smp_br_main.cc 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361
  1. /******************************************************************************
  2. *
  3. * Copyright 2014-2015 Broadcom Corporation
  4. *
  5. * Licensed under the Apache License, Version 2.0 (the "License");
  6. * you may not use this file except in compliance with the License.
  7. * You may obtain a copy of the License at:
  8. *
  9. * http://www.apache.org/licenses/LICENSE-2.0
  10. *
  11. * Unless required by applicable law or agreed to in writing, software
  12. * distributed under the License is distributed on an "AS IS" BASIS,
  13. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. * See the License for the specific language governing permissions and
  15. * limitations under the License.
  16. *
  17. ******************************************************************************/
  18. #include "bt_target.h"
  19. #include <string.h>
  20. #include "log/log.h"
  21. #include "smp_int.h"
  22. const char* const smp_br_state_name[SMP_BR_STATE_MAX + 1] = {
  23. "SMP_BR_STATE_IDLE", "SMP_BR_STATE_WAIT_APP_RSP",
  24. "SMP_BR_STATE_PAIR_REQ_RSP", "SMP_BR_STATE_BOND_PENDING",
  25. "SMP_BR_STATE_OUT_OF_RANGE"};
  26. const char* const smp_br_event_name[SMP_BR_MAX_EVT] = {
  27. "BR_PAIRING_REQ_EVT", "BR_PAIRING_RSP_EVT",
  28. "BR_CONFIRM_EVT", "BR_RAND_EVT",
  29. "BR_PAIRING_FAILED_EVT", "BR_ENCRPTION_INFO_EVT",
  30. "BR_MASTER_ID_EVT", "BR_ID_INFO_EVT",
  31. "BR_ID_ADDR_EVT", "BR_SIGN_INFO_EVT",
  32. "BR_SECURITY_REQ_EVT", "BR_PAIR_PUBLIC_KEY_EVT",
  33. "BR_PAIR_DHKEY_CHCK_EVT", "BR_PAIR_KEYPR_NOTIF_EVT",
  34. "BR_KEY_READY_EVT", "BR_ENCRYPTED_EVT",
  35. "BR_L2CAP_CONN_EVT", "BR_L2CAP_DISCONN_EVT",
  36. "BR_KEYS_RSP_EVT", "BR_API_SEC_GRANT_EVT",
  37. "BR_TK_REQ_EVT", "BR_AUTH_CMPL_EVT",
  38. "BR_ENC_REQ_EVT", "BR_BOND_REQ_EVT",
  39. "BR_DISCARD_SEC_REQ_EVT", "BR_OUT_OF_RANGE_EVT"};
  40. const char* smp_get_br_event_name(tSMP_BR_EVENT event);
  41. const char* smp_get_br_state_name(tSMP_BR_STATE state);
  42. #define SMP_BR_SM_IGNORE 0
  43. #define SMP_BR_NUM_ACTIONS 2
  44. #define SMP_BR_SME_NEXT_STATE 2
  45. #define SMP_BR_SM_NUM_COLS 3
  46. typedef const uint8_t (*tSMP_BR_SM_TBL)[SMP_BR_SM_NUM_COLS];
  47. enum {
  48. SMP_SEND_PAIR_REQ,
  49. SMP_BR_SEND_PAIR_RSP,
  50. SMP_SEND_PAIR_FAIL,
  51. SMP_SEND_ID_INFO,
  52. SMP_BR_PROC_PAIR_CMD,
  53. SMP_PROC_PAIR_FAIL,
  54. SMP_PROC_ID_INFO,
  55. SMP_PROC_ID_ADDR,
  56. SMP_PROC_SRK_INFO,
  57. SMP_BR_PROC_SEC_GRANT,
  58. SMP_BR_PROC_SL_KEYS_RSP,
  59. SMP_BR_KEY_DISTRIBUTION,
  60. SMP_BR_PAIRING_COMPLETE,
  61. SMP_SEND_APP_CBACK,
  62. SMP_BR_CHECK_AUTH_REQ,
  63. SMP_PAIR_TERMINATE,
  64. SMP_IDLE_TERMINATE,
  65. SMP_BR_SM_NO_ACTION
  66. };
  67. static const tSMP_ACT smp_br_sm_action[] = {
