• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * windows backend for libusb 1.0
3  * Copyright © 2009-2012 Pete Batard <pete@akeo.ie>
4  * Copyright © 2016-2018 Chris Dickens <christopher.a.dickens@gmail.com>
5  * With contributions from Michael Plante, Orin Eman et al.
6  * Parts of this code adapted from libusb-win32-v1 by Stephan Meyer
7  * HID Reports IOCTLs inspired from HIDAPI by Alan Ott, Signal 11 Software
8  * Hash table functions adapted from glibc, by Ulrich Drepper et al.
9  * Major code testing contribution by Xiaofan Chen
10  *
11  * This library is free software; you can redistribute it and/or
12  * modify it under the terms of the GNU Lesser General Public
13  * License as published by the Free Software Foundation; either
14  * version 2.1 of the License, or (at your option) any later version.
15  *
16  * This library is distributed in the hope that it will be useful,
17  * but WITHOUT ANY WARRANTY; without even the implied warranty of
18  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
19  * Lesser General Public License for more details.
20  *
21  * You should have received a copy of the GNU Lesser General Public
22  * License along with this library; if not, write to the Free Software
23  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
24  */
25 
26 #include <config.h>
27 
28 #include <windows.h>
29 #include <setupapi.h>
30 #include <ctype.h>
31 #include <stdio.h>
32 
33 #include "libusbi.h"
34 #include "windows_winusb.h"
35 
36 #define HANDLE_VALID(h) (((h) != NULL) && ((h) != INVALID_HANDLE_VALUE))
37 
38 // The below macro is used in conjunction with safe loops.
39 #define LOOP_BREAK(err)				\
40 	{					\
41 		r = err;			\
42 		continue;			\
43 	}
44 
45 // WinUSB-like API prototypes
46 static bool winusbx_init(struct libusb_context *ctx);
47 static void winusbx_exit(void);
48 static int winusbx_open(int sub_api, struct libusb_device_handle *dev_handle);
49 static void winusbx_close(int sub_api, struct libusb_device_handle *dev_handle);
50 static int winusbx_configure_endpoints(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface);
51 static int winusbx_claim_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface);
52 static int winusbx_release_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface);
53 static int winusbx_submit_control_transfer(int sub_api, struct usbi_transfer *itransfer);
54 static int winusbx_set_interface_altsetting(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface, uint8_t altsetting);
55 static int winusbx_submit_iso_transfer(int sub_api, struct usbi_transfer *itransfer);
56 static int winusbx_submit_bulk_transfer(int sub_api, struct usbi_transfer *itransfer);
57 static int winusbx_clear_halt(int sub_api, struct libusb_device_handle *dev_handle, unsigned char endpoint);
58 static int winusbx_cancel_transfer(int sub_api, struct usbi_transfer *itransfer);
59 static int winusbx_reset_device(int sub_api, struct libusb_device_handle *dev_handle);
60 static enum libusb_transfer_status winusbx_copy_transfer_data(int sub_api, struct usbi_transfer *itransfer, DWORD length);
61 // HID API prototypes
62 static bool hid_init(struct libusb_context *ctx);
63 static void hid_exit(void);
64 static int hid_open(int sub_api, struct libusb_device_handle *dev_handle);
65 static void hid_close(int sub_api, struct libusb_device_handle *dev_handle);
66 static int hid_claim_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface);
67 static int hid_release_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface);
68 static int hid_set_interface_altsetting(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface, uint8_t altsetting);
69 static int hid_submit_control_transfer(int sub_api, struct usbi_transfer *itransfer);
70 static int hid_submit_bulk_transfer(int sub_api, struct usbi_transfer *itransfer);
71 static int hid_clear_halt(int sub_api, struct libusb_device_handle *dev_handle, unsigned char endpoint);
72 static int hid_reset_device(int sub_api, struct libusb_device_handle *dev_handle);
73 static enum libusb_transfer_status hid_copy_transfer_data(int sub_api, struct usbi_transfer *itransfer, DWORD length);
74 // Composite API prototypes
75 static int composite_open(int sub_api, struct libusb_device_handle *dev_handle);
76 static void composite_close(int sub_api, struct libusb_device_handle *dev_handle);
77 static int composite_claim_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface);
78 static int composite_set_interface_altsetting(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface, uint8_t altsetting);
79 static int composite_release_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface);
80 static int composite_submit_control_transfer(int sub_api, struct usbi_transfer *itransfer);
81 static int composite_submit_bulk_transfer(int sub_api, struct usbi_transfer *itransfer);
82 static int composite_submit_iso_transfer(int sub_api, struct usbi_transfer *itransfer);
83 static int composite_clear_halt(int sub_api, struct libusb_device_handle *dev_handle, unsigned char endpoint);
84 static int composite_cancel_transfer(int sub_api, struct usbi_transfer *itransfer);
85 static int composite_reset_device(int sub_api, struct libusb_device_handle *dev_handle);
86 static enum libusb_transfer_status composite_copy_transfer_data(int sub_api, struct usbi_transfer *itransfer, DWORD length);
87 
88 static usbi_mutex_t autoclaim_lock;
89 
90 // API globals
91 static struct winusb_interface WinUSBX[SUB_API_MAX];
92 #define CHECK_WINUSBX_AVAILABLE(sub_api)		\
93 	do {						\
94 		if (sub_api == SUB_API_NOTSET)		\
95 			sub_api = priv->sub_api;	\
96 		if (WinUSBX[sub_api].hDll == NULL)	\
97 			return LIBUSB_ERROR_ACCESS;	\
98 	} while (0)
99 
100 #define CHECK_HID_AVAILABLE				\
101 	do {						\
102 		if (DLL_HANDLE_NAME(hid) == NULL)	\
103 			return LIBUSB_ERROR_ACCESS;	\
104 	} while (0)
105 
106 #if defined(ENABLE_LOGGING)
guid_to_string(const GUID * guid,char guid_string[MAX_GUID_STRING_LENGTH])107 static const char *guid_to_string(const GUID *guid, char guid_string[MAX_GUID_STRING_LENGTH])
108 {
109 	if (guid == NULL) {
110 		guid_string[0] = '\0';
111 		return guid_string;
112 	}
113 
114 	sprintf(guid_string, "{%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}",
115 		(unsigned int)guid->Data1, guid->Data2, guid->Data3,
116 		guid->Data4[0], guid->Data4[1], guid->Data4[2], guid->Data4[3],
117 		guid->Data4[4], guid->Data4[5], guid->Data4[6], guid->Data4[7]);
118 
119 	return guid_string;
120 }
121 #endif
122 
string_to_guid(const char guid_string[MAX_GUID_STRING_LENGTH],GUID * guid)123 static bool string_to_guid(const char guid_string[MAX_GUID_STRING_LENGTH], GUID *guid)
124 {
125 	unsigned short tmp[4];
126 	int num_chars = -1;
127 	char extra;
128 	int r;
129 
130 	// Unfortunately MinGW complains that '%hhx' is not a valid format specifier,
131 	// even though Visual Studio 2013 and later support it. Rather than complicating
132 	// the logic in this function with '#ifdef's, use a temporary array on the stack
133 	// to store the conversions.
134 	r = sscanf(guid_string, "{%8x-%4hx-%4hx-%4hx-%4hx%4hx%4hx}%n%c",
135 		(unsigned int *)&guid->Data1, &guid->Data2, &guid->Data3,
136 		&tmp[0], &tmp[1], &tmp[2], &tmp[3], &num_chars, &extra);
137 
138 	if ((r != 7) || (num_chars != 38))
139 		return false;
140 
141 	// Extract the bytes from the 2-byte shorts
142 	guid->Data4[0] = (unsigned char)((tmp[0] >> 8) & 0xFF);
143 	guid->Data4[1] = (unsigned char)(tmp[0] & 0xFF);
144 	guid->Data4[2] = (unsigned char)((tmp[1] >> 8) & 0xFF);
145 	guid->Data4[3] = (unsigned char)(tmp[1] & 0xFF);
146 	guid->Data4[4] = (unsigned char)((tmp[2] >> 8) & 0xFF);
147 	guid->Data4[5] = (unsigned char)(tmp[2] & 0xFF);
148 	guid->Data4[6] = (unsigned char)((tmp[3] >> 8) & 0xFF);
149 	guid->Data4[7] = (unsigned char)(tmp[3] & 0xFF);
150 
151 	return true;
152 }
153 
154 /*
155  * Normalize Microsoft's paths: return a duplicate of the given path
156  * with all characters converted to uppercase
157  */
normalize_path(const char * path)158 static char *normalize_path(const char *path)
159 {
160 	char *ret_path = _strdup(path);
161 	char *p;
162 
163 	if (ret_path == NULL)
164 		return NULL;
165 
166 	for (p = ret_path; *p != '\0'; p++)
167 		*p = (char)toupper((unsigned char)*p);
168 
169 	return ret_path;
170 }
171 
172 /*
173  * Cfgmgr32, AdvAPI32, OLE32 and SetupAPI DLL functions
174  */
init_dlls(struct libusb_context * ctx)175 static bool init_dlls(struct libusb_context *ctx)
176 {
177 	DLL_GET_HANDLE(ctx, Cfgmgr32);
178 	DLL_LOAD_FUNC(Cfgmgr32, CM_Get_Parent, true);
179 	DLL_LOAD_FUNC(Cfgmgr32, CM_Get_Child, true);
180 
181 	// Prefixed to avoid conflict with header files
182 	DLL_GET_HANDLE(ctx, AdvAPI32);
183 	DLL_LOAD_FUNC_PREFIXED(AdvAPI32, p, RegQueryValueExA, true);
184 	DLL_LOAD_FUNC_PREFIXED(AdvAPI32, p, RegCloseKey, true);
185 
186 	DLL_GET_HANDLE(ctx, SetupAPI);
187 	DLL_LOAD_FUNC_PREFIXED(SetupAPI, p, SetupDiGetClassDevsA, true);
188 	DLL_LOAD_FUNC_PREFIXED(SetupAPI, p, SetupDiEnumDeviceInfo, true);
189 	DLL_LOAD_FUNC_PREFIXED(SetupAPI, p, SetupDiEnumDeviceInterfaces, true);
190 	DLL_LOAD_FUNC_PREFIXED(SetupAPI, p, SetupDiGetDeviceInstanceIdA, true);
191 	DLL_LOAD_FUNC_PREFIXED(SetupAPI, p, SetupDiGetDeviceInterfaceDetailA, true);
192 	DLL_LOAD_FUNC_PREFIXED(SetupAPI, p, SetupDiGetDeviceRegistryPropertyA, true);
193 	DLL_LOAD_FUNC_PREFIXED(SetupAPI, p, SetupDiDestroyDeviceInfoList, true);
194 	DLL_LOAD_FUNC_PREFIXED(SetupAPI, p, SetupDiOpenDevRegKey, true);
195 	DLL_LOAD_FUNC_PREFIXED(SetupAPI, p, SetupDiOpenDeviceInterfaceRegKey, true);
196 
197 	return true;
198 }
199 
exit_dlls(void)200 static void exit_dlls(void)
201 {
202 	DLL_FREE_HANDLE(SetupAPI);
203 	DLL_FREE_HANDLE(AdvAPI32);
204 	DLL_FREE_HANDLE(Cfgmgr32);
205 }
206 
207 /*
208  * enumerate interfaces for the whole USB class
209  *
210  * Parameters:
211  * dev_info: a pointer to a dev_info list
212  * dev_info_data: a pointer to an SP_DEVINFO_DATA to be filled (or NULL if not needed)
213  * enumerator: the generic USB class for which to retrieve interface details
214  * index: zero based index of the interface in the device info list
215  *
216  * Note: it is the responsibility of the caller to free the DEVICE_INTERFACE_DETAIL_DATA
217  * structure returned and call this function repeatedly using the same guid (with an
218  * incremented index starting at zero) until all interfaces have been returned.
219  */
get_devinfo_data(struct libusb_context * ctx,HDEVINFO * dev_info,SP_DEVINFO_DATA * dev_info_data,const char * enumerator,unsigned _index)220 static bool get_devinfo_data(struct libusb_context *ctx,
221 	HDEVINFO *dev_info, SP_DEVINFO_DATA *dev_info_data, const char *enumerator, unsigned _index)
222 {
223 	if (_index == 0) {
224 		*dev_info = pSetupDiGetClassDevsA(NULL, enumerator, NULL, DIGCF_PRESENT|DIGCF_ALLCLASSES);
225 		if (*dev_info == INVALID_HANDLE_VALUE) {
226 			usbi_err(ctx, "could not obtain device info set for PnP enumerator '%s': %s",
227 				enumerator, windows_error_str(0));
228 			return false;
229 		}
230 	}
231 
232 	dev_info_data->cbSize = sizeof(SP_DEVINFO_DATA);
233 	if (!pSetupDiEnumDeviceInfo(*dev_info, _index, dev_info_data)) {
234 		if (GetLastError() != ERROR_NO_MORE_ITEMS)
235 			usbi_err(ctx, "could not obtain device info data for PnP enumerator '%s' index %u: %s",
236 				enumerator, _index, windows_error_str(0));
237 
238 		pSetupDiDestroyDeviceInfoList(*dev_info);
239 		*dev_info = INVALID_HANDLE_VALUE;
240 		return false;
241 	}
242 	return true;
243 }
244 
245 /*
246  * enumerate interfaces for a specific GUID
247  *
248  * Parameters:
249  * dev_info: a pointer to a dev_info list
250  * dev_info_data: a pointer to an SP_DEVINFO_DATA to be filled (or NULL if not needed)
251  * guid: the GUID for which to retrieve interface details
252  * index: zero based index of the interface in the device info list
253  *
254  * Note: it is the responsibility of the caller to free the DEVICE_INTERFACE_DETAIL_DATA
255  * structure returned and call this function repeatedly using the same guid (with an
256  * incremented index starting at zero) until all interfaces have been returned.
257  */
get_interface_details(struct libusb_context * ctx,HDEVINFO dev_info,PSP_DEVINFO_DATA dev_info_data,LPCGUID guid,DWORD * _index,char ** dev_interface_path)258 static int get_interface_details(struct libusb_context *ctx, HDEVINFO dev_info,
259 	PSP_DEVINFO_DATA dev_info_data, LPCGUID guid, DWORD *_index, char **dev_interface_path)
260 {
261 	SP_DEVICE_INTERFACE_DATA dev_interface_data;
262 	PSP_DEVICE_INTERFACE_DETAIL_DATA_A dev_interface_details;
263 	char guid_string[MAX_GUID_STRING_LENGTH];
264 	DWORD size;
265 
266 	dev_info_data->cbSize = sizeof(SP_DEVINFO_DATA);
267 	dev_interface_data.cbSize = sizeof(SP_DEVICE_INTERFACE_DATA);
268 	for (;;) {
269 		if (!pSetupDiEnumDeviceInfo(dev_info, *_index, dev_info_data)) {
270 			if (GetLastError() != ERROR_NO_MORE_ITEMS) {
271 				usbi_err(ctx, "Could not obtain device info data for %s index %lu: %s",
272 					guid_to_string(guid, guid_string), ULONG_CAST(*_index), windows_error_str(0));
273 				return LIBUSB_ERROR_OTHER;
274 			}
275 
276 			// No more devices
277 			return LIBUSB_SUCCESS;
278 		}
279 
280 		// Always advance the index for the next iteration
281 		(*_index)++;
282 
283 		if (pSetupDiEnumDeviceInterfaces(dev_info, dev_info_data, guid, 0, &dev_interface_data))
284 			break;
285 
286 		if (GetLastError() != ERROR_NO_MORE_ITEMS) {
287 			usbi_err(ctx, "Could not obtain interface data for %s devInst %lX: %s",
288 				guid_to_string(guid, guid_string), ULONG_CAST(dev_info_data->DevInst), windows_error_str(0));
289 			return LIBUSB_ERROR_OTHER;
290 		}
291 
292 		// Device does not have an interface matching this GUID, skip
293 	}
294 
295 	// Read interface data (dummy + actual) to access the device path
296 	if (!pSetupDiGetDeviceInterfaceDetailA(dev_info, &dev_interface_data, NULL, 0, &size, NULL)) {
297 		// The dummy call should fail with ERROR_INSUFFICIENT_BUFFER
298 		if (GetLastError() != ERROR_INSUFFICIENT_BUFFER) {
299 			usbi_err(ctx, "could not access interface data (dummy) for %s devInst %lX: %s",
300 				guid_to_string(guid, guid_string), ULONG_CAST(dev_info_data->DevInst), windows_error_str(0));
301 			return LIBUSB_ERROR_OTHER;
302 		}
303 	} else {
304 		usbi_err(ctx, "program assertion failed - http://msdn.microsoft.com/en-us/library/ms792901.aspx is wrong");
305 		return LIBUSB_ERROR_OTHER;
306 	}
307 
308 	dev_interface_details = malloc(size);
309 	if (dev_interface_details == NULL) {
310 		usbi_err(ctx, "could not allocate interface data for %s devInst %lX",
311 			guid_to_string(guid, guid_string), ULONG_CAST(dev_info_data->DevInst));
312 		return LIBUSB_ERROR_NO_MEM;
313 	}
314 
315 	dev_interface_details->cbSize = sizeof(SP_DEVICE_INTERFACE_DETAIL_DATA_A);
316 	if (!pSetupDiGetDeviceInterfaceDetailA(dev_info, &dev_interface_data,
317 		dev_interface_details, size, NULL, NULL)) {
318 		usbi_err(ctx, "could not access interface data (actual) for %s devInst %lX: %s",
319 			guid_to_string(guid, guid_string), ULONG_CAST(dev_info_data->DevInst), windows_error_str(0));
320 		free(dev_interface_details);
321 		return LIBUSB_ERROR_OTHER;
322 	}
323 
324 	*dev_interface_path = normalize_path(dev_interface_details->DevicePath);
325 	free(dev_interface_details);
326 
327 	if (*dev_interface_path == NULL) {
328 		usbi_err(ctx, "could not allocate interface path for %s devInst %lX",
329 			guid_to_string(guid, guid_string), ULONG_CAST(dev_info_data->DevInst));
330 		return LIBUSB_ERROR_NO_MEM;
331 	}
332 
333 	return LIBUSB_SUCCESS;
334 }
335 
336 /* For libusb0 filter */
get_interface_details_filter(struct libusb_context * ctx,HDEVINFO * dev_info,DWORD _index,char * filter_path,char ** dev_interface_path)337 static int get_interface_details_filter(struct libusb_context *ctx, HDEVINFO *dev_info,
338 	DWORD _index, char *filter_path, char **dev_interface_path)
339 {
340 	const GUID *libusb0_guid = &GUID_DEVINTERFACE_LIBUSB0_FILTER;
341 	SP_DEVICE_INTERFACE_DATA dev_interface_data;
342 	PSP_DEVICE_INTERFACE_DETAIL_DATA_A dev_interface_details;
343 	HKEY hkey_dev_interface;
344 	DWORD size;
345 	int err = LIBUSB_ERROR_OTHER;
346 
347 	if (_index == 0) {
348 		*dev_info = pSetupDiGetClassDevsA(libusb0_guid, NULL, NULL, DIGCF_PRESENT | DIGCF_DEVICEINTERFACE);
349 		if (*dev_info == INVALID_HANDLE_VALUE) {
350 			usbi_err(ctx, "could not obtain device info set: %s", windows_error_str(0));
351 			return LIBUSB_ERROR_OTHER;
352 		}
353 	}
354 
355 	dev_interface_data.cbSize = sizeof(SP_DEVICE_INTERFACE_DATA);
356 	if (!pSetupDiEnumDeviceInterfaces(*dev_info, NULL, libusb0_guid, _index, &dev_interface_data)) {
357 		if (GetLastError() != ERROR_NO_MORE_ITEMS) {
358 			usbi_err(ctx, "Could not obtain interface data for index %lu: %s",
359 				ULONG_CAST(_index), windows_error_str(0));
360 			goto err_exit;
361 		}
362 
363 		pSetupDiDestroyDeviceInfoList(*dev_info);
364 		*dev_info = INVALID_HANDLE_VALUE;
365 		return LIBUSB_SUCCESS;
366 	}
367 
368 	// Read interface data (dummy + actual) to access the device path
369 	if (!pSetupDiGetDeviceInterfaceDetailA(*dev_info, &dev_interface_data, NULL, 0, &size, NULL)) {
370 		// The dummy call should fail with ERROR_INSUFFICIENT_BUFFER
371 		if (GetLastError() != ERROR_INSUFFICIENT_BUFFER) {
372 			usbi_err(ctx, "could not access interface data (dummy) for index %lu: %s",
373 				ULONG_CAST(_index), windows_error_str(0));
374 			goto err_exit;
375 		}
376 	} else {
377 		usbi_err(ctx, "program assertion failed - http://msdn.microsoft.com/en-us/library/ms792901.aspx is wrong");
378 		goto err_exit;
379 	}
380 
381 	dev_interface_details = malloc(size);
382 	if (dev_interface_details == NULL) {
383 		usbi_err(ctx, "could not allocate interface data for index %lu", ULONG_CAST(_index));
384 		err = LIBUSB_ERROR_NO_MEM;
385 		goto err_exit;
386 	}
387 
388 	dev_interface_details->cbSize = sizeof(SP_DEVICE_INTERFACE_DETAIL_DATA_A);
389 	if (!pSetupDiGetDeviceInterfaceDetailA(*dev_info, &dev_interface_data, dev_interface_details, size, NULL, NULL)) {
390 		usbi_err(ctx, "could not access interface data (actual) for index %lu: %s",
391 			ULONG_CAST(_index), windows_error_str(0));
392 		free(dev_interface_details);
393 		goto err_exit;
394 	}
395 
396 	*dev_interface_path = normalize_path(dev_interface_details->DevicePath);
397 	free(dev_interface_details);
398 
399 	if (*dev_interface_path == NULL) {
400 		usbi_err(ctx, "could not allocate interface path for index %lu", ULONG_CAST(_index));
401 		err = LIBUSB_ERROR_NO_MEM;
402 		goto err_exit;
403 	}
404 
405 	// [trobinso] lookup the libusb0 symbolic index.
406 	hkey_dev_interface = pSetupDiOpenDeviceInterfaceRegKey(*dev_info, &dev_interface_data, 0, KEY_READ);
407 	if (hkey_dev_interface != INVALID_HANDLE_VALUE) {
408 		DWORD libusb0_symboliclink_index = 0;
409 		DWORD value_length = sizeof(DWORD);
410 		LONG status;
411 
412 		status = pRegQueryValueExA(hkey_dev_interface, "LUsb0", NULL, NULL,
413 			(LPBYTE)&libusb0_symboliclink_index, &value_length);
414 		if (status == ERROR_SUCCESS) {
415 			if (libusb0_symboliclink_index < 256) {
416 				// libusb0.sys is connected to this device instance.
417 				// If the the device interface guid is {F9F3FF14-AE21-48A0-8A25-8011A7A931D9} then it's a filter.
418 				sprintf(filter_path, "\\\\.\\libusb0-%04u", (unsigned int)libusb0_symboliclink_index);
419 				usbi_dbg(ctx, "assigned libusb0 symbolic link %s", filter_path);
420 			} else {
421 				// libusb0.sys was connected to this device instance at one time; but not anymore.
422 			}
423 		}
424 		pRegCloseKey(hkey_dev_interface);
425 	} else {
426 		usbi_warn(ctx, "could not open device interface registry key for index %lu: %s",
427 			ULONG_CAST(_index), windows_error_str(0));
428 		// TODO: should this be an error?
429 	}
430 
431 	return LIBUSB_SUCCESS;
432 
433 err_exit:
434 	pSetupDiDestroyDeviceInfoList(*dev_info);
435 	*dev_info = INVALID_HANDLE_VALUE;
436 	return err;
437 }
438 
439 /*
440  * Returns the first known ancestor of a device
441  */
get_ancestor(struct libusb_context * ctx,DEVINST devinst,PDEVINST _parent_devinst)442 static struct libusb_device *get_ancestor(struct libusb_context *ctx,
443 	DEVINST devinst, PDEVINST _parent_devinst)
444 {
445 	struct libusb_device *dev = NULL;
446 	DEVINST parent_devinst;
447 
448 	while (dev == NULL) {
449 		if (CM_Get_Parent(&parent_devinst, devinst, 0) != CR_SUCCESS)
450 			break;
451 		devinst = parent_devinst;
452 		dev = usbi_get_device_by_session_id(ctx, (unsigned long)devinst);
453 	}
454 
455 	if ((dev != NULL) && (_parent_devinst != NULL))
456 		*_parent_devinst = devinst;
457 
458 	return dev;
459 }
460 
461 /*
462  * Determine which interface the given endpoint address belongs to
463  */
get_interface_by_endpoint(struct libusb_config_descriptor * conf_desc,uint8_t ep)464 static int get_interface_by_endpoint(struct libusb_config_descriptor *conf_desc, uint8_t ep)
465 {
466 	const struct libusb_interface *intf;
467 	const struct libusb_interface_descriptor *intf_desc;
468 	uint8_t i, k;
469 	int j;
470 
471 	for (i = 0; i < conf_desc->bNumInterfaces; i++) {
472 		intf = &conf_desc->interface[i];
473 		for (j = 0; j < intf->num_altsetting; j++) {
474 			intf_desc = &intf->altsetting[j];
475 			for (k = 0; k < intf_desc->bNumEndpoints; k++) {
476 				if (intf_desc->endpoint[k].bEndpointAddress == ep) {
477 					usbi_dbg(NULL, "found endpoint %02X on interface %d", intf_desc->bInterfaceNumber, i);
478 					return intf_desc->bInterfaceNumber;
479 				}
480 			}
481 		}
482 	}
483 
484 	usbi_dbg(NULL, "endpoint %02X not found on any interface", ep);
485 	return LIBUSB_ERROR_NOT_FOUND;
486 }
487 
488 /*
489  * Open a device and associate the HANDLE with the context's I/O completion port
490  */
windows_open(struct libusb_device_handle * dev_handle,const char * path,DWORD access)491 static HANDLE windows_open(struct libusb_device_handle *dev_handle, const char *path, DWORD access)
492 {
493 	struct libusb_context *ctx = HANDLE_CTX(dev_handle);
494 	struct windows_context_priv *priv = usbi_get_context_priv(ctx);
495 	HANDLE handle;
496 
497 	handle = CreateFileA(path, access, FILE_SHARE_READ | FILE_SHARE_WRITE, NULL, OPEN_EXISTING, FILE_FLAG_OVERLAPPED, NULL);
498 	if (handle == INVALID_HANDLE_VALUE)
499 		return handle;
500 
501 	if (CreateIoCompletionPort(handle, priv->completion_port, (ULONG_PTR)dev_handle, 0) == NULL) {
502 		usbi_err(ctx, "failed to associate handle to I/O completion port: %s", windows_error_str(0));
503 		CloseHandle(handle);
504 		return INVALID_HANDLE_VALUE;
505 	}
506 
507 	return handle;
508 }
509 
510 /*
511  * Populate the endpoints addresses of the device_priv interface helper structs
512  */
windows_assign_endpoints(struct libusb_device_handle * dev_handle,uint8_t iface,uint8_t altsetting)513 static int windows_assign_endpoints(struct libusb_device_handle *dev_handle, uint8_t iface, uint8_t altsetting)
514 {
515 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
516 	struct libusb_config_descriptor *conf_desc;
517 	const struct libusb_interface_descriptor *if_desc;
518 	int i, r;
519 
520 	r = libusb_get_active_config_descriptor(dev_handle->dev, &conf_desc);
521 	if (r != LIBUSB_SUCCESS) {
522 		usbi_warn(HANDLE_CTX(dev_handle), "could not read config descriptor: error %d", r);
523 		return r;
524 	}
525 
526 	if (iface >= conf_desc->bNumInterfaces) {
527 		usbi_err(HANDLE_CTX(dev_handle), "interface %d out of range for device", iface);
528 		return LIBUSB_ERROR_NOT_FOUND;
529 	}
530 	if_desc = &conf_desc->interface[iface].altsetting[altsetting];
531 	safe_free(priv->usb_interface[iface].endpoint);
532 
533 	if (if_desc->bNumEndpoints == 0) {
534 		usbi_dbg(HANDLE_CTX(dev_handle), "no endpoints found for interface %u", iface);
535 	} else {
536 		priv->usb_interface[iface].endpoint = malloc(if_desc->bNumEndpoints);
537 		if (priv->usb_interface[iface].endpoint == NULL) {
538 			libusb_free_config_descriptor(conf_desc);
539 			return LIBUSB_ERROR_NO_MEM;
540 		}
541 		priv->usb_interface[iface].nb_endpoints = if_desc->bNumEndpoints;
542 		for (i = 0; i < if_desc->bNumEndpoints; i++) {
543 			priv->usb_interface[iface].endpoint[i] = if_desc->endpoint[i].bEndpointAddress;
544 			usbi_dbg(HANDLE_CTX(dev_handle), "(re)assigned endpoint %02X to interface %u", priv->usb_interface[iface].endpoint[i], iface);
545 		}
546 	}
547 	libusb_free_config_descriptor(conf_desc);
548 
549 	// Extra init may be required to configure endpoints
550 	if (priv->apib->configure_endpoints)
551 		r = priv->apib->configure_endpoints(SUB_API_NOTSET, dev_handle, iface);
552 
553 	if (r == LIBUSB_SUCCESS)
554 		priv->usb_interface[iface].current_altsetting = altsetting;
555 
556 	return r;
557 }
558 
559 // Lookup for a match in the list of API driver names
560 // return -1 if not found, driver match number otherwise
get_sub_api(char * driver,int api)561 static int get_sub_api(char *driver, int api)
562 {
563 	const char sep_str[2] = {LIST_SEPARATOR, 0};
564 	char *tok, *tmp_str;
565 	size_t len = strlen(driver);
566 	int i;
567 
568 	if (len == 0)
569 		return SUB_API_NOTSET;
570 
571 	tmp_str = _strdup(driver);
572 	if (tmp_str == NULL)
573 		return SUB_API_NOTSET;
574 
575 	tok = strtok(tmp_str, sep_str);
576 	while (tok != NULL) {
577 		for (i = 0; i < usb_api_backend[api].nb_driver_names; i++) {
578 			if (_stricmp(tok, usb_api_backend[api].driver_name_list[i]) == 0) {
579 				free(tmp_str);
580 				return i;
581 			}
582 		}
583 		tok = strtok(NULL, sep_str);
584 	}
585 
586 	free(tmp_str);
587 	return SUB_API_NOTSET;
588 }
589 
590 /*
591  * auto-claiming and auto-release helper functions
592  */
auto_claim(struct libusb_transfer * transfer,int * interface_number,int api_type)593 static int auto_claim(struct libusb_transfer *transfer, int *interface_number, int api_type)
594 {
595 	struct winusb_device_handle_priv *handle_priv =
596 		get_winusb_device_handle_priv(transfer->dev_handle);
597 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
598 	int current_interface = *interface_number;
599 	int r = LIBUSB_SUCCESS;
600 
601 	switch (api_type) {
602 	case USB_API_WINUSBX:
603 	case USB_API_HID:
604 		break;
605 	default:
606 		return LIBUSB_ERROR_INVALID_PARAM;
607 	}
608 
609 	usbi_mutex_lock(&autoclaim_lock);
610 	if (current_interface < 0) { // No serviceable interface was found
611 		for (current_interface = 0; current_interface < USB_MAXINTERFACES; current_interface++) {
612 			// Must claim an interface of the same API type
613 			if ((priv->usb_interface[current_interface].apib->id == api_type)
614 					&& (libusb_claim_interface(transfer->dev_handle, current_interface) == LIBUSB_SUCCESS)) {
615 				usbi_dbg(TRANSFER_CTX(transfer), "auto-claimed interface %d for control request", current_interface);
616 				if (handle_priv->autoclaim_count[current_interface] != 0)
617 					usbi_err(TRANSFER_CTX(transfer), "program assertion failed - autoclaim_count was nonzero");
618 				handle_priv->autoclaim_count[current_interface]++;
619 				break;
620 			}
621 		}
622 		if (current_interface == USB_MAXINTERFACES) {
623 			usbi_err(TRANSFER_CTX(transfer), "could not auto-claim any interface");
624 			r = LIBUSB_ERROR_NOT_FOUND;
625 		}
626 	} else {
627 		// If we have a valid interface that was autoclaimed, we must increment
628 		// its autoclaim count so that we can prevent an early release.
