• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3  *
4  *  Bluetooth support for Broadcom devices
5  *
6  *  Copyright (C) 2015  Intel Corporation
7  */
8 
9 #ifndef __GENKSYMS__	// ANDROID CRC kabi preservation hack due to commit 76dd7893bd10
10 #include <linux/efi.h>
11 #endif
12 #include <linux/module.h>
13 #include <linux/firmware.h>
14 #include <linux/dmi.h>
15 #include <asm/unaligned.h>
16 
17 #include <net/bluetooth/bluetooth.h>
18 #include <net/bluetooth/hci_core.h>
19 
20 #include "btbcm.h"
21 
22 #define VERSION "0.1"
23 
24 #define BDADDR_BCM20702A0 (&(bdaddr_t) {{0x00, 0xa0, 0x02, 0x70, 0x20, 0x00}})
25 #define BDADDR_BCM20702A1 (&(bdaddr_t) {{0x00, 0x00, 0xa0, 0x02, 0x70, 0x20}})
26 #define BDADDR_BCM2076B1 (&(bdaddr_t) {{0x79, 0x56, 0x00, 0xa0, 0x76, 0x20}})
27 #define BDADDR_BCM43430A0 (&(bdaddr_t) {{0xac, 0x1f, 0x12, 0xa0, 0x43, 0x43}})
28 #define BDADDR_BCM4324B3 (&(bdaddr_t) {{0x00, 0x00, 0x00, 0xb3, 0x24, 0x43}})
29 #define BDADDR_BCM4330B1 (&(bdaddr_t) {{0x00, 0x00, 0x00, 0xb1, 0x30, 0x43}})
30 #define BDADDR_BCM4334B0 (&(bdaddr_t) {{0x00, 0x00, 0x00, 0xb0, 0x34, 0x43}})
31 #define BDADDR_BCM4345C5 (&(bdaddr_t) {{0xac, 0x1f, 0x00, 0xc5, 0x45, 0x43}})
32 #define BDADDR_BCM43341B (&(bdaddr_t) {{0xac, 0x1f, 0x00, 0x1b, 0x34, 0x43}})
33 
34 #define BCM_FW_NAME_LEN			64
35 #define BCM_FW_NAME_COUNT_MAX		2
36 /* For kmalloc-ing the fw-name array instead of putting it on the stack */
37 typedef char bcm_fw_name[BCM_FW_NAME_LEN];
38 
39 #ifdef CONFIG_EFI
btbcm_set_bdaddr_from_efi(struct hci_dev * hdev)40 static int btbcm_set_bdaddr_from_efi(struct hci_dev *hdev)
41 {
42 	efi_guid_t guid = EFI_GUID(0x74b00bd9, 0x805a, 0x4d61, 0xb5, 0x1f,
43 				   0x43, 0x26, 0x81, 0x23, 0xd1, 0x13);
44 	bdaddr_t efi_bdaddr, bdaddr;
45 	efi_status_t status;
46 	unsigned long len;
47 	int ret;
48 
49 	if (!efi_rt_services_supported(EFI_RT_SUPPORTED_GET_VARIABLE))
50 		return -EOPNOTSUPP;
51 
52 	len = sizeof(efi_bdaddr);
53 	status = efi.get_variable(L"BDADDR", &guid, NULL, &len, &efi_bdaddr);
54 	if (status != EFI_SUCCESS)
55 		return -ENXIO;
56 
57 	if (len != sizeof(efi_bdaddr))
58 		return -EIO;
59 
60 	baswap(&bdaddr, &efi_bdaddr);
61 
62 	ret = btbcm_set_bdaddr(hdev, &bdaddr);
63 	if (ret)
64 		return ret;
65 
66 	bt_dev_info(hdev, "BCM: Using EFI device address (%pMR)", &bdaddr);
67 	return 0;
68 }
69 #else
btbcm_set_bdaddr_from_efi(struct hci_dev * hdev)70 static int btbcm_set_bdaddr_from_efi(struct hci_dev *hdev)
71 {
72 	return -EOPNOTSUPP;
73 }
74 #endif
75 
btbcm_check_bdaddr(struct hci_dev * hdev)76 int btbcm_check_bdaddr(struct hci_dev *hdev)
77 {
78 	struct hci_rp_read_bd_addr *bda;
79 	struct sk_buff *skb;
80 
