xref: /btstack/src/classic/rfcomm.c (revision f8fbdce0c5067e7e7edd3a29934b1f9b79c8ff2d)
1 /*
2  * Copyright (C) 2014 BlueKitchen GmbH
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  *
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  * 3. Neither the name of the copyright holders nor the names of
14  *    contributors may be used to endorse or promote products derived
15  *    from this software without specific prior written permission.
16  * 4. Any redistribution, use, or modification is done solely for
17  *    personal benefit and not for any commercial purpose or for
18  *    monetary gain.
19  *
20  * THIS SOFTWARE IS PROVIDED BY BLUEKITCHEN GMBH AND CONTRIBUTORS
21  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
22  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
23  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL MATTHIAS
24  * RINGWALD OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
25  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
26  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
27  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
28  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
29  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
30  * THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  *
33  * Please inquire about commercial licensing options at
34  * [email protected]
35  *
36  */
37 
38 /*
39  *  rfcomm.c
40  */
41 
42 #include <stdio.h>
43 #include <stdlib.h>
44 #include <string.h> // memcpy
45 #include <stdint.h>
46 
47 #include "hci_cmd.h"
48 #include "btstack_util.h"
49 
50 #include "btstack_util.h"
51 #include "btstack_memory.h"
52 #include "hci.h"
53 #include "hci_dump.h"
54 #include "btstack_debug.h"
55 #include "classic/rfcomm.h"
56 
57 // workaround for missing PRIxPTR on mspgcc (16/20-bit MCU)
58 #ifndef PRIxPTR
59 #if defined(__MSP430X__)  &&  defined(__MSP430X_LARGE__)
60 #define PRIxPTR "lx"
61 #else
62 #define PRIxPTR "x"
63 #endif
64 #endif
65 
66 #define RFCOMM_MULIPLEXER_TIMEOUT_MS 60000
67 
68 #define RFCOMM_CREDITS 10
69 
70 // FCS calc
71 #define BT_RFCOMM_CODE_WORD         0xE0 // pol = x8+x2+x1+1
72 #define BT_RFCOMM_CRC_CHECK_LEN     3
73 #define BT_RFCOMM_UIHCRC_CHECK_LEN  2
74 
75 #include "l2cap.h"
76 
77 // global rfcomm data
78 static uint16_t      rfcomm_client_cid_generator;  // used for client channel IDs
79 
80 // linked lists for all
81 static btstack_linked_list_t rfcomm_multiplexers = NULL;
82 static btstack_linked_list_t rfcomm_channels = NULL;
83 static btstack_linked_list_t rfcomm_services = NULL;
84 
85 static gap_security_level_t rfcomm_security_level;
86 
87 static void (*app_packet_handler)(uint8_t packet_type,
88                                   uint16_t channel, uint8_t *packet, uint16_t size);
89 
90 static void rfcomm_run(void);
91 static void rfcomm_channel_state_machine(rfcomm_channel_t *channel, rfcomm_channel_event_t *event);
92 static void rfcomm_channel_state_machine_2(rfcomm_multiplexer_t * multiplexer, uint8_t dlci, rfcomm_channel_event_t *event);
93 static int rfcomm_channel_ready_for_open(rfcomm_channel_t *channel);
94 static void rfcomm_multiplexer_state_machine(rfcomm_multiplexer_t * multiplexer, RFCOMM_MULTIPLEXER_EVENT event);
95 
96 
97 // MARK: RFCOMM CLIENT EVENTS
98 
99 // data: event (8), len(8), address(48), channel (8), rfcomm_cid (16)
100 static void rfcomm_emit_connection_request(rfcomm_channel_t *channel) {
101     log_info("RFCOMM_EVENT_INCOMING_CONNECTION addr %s channel #%u cid 0x%02x",
102              bd_addr_to_str(channel->multiplexer->remote_addr), channel->dlci>>1, channel->rfcomm_cid);
103     uint8_t event[11];
104     event[0] = RFCOMM_EVENT_INCOMING_CONNECTION;
105     event[1] = sizeof(event) - 2;
106     bt_flip_addr(&event[2], channel->multiplexer->remote_addr);
107     event[8] = channel->dlci >> 1;
108     little_endian_store_16(event, 9, channel->rfcomm_cid);
109     hci_dump_packet(HCI_EVENT_PACKET, 0, event, sizeof(event));
110 	(*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) event, sizeof(event));
111 }
112 
113 // API Change: BTstack-0.3.50x uses
114 // data: event(8), len(8), status (8), address (48), server channel(8), rfcomm_cid(16), max frame size(16)
115 // next Cydia release will use SVN version of this
116 // data: event(8), len(8), status (8), address (48), handle (16), server channel(8), rfcomm_cid(16), max frame size(16)
117 static void rfcomm_emit_channel_opened(rfcomm_channel_t *channel, uint8_t status) {
118     log_info("RFCOMM_EVENT_OPEN_CHANNEL_COMPLETE status 0x%x addr %s handle 0x%x channel #%u cid 0x%02x mtu %u",
119              status, bd_addr_to_str(channel->multiplexer->remote_addr), channel->multiplexer->con_handle,
120              channel->dlci>>1, channel->rfcomm_cid, channel->max_frame_size);
121     uint8_t event[16];
122     uint8_t pos = 0;
123     event[pos++] = RFCOMM_EVENT_OPEN_CHANNEL_COMPLETE;  // 0
124     event[pos++] = sizeof(event) - 2;                   // 1
125     event[pos++] = status;                              // 2
126     bt_flip_addr(&event[pos], channel->multiplexer->remote_addr); pos += 6; // 3
127     little_endian_store_16(event,  pos, channel->multiplexer->con_handle);   pos += 2; // 9
128 	event[pos++] = channel->dlci >> 1;                                      // 11
129 	little_endian_store_16(event, pos, channel->rfcomm_cid); pos += 2;                 // 12 - channel ID
130 	little_endian_store_16(event, pos, channel->max_frame_size); pos += 2;   // max frame size
131     hci_dump_packet(HCI_EVENT_PACKET, 0, event, sizeof(event));
132 	(*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) event, pos);
133 }
134 
135 // data: event(8), len(8), rfcomm_cid(16)
136 static void rfcomm_emit_channel_closed(rfcomm_channel_t * channel) {
137     log_info("RFCOMM_EVENT_CHANNEL_CLOSED cid 0x%02x", channel->rfcomm_cid);
138     uint8_t event[4];
139     event[0] = RFCOMM_EVENT_CHANNEL_CLOSED;
140     event[1] = sizeof(event) - 2;
141     little_endian_store_16(event, 2, channel->rfcomm_cid);
142     hci_dump_packet(HCI_EVENT_PACKET, 0, event, sizeof(event));
143 	(*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) event, sizeof(event));
144 }
145 
146 static void rfcomm_emit_remote_line_status(rfcomm_channel_t *channel, uint8_t line_status){
147     log_info("RFCOMM_EVENT_REMOTE_LINE_STATUS cid 0x%02x c, line status 0x%x", channel->rfcomm_cid, line_status);
148     uint8_t event[5];
149     event[0] = RFCOMM_EVENT_REMOTE_LINE_STATUS;
150     event[1] = sizeof(event) - 2;
151     little_endian_store_16(event, 2, channel->rfcomm_cid);
152     event[4] = line_status;
153     hci_dump_packet( HCI_EVENT_PACKET, 0, event, sizeof(event));
154     (*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) event, sizeof(event));
155 }
156 
157 static void rfcomm_emit_port_configuration(rfcomm_channel_t *channel){
158     // notify client about new settings
159     uint8_t event[2+sizeof(rfcomm_rpn_data_t)];
160     event[0] = RFCOMM_EVENT_PORT_CONFIGURATION;
161     event[1] = sizeof(rfcomm_rpn_data_t);
162     memcpy(&event[2], (uint8_t*) &channel->rpn_data, sizeof(rfcomm_rpn_data_t));
163     hci_dump_packet( HCI_EVENT_PACKET, 0, event, sizeof(event));
164     (*app_packet_handler)(HCI_EVENT_PACKET, channel->rfcomm_cid, (uint8_t*)event, sizeof(event));
165 }
166 
167 // MARK RFCOMM RPN DATA HELPER
168 static void rfcomm_rpn_data_set_defaults(rfcomm_rpn_data_t * rpn_data){
169         rpn_data->baud_rate = RPN_BAUD_9600;  /* 9600 bps */
170         rpn_data->flags = 0x03;               /* 8-n-1 */
171         rpn_data->flow_control = 0;           /* no flow control */
172         rpn_data->xon  = 0xd1;                /* XON */
173         rpn_data->xoff = 0xd3;                /* XOFF */
174         rpn_data->parameter_mask_0 = 0x7f;    /* parameter mask, all values set */
175         rpn_data->parameter_mask_1 = 0x3f;    /* parameter mask, all values set */
176 }
177 
178 static void rfcomm_rpn_data_update(rfcomm_rpn_data_t * dest, rfcomm_rpn_data_t * src){
179     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_BAUD){
180         dest->baud_rate = src->baud_rate;
181     }
182     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_DATA_BITS){
183         dest->flags = (dest->flags & 0xfc) | (src->flags & 0x03);
184     }
185     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_STOP_BITS){
186         dest->flags = (dest->flags & 0xfb) | (src->flags & 0x04);
187     }
188     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_PARITY){
189         dest->flags = (dest->flags & 0xf7) | (src->flags & 0x08);
190     }
191     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_PARITY_TYPE){
192         dest->flags = (dest->flags & 0xfc) | (src->flags & 0x30);
193     }
194     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_XON_CHAR){
195         dest->xon = src->xon;
196     }
197     if (src->parameter_mask_0 & RPN_PARAM_MASK_0_XOFF_CHAR){
198         dest->xoff = src->xoff;
199     }
200     int i;
201     for (i=0; i < 6 ; i++){
202         uint8_t mask = 1 << i;
203         if (src->parameter_mask_1 & mask){
204             dest->flags = (dest->flags & ~mask) | (src->flags & mask);
205         }
206     }
207     // always copy parameter mask, too. informative for client, needed for response
208     dest->parameter_mask_0 = src->parameter_mask_0;
209     dest->parameter_mask_1 = src->parameter_mask_1;
210 }
211 // MARK: RFCOMM MULTIPLEXER HELPER
212 
213 static uint16_t rfcomm_max_frame_size_for_l2cap_mtu(uint16_t l2cap_mtu){
214     // Assume RFCOMM header without credits and 2 byte (14 bit) length field
215     uint16_t max_frame_size = l2cap_mtu - 5;
216     log_info("rfcomm_max_frame_size_for_l2cap_mtu:  %u -> %u", l2cap_mtu, max_frame_size);
217     return max_frame_size;
218 }
219 
220 static void rfcomm_multiplexer_initialize(rfcomm_multiplexer_t *multiplexer){
221 
222     memset(multiplexer, 0, sizeof(rfcomm_multiplexer_t));
223 
