e0268777ab180ac8eee0a7d8f2c23c82a1b26aeb
[cascardo/linux.git] / net / nfc / digital_dep.c
1 /*
2  * NFC Digital Protocol stack
3  * Copyright (c) 2013, Intel Corporation.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms and conditions of the GNU General Public License,
7  * version 2, as published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for
12  * more details.
13  *
14  */
15
16 #define pr_fmt(fmt) "digital: %s: " fmt, __func__
17
18 #include "digital.h"
19
20 #define DIGITAL_NFC_DEP_N_RETRY_NACK    2
21 #define DIGITAL_NFC_DEP_N_RETRY_ATN     2
22
23 #define DIGITAL_NFC_DEP_FRAME_DIR_OUT 0xD4
24 #define DIGITAL_NFC_DEP_FRAME_DIR_IN  0xD5
25
26 #define DIGITAL_NFC_DEP_NFCA_SOD_SB   0xF0
27
28 #define DIGITAL_CMD_ATR_REQ 0x00
29 #define DIGITAL_CMD_ATR_RES 0x01
30 #define DIGITAL_CMD_PSL_REQ 0x04
31 #define DIGITAL_CMD_PSL_RES 0x05
32 #define DIGITAL_CMD_DEP_REQ 0x06
33 #define DIGITAL_CMD_DEP_RES 0x07
34
35 #define DIGITAL_ATR_REQ_MIN_SIZE 16
36 #define DIGITAL_ATR_REQ_MAX_SIZE 64
37
38 #define DIGITAL_DID_MAX 14
39
40 #define DIGITAL_PAYLOAD_SIZE_MAX        254
41 #define DIGITAL_PAYLOAD_BITS_TO_PP(s)   (((s) & 0x3) << 4)
42 #define DIGITAL_PAYLOAD_PP_TO_BITS(s)   (((s) >> 4) & 0x3)
43 #define DIGITAL_PAYLOAD_BITS_TO_FSL(s)  ((s) & 0x3)
44 #define DIGITAL_PAYLOAD_FSL_TO_BITS(s)  ((s) & 0x3)
45
46 #define DIGITAL_GB_BIT  0x02
47
48 #define DIGITAL_NFC_DEP_REQ_RES_HEADROOM        2 /* SoD: [SB (NFC-A)] + LEN */
49 #define DIGITAL_NFC_DEP_REQ_RES_TAILROOM        2 /* EoD: 2-byte CRC */
50
51 #define DIGITAL_NFC_DEP_PFB_TYPE(pfb) ((pfb) & 0xE0)
52
53 #define DIGITAL_NFC_DEP_PFB_TIMEOUT_BIT 0x10
54 #define DIGITAL_NFC_DEP_PFB_MI_BIT      0x10
55 #define DIGITAL_NFC_DEP_PFB_NACK_BIT    0x10
56 #define DIGITAL_NFC_DEP_PFB_DID_BIT     0x04
57
58 #define DIGITAL_NFC_DEP_PFB_IS_TIMEOUT(pfb) \
59                                 ((pfb) & DIGITAL_NFC_DEP_PFB_TIMEOUT_BIT)
60 #define DIGITAL_NFC_DEP_MI_BIT_SET(pfb)  ((pfb) & DIGITAL_NFC_DEP_PFB_MI_BIT)
61 #define DIGITAL_NFC_DEP_NACK_BIT_SET(pfb) ((pfb) & DIGITAL_NFC_DEP_PFB_NACK_BIT)
62 #define DIGITAL_NFC_DEP_NAD_BIT_SET(pfb) ((pfb) & 0x08)
63 #define DIGITAL_NFC_DEP_DID_BIT_SET(pfb) ((pfb) & DIGITAL_NFC_DEP_PFB_DID_BIT)
64 #define DIGITAL_NFC_DEP_PFB_PNI(pfb)     ((pfb) & 0x03)
65
66 #define DIGITAL_NFC_DEP_PFB_I_PDU          0x00
67 #define DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU   0x40
68 #define DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU 0x80
69
70 struct digital_atr_req {
71         u8 dir;
72         u8 cmd;
73         u8 nfcid3[10];
74         u8 did;
75         u8 bs;
76         u8 br;
77         u8 pp;
78         u8 gb[0];
79 } __packed;
80
81 struct digital_atr_res {
82         u8 dir;
83         u8 cmd;
84         u8 nfcid3[10];
85         u8 did;
86         u8 bs;
87         u8 br;
88         u8 to;
89         u8 pp;
90         u8 gb[0];
91 } __packed;
92
93 struct digital_psl_req {
94         u8 dir;
95         u8 cmd;
96         u8 did;
97         u8 brs;
98         u8 fsl;
99 } __packed;
100
101 struct digital_psl_res {
102         u8 dir;
103         u8 cmd;
104         u8 did;
105 } __packed;
106
107 struct digital_dep_req_res {
108         u8 dir;
109         u8 cmd;
110         u8 pfb;
111 } __packed;
112
113 static void digital_in_recv_dep_res(struct nfc_digital_dev *ddev, void *arg,
114                                     struct sk_buff *resp);
115 static void digital_tg_recv_dep_req(struct nfc_digital_dev *ddev, void *arg,
116                                     struct sk_buff *resp);
117
118 static const u8 digital_payload_bits_map[4] = {
119         [0] = 64,
120         [1] = 128,
121         [2] = 192,
122         [3] = 254
123 };
124
125 static u8 digital_payload_bits_to_size(u8 payload_bits)
126 {
127         if (payload_bits >= ARRAY_SIZE(digital_payload_bits_map))
128                 return 0;
129
130         return digital_payload_bits_map[payload_bits];
131 }
132
133 static u8 digital_payload_size_to_bits(u8 payload_size)
134 {
135         int i;
136
137         for (i = 0; i < ARRAY_SIZE(digital_payload_bits_map); i++)
138                 if (digital_payload_bits_map[i] == payload_size)
139                         return i;
140
141         return 0xff;
142 }
143
144 static void digital_skb_push_dep_sod(struct nfc_digital_dev *ddev,
145                                      struct sk_buff *skb)
146 {
147         skb_push(skb, sizeof(u8));
148
149         skb->data[0] = skb->len;
150
151         if (ddev->curr_rf_tech == NFC_DIGITAL_RF_TECH_106A)
152                 *skb_push(skb, sizeof(u8)) = DIGITAL_NFC_DEP_NFCA_SOD_SB;
153 }
154
155 static int digital_skb_pull_dep_sod(struct nfc_digital_dev *ddev,
156                                     struct sk_buff *skb)
157 {
158         u8 size;
159
160         if (skb->len < 2)
161                 return -EIO;
162
163         if (ddev->curr_rf_tech == NFC_DIGITAL_RF_TECH_106A)
164                 skb_pull(skb, sizeof(u8));
165
166         size = skb->data[0];
167         if (size != skb->len)
168                 return -EIO;
169
170         skb_pull(skb, sizeof(u8));
171
172         return 0;
173 }
174
175 static struct sk_buff *
176 digital_send_dep_data_prep(struct nfc_digital_dev *ddev, struct sk_buff *skb,
177                            struct digital_dep_req_res *dep_req_res,
178                            struct digital_data_exch *data_exch)
179 {
180         struct sk_buff *new_skb;
181
182         if (skb->len > ddev->remote_payload_max) {
183                 dep_req_res->pfb |= DIGITAL_NFC_DEP_PFB_MI_BIT;
184
185                 new_skb = digital_skb_alloc(ddev, ddev->remote_payload_max);
186                 if (!new_skb) {
187                         kfree_skb(ddev->chaining_skb);
188                         ddev->chaining_skb = NULL;
189
190                         return ERR_PTR(-ENOMEM);
191                 }
192
193                 memcpy(skb_put(new_skb, ddev->remote_payload_max), skb->data,
194                        ddev->remote_payload_max);
195                 skb_pull(skb, ddev->remote_payload_max);
196
197                 ddev->chaining_skb = skb;
198                 ddev->data_exch = data_exch;
199         } else {
200                 ddev->chaining_skb = NULL;
201                 new_skb = skb;
202         }
203
204         return new_skb;
205 }
206
207 static struct sk_buff *
208 digital_recv_dep_data_gather(struct nfc_digital_dev *ddev, u8 pfb,
