USB: oti6858: fix use-after-free in TIOCMIWAIT
[pandora-kernel.git] / drivers / usb / serial / oti6858.c
1 /*
2  * Ours Technology Inc. OTi-6858 USB to serial adapter driver.
3  *
4  * Copyleft  (C) 2007 Kees Lemmens (adapted for kernel 2.6.20)
5  * Copyright (C) 2006 Tomasz Michal Lukaszewski (FIXME: add e-mail)
6  * Copyright (C) 2001-2004 Greg Kroah-Hartman (greg@kroah.com)
7  * Copyright (C) 2003 IBM Corp.
8  *
9  * Many thanks to the authors of pl2303 driver: all functions in this file
10  * are heavily based on pl2303 code, buffering code is a 1-to-1 copy.
11  *
12  * Warning! You use this driver on your own risk! The only official
13  * description of this device I have is datasheet from manufacturer,
14  * and it doesn't contain almost any information needed to write a driver.
15  * Almost all knowlegde used while writing this driver was gathered by:
16  *  - analyzing traffic between device and the M$ Windows 2000 driver,
17  *  - trying different bit combinations and checking pin states
18  *    with a voltmeter,
19  *  - receiving malformed frames and producing buffer overflows
20  *    to learn how errors are reported,
21  * So, THIS CODE CAN DESTROY OTi-6858 AND ANY OTHER DEVICES, THAT ARE
22  * CONNECTED TO IT!
23  *
24  * This program is free software; you can redistribute it and/or modify
25  * it under the terms of the GNU General Public License as published by
26  * the Free Software Foundation; either version 2 of the License.
27  *
28  * See Documentation/usb/usb-serial.txt for more information on using this
29  * driver
30  *
31  * TODO:
32  *  - implement correct flushing for ioctls and oti6858_close()
33  *  - check how errors (rx overflow, parity error, framing error) are reported
34  *  - implement oti6858_break_ctl()
35  *  - implement more ioctls
36  *  - test/implement flow control
37  *  - allow setting custom baud rates
38  */
39
40 #include <linux/kernel.h>
41 #include <linux/errno.h>
42 #include <linux/init.h>
43 #include <linux/slab.h>
44 #include <linux/tty.h>
45 #include <linux/tty_driver.h>
46 #include <linux/tty_flip.h>
47 #include <linux/serial.h>
48 #include <linux/module.h>
49 #include <linux/moduleparam.h>
50 #include <linux/spinlock.h>
51 #include <linux/usb.h>
52 #include <linux/usb/serial.h>
53 #include <linux/uaccess.h>
54 #include <linux/kfifo.h>
55 #include "oti6858.h"
56
57 #define OTI6858_DESCRIPTION \
58         "Ours Technology Inc. OTi-6858 USB to serial adapter driver"
59 #define OTI6858_AUTHOR "Tomasz Michal Lukaszewski <FIXME@FIXME>"
60
61 static const struct usb_device_id id_table[] = {
62         { USB_DEVICE(OTI6858_VENDOR_ID, OTI6858_PRODUCT_ID) },
63         { }
64 };
65
66 MODULE_DEVICE_TABLE(usb, id_table);
67
68 /* requests */
69 #define OTI6858_REQ_GET_STATUS          (USB_DIR_IN | USB_TYPE_VENDOR | 0x00)
70 #define OTI6858_REQ_T_GET_STATUS        0x01
71
72 #define OTI6858_REQ_SET_LINE            (USB_DIR_OUT | USB_TYPE_VENDOR | 0x00)
73 #define OTI6858_REQ_T_SET_LINE          0x00
74
75 #define OTI6858_REQ_CHECK_TXBUFF        (USB_DIR_IN | USB_TYPE_VENDOR | 0x01)
76 #define OTI6858_REQ_T_CHECK_TXBUFF      0x00
77
78 /* format of the control packet */
79 struct oti6858_control_pkt {
80         __le16  divisor;        /* baud rate = 96000000 / (16 * divisor), LE */
81 #define OTI6858_MAX_BAUD_RATE   3000000
82         u8      frame_fmt;
83 #define FMT_STOP_BITS_MASK      0xc0
84 #define FMT_STOP_BITS_1         0x00
85 #define FMT_STOP_BITS_2         0x40    /* 1.5 stop bits if FMT_DATA_BITS_5 */
86 #define FMT_PARITY_MASK         0x38
87 #define FMT_PARITY_NONE         0x00
88 #define FMT_PARITY_ODD          0x08
89 #define FMT_PARITY_EVEN         0x18
90 #define FMT_PARITY_MARK         0x28
91 #define FMT_PARITY_SPACE        0x38
92 #define FMT_DATA_BITS_MASK      0x03
93 #define FMT_DATA_BITS_5         0x00
94 #define FMT_DATA_BITS_6         0x01
95 #define FMT_DATA_BITS_7         0x02
96 #define FMT_DATA_BITS_8         0x03
97         u8      something;      /* always equals 0x43 */
98         u8      control;        /* settings of flow control lines */
99 #define CONTROL_MASK            0x0c
100 #define CONTROL_DTR_HIGH        0x08
101 #define CONTROL_RTS_HIGH        0x04
102         u8      tx_status;
103 #define TX_BUFFER_EMPTIED       0x09
104         u8      pin_state;
105 #define PIN_MASK                0x3f
106 #define PIN_RTS                 0x20    /* output pin */
107 #define PIN_CTS                 0x10    /* input pin, active low */
108 #define PIN_DSR                 0x08    /* input pin, active low */
109 #define PIN_DTR                 0x04    /* output pin */