81 	skb = __hci_cmd_sync(hdev, HCI_OP_READ_BD_ADDR, 0, NULL,
82 			     HCI_INIT_TIMEOUT);
83 	if (IS_ERR(skb)) {
84 		int err = PTR_ERR(skb);
85 
86 		bt_dev_err(hdev, "BCM: Reading device address failed (%d)", err);
87 		return err;
88 	}
89 
90 	if (skb->len != sizeof(*bda)) {
91 		bt_dev_err(hdev, "BCM: Device address length mismatch");
92 		kfree_skb(skb);
93 		return -EIO;
94 	}
95 
96 	bda = (struct hci_rp_read_bd_addr *)skb->data;
97 
98 	/* Check if the address indicates a controller with either an
99 	 * invalid or default address. In both cases the device needs
100 	 * to be marked as not having a valid address.
101 	 *
102 	 * The address 00:20:70:02:A0:00 indicates a BCM20702A0 controller
103 	 * with no configured address.
104 	 *
105 	 * The address 20:70:02:A0:00:00 indicates a BCM20702A1 controller
106 	 * with no configured address.
107 	 *
108 	 * The address 20:76:A0:00:56:79 indicates a BCM2076B1 controller
109 	 * with no configured address.
110 	 *
111 	 * The address 43:24:B3:00:00:00 indicates a BCM4324B3 controller
112 	 * with waiting for configuration state.
113 	 *
114 	 * The address 43:30:B1:00:00:00 indicates a BCM4330B1 controller
115 	 * with waiting for configuration state.
116 	 *
117 	 * The address 43:43:A0:12:1F:AC indicates a BCM43430A0 controller
118 	 * with no configured address.
119 	 */
120 	if (!bacmp(&bda->bdaddr, BDADDR_BCM20702A0) ||
121 	    !bacmp(&bda->bdaddr, BDADDR_BCM20702A1) ||
122 	    !bacmp(&bda->bdaddr, BDADDR_BCM2076B1) ||
123 	    !bacmp(&bda->bdaddr, BDADDR_BCM4324B3) ||
124 	    !bacmp(&bda->bdaddr, BDADDR_BCM4330B1) ||
125 	    !bacmp(&bda->bdaddr, BDADDR_BCM4334B0) ||
126 	    !bacmp(&bda->bdaddr, BDADDR_BCM4345C5) ||
127 	    !bacmp(&bda->bdaddr, BDADDR_BCM43430A0) ||
128 	    !bacmp(&bda->bdaddr, BDADDR_BCM43341B)) {
129 		/* Try falling back to BDADDR EFI variable */
130 		if (btbcm_set_bdaddr_from_efi(hdev) != 0) {
131 			bt_dev_info(hdev, "BCM: Using default device address (%pMR)",
132 				    &bda->bdaddr);
133 			set_bit(HCI_QUIRK_INVALID_BDADDR, &hdev->quirks);
134 		}
135 	}
136 
137 	kfree_skb(skb);
138 
139 	return 0;
140 }
141 EXPORT_SYMBOL_GPL(btbcm_check_bdaddr);
142 
btbcm_set_bdaddr(struct hci_dev * hdev,const bdaddr_t * bdaddr)143 int btbcm_set_bdaddr(struct hci_dev *hdev, const bdaddr_t *bdaddr)
144 {
145 	struct sk_buff *skb;
146 	int err;
147 
148 	skb = __hci_cmd_sync(hdev, 0xfc01, 6, bdaddr, HCI_INIT_TIMEOUT);
149 	if (IS_ERR(skb)) {
150 		err = PTR_ERR(skb);
151 		bt_dev_err(hdev, "BCM: Change address command failed (%d)", err);
152 		return err;
153 	}
154 	kfree_skb(skb);
155 
156 	return 0;
157 }
158 EXPORT_SYMBOL_GPL(btbcm_set_bdaddr);