224     multiplexer->state = RFCOMM_MULTIPLEXER_CLOSED;
225     multiplexer->fcon = 1;
226     multiplexer->send_dm_for_dlci = 0;
227     multiplexer->max_frame_size = rfcomm_max_frame_size_for_l2cap_mtu(l2cap_max_mtu());
228     multiplexer->test_data_len = 0;
229     multiplexer->nsc_command = 0;
230 }
231 
232 static rfcomm_multiplexer_t * rfcomm_multiplexer_create_for_addr(bd_addr_t addr){
233 
234     // alloc structure
235     rfcomm_multiplexer_t * multiplexer = btstack_memory_rfcomm_multiplexer_get();
236     if (!multiplexer) return NULL;
237 
238     // fill in
239     rfcomm_multiplexer_initialize(multiplexer);
240     BD_ADDR_COPY(&multiplexer->remote_addr, addr);
241 
242     // add to services list
243     btstack_linked_list_add(&rfcomm_multiplexers, (btstack_linked_item_t *) multiplexer);
244 
245     return multiplexer;
246 }
247 
248 static rfcomm_multiplexer_t * rfcomm_multiplexer_for_addr(bd_addr_t addr){
249     btstack_linked_item_t *it;
250     for (it = (btstack_linked_item_t *) rfcomm_multiplexers; it ; it = it->next){
251         rfcomm_multiplexer_t * multiplexer = ((rfcomm_multiplexer_t *) it);
252         if (BD_ADDR_CMP(addr, multiplexer->remote_addr) == 0) {
253             return multiplexer;
254         };
255     }
256     return NULL;
257 }
258 
259 static rfcomm_multiplexer_t * rfcomm_multiplexer_for_l2cap_cid(uint16_t l2cap_cid) {
260     btstack_linked_item_t *it;
261     for (it = (btstack_linked_item_t *) rfcomm_multiplexers; it ; it = it->next){
262         rfcomm_multiplexer_t * multiplexer = ((rfcomm_multiplexer_t *) it);
263         if (multiplexer->l2cap_cid == l2cap_cid) {
264             return multiplexer;
265         };
266     }
267     return NULL;
268 }
269 
270 static int rfcomm_multiplexer_has_channels(rfcomm_multiplexer_t * multiplexer){
271     btstack_linked_item_t *it;
272     for (it = (btstack_linked_item_t *) rfcomm_channels; it ; it = it->next){
273         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
274         if (channel->multiplexer == multiplexer) {
275             return 1;
276         }
277     }
278     return 0;
279 }
280 
281 // MARK: RFCOMM CHANNEL HELPER
282 
283 static void rfcomm_dump_channels(void){
284     btstack_linked_item_t * it;
285     int channels = 0;
286     for (it = (btstack_linked_item_t *) rfcomm_channels; it ; it = it->next){
287         rfcomm_channel_t * channel = (rfcomm_channel_t *) it;
288         log_info("Channel #%u: addr %p, state %u", channels, channel, channel->state);
289         channels++;
290     }
291 }
292 
293 static void rfcomm_channel_initialize(rfcomm_channel_t *channel, rfcomm_multiplexer_t *multiplexer,
294                                rfcomm_service_t *service, uint8_t server_channel){
295 
296     // don't use 0 as channel id
297     if (rfcomm_client_cid_generator == 0) ++rfcomm_client_cid_generator;
298 
299     // setup channel
300     memset(channel, 0, sizeof(rfcomm_channel_t));
301 
302     channel->state             = RFCOMM_CHANNEL_CLOSED;
303     channel->state_var         = RFCOMM_CHANNEL_STATE_VAR_NONE;
304 
305     channel->multiplexer      = multiplexer;
306     channel->service          = service;
307     channel->rfcomm_cid       = rfcomm_client_cid_generator++;
308     channel->max_frame_size   = multiplexer->max_frame_size;
309 
310     channel->credits_incoming = 0;
311     channel->credits_outgoing = 0;
312 
313     // set defaults for port configuration (even for services)
314     rfcomm_rpn_data_set_defaults(&channel->rpn_data);
315 
316     // incoming flow control not active
317     channel->new_credits_incoming  =RFCOMM_CREDITS;
318     channel->incoming_flow_control = 0;
319 
320     channel->rls_line_status = RFCOMM_RLS_STATUS_INVALID;
321 
322 	if (service) {
323 		// incoming connection
324 		channel->outgoing = 0;
325 		channel->dlci = (server_channel << 1) |  multiplexer->outgoing;
326         if (channel->max_frame_size > service->max_frame_size) {
327             channel->max_frame_size = service->max_frame_size;
328         }
329         channel->incoming_flow_control = service->incoming_flow_control;
330         channel->new_credits_incoming  = service->incoming_initial_credits;
331 	} else {
332 		// outgoing connection
333 		channel->outgoing = 1;
334 		channel->dlci = (server_channel << 1) | (multiplexer->outgoing ^ 1);
335 
336 	}
337 }
338 
339 // service == NULL -> outgoing channel
340 static rfcomm_channel_t * rfcomm_channel_create(rfcomm_multiplexer_t * multiplexer,
341                                                 rfcomm_service_t * service, uint8_t server_channel){
342 
343     log_info("rfcomm_channel_create for service %p, channel %u --- list of channels:", service, server_channel);
344     rfcomm_dump_channels();
345 
346     // alloc structure
347     rfcomm_channel_t * channel = btstack_memory_rfcomm_channel_get();
348     if (!channel) return NULL;
349 
350     // fill in
351     rfcomm_channel_initialize(channel, multiplexer, service, server_channel);
352 
353     // add to services list
354     btstack_linked_list_add(&rfcomm_channels, (btstack_linked_item_t *) channel);
355 
356     return channel;
357 }
358 
359 static rfcomm_channel_t * rfcomm_channel_for_rfcomm_cid(uint16_t rfcomm_cid){
360     btstack_linked_item_t *it;
361     for (it = (btstack_linked_item_t *) rfcomm_channels; it ; it = it->next){
362         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
363         if (channel->rfcomm_cid == rfcomm_cid) {
364             return channel;
365         };
366     }
367     return NULL;
368 }
369 
370 static rfcomm_channel_t * rfcomm_channel_for_multiplexer_and_dlci(rfcomm_multiplexer_t * multiplexer, uint8_t dlci){
371     btstack_linked_item_t *it;
372     for (it = (btstack_linked_item_t *) rfcomm_channels; it ; it = it->next){
373         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
374         if (channel->dlci == dlci && channel->multiplexer == multiplexer) {
375             return channel;
376         };
377     }
378     return NULL;
379 }
380 
381 static rfcomm_service_t * rfcomm_service_for_channel(uint8_t server_channel){
382     btstack_linked_item_t *it;
383     for (it = (btstack_linked_item_t *) rfcomm_services; it ; it = it->next){
384         rfcomm_service_t * service = ((rfcomm_service_t *) it);
385         if ( service->server_channel == server_channel){
386             return service;
387         };
388     }
389     return NULL;
390 }
391 
392 // MARK: RFCOMM SEND
393 
394 /**
395  * @param credits - only used for RFCOMM flow control in UIH wiht P/F = 1
396  */
397 static int rfcomm_send_packet_for_multiplexer(rfcomm_multiplexer_t *multiplexer, uint8_t address, uint8_t control, uint8_t credits, uint8_t *data, uint16_t len){
398 
399     if (!l2cap_can_send_packet_now(multiplexer->l2cap_cid)) return BTSTACK_ACL_BUFFERS_FULL;
400 
401     l2cap_reserve_packet_buffer();
402     uint8_t * rfcomm_out_buffer = l2cap_get_outgoing_buffer();
403 
404 	uint16_t pos = 0;
405 	uint8_t crc_fields = 3;
406 
407 	rfcomm_out_buffer[pos++] = address;
408 	rfcomm_out_buffer[pos++] = control;
409 
410 	// length field can be 1 or 2 octets
411 	if (len < 128){
412 		rfcomm_out_buffer[pos++] = (len << 1)| 1;     // bits 0-6
413 	} else {
414 		rfcomm_out_buffer[pos++] = (len & 0x7f) << 1; // bits 0-6
415 		rfcomm_out_buffer[pos++] = len >> 7;          // bits 7-14
416 		crc_fields++;
417 	}
418 
419 	// add credits for UIH frames when PF bit is set
420 	if (control == BT_RFCOMM_UIH_PF){
421 		rfcomm_out_buffer[pos++] = credits;
422 	}
423 
424 	// copy actual data
425 	if (len) {
426 		memcpy(&rfcomm_out_buffer[pos], data, len);
427 		pos += len;
428 	}
429 
430 	// UIH frames only calc FCS over address + control (5.1.1)
431 	if ((control & 0xef) == BT_RFCOMM_UIH){
432 		crc_fields = 2;
433 	}
434 	rfcomm_out_buffer[pos++] =  crc8_calc(rfcomm_out_buffer, crc_fields); // calc fcs
435 
436     int err = l2cap_send_prepared(multiplexer->l2cap_cid, pos);
437 
438     return err;
439 }
440 
441 // simplified version of rfcomm_send_packet_for_multiplexer for prepared rfcomm packet (UIH, 2 byte len, no credits)
442 static int rfcomm_send_uih_prepared(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint16_t len){
443 
444     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1) | (dlci << 2);
445     uint8_t control = BT_RFCOMM_UIH;
446 
447     uint8_t * rfcomm_out_buffer = l2cap_get_outgoing_buffer();
448 
449     uint16_t pos = 0;
450     rfcomm_out_buffer[pos++] = address;
451     rfcomm_out_buffer[pos++] = control;
452     rfcomm_out_buffer[pos++] = (len & 0x7f) << 1; // bits 0-6
453     rfcomm_out_buffer[pos++] = len >> 7;          // bits 7-14
454 
455     // actual data is already in place
456     pos += len;
457 
458     // UIH frames only calc FCS over address + control (5.1.1)
459     rfcomm_out_buffer[pos++] =  crc8_calc(rfcomm_out_buffer, 2); // calc fcs
460 
461     int err = l2cap_send_prepared(multiplexer->l2cap_cid, pos);
462 
463     return err;
464 }
465 
466 // C/R Flag in Address
467 // - terms: initiator = station that creates multiplexer with SABM
468 // - terms: responder = station that responds to multiplexer setup with UA
469 // "For SABM, UA, DM and DISC frames C/R bit is set according to Table 1 in GSM 07.10, section 5.2.1.2"
470 //    - command initiator = 1 /response responder = 1
471 //    - command responder = 0 /response initiator = 0
472 // "For UIH frames, the C/R bit is always set according to section 5.4.3.1 in GSM 07.10.
473 //  This applies independently of what is contained wthin the UIH frames, either data or control messages."
474 //    - c/r = 1 for frames by initiating station, 0 = for frames by responding station
475 
476 // C/R Flag in Message
477 // "In the message level, the C/R bit in the command type field is set as stated in section 5.4.6.2 in GSM 07.10."
478 //   - If the C/R bit is set to 1 the message is a command
479 //   - if it is set to 0 the message is a response.
