1 /******************************************************************************
2  *
3  *  Copyright 2004-2012 Broadcom Corporation
4  *
5  *  Licensed under the Apache License, Version 2.0 (the "License");
6  *  you may not use this file except in compliance with the License.
7  *  You may obtain a copy of the License at:
8  *
9  *  http://www.apache.org/licenses/LICENSE-2.0
10  *
11  *  Unless required by applicable law or agreed to in writing, software
12  *  distributed under the License is distributed on an "AS IS" BASIS,
13  *  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14  *  See the License for the specific language governing permissions and
15  *  limitations under the License.
16  *
17  ******************************************************************************/
18 
19 /******************************************************************************
20  *
21  *  This is the main implementation file for the BTA advanced audio/video.
22  *
23  ******************************************************************************/
24 
25 #define LOG_TAG "bt_bta_av"
26 
27 #include <cstdint>
28 
29 #include "bt_target.h"  // Must be first to define build configuration
30 
31 #include "bta/av/bta_av_int.h"
32 #include "bta/include/bta_ar_api.h"
33 #include "bta/include/utl.h"
34 #include "btif/avrcp/avrcp_service.h"
35 #include "btif/include/btif_av_co.h"
36 #include "btif/include/btif_config.h"
37 #include "main/shim/dumpsys.h"
38 #include "osi/include/log.h"
39 #include "osi/include/osi.h"  // UNUSED_ATTR
40 #include "osi/include/properties.h"
41 #include "stack/include/acl_api.h"
42 #include "stack/include/btm_api.h"
43 #include "types/hci_role.h"
44 
45 /*****************************************************************************
46  * Constants and types
47  ****************************************************************************/
48 
49 #ifndef BTA_AV_RET_TOUT
50 #define BTA_AV_RET_TOUT 4
51 #endif
52 
53 #ifndef BTA_AV_SIG_TOUT
54 #define BTA_AV_SIG_TOUT 4
55 #endif
56 
57 #ifndef BTA_AV_IDLE_TOUT
58 #define BTA_AV_IDLE_TOUT 10
59 #endif
60 
61 /* the delay time in milliseconds to retry role switch */
62 #ifndef BTA_AV_RS_TIME_VAL
63 #define BTA_AV_RS_TIME_VAL 1000
64 #endif
65 
66 #ifndef AVRCP_VERSION_PROPERTY
67 #define AVRCP_VERSION_PROPERTY "persist.bluetooth.avrcpversion"
68 #endif
69 
70 #ifndef AVRCP_1_6_STRING
71 #define AVRCP_1_6_STRING "avrcp16"
72 #endif
73 
74 #ifndef AVRCP_1_5_STRING
75 #define AVRCP_1_5_STRING "avrcp15"
76 #endif
77 
78 #ifndef AVRCP_1_4_STRING
79 #define AVRCP_1_4_STRING "avrcp14"
80 #endif
81 
82 #ifndef AVRCP_1_3_STRING
83 #define AVRCP_1_3_STRING "avrcp13"
84 #endif
85 
86 #ifndef AVRCP_DEFAULT_VERSION
87 #define AVRCP_DEFAULT_VERSION AVRCP_1_5_STRING
88 #endif
89 
90 /* state machine states */
91 enum { BTA_AV_INIT_ST, BTA_AV_OPEN_ST };
92 
93 typedef void (*tBTA_AV_NSM_ACT)(tBTA_AV_DATA* p_data);
94 static void bta_av_api_enable(tBTA_AV_DATA* p_data);
95 static void bta_av_api_register(tBTA_AV_DATA* p_data);
96 static void bta_av_ci_data(tBTA_AV_DATA* p_data);
97 static void bta_av_rpc_conn(tBTA_AV_DATA* p_data);
98 static void bta_av_api_to_ssm(tBTA_AV_DATA* p_data);
99 
100 static void bta_av_sco_chg_cback(tBTA_SYS_CONN_STATUS status, uint8_t id,
101                                  uint8_t app_id, const RawAddress& peer_addr);
102 static void bta_av_sys_rs_cback(tBTA_SYS_CONN_STATUS status, uint8_t id,
103                                 uint8_t app_id, const RawAddress& peer_addr);
104 
105 /*****************************************************************************
106  * Global data
107  ****************************************************************************/
108 
109 /* AV control block */
110 tBTA_AV_CB bta_av_cb = {};
111 
112 static const char* bta_av_st_code(uint8_t state);
113 
114 /*******************************************************************************
115  *
116  * Function         bta_av_api_enable
117  *
118  * Description      Handle an API enable event.
119  *
120  *
121  * Returns          void
122  *
123  ******************************************************************************/
bta_av_api_enable(tBTA_AV_DATA * p_data)124 static void bta_av_api_enable(tBTA_AV_DATA* p_data) {
125   if (bta_av_cb.disabling) {
126     APPL_TRACE_WARNING(
127         "%s: previous (reg_audio=%#x) is still disabling (attempts=%d)",
128         __func__, bta_av_cb.reg_audio, bta_av_cb.enabling_attempts);
129     if (++bta_av_cb.enabling_attempts <= kEnablingAttemptsCountMaximum) {
130       tBTA_AV_API_ENABLE* p_buf =
131           (tBTA_AV_API_ENABLE*)osi_malloc(sizeof(tBTA_AV_API_ENABLE));
132       memcpy(p_buf, &p_data->api_enable, sizeof(tBTA_AV_API_ENABLE));
133       bta_sys_sendmsg_delayed(p_buf, base::TimeDelta::FromMilliseconds(
134                                          kEnablingAttemptsIntervalMs));
135       return;
136     }
137     if (bta_av_cb.sdp_a2dp_handle) {
138       SDP_DeleteRecord(bta_av_cb.sdp_a2dp_handle);
139       bta_sys_remove_uuid(UUID_SERVCLASS_AUDIO_SOURCE);
140     }
141 #if (BTA_AV_SINK_INCLUDED == TRUE)
142     if (bta_av_cb.sdp_a2dp_snk_handle) {
143       SDP_DeleteRecord(bta_av_cb.sdp_a2dp_snk_handle);
144       bta_sys_remove_uuid(UUID_SERVCLASS_AUDIO_SINK);
145     }
146 #endif
147     // deregister from AVDT
148     bta_ar_dereg_avdt();
149 
150     // deregister from AVCT
151     bta_ar_dereg_avrc(UUID_SERVCLASS_AV_REMOTE_CONTROL);
152     bta_ar_dereg_avrc(UUID_SERVCLASS_AV_REM_CTRL_TARGET);
153     bta_ar_dereg_avct();
154   }
155 
156   /* initialize control block */
157   memset(&bta_av_cb, 0, sizeof(tBTA_AV_CB));
158 
159   for (int i = 0; i < BTA_AV_NUM_RCB; i++)
160     bta_av_cb.rcb[i].handle = BTA_AV_RC_HANDLE_NONE;
161 
162   bta_av_cb.rc_acp_handle = BTA_AV_RC_HANDLE_NONE;
163 
164   /* store parameters */
165   bta_av_cb.p_cback = p_data->api_enable.p_cback;
166   bta_av_cb.features = p_data->api_enable.features;
167   bta_av_cb.offload_start_pending_hndl = 0;
168   bta_av_cb.offload_started_hndl = 0;
169 
170   tBTA_AV_ENABLE enable;
171   enable.features = bta_av_cb.features;
172 
173   /* Register for SCO change event */
174   bta_sys_sco_register(bta_av_sco_chg_cback);
175 
176   /* call callback with enable event */
177   tBTA_AV bta_av_data;
178   bta_av_data.enable = enable;
179   (*bta_av_cb.p_cback)(BTA_AV_ENABLE_EVT, &bta_av_data);
180 }
181 
182 /*******************************************************************************
183  *
184  * Function         bta_av_addr_to_scb
185  *
186  * Description      find the stream control block by the peer addr
187  *
188  * Returns          void
189  *
190  ******************************************************************************/
bta_av_addr_to_scb(const RawAddress & bd_addr)191 tBTA_AV_SCB* bta_av_addr_to_scb(const RawAddress& bd_addr) {
192   tBTA_AV_SCB* p_scb = NULL;
193   int xx;
194 
195   for (xx = 0; xx < BTA_AV_NUM_STRS; xx++) {
196     if (bta_av_cb.p_scb[xx]) {
197       if (bd_addr == bta_av_cb.p_scb[xx]->PeerAddress()) {
198         p_scb = bta_av_cb.p_scb[xx];
199         break;
200       }
201     }
202   }
203   return p_scb;
204 }
205 
BTA_AvObtainPeerChannelIndex(const RawAddress & peer_address)206 int BTA_AvObtainPeerChannelIndex(const RawAddress& peer_address) {
207   // Find the entry for the peer (if exists)
208   tBTA_AV_SCB* p_scb = bta_av_addr_to_scb(peer_address);
209   if (p_scb != nullptr) {
210     return p_scb->hdi;
211   }
212 
213   // Find the index for an entry that is not used
214   for (int index = 0; index < BTA_AV_NUM_STRS; index++) {
215     tBTA_AV_SCB* p_scb = bta_av_cb.p_scb[index];
216     if (p_scb == nullptr) {
217       continue;
218     }
219     if (p_scb->PeerAddress().IsEmpty()) {
220       return p_scb->hdi;
221     }
222   }
223 
224   return -1;
225 }
226 
227 /*******************************************************************************
228  *
229  * Function         bta_av_hndl_to_scb
230  *
231  * Description      find the stream control block by the handle
232  *
233  * Returns          void
234  *
235  ******************************************************************************/
bta_av_hndl_to_scb(uint16_t handle)236 tBTA_AV_SCB* bta_av_hndl_to_scb(uint16_t handle) {
237   tBTA_AV_HNDL hndl = (tBTA_AV_HNDL)handle;
238   tBTA_AV_SCB* p_scb = NULL;
239   uint8_t idx = (hndl & BTA_AV_HNDL_MSK);
240 
241   if (idx && (idx <= BTA_AV_NUM_STRS)) {
242     p_scb = bta_av_cb.p_scb[idx - 1];
243   }
244   return p_scb;
245 }
246 
247 /*******************************************************************************
248  *
249  * Function         bta_av_alloc_scb
250  *
251  * Description      allocate stream control block,
252  *                  register the service to stack
253  *                  create SDP record
254  *
255  * Returns          void
256  *
257  ******************************************************************************/
bta_av_alloc_scb(tBTA_AV_CHNL chnl)258 static tBTA_AV_SCB* bta_av_alloc_scb(tBTA_AV_CHNL chnl) {
259   if (chnl != BTA_AV_CHNL_AUDIO) {
260     APPL_TRACE_ERROR("%s: bad channel: %d", __func__, chnl);
261     return nullptr;
262   }
263 
264   for (int xx = 0; xx < BTA_AV_NUM_STRS; xx++) {
265     if (bta_av_cb.p_scb[xx] != nullptr) continue;
266     // Found an empty spot
267     // TODO: After tBTA_AV_SCB is changed to a proper class, the entry
268     // here should be allocated by C++ 'new' statement.