159 
btbcm_read_pcm_int_params(struct hci_dev * hdev,struct bcm_set_pcm_int_params * params)160 int btbcm_read_pcm_int_params(struct hci_dev *hdev,
161 			      struct bcm_set_pcm_int_params *params)
162 {
163 	struct sk_buff *skb;
164 	int err = 0;
165 
166 	skb = __hci_cmd_sync(hdev, 0xfc1d, 0, NULL, HCI_INIT_TIMEOUT);
167 	if (IS_ERR(skb)) {
168 		err = PTR_ERR(skb);
169 		bt_dev_err(hdev, "BCM: Read PCM int params failed (%d)", err);
170 		return err;
171 	}
172 
173 	if (skb->len != 6 || skb->data[0]) {
174 		bt_dev_err(hdev, "BCM: Read PCM int params length mismatch");
175 		kfree_skb(skb);
176 		return -EIO;
177 	}
178 
179 	if (params)
180 		memcpy(params, skb->data + 1, 5);
181 
182 	kfree_skb(skb);
183 
184 	return 0;
185 }
186 EXPORT_SYMBOL_GPL(btbcm_read_pcm_int_params);
187 
btbcm_write_pcm_int_params(struct hci_dev * hdev,const struct bcm_set_pcm_int_params * params)188 int btbcm_write_pcm_int_params(struct hci_dev *hdev,
189 			       const struct bcm_set_pcm_int_params *params)
190 {
191 	struct sk_buff *skb;
192 	int err;
193 
194 	skb = __hci_cmd_sync(hdev, 0xfc1c, 5, params, HCI_INIT_TIMEOUT);
195 	if (IS_ERR(skb)) {
196 		err = PTR_ERR(skb);
197 		bt_dev_err(hdev, "BCM: Write PCM int params failed (%d)", err);
198 		return err;
199 	}
200 	kfree_skb(skb);
201 
202 	return 0;
203 }
204 EXPORT_SYMBOL_GPL(btbcm_write_pcm_int_params);
205 
btbcm_patchram(struct hci_dev * hdev,const struct firmware * fw)206 int btbcm_patchram(struct hci_dev *hdev, const struct firmware *fw)
207 {
208 	const struct hci_command_hdr *cmd;
209 	const u8 *fw_ptr;
210 	size_t fw_size;
211 	struct sk_buff *skb;
212 	u16 opcode;
213 	int err = 0;
214 
215 	/* Start Download */
216 	skb = __hci_cmd_sync(hdev, 0xfc2e, 0, NULL, HCI_INIT_TIMEOUT);
217 	if (IS_ERR(skb)) {
218 		err = PTR_ERR(skb);
219 		bt_dev_err(hdev, "BCM: Download Minidrv command failed (%d)",
220 			   err);
221 		goto done;
222 	}
223 	kfree_skb(skb);
224 
225 	/* 50 msec delay after Download Minidrv completes */
226 	msleep(50);
227 
228 	fw_ptr = fw->data;
229 	fw_size = fw->size;
230 
231 	while (fw_size >= sizeof(*cmd)) {
232 		const u8 *cmd_param;
233 
234 		cmd = (struct hci_command_hdr *)fw_ptr;
235 		fw_ptr += sizeof(*cmd);
236 		fw_size -= sizeof(*cmd);
237 
238 		if (fw_size < cmd->plen) {
239 			bt_dev_err(hdev, "BCM: Patch is corrupted");
240 			err = -EINVAL;
241 			goto done;
242 		}
243 
244 		cmd_param = fw_ptr;
245 		fw_ptr += cmd->plen;
246 		fw_size -= cmd->plen;
247 
248 		opcode = le16_to_cpu(cmd->opcode);
249 
250 		skb = __hci_cmd_sync(hdev, opcode, cmd->plen, cmd_param,
251 				     HCI_INIT_TIMEOUT);
252 		if (IS_ERR(skb)) {
253 			err = PTR_ERR(skb);
