xref: /openbmc/linux/drivers/bluetooth/btrtl.c (revision 1996d9cad6ad4882a79464e9fb941a68c693f8fc)
1c942fddfSThomas Gleixner // SPDX-License-Identifier: GPL-2.0-or-later
2db33c77dSCarlo Caione /*
3db33c77dSCarlo Caione  *  Bluetooth support for Realtek devices
4db33c77dSCarlo Caione  *
5db33c77dSCarlo Caione  *  Copyright (C) 2015 Endless Mobile, Inc.
6db33c77dSCarlo Caione  */
7db33c77dSCarlo Caione 
8db33c77dSCarlo Caione #include <linux/module.h>
9db33c77dSCarlo Caione #include <linux/firmware.h>
10db33c77dSCarlo Caione #include <asm/unaligned.h>
11db33c77dSCarlo Caione #include <linux/usb.h>
12db33c77dSCarlo Caione 
13db33c77dSCarlo Caione #include <net/bluetooth/bluetooth.h>
14db33c77dSCarlo Caione #include <net/bluetooth/hci_core.h>
15db33c77dSCarlo Caione 
16db33c77dSCarlo Caione #include "btrtl.h"
17db33c77dSCarlo Caione 
18db33c77dSCarlo Caione #define VERSION "0.1"
19db33c77dSCarlo Caione 
20db33c77dSCarlo Caione #define RTL_EPATCH_SIGNATURE	"Realtech"
21db33c77dSCarlo Caione #define RTL_ROM_LMP_8723A	0x1200
22db33c77dSCarlo Caione #define RTL_ROM_LMP_8723B	0x8723
23db33c77dSCarlo Caione #define RTL_ROM_LMP_8821A	0x8821
24db33c77dSCarlo Caione #define RTL_ROM_LMP_8761A	0x8761
251110a2dbSLarry Finger #define RTL_ROM_LMP_8822B	0x8822
26b85b0ee1SMartin Blumenstingl #define RTL_CONFIG_MAGIC	0x8723ab55
27db33c77dSCarlo Caione 
28907f8499SAlex Lu #define IC_MATCH_FL_LMPSUBV	(1 << 0)
29907f8499SAlex Lu #define IC_MATCH_FL_HCIREV	(1 << 1)
30c50903e3SMartin Blumenstingl #define IC_MATCH_FL_HCIVER	(1 << 2)
31c50903e3SMartin Blumenstingl #define IC_MATCH_FL_HCIBUS	(1 << 3)
326f9ff246SMax Chou #define IC_INFO(lmps, hcir, hciv, bus) \
336f9ff246SMax Chou 	.match_flags = IC_MATCH_FL_LMPSUBV | IC_MATCH_FL_HCIREV | \
346f9ff246SMax Chou 		       IC_MATCH_FL_HCIVER | IC_MATCH_FL_HCIBUS, \
35907f8499SAlex Lu 	.lmp_subver = (lmps), \
366f9ff246SMax Chou 	.hci_rev = (hcir), \
376f9ff246SMax Chou 	.hci_ver = (hciv), \
386f9ff246SMax Chou 	.hci_bus = (bus)
39907f8499SAlex Lu 
40907f8499SAlex Lu struct id_table {
41907f8499SAlex Lu 	__u16 match_flags;
42907f8499SAlex Lu 	__u16 lmp_subver;
43907f8499SAlex Lu 	__u16 hci_rev;
44c50903e3SMartin Blumenstingl 	__u8 hci_ver;
45c50903e3SMartin Blumenstingl 	__u8 hci_bus;
46907f8499SAlex Lu 	bool config_needed;
4726503ad2SMartin Blumenstingl 	bool has_rom_version;
48907f8499SAlex Lu 	char *fw_name;
49907f8499SAlex Lu 	char *cfg_name;
50907f8499SAlex Lu };
51907f8499SAlex Lu 
5226503ad2SMartin Blumenstingl struct btrtl_device_info {
5326503ad2SMartin Blumenstingl 	const struct id_table *ic_info;
5426503ad2SMartin Blumenstingl 	u8 rom_version;
5526503ad2SMartin Blumenstingl 	u8 *fw_data;
5626503ad2SMartin Blumenstingl 	int fw_len;
5726503ad2SMartin Blumenstingl 	u8 *cfg_data;
5826503ad2SMartin Blumenstingl 	int cfg_len;
59*1996d9caSKai-Heng Feng 	bool drop_fw;
6026503ad2SMartin Blumenstingl };
6126503ad2SMartin Blumenstingl 
62907f8499SAlex Lu static const struct id_table ic_id_table[] = {
636f9ff246SMax Chou 	/* 8723A */
646f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8723A, 0xb, 0x6, HCI_USB),
6526503ad2SMartin Blumenstingl 	  .config_needed = false,
6626503ad2SMartin Blumenstingl 	  .has_rom_version = false,
6726503ad2SMartin Blumenstingl 	  .fw_name = "rtl_bt/rtl8723a_fw.bin",
6826503ad2SMartin Blumenstingl 	  .cfg_name = NULL },
6926503ad2SMartin Blumenstingl 
70c50903e3SMartin Blumenstingl 	/* 8723BS */
716f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8723B, 0xb, 0x6, HCI_UART),
72c50903e3SMartin Blumenstingl 	  .config_needed = true,
73c50903e3SMartin Blumenstingl 	  .has_rom_version = true,
74c50903e3SMartin Blumenstingl 	  .fw_name  = "rtl_bt/rtl8723bs_fw.bin",
751cc194caSHans de Goede 	  .cfg_name = "rtl_bt/rtl8723bs_config" },
76c50903e3SMartin Blumenstingl 
77907f8499SAlex Lu 	/* 8723B */
786f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8723B, 0xb, 0x6, HCI_USB),
79907f8499SAlex Lu 	  .config_needed = false,
8026503ad2SMartin Blumenstingl 	  .has_rom_version = true,
81907f8499SAlex Lu 	  .fw_name  = "rtl_bt/rtl8723b_fw.bin",
821cc194caSHans de Goede 	  .cfg_name = "rtl_bt/rtl8723b_config" },
83907f8499SAlex Lu 
84907f8499SAlex Lu 	/* 8723D */
856f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8723B, 0xd, 0x8, HCI_USB),
86907f8499SAlex Lu 	  .config_needed = true,
8726503ad2SMartin Blumenstingl 	  .has_rom_version = true,
88907f8499SAlex Lu 	  .fw_name  = "rtl_bt/rtl8723d_fw.bin",
891cc194caSHans de Goede 	  .cfg_name = "rtl_bt/rtl8723d_config" },
90907f8499SAlex Lu 
91c50903e3SMartin Blumenstingl 	/* 8723DS */
926f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8723B, 0xd, 0x8, HCI_UART),
93c50903e3SMartin Blumenstingl 	  .config_needed = true,
94c50903e3SMartin Blumenstingl 	  .has_rom_version = true,
95c50903e3SMartin Blumenstingl 	  .fw_name  = "rtl_bt/rtl8723ds_fw.bin",
961cc194caSHans de Goede 	  .cfg_name = "rtl_bt/rtl8723ds_config" },
97c50903e3SMartin Blumenstingl 
98907f8499SAlex Lu 	/* 8821A */
996f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8821A, 0xa, 0x6, HCI_USB),
100907f8499SAlex Lu 	  .config_needed = false,
10126503ad2SMartin Blumenstingl 	  .has_rom_version = true,
102907f8499SAlex Lu 	  .fw_name  = "rtl_bt/rtl8821a_fw.bin",
1031cc194caSHans de Goede 	  .cfg_name = "rtl_bt/rtl8821a_config" },
104907f8499SAlex Lu 
105907f8499SAlex Lu 	/* 8821C */
1066f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8821A, 0xc, 0x8, HCI_USB),
107907f8499SAlex Lu 	  .config_needed = false,
10826503ad2SMartin Blumenstingl 	  .has_rom_version = true,
109907f8499SAlex Lu 	  .fw_name  = "rtl_bt/rtl8821c_fw.bin",
1101cc194caSHans de Goede 	  .cfg_name = "rtl_bt/rtl8821c_config" },
111907f8499SAlex Lu 
112907f8499SAlex Lu 	/* 8761A */