110 #define PIN_RI                  0x02    /* input pin, active low */
111 #define PIN_DCD                 0x01    /* input pin, active low */
112         u8      rx_bytes_avail;         /* number of bytes in rx buffer */;
113 };
114
115 #define OTI6858_CTRL_PKT_SIZE   sizeof(struct oti6858_control_pkt)
116 #define OTI6858_CTRL_EQUALS_PENDING(a, priv) \
117         (((a)->divisor == (priv)->pending_setup.divisor) \
118           && ((a)->control == (priv)->pending_setup.control) \
119           && ((a)->frame_fmt == (priv)->pending_setup.frame_fmt))
120
121 /* function prototypes */
122 static int oti6858_open(struct tty_struct *tty, struct usb_serial_port *port);
123 static void oti6858_close(struct usb_serial_port *port);
124 static void oti6858_set_termios(struct tty_struct *tty,
125                         struct usb_serial_port *port, struct ktermios *old);
126 static void oti6858_init_termios(struct tty_struct *tty);
127 static int oti6858_ioctl(struct tty_struct *tty,
128                         unsigned int cmd, unsigned long arg);
129 static void oti6858_read_int_callback(struct urb *urb);
130 static void oti6858_read_bulk_callback(struct urb *urb);
131 static void oti6858_write_bulk_callback(struct urb *urb);
132 static int oti6858_write(struct tty_struct *tty, struct usb_serial_port *port,
133                         const unsigned char *buf, int count);
134 static int oti6858_write_room(struct tty_struct *tty);
135 static int oti6858_chars_in_buffer(struct tty_struct *tty);
136 static int oti6858_tiocmget(struct tty_struct *tty);
137 static int oti6858_tiocmset(struct tty_struct *tty,
138                                 unsigned int set, unsigned int clear);
139 static int oti6858_port_probe(struct usb_serial_port *port);
140 static int oti6858_port_remove(struct usb_serial_port *port);
141
142 /* device info */
143 static struct usb_serial_driver oti6858_device = {
144         .driver = {
145                 .owner =        THIS_MODULE,
146                 .name =         "oti6858",
147         },
148         .id_table =             id_table,
149         .num_ports =            1,
150         .open =                 oti6858_open,
151         .close =                oti6858_close,
152         .write =                oti6858_write,
153         .ioctl =                oti6858_ioctl,
154         .set_termios =          oti6858_set_termios,
155         .init_termios =         oti6858_init_termios,
156         .tiocmget =             oti6858_tiocmget,
157         .tiocmset =             oti6858_tiocmset,
158         .read_bulk_callback =   oti6858_read_bulk_callback,
159         .read_int_callback =    oti6858_read_int_callback,
160         .write_bulk_callback =  oti6858_write_bulk_callback,
161         .write_room =           oti6858_write_room,
162         .chars_in_buffer =      oti6858_chars_in_buffer,
163         .port_probe =           oti6858_port_probe,
164         .port_remove =          oti6858_port_remove,
165 };
166
167 static struct usb_serial_driver * const serial_drivers[] = {
168         &oti6858_device, NULL
169 };
170
171 struct oti6858_private {
172         spinlock_t lock;
173
174         struct oti6858_control_pkt status;
175
176         struct {
177                 u8 read_urb_in_use;
178                 u8 write_urb_in_use;
179         } flags;
180         struct delayed_work delayed_write_work;
181
182         struct {
183                 __le16 divisor;
184                 u8 frame_fmt;
185                 u8 control;
186         } pending_setup;
187         u8 transient;
188         u8 setup_done;
189         struct delayed_work delayed_setup_work;
190
191         struct usb_serial_port *port;   /* USB port with which associated */
192 };
193
194 static void setup_line(struct work_struct *work)
195 {
196         struct oti6858_private *priv = container_of(work,
197                         struct oti6858_private, delayed_setup_work.work);
198         struct usb_serial_port *port = priv->port;
199         struct oti6858_control_pkt *new_setup;
200         unsigned long flags;
201         int result;
202
203         new_setup = kmalloc(OTI6858_CTRL_PKT_SIZE, GFP_KERNEL);
204         if (new_setup == NULL) {
205                 dev_err(&port->dev, "%s(): out of memory!\n", __func__);
206                 /* we will try again */
207                 schedule_delayed_work(&priv->delayed_setup_work,
208                                                 msecs_to_jiffies(2));
209                 return;
210         }
211
212         result = usb_control_msg(port->serial->dev,
213                                 usb_rcvctrlpipe(port->serial->dev, 0),
