]> Pileus Git - ~andy/linux/blob - drivers/misc/mei/main.c
mei: revamp hbm state machine
[~andy/linux] / drivers / misc / mei / main.c
1 /*
2  *
3  * Intel Management Engine Interface (Intel MEI) Linux driver
4  * Copyright (c) 2003-2012, Intel Corporation.
5  *
6  * This program is free software; you can redistribute it and/or modify it
7  * under the terms and conditions of the GNU General Public License,
8  * version 2, as published by the Free Software Foundation.
9  *
10  * This program is distributed in the hope it will be useful, but WITHOUT
11  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
12  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for
13  * more details.
14  *
15  */
16
17 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
18
19 #include <linux/module.h>
20 #include <linux/moduleparam.h>
21 #include <linux/kernel.h>
22 #include <linux/device.h>
23 #include <linux/fs.h>
24 #include <linux/errno.h>
25 #include <linux/types.h>
26 #include <linux/fcntl.h>
27 #include <linux/aio.h>
28 #include <linux/pci.h>
29 #include <linux/poll.h>
30 #include <linux/init.h>
31 #include <linux/ioctl.h>
32 #include <linux/cdev.h>
33 #include <linux/sched.h>
34 #include <linux/uuid.h>
35 #include <linux/compat.h>
36 #include <linux/jiffies.h>
37 #include <linux/interrupt.h>
38 #include <linux/miscdevice.h>
39
40 #include <linux/mei.h>
41
42 #include "mei_dev.h"
43 #include "hw-me.h"
44 #include "client.h"
45
46 /**
47  * mei_open - the open function
48  *
49  * @inode: pointer to inode structure
50  * @file: pointer to file structure
51  e
52  * returns 0 on success, <0 on error
53  */
54 static int mei_open(struct inode *inode, struct file *file)
55 {
56         struct miscdevice *misc = file->private_data;
57         struct pci_dev *pdev;
58         struct mei_cl *cl;
59         struct mei_device *dev;
60
61         int err;
62
63         err = -ENODEV;
64         if (!misc->parent)
65                 goto out;
66
67         pdev = container_of(misc->parent, struct pci_dev, dev);
68
69         dev = pci_get_drvdata(pdev);
70         if (!dev)
71                 goto out;
72
73         mutex_lock(&dev->device_lock);
74         err = -ENOMEM;
75         cl = mei_cl_allocate(dev);
76         if (!cl)
77                 goto out_unlock;
78
79         err = -ENODEV;
80         if (dev->dev_state != MEI_DEV_ENABLED) {
81                 dev_dbg(&dev->pdev->dev, "dev_state != MEI_ENABLED  dev_state = %s\n",
82                     mei_dev_state_str(dev->dev_state));
83                 goto out_unlock;
84         }
85         err = -EMFILE;
86         if (dev->open_handle_count >= MEI_MAX_OPEN_HANDLE_COUNT) {
87                 dev_err(&dev->pdev->dev, "open_handle_count exceded %d",
88                         MEI_MAX_OPEN_HANDLE_COUNT);
89                 goto out_unlock;
90         }
91
92         err = mei_cl_link(cl, MEI_HOST_CLIENT_ID_ANY);
93         if (err)
94                 goto out_unlock;
95
96         file->private_data = cl;
97         mutex_unlock(&dev->device_lock);
98
99         return nonseekable_open(inode, file);
100
101 out_unlock:
102         mutex_unlock(&dev->device_lock);
103         kfree(cl);
104 out:
105         return err;
106 }
107
108 /**
109  * mei_release - the release function
110  *
111  * @inode: pointer to inode structure
112  * @file: pointer to file structure
113  *
114  * returns 0 on success, <0 on error
115  */
116 static int mei_release(struct inode *inode, struct file *file)
117 {
118         struct mei_cl *cl = file->private_data;
119         struct mei_cl_cb *cb;
120         struct mei_device *dev;
121         int rets = 0;
122
123         if (WARN_ON(!cl || !cl->dev))
124                 return -ENODEV;
125
126         dev = cl->dev;
127
128         mutex_lock(&dev->device_lock);
129         if (cl == &dev->iamthif_cl) {
130                 rets = mei_amthif_release(dev, file);
131                 goto out;
132         }