1136f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8761A, 0xa, 0x6, HCI_USB),
114907f8499SAlex Lu 	  .config_needed = false,
11526503ad2SMartin Blumenstingl 	  .has_rom_version = true,
116907f8499SAlex Lu 	  .fw_name  = "rtl_bt/rtl8761a_fw.bin",
1171cc194caSHans de Goede 	  .cfg_name = "rtl_bt/rtl8761a_config" },
118907f8499SAlex Lu 
11904896832SZiqian SUN (Zamir) 	/* 8761B */
1206f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8761A, 0xb, 0xa, HCI_USB),
12104896832SZiqian SUN (Zamir) 	  .config_needed = false,
12204896832SZiqian SUN (Zamir) 	  .has_rom_version = true,
12304896832SZiqian SUN (Zamir) 	  .fw_name  = "rtl_bt/rtl8761b_fw.bin",
12404896832SZiqian SUN (Zamir) 	  .cfg_name = "rtl_bt/rtl8761b_config" },
12504896832SZiqian SUN (Zamir) 
126848fc616SMax Chou 	/* 8822C with UART interface */
1276f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8822B, 0xc, 0xa, HCI_UART),
128848fc616SMax Chou 	  .config_needed = true,
129848fc616SMax Chou 	  .has_rom_version = true,
130848fc616SMax Chou 	  .fw_name  = "rtl_bt/rtl8822cs_fw.bin",
131848fc616SMax Chou 	  .cfg_name = "rtl_bt/rtl8822cs_config" },
132848fc616SMax Chou 
1338ecfdc95SAlex Lu 	/* 8822C with USB interface */
1346f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8822B, 0xc, 0xa, HCI_USB),
1358ecfdc95SAlex Lu 	  .config_needed = false,
1368ecfdc95SAlex Lu 	  .has_rom_version = true,
1378ecfdc95SAlex Lu 	  .fw_name  = "rtl_bt/rtl8822cu_fw.bin",
1388ecfdc95SAlex Lu 	  .cfg_name = "rtl_bt/rtl8822cu_config" },
1398ecfdc95SAlex Lu 
140907f8499SAlex Lu 	/* 8822B */
1416f9ff246SMax Chou 	{ IC_INFO(RTL_ROM_LMP_8822B, 0xb, 0x7, HCI_USB),
142907f8499SAlex Lu 	  .config_needed = true,
14326503ad2SMartin Blumenstingl 	  .has_rom_version = true,
144907f8499SAlex Lu 	  .fw_name  = "rtl_bt/rtl8822b_fw.bin",
1451cc194caSHans de Goede 	  .cfg_name = "rtl_bt/rtl8822b_config" },
146907f8499SAlex Lu 	};
147907f8499SAlex Lu 
148c50903e3SMartin Blumenstingl static const struct id_table *btrtl_match_ic(u16 lmp_subver, u16 hci_rev,
149c50903e3SMartin Blumenstingl 					     u8 hci_ver, u8 hci_bus)
15026503ad2SMartin Blumenstingl {
15126503ad2SMartin Blumenstingl 	int i;
15226503ad2SMartin Blumenstingl 
15326503ad2SMartin Blumenstingl 	for (i = 0; i < ARRAY_SIZE(ic_id_table); i++) {
15426503ad2SMartin Blumenstingl 		if ((ic_id_table[i].match_flags & IC_MATCH_FL_LMPSUBV) &&
15526503ad2SMartin Blumenstingl 		    (ic_id_table[i].lmp_subver != lmp_subver))
15626503ad2SMartin Blumenstingl 			continue;
15726503ad2SMartin Blumenstingl 		if ((ic_id_table[i].match_flags & IC_MATCH_FL_HCIREV) &&
15826503ad2SMartin Blumenstingl 		    (ic_id_table[i].hci_rev != hci_rev))
15926503ad2SMartin Blumenstingl 			continue;
160c50903e3SMartin Blumenstingl 		if ((ic_id_table[i].match_flags & IC_MATCH_FL_HCIVER) &&
161c50903e3SMartin Blumenstingl 		    (ic_id_table[i].hci_ver != hci_ver))
162c50903e3SMartin Blumenstingl 			continue;
163c50903e3SMartin Blumenstingl 		if ((ic_id_table[i].match_flags & IC_MATCH_FL_HCIBUS) &&
164c50903e3SMartin Blumenstingl 		    (ic_id_table[i].hci_bus != hci_bus))
165c50903e3SMartin Blumenstingl 			continue;
16626503ad2SMartin Blumenstingl 
16726503ad2SMartin Blumenstingl 		break;
16826503ad2SMartin Blumenstingl 	}
16926503ad2SMartin Blumenstingl 	if (i >= ARRAY_SIZE(ic_id_table))
17026503ad2SMartin Blumenstingl 		return NULL;
17126503ad2SMartin Blumenstingl 
17226503ad2SMartin Blumenstingl 	return &ic_id_table[i];
17326503ad2SMartin Blumenstingl }
17426503ad2SMartin Blumenstingl 
175240b64a8SAlex Lu static struct sk_buff *btrtl_read_local_version(struct hci_dev *hdev)
176240b64a8SAlex Lu {
177240b64a8SAlex Lu 	struct sk_buff *skb;
178240b64a8SAlex Lu 
179240b64a8SAlex Lu 	skb = __hci_cmd_sync(hdev, HCI_OP_READ_LOCAL_VERSION, 0, NULL,
180240b64a8SAlex Lu 			     HCI_INIT_TIMEOUT);
181240b64a8SAlex Lu 	if (IS_ERR(skb)) {
182240b64a8SAlex Lu 		rtl_dev_err(hdev, "HCI_OP_READ_LOCAL_VERSION failed (%ld)",
183240b64a8SAlex Lu 			    PTR_ERR(skb));
184240b64a8SAlex Lu 		return skb;
185240b64a8SAlex Lu 	}
186240b64a8SAlex Lu 
187240b64a8SAlex Lu 	if (skb->len != sizeof(struct hci_rp_read_local_version)) {
188240b64a8SAlex Lu 		rtl_dev_err(hdev, "HCI_OP_READ_LOCAL_VERSION event length mismatch");
189240b64a8SAlex Lu 		kfree_skb(skb);
190240b64a8SAlex Lu 		return ERR_PTR(-EIO);
191240b64a8SAlex Lu 	}
192240b64a8SAlex Lu 
193240b64a8SAlex Lu 	return skb;
194240b64a8SAlex Lu }
195240b64a8SAlex Lu 
196db33c77dSCarlo Caione static int rtl_read_rom_version(struct hci_dev *hdev, u8 *version)
197db33c77dSCarlo Caione {
198db33c77dSCarlo Caione 	struct rtl_rom_version_evt *rom_version;
199db33c77dSCarlo Caione 	struct sk_buff *skb;
200db33c77dSCarlo Caione 
201db33c77dSCarlo Caione 	/* Read RTL ROM version command */
202db33c77dSCarlo Caione 	skb = __hci_cmd_sync(hdev, 0xfc6d, 0, NULL, HCI_INIT_TIMEOUT);
203db33c77dSCarlo Caione 	if (IS_ERR(skb)) {
204f1300c03SAlex Lu 		rtl_dev_err(hdev, "Read ROM version failed (%ld)",
205a5c76e67SHans de Goede 			    PTR_ERR(skb));
206db33c77dSCarlo Caione 		return PTR_ERR(skb);
207db33c77dSCarlo Caione 	}
208db33c77dSCarlo Caione 
209db33c77dSCarlo Caione 	if (skb->len != sizeof(*rom_version)) {
210f1300c03SAlex Lu 		rtl_dev_err(hdev, "version event length mismatch");
211db33c77dSCarlo Caione 		kfree_skb(skb);
212db33c77dSCarlo Caione 		return -EIO;
213db33c77dSCarlo Caione 	}
214db33c77dSCarlo Caione 
215db33c77dSCarlo Caione 	rom_version = (struct rtl_rom_version_evt *)skb->data;
216f1300c03SAlex Lu 	rtl_dev_info(hdev, "rom_version status=%x version=%x",
2172064ee33SMarcel Holtmann 		     rom_version->status, rom_version->version);
218db33c77dSCarlo Caione 
219db33c77dSCarlo Caione 	*version = rom_version->version;
220db33c77dSCarlo Caione 
221db33c77dSCarlo Caione 	kfree_skb(skb);