269     tBTA_AV_SCB* p_ret = (tBTA_AV_SCB*)osi_calloc(sizeof(tBTA_AV_SCB));
270     p_ret->rc_handle = BTA_AV_RC_HANDLE_NONE;
271     p_ret->chnl = chnl;
272     p_ret->hndl = (tBTA_AV_HNDL)((xx + 1) | chnl);
273     p_ret->hdi = xx;
274     p_ret->a2dp_list = list_new(nullptr);
275     p_ret->avrc_ct_timer = alarm_new("bta_av.avrc_ct_timer");
276     bta_av_cb.p_scb[xx] = p_ret;
277     return p_ret;
278   }
279 
280   return nullptr;
281 }
282 
bta_av_free_scb(tBTA_AV_SCB * p_scb)283 void bta_av_free_scb(tBTA_AV_SCB* p_scb) {
284   if (p_scb == nullptr) return;
285   uint8_t scb_index = p_scb->hdi;
286   CHECK(scb_index < BTA_AV_NUM_STRS);
287 
288   CHECK(p_scb == bta_av_cb.p_scb[scb_index]);
289   bta_av_cb.p_scb[scb_index] = nullptr;
290   alarm_free(p_scb->avrc_ct_timer);
291   // TODO: After tBTA_AV_SCB is changed to a proper class, the entry
292   // here should be de-allocated by C++ 'delete' statement.
293   osi_free(p_scb);
294 }
295 
OnConnected(const RawAddress & peer_address)296 void tBTA_AV_SCB::OnConnected(const RawAddress& peer_address) {
297   peer_address_ = peer_address;
298 
299   if (peer_address.IsEmpty()) {
300     LOG_ERROR("%s: Invalid peer address: %s", __func__,
301               peer_address.ToString().c_str());
302     return;
303   }
304 
305   // Read and restore the AVDTP version from local storage
306   uint16_t avdtp_version = 0;
307   size_t version_value_size = sizeof(avdtp_version);
308   if (!btif_config_get_bin(peer_address_.ToString(), AVDTP_VERSION_CONFIG_KEY,
309                            (uint8_t*)&avdtp_version, &version_value_size)) {
310     LOG_WARN("%s: Failed to read cached peer AVDTP version for %s", __func__,
311              peer_address_.ToString().c_str());
312   } else {
313     SetAvdtpVersion(avdtp_version);
314   }
315 }
316 
OnDisconnected()317 void tBTA_AV_SCB::OnDisconnected() {
318   peer_address_ = RawAddress::kEmpty;
319   SetAvdtpVersion(0);
320 }
321 
SetAvdtpVersion(uint16_t avdtp_version)322 void tBTA_AV_SCB::SetAvdtpVersion(uint16_t avdtp_version) {
323   avdtp_version_ = avdtp_version;
324   LOG_INFO("%s: AVDTP version for %s set to 0x%x", __func__,
325            peer_address_.ToString().c_str(), avdtp_version_);
326 }
327 
328 /*******************************************************************************
329  ******************************************************************************/
bta_av_conn_cback(UNUSED_ATTR uint8_t handle,const RawAddress & bd_addr,uint8_t event,tAVDT_CTRL * p_data,uint8_t scb_index)330 void bta_av_conn_cback(UNUSED_ATTR uint8_t handle, const RawAddress& bd_addr,
331                        uint8_t event, tAVDT_CTRL* p_data, uint8_t scb_index) {
332   uint16_t evt = 0;
333   tBTA_AV_SCB* p_scb = NULL;
334 
335   if (event == BTA_AR_AVDT_CONN_EVT || event == AVDT_CONNECT_IND_EVT ||
336       event == AVDT_DISCONNECT_IND_EVT)
337   {
338     evt = BTA_AV_SIG_CHG_EVT;
339     if (event == AVDT_DISCONNECT_IND_EVT) {
340       p_scb = bta_av_addr_to_scb(bd_addr);
341     } else if (event == AVDT_CONNECT_IND_EVT) {
342       APPL_TRACE_DEBUG("%s: CONN_IND is ACP:%d", __func__,
343                        p_data->hdr.err_param);
344     }
345 
346     tBTA_AV_STR_MSG* p_msg =
347         (tBTA_AV_STR_MSG*)osi_malloc(sizeof(tBTA_AV_STR_MSG));
348     p_msg->hdr.event = evt;
349     p_msg->hdr.layer_specific = event;
350     p_msg->hdr.offset = p_data->hdr.err_param;
351     p_msg->bd_addr = bd_addr;
352     p_msg->scb_index = scb_index;
353     if (p_scb) {
354       APPL_TRACE_DEBUG("%s: bta_handle x%x, role x%x", __func__, p_scb->hndl,
355                        p_scb->role);
356     }
357     LOG_INFO("%s: conn_cback bd_addr: %s", __func__,
358              bd_addr.ToString().c_str());
359     bta_sys_sendmsg(p_msg);
360   }
361 }
362 
363 /*******************************************************************************
364  *
365  * Function         bta_av_a2dp_report_cback
366  *
367  * Description      A2DP report callback.
368  *
369  * Returns          void
370  *
371  ******************************************************************************/
bta_av_a2dp_report_cback(UNUSED_ATTR uint8_t handle,UNUSED_ATTR AVDT_REPORT_TYPE type,UNUSED_ATTR tAVDT_REPORT_DATA * p_data)372 static void bta_av_a2dp_report_cback(UNUSED_ATTR uint8_t handle,
373                                      UNUSED_ATTR AVDT_REPORT_TYPE type,
374                                      UNUSED_ATTR tAVDT_REPORT_DATA* p_data) {
375   /* Do not need to handle report data for now.