254 			bt_dev_err(hdev, "BCM: Patch command %04x failed (%d)",
255 				   opcode, err);
256 			goto done;
257 		}
258 		kfree_skb(skb);
259 	}
260 
261 	/* 250 msec delay after Launch Ram completes */
262 	msleep(250);
263 
264 done:
265 	return err;
266 }
267 EXPORT_SYMBOL(btbcm_patchram);
268 
btbcm_reset(struct hci_dev * hdev)269 static int btbcm_reset(struct hci_dev *hdev)
270 {
271 	struct sk_buff *skb;
272 
273 	skb = __hci_cmd_sync(hdev, HCI_OP_RESET, 0, NULL, HCI_INIT_TIMEOUT);
274 	if (IS_ERR(skb)) {
275 		int err = PTR_ERR(skb);
276 
277 		bt_dev_err(hdev, "BCM: Reset failed (%d)", err);
278 		return err;
279 	}
280 	kfree_skb(skb);
281 
282 	/* 100 msec delay for module to complete reset process */
283 	msleep(100);
284 
285 	return 0;
286 }
287 
btbcm_read_local_name(struct hci_dev * hdev)288 static struct sk_buff *btbcm_read_local_name(struct hci_dev *hdev)
289 {
290 	struct sk_buff *skb;
291 
292 	skb = __hci_cmd_sync(hdev, HCI_OP_READ_LOCAL_NAME, 0, NULL,
293 			     HCI_INIT_TIMEOUT);
294 	if (IS_ERR(skb)) {
295 		bt_dev_err(hdev, "BCM: Reading local name failed (%ld)",
296 			   PTR_ERR(skb));
297 		return skb;
298 	}
299 
300 	if (skb->len != sizeof(struct hci_rp_read_local_name)) {
301 		bt_dev_err(hdev, "BCM: Local name length mismatch");
302 		kfree_skb(skb);
303 		return ERR_PTR(-EIO);
304 	}
305 
306 	return skb;
307 }
308 
btbcm_read_local_version(struct hci_dev * hdev)309 static struct sk_buff *btbcm_read_local_version(struct hci_dev *hdev)
310 {
311 	struct sk_buff *skb;
312 
313 	skb = __hci_cmd_sync(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL,
314 			     HCI_INIT_TIMEOUT);
315 	if (IS_ERR(skb)) {
316 		bt_dev_err(hdev, "BCM: Reading local version info failed (%ld)",
317 			   PTR_ERR(skb));
318 		return skb;
319 	}
320 
321 	if (skb->len != sizeof(struct hci_rp_read_local_version)) {
322 		bt_dev_err(hdev, "BCM: Local version length mismatch");
323 		kfree_skb(skb);
324 		return ERR_PTR(-EIO);
325 	}
326 
327 	return skb;
328 }
329 
btbcm_read_verbose_config(struct hci_dev * hdev)330 static struct sk_buff *btbcm_read_verbose_config(struct hci_dev *hdev)
331 {
332 	struct sk_buff *skb;
333 
334 	skb = __hci_cmd_sync(hdev, 0xfc79, 0, NULL, HCI_INIT_TIMEOUT);
335 	if (IS_ERR(skb)) {
336 		bt_dev_err(hdev, "BCM: Read verbose config info failed (%ld)",
337 			   PTR_ERR(skb));
338 		return skb;
339 	}
340 
341 	if (skb->len != 7) {
342 		bt_dev_err(hdev, "BCM: Verbose config length mismatch");
343 		kfree_skb(skb);
344 		return ERR_PTR(-EIO);
345 	}
346 
347 	return skb;
348 }
349 
btbcm_read_controller_features(struct hci_dev * hdev)350 static struct sk_buff *btbcm_read_controller_features(struct hci_dev *hdev)