222db33c77dSCarlo Caione 	return 0;
223db33c77dSCarlo Caione }
224db33c77dSCarlo Caione 
22526503ad2SMartin Blumenstingl static int rtlbt_parse_firmware(struct hci_dev *hdev,
22626503ad2SMartin Blumenstingl 				struct btrtl_device_info *btrtl_dev,
227db33c77dSCarlo Caione 				unsigned char **_buf)
228db33c77dSCarlo Caione {
229e5070e07SColin Ian King 	static const u8 extension_sig[] = { 0x51, 0x04, 0xfd, 0x77 };
230db33c77dSCarlo Caione 	struct rtl_epatch_header *epatch_info;
231db33c77dSCarlo Caione 	unsigned char *buf;
23226503ad2SMartin Blumenstingl 	int i, len;
233db33c77dSCarlo Caione 	size_t min_size;
23426503ad2SMartin Blumenstingl 	u8 opcode, length, data;
235db33c77dSCarlo Caione 	int project_id = -1;
236db33c77dSCarlo Caione 	const unsigned char *fwptr, *chip_id_base;
237db33c77dSCarlo Caione 	const unsigned char *patch_length_base, *patch_offset_base;
238db33c77dSCarlo Caione 	u32 patch_offset = 0;
239db33c77dSCarlo Caione 	u16 patch_length, num_patches;
2401110a2dbSLarry Finger 	static const struct {
2411110a2dbSLarry Finger 		__u16 lmp_subver;
2421110a2dbSLarry Finger 		__u8 id;
2431110a2dbSLarry Finger 	} project_id_to_lmp_subver[] = {
2441110a2dbSLarry Finger 		{ RTL_ROM_LMP_8723A, 0 },
2451110a2dbSLarry Finger 		{ RTL_ROM_LMP_8723B, 1 },
2461110a2dbSLarry Finger 		{ RTL_ROM_LMP_8821A, 2 },
2471110a2dbSLarry Finger 		{ RTL_ROM_LMP_8761A, 3 },
2481110a2dbSLarry Finger 		{ RTL_ROM_LMP_8822B, 8 },
249907f8499SAlex Lu 		{ RTL_ROM_LMP_8723B, 9 },	/* 8723D */
250907f8499SAlex Lu 		{ RTL_ROM_LMP_8821A, 10 },	/* 8821C */
2518ecfdc95SAlex Lu 		{ RTL_ROM_LMP_8822B, 13 },	/* 8822C */
25204896832SZiqian SUN (Zamir) 		{ RTL_ROM_LMP_8761A, 14 },	/* 8761B */
253db33c77dSCarlo Caione 	};
254db33c77dSCarlo Caione 
255db33c77dSCarlo Caione 	min_size = sizeof(struct rtl_epatch_header) + sizeof(extension_sig) + 3;
25626503ad2SMartin Blumenstingl 	if (btrtl_dev->fw_len < min_size)
257db33c77dSCarlo Caione 		return -EINVAL;
258db33c77dSCarlo Caione 
25926503ad2SMartin Blumenstingl 	fwptr = btrtl_dev->fw_data + btrtl_dev->fw_len - sizeof(extension_sig);
260db33c77dSCarlo Caione 	if (memcmp(fwptr, extension_sig, sizeof(extension_sig)) != 0) {
261f1300c03SAlex Lu 		rtl_dev_err(hdev, "extension section signature mismatch");
262db33c77dSCarlo Caione 		return -EINVAL;
263db33c77dSCarlo Caione 	}
264db33c77dSCarlo Caione 
265db33c77dSCarlo Caione 	/* Loop from the end of the firmware parsing instructions, until
266db33c77dSCarlo Caione 	 * we find an instruction that identifies the "project ID" for the
267db33c77dSCarlo Caione 	 * hardware supported by this firwmare file.
268db33c77dSCarlo Caione 	 * Once we have that, we double-check that that project_id is suitable
269db33c77dSCarlo Caione 	 * for the hardware we are working with.
270db33c77dSCarlo Caione 	 */
27126503ad2SMartin Blumenstingl 	while (fwptr >= btrtl_dev->fw_data + (sizeof(*epatch_info) + 3)) {
272db33c77dSCarlo Caione 		opcode = *--fwptr;
273db33c77dSCarlo Caione 		length = *--fwptr;
274db33c77dSCarlo Caione 		data = *--fwptr;
275db33c77dSCarlo Caione 
276db33c77dSCarlo Caione 		BT_DBG("check op=%x len=%x data=%x", opcode, length, data);
277db33c77dSCarlo Caione 
278db33c77dSCarlo Caione 		if (opcode == 0xff) /* EOF */
279db33c77dSCarlo Caione 			break;
280db33c77dSCarlo Caione 
281db33c77dSCarlo Caione 		if (length == 0) {
282f1300c03SAlex Lu 			rtl_dev_err(hdev, "found instruction with length 0");
283db33c77dSCarlo Caione 			return -EINVAL;
284db33c77dSCarlo Caione 		}
285db33c77dSCarlo Caione 
286db33c77dSCarlo Caione 		if (opcode == 0 && length == 1) {
287db33c77dSCarlo Caione 			project_id = data;
288db33c77dSCarlo Caione 			break;
289db33c77dSCarlo Caione 		}
290db33c77dSCarlo Caione 
291db33c77dSCarlo Caione 		fwptr -= length;
292db33c77dSCarlo Caione 	}
293db33c77dSCarlo Caione 
294db33c77dSCarlo Caione 	if (project_id < 0) {
295f1300c03SAlex Lu 		rtl_dev_err(hdev, "failed to find version instruction");
296db33c77dSCarlo Caione 		return -EINVAL;
297db33c77dSCarlo Caione 	}
298db33c77dSCarlo Caione 
2991110a2dbSLarry Finger 	/* Find project_id in table */
3001110a2dbSLarry Finger 	for (i = 0; i < ARRAY_SIZE(project_id_to_lmp_subver); i++) {
3011110a2dbSLarry Finger 		if (project_id == project_id_to_lmp_subver[i].id)
3021110a2dbSLarry Finger 			break;
3031110a2dbSLarry Finger 	}
3041110a2dbSLarry Finger 
3051110a2dbSLarry Finger 	if (i >= ARRAY_SIZE(project_id_to_lmp_subver)) {
306f1300c03SAlex Lu 		rtl_dev_err(hdev, "unknown project id %d", project_id);
307db33c77dSCarlo Caione 		return -EINVAL;
308db33c77dSCarlo Caione 	}
309db33c77dSCarlo Caione 
31026503ad2SMartin Blumenstingl 	if (btrtl_dev->ic_info->lmp_subver !=
31126503ad2SMartin Blumenstingl 				project_id_to_lmp_subver[i].lmp_subver) {
312f1300c03SAlex Lu 		rtl_dev_err(hdev, "firmware is for %x but this is a %x",
31326503ad2SMartin Blumenstingl 			    project_id_to_lmp_subver[i].lmp_subver,
31426503ad2SMartin Blumenstingl 			    btrtl_dev->ic_info->lmp_subver);
315db33c77dSCarlo Caione 		return -EINVAL;
316db33c77dSCarlo Caione 	}
317db33c77dSCarlo Caione 
31826503ad2SMartin Blumenstingl 	epatch_info = (struct rtl_epatch_header *)btrtl_dev->fw_data;
319db33c77dSCarlo Caione 	if (memcmp(epatch_info->signature, RTL_EPATCH_SIGNATURE, 8) != 0) {
320f1300c03SAlex Lu 		rtl_dev_err(hdev, "bad EPATCH signature");
321db33c77dSCarlo Caione 		return -EINVAL;
322db33c77dSCarlo Caione 	}
323db33c77dSCarlo Caione 
324db33c77dSCarlo Caione 	num_patches = le16_to_cpu(epatch_info->num_patches);
325db33c77dSCarlo Caione 	BT_DBG("fw_version=%x, num_patches=%d",
326db33c77dSCarlo Caione 	       le32_to_cpu(epatch_info->fw_version), num_patches);
327db33c77dSCarlo Caione 
328db33c77dSCarlo Caione 	/* After the rtl_epatch_header there is a funky patch metadata section.
