USB: serial: oti6858: fix NULL-deref at open
[pandora-kernel.git] / drivers / usb / serial / oti6858.c
1 /*
2  * Ours Technology Inc. OTi-6858 USB to serial adapter driver.
3  *
4  * Copyleft  (C) 2007 Kees Lemmens (adapted for kernel 2.6.20)
5  * Copyright (C) 2006 Tomasz Michal Lukaszewski (FIXME: add e-mail)
6  * Copyright (C) 2001-2004 Greg Kroah-Hartman (greg@kroah.com)
7  * Copyright (C) 2003 IBM Corp.
8  *
9  * Many thanks to the authors of pl2303 driver: all functions in this file
10  * are heavily based on pl2303 code, buffering code is a 1-to-1 copy.
11  *
12  * Warning! You use this driver on your own risk! The only official
13  * description of this device I have is datasheet from manufacturer,
14  * and it doesn't contain almost any information needed to write a driver.
15  * Almost all knowlegde used while writing this driver was gathered by:
16  *  - analyzing traffic between device and the M$ Windows 2000 driver,
17  *  - trying different bit combinations and checking pin states
18  *    with a voltmeter,
19  *  - receiving malformed frames and producing buffer overflows
20  *    to learn how errors are reported,
21  * So, THIS CODE CAN DESTROY OTi-6858 AND ANY OTHER DEVICES, THAT ARE
22  * CONNECTED TO IT!
23  *
24  * This program is free software; you can redistribute it and/or modify
25  * it under the terms of the GNU General Public License as published by
26  * the Free Software Foundation; either version 2 of the License.
27  *
28  * See Documentation/usb/usb-serial.txt for more information on using this
29  * driver
30  *
31  * TODO:
32  *  - implement correct flushing for ioctls and oti6858_close()
33  *  - check how errors (rx overflow, parity error, framing error) are reported
34  *  - implement oti6858_break_ctl()
35  *  - implement more ioctls
36  *  - test/implement flow control
37  *  - allow setting custom baud rates
38  */
39
40 #include <linux/kernel.h>
41 #include <linux/errno.h>
42 #include <linux/init.h>
43 #include <linux/slab.h>
44 #include <linux/tty.h>
45 #include <linux/tty_driver.h>
46 #include <linux/tty_flip.h>
47 #include <linux/serial.h>
48 #include <linux/module.h>
49 #include <linux/moduleparam.h>
50 #include <linux/spinlock.h>
51 #include <linux/usb.h>
52 #include <linux/usb/serial.h>
53 #include <linux/uaccess.h>
54 #include <linux/kfifo.h>
55 #include "oti6858.h"
56
57 #define OTI6858_DESCRIPTION \
58         "Ours Technology Inc. OTi-6858 USB to serial adapter driver"
59 #define OTI6858_AUTHOR "Tomasz Michal Lukaszewski <FIXME@FIXME>"
60 #define OTI6858_VERSION "0.2"
61
62 static const struct usb_device_id id_table[] = {
63         { USB_DEVICE(OTI6858_VENDOR_ID, OTI6858_PRODUCT_ID) },
64         { }
65 };
66
67 MODULE_DEVICE_TABLE(usb, id_table);
68
69 static struct usb_driver oti6858_driver = {
70         .name =         "oti6858",
71         .probe =        usb_serial_probe,
72         .disconnect =   usb_serial_disconnect,
73         .id_table =     id_table,
74         .no_dynamic_id =        1,
75 };
76
77 static int debug;
78
79 /* requests */
80 #define OTI6858_REQ_GET_STATUS          (USB_DIR_IN | USB_TYPE_VENDOR | 0x00)
81 #define OTI6858_REQ_T_GET_STATUS        0x01
82
83 #define OTI6858_REQ_SET_LINE            (USB_DIR_OUT | USB_TYPE_VENDOR | 0x00)
84 #define OTI6858_REQ_T_SET_LINE          0x00
85
86 #define OTI6858_REQ_CHECK_TXBUFF        (USB_DIR_IN | USB_TYPE_VENDOR | 0x01)
87 #define OTI6858_REQ_T_CHECK_TXBUFF      0x00
88
89 /* format of the control packet */
90 struct oti6858_control_pkt {
91         __le16  divisor;        /* baud rate = 96000000 / (16 * divisor), LE */
92 #define OTI6858_MAX_BAUD_RATE   3000000
93         u8      frame_fmt;
94 #define FMT_STOP_BITS_MASK      0xc0
95 #define FMT_STOP_BITS_1         0x00
96 #define FMT_STOP_BITS_2         0x40    /* 1.5 stop bits if FMT_DATA_BITS_5 */
97 #define FMT_PARITY_MASK         0x38
98 #define FMT_PARITY_NONE         0x00
99 #define FMT_PARITY_ODD          0x08
100 #define FMT_PARITY_EVEN         0x18
101 #define FMT_PARITY_MARK         0x28
102 #define FMT_PARITY_SPACE        0x38
103 #define FMT_DATA_BITS_MASK      0x03
104 #define FMT_DATA_BITS_5         0x00
105 #define FMT_DATA_BITS_6         0x01
106 #define FMT_DATA_BITS_7         0x02
107 #define FMT_DATA_BITS_8         0x03
108         u8      something;      /* always equals 0x43 */
109         u8      control;        /* settings of flow control lines */
110 #define CONTROL_MASK            0x0c
111 #define CONTROL_DTR_HIGH        0x08
112 #define CONTROL_RTS_HIGH        0x04
113         u8      tx_status;
114 #define TX_BUFFER_EMPTIED       0x09
115         u8      pin_state;
116 #define PIN_MASK                0x3f
117 #define PIN_RTS                 0x20    /* output pin */
118 #define PIN_CTS                 0x10    /* input pin, active low */
119 #define PIN_DSR                 0x08    /* input pin, active low */
120 #define PIN_DTR                 0x04    /* output pin */
121 #define PIN_RI                  0x02    /* input pin, active low */
122 #define PIN_DCD                 0x01    /* input pin, active low */
123         u8      rx_bytes_avail;         /* number of bytes in rx buffer */;
124 };
125
