xref: /btstack/src/classic/rfcomm.c (revision f5054c0028135915921b5f31909b986101cbedd2)
1 /*
2  * Copyright (C) 2014 BlueKitchen GmbH
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  *
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  * 3. Neither the name of the copyright holders nor the names of
14  *    contributors may be used to endorse or promote products derived
15  *    from this software without specific prior written permission.
16  * 4. Any redistribution, use, or modification is done solely for
17  *    personal benefit and not for any commercial purpose or for
18  *    monetary gain.
19  *
20  * THIS SOFTWARE IS PROVIDED BY BLUEKITCHEN GMBH AND CONTRIBUTORS
21  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
22  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
23  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL MATTHIAS
24  * RINGWALD OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
25  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
26  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
27  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
28  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
29  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
30  * THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  *
33  * Please inquire about commercial licensing options at
34  * [email protected]
35  *
36  */
37 
38 /*
39  *  rfcomm.c
40  */
41 
42 #include <stdio.h>
43 #include <stdlib.h>
44 #include <string.h> // memcpy
45 #include <stdint.h>
46 
47 #include "hci_cmds.h"
48 #include "utils.h"
49 
50 #include "utils.h"
51 #include "btstack_memory.h"
52 #include "hci.h"
53 #include "hci_dump.h"
54 #include "debug.h"
55 #include "classic/rfcomm.h"
56 
57 // workaround for missing PRIxPTR on mspgcc (16/20-bit MCU)
58 #ifndef PRIxPTR
59 #if defined(__MSP430X__)  &&  defined(__MSP430X_LARGE__)
60 #define PRIxPTR "lx"
61 #else
62 #define PRIxPTR "x"
63 #endif
64 #endif
65 
66 #define RFCOMM_MULIPLEXER_TIMEOUT_MS 60000
67 
68 #define RFCOMM_CREDITS 10
69 
70 // FCS calc
71 #define BT_RFCOMM_CODE_WORD         0xE0 // pol = x8+x2+x1+1
72 #define BT_RFCOMM_CRC_CHECK_LEN     3
73 #define BT_RFCOMM_UIHCRC_CHECK_LEN  2
74 
75 #include "l2cap.h"
76 
77 // global rfcomm data
78 static uint16_t      rfcomm_client_cid_generator;  // used for client channel IDs
79 
80 // linked lists for all
81 static linked_list_t rfcomm_multiplexers = NULL;
82 static linked_list_t rfcomm_channels = NULL;
83 static linked_list_t rfcomm_services = NULL;
84 
85 static gap_security_level_t rfcomm_security_level;
86 
87 static void (*app_packet_handler)(uint8_t packet_type,
88                                   uint16_t channel, uint8_t *packet, uint16_t size);
89 
90 static void rfcomm_run(void);
91 static void rfcomm_hand_out_credits(void);
92 static void rfcomm_channel_state_machine(rfcomm_channel_t *channel, rfcomm_channel_event_t *event);
93 static void rfcomm_channel_state_machine_2(rfcomm_multiplexer_t * multiplexer, uint8_t dlci, rfcomm_channel_event_t *event);
94 static int rfcomm_channel_ready_for_open(rfcomm_channel_t *channel);
95 static void rfcomm_multiplexer_state_machine(rfcomm_multiplexer_t * multiplexer, RFCOMM_MULTIPLEXER_EVENT event);
96 
97 
98 // MARK: RFCOMM CLIENT EVENTS
99 
100 // data: event (8), len(8), address(48), channel (8), rfcomm_cid (16)
101 static void rfcomm_emit_connection_request(rfcomm_channel_t *channel) {
102     log_info("RFCOMM_EVENT_INCOMING_CONNECTION addr %s channel #%u cid 0x%02x",
103              bd_addr_to_str(channel->multiplexer->remote_addr), channel->dlci>>1, channel->rfcomm_cid);
104     uint8_t event[11];
105     event[0] = RFCOMM_EVENT_INCOMING_CONNECTION;
106     event[1] = sizeof(event) - 2;
107     bt_flip_addr(&event[2], channel->multiplexer->remote_addr);
108     event[8] = channel->dlci >> 1;
109     bt_store_16(event, 9, channel->rfcomm_cid);
110     hci_dump_packet(HCI_EVENT_PACKET, 0, event, sizeof(event));
111 	(*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) event, sizeof(event));
112 }
113 
114 // API Change: BTstack-0.3.50x uses
115 // data: event(8), len(8), status (8), address (48), server channel(8), rfcomm_cid(16), max frame size(16)
116 // next Cydia release will use SVN version of this
117 // data: event(8), len(8), status (8), address (48), handle (16), server channel(8), rfcomm_cid(16), max frame size(16)
118 static void rfcomm_emit_channel_opened(rfcomm_channel_t *channel, uint8_t status) {
119     log_info("RFCOMM_EVENT_OPEN_CHANNEL_COMPLETE status 0x%x addr %s handle 0x%x channel #%u cid 0x%02x mtu %u",
120              status, bd_addr_to_str(channel->multiplexer->remote_addr), channel->multiplexer->con_handle,
121              channel->dlci>>1, channel->rfcomm_cid, channel->max_frame_size);
122     uint8_t event[16];
123     uint8_t pos = 0;
124     event[pos++] = RFCOMM_EVENT_OPEN_CHANNEL_COMPLETE;  // 0
125     event[pos++] = sizeof(event) - 2;                   // 1
126     event[pos++] = status;                              // 2
127     bt_flip_addr(&event[pos], channel->multiplexer->remote_addr); pos += 6; // 3
128     bt_store_16(event,  pos, channel->multiplexer->con_handle);   pos += 2; // 9
129 	event[pos++] = channel->dlci >> 1;                                      // 11
130 	bt_store_16(event, pos, channel->rfcomm_cid); pos += 2;                 // 12 - channel ID
131 	bt_store_16(event, pos, channel->max_frame_size); pos += 2;   // max frame size
132     hci_dump_packet(HCI_EVENT_PACKET, 0, event, sizeof(event));
133 	(*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) event, pos);
134 }
135 
136 // data: event(8), len(8), rfcomm_cid(16)
137 static void rfcomm_emit_channel_closed(rfcomm_channel_t * channel) {
138     log_info("RFCOMM_EVENT_CHANNEL_CLOSED cid 0x%02x", channel->rfcomm_cid);
139     uint8_t event[4];
140     event[0] = RFCOMM_EVENT_CHANNEL_CLOSED;
141     event[1] = sizeof(event) - 2;
142     bt_store_16(event, 2, channel->rfcomm_cid);
143     hci_dump_packet(HCI_EVENT_PACKET, 0, event, sizeof(event));
144 	(*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) event, sizeof(event));
145 }
146 
147 static void rfcomm_emit_credits(rfcomm_channel_t * channel, uint8_t credits) {
148     log_info("RFCOMM_EVENT_CREDITS cid 0x%02x credits %u", channel->rfcomm_cid, credits);
149     uint8_t event[5];
150     event[0] = RFCOMM_EVENT_CREDITS;
151     event[1] = sizeof(event) - 2;
152     bt_store_16(event, 2, channel->rfcomm_cid);
153     event[4] = credits;
154     hci_dump_packet(HCI_EVENT_PACKET, 0, event, sizeof(event));
155 	(*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) event, sizeof(event));
156 }
157 
158 static void rfcomm_emit_remote_line_status(rfcomm_channel_t *channel, uint8_t line_status){
159     log_info("RFCOMM_EVENT_REMOTE_LINE_STATUS cid 0x%02x c, line status 0x%x", channel->rfcomm_cid, line_status);
160     uint8_t event[5];
161     event[0] = RFCOMM_EVENT_REMOTE_LINE_STATUS;
162     event[1] = sizeof(event) - 2;
163     bt_store_16(event, 2, channel->rfcomm_cid);
164     event[4] = line_status;
165     hci_dump_packet( HCI_EVENT_PACKET, 0, event, sizeof(event));
166     (*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) event, sizeof(event));
167 }
168 
169 static void rfcomm_emit_port_configuration(rfcomm_channel_t *channel){
170     // notify client about new settings
171     uint8_t event[2+sizeof(rfcomm_rpn_data_t)];
172     event[0] = RFCOMM_EVENT_PORT_CONFIGURATION;
173     event[1] = sizeof(rfcomm_rpn_data_t);
174     memcpy(&event[2], (uint8_t*) &channel->rpn_data, sizeof(rfcomm_rpn_data_t));
175     hci_dump_packet( HCI_EVENT_PACKET, 0, event, sizeof(event));
176     (*app_packet_handler)(HCI_EVENT_PACKET, channel->rfcomm_cid, (uint8_t*)event, sizeof(event));
177 }
178 
179 // MARK RFCOMM RPN DATA HELPER
180 static void rfcomm_rpn_data_set_defaults(rfcomm_rpn_data_t * rpn_data){
181         rpn_data->baud_rate = RPN_BAUD_9600;  /* 9600 bps */
182         rpn_data->flags = 0x03;               /* 8-n-1 */
183         rpn_data->flow_control = 0;           /* no flow control */
184         rpn_data->xon  = 0xd1;                /* XON */
185         rpn_data->xoff = 0xd3;                /* XOFF */
186         rpn_data->parameter_mask_0 = 0x7f;    /* parameter mask, all values set */
187         rpn_data->parameter_mask_1 = 0x3f;    /* parameter mask, all values set */
188 }
189 
190 static void rfcomm_rpn_data_update(rfcomm_rpn_data_t * dest, rfcomm_rpn_data_t * src){
191     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_BAUD){
192         dest->baud_rate = src->baud_rate;
193     }
194     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_DATA_BITS){
195         dest->flags = (dest->flags & 0xfc) | (src->flags & 0x03);
196     }
197     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_STOP_BITS){
198         dest->flags = (dest->flags & 0xfb) | (src->flags & 0x04);
199     }
200     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_PARITY){
201         dest->flags = (dest->flags & 0xf7) | (src->flags & 0x08);
202     }
203     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_PARITY_TYPE){
204         dest->flags = (dest->flags & 0xfc) | (src->flags & 0x30);
205     }
206     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_XON_CHAR){
207         dest->xon = src->xon;
208     }
209     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_XOFF_CHAR){
210         dest->xoff = src->xoff;
211     }
212     int i;
213     for (i=0; i < 6 ; i++){
214         uint8_t mask = 1 << i;
215         if (src->parameter_mask_1 & mask){
216             dest->flags = (dest->flags & ~mask) | (src->flags & mask);
217         }
218     }
219     // always copy parameter mask, too. informative for client, needed for response
220     dest->parameter_mask_0 = src->parameter_mask_0;
221     dest->parameter_mask_1 = src->parameter_mask_1;
222 }
223 // MARK: RFCOMM MULTIPLEXER HELPER
224 
225 static uint16_t rfcomm_max_frame_size_for_l2cap_mtu(uint16_t l2cap_mtu){
226     // Assume RFCOMM header without credits and 2 byte (14 bit) length field
227     uint16_t max_frame_size = l2cap_mtu - 5;