329db33c77dSCarlo Caione 	 * Assuming 2 patches, the layout is:
330db33c77dSCarlo Caione 	 * ChipID1 ChipID2 PatchLength1 PatchLength2 PatchOffset1 PatchOffset2
331db33c77dSCarlo Caione 	 *
332db33c77dSCarlo Caione 	 * Find the right patch for this chip.
333db33c77dSCarlo Caione 	 */
334db33c77dSCarlo Caione 	min_size += 8 * num_patches;
33526503ad2SMartin Blumenstingl 	if (btrtl_dev->fw_len < min_size)
336db33c77dSCarlo Caione 		return -EINVAL;
337db33c77dSCarlo Caione 
33826503ad2SMartin Blumenstingl 	chip_id_base = btrtl_dev->fw_data + sizeof(struct rtl_epatch_header);
339db33c77dSCarlo Caione 	patch_length_base = chip_id_base + (sizeof(u16) * num_patches);
340db33c77dSCarlo Caione 	patch_offset_base = patch_length_base + (sizeof(u16) * num_patches);
341db33c77dSCarlo Caione 	for (i = 0; i < num_patches; i++) {
342db33c77dSCarlo Caione 		u16 chip_id = get_unaligned_le16(chip_id_base +
343db33c77dSCarlo Caione 						 (i * sizeof(u16)));
34426503ad2SMartin Blumenstingl 		if (chip_id == btrtl_dev->rom_version + 1) {
345db33c77dSCarlo Caione 			patch_length = get_unaligned_le16(patch_length_base +
346db33c77dSCarlo Caione 							  (i * sizeof(u16)));
347db33c77dSCarlo Caione 			patch_offset = get_unaligned_le32(patch_offset_base +
348db33c77dSCarlo Caione 							  (i * sizeof(u32)));
349db33c77dSCarlo Caione 			break;
350db33c77dSCarlo Caione 		}
351db33c77dSCarlo Caione 	}
352db33c77dSCarlo Caione 
353db33c77dSCarlo Caione 	if (!patch_offset) {
354a5c76e67SHans de Goede 		rtl_dev_err(hdev, "didn't find patch for chip id %d",
355a5c76e67SHans de Goede 			    btrtl_dev->rom_version);
356db33c77dSCarlo Caione 		return -EINVAL;
357db33c77dSCarlo Caione 	}
358db33c77dSCarlo Caione 
359db33c77dSCarlo Caione 	BT_DBG("length=%x offset=%x index %d", patch_length, patch_offset, i);
360db33c77dSCarlo Caione 	min_size = patch_offset + patch_length;
36126503ad2SMartin Blumenstingl 	if (btrtl_dev->fw_len < min_size)
362db33c77dSCarlo Caione 		return -EINVAL;
363db33c77dSCarlo Caione 
364db33c77dSCarlo Caione 	/* Copy the firmware into a new buffer and write the version at
365db33c77dSCarlo Caione 	 * the end.
366db33c77dSCarlo Caione 	 */
367db33c77dSCarlo Caione 	len = patch_length;
368268d3636SMaxim Mikityanskiy 	buf = kvmalloc(patch_length, GFP_KERNEL);
369db33c77dSCarlo Caione 	if (!buf)
370db33c77dSCarlo Caione 		return -ENOMEM;
371db33c77dSCarlo Caione 
372268d3636SMaxim Mikityanskiy 	memcpy(buf, btrtl_dev->fw_data + patch_offset, patch_length - 4);
373db33c77dSCarlo Caione 	memcpy(buf + patch_length - 4, &epatch_info->fw_version, 4);
374db33c77dSCarlo Caione 
375db33c77dSCarlo Caione 	*_buf = buf;
376db33c77dSCarlo Caione 	return len;
377db33c77dSCarlo Caione }
378db33c77dSCarlo Caione 
379db33c77dSCarlo Caione static int rtl_download_firmware(struct hci_dev *hdev,
380db33c77dSCarlo Caione 				 const unsigned char *data, int fw_len)
381db33c77dSCarlo Caione {
382db33c77dSCarlo Caione 	struct rtl_download_cmd *dl_cmd;
383db33c77dSCarlo Caione 	int frag_num = fw_len / RTL_FRAG_LEN + 1;
384db33c77dSCarlo Caione 	int frag_len = RTL_FRAG_LEN;
385db33c77dSCarlo Caione 	int ret = 0;
386db33c77dSCarlo Caione 	int i;
387240b64a8SAlex Lu 	struct sk_buff *skb;
388240b64a8SAlex Lu 	struct hci_rp_read_local_version *rp;
389db33c77dSCarlo Caione 
390db33c77dSCarlo Caione 	dl_cmd = kmalloc(sizeof(struct rtl_download_cmd), GFP_KERNEL);
391db33c77dSCarlo Caione 	if (!dl_cmd)
392db33c77dSCarlo Caione 		return -ENOMEM;
393db33c77dSCarlo Caione 
394db33c77dSCarlo Caione 	for (i = 0; i < frag_num; i++) {
395db33c77dSCarlo Caione 		struct sk_buff *skb;
396db33c77dSCarlo Caione 
397db33c77dSCarlo Caione 		BT_DBG("download fw (%d/%d)", i, frag_num);
398db33c77dSCarlo Caione 
399cf0d9a70SMax Chou 		if (i > 0x7f)
400cf0d9a70SMax Chou 			dl_cmd->index = (i & 0x7f) + 1;
401cf0d9a70SMax Chou 		else
402db33c77dSCarlo Caione 			dl_cmd->index = i;
403cf0d9a70SMax Chou 
404db33c77dSCarlo Caione 		if (i == (frag_num - 1)) {
405db33c77dSCarlo Caione 			dl_cmd->index |= 0x80; /* data end */
406db33c77dSCarlo Caione 			frag_len = fw_len % RTL_FRAG_LEN;
407db33c77dSCarlo Caione 		}
408db33c77dSCarlo Caione 		memcpy(dl_cmd->data, data, frag_len);
409db33c77dSCarlo Caione 
410db33c77dSCarlo Caione 		/* Send download command */
411db33c77dSCarlo Caione 		skb = __hci_cmd_sync(hdev, 0xfc20, frag_len + 1, dl_cmd,
412db33c77dSCarlo Caione 				     HCI_INIT_TIMEOUT);
413db33c77dSCarlo Caione 		if (IS_ERR(skb)) {
414f1300c03SAlex Lu 			rtl_dev_err(hdev, "download fw command failed (%ld)",
415a5c76e67SHans de Goede 				    PTR_ERR(skb));
416d171dfb6SMax Chou 			ret = PTR_ERR(skb);
417db33c77dSCarlo Caione 			goto out;
418db33c77dSCarlo Caione 		}
419db33c77dSCarlo Caione 
420db33c77dSCarlo Caione 		if (skb->len != sizeof(struct rtl_download_response)) {
421f1300c03SAlex Lu 			rtl_dev_err(hdev, "download fw event length mismatch");
422db33c77dSCarlo Caione 			kfree_skb(skb);
423db33c77dSCarlo Caione 			ret = -EIO;
424db33c77dSCarlo Caione 			goto out;
425db33c77dSCarlo Caione 		}
426db33c77dSCarlo Caione 
427db33c77dSCarlo Caione 		kfree_skb(skb);
428db33c77dSCarlo Caione 		data += RTL_FRAG_LEN;
429db33c77dSCarlo Caione 	}
430db33c77dSCarlo Caione 
431240b64a8SAlex Lu 	skb = btrtl_read_local_version(hdev);
432240b64a8SAlex Lu 	if (IS_ERR(skb)) {
433240b64a8SAlex Lu 		ret = PTR_ERR(skb);
434240b64a8SAlex Lu 		rtl_dev_err(hdev, "read local version failed");
435240b64a8SAlex Lu 		goto out;
436240b64a8SAlex Lu 	}
437240b64a8SAlex Lu 
438240b64a8SAlex Lu 	rp = (struct hci_rp_read_local_version *)skb->data;
439240b64a8SAlex Lu 	rtl_dev_info(hdev, "fw version 0x%04x%04x",
440240b64a8SAlex Lu 		     __le16_to_cpu(rp->hci_rev), __le16_to_cpu(rp->lmp_subver));
441240b64a8SAlex Lu 	kfree_skb(skb);
442240b64a8SAlex Lu 
443db33c77dSCarlo Caione out:
