USB: serial: cyberjack: fix NULL-deref at open
[pandora-kernel.git] / drivers / usb / serial / oti6858.c
1 /*
2  * Ours Technology Inc. OTi-6858 USB to serial adapter driver.
3  *
4  * Copyleft  (C) 2007 Kees Lemmens (adapted for kernel 2.6.20)
5  * Copyright (C) 2006 Tomasz Michal Lukaszewski (FIXME: add e-mail)
6  * Copyright (C) 2001-2004 Greg Kroah-Hartman (greg@kroah.com)
7  * Copyright (C) 2003 IBM Corp.
8  *
9  * Many thanks to the authors of pl2303 driver: all functions in this file
10  * are heavily based on pl2303 code, buffering code is a 1-to-1 copy.
11  *
12  * Warning! You use this driver on your own risk! The only official
13  * description of this device I have is datasheet from manufacturer,
14  * and it doesn't contain almost any information needed to write a driver.
15  * Almost all knowlegde used while writing this driver was gathered by:
16  *  - analyzing traffic between device and the M$ Windows 2000 driver,
17  *  - trying different bit combinations and checking pin states
18  *    with a voltmeter,
19  *  - receiving malformed frames and producing buffer overflows
20  *    to learn how errors are reported,
21  * So, THIS CODE CAN DESTROY OTi-6858 AND ANY OTHER DEVICES, THAT ARE
22  * CONNECTED TO IT!
23  *
24  * This program is free software; you can redistribute it and/or modify
25  * it under the terms of the GNU General Public License as published by
26  * the Free Software Foundation; either version 2 of the License.
27  *
28  * See Documentation/usb/usb-serial.txt for more information on using this
29  * driver
30  *
31  * TODO:
32  *  - implement correct flushing for ioctls and oti6858_close()
33  *  - check how errors (rx overflow, parity error, framing error) are reported
34  *  - implement oti6858_break_ctl()
35  *  - implement more ioctls
36  *  - test/implement flow control
37  *  - allow setting custom baud rates
38  */
39
40 #include <linux/kernel.h>
41 #include <linux/errno.h>
42 #include <linux/init.h>
43 #include <linux/slab.h>
44 #include <linux/tty.h>
45 #include <linux/tty_driver.h>
46 #include <linux/tty_flip.h>
47 #include <linux/serial.h>
48 #include <linux/module.h>
49 #include <linux/moduleparam.h>
50 #include <linux/spinlock.h>
51 #include <linux/usb.h>
52 #include <linux/usb/serial.h>
53 #include <linux/uaccess.h>
54 #include <linux/kfifo.h>
55 #include "oti6858.h"
56
57 #define OTI6858_DESCRIPTION \
58         "Ours Technology Inc. OTi-6858 USB to serial adapter driver"
59 #define OTI6858_AUTHOR "Tomasz Michal Lukaszewski <FIXME@FIXME>"
60 #define OTI6858_VERSION "0.2"
61
62 static const struct usb_device_id id_table[] = {
63         { USB_DEVICE(OTI6858_VENDOR_ID, OTI6858_PRODUCT_ID) },
64         { }
65 };
66
67 MODULE_DEVICE_TABLE(usb, id_table);
68
69 static struct usb_driver oti6858_driver = {
70         .name =         "oti6858",
71         .probe =        usb_serial_probe,
72         .disconnect =   usb_serial_disconnect,
73         .id_table =     id_table,
74         .no_dynamic_id =        1,
75 };
76
77 static int debug;
78
79 /* requests */
80 #define OTI6858_REQ_GET_STATUS          (USB_DIR_IN | USB_TYPE_VENDOR | 0x00)
81 #define OTI6858_REQ_T_GET_STATUS        0x01
82
83 #define OTI6858_REQ_SET_LINE            (USB_DIR_OUT | USB_TYPE_VENDOR | 0x00)
84 #define OTI6858_REQ_T_SET_LINE          0x00
85
86 #define OTI6858_REQ_CHECK_TXBUFF        (USB_DIR_IN | USB_TYPE_VENDOR | 0x01)
87 #define OTI6858_REQ_T_CHECK_TXBUFF      0x00
88
89 /* format of the control packet */
90 struct oti6858_control_pkt {
91         __le16  divisor;        /* baud rate = 96000000 / (16 * divisor), LE */
92 #define OTI6858_MAX_BAUD_RATE   3000000
93         u8      frame_fmt;
94 #define FMT_STOP_BITS_MASK      0xc0
95 #define FMT_STOP_BITS_1         0x00
96 #define FMT_STOP_BITS_2         0x40    /* 1.5 stop bits if FMT_DATA_BITS_5 */
97 #define FMT_PARITY_MASK         0x38
98 #define FMT_PARITY_NONE         0x00
99 #define FMT_PARITY_ODD          0x08
100 #define FMT_PARITY_EVEN         0x18
101 #define FMT_PARITY_MARK         0x28
102 #define FMT_PARITY_SPACE        0x38
103 #define FMT_DATA_BITS_MASK      0x03
104 #define FMT_DATA_BITS_5         0x00
105 #define FMT_DATA_BITS_6         0x01
106 #define FMT_DATA_BITS_7         0x02
107 #define FMT_DATA_BITS_8         0x03
108         u8      something;      /* always equals 0x43 */
109         u8      control;        /* settings of flow control lines */
110 #define CONTROL_MASK            0x0c
111 #define CONTROL_DTR_HIGH        0x08
112 #define CONTROL_RTS_HIGH        0x04
113         u8      tx_status;
114 #define TX_BUFFER_EMPTIED       0x09
115         u8      pin_state;
116 #define PIN_MASK                0x3f
117 #define PIN_RTS                 0x20    /* output pin */
118 #define PIN_CTS                 0x10    /* input pin, active low */
119 #define PIN_DSR                 0x08    /* input pin, active low */
120 #define PIN_DTR                 0x04    /* output pin */
121 #define PIN_RI                  0x02    /* input pin, active low */
122 #define PIN_DCD                 0x01    /* input pin, active low */
123         u8      rx_bytes_avail;         /* number of bytes in rx buffer */;