228     log_info("rfcomm_max_frame_size_for_l2cap_mtu:  %u -> %u", l2cap_mtu, max_frame_size);
229     return max_frame_size;
230 }
231 
232 static void rfcomm_multiplexer_initialize(rfcomm_multiplexer_t *multiplexer){
233 
234     memset(multiplexer, 0, sizeof(rfcomm_multiplexer_t));
235 
236     multiplexer->state = RFCOMM_MULTIPLEXER_CLOSED;
237     multiplexer->fcon = 1;
238     multiplexer->send_dm_for_dlci = 0;
239     multiplexer->max_frame_size = rfcomm_max_frame_size_for_l2cap_mtu(l2cap_max_mtu());
240     multiplexer->test_data_len = 0;
241     multiplexer->nsc_command = 0;
242 }
243 
244 static rfcomm_multiplexer_t * rfcomm_multiplexer_create_for_addr(bd_addr_t addr){
245 
246     // alloc structure
247     rfcomm_multiplexer_t * multiplexer = btstack_memory_rfcomm_multiplexer_get();
248     if (!multiplexer) return NULL;
249 
250     // fill in
251     rfcomm_multiplexer_initialize(multiplexer);
252     BD_ADDR_COPY(&multiplexer->remote_addr, addr);
253 
254     // add to services list
255     linked_list_add(&rfcomm_multiplexers, (linked_item_t *) multiplexer);
256 
257     return multiplexer;
258 }
259 
260 static rfcomm_multiplexer_t * rfcomm_multiplexer_for_addr(bd_addr_t addr){
261     linked_item_t *it;
262     for (it = (linked_item_t *) rfcomm_multiplexers; it ; it = it->next){
263         rfcomm_multiplexer_t * multiplexer = ((rfcomm_multiplexer_t *) it);
264         if (BD_ADDR_CMP(addr, multiplexer->remote_addr) == 0) {
265             return multiplexer;
266         };
267     }
268     return NULL;
269 }
270 
271 static rfcomm_multiplexer_t * rfcomm_multiplexer_for_l2cap_cid(uint16_t l2cap_cid) {
272     linked_item_t *it;
273     for (it = (linked_item_t *) rfcomm_multiplexers; it ; it = it->next){
274         rfcomm_multiplexer_t * multiplexer = ((rfcomm_multiplexer_t *) it);
275         if (multiplexer->l2cap_cid == l2cap_cid) {
276             return multiplexer;
277         };
278     }
279     return NULL;
280 }
281 
282 static int rfcomm_multiplexer_has_channels(rfcomm_multiplexer_t * multiplexer){
283     linked_item_t *it;
284     for (it = (linked_item_t *) rfcomm_channels; it ; it = it->next){
285         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
286         if (channel->multiplexer == multiplexer) {
287             return 1;
288         }
289     }
290     return 0;
291 }
292 
293 // MARK: RFCOMM CHANNEL HELPER
294 
295 static void rfcomm_dump_channels(void){
296 #ifndef EMBEDDED
297     linked_item_t * it;
298     int channels = 0;
299     for (it = (linked_item_t *) rfcomm_channels; it ; it = it->next){
300         rfcomm_channel_t * channel = (rfcomm_channel_t *) it;
301         log_info("Channel #%u: addr %p, state %u", channels, channel, channel->state);
302         channels++;
303     }
304 #endif
305 }
306 
307 static void rfcomm_channel_initialize(rfcomm_channel_t *channel, rfcomm_multiplexer_t *multiplexer,
308                                rfcomm_service_t *service, uint8_t server_channel){
309 
310     // don't use 0 as channel id
311     if (rfcomm_client_cid_generator == 0) ++rfcomm_client_cid_generator;
312 
313     // setup channel
314     memset(channel, 0, sizeof(rfcomm_channel_t));
315 
316     channel->state             = RFCOMM_CHANNEL_CLOSED;
317     channel->state_var         = RFCOMM_CHANNEL_STATE_VAR_NONE;
318 
319     channel->multiplexer      = multiplexer;
320     channel->service          = service;
321     channel->rfcomm_cid       = rfcomm_client_cid_generator++;
322     channel->max_frame_size   = multiplexer->max_frame_size;
323 
324     channel->credits_incoming = 0;
325     channel->credits_outgoing = 0;
326     channel->packets_granted  = 0;
327 
328     // set defaults for port configuration (even for services)
329     rfcomm_rpn_data_set_defaults(&channel->rpn_data);
330 
331     // incoming flow control not active
332     channel->new_credits_incoming  =RFCOMM_CREDITS;
333     channel->incoming_flow_control = 0;
334 
335     channel->rls_line_status = RFCOMM_RLS_STATUS_INVALID;
336 
337 	if (service) {
338 		// incoming connection
339 		channel->outgoing = 0;
340 		channel->dlci = (server_channel << 1) |  multiplexer->outgoing;
341         if (channel->max_frame_size > service->max_frame_size) {
342             channel->max_frame_size = service->max_frame_size;
343         }
344         channel->incoming_flow_control = service->incoming_flow_control;
345         channel->new_credits_incoming  = service->incoming_initial_credits;
346 	} else {
347 		// outgoing connection
348 		channel->outgoing = 1;
349 		channel->dlci = (server_channel << 1) | (multiplexer->outgoing ^ 1);
350 
351 	}
352 }
353 
354 // service == NULL -> outgoing channel
355 static rfcomm_channel_t * rfcomm_channel_create(rfcomm_multiplexer_t * multiplexer,
356                                                 rfcomm_service_t * service, uint8_t server_channel){
357 
358     log_info("rfcomm_channel_create for service %p, channel %u --- list of channels:", service, server_channel);
359     rfcomm_dump_channels();
360 
361     // alloc structure
362     rfcomm_channel_t * channel = btstack_memory_rfcomm_channel_get();
363     if (!channel) return NULL;
364 
365     // fill in
366     rfcomm_channel_initialize(channel, multiplexer, service, server_channel);
367 
368     // add to services list
369     linked_list_add(&rfcomm_channels, (linked_item_t *) channel);
370 
371     return channel;
372 }
373 
374 static rfcomm_channel_t * rfcomm_channel_for_rfcomm_cid(uint16_t rfcomm_cid){
375     linked_item_t *it;
376     for (it = (linked_item_t *) rfcomm_channels; it ; it = it->next){
377         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
378         if (channel->rfcomm_cid == rfcomm_cid) {
379             return channel;
380         };
381     }
382     return NULL;
383 }
384 
385 static rfcomm_channel_t * rfcomm_channel_for_multiplexer_and_dlci(rfcomm_multiplexer_t * multiplexer, uint8_t dlci){
386     linked_item_t *it;
387     for (it = (linked_item_t *) rfcomm_channels; it ; it = it->next){
388         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
389         if (channel->dlci == dlci && channel->multiplexer == multiplexer) {
390             return channel;
391         };
392     }
393     return NULL;
394 }
395 
396 static rfcomm_service_t * rfcomm_service_for_channel(uint8_t server_channel){
397     linked_item_t *it;
398     for (it = (linked_item_t *) rfcomm_services; it ; it = it->next){
399         rfcomm_service_t * service = ((rfcomm_service_t *) it);
400         if ( service->server_channel == server_channel){
401             return service;
402         };
403     }
404     return NULL;
405 }
406 
407 // MARK: RFCOMM SEND
408 
409 /**
410  * @param credits - only used for RFCOMM flow control in UIH wiht P/F = 1
411  */
412 static int rfcomm_send_packet_for_multiplexer(rfcomm_multiplexer_t *multiplexer, uint8_t address, uint8_t control, uint8_t credits, uint8_t *data, uint16_t len){
413 
414     if (!l2cap_can_send_packet_now(multiplexer->l2cap_cid)) return BTSTACK_ACL_BUFFERS_FULL;
415 
416     l2cap_reserve_packet_buffer();
417     uint8_t * rfcomm_out_buffer = l2cap_get_outgoing_buffer();
418 
419 	uint16_t pos = 0;
420 	uint8_t crc_fields = 3;
421 
422 	rfcomm_out_buffer[pos++] = address;
423 	rfcomm_out_buffer[pos++] = control;
424 
425 	// length field can be 1 or 2 octets
426 	if (len < 128){
427 		rfcomm_out_buffer[pos++] = (len << 1)| 1;     // bits 0-6
428 	} else {
429 		rfcomm_out_buffer[pos++] = (len & 0x7f) << 1; // bits 0-6
430 		rfcomm_out_buffer[pos++] = len >> 7;          // bits 7-14
431 		crc_fields++;
432 	}
433 
434 	// add credits for UIH frames when PF bit is set
435 	if (control == BT_RFCOMM_UIH_PF){
436 		rfcomm_out_buffer[pos++] = credits;
437 	}
438 
439 	// copy actual data
440 	if (len) {
441 		memcpy(&rfcomm_out_buffer[pos], data, len);
442 		pos += len;
443 	}
444 
445 	// UIH frames only calc FCS over address + control (5.1.1)
446 	if ((control & 0xef) == BT_RFCOMM_UIH){
447 		crc_fields = 2;
448 	}
449 	rfcomm_out_buffer[pos++] =  crc8_calc(rfcomm_out_buffer, crc_fields); // calc fcs
450 
451     int err = l2cap_send_prepared(multiplexer->l2cap_cid, pos);
452 
453     return err;
454 }
455 
456 // simplified version of rfcomm_send_packet_for_multiplexer for prepared rfcomm packet (UIH, 2 byte len, no credits)
457 static int rfcomm_send_uih_prepared(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint16_t len){
458 
459     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1) | (dlci << 2);
460     uint8_t control = BT_RFCOMM_UIH;
461 
462     uint8_t * rfcomm_out_buffer = l2cap_get_outgoing_buffer();
463 
464     uint16_t pos = 0;
465     rfcomm_out_buffer[pos++] = address;
466     rfcomm_out_buffer[pos++] = control;
467     rfcomm_out_buffer[pos++] = (len & 0x7f) << 1; // bits 0-6
468     rfcomm_out_buffer[pos++] = len >> 7;          // bits 7-14
469 
470     // actual data is already in place
471     pos += len;
472 
473     // UIH frames only calc FCS over address + control (5.1.1)
474     rfcomm_out_buffer[pos++] =  crc8_calc(rfcomm_out_buffer, 2); // calc fcs
475 
476     int err = l2cap_send_prepared(multiplexer->l2cap_cid, pos);
477 
478     return err;
479 }
480 
481 // C/R Flag in Address
482 // - terms: initiator = station that creates multiplexer with SABM
483 // - terms: responder = station that responds to multiplexer setup with UA
484 // "For SABM, UA, DM and DISC frames C/R bit is set according to Table 1 in GSM 07.10, section 5.2.1.2"
485 //    - command initiator = 1 /response responder = 1
486 //    - command responder = 0 /response initiator = 0
487 // "For UIH frames, the C/R bit is always set according to section 5.4.3.1 in GSM 07.10.
488 //  This applies independently of what is contained wthin the UIH frames, either data or control messages."
489 //    - c/r = 1 for frames by initiating station, 0 = for frames by responding station
490 
491 // C/R Flag in Message
492 // "In the message level, the C/R bit in the command type field is set as stated in section 5.4.6.2 in GSM 07.10."
493 //   - If the C/R bit is set to 1 the message is a command
494 //   - if it is set to 0 the message is a response.
