1 /* 2 * Copyright (C) 2014 BlueKitchen GmbH 3 * 4 * Redistribution and use in source and binary forms, with or without 5 * modification, are permitted provided that the following conditions 6 * are met: 7 * 8 * 1. Redistributions of source code must retain the above copyright 9 * notice, this list of conditions and the following disclaimer. 10 * 2. Redistributions in binary form must reproduce the above copyright 11 * notice, this list of conditions and the following disclaimer in the 12 * documentation and/or other materials provided with the distribution. 13 * 3. Neither the name of the copyright holders nor the names of 14 * contributors may be used to endorse or promote products derived 15 * from this software without specific prior written permission. 16 * 4. Any redistribution, use, or modification is done solely for 17 * personal benefit and not for any commercial purpose or for 18 * monetary gain. 19 * 20 * THIS SOFTWARE IS PROVIDED BY BLUEKITCHEN GMBH AND CONTRIBUTORS 21 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 22 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 23 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL BLUEKITCHEN 24 * GMBH OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, 25 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, 26 * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS 27 * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED 28 * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, 29 * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF 30 * THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 31 * SUCH DAMAGE. 32 * 33 * Please inquire about commercial licensing options at 34 * [email protected] 35 * 36 */ 37 38 #define BTSTACK_FILE__ "gatt_client.c" 39 40 #include <stdint.h> 41 #include <string.h> 42 #include <stddef.h> 43 44 #include "btstack_config.h" 45 46 #include "ble/att_dispatch.h" 47 #include "ble/att_db.h" 48 #include "ble/gatt_client.h" 49 #include "ble/le_device_db.h" 50 #include "ble/sm.h" 51 #include "bluetooth_psm.h" 52 #include "btstack_debug.h" 53 #include "btstack_event.h" 54 #include "btstack_memory.h" 55 #include "btstack_run_loop.h" 56 #include "btstack_util.h" 57 #include "hci.h" 58 #include "hci_dump.h" 59 #include "hci_event_builder.h" 60 #include "l2cap.h" 61 #include "classic/sdp_client.h" 62 #include "bluetooth_gatt.h" 63 #include "bluetooth_sdp.h" 64 #include "classic/sdp_util.h" 65 66 #if defined(ENABLE_GATT_OVER_EATT) && !defined(ENABLE_L2CAP_ENHANCED_CREDIT_BASED_FLOW_CONTROL_MODE) 67 #error "GATT Over EATT requires support for L2CAP Enhanced CoC. Please enable ENABLE_L2CAP_ENHANCED_CREDIT_BASED_FLOW_CONTROL_MODE" 68 #endif 69 70 // L2CAP Test Spec p35 defines a minimum of 100 ms, but PTS might indicate an error if we sent after 100 ms 71 #define GATT_CLIENT_COLLISION_BACKOFF_MS 150 72 73 static btstack_linked_list_t gatt_client_connections; 74 static btstack_linked_list_t gatt_client_value_listeners; 75 #ifdef ENABLE_GATT_CLIENT_SERVICE_CHANGED 76 static btstack_linked_list_t gatt_client_service_changed_handler; 77 #endif 78 static btstack_packet_callback_registration_t hci_event_callback_registration; 79 static btstack_packet_callback_registration_t sm_event_callback_registration; 80 static btstack_context_callback_registration_t gatt_client_deferred_event_emit; 81 82 // GATT Client Configuration 83 static bool gatt_client_mtu_exchange_enabled; 84 static gap_security_level_t gatt_client_required_security_level; 85 86 static void gatt_client_att_packet_handler(uint8_t packet_type, uint16_t handle, uint8_t *packet, uint16_t size); 87 static void gatt_client_event_packet_handler(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size); 88 static void gatt_client_report_error_if_pending(gatt_client_t *gatt_client, uint8_t att_error_code); 89 90 #ifdef ENABLE_LE_SIGNED_WRITE 91 static void att_signed_write_handle_cmac_result(uint8_t hash[8]); 92 #endif 93 94 #ifdef ENABLE_GATT_OVER_CLASSIC 95 static gatt_client_t * gatt_client_get_context_for_l2cap_cid(uint16_t l2cap_cid); 96 static void gatt_client_classic_handle_connected(gatt_client_t * gatt_client, uint8_t status); 97 static void gatt_client_classic_handle_disconnected(gatt_client_t * gatt_client); 98 static void gatt_client_classic_retry(btstack_timer_source_t * ts); 99 #endif 100 101 #ifdef ENABLE_GATT_OVER_EATT 102 static bool gatt_client_le_enhanced_handle_can_send_query(gatt_client_t * gatt_client); 103 static void gatt_client_le_enhanced_retry(btstack_timer_source_t * ts); 104 #endif 105 106 void gatt_client_init(void){ 107 gatt_client_connections = NULL; 108 #ifdef ENABLE_GATT_CLIENT_SERVICE_CHANGED 109 gatt_client_service_changed_handler = NULL; 110 #endif 111 // default configuration 112 gatt_client_mtu_exchange_enabled = true; 113 gatt_client_required_security_level = LEVEL_0; 114 115 // register for HCI Events 116 hci_event_callback_registration.callback = &gatt_client_event_packet_handler; 117 hci_add_event_handler(&hci_event_callback_registration); 118 119 // register for SM Events 120 sm_event_callback_registration.callback = &gatt_client_event_packet_handler; 121 sm_add_event_handler(&sm_event_callback_registration); 122 123 // and ATT Client PDUs 124 att_dispatch_register_client(gatt_client_att_packet_handler); 125 } 126 127 void gatt_client_set_required_security_level(gap_security_level_t level){ 128 gatt_client_required_security_level = level; 129 } 130 131 static gatt_client_t * gatt_client_for_timer(btstack_timer_source_t * ts){ 132 btstack_linked_list_iterator_t it; 133 btstack_linked_list_iterator_init(&it, &gatt_client_connections); 134 while (btstack_linked_list_iterator_has_next(&it)){ 135 gatt_client_t * gatt_client = (gatt_client_t *) btstack_linked_list_iterator_next(&it); 136 if (&gatt_client->gc_timeout == ts) { 137 return gatt_client; 138 } 139 } 140 return NULL; 141 } 142 143 static void gatt_client_timeout_handler(btstack_timer_source_t * timer){ 144 gatt_client_t * gatt_client = gatt_client_for_timer(timer); 145 if (gatt_client == NULL) return; 146 log_info("GATT client timeout handle, handle 0x%02x", gatt_client->con_handle); 147 gatt_client_report_error_if_pending(gatt_client, ATT_ERROR_TIMEOUT); 148 } 149 150 static void gatt_client_timeout_start(gatt_client_t * gatt_client){ 151 log_debug("GATT client timeout start, handle 0x%02x", gatt_client->con_handle); 152 btstack_run_loop_remove_timer(&gatt_client->gc_timeout); 153 btstack_run_loop_set_timer_handler(&gatt_client->gc_timeout, gatt_client_timeout_handler); 154 btstack_run_loop_set_timer(&gatt_client->gc_timeout, 30000); // 30 seconds sm timeout 155 btstack_run_loop_add_timer(&gatt_client->gc_timeout); 156 } 157 158 static void gatt_client_timeout_stop(gatt_client_t * gatt_client){ 159 log_debug("GATT client timeout stop, handle 0x%02x", gatt_client->con_handle); 160 btstack_run_loop_remove_timer(&gatt_client->gc_timeout); 161 } 162 163 static gap_security_level_t gatt_client_le_security_level_for_connection(hci_con_handle_t con_handle){ 164 uint8_t encryption_key_size = gap_encryption_key_size(con_handle); 165 if (encryption_key_size == 0) return LEVEL_0; 166 167 bool authenticated = gap_authenticated(con_handle); 168 if (!authenticated) return LEVEL_2; 169 170 return encryption_key_size == 16 ? LEVEL_4 : LEVEL_3; 171 } 172 173 static gatt_client_t * gatt_client_get_context_for_handle(uint16_t handle){ 174 btstack_linked_item_t *it; 175 for (it = (btstack_linked_item_t *) gatt_client_connections; it != NULL; it = it->next){ 176 gatt_client_t * gatt_client = (gatt_client_t *) it; 177 if (gatt_client->con_handle == handle){ 178 return gatt_client; 179 } 180 } 181 return NULL; 182 } 183 184 185 // @return gatt_client context 186 // returns existing one, or tries to setup new one 187 static uint8_t gatt_client_provide_context_for_handle(hci_con_handle_t con_handle, gatt_client_t ** out_gatt_client){ 188 gatt_client_t * gatt_client = gatt_client_get_context_for_handle(con_handle); 189 190 if (gatt_client != NULL){ 191 *out_gatt_client = gatt_client; 192 return ERROR_CODE_SUCCESS; 193 } 194 195 // bail if no such hci connection 196 hci_connection_t * hci_connection = hci_connection_for_handle(con_handle); 197 if (hci_connection == NULL){ 198 log_error("No connection for handle 0x%04x", con_handle); 199 *out_gatt_client = NULL; 200 return ERROR_CODE_UNKNOWN_CONNECTION_IDENTIFIER; 201 } 202 203 gatt_client = btstack_memory_gatt_client_get(); 204 if (gatt_client == NULL){ 205 *out_gatt_client = NULL; 206 return ERROR_CODE_MEMORY_CAPACITY_EXCEEDED; 207 } 208 // init state 209 gatt_client->bearer_type = ATT_BEARER_UNENHANCED_LE; 210 gatt_client->con_handle = con_handle; 211 gatt_client->mtu = ATT_DEFAULT_MTU; 212 gatt_client->security_level = gatt_client_le_security_level_for_connection(con_handle); 213 if (gatt_client_mtu_exchange_enabled){ 214 gatt_client->mtu_state = SEND_MTU_EXCHANGE; 215 } else { 216 gatt_client->mtu_state = MTU_AUTO_EXCHANGE_DISABLED; 217 } 218 gatt_client->state = P_READY; 219 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DISCOVER_W2_SEND; 220 #ifdef ENABLE_GATT_OVER_EATT 221 gatt_client->eatt_state = GATT_CLIENT_EATT_IDLE; 222 #endif 223 btstack_linked_list_add(&gatt_client_connections, (btstack_linked_item_t*)gatt_client); 224 225 // get unenhanced att bearer state 226 if (hci_connection->att_connection.mtu_exchanged){ 227 gatt_client->mtu = hci_connection->att_connection.mtu; 228 gatt_client->mtu_state = MTU_EXCHANGED; 229 } 230 *out_gatt_client = gatt_client; 231 return ERROR_CODE_SUCCESS; 232 } 233 234 static bool is_ready(gatt_client_t * gatt_client){ 235 return gatt_client->state == P_READY; 236 } 237 238 static uint8_t gatt_client_provide_context_for_request(hci_con_handle_t con_handle, gatt_client_t ** out_gatt_client){ 239 gatt_client_t * gatt_client = NULL; 240 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 241 if (status != ERROR_CODE_SUCCESS){ 242 return status; 243 } 244 245 #ifdef ENABLE_GATT_OVER_EATT 246 if (gatt_client->eatt_state == GATT_CLIENT_EATT_READY){ 247 btstack_linked_list_iterator_t it; 248 gatt_client_t * eatt_client = NULL; 249 // find free eatt client 250 btstack_linked_list_iterator_init(&it, &gatt_client->eatt_clients); 251 while (btstack_linked_list_iterator_has_next(&it)){ 252 gatt_client_t * client = (gatt_client_t *) btstack_linked_list_iterator_next(&it); 253 if (client->state == P_READY){ 254 eatt_client = client; 255 break; 256 } 257 } 258 if (eatt_client == NULL){ 259 return ERROR_CODE_COMMAND_DISALLOWED; 260 } 261 gatt_client = eatt_client; 262 } 263 #endif 264 265 if (is_ready(gatt_client) == false){ 266 return GATT_CLIENT_IN_WRONG_STATE; 267 } 268 269 gatt_client_timeout_start(gatt_client); 270 271 *out_gatt_client = gatt_client; 272 273 return status; 274 } 275 276 int gatt_client_is_ready(hci_con_handle_t con_handle){ 277 gatt_client_t * gatt_client; 278 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 279 if (status != ERROR_CODE_SUCCESS){ 280 return 0; 281 } 282 return is_ready(gatt_client) ? 1 : 0; 283 } 284 285 void gatt_client_mtu_enable_auto_negotiation(uint8_t enabled){ 286 gatt_client_mtu_exchange_enabled = enabled != 0; 287 } 288 289 uint8_t gatt_client_get_mtu(hci_con_handle_t con_handle, uint16_t * mtu){ 290 gatt_client_t * gatt_client; 291 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 292 if (status != ERROR_CODE_SUCCESS){ 293 return status; 294 } 295 296 if ((gatt_client->mtu_state == MTU_EXCHANGED) || (gatt_client->mtu_state == MTU_AUTO_EXCHANGE_DISABLED)){ 297 *mtu = gatt_client->mtu; 298 return ERROR_CODE_SUCCESS; 299 } 300 *mtu = ATT_DEFAULT_MTU; 301 return GATT_CLIENT_IN_WRONG_STATE; 302 } 303 304 static uint8_t *gatt_client_reserve_request_buffer(gatt_client_t *gatt_client) { 305 switch (gatt_client->bearer_type){ 306 #ifdef ENABLE_GATT_OVER_CLASSIC 307 case ATT_BEARER_UNENHANCED_CLASSIC: 308 #endif 309 case ATT_BEARER_UNENHANCED_LE: 310 l2cap_reserve_packet_buffer(); 311 return l2cap_get_outgoing_buffer(); 312 #ifdef ENABLE_GATT_OVER_EATT 313 case ATT_BEARER_ENHANCED_LE: 314 return gatt_client->eatt_storage_buffer; 315 #endif 316 default: 317 btstack_unreachable(); 318 break; 319 } 320 return NULL; 321 } 322 323 // precondition: can_send_packet_now == TRUE 324 static uint8_t gatt_client_send(gatt_client_t * gatt_client, uint16_t len){ 325 switch (gatt_client->bearer_type){ 326 case ATT_BEARER_UNENHANCED_LE: 327 return l2cap_send_prepared_connectionless(gatt_client->con_handle, L2CAP_CID_ATTRIBUTE_PROTOCOL, len); 328 #ifdef ENABLE_GATT_OVER_CLASSIC 329 case ATT_BEARER_UNENHANCED_CLASSIC: 330 return l2cap_send_prepared(gatt_client->l2cap_cid, len); 331 #endif 332 #ifdef ENABLE_GATT_OVER_EATT 333 case ATT_BEARER_ENHANCED_LE: 334 return l2cap_send(gatt_client->l2cap_cid, gatt_client->eatt_storage_buffer, len); 335 #endif 336 default: 337 btstack_unreachable(); 338 return ERROR_CODE_HARDWARE_FAILURE; 339 } 340 } 341 342 // precondition: can_send_packet_now == TRUE 343 static uint8_t att_confirmation(gatt_client_t * gatt_client) { 344 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 345 346 request[0] = ATT_HANDLE_VALUE_CONFIRMATION; 347 348 return gatt_client_send(gatt_client, 1); 349 } 350 351 // precondition: can_send_packet_now == TRUE 352 static uint8_t att_find_information_request(gatt_client_t *gatt_client, uint8_t request_type, uint16_t start_handle, 353 uint16_t end_handle) { 354 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 355 356 request[0] = request_type; 357 little_endian_store_16(request, 1, start_handle); 358 little_endian_store_16(request, 3, end_handle); 359 360 return gatt_client_send(gatt_client, 5); 361 } 362 363 // precondition: can_send_packet_now == TRUE 364 static uint8_t 365 att_find_by_type_value_request(gatt_client_t *gatt_client, uint8_t request_type, uint16_t attribute_group_type, 366 uint16_t start_handle, uint16_t end_handle, uint8_t *value, uint16_t value_size) { 367 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 368 request[0] = request_type; 369 370 little_endian_store_16(request, 1, start_handle); 371 little_endian_store_16(request, 3, end_handle); 372 little_endian_store_16(request, 5, attribute_group_type); 373 (void)memcpy(&request[7], value, value_size); 374 375 return gatt_client_send(gatt_client, 7u + value_size); 376 } 377 378 // precondition: can_send_packet_now == TRUE 379 static uint8_t 380 att_read_by_type_or_group_request_for_uuid16(gatt_client_t *gatt_client, uint8_t request_type, uint16_t uuid16, 381 uint16_t start_handle, uint16_t end_handle) { 382 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 383 384 request[0] = request_type; 385 little_endian_store_16(request, 1, start_handle); 386 little_endian_store_16(request, 3, end_handle); 387 little_endian_store_16(request, 5, uuid16); 388 389 return gatt_client_send(gatt_client, 7); 390 } 391 392 // precondition: can_send_packet_now == TRUE 393 static uint8_t 394 att_read_by_type_or_group_request_for_uuid128(gatt_client_t *gatt_client, uint8_t request_type, const uint8_t *uuid128, 395 uint16_t start_handle, uint16_t end_handle) { 396 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 397 398 request[0] = request_type; 399 little_endian_store_16(request, 1, start_handle); 400 little_endian_store_16(request, 3, end_handle); 401 reverse_128(uuid128, &request[5]); 402 403 return gatt_client_send(gatt_client, 21); 404 } 405 406 // precondition: can_send_packet_now == TRUE 407 static uint8_t att_read_request(gatt_client_t *gatt_client, uint8_t request_type, uint16_t attribute_handle) { 408 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 409 410 request[0] = request_type; 411 little_endian_store_16(request, 1, attribute_handle); 412 413 return gatt_client_send(gatt_client, 3); 414 } 415 416 // precondition: can_send_packet_now == TRUE 417 static uint8_t att_read_blob_request(gatt_client_t *gatt_client, uint8_t request_type, uint16_t attribute_handle, 418 uint16_t value_offset) { 419 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 420 421 request[0] = request_type; 422 little_endian_store_16(request, 1, attribute_handle); 423 little_endian_store_16(request, 3, value_offset); 424 425 return gatt_client_send(gatt_client, 5); 426 } 427 428 static uint8_t 429 att_read_multiple_request_with_opcode(gatt_client_t *gatt_client, uint16_t num_value_handles, uint16_t *value_handles, uint8_t opcode) { 430 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 431 432 request[0] = opcode; 433 uint16_t i; 434 uint16_t offset = 1; 435 for (i=0;i<num_value_handles;i++){ 436 little_endian_store_16(request, offset, value_handles[i]); 437 offset += 2; 438 } 439 440 return gatt_client_send(gatt_client, offset); 441 } 442 443 static uint8_t 444 att_read_multiple_request(gatt_client_t *gatt_client, uint16_t num_value_handles, uint16_t *value_handles) { 445 return att_read_multiple_request_with_opcode(gatt_client, num_value_handles, value_handles, ATT_READ_MULTIPLE_REQUEST); 446 } 447 448 #ifdef ENABLE_GATT_OVER_EATT 449 static uint8_t 450 att_read_multiple_variable_request(gatt_client_t *gatt_client, uint16_t num_value_handles, uint16_t *value_handles) { 451 return att_read_multiple_request_with_opcode(gatt_client, num_value_handles, value_handles, ATT_READ_MULTIPLE_VARIABLE_REQ); 452 } 453 #endif 454 455 #ifdef ENABLE_LE_SIGNED_WRITE 456 // precondition: can_send_packet_now == TRUE 457 static uint8_t att_signed_write_request(gatt_client_t *gatt_client, uint16_t request_type, uint16_t attribute_handle, 458 uint16_t value_length, uint8_t *value, uint32_t sign_counter, uint8_t sgn[8]) { 459 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 460 461 request[0] = request_type; 462 little_endian_store_16(request, 1, attribute_handle); 463 (void)memcpy(&request[3], value, value_length); 464 little_endian_store_32(request, 3 + value_length, sign_counter); 465 reverse_64(sgn, &request[3 + value_length + 4]); 466 467 return gatt_client_send(gatt_client, 3 + value_length + 12); 468 } 469 #endif 470 471 // precondition: can_send_packet_now == TRUE 472 static uint8_t 473 att_write_request(gatt_client_t *gatt_client, uint8_t request_type, uint16_t attribute_handle, uint16_t value_length, 474 uint8_t *value) { 475 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 476 477 request[0] = request_type; 478 little_endian_store_16(request, 1, attribute_handle); 479 (void)memcpy(&request[3], value, value_length); 480 481 return gatt_client_send(gatt_client, 3u + value_length); 482 } 483 484 // precondition: can_send_packet_now == TRUE 485 static uint8_t att_execute_write_request(gatt_client_t *gatt_client, uint8_t request_type, uint8_t execute_write) { 486 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 487 488 request[0] = request_type; 489 request[1] = execute_write; 490 491 return gatt_client_send(gatt_client, 2); 492 } 493 494 // precondition: can_send_packet_now == TRUE 495 static uint8_t att_prepare_write_request(gatt_client_t *gatt_client, uint8_t request_type, uint16_t attribute_handle, 496 uint16_t value_offset, uint16_t blob_length, uint8_t *value) { 497 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 498 499 request[0] = request_type; 500 little_endian_store_16(request, 1, attribute_handle); 501 little_endian_store_16(request, 3, value_offset); 502 (void)memcpy(&request[5], &value[value_offset], blob_length); 503 504 return gatt_client_send(gatt_client, 5u + blob_length); 505 } 506 507 static uint8_t att_exchange_mtu_request(gatt_client_t *gatt_client) { 508 uint8_t *request = gatt_client_reserve_request_buffer(gatt_client); 509 510 request[0] = ATT_EXCHANGE_MTU_REQUEST; 511 uint16_t mtu = l2cap_max_le_mtu(); 512 little_endian_store_16(request, 1, mtu); 513 514 