124 };
125
126 #define OTI6858_CTRL_PKT_SIZE   sizeof(struct oti6858_control_pkt)
127 #define OTI6858_CTRL_EQUALS_PENDING(a, priv) \
128         (((a)->divisor == (priv)->pending_setup.divisor) \
129           && ((a)->control == (priv)->pending_setup.control) \
130           && ((a)->frame_fmt == (priv)->pending_setup.frame_fmt))
131
132 /* function prototypes */
133 static int oti6858_open(struct tty_struct *tty, struct usb_serial_port *port);
134 static void oti6858_close(struct usb_serial_port *port);
135 static void oti6858_set_termios(struct tty_struct *tty,
136                         struct usb_serial_port *port, struct ktermios *old);
137 static void oti6858_init_termios(struct tty_struct *tty);
138 static int oti6858_ioctl(struct tty_struct *tty,
139                         unsigned int cmd, unsigned long arg);
140 static void oti6858_read_int_callback(struct urb *urb);
141 static void oti6858_read_bulk_callback(struct urb *urb);
142 static void oti6858_write_bulk_callback(struct urb *urb);
143 static int oti6858_write(struct tty_struct *tty, struct usb_serial_port *port,
144                         const unsigned char *buf, int count);
145 static int oti6858_write_room(struct tty_struct *tty);
146 static int oti6858_chars_in_buffer(struct tty_struct *tty);
147 static int oti6858_tiocmget(struct tty_struct *tty);
148 static int oti6858_tiocmset(struct tty_struct *tty,
149                                 unsigned int set, unsigned int clear);
150 static int oti6858_startup(struct usb_serial *serial);
151 static void oti6858_release(struct usb_serial *serial);
152
153 /* device info */
154 static struct usb_serial_driver oti6858_device = {
155         .driver = {
156                 .owner =        THIS_MODULE,
157                 .name =         "oti6858",
158         },
159         .id_table =             id_table,
160         .usb_driver =           &oti6858_driver,
161         .num_ports =            1,
162         .open =                 oti6858_open,
163         .close =                oti6858_close,
164         .write =                oti6858_write,
165         .ioctl =                oti6858_ioctl,
166         .set_termios =          oti6858_set_termios,
167         .init_termios =         oti6858_init_termios,
168         .tiocmget =             oti6858_tiocmget,
169         .tiocmset =             oti6858_tiocmset,
170         .read_bulk_callback =   oti6858_read_bulk_callback,
171         .read_int_callback =    oti6858_read_int_callback,
172         .write_bulk_callback =  oti6858_write_bulk_callback,
173         .write_room =           oti6858_write_room,
174         .chars_in_buffer =      oti6858_chars_in_buffer,
175         .attach =               oti6858_startup,
176         .release =              oti6858_release,
177 };
178
179 struct oti6858_private {
180         spinlock_t lock;
181
182         struct oti6858_control_pkt status;
183
184         struct {
185                 u8 read_urb_in_use;
186                 u8 write_urb_in_use;
187         } flags;
188         struct delayed_work delayed_write_work;
189
190         struct {
191                 __le16 divisor;
192                 u8 frame_fmt;
193                 u8 control;
194         } pending_setup;
195         u8 transient;
196         u8 setup_done;
197         struct delayed_work delayed_setup_work;
198
199         struct usb_serial_port *port;   /* USB port with which associated */
200 };
201
202 static void setup_line(struct work_struct *work)
203 {
204         struct oti6858_private *priv = container_of(work,
205                         struct oti6858_private, delayed_setup_work.work);
206         struct usb_serial_port *port = priv->port;
207         struct oti6858_control_pkt *new_setup;
208         unsigned long flags;
209         int result;
210
211         dbg("%s(port = %d)", __func__, port->number);
212
213         new_setup = kmalloc(OTI6858_CTRL_PKT_SIZE, GFP_KERNEL);
214         if (new_setup == NULL) {
215                 dev_err(&port->dev, "%s(): out of memory!\n", __func__);
216                 /* we will try again */
217                 schedule_delayed_work(&priv->delayed_setup_work,
218                                                 msecs_to_jiffies(2));
219                 return;
220         }
221
222         result = usb_control_msg(port->serial->dev,
223                                 usb_rcvctrlpipe(port->serial->dev, 0),
224                                 OTI6858_REQ_T_GET_STATUS,
225                                 OTI6858_REQ_GET_STATUS,
226                                 0, 0,
227                                 new_setup, OTI6858_CTRL_PKT_SIZE,
228                                 100);
229
230         if (result != OTI6858_CTRL_PKT_SIZE) {
231                 dev_err(&port->dev, "%s(): error reading status\n", __func__);
232                 kfree(new_setup);
233                 /* we will try again */
234                 schedule_delayed_work(&priv->delayed_setup_work,
235                                                         msecs_to_jiffies(2));
236                 return;
237         }
238
239         spin_lock_irqsave(&priv->lock, flags);