495 
496 // temp/old messge construction
497 
498 // new object oriented version
499 static int rfcomm_send_sabm(rfcomm_multiplexer_t *multiplexer, uint8_t dlci){
500 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1) | (dlci << 2);   // command
501     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_SABM, 0, NULL, 0);
502 }
503 
504 static int rfcomm_send_disc(rfcomm_multiplexer_t *multiplexer, uint8_t dlci){
505 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1) | (dlci << 2);  // command
506     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_DISC, 0, NULL, 0);
507 }
508 
509 static int rfcomm_send_ua(rfcomm_multiplexer_t *multiplexer, uint8_t dlci){
510 	uint8_t address = (1 << 0) | ((multiplexer->outgoing ^ 1) << 1) | (dlci << 2); // response
511     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UA, 0, NULL, 0);
512 }
513 
514 static int rfcomm_send_dm_pf(rfcomm_multiplexer_t *multiplexer, uint8_t dlci){
515 	uint8_t address = (1 << 0) | ((multiplexer->outgoing ^ 1) << 1) | (dlci << 2); // response
516     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_DM_PF, 0, NULL, 0);
517 }
518 
519 static int rfcomm_send_uih_fc_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t fcon) {
520     uint8_t address = (1 << 0) | (multiplexer->outgoing<< 1);
521     uint8_t payload[2];
522     uint8_t pos = 0;
523     payload[pos++] = fcon ? BT_RFCOMM_FCON_RSP : BT_RFCOMM_FCOFF_RSP;
524     payload[pos++] = (0 << 1) | 1;  // len
525     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
526 }
527 
528 // static int rfcomm_send_uih_test_cmd(rfcomm_multiplexer_t *multiplexer, uint8_t * data, uint16_t len) {
529 //     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
530 //     uint8_t payload[2+len];
531 //     uint8_t pos = 0;
532 //     payload[pos++] = BT_RFCOMM_TEST_CMD;
533 //     payload[pos++] = (len + 1) << 1 | 1;  // len
534 //     memcpy(&payload[pos], data, len);
535 //     pos += len;
536 //     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
537 // }
538 
539 static int rfcomm_send_uih_test_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t * data, uint16_t len) {
540     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
541     uint8_t payload[2+RFCOMM_TEST_DATA_MAX_LEN];
542     uint8_t pos = 0;
543     payload[pos++] = BT_RFCOMM_TEST_RSP;
544     if (len > RFCOMM_TEST_DATA_MAX_LEN) {
545         len = RFCOMM_TEST_DATA_MAX_LEN;
546     }
547     payload[pos++] = (len << 1) | 1;  // len
548     memcpy(&payload[pos], data, len);
549     pos += len;
550     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
551 }
552 
553 static int rfcomm_send_uih_msc_cmd(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint8_t signals) {
554 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
555 	uint8_t payload[4];
556 	uint8_t pos = 0;
557 	payload[pos++] = BT_RFCOMM_MSC_CMD;
558 	payload[pos++] = (2 << 1) | 1;  // len
559 	payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
560 	payload[pos++] = signals;
561 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
562 }
563 
564 static int rfcomm_send_uih_msc_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint8_t signals) {
565 	uint8_t address = (1 << 0) | (multiplexer->outgoing<< 1);
566 	uint8_t payload[4];
567 	uint8_t pos = 0;
568 	payload[pos++] = BT_RFCOMM_MSC_RSP;
569 	payload[pos++] = (2 << 1) | 1;  // len
570 	payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
571 	payload[pos++] = signals;
572 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
573 }
574 
575 static int rfcomm_send_uih_nsc_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t command) {
576     uint8_t address = (1 << 0) | (multiplexer->outgoing<< 1);
577     uint8_t payload[3];
578     uint8_t pos = 0;
579     payload[pos++] = BT_RFCOMM_NSC_RSP;
580     payload[pos++] = (1 << 1) | 1;  // len
581     payload[pos++] = command;
582     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
583 }
584 
585 static int rfcomm_send_uih_pn_command(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint16_t max_frame_size){
586 	uint8_t payload[10];
587 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
588 	uint8_t pos = 0;
589 	payload[pos++] = BT_RFCOMM_PN_CMD;
590 	payload[pos++] = (8 << 1) | 1;  // len
591 	payload[pos++] = dlci;
592 	payload[pos++] = 0xf0; // pre-defined for Bluetooth, see 5.5.3 of TS 07.10 Adaption for RFCOMM
593 	payload[pos++] = 0; // priority
594 	payload[pos++] = 0; // max 60 seconds ack
595 	payload[pos++] = max_frame_size & 0xff; // max framesize low
596 	payload[pos++] = max_frame_size >> 8;   // max framesize high
597 	payload[pos++] = 0x00; // number of retransmissions
598 	payload[pos++] = 0x00; // (unused error recovery window) initial number of credits
599 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
600 }
601 
602 // "The response may not change the DLCI, the priority, the convergence layer, or the timer value." RFCOMM-tutorial.pdf
603 static int rfcomm_send_uih_pn_response(rfcomm_multiplexer_t *multiplexer, uint8_t dlci,
604                                        uint8_t priority, uint16_t max_frame_size){
605 	uint8_t payload[10];
606 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
607 	uint8_t pos = 0;
608 	payload[pos++] = BT_RFCOMM_PN_RSP;
609 	payload[pos++] = (8 << 1) | 1;  // len
610 	payload[pos++] = dlci;
611 	payload[pos++] = 0xe0; // pre defined for Bluetooth, see 5.5.3 of TS 07.10 Adaption for RFCOMM
612 	payload[pos++] = priority; // priority
613 	payload[pos++] = 0; // max 60 seconds ack
614 	payload[pos++] = max_frame_size & 0xff; // max framesize low
615 	payload[pos++] = max_frame_size >> 8;   // max framesize high
616 	payload[pos++] = 0x00; // number of retransmissions
617 	payload[pos++] = 0x00; // (unused error recovery window) initial number of credits
618 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
619 }
620 
621 static int rfcomm_send_uih_rls_cmd(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint8_t line_status) {
622     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
623     uint8_t payload[4];
624     uint8_t pos = 0;
625     payload[pos++] = BT_RFCOMM_RLS_CMD;
626     payload[pos++] = (2 << 1) | 1;  // len
627     payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
628     payload[pos++] = line_status;
629     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
630 }
631 
632 static int rfcomm_send_uih_rls_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint8_t line_status) {
633     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
634     uint8_t payload[4];
635     uint8_t pos = 0;
636     payload[pos++] = BT_RFCOMM_RLS_RSP;
637     payload[pos++] = (2 << 1) | 1;  // len
638     payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
639     payload[pos++] = line_status;
640     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
641 }
642 
643 static int rfcomm_send_uih_rpn_cmd(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, rfcomm_rpn_data_t *rpn_data) {
644     uint8_t payload[10];
645     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
646     uint8_t pos = 0;
647     payload[pos++] = BT_RFCOMM_RPN_CMD;
648     payload[pos++] = (8 << 1) | 1;  // len
649     payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
650     payload[pos++] = rpn_data->baud_rate;
651     payload[pos++] = rpn_data->flags;
652     payload[pos++] = rpn_data->flow_control;
653     payload[pos++] = rpn_data->xon;
654     payload[pos++] = rpn_data->xoff;
655     payload[pos++] = rpn_data->parameter_mask_0;
656     payload[pos++] = rpn_data->parameter_mask_1;
657     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
658 }
659 
660 static int rfcomm_send_uih_rpn_req(rfcomm_multiplexer_t *multiplexer, uint8_t dlci) {
661     uint8_t payload[3];
662     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
663     uint8_t pos = 0;
664     payload[pos++] = BT_RFCOMM_RPN_CMD;
665     payload[pos++] = (1 << 1) | 1;  // len
666     payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
667     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
668 }
669 
670 static int rfcomm_send_uih_rpn_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, rfcomm_rpn_data_t *rpn_data) {
671 	uint8_t payload[10];
672 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
673 	uint8_t pos = 0;
674 	payload[pos++] = BT_RFCOMM_RPN_RSP;
675 	payload[pos++] = (8 << 1) | 1;  // len
676 	payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
677 	payload[pos++] = rpn_data->baud_rate;
678 	payload[pos++] = rpn_data->flags;
679 	payload[pos++] = rpn_data->flow_control;
680 	payload[pos++] = rpn_data->xon;
681 	payload[pos++] = rpn_data->xoff;
682 	payload[pos++] = rpn_data->parameter_mask_0;
683 	payload[pos++] = rpn_data->parameter_mask_1;
684 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
685 }
686 
687 static void rfcomm_send_uih_credits(rfcomm_multiplexer_t *multiplexer, uint8_t dlci,  uint8_t credits){
688     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1) |  (dlci << 2);
689     rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH_PF, credits, NULL, 0);
690 }
691 
692 // MARK: RFCOMM MULTIPLEXER
693 static void rfcomm_multiplexer_stop_timer(rfcomm_multiplexer_t * multiplexer){
694     if (multiplexer->timer_active) {
695         run_loop_remove_timer(&multiplexer->timer);
696         multiplexer->timer_active = 0;
697     }
698 }
699 static void rfcomm_multiplexer_free(rfcomm_multiplexer_t * multiplexer){
700     linked_list_remove( &rfcomm_multiplexers, (linked_item_t *) multiplexer);
701     btstack_memory_rfcomm_multiplexer_free(multiplexer);
702 }
703 
704 static void rfcomm_multiplexer_finalize(rfcomm_multiplexer_t * multiplexer){
705     // remove (potential) timer
706     rfcomm_multiplexer_stop_timer(multiplexer);
707 
708     // close and remove all channels
709     linked_item_t *it = (linked_item_t *) &rfcomm_channels;
710     while (it->next){
711         rfcomm_channel_t * channel = (rfcomm_channel_t *) it->next;
712         if (channel->multiplexer == multiplexer) {
713             // emit appropriate events
714             if (channel->state == RFCOMM_CHANNEL_OPEN) {
715                 rfcomm_emit_channel_closed(channel);
716             } else {
717                 rfcomm_emit_channel_opened(channel, RFCOMM_MULTIPLEXER_STOPPED);
718             }
719             // remove from list
720             it->next = it->next->next;
721             // free channel struct
722             btstack_memory_rfcomm_channel_free(channel);
723         } else {
724             it = it->next;
725         }
726     }
727 
728     // remove mutliplexer
729     rfcomm_multiplexer_free(multiplexer);
730 }
731 
732 static void rfcomm_multiplexer_timer_handler(timer_source_t *timer){
733     rfcomm_multiplexer_t * multiplexer = (rfcomm_multiplexer_t *) linked_item_get_user( (linked_item_t *) timer);
734     if (rfcomm_multiplexer_has_channels(multiplexer)) return;
735 
736     log_info("rfcomm_multiplexer_timer_handler timeout: shutting down multiplexer! (no channels)");
737     uint16_t l2cap_cid = multiplexer->l2cap_cid;
738     rfcomm_multiplexer_finalize(multiplexer);
739     l2cap_disconnect_internal(l2cap_cid, 0x13);
740 }
741 
742 static void rfcomm_multiplexer_prepare_idle_timer(rfcomm_multiplexer_t * multiplexer){
743     if (multiplexer->timer_active) {
744         run_loop_remove_timer(&multiplexer->timer);
745         multiplexer->timer_active = 0;
746     }
747     if (rfcomm_multiplexer_has_channels(multiplexer)) return;
748 
749     // start idle timer for multiplexer timeout check as there are no rfcomm channels yet
750     run_loop_set_timer(&multiplexer->timer, RFCOMM_MULIPLEXER_TIMEOUT_MS);
751     multiplexer->timer.process = rfcomm_multiplexer_timer_handler;
752     linked_item_set_user((linked_item_t*) &multiplexer->timer, multiplexer);
753     run_loop_add_timer(&multiplexer->timer);
754     multiplexer->timer_active = 1;
755 }
756 
757 static void rfcomm_multiplexer_opened(rfcomm_multiplexer_t *multiplexer){
758     log_info("Multiplexer up and running");
759     multiplexer->state = RFCOMM_MULTIPLEXER_OPEN;
760 
761     rfcomm_channel_event_t event = { CH_EVT_MULTIPLEXER_READY };
762 
763     // transition of channels that wait for multiplexer
764     linked_item_t *it;
765     for (it = (linked_item_t *) rfcomm_channels; it ; it = it->next){
766         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
767         if (channel->multiplexer != multiplexer) continue;
768         rfcomm_channel_state_machine(channel, &event);
769     }
770 
771     rfcomm_run();
772     rfcomm_multiplexer_prepare_idle_timer(multiplexer);
773 }
774 
775 
776 /**
777  * @return handled packet
778  */
779 static int rfcomm_multiplexer_hci_event_handler(uint8_t *packet, uint16_t size){
780     bd_addr_t event_addr;
781     uint16_t  psm;
782     uint16_t l2cap_cid;
783     hci_con_handle_t con_handle;
784     rfcomm_multiplexer_t *multiplexer = NULL;
785     uint8_t status;
786 
787     switch (packet[0]) {
788 
789         // accept incoming PSM_RFCOMM connection if no multiplexer exists yet
790         case L2CAP_EVENT_INCOMING_CONNECTION:
791             // data: event(8), len(8), address(48), handle (16),  psm (16), source cid(16) dest cid(16)
792             bt_flip_addr(event_addr, &packet[2]);
793             con_handle = READ_BT_16(packet,  8);
794             psm        = READ_BT_16(packet, 10);
795             l2cap_cid  = READ_BT_16(packet, 12);
796 
797             if (psm != PSM_RFCOMM) break;
798 
799             multiplexer = rfcomm_multiplexer_for_addr(event_addr);
800 
801             if (multiplexer) {
802                 log_info("INCOMING_CONNECTION (l2cap_cid 0x%02x) for PSM_RFCOMM => decline - multiplexer already exists", l2cap_cid);
803                 l2cap_decline_connection_internal(l2cap_cid,  0x04);    // no resources available
804                 return 1;
805             }
806 
807             // create and inititialize new multiplexer instance (incoming)
808             multiplexer = rfcomm_multiplexer_create_for_addr(event_addr);
809             if (!multiplexer){
810                 log_info("INCOMING_CONNECTION (l2cap_cid 0x%02x) for PSM_RFCOMM => decline - no memory left", l2cap_cid);
811                 l2cap_decline_connection_internal(l2cap_cid,  0x04);    // no resources available
812                 return 1;
813             }