126 #define OTI6858_CTRL_PKT_SIZE   sizeof(struct oti6858_control_pkt)
127 #define OTI6858_CTRL_EQUALS_PENDING(a, priv) \
128         (((a)->divisor == (priv)->pending_setup.divisor) \
129           && ((a)->control == (priv)->pending_setup.control) \
130           && ((a)->frame_fmt == (priv)->pending_setup.frame_fmt))
131
132 /* function prototypes */
133 static int oti6858_open(struct tty_struct *tty, struct usb_serial_port *port);
134 static void oti6858_close(struct usb_serial_port *port);
135 static void oti6858_set_termios(struct tty_struct *tty,
136                         struct usb_serial_port *port, struct ktermios *old);
137 static void oti6858_init_termios(struct tty_struct *tty);
138 static int oti6858_ioctl(struct tty_struct *tty,
139                         unsigned int cmd, unsigned long arg);
140 static void oti6858_read_int_callback(struct urb *urb);
141 static void oti6858_read_bulk_callback(struct urb *urb);
142 static void oti6858_write_bulk_callback(struct urb *urb);
143 static int oti6858_write(struct tty_struct *tty, struct usb_serial_port *port,
144                         const unsigned char *buf, int count);
145 static int oti6858_write_room(struct tty_struct *tty);
146 static int oti6858_chars_in_buffer(struct tty_struct *tty);
147 static int oti6858_tiocmget(struct tty_struct *tty);
148 static int oti6858_tiocmset(struct tty_struct *tty,
149                                 unsigned int set, unsigned int clear);
150 static int oti6858_startup(struct usb_serial *serial);
151 static void oti6858_release(struct usb_serial *serial);
152
153 /* device info */
154 static struct usb_serial_driver oti6858_device = {
155         .driver = {
156                 .owner =        THIS_MODULE,
157                 .name =         "oti6858",
158         },
159         .id_table =             id_table,
160         .usb_driver =           &oti6858_driver,
161         .num_ports =            1,
162         .open =                 oti6858_open,
163         .close =                oti6858_close,
164         .write =                oti6858_write,
165         .ioctl =                oti6858_ioctl,
166         .set_termios =          oti6858_set_termios,
167         .init_termios =         oti6858_init_termios,
168         .tiocmget =             oti6858_tiocmget,
169         .tiocmset =             oti6858_tiocmset,
170         .read_bulk_callback =   oti6858_read_bulk_callback,
171         .read_int_callback =    oti6858_read_int_callback,
172         .write_bulk_callback =  oti6858_write_bulk_callback,
173         .write_room =           oti6858_write_room,
174         .chars_in_buffer =      oti6858_chars_in_buffer,
175         .attach =               oti6858_startup,
176         .release =              oti6858_release,
177 };
178
179 struct oti6858_private {
180         spinlock_t lock;
181
182         struct oti6858_control_pkt status;
183
184         struct {
185                 u8 read_urb_in_use;
186                 u8 write_urb_in_use;
187         } flags;
188         struct delayed_work delayed_write_work;
189
190         struct {
191                 __le16 divisor;
192                 u8 frame_fmt;
193                 u8 control;
194         } pending_setup;
195         u8 transient;
196         u8 setup_done;
197         struct delayed_work delayed_setup_work;
198
199         struct usb_serial_port *port;   /* USB port with which associated */
200 };
201
202 static void setup_line(struct work_struct *work)
203 {
204         struct oti6858_private *priv = container_of(work,
205                         struct oti6858_private, delayed_setup_work.work);
206         struct usb_serial_port *port = priv->port;
207         struct oti6858_control_pkt *new_setup;
208         unsigned long flags;
209         int result;
210
211         dbg("%s(port = %d)", __func__, port->number);
212
213         new_setup = kmalloc(OTI6858_CTRL_PKT_SIZE, GFP_KERNEL);
214         if (new_setup == NULL) {
215                 dev_err(&port->dev, "%s(): out of memory!\n", __func__);
216                 /* we will try again */
217                 schedule_delayed_work(&priv->delayed_setup_work,
218                                                 msecs_to_jiffies(2));
219                 return;
220         }
221
222         result = usb_control_msg(port->serial->dev,
223                                 usb_rcvctrlpipe(port->serial->dev, 0),
224                                 OTI6858_REQ_T_GET_STATUS,
225                                 OTI6858_REQ_GET_STATUS,
226                                 0, 0,
227                                 new_setup, OTI6858_CTRL_PKT_SIZE,
228                                 100);
229
230         if (result != OTI6858_CTRL_PKT_SIZE) {
231                 dev_err(&port->dev, "%s(): error reading status\n", __func__);
232                 kfree(new_setup);
233                 /* we will try again */
234                 schedule_delayed_work(&priv->delayed_setup_work,
235                                                         msecs_to_jiffies(2));
236                 return;
237         }
238
239         spin_lock_irqsave(&priv->lock, flags);
240         if (!OTI6858_CTRL_EQUALS_PENDING(new_setup, priv)) {
241                 new_setup->divisor = priv->pending_setup.divisor;
