679 lines · c
1/*2 * ipheth.c - Apple iPhone USB Ethernet driver3 *4 * Copyright (c) 2009 Diego Giagio <diego@giagio.com>5 * All rights reserved.6 *7 * Redistribution and use in source and binary forms, with or without8 * modification, are permitted provided that the following conditions9 * are met:10 * 1. Redistributions of source code must retain the above copyright11 * notice, this list of conditions and the following disclaimer.12 * 2. Redistributions in binary form must reproduce the above copyright13 * notice, this list of conditions and the following disclaimer in the14 * documentation and/or other materials provided with the distribution.15 * 3. Neither the name of GIAGIO.COM nor the names of its contributors16 * may be used to endorse or promote products derived from this software17 * without specific prior written permission.18 *19 * Alternatively, provided that this notice is retained in full, this20 * software may be distributed under the terms of the GNU General21 * Public License ("GPL") version 2, in which case the provisions of the22 * GPL apply INSTEAD OF those given above.23 *24 * The provided data structures and external interfaces from this code25 * are not restricted to be used by modules with a GPL compatible license.26 *27 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS28 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT29 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR30 * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT31 * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,32 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT33 * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,34 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY35 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT36 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE37 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH38 * DAMAGE.39 *40 *41 * Attention: iPhone device must be paired, otherwise it won't respond to our42 * driver. For more info: http://giagio.com/wiki/moin.cgi/iPhoneEthernetDriver43 *44 */45 46#include <linux/kernel.h>47#include <linux/errno.h>48#include <linux/slab.h>49#include <linux/module.h>50#include <linux/netdevice.h>51#include <linux/etherdevice.h>52#include <linux/ethtool.h>53#include <linux/usb.h>54#include <linux/workqueue.h>55#include <linux/usb/cdc.h>56 57#define USB_VENDOR_APPLE 0x05ac58 59#define IPHETH_USBINTF_CLASS 25560#define IPHETH_USBINTF_SUBCLASS 25361#define IPHETH_USBINTF_PROTO 162 63#define IPHETH_IP_ALIGN 2 /* padding at front of URB */64#define IPHETH_NCM_HEADER_SIZE (12 + 96) /* NCMH + NCM0 */65#define IPHETH_TX_BUF_SIZE ETH_FRAME_LEN66#define IPHETH_RX_BUF_SIZE_LEGACY (IPHETH_IP_ALIGN + ETH_FRAME_LEN)67#define IPHETH_RX_BUF_SIZE_NCM 6553668 69#define IPHETH_TX_TIMEOUT (5 * HZ)70 71#define IPHETH_INTFNUM 272#define IPHETH_ALT_INTFNUM 173 74#define IPHETH_CTRL_ENDP 0x0075#define IPHETH_CTRL_BUF_SIZE 0x4076#define IPHETH_CTRL_TIMEOUT (5 * HZ)77 78#define IPHETH_CMD_GET_MACADDR 0x0079#define IPHETH_CMD_ENABLE_NCM 0x0480#define IPHETH_CMD_CARRIER_CHECK 0x4581 82#define