240         if (!OTI6858_CTRL_EQUALS_PENDING(new_setup, priv)) {
241                 new_setup->divisor = priv->pending_setup.divisor;
242                 new_setup->control = priv->pending_setup.control;
243                 new_setup->frame_fmt = priv->pending_setup.frame_fmt;
244
245                 spin_unlock_irqrestore(&priv->lock, flags);
246                 result = usb_control_msg(port->serial->dev,
247                                         usb_sndctrlpipe(port->serial->dev, 0),
248                                         OTI6858_REQ_T_SET_LINE,
249                                         OTI6858_REQ_SET_LINE,
250                                         0, 0,
251                                         new_setup, OTI6858_CTRL_PKT_SIZE,
252                                         100);
253         } else {
254                 spin_unlock_irqrestore(&priv->lock, flags);
255                 result = 0;
256         }
257         kfree(new_setup);
258
259         spin_lock_irqsave(&priv->lock, flags);
260         if (result != OTI6858_CTRL_PKT_SIZE)
261                 priv->transient = 0;
262         priv->setup_done = 1;
263         spin_unlock_irqrestore(&priv->lock, flags);
264
265         dbg("%s(): submitting interrupt urb", __func__);
266         port->interrupt_in_urb->dev = port->serial->dev;
267         result = usb_submit_urb(port->interrupt_in_urb, GFP_KERNEL);
268         if (result != 0) {
269                 dev_err(&port->dev, "%s(): usb_submit_urb() failed"
270                                 " with error %d\n", __func__, result);
271         }
272 }
273
274 static void send_data(struct work_struct *work)
275 {
276         struct oti6858_private *priv = container_of(work,
277                         struct oti6858_private, delayed_write_work.work);
278         struct usb_serial_port *port = priv->port;
279         int count = 0, result;
280         unsigned long flags;
281         u8 *allow;
282
283         dbg("%s(port = %d)", __func__, port->number);
284
285         spin_lock_irqsave(&priv->lock, flags);
286         if (priv->flags.write_urb_in_use) {
287                 spin_unlock_irqrestore(&priv->lock, flags);
288                 schedule_delayed_work(&priv->delayed_write_work,
289                                                 msecs_to_jiffies(2));
290                 return;
291         }
292         priv->flags.write_urb_in_use = 1;
293         spin_unlock_irqrestore(&priv->lock, flags);
294
295         spin_lock_irqsave(&port->lock, flags);
296         count = kfifo_len(&port->write_fifo);
297         spin_unlock_irqrestore(&port->lock, flags);
298
299         if (count > port->bulk_out_size)
300                 count = port->bulk_out_size;
301
302         if (count != 0) {
303                 allow = kmalloc(1, GFP_KERNEL);
304                 if (!allow) {
305                         dev_err(&port->dev, "%s(): kmalloc failed\n",
306                                         __func__);
307                         return;
308                 }
309                 result = usb_control_msg(port->serial->dev,
310                                 usb_rcvctrlpipe(port->serial->dev, 0),
311                                 OTI6858_REQ_T_CHECK_TXBUFF,
312                                 OTI6858_REQ_CHECK_TXBUFF,
313                                 count, 0, allow, 1, 100);
314                 if (result != 1 || *allow != 0)
315                         count = 0;
316                 kfree(allow);
317         }
318
319         if (count == 0) {
320                 priv->flags.write_urb_in_use = 0;
321
322                 dbg("%s(): submitting interrupt urb", __func__);
323                 port->interrupt_in_urb->dev = port->serial->dev;
324                 result = usb_submit_urb(port->interrupt_in_urb, GFP_NOIO);
325                 if (result != 0) {
326                         dev_err(&port->dev, "%s(): usb_submit_urb() failed"
327                                 " with error %d\n", __func__, result);
328                 }
329                 return;
330         }
331
332         count = kfifo_out_locked(&port->write_fifo,
333                                         port->write_urb->transfer_buffer,
334                                         count, &port->lock);
335         port->write_urb->transfer_buffer_length = count;
336         port->write_urb->dev = port->serial->dev;
337         result = usb_submit_urb(port->write_urb, GFP_NOIO);
338         if (result != 0) {
339                 dev_err(&port->dev, "%s(): usb_submit_urb() failed"
340                                " with error %d\n", __func__, result);
341                 priv->flags.write_urb_in_use = 0;
342         }
343
344         usb_serial_port_softint(port);
345 }
346
347 static int oti6858_startup(struct usb_serial *serial)
348 {
349         struct usb_serial_port *port = serial->port[0];
350         struct oti6858_private *priv;
351         int i;
352
353         for (i = 0; i < serial->num_ports; ++i) {
354                 priv = kzalloc(sizeof(struct oti6858_private), GFP_KERNEL);
355                 if (!priv)
356                         break;
357
358                 spin_lock_init(&priv->lock);
