xref: /btstack/src/classic/avrcp.c (revision 12448779a178f27ae262ca5990b01c627a82ab22)
1 /*
2  * Copyright (C) 2016 BlueKitchen GmbH
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  *
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  * 3. Neither the name of the copyright holders nor the names of
14  *    contributors may be used to endorse or promote products derived
15  *    from this software without specific prior written permission.
16  * 4. Any redistribution, use, or modification is done solely for
17  *    personal benefit and not for any commercial purpose or for
18  *    monetary gain.
19  *
20  * THIS SOFTWARE IS PROVIDED BY BLUEKITCHEN GMBH AND CONTRIBUTORS
21  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
22  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
23  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL BLUEKITCHEN
24  * GMBH OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
25  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
26  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
27  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
28  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
29  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
30  * THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  *
33  * Please inquire about commercial licensing options at
34  * [email protected]
35  *
36  */
37 
38 #define BTSTACK_FILE__ "avrcp.c"
39 
40 #include <stdint.h>
41 #include <string.h>
42 // snprintf
43 #include <stdio.h>
44 
45 #include "bluetooth_psm.h"
46 #include "bluetooth_sdp.h"
47 #include "btstack_debug.h"
48 #include "btstack_event.h"
49 #include "btstack_memory.h"
50 #include "classic/sdp_client.h"
51 #include "classic/sdp_util.h"
52 #include "classic/avrcp.h"
53 
54 
55 typedef struct {
56     uint8_t  parse_sdp_record;
57     uint32_t record_id;
58     uint16_t avrcp_cid;
59     uint16_t avrcp_l2cap_psm;
60     uint16_t avrcp_version;
61 
62     uint16_t browsing_l2cap_psm;
63     uint16_t browsing_version;
64 } avrcp_sdp_query_context_t;
65 
66 static void avrcp_packet_handler(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size);
67 
68 static const char * avrcp_default_controller_service_name = "BTstack AVRCP Controller Service";
69 static const char * avrcp_default_controller_service_provider_name = "BTstack AVRCP Controller Service Provider";
70 static const char * avrcp_defaul_target_service_name = "BTstack AVRCP Target Service";
71 static const char * avrcp_default_target_service_provider_name = "BTstack AVRCP Target Service Provider";
72 
73 static const char * avrcp_subunit_type_name[] = {
74         "MONITOR", "AUDIO", "PRINTER", "DISC", "TAPE_RECORDER_PLAYER", "TUNER",
75         "CA", "CAMERA", "RESERVED", "PANEL", "BULLETIN_BOARD", "CAMERA_STORAGE",
76         "VENDOR_UNIQUE", "RESERVED_FOR_ALL_SUBUNIT_TYPES",
77         "EXTENDED_TO_NEXT_BYTE", "UNIT", "ERROR"
78 };
79 
80 // default subunit info: single PANEL subunit
81 static const uint8_t avrcp_default_subunit_info[] = { AVRCP_SUBUNIT_TYPE_PANEL << 3};
82 
83 // globals
84 static bool avrcp_l2cap_service_registered = false;
85 
86 // connections
87 static uint16_t                 avrcp_cid_counter;
88 static btstack_linked_list_t    avrcp_connections;
89 
90 // higher layer callbacks
91 static btstack_packet_handler_t avrcp_callback;
92 static btstack_packet_handler_t avrcp_controller_packet_handler;
93 static btstack_packet_handler_t avrcp_target_packet_handler;
94 
95 // sdp query
96 static btstack_context_callback_registration_t avrcp_sdp_query_registration;
97 static avrcp_sdp_query_context_t               avrcp_sdp_query_context;
98 static uint8_t                                 avrcp_sdp_query_attribute_value[45];
99 static const unsigned int                      avrcp_sdp_query_attribute_value_buffer_size = sizeof(avrcp_sdp_query_attribute_value);
100 
101 
102 const char * avrcp_subunit2str(uint16_t index){
103     if (index <= 11) return avrcp_subunit_type_name[index];
104     if ((index >= 0x1C) && (index <= 0x1F)) return avrcp_subunit_type_name[index - 0x10];
105     return avrcp_subunit_type_name[16];
106 }
107 
108 static const char * avrcp_event_name[] = {
109     "ERROR", "PLAYBACK_STATUS_CHANGED",
110     "TRACK_CHANGED", "TRACK_REACHED_END", "TRACK_REACHED_START",
111     "PLAYBACK_POS_CHANGED", "BATT_STATUS_CHANGED", "SYSTEM_STATUS_CHANGED",
112     "PLAYER_APPLICATION_SETTING_CHANGED", "NOW_PLAYING_CONTENT_CHANGED",
113     "AVAILABLE_PLAYERS_CHANGED", "ADDRESSED_PLAYER_CHANGED", "UIDS_CHANGED", "VOLUME_CHANGED"
114 };
115 const char * avrcp_event2str(uint16_t index){
116     if (index <= 0x0d) return avrcp_event_name[index];
117     return avrcp_event_name[0];
118 }
119 
120 static const char * avrcp_operation_name[] = {
121     "SKIP", NULL, NULL, NULL, NULL,
122     "VOLUME_UP", "VOLUME_DOWN", "MUTE", "PLAY", "STOP", "PAUSE", NULL,
123     "REWIND", "FAST_FORWARD", NULL, "FORWARD", "BACKWARD" // 0x4C
124 };
125 
126 const char * avrcp_operation2str(uint8_t operation_id){
127     char * name = NULL;
128     if ((operation_id >= AVRCP_OPERATION_ID_SKIP) && (operation_id <= AVRCP_OPERATION_ID_BACKWARD)){
129         name = (char *)avrcp_operation_name[operation_id - AVRCP_OPERATION_ID_SKIP];
130     }
131     if (name == NULL){
132         static char buffer[13];
133         snprintf(buffer, sizeof(buffer), "Unknown 0x%02x", operation_id);
134         buffer[sizeof(buffer)-1] = 0;
135         return buffer;
136     } else {
137         return name;
138     }
139 }
140 
141 static const char * avrcp_media_attribute_id_name[] = {
142     "NONE", "TITLE", "ARTIST", "ALBUM", "TRACK", "TOTAL TRACKS", "GENRE", "SONG LENGTH"
143 };
144 const char * avrcp_attribute2str(uint8_t index){
145     if ((index >= 1) && (index <= 7)) return avrcp_media_attribute_id_name[index];
146     return avrcp_media_attribute_id_name[0];
147 }
148 
149 static const char * avrcp_play_status_name[] = {
150     "STOPPED", "PLAYING", "PAUSED", "FORWARD SEEK", "REVERSE SEEK",
151     "ERROR" // 0xFF
152 };
153 const char * avrcp_play_status2str(uint8_t index){
154     if (index > 4) {
155         return avrcp_play_status_name[5];
156     }
157     return avrcp_play_status_name[index];
158 }
159 
160 static const char * avrcp_ctype_name[] = {
161     "CONTROL",
162     "STATUS",
163     "SPECIFIC_INQUIRY",
164     "NOTIFY",
165     "GENERAL_INQUIRY",
166     "RESERVED5",
167     "RESERVED6",
168     "RESERVED7",
169     "NOT IMPLEMENTED IN REMOTE",
170     "ACCEPTED BY REMOTE",
171     "REJECTED BY REMOTE",
172     "IN_TRANSITION",
173     "IMPLEMENTED_STABLE",
174     "CHANGED_STABLE",
175     "RESERVED",
176     "INTERIM"
177 };
178 static const uint16_t avrcp_ctype_name_num = 16;
179 
180 const char * avrcp_ctype2str(uint8_t index){
181     if (index < avrcp_ctype_name_num){
182         return avrcp_ctype_name[index];
183     }
184     return "NONE";
185 }
186 
187 static const char * avrcp_shuffle_mode_name[] = {
188     "SHUFFLE OFF",
189     "SHUFFLE ALL TRACKS",
190     "SHUFFLE GROUP"
191 };
192 
193 const char * avrcp_shuffle2str(uint8_t index){
