]> git.karo-electronics.de Git - karo-tx-linux.git/blob - net/nfc/digital_dep.c
NFC: digital: Rework ACK PDU handling in initiator mode
[karo-tx-linux.git] / net / nfc / digital_dep.c
1 /*
2  * NFC Digital Protocol stack
3  * Copyright (c) 2013, Intel Corporation.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms and conditions of the GNU General Public License,
7  * version 2, as published by the Free Software Foundation.
8  *
9  * This program is distributed in the hope it will be useful, but WITHOUT
10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for
12  * more details.
13  *
14  */
15
16 #define pr_fmt(fmt) "digital: %s: " fmt, __func__
17
18 #include "digital.h"
19
20 #define DIGITAL_NFC_DEP_N_RETRY_NACK    2
21 #define DIGITAL_NFC_DEP_N_RETRY_ATN     2
22
23 #define DIGITAL_NFC_DEP_FRAME_DIR_OUT 0xD4
24 #define DIGITAL_NFC_DEP_FRAME_DIR_IN  0xD5
25
26 #define DIGITAL_NFC_DEP_NFCA_SOD_SB   0xF0
27
28 #define DIGITAL_CMD_ATR_REQ 0x00
29 #define DIGITAL_CMD_ATR_RES 0x01
30 #define DIGITAL_CMD_PSL_REQ 0x04
31 #define DIGITAL_CMD_PSL_RES 0x05
32 #define DIGITAL_CMD_DEP_REQ 0x06
33 #define DIGITAL_CMD_DEP_RES 0x07
34
35 #define DIGITAL_ATR_REQ_MIN_SIZE 16
36 #define DIGITAL_ATR_REQ_MAX_SIZE 64
37
38 #define DIGITAL_DID_MAX 14
39
40 #define DIGITAL_PAYLOAD_SIZE_MAX        254
41 #define DIGITAL_PAYLOAD_BITS_TO_PP(s)   (((s) & 0x3) << 4)
42 #define DIGITAL_PAYLOAD_PP_TO_BITS(s)   (((s) >> 4) & 0x3)
43 #define DIGITAL_PAYLOAD_BITS_TO_FSL(s)  ((s) & 0x3)
44 #define DIGITAL_PAYLOAD_FSL_TO_BITS(s)  ((s) & 0x3)
45
46 #define DIGITAL_GB_BIT  0x02
47
48 #define DIGITAL_NFC_DEP_REQ_RES_HEADROOM        2 /* SoD: [SB (NFC-A)] + LEN */
49 #define DIGITAL_NFC_DEP_REQ_RES_TAILROOM        2 /* EoD: 2-byte CRC */
50
51 #define DIGITAL_NFC_DEP_PFB_TYPE(pfb) ((pfb) & 0xE0)
52
53 #define DIGITAL_NFC_DEP_PFB_TIMEOUT_BIT 0x10
54 #define DIGITAL_NFC_DEP_PFB_MI_BIT      0x10
55 #define DIGITAL_NFC_DEP_PFB_NACK_BIT    0x10
56 #define DIGITAL_NFC_DEP_PFB_DID_BIT     0x04
57
58 #define DIGITAL_NFC_DEP_PFB_IS_TIMEOUT(pfb) \
59                                 ((pfb) & DIGITAL_NFC_DEP_PFB_TIMEOUT_BIT)
60 #define DIGITAL_NFC_DEP_MI_BIT_SET(pfb)  ((pfb) & DIGITAL_NFC_DEP_PFB_MI_BIT)
61 #define DIGITAL_NFC_DEP_NACK_BIT_SET(pfb) ((pfb) & DIGITAL_NFC_DEP_PFB_NACK_BIT)
62 #define DIGITAL_NFC_DEP_NAD_BIT_SET(pfb) ((pfb) & 0x08)
63 #define DIGITAL_NFC_DEP_DID_BIT_SET(pfb) ((pfb) & DIGITAL_NFC_DEP_PFB_DID_BIT)
64 #define DIGITAL_NFC_DEP_PFB_PNI(pfb)     ((pfb) & 0x03)
65
66 #define DIGITAL_NFC_DEP_PFB_I_PDU          0x00
67 #define DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU   0x40
68 #define DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU 0x80
69
70 struct digital_atr_req {
71         u8 dir;
72         u8 cmd;
73         u8 nfcid3[10];
74         u8 did;
75         u8 bs;
76         u8 br;
77         u8 pp;
78         u8 gb[0];
79 } __packed;
80
81 struct digital_atr_res {
82         u8 dir;
83         u8 cmd;
84         u8 nfcid3[10];
85         u8 did;
86         u8 bs;
87         u8 br;
88         u8 to;
89         u8 pp;
90         u8 gb[0];
91 } __packed;
92
93 struct digital_psl_req {
94         u8 dir;
95         u8 cmd;
96         u8 did;
97         u8 brs;
98         u8 fsl;
99 } __packed;
100
101 struct digital_psl_res {
102         u8 dir;
103         u8 cmd;
104         u8 did;
105 } __packed;
106
107 struct digital_dep_req_res {
108         u8 dir;
109         u8 cmd;
110         u8 pfb;
111 } __packed;
112
113 static void digital_in_recv_dep_res(struct nfc_digital_dev *ddev, void *arg,
114                                     struct sk_buff *resp);
115 static void digital_tg_recv_dep_req(struct nfc_digital_dev *ddev, void *arg,
116                                     struct sk_buff *resp);
117
118 static const u8 digital_payload_bits_map[4] = {
119         [0] = 64,
120         [1] = 128,
121         [2] = 192,
122         [3] = 254
123 };
124
125 static u8 digital_payload_bits_to_size(u8 payload_bits)
126 {
127         if (payload_bits >= ARRAY_SIZE(digital_payload_bits_map))
128                 return 0;
129
130         return digital_payload_bits_map[payload_bits];
131 }
132
133 static u8 digital_payload_size_to_bits(u8 payload_size)
134 {
135         int i;
136
137         for (i = 0; i < ARRAY_SIZE(digital_payload_bits_map); i++)
138                 if (digital_payload_bits_map[i] == payload_size)
139                         return i;
140
141         return 0xff;
142 }
143
144 static void digital_skb_push_dep_sod(struct nfc_digital_dev *ddev,
145                                      struct sk_buff *skb)
146 {
147         skb_push(skb, sizeof(u8));
148
149         skb->data[0] = skb->len;
150
151         if (ddev->curr_rf_tech == NFC_DIGITAL_RF_TECH_106A)
152                 *skb_push(skb, sizeof(u8)) = DIGITAL_NFC_DEP_NFCA_SOD_SB;
153 }
154
155 static int digital_skb_pull_dep_sod(struct nfc_digital_dev *ddev,
156                                     struct sk_buff *skb)
157 {
158         u8 size;
159
160         if (skb->len < 2)
161                 return -EIO;
162
163         if (ddev->curr_rf_tech == NFC_DIGITAL_RF_TECH_106A)
164                 skb_pull(skb, sizeof(u8));
165
166         size = skb->data[0];
167         if (size != skb->len)
168                 return -EIO;
169
170         skb_pull(skb, sizeof(u8));
171
172         return 0;
173 }
174
175 static struct sk_buff *
176 digital_send_dep_data_prep(struct nfc_digital_dev *ddev, struct sk_buff *skb,
177                            struct digital_dep_req_res *dep_req_res,
178                            struct digital_data_exch *data_exch)
179 {
180         struct sk_buff *new_skb;
181
182         if (skb->len > ddev->remote_payload_max) {
183                 dep_req_res->pfb |= DIGITAL_NFC_DEP_PFB_MI_BIT;
184
185                 new_skb = digital_skb_alloc(ddev, ddev->remote_payload_max);
186                 if (!new_skb) {
187                         kfree_skb(ddev->chaining_skb);
188                         ddev->chaining_skb = NULL;
189
190                         return ERR_PTR(-ENOMEM);
191                 }
192
193                 memcpy(skb_put(new_skb, ddev->remote_payload_max), skb->data,
194                        ddev->remote_payload_max);
195                 skb_pull(skb, ddev->remote_payload_max);
196
197                 ddev->chaining_skb = skb;
198                 ddev->data_exch = data_exch;
199         } else {
200                 ddev->chaining_skb = NULL;
201                 new_skb = skb;
202         }
203
204         return new_skb;
205 }
206
207 static struct sk_buff *
208 digital_recv_dep_data_gather(struct nfc_digital_dev *ddev, u8 pfb,
209                              struct sk_buff *resp,
210                              int (*send_ack)(struct nfc_digital_dev *ddev,
