 0x26 */ "UNKNOWN",
    110      1.14   plunky /* 0x27 */ "UNKNOWN",
    111      1.14   plunky /* 0x28 */ "UNKNOWN",
    112      1.14   plunky /* 0x29 */ "UNKNOWN",
    113      1.14   plunky /* 0x2a */ "UNKNOWN",
    114      1.14   plunky /* 0x2b */ "UNKNOWN",
    115      1.14   plunky /* 0x2c */ "SCO CON COMPLETE",
    116      1.14   plunky /* 0x2d */ "SCO CON CHANGED",
    117      1.14   plunky /* 0x2e */ "SNIFF SUBRATING",
    118      1.14   plunky /* 0x2f */ "EXTENDED INQUIRY RESULT",
    119      1.14   plunky /* 0x30 */ "ENCRYPTION KEY REFRESH",
    120      1.14   plunky /* 0x31 */ "IO CAPABILITY REQUEST",
    121      1.14   plunky /* 0x32 */ "IO CAPABILITY RESPONSE",
    122      1.14   plunky /* 0x33 */ "USER CONFIRM REQUEST",
    123      1.14   plunky /* 0x34 */ "USER PASSKEY REQUEST",
    124      1.14   plunky /* 0x35 */ "REMOTE OOB DATA REQUEST",
    125      1.14   plunky /* 0x36 */ "SIMPLE PAIRING COMPLETE",
    126      1.14   plunky /* 0x37 */ "UNKNOWN",
    127      1.14   plunky /* 0x38 */ "LINK SUPERVISION TIMEOUT CHANGED",
    128      1.14   plunky /* 0x39 */ "ENHANCED FLUSH COMPLETE",
    129      1.14   plunky /* 0x3a */ "UNKNOWN",
    130      1.14   plunky /* 0x3b */ "USER PASSKEY NOTIFICATION",
    131      1.14   plunky /* 0x3c */ "KEYPRESS NOTIFICATION",
    132      1.14   plunky /* 0x3d */ "REMOTE HOST FEATURES NOTIFICATION",
    133       1.1  gdamore };
    134       1.1  gdamore 
    135       1.1  gdamore static const char *
    136       1.1  gdamore hci_eventstr(unsigned int event)
    137       1.1  gdamore {
    138       1.1  gdamore 
    139      1.14   plunky 	if (event < __arraycount(hci_eventnames))
    140       1.1  gdamore 		return hci_eventnames[event];
    141       1.1  gdamore 
    142       1.1  gdamore 	switch (event) {
    143       1.1  gdamore 	case HCI_EVENT_BT_LOGO:		/* 0xfe */
    144       1.1  gdamore 		return "BT_LOGO";
    145       1.1  gdamore 
    146       1.1  gdamore 	case HCI_EVENT_VENDOR:		/* 0xff */
    147       1.1  gdamore 		return "VENDOR";
    148       1.1  gdamore 	}
    149       1.1  gdamore 
    150      1.14   plunky 	return "UNKNOWN";
    151       1.1  gdamore }
    152       1.1  gdamore #endif	/* BLUETOOTH_DEBUG */
    153       1.1  gdamore 
    154       1.1  gdamore /*
    155       1.1  gdamore  * process HCI Events
    156       1.1  gdamore  *
    157       1.1  gdamore  * We will free the mbuf at the end, no need for any sub
    158       1.1  gdamore  * functions to handle that. We kind of assume that the
    159       1.1  gdamore  * device sends us valid events.
    160       1.1  gdamore  */
    161       1.1  gdamore void
    162       1.1  gdamore hci_event(struct mbuf *m, struct hci_unit *unit)
    163       1.1  gdamore {
    164       1.1  gdamore 	hci_event_hdr_t hdr;
    165       1.1  gdamore 
    166       1.1  gdamore 	KASSERT(m->m_flags & M_PKTHDR);
    167       1.1  gdamore 
    168       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(hdr));
    169       1.1  gdamore 	m_copydata(m, 0, sizeof(hdr), &hdr);
    170       1.1  gdamore 	m_adj(m, sizeof(hdr));
    171       1.1  gdamore 
    172       1.1  gdamore 	KASSERT(hdr.type == HCI_EVENT_PKT);
    173       1.1  gdamore 
    174      1.10   plunky 	DPRINTFN(1, "(%s) event %s\n",
    175      1.10   plunky 	    device_xname(unit->hci_dev), hci_eventstr(hdr.event));
    176       1.1  gdamore 
    177       1.1  gdamore 	switch(hdr.event) {
    178       1.1  gdamore 	case HCI_EVENT_COMMAND_STATUS:
    179       1.1  gdamore 		hci_event_command_status(unit, m);
    180       1.1  gdamore 		break;
    181       1.1  gdamore 
    182       1.1  gdamore 	case HCI_EVENT_COMMAND_COMPL:
    183       1.1  gdamore 		hci_event_command_compl(unit, m);
    184       1.1  gdamore 		break;
    185       1.1  gdamore 
    186       1.1  gdamore 	case HCI_EVENT_NUM_COMPL_PKTS:
    187       1.1  gdamore 		hci_event_num_compl_pkts(unit, m);
    188       1.1  gdamore 		break;
    189       1.1  gdamore 
    190       1.1  gdamore 	case HCI_EVENT_INQUIRY_RESULT:
    191       1.1  gdamore 		hci_event_inquiry_result(unit, m);
    192       1.1  gdamore 		break;
    193       1.1  gdamore 
    194       1.8   plunky 	case HCI_EVENT_RSSI_RESULT:
    195       1.8   plunky 		hci_event_rssi_result(unit, m);
    196       1.8   plunky 		break;
    197       1.8   plunky 
    198       1.1  gdamore 	case HCI_EVENT_CON_COMPL:
    199       1.1  gdamore 		hci_event_con_compl(unit, m);
    200       1.1  gdamore 		break;
    201       1.1  gdamore 
    202       1.1  gdamore 	case HCI_EVENT_DISCON_COMPL:
    203       1.1  gdamore 		hci_event_discon_compl(unit, m);
    204       1.1  gdamore 		break;
    205       1.1  gdamore 
    206       1.1  gdamore 	case HCI_EVENT_CON_REQ:
    207       1.1  gdamore 		hci_event_con_req(unit, m);
    208       1.1  gdamore 		break;
    209       1.1  gdamore 
    210       1.6   plunky 	case HCI_EVENT_AUTH_COMPL:
    211       1.6   plunky 		hci_event_auth_compl(unit, m);
    212       1.6   plunky 		break;
    213       1.6   plunky 
    214       1.6   plunky 	case HCI_EVENT_ENCRYPTION_CHANGE:
    215       1.6   plunky 		hci_event_encryption_change(unit, m);
    216       1.6   plunky 		break;
    217       1.6   plunky 
    218       1.6   plunky 	case HCI_EVENT_CHANGE_CON_LINK_KEY_COMPL:
    219       1.6   plunky 		hci_event_change_con_link_key_compl(unit, m);
    220       1.6   plunky 		break;
    221       1.6   plunky 
    222       1.9   plunky 	case HCI_EVENT_READ_CLOCK_OFFSET_COMPL:
    223       1.9   plunky 		hci_event_read_clock_offset_compl(unit, m);
    224       1.9   plunky 		break;
    225       1.9   plunky 
    226       1.1  gdamore 	default:
    227       1.1  gdamore 		break;
    228       1.1  gdamore 	}
    229       1.1  gdamore 
    230       1.1  gdamore 	m_freem(m);
    231       1.1  gdamore }
    232       1.1  gdamore 