629 		if (handle_priv->autoclaim_count[current_interface] != 0)
630 			handle_priv->autoclaim_count[current_interface]++;
631 	}
632 	usbi_mutex_unlock(&autoclaim_lock);
633 
634 	*interface_number = current_interface;
635 	return r;
636 }
637 
auto_release(struct usbi_transfer * itransfer)638 static void auto_release(struct usbi_transfer *itransfer)
639 {
640 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
641 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
642 	libusb_device_handle *dev_handle = transfer->dev_handle;
643 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
644 	int r;
645 
646 	usbi_mutex_lock(&autoclaim_lock);
647 	if (handle_priv->autoclaim_count[transfer_priv->interface_number] > 0) {
648 		handle_priv->autoclaim_count[transfer_priv->interface_number]--;
649 		if (handle_priv->autoclaim_count[transfer_priv->interface_number] == 0) {
650 			r = libusb_release_interface(dev_handle, transfer_priv->interface_number);
651 			if (r == LIBUSB_SUCCESS)
652 				usbi_dbg(ITRANSFER_CTX(itransfer), "auto-released interface %d", transfer_priv->interface_number);
653 			else
654 				usbi_dbg(ITRANSFER_CTX(itransfer), "failed to auto-release interface %d (%s)",
655 					transfer_priv->interface_number, libusb_error_name((enum libusb_error)r));
656 		}
657 	}
658 	usbi_mutex_unlock(&autoclaim_lock);
659 }
660 
661 /*
662  * init: libusb backend init function
663  */
winusb_init(struct libusb_context * ctx)664 static int winusb_init(struct libusb_context *ctx)
665 {
666 	int i;
667 
668 	// Load DLL imports
669 	if (!init_dlls(ctx)) {
670 		usbi_err(ctx, "could not resolve DLL functions");
671 		return LIBUSB_ERROR_OTHER;
672 	}
673 
674 	// Initialize the low level APIs (we don't care about errors at this stage)
675 	for (i = 0; i < USB_API_MAX; i++) {
676 		if (usb_api_backend[i].init && !usb_api_backend[i].init(ctx))
677 			usbi_warn(ctx, "error initializing %s backend",
678 				usb_api_backend[i].designation);
679 	}
680 
681 	// We need a lock for proper auto-release
682 	usbi_mutex_init(&autoclaim_lock);
683 
684 	return LIBUSB_SUCCESS;
685 }
686 
687 /*
688 * exit: libusb backend deinitialization function
689 */
winusb_exit(struct libusb_context * ctx)690 static void winusb_exit(struct libusb_context *ctx)
691 {
692 	int i;
693 
694 	UNUSED(ctx);
695 
696 	usbi_mutex_destroy(&autoclaim_lock);
697 
698 	for (i = 0; i < USB_API_MAX; i++) {
699 		if (usb_api_backend[i].exit)
700 			usb_api_backend[i].exit();
701 	}
702 
703 	exit_dlls();
704 }
705 
706 /*
707  * fetch and cache all the config descriptors through I/O
708  */
cache_config_descriptors(struct libusb_device * dev,HANDLE hub_handle)709 static void cache_config_descriptors(struct libusb_device *dev, HANDLE hub_handle)
710 {
711 	struct libusb_context *ctx = DEVICE_CTX(dev);
712 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
713 	DWORD size, ret_size;
714 	uint8_t i, num_configurations;
715 
716 	USB_CONFIGURATION_DESCRIPTOR_SHORT cd_buf_short; // dummy request
717 	PUSB_DESCRIPTOR_REQUEST cd_buf_actual = NULL;    // actual request
718 	PUSB_CONFIGURATION_DESCRIPTOR cd_data;
719 
720 	num_configurations = dev->device_descriptor.bNumConfigurations;
721 	if (num_configurations == 0)
722 		return;
723 
724 	assert(sizeof(USB_DESCRIPTOR_REQUEST) == USB_DESCRIPTOR_REQUEST_SIZE);
725 
726 	priv->config_descriptor = calloc(num_configurations, sizeof(PUSB_CONFIGURATION_DESCRIPTOR));
727 	if (priv->config_descriptor == NULL) {
728 		usbi_err(ctx, "could not allocate configuration descriptor array for '%s'", priv->dev_id);
729 		return;
730 	}
731 
732 	for (i = 0; i <= num_configurations; i++) {
733 		safe_free(cd_buf_actual);
734 
735 		if (i == num_configurations)
736 			break;
737 
738 		size = sizeof(cd_buf_short);
739 		memset(&cd_buf_short.desc, 0, sizeof(cd_buf_short.desc));
740 
741 		cd_buf_short.req.ConnectionIndex = (ULONG)dev->port_number;
742 		cd_buf_short.req.SetupPacket.bmRequest = LIBUSB_ENDPOINT_IN;
743 		cd_buf_short.req.SetupPacket.bRequest = LIBUSB_REQUEST_GET_DESCRIPTOR;
744 		cd_buf_short.req.SetupPacket.wValue = (LIBUSB_DT_CONFIG << 8) | i;
745 		cd_buf_short.req.SetupPacket.wIndex = 0;
746 		cd_buf_short.req.SetupPacket.wLength = (USHORT)sizeof(USB_CONFIGURATION_DESCRIPTOR);
747 
748 		// Dummy call to get the required data size. Initial failures are reported as info rather
749 		// than error as they can occur for non-penalizing situations, such as with some hubs.
750 		// coverity[tainted_data_argument]
751 		if (!DeviceIoControl(hub_handle, IOCTL_USB_GET_DESCRIPTOR_FROM_NODE_CONNECTION, &cd_buf_short, size,
752 			&cd_buf_short, size, &ret_size, NULL)) {
753 			usbi_info(ctx, "could not access configuration descriptor %u (dummy) for '%s': %s", i, priv->dev_id, windows_error_str(0));
754 			continue;
755 		}
756 
757 		if ((ret_size != size) || (cd_buf_short.desc.wTotalLength < sizeof(USB_CONFIGURATION_DESCRIPTOR))) {
758 			usbi_info(ctx, "unexpected configuration descriptor %u size (dummy) for '%s'", i, priv->dev_id);
759 			continue;
760 		}
761 
762 		size = sizeof(USB_DESCRIPTOR_REQUEST) + cd_buf_short.desc.wTotalLength;
763 		cd_buf_actual = malloc(size);
764 		if (cd_buf_actual == NULL) {
765 			usbi_err(ctx, "could not allocate configuration descriptor %u buffer for '%s'", i, priv->dev_id);
766 			continue;
767 		}
768 
769 		// Actual call
770 		cd_buf_actual->ConnectionIndex = (ULONG)dev->port_number;
771 		cd_buf_actual->SetupPacket.bmRequest = LIBUSB_ENDPOINT_IN;
772 		cd_buf_actual->SetupPacket.bRequest = LIBUSB_REQUEST_GET_DESCRIPTOR;
773 		cd_buf_actual->SetupPacket.wValue = (LIBUSB_DT_CONFIG << 8) | i;
774 		cd_buf_actual->SetupPacket.wIndex = 0;
775 		cd_buf_actual->SetupPacket.wLength = cd_buf_short.desc.wTotalLength;
776 
777 		if (!DeviceIoControl(hub_handle, IOCTL_USB_GET_DESCRIPTOR_FROM_NODE_CONNECTION, cd_buf_actual, size,
778 			cd_buf_actual, size, &ret_size, NULL)) {
779 			usbi_err(ctx, "could not access configuration descriptor %u (actual) for '%s': %s", i, priv->dev_id, windows_error_str(0));
780 			continue;
781 		}
782 
783 		cd_data = (PUSB_CONFIGURATION_DESCRIPTOR)((UCHAR *)cd_buf_actual + USB_DESCRIPTOR_REQUEST_SIZE);
784 
785 		if ((size != ret_size) || (cd_data->wTotalLength != cd_buf_short.desc.wTotalLength)) {
786 			usbi_err(ctx, "unexpected configuration descriptor %u size (actual) for '%s'", i, priv->dev_id);
787 			continue;
788 		}
789 
790 		if (cd_data->bDescriptorType != LIBUSB_DT_CONFIG) {
791 			usbi_err(ctx, "descriptor %u not a configuration descriptor for '%s'", i, priv->dev_id);
792 			continue;
793 		}
794 
795 		usbi_dbg(ctx, "cached config descriptor %u (bConfigurationValue=%u, %u bytes)",
796 			i, cd_data->bConfigurationValue, cd_data->wTotalLength);
797 
798 		// Cache the descriptor
799 		priv->config_descriptor[i] = cd_data;
800 		cd_buf_actual = NULL;
801 	}
802 }
803 
804 #define ROOT_HUB_FS_CONFIG_DESC_LENGTH		0x19
805 #define ROOT_HUB_HS_CONFIG_DESC_LENGTH		0x19
806 #define ROOT_HUB_SS_CONFIG_DESC_LENGTH		0x1f
807 #define CONFIG_DESC_WTOTAL_LENGTH_OFFSET	0x02
808 #define CONFIG_DESC_EP_MAX_PACKET_OFFSET	0x16
809 #define CONFIG_DESC_EP_BINTERVAL_OFFSET		0x18
810 
811 static const uint8_t root_hub_config_descriptor_template[] = {
812 	// Configuration Descriptor
813 	LIBUSB_DT_CONFIG_SIZE,		// bLength
814 	LIBUSB_DT_CONFIG,		// bDescriptorType
815 	0x00, 0x00,			// wTotalLength (filled in)
816 	0x01,				// bNumInterfaces
817 	0x01,				// bConfigurationValue
818 	0x00,				// iConfiguration
819 	0xc0,				// bmAttributes (reserved + self-powered)
820 	0x00,				// bMaxPower
821 	// Interface Descriptor
822 	LIBUSB_DT_INTERFACE_SIZE,	// bLength
823 	LIBUSB_DT_INTERFACE,		// bDescriptorType
824 	0x00,				// bInterfaceNumber
825 	0x00,				// bAlternateSetting
826 	0x01,				// bNumEndpoints
827 	LIBUSB_CLASS_HUB,		// bInterfaceClass
828 	0x00,				// bInterfaceSubClass
829 	0x00,				// bInterfaceProtocol
830 	0x00,				// iInterface
831 	// Endpoint Descriptor
832 	LIBUSB_DT_ENDPOINT_SIZE,	// bLength
833 	LIBUSB_DT_ENDPOINT,		// bDescriptorType
834 	0x81,				// bEndpointAddress
835 	0x03,				// bmAttributes (Interrupt)
836 	0x00, 0x00,			// wMaxPacketSize (filled in)
837 	0x00,				// bInterval (filled in)
838 	// SuperSpeed Endpoint Companion Descriptor
839 	LIBUSB_DT_SS_ENDPOINT_COMPANION_SIZE,	// bLength
840 	LIBUSB_DT_SS_ENDPOINT_COMPANION,	// bDescriptorType
841 	0x00,					// bMaxBurst
842 	0x00,					// bmAttributes
843 	0x02, 0x00				// wBytesPerInterval
844 };
845 
alloc_root_hub_config_desc(struct libusb_device * dev,ULONG num_ports,uint8_t config_desc_length,uint8_t ep_interval)846 static int alloc_root_hub_config_desc(struct libusb_device *dev, ULONG num_ports,
847 	uint8_t config_desc_length, uint8_t ep_interval)
848 {
849 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
850 	uint8_t *ptr;
851 
852 	priv->config_descriptor = malloc(sizeof(*priv->config_descriptor));
853 	if (priv->config_descriptor == NULL)
854 		return LIBUSB_ERROR_NO_MEM;
855 
856 	// Most config descriptors come from cache_config_descriptors() which obtains the
857 	// descriptors from the hub using an allocated USB_DESCRIPTOR_REQUEST structure.
858 	// To avoid an extra malloc + memcpy we just hold on to the USB_DESCRIPTOR_REQUEST
859 	// structure we already have and back up the pointer in windows_device_priv_release()
860 	// when freeing the descriptors. To keep a single execution path, we need to offset
861 	// the pointer here by the same amount.
862 	ptr = malloc(USB_DESCRIPTOR_REQUEST_SIZE + config_desc_length);
863 	if (ptr == NULL)
864 		return LIBUSB_ERROR_NO_MEM;
865 
866 	ptr += USB_DESCRIPTOR_REQUEST_SIZE;
867 
868 	memcpy(ptr, root_hub_config_descriptor_template, config_desc_length);
869 	ptr[CONFIG_DESC_WTOTAL_LENGTH_OFFSET] = config_desc_length;
870 	ptr[CONFIG_DESC_EP_MAX_PACKET_OFFSET] = (uint8_t)((num_ports + 7) / 8);
871 	ptr[CONFIG_DESC_EP_BINTERVAL_OFFSET] = ep_interval;
872 
873 	priv->config_descriptor[0] = (PUSB_CONFIGURATION_DESCRIPTOR)ptr;
874 	priv->active_config = 1;
875 
876 	return 0;
877 }
878 
init_root_hub(struct libusb_device * dev)879 static int init_root_hub(struct libusb_device *dev)
880 {
881 	struct libusb_context *ctx = DEVICE_CTX(dev);
882 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
883 	USB_NODE_CONNECTION_INFORMATION_EX conn_info;
884 	USB_NODE_CONNECTION_INFORMATION_EX_V2 conn_info_v2;
885 	USB_NODE_INFORMATION hub_info;
886 	enum libusb_speed speed = LIBUSB_SPEED_UNKNOWN;
887 	uint8_t config_desc_length;
888 	uint8_t ep_interval;
889 	HANDLE handle;
890 	ULONG port_number, num_ports;
891 	DWORD size;
892 	int r;
893 
894 	// Determining the speed of a root hub is painful. Microsoft does not directly report the speed
895 	// capabilities of the root hub itself, only its ports and/or connected devices. Therefore we
896 	// are forced to query each individual port of the root hub to try and infer the root hub's
897 	// speed. Note that we have to query all ports because the presence of a device on that port
898 	// changes if/how Windows returns any useful speed information.
899 	handle = CreateFileA(priv->path, GENERIC_WRITE, FILE_SHARE_WRITE, NULL, OPEN_EXISTING, 0, NULL);
900 	if (handle == INVALID_HANDLE_VALUE) {
901 		usbi_err(ctx, "could not open root hub %s: %s", priv->path, windows_error_str(0));
902 		return LIBUSB_ERROR_ACCESS;
903 	}
904 
905 	if (!DeviceIoControl(handle, IOCTL_USB_GET_NODE_INFORMATION, NULL, 0, &hub_info, sizeof(hub_info), &size, NULL)) {
906 		usbi_warn(ctx, "could not get root hub info for '%s': %s", priv->dev_id, windows_error_str(0));
907 		CloseHandle(handle);
908 		return LIBUSB_ERROR_ACCESS;
909 	}
910 
911 	num_ports = hub_info.u.HubInformation.HubDescriptor.bNumberOfPorts;
912 	usbi_dbg(ctx, "root hub '%s' reports %lu ports", priv->dev_id, ULONG_CAST(num_ports));
913 
914 	if (windows_version >= WINDOWS_8) {
915 		// Windows 8 and later is better at reporting the speed capabilities of the root hub,
916 		// but it is not perfect. If no device is attached to the port being queried, the
917 		// returned information will only indicate whether that port supports USB 3.0 signalling.
918 		// That is not enough information to distinguish between SuperSpeed and SuperSpeed Plus.
919 		for (port_number = 1; port_number <= num_ports; port_number++) {
920 			conn_info_v2.ConnectionIndex = port_number;
921 			conn_info_v2.Length = sizeof(conn_info_v2);
922 			conn_info_v2.SupportedUsbProtocols.Usb300 = 1;
923 			if (!DeviceIoControl(handle, IOCTL_USB_GET_NODE_CONNECTION_INFORMATION_EX_V2,
924 				&conn_info_v2, sizeof(conn_info_v2), &conn_info_v2, sizeof(conn_info_v2), &size, NULL)) {
925 				usbi_warn(ctx, "could not get node connection information (V2) for root hub '%s' port %lu: %s",
926 					priv->dev_id, ULONG_CAST(port_number), windows_error_str(0));
927 				break;
928 			}
929 
930 			if (conn_info_v2.Flags.DeviceIsSuperSpeedPlusCapableOrHigher)
931 				speed = MAX(speed, LIBUSB_SPEED_SUPER_PLUS);
932 			else if (conn_info_v2.Flags.DeviceIsSuperSpeedCapableOrHigher || conn_info_v2.SupportedUsbProtocols.Usb300)
933 				speed = MAX(speed, LIBUSB_SPEED_SUPER);
934 			else if (conn_info_v2.SupportedUsbProtocols.Usb200)
935 				speed = MAX(speed, LIBUSB_SPEED_HIGH);
936 			else
937 				speed = MAX(speed, LIBUSB_SPEED_FULL);
938 		}
939 
940 		if (speed != LIBUSB_SPEED_UNKNOWN)
941 			goto make_descriptors;
942 	}
943 
944 	// At this point the speed is still not known, most likely because we are executing on
945 	// Windows 7 or earlier. The following hackery peeks into the root hub's Device ID and
946 	// tries to extract speed information from it, based on observed naming conventions.
947 	// If this does not work, we will query individual ports of the root hub.
948 	if (strstr(priv->dev_id, "ROOT_HUB31") != NULL)
949 		speed = LIBUSB_SPEED_SUPER_PLUS;
950 	else if (strstr(priv->dev_id, "ROOT_HUB30") != NULL)
951 		speed = LIBUSB_SPEED_SUPER;
952 	else if (strstr(priv->dev_id, "ROOT_HUB20") != NULL)
953 		speed = LIBUSB_SPEED_HIGH;
954 
955 	if (speed != LIBUSB_SPEED_UNKNOWN)
956 		goto make_descriptors;
957 
958 	// Windows only reports speed information about a connected device. This means that a root
959 	// hub with no connected devices or devices that are all operating at a speed less than the
960 	// highest speed that the root hub supports will not give us the correct speed.
961 	for (port_number = 1; port_number <= num_ports; port_number++) {
962 		conn_info.ConnectionIndex = port_number;
963 		if (!DeviceIoControl(handle, IOCTL_USB_GET_NODE_CONNECTION_INFORMATION_EX, &conn_info, sizeof(conn_info),
964 			&conn_info, sizeof(conn_info), &size, NULL)) {
965 			usbi_warn(ctx, "could not get node connection information for root hub '%s' port %lu: %s",
966 				priv->dev_id, ULONG_CAST(port_number), windows_error_str(0));
967 			continue;
968 		}
969 
970 		if (conn_info.ConnectionStatus != DeviceConnected)
971 			continue;
972 
973 		if (conn_info.Speed == UsbHighSpeed) {
974 			speed = LIBUSB_SPEED_HIGH;
975 			break;
976 		}
977 	}
978 
979 make_descriptors:
980 	CloseHandle(handle);
981 
982 	dev->device_descriptor.bLength = LIBUSB_DT_DEVICE_SIZE;
983 	dev->device_descriptor.bDescriptorType = LIBUSB_DT_DEVICE;
984 	dev->device_descriptor.bDeviceClass = LIBUSB_CLASS_HUB;
985 	if ((dev->device_descriptor.idVendor == 0) && (dev->device_descriptor.idProduct == 0)) {
986 		dev->device_descriptor.idVendor = 0x1d6b;	// Linux Foundation
987 		dev->device_descriptor.idProduct = (uint16_t)speed;
988 	}
989 	dev->device_descriptor.bcdDevice = 0x0100;
990 	dev->device_descriptor.bNumConfigurations = 1;
991 
992 	switch (speed) {
993 	case LIBUSB_SPEED_SUPER_PLUS:
994 		dev->device_descriptor.bcdUSB = 0x0310;
995 		config_desc_length = ROOT_HUB_SS_CONFIG_DESC_LENGTH;
996 		ep_interval = 0x0c;	// 256ms
997 		break;
998 	case LIBUSB_SPEED_SUPER:
999 		dev->device_descriptor.bcdUSB = 0x0300;
1000 		config_desc_length = ROOT_HUB_SS_CONFIG_DESC_LENGTH;
1001 		ep_interval = 0x0c;	// 256ms
1002 		break;
1003 	case LIBUSB_SPEED_HIGH:
1004 		dev->device_descriptor.bcdUSB = 0x0200;
1005 		config_desc_length = ROOT_HUB_HS_CONFIG_DESC_LENGTH;
1006 		ep_interval = 0x0c;	// 256ms
1007 		break;
1008 	case LIBUSB_SPEED_LOW:		// Not used, but keeps compiler happy
1009 	case LIBUSB_SPEED_UNKNOWN:
1010 		// This case means absolutely no information about this root hub was determined.
1011 		// There is not much choice than to be pessimistic and label this as a
1012 		// full-speed device.