814 
815             multiplexer->con_handle = con_handle;
816             multiplexer->l2cap_cid = l2cap_cid;
817             multiplexer->state = RFCOMM_MULTIPLEXER_W4_SABM_0;
818 
819             log_info("L2CAP_EVENT_INCOMING_CONNECTION (l2cap_cid 0x%02x) for PSM_RFCOMM => accept", l2cap_cid);
820             l2cap_accept_connection_internal(l2cap_cid);
821             return 1;
822 
823         // l2cap connection opened -> store l2cap_cid, remote_addr
824         case L2CAP_EVENT_CHANNEL_OPENED:
825 
826             if (READ_BT_16(packet, 11) != PSM_RFCOMM) break;
827 
828             status = packet[2];
829             log_info("L2CAP_EVENT_CHANNEL_OPENED for PSM_RFCOMM, status %u", status);
830 
831             // get multiplexer for remote addr
832             con_handle = READ_BT_16(packet, 9);
833             l2cap_cid = READ_BT_16(packet, 13);
834             bt_flip_addr(event_addr, &packet[3]);
835             multiplexer = rfcomm_multiplexer_for_addr(event_addr);
836             if (!multiplexer) {
837                 log_error("L2CAP_EVENT_CHANNEL_OPENED but no multiplexer prepared");
838                 return 1;
839             }
840 
841             // on l2cap open error discard everything
842             if (status){
843 
844                 // remove (potential) timer
845                 rfcomm_multiplexer_stop_timer(multiplexer);
846 
847                 // emit rfcomm_channel_opened with status and free channel
848                 linked_item_t * it = (linked_item_t *) &rfcomm_channels;
849                 while (it->next) {
850                     rfcomm_channel_t * channel = (rfcomm_channel_t *) it->next;
851                     if (channel->multiplexer == multiplexer){
852                         rfcomm_emit_channel_opened(channel, status);
853                         it->next = it->next->next;
854                         btstack_memory_rfcomm_channel_free(channel);
855                     } else {
856                         it = it->next;
857                     }
858                 }
859 
860                 // free multiplexer
861                 rfcomm_multiplexer_free(multiplexer);
862                 return 1;
863             }
864 
865             if (multiplexer->state == RFCOMM_MULTIPLEXER_W4_CONNECT) {
866                 log_info("L2CAP_EVENT_CHANNEL_OPENED: outgoing connection");
867                 // wrong remote addr
868                 if (BD_ADDR_CMP(event_addr, multiplexer->remote_addr)) break;
869                 multiplexer->l2cap_cid = l2cap_cid;
870                 multiplexer->con_handle = con_handle;
871                 // send SABM #0
872                 multiplexer->state = RFCOMM_MULTIPLEXER_SEND_SABM_0;
873             } else { // multiplexer->state == RFCOMM_MULTIPLEXER_W4_SABM_0
874 
875                 // set max frame size based on l2cap MTU
876                 multiplexer->max_frame_size = rfcomm_max_frame_size_for_l2cap_mtu(READ_BT_16(packet, 17));
877             }
878             return 1;
879 
880             // l2cap disconnect -> state = RFCOMM_MULTIPLEXER_CLOSED;
881 
882         case L2CAP_EVENT_CREDITS:
883             // data: event(8), len(8), local_cid(16), credits(8)
884             l2cap_cid = READ_BT_16(packet, 2);
885             multiplexer = rfcomm_multiplexer_for_l2cap_cid(l2cap_cid);
886             if (!multiplexer) break;
887             // log_info("L2CAP_EVENT_CREDITS: %u (now %u)", packet[4], multiplexer->l2cap_credits);
888 
889             // new credits, continue with signaling
890             rfcomm_run();
891 
892             if (multiplexer->state != RFCOMM_MULTIPLEXER_OPEN) break;
893             rfcomm_hand_out_credits();
894             return 1;
895 
896         case DAEMON_EVENT_HCI_PACKET_SENT:
897             // testing DMA done code
898             rfcomm_run();
899             break;
900 
901         case L2CAP_EVENT_CHANNEL_CLOSED:
902             // data: event (8), len(8), channel (16)
903             l2cap_cid = READ_BT_16(packet, 2);
904             multiplexer = rfcomm_multiplexer_for_l2cap_cid(l2cap_cid);
905             log_info("L2CAP_EVENT_CHANNEL_CLOSED cid 0x%0x, mult %p", l2cap_cid, multiplexer);
906             if (!multiplexer) break;
907             log_info("L2CAP_EVENT_CHANNEL_CLOSED state %u", multiplexer->state);
908             switch (multiplexer->state) {
909                 case RFCOMM_MULTIPLEXER_W4_CONNECT:
910                 case RFCOMM_MULTIPLEXER_SEND_SABM_0:
911                 case RFCOMM_MULTIPLEXER_W4_SABM_0:
912                 case RFCOMM_MULTIPLEXER_SEND_UA_0:
913                 case RFCOMM_MULTIPLEXER_W4_UA_0:
914                 case RFCOMM_MULTIPLEXER_OPEN:
915                     // don't call l2cap_disconnect as it's alreay closed
916                     rfcomm_multiplexer_finalize(multiplexer);
917                     return 1;
918                 default:
919                     break;
920             }
921             break;
922         default:
923             break;
924     }
925     return 0;
926 }
927 
928 static int rfcomm_multiplexer_l2cap_packet_handler(uint16_t channel, uint8_t *packet, uint16_t size){
929 
930     // get or create a multiplexer for a certain device
931     rfcomm_multiplexer_t *multiplexer = rfcomm_multiplexer_for_l2cap_cid(channel);
932     if (!multiplexer) return 0;
933 
934     uint16_t l2cap_cid = multiplexer->l2cap_cid;
935 
936 	// but only care for multiplexer control channel
937     uint8_t frame_dlci = packet[0] >> 2;
938     if (frame_dlci) return 0;
939     const uint8_t length_offset = (packet[2] & 1) ^ 1;  // to be used for pos >= 3
940     const uint8_t credit_offset = ((packet[1] & BT_RFCOMM_UIH_PF) == BT_RFCOMM_UIH_PF) ? 1 : 0;   // credits for uih_pf frames
941     const uint8_t payload_offset = 3 + length_offset + credit_offset;
942     switch (packet[1]){
943 
944         case BT_RFCOMM_SABM:
945             if (multiplexer->state == RFCOMM_MULTIPLEXER_W4_SABM_0){
946                 log_info("Received SABM #0");
947                 multiplexer->outgoing = 0;
948                 multiplexer->state = RFCOMM_MULTIPLEXER_SEND_UA_0;
949                 return 1;
950             }
951             break;
952 
953         case BT_RFCOMM_UA:
954             if (multiplexer->state == RFCOMM_MULTIPLEXER_W4_UA_0) {
955                 // UA #0 -> send UA #0, state = RFCOMM_MULTIPLEXER_OPEN
956                 log_info("Received UA #0 ");
957                 rfcomm_multiplexer_opened(multiplexer);
958                 return 1;
959             }
960             break;
961 
962         case BT_RFCOMM_DISC:
963             // DISC #0 -> send UA #0, close multiplexer
964             log_info("Received DISC #0, (ougoing = %u)", multiplexer->outgoing);
965             multiplexer->state = RFCOMM_MULTIPLEXER_SEND_UA_0_AND_DISC;
966             return 1;
967 
968         case BT_RFCOMM_DM:
969             // DM #0 - we shouldn't get this, just give up
970             log_info("Received DM #0");
971             log_info("-> Closing down multiplexer");
972             rfcomm_multiplexer_finalize(multiplexer);
973             l2cap_disconnect_internal(l2cap_cid, 0x13);
974             return 1;
975 
976         case BT_RFCOMM_UIH:
977             if (packet[payload_offset] == BT_RFCOMM_CLD_CMD){
978                 // Multiplexer close down (CLD) -> close mutliplexer
979                 log_info("Received Multiplexer close down command");
980                 log_info("-> Closing down multiplexer");
981                 rfcomm_multiplexer_finalize(multiplexer);
982                 l2cap_disconnect_internal(l2cap_cid, 0x13);
983                 return 1;
984             }
985             switch (packet[payload_offset]){
986                 case BT_RFCOMM_CLD_CMD:
987                      // Multiplexer close down (CLD) -> close mutliplexer
988                     log_info("Received Multiplexer close down command");
989                     log_info("-> Closing down multiplexer");
990                     rfcomm_multiplexer_finalize(multiplexer);
991                     l2cap_disconnect_internal(l2cap_cid, 0x13);
992                     return 1;
993 
994                 case BT_RFCOMM_FCON_CMD:
995                     multiplexer->fcon = 0x81;
996                     break;
997 
998                 case BT_RFCOMM_FCOFF_CMD:
999                     multiplexer->fcon = 0x80;
1000                     break;
1001 
1002                 case BT_RFCOMM_TEST_CMD: {
1003                     log_info("Received test command");
1004                     int len = packet[payload_offset+1] >> 1; // length < 125
1005                     if (len > RFCOMM_TEST_DATA_MAX_LEN){
1006                         len = RFCOMM_TEST_DATA_MAX_LEN;
1007                     }
1008                     multiplexer->test_data_len = len;
1009                     memcpy(multiplexer->test_data, &packet[payload_offset + 2], len);
1010                     return 1;
1011                 }
1012                 default:
1013                     break;
1014             }
1015             break;
1016 
1017         default:
1018             break;
1019 
1020     }
1021     return 0;
1022 }
1023 
1024 static void rfcomm_multiplexer_state_machine(rfcomm_multiplexer_t * multiplexer, RFCOMM_MULTIPLEXER_EVENT event){
1025 
1026     uint16_t l2cap_cid = multiplexer->l2cap_cid;
1027 
1028     // process stored DM responses
1029     if (multiplexer->send_dm_for_dlci){
1030         uint8_t dlci = multiplexer->send_dm_for_dlci;
1031         multiplexer->send_dm_for_dlci = 0;
1032         rfcomm_send_dm_pf(multiplexer, dlci);
1033         return;
1034     }
1035 
1036     if (multiplexer->nsc_command){
1037         uint8_t command = multiplexer->nsc_command;
1038         multiplexer->nsc_command = 0;
1039         rfcomm_send_uih_nsc_rsp(multiplexer, command);
1040         return;
1041     }
1042 
1043     if (multiplexer->fcon & 0x80){
1044         multiplexer->fcon &= 0x01;
1045         rfcomm_send_uih_fc_rsp(multiplexer, multiplexer->fcon);
1046         if (multiplexer->fcon == 0) return;
1047         // trigger client to send again after sending FCon Response
1048         uint8_t packet_sent_event[] = { DAEMON_EVENT_HCI_PACKET_SENT, 0};
1049         linked_item_t *it;
1050         for (it = (linked_item_t *) rfcomm_channels; it ; it = it->next){
1051             rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
1052             if (channel->multiplexer != multiplexer) continue;
1053             (*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) packet_sent_event, sizeof(packet_sent_event));
1054         }
1055         return;
1056     }
1057 
1058     switch (multiplexer->state) {
1059         case RFCOMM_MULTIPLEXER_SEND_SABM_0:
1060             switch (event) {
1061                 case MULT_EV_READY_TO_SEND:
1062                     log_info("Sending SABM #0 - (multi 0x%p)", multiplexer);
1063                     multiplexer->state = RFCOMM_MULTIPLEXER_W4_UA_0;
1064                     rfcomm_send_sabm(multiplexer, 0);
1065                     break;
1066                 default:
1067                     break;
1068             }
1069             break;
1070         case RFCOMM_MULTIPLEXER_SEND_UA_0:
1071             switch (event) {
1072                 case MULT_EV_READY_TO_SEND:
1073                     log_info("Sending UA #0");
1074                     multiplexer->state = RFCOMM_MULTIPLEXER_OPEN;
1075                     rfcomm_send_ua(multiplexer, 0);
1076                     rfcomm_multiplexer_opened(multiplexer);
1077                     break;
1078                 default:
1079                     break;
1080             }
1081             break;
1082         case RFCOMM_MULTIPLEXER_SEND_UA_0_AND_DISC:
1083             switch (event) {
1084                 case MULT_EV_READY_TO_SEND:
1085                     // try to detect authentication errors: drop link key if multiplexer closed before first channel got opened
1086                     if (!multiplexer->at_least_one_connection){
1087                         log_info("TODO: no connections established - delete link key prophylactically");
1088                         // hci_send_cmd(&hci_delete_stored_link_key, multiplexer->remote_addr);
1089                     }
1090                     log_info("Sending UA #0");
1091                     log_info("Closing down multiplexer");
1092                     multiplexer->state = RFCOMM_MULTIPLEXER_CLOSED;
1093                     rfcomm_send_ua(multiplexer, 0);
1094                     rfcomm_multiplexer_finalize(multiplexer);
1095                     l2cap_disconnect_internal(l2cap_cid, 0x13);
1096                 default:
1097                     break;
1098             }
1099             break;
1100         case RFCOMM_MULTIPLEXER_OPEN:
1101             switch (event) {
1102                 case MULT_EV_READY_TO_SEND:
1103                     // respond to test command
1104                     if (multiplexer->test_data_len){
1105                         int len = multiplexer->test_data_len;
1106                         log_info("Sending TEST Response with %u bytes", len);
1107                         multiplexer->test_data_len = 0;
1108                         rfcomm_send_uih_test_rsp(multiplexer, multiplexer->test_data, len);
1109                         return;
1110                     }
1111                     break;
1112                 default:
1113                     break;
1114             }
1115             break;
1116         default:
1117             break;
1118     }
1119 }
1120 
1121 // MARK: RFCOMM CHANNEL
1122 
1123 static void rfcomm_hand_out_credits(void){
1124     linked_item_t * it;
1125     for (it = (linked_item_t *) rfcomm_channels; it ; it = it->next){
1126         rfcomm_channel_t * channel = (rfcomm_channel_t *) it;
1127         if (channel->state != RFCOMM_CHANNEL_OPEN) {
1128             // log_info("RFCOMM_EVENT_CREDITS: multiplexer not open");
1129             continue;
1130         }
1131         if (channel->packets_granted) {
1132             // log_info("RFCOMM_EVENT_CREDITS: already packets granted");
1133             continue;
1134         }
1135         if (!channel->credits_outgoing) {
1136             // log_info("RFCOMM_EVENT_CREDITS: no outgoing credits");
1137             continue;
1138         }
1139         // channel open, multiplexer has l2cap credits and we didn't hand out credit before -> go!