211                                              struct digital_data_exch
212                                                              *data_exch),
213                              struct digital_data_exch *data_exch)
214 {
215         struct sk_buff *new_skb;
216         int rc;
217
218         if (DIGITAL_NFC_DEP_MI_BIT_SET(pfb) && (!ddev->chaining_skb)) {
219                 ddev->chaining_skb =
220                         nfc_alloc_recv_skb(8 * ddev->local_payload_max,
221                                            GFP_KERNEL);
222                 if (!ddev->chaining_skb) {
223                         rc = -ENOMEM;
224                         goto error;
225                 }
226         }
227
228         if (ddev->chaining_skb) {
229                 if (resp->len > skb_tailroom(ddev->chaining_skb)) {
230                         new_skb = skb_copy_expand(ddev->chaining_skb,
231                                                   skb_headroom(
232                                                           ddev->chaining_skb),
233                                                   8 * ddev->local_payload_max,
234                                                   GFP_KERNEL);
235                         if (!new_skb) {
236                                 rc = -ENOMEM;
237                                 goto error;
238                         }
239
240                         kfree_skb(ddev->chaining_skb);
241                         ddev->chaining_skb = new_skb;
242                 }
243
244                 memcpy(skb_put(ddev->chaining_skb, resp->len), resp->data,
245                        resp->len);
246
247                 kfree_skb(resp);
248                 resp = NULL;
249
250                 if (DIGITAL_NFC_DEP_MI_BIT_SET(pfb)) {
251                         rc = send_ack(ddev, data_exch);
252                         if (rc)
253                                 goto error;
254
255                         return NULL;
256                 }
257
258                 resp = ddev->chaining_skb;
259                 ddev->chaining_skb = NULL;
260         }
261
262         return resp;
263
264 error:
265         kfree_skb(resp);
266
267         kfree_skb(ddev->chaining_skb);
268         ddev->chaining_skb = NULL;
269
270         return ERR_PTR(rc);
271 }
272
273 static void digital_in_recv_psl_res(struct nfc_digital_dev *ddev, void *arg,
274                                     struct sk_buff *resp)
275 {
276         struct nfc_target *target = arg;
277         struct digital_psl_res *psl_res;
278         int rc;
279
280         if (IS_ERR(resp)) {
281                 rc = PTR_ERR(resp);
282                 resp = NULL;
283                 goto exit;
284         }
285
286         rc = ddev->skb_check_crc(resp);
287         if (rc) {
288                 PROTOCOL_ERR("14.4.1.6");
289                 goto exit;
290         }
291
292         rc = digital_skb_pull_dep_sod(ddev, resp);
293         if (rc) {
294                 PROTOCOL_ERR("14.4.1.2");
295                 goto exit;
296         }
297
298         psl_res = (struct digital_psl_res *)resp->data;
299
300         if ((resp->len != sizeof(*psl_res)) ||
301             (psl_res->dir != DIGITAL_NFC_DEP_FRAME_DIR_IN) ||
302             (psl_res->cmd != DIGITAL_CMD_PSL_RES)) {
303                 rc = -EIO;
304                 goto exit;
305         }
306
307         rc = digital_in_configure_hw(ddev, NFC_DIGITAL_CONFIG_RF_TECH,
308                                      NFC_DIGITAL_RF_TECH_424F);
309         if (rc)
310                 goto exit;
311
312         rc = digital_in_configure_hw(ddev, NFC_DIGITAL_CONFIG_FRAMING,
313                                      NFC_DIGITAL_FRAMING_NFCF_NFC_DEP);
314         if (rc)
315                 goto exit;
316
317         if (!DIGITAL_DRV_CAPS_IN_CRC(ddev) &&
318             (ddev->curr_rf_tech == NFC_DIGITAL_RF_TECH_106A)) {
319                 ddev->skb_add_crc = digital_skb_add_crc_f;
320                 ddev->skb_check_crc = digital_skb_check_crc_f;
321         }
322
323         ddev->curr_rf_tech = NFC_DIGITAL_RF_TECH_424F;
324
325         nfc_dep_link_is_up(ddev->nfc_dev, target->idx, NFC_COMM_ACTIVE,
326                            NFC_RF_INITIATOR);
327
328         ddev->curr_nfc_dep_pni = 0;
329
330 exit:
331         dev_kfree_skb(resp);
332
333         if (rc)
334                 ddev->curr_protocol = 0;
335 }
336
337 static int digital_in_send_psl_req(struct nfc_digital_dev *ddev,
338                                    struct nfc_target *target)
339 {
340         struct sk_buff *skb;
341         struct digital_psl_req *psl_req;
342         int rc;
343         u8 payload_size, payload_bits;
344
345         skb = digital_skb_alloc(ddev, sizeof(*psl_req));
346         if (!skb)
347                 return -ENOMEM;
348
349         skb_put(skb, sizeof(*psl_req));
350
351         psl_req = (struct digital_psl_req *)skb->data;
352
353         psl_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
354         psl_req->cmd = DIGITAL_CMD_PSL_REQ;
355         psl_req->did = 0;
356         psl_req->brs = (0x2 << 3) | 0x2; /* 424F both directions */
357
358         payload_size = min(ddev->local_payload_max, ddev->remote_payload_max);
359         payload_bits = digital_payload_size_to_bits(payload_size);
360         psl_req->fsl = DIGITAL_PAYLOAD_BITS_TO_FSL(payload_bits);
361
362         ddev->local_payload_max = payload_size;
363         ddev->remote_payload_max = payload_size;
364
365         digital_skb_push_dep_sod(ddev, skb);
366
367         ddev->skb_add_crc(skb);
368
369         rc = digital_in_send_cmd(ddev, skb, 500, digital_in_recv_psl_res,
370                                  target);
371         if (rc)
372                 kfree_skb(skb);
373
374         return rc;
375 }
376
377 static void digital_in_recv_atr_res(struct nfc_digital_dev *ddev, void *arg,
378                                  struct sk_buff *resp)
379 {
380         struct nfc_target *target = arg;
381         struct digital_atr_res *atr_res;
382         u8 gb_len, payload_bits;
383         int rc;
384
385         if (IS_ERR(resp)) {
386                 rc = PTR_ERR(resp);
387                 resp = NULL;
388                 goto exit;
389         }
390
391         rc = ddev->skb_check_crc(resp);
392         if (rc) {
393                 PROTOCOL_ERR("14.4.1.6");
394                 goto exit;
395         }
396
397         rc = digital_skb_pull_dep_sod(ddev, resp);
398         if (rc) {
399                 PROTOCOL_ERR("14.4.1.2");
400                 goto exit;
401         }
402
403         if (resp->len < sizeof(struct digital_atr_res)) {
404                 rc = -EIO;
405                 goto exit;
406         }
407
408         gb_len = resp->len - sizeof(struct digital_atr_res);
409
