1*e501bae0SMatthias Ringwald /* 2*e501bae0SMatthias Ringwald * Copyright (C) 2018 BlueKitchen GmbH 3*e501bae0SMatthias Ringwald * 4*e501bae0SMatthias Ringwald * Redistribution and use in source and binary forms, with or without 5*e501bae0SMatthias Ringwald * modification, are permitted provided that the following conditions 6*e501bae0SMatthias Ringwald * are met: 7*e501bae0SMatthias Ringwald * 8*e501bae0SMatthias Ringwald * 1. Redistributions of source code must retain the above copyright 9*e501bae0SMatthias Ringwald * notice, this list of conditions and the following disclaimer. 10*e501bae0SMatthias Ringwald * 2. Redistributions in binary form must reproduce the above copyright 11*e501bae0SMatthias Ringwald * notice, this list of conditions and the following disclaimer in the 12*e501bae0SMatthias Ringwald * documentation and/or other materials provided with the distribution. 13*e501bae0SMatthias Ringwald * 3. Neither the name of the copyright holders nor the names of 14*e501bae0SMatthias Ringwald * contributors may be used to endorse or promote products derived 15*e501bae0SMatthias Ringwald * from this software without specific prior written permission. 16*e501bae0SMatthias Ringwald * 4. Any redistribution, use, or modification is done solely for 17*e501bae0SMatthias Ringwald * personal benefit and not for any commercial purpose or for 18*e501bae0SMatthias Ringwald * monetary gain. 19*e501bae0SMatthias Ringwald * 20*e501bae0SMatthias Ringwald * THIS SOFTWARE IS PROVIDED BY BLUEKITCHEN GMBH AND CONTRIBUTORS 21*e501bae0SMatthias Ringwald * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 22*e501bae0SMatthias Ringwald * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 23*e501bae0SMatthias Ringwald * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL MATTHIAS 24*e501bae0SMatthias Ringwald * RINGWALD OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, 25*e501bae0SMatthias Ringwald * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, 26*e501bae0SMatthias Ringwald * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS 27*e501bae0SMatthias Ringwald * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED 28*e501bae0SMatthias Ringwald * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, 29*e501bae0SMatthias Ringwald * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF 30*e501bae0SMatthias Ringwald * THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 31*e501bae0SMatthias Ringwald * SUCH DAMAGE. 32*e501bae0SMatthias Ringwald * 33*e501bae0SMatthias Ringwald * Please inquire about commercial licensing options at 34*e501bae0SMatthias Ringwald * [email protected] 35*e501bae0SMatthias Ringwald * 36*e501bae0SMatthias Ringwald */ 37*e501bae0SMatthias Ringwald 38*e501bae0SMatthias Ringwald #define BTSTACK_FILE__ "btstack_chipset_intel_firmware.c" 398174b66aSMatthias Ringwald 408174b66aSMatthias Ringwald #include <fcntl.h> 418174b66aSMatthias Ringwald #include <unistd.h> 428174b66aSMatthias Ringwald #include <stdio.h> 438174b66aSMatthias Ringwald 448174b66aSMatthias Ringwald #include "btstack_chipset_intel_firmware.h" 458174b66aSMatthias Ringwald #include "hci_cmd.h" 468174b66aSMatthias Ringwald #include "bluetooth.h" 478174b66aSMatthias Ringwald #include "hci_dump.h" 488174b66aSMatthias Ringwald #include "btstack_event.h" 