376    * This empty function is here for conformance reasons. */
377 }
378 
379 /*******************************************************************************
380  *
381  * Function         bta_av_api_register
382  *
383  * Description      allocate stream control block,
384  *                  register the service to stack
385  *                  create SDP record
386  *
387  * Returns          void
388  *
389  ******************************************************************************/
bta_av_api_register(tBTA_AV_DATA * p_data)390 static void bta_av_api_register(tBTA_AV_DATA* p_data) {
391   tBTA_AV_REGISTER registr;
392   tBTA_AV_SCB* p_scb; /* stream control block */
393   AvdtpRcb reg;
394   AvdtpStreamConfig avdtp_stream_config;
395   char* p_service_name;
396   tBTA_UTL_COD cod;
397 
398   if (bta_av_cb.disabling || (bta_av_cb.features == 0)) {
399     APPL_TRACE_WARNING(
400         "%s: AV instance (features=%#x, reg_audio=%#x) is not "
401         "ready for app_id %d",
402         __func__, bta_av_cb.features, bta_av_cb.reg_audio,
403         p_data->api_reg.app_id);
404     tBTA_AV_API_REG* p_buf =
405         (tBTA_AV_API_REG*)osi_malloc(sizeof(tBTA_AV_API_REG));
406     memcpy(p_buf, &p_data->api_reg, sizeof(tBTA_AV_API_REG));
407     bta_sys_sendmsg_delayed(
408         p_buf, base::TimeDelta::FromMilliseconds(kEnablingAttemptsIntervalMs));
409     return;
410   }
411 
412   avdtp_stream_config.Reset();
413 
414   registr.status = BTA_AV_FAIL_RESOURCES;
415   registr.app_id = p_data->api_reg.app_id;
416   registr.chnl = (tBTA_AV_CHNL)p_data->hdr.layer_specific;
417 
418   char avrcp_version[PROPERTY_VALUE_MAX] = {0};
419   osi_property_get(AVRCP_VERSION_PROPERTY, avrcp_version,
420                    AVRCP_DEFAULT_VERSION);
421   LOG_INFO("%s: AVRCP version used for sdp: \"%s\"", __func__, avrcp_version);
422 
423   uint16_t profile_initialized = p_data->api_reg.service_uuid;
424   if (profile_initialized == UUID_SERVCLASS_AUDIO_SINK) {
425     p_bta_av_cfg = &bta_avk_cfg;
426   } else if (profile_initialized == UUID_SERVCLASS_AUDIO_SOURCE) {
427     p_bta_av_cfg = &bta_av_cfg;
428 
429     if (!strncmp(AVRCP_1_3_STRING, avrcp_version, sizeof(AVRCP_1_3_STRING))) {
430       LOG_INFO("%s: AVRCP 1.3 capabilites used", __func__);
431       p_bta_av_cfg = &bta_av_cfg_compatibility;
432     }
433   }
434 
435   APPL_TRACE_DEBUG("%s: profile: 0x%x", __func__, profile_initialized);
436   if (p_bta_av_cfg == NULL) {
437     APPL_TRACE_ERROR("%s: AV configuration is null!", __func__);
438     return;
439   }
440 
441   do {
442     p_scb = bta_av_alloc_scb(registr.chnl);
443     if (p_scb == NULL) {
444       APPL_TRACE_ERROR("%s: failed to alloc SCB", __func__);
445       break;
446     }
447 
448     registr.hndl = p_scb->hndl;
449     p_scb->app_id = registr.app_id;
450 
451     /* initialize the stream control block */
452     registr.status = BTA_AV_SUCCESS;
453 
454     if (bta_av_cb.reg_audio == 0) {
455       /* the first channel registered. register to AVDTP */
456       reg.ctrl_mtu = 672;
457       reg.ret_tout = BTA_AV_RET_TOUT;
458       reg.sig_tout = BTA_AV_SIG_TOUT;
459       reg.idle_tout = BTA_AV_IDLE_TOUT;
460       reg.scb_index = p_scb->hdi;
461       bta_ar_reg_avdt(&reg, bta_av_conn_cback);
462       bta_sys_role_chg_register(&bta_av_sys_rs_cback);
463 
464       /* create remote control TG service if required */
465       if (bta_av_cb.features & (BTA_AV_FEAT_RCTG)) {
466         /* register with no authorization; let AVDTP use authorization instead
467          */
468         bta_ar_reg_avct();
469 
470         /* For the Audio Sink role we support additional TG to support
471          * absolute volume.
472          */
473         if (is_new_avrcp_enabled()) {
474           APPL_TRACE_DEBUG("%s: newavrcp is the owner of the AVRCP Target SDP "
475               "record. Don't create the SDP record", __func__);
476         } else {
477           APPL_TRACE_DEBUG("%s: newavrcp is not enabled. Create SDP record",
478               __func__);
479 
480           uint16_t profile_version = AVRC_REV_1_0;
481           if (!strncmp(AVRCP_1_6_STRING, avrcp_version,
482                       sizeof(AVRCP_1_6_STRING))) {
483             profile_version = AVRC_REV_1_6;
484           } else if (!strncmp(AVRCP_1_5_STRING, avrcp_version,
485                               sizeof(AVRCP_1_5_STRING))) {
486             profile_version = AVRC_REV_1_5;
487           } else if (!strncmp(AVRCP_1_3_STRING, avrcp_version,
488                               sizeof(AVRCP_1_3_STRING))) {
489             profile_version = AVRC_REV_1_3;
490           } else {
491             profile_version = AVRC_REV_1_4;
492           }
493 
494           bta_ar_reg_avrc(
495               UUID_SERVCLASS_AV_REM_CTRL_TARGET, "AV Remote Control Target", NULL,
496               p_bta_av_cfg->avrc_tg_cat,
497               (bta_av_cb.features & BTA_AV_FEAT_BROWSE), profile_version);
498         }
499       }
500 
501       /* Set the Capturing service class bit */
502       if (profile_initialized == UUID_SERVCLASS_AUDIO_SOURCE)
503         cod.service = BTM_COD_SERVICE_CAPTURING;
504       else if (profile_initialized == UUID_SERVCLASS_AUDIO_SINK)
505         cod.service = BTM_COD_SERVICE_RENDERING;
506       utl_set_device_class(&cod, BTA_UTL_SET_COD_SERVICE_CLASS);
507     } /* if 1st channel */
508 
509     /* get stream configuration and create stream */
510     avdtp_stream_config.cfg.num_codec = 1;
511     avdtp_stream_config.nsc_mask = AvdtpStreamConfig::AVDT_NSC_RECONFIG;
512     if (!(bta_av_cb.features & BTA_AV_FEAT_PROTECT)) {
513       avdtp_stream_config.nsc_mask |= AvdtpStreamConfig::AVDT_NSC_SECURITY;
514     }
515     APPL_TRACE_DEBUG("%s: nsc_mask: 0x%x", __func__,
516                      avdtp_stream_config.nsc_mask);
517 
518     if (p_data->api_reg.p_service_name[0] == 0) {
519       p_service_name = NULL;
520     } else {
521       p_service_name = p_data->api_reg.p_service_name;
522     }
523 
524     p_scb->suspend_sup = true;
525     p_scb->recfg_sup = true;
526 
527     avdtp_stream_config.scb_index = p_scb->hdi;
528     avdtp_stream_config.p_avdt_ctrl_cback = &bta_av_proc_stream_evt;
529 
530     /* set up the audio stream control block */
531     p_scb->p_cos = &bta_av_a2dp_cos;
532     p_scb->media_type = AVDT_MEDIA_TYPE_AUDIO;
533     avdtp_stream_config.cfg.psc_mask = AVDT_PSC_TRANS;
534     avdtp_stream_config.media_type = AVDT_MEDIA_TYPE_AUDIO;
535     avdtp_stream_config.mtu = MAX_3MBPS_AVDTP_MTU;
536     btav_a2dp_codec_index_t codec_index_min = BTAV_A2DP_CODEC_INDEX_SOURCE_MIN;
537     btav_a2dp_codec_index_t codec_index_max = BTAV_A2DP_CODEC_INDEX_SOURCE_MAX;
538 
539     if (bta_av_cb.features & BTA_AV_FEAT_REPORT) {
540       avdtp_stream_config.cfg.psc_mask |= AVDT_PSC_REPORT;
541       avdtp_stream_config.p_report_cback = bta_av_a2dp_report_cback;
542     }
543     if (bta_av_cb.features & BTA_AV_FEAT_DELAY_RPT)
544       avdtp_stream_config.cfg.psc_mask |= AVDT_PSC_DELAY_RPT;
545 
546     if (profile_initialized == UUID_SERVCLASS_AUDIO_SOURCE) {
547       avdtp_stream_config.tsep = AVDT_TSEP_SRC;
548       codec_index_min = BTAV_A2DP_CODEC_INDEX_SOURCE_MIN;
549       codec_index_max = BTAV_A2DP_CODEC_INDEX_SOURCE_MAX;
550     } else if (profile_initialized == UUID_SERVCLASS_AUDIO_SINK) {
551       avdtp_stream_config.tsep = AVDT_TSEP_SNK;
552       avdtp_stream_config.p_sink_data_cback = bta_av_sink_data_cback;
553       codec_index_min = BTAV_A2DP_CODEC_INDEX_SINK_MIN;
554       codec_index_max = BTAV_A2DP_CODEC_INDEX_SINK_MAX;
555     }
556 
557     /* Initialize handles to zero */
558     for (int xx = 0; xx < BTAV_A2DP_CODEC_INDEX_MAX; xx++) {
559       p_scb->seps[xx].av_handle = 0;
560     }
561 
562     /* keep the configuration in the stream control block */
563     p_scb->cfg = avdtp_stream_config.cfg;
564     for (int i = codec_index_min; i < codec_index_max; i++) {
565       btav_a2dp_codec_index_t codec_index =
566           static_cast<btav_a2dp_codec_index_t>(i);
567       if (!bta_av_co_is_supported_codec(codec_index)) {
568         continue;
569       }
570       if (!(*bta_av_a2dp_cos.init)(codec_index, &avdtp_stream_config.cfg)) {
571         continue;
572       }
573       if (AVDT_CreateStream(p_scb->app_id, &p_scb->seps[codec_index].av_handle,
574                             avdtp_stream_config) != AVDT_SUCCESS) {
575         APPL_TRACE_WARNING(
576             "%s: bta_handle=0x%x (app_id %d) failed to alloc an SEP index:%d",
577             __func__, p_scb->hndl, p_scb->app_id, codec_index);
578         continue;
579       }
580       /* Save a copy of the codec */
581       memcpy(p_scb->seps[codec_index].codec_info,
582              avdtp_stream_config.cfg.codec_info, AVDT_CODEC_SIZE);
583       p_scb->seps[codec_index].tsep = avdtp_stream_config.tsep;
584       if (avdtp_stream_config.tsep == AVDT_TSEP_SNK) {
585         p_scb->seps[codec_index].p_app_sink_data_cback =
586             p_data->api_reg.p_app_sink_data_cback;
587       } else {
588         /* In case of A2DP SOURCE we don't need a callback to
589          * handle media packets.