242                 new_setup->control = priv->pending_setup.control;
243                 new_setup->frame_fmt = priv->pending_setup.frame_fmt;
244
245                 spin_unlock_irqrestore(&priv->lock, flags);
246                 result = usb_control_msg(port->serial->dev,
247                                         usb_sndctrlpipe(port->serial->dev, 0),
248                                         OTI6858_REQ_T_SET_LINE,
249                                         OTI6858_REQ_SET_LINE,
250                                         0, 0,
251                                         new_setup, OTI6858_CTRL_PKT_SIZE,
252                                         100);
253         } else {
254                 spin_unlock_irqrestore(&priv->lock, flags);
255                 result = 0;
256         }
257         kfree(new_setup);
258
259         spin_lock_irqsave(&priv->lock, flags);
260         if (result != OTI6858_CTRL_PKT_SIZE)
261                 priv->transient = 0;
262         priv->setup_done = 1;
263         spin_unlock_irqrestore(&priv->lock, flags);
264
265         dbg("%s(): submitting interrupt urb", __func__);
266         port->interrupt_in_urb->dev = port->serial->dev;
267         result = usb_submit_urb(port->interrupt_in_urb, GFP_KERNEL);
268         if (result != 0) {
269                 dev_err(&port->dev, "%s(): usb_submit_urb() failed"
270                                 " with error %d\n", __func__, result);
271         }
272 }
273
274 static void send_data(struct work_struct *work)
275 {
276         struct oti6858_private *priv = container_of(work,
277                         struct oti6858_private, delayed_write_work.work);
278         struct usb_serial_port *port = priv->port;
279         int count = 0, result;
280         unsigned long flags;
281         u8 *allow;
282
283         dbg("%s(port = %d)", __func__, port->number);
284
285         spin_lock_irqsave(&priv->lock, flags);
286         if (priv->flags.write_urb_in_use) {
287                 spin_unlock_irqrestore(&priv->lock, flags);
288                 schedule_delayed_work(&priv->delayed_write_work,
289                                                 msecs_to_jiffies(2));
290                 return;
291         }
292         priv->flags.write_urb_in_use = 1;
293         spin_unlock_irqrestore(&priv->lock, flags);
294
295         spin_lock_irqsave(&port->lock, flags);
296         count = kfifo_len(&port->write_fifo);
297         spin_unlock_irqrestore(&port->lock, flags);
298
299         if (count > port->bulk_out_size)
300                 count = port->bulk_out_size;
301
302         if (count != 0) {
303                 allow = kmalloc(1, GFP_KERNEL);
304                 if (!allow) {
305                         dev_err(&port->dev, "%s(): kmalloc failed\n",
306                                         __func__);
307                         return;
308                 }
309                 result = usb_control_msg(port->serial->dev,
310                                 usb_rcvctrlpipe(port->serial->dev, 0),
311                                 OTI6858_REQ_T_CHECK_TXBUFF,
312                                 OTI6858_REQ_CHECK_TXBUFF,
313                                 count, 0, allow, 1, 100);
314                 if (result != 1 || *allow != 0)
315                         count = 0;
316                 kfree(allow);
317         }
318
319         if (count == 0) {
320                 priv->flags.write_urb_in_use = 0;
321
322                 dbg("%s(): submitting interrupt urb", __func__);
323                 port->interrupt_in_urb->dev = port->serial->dev;
324                 result = usb_submit_urb(port->interrupt_in_urb, GFP_NOIO);
325                 if (result != 0) {
326                         dev_err(&port->dev, "%s(): usb_submit_urb() failed"
327                                 " with error %d\n", __func__, result);
328                 }
329                 return;
330         }
331
332         count = kfifo_out_locked(&port->write_fifo,
333                                         port->write_urb->transfer_buffer,
334                                         count, &port->lock);
335         port->write_urb->transfer_buffer_length = count;
336         port->write_urb->dev = port->serial->dev;
337         result = usb_submit_urb(port->write_urb, GFP_NOIO);
338         if (result != 0) {
339                 dev_err(&port->dev, "%s(): usb_submit_urb() failed"
340                                " with error %d\n", __func__, result);
341                 priv->flags.write_urb_in_use = 0;
342         }
343
344         usb_serial_port_softint(port);
345 }
346
347 static int oti6858_startup(struct usb_serial *serial)
348 {
349         struct usb_serial_port *port = serial->port[0];
350         unsigned char num_ports = serial->num_ports;
351         struct oti6858_private *priv;
352         int i;
353
354         if (serial->num_bulk_in < num_ports ||
355                         serial->num_bulk_out < num_ports ||
356                         serial->num_interrupt_in < num_ports) {
357                 dev_err(&serial->interface->dev, "missing endpoints\n");
358                 return -ENODEV;
359         }
360