359 /*              INIT_WORK(&priv->setup_work, setup_line, serial->port[i]); */
360 /*              INIT_WORK(&priv->write_work, send_data, serial->port[i]); */
361                 priv->port = port;
362                 INIT_DELAYED_WORK(&priv->delayed_setup_work, setup_line);
363                 INIT_DELAYED_WORK(&priv->delayed_write_work, send_data);
364
365                 usb_set_serial_port_data(serial->port[i], priv);
366         }
367         if (i == serial->num_ports)
368                 return 0;
369
370         for (--i; i >= 0; --i) {
371                 priv = usb_get_serial_port_data(serial->port[i]);
372                 kfree(priv);
373                 usb_set_serial_port_data(serial->port[i], NULL);
374         }
375         return -ENOMEM;
376 }
377
378 static int oti6858_write(struct tty_struct *tty, struct usb_serial_port *port,
379                         const unsigned char *buf, int count)
380 {
381         dbg("%s(port = %d, count = %d)", __func__, port->number, count);
382
383         if (!count)
384                 return count;
385
386         count = kfifo_in_locked(&port->write_fifo, buf, count, &port->lock);
387
388         return count;
389 }
390
391 static int oti6858_write_room(struct tty_struct *tty)
392 {
393         struct usb_serial_port *port = tty->driver_data;
394         int room = 0;
395         unsigned long flags;
396
397         dbg("%s(port = %d)", __func__, port->number);
398
399         spin_lock_irqsave(&port->lock, flags);
400         room = kfifo_avail(&port->write_fifo);
401         spin_unlock_irqrestore(&port->lock, flags);
402
403         return room;
404 }
405
406 static int oti6858_chars_in_buffer(struct tty_struct *tty)
407 {
408         struct usb_serial_port *port = tty->driver_data;
409         int chars = 0;
410         unsigned long flags;
411
412         dbg("%s(port = %d)", __func__, port->number);
413
414         spin_lock_irqsave(&port->lock, flags);
415         chars = kfifo_len(&port->write_fifo);
416         spin_unlock_irqrestore(&port->lock, flags);
417
418         return chars;
419 }
420
421 static void oti6858_init_termios(struct tty_struct *tty)
422 {
423         *(tty->termios) = tty_std_termios;
424         tty->termios->c_cflag = B38400 | CS8 | CREAD | HUPCL | CLOCAL;
425         tty->termios->c_ispeed = 38400;
426         tty->termios->c_ospeed = 38400;
427 }
428
429 static void oti6858_set_termios(struct tty_struct *tty,
430                 struct usb_serial_port *port, struct ktermios *old_termios)
431 {
432         struct oti6858_private *priv = usb_get_serial_port_data(port);
433         unsigned long flags;
434         unsigned int cflag;
435         u8 frame_fmt, control;
436         __le16 divisor;
437         int br;
438
439         dbg("%s(port = %d)", __func__, port->number);
440
441         if (!tty) {
442                 dbg("%s(): no tty structures", __func__);
443                 return;
444         }
445
446         cflag = tty->termios->c_cflag;
447
448         spin_lock_irqsave(&priv->lock, flags);
449         divisor = priv->pending_setup.divisor;
450         frame_fmt = priv->pending_setup.frame_fmt;
451         control = priv->pending_setup.control;
452         spin_unlock_irqrestore(&priv->lock, flags);
453
454         frame_fmt &= ~FMT_DATA_BITS_MASK;
455         switch (cflag & CSIZE) {
456         case CS5:
457                 frame_fmt |= FMT_DATA_BITS_5;
458                 break;
459         case CS6:
460                 frame_fmt |= FMT_DATA_BITS_6;
461                 break;
462         case CS7:
463                 frame_fmt |= FMT_DATA_BITS_7;
464                 break;
465         default:
466         case CS8:
467                 frame_fmt |= FMT_DATA_BITS_8;
468                 break;
469         }
470
471         /* manufacturer claims that this device can work with baud rates
472          * up to 3 Mbps; I've tested it only on 115200 bps, so I can't
473          * guarantee that any other baud rate will work (especially
474          * the higher ones)
475          */
476         br = tty_get_baud_rate(tty);
477         if (br == 0) {
478                 divisor = 0;
479         } else {
480                 int real_br;
481                 int new_divisor;
482                 br = min(br, OTI6858_MAX_BAUD_RATE);
483
484                 new_divisor = (96000000 + 8 * br) / (16 * br);
485                 real_br = 96000000 / (16 * new_divisor);
486                 divisor = cpu_to_le16(new_divisor);
487                 tty_encode_baud_rate(tty, real_br, real_br);
488         }
489
490         frame_fmt &= ~FMT_STOP_BITS_MASK;
491         if ((cflag & CSTOPB) != 0)
492                 frame_fmt |= FMT_STOP_BITS_2;
493         else
494                 frame_fmt |= FMT_STOP_BITS_1;
495
496         frame_fmt &= ~FMT_PARITY_MASK;
497         if ((cflag & PARENB) != 0) {
498                 if ((cflag & PARODD) != 0)
499                         frame_fmt |= FMT_PARITY_ODD;
500                 else
501                         frame_fmt |= FMT_PARITY_EVEN;
502         } else {
503                 frame_fmt |= FMT_PARITY_NONE;
504         }
505
506         control &= ~CONTROL_MASK;