590          */
591         p_scb->seps[codec_index].p_app_sink_data_cback = NULL;
592       }
593     }
594 
595     if (!bta_av_cb.reg_audio) {
596       bta_av_cb.sdp_a2dp_handle = 0;
597       bta_av_cb.sdp_a2dp_snk_handle = 0;
598       if (profile_initialized == UUID_SERVCLASS_AUDIO_SOURCE) {
599         /* create the SDP records on the 1st audio channel */
600         bta_av_cb.sdp_a2dp_handle = SDP_CreateRecord();
601         A2DP_AddRecord(UUID_SERVCLASS_AUDIO_SOURCE, p_service_name, NULL,
602                        A2DP_SUPF_PLAYER, bta_av_cb.sdp_a2dp_handle);
603         bta_sys_add_uuid(UUID_SERVCLASS_AUDIO_SOURCE);
604       } else if (profile_initialized == UUID_SERVCLASS_AUDIO_SINK) {
605 #if (BTA_AV_SINK_INCLUDED == TRUE)
606         bta_av_cb.sdp_a2dp_snk_handle = SDP_CreateRecord();
607         A2DP_AddRecord(UUID_SERVCLASS_AUDIO_SINK, p_service_name, NULL,
608                        A2DP_SUPF_PLAYER, bta_av_cb.sdp_a2dp_snk_handle);
609         bta_sys_add_uuid(UUID_SERVCLASS_AUDIO_SINK);
610 #endif
611       }
612       /* start listening when A2DP is registered */
613       if (bta_av_cb.features & BTA_AV_FEAT_RCTG)
614         bta_av_rc_create(&bta_av_cb, AVCT_ACP, 0, BTA_AV_NUM_LINKS + 1);
615 
616       /* if the AV and AVK are both supported, it cannot support the CT role
617        */
618       if (bta_av_cb.features & (BTA_AV_FEAT_RCCT)) {
619         /* if TG is not supported, we need to register to AVCT now */
620         if ((bta_av_cb.features & (BTA_AV_FEAT_RCTG)) == 0) {
621           bta_ar_reg_avct();
622           bta_av_rc_create(&bta_av_cb, AVCT_ACP, 0, BTA_AV_NUM_LINKS + 1);
623         }
624         /* create an SDP record as AVRC CT. We create 1.3 for SOURCE
625          * because we rely on feature bits being scanned by external
626          * devices more than the profile version itself.
627          *
628          * We create 1.4 for SINK since we support browsing.
629          */
630         if (profile_initialized == UUID_SERVCLASS_AUDIO_SOURCE &&
631             !is_new_avrcp_enabled()) {
632           bta_ar_reg_avrc(UUID_SERVCLASS_AV_REMOTE_CONTROL, NULL, NULL,
633                           p_bta_av_cfg->avrc_ct_cat,
634                           (bta_av_cb.features & BTA_AV_FEAT_BROWSE),
635                           AVRC_REV_1_3);
636         } else if (profile_initialized == UUID_SERVCLASS_AUDIO_SINK) {
637           bta_ar_reg_avrc(UUID_SERVCLASS_AV_REMOTE_CONTROL, NULL, NULL,
638                           p_bta_av_cfg->avrc_ct_cat,
639                           (bta_av_cb.features & BTA_AV_FEAT_BROWSE),
640                           AVRC_REV_1_6);
641         }
642       }
643     }
644     bta_av_cb.reg_audio |= BTA_AV_HNDL_TO_MSK(p_scb->hdi);
645     APPL_TRACE_DEBUG("%s: reg_audio: 0x%x", __func__, bta_av_cb.reg_audio);
646   } while (0);
647 
648   /* call callback with register event */
649   tBTA_AV bta_av_data;
650   bta_av_data.registr = registr;
651   (*bta_av_cb.p_cback)(BTA_AV_REGISTER_EVT, &bta_av_data);
652 }
653 
654 /*******************************************************************************
655  *
656  * Function         bta_av_api_deregister
657  *
658  * Description      de-register a channel
659  *
660  *
661  * Returns          void
662  *
663  ******************************************************************************/
bta_av_api_deregister(tBTA_AV_DATA * p_data)664 void bta_av_api_deregister(tBTA_AV_DATA* p_data) {
665   tBTA_AV_SCB* p_scb = bta_av_hndl_to_scb(p_data->hdr.layer_specific);
666 
667   if (p_scb) {
668     p_scb->deregistering = true;
669     bta_av_ssm_execute(p_scb, BTA_AV_API_CLOSE_EVT, p_data);
670   } else {
671     bta_av_dereg_comp(p_data);
672   }
673 }
674 
675 /*******************************************************************************
676  *
677  * Function         bta_av_ci_data
678  *
679  * Description      Forward the BTA_AV_CI_SRC_DATA_READY_EVT to stream state
680  *                  machine.
681  *
682  *
683  * Returns          void
684  *
685  ******************************************************************************/
bta_av_ci_data(tBTA_AV_DATA * p_data)686 static void bta_av_ci_data(tBTA_AV_DATA* p_data) {
687   tBTA_AV_SCB* p_scb;
688   int i;
689   uint8_t chnl = (uint8_t)p_data->hdr.layer_specific;
690 
691   for (i = 0; i < BTA_AV_NUM_STRS; i++) {
692     p_scb = bta_av_cb.p_scb[i];
693 
694     if (p_scb && p_scb->chnl == chnl) {
695       bta_av_ssm_execute(p_scb, BTA_AV_SRC_DATA_READY_EVT, p_data);
696     }
697   }
698 }
699 
700 /*******************************************************************************
701  *
702  * Function         bta_av_rpc_conn
703  *
704  * Description      report report channel open
705  *
706  * Returns          void
707  *
708  ******************************************************************************/
bta_av_rpc_conn(UNUSED_ATTR tBTA_AV_DATA * p_data)709 static void bta_av_rpc_conn(UNUSED_ATTR tBTA_AV_DATA* p_data) {}
710 
711 /*******************************************************************************
712  *
713  * Function         bta_av_api_to_ssm
714  *
715  * Description      forward the API request to stream state machine
716  *
717  *
718  * Returns          void
719  *
720  ******************************************************************************/
bta_av_api_to_ssm(tBTA_AV_DATA * p_data)721 static void bta_av_api_to_ssm(tBTA_AV_DATA* p_data) {
722   uint16_t event =
723       p_data->hdr.event - BTA_AV_FIRST_A2S_API_EVT + BTA_AV_FIRST_A2S_SSM_EVT;
724   tBTA_AV_HNDL handle = p_data->hdr.layer_specific;
725   tBTA_AV_SCB* p_scb = bta_av_hndl_to_scb(handle);
726 
727   if (p_scb != nullptr) {
728     bta_av_ssm_execute(p_scb, event, p_data);
729   }
730 }
731 
732 /*******************************************************************************
733  *
734  * Function         bta_av_chk_start
735  *
736  * Description      if this is audio channel, check if more than one audio
737  *                  channel is connected & already started.
738  *                  This function needs to be kept very similar to
739  *                  bta_av_chk_2nd_start
740  *
741  * Returns          true, if need api_start
742  *
743  ******************************************************************************/
bta_av_chk_start(tBTA_AV_SCB * p_scb)744 bool bta_av_chk_start(tBTA_AV_SCB* p_scb) {
745   bool start = false;
746 
747   if ((p_scb->chnl == BTA_AV_CHNL_AUDIO) && (bta_av_cb.audio_open_cnt >= 2) &&
748       (((p_scb->role & BTA_AV_ROLE_AD_ACP) == 0) ||  // Outgoing connection or
749        (bta_av_cb.features & BTA_AV_FEAT_ACP_START))) {  // Auto-starting option
750     // More than one audio channel is connected.
751     // If this is the 2nd stream as ACP, give INT a chance to issue the START
752     // command.
