Statistics
| Branch: | Revision:

root / hw / bt-hci-csr.c @ 7696d1ec

History | View | Annotate | Download (12.1 kB)

1 58a26b47 balrog
/*
2 58a26b47 balrog
 * Bluetooth serial HCI transport.
3 58a26b47 balrog
 * CSR41814 HCI with H4p vendor extensions.
4 58a26b47 balrog
 *
5 58a26b47 balrog
 * Copyright (C) 2008 Andrzej Zaborowski  <balrog@zabor.org>
6 58a26b47 balrog
 *
7 58a26b47 balrog
 * This program is free software; you can redistribute it and/or
8 58a26b47 balrog
 * modify it under the terms of the GNU General Public License as
9 58a26b47 balrog
 * published by the Free Software Foundation; either version 2 or
10 58a26b47 balrog
 * (at your option) version 3 of the License.
11 58a26b47 balrog
 *
12 58a26b47 balrog
 * This program is distributed in the hope that it will be useful,
13 58a26b47 balrog
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 58a26b47 balrog
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15 58a26b47 balrog
 * GNU General Public License for more details.
16 58a26b47 balrog
 *
17 fad6cb1a aurel32
 * You should have received a copy of the GNU General Public License along
18 fad6cb1a aurel32
 * with this program; if not, write to the Free Software Foundation, Inc.,
19 fad6cb1a aurel32
 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
20 58a26b47 balrog
 */
21 58a26b47 balrog
22 58a26b47 balrog
#include "qemu-common.h"
23 58a26b47 balrog
#include "qemu-char.h"
24 58a26b47 balrog
#include "qemu-timer.h"
25 58a26b47 balrog
#include "irq.h"
26 58a26b47 balrog
#include "sysemu.h"
27 58a26b47 balrog
#include "net.h"
28 58a26b47 balrog
#include "bt.h"
29 58a26b47 balrog
30 58a26b47 balrog
struct csrhci_s {
31 58a26b47 balrog
    int enable;
32 58a26b47 balrog
    qemu_irq *pins;
33 58a26b47 balrog
    int pin_state;
34 58a26b47 balrog
    int modem_state;
35 58a26b47 balrog
    CharDriverState chr;
36 58a26b47 balrog
#define FIFO_LEN        4096
37 58a26b47 balrog
    int out_start;
38 58a26b47 balrog
    int out_len;
39 58a26b47 balrog
    int out_size;
40 58a26b47 balrog
    uint8_t outfifo[FIFO_LEN * 2];
41 58a26b47 balrog
    uint8_t inpkt[FIFO_LEN];
42 58a26b47 balrog
    int in_len;
43 58a26b47 balrog
    int in_hdr;
44 58a26b47 balrog
    int in_data;
45 58a26b47 balrog
    QEMUTimer *out_tm;
46 58a26b47 balrog
    int64_t baud_delay;
47 58a26b47 balrog
48 58a26b47 balrog
    bdaddr_t bd_addr;
49 58a26b47 balrog
    struct HCIInfo *hci;
50 58a26b47 balrog
};
51 58a26b47 balrog
52 58a26b47 balrog
/* H4+ packet types */
53 58a26b47 balrog
enum {
54 58a26b47 balrog
    H4_CMD_PKT   = 1,
55 58a26b47 balrog
    H4_ACL_PKT   = 2,
56 58a26b47 balrog
    H4_SCO_PKT   = 3,
57 58a26b47 balrog
    H4_EVT_PKT   = 4,
58 58a26b47 balrog
    H4_NEG_PKT   = 6,
59 58a26b47 balrog
    H4_ALIVE_PKT = 7,
60 58a26b47 balrog
};
61 58a26b47 balrog
62 58a26b47 balrog
/* CSR41814 negotiation start magic packet */
63 58a26b47 balrog
static const uint8_t csrhci_neg_packet[] = {
64 58a26b47 balrog
    H4_NEG_PKT, 10,
65 58a26b47 balrog
    0x00, 0xa0, 0x01, 0x00, 0x00,
66 58a26b47 balrog