507         if ((cflag & CRTSCTS) != 0)
508                 control |= (CONTROL_DTR_HIGH | CONTROL_RTS_HIGH);
509
510         /* change control lines if we are switching to or from B0 */
511         /* FIXME:
512         spin_lock_irqsave(&priv->lock, flags);
513         control = priv->line_control;
514         if ((cflag & CBAUD) == B0)
515                 priv->line_control &= ~(CONTROL_DTR | CONTROL_RTS);
516         else
517                 priv->line_control |= (CONTROL_DTR | CONTROL_RTS);
518         if (control != priv->line_control) {
519                 control = priv->line_control;
520                 spin_unlock_irqrestore(&priv->lock, flags);
521                 set_control_lines(serial->dev, control);
522         } else {
523                 spin_unlock_irqrestore(&priv->lock, flags);
524         }
525         */
526
527         spin_lock_irqsave(&priv->lock, flags);
528         if (divisor != priv->pending_setup.divisor
529                         || control != priv->pending_setup.control
530                         || frame_fmt != priv->pending_setup.frame_fmt) {
531                 priv->pending_setup.divisor = divisor;
532                 priv->pending_setup.control = control;
533                 priv->pending_setup.frame_fmt = frame_fmt;
534         }
535         spin_unlock_irqrestore(&priv->lock, flags);
536 }
537
538 static int oti6858_open(struct tty_struct *tty, struct usb_serial_port *port)
539 {
540         struct oti6858_private *priv = usb_get_serial_port_data(port);
541         struct ktermios tmp_termios;
542         struct usb_serial *serial = port->serial;
543         struct oti6858_control_pkt *buf;
544         unsigned long flags;
545         int result;
546
547         dbg("%s(port = %d)", __func__, port->number);
548
549         usb_clear_halt(serial->dev, port->write_urb->pipe);
550         usb_clear_halt(serial->dev, port->read_urb->pipe);
551
552         buf = kmalloc(OTI6858_CTRL_PKT_SIZE, GFP_KERNEL);
553         if (buf == NULL) {
554                 dev_err(&port->dev, "%s(): out of memory!\n", __func__);
555                 return -ENOMEM;
556         }
557
558         result = usb_control_msg(serial->dev, usb_rcvctrlpipe(serial->dev, 0),
559                                 OTI6858_REQ_T_GET_STATUS,
560                                 OTI6858_REQ_GET_STATUS,
561                                 0, 0,
562                                 buf, OTI6858_CTRL_PKT_SIZE,
563                                 100);
564         if (result != OTI6858_CTRL_PKT_SIZE) {
565                 /* assume default (after power-on reset) values */
566                 buf->divisor = cpu_to_le16(0x009c);     /* 38400 bps */
567                 buf->frame_fmt = 0x03;  /* 8N1 */
568                 buf->something = 0x43;
569                 buf->control = 0x4c;    /* DTR, RTS */
570                 buf->tx_status = 0x00;
571                 buf->pin_state = 0x5b;  /* RTS, CTS, DSR, DTR, RI, DCD */
572                 buf->rx_bytes_avail = 0x00;
573         }
574
575         spin_lock_irqsave(&priv->lock, flags);
576         memcpy(&priv->status, buf, OTI6858_CTRL_PKT_SIZE);
577         priv->pending_setup.divisor = buf->divisor;
578         priv->pending_setup.frame_fmt = buf->frame_fmt;
579         priv->pending_setup.control = buf->control;
580         spin_unlock_irqrestore(&priv->lock, flags);
581         kfree(buf);
582
583         dbg("%s(): submitting interrupt urb", __func__);
584         port->interrupt_in_urb->dev = serial->dev;
585         result = usb_submit_urb(port->interrupt_in_urb, GFP_KERNEL);
586         if (result != 0) {
587                 dev_err(&port->dev, "%s(): usb_submit_urb() failed"
588                                " with error %d\n", __func__, result);
589                 oti6858_close(port);
590                 return -EPROTO;
591         }
592
593         /* setup termios */
594         if (tty)
595                 oti6858_set_termios(tty, port, &tmp_termios);
596         port->port.drain_delay = 256;   /* FIXME: check the FIFO length */
597         return 0;
598 }
599
600 static void oti6858_close(struct usb_serial_port *port)
601 {
602         struct oti6858_private *priv = usb_get_serial_port_data(port);
603         unsigned long flags;
604
605         dbg("%s(port = %d)", __func__, port->number);
606
607         spin_lock_irqsave(&port->lock, flags);
608         /* clear out any remaining data in the buffer */
609         kfifo_reset_out(&port->write_fifo);
610         spin_unlock_irqrestore(&port->lock, flags);
611
612         dbg("%s(): after buf_clear()", __func__);
613
614         /* cancel scheduled setup */
615         cancel_delayed_work_sync(&priv->delayed_setup_work);
616         cancel_delayed_work_sync(&priv->delayed_write_work);
617
618         /* shutdown our urbs */
619         dbg("%s(): shutting down urbs", __func__);
620         usb_kill_urb(port->write_urb);
621         usb_kill_urb(port->read_urb);
622         usb_kill_urb(port->interrupt_in_urb);
623 }
624
625 static int oti6858_tiocmset(struct tty_struct *tty,
626                                 unsigned int set, unsigned int clear)
627 {