410         atr_res = (struct digital_atr_res *)resp->data;
411
412         payload_bits = DIGITAL_PAYLOAD_PP_TO_BITS(atr_res->pp);
413         ddev->remote_payload_max = digital_payload_bits_to_size(payload_bits);
414
415         if (!ddev->remote_payload_max) {
416                 rc = -EINVAL;
417                 goto exit;
418         }
419
420         rc = nfc_set_remote_general_bytes(ddev->nfc_dev, atr_res->gb, gb_len);
421         if (rc)
422                 goto exit;
423
424         if ((ddev->protocols & NFC_PROTO_FELICA_MASK) &&
425             (ddev->curr_rf_tech != NFC_DIGITAL_RF_TECH_424F)) {
426                 rc = digital_in_send_psl_req(ddev, target);
427                 if (!rc)
428                         goto exit;
429         }
430
431         rc = nfc_dep_link_is_up(ddev->nfc_dev, target->idx, NFC_COMM_ACTIVE,
432                                 NFC_RF_INITIATOR);
433
434         ddev->curr_nfc_dep_pni = 0;
435
436 exit:
437         dev_kfree_skb(resp);
438
439         if (rc)
440                 ddev->curr_protocol = 0;
441 }
442
443 int digital_in_send_atr_req(struct nfc_digital_dev *ddev,
444                             struct nfc_target *target, __u8 comm_mode, __u8 *gb,
445                             size_t gb_len)
446 {
447         struct sk_buff *skb;
448         struct digital_atr_req *atr_req;
449         uint size;
450         int rc;
451         u8 payload_bits;
452
453         size = DIGITAL_ATR_REQ_MIN_SIZE + gb_len;
454
455         if (size > DIGITAL_ATR_REQ_MAX_SIZE) {
456                 PROTOCOL_ERR("14.6.1.1");
457                 return -EINVAL;
458         }
459
460         skb = digital_skb_alloc(ddev, size);
461         if (!skb)
462                 return -ENOMEM;
463
464         skb_put(skb, sizeof(struct digital_atr_req));
465
466         atr_req = (struct digital_atr_req *)skb->data;
467         memset(atr_req, 0, sizeof(struct digital_atr_req));
468
469         atr_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
470         atr_req->cmd = DIGITAL_CMD_ATR_REQ;
471         if (target->nfcid2_len)
472                 memcpy(atr_req->nfcid3, target->nfcid2, NFC_NFCID2_MAXSIZE);
473         else
474                 get_random_bytes(atr_req->nfcid3, NFC_NFCID3_MAXSIZE);
475
476         atr_req->did = 0;
477         atr_req->bs = 0;
478         atr_req->br = 0;
479
480         ddev->local_payload_max = DIGITAL_PAYLOAD_SIZE_MAX;
481         payload_bits = digital_payload_size_to_bits(ddev->local_payload_max);
482         atr_req->pp = DIGITAL_PAYLOAD_BITS_TO_PP(payload_bits);
483
484         if (gb_len) {
485                 atr_req->pp |= DIGITAL_GB_BIT;
486                 memcpy(skb_put(skb, gb_len), gb, gb_len);
487         }
488
489         digital_skb_push_dep_sod(ddev, skb);
490
491         ddev->skb_add_crc(skb);
492
493         rc = digital_in_send_cmd(ddev, skb, 500, digital_in_recv_atr_res,
494                                  target);
495         if (rc)
496                 kfree_skb(skb);
497
498         return rc;
499 }
500
501 static int digital_in_send_ack(struct nfc_digital_dev *ddev,
502                                struct digital_data_exch *data_exch)
503 {
504         struct digital_dep_req_res *dep_req;
505         struct sk_buff *skb;
506         int rc;
507
508         skb = digital_skb_alloc(ddev, 1);
509         if (!skb)
510                 return -ENOMEM;
511
512         skb_push(skb, sizeof(struct digital_dep_req_res));
513
514         dep_req = (struct digital_dep_req_res *)skb->data;
515
516         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
517         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
518         dep_req->pfb = DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU |
519                        ddev->curr_nfc_dep_pni;
520
521         digital_skb_push_dep_sod(ddev, skb);
522
523         ddev->skb_add_crc(skb);
524
525         ddev->saved_skb = pskb_copy(skb, GFP_KERNEL);
526
527         rc = digital_in_send_cmd(ddev, skb, 1500, digital_in_recv_dep_res,
528                                  data_exch);
529         if (rc) {
530                 kfree_skb(skb);
531                 kfree_skb(ddev->saved_skb);
532                 ddev->saved_skb = NULL;
533         }
534
535         return rc;
536 }
537
538 static int digital_in_send_nack(struct nfc_digital_dev *ddev,
539                                 struct digital_data_exch *data_exch)
540 {
541         struct digital_dep_req_res *dep_req;
542         struct sk_buff *skb;
543         int rc;
544
545         skb = digital_skb_alloc(ddev, 1);
546         if (!skb)
547                 return -ENOMEM;
548
549         skb_push(skb, sizeof(struct digital_dep_req_res));
550
551         dep_req = (struct digital_dep_req_res *)skb->data;
552
553         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
554         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
555         dep_req->pfb = DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU |
556                        DIGITAL_NFC_DEP_PFB_NACK_BIT | ddev->curr_nfc_dep_pni;
557
558         digital_skb_push_dep_sod(ddev, skb);
559
560         ddev->skb_add_crc(skb);
561
562         rc = digital_in_send_cmd(ddev, skb, 1500, digital_in_recv_dep_res,
563                                  data_exch);
564         if (rc)
565                 kfree_skb(skb);
566
567         return rc;
568 }
569
570 static int digital_in_send_atn(struct nfc_digital_dev *ddev,
571                                struct digital_data_exch *data_exch)
572 {
573         struct digital_dep_req_res *dep_req;
574         struct sk_buff *skb;
575         int rc;
576
577         skb = digital_skb_alloc(ddev, 1);
578         if (!skb)
579                 return -ENOMEM;
580
581         skb_push(skb, sizeof(struct digital_dep_req_res));
582
583         dep_req = (struct digital_dep_req_res *)skb->data;
584
585         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
586         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
587         dep_req->pfb = DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU;
588
589         digital_skb_push_dep_sod(ddev, skb);
590
591         ddev->skb_add_crc(skb);
592
593         rc = digital_in_send_cmd(ddev, skb, 1500, digital_in_recv_dep_res,
594                                  data_exch);
595         if (rc)
596                 kfree_skb(skb);
597
598         return rc;
599 }
600
601 static int digital_in_send_rtox(struct nfc_digital_dev *ddev,
602                                 struct digital_data_exch *data_exch, u8 rtox)
603 {
604         struct digital_dep_req_res *dep_req;
605         struct sk_buff *skb;
606         int rc;
607
608         skb = digital_skb_alloc(ddev, 1);
609         if (!skb)
610                 return -ENOMEM;
611
612         *skb_put(skb, 1) = rtox;