361         for (i = 0; i < serial->num_ports; ++i) {
362                 priv = kzalloc(sizeof(struct oti6858_private), GFP_KERNEL);
363                 if (!priv)
364                         break;
365
366                 spin_lock_init(&priv->lock);
367 /*              INIT_WORK(&priv->setup_work, setup_line, serial->port[i]); */
368 /*              INIT_WORK(&priv->write_work, send_data, serial->port[i]); */
369                 priv->port = port;
370                 INIT_DELAYED_WORK(&priv->delayed_setup_work, setup_line);
371                 INIT_DELAYED_WORK(&priv->delayed_write_work, send_data);
372
373                 usb_set_serial_port_data(serial->port[i], priv);
374         }
375         if (i == serial->num_ports)
376                 return 0;
377
378         for (--i; i >= 0; --i) {
379                 priv = usb_get_serial_port_data(serial->port[i]);
380                 kfree(priv);
381                 usb_set_serial_port_data(serial->port[i], NULL);
382         }
383         return -ENOMEM;
384 }
385
386 static int oti6858_write(struct tty_struct *tty, struct usb_serial_port *port,
387                         const unsigned char *buf, int count)
388 {
389         dbg("%s(port = %d, count = %d)", __func__, port->number, count);
390
391         if (!count)
392                 return count;
393
394         count = kfifo_in_locked(&port->write_fifo, buf, count, &port->lock);
395
396         return count;
397 }
398
399 static int oti6858_write_room(struct tty_struct *tty)
400 {
401         struct usb_serial_port *port = tty->driver_data;
402         int room = 0;
403         unsigned long flags;
404
405         dbg("%s(port = %d)", __func__, port->number);
406
407         spin_lock_irqsave(&port->lock, flags);
408         room = kfifo_avail(&port->write_fifo);
409         spin_unlock_irqrestore(&port->lock, flags);
410
411         return room;
412 }
413
414 static int oti6858_chars_in_buffer(struct tty_struct *tty)
415 {
416         struct usb_serial_port *port = tty->driver_data;
417         int chars = 0;
418         unsigned long flags;
419
420         dbg("%s(port = %d)", __func__, port->number);
421
422         spin_lock_irqsave(&port->lock, flags);
423         chars = kfifo_len(&port->write_fifo);
424         spin_unlock_irqrestore(&port->lock, flags);
425
426         return chars;
427 }
428
429 static void oti6858_init_termios(struct tty_struct *tty)
430 {
431         *(tty->termios) = tty_std_termios;
432         tty->termios->c_cflag = B38400 | CS8 | CREAD | HUPCL | CLOCAL;
433         tty->termios->c_ispeed = 38400;
434         tty->termios->c_ospeed = 38400;
435 }
436
437 static void oti6858_set_termios(struct tty_struct *tty,
438                 struct usb_serial_port *port, struct ktermios *old_termios)
439 {
440         struct oti6858_private *priv = usb_get_serial_port_data(port);
441         unsigned long flags;
442         unsigned int cflag;
443         u8 frame_fmt, control;
444         __le16 divisor;
445         int br;
446
447         dbg("%s(port = %d)", __func__, port->number);
448
449         if (!tty) {
450                 dbg("%s(): no tty structures", __func__);
451                 return;
452         }
453
454         cflag = tty->termios->c_cflag;
455
456         spin_lock_irqsave(&priv->lock, flags);
457         divisor = priv->pending_setup.divisor;
458         frame_fmt = priv->pending_setup.frame_fmt;
459         control = priv->pending_setup.control;
460         spin_unlock_irqrestore(&priv->lock, flags);
461
462         frame_fmt &= ~FMT_DATA_BITS_MASK;
463         switch (cflag & CSIZE) {
464         case CS5:
465                 frame_fmt |= FMT_DATA_BITS_5;
466                 break;
467         case CS6:
468                 frame_fmt |= FMT_DATA_BITS_6;
469                 break;
470         case CS7:
471                 frame_fmt |= FMT_DATA_BITS_7;
472                 break;
473         default:
474         case CS8:
475                 frame_fmt |= FMT_DATA_BITS_8;
476                 break;
477         }
478
479         /* manufacturer claims that this device can work with baud rates
480          * up to 3 Mbps; I've tested it only on 115200 bps, so I can't
481          * guarantee that any other baud rate will work (especially
482          * the higher ones)
483          */
484         br = tty_get_baud_rate(tty);
485         if (br == 0) {
486                 divisor = 0;
487         } else {
488                 int real_br;
489                 int new_divisor;
490                 br = min(br, OTI6858_MAX_BAUD_RATE);
491
492                 new_divisor = (96000000 + 8 * br) / (16 * br);
493                 real_br = 96000000 / (16 * new_divisor);
494                 divisor = cpu_to_le16(new_divisor);
495                 tty_encode_baud_rate(tty, real_br, real_br);
496         }
497
498         frame_fmt &= ~FMT_STOP_BITS_MASK;
499         if ((cflag & CSTOPB) != 0)
500                 frame_fmt |= FMT_STOP_BITS_2;
501         else
502                 frame_fmt |= FMT_STOP_BITS_1;
503
504         frame_fmt &= ~FMT_PARITY_MASK;
505         if ((cflag & PARENB) != 0) {
506                 if ((cflag & PARODD) != 0)
507                         frame_fmt |= FMT_PARITY_ODD;
508                 else