209                              struct sk_buff *resp,
210                              int (*send_ack)(struct nfc_digital_dev *ddev,
211                                              struct digital_data_exch
212                                                              *data_exch),
213                              struct digital_data_exch *data_exch)
214 {
215         struct sk_buff *new_skb;
216         int rc;
217
218         if (DIGITAL_NFC_DEP_MI_BIT_SET(pfb) && (!ddev->chaining_skb)) {
219                 ddev->chaining_skb =
220                         nfc_alloc_recv_skb(8 * ddev->local_payload_max,
221                                            GFP_KERNEL);
222                 if (!ddev->chaining_skb) {
223                         rc = -ENOMEM;
224                         goto error;
225                 }
226         }
227
228         if (ddev->chaining_skb) {
229                 if (resp->len > skb_tailroom(ddev->chaining_skb)) {
230                         new_skb = skb_copy_expand(ddev->chaining_skb,
231                                                   skb_headroom(
232                                                           ddev->chaining_skb),
233                                                   8 * ddev->local_payload_max,
234                                                   GFP_KERNEL);
235                         if (!new_skb) {
236                                 rc = -ENOMEM;
237                                 goto error;
238                         }
239
240                         kfree_skb(ddev->chaining_skb);
241                         ddev->chaining_skb = new_skb;
242                 }
243
244                 memcpy(skb_put(ddev->chaining_skb, resp->len), resp->data,
245                        resp->len);
246
247                 kfree_skb(resp);
248                 resp = NULL;
249
250                 if (DIGITAL_NFC_DEP_MI_BIT_SET(pfb)) {
251                         rc = send_ack(ddev, data_exch);
252                         if (rc)
253                                 goto error;
254
255                         return NULL;
256                 }
257
258                 resp = ddev->chaining_skb;
259                 ddev->chaining_skb = NULL;
260         }
261
262         return resp;
263
264 error:
265         kfree_skb(resp);
266
267         kfree_skb(ddev->chaining_skb);
268         ddev->chaining_skb = NULL;
269
270         return ERR_PTR(rc);
271 }
272
273 static void digital_in_recv_psl_res(struct nfc_digital_dev *ddev, void *arg,
274                                     struct sk_buff *resp)
275 {
276         struct nfc_target *target = arg;
277         struct digital_psl_res *psl_res;
278         int rc;
279
280         if (IS_ERR(resp)) {
281                 rc = PTR_ERR(resp);
282                 resp = NULL;
283                 goto exit;
284         }
285
286         rc = ddev->skb_check_crc(resp);
287         if (rc) {
288                 PROTOCOL_ERR("14.4.1.6");
289                 goto exit;
290         }
291
292         rc = digital_skb_pull_dep_sod(ddev, resp);
293         if (rc) {
294                 PROTOCOL_ERR("14.4.1.2");
295                 goto exit;
296         }
297
298         psl_res = (struct digital_psl_res *)resp->data;
299
300         if ((resp->len != sizeof(*psl_res)) ||
301             (psl_res->dir != DIGITAL_NFC_DEP_FRAME_DIR_IN) ||
302             (psl_res->cmd != DIGITAL_CMD_PSL_RES)) {
303                 rc = -EIO;
304                 goto exit;
305         }
306
307         rc = digital_in_configure_hw(ddev, NFC_DIGITAL_CONFIG_RF_TECH,
308                                      NFC_DIGITAL_RF_TECH_424F);
309         if (rc)
310                 goto exit;
311
312         rc = digital_in_configure_hw(ddev, NFC_DIGITAL_CONFIG_FRAMING,
313                                      NFC_DIGITAL_FRAMING_NFCF_NFC_DEP);
314         if (rc)
315                 goto exit;
316
317         if (!DIGITAL_DRV_CAPS_IN_CRC(ddev) &&
318             (ddev->curr_rf_tech == NFC_DIGITAL_RF_TECH_106A)) {
319                 ddev->skb_add_crc = digital_skb_add_crc_f;
320                 ddev->skb_check_crc = digital_skb_check_crc_f;
321         }
322
323         ddev->curr_rf_tech = NFC_DIGITAL_RF_TECH_424F;
324
325         nfc_dep_link_is_up(ddev->nfc_dev, target->idx, NFC_COMM_ACTIVE,
326                            NFC_RF_INITIATOR);
327
328         ddev->curr_nfc_dep_pni = 0;
329
330 exit:
331         dev_kfree_skb(resp);
332
333         if (rc)
334                 ddev->curr_protocol = 0;
335 }
336
337 static int digital_in_send_psl_req(struct nfc_digital_dev *ddev,
338                                    struct nfc_target *target)
339 {
340         struct sk_buff *skb;
341         struct digital_psl_req *psl_req;
342         int rc;
343         u8 payload_size, payload_bits;
344
345         skb = digital_skb_alloc(ddev, sizeof(*psl_req));
346         if (!skb)
347                 return -ENOMEM;
348
349         skb_put(skb, sizeof(*psl_req));
350
351         psl_req = (struct digital_psl_req *)skb->data;
352
353         psl_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
354         psl_req->cmd = DIGITAL_CMD_PSL_REQ;
355         psl_req->did = 0;
356         psl_req->brs = (0x2 << 3) | 0x2; /* 424F both directions */
357
358         payload_size = min(ddev->local_payload_max, ddev->remote_payload_max);
359         payload_bits = digital_payload_size_to_bits(payload_size);
360         psl_req->fsl = DIGITAL_PAYLOAD_BITS_TO_FSL(payload_bits);
361
362         ddev->local_payload_max = payload_size;
363         ddev->remote_payload_max = payload_size;
364
365         digital_skb_push_dep_sod(ddev, skb);
366
367         ddev->skb_add_crc(skb);
368
369         rc = digital_in_send_cmd(ddev, skb, 500, digital_in_recv_psl_res,
370                                  target);
371         if (rc)
372                 kfree_skb(skb);
373
374         return rc;
375 }
376
377 static void digital_in_recv_atr_res(struct nfc_digital_dev *ddev, void *arg,
378                                  struct sk_buff *resp)
379 {
380         struct nfc_target *target = arg;
381         struct digital_atr_res *atr_res;
382         u8 gb_len, payload_bits;
383         int rc;
384
385         if (IS_ERR(resp)) {
386                 rc = PTR_ERR(resp);
387                 resp = NULL;
388                 goto exit;
389         }
390
391         rc = ddev->skb_check_crc(resp);
392         if (rc) {