    233       1.1  gdamore /*
    234       1.1  gdamore  * Command Status
    235       1.1  gdamore  *
    236  1.14.6.1      mjf  * Restart command queue and post-process any pending commands
    237       1.1  gdamore  */
    238       1.1  gdamore static void
    239       1.1  gdamore hci_event_command_status(struct hci_unit *unit, struct mbuf *m)
    240       1.1  gdamore {
    241       1.1  gdamore 	hci_command_status_ep ep;
    242       1.1  gdamore 
    243       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    244       1.1  gdamore 	m_copydata(m, 0, sizeof(ep), &ep);
    245       1.1  gdamore 	m_adj(m, sizeof(ep));
    246       1.1  gdamore 
    247  1.14.6.1      mjf 	ep.opcode = le16toh(ep.opcode);
    248  1.14.6.1      mjf 
    249       1.6   plunky 	DPRINTFN(1, "(%s) opcode (%03x|%04x) status = 0x%x num_cmd_pkts = %d\n",
    250      1.10   plunky 		device_xname(unit->hci_dev),
    251  1.14.6.1      mjf 		HCI_OGF(ep.opcode), HCI_OCF(ep.opcode),
    252       1.6   plunky 		ep.status,
    253       1.1  gdamore 		ep.num_cmd_pkts);
    254       1.1  gdamore 
    255  1.14.6.1      mjf 	hci_num_cmds(unit, ep.num_cmd_pkts);
    256       1.1  gdamore 
    257       1.1  gdamore 	/*
    258       1.1  gdamore 	 * post processing of pending commands
    259       1.1  gdamore 	 */
    260  1.14.6.1      mjf 	switch(ep.opcode) {
    261  1.14.6.1      mjf 	case HCI_CMD_CREATE_CON:
    262  1.14.6.1      mjf 		hci_cmd_create_con(unit, ep.status);
    263       1.1  gdamore 		break;
    264       1.1  gdamore 
    265  1.14.6.1      mjf 	default:
    266  1.14.6.1      mjf 		if (ep.status == 0)
    267  1.14.6.1      mjf 			break;
    268  1.14.6.1      mjf 
    269  1.14.6.1      mjf 		aprint_error_dev(unit->hci_dev,
    270  1.14.6.1      mjf 		    "CommandStatus opcode (%03x|%04x) failed (status=0x%02x)\n",
    271  1.14.6.1      mjf 		    HCI_OGF(ep.opcode), HCI_OCF(ep.opcode),
    272  1.14.6.1      mjf 		    ep.status);
    273  1.14.6.1      mjf 
    274  1.14.6.1      mjf 		break;
    275       1.1  gdamore 	}
    276       1.1  gdamore }
    277       1.1  gdamore 
    278       1.1  gdamore /*
    279       1.1  gdamore  * Command Complete
    280       1.1  gdamore  *
    281  1.14.6.1      mjf  * Restart command queue and handle the completed command
    282       1.1  gdamore  */
    283       1.1  gdamore static void
    284       1.1  gdamore hci_event_command_compl(struct hci_unit *unit, struct mbuf *m)
    285       1.1  gdamore {
    286       1.1  gdamore 	hci_command_compl_ep ep;
    287      1.12   plunky 	hci_status_rp rp;
    288       1.1  gdamore 
    289       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    290       1.1  gdamore 	m_copydata(m, 0, sizeof(ep), &ep);
    291       1.1  gdamore 	m_adj(m, sizeof(ep));
    292       1.1  gdamore 
    293       1.1  gdamore 	DPRINTFN(1, "(%s) opcode (%03x|%04x) num_cmd_pkts = %d\n",
    294      1.10   plunky 		device_xname(unit->hci_dev),
    295       1.1  gdamore 		HCI_OGF(le16toh(ep.opcode)), HCI_OCF(le16toh(ep.opcode)),
    296       1.1  gdamore 		ep.num_cmd_pkts);
    297       1.1  gdamore 
    298  1.14.6.1      mjf 	hci_num_cmds(unit, ep.num_cmd_pkts);
    299  1.14.6.1      mjf 
    300      1.12   plunky 	/*
    301      1.12   plunky 	 * I am not sure if this is completely correct, it is not guaranteed
    302      1.12   plunky 	 * that a command_complete packet will contain the status though most
    303      1.12   plunky 	 * do seem to.
    304      1.12   plunky 	 */
    305      1.12   plunky 	m_copydata(m, 0, sizeof(rp), &rp);
    306      1.12   plunky 	if (rp.status > 0)
    307      1.12   plunky 		aprint_error_dev(unit->hci_dev,
    308      1.12   plunky 		    "CommandComplete opcode (%03x|%04x) failed (status=0x%02x)\n",
    309      1.12   plunky 		    HCI_OGF(le16toh(ep.opcode)), HCI_OCF(le16toh(ep.opcode)),
    310      1.12   plunky 		    rp.status);
    311      1.12   plunky 
    312       1.1  gdamore 	/*
    313       1.1  gdamore 	 * post processing of completed commands
    314       1.1  gdamore 	 */
    315       1.1  gdamore 	switch(le16toh(ep.opcode)) {
    316       1.1  gdamore 	case HCI_CMD_READ_BDADDR:
    317       1.1  gdamore 		hci_cmd_read_bdaddr(unit, m);
    318       1.1  gdamore 		break;
    319       1.1  gdamore 
    320       1.1  gdamore 	case HCI_CMD_READ_BUFFER_SIZE:
    321       1.1  gdamore 		hci_cmd_read_buffer_size(unit, m);
    322       1.1  gdamore 		break;
    323       1.1  gdamore 
    324       1.1  gdamore 	case HCI_CMD_READ_LOCAL_FEATURES:
    325       1.1  gdamore 		hci_cmd_read_local_features(unit, m);
    326       1.1  gdamore 		break;
    327       1.1  gdamore 
    328      1.13   plunky 	case HCI_CMD_READ_LOCAL_VER:
    329      1.13   plunky 		hci_cmd_read_local_ver(unit, m);
    330      1.13   plunky 		break;
    331      1.13   plunky 
    332      1.13   plunky 	case HCI_CMD_READ_LOCAL_COMMANDS:
    333      1.13   plunky 		hci_cmd_read_local_commands(unit, m);
    334      1.13   plunky 		break;
    335      1.13   plunky 
    336       1.1  gdamore 	case HCI_CMD_RESET:
    337       1.1  gdamore 		hci_cmd_reset(unit, m);
    338       1.1  gdamore 		break;
    339       1.1  gdamore 
    340       1.1  gdamore 	default:
    341       1.1  gdamore 		break;
    342       1.1  gdamore 	}
    343       1.1  gdamore }
    344       1.1  gdamore 
    345       1.1  gdamore /*
    346       1.1  gdamore  * Number of Completed Packets
    347       1.1  gdamore  *
    348       1.1  gdamore  * This is sent periodically by the Controller telling us how many
    349       1.1  gdamore  * buffers are now freed up and which handle was using them. From
    350       1.1  gdamore  * this we determine which type of buffer it was and add the qty
    351       1.1  gdamore  * back into the relevant packet counter, then restart output on
    352       1.1  gdamore  * links that have halted.