    0x4c, 0x00, 0x96, 0x00, 0x00,
67 58a26b47 balrog
};
68 58a26b47 balrog
69 58a26b47 balrog
/* CSR41814 vendor-specific command OCFs */
70 58a26b47 balrog
enum {
71 58a26b47 balrog
    OCF_CSR_SEND_FIRMWARE = 0x000,
72 58a26b47 balrog
};
73 58a26b47 balrog
74 58a26b47 balrog
static inline void csrhci_fifo_wake(struct csrhci_s *s)
75 58a26b47 balrog
{
76 58a26b47 balrog
    if (!s->enable || !s->out_len)
77 58a26b47 balrog
        return;
78 58a26b47 balrog
79 58a26b47 balrog
    /* XXX: Should wait for s->modem_state & CHR_TIOCM_RTS? */
80 58a26b47 balrog
    if (s->chr.chr_can_read && s->chr.chr_can_read(s->chr.handler_opaque) &&
81 58a26b47 balrog
                    s->chr.chr_read) {
82 58a26b47 balrog
        s->chr.chr_read(s->chr.handler_opaque,
83 58a26b47 balrog
                        s->outfifo + s->out_start ++, 1);
84 58a26b47 balrog
        s->out_len --;
85 58a26b47 balrog
        if (s->out_start >= s->out_size) {
86 58a26b47 balrog
            s->out_start = 0;
87 58a26b47 balrog
            s->out_size = FIFO_LEN;
88 58a26b47 balrog
        }
89 58a26b47 balrog
    }
90 58a26b47 balrog
91 58a26b47 balrog
    if (s->out_len)
92 58a26b47 balrog
        qemu_mod_timer(s->out_tm, qemu_get_clock(vm_clock) + s->baud_delay);
93 58a26b47 balrog
}
94 58a26b47 balrog
95 58a26b47 balrog
#define csrhci_out_packetz(s, len) memset(csrhci_out_packet(s, len), 0, len)
96 58a26b47 balrog
static uint8_t *csrhci_out_packet(struct csrhci_s *s, int len)
97 58a26b47 balrog
{
98 58a26b47 balrog
    int off = s->out_start + s->out_len;
99 58a26b47 balrog
100 58a26b47 balrog
    /* TODO: do the padding here, i.e. align len */
101 58a26b47 balrog
    s->out_len += len;
102 58a26b47 balrog
103 58a26b47 balrog
    if (off < FIFO_LEN) {
104 58a26b47 balrog
        if (off + len > FIFO_LEN && (s->out_size = off + len) > FIFO_LEN * 2) {
105 58a26b47 balrog
            fprintf(stderr, "%s: can't alloc %i bytes\n", __FUNCTION__, len);
106 58a26b47 balrog
            exit(-1);
107 58a26b47 balrog
        }
108 58a26b47 balrog
        return s->outfifo + off;
109 58a26b47 balrog
    }
110 58a26b47 balrog
111 58a26b47 balrog
    if (s->out_len > s->out_size) {
112 58a26b47 balrog
        fprintf(stderr, "%s: can't alloc %i bytes\n", __FUNCTION__, len);
113 58a26b47 balrog
        exit(-1);
114 58a26b47 balrog
    }
115 58a26b47 balrog
116 58a26b47 balrog
    return s->outfifo + off - s->out_size;
117 58a26b47 balrog
}
118 58a26b47 balrog
119 58a26b47 balrog
static inline uint8_t *csrhci_out_packet_csr(struct csrhci_s *s,
120 58a26b47 balrog
                int type, int len)
121 58a26b47 balrog
{
122 58a26b47 balrog
    uint8_t *ret = csrhci_out_packetz(s, len + 2);
123 58a26b47 balrog
124 58a26b47 balrog
    *ret ++ = type;
125 58a26b47 balrog
    *ret ++ = len;
126 58a26b47 balrog
127 58a26b47 balrog
    return ret;
128 58a26b47 balrog
}
129 58a26b47 balrog
130 58a26b47 balrog
static inline uint8_t *csrhci_out_packet_event(struct csrhci_s *s,
131 58a26b47 balrog
                int evt, int len)
132 58a26b47 balrog
{