351 {
352 	struct sk_buff *skb;
353 
354 	skb = __hci_cmd_sync(hdev, 0xfc6e, 0, NULL, HCI_INIT_TIMEOUT);
355 	if (IS_ERR(skb)) {
356 		bt_dev_err(hdev, "BCM: Read controller features failed (%ld)",
357 			   PTR_ERR(skb));
358 		return skb;
359 	}
360 
361 	if (skb->len != 9) {
362 		bt_dev_err(hdev, "BCM: Controller features length mismatch");
363 		kfree_skb(skb);
364 		return ERR_PTR(-EIO);
365 	}
366 
367 	return skb;
368 }
369 
btbcm_read_usb_product(struct hci_dev * hdev)370 static struct sk_buff *btbcm_read_usb_product(struct hci_dev *hdev)
371 {
372 	struct sk_buff *skb;
373 
374 	skb = __hci_cmd_sync(hdev, 0xfc5a, 0, NULL, HCI_INIT_TIMEOUT);
375 	if (IS_ERR(skb)) {
376 		bt_dev_err(hdev, "BCM: Read USB product info failed (%ld)",
377 			   PTR_ERR(skb));
378 		return skb;
379 	}
380 
381 	if (skb->len != 5) {
382 		bt_dev_err(hdev, "BCM: USB product length mismatch");
383 		kfree_skb(skb);
384 		return ERR_PTR(-EIO);
385 	}
386 
387 	return skb;
388 }
389 
390 static const struct dmi_system_id disable_broken_read_transmit_power[] = {
391 	{
392 		 .matches = {
393 			DMI_MATCH(DMI_BOARD_VENDOR, "Apple Inc."),
394 			DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,1"),
395 		},
396 	},
397 	{
398 		 .matches = {
399 			DMI_MATCH(DMI_BOARD_VENDOR, "Apple Inc."),
400 			DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,2"),
401 		},
402 	},
403 	{
404 		 .matches = {
405 			DMI_MATCH(DMI_BOARD_VENDOR, "Apple Inc."),
406 			DMI_MATCH(DMI_PRODUCT_NAME, "MacBookPro16,4"),
407 		},
408 	},
409 	{
410 		 .matches = {
411 			DMI_MATCH(DMI_BOARD_VENDOR, "Apple Inc."),
412 			DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,1"),
413 		},
414 	},
415 	{
416 		 .matches = {
417 			DMI_MATCH(DMI_BOARD_VENDOR, "Apple Inc."),
418 			DMI_MATCH(DMI_PRODUCT_NAME, "MacBookAir8,2"),
419 		},
420 	},
421 	{
422 		 .matches = {
423 			DMI_MATCH(DMI_BOARD_VENDOR, "Apple Inc."),
424 			DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,1"),
425 		},
426 	},
427 	{
428 		 .matches = {
429 			DMI_MATCH(DMI_BOARD_VENDOR, "Apple Inc."),
430 			DMI_MATCH(DMI_PRODUCT_NAME, "iMac20,2"),
431 		},
432 	},
433 	{ }
434 };
435 
btbcm_read_info(struct hci_dev * hdev)436 static int btbcm_read_info(struct hci_dev *hdev)
437 {
438 	struct sk_buff *skb;
439 
440 	/* Read Verbose Config Version Info */
441 	skb = btbcm_read_verbose_config(hdev);
442 	if (IS_ERR(skb))
443 		return PTR_ERR(skb);
444 
445 	bt_dev_info(hdev, "BCM: chip id %u", skb->data[1]);
446 	kfree_skb(skb);
447 
448 	/* Read Controller Features */
449 	skb = btbcm_read_controller_features(hdev);
450 	if (IS_ERR(skb))
451 		return PTR_ERR(skb);