    353       1.1  gdamore  */
    354       1.1  gdamore static void
    355       1.1  gdamore hci_event_num_compl_pkts(struct hci_unit *unit, struct mbuf *m)
    356       1.1  gdamore {
    357       1.1  gdamore 	hci_num_compl_pkts_ep ep;
    358       1.1  gdamore 	struct hci_link *link, *next;
    359       1.1  gdamore 	uint16_t handle, num;
    360       1.1  gdamore 	int num_acl = 0, num_sco = 0;
    361       1.1  gdamore 
    362       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    363       1.1  gdamore 	m_copydata(m, 0, sizeof(ep), &ep);
    364       1.1  gdamore 	m_adj(m, sizeof(ep));
    365       1.1  gdamore 
    366       1.1  gdamore 	while (ep.num_con_handles--) {
    367       1.7   plunky 		m_copydata(m, 0, sizeof(handle), &handle);
    368       1.1  gdamore 		m_adj(m, sizeof(handle));
    369       1.1  gdamore 		handle = le16toh(handle);
    370       1.1  gdamore 
    371       1.7   plunky 		m_copydata(m, 0, sizeof(num), &num);
    372       1.1  gdamore 		m_adj(m, sizeof(num));
    373       1.1  gdamore 		num = le16toh(num);
    374       1.1  gdamore 
    375       1.1  gdamore 		link = hci_link_lookup_handle(unit, handle);
    376       1.1  gdamore 		if (link) {
    377       1.1  gdamore 			if (link->hl_type == HCI_LINK_ACL) {
    378       1.1  gdamore 				num_acl += num;
    379       1.1  gdamore 				hci_acl_complete(link, num);
    380       1.1  gdamore 			} else {
    381       1.1  gdamore 				num_sco += num;
    382       1.1  gdamore 				hci_sco_complete(link, num);
    383       1.1  gdamore 			}
    384       1.1  gdamore 		} else {
    385       1.4   plunky 			/* XXX need to issue Read_Buffer_Size or Reset? */
    386      1.10   plunky 			aprint_error_dev(unit->hci_dev,
    387      1.10   plunky 			    "unknown handle %d! (losing track of %d packet buffer%s)\n",
    388      1.10   plunky 			    handle, num, (num == 1 ? "" : "s"));
    389       1.1  gdamore 		}
    390       1.1  gdamore 	}
    391       1.1  gdamore 
    392       1.1  gdamore 	/*
    393       1.1  gdamore 	 * Move up any queued packets. When a link has sent data, it will move
    394       1.1  gdamore 	 * to the back of the queue - technically then if a link had something
    395       1.1  gdamore 	 * to send and there were still buffers available it could get started
    396       1.1  gdamore 	 * twice but it seemed more important to to handle higher loads fairly
    397       1.1  gdamore 	 * than worry about wasting cycles when we are not busy.
    398       1.1  gdamore 	 */
    399       1.1  gdamore 
    400       1.1  gdamore 	unit->hci_num_acl_pkts += num_acl;
    401       1.1  gdamore 	unit->hci_num_sco_pkts += num_sco;
    402       1.1  gdamore 
    403       1.1  gdamore 	link = TAILQ_FIRST(&unit->hci_links);
    404       1.1  gdamore 	while (link && (unit->hci_num_acl_pkts > 0 || unit->hci_num_sco_pkts > 0)) {
    405       1.1  gdamore 		next = TAILQ_NEXT(link, hl_next);
    406       1.1  gdamore 
    407       1.1  gdamore 		if (link->hl_type == HCI_LINK_ACL) {
    408       1.1  gdamore 			if (unit->hci_num_acl_pkts > 0 && link->hl_txqlen > 0)
    409       1.1  gdamore 				hci_acl_start(link);
    410       1.1  gdamore 		} else {
    411       1.1  gdamore 			if (unit->hci_num_sco_pkts > 0 && link->hl_txqlen > 0)
    412       1.1  gdamore 				hci_sco_start(link);
    413       1.1  gdamore 		}
    414       1.1  gdamore 
    415       1.1  gdamore 		link = next;
    416       1.1  gdamore 	}
    417       1.1  gdamore }
    418       1.1  gdamore 
    419       1.1  gdamore /*
    420       1.1  gdamore  * Inquiry Result
    421       1.1  gdamore  *
    422       1.1  gdamore  * keep a note of devices seen, so we know which unit to use
    423       1.1  gdamore  * on outgoing connections
    424       1.1  gdamore  */
    425       1.1  gdamore static void
    426       1.1  gdamore hci_event_inquiry_result(struct hci_unit *unit, struct mbuf *m)
    427       1.1  gdamore {
    428       1.1  gdamore 	hci_inquiry_result_ep ep;
    429       1.8   plunky 	hci_inquiry_response ir;
    430       1.1  gdamore 	struct hci_memo *memo;
    431       1.1  gdamore 
    432       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    433       1.1  gdamore 	m_copydata(m, 0, sizeof(ep), &ep);
    434       1.1  gdamore 	m_adj(m, sizeof(ep));
    435       1.1  gdamore 
    436       1.1  gdamore 	DPRINTFN(1, "%d response%s\n", ep.num_responses,
    437       1.1  gdamore 				(ep.num_responses == 1 ? "" : "s"));
    438       1.1  gdamore 
    439       1.1  gdamore 	while(ep.num_responses--) {
    440       1.9   plunky 		KASSERT(m->m_pkthdr.len >= sizeof(ir));
    441       1.9   plunky 		m_copydata(m, 0, sizeof(ir), &ir);
    442       1.9   plunky 		m_adj(m, sizeof(ir));
    443       1.1  gdamore 
    444       1.1  gdamore 		DPRINTFN(1, "bdaddr %02x:%02x:%02x:%02x:%02x:%02x\n",
    445       1.9   plunky 			ir.bdaddr.b[5], ir.bdaddr.b[4], ir.bdaddr.b[3],
    446       1.9   plunky 			ir.bdaddr.b[2], ir.bdaddr.b[1], ir.bdaddr.b[0]);
    447       1.1  gdamore 
    448       1.9   plunky 		memo = hci_memo_new(unit, &ir.bdaddr);
    449       1.9   plunky 		if (memo != NULL) {
    450       1.9   plunky 			memo->page_scan_rep_mode = ir.page_scan_rep_mode;
    451       1.9   plunky 			memo->page_scan_mode = ir.page_scan_mode;
    452       1.9   plunky 			memo->clock_offset = ir.clock_offset;
    453       1.1  gdamore 		}
    454       1.8   plunky 	}
    455       1.8   plunky }
    456       1.8   plunky 
    457       1.8   plunky /*
    458       1.8   plunky  * Inquiry Result with RSSI
    459       1.8   plunky  *
    460       1.8   plunky  * as above but different packet when RSSI result is enabled
    461       1.8   plunky  */
    462       1.8   plunky static void
    463       1.8   plunky hci_event_rssi_result(struct hci_unit *unit, struct mbuf *m)
    464       1.8   plunky {
    465       1.8   plunky 	hci_rssi_result_ep ep;
    466       1.8   plunky 	hci_rssi_response rr;
    467       1.8   plunky 	struct hci_memo *memo;
    468       1.8   plunky 
    469       1.8   plunky 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    470       1.8   plunky 	m_copydata(m, 0, sizeof(ep), &ep);
    471       1.8   plunky 	m_adj(m, sizeof(ep));
    472       1.8   plunky 
    473       1.8   plunky 	DPRINTFN(1, "%d response%s\n", ep.num_responses,
    474       1.8   plunky 				(ep.num_responses == 1 ? "" : "s"));
    475       1.8   plunky 
    476       1.8   plunky 	while(ep.num_responses--) {
    477       1.9   plunky 		KASSERT(m->m_pkthdr.len >= sizeof(rr));
    478       1.9   plunky 		m_copydata(m, 0, sizeof(rr), &rr);
    479       1.9   plunky 		m_adj(m, sizeof(rr));
    480       1.2   plunky 
    481       1.8   plunky 		DPRINTFN(1, "bdaddr %02x:%02x:%02x:%02x:%02x:%02x\n",
    482       1.9   plunky 			rr.bdaddr.b[5], rr.bdaddr.b[4], rr.bdaddr.b[3],
    483       1.9   plunky 			rr.bdaddr.b[2], rr.bdaddr.b[1], rr.bdaddr.b[0]);
    484       1.8   plunky 
    485       1.9   plunky 		memo = hci_memo_new(unit, &rr.bdaddr);
    486       1.9   plunky 		if (memo != NULL) {
    487       1.9   plunky 			memo->page_scan_rep_mode = rr.page_scan_rep_mode;
    488       1.9   plunky 			memo->page_scan_mode = 0;
    489       1.9   plunky 			memo->clock_offset = rr.clock_offset;
    490       1.8   plunky 		}
    491       1.1  gdamore 	}
    492       1.1  gdamore }
    493       1.1  gdamore 
    494       1.1  gdamore /*
    495       1.1  gdamore  * Connection Complete
    496       1.1  gdamore  *
    497       1.1  gdamore  * Sent to us when a connection is made. If there is no link
    498       1.1  gdamore  * structure already allocated for this, we must have changed
    499       1.1  gdamore  * our mind, so just disconnect.