IPHETH_CARRIER_CHECK_TIMEOUT round_jiffies_relative(1 * HZ)83#define IPHETH_CARRIER_ON 0x0484 85static const struct usb_device_id ipheth_table[] = {86 { USB_VENDOR_AND_INTERFACE_INFO(USB_VENDOR_APPLE, IPHETH_USBINTF_CLASS,87 IPHETH_USBINTF_SUBCLASS,88 IPHETH_USBINTF_PROTO) },89 { }90};91MODULE_DEVICE_TABLE(usb, ipheth_table);92 93struct ipheth_device {94 struct usb_device *udev;95 struct usb_interface *intf;96 struct net_device *net;97 struct urb *tx_urb;98 struct urb *rx_urb;99 unsigned char *tx_buf;100 unsigned char *rx_buf;101 unsigned char *ctrl_buf;102 u8 bulk_in;103 u8 bulk_out;104 struct delayed_work carrier_work;105 bool confirmed_pairing;106 int (*rcvbulk_callback)(struct urb *urb);107 size_t rx_buf_len;108};109 110static int ipheth_rx_submit(struct ipheth_device *dev, gfp_t mem_flags);111 112static int ipheth_alloc_urbs(struct ipheth_device *iphone)113{114 struct urb *tx_urb = NULL;115 struct urb *rx_urb = NULL;116 u8 *tx_buf = NULL;117 u8 *rx_buf = NULL;118 119 tx_urb = usb_alloc_urb(0, GFP_KERNEL);120 if (tx_urb == NULL)121 goto error_nomem;122 123 rx_urb = usb_alloc_urb(0, GFP_KERNEL);124 if (rx_urb == NULL)125 goto free_tx_urb;126 127 tx_buf = usb_alloc_coherent(iphone->udev, IPHETH_TX_BUF_SIZE,128 GFP_KERNEL, &tx_urb->transfer_dma);129 if (tx_buf == NULL)130 goto free_rx_urb;131 132 rx_buf = usb_alloc_coherent(iphone->udev, iphone->rx_buf_len,133 GFP_KERNEL, &rx_urb->transfer_dma);134 if (rx_buf == NULL)135 goto free_tx_buf;136 137 138 iphone->tx_urb = tx_urb;139 iphone->rx_urb = rx_urb;140 iphone->tx_buf = tx_buf;141 iphone->rx_buf = rx_buf;142 return 0;143 144free_tx_buf:145 usb_free_coherent(iphone->udev, IPHETH_TX_BUF_SIZE, tx_buf,146 tx_urb->transfer_dma);147free_rx_urb:148 usb_free_urb(rx_urb);149free_tx_urb:150 usb_free_urb(tx_urb);151error_nomem:152 return -ENOMEM;153}154 155static void ipheth_free_urbs(struct ipheth_device *iphone)156{157 usb_free_coherent(iphone->udev, iphone->rx_buf_len, iphone->rx_buf,158 iphone->rx_urb->transfer_dma);159 usb_free_coherent(iphone->udev, IPHETH_TX_BUF_SIZE, iphone->tx_buf,160 iphone->tx_urb->transfer_dma);161 usb_free_urb(iphone->rx_urb);162 usb_free_urb(iphone->tx_urb);163}164 165static void ipheth_kill_urbs(struct ipheth_device *dev)166{167 usb_kill_urb(dev->tx_urb);168 usb_kill_urb(dev->rx_urb);169}170 171static int ipheth_consume_skb(char *buf, int len, struct ipheth_device *dev)172{173 struct sk_buff *skb;174 175 skb = dev_alloc_skb(len);176 if (!skb) {177 dev->net->stats.rx_dropped++;178 return -ENOMEM;179 }180 181 skb_put_data(skb, buf, len);182 skb->dev = dev->net;183 skb->protocol = eth_type_trans(skb, dev->net);184 185 dev->net->stats.rx_packets++;186 dev->net->stats.rx_bytes += len;187 netif_rx(skb);188 189 return 0;190}191 192static int ipheth_rcvbulk_callback_legacy(struct urb *urb)193{194 struct ipheth_device *dev;195 char *buf;196 int len;197 198 dev = urb->context;199 200 if (urb->actual_length <= IPHETH_IP_ALIGN) {201 dev->net->stats.rx_length_errors++;202 return -EINVAL;203 }204 len = urb->actual_length - IPHETH_IP_ALIGN;205 buf = urb->transfer_buffer + IPHETH_IP_ALIGN;206 