444db33c77dSCarlo Caione 	kfree(dl_cmd);
445db33c77dSCarlo Caione 	return ret;
446db33c77dSCarlo Caione }
447db33c77dSCarlo Caione 
44826503ad2SMartin Blumenstingl static int rtl_load_file(struct hci_dev *hdev, const char *name, u8 **buff)
4491110a2dbSLarry Finger {
4501110a2dbSLarry Finger 	const struct firmware *fw;
4511110a2dbSLarry Finger 	int ret;
4521110a2dbSLarry Finger 
453f1300c03SAlex Lu 	rtl_dev_info(hdev, "loading %s", name);
4541110a2dbSLarry Finger 	ret = request_firmware(&fw, name, &hdev->dev);
455abed84a0SLarry Finger 	if (ret < 0)
4561110a2dbSLarry Finger 		return ret;
4571110a2dbSLarry Finger 	ret = fw->size;
458268d3636SMaxim Mikityanskiy 	*buff = kvmalloc(fw->size, GFP_KERNEL);
459268d3636SMaxim Mikityanskiy 	if (*buff)
460268d3636SMaxim Mikityanskiy 		memcpy(*buff, fw->data, ret);
461268d3636SMaxim Mikityanskiy 	else
462c3327bdeSDan Carpenter 		ret = -ENOMEM;
4631110a2dbSLarry Finger 
4641110a2dbSLarry Finger 	release_firmware(fw);
4651110a2dbSLarry Finger 
4661110a2dbSLarry Finger 	return ret;
4671110a2dbSLarry Finger }
4681110a2dbSLarry Finger 
46926503ad2SMartin Blumenstingl static int btrtl_setup_rtl8723a(struct hci_dev *hdev,
47026503ad2SMartin Blumenstingl 				struct btrtl_device_info *btrtl_dev)
471db33c77dSCarlo Caione {
47226503ad2SMartin Blumenstingl 	if (btrtl_dev->fw_len < 8)
47326503ad2SMartin Blumenstingl 		return -EINVAL;
474db33c77dSCarlo Caione 
475db33c77dSCarlo Caione 	/* Check that the firmware doesn't have the epatch signature
476db33c77dSCarlo Caione 	 * (which is only for RTL8723B and newer).
477db33c77dSCarlo Caione 	 */
47826503ad2SMartin Blumenstingl 	if (!memcmp(btrtl_dev->fw_data, RTL_EPATCH_SIGNATURE, 8)) {
479f1300c03SAlex Lu 		rtl_dev_err(hdev, "unexpected EPATCH signature!");
480907f8499SAlex Lu 		return -EINVAL;
481907f8499SAlex Lu 	}
482907f8499SAlex Lu 
48326503ad2SMartin Blumenstingl 	return rtl_download_firmware(hdev, btrtl_dev->fw_data,
48426503ad2SMartin Blumenstingl 				     btrtl_dev->fw_len);
485db33c77dSCarlo Caione }
486db33c77dSCarlo Caione 
48726503ad2SMartin Blumenstingl static int btrtl_setup_rtl8723b(struct hci_dev *hdev,
48826503ad2SMartin Blumenstingl 				struct btrtl_device_info *btrtl_dev)
48926503ad2SMartin Blumenstingl {
49026503ad2SMartin Blumenstingl 	unsigned char *fw_data = NULL;
49126503ad2SMartin Blumenstingl 	int ret;
49226503ad2SMartin Blumenstingl 	u8 *tbuff;
49326503ad2SMartin Blumenstingl 
49426503ad2SMartin Blumenstingl 	ret = rtlbt_parse_firmware(hdev, btrtl_dev, &fw_data);
495db33c77dSCarlo Caione 	if (ret < 0)
496db33c77dSCarlo Caione 		goto out;
497db33c77dSCarlo Caione 
49826503ad2SMartin Blumenstingl 	if (btrtl_dev->cfg_len > 0) {
499268d3636SMaxim Mikityanskiy 		tbuff = kvzalloc(ret + btrtl_dev->cfg_len, GFP_KERNEL);
5001110a2dbSLarry Finger 		if (!tbuff) {
5011110a2dbSLarry Finger 			ret = -ENOMEM;
502db33c77dSCarlo Caione 			goto out;
5031110a2dbSLarry Finger 		}
5041110a2dbSLarry Finger 
5051110a2dbSLarry Finger 		memcpy(tbuff, fw_data, ret);
506268d3636SMaxim Mikityanskiy 		kvfree(fw_data);
5071110a2dbSLarry Finger 
50826503ad2SMartin Blumenstingl 		memcpy(tbuff + ret, btrtl_dev->cfg_data, btrtl_dev->cfg_len);
50926503ad2SMartin Blumenstingl 		ret += btrtl_dev->cfg_len;
5101110a2dbSLarry Finger 
5111110a2dbSLarry Finger 		fw_data = tbuff;
5121110a2dbSLarry Finger 	}
5131110a2dbSLarry Finger 
514f1300c03SAlex Lu 	rtl_dev_info(hdev, "cfg_sz %d, total sz %d", btrtl_dev->cfg_len, ret);
5151110a2dbSLarry Finger 
5161110a2dbSLarry Finger 	ret = rtl_download_firmware(hdev, fw_data, ret);
517db33c77dSCarlo Caione 
518db33c77dSCarlo Caione out:
519268d3636SMaxim Mikityanskiy 	kvfree(fw_data);
520db33c77dSCarlo Caione 	return ret;
521db33c77dSCarlo Caione }
522db33c77dSCarlo Caione 
52326503ad2SMartin Blumenstingl void btrtl_free(struct btrtl_device_info *btrtl_dev)
524db33c77dSCarlo Caione {
525268d3636SMaxim Mikityanskiy 	kvfree(btrtl_dev->fw_data);
526268d3636SMaxim Mikityanskiy 	kvfree(btrtl_dev->cfg_data);
52726503ad2SMartin Blumenstingl 	kfree(btrtl_dev);
52826503ad2SMartin Blumenstingl }
52926503ad2SMartin Blumenstingl EXPORT_SYMBOL_GPL(btrtl_free);
53026503ad2SMartin Blumenstingl 
5311cc194caSHans de Goede struct btrtl_device_info *btrtl_initialize(struct hci_dev *hdev,
5321cc194caSHans de Goede 					   const char *postfix)
53326503ad2SMartin Blumenstingl {
53426503ad2SMartin Blumenstingl 	struct btrtl_device_info *btrtl_dev;
535db33c77dSCarlo Caione 	struct sk_buff *skb;
536db33c77dSCarlo Caione 	struct hci_rp_read_local_version *resp;
5371cc194caSHans de Goede 	char cfg_name[40];
538907f8499SAlex Lu 	u16 hci_rev, lmp_subver;
539c50903e3SMartin Blumenstingl 	u8 hci_ver;
54026503ad2SMartin Blumenstingl 	int ret;
541*1996d9caSKai-Heng Feng 	u16 opcode;
542*1996d9caSKai-Heng Feng 	u8 cmd[2];
54326503ad2SMartin Blumenstingl 
54426503ad2SMartin Blumenstingl 	btrtl_dev = kzalloc(sizeof(*btrtl_dev), GFP_KERNEL);
54526503ad2SMartin Blumenstingl 	if (!btrtl_dev) {
54626503ad2SMartin Blumenstingl 		ret = -ENOMEM;
54726503ad2SMartin Blumenstingl 		goto err_alloc;
54826503ad2SMartin Blumenstingl 	}
549db33c77dSCarlo Caione 
550db33c77dSCarlo Caione 	skb = btrtl_read_local_version(hdev);
55126503ad2SMartin Blumenstingl 	if (IS_ERR(skb)) {
55226503ad2SMartin Blumenstingl 		ret = PTR_ERR(skb);
55326503ad2SMartin Blumenstingl 		goto err_free;
55426503ad2SMartin Blumenstingl 	}
555db33c77dSCarlo Caione 
556db33c77dSCarlo Caione 	resp = (struct hci_rp_read_local_version *)skb->data;
557f1300c03SAlex Lu 	rtl_dev_info(hdev, "examining hci_ver=%02x hci_rev=%04x lmp_ver=%02x lmp_subver=%04x",
5582064ee33SMarcel Holtmann 		     resp->hci_ver, resp->hci_rev,
559db33c77dSCarlo Caione 		     resp->lmp_ver, resp->lmp_subver);
560db33c77dSCarlo Caione 
561c50903e3SMartin Blumenstingl 	hci_ver = resp->hci_ver;