    500       1.1  gdamore  */
    501       1.1  gdamore static void
    502       1.1  gdamore hci_event_con_compl(struct hci_unit *unit, struct mbuf *m)
    503       1.1  gdamore {
    504       1.1  gdamore 	hci_con_compl_ep ep;
    505       1.1  gdamore 	hci_write_link_policy_settings_cp cp;
    506       1.1  gdamore 	struct hci_link *link;
    507       1.1  gdamore 	int err;
    508       1.1  gdamore 
    509       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    510       1.1  gdamore 	m_copydata(m, 0, sizeof(ep), &ep);
    511       1.1  gdamore 	m_adj(m, sizeof(ep));
    512       1.1  gdamore 
    513       1.1  gdamore 	DPRINTFN(1, "(%s) %s connection complete for "
    514       1.1  gdamore 		"%02x:%02x:%02x:%02x:%02x:%02x status %#x\n",
    515      1.10   plunky 		device_xname(unit->hci_dev),
    516       1.1  gdamore 		(ep.link_type == HCI_LINK_ACL ? "ACL" : "SCO"),
    517       1.1  gdamore 		ep.bdaddr.b[5], ep.bdaddr.b[4], ep.bdaddr.b[3],
    518       1.1  gdamore 		ep.bdaddr.b[2], ep.bdaddr.b[1], ep.bdaddr.b[0],
    519       1.1  gdamore 		ep.status);
    520       1.1  gdamore 
    521       1.1  gdamore 	link = hci_link_lookup_bdaddr(unit, &ep.bdaddr, ep.link_type);
    522       1.1  gdamore 
    523       1.1  gdamore 	if (ep.status) {
    524       1.1  gdamore 		if (link != NULL) {
    525       1.1  gdamore 			switch (ep.status) {
    526       1.1  gdamore 			case 0x04: /* "Page Timeout" */
    527       1.1  gdamore 				err = EHOSTDOWN;
    528       1.1  gdamore 				break;
    529       1.1  gdamore 
    530       1.1  gdamore 			case 0x08: /* "Connection Timed Out" */
    531       1.1  gdamore 				err = ETIMEDOUT;
    532       1.1  gdamore 				break;
    533       1.1  gdamore 
    534       1.1  gdamore 			case 0x16: /* "Connection Terminated by Local Host" */
    535       1.1  gdamore 				err = 0;
    536       1.1  gdamore 				break;
    537       1.1  gdamore 
    538       1.1  gdamore 			default:
    539       1.1  gdamore 				err = ECONNREFUSED;
    540       1.1  gdamore 				break;
    541       1.1  gdamore 			}
    542       1.1  gdamore 
    543       1.1  gdamore 			hci_link_free(link, err);
    544       1.1  gdamore 		}
    545       1.1  gdamore 
    546       1.1  gdamore 		return;
    547       1.1  gdamore 	}
    548       1.1  gdamore 
    549       1.1  gdamore 	if (link == NULL) {
    550       1.1  gdamore 		hci_discon_cp dp;
    551       1.1  gdamore 
    552       1.1  gdamore 		dp.con_handle = ep.con_handle;
    553       1.1  gdamore 		dp.reason = 0x13; /* "Remote User Terminated Connection" */
    554       1.1  gdamore 
    555       1.1  gdamore 		hci_send_cmd(unit, HCI_CMD_DISCONNECT, &dp, sizeof(dp));
    556       1.1  gdamore 		return;
    557       1.1  gdamore 	}
    558       1.1  gdamore 
    559       1.6   plunky 	/* XXX could check auth_enable here */
    560       1.6   plunky 
    561       1.6   plunky 	if (ep.encryption_mode)
    562       1.6   plunky 		link->hl_flags |= (HCI_LINK_AUTH | HCI_LINK_ENCRYPT);
    563       1.6   plunky 
    564       1.1  gdamore 	link->hl_state = HCI_LINK_OPEN;
    565       1.1  gdamore 	link->hl_handle = HCI_CON_HANDLE(le16toh(ep.con_handle));
    566       1.1  gdamore 
    567       1.1  gdamore 	if (ep.link_type == HCI_LINK_ACL) {
    568       1.1  gdamore 		cp.con_handle = ep.con_handle;
    569       1.1  gdamore 		cp.settings = htole16(unit->hci_link_policy);
    570       1.1  gdamore 		err = hci_send_cmd(unit, HCI_CMD_WRITE_LINK_POLICY_SETTINGS,
    571       1.1  gdamore 						&cp, sizeof(cp));
    572       1.1  gdamore 		if (err)
    573      1.10   plunky 			aprint_error_dev(unit->hci_dev,
    574      1.10   plunky 			    "Warning, could not write link policy\n");
    575       1.1  gdamore 
    576       1.9   plunky 		err = hci_send_cmd(unit, HCI_CMD_READ_CLOCK_OFFSET,
    577       1.9   plunky 				    &cp.con_handle, sizeof(cp.con_handle));
    578       1.9   plunky 		if (err)
    579      1.10   plunky 			aprint_error_dev(unit->hci_dev,
    580      1.10   plunky 			    "Warning, could not read clock offset\n");
    581       1.9   plunky 
    582       1.6   plunky 		err = hci_acl_setmode(link);
    583       1.6   plunky 		if (err == EINPROGRESS)
    584       1.6   plunky 			return;
    585       1.6   plunky 
    586       1.6   plunky 		hci_acl_linkmode(link);
    587       1.1  gdamore 	} else {
    588       1.1  gdamore 		(*link->hl_sco->sp_proto->connected)(link->hl_sco->sp_upper);
    589       1.1  gdamore 	}
    590       1.1  gdamore }
    591       1.1  gdamore 
    592       1.1  gdamore /*
    593       1.1  gdamore  * Disconnection Complete
    594       1.1  gdamore  *
    595       1.1  gdamore  * This is sent in response to a disconnection request, but also if
    596       1.1  gdamore  * the remote device goes out of range.
    597       1.1  gdamore  */
    598       1.1  gdamore static void
    599       1.1  gdamore hci_event_discon_compl(struct hci_unit *unit, struct mbuf *m)
    600       1.1  gdamore {
    601       1.1  gdamore 	hci_discon_compl_ep ep;
    602       1.1  gdamore 	struct hci_link *link;
    603       1.1  gdamore 
    604       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    605       1.1  gdamore 	m_copydata(m, 0, sizeof(ep), &ep);
    606       1.1  gdamore 	m_adj(m, sizeof(ep));
    607       1.1  gdamore 
    608       1.1  gdamore 	ep.con_handle = le16toh(ep.con_handle);
    609       1.1  gdamore 
    610       1.1  gdamore 	DPRINTFN(1, "handle #%d, status=0x%x\n", ep.con_handle, ep.status);
    611       1.1  gdamore 
    612       1.1  gdamore 	link = hci_link_lookup_handle(unit, HCI_CON_HANDLE(ep.con_handle));
    613       1.1  gdamore 	if (link)
    614       1.1  gdamore 		hci_link_free(link, ENOLINK);
    615       1.1  gdamore }
    616       1.1  gdamore 
    617       1.1  gdamore /*
    618       1.1  gdamore  * Connect Request
    619       1.1  gdamore  *
    620       1.1  gdamore  * We check upstream for appropriate listeners and accept connections
    621       1.1  gdamore  * that are wanted.