452 
453 	bt_dev_info(hdev, "BCM: features 0x%2.2x", skb->data[1]);
454 	kfree_skb(skb);
455 
456 	/* Read DMI and disable broken Read LE Min/Max Tx Power */
457 	if (dmi_first_match(disable_broken_read_transmit_power))
458 		set_bit(HCI_QUIRK_BROKEN_READ_TRANSMIT_POWER, &hdev->quirks);
459 
460 	return 0;
461 }
462 
btbcm_print_local_name(struct hci_dev * hdev)463 static int btbcm_print_local_name(struct hci_dev *hdev)
464 {
465 	struct sk_buff *skb;
466 
467 	/* Read Local Name */
468 	skb = btbcm_read_local_name(hdev);
469 	if (IS_ERR(skb))
470 		return PTR_ERR(skb);
471 
472 	bt_dev_info(hdev, "%s", (char *)(skb->data + 1));
473 	kfree_skb(skb);
474 
475 	return 0;
476 }
477 
478 struct bcm_subver_table {
479 	u16 subver;
480 	const char *name;
481 };
482 
483 static const struct bcm_subver_table bcm_uart_subver_table[] = {
484 	{ 0x1111, "BCM4362A2"	},	/* 000.017.017 */
485 	{ 0x4103, "BCM4330B1"	},	/* 002.001.003 */
486 	{ 0x410d, "BCM4334B0"	},	/* 002.001.013 */
487 	{ 0x410e, "BCM43341B0"	},	/* 002.001.014 */
488 	{ 0x4204, "BCM2076B1"	},	/* 002.002.004 */
489 	{ 0x4406, "BCM4324B3"	},	/* 002.004.006 */
490 	{ 0x4606, "BCM4324B5"	},	/* 002.006.006 */
491 	{ 0x6109, "BCM4335C0"	},	/* 003.001.009 */
492 	{ 0x610c, "BCM4354"	},	/* 003.001.012 */
493 	{ 0x2122, "BCM4343A0"	},	/* 001.001.034 */
494 	{ 0x2209, "BCM43430A1"  },	/* 001.002.009 */
495 	{ 0x6119, "BCM4345C0"	},	/* 003.001.025 */
496 	{ 0x6606, "BCM4345C5"	},	/* 003.006.006 */
497 	{ 0x230f, "BCM4356A2"	},	/* 001.003.015 */
498 	{ 0x220e, "BCM20702A1"  },	/* 001.002.014 */
499 	{ 0x420d, "BCM4349B1"	},	/* 002.002.013 */
500 	{ 0x420e, "BCM4349B1"	},	/* 002.002.014 */
501 	{ 0x4217, "BCM4329B1"   },	/* 002.002.023 */
502 	{ 0x6106, "BCM4359C0"	},	/* 003.001.006 */
503 	{ 0x4106, "BCM4335A0"	},	/* 002.001.006 */
504 	{ 0x410c, "BCM43430B0"	},	/* 002.001.012 */
505 	{ }
506 };
507 
508 static const struct bcm_subver_table bcm_usb_subver_table[] = {
509 	{ 0x2105, "BCM20703A1"	},	/* 001.001.005 */
510 	{ 0x210b, "BCM43142A0"	},	/* 001.001.011 */
511 	{ 0x2112, "BCM4314A0"	},	/* 001.001.018 */
512 	{ 0x2118, "BCM20702A0"	},	/* 001.001.024 */
513 	{ 0x2126, "BCM4335A0"	},	/* 001.001.038 */
514 	{ 0x220e, "BCM20702A1"	},	/* 001.002.014 */
515 	{ 0x230f, "BCM4356A2"	},	/* 001.003.015 */
516 	{ 0x4106, "BCM4335B0"	},	/* 002.001.006 */
517 	{ 0x410e, "BCM20702B0"	},	/* 002.001.014 */
518 	{ 0x6109, "BCM4335C0"	},	/* 003.001.009 */
519 	{ 0x610c, "BCM4354"	},	/* 003.001.012 */
520 	{ 0x6607, "BCM4350C5"	},	/* 003.006.007 */
521 	{ }
522 };
523 
btbcm_initialize(struct hci_dev * hdev,bool * fw_load_done)524 int btbcm_initialize(struct hci_dev *hdev, bool *fw_load_done)