393                 PROTOCOL_ERR("14.4.1.6");
394                 goto exit;
395         }
396
397         rc = digital_skb_pull_dep_sod(ddev, resp);
398         if (rc) {
399                 PROTOCOL_ERR("14.4.1.2");
400                 goto exit;
401         }
402
403         if (resp->len < sizeof(struct digital_atr_res)) {
404                 rc = -EIO;
405                 goto exit;
406         }
407
408         gb_len = resp->len - sizeof(struct digital_atr_res);
409
410         atr_res = (struct digital_atr_res *)resp->data;
411
412         payload_bits = DIGITAL_PAYLOAD_PP_TO_BITS(atr_res->pp);
413         ddev->remote_payload_max = digital_payload_bits_to_size(payload_bits);
414
415         if (!ddev->remote_payload_max) {
416                 rc = -EINVAL;
417                 goto exit;
418         }
419
420         rc = nfc_set_remote_general_bytes(ddev->nfc_dev, atr_res->gb, gb_len);
421         if (rc)
422                 goto exit;
423
424         if ((ddev->protocols & NFC_PROTO_FELICA_MASK) &&
425             (ddev->curr_rf_tech != NFC_DIGITAL_RF_TECH_424F)) {
426                 rc = digital_in_send_psl_req(ddev, target);
427                 if (!rc)
428                         goto exit;
429         }
430
431         rc = nfc_dep_link_is_up(ddev->nfc_dev, target->idx, NFC_COMM_ACTIVE,
432                                 NFC_RF_INITIATOR);
433
434         ddev->curr_nfc_dep_pni = 0;
435
436 exit:
437         dev_kfree_skb(resp);
438
439         if (rc)
440                 ddev->curr_protocol = 0;
441 }
442
443 int digital_in_send_atr_req(struct nfc_digital_dev *ddev,
444                             struct nfc_target *target, __u8 comm_mode, __u8 *gb,
445                             size_t gb_len)
446 {
447         struct sk_buff *skb;
448         struct digital_atr_req *atr_req;
449         uint size;
450         int rc;
451         u8 payload_bits;
452
453         size = DIGITAL_ATR_REQ_MIN_SIZE + gb_len;
454
455         if (size > DIGITAL_ATR_REQ_MAX_SIZE) {
456                 PROTOCOL_ERR("14.6.1.1");
457                 return -EINVAL;
458         }
459
460         skb = digital_skb_alloc(ddev, size);
461         if (!skb)
462                 return -ENOMEM;
463
464         skb_put(skb, sizeof(struct digital_atr_req));
465
466         atr_req = (struct digital_atr_req *)skb->data;
467         memset(atr_req, 0, sizeof(struct digital_atr_req));
468
469         atr_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
470         atr_req->cmd = DIGITAL_CMD_ATR_REQ;
471         if (target->nfcid2_len)
472                 memcpy(atr_req->nfcid3, target->nfcid2, NFC_NFCID2_MAXSIZE);
473         else
474                 get_random_bytes(atr_req->nfcid3, NFC_NFCID3_MAXSIZE);
475
476         atr_req->did = 0;
477         atr_req->bs = 0;
478         atr_req->br = 0;
479
480         ddev->local_payload_max = DIGITAL_PAYLOAD_SIZE_MAX;
481         payload_bits = digital_payload_size_to_bits(ddev->local_payload_max);
482         atr_req->pp = DIGITAL_PAYLOAD_BITS_TO_PP(payload_bits);
483
484         if (gb_len) {
485                 atr_req->pp |= DIGITAL_GB_BIT;
486                 memcpy(skb_put(skb, gb_len), gb, gb_len);
487         }
488
489         digital_skb_push_dep_sod(ddev, skb);
490
491         ddev->skb_add_crc(skb);
492
493         rc = digital_in_send_cmd(ddev, skb, 500, digital_in_recv_atr_res,
494                                  target);
495         if (rc)
496                 kfree_skb(skb);
497
498         return rc;
499 }
500
501 static int digital_in_send_ack(struct nfc_digital_dev *ddev,
502                                struct digital_data_exch *data_exch)
503 {
504         struct digital_dep_req_res *dep_req;
505         struct sk_buff *skb;
506         int rc;
507
508         skb = digital_skb_alloc(ddev, 1);
509         if (!skb)
510                 return -ENOMEM;
511
512         skb_push(skb, sizeof(struct digital_dep_req_res));
513
514         dep_req = (struct digital_dep_req_res *)skb->data;
515
516         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
517         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
518         dep_req->pfb = DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU |
519                        ddev->curr_nfc_dep_pni;
520
521         digital_skb_push_dep_sod(ddev, skb);
522
523         ddev->skb_add_crc(skb);
524
525         ddev->saved_skb = pskb_copy(skb, GFP_KERNEL);
526
527         rc = digital_in_send_cmd(ddev, skb, 1500, digital_in_recv_dep_res,
528                                  data_exch);
529         if (rc) {
530                 kfree_skb(skb);
531                 kfree_skb(ddev->saved_skb);
532                 ddev->saved_skb = NULL;
533         }
534
535         return rc;
536 }
537
538 static int digital_in_send_nack(struct nfc_digital_dev *ddev,
539                                 struct digital_data_exch *data_exch)
540 {
541         struct digital_dep_req_res *dep_req;
542         struct sk_buff *skb;
543         int rc;
544
545         skb = digital_skb_alloc(ddev, 1);
546         if (!skb)
547                 return -ENOMEM;
548
549         skb_push(skb, sizeof(struct digital_dep_req_res));
550
551         dep_req = (struct digital_dep_req_res *)skb->data;
552
553         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
554         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
555         dep_req->pfb = DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU |
556                        DIGITAL_NFC_DEP_PFB_NACK_BIT | ddev->curr_nfc_dep_pni;
557
558         digital_skb_push_dep_sod(ddev, skb);
559
560         ddev->skb_add_crc(skb);
561
562         rc = digital_in_send_cmd(ddev, skb, 1500, digital_in_recv_dep_res,
563                                  data_exch);
564         if (rc)
565                 kfree_skb(skb);
566
567         return rc;
568 }
569
570 static int digital_in_send_atn(struct nfc_digital_dev *ddev,
571                                struct digital_data_exch *data_exch)
572 {
573         struct digital_dep_req_res *dep_req;
574         struct sk_buff *skb;
575         int rc;
576
577         skb = digital_skb_alloc(ddev, 1);
578         if (!skb)
579                 return -ENOMEM;
580
581         skb_push(skb, sizeof(struct digital_dep_req_res));
582
583         dep_req = (struct digital_dep_req_res *)skb->data;
584
585         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