return gatt_client_send(gatt_client, 3); 515 } 516 517 static uint16_t write_blob_length(gatt_client_t * gatt_client){ 518 uint16_t max_blob_length = gatt_client->mtu - 5u; 519 if (gatt_client->attribute_offset >= gatt_client->attribute_length) { 520 return 0; 521 } 522 uint16_t rest_length = gatt_client->attribute_length - gatt_client->attribute_offset; 523 if (max_blob_length > rest_length){ 524 return rest_length; 525 } 526 return max_blob_length; 527 } 528 529 static void send_gatt_services_request(gatt_client_t *gatt_client){ 530 att_read_by_type_or_group_request_for_uuid16(gatt_client, ATT_READ_BY_GROUP_TYPE_REQUEST, 531 gatt_client->uuid16, gatt_client->start_group_handle, 532 gatt_client->end_group_handle); 533 } 534 535 static void send_gatt_by_uuid_request(gatt_client_t *gatt_client, uint16_t attribute_group_type){ 536 if (gatt_client->uuid16 != 0u){ 537 uint8_t uuid16[2]; 538 little_endian_store_16(uuid16, 0, gatt_client->uuid16); 539 att_find_by_type_value_request(gatt_client, ATT_FIND_BY_TYPE_VALUE_REQUEST, attribute_group_type, 540 gatt_client->start_group_handle, gatt_client->end_group_handle, uuid16, 2); 541 return; 542 } 543 uint8_t uuid128[16]; 544 reverse_128(gatt_client->uuid128, uuid128); 545 att_find_by_type_value_request(gatt_client, ATT_FIND_BY_TYPE_VALUE_REQUEST, attribute_group_type, 546 gatt_client->start_group_handle, gatt_client->end_group_handle, uuid128, 16); 547 } 548 549 static void send_gatt_services_by_uuid_request(gatt_client_t *gatt_client){ 550 send_gatt_by_uuid_request(gatt_client, GATT_PRIMARY_SERVICE_UUID); 551 } 552 553 static void send_gatt_included_service_uuid_request(gatt_client_t *gatt_client){ 554 att_read_request(gatt_client, ATT_READ_REQUEST, gatt_client->query_start_handle); 555 } 556 557 static void send_gatt_included_service_request(gatt_client_t *gatt_client){ 558 att_read_by_type_or_group_request_for_uuid16(gatt_client, ATT_READ_BY_TYPE_REQUEST, 559 GATT_INCLUDE_SERVICE_UUID, gatt_client->start_group_handle, 560 gatt_client->end_group_handle); 561 } 562 563 static void send_gatt_characteristic_request(gatt_client_t *gatt_client){ 564 att_read_by_type_or_group_request_for_uuid16(gatt_client, ATT_READ_BY_TYPE_REQUEST, 565 GATT_CHARACTERISTICS_UUID, gatt_client->start_group_handle, 566 gatt_client->end_group_handle); 567 } 568 569 static void send_gatt_characteristic_descriptor_request(gatt_client_t *gatt_client){ 570 att_find_information_request(gatt_client, ATT_FIND_INFORMATION_REQUEST, gatt_client->start_group_handle, 571 gatt_client->end_group_handle); 572 } 573 574 static void send_gatt_read_characteristic_value_request(gatt_client_t *gatt_client){ 575 att_read_request(gatt_client, ATT_READ_REQUEST, gatt_client->attribute_handle); 576 } 577 578 static void send_gatt_read_by_type_request(gatt_client_t * gatt_client){ 579 if (gatt_client->uuid16 != 0u){ 580 att_read_by_type_or_group_request_for_uuid16(gatt_client, ATT_READ_BY_TYPE_REQUEST, 581 gatt_client->uuid16, gatt_client->start_group_handle, 582 gatt_client->end_group_handle); 583 } else { 584 att_read_by_type_or_group_request_for_uuid128(gatt_client, ATT_READ_BY_TYPE_REQUEST, 585 gatt_client->uuid128, gatt_client->start_group_handle, 586 gatt_client->end_group_handle); 587 } 588 } 589 590 static void send_gatt_read_blob_request(gatt_client_t *gatt_client){ 591 if (gatt_client->attribute_offset == 0){ 592 att_read_request(gatt_client, ATT_READ_REQUEST, gatt_client->attribute_handle); 593 } else { 594 att_read_blob_request(gatt_client, ATT_READ_BLOB_REQUEST, gatt_client->attribute_handle, 595 gatt_client->attribute_offset); 596 } 597 } 598 599 static void send_gatt_read_multiple_request(gatt_client_t * gatt_client){ 600 att_read_multiple_request(gatt_client, gatt_client->read_multiple_handle_count, gatt_client->read_multiple_handles); 601 } 602 603 #ifdef ENABLE_GATT_OVER_EATT 604 static void send_gatt_read_multiple_variable_request(gatt_client_t * gatt_client){ 605 att_read_multiple_variable_request(gatt_client, gatt_client->read_multiple_handle_count, gatt_client->read_multiple_handles); 606 } 607 #endif 608 609 static void send_gatt_write_attribute_value_request(gatt_client_t * gatt_client){ 610 att_write_request(gatt_client, ATT_WRITE_REQUEST, gatt_client->attribute_handle, gatt_client->attribute_length, 611 gatt_client->attribute_value); 612 } 613 614 static void send_gatt_write_client_characteristic_configuration_request(gatt_client_t * gatt_client){ 615 att_write_request(gatt_client, ATT_WRITE_REQUEST, gatt_client->client_characteristic_configuration_handle, 2, 616 gatt_client->client_characteristic_configuration_value); 617 } 618 619 static void send_gatt_prepare_write_request(gatt_client_t * gatt_client){ 620 att_prepare_write_request(gatt_client, ATT_PREPARE_WRITE_REQUEST, gatt_client->attribute_handle, 621 gatt_client->attribute_offset, write_blob_length(gatt_client), 622 gatt_client->attribute_value); 623 } 624 625 static void send_gatt_execute_write_request(gatt_client_t * gatt_client){ 626 att_execute_write_request(gatt_client, ATT_EXECUTE_WRITE_REQUEST, 1); 627 } 628 629 static void send_gatt_cancel_prepared_write_request(gatt_client_t * gatt_client){ 630 att_execute_write_request(gatt_client, ATT_EXECUTE_WRITE_REQUEST, 0); 631 } 632 633 #ifndef ENABLE_GATT_FIND_INFORMATION_FOR_CCC_DISCOVERY 634 static void send_gatt_read_client_characteristic_configuration_request(gatt_client_t * gatt_client){ 635 att_read_by_type_or_group_request_for_uuid16(gatt_client, ATT_READ_BY_TYPE_REQUEST, 636 GATT_CLIENT_CHARACTERISTICS_CONFIGURATION, 637 gatt_client->start_group_handle, gatt_client->end_group_handle); 638 } 639 #endif 640 641 static void send_gatt_read_characteristic_descriptor_request(gatt_client_t * gatt_client){ 642 att_read_request(gatt_client, ATT_READ_REQUEST, gatt_client->attribute_handle); 643 } 644 645 #ifdef ENABLE_LE_SIGNED_WRITE 646 static void send_gatt_signed_write_request(gatt_client_t * gatt_client, uint32_t sign_counter){ 647 att_signed_write_request(gatt_client, ATT_SIGNED_WRITE_COMMAND, gatt_client->attribute_handle, 648 gatt_client->attribute_length, gatt_client->attribute_value, sign_counter, 649 gatt_client->cmac); 650 } 651 #endif 652 653 static uint16_t get_last_result_handle_from_service_list(uint8_t * packet, uint16_t size){ 654 if (size < 2) return 0xffff; 655 uint8_t attr_length = packet[1]; 656 if ((2 + attr_length) > size) return 0xffff; 657 return little_endian_read_16(packet, size - attr_length + 2u); 658 } 659 660 static uint16_t get_last_result_handle_from_characteristics_list(uint8_t * packet, uint16_t size){ 661 if (size < 2) return 0xffff; 662 uint8_t attr_length = packet[1]; 663 if ((2 + attr_length) > size) return 0xffff; 664 return little_endian_read_16(packet, size - attr_length + 3u); 665 } 666 667 static uint16_t get_last_result_handle_from_included_services_list(uint8_t * packet, uint16_t size){ 668 if (size < 2) return 0xffff; 669 uint8_t attr_length = packet[1]; 670 if ((2 + attr_length) > size) return 0xffff; 671 return little_endian_read_16(packet, size - attr_length); 672 } 673 674 #ifdef ENABLE_GATT_CLIENT_SERVICE_CHANGED 675 static void gatt_client_service_emit_event(gatt_client_t * gatt_client, uint8_t * event, uint16_t size){ 676 btstack_linked_list_iterator_t it; 677 btstack_linked_list_iterator_init(&it, &gatt_client_service_changed_handler); 678 while (btstack_linked_list_iterator_has_next(&it)) { 679 btstack_packet_callback_registration_t *callback = (btstack_packet_callback_registration_t *) btstack_linked_list_iterator_next(&it); 680 (*callback->callback)(HCI_EVENT_PACKET, (uint16_t) gatt_client->con_handle, event, size); 681 } 682 } 683 684 static void 685 gatt_client_service_emit_database_hash(gatt_client_t *gatt_client, const uint8_t *value, uint16_t value_len) { 686 if (value_len == 16){ 687 uint8_t event[21]; 688 hci_event_builder_context_t context; 689 hci_event_builder_init(&context, event, sizeof(event), HCI_EVENT_GATTSERVICE_META, GATTSERVICE_SUBEVENT_GATT_DATABASE_HASH); 690 hci_event_builder_add_con_handle(&context, gatt_client->con_handle); 691 hci_event_builder_add_bytes(&context, value, 16); 692 gatt_client_service_emit_event(gatt_client, event, hci_event_builder_get_length(&context)); 693 } 694 } 695 696 static void 697 gatt_client_service_emit_service_changed(gatt_client_t *gatt_client, const uint8_t *value, uint16_t value_len) { 698 if (value_len == 4){ 699 uint8_t event[9]; 700 hci_event_builder_context_t context; 701 hci_event_builder_init(&context, event, sizeof(event), HCI_EVENT_GATTSERVICE_META, GATTSERVICE_SUBEVENT_GATT_SERVICE_CHANGED); 702 hci_event_builder_add_con_handle(&context, gatt_client->con_handle); 703 hci_event_builder_add_bytes(&context, value, 4); 704 gatt_client_service_emit_event(gatt_client, event, hci_event_builder_get_length(&context)); 705 } 706 } 707 708 static void gatt_client_service_packet_handler(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size){ 709 UNUSED(channel); // ok: handling own l2cap events 710 UNUSED(size); // ok: there is no channel 711 712 hci_con_handle_t con_handle; 713 gatt_client_t *gatt_client; 714 gatt_client_service_t service; 715 gatt_client_characteristic_t characteristic; 716 switch (packet_type) { 717 case HCI_EVENT_PACKET: 718 switch (hci_event_packet_get_type(packet)) { 719 case GATT_EVENT_SERVICE_QUERY_RESULT: 720 con_handle = gatt_event_service_query_result_get_handle(packet); 721 gatt_client = gatt_client_get_context_for_handle(con_handle); 722 btstack_assert(gatt_client != NULL); 723 btstack_assert(gatt_client->gatt_service_state == GATT_CLIENT_SERVICE_DISCOVER_W4_DONE); 724 gatt_event_service_query_result_get_service(packet, &service); 725 gatt_client->gatt_service_start_group_handle = service.start_group_handle; 726 gatt_client->gatt_service_end_group_handle = service.end_group_handle; 727 break; 728 case GATT_EVENT_CHARACTERISTIC_QUERY_RESULT: 729 con_handle = gatt_event_characteristic_query_result_get_handle(packet); 730 gatt_client = gatt_client_get_context_for_handle(con_handle); 731 btstack_assert(gatt_client != NULL); 732 btstack_assert(gatt_client->gatt_service_state == GATT_CLIENT_SERVICE_DISCOVER_CHARACTERISTICS_W4_DONE); 733 gatt_event_characteristic_query_result_get_characteristic(packet, &characteristic); 734 switch (characteristic.uuid16){ 735 case ORG_BLUETOOTH_CHARACTERISTIC_GATT_SERVICE_CHANGED: 736 gatt_client->gatt_service_changed_value_handle = characteristic.value_handle; 737 gatt_client->gatt_service_changed_end_handle = characteristic.end_handle; 738 break; 739 case ORG_BLUETOOTH_CHARACTERISTIC_DATABASE_HASH: 740 gatt_client->gatt_service_database_hash_value_handle = characteristic.value_handle; 741 gatt_client->gatt_service_database_hash_end_handle = characteristic.end_handle; 742 break; 743 default: 744 break; 745 } 746 break; 747 case GATT_EVENT_CHARACTERISTIC_VALUE_QUERY_RESULT: 748 con_handle = gatt_event_characteristic_value_query_result_get_handle(packet); 749 gatt_client = gatt_client_get_context_for_handle(con_handle); 750 btstack_assert(gatt_client != NULL); 751 btstack_assert(gatt_client->gatt_service_state == GATT_CLIENT_SERVICE_DATABASE_HASH_READ_W4_DONE); 752 gatt_client_service_emit_database_hash(gatt_client, 753 gatt_event_characteristic_value_query_result_get_value(packet), 754 gatt_event_characteristic_value_query_result_get_value_length(packet)); 755 break; 756 case GATT_EVENT_QUERY_COMPLETE: 757 con_handle = gatt_event_query_complete_get_handle(packet); 758 gatt_client = gatt_client_get_context_for_handle(con_handle); 759 btstack_assert(gatt_client != NULL); 760 switch (gatt_client->gatt_service_state) { 761 case GATT_CLIENT_SERVICE_DISCOVER_W4_DONE: 762 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DISCOVER_CHARACTERISTICS_W2_SEND; 763 break; 764 case GATT_CLIENT_SERVICE_DISCOVER_CHARACTERISTICS_W4_DONE: 765 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_SERVICE_CHANGED_WRITE_CCCD_W2_SEND; 766 break; 767 case GATT_CLIENT_SERVICE_SERVICE_CHANGED_WRITE_CCCD_W4_DONE: 768 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DATABASE_HASH_READ_W2_SEND; 769 break; 770 case GATT_CLIENT_SERVICE_DATABASE_HASH_READ_W4_DONE: 771 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DATABASE_HASH_WRITE_CCCD_W2_SEND; 772 break; 773 case GATT_CLIENT_SERVICE_DATABASE_HASH_WRITE_CCCD_W4_DONE: 774 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DONE; 775 break; 776 default: 777 btstack_unreachable(); 778 break; 779 } 780 break; 781 default: 782 break; 783 } 784 break; 785 default: 786 break; 787 } 788 } 789 #endif 790 791 static void gatt_client_notify_can_send_query(gatt_client_t * gatt_client){ 792 793 #ifdef ENABLE_GATT_OVER_EATT 794 // if eatt is ready, notify all clients that can send a query 795 if (gatt_client->eatt_state == GATT_CLIENT_EATT_READY){ 796 btstack_linked_list_iterator_t it; 797 btstack_linked_list_iterator_init(&it, &gatt_client->eatt_clients); 798 while (btstack_linked_list_iterator_has_next(&it)){ 799 gatt_client_t * client = (gatt_client_t *) btstack_linked_list_iterator_next(&it); 800 if (client->state == P_READY){ 801 // call callback 802 btstack_context_callback_registration_t * callback = (btstack_context_callback_registration_t *) btstack_linked_list_pop(&gatt_client->query_requests); 803 if (callback == NULL) { 804 return; 805 } 806 (*callback->callback)(callback->context); 807 } 808 } 809 return; 810 } 811 #endif 812 813 while (gatt_client->state == P_READY){ 814 bool query_sent = false; 815 UNUSED(query_sent); 816 817 #ifdef ENABLE_GATT_CLIENT_SERVICE_CHANGED 818 uint8_t status = ERROR_CODE_SUCCESS; 819 gatt_client_service_t gatt_service; 820 gatt_client_characteristic_t characteristic; 821 switch (gatt_client->gatt_service_state){ 822 case GATT_CLIENT_SERVICE_DISCOVER_W2_SEND: 823 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DISCOVER_W4_DONE; 824 status = gatt_client_discover_primary_services_by_uuid16(&gatt_client_service_packet_handler, 825 gatt_client->con_handle, 826 ORG_BLUETOOTH_SERVICE_GENERIC_ATTRIBUTE); 827 query_sent = true; 828 break; 829 case GATT_CLIENT_SERVICE_DISCOVER_CHARACTERISTICS_W2_SEND: 830 if (gatt_client->gatt_service_start_group_handle != 0){ 831 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DISCOVER_CHARACTERISTICS_W4_DONE; 832 gatt_service.start_group_handle = gatt_client->gatt_service_start_group_handle; 833 gatt_service.end_group_handle = gatt_client->gatt_service_end_group_handle; 834 status = gatt_client_discover_characteristics_for_service(&gatt_client_service_packet_handler, gatt_client->con_handle, &gatt_service); 835 query_sent = true; 836 break; 837 } 838 839 /* fall through */ 840 841 case GATT_CLIENT_SERVICE_SERVICE_CHANGED_WRITE_CCCD_W2_SEND: 842 if (gatt_client->gatt_service_changed_value_handle != 0){ 843 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_SERVICE_CHANGED_WRITE_CCCD_W4_DONE; 844 characteristic.value_handle = gatt_client->gatt_service_changed_value_handle; 845 characteristic.end_handle = gatt_client->gatt_service_changed_end_handle; 846 // we assume good case. We cannot do much otherwise 847 characteristic.properties = ATT_PROPERTY_INDICATE; 848 status = gatt_client_write_client_characteristic_configuration(&gatt_client_service_packet_handler, 849 gatt_client->con_handle, &characteristic, 850 GATT_CLIENT_CHARACTERISTICS_CONFIGURATION_INDICATION); 851 query_sent = true; 852 break; 853 } 854 855 /* fall through */ 856 857 case GATT_CLIENT_SERVICE_DATABASE_HASH_READ_W2_SEND: 858 if (gatt_client->gatt_service_database_hash_value_handle != 0){ 859 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DATABASE_HASH_READ_W4_DONE; 860 status = gatt_client_read_value_of_characteristics_by_uuid16(&gatt_client_service_packet_handler, 861 gatt_client->con_handle, 862 0x0001, 0xffff, ORG_BLUETOOTH_CHARACTERISTIC_DATABASE_HASH); 863 query_sent = true; 864 break; 865 } 866 867 /* fall through */ 868 869 case GATT_CLIENT_SERVICE_DATABASE_HASH_WRITE_CCCD_W2_SEND: 870 if (gatt_client->gatt_service_database_hash_value_handle != 0) { 871 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DATABASE_HASH_WRITE_CCCD_W4_DONE; 872 characteristic.value_handle = gatt_client->gatt_service_database_hash_value_handle; 873 characteristic.end_handle = gatt_client->gatt_service_database_hash_end_handle; 874 // we assume good case. We cannot do much otherwise 875 characteristic.properties = ATT_PROPERTY_INDICATE; 876 status = gatt_client_write_client_characteristic_configuration(&gatt_client_service_packet_handler, 877 gatt_client->con_handle, 878 &characteristic, 879 GATT_CLIENT_CHARACTERISTICS_CONFIGURATION_INDICATION); 880 query_sent = true; 881 break; 882 } 883 884 // DONE 885 gatt_client->gatt_service_state = GATT_CLIENT_SERVICE_DONE; 886 break; 887 default: 888 break; 889 } 890 btstack_assert(status == ERROR_CODE_SUCCESS); 891 UNUSED(status); 892 if (query_sent){ 893 continue; 894 } 895 #endif 896 897 #ifdef ENABLE_GATT_OVER_EATT 898 query_sent = gatt_client_le_enhanced_handle_can_send_query(gatt_client); 899 if (query_sent){ 900 continue; 901 } 902 #endif 903 btstack_context_callback_registration_t * callback = (btstack_context_callback_registration_t *) btstack_linked_list_pop(&gatt_client->query_requests); 904 if (callback == NULL) { 905 return; 906 } 907 (*callback->callback)(callback->context); 908 } 909 } 910 911 // test if notification/indication should be delivered to application (BLESA) 912 static bool gatt_client_accept_server_message(gatt_client_t *gatt_client) { 913 // ignore messages until re-encryption is complete 914 if (gap_reconnect_security_setup_active(gatt_client->con_handle)) return false; 915 916 // after that ignore if bonded but not encrypted 917 return !gap_bonded(gatt_client->con_handle) || (gap_encryption_key_size(gatt_client->con_handle) > 0); 918 } 919 920 static void emit_event_new(btstack_packet_handler_t callback, uint8_t * packet, uint16_t size){ 921 if (!callback) return; 922 hci_dump_btstack_event(packet, size); 923 (*callback)(HCI_EVENT_PACKET, 0, packet, size); 924 } 925 926 static void emit_event_to_registered_listeners(hci_con_handle_t con_handle, uint16_t attribute_handle, uint8_t * packet, uint16_t size){ 927 btstack_linked_list_iterator_t it; 928 btstack_linked_list_iterator_init(&it, &gatt_client_value_listeners); 929 while (btstack_linked_list_iterator_has_next(&it)){ 930 gatt_client_notification_t * notification = (gatt_client_notification_t*) btstack_linked_list_iterator_next(&it); 931 if ((notification->con_handle != GATT_CLIENT_ANY_CONNECTION) && (notification->con_handle != con_handle)) continue; 932 if ((notification->attribute_handle != GATT_CLIENT_ANY_VALUE_HANDLE) && (notification->attribute_handle != attribute_handle)) continue; 933 (*notification->callback)(HCI_EVENT_PACKET, 0, packet, size); 934 } 935 } 936 937 static void emit_gatt_complete_event(gatt_client_t * gatt_client, uint8_t att_status){ 938 // @format H1 939 uint8_t packet[5]; 940 packet[0] = GATT_EVENT_QUERY_COMPLETE; 941 packet[1] = 3; 942 little_endian_store_16(packet, 2, gatt_client->con_handle); 943 packet[4] = att_status; 944 emit_event_new(gatt_client->callback, packet, sizeof(packet)); 945 } 946 947 static void emit_gatt_service_query_result_event(gatt_client_t * gatt_client, uint16_t start_group_handle, uint16_t end_group_handle, const uint8_t * uuid128){ 948 // @format HX 949 uint8_t packet[24]; 950 packet[0] = GATT_EVENT_SERVICE_QUERY_RESULT; 951 packet[1] = sizeof(packet) - 2u; 952 little_endian_store_16(packet, 2, gatt_client->con_handle); 953 /// 954 little_endian_store_16(packet, 4, start_group_handle); 955 little_endian_store_16(packet, 6, end_group_handle); 956 reverse_128(uuid128, &packet[8]); 957 