214                                 OTI6858_REQ_T_GET_STATUS,
215                                 OTI6858_REQ_GET_STATUS,
216                                 0, 0,
217                                 new_setup, OTI6858_CTRL_PKT_SIZE,
218                                 100);
219
220         if (result != OTI6858_CTRL_PKT_SIZE) {
221                 dev_err(&port->dev, "%s(): error reading status\n", __func__);
222                 kfree(new_setup);
223                 /* we will try again */
224                 schedule_delayed_work(&priv->delayed_setup_work,
225                                                         msecs_to_jiffies(2));
226                 return;
227         }
228
229         spin_lock_irqsave(&priv->lock, flags);
230         if (!OTI6858_CTRL_EQUALS_PENDING(new_setup, priv)) {
231                 new_setup->divisor = priv->pending_setup.divisor;
232                 new_setup->control = priv->pending_setup.control;
233                 new_setup->frame_fmt = priv->pending_setup.frame_fmt;
234
235                 spin_unlock_irqrestore(&priv->lock, flags);
236                 result = usb_control_msg(port->serial->dev,
237                                         usb_sndctrlpipe(port->serial->dev, 0),
238                                         OTI6858_REQ_T_SET_LINE,
239                                         OTI6858_REQ_SET_LINE,
240                                         0, 0,
241                                         new_setup, OTI6858_CTRL_PKT_SIZE,
242                                         100);
243         } else {
244                 spin_unlock_irqrestore(&priv->lock, flags);
245                 result = 0;
246         }
247         kfree(new_setup);
248
249         spin_lock_irqsave(&priv->lock, flags);
250         if (result != OTI6858_CTRL_PKT_SIZE)
251                 priv->transient = 0;
252         priv->setup_done = 1;
253         spin_unlock_irqrestore(&priv->lock, flags);
254
255         dev_dbg(&port->dev, "%s(): submitting interrupt urb\n", __func__);
256         result = usb_submit_urb(port->interrupt_in_urb, GFP_KERNEL);
257         if (result != 0) {
258                 dev_err(&port->dev, "%s(): usb_submit_urb() failed with error %d\n",
259                         __func__, result);
260         }
261 }
262
263 static void send_data(struct work_struct *work)
264 {
265         struct oti6858_private *priv = container_of(work,
266                         struct oti6858_private, delayed_write_work.work);
267         struct usb_serial_port *port = priv->port;
268         int count = 0, result;
269         unsigned long flags;
270         u8 *allow;
271
272         spin_lock_irqsave(&priv->lock, flags);
273         if (priv->flags.write_urb_in_use) {
274                 spin_unlock_irqrestore(&priv->lock, flags);
275                 schedule_delayed_work(&priv->delayed_write_work,
276                                                 msecs_to_jiffies(2));
277                 return;
278         }
279         priv->flags.write_urb_in_use = 1;
280         spin_unlock_irqrestore(&priv->lock, flags);
281
282         spin_lock_irqsave(&port->lock, flags);
283         count = kfifo_len(&port->write_fifo);
284         spin_unlock_irqrestore(&port->lock, flags);
285
286         if (count > port->bulk_out_size)
287                 count = port->bulk_out_size;
288
289         if (count != 0) {
290                 allow = kmalloc(1, GFP_KERNEL);
291                 if (!allow) {
292                         dev_err_console(port, "%s(): kmalloc failed\n",
293                                         __func__);
294                         return;
295                 }
296                 result = usb_control_msg(port->serial->dev,
297                                 usb_rcvctrlpipe(port->serial->dev, 0),
298                                 OTI6858_REQ_T_CHECK_TXBUFF,
299                                 OTI6858_REQ_CHECK_TXBUFF,
300                                 count, 0, allow, 1, 100);
301                 if (result != 1 || *allow != 0)
302                         count = 0;
303                 kfree(allow);
304         }
305
306         if (count == 0) {
307                 priv->flags.write_urb_in_use = 0;
308
309                 dev_dbg(&port->dev, "%s(): submitting interrupt urb\n", __func__);
310                 result = usb_submit_urb(port->interrupt_in_urb, GFP_NOIO);
311                 if (result != 0) {
312                         dev_err(&port->dev, "%s(): usb_submit_urb() failed with error %d\n",
313                                 __func__, result);
314                 }
315                 return;
316         }
317