1140         // log_info("RFCOMM_EVENT_CREDITS: 1");
1141         channel->packets_granted += 1;
1142         rfcomm_emit_credits(channel, 1);
1143     }
1144 }
1145 
1146 static void rfcomm_channel_send_credits(rfcomm_channel_t *channel, uint8_t credits){
1147     rfcomm_send_uih_credits(channel->multiplexer, channel->dlci, credits);
1148     channel->credits_incoming += credits;
1149 }
1150 
1151 static void rfcomm_channel_opened(rfcomm_channel_t *rfChannel){
1152 
1153     log_info("rfcomm_channel_opened!");
1154 
1155     rfChannel->state = RFCOMM_CHANNEL_OPEN;
1156     rfcomm_emit_channel_opened(rfChannel, 0);
1157     rfcomm_emit_port_configuration(rfChannel);
1158     rfcomm_hand_out_credits();
1159 
1160     // remove (potential) timer
1161     rfcomm_multiplexer_t *multiplexer = rfChannel->multiplexer;
1162     if (multiplexer->timer_active) {
1163         run_loop_remove_timer(&multiplexer->timer);
1164         multiplexer->timer_active = 0;
1165     }
1166     // hack for problem detecting authentication failure
1167     multiplexer->at_least_one_connection = 1;
1168 
1169     // start next connection request if pending
1170     rfcomm_run();
1171 }
1172 
1173 static void rfcomm_channel_packet_handler_uih(rfcomm_multiplexer_t *multiplexer, uint8_t * packet, uint16_t size){
1174     const uint8_t frame_dlci = packet[0] >> 2;
1175     const uint8_t length_offset = (packet[2] & 1) ^ 1;  // to be used for pos >= 3
1176     const uint8_t credit_offset = ((packet[1] & BT_RFCOMM_UIH_PF) == BT_RFCOMM_UIH_PF) ? 1 : 0;   // credits for uih_pf frames
1177     const uint8_t payload_offset = 3 + length_offset + credit_offset;
1178 
1179     rfcomm_channel_t * channel = rfcomm_channel_for_multiplexer_and_dlci(multiplexer, frame_dlci);
1180     if (!channel) return;
1181 
1182     // handle new outgoing credits
1183     if (packet[1] == BT_RFCOMM_UIH_PF) {
1184 
1185         // add them
1186         uint16_t new_credits = packet[3+length_offset];
1187         channel->credits_outgoing += new_credits;
1188         log_info( "RFCOMM data UIH_PF, new credits: %u, now %u", new_credits, channel->credits_outgoing);
1189 
1190         // notify channel statemachine
1191         rfcomm_channel_event_t channel_event = { CH_EVT_RCVD_CREDITS };
1192         rfcomm_channel_state_machine(channel, &channel_event);
1193     }
1194 
1195     // contains payload?
1196     if (size - 1 > payload_offset){
1197 
1198         // log_info( "RFCOMM data UIH_PF, size %u, channel %p", size-payload_offset-1, rfChannel->connection);
1199 
1200         // decrease incoming credit counter
1201         if (channel->credits_incoming > 0){
1202             channel->credits_incoming--;
1203         }
1204 
1205         // deliver payload
1206         (*app_packet_handler)(RFCOMM_DATA_PACKET, channel->rfcomm_cid,
1207                               &packet[payload_offset], size-payload_offset-1);
1208     }
1209 
1210     // automatically provide new credits to remote device, if no incoming flow control
1211     if (!channel->incoming_flow_control && channel->credits_incoming < 5){
1212         channel->new_credits_incoming =RFCOMM_CREDITS;
1213     }
1214     // we received new RFCOMM credits, hand them out if possible
1215     rfcomm_hand_out_credits();
1216 }
1217 
1218 static void rfcomm_channel_accept_pn(rfcomm_channel_t *channel, rfcomm_channel_event_pn_t *event){
1219     // priority of client request
1220     channel->pn_priority = event->priority;
1221 
1222     // new credits
1223     channel->credits_outgoing = event->credits_outgoing;
1224 
1225     // negotiate max frame size
1226     if (channel->max_frame_size > channel->multiplexer->max_frame_size) {
1227         channel->max_frame_size = channel->multiplexer->max_frame_size;
1228     }
1229     if (channel->max_frame_size > event->max_frame_size) {
1230         channel->max_frame_size = event->max_frame_size;
1231     }
1232 
1233 }
1234 
1235 static void rfcomm_channel_finalize(rfcomm_channel_t *channel){
1236 
1237     rfcomm_multiplexer_t *multiplexer = channel->multiplexer;
1238 
1239     // remove from list
1240     linked_list_remove( &rfcomm_channels, (linked_item_t *) channel);
1241 
1242     // free channel
1243     btstack_memory_rfcomm_channel_free(channel);
1244 
1245     // update multiplexer timeout after channel was removed from list
1246     rfcomm_multiplexer_prepare_idle_timer(multiplexer);
1247 }
1248 
1249 static void rfcomm_channel_state_machine_2(rfcomm_multiplexer_t * multiplexer, uint8_t dlci, rfcomm_channel_event_t *event){
1250 
1251     // TODO: if client max frame size is smaller than RFCOMM_DEFAULT_SIZE, send PN
1252 
1253 
1254     // lookup existing channel
1255     rfcomm_channel_t * channel = rfcomm_channel_for_multiplexer_and_dlci(multiplexer, dlci);
1256 
1257     // log_info("rfcomm_channel_state_machine_2 lookup dlci #%u = 0x%08x - event %u", dlci, (int) channel, event->type);
1258 
1259     if (channel) {
1260         rfcomm_channel_state_machine(channel, event);
1261         return;
1262     }
1263 
1264     // service registered?
1265     rfcomm_service_t * service = rfcomm_service_for_channel(dlci >> 1);
1266     // log_info("rfcomm_channel_state_machine_2 service dlci #%u = 0x%08x", dlci, (int) service);
1267     if (!service) {
1268         // discard request by sending disconnected mode
1269         multiplexer->send_dm_for_dlci = dlci;
1270         return;
1271     }
1272 
1273     // create channel for some events
1274     switch (event->type) {
1275         case CH_EVT_RCVD_SABM:
1276         case CH_EVT_RCVD_PN:
1277         case CH_EVT_RCVD_RPN_REQ:
1278         case CH_EVT_RCVD_RPN_CMD:
1279             // setup incoming channel
1280             channel = rfcomm_channel_create(multiplexer, service, dlci >> 1);
1281             if (!channel){
1282                 // discard request by sending disconnected mode
1283                 multiplexer->send_dm_for_dlci = dlci;
1284             }
1285             break;
1286         default:
1287             break;
1288     }
1289 
1290     if (!channel) {
1291         // discard request by sending disconnected mode
1292         multiplexer->send_dm_for_dlci = dlci;
1293         return;
1294     }
1295     rfcomm_channel_state_machine(channel, event);
1296 }
1297 
1298 static void rfcomm_channel_packet_handler(rfcomm_multiplexer_t * multiplexer,  uint8_t *packet, uint16_t size){
1299 
1300     // rfcomm: (0) addr [76543 server channel] [2 direction: initiator uses 1] [1 C/R: CMD by initiator = 1] [0 EA=1]
1301     const uint8_t frame_dlci = packet[0] >> 2;
1302     uint8_t message_dlci; // used by commands in UIH(_PF) packets
1303 	uint8_t message_len;  //   "
1304 
1305     // rfcomm: (1) command/control
1306     // -- credits_offset = 1 if command == BT_RFCOMM_UIH_PF
1307     const uint8_t credit_offset = ((packet[1] & BT_RFCOMM_UIH_PF) == BT_RFCOMM_UIH_PF) ? 1 : 0;   // credits for uih_pf frames
1308     // rfcomm: (2) length. if bit 0 is cleared, 2 byte length is used. (little endian)
1309     const uint8_t length_offset = (packet[2] & 1) ^ 1;  // to be used for pos >= 3
1310     // rfcomm: (3+length_offset) credits if credits_offset == 1
1311     // rfcomm: (3+length_offest+credits_offset)
1312     const uint8_t payload_offset = 3 + length_offset + credit_offset;
1313 
1314     rfcomm_channel_event_t event;
1315     rfcomm_channel_event_pn_t event_pn;
1316     rfcomm_channel_event_rpn_t event_rpn;
1317     rfcomm_channel_event_msc_t event_msc;
1318 
1319     // switch by rfcomm message type
1320     switch(packet[1]) {
1321 
1322         case BT_RFCOMM_SABM:
1323             event.type = CH_EVT_RCVD_SABM;
1324             log_info("Received SABM #%u", frame_dlci);
1325             rfcomm_channel_state_machine_2(multiplexer, frame_dlci, &event);
1326             break;
1327 
1328         case BT_RFCOMM_UA:
1329             event.type = CH_EVT_RCVD_UA;
1330             log_info("Received UA #%u",frame_dlci);
1331             rfcomm_channel_state_machine_2(multiplexer, frame_dlci, &event);
1332             break;
1333 
1334         case BT_RFCOMM_DISC:
1335             event.type = CH_EVT_RCVD_DISC;
1336             rfcomm_channel_state_machine_2(multiplexer, frame_dlci, &event);
1337             break;
1338 
1339         case BT_RFCOMM_DM:
1340         case BT_RFCOMM_DM_PF:
1341             event.type = CH_EVT_RCVD_DM;
1342             rfcomm_channel_state_machine_2(multiplexer, frame_dlci, &event);
1343             break;
1344 
1345         case BT_RFCOMM_UIH_PF:
1346         case BT_RFCOMM_UIH:
1347 
1348             message_len  = packet[payload_offset+1] >> 1;
1349 
1350             switch (packet[payload_offset]) {
1351                 case BT_RFCOMM_PN_CMD:
1352                     message_dlci = packet[payload_offset+2];
1353                     event_pn.super.type = CH_EVT_RCVD_PN;
1354                     event_pn.priority = packet[payload_offset+4];
1355                     event_pn.max_frame_size = READ_BT_16(packet, payload_offset+6);
1356                     event_pn.credits_outgoing = packet[payload_offset+9];
1357                     log_info("Received UIH Parameter Negotiation Command for #%u, credits %u",
1358                         message_dlci, event_pn.credits_outgoing);
1359                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_pn);
1360                     break;
1361 
1362                 case BT_RFCOMM_PN_RSP:
1363                     message_dlci = packet[payload_offset+2];
1364                     event_pn.super.type = CH_EVT_RCVD_PN_RSP;
1365                     event_pn.priority = packet[payload_offset+4];
1366                     event_pn.max_frame_size = READ_BT_16(packet, payload_offset+6);
1367                     event_pn.credits_outgoing = packet[payload_offset+9];
1368                     log_info("Received UIH Parameter Negotiation Response max frame %u, credits %u",
1369                             event_pn.max_frame_size, event_pn.credits_outgoing);
1370                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_pn);
1371                     break;
1372 
1373                 case BT_RFCOMM_MSC_CMD:
1374                     message_dlci = packet[payload_offset+2] >> 2;
1375                     event_msc.super.type = CH_EVT_RCVD_MSC_CMD;
1376                     event_msc.modem_status = packet[payload_offset+3];
1377                     log_info("Received MSC CMD for #%u, ", message_dlci);
1378                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_msc);
1379                     break;
1380 
1381                 case BT_RFCOMM_MSC_RSP:
1382                     message_dlci = packet[payload_offset+2] >> 2;
1383                     event.type = CH_EVT_RCVD_MSC_RSP;
1384                     log_info("Received MSC RSP for #%u", message_dlci);
1385                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, &event);
1386                     break;
1387 
1388                 case BT_RFCOMM_RPN_CMD:
1389                     message_dlci = packet[payload_offset+2] >> 2;
1390                     switch (message_len){
1391                         case 1:
1392                             log_info("Received Remote Port Negotiation Request for #%u", message_dlci);
1393                             event.type = CH_EVT_RCVD_RPN_REQ;
1394                             rfcomm_channel_state_machine_2(multiplexer, message_dlci, &event);
1395                             break;
1396                         case 8:
1397                             log_info("Received Remote Port Negotiation Update for #%u", message_dlci);
1398                             event_rpn.super.type = CH_EVT_RCVD_RPN_CMD;
1399                             event_rpn.data = *(rfcomm_rpn_data_t*) &packet[payload_offset+3];
1400                             rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_rpn);
1401                             break;
1402                         default:
1403                             break;
1404                     }
1405                     break;
1406 
1407                 case BT_RFCOMM_RPN_RSP:
1408                     log_info("Received RPN response");
1409                     break;
1410 
1411                 case BT_RFCOMM_RLS_CMD: {
1412                     log_info("Received RLS command");
1413                     message_dlci = packet[payload_offset+2] >> 2;
1414                     rfcomm_channel_event_rls_t event_rls;
1415                     event_rls.super.type = CH_EVT_RCVD_RLS_CMD;
1416                     event_rls.line_status = packet[payload_offset+3];
1417                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_rls);
1418                     break;
1419                 }
1420 
1421                 case BT_RFCOMM_RLS_RSP:
1422                     log_info("Received RLS response");
1423                     break;
1424 
1425                 // Following commands are handled by rfcomm_multiplexer_l2cap_packet_handler
1426                 // case BT_RFCOMM_TEST_CMD:
1427                 // case BT_RFCOMM_FCOFF_CMD:
1428                 // case BT_RFCOMM_FCON_CMD:
1429                 // everything else is an not supported command
1430                 default: {
1431                     log_error("Received unknown UIH command packet - 0x%02x", packet[payload_offset]);
1432                     multiplexer->nsc_command = packet[payload_offset];
1433                     break;
1434                 }
1435             }
1436             break;
1437 
1438         default:
1439             log_error("Received unknown RFCOMM message type %x", packet[1]);
1440             break;
1441     }
1442 
1443     // trigger next action - example W4_PN_RSP: transition to SEND_SABM which only depends on "can send"
1444     rfcomm_run();
1445 }
1446 
1447 static void rfcomm_packet_handler(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size){
1448 
1449     // multiplexer handler
1450     int handled = 0;
1451     switch (packet_type) {
1452         case HCI_EVENT_PACKET:
1453             handled = rfcomm_multiplexer_hci_event_handler(packet, size);
1454             break;
1455         case L2CAP_DATA_PACKET:
1456             handled = rfcomm_multiplexer_l2cap_packet_handler(channel, packet, size);
1457             break;
1458         default:
1459             break;
1460     }
1461 
1462     if (handled) {
1463         rfcomm_run();
1464         return;
1465     }
1466 
1467     // we only handle l2cap packet over open multiplexer channel now
1468     if (packet_type != L2CAP_DATA_PACKET) {
1469         (*app_packet_handler)(packet_type, channel, packet, size);
1470         return;
1471     }
1472     rfcomm_multiplexer_t * multiplexer = rfcomm_multiplexer_for_l2cap_cid(channel);
1473     if (!multiplexer || multiplexer->state != RFCOMM_MULTIPLEXER_OPEN) {
1474         (*app_packet_handler)(packet_type, channel, packet, size);
1475         return;
1476     }
1477 
1478     // channel data ?