133 58a26b47 balrog
    uint8_t *ret = csrhci_out_packetz(s,
134 58a26b47 balrog
                    len + 1 + sizeof(struct hci_event_hdr));
135 58a26b47 balrog
136 58a26b47 balrog
    *ret ++ = H4_EVT_PKT;
137 58a26b47 balrog
    ((struct hci_event_hdr *) ret)->evt = evt;
138 58a26b47 balrog
    ((struct hci_event_hdr *) ret)->plen = len;
139 58a26b47 balrog
140 58a26b47 balrog
    return ret + sizeof(struct hci_event_hdr);
141 58a26b47 balrog
}
142 58a26b47 balrog
143 58a26b47 balrog
static void csrhci_in_packet_vendor(struct csrhci_s *s, int ocf,
144 58a26b47 balrog
                uint8_t *data, int len)
145 58a26b47 balrog
{
146 58a26b47 balrog
    int offset;
147 58a26b47 balrog
    uint8_t *rpkt;
148 58a26b47 balrog
149 58a26b47 balrog
    switch (ocf) {
150 58a26b47 balrog
    case OCF_CSR_SEND_FIRMWARE:
151 58a26b47 balrog
        /* Check if this is the bd_address packet */
152 58a26b47 balrog
        if (len >= 18 + 8 && data[12] == 0x01 && data[13] == 0x00) {
153 58a26b47 balrog
            offset = 18;
154 58a26b47 balrog
            s->bd_addr.b[0] = data[offset + 7];        /* Beyond cmd packet end(!?) */
155 58a26b47 balrog
            s->bd_addr.b[1] = data[offset + 6];
156 58a26b47 balrog
            s->bd_addr.b[2] = data[offset + 4];
157 58a26b47 balrog
            s->bd_addr.b[3] = data[offset + 0];
158 58a26b47 balrog
            s->bd_addr.b[4] = data[offset + 3];
159 58a26b47 balrog
            s->bd_addr.b[5] = data[offset + 2];
160 58a26b47 balrog
161 58a26b47 balrog
            s->hci->bdaddr_set(s->hci, s->bd_addr.b);
162 58a26b47 balrog
            fprintf(stderr, "%s: bd_address loaded from firmware: "
163 58a26b47 balrog
                            "%02x:%02x:%02x:%02x:%02x:%02x\n", __FUNCTION__,
164 58a26b47 balrog
                            s->bd_addr.b[0], s->bd_addr.b[1], s->bd_addr.b[2],
165 58a26b47 balrog
                            s->bd_addr.b[3], s->bd_addr.b[4], s->bd_addr.b[5]);
166 58a26b47 balrog
        }
167 58a26b47 balrog
168 58a26b47 balrog
        rpkt = csrhci_out_packet_event(s, EVT_VENDOR, 11);
169 58a26b47 balrog
        /* Status bytes: no error */
170 58a26b47 balrog
        rpkt[9] = 0x00;
171 58a26b47 balrog
        rpkt[10] = 0x00;
172 58a26b47 balrog
        break;
173 58a26b47 balrog
174 58a26b47 balrog
    default:
175 58a26b47 balrog
        fprintf(stderr, "%s: got a bad CMD packet\n", __FUNCTION__);
176 58a26b47 balrog
        return;
177 58a26b47 balrog
    }
178 58a26b47 balrog
179 58a26b47 balrog
    csrhci_fifo_wake(s);
180 58a26b47 balrog
}
181 58a26b47 balrog
182 58a26b47 balrog
static void csrhci_in_packet(struct csrhci_s *s, uint8_t *pkt)
183 58a26b47 balrog
{
184 58a26b47 balrog
    uint8_t *rpkt;
185 58a26b47 balrog
    int opc;
186 58a26b47 balrog
187 58a26b47 balrog
    switch (*pkt ++) {
188 58a26b47 balrog
    case H4_CMD_PKT:
189 58a26b47 balrog
        opc = le16_to_cpu(((struct hci_command_hdr *) pkt)->opcode);
190 58a26b47 balrog
        if (cmd_opcode_ogf(opc) == OGF_VENDOR_CMD) {
191 58a26b47 balrog