  68. smp_send_pair_req, /* SMP_SEND_PAIR_REQ */
  69. smp_br_send_pair_response, /* SMP_BR_SEND_PAIR_RSP */
  70. smp_send_pair_fail, /* SMP_SEND_PAIR_FAIL */
  71. smp_send_id_info, /* SMP_SEND_ID_INFO */
  72. smp_br_process_pairing_command, /* SMP_BR_PROC_PAIR_CMD */
  73. smp_proc_pair_fail, /* SMP_PROC_PAIR_FAIL */
  74. smp_proc_id_info, /* SMP_PROC_ID_INFO */
  75. smp_proc_id_addr, /* SMP_PROC_ID_ADDR */
  76. smp_proc_srk_info, /* SMP_PROC_SRK_INFO */
  77. smp_br_process_security_grant, /* SMP_BR_PROC_SEC_GRANT */
  78. smp_br_process_slave_keys_response, /* SMP_BR_PROC_SL_KEYS_RSP */
  79. smp_br_select_next_key, /* SMP_BR_KEY_DISTRIBUTION */
  80. smp_br_pairing_complete, /* SMP_BR_PAIRING_COMPLETE */
  81. smp_send_app_cback, /* SMP_SEND_APP_CBACK */
  82. smp_br_check_authorization_request, /* SMP_BR_CHECK_AUTH_REQ */
  83. smp_pair_terminate, /* SMP_PAIR_TERMINATE */
  84. smp_idle_terminate /* SMP_IDLE_TERMINATE */
  85. };
  86. static const uint8_t smp_br_all_table[][SMP_BR_SM_NUM_COLS] = {
  87. /* Event Action Next State */
  88. /* BR_PAIRING_FAILED */
  89. {SMP_PROC_PAIR_FAIL, SMP_BR_PAIRING_COMPLETE, SMP_BR_STATE_IDLE},
  90. /* BR_AUTH_CMPL */
  91. {SMP_SEND_PAIR_FAIL, SMP_BR_PAIRING_COMPLETE, SMP_BR_STATE_IDLE},
  92. /* BR_L2CAP_DISCONN */
  93. {SMP_PAIR_TERMINATE, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_IDLE}};
  94. /************ SMP Master FSM State/Event Indirection Table **************/
  95. static const uint8_t smp_br_master_entry_map[][SMP_BR_STATE_MAX] = {
  96. /* br_state name: Idle WaitApp Pair Bond
  97. Rsp ReqRsp Pend */
  98. /* BR_PAIRING_REQ */ {0, 0, 0, 0},
  99. /* BR_PAIRING_RSP */ {0, 0, 1, 0},
  100. /* BR_CONFIRM */ {0, 0, 0, 0},
  101. /* BR_RAND */ {0, 0, 0, 0},
  102. /* BR_PAIRING_FAILED */ {0, 0x81, 0x81, 0},
  103. /* BR_ENCRPTION_INFO */ {0, 0, 0, 0},
  104. /* BR_MASTER_ID */ {0, 0, 0, 0},
  105. /* BR_ID_INFO */ {0, 0, 0, 1},
  106. /* BR_ID_ADDR */ {0, 0, 0, 2},
  107. /* BR_SIGN_INFO */ {0, 0, 0, 3},
  108. /* BR_SECURITY_REQ */ {0, 0, 0, 0},
  109. /* BR_PAIR_PUBLIC_KEY_EVT */ {0, 0, 0, 0},
  110. /* BR_PAIR_DHKEY_CHCK_EVT */ {0, 0, 0, 0},
  111. /* BR_PAIR_KEYPR_NOTIF_EVT */ {0, 0, 0, 0},
  112. /* BR_KEY_READY */ {0, 0, 0, 0},
  113. /* BR_ENCRYPTED */ {0, 0, 0, 0},
  114. /* BR_L2CAP_CONN */ {1, 0, 0, 0},
  115. /* BR_L2CAP_DISCONN */ {2, 0x83, 0x83, 0x83},
  116. /* BR_KEYS_RSP */ {0, 1, 0, 0},
  117. /* BR_API_SEC_GRANT */ {0, 0, 0, 0},
  118. /* BR_TK_REQ */ {0, 0, 0, 0},
  119. /* BR_AUTH_CMPL */ {0, 0x82, 0x82, 0x82},
  120. /* BR_ENC_REQ */ {0, 0, 0, 0},
  121. /* BR_BOND_REQ */ {0, 0, 2, 0},
  122. /* BR_DISCARD_SEC_REQ */ {0, 0, 0, 0}};
  123. static const uint8_t smp_br_master_idle_table[][SMP_BR_SM_NUM_COLS] = {
  124. /* Event Action Next State */