613
614         skb_push(skb, sizeof(struct digital_dep_req_res));
615
616         dep_req = (struct digital_dep_req_res *)skb->data;
617
618         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
619         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
620         dep_req->pfb = DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU |
621                        DIGITAL_NFC_DEP_PFB_TIMEOUT_BIT;
622
623         digital_skb_push_dep_sod(ddev, skb);
624
625         ddev->skb_add_crc(skb);
626
627         rc = digital_in_send_cmd(ddev, skb, 1500, digital_in_recv_dep_res,
628                                  data_exch);
629         if (rc)
630                 kfree_skb(skb);
631
632         return rc;
633 }
634
635 static int digital_in_send_saved_skb(struct nfc_digital_dev *ddev,
636                                      struct digital_data_exch *data_exch)
637 {
638         int rc;
639
640         if (!ddev->saved_skb)
641                 return -EINVAL;
642
643         skb_get(ddev->saved_skb);
644
645         rc = digital_in_send_cmd(ddev, ddev->saved_skb, 1500,
646                                  digital_in_recv_dep_res, data_exch);
647         if (rc)
648                 kfree_skb(ddev->saved_skb);
649
650         return rc;
651 }
652
653 static void digital_in_recv_dep_res(struct nfc_digital_dev *ddev, void *arg,
654                                     struct sk_buff *resp)
655 {
656         struct digital_data_exch *data_exch = arg;
657         struct digital_dep_req_res *dep_res;
658         u8 pfb;
659         uint size;
660         int rc;
661
662         if (IS_ERR(resp)) {
663                 rc = PTR_ERR(resp);
664                 resp = NULL;
665
666                 if ((rc == -EIO || (rc == -ETIMEDOUT && ddev->nack_count)) &&
667                     (ddev->nack_count++ < DIGITAL_NFC_DEP_N_RETRY_NACK)) {
668                         ddev->atn_count = 0;
669
670                         rc = digital_in_send_nack(ddev, data_exch);
671                         if (rc)
672                                 goto error;
673
674                         return;
675                 } else if ((rc == -ETIMEDOUT) &&
676                            (ddev->atn_count++ < DIGITAL_NFC_DEP_N_RETRY_ATN)) {
677                         ddev->nack_count = 0;
678
679                         rc = digital_in_send_atn(ddev, data_exch);
680                         if (rc)
681                                 goto error;
682
683                         return;
684                 }
685
686                 goto exit;
687         }
688
689         rc = digital_skb_pull_dep_sod(ddev, resp);
690         if (rc) {
691                 PROTOCOL_ERR("14.4.1.2");
692                 goto exit;
693         }
694
695         rc = ddev->skb_check_crc(resp);
696         if (rc) {
697                 if ((resp->len >= 4) &&
698                     (ddev->nack_count++ < DIGITAL_NFC_DEP_N_RETRY_NACK)) {
699                         ddev->atn_count = 0;
700
701                         rc = digital_in_send_nack(ddev, data_exch);
702                         if (rc)
703                                 goto error;
704
705                         kfree_skb(resp);
706
707                         return;
708                 }
709
710                 PROTOCOL_ERR("14.4.1.6");
711                 goto error;
712         }
713
714         ddev->atn_count = 0;
715         ddev->nack_count = 0;
716
717         if (resp->len > ddev->local_payload_max) {
718                 rc = -EMSGSIZE;
719                 goto exit;
720         }
721
722         size = sizeof(struct digital_dep_req_res);
723         dep_res = (struct digital_dep_req_res *)resp->data;
724
725         if (resp->len < size || dep_res->dir != DIGITAL_NFC_DEP_FRAME_DIR_IN ||
726             dep_res->cmd != DIGITAL_CMD_DEP_RES) {
727                 rc = -EIO;
728                 goto error;
729         }
730
731         pfb = dep_res->pfb;
732
733         if (DIGITAL_NFC_DEP_DID_BIT_SET(pfb)) {
734                 PROTOCOL_ERR("14.8.2.1");
735                 rc = -EIO;
736                 goto error;
737         }
738
739         if (DIGITAL_NFC_DEP_NAD_BIT_SET(pfb)) {
740                 rc = -EIO;
741                 goto exit;
742         }
743
744         if (size > resp->len) {
745                 rc = -EIO;
746                 goto error;
747         }
748
749         skb_pull(resp, size);
750
751         switch (DIGITAL_NFC_DEP_PFB_TYPE(pfb)) {
752         case DIGITAL_NFC_DEP_PFB_I_PDU:
753                 if (DIGITAL_NFC_DEP_PFB_PNI(pfb) != ddev->curr_nfc_dep_pni) {
754                         PROTOCOL_ERR("14.12.3.3");
755                         rc = -EIO;
756                         goto error;
757                 }
758
759                 ddev->curr_nfc_dep_pni =
760                         DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni + 1);
761
762                 kfree_skb(ddev->saved_skb);
763                 ddev->saved_skb = NULL;
764
765                 resp = digital_recv_dep_data_gather(ddev, pfb, resp,
766                                                     digital_in_send_ack,
767                                                     data_exch);
768                 if (IS_ERR(resp)) {
769                         rc = PTR_ERR(resp);
770                         resp = NULL;
771                         goto error;
772                 }
773
774                 /* If resp is NULL then we're still chaining so return and
775                  * wait for the next part of the PDU.  Else, the PDU is
776                  * complete so pass it up.
777                  */
778                 if (!resp)
779                         return;
780
781                 rc = 0;
782                 break;
783
784         case DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU:
785                 if (DIGITAL_NFC_DEP_NACK_BIT_SET(pfb)) {
786                         PROTOCOL_ERR("14.12.4.5");
787                         rc = -EIO;
788                         goto exit;
789                 }
790
791                 if (DIGITAL_NFC_DEP_PFB_PNI(pfb) != ddev->curr_nfc_dep_pni) {
792                         PROTOCOL_ERR("14.12.3.3");
793                         rc = -EIO;
794                         goto exit;
795                 }
796
797                 ddev->curr_nfc_dep_pni =
798                         DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni + 1);
799
800                 if (!ddev->chaining_skb) {
801                         PROTOCOL_ERR("14.12.4.3");
802                         rc = -EIO;
803                         goto exit;
804                 }
805
806                 /* The initiator has received a valid ACK. Free the last sent
807                  * PDU and keep on sending chained skb.