194     if ((index >= 1) && (index <= 3)) return avrcp_shuffle_mode_name[index-1];
195     return "NONE";
196 }
197 
198 static const char * avrcp_repeat_mode_name[] = {
199     "REPEAT OFF",
200     "REPEAT SINGLE TRACK",
201     "REPEAT ALL TRACKS",
202     "REPEAT GROUP"
203 };
204 
205 const char * avrcp_repeat2str(uint8_t index){
206     if ((index >= 1) && (index <= 4)) return avrcp_repeat_mode_name[index-1];
207     return "NONE";
208 }
209 
210 static const char * notification_name[] = {
211     "INVALID_INDEX",
212     "PLAYBACK_STATUS_CHANGED",
213     "TRACK_CHANGED",
214     "TRACK_REACHED_END",
215     "TRACK_REACHED_START",
216     "PLAYBACK_POS_CHANGED",
217     "BATT_STATUS_CHANGED",
218     "SYSTEM_STATUS_CHANGED",
219     "PLAYER_APPLICATION_SETTING_CHANGED",
220     "NOW_PLAYING_CONTENT_CHANGED",
221     "AVAILABLE_PLAYERS_CHANGED",
222     "ADDRESSED_PLAYER_CHANGED",
223     "UIDS_CHANGED",
224     "VOLUME_CHANGED",
225     "MAX_VALUE"
226 };
227 
228 const char * avrcp_notification2str(avrcp_notification_event_id_t index){
229     if ((index >= AVRCP_NOTIFICATION_EVENT_FIRST_INDEX) && (index <= AVRCP_NOTIFICATION_EVENT_LAST_INDEX)){
230         return notification_name[index];
231     }
232     return notification_name[0];
233 }
234 
235 btstack_linked_list_t avrcp_get_connections(void){
236     return avrcp_connections;
237 }
238 
239 uint8_t avrcp_cmd_opcode(uint8_t *packet, uint16_t size){
240     uint8_t cmd_opcode_index = 5;
241     if (cmd_opcode_index > size) return AVRCP_CMD_OPCODE_UNDEFINED;
242     return packet[cmd_opcode_index];
243 }
244 
245 void avrcp_create_sdp_record(uint8_t controller, uint8_t * service, uint32_t service_record_handle, uint8_t browsing, uint16_t supported_features,
246     const char * service_name, const char * service_provider_name){
247     uint8_t* attribute;
248     de_create_sequence(service);
249 
250     // 0x0000 "Service Record Handle"
251     de_add_number(service, DE_UINT, DE_SIZE_16, BLUETOOTH_ATTRIBUTE_SERVICE_RECORD_HANDLE);
252     de_add_number(service, DE_UINT, DE_SIZE_32, service_record_handle);
253 
254     // 0x0001 "Service Class ID List"
255     de_add_number(service,  DE_UINT, DE_SIZE_16, BLUETOOTH_ATTRIBUTE_SERVICE_CLASS_ID_LIST);
256     attribute = de_push_sequence(service);
257     {
258         if (controller){
259             de_add_number(attribute, DE_UUID, DE_SIZE_16, BLUETOOTH_SERVICE_CLASS_AV_REMOTE_CONTROL);
260             de_add_number(attribute, DE_UUID, DE_SIZE_16, BLUETOOTH_SERVICE_CLASS_AV_REMOTE_CONTROL_CONTROLLER);
261         } else {
262             de_add_number(attribute, DE_UUID, DE_SIZE_16, BLUETOOTH_SERVICE_CLASS_AV_REMOTE_CONTROL_TARGET);
263         }
264     }
265     de_pop_sequence(service, attribute);
266 
267     // 0x0004 "Protocol Descriptor List"
268     de_add_number(service,  DE_UINT, DE_SIZE_16, BLUETOOTH_ATTRIBUTE_PROTOCOL_DESCRIPTOR_LIST);
269     attribute = de_push_sequence(service);
270     {
271         uint8_t* l2cpProtocol = de_push_sequence(attribute);
272         {
273             de_add_number(l2cpProtocol,  DE_UUID, DE_SIZE_16, BLUETOOTH_PROTOCOL_L2CAP);
274             de_add_number(l2cpProtocol,  DE_UINT, DE_SIZE_16, BLUETOOTH_PSM_AVCTP);
275         }
276         de_pop_sequence(attribute, l2cpProtocol);
277 
278         uint8_t* avctpProtocol = de_push_sequence(attribute);
279         {
280             de_add_number(avctpProtocol,  DE_UUID, DE_SIZE_16, BLUETOOTH_PROTOCOL_AVCTP);  // avctpProtocol_service
281             de_add_number(avctpProtocol,  DE_UINT, DE_SIZE_16,  0x0104);    // version
282         }
283         de_pop_sequence(attribute, avctpProtocol);
284     }
285     de_pop_sequence(service, attribute);
286 
287     // 0x0005 "Public Browse Group"
288     de_add_number(service,  DE_UINT, DE_SIZE_16, BLUETOOTH_ATTRIBUTE_BROWSE_GROUP_LIST); // public browse group
289     attribute = de_push_sequence(service);
290     {
291         de_add_number(attribute,  DE_UUID, DE_SIZE_16, BLUETOOTH_ATTRIBUTE_PUBLIC_BROWSE_ROOT);
292     }
293     de_pop_sequence(service, attribute);
294 
295     // 0x0009 "Bluetooth Profile Descriptor List"
296     de_add_number(service,  DE_UINT, DE_SIZE_16, BLUETOOTH_ATTRIBUTE_BLUETOOTH_PROFILE_DESCRIPTOR_LIST);
297     attribute = de_push_sequence(service);
298     {
299         uint8_t *avrcProfile = de_push_sequence(attribute);
300         {
301             de_add_number(avrcProfile,  DE_UUID, DE_SIZE_16, BLUETOOTH_SERVICE_CLASS_AV_REMOTE_CONTROL);
302             de_add_number(avrcProfile,  DE_UINT, DE_SIZE_16, 0x0106);
303         }
304         de_pop_sequence(attribute, avrcProfile);
305     }
306     de_pop_sequence(service, attribute);
307 
308     // 0x000d "Additional Bluetooth Profile Descriptor List"
309     if (browsing){
310         de_add_number(service,  DE_UINT, DE_SIZE_16, BLUETOOTH_ATTRIBUTE_ADDITIONAL_PROTOCOL_DESCRIPTOR_LISTS);
311         attribute = de_push_sequence(service);
312         {
313             uint8_t * des = de_push_sequence(attribute);
314             {
315                 uint8_t* browsing_l2cpProtocol = de_push_sequence(des);
316                 {
317                     de_add_number(browsing_l2cpProtocol,  DE_UUID, DE_SIZE_16, BLUETOOTH_PROTOCOL_L2CAP);
318                     de_add_number(browsing_l2cpProtocol,  DE_UINT, DE_SIZE_16, BLUETOOTH_PSM_AVCTP_BROWSING);
319                 }
320                 de_pop_sequence(des, browsing_l2cpProtocol);
321 
322                 uint8_t* browsing_avctpProtocol = de_push_sequence(des);
323                 {
324                     de_add_number(browsing_avctpProtocol,  DE_UUID, DE_SIZE_16, BLUETOOTH_PROTOCOL_AVCTP);  // browsing_avctpProtocol_service
325                     de_add_number(browsing_avctpProtocol,  DE_UINT, DE_SIZE_16, 0x0104);                   // version
326                 }
327                 de_pop_sequence(des, browsing_avctpProtocol);
328             }
329             de_pop_sequence(attribute, des);
330         }
331         de_pop_sequence(service, attribute);
332     }
333 
334 
335     // 0x0100 "Service Name"
336     de_add_number(service,  DE_UINT, DE_SIZE_16, 0x0100);
337     if (service_name){
338         de_add_data(service,  DE_STRING, (uint16_t) strlen(service_name), (uint8_t *) service_name);
339     } else {
340         if (controller){
341             de_add_data(service, DE_STRING, (uint16_t) strlen(avrcp_default_controller_service_name), (uint8_t *) avrcp_default_controller_service_name);
342         } else {
343             de_add_data(service, DE_STRING, (uint16_t) strlen(avrcp_defaul_target_service_name), (uint8_t *) avrcp_defaul_target_service_name);
344         }
345     }
346 
347     // 0x0100 "Provider Name"
348     de_add_number(service,  DE_UINT, DE_SIZE_16, 0x0102);
349     if (service_provider_name){
350         de_add_data(service,  DE_STRING, (uint16_t) strlen(service_provider_name), (uint8_t *) service_provider_name);
351     } else {
352         if (controller){
353             de_add_data(service, DE_STRING, (uint16_t) strlen(avrcp_default_controller_service_provider_name), (uint8_t *) avrcp_default_controller_service_provider_name);