    622       1.1  gdamore  */
    623       1.1  gdamore static void
    624       1.1  gdamore hci_event_con_req(struct hci_unit *unit, struct mbuf *m)
    625       1.1  gdamore {
    626       1.1  gdamore 	hci_con_req_ep ep;
    627       1.1  gdamore 	hci_accept_con_cp ap;
    628       1.1  gdamore 	hci_reject_con_cp rp;
    629       1.1  gdamore 	struct hci_link *link;
    630       1.1  gdamore 
    631       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    632       1.1  gdamore 	m_copydata(m, 0, sizeof(ep), &ep);
    633       1.1  gdamore 	m_adj(m, sizeof(ep));
    634       1.1  gdamore 
    635       1.1  gdamore 	DPRINTFN(1, "bdaddr %2.2x:%2.2x:%2.2x:%2.2x:%2.2x:%2.2x "
    636       1.1  gdamore 		"class %2.2x%2.2x%2.2x type %s\n",
    637       1.1  gdamore 		ep.bdaddr.b[5], ep.bdaddr.b[4], ep.bdaddr.b[3],
    638       1.1  gdamore 		ep.bdaddr.b[2], ep.bdaddr.b[1], ep.bdaddr.b[0],
    639       1.1  gdamore 		ep.uclass[0], ep.uclass[1], ep.uclass[2],
    640       1.1  gdamore 		ep.link_type == HCI_LINK_ACL ? "ACL" : "SCO");
    641       1.1  gdamore 
    642       1.1  gdamore 	if (ep.link_type == HCI_LINK_ACL)
    643       1.1  gdamore 		link = hci_acl_newconn(unit, &ep.bdaddr);
    644       1.1  gdamore 	else
    645       1.1  gdamore 		link = hci_sco_newconn(unit, &ep.bdaddr);
    646       1.1  gdamore 
    647       1.1  gdamore 	if (link == NULL) {
    648       1.1  gdamore 		memset(&rp, 0, sizeof(rp));
    649       1.1  gdamore 		bdaddr_copy(&rp.bdaddr, &ep.bdaddr);
    650       1.1  gdamore 		rp.reason = 0x0f;	/* Unacceptable BD_ADDR */
    651       1.1  gdamore 
    652       1.1  gdamore 		hci_send_cmd(unit, HCI_CMD_REJECT_CON, &rp, sizeof(rp));
    653       1.1  gdamore 	} else {
    654       1.1  gdamore 		memset(&ap, 0, sizeof(ap));
    655       1.1  gdamore 		bdaddr_copy(&ap.bdaddr, &ep.bdaddr);
    656       1.1  gdamore 		if (unit->hci_link_policy & HCI_LINK_POLICY_ENABLE_ROLE_SWITCH)
    657       1.1  gdamore 			ap.role = HCI_ROLE_MASTER;
    658       1.1  gdamore 		else
    659       1.1  gdamore 			ap.role = HCI_ROLE_SLAVE;
    660       1.1  gdamore 
    661       1.1  gdamore 		hci_send_cmd(unit, HCI_CMD_ACCEPT_CON, &ap, sizeof(ap));
    662       1.1  gdamore 	}
    663       1.1  gdamore }
    664       1.1  gdamore 
    665       1.1  gdamore /*
    666       1.6   plunky  * Auth Complete
    667       1.6   plunky  *
    668       1.6   plunky  * Authentication has been completed on an ACL link. We can notify the
    669       1.6   plunky  * upper layer protocols unless further mode changes are pending.
    670       1.6   plunky  */
    671       1.6   plunky static void
    672       1.6   plunky hci_event_auth_compl(struct hci_unit *unit, struct mbuf *m)
    673       1.6   plunky {
    674       1.6   plunky 	hci_auth_compl_ep ep;
    675       1.6   plunky 	struct hci_link *link;
    676       1.6   plunky 	int err;
    677       1.6   plunky 
    678       1.6   plunky 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    679       1.6   plunky 	m_copydata(m, 0, sizeof(ep), &ep);
    680       1.6   plunky 	m_adj(m, sizeof(ep));
    681       1.6   plunky 
    682       1.6   plunky 	ep.con_handle = HCI_CON_HANDLE(le16toh(ep.con_handle));
    683       1.6   plunky 
    684       1.6   plunky 	DPRINTFN(1, "handle #%d, status=0x%x\n", ep.con_handle, ep.status);
    685       1.6   plunky 
    686       1.6   plunky 	link = hci_link_lookup_handle(unit, ep.con_handle);
    687       1.6   plunky 	if (link == NULL || link->hl_type != HCI_LINK_ACL)
    688       1.6   plunky 		return;
    689       1.6   plunky 
    690       1.6   plunky 	if (ep.status == 0) {
    691       1.6   plunky 		link->hl_flags |= HCI_LINK_AUTH;
    692       1.6   plunky 
    693       1.6   plunky 		if (link->hl_state == HCI_LINK_WAIT_AUTH)
    694       1.6   plunky 			link->hl_state = HCI_LINK_OPEN;
    695       1.6   plunky 
    696       1.6   plunky 		err = hci_acl_setmode(link);
    697       1.6   plunky 		if (err == EINPROGRESS)
    698       1.6   plunky 			return;
    699       1.6   plunky 	}
    700       1.6   plunky 
    701       1.6   plunky 	hci_acl_linkmode(link);
    702       1.6   plunky }
    703       1.6   plunky 
    704       1.6   plunky /*
    705       1.6   plunky  * Encryption Change
    706       1.6   plunky  *
    707       1.6   plunky  * The encryption status has changed. Basically, we note the change
    708       1.6   plunky  * then notify the upper layer protocol unless further mode changes
    709       1.6   plunky  * are pending.
    710       1.6   plunky  * Note that if encryption gets disabled when it has been requested,
    711       1.6   plunky  * we will attempt to enable it again.. (its a feature not a bug :)
    712       1.6   plunky  */
    713       1.6   plunky static void
    714       1.6   plunky hci_event_encryption_change(struct hci_unit *unit, struct mbuf *m)
    715       1.6   plunky {
    716       1.6   plunky 	hci_encryption_change_ep ep;
    717       1.6   plunky 	struct hci_link *link;
    718       1.6   plunky 	int err;
    719       1.6   plunky 
    720       1.6   plunky 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    721       1.6   plunky 	m_copydata(m, 0, sizeof(ep), &ep);
    722       1.6   plunky 	m_adj(m, sizeof(ep));
    723       1.6   plunky 
    724       1.6   plunky 	ep.con_handle = HCI_CON_HANDLE(le16toh(ep.con_handle));
    725       1.6   plunky 
    726       1.6   plunky 	DPRINTFN(1, "handle #%d, status=0x%x, encryption_enable=0x%x\n",
    727       1.6   plunky 		 ep.con_handle, ep.status, ep.encryption_enable);
    728       1.6   plunky 
    729       1.6   plunky 	link = hci_link_lookup_handle(unit, ep.con_handle);
    730       1.6   plunky 	if (link == NULL || link->hl_type != HCI_LINK_ACL)
    731       1.6   plunky 		return;
    732       1.6   plunky 
    733       1.6   plunky 	if (ep.status == 0) {
    734       1.6   plunky 		if (ep.encryption_enable == 0)
    735       1.6   plunky 			link->hl_flags &= ~HCI_LINK_ENCRYPT;
    736       1.6   plunky 		else
    737       1.6   plunky 			link->hl_flags |= (HCI_LINK_AUTH | HCI_LINK_ENCRYPT);
    738       1.6   plunky 
    739       1.6   plunky 		if (link->hl_state == HCI_LINK_WAIT_ENCRYPT)
    740       1.6   plunky 			link->hl_state = HCI_LINK_OPEN;
    741       1.6   plunky 
    742       1.6   plunky 		err = hci_acl_setmode(link);
    743       1.6   plunky 		if (err == EINPROGRESS)
    744       1.6   plunky 			return;
    745       1.6   plunky 	}
    746       1.6   plunky 
    747       1.6   plunky 	hci_acl_linkmode(link);
    748       1.6   plunky }
    749       1.6   plunky 
    750       1.6   plunky /*
    751       1.6   plunky  * Change Connection Link Key Complete
    752       1.6   plunky  *
    753       1.6   plunky  * Link keys are handled in userland but if we are waiting to secure
    754       1.6   plunky  * this link, we should notify the upper protocols. A SECURE request
    755       1.6   plunky  * only needs a single key change, so we can cancel the request.