808                  */
809                 kfree_skb(ddev->saved_skb);
810                 ddev->saved_skb = NULL;
811
812                 rc = digital_in_send_dep_req(ddev, NULL,
813                                              ddev->chaining_skb,
814                                              ddev->data_exch);
815                 if (rc)
816                         goto error;
817
818                 goto free_resp;
819
820         case DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU:
821                 if (!DIGITAL_NFC_DEP_PFB_IS_TIMEOUT(pfb)) { /* ATN */
822                         rc = digital_in_send_saved_skb(ddev, data_exch);
823                         if (rc)
824                                 goto error;
825
826                         return;
827                 }
828
829                 rc = digital_in_send_rtox(ddev, data_exch, resp->data[0]);
830                 if (rc)
831                         goto error;
832
833                 kfree_skb(resp);
834                 return;
835         }
836
837 exit:
838         data_exch->cb(data_exch->cb_context, resp, rc);
839
840 error:
841         kfree(data_exch);
842
843         kfree_skb(ddev->chaining_skb);
844         ddev->chaining_skb = NULL;
845
846         kfree_skb(ddev->saved_skb);
847         ddev->saved_skb = NULL;
848
849         if (rc)
850                 kfree_skb(resp);
851
852         return;
853
854 free_resp:
855         dev_kfree_skb(resp);
856 }
857
858 int digital_in_send_dep_req(struct nfc_digital_dev *ddev,
859                             struct nfc_target *target, struct sk_buff *skb,
860                             struct digital_data_exch *data_exch)
861 {
862         struct digital_dep_req_res *dep_req;
863         struct sk_buff *chaining_skb, *tmp_skb;
864         int rc;
865
866         skb_push(skb, sizeof(struct digital_dep_req_res));
867
868         dep_req = (struct digital_dep_req_res *)skb->data;
869
870         dep_req->dir = DIGITAL_NFC_DEP_FRAME_DIR_OUT;
871         dep_req->cmd = DIGITAL_CMD_DEP_REQ;
872         dep_req->pfb = ddev->curr_nfc_dep_pni;
873
874         ddev->atn_count = 0;
875         ddev->nack_count = 0;
876
877         chaining_skb = ddev->chaining_skb;
878
879         tmp_skb = digital_send_dep_data_prep(ddev, skb, dep_req, data_exch);
880         if (IS_ERR(tmp_skb))
881                 return PTR_ERR(tmp_skb);
882
883         digital_skb_push_dep_sod(ddev, tmp_skb);
884
885         ddev->skb_add_crc(tmp_skb);
886
887         ddev->saved_skb = pskb_copy(tmp_skb, GFP_KERNEL);
888
889         rc = digital_in_send_cmd(ddev, tmp_skb, 1500, digital_in_recv_dep_res,
890                                  data_exch);
891         if (rc) {
892                 if (tmp_skb != skb)
893                         kfree_skb(tmp_skb);
894
895                 kfree_skb(chaining_skb);
896                 ddev->chaining_skb = NULL;
897
898                 kfree_skb(ddev->saved_skb);
899                 ddev->saved_skb = NULL;
900         }
901
902         return rc;
903 }
904
905 static void digital_tg_set_rf_tech(struct nfc_digital_dev *ddev, u8 rf_tech)
906 {
907         ddev->curr_rf_tech = rf_tech;
908
909         ddev->skb_add_crc = digital_skb_add_crc_none;
910         ddev->skb_check_crc = digital_skb_check_crc_none;
911
912         if (DIGITAL_DRV_CAPS_TG_CRC(ddev))
913                 return;
914
915         switch (ddev->curr_rf_tech) {
916         case NFC_DIGITAL_RF_TECH_106A:
917                 ddev->skb_add_crc = digital_skb_add_crc_a;
918                 ddev->skb_check_crc = digital_skb_check_crc_a;
919                 break;
920
921         case NFC_DIGITAL_RF_TECH_212F:
922         case NFC_DIGITAL_RF_TECH_424F:
923                 ddev->skb_add_crc = digital_skb_add_crc_f;
924                 ddev->skb_check_crc = digital_skb_check_crc_f;
925                 break;
926
927         default:
928                 break;
929         }
930 }
931
932 static int digital_tg_send_ack(struct nfc_digital_dev *ddev,
933                                struct digital_data_exch *data_exch)
934 {
935         struct digital_dep_req_res *dep_res;
936         struct sk_buff *skb;
937         int rc;
938
939         skb = digital_skb_alloc(ddev, 1);
940         if (!skb)
941                 return -ENOMEM;
942
943         skb_push(skb, sizeof(struct digital_dep_req_res));
944
945         dep_res = (struct digital_dep_req_res *)skb->data;
946
947         dep_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
948         dep_res->cmd = DIGITAL_CMD_DEP_RES;
949         dep_res->pfb = DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU |
950                        ddev->curr_nfc_dep_pni;
951
952         if (ddev->did) {
953                 dep_res->pfb |= DIGITAL_NFC_DEP_PFB_DID_BIT;
954
955                 memcpy(skb_put(skb, sizeof(ddev->did)), &ddev->did,
956                        sizeof(ddev->did));
957         }
958
959         ddev->curr_nfc_dep_pni =
960                 DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni + 1);
961
962         digital_skb_push_dep_sod(ddev, skb);
963
964         ddev->skb_add_crc(skb);
965
966         ddev->saved_skb = pskb_copy(skb, GFP_KERNEL);
967
968         rc = digital_tg_send_cmd(ddev, skb, 1500, digital_tg_recv_dep_req,
969                                  data_exch);
970         if (rc) {
971                 kfree_skb(skb);
972                 kfree_skb(ddev->saved_skb);
973                 ddev->saved_skb = NULL;
974         }
975
976         return rc;
977 }
978
979 static int digital_tg_send_atn(struct nfc_digital_dev *ddev)
980 {
981         struct digital_dep_req_res *dep_res;
982         struct sk_buff *skb;
983         int rc;
984
985         skb = digital_skb_alloc(ddev, 1);
986         if (!skb)
987                 return -ENOMEM;
988
989         skb_push(skb, sizeof(struct digital_dep_req_res));
990
991         dep_res = (struct digital_dep_req_res *)skb->data;
992
993         dep_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
994         dep_res->cmd = DIGITAL_CMD_DEP_RES;
995         dep_res->pfb = DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU;
996
997         if (ddev->did) {
998                 dep_res->pfb |= DIGITAL_NFC_DEP_PFB_DID_BIT;
999
1000                 memcpy(skb_put(skb, sizeof(ddev->did)), &ddev->did,
1001                        sizeof(ddev->did));
1002         }
1003
1004         digital_skb_push_dep_sod(ddev, skb);
1005
1006         ddev->skb_add_crc(skb);
1007
1008         rc = digital_tg_send_cmd(ddev, skb, 1500, digital_tg_recv_dep_req,
1009                                  NULL);
1010         if (rc)
1011                 kfree_skb(skb);
1012
1013         return rc;
1014 }
1015
1016 static int digital_tg_send_saved_skb(struct nfc_digital_dev *ddev)
1017 {
1018         int rc;
1019
1020         if (!ddev->saved_skb)
1021                 return -EINVAL;
1022