318         count = kfifo_out_locked(&port->write_fifo,
319                                         port->write_urb->transfer_buffer,
320                                         count, &port->lock);
321         port->write_urb->transfer_buffer_length = count;
322         result = usb_submit_urb(port->write_urb, GFP_NOIO);
323         if (result != 0) {
324                 dev_err_console(port, "%s(): usb_submit_urb() failed with error %d\n",
325                                 __func__, result);
326                 priv->flags.write_urb_in_use = 0;
327         }
328
329         usb_serial_port_softint(port);
330 }
331
332 static int oti6858_port_probe(struct usb_serial_port *port)
333 {
334         struct oti6858_private *priv;
335
336         priv = kzalloc(sizeof(*priv), GFP_KERNEL);
337         if (!priv)
338                 return -ENOMEM;
339
340         spin_lock_init(&priv->lock);
341         priv->port = port;
342         INIT_DELAYED_WORK(&priv->delayed_setup_work, setup_line);
343         INIT_DELAYED_WORK(&priv->delayed_write_work, send_data);
344
345         usb_set_serial_port_data(port, priv);
346
347         return 0;
348 }
349
350 static int oti6858_port_remove(struct usb_serial_port *port)
351 {
352         struct oti6858_private *priv;
353
354         priv = usb_get_serial_port_data(port);
355         kfree(priv);
356
357         return 0;
358 }
359
360 static int oti6858_write(struct tty_struct *tty, struct usb_serial_port *port,
361                         const unsigned char *buf, int count)
362 {
363         if (!count)
364                 return count;
365
366         count = kfifo_in_locked(&port->write_fifo, buf, count, &port->lock);
367
368         return count;
369 }
370
371 static int oti6858_write_room(struct tty_struct *tty)
372 {
373         struct usb_serial_port *port = tty->driver_data;
374         int room = 0;
375         unsigned long flags;
376
377         spin_lock_irqsave(&port->lock, flags);
378         room = kfifo_avail(&port->write_fifo);
379         spin_unlock_irqrestore(&port->lock, flags);
380
381         return room;
382 }
383
384 static int oti6858_chars_in_buffer(struct tty_struct *tty)
385 {
386         struct usb_serial_port *port = tty->driver_data;
387         int chars = 0;
388         unsigned long flags;
389
390         spin_lock_irqsave(&port->lock, flags);
391         chars = kfifo_len(&port->write_fifo);
392         spin_unlock_irqrestore(&port->lock, flags);
393
394         return chars;
395 }
396
397 static void oti6858_init_termios(struct tty_struct *tty)
398 {
399         tty->termios = tty_std_termios;
400         tty->termios.c_cflag = B38400 | CS8 | CREAD | HUPCL | CLOCAL;
401         tty->termios.c_ispeed = 38400;
402         tty->termios.c_ospeed = 38400;
403 }
404
405 static void oti6858_set_termios(struct tty_struct *tty,
406                 struct usb_serial_port *port, struct ktermios *old_termios)
407 {
408         struct oti6858_private *priv = usb_get_serial_port_data(port);
409         unsigned long flags;
410         unsigned int cflag;
411         u8 frame_fmt, control;
412         __le16 divisor;
413         int br;
414
415         if (!tty)
416                 return;
417
418         cflag = tty->termios.c_cflag;
419
420         spin_lock_irqsave(&priv->lock, flags);
421         divisor = priv->pending_setup.divisor;
422         frame_fmt = priv->pending_setup.frame_fmt;
423         control = priv->pending_setup.control;
424         spin_unlock_irqrestore(&priv->lock, flags);
425
426         frame_fmt &= ~FMT_DATA_BITS_MASK;
427         switch (cflag & CSIZE) {
428         case CS5:
429                 frame_fmt |= FMT_DATA_BITS_5;
430                 break;
431         case CS6:
432                 frame_fmt |= FMT_DATA_BITS_6;
433                 break;
434         case CS7:
435                 frame_fmt |= FMT_DATA_BITS_7;
436                 break;
437         default:
438         case CS8:
439                 frame_fmt |= FMT_DATA_BITS_8;
440                 break;
441         }
442
443         /* manufacturer claims that this device can work with baud rates
444          * up to 3 Mbps; I've tested it only on 115200 bps, so I can't
445          * guarantee that any other baud rate will work (especially
446          * the higher ones)
447          */
448         br = tty_get_baud_rate(tty);
449         if (br == 0) {
450                 divisor = 0;
451         } else {
452                 int real_br;
453                 int new_divisor;
454                 br = min(br, OTI6858_MAX_BAUD_RATE);
455
456                 new_divisor = (96000000 + 8 * br) / (16 * br);
457                 real_br = 96000000 / (16 * new_divisor);