628         struct usb_serial_port *port = tty->driver_data;
629         struct oti6858_private *priv = usb_get_serial_port_data(port);
630         unsigned long flags;
631         u8 control;
632
633         dbg("%s(port = %d, set = 0x%08x, clear = 0x%08x)",
634                                 __func__, port->number, set, clear);
635
636         if (!usb_get_intfdata(port->serial->interface))
637                 return -ENODEV;
638
639         /* FIXME: check if this is correct (active high/low) */
640         spin_lock_irqsave(&priv->lock, flags);
641         control = priv->pending_setup.control;
642         if ((set & TIOCM_RTS) != 0)
643                 control |= CONTROL_RTS_HIGH;
644         if ((set & TIOCM_DTR) != 0)
645                 control |= CONTROL_DTR_HIGH;
646         if ((clear & TIOCM_RTS) != 0)
647                 control &= ~CONTROL_RTS_HIGH;
648         if ((clear & TIOCM_DTR) != 0)
649                 control &= ~CONTROL_DTR_HIGH;
650
651         if (control != priv->pending_setup.control)
652                 priv->pending_setup.control = control;
653
654         spin_unlock_irqrestore(&priv->lock, flags);
655         return 0;
656 }
657
658 static int oti6858_tiocmget(struct tty_struct *tty)
659 {
660         struct usb_serial_port *port = tty->driver_data;
661         struct oti6858_private *priv = usb_get_serial_port_data(port);
662         unsigned long flags;
663         unsigned pin_state;
664         unsigned result = 0;
665
666         dbg("%s(port = %d)", __func__, port->number);
667
668         if (!usb_get_intfdata(port->serial->interface))
669                 return -ENODEV;
670
671         spin_lock_irqsave(&priv->lock, flags);
672         pin_state = priv->status.pin_state & PIN_MASK;
673         spin_unlock_irqrestore(&priv->lock, flags);
674
675         /* FIXME: check if this is correct (active high/low) */
676         if ((pin_state & PIN_RTS) != 0)
677                 result |= TIOCM_RTS;
678         if ((pin_state & PIN_CTS) != 0)
679                 result |= TIOCM_CTS;
680         if ((pin_state & PIN_DSR) != 0)
681                 result |= TIOCM_DSR;
682         if ((pin_state & PIN_DTR) != 0)
683                 result |= TIOCM_DTR;
684         if ((pin_state & PIN_RI) != 0)
685                 result |= TIOCM_RI;
686         if ((pin_state & PIN_DCD) != 0)
687                 result |= TIOCM_CD;
688
689         dbg("%s() = 0x%08x", __func__, result);
690
691         return result;
692 }
693
694 static int wait_modem_info(struct usb_serial_port *port, unsigned int arg)
695 {
696         struct oti6858_private *priv = usb_get_serial_port_data(port);
697         unsigned long flags;
698         unsigned int prev, status;
699         unsigned int changed;
700
701         spin_lock_irqsave(&priv->lock, flags);
702         prev = priv->status.pin_state;
703         spin_unlock_irqrestore(&priv->lock, flags);
704
705         while (1) {
706                 wait_event_interruptible(port->delta_msr_wait,
707                                         port->serial->disconnected ||
708                                         priv->status.pin_state != prev);
709                 if (signal_pending(current))
710                         return -ERESTARTSYS;
711
712                 if (port->serial->disconnected)
713                         return -EIO;
714
715                 spin_lock_irqsave(&priv->lock, flags);
716                 status = priv->status.pin_state & PIN_MASK;
717                 spin_unlock_irqrestore(&priv->lock, flags);
718
719                 changed = prev ^ status;
720                 /* FIXME: check if this is correct (active high/low) */
721                 if (((arg & TIOCM_RNG) && (changed & PIN_RI)) ||
722                     ((arg & TIOCM_DSR) && (changed & PIN_DSR)) ||
723                     ((arg & TIOCM_CD)  && (changed & PIN_DCD)) ||
724                     ((arg & TIOCM_CTS) && (changed & PIN_CTS)))
725                         return 0;
726                 prev = status;
727         }
728
729         /* NOTREACHED */
730         return 0;
731 }
732
733 static int oti6858_ioctl(struct tty_struct *tty,
734                         unsigned int cmd, unsigned long arg)
735 {
736         struct usb_serial_port *port = tty->driver_data;
737
738         dbg("%s(port = %d, cmd = 0x%04x, arg = 0x%08lx)",
739                                 __func__, port->number, cmd, arg);
740
741         switch (cmd) {
742         case TIOCMIWAIT:
743                 dbg("%s(): TIOCMIWAIT", __func__);
744                 return wait_modem_info(port, arg);
745         default:
746                 dbg("%s(): 0x%04x not supported", __func__, cmd);
747                 break;
748         }
749         return -ENOIOCTLCMD;
750 }
751
752
753 static void oti6858_release(struct usb_serial *serial)
754 {
755         int i;
756
757         dbg("%s()", __func__);
758
759         for (i = 0; i < serial->num_ports; ++i)
760                 kfree(usb_get_serial_port_data(serial->port[i]));
761 }
762
763 static void oti6858_read_int_callback(struct urb *urb)
764 {
765         struct usb_serial_port *port =  urb->context;
766         struct oti6858_private *priv = usb_get_serial_port_data(port);