586         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
587         dep_req->pfb = DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU;
588
589         digital_skb_push_dep_sod(ddev, skb);
590
591         ddev->skb_add_crc(skb);
592
593         rc = digital_in_send_cmd(ddev, skb, 1500, digital_in_recv_dep_res,
594                                  data_exch);
595         if (rc)
596                 kfree_skb(skb);
597
598         return rc;
599 }
600
601 static int digital_in_send_rtox(struct nfc_digital_dev *ddev,
602                                 struct digital_data_exch *data_exch, u8 rtox)
603 {
604         struct digital_dep_req_res *dep_req;
605         struct sk_buff *skb;
606         int rc;
607
608         skb = digital_skb_alloc(ddev, 1);
609         if (!skb)
610                 return -ENOMEM;
611
612         *skb_put(skb, 1) = rtox;
613
614         skb_push(skb, sizeof(struct digital_dep_req_res));
615
616         dep_req = (struct digital_dep_req_res *)skb->data;
617
618         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
619         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
620         dep_req->pfb = DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU |
621                        DIGITAL_NFC_DEP_PFB_TIMEOUT_BIT;
622
623         digital_skb_push_dep_sod(ddev, skb);
624
625         ddev->skb_add_crc(skb);
626
627         rc = digital_in_send_cmd(ddev, skb, 1500, digital_in_recv_dep_res,
628                                  data_exch);
629         if (rc)
630                 kfree_skb(skb);
631
632         return rc;
633 }
634
635 static int digital_in_send_saved_skb(struct nfc_digital_dev *ddev,
636                                      struct digital_data_exch *data_exch)
637 {
638         int rc;
639
640         if (!ddev->saved_skb)
641                 return -EINVAL;
642
643         skb_get(ddev->saved_skb);
644
645         rc = digital_in_send_cmd(ddev, ddev->saved_skb, 1500,
646                                  digital_in_recv_dep_res, data_exch);
647         if (rc)
648                 kfree_skb(ddev->saved_skb);
649
650         return rc;
651 }
652
653 static void digital_in_recv_dep_res(struct nfc_digital_dev *ddev, void *arg,
654                                     struct sk_buff *resp)
655 {
656         struct digital_data_exch *data_exch = arg;
657         struct digital_dep_req_res *dep_res;
658         u8 pfb;
659         uint size;
660         int rc;
661
662         if (IS_ERR(resp)) {
663                 rc = PTR_ERR(resp);
664                 resp = NULL;
665
666                 if ((rc == -EIO || (rc == -ETIMEDOUT && ddev->nack_count)) &&
667                     (ddev->nack_count++ < DIGITAL_NFC_DEP_N_RETRY_NACK)) {
668                         ddev->atn_count = 0;
669
670                         rc = digital_in_send_nack(ddev, data_exch);
671                         if (rc)
672                                 goto error;
673
674                         return;
675                 } else if ((rc == -ETIMEDOUT) &&
676                            (ddev->atn_count++ < DIGITAL_NFC_DEP_N_RETRY_ATN)) {
677                         ddev->nack_count = 0;
678
679                         rc = digital_in_send_atn(ddev, data_exch);
680                         if (rc)
681                                 goto error;
682
683                         return;
684                 }
685
686                 goto exit;
687         }
688
689         rc = digital_skb_pull_dep_sod(ddev, resp);
690         if (rc) {
691                 PROTOCOL_ERR("14.4.1.2");
692                 goto exit;
693         }
694
695         rc = ddev->skb_check_crc(resp);
696         if (rc) {
697                 if ((resp->len >= 4) &&
698                     (ddev->nack_count++ < DIGITAL_NFC_DEP_N_RETRY_NACK)) {
699                         ddev->atn_count = 0;
700
701                         rc = digital_in_send_nack(ddev, data_exch);
702                         if (rc)
703                                 goto error;
704
705                         kfree_skb(resp);
706
707                         return;
708                 }
709
710                 PROTOCOL_ERR("14.4.1.6");
711                 goto error;
712         }
713
714         ddev->atn_count = 0;
715         ddev->nack_count = 0;
716
717         if (resp->len > ddev->local_payload_max) {
718                 rc = -EMSGSIZE;
719                 goto exit;
720         }
721
722         size = sizeof(struct digital_dep_req_res);
723         dep_res = (struct digital_dep_req_res *)resp->data;
724
725         if (resp->len < size || dep_res->dir != DIGITAL_NFC_DEP_FRAME_DIR_IN ||
726             dep_res->cmd != DIGITAL_CMD_DEP_RES) {
727                 rc = -EIO;
728                 goto error;
729         }
730
731         pfb = dep_res->pfb;
732
733         if (DIGITAL_NFC_DEP_DID_BIT_SET(pfb)) {
734                 PROTOCOL_ERR("14.8.2.1");
735                 rc = -EIO;
736                 goto error;
737         }
738
739         if (DIGITAL_NFC_DEP_NAD_BIT_SET(pfb)) {
740                 rc = -EIO;
741                 goto exit;
742         }
743
744         if (size > resp->len) {
745                 rc = -EIO;
746                 goto error;
747         }
748
749         skb_pull(resp, size);
750
751         switch (DIGITAL_NFC_DEP_PFB_TYPE(pfb)) {
752         case DIGITAL_NFC_DEP_PFB_I_PDU:
753                 if (DIGITAL_NFC_DEP_PFB_PNI(pfb) != ddev->curr_nfc_dep_pni) {
754                         PROTOCOL_ERR("14.12.3.3");
755                         rc = -EIO;
756                         goto error;
757                 }
758
759                 ddev->curr_nfc_dep_pni =
760                         DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni + 1);
761
762                 kfree_skb(ddev->saved_skb);
763                 ddev->saved_skb = NULL;
764
765                 resp = digital_recv_dep_data_gather(ddev, pfb, resp,
766                                                     digital_in_send_ack,
767                                                     data_exch);
768                 if (IS_ERR(resp)) {
769                         rc = PTR_ERR(resp);
770                         resp = NULL;
771                         goto error;
772                 }
773
774                 /* If resp is NULL then we're still chaining so return and
775                  * wait for the next part of the PDU.  Else, the PDU is
776                  * complete so pass it up.