562907f8499SAlex Lu 	hci_rev = le16_to_cpu(resp->hci_rev);
563db33c77dSCarlo Caione 	lmp_subver = le16_to_cpu(resp->lmp_subver);
564*1996d9caSKai-Heng Feng 
565*1996d9caSKai-Heng Feng 	if (resp->hci_ver == 0x8 && le16_to_cpu(resp->hci_rev) == 0x826c &&
566*1996d9caSKai-Heng Feng 	    resp->lmp_ver == 0x8 && le16_to_cpu(resp->lmp_subver) == 0xa99e)
567*1996d9caSKai-Heng Feng 		btrtl_dev->drop_fw = true;
568*1996d9caSKai-Heng Feng 
569*1996d9caSKai-Heng Feng 	if (btrtl_dev->drop_fw) {
570*1996d9caSKai-Heng Feng 		opcode = hci_opcode_pack(0x3f, 0x66);
571*1996d9caSKai-Heng Feng 		cmd[0] = opcode & 0xff;
572*1996d9caSKai-Heng Feng 		cmd[1] = opcode >> 8;
573*1996d9caSKai-Heng Feng 
574*1996d9caSKai-Heng Feng 		skb = bt_skb_alloc(sizeof(cmd), GFP_KERNEL);
575*1996d9caSKai-Heng Feng 		if (IS_ERR(skb))
576*1996d9caSKai-Heng Feng 			goto out_free;
577*1996d9caSKai-Heng Feng 
578*1996d9caSKai-Heng Feng 		skb_put_data(skb, cmd, sizeof(cmd));
579*1996d9caSKai-Heng Feng 		hci_skb_pkt_type(skb) = HCI_COMMAND_PKT;
580*1996d9caSKai-Heng Feng 
581*1996d9caSKai-Heng Feng 		hdev->send(hdev, skb);
582*1996d9caSKai-Heng Feng 
583*1996d9caSKai-Heng Feng 		/* Ensure the above vendor command is sent to controller and
584*1996d9caSKai-Heng Feng 		 * process has done.
585*1996d9caSKai-Heng Feng 		 */
586*1996d9caSKai-Heng Feng 		msleep(200);
587*1996d9caSKai-Heng Feng 
588*1996d9caSKai-Heng Feng 		/* Read the local version again. Expect to have the vanilla
589*1996d9caSKai-Heng Feng 		 * version as cold boot.
590*1996d9caSKai-Heng Feng 		 */
591*1996d9caSKai-Heng Feng 		skb = btrtl_read_local_version(hdev);
592*1996d9caSKai-Heng Feng 		if (IS_ERR(skb)) {
593*1996d9caSKai-Heng Feng 			ret = PTR_ERR(skb);
594*1996d9caSKai-Heng Feng 			goto err_free;
595*1996d9caSKai-Heng Feng 		}
596*1996d9caSKai-Heng Feng 
597*1996d9caSKai-Heng Feng 		resp = (struct hci_rp_read_local_version *)skb->data;
598*1996d9caSKai-Heng Feng 		rtl_dev_info(hdev, "examining hci_ver=%02x hci_rev=%04x lmp_ver=%02x lmp_subver=%04x",
599*1996d9caSKai-Heng Feng 			     resp->hci_ver, resp->hci_rev,
600*1996d9caSKai-Heng Feng 			     resp->lmp_ver, resp->lmp_subver);
601*1996d9caSKai-Heng Feng 
602*1996d9caSKai-Heng Feng 		hci_ver = resp->hci_ver;
603*1996d9caSKai-Heng Feng 		hci_rev = le16_to_cpu(resp->hci_rev);
604*1996d9caSKai-Heng Feng 		lmp_subver = le16_to_cpu(resp->lmp_subver);
605*1996d9caSKai-Heng Feng 	}
606*1996d9caSKai-Heng Feng out_free:
607db33c77dSCarlo Caione 	kfree_skb(skb);
608db33c77dSCarlo Caione 
609c50903e3SMartin Blumenstingl 	btrtl_dev->ic_info = btrtl_match_ic(lmp_subver, hci_rev, hci_ver,
610c50903e3SMartin Blumenstingl 					    hdev->bus);
611c50903e3SMartin Blumenstingl 
61226503ad2SMartin Blumenstingl 	if (!btrtl_dev->ic_info) {
613d182215dSAlex Lu 		rtl_dev_info(hdev, "unknown IC info, lmp subver %04x, hci rev %04x, hci ver %04x",
614c50903e3SMartin Blumenstingl 			    lmp_subver, hci_rev, hci_ver);
61500df214bSKai-Heng Feng 		return btrtl_dev;
61626503ad2SMartin Blumenstingl 	}
61726503ad2SMartin Blumenstingl 
61826503ad2SMartin Blumenstingl 	if (btrtl_dev->ic_info->has_rom_version) {
61926503ad2SMartin Blumenstingl 		ret = rtl_read_rom_version(hdev, &btrtl_dev->rom_version);
62026503ad2SMartin Blumenstingl 		if (ret)
62126503ad2SMartin Blumenstingl 			goto err_free;
62226503ad2SMartin Blumenstingl 	}
62326503ad2SMartin Blumenstingl 
62426503ad2SMartin Blumenstingl 	btrtl_dev->fw_len = rtl_load_file(hdev, btrtl_dev->ic_info->fw_name,
62526503ad2SMartin Blumenstingl 					  &btrtl_dev->fw_data);
62626503ad2SMartin Blumenstingl 	if (btrtl_dev->fw_len < 0) {
627f1300c03SAlex Lu 		rtl_dev_err(hdev, "firmware file %s not found",
62826503ad2SMartin Blumenstingl 			    btrtl_dev->ic_info->fw_name);
62926503ad2SMartin Blumenstingl 		ret = btrtl_dev->fw_len;
63026503ad2SMartin Blumenstingl 		goto err_free;
63126503ad2SMartin Blumenstingl 	}
63226503ad2SMartin Blumenstingl 
63326503ad2SMartin Blumenstingl 	if (btrtl_dev->ic_info->cfg_name) {
6341cc194caSHans de Goede 		if (postfix) {
6351cc194caSHans de Goede 			snprintf(cfg_name, sizeof(cfg_name), "%s-%s.bin",
6361cc194caSHans de Goede 				 btrtl_dev->ic_info->cfg_name, postfix);
6371cc194caSHans de Goede 		} else {
6381cc194caSHans de Goede 			snprintf(cfg_name, sizeof(cfg_name), "%s.bin",
6391cc194caSHans de Goede 				 btrtl_dev->ic_info->cfg_name);
6401cc194caSHans de Goede 		}
6411cc194caSHans de Goede 		btrtl_dev->cfg_len = rtl_load_file(hdev, cfg_name,
64226503ad2SMartin Blumenstingl 						   &btrtl_dev->cfg_data);
64326503ad2SMartin Blumenstingl 		if (btrtl_dev->ic_info->config_needed &&
64426503ad2SMartin Blumenstingl 		    btrtl_dev->cfg_len <= 0) {
645f1300c03SAlex Lu 			rtl_dev_err(hdev, "mandatory config file %s not found",
64626503ad2SMartin Blumenstingl 				    btrtl_dev->ic_info->cfg_name);
64726503ad2SMartin Blumenstingl 			ret = btrtl_dev->cfg_len;
64826503ad2SMartin Blumenstingl 			goto err_free;
64926503ad2SMartin Blumenstingl 		}
65026503ad2SMartin Blumenstingl 	}
65126503ad2SMartin Blumenstingl 
65226503ad2SMartin Blumenstingl 	return btrtl_dev;
65326503ad2SMartin Blumenstingl 
65426503ad2SMartin Blumenstingl err_free:
65526503ad2SMartin Blumenstingl 	btrtl_free(btrtl_dev);
65626503ad2SMartin Blumenstingl err_alloc:
65726503ad2SMartin Blumenstingl 	return ERR_PTR(ret);
65826503ad2SMartin Blumenstingl }
65926503ad2SMartin Blumenstingl EXPORT_SYMBOL_GPL(btrtl_initialize);
66026503ad2SMartin Blumenstingl 
66126503ad2SMartin Blumenstingl int btrtl_download_firmware(struct hci_dev *hdev,
66226503ad2SMartin Blumenstingl 			    struct btrtl_device_info *btrtl_dev)
66326503ad2SMartin Blumenstingl {
664db33c77dSCarlo Caione 	/* Match a set of subver values that correspond to stock firmware,
665db33c77dSCarlo Caione 	 * which is not compatible with standard btusb.