207 return ipheth_consume_skb(buf, len, dev);208}209 210static int ipheth_rcvbulk_callback_ncm(struct urb *urb)211{212 struct usb_cdc_ncm_nth16 *ncmh;213 struct usb_cdc_ncm_ndp16 *ncm0;214 struct usb_cdc_ncm_dpe16 *dpe;215 struct ipheth_device *dev;216 int retval = -EINVAL;217 char *buf;218 int len;219 220 dev = urb->context;221 222 if (urb->actual_length < IPHETH_NCM_HEADER_SIZE) {223 dev->net->stats.rx_length_errors++;224 return retval;225 }226 227 ncmh = urb->transfer_buffer;228 if (ncmh->dwSignature != cpu_to_le32(USB_CDC_NCM_NTH16_SIGN) ||229 le16_to_cpu(ncmh->wNdpIndex) >= urb->actual_length) {230 dev->net->stats.rx_errors++;231 return retval;232 }233 234 ncm0 = urb->transfer_buffer + le16_to_cpu(ncmh->wNdpIndex);235 if (ncm0->dwSignature != cpu_to_le32(USB_CDC_NCM_NDP16_NOCRC_SIGN) ||236 le16_to_cpu(ncmh->wHeaderLength) + le16_to_cpu(ncm0->wLength) >=237 urb->actual_length) {238 dev->net->stats.rx_errors++;239 return retval;240 }241 242 dpe = ncm0->dpe16;243 while (le16_to_cpu(dpe->wDatagramIndex) != 0 &&244 le16_to_cpu(dpe->wDatagramLength) != 0) {245 if (le16_to_cpu(dpe->wDatagramIndex) >= urb->actual_length ||246 le16_to_cpu(dpe->wDatagramIndex) +247 le16_to_cpu(dpe->wDatagramLength) > urb->actual_length) {248 dev->net->stats.rx_length_errors++;249 return retval;250 }251 252 buf = urb->transfer_buffer + le16_to_cpu(dpe->wDatagramIndex);253 len = le16_to_cpu(dpe->wDatagramLength);254 255 retval = ipheth_consume_skb(buf, len, dev);256 if (retval != 0)257 return retval;258 259 dpe++;260 }261 262 return 0;263}264 265static void ipheth_rcvbulk_callback(struct urb *urb)266{267 struct ipheth_device *dev;268 int retval, status;269 270 dev = urb->context;271 if (dev == NULL)272 return;273 274 status = urb->status;275 switch (status) {276 case -ENOENT:277 case -ECONNRESET:278 case -ESHUTDOWN:279 case -EPROTO:280 return;281 case 0:282 break;283 default:284 dev_err(&dev->intf->dev, "%s: urb status: %d\n",285 __func__, status);286 return;287 }288 289 /* iPhone may periodically send URBs with no payload290 * on the "bulk in" endpoint. It is safe to ignore them.291 */292 if (urb->actual_length == 0)293 goto rx_submit;294 295 /* RX URBs starting with 0x00 0x01 do not encapsulate Ethernet frames,296 * but rather are control frames. Their purpose is not documented, and297 * they don't affect driver functionality, okay to drop them.298 * There is usually just one 4-byte control frame as the very first299 * URB received from the bulk IN endpoint.300 */301 if (unlikely302 (urb->actual_length == 4 &&303 ((char *)urb->transfer_buffer)[0] == 0 &&304 ((char *)urb->transfer_buffer)[1] == 1))305 goto rx_submit;306 307 retval = dev->rcvbulk_callback(urb);308 if (retval != 0) {309 dev_err(&dev->intf->dev, "%s: callback retval: %d\n",310 __func__, retval);311 }312 313rx_submit:314 dev->confirmed_pairing = true;315 ipheth_rx_submit(dev, GFP_ATOMIC);316}317 318static void ipheth_sndbulk_callback(struct urb *urb)319{320 struct ipheth_device *dev;321 int status = urb->status;322 323 dev = urb->context;324 if (dev == NULL)325 return;326 327 if (status != 0 &&328 status != -ENOENT &&329 status != -ECONNRESET &&330 status != -ESHUTDOWN)331 dev_err(&dev->intf->dev, "%s: urb status: %d\n",332 __func__, status);333 334 if (status == 0)335 netif_wake_queue(dev->net);336 else337 // on URB error, trigger immediate poll338 schedule_delayed_work(&dev->carrier_work, 0);339}340 341static int ipheth_carrier_set(struct ipheth_device *dev)342{343 struct usb_device *udev;344 int retval;345 346 if (!dev->confirmed_pairing)347 return 0;348 349 udev = dev->udev;350 retval = usb_control_msg(udev,351 usb_rcvctrlpipe(udev, IPHETH_CTRL_ENDP),352 IPHETH_CMD_CARRIER_CHECK, /* request */353 0xc0, /* request type */354 0x00, /* value */355 0x02, /* index */356 dev->ctrl_buf, IPHETH_CTRL_BUF_SIZE,357 IPHETH_CTRL_TIMEOUT);358 if (retval <= 0) {359 dev_err(&dev->intf->dev, "%s: usb_control_msg: %d\n",360 __func__, retval);361 return retval;362 }363 364 if ((retval == 1 && dev->ctrl_buf[0] == IPHETH_CARRIER_ON) ||365 (retval >= 2 && dev->ctrl_buf[1] == IPHETH_CARRIER_ON)) {366 netif_carrier_on(dev->net);367 if (dev->tx_urb->status != -EINPROGRESS)368 netif_wake_queue(dev->net);369 } else {370 netif_carrier_off(dev->net);371 netif_stop_queue(dev->net);372 }373 return 0;374}375 376static void ipheth_carrier_check_work(struct work_struct *work)377{378 struct ipheth_device *dev = container_of(work, struct ipheth_device,379 carrier_work.work);380 381 ipheth_carrier_set(dev);382 schedule_delayed_work(&dev->carrier_work, IPHETH_CARRIER_CHECK_TIMEOUT);383}384 385static int ipheth_get_macaddr(struct ipheth_device *dev)386{387 struct usb_device *udev = dev->udev;388 struct net_device *net = dev->net;389 int retval;390 391 retval = usb_control_msg(udev,392 usb_rcvctrlpipe(udev, IPHETH_CTRL_ENDP),393 IPHETH_CMD_GET_MACADDR, /* request */394 0xc0, /* request type */395 0x00, /* value */396 0x02, /* index */397 dev->ctrl_buf,398 IPHETH_CTRL_BUF_SIZE,399 IPHETH_CTRL_TIMEOUT);400 if (retval < 0) {401 dev_err(&dev->intf->dev, "%s: usb_control_msg: %d\n",402 __func__, retval);403 } else if (retval < ETH_ALEN) {404 dev_err(&dev->intf->dev,405 "%s: usb_control_msg: short packet: %d bytes\n",406 __func__, retval);407 retval = -EINVAL;408 } else {409 eth_hw_addr_set(net, dev->ctrl_buf);410 retval = 0;411 }412 413 return retval;414}415 416static int ipheth_enable_ncm(struct ipheth_device *dev)417{418 struct usb_device *udev = dev->udev;419 int retval;420 421 retval = usb_control_msg(udev,422 usb_sndctrlpipe(udev, IPHETH_CTRL_ENDP),423 IPHETH_CMD_ENABLE_NCM, /* request */424 0x41, /* request type */425 0x00, /* value */426 0x02, /* index */427 NULL,428 0,429 IPHETH_CTRL_TIMEOUT);430 431 dev_info(&dev->intf->dev, "%s: usb_control_msg: %d\n",432 __func__, retval);433 434 return retval;435}436 437static int ipheth_rx_submit(struct ipheth_device *dev, gfp_t mem_flags)438{439 struct usb_device *udev = dev->udev;440 int retval;441 442 usb_fill_bulk_urb(dev->rx_urb, udev,443 usb_rcvbulkpipe(udev, dev->bulk_in),444 dev->rx_buf, dev->rx_buf_len,445 ipheth_rcvbulk_callback,446 dev);447 dev->rx_urb->transfer_flags |= URB_NO_TRANSFER_DMA_MAP;448 449 retval = usb_submit_urb(dev->rx_urb, mem_flags);450 if (retval)451 dev_err(&dev->intf->dev, "%s: usb_submit_urb: %d\n",452 __func__, retval);453 return retval;454}455 456static int ipheth_open(struct net_device *net)457{458 struct ipheth_device *dev = netdev_priv(net);459 struct usb_device *udev = dev->udev;460 int retval = 0;461 462 usb_set_interface(udev, IPHETH_INTFNUM, IPHETH_ALT_INTFNUM);463 464 retval = ipheth_carrier_set(dev);465 if (retval)466 return retval;467 468 retval = ipheth_rx_submit(dev, GFP_KERNEL);469 if (retval)470 return retval;471 472 schedule_delayed_work(&dev->carrier_work, IPHETH_CARRIER_CHECK_TIMEOUT);473 return retval;474}475 476static int ipheth_close(struct net_device *net)477{478 struct ipheth_device *dev = netdev_priv(net);479 480 netif_stop_queue(net);481 cancel_delayed_work_sync(&dev->carrier_work);482 return 0;483}484 485static netdev_tx_t ipheth_tx(struct sk_buff *skb, struct net_device *net)486{487 struct ipheth_device *dev = netdev_priv(net);488 struct usb_device *udev = dev->udev;489 int retval;490 491 /* Paranoid */492 if (skb->len > IPHETH_TX_BUF_SIZE) {493 WARN(1, "%s: skb too large: %d bytes\n", __func__, skb->len);494 dev->net->stats.tx_dropped++;495 dev_kfree_skb_any(skb);496 return NETDEV_TX_OK;497 }498 499 memcpy(dev->tx_buf, skb->data, skb->len);500 501 usb_fill_bulk_urb(dev->tx_urb, udev,502 usb_sndbulkpipe(udev, dev->bulk_out),503 dev->tx_buf, skb->len,504 ipheth_sndbulk_callback,505 dev);506 dev->tx_urb->transfer_flags |= URB_NO_TRANSFER_DMA_MAP;507 508 netif_stop_queue(net);509 retval = usb_submit_urb(dev->tx_urb, GFP_ATOMIC);510 if (retval) {511 dev_err(&dev->intf->dev, "%s: usb_submit_urb: %d\n",512 __func__, retval);513 dev->net->stats.tx_errors++;514 dev_kfree_skb_any(skb);515 netif_wake_queue(net);516 } else {517 dev->net->stats.tx_packets++;518 dev->net->stats.tx_bytes += skb->len;519 dev_consume_skb_any(skb);520 }521 522 return NETDEV_TX_OK;523}524 525static void ipheth_tx_timeout(struct net_device *net, unsigned int txqueue)526{527 struct ipheth_device *dev = netdev_priv(net);528 529 dev_err(&dev->intf->dev, "%s: TX timeout\n", __func__);530 dev->net->stats.tx_errors++;531 usb_unlink_urb(dev->tx_urb);532}533 534static u32 ipheth_ethtool_op_get_link(struct net_device *net)535{536 struct ipheth_device *dev = netdev_priv(net);537 return netif_carrier_ok(dev->net);538}539 540static const struct ethtool_ops ops = {541 .get_link = ipheth_ethtool_op_get_link542};543 544static const struct net_device_ops ipheth_netdev_ops = {545 .ndo_open = ipheth_open,546 .ndo_stop = ipheth_close,547 .ndo_start_xmit = ipheth_tx,548 .ndo_tx_timeout = ipheth_tx_timeout,549};550 551static int ipheth_probe(struct usb_interface *intf,552 const struct usb_device_id *id)553{554 struct usb_device *udev = interface_to_usbdev(intf);555 struct usb_host_interface *hintf;556 struct usb_endpoint_descriptor *endp;557 struct ipheth_device *dev;558 struct net_device *netdev;559 int i;560 int retval;561 562 netdev = alloc_etherdev(sizeof(struct ipheth_device));563 if (!netdev)564 return -ENOMEM;565 566 netdev->netdev_ops = &ipheth_netdev_ops;567 