            csrhci_in_packet_vendor(s, cmd_opcode_ocf(opc),
192 58a26b47 balrog
                            pkt + sizeof(struct hci_command_hdr),
193 58a26b47 balrog
                            s->in_len - sizeof(struct hci_command_hdr) - 1);
194 58a26b47 balrog
            return;
195 58a26b47 balrog
        }
196 58a26b47 balrog
197 58a26b47 balrog
        /* TODO: if the command is OCF_READ_LOCAL_COMMANDS or the likes,
198 58a26b47 balrog
         * we need to send it to the HCI layer and then add our supported
199 58a26b47 balrog
         * commands to the returned mask (such as OGF_VENDOR_CMD).  With
200 58a26b47 balrog
         * bt-hci.c we could just have hooks for this kind of commands but
201 58a26b47 balrog
         * we can't with bt-host.c.  */
202 58a26b47 balrog
203 58a26b47 balrog
        s->hci->cmd_send(s->hci, pkt, s->in_len - 1);
204 58a26b47 balrog
        break;
205 58a26b47 balrog
206 58a26b47 balrog
    case H4_EVT_PKT:
207 58a26b47 balrog
        goto bad_pkt;
208 58a26b47 balrog
209 58a26b47 balrog
    case H4_ACL_PKT:
210 58a26b47 balrog
        s->hci->acl_send(s->hci, pkt, s->in_len - 1);
211 58a26b47 balrog
        break;
212 58a26b47 balrog
213 58a26b47 balrog
    case H4_SCO_PKT:
214 58a26b47 balrog
        s->hci->sco_send(s->hci, pkt, s->in_len - 1);
215 58a26b47 balrog
        break;
216 58a26b47 balrog
217 58a26b47 balrog
    case H4_NEG_PKT:
218 58a26b47 balrog
        if (s->in_hdr != sizeof(csrhci_neg_packet) ||
219 58a26b47 balrog
                        memcmp(pkt - 1, csrhci_neg_packet, s->in_hdr)) {
220 58a26b47 balrog
            fprintf(stderr, "%s: got a bad NEG packet\n", __FUNCTION__);
221 58a26b47 balrog
            return;
222 58a26b47 balrog
        }
223 58a26b47 balrog
        pkt += 2;
224 58a26b47 balrog
225 58a26b47 balrog
        rpkt = csrhci_out_packet_csr(s, H4_NEG_PKT, 10);
226 58a26b47 balrog
227 58a26b47 balrog
        *rpkt ++ = 0x20;        /* Operational settings negotation Ok */
228 58a26b47 balrog
        memcpy(rpkt, pkt, 7); rpkt += 7;
229 58a26b47 balrog
        *rpkt ++ = 0xff;
230 58a26b47 balrog
        *rpkt ++ = 0xff;
231 58a26b47 balrog
        break;
232 58a26b47 balrog
233 58a26b47 balrog
    case H4_ALIVE_PKT:
234 58a26b47 balrog
        if (s->in_hdr != 4 || pkt[1] != 0x55 || pkt[2] != 0x00) {
235 58a26b47 balrog
            fprintf(stderr, "%s: got a bad ALIVE packet\n", __FUNCTION__);
236 58a26b47 balrog
            return;
237 58a26b47 balrog
        }
238 58a26b47 balrog
239 58a26b47 balrog
        rpkt = csrhci_out_packet_csr(s, H4_ALIVE_PKT, 2);
240 58a26b47 balrog
241 58a26b47 balrog
        *rpkt ++ = 0xcc;
242 58a26b47 balrog
        *rpkt ++ = 0x00;
243 58a26b47 balrog
        break;
244 58a26b47 balrog
245 58a26b47 balrog
    default:
246 58a26b47 balrog
    bad_pkt:
247 58a26b47 balrog
        /* TODO: error out */
248 58a26b47 balrog
        fprintf(stderr, "%s: got a bad packet\n", __FUNCTION__);
249 58a26b47 balrog
        break;
250 58a26b47 balrog
    }
251 58a26b47 balrog
252 58a26b47 balrog
    csrhci_fifo_wake(s);