1013 		speed = LIBUSB_SPEED_FULL;
1014 		// fallthrough
1015 	case LIBUSB_SPEED_FULL:
1016 		dev->device_descriptor.bcdUSB = 0x0110;
1017 		config_desc_length = ROOT_HUB_FS_CONFIG_DESC_LENGTH;
1018 		ep_interval = 0xff;	// 255ms
1019 		break;
1020 	default:			// Impossible, buts keeps compiler happy
1021 		usbi_err(ctx, "program assertion failed - unknown root hub speed");
1022 		return LIBUSB_ERROR_INVALID_PARAM;
1023 	}
1024 
1025 	if (speed >= LIBUSB_SPEED_SUPER) {
1026 		dev->device_descriptor.bDeviceProtocol = 0x03;	// USB 3.0 Hub
1027 		dev->device_descriptor.bMaxPacketSize0 = 0x09;	// 2^9 bytes
1028 	} else {
1029 		dev->device_descriptor.bMaxPacketSize0 = 0x40;	// 64 bytes
1030 	}
1031 
1032 	dev->speed = speed;
1033 
1034 	r = alloc_root_hub_config_desc(dev, num_ports, config_desc_length, ep_interval);
1035 	if (r)
1036 		usbi_err(ctx, "could not allocate config descriptor for root hub '%s'", priv->dev_id);
1037 
1038 	return r;
1039 }
1040 
1041 /*
1042  * Populate a libusb device structure
1043  */
init_device(struct libusb_device * dev,struct libusb_device * parent_dev,uint8_t port_number,DEVINST devinst)1044 static int init_device(struct libusb_device *dev, struct libusb_device *parent_dev,
1045 	uint8_t port_number, DEVINST devinst)
1046 {
1047 	struct libusb_context *ctx = NULL;
1048 	struct libusb_device *tmp_dev;
1049 	struct winusb_device_priv *priv, *parent_priv, *tmp_priv;
1050 	USB_NODE_CONNECTION_INFORMATION_EX conn_info;
1051 	USB_NODE_CONNECTION_INFORMATION_EX_V2 conn_info_v2;
1052 	HANDLE hub_handle;
1053 	DWORD size;
1054 	uint8_t bus_number, depth;
1055 	int r;
1056 	int ginfotimeout;
1057 
1058 	priv = usbi_get_device_priv(dev);
1059 
1060 	// If the device is already initialized, we can stop here
1061 	if (priv->initialized)
1062 		return LIBUSB_SUCCESS;
1063 
1064 	if (parent_dev != NULL) { // Not a HCD root hub
1065 		ctx = DEVICE_CTX(dev);
1066 		parent_priv = usbi_get_device_priv(parent_dev);
1067 		if (parent_priv->apib->id != USB_API_HUB) {
1068 			usbi_warn(ctx, "parent for device '%s' is not a hub", priv->dev_id);
1069 			return LIBUSB_ERROR_NOT_FOUND;
1070 		}
1071 
1072 		// Calculate depth and fetch bus number
1073 		bus_number = parent_dev->bus_number;
1074 		if (bus_number == 0) {
1075 			tmp_dev = get_ancestor(ctx, devinst, &devinst);
1076 			if (tmp_dev != parent_dev) {
1077 				usbi_err(ctx, "program assertion failed - first ancestor is not parent");
1078 				return LIBUSB_ERROR_NOT_FOUND;
1079 			}
1080 			libusb_unref_device(tmp_dev);
1081 
1082 			for (depth = 1; bus_number == 0; depth++) {
1083 				tmp_dev = get_ancestor(ctx, devinst, &devinst);
1084 				if (tmp_dev == NULL) {
1085 					usbi_warn(ctx, "ancestor for device '%s' not found at depth %u", priv->dev_id, depth);
1086 					return LIBUSB_ERROR_NO_DEVICE;
1087 				}
1088 				if (tmp_dev->bus_number != 0) {
1089 					bus_number = tmp_dev->bus_number;
1090 					tmp_priv = usbi_get_device_priv(tmp_dev);
1091 					depth += tmp_priv->depth;
1092 				}
1093 				libusb_unref_device(tmp_dev);
1094 			}
1095 		} else {
1096 			depth = parent_priv->depth + 1;
1097 		}
1098 
1099 		if (bus_number == 0) {
1100 			usbi_err(ctx, "program assertion failed - bus number not found for '%s'", priv->dev_id);
1101 			return LIBUSB_ERROR_NOT_FOUND;
1102 		}
1103 
1104 		dev->bus_number = bus_number;
1105 		dev->port_number = port_number;
1106 		dev->parent_dev = parent_dev;
1107 		priv->depth = depth;
1108 
1109 		hub_handle = CreateFileA(parent_priv->path, GENERIC_WRITE, FILE_SHARE_WRITE, NULL, OPEN_EXISTING, 0, NULL);
1110 		if (hub_handle == INVALID_HANDLE_VALUE) {
1111 			usbi_warn(ctx, "could not open hub %s: %s", parent_priv->path, windows_error_str(0));
1112 			return LIBUSB_ERROR_ACCESS;
1113 		}
1114 
1115 		conn_info.ConnectionIndex = (ULONG)port_number;
1116 		// coverity[tainted_data_argument]
1117 		ginfotimeout = 20;
1118 		do {
1119 			if (!DeviceIoControl(hub_handle, IOCTL_USB_GET_NODE_CONNECTION_INFORMATION_EX, &conn_info, sizeof(conn_info),
1120 				&conn_info, sizeof(conn_info), &size, NULL)) {
1121 				usbi_warn(ctx, "could not get node connection information for device '%s': %s",
1122 					priv->dev_id, windows_error_str(0));
1123 				CloseHandle(hub_handle);
1124 				return LIBUSB_ERROR_NO_DEVICE;
1125 			}
1126 
1127 			if (conn_info.ConnectionStatus == NoDeviceConnected) {
1128 				usbi_err(ctx, "device '%s' is no longer connected!", priv->dev_id);
1129 				CloseHandle(hub_handle);
1130 				return LIBUSB_ERROR_NO_DEVICE;
1131 			}
1132 
1133 			if ((conn_info.DeviceDescriptor.bLength != LIBUSB_DT_DEVICE_SIZE)
1134 				 || (conn_info.DeviceDescriptor.bDescriptorType != LIBUSB_DT_DEVICE)) {
1135 				SleepEx(50, TRUE);
1136 				continue;
1137 			}
1138 
1139 			static_assert(sizeof(dev->device_descriptor) == sizeof(conn_info.DeviceDescriptor),
1140 				      "mismatch between libusb and OS device descriptor sizes");
1141 			memcpy(&dev->device_descriptor, &conn_info.DeviceDescriptor, LIBUSB_DT_DEVICE_SIZE);
1142 			usbi_localize_device_descriptor(&dev->device_descriptor);
1143 
1144 			priv->active_config = conn_info.CurrentConfigurationValue;
1145 			if (priv->active_config == 0) {
1146 				usbi_dbg(ctx, "0x%x:0x%x found %u configurations (not configured)",
1147 					dev->device_descriptor.idVendor,
1148 					dev->device_descriptor.idProduct,
1149 					dev->device_descriptor.bNumConfigurations);
1150 				SleepEx(50, TRUE);
1151 			}
1152 		} while (priv->active_config == 0 && --ginfotimeout >= 0);
1153 
1154 		if ((conn_info.DeviceDescriptor.bLength != LIBUSB_DT_DEVICE_SIZE)
1155 			 || (conn_info.DeviceDescriptor.bDescriptorType != LIBUSB_DT_DEVICE)) {
1156 			usbi_err(ctx, "device '%s' has invalid descriptor!", priv->dev_id);
1157 			CloseHandle(hub_handle);
1158 			return LIBUSB_ERROR_OTHER;
1159 		}
1160 
1161 		if (priv->active_config == 0) {
1162 			usbi_info(ctx, "0x%x:0x%x found %u configurations but device isn't configured, "
1163 				"forcing current configuration to 1",
1164 				dev->device_descriptor.idVendor,
1165 				dev->device_descriptor.idProduct,
1166 				dev->device_descriptor.bNumConfigurations);
1167 			priv->active_config = 1;
1168 		} else {
1169 			usbi_dbg(ctx, "found %u configurations (current config: %u)", dev->device_descriptor.bNumConfigurations, priv->active_config);
1170 		}
1171 
1172 		// Cache as many config descriptors as we can
1173 		cache_config_descriptors(dev, hub_handle);
1174 
1175 		// In their great wisdom, Microsoft decided to BREAK the USB speed report between Windows 7 and Windows 8
1176 		if (windows_version >= WINDOWS_8) {
1177 			conn_info_v2.ConnectionIndex = (ULONG)port_number;
1178 			conn_info_v2.Length = sizeof(USB_NODE_CONNECTION_INFORMATION_EX_V2);
1179 			conn_info_v2.SupportedUsbProtocols.Usb300 = 1;
1180 			if (!DeviceIoControl(hub_handle, IOCTL_USB_GET_NODE_CONNECTION_INFORMATION_EX_V2,
1181 				&conn_info_v2, sizeof(conn_info_v2), &conn_info_v2, sizeof(conn_info_v2), &size, NULL)) {
1182 				usbi_warn(ctx, "could not get node connection information (V2) for device '%s': %s",
1183 					priv->dev_id,  windows_error_str(0));
1184 			} else if (conn_info_v2.Flags.DeviceIsOperatingAtSuperSpeedPlusOrHigher) {
1185 				conn_info.Speed = UsbSuperSpeedPlus;
1186 			} else if (conn_info_v2.Flags.DeviceIsOperatingAtSuperSpeedOrHigher) {
1187 				conn_info.Speed = UsbSuperSpeed;
1188 			}
1189 		}
1190 
1191 		CloseHandle(hub_handle);
1192 
1193 		if (conn_info.DeviceAddress > UINT8_MAX)
1194 			usbi_err(ctx, "program assertion failed - device address overflow");
1195 
1196 		dev->device_address = (uint8_t)conn_info.DeviceAddress;
1197 
1198 		switch (conn_info.Speed) {
1199 		case UsbLowSpeed: dev->speed = LIBUSB_SPEED_LOW; break;
1200 		case UsbFullSpeed: dev->speed = LIBUSB_SPEED_FULL; break;
1201 		case UsbHighSpeed: dev->speed = LIBUSB_SPEED_HIGH; break;
1202 		case UsbSuperSpeed: dev->speed = LIBUSB_SPEED_SUPER; break;
1203 		case UsbSuperSpeedPlus: dev->speed = LIBUSB_SPEED_SUPER_PLUS; break;
1204 		default:
1205 			usbi_warn(ctx, "unknown device speed %u", conn_info.Speed);
1206 			break;
1207 		}
1208 	} else {
1209 		r = init_root_hub(dev);
1210 		if (r)
1211 			return r;
1212 	}
1213 
1214 	r = usbi_sanitize_device(dev);
1215 	if (r)
1216 		return r;
1217 
1218 	priv->initialized = true;
1219 
1220 	usbi_dbg(ctx, "(bus: %u, addr: %u, depth: %u, port: %u): '%s'",
1221 		dev->bus_number, dev->device_address, priv->depth, dev->port_number, priv->dev_id);
1222 
1223 	return LIBUSB_SUCCESS;
1224 }
1225 
get_dev_port_number(HDEVINFO dev_info,SP_DEVINFO_DATA * dev_info_data,DWORD * port_nr)1226 static bool get_dev_port_number(HDEVINFO dev_info, SP_DEVINFO_DATA *dev_info_data, DWORD *port_nr)
1227 {
1228 	char buffer[MAX_KEY_LENGTH];
1229 	DWORD size;
1230 
1231 	// First try SPDRP_LOCATION_INFORMATION, which returns a REG_SZ. The string *may* have a format
1232 	// similar to "Port_#0002.Hub_#000D", in which case we can extract the port number. However, we
1233 	// cannot extract the port if the returned string does not follow this format.
1234 	if (pSetupDiGetDeviceRegistryPropertyA(dev_info, dev_info_data, SPDRP_LOCATION_INFORMATION,
1235 			NULL, (PBYTE)buffer, sizeof(buffer), NULL)) {
1236 		// Check for the required format.
1237 		if (strncmp(buffer, "Port_#", 6) == 0) {
1238 			*port_nr = atoi(buffer + 6);
1239 			return true;
1240 		}
1241 	}
1242 
1243 	// Next try SPDRP_LOCATION_PATHS, which returns a REG_MULTI_SZ (but we only examine the first
1244 	// string in it). Each path has a format similar to,
1245 	// "PCIROOT(B2)#PCI(0300)#PCI(0000)#USBROOT(0)#USB(1)#USB(2)#USBMI(3)", and the port number is
1246 	// the number within the last "USB(x)" token.
1247 	if (pSetupDiGetDeviceRegistryPropertyA(dev_info, dev_info_data, SPDRP_LOCATION_PATHS,
1248 			NULL, (PBYTE)buffer, sizeof(buffer), NULL)) {
1249 		// Find the last "#USB(x)" substring
1250 		for (char *token = strrchr(buffer, '#'); token != NULL; token = strrchr(buffer, '#')) {
1251 			if (strncmp(token, "#USB(", 5) == 0) {
1252 				*port_nr = atoi(token + 5);
1253 				return true;
1254 			}
1255 			// Shorten the string and try again.
1256 			*token = '\0';
1257 		}
1258 	}
1259 
1260 	// Lastly, try SPDRP_ADDRESS, which returns a REG_DWORD. The address *may* be the port number,
1261 	// which is true for the Microsoft driver but may not be true for other drivers. However, we
1262 	// have no other options here but to accept what it returns.
1263 	return pSetupDiGetDeviceRegistryPropertyA(dev_info, dev_info_data, SPDRP_ADDRESS,
1264 			NULL, (PBYTE)port_nr, sizeof(*port_nr), &size) && (size == sizeof(*port_nr));
1265 }
1266 
enumerate_hcd_root_hub(struct libusb_context * ctx,const char * dev_id,uint8_t bus_number,DEVINST devinst)1267 static int enumerate_hcd_root_hub(struct libusb_context *ctx, const char *dev_id,
1268 	uint8_t bus_number, DEVINST devinst)
1269 {
1270 	struct libusb_device *dev;
1271 	struct winusb_device_priv *priv;
1272 	unsigned long session_id;
1273 	DEVINST child_devinst;
1274 
1275 	if (CM_Get_Child(&child_devinst, devinst, 0) != CR_SUCCESS) {
1276 		usbi_warn(ctx, "could not get child devinst for '%s'", dev_id);
1277 		return LIBUSB_SUCCESS;
1278 	}
1279 
1280 	session_id = (unsigned long)child_devinst;
1281 	dev = usbi_get_device_by_session_id(ctx, session_id);
1282 	if (dev == NULL) {
1283 		usbi_err(ctx, "program assertion failed - HCD '%s' child not found", dev_id);
1284 		return LIBUSB_SUCCESS;
1285 	}
1286 
1287 	if (dev->bus_number == 0) {
1288 		// Only do this once
1289 		usbi_dbg(ctx, "assigning HCD '%s' bus number %u", dev_id, bus_number);
1290 		dev->bus_number = bus_number;
1291 
1292 		if (sscanf(dev_id, "PCI\\VEN_%04hx&DEV_%04hx%*s", &dev->device_descriptor.idVendor, &dev->device_descriptor.idProduct) != 2)
1293 			usbi_warn(ctx, "could not infer VID/PID of HCD root hub from '%s'", dev_id);
1294 
1295 		priv = usbi_get_device_priv(dev);
1296 		priv->root_hub = true;
1297 	}
1298 
1299 	libusb_unref_device(dev);
1300 	return LIBUSB_SUCCESS;
1301 }
1302 
1303 // Returns the api type, or 0 if not found/unsupported
get_api_type(HDEVINFO * dev_info,SP_DEVINFO_DATA * dev_info_data,int * api,int * sub_api)1304 static void get_api_type(HDEVINFO *dev_info, SP_DEVINFO_DATA *dev_info_data,
1305 	int *api, int *sub_api)
1306 {
1307 	// Precedence for filter drivers vs driver is in the order of this array
1308 	struct driver_lookup lookup[3] = {
1309 		{"\0\0", SPDRP_SERVICE, "driver"},
1310 		{"\0\0", SPDRP_UPPERFILTERS, "upper filter driver"},
1311 		{"\0\0", SPDRP_LOWERFILTERS, "lower filter driver"}
1312 	};
1313 	DWORD size, reg_type;
1314 	unsigned k, l;
1315 	int i, j;
1316 
1317 	// Check the service & filter names to know the API we should use
1318 	for (k = 0; k < 3; k++) {
1319 		if (pSetupDiGetDeviceRegistryPropertyA(*dev_info, dev_info_data, lookup[k].reg_prop,
1320 			&reg_type, (PBYTE)lookup[k].list, MAX_KEY_LENGTH, &size)) {
1321 			// Turn the REG_SZ SPDRP_SERVICE into REG_MULTI_SZ
1322 			if (lookup[k].reg_prop == SPDRP_SERVICE)
1323 				// our buffers are MAX_KEY_LENGTH + 1 so we can overflow if needed
1324 				lookup[k].list[strlen(lookup[k].list) + 1] = 0;
1325 
1326 			// MULTI_SZ is a pain to work with. Turn it into something much more manageable
1327 			// NB: none of the driver names we check against contain LIST_SEPARATOR,
1328 			// (currently ';'), so even if an unsupported one does, it's not an issue
1329 			for (l = 0; (lookup[k].list[l] != 0) || (lookup[k].list[l + 1] != 0); l++) {
1330 				if (lookup[k].list[l] == 0)
1331 					lookup[k].list[l] = LIST_SEPARATOR;
1332 			}
1333 			usbi_dbg(NULL, "%s(s): %s", lookup[k].designation, lookup[k].list);
1334 		} else {
1335 			if (GetLastError() != ERROR_INVALID_DATA)
1336 				usbi_dbg(NULL, "could not access %s: %s", lookup[k].designation, windows_error_str(0));
1337 			lookup[k].list[0] = 0;
1338 		}
1339 	}
1340 
1341 	for (i = 2; i < USB_API_MAX; i++) {
1342 		for (k = 0; k < 3; k++) {
1343 			j = get_sub_api(lookup[k].list, i);
1344 			if (j >= 0) {
1345 				usbi_dbg(NULL, "matched %s name against %s", lookup[k].designation,
1346 					(i != USB_API_WINUSBX) ? usb_api_backend[i].designation : usb_api_backend[i].driver_name_list[j]);
1347 				*api = i;
1348 				*sub_api = j;
1349 				return;
1350 			}
1351 		}
1352 	}
1353 }
1354 
set_composite_interface(struct libusb_context * ctx,struct libusb_device * dev,char * dev_interface_path,char * device_id,int api,int sub_api)1355 static int set_composite_interface(struct libusb_context *ctx, struct libusb_device *dev,
1356 	char *dev_interface_path, char *device_id, int api, int sub_api)
1357 {
1358 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
1359 	int interface_number;
1360 	const char *mi_str;
1361 
1362 	// Because MI_## are not necessarily in sequential order (some composite
1363 	// devices will have only MI_00 & MI_03 for instance), we retrieve the actual
1364 	// interface number from the path's MI value
1365 	mi_str = strstr(device_id, "MI_");
1366 	if ((mi_str != NULL) && isdigit((unsigned char)mi_str[3]) && isdigit((unsigned char)mi_str[4])) {
1367 		interface_number = ((mi_str[3] - '0') * 10) + (mi_str[4] - '0');
1368 	} else {
1369 		usbi_warn(ctx, "failure to read interface number for %s, using default value", device_id);
1370 		interface_number = 0;
1371 	}
1372 
1373 	if (interface_number >= USB_MAXINTERFACES) {
1374 		usbi_warn(ctx, "interface %d too large - ignoring interface path %s", interface_number, dev_interface_path);
1375 		return LIBUSB_ERROR_ACCESS;
1376 	}
1377 
1378 	if (priv->usb_interface[interface_number].path != NULL) {
1379 		if (api == USB_API_HID) {
1380 			// HID devices can have multiple collections (COL##) for each MI_## interface
1381 			usbi_dbg(ctx, "interface[%d] already set - ignoring HID collection: %s",
1382 				interface_number, device_id);
1383 			return LIBUSB_ERROR_ACCESS;
1384 		}
1385 		// In other cases, just use the latest data
1386 		safe_free(priv->usb_interface[interface_number].path);
1387 	}
1388 
1389 	usbi_dbg(ctx, "interface[%d] = %s", interface_number, dev_interface_path);
1390 	priv->usb_interface[interface_number].path = dev_interface_path;
1391 	priv->usb_interface[interface_number].apib = &usb_api_backend[api];
1392 	priv->usb_interface[interface_number].sub_api = sub_api;
1393 	if ((api == USB_API_HID) && (priv->hid == NULL)) {
1394 		priv->hid = calloc(1, sizeof(struct hid_device_priv));
1395 		if (priv->hid == NULL)
1396 			return LIBUSB_ERROR_NO_MEM;
1397 	}
1398 
1399 	return LIBUSB_SUCCESS;
1400 }
1401 
set_hid_interface(struct libusb_context * ctx,struct libusb_device * dev,char * dev_interface_path)1402 static int set_hid_interface(struct libusb_context *ctx, struct libusb_device *dev,
1403 	char *dev_interface_path)
1404 {
1405 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
1406 	uint8_t i;
1407 
1408 	if (priv->hid == NULL) {
1409 		usbi_err(ctx, "program assertion failed - parent is not HID");
1410 		return LIBUSB_ERROR_NO_DEVICE;
1411 	} else if (priv->hid->nb_interfaces == USB_MAXINTERFACES) {
1412 		usbi_err(ctx, "program assertion failed - max USB interfaces reached for HID device");
1413 		return LIBUSB_ERROR_NO_DEVICE;
1414 	}
1415 
1416 	for (i = 0; i < priv->hid->nb_interfaces; i++) {
1417 		if ((priv->usb_interface[i].path != NULL) && strcmp(priv->usb_interface[i].path, dev_interface_path) == 0) {
1418 			usbi_dbg(ctx, "interface[%u] already set to %s", i, dev_interface_path);
1419 			return LIBUSB_ERROR_ACCESS;
1420 		}
1421 	}
1422 
1423 	priv->usb_interface[priv->hid->nb_interfaces].path = dev_interface_path;
1424 	priv->usb_interface[priv->hid->nb_interfaces].apib = &usb_api_backend[USB_API_HID];
1425 	usbi_dbg(ctx, "interface[%u] = %s", priv->hid->nb_interfaces, dev_interface_path);
1426 	priv->hid->nb_interfaces++;
1427 	return LIBUSB_SUCCESS;
1428 }
1429 
1430 /*
1431  * get_device_list: libusb backend device enumeration function
1432  */
winusb_get_device_list(struct libusb_context * ctx,struct discovered_devs ** _discdevs)1433 static int winusb_get_device_list(struct libusb_context *ctx, struct discovered_devs **_discdevs)
1434 {
1435 	struct discovered_devs *discdevs;
1436 	HDEVINFO *dev_info, dev_info_intf, dev_info_enum;
1437 	SP_DEVINFO_DATA dev_info_data;
1438 	DWORD _index = 0;
1439 	GUID hid_guid;
1440 	int r = LIBUSB_SUCCESS;
1441 	int api, sub_api;
1442 	unsigned int pass, i, j;
1443 	char enumerator[16];
1444 	char dev_id[MAX_PATH_LENGTH];
1445 	struct libusb_device *dev, *parent_dev;
1446 	struct winusb_device_priv *priv, *parent_priv;
1447 	char *dev_interface_path = NULL;
1448 	unsigned long session_id;
1449 	DWORD size, port_nr, reg_type, install_state;
1450 	HKEY key;
1451 	char guid_string[MAX_GUID_STRING_LENGTH];
1452 	GUID *if_guid;
1453 	LONG s;
1454 #define HUB_PASS 0
1455 #define DEV_PASS 1
1456 #define HCD_PASS 2
1457 #define GEN_PASS 3
1458 #define HID_PASS 4
1459 #define EXT_PASS 5
1460 	// Keep a list of guids that will be enumerated
1461 #define GUID_SIZE_STEP 8
1462 	const GUID **guid_list, **new_guid_list;
1463 	unsigned int guid_size = GUID_SIZE_STEP;
1464 	unsigned int nb_guids;
1465 	// Keep a list of PnP enumerator strings that are found
1466 	const char *usb_enumerator[8] = { "USB" };
1467 	unsigned int nb_usb_enumerators = 1;
1468 	unsigned int usb_enum_index = 0;
1469 	// Keep a list of newly allocated devs to unref
1470 #define UNREF_SIZE_STEP 16
1471 	libusb_device **unref_list, **new_unref_list;
1472 	unsigned int unref_size = UNREF_SIZE_STEP;
1473 	unsigned int unref_cur = 0;
1474 
1475 	// PASS 1 : (re)enumerate HCDs (allows for HCD hotplug)
1476 	// PASS 2 : (re)enumerate HUBS
1477 	// PASS 3 : (re)enumerate generic USB devices (including driverless)
1478 	//           and list additional USB device interface GUIDs to explore
1479 	// PASS 4 : (re)enumerate master USB devices that have a device interface
1480 	// PASS 5+: (re)enumerate device interfaced GUIDs (including HID) and
1481 	//           set the device interfaces.
1482 
1483 	// Init the GUID table
1484 	guid_list = malloc(guid_size * sizeof(void *));
1485 	if (guid_list == NULL) {
1486 		usbi_err(ctx, "failed to alloc guid list");
1487 		return LIBUSB_ERROR_NO_MEM;
1488 	}
1489 
1490 	guid_list[HUB_PASS] = &GUID_DEVINTERFACE_USB_HUB;
1491 	guid_list[DEV_PASS] = &GUID_DEVINTERFACE_USB_DEVICE;
1492 	guid_list[HCD_PASS] = &GUID_DEVINTERFACE_USB_HOST_CONTROLLER;
1493 	guid_list[GEN_PASS] = NULL;
1494 	if (HidD_GetHidGuid != NULL) {
1495 		HidD_GetHidGuid(&hid_guid);
1496 		guid_list[HID_PASS] = &hid_guid;
1497 	} else {
1498 		guid_list[HID_PASS] = NULL;
1499 	}
1500 	nb_guids = EXT_PASS;
1501 
1502 	unref_list = malloc(unref_size * sizeof(void *));
1503 	if (unref_list == NULL) {
1504 		usbi_err(ctx, "failed to alloc unref list");
1505 		free((void *)guid_list);
1506 		return LIBUSB_ERROR_NO_MEM;
1507 	}
1508 
1509 	dev_info_intf = pSetupDiGetClassDevsA(NULL, NULL, NULL, DIGCF_ALLCLASSES | DIGCF_PRESENT | DIGCF_DEVICEINTERFACE);
1510 	if (dev_info_intf == INVALID_HANDLE_VALUE) {
1511 		usbi_err(ctx, "failed to obtain device info list: %s", windows_error_str(0));
1512 		free(unref_list);
1513 		free((void *)guid_list);
1514 		return LIBUSB_ERROR_OTHER;
1515 	}
1516 
1517 	for (pass = 0; ((pass < nb_guids) && (r == LIBUSB_SUCCESS)); pass++) {
1518 //#define ENUM_DEBUG
1519 #if defined(ENABLE_LOGGING) && defined(ENUM_DEBUG)
1520 		const char * const passname[] = {"HUB", "DEV", "HCD", "GEN", "HID", "EXT"};
1521 		usbi_dbg(ctx, "#### PROCESSING %ss %s", passname[MIN(pass, EXT_PASS)], guid_to_string(guid_list[pass], guid_string));
1522 #endif
1523 		if ((pass == HID_PASS) && (guid_list[HID_PASS] == NULL))
1524 			continue;
1525 
1526 		dev_info = (pass != GEN_PASS) ? &dev_info_intf : &dev_info_enum;
1527 
1528 		for (i = 0; ; i++) {
1529 			// safe loop: free up any (unprotected) dynamic resource
1530 			// NB: this is always executed before breaking the loop
1531 			safe_free(dev_interface_path);
1532 			priv = parent_priv = NULL;
1533 			dev = parent_dev = NULL;
1534 
1535 			// Safe loop: end of loop conditions
1536 			if (r != LIBUSB_SUCCESS)
1537 				break;
1538 
1539 			if ((pass == HCD_PASS) && (i == UINT8_MAX)) {
1540 				usbi_warn(ctx, "program assertion failed - found more than %u buses, skipping the rest", UINT8_MAX);
1541 				break;
1542 			}
1543 
1544 			if (pass != GEN_PASS) {
1545 				// Except for GEN, all passes deal with device interfaces
1546 				r = get_interface_details(ctx, *dev_info, &dev_info_data, guid_list[pass], &_index, &dev_interface_path);
1547 				if ((r != LIBUSB_SUCCESS) || (dev_interface_path == NULL)) {
1548 					_index = 0;
1549 					break;
1550 				}
1551 			} else {
1552 				// Workaround for a Nec/Renesas USB 3.0 driver bug where root hubs are
1553 				// being listed under the "NUSB3" PnP Symbolic Name rather than "USB".
1554 				// The Intel USB 3.0 driver behaves similar, but uses "IUSB3"
1555 				// The Intel Alpine Ridge USB 3.1 driver uses "IARUSB3"
1556 				for (; usb_enum_index < nb_usb_enumerators; usb_enum_index++) {
1557 					if (get_devinfo_data(ctx, dev_info, &dev_info_data, usb_enumerator[usb_enum_index], i))
1558 						break;
1559 					i = 0;
1560 				}
1561 				if (usb_enum_index == nb_usb_enumerators)
1562 					break;
1563 			}
1564 
1565 			// Read the Device ID path
1566 			if (!pSetupDiGetDeviceInstanceIdA(*dev_info, &dev_info_data, dev_id, sizeof(dev_id), NULL)) {
1567 				usbi_warn(ctx, "could not read the device instance ID for devInst %lX, skipping",
1568 					  ULONG_CAST(dev_info_data.DevInst));
1569 				continue;
1570 			}
1571 
1572 #ifdef ENUM_DEBUG
1573 			usbi_dbg(ctx, "PRO: %s", dev_id);
1574 #endif
1575 
1576 			// Set API to use or get additional data from generic pass
1577 			api = USB_API_UNSUPPORTED;
1578 			sub_api = SUB_API_NOTSET;
1579 			switch (pass) {
1580 			case HCD_PASS:
1581 				break;
1582 			case HUB_PASS:
1583 				api = USB_API_HUB;
1584 				// Fetch the PnP enumerator class for this hub
1585 				// This will allow us to enumerate all classes during the GEN pass
1586 				if (!pSetupDiGetDeviceRegistryPropertyA(*dev_info, &dev_info_data, SPDRP_ENUMERATOR_NAME,
1587 					NULL, (PBYTE)enumerator, sizeof(enumerator), NULL)) {
1588 					usbi_err(ctx, "could not read enumerator string for device '%s': %s", dev_id, windows_error_str(0));
1589 					LOOP_BREAK(LIBUSB_ERROR_OTHER);
1590 				}
1591 				for (j = 0; j < nb_usb_enumerators; j++) {
1592 					if (strcmp(usb_enumerator[j], enumerator) == 0)
1593 						break;
1594 				}
1595 				if (j == nb_usb_enumerators) {
1596 					usbi_dbg(ctx, "found new PnP enumerator string '%s'", enumerator);
1597 					if (nb_usb_enumerators < ARRAYSIZE(usb_enumerator)) {
1598 						usb_enumerator[nb_usb_enumerators] = _strdup(enumerator);
1599 						if (usb_enumerator[nb_usb_enumerators] != NULL) {
1600 							nb_usb_enumerators++;
1601 						} else {
1602 							usbi_err(ctx, "could not allocate enumerator string '%s'", enumerator);
1603 							LOOP_BREAK(LIBUSB_ERROR_NO_MEM);
1604 						}
1605 					} else {
1606 						usbi_warn(ctx, "too many enumerator strings, some devices may not be accessible");
1607 					}
1608 				}
1609 				break;
1610 			case GEN_PASS:
1611 				// We use the GEN pass to detect driverless devices...