458                 divisor = cpu_to_le16(new_divisor);
459                 tty_encode_baud_rate(tty, real_br, real_br);
460         }
461
462         frame_fmt &= ~FMT_STOP_BITS_MASK;
463         if ((cflag & CSTOPB) != 0)
464                 frame_fmt |= FMT_STOP_BITS_2;
465         else
466                 frame_fmt |= FMT_STOP_BITS_1;
467
468         frame_fmt &= ~FMT_PARITY_MASK;
469         if ((cflag & PARENB) != 0) {
470                 if ((cflag & PARODD) != 0)
471                         frame_fmt |= FMT_PARITY_ODD;
472                 else
473                         frame_fmt |= FMT_PARITY_EVEN;
474         } else {
475                 frame_fmt |= FMT_PARITY_NONE;
476         }
477
478         control &= ~CONTROL_MASK;
479         if ((cflag & CRTSCTS) != 0)
480                 control |= (CONTROL_DTR_HIGH | CONTROL_RTS_HIGH);
481
482         /* change control lines if we are switching to or from B0 */
483         /* FIXME:
484         spin_lock_irqsave(&priv->lock, flags);
485         control = priv->line_control;
486         if ((cflag & CBAUD) == B0)
487                 priv->line_control &= ~(CONTROL_DTR | CONTROL_RTS);
488         else
489                 priv->line_control |= (CONTROL_DTR | CONTROL_RTS);
490         if (control != priv->line_control) {
491                 control = priv->line_control;
492                 spin_unlock_irqrestore(&priv->lock, flags);
493                 set_control_lines(serial->dev, control);
494         } else {
495                 spin_unlock_irqrestore(&priv->lock, flags);
496         }
497         */
498
499         spin_lock_irqsave(&priv->lock, flags);
500         if (divisor != priv->pending_setup.divisor
501                         || control != priv->pending_setup.control
502                         || frame_fmt != priv->pending_setup.frame_fmt) {
503                 priv->pending_setup.divisor = divisor;
504                 priv->pending_setup.control = control;
505                 priv->pending_setup.frame_fmt = frame_fmt;
506         }
507         spin_unlock_irqrestore(&priv->lock, flags);
508 }
509
510 static int oti6858_open(struct tty_struct *tty, struct usb_serial_port *port)
511 {
512         struct oti6858_private *priv = usb_get_serial_port_data(port);
513         struct ktermios tmp_termios;
514         struct usb_serial *serial = port->serial;
515         struct oti6858_control_pkt *buf;
516         unsigned long flags;
517         int result;
518
519         usb_clear_halt(serial->dev, port->write_urb->pipe);
520         usb_clear_halt(serial->dev, port->read_urb->pipe);
521
522         buf = kmalloc(OTI6858_CTRL_PKT_SIZE, GFP_KERNEL);
523         if (buf == NULL) {
524                 dev_err(&port->dev, "%s(): out of memory!\n", __func__);
525                 return -ENOMEM;
526         }
527
528         result = usb_control_msg(serial->dev, usb_rcvctrlpipe(serial->dev, 0),
529                                 OTI6858_REQ_T_GET_STATUS,
530                                 OTI6858_REQ_GET_STATUS,
531                                 0, 0,
532                                 buf, OTI6858_CTRL_PKT_SIZE,
533                                 100);
534         if (result != OTI6858_CTRL_PKT_SIZE) {
535                 /* assume default (after power-on reset) values */
536                 buf->divisor = cpu_to_le16(0x009c);     /* 38400 bps */
537                 buf->frame_fmt = 0x03;  /* 8N1 */
538                 buf->something = 0x43;
539                 buf->control = 0x4c;    /* DTR, RTS */
540                 buf->tx_status = 0x00;
541                 buf->pin_state = 0x5b;  /* RTS, CTS, DSR, DTR, RI, DCD */
542                 buf->rx_bytes_avail = 0x00;
543         }
544
545         spin_lock_irqsave(&priv->lock, flags);
546         memcpy(&priv->status, buf, OTI6858_CTRL_PKT_SIZE);
547         priv->pending_setup.divisor = buf->divisor;
548         priv->pending_setup.frame_fmt = buf->frame_fmt;
549         priv->pending_setup.control = buf->control;
550         spin_unlock_irqrestore(&priv->lock, flags);
551         kfree(buf);
552
553         dev_dbg(&port->dev, "%s(): submitting interrupt urb\n", __func__);
554         result = usb_submit_urb(port->interrupt_in_urb, GFP_KERNEL);
555         if (result != 0) {
556                 dev_err(&port->dev, "%s(): usb_submit_urb() failed with error %d\n",
557                         __func__, result);
558                 oti6858_close(port);
559                 return result;
560         }
561
562         /* setup termios */
563         if (tty)
564                 oti6858_set_termios(tty, port, &tmp_termios);