1023         skb_get(ddev->saved_skb);
1024
1025         rc = digital_tg_send_cmd(ddev, ddev->saved_skb, 1500,
1026                                  digital_tg_recv_dep_req, NULL);
1027         if (rc)
1028                 kfree_skb(ddev->saved_skb);
1029
1030         return rc;
1031 }
1032
1033 static void digital_tg_recv_dep_req(struct nfc_digital_dev *ddev, void *arg,
1034                                     struct sk_buff *resp)
1035 {
1036         int rc;
1037         struct digital_dep_req_res *dep_req;
1038         u8 pfb;
1039         size_t size;
1040
1041         if (IS_ERR(resp)) {
1042                 rc = PTR_ERR(resp);
1043                 resp = NULL;
1044                 goto exit;
1045         }
1046
1047         rc = ddev->skb_check_crc(resp);
1048         if (rc) {
1049                 PROTOCOL_ERR("14.4.1.6");
1050                 goto exit;
1051         }
1052
1053         rc = digital_skb_pull_dep_sod(ddev, resp);
1054         if (rc) {
1055                 PROTOCOL_ERR("14.4.1.2");
1056                 goto exit;
1057         }
1058
1059         if (resp->len > ddev->local_payload_max) {
1060                 rc = -EMSGSIZE;
1061                 goto exit;
1062         }
1063
1064         size = sizeof(struct digital_dep_req_res);
1065         dep_req = (struct digital_dep_req_res *)resp->data;
1066
1067         if (resp->len < size || dep_req->dir != DIGITAL_NFC_DEP_FRAME_DIR_OUT ||
1068             dep_req->cmd != DIGITAL_CMD_DEP_REQ) {
1069                 rc = -EIO;
1070                 goto exit;
1071         }
1072
1073         pfb = dep_req->pfb;
1074
1075         if (DIGITAL_NFC_DEP_DID_BIT_SET(pfb)) {
1076                 if (ddev->did && (ddev->did == resp->data[3])) {
1077                         size++;
1078                 } else {
1079                         rc = -EIO;
1080                         goto exit;
1081                 }
1082         } else if (ddev->did) {
1083                 rc = -EIO;
1084                 goto exit;
1085         }
1086
1087         if (DIGITAL_NFC_DEP_NAD_BIT_SET(pfb)) {
1088                 rc = -EIO;
1089                 goto exit;
1090         }
1091
1092         if (size > resp->len) {
1093                 rc = -EIO;
1094                 goto exit;
1095         }
1096
1097         skb_pull(resp, size);
1098
1099         switch (DIGITAL_NFC_DEP_PFB_TYPE(pfb)) {
1100         case DIGITAL_NFC_DEP_PFB_I_PDU:
1101                 pr_debug("DIGITAL_NFC_DEP_PFB_I_PDU\n");
1102
1103                 if (ddev->atn_count) {
1104                         /* The target has received (and replied to) at least one
1105                          * ATN DEP_REQ.
1106                          */
1107                         ddev->atn_count = 0;
1108
1109                         /* pni of resp PDU equal to the target current pni - 1
1110                          * means resp is the previous DEP_REQ PDU received from
1111                          * the initiator so the target replies with saved_skb
1112                          * which is the previous DEP_RES saved in
1113                          * digital_tg_send_dep_res().
1114                          */
1115                         if (DIGITAL_NFC_DEP_PFB_PNI(pfb) ==
1116                           DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni - 1)) {
1117                                 rc = digital_tg_send_saved_skb(ddev);
1118                                 if (rc)
1119                                         goto exit;
1120
1121                                 goto free_resp;
1122                         }
1123
1124                         /* atn_count > 0 and PDU pni != curr_nfc_dep_pni - 1
1125                          * means the target probably did not received the last
1126                          * DEP_REQ PDU sent by the initiator. The target
1127                          * fallbacks to normal processing then.
1128                          */
1129                 }
1130
1131                 if (DIGITAL_NFC_DEP_PFB_PNI(pfb) != ddev->curr_nfc_dep_pni) {
1132                         PROTOCOL_ERR("14.12.3.4");
1133                         rc = -EIO;
1134                         goto exit;
1135                 }
1136
1137                 kfree_skb(ddev->saved_skb);
1138                 ddev->saved_skb = NULL;
1139
1140                 resp = digital_recv_dep_data_gather(ddev, pfb, resp,
1141                                                     digital_tg_send_ack, NULL);
1142                 if (IS_ERR(resp)) {
1143                         rc = PTR_ERR(resp);
1144                         resp = NULL;
1145                         goto exit;
1146                 }
1147
1148                 /* If resp is NULL then we're still chaining so return and
1149                  * wait for the next part of the PDU.  Else, the PDU is
1150                  * complete so pass it up.
1151                  */
1152                 if (!resp)
1153                         return;
1154
1155                 rc = 0;
1156                 break;
1157         case DIGITAL_NFC_DEP_PFB_ACK_NACK_PDU:
1158                 if (DIGITAL_NFC_DEP_NACK_BIT_SET(pfb)) { /* NACK */
1159                         if (DIGITAL_NFC_DEP_PFB_PNI(pfb + 1) !=
1160                                                 ddev->curr_nfc_dep_pni) {
1161                                 rc = -EIO;
1162                                 goto exit;
1163                         }
1164
1165                         ddev->atn_count = 0;
1166
1167                         rc = digital_tg_send_saved_skb(ddev);
1168                         if (rc)
1169                                 goto exit;
1170
1171                         goto free_resp;
1172                 }
1173
1174                 /* ACK */
1175                 if (ddev->atn_count) {
1176                         /* The target has previously recevied one or more ATN
1177                          * PDUs.
1178                          */
1179                         ddev->atn_count = 0;
1180
1181                         /* If the ACK PNI is equal to the target PNI - 1 means
1182                          * that the initiator did not receive the previous PDU
1183                          * sent by the target so re-send it.
1184                          */
1185                         if (DIGITAL_NFC_DEP_PFB_PNI(pfb + 1) ==
1186                                                 ddev->curr_nfc_dep_pni) {
1187                                 rc = digital_tg_send_saved_skb(ddev);
1188                                 if (rc)
1189                                         goto exit;
1190
1191                                 goto free_resp;
1192                         }
1193
1194                         /* Otherwise, the target did not receive the previous
1195                          * ACK PDU from the initiator. Fallback to normal
1196                          * processing of chained PDU then.