1479     // rfcomm: (0) addr [76543 server channel] [2 direction: initiator uses 1] [1 C/R: CMD by initiator = 1] [0 EA=1]
1480     const uint8_t frame_dlci = packet[0] >> 2;
1481 
1482     if (frame_dlci && (packet[1] == BT_RFCOMM_UIH || packet[1] == BT_RFCOMM_UIH_PF)) {
1483         rfcomm_channel_packet_handler_uih(multiplexer, packet, size);
1484         rfcomm_run();
1485         return;
1486     }
1487 
1488     rfcomm_channel_packet_handler(multiplexer, packet, size);
1489 }
1490 
1491 static int rfcomm_channel_ready_for_open(rfcomm_channel_t *channel){
1492     // note: exchanging MSC isn't neccessary to consider channel open
1493     // note: having outgoing credits is also not necessary to consider channel open
1494     // log_info("rfcomm_channel_ready_for_open state %u, flags needed %04x, current %04x, rf credits %u, l2cap credits %u ", channel->state, RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_RSP|RFCOMM_CHANNEL_STATE_VAR_SENT_MSC_RSP|RFCOMM_CHANNEL_STATE_VAR_SENT_CREDITS, channel->state_var, channel->credits_outgoing, channel->multiplexer->l2cap_credits);
1495     // if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SENT_MSC_RSP) == 0) return 0;
1496     // if (channel->credits_outgoing == 0) return 0;
1497     log_info("rfcomm_channel_ready_for_open state %u, flags needed %04x, current %04x, rf credits %u",
1498          channel->state, RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_RSP, channel->state_var, channel->credits_outgoing);
1499     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_RSP) == 0) return 0;
1500     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SENT_CREDITS) == 0) return 0;
1501 
1502     return 1;
1503 }
1504 
1505 static int rfcomm_channel_ready_for_incoming_dlc_setup(rfcomm_channel_t * channel){
1506     log_info("rfcomm_channel_ready_for_incoming_dlc_setup state var %04x", channel->state_var);
1507     // Client accept and SABM/UA is required, PN RSP is needed if PN was received
1508     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_CLIENT_ACCEPTED) == 0) return 0;
1509     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_RCVD_SABM      ) == 0) return 0;
1510     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_UA        ) != 0) return 0;
1511     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP    ) != 0) return 0;
1512     return 1;
1513 }
1514 
1515 inline static void rfcomm_channel_state_add(rfcomm_channel_t *channel, RFCOMM_CHANNEL_STATE_VAR event){
1516     channel->state_var = (RFCOMM_CHANNEL_STATE_VAR) (channel->state_var | event);
1517 }
1518 inline static void rfcomm_channel_state_remove(rfcomm_channel_t *channel, RFCOMM_CHANNEL_STATE_VAR event){
1519     channel->state_var = (RFCOMM_CHANNEL_STATE_VAR) (channel->state_var & ~event);
1520 }
1521 
1522 static void rfcomm_channel_state_machine(rfcomm_channel_t *channel, rfcomm_channel_event_t *event){
1523 
1524     // log_info("rfcomm_channel_state_machine: state %u, state_var %04x, event %u", channel->state, channel->state_var ,event->type);
1525 
1526     rfcomm_multiplexer_t *multiplexer = channel->multiplexer;
1527 
1528     // TODO: integrate in common switch
1529     if (event->type == CH_EVT_RCVD_DISC){
1530         rfcomm_emit_channel_closed(channel);
1531         channel->state = RFCOMM_CHANNEL_SEND_UA_AFTER_DISC;
1532         return;
1533     }
1534 
1535     // TODO: integrate in common switch
1536     if (event->type == CH_EVT_RCVD_DM){
1537         log_info("Received DM message for #%u", channel->dlci);
1538         log_info("-> Closing channel locally for #%u", channel->dlci);
1539         rfcomm_emit_channel_closed(channel);
1540         rfcomm_channel_finalize(channel);
1541         return;
1542     }
1543 
1544     // remote port negotiation command - just accept everything for now
1545     //
1546     // "The RPN command can be used before a new DLC is opened and should be used whenever the port settings change."
1547     // "The RPN command is specified as optional in TS 07.10, but it is mandatory to recognize and respond to it in RFCOMM.
1548     //   (Although the handling of individual settings are implementation-dependent.)"
1549     //
1550 
1551     // TODO: integrate in common switch
1552     if (event->type == CH_EVT_RCVD_RPN_CMD){
1553         // control port parameters
1554         rfcomm_channel_event_rpn_t *event_rpn = (rfcomm_channel_event_rpn_t*) event;
1555         rfcomm_rpn_data_update(&channel->rpn_data, &event_rpn->data);
1556         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_RPN_RSP);
1557         // notify client about new settings
1558         rfcomm_emit_port_configuration(channel);
1559         return;
1560     }
1561 
1562     // TODO: integrate in common switch
1563     if (event->type == CH_EVT_RCVD_RPN_REQ){
1564         // no values got accepted (no values have beens sent)
1565         channel->rpn_data.parameter_mask_0 = 0x00;
1566         channel->rpn_data.parameter_mask_1 = 0x00;
1567         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_RPN_RSP);
1568         return;
1569     }
1570 
1571     if (event->type == CH_EVT_RCVD_RLS_CMD){
1572         rfcomm_channel_event_rls_t * event_rls = (rfcomm_channel_event_rls_t*) event;
1573         channel->rls_line_status = event_rls->line_status & 0x0f;
1574         log_info("CH_EVT_RCVD_RLS_CMD setting line status to 0x%0x", channel->rls_line_status);
1575         rfcomm_emit_remote_line_status(channel, event_rls->line_status);
1576         return;
1577     }
1578 
1579     // TODO: integrate in common swich
1580     if (event->type == CH_EVT_READY_TO_SEND){
1581         if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_RPN_RSP){
1582             log_info("Sending Remote Port Negotiation RSP for #%u", channel->dlci);
1583             rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_RPN_RSP);
1584             rfcomm_send_uih_rpn_rsp(multiplexer, channel->dlci, &channel->rpn_data);
1585             return;
1586         }
1587         if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_RSP){
1588             log_info("Sending MSC RSP for #%u", channel->dlci);
1589             rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_RSP);
1590             rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SENT_MSC_RSP);
1591             rfcomm_send_uih_msc_rsp(multiplexer, channel->dlci, 0x8d);  // ea=1,fc=0,rtc=1,rtr=1,ic=0,dv=1
1592             return;
1593         }
1594         if (channel->rls_line_status != RFCOMM_RLS_STATUS_INVALID){
1595             log_info("Sending RLS RSP 0x%0x", channel->rls_line_status);
1596             uint8_t line_status = channel->rls_line_status;
1597             channel->rls_line_status = RFCOMM_RLS_STATUS_INVALID;
1598             rfcomm_send_uih_rls_rsp(multiplexer, channel->dlci, line_status);
1599             return;
1600         }
1601     }
1602 
1603     // emit MSC status to app
1604     if (event->type == CH_EVT_RCVD_MSC_CMD){
1605         // notify client about new settings
1606         rfcomm_channel_event_msc_t *event_msc = (rfcomm_channel_event_msc_t*) event;
1607         uint8_t modem_status_event[2+1];
1608         modem_status_event[0] = RFCOMM_EVENT_REMOTE_MODEM_STATUS;
1609         modem_status_event[1] = 1;
1610         modem_status_event[2] = event_msc->modem_status;
1611         (*app_packet_handler)(HCI_EVENT_PACKET, channel->rfcomm_cid, (uint8_t*)&modem_status_event, sizeof(modem_status_event));
1612         // no return, MSC_CMD will be handled by state machine below
1613     }
1614 
1615     rfcomm_channel_event_pn_t * event_pn = (rfcomm_channel_event_pn_t*) event;
1616 
1617     switch (channel->state) {
1618         case RFCOMM_CHANNEL_CLOSED:
1619             switch (event->type){
1620                 case CH_EVT_RCVD_SABM:
1621                     log_info("-> Inform app");
1622                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_SABM);
1623                     channel->state = RFCOMM_CHANNEL_INCOMING_SETUP;
1624                     rfcomm_emit_connection_request(channel);
1625                     break;
1626                 case CH_EVT_RCVD_PN:
1627                     rfcomm_channel_accept_pn(channel, event_pn);
1628                     log_info("-> Inform app");
1629                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_PN);
1630                     channel->state = RFCOMM_CHANNEL_INCOMING_SETUP;
1631                     rfcomm_emit_connection_request(channel);
1632                     break;
1633                 default:
1634                     break;
1635             }
1636             break;
1637 
1638         case RFCOMM_CHANNEL_INCOMING_SETUP:
1639             switch (event->type){
1640                 case CH_EVT_RCVD_SABM:
1641                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_SABM);
1642                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_CLIENT_ACCEPTED) {
1643                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_UA);
1644                     }
1645                     break;
1646                 case CH_EVT_RCVD_PN:
1647                     rfcomm_channel_accept_pn(channel, event_pn);
1648                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_PN);
1649                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_CLIENT_ACCEPTED) {
1650                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP);
1651                     }
1652                     break;
1653                 case CH_EVT_READY_TO_SEND:
1654                     // if / else if is used to check for state transition after sending
1655                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP){
1656                         log_info("Sending UIH Parameter Negotiation Respond for #%u", channel->dlci);
1657                         rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP);
1658                         rfcomm_send_uih_pn_response(multiplexer, channel->dlci, channel->pn_priority, channel->max_frame_size);
1659                     } else if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_UA){
1660                         log_info("Sending UA #%u", channel->dlci);
1661                         rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_UA);
1662                         rfcomm_send_ua(multiplexer, channel->dlci);
1663                     }
1664                     if (rfcomm_channel_ready_for_incoming_dlc_setup(channel)){
1665                         log_info("Incomping setup done, requesting send MSC CMD and send Credits");
1666                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_CMD);
1667                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_CREDITS);
1668                         channel->state = RFCOMM_CHANNEL_DLC_SETUP;
1669                     }
1670                     break;
1671                 default:
1672                     break;
1673             }
1674             break;
1675 
1676         case RFCOMM_CHANNEL_W4_MULTIPLEXER:
1677             switch (event->type) {
1678                 case CH_EVT_MULTIPLEXER_READY:
1679                     log_info("Muliplexer opened, sending UIH PN next");
1680                     channel->state = RFCOMM_CHANNEL_SEND_UIH_PN;
1681                     break;
1682                 default:
1683                     break;
1684             }
1685             break;
1686 
1687         case RFCOMM_CHANNEL_SEND_UIH_PN:
1688             switch (event->type) {
1689                 case CH_EVT_READY_TO_SEND:
1690                     log_info("Sending UIH Parameter Negotiation Command for #%u (channel 0x%p)", channel->dlci, channel );
1691                     channel->state = RFCOMM_CHANNEL_W4_PN_RSP;
1692                     rfcomm_send_uih_pn_command(multiplexer, channel->dlci, channel->max_frame_size);
1693                     break;
1694                 default:
1695                     break;
1696             }
1697             break;
1698 
1699         case RFCOMM_CHANNEL_W4_PN_RSP:
1700             switch (event->type){
1701                 case CH_EVT_RCVD_PN_RSP:
1702                     // update max frame size
1703                     if (channel->max_frame_size > event_pn->max_frame_size) {
1704                         channel->max_frame_size = event_pn->max_frame_size;
1705                     }
1706                     // new credits
1707                     channel->credits_outgoing = event_pn->credits_outgoing;
1708                     channel->state = RFCOMM_CHANNEL_SEND_SABM_W4_UA;
1709                     break;
1710                 default:
1711                     break;