emit_event_new(gatt_client->callback, packet, sizeof(packet)); 958 } 959 960 static void emit_gatt_included_service_query_result_event(gatt_client_t * gatt_client, uint16_t include_handle, uint16_t start_group_handle, uint16_t end_group_handle, const uint8_t * uuid128){ 961 // @format HX 962 uint8_t packet[26]; 963 packet[0] = GATT_EVENT_INCLUDED_SERVICE_QUERY_RESULT; 964 packet[1] = sizeof(packet) - 2u; 965 little_endian_store_16(packet, 2, gatt_client->con_handle); 966 /// 967 little_endian_store_16(packet, 4, include_handle); 968 // 969 little_endian_store_16(packet, 6, start_group_handle); 970 little_endian_store_16(packet, 8, end_group_handle); 971 reverse_128(uuid128, &packet[10]); 972 emit_event_new(gatt_client->callback, packet, sizeof(packet)); 973 } 974 975 static void emit_gatt_characteristic_query_result_event(gatt_client_t * gatt_client, uint16_t start_handle, uint16_t value_handle, uint16_t end_handle, 976 uint16_t properties, const uint8_t * uuid128){ 977 // @format HY 978 uint8_t packet[28]; 979 packet[0] = GATT_EVENT_CHARACTERISTIC_QUERY_RESULT; 980 packet[1] = sizeof(packet) - 2u; 981 little_endian_store_16(packet, 2, gatt_client->con_handle); 982 /// 983 little_endian_store_16(packet, 4, start_handle); 984 little_endian_store_16(packet, 6, value_handle); 985 little_endian_store_16(packet, 8, end_handle); 986 little_endian_store_16(packet, 10, properties); 987 reverse_128(uuid128, &packet[12]); 988 emit_event_new(gatt_client->callback, packet, sizeof(packet)); 989 } 990 991 static void emit_gatt_all_characteristic_descriptors_result_event( 992 gatt_client_t * gatt_client, uint16_t descriptor_handle, const uint8_t * uuid128){ 993 // @format HZ 994 uint8_t packet[22]; 995 packet[0] = GATT_EVENT_ALL_CHARACTERISTIC_DESCRIPTORS_QUERY_RESULT; 996 packet[1] = sizeof(packet) - 2u; 997 little_endian_store_16(packet, 2, gatt_client->con_handle); 998 /// 999 little_endian_store_16(packet, 4, descriptor_handle); 1000 reverse_128(uuid128, &packet[6]); 1001 emit_event_new(gatt_client->callback, packet, sizeof(packet)); 1002 } 1003 1004 static void emit_gatt_mtu_exchanged_result_event(gatt_client_t * gatt_client, uint16_t new_mtu){ 1005 // @format H2 1006 uint8_t packet[6]; 1007 packet[0] = GATT_EVENT_MTU; 1008 packet[1] = sizeof(packet) - 2u; 1009 little_endian_store_16(packet, 2, gatt_client->con_handle); 1010 little_endian_store_16(packet, 4, new_mtu); 1011 att_dispatch_client_mtu_exchanged(gatt_client->con_handle, new_mtu); 1012 emit_event_new(gatt_client->callback, packet, sizeof(packet)); 1013 } 1014 1015 // helper 1016 static void gatt_client_handle_transaction_complete(gatt_client_t *gatt_client, uint8_t att_status) { 1017 gatt_client->state = P_READY; 1018 gatt_client_timeout_stop(gatt_client); 1019 emit_gatt_complete_event(gatt_client, att_status); 1020 gatt_client_notify_can_send_query(gatt_client); 1021 } 1022 1023 // @return packet pointer 1024 // @note assume that value is part of an l2cap buffer - overwrite HCI + L2CAP packet headers 1025 #define CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE 8 1026 static uint8_t * setup_characteristic_value_packet(uint8_t type, hci_con_handle_t con_handle, uint16_t attribute_handle, uint8_t * value, uint16_t length){ 1027 #ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION 1028 // copy value into test packet for testing 1029 static uint8_t packet[1000]; 1030 memcpy(&packet[8], value, length); 1031 #else 1032 // before the value inside the ATT PDU 1033 uint8_t * packet = value - CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE; 1034 #endif 1035 packet[0] = type; 1036 packet[1] = CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE - 2 + length; 1037 little_endian_store_16(packet, 2, con_handle); 1038 little_endian_store_16(packet, 4, attribute_handle); 1039 little_endian_store_16(packet, 6, length); 1040 return packet; 1041 } 1042 1043 // @return packet pointer 1044 // @note assume that value is part of an l2cap buffer - overwrite parts of the HCI/L2CAP/ATT packet (4/4/3) bytes 1045 #define LONG_CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE 10 1046 static uint8_t * setup_long_characteristic_value_packet(uint8_t type, hci_con_handle_t con_handle, uint16_t attribute_handle, uint16_t offset, uint8_t * value, uint16_t length){ 1047 #ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION 1048 // avoid using pre ATT headers. 1049 return NULL; 1050 #endif 1051 #if defined(HCI_INCOMING_PRE_BUFFER_SIZE) && (HCI_INCOMING_PRE_BUFFER_SIZE >= LONG_CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE - 8) // L2CAP Header (4) - ACL Header (4) 1052 // before the value inside the ATT PDU 1053 uint8_t * packet = value - LONG_CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE; 1054 packet[0] = type; 1055 packet[1] = LONG_CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE - 2 + length; 1056 little_endian_store_16(packet, 2, con_handle); 1057 little_endian_store_16(packet, 4, attribute_handle); 1058 little_endian_store_16(packet, 6, offset); 1059 little_endian_store_16(packet, 8, length); 1060 return packet; 1061 #else 1062 log_error("HCI_INCOMING_PRE_BUFFER_SIZE >= 2 required for long characteristic reads"); 1063 return NULL; 1064 #endif 1065 } 1066 1067 #if (LONG_CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE > CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE) 1068 #define REPORT_PREBUFFER_HEADER LONG_CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE 1069 #else 1070 #define REPORT_PREBUFFER_HEADER CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE 1071 #endif 1072 1073 /// 1074 static void report_gatt_services(gatt_client_t * gatt_client, uint8_t * packet, uint16_t size){ 1075 if (size < 2) return; 1076 uint8_t attr_length = packet[1]; 1077 uint8_t uuid_length = attr_length - 4u; 1078 1079 int i; 1080 for (i = 2; (i+attr_length) <= size; i += attr_length){ 1081 uint16_t start_group_handle = little_endian_read_16(packet,i); 1082 uint16_t end_group_handle = little_endian_read_16(packet,i+2); 1083 uint8_t uuid128[16]; 1084 uint16_t uuid16 = 0; 1085 1086 if (uuid_length == 2u){ 1087 uuid16 = little_endian_read_16(packet, i+4); 1088 uuid_add_bluetooth_prefix((uint8_t*) &uuid128, uuid16); 1089 } else if (uuid_length == 16u) { 1090 reverse_128(&packet[i+4], uuid128); 1091 } else { 1092 return; 1093 } 1094 emit_gatt_service_query_result_event(gatt_client, start_group_handle, end_group_handle, uuid128); 1095 } 1096 } 1097 1098 static void report_gatt_characteristic_start_found(gatt_client_t * gatt_client, uint16_t start_handle, uint8_t properties, uint16_t value_handle, uint8_t * uuid, uint16_t uuid_length){ 1099 uint8_t uuid128[16]; 1100 uint16_t uuid16 = 0; 1101 if (uuid_length == 2u){ 1102 uuid16 = little_endian_read_16(uuid, 0); 1103 uuid_add_bluetooth_prefix((uint8_t*) uuid128, uuid16); 1104 } else if (uuid_length == 16u){ 1105 reverse_128(uuid, uuid128); 1106 } else { 1107 return; 1108 } 1109 1110 if (gatt_client->filter_with_uuid && (memcmp(gatt_client->uuid128, uuid128, 16) != 0)) return; 1111 1112 gatt_client->characteristic_properties = properties; 1113 gatt_client->characteristic_start_handle = start_handle; 1114 gatt_client->attribute_handle = value_handle; 1115 1116 if (gatt_client->filter_with_uuid) return; 1117 1118 gatt_client->uuid16 = uuid16; 1119 (void)memcpy(gatt_client->uuid128, uuid128, 16); 1120 } 1121 1122 static void report_gatt_characteristic_end_found(gatt_client_t * gatt_client, uint16_t end_handle){ 1123 // TODO: stop searching if filter and uuid found 1124 1125 if (!gatt_client->characteristic_start_handle) return; 1126 1127 emit_gatt_characteristic_query_result_event(gatt_client, gatt_client->characteristic_start_handle, gatt_client->attribute_handle, 1128 end_handle, gatt_client->characteristic_properties, gatt_client->uuid128); 1129 1130 gatt_client->characteristic_start_handle = 0; 1131 } 1132 1133 1134 static void report_gatt_characteristics(gatt_client_t * gatt_client, uint8_t * packet, uint16_t size){ 1135 if (size < 2u) return; 1136 uint8_t attr_length = packet[1]; 1137 if ((attr_length != 7u) && (attr_length != 21u)) return; 1138 uint8_t uuid_length = attr_length - 5u; 1139 int i; 1140 for (i = 2u; (i + attr_length) <= size; i += attr_length){ 1141 uint16_t start_handle = little_endian_read_16(packet, i); 1142 uint8_t properties = packet[i+2]; 1143 uint16_t value_handle = little_endian_read_16(packet, i+3); 1144 report_gatt_characteristic_end_found(gatt_client, start_handle - 1u); 1145 report_gatt_characteristic_start_found(gatt_client, start_handle, properties, value_handle, &packet[i + 5], 1146 uuid_length); 1147 } 1148 } 1149 1150 static void report_gatt_included_service_uuid16(gatt_client_t * gatt_client, uint16_t include_handle, uint16_t uuid16){ 1151 uint8_t normalized_uuid128[16]; 1152 uuid_add_bluetooth_prefix(normalized_uuid128, uuid16); 1153 emit_gatt_included_service_query_result_event(gatt_client, include_handle, gatt_client->query_start_handle, 1154 gatt_client->query_end_handle, normalized_uuid128); 1155 } 1156 1157 static void report_gatt_included_service_uuid128(gatt_client_t * gatt_client, uint16_t include_handle, const uint8_t * uuid128){ 1158 emit_gatt_included_service_query_result_event(gatt_client, include_handle, gatt_client->query_start_handle, 1159 gatt_client->query_end_handle, uuid128); 1160 } 1161 1162 // @note assume that value is part of an l2cap buffer - overwrite parts of the HCI/L2CAP/ATT packet (4/4/3) bytes 1163 static void report_gatt_notification(gatt_client_t *gatt_client, uint16_t value_handle, uint8_t *value, int length) { 1164 if (!gatt_client_accept_server_message(gatt_client)) return; 1165 uint8_t * packet = setup_characteristic_value_packet(GATT_EVENT_NOTIFICATION, gatt_client->con_handle, value_handle, value, length); 1166 emit_event_to_registered_listeners(gatt_client->con_handle, value_handle, packet, CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE + length); 1167 } 1168 1169 // @note assume that value is part of an l2cap buffer - overwrite parts of the HCI/L2CAP/ATT packet (4/4/3) bytes 1170 static void report_gatt_indication(gatt_client_t *gatt_client, uint16_t value_handle, uint8_t *value, int length) { 1171 if (!gatt_client_accept_server_message(gatt_client)) return; 1172 #ifdef ENABLE_GATT_CLIENT_SERVICE_CHANGED 1173 // Directly Handle GATT Service Changed and Database Hash indications 1174 if (value_handle == gatt_client->gatt_service_database_hash_value_handle){ 1175 gatt_client_service_emit_database_hash(gatt_client, value, length); 1176 } 1177 if (value_handle == gatt_client->gatt_service_changed_value_handle){ 1178 gatt_client_service_emit_service_changed(gatt_client, value, length); 1179 } 1180 #endif 1181 uint8_t * packet = setup_characteristic_value_packet(GATT_EVENT_INDICATION, gatt_client->con_handle, value_handle, value, length); 1182 emit_event_to_registered_listeners(gatt_client->con_handle, value_handle, packet, CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE + length); 1183 } 1184 1185 // @note assume that value is part of an l2cap buffer - overwrite parts of the HCI/L2CAP/ATT packet (4/4/3) bytes 1186 static void report_gatt_characteristic_value(gatt_client_t * gatt_client, uint16_t attribute_handle, uint8_t * value, uint16_t length){ 1187 uint8_t * packet = setup_characteristic_value_packet(GATT_EVENT_CHARACTERISTIC_VALUE_QUERY_RESULT, gatt_client->con_handle, attribute_handle, value, length); 1188 emit_event_new(gatt_client->callback, packet, CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE + length); 1189 } 1190 1191 // @note assume that value is part of an l2cap buffer - overwrite parts of the HCI/L2CAP/ATT packet (4/4/3) bytes 1192 static void report_gatt_long_characteristic_value_blob(gatt_client_t * gatt_client, uint16_t attribute_handle, uint8_t * blob, uint16_t blob_length, int value_offset){ 1193 uint8_t * packet = setup_long_characteristic_value_packet(GATT_EVENT_LONG_CHARACTERISTIC_VALUE_QUERY_RESULT, gatt_client->con_handle, attribute_handle, value_offset, blob, blob_length); 1194 if (!packet) return; 1195 emit_event_new(gatt_client->callback, packet, blob_length + LONG_CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE); 1196 } 1197 1198 static void report_gatt_characteristic_descriptor(gatt_client_t * gatt_client, uint16_t descriptor_handle, uint8_t *value, uint16_t value_length, uint16_t value_offset){ 1199 UNUSED(value_offset); 1200 uint8_t * packet = setup_characteristic_value_packet(GATT_EVENT_CHARACTERISTIC_DESCRIPTOR_QUERY_RESULT, gatt_client->con_handle, descriptor_handle, value, value_length); 1201 emit_event_new(gatt_client->callback, packet, value_length + 8u); 1202 } 1203 1204 static void report_gatt_long_characteristic_descriptor(gatt_client_t * gatt_client, uint16_t descriptor_handle, uint8_t *blob, uint16_t blob_length, uint16_t value_offset){ 1205 uint8_t * packet = setup_long_characteristic_value_packet(GATT_EVENT_LONG_CHARACTERISTIC_DESCRIPTOR_QUERY_RESULT, gatt_client->con_handle, descriptor_handle, value_offset, blob, blob_length); 1206 if (!packet) return; 1207 emit_event_new(gatt_client->callback, packet, blob_length + LONG_CHARACTERISTIC_VALUE_EVENT_HEADER_SIZE); 1208 } 1209 1210 static void report_gatt_all_characteristic_descriptors(gatt_client_t * gatt_client, uint8_t * packet, uint16_t size, uint16_t pair_size){ 1211 int i; 1212 for (i = 0u; (i + pair_size) <= size; i += pair_size){ 1213 uint16_t descriptor_handle = little_endian_read_16(packet,i); 1214 uint8_t uuid128[16]; 1215 uint16_t uuid16 = 0; 1216 if (pair_size == 4u){ 1217 uuid16 = little_endian_read_16(packet,i+2); 1218 uuid_add_bluetooth_prefix(uuid128, uuid16); 1219 } else { 1220 reverse_128(&packet[i+2], uuid128); 1221 } 1222 emit_gatt_all_characteristic_descriptors_result_event(gatt_client, descriptor_handle, uuid128); 1223 } 1224 1225 } 1226 1227 static bool is_query_done(gatt_client_t * gatt_client, uint16_t last_result_handle){ 1228 return last_result_handle >= gatt_client->end_group_handle; 1229 } 1230 1231 static void trigger_next_query(gatt_client_t * gatt_client, uint16_t last_result_handle, gatt_client_state_t next_query_state){ 1232 if (is_query_done(gatt_client, last_result_handle)){ 1233 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 1234 return; 1235 } 1236 // next 1237 gatt_client->start_group_handle = last_result_handle + 1u; 1238 gatt_client->state = next_query_state; 1239 } 1240 1241 static void trigger_next_included_service_query(gatt_client_t * gatt_client, uint16_t last_result_handle){ 1242 trigger_next_query(gatt_client, last_result_handle, P_W2_SEND_INCLUDED_SERVICE_QUERY); 1243 } 1244 1245 static void trigger_next_service_query(gatt_client_t * gatt_client, uint16_t last_result_handle){ 1246 trigger_next_query(gatt_client, last_result_handle, P_W2_SEND_SERVICE_QUERY); 1247 } 1248 1249 static void trigger_next_service_by_uuid_query(gatt_client_t * gatt_client, uint16_t last_result_handle){ 1250 trigger_next_query(gatt_client, last_result_handle, P_W2_SEND_SERVICE_WITH_UUID_QUERY); 1251 } 1252 1253 static void trigger_next_characteristic_query(gatt_client_t * gatt_client, uint16_t last_result_handle){ 1254 if (is_query_done(gatt_client, last_result_handle)){ 1255 // report last characteristic 1256 report_gatt_characteristic_end_found(gatt_client, gatt_client->end_group_handle); 1257 } 1258 trigger_next_query(gatt_client, last_result_handle, P_W2_SEND_ALL_CHARACTERISTICS_OF_SERVICE_QUERY); 1259 } 1260 1261 static void trigger_next_characteristic_descriptor_query(gatt_client_t * gatt_client, uint16_t last_result_handle){ 1262 trigger_next_query(gatt_client, last_result_handle, P_W2_SEND_ALL_CHARACTERISTIC_DESCRIPTORS_QUERY); 1263 } 1264 1265 static void trigger_next_read_by_type_query(gatt_client_t * gatt_client, uint16_t last_result_handle){ 1266 trigger_next_query(gatt_client, last_result_handle, P_W2_SEND_READ_BY_TYPE_REQUEST); 1267 } 1268 1269 static void trigger_next_prepare_write_query(gatt_client_t * gatt_client, gatt_client_state_t next_query_state, gatt_client_state_t done_state){ 1270 gatt_client->attribute_offset += write_blob_length(gatt_client); 1271 uint16_t next_blob_length = write_blob_length(gatt_client); 1272 1273 if (next_blob_length == 0u){ 1274 gatt_client->state = done_state; 1275 return; 1276 } 1277 gatt_client->state = next_query_state; 1278 } 1279 1280 static void trigger_next_blob_query(gatt_client_t * gatt_client, gatt_client_state_t next_query_state, uint16_t received_blob_length){ 1281 1282 uint16_t max_blob_length = gatt_client->mtu - 1u; 1283 if (received_blob_length < max_blob_length){ 1284 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 1285 return; 1286 } 1287 1288 gatt_client->attribute_offset += received_blob_length; 1289 gatt_client->state = next_query_state; 1290 } 1291 1292 void gatt_client_listen_for_characteristic_value_updates(gatt_client_notification_t * notification, btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_characteristic_t * characteristic){ 1293 notification->callback = callback; 1294 notification->con_handle = con_handle; 1295 if (characteristic == NULL){ 1296 notification->attribute_handle = GATT_CLIENT_ANY_VALUE_HANDLE; 1297 } else { 1298 notification->attribute_handle = characteristic->value_handle; 1299 } 1300 btstack_linked_list_add(&gatt_client_value_listeners, (btstack_linked_item_t*) notification); 1301 } 1302 1303 void gatt_client_stop_listening_for_characteristic_value_updates(gatt_client_notification_t * notification){ 1304 btstack_linked_list_remove(&gatt_client_value_listeners, (btstack_linked_item_t*) notification); 1305 } 1306 1307 static bool is_value_valid(gatt_client_t *gatt_client, uint8_t *packet, uint16_t size){ 1308 uint16_t attribute_handle = little_endian_read_16(packet, 1); 1309 uint16_t value_offset = little_endian_read_16(packet, 3); 1310 1311 if (gatt_client->attribute_handle != attribute_handle) return false; 1312 if (gatt_client->attribute_offset != value_offset) return false; 1313 return memcmp(&gatt_client->attribute_value[gatt_client->attribute_offset], &packet[5], size - 5u) == 0u; 1314 } 1315 1316 #ifdef ENABLE_LE_SIGNED_WRITE 1317 static void gatt_client_run_for_client_start_signed_write(gatt_client_t *gatt_client) { 1318 sm_key_t csrk; 1319 le_device_db_local_csrk_get(gatt_client->le_device_index, csrk); 1320 uint32_t sign_counter = le_device_db_local_counter_get(gatt_client->le_device_index); 1321 gatt_client->state = P_W4_CMAC_RESULT; 1322 sm_cmac_signed_write_start(csrk, ATT_SIGNED_WRITE_COMMAND, gatt_client->attribute_handle, gatt_client->attribute_length, gatt_client->attribute_value, sign_counter, att_signed_write_handle_cmac_result); 1323 } 1324 #endif 1325 1326 // returns true if packet was sent 1327 static bool gatt_client_run_for_gatt_client(gatt_client_t * gatt_client){ 1328 1329 // wait until re-encryption is complete 1330 if (gap_reconnect_security_setup_active(gatt_client->con_handle)) return false; 1331 1332 // wait until re-encryption is complete 1333 if (gatt_client->reencryption_active) return false; 1334 1335 // wait until pairing complete (either reactive authentication or due to required security level) 1336 if (gatt_client->wait_for_authentication_complete) return false; 1337 1338 bool client_request_pending = gatt_client->state != P_READY; 1339 1340 // verify security level for Mandatory Authentication over LE 1341 bool check_security; 1342 switch (gatt_client->bearer_type){ 1343 case ATT_BEARER_UNENHANCED_LE: 1344 check_security = true; 1345 break; 1346 default: 1347 check_security = false; 1348 break; 1349 } 1350 if (client_request_pending && (gatt_client_required_security_level > gatt_client->security_level) && check_security){ 1351 log_info("Trigger