1612 				if (!pSetupDiGetDeviceRegistryPropertyA(*dev_info, &dev_info_data, SPDRP_DRIVER,
1613 					NULL, NULL, 0, NULL) && (GetLastError() != ERROR_INSUFFICIENT_BUFFER)) {
1614 					usbi_info(ctx, "The following device has no driver: '%s'", dev_id);
1615 					usbi_info(ctx, "libusb will not be able to access it");
1616 				}
1617 				// ...and to add the additional device interface GUIDs
1618 				key = pSetupDiOpenDevRegKey(*dev_info, &dev_info_data, DICS_FLAG_GLOBAL, 0, DIREG_DEV, KEY_READ);
1619 				if (key == INVALID_HANDLE_VALUE)
1620 					break;
1621 				// Look for both DeviceInterfaceGUIDs *and* DeviceInterfaceGUID, in that order
1622 				// If multiple GUIDs just process the first and ignore the others
1623 				size = sizeof(guid_string);
1624 				s = pRegQueryValueExA(key, "DeviceInterfaceGUIDs", NULL, &reg_type,
1625 					(LPBYTE)guid_string, &size);
1626 				if (s == ERROR_FILE_NOT_FOUND)
1627 					s = pRegQueryValueExA(key, "DeviceInterfaceGUID", NULL, &reg_type,
1628 						(LPBYTE)guid_string, &size);
1629 				pRegCloseKey(key);
1630 				if (s == ERROR_FILE_NOT_FOUND) {
1631 					break; /* no DeviceInterfaceGUID registered */
1632 				} else if (s != ERROR_SUCCESS && s != ERROR_MORE_DATA) {
1633 					usbi_warn(ctx, "unexpected error from pRegQueryValueExA for '%s'", dev_id);
1634 					break;
1635 				}
1636 				// https://docs.microsoft.com/en-us/windows/win32/api/winreg/nf-winreg-regqueryvalueexa#remarks
1637 				// - "string may not have been stored with the proper terminating null characters"
1638 				// - "Note that REG_MULTI_SZ strings could have two terminating null characters"
1639 			        if ((reg_type == REG_SZ && size >= sizeof(guid_string) - sizeof(char))
1640 				    || (reg_type == REG_MULTI_SZ && size >= sizeof(guid_string) - 2 * sizeof(char))) {
1641 					if (nb_guids == guid_size) {
1642 						new_guid_list = realloc((void *)guid_list, (guid_size + GUID_SIZE_STEP) * sizeof(void *));
1643 						if (new_guid_list == NULL) {
1644 							usbi_err(ctx, "failed to realloc guid list");
1645 							LOOP_BREAK(LIBUSB_ERROR_NO_MEM);
1646 						}
1647 						guid_list = new_guid_list;
1648 						guid_size += GUID_SIZE_STEP;
1649 					}
1650 					if_guid = malloc(sizeof(*if_guid));
1651 					if (if_guid == NULL) {
1652 						usbi_err(ctx, "failed to alloc if_guid");
1653 						LOOP_BREAK(LIBUSB_ERROR_NO_MEM);
1654 					}
1655 					if (!string_to_guid(guid_string, if_guid)) {
1656 						usbi_warn(ctx, "device '%s' has malformed DeviceInterfaceGUID string '%s', skipping", dev_id, guid_string);
1657 						free(if_guid);
1658 					} else {
1659 						// Check if we've already seen this GUID
1660 						for (j = EXT_PASS; j < nb_guids; j++) {
1661 							if (memcmp(guid_list[j], if_guid, sizeof(*if_guid)) == 0)
1662 								break;
1663 						}
1664 						if (j == nb_guids) {
1665 							usbi_dbg(ctx, "extra GUID: %s", guid_string);
1666 							guid_list[nb_guids++] = if_guid;
1667 						} else {
1668 							// Duplicate, ignore
1669 							free(if_guid);
1670 						}
1671 					}
1672 				} else {
1673 					usbi_warn(ctx, "unexpected type/size of DeviceInterfaceGUID for '%s'", dev_id);
1674 				}
1675 				break;
1676 			case HID_PASS:
1677 				api = USB_API_HID;
1678 				break;
1679 			default:
1680 				// Get the API type (after checking that the driver installation is OK)
1681 				if ((!pSetupDiGetDeviceRegistryPropertyA(*dev_info, &dev_info_data, SPDRP_INSTALL_STATE,
1682 					NULL, (PBYTE)&install_state, sizeof(install_state), &size)) || (size != sizeof(install_state))) {
1683 					usbi_warn(ctx, "could not detect installation state of driver for '%s': %s",
1684 						dev_id, windows_error_str(0));
1685 				} else if (install_state != 0) {
1686 					usbi_warn(ctx, "driver for device '%s' is reporting an issue (code: %lu) - skipping",
1687 						dev_id, ULONG_CAST(install_state));
1688 					continue;
1689 				}
1690 				get_api_type(dev_info, &dev_info_data, &api, &sub_api);
1691 				break;
1692 			}
1693 
1694 			// Find parent device (for the passes that need it)
1695 			if (pass >= GEN_PASS) {
1696 				parent_dev = get_ancestor(ctx, dev_info_data.DevInst, NULL);
1697 				if (parent_dev == NULL) {
1698 					// Root hubs will not have a parent
1699 					dev = usbi_get_device_by_session_id(ctx, (unsigned long)dev_info_data.DevInst);
1700 					if (dev != NULL) {
1701 						priv = usbi_get_device_priv(dev);
1702 						if (priv->root_hub)
1703 							goto track_unref;
1704 						libusb_unref_device(dev);
1705 					}
1706 
1707 					usbi_dbg(ctx, "unlisted ancestor for '%s' (non USB HID, newly connected, etc.) - ignoring", dev_id);
1708 					continue;
1709 				}
1710 
1711 				parent_priv = usbi_get_device_priv(parent_dev);
1712 				// virtual USB devices are also listed during GEN - don't process these yet
1713 				if ((pass == GEN_PASS) && (parent_priv->apib->id != USB_API_HUB)) {
1714 					libusb_unref_device(parent_dev);
1715 					continue;
1716 				}
1717 			}
1718 
1719 			// Create new or match existing device, using the devInst as session id
1720 			if ((pass <= GEN_PASS) && (pass != HCD_PASS)) {	// For subsequent passes, we'll lookup the parent
1721 				// These are the passes that create "new" devices
1722 				session_id = (unsigned long)dev_info_data.DevInst;
1723 				dev = usbi_get_device_by_session_id(ctx, session_id);
1724 				if (dev == NULL) {
1725 				alloc_device:
1726 					usbi_dbg(ctx, "allocating new device for session [%lX]", session_id);
1727 					dev = usbi_alloc_device(ctx, session_id);
1728 					if (dev == NULL)
1729 						LOOP_BREAK(LIBUSB_ERROR_NO_MEM);
1730 
1731 					priv = winusb_device_priv_init(dev);
1732 					priv->dev_id = _strdup(dev_id);
1733 					priv->class_guid = dev_info_data.ClassGuid;
1734 					if (priv->dev_id == NULL) {
1735 						libusb_unref_device(dev);
1736 						LOOP_BREAK(LIBUSB_ERROR_NO_MEM);
1737 					}
1738 				} else {
1739 					usbi_dbg(ctx, "found existing device for session [%lX]", session_id);
1740 
1741 					priv = usbi_get_device_priv(dev);
1742 					if (strcmp(priv->dev_id, dev_id) != 0) {
1743 						usbi_dbg(ctx, "device instance ID for session [%lX] changed", session_id);
1744 						usbi_disconnect_device(dev);
1745 						libusb_unref_device(dev);
1746 						goto alloc_device;
1747 					}
1748 					if (!IsEqualGUID(&priv->class_guid, &dev_info_data.ClassGuid)) {
1749 						usbi_dbg(ctx, "device class GUID for session [%lX] changed", session_id);
1750 						usbi_disconnect_device(dev);
1751 						libusb_unref_device(dev);
1752 						goto alloc_device;
1753 					}
1754 				}
1755 
1756 			track_unref:
1757 				// Keep track of devices that need unref
1758 				if (unref_cur == unref_size) {
1759 					new_unref_list = realloc(unref_list, (unref_size + UNREF_SIZE_STEP) * sizeof(void *));
1760 					if (new_unref_list == NULL) {
1761 						usbi_err(ctx, "could not realloc list for unref - aborting");
1762 						LOOP_BREAK(LIBUSB_ERROR_NO_MEM);
1763 					}
1764 					unref_list = new_unref_list;
1765 					unref_size += UNREF_SIZE_STEP;
1766 				}
1767 				unref_list[unref_cur++] = dev;
1768 			}
1769 
1770 			// Setup device
1771 			switch (pass) {
1772 			case HUB_PASS:
1773 			case DEV_PASS:
1774 				// If the device has already been setup, don't do it again
1775 				if (priv->path != NULL)
1776 					break;
1777 				// Take care of API initialization
1778 				priv->path = dev_interface_path;
1779 				dev_interface_path = NULL;
1780 				priv->apib = &usb_api_backend[api];
1781 				priv->sub_api = sub_api;
1782 				switch (api) {
1783 				case USB_API_COMPOSITE:
1784 				case USB_API_HUB:
1785 					break;
1786 				case USB_API_HID:
1787 					priv->hid = calloc(1, sizeof(struct hid_device_priv));
1788 					if (priv->hid == NULL)
1789 						LOOP_BREAK(LIBUSB_ERROR_NO_MEM);
1790 					break;
1791 				default:
1792 					// For other devices, the first interface is the same as the device
1793 					priv->usb_interface[0].path = _strdup(priv->path);
1794 					if (priv->usb_interface[0].path == NULL)
1795 						LOOP_BREAK(LIBUSB_ERROR_NO_MEM);
1796 					// The following is needed if we want API calls to work for both simple
1797 					// and composite devices.
1798 					for (j = 0; j < USB_MAXINTERFACES; j++)
1799 						priv->usb_interface[j].apib = &usb_api_backend[api];
1800 					break;
1801 				}
1802 				break;
1803 			case HCD_PASS:
1804 				r = enumerate_hcd_root_hub(ctx, dev_id, (uint8_t)(i + 1), dev_info_data.DevInst);
1805 				break;
1806 			case GEN_PASS:
1807 				port_nr = 0;
1808 				if (!get_dev_port_number(*dev_info, &dev_info_data, &port_nr))
1809 					usbi_warn(ctx, "could not retrieve port number for device '%s': %s", dev_id, windows_error_str(0));
1810 				r = init_device(dev, parent_dev, (uint8_t)port_nr, dev_info_data.DevInst);
1811 				if (r == LIBUSB_SUCCESS) {
1812 					// Append device to the list of discovered devices
1813 					discdevs = discovered_devs_append(*_discdevs, dev);
1814 					if (!discdevs)
1815 						LOOP_BREAK(LIBUSB_ERROR_NO_MEM);
1816 
1817 					*_discdevs = discdevs;
1818 				} else {
1819 					// Failed to initialize a single device doesn't stop us from enumerating all other devices,
1820 					// but we skip it (don't add to list of discovered devices)
1821 					usbi_warn(ctx, "failed to initialize device '%s'", priv->dev_id);
1822 					r = LIBUSB_SUCCESS;
1823 				}
1824 				break;
1825 			default: // HID_PASS and later
1826 				if (parent_priv->apib->id == USB_API_HID || parent_priv->apib->id == USB_API_COMPOSITE) {
1827 					if (parent_priv->apib->id == USB_API_HID) {
1828 						usbi_dbg(ctx, "setting HID interface for [%lX]:", parent_dev->session_data);
1829 						r = set_hid_interface(ctx, parent_dev, dev_interface_path);
1830 					} else {
1831 						usbi_dbg(ctx, "setting composite interface for [%lX]:", parent_dev->session_data);
1832 						r = set_composite_interface(ctx, parent_dev, dev_interface_path, dev_id, api, sub_api);
1833 					}
1834 					switch (r) {
1835 					case LIBUSB_SUCCESS:
1836 						dev_interface_path = NULL;
1837 						break;
1838 					case LIBUSB_ERROR_ACCESS:
1839 						// interface has already been set => make sure dev_interface_path is freed then
1840 						r = LIBUSB_SUCCESS;
1841 						break;
1842 					default:
1843 						LOOP_BREAK(r);
1844 						break;
1845 					}
1846 				}
1847 				libusb_unref_device(parent_dev);
1848 				break;
1849 			}
1850 		}
1851 	}
1852 
1853 	pSetupDiDestroyDeviceInfoList(dev_info_intf);
1854 
1855 	// Free any additional GUIDs
1856 	for (pass = EXT_PASS; pass < nb_guids; pass++)
1857 		free((void *)guid_list[pass]);
1858 	free((void *)guid_list);
1859 
1860 	// Free any PnP enumerator strings
1861 	for (i = 1; i < nb_usb_enumerators; i++)
1862 		free((void *)usb_enumerator[i]);
1863 
1864 	// Unref newly allocated devs
1865 	for (i = 0; i < unref_cur; i++)
1866 		libusb_unref_device(unref_list[i]);
1867 	free(unref_list);
1868 
1869 	return r;
1870 }
1871 
winusb_get_config_descriptor(struct libusb_device * dev,uint8_t config_index,void * buffer,size_t len)1872 static int winusb_get_config_descriptor(struct libusb_device *dev, uint8_t config_index, void *buffer, size_t len)
1873 {
1874 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
1875 	PUSB_CONFIGURATION_DESCRIPTOR config_header;
1876 
1877 	if ((priv->config_descriptor == NULL) || (priv->config_descriptor[config_index] == NULL))
1878 		return LIBUSB_ERROR_NOT_FOUND;
1879 
1880 	config_header = priv->config_descriptor[config_index];
1881 
1882 	len = MIN(len, config_header->wTotalLength);
1883 	memcpy(buffer, config_header, len);
1884 	return (int)len;
1885 }
1886 
winusb_get_config_descriptor_by_value(struct libusb_device * dev,uint8_t bConfigurationValue,void ** buffer)1887 static int winusb_get_config_descriptor_by_value(struct libusb_device *dev, uint8_t bConfigurationValue,
1888 	void **buffer)
1889 {
1890 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
1891 	PUSB_CONFIGURATION_DESCRIPTOR config_header;
1892 	uint8_t index;
1893 
1894 	if (priv->config_descriptor == NULL)
1895 		return LIBUSB_ERROR_NOT_FOUND;
1896 
1897 	for (index = 0; index < dev->device_descriptor.bNumConfigurations; index++) {
1898 		config_header = priv->config_descriptor[index];
1899 		if (config_header == NULL)
1900 			continue;
1901 		if (config_header->bConfigurationValue == bConfigurationValue) {
1902 			*buffer = config_header;
1903 			return (int)config_header->wTotalLength;
1904 		}
1905 	}
1906 
1907 	return LIBUSB_ERROR_NOT_FOUND;
1908 }
1909 
1910 /*
1911  * return the cached copy of the active config descriptor
1912  */
winusb_get_active_config_descriptor(struct libusb_device * dev,void * buffer,size_t len)1913 static int winusb_get_active_config_descriptor(struct libusb_device *dev, void *buffer, size_t len)
1914 {
1915 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
1916 	void *config_desc;
1917 	int r;
1918 
1919 	if (priv->active_config == 0)
1920 		return LIBUSB_ERROR_NOT_FOUND;
1921 
1922 	r = winusb_get_config_descriptor_by_value(dev, priv->active_config, &config_desc);
1923 	if (r < 0)
1924 		return r;
1925 
1926 	len = MIN(len, (size_t)r);
1927 	memcpy(buffer, config_desc, len);
1928 	return (int)len;
1929 }
1930 
winusb_open(struct libusb_device_handle * dev_handle)1931 static int winusb_open(struct libusb_device_handle *dev_handle)
1932 {
1933 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
1934 
1935 	CHECK_SUPPORTED_API(priv->apib, open);
1936 
1937 	return priv->apib->open(SUB_API_NOTSET, dev_handle);
1938 }
1939 
winusb_close(struct libusb_device_handle * dev_handle)1940 static void winusb_close(struct libusb_device_handle *dev_handle)
1941 {
1942 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
1943 
1944 	if (priv->apib->close)
1945 		priv->apib->close(SUB_API_NOTSET, dev_handle);
1946 }
1947 
winusb_get_configuration(struct libusb_device_handle * dev_handle,uint8_t * config)1948 static int winusb_get_configuration(struct libusb_device_handle *dev_handle, uint8_t *config)
1949 {
1950 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
1951 
1952 	*config = priv->active_config;
1953 	return LIBUSB_SUCCESS;
1954 }
1955 
1956 /*
1957  * from http://msdn.microsoft.com/en-us/library/ms793522.aspx: "The port driver
1958  * does not currently expose a service that allows higher-level drivers to set
1959  * the configuration."
1960  */
winusb_set_configuration(struct libusb_device_handle * dev_handle,uint8_t config)1961 static int winusb_set_configuration(struct libusb_device_handle *dev_handle, uint8_t config)
1962 {
1963 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
1964 	int r = LIBUSB_SUCCESS;
1965 
1966 	r = libusb_control_transfer(dev_handle, LIBUSB_ENDPOINT_OUT |
1967 		LIBUSB_REQUEST_TYPE_STANDARD | LIBUSB_RECIPIENT_DEVICE,
1968 		LIBUSB_REQUEST_SET_CONFIGURATION, config,
1969 		0, NULL, 0, 1000);
1970 
1971 	if (r == LIBUSB_SUCCESS)
1972 		priv->active_config = config;
1973 
1974 	return r;
1975 }
1976 
winusb_claim_interface(struct libusb_device_handle * dev_handle,uint8_t iface)1977 static int winusb_claim_interface(struct libusb_device_handle *dev_handle, uint8_t iface)
1978 {
1979 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
1980 	int r;
1981 
1982 	CHECK_SUPPORTED_API(priv->apib, claim_interface);
1983 
1984 	safe_free(priv->usb_interface[iface].endpoint);
1985 	priv->usb_interface[iface].nb_endpoints = 0;
1986 
1987 	r = priv->apib->claim_interface(SUB_API_NOTSET, dev_handle, iface);
1988 
1989 	if (r == LIBUSB_SUCCESS)
1990 		r = windows_assign_endpoints(dev_handle, iface, 0);
1991 
1992 	return r;
1993 }
1994 
winusb_set_interface_altsetting(struct libusb_device_handle * dev_handle,uint8_t iface,uint8_t altsetting)1995 static int winusb_set_interface_altsetting(struct libusb_device_handle *dev_handle, uint8_t iface, uint8_t altsetting)
1996 {
1997 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
1998 	int r;
1999 
2000 	CHECK_SUPPORTED_API(priv->apib, set_interface_altsetting);
2001 
2002 	safe_free(priv->usb_interface[iface].endpoint);
2003 	priv->usb_interface[iface].nb_endpoints = 0;
2004 
2005 	r = priv->apib->set_interface_altsetting(SUB_API_NOTSET, dev_handle, iface, altsetting);
2006 
2007 	if (r == LIBUSB_SUCCESS)
2008 		r = windows_assign_endpoints(dev_handle, iface, altsetting);
2009 
2010 	return r;
2011 }
2012 
winusb_release_interface(struct libusb_device_handle * dev_handle,uint8_t iface)2013 static int winusb_release_interface(struct libusb_device_handle *dev_handle, uint8_t iface)
2014 {
2015 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2016 
2017 	CHECK_SUPPORTED_API(priv->apib, release_interface);
2018 
2019 	return priv->apib->release_interface(SUB_API_NOTSET, dev_handle, iface);
2020 }
2021 
winusb_clear_halt(struct libusb_device_handle * dev_handle,unsigned char endpoint)2022 static int winusb_clear_halt(struct libusb_device_handle *dev_handle, unsigned char endpoint)
2023 {
2024 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2025 
2026 	CHECK_SUPPORTED_API(priv->apib, clear_halt);
2027 
2028 	return priv->apib->clear_halt(SUB_API_NOTSET, dev_handle, endpoint);
2029 }
2030 
winusb_reset_device(struct libusb_device_handle * dev_handle)2031 static int winusb_reset_device(struct libusb_device_handle *dev_handle)
2032 {
2033 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2034 
2035 	CHECK_SUPPORTED_API(priv->apib, reset_device);
2036 
2037 	return priv->apib->reset_device(SUB_API_NOTSET, dev_handle);
2038 }
2039 
winusb_destroy_device(struct libusb_device * dev)2040 static void winusb_destroy_device(struct libusb_device *dev)
2041 {
2042 	winusb_device_priv_release(dev);
2043 }
2044 
winusb_clear_transfer_priv(struct usbi_transfer * itransfer)2045 static void winusb_clear_transfer_priv(struct usbi_transfer *itransfer)
2046 {
2047 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
2048 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
2049 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
2050 	int sub_api = priv->sub_api;
2051 
2052 	safe_free(transfer_priv->hid_buffer);
2053 
2054 	if (transfer->type == LIBUSB_TRANSFER_TYPE_ISOCHRONOUS && sub_api == SUB_API_WINUSB) {
2055 		if (transfer_priv->isoch_buffer_handle != NULL) {
2056 			if (WinUSBX[sub_api].UnregisterIsochBuffer(transfer_priv->isoch_buffer_handle)) {
2057 				transfer_priv->isoch_buffer_handle = NULL;
2058 			} else {
2059 				usbi_warn(TRANSFER_CTX(transfer), "failed to unregister WinUSB isoch buffer: %s", windows_error_str(0));
2060 			}
2061 		}
2062 	}
2063 
2064 	safe_free(transfer_priv->iso_context);
2065 
2066 	// When auto claim is in use, attempt to release the auto-claimed interface
2067 	auto_release(itransfer);
2068 }
2069 
winusb_submit_transfer(struct usbi_transfer * itransfer)2070 static int winusb_submit_transfer(struct usbi_transfer *itransfer)
2071 {
2072 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
2073 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
2074 	int (*transfer_fn)(int, struct usbi_transfer *);
2075 
2076 	switch (transfer->type) {
2077 	case LIBUSB_TRANSFER_TYPE_CONTROL:
2078 		transfer_fn = priv->apib->submit_control_transfer;
2079 		break;
2080 	case LIBUSB_TRANSFER_TYPE_BULK:
2081 	case LIBUSB_TRANSFER_TYPE_INTERRUPT:
2082 		transfer_fn = priv->apib->submit_bulk_transfer;
2083 		break;
2084 	case LIBUSB_TRANSFER_TYPE_ISOCHRONOUS:
2085 		transfer_fn = priv->apib->submit_iso_transfer;
2086 		break;
2087 	default:
2088 		// Should not get here since windows_submit_transfer() validates
2089 		// the transfer->type field
2090 		usbi_err(TRANSFER_CTX(transfer), "unknown endpoint type %d", transfer->type);
2091 		return LIBUSB_ERROR_INVALID_PARAM;
2092 	}
2093 
2094 	if (transfer_fn == NULL) {
2095 		usbi_warn(TRANSFER_CTX(transfer),
2096 			"unsupported transfer type %d (unrecognized device driver)",
2097 			transfer->type);
2098 		return LIBUSB_ERROR_NOT_SUPPORTED;
2099 	}
2100 
2101 	return transfer_fn(SUB_API_NOTSET, itransfer);
2102 }
2103 
winusb_cancel_transfer(struct usbi_transfer * itransfer)2104 static int winusb_cancel_transfer(struct usbi_transfer *itransfer)
2105 {
2106 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
2107 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
2108 
2109 	CHECK_SUPPORTED_API(priv->apib, cancel_transfer);
2110 
2111 	return priv->apib->cancel_transfer(SUB_API_NOTSET, itransfer);
2112 }
2113 
winusb_copy_transfer_data(struct usbi_transfer * itransfer,DWORD length)2114 static enum libusb_transfer_status winusb_copy_transfer_data(struct usbi_transfer *itransfer, DWORD length)
2115 {
2116 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
2117 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
2118 
2119 	if (priv->apib->copy_transfer_data == NULL) {
2120 		usbi_err(TRANSFER_CTX(transfer), "program assertion failed - no function to copy transfer data");
2121 		return LIBUSB_TRANSFER_ERROR;
2122 	}
2123 
2124 	return priv->apib->copy_transfer_data(SUB_API_NOTSET, itransfer, length);
2125 }
2126 
2127 // NB: MSVC6 does not support named initializers.