565         port->port.drain_delay = 256;   /* FIXME: check the FIFO length */
566         return 0;
567 }
568
569 static void oti6858_close(struct usb_serial_port *port)
570 {
571         struct oti6858_private *priv = usb_get_serial_port_data(port);
572         unsigned long flags;
573
574         spin_lock_irqsave(&port->lock, flags);
575         /* clear out any remaining data in the buffer */
576         kfifo_reset_out(&port->write_fifo);
577         spin_unlock_irqrestore(&port->lock, flags);
578
579         dev_dbg(&port->dev, "%s(): after buf_clear()\n", __func__);
580
581         /* cancel scheduled setup */
582         cancel_delayed_work_sync(&priv->delayed_setup_work);
583         cancel_delayed_work_sync(&priv->delayed_write_work);
584
585         /* shutdown our urbs */
586         dev_dbg(&port->dev, "%s(): shutting down urbs\n", __func__);
587         usb_kill_urb(port->write_urb);
588         usb_kill_urb(port->read_urb);
589         usb_kill_urb(port->interrupt_in_urb);
590 }
591
592 static int oti6858_tiocmset(struct tty_struct *tty,
593                                 unsigned int set, unsigned int clear)
594 {
595         struct usb_serial_port *port = tty->driver_data;
596         struct oti6858_private *priv = usb_get_serial_port_data(port);
597         unsigned long flags;
598         u8 control;
599
600         dev_dbg(&port->dev, "%s(set = 0x%08x, clear = 0x%08x)\n",
601                 __func__, set, clear);
602
603         /* FIXME: check if this is correct (active high/low) */
604         spin_lock_irqsave(&priv->lock, flags);
605         control = priv->pending_setup.control;
606         if ((set & TIOCM_RTS) != 0)
607                 control |= CONTROL_RTS_HIGH;
608         if ((set & TIOCM_DTR) != 0)
609                 control |= CONTROL_DTR_HIGH;
610         if ((clear & TIOCM_RTS) != 0)
611                 control &= ~CONTROL_RTS_HIGH;
612         if ((clear & TIOCM_DTR) != 0)
613                 control &= ~CONTROL_DTR_HIGH;
614
615         if (control != priv->pending_setup.control)
616                 priv->pending_setup.control = control;
617
618         spin_unlock_irqrestore(&priv->lock, flags);
619         return 0;
620 }
621
622 static int oti6858_tiocmget(struct tty_struct *tty)
623 {
624         struct usb_serial_port *port = tty->driver_data;
625         struct oti6858_private *priv = usb_get_serial_port_data(port);
626         unsigned long flags;
627         unsigned pin_state;
628         unsigned result = 0;
629
630         spin_lock_irqsave(&priv->lock, flags);
631         pin_state = priv->status.pin_state & PIN_MASK;
632         spin_unlock_irqrestore(&priv->lock, flags);
633
634         /* FIXME: check if this is correct (active high/low) */
635         if ((pin_state & PIN_RTS) != 0)
636                 result |= TIOCM_RTS;
637         if ((pin_state & PIN_CTS) != 0)
638                 result |= TIOCM_CTS;
639         if ((pin_state & PIN_DSR) != 0)
640                 result |= TIOCM_DSR;
641         if ((pin_state & PIN_DTR) != 0)
642                 result |= TIOCM_DTR;
643         if ((pin_state & PIN_RI) != 0)
644                 result |= TIOCM_RI;
645         if ((pin_state & PIN_DCD) != 0)
646                 result |= TIOCM_CD;
647
648         dev_dbg(&port->dev, "%s() = 0x%08x\n", __func__, result);
649
650         return result;
651 }
652
653 static int wait_modem_info(struct usb_serial_port *port, unsigned int arg)
654 {
655         struct oti6858_private *priv = usb_get_serial_port_data(port);
656         unsigned long flags;
657         unsigned int prev, status;
658         unsigned int changed;
659
660         spin_lock_irqsave(&priv->lock, flags);
661         prev = priv->status.pin_state;
662         spin_unlock_irqrestore(&priv->lock, flags);
663
664         while (1) {
665                 wait_event_interruptible(port->delta_msr_wait,
666                                         port->serial->disconnected ||
667                                         priv->status.pin_state != prev);
668                 if (signal_pending(current))
669                         return -ERESTARTSYS;
670
671                 if (port->serial->disconnected)
672                         return -EIO;
673
674                 spin_lock_irqsave(&priv->lock, flags);
675                 status = priv->status.pin_state & PIN_MASK;
676                 spin_unlock_irqrestore(&priv->lock, flags);
677
678                 changed = prev ^ status;
679                 /* FIXME: check if this is correct (active high/low) */
680                 if (((arg & TIOCM_RNG) && (changed & PIN_RI)) ||
681                     ((arg & TIOCM_DSR) && (changed & PIN_DSR)) ||