133         if (cl->state == MEI_FILE_CONNECTED) {
134                 cl->state = MEI_FILE_DISCONNECTING;
135                 dev_dbg(&dev->pdev->dev,
136                         "disconnecting client host client = %d, "
137                     "ME client = %d\n",
138                     cl->host_client_id,
139                     cl->me_client_id);
140                 rets = mei_cl_disconnect(cl);
141         }
142         mei_cl_flush_queues(cl);
143         dev_dbg(&dev->pdev->dev, "remove client host client = %d, ME client = %d\n",
144             cl->host_client_id,
145             cl->me_client_id);
146
147         if (dev->open_handle_count > 0) {
148                 clear_bit(cl->host_client_id, dev->host_clients_map);
149                 dev->open_handle_count--;
150         }
151         mei_cl_unlink(cl);
152
153
154         /* free read cb */
155         cb = NULL;
156         if (cl->read_cb) {
157                 cb = mei_cl_find_read_cb(cl);
158                 /* Remove entry from read list */
159                 if (cb)
160                         list_del(&cb->list);
161
162                 cb = cl->read_cb;
163                 cl->read_cb = NULL;
164         }
165
166         file->private_data = NULL;
167
168         if (cb) {
169                 mei_io_cb_free(cb);
170                 cb = NULL;
171         }
172
173         kfree(cl);
174 out:
175         mutex_unlock(&dev->device_lock);
176         return rets;
177 }
178
179
180 /**
181  * mei_read - the read function.
182  *
183  * @file: pointer to file structure
184  * @ubuf: pointer to user buffer
185  * @length: buffer length
186  * @offset: data offset in buffer
187  *
188  * returns >=0 data length on success , <0 on error
189  */
190 static ssize_t mei_read(struct file *file, char __user *ubuf,
191                         size_t length, loff_t *offset)
192 {
193         struct mei_cl *cl = file->private_data;
194         struct mei_cl_cb *cb_pos = NULL;
195         struct mei_cl_cb *cb = NULL;
196         struct mei_device *dev;
197         int i;
198         int rets;
199         int err;
200
201
202         if (WARN_ON(!cl || !cl->dev))
203                 return -ENODEV;
204
205         dev = cl->dev;
206
207         mutex_lock(&dev->device_lock);
208         if (dev->dev_state != MEI_DEV_ENABLED) {
209                 rets = -ENODEV;
210                 goto out;
211         }
212
213         if ((cl->sm_state & MEI_WD_STATE_INDEPENDENCE_MSG_SENT) == 0) {
214                 /* Do not allow to read watchdog client */
215                 i = mei_me_cl_by_uuid(dev, &mei_wd_guid);
216                 if (i >= 0) {
217                         struct mei_me_client *me_client = &dev->me_clients[i];
218                         if (cl->me_client_id == me_client->client_id) {
219                                 rets = -EBADF;
220                                 goto out;
221                         }
222                 }
223         } else {
224                 cl->sm_state &= ~MEI_WD_STATE_INDEPENDENCE_MSG_SENT;
225         }
226
227         if (cl == &dev->iamthif_cl) {
228                 rets = mei_amthif_read(dev, file, ubuf, length, offset);
229                 goto out;
230         }
231
232         if (cl->read_cb && cl->read_cb->buf_idx > *offset) {
233                 cb = cl->read_cb;
234                 goto copy_buffer;
235         } else if (cl->read_cb && cl->read_cb->buf_idx > 0 &&
236                    cl->read_cb->buf_idx <= *offset) {
237                 cb = cl->read_cb;
238                 rets = 0;
239                 goto free;
240         } else if ((!cl->read_cb || !cl->read_cb->buf_idx) && *offset > 0) {
241                 /*Offset needs to be cleaned for contiguous reads*/
242                 *offset = 0;
243                 rets = 0;
244                 goto out;
245         }
246
247         err = mei_cl_read_start(cl);
248         if (err && err != -EBUSY) {
249                 dev_dbg(&dev->pdev->dev,