767         int transient = 0, can_recv = 0, resubmit = 1;
768         int status = urb->status;
769
770         dbg("%s(port = %d, status = %d)",
771                                 __func__, port->number, status);
772
773         switch (status) {
774         case 0:
775                 /* success */
776                 break;
777         case -ECONNRESET:
778         case -ENOENT:
779         case -ESHUTDOWN:
780                 /* this urb is terminated, clean up */
781                 dbg("%s(): urb shutting down with status: %d",
782                                         __func__, status);
783                 return;
784         default:
785                 dbg("%s(): nonzero urb status received: %d",
786                                         __func__, status);
787                 break;
788         }
789
790         if (status == 0 && urb->actual_length == OTI6858_CTRL_PKT_SIZE) {
791                 struct oti6858_control_pkt *xs = urb->transfer_buffer;
792                 unsigned long flags;
793
794                 spin_lock_irqsave(&priv->lock, flags);
795
796                 if (!priv->transient) {
797                         if (!OTI6858_CTRL_EQUALS_PENDING(xs, priv)) {
798                                 if (xs->rx_bytes_avail == 0) {
799                                         priv->transient = 4;
800                                         priv->setup_done = 0;
801                                         resubmit = 0;
802                                         dbg("%s(): scheduling setup_line()",
803                                             __func__);
804                                         schedule_delayed_work(&priv->delayed_setup_work, 0);
805                                 }
806                         }
807                 } else {
808                         if (OTI6858_CTRL_EQUALS_PENDING(xs, priv)) {
809                                 priv->transient = 0;
810                         } else if (!priv->setup_done) {
811                                 resubmit = 0;
812                         } else if (--priv->transient == 0) {
813                                 if (xs->rx_bytes_avail == 0) {
814                                         priv->transient = 4;
815                                         priv->setup_done = 0;
816                                         resubmit = 0;
817                                         dbg("%s(): scheduling setup_line()",
818                                             __func__);
819                                         schedule_delayed_work(&priv->delayed_setup_work, 0);
820                                 }
821                         }
822                 }
823
824                 if (!priv->transient) {
825                         if (xs->pin_state != priv->status.pin_state)
826                                 wake_up_interruptible(&port->delta_msr_wait);
827                         memcpy(&priv->status, xs, OTI6858_CTRL_PKT_SIZE);
828                 }
829
830                 if (!priv->transient && xs->rx_bytes_avail != 0) {
831                         can_recv = xs->rx_bytes_avail;
832                         priv->flags.read_urb_in_use = 1;
833                 }
834
835                 transient = priv->transient;
836                 spin_unlock_irqrestore(&priv->lock, flags);
837         }
838
839         if (can_recv) {
840                 int result;
841
842                 port->read_urb->dev = port->serial->dev;
843                 result = usb_submit_urb(port->read_urb, GFP_ATOMIC);
844                 if (result != 0) {
845                         priv->flags.read_urb_in_use = 0;
846                         dev_err(&port->dev, "%s(): usb_submit_urb() failed,"
847                                         " error %d\n", __func__, result);
848                 } else {
849                         resubmit = 0;
850                 }
851         } else if (!transient) {
852                 unsigned long flags;
853                 int count;
854
855                 spin_lock_irqsave(&port->lock, flags);
856                 count = kfifo_len(&port->write_fifo);
857                 spin_unlock_irqrestore(&port->lock, flags);
858
859                 spin_lock_irqsave(&priv->lock, flags);
860                 if (priv->flags.write_urb_in_use == 0 && count != 0) {
861                         schedule_delayed_work(&priv->delayed_write_work, 0);
862                         resubmit = 0;
863                 }
864                 spin_unlock_irqrestore(&priv->lock, flags);
865         }
866
867         if (resubmit) {
868                 int result;
869
870 /*              dbg("%s(): submitting interrupt urb", __func__); */
871                 urb->dev = port->serial->dev;
872                 result = usb_submit_urb(urb, GFP_ATOMIC);
873                 if (result != 0) {
874                         dev_err(&urb->dev->dev,
875                                         "%s(): usb_submit_urb() failed with"
876                                         " error %d\n", __func__, result);
877                 }
878         }
879 }
880
881 static void oti6858_read_bulk_callback(struct urb *urb)
882 {