253 58a26b47 balrog
}
254 58a26b47 balrog
255 58a26b47 balrog
static int csrhci_header_len(const uint8_t *pkt)
256 58a26b47 balrog
{
257 58a26b47 balrog
    switch (pkt[0]) {
258 58a26b47 balrog
    case H4_CMD_PKT:
259 58a26b47 balrog
        return HCI_COMMAND_HDR_SIZE;
260 58a26b47 balrog
    case H4_EVT_PKT:
261 58a26b47 balrog
        return HCI_EVENT_HDR_SIZE;
262 58a26b47 balrog
    case H4_ACL_PKT:
263 58a26b47 balrog
        return HCI_ACL_HDR_SIZE;
264 58a26b47 balrog
    case H4_SCO_PKT:
265 58a26b47 balrog
        return HCI_SCO_HDR_SIZE;
266 58a26b47 balrog
    case H4_NEG_PKT:
267 58a26b47 balrog
        return pkt[1] + 1;
268 58a26b47 balrog
    case H4_ALIVE_PKT:
269 58a26b47 balrog
        return 3;
270 58a26b47 balrog
    }
271 58a26b47 balrog
272 58a26b47 balrog
    exit(-1);
273 58a26b47 balrog
}
274 58a26b47 balrog
275 58a26b47 balrog
static int csrhci_data_len(const uint8_t *pkt)
276 58a26b47 balrog
{
277 58a26b47 balrog
    switch (*pkt ++) {
278 58a26b47 balrog
    case H4_CMD_PKT:
279 58a26b47 balrog
        /* It seems that vendor-specific command packets for H4+ are all
280 58a26b47 balrog
         * one byte longer than indicated in the standard header.  */
281 58a26b47 balrog
        if (le16_to_cpu(((struct hci_command_hdr *) pkt)->opcode) == 0xfc00)
282 58a26b47 balrog
            return (((struct hci_command_hdr *) pkt)->plen + 1) & ~1;
283 58a26b47 balrog
284 58a26b47 balrog
        return ((struct hci_command_hdr *) pkt)->plen;
285 58a26b47 balrog
    case H4_EVT_PKT:
286 58a26b47 balrog
        return ((struct hci_event_hdr *) pkt)->plen;
287 58a26b47 balrog
    case H4_ACL_PKT:
288 58a26b47 balrog
        return le16_to_cpu(((struct hci_acl_hdr *) pkt)->dlen);
289 58a26b47 balrog
    case H4_SCO_PKT:
290 58a26b47 balrog
        return ((struct hci_sco_hdr *) pkt)->dlen;
291 58a26b47 balrog
    case H4_NEG_PKT:
292 58a26b47 balrog
    case H4_ALIVE_PKT:
293 58a26b47 balrog
        return 0;
294 58a26b47 balrog
    }
295 58a26b47 balrog
296 58a26b47 balrog
    exit(-1);
297 58a26b47 balrog
}
298 58a26b47 balrog
299 58a26b47 balrog
static int csrhci_write(struct CharDriverState *chr,
300 58a26b47 balrog
                const uint8_t *buf, int len)
301 58a26b47 balrog
{
302 58a26b47 balrog
    struct csrhci_s *s = (struct csrhci_s *) chr->opaque;
303 58a26b47 balrog
    int plen = s->in_len;
304 58a26b47 balrog
305 58a26b47 balrog
    if (!s->enable)
306 58a26b47 balrog
        return 0;
307 58a26b47 balrog
308 58a26b47 balrog
    s->in_len += len;
309 58a26b47 balrog
    memcpy(s->inpkt + plen, buf, len);
310 58a26b47 balrog
311 58a26b47 balrog
    while (1) {
312 58a26b47 balrog
        if (s->in_len >= 2 && plen < 2)
313 58a26b47 balrog
            s->in_hdr = csrhci_header_len(s->inpkt) + 1;
314 58a26b47 balrog
315 58a26b47 balrog
        if (s->in_len >= s->in_hdr && plen < s->in_hdr)
316 58a26b47 balrog
            s->in_data = csrhci_data_len(s->inpkt) + s->in_hdr;
317 58a26b47 balrog
318 58a26b47 balrog
        if (s->in_len >= s->in_data) {
319 58a26b47 balrog