pairing, current security level %u, required %u\n", gatt_client->security_level, gatt_client_required_security_level); 1352 gatt_client->wait_for_authentication_complete = true; 1353 // set att error code for pairing failure based on required level 1354 switch (gatt_client_required_security_level){ 1355 case LEVEL_4: 1356 case LEVEL_3: 1357 gatt_client->pending_error_code = ATT_ERROR_INSUFFICIENT_AUTHENTICATION; 1358 break; 1359 default: 1360 gatt_client->pending_error_code = ATT_ERROR_INSUFFICIENT_ENCRYPTION; 1361 break; 1362 } 1363 sm_request_pairing(gatt_client->con_handle); 1364 // sm probably just sent a pdu 1365 return true; 1366 } 1367 1368 switch (gatt_client->mtu_state) { 1369 case SEND_MTU_EXCHANGE: 1370 gatt_client->mtu_state = SENT_MTU_EXCHANGE; 1371 att_exchange_mtu_request(gatt_client); 1372 return true; 1373 case SENT_MTU_EXCHANGE: 1374 return false; 1375 default: 1376 break; 1377 } 1378 1379 if (gatt_client->send_confirmation){ 1380 gatt_client->send_confirmation = false; 1381 att_confirmation(gatt_client); 1382 return true; 1383 } 1384 1385 // check MTU for writes 1386 switch (gatt_client->state){ 1387 case P_W2_SEND_WRITE_CHARACTERISTIC_VALUE: 1388 case P_W2_SEND_WRITE_CHARACTERISTIC_DESCRIPTOR: 1389 if (gatt_client->attribute_length <= (gatt_client->mtu - 3u)) break; 1390 log_error("gatt_client_run: value len %u > MTU %u - 3\n", gatt_client->attribute_length,gatt_client->mtu); 1391 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_INVALID_ATTRIBUTE_VALUE_LENGTH); 1392 return false; 1393 default: 1394 break; 1395 } 1396 1397 bool packet_sent = true; 1398 bool done = true; 1399 switch (gatt_client->state){ 1400 case P_W2_SEND_SERVICE_QUERY: 1401 gatt_client->state = P_W4_SERVICE_QUERY_RESULT; 1402 send_gatt_services_request(gatt_client); 1403 break; 1404 1405 case P_W2_SEND_SERVICE_WITH_UUID_QUERY: 1406 gatt_client->state = P_W4_SERVICE_WITH_UUID_RESULT; 1407 send_gatt_services_by_uuid_request(gatt_client); 1408 break; 1409 1410 case P_W2_SEND_ALL_CHARACTERISTICS_OF_SERVICE_QUERY: 1411 gatt_client->state = P_W4_ALL_CHARACTERISTICS_OF_SERVICE_QUERY_RESULT; 1412 send_gatt_characteristic_request(gatt_client); 1413 break; 1414 1415 case P_W2_SEND_CHARACTERISTIC_WITH_UUID_QUERY: 1416 gatt_client->state = P_W4_CHARACTERISTIC_WITH_UUID_QUERY_RESULT; 1417 send_gatt_characteristic_request(gatt_client); 1418 break; 1419 1420 case P_W2_SEND_ALL_CHARACTERISTIC_DESCRIPTORS_QUERY: 1421 gatt_client->state = P_W4_CHARACTERISTIC_WITH_UUID_QUERY_RESULT; 1422 send_gatt_characteristic_descriptor_request(gatt_client); 1423 break; 1424 1425 case P_W2_SEND_INCLUDED_SERVICE_QUERY: 1426 gatt_client->state = P_W4_INCLUDED_SERVICE_QUERY_RESULT; 1427 send_gatt_included_service_request(gatt_client); 1428 break; 1429 1430 case P_W2_SEND_INCLUDED_SERVICE_WITH_UUID_QUERY: 1431 gatt_client->state = P_W4_INCLUDED_SERVICE_UUID_WITH_QUERY_RESULT; 1432 send_gatt_included_service_uuid_request(gatt_client); 1433 break; 1434 1435 case P_W2_SEND_READ_CHARACTERISTIC_VALUE_QUERY: 1436 gatt_client->state = P_W4_READ_CHARACTERISTIC_VALUE_RESULT; 1437 send_gatt_read_characteristic_value_request(gatt_client); 1438 break; 1439 1440 case P_W2_SEND_READ_BLOB_QUERY: 1441 gatt_client->state = P_W4_READ_BLOB_RESULT; 1442 send_gatt_read_blob_request(gatt_client); 1443 break; 1444 1445 case P_W2_SEND_READ_BY_TYPE_REQUEST: 1446 gatt_client->state = P_W4_READ_BY_TYPE_RESPONSE; 1447 send_gatt_read_by_type_request(gatt_client); 1448 break; 1449 1450 case P_W2_SEND_READ_MULTIPLE_REQUEST: 1451 gatt_client->state = P_W4_READ_MULTIPLE_RESPONSE; 1452 send_gatt_read_multiple_request(gatt_client); 1453 break; 1454 1455 #ifdef ENABLE_GATT_OVER_EATT 1456 case P_W2_SEND_READ_MULTIPLE_VARIABLE_REQUEST: 1457 gatt_client->state = P_W4_READ_MULTIPLE_VARIABLE_RESPONSE; 1458 send_gatt_read_multiple_variable_request(gatt_client); 1459 break; 1460 #endif 1461 1462 case P_W2_SEND_WRITE_CHARACTERISTIC_VALUE: 1463 gatt_client->state = P_W4_WRITE_CHARACTERISTIC_VALUE_RESULT; 1464 send_gatt_write_attribute_value_request(gatt_client); 1465 break; 1466 1467 case P_W2_PREPARE_WRITE: 1468 gatt_client->state = P_W4_PREPARE_WRITE_RESULT; 1469 send_gatt_prepare_write_request(gatt_client); 1470 break; 1471 1472 case P_W2_PREPARE_WRITE_SINGLE: 1473 gatt_client->state = P_W4_PREPARE_WRITE_SINGLE_RESULT; 1474 send_gatt_prepare_write_request(gatt_client); 1475 break; 1476 1477 case P_W2_PREPARE_RELIABLE_WRITE: 1478 gatt_client->state = P_W4_PREPARE_RELIABLE_WRITE_RESULT; 1479 send_gatt_prepare_write_request(gatt_client); 1480 break; 1481 1482 case P_W2_EXECUTE_PREPARED_WRITE: 1483 gatt_client->state = P_W4_EXECUTE_PREPARED_WRITE_RESULT; 1484 send_gatt_execute_write_request(gatt_client); 1485 break; 1486 1487 case P_W2_CANCEL_PREPARED_WRITE: 1488 gatt_client->state = P_W4_CANCEL_PREPARED_WRITE_RESULT; 1489 send_gatt_cancel_prepared_write_request(gatt_client); 1490 break; 1491 1492 case P_W2_CANCEL_PREPARED_WRITE_DATA_MISMATCH: 1493 gatt_client->state = P_W4_CANCEL_PREPARED_WRITE_DATA_MISMATCH_RESULT; 1494 send_gatt_cancel_prepared_write_request(gatt_client); 1495 break; 1496 1497 #ifdef ENABLE_GATT_FIND_INFORMATION_FOR_CCC_DISCOVERY 1498 case P_W2_SEND_FIND_CLIENT_CHARACTERISTIC_CONFIGURATION_QUERY: 1499 // use Find Information 1500 gatt_client->gatt_client_state = P_W4_FIND_CLIENT_CHARACTERISTIC_CONFIGURATION_QUERY_RESULT; 1501 send_gatt_characteristic_descriptor_request(gatt_client); 1502 #else 1503 case P_W2_SEND_READ_CLIENT_CHARACTERISTIC_CONFIGURATION_QUERY: 1504 // Use Read By Type 1505 gatt_client->state = P_W4_READ_CLIENT_CHARACTERISTIC_CONFIGURATION_QUERY_RESULT; 1506 send_gatt_read_client_characteristic_configuration_request(gatt_client); 1507 #endif 1508 break; 1509 1510 case P_W2_SEND_READ_CHARACTERISTIC_DESCRIPTOR_QUERY: 1511 gatt_client->state = P_W4_READ_CHARACTERISTIC_DESCRIPTOR_RESULT; 1512 send_gatt_read_characteristic_descriptor_request(gatt_client); 1513 break; 1514 1515 case P_W2_SEND_READ_BLOB_CHARACTERISTIC_DESCRIPTOR_QUERY: 1516 gatt_client->state = P_W4_READ_BLOB_CHARACTERISTIC_DESCRIPTOR_RESULT; 1517 send_gatt_read_blob_request(gatt_client); 1518 break; 1519 1520 case P_W2_SEND_WRITE_CHARACTERISTIC_DESCRIPTOR: 1521 gatt_client->state = P_W4_WRITE_CHARACTERISTIC_DESCRIPTOR_RESULT; 1522 send_gatt_write_attribute_value_request(gatt_client); 1523 break; 1524 1525 case P_W2_WRITE_CLIENT_CHARACTERISTIC_CONFIGURATION: 1526 gatt_client->state = P_W4_CLIENT_CHARACTERISTIC_CONFIGURATION_RESULT; 1527 send_gatt_write_client_characteristic_configuration_request(gatt_client); 1528 break; 1529 1530 case P_W2_PREPARE_WRITE_CHARACTERISTIC_DESCRIPTOR: 1531 gatt_client->state = P_W4_PREPARE_WRITE_CHARACTERISTIC_DESCRIPTOR_RESULT; 1532 send_gatt_prepare_write_request(gatt_client); 1533 break; 1534 1535 case P_W2_EXECUTE_PREPARED_WRITE_CHARACTERISTIC_DESCRIPTOR: 1536 gatt_client->state = P_W4_EXECUTE_PREPARED_WRITE_CHARACTERISTIC_DESCRIPTOR_RESULT; 1537 send_gatt_execute_write_request(gatt_client); 1538 break; 1539 1540 #ifdef ENABLE_LE_SIGNED_WRITE 1541 case P_W4_IDENTITY_RESOLVING: 1542 log_info("P_W4_IDENTITY_RESOLVING - state %x", sm_identity_resolving_state(gatt_client->con_handle)); 1543 switch (sm_identity_resolving_state(gatt_client->con_handle)){ 1544 case IRK_LOOKUP_SUCCEEDED: 1545 gatt_client->le_device_index = sm_le_device_index(gatt_client->con_handle); 1546 gatt_client->state = P_W4_CMAC_READY; 1547 if (sm_cmac_ready()){ 1548 gatt_client_run_for_client_start_signed_write(gatt_client); 1549 } 1550 break; 1551 case IRK_LOOKUP_FAILED: 1552 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_BONDING_INFORMATION_MISSING); 1553 break; 1554 default: 1555 break; 1556 } 1557 packet_sent = false; 1558 break; 1559 1560 case P_W4_CMAC_READY: 1561 if (sm_cmac_ready()){ 1562 gatt_client_run_for_client_start_signed_write(gatt_client); 1563 } 1564 packet_sent = false; 1565 break; 1566 1567 case P_W2_SEND_SIGNED_WRITE: { 1568 gatt_client->state = P_W4_SEND_SIGNED_WRITE_DONE; 1569 // bump local signing counter 1570 uint32_t sign_counter = le_device_db_local_counter_get(gatt_client->le_device_index); 1571 le_device_db_local_counter_set(gatt_client->le_device_index, sign_counter + 1); 1572 // send signed write command 1573 send_gatt_signed_write_request(gatt_client, sign_counter); 1574 // finally, notifiy client that write is complete 1575 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 1576 break; 1577 } 1578 #endif 1579 default: 1580 done = false; 1581 break; 1582 } 1583 1584 if (done){ 1585 return packet_sent; 1586 } 1587 1588 // write without response callback 1589 btstack_context_callback_registration_t * callback = 1590 (btstack_context_callback_registration_t *) btstack_linked_list_pop(&gatt_client->write_without_response_requests); 1591 if (callback != NULL){ 1592 (*callback->callback)(callback->context); 1593 return true; 1594 } 1595 1596 // requested can send now old 1597 if (gatt_client->write_without_response_callback != NULL){ 1598 btstack_packet_handler_t packet_handler = gatt_client->write_without_response_callback; 1599 gatt_client->write_without_response_callback = NULL; 1600 uint8_t event[4]; 1601 event[0] = GATT_EVENT_CAN_WRITE_WITHOUT_RESPONSE; 1602 event[1] = sizeof(event) - 2u; 1603 little_endian_store_16(event, 2, gatt_client->con_handle); 1604 packet_handler(HCI_EVENT_PACKET, gatt_client->con_handle, event, sizeof(event)); 1605 return true; // to trigger requeueing (even if higher layer didn't sent) 1606 } 1607 1608 return false; 1609 } 1610 1611 static void gatt_client_run(void){ 1612 btstack_linked_item_t *it; 1613 bool packet_sent; 1614 #ifdef ENABLE_GATT_OVER_EATT 1615 btstack_linked_list_iterator_t it_eatt; 1616 #endif 1617 for (it = (btstack_linked_item_t *) gatt_client_connections; it != NULL; it = it->next){ 1618 gatt_client_t * gatt_client = (gatt_client_t *) it; 1619 switch (gatt_client->bearer_type){ 1620 case ATT_BEARER_UNENHANCED_LE: 1621 #ifdef ENABLE_GATT_OVER_EATT 1622 btstack_linked_list_iterator_init(&it_eatt, &gatt_client->eatt_clients); 1623 while (btstack_linked_list_iterator_has_next(&it_eatt)) { 1624 gatt_client_t * eatt_client = (gatt_client_t *) btstack_linked_list_iterator_next(&it_eatt); 1625 if (eatt_client->state != P_READY){ 1626 if (att_dispatch_client_can_send_now(gatt_client->con_handle)){ 1627 gatt_client_run_for_gatt_client(eatt_client); 1628 } 1629 } 1630 } 1631 #endif 1632 if (!att_dispatch_client_can_send_now(gatt_client->con_handle)) { 1633 att_dispatch_client_request_can_send_now_event(gatt_client->con_handle); 1634 return; 1635 } 1636 packet_sent = gatt_client_run_for_gatt_client(gatt_client); 1637 if (packet_sent){ 1638 // request new permission 1639 att_dispatch_client_request_can_send_now_event(gatt_client->con_handle); 1640 // requeue client for fairness and exit 1641 // note: iterator has become invalid 1642 btstack_linked_list_remove(&gatt_client_connections, (btstack_linked_item_t *) gatt_client); 1643 btstack_linked_list_add_tail(&gatt_client_connections, (btstack_linked_item_t *) gatt_client); 1644 return; 1645 } 1646 break; 1647 #ifdef ENABLE_GATT_OVER_CLASSIC 1648 case ATT_BEARER_UNENHANCED_CLASSIC: 1649 if (gatt_client->con_handle == HCI_CON_HANDLE_INVALID) { 1650 continue; 1651 } 1652 1653 // handle GATT over BR/EDR 1654 if (att_dispatch_client_can_send_now(gatt_client->con_handle) == false) { 1655 att_dispatch_client_request_can_send_now_event(gatt_client->con_handle); 1656 return; 1657 } 1658 packet_sent = gatt_client_run_for_gatt_client(gatt_client); 1659 if (packet_sent){ 1660 // request new permission 1661 att_dispatch_client_request_can_send_now_event(gatt_client->con_handle); 1662 // requeue client for fairness and exit 1663 // note: iterator has become invalid 1664 btstack_linked_list_remove(&gatt_client_connections, (btstack_linked_item_t *) gatt_client); 1665 btstack_linked_list_add_tail(&gatt_client_connections, (btstack_linked_item_t *) gatt_client); 1666 return; 1667 } 1668 break; 1669 #endif 1670 default: 1671 btstack_unreachable(); 1672 break; 1673 } 1674 1675 1676 } 1677 } 1678 1679 // emit complete event, used to avoid emitting event from API call 1680 static void gatt_client_emit_events(void * context){ 1681 UNUSED(context); 1682 btstack_linked_item_t *it; 1683 for (it = (btstack_linked_item_t *) gatt_client_connections; it != NULL; it = it->next) { 1684 gatt_client_t *gatt_client = (gatt_client_t *) it; 1685 if (gatt_client->state == P_W2_EMIT_QUERY_COMPLETE_EVENT){ 1686 gatt_client->state = P_READY; 1687 emit_gatt_complete_event(gatt_client, ATT_ERROR_SUCCESS); 1688 } 1689 } 1690 } 1691 1692 static void gatt_client_report_error_if_pending(gatt_client_t *gatt_client, uint8_t att_error_code) { 1693 if (is_ready(gatt_client)) return; 1694 gatt_client_handle_transaction_complete(gatt_client, att_error_code); 1695 } 1696 1697 static void gatt_client_handle_reencryption_complete(const uint8_t * packet){ 1698 hci_con_handle_t con_handle = sm_event_reencryption_complete_get_handle(packet); 1699 gatt_client_t * gatt_client = gatt_client_get_context_for_handle(con_handle); 1700 if (gatt_client == NULL) return; 1701 1702 // update security level 1703 gatt_client->security_level = gatt_client_le_security_level_for_connection(con_handle); 1704 1705 gatt_client->reencryption_result = sm_event_reencryption_complete_get_status(packet); 1706 gatt_client->reencryption_active = false; 1707 gatt_client->wait_for_authentication_complete = false; 1708 1709 if (gatt_client->state == P_READY) return; 1710 1711 switch (sm_event_reencryption_complete_get_status(packet)){ 1712 case ERROR_CODE_SUCCESS: 1713 log_info("re-encryption success, retry operation"); 1714 break; 1715 case ERROR_CODE_AUTHENTICATION_FAILURE: 1716 case ERROR_CODE_PIN_OR_KEY_MISSING: 1717 #if defined(ENABLE_GATT_CLIENT_PAIRING) && !defined(ENABLE_LE_PROACTIVE_AUTHENTICATION) 1718 if (gatt_client_required_security_level == LEVEL_0) { 1719 // re-encryption failed for reactive authentication with pairing and we have a pending client request 1720 // => try to resolve it by deleting bonding information if we started pairing before 1721 // delete bonding information 1722 int le_device_db_index = sm_le_device_index(gatt_client->con_handle); 1723 btstack_assert(le_device_db_index >= 0); 1724 log_info("reactive auth with pairing: delete bonding and start pairing"); 1725 #ifdef ENABLE_LE_PRIVACY_ADDRESS_RESOLUTION 1726 hci_remove_le_device_db_entry_from_resolving_list((uint16_t) le_device_db_index); 1727 #endif 1728 le_device_db_remove(le_device_db_index); 1729 // trigger pairing again 1730 sm_request_pairing(gatt_client->con_handle); 1731 break; 1732 } 1733 #endif 1734 // report bonding information missing 1735 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_BONDING_INFORMATION_MISSING); 1736 break; 1737 default: 1738 // report bonding information missing 1739 gatt_client_handle_transaction_complete(gatt_client, gatt_client->pending_error_code); 1740 break; 1741 } 1742 } 1743 1744 static void gatt_client_handle_disconnection_complete(const uint8_t * packet){ 1745 log_info("GATT Client: HCI_EVENT_DISCONNECTION_COMPLETE"); 1746 hci_con_handle_t con_handle = little_endian_read_16(packet,3); 1747 gatt_client_t * gatt_client = gatt_client_get_context_for_handle(con_handle); 1748 if (gatt_client == NULL) return; 1749 1750 gatt_client_report_error_if_pending(gatt_client, ATT_ERROR_HCI_DISCONNECT_RECEIVED); 1751 gatt_client_timeout_stop(gatt_client); 1752 btstack_linked_list_remove(&gatt_client_connections, (btstack_linked_item_t *) gatt_client); 1753 btstack_memory_gatt_client_free(gatt_client); 1754 } 1755 1756 static void gatt_client_event_packet_handler(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size){ 1757 UNUSED(channel); // ok: handling own l2cap events 1758 UNUSED(size); // ok: there is no channel 1759 1760 if (packet_type != HCI_EVENT_PACKET) return; 1761 1762 hci_con_handle_t con_handle; 1763 gatt_client_t * gatt_client; 1764 switch (hci_event_packet_get_type(packet)) { 1765 case HCI_EVENT_DISCONNECTION_COMPLETE: 1766 gatt_client_handle_disconnection_complete(packet); 1767 break; 1768 1769 // Pairing complete (with/without bonding=storing of pairing information) 1770 case SM_EVENT_PAIRING_COMPLETE: 1771 con_handle = sm_event_pairing_complete_get_handle(packet); 1772 gatt_client = gatt_client_get_context_for_handle(con_handle); 1773 if (gatt_client == NULL) break; 1774 1775 // update security level 1776 gatt_client->security_level = gatt_client_le_security_level_for_connection(con_handle); 1777 1778 if (gatt_client->wait_for_authentication_complete){ 1779 gatt_client->wait_for_authentication_complete = false; 1780 if (sm_event_pairing_complete_get_status(packet) != ERROR_CODE_SUCCESS){ 1781 log_info("pairing failed, report previous error 0x%x", gatt_client->pending_error_code); 1782 gatt_client_report_error_if_pending(gatt_client, gatt_client->pending_error_code); 1783 } else { 1784 log_info("pairing success, retry operation"); 1785 } 1786 } 1787 break; 1788 1789 #ifdef ENABLE_LE_SIGNED_WRITE 1790 // Identity Resolving completed (no code, gatt_client_run will continue) 1791 case SM_EVENT_IDENTITY_RESOLVING_SUCCEEDED: 1792 case SM_EVENT_IDENTITY_RESOLVING_FAILED: 1793 break; 1794 #endif 1795 1796 // re-encryption started 1797 case SM_EVENT_REENCRYPTION_STARTED: 1798 con_handle = sm_event_reencryption_complete_get_handle(packet); 1799 gatt_client = gatt_client_get_context_for_handle(con_handle); 1800 if (gatt_client == NULL) break; 1801 1802 gatt_client->reencryption_active = true; 1803 gatt_client->reencryption_result = ERROR_CODE_SUCCESS; 1804 break; 1805 1806 // re-encryption complete 1807 case SM_EVENT_REENCRYPTION_COMPLETE: 1808 gatt_client_handle_reencryption_complete(packet); 1809 break; 1810 default: 1811 break; 1812 } 1813 1814 gatt_client_run(); 1815 } 1816 1817 static void gatt_client_handle_att_read_response(gatt_client_t *gatt_client, uint8_t *packet, uint16_t size) { 1818 switch (gatt_client->state) { 1819 case P_W4_INCLUDED_SERVICE_UUID_WITH_QUERY_RESULT: 1820 if (size >= 17) { 1821 uint8_t uuid128[16]; 1822 reverse_128(&packet[1], uuid128); 1823 report_gatt_included_service_uuid128(gatt_client, gatt_client->start_group_handle, uuid128); 1824 } 1825 trigger_next_included_service_query(gatt_client, gatt_client->start_group_handle); 1826 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 1827 break; 1828 1829 case P_W4_READ_CHARACTERISTIC_VALUE_RESULT: 1830 report_gatt_characteristic_value(gatt_client, gatt_client->attribute_handle, &packet[1], size - 1u); 1831 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 1832 break; 1833 1834 case P_W4_READ_CHARACTERISTIC_DESCRIPTOR_RESULT: 1835 report_gatt_characteristic_descriptor(gatt_client, gatt_client->attribute_handle, &packet[1], 1836 size - 1u, 0u); 1837 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 1838 break; 1839 1840 // Use ATT_READ_REQUEST for first blob of Read Long Characteristic 1841 case P_W4_READ_BLOB_RESULT: 1842 report_gatt_long_characteristic_value_blob(gatt_client, gatt_client->attribute_handle, &packet[1], 1843 size - 1u, gatt_client->attribute_offset); 1844 trigger_next_blob_query(gatt_client, P_W2_SEND_READ_BLOB_QUERY, size - 1u); 1845 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 1846 break; 1847 1848 // Use ATT_READ_REQUEST for first blob of Read Long Characteristic Descriptor 1849 case P_W4_READ_BLOB_CHARACTERISTIC_DESCRIPTOR_RESULT: 1850 report_gatt_long_characteristic_descriptor(gatt_client, gatt_client->attribute_handle, &packet[1], 1851 size - 1u, gatt_client->attribute_offset); 1852 trigger_next_blob_query(gatt_client, P_W2_SEND_READ_BLOB_CHARACTERISTIC_DESCRIPTOR_QUERY, 1853 size - 1u); 1854 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 