2128 const struct windows_backend winusb_backend = {
2129 	winusb_init,
2130 	winusb_exit,
2131 	winusb_get_device_list,
2132 	winusb_open,
2133 	winusb_close,
2134 	winusb_get_active_config_descriptor,
2135 	winusb_get_config_descriptor,
2136 	winusb_get_config_descriptor_by_value,
2137 	winusb_get_configuration,
2138 	winusb_set_configuration,
2139 	winusb_claim_interface,
2140 	winusb_release_interface,
2141 	winusb_set_interface_altsetting,
2142 	winusb_clear_halt,
2143 	winusb_reset_device,
2144 	winusb_destroy_device,
2145 	winusb_submit_transfer,
2146 	winusb_cancel_transfer,
2147 	winusb_clear_transfer_priv,
2148 	winusb_copy_transfer_data,
2149 };
2150 
2151 /*
2152  * USB API backends
2153  */
2154 
2155 static const char * const composite_driver_names[] = {"USBCCGP"};
2156 static const char * const winusbx_driver_names[] = {"libusbK", "libusb0", "WinUSB"};
2157 static const char * const hid_driver_names[] = {"HIDUSB", "MOUHID", "KBDHID"};
2158 const struct windows_usb_api_backend usb_api_backend[USB_API_MAX] = {
2159 	{
2160 		USB_API_UNSUPPORTED,
2161 		"Unsupported API",
2162 		NULL,	/* driver_name_list */
2163 		0,	/* nb_driver_names */
2164 		NULL,	/* init */
2165 		NULL,	/* exit */
2166 		NULL,	/* open */
2167 		NULL,	/* close */
2168 		NULL,	/* configure_endpoints */
2169 		NULL,	/* claim_interface */
2170 		NULL,	/* set_interface_altsetting */
2171 		NULL,	/* release_interface */
2172 		NULL,	/* clear_halt */
2173 		NULL,	/* reset_device */
2174 		NULL,	/* submit_bulk_transfer */
2175 		NULL,	/* submit_iso_transfer */
2176 		NULL,	/* submit_control_transfer */
2177 		NULL,	/* cancel_transfer */
2178 		NULL,	/* copy_transfer_data */
2179 	},
2180 	{
2181 		USB_API_HUB,
2182 		"HUB API",
2183 		NULL,	/* driver_name_list */
2184 		0,	/* nb_driver_names */
2185 		NULL,	/* init */
2186 		NULL,	/* exit */
2187 		NULL,	/* open */
2188 		NULL,	/* close */
2189 		NULL,	/* configure_endpoints */
2190 		NULL,	/* claim_interface */
2191 		NULL,	/* set_interface_altsetting */
2192 		NULL,	/* release_interface */
2193 		NULL,	/* clear_halt */
2194 		NULL,	/* reset_device */
2195 		NULL,	/* submit_bulk_transfer */
2196 		NULL,	/* submit_iso_transfer */
2197 		NULL,	/* submit_control_transfer */
2198 		NULL,	/* cancel_transfer */
2199 		NULL,	/* copy_transfer_data */
2200 	},
2201 	{
2202 		USB_API_COMPOSITE,
2203 		"Composite API",
2204 		composite_driver_names,
2205 		ARRAYSIZE(composite_driver_names),
2206 		NULL,	/* init */
2207 		NULL,	/* exit */
2208 		composite_open,
2209 		composite_close,
2210 		NULL,	/* configure_endpoints */
2211 		composite_claim_interface,
2212 		composite_set_interface_altsetting,
2213 		composite_release_interface,
2214 		composite_clear_halt,
2215 		composite_reset_device,
2216 		composite_submit_bulk_transfer,
2217 		composite_submit_iso_transfer,
2218 		composite_submit_control_transfer,
2219 		composite_cancel_transfer,
2220 		composite_copy_transfer_data,
2221 	},
2222 	{
2223 		USB_API_WINUSBX,
2224 		"WinUSB-like APIs",
2225 		winusbx_driver_names,
2226 		ARRAYSIZE(winusbx_driver_names),
2227 		winusbx_init,
2228 		winusbx_exit,
2229 		winusbx_open,
2230 		winusbx_close,
2231 		winusbx_configure_endpoints,
2232 		winusbx_claim_interface,
2233 		winusbx_set_interface_altsetting,
2234 		winusbx_release_interface,
2235 		winusbx_clear_halt,
2236 		winusbx_reset_device,
2237 		winusbx_submit_bulk_transfer,
2238 		winusbx_submit_iso_transfer,
2239 		winusbx_submit_control_transfer,
2240 		winusbx_cancel_transfer,
2241 		winusbx_copy_transfer_data,
2242 	},
2243 	{
2244 		USB_API_HID,
2245 		"HID API",
2246 		hid_driver_names,
2247 		ARRAYSIZE(hid_driver_names),
2248 		hid_init,
2249 		hid_exit,
2250 		hid_open,
2251 		hid_close,
2252 		NULL,	/* configure_endpoints */
2253 		hid_claim_interface,
2254 		hid_set_interface_altsetting,
2255 		hid_release_interface,
2256 		hid_clear_halt,
2257 		hid_reset_device,
2258 		hid_submit_bulk_transfer,
2259 		NULL,	/* submit_iso_transfer */
2260 		hid_submit_control_transfer,
2261 		NULL,	/* cancel_transfer */
2262 		hid_copy_transfer_data,
2263 	},
2264 };
2265 
2266 
2267 /*
2268  * WinUSB-like (WinUSB, libusb0/libusbK through libusbk DLL) API functions
2269  */
2270 #define WinUSB_Set(h, fn, required)										\
2271 	do {											\
2272 		WinUSBX[SUB_API_WINUSB].fn = (WinUsb_##fn##_t)GetProcAddress(h, "WinUsb_" #fn);	\
2273 		if (required && (WinUSBX[SUB_API_WINUSB].fn == NULL)) {				\
2274 			usbi_err(ctx, "GetProcAddress() failed for WinUsb_%s", #fn);		\
2275 			goto cleanup_winusb;							\
2276 		}										\
2277 	} while (0)
2278 
2279 #define libusbK_Set(sub_api, fn, required)								\
2280 	do {											\
2281 		pLibK_GetProcAddress((PVOID *)&WinUSBX[sub_api].fn, sub_api, KUSB_FNID_##fn);	\
2282 		if (required && (WinUSBX[sub_api].fn == NULL)) {				\
2283 			usbi_err(ctx, "LibK_GetProcAddress() failed for LibK_%s", #fn);		\
2284 			goto cleanup_libusbk;							\
2285 		}										\
2286 	} while (0)
2287 
winusbx_init(struct libusb_context * ctx)2288 static bool winusbx_init(struct libusb_context *ctx)
2289 {
2290 	HMODULE hWinUSB, hlibusbK;
2291 
2292 	hWinUSB = load_system_library(ctx, "WinUSB");
2293 	if (hWinUSB != NULL) {
2294 		WinUSB_Set(hWinUSB, AbortPipe, true);
2295 		WinUSB_Set(hWinUSB, ControlTransfer, true);
2296 		WinUSB_Set(hWinUSB, FlushPipe, true);
2297 		WinUSB_Set(hWinUSB, Free, true);
2298 		WinUSB_Set(hWinUSB, GetAssociatedInterface, true);
2299 		WinUSB_Set(hWinUSB, Initialize, true);
2300 		WinUSB_Set(hWinUSB, ReadPipe, true);
2301 		WinUSB_Set(hWinUSB, ResetPipe, true);
2302 		WinUSB_Set(hWinUSB, SetCurrentAlternateSetting, true);
2303 		WinUSB_Set(hWinUSB, SetPipePolicy, true);
2304 		WinUSB_Set(hWinUSB, WritePipe, true);
2305 
2306 		// Check for isochronous transfers support (available starting with Windows 8.1)
2307 		WinUSB_Set(hWinUSB, ReadIsochPipeAsap, false);
2308 		if (WinUSBX[SUB_API_WINUSB].ReadIsochPipeAsap != NULL) {
2309 			WinUSB_Set(hWinUSB, QueryPipeEx, true);
2310 			WinUSB_Set(hWinUSB, RegisterIsochBuffer, true);
2311 			WinUSB_Set(hWinUSB, UnregisterIsochBuffer, true);
2312 			WinUSB_Set(hWinUSB, WriteIsochPipeAsap, true);
2313 		}
2314 
2315 		WinUSBX[SUB_API_WINUSB].hDll = hWinUSB;
2316 
2317 		usbi_info(ctx, "WinUSB DLL available (%s isoch support)",
2318 			(WinUSBX[SUB_API_WINUSB].ReadIsochPipeAsap != NULL) ? "with" : "without");
2319 
2320 cleanup_winusb:
2321 		if (WinUSBX[SUB_API_WINUSB].hDll == NULL) {
2322 			usbi_err(ctx, "failed to initialize WinUSB");
2323 			memset(&WinUSBX[SUB_API_WINUSB], 0, sizeof(WinUSBX[SUB_API_WINUSB]));
2324 			FreeLibrary(hWinUSB);
2325 			hWinUSB = NULL;
2326 		}
2327 	} else {
2328 		usbi_info(ctx, "WinUSB DLL is not available");
2329 	}
2330 
2331 	hlibusbK = load_system_library(ctx, "libusbK");
2332 	if (hlibusbK != NULL) {
2333 		LibK_GetVersion_t pLibK_GetVersion;
2334 		LibK_GetProcAddress_t pLibK_GetProcAddress;
2335 		int sub_api = 0;
2336 
2337 		pLibK_GetVersion = (LibK_GetVersion_t)GetProcAddress(hlibusbK, "LibK_GetVersion");
2338 		if (pLibK_GetVersion != NULL) {
2339 			KLIB_VERSION LibK_Version;
2340 
2341 			pLibK_GetVersion(&LibK_Version);
2342 			usbi_dbg(ctx, "libusbK DLL found, version: %d.%d.%d.%d", LibK_Version.Major, LibK_Version.Minor,
2343 				LibK_Version.Micro, LibK_Version.Nano);
2344 		} else {
2345 			usbi_dbg(ctx, "libusbK DLL found, version unknown");
2346 		}
2347 
2348 		pLibK_GetProcAddress = (LibK_GetProcAddress_t)GetProcAddress(hlibusbK, "LibK_GetProcAddress");
2349 		if (pLibK_GetProcAddress == NULL) {
2350 			usbi_err(ctx, "LibK_GetProcAddress() not found in libusbK DLL");
2351 			goto cleanup_libusbk;
2352 		}
2353 
2354 		// NB: The below for loop works because the sub_api value for WinUSB
2355 		// is a higher value than that of libusbK and libusb0
2356 		for (; sub_api < SUB_API_WINUSB; sub_api++) {
2357 			libusbK_Set(sub_api, AbortPipe, true);
2358 			libusbK_Set(sub_api, ControlTransfer, true);
2359 			libusbK_Set(sub_api, FlushPipe, true);
2360 			libusbK_Set(sub_api, Free, true);
2361 			libusbK_Set(sub_api, GetAssociatedInterface, true);
2362 			libusbK_Set(sub_api, Initialize, true);
2363 			libusbK_Set(sub_api, ReadPipe, true);
2364 			libusbK_Set(sub_api, ResetPipe, true);
2365 			libusbK_Set(sub_api, SetCurrentAlternateSetting, true);
2366 			libusbK_Set(sub_api, SetPipePolicy, true);
2367 			libusbK_Set(sub_api, WritePipe, true);
2368 
2369 			// Optional isochronous support
2370 			libusbK_Set(sub_api, IsoReadPipe, false);
2371 			if (WinUSBX[sub_api].IsoReadPipe != NULL)
2372 				libusbK_Set(sub_api, IsoWritePipe, true);
2373 
2374 			// Optional device reset support
2375 			libusbK_Set(sub_api, ResetDevice, false);
2376 
2377 			WinUSBX[sub_api].hDll = hlibusbK;
2378 		}
2379 
2380 cleanup_libusbk:
2381 		if (sub_api < SUB_API_WINUSB) {
2382 			usbi_err(ctx, "failed to initialize libusbK");
2383 			while (sub_api >= 0) {
2384 				memset(&WinUSBX[sub_api], 0, sizeof(WinUSBX[sub_api]));
2385 				sub_api--;
2386 			}
2387 			FreeLibrary(hlibusbK);
2388 			hlibusbK = NULL;
2389 		}
2390 	} else {
2391 		usbi_info(ctx, "libusbK DLL is not available");
2392 	}
2393 
2394 	if ((hWinUSB == NULL) && (hlibusbK == NULL)) {
2395 		usbi_warn(ctx, "neither WinUSB nor libusbK DLLs were found, "
2396 			"you will not be able to access devices outside of enumeration");
2397 		return false;
2398 	}
2399 
2400 	return true;
2401 }
2402 
winusbx_exit(void)2403 static void winusbx_exit(void)
2404 {
2405 	bool loaded = false;
2406 	HMODULE hDll;
2407 
2408 	hDll = WinUSBX[SUB_API_LIBUSBK].hDll;
2409 	if (hDll != NULL) {
2410 		FreeLibrary(hDll);
2411 		loaded = true;
2412 	}
2413 
2414 	hDll = WinUSBX[SUB_API_WINUSB].hDll;
2415 	if (hDll != NULL) {
2416 		FreeLibrary(hDll);
2417 		loaded = true;
2418 	}
2419 
2420 	// Reset the WinUSBX API structures if something was loaded
2421 	if (loaded)
2422 		memset(&WinUSBX, 0, sizeof(WinUSBX));
2423 }
2424 
2425 // NB: open and close must ensure that they only handle interface of
2426 // the right API type, as these functions can be called wholesale from
2427 // composite_open(), with interfaces belonging to different APIs
winusbx_open(int sub_api,struct libusb_device_handle * dev_handle)2428 static int winusbx_open(int sub_api, struct libusb_device_handle *dev_handle)
2429 {
2430 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2431 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
2432 	HANDLE file_handle;
2433 	int i;
2434 
2435 	CHECK_WINUSBX_AVAILABLE(sub_api);
2436 
2437 	// WinUSB requires a separate handle for each interface
2438 	for (i = 0; i < USB_MAXINTERFACES; i++) {
2439 		if ((priv->usb_interface[i].path != NULL)
2440 				&& (priv->usb_interface[i].apib->id == USB_API_WINUSBX)) {
2441 			file_handle = windows_open(dev_handle, priv->usb_interface[i].path, GENERIC_READ | GENERIC_WRITE);
2442 			if (file_handle == INVALID_HANDLE_VALUE) {
2443 				usbi_err(HANDLE_CTX(dev_handle), "could not open device %s (interface %d): %s", priv->usb_interface[i].path, i, windows_error_str(0));
2444 				switch (GetLastError()) {
2445 				case ERROR_FILE_NOT_FOUND: // The device was disconnected
2446 					return LIBUSB_ERROR_NO_DEVICE;
2447 				case ERROR_ACCESS_DENIED:
2448 					return LIBUSB_ERROR_ACCESS;
2449 				default:
2450 					return LIBUSB_ERROR_IO;
2451 				}
2452 			}
2453 
2454 			handle_priv->interface_handle[i].dev_handle = file_handle;
2455 		}
2456 	}
2457 
2458 	return LIBUSB_SUCCESS;
2459 }
2460 
winusbx_close(int sub_api,struct libusb_device_handle * dev_handle)2461 static void winusbx_close(int sub_api, struct libusb_device_handle *dev_handle)
2462 {
2463 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
2464 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2465 	HANDLE handle;
2466 	int i;
2467 
2468 	if (sub_api == SUB_API_NOTSET)
2469 		sub_api = priv->sub_api;
2470 
2471 	if (WinUSBX[sub_api].hDll == NULL)
2472 		return;
2473 
2474 	if (priv->apib->id == USB_API_COMPOSITE) {
2475 		// If this is a composite device, just free and close all WinUSB-like
2476 		// interfaces directly (each is independent and not associated with another)
2477 		for (i = 0; i < USB_MAXINTERFACES; i++) {
2478 			if (priv->usb_interface[i].apib->id == USB_API_WINUSBX) {
2479 				handle = handle_priv->interface_handle[i].api_handle;
2480 				if (HANDLE_VALID(handle))
2481 					WinUSBX[sub_api].Free(handle);
2482 
2483 				handle = handle_priv->interface_handle[i].dev_handle;
2484 				if (HANDLE_VALID(handle))
2485 					CloseHandle(handle);
2486 			}
2487 		}
2488 	} else {
2489 		// If this is a WinUSB device, free all interfaces above interface 0,
2490 		// then free and close interface 0 last
2491 		for (i = 1; i < USB_MAXINTERFACES; i++) {
2492 			handle = handle_priv->interface_handle[i].api_handle;
2493 			if (HANDLE_VALID(handle))
2494 				WinUSBX[sub_api].Free(handle);
2495 		}
2496 		handle = handle_priv->interface_handle[0].api_handle;
2497 		if (HANDLE_VALID(handle))
2498 			WinUSBX[sub_api].Free(handle);
2499 
2500 		handle = handle_priv->interface_handle[0].dev_handle;
2501 		if (HANDLE_VALID(handle))
2502 			CloseHandle(handle);
2503 	}
2504 }
2505 
winusbx_configure_endpoints(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface)2506 static int winusbx_configure_endpoints(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface)
2507 {
2508 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
2509 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2510 	HANDLE winusb_handle = handle_priv->interface_handle[iface].api_handle;
2511 	UCHAR policy;
2512 	ULONG timeout = 0;
2513 	uint8_t endpoint_address;
2514 	int i;
2515 
2516 	CHECK_WINUSBX_AVAILABLE(sub_api);
2517 
2518 	// With handle and endpoints set (in parent), we can setup the default pipe properties
2519 	// see http://download.microsoft.com/download/D/1/D/D1DD7745-426B-4CC3-A269-ABBBE427C0EF/DVC-T705_DDC08.pptx
2520 	for (i = -1; i < priv->usb_interface[iface].nb_endpoints; i++) {
2521 		endpoint_address = (i == -1) ? 0 : priv->usb_interface[iface].endpoint[i];
2522 		if (!WinUSBX[sub_api].SetPipePolicy(winusb_handle, endpoint_address,
2523 			PIPE_TRANSFER_TIMEOUT, sizeof(ULONG), &timeout))
2524 			usbi_dbg(HANDLE_CTX(dev_handle), "failed to set PIPE_TRANSFER_TIMEOUT for control endpoint %02X", endpoint_address);
2525 
2526 		if ((i == -1) || (sub_api == SUB_API_LIBUSB0))
2527 			continue; // Other policies don't apply to control endpoint or libusb0
2528 
2529 		policy = false;
2530 		handle_priv->interface_handle[iface].zlp[endpoint_address] = WINUSB_ZLP_UNSET;
2531 		if (!WinUSBX[sub_api].SetPipePolicy(winusb_handle, endpoint_address,
2532 			SHORT_PACKET_TERMINATE, sizeof(UCHAR), &policy))
2533 			usbi_dbg(HANDLE_CTX(dev_handle), "failed to disable SHORT_PACKET_TERMINATE for endpoint %02X", endpoint_address);
2534 
2535 		if (!WinUSBX[sub_api].SetPipePolicy(winusb_handle, endpoint_address,
2536 			IGNORE_SHORT_PACKETS, sizeof(UCHAR), &policy))
2537 			usbi_dbg(HANDLE_CTX(dev_handle), "failed to disable IGNORE_SHORT_PACKETS for endpoint %02X", endpoint_address);
2538 
2539 		policy = true;
2540 		/* ALLOW_PARTIAL_READS must be enabled due to likely libusbK bug. See:
2541 		   https://sourceforge.net/mailarchive/message.php?msg_id=29736015 */
2542 		if (!WinUSBX[sub_api].SetPipePolicy(winusb_handle, endpoint_address,
2543 			ALLOW_PARTIAL_READS, sizeof(UCHAR), &policy))
2544 			usbi_dbg(HANDLE_CTX(dev_handle), "failed to enable ALLOW_PARTIAL_READS for endpoint %02X", endpoint_address);
2545 
2546 		if (!WinUSBX[sub_api].SetPipePolicy(winusb_handle, endpoint_address,
2547 			AUTO_CLEAR_STALL, sizeof(UCHAR), &policy))
2548 			usbi_dbg(HANDLE_CTX(dev_handle), "failed to enable AUTO_CLEAR_STALL for endpoint %02X", endpoint_address);
2549 
2550 		if (sub_api == SUB_API_LIBUSBK) {
2551 			if (!WinUSBX[sub_api].SetPipePolicy(winusb_handle, endpoint_address,
2552 				ISO_ALWAYS_START_ASAP, sizeof(UCHAR), &policy))
2553 				usbi_dbg(HANDLE_CTX(dev_handle), "failed to enable ISO_ALWAYS_START_ASAP for endpoint %02X", endpoint_address);
2554 		}
2555 	}
2556 
2557 	return LIBUSB_SUCCESS;
2558 }
2559 
winusbx_claim_interface(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface)2560 static int winusbx_claim_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface)
2561 {
2562 	struct libusb_context *ctx = HANDLE_CTX(dev_handle);
2563 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
2564 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2565 	bool is_using_usbccgp = (priv->apib->id == USB_API_COMPOSITE);
2566 	HDEVINFO dev_info;
2567 	char *dev_interface_path = NULL;
2568 	char *dev_interface_path_guid_start;
2569 	char filter_path[] = "\\\\.\\libusb0-0000";
2570 	bool found_filter = false;
2571 	HANDLE file_handle, winusb_handle;
2572 	DWORD err, _index;
2573 	int r;
2574 
2575 	CHECK_WINUSBX_AVAILABLE(sub_api);
2576 
2577 	// If the device is composite, but using the default Windows composite parent driver (usbccgp)
2578 	// or if it's the first WinUSB-like interface, we get a handle through Initialize().
2579 	if ((is_using_usbccgp) || (iface == 0)) {
2580 		// composite device (independent interfaces) or interface 0
2581 		file_handle = handle_priv->interface_handle[iface].dev_handle;
2582 		if (!HANDLE_VALID(file_handle))
2583 			return LIBUSB_ERROR_NOT_FOUND;
2584 
2585 		if (!WinUSBX[sub_api].Initialize(file_handle, &winusb_handle)) {
2586 			handle_priv->interface_handle[iface].api_handle = INVALID_HANDLE_VALUE;
2587 			err = GetLastError();
2588 			switch (err) {
2589 			case ERROR_BAD_COMMAND:
2590 				// The device was disconnected
2591 				usbi_err(ctx, "could not access interface %u: %s", iface, windows_error_str(0));
2592 				return LIBUSB_ERROR_NO_DEVICE;
2593 			default:
2594 				// it may be that we're using the libusb0 filter driver.
2595 				// TODO: can we move this whole business into the K/0 DLL?
2596 				r = LIBUSB_SUCCESS;
2597 				for (_index = 0; ; _index++) {
2598 					safe_free(dev_interface_path);
2599 
2600 					if (found_filter)
2601 						break;
2602 
2603 					r = get_interface_details_filter(ctx, &dev_info, _index, filter_path, &dev_interface_path);
2604 					if ((r != LIBUSB_SUCCESS) || (dev_interface_path == NULL))
2605 						break;
2606 
2607 					// ignore GUID part
2608 					dev_interface_path_guid_start = strchr(dev_interface_path, '{');
2609 					if (dev_interface_path_guid_start == NULL)
2610 						continue;
2611 					*dev_interface_path_guid_start = '\0';
2612 
2613 					if (strncmp(dev_interface_path, priv->usb_interface[iface].path, strlen(dev_interface_path)) == 0) {
2614 						file_handle = windows_open(dev_handle, filter_path, GENERIC_READ | GENERIC_WRITE);
2615 						if (file_handle != INVALID_HANDLE_VALUE) {
2616 							if (WinUSBX[sub_api].Initialize(file_handle, &winusb_handle)) {
2617 								// Replace the existing file handle with the working one
2618 								CloseHandle(handle_priv->interface_handle[iface].dev_handle);
2619 								handle_priv->interface_handle[iface].dev_handle = file_handle;
2620 								found_filter = true;
2621 							} else {
2622 								usbi_err(ctx, "could not initialize filter driver for %s", filter_path);
2623 								CloseHandle(file_handle);
2624 							}
2625 						} else {
2626 							usbi_err(ctx, "could not open device %s: %s", filter_path, windows_error_str(0));
2627 						}
2628 					}
2629 				}
2630 				if (r != LIBUSB_SUCCESS)
2631 					return r;
2632 				if (!found_filter) {
2633 					usbi_err(ctx, "could not access interface %u: %s", iface, windows_error_str(err));
2634 					return LIBUSB_ERROR_ACCESS;
2635 				}
2636 			}
2637 		}
2638 		handle_priv->interface_handle[iface].api_handle = winusb_handle;
2639 	} else {
2640 		// For all other interfaces, use GetAssociatedInterface()
2641 		winusb_handle = handle_priv->interface_handle[0].api_handle;
2642 		// It is a requirement for multiple interface devices on Windows that, to you
2643 		// must first claim the first interface before you claim the others
2644 		if (!HANDLE_VALID(winusb_handle)) {
2645 			file_handle = handle_priv->interface_handle[0].dev_handle;
2646 			if (WinUSBX[sub_api].Initialize(file_handle, &winusb_handle)) {
2647 				handle_priv->interface_handle[0].api_handle = winusb_handle;
2648 				usbi_warn(ctx, "auto-claimed interface 0 (required to claim %u with WinUSB)", iface);
2649 			} else {
2650 				usbi_warn(ctx, "failed to auto-claim interface 0 (required to claim %u with WinUSB): %s", iface, windows_error_str(0));
2651 				return LIBUSB_ERROR_ACCESS;
2652 			}
2653 		}
2654 		if (!WinUSBX[sub_api].GetAssociatedInterface(winusb_handle, (UCHAR)(iface - 1),
2655 			&handle_priv->interface_handle[iface].api_handle)) {
2656 			handle_priv->interface_handle[iface].api_handle = INVALID_HANDLE_VALUE;
2657 			switch (GetLastError()) {
2658 			case ERROR_NO_MORE_ITEMS:   // invalid iface
2659 				return LIBUSB_ERROR_NOT_FOUND;
2660 			case ERROR_BAD_COMMAND:     // The device was disconnected
2661 				return LIBUSB_ERROR_NO_DEVICE;
2662 			case ERROR_ALREADY_EXISTS:  // already claimed
2663 				return LIBUSB_ERROR_BUSY;
2664 			default:
2665 				usbi_err(ctx, "could not claim interface %u: %s", iface, windows_error_str(0));
2666 				return LIBUSB_ERROR_ACCESS;
2667 			}
2668 		}
2669 		handle_priv->interface_handle[iface].dev_handle = handle_priv->interface_handle[0].dev_handle;
2670 	}
2671 	usbi_dbg(ctx, "claimed interface %u", iface);
2672 	handle_priv->active_interface = iface;
2673 
2674 	return LIBUSB_SUCCESS;
2675 }
2676 
winusbx_release_interface(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface)2677 static int winusbx_release_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface)
2678 {
2679 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
2680 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2681 	HANDLE winusb_handle;
2682 
2683 	CHECK_WINUSBX_AVAILABLE(sub_api);
2684 
2685 	winusb_handle = handle_priv->interface_handle[iface].api_handle;
2686 	if (!HANDLE_VALID(winusb_handle))
2687 		return LIBUSB_ERROR_NOT_FOUND;
2688 
2689 	WinUSBX[sub_api].Free(winusb_handle);
2690 	handle_priv->interface_handle[iface].api_handle = INVALID_HANDLE_VALUE;
2691 
2692 	return LIBUSB_SUCCESS;
2693 }
2694 
2695 /*
2696  * Return the first valid interface (of the same API type), for control transfers
2697  */
get_valid_interface(struct libusb_device_handle * dev_handle,int api_id)2698 static int get_valid_interface(struct libusb_device_handle *dev_handle, int api_id)
2699 {
2700 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
2701 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2702 	int i;
2703 
2704 	if ((api_id < USB_API_WINUSBX) || (api_id > USB_API_HID)) {
2705 		usbi_dbg(HANDLE_CTX(dev_handle), "unsupported API ID");
2706 		return -1;
2707 	}
2708 
2709 	for (i = 0; i < USB_MAXINTERFACES; i++) {
2710 	if (HANDLE_VALID(handle_priv->interface_handle[i].dev_handle)
2711 			&& HANDLE_VALID(handle_priv->interface_handle[i].api_handle)
2712 			&& (priv->usb_interface[i].apib->id == api_id))
2713 		return i;
2714 	}
2715 
2716 	return -1;
2717 }
2718 
2719 /*
2720 * Check a specific interface is valid (of the same API type), for control transfers
2721 */
check_valid_interface(struct libusb_device_handle * dev_handle,unsigned short interface,int api_id)2722 static int check_valid_interface(struct libusb_device_handle *dev_handle, unsigned short interface, int api_id)
2723 {
2724 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
2725 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2726 
2727 	if (interface >= USB_MAXINTERFACES)
2728 		return -1;
2729 
2730 	if ((api_id < USB_API_WINUSBX) || (api_id > USB_API_HID)) {
2731 		usbi_dbg(HANDLE_CTX(dev_handle), "unsupported API ID");
2732 		return -1;
2733 	}
2734 
2735 	// try the requested interface
2736 	if (HANDLE_VALID(handle_priv->interface_handle[interface].dev_handle)
2737 		&& HANDLE_VALID(handle_priv->interface_handle[interface].api_handle)
2738 		&& (priv->usb_interface[interface].apib->id == api_id))
2739 		return interface;
2740 
2741 	return -1;
2742 }
2743 
2744 /*
2745  * Lookup interface by endpoint address. -1 if not found
2746  */
interface_by_endpoint(struct winusb_device_priv * priv,struct winusb_device_handle_priv * handle_priv,uint8_t endpoint_address)2747 static int interface_by_endpoint(struct winusb_device_priv *priv,
2748 	struct winusb_device_handle_priv *handle_priv, uint8_t endpoint_address)
2749 {
2750 	int i, j;
2751 
2752 	for (i = 0; i < USB_MAXINTERFACES; i++) {
2753 		if (!HANDLE_VALID(handle_priv->interface_handle[i].api_handle))
2754 			continue;
2755 		if (priv->usb_interface[i].endpoint == NULL)
2756 			continue;
2757 		for (j = 0; j < priv->usb_interface[i].nb_endpoints; j++) {
2758 			if (priv->usb_interface[i].endpoint[j] == endpoint_address)
2759 				return i;
2760 		}
2761 	}
2762 
2763 	return -1;
2764 }
2765 
winusbx_submit_control_transfer(int sub_api,struct usbi_transfer * itransfer)2766 static int winusbx_submit_control_transfer(int sub_api, struct usbi_transfer *itransfer)
2767 {
2768 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
2769 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
2770 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
2771 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(transfer->dev_handle);
2772 	PWINUSB_SETUP_PACKET setup = (PWINUSB_SETUP_PACKET)transfer->buffer;
2773 	ULONG size, transferred;
2774 	HANDLE winusb_handle;
2775 	OVERLAPPED *overlapped;
2776 	int current_interface;
2777 
2778 	CHECK_WINUSBX_AVAILABLE(sub_api);
2779 
2780 	size = transfer->length - LIBUSB_CONTROL_SETUP_SIZE;
2781 
2782 	// Windows places upper limits on the control transfer size
2783 	// See: https://docs.microsoft.com/en-us/windows-hardware/drivers/usbcon/usb-bandwidth-allocation#maximum-transfer-size
2784 	if (size > MAX_CTRL_BUFFER_LENGTH)
2785 		return LIBUSB_ERROR_INVALID_PARAM;
2786 
2787 	if ((setup->RequestType & 0x1F) == LIBUSB_RECIPIENT_INTERFACE)
2788 		current_interface = check_valid_interface(transfer->dev_handle, setup->Index & 0xff, USB_API_WINUSBX);
2789 	else
2790 		current_interface = get_valid_interface(transfer->dev_handle, USB_API_WINUSBX);
2791 	if (current_interface < 0) {
2792 		if (auto_claim(transfer, &current_interface, USB_API_WINUSBX) != LIBUSB_SUCCESS)
2793 			return LIBUSB_ERROR_NOT_FOUND;
2794 	}
2795 
2796 	usbi_dbg(ITRANSFER_CTX(itransfer), "will use interface %d", current_interface);
2797 
2798 	transfer_priv->interface_number = (uint8_t)current_interface;
2799 	winusb_handle = handle_priv->interface_handle[current_interface].api_handle;
2800 	set_transfer_priv_handle(itransfer, handle_priv->interface_handle[current_interface].dev_handle);
2801 	overlapped = get_transfer_priv_overlapped(itransfer);
2802 
2803 	// Sending of set configuration control requests from WinUSB creates issues, except when using libusb0.sys
2804 	if (sub_api != SUB_API_LIBUSB0
2805 			&& (LIBUSB_REQ_TYPE(setup->RequestType) == LIBUSB_REQUEST_TYPE_STANDARD)
2806 			&& (setup->Request == LIBUSB_REQUEST_SET_CONFIGURATION)) {
2807 		if (setup->Value != priv->active_config) {
2808 			usbi_warn(TRANSFER_CTX(transfer), "cannot set configuration other than the default one");
2809 			return LIBUSB_ERROR_NOT_SUPPORTED;
2810 		}
2811 		windows_force_sync_completion(itransfer, 0);
2812 	} else {
2813 		if (!WinUSBX[sub_api].ControlTransfer(winusb_handle, *setup, transfer->buffer + LIBUSB_CONTROL_SETUP_SIZE, size, &transferred, overlapped)) {
2814 			if (GetLastError() != ERROR_IO_PENDING) {
2815 				usbi_warn(TRANSFER_CTX(transfer), "ControlTransfer failed: %s", windows_error_str(0));
2816 				return LIBUSB_ERROR_IO;
2817 			}
2818 		} else {
2819 			windows_force_sync_completion(itransfer, transferred);
2820 		}
2821 	}
2822 
2823 	return LIBUSB_SUCCESS;
2824 }
2825 
winusbx_set_interface_altsetting(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface,uint8_t altsetting)2826 static int winusbx_set_interface_altsetting(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface, uint8_t altsetting)
2827 {
2828 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
2829 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
2830 	HANDLE winusb_handle;
2831 
2832 	CHECK_WINUSBX_AVAILABLE(sub_api);
2833 
2834 	winusb_handle = handle_priv->interface_handle[iface].api_handle;
2835 	if (!HANDLE_VALID(winusb_handle)) {
2836 		usbi_err(HANDLE_CTX(dev_handle), "interface must be claimed first");
2837 		return LIBUSB_ERROR_NOT_FOUND;
2838 	}
2839 
2840 	if (!WinUSBX[sub_api].SetCurrentAlternateSetting(winusb_handle, altsetting)) {
2841 		usbi_err(HANDLE_CTX(dev_handle), "SetCurrentAlternateSetting failed: %s", windows_error_str(0));
2842 		return LIBUSB_ERROR_IO;
2843 	}
2844 
2845 	return LIBUSB_SUCCESS;
2846 }
2847 
2848 
winusbx_native_iso_transfer_continue_stream_callback(struct libusb_transfer * transfer)2849 static void WINAPI winusbx_native_iso_transfer_continue_stream_callback(struct libusb_transfer *transfer)
2850 {
2851 	// If this callback is invoked, this means that we attempted to set ContinueStream
2852 	// to TRUE when calling Read/WriteIsochPipeAsap in winusbx_do_iso_transfer.
2853 	// The role of this callback is to fallback to ContinueStream = FALSE if the transfer
2854 	// did not succeed.
2855 
2856 	struct winusb_transfer_priv *transfer_priv =
2857 		get_winusb_transfer_priv(LIBUSB_TRANSFER_TO_USBI_TRANSFER(transfer));
2858 	bool fallback = (transfer->status != LIBUSB_TRANSFER_COMPLETED);
2859 	int idx;
2860 
2861 	// Restore the user callback
2862 	transfer->callback = transfer_priv->iso_user_callback;
2863 
2864 	for (idx = 0; idx < transfer->num_iso_packets && !fallback; idx++) {
2865 		if (transfer->iso_packet_desc[idx].status != LIBUSB_TRANSFER_COMPLETED)
2866 			fallback = true;
2867 	}
2868 
2869 	if (!fallback) {
2870 		// If the transfer was successful, we restore the user callback and call it.
2871 		if (transfer->callback)
2872 			transfer->callback(transfer);
2873 	} else {
2874 		// If the transfer wasn't successful we reschedule the transfer while forcing it
2875 		// not to continue the stream. This might results in a 5-ms delay.