753     for (int i = 0; i < BTA_AV_NUM_STRS; i++) {
754       tBTA_AV_SCB* p_scbi = bta_av_cb.p_scb[i];
755       if (p_scbi && p_scbi->chnl == BTA_AV_CHNL_AUDIO && p_scbi->co_started) {
756         start = true;
757         // May need to update the flush timeout of this already started stream
758         if (p_scbi->co_started != bta_av_cb.audio_open_cnt) {
759           p_scbi->co_started = bta_av_cb.audio_open_cnt;
760         }
761       }
762     }
763   }
764 
765   LOG_INFO(
766       "%s: peer %s channel:%d bta_av_cb.audio_open_cnt:%d role:0x%x "
767       "features:0x%x start:%s",
768       __func__, p_scb->PeerAddress().ToString().c_str(), p_scb->chnl,
769       bta_av_cb.audio_open_cnt, p_scb->role, bta_av_cb.features,
770       logbool(start).c_str());
771   return start;
772 }
773 
774 /*******************************************************************************
775  *
776  * Function         bta_av_restore_switch
777  *
778  * Description      assume that the caller of this function already makes
779  *                  sure that there's only one ACL connection left
780  *
781  * Returns          void
782  *
783  ******************************************************************************/
bta_av_restore_switch(void)784 void bta_av_restore_switch(void) {
785   tBTA_AV_CB* p_cb = &bta_av_cb;
786   int i;
787   uint8_t mask;
788 
789   APPL_TRACE_DEBUG("%s: reg_audio: 0x%x", __func__, bta_av_cb.reg_audio);
790   for (i = 0; i < BTA_AV_NUM_STRS; i++) {
791     mask = BTA_AV_HNDL_TO_MSK(i);
792     if (p_cb->conn_audio == mask) {
793       if (p_cb->p_scb[i]) {
794         BTM_unblock_role_switch_for(p_cb->p_scb[i]->PeerAddress());
795       }
796       break;
797     }
798   }
799 }
800 
801 /*******************************************************************************
802  *
803  * Function         bta_av_sys_rs_cback
804  *
805  * Description      Receives the role change event from dm
806  *
807  * Returns          (BTA_SYS_ROLE_CHANGE, new_role, hci_status, p_bda)
808  *
809  ******************************************************************************/
bta_av_sys_rs_cback(UNUSED_ATTR tBTA_SYS_CONN_STATUS status,uint8_t id,uint8_t app_id,const RawAddress & peer_addr)810 static void bta_av_sys_rs_cback(UNUSED_ATTR tBTA_SYS_CONN_STATUS status,
811                                 uint8_t id, uint8_t app_id,
812                                 const RawAddress& peer_addr) {
813   int i;
814   tBTA_AV_SCB* p_scb = NULL;
815   tHCI_ROLE cur_role;
816   uint8_t peer_idx = 0;
817 
818   APPL_TRACE_DEBUG(
819       "%s: peer %s new_role:%d hci_status:0x%x bta_av_cb.rs_idx:%d", __func__,
820       peer_addr.ToString().c_str(), id, app_id, bta_av_cb.rs_idx);
821 
822   for (i = 0; i < BTA_AV_NUM_STRS; i++) {
823     /* loop through all the SCBs to find matching peer addresses and report the
824      * role change event */
825     /* note that more than one SCB (a2dp & vdp) maybe waiting for this event */
826     p_scb = bta_av_cb.p_scb[i];
827     if (p_scb && p_scb->PeerAddress() == peer_addr) {
828       tBTA_AV_ROLE_RES* p_buf =
829           (tBTA_AV_ROLE_RES*)osi_malloc(sizeof(tBTA_AV_ROLE_RES));
830       APPL_TRACE_DEBUG(
831           "%s: peer %s found: new_role:%d, hci_status:0x%x bta_handle:0x%x",
832           __func__, peer_addr.ToString().c_str(), id, app_id, p_scb->hndl);
833       p_buf->hdr.event = BTA_AV_ROLE_CHANGE_EVT;
834       p_buf->hdr.layer_specific = p_scb->hndl;
835       p_buf->new_role = id;
836       p_buf->hci_status = app_id;
837       bta_sys_sendmsg(p_buf);
838 
839       peer_idx = p_scb->hdi + 1; /* Handle index for the peer_addr */
840     }
841   }
842 
843   /* restore role switch policy, if role switch failed */
844   if ((HCI_SUCCESS != app_id) &&
845       (BTM_GetRole(peer_addr, &cur_role) == BTM_SUCCESS) &&
846       (cur_role == HCI_ROLE_PERIPHERAL)) {
847     BTM_unblock_role_switch_for(peer_addr);
848   }
849 
850   /* if BTA_AvOpen() was called for other device, which caused the role switch
851    * of the peer_addr,  */
852   /* we need to continue opening process for the BTA_AvOpen(). */
853   if ((bta_av_cb.rs_idx != 0) && (bta_av_cb.rs_idx != peer_idx)) {
854     if ((bta_av_cb.rs_idx - 1) < BTA_AV_NUM_STRS) {
855       p_scb = bta_av_cb.p_scb[bta_av_cb.rs_idx - 1];
856     }
857     if (p_scb && p_scb->q_tag == BTA_AV_Q_TAG_OPEN) {
858       APPL_TRACE_DEBUG("%s: peer %s rs_idx:%d, bta_handle:0x%x q_tag:%d",
859                        __func__, p_scb->PeerAddress().ToString().c_str(),
860                        bta_av_cb.rs_idx, p_scb->hndl, p_scb->q_tag);
861 
862       if (HCI_SUCCESS == app_id || HCI_ERR_NO_CONNECTION == app_id) {
863         p_scb->q_info.open.switch_res = BTA_AV_RS_OK;
864       } else {
865         APPL_TRACE_ERROR(
866             "%s: peer %s (p_scb peer %s) role switch failed: new_role:%d "
867             "hci_status:0x%x",
868             __func__, peer_addr.ToString().c_str(),
869             p_scb->PeerAddress().ToString().c_str(), id, app_id);
870         p_scb->q_info.open.switch_res = BTA_AV_RS_FAIL;
871       }
872 
873       /* Continue av open process */
874       bta_av_do_disc_a2dp(p_scb, (tBTA_AV_DATA*)&(p_scb->q_info.open));
875     }
876 
877     bta_av_cb.rs_idx = 0;
878   }
879 }
880 
881 /*******************************************************************************
882  *
883  * Function         bta_av_sco_chg_cback
884  *
885  * Description      receive & process the SCO connection up/down event from sys.
886  *                  call setup also triggers this callback, to suspend av before
887  *                  SCO activity happens, or to resume av once call ends.
888  *
889  * Returns          void
890  *
891  ******************************************************************************/
bta_av_sco_chg_cback(tBTA_SYS_CONN_STATUS status,uint8_t id,UNUSED_ATTR uint8_t app_id,UNUSED_ATTR const RawAddress & peer_addr)892 static void bta_av_sco_chg_cback(tBTA_SYS_CONN_STATUS status, uint8_t id,
893                                  UNUSED_ATTR uint8_t app_id,
894                                  UNUSED_ATTR const RawAddress& peer_addr) {
895   tBTA_AV_SCB* p_scb;
896   int i;
897   tBTA_AV_API_STOP stop;
898 
899   LOG(INFO) << __func__ << ": status=" << bta_sys_conn_status_text(status)
900             << ", num_links=" << +id;
901   if (id) {
902     bta_av_cb.sco_occupied = true;
903     LOG_DEBUG("SCO occupied peer:%s status:%s", PRIVATE_ADDRESS(peer_addr),
904               bta_sys_conn_status_text(status).c_str());
905 
906     if (bta_av_cb.features & BTA_AV_FEAT_NO_SCO_SSPD) {
907       return;
908     }
909 
910     /* either BTA_SYS_SCO_OPEN or BTA_SYS_SCO_CLOSE with remaining active SCO */
911     for (i = 0; i < BTA_AV_NUM_STRS; i++) {
912       p_scb = bta_av_cb.p_scb[i];
913 
914       if (p_scb && p_scb->co_started && (!p_scb->sco_suspend)) {
915         VLOG(1) << __func__ << ": suspending scb:" << i;
916         /* scb is used and started, not suspended automatically */
917         p_scb->sco_suspend = true;
918         stop.flush = false;
919         stop.suspend = true;
920         stop.reconfig_stop = false;
921         bta_av_ssm_execute(p_scb, BTA_AV_AP_STOP_EVT, (tBTA_AV_DATA*)&stop);
922       }
923     }
924   } else {
925     bta_av_cb.sco_occupied = false;
926     LOG_DEBUG("SCO unoccupied peer:%s status:%s", PRIVATE_ADDRESS(peer_addr),
927               bta_sys_conn_status_text(status).c_str());
928 
929     if (bta_av_cb.features & BTA_AV_FEAT_NO_SCO_SSPD) {
930       return;
931     }
932 
933     for (i = 0; i < BTA_AV_NUM_STRS; i++) {
934       p_scb = bta_av_cb.p_scb[i];
935 
936       if (p_scb && p_scb->sco_suspend) /* scb is used and suspended for SCO */
937       {
938         VLOG(1) << __func__ << ": starting scb:" << i;
939         bta_av_ssm_execute(p_scb, BTA_AV_AP_START_EVT, NULL);
940       }
941     }
942   }
943 }
944 
945 /*******************************************************************************
946  *
947  * Function         bta_av_switch_if_needed
948  *
949  * Description      This function checks if there is another existing AV
950  *                  channel that is local as peripheral role.
951  *                  If so, role switch and remove it from link policy.
952  *
953  * Returns          true, if role switch is done
954  *
955  ******************************************************************************/
bta_av_switch_if_needed(tBTA_AV_SCB * p_scb)956 bool bta_av_switch_if_needed(tBTA_AV_SCB* p_scb) {
957   // TODO: A workaround for devices that are connected first, become
958   // Central, and block follow-up role changes - b/72122792 .
959   return false;
960 #if 0
961   uint8_t role;
962   bool needed = false;
963   tBTA_AV_SCB* p_scbi;
964   int i;
965   uint8_t mask;
966 
967   for (i = 0; i < BTA_AV_NUM_STRS; i++) {
968     mask = BTA_AV_HNDL_TO_MSK(i);
969     p_scbi = bta_av_cb.p_scb[i];
970     if (p_scbi && (p_scb->hdi != i) &&   /* not the original channel */
971         ((bta_av_cb.conn_audio & mask))) /* connected audio */
972     {
973       BTM_GetRole(p_scbi->PeerAddress(), &role);
974       /* this channel is open - clear the role switch link policy for this link
975        */
976       if (HCI_ROLE_CENTRAL != role) {
977         if (bta_av_cb.features & BTA_AV_FEAT_CENTRAL)
978           BTM_block_role_switch_for(p_scbi->PeerAddress());
979         if (BTM_CMD_STARTED !=
980             BTM_SwitchRole(p_scbi->PeerAddress(), HCI_ROLE_CENTRAL)) {
981           /* can not switch role on SCBI
982            * start the timer on SCB - because this function is ONLY called when
983            * SCB gets API_OPEN */
984           bta_sys_start_timer(p_scb->avrc_ct_timer, BTA_AV_RS_TIME_VAL,
985                               BTA_AV_AVRC_TIMER_EVT, p_scb->hndl);
986         }
987         needed = true;
988         /* mark the original channel as waiting for RS result */
989         bta_av_cb.rs_idx = p_scb->hdi + 1;
990         break;
991       }
992     }
993   }
994   return needed;
995 #endif
996 }
997 
998 /*******************************************************************************
999  *
1000  * Function         bta_av_link_role_ok
1001  *
1002  * Description      This function checks if the SCB has existing ACL connection
1003  *                  If so, check if the link role fits the requirements.