            csrhci_in_packet(s, s->inpkt);
320 58a26b47 balrog
321 58a26b47 balrog
            memmove(s->inpkt, s->inpkt + s->in_len, s->in_len - s->in_data);
322 58a26b47 balrog
            s->in_len -= s->in_data;
323 58a26b47 balrog
            s->in_hdr = INT_MAX;
324 58a26b47 balrog
            s->in_data = INT_MAX;
325 58a26b47 balrog
            plen = 0;
326 58a26b47 balrog
        } else
327 58a26b47 balrog
            break;
328 58a26b47 balrog
    }
329 58a26b47 balrog
330 58a26b47 balrog
    return len;
331 58a26b47 balrog
}
332 58a26b47 balrog
333 58a26b47 balrog
static void csrhci_out_hci_packet_event(void *opaque,
334 58a26b47 balrog
                const uint8_t *data, int len)
335 58a26b47 balrog
{
336 58a26b47 balrog
    struct csrhci_s *s = (struct csrhci_s *) opaque;
337 58a26b47 balrog
    uint8_t *pkt = csrhci_out_packet(s, (len + 2) & ~1);        /* Align */
338 58a26b47 balrog
339 58a26b47 balrog
    *pkt ++ = H4_EVT_PKT;
340 58a26b47 balrog
    memcpy(pkt, data, len);
341 58a26b47 balrog
342 58a26b47 balrog
    csrhci_fifo_wake(s);
343 58a26b47 balrog
}
344 58a26b47 balrog
345 58a26b47 balrog
static void csrhci_out_hci_packet_acl(void *opaque,
346 58a26b47 balrog
                const uint8_t *data, int len)
347 58a26b47 balrog
{
348 58a26b47 balrog
    struct csrhci_s *s = (struct csrhci_s *) opaque;
349 58a26b47 balrog
    uint8_t *pkt = csrhci_out_packet(s, (len + 2) & ~1);        /* Align */
350 58a26b47 balrog
351 58a26b47 balrog
    *pkt ++ = H4_ACL_PKT;
352 58a26b47 balrog
    pkt[len & ~1] = 0;
353 58a26b47 balrog
    memcpy(pkt, data, len);
354 58a26b47 balrog
355 58a26b47 balrog
    csrhci_fifo_wake(s);
356 58a26b47 balrog
}
357 58a26b47 balrog
358 58a26b47 balrog
static int csrhci_ioctl(struct CharDriverState *chr, int cmd, void *arg)
359 58a26b47 balrog
{
360 58a26b47 balrog
    QEMUSerialSetParams *ssp;
361 58a26b47 balrog
    struct csrhci_s *s = (struct csrhci_s *) chr->opaque;
362 58a26b47 balrog
    int prev_state = s->modem_state;
363 58a26b47 balrog
364 58a26b47 balrog
    switch (cmd) {
365 58a26b47 balrog
    case CHR_IOCTL_SERIAL_SET_PARAMS:
366 58a26b47 balrog
        ssp = (QEMUSerialSetParams *) arg;
367 58a26b47 balrog
        s->baud_delay = ticks_per_sec / ssp->speed;
368 58a26b47 balrog
        /* Moments later... (but shorter than 100ms) */
369 58a26b47 balrog
        s->modem_state |= CHR_TIOCM_CTS;
370 58a26b47 balrog
        break;
371 58a26b47 balrog
372 58a26b47 balrog
    case CHR_IOCTL_SERIAL_GET_TIOCM:
373 58a26b47 balrog
        *(int *) arg = s->modem_state;
374 58a26b47 balrog
        break;
375 58a26b47 balrog
376 58a26b47 balrog
    case CHR_IOCTL_SERIAL_SET_TIOCM:
377 58a26b47 balrog
        s->modem_state = *(int *) arg;
378 58a26b47 balrog
        if (~s->modem_state & prev_state & CHR_TIOCM_RTS)
379 58a26b47 balrog
            s->modem_state &= ~CHR_TIOCM_CTS;
380 58a26b47 balrog
        break;
381 58a26b47 balrog
382 58a26b47 balrog
    default:
383 58a26b47 balrog
        return -ENOTSUP;
384 58a26b47 balrog
    }
385 58a26b47 balrog