883         struct usb_serial_port *port =  urb->context;
884         struct oti6858_private *priv = usb_get_serial_port_data(port);
885         struct tty_struct *tty;
886         unsigned char *data = urb->transfer_buffer;
887         unsigned long flags;
888         int status = urb->status;
889         int result;
890
891         dbg("%s(port = %d, status = %d)",
892                                 __func__, port->number, status);
893
894         spin_lock_irqsave(&priv->lock, flags);
895         priv->flags.read_urb_in_use = 0;
896         spin_unlock_irqrestore(&priv->lock, flags);
897
898         if (status != 0) {
899                 /*
900                 if (status == -EPROTO) {
901                         * PL2303 mysteriously fails with -EPROTO reschedule
902                            the read *
903                         dbg("%s - caught -EPROTO, resubmitting the urb",
904                                                                 __func__);
905                         result = usb_submit_urb(urb, GFP_ATOMIC);
906                         if (result)
907                                 dev_err(&urb->dev->dev, "%s - failed resubmitting read urb, error %d\n", __func__, result);
908                         return;
909                 }
910                 */
911                 dbg("%s(): unable to handle the error, exiting", __func__);
912                 return;
913         }
914
915         tty = tty_port_tty_get(&port->port);
916         if (tty != NULL && urb->actual_length > 0) {
917                 tty_insert_flip_string(tty, data, urb->actual_length);
918                 tty_flip_buffer_push(tty);
919         }
920         tty_kref_put(tty);
921
922         /* schedule the interrupt urb */
923         port->interrupt_in_urb->dev = port->serial->dev;
924         result = usb_submit_urb(port->interrupt_in_urb, GFP_ATOMIC);
925         if (result != 0 && result != -EPERM) {
926                 dev_err(&port->dev, "%s(): usb_submit_urb() failed,"
927                                 " error %d\n", __func__, result);
928         }
929 }
930
931 static void oti6858_write_bulk_callback(struct urb *urb)
932 {
933         struct usb_serial_port *port =  urb->context;
934         struct oti6858_private *priv = usb_get_serial_port_data(port);
935         int status = urb->status;
936         int result;
937
938         dbg("%s(port = %d, status = %d)",
939                                 __func__, port->number, status);
940
941         switch (status) {
942         case 0:
943                 /* success */
944                 break;
945         case -ECONNRESET:
946         case -ENOENT:
947         case -ESHUTDOWN:
948                 /* this urb is terminated, clean up */
949                 dbg("%s(): urb shutting down with status: %d",
950                                         __func__, status);
951                 priv->flags.write_urb_in_use = 0;
952                 return;
953         default:
954                 /* error in the urb, so we have to resubmit it */
955                 dbg("%s(): nonzero write bulk status received: %d",
956                                         __func__, status);
957                 dbg("%s(): overflow in write", __func__);
958
959                 port->write_urb->transfer_buffer_length = 1;
960                 port->write_urb->dev = port->serial->dev;
961                 result = usb_submit_urb(port->write_urb, GFP_ATOMIC);
962                 if (result) {
963                         dev_err(&port->dev, "%s(): usb_submit_urb() failed,"
964                                         " error %d\n", __func__, result);
965                 } else {
966                         return;
967                 }
968         }
969
970         priv->flags.write_urb_in_use = 0;
971
972         /* schedule the interrupt urb if we are still open */
973         port->interrupt_in_urb->dev = port->serial->dev;
974         dbg("%s(): submitting interrupt urb", __func__);
975         result = usb_submit_urb(port->interrupt_in_urb, GFP_ATOMIC);
976         if (result != 0) {
977                 dev_err(&port->dev, "%s(): failed submitting int urb,"
978                                         " error %d\n", __func__, result);
979         }
980 }
981
982 /* module description and (de)initialization */
983
984 static int __init oti6858_init(void)
985 {
986         int retval;
987
988         retval = usb_serial_register(&oti6858_device);
989         if (retval == 0) {
990                 retval = usb_register(&oti6858_driver);
991                 if (retval)
992                         usb_serial_deregister(&oti6858_device);
993         }
994         return retval;
995 }
996
997 static void __exit oti6858_exit(void)
998 {
999         usb_deregister(&oti6858_driver);
1000         usb_serial_deregister(&oti6858_device);
1001 }
1002
1003 module_init(oti6858_init);
1004 module_exit(oti6858_exit);
1005
1006 MODULE_DESCRIPTION(OTI6858_DESCRIPTION);
1007 MODULE_AUTHOR(OTI6858_AUTHOR);
1008 MODULE_VERSION(OTI6858_VERSION);
1009 MODULE_LICENSE("GPL");
1010
1011 module_param(debug, bool, S_IRUGO | S_IWUSR);
1012 MODULE_PARM_DESC(debug, "enable debug output");
1013