682                     ((arg & TIOCM_CD)  && (changed & PIN_DCD)) ||
683                     ((arg & TIOCM_CTS) && (changed & PIN_CTS)))
684                         return 0;
685                 prev = status;
686         }
687
688         /* NOTREACHED */
689         return 0;
690 }
691
692 static int oti6858_ioctl(struct tty_struct *tty,
693                         unsigned int cmd, unsigned long arg)
694 {
695         struct usb_serial_port *port = tty->driver_data;
696
697         dev_dbg(&port->dev, "%s(cmd = 0x%04x, arg = 0x%08lx)\n", __func__, cmd, arg);
698
699         switch (cmd) {
700         case TIOCMIWAIT:
701                 dev_dbg(&port->dev, "%s(): TIOCMIWAIT\n", __func__);
702                 return wait_modem_info(port, arg);
703         default:
704                 dev_dbg(&port->dev, "%s(): 0x%04x not supported\n", __func__, cmd);
705                 break;
706         }
707         return -ENOIOCTLCMD;
708 }
709
710 static void oti6858_read_int_callback(struct urb *urb)
711 {
712         struct usb_serial_port *port =  urb->context;
713         struct oti6858_private *priv = usb_get_serial_port_data(port);
714         int transient = 0, can_recv = 0, resubmit = 1;
715         int status = urb->status;
716
717         switch (status) {
718         case 0:
719                 /* success */
720                 break;
721         case -ECONNRESET:
722         case -ENOENT:
723         case -ESHUTDOWN:
724                 /* this urb is terminated, clean up */
725                 dev_dbg(&urb->dev->dev, "%s(): urb shutting down with status: %d\n",
726                         __func__, status);
727                 return;
728         default:
729                 dev_dbg(&urb->dev->dev, "%s(): nonzero urb status received: %d\n",
730                         __func__, status);
731                 break;
732         }
733
734         if (status == 0 && urb->actual_length == OTI6858_CTRL_PKT_SIZE) {
735                 struct oti6858_control_pkt *xs = urb->transfer_buffer;
736                 unsigned long flags;
737
738                 spin_lock_irqsave(&priv->lock, flags);
739
740                 if (!priv->transient) {
741                         if (!OTI6858_CTRL_EQUALS_PENDING(xs, priv)) {
742                                 if (xs->rx_bytes_avail == 0) {
743                                         priv->transient = 4;
744                                         priv->setup_done = 0;
745                                         resubmit = 0;
746                                         dev_dbg(&port->dev, "%s(): scheduling setup_line()\n", __func__);
747                                         schedule_delayed_work(&priv->delayed_setup_work, 0);
748                                 }
749                         }
750                 } else {
751                         if (OTI6858_CTRL_EQUALS_PENDING(xs, priv)) {
752                                 priv->transient = 0;
753                         } else if (!priv->setup_done) {
754                                 resubmit = 0;
755                         } else if (--priv->transient == 0) {
756                                 if (xs->rx_bytes_avail == 0) {
757                                         priv->transient = 4;
758                                         priv->setup_done = 0;
759                                         resubmit = 0;
760                                         dev_dbg(&port->dev, "%s(): scheduling setup_line()\n", __func__);
761                                         schedule_delayed_work(&priv->delayed_setup_work, 0);
762                                 }
763                         }
764                 }
765
766                 if (!priv->transient) {
767                         if (xs->pin_state != priv->status.pin_state)
768                                 wake_up_interruptible(&port->delta_msr_wait);
769                         memcpy(&priv->status, xs, OTI6858_CTRL_PKT_SIZE);
770                 }
771
772                 if (!priv->transient && xs->rx_bytes_avail != 0) {
773                         can_recv = xs->rx_bytes_avail;
774                         priv->flags.read_urb_in_use = 1;
775                 }
776
777                 transient = priv->transient;
778                 spin_unlock_irqrestore(&priv->lock, flags);
779         }
780
781         if (can_recv) {
782                 int result;
783
784                 result = usb_submit_urb(port->read_urb, GFP_ATOMIC);
785                 if (result != 0) {
786                         priv->flags.read_urb_in_use = 0;
787                         dev_err(&port->dev, "%s(): usb_submit_urb() failed,"