250                         "mei start read failure with status = %d\n", err);
251                 rets = err;
252                 goto out;
253         }
254
255         if (MEI_READ_COMPLETE != cl->reading_state &&
256                         !waitqueue_active(&cl->rx_wait)) {
257                 if (file->f_flags & O_NONBLOCK) {
258                         rets = -EAGAIN;
259                         goto out;
260                 }
261
262                 mutex_unlock(&dev->device_lock);
263
264                 if (wait_event_interruptible(cl->rx_wait,
265                         (MEI_READ_COMPLETE == cl->reading_state ||
266                          MEI_FILE_INITIALIZING == cl->state ||
267                          MEI_FILE_DISCONNECTED == cl->state ||
268                          MEI_FILE_DISCONNECTING == cl->state))) {
269                         if (signal_pending(current))
270                                 return -EINTR;
271                         return -ERESTARTSYS;
272                 }
273
274                 mutex_lock(&dev->device_lock);
275                 if (MEI_FILE_INITIALIZING == cl->state ||
276                     MEI_FILE_DISCONNECTED == cl->state ||
277                     MEI_FILE_DISCONNECTING == cl->state) {
278                         rets = -EBUSY;
279                         goto out;
280                 }
281         }
282
283         cb = cl->read_cb;
284
285         if (!cb) {
286                 rets = -ENODEV;
287                 goto out;
288         }
289         if (cl->reading_state != MEI_READ_COMPLETE) {
290                 rets = 0;
291                 goto out;
292         }
293         /* now copy the data to user space */
294 copy_buffer:
295         dev_dbg(&dev->pdev->dev, "cb->response_buffer size - %d\n",
296             cb->response_buffer.size);
297         dev_dbg(&dev->pdev->dev, "cb->buf_idx - %lu\n", cb->buf_idx);
298         if (length == 0 || ubuf == NULL || *offset > cb->buf_idx) {
299                 rets = -EMSGSIZE;
300                 goto free;
301         }
302
303         /* length is being truncated to PAGE_SIZE,
304          * however buf_idx may point beyond that */
305         length = min_t(size_t, length, cb->buf_idx - *offset);
306
307         if (copy_to_user(ubuf, cb->response_buffer.data + *offset, length)) {
308                 rets = -EFAULT;
309                 goto free;
310         }
311
312         rets = length;
313         *offset += length;
314         if ((unsigned long)*offset < cb->buf_idx)
315                 goto out;
316
317 free:
318         cb_pos = mei_cl_find_read_cb(cl);
319         /* Remove entry from read list */
320         if (cb_pos)
321                 list_del(&cb_pos->list);
322         mei_io_cb_free(cb);
323         cl->reading_state = MEI_IDLE;
324         cl->read_cb = NULL;
325 out:
326         dev_dbg(&dev->pdev->dev, "end mei read rets= %d\n", rets);
327         mutex_unlock(&dev->device_lock);
328         return rets;
329 }
330 /**
331  * mei_write - the write function.
332  *
333  * @file: pointer to file structure
334  * @ubuf: pointer to user buffer
335  * @length: buffer length
336  * @offset: data offset in buffer
337  *
338  * returns >=0 data length on success , <0 on error
339  */
340 static ssize_t mei_write(struct file *file, const char __user *ubuf,
341                          size_t length, loff_t *offset)
342 {
343         struct mei_cl *cl = file->private_data;
344         struct mei_cl_cb *write_cb = NULL;
345         struct mei_device *dev;
346         unsigned long timeout = 0;
347         int rets;
348         int id;
349
350         if (WARN_ON(!cl || !cl->dev))
351                 return -ENODEV;
352
353         dev = cl->dev;
354
355         mutex_lock(&dev->device_lock);
356
357         if (dev->dev_state != MEI_DEV_ENABLED) {
358                 rets = -ENODEV;
359                 goto out;
360         }
361
362         id = mei_me_cl_by_id(dev, cl->me_client_id);