480 
481 // temp/old messge construction
482 
483 // new object oriented version
484 static int rfcomm_send_sabm(rfcomm_multiplexer_t *multiplexer, uint8_t dlci){
485 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1) | (dlci << 2);   // command
486     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_SABM, 0, NULL, 0);
487 }
488 
489 static int rfcomm_send_disc(rfcomm_multiplexer_t *multiplexer, uint8_t dlci){
490 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1) | (dlci << 2);  // command
491     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_DISC, 0, NULL, 0);
492 }
493 
494 static int rfcomm_send_ua(rfcomm_multiplexer_t *multiplexer, uint8_t dlci){
495 	uint8_t address = (1 << 0) | ((multiplexer->outgoing ^ 1) << 1) | (dlci << 2); // response
496     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UA, 0, NULL, 0);
497 }
498 
499 static int rfcomm_send_dm_pf(rfcomm_multiplexer_t *multiplexer, uint8_t dlci){
500 	uint8_t address = (1 << 0) | ((multiplexer->outgoing ^ 1) << 1) | (dlci << 2); // response
501     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_DM_PF, 0, NULL, 0);
502 }
503 
504 static int rfcomm_send_uih_fc_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t fcon) {
505     uint8_t address = (1 << 0) | (multiplexer->outgoing<< 1);
506     uint8_t payload[2];
507     uint8_t pos = 0;
508     payload[pos++] = fcon ? BT_RFCOMM_FCON_RSP : BT_RFCOMM_FCOFF_RSP;
509     payload[pos++] = (0 << 1) | 1;  // len
510     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
511 }
512 
513 // static int rfcomm_send_uih_test_cmd(rfcomm_multiplexer_t *multiplexer, uint8_t * data, uint16_t len) {
514 //     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
515 //     uint8_t payload[2+len];
516 //     uint8_t pos = 0;
517 //     payload[pos++] = BT_RFCOMM_TEST_CMD;
518 //     payload[pos++] = (len + 1) << 1 | 1;  // len
519 //     memcpy(&payload[pos], data, len);
520 //     pos += len;
521 //     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
522 // }
523 
524 static int rfcomm_send_uih_test_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t * data, uint16_t len) {
525     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
526     uint8_t payload[2+RFCOMM_TEST_DATA_MAX_LEN];
527     uint8_t pos = 0;
528     payload[pos++] = BT_RFCOMM_TEST_RSP;
529     if (len > RFCOMM_TEST_DATA_MAX_LEN) {
530         len = RFCOMM_TEST_DATA_MAX_LEN;
531     }
532     payload[pos++] = (len << 1) | 1;  // len
533     memcpy(&payload[pos], data, len);
534     pos += len;
535     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
536 }
537 
538 static int rfcomm_send_uih_msc_cmd(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint8_t signals) {
539 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
540 	uint8_t payload[4];
541 	uint8_t pos = 0;
542 	payload[pos++] = BT_RFCOMM_MSC_CMD;
543 	payload[pos++] = (2 << 1) | 1;  // len
544 	payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
545 	payload[pos++] = signals;
546 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
547 }
548 
549 static int rfcomm_send_uih_msc_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint8_t signals) {
550 	uint8_t address = (1 << 0) | (multiplexer->outgoing<< 1);
551 	uint8_t payload[4];
552 	uint8_t pos = 0;
553 	payload[pos++] = BT_RFCOMM_MSC_RSP;
554 	payload[pos++] = (2 << 1) | 1;  // len
555 	payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
556 	payload[pos++] = signals;
557 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
558 }
559 
560 static int rfcomm_send_uih_nsc_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t command) {
561     uint8_t address = (1 << 0) | (multiplexer->outgoing<< 1);
562     uint8_t payload[3];
563     uint8_t pos = 0;
564     payload[pos++] = BT_RFCOMM_NSC_RSP;
565     payload[pos++] = (1 << 1) | 1;  // len
566     payload[pos++] = command;
567     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
568 }
569 
570 static int rfcomm_send_uih_pn_command(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint16_t max_frame_size){
571 	uint8_t payload[10];
572 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
573 	uint8_t pos = 0;
574 	payload[pos++] = BT_RFCOMM_PN_CMD;
575 	payload[pos++] = (8 << 1) | 1;  // len
576 	payload[pos++] = dlci;
577 	payload[pos++] = 0xf0; // pre-defined for Bluetooth, see 5.5.3 of TS 07.10 Adaption for RFCOMM
578 	payload[pos++] = 0; // priority
579 	payload[pos++] = 0; // max 60 seconds ack
580 	payload[pos++] = max_frame_size & 0xff; // max framesize low
581 	payload[pos++] = max_frame_size >> 8;   // max framesize high
582 	payload[pos++] = 0x00; // number of retransmissions
583 	payload[pos++] = 0x00; // (unused error recovery window) initial number of credits
584 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
585 }
586 
587 // "The response may not change the DLCI, the priority, the convergence layer, or the timer value." rfcomm_tutorial.pdf
588 static int rfcomm_send_uih_pn_response(rfcomm_multiplexer_t *multiplexer, uint8_t dlci,
589                                        uint8_t priority, uint16_t max_frame_size){
590 	uint8_t payload[10];
591 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
592 	uint8_t pos = 0;
593 	payload[pos++] = BT_RFCOMM_PN_RSP;
594 	payload[pos++] = (8 << 1) | 1;  // len
595 	payload[pos++] = dlci;
596 	payload[pos++] = 0xe0; // pre defined for Bluetooth, see 5.5.3 of TS 07.10 Adaption for RFCOMM
597 	payload[pos++] = priority; // priority
598 	payload[pos++] = 0; // max 60 seconds ack
599 	payload[pos++] = max_frame_size & 0xff; // max framesize low
600 	payload[pos++] = max_frame_size >> 8;   // max framesize high
601 	payload[pos++] = 0x00; // number of retransmissions
602 	payload[pos++] = 0x00; // (unused error recovery window) initial number of credits
603 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
604 }
605 
606 static int rfcomm_send_uih_rls_cmd(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint8_t line_status) {
607     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
608     uint8_t payload[4];
609     uint8_t pos = 0;
610     payload[pos++] = BT_RFCOMM_RLS_CMD;
611     payload[pos++] = (2 << 1) | 1;  // len
612     payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
613     payload[pos++] = line_status;
614     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
615 }
616 
617 static int rfcomm_send_uih_rls_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, uint8_t line_status) {
618     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
619     uint8_t payload[4];
620     uint8_t pos = 0;
621     payload[pos++] = BT_RFCOMM_RLS_RSP;
622     payload[pos++] = (2 << 1) | 1;  // len
623     payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
624     payload[pos++] = line_status;
625     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
626 }
627 
628 static int rfcomm_send_uih_rpn_cmd(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, rfcomm_rpn_data_t *rpn_data) {
629     uint8_t payload[10];
630     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
631     uint8_t pos = 0;
632     payload[pos++] = BT_RFCOMM_RPN_CMD;
633     payload[pos++] = (8 << 1) | 1;  // len
634     payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
635     payload[pos++] = rpn_data->baud_rate;
636     payload[pos++] = rpn_data->flags;
637     payload[pos++] = rpn_data->flow_control;
638     payload[pos++] = rpn_data->xon;
639     payload[pos++] = rpn_data->xoff;
640     payload[pos++] = rpn_data->parameter_mask_0;
641     payload[pos++] = rpn_data->parameter_mask_1;
642     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
643 }
644 
645 static int rfcomm_send_uih_rpn_req(rfcomm_multiplexer_t *multiplexer, uint8_t dlci) {
646     uint8_t payload[3];
647     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
648     uint8_t pos = 0;
649     payload[pos++] = BT_RFCOMM_RPN_CMD;
650     payload[pos++] = (1 << 1) | 1;  // len
651     payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
652     return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
653 }
654 
655 static int rfcomm_send_uih_rpn_rsp(rfcomm_multiplexer_t *multiplexer, uint8_t dlci, rfcomm_rpn_data_t *rpn_data) {
656 	uint8_t payload[10];
657 	uint8_t address = (1 << 0) | (multiplexer->outgoing << 1);
658 	uint8_t pos = 0;
659 	payload[pos++] = BT_RFCOMM_RPN_RSP;
660 	payload[pos++] = (8 << 1) | 1;  // len
661 	payload[pos++] = (1 << 0) | (1 << 1) | (dlci << 2); // CMD => C/R = 1
662 	payload[pos++] = rpn_data->baud_rate;
663 	payload[pos++] = rpn_data->flags;
664 	payload[pos++] = rpn_data->flow_control;
665 	payload[pos++] = rpn_data->xon;
666 	payload[pos++] = rpn_data->xoff;
667 	payload[pos++] = rpn_data->parameter_mask_0;
668 	payload[pos++] = rpn_data->parameter_mask_1;
669 	return rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH, 0, (uint8_t *) payload, pos);
670 }
671 
672 static void rfcomm_send_uih_credits(rfcomm_multiplexer_t *multiplexer, uint8_t dlci,  uint8_t credits){
673     uint8_t address = (1 << 0) | (multiplexer->outgoing << 1) |  (dlci << 2);
674     rfcomm_send_packet_for_multiplexer(multiplexer, address, BT_RFCOMM_UIH_PF, credits, NULL, 0);
675 }
676 
677 // MARK: RFCOMM MULTIPLEXER
678 static void rfcomm_multiplexer_stop_timer(rfcomm_multiplexer_t * multiplexer){
679     if (multiplexer->timer_active) {
680         btstack_run_loop_remove_timer(&multiplexer->timer);
681         multiplexer->timer_active = 0;
682     }
683 }
684 static void rfcomm_multiplexer_free(rfcomm_multiplexer_t * multiplexer){
685     btstack_linked_list_remove( &rfcomm_multiplexers, (btstack_linked_item_t *) multiplexer);
686     btstack_memory_rfcomm_multiplexer_free(multiplexer);
687 }
688 
689 static void rfcomm_multiplexer_finalize(rfcomm_multiplexer_t * multiplexer){
690     // remove (potential) timer
691     rfcomm_multiplexer_stop_timer(multiplexer);
692 
693     // close and remove all channels
694     btstack_linked_item_t *it = (btstack_linked_item_t *) &rfcomm_channels;
695     while (it->next){
696         rfcomm_channel_t * channel = (rfcomm_channel_t *) it->next;
697         if (channel->multiplexer == multiplexer) {
698             // emit appropriate events
699             if (channel->state == RFCOMM_CHANNEL_OPEN) {
700                 rfcomm_emit_channel_closed(channel);
701             } else {
702                 rfcomm_emit_channel_opened(channel, RFCOMM_MULTIPLEXER_STOPPED);
703             }
704             // remove from list
705             it->next = it->next->next;
706             // free channel struct
707             btstack_memory_rfcomm_channel_free(channel);
708         } else {
709             it = it->next;
710         }
711     }
712 
713     // remove mutliplexer
714     rfcomm_multiplexer_free(multiplexer);
715 }
716 
717 static void rfcomm_multiplexer_timer_handler(btstack_timer_source_t *timer){
718     rfcomm_multiplexer_t * multiplexer = (rfcomm_multiplexer_t *) btstack_linked_item_get_user( (btstack_linked_item_t *) timer);
719     if (rfcomm_multiplexer_has_channels(multiplexer)) return;
720 
721     log_info("rfcomm_multiplexer_timer_handler timeout: shutting down multiplexer! (no channels)");
722     uint16_t l2cap_cid = multiplexer->l2cap_cid;
723     rfcomm_multiplexer_finalize(multiplexer);
724     l2cap_disconnect(l2cap_cid, 0x13);
725 }
726 
727 static void rfcomm_multiplexer_prepare_idle_timer(rfcomm_multiplexer_t * multiplexer){
728     if (multiplexer->timer_active) {
729         btstack_run_loop_remove_timer(&multiplexer->timer);
730         multiplexer->timer_active = 0;
731     }
732     if (rfcomm_multiplexer_has_channels(multiplexer)) return;
733 
734     // start idle timer for multiplexer timeout check as there are no rfcomm channels yet
735     btstack_run_loop_set_timer(&multiplexer->timer, RFCOMM_MULIPLEXER_TIMEOUT_MS);
736     multiplexer->timer.process = rfcomm_multiplexer_timer_handler;
737     btstack_linked_item_set_user((btstack_linked_item_t*) &multiplexer->timer, multiplexer);
738     btstack_run_loop_add_timer(&multiplexer->timer);
739     multiplexer->timer_active = 1;
740 }
741 
742 static void rfcomm_multiplexer_opened(rfcomm_multiplexer_t *multiplexer){
743     log_info("Multiplexer up and running");
744     multiplexer->state = RFCOMM_MULTIPLEXER_OPEN;
745 
746     rfcomm_channel_event_t event = { CH_EVT_MULTIPLEXER_READY };
747 
748     // transition of channels that wait for multiplexer
749     btstack_linked_item_t *it;
750     for (it = (btstack_linked_item_t *) rfcomm_channels; it ; it = it->next){
751         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
752         if (channel->multiplexer != multiplexer) continue;
753         rfcomm_channel_state_machine(channel, &event);
754     }
755 
756     rfcomm_run();
757     rfcomm_multiplexer_prepare_idle_timer(multiplexer);
758 }
759 
760 
761 /**
762  * @return handled packet
763  */
764 static int rfcomm_multiplexer_hci_event_handler(uint8_t *packet, uint16_t size){
765     bd_addr_t event_addr;
766     uint16_t  psm;
767     uint16_t l2cap_cid;
768     hci_con_handle_t con_handle;
769     rfcomm_multiplexer_t *multiplexer = NULL;
770     uint8_t status;
771 
772     switch (packet[0]) {
773 
774         // accept incoming PSM_RFCOMM connection if no multiplexer exists yet
775         case L2CAP_EVENT_INCOMING_CONNECTION:
776             // data: event(8), len(8), address(48), handle (16),  psm (16), source cid(16) dest cid(16)
777             bt_flip_addr(event_addr, &packet[2]);
778             con_handle = little_endian_read_16(packet,  8);
779             psm        = little_endian_read_16(packet, 10);
780             l2cap_cid  = little_endian_read_16(packet, 12);
781 
782             if (psm != PSM_RFCOMM) break;
783 
784             multiplexer = rfcomm_multiplexer_for_addr(event_addr);
785 
786             if (multiplexer) {
787                 log_info("INCOMING_CONNECTION (l2cap_cid 0x%02x) for PSM_RFCOMM => decline - multiplexer already exists", l2cap_cid);
788                 l2cap_decline_connection(l2cap_cid,  0x04);    // no resources available
789                 return 1;
790             }
791 
792             // create and inititialize new multiplexer instance (incoming)
793             multiplexer = rfcomm_multiplexer_create_for_addr(event_addr);
794             if (!multiplexer){
795                 log_info("INCOMING_CONNECTION (l2cap_cid 0x%02x) for PSM_RFCOMM => decline - no memory left", l2cap_cid);
796                 l2cap_decline_connection(l2cap_cid,  0x04);    // no resources available
797                 return 1;
798             }
799 
800             multiplexer->con_handle = con_handle;
801             multiplexer->l2cap_cid = l2cap_cid;
802             multiplexer->state = RFCOMM_MULTIPLEXER_W4_SABM_0;
803 
804             log_info("L2CAP_EVENT_INCOMING_CONNECTION (l2cap_cid 0x%02x) for PSM_RFCOMM => accept", l2cap_cid);