498174b66aSMatthias Ringwald #include "btstack_debug.h" 508174b66aSMatthias Ringwald #include "btstack_util.h" 518174b66aSMatthias Ringwald #include "btstack_run_loop.h" 528174b66aSMatthias Ringwald 538174b66aSMatthias Ringwald // Vendor specific structs 548174b66aSMatthias Ringwald 558174b66aSMatthias Ringwald typedef struct { 568174b66aSMatthias Ringwald uint8_t status; 578174b66aSMatthias Ringwald uint8_t hw_platform; 588174b66aSMatthias Ringwald uint8_t hw_variant; 598174b66aSMatthias Ringwald uint8_t hw_revision; 608174b66aSMatthias Ringwald uint8_t fw_variant; 618174b66aSMatthias Ringwald uint8_t fw_revision; 628174b66aSMatthias Ringwald uint8_t fw_build_num; 638174b66aSMatthias Ringwald uint8_t fw_build_ww; 648174b66aSMatthias Ringwald uint8_t fw_build_yy; 658174b66aSMatthias Ringwald uint8_t fw_patch_num; 668174b66aSMatthias Ringwald } intel_version_t; 678174b66aSMatthias Ringwald 688174b66aSMatthias Ringwald typedef struct { 698174b66aSMatthias Ringwald uint8_t status; 708174b66aSMatthias Ringwald uint8_t otp_format; 718174b66aSMatthias Ringwald uint8_t otp_content; 728174b66aSMatthias Ringwald uint8_t otp_patch; 738174b66aSMatthias Ringwald uint16_t dev_revid; 748174b66aSMatthias Ringwald uint8_t secure_boot; 758174b66aSMatthias Ringwald uint8_t key_from_hdr; 768174b66aSMatthias Ringwald uint8_t key_type; 778174b66aSMatthias Ringwald uint8_t otp_lock; 788174b66aSMatthias Ringwald uint8_t api_lock; 798174b66aSMatthias Ringwald uint8_t debug_lock; 808174b66aSMatthias Ringwald bd_addr_t otp_bdaddr; 818174b66aSMatthias Ringwald uint8_t min_fw_build_nn; 828174b66aSMatthias Ringwald uint8_t min_fw_build_cw; 838174b66aSMatthias Ringwald uint8_t min_fw_build_yy; 848174b66aSMatthias Ringwald uint8_t limited_cce; 858174b66aSMatthias Ringwald uint8_t unlocked_state; 868174b66aSMatthias Ringwald } intel_boot_params_t; 878174b66aSMatthias Ringwald 888174b66aSMatthias Ringwald // Vendor sepcific commands 898174b66aSMatthias Ringwald 908174b66aSMatthias Ringwald static const hci_cmd_t hci_intel_read_version = { 918174b66aSMatthias Ringwald 0xfc05, "" 928174b66aSMatthias Ringwald }; 938174b66aSMatthias Ringwald static const hci_cmd_t hci_intel_read_secure_boot_params = { 948174b66aSMatthias Ringwald 0xfc0d, "" 958174b66aSMatthias Ringwald }; 968174b66aSMatthias Ringwald 978174b66aSMatthias Ringwald static const hci_cmd_t hci_intel_reset_param = { 988174b66aSMatthias Ringwald 0xfc01, "11111111" 998174b66aSMatthias Ringwald }; 1008174b66aSMatthias Ringwald 1018174b66aSMatthias Ringwald static const hci_cmd_t hci_intel_set_event_mask = { 1028174b66aSMatthias Ringwald 0xfc52, "11111111" 1038174b66aSMatthias Ringwald }; 1048174b66aSMatthias Ringwald 1058174b66aSMatthias Ringwald static const hci_cmd_t hci_intel_fc9f = { 1068174b66aSMatthias Ringwald 0xfc9f, "1" 1078174b66aSMatthias Ringwald }; 1088174b66aSMatthias Ringwald 1098174b66aSMatthias Ringwald // state 1108174b66aSMatthias Ringwald 11129c6772bSMatthias Ringwald const char * firmware_path = "."; 11229c6772bSMatthias Ringwald 1138174b66aSMatthias Ringwald const hci_transport_t * transport; 1148174b66aSMatthias Ringwald 1158174b66aSMatthias Ringwald static int state = 0; 1168174b66aSMatthias Ringwald 1178174b66aSMatthias Ringwald static uint8_t hci_outgoing[300]; 1188174b66aSMatthias