1004  *
1005  * Returns          true, if role is ok
1006  *
1007  ******************************************************************************/
bta_av_link_role_ok(tBTA_AV_SCB * p_scb,uint8_t bits)1008 bool bta_av_link_role_ok(tBTA_AV_SCB* p_scb, uint8_t bits) {
1009   tHCI_ROLE role;
1010   if (BTM_GetRole(p_scb->PeerAddress(), &role) != BTM_SUCCESS) {
1011     LOG_WARN("Unable to find link role for device:%s",
1012              PRIVATE_ADDRESS(p_scb->PeerAddress()));
1013     return true;
1014   }
1015 
1016   if (role != HCI_ROLE_CENTRAL && (A2DP_BitsSet(bta_av_cb.conn_audio) > bits)) {
1017     LOG_INFO(
1018         "Switch link role to central peer:%s bta_handle:0x%x current_role:%s"
1019         " conn_audio:0x%x bits:%d features:0x%x",
1020         PRIVATE_ADDRESS(p_scb->PeerAddress()), p_scb->hndl,
1021         RoleText(role).c_str(), bta_av_cb.conn_audio, bits, bta_av_cb.features);
1022     const tBTM_STATUS status = BTM_SwitchRoleToCentral(p_scb->PeerAddress());
1023     switch (status) {
1024       case BTM_CMD_STARTED:
1025         break;
1026       case BTM_MODE_UNSUPPORTED:
1027       case BTM_DEV_RESTRICT_LISTED:
1028         // Role switch can never happen, but indicate to caller
1029         // a result such that a timer will not start to repeatedly
1030         // try something not possible.
1031         LOG_ERROR("Link can never role switch to central device:%s",
1032                   PRIVATE_ADDRESS(p_scb->PeerAddress()));
1033         break;
1034       default:
1035         /* can not switch role on SCB - start the timer on SCB */
1036         p_scb->wait |= BTA_AV_WAIT_ROLE_SW_RES_START;
1037         LOG_ERROR("Unable to switch role to central device:%s error:%s",
1038                   PRIVATE_ADDRESS(p_scb->PeerAddress()),
1039                   btm_status_text(status).c_str());
1040         return false;
1041     }
1042   }
1043   return true;
1044 }
1045 
1046 /*******************************************************************************
1047  *
1048  * Function         bta_av_dup_audio_buf
1049  *
1050  * Description      dup the audio data to the q_info.a2dp of other audio
1051  *                  channels
1052  *
1053  * Returns          void
1054  *
1055  ******************************************************************************/
bta_av_dup_audio_buf(tBTA_AV_SCB * p_scb,BT_HDR * p_buf)1056 void bta_av_dup_audio_buf(tBTA_AV_SCB* p_scb, BT_HDR* p_buf) {
1057   /* Test whether there is more than one audio channel connected */
1058   if ((p_buf == NULL) || (bta_av_cb.audio_open_cnt < 2)) return;
1059 
1060   uint16_t copy_size = BT_HDR_SIZE + p_buf->len + p_buf->offset;
1061   for (int i = 0; i < BTA_AV_NUM_STRS; i++) {
1062     tBTA_AV_SCB* p_scbi = bta_av_cb.p_scb[i];
1063 
1064     if (i == p_scb->hdi) continue; /* Ignore the original channel */
1065     if ((p_scbi == NULL) || !p_scbi->co_started)
1066       continue; /* Ignore if SCB is not used or started */
1067     if (!(bta_av_cb.conn_audio & BTA_AV_HNDL_TO_MSK(i)))
1068       continue; /* Audio is not connected */
1069 
1070     /* Enqueue the data */
1071     BT_HDR* p_new = (BT_HDR*)osi_malloc(copy_size);
1072     memcpy(p_new, p_buf, copy_size);
1073     list_append(p_scbi->a2dp_list, p_new);
1074 
1075     if (list_length(p_scbi->a2dp_list) > p_bta_av_cfg->audio_mqs) {
1076       // Drop the oldest packet
1077       bta_av_co_audio_drop(p_scbi->hndl, p_scbi->PeerAddress());
1078       BT_HDR* p_buf_drop = static_cast<BT_HDR*>(list_front(p_scbi->a2dp_list));
1079       list_remove(p_scbi->a2dp_list, p_buf_drop);
1080       osi_free(p_buf_drop);
1081     }
1082   }
1083 }
1084 
bta_av_non_state_machine_event(uint16_t event,tBTA_AV_DATA * p_data)1085 static void bta_av_non_state_machine_event(uint16_t event,
1086                                            tBTA_AV_DATA* p_data) {
1087   switch (event) {
1088     case BTA_AV_API_ENABLE_EVT:
1089       bta_av_api_enable(p_data);
1090       break;
1091     case BTA_AV_API_REGISTER_EVT:
1092       bta_av_api_register(p_data);
1093       break;
1094     case BTA_AV_API_DEREGISTER_EVT:
1095       bta_av_api_deregister(p_data);
1096       break;
1097     case BTA_AV_API_DISCONNECT_EVT:
1098       bta_av_api_disconnect(p_data);
1099       break;
1100     case BTA_AV_CI_SRC_DATA_READY_EVT:
1101       bta_av_ci_data(p_data);
1102       break;
1103     case BTA_AV_SIG_CHG_EVT:
1104       bta_av_sig_chg(p_data);
1105       break;
1106     case BTA_AV_SIGNALLING_TIMER_EVT:
1107       bta_av_signalling_timer(p_data);
1108       break;
1109     case BTA_AV_SDP_AVRC_DISC_EVT:
1110       bta_av_rc_disc_done(p_data);
1111       break;
1112     case BTA_AV_AVRC_CLOSE_EVT:
1113       bta_av_rc_closed(p_data);
1114       break;
1115     case BTA_AV_AVRC_BROWSE_OPEN_EVT:
1116       bta_av_rc_browse_opened(p_data);
1117       break;
1118     case BTA_AV_AVRC_BROWSE_CLOSE_EVT:
1119       bta_av_rc_browse_closed(p_data);
1120       break;
1121     case BTA_AV_CONN_CHG_EVT:
1122       bta_av_conn_chg(p_data);
1123       break;
1124     case BTA_AV_DEREG_COMP_EVT:
1125       bta_av_dereg_comp(p_data);
1126       break;
1127     case BTA_AV_AVDT_RPT_CONN_EVT:
1128       bta_av_rpc_conn(p_data);
1129       break;
1130     case BTA_AV_API_START_EVT:
1131       bta_av_api_to_ssm(p_data);
1132       break;
1133     case BTA_AV_API_STOP_EVT:
1134       bta_av_api_to_ssm(p_data);
1135       break;
1136   }
1137 }
1138 
bta_av_better_state_machine(tBTA_AV_CB * p_cb,uint16_t event,tBTA_AV_DATA * p_data)1139 static void bta_av_better_state_machine(tBTA_AV_CB* p_cb, uint16_t event,
1140                                         tBTA_AV_DATA* p_data) {
1141   switch (p_cb->state) {
1142     case BTA_AV_INIT_ST:
1143       switch (event) {
1144         case BTA_AV_API_DISABLE_EVT:
1145           bta_av_disable(p_cb, p_data);
1146           break;
1147         case BTA_AV_API_META_RSP_EVT:
1148           bta_av_rc_free_rsp(p_cb, p_data);
1149           break;
1150         case BTA_AV_AVRC_OPEN_EVT:
1151           p_cb->state = BTA_AV_OPEN_ST;
1152           bta_av_rc_opened(p_cb, p_data);
1153           break;
1154         case BTA_AV_AVRC_MSG_EVT:
1155           bta_av_rc_free_browse_msg(p_cb, p_data);
1156           break;
1157       }
1158       break;
1159     case BTA_AV_OPEN_ST:
1160       switch (event) {
1161         case BTA_AV_API_DISABLE_EVT:
1162           p_cb->state = BTA_AV_INIT_ST;
1163           bta_av_disable(p_cb, p_data);
1164           break;
1165         case BTA_AV_API_REMOTE_CMD_EVT:
1166           bta_av_rc_remote_cmd(p_cb, p_data);
1167           break;
1168         case BTA_AV_API_VENDOR_CMD_EVT:
1169           bta_av_rc_vendor_cmd(p_cb, p_data);
1170           break;
1171         case BTA_AV_API_VENDOR_RSP_EVT:
1172           bta_av_rc_vendor_rsp(p_cb, p_data);
1173           break;
1174         case BTA_AV_API_META_RSP_EVT:
1175           bta_av_rc_meta_rsp(p_cb, p_data);
1176           break;
1177         case BTA_AV_API_RC_CLOSE_EVT:
1178           bta_av_rc_close(p_cb, p_data);
1179           break;
1180         case BTA_AV_AVRC_OPEN_EVT:
1181           bta_av_rc_opened(p_cb, p_data);
1182           break;
1183         case BTA_AV_AVRC_MSG_EVT:
1184           bta_av_rc_msg(p_cb, p_data);
1185           break;
1186         case BTA_AV_AVRC_NONE_EVT:
1187           p_cb->state = BTA_AV_INIT_ST;
1188           break;
1189       }
1190       break;
1191   }
1192 }
1193 
bta_av_sm_execute(tBTA_AV_CB * p_cb,uint16_t event,tBTA_AV_DATA * p_data)1194 void bta_av_sm_execute(tBTA_AV_CB* p_cb, uint16_t event, tBTA_AV_DATA* p_data) {
1195   APPL_TRACE_EVENT("%s: AV event=0x%x(%s) state=%d(%s)", __func__, event,
1196                    bta_av_evt_code(event), p_cb->state,
1197                    bta_av_st_code(p_cb->state));
1198   bta_av_better_state_machine(p_cb, event, p_data);
1199 }
1200 
1201 /*******************************************************************************
1202  *
1203  * Function         bta_av_hdl_event
1204  *
1205  * Description      Advanced audio/video main event handling function.