805             l2cap_accept_connection(l2cap_cid);
806             return 1;
807 
808         // l2cap connection opened -> store l2cap_cid, remote_addr
809         case L2CAP_EVENT_CHANNEL_OPENED:
810 
811             if (little_endian_read_16(packet, 11) != PSM_RFCOMM) break;
812 
813             status = packet[2];
814             log_info("L2CAP_EVENT_CHANNEL_OPENED for PSM_RFCOMM, status %u", status);
815 
816             // get multiplexer for remote addr
817             con_handle = little_endian_read_16(packet, 9);
818             l2cap_cid = little_endian_read_16(packet, 13);
819             bt_flip_addr(event_addr, &packet[3]);
820             multiplexer = rfcomm_multiplexer_for_addr(event_addr);
821             if (!multiplexer) {
822                 log_error("L2CAP_EVENT_CHANNEL_OPENED but no multiplexer prepared");
823                 return 1;
824             }
825 
826             // on l2cap open error discard everything
827             if (status){
828 
829                 // remove (potential) timer
830                 rfcomm_multiplexer_stop_timer(multiplexer);
831 
832                 // emit rfcomm_channel_opened with status and free channel
833                 btstack_linked_item_t * it = (btstack_linked_item_t *) &rfcomm_channels;
834                 while (it->next) {
835                     rfcomm_channel_t * channel = (rfcomm_channel_t *) it->next;
836                     if (channel->multiplexer == multiplexer){
837                         rfcomm_emit_channel_opened(channel, status);
838                         it->next = it->next->next;
839                         btstack_memory_rfcomm_channel_free(channel);
840                     } else {
841                         it = it->next;
842                     }
843                 }
844 
845                 // free multiplexer
846                 rfcomm_multiplexer_free(multiplexer);
847                 return 1;
848             }
849 
850             if (multiplexer->state == RFCOMM_MULTIPLEXER_W4_CONNECT) {
851                 log_info("L2CAP_EVENT_CHANNEL_OPENED: outgoing connection");
852                 // wrong remote addr
853                 if (BD_ADDR_CMP(event_addr, multiplexer->remote_addr)) break;
854                 multiplexer->l2cap_cid = l2cap_cid;
855                 multiplexer->con_handle = con_handle;
856                 // send SABM #0
857                 multiplexer->state = RFCOMM_MULTIPLEXER_SEND_SABM_0;
858             } else { // multiplexer->state == RFCOMM_MULTIPLEXER_W4_SABM_0
859 
860                 // set max frame size based on l2cap MTU
861                 multiplexer->max_frame_size = rfcomm_max_frame_size_for_l2cap_mtu(little_endian_read_16(packet, 17));
862             }
863             return 1;
864 
865             // l2cap disconnect -> state = RFCOMM_MULTIPLEXER_CLOSED;
866 
867         case DAEMON_EVENT_HCI_PACKET_SENT:
868             // testing DMA done code
869             rfcomm_run();
870             break;
871 
872         case L2CAP_EVENT_CHANNEL_CLOSED:
873             // data: event (8), len(8), channel (16)
874             l2cap_cid = little_endian_read_16(packet, 2);
875             multiplexer = rfcomm_multiplexer_for_l2cap_cid(l2cap_cid);
876             log_info("L2CAP_EVENT_CHANNEL_CLOSED cid 0x%0x, mult %p", l2cap_cid, multiplexer);
877             if (!multiplexer) break;
878             log_info("L2CAP_EVENT_CHANNEL_CLOSED state %u", multiplexer->state);
879             switch (multiplexer->state) {
880                 case RFCOMM_MULTIPLEXER_W4_CONNECT:
881                 case RFCOMM_MULTIPLEXER_SEND_SABM_0:
882                 case RFCOMM_MULTIPLEXER_W4_SABM_0:
883                 case RFCOMM_MULTIPLEXER_SEND_UA_0:
884                 case RFCOMM_MULTIPLEXER_W4_UA_0:
885                 case RFCOMM_MULTIPLEXER_OPEN:
886                     // don't call l2cap_disconnect as it's alreay closed
887                     rfcomm_multiplexer_finalize(multiplexer);
888                     return 1;
889                 default:
890                     break;
891             }
892             break;
893         default:
894             break;
895     }
896     return 0;
897 }
898 
899 static int rfcomm_multiplexer_l2cap_packet_handler(uint16_t channel, uint8_t *packet, uint16_t size){
900 
901     // get or create a multiplexer for a certain device
902     rfcomm_multiplexer_t *multiplexer = rfcomm_multiplexer_for_l2cap_cid(channel);
903     if (!multiplexer) return 0;
904 
905     uint16_t l2cap_cid = multiplexer->l2cap_cid;
906 
907 	// but only care for multiplexer control channel
908     uint8_t frame_dlci = packet[0] >> 2;
909     if (frame_dlci) return 0;
910     const uint8_t length_offset = (packet[2] & 1) ^ 1;  // to be used for pos >= 3
911     const uint8_t credit_offset = ((packet[1] & BT_RFCOMM_UIH_PF) == BT_RFCOMM_UIH_PF) ? 1 : 0;   // credits for uih_pf frames
912     const uint8_t payload_offset = 3 + length_offset + credit_offset;
913     switch (packet[1]){
914 
915         case BT_RFCOMM_SABM:
916             if (multiplexer->state == RFCOMM_MULTIPLEXER_W4_SABM_0){
917                 log_info("Received SABM #0");
918                 multiplexer->outgoing = 0;
919                 multiplexer->state = RFCOMM_MULTIPLEXER_SEND_UA_0;
920                 return 1;
921             }
922             break;
923 
924         case BT_RFCOMM_UA:
925             if (multiplexer->state == RFCOMM_MULTIPLEXER_W4_UA_0) {
926                 // UA #0 -> send UA #0, state = RFCOMM_MULTIPLEXER_OPEN
927                 log_info("Received UA #0 ");
928                 rfcomm_multiplexer_opened(multiplexer);
929                 return 1;
930             }
931             break;
932 
933         case BT_RFCOMM_DISC:
934             // DISC #0 -> send UA #0, close multiplexer
935             log_info("Received DISC #0, (ougoing = %u)", multiplexer->outgoing);
936             multiplexer->state = RFCOMM_MULTIPLEXER_SEND_UA_0_AND_DISC;
937             return 1;
938 
939         case BT_RFCOMM_DM:
940             // DM #0 - we shouldn't get this, just give up
941             log_info("Received DM #0");
942             log_info("-> Closing down multiplexer");
943             rfcomm_multiplexer_finalize(multiplexer);
944             l2cap_disconnect(l2cap_cid, 0x13);
945             return 1;
946 
947         case BT_RFCOMM_UIH:
948             if (packet[payload_offset] == BT_RFCOMM_CLD_CMD){
949                 // Multiplexer close down (CLD) -> close mutliplexer
950                 log_info("Received Multiplexer close down command");
951                 log_info("-> Closing down multiplexer");
952                 rfcomm_multiplexer_finalize(multiplexer);
953                 l2cap_disconnect(l2cap_cid, 0x13);
954                 return 1;
955             }
956             switch (packet[payload_offset]){
957                 case BT_RFCOMM_CLD_CMD:
958                      // Multiplexer close down (CLD) -> close mutliplexer
959                     log_info("Received Multiplexer close down command");
960                     log_info("-> Closing down multiplexer");
961                     rfcomm_multiplexer_finalize(multiplexer);
962                     l2cap_disconnect(l2cap_cid, 0x13);
963                     return 1;
964 
965                 case BT_RFCOMM_FCON_CMD:
966                     multiplexer->fcon = 0x81;
967                     break;
968 
969                 case BT_RFCOMM_FCOFF_CMD:
970                     multiplexer->fcon = 0x80;
971                     break;
972 
973                 case BT_RFCOMM_TEST_CMD: {
974                     log_info("Received test command");
975                     int len = packet[payload_offset+1] >> 1; // length < 125
976                     if (len > RFCOMM_TEST_DATA_MAX_LEN){
977                         len = RFCOMM_TEST_DATA_MAX_LEN;
978                     }
979                     multiplexer->test_data_len = len;
980                     memcpy(multiplexer->test_data, &packet[payload_offset + 2], len);
981                     return 1;
982                 }
983                 default:
984                     break;
985             }
986             break;
987 
988         default:
989             break;
990 
991     }
992     return 0;
993 }
994 
995 static void rfcomm_multiplexer_state_machine(rfcomm_multiplexer_t * multiplexer, RFCOMM_MULTIPLEXER_EVENT event){
996 
997     uint16_t l2cap_cid = multiplexer->l2cap_cid;
998 
999     // process stored DM responses
1000     if (multiplexer->send_dm_for_dlci){
1001         uint8_t dlci = multiplexer->send_dm_for_dlci;
1002         multiplexer->send_dm_for_dlci = 0;
1003         rfcomm_send_dm_pf(multiplexer, dlci);
1004         return;
1005     }
1006 
1007     if (multiplexer->nsc_command){
1008         uint8_t command = multiplexer->nsc_command;
1009         multiplexer->nsc_command = 0;
1010         rfcomm_send_uih_nsc_rsp(multiplexer, command);
1011         return;
1012     }
1013 
1014     if (multiplexer->fcon & 0x80){
1015         multiplexer->fcon &= 0x01;
1016         rfcomm_send_uih_fc_rsp(multiplexer, multiplexer->fcon);
1017         if (multiplexer->fcon == 0) return;
1018         // trigger client to send again after sending FCon Response
1019         uint8_t packet_sent_event[] = { DAEMON_EVENT_HCI_PACKET_SENT, 0};
1020         btstack_linked_item_t *it;
1021         for (it = (btstack_linked_item_t *) rfcomm_channels; it ; it = it->next){
1022             rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
1023             if (channel->multiplexer != multiplexer) continue;
1024             (*app_packet_handler)(HCI_EVENT_PACKET, 0, (uint8_t *) packet_sent_event, sizeof(packet_sent_event));
1025         }
1026         return;
1027     }
1028 
1029     switch (multiplexer->state) {
1030         case RFCOMM_MULTIPLEXER_SEND_SABM_0:
1031             switch (event) {
1032                 case MULT_EV_READY_TO_SEND:
1033                     log_info("Sending SABM #0 - (multi 0x%p)", multiplexer);
1034                     multiplexer->state = RFCOMM_MULTIPLEXER_W4_UA_0;
1035                     rfcomm_send_sabm(multiplexer, 0);
1036                     break;
1037                 default:
1038                     break;
1039             }
1040             break;
1041         case RFCOMM_MULTIPLEXER_SEND_UA_0:
1042             switch (event) {
1043                 case MULT_EV_READY_TO_SEND:
1044                     log_info("Sending UA #0");
1045                     multiplexer->state = RFCOMM_MULTIPLEXER_OPEN;
1046                     rfcomm_send_ua(multiplexer, 0);
1047                     rfcomm_multiplexer_opened(multiplexer);
1048                     break;
1049                 default:
1050                     break;
1051             }
1052             break;
1053         case RFCOMM_MULTIPLEXER_SEND_UA_0_AND_DISC:
1054             switch (event) {
1055                 case MULT_EV_READY_TO_SEND:
1056                     // try to detect authentication errors: drop link key if multiplexer closed before first channel got opened
1057                     if (!multiplexer->at_least_one_connection){
1058                         log_info("TODO: no connections established - delete link key prophylactically");
1059                         // hci_send_cmd(&hci_delete_stored_link_key, multiplexer->remote_addr);
1060                     }
1061                     log_info("Sending UA #0");
1062                     log_info("Closing down multiplexer");
1063                     multiplexer->state = RFCOMM_MULTIPLEXER_CLOSED;
1064                     rfcomm_send_ua(multiplexer, 0);
1065                     rfcomm_multiplexer_finalize(multiplexer);
1066                     l2cap_disconnect(l2cap_cid, 0x13);
1067                 default:
1068                     break;
1069             }
1070             break;
1071         case RFCOMM_MULTIPLEXER_OPEN:
1072             switch (event) {
1073                 case MULT_EV_READY_TO_SEND:
1074                     // respond to test command
1075                     if (multiplexer->test_data_len){
1076                         int len = multiplexer->test_data_len;
1077                         log_info("Sending TEST Response with %u bytes", len);
1078                         multiplexer->test_data_len = 0;
1079                         rfcomm_send_uih_test_rsp(multiplexer, multiplexer->test_data, len);
1080                         return;
1081                     }
1082                     break;
1083                 default:
1084                     break;
1085             }
1086             break;
1087         default:
1088             break;
1089     }
1090 }
1091 
1092 // MARK: RFCOMM CHANNEL
1093 
1094 static void rfcomm_channel_send_credits(rfcomm_channel_t *channel, uint8_t credits){
1095     rfcomm_send_uih_credits(channel->multiplexer, channel->dlci, credits);
1096     channel->credits_incoming += credits;
1097 }
1098 
1099 static void rfcomm_channel_opened(rfcomm_channel_t *rfChannel){
1100 
1101     log_info("rfcomm_channel_opened!");
1102 
1103     rfChannel->state = RFCOMM_CHANNEL_OPEN;
1104     rfcomm_emit_channel_opened(rfChannel, 0);
1105     rfcomm_emit_port_configuration(rfChannel);
1106 
1107     // remove (potential) timer
1108     rfcomm_multiplexer_t *multiplexer = rfChannel->multiplexer;
1109     if (multiplexer->timer_active) {
1110         btstack_run_loop_remove_timer(&multiplexer->timer);
1111         multiplexer->timer_active = 0;
1112     }
1113     // hack for problem detecting authentication failure
1114     multiplexer->at_least_one_connection = 1;
1115 
1116     // start next connection request if pending
1117     rfcomm_run();
1118 }
1119 
1120 static void rfcomm_channel_packet_handler_uih(rfcomm_multiplexer_t *multiplexer, uint8_t * packet, uint16_t size){
1121     const uint8_t frame_dlci = packet[0] >> 2;
1122     const uint8_t length_offset = (packet[2] & 1) ^ 1;  // to be used for pos >= 3
1123     const uint8_t credit_offset = ((packet[1] & BT_RFCOMM_UIH_PF) == BT_RFCOMM_UIH_PF) ? 1 : 0;   // credits for uih_pf frames
1124     const uint8_t payload_offset = 3 + length_offset + credit_offset;
1125 
1126     rfcomm_channel_t * channel = rfcomm_channel_for_multiplexer_and_dlci(multiplexer, frame_dlci);
1127     if (!channel) return;
1128 
1129     // handle new outgoing credits
1130     if (packet[1] == BT_RFCOMM_UIH_PF) {
1131 
1132         // add them
1133         uint16_t new_credits = packet[3+length_offset];
1134         channel->credits_outgoing += new_credits;
1135         log_info( "RFCOMM data UIH_PF, new credits: %u, now %u", new_credits, channel->credits_outgoing);
1136 
1137         // notify channel statemachine
1138         rfcomm_channel_event_t channel_event = { CH_EVT_RCVD_CREDITS };
1139         rfcomm_channel_state_machine(channel, &channel_event);
1140     }
1141 
1142     // contains payload?