Ringwald static uint8_t fw_buffer[300]; 1198174b66aSMatthias Ringwald 1208174b66aSMatthias Ringwald static uint8_t hw_variant; 1218174b66aSMatthias Ringwald static uint16_t dev_revid; 1228174b66aSMatthias Ringwald 1238174b66aSMatthias Ringwald static FILE * fw_file; 1248174b66aSMatthias Ringwald static uint32_t fw_offset; 1258174b66aSMatthias Ringwald 1268174b66aSMatthias Ringwald static void (*done)(int result); 1278174b66aSMatthias Ringwald 1288174b66aSMatthias Ringwald // functions 1298174b66aSMatthias Ringwald 1308174b66aSMatthias Ringwald static int transport_send_packet(uint8_t packet_type, const uint8_t * packet, uint16_t size){ 1318174b66aSMatthias Ringwald hci_dump_packet(HCI_COMMAND_DATA_PACKET, 0, (uint8_t*) packet, size); 1328174b66aSMatthias Ringwald return transport->send_packet(packet_type, (uint8_t *) packet, size); 1338174b66aSMatthias Ringwald } 1348174b66aSMatthias Ringwald 1358174b66aSMatthias Ringwald static int transport_send_cmd_va_arg(const hci_cmd_t *cmd, va_list argptr){ 1368174b66aSMatthias Ringwald uint8_t * packet = hci_outgoing; 1378174b66aSMatthias Ringwald uint16_t size = hci_cmd_create_from_template(packet, cmd, argptr); 1388174b66aSMatthias Ringwald return transport_send_packet(HCI_COMMAND_DATA_PACKET, packet, size); 1398174b66aSMatthias Ringwald } 1408174b66aSMatthias Ringwald 1418174b66aSMatthias Ringwald static int transport_send_cmd(const hci_cmd_t *cmd, ...){ 1428174b66aSMatthias Ringwald va_list argptr; 1438174b66aSMatthias Ringwald va_start(argptr, cmd); 1448174b66aSMatthias Ringwald int res = transport_send_cmd_va_arg(cmd, argptr); 1458174b66aSMatthias Ringwald va_end(argptr); 1468174b66aSMatthias Ringwald return res; 1478174b66aSMatthias Ringwald } 1488174b66aSMatthias Ringwald 1498174b66aSMatthias Ringwald static int transport_send_intel_secure(uint8_t fragment_type, const uint8_t * data, uint16_t len){ 1508174b66aSMatthias Ringwald little_endian_store_16(hci_outgoing, 0, 0xfc09); 1518174b66aSMatthias Ringwald hci_outgoing[2] = 1 + len; 1528174b66aSMatthias Ringwald hci_outgoing[3] = fragment_type; 1538174b66aSMatthias Ringwald memcpy(&hci_outgoing[4], data, len); 1548174b66aSMatthias Ringwald uint16_t size = 3 + 1 + len; 1558174b66aSMatthias Ringwald return transport_send_packet(HCI_ACL_DATA_PACKET, hci_outgoing, size); 1568174b66aSMatthias Ringwald } 1578174b66aSMatthias Ringwald 1588174b66aSMatthias Ringwald static int transport_send_intel_ddc(const uint8_t * data, uint16_t len){ 1598174b66aSMatthias Ringwald little_endian_store_16(hci_outgoing, 0, 0xfc8b); 1608174b66aSMatthias Ringwald hci_outgoing[2] = len; 1618174b66aSMatthias Ringwald memcpy(&hci_outgoing[3], data, len); 1628174b66aSMatthias Ringwald uint16_t size = 3 + len; 1638174b66aSMatthias Ringwald return transport_send_packet(HCI_COMMAND_DATA_PACKET, hci_outgoing, size); 1648174b66aSMatthias Ringwald } 1658174b66aSMatthias Ringwald 1668174b66aSMatthias Ringwald static void state_machine(uint8_t * packet); 1678174b66aSMatthias Ringwald 1688174b66aSMatthias Ringwald // read data from fw file and send it via intel_secure + update state 1698174b66aSMatthias Ringwald static int intel_send_fragment(uint8_t fragment_type, uint16_t len){ 1708174b66aSMatthias Ringwald int res = fread(fw_buffer, 1, len, fw_file); 1718174b66aSMatthias