1197                          */
1198                 }
1199
1200                 /* Keep on sending chained PDU */
1201                 if (!ddev->chaining_skb ||
1202                     DIGITAL_NFC_DEP_PFB_PNI(pfb) !=
1203                                         ddev->curr_nfc_dep_pni) {
1204                         rc = -EIO;
1205                         goto exit;
1206                 }
1207
1208                 kfree_skb(ddev->saved_skb);
1209                 ddev->saved_skb = NULL;
1210
1211                 rc = digital_tg_send_dep_res(ddev, ddev->chaining_skb);
1212                 if (rc)
1213                         goto exit;
1214
1215                 goto free_resp;
1216         case DIGITAL_NFC_DEP_PFB_SUPERVISOR_PDU:
1217                 if (DIGITAL_NFC_DEP_PFB_IS_TIMEOUT(pfb)) {
1218                         rc = -EINVAL;
1219                         goto exit;
1220                 }
1221
1222                 rc = digital_tg_send_atn(ddev);
1223                 if (rc)
1224                         goto exit;
1225
1226                 ddev->atn_count++;
1227
1228                 kfree_skb(resp);
1229                 return;
1230         }
1231
1232         rc = nfc_tm_data_received(ddev->nfc_dev, resp);
1233
1234 exit:
1235         kfree_skb(ddev->chaining_skb);
1236         ddev->chaining_skb = NULL;
1237
1238         ddev->atn_count = 0;
1239
1240         kfree_skb(ddev->saved_skb);
1241         ddev->saved_skb = NULL;
1242
1243         if (rc)
1244                 kfree_skb(resp);
1245
1246         return;
1247
1248 free_resp:
1249         dev_kfree_skb(resp);
1250 }
1251
1252 int digital_tg_send_dep_res(struct nfc_digital_dev *ddev, struct sk_buff *skb)
1253 {
1254         struct digital_dep_req_res *dep_res;
1255         struct sk_buff *chaining_skb, *tmp_skb;
1256         int rc;
1257
1258         skb_push(skb, sizeof(struct digital_dep_req_res));
1259
1260         dep_res = (struct digital_dep_req_res *)skb->data;
1261
1262         dep_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
1263         dep_res->cmd = DIGITAL_CMD_DEP_RES;
1264         dep_res->pfb = ddev->curr_nfc_dep_pni;
1265
1266         if (ddev->did) {
1267                 dep_res->pfb |= DIGITAL_NFC_DEP_PFB_DID_BIT;
1268
1269                 memcpy(skb_put(skb, sizeof(ddev->did)), &ddev->did,
1270                        sizeof(ddev->did));
1271         }
1272
1273         ddev->curr_nfc_dep_pni =
1274                 DIGITAL_NFC_DEP_PFB_PNI(ddev->curr_nfc_dep_pni + 1);
1275
1276         chaining_skb = ddev->chaining_skb;
1277
1278         tmp_skb = digital_send_dep_data_prep(ddev, skb, dep_res, NULL);
1279         if (IS_ERR(tmp_skb))
1280                 return PTR_ERR(tmp_skb);
1281
1282         digital_skb_push_dep_sod(ddev, tmp_skb);
1283
1284         ddev->skb_add_crc(tmp_skb);
1285
1286         ddev->saved_skb = pskb_copy(tmp_skb, GFP_KERNEL);
1287
1288         rc = digital_tg_send_cmd(ddev, tmp_skb, 1500, digital_tg_recv_dep_req,
1289                                  NULL);
1290         if (rc) {
1291                 if (tmp_skb != skb)
1292                         kfree_skb(tmp_skb);
1293
1294                 kfree_skb(chaining_skb);
1295                 ddev->chaining_skb = NULL;
1296
1297                 kfree_skb(ddev->saved_skb);
1298                 ddev->saved_skb = NULL;
1299         }
1300
1301         return rc;
1302 }
1303
1304 static void digital_tg_send_psl_res_complete(struct nfc_digital_dev *ddev,
1305                                              void *arg, struct sk_buff *resp)
1306 {
1307         u8 rf_tech = (unsigned long)arg;
1308
1309         if (IS_ERR(resp))
1310                 return;
1311
1312         digital_tg_set_rf_tech(ddev, rf_tech);
1313
1314         digital_tg_configure_hw(ddev, NFC_DIGITAL_CONFIG_RF_TECH, rf_tech);
1315
1316         digital_tg_listen(ddev, 1500, digital_tg_recv_dep_req, NULL);
1317
1318         dev_kfree_skb(resp);
1319 }
1320
1321 static int digital_tg_send_psl_res(struct nfc_digital_dev *ddev, u8 did,
1322                                    u8 rf_tech)
1323 {
1324         struct digital_psl_res *psl_res;
1325         struct sk_buff *skb;
1326         int rc;
1327
1328         skb = digital_skb_alloc(ddev, sizeof(struct digital_psl_res));
1329         if (!skb)
1330                 return -ENOMEM;
1331
1332         skb_put(skb, sizeof(struct digital_psl_res));
1333
1334         psl_res = (struct digital_psl_res *)skb->data;
1335
1336         psl_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
1337         psl_res->cmd = DIGITAL_CMD_PSL_RES;
1338         psl_res->did = did;
1339
1340         digital_skb_push_dep_sod(ddev, skb);
1341
1342         ddev->skb_add_crc(skb);
1343
1344         ddev->curr_nfc_dep_pni = 0;
1345
1346         rc = digital_tg_send_cmd(ddev, skb, 0, digital_tg_send_psl_res_complete,
1347                                  (void *)(unsigned long)rf_tech);
1348         if (rc)
1349                 kfree_skb(skb);
1350
1351         return rc;
1352 }
1353
1354 static void digital_tg_recv_psl_req(struct nfc_digital_dev *ddev, void *arg,
1355                                     struct sk_buff *resp)
1356 {
1357         int rc;
1358         struct digital_psl_req *psl_req;
1359         u8 rf_tech;
1360         u8 dsi, payload_size, payload_bits;
1361
1362         if (IS_ERR(resp)) {
1363                 rc = PTR_ERR(resp);
1364                 resp = NULL;
1365                 goto exit;
1366         }
1367
1368         rc = ddev->skb_check_crc(resp);
1369         if (rc) {
1370                 PROTOCOL_ERR("14.4.1.6");
1371                 goto exit;
1372         }
1373
1374         rc = digital_skb_pull_dep_sod(ddev, resp);
1375         if (rc) {
1376                 PROTOCOL_ERR("14.4.1.2");
1377                 goto exit;
1378         }
1379
1380         psl_req = (struct digital_psl_req *)resp->data;
1381
1382         if (resp->len != sizeof(struct digital_psl_req) ||
1383             psl_req->dir != DIGITAL_NFC_DEP_FRAME_DIR_OUT ||
1384             psl_req->cmd != DIGITAL_CMD_PSL_REQ) {
1385                 rc = -EIO;
1386                 goto exit;
1387         }
1388
1389         dsi = (psl_req->brs >> 3) & 0x07;
1390         switch (dsi) {
1391         case 0:
1392                 rf_tech = NFC_DIGITAL_RF_TECH_106A;
1393                 break;
1394         case 1:
1395                 rf_tech = NFC_DIGITAL_RF_TECH_212F;
1396                 break;
1397         case 2:
1398                 rf_tech = NFC_DIGITAL_RF_TECH_424F;
1399                 break;
1400         default:
1401                 pr_err("Unsupported dsi value %d\n", dsi);
1402                 goto exit;
1403         }
1404
1405         payload_bits = DIGITAL_PAYLOAD_FSL_TO_BITS(psl_req->fsl);
1406         payload_size = digital_payload_bits_to_size(payload_bits);
1407
1408         if (!payload_size || (payload_size > min(ddev->local_payload_max,
1409                                                  ddev->remote_payload_max))) {
1410                 rc = -EINVAL;
1411                 goto exit;
1412         }
1413
1414         ddev->local_payload_max = payload_size;
1415         ddev->remote_payload_max = payload_size;
1416
1417         rc = digital_tg_send_psl_res(ddev, psl_req->did, rf_tech);
1418
1419 exit:
1420         kfree_skb(resp);
1421 }
1422
1423 static void digital_tg_send_atr_res_complete(struct nfc_digital_dev *ddev,
1424                                              void *arg, struct sk_buff *resp)
1425 {
1426         int offset;
1427
1428         if (IS_ERR(resp)) {
1429                 digital_poll_next_tech(ddev);
1430                 return;
1431         }
1432
1433         offset = 2;
1434         if (resp->data[0] == DIGITAL_NFC_DEP_NFCA_SOD_SB)
1435                 offset++;
1436
1437         ddev->atn_count = 0;
1438
1439         if (resp->data[offset] == DIGITAL_CMD_PSL_REQ)
1440                 digital_tg_recv_psl_req(ddev, arg, resp);
1441         else
1442                 digital_tg_recv_dep_req(ddev, arg, resp);
1443 }
1444
1445 static int digital_tg_send_atr_res(struct nfc_digital_dev *ddev,
1446                                    struct digital_atr_req *atr_req)
1447 {
1448         struct digital_atr_res *atr_res;
1449         struct sk_buff *skb;
1450         u8 *gb, payload_bits;
1451         size_t gb_len;
1452         int rc;
1453
1454         gb = nfc_get_local_general_bytes(ddev->nfc_dev, &gb_len);
1455         if (!gb)
1456                 gb_len = 0;
1457
1458         skb = digital_skb_alloc(ddev, sizeof(struct digital_atr_res) + gb_len);
1459         if (!skb)
1460                 return -ENOMEM;
1461
1462         skb_put(skb, sizeof(struct digital_atr_res));
1463         atr_res = (struct digital_atr_res *)skb->data;
1464
1465         memset(atr_res, 0, sizeof(struct digital_atr_res));
1466
1467         atr_res->dir = DIGITAL_NFC_DEP_FRAME_DIR_IN;
1468         atr_res->cmd = DIGITAL_CMD_ATR_RES;
1469         memcpy(atr_res->nfcid3, atr_req->nfcid3, sizeof(atr_req->nfcid3));
1470         atr_res->to = 8;
1471
1472         ddev->local_payload_max = DIGITAL_PAYLOAD_SIZE_MAX;
1473         payload_bits = digital_payload_size_to_bits(ddev->local_payload_max);
1474         atr_res->pp = DIGITAL_PAYLOAD_BITS_TO_PP(payload_bits);
1475
1476         if (gb_len) {
1477                 skb_put(skb, gb_len);
1478
1479                 atr_res->pp |= DIGITAL_GB_BIT;
1480                 memcpy(atr_res->gb, gb, gb_len);
1481         }
1482
1483         digital_skb_push_dep_sod(ddev, skb);
1484
1485         ddev->skb_add_crc(skb);
1486
1487         ddev->curr_nfc_dep_pni = 0;
1488
1489         rc = digital_tg_send_cmd(ddev, skb, 999,
1490                                  digital_tg_send_atr_res_complete, NULL);
1491         if (rc)
1492                 kfree_skb(skb);
1493
1494         return rc;
1495 }
1496
1497 void digital_tg_recv_atr_req(struct nfc_digital_dev *ddev, void *arg,
1498                              struct sk_buff *resp)
1499 {
1500         int rc;
1501         struct digital_atr_req *atr_req;
1502         size_t gb_len, min_size;
1503         u8 poll_tech_count, payload_bits;
1504
1505         if (IS_ERR(resp)) {
1506                 rc = PTR_ERR(resp);
1507                 resp = NULL;
1508                 goto exit;
1509         }
1510
1511         if (!resp->len) {
1512                 rc = -EIO;
1513                 goto exit;
1514         }
1515
1516         if (resp->data[0] == DIGITAL_NFC_DEP_NFCA_SOD_SB) {
1517                 min_size = DIGITAL_ATR_REQ_MIN_SIZE + 2;
1518                 digital_tg_set_rf_tech(ddev, NFC_DIGITAL_RF_TECH_106A);
1519         } else {
1520                 min_size = DIGITAL_ATR_REQ_MIN_SIZE + 1;
1521                 digital_tg_set_rf_tech(ddev, NFC_DIGITAL_RF_TECH_212F);
1522         }
1523
1524         if (resp->len < min_size) {
1525                 rc = -EIO;
1526                 goto exit;
1527         }
1528
1529         ddev->curr_protocol = NFC_PROTO_NFC_DEP_MASK;
1530
1531         rc = ddev->skb_check_crc(resp);
1532         if (rc) {
1533                 PROTOCOL_ERR("14.4.1.6");
1534                 goto exit;
1535         }
1536
1537         rc = digital_skb_pull_dep_sod(ddev, resp);
1538         if (rc) {
1539                 PROTOCOL_ERR("14.4.1.2");
1540                 goto exit;
1541         }
1542
1543         atr_req = (struct digital_atr_req *)resp->data;
1544
1545         if (atr_req->dir != DIGITAL_NFC_DEP_FRAME_DIR_OUT ||
1546             atr_req->cmd != DIGITAL_CMD_ATR_REQ ||
1547             atr_req->did > DIGITAL_DID_MAX) {
1548                 rc = -EINVAL;
1549                 goto exit;
1550         }
1551
1552         payload_bits = DIGITAL_PAYLOAD_PP_TO_BITS(atr_req->pp);
1553         ddev->remote_payload_max = digital_payload_bits_to_size(payload_bits);
1554
1555         if (!ddev->remote_payload_max) {
1556                 rc = -EINVAL;
1557                 goto exit;
1558         }
1559
1560         ddev->did = atr_req->did;
1561
1562         rc = digital_tg_configure_hw(ddev, NFC_DIGITAL_CONFIG_FRAMING,
1563                                      NFC_DIGITAL_FRAMING_NFC_DEP_ACTIVATED);
1564         if (rc)
1565                 goto exit;
1566
1567         rc = digital_tg_send_atr_res(ddev, atr_req);
1568         if (rc)
1569                 goto exit;
1570
1571         gb_len = resp->len - sizeof(struct digital_atr_req);
1572
1573         poll_tech_count = ddev->poll_tech_count;
1574         ddev->poll_tech_count = 0;
1575
1576         rc = nfc_tm_activated(ddev->nfc_dev, NFC_PROTO_NFC_DEP_MASK,
1577                               NFC_COMM_PASSIVE, atr_req->gb, gb_len);
1578         if (rc) {
1579                 ddev->poll_tech_count = poll_tech_count;
1580                 goto exit;
1581         }
1582
1583         rc = 0;
1584 exit:
1585         if (rc)
1586                 digital_poll_next_tech(ddev);
1587
1588         dev_kfree_skb(resp);
1589 }