1143     if (size - 1 > payload_offset){
1144 
1145         // log_info( "RFCOMM data UIH_PF, size %u, channel %p", size-payload_offset-1, rfChannel->connection);
1146 
1147         // decrease incoming credit counter
1148         if (channel->credits_incoming > 0){
1149             channel->credits_incoming--;
1150         }
1151 
1152         // deliver payload
1153         (*app_packet_handler)(RFCOMM_DATA_PACKET, channel->rfcomm_cid,
1154                               &packet[payload_offset], size-payload_offset-1);
1155     }
1156 
1157     // automatically provide new credits to remote device, if no incoming flow control
1158     if (!channel->incoming_flow_control && channel->credits_incoming < 5){
1159         channel->new_credits_incoming =RFCOMM_CREDITS;
1160     }
1161 }
1162 
1163 static void rfcomm_channel_accept_pn(rfcomm_channel_t *channel, rfcomm_channel_event_pn_t *event){
1164     // priority of client request
1165     channel->pn_priority = event->priority;
1166 
1167     // new credits
1168     channel->credits_outgoing = event->credits_outgoing;
1169 
1170     // negotiate max frame size
1171     if (channel->max_frame_size > channel->multiplexer->max_frame_size) {
1172         channel->max_frame_size = channel->multiplexer->max_frame_size;
1173     }
1174     if (channel->max_frame_size > event->max_frame_size) {
1175         channel->max_frame_size = event->max_frame_size;
1176     }
1177 
1178 }
1179 
1180 static void rfcomm_channel_finalize(rfcomm_channel_t *channel){
1181 
1182     rfcomm_multiplexer_t *multiplexer = channel->multiplexer;
1183 
1184     // remove from list
1185     btstack_linked_list_remove( &rfcomm_channels, (btstack_linked_item_t *) channel);
1186 
1187     // free channel
1188     btstack_memory_rfcomm_channel_free(channel);
1189 
1190     // update multiplexer timeout after channel was removed from list
1191     rfcomm_multiplexer_prepare_idle_timer(multiplexer);
1192 }
1193 
1194 static void rfcomm_channel_state_machine_2(rfcomm_multiplexer_t * multiplexer, uint8_t dlci, rfcomm_channel_event_t *event){
1195 
1196     // TODO: if client max frame size is smaller than RFCOMM_DEFAULT_SIZE, send PN
1197 
1198 
1199     // lookup existing channel
1200     rfcomm_channel_t * channel = rfcomm_channel_for_multiplexer_and_dlci(multiplexer, dlci);
1201 
1202     // log_info("rfcomm_channel_state_machine_2 lookup dlci #%u = 0x%08x - event %u", dlci, (int) channel, event->type);
1203 
1204     if (channel) {
1205         rfcomm_channel_state_machine(channel, event);
1206         return;
1207     }
1208 
1209     // service registered?
1210     rfcomm_service_t * service = rfcomm_service_for_channel(dlci >> 1);
1211     // log_info("rfcomm_channel_state_machine_2 service dlci #%u = 0x%08x", dlci, (int) service);
1212     if (!service) {
1213         // discard request by sending disconnected mode
1214         multiplexer->send_dm_for_dlci = dlci;
1215         return;
1216     }
1217 
1218     // create channel for some events
1219     switch (event->type) {
1220         case CH_EVT_RCVD_SABM:
1221         case CH_EVT_RCVD_PN:
1222         case CH_EVT_RCVD_RPN_REQ:
1223         case CH_EVT_RCVD_RPN_CMD:
1224             // setup incoming channel
1225             channel = rfcomm_channel_create(multiplexer, service, dlci >> 1);
1226             if (!channel){
1227                 // discard request by sending disconnected mode
1228                 multiplexer->send_dm_for_dlci = dlci;
1229             }
1230             break;
1231         default:
1232             break;
1233     }
1234 
1235     if (!channel) {
1236         // discard request by sending disconnected mode
1237         multiplexer->send_dm_for_dlci = dlci;
1238         return;
1239     }
1240     rfcomm_channel_state_machine(channel, event);
1241 }
1242 
1243 static void rfcomm_channel_packet_handler(rfcomm_multiplexer_t * multiplexer,  uint8_t *packet, uint16_t size){
1244 
1245     // rfcomm: (0) addr [76543 server channel] [2 direction: initiator uses 1] [1 C/R: CMD by initiator = 1] [0 EA=1]
1246     const uint8_t frame_dlci = packet[0] >> 2;
1247     uint8_t message_dlci; // used by commands in UIH(_PF) packets
1248 	uint8_t message_len;  //   "
1249 
1250     // rfcomm: (1) command/control
1251     // -- credits_offset = 1 if command == BT_RFCOMM_UIH_PF
1252     const uint8_t credit_offset = ((packet[1] & BT_RFCOMM_UIH_PF) == BT_RFCOMM_UIH_PF) ? 1 : 0;   // credits for uih_pf frames
1253     // rfcomm: (2) length. if bit 0 is cleared, 2 byte length is used. (little endian)
1254     const uint8_t length_offset = (packet[2] & 1) ^ 1;  // to be used for pos >= 3
1255     // rfcomm: (3+length_offset) credits if credits_offset == 1
1256     // rfcomm: (3+length_offest+credits_offset)
1257     const uint8_t payload_offset = 3 + length_offset + credit_offset;
1258 
1259     rfcomm_channel_event_t event;
1260     rfcomm_channel_event_pn_t event_pn;
1261     rfcomm_channel_event_rpn_t event_rpn;
1262     rfcomm_channel_event_msc_t event_msc;
1263 
1264     // switch by rfcomm message type
1265     switch(packet[1]) {
1266 
1267         case BT_RFCOMM_SABM:
1268             event.type = CH_EVT_RCVD_SABM;
1269             log_info("Received SABM #%u", frame_dlci);
1270             rfcomm_channel_state_machine_2(multiplexer, frame_dlci, &event);
1271             break;
1272 
1273         case BT_RFCOMM_UA:
1274             event.type = CH_EVT_RCVD_UA;
1275             log_info("Received UA #%u",frame_dlci);
1276             rfcomm_channel_state_machine_2(multiplexer, frame_dlci, &event);
1277             break;
1278 
1279         case BT_RFCOMM_DISC:
1280             event.type = CH_EVT_RCVD_DISC;
1281             rfcomm_channel_state_machine_2(multiplexer, frame_dlci, &event);
1282             break;
1283 
1284         case BT_RFCOMM_DM:
1285         case BT_RFCOMM_DM_PF:
1286             event.type = CH_EVT_RCVD_DM;
1287             rfcomm_channel_state_machine_2(multiplexer, frame_dlci, &event);
1288             break;
1289 
1290         case BT_RFCOMM_UIH_PF:
1291         case BT_RFCOMM_UIH:
1292 
1293             message_len  = packet[payload_offset+1] >> 1;
1294 
1295             switch (packet[payload_offset]) {
1296                 case BT_RFCOMM_PN_CMD:
1297                     message_dlci = packet[payload_offset+2];
1298                     event_pn.super.type = CH_EVT_RCVD_PN;
1299                     event_pn.priority = packet[payload_offset+4];
1300                     event_pn.max_frame_size = little_endian_read_16(packet, payload_offset+6);
1301                     event_pn.credits_outgoing = packet[payload_offset+9];
1302                     log_info("Received UIH Parameter Negotiation Command for #%u, credits %u",
1303                         message_dlci, event_pn.credits_outgoing);
1304                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_pn);
1305                     break;
1306 
1307                 case BT_RFCOMM_PN_RSP:
1308                     message_dlci = packet[payload_offset+2];
1309                     event_pn.super.type = CH_EVT_RCVD_PN_RSP;
1310                     event_pn.priority = packet[payload_offset+4];
1311                     event_pn.max_frame_size = little_endian_read_16(packet, payload_offset+6);
1312                     event_pn.credits_outgoing = packet[payload_offset+9];
1313                     log_info("Received UIH Parameter Negotiation Response max frame %u, credits %u",
1314                             event_pn.max_frame_size, event_pn.credits_outgoing);
1315                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_pn);
1316                     break;
1317 
1318                 case BT_RFCOMM_MSC_CMD:
1319                     message_dlci = packet[payload_offset+2] >> 2;
1320                     event_msc.super.type = CH_EVT_RCVD_MSC_CMD;
1321                     event_msc.modem_status = packet[payload_offset+3];
1322                     log_info("Received MSC CMD for #%u, ", message_dlci);
1323                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_msc);
1324                     break;
1325 
1326                 case BT_RFCOMM_MSC_RSP:
1327                     message_dlci = packet[payload_offset+2] >> 2;
1328                     event.type = CH_EVT_RCVD_MSC_RSP;
1329                     log_info("Received MSC RSP for #%u", message_dlci);
1330                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, &event);
1331                     break;
1332 
1333                 case BT_RFCOMM_RPN_CMD:
1334                     message_dlci = packet[payload_offset+2] >> 2;
1335                     switch (message_len){
1336                         case 1:
1337                             log_info("Received Remote Port Negotiation Request for #%u", message_dlci);
1338                             event.type = CH_EVT_RCVD_RPN_REQ;
1339                             rfcomm_channel_state_machine_2(multiplexer, message_dlci, &event);
1340                             break;
1341                         case 8:
1342                             log_info("Received Remote Port Negotiation Update for #%u", message_dlci);
1343                             event_rpn.super.type = CH_EVT_RCVD_RPN_CMD;
1344                             event_rpn.data = *(rfcomm_rpn_data_t*) &packet[payload_offset+3];
1345                             rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_rpn);
1346                             break;
1347                         default:
1348                             break;
1349                     }
1350                     break;
1351 
1352                 case BT_RFCOMM_RPN_RSP:
1353                     log_info("Received RPN response");
1354                     break;
1355 
1356                 case BT_RFCOMM_RLS_CMD: {
1357                     log_info("Received RLS command");
1358                     message_dlci = packet[payload_offset+2] >> 2;
1359                     rfcomm_channel_event_rls_t event_rls;
1360                     event_rls.super.type = CH_EVT_RCVD_RLS_CMD;
1361                     event_rls.line_status = packet[payload_offset+3];
1362                     rfcomm_channel_state_machine_2(multiplexer, message_dlci, (rfcomm_channel_event_t*) &event_rls);
1363                     break;
1364                 }
1365 
1366                 case BT_RFCOMM_RLS_RSP:
1367                     log_info("Received RLS response");
1368                     break;
1369 
1370                 // Following commands are handled by rfcomm_multiplexer_l2cap_packet_handler
1371                 // case BT_RFCOMM_TEST_CMD:
1372                 // case BT_RFCOMM_FCOFF_CMD:
1373                 // case BT_RFCOMM_FCON_CMD:
1374                 // everything else is an not supported command
1375                 default: {
1376                     log_error("Received unknown UIH command packet - 0x%02x", packet[payload_offset]);
1377                     multiplexer->nsc_command = packet[payload_offset];
1378                     break;
1379                 }
1380             }
1381             break;
1382 
1383         default:
1384             log_error("Received unknown RFCOMM message type %x", packet[1]);
1385             break;
1386     }
1387 
1388     // trigger next action - example W4_PN_RSP: transition to SEND_SABM which only depends on "can send"
1389     rfcomm_run();
1390 }
1391 
1392 static void rfcomm_packet_handler(uint8_t packet_type, uint16_t channel, uint8_t *packet, uint16_t size){
1393 
1394     // multiplexer handler
1395     int handled = 0;
1396     switch (packet_type) {
1397         case HCI_EVENT_PACKET:
1398             handled = rfcomm_multiplexer_hci_event_handler(packet, size);
1399             break;
1400         case L2CAP_DATA_PACKET:
1401             handled = rfcomm_multiplexer_l2cap_packet_handler(channel, packet, size);
1402             break;
1403         default:
1404             break;
1405     }
1406 
1407     if (handled) {
1408         rfcomm_run();
1409         return;
1410     }
1411 
1412     // we only handle l2cap packet over open multiplexer channel now
1413     if (packet_type != L2CAP_DATA_PACKET) {
1414         (*app_packet_handler)(packet_type, channel, packet, size);
1415         return;
1416     }
1417     rfcomm_multiplexer_t * multiplexer = rfcomm_multiplexer_for_l2cap_cid(channel);
1418     if (!multiplexer || multiplexer->state != RFCOMM_MULTIPLEXER_OPEN) {
1419         (*app_packet_handler)(packet_type, channel, packet, size);
1420         return;
1421     }
1422 
1423     // channel data ?