509                         frame_fmt |= FMT_PARITY_EVEN;
510         } else {
511                 frame_fmt |= FMT_PARITY_NONE;
512         }
513
514         control &= ~CONTROL_MASK;
515         if ((cflag & CRTSCTS) != 0)
516                 control |= (CONTROL_DTR_HIGH | CONTROL_RTS_HIGH);
517
518         /* change control lines if we are switching to or from B0 */
519         /* FIXME:
520         spin_lock_irqsave(&priv->lock, flags);
521         control = priv->line_control;
522         if ((cflag & CBAUD) == B0)
523                 priv->line_control &= ~(CONTROL_DTR | CONTROL_RTS);
524         else
525                 priv->line_control |= (CONTROL_DTR | CONTROL_RTS);
526         if (control != priv->line_control) {
527                 control = priv->line_control;
528                 spin_unlock_irqrestore(&priv->lock, flags);
529                 set_control_lines(serial->dev, control);
530         } else {
531                 spin_unlock_irqrestore(&priv->lock, flags);
532         }
533         */
534
535         spin_lock_irqsave(&priv->lock, flags);
536         if (divisor != priv->pending_setup.divisor
537                         || control != priv->pending_setup.control
538                         || frame_fmt != priv->pending_setup.frame_fmt) {
539                 priv->pending_setup.divisor = divisor;
540                 priv->pending_setup.control = control;
541                 priv->pending_setup.frame_fmt = frame_fmt;
542         }
543         spin_unlock_irqrestore(&priv->lock, flags);
544 }
545
546 static int oti6858_open(struct tty_struct *tty, struct usb_serial_port *port)
547 {
548         struct oti6858_private *priv = usb_get_serial_port_data(port);
549         struct ktermios tmp_termios;
550         struct usb_serial *serial = port->serial;
551         struct oti6858_control_pkt *buf;
552         unsigned long flags;
553         int result;
554
555         dbg("%s(port = %d)", __func__, port->number);
556
557         usb_clear_halt(serial->dev, port->write_urb->pipe);
558         usb_clear_halt(serial->dev, port->read_urb->pipe);
559
560         buf = kmalloc(OTI6858_CTRL_PKT_SIZE, GFP_KERNEL);
561         if (buf == NULL) {
562                 dev_err(&port->dev, "%s(): out of memory!\n", __func__);
563                 return -ENOMEM;
564         }
565
566         result = usb_control_msg(serial->dev, usb_rcvctrlpipe(serial->dev, 0),
567                                 OTI6858_REQ_T_GET_STATUS,
568                                 OTI6858_REQ_GET_STATUS,
569                                 0, 0,
570                                 buf, OTI6858_CTRL_PKT_SIZE,
571                                 100);
572         if (result != OTI6858_CTRL_PKT_SIZE) {
573                 /* assume default (after power-on reset) values */
574                 buf->divisor = cpu_to_le16(0x009c);     /* 38400 bps */
575                 buf->frame_fmt = 0x03;  /* 8N1 */
576                 buf->something = 0x43;
577                 buf->control = 0x4c;    /* DTR, RTS */
578                 buf->tx_status = 0x00;
579                 buf->pin_state = 0x5b;  /* RTS, CTS, DSR, DTR, RI, DCD */
580                 buf->rx_bytes_avail = 0x00;
581         }
582
583         spin_lock_irqsave(&priv->lock, flags);
584         memcpy(&priv->status, buf, OTI6858_CTRL_PKT_SIZE);
585         priv->pending_setup.divisor = buf->divisor;
586         priv->pending_setup.frame_fmt = buf->frame_fmt;
587         priv->pending_setup.control = buf->control;
588         spin_unlock_irqrestore(&priv->lock, flags);
589         kfree(buf);
590
591         dbg("%s(): submitting interrupt urb", __func__);
592         port->interrupt_in_urb->dev = serial->dev;
593         result = usb_submit_urb(port->interrupt_in_urb, GFP_KERNEL);
594         if (result != 0) {
595                 dev_err(&port->dev, "%s(): usb_submit_urb() failed"
596                                " with error %d\n", __func__, result);
597                 oti6858_close(port);
598                 return -EPROTO;
599         }
600
601         /* setup termios */
602         if (tty)
603                 oti6858_set_termios(tty, port, &tmp_termios);
604         port->port.drain_delay = 256;   /* FIXME: check the FIFO length */
605         return 0;
606 }
607
608 static void oti6858_close(struct usb_serial_port *port)
609 {
610         struct oti6858_private *priv = usb_get_serial_port_data(port);
611         unsigned long flags;
612
613         dbg("%s(port = %d)", __func__, port->number);
614
615         spin_lock_irqsave(&port->lock, flags);
616         /* clear out any remaining data in the buffer */
617         kfifo_reset_out(&port->write_fifo);
618         spin_unlock_irqrestore(&port->lock, flags);
619
620         dbg("%s(): after buf_clear()", __func__);
621
622         /* cancel scheduled setup */
623         cancel_delayed_work_sync(&priv->delayed_setup_work);
624         cancel_delayed_work_sync(&priv->delayed_write_work);
625
626         /* shutdown our urbs */
627         dbg("%s(): shutting down urbs", __func__);
628         usb_kill_urb(port->write_urb);
629         usb_kill_urb(port->read_urb);
630         usb_kill_urb(port->interrupt_in_urb);
631 }
632