354         } else {
355             de_add_data(service, DE_STRING, (uint16_t) strlen(avrcp_default_target_service_provider_name), (uint8_t *) avrcp_default_target_service_provider_name);
356         }
357     }
358 
359     // 0x0311 "Supported Features"
360     de_add_number(service, DE_UINT, DE_SIZE_16, 0x0311);
361     de_add_number(service, DE_UINT, DE_SIZE_16, supported_features);
362 }
363 
364 uint16_t avctp_get_num_bytes_for_header(avctp_packet_type_t avctp_packet_type) {
365     switch (avctp_packet_type){
366         case AVCTP_SINGLE_PACKET:
367             // AVCTP message: transport header (1), pid (2)
368             return 3;
369         case AVCTP_START_PACKET:
370             // AVCTP message: transport header (1), num_packets (1), pid (2)
371             return 4;
372         default:
373             // AVCTP message: transport header (1)
374             return 1;
375     }
376 }
377 
378 uint16_t avrcp_get_num_bytes_for_header(avrcp_command_opcode_t command_opcode, avctp_packet_type_t avctp_packet_type) {
379     switch (avctp_packet_type){
380         case AVCTP_SINGLE_PACKET:
381         case AVCTP_START_PACKET:
382             break;
383         default:
384             return 0;
385     }
386 
387     uint16_t offset = 3; // AVRCP message: cmd type (1), subunit (1), opcode (1)
388     switch (command_opcode){
389         case AVRCP_CMD_OPCODE_VENDOR_DEPENDENT:
390             offset += 7; // AVRCP message:  company (3), pdu id(1), AVRCP packet type (1), param_len (2)
391             break;
392         case AVRCP_CMD_OPCODE_PASS_THROUGH:
393             offset += 3;  // AVRCP message: operation id (1), param_len (2)
394             break;
395         default:
396             break;
397     }
398     return offset;
399 }
400 
401 static uint16_t avrcp_get_num_free_bytes_for_payload(uint16_t l2cap_mtu, avrcp_command_opcode_t command_opcode, avctp_packet_type_t avctp_packet_type){
402     uint16_t max_frame_size = btstack_min(l2cap_mtu, AVRCP_MAX_AV_C_MESSAGE_FRAME_SIZE);
403     uint16_t payload_offset = avctp_get_num_bytes_for_header(avctp_packet_type) +
404                               avrcp_get_num_bytes_for_header(command_opcode, avctp_packet_type);
405 
406     btstack_assert(max_frame_size >= payload_offset);
407     return (max_frame_size - payload_offset);
408 }
409 
410 
411 avctp_packet_type_t avctp_get_packet_type(avrcp_connection_t * connection, uint16_t * max_payload_size){
412     if (connection->l2cap_mtu >= AVRCP_MAX_AV_C_MESSAGE_FRAME_SIZE){
413         return AVCTP_SINGLE_PACKET;
414     }
415 
416     if (connection->data_offset == 0){
417         uint16_t max_payload_size_for_single_packet = avrcp_get_num_free_bytes_for_payload(connection->l2cap_mtu,
418                                                                  connection->command_opcode,
419                                                                  AVCTP_SINGLE_PACKET);
420         if (max_payload_size_for_single_packet >= connection->data_len){
421             *max_payload_size = max_payload_size_for_single_packet;
422             return AVCTP_SINGLE_PACKET;
423         } else {
424             uint16_t max_payload_size_for_start_packet = max_payload_size_for_single_packet - 1;
425             *max_payload_size = max_payload_size_for_start_packet;
426             return AVCTP_START_PACKET;
427         }
428     } else {
429         // both packet types have the same single byte AVCTP header
430         *max_payload_size = avrcp_get_num_free_bytes_for_payload(connection->l2cap_mtu,
431                                                                  connection->command_opcode,
432                                                                  AVCTP_CONTINUE_PACKET);
433         if ((connection->data_len - connection->data_offset) > *max_payload_size){
434             return AVCTP_CONTINUE_PACKET;
435         } else {
436             return AVCTP_END_PACKET;
437         }
438     }
439 }
440 
441 avrcp_packet_type_t avrcp_get_packet_type(avrcp_connection_t * connection){
442     switch (connection->avctp_packet_type) {
443         case AVCTP_SINGLE_PACKET:
444         case AVCTP_START_PACKET:
445             break;
446         default:
447             return connection->avrcp_packet_type;
448     }
449 
450     uint16_t payload_offset = avctp_get_num_bytes_for_header(connection->avctp_packet_type) +
451                               avrcp_get_num_bytes_for_header(connection->command_opcode, connection->avctp_packet_type);
452     uint16_t bytes_to_send = (connection->data_len - connection->data_offset) + payload_offset;
453 
454     if (connection->data_offset == 0){
455         if (bytes_to_send <= AVRCP_MAX_AV_C_MESSAGE_FRAME_SIZE){
456             return AVRCP_SINGLE_PACKET;
457         } else {
458             return AVRCP_START_PACKET;
459         }
460     } else {
461         if (bytes_to_send > AVRCP_MAX_AV_C_MESSAGE_FRAME_SIZE){
462             return AVRCP_CONTINUE_PACKET;
463         } else {
464             return AVRCP_END_PACKET;
465         }
466     }
467 }
468 
469 avrcp_connection_t * avrcp_get_connection_for_bd_addr_for_role(avrcp_role_t role, bd_addr_t addr){
470     btstack_linked_list_iterator_t it;
471     btstack_linked_list_iterator_init(&it, (btstack_linked_list_t *) &avrcp_connections);
472     while (btstack_linked_list_iterator_has_next(&it)){
473         avrcp_connection_t * connection = (avrcp_connection_t *)btstack_linked_list_iterator_next(&it);
474         if (connection->role != role) continue;
475         if (memcmp(addr, connection->remote_addr, 6) != 0) continue;
476         return connection;
477     }
478     return NULL;
479 }
480 
481 avrcp_connection_t * avrcp_get_connection_for_l2cap_signaling_cid_for_role(avrcp_role_t role, uint16_t l2cap_cid){
482     btstack_linked_list_iterator_t it;
483     btstack_linked_list_iterator_init(&it, (btstack_linked_list_t *) &avrcp_connections);
484     while (btstack_linked_list_iterator_has_next(&it)){
485         avrcp_connection_t * connection = (avrcp_connection_t *)btstack_linked_list_iterator_next(&it);
486         if (connection->role != role) continue;
487         if (connection->l2cap_signaling_cid != l2cap_cid) continue;
488         return connection;
489     }
490     return NULL;
491 }
492 
493 avrcp_connection_t * avrcp_get_connection_for_avrcp_cid_for_role(avrcp_role_t role, uint16_t avrcp_cid){
494     btstack_linked_list_iterator_t it;
495     btstack_linked_list_iterator_init(&it, (btstack_linked_list_t *) &avrcp_connections);
496     while (btstack_linked_list_iterator_has_next(&it)){
497         avrcp_connection_t * connection = (avrcp_connection_t *)btstack_linked_list_iterator_next(&it);
498         if (connection->role != role) continue;
499         if (connection->avrcp_cid != avrcp_cid) continue;
500         return connection;
501     }
502     return NULL;
503 }
504 
505 avrcp_connection_t * avrcp_get_connection_for_browsing_cid_for_role(avrcp_role_t role, uint16_t browsing_cid){
506     btstack_linked_list_iterator_t it;