777                  */
778                 if (!resp)
779                         return;
780
781                 rc = 0;
782                 break;
783
784         case DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU:
785                 if (DIGITAL_NFC_DEP_PFB_PNI(pfb) != ddev->curr_nfc_dep_pni) {
786                         PROTOCOL_ERR("14.12.3.3");
787                         rc = -EIO;
788                         goto exit;
789                 }
790
791                 ddev->curr_nfc_dep_pni =
792                         DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni + 1);
793
794                 if (ddev->chaining_skb && !DIGITAL_NFC_DEP_NACK_BIT_SET(pfb)) {
795                         kfree_skb(ddev->saved_skb);
796                         ddev->saved_skb = NULL;
797
798                         rc = digital_in_send_dep_req(ddev, NULL,
799                                                      ddev->chaining_skb,
800                                                      ddev->data_exch);
801                         if (rc)
802                                 goto error;
803
804                         return;
805                 }
806
807                 pr_err("Received a ACK/NACK PDU\n");
808                 rc = -EINVAL;
809                 goto exit;
810
811         case DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU:
812                 if (!DIGITAL_NFC_DEP_PFB_IS_TIMEOUT(pfb)) { /* ATN */
813                         rc = digital_in_send_saved_skb(ddev, data_exch);
814                         if (rc)
815                                 goto error;
816
817                         return;
818                 }
819
820                 rc = digital_in_send_rtox(ddev, data_exch, resp->data[0]);
821                 if (rc)
822                         goto error;
823
824                 kfree_skb(resp);
825                 return;
826         }
827
828 exit:
829         data_exch->cb(data_exch->cb_context, resp, rc);
830
831 error:
832         kfree(data_exch);
833
834         kfree_skb(ddev->chaining_skb);
835         ddev->chaining_skb = NULL;
836
837         kfree_skb(ddev->saved_skb);
838         ddev->saved_skb = NULL;
839
840         if (rc)
841                 kfree_skb(resp);
842 }
843
844 int digital_in_send_dep_req(struct nfc_digital_dev *ddev,
845                             struct nfc_target *target, struct sk_buff *skb,
846                             struct digital_data_exch *data_exch)
847 {
848         struct digital_dep_req_res *dep_req;
849         struct sk_buff *chaining_skb, *tmp_skb;
850         int rc;
851
852         skb_push(skb, sizeof(struct digital_dep_req_res));
853
854         dep_req = (struct digital_dep_req_res *)skb->data;
855
856         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
857         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
858         dep_req->pfb = ddev->curr_nfc_dep_pni;
859
860         ddev->atn_count = 0;
861         ddev->nack_count = 0;
862
863         chaining_skb = ddev->chaining_skb;
864
865         tmp_skb = digital_send_dep_data_prep(ddev, skb, dep_req, data_exch);
866         if (IS_ERR(tmp_skb))
867                 return PTR_ERR(tmp_skb);
868
869         digital_skb_push_dep_sod(ddev, tmp_skb);
870
871         ddev->skb_add_crc(tmp_skb);
872
873         ddev->saved_skb = pskb_copy(tmp_skb, GFP_KERNEL);
874
875         rc = digital_in_send_cmd(ddev, tmp_skb, 1500, digital_in_recv_dep_res,
876                                  data_exch);
877         if (rc) {
878                 if (tmp_skb != skb)
879                         kfree_skb(tmp_skb);
880
881                 kfree_skb(chaining_skb);
882                 ddev->chaining_skb = NULL;
883
884                 kfree_skb(ddev->saved_skb);
885                 ddev->saved_skb = NULL;
886         }
887
888         return rc;
889 }
890
891 static void digital_tg_set_rf_tech(struct nfc_digital_dev *ddev, u8 rf_tech)
892 {
893         ddev->curr_rf_tech = rf_tech;
894
895         ddev->skb_add_crc = digital_skb_add_crc_none;
896         ddev->skb_check_crc = digital_skb_check_crc_none;
897
898         if (DIGITAL_DRV_CAPS_TG_CRC(ddev))
899                 return;
900
901         switch (ddev->curr_rf_tech) {
902         case NFC_DIGITAL_RF_TECH_106A:
903                 ddev->skb_add_crc = digital_skb_add_crc_a;
904                 ddev->skb_check_crc = digital_skb_check_crc_a;
905                 break;
906
907         case NFC_DIGITAL_RF_TECH_212F:
908         case NFC_DIGITAL_RF_TECH_424F:
909                 ddev->skb_add_crc = digital_skb_add_crc_f;
910                 ddev->skb_check_crc = digital_skb_check_crc_f;
911                 break;
912
913         default:
914                 break;
915         }
916 }
917
918 static int digital_tg_send_ack(struct nfc_digital_dev *ddev,
919                                struct digital_data_exch *data_exch)
920 {
921         struct digital_dep_req_res *dep_res;
922         struct sk_buff *skb;
923         int rc;
924
925         skb = digital_skb_alloc(ddev, 1);
926         if (!skb)
927                 return -ENOMEM;
928
929         skb_push(skb, sizeof(struct digital_dep_req_res));
930
931         dep_res = (struct digital_dep_req_res *)skb->data;
932
933         dep_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
934         dep_res->cmd = DIGITAL_CMD_DEP_RES;
935         dep_res->pfb = DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU |
936                        ddev->curr_nfc_dep_pni;
937
938         if (ddev->did) {
939                 dep_res->pfb |= DIGITAL_NFC_DEP_PFB_DID_BIT;
940
941                 memcpy(skb_put(skb, sizeof(ddev->did)), &ddev->did,
942                        sizeof(ddev->did));
943         }
944
945         ddev->curr_nfc_dep_pni =
946                 DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni + 1);
947
948         digital_skb_push_dep_sod(ddev, skb);
949
950         ddev->skb_add_crc(skb);
951
952         ddev->saved_skb = pskb_copy(skb, GFP_KERNEL);
953
954         rc = digital_tg_send_cmd(ddev, skb, 1500, digital_tg_recv_dep_req,
955                                  data_exch);
956         if (rc) {
957                 kfree_skb(skb);
958                 kfree_skb(ddev->saved_skb);
959                 ddev->saved_skb = NULL;
960         }
961
962         return rc;
963 }
964
965 static int digital_tg_send_atn(struct nfc_digital_dev *ddev)
966 {
967         struct digital_dep_req_res *dep_res;
968         struct sk_buff *skb;
969         int rc;
970
971         skb = digital_skb_alloc(ddev, 1);
972         if (!skb)
973                 return -ENOMEM;
974
975         skb_push(skb, sizeof(struct digital_dep_req_res));
976
977         dep_res = (struct digital_dep_req_res *)skb->data;
978
979         dep_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
980         dep_res->cmd = DIGITAL_CMD_DEP_RES;
981         dep_res->pfb = DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU;
982
983         if (ddev->did) {
984                 dep_res->pfb |= DIGITAL_NFC_DEP_PFB_DID_BIT;
985
986                 memcpy(skb_put(skb, sizeof(ddev->did)), &ddev->did,
987                        sizeof(ddev->did));
988         }
989
990         digital_skb_push_dep_sod(ddev, skb);
991
992         ddev->skb_add_crc(skb);
993