  125. /* BR_L2CAP_CONN */
  126. {SMP_SEND_APP_CBACK, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_WAIT_APP_RSP},
  127. /* BR_L2CAP_DISCONN */
  128. {SMP_IDLE_TERMINATE, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_IDLE}};
  129. static const uint8_t
  130. smp_br_master_wait_appln_response_table[][SMP_BR_SM_NUM_COLS] = {
  131. /* Event Action Next State */
  132. /* BR_KEYS_RSP */
  133. {SMP_SEND_PAIR_REQ, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_PAIR_REQ_RSP}};
  134. static const uint8_t
  135. smp_br_master_pair_request_response_table[][SMP_BR_SM_NUM_COLS] = {
  136. /* Event Action Next State */
  137. /* BR_PAIRING_RSP */
  138. {SMP_BR_PROC_PAIR_CMD, SMP_BR_CHECK_AUTH_REQ,
  139. SMP_BR_STATE_PAIR_REQ_RSP},
  140. /* BR_BOND_REQ */
  141. {SMP_BR_SM_NO_ACTION, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_BOND_PENDING}};
  142. static const uint8_t smp_br_master_bond_pending_table[][SMP_BR_SM_NUM_COLS] = {
  143. /* Event Action Next State */
  144. /* BR_ID_INFO */
  145. {SMP_PROC_ID_INFO, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_BOND_PENDING},
  146. /* BR_ID_ADDR */
  147. {SMP_PROC_ID_ADDR, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_BOND_PENDING},
  148. /* BR_SIGN_INFO */
  149. {SMP_PROC_SRK_INFO, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_BOND_PENDING}};
  150. static const uint8_t smp_br_slave_entry_map[][SMP_BR_STATE_MAX] = {
  151. /* br_state name: Idle WaitApp Pair Bond
  152. Rsp ReqRsp Pend */
  153. /* BR_PAIRING_REQ */ {1, 0, 0, 0},
  154. /* BR_PAIRING_RSP */ {0, 0, 0, 0},
  155. /* BR_CONFIRM */ {0, 0, 0, 0},
  156. /* BR_RAND */ {0, 0, 0, 0},
  157. /* BR_PAIRING_FAILED */ {0, 0x81, 0x81, 0x81},
  158. /* BR_ENCRPTION_INFO */ {0, 0, 0, 0},
  159. /* BR_MASTER_ID */ {0, 0, 0, 0},
  160. /* BR_ID_INFO */ {0, 0, 0, 1},
  161. /* BR_ID_ADDR */ {0, 0, 0, 2},
  162. /* BR_SIGN_INFO */ {0, 0, 0, 3},
  163. /* BR_SECURITY_REQ */ {0, 0, 0, 0},
  164. /* BR_PAIR_PUBLIC_KEY_EVT */ {0, 0, 0, 0},
  165. /* BR_PAIR_DHKEY_CHCK_EVT */ {0, 0, 0, 0},
  166. /* BR_PAIR_KEYPR_NOTIF_EVT */ {0, 0, 0, 0},
  167. /* BR_KEY_READY */ {0, 0, 0, 0},
  168. /* BR_ENCRYPTED */ {0, 0, 0, 0},
  169. /* BR_L2CAP_CONN */ {0, 0, 0, 0},
  170. /* BR_L2CAP_DISCONN */ {0, 0x83, 0x83, 0x83},
  171. /* BR_KEYS_RSP */ {0, 2, 0, 0},
  172. /* BR_API_SEC_GRANT */ {0, 1, 0, 0},
  173. /* BR_TK_REQ */ {0, 0, 0, 0},
  174. /* BR_AUTH_CMPL */ {0, 0x82, 0x82, 0x82},
  175. /* BR_ENC_REQ */ {0, 0, 0, 0},
  176. /* BR_BOND_REQ */ {0, 3, 0, 0},
  177. /* BR_DISCARD_SEC_REQ */ {0, 0, 0, 0}};
  178. static const uint8_t smp_br_slave_idle_table[][SMP_BR_SM_NUM_COLS] = {
  179. /* Event Action Next State */
  180. /* BR_PAIRING_REQ */
  181. {SMP_BR_PROC_PAIR_CMD, SMP_SEND_APP_CBACK, SMP_BR_STATE_WAIT_APP_RSP}};