1855 break; 1856 1857 default: 1858 break; 1859 } 1860 } 1861 1862 static void gatt_client_handle_att_read_by_type_response(gatt_client_t *gatt_client, uint8_t *packet, uint16_t size) { 1863 switch (gatt_client->state) { 1864 case P_W4_ALL_CHARACTERISTICS_OF_SERVICE_QUERY_RESULT: 1865 report_gatt_characteristics(gatt_client, packet, size); 1866 trigger_next_characteristic_query(gatt_client, 1867 get_last_result_handle_from_characteristics_list(packet, size)); 1868 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done, or by ATT_ERROR 1869 break; 1870 case P_W4_CHARACTERISTIC_WITH_UUID_QUERY_RESULT: 1871 report_gatt_characteristics(gatt_client, packet, size); 1872 trigger_next_characteristic_query(gatt_client, 1873 get_last_result_handle_from_characteristics_list(packet, size)); 1874 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done, or by ATT_ERROR 1875 break; 1876 case P_W4_INCLUDED_SERVICE_QUERY_RESULT: { 1877 if (size < 2u) break; 1878 uint16_t uuid16 = 0; 1879 uint16_t pair_size = packet[1]; 1880 1881 if (pair_size == 6u) { 1882 if (size < 8u) break; 1883 // UUIDs not available, query first included service 1884 gatt_client->start_group_handle = little_endian_read_16(packet, 2); // ready for next query 1885 gatt_client->query_start_handle = little_endian_read_16(packet, 4); 1886 gatt_client->query_end_handle = little_endian_read_16(packet, 6); 1887 gatt_client->state = P_W2_SEND_INCLUDED_SERVICE_WITH_UUID_QUERY; 1888 break; 1889 } 1890 1891 if (pair_size != 8u) break; 1892 1893 // UUIDs included, report all of them 1894 uint16_t offset; 1895 for (offset = 2u; (offset + 8u) <= size; offset += pair_size) { 1896 uint16_t include_handle = little_endian_read_16(packet, offset); 1897 gatt_client->query_start_handle = little_endian_read_16(packet, offset + 2u); 1898 gatt_client->query_end_handle = little_endian_read_16(packet, offset + 4u); 1899 uuid16 = little_endian_read_16(packet, offset + 6u); 1900 report_gatt_included_service_uuid16(gatt_client, include_handle, uuid16); 1901 } 1902 1903 trigger_next_included_service_query(gatt_client, 1904 get_last_result_handle_from_included_services_list(packet, 1905 size)); 1906 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 1907 break; 1908 } 1909 #ifndef ENABLE_GATT_FIND_INFORMATION_FOR_CCC_DISCOVERY 1910 case P_W4_READ_CLIENT_CHARACTERISTIC_CONFIGURATION_QUERY_RESULT: 1911 gatt_client->client_characteristic_configuration_handle = little_endian_read_16(packet, 2); 1912 gatt_client->state = P_W2_WRITE_CLIENT_CHARACTERISTIC_CONFIGURATION; 1913 break; 1914 #endif 1915 case P_W4_READ_BY_TYPE_RESPONSE: { 1916 uint16_t pair_size = packet[1]; 1917 // set last result handle to last valid handle, only used if pair_size invalid 1918 uint16_t last_result_handle = 0xffff; 1919 if (pair_size > 2) { 1920 uint16_t offset; 1921 for (offset = 2; offset < size; offset += pair_size) { 1922 uint16_t value_handle = little_endian_read_16(packet, offset); 1923 report_gatt_characteristic_value(gatt_client, value_handle, &packet[offset + 2u], 1924 pair_size - 2u); 1925 last_result_handle = value_handle; 1926 } 1927 } 1928 trigger_next_read_by_type_query(gatt_client, last_result_handle); 1929 break; 1930 } 1931 default: 1932 break; 1933 } 1934 } 1935 1936 static void gatt_client_handle_att_write_response(gatt_client_t *gatt_client) { 1937 switch (gatt_client->state) { 1938 case P_W4_WRITE_CHARACTERISTIC_VALUE_RESULT: 1939 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 1940 break; 1941 case P_W4_CLIENT_CHARACTERISTIC_CONFIGURATION_RESULT: 1942 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 1943 break; 1944 case P_W4_WRITE_CHARACTERISTIC_DESCRIPTOR_RESULT: 1945 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 1946 break; 1947 default: 1948 break; 1949 } 1950 } 1951 1952 static void gatt_client_handle_att_response(gatt_client_t * gatt_client, uint8_t * packet, uint16_t size) { 1953 uint8_t att_status; 1954 switch (packet[0]) { 1955 case ATT_EXCHANGE_MTU_RESPONSE: { 1956 if (size < 3u) break; 1957 bool update_gatt_server_att_mtu = false; 1958 uint16_t remote_rx_mtu = little_endian_read_16(packet, 1); 1959 uint16_t local_rx_mtu = l2cap_max_le_mtu(); 1960 switch (gatt_client->bearer_type){ 1961 case ATT_BEARER_UNENHANCED_LE: 1962 update_gatt_server_att_mtu = true; 1963 break; 1964 #ifdef ENABLE_GATT_OVER_CLASSIC 1965 case ATT_BEARER_UNENHANCED_CLASSIC: 1966 local_rx_mtu = gatt_client->mtu; 1967 break; 1968 #endif 1969 default: 1970 btstack_unreachable(); 1971 break; 1972 } 1973 1974 uint16_t mtu = (remote_rx_mtu < local_rx_mtu) ? remote_rx_mtu : local_rx_mtu; 1975 1976 // set gatt client mtu 1977 gatt_client->mtu = mtu; 1978 gatt_client->mtu_state = MTU_EXCHANGED; 1979 1980 if (update_gatt_server_att_mtu){ 1981 // set per connection mtu state - for fixed channel 1982 hci_connection_t *hci_connection = hci_connection_for_handle(gatt_client->con_handle); 1983 hci_connection->att_connection.mtu = gatt_client->mtu; 1984 hci_connection->att_connection.mtu_exchanged = true; 1985 } 1986 emit_gatt_mtu_exchanged_result_event(gatt_client, gatt_client->mtu); 1987 break; 1988 } 1989 case ATT_READ_BY_GROUP_TYPE_RESPONSE: 1990 switch (gatt_client->state) { 1991 case P_W4_SERVICE_QUERY_RESULT: 1992 report_gatt_services(gatt_client, packet, size); 1993 trigger_next_service_query(gatt_client, get_last_result_handle_from_service_list(packet, size)); 1994 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 1995 break; 1996 default: 1997 break; 1998 } 1999 break; 2000 case ATT_HANDLE_VALUE_NOTIFICATION: 2001 if (size < 3u) return; 2002 report_gatt_notification(gatt_client, little_endian_read_16(packet, 1u), &packet[3], size - 3u); 2003 return; 2004 #ifdef ENABLE_GATT_OVER_EATT 2005 case ATT_MULTIPLE_HANDLE_VALUE_NTF: 2006 if (size >= 5u) { 2007 uint16_t offset = 1; 2008 while (true){ 2009 uint16_t value_handle = little_endian_read_16(packet, offset); 2010 offset += 2; 2011 uint16_t value_length = little_endian_read_16(packet, offset); 2012 offset += 2; 2013 if ((offset + value_length) > size) break; 2014 report_gatt_notification(gatt_client, value_handle, &packet[offset], value_length); 2015 offset += value_length; 2016 } 2017 } 2018 return; 2019 #endif 2020 case ATT_HANDLE_VALUE_INDICATION: 2021 if (size < 3u) break; 2022 report_gatt_indication(gatt_client, little_endian_read_16(packet, 1u), &packet[3], size - 3u); 2023 gatt_client->send_confirmation = true; 2024 break; 2025 case ATT_READ_BY_TYPE_RESPONSE: 2026 gatt_client_handle_att_read_by_type_response(gatt_client, packet, size); 2027 break; 2028 case ATT_READ_RESPONSE: 2029 gatt_client_handle_att_read_response(gatt_client, packet, size); 2030 break; 2031 case ATT_FIND_BY_TYPE_VALUE_RESPONSE: { 2032 uint8_t pair_size = 4; 2033 int i; 2034 uint16_t start_group_handle; 2035 uint16_t end_group_handle = 0xffff; // asserts GATT_EVENT_QUERY_COMPLETE is emitted if no results 2036 for (i = 1u; (i + pair_size) <= size; i += pair_size) { 2037 start_group_handle = little_endian_read_16(packet, i); 2038 end_group_handle = little_endian_read_16(packet, i + 2); 2039 emit_gatt_service_query_result_event(gatt_client, start_group_handle, end_group_handle, 2040 gatt_client->uuid128); 2041 } 2042 trigger_next_service_by_uuid_query(gatt_client, end_group_handle); 2043 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 2044 break; 2045 } 2046 case ATT_FIND_INFORMATION_REPLY: { 2047 if (size < 2u) break; 2048 2049 uint8_t pair_size = 4; 2050 if (packet[1u] == 2u) { 2051 pair_size = 18; 2052 } 2053 uint16_t offset = 2; 2054 2055 if (size < (pair_size + offset)) break; 2056 uint16_t last_descriptor_handle = little_endian_read_16(packet, size - pair_size); 2057 2058 #ifdef ENABLE_GATT_FIND_INFORMATION_FOR_CCC_DISCOVERY 2059 log_info("ENABLE_GATT_FIND_INFORMATION_FOR_CCC_DISCOVERY, state %x", gatt_client->gatt_client_state); 2060 if (gatt_client->gatt_client_state == P_W4_FIND_CLIENT_CHARACTERISTIC_CONFIGURATION_QUERY_RESULT){ 2061 // iterate over descriptors looking for CCC 2062 if (pair_size == 4){ 2063 while ((offset + 4) <= size){ 2064 uint16_t uuid16 = little_endian_read_16(packet, offset + 2); 2065 if (uuid16 == GATT_CLIENT_CHARACTERISTICS_CONFIGURATION){ 2066 gatt_client->client_characteristic_configuration_handle = little_endian_read_16(packet, offset); 2067 gatt_client->gatt_client_state = P_W2_WRITE_CLIENT_CHARACTERISTIC_CONFIGURATION; 2068 log_info("CCC found %x", gatt_client->client_characteristic_configuration_handle); 2069 break; 2070 } 2071 offset += pair_size; 2072 } 2073 } 2074 if (is_query_done(gatt_client, last_descriptor_handle)){ 2075 2076 } else { 2077 // next 2078 gatt_client->start_group_handle = last_descriptor_handle + 1; 2079 gatt_client->gatt_client_state = P_W2_SEND_FIND_CLIENT_CHARACTERISTIC_CONFIGURATION_QUERY; 2080 } 2081 break; 2082 } 2083 #endif 2084 report_gatt_all_characteristic_descriptors(gatt_client, &packet[2], size - 2u, pair_size); 2085 trigger_next_characteristic_descriptor_query(gatt_client, last_descriptor_handle); 2086 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 2087 break; 2088 } 2089 2090 case ATT_WRITE_RESPONSE: 2091 gatt_client_handle_att_write_response(gatt_client); 2092 break; 2093 2094 case ATT_READ_BLOB_RESPONSE: { 2095 uint16_t received_blob_length = size - 1u; 2096 switch (gatt_client->state) { 2097 case P_W4_READ_BLOB_RESULT: 2098 report_gatt_long_characteristic_value_blob(gatt_client, gatt_client->attribute_handle, &packet[1], 2099 received_blob_length, gatt_client->attribute_offset); 2100 trigger_next_blob_query(gatt_client, P_W2_SEND_READ_BLOB_QUERY, received_blob_length); 2101 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 2102 break; 2103 case P_W4_READ_BLOB_CHARACTERISTIC_DESCRIPTOR_RESULT: 2104 report_gatt_long_characteristic_descriptor(gatt_client, gatt_client->attribute_handle, 2105 &packet[1], received_blob_length, 2106 gatt_client->attribute_offset); 2107 trigger_next_blob_query(gatt_client, P_W2_SEND_READ_BLOB_CHARACTERISTIC_DESCRIPTOR_QUERY, 2108 received_blob_length); 2109 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 2110 break; 2111 default: 2112 break; 2113 } 2114 break; 2115 } 2116 case ATT_PREPARE_WRITE_RESPONSE: 2117 switch (gatt_client->state) { 2118 case P_W4_PREPARE_WRITE_SINGLE_RESULT: 2119 if (is_value_valid(gatt_client, packet, size)) { 2120 att_status = ATT_ERROR_SUCCESS; 2121 } else { 2122 att_status = ATT_ERROR_DATA_MISMATCH; 2123 } 2124 gatt_client_handle_transaction_complete(gatt_client, att_status); 2125 break; 2126 2127 case P_W4_PREPARE_WRITE_RESULT: { 2128 gatt_client->attribute_offset = little_endian_read_16(packet, 3); 2129 trigger_next_prepare_write_query(gatt_client, P_W2_PREPARE_WRITE, P_W2_EXECUTE_PREPARED_WRITE); 2130 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 2131 break; 2132 } 2133 case P_W4_PREPARE_WRITE_CHARACTERISTIC_DESCRIPTOR_RESULT: { 2134 gatt_client->attribute_offset = little_endian_read_16(packet, 3); 2135 trigger_next_prepare_write_query(gatt_client, P_W2_PREPARE_WRITE_CHARACTERISTIC_DESCRIPTOR, 2136 P_W2_EXECUTE_PREPARED_WRITE_CHARACTERISTIC_DESCRIPTOR); 2137 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 2138 break; 2139 } 2140 case P_W4_PREPARE_RELIABLE_WRITE_RESULT: { 2141 if (is_value_valid(gatt_client, packet, size)) { 2142 gatt_client->attribute_offset = little_endian_read_16(packet, 3); 2143 trigger_next_prepare_write_query(gatt_client, P_W2_PREPARE_RELIABLE_WRITE, 2144 P_W2_EXECUTE_PREPARED_WRITE); 2145 // GATT_EVENT_QUERY_COMPLETE is emitted by trigger_next_xxx when done 2146 break; 2147 } 2148 gatt_client->state = P_W2_CANCEL_PREPARED_WRITE_DATA_MISMATCH; 2149 break; 2150 } 2151 default: 2152 break; 2153 } 2154 break; 2155 2156 case ATT_EXECUTE_WRITE_RESPONSE: 2157 switch (gatt_client->state) { 2158 case P_W4_EXECUTE_PREPARED_WRITE_RESULT: 2159 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 2160 break; 2161 case P_W4_CANCEL_PREPARED_WRITE_RESULT: 2162 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 2163 break; 2164 case P_W4_CANCEL_PREPARED_WRITE_DATA_MISMATCH_RESULT: 2165 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_DATA_MISMATCH); 2166 break; 2167 case P_W4_EXECUTE_PREPARED_WRITE_CHARACTERISTIC_DESCRIPTOR_RESULT: 2168 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 2169 break; 2170 default: 2171 break; 2172 2173 } 2174 break; 2175 2176 case ATT_READ_MULTIPLE_RESPONSE: 2177 switch (gatt_client->state) { 2178 case P_W4_READ_MULTIPLE_RESPONSE: 2179 report_gatt_characteristic_value(gatt_client, 0u, &packet[1], size - 1u); 2180 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 2181 break; 2182 default: 2183 break; 2184 } 2185 break; 2186 2187 #ifdef ENABLE_GATT_OVER_EATT 2188 case ATT_READ_MULTIPLE_VARIABLE_RSP: 2189 switch (gatt_client->state) { 2190 case P_W4_READ_MULTIPLE_VARIABLE_RESPONSE: 2191 report_gatt_characteristic_value(gatt_client, 0u, &packet[1], size - 1u); 2192 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 2193 break; 2194 default: 2195 break; 2196 } 2197 break; 2198 #endif 2199 2200 case ATT_ERROR_RESPONSE: 2201 if (size < 5u) return; 2202 att_status = packet[4]; 2203 switch (att_status) { 2204 case ATT_ERROR_ATTRIBUTE_NOT_FOUND: { 2205 switch (gatt_client->state) { 2206 case P_W4_SERVICE_QUERY_RESULT: 2207 case P_W4_SERVICE_WITH_UUID_RESULT: 2208 case P_W4_INCLUDED_SERVICE_QUERY_RESULT: 2209 case P_W4_ALL_CHARACTERISTIC_DESCRIPTORS_QUERY_RESULT: 2210 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 2211 break; 2212 case P_W4_ALL_CHARACTERISTICS_OF_SERVICE_QUERY_RESULT: 2213 case P_W4_CHARACTERISTIC_WITH_UUID_QUERY_RESULT: 2214 report_gatt_characteristic_end_found(gatt_client, gatt_client->end_group_handle); 2215 gatt_client_handle_transaction_complete(gatt_client, ATT_ERROR_SUCCESS); 2216 break; 2217 case P_W4_READ_BY_TYPE_RESPONSE: 2218 if (gatt_client->start_group_handle == gatt_client->query_start_handle) { 2219 att_status = ATT_ERROR_ATTRIBUTE_NOT_FOUND; 2220 } else { 2221 att_status = ATT_ERROR_SUCCESS; 2222 } 2223 gatt_client_handle_transaction_complete(gatt_client, att_status); 2224 break; 2225 default: 2226 gatt_client_report_error_if_pending(gatt_client, att_status); 2227 break; 2228 } 2229 break; 2230 } 2231 2232 #ifdef ENABLE_GATT_CLIENT_PAIRING 2233 2234 case ATT_ERROR_INSUFFICIENT_AUTHENTICATION: 2235 case ATT_ERROR_INSUFFICIENT_ENCRYPTION_KEY_SIZE: 2236 case ATT_ERROR_INSUFFICIENT_ENCRYPTION: { 2237 2238 // security too low 2239 if (gatt_client->security_counter > 0) { 2240 gatt_client_report_error_if_pending(gatt_client, att_status); 2241 break; 2242 } 2243 // start security 2244 gatt_client->security_counter++; 2245 2246 // setup action 2247 int retry = 1; 2248 switch (gatt_client->state){ 2249 case P_W4_READ_CHARACTERISTIC_VALUE_RESULT: 2250 gatt_client->state = P_W2_SEND_READ_CHARACTERISTIC_VALUE_QUERY ; 2251 break; 2252 case P_W4_READ_BLOB_RESULT: 2253 gatt_client->state = P_W2_SEND_READ_BLOB_QUERY; 2254 break; 2255 case P_W4_READ_BY_TYPE_RESPONSE: 2256 gatt_client->state = P_W2_SEND_READ_BY_TYPE_REQUEST; 2257 break; 2258 case P_W4_READ_MULTIPLE_RESPONSE: 2259 gatt_client->state = P_W2_SEND_READ_MULTIPLE_REQUEST; 2260 break; 2261 case P_W4_READ_MULTIPLE_VARIABLE_RESPONSE: 2262 gatt_client->state = P_W2_SEND_READ_MULTIPLE_VARIABLE_REQUEST; 2263 break; 2264 case P_W4_WRITE_CHARACTERISTIC_VALUE_RESULT: 2265 gatt_client->state = P_W2_SEND_WRITE_CHARACTERISTIC_VALUE; 2266 break; 2267 case P_W4_PREPARE_WRITE_RESULT: 2268 gatt_client->state = P_W2_PREPARE_WRITE; 2269 break; 2270 case P_W4_PREPARE_WRITE_SINGLE_RESULT: 2271 gatt_client->state = P_W2_PREPARE_WRITE_SINGLE; 2272 break; 2273 case P_W4_PREPARE_RELIABLE_WRITE_RESULT: 2274 gatt_client->state = P_W2_PREPARE_RELIABLE_WRITE; 2275 break; 2276 case P_W4_EXECUTE_PREPARED_WRITE_RESULT: 2277 gatt_client->state = P_W2_EXECUTE_PREPARED_WRITE; 2278 break; 2279 case P_W4_CANCEL_PREPARED_WRITE_RESULT: 2280 gatt_client->state = P_W2_CANCEL_PREPARED_WRITE; 2281 break; 2282 case P_W4_CANCEL_PREPARED_WRITE_DATA_MISMATCH_RESULT: 2283 gatt_client->state = P_W2_CANCEL_PREPARED_WRITE_DATA_MISMATCH; 2284 break; 2285 case P_W4_READ_CHARACTERISTIC_DESCRIPTOR_RESULT: 2286 gatt_client->state = P_W2_SEND_READ_CHARACTERISTIC_DESCRIPTOR_QUERY; 2287 break; 2288 case P_W4_READ_BLOB_CHARACTERISTIC_DESCRIPTOR_RESULT: 2289 gatt_client->state = P_W2_SEND_READ_BLOB_CHARACTERISTIC_DESCRIPTOR_QUERY; 2290 break; 2291 case P_W4_WRITE_CHARACTERISTIC_DESCRIPTOR_RESULT: 2292 gatt_client->state = P_W2_SEND_WRITE_CHARACTERISTIC_DESCRIPTOR; 2293 break; 2294 case P_W4_CLIENT_CHARACTERISTIC_CONFIGURATION_RESULT: 2295 gatt_client->state = P_W2_WRITE_CLIENT_CHARACTERISTIC_CONFIGURATION; 2296 break; 2297 case P_W4_PREPARE_WRITE_CHARACTERISTIC_DESCRIPTOR_RESULT: 2298 gatt_client->state = P_W2_PREPARE_WRITE_CHARACTERISTIC_DESCRIPTOR; 2299 break; 2300 case P_W4_EXECUTE_PREPARED_WRITE_CHARACTERISTIC_DESCRIPTOR_RESULT: 2301 gatt_client->state = P_W2_EXECUTE_PREPARED_WRITE_CHARACTERISTIC_DESCRIPTOR; 2302 break; 2303 #ifdef ENABLE_LE_SIGNED_WRITE 2304 case P_W4_SEND_SIGNED_WRITE_DONE: 2305 gatt_client->state = P_W2_SEND_SIGNED_WRITE; 2306 break; 2307 #endif 2308 default: 2309 log_info("retry not supported for state %x", gatt_client->state); 2310 retry = 0; 2311 break; 2312 } 2313 2314 if (!retry) { 2315 gatt_client_report_error_if_pending(gatt_client, att_status); 2316 break; 2317 } 2318 2319 log_info("security error, start pairing"); 2320 2321 // start pairing for higher security level 2322 gatt_client->wait_for_authentication_complete = true; 2323 gatt_client->pending_error_code = att_status; 2324 sm_request_pairing(gatt_client->con_handle); 2325 break; 2326 } 2327 #endif 2328 2329 // nothing we can do about that 2330 case ATT_ERROR_INSUFFICIENT_AUTHORIZATION: 2331 default: 2332 gatt_client_report_error_if_pending(gatt_client, att_status); 2333 break; 2334 } 2335 break; 2336 2337 default: 2338 log_info("ATT Handler, unhandled response type 0x%02x", packet[0]); 2339 break; 2340 } 2341 } 2342 2343 static void gatt_client_att_packet_handler(uint8_t packet_type, uint16_t handle, uint8_t *packet, uint16_t size) { 2344 gatt_client_t *gatt_client; 2345 #ifdef ENABLE_GATT_OVER_CLASSIC 2346 uint8_t status; 2347 hci_connection_t * hci_connection; 2348 hci_con_handle_t con_handle; 2349 #endif 2350 2351 if (size < 1u) return; 2352 switch (packet_type){ 2353 case HCI_EVENT_PACKET: 2354 switch (hci_event_packet_get_type(packet)) { 2355 #ifdef ENABLE_GATT_OVER_CLASSIC 2356 case L2CAP_EVENT_CHANNEL_OPENED: 2357 status = l2cap_event_channel_opened_get_status(packet); 2358 gatt_client = gatt_client_get_context_for_l2cap_cid(l2cap_event_channel_opened_get_local_cid(packet)); 2359 if (gatt_client != NULL){ 2360 con_handle = l2cap_event_channel_opened_get_handle(packet); 2361 hci_connection = hci_connection_for_handle(con_handle); 2362 if (status == L2CAP_CONNECTION_RESPONSE_RESULT_REFUSED_RESOURCES){ 2363 if ((hci_connection != NULL) && hci_connection->att_server.incoming_connection_request) { 2364 log_info("Collision, retry in 100ms"); 2365 gatt_client->state = P_W2_L2CAP_CONNECT; 2366 // set timer for retry 2367 btstack_run_loop_set_timer(&gatt_client->gc_timeout, GATT_CLIENT_COLLISION_BACKOFF_MS); 2368 btstack_run_loop_set_timer_handler(&gatt_client->gc_timeout, gatt_client_classic_retry); 2369 btstack_run_loop_add_timer(&gatt_client->gc_timeout); 2370 break; 2371 } 2372 } 2373 // if status != 0, gatt_client will be discarded 2374 gatt_client->state = P_READY; 2375 gatt_client->con_handle = l2cap_event_channel_opened_get_handle(packet); 2376 gatt_client->mtu = l2cap_event_channel_opened_get_remote_mtu(packet); 2377 gatt_client_classic_handle_connected(gatt_client, status); 2378 } 2379 break; 2380 case L2CAP_EVENT_CHANNEL_CLOSED: 2381 gatt_client = gatt_client_get_context_for_l2cap_cid(l2cap_event_channel_closed_get_local_cid(packet)); 2382 if (gatt_client != NULL){ 2383 // discard gatt client object 2384 gatt_client_classic_handle_disconnected(gatt_client); 2385 } 2386 break; 2387 #endif 2388 case L2CAP_EVENT_CAN_SEND_NOW: 2389 gatt_client_run(); 2390 break; 2391 // att_server has negotiated the mtu for this connection, cache if context exists 2392 case ATT_EVENT_MTU_EXCHANGE_COMPLETE: 2393 if (size < 6u) break; 2394 gatt_client = gatt_client_get_context_for_handle(handle); 2395 if (gatt_client != NULL) { 2396 gatt_client->mtu = little_endian_read_16(packet, 4); 2397 } 2398 break; 2399 default: 2400 break; 2401 } 2402 break; 2403 2404 case ATT_DATA_PACKET: 2405 // special cases: notifications & indications motivate creating context 2406 switch (packet[0]) { 2407 case ATT_HANDLE_VALUE_NOTIFICATION: 2408 case ATT_HANDLE_VALUE_INDICATION: 2409 gatt_client_provide_context_for_handle(handle, &gatt_client); 2410 break; 2411 default: 2412 gatt_client = gatt_client_get_context_for_handle(handle); 2413 break; 2414 } 2415 2416 if (gatt_client != NULL) { 2417 gatt_client_handle_att_response(gatt_client, packet, size); 2418 gatt_client_run(); 2419 } 2420 break; 2421 2422 #ifdef ENABLE_GATT_OVER_CLASSIC 2423 case L2CAP_DATA_PACKET: 2424 gatt_client = gatt_client_get_context_for_l2cap_cid(handle); 2425 if (gatt_client != NULL){ 2426 gatt_client_handle_att_response(gatt_client, packet, size); 2427 gatt_client_run(); 2428 } 2429 break; 2430 #endif 2431 2432 default: 2433 break; 2434 } 2435 } 2436 2437 #ifdef ENABLE_LE_SIGNED_WRITE 2438 static void att_signed_write_handle_cmac_result(uint8_t hash[8]){ 2439 btstack_linked_list_iterator_t it; 2440 btstack_linked_list_iterator_init(&it, &gatt_client_connections); 2441 while (btstack_linked_list_iterator_has_next(&it)){ 2442 gatt_client_t * gatt_client = (gatt_client_t *) btstack_linked_list_iterator_next(&it); 2443 if (gatt_client->state == P_W4_CMAC_RESULT){ 2444 // store result 2445 (void)memcpy(gatt_client->cmac, hash, 8); 2446 // reverse_64(hash, gatt_client->cmac); 2447 gatt_client->state = P_W2_SEND_SIGNED_WRITE; 2448 gatt_client_run(); 2449 return; 2450 } 2451 } 2452 } 2453 2454 uint8_t gatt_client_signed_write_without_response(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t value_handle, uint16_t message_len, uint8_t * message){ 2455 gatt_client_t * gatt_client; 2456 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 2457 if (status != ERROR_CODE_SUCCESS){ 2458 return status; 2459 } 2460 if (is_ready(gatt_client) == 0){ 2461 return GATT_CLIENT_IN_WRONG_STATE; 2462 } 2463 2464 gatt_client->callback = callback; 2465 gatt_client->attribute_handle = value_handle; 2466 gatt_client->attribute_length = message_len; 2467 gatt_client->attribute_value = message; 2468 gatt_client->state = P_W4_IDENTITY_RESOLVING; 2469 gatt_client_run(); 2470 return ERROR_CODE_SUCCESS; 2471 } 2472 #endif 2473 2474 uint8_t gatt_client_discover_primary_services(btstack_packet_handler_t callback, hci_con_handle_t con_handle){ 2475 gatt_client_t * gatt_client; 2476 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2477 if (status != ERROR_CODE_SUCCESS){ 2478 return status; 2479 } 2480 2481 gatt_client->callback = callback; 2482 gatt_client->start_group_handle = 0x0001; 2483 gatt_client->end_group_handle = 0xffff; 2484 gatt_client->state = P_W2_SEND_SERVICE_QUERY; 2485 gatt_client->uuid16 = GATT_PRIMARY_SERVICE_UUID; 2486 gatt_client_run(); 2487 return ERROR_CODE_SUCCESS; 2488 } 2489 2490 uint8_t gatt_client_discover_secondary_services(btstack_packet_handler_t callback, hci_con_handle_t con_handle){ 2491 gatt_client_t * gatt_client; 2492 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2493 if (status != ERROR_CODE_SUCCESS){ 2494 return status; 2495 } 2496 2497 gatt_client->callback = callback; 2498 gatt_client->start_group_handle = 0x0001; 2499 gatt_client->end_group_handle = 0xffff; 2500 gatt_client->state = P_W2_SEND_SERVICE_QUERY; 2501 gatt_client->uuid16 = GATT_SECONDARY_SERVICE_UUID; 2502 gatt_client_run(); 2503 return ERROR_CODE_SUCCESS; 2504 } 2505 2506 uint8_t gatt_client_discover_primary_services_by_uuid16(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t uuid16){ 2507 gatt_client_t * gatt_client; 2508 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2509 if (status != ERROR_CODE_SUCCESS){ 2510 return status; 2511 } 2512 2513 gatt_client->callback = callback; 2514 gatt_client->start_group_handle = 0x0001; 2515 gatt_client->end_group_handle = 0xffff; 2516 gatt_client->state = P_W2_SEND_SERVICE_WITH_UUID_QUERY; 2517 gatt_client->uuid16 = uuid16; 2518 uuid_add_bluetooth_prefix((uint8_t*) &(gatt_client->uuid128), gatt_client->uuid16); 2519 gatt_client_run(); 2520 return ERROR_CODE_SUCCESS; 2521 } 2522 2523 uint8_t gatt_client_discover_primary_services_by_uuid128(btstack_packet_handler_t callback, hci_con_handle_t con_handle, const uint8_t * uuid128){ 2524 gatt_client_t * gatt_client; 2525 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2526 if (status != ERROR_CODE_SUCCESS){ 2527 return status; 2528 } 2529 2530 gatt_client->callback = callback; 2531 gatt_client->start_group_handle = 0x0001; 2532 gatt_client->end_group_handle = 0xffff; 2533 gatt_client->uuid16 = 0; 2534 (void)memcpy(gatt_client->uuid128, uuid128, 16); 2535 gatt_client->state = P_W2_SEND_SERVICE_WITH_UUID_QUERY; 2536 gatt_client_run(); 2537 return ERROR_CODE_SUCCESS; 2538 } 2539 2540 uint8_t gatt_client_discover_characteristics_for_service(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_service_t * service){ 2541 gatt_client_t * gatt_client; 2542 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2543 if (status != ERROR_CODE_SUCCESS){ 2544 return status; 2545 } 2546 2547 gatt_client->callback = callback; 2548 gatt_client->start_group_handle = service->start_group_handle; 2549 gatt_client->end_group_handle = service->end_group_handle; 2550 gatt_client->filter_with_uuid = false; 2551 gatt_client->characteristic_start_handle = 0; 2552 gatt_client->state = P_W2_SEND_ALL_CHARACTERISTICS_OF_SERVICE_QUERY; 2553 gatt_client_run(); 2554 return ERROR_CODE_SUCCESS; 2555 } 2556 2557 uint8_t gatt_client_find_included_services_for_service(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_service_t * service){ 2558 gatt_client_t * gatt_client; 2559 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2560 if (status != ERROR_CODE_SUCCESS){ 2561 return status; 2562 } 2563 2564 gatt_client->callback = callback; 2565 gatt_client->start_group_handle = service->start_group_handle; 2566 gatt_client->end_group_handle = service->end_group_handle; 2567 gatt_client->state = P_W2_SEND_INCLUDED_SERVICE_QUERY; 2568 2569 gatt_client_run(); 2570 return ERROR_CODE_SUCCESS; 2571 } 2572 2573 uint8_t gatt_client_discover_characteristics_for_handle_range_by_uuid16(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t start_handle, uint16_t end_handle, uint16_t uuid16){ 2574 gatt_client_t * gatt_client; 2575 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2576 if (status != ERROR_CODE_SUCCESS){ 2577 return status; 2578 } 2579 2580 gatt_client->callback = callback; 2581 gatt_client->start_group_handle = start_handle; 2582 gatt_client->end_group_handle = end_handle; 2583 gatt_client->filter_with_uuid = true; 2584 gatt_client->uuid16 = uuid16; 2585 uuid_add_bluetooth_prefix((uint8_t*) &(gatt_client->uuid128), uuid16); 2586 gatt_client->characteristic_start_handle = 0; 2587 gatt_client->state = P_W2_SEND_CHARACTERISTIC_WITH_UUID_QUERY; 2588 gatt_client_run(); 2589 return ERROR_CODE_SUCCESS; 2590 } 2591 2592 uint8_t gatt_client_discover_characteristics_for_handle_range_by_uuid128(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t start_handle, uint16_t end_handle, const uint8_t * uuid128){ 2593 gatt_client_t * gatt_client; 2594 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2595 if (status != ERROR_CODE_SUCCESS){ 2596 return status; 2597 } 2598 2599 gatt_client->callback = callback; 2600 gatt_client->start_group_handle = start_handle; 2601 gatt_client->end_group_handle = end_handle; 2602 gatt_client->filter_with_uuid = true; 2603 gatt_client->uuid16 = 0; 2604 (void)memcpy(gatt_client->uuid128, uuid128, 16); 2605 gatt_client->characteristic_start_handle = 0; 2606 gatt_client->state = P_W2_SEND_CHARACTERISTIC_WITH_UUID_QUERY; 2607 gatt_client_run(); 2608 return ERROR_CODE_SUCCESS; 2609 } 2610 2611 2612 uint8_t gatt_client_discover_characteristics_for_service_by_uuid16(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_service_t * service, uint16_t uuid16){ 2613 return gatt_client_discover_characteristics_for_handle_range_by_uuid16(callback, con_handle, service->start_group_handle, service->end_group_handle, uuid16); 2614 } 2615 2616 uint8_t gatt_client_discover_characteristics_for_service_by_uuid128(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_service_t * service, const uint8_t * uuid128){ 2617 return gatt_client_discover_characteristics_for_handle_range_by_uuid128(callback, con_handle, service->start_group_handle, service->end_group_handle, uuid128); 2618 } 2619 2620 uint8_t gatt_client_discover_characteristic_descriptors(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_characteristic_t * characteristic){ 2621 gatt_client_t * gatt_client; 2622 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2623 if (status != ERROR_CODE_SUCCESS){ 2624 return status; 2625 } 2626 2627 // check if there is space for characteristics descriptors 2628 if (characteristic->end_handle > characteristic->value_handle){ 2629 gatt_client->callback = callback; 2630 gatt_client->start_group_handle = characteristic->value_handle + 1u; 2631 gatt_client->end_group_handle = characteristic->end_handle; 2632 gatt_client->state = P_W2_SEND_ALL_CHARACTERISTIC_DESCRIPTORS_QUERY; 2633 gatt_client_run(); 2634 } else { 2635 // schedule gatt complete event on next run loop iteration otherwise 2636 gatt_client->state = P_W2_EMIT_QUERY_COMPLETE_EVENT; 2637 gatt_client_deferred_event_emit.callback = gatt_client_emit_events; 2638 btstack_run_loop_execute_on_main_thread(&gatt_client_deferred_event_emit); 2639 } 2640 return ERROR_CODE_SUCCESS; 2641 } 2642 2643 uint8_t gatt_client_read_value_of_characteristic_using_value_handle(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t value_handle){ 2644 gatt_client_t * gatt_client; 2645 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2646 if (status != ERROR_CODE_SUCCESS){ 2647 return status; 2648 } 2649 2650 gatt_client->callback = callback; 2651 gatt_client->attribute_handle = value_handle; 2652 gatt_client->attribute_offset = 0; 2653 gatt_client->state = P_W2_SEND_READ_CHARACTERISTIC_VALUE_QUERY; 2654 gatt_client_run(); 2655 return ERROR_CODE_SUCCESS; 2656 } 2657 2658 uint8_t gatt_client_read_value_of_characteristics_by_uuid16(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t start_handle, uint16_t end_handle, uint16_t uuid16){ 2659 gatt_client_t * gatt_client; 2660 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2661 if (status != ERROR_CODE_SUCCESS){ 2662 return status; 2663 } 2664 2665 gatt_client->callback = callback; 2666 gatt_client->start_group_handle = start_handle; 2667 gatt_client->end_group_handle = end_handle; 2668 gatt_client->query_start_handle = start_handle; 2669 gatt_client->query_end_handle = end_handle; 2670 gatt_client->uuid16 = uuid16; 2671 uuid_add_bluetooth_prefix((uint8_t*) &(gatt_client->uuid128), uuid16); 2672 gatt_client->state = P_W2_SEND_READ_BY_TYPE_REQUEST; 2673 gatt_client_run(); 2674 return ERROR_CODE_SUCCESS; 2675 } 2676 2677 uint8_t gatt_client_read_value_of_characteristics_by_uuid128(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t start_handle, uint16_t end_handle, const uint8_t * uuid128){ 2678 gatt_client_t * gatt_client; 2679 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2680 if (status != ERROR_CODE_SUCCESS){ 2681 return status; 2682 } 2683 2684 gatt_client->callback = callback; 2685 gatt_client->start_group_handle = start_handle; 2686 gatt_client->end_group_handle = end_handle; 2687 gatt_client->query_start_handle = start_handle; 2688 gatt_client->query_end_handle = end_handle; 2689 gatt_client->uuid16 = 0; 2690 (void)memcpy(gatt_client->uuid128, uuid128, 16); 2691 gatt_client->state = P_W2_SEND_READ_BY_TYPE_REQUEST; 2692 gatt_client_run(); 2693 return ERROR_CODE_SUCCESS; 2694 } 2695 2696 2697 uint8_t gatt_client_read_value_of_characteristic(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_characteristic_t * characteristic){ 2698 return gatt_client_read_value_of_characteristic_using_value_handle(callback, con_handle, characteristic->value_handle); 2699 } 2700 2701 uint8_t gatt_client_read_long_value_of_characteristic_using_value_handle_with_offset(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t value_handle, uint16_t offset){ 2702 gatt_client_t * gatt_client; 2703 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2704 if (status != ERROR_CODE_SUCCESS){ 2705 return status; 2706 } 2707 2708 gatt_client->callback = callback; 2709 gatt_client->attribute_handle = value_handle; 2710 gatt_client->attribute_offset = offset; 2711 gatt_client->state = P_W2_SEND_READ_BLOB_QUERY; 2712 gatt_client_run(); 2713 return ERROR_CODE_SUCCESS; 2714 } 2715 2716 uint8_t gatt_client_read_long_value_of_characteristic_using_value_handle(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t value_handle){ 2717 return gatt_client_read_long_value_of_characteristic_using_value_handle_with_offset(callback, con_handle, value_handle, 0); 2718 } 2719 2720 uint8_t gatt_client_read_long_value_of_characteristic(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_characteristic_t * characteristic){ 2721 return gatt_client_read_long_value_of_characteristic_using_value_handle(callback, con_handle, characteristic->value_handle); 2722 } 2723 2724 static uint8_t gatt_client_read_multiple_characteristic_values_with_state(btstack_packet_handler_t callback, hci_con_handle_t con_handle, int num_value_handles, uint16_t * value_handles, gatt_client_state_t state){ 2725 gatt_client_t * gatt_client; 2726 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2727 if (status != ERROR_CODE_SUCCESS){ 2728 return status; 2729 } 2730 2731 #ifdef ENABLE_GATT_OVER_EATT 2732 if (state == P_W2_SEND_READ_MULTIPLE_VARIABLE_REQUEST){ 2733 if (gatt_client->bearer_type != ATT_BEARER_ENHANCED_LE){ 2734 return ERROR_CODE_COMMAND_DISALLOWED; 2735 } 2736 } 2737 #endif 2738 2739 gatt_client->callback = callback; 2740 gatt_client->read_multiple_handle_count = num_value_handles; 2741 gatt_client->read_multiple_handles = value_handles; 2742 gatt_client->state = state; 2743 gatt_client_run(); 2744 return ERROR_CODE_SUCCESS; 2745 } 2746 2747 uint8_t gatt_client_read_multiple_characteristic_values(btstack_packet_handler_t callback, hci_con_handle_t con_handle, int num_value_handles, uint16_t * value_handles){ 2748 return gatt_client_read_multiple_characteristic_values_with_state(callback, con_handle, num_value_handles, value_handles, P_W2_SEND_READ_MULTIPLE_REQUEST); 2749 } 2750 2751 #ifdef ENABLE_GATT_OVER_EATT 2752 uint8_t gatt_client_read_multiple_variable_characteristic_values(btstack_packet_handler_t callback, hci_con_handle_t con_handle, int num_value_handles, uint16_t * value_handles){ 2753 return gatt_client_read_multiple_characteristic_values_with_state(callback, con_handle, num_value_handles, value_handles, P_W2_SEND_READ_MULTIPLE_VARIABLE_REQUEST); 2754 } 2755 #endif 2756 2757 uint8_t gatt_client_write_value_of_characteristic_without_response(hci_con_handle_t con_handle, uint16_t value_handle, uint16_t value_length, uint8_t * value){ 2758 gatt_client_t * gatt_client; 2759 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 2760 if (status != ERROR_CODE_SUCCESS){ 2761 return status; 2762 } 2763 2764 if (value_length > (gatt_client->mtu - 3u)) return GATT_CLIENT_VALUE_TOO_LONG; 2765 if (!att_dispatch_client_can_send_now(gatt_client->con_handle)) return GATT_CLIENT_BUSY; 2766 2767 return att_write_request(gatt_client, ATT_WRITE_COMMAND, value_handle, value_length, value); 2768 } 2769 2770 uint8_t gatt_client_write_value_of_characteristic(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t value_handle, uint16_t value_length, uint8_t * value){ 2771 gatt_client_t * gatt_client; 2772 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2773 if (status != ERROR_CODE_SUCCESS){ 2774 return status; 2775 } 2776 2777 gatt_client->callback = callback; 2778 gatt_client->attribute_handle = value_handle; 2779 gatt_client->attribute_length = value_length; 2780 gatt_client->attribute_value = value; 2781 gatt_client->state = P_W2_SEND_WRITE_CHARACTERISTIC_VALUE; 2782 gatt_client_run(); 2783 return ERROR_CODE_SUCCESS; 2784 } 2785 2786 uint8_t gatt_client_write_long_value_of_characteristic_with_offset(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t value_handle, uint16_t offset, uint16_t value_length, uint8_t * value){ 2787 gatt_client_t * gatt_client; 2788 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2789 if (status != ERROR_CODE_SUCCESS){ 2790 return status; 2791 } 2792 2793 gatt_client->callback = callback; 2794 gatt_client->attribute_handle = value_handle; 2795 gatt_client->attribute_length = value_length; 2796 gatt_client->attribute_offset = offset; 2797 gatt_client->attribute_value = value; 2798 gatt_client->state = P_W2_PREPARE_WRITE; 2799 gatt_client_run(); 2800 return ERROR_CODE_SUCCESS; 2801 } 2802 2803 uint8_t gatt_client_write_long_value_of_characteristic(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t value_handle, uint16_t value_length, uint8_t * value){ 2804 return gatt_client_write_long_value_of_characteristic_with_offset(callback, con_handle, value_handle, 0, value_length, value); 2805 } 2806 2807 uint8_t gatt_client_reliable_write_long_value_of_characteristic(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t value_handle, uint16_t value_length, uint8_t * value){ 2808 gatt_client_t * gatt_client; 2809 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2810 if (status != ERROR_CODE_SUCCESS){ 2811 return status; 2812 } 2813 2814 gatt_client->callback = callback; 2815 gatt_client->attribute_handle = value_handle; 2816 gatt_client->attribute_length = value_length; 2817 gatt_client->attribute_offset = 0; 2818 gatt_client->attribute_value = value; 2819 gatt_client->state = P_W2_PREPARE_RELIABLE_WRITE; 2820 gatt_client_run(); 2821 return ERROR_CODE_SUCCESS; 2822 } 2823 2824 uint8_t gatt_client_write_client_characteristic_configuration(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_characteristic_t * characteristic, uint16_t configuration){ 2825 gatt_client_t * gatt_client; 2826 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2827 if (status != ERROR_CODE_SUCCESS){ 2828 return status; 2829 } 2830 2831 if (configuration > 3){ 2832 return ERROR_CODE_UNSUPPORTED_FEATURE_OR_PARAMETER_VALUE; 2833 } 2834 2835 if ( (configuration & GATT_CLIENT_CHARACTERISTICS_CONFIGURATION_NOTIFICATION) && 2836 ((characteristic->properties & ATT_PROPERTY_NOTIFY) == 0u)) { 2837 log_info("gatt_client_write_client_characteristic_configuration: GATT_CLIENT_CHARACTERISTIC_NOTIFICATION_NOT_SUPPORTED"); 2838 return GATT_CLIENT_CHARACTERISTIC_NOTIFICATION_NOT_SUPPORTED; 2839 } else if ( (configuration & GATT_CLIENT_CHARACTERISTICS_CONFIGURATION_INDICATION) && 2840 ((characteristic->properties & ATT_PROPERTY_INDICATE) == 0u)){ 2841 log_info("gatt_client_write_client_characteristic_configuration: GATT_CLIENT_CHARACTERISTIC_INDICATION_NOT_SUPPORTED"); 2842 return GATT_CLIENT_CHARACTERISTIC_INDICATION_NOT_SUPPORTED; 2843 } 2844 2845 gatt_client->callback = callback; 2846 gatt_client->start_group_handle = characteristic->value_handle; 2847 