994         rc = digital_tg_send_cmd(ddev, skb, 1500, digital_tg_recv_dep_req,
995                                  NULL);
996         if (rc)
997                 kfree_skb(skb);
998
999         return rc;
1000 }
1001
1002 static int digital_tg_send_saved_skb(struct nfc_digital_dev *ddev)
1003 {
1004         int rc;
1005
1006         if (!ddev->saved_skb)
1007                 return -EINVAL;
1008
1009         skb_get(ddev->saved_skb);
1010
1011         rc = digital_tg_send_cmd(ddev, ddev->saved_skb, 1500,
1012                                  digital_tg_recv_dep_req, NULL);
1013         if (rc)
1014                 kfree_skb(ddev->saved_skb);
1015
1016         return rc;
1017 }
1018
1019 static void digital_tg_recv_dep_req(struct nfc_digital_dev *ddev, void *arg,
1020                                     struct sk_buff *resp)
1021 {
1022         int rc;
1023         struct digital_dep_req_res *dep_req;
1024         u8 pfb;
1025         size_t size;
1026
1027         if (IS_ERR(resp)) {
1028                 rc = PTR_ERR(resp);
1029                 resp = NULL;
1030                 goto exit;
1031         }
1032
1033         rc = ddev->skb_check_crc(resp);
1034         if (rc) {
1035                 PROTOCOL_ERR("14.4.1.6");
1036                 goto exit;
1037         }
1038
1039         rc = digital_skb_pull_dep_sod(ddev, resp);
1040         if (rc) {
1041                 PROTOCOL_ERR("14.4.1.2");
1042                 goto exit;
1043         }
1044
1045         if (resp->len > ddev->local_payload_max) {
1046                 rc = -EMSGSIZE;
1047                 goto exit;
1048         }
1049
1050         size = sizeof(struct digital_dep_req_res);
1051         dep_req = (struct digital_dep_req_res *)resp->data;
1052
1053         if (resp->len < size || dep_req->dir != DIGITAL_NFC_DEP_FRAME_DIR_OUT ||
1054             dep_req->cmd != DIGITAL_CMD_DEP_REQ) {
1055                 rc = -EIO;
1056                 goto exit;
1057         }
1058
1059         pfb = dep_req->pfb;
1060
1061         if (DIGITAL_NFC_DEP_DID_BIT_SET(pfb)) {
1062                 if (ddev->did && (ddev->did == resp->data[3])) {
1063                         size++;
1064                 } else {
1065                         rc = -EIO;
1066                         goto exit;
1067                 }
1068         } else if (ddev->did) {
1069                 rc = -EIO;
1070                 goto exit;
1071         }
1072
1073         if (DIGITAL_NFC_DEP_NAD_BIT_SET(pfb)) {
1074                 rc = -EIO;
1075                 goto exit;
1076         }
1077
1078         if (size > resp->len) {
1079                 rc = -EIO;
1080                 goto exit;
1081         }
1082
1083         skb_pull(resp, size);
1084
1085         switch (DIGITAL_NFC_DEP_PFB_TYPE(pfb)) {
1086         case DIGITAL_NFC_DEP_PFB_I_PDU:
1087                 pr_debug("DIGITAL_NFC_DEP_PFB_I_PDU\n");
1088
1089                 if (ddev->atn_count) {
1090                         /* The target has received (and replied to) at least one
1091                          * ATN DEP_REQ.
1092                          */
1093                         ddev->atn_count = 0;
1094
1095                         /* pni of resp PDU equal to the target current pni - 1
1096                          * means resp is the previous DEP_REQ PDU received from
1097                          * the initiator so the target replies with saved_skb
1098                          * which is the previous DEP_RES saved in
1099                          * digital_tg_send_dep_res().
1100                          */
1101                         if (DIGITAL_NFC_DEP_PFB_PNI(pfb) ==
1102                           DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni - 1)) {
1103                                 rc = digital_tg_send_saved_skb(ddev);
1104                                 if (rc)
1105                                         goto exit;
1106
1107                                 goto free_resp;
1108                         }
1109
1110                         /* atn_count > 0 and PDU pni != curr_nfc_dep_pni - 1
1111                          * means the target probably did not received the last
1112                          * DEP_REQ PDU sent by the initiator. The target
1113                          * fallbacks to normal processing then.
1114                          */
1115                 }
1116
1117                 if (DIGITAL_NFC_DEP_PFB_PNI(pfb) != ddev->curr_nfc_dep_pni) {
1118                         PROTOCOL_ERR("14.12.3.4");
1119                         rc = -EIO;
1120                         goto exit;
1121                 }
1122
1123                 kfree_skb(ddev->saved_skb);
1124                 ddev->saved_skb = NULL;
1125
1126                 resp = digital_recv_dep_data_gather(ddev, pfb, resp,
1127                                                     digital_tg_send_ack, NULL);
1128                 if (IS_ERR(resp)) {
1129                         rc = PTR_ERR(resp);
1130                         resp = NULL;
1131                         goto exit;
1132                 }
1133
1134                 /* If resp is NULL then we're still chaining so return and
1135                  * wait for the next part of the PDU.  Else, the PDU is
1136                  * complete so pass it up.
1137                  */
1138                 if (!resp)
1139                         return;
1140
1141                 rc = 0;
1142                 break;
1143         case DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU:
1144                 if (DIGITAL_NFC_DEP_NACK_BIT_SET(pfb)) { /* NACK */
1145                         if (DIGITAL_NFC_DEP_PFB_PNI(pfb + 1) !=
1146                                                 ddev->curr_nfc_dep_pni) {
1147                                 rc = -EIO;
1148                                 goto exit;
1149                         }
1150
1151                         ddev->atn_count = 0;
1152
1153                         rc = digital_tg_send_saved_skb(ddev);
1154                         if (rc)
1155                                 goto exit;
1156
1157                         goto free_resp;
1158                 }
1159
1160                 /* ACK */
1161                 if (ddev->atn_count) {
1162                         /* The target has previously recevied one or more ATN
1163                          * PDUs.
1164                          */
1165                         ddev->atn_count = 0;
1166
1167                         /* If the ACK PNI is equal to the target PNI - 1 means
1168                          * that the initiator did not receive the previous PDU
1169                          * sent by the target so re-send it.
1170                          */
1171                         if (DIGITAL_NFC_DEP_PFB_PNI(pfb + 1) ==
1172                                                 ddev->curr_nfc_dep_pni) {
1173                                 rc = digital_tg_send_saved_skb(ddev);
1174                                 if (rc)
1175                                         goto exit;
1176
1177                                 goto free_resp;
1178                         }
1179
1180                         /* Otherwise, the target did not receive the previous
1181                          * ACK PDU from the initiator. Fallback to normal
1182                          * processing of chained PDU then.