  182. static const uint8_t
  183. smp_br_slave_wait_appln_response_table[][SMP_BR_SM_NUM_COLS] = {
  184. /* Event Action Next State */
  185. /* BR_API_SEC_GRANT */
  186. {SMP_BR_PROC_SEC_GRANT, SMP_SEND_APP_CBACK, SMP_BR_STATE_WAIT_APP_RSP},
  187. /* BR_KEYS_RSP */
  188. {SMP_BR_PROC_SL_KEYS_RSP, SMP_BR_CHECK_AUTH_REQ,
  189. SMP_BR_STATE_WAIT_APP_RSP},
  190. /* BR_BOND_REQ */
  191. {SMP_BR_KEY_DISTRIBUTION, SMP_BR_SM_NO_ACTION,
  192. SMP_BR_STATE_BOND_PENDING}};
  193. static const uint8_t smp_br_slave_bond_pending_table[][SMP_BR_SM_NUM_COLS] = {
  194. /* Event Action Next State */
  195. /* BR_ID_INFO */
  196. {SMP_PROC_ID_INFO, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_BOND_PENDING},
  197. /* BR_ID_ADDR */
  198. {SMP_PROC_ID_ADDR, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_BOND_PENDING},
  199. /* BR_SIGN_INFO */
  200. {SMP_PROC_SRK_INFO, SMP_BR_SM_NO_ACTION, SMP_BR_STATE_BOND_PENDING}};
  201. static const tSMP_BR_SM_TBL smp_br_state_table[][2] = {
  202. /* SMP_BR_STATE_IDLE */
  203. {smp_br_master_idle_table, smp_br_slave_idle_table},
  204. /* SMP_BR_STATE_WAIT_APP_RSP */
  205. {smp_br_master_wait_appln_response_table,
  206. smp_br_slave_wait_appln_response_table},
  207. /* SMP_BR_STATE_PAIR_REQ_RSP */
  208. {smp_br_master_pair_request_response_table, NULL},
  209. /* SMP_BR_STATE_BOND_PENDING */
  210. {smp_br_master_bond_pending_table, smp_br_slave_bond_pending_table},
  211. };
  212. typedef const uint8_t (*tSMP_BR_ENTRY_TBL)[SMP_BR_STATE_MAX];
  213. static const tSMP_BR_ENTRY_TBL smp_br_entry_table[] = {smp_br_master_entry_map,
  214. smp_br_slave_entry_map};
  215. #define SMP_BR_ALL_TABLE_MASK 0x80
  216. /*******************************************************************************
  217. * Function smp_set_br_state
  218. * Returns None
  219. ******************************************************************************/
  220. void smp_set_br_state(tSMP_BR_STATE br_state) {
  221. if (br_state < SMP_BR_STATE_MAX) {
  222. SMP_TRACE_DEBUG("BR_State change: %s(%d) ==> %s(%d)",
  223. smp_get_br_state_name(smp_cb.br_state), smp_cb.br_state,
  224. smp_get_br_state_name(br_state), br_state);
  225. smp_cb.br_state = br_state;
  226. } else {
  227. SMP_TRACE_DEBUG("%s invalid br_state =%d", __func__, br_state);
  228. }
  229. }
  230. /*******************************************************************************
  231. * Function smp_get_br_state
  232. * Returns The smp_br state
  233. ******************************************************************************/
  234. tSMP_BR_STATE smp_get_br_state(void) { return smp_cb.br_state; }
  235. /*******************************************************************************
  236. * Function smp_get_br_state_name
  237. * Returns The smp_br state name.