666db33c77dSCarlo Caione 	 * If matched, upload an alternative firmware that does conform to
667db33c77dSCarlo Caione 	 * standard btusb. Once that firmware is uploaded, the subver changes
668db33c77dSCarlo Caione 	 * to a different value.
669db33c77dSCarlo Caione 	 */
67000df214bSKai-Heng Feng 	if (!btrtl_dev->ic_info) {
671f1300c03SAlex Lu 		rtl_dev_info(hdev, "assuming no firmware upload needed");
67200df214bSKai-Heng Feng 		return 0;
67300df214bSKai-Heng Feng 	}
67400df214bSKai-Heng Feng 
67526503ad2SMartin Blumenstingl 	switch (btrtl_dev->ic_info->lmp_subver) {
676db33c77dSCarlo Caione 	case RTL_ROM_LMP_8723A:
67726503ad2SMartin Blumenstingl 		return btrtl_setup_rtl8723a(hdev, btrtl_dev);
678db33c77dSCarlo Caione 	case RTL_ROM_LMP_8723B:
679db33c77dSCarlo Caione 	case RTL_ROM_LMP_8821A:
680db33c77dSCarlo Caione 	case RTL_ROM_LMP_8761A:
6811110a2dbSLarry Finger 	case RTL_ROM_LMP_8822B:
68226503ad2SMartin Blumenstingl 		return btrtl_setup_rtl8723b(hdev, btrtl_dev);
683db33c77dSCarlo Caione 	default:
684f1300c03SAlex Lu 		rtl_dev_info(hdev, "assuming no firmware upload needed");
685db33c77dSCarlo Caione 		return 0;
686db33c77dSCarlo Caione 	}
687db33c77dSCarlo Caione }
68826503ad2SMartin Blumenstingl EXPORT_SYMBOL_GPL(btrtl_download_firmware);
68926503ad2SMartin Blumenstingl 
69026503ad2SMartin Blumenstingl int btrtl_setup_realtek(struct hci_dev *hdev)
69126503ad2SMartin Blumenstingl {
69226503ad2SMartin Blumenstingl 	struct btrtl_device_info *btrtl_dev;
69326503ad2SMartin Blumenstingl 	int ret;
69426503ad2SMartin Blumenstingl 
6951cc194caSHans de Goede 	btrtl_dev = btrtl_initialize(hdev, NULL);
69626503ad2SMartin Blumenstingl 	if (IS_ERR(btrtl_dev))
69726503ad2SMartin Blumenstingl 		return PTR_ERR(btrtl_dev);
69826503ad2SMartin Blumenstingl 
69926503ad2SMartin Blumenstingl 	ret = btrtl_download_firmware(hdev, btrtl_dev);
70026503ad2SMartin Blumenstingl 
70126503ad2SMartin Blumenstingl 	btrtl_free(btrtl_dev);
70226503ad2SMartin Blumenstingl 
70365251e2eSAlex Lu 	/* Enable controller to do both LE scan and BR/EDR inquiry
70465251e2eSAlex Lu 	 * simultaneously.
70565251e2eSAlex Lu 	 */
70665251e2eSAlex Lu 	set_bit(HCI_QUIRK_SIMULTANEOUS_DISCOVERY, &hdev->quirks);
70765251e2eSAlex Lu 
70826503ad2SMartin Blumenstingl 	return ret;
70926503ad2SMartin Blumenstingl }
710db33c77dSCarlo Caione EXPORT_SYMBOL_GPL(btrtl_setup_realtek);
711db33c77dSCarlo Caione 
7127af3f558SJian-Hong Pan int btrtl_shutdown_realtek(struct hci_dev *hdev)
7137af3f558SJian-Hong Pan {
7147af3f558SJian-Hong Pan 	struct sk_buff *skb;
7157af3f558SJian-Hong Pan 	int ret;
7167af3f558SJian-Hong Pan 
7177af3f558SJian-Hong Pan 	/* According to the vendor driver, BT must be reset on close to avoid
7187af3f558SJian-Hong Pan 	 * firmware crash.