1183                          */
1184                 }
1185
1186                 /* Keep on sending chained PDU */
1187                 if (!ddev->chaining_skb ||
1188                     DIGITAL_NFC_DEP_PFB_PNI(pfb) !=
1189                                         ddev->curr_nfc_dep_pni) {
1190                         rc = -EIO;
1191                         goto exit;
1192                 }
1193
1194                 kfree_skb(ddev->saved_skb);
1195                 ddev->saved_skb = NULL;
1196
1197                 rc = digital_tg_send_dep_res(ddev, ddev->chaining_skb);
1198                 if (rc)
1199                         goto exit;
1200
1201                 goto free_resp;
1202         case DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU:
1203                 if (DIGITAL_NFC_DEP_PFB_IS_TIMEOUT(pfb)) {
1204                         rc = -EINVAL;
1205                         goto exit;
1206                 }
1207
1208                 rc = digital_tg_send_atn(ddev);
1209                 if (rc)
1210                         goto exit;
1211
1212                 ddev->atn_count++;
1213
1214                 kfree_skb(resp);
1215                 return;
1216         }
1217
1218         rc = nfc_tm_data_received(ddev->nfc_dev, resp);
1219
1220 exit:
1221         kfree_skb(ddev->chaining_skb);
1222         ddev->chaining_skb = NULL;
1223
1224         ddev->atn_count = 0;
1225
1226         kfree_skb(ddev->saved_skb);
1227         ddev->saved_skb = NULL;
1228
1229         if (rc)
1230                 kfree_skb(resp);
1231
1232         return;
1233
1234 free_resp:
1235         dev_kfree_skb(resp);
1236 }
1237
1238 int digital_tg_send_dep_res(struct nfc_digital_dev *ddev, struct sk_buff *skb)
1239 {
1240         struct digital_dep_req_res *dep_res;
1241         struct sk_buff *chaining_skb, *tmp_skb;
1242         int rc;
1243
1244         skb_push(skb, sizeof(struct digital_dep_req_res));
1245
1246         dep_res = (struct digital_dep_req_res *)skb->data;
1247
1248         dep_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
1249         dep_res->cmd = DIGITAL_CMD_DEP_RES;
1250         dep_res->pfb = ddev->curr_nfc_dep_pni;
1251
1252         if (ddev->did) {
1253                 dep_res->pfb |= DIGITAL_NFC_DEP_PFB_DID_BIT;
1254
1255                 memcpy(skb_put(skb, sizeof(ddev->did)), &ddev->did,
1256                        sizeof(ddev->did));
1257         }
1258
1259         ddev->curr_nfc_dep_pni =
1260                 DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni + 1);
1261
1262         chaining_skb = ddev->chaining_skb;
1263
1264         tmp_skb = digital_send_dep_data_prep(ddev, skb, dep_res, NULL);
1265         if (IS_ERR(tmp_skb))
1266                 return PTR_ERR(tmp_skb);
1267
1268         digital_skb_push_dep_sod(ddev, tmp_skb);
1269
1270         ddev->skb_add_crc(tmp_skb);
1271
1272         ddev->saved_skb = pskb_copy(tmp_skb, GFP_KERNEL);
1273
1274         rc = digital_tg_send_cmd(ddev, tmp_skb, 1500, digital_tg_recv_dep_req,
1275                                  NULL);
1276         if (rc) {
1277                 if (tmp_skb != skb)
1278                         kfree_skb(tmp_skb);
1279
1280                 kfree_skb(chaining_skb);
1281                 ddev->chaining_skb = NULL;
1282
1283                 kfree_skb(ddev->saved_skb);
1284                 ddev->saved_skb = NULL;
1285         }
1286
1287         return rc;
1288 }
1289
1290 static void digital_tg_send_psl_res_complete(struct nfc_digital_dev *ddev,
1291                                              void *arg, struct sk_buff *resp)
1292 {
1293         u8 rf_tech = (unsigned long)arg;
1294
1295         if (IS_ERR(resp))
1296                 return;
1297
1298         digital_tg_set_rf_tech(ddev, rf_tech);
1299
1300         digital_tg_configure_hw(ddev, NFC_DIGITAL_CONFIG_RF_TECH, rf_tech);
1301
1302         digital_tg_listen(ddev, 1500, digital_tg_recv_dep_req, NULL);
1303
1304         dev_kfree_skb(resp);
1305 }
1306
1307 static int digital_tg_send_psl_res(struct nfc_digital_dev *ddev, u8 did,
1308                                    u8 rf_tech)
1309 {
1310         struct digital_psl_res *psl_res;
1311         struct sk_buff *skb;
1312         int rc;
1313
1314         skb = digital_skb_alloc(ddev, sizeof(struct digital_psl_res));
1315         if (!skb)
1316                 return -ENOMEM;
1317
1318         skb_put(skb, sizeof(struct digital_psl_res));
1319
1320         psl_res = (struct digital_psl_res *)skb->data;
1321
1322         psl_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
1323         psl_res->cmd = DIGITAL_CMD_PSL_RES;
1324         psl_res->did = did;
1325
1326         digital_skb_push_dep_sod(ddev, skb);
1327
1328         ddev->skb_add_crc(skb);
1329
1330         ddev->curr_nfc_dep_pni = 0;
1331
1332         rc = digital_tg_send_cmd(ddev, skb, 0, digital_tg_send_psl_res_complete,
1333                                  (void *)(unsigned long)rf_tech);
1334         if (rc)
1335                 kfree_skb(skb);
1336
1337         return rc;
1338 }
1339
1340 static void digital_tg_recv_psl_req(struct nfc_digital_dev *ddev, void *arg,
1341                                     struct sk_buff *resp)
1342 {
1343         int rc;
1344         struct digital_psl_req *psl_req;
1345         u8 rf_tech;
1346         u8 dsi, payload_size, payload_bits;
1347
1348         if (IS_ERR(resp)) {
1349                 rc = PTR_ERR(resp);
1350                 resp = NULL;
1351                 goto exit;
1352         }
1353
1354         rc = ddev->skb_check_crc(resp);
1355         if (rc) {
1356                 PROTOCOL_ERR("14.4.1.6");
1357                 goto exit;
1358         }
1359
1360         rc = digital_skb_pull_dep_sod(ddev, resp);
1361         if (rc) {
1362                 PROTOCOL_ERR("14.4.1.2");
1363                 goto exit;
1364         }
1365
1366         psl_req = (struct digital_psl_req *)resp->data;
1367
1368         if (resp->len != sizeof(struct digital_psl_req) ||
1369             psl_req->dir != DIGITAL_NFC_DEP_FRAME_DIR_OUT ||
1370             psl_req->cmd != DIGITAL_CMD_PSL_REQ) {
1371                 rc = -EIO;
1372                 goto exit;
1373         }
1374
1375         dsi = (psl_req->brs >> 3) & 0x07;
1376         switch (dsi) {
1377         case 0:
1378                 rf_tech = NFC_DIGITAL_RF_TECH_106A;
1379                 break;
1380         case 1:
1381                 rf_tech = NFC_DIGITAL_RF_TECH_212F;
1382                 break;
1383         case 2:
