3 * Intel Management Engine Interface (Intel MEI) Linux driver
4 * Copyright (c) 2003-2012, Intel Corporation.
6 * This program is free software; you can redistribute it and/or modify it
7 * under the terms and conditions of the GNU General Public License,
8 * version 2, as published by the Free Software Foundation.
10 * This program is distributed in the hope it will be useful, but WITHOUT
11 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
12 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
17 #include <linux/kernel.h>
19 #include <linux/errno.h>
20 #include <linux/types.h>
21 #include <linux/fcntl.h>
22 #include <linux/ioctl.h>
23 #include <linux/cdev.h>
24 #include <linux/list.h>
25 #include <linux/delay.h>
26 #include <linux/sched.h>
27 #include <linux/uuid.h>
28 #include <linux/jiffies.h>
29 #include <linux/uaccess.h>
30 #include <linux/slab.h>
32 #include <linux/mei.h>
38 const uuid_le mei_amthif_guid = UUID_LE(0x12f80028, 0xb4b7, 0x4b2d,
39 0xac, 0xa8, 0x46, 0xe0,
40 0xff, 0x65, 0x81, 0x4c);
43 * mei_amthif_reset_params - initializes mei device iamthif
45 * @dev: the device structure
47 void mei_amthif_reset_params(struct mei_device *dev)
49 /* reset iamthif parameters. */
50 dev->iamthif_current_cb = NULL;
51 dev->iamthif_msg_buf_size = 0;
52 dev->iamthif_msg_buf_index = 0;
53 dev->iamthif_canceled = false;
54 dev->iamthif_ioctl = false;
55 dev->iamthif_state = MEI_IAMTHIF_IDLE;
56 dev->iamthif_timer = 0;
57 dev->iamthif_stall_timer = 0;
58 dev->iamthif_open_count = 0;
62 * mei_amthif_host_init - mei initialization amthif client.
64 * @dev: the device structure
66 * Return: 0 on success, <0 on failure.
68 int mei_amthif_host_init(struct mei_device *dev)
70 struct mei_cl *cl = &dev->iamthif_cl;
71 struct mei_me_client *me_cl;
72 unsigned char *msg_buf;
75 dev->iamthif_state = MEI_IAMTHIF_IDLE;
79 me_cl = mei_me_cl_by_uuid(dev, &mei_amthif_guid);
81 dev_info(dev->dev, "amthif: failed to find the client");
85 cl->me_client_id = me_cl->client_id;
86 cl->cl_uuid = me_cl->props.protocol_name;
88 /* Assign iamthif_mtu to the value received from ME */
90 dev->iamthif_mtu = me_cl->props.max_msg_length;
91 dev_dbg(dev->dev, "IAMTHIF_MTU = %d\n", dev->iamthif_mtu);
93 kfree(dev->iamthif_msg_buf);
94 dev->iamthif_msg_buf = NULL;
96 /* allocate storage for ME message buffer */
97 msg_buf = kcalloc(dev->iamthif_mtu,
98 sizeof(unsigned char), GFP_KERNEL);
104 dev->iamthif_msg_buf = msg_buf;
106 ret = mei_cl_link(cl, MEI_IAMTHIF_HOST_CLIENT_ID);
108 dev_err(dev->dev, "amthif: failed cl_link %d\n", ret);
112 ret = mei_cl_connect(cl, NULL);
114 dev->iamthif_state = MEI_IAMTHIF_IDLE;
117 mei_me_cl_put(me_cl);
122 * mei_amthif_find_read_list_entry - finds a amthilist entry for current file
124 * @dev: the device structure
125 * @file: pointer to file object
127 * Return: returned a list entry on success, NULL on failure.
129 struct mei_cl_cb *mei_amthif_find_read_list_entry(struct mei_device *dev,
132 struct mei_cl_cb *cb;
134 list_for_each_entry(cb, &dev->amthif_rd_complete_list.list, list)
135 if (cb->file_object == file)
142 * mei_amthif_read - read data from AMTHIF client
144 * @dev: the device structure
145 * @file: pointer to file object
146 * @ubuf: pointer to user data in user space
147 * @length: data length to read
148 * @offset: data read offset
150 * Locking: called under "dev->device_lock" lock
153 * returned data length on success,
154 * zero if no data to read,
155 * negative on failure.