507     btstack_linked_list_iterator_init(&it, (btstack_linked_list_t *) &avrcp_connections);
508     while (btstack_linked_list_iterator_has_next(&it)){
509         avrcp_connection_t * connection = (avrcp_connection_t *)btstack_linked_list_iterator_next(&it);
510         if (connection->role != role) continue;
511         if (connection->avrcp_browsing_cid != browsing_cid) continue;
512         return connection;
513     }
514     return NULL;
515 }
516 
517 avrcp_connection_t * avrcp_get_connection_for_browsing_l2cap_cid_for_role(avrcp_role_t role, uint16_t browsing_l2cap_cid){
518     btstack_linked_list_iterator_t it;
519     btstack_linked_list_iterator_init(&it, (btstack_linked_list_t *) &avrcp_connections);
520     while (btstack_linked_list_iterator_has_next(&it)){
521         avrcp_connection_t * connection = (avrcp_connection_t *)btstack_linked_list_iterator_next(&it);
522         if (connection->role != role) continue;
523         if (connection->browsing_connection &&  (connection->browsing_connection->l2cap_browsing_cid != browsing_l2cap_cid)) continue;
524         return connection;
525     }
526     return NULL;
527 }
528 
529 avrcp_browsing_connection_t * avrcp_get_browsing_connection_for_l2cap_cid_for_role(avrcp_role_t role, uint16_t l2cap_cid){
530     btstack_linked_list_iterator_t it;
531     btstack_linked_list_iterator_init(&it, (btstack_linked_list_t *) &avrcp_connections);
532     while (btstack_linked_list_iterator_has_next(&it)){
533         avrcp_connection_t * connection = (avrcp_connection_t *)btstack_linked_list_iterator_next(&it);
534         if (connection->role != role) continue;
535         if (connection->browsing_connection && (connection->browsing_connection->l2cap_browsing_cid != l2cap_cid)) continue;
536         return connection->browsing_connection;
537     }
538     return NULL;
539 }
540 
541 void avrcp_request_can_send_now(avrcp_connection_t * connection, uint16_t l2cap_cid){
542     connection->wait_to_send = true;
543     l2cap_request_can_send_now_event(l2cap_cid);
544 }
545 
546 uint16_t avrcp_get_next_cid(avrcp_role_t role){
547     do {
548         if (avrcp_cid_counter == 0xffff) {
549             avrcp_cid_counter = 1;
550         } else {
551             avrcp_cid_counter++;
552         }
553     } while (avrcp_get_connection_for_avrcp_cid_for_role(role, avrcp_cid_counter) !=  NULL) ;
554     return avrcp_cid_counter;
555 }
556 
557 static avrcp_connection_t * avrcp_create_connection(avrcp_role_t role, bd_addr_t remote_addr){
558     avrcp_connection_t * connection = btstack_memory_avrcp_connection_get();
559     if (!connection){
560         log_error("Not enough memory to create connection for role %d", role);
561         return NULL;
562     }
563 
564     connection->state = AVCTP_CONNECTION_IDLE;
565     connection->role = role;
566 
567     connection->transaction_id = 0xFF;
568     connection->transaction_id_counter = 0;
569 
570     connection->controller_max_num_fragments = 0xFF;
571 
572     // setup default unit / subunit info
573     connection->company_id = 0xffffff;
574     connection->target_unit_type = AVRCP_SUBUNIT_TYPE_PANEL;
575     connection->target_subunit_info_data_size = sizeof(avrcp_default_subunit_info);
576     connection->target_subunit_info_data = avrcp_default_subunit_info;
577 
578     log_info("avrcp_create_connection, role %d", role);
579     (void)memcpy(connection->remote_addr, remote_addr, 6);
580     btstack_linked_list_add(&avrcp_connections, (btstack_linked_item_t *) connection);
581     return connection;
582 }
583 
584 static void avrcp_finalize_connection(avrcp_connection_t * connection){
585     btstack_run_loop_remove_timer(&connection->retry_timer);
586     btstack_run_loop_remove_timer(&connection->controller_press_and_hold_cmd_timer);
587     btstack_linked_list_remove(&avrcp_connections, (btstack_linked_item_t*) connection);
588     btstack_memory_avrcp_connection_free(connection);
589 }
590 
591 static void avrcp_emit_connection_established(uint16_t avrcp_cid, bd_addr_t addr, hci_con_handle_t con_handle, uint8_t status){
592     btstack_assert(avrcp_callback != NULL);
593 
594     uint8_t event[14];
595     int pos = 0;
596     event[pos++] = HCI_EVENT_AVRCP_META;
597     event[pos++] = sizeof(event) - 2;
598     event[pos++] = AVRCP_SUBEVENT_CONNECTION_ESTABLISHED;
599     event[pos++] = status;
600     little_endian_store_16(event, pos, avrcp_cid);
601     pos += 2;
602     reverse_bd_addr(addr,&event[pos]);
603     pos += 6;
604     little_endian_store_16(event, pos, con_handle);
605     pos += 2;
606     (*avrcp_callback)(HCI_EVENT_PACKET, 0, event, sizeof(event));
607 }
608 
609 static void avrcp_emit_connection_closed(uint16_t avrcp_cid){
610     btstack_assert(avrcp_callback != NULL);
611 
612     uint8_t event[5];
613     int pos = 0;
614     event[pos++] = HCI_EVENT_AVRCP_META;
615     event[pos++] = sizeof(event) - 2;
616     event[pos++] = AVRCP_SUBEVENT_CONNECTION_RELEASED;
617     little_endian_store_16(event, pos, avrcp_cid);
618     pos += 2;
619     (*avrcp_callback)(HCI_EVENT_PACKET, 0, event, sizeof(event));
620 }
621 
622 uint16_t avrcp_sdp_query_browsing_l2cap_psm(void){
623     return avrcp_sdp_query_context.browsing_l2cap_psm;
624 }
625 
626 void avrcp_handle_sdp_client_query_attribute_value(uint8_t *packet){
627     des_iterator_t des_list_it;
628     des_iterator_t prot_it;
629 
630     // Handle new SDP record
631     if (sdp_event_query_attribute_byte_get_record_id(packet) != avrcp_sdp_query_context.record_id) {
632         avrcp_sdp_query_context.record_id = sdp_event_query_attribute_byte_get_record_id(packet);
633         avrcp_sdp_query_context.parse_sdp_record = 0;
634         // log_info("SDP Record: Nr: %d", record_id);
635     }
636 
637     if (sdp_event_query_attribute_byte_get_attribute_length(packet) <= avrcp_sdp_query_attribute_value_buffer_size) {
638         avrcp_sdp_query_attribute_value[sdp_event_query_attribute_byte_get_data_offset(packet)] = sdp_event_query_attribute_byte_get_data(packet);
639 
640         if ((uint16_t)(sdp_event_query_attribute_byte_get_data_offset(packet)+1) == sdp_event_query_attribute_byte_get_attribute_length(packet)) {
641             switch(sdp_event_query_attribute_byte_get_attribute_id(packet)) {
642                 case BLUETOOTH_ATTRIBUTE_SERVICE_CLASS_ID_LIST:
643                     if (de_get_element_type(avrcp_sdp_query_attribute_value) != DE_DES) break;
644                     for (des_iterator_init(&des_list_it, avrcp_sdp_query_attribute_value); des_iterator_has_more(&des_list_it); des_iterator_next(&des_list_it)) {
645                         uint8_t * element = des_iterator_get_element(&des_list_it);
646                         if (de_get_element_type(element) != DE_UUID) continue;
647                         uint32_t uuid = de_get_uuid32(element);
648                         switch (uuid){
649                             case BLUETOOTH_SERVICE_CLASS_AV_REMOTE_CONTROL_TARGET:
650                             case BLUETOOTH_SERVICE_CLASS_AV_REMOTE_CONTROL:
651                             case BLUETOOTH_SERVICE_CLASS_AV_REMOTE_CONTROL_CONTROLLER:
652                                 avrcp_sdp_query_context.parse_sdp_record = 1;
653                                 break;
654                             default:
655                                 break;
656                         }
657                     }
658                     break;
659 
660                 case BLUETOOTH_ATTRIBUTE_PROTOCOL_DESCRIPTOR_LIST: {
661                     if (!avrcp_sdp_query_context.parse_sdp_record) break;
662                     // log_info("SDP Attribute: 0x%04x", sdp_event_query_attribute_byte_get_attribute_id(packet));
663                     for (des_iterator_init(&des_list_it, avrcp_sdp_query_attribute_value); des_iterator_has_more(&des_list_it); des_iterator_next(&des_list_it)) {
664                         uint8_t       *des_element;
665                         uint8_t       *element;
666                         uint32_t       uuid;
667 
668                         if (des_iterator_get_type(&des_list_it) != DE_DES) continue;
669 
670                         des_element = des_iterator_get_element(&des_list_it);
671                         des_iterator_init(&prot_it, des_element);
672                         element = des_iterator_get_element(&prot_it);
673 
674                         if (de_get_element_type(element) != DE_UUID) continue;
675 
676                         uuid = de_get_uuid32(element);
677                         des_iterator_next(&prot_it);
678                         switch (uuid){
679                             case BLUETOOTH_PROTOCOL_L2CAP:
680                                 if (!des_iterator_has_more(&prot_it)) continue;
681                                 de_element_get_uint16(des_iterator_get_element(&prot_it), &avrcp_sdp_query_context.avrcp_l2cap_psm);
682                                 break;
683                             case BLUETOOTH_PROTOCOL_AVCTP:
684                                 if (!des_iterator_has_more(&prot_it)) continue;
685                                 de_element_get_uint16(des_iterator_get_element(&prot_it), &avrcp_sdp_query_context.avrcp_version);
686                                 break;
687                             default:
688                                 break;
689                         }
690                     }
691                 }
692                     break;
693                 case BLUETOOTH_ATTRIBUTE_ADDITIONAL_PROTOCOL_DESCRIPTOR_LISTS: {
694                     // log_info("SDP Attribute: 0x%04x", sdp_event_query_attribute_byte_get_attribute_id(packet));
695                     if (!avrcp_sdp_query_context.parse_sdp_record) break;
696                     if (de_get_element_type(avrcp_sdp_query_attribute_value) != DE_DES) break;
697 
698                     des_iterator_t des_list_0_it;
699                     uint8_t       *element_0;
700 
701                     des_iterator_init(&des_list_0_it, avrcp_sdp_query_attribute_value);
702                     element_0 = des_iterator_get_element(&des_list_0_it);
703 
704                     for (des_iterator_init(&des_list_it, element_0); des_iterator_has_more(&des_list_it); des_iterator_next(&des_list_it)) {
705                         uint8_t       *des_element;
706                         uint8_t       *element;
707                         uint32_t       uuid;
708 
709                         if (des_iterator_get_type(&des_list_it) != DE_DES) continue;
710 
711                         des_element = des_iterator_get_element(&des_list_it);
712                         des_iterator_init(&prot_it, des_element);
713                         element = des_iterator_get_element(&prot_it);
714 
715                         if (de_get_element_type(element) != DE_UUID) continue;
716 
717                         uuid = de_get_uuid32(element);
718                         des_iterator_next(&prot_it);
719                         switch (uuid){
720                             case BLUETOOTH_PROTOCOL_L2CAP:
721                                 if (!des_iterator_has_more(&prot_it)) continue;
722                                 de_element_get_uint16(des_iterator_get_element(&prot_it), &avrcp_sdp_query_context.browsing_l2cap_psm);
723                                 break;
724                             case BLUETOOTH_PROTOCOL_AVCTP:
725                                 if (!des_iterator_has_more(&prot_it)) continue;
726                                 de_element_get_uint16(des_iterator_get_element(&prot_it), &avrcp_sdp_query_context.browsing_version);
727                                 break;
728                             default:
729                                 break;
730                         }
731                     }
732                 }
733                     break;
734                 default:
735                     break;
736             }
737         }
738     } else {
739         log_error("SDP attribute value buffer size exceeded: available %d, required %d", avrcp_sdp_query_attribute_value_buffer_size, sdp_event_query_attribute_byte_get_attribute_length(packet));
740     }
741 }
742 
743 static void avrcp_handle_sdp_query_failed(avrcp_connection_t * connection, uint8_t status){
744     if (connection == NULL) return;
745     log_info("AVRCP: SDP query failed with status 0x%02x.", status);
746     avrcp_emit_connection_established(connection->avrcp_cid, connection->remote_addr, connection->con_handle, status);
747     avrcp_finalize_connection(connection);
748 }
749 
750 static void avrcp_handle_sdp_query_succeeded(avrcp_connection_t * connection){
751     if (connection == NULL) return;
752     connection->state = AVCTP_CONNECTION_W4_L2CAP_CONNECTED;
753     connection->avrcp_l2cap_psm = avrcp_sdp_query_context.avrcp_l2cap_psm;
754     connection->browsing_version = avrcp_sdp_query_context.browsing_version;
755     connection->browsing_l2cap_psm = avrcp_sdp_query_context.browsing_l2cap_psm;
756 }
757 
758 static void avrcp_handle_sdp_client_query_result(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size){
759     UNUSED(packet_type);
760     UNUSED(channel);
761     UNUSED(size);
762 
763     bool state_ok = true;
764     avrcp_connection_t * avrcp_target_connection = avrcp_get_connection_for_avrcp_cid_for_role(AVRCP_TARGET, avrcp_sdp_query_context.avrcp_cid);
765     if (!avrcp_target_connection || avrcp_target_connection->state != AVCTP_CONNECTION_W4_SDP_QUERY_COMPLETE) {
766         state_ok = false;
767     }
768     avrcp_connection_t * avrcp_controller_connection = avrcp_get_connection_for_avrcp_cid_for_role(AVRCP_CONTROLLER, avrcp_sdp_query_context.avrcp_cid);
769     if (!avrcp_controller_connection || avrcp_controller_connection->state != AVCTP_CONNECTION_W4_SDP_QUERY_COMPLETE) {
770         state_ok = false;
771     }
772     if (!state_ok){
773         // something wrong, nevertheless, start next sdp query if this one is complete
774         if (hci_event_packet_get_type(packet) == SDP_EVENT_QUERY_COMPLETE){
775             (void) sdp_client_register_query_callback(&avrcp_sdp_query_registration);
776         }
777         return;
778     }
779 
780     uint8_t status;