1206  *
1207  *
1208  * Returns          bool
1209  *
1210  ******************************************************************************/
bta_av_hdl_event(BT_HDR_RIGID * p_msg)1211 bool bta_av_hdl_event(BT_HDR_RIGID* p_msg) {
1212   if (p_msg->event > BTA_AV_LAST_EVT) {
1213     return true; /* to free p_msg */
1214   }
1215   if (p_msg->event >= BTA_AV_FIRST_NSM_EVT) {
1216     APPL_TRACE_VERBOSE("%s: AV nsm event=0x%x(%s)", __func__, p_msg->event,
1217                        bta_av_evt_code(p_msg->event));
1218     bta_av_non_state_machine_event(p_msg->event, (tBTA_AV_DATA*)p_msg);
1219   } else if (p_msg->event >= BTA_AV_FIRST_SM_EVT &&
1220              p_msg->event <= BTA_AV_LAST_SM_EVT) {
1221     APPL_TRACE_VERBOSE("%s: AV sm event=0x%x(%s)", __func__, p_msg->event,
1222                        bta_av_evt_code(p_msg->event));
1223     /* state machine events */
1224     bta_av_sm_execute(&bta_av_cb, p_msg->event, (tBTA_AV_DATA*)p_msg);
1225   } else {
1226     APPL_TRACE_VERBOSE("%s: bta_handle=0x%x", __func__, p_msg->layer_specific);
1227     /* stream state machine events */
1228     bta_av_ssm_execute(bta_av_hndl_to_scb(p_msg->layer_specific), p_msg->event,
1229                        (tBTA_AV_DATA*)p_msg);
1230   }
1231   return true;
1232 }
1233 
1234 /*****************************************************************************
1235  *  Debug Functions
1236  ****************************************************************************/
1237 /*******************************************************************************
1238  *
1239  * Function         bta_av_st_code
1240  *
1241  * Description
1242  *
1243  * Returns          char *
1244  *
1245  ******************************************************************************/
bta_av_st_code(uint8_t state)1246 static const char* bta_av_st_code(uint8_t state) {
1247   switch (state) {
1248     case BTA_AV_INIT_ST:
1249       return "INIT";
1250     case BTA_AV_OPEN_ST:
1251       return "OPEN";
1252     default:
1253       return "unknown";
1254   }
1255 }
1256 /*******************************************************************************
1257  *
1258  * Function         bta_av_evt_code
1259  *
1260  * Description
1261  *
1262  * Returns          char *
1263  *
1264  ******************************************************************************/
bta_av_evt_code(uint16_t evt_code)1265 const char* bta_av_evt_code(uint16_t evt_code) {
1266   switch (evt_code) {
1267     case BTA_AV_API_DISABLE_EVT:
1268       return "API_DISABLE";
1269     case BTA_AV_API_REMOTE_CMD_EVT:
1270       return "API_REMOTE_CMD";
1271     case BTA_AV_API_VENDOR_CMD_EVT:
1272       return "API_VENDOR_CMD";
1273     case BTA_AV_API_VENDOR_RSP_EVT:
1274       return "API_VENDOR_RSP";
1275     case BTA_AV_API_META_RSP_EVT:
1276       return "API_META_RSP_EVT";
1277     case BTA_AV_API_RC_CLOSE_EVT:
1278       return "API_RC_CLOSE";
1279     case BTA_AV_AVRC_OPEN_EVT:
1280       return "AVRC_OPEN";
1281     case BTA_AV_AVRC_MSG_EVT:
1282       return "AVRC_MSG";
1283     case BTA_AV_AVRC_NONE_EVT:
1284       return "AVRC_NONE";
1285 
1286     case BTA_AV_API_OPEN_EVT:
1287       return "API_OPEN";
1288     case BTA_AV_API_CLOSE_EVT:
1289       return "API_CLOSE";
1290     case BTA_AV_AP_START_EVT:
1291       return "AP_START";
1292     case BTA_AV_AP_STOP_EVT:
1293       return "AP_STOP";
1294     case BTA_AV_API_RECONFIG_EVT:
1295       return "API_RECONFIG";
1296     case BTA_AV_API_PROTECT_REQ_EVT:
1297       return "API_PROTECT_REQ";
1298     case BTA_AV_API_PROTECT_RSP_EVT:
1299       return "API_PROTECT_RSP";
1300     case BTA_AV_API_RC_OPEN_EVT:
1301       return "API_RC_OPEN";
1302     case BTA_AV_SRC_DATA_READY_EVT:
1303       return "SRC_DATA_READY";
1304     case BTA_AV_CI_SETCONFIG_OK_EVT:
1305       return "CI_SETCONFIG_OK";
1306     case BTA_AV_CI_SETCONFIG_FAIL_EVT:
1307       return "CI_SETCONFIG_FAIL";
1308     case BTA_AV_SDP_DISC_OK_EVT:
1309       return "SDP_DISC_OK";
1310     case BTA_AV_SDP_DISC_FAIL_EVT:
1311       return "SDP_DISC_FAIL";
1312     case BTA_AV_STR_DISC_OK_EVT:
1313       return "STR_DISC_OK";
1314     case BTA_AV_STR_DISC_FAIL_EVT:
1315       return "STR_DISC_FAIL";
1316     case BTA_AV_STR_GETCAP_OK_EVT:
1317       return "STR_GETCAP_OK";
1318     case BTA_AV_STR_GETCAP_FAIL_EVT:
1319       return "STR_GETCAP_FAIL";
1320     case BTA_AV_STR_OPEN_OK_EVT:
1321       return "STR_OPEN_OK";
1322     case BTA_AV_STR_OPEN_FAIL_EVT:
1323       return "STR_OPEN_FAIL";
1324     case BTA_AV_STR_START_OK_EVT:
1325       return "STR_START_OK";
1326     case BTA_AV_STR_START_FAIL_EVT:
1327       return "STR_START_FAIL";
1328     case BTA_AV_STR_CLOSE_EVT:
1329       return "STR_CLOSE";
1330     case BTA_AV_STR_CONFIG_IND_EVT:
1331       return "STR_CONFIG_IND";
1332     case BTA_AV_STR_SECURITY_IND_EVT:
1333       return "STR_SECURITY_IND";
1334     case BTA_AV_STR_SECURITY_CFM_EVT:
1335       return "STR_SECURITY_CFM";
1336     case BTA_AV_STR_WRITE_CFM_EVT:
1337       return "STR_WRITE_CFM";
1338     case BTA_AV_STR_SUSPEND_CFM_EVT:
1339       return "STR_SUSPEND_CFM";
1340     case BTA_AV_STR_RECONFIG_CFM_EVT:
1341       return "STR_RECONFIG_CFM";
1342     case BTA_AV_AVRC_TIMER_EVT:
1343       return "AVRC_TIMER";
1344     case BTA_AV_AVDT_CONNECT_EVT:
1345       return "AVDT_CONNECT";
1346     case BTA_AV_AVDT_DISCONNECT_EVT:
1347       return "AVDT_DISCONNECT";
1348     case BTA_AV_ROLE_CHANGE_EVT:
1349       return "ROLE_CHANGE";
1350     case BTA_AV_AVDT_DELAY_RPT_EVT:
1351       return "AVDT_DELAY_RPT";
1352     case BTA_AV_ACP_CONNECT_EVT:
1353       return "ACP_CONNECT";
1354     case BTA_AV_API_OFFLOAD_START_EVT:
1355       return "OFFLOAD_START";
1356     case BTA_AV_API_OFFLOAD_START_RSP_EVT:
1357       return "OFFLOAD_START_RSP";
1358 
1359     case BTA_AV_API_ENABLE_EVT:
1360       return "API_ENABLE";
1361     case BTA_AV_API_REGISTER_EVT:
1362       return "API_REG";
1363     case BTA_AV_API_DEREGISTER_EVT:
1364       return "API_DEREG";
1365     case BTA_AV_API_DISCONNECT_EVT:
1366       return "API_DISCNT";
1367     case BTA_AV_CI_SRC_DATA_READY_EVT:
1368       return "CI_DATA_READY";
1369     case BTA_AV_SIG_CHG_EVT:
1370       return "SIG_CHG";
1371     case BTA_AV_SIGNALLING_TIMER_EVT:
1372       return "SIGNALLING_TIMER";
1373     case BTA_AV_SDP_AVRC_DISC_EVT:
1374       return "SDP_AVRC_DISC";
1375     case BTA_AV_AVRC_CLOSE_EVT:
1376       return "AVRC_CLOSE";
1377     case BTA_AV_AVRC_BROWSE_OPEN_EVT:
1378       return "AVRC_BROWSE_OPEN";
1379     case BTA_AV_AVRC_BROWSE_CLOSE_EVT:
1380       return "AVRC_BROWSE_CLOSE";
1381     case BTA_AV_CONN_CHG_EVT:
1382       return "CONN_CHG";
1383     case BTA_AV_DEREG_COMP_EVT:
1384       return "DEREG_COMP";
1385     case BTA_AV_AVDT_RPT_CONN_EVT:
1386       return "RPT_CONN";
1387     case BTA_AV_API_START_EVT:
1388       return "API_START";
1389     case BTA_AV_API_STOP_EVT:
1390       return "API_STOP";
1391     default:
1392       return "unknown";
1393   }
1394 }
1395 
bta_debug_av_dump(int fd)1396 void bta_debug_av_dump(int fd) {
1397   if (appl_trace_level < BT_TRACE_LEVEL_DEBUG) return;
1398 
1399   dprintf(fd, "\nBTA AV State:\n");
1400   dprintf(fd, "  State Machine State: %s\n", bta_av_st_code(bta_av_cb.state));
1401   dprintf(fd, "  SDP A2DP source handle: %d\n", bta_av_cb.sdp_a2dp_handle);
1402   dprintf(fd, "  SDP A2DP sink handle: %d\n", bta_av_cb.sdp_a2dp_snk_handle);
1403   dprintf(fd, "  Features: 0x%x\n", bta_av_cb.features);
1404   dprintf(fd, "  SDP handle: %d\n", bta_av_cb.handle);
1405   dprintf(fd, "  Disabling: %s\n", bta_av_cb.disabling ? "true" : "false");
1406   dprintf(fd, "  SCO occupied: %s\n",
1407           bta_av_cb.sco_occupied ? "true" : "false");
1408   dprintf(fd, "  Connected audio channels: %d\n", bta_av_cb.audio_open_cnt);
1409   dprintf(fd, "  Connected audio channels mask: 0x%x\n", bta_av_cb.conn_audio);
1410   dprintf(fd, "  Registered audio channels mask: 0x%x\n", bta_av_cb.reg_audio);
1411   dprintf(fd, "  Connected LCBs mask: 0x%x\n", bta_av_cb.conn_lcb);
1412   dprintf(fd, "  Offload start pending handle: %d\n",
1413           bta_av_cb.offload_start_pending_hndl);
1414   dprintf(fd, "  Offload started handle: %d\n", bta_av_cb.offload_started_hndl);
1415 
1416   for (size_t i = 0; i < sizeof(bta_av_cb.lcb) / sizeof(bta_av_cb.lcb[0]);
1417        i++) {
1418     const tBTA_AV_LCB& lcb = bta_av_cb.lcb[i];
1419     if (lcb.addr.IsEmpty()) {
1420       continue;
1421     }
1422     dprintf(fd, "\n  Link control block: %zu peer: %s\n", i,
1423             lcb.addr.ToString().c_str());
1424     dprintf(fd, "    Connected stream handle mask: 0x%x\n", lcb.conn_msk);
1425     dprintf(fd, "    Index(+1) to LCB: %d\n", lcb.lidx);
1426   }
1427   for (size_t i = 0; i < BTA_AV_NUM_STRS; i++) {
1428     const tBTA_AV_SCB* p_scb = bta_av_cb.p_scb[i];
1429     if (p_scb == nullptr) {
1430       continue;
1431     }
1432     if (p_scb->PeerAddress().IsEmpty()) {
1433       continue;
1434     }
1435     dprintf(fd, "\n  BTA ID: %zu peer: %s\n", i,
1436             p_scb->PeerAddress().ToString().c_str());
1437     dprintf(fd, "    SDP discovery started: %s\n",
1438             p_scb->sdp_discovery_started ? "true" : "false");
1439     for (size_t j = 0; j < BTAV_A2DP_CODEC_INDEX_MAX; j++) {
1440       const tBTA_AV_SEP& sep = p_scb->seps[j];
1441       if (sep.av_handle == 0) {
1442         continue;
1443       }
1444       dprintf(fd, "    SEP ID: %zu\n", j);
1445       dprintf(fd, "      SEP AVDTP handle: %d\n", sep.av_handle);
1446       dprintf(fd, "      Local SEP type: %d\n", sep.tsep);
1447       dprintf(fd, "      Codec: %s\n", A2DP_CodecName(sep.codec_info));
1448     }
1449     dprintf(fd, "    BTA info tag: %d\n", p_scb->q_tag);
1450     dprintf(fd, "    API Open peer: %s\n",
1451             p_scb->q_info.open.bd_addr.ToString().c_str());
1452     dprintf(fd, "      Use AVRCP: %s\n",
1453             p_scb->q_info.open.use_rc ? "true" : "false");
1454     dprintf(fd, "      Switch result: %d\n", p_scb->q_info.open.switch_res);
1455     dprintf(fd, "      Initiator UUID: 0x%x\n", p_scb->q_info.open.uuid);
1456     dprintf(fd, "    Saved API Open peer: %s\n",
1457             p_scb->open_api.bd_addr.ToString().c_str());
1458     dprintf(fd, "      Use AVRCP: %s\n",
1459             p_scb->open_api.use_rc ? "true" : "false");
1460     dprintf(fd, "      Switch result: %d\n", p_scb->open_api.switch_res);
1461     dprintf(fd, "      Initiator UUID: 0x%x\n", p_scb->open_api.uuid);
1462     dprintf(fd, "  Link signalling timer: %s\n",
1463             alarm_is_scheduled(p_scb->link_signalling_timer) ? "Scheduled"
1464                                                              : "Not scheduled");
1465     dprintf(fd, "  Accept signalling timer: %s\n",
1466             alarm_is_scheduled(p_scb->accept_signalling_timer)
1467                 ? "Scheduled"
1468                 : "Not scheduled");
1469     // TODO: Print p_scb->sep_info[], cfg, avrc_ct_timer, current_codec ?
1470     dprintf(fd, "    L2CAP Channel ID: %d\n", p_scb->l2c_cid);
1471     dprintf(fd, "    Stream MTU: %d\n", p_scb->stream_mtu);
1472     dprintf(fd, "    AVDTP version: 0x%x\n", p_scb->AvdtpVersion());
1473     dprintf(fd, "    Media type: %d\n", p_scb->media_type);
1474     dprintf(fd, "    Congested: %s\n", p_scb->cong ? "true" : "false");
1475     dprintf(fd, "    Open status: %d\n", p_scb->open_status);
1476     dprintf(fd, "    Channel: %d\n", p_scb->chnl);
1477     dprintf(fd, "    BTA handle: 0x%x\n", p_scb->hndl);
1478     dprintf(fd, "    Protocol service capabilities mask: 0x%x\n",
1479             p_scb->cur_psc_mask);
1480     dprintf(fd, "    AVDTP handle: %d\n", p_scb->avdt_handle);
1481     dprintf(fd, "    Stream control block index: %d\n", p_scb->hdi);
1482     dprintf(fd, "    State machine state: %s(%d)\n",
1483             bta_av_sst_code(p_scb->state), p_scb->state);
1484     dprintf(fd, "    AVDTP label: 0x%x\n", p_scb->avdt_label);
1485     dprintf(fd, "    Application ID: %d\n", p_scb->app_id);
1486     dprintf(fd, "    Role: 0x%x\n", p_scb->role);
1487     dprintf(fd, "    Queued L2CAP buffers: %d\n", p_scb->l2c_bufs);
1488     dprintf(fd, "    AVRCP allowed: %s\n", p_scb->use_rc ? "true" : "false");
1489     dprintf(fd, "    Stream started: %s\n", p_scb->started ? "true" : "false");
1490     dprintf(fd, "    Stream call-out started: %d\n", p_scb->co_started);
1491     dprintf(fd, "    AVDTP Reconfig supported: %s\n",
1492             p_scb->recfg_sup ? "true" : "false");
1493     dprintf(fd, "    AVDTP Suspend supported: %s\n",
1494             p_scb->suspend_sup ? "true" : "false");
1495     dprintf(fd, "    Deregistering: %s\n",
1496             p_scb->deregistering ? "true" : "false");
1497     dprintf(fd, "    SCO automatic Suspend: %s\n",
1498             p_scb->sco_suspend ? "true" : "false");
1499     dprintf(fd, "    Incoming/outgoing connection collusion mask: 0x%x\n",
1500             p_scb->coll_mask);
1501     dprintf(fd, "    Wait mask: 0x%x\n", p_scb->wait);
1502     dprintf(fd, "    Don't use RTP header: %s\n",
1503             p_scb->no_rtp_header ? "true" : "false");
1504     dprintf(fd, "    Intended UUID of Initiator to connect to: 0x%x\n",
1505             p_scb->uuid_int);
1506   }
1507 }
1508