633 static int oti6858_tiocmset(struct tty_struct *tty,
634                                 unsigned int set, unsigned int clear)
635 {
636         struct usb_serial_port *port = tty->driver_data;
637         struct oti6858_private *priv = usb_get_serial_port_data(port);
638         unsigned long flags;
639         u8 control;
640
641         dbg("%s(port = %d, set = 0x%08x, clear = 0x%08x)",
642                                 __func__, port->number, set, clear);
643
644         if (!usb_get_intfdata(port->serial->interface))
645                 return -ENODEV;
646
647         /* FIXME: check if this is correct (active high/low) */
648         spin_lock_irqsave(&priv->lock, flags);
649         control = priv->pending_setup.control;
650         if ((set & TIOCM_RTS) != 0)
651                 control |= CONTROL_RTS_HIGH;
652         if ((set & TIOCM_DTR) != 0)
653                 control |= CONTROL_DTR_HIGH;
654         if ((clear & TIOCM_RTS) != 0)
655                 control &= ~CONTROL_RTS_HIGH;
656         if ((clear & TIOCM_DTR) != 0)
657                 control &= ~CONTROL_DTR_HIGH;
658
659         if (control != priv->pending_setup.control)
660                 priv->pending_setup.control = control;
661
662         spin_unlock_irqrestore(&priv->lock, flags);
663         return 0;
664 }
665
666 static int oti6858_tiocmget(struct tty_struct *tty)
667 {
668         struct usb_serial_port *port = tty->driver_data;
669         struct oti6858_private *priv = usb_get_serial_port_data(port);
670         unsigned long flags;
671         unsigned pin_state;
672         unsigned result = 0;
673
674         dbg("%s(port = %d)", __func__, port->number);
675
676         if (!usb_get_intfdata(port->serial->interface))
677                 return -ENODEV;
678
679         spin_lock_irqsave(&priv->lock, flags);
680         pin_state = priv->status.pin_state & PIN_MASK;
681         spin_unlock_irqrestore(&priv->lock, flags);
682
683         /* FIXME: check if this is correct (active high/low) */
684         if ((pin_state & PIN_RTS) != 0)
685                 result |= TIOCM_RTS;
686         if ((pin_state & PIN_CTS) != 0)
687                 result |= TIOCM_CTS;
688         if ((pin_state & PIN_DSR) != 0)
689                 result |= TIOCM_DSR;
690         if ((pin_state & PIN_DTR) != 0)
691                 result |= TIOCM_DTR;
692         if ((pin_state & PIN_RI) != 0)
693                 result |= TIOCM_RI;
694         if ((pin_state & PIN_DCD) != 0)
695                 result |= TIOCM_CD;
696
697         dbg("%s() = 0x%08x", __func__, result);
698
699         return result;
700 }
701
702 static int wait_modem_info(struct usb_serial_port *port, unsigned int arg)
703 {
704         struct oti6858_private *priv = usb_get_serial_port_data(port);
705         unsigned long flags;
706         unsigned int prev, status;
707         unsigned int changed;
708
709         spin_lock_irqsave(&priv->lock, flags);
710         prev = priv->status.pin_state;
711         spin_unlock_irqrestore(&priv->lock, flags);
712
713         while (1) {
714                 wait_event_interruptible(port->delta_msr_wait,
715                                         port->serial->disconnected ||
716                                         priv->status.pin_state != prev);
717                 if (signal_pending(current))
718                         return -ERESTARTSYS;
719
720                 if (port->serial->disconnected)
721                         return -EIO;
722
723                 spin_lock_irqsave(&priv->lock, flags);
724                 status = priv->status.pin_state & PIN_MASK;
725                 spin_unlock_irqrestore(&priv->lock, flags);
726
727                 changed = prev ^ status;
728                 /* FIXME: check if this is correct (active high/low) */
729                 if (((arg & TIOCM_RNG) && (changed & PIN_RI)) ||
730                     ((arg & TIOCM_DSR) && (changed & PIN_DSR)) ||
731                     ((arg & TIOCM_CD)  && (changed & PIN_DCD)) ||
732                     ((arg & TIOCM_CTS) && (changed & PIN_CTS)))
733                         return 0;
734                 prev = status;
735         }
736
737         /* NOTREACHED */
738         return 0;
739 }
740
741 static int oti6858_ioctl(struct tty_struct *tty,
742                         unsigned int cmd, unsigned long arg)
743 {
744         struct usb_serial_port *port = tty->driver_data;
745
746         dbg("%s(port = %d, cmd = 0x%04x, arg = 0x%08lx)",
747                                 __func__, port->number, cmd, arg);
748
749         switch (cmd) {
750         case TIOCMIWAIT:
751                 dbg("%s(): TIOCMIWAIT", __func__);
752                 return wait_modem_info(port, arg);
753         default:
754                 dbg("%s(): 0x%04x not supported", __func__, cmd);
755                 break;
756         }
757         return -ENOIOCTLCMD;
758 }
759
760
761 static void oti6858_release(struct usb_serial *serial)
762 {
763         int i;
764
765         dbg("%s()", __func__);
766
767         for (i = 0; i < serial->num_ports; ++i)
768                 kfree(usb_get_serial_port_data(serial->port[i]));
769 }
770
771 static void oti6858_read_int_callback(struct urb *urb)
772 {