netdev->watchdog_timeo = IPHETH_TX_TIMEOUT;568 strscpy(netdev->name, "eth%d", sizeof(netdev->name));569 570 dev = netdev_priv(netdev);571 dev->udev = udev;572 dev->net = netdev;573 dev->intf = intf;574 dev->confirmed_pairing = false;575 dev->rx_buf_len = IPHETH_RX_BUF_SIZE_LEGACY;576 dev->rcvbulk_callback = ipheth_rcvbulk_callback_legacy;577 /* Set up endpoints */578 hintf = usb_altnum_to_altsetting(intf, IPHETH_ALT_INTFNUM);579 if (hintf == NULL) {580 retval = -ENODEV;581 dev_err(&intf->dev, "Unable to find alternate settings interface\n");582 goto err_endpoints;583 }584 585 for (i = 0; i < hintf->desc.bNumEndpoints; i++) {586 endp = &hintf->endpoint[i].desc;587 if (usb_endpoint_is_bulk_in(endp))588 dev->bulk_in = endp->bEndpointAddress;589 else if (usb_endpoint_is_bulk_out(endp))590 dev->bulk_out = endp->bEndpointAddress;591 }592 if (!(dev->bulk_in && dev->bulk_out)) {593 retval = -ENODEV;594 dev_err(&intf->dev, "Unable to find endpoints\n");595 goto err_endpoints;596 }597 598 dev->ctrl_buf = kmalloc(IPHETH_CTRL_BUF_SIZE, GFP_KERNEL);599 if (dev->ctrl_buf == NULL) {600 retval = -ENOMEM;601 goto err_alloc_ctrl_buf;602 }603 604 retval = ipheth_get_macaddr(dev);605 if (retval)606 goto err_get_macaddr;607 608 retval = ipheth_enable_ncm(dev);609 if (!retval) {610 dev->rx_buf_len = IPHETH_RX_BUF_SIZE_NCM;611 dev->rcvbulk_callback = ipheth_rcvbulk_callback_ncm;612 }613 614 INIT_DELAYED_WORK(&dev->carrier_work, ipheth_carrier_check_work);615 616 retval = ipheth_alloc_urbs(dev);617 if (retval) {618 dev_err(&intf->dev, "error allocating urbs: %d\n", retval);619 goto err_alloc_urbs;620 }621 622 usb_set_intfdata(intf, dev);623 624 SET_NETDEV_DEV(netdev, &intf->dev);625 netdev->ethtool_ops = &ops;626 627 retval = register_netdev(netdev);628 if (retval) {629 dev_err(&intf->dev, "error registering netdev: %d\n", retval);630 retval = -EIO;631 goto err_register_netdev;632 }633 // carrier down and transmit queues stopped until packet from device634 netif_carrier_off(netdev);635 netif_tx_stop_all_queues(netdev);636 dev_info(&intf->dev, "Apple iPhone USB Ethernet device attached\n");637 return 0;638 639err_register_netdev:640 ipheth_free_urbs(dev);641err_alloc_urbs:642err_get_macaddr:643 kfree(dev->ctrl_buf);644err_alloc_ctrl_buf:645err_endpoints:646 free_netdev(netdev);647 return retval;648}649 650static void ipheth_disconnect(struct usb_interface *intf)651{652 struct ipheth_device *dev;653 654 dev = usb_get_intfdata(intf);655 if (dev != NULL) {656 unregister_netdev(dev->net);657 ipheth_kill_urbs(dev);658 ipheth_free_urbs(dev);659 kfree(dev->ctrl_buf);660 free_netdev(dev->net);661 }662 usb_set_intfdata(intf, NULL);663 dev_info(&intf->dev, "Apple iPhone USB Ethernet now disconnected\n");664}665 666static struct usb_driver ipheth_driver = {667 .name = "ipheth",668 .probe = ipheth_probe,669 .disconnect = ipheth_disconnect,670 .id_table = ipheth_table,671 .disable_hub_initiated_lpm = 1,672};673 674module_usb_driver(ipheth_driver);675 676MODULE_AUTHOR("Diego Giagio <diego@giagio.com>");677MODULE_DESCRIPTION("Apple iPhone USB Ethernet driver");678MODULE_LICENSE("Dual BSD/GPL");679