363         if (id < 0) {
364                 rets = -ENODEV;
365                 goto out;
366         }
367         if (length > dev->me_clients[id].props.max_msg_length || length <= 0) {
368                 rets = -EMSGSIZE;
369                 goto out;
370         }
371
372         if (cl->state != MEI_FILE_CONNECTED) {
373                 dev_err(&dev->pdev->dev, "host client = %d,  is not connected to ME client = %d",
374                         cl->host_client_id, cl->me_client_id);
375                 rets = -ENODEV;
376                 goto out;
377         }
378         if (cl == &dev->iamthif_cl) {
379                 write_cb = mei_amthif_find_read_list_entry(dev, file);
380
381                 if (write_cb) {
382                         timeout = write_cb->read_time +
383                                 mei_secs_to_jiffies(MEI_IAMTHIF_READ_TIMER);
384
385                         if (time_after(jiffies, timeout) ||
386                             cl->reading_state == MEI_READ_COMPLETE) {
387                                 *offset = 0;
388                                 list_del(&write_cb->list);
389                                 mei_io_cb_free(write_cb);
390                                 write_cb = NULL;
391                         }
392                 }
393         }
394
395         /* free entry used in read */
396         if (cl->reading_state == MEI_READ_COMPLETE) {
397                 *offset = 0;
398                 write_cb = mei_cl_find_read_cb(cl);
399                 if (write_cb) {
400                         list_del(&write_cb->list);
401                         mei_io_cb_free(write_cb);
402                         write_cb = NULL;
403                         cl->reading_state = MEI_IDLE;
404                         cl->read_cb = NULL;
405                 }
406         } else if (cl->reading_state == MEI_IDLE)
407                 *offset = 0;
408
409
410         write_cb = mei_io_cb_init(cl, file);
411         if (!write_cb) {
412                 dev_err(&dev->pdev->dev, "write cb allocation failed\n");
413                 rets = -ENOMEM;
414                 goto out;
415         }
416         rets = mei_io_cb_alloc_req_buf(write_cb, length);
417         if (rets)
418                 goto out;
419
420         rets = copy_from_user(write_cb->request_buffer.data, ubuf, length);
421         if (rets)
422                 goto out;
423
424         cl->sm_state = 0;
425         if (length == 4 &&
426             ((memcmp(mei_wd_state_independence_msg[0],
427                                  write_cb->request_buffer.data, 4) == 0) ||
428              (memcmp(mei_wd_state_independence_msg[1],
429                                  write_cb->request_buffer.data, 4) == 0) ||
430              (memcmp(mei_wd_state_independence_msg[2],
431                                  write_cb->request_buffer.data, 4) == 0)))
432                 cl->sm_state |= MEI_WD_STATE_INDEPENDENCE_MSG_SENT;
433
434         if (cl == &dev->iamthif_cl) {
435                 rets = mei_amthif_write(dev, write_cb);
436
437                 if (rets) {
438                         dev_err(&dev->pdev->dev,
439                                 "amthif write failed with status = %d\n", rets);
440                         goto out;
441                 }
442                 mutex_unlock(&dev->device_lock);
443                 return length;
444         }
445
446         rets = mei_cl_write(cl, write_cb, false);
447 out:
448         mutex_unlock(&dev->device_lock);
449         if (rets < 0)
450                 mei_io_cb_free(write_cb);
451         return rets;
452 }
453
454 /**
455  * mei_ioctl_connect_client - the connect to fw client IOCTL function
456  *
457  * @dev: the device structure
458  * @data: IOCTL connect data, input and output parameters
459  * @file: private data of the file object
460  *
461  * Locking: called under "dev->device_lock" lock
462  *
463  * returns 0 on success, <0 on failure.