773         struct usb_serial_port *port =  urb->context;
774         struct oti6858_private *priv = usb_get_serial_port_data(port);
775         int transient = 0, can_recv = 0, resubmit = 1;
776         int status = urb->status;
777
778         dbg("%s(port = %d, status = %d)",
779                                 __func__, port->number, status);
780
781         switch (status) {
782         case 0:
783                 /* success */
784                 break;
785         case -ECONNRESET:
786         case -ENOENT:
787         case -ESHUTDOWN:
788                 /* this urb is terminated, clean up */
789                 dbg("%s(): urb shutting down with status: %d",
790                                         __func__, status);
791                 return;
792         default:
793                 dbg("%s(): nonzero urb status received: %d",
794                                         __func__, status);
795                 break;
796         }
797
798         if (status == 0 && urb->actual_length == OTI6858_CTRL_PKT_SIZE) {
799                 struct oti6858_control_pkt *xs = urb->transfer_buffer;
800                 unsigned long flags;
801
802                 spin_lock_irqsave(&priv->lock, flags);
803
804                 if (!priv->transient) {
805                         if (!OTI6858_CTRL_EQUALS_PENDING(xs, priv)) {
806                                 if (xs->rx_bytes_avail == 0) {
807                                         priv->transient = 4;
808                                         priv->setup_done = 0;
809                                         resubmit = 0;
810                                         dbg("%s(): scheduling setup_line()",
811                                             __func__);
812                                         schedule_delayed_work(&priv->delayed_setup_work, 0);
813                                 }
814                         }
815                 } else {
816                         if (OTI6858_CTRL_EQUALS_PENDING(xs, priv)) {
817                                 priv->transient = 0;
818                         } else if (!priv->setup_done) {
819                                 resubmit = 0;
820                         } else if (--priv->transient == 0) {
821                                 if (xs->rx_bytes_avail == 0) {
822                                         priv->transient = 4;
823                                         priv->setup_done = 0;
824                                         resubmit = 0;
825                                         dbg("%s(): scheduling setup_line()",
826                                             __func__);
827                                         schedule_delayed_work(&priv->delayed_setup_work, 0);
828                                 }
829                         }
830                 }
831
832                 if (!priv->transient) {
833                         if (xs->pin_state != priv->status.pin_state)
834                                 wake_up_interruptible(&port->delta_msr_wait);
835                         memcpy(&priv->status, xs, OTI6858_CTRL_PKT_SIZE);
836                 }
837
838                 if (!priv->transient && xs->rx_bytes_avail != 0) {
839                         can_recv = xs->rx_bytes_avail;
840                         priv->flags.read_urb_in_use = 1;
841                 }
842
843                 transient = priv->transient;
844                 spin_unlock_irqrestore(&priv->lock, flags);
845         }
846
847         if (can_recv) {
848                 int result;
849
850                 port->read_urb->dev = port->serial->dev;
851                 result = usb_submit_urb(port->read_urb, GFP_ATOMIC);
852                 if (result != 0) {
853                         priv->flags.read_urb_in_use = 0;
854                         dev_err(&port->dev, "%s(): usb_submit_urb() failed,"
855                                         " error %d\n", __func__, result);
856                 } else {
857                         resubmit = 0;
858                 }
859         } else if (!transient) {
860                 unsigned long flags;
861                 int count;
862
863                 spin_lock_irqsave(&port->lock, flags);
864                 count = kfifo_len(&port->write_fifo);
865                 spin_unlock_irqrestore(&port->lock, flags);
866
867                 spin_lock_irqsave(&priv->lock, flags);
868                 if (priv->flags.write_urb_in_use == 0 && count != 0) {
869                         schedule_delayed_work(&priv->delayed_write_work, 0);
870                         resubmit = 0;
871                 }
872                 spin_unlock_irqrestore(&priv->lock, flags);
873         }
874
875         if (resubmit) {
876                 int result;
877
878 /*              dbg("%s(): submitting interrupt urb", __func__); */
879                 urb->dev = port->serial->dev;
880                 result = usb_submit_urb(urb, GFP_ATOMIC);
881                 if (result != 0) {
882                         dev_err(&urb->dev->dev,
883                                         "%s(): usb_submit_urb() failed with"
884                                         " error %d\n", __func__, result);
885                 }
886         }
887 }
888