1424     // rfcomm: (0) addr [76543 server channel] [2 direction: initiator uses 1] [1 C/R: CMD by initiator = 1] [0 EA=1]
1425     const uint8_t frame_dlci = packet[0] >> 2;
1426 
1427     if (frame_dlci && (packet[1] == BT_RFCOMM_UIH || packet[1] == BT_RFCOMM_UIH_PF)) {
1428         rfcomm_channel_packet_handler_uih(multiplexer, packet, size);
1429         rfcomm_run();
1430         return;
1431     }
1432 
1433     rfcomm_channel_packet_handler(multiplexer, packet, size);
1434 }
1435 
1436 static int rfcomm_channel_ready_for_open(rfcomm_channel_t *channel){
1437     // note: exchanging MSC isn't neccessary to consider channel open
1438     // note: having outgoing credits is also not necessary to consider channel open
1439     // log_info("rfcomm_channel_ready_for_open state %u, flags needed %04x, current %04x, rf credits %u, l2cap credits %u ", channel->state, RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_RSP|RFCOMM_CHANNEL_STATE_VAR_SENT_MSC_RSP|RFCOMM_CHANNEL_STATE_VAR_SENT_CREDITS, channel->state_var, channel->credits_outgoing, channel->multiplexer->l2cap_credits);
1440     // if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SENT_MSC_RSP) == 0) return 0;
1441     // if (channel->credits_outgoing == 0) return 0;
1442     log_info("rfcomm_channel_ready_for_open state %u, flags needed %04x, current %04x, rf credits %u",
1443          channel->state, RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_RSP, channel->state_var, channel->credits_outgoing);
1444     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_RSP) == 0) return 0;
1445     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SENT_CREDITS) == 0) return 0;
1446 
1447     return 1;
1448 }
1449 
1450 static int rfcomm_channel_ready_for_incoming_dlc_setup(rfcomm_channel_t * channel){
1451     log_info("rfcomm_channel_ready_for_incoming_dlc_setup state var %04x", channel->state_var);
1452     // Client accept and SABM/UA is required, PN RSP is needed if PN was received
1453     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_CLIENT_ACCEPTED) == 0) return 0;
1454     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_RCVD_SABM      ) == 0) return 0;
1455     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_UA        ) != 0) return 0;
1456     if ((channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP    ) != 0) return 0;
1457     return 1;
1458 }
1459 
1460 inline static void rfcomm_channel_state_add(rfcomm_channel_t *channel, RFCOMM_CHANNEL_STATE_VAR event){
1461     channel->state_var = (RFCOMM_CHANNEL_STATE_VAR) (channel->state_var | event);
1462 }
1463 inline static void rfcomm_channel_state_remove(rfcomm_channel_t *channel, RFCOMM_CHANNEL_STATE_VAR event){
1464     channel->state_var = (RFCOMM_CHANNEL_STATE_VAR) (channel->state_var & ~event);
1465 }
1466 
1467 static void rfcomm_channel_state_machine(rfcomm_channel_t *channel, rfcomm_channel_event_t *event){
1468 
1469     // log_info("rfcomm_channel_state_machine: state %u, state_var %04x, event %u", channel->state, channel->state_var ,event->type);
1470 
1471     rfcomm_multiplexer_t *multiplexer = channel->multiplexer;
1472 
1473     // TODO: integrate in common switch
1474     if (event->type == CH_EVT_RCVD_DISC){
1475         rfcomm_emit_channel_closed(channel);
1476         channel->state = RFCOMM_CHANNEL_SEND_UA_AFTER_DISC;
1477         return;
1478     }
1479 
1480     // TODO: integrate in common switch
1481     if (event->type == CH_EVT_RCVD_DM){
1482         log_info("Received DM message for #%u", channel->dlci);
1483         log_info("-> Closing channel locally for #%u", channel->dlci);
1484         rfcomm_emit_channel_closed(channel);
1485         rfcomm_channel_finalize(channel);
1486         return;
1487     }
1488 
1489     // remote port negotiation command - just accept everything for now
1490     //
1491     // "The RPN command can be used before a new DLC is opened and should be used whenever the port settings change."
1492     // "The RPN command is specified as optional in TS 07.10, but it is mandatory to recognize and respond to it in RFCOMM.
1493     //   (Although the handling of individual settings are implementation-dependent.)"
1494     //
1495 
1496     // TODO: integrate in common switch
1497     if (event->type == CH_EVT_RCVD_RPN_CMD){
1498         // control port parameters
1499         rfcomm_channel_event_rpn_t *event_rpn = (rfcomm_channel_event_rpn_t*) event;
1500         rfcomm_rpn_data_update(&channel->rpn_data, &event_rpn->data);
1501         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_RPN_RSP);
1502         // notify client about new settings
1503         rfcomm_emit_port_configuration(channel);
1504         return;
1505     }
1506 
1507     // TODO: integrate in common switch
1508     if (event->type == CH_EVT_RCVD_RPN_REQ){
1509         // no values got accepted (no values have beens sent)
1510         channel->rpn_data.parameter_mask_0 = 0x00;
1511         channel->rpn_data.parameter_mask_1 = 0x00;
1512         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_RPN_RSP);
1513         return;
1514     }
1515 
1516     if (event->type == CH_EVT_RCVD_RLS_CMD){
1517         rfcomm_channel_event_rls_t * event_rls = (rfcomm_channel_event_rls_t*) event;
1518         channel->rls_line_status = event_rls->line_status & 0x0f;
1519         log_info("CH_EVT_RCVD_RLS_CMD setting line status to 0x%0x", channel->rls_line_status);
1520         rfcomm_emit_remote_line_status(channel, event_rls->line_status);
1521         return;
1522     }
1523 
1524     // TODO: integrate in common swich
1525     if (event->type == CH_EVT_READY_TO_SEND){
1526         if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_RPN_RSP){
1527             log_info("Sending Remote Port Negotiation RSP for #%u", channel->dlci);
1528             rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_RPN_RSP);
1529             rfcomm_send_uih_rpn_rsp(multiplexer, channel->dlci, &channel->rpn_data);
1530             return;
1531         }
1532         if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_RSP){
1533             log_info("Sending MSC RSP for #%u", channel->dlci);
1534             rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_RSP);
1535             rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SENT_MSC_RSP);
1536             rfcomm_send_uih_msc_rsp(multiplexer, channel->dlci, 0x8d);  // ea=1,fc=0,rtc=1,rtr=1,ic=0,dv=1
1537             return;
1538         }
1539         if (channel->rls_line_status != RFCOMM_RLS_STATUS_INVALID){
1540             log_info("Sending RLS RSP 0x%0x", channel->rls_line_status);
1541             uint8_t line_status = channel->rls_line_status;
1542             channel->rls_line_status = RFCOMM_RLS_STATUS_INVALID;
1543             rfcomm_send_uih_rls_rsp(multiplexer, channel->dlci, line_status);
1544             return;
1545         }
1546     }
1547 
1548     // emit MSC status to app
1549     if (event->type == CH_EVT_RCVD_MSC_CMD){
1550         // notify client about new settings
1551         rfcomm_channel_event_msc_t *event_msc = (rfcomm_channel_event_msc_t*) event;
1552         uint8_t modem_status_event[2+1];
1553         modem_status_event[0] = RFCOMM_EVENT_REMOTE_MODEM_STATUS;
1554         modem_status_event[1] = 1;
1555         modem_status_event[2] = event_msc->modem_status;
1556         (*app_packet_handler)(HCI_EVENT_PACKET, channel->rfcomm_cid, (uint8_t*)&modem_status_event, sizeof(modem_status_event));
1557         // no return, MSC_CMD will be handled by state machine below
1558     }
1559 
1560     rfcomm_channel_event_pn_t * event_pn = (rfcomm_channel_event_pn_t*) event;
1561 
1562     switch (channel->state) {
1563         case RFCOMM_CHANNEL_CLOSED:
1564             switch (event->type){
1565                 case CH_EVT_RCVD_SABM:
1566                     log_info("-> Inform app");
1567                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_SABM);
1568                     channel->state = RFCOMM_CHANNEL_INCOMING_SETUP;
1569                     rfcomm_emit_connection_request(channel);
1570                     break;
1571                 case CH_EVT_RCVD_PN:
1572                     rfcomm_channel_accept_pn(channel, event_pn);
1573                     log_info("-> Inform app");
1574                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_PN);
1575                     channel->state = RFCOMM_CHANNEL_INCOMING_SETUP;
1576                     rfcomm_emit_connection_request(channel);
1577                     break;
1578                 default:
1579                     break;
1580             }
1581             break;
1582 
1583         case RFCOMM_CHANNEL_INCOMING_SETUP:
1584             switch (event->type){
1585                 case CH_EVT_RCVD_SABM:
1586                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_SABM);
1587                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_CLIENT_ACCEPTED) {
1588                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_UA);
1589                     }
1590                     break;
1591                 case CH_EVT_RCVD_PN:
1592                     rfcomm_channel_accept_pn(channel, event_pn);
1593                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_PN);
1594                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_CLIENT_ACCEPTED) {
1595                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP);
1596                     }
1597                     break;
1598                 case CH_EVT_READY_TO_SEND:
1599                     // if / else if is used to check for state transition after sending
1600                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP){
1601                         log_info("Sending UIH Parameter Negotiation Respond for #%u", channel->dlci);
1602                         rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP);
1603                         rfcomm_send_uih_pn_response(multiplexer, channel->dlci, channel->pn_priority, channel->max_frame_size);
1604                     } else if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_UA){
1605                         log_info("Sending UA #%u", channel->dlci);
1606                         rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_UA);
1607                         rfcomm_send_ua(multiplexer, channel->dlci);
1608                     }
1609                     if (rfcomm_channel_ready_for_incoming_dlc_setup(channel)){
1610                         log_info("Incomping setup done, requesting send MSC CMD and send Credits");
1611                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_CMD);
1612                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_CREDITS);
1613                         channel->state = RFCOMM_CHANNEL_DLC_SETUP;
1614                     }
1615                     break;
1616                 default:
1617                     break;
1618             }
1619             break;
1620 
1621         case RFCOMM_CHANNEL_W4_MULTIPLEXER:
1622             switch (event->type) {
1623                 case CH_EVT_MULTIPLEXER_READY:
1624                     log_info("Muliplexer opened, sending UIH PN next");
1625                     channel->state = RFCOMM_CHANNEL_SEND_UIH_PN;
1626                     break;
1627                 default:
1628                     break;
1629             }
1630             break;
1631 
1632         case RFCOMM_CHANNEL_SEND_UIH_PN:
1633             switch (event->type) {
1634                 case CH_EVT_READY_TO_SEND:
1635                     log_info("Sending UIH Parameter Negotiation Command for #%u (channel 0x%p)", channel->dlci, channel );
1636                     channel->state = RFCOMM_CHANNEL_W4_PN_RSP;
1637                     rfcomm_send_uih_pn_command(multiplexer, channel->dlci, channel->max_frame_size);
1638                     break;
1639                 default:
1640                     break;
1641             }
1642             break;
1643 
1644         case RFCOMM_CHANNEL_W4_PN_RSP:
1645             switch (event->type){
1646                 case CH_EVT_RCVD_PN_RSP:
1647                     // update max frame size
1648                     if (channel->max_frame_size > event_pn->max_frame_size) {
1649                         channel->max_frame_size = event_pn->max_frame_size;
1650                     }
1651                     // new credits
1652                     channel->credits_outgoing = event_pn->credits_outgoing;
1653                     channel->state = RFCOMM_CHANNEL_SEND_SABM_W4_UA;
1654                     break;
1655                 default:
1656                     break;
1657             }
1658             break;
1659 
1660         case RFCOMM_CHANNEL_SEND_SABM_W4_UA:
1661             switch (event->type) {