2876 		transfer_priv->iso_break_stream = TRUE;
2877 		libusb_submit_transfer(transfer);
2878 	}
2879 }
winusbx_submit_iso_transfer(int sub_api,struct usbi_transfer * itransfer)2880 static int winusbx_submit_iso_transfer(int sub_api, struct usbi_transfer *itransfer)
2881 {
2882 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
2883 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
2884 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(transfer->dev_handle);
2885 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
2886 	HANDLE winusb_handle;
2887 	OVERLAPPED *overlapped;
2888 	BOOL ret;
2889 	int current_interface;
2890 
2891 	CHECK_WINUSBX_AVAILABLE(sub_api);
2892 
2893 	current_interface = interface_by_endpoint(priv, handle_priv, transfer->endpoint);
2894 	if (current_interface < 0) {
2895 		usbi_err(TRANSFER_CTX(transfer), "unable to match endpoint to an open interface - cancelling transfer");
2896 		return LIBUSB_ERROR_NOT_FOUND;
2897 	}
2898 
2899 	usbi_dbg(TRANSFER_CTX(transfer), "matched endpoint %02X with interface %d", transfer->endpoint, current_interface);
2900 
2901 	transfer_priv->interface_number = (uint8_t)current_interface;
2902 	winusb_handle = handle_priv->interface_handle[current_interface].api_handle;
2903 	set_transfer_priv_handle(itransfer, handle_priv->interface_handle[current_interface].dev_handle);
2904 	overlapped = get_transfer_priv_overlapped(itransfer);
2905 
2906 	if ((sub_api == SUB_API_LIBUSBK) || (sub_api == SUB_API_LIBUSB0)) {
2907 		int i;
2908 		UINT offset;
2909 		size_t iso_ctx_size;
2910 		PKISO_CONTEXT iso_context;
2911 
2912 		if (WinUSBX[sub_api].IsoReadPipe == NULL) {
2913 			usbi_warn(TRANSFER_CTX(transfer), "libusbK DLL does not support isoch transfers");
2914 			return LIBUSB_ERROR_NOT_SUPPORTED;
2915 		}
2916 
2917 		iso_ctx_size = sizeof(KISO_CONTEXT) + (transfer->num_iso_packets * sizeof(KISO_PACKET));
2918 		transfer_priv->iso_context = iso_context = calloc(1, iso_ctx_size);
2919 		if (transfer_priv->iso_context == NULL)
2920 			return LIBUSB_ERROR_NO_MEM;
2921 
2922 		// start ASAP
2923 		iso_context->StartFrame = 0;
2924 		iso_context->NumberOfPackets = (SHORT)transfer->num_iso_packets;
2925 
2926 		// convert the transfer packet lengths to iso_packet offsets
2927 		offset = 0;
2928 		for (i = 0; i < transfer->num_iso_packets; i++) {
2929 			iso_context->IsoPackets[i].offset = offset;
2930 			offset += transfer->iso_packet_desc[i].length;
2931 		}
2932 
2933 		if (IS_XFERIN(transfer)) {
2934 			usbi_dbg(TRANSFER_CTX(transfer), "reading %d iso packets", transfer->num_iso_packets);
2935 			ret = WinUSBX[sub_api].IsoReadPipe(winusb_handle, transfer->endpoint, transfer->buffer, transfer->length, overlapped, iso_context);
2936 		} else {
2937 			usbi_dbg(TRANSFER_CTX(transfer), "writing %d iso packets", transfer->num_iso_packets);
2938 			ret = WinUSBX[sub_api].IsoWritePipe(winusb_handle, transfer->endpoint, transfer->buffer, transfer->length, overlapped, iso_context);
2939 		}
2940 
2941 		if (!ret && GetLastError() != ERROR_IO_PENDING) {
2942 			usbi_err(TRANSFER_CTX(transfer), "IsoReadPipe/IsoWritePipe failed: %s", windows_error_str(0));
2943 			return LIBUSB_ERROR_IO;
2944 		}
2945 
2946 		return LIBUSB_SUCCESS;
2947 	} else if (sub_api == SUB_API_WINUSB) {
2948 		WINUSB_PIPE_INFORMATION_EX pipe_info_ex = { 0 };
2949 		WINUSB_ISOCH_BUFFER_HANDLE buffer_handle;
2950 		ULONG iso_transfer_size_multiple;
2951 		int out_transfer_length = 0;
2952 		int idx;
2953 
2954 		// Depending on the version of Microsoft WinUSB, isochronous transfers may not be supported.
2955 		if (WinUSBX[sub_api].ReadIsochPipeAsap == NULL) {
2956 			usbi_warn(TRANSFER_CTX(transfer), "WinUSB DLL does not support isoch transfers");
2957 			return LIBUSB_ERROR_NOT_SUPPORTED;
2958 		}
2959 
2960 		if (sizeof(struct libusb_iso_packet_descriptor) != sizeof(USBD_ISO_PACKET_DESCRIPTOR)) {
2961 			usbi_err(TRANSFER_CTX(transfer), "size of WinUsb and libusb isoch packet descriptors don't match");
2962 			return LIBUSB_ERROR_NOT_SUPPORTED;
2963 		}
2964 
2965 		// Query the pipe extended information to find the pipe index corresponding to the endpoint.
2966 		for (idx = 0; idx < priv->usb_interface[current_interface].nb_endpoints; ++idx) {
2967 			ret = WinUSBX[sub_api].QueryPipeEx(winusb_handle, (UINT8)priv->usb_interface[current_interface].current_altsetting, (UCHAR)idx, &pipe_info_ex);
2968 			if (!ret) {
2969 				usbi_err(TRANSFER_CTX(transfer), "couldn't query interface settings for USB pipe with index %d. Error: %s", idx, windows_error_str(0));
2970 				return LIBUSB_ERROR_NOT_FOUND;
2971 			}
2972 
2973 			if (pipe_info_ex.PipeId == transfer->endpoint && pipe_info_ex.PipeType == UsbdPipeTypeIsochronous)
2974 				break;
2975 		}
2976 
2977 		// Make sure we found the index.
2978 		if (idx == priv->usb_interface[current_interface].nb_endpoints) {
2979 			usbi_err(TRANSFER_CTX(transfer), "couldn't find isoch endpoint 0x%02x", transfer->endpoint);
2980 			return LIBUSB_ERROR_NOT_FOUND;
2981 		}
2982 
2983 		if (IS_XFERIN(transfer)) {
2984 			int interval = pipe_info_ex.Interval;
2985 
2986 			// For high-speed and SuperSpeed device, the interval is 2**(bInterval-1).
2987 			if (transfer->dev_handle->dev->speed >= LIBUSB_SPEED_HIGH)
2988 				interval = (1 << (pipe_info_ex.Interval - 1));
2989 
2990 			// WinUSB only supports isoch transfers spanning a full USB frames. Later, we might be smarter about this
2991 			// and allocate a temporary buffer. However, this is harder than it seems as its destruction would depend on overlapped
2992 			// IO...
2993 			if (transfer->dev_handle->dev->speed >= LIBUSB_SPEED_HIGH) // Microframes (125us)
2994 				iso_transfer_size_multiple = (pipe_info_ex.MaximumBytesPerInterval * 8) / interval;
2995 			else // Normal Frames (1ms)
2996 				iso_transfer_size_multiple = pipe_info_ex.MaximumBytesPerInterval / interval;
2997 
2998 			if (transfer->length % iso_transfer_size_multiple != 0) {
2999 				usbi_err(TRANSFER_CTX(transfer), "length of isoch buffer must be a multiple of the MaximumBytesPerInterval * 8 / Interval");
3000 				return LIBUSB_ERROR_INVALID_PARAM;
3001 			}
3002 		} else {
3003 			// If this is an OUT transfer, we make sure the isoch packets are contiguous as this isn't supported otherwise.
3004 			bool size_should_be_zero = false;
3005 
3006 			for (idx = 0; idx < transfer->num_iso_packets; ++idx) {
3007 				if ((size_should_be_zero && transfer->iso_packet_desc[idx].length != 0) ||
3008 					(transfer->iso_packet_desc[idx].length != pipe_info_ex.MaximumBytesPerInterval && idx + 1 < transfer->num_iso_packets && transfer->iso_packet_desc[idx + 1].length > 0)) {
3009 					usbi_err(TRANSFER_CTX(transfer), "isoch packets for OUT transfer with WinUSB must be contiguous in memory");
3010 					return LIBUSB_ERROR_INVALID_PARAM;
3011 				}
3012 
3013 				size_should_be_zero = (transfer->iso_packet_desc[idx].length == 0);
3014 				out_transfer_length += transfer->iso_packet_desc[idx].length;
3015 			}
3016 		}
3017 
3018 		if (transfer_priv->isoch_buffer_handle != NULL) {
3019 			if (WinUSBX[sub_api].UnregisterIsochBuffer(transfer_priv->isoch_buffer_handle)) {
3020 				transfer_priv->isoch_buffer_handle = NULL;
3021 			} else {
3022 				usbi_err(TRANSFER_CTX(transfer), "failed to unregister WinUSB isoch buffer: %s", windows_error_str(0));
3023 				return LIBUSB_ERROR_OTHER;
3024 			}
3025 		}
3026 
3027 		// Register the isoch buffer to the operating system.
3028 		ret = WinUSBX[sub_api].RegisterIsochBuffer(winusb_handle, transfer->endpoint, transfer->buffer, transfer->length, &buffer_handle);
3029 		if (!ret) {
3030 			usbi_err(TRANSFER_CTX(transfer), "failed to register WinUSB isoch buffer: %s", windows_error_str(0));
3031 			return LIBUSB_ERROR_NO_MEM;
3032 		}
3033 
3034 		// Important note: the WinUSB_Read/WriteIsochPipeAsap API requires a ContinueStream parameter that tells whether the isochronous
3035 		// stream must be continued or if the WinUSB driver can schedule the transfer at its convenience. Profiling subsequent transfers
3036 		// with ContinueStream = FALSE showed that 5 frames, i.e. about 5 milliseconds, were left empty between each transfer. This
3037 		// is critical as this greatly diminish the achievable isochronous bandwidth. We solved the problem using the following strategy:
3038 		// - Transfers are first scheduled with ContinueStream = TRUE and with winusbx_iso_transfer_continue_stream_callback as user callback.
3039 		// - If the transfer succeeds, winusbx_iso_transfer_continue_stream_callback restore the user callback and calls its.
3040 		// - If the transfer fails, winusbx_iso_transfer_continue_stream_callback reschedule the transfer and force ContinueStream = FALSE.
3041 		if (!transfer_priv->iso_break_stream) {
3042 			transfer_priv->iso_user_callback = transfer->callback;
3043 			transfer->callback = winusbx_native_iso_transfer_continue_stream_callback;
3044 		}
3045 
3046 		// Initiate the transfers.
3047 		if (IS_XFERIN(transfer))
3048 			ret = WinUSBX[sub_api].ReadIsochPipeAsap(buffer_handle, 0, transfer->length, !transfer_priv->iso_break_stream, transfer->num_iso_packets, (PUSBD_ISO_PACKET_DESCRIPTOR)transfer->iso_packet_desc, overlapped);
3049 		else
3050 			ret = WinUSBX[sub_api].WriteIsochPipeAsap(buffer_handle, 0, out_transfer_length, !transfer_priv->iso_break_stream, overlapped);
3051 
3052 		if (!ret && GetLastError() != ERROR_IO_PENDING) {
3053 			usbi_err(TRANSFER_CTX(transfer), "ReadIsochPipeAsap/WriteIsochPipeAsap failed: %s", windows_error_str(0));
3054 			if (!WinUSBX[sub_api].UnregisterIsochBuffer(buffer_handle))
3055 				usbi_warn(TRANSFER_CTX(transfer), "failed to unregister WinUSB isoch buffer: %s", windows_error_str(0));
3056 			return LIBUSB_ERROR_IO;
3057 		}
3058 
3059 		// Restore the ContinueStream parameter to TRUE.
3060 		transfer_priv->iso_break_stream = FALSE;
3061 
3062 		transfer_priv->isoch_buffer_handle = buffer_handle;
3063 
3064 		return LIBUSB_SUCCESS;
3065 	} else {
3066 		PRINT_UNSUPPORTED_API(winusbx_submit_iso_transfer);
3067 		return LIBUSB_ERROR_NOT_SUPPORTED;
3068 	}
3069 }
3070 
winusbx_submit_bulk_transfer(int sub_api,struct usbi_transfer * itransfer)3071 static int winusbx_submit_bulk_transfer(int sub_api, struct usbi_transfer *itransfer)
3072 {
3073 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
3074 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
3075 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(transfer->dev_handle);
3076 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
3077 	HANDLE winusb_handle;
3078 	OVERLAPPED *overlapped;
3079 	BOOL ret;
3080 	int current_interface;
3081 
3082 	CHECK_WINUSBX_AVAILABLE(sub_api);
3083 
3084 	current_interface = interface_by_endpoint(priv, handle_priv, transfer->endpoint);
3085 	if (current_interface < 0) {
3086 		usbi_err(TRANSFER_CTX(transfer), "unable to match endpoint to an open interface - cancelling transfer");
3087 		return LIBUSB_ERROR_NOT_FOUND;
3088 	}
3089 
3090 	usbi_dbg(TRANSFER_CTX(transfer), "matched endpoint %02X with interface %d", transfer->endpoint, current_interface);
3091 
3092 	transfer_priv->interface_number = (uint8_t)current_interface;
3093 	winusb_handle = handle_priv->interface_handle[current_interface].api_handle;
3094 	set_transfer_priv_handle(itransfer, handle_priv->interface_handle[current_interface].dev_handle);
3095 	overlapped = get_transfer_priv_overlapped(itransfer);
3096 
3097 	if (IS_XFERIN(transfer)) {
3098 		usbi_dbg(TRANSFER_CTX(transfer), "reading %d bytes", transfer->length);
3099 		ret = WinUSBX[sub_api].ReadPipe(winusb_handle, transfer->endpoint, transfer->buffer, transfer->length, NULL, overlapped);
3100 	} else {
3101 		// Set SHORT_PACKET_TERMINATE if ZLP requested.
3102 		// Changing this can be a problem with packets in flight, so only allow on the first transfer.
3103 		UCHAR policy = (transfer->flags & LIBUSB_TRANSFER_ADD_ZERO_PACKET) != 0;
3104 		uint8_t* current_zlp = &handle_priv->interface_handle[current_interface].zlp[transfer->endpoint];
3105 		if (*current_zlp == WINUSB_ZLP_UNSET) {
3106 			if (policy &&
3107 				!WinUSBX[sub_api].SetPipePolicy(winusb_handle, transfer->endpoint,
3108 				SHORT_PACKET_TERMINATE, sizeof(UCHAR), &policy)) {
3109 				usbi_err(TRANSFER_CTX(transfer), "failed to set SHORT_PACKET_TERMINATE for endpoint %02X", transfer->endpoint);
3110 				return LIBUSB_ERROR_NOT_SUPPORTED;
3111 			}
3112 			*current_zlp = policy ? WINUSB_ZLP_ON : WINUSB_ZLP_OFF;
3113 		} else if (policy != (*current_zlp == WINUSB_ZLP_ON)) {
3114 			usbi_err(TRANSFER_CTX(transfer), "cannot change ZERO_PACKET for endpoint %02X on Windows", transfer->endpoint);
3115 			return LIBUSB_ERROR_NOT_SUPPORTED;
3116 		}
3117 
3118 		usbi_dbg(TRANSFER_CTX(transfer), "writing %d bytes", transfer->length);
3119 		ret = WinUSBX[sub_api].WritePipe(winusb_handle, transfer->endpoint, transfer->buffer, transfer->length, NULL, overlapped);
3120 	}
3121 
3122 	if (!ret && GetLastError() != ERROR_IO_PENDING) {
3123 		usbi_err(TRANSFER_CTX(transfer), "ReadPipe/WritePipe failed: %s", windows_error_str(0));
3124 		return LIBUSB_ERROR_IO;
3125 	}
3126 
3127 	return LIBUSB_SUCCESS;
3128 }
3129 
winusbx_clear_halt(int sub_api,struct libusb_device_handle * dev_handle,unsigned char endpoint)3130 static int winusbx_clear_halt(int sub_api, struct libusb_device_handle *dev_handle, unsigned char endpoint)
3131 {
3132 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
3133 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
3134 	HANDLE winusb_handle;
3135 	int current_interface;
3136 
3137 	CHECK_WINUSBX_AVAILABLE(sub_api);
3138 
3139 	current_interface = interface_by_endpoint(priv, handle_priv, endpoint);
3140 	if (current_interface < 0) {
3141 		usbi_err(HANDLE_CTX(dev_handle), "unable to match endpoint to an open interface - cannot clear");
3142 		return LIBUSB_ERROR_NOT_FOUND;
3143 	}
3144 
3145 	usbi_dbg(HANDLE_CTX(dev_handle), "matched endpoint %02X with interface %d", endpoint, current_interface);
3146 	winusb_handle = handle_priv->interface_handle[current_interface].api_handle;
3147 
3148 	if (!WinUSBX[sub_api].ResetPipe(winusb_handle, endpoint)) {
3149 		usbi_err(HANDLE_CTX(dev_handle), "ResetPipe failed: %s", windows_error_str(0));
3150 		return LIBUSB_ERROR_NO_DEVICE;
3151 	}
3152 
3153 	return LIBUSB_SUCCESS;
3154 }
3155 
winusbx_cancel_transfer(int sub_api,struct usbi_transfer * itransfer)3156 static int winusbx_cancel_transfer(int sub_api, struct usbi_transfer *itransfer)
3157 {
3158 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
3159 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(transfer->dev_handle);
3160 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
3161 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
3162 	int current_interface = transfer_priv->interface_number;
3163 	HANDLE handle;
3164 
3165 	CHECK_WINUSBX_AVAILABLE(sub_api);
3166 
3167 	usbi_dbg(TRANSFER_CTX(transfer), "will use interface %d", current_interface);
3168 
3169 	handle = handle_priv->interface_handle[current_interface].api_handle;
3170 	if (!WinUSBX[sub_api].AbortPipe(handle, transfer->endpoint)) {
3171 		usbi_err(TRANSFER_CTX(transfer), "AbortPipe failed: %s", windows_error_str(0));
3172 		return LIBUSB_ERROR_NO_DEVICE;
3173 	}
3174 
3175 	return LIBUSB_SUCCESS;
3176 }
3177 
3178 /*
3179  * from the "How to Use WinUSB to Communicate with a USB Device" Microsoft white paper
3180  * (http://www.microsoft.com/whdc/connect/usb/winusb_howto.mspx):
3181  * "WinUSB does not support host-initiated reset port and cycle port operations" and
3182  * IOCTL_INTERNAL_USB_CYCLE_PORT is only available in kernel mode and the
3183  * IOCTL_USB_HUB_CYCLE_PORT ioctl was removed from Vista => the best we can do is
3184  * cycle the pipes (and even then, the control pipe can not be reset using WinUSB)
3185  */
3186 // TODO: (post hotplug): see if we can force eject the device and redetect it (reuse hotplug?)
winusbx_reset_device(int sub_api,struct libusb_device_handle * dev_handle)3187 static int winusbx_reset_device(int sub_api, struct libusb_device_handle *dev_handle)
3188 {
3189 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
3190 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
3191 	HANDLE winusb_handle;
3192 	int i, j;
3193 
3194 	CHECK_WINUSBX_AVAILABLE(sub_api);
3195 
3196 	// Reset any available pipe (except control)
3197 	for (i = 0; i < USB_MAXINTERFACES; i++) {
3198 		winusb_handle = handle_priv->interface_handle[i].api_handle;
3199 		if (HANDLE_VALID(winusb_handle)) {
3200 			for (j = 0; j < priv->usb_interface[i].nb_endpoints; j++) {
3201 				usbi_dbg(HANDLE_CTX(dev_handle), "resetting ep %02X", priv->usb_interface[i].endpoint[j]);
3202 				if (!WinUSBX[sub_api].AbortPipe(winusb_handle, priv->usb_interface[i].endpoint[j]))
3203 					usbi_err(HANDLE_CTX(dev_handle), "AbortPipe (pipe address %02X) failed: %s",
3204 						priv->usb_interface[i].endpoint[j], windows_error_str(0));
3205 
3206 				// FlushPipe seems to fail on OUT pipes
3207 				if (IS_EPIN(priv->usb_interface[i].endpoint[j])
3208 						&& (!WinUSBX[sub_api].FlushPipe(winusb_handle, priv->usb_interface[i].endpoint[j])))
3209 					usbi_err(HANDLE_CTX(dev_handle), "FlushPipe (pipe address %02X) failed: %s",
3210 						priv->usb_interface[i].endpoint[j], windows_error_str(0));
3211 
3212 				if (!WinUSBX[sub_api].ResetPipe(winusb_handle, priv->usb_interface[i].endpoint[j]))
3213 					usbi_err(HANDLE_CTX(dev_handle), "ResetPipe (pipe address %02X) failed: %s",
3214 						priv->usb_interface[i].endpoint[j], windows_error_str(0));
3215 			}
3216 		}
3217 	}
3218 
3219 	// libusbK & libusb0 have the ability to issue an actual device reset
3220 	if ((sub_api != SUB_API_WINUSB) && (WinUSBX[sub_api].ResetDevice != NULL)) {
3221 		winusb_handle = handle_priv->interface_handle[0].api_handle;
3222 		if (HANDLE_VALID(winusb_handle))
3223 			WinUSBX[sub_api].ResetDevice(winusb_handle);
3224 	}
3225 
3226 	return LIBUSB_SUCCESS;
3227 }
3228 
winusbx_copy_transfer_data(int sub_api,struct usbi_transfer * itransfer,DWORD length)3229 static enum libusb_transfer_status winusbx_copy_transfer_data(int sub_api, struct usbi_transfer *itransfer, DWORD length)
3230 {
3231 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
3232 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
3233 	int i;
3234 
3235 	if (transfer->type == LIBUSB_TRANSFER_TYPE_ISOCHRONOUS) {
3236 		struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
3237 
3238 		if (sub_api == SUB_API_NOTSET)
3239 			sub_api = priv->sub_api;
3240 		if (WinUSBX[sub_api].hDll == NULL)
3241 			return LIBUSB_TRANSFER_ERROR;
3242 
3243 		// for isochronous, need to copy the individual iso packet actual_lengths and statuses
3244 		if ((sub_api == SUB_API_LIBUSBK) || (sub_api == SUB_API_LIBUSB0)) {
3245 			// iso only supported on libusbk-based backends for now
3246 			PKISO_CONTEXT iso_context = transfer_priv->iso_context;
3247 			for (i = 0; i < transfer->num_iso_packets; i++) {
3248 				if (IS_XFERIN(transfer)) {
3249 					transfer->iso_packet_desc[i].actual_length = iso_context->IsoPackets[i].actual_length;
3250 				} else {
3251 					// On Windows the usbd Length field is not used for OUT transfers.
3252 					// Copy the requested value back for consistency with other platforms.
3253 					transfer->iso_packet_desc[i].actual_length = transfer->iso_packet_desc[i].length;
3254 				}
3255 				// TODO translate USDB_STATUS codes http://msdn.microsoft.com/en-us/library/ff539136(VS.85).aspx to libusb_transfer_status
3256 				//transfer->iso_packet_desc[i].status = transfer_priv->iso_context->IsoPackets[i].status;
3257 			}
3258 		} else if (sub_api == SUB_API_WINUSB) {
3259 			if (IS_XFERIN(transfer)) {
3260 				/* Convert isochronous packet descriptor between Windows and libusb representation.
3261 				 * Both representation are guaranteed to have the same length in bytes.*/
3262 				PUSBD_ISO_PACKET_DESCRIPTOR usbd_iso_packet_desc = (PUSBD_ISO_PACKET_DESCRIPTOR)transfer->iso_packet_desc;
3263 				for (i = 0; i < transfer->num_iso_packets; i++) {
3264 					unsigned int packet_length = (i < transfer->num_iso_packets - 1) ? (usbd_iso_packet_desc[i + 1].Offset - usbd_iso_packet_desc[i].Offset) : usbd_iso_packet_desc[i].Length;
3265 					unsigned int actual_length = usbd_iso_packet_desc[i].Length;
3266 					USBD_STATUS status = usbd_iso_packet_desc[i].Status;
3267 
3268 					transfer->iso_packet_desc[i].length = packet_length;
3269 					transfer->iso_packet_desc[i].actual_length = actual_length;
3270 					transfer->iso_packet_desc[i].status = usbd_status_to_libusb_transfer_status(status);
3271 				}
3272 			} else {
3273 				for (i = 0; i < transfer->num_iso_packets; i++) {
3274 					transfer->iso_packet_desc[i].status = LIBUSB_TRANSFER_COMPLETED;
3275 					// On Windows the usbd Length field is not used for OUT transfers.
3276 					// Copy the requested value back for consistency with other platforms.