781 
782     switch (hci_event_packet_get_type(packet)){
783         case SDP_EVENT_QUERY_ATTRIBUTE_VALUE:
784             avrcp_handle_sdp_client_query_attribute_value(packet);
785             return;
786 
787         case SDP_EVENT_QUERY_COMPLETE:
788             status = sdp_event_query_complete_get_status(packet);
789 
790             if (status != ERROR_CODE_SUCCESS){
791                 avrcp_handle_sdp_query_failed(avrcp_controller_connection, status);
792                 avrcp_handle_sdp_query_failed(avrcp_target_connection, status);
793                 break;
794             }
795 
796             if (!avrcp_sdp_query_context.avrcp_l2cap_psm){
797                 avrcp_handle_sdp_query_failed(avrcp_controller_connection, SDP_SERVICE_NOT_FOUND);
798                 avrcp_handle_sdp_query_failed(avrcp_target_connection, SDP_SERVICE_NOT_FOUND);
799                 break;
800             }
801 
802             avrcp_handle_sdp_query_succeeded(avrcp_controller_connection);
803             avrcp_handle_sdp_query_succeeded(avrcp_target_connection);
804 
805             l2cap_create_channel(&avrcp_packet_handler, avrcp_target_connection->remote_addr, avrcp_sdp_query_context.avrcp_l2cap_psm, l2cap_max_mtu(), NULL);
806             break;
807 
808         default:
809             return;
810     }
811 
812     // register the SDP Query request to check if there is another connection waiting for the query
813     // ignore ERROR_CODE_COMMAND_DISALLOWED because in that case, we already have requested an SDP callback
814     (void) sdp_client_register_query_callback(&avrcp_sdp_query_registration);
815 }
816 
817 
818 static avrcp_connection_t * avrcp_handle_incoming_connection_for_role(avrcp_role_t role, avrcp_connection_t * connection, bd_addr_t event_addr, hci_con_handle_t con_handle, uint16_t local_cid, uint16_t avrcp_cid){
819     if (connection == NULL){
820         connection = avrcp_create_connection(role, event_addr);
821     }
822     if (connection) {
823         connection->state = AVCTP_CONNECTION_W4_L2CAP_CONNECTED;
824         connection->l2cap_signaling_cid = local_cid;
825         connection->avrcp_cid = avrcp_cid;
826         connection->con_handle = con_handle;
827         btstack_run_loop_remove_timer(&connection->retry_timer);
828     }
829     return connection;
830 }
831 
832 static void avrcp_handle_open_connection(avrcp_connection_t * connection, hci_con_handle_t con_handle, uint16_t local_cid, uint16_t l2cap_mtu){
833     connection->l2cap_signaling_cid = local_cid;
834     connection->l2cap_mtu = l2cap_mtu;
835     connection->con_handle = con_handle;
836     connection->incoming_declined = false;
837     connection->target_song_length_ms = 0xFFFFFFFF;
838     connection->target_song_position_ms = 0xFFFFFFFF;
839     memset(connection->target_track_id, 0xFF, 8);
840     connection->target_track_selected = false;
841     connection->target_track_changed = false;
842     connection->target_playback_status = AVRCP_PLAYBACK_STATUS_STOPPED;
843     connection->state = AVCTP_CONNECTION_OPENED;
844 
845     log_info("L2CAP_EVENT_CHANNEL_OPENED avrcp_cid 0x%02x, l2cap_signaling_cid 0x%02x, role %d, state %d", connection->avrcp_cid, connection->l2cap_signaling_cid, connection->role, connection->state);
846 }
847 
848 static void avrcp_retry_timer_timeout_handler(btstack_timer_source_t * timer){
849     uint16_t avrcp_cid = (uint16_t)(uintptr_t) btstack_run_loop_get_timer_context(timer);
850     avrcp_connection_t * connection_controller = avrcp_get_connection_for_avrcp_cid_for_role(AVRCP_CONTROLLER, avrcp_cid);
851     if (connection_controller == NULL) return;
852     avrcp_connection_t * connection_target = avrcp_get_connection_for_avrcp_cid_for_role(AVRCP_TARGET, avrcp_cid);
853     if (connection_target == NULL) return;
854 
855     if (connection_controller->state == AVCTP_CONNECTION_W2_L2CAP_RETRY){
856         connection_controller->state = AVCTP_CONNECTION_W4_L2CAP_CONNECTED;
857         connection_target->state = AVCTP_CONNECTION_W4_L2CAP_CONNECTED;
858         l2cap_create_channel(&avrcp_packet_handler, connection_controller->remote_addr, connection_controller->avrcp_l2cap_psm, l2cap_max_mtu(), NULL);
859     }
860 }
861 
862 static void avrcp_retry_timer_start(avrcp_connection_t * connection){
863     btstack_run_loop_set_timer_handler(&connection->retry_timer, avrcp_retry_timer_timeout_handler);
864     btstack_run_loop_set_timer_context(&connection->retry_timer, (void *)(uintptr_t)connection->avrcp_cid);
865 
866     // add some jitter/randomness to reconnect delay
867     uint32_t timeout = 100 + (btstack_run_loop_get_time_ms() & 0x7F);
868     btstack_run_loop_set_timer(&connection->retry_timer, timeout);
869 
870     btstack_run_loop_add_timer(&connection->retry_timer);
871 }
872 
873 static avrcp_frame_type_t avrcp_get_frame_type(uint8_t header){
874     return (avrcp_frame_type_t)((header & 0x02) >> 1);
875 }
876 
877 static void avrcp_packet_handler(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size){
878     UNUSED(channel);
879     UNUSED(size);
880     bd_addr_t event_addr;
881     uint16_t local_cid;
882     uint16_t l2cap_mtu;
883     uint8_t  status;
884     bool decline_connection;
885     bool outoing_active;
886     hci_con_handle_t con_handle;
887 
888     avrcp_connection_t * connection_controller;
889     avrcp_connection_t * connection_target;
890     bool can_send;
891 
892     switch (packet_type) {
893         case HCI_EVENT_PACKET:
894             switch (hci_event_packet_get_type(packet)) {
895 
896                 case L2CAP_EVENT_INCOMING_CONNECTION:
897                     btstack_assert(avrcp_controller_packet_handler != NULL);
898                     btstack_assert(avrcp_target_packet_handler != NULL);
899 
900                     l2cap_event_incoming_connection_get_address(packet, event_addr);
901                     local_cid = l2cap_event_incoming_connection_get_local_cid(packet);
902                     con_handle = l2cap_event_incoming_connection_get_handle(packet);
903 
904                     outoing_active = false;
905                     connection_target = avrcp_get_connection_for_bd_addr_for_role(AVRCP_TARGET, event_addr);
906                     if (connection_target != NULL){
907                         if (connection_target->state == AVCTP_CONNECTION_W4_L2CAP_CONNECTED){
908                             outoing_active = true;
909                             connection_target->incoming_declined = true;
910                         }
911                     }
912 
913                     connection_controller = avrcp_get_connection_for_bd_addr_for_role(AVRCP_CONTROLLER, event_addr);
914                     if (connection_controller != NULL){
915                         if (connection_controller->state == AVCTP_CONNECTION_W4_L2CAP_CONNECTED) {
916                             outoing_active = true;
917                             connection_controller->incoming_declined = true;
918                         }
919                     }
920 
921                     decline_connection = outoing_active;