464  */
465 static int mei_ioctl_connect_client(struct file *file,
466                         struct mei_connect_client_data *data)
467 {
468         struct mei_device *dev;
469         struct mei_client *client;
470         struct mei_cl *cl;
471         int i;
472         int rets;
473
474         cl = file->private_data;
475         if (WARN_ON(!cl || !cl->dev))
476                 return -ENODEV;
477
478         dev = cl->dev;
479
480         if (dev->dev_state != MEI_DEV_ENABLED) {
481                 rets = -ENODEV;
482                 goto end;
483         }
484
485         if (cl->state != MEI_FILE_INITIALIZING &&
486             cl->state != MEI_FILE_DISCONNECTED) {
487                 rets = -EBUSY;
488                 goto end;
489         }
490
491         /* find ME client we're trying to connect to */
492         i = mei_me_cl_by_uuid(dev, &data->in_client_uuid);
493         if (i >= 0 && !dev->me_clients[i].props.fixed_address) {
494                 cl->me_client_id = dev->me_clients[i].client_id;
495                 cl->state = MEI_FILE_CONNECTING;
496         }
497
498         dev_dbg(&dev->pdev->dev, "Connect to FW Client ID = %d\n",
499                         cl->me_client_id);
500         dev_dbg(&dev->pdev->dev, "FW Client - Protocol Version = %d\n",
501                         dev->me_clients[i].props.protocol_version);
502         dev_dbg(&dev->pdev->dev, "FW Client - Max Msg Len = %d\n",
503                         dev->me_clients[i].props.max_msg_length);
504
505         /* if we're connecting to amthif client then we will use the
506          * existing connection
507          */
508         if (uuid_le_cmp(data->in_client_uuid, mei_amthif_guid) == 0) {
509                 dev_dbg(&dev->pdev->dev, "FW Client is amthi\n");
510                 if (dev->iamthif_cl.state != MEI_FILE_CONNECTED) {
511                         rets = -ENODEV;
512                         goto end;
513                 }
514                 clear_bit(cl->host_client_id, dev->host_clients_map);
515                 mei_cl_unlink(cl);
516
517                 kfree(cl);
518                 cl = NULL;
519                 file->private_data = &dev->iamthif_cl;
520
521                 client = &data->out_client_properties;
522                 client->max_msg_length =
523                         dev->me_clients[i].props.max_msg_length;
524                 client->protocol_version =
525                         dev->me_clients[i].props.protocol_version;
526                 rets = dev->iamthif_cl.status;
527
528                 goto end;
529         }
530
531         if (cl->state != MEI_FILE_CONNECTING) {
532                 rets = -ENODEV;
533                 goto end;
534         }
535
536
537         /* prepare the output buffer */
538         client = &data->out_client_properties;
539         client->max_msg_length = dev->me_clients[i].props.max_msg_length;
540         client->protocol_version = dev->me_clients[i].props.protocol_version;
541         dev_dbg(&dev->pdev->dev, "Can connect?\n");
542
543
544         rets = mei_cl_connect(cl, file);
545
546 end:
547         dev_dbg(&dev->pdev->dev, "free connect cb memory.");
548         return rets;
549 }
550
551
552 /**
553  * mei_ioctl - the IOCTL function
554  *
555  * @file: pointer to file structure
556  * @cmd: ioctl command
557  * @data: pointer to mei message structure
558  *
559  * returns 0 on success , <0 on error
560  */
561 static long mei_ioctl(struct file *file, unsigned int cmd, unsigned long data)
562 {
563         struct mei_device *dev;
564         struct mei_cl *cl = file->private_data;
565         struct mei_connect_client_data *connect_data = NULL;
566         int rets;
567
568         if (cmd != IOCTL_MEI_CONNECT_CLIENT)
569                 return -EINVAL;
570
571         if (WARN_ON(!cl || !cl->dev))
572                 return -ENODEV;
573
574         dev = cl->dev;
575
576         dev_dbg(&dev->pdev->dev, "IOCTL cmd = 0x%x", cmd);
577
578         mutex_lock(&dev->device_lock);
579         if (dev->dev_state != MEI_DEV_ENABLED) {
580                 rets = -ENODEV;
581                 goto out;
582         }
583
584         dev_dbg(&dev->pdev->dev, ": IOCTL_MEI_CONNECT_CLIENT.\n");
585
586         connect_data = kzalloc(sizeof(struct mei_connect_client_data),
587                                                         GFP_KERNEL);
588         if (!connect_data) {
589                 rets = -ENOMEM;
590                 goto out;