gatt_client->end_group_handle = characteristic->end_handle; 2848 little_endian_store_16(gatt_client->client_characteristic_configuration_value, 0, configuration); 2849 2850 #ifdef ENABLE_GATT_FIND_INFORMATION_FOR_CCC_DISCOVERY 2851 gatt_client->gatt_client_state = P_W2_SEND_FIND_CLIENT_CHARACTERISTIC_CONFIGURATION_QUERY; 2852 #else 2853 gatt_client->state = P_W2_SEND_READ_CLIENT_CHARACTERISTIC_CONFIGURATION_QUERY; 2854 #endif 2855 gatt_client_run(); 2856 return ERROR_CODE_SUCCESS; 2857 } 2858 2859 uint8_t gatt_client_read_characteristic_descriptor_using_descriptor_handle(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t descriptor_handle){ 2860 gatt_client_t * gatt_client; 2861 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2862 if (status != ERROR_CODE_SUCCESS){ 2863 return status; 2864 } 2865 2866 gatt_client->callback = callback; 2867 gatt_client->attribute_handle = descriptor_handle; 2868 2869 gatt_client->state = P_W2_SEND_READ_CHARACTERISTIC_DESCRIPTOR_QUERY; 2870 gatt_client_run(); 2871 return ERROR_CODE_SUCCESS; 2872 } 2873 2874 uint8_t gatt_client_read_characteristic_descriptor(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_characteristic_descriptor_t * descriptor){ 2875 return gatt_client_read_characteristic_descriptor_using_descriptor_handle(callback, con_handle, descriptor->handle); 2876 } 2877 2878 uint8_t gatt_client_read_long_characteristic_descriptor_using_descriptor_handle_with_offset(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t descriptor_handle, uint16_t offset){ 2879 gatt_client_t * gatt_client; 2880 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2881 if (status != ERROR_CODE_SUCCESS){ 2882 return status; 2883 } 2884 2885 gatt_client->callback = callback; 2886 gatt_client->attribute_handle = descriptor_handle; 2887 gatt_client->attribute_offset = offset; 2888 gatt_client->state = P_W2_SEND_READ_BLOB_CHARACTERISTIC_DESCRIPTOR_QUERY; 2889 gatt_client_run(); 2890 return ERROR_CODE_SUCCESS; 2891 } 2892 2893 uint8_t gatt_client_read_long_characteristic_descriptor_using_descriptor_handle(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t descriptor_handle){ 2894 return gatt_client_read_long_characteristic_descriptor_using_descriptor_handle_with_offset(callback, con_handle, descriptor_handle, 0); 2895 } 2896 2897 uint8_t gatt_client_read_long_characteristic_descriptor(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_characteristic_descriptor_t * descriptor){ 2898 return gatt_client_read_long_characteristic_descriptor_using_descriptor_handle(callback, con_handle, descriptor->handle); 2899 } 2900 2901 uint8_t gatt_client_write_characteristic_descriptor_using_descriptor_handle(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t descriptor_handle, uint16_t value_length, uint8_t * value){ 2902 gatt_client_t * gatt_client; 2903 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2904 if (status != ERROR_CODE_SUCCESS){ 2905 return status; 2906 } 2907 2908 gatt_client->callback = callback; 2909 gatt_client->attribute_handle = descriptor_handle; 2910 gatt_client->attribute_length = value_length; 2911 gatt_client->attribute_offset = 0; 2912 gatt_client->attribute_value = value; 2913 gatt_client->state = P_W2_SEND_WRITE_CHARACTERISTIC_DESCRIPTOR; 2914 gatt_client_run(); 2915 return ERROR_CODE_SUCCESS; 2916 } 2917 2918 uint8_t gatt_client_write_characteristic_descriptor(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_characteristic_descriptor_t * descriptor, uint16_t value_length, uint8_t * value){ 2919 return gatt_client_write_characteristic_descriptor_using_descriptor_handle(callback, con_handle, descriptor->handle, value_length, value); 2920 } 2921 2922 uint8_t gatt_client_write_long_characteristic_descriptor_using_descriptor_handle_with_offset(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t descriptor_handle, uint16_t offset, uint16_t value_length, uint8_t * value){ 2923 gatt_client_t * gatt_client; 2924 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2925 if (status != ERROR_CODE_SUCCESS){ 2926 return status; 2927 } 2928 2929 gatt_client->callback = callback; 2930 gatt_client->attribute_handle = descriptor_handle; 2931 gatt_client->attribute_length = value_length; 2932 gatt_client->attribute_offset = offset; 2933 gatt_client->attribute_value = value; 2934 gatt_client->state = P_W2_PREPARE_WRITE_CHARACTERISTIC_DESCRIPTOR; 2935 gatt_client_run(); 2936 return ERROR_CODE_SUCCESS; 2937 } 2938 2939 uint8_t gatt_client_write_long_characteristic_descriptor_using_descriptor_handle(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t descriptor_handle, uint16_t value_length, uint8_t * value){ 2940 return gatt_client_write_long_characteristic_descriptor_using_descriptor_handle_with_offset(callback, con_handle, descriptor_handle, 0, value_length, value); 2941 } 2942 2943 uint8_t gatt_client_write_long_characteristic_descriptor(btstack_packet_handler_t callback, hci_con_handle_t con_handle, gatt_client_characteristic_descriptor_t * descriptor, uint16_t value_length, uint8_t * value){ 2944 return gatt_client_write_long_characteristic_descriptor_using_descriptor_handle(callback, con_handle, descriptor->handle, value_length, value); 2945 } 2946 2947 /** 2948 * @brief -> gatt complete event 2949 */ 2950 uint8_t gatt_client_prepare_write(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint16_t attribute_handle, uint16_t offset, uint16_t value_length, uint8_t * value){ 2951 gatt_client_t * gatt_client; 2952 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2953 if (status != ERROR_CODE_SUCCESS){ 2954 return status; 2955 } 2956 2957 gatt_client->callback = callback; 2958 gatt_client->attribute_handle = attribute_handle; 2959 gatt_client->attribute_length = value_length; 2960 gatt_client->attribute_offset = offset; 2961 gatt_client->attribute_value = value; 2962 gatt_client->state = P_W2_PREPARE_WRITE_SINGLE; 2963 gatt_client_run(); 2964 return ERROR_CODE_SUCCESS; 2965 } 2966 2967 /** 2968 * @brief -> gatt complete event 2969 */ 2970 uint8_t gatt_client_execute_write(btstack_packet_handler_t callback, hci_con_handle_t con_handle){ 2971 gatt_client_t * gatt_client; 2972 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2973 if (status != ERROR_CODE_SUCCESS){ 2974 return status; 2975 } 2976 2977 gatt_client->callback = callback; 2978 gatt_client->state = P_W2_EXECUTE_PREPARED_WRITE; 2979 gatt_client_run(); 2980 return ERROR_CODE_SUCCESS; 2981 } 2982 2983 /** 2984 * @brief -> gatt complete event 2985 */ 2986 uint8_t gatt_client_cancel_write(btstack_packet_handler_t callback, hci_con_handle_t con_handle){ 2987 gatt_client_t * gatt_client; 2988 uint8_t status = gatt_client_provide_context_for_request(con_handle, &gatt_client); 2989 if (status != ERROR_CODE_SUCCESS){ 2990 return status; 2991 } 2992 2993 gatt_client->callback = callback; 2994 gatt_client->state = P_W2_CANCEL_PREPARED_WRITE; 2995 gatt_client_run(); 2996 return ERROR_CODE_SUCCESS; 2997 } 2998 2999 void gatt_client_deserialize_service(const uint8_t *packet, int offset, gatt_client_service_t * service){ 3000 service->start_group_handle = little_endian_read_16(packet, offset); 3001 service->end_group_handle = little_endian_read_16(packet, offset + 2); 3002 reverse_128(&packet[offset + 4], service->uuid128); 3003 if (uuid_has_bluetooth_prefix(service->uuid128)){ 3004 service->uuid16 = big_endian_read_32(service->uuid128, 0); 3005 } else { 3006 service->uuid16 = 0; 3007 } 3008 } 3009 3010 void gatt_client_deserialize_characteristic(const uint8_t * packet, int offset, gatt_client_characteristic_t * characteristic){ 3011 characteristic->start_handle = little_endian_read_16(packet, offset); 3012 characteristic->value_handle = little_endian_read_16(packet, offset + 2); 3013 characteristic->end_handle = little_endian_read_16(packet, offset + 4); 3014 characteristic->properties = little_endian_read_16(packet, offset + 6); 3015 reverse_128(&packet[offset+8], characteristic->uuid128); 3016 if (uuid_has_bluetooth_prefix(characteristic->uuid128)){ 3017 characteristic->uuid16 = big_endian_read_32(characteristic->uuid128, 0); 3018 } else { 3019 characteristic->uuid16 = 0; 3020 } 3021 } 3022 3023 void gatt_client_deserialize_characteristic_descriptor(const uint8_t * packet, int offset, gatt_client_characteristic_descriptor_t * descriptor){ 3024 descriptor->handle = little_endian_read_16(packet, offset); 3025 reverse_128(&packet[offset+2], descriptor->uuid128); 3026 if (uuid_has_bluetooth_prefix(descriptor->uuid128)){ 3027 descriptor->uuid16 = big_endian_read_32(descriptor->uuid128, 0); 3028 } else { 3029 descriptor->uuid16 = 0; 3030 } 3031 } 3032 3033 void gatt_client_send_mtu_negotiation(btstack_packet_handler_t callback, hci_con_handle_t con_handle){ 3034 gatt_client_t * gatt_client; 3035 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 3036 if (status != ERROR_CODE_SUCCESS){ 3037 return; 3038 } 3039 if (gatt_client->mtu_state == MTU_AUTO_EXCHANGE_DISABLED){ 3040 gatt_client->callback = callback; 3041 gatt_client->mtu_state = SEND_MTU_EXCHANGE; 3042 gatt_client_run(); 3043 } 3044 } 3045 3046 uint8_t gatt_client_request_to_write_without_response(btstack_context_callback_registration_t * callback_registration, hci_con_handle_t con_handle){ 3047 gatt_client_t * gatt_client; 3048 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 3049 if (status != ERROR_CODE_SUCCESS){ 3050 return status; 3051 } 3052 bool added = btstack_linked_list_add_tail(&gatt_client->write_without_response_requests, (btstack_linked_item_t*) callback_registration); 3053 if (added == false){ 3054 return ERROR_CODE_COMMAND_DISALLOWED; 3055 } else { 3056 att_dispatch_client_request_can_send_now_event(gatt_client->con_handle); 3057 return ERROR_CODE_SUCCESS; 3058 } 3059 } 3060 3061 uint8_t gatt_client_request_to_send_gatt_query(btstack_context_callback_registration_t * callback_registration, hci_con_handle_t con_handle){ 3062 gatt_client_t * gatt_client; 3063 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 3064 if (status != ERROR_CODE_SUCCESS){ 3065 return status; 3066 } 3067 bool added = btstack_linked_list_add_tail(&gatt_client->query_requests, (btstack_linked_item_t*) callback_registration); 3068 if (added == false){ 3069 return ERROR_CODE_COMMAND_DISALLOWED; 3070 } else { 3071 gatt_client_notify_can_send_query(gatt_client); 3072 return ERROR_CODE_SUCCESS; 3073 } 3074 } 3075 3076 uint8_t gatt_client_remove_gatt_query(btstack_context_callback_registration_t * callback_registration, hci_con_handle_t con_handle){ 3077 gatt_client_t * gatt_client; 3078 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 3079 if (status != ERROR_CODE_SUCCESS){ 3080 return status; 3081 } 3082 (void)btstack_linked_list_remove(&gatt_client->query_requests, (btstack_linked_item_t*) callback_registration); 3083 return ERROR_CODE_SUCCESS; 3084 } 3085 3086 uint8_t gatt_client_request_can_write_without_response_event(btstack_packet_handler_t callback, hci_con_handle_t con_handle){ 3087 gatt_client_t * gatt_client; 3088 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 3089 if (status != ERROR_CODE_SUCCESS){ 3090 return status; 3091 } 3092 if (gatt_client->write_without_response_callback != NULL){ 3093 return GATT_CLIENT_IN_WRONG_STATE; 3094 } 3095 gatt_client->write_without_response_callback = callback; 3096 att_dispatch_client_request_can_send_now_event(gatt_client->con_handle); 3097 return ERROR_CODE_SUCCESS; 3098 } 3099 3100 #ifdef ENABLE_GATT_CLIENT_SERVICE_CHANGED 3101 void gatt_client_add_service_changed_handler(btstack_packet_callback_registration_t * callback) { 3102 btstack_linked_list_add_tail(&gatt_client_service_changed_handler, (btstack_linked_item_t*) callback); 3103 } 3104 3105 void gatt_client_remove_service_changed_handler(btstack_packet_callback_registration_t * callback){ 3106 btstack_linked_list_remove(&gatt_client_service_changed_handler, (btstack_linked_item_t*) callback); 3107 } 3108 #endif 3109 3110 #if defined(ENABLE_GATT_OVER_CLASSIC) || defined(ENABLE_GATT_OVER_EATT) 3111 3112 #include "hci_event.h" 3113 3114 static const hci_event_t gatt_client_connected = { 3115 GATT_EVENT_CONNECTED, 0, "1BH" 3116 }; 3117 3118 static const hci_event_t gatt_client_disconnected = { 3119 GATT_EVENT_DISCONNECTED, 0, "H" 3120 }; 3121 3122 static void gatt_client_emit_connected(btstack_packet_handler_t callback, uint8_t status, bd_addr_t addr, 3123 hci_con_handle_t con_handle) { 3124 uint8_t buffer[20]; 3125 uint16_t len = hci_event_create_from_template_and_arguments(buffer, sizeof(buffer), &gatt_client_connected, status, addr, con_handle); 3126 (*callback)(HCI_EVENT_PACKET, 0, buffer, len); 3127 } 3128 3129 #endif 3130 3131 #ifdef ENABLE_GATT_OVER_CLASSIC 3132 3133 #include "bluetooth_psm.h" 3134 3135 // single active SDP query 3136 static gatt_client_t * gatt_client_classic_active_sdp_query; 3137 3138 // macos protocol descriptor list requires 16 bytes 3139 static uint8_t gatt_client_classic_sdp_buffer[32]; 3140 3141 3142 static gatt_client_t * gatt_client_get_context_for_classic_addr(bd_addr_t addr){ 3143 btstack_linked_item_t *it; 3144 for (it = (btstack_linked_item_t *) gatt_client_connections; it != NULL; it = it->next){ 3145 gatt_client_t * gatt_client = (gatt_client_t *) it; 3146 if (memcmp(gatt_client->addr, addr, 6) == 0){ 3147 return gatt_client; 3148 } 3149 } 3150 return NULL; 3151 } 3152 3153 static gatt_client_t * gatt_client_get_context_for_l2cap_cid(uint16_t l2cap_cid){ 3154 btstack_linked_item_t *it; 3155 for (it = (btstack_linked_item_t *) gatt_client_connections; it != NULL; it = it->next){ 3156 gatt_client_t * gatt_client = (gatt_client_t *) it; 3157 if (gatt_client->l2cap_cid == l2cap_cid){ 3158 return gatt_client; 3159 } 3160 } 3161 return NULL; 3162 } 3163 3164 static void gatt_client_classic_handle_connected(gatt_client_t * gatt_client, uint8_t status){ 3165 bd_addr_t addr; 3166 // cppcheck-suppress uninitvar ; addr is reported as uninitialized although it's the destination of the memcpy 3167 memcpy(addr, gatt_client->addr, 6); 3168 hci_con_handle_t con_handle = gatt_client->con_handle; 3169 btstack_packet_handler_t callback = gatt_client->callback; 3170 if (status != ERROR_CODE_SUCCESS){ 3171 btstack_linked_list_remove(&gatt_client_connections, (btstack_linked_item_t *) gatt_client); 3172 btstack_memory_gatt_client_free(gatt_client); 3173 } 3174 gatt_client_emit_connected(callback, status, addr, con_handle); 3175 } 3176 3177 static void gatt_client_classic_retry(btstack_timer_source_t * ts){ 3178 gatt_client_t * gatt_client = gatt_client_for_timer(ts); 3179 if (gatt_client != NULL){ 3180 gatt_client->state = P_W4_L2CAP_CONNECTION; 3181 att_dispatch_classic_connect(gatt_client->addr, gatt_client->l2cap_psm, &gatt_client->l2cap_cid); 3182 } 3183 } 3184 3185 static void gatt_client_classic_handle_disconnected(gatt_client_t * gatt_client){ 3186 3187 gatt_client_report_error_if_pending(gatt_client, ATT_ERROR_HCI_DISCONNECT_RECEIVED); 3188 gatt_client_timeout_stop(gatt_client); 3189 3190 hci_con_handle_t con_handle = gatt_client->con_handle; 3191 btstack_packet_handler_t callback = gatt_client->callback; 3192 btstack_linked_list_remove(&gatt_client_connections, (btstack_linked_item_t *) gatt_client); 3193 btstack_memory_gatt_client_free(gatt_client); 3194 3195 uint8_t buffer[20]; 3196 uint16_t len = hci_event_create_from_template_and_arguments(buffer, sizeof(buffer), &gatt_client_disconnected, con_handle); 3197 (*callback)(HCI_EVENT_PACKET, 0, buffer, len); 3198 } 3199 3200 static void gatt_client_handle_sdp_client_query_attribute_value(gatt_client_t * connection, uint8_t *packet){ 3201 des_iterator_t des_list_it; 3202 des_iterator_t prot_it; 3203 3204 if (sdp_event_query_attribute_byte_get_attribute_length(packet) <= sizeof(gatt_client_classic_sdp_buffer)) { 3205 gatt_client_classic_sdp_buffer[sdp_event_query_attribute_byte_get_data_offset(packet)] = sdp_event_query_attribute_byte_get_data(packet); 3206 if ((uint16_t)(sdp_event_query_attribute_byte_get_data_offset(packet)+1) == sdp_event_query_attribute_byte_get_attribute_length(packet)) { 3207 switch(sdp_event_query_attribute_byte_get_attribute_id(packet)) { 3208 case BLUETOOTH_ATTRIBUTE_PROTOCOL_DESCRIPTOR_LIST: 3209 for (des_iterator_init(&des_list_it, gatt_client_classic_sdp_buffer); des_iterator_has_more(&des_list_it); des_iterator_next(&des_list_it)) { 3210 uint8_t *des_element; 3211 uint8_t *element; 3212 uint32_t uuid; 3213 3214 if (des_iterator_get_type(&des_list_it) != DE_DES) continue; 3215 3216 des_element = des_iterator_get_element(&des_list_it); 3217 des_iterator_init(&prot_it, des_element); 3218 element = des_iterator_get_element(&prot_it); 3219 3220 if (de_get_element_type(element) != DE_UUID) continue; 3221 3222 uuid = de_get_uuid32(element); 3223 des_iterator_next(&prot_it); 3224 // we assume that the even if there are both roles supported, remote device uses the same psm and avdtp version for both 3225 switch (uuid){ 3226 case BLUETOOTH_PROTOCOL_L2CAP: 3227 if (!des_iterator_has_more(&prot_it)) continue; 3228 de_element_get_uint16(des_iterator_get_element(&prot_it), &connection->l2cap_psm); 3229 break; 3230 default: 3231 break; 3232 } 3233 } 3234 break; 3235 3236 default: 3237 break; 3238 } 3239 } 3240 } 3241 } 3242 3243 static void gatt_client_classic_sdp_handler(uint8_t packet_type, uint16_t handle, uint8_t *packet, uint16_t size){ 3244 gatt_client_t * gatt_client = gatt_client_classic_active_sdp_query; 3245 btstack_assert(gatt_client != NULL); 3246 uint8_t status; 3247 3248 // TODO: handle sdp events, get l2cap psm 3249 switch (hci_event_packet_get_type(packet)){ 3250 case SDP_EVENT_QUERY_ATTRIBUTE_VALUE: 3251 gatt_client_handle_sdp_client_query_attribute_value(gatt_client, packet); 3252 // TODO: 3253 return; 3254 case SDP_EVENT_QUERY_COMPLETE: 3255 status = sdp_event_query_complete_get_status(packet); 3256 gatt_client_classic_active_sdp_query = NULL; 3257 log_info("l2cap psm: %0x, status %02x", gatt_client->l2cap_psm, status); 3258 if (status != ERROR_CODE_SUCCESS) break; 3259 if (gatt_client->l2cap_psm == 0) { 3260 status = SDP_SERVICE_NOT_FOUND; 3261 break; 3262 } 3263 break; 3264 default: 3265 btstack_assert(false); 3266 return; 3267 } 3268 3269 // done 3270 if (status == ERROR_CODE_SUCCESS){ 3271 gatt_client->state = P_W4_L2CAP_CONNECTION; 3272 status = att_dispatch_classic_connect(gatt_client->addr, gatt_client->l2cap_psm, &gatt_client->l2cap_cid); 3273 } 3274 if (status != ERROR_CODE_SUCCESS) { 3275 gatt_client_classic_handle_connected(gatt_client, status); 3276 } 3277 } 3278 3279 static void gatt_client_classic_sdp_start(void * context){ 3280 gatt_client_classic_active_sdp_query = (gatt_client_t *) context; 3281 gatt_client_classic_active_sdp_query->state = P_W4_SDP_QUERY; 3282 sdp_client_query_uuid16(gatt_client_classic_sdp_handler, gatt_client_classic_active_sdp_query->addr, ORG_BLUETOOTH_SERVICE_GENERIC_ATTRIBUTE); 3283 } 3284 3285 static void gatt_client_classic_emit_connected(void * context){ 3286 gatt_client_t * gatt_client = (gatt_client_t *) context; 3287 gatt_client->state = P_READY; 3288 hci_connection_t * hci_connection = hci_connection_for_handle(gatt_client->con_handle); 3289 btstack_assert(hci_connection != NULL); 3290 gatt_client_emit_connected(gatt_client->callback, ERROR_CODE_SUCCESS, hci_connection->address, gatt_client->con_handle); 3291 } 3292 3293 uint8_t gatt_client_classic_connect(btstack_packet_handler_t callback, bd_addr_t addr){ 3294 gatt_client_t * gatt_client = gatt_client_get_context_for_classic_addr(addr); 3295 if (gatt_client != NULL){ 3296 return ERROR_CODE_ACL_CONNECTION_ALREADY_EXISTS; 3297 } 3298 gatt_client = btstack_memory_gatt_client_get(); 3299 if (gatt_client == NULL){ 3300 return ERROR_CODE_MEMORY_CAPACITY_EXCEEDED; 3301 } 