Ringwald log_info("offset %6u, read %3u -> res %d", fw_offset, len, res); 1728174b66aSMatthias Ringwald fw_offset += res; 1738174b66aSMatthias Ringwald state++; 1748174b66aSMatthias Ringwald return transport_send_intel_secure(fragment_type, fw_buffer, len); 1758174b66aSMatthias Ringwald } 1768174b66aSMatthias Ringwald 1778174b66aSMatthias Ringwald // read data from ddc file and send iva intel ddc command 1788174b66aSMatthias Ringwald // @returns -1 on eof 1798174b66aSMatthias Ringwald static int intel_send_ddc(void){ 1808174b66aSMatthias Ringwald int res; 1818174b66aSMatthias Ringwald // read len 1828174b66aSMatthias Ringwald res = fread(fw_buffer, 1, 1, fw_file); 1838174b66aSMatthias Ringwald log_info("offset %6u, read 1 -> res %d", fw_offset, res); 1848174b66aSMatthias Ringwald if (res == 0) return -1; 1858174b66aSMatthias Ringwald uint8_t len = fw_buffer[0]; 1868174b66aSMatthias Ringwald fw_offset += 1; 1878174b66aSMatthias Ringwald res = fread(&fw_buffer[1], 1, len, fw_file); 1888174b66aSMatthias Ringwald log_info("offset %6u, read %u -> res %d", fw_offset, 1, res); 1898174b66aSMatthias Ringwald return transport_send_intel_ddc(fw_buffer, 1 + len); 1908174b66aSMatthias Ringwald } 1918174b66aSMatthias Ringwald 1928174b66aSMatthias Ringwald static void dump_intel_version(intel_version_t * version){ 1938174b66aSMatthias Ringwald log_info("status 0x%02x", version->status); 1948174b66aSMatthias Ringwald log_info("hw_platform 0x%02x", version->hw_platform); 1958174b66aSMatthias Ringwald log_info("hw_variant 0x%02x", version->hw_variant); 1968174b66aSMatthias Ringwald log_info("hw_revision 0x%02x", version->hw_revision); 1978174b66aSMatthias Ringwald log_info("fw_variant 0x%02x", version->fw_variant); 1988174b66aSMatthias Ringwald log_info("fw_revision 0x%02x", version->fw_revision); 1998174b66aSMatthias Ringwald log_info("fw_build_num 0x%02x", version->fw_build_num); 2008174b66aSMatthias Ringwald log_info("fw_build_ww 0x%02x", version->fw_build_ww); 2018174b66aSMatthias Ringwald log_info("fw_build_yy 0x%02x", version->fw_build_yy); 2028174b66aSMatthias Ringwald log_info("fw_patch_num 0x%02x", version->fw_patch_num); 2038174b66aSMatthias Ringwald } 2048174b66aSMatthias Ringwald 2058174b66aSMatthias Ringwald static void dump_intel_boot_params(intel_boot_params_t * boot_params){ 2068174b66aSMatthias Ringwald bd_addr_t addr; 2078174b66aSMatthias Ringwald reverse_bd_addr(boot_params->otp_bdaddr, addr); 2088174b66aSMatthias Ringwald log_info("Device revision: %u", dev_revid); 2098174b66aSMatthias Ringwald log_info("Secure Boot: %s", boot_params->secure_boot ? "enabled" : "disabled"); 2108174b66aSMatthias Ringwald log_info("OTP lock: %s", boot_params->otp_lock ? "enabled" : "disabled"); 2118174b66aSMatthias Ringwald log_info("API lock: %s", boot_params->api_lock ? "enabled" : "disabled"); 2128174b66aSMatthias Ringwald log_info("Debug lock: %s", boot_params->debug_lock ? "enabled" : "disabled"); 2138174b66aSMatthias Ringwald log_info("Minimum firmware build %u week %u %u", boot_params->min_fw_build_nn, boot_params->min_fw_build_cw, 2000 + boot_params->min_fw_build_yy); 2148174b66aSMatthias Ringwald log_info("OTC BD_ADDR: %s", bd_addr_to_str(addr)); 2158174b66aSMatthias Ringwald } 2168174b66aSMatthias Ringwald 2178174b66aSMatthias Ringwald