3277 					transfer->iso_packet_desc[i].actual_length = transfer->iso_packet_desc[i].length;
3278 				}
3279 			}
3280 		} else {
3281 			// This should only occur if backend is not set correctly or other backend isoc is partially implemented
3282 			PRINT_UNSUPPORTED_API(copy_transfer_data);
3283 			return LIBUSB_TRANSFER_ERROR;
3284 		}
3285 	}
3286 
3287 	itransfer->transferred += (int)length;
3288 	return LIBUSB_TRANSFER_COMPLETED;
3289 }
3290 
3291 /*
3292  * Internal HID Support functions (from libusb-win32)
3293  * Note that functions that complete data transfer synchronously must return
3294  * LIBUSB_COMPLETED instead of LIBUSB_SUCCESS
3295  */
3296 static int _hid_get_hid_descriptor(struct hid_device_priv *dev, void *data, size_t *size);
3297 static int _hid_get_report_descriptor(struct hid_device_priv *dev, void *data, size_t *size);
3298 
_hid_wcslen(WCHAR * str)3299 static int _hid_wcslen(WCHAR *str)
3300 {
3301 	int i = 0;
3302 
3303 	while (str[i] && (str[i] != 0x409))
3304 		i++;
3305 
3306 	return i;
3307 }
3308 
_hid_get_device_descriptor(struct hid_device_priv * hid_priv,void * data,size_t * size)3309 static int _hid_get_device_descriptor(struct hid_device_priv *hid_priv, void *data, size_t *size)
3310 {
3311 	struct libusb_device_descriptor d;
3312 
3313 	d.bLength = LIBUSB_DT_DEVICE_SIZE;
3314 	d.bDescriptorType = LIBUSB_DT_DEVICE;
3315 	d.bcdUSB = 0x0200; /* 2.00 */
3316 	d.bDeviceClass = 0;
3317 	d.bDeviceSubClass = 0;
3318 	d.bDeviceProtocol = 0;
3319 	d.bMaxPacketSize0 = 64; /* fix this! */
3320 	d.idVendor = (uint16_t)hid_priv->vid;
3321 	d.idProduct = (uint16_t)hid_priv->pid;
3322 	d.bcdDevice = 0x0100;
3323 	d.iManufacturer = hid_priv->string_index[0];
3324 	d.iProduct = hid_priv->string_index[1];
3325 	d.iSerialNumber = hid_priv->string_index[2];
3326 	d.bNumConfigurations = 1;
3327 
3328 	if (*size > LIBUSB_DT_DEVICE_SIZE)
3329 		*size = LIBUSB_DT_DEVICE_SIZE;
3330 	memcpy(data, &d, *size);
3331 
3332 	return LIBUSB_COMPLETED;
3333 }
3334 
_hid_get_config_descriptor(struct hid_device_priv * hid_priv,void * data,size_t * size)3335 static int _hid_get_config_descriptor(struct hid_device_priv *hid_priv, void *data, size_t *size)
3336 {
3337 	char num_endpoints = 0;
3338 	size_t config_total_len = 0;
3339 	char tmp[HID_MAX_CONFIG_DESC_SIZE];
3340 	struct libusb_config_descriptor *cd;
3341 	struct libusb_interface_descriptor *id;
3342 	struct libusb_hid_descriptor *hd;
3343 	struct libusb_endpoint_descriptor *ed;
3344 	size_t tmp_size;
3345 
3346 	if (hid_priv->input_report_size)
3347 		num_endpoints++;
3348 	if (hid_priv->output_report_size)
3349 		num_endpoints++;
3350 
3351 	config_total_len = LIBUSB_DT_CONFIG_SIZE + LIBUSB_DT_INTERFACE_SIZE
3352 		+ LIBUSB_DT_HID_SIZE + num_endpoints * LIBUSB_DT_ENDPOINT_SIZE;
3353 
3354 	cd = (struct libusb_config_descriptor *)tmp;
3355 	id = (struct libusb_interface_descriptor *)(tmp + LIBUSB_DT_CONFIG_SIZE);
3356 	hd = (struct libusb_hid_descriptor *)(tmp + LIBUSB_DT_CONFIG_SIZE
3357 		+ LIBUSB_DT_INTERFACE_SIZE);
3358 	ed = (struct libusb_endpoint_descriptor *)(tmp + LIBUSB_DT_CONFIG_SIZE
3359 		+ LIBUSB_DT_INTERFACE_SIZE
3360 		+ LIBUSB_DT_HID_SIZE);
3361 
3362 	cd->bLength = LIBUSB_DT_CONFIG_SIZE;
3363 	cd->bDescriptorType = LIBUSB_DT_CONFIG;
3364 	cd->wTotalLength = (uint16_t)config_total_len;
3365 	cd->bNumInterfaces = 1;
3366 	cd->bConfigurationValue = 1;
3367 	cd->iConfiguration = 0;
3368 	cd->bmAttributes = 1 << 7; /* bus powered */
3369 	cd->MaxPower = 50;
3370 
3371 	id->bLength = LIBUSB_DT_INTERFACE_SIZE;
3372 	id->bDescriptorType = LIBUSB_DT_INTERFACE;
3373 	id->bInterfaceNumber = 0;
3374 	id->bAlternateSetting = 0;
3375 	id->bNumEndpoints = num_endpoints;
3376 	id->bInterfaceClass = 3;
3377 	id->bInterfaceSubClass = 0;
3378 	id->bInterfaceProtocol = 0;
3379 	id->iInterface = 0;
3380 
3381 	tmp_size = LIBUSB_DT_HID_SIZE;
3382 	_hid_get_hid_descriptor(hid_priv, hd, &tmp_size);
3383 
3384 	if (hid_priv->input_report_size) {
3385 		ed->bLength = LIBUSB_DT_ENDPOINT_SIZE;
3386 		ed->bDescriptorType = LIBUSB_DT_ENDPOINT;
3387 		ed->bEndpointAddress = HID_IN_EP;
3388 		ed->bmAttributes = 3;
3389 		ed->wMaxPacketSize = hid_priv->input_report_size - 1;
3390 		ed->bInterval = 10;
3391 		ed = (struct libusb_endpoint_descriptor *)((char *)ed + LIBUSB_DT_ENDPOINT_SIZE);
3392 	}
3393 
3394 	if (hid_priv->output_report_size) {
3395 		ed->bLength = LIBUSB_DT_ENDPOINT_SIZE;
3396 		ed->bDescriptorType = LIBUSB_DT_ENDPOINT;
3397 		ed->bEndpointAddress = HID_OUT_EP;
3398 		ed->bmAttributes = 3;
3399 		ed->wMaxPacketSize = hid_priv->output_report_size - 1;
3400 		ed->bInterval = 10;
3401 	}
3402 
3403 	if (*size > config_total_len)
3404 		*size = config_total_len;
3405 	memcpy(data, tmp, *size);
3406 
3407 	return LIBUSB_COMPLETED;
3408 }
3409 
_hid_get_string_descriptor(struct hid_device_priv * hid_priv,int _index,void * data,size_t * size,HANDLE hid_handle)3410 static int _hid_get_string_descriptor(struct hid_device_priv *hid_priv, int _index,
3411 	void *data, size_t *size, HANDLE hid_handle)
3412 {
3413 	void *tmp = NULL;
3414 	WCHAR string[MAX_USB_STRING_LENGTH];
3415 	size_t tmp_size = 0;
3416 	int i;
3417 
3418 	/* language ID, EN-US */
3419 	char string_langid[] = {0x09, 0x04};
3420 
3421 	if (_index == 0) {
3422 		tmp = string_langid;
3423 		tmp_size = sizeof(string_langid) + 2;
3424 	} else {
3425 		for (i = 0; i < 3; i++) {
3426 			if (_index == (hid_priv->string_index[i])) {
3427 				tmp = hid_priv->string[i];
3428 				tmp_size = (_hid_wcslen(hid_priv->string[i]) + 1) * sizeof(WCHAR);
3429 				break;
3430 			}
3431 		}
3432 
3433 		if (i == 3) {
3434 			if (!HidD_GetIndexedString(hid_handle, _index, string, sizeof(string)))
3435 				return LIBUSB_ERROR_INVALID_PARAM;
3436 			tmp = string;
3437 			tmp_size = (_hid_wcslen(string) + 1) * sizeof(WCHAR);
3438 		}
3439 	}
3440 
3441 	if (!tmp_size)
3442 		return LIBUSB_ERROR_INVALID_PARAM;
3443 
3444 	if (tmp_size < *size)
3445 		*size = tmp_size;
3446 
3447 	// 2 byte header
3448 	((uint8_t *)data)[0] = (uint8_t)*size;
3449 	((uint8_t *)data)[1] = LIBUSB_DT_STRING;
3450 	memcpy((uint8_t *)data + 2, tmp, *size - 2);
3451 
3452 	return LIBUSB_COMPLETED;
3453 }
3454 
_hid_get_hid_descriptor(struct hid_device_priv * hid_priv,void * data,size_t * size)3455 static int _hid_get_hid_descriptor(struct hid_device_priv *hid_priv, void *data, size_t *size)
3456 {
3457 	struct libusb_hid_descriptor d;
3458 	uint8_t tmp[MAX_HID_DESCRIPTOR_SIZE];
3459 	size_t report_len = MAX_HID_DESCRIPTOR_SIZE;
3460 
3461 	_hid_get_report_descriptor(hid_priv, tmp, &report_len);
3462 
3463 	d.bLength = LIBUSB_DT_HID_SIZE;
3464 	d.bDescriptorType = LIBUSB_DT_HID;
3465 	d.bcdHID = 0x0110; /* 1.10 */
3466 	d.bCountryCode = 0;
3467 	d.bNumDescriptors = 1;
3468 	d.bClassDescriptorType = LIBUSB_DT_REPORT;
3469 	d.wClassDescriptorLength = (uint16_t)report_len;
3470 
3471 	if (*size > LIBUSB_DT_HID_SIZE)
3472 		*size = LIBUSB_DT_HID_SIZE;
3473 	memcpy(data, &d, *size);
3474 
3475 	return LIBUSB_COMPLETED;
3476 }
3477 
_hid_get_report_descriptor(struct hid_device_priv * hid_priv,void * data,size_t * size)3478 static int _hid_get_report_descriptor(struct hid_device_priv *hid_priv, void *data, size_t *size)
3479 {
3480 	uint8_t d[MAX_HID_DESCRIPTOR_SIZE];
3481 	size_t i = 0;
3482 
3483 	/* usage page */
3484 	d[i++] = 0x06; d[i++] = hid_priv->usagePage & 0xFF; d[i++] = hid_priv->usagePage >> 8;
3485 	/* usage */
3486 	d[i++] = 0x09; d[i++] = (uint8_t)hid_priv->usage;
3487 	/* start collection (application) */
3488 	d[i++] = 0xA1; d[i++] = 0x01;
3489 	/* input report */
3490 	if (hid_priv->input_report_size) {
3491 		/* usage (vendor defined) */
3492 		d[i++] = 0x09; d[i++] = 0x01;
3493 		/* logical minimum (0) */
3494 		d[i++] = 0x15; d[i++] = 0x00;
3495 		/* logical maximum (255) */
3496 		d[i++] = 0x25; d[i++] = 0xFF;
3497 		/* report size (8 bits) */
3498 		d[i++] = 0x75; d[i++] = 0x08;
3499 		/* report count */
3500 		d[i++] = 0x95; d[i++] = (uint8_t)hid_priv->input_report_size - 1;
3501 		/* input (data, variable, absolute) */
3502 		d[i++] = 0x81; d[i++] = 0x00;
3503 	}
3504 	/* output report */
3505 	if (hid_priv->output_report_size) {
3506 		/* usage (vendor defined) */
3507 		d[i++] = 0x09; d[i++] = 0x02;
3508 		/* logical minimum (0) */
3509 		d[i++] = 0x15; d[i++] = 0x00;
3510 		/* logical maximum (255) */
3511 		d[i++] = 0x25; d[i++] = 0xFF;
3512 		/* report size (8 bits) */
3513 		d[i++] = 0x75; d[i++] = 0x08;
3514 		/* report count */
3515 		d[i++] = 0x95; d[i++] = (uint8_t)hid_priv->output_report_size - 1;
3516 		/* output (data, variable, absolute) */
3517 		d[i++] = 0x91; d[i++] = 0x00;
3518 	}
3519 	/* feature report */
3520 	if (hid_priv->feature_report_size) {
3521 		/* usage (vendor defined) */
3522 		d[i++] = 0x09; d[i++] = 0x03;
3523 		/* logical minimum (0) */
3524 		d[i++] = 0x15; d[i++] = 0x00;
3525 		/* logical maximum (255) */
3526 		d[i++] = 0x25; d[i++] = 0xFF;
3527 		/* report size (8 bits) */
3528 		d[i++] = 0x75; d[i++] = 0x08;
3529 		/* report count */
3530 		d[i++] = 0x95; d[i++] = (uint8_t)hid_priv->feature_report_size - 1;
3531 		/* feature (data, variable, absolute) */
3532 		d[i++] = 0xb2; d[i++] = 0x02; d[i++] = 0x01;
3533 	}
3534 
3535 	/* end collection */
3536 	d[i++] = 0xC0;
3537 
3538 	if (*size > i)
3539 		*size = i;
3540 	memcpy(data, d, *size);
3541 
3542 	return LIBUSB_COMPLETED;
3543 }
3544 
_hid_get_descriptor(struct libusb_device * dev,HANDLE hid_handle,int recipient,int type,int _index,void * data,size_t * size)3545 static int _hid_get_descriptor(struct libusb_device *dev, HANDLE hid_handle, int recipient,
3546 	int type, int _index, void *data, size_t *size)
3547 {
3548 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
3549 	UNUSED(recipient);
3550 
3551 	switch (type) {
3552 	case LIBUSB_DT_DEVICE:
3553 		usbi_dbg(DEVICE_CTX(dev), "LIBUSB_DT_DEVICE");
3554 		return _hid_get_device_descriptor(priv->hid, data, size);
3555 	case LIBUSB_DT_CONFIG:
3556 		usbi_dbg(DEVICE_CTX(dev), "LIBUSB_DT_CONFIG");
3557 		if (!_index)
3558 			return _hid_get_config_descriptor(priv->hid, data, size);
3559 		return LIBUSB_ERROR_INVALID_PARAM;
3560 	case LIBUSB_DT_STRING:
3561 		usbi_dbg(DEVICE_CTX(dev), "LIBUSB_DT_STRING");
3562 		return _hid_get_string_descriptor(priv->hid, _index, data, size, hid_handle);
3563 	case LIBUSB_DT_HID:
3564 		usbi_dbg(DEVICE_CTX(dev), "LIBUSB_DT_HID");
3565 		if (!_index)
3566 			return _hid_get_hid_descriptor(priv->hid, data, size);
3567 		return LIBUSB_ERROR_INVALID_PARAM;
3568 	case LIBUSB_DT_REPORT:
3569 		usbi_dbg(DEVICE_CTX(dev), "LIBUSB_DT_REPORT");
3570 		if (!_index)
3571 			return _hid_get_report_descriptor(priv->hid, data, size);
3572 		return LIBUSB_ERROR_INVALID_PARAM;
3573 	case LIBUSB_DT_PHYSICAL:
3574 		usbi_dbg(DEVICE_CTX(dev), "LIBUSB_DT_PHYSICAL");
3575 		if (HidD_GetPhysicalDescriptor(hid_handle, data, (ULONG)*size))
3576 			return LIBUSB_COMPLETED;
3577 		return LIBUSB_ERROR_OTHER;
3578 	}
3579 
3580 	usbi_warn(DEVICE_CTX(dev), "unsupported");
3581 	return LIBUSB_ERROR_NOT_SUPPORTED;
3582 }
3583 
_hid_get_report(struct libusb_device * dev,HANDLE hid_handle,int id,void * data,struct winusb_transfer_priv * tp,size_t size,OVERLAPPED * overlapped,int report_type)3584 static int _hid_get_report(struct libusb_device *dev, HANDLE hid_handle, int id, void *data,
3585 	struct winusb_transfer_priv *tp, size_t size, OVERLAPPED *overlapped, int report_type)
3586 {
3587 	DWORD ioctl_code, expected_size = (DWORD)size;
3588 	uint8_t *buf;
3589 
3590 	if (tp->hid_buffer != NULL)
3591 		usbi_err(DEVICE_CTX(dev), "program assertion failed - hid_buffer is not NULL");
3592 
3593 	if ((size == 0) || (size > MAX_HID_REPORT_SIZE)) {
3594 		usbi_warn(DEVICE_CTX(dev), "invalid size (%"PRIuPTR")", (uintptr_t)size);
3595 		return LIBUSB_ERROR_INVALID_PARAM;
3596 	}
3597 
3598 	switch (report_type) {
3599 	case HID_REPORT_TYPE_INPUT:
3600 		ioctl_code = IOCTL_HID_GET_INPUT_REPORT;
3601 		break;
3602 	case HID_REPORT_TYPE_FEATURE:
3603 		ioctl_code = IOCTL_HID_GET_FEATURE;
3604 		break;
3605 	default:
3606 		usbi_warn(DEVICE_CTX(dev), "unknown HID report type %d", report_type);
3607 		return LIBUSB_ERROR_INVALID_PARAM;
3608 	}
3609 
3610 	// Add a trailing byte to detect overflows
3611 	buf = calloc(1, expected_size + 1);
3612 	if (buf == NULL)
3613 		return LIBUSB_ERROR_NO_MEM;
3614 
3615 	buf[0] = (uint8_t)id; // Must be set always
3616 	usbi_dbg(DEVICE_CTX(dev), "report ID: 0x%02X", buf[0]);
3617 
3618 	// NB: The size returned by DeviceIoControl doesn't include report IDs when not in use (0)
3619 	if (!DeviceIoControl(hid_handle, ioctl_code, buf, expected_size + 1,
3620 		buf, expected_size + 1, NULL, overlapped)) {
3621 		if (GetLastError() != ERROR_IO_PENDING) {
3622 			usbi_err(DEVICE_CTX(dev), "failed to read HID Report: %s", windows_error_str(0));
3623 			free(buf);
3624 			return LIBUSB_ERROR_IO;
3625 		}
3626 	}
3627 
3628 	// Asynchronous wait
3629 	tp->hid_buffer = buf;
3630 	tp->hid_dest = data; // copy dest, as not necessarily the start of the transfer buffer
3631 	tp->hid_expected_size = expected_size;
3632 
3633 	return LIBUSB_SUCCESS;
3634 }
3635 
_hid_set_report(struct libusb_device * dev,HANDLE hid_handle,int id,void * data,struct winusb_transfer_priv * tp,size_t size,OVERLAPPED * overlapped,int report_type)3636 static int _hid_set_report(struct libusb_device *dev, HANDLE hid_handle, int id, void *data,
3637 	struct winusb_transfer_priv *tp, size_t size, OVERLAPPED *overlapped, int report_type)
3638 {
3639 	DWORD ioctl_code, write_size = (DWORD)size;
3640 	// If an id is reported, we must allow MAX_HID_REPORT_SIZE + 1
3641 	size_t max_report_size = MAX_HID_REPORT_SIZE + (id ? 1 : 0);
3642 	uint8_t *buf;
3643 
3644 	if (tp->hid_buffer != NULL)
3645 		usbi_err(DEVICE_CTX(dev), "program assertion failed - hid_buffer is not NULL");
3646 
3647 	if ((size == 0) || (size > max_report_size)) {
3648 		usbi_warn(DEVICE_CTX(dev), "invalid size (%"PRIuPTR")", (uintptr_t)size);
3649 		return LIBUSB_ERROR_INVALID_PARAM;
3650 	}
3651 
3652 	switch (report_type) {
3653 	case HID_REPORT_TYPE_OUTPUT:
3654 		ioctl_code = IOCTL_HID_SET_OUTPUT_REPORT;
3655 		break;
3656 	case HID_REPORT_TYPE_FEATURE:
3657 		ioctl_code = IOCTL_HID_SET_FEATURE;
3658 		break;
3659 	default:
3660 		usbi_warn(DEVICE_CTX(dev), "unknown HID report type %d", report_type);
3661 		return LIBUSB_ERROR_INVALID_PARAM;
3662 	}
3663 
3664 	usbi_dbg(DEVICE_CTX(dev), "report ID: 0x%02X", id);
3665 	// When report IDs are not used (i.e. when id == 0), we must add
3666 	// a null report ID. Otherwise, we just use original data buffer
3667 	if (id == 0)
3668 		write_size++;
3669 
3670 	buf = malloc(write_size);
3671 	if (buf == NULL)
3672 		return LIBUSB_ERROR_NO_MEM;
3673 
3674 	if (id == 0) {
3675 		buf[0] = 0;
3676 		memcpy(buf + 1, data, size);
3677 	} else {
3678 		// This seems like a waste, but if we don't duplicate the
3679 		// data, we'll get issues when freeing hid_buffer
3680 		memcpy(buf, data, size);
3681 		if (buf[0] != id)
3682 			usbi_warn(DEVICE_CTX(dev), "mismatched report ID (data is %02X, parameter is %02X)", buf[0], id);
3683 	}
3684 
3685 	// NB: The size returned by DeviceIoControl doesn't include report IDs when not in use (0)
3686 	if (!DeviceIoControl(hid_handle, ioctl_code, buf, write_size,
3687 		buf, write_size, NULL, overlapped)) {
3688 		if (GetLastError() != ERROR_IO_PENDING) {
3689 			usbi_err(DEVICE_CTX(dev), "failed to write HID Output Report: %s", windows_error_str(0));
3690 			free(buf);
3691 			return LIBUSB_ERROR_IO;
3692 		}
3693 	}
3694 
3695 	tp->hid_buffer = buf;
3696 	tp->hid_dest = NULL;
3697 	return LIBUSB_SUCCESS;
3698 }
3699 
_hid_class_request(struct libusb_device * dev,HANDLE hid_handle,int request_type,int request,int value,int _index,void * data,struct winusb_transfer_priv * tp,size_t size,OVERLAPPED * overlapped)3700 static int _hid_class_request(struct libusb_device *dev, HANDLE hid_handle, int request_type,
3701 	int request, int value, int _index, void *data, struct winusb_transfer_priv *tp,
3702 	size_t size, OVERLAPPED *overlapped)
3703 {
3704 	int report_type = (value >> 8) & 0xFF;
3705 	int report_id = value & 0xFF;
3706 
3707 	UNUSED(_index);
3708 
3709 	if ((LIBUSB_REQ_RECIPIENT(request_type) != LIBUSB_RECIPIENT_INTERFACE)
3710 			&& (LIBUSB_REQ_RECIPIENT(request_type) != LIBUSB_RECIPIENT_DEVICE))
3711 		return LIBUSB_ERROR_INVALID_PARAM;
3712 
3713 	if (LIBUSB_REQ_OUT(request_type) && request == HID_REQ_SET_REPORT)
3714 		return _hid_set_report(dev, hid_handle, report_id, data, tp, size, overlapped, report_type);
3715 
3716 	if (LIBUSB_REQ_IN(request_type) && request == HID_REQ_GET_REPORT)
3717 		return _hid_get_report(dev, hid_handle, report_id, data, tp, size, overlapped, report_type);
3718 
3719 	return LIBUSB_ERROR_INVALID_PARAM;
3720 }
3721 
3722 /*
3723  * HID API functions
3724  */
hid_init(struct libusb_context * ctx)3725 static bool hid_init(struct libusb_context *ctx)
3726 {
3727 	DLL_GET_HANDLE(ctx, hid);
3728 
3729 	DLL_LOAD_FUNC(hid, HidD_GetAttributes, true);
3730 	DLL_LOAD_FUNC(hid, HidD_GetHidGuid, true);
3731 	DLL_LOAD_FUNC(hid, HidD_GetPreparsedData, true);
3732 	DLL_LOAD_FUNC(hid, HidD_FreePreparsedData, true);
3733 	DLL_LOAD_FUNC(hid, HidD_GetManufacturerString, true);
3734 	DLL_LOAD_FUNC(hid, HidD_GetProductString, true);
3735 	DLL_LOAD_FUNC(hid, HidD_GetSerialNumberString, true);
3736 	DLL_LOAD_FUNC(hid, HidD_GetIndexedString, true);
3737 	DLL_LOAD_FUNC(hid, HidP_GetCaps, true);
3738 	DLL_LOAD_FUNC(hid, HidD_SetNumInputBuffers, true);
3739 	DLL_LOAD_FUNC(hid, HidD_GetPhysicalDescriptor, true);
3740 	DLL_LOAD_FUNC(hid, HidD_FlushQueue, true);
3741 	DLL_LOAD_FUNC(hid, HidP_GetValueCaps, true);
3742 
3743 	return true;
3744 }
3745 
hid_exit(void)3746 static void hid_exit(void)
3747 {
3748 	DLL_FREE_HANDLE(hid);
3749 }
3750 
3751 // NB: open and close must ensure that they only handle interface of
3752 // the right API type, as these functions can be called wholesale from
3753 // composite_open(), with interfaces belonging to different APIs
hid_open(int sub_api,struct libusb_device_handle * dev_handle)3754 static int hid_open(int sub_api, struct libusb_device_handle *dev_handle)
3755 {
3756 	struct libusb_device *dev = dev_handle->dev;
3757 	struct winusb_device_priv *priv = usbi_get_device_priv(dev);
3758 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
3759 	HIDD_ATTRIBUTES hid_attributes;
3760 	PHIDP_PREPARSED_DATA preparsed_data = NULL;
3761 	HIDP_CAPS capabilities;
3762 	HIDP_VALUE_CAPS *value_caps;
3763 	HANDLE hid_handle = INVALID_HANDLE_VALUE;
3764 	int i, j;
3765 	// report IDs handling
3766 	ULONG size[3];
3767 	int nb_ids[2]; // zero and nonzero report IDs
3768 #if defined(ENABLE_LOGGING)
3769 	const char * const type[3] = {"input", "output", "feature"};
3770 #endif
3771 
3772 	UNUSED(sub_api);
3773 	CHECK_HID_AVAILABLE;
3774 
3775 	if (priv->hid == NULL) {
3776 		usbi_err(HANDLE_CTX(dev_handle), "program assertion failed - private HID structure is uninitialized");
3777 		return LIBUSB_ERROR_NOT_FOUND;
3778 	}
3779 
3780 	for (i = 0; i < USB_MAXINTERFACES; i++) {
3781 		if ((priv->usb_interface[i].path != NULL)
3782 				&& (priv->usb_interface[i].apib->id == USB_API_HID)) {
3783 			hid_handle = windows_open(dev_handle, priv->usb_interface[i].path, GENERIC_READ | GENERIC_WRITE);
3784 			/*
3785 			 * http://www.lvr.com/hidfaq.htm: Why do I receive "Access denied" when attempting to access my HID?
3786 			 * "Windows 2000 and later have exclusive read/write access to HIDs that are configured as a system
3787 			 * keyboards or mice. An application can obtain a handle to a system keyboard or mouse by not
3788 			 * requesting READ or WRITE access with CreateFile. Applications can then use HidD_SetFeature and
3789 			 * HidD_GetFeature (if the device supports Feature reports)."