157 int mei_amthif_read(struct mei_device *dev, struct file *file,
158 char __user *ubuf, size_t length, loff_t *offset)
160 struct mei_cl *cl = file->private_data;
161 struct mei_cl_cb *cb;
162 unsigned long timeout;
166 /* Only possible if we are in timeout */
168 dev_err(dev->dev, "bad file ext.\n");
172 dev_dbg(dev->dev, "checking amthif data\n");
173 cb = mei_amthif_find_read_list_entry(dev, file);
175 /* Check for if we can block or not*/
176 if (cb == NULL && file->f_flags & O_NONBLOCK)
180 dev_dbg(dev->dev, "waiting for amthif data\n");
182 /* unlock the Mutex */
183 mutex_unlock(&dev->device_lock);
185 wait_ret = wait_event_interruptible(dev->iamthif_cl.wait,
186 (cb = mei_amthif_find_read_list_entry(dev, file)));
188 /* Locking again the Mutex */
189 mutex_lock(&dev->device_lock);
194 dev_dbg(dev->dev, "woke up from sleep\n");
198 dev_dbg(dev->dev, "Got amthif data\n");
199 dev->iamthif_timer = 0;
202 timeout = cb->read_time +
203 mei_secs_to_jiffies(MEI_IAMTHIF_READ_TIMER);
204 dev_dbg(dev->dev, "amthif timeout = %lud\n",
207 if (time_after(jiffies, timeout)) {
208 dev_dbg(dev->dev, "amthif Time out\n");
209 /* 15 sec for the message has expired */
215 /* if the whole message will fit remove it from the list */
216 if (cb->buf_idx >= *offset && length >= (cb->buf_idx - *offset))
218 else if (cb->buf_idx > 0 && cb->buf_idx <= *offset) {
219 /* end of the message has been reached */
224 /* else means that not full buffer will be read and do not
225 * remove message from deletion list
228 dev_dbg(dev->dev, "amthif cb->response_buffer size - %d\n",
229 cb->response_buffer.size);
230 dev_dbg(dev->dev, "amthif cb->buf_idx - %lu\n", cb->buf_idx);
232 /* length is being truncated to PAGE_SIZE, however,
233 * the buf_idx may point beyond */
234 length = min_t(size_t, length, (cb->buf_idx - *offset));
236 if (copy_to_user(ubuf, cb->response_buffer.data + *offset, length)) {
237 dev_dbg(dev->dev, "failed to copy data to userland\n");
241 if ((*offset + length) < cb->buf_idx) {
247 dev_dbg(dev->dev, "free amthif cb memory.\n");
255 * mei_amthif_send_cmd - send amthif command to the ME
257 * @dev: the device structure
258 * @cb: mei call back struct
260 * Return: 0 on success, <0 on failure.
263 static int mei_amthif_send_cmd(struct mei_device *dev, struct mei_cl_cb *cb)
265 struct mei_msg_hdr mei_hdr;
272 dev_dbg(dev->dev, "write data to amthif client.\n");
274 dev->iamthif_state = MEI_IAMTHIF_WRITING;
275 dev->iamthif_current_cb = cb;
276 dev->iamthif_file_object = cb->file_object;
277 dev->iamthif_canceled = false;
278 dev->iamthif_ioctl = true;
279 dev->iamthif_msg_buf_size = cb->request_buffer.size;
280 memcpy(dev->iamthif_msg_buf, cb->request_buffer.data,
281 cb->request_buffer.size);
282 cl = &dev->iamthif_cl;
284 ret = mei_cl_flow_ctrl_creds(cl);
288 if (ret && mei_hbuf_acquire(dev)) {
290 if (cb->request_buffer.size > mei_hbuf_max_len(dev)) {
291 mei_hdr.length = mei_hbuf_max_len(dev);
292 mei_hdr.msg_complete = 0;
294 mei_hdr.length = cb->request_buffer.size;
295 mei_hdr.msg_complete = 1;
298 mei_hdr.host_addr = cl->host_client_id;
299 mei_hdr.me_addr = cl->me_client_id;
300 mei_hdr.reserved = 0;
301 mei_hdr.internal = 0;
302 dev->iamthif_msg_buf_index += mei_hdr.length;
303 ret = mei_write_message(dev, &mei_hdr, dev->iamthif_msg_buf);
307 if (mei_hdr.msg_complete) {
308 if (mei_cl_flow_ctrl_reduce(cl))
310 dev->iamthif_flow_control_pending = true;
311 dev->iamthif_state = MEI_IAMTHIF_FLOW_CONTROL;
312 dev_dbg(dev->dev, "add amthif cb to write waiting list\n");
313 dev->iamthif_current_cb = cb;
314 dev->iamthif_file_object = cb->file_object;
315 list_add_tail(&cb->list, &dev->write_waiting_list.list);
317 dev_dbg(dev->dev, "message does not complete, so add amthif cb to write list.\n");
318 list_add_tail(&cb->list, &dev->write_list.list);
321 list_add_tail(&cb->list, &dev->write_list.list);
327 * mei_amthif_write - write amthif data to amthif client
329 * @dev: the device structure
330 * @cb: mei call back struct
332 * Return: 0 on success, <0 on failure.