    756       1.6   plunky  */
    757       1.6   plunky static void
    758       1.6   plunky hci_event_change_con_link_key_compl(struct hci_unit *unit, struct mbuf *m)
    759       1.6   plunky {
    760       1.6   plunky 	hci_change_con_link_key_compl_ep ep;
    761       1.6   plunky 	struct hci_link *link;
    762       1.6   plunky 	int err;
    763       1.6   plunky 
    764       1.6   plunky 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    765       1.6   plunky 	m_copydata(m, 0, sizeof(ep), &ep);
    766       1.6   plunky 	m_adj(m, sizeof(ep));
    767       1.6   plunky 
    768       1.6   plunky 	ep.con_handle = HCI_CON_HANDLE(le16toh(ep.con_handle));
    769       1.6   plunky 
    770       1.6   plunky 	DPRINTFN(1, "handle #%d, status=0x%x\n", ep.con_handle, ep.status);
    771       1.6   plunky 
    772       1.6   plunky 	link = hci_link_lookup_handle(unit, ep.con_handle);
    773       1.6   plunky 	if (link == NULL || link->hl_type != HCI_LINK_ACL)
    774       1.6   plunky 		return;
    775       1.6   plunky 
    776       1.6   plunky 	link->hl_flags &= ~HCI_LINK_SECURE_REQ;
    777       1.6   plunky 
    778       1.6   plunky 	if (ep.status == 0) {
    779       1.6   plunky 		link->hl_flags |= (HCI_LINK_AUTH | HCI_LINK_SECURE);
    780       1.6   plunky 
    781       1.6   plunky 		if (link->hl_state == HCI_LINK_WAIT_SECURE)
    782       1.6   plunky 			link->hl_state = HCI_LINK_OPEN;
    783       1.6   plunky 
    784       1.6   plunky 		err = hci_acl_setmode(link);
    785       1.6   plunky 		if (err == EINPROGRESS)
    786       1.6   plunky 			return;
    787       1.6   plunky 	}
    788       1.6   plunky 
    789       1.6   plunky 	hci_acl_linkmode(link);
    790       1.6   plunky }
    791       1.6   plunky 
    792       1.6   plunky /*
    793       1.9   plunky  * Read Clock Offset Complete
    794       1.9   plunky  *
    795       1.9   plunky  * We keep a note of the clock offset of remote devices when a
    796       1.9   plunky  * link is made, in order to facilitate reconnections to the device
    797       1.9   plunky  */
    798       1.9   plunky static void
    799       1.9   plunky hci_event_read_clock_offset_compl(struct hci_unit *unit, struct mbuf *m)
    800       1.9   plunky {
    801       1.9   plunky 	hci_read_clock_offset_compl_ep ep;
    802       1.9   plunky 	struct hci_link *link;
    803       1.9   plunky 
    804       1.9   plunky 	KASSERT(m->m_pkthdr.len >= sizeof(ep));
    805       1.9   plunky 	m_copydata(m, 0, sizeof(ep), &ep);
    806       1.9   plunky 	m_adj(m, sizeof(ep));
    807       1.9   plunky 
    808       1.9   plunky 	DPRINTFN(1, "handle #%d, offset=%u, status=0x%x\n",
    809       1.9   plunky 		le16toh(ep.con_handle), le16toh(ep.clock_offset), ep.status);
    810       1.9   plunky 
    811       1.9   plunky 	ep.con_handle = HCI_CON_HANDLE(le16toh(ep.con_handle));
    812       1.9   plunky 	link = hci_link_lookup_handle(unit, ep.con_handle);
    813       1.9   plunky 
    814       1.9   plunky 	if (ep.status != 0 || link == NULL)
    815       1.9   plunky 		return;
    816       1.9   plunky 
    817       1.9   plunky 	link->hl_clock = ep.clock_offset;
    818       1.9   plunky }
    819       1.9   plunky 
    820       1.9   plunky /*
    821       1.1  gdamore  * process results of read_bdaddr command_complete event
    822       1.1  gdamore  */
    823       1.1  gdamore static void
    824       1.1  gdamore hci_cmd_read_bdaddr(struct hci_unit *unit, struct mbuf *m)
    825       1.1  gdamore {
    826       1.1  gdamore 	hci_read_bdaddr_rp rp;
    827       1.1  gdamore 
    828       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(rp));
    829       1.1  gdamore 	m_copydata(m, 0, sizeof(rp), &rp);
    830       1.1  gdamore 	m_adj(m, sizeof(rp));
    831       1.1  gdamore 
    832       1.1  gdamore 	if (rp.status > 0)
    833       1.1  gdamore 		return;
    834       1.1  gdamore 
    835       1.1  gdamore 	if ((unit->hci_flags & BTF_INIT_BDADDR) == 0)
    836       1.1  gdamore 		return;
    837       1.1  gdamore 
    838       1.1  gdamore 	bdaddr_copy(&unit->hci_bdaddr, &rp.bdaddr);
    839       1.1  gdamore 
    840       1.1  gdamore 	unit->hci_flags &= ~BTF_INIT_BDADDR;
    841       1.1  gdamore 
    842       1.1  gdamore 	wakeup(unit);
    843       1.1  gdamore }
    844       1.1  gdamore 
    845       1.1  gdamore /*
    846       1.1  gdamore  * process results of read_buffer_size command_complete event
    847       1.1  gdamore  */
    848       1.1  gdamore static void
    849       1.1  gdamore hci_cmd_read_buffer_size(struct hci_unit *unit, struct mbuf *m)
    850       1.1  gdamore {
    851       1.1  gdamore 	hci_read_buffer_size_rp rp;
    852       1.1  gdamore 
    853       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(rp));
    854       1.1  gdamore 	m_copydata(m, 0, sizeof(rp), &rp);
    855       1.1  gdamore 	m_adj(m, sizeof(rp));
    856       1.1  gdamore 
    857       1.1  gdamore 	if (rp.status > 0)
    858       1.1  gdamore 		return;
    859       1.1  gdamore 
    860       1.1  gdamore 	if ((unit->hci_flags & BTF_INIT_BUFFER_SIZE) == 0)
    861       1.1  gdamore 		return;
    862       1.1  gdamore 
    863       1.1  gdamore 	unit->hci_max_acl_size = le16toh(rp.max_acl_size);
    864       1.1  gdamore 	unit->hci_num_acl_pkts = le16toh(rp.num_acl_pkts);
    865       1.1  gdamore 	unit->hci_max_sco_size = rp.max_sco_size;
    866       1.1  gdamore 	unit->hci_num_sco_pkts = le16toh(rp.num_sco_pkts);
    867       1.1  gdamore 
    868       1.1  gdamore 	unit->hci_flags &= ~BTF_INIT_BUFFER_SIZE;
    869       1.1  gdamore 
    870       1.1  gdamore 	wakeup(unit);
    871       1.1  gdamore }
    872       1.1  gdamore 
    873       1.1  gdamore /*
    874       1.1  gdamore  * process results of read_local_features command_complete event
    875       1.1  gdamore  */
    876       1.1  gdamore static void
    877       1.1  gdamore hci_cmd_read_local_features(struct hci_unit *unit, struct mbuf *m)
    878       1.1  gdamore {
    879       1.1  gdamore 	hci_read_local_features_rp rp;
    880       1.1  gdamore 
    881       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(rp));
    882       1.1  gdamore 	m_copydata(m, 0, sizeof(rp), &rp);
    883       1.1  gdamore 	m_adj(m, sizeof(rp));
    884       1.1  gdamore 
    885       1.1  gdamore 	if (rp.status > 0)
    886       1.1  gdamore 		return;
    887       1.1  gdamore 
    888       1.1  gdamore 	if ((unit->hci_flags & BTF_INIT_FEATURES) == 0)
    889       1.1  gdamore 		return;
    890       1.1  gdamore 
    891       1.1  gdamore 	unit->hci_lmp_mask = 0;
    892       1.1  gdamore 