889 static void oti6858_read_bulk_callback(struct urb *urb)
890 {
891         struct usb_serial_port *port =  urb->context;
892         struct oti6858_private *priv = usb_get_serial_port_data(port);
893         struct tty_struct *tty;
894         unsigned char *data = urb->transfer_buffer;
895         unsigned long flags;
896         int status = urb->status;
897         int result;
898
899         dbg("%s(port = %d, status = %d)",
900                                 __func__, port->number, status);
901
902         spin_lock_irqsave(&priv->lock, flags);
903         priv->flags.read_urb_in_use = 0;
904         spin_unlock_irqrestore(&priv->lock, flags);
905
906         if (status != 0) {
907                 /*
908                 if (status == -EPROTO) {
909                         * PL2303 mysteriously fails with -EPROTO reschedule
910                            the read *
911                         dbg("%s - caught -EPROTO, resubmitting the urb",
912                                                                 __func__);
913                         result = usb_submit_urb(urb, GFP_ATOMIC);
914                         if (result)
915                                 dev_err(&urb->dev->dev, "%s - failed resubmitting read urb, error %d\n", __func__, result);
916                         return;
917                 }
918                 */
919                 dbg("%s(): unable to handle the error, exiting", __func__);
920                 return;
921         }
922
923         tty = tty_port_tty_get(&port->port);
924         if (tty != NULL && urb->actual_length > 0) {
925                 tty_insert_flip_string(tty, data, urb->actual_length);
926                 tty_flip_buffer_push(tty);
927         }
928         tty_kref_put(tty);
929
930         /* schedule the interrupt urb */
931         port->interrupt_in_urb->dev = port->serial->dev;
932         result = usb_submit_urb(port->interrupt_in_urb, GFP_ATOMIC);
933         if (result != 0 && result != -EPERM) {
934                 dev_err(&port->dev, "%s(): usb_submit_urb() failed,"
935                                 " error %d\n", __func__, result);
936         }
937 }
938
939 static void oti6858_write_bulk_callback(struct urb *urb)
940 {
941         struct usb_serial_port *port =  urb->context;
942         struct oti6858_private *priv = usb_get_serial_port_data(port);
943         int status = urb->status;
944         int result;
945
946         dbg("%s(port = %d, status = %d)",
947                                 __func__, port->number, status);
948
949         switch (status) {
950         case 0:
951                 /* success */
952                 break;
953         case -ECONNRESET:
954         case -ENOENT:
955         case -ESHUTDOWN:
956                 /* this urb is terminated, clean up */
957                 dbg("%s(): urb shutting down with status: %d",
958                                         __func__, status);
959                 priv->flags.write_urb_in_use = 0;
960                 return;
961         default:
962                 /* error in the urb, so we have to resubmit it */
963                 dbg("%s(): nonzero write bulk status received: %d",
964                                         __func__, status);
965                 dbg("%s(): overflow in write", __func__);
966
967                 port->write_urb->transfer_buffer_length = 1;
968                 port->write_urb->dev = port->serial->dev;
969                 result = usb_submit_urb(port->write_urb, GFP_ATOMIC);
970                 if (result) {
971                         dev_err(&port->dev, "%s(): usb_submit_urb() failed,"
972                                         " error %d\n", __func__, result);
973                 } else {
974                         return;
975                 }
976         }
977
978         priv->flags.write_urb_in_use = 0;
979
980         /* schedule the interrupt urb if we are still open */
981         port->interrupt_in_urb->dev = port->serial->dev;
982         dbg("%s(): submitting interrupt urb", __func__);
983         result = usb_submit_urb(port->interrupt_in_urb, GFP_ATOMIC);
984         if (result != 0) {
985                 dev_err(&port->dev, "%s(): failed submitting int urb,"
986                                         " error %d\n", __func__, result);
987         }
988 }
989
990 /* module description and (de)initialization */
991
992 static int __init oti6858_init(void)
993 {
994         int retval;
995
996         retval = usb_serial_register(&oti6858_device);
997         if (retval == 0) {
998                 retval = usb_register(&oti6858_driver);
999                 if (retval)
1000                         usb_serial_deregister(&oti6858_device);
1001         }
1002         return retval;
1003 }
1004
1005 static void __exit oti6858_exit(void)
1006 {
1007         usb_deregister(&oti6858_driver);
1008         usb_serial_deregister(&oti6858_device);
1009 }
1010
1011 module_init(oti6858_init);
1012 module_exit(oti6858_exit);
1013
1014 MODULE_DESCRIPTION(OTI6858_DESCRIPTION);
1015 MODULE_AUTHOR(OTI6858_AUTHOR);
1016 MODULE_VERSION(OTI6858_VERSION);
1017 MODULE_LICENSE("GPL");
1018
1019 module_param(debug, bool, S_IRUGO | S_IWUSR);
1020 MODULE_PARM_DESC(debug, "enable debug output");
1021