1384                 rf_tech = NFC_DIGITAL_RF_TECH_424F;
1385                 break;
1386         default:
1387                 pr_err("Unsupported dsi value %d\n", dsi);
1388                 goto exit;
1389         }
1390
1391         payload_bits = DIGITAL_PAYLOAD_FSL_TO_BITS(psl_req->fsl);
1392         payload_size = digital_payload_bits_to_size(payload_bits);
1393
1394         if (!payload_size || (payload_size > min(ddev->local_payload_max,
1395                                                  ddev->remote_payload_max))) {
1396                 rc = -EINVAL;
1397                 goto exit;
1398         }
1399
1400         ddev->local_payload_max = payload_size;
1401         ddev->remote_payload_max = payload_size;
1402
1403         rc = digital_tg_send_psl_res(ddev, psl_req->did, rf_tech);
1404
1405 exit:
1406         kfree_skb(resp);
1407 }
1408
1409 static void digital_tg_send_atr_res_complete(struct nfc_digital_dev *ddev,
1410                                              void *arg, struct sk_buff *resp)
1411 {
1412         int offset;
1413
1414         if (IS_ERR(resp)) {
1415                 digital_poll_next_tech(ddev);
1416                 return;
1417         }
1418
1419         offset = 2;
1420         if (resp->data[0] == DIGITAL_NFC_DEP_NFCA_SOD_SB)
1421                 offset++;
1422
1423         ddev->atn_count = 0;
1424
1425         if (resp->data[offset] == DIGITAL_CMD_PSL_REQ)
1426                 digital_tg_recv_psl_req(ddev, arg, resp);
1427         else
1428                 digital_tg_recv_dep_req(ddev, arg, resp);
1429 }
1430
1431 static int digital_tg_send_atr_res(struct nfc_digital_dev *ddev,
1432                                    struct digital_atr_req *atr_req)
1433 {
1434         struct digital_atr_res *atr_res;
1435         struct sk_buff *skb;
1436         u8 *gb, payload_bits;
1437         size_t gb_len;
1438         int rc;
1439
1440         gb = nfc_get_local_general_bytes(ddev->nfc_dev, &gb_len);
1441         if (!gb)
1442                 gb_len = 0;
1443
1444         skb = digital_skb_alloc(ddev, sizeof(struct digital_atr_res) + gb_len);
1445         if (!skb)
1446                 return -ENOMEM;
1447
1448         skb_put(skb, sizeof(struct digital_atr_res));
1449         atr_res = (struct digital_atr_res *)skb->data;
1450
1451         memset(atr_res, 0, sizeof(struct digital_atr_res));
1452
1453         atr_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
1454         atr_res->cmd = DIGITAL_CMD_ATR_RES;
1455         memcpy(atr_res->nfcid3, atr_req->nfcid3, sizeof(atr_req->nfcid3));
1456         atr_res->to = 8;
1457
1458         ddev->local_payload_max = DIGITAL_PAYLOAD_SIZE_MAX;
1459         payload_bits = digital_payload_size_to_bits(ddev->local_payload_max);
1460         atr_res->pp = DIGITAL_PAYLOAD_BITS_TO_PP(payload_bits);
1461
1462         if (gb_len) {
1463                 skb_put(skb, gb_len);
1464
1465                 atr_res->pp |= DIGITAL_GB_BIT;
1466                 memcpy(atr_res->gb, gb, gb_len);
1467         }
1468
1469         digital_skb_push_dep_sod(ddev, skb);
1470
1471         ddev->skb_add_crc(skb);
1472
1473         ddev->curr_nfc_dep_pni = 0;
1474
1475         rc = digital_tg_send_cmd(ddev, skb, 999,
1476                                  digital_tg_send_atr_res_complete, NULL);
1477         if (rc)
1478                 kfree_skb(skb);
1479
1480         return rc;
1481 }
1482
1483 void digital_tg_recv_atr_req(struct nfc_digital_dev *ddev, void *arg,
1484                              struct sk_buff *resp)
1485 {
1486         int rc;
1487         struct digital_atr_req *atr_req;
1488         size_t gb_len, min_size;
1489         u8 poll_tech_count, payload_bits;
1490
1491         if (IS_ERR(resp)) {
1492                 rc = PTR_ERR(resp);
1493                 resp = NULL;
1494                 goto exit;
1495         }
1496
1497         if (!resp->len) {
1498                 rc = -EIO;
1499                 goto exit;
1500         }
1501
1502         if (resp->data[0] == DIGITAL_NFC_DEP_NFCA_SOD_SB) {
1503                 min_size = DIGITAL_ATR_REQ_MIN_SIZE + 2;
1504                 digital_tg_set_rf_tech(ddev, NFC_DIGITAL_RF_TECH_106A);
1505         } else {
1506                 min_size = DIGITAL_ATR_REQ_MIN_SIZE + 1;
1507                 digital_tg_set_rf_tech(ddev, NFC_DIGITAL_RF_TECH_212F);
1508         }
1509
1510         if (resp->len < min_size) {
1511                 rc = -EIO;
1512                 goto exit;
1513         }
1514
1515         ddev->curr_protocol = NFC_PROTO_NFC_DEP_MASK;
1516
1517         rc = ddev->skb_check_crc(resp);
1518         if (rc) {
1519                 PROTOCOL_ERR("14.4.1.6");
1520                 goto exit;
1521         }
1522
1523         rc = digital_skb_pull_dep_sod(ddev, resp);
1524         if (rc) {
1525                 PROTOCOL_ERR("14.4.1.2");
1526                 goto exit;
1527         }
1528
1529         atr_req = (struct digital_atr_req *)resp->data;
1530
1531         if (atr_req->dir != DIGITAL_NFC_DEP_FRAME_DIR_OUT ||
1532             atr_req->cmd != DIGITAL_CMD_ATR_REQ ||
1533             atr_req->did > DIGITAL_DID_MAX) {
1534                 rc = -EINVAL;
1535                 goto exit;
1536         }
1537
1538         payload_bits = DIGITAL_PAYLOAD_PP_TO_BITS(atr_req->pp);
1539         ddev->remote_payload_max = digital_payload_bits_to_size(payload_bits);
1540
1541         if (!ddev->remote_payload_max) {
1542                 rc = -EINVAL;
1543                 goto exit;
1544         }
1545
1546         ddev->did = atr_req->did;
1547
1548         rc = digital_tg_configure_hw(ddev, NFC_DIGITAL_CONFIG_FRAMING,
1549                                      NFC_DIGITAL_FRAMING_NFC_DEP_ACTIVATED);
1550         if (rc)
1551                 goto exit;
1552
1553         rc = digital_tg_send_atr_res(ddev, atr_req);
1554         if (rc)
1555                 goto exit;
1556
1557         gb_len = resp->len - sizeof(struct digital_atr_req);
1558
1559         poll_tech_count = ddev->poll_tech_count;
1560         ddev->poll_tech_count = 0;
1561
1562         rc = nfc_tm_activated(ddev->nfc_dev, NFC_PROTO_NFC_DEP_MASK,
1563                               NFC_COMM_PASSIVE, atr_req->gb, gb_len);
1564         if (rc) {
1565                 ddev->poll_tech_count = poll_tech_count;
1566                 goto exit;
1567         }
1568
1569         rc = 0;
1570 exit:
1571         if (rc)
1572                 digital_poll_next_tech(ddev);
1573
1574         dev_kfree_skb(resp);
1575 }