static int vendor_firmware_complete_received; 2188174b66aSMatthias Ringwald static int waiting_for_command_complete; 2198174b66aSMatthias Ringwald 2208174b66aSMatthias Ringwald static void state_machine(uint8_t * packet){ 2218174b66aSMatthias Ringwald intel_version_t * version; 2228174b66aSMatthias Ringwald intel_boot_params_t * boot_params; 2238174b66aSMatthias Ringwald int res; 2248174b66aSMatthias Ringwald uint16_t buffer_offset; 2258174b66aSMatthias Ringwald bd_addr_t addr; 22629c6772bSMatthias Ringwald char fw_path[300]; 2278174b66aSMatthias Ringwald 2288174b66aSMatthias Ringwald if (packet){ 2298174b66aSMatthias Ringwald // firmware upload complete event? 2308174b66aSMatthias Ringwald if (packet[0] == 0xff && packet[2] == 0x06) { 2318174b66aSMatthias Ringwald vendor_firmware_complete_received = 1; 2328174b66aSMatthias Ringwald } 2338174b66aSMatthias Ringwald 2348174b66aSMatthias Ringwald // command complete 2358174b66aSMatthias Ringwald if (packet[0] == 0x0e){ 2368174b66aSMatthias Ringwald waiting_for_command_complete = 0; 2378174b66aSMatthias Ringwald } 2388174b66aSMatthias Ringwald } 2398174b66aSMatthias Ringwald 2408174b66aSMatthias Ringwald switch (state){ 2418174b66aSMatthias Ringwald case 0: 2428174b66aSMatthias Ringwald state++; 2438174b66aSMatthias Ringwald transport_send_cmd(&hci_reset); 2448174b66aSMatthias Ringwald break; 2458174b66aSMatthias Ringwald case 1: 24688362d5eSMatthias Ringwald // check if HCI Reset was supported 24788362d5eSMatthias Ringwald if (packet[0] == 0x0e && packet[1] == 0x04 && packet[3] == 0x03 && packet[4] == 0x0c && packet[5] == 0x00){ 24888362d5eSMatthias Ringwald log_info("HCI Reset was successful, no need for firmware upload / or not an Intel chipset"); 24988362d5eSMatthias Ringwald (*done)(0); 25088362d5eSMatthias Ringwald break; 25188362d5eSMatthias Ringwald } 25288362d5eSMatthias Ringwald 2538174b66aSMatthias Ringwald // Read Intel Version 2548174b66aSMatthias Ringwald state++; 2558174b66aSMatthias Ringwald transport_send_cmd(&hci_intel_read_version); 2568174b66aSMatthias Ringwald break; 2578174b66aSMatthias Ringwald case 2: 2588174b66aSMatthias Ringwald version = (intel_version_t*) hci_event_command_complete_get_return_parameters(packet); 2598174b66aSMatthias Ringwald dump_intel_version(version); 2608174b66aSMatthias Ringwald 2618174b66aSMatthias Ringwald hw_variant = version->hw_variant; 2628174b66aSMatthias Ringwald 2638174b66aSMatthias Ringwald // fw_variant = 0x06 bootloader mode / 0x23 operational mode 2648174b66aSMatthias Ringwald if (version->fw_variant == 0x23) { 2658174b66aSMatthias Ringwald (*done)(0); 2668174b66aSMatthias Ringwald break; 2678174b66aSMatthias Ringwald } 2688174b66aSMatthias Ringwald 2698174b66aSMatthias Ringwald if (version->fw_variant != 0x06){ 2708174b66aSMatthias Ringwald log_error("unknown fw_variant 0x%02x", version->fw_variant); 2718174b66aSMatthias Ringwald break; 2728174b66aSMatthias Ringwald } 2738174b66aSMatthias Ringwald 2748174b66aSMatthias Ringwald // Read Intel Secure Boot Params 2758174b66aSMatthias Ringwald state++; 2768174b66aSMatthias Ringwald transport_send_cmd(&hci_intel_read_secure_boot_params); 2778174b66aSMatthias Ringwald break; 2788174b66aSMatthias Ringwald case 3: 2798174b66aSMatthias Ringwald boot_params = (intel_boot_params_t *) hci_event_command_complete_get_return_parameters(packet); 2808174b66aSMatthias Ringwald dump_intel_boot_params(boot_params); 2818174b66aSMatthias Ringwald 2828174b66aSMatthias Ringwald reverse_bd_addr(boot_params->otp_bdaddr, addr); 2838174b66aSMatthias Ringwald dev_revid = little_endian_read_16((uint8_t*)&boot_params->dev_revid, 0); 2848174b66aSMatthias Ringwald 2858174b66aSMatthias Ringwald // assert commmand complete is required 2868174b66aSMatthias Ringwald if (boot_params->limited_cce != 0) break; 2878174b66aSMatthias Ringwald 2888174b66aSMatthias Ringwald // firmware file 28929c6772bSMatthias Ringwald snprintf(fw_path, sizeof(fw_path), "%s/ibt-%u-%u.sfi", firmware_path, hw_variant, dev_revid); 29029c6772bSMatthias Ringwald log_info("Open firmware %s", fw_path); 29129c6772bSMatthias Ringwald printf("Firwmare %s\n", fw_path); 2928174b66aSMatthias Ringwald 2938174b66aSMatthias Ringwald // open firmware file 2948174b66aSMatthias Ringwald fw_offset = 0; 29529c6772bSMatthias Ringwald fw_file = fopen(fw_path, "rb"); 2968174b66aSMatthias Ringwald if (!fw_file){ 29729c6772bSMatthias Ringwald log_error("can't open file %s", fw_path); 2988174b66aSMatthias Ringwald (*done)(1); 2998174b66aSMatthias Ringwald return; 3008174b66aSMatthias Ringwald } 3018174b66aSMatthias Ringwald 3028174b66aSMatthias Ringwald vendor_firmware_complete_received = 0; 3038174b66aSMatthias Ringwald 3048174b66aSMatthias Ringwald // send CCS segment - offset 0 3058174b66aSMatthias Ringwald intel_send_fragment(0x00, 128); 3068174b66aSMatthias Ringwald break; 3078174b66aSMatthias Ringwald case 4: 3088174b66aSMatthias Ringwald // send public key / part 1 - offset 128 3098174b66aSMatthias Ringwald intel_send_fragment(0x03, 128); 3108174b66aSMatthias Ringwald break; 3118174b66aSMatthias Ringwald case 5: 3128174b66aSMatthias Ringwald // send public key / part 2 - offset 384 3138174b66aSMatthias Ringwald intel_send_fragment(0x03, 128); 3148174b66aSMatthias Ringwald break; 3158174b66aSMatthias Ringwald case 6: 3168174b66aSMatthias Ringwald // skip 4 bytes 3178174b66aSMatthias Ringwald res = fread(fw_buffer, 1, 4, fw_file); 3188174b66aSMatthias Ringwald log_info("read res %d", res); 3198174b66aSMatthias Ringwald fw_offset += res; 3208174b66aSMatthias Ringwald 3218174b66aSMatthias Ringwald // send signature / part 1 - offset 388 3228174b66aSMatthias Ringwald intel_send_fragment(0x02, 128); 3238174b66aSMatthias Ringwald break; 3248174b66aSMatthias Ringwald case 7: 3258174b66aSMatthias Ringwald // send signature / part 2 - offset 516 3268174b66aSMatthias Ringwald intel_send_fragment(0x02, 128); 3278174b66aSMatthias Ringwald break; 3288174b66aSMatthias Ringwald case 8: 3298174b66aSMatthias Ringwald // send firmware chunks - offset 644 3308174b66aSMatthias Ringwald // chunk len must be 4 byte aligned 3318174b66aSMatthias Ringwald // multiple commands can be combined 3328174b66aSMatthias Ringwald buffer_offset = 0; 3338174b66aSMatthias Ringwald do { 3348174b66aSMatthias Ringwald res = fread(&fw_buffer[buffer_offset], 1, 3, fw_file); 3358174b66aSMatthias Ringwald log_info("fw_offset %6u, buffer_offset %u, read %3u -> res %d", fw_offset, buffer_offset, 3, res); 3368174b66aSMatthias Ringwald fw_offset += res; 3378174b66aSMatthias Ringwald if (res == 0 ){ 3388174b66aSMatthias Ringwald // EOF 