922                     if (decline_connection == false){
923                         uint16_t avrcp_cid;
924                         if ((connection_controller == NULL) || (connection_target == NULL)){
925                             avrcp_cid = avrcp_get_next_cid(AVRCP_CONTROLLER);
926                         } else {
927                             avrcp_cid = connection_controller->avrcp_cid;
928                         }
929                         // create two connection objects (both)
930                         connection_target     = avrcp_handle_incoming_connection_for_role(AVRCP_TARGET, connection_target, event_addr, con_handle, local_cid, avrcp_cid);
931                         connection_controller = avrcp_handle_incoming_connection_for_role(AVRCP_CONTROLLER, connection_controller, event_addr, con_handle, local_cid, avrcp_cid);
932                         if ((connection_target == NULL) || (connection_controller == NULL)){
933                             decline_connection = true;
934                             if (connection_target) {
935                                 avrcp_finalize_connection(connection_target);
936                             }
937                             if (connection_controller) {
938                                 avrcp_finalize_connection(connection_controller);
939                             }
940                         }
941                     }
942                     if (decline_connection){
943                         l2cap_decline_connection(local_cid);
944                     } else {
945                         log_info("AVRCP: L2CAP_EVENT_INCOMING_CONNECTION local cid 0x%02x, state %d", local_cid, connection_controller->state);
946                         l2cap_accept_connection(local_cid);
947                     }
948                     break;
949 
950                 case L2CAP_EVENT_CHANNEL_OPENED:
951                     l2cap_event_channel_opened_get_address(packet, event_addr);
952                     status = l2cap_event_channel_opened_get_status(packet);
953                     local_cid = l2cap_event_channel_opened_get_local_cid(packet);
954                     l2cap_mtu = l2cap_event_channel_opened_get_remote_mtu(packet);
955                     con_handle = l2cap_event_channel_opened_get_handle(packet);
956 
957                     connection_controller = avrcp_get_connection_for_bd_addr_for_role(AVRCP_CONTROLLER, event_addr);
958                     connection_target = avrcp_get_connection_for_bd_addr_for_role(AVRCP_TARGET, event_addr);
959 
960                     // incoming: structs are already created in L2CAP_EVENT_INCOMING_CONNECTION
961                     // outgoing: structs are cteated in avrcp_connect()
962                     if ((connection_controller == NULL) || (connection_target == NULL)) {
963                         break;
964                     }
965 
966                     switch (status){
967                         case ERROR_CODE_SUCCESS:
968                             avrcp_handle_open_connection(connection_target, con_handle, local_cid, l2cap_mtu);
969                             avrcp_handle_open_connection(connection_controller, con_handle, local_cid, l2cap_mtu);
970                             avrcp_emit_connection_established(connection_controller->avrcp_cid, event_addr, con_handle, status);
971                             return;
972                         case L2CAP_CONNECTION_RESPONSE_RESULT_REFUSED_RESOURCES:
973                             if (connection_controller->incoming_declined == true){
974                                 log_info("Incoming connection was declined, and the outgoing failed");
975                                 connection_controller->state = AVCTP_CONNECTION_W2_L2CAP_RETRY;
976                                 connection_controller->incoming_declined = false;
977                                 connection_target->state = AVCTP_CONNECTION_W2_L2CAP_RETRY;
978                                 connection_target->incoming_declined = false;
979                                 avrcp_retry_timer_start(connection_controller);
980                                 return;
981                             }
982                             break;
983                         default:
984                             break;
985                     }
986                     log_info("L2CAP connection to connection %s failed. status code 0x%02x", bd_addr_to_str(event_addr), status);
987                     avrcp_emit_connection_established(connection_controller->avrcp_cid, event_addr, con_handle, status);
988                     avrcp_finalize_connection(connection_controller);
989                     avrcp_finalize_connection(connection_target);
990 
991                     break;
992 
993                 case L2CAP_EVENT_CHANNEL_CLOSED:
994                     local_cid = l2cap_event_channel_closed_get_local_cid(packet);
995 
996                     connection_controller = avrcp_get_connection_for_l2cap_signaling_cid_for_role(AVRCP_CONTROLLER, local_cid);
997                     connection_target = avrcp_get_connection_for_l2cap_signaling_cid_for_role(AVRCP_TARGET, local_cid);
998                     if ((connection_controller == NULL) || (connection_target == NULL)) {
999                         break;
1000                     }
1001                     avrcp_emit_connection_closed(connection_controller->avrcp_cid);
1002                     avrcp_finalize_connection(connection_controller);
1003                     avrcp_finalize_connection(connection_target);
1004                     break;
1005 
1006                 case L2CAP_EVENT_CAN_SEND_NOW:
1007                     local_cid = l2cap_event_can_send_now_get_local_cid(packet);
1008                     can_send = true;
1009 
1010                     connection_target = avrcp_get_connection_for_l2cap_signaling_cid_for_role(AVRCP_TARGET, local_cid);
1011                     if ((connection_target != NULL) && connection_target->wait_to_send){
1012                         connection_target->wait_to_send = false;
1013                         (*avrcp_target_packet_handler)(HCI_EVENT_PACKET, channel, packet, size);
1014                         can_send = false;
1015                     }
1016 
1017                     connection_controller = avrcp_get_connection_for_l2cap_signaling_cid_for_role(AVRCP_CONTROLLER, local_cid);
1018                     if ((connection_controller != NULL) && connection_controller->wait_to_send){
1019                         if (can_send){
1020                             connection_controller->wait_to_send = false;
1021                             (*avrcp_controller_packet_handler)(HCI_EVENT_PACKET, channel, packet, size);
1022                         } else {
1023                             l2cap_request_can_send_now_event(local_cid);
1024                         }
1025                     }
1026                     break;
1027 
1028                 default:
1029                     break;
1030             }
1031             break;
1032 
1033         case L2CAP_DATA_PACKET:
1034             switch (avrcp_get_frame_type(packet[0])){