525 {
526 	u16 subver, rev, pid, vid;
527 	struct sk_buff *skb;
528 	struct hci_rp_read_local_version *ver;
529 	const struct bcm_subver_table *bcm_subver_table;
530 	const char *hw_name = NULL;
531 	char postfix[16] = "";
532 	int fw_name_count = 0;
533 	bcm_fw_name *fw_name;
534 	const struct firmware *fw;
535 	int i, err;
536 
537 	/* Reset */
538 	err = btbcm_reset(hdev);
539 	if (err)
540 		return err;
541 
542 	/* Read Local Version Info */
543 	skb = btbcm_read_local_version(hdev);
544 	if (IS_ERR(skb))
545 		return PTR_ERR(skb);
546 
547 	ver = (struct hci_rp_read_local_version *)skb->data;
548 	rev = le16_to_cpu(ver->hci_rev);
549 	subver = le16_to_cpu(ver->lmp_subver);
550 	kfree_skb(skb);
551 
552 	/* Read controller information */
553 	if (!(*fw_load_done)) {
554 		err = btbcm_read_info(hdev);
555 		if (err)
556 			return err;
557 	}
558 	err = btbcm_print_local_name(hdev);
559 	if (err)
560 		return err;
561 
562 	bcm_subver_table = (hdev->bus == HCI_USB) ? bcm_usb_subver_table :
563 						    bcm_uart_subver_table;
564 
565 	for (i = 0; bcm_subver_table[i].name; i++) {
566 		if (subver == bcm_subver_table[i].subver) {
567 			hw_name = bcm_subver_table[i].name;
568 			break;
569 		}
570 	}
571 
572 	bt_dev_info(hdev, "%s (%3.3u.%3.3u.%3.3u) build %4.4u",
573 		    hw_name ? hw_name : "BCM", (subver & 0xe000) >> 13,
574 		    (subver & 0x1f00) >> 8, (subver & 0x00ff), rev & 0x0fff);
575 
576 	if (*fw_load_done)
577 		return 0;
578 
579 	if (hdev->bus == HCI_USB) {
580 		/* Read USB Product Info */
581 		skb = btbcm_read_usb_product(hdev);
582 		if (IS_ERR(skb))
583 			return PTR_ERR(skb);
584 
585 		vid = get_unaligned_le16(skb->data + 1);
586 		pid = get_unaligned_le16(skb->data + 3);
587 		kfree_skb(skb);
588 
589 		snprintf(postfix, sizeof(postfix), "-%4.4x-%4.4x", vid, pid);
590 	}
591 
592 	fw_name = kmalloc(BCM_FW_NAME_COUNT_MAX * BCM_FW_NAME_LEN, GFP_KERNEL);
593 	if (!fw_name)
594 		return -ENOMEM;
595 
596 	if (hw_name) {
597 		snprintf(fw_name[fw_name_count], BCM_FW_NAME_LEN,
598 			 "brcm/%s%s.hcd", hw_name, postfix);
599 		fw_name_count++;
600 	}
601 
602 	snprintf(fw_name[fw_name_count], BCM_FW_NAME_LEN,
603 		 "brcm/BCM%s.hcd", postfix);
604 	fw_name_count++;
605 
606 	for (i = 0; i < fw_name_count; i++) {
607 		err = firmware_request_nowarn(&fw, fw_name[i], &hdev->dev);
608 		if (err == 0) {
609 			bt_dev_info(hdev, "%s '%s' Patch",
610 				    hw_name ? hw_name : "BCM", fw_name[i]);
611 			*fw_load_done = true;
612 			break;
613 		}
614 	}
615 
616 	if (*fw_load_done) {
617 		err = btbcm_patchram(hdev, fw);
618 		if (err)
619 			bt_dev_info(hdev, "BCM: Patch failed (%d)", err);
620 