1712             }
1713             break;
1714 
1715         case RFCOMM_CHANNEL_SEND_SABM_W4_UA:
1716             switch (event->type) {
1717                 case CH_EVT_READY_TO_SEND:
1718                     log_info("Sending SABM #%u", channel->dlci);
1719                     channel->state = RFCOMM_CHANNEL_W4_UA;
1720                     rfcomm_send_sabm(multiplexer, channel->dlci);
1721                     break;
1722                 default:
1723                     break;
1724             }
1725             break;
1726 
1727         case RFCOMM_CHANNEL_W4_UA:
1728             switch (event->type){
1729                 case CH_EVT_RCVD_UA:
1730                     channel->state = RFCOMM_CHANNEL_DLC_SETUP;
1731                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_CMD);
1732                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_CREDITS);
1733                     break;
1734                 default:
1735                     break;
1736             }
1737             break;
1738 
1739         case RFCOMM_CHANNEL_DLC_SETUP:
1740             switch (event->type){
1741                 case CH_EVT_RCVD_MSC_CMD:
1742                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_CMD);
1743                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_RSP);
1744                     break;
1745                 case CH_EVT_RCVD_MSC_RSP:
1746                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_RSP);
1747                     break;
1748 
1749                 case CH_EVT_READY_TO_SEND:
1750                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_CMD){
1751                         log_info("Sending MSC CMD for #%u", channel->dlci);
1752                         rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_CMD);
1753                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SENT_MSC_CMD);
1754                         rfcomm_send_uih_msc_cmd(multiplexer, channel->dlci , 0x8d);  // ea=1,fc=0,rtc=1,rtr=1,ic=0,dv=1
1755                         break;
1756                     }
1757                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_CREDITS){
1758                         log_info("Providing credits for #%u", channel->dlci);
1759                         rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_CREDITS);
1760                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SENT_CREDITS);
1761 
1762                         if (channel->new_credits_incoming) {
1763                             uint8_t new_credits = channel->new_credits_incoming;
1764                             channel->new_credits_incoming = 0;
1765                             rfcomm_channel_send_credits(channel, new_credits);
1766                         }
1767                         break;
1768 
1769                     }
1770                     break;
1771                 default:
1772                     break;
1773             }
1774             // finally done?
1775             if (rfcomm_channel_ready_for_open(channel)){
1776                 channel->state = RFCOMM_CHANNEL_OPEN;
1777                 rfcomm_channel_opened(channel);
1778             }
1779             break;
1780 
1781         case RFCOMM_CHANNEL_OPEN:
1782             switch (event->type){
1783                 case CH_EVT_RCVD_MSC_CMD:
1784                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_RSP);
1785                     break;
1786                 case CH_EVT_READY_TO_SEND:
1787                     if (channel->new_credits_incoming) {
1788                         uint8_t new_credits = channel->new_credits_incoming;
1789                         channel->new_credits_incoming = 0;
1790                         rfcomm_channel_send_credits(channel, new_credits);
1791                         break;
1792                     }
1793                     break;
1794                 case CH_EVT_RCVD_CREDITS: {
1795                     // notify daemon -> might trigger re-try of parked connections
1796                     uint8_t credits_event[2] = { DAEMON_EVENT_NEW_RFCOMM_CREDITS, 0 };
1797                     (*app_packet_handler)(DAEMON_EVENT_PACKET, channel->rfcomm_cid, credits_event, sizeof(credits_event));
1798                     break;
1799                 }
1800                 default:
1801                     break;
1802             }
1803             break;
1804 
1805         case RFCOMM_CHANNEL_SEND_DM:
1806             switch (event->type) {
1807                 case CH_EVT_READY_TO_SEND:
1808                     log_info("Sending DM_PF for #%u", channel->dlci);
1809                     // don't emit channel closed - channel was never open
1810                     channel->state = RFCOMM_CHANNEL_CLOSED;
1811                     rfcomm_send_dm_pf(multiplexer, channel->dlci);
1812                     rfcomm_channel_finalize(channel);
1813                     break;
1814                 default:
1815                     break;
1816             }
1817             break;
1818 
1819         case RFCOMM_CHANNEL_SEND_DISC:
1820             switch (event->type) {
1821                 case CH_EVT_READY_TO_SEND:
1822                     channel->state = RFCOMM_CHANNEL_W4_UA_AFTER_UA;
1823                     rfcomm_send_disc(multiplexer, channel->dlci);
1824                     break;
1825                 default:
1826                     break;
1827             }
1828             break;
1829 
1830         case RFCOMM_CHANNEL_W4_UA_AFTER_UA:
1831             switch (event->type){
1832                 case CH_EVT_RCVD_UA:
1833                     channel->state = RFCOMM_CHANNEL_CLOSED;
1834                     rfcomm_emit_channel_closed(channel);
1835                     rfcomm_channel_finalize(channel);
1836                     break;
1837                 default:
1838                     break;
1839             }
1840             break;
1841 
1842         case RFCOMM_CHANNEL_SEND_UA_AFTER_DISC:
1843             switch (event->type) {
1844                 case CH_EVT_READY_TO_SEND:
1845                     log_info("Sending UA after DISC for #%u", channel->dlci);
1846                     channel->state = RFCOMM_CHANNEL_CLOSED;
1847                     rfcomm_send_ua(multiplexer, channel->dlci);
1848                     rfcomm_channel_finalize(channel);
1849                     break;
1850                 default:
1851                     break;
1852             }
1853             break;
1854 
1855         default:
1856             break;
1857     }
1858 }
1859 
1860 
1861 // MARK: RFCOMM RUN
1862 // process outstanding signaling tasks
1863 static void rfcomm_run(void){
1864 
1865     linked_item_t *it;
1866     linked_item_t *next;
1867 
1868     for (it = (linked_item_t *) rfcomm_multiplexers; it ; it = next){
1869 
1870         next = it->next;    // be prepared for removal of channel in state machine
1871 
1872         rfcomm_multiplexer_t * multiplexer = ((rfcomm_multiplexer_t *) it);
1873 
1874         if (!l2cap_can_send_packet_now(multiplexer->l2cap_cid)) {
1875             // log_info("rfcomm_run A cannot send l2cap packet for #%u, credits %u", multiplexer->l2cap_cid, multiplexer->l2cap_credits);
1876             continue;
1877         }
1878         // log_info("rfcomm_run: multi 0x%08x, state %u", (int) multiplexer, multiplexer->state);
1879 
1880         rfcomm_multiplexer_state_machine(multiplexer, MULT_EV_READY_TO_SEND);
1881     }
1882 
1883     for (it = (linked_item_t *) rfcomm_channels; it ; it = next){
1884 
1885         next = it->next;    // be prepared for removal of channel in state machine
1886 
1887         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
1888         rfcomm_multiplexer_t * multiplexer = channel->multiplexer;
1889 
1890         if (!l2cap_can_send_packet_now(multiplexer->l2cap_cid)) {
1891             // log_info("rfcomm_run B cannot send l2cap packet for #%u, credits %u", multiplexer->l2cap_cid, multiplexer->l2cap_credits);
1892             continue;
1893         }
1894 
1895         rfcomm_channel_event_t event = { CH_EVT_READY_TO_SEND };
1896         rfcomm_channel_state_machine(channel, &event);
1897     }
1898 }
1899 
1900 // MARK: RFCOMM BTstack API
1901 
1902 void rfcomm_init(void){
1903     rfcomm_client_cid_generator = 0;
1904     rfcomm_multiplexers = NULL;
1905     rfcomm_services     = NULL;
1906     rfcomm_channels     = NULL;
1907     rfcomm_security_level = LEVEL_2;
1908 }
1909 
1910 void rfcomm_set_required_security_level(gap_security_level_t security_level){
1911     rfcomm_security_level = security_level;
1912 }
1913 
1914 // register packet handler
1915 void rfcomm_register_packet_handler(void (*handler)(uint8_t packet_type,
1916                                                     uint16_t channel, uint8_t *packet, uint16_t size)){
1917 	app_packet_handler = handler;
1918 }
1919 
1920 int rfcomm_can_send_packet_now(uint16_t rfcomm_cid){
1921     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1922     if (!channel){
1923         log_error("rfcomm_send_internal cid 0x%02x doesn't exist!", rfcomm_cid);
1924         return 1;
1925     }
1926     if (!channel->credits_outgoing) return 0;
1927     if ((channel->multiplexer->fcon & 1) == 0) return 0;
1928 
1929     return l2cap_can_send_packet_now(channel->multiplexer->l2cap_cid);
1930 }
1931 
1932 static int rfcomm_assert_send_valid(rfcomm_channel_t * channel , uint16_t len){
1933     if (len > channel->max_frame_size){
1934         log_error("rfcomm_send_internal cid 0x%02x, rfcomm data lenght exceeds MTU!", channel->rfcomm_cid);
1935         return RFCOMM_DATA_LEN_EXCEEDS_MTU;
1936     }
1937 
1938     if (!channel->credits_outgoing){
1939         log_info("rfcomm_send_internal cid 0x%02x, no rfcomm outgoing credits!", channel->rfcomm_cid);
1940         return RFCOMM_NO_OUTGOING_CREDITS;
1941     }
1942 
1943     if ((channel->multiplexer->fcon & 1) == 0){
1944         log_info("rfcomm_send_internal cid 0x%02x, aggregate flow off!", channel->rfcomm_cid);
1945         return RFCOMM_AGGREGATE_FLOW_OFF;
1946     }
1947     return 0;
1948 }
1949 
1950 // pre: rfcomm_can_send_packet_now(rfcomm_cid) == true
1951 int rfcomm_reserve_packet_buffer(void){
1952     return l2cap_reserve_packet_buffer();
1953 }
1954 
1955 void rfcomm_release_packet_buffer(void){
1956     l2cap_release_packet_buffer();
1957 }
1958 
1959 uint8_t * rfcomm_get_outgoing_buffer(void){
1960     uint8_t * rfcomm_out_buffer = l2cap_get_outgoing_buffer();
1961     // address + control + length (16) + no credit field
1962     return &rfcomm_out_buffer[4];
1963 }
1964 
1965 uint16_t rfcomm_get_max_frame_size(uint16_t rfcomm_cid){
1966     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1967     if (!channel){
1968         log_error("rfcomm_get_max_frame_size cid 0x%02x doesn't exist!", rfcomm_cid);
1969         return 0;
1970     }
1971     return channel->max_frame_size;
1972 }
1973 int rfcomm_send_prepared(uint16_t rfcomm_cid, uint16_t len){
1974     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1975     if (!channel){
1976         log_error("rfcomm_send_prepared cid 0x%02x doesn't exist!", rfcomm_cid);
1977         return 0;
1978     }
1979 
1980     int err = rfcomm_assert_send_valid(channel, len);
1981     if (err) return err;
1982 
1983     // send might cause l2cap to emit new credits, update counters first
1984     channel->credits_outgoing--;
1985     int packets_granted_decreased = 0;
1986     if (channel->packets_granted) {
1987         channel->packets_granted--;
1988         packets_granted_decreased++;
1989     }
1990 
1991     int result = rfcomm_send_uih_prepared(channel->multiplexer, channel->dlci, len);
1992 
1993     if (result != 0) {
1994         channel->credits_outgoing++;
1995         channel->packets_granted += packets_granted_decreased;
1996         log_info("rfcomm_send_internal: error %d", result);
1997         return result;
1998     }
1999 
2000     rfcomm_hand_out_credits();
2001 
2002     return result;
2003 }
2004 
2005 int rfcomm_send_internal(uint16_t rfcomm_cid, uint8_t *data, uint16_t len){
2006     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2007     if (!channel){
2008         log_error("rfcomm_send_internal cid 0x%02x doesn't exist!", rfcomm_cid);
2009         return 1;
2010     }
2011 
2012     int err = rfcomm_assert_send_valid(channel, len);
2013     if (err) return err;
2014 
2015     rfcomm_reserve_packet_buffer();
2016     uint8_t * rfcomm_payload = rfcomm_get_outgoing_buffer();
2017     memcpy(rfcomm_payload, data, len);
2018     return rfcomm_send_prepared(rfcomm_cid, len);
2019 }
2020 
2021 // Sends Local Lnie Status, see LINE_STATUS_..