  238. ******************************************************************************/
  239. const char* smp_get_br_state_name(tSMP_BR_STATE br_state) {
  240. const char* p_str = smp_br_state_name[SMP_BR_STATE_MAX];
  241. if (br_state < SMP_BR_STATE_MAX) p_str = smp_br_state_name[br_state];
  242. return p_str;
  243. }
  244. /*******************************************************************************
  245. * Function smp_get_br_event_name
  246. * Returns The smp_br event name.
  247. ******************************************************************************/
  248. const char* smp_get_br_event_name(tSMP_BR_EVENT event) {
  249. const char* p_str = smp_br_event_name[SMP_BR_MAX_EVT - 1];
  250. if (event < SMP_BR_MAX_EVT) {
  251. p_str = smp_br_event_name[event - 1];
  252. }
  253. return p_str;
  254. }
  255. /*******************************************************************************
  256. *
  257. * Function smp_br_state_machine_event
  258. *
  259. * Description Handle events to the state machine. It looks up the entry
  260. * in the smp_br_entry_table array.
  261. * If it is a valid entry, it gets the state table. Set the next
  262. * state, if not NULL state. Execute the action function according
  263. * to the state table. If the state returned by action function is
  264. * not NULL state, adjust the new state to the returned state.
  265. *
  266. * Returns void.
  267. *
  268. ******************************************************************************/
  269. void smp_br_state_machine_event(tSMP_CB* p_cb, tSMP_BR_EVENT event,
  270. tSMP_INT_DATA* p_data) {
  271. tSMP_BR_STATE curr_state = p_cb->br_state;
  272. tSMP_BR_SM_TBL state_table;
  273. uint8_t action, entry;
  274. tSMP_BR_ENTRY_TBL entry_table = smp_br_entry_table[p_cb->role];
  275. SMP_TRACE_EVENT("main %s", __func__);
  276. if (curr_state >= SMP_BR_STATE_MAX) {
  277. SMP_TRACE_DEBUG("Invalid br_state: %d", curr_state);
  278. return;
  279. }
  280. if (p_cb->role > HCI_ROLE_SLAVE) {
  281. SMP_TRACE_ERROR("%s: invalid role %d", __func__, p_cb->role);
  282. android_errorWriteLog(0x534e4554, "80145946");
  283. return;
  284. }
  285. SMP_TRACE_DEBUG("SMP Role: %s State: [%s (%d)], Event: [%s (%d)]",
  286. (p_cb->role == HCI_ROLE_SLAVE) ? "Slave" : "Master",
  287. smp_get_br_state_name(p_cb->br_state), p_cb->br_state,
  288. smp_get_br_event_name(event), event);
  289. /* look up the state table for the current state */
  290. /* lookup entry / w event & curr_state */
  291. /* If entry is ignore, return.
  292. * Otherwise, get state table (according to curr_state or all_state) */
  293. if ((event <= SMP_BR_MAX_EVT) &&
  294. ((entry = entry_table[event - 1][curr_state]) != SMP_BR_SM_IGNORE)) {
  295. if (entry & SMP_BR_ALL_TABLE_MASK) {
  296. entry &= ~SMP_BR_ALL_TABLE_MASK;
  297. state_table = smp_br_all_table;
  298. } else {
  299. state_table = smp_br_state_table[curr_state][p_cb->role];
  300. }
  301. } else {
  302. SMP_TRACE_DEBUG("Ignore event [%s (%d)] in state [%s (%d)]",
  303. smp_get_br_event_name(event), event,
  304. smp_get_br_state_name(curr_state), curr_state);
  305. return;
  306. }
  307. /* Get possible next state from state table. */
  308. smp_set_br_state(state_table[entry - 1][SMP_BR_SME_NEXT_STATE]);
  309. /* If action is not ignore, clear param, exec action and get next state.
  310. * The action function may set the Param for cback.
  311. * Depending on param, call cback or free buffer. */
  312. /* execute action functions */
  313. for (uint8_t i = 0; i < SMP_BR_NUM_ACTIONS; i++) {
  314. action = state_table[entry - 1][i];
  315. if (action != SMP_BR_SM_NO_ACTION) {
  316. (*smp_br_sm_action[action])(p_cb, p_data);
  317. } else {
  318. break;
  319. }
  320. }
  321. SMP_TRACE_DEBUG("result state = %s", smp_get_br_state_name(p_cb->br_state));
  322. }