621 		release_firmware(fw);
622 	} else {
623 		bt_dev_err(hdev, "BCM: firmware Patch file not found, tried:");
624 		for (i = 0; i < fw_name_count; i++)
625 			bt_dev_err(hdev, "BCM: '%s'", fw_name[i]);
626 	}
627 
628 	kfree(fw_name);
629 	return 0;
630 }
631 EXPORT_SYMBOL_GPL(btbcm_initialize);
632 
btbcm_finalize(struct hci_dev * hdev,bool * fw_load_done)633 int btbcm_finalize(struct hci_dev *hdev, bool *fw_load_done)
634 {
635 	int err;
636 
637 	/* Re-initialize if necessary */
638 	if (*fw_load_done) {
639 		err = btbcm_initialize(hdev, fw_load_done);
640 		if (err)
641 			return err;
642 	}
643 
644 	btbcm_check_bdaddr(hdev);
645 
646 	set_bit(HCI_QUIRK_STRICT_DUPLICATE_FILTER, &hdev->quirks);
647 
648 	return 0;
649 }
650 EXPORT_SYMBOL_GPL(btbcm_finalize);
651 
btbcm_setup_patchram(struct hci_dev * hdev)652 int btbcm_setup_patchram(struct hci_dev *hdev)
653 {
654 	bool fw_load_done = false;
655 	int err;
656 
657 	/* Initialize */
658 	err = btbcm_initialize(hdev, &fw_load_done);
659 	if (err)
660 		return err;
661 
662 	/* Re-initialize after loading Patch */
663 	return btbcm_finalize(hdev, &fw_load_done);
664 }
665 EXPORT_SYMBOL_GPL(btbcm_setup_patchram);
666 
btbcm_setup_apple(struct hci_dev * hdev)667 int btbcm_setup_apple(struct hci_dev *hdev)
668 {
669 	struct sk_buff *skb;
670 	int err;
671 
672 	/* Reset */
673 	err = btbcm_reset(hdev);
674 	if (err)
675 		return err;
676 
677 	/* Read Verbose Config Version Info */
678 	skb = btbcm_read_verbose_config(hdev);
679 	if (!IS_ERR(skb)) {
680 		bt_dev_info(hdev, "BCM: chip id %u build %4.4u",
681 			    skb->data[1], get_unaligned_le16(skb->data + 5));
682 		kfree_skb(skb);
683 	}
684 
685 	/* Read USB Product Info */
686 	skb = btbcm_read_usb_product(hdev);
687 	if (!IS_ERR(skb)) {
688 		bt_dev_info(hdev, "BCM: product %4.4x:%4.4x",
689 			    get_unaligned_le16(skb->data + 1),
690 			    get_unaligned_le16(skb->data + 3));
691 		kfree_skb(skb);
692 	}
693 
694 	/* Read Controller Features */
695 	skb = btbcm_read_controller_features(hdev);
696 	if (!IS_ERR(skb)) {
697 		bt_dev_info(hdev, "BCM: features 0x%2.2x", skb->data[1]);
698 		kfree_skb(skb);
699 	}
700 
701 	/* Read Local Name */
702 	skb = btbcm_read_local_name(hdev);
703 	if (!IS_ERR(skb)) {
704 		bt_dev_info(hdev, "%s", (char *)(skb->data + 1));
705 		kfree_skb(skb);
706 	}
707 
708 	set_bit(HCI_QUIRK_STRICT_DUPLICATE_FILTER, &hdev->quirks);
709 
710 	return 0;
711 }
712 EXPORT_SYMBOL_GPL(btbcm_setup_apple);
713 
714 MODULE_AUTHOR("Marcel Holtmann <marcel@holtmann.org>");
715 MODULE_DESCRIPTION("Bluetooth support for Broadcom devices ver " VERSION);
716 MODULE_VERSION(VERSION);
717 MODULE_LICENSE("GPL");
718