    893       1.1  gdamore 	if (rp.features[0] & HCI_LMP_ROLE_SWITCH)
    894       1.1  gdamore 		unit->hci_lmp_mask |= HCI_LINK_POLICY_ENABLE_ROLE_SWITCH;
    895       1.1  gdamore 
    896       1.1  gdamore 	if (rp.features[0] & HCI_LMP_HOLD_MODE)
    897       1.1  gdamore 		unit->hci_lmp_mask |= HCI_LINK_POLICY_ENABLE_HOLD_MODE;
    898       1.1  gdamore 
    899       1.1  gdamore 	if (rp.features[0] & HCI_LMP_SNIFF_MODE)
    900       1.1  gdamore 		unit->hci_lmp_mask |= HCI_LINK_POLICY_ENABLE_SNIFF_MODE;
    901       1.1  gdamore 
    902       1.1  gdamore 	if (rp.features[1] & HCI_LMP_PARK_MODE)
    903       1.1  gdamore 		unit->hci_lmp_mask |= HCI_LINK_POLICY_ENABLE_PARK_MODE;
    904       1.1  gdamore 
    905       1.1  gdamore 	/* ACL packet mask */
    906       1.1  gdamore 	unit->hci_acl_mask = HCI_PKT_DM1 | HCI_PKT_DH1;
    907       1.1  gdamore 
    908       1.1  gdamore 	if (rp.features[0] & HCI_LMP_3SLOT)
    909       1.1  gdamore 		unit->hci_acl_mask |= HCI_PKT_DM3 | HCI_PKT_DH3;
    910       1.1  gdamore 
    911       1.1  gdamore 	if (rp.features[0] & HCI_LMP_5SLOT)
    912       1.1  gdamore 		unit->hci_acl_mask |= HCI_PKT_DM5 | HCI_PKT_DH5;
    913       1.1  gdamore 
    914       1.1  gdamore 	if ((rp.features[3] & HCI_LMP_EDR_ACL_2MBPS) == 0)
    915       1.1  gdamore 		unit->hci_acl_mask |= HCI_PKT_2MBPS_DH1
    916       1.1  gdamore 				    | HCI_PKT_2MBPS_DH3
    917       1.1  gdamore 				    | HCI_PKT_2MBPS_DH5;
    918       1.1  gdamore 
    919       1.1  gdamore 	if ((rp.features[3] & HCI_LMP_EDR_ACL_3MBPS) == 0)
    920       1.1  gdamore 		unit->hci_acl_mask |= HCI_PKT_3MBPS_DH1
    921       1.1  gdamore 				    | HCI_PKT_3MBPS_DH3
    922       1.1  gdamore 				    | HCI_PKT_3MBPS_DH5;
    923       1.1  gdamore 
    924       1.1  gdamore 	if ((rp.features[4] & HCI_LMP_3SLOT_EDR_ACL) == 0)
    925       1.1  gdamore 		unit->hci_acl_mask |= HCI_PKT_2MBPS_DH3
    926       1.1  gdamore 				    | HCI_PKT_3MBPS_DH3;
    927       1.1  gdamore 
    928       1.1  gdamore 	if ((rp.features[5] & HCI_LMP_5SLOT_EDR_ACL) == 0)
    929       1.1  gdamore 		unit->hci_acl_mask |= HCI_PKT_2MBPS_DH5
    930       1.1  gdamore 				    | HCI_PKT_3MBPS_DH5;
    931       1.1  gdamore 
    932       1.1  gdamore 	unit->hci_packet_type = unit->hci_acl_mask;
    933       1.1  gdamore 
    934       1.1  gdamore 	/* SCO packet mask */
    935       1.1  gdamore 	unit->hci_sco_mask = 0;
    936       1.1  gdamore 	if (rp.features[1] & HCI_LMP_SCO_LINK)
    937       1.1  gdamore 		unit->hci_sco_mask |= HCI_PKT_HV1;
    938       1.1  gdamore 
    939       1.1  gdamore 	if (rp.features[1] & HCI_LMP_HV2_PKT)
    940       1.1  gdamore 		unit->hci_sco_mask |= HCI_PKT_HV2;
    941       1.1  gdamore 
    942       1.1  gdamore 	if (rp.features[1] & HCI_LMP_HV3_PKT)
    943       1.1  gdamore 		unit->hci_sco_mask |= HCI_PKT_HV3;
    944       1.1  gdamore 
    945       1.1  gdamore 	if (rp.features[3] & HCI_LMP_EV3_PKT)
    946       1.1  gdamore 		unit->hci_sco_mask |= HCI_PKT_EV3;
    947       1.1  gdamore 
    948       1.1  gdamore 	if (rp.features[4] & HCI_LMP_EV4_PKT)
    949       1.1  gdamore 		unit->hci_sco_mask |= HCI_PKT_EV4;
    950       1.1  gdamore 
    951       1.1  gdamore 	if (rp.features[4] & HCI_LMP_EV5_PKT)
    952       1.1  gdamore 		unit->hci_sco_mask |= HCI_PKT_EV5;
    953       1.1  gdamore 
    954       1.4   plunky 	/* XXX what do 2MBPS/3MBPS/3SLOT eSCO mean? */
    955       1.1  gdamore 
    956       1.1  gdamore 	unit->hci_flags &= ~BTF_INIT_FEATURES;
    957       1.1  gdamore 
    958       1.1  gdamore 	wakeup(unit);
    959       1.1  gdamore 
    960       1.1  gdamore 	DPRINTFN(1, "%s: lmp_mask %4.4x, acl_mask %4.4x, sco_mask %4.4x\n",
    961      1.10   plunky 		device_xname(unit->hci_dev), unit->hci_lmp_mask,
    962       1.1  gdamore 		unit->hci_acl_mask, unit->hci_sco_mask);
    963       1.1  gdamore }
    964       1.1  gdamore 
    965       1.1  gdamore /*
    966      1.13   plunky  * process results of read_local_ver command_complete event
    967      1.13   plunky  *
    968      1.13   plunky  * reading local supported commands is only supported from 1.2 spec
    969      1.13   plunky  */
    970      1.13   plunky static void
    971      1.13   plunky hci_cmd_read_local_ver(struct hci_unit *unit, struct mbuf *m)
    972      1.13   plunky {
    973      1.13   plunky 	hci_read_local_ver_rp rp;
    974      1.13   plunky 
    975      1.13   plunky 	KASSERT(m->m_pkthdr.len >= sizeof(rp));
    976      1.13   plunky 	m_copydata(m, 0, sizeof(rp), &rp);
    977      1.13   plunky 	m_adj(m, sizeof(rp));
    978      1.13   plunky 
    979      1.13   plunky 	if (rp.status != 0)
    980      1.13   plunky 		return;
    981      1.13   plunky 
    982      1.13   plunky 	if ((unit->hci_flags & BTF_INIT_COMMANDS) == 0)
    983      1.13   plunky 		return;
    984      1.13   plunky 
    985      1.13   plunky 	if (rp.hci_version < HCI_SPEC_V12) {
    986      1.13   plunky 		unit->hci_flags &= ~BTF_INIT_COMMANDS;
    987      1.13   plunky 		wakeup(unit);
    988      1.13   plunky 		return;
    989      1.13   plunky 	}
    990      1.13   plunky 
    991      1.13   plunky 	hci_send_cmd(unit, HCI_CMD_READ_LOCAL_COMMANDS, NULL, 0);
    992      1.13   plunky }
    993      1.13   plunky 
    994      1.13   plunky /*
    995      1.13   plunky  * process results of read_local_commands command_complete event
    996      1.13   plunky  */
    997      1.13   plunky static void
    998      1.13   plunky hci_cmd_read_local_commands(struct hci_unit *unit, struct mbuf *m)
    999      1.13   plunky {
   1000      1.13   plunky 	hci_read_local_commands_rp rp;
   1001      1.13   plunky 
   1002      1.13   plunky 	KASSERT(m->m_pkthdr.len >= sizeof(rp));
   1003      1.13   plunky 	m_copydata(m, 0, sizeof(rp), &rp);
   1004      1.13   plunky 	m_adj(m, sizeof(rp));
   1005      1.13   plunky 
   1006      1.13   plunky 	if (rp.status != 0)
   1007      1.13   plunky 		return;
   1008      1.13   plunky 
   1009      1.13   plunky 	if ((unit->hci_flags & BTF_INIT_COMMANDS) == 0)
   1010      1.13   plunky 		return;
   1011      1.13   plunky 
   1012      1.13   plunky 	unit->hci_flags &= ~BTF_INIT_COMMANDS;
   1013      1.13   plunky 	memcpy(unit->hci_cmds, rp.commands, HCI_COMMANDS_SIZE);
   1014      1.13   plunky 
   1015      1.13   plunky 	wakeup(unit);
   1016      1.13   plunky }
   1017      1.13   plunky 
   1018      1.13   plunky /*
   1019       1.1  gdamore  * process results of reset command_complete event
   1020       1.1  gdamore  *
   1021       1.1  gdamore  * This has killed all the connections, so close down anything we have left,
   1022       1.1  gdamore  * and reinitialise the unit.