3790 			 */
3791 			if (hid_handle == INVALID_HANDLE_VALUE) {
3792 				usbi_warn(HANDLE_CTX(dev_handle), "could not open HID device in R/W mode (keyboard or mouse?) - trying without");
3793 				hid_handle = windows_open(dev_handle, priv->usb_interface[i].path, 0);
3794 				if (hid_handle == INVALID_HANDLE_VALUE) {
3795 					usbi_err(HANDLE_CTX(dev_handle), "could not open device %s (interface %d): %s", priv->path, i, windows_error_str(0));
3796 					switch (GetLastError()) {
3797 					case ERROR_FILE_NOT_FOUND: // The device was disconnected
3798 						return LIBUSB_ERROR_NO_DEVICE;
3799 					case ERROR_ACCESS_DENIED:
3800 						return LIBUSB_ERROR_ACCESS;
3801 					default:
3802 						return LIBUSB_ERROR_IO;
3803 					}
3804 				}
3805 				priv->usb_interface[i].restricted_functionality = true;
3806 			}
3807 			handle_priv->interface_handle[i].api_handle = hid_handle;
3808 		}
3809 	}
3810 
3811 	hid_attributes.Size = sizeof(hid_attributes);
3812 	do {
3813 		if (!HidD_GetAttributes(hid_handle, &hid_attributes)) {
3814 			usbi_err(HANDLE_CTX(dev_handle), "could not gain access to HID top collection (HidD_GetAttributes)");
3815 			break;
3816 		}
3817 
3818 		priv->hid->vid = hid_attributes.VendorID;
3819 		priv->hid->pid = hid_attributes.ProductID;
3820 
3821 		// Set the maximum available input buffer size
3822 		for (i = 32; HidD_SetNumInputBuffers(hid_handle, i); i *= 2);
3823 		usbi_dbg(HANDLE_CTX(dev_handle), "set maximum input buffer size to %d", i / 2);
3824 
3825 		// Get the maximum input and output report size
3826 		if (!HidD_GetPreparsedData(hid_handle, &preparsed_data) || !preparsed_data) {
3827 			usbi_err(HANDLE_CTX(dev_handle), "could not read HID preparsed data (HidD_GetPreparsedData)");
3828 			break;
3829 		}
3830 		if (HidP_GetCaps(preparsed_data, &capabilities) != HIDP_STATUS_SUCCESS) {
3831 			usbi_err(HANDLE_CTX(dev_handle), "could not parse HID capabilities (HidP_GetCaps)");
3832 			break;
3833 		}
3834 
3835 		// Find out if interrupt will need report IDs
3836 		size[0] = capabilities.NumberInputValueCaps;
3837 		size[1] = capabilities.NumberOutputValueCaps;
3838 		size[2] = capabilities.NumberFeatureValueCaps;
3839 		for (j = HidP_Input; j <= HidP_Feature; j++) {
3840 			usbi_dbg(HANDLE_CTX(dev_handle), "%lu HID %s report value(s) found", ULONG_CAST(size[j]), type[j]);
3841 			priv->hid->uses_report_ids[j] = false;
3842 			if (size[j] > 0) {
3843 				value_caps = calloc(size[j], sizeof(HIDP_VALUE_CAPS));
3844 				if ((value_caps != NULL)
3845 						&& (HidP_GetValueCaps((HIDP_REPORT_TYPE)j, value_caps, &size[j], preparsed_data) == HIDP_STATUS_SUCCESS)
3846 						&& (size[j] >= 1)) {
3847 					nb_ids[0] = 0;
3848 					nb_ids[1] = 0;
3849 					for (i = 0; i < (int)size[j]; i++) {
3850 						usbi_dbg(HANDLE_CTX(dev_handle), "  Report ID: 0x%02X", value_caps[i].ReportID);
3851 						if (value_caps[i].ReportID != 0)
3852 							nb_ids[1]++;
3853 						else
3854 							nb_ids[0]++;
3855 					}
3856 					if (nb_ids[1] != 0) {
3857 						if (nb_ids[0] != 0)
3858 							usbi_warn(HANDLE_CTX(dev_handle), "program assertion failed - zero and nonzero report IDs used for %s",
3859 								type[j]);
3860 						priv->hid->uses_report_ids[j] = true;
3861 					}
3862 				} else {
3863 					usbi_warn(HANDLE_CTX(dev_handle), "  could not process %s report IDs", type[j]);
3864 				}
3865 				free(value_caps);
3866 			}
3867 		}
3868 
3869 		// Set the report sizes
3870 		priv->hid->input_report_size = capabilities.InputReportByteLength;
3871 		priv->hid->output_report_size = capabilities.OutputReportByteLength;
3872 		priv->hid->feature_report_size = capabilities.FeatureReportByteLength;
3873 
3874 		// Store usage and usagePage values
3875 		priv->hid->usage = capabilities.Usage;
3876 		priv->hid->usagePage = capabilities.UsagePage;
3877 
3878 		// Fetch string descriptors
3879 		priv->hid->string_index[0] = dev->device_descriptor.iManufacturer;
3880 		if (priv->hid->string_index[0] != 0)
3881 			HidD_GetManufacturerString(hid_handle, priv->hid->string[0], sizeof(priv->hid->string[0]));
3882 		else
3883 			priv->hid->string[0][0] = 0;
3884 
3885 		priv->hid->string_index[1] = dev->device_descriptor.iProduct;
3886 		if (priv->hid->string_index[1] != 0)
3887 			// Using HidD_GetIndexedString() instead of HidD_GetProductString(), as the latter would otherwise return the name
3888 			// of the interface instead of the iProduct string whenever the iInterface member of the USB_INTERFACE_DESCRIPTOR
3889 			// structure for the interface is nonzero (see Remarks section in the documentation of the HID API routines)
3890 			HidD_GetIndexedString(hid_handle, priv->hid->string_index[1], priv->hid->string[1], sizeof(priv->hid->string[1]));
3891 		else
3892 			priv->hid->string[1][0] = 0;
3893 
3894 		priv->hid->string_index[2] = dev->device_descriptor.iSerialNumber;
3895 		if (priv->hid->string_index[2] != 0)
3896 			HidD_GetSerialNumberString(hid_handle, priv->hid->string[2], sizeof(priv->hid->string[2]));
3897 		else
3898 			priv->hid->string[2][0] = 0;
3899 	} while (0);
3900 
3901 	if (preparsed_data)
3902 		HidD_FreePreparsedData(preparsed_data);
3903 
3904 	return LIBUSB_SUCCESS;
3905 }
3906 
hid_close(int sub_api,struct libusb_device_handle * dev_handle)3907 static void hid_close(int sub_api, struct libusb_device_handle *dev_handle)
3908 {
3909 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
3910 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
3911 	HANDLE file_handle;
3912 	int i;
3913 
3914 	UNUSED(sub_api);
3915 
3916 	if (DLL_HANDLE_NAME(hid) == NULL)
3917 		return;
3918 
3919 	for (i = 0; i < USB_MAXINTERFACES; i++) {
3920 		if (priv->usb_interface[i].apib->id == USB_API_HID) {
3921 			file_handle = handle_priv->interface_handle[i].api_handle;
3922 			if (HANDLE_VALID(file_handle))
3923 				CloseHandle(file_handle);
3924 		}
3925 	}
3926 }
3927 
hid_claim_interface(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface)3928 static int hid_claim_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface)
3929 {
3930 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
3931 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
3932 
3933 	UNUSED(sub_api);
3934 	CHECK_HID_AVAILABLE;
3935 
3936 	// NB: Disconnection detection is not possible in this function
3937 	if (priv->usb_interface[iface].path == NULL)
3938 		return LIBUSB_ERROR_NOT_FOUND; // invalid iface
3939 
3940 	// We use dev_handle as a flag for interface claimed
3941 	if (handle_priv->interface_handle[iface].dev_handle == INTERFACE_CLAIMED)
3942 		return LIBUSB_ERROR_BUSY; // already claimed
3943 
3944 	handle_priv->interface_handle[iface].dev_handle = INTERFACE_CLAIMED;
3945 
3946 	usbi_dbg(HANDLE_CTX(dev_handle), "claimed interface %u", iface);
3947 	handle_priv->active_interface = iface;
3948 
3949 	return LIBUSB_SUCCESS;
3950 }
3951 
hid_release_interface(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface)3952 static int hid_release_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface)
3953 {
3954 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
3955 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
3956 
3957 	UNUSED(sub_api);
3958 	CHECK_HID_AVAILABLE;
3959 
3960 	if (priv->usb_interface[iface].path == NULL)
3961 		return LIBUSB_ERROR_NOT_FOUND; // invalid iface
3962 
3963 	if (handle_priv->interface_handle[iface].dev_handle != INTERFACE_CLAIMED)
3964 		return LIBUSB_ERROR_NOT_FOUND; // invalid iface
3965 
3966 	handle_priv->interface_handle[iface].dev_handle = INVALID_HANDLE_VALUE;
3967 
3968 	return LIBUSB_SUCCESS;
3969 }
3970 
hid_set_interface_altsetting(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface,uint8_t altsetting)3971 static int hid_set_interface_altsetting(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface, uint8_t altsetting)
3972 {
3973 	UNUSED(sub_api);
3974 	UNUSED(iface);
3975 
3976 	CHECK_HID_AVAILABLE;
3977 
3978 	if (altsetting != 0) {
3979 		usbi_err(HANDLE_CTX(dev_handle), "set interface altsetting not supported for altsetting >0");
3980 		return LIBUSB_ERROR_NOT_SUPPORTED;
3981 	}
3982 
3983 	return LIBUSB_SUCCESS;
3984 }
3985 
hid_submit_control_transfer(int sub_api,struct usbi_transfer * itransfer)3986 static int hid_submit_control_transfer(int sub_api, struct usbi_transfer *itransfer)
3987 {
3988 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
3989 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
3990 	struct libusb_device_handle *dev_handle = transfer->dev_handle;
3991 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
3992 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
3993 	WINUSB_SETUP_PACKET *setup = (WINUSB_SETUP_PACKET *)transfer->buffer;
3994 	HANDLE hid_handle;
3995 	OVERLAPPED *overlapped;
3996 	int current_interface;
3997 	uint8_t config;
3998 	size_t size;
3999 	int r;
4000 
4001 	UNUSED(sub_api);
4002 	CHECK_HID_AVAILABLE;
4003 
4004 	safe_free(transfer_priv->hid_buffer);
4005 	transfer_priv->hid_dest = NULL;
4006 	size = transfer->length - LIBUSB_CONTROL_SETUP_SIZE;
4007 
4008 	if (size > MAX_CTRL_BUFFER_LENGTH)
4009 		return LIBUSB_ERROR_INVALID_PARAM;
4010 
4011 	current_interface = get_valid_interface(dev_handle, USB_API_HID);
4012 	if (current_interface < 0) {
4013 		if (auto_claim(transfer, &current_interface, USB_API_HID) != LIBUSB_SUCCESS)
4014 			return LIBUSB_ERROR_NOT_FOUND;
4015 	}
4016 
4017 	usbi_dbg(ITRANSFER_CTX(itransfer), "will use interface %d", current_interface);
4018 
4019 	transfer_priv->interface_number = (uint8_t)current_interface;
4020 	hid_handle = handle_priv->interface_handle[current_interface].api_handle;
4021 	set_transfer_priv_handle(itransfer, hid_handle);
4022 	overlapped = get_transfer_priv_overlapped(itransfer);
4023 
4024 	switch (LIBUSB_REQ_TYPE(setup->RequestType)) {
4025 	case LIBUSB_REQUEST_TYPE_STANDARD:
4026 		switch (setup->Request) {
4027 		case LIBUSB_REQUEST_GET_DESCRIPTOR:
4028 			r = _hid_get_descriptor(dev_handle->dev, hid_handle, LIBUSB_REQ_RECIPIENT(setup->RequestType),
4029 				(setup->Value >> 8) & 0xFF, setup->Value & 0xFF, transfer->buffer + LIBUSB_CONTROL_SETUP_SIZE, &size);
4030 			break;
4031 		case LIBUSB_REQUEST_GET_CONFIGURATION:
4032 			r = winusb_get_configuration(dev_handle, &config);
4033 			if (r == LIBUSB_SUCCESS) {
4034 				size = 1;
4035 				((uint8_t *)transfer->buffer)[LIBUSB_CONTROL_SETUP_SIZE] = config;
4036 				r = LIBUSB_COMPLETED;
4037 			}
4038 			break;
4039 		case LIBUSB_REQUEST_SET_CONFIGURATION:
4040 			if (setup->Value == priv->active_config) {
4041 				r = LIBUSB_COMPLETED;
4042 			} else {
4043 				usbi_warn(TRANSFER_CTX(transfer), "cannot set configuration other than the default one");
4044 				r = LIBUSB_ERROR_NOT_SUPPORTED;
4045 			}
4046 			break;
4047 		case LIBUSB_REQUEST_GET_INTERFACE:
4048 			size = 1;
4049 			((uint8_t *)transfer->buffer)[LIBUSB_CONTROL_SETUP_SIZE] = 0;
4050 			r = LIBUSB_COMPLETED;
4051 			break;
4052 		case LIBUSB_REQUEST_SET_INTERFACE:
4053 			r = hid_set_interface_altsetting(0, dev_handle, (uint8_t)setup->Index, (uint8_t)setup->Value);
4054 			if (r == LIBUSB_SUCCESS)
4055 				r = LIBUSB_COMPLETED;
4056 			break;
4057 		default:
4058 			usbi_warn(TRANSFER_CTX(transfer), "unsupported HID control request");
4059 			return LIBUSB_ERROR_NOT_SUPPORTED;
4060 		}
4061 		break;
4062 	case LIBUSB_REQUEST_TYPE_CLASS:
4063 		r = _hid_class_request(dev_handle->dev, hid_handle, setup->RequestType, setup->Request, setup->Value,
4064 			setup->Index, transfer->buffer + LIBUSB_CONTROL_SETUP_SIZE, transfer_priv,
4065 			size, overlapped);
4066 		break;
4067 	default:
4068 		usbi_warn(TRANSFER_CTX(transfer), "unsupported HID control request");
4069 		return LIBUSB_ERROR_NOT_SUPPORTED;
4070 	}
4071 
4072 	if (r < 0)
4073 		return r;
4074 
4075 	if (r == LIBUSB_COMPLETED) {
4076 		// Force request to be completed synchronously. Transferred size has been set by previous call
4077 		windows_force_sync_completion(itransfer, (ULONG)size);
4078 		r = LIBUSB_SUCCESS;
4079 	}
4080 
4081 	return LIBUSB_SUCCESS;
4082 }
4083 
hid_submit_bulk_transfer(int sub_api,struct usbi_transfer * itransfer)4084 static int hid_submit_bulk_transfer(int sub_api, struct usbi_transfer *itransfer)
4085 {
4086 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
4087 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
4088 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(transfer->dev_handle);
4089 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
4090 	HANDLE hid_handle;
4091 	OVERLAPPED *overlapped;
4092 	bool direction_in;
4093 	BOOL ret;
4094 	int current_interface, length;
4095 
4096 	UNUSED(sub_api);
4097 	CHECK_HID_AVAILABLE;
4098 
4099 	if (IS_XFEROUT(transfer) && (transfer->flags & LIBUSB_TRANSFER_ADD_ZERO_PACKET))
4100 		return LIBUSB_ERROR_NOT_SUPPORTED;
4101 
4102 	transfer_priv->hid_dest = NULL;
4103 	safe_free(transfer_priv->hid_buffer);
4104 
4105 	current_interface = interface_by_endpoint(priv, handle_priv, transfer->endpoint);
4106 	if (current_interface < 0) {
4107 		usbi_err(TRANSFER_CTX(transfer), "unable to match endpoint to an open interface - cancelling transfer");
4108 		return LIBUSB_ERROR_NOT_FOUND;
4109 	}
4110 
4111 	usbi_dbg(TRANSFER_CTX(transfer), "matched endpoint %02X with interface %d", transfer->endpoint, current_interface);
4112 
4113 	transfer_priv->interface_number = (uint8_t)current_interface;
4114 	hid_handle = handle_priv->interface_handle[current_interface].api_handle;
4115 	set_transfer_priv_handle(itransfer, hid_handle);
4116 	overlapped = get_transfer_priv_overlapped(itransfer);
4117 	direction_in = IS_XFERIN(transfer);
4118 
4119 	// If report IDs are not in use, an extra prefix byte must be added
4120 	if (((direction_in) && (!priv->hid->uses_report_ids[0]))
4121 			|| ((!direction_in) && (!priv->hid->uses_report_ids[1])))
4122 		length = transfer->length + 1;
4123 	else
4124 		length = transfer->length;
4125 
4126 	// Add a trailing byte to detect overflows on input
4127 	transfer_priv->hid_buffer = calloc(1, length + 1);
4128 	if (transfer_priv->hid_buffer == NULL)
4129 		return LIBUSB_ERROR_NO_MEM;
4130 
4131 	transfer_priv->hid_expected_size = length;
4132 
4133 	if (direction_in) {
4134 		transfer_priv->hid_dest = transfer->buffer;
4135 		usbi_dbg(TRANSFER_CTX(transfer), "reading %d bytes (report ID: 0x00)", length);
4136 		ret = ReadFile(hid_handle, transfer_priv->hid_buffer, length + 1, NULL, overlapped);
4137 	} else {
4138 		if (!priv->hid->uses_report_ids[1])
4139 			memcpy(transfer_priv->hid_buffer + 1, transfer->buffer, transfer->length);
4140 		else
4141 			// We could actually do without the calloc and memcpy in this case
4142 			memcpy(transfer_priv->hid_buffer, transfer->buffer, transfer->length);
4143 
4144 		usbi_dbg(TRANSFER_CTX(transfer), "writing %d bytes (report ID: 0x%02X)", length, transfer_priv->hid_buffer[0]);
4145 		ret = WriteFile(hid_handle, transfer_priv->hid_buffer, length, NULL, overlapped);
4146 	}
4147 
4148 	if (!ret && GetLastError() != ERROR_IO_PENDING) {
4149 		usbi_err(TRANSFER_CTX(transfer), "HID transfer failed: %s", windows_error_str(0));
4150 		safe_free(transfer_priv->hid_buffer);
4151 		return LIBUSB_ERROR_IO;
4152 	}
4153 
4154 	return LIBUSB_SUCCESS;
4155 }
4156 
hid_reset_device(int sub_api,struct libusb_device_handle * dev_handle)4157 static int hid_reset_device(int sub_api, struct libusb_device_handle *dev_handle)
4158 {
4159 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
4160 	HANDLE hid_handle;
4161 	int current_interface;
4162 
4163 	UNUSED(sub_api);
4164 	CHECK_HID_AVAILABLE;
4165 
4166 	// Flushing the queues on all interfaces is the best we can achieve
4167 	for (current_interface = 0; current_interface < USB_MAXINTERFACES; current_interface++) {
4168 		hid_handle = handle_priv->interface_handle[current_interface].api_handle;
4169 		if (HANDLE_VALID(hid_handle))
4170 			HidD_FlushQueue(hid_handle);
4171 	}
4172 
4173 	return LIBUSB_SUCCESS;
4174 }
4175 
hid_clear_halt(int sub_api,struct libusb_device_handle * dev_handle,unsigned char endpoint)4176 static int hid_clear_halt(int sub_api, struct libusb_device_handle *dev_handle, unsigned char endpoint)
4177 {
4178 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
4179 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
4180 	HANDLE hid_handle;
4181 	int current_interface;
4182 
4183 	UNUSED(sub_api);
4184 	CHECK_HID_AVAILABLE;
4185 
4186 	current_interface = interface_by_endpoint(priv, handle_priv, endpoint);
4187 	if (current_interface < 0) {
4188 		usbi_err(HANDLE_CTX(dev_handle), "unable to match endpoint to an open interface - cannot clear");
4189 		return LIBUSB_ERROR_NOT_FOUND;
4190 	}
4191 
4192 	usbi_dbg(HANDLE_CTX(dev_handle), "matched endpoint %02X with interface %d", endpoint, current_interface);
4193 	hid_handle = handle_priv->interface_handle[current_interface].api_handle;
4194 
4195 	// No endpoint selection with Microsoft's implementation, so we try to flush the
4196 	// whole interface. Should be OK for most case scenarios
4197 	if (!HidD_FlushQueue(hid_handle)) {
4198 		usbi_err(HANDLE_CTX(dev_handle), "Flushing of HID queue failed: %s", windows_error_str(0));
4199 		// Device was probably disconnected
4200 		return LIBUSB_ERROR_NO_DEVICE;
4201 	}
4202 
4203 	return LIBUSB_SUCCESS;
4204 }
4205 
4206 // This extra function is only needed for HID
hid_copy_transfer_data(int sub_api,struct usbi_transfer * itransfer,DWORD length)4207 static enum libusb_transfer_status hid_copy_transfer_data(int sub_api, struct usbi_transfer *itransfer, DWORD length)
4208 {
4209 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
4210 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
4211 	enum libusb_transfer_status r = LIBUSB_TRANSFER_COMPLETED;
4212 
4213 	UNUSED(sub_api);
4214 
4215 	if (transfer_priv->hid_buffer != NULL) {
4216 		// If we have a valid hid_buffer, it means the transfer was async
4217 		if (transfer_priv->hid_dest != NULL) { // Data readout
4218 			if (length > 0) {
4219 				// First, check for overflow
4220 				if ((size_t)length > transfer_priv->hid_expected_size) {
4221 					usbi_err(TRANSFER_CTX(transfer), "OVERFLOW!");
4222 					length = (DWORD)transfer_priv->hid_expected_size;
4223 					r = LIBUSB_TRANSFER_OVERFLOW;
4224 				}
4225 
4226 				if (transfer_priv->hid_buffer[0] == 0) {
4227 					memcpy(transfer_priv->hid_dest, transfer_priv->hid_buffer + 1, length);
4228 				} else {
4229 					memcpy(transfer_priv->hid_dest, transfer_priv->hid_buffer, length);
4230 				}
4231 			}
4232 			transfer_priv->hid_dest = NULL;
4233 		}
4234 		// For write, we just need to free the hid buffer
4235 		safe_free(transfer_priv->hid_buffer);
4236 	}
4237 
4238 	itransfer->transferred += (int)length;
4239 	return r;
4240 }
4241 
4242 
4243 /*
4244  * Composite API functions
4245  */
composite_open(int sub_api,struct libusb_device_handle * dev_handle)4246 static int composite_open(int sub_api, struct libusb_device_handle *dev_handle)
4247 {
4248 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
4249 	int i, r = LIBUSB_ERROR_NOT_FOUND;
4250 	// SUB_API_MAX + 1 as the SUB_API_MAX pos is used to indicate availability of HID
4251 	bool available[SUB_API_MAX + 1];
4252 
4253 	UNUSED(sub_api);
4254 
4255 	for (i = 0; i < SUB_API_MAX + 1; i++)
4256 		available[i] = false;
4257 
4258 	for (i = 0; i < USB_MAXINTERFACES; i++) {
4259 		switch (priv->usb_interface[i].apib->id) {
4260 		case USB_API_WINUSBX:
4261 			if (priv->usb_interface[i].sub_api != SUB_API_NOTSET)
4262 				available[priv->usb_interface[i].sub_api] = true;
4263 			break;
4264 		case USB_API_HID:
4265 			available[SUB_API_MAX] = true;
4266 			break;
4267 		default:
4268 			break;
4269 		}
4270 	}
4271 
4272 	for (i = 0; i < SUB_API_MAX; i++) { // WinUSB-like drivers
4273 		if (available[i]) {
4274 			r = usb_api_backend[USB_API_WINUSBX].open(i, dev_handle);
4275 			if (r != LIBUSB_SUCCESS)
4276 				return r;
4277 		}
4278 	}
4279 
4280 	if (available[SUB_API_MAX]) { // HID driver
4281 		r = hid_open(SUB_API_NOTSET, dev_handle);
4282 
4283 		// On Windows 10 version 1903 (OS Build 18362) and later Windows blocks attempts to
4284 		// open HID devices with a U2F usage unless running as administrator. We ignore this
4285 		// failure and proceed without the HID device opened.
4286 		if (r == LIBUSB_ERROR_ACCESS) {
4287 			usbi_dbg(HANDLE_CTX(dev_handle), "ignoring access denied error while opening HID interface of composite device");
4288 			r = LIBUSB_SUCCESS;
4289 		}
4290 	}
4291 
4292 	return r;
4293 }
4294 
composite_close(int sub_api,struct libusb_device_handle * dev_handle)4295 static void composite_close(int sub_api, struct libusb_device_handle *dev_handle)
4296 {
4297 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
4298 	int i;
4299 	// SUB_API_MAX + 1 as the SUB_API_MAX pos is used to indicate availability of HID
4300 	bool available[SUB_API_MAX + 1];
4301 
4302 	UNUSED(sub_api);
4303 
4304 	for (i = 0; i < SUB_API_MAX + 1; i++)
4305 		available[i] = false;
4306 
4307 	for (i = 0; i < USB_MAXINTERFACES; i++) {
4308 		switch (priv->usb_interface[i].apib->id) {
4309 		case USB_API_WINUSBX:
4310 			if (priv->usb_interface[i].sub_api != SUB_API_NOTSET)
4311 				available[priv->usb_interface[i].sub_api] = true;
4312 			break;
4313 		case USB_API_HID:
4314 			available[SUB_API_MAX] = true;
4315 			break;
4316 		default:
4317 			break;
4318 		}
4319 	}
4320 
4321 	for (i = 0; i < SUB_API_MAX; i++) { // WinUSB-like drivers
4322 		if (available[i])
4323 			usb_api_backend[USB_API_WINUSBX].close(i, dev_handle);
4324 	}
4325 
4326 	if (available[SUB_API_MAX]) // HID driver
4327 		hid_close(SUB_API_NOTSET, dev_handle);
4328 }
4329 
composite_claim_interface(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface)4330 static int composite_claim_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface)
4331 {
4332 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
4333 
4334 	UNUSED(sub_api);
4335 	CHECK_SUPPORTED_API(priv->usb_interface[iface].apib, claim_interface);
4336 
4337 	return priv->usb_interface[iface].apib->
4338 		claim_interface(priv->usb_interface[iface].sub_api, dev_handle, iface);
4339 }
4340 
composite_set_interface_altsetting(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface,uint8_t altsetting)4341 static int composite_set_interface_altsetting(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface, uint8_t altsetting)
4342 {
4343 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
4344 
4345 	UNUSED(sub_api);
4346 	CHECK_SUPPORTED_API(priv->usb_interface[iface].apib, set_interface_altsetting);
4347 
4348 	return priv->usb_interface[iface].apib->
4349 		set_interface_altsetting(priv->usb_interface[iface].sub_api, dev_handle, iface, altsetting);
4350 }
4351 
composite_release_interface(int sub_api,struct libusb_device_handle * dev_handle,uint8_t iface)4352 static int composite_release_interface(int sub_api, struct libusb_device_handle *dev_handle, uint8_t iface)
4353 {
4354 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
4355 
4356 	UNUSED(sub_api);
4357 	CHECK_SUPPORTED_API(priv->usb_interface[iface].apib, release_interface);
4358 
4359 	return priv->usb_interface[iface].apib->
4360 		release_interface(priv->usb_interface[iface].sub_api, dev_handle, iface);
4361 }
4362 
composite_submit_control_transfer(int sub_api,struct usbi_transfer * itransfer)4363 static int composite_submit_control_transfer(int sub_api, struct usbi_transfer *itransfer)
4364 {
4365 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
4366 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
4367 	struct libusb_config_descriptor *conf_desc;
4368 	WINUSB_SETUP_PACKET *setup = (WINUSB_SETUP_PACKET *)transfer->buffer;
4369 	int iface, pass, r;
4370 
4371 	UNUSED(sub_api);
4372 
4373 	// Interface shouldn't matter for control, but it does in practice, with Windows'
4374 	// restrictions with regards to accessing HID keyboards and mice. Try to target
4375 	// a specific interface first, if possible.
4376 	switch (LIBUSB_REQ_RECIPIENT(setup->RequestType)) {
4377 	case LIBUSB_RECIPIENT_INTERFACE:
4378 		iface = setup->Index & 0xFF;
4379 		break;
4380 	case LIBUSB_RECIPIENT_ENDPOINT:
4381 		r = libusb_get_active_config_descriptor(transfer->dev_handle->dev, &conf_desc);
4382 		if (r == LIBUSB_SUCCESS) {
4383 			iface = get_interface_by_endpoint(conf_desc, (setup->Index & 0xFF));
4384 			libusb_free_config_descriptor(conf_desc);
4385 			break;
4386 		}
4387 		// No break if not able to determine interface
4388 		// Fall through
4389 	default:
4390 		iface = -1;
4391 		break;
4392 	}
4393 
4394 	// Try and target a specific interface if the control setup indicates such
4395 	if ((iface >= 0) && (iface < USB_MAXINTERFACES)) {
4396 		usbi_dbg(TRANSFER_CTX(transfer), "attempting control transfer targeted to interface %d", iface);
4397 		if ((priv->usb_interface[iface].path != NULL)
4398 				&& (priv->usb_interface[iface].apib->submit_control_transfer != NULL)) {
4399 			r = priv->usb_interface[iface].apib->submit_control_transfer(priv->usb_interface[iface].sub_api, itransfer);
4400 			if (r == LIBUSB_SUCCESS)
4401 				return r;
4402 		}
4403 	}
4404 
4405 	// Either not targeted to a specific interface or no luck in doing so.
4406 	// Try a 2 pass approach with all interfaces.
4407 	for (pass = 0; pass < 2; pass++) {
4408 		for (iface = 0; iface < USB_MAXINTERFACES; iface++) {
4409 			if ((priv->usb_interface[iface].path != NULL)
4410 					&& (priv->usb_interface[iface].apib->submit_control_transfer != NULL)) {
4411 				if ((pass == 0) && (priv->usb_interface[iface].restricted_functionality)) {
4412 					usbi_dbg(TRANSFER_CTX(transfer), "trying to skip restricted interface #%d (HID keyboard or mouse?)", iface);
4413 					continue;
4414 				}
4415 				usbi_dbg(TRANSFER_CTX(transfer), "using interface %d", iface);
4416 				r = priv->usb_interface[iface].apib->submit_control_transfer(priv->usb_interface[iface].sub_api, itransfer);
4417 				// If not supported on this API, it may be supported on another, so don't give up yet!!
4418 				if (r == LIBUSB_ERROR_NOT_SUPPORTED)
4419 					continue;
4420 				return r;
4421 			}
4422 		}
4423 	}
4424 
4425 	usbi_err(TRANSFER_CTX(transfer), "no libusb supported interfaces to complete request");
4426 	return LIBUSB_ERROR_NOT_FOUND;
4427 }
4428 
composite_submit_bulk_transfer(int sub_api,struct usbi_transfer * itransfer)4429 static int composite_submit_bulk_transfer(int sub_api, struct usbi_transfer *itransfer)
4430 {
4431 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
4432 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(transfer->dev_handle);
4433 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
4434 	int current_interface;
4435 
4436 	UNUSED(sub_api);
4437 
4438 	current_interface = interface_by_endpoint(priv, handle_priv, transfer->endpoint);
4439 	if (current_interface < 0) {
4440 		usbi_err(TRANSFER_CTX(transfer), "unable to match endpoint to an open interface - cancelling transfer");
4441 		return LIBUSB_ERROR_NOT_FOUND;
4442 	}
4443 
4444 	CHECK_SUPPORTED_API(priv->usb_interface[current_interface].apib, submit_bulk_transfer);
4445 
4446 	return priv->usb_interface[current_interface].apib->
4447 		submit_bulk_transfer(priv->usb_interface[current_interface].sub_api, itransfer);
4448 }
4449 
composite_submit_iso_transfer(int sub_api,struct usbi_transfer * itransfer)4450 static int composite_submit_iso_transfer(int sub_api, struct usbi_transfer *itransfer)
4451 {
4452 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
4453 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(transfer->dev_handle);
4454 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
4455 	int current_interface;
4456 
4457 	UNUSED(sub_api);
4458 
4459 	current_interface = interface_by_endpoint(priv, handle_priv, transfer->endpoint);
4460 	if (current_interface < 0) {
4461 		usbi_err(TRANSFER_CTX(transfer), "unable to match endpoint to an open interface - cancelling transfer");
4462 		return LIBUSB_ERROR_NOT_FOUND;
4463 	}
4464 
4465 	CHECK_SUPPORTED_API(priv->usb_interface[current_interface].apib, submit_iso_transfer);
4466 
4467 	return priv->usb_interface[current_interface].apib->
4468 		submit_iso_transfer(priv->usb_interface[current_interface].sub_api, itransfer);
4469 }
4470 
composite_clear_halt(int sub_api,struct libusb_device_handle * dev_handle,unsigned char endpoint)4471 static int composite_clear_halt(int sub_api, struct libusb_device_handle *dev_handle, unsigned char endpoint)
4472 {
4473 	struct winusb_device_handle_priv *handle_priv = get_winusb_device_handle_priv(dev_handle);
4474 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
4475 	int current_interface;
4476 
4477 	UNUSED(sub_api);
4478 
4479 	current_interface = interface_by_endpoint(priv, handle_priv, endpoint);
4480 	if (current_interface < 0) {
4481 		usbi_err(HANDLE_CTX(dev_handle), "unable to match endpoint to an open interface - cannot clear");
4482 		return LIBUSB_ERROR_NOT_FOUND;
4483 	}
4484 
4485 	CHECK_SUPPORTED_API(priv->usb_interface[current_interface].apib, clear_halt);
4486 
4487 	return priv->usb_interface[current_interface].apib->
4488 		clear_halt(priv->usb_interface[current_interface].sub_api, dev_handle, endpoint);
4489 }
4490 
composite_cancel_transfer(int sub_api,struct usbi_transfer * itransfer)4491 static int composite_cancel_transfer(int sub_api, struct usbi_transfer *itransfer)
4492 {
4493 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
4494 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
4495 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
4496 	int current_interface = transfer_priv->interface_number;
4497 
4498 	UNUSED(sub_api);
4499 
4500 	if ((current_interface < 0) || (current_interface >= USB_MAXINTERFACES)) {
4501 		usbi_err(TRANSFER_CTX(transfer), "program assertion failed - invalid interface_number");
4502 		return LIBUSB_ERROR_NOT_FOUND;
4503 	}
4504 
4505 	CHECK_SUPPORTED_API(priv->usb_interface[current_interface].apib, cancel_transfer);
4506 
4507 	return priv->usb_interface[current_interface].apib->
4508 		cancel_transfer(priv->usb_interface[current_interface].sub_api, itransfer);
4509 }
4510 
composite_reset_device(int sub_api,struct libusb_device_handle * dev_handle)4511 static int composite_reset_device(int sub_api, struct libusb_device_handle *dev_handle)
4512 {
4513 	struct winusb_device_priv *priv = usbi_get_device_priv(dev_handle->dev);
4514 	int i, r;
4515 	bool available[SUB_API_MAX];
4516 
4517 	UNUSED(sub_api);
4518 
4519 	for (i = 0; i < SUB_API_MAX; i++)
4520 		available[i] = false;
4521 
4522 	for (i = 0; i < USB_MAXINTERFACES; i++) {
4523 		if ((priv->usb_interface[i].apib->id == USB_API_WINUSBX)
4524 				&& (priv->usb_interface[i].sub_api != SUB_API_NOTSET))
4525 			available[priv->usb_interface[i].sub_api] = true;
4526 	}
4527 
4528 	for (i = 0; i < SUB_API_MAX; i++) {
4529 		if (available[i]) {
4530 			r = usb_api_backend[USB_API_WINUSBX].reset_device(i, dev_handle);
4531 			if (r != LIBUSB_SUCCESS)
4532 				return r;
4533 		}
4534 	}
4535 
4536 	return LIBUSB_SUCCESS;
4537 }
4538 
composite_copy_transfer_data(int sub_api,struct usbi_transfer * itransfer,DWORD length)4539 static enum libusb_transfer_status composite_copy_transfer_data(int sub_api, struct usbi_transfer *itransfer, DWORD length)
4540 {
4541 	struct libusb_transfer *transfer = USBI_TRANSFER_TO_LIBUSB_TRANSFER(itransfer);
4542 	struct winusb_transfer_priv *transfer_priv = get_winusb_transfer_priv(itransfer);
4543 	struct winusb_device_priv *priv = usbi_get_device_priv(transfer->dev_handle->dev);
4544 	int current_interface = transfer_priv->interface_number;
4545 
4546 	UNUSED(sub_api);
4547 	if (priv->usb_interface[current_interface].apib->copy_transfer_data == NULL) {
4548 		usbi_err(TRANSFER_CTX(transfer), "program assertion failed - no function to copy transfer data");
4549 		return LIBUSB_TRANSFER_ERROR;
4550 	}
4551 
4552 	return priv->usb_interface[current_interface].apib->
4553 		copy_transfer_data(priv->usb_interface[current_interface].sub_api, itransfer, length);
4554 }
4555