1662                 case CH_EVT_READY_TO_SEND:
1663                     log_info("Sending SABM #%u", channel->dlci);
1664                     channel->state = RFCOMM_CHANNEL_W4_UA;
1665                     rfcomm_send_sabm(multiplexer, channel->dlci);
1666                     break;
1667                 default:
1668                     break;
1669             }
1670             break;
1671 
1672         case RFCOMM_CHANNEL_W4_UA:
1673             switch (event->type){
1674                 case CH_EVT_RCVD_UA:
1675                     channel->state = RFCOMM_CHANNEL_DLC_SETUP;
1676                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_CMD);
1677                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_CREDITS);
1678                     break;
1679                 default:
1680                     break;
1681             }
1682             break;
1683 
1684         case RFCOMM_CHANNEL_DLC_SETUP:
1685             switch (event->type){
1686                 case CH_EVT_RCVD_MSC_CMD:
1687                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_CMD);
1688                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_RSP);
1689                     break;
1690                 case CH_EVT_RCVD_MSC_RSP:
1691                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_RCVD_MSC_RSP);
1692                     break;
1693 
1694                 case CH_EVT_READY_TO_SEND:
1695                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_CMD){
1696                         log_info("Sending MSC CMD for #%u", channel->dlci);
1697                         rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_CMD);
1698                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SENT_MSC_CMD);
1699                         rfcomm_send_uih_msc_cmd(multiplexer, channel->dlci , 0x8d);  // ea=1,fc=0,rtc=1,rtr=1,ic=0,dv=1
1700                         break;
1701                     }
1702                     if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_SEND_CREDITS){
1703                         log_info("Providing credits for #%u", channel->dlci);
1704                         rfcomm_channel_state_remove(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_CREDITS);
1705                         rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SENT_CREDITS);
1706 
1707                         if (channel->new_credits_incoming) {
1708                             uint8_t new_credits = channel->new_credits_incoming;
1709                             channel->new_credits_incoming = 0;
1710                             rfcomm_channel_send_credits(channel, new_credits);
1711                         }
1712                         break;
1713 
1714                     }
1715                     break;
1716                 default:
1717                     break;
1718             }
1719             // finally done?
1720             if (rfcomm_channel_ready_for_open(channel)){
1721                 channel->state = RFCOMM_CHANNEL_OPEN;
1722                 rfcomm_channel_opened(channel);
1723             }
1724             break;
1725 
1726         case RFCOMM_CHANNEL_OPEN:
1727             switch (event->type){
1728                 case CH_EVT_RCVD_MSC_CMD:
1729                     rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_MSC_RSP);
1730                     break;
1731                 case CH_EVT_READY_TO_SEND:
1732                     if (channel->new_credits_incoming) {
1733                         uint8_t new_credits = channel->new_credits_incoming;
1734                         channel->new_credits_incoming = 0;
1735                         rfcomm_channel_send_credits(channel, new_credits);
1736                         break;
1737                     }
1738                     break;
1739                 case CH_EVT_RCVD_CREDITS: {
1740                     // notify daemon -> might trigger re-try of parked connections
1741                     uint8_t credits_event[2] = { DAEMON_EVENT_NEW_RFCOMM_CREDITS, 0 };
1742                     (*app_packet_handler)(DAEMON_EVENT_PACKET, channel->rfcomm_cid, credits_event, sizeof(credits_event));
1743                     break;
1744                 }
1745                 default:
1746                     break;
1747             }
1748             break;
1749 
1750         case RFCOMM_CHANNEL_SEND_DM:
1751             switch (event->type) {
1752                 case CH_EVT_READY_TO_SEND:
1753                     log_info("Sending DM_PF for #%u", channel->dlci);
1754                     // don't emit channel closed - channel was never open
1755                     channel->state = RFCOMM_CHANNEL_CLOSED;
1756                     rfcomm_send_dm_pf(multiplexer, channel->dlci);
1757                     rfcomm_channel_finalize(channel);
1758                     break;
1759                 default:
1760                     break;
1761             }
1762             break;
1763 
1764         case RFCOMM_CHANNEL_SEND_DISC:
1765             switch (event->type) {
1766                 case CH_EVT_READY_TO_SEND:
1767                     channel->state = RFCOMM_CHANNEL_W4_UA_AFTER_UA;
1768                     rfcomm_send_disc(multiplexer, channel->dlci);
1769                     break;
1770                 default:
1771                     break;
1772             }
1773             break;
1774 
1775         case RFCOMM_CHANNEL_W4_UA_AFTER_UA:
1776             switch (event->type){
1777                 case CH_EVT_RCVD_UA:
1778                     channel->state = RFCOMM_CHANNEL_CLOSED;
1779                     rfcomm_emit_channel_closed(channel);
1780                     rfcomm_channel_finalize(channel);
1781                     break;
1782                 default:
1783                     break;
1784             }
1785             break;
1786 
1787         case RFCOMM_CHANNEL_SEND_UA_AFTER_DISC:
1788             switch (event->type) {
1789                 case CH_EVT_READY_TO_SEND:
1790                     log_info("Sending UA after DISC for #%u", channel->dlci);
1791                     channel->state = RFCOMM_CHANNEL_CLOSED;
1792                     rfcomm_send_ua(multiplexer, channel->dlci);
1793                     rfcomm_channel_finalize(channel);
1794                     break;
1795                 default:
1796                     break;
1797             }
1798             break;
1799 
1800         default:
1801             break;
1802     }
1803 }
1804 
1805 
1806 // MARK: RFCOMM RUN
1807 // process outstanding signaling tasks
1808 static void rfcomm_run(void){
1809 
1810     btstack_linked_item_t *it;
1811     btstack_linked_item_t *next;
1812 
1813     for (it = (btstack_linked_item_t *) rfcomm_multiplexers; it ; it = next){
1814 
1815         next = it->next;    // be prepared for removal of channel in state machine
1816 
1817         rfcomm_multiplexer_t * multiplexer = ((rfcomm_multiplexer_t *) it);
1818 
1819         if (!l2cap_can_send_packet_now(multiplexer->l2cap_cid)) {
1820             // log_info("rfcomm_run A cannot send l2cap packet for #%u, credits %u", multiplexer->l2cap_cid, multiplexer->l2cap_credits);
1821             continue;
1822         }
1823         // log_info("rfcomm_run: multi 0x%08x, state %u", (int) multiplexer, multiplexer->state);
1824 
1825         rfcomm_multiplexer_state_machine(multiplexer, MULT_EV_READY_TO_SEND);
1826     }
1827 
1828     for (it = (btstack_linked_item_t *) rfcomm_channels; it ; it = next){
1829 
1830         next = it->next;    // be prepared for removal of channel in state machine
1831 
1832         rfcomm_channel_t * channel = ((rfcomm_channel_t *) it);
1833         rfcomm_multiplexer_t * multiplexer = channel->multiplexer;
1834 
1835         if (!l2cap_can_send_packet_now(multiplexer->l2cap_cid)) {
1836             // log_info("rfcomm_run B cannot send l2cap packet for #%u, credits %u", multiplexer->l2cap_cid, multiplexer->l2cap_credits);
1837             continue;
1838         }
1839 
1840         rfcomm_channel_event_t event = { CH_EVT_READY_TO_SEND };
1841         rfcomm_channel_state_machine(channel, &event);
1842     }
1843 }
1844 
1845 // MARK: RFCOMM BTstack API
1846 
1847 void rfcomm_init(void){
1848     rfcomm_client_cid_generator = 0;
1849     rfcomm_multiplexers = NULL;
1850     rfcomm_services     = NULL;
1851     rfcomm_channels     = NULL;
1852     rfcomm_security_level = LEVEL_2;
1853 }
1854 
1855 void rfcomm_set_required_security_level(gap_security_level_t security_level){
1856     rfcomm_security_level = security_level;
1857 }
1858 
1859 // register packet handler
1860 void rfcomm_register_packet_handler(void (*handler)(uint8_t packet_type,
1861                                                     uint16_t channel, uint8_t *packet, uint16_t size)){
1862 	app_packet_handler = handler;
1863 }
1864 
1865 int rfcomm_can_send_packet_now(uint16_t rfcomm_cid){
1866     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1867     if (!channel){
1868         log_error("rfcomm_send cid 0x%02x doesn't exist!", rfcomm_cid);
1869         return 1;
1870     }
1871     if (!channel->credits_outgoing) return 0;
1872     if ((channel->multiplexer->fcon & 1) == 0) return 0;
1873 
1874     return l2cap_can_send_packet_now(channel->multiplexer->l2cap_cid);
1875 }
1876 
1877 static int rfcomm_assert_send_valid(rfcomm_channel_t * channel , uint16_t len){
1878     if (len > channel->max_frame_size){
1879         log_error("rfcomm_send cid 0x%02x, rfcomm data lenght exceeds MTU!", channel->rfcomm_cid);
1880         return RFCOMM_DATA_LEN_EXCEEDS_MTU;
1881     }
1882 
1883     if (!channel->credits_outgoing){
1884         log_info("rfcomm_send cid 0x%02x, no rfcomm outgoing credits!", channel->rfcomm_cid);
1885         return RFCOMM_NO_OUTGOING_CREDITS;
1886     }
1887 
1888     if ((channel->multiplexer->fcon & 1) == 0){
1889         log_info("rfcomm_send cid 0x%02x, aggregate flow off!", channel->rfcomm_cid);
1890         return RFCOMM_AGGREGATE_FLOW_OFF;
1891     }
1892     return 0;
1893 }
1894 
1895 // pre: rfcomm_can_send_packet_now(rfcomm_cid) == true
1896 int rfcomm_reserve_packet_buffer(void){
1897     return l2cap_reserve_packet_buffer();
1898 }
1899 
1900 void rfcomm_release_packet_buffer(void){
1901     l2cap_release_packet_buffer();
1902 }
1903 
1904 uint8_t * rfcomm_get_outgoing_buffer(void){
1905     uint8_t * rfcomm_out_buffer = l2cap_get_outgoing_buffer();
1906     // address + control + length (16) + no credit field
1907     return &rfcomm_out_buffer[4];
1908 }
1909 
1910 uint16_t rfcomm_get_max_frame_size(uint16_t rfcomm_cid){
1911     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1912     if (!channel){
1913         log_error("rfcomm_get_max_frame_size cid 0x%02x doesn't exist!", rfcomm_cid);
1914         return 0;
1915     }
1916     return channel->max_frame_size;
1917 }
1918 int rfcomm_send_prepared(uint16_t rfcomm_cid, uint16_t len){
1919     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1920     if (!channel){
1921         log_error("rfcomm_send_prepared cid 0x%02x doesn't exist!", rfcomm_cid);
1922         return 0;
1923     }
1924 
1925     int err = rfcomm_assert_send_valid(channel, len);
1926     if (err) return err;
1927     if (l2cap_can_send_prepared_packet_now(channel->multiplexer->l2cap_cid)){
1928         log_error("rfcomm_send_prepared: l2cap cannot send now");
1929         return BTSTACK_ACL_BUFFERS_FULL;
1930     }
1931 
1932     // send might cause l2cap to emit new credits, update counters first
1933     channel->credits_outgoing--;
1934 
1935     int result = rfcomm_send_uih_prepared(channel->multiplexer, channel->dlci, len);
1936 
1937     if (result != 0) {
1938         channel->credits_outgoing++;
1939         log_error("rfcomm_send_prepared: error %d", result);
1940         return result;
1941     }
1942 
1943     return result;
1944 }
1945 
1946 int rfcomm_send(uint16_t rfcomm_cid, uint8_t *data, uint16_t len){
1947     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1948     if (!channel){
1949         log_error("rfcomm_send cid 0x%02x doesn't exist!", rfcomm_cid);
1950         return 1;
1951     }
1952 
1953     int err = rfcomm_assert_send_valid(channel, len);
1954     if (err) return err;
1955     if (l2cap_can_send_packet_now(channel->multiplexer->l2cap_cid)){
1956         log_error("rfcomm_send_internal: l2cap cannot send now");
1957         return BTSTACK_ACL_BUFFERS_FULL;
1958     }
1959 
1960     rfcomm_reserve_packet_buffer();
1961     uint8_t * rfcomm_payload = rfcomm_get_outgoing_buffer();
1962     memcpy(rfcomm_payload, data, len);
1963     err = rfcomm_send_prepared(rfcomm_cid, len);
1964     if (err){
1965         rfcomm_release_packet_buffer();
1966     }
1967     return err;
1968 }
1969 
1970 // Sends Local Lnie Status, see LINE_STATUS_..