2022 int rfcomm_send_local_line_status(uint16_t rfcomm_cid, uint8_t line_status){
2023     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2024     if (!channel){
2025         log_error("rfcomm_send_local_line_status cid 0x%02x doesn't exist!", rfcomm_cid);
2026         return 0;
2027     }
2028     return rfcomm_send_uih_rls_cmd(channel->multiplexer, channel->dlci, line_status);
2029 }
2030 
2031 // Sned local modem status. see MODEM_STAUS_..
2032 int rfcomm_send_modem_status(uint16_t rfcomm_cid, uint8_t modem_status){
2033     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2034     if (!channel){
2035         log_error("rfcomm_send_modem_status cid 0x%02x doesn't exist!", rfcomm_cid);
2036         return 0;
2037     }
2038     return rfcomm_send_uih_msc_cmd(channel->multiplexer, channel->dlci, modem_status);
2039 }
2040 
2041 // Configure remote port
2042 int rfcomm_send_port_configuration(uint16_t rfcomm_cid, rpn_baud_t baud_rate, rpn_data_bits_t data_bits, rpn_stop_bits_t stop_bits, rpn_parity_t parity, rpn_flow_control_t flow_control){
2043     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2044     if (!channel){
2045         log_error("rfcomm_send_port_configuration cid 0x%02x doesn't exist!", rfcomm_cid);
2046         return 0;
2047     }
2048     rfcomm_rpn_data_t rpn_data;
2049     rpn_data.baud_rate = baud_rate;
2050     rpn_data.flags = data_bits | (stop_bits << 2) | (parity << 3);
2051     rpn_data.flow_control = flow_control;
2052     rpn_data.xon = 0;
2053     rpn_data.xoff = 0;
2054     rpn_data.parameter_mask_0 = 0x1f;   // all but xon/xoff
2055     rpn_data.parameter_mask_1 = 0x3f;   // all flow control options
2056     return rfcomm_send_uih_rpn_cmd(channel->multiplexer, channel->dlci, &rpn_data);
2057 }
2058 
2059 // Query remote port
2060 int rfcomm_query_port_configuration(uint16_t rfcomm_cid){
2061     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2062     if (!channel){
2063         log_error("rfcomm_query_port_configuration cid 0x%02x doesn't exist!", rfcomm_cid);
2064         return 0;
2065     }
2066     return rfcomm_send_uih_rpn_req(channel->multiplexer, channel->dlci);
2067 }
2068 
2069 
2070 static uint8_t rfcomm_create_channel_internal(bd_addr_t addr, uint8_t server_channel, uint8_t incoming_flow_control, uint8_t initial_credits, uint16_t * out_rfcomm_cid){
2071     log_info("RFCOMM_CREATE_CHANNEL addr %s channel #%u init credits %u",  bd_addr_to_str(addr), server_channel, initial_credits);
2072 
2073     // create new multiplexer if necessary
2074     uint8_t status = 0;
2075     int new_multiplexer = 0;
2076     rfcomm_channel_t * channel = NULL;
2077     rfcomm_multiplexer_t * multiplexer = rfcomm_multiplexer_for_addr(addr);
2078     if (!multiplexer) {
2079         multiplexer = rfcomm_multiplexer_create_for_addr(addr);
2080         if (!multiplexer){
2081             status = BTSTACK_MEMORY_ALLOC_FAILED;
2082             goto fail;
2083         }
2084         multiplexer->outgoing = 1;
2085         multiplexer->state = RFCOMM_MULTIPLEXER_W4_CONNECT;
2086         new_multiplexer = 1;
2087     }
2088 
2089     // prepare channel
2090     channel = rfcomm_channel_create(multiplexer, NULL, server_channel);
2091     if (!channel){
2092         status = BTSTACK_MEMORY_ALLOC_FAILED;
2093         goto fail;
2094     }
2095     // rfcomm_cid is already assigned by rfcomm_channel_create
2096     channel->incoming_flow_control = incoming_flow_control;
2097     channel->new_credits_incoming  = initial_credits;
2098 
2099     // return rfcomm_cid
2100     if (out_rfcomm_cid){
2101         *out_rfcomm_cid = channel->rfcomm_cid;
2102     }
2103 
2104     // start multiplexer setup
2105     if (multiplexer->state != RFCOMM_MULTIPLEXER_OPEN) {
2106         channel->state = RFCOMM_CHANNEL_W4_MULTIPLEXER;
2107         uint16_t l2cap_cid = 0;
2108         status = l2cap_create_channel(rfcomm_packet_handler, addr, PSM_RFCOMM, l2cap_max_mtu(), &l2cap_cid);
2109         if (status) goto fail;
2110         multiplexer->l2cap_cid = l2cap_cid;
2111         return 0;
2112     }
2113 
2114     channel->state = RFCOMM_CHANNEL_SEND_UIH_PN;
2115 
2116     // start connecting, if multiplexer is already up and running
2117     rfcomm_run();
2118     return 0;
2119 
2120 fail:
2121     if (new_multiplexer) btstack_memory_rfcomm_multiplexer_free(multiplexer);
2122     if (channel)         btstack_memory_rfcomm_channel_free(channel);
2123     return status;
2124 }
2125 
2126 uint8_t rfcomm_create_channel_with_initial_credits(bd_addr_t addr, uint8_t server_channel, uint8_t initial_credits, uint16_t * out_rfcomm_cid){
2127     return rfcomm_create_channel_internal(addr, server_channel, 1, initial_credits, out_rfcomm_cid);
2128 }
2129 
2130 uint8_t rfcomm_create_channel(bd_addr_t addr, uint8_t server_channel, uint16_t * out_rfcomm_cid){
2131     return rfcomm_create_channel_internal(addr, server_channel, 0, RFCOMM_CREDITS, out_rfcomm_cid);
2132 }
2133 
2134 void rfcomm_disconnect_internal(uint16_t rfcomm_cid){
2135     log_info("RFCOMM_DISCONNECT cid 0x%02x", rfcomm_cid);
2136     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2137     if (channel) {
2138         channel->state = RFCOMM_CHANNEL_SEND_DISC;
2139     }
2140 
2141     // process
2142     rfcomm_run();
2143 }
2144 
2145 static uint8_t rfcomm_register_service_internal(uint8_t channel, uint16_t max_frame_size, uint8_t incoming_flow_control, uint8_t initial_credits){    log_info("RFCOMM_REGISTER_SERVICE channel #%u mtu %u flow_control %u credits %u",
2146              channel, max_frame_size, incoming_flow_control, initial_credits);
2147 
2148     // check if already registered
2149     rfcomm_service_t * service = rfcomm_service_for_channel(channel);
2150     if (service){
2151         return RFCOMM_CHANNEL_ALREADY_REGISTERED;
2152     }
2153 
2154     // alloc structure
2155     service = btstack_memory_rfcomm_service_get();
2156     if (!service) {
2157         return BTSTACK_MEMORY_ALLOC_FAILED;
2158     }
2159 
2160     // register with l2cap if not registered before, max MTU
2161     if (linked_list_empty(&rfcomm_services)){
2162         l2cap_register_service(rfcomm_packet_handler, PSM_RFCOMM, 0xffff, rfcomm_security_level);
2163     }
2164 
2165     // fill in
2166     service->server_channel = channel;
2167     service->max_frame_size = max_frame_size;
2168     service->incoming_flow_control = incoming_flow_control;
2169     service->incoming_initial_credits = initial_credits;
2170 
2171     // add to services list
2172     linked_list_add(&rfcomm_services, (linked_item_t *) service);
2173 
2174     return 0;
2175 }
2176 
2177 uint8_t rfcomm_register_service_with_initial_credits(uint8_t channel, uint16_t max_frame_size, uint8_t initial_credits){
2178     return rfcomm_register_service_internal(channel, max_frame_size, 1, initial_credits);
2179 }
2180 
2181 uint8_t rfcomm_register_service(uint8_t channel, uint16_t max_frame_size){
2182     return rfcomm_register_service_internal(channel, max_frame_size, 0,RFCOMM_CREDITS);
2183 }
2184 
2185 void rfcomm_unregister_service(uint8_t service_channel){
2186     log_info("RFCOMM_UNREGISTER_SERVICE #%u", service_channel);
2187     rfcomm_service_t *service = rfcomm_service_for_channel(service_channel);
2188     if (!service) return;
2189     linked_list_remove(&rfcomm_services, (linked_item_t *) service);
2190     btstack_memory_rfcomm_service_free(service);
2191 
2192     // unregister if no services active
2193     if (linked_list_empty(&rfcomm_services)){
2194         // bt_send_cmd(&l2cap_unregister_service, PSM_RFCOMM);
2195         l2cap_unregister_service(PSM_RFCOMM);
2196     }
2197 }
2198 
2199 void rfcomm_accept_connection_internal(uint16_t rfcomm_cid){
2200     log_info("RFCOMM_ACCEPT_CONNECTION cid 0x%02x", rfcomm_cid);
2201     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2202     if (!channel) return;
2203     switch (channel->state) {
2204         case RFCOMM_CHANNEL_INCOMING_SETUP:
2205             rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_CLIENT_ACCEPTED);
2206             if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_RCVD_PN){
2207                 rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP);
2208             }
2209             if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_RCVD_SABM){
2210                 rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_UA);
2211             }
2212             // at least one of { PN RSP, UA } needs to be sent
2213             // state transistion incoming setup -> dlc setup happens in rfcomm_run after these have been sent
2214             break;
2215         default:
2216             break;
2217     }
2218 
2219     // process
2220     rfcomm_run();
2221 }
2222 
2223 void rfcomm_decline_connection_internal(uint16_t rfcomm_cid){
2224     log_info("RFCOMM_DECLINE_CONNECTION cid 0x%02x", rfcomm_cid);
2225     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2226     if (!channel) return;
2227     switch (channel->state) {
2228         case RFCOMM_CHANNEL_INCOMING_SETUP:
2229             channel->state = RFCOMM_CHANNEL_SEND_DM;
2230             break;
2231         default:
2232             break;
2233     }
2234 
2235     // process
2236     rfcomm_run();
2237 }
2238 
2239 void rfcomm_grant_credits(uint16_t rfcomm_cid, uint8_t credits){
2240     log_info("RFCOMM_GRANT_CREDITS cid 0x%02x credits %u", rfcomm_cid, credits);
2241     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2242     if (!channel) return;
2243     if (!channel->incoming_flow_control) return;
2244     channel->new_credits_incoming += credits;
2245 
2246     // process
2247     rfcomm_run();
2248 }
2249 
2250 
2251 
2252 
2253