591         }
592         dev_dbg(&dev->pdev->dev, "copy connect data from user\n");
593         if (copy_from_user(connect_data, (char __user *)data,
594                                 sizeof(struct mei_connect_client_data))) {
595                 dev_dbg(&dev->pdev->dev, "failed to copy data from userland\n");
596                 rets = -EFAULT;
597                 goto out;
598         }
599
600         rets = mei_ioctl_connect_client(file, connect_data);
601
602         /* if all is ok, copying the data back to user. */
603         if (rets)
604                 goto out;
605
606         dev_dbg(&dev->pdev->dev, "copy connect data to user\n");
607         if (copy_to_user((char __user *)data, connect_data,
608                                 sizeof(struct mei_connect_client_data))) {
609                 dev_dbg(&dev->pdev->dev, "failed to copy data to userland\n");
610                 rets = -EFAULT;
611                 goto out;
612         }
613
614 out:
615         kfree(connect_data);
616         mutex_unlock(&dev->device_lock);
617         return rets;
618 }
619
620 /**
621  * mei_compat_ioctl - the compat IOCTL function
622  *
623  * @file: pointer to file structure
624  * @cmd: ioctl command
625  * @data: pointer to mei message structure
626  *
627  * returns 0 on success , <0 on error
628  */
629 #ifdef CONFIG_COMPAT
630 static long mei_compat_ioctl(struct file *file,
631                         unsigned int cmd, unsigned long data)
632 {
633         return mei_ioctl(file, cmd, (unsigned long)compat_ptr(data));
634 }
635 #endif
636
637
638 /**
639  * mei_poll - the poll function
640  *
641  * @file: pointer to file structure
642  * @wait: pointer to poll_table structure
643  *
644  * returns poll mask
645  */
646 static unsigned int mei_poll(struct file *file, poll_table *wait)
647 {
648         struct mei_cl *cl = file->private_data;
649         struct mei_device *dev;
650         unsigned int mask = 0;
651
652         if (WARN_ON(!cl || !cl->dev))
653                 return mask;
654
655         dev = cl->dev;
656
657         mutex_lock(&dev->device_lock);
658
659         if (dev->dev_state != MEI_DEV_ENABLED)
660                 goto out;
661
662
663         if (cl == &dev->iamthif_cl) {
664                 mask = mei_amthif_poll(dev, file, wait);
665                 goto out;
666         }
667
668         mutex_unlock(&dev->device_lock);
669         poll_wait(file, &cl->tx_wait, wait);
670         mutex_lock(&dev->device_lock);
671         if (MEI_WRITE_COMPLETE == cl->writing_state)
672                 mask |= (POLLIN | POLLRDNORM);
673
674 out:
675         mutex_unlock(&dev->device_lock);
676         return mask;
677 }
678
679 /*
680  * file operations structure will be used for mei char device.
681  */
682 static const struct file_operations mei_fops = {
683         .owner = THIS_MODULE,
684         .read = mei_read,
685         .unlocked_ioctl = mei_ioctl,
686 #ifdef CONFIG_COMPAT
687         .compat_ioctl = mei_compat_ioctl,
688 #endif
689         .open = mei_open,
690         .release = mei_release,
691         .write = mei_write,
692         .poll = mei_poll,
693         .llseek = no_llseek
694 };
695
696 /*
697  * Misc Device Struct
698  */
699 static struct miscdevice  mei_misc_device = {
700                 .name = "mei",
701                 .fops = &mei_fops,
702                 .minor = MISC_DYNAMIC_MINOR,
703 };
704
705
706 int mei_register(struct mei_device *dev)
707 {
708         int ret;
709         mei_misc_device.parent = &dev->pdev->dev;
710         ret = misc_register(&mei_misc_device);
711         if (ret)
712                 return ret;
713
714         if (mei_dbgfs_register(dev, mei_misc_device.name))
715                 dev_err(&dev->pdev->dev, "cannot register debugfs\n");
716
717         return 0;
718 }
719 EXPORT_SYMBOL_GPL(mei_register);
720
721 void mei_deregister(struct mei_device *dev)
722 {
723         mei_dbgfs_deregister(dev);
724         misc_deregister(&mei_misc_device);
725         mei_misc_device.parent = NULL;
726 }
727 EXPORT_SYMBOL_GPL(mei_deregister);
728
729 static int __init mei_init(void)
730 {
731         return mei_cl_bus_init();
732 }
733
734 static void __exit mei_exit(void)
735 {
736         mei_cl_bus_exit();
737 }
738
739 module_init(mei_init);
740 module_exit(mei_exit);
741
742 MODULE_AUTHOR("Intel Corporation");
743 MODULE_DESCRIPTION("Intel(R) Management Engine Interface");
744 MODULE_LICENSE("GPL v2");
745