   1023       1.1  gdamore  */
   1024       1.1  gdamore static void
   1025       1.1  gdamore hci_cmd_reset(struct hci_unit *unit, struct mbuf *m)
   1026       1.1  gdamore {
   1027       1.1  gdamore 	hci_reset_rp rp;
   1028       1.1  gdamore 	struct hci_link *link, *next;
   1029       1.1  gdamore 	int acl;
   1030       1.1  gdamore 
   1031       1.1  gdamore 	KASSERT(m->m_pkthdr.len >= sizeof(rp));
   1032       1.1  gdamore 	m_copydata(m, 0, sizeof(rp), &rp);
   1033       1.1  gdamore 	m_adj(m, sizeof(rp));
   1034       1.1  gdamore 
   1035       1.1  gdamore 	if (rp.status != 0)
   1036       1.1  gdamore 		return;
   1037       1.1  gdamore 
   1038       1.1  gdamore 	/*
   1039       1.1  gdamore 	 * release SCO links first, since they may be holding
   1040       1.1  gdamore 	 * an ACL link reference.
   1041       1.1  gdamore 	 */
   1042       1.1  gdamore 	for (acl = 0 ; acl < 2 ; acl++) {
   1043       1.1  gdamore 		next = TAILQ_FIRST(&unit->hci_links);
   1044       1.1  gdamore 		while ((link = next) != NULL) {
   1045       1.1  gdamore 			next = TAILQ_NEXT(link, hl_next);
   1046       1.1  gdamore 			if (acl || link->hl_type != HCI_LINK_ACL)
   1047       1.1  gdamore 				hci_link_free(link, ECONNABORTED);
   1048       1.1  gdamore 		}
   1049       1.1  gdamore 	}
   1050       1.1  gdamore 
   1051       1.1  gdamore 	unit->hci_num_acl_pkts = 0;
   1052       1.1  gdamore 	unit->hci_num_sco_pkts = 0;
   1053       1.1  gdamore 
   1054       1.1  gdamore 	if (hci_send_cmd(unit, HCI_CMD_READ_BDADDR, NULL, 0))
   1055       1.1  gdamore 		return;
   1056       1.1  gdamore 
   1057       1.1  gdamore 	if (hci_send_cmd(unit, HCI_CMD_READ_BUFFER_SIZE, NULL, 0))
   1058       1.1  gdamore 		return;
   1059       1.1  gdamore 
   1060       1.1  gdamore 	if (hci_send_cmd(unit, HCI_CMD_READ_LOCAL_FEATURES, NULL, 0))
   1061       1.1  gdamore 		return;
   1062      1.13   plunky 
   1063      1.13   plunky 	if (hci_send_cmd(unit, HCI_CMD_READ_LOCAL_VER, NULL, 0))
   1064      1.13   plunky 		return;
   1065       1.1  gdamore }
   1066  1.14.6.1      mjf 
   1067  1.14.6.1      mjf /*
   1068  1.14.6.1      mjf  * process command_status event for create_con command
   1069  1.14.6.1      mjf  *
   1070  1.14.6.1      mjf  * a "Create Connection" command can sometimes fail to start for whatever
   1071  1.14.6.1      mjf  * reason and the command_status event returns failure but we get no
   1072  1.14.6.1      mjf  * indication of which connection failed (for instance in the case where
   1073  1.14.6.1      mjf  * we tried to open too many connections all at once) So, we keep a flag
   1074  1.14.6.1      mjf  * on the link to indicate pending status until the command_status event
   1075  1.14.6.1      mjf  * is returned to help us decide which needs to be failed.
   1076  1.14.6.1      mjf  *
   1077  1.14.6.1      mjf  * since created links are inserted at the tail of hci_links, we know that
   1078  1.14.6.1      mjf  * the first pending link we find will be the one that this command status
   1079  1.14.6.1      mjf  * refers to.
   1080  1.14.6.1      mjf  */
   1081  1.14.6.1      mjf static void
   1082  1.14.6.1      mjf hci_cmd_create_con(struct hci_unit *unit, uint8_t status)
   1083  1.14.6.1      mjf {
   1084  1.14.6.1      mjf 	struct hci_link *link;
   1085  1.14.6.1      mjf 
   1086  1.14.6.1      mjf 	TAILQ_FOREACH(link, &unit->hci_links, hl_next) {
   1087  1.14.6.1      mjf 		if ((link->hl_flags & HCI_LINK_CREATE_CON) == 0)
   1088  1.14.6.1      mjf 			continue;
   1089  1.14.6.1      mjf 
   1090  1.14.6.1      mjf 		link->hl_flags &= ~HCI_LINK_CREATE_CON;
   1091  1.14.6.1      mjf 
   1092  1.14.6.1      mjf 		switch(status) {
   1093  1.14.6.1      mjf 		case 0x00:	/* success */
   1094  1.14.6.1      mjf 			break;
   1095  1.14.6.1      mjf 
   1096  1.14.6.1      mjf 		case 0x0c:	/* "Command Disallowed" */
   1097  1.14.6.1      mjf 			hci_link_free(link, EBUSY);
   1098  1.14.6.1      mjf 			break;
   1099  1.14.6.1      mjf 
   1100  1.14.6.1      mjf 		default:	/* some other trouble */
   1101  1.14.6.1      mjf 			hci_link_free(link, EPROTO);
   1102  1.14.6.1      mjf 			break;
   1103  1.14.6.1      mjf 		}
   1104  1.14.6.1      mjf 
   1105  1.14.6.1      mjf 		return;
   1106  1.14.6.1      mjf 	}
   1107  1.14.6.1      mjf }
   1108