1035                 case AVRCP_RESPONSE_FRAME:
1036                     (*avrcp_controller_packet_handler)(packet_type, channel, packet, size);
1037                     break;
1038                 case AVRCP_COMMAND_FRAME:
1039                 default:    // make compiler happy
1040                     (*avrcp_target_packet_handler)(packet_type, channel, packet, size);
1041                     break;
1042             }
1043             break;
1044 
1045         default:
1046             break;
1047     }
1048 }
1049 
1050 uint8_t avrcp_disconnect(uint16_t avrcp_cid){
1051     avrcp_connection_t * connection_controller = avrcp_get_connection_for_avrcp_cid_for_role(AVRCP_CONTROLLER, avrcp_cid);
1052     if (!connection_controller){
1053         return ERROR_CODE_UNKNOWN_CONNECTION_IDENTIFIER;
1054     }
1055     avrcp_connection_t * connection_target = avrcp_get_connection_for_avrcp_cid_for_role(AVRCP_TARGET, avrcp_cid);
1056     if (!connection_target){
1057         return ERROR_CODE_UNKNOWN_CONNECTION_IDENTIFIER;
1058     }
1059     if (connection_controller->browsing_connection){
1060         l2cap_disconnect(connection_controller->browsing_connection->l2cap_browsing_cid);
1061     }
1062     l2cap_disconnect(connection_controller->l2cap_signaling_cid);
1063     return ERROR_CODE_SUCCESS;
1064 }
1065 
1066 static void avrcp_handle_start_sdp_client_query(void * context){
1067     UNUSED(context);
1068 
1069     btstack_linked_list_iterator_t it;
1070     btstack_linked_list_iterator_init(&it, &avrcp_connections);
1071     while (btstack_linked_list_iterator_has_next(&it)){
1072         avrcp_connection_t * connection = (avrcp_connection_t *)btstack_linked_list_iterator_next(&it);
1073 
1074         if (connection->state != AVCTP_CONNECTION_W2_SEND_SDP_QUERY) continue;
1075         connection->state = AVCTP_CONNECTION_W4_SDP_QUERY_COMPLETE;
1076 
1077         // prevent triggering SDP query twice (for each role once)
1078         avrcp_connection_t * connection_with_opposite_role;
1079         switch (connection->role){
1080             case AVRCP_CONTROLLER:
1081                 connection_with_opposite_role = avrcp_get_connection_for_avrcp_cid_for_role(AVRCP_TARGET, connection->avrcp_cid);
1082                 break;
1083             case AVRCP_TARGET:
1084                 connection_with_opposite_role = avrcp_get_connection_for_avrcp_cid_for_role(AVRCP_CONTROLLER, connection->avrcp_cid);
1085                 break;
1086             default:
1087                 btstack_assert(false);
1088                 return;
1089         }
1090         connection_with_opposite_role->state = AVCTP_CONNECTION_W4_SDP_QUERY_COMPLETE;
1091 
1092         avrcp_sdp_query_context.avrcp_l2cap_psm = 0;
1093         avrcp_sdp_query_context.avrcp_version  = 0;
1094         avrcp_sdp_query_context.avrcp_cid = connection->avrcp_cid;
1095         sdp_client_query_uuid16(&avrcp_handle_sdp_client_query_result, (uint8_t *) connection->remote_addr, BLUETOOTH_PROTOCOL_AVCTP);
1096         return;
1097     }
1098 }
1099 
1100 uint8_t avrcp_connect(bd_addr_t remote_addr, uint16_t * avrcp_cid){
1101     btstack_assert(avrcp_controller_packet_handler != NULL);
1102     btstack_assert(avrcp_target_packet_handler != NULL);
1103 
1104     avrcp_connection_t * connection_controller = avrcp_get_connection_for_bd_addr_for_role(AVRCP_CONTROLLER, remote_addr);
1105     if (connection_controller){
1106         return ERROR_CODE_COMMAND_DISALLOWED;
1107     }
1108     avrcp_connection_t * connection_target = avrcp_get_connection_for_bd_addr_for_role(AVRCP_TARGET, remote_addr);
1109     if (connection_target){
1110         return ERROR_CODE_COMMAND_DISALLOWED;
1111     }
1112 
1113     uint16_t cid = avrcp_get_next_cid(AVRCP_CONTROLLER);
1114 
1115     connection_controller = avrcp_create_connection(AVRCP_CONTROLLER, remote_addr);
1116     if (!connection_controller) return BTSTACK_MEMORY_ALLOC_FAILED;
1117 
1118     connection_target = avrcp_create_connection(AVRCP_TARGET, remote_addr);
1119     if (!connection_target){
1120         avrcp_finalize_connection(connection_controller);
1121         return BTSTACK_MEMORY_ALLOC_FAILED;
1122     }
1123 
1124     if (avrcp_cid != NULL){
1125         *avrcp_cid = cid;
1126     }
1127 
1128     connection_controller->state = AVCTP_CONNECTION_W2_SEND_SDP_QUERY;
1129     connection_controller->avrcp_cid = cid;
1130 
1131     connection_target->state     = AVCTP_CONNECTION_W2_SEND_SDP_QUERY;
1132     connection_target->avrcp_cid = cid;
1133 
1134     avrcp_sdp_query_registration.callback = &avrcp_handle_start_sdp_client_query;
1135     // ignore ERROR_CODE_COMMAND_DISALLOWED because in that case, we already have requested an SDP callback
1136     (void) sdp_client_register_query_callback(&avrcp_sdp_query_registration);
1137     return ERROR_CODE_SUCCESS;
1138 }
1139 
1140 void avrcp_init(void){
1141     avrcp_connections = NULL;
1142     if (avrcp_l2cap_service_registered) return;
1143 
1144     int status = l2cap_register_service(&avrcp_packet_handler, BLUETOOTH_PSM_AVCTP, 0xffff, gap_get_security_level());
1145     if (status != ERROR_CODE_SUCCESS) return;
1146     avrcp_l2cap_service_registered = true;
1147 }
1148 
1149 void avrcp_deinit(void){
1150     avrcp_l2cap_service_registered = false;
1151 
1152     avrcp_cid_counter = 0;
1153     avrcp_connections = NULL;
1154 
1155     avrcp_callback = NULL;
1156     avrcp_controller_packet_handler = NULL;
1157     avrcp_target_packet_handler = NULL;
1158 
1159     (void) memset(&avrcp_sdp_query_registration, 0, sizeof(avrcp_sdp_query_registration));
1160     (void) memset(&avrcp_sdp_query_context, 0, sizeof(avrcp_sdp_query_context_t));
1161     (void) memset(avrcp_sdp_query_attribute_value, 0, sizeof(avrcp_sdp_query_attribute_value));
1162 }
1163 
1164 void avrcp_register_controller_packet_handler(btstack_packet_handler_t callback){
1165     avrcp_controller_packet_handler = callback;
1166 }
1167 
1168 void avrcp_register_target_packet_handler(btstack_packet_handler_t callback){
1169     avrcp_target_packet_handler = callback;
1170 }
1171 
1172 void avrcp_register_packet_handler(btstack_packet_handler_t callback){
1173     btstack_assert(callback != NULL);
1174     avrcp_callback = callback;
1175 }
1176 
1177 #ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
1178 #define FUZZ_CID 0x44
1179 #define FUZZ_CON_HANDLE 0x0001
1180 static bd_addr_t remote_addr = { 0x33, 0x33, 0x33, 0x33, 0x33, 0x33 };
1181 void avrcp_init_fuzz(void){
1182     // setup avrcp connections for cid
1183     avrcp_connection_t * connection_controller = avrcp_create_connection(AVRCP_CONTROLLER, remote_addr);
1184     avrcp_connection_t * connection_target     = avrcp_create_connection(AVRCP_TARGET, remote_addr);
1185     avrcp_handle_open_connection(connection_controller, FUZZ_CON_HANDLE, FUZZ_CID, 999);
1186     avrcp_handle_open_connection(connection_target, FUZZ_CON_HANDLE, FUZZ_CID, 999);
1187 }
1188 void avrcp_packet_handler_fuzz(uint8_t *packet, uint16_t size){
1189     avrcp_packet_handler(L2CAP_DATA_PACKET, FUZZ_CID, packet, size);
1190 }
1191 #endif