3302 // init state 3303 gatt_client->bearer_type = ATT_BEARER_UNENHANCED_CLASSIC; 3304 gatt_client->con_handle = HCI_CON_HANDLE_INVALID; 3305 memcpy(gatt_client->addr, addr, 6); 3306 gatt_client->mtu = ATT_DEFAULT_MTU; 3307 gatt_client->security_level = LEVEL_0; 3308 gatt_client->mtu_state = MTU_AUTO_EXCHANGE_DISABLED; 3309 gatt_client->callback = callback; 3310 #ifdef ENABLE_GATT_OVER_EATT 3311 gatt_client->eatt_state = GATT_CLIENT_EATT_IDLE; 3312 #endif 3313 btstack_linked_list_add(&gatt_client_connections, (btstack_linked_item_t*)gatt_client); 3314 3315 // schedule emitted event if already connected, otherwise 3316 bool already_connected = false; 3317 hci_connection_t * hci_connection = hci_connection_for_bd_addr_and_type(addr, BD_ADDR_TYPE_ACL); 3318 if (hci_connection != NULL){ 3319 if (hci_connection->att_server.l2cap_cid != 0){ 3320 already_connected = true; 3321 } 3322 } 3323 gatt_client->callback_request.context = gatt_client; 3324 if (already_connected){ 3325 gatt_client->con_handle = hci_connection->con_handle; 3326 gatt_client->callback_request.callback = &gatt_client_classic_emit_connected; 3327 gatt_client->state = P_W2_EMIT_CONNECTED; 3328 btstack_run_loop_execute_on_main_thread(&gatt_client->callback_request); 3329 } else { 3330 gatt_client->callback_request.callback = &gatt_client_classic_sdp_start; 3331 gatt_client->state = P_W2_SDP_QUERY; 3332 sdp_client_register_query_callback(&gatt_client->callback_request); 3333 } 3334 return ERROR_CODE_SUCCESS; 3335 } 3336 3337 uint8_t gatt_client_classic_disconnect(btstack_packet_handler_t callback, hci_con_handle_t con_handle){ 3338 gatt_client_t * gatt_client = gatt_client_get_context_for_handle(con_handle); 3339 if (gatt_client == NULL){ 3340 return ERROR_CODE_UNKNOWN_CONNECTION_IDENTIFIER; 3341 } 3342 gatt_client->callback = callback; 3343 return l2cap_disconnect(gatt_client->l2cap_cid); 3344 } 3345 #endif 3346 3347 #ifdef ENABLE_GATT_OVER_EATT 3348 3349 #define MAX_NR_EATT_CHANNELS 5 3350 3351 static void gatt_client_le_enhanced_packet_handler(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size); 3352 3353 static uint8_t gatt_client_le_enhanced_num_eatt_clients_in_state(gatt_client_t * gatt_client, gatt_client_state_t state){ 3354 uint8_t num_clients = 0; 3355 btstack_linked_list_iterator_t it; 3356 btstack_linked_list_iterator_init(&it, &gatt_client->eatt_clients); 3357 while (btstack_linked_list_iterator_has_next(&it)){ 3358 gatt_client_t * eatt_client = (gatt_client_t *) btstack_linked_list_iterator_next(&it); 3359 if (eatt_client->state == state){ 3360 num_clients++; 3361 } 3362 } 3363 return num_clients; 3364 } 3365 3366 static void gatt_client_eatt_finalize(gatt_client_t * gatt_client) { 3367 // free eatt clients 3368 btstack_linked_list_iterator_t it; 3369 btstack_linked_list_iterator_init(&it, &gatt_client_connections); 3370 while (btstack_linked_list_iterator_has_next(&it)) { 3371 gatt_client_t *eatt_client = (gatt_client_t *) btstack_linked_list_iterator_next(&it); 3372 btstack_linked_list_iterator_remove(&it); 3373 btstack_memory_gatt_client_free(eatt_client); 3374 } 3375 } 3376 3377 // all channels connected 3378 static void gatt_client_le_enhanced_handle_connected(gatt_client_t * gatt_client, uint8_t status) { 3379 if (status == ERROR_CODE_SUCCESS){ 3380 uint8_t num_ready = gatt_client_le_enhanced_num_eatt_clients_in_state(gatt_client, P_READY); 3381 if (num_ready > 0){ 3382 gatt_client->eatt_state = GATT_CLIENT_EATT_READY; 3383 // free unused channels 3384 btstack_linked_list_iterator_t it; 3385 btstack_linked_list_iterator_init(&it, &gatt_client_connections); 3386 while (btstack_linked_list_iterator_has_next(&it)) { 3387 gatt_client_t *eatt_client = (gatt_client_t *) btstack_linked_list_iterator_next(&it); 3388 if (eatt_client->state == P_L2CAP_CLOSED){ 3389 btstack_linked_list_iterator_remove(&it); 3390 btstack_memory_gatt_client_free(eatt_client); 3391 } 3392 } 3393 } else { 3394 hci_connection_t * hci_connection = hci_connection_for_handle(gatt_client->con_handle); 3395 btstack_assert(hci_connection != NULL); 3396 if (hci_connection->att_server.incoming_connection_request){ 3397 hci_connection->att_server.incoming_connection_request = false; 3398 log_info("Collision, retry in 100ms"); 3399 gatt_client->state = P_W2_L2CAP_CONNECT; 3400 // set timer for retry 3401 btstack_run_loop_set_timer(&gatt_client->gc_timeout, GATT_CLIENT_COLLISION_BACKOFF_MS); 3402 btstack_run_loop_set_timer_handler(&gatt_client->gc_timeout, gatt_client_le_enhanced_retry); 3403 btstack_run_loop_add_timer(&gatt_client->gc_timeout); 3404 return; 3405 } else { 3406 gatt_client->eatt_state = GATT_CLIENT_EATT_IDLE; 3407 status = ERROR_CODE_CONNECTION_REJECTED_DUE_TO_LIMITED_RESOURCES; 3408 } 3409 } 3410 } else { 3411 gatt_client_eatt_finalize(gatt_client); 3412 gatt_client->eatt_state = GATT_CLIENT_EATT_IDLE; 3413 } 3414 3415 gatt_client_emit_connected(gatt_client->callback, status, gatt_client->addr, gatt_client->con_handle); 3416 } 3417 3418 // single channel disconnected 3419 static void gatt_client_le_enhanced_handle_ecbm_disconnected(gatt_client_t * gatt_client, gatt_client_t * eatt_client) { 3420 3421 // report error 3422 gatt_client_report_error_if_pending(eatt_client, ATT_ERROR_HCI_DISCONNECT_RECEIVED); 3423 3424 // free memory 3425 btstack_linked_list_remove(&gatt_client->eatt_clients, (btstack_linked_item_t *) eatt_client); 3426 btstack_memory_gatt_client_free(eatt_client); 3427 3428 // last channel 3429 if (btstack_linked_list_empty(&gatt_client->eatt_clients)){ 3430 hci_connection_t * hci_connection = hci_connection_for_handle(gatt_client->con_handle); 3431 hci_connection->att_server.eatt_outgoing_active = false; 3432 3433 if (gatt_client->eatt_state == GATT_CLIENT_EATT_READY) { 3434 // report disconnected if last channel closed 3435 uint8_t buffer[20]; 3436 uint16_t len = hci_event_create_from_template_and_arguments(buffer, sizeof(buffer), &gatt_client_disconnected, gatt_client->con_handle); 3437 (*gatt_client->callback)(HCI_EVENT_PACKET, 0, buffer, len); 3438 } 3439 } 3440 } 3441 3442 static gatt_client_t * gatt_client_le_enhanced_get_context_for_l2cap_cid(uint16_t l2cap_cid, gatt_client_t ** out_eatt_client){ 3443 btstack_linked_list_iterator_t it; 3444 btstack_linked_list_iterator_init(&it, &gatt_client_connections); 3445 while (btstack_linked_list_iterator_has_next(&it)) { 3446 gatt_client_t * gatt_client = (gatt_client_t *) btstack_linked_list_iterator_next(&it); 3447 btstack_linked_list_iterator_t it2; 3448 btstack_linked_list_iterator_init(&it2, &gatt_client->eatt_clients); 3449 while (btstack_linked_list_iterator_has_next(&it2)) { 3450 gatt_client_t * eatt_client = (gatt_client_t *) btstack_linked_list_iterator_next(&it2); 3451 if (eatt_client->l2cap_cid == l2cap_cid){ 3452 *out_eatt_client = eatt_client; 3453 return gatt_client; 3454 } 3455 } 3456 } 3457 return NULL; 3458 } 3459 3460 static void gatt_client_le_enhanced_setup_l2cap_channel(gatt_client_t * gatt_client){ 3461 uint8_t num_channels = gatt_client->eatt_num_clients; 3462 3463 // setup channels 3464 uint16_t buffer_size_per_client = gatt_client->eatt_storage_size / num_channels; 3465 uint16_t max_mtu = (buffer_size_per_client - REPORT_PREBUFFER_HEADER) / 2; 3466 uint8_t * receive_buffers[MAX_NR_EATT_CHANNELS]; 3467 uint16_t new_cids[MAX_NR_EATT_CHANNELS]; 3468 memset(gatt_client->eatt_storage_buffer, 0, gatt_client->eatt_storage_size); 3469 uint8_t i; 3470 for (i=0;i<gatt_client->eatt_num_clients; i++){ 3471 receive_buffers[i] = &gatt_client->eatt_storage_buffer[REPORT_PREBUFFER_HEADER]; 3472 gatt_client->eatt_storage_buffer += REPORT_PREBUFFER_HEADER + max_mtu; 3473 } 3474 3475 log_info("%u EATT clients with receive buffer size %u", gatt_client->eatt_num_clients, buffer_size_per_client); 3476 3477 uint8_t status = l2cap_ecbm_create_channels(&gatt_client_le_enhanced_packet_handler, 3478 gatt_client->con_handle, 3479 gatt_client->security_level, 3480 BLUETOOTH_PSM_EATT, num_channels, 3481 L2CAP_LE_AUTOMATIC_CREDITS, 3482 buffer_size_per_client, 3483 receive_buffers, 3484 new_cids); 3485 3486 if (status == ERROR_CODE_SUCCESS){ 3487 i = 0; 3488 btstack_linked_list_iterator_t it; 3489 btstack_linked_list_iterator_init(&it, &gatt_client->eatt_clients); 3490 while (btstack_linked_list_iterator_has_next(&it)) { 3491 gatt_client_t *new_eatt_client = (gatt_client_t *) btstack_linked_list_iterator_next(&it); 3492 3493 // init state with new cid and transmit buffer 3494 new_eatt_client->bearer_type = ATT_BEARER_ENHANCED_LE; 3495 new_eatt_client->con_handle = gatt_client->con_handle; 3496 new_eatt_client->mtu = 64; 3497 new_eatt_client->security_level = LEVEL_0; 3498 new_eatt_client->mtu_state = MTU_AUTO_EXCHANGE_DISABLED; 3499 new_eatt_client->state = P_W4_L2CAP_CONNECTION; 3500 new_eatt_client->l2cap_cid = new_cids[i]; 3501 new_eatt_client->eatt_storage_buffer = gatt_client->eatt_storage_buffer; 3502 gatt_client->eatt_storage_buffer += max_mtu; 3503 i++; 3504 } 3505 gatt_client->eatt_state = GATT_CLIENT_EATT_L2CAP_SETUP; 3506 } else { 3507 gatt_client_le_enhanced_handle_connected(gatt_client, status); 3508 } 3509 } 3510 3511 static void gatt_client_le_enhanced_retry(btstack_timer_source_t * ts){ 3512 gatt_client_t * gatt_client = gatt_client_for_timer(ts); 3513 if (gatt_client != NULL){ 3514 gatt_client->state = P_W4_L2CAP_CONNECTION; 3515 gatt_client_le_enhanced_setup_l2cap_channel(gatt_client); 3516 } 3517 } 3518 3519 static void gatt_client_le_enhanced_packet_handler(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size) { 3520 gatt_client_t *gatt_client; 3521 gatt_client_t *eatt_client; 3522 hci_con_handle_t con_handle; 3523 uint16_t l2cap_cid; 3524 uint8_t status; 3525 gatt_client_characteristic_t characteristic; 3526 gatt_client_service_t service; 3527 switch (packet_type) { 3528 case HCI_EVENT_PACKET: 3529 switch (hci_event_packet_get_type(packet)) { 3530 case GATT_EVENT_SERVICE_QUERY_RESULT: 3531 con_handle = gatt_event_service_query_result_get_handle(packet); 3532 gatt_client = gatt_client_get_context_for_handle(con_handle); 3533 btstack_assert(gatt_client != NULL); 3534 btstack_assert(gatt_client->eatt_state == GATT_CLIENT_EATT_DISCOVER_GATT_SERVICE_W4_DONE); 3535 gatt_event_service_query_result_get_service(packet, &service); 3536 gatt_client->gatt_service_start_group_handle = service.start_group_handle; 3537 gatt_client->gatt_service_end_group_handle = service.end_group_handle; 3538 break; 3539 case GATT_EVENT_CHARACTERISTIC_VALUE_QUERY_RESULT: 3540 con_handle = gatt_event_characteristic_value_query_result_get_handle(packet); 3541 gatt_client = gatt_client_get_context_for_handle(con_handle); 3542 btstack_assert(gatt_client != NULL); 3543 btstack_assert(gatt_client->eatt_state == GATT_CLIENT_EATT_READ_SERVER_SUPPORTED_FEATURES_W4_DONE); 3544 if (gatt_event_characteristic_value_query_result_get_value_length(packet) >= 1) { 3545 gatt_client->gatt_server_supported_features = gatt_event_characteristic_value_query_result_get_value(packet)[0]; 3546 } 3547 break; 3548 case GATT_EVENT_CHARACTERISTIC_QUERY_RESULT: 3549 con_handle = gatt_event_characteristic_query_result_get_handle(packet); 3550 gatt_client = gatt_client_get_context_for_handle(con_handle); 3551 btstack_assert(gatt_client != NULL); 3552 btstack_assert(gatt_client->eatt_state == GATT_CLIENT_EATT_FIND_CLIENT_SUPPORTED_FEATURES_W4_DONE); 3553 gatt_event_characteristic_query_result_get_characteristic(packet, &characteristic); 3554 gatt_client->gatt_client_supported_features_handle = characteristic.value_handle; 3555 break; 3556 case GATT_EVENT_QUERY_COMPLETE: 3557 con_handle = gatt_event_query_complete_get_handle(packet); 3558 gatt_client = gatt_client_get_context_for_handle(con_handle); 3559 btstack_assert(gatt_client != NULL); 3560 switch (gatt_client->eatt_state){ 3561 case GATT_CLIENT_EATT_DISCOVER_GATT_SERVICE_W4_DONE: 3562 if (gatt_client->gatt_service_start_group_handle == 0){ 3563 gatt_client_le_enhanced_handle_connected(gatt_client, ERROR_CODE_UNSUPPORTED_FEATURE_OR_PARAMETER_VALUE); 3564 } else { 3565 gatt_client->eatt_state = GATT_CLIENT_EATT_READ_SERVER_SUPPORTED_FEATURES_W2_SEND; 3566 } 3567 break; 3568 case GATT_CLIENT_EATT_READ_SERVER_SUPPORTED_FEATURES_W4_DONE: 3569 if ((gatt_client->gatt_server_supported_features & 1) == 0) { 3570 gatt_client_le_enhanced_handle_connected(gatt_client, ERROR_CODE_UNSUPPORTED_FEATURE_OR_PARAMETER_VALUE); 3571 } else { 3572 gatt_client->eatt_state = GATT_CLIENT_EATT_FIND_CLIENT_SUPPORTED_FEATURES_W2_SEND; 3573 } 3574 break; 3575 case GATT_CLIENT_EATT_FIND_CLIENT_SUPPORTED_FEATURES_W4_DONE: 3576 if (gatt_client->gatt_client_supported_features_handle == 0){ 3577 gatt_client_le_enhanced_handle_connected(gatt_client, ERROR_CODE_UNSUPPORTED_FEATURE_OR_PARAMETER_VALUE); 3578 } else { 3579 gatt_client->eatt_state = GATT_CLIENT_EATT_WRITE_ClIENT_SUPPORTED_FEATURES_W2_SEND; 3580 } 3581 break; 3582 case GATT_CLIENT_EATT_WRITE_ClIENT_SUPPORTED_FEATURES_W4_DONE: 3583 gatt_client_le_enhanced_setup_l2cap_channel(gatt_client); 3584 break; 3585 default: 3586 break; 3587 } 3588 break; 3589 case L2CAP_EVENT_ECBM_CHANNEL_OPENED: 3590 l2cap_cid = l2cap_event_ecbm_channel_opened_get_local_cid(packet); 3591 gatt_client = gatt_client_le_enhanced_get_context_for_l2cap_cid(l2cap_cid, &eatt_client); 3592 3593 btstack_assert(gatt_client != NULL); 3594 btstack_assert(eatt_client != NULL); 3595 btstack_assert(eatt_client->state == P_W4_L2CAP_CONNECTION); 3596 3597 status = l2cap_event_channel_opened_get_status(packet); 3598 if (status == ERROR_CODE_SUCCESS){ 3599 eatt_client->state = P_READY; 3600 eatt_client->mtu = l2cap_event_channel_opened_get_remote_mtu(packet); 3601 } else { 3602 eatt_client->state = P_L2CAP_CLOSED; 3603 } 3604 // connected if opened event for all channels received 3605 if (gatt_client_le_enhanced_num_eatt_clients_in_state(gatt_client, P_W4_L2CAP_CONNECTION) == 0){ 3606 gatt_client_le_enhanced_handle_connected(gatt_client, ERROR_CODE_SUCCESS); 3607 } 3608 break; 3609 case L2CAP_EVENT_CHANNEL_CLOSED: 3610 l2cap_cid = l2cap_event_channel_closed_get_local_cid(packet); 3611 gatt_client = gatt_client_le_enhanced_get_context_for_l2cap_cid(l2cap_cid, &eatt_client); 3612 btstack_assert(gatt_client != NULL); 3613 btstack_assert(eatt_client != NULL); 3614 gatt_client_le_enhanced_handle_ecbm_disconnected(gatt_client, eatt_client); 3615 break; 3616 default: 3617 break; 3618 } 3619 break; 3620 case L2CAP_DATA_PACKET: 3621 gatt_client = gatt_client_le_enhanced_get_context_for_l2cap_cid(channel, &eatt_client); 3622 btstack_assert(gatt_client != NULL); 3623 btstack_assert(eatt_client != NULL); 3624 gatt_client_handle_att_response(eatt_client, packet, size); 3625 gatt_client_run(); 3626 break; 3627 default: 3628 break; 3629 } 3630 } 3631 3632 static bool gatt_client_le_enhanced_handle_can_send_query(gatt_client_t * gatt_client){ 3633 uint8_t status = ERROR_CODE_SUCCESS; 3634 uint8_t gatt_client_supported_features = 0x06; // eatt + multiple value notifications 3635 switch (gatt_client->eatt_state){ 3636 case GATT_CLIENT_EATT_DISCOVER_GATT_SERVICE_W2_SEND: 3637 gatt_client->gatt_service_start_group_handle = 0; 3638 gatt_client->eatt_state = GATT_CLIENT_EATT_DISCOVER_GATT_SERVICE_W4_DONE; 3639 status = gatt_client_discover_primary_services_by_uuid16(&gatt_client_le_enhanced_packet_handler, 3640 gatt_client->con_handle, 3641 ORG_BLUETOOTH_SERVICE_GENERIC_ATTRIBUTE); 3642 break; 3643 case GATT_CLIENT_EATT_READ_SERVER_SUPPORTED_FEATURES_W2_SEND: 3644 gatt_client->gatt_server_supported_features = 0; 3645 gatt_client->eatt_state = GATT_CLIENT_EATT_READ_SERVER_SUPPORTED_FEATURES_W4_DONE; 3646 status = gatt_client_read_value_of_characteristics_by_uuid16(&gatt_client_le_enhanced_packet_handler, 3647 gatt_client->con_handle, 3648 gatt_client->gatt_service_start_group_handle, 3649 gatt_client->gatt_service_end_group_handle, 3650 ORG_BLUETOOTH_CHARACTERISTIC_SERVER_SUPPORTED_FEATURES); 3651 return true; 3652 case GATT_CLIENT_EATT_FIND_CLIENT_SUPPORTED_FEATURES_W2_SEND: 3653 gatt_client->gatt_client_supported_features_handle = 0; 3654 gatt_client->eatt_state = GATT_CLIENT_EATT_FIND_CLIENT_SUPPORTED_FEATURES_W4_DONE; 3655 status = gatt_client_discover_characteristics_for_handle_range_by_uuid16(&gatt_client_le_enhanced_packet_handler, 3656 gatt_client->con_handle, 3657 gatt_client->gatt_service_start_group_handle, 3658 gatt_client->gatt_service_end_group_handle, 3659 ORG_BLUETOOTH_CHARACTERISTIC_CLIENT_SUPPORTED_FEATURES); 3660 return true; 3661 case GATT_CLIENT_EATT_WRITE_ClIENT_SUPPORTED_FEATURES_W2_SEND: 3662 gatt_client->eatt_state = GATT_CLIENT_EATT_WRITE_ClIENT_SUPPORTED_FEATURES_W4_DONE; 3663 status = gatt_client_write_value_of_characteristic(&gatt_client_le_enhanced_packet_handler, gatt_client->con_handle, 3664 gatt_client->gatt_client_supported_features_handle, 1, 3665 &gatt_client_supported_features); 3666 return true; 3667 default: 3668 break; 3669 } 3670 btstack_assert(status == ERROR_CODE_SUCCESS); 3671 UNUSED(status); 3672 return false; 3673 } 3674 3675 uint8_t gatt_client_le_enhanced_connect(btstack_packet_handler_t callback, hci_con_handle_t con_handle, uint8_t num_channels, uint8_t * storage_buffer, uint16_t storage_size) { 3676 gatt_client_t * gatt_client; 3677 uint8_t status = gatt_client_provide_context_for_handle(con_handle, &gatt_client); 3678 if (status != ERROR_CODE_SUCCESS){ 3679 return status; 3680 } 3681 3682 if (gatt_client->eatt_state != GATT_CLIENT_EATT_IDLE){ 3683 return ERROR_CODE_COMMAND_DISALLOWED; 3684 } 3685 3686 // need one buffer for sending and one for receiving. Receiving includes pre-buffer for reports 3687 uint16_t buffer_size_per_client = storage_size / num_channels; 3688 uint16_t max_mtu = (buffer_size_per_client - REPORT_PREBUFFER_HEADER) / 2; 3689 if (max_mtu < 64) { 3690 return ERROR_CODE_INVALID_HCI_COMMAND_PARAMETERS; 3691 } 3692 3693 if ((num_channels == 0) || (num_channels > MAX_NR_EATT_CHANNELS)){ 3694 return ERROR_CODE_INVALID_HCI_COMMAND_PARAMETERS; 3695 } 3696 3697 // create max num_channel eatt clients 3698 uint8_t i; 3699 btstack_linked_list_t eatt_clients = NULL; 3700 for (i=0;i<num_channels;i++) { 3701 gatt_client_t * new_gatt_client = btstack_memory_gatt_client_get(); 3702 if (new_gatt_client == NULL) { 3703 break; 3704 } 3705 btstack_linked_list_add(&eatt_clients, (btstack_linked_item_t*)new_gatt_client); 3706 } 3707 3708 if (i != num_channels){ 3709 while (true){ 3710 gatt_client = (gatt_client_t *) btstack_linked_list_pop(&eatt_clients); 3711 if (gatt_client == NULL) { 3712 break; 3713 } 3714 btstack_memory_gatt_client_free(gatt_client); 3715 } 3716 return ERROR_CODE_MEMORY_CAPACITY_EXCEEDED; 3717 } 3718 3719 hci_connection_t * hci_connection = hci_connection_for_handle(con_handle); 3720 hci_connection->att_server.eatt_outgoing_active = true; 3721 3722 gatt_client->callback = callback; 3723 gatt_client->eatt_num_clients = num_channels; 3724 gatt_client->eatt_storage_buffer = storage_buffer; 3725 gatt_client->eatt_storage_size = storage_size; 3726 gatt_client->eatt_clients = eatt_clients; 3727 gatt_client->eatt_state = GATT_CLIENT_EATT_DISCOVER_GATT_SERVICE_W2_SEND; 3728 gatt_client_notify_can_send_query(gatt_client); 3729 3730 return ERROR_CODE_SUCCESS; 3731 } 3732 3733 #endif 3734 3735 #ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION 3736 void gatt_client_att_packet_handler_fuzz(uint8_t packet_type, uint16_t handle, uint8_t *packet, uint16_t size){ 3737 gatt_client_att_packet_handler(packet_type, handle, packet, size); 3738 } 3739 3740 uint8_t gatt_client_get_client(hci_con_handle_t con_handle, gatt_client_t ** out_gatt_client){ 3741 uint8_t status = gatt_client_provide_context_for_handle(con_handle, out_gatt_client); 3742 return status; 3743 } 3744 #endif 3745