3398174b66aSMatthias Ringwald log_info("End of file"); 3408174b66aSMatthias Ringwald fclose(fw_file); 3418174b66aSMatthias Ringwald fw_file = NULL; 3428174b66aSMatthias Ringwald state++; 3438174b66aSMatthias Ringwald break; 3448174b66aSMatthias Ringwald } 3458174b66aSMatthias Ringwald int param_len = fw_buffer[buffer_offset + 2]; 3468174b66aSMatthias Ringwald buffer_offset += 3; 3478174b66aSMatthias Ringwald if (param_len){ 3488174b66aSMatthias Ringwald res = fread(&fw_buffer[buffer_offset], 1, param_len, fw_file); 3498174b66aSMatthias Ringwald fw_offset += res; 3508174b66aSMatthias Ringwald buffer_offset += res; 3518174b66aSMatthias Ringwald } 3528174b66aSMatthias Ringwald } while ((buffer_offset & 3) != 0); 3538174b66aSMatthias Ringwald 3548174b66aSMatthias Ringwald if (buffer_offset == 0) break; 3558174b66aSMatthias Ringwald 3568174b66aSMatthias Ringwald waiting_for_command_complete = 1; 3578174b66aSMatthias Ringwald transport_send_intel_secure(0x01, fw_buffer, buffer_offset); 3588174b66aSMatthias Ringwald break; 3598174b66aSMatthias Ringwald 3608174b66aSMatthias Ringwald case 9: 3618174b66aSMatthias Ringwald // expect Vendor Specific Event 0x06 3628174b66aSMatthias Ringwald if (!vendor_firmware_complete_received) break; 3638174b66aSMatthias Ringwald 3648174b66aSMatthias Ringwald printf("Firmware upload complete\n"); 3658174b66aSMatthias Ringwald log_info("Vendor Event 0x06 - firmware complete"); 3668174b66aSMatthias Ringwald 3678174b66aSMatthias Ringwald // Reset Params - constants from Windows Intel driver 3688174b66aSMatthias Ringwald state++; 3698174b66aSMatthias Ringwald transport_send_cmd(&hci_intel_reset_param, 0x00, 0x00, 0x00, 0x01, 0x00, 0x08, 0x04, 0x00); 3708174b66aSMatthias Ringwald break; 3718174b66aSMatthias Ringwald 3728174b66aSMatthias Ringwald case 10: 3738174b66aSMatthias Ringwald // expect Vendor Specific Event 0x02 3748174b66aSMatthias Ringwald if (packet[0] != 0xff) break; 3758174b66aSMatthias Ringwald if (packet[2] != 0x02) break; 3768174b66aSMatthias Ringwald 3778174b66aSMatthias Ringwald printf("Firmware operational\n"); 3788174b66aSMatthias Ringwald log_info("Vendor Event 0x02 - firmware operational"); 3798174b66aSMatthias Ringwald 3808174b66aSMatthias Ringwald // Read Intel Version 3818174b66aSMatthias Ringwald state++; 3828174b66aSMatthias Ringwald transport_send_cmd(&hci_intel_read_version); 3838174b66aSMatthias Ringwald break; 3848174b66aSMatthias Ringwald 3858174b66aSMatthias Ringwald case 11: 3868174b66aSMatthias Ringwald version = (intel_version_t*) hci_event_command_complete_get_return_parameters(packet); 3878174b66aSMatthias Ringwald dump_intel_version(version); 3888174b66aSMatthias Ringwald 3898174b66aSMatthias Ringwald // ddc config 39029c6772bSMatthias Ringwald snprintf(fw_path, sizeof(fw_path), "%s/ibt-%u-%u.ddc", firmware_path, hw_variant, dev_revid); 39129c6772bSMatthias Ringwald log_info("Open DDC %s", fw_path); 3928174b66aSMatthias Ringwald 3938174b66aSMatthias Ringwald // open ddc file 3948174b66aSMatthias Ringwald fw_offset = 0; 39529c6772bSMatthias Ringwald fw_file = fopen(fw_path, "rb"); 3968174b66aSMatthias Ringwald if (!fw_file){ 39729c6772bSMatthias Ringwald log_error("can't open file %s", fw_path); 3988174b66aSMatthias Ringwald 3998174b66aSMatthias Ringwald (*done)(1); 