788                                         " error %d\n", __func__, result);
789                 } else {
790                         resubmit = 0;
791                 }
792         } else if (!transient) {
793                 unsigned long flags;
794                 int count;
795
796                 spin_lock_irqsave(&port->lock, flags);
797                 count = kfifo_len(&port->write_fifo);
798                 spin_unlock_irqrestore(&port->lock, flags);
799
800                 spin_lock_irqsave(&priv->lock, flags);
801                 if (priv->flags.write_urb_in_use == 0 && count != 0) {
802                         schedule_delayed_work(&priv->delayed_write_work, 0);
803                         resubmit = 0;
804                 }
805                 spin_unlock_irqrestore(&priv->lock, flags);
806         }
807
808         if (resubmit) {
809                 int result;
810
811 /*              dev_dbg(&urb->dev->dev, "%s(): submitting interrupt urb\n", __func__); */
812                 result = usb_submit_urb(urb, GFP_ATOMIC);
813                 if (result != 0) {
814                         dev_err(&urb->dev->dev,
815                                         "%s(): usb_submit_urb() failed with"
816                                         " error %d\n", __func__, result);
817                 }
818         }
819 }
820
821 static void oti6858_read_bulk_callback(struct urb *urb)
822 {
823         struct usb_serial_port *port =  urb->context;
824         struct oti6858_private *priv = usb_get_serial_port_data(port);
825         unsigned char *data = urb->transfer_buffer;
826         unsigned long flags;
827         int status = urb->status;
828         int result;
829
830         spin_lock_irqsave(&priv->lock, flags);
831         priv->flags.read_urb_in_use = 0;
832         spin_unlock_irqrestore(&priv->lock, flags);
833
834         if (status != 0) {
835                 dev_dbg(&urb->dev->dev, "%s(): unable to handle the error, exiting\n", __func__);
836                 return;
837         }
838
839         if (urb->actual_length > 0) {
840                 tty_insert_flip_string(&port->port, data, urb->actual_length);
841                 tty_flip_buffer_push(&port->port);
842         }
843
844         /* schedule the interrupt urb */
845         result = usb_submit_urb(port->interrupt_in_urb, GFP_ATOMIC);
846         if (result != 0 && result != -EPERM) {
847                 dev_err(&port->dev, "%s(): usb_submit_urb() failed,"
848                                 " error %d\n", __func__, result);
849         }
850 }
851
852 static void oti6858_write_bulk_callback(struct urb *urb)
853 {
854         struct usb_serial_port *port =  urb->context;
855         struct oti6858_private *priv = usb_get_serial_port_data(port);
856         int status = urb->status;
857         int result;
858
859         switch (status) {
860         case 0:
861                 /* success */
862                 break;
863         case -ECONNRESET:
864         case -ENOENT:
865         case -ESHUTDOWN:
866                 /* this urb is terminated, clean up */
867                 dev_dbg(&urb->dev->dev, "%s(): urb shutting down with status: %d\n", __func__, status);
868                 priv->flags.write_urb_in_use = 0;
869                 return;
870         default:
871                 /* error in the urb, so we have to resubmit it */
872                 dev_dbg(&urb->dev->dev, "%s(): nonzero write bulk status received: %d\n", __func__, status);
873                 dev_dbg(&urb->dev->dev, "%s(): overflow in write\n", __func__);
874
875                 port->write_urb->transfer_buffer_length = 1;
876                 result = usb_submit_urb(port->write_urb, GFP_ATOMIC);
877                 if (result) {
878                         dev_err_console(port, "%s(): usb_submit_urb() failed,"
879                                         " error %d\n", __func__, result);
880                 } else {
881                         return;
882                 }
883         }
884
885         priv->flags.write_urb_in_use = 0;
886
887         /* schedule the interrupt urb if we are still open */
888         dev_dbg(&port->dev, "%s(): submitting interrupt urb\n", __func__);
889         result = usb_submit_urb(port->interrupt_in_urb, GFP_ATOMIC);
890         if (result != 0) {
891                 dev_err(&port->dev, "%s(): failed submitting int urb,"
892                                         " error %d\n", __func__, result);
893         }
894 }
895
896 module_usb_serial_driver(serial_drivers, id_table);
897
898 MODULE_DESCRIPTION(OTI6858_DESCRIPTION);
899 MODULE_AUTHOR(OTI6858_AUTHOR);
900 MODULE_LICENSE("GPL");