1971 int rfcomm_send_local_line_status(uint16_t rfcomm_cid, uint8_t line_status){
1972     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1973     if (!channel){
1974         log_error("rfcomm_send_local_line_status cid 0x%02x doesn't exist!", rfcomm_cid);
1975         return 0;
1976     }
1977     return rfcomm_send_uih_rls_cmd(channel->multiplexer, channel->dlci, line_status);
1978 }
1979 
1980 // Sned local modem status. see MODEM_STAUS_..
1981 int rfcomm_send_modem_status(uint16_t rfcomm_cid, uint8_t modem_status){
1982     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1983     if (!channel){
1984         log_error("rfcomm_send_modem_status cid 0x%02x doesn't exist!", rfcomm_cid);
1985         return 0;
1986     }
1987     return rfcomm_send_uih_msc_cmd(channel->multiplexer, channel->dlci, modem_status);
1988 }
1989 
1990 // Configure remote port
1991 int rfcomm_send_port_configuration(uint16_t rfcomm_cid, rpn_baud_t baud_rate, rpn_data_bits_t data_bits, rpn_stop_bits_t stop_bits, rpn_parity_t parity, rpn_flow_control_t flow_control){
1992     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
1993     if (!channel){
1994         log_error("rfcomm_send_port_configuration cid 0x%02x doesn't exist!", rfcomm_cid);
1995         return 0;
1996     }
1997     rfcomm_rpn_data_t rpn_data;
1998     rpn_data.baud_rate = baud_rate;
1999     rpn_data.flags = data_bits | (stop_bits << 2) | (parity << 3);
2000     rpn_data.flow_control = flow_control;
2001     rpn_data.xon = 0;
2002     rpn_data.xoff = 0;
2003     rpn_data.parameter_mask_0 = 0x1f;   // all but xon/xoff
2004     rpn_data.parameter_mask_1 = 0x3f;   // all flow control options
2005     return rfcomm_send_uih_rpn_cmd(channel->multiplexer, channel->dlci, &rpn_data);
2006 }
2007 
2008 // Query remote port
2009 int rfcomm_query_port_configuration(uint16_t rfcomm_cid){
2010     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2011     if (!channel){
2012         log_error("rfcomm_query_port_configuration cid 0x%02x doesn't exist!", rfcomm_cid);
2013         return 0;
2014     }
2015     return rfcomm_send_uih_rpn_req(channel->multiplexer, channel->dlci);
2016 }
2017 
2018 
2019 static uint8_t rfcomm_create_channel_internal(bd_addr_t addr, uint8_t server_channel, uint8_t incoming_flow_control, uint8_t initial_credits, uint16_t * out_rfcomm_cid){
2020     log_info("RFCOMM_CREATE_CHANNEL addr %s channel #%u init credits %u",  bd_addr_to_str(addr), server_channel, initial_credits);
2021 
2022     // create new multiplexer if necessary
2023     uint8_t status = 0;
2024     int new_multiplexer = 0;
2025     rfcomm_channel_t * channel = NULL;
2026     rfcomm_multiplexer_t * multiplexer = rfcomm_multiplexer_for_addr(addr);
2027     if (!multiplexer) {
2028         multiplexer = rfcomm_multiplexer_create_for_addr(addr);
2029         if (!multiplexer){
2030             status = BTSTACK_MEMORY_ALLOC_FAILED;
2031             goto fail;
2032         }
2033         multiplexer->outgoing = 1;
2034         multiplexer->state = RFCOMM_MULTIPLEXER_W4_CONNECT;
2035         new_multiplexer = 1;
2036     }
2037 
2038     // prepare channel
2039     channel = rfcomm_channel_create(multiplexer, NULL, server_channel);
2040     if (!channel){
2041         status = BTSTACK_MEMORY_ALLOC_FAILED;
2042         goto fail;
2043     }
2044     // rfcomm_cid is already assigned by rfcomm_channel_create
2045     channel->incoming_flow_control = incoming_flow_control;
2046     channel->new_credits_incoming  = initial_credits;
2047 
2048     // return rfcomm_cid
2049     if (out_rfcomm_cid){
2050         *out_rfcomm_cid = channel->rfcomm_cid;
2051     }
2052 
2053     // start multiplexer setup
2054     if (multiplexer->state != RFCOMM_MULTIPLEXER_OPEN) {
2055         channel->state = RFCOMM_CHANNEL_W4_MULTIPLEXER;
2056         uint16_t l2cap_cid = 0;
2057         status = l2cap_create_channel(rfcomm_packet_handler, addr, PSM_RFCOMM, l2cap_max_mtu(), &l2cap_cid);
2058         if (status) goto fail;
2059         multiplexer->l2cap_cid = l2cap_cid;
2060         return 0;
2061     }
2062 
2063     channel->state = RFCOMM_CHANNEL_SEND_UIH_PN;
2064 
2065     // start connecting, if multiplexer is already up and running
2066     rfcomm_run();
2067     return 0;
2068 
2069 fail:
2070     if (new_multiplexer) btstack_memory_rfcomm_multiplexer_free(multiplexer);
2071     if (channel)         btstack_memory_rfcomm_channel_free(channel);
2072     return status;
2073 }
2074 
2075 uint8_t rfcomm_create_channel_with_initial_credits(bd_addr_t addr, uint8_t server_channel, uint8_t initial_credits, uint16_t * out_rfcomm_cid){
2076     return rfcomm_create_channel_internal(addr, server_channel, 1, initial_credits, out_rfcomm_cid);
2077 }
2078 
2079 uint8_t rfcomm_create_channel(bd_addr_t addr, uint8_t server_channel, uint16_t * out_rfcomm_cid){
2080     return rfcomm_create_channel_internal(addr, server_channel, 0, RFCOMM_CREDITS, out_rfcomm_cid);
2081 }
2082 
2083 void rfcomm_disconnect(uint16_t rfcomm_cid){
2084     log_info("RFCOMM_DISCONNECT cid 0x%02x", rfcomm_cid);
2085     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2086     if (channel) {
2087         channel->state = RFCOMM_CHANNEL_SEND_DISC;
2088     }
2089 
2090     // process
2091     rfcomm_run();
2092 }
2093 
2094 static uint8_t rfcomm_register_service_internal(uint8_t channel, uint16_t max_frame_size, uint8_t incoming_flow_control, uint8_t initial_credits){    log_info("RFCOMM_REGISTER_SERVICE channel #%u mtu %u flow_control %u credits %u",
2095              channel, max_frame_size, incoming_flow_control, initial_credits);
2096 
2097     // check if already registered
2098     rfcomm_service_t * service = rfcomm_service_for_channel(channel);
2099     if (service){
2100         return RFCOMM_CHANNEL_ALREADY_REGISTERED;
2101     }
2102 
2103     // alloc structure
2104     service = btstack_memory_rfcomm_service_get();
2105     if (!service) {
2106         return BTSTACK_MEMORY_ALLOC_FAILED;
2107     }
2108 
2109     // register with l2cap if not registered before, max MTU
2110     if (btstack_linked_list_empty(&rfcomm_services)){
2111         l2cap_register_service(rfcomm_packet_handler, PSM_RFCOMM, 0xffff, rfcomm_security_level);
2112     }
2113 
2114     // fill in
2115     service->server_channel = channel;
2116     service->max_frame_size = max_frame_size;
2117     service->incoming_flow_control = incoming_flow_control;
2118     service->incoming_initial_credits = initial_credits;
2119 
2120     // add to services list
2121     btstack_linked_list_add(&rfcomm_services, (btstack_linked_item_t *) service);
2122 
2123     return 0;
2124 }
2125 
2126 uint8_t rfcomm_register_service_with_initial_credits(uint8_t channel, uint16_t max_frame_size, uint8_t initial_credits){
2127     return rfcomm_register_service_internal(channel, max_frame_size, 1, initial_credits);
2128 }
2129 
2130 uint8_t rfcomm_register_service(uint8_t channel, uint16_t max_frame_size){
2131     return rfcomm_register_service_internal(channel, max_frame_size, 0,RFCOMM_CREDITS);
2132 }
2133 
2134 void rfcomm_unregister_service(uint8_t service_channel){
2135     log_info("RFCOMM_UNREGISTER_SERVICE #%u", service_channel);
2136     rfcomm_service_t *service = rfcomm_service_for_channel(service_channel);
2137     if (!service) return;
2138     btstack_linked_list_remove(&rfcomm_services, (btstack_linked_item_t *) service);
2139     btstack_memory_rfcomm_service_free(service);
2140 
2141     // unregister if no services active
2142     if (btstack_linked_list_empty(&rfcomm_services)){
2143         // bt_send_cmd(&l2cap_unregister_service, PSM_RFCOMM);
2144         l2cap_unregister_service(PSM_RFCOMM);
2145     }
2146 }
2147 
2148 void rfcomm_accept_connection(uint16_t rfcomm_cid){
2149     log_info("RFCOMM_ACCEPT_CONNECTION cid 0x%02x", rfcomm_cid);
2150     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2151     if (!channel) return;
2152     switch (channel->state) {
2153         case RFCOMM_CHANNEL_INCOMING_SETUP:
2154             rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_CLIENT_ACCEPTED);
2155             if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_RCVD_PN){
2156                 rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_PN_RSP);
2157             }
2158             if (channel->state_var & RFCOMM_CHANNEL_STATE_VAR_RCVD_SABM){
2159                 rfcomm_channel_state_add(channel, RFCOMM_CHANNEL_STATE_VAR_SEND_UA);
2160             }
2161             // at least one of { PN RSP, UA } needs to be sent
2162             // state transistion incoming setup -> dlc setup happens in rfcomm_run after these have been sent
2163             break;
2164         default:
2165             break;
2166     }
2167 
2168     // process
2169     rfcomm_run();
2170 }
2171 
2172 void rfcomm_decline_connection(uint16_t rfcomm_cid){
2173     log_info("RFCOMM_DECLINE_CONNECTION cid 0x%02x", rfcomm_cid);
2174     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2175     if (!channel) return;
2176     switch (channel->state) {
2177         case RFCOMM_CHANNEL_INCOMING_SETUP:
2178             channel->state = RFCOMM_CHANNEL_SEND_DM;
2179             break;
2180         default:
2181             break;
2182     }
2183 
2184     // process
2185     rfcomm_run();
2186 }
2187 
2188 void rfcomm_grant_credits(uint16_t rfcomm_cid, uint8_t credits){
2189     log_info("RFCOMM_GRANT_CREDITS cid 0x%02x credits %u", rfcomm_cid, credits);
2190     rfcomm_channel_t * channel = rfcomm_channel_for_rfcomm_cid(rfcomm_cid);
2191     if (!channel) return;
2192     if (!channel->incoming_flow_control) return;
2193     channel->new_credits_incoming += credits;
2194 
2195     // process
2196     rfcomm_run();
2197 }
2198 
2199 
2200 
2201 
2202