    return 0;
386 58a26b47 balrog
}
387 58a26b47 balrog
388 58a26b47 balrog
static void csrhci_reset(struct csrhci_s *s)
389 58a26b47 balrog
{
390 58a26b47 balrog
    s->out_len = 0;
391 58a26b47 balrog
    s->out_size = FIFO_LEN;
392 58a26b47 balrog
    s->in_len = 0;
393 58a26b47 balrog
    s->baud_delay = ticks_per_sec;
394 58a26b47 balrog
    s->enable = 0;
395 58a26b47 balrog
    s->in_hdr = INT_MAX;
396 58a26b47 balrog
    s->in_data = INT_MAX;
397 58a26b47 balrog
398 58a26b47 balrog
    s->modem_state = 0;
399 58a26b47 balrog
    /* After a while... (but sooner than 10ms) */
400 58a26b47 balrog
    s->modem_state |= CHR_TIOCM_CTS;
401 58a26b47 balrog
402 58a26b47 balrog
    memset(&s->bd_addr, 0, sizeof(bdaddr_t));
403 58a26b47 balrog
}
404 58a26b47 balrog
405 58a26b47 balrog
static void csrhci_out_tick(void *opaque)
406 58a26b47 balrog
{
407 58a26b47 balrog
    csrhci_fifo_wake((struct csrhci_s *) opaque);
408 58a26b47 balrog
}
409 58a26b47 balrog
410 58a26b47 balrog
static void csrhci_pins(void *opaque, int line, int level)
411 58a26b47 balrog
{
412 58a26b47 balrog
    struct csrhci_s *s = (struct csrhci_s *) opaque;
413 58a26b47 balrog
    int state = s->pin_state;
414 58a26b47 balrog
415 58a26b47 balrog
    s->pin_state &= ~(1 << line);
416 58a26b47 balrog
    s->pin_state |= (!!level) << line;
417 58a26b47 balrog
418 58a26b47 balrog
    if ((state & ~s->pin_state) & (1 << csrhci_pin_reset)) {
419 58a26b47 balrog
        /* TODO: Disappear from lower layers */
420 58a26b47 balrog
        csrhci_reset(s);
421 58a26b47 balrog
    }
422 58a26b47 balrog
423 58a26b47 balrog
    if (s->pin_state == 3 && state != 3) {
424 58a26b47 balrog
        s->enable = 1;
425 58a26b47 balrog
        /* TODO: Wake lower layers up */
426 58a26b47 balrog
    }
427 58a26b47 balrog
}
428 58a26b47 balrog
429 58a26b47 balrog
qemu_irq *csrhci_pins_get(CharDriverState *chr)
430 58a26b47 balrog
{
431 58a26b47 balrog
    struct csrhci_s *s = (struct csrhci_s *) chr->opaque;
432 58a26b47 balrog
433 58a26b47 balrog
    return s->pins;
434 58a26b47 balrog
}
435 58a26b47 balrog
436 58a26b47 balrog
CharDriverState *uart_hci_init(qemu_irq wakeup)
437 58a26b47 balrog
{
438 58a26b47 balrog
    struct csrhci_s *s = (struct csrhci_s *)
439 58a26b47 balrog
            qemu_mallocz(sizeof(struct csrhci_s));
440 58a26b47 balrog
441 58a26b47 balrog
    s->chr.opaque = s;
442 58a26b47 balrog
    s->chr.chr_write = csrhci_write;
443 58a26b47 balrog
    s->chr.chr_ioctl = csrhci_ioctl;
444 58a26b47 balrog
445 58a26b47 balrog
    s->hci = qemu_next_hci();
446 58a26b47 balrog
    s->hci->opaque = s;
447 58a26b47 balrog
    s->hci->evt_recv = csrhci_out_hci_packet_event;
448 58a26b47 balrog
    s->hci->acl_recv = csrhci_out_hci_packet_acl;
449 58a26b47 balrog
450 58a26b47 balrog
    s->out_tm = qemu_new_timer(vm_clock, csrhci_out_tick, s);
451 58a26b47 balrog
    s->pins = qemu_allocate_irqs(csrhci_pins, s, __csrhci_pins);
452 58a26b47 balrog
    csrhci_reset(s);
453 58a26b47 balrog
454 58a26b47 balrog
    return &s->chr;
455 58a26b47 balrog
}