7197af3f558SJian-Hong Pan 	 */
7207af3f558SJian-Hong Pan 	skb = __hci_cmd_sync(hdev, HCI_OP_RESET, 0, NULL, HCI_INIT_TIMEOUT);
7217af3f558SJian-Hong Pan 	if (IS_ERR(skb)) {
7227af3f558SJian-Hong Pan 		ret = PTR_ERR(skb);
7237af3f558SJian-Hong Pan 		bt_dev_err(hdev, "HCI reset during shutdown failed");
7247af3f558SJian-Hong Pan 		return ret;
7257af3f558SJian-Hong Pan 	}
7267af3f558SJian-Hong Pan 	kfree_skb(skb);
7277af3f558SJian-Hong Pan 
7287af3f558SJian-Hong Pan 	return 0;
7297af3f558SJian-Hong Pan }
7307af3f558SJian-Hong Pan EXPORT_SYMBOL_GPL(btrtl_shutdown_realtek);
7317af3f558SJian-Hong Pan 
732b85b0ee1SMartin Blumenstingl static unsigned int btrtl_convert_baudrate(u32 device_baudrate)
733b85b0ee1SMartin Blumenstingl {
734b85b0ee1SMartin Blumenstingl 	switch (device_baudrate) {
735b85b0ee1SMartin Blumenstingl 	case 0x0252a00a:
736b85b0ee1SMartin Blumenstingl 		return 230400;
737b85b0ee1SMartin Blumenstingl 
738b85b0ee1SMartin Blumenstingl 	case 0x05f75004:
739b85b0ee1SMartin Blumenstingl 		return 921600;
740b85b0ee1SMartin Blumenstingl 
741b85b0ee1SMartin Blumenstingl 	case 0x00005004:
742b85b0ee1SMartin Blumenstingl 		return 1000000;
743b85b0ee1SMartin Blumenstingl 
744b85b0ee1SMartin Blumenstingl 	case 0x04928002:
745b85b0ee1SMartin Blumenstingl 	case 0x01128002:
746b85b0ee1SMartin Blumenstingl 		return 1500000;
747b85b0ee1SMartin Blumenstingl 
748b85b0ee1SMartin Blumenstingl 	case 0x00005002:
749b85b0ee1SMartin Blumenstingl 		return 2000000;
750b85b0ee1SMartin Blumenstingl 
751b85b0ee1SMartin Blumenstingl 	case 0x0000b001:
752b85b0ee1SMartin Blumenstingl 		return 2500000;
753b85b0ee1SMartin Blumenstingl 
754b85b0ee1SMartin Blumenstingl 	case 0x04928001:
755b85b0ee1SMartin Blumenstingl 		return 3000000;
756b85b0ee1SMartin Blumenstingl 
757b85b0ee1SMartin Blumenstingl 	case 0x052a6001:
758b85b0ee1SMartin Blumenstingl 		return 3500000;
759b85b0ee1SMartin Blumenstingl 
760b85b0ee1SMartin Blumenstingl 	case 0x00005001:
761b85b0ee1SMartin Blumenstingl 		return 4000000;
762b85b0ee1SMartin Blumenstingl 
763b85b0ee1SMartin Blumenstingl 	case 0x0252c014:
764b85b0ee1SMartin Blumenstingl 	default:
765b85b0ee1SMartin Blumenstingl 		return 115200;
766b85b0ee1SMartin Blumenstingl 	}
767b85b0ee1SMartin Blumenstingl }
768b85b0ee1SMartin Blumenstingl 
769b85b0ee1SMartin Blumenstingl int btrtl_get_uart_settings(struct hci_dev *hdev,
770b85b0ee1SMartin Blumenstingl 			    struct btrtl_device_info *btrtl_dev,
771b85b0ee1SMartin Blumenstingl 			    unsigned int *controller_baudrate,
772b85b0ee1SMartin Blumenstingl 			    u32 *device_baudrate, bool *flow_control)
773b85b0ee1SMartin Blumenstingl {
774b85b0ee1SMartin Blumenstingl 	struct rtl_vendor_config *config;
775b85b0ee1SMartin Blumenstingl 	struct rtl_vendor_config_entry *entry;
776b85b0ee1SMartin Blumenstingl 	int i, total_data_len;
777b85b0ee1SMartin Blumenstingl 	bool found = false;
778b85b0ee1SMartin Blumenstingl 
779b85b0ee1SMartin Blumenstingl 	total_data_len = btrtl_dev->cfg_len - sizeof(*config);
780b85b0ee1SMartin Blumenstingl 	if (total_data_len <= 0) {
781f1300c03SAlex Lu 		rtl_dev_warn(hdev, "no config loaded");
782b85b0ee1SMartin Blumenstingl 		return -EINVAL;
783b85b0ee1SMartin Blumenstingl 	}
784b85b0ee1SMartin Blumenstingl 
785b85b0ee1SMartin Blumenstingl 	config = (struct rtl_vendor_config *)btrtl_dev->cfg_data;
786b85b0ee1SMartin Blumenstingl 	if (le32_to_cpu(config->signature) != RTL_CONFIG_MAGIC) {
787f1300c03SAlex Lu 		rtl_dev_err(hdev, "invalid config magic");
788b85b0ee1SMartin Blumenstingl 		return -EINVAL;
789b85b0ee1SMartin Blumenstingl 	}
790b85b0ee1SMartin Blumenstingl 
791b85b0ee1SMartin Blumenstingl 	if (total_data_len < le16_to_cpu(config->total_len)) {
792f1300c03SAlex Lu 		rtl_dev_err(hdev, "config is too short");
793b85b0ee1SMartin Blumenstingl 		return -EINVAL;
794b85b0ee1SMartin Blumenstingl 	}
795b85b0ee1SMartin Blumenstingl 
796b85b0ee1SMartin Blumenstingl 	for (i = 0; i < total_data_len; ) {
797b85b0ee1SMartin Blumenstingl 		entry = ((void *)config->entry) + i;
798b85b0ee1SMartin Blumenstingl 
799b85b0ee1SMartin Blumenstingl 		switch (le16_to_cpu(entry->offset)) {
800b85b0ee1SMartin Blumenstingl 		case 0xc:
801b85b0ee1SMartin Blumenstingl 			if (entry->len < sizeof(*device_baudrate)) {
802f1300c03SAlex Lu 				rtl_dev_err(hdev, "invalid UART config entry");
803b85b0ee1SMartin Blumenstingl 				return -EINVAL;
804b85b0ee1SMartin Blumenstingl 			}
805b85b0ee1SMartin Blumenstingl 
806b85b0ee1SMartin Blumenstingl 			*device_baudrate = get_unaligned_le32(entry->data);
807b85b0ee1SMartin Blumenstingl 			*controller_baudrate = btrtl_convert_baudrate(
808b85b0ee1SMartin Blumenstingl 							*device_baudrate);
809b85b0ee1SMartin Blumenstingl 
810b85b0ee1SMartin Blumenstingl 			if (entry->len >= 13)
811b85b0ee1SMartin Blumenstingl 				*flow_control = !!(entry->data[12] & BIT(2));
812b85b0ee1SMartin Blumenstingl 			else
813b85b0ee1SMartin Blumenstingl 				*flow_control = false;
814b85b0ee1SMartin Blumenstingl 
815b85b0ee1SMartin Blumenstingl 			found = true;
816b85b0ee1SMartin Blumenstingl 			break;
817b85b0ee1SMartin Blumenstingl 
818b85b0ee1SMartin Blumenstingl 		default:
819f1300c03SAlex Lu 			rtl_dev_dbg(hdev, "skipping config entry 0x%x (len %u)",
820b85b0ee1SMartin Blumenstingl 				   le16_to_cpu(entry->offset), entry->len);
821b85b0ee1SMartin Blumenstingl 			break;
822515d6798SYueHaibing 		}
823b85b0ee1SMartin Blumenstingl 
824b85b0ee1SMartin Blumenstingl 		i += sizeof(*entry) + entry->len;
825b85b0ee1SMartin Blumenstingl 	}
826b85b0ee1SMartin Blumenstingl 
827b85b0ee1SMartin Blumenstingl 	if (!found) {
828f1300c03SAlex Lu 		rtl_dev_err(hdev, "no UART config entry found");
829b85b0ee1SMartin Blumenstingl 		return -ENOENT;
830b85b0ee1SMartin Blumenstingl 	}
831b85b0ee1SMartin Blumenstingl 
832f1300c03SAlex Lu 	rtl_dev_dbg(hdev, "device baudrate = 0x%08x", *device_baudrate);
833f1300c03SAlex Lu 	rtl_dev_dbg(hdev, "controller baudrate = %u", *controller_baudrate);
834f1300c03SAlex Lu 	rtl_dev_dbg(hdev, "flow control %d", *flow_control);
835b85b0ee1SMartin Blumenstingl 
836b85b0ee1SMartin Blumenstingl 	return 0;
837b85b0ee1SMartin Blumenstingl }
838b85b0ee1SMartin Blumenstingl EXPORT_SYMBOL_GPL(btrtl_get_uart_settings);
839b85b0ee1SMartin Blumenstingl 
840db33c77dSCarlo Caione MODULE_AUTHOR("Daniel Drake <drake@endlessm.com>");
841db33c77dSCarlo Caione MODULE_DESCRIPTION("Bluetooth support for Realtek devices ver " VERSION);
842db33c77dSCarlo Caione MODULE_VERSION(VERSION);
843db33c77dSCarlo Caione MODULE_LICENSE("GPL");
844f96dbd32SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8723a_fw.bin");
845f96dbd32SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8723b_fw.bin");
846f96dbd32SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8723b_config.bin");
847c50903e3SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8723bs_fw.bin");
848c50903e3SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8723bs_config.bin");
849c50903e3SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8723ds_fw.bin");
850c50903e3SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8723ds_config.bin");
851f96dbd32SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8761a_fw.bin");
852f96dbd32SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8761a_config.bin");
853f96dbd32SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8821a_fw.bin");
854f96dbd32SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8821a_config.bin");
855f96dbd32SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8822b_fw.bin");
856f96dbd32SMartin Blumenstingl MODULE_FIRMWARE("rtl_bt/rtl8822b_config.bin");
857