4008174b66aSMatthias Ringwald return; 4018174b66aSMatthias Ringwald } 4028174b66aSMatthias Ringwald 4038174b66aSMatthias Ringwald // load ddc 4048174b66aSMatthias Ringwald state++; 4058174b66aSMatthias Ringwald 4068174b66aSMatthias Ringwald /* fall through */ 4078174b66aSMatthias Ringwald 4088174b66aSMatthias Ringwald case 12: 4098174b66aSMatthias Ringwald res = intel_send_ddc(); 4108174b66aSMatthias Ringwald if (res == 0) break; 4118174b66aSMatthias Ringwald 4128174b66aSMatthias Ringwald // DDC download complete 4138174b66aSMatthias Ringwald state++; 4148174b66aSMatthias Ringwald log_info("Load DDC Complete"); 4158174b66aSMatthias Ringwald 4168174b66aSMatthias Ringwald 4178174b66aSMatthias Ringwald // Set Intel event mask 0xfc52 4188174b66aSMatthias Ringwald state++; 4198174b66aSMatthias Ringwald transport_send_cmd(&hci_intel_set_event_mask, 0x87, 0x0c, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00); 4208174b66aSMatthias Ringwald break; 4218174b66aSMatthias Ringwald 4228174b66aSMatthias Ringwald case 13: 4238174b66aSMatthias Ringwald // 9F FC 01 00 4248174b66aSMatthias Ringwald state++; 4258174b66aSMatthias Ringwald transport_send_cmd(&hci_intel_fc9f, 0x00); 4268174b66aSMatthias Ringwald break; 4278174b66aSMatthias Ringwald 4288174b66aSMatthias Ringwald case 14: 4298174b66aSMatthias Ringwald (*done)(0); 4308174b66aSMatthias Ringwald break; 4318174b66aSMatthias Ringwald 4328174b66aSMatthias Ringwald default: 4338174b66aSMatthias Ringwald break; 4348174b66aSMatthias Ringwald } 4358174b66aSMatthias Ringwald } 4368174b66aSMatthias Ringwald 4378174b66aSMatthias Ringwald static void transport_packet_handler (uint8_t packet_type, uint8_t *packet, uint16_t size){ 4388174b66aSMatthias Ringwald UNUSED(packet_type); 4398174b66aSMatthias Ringwald // we also get events with packet_type ACL from the controller 4408174b66aSMatthias Ringwald hci_dump_packet(HCI_EVENT_PACKET, 1, packet, size); 4418174b66aSMatthias Ringwald switch (hci_event_packet_get_type(packet)){ 4428174b66aSMatthias Ringwald case HCI_EVENT_COMMAND_COMPLETE: 4438174b66aSMatthias Ringwald case HCI_EVENT_VENDOR_SPECIFIC: 4448174b66aSMatthias Ringwald state_machine(packet); 4458174b66aSMatthias Ringwald break; 4468174b66aSMatthias Ringwald default: 4478174b66aSMatthias Ringwald break; 4488174b66aSMatthias Ringwald } 4498174b66aSMatthias Ringwald } 4508174b66aSMatthias Ringwald 45129c6772bSMatthias Ringwald void btstack_chipset_intel_set_firmware_path(const char * path){ 45229c6772bSMatthias Ringwald firmware_path = path; 45329c6772bSMatthias Ringwald } 45429c6772bSMatthias Ringwald 4558174b66aSMatthias Ringwald void btstack_chipset_intel_download_firmware(const hci_transport_t * hci_transport, void (*callback)(int result)){ 4568174b66aSMatthias Ringwald 4578174b66aSMatthias Ringwald done = callback; 4588174b66aSMatthias Ringwald 4598174b66aSMatthias Ringwald transport = hci_transport;; 4608174b66aSMatthias Ringwald // transport->init(NULL); 4618174b66aSMatthias Ringwald transport->register_packet_handler(&transport_packet_handler); 4628174b66aSMatthias Ringwald transport->open(); 4638174b66aSMatthias Ringwald 4648174b66aSMatthias Ringwald // get started 4658174b66aSMatthias Ringwald state = 0; 4668174b66aSMatthias Ringwald state_machine(NULL); 4678174b66aSMatthias Ringwald } 468