335 int mei_amthif_write(struct mei_device *dev, struct mei_cl_cb *cb)
342 ret = mei_io_cb_alloc_resp_buf(cb, dev->iamthif_mtu);
346 cb->fop_type = MEI_FOP_WRITE;
348 if (!list_empty(&dev->amthif_cmd_list.list) ||
349 dev->iamthif_state != MEI_IAMTHIF_IDLE) {
351 "amthif state = %d\n", dev->iamthif_state);
352 dev_dbg(dev->dev, "AMTHIF: add cb to the wait list\n");
353 list_add_tail(&cb->list, &dev->amthif_cmd_list.list);
356 return mei_amthif_send_cmd(dev, cb);
359 * mei_amthif_run_next_cmd - send next amt command from queue
361 * @dev: the device structure
363 void mei_amthif_run_next_cmd(struct mei_device *dev)
365 struct mei_cl_cb *cb;
371 dev->iamthif_msg_buf_size = 0;
372 dev->iamthif_msg_buf_index = 0;
373 dev->iamthif_canceled = false;
374 dev->iamthif_ioctl = true;
375 dev->iamthif_state = MEI_IAMTHIF_IDLE;
376 dev->iamthif_timer = 0;
377 dev->iamthif_file_object = NULL;
379 dev_dbg(dev->dev, "complete amthif cmd_list cb.\n");
381 cb = list_first_entry_or_null(&dev->amthif_cmd_list.list,
386 ret = mei_amthif_send_cmd(dev, cb);
388 dev_warn(dev->dev, "amthif write failed status = %d\n", ret);
392 unsigned int mei_amthif_poll(struct mei_device *dev,
393 struct file *file, poll_table *wait)
395 unsigned int mask = 0;
397 poll_wait(file, &dev->iamthif_cl.wait, wait);
399 mutex_lock(&dev->device_lock);
400 if (!mei_cl_is_connected(&dev->iamthif_cl)) {
404 } else if (dev->iamthif_state == MEI_IAMTHIF_READ_COMPLETE &&
405 dev->iamthif_file_object == file) {
407 mask |= (POLLIN | POLLRDNORM);
408 dev_dbg(dev->dev, "run next amthif cb\n");
409 mei_amthif_run_next_cmd(dev);
411 mutex_unlock(&dev->device_lock);
419 * mei_amthif_irq_write - write iamthif command in irq thread context.
421 * @cl: private data of the file object.
422 * @cb: callback block.
423 * @cmpl_list: complete list.
425 * Return: 0, OK; otherwise, error.
427 int mei_amthif_irq_write(struct mei_cl *cl, struct mei_cl_cb *cb,
428 struct mei_cl_cb *cmpl_list)
430 struct mei_device *dev = cl->dev;
431 struct mei_msg_hdr mei_hdr;
432 size_t len = dev->iamthif_msg_buf_size - dev->iamthif_msg_buf_index;
433 u32 msg_slots = mei_data2slots(len);
437 rets = mei_cl_flow_ctrl_creds(cl);
442 cl_dbg(dev, cl, "No flow control credentials: not sending.\n");
446 mei_hdr.host_addr = cl->host_client_id;
447 mei_hdr.me_addr = cl->me_client_id;
448 mei_hdr.reserved = 0;
449 mei_hdr.internal = 0;
451 slots = mei_hbuf_empty_slots(dev);
453 if (slots >= msg_slots) {
454 mei_hdr.length = len;
455 mei_hdr.msg_complete = 1;
456 /* Split the message only if we can write the whole host buffer */
457 } else if (slots == dev->hbuf_depth) {
459 len = (slots * sizeof(u32)) - sizeof(struct mei_msg_hdr);
460 mei_hdr.length = len;
461 mei_hdr.msg_complete = 0;
463 /* wait for next time the host buffer is empty */
467 dev_dbg(dev->dev, MEI_HDR_FMT, MEI_HDR_PRM(&mei_hdr));
469 rets = mei_write_message(dev, &mei_hdr,
470 dev->iamthif_msg_buf + dev->iamthif_msg_buf_index);
472 dev->iamthif_state = MEI_IAMTHIF_IDLE;
478 if (mei_cl_flow_ctrl_reduce(cl))
481 dev->iamthif_msg_buf_index += mei_hdr.length;
484 if (mei_hdr.msg_complete) {
485 dev->iamthif_state = MEI_IAMTHIF_FLOW_CONTROL;
486 dev->iamthif_flow_control_pending = true;
488 /* save iamthif cb sent to amthif client */
489 cb->buf_idx = dev->iamthif_msg_buf_index;
490 dev->iamthif_current_cb = cb;
492 list_move_tail(&cb->list, &dev->write_waiting_list.list);
500 * mei_amthif_irq_read_msg - read routine after ISR to
501 * handle the read amthif message
503 * @dev: the device structure
504 * @mei_hdr: header of amthif message
505 * @complete_list: An instance of our list structure
507 * Return: 0 on success, <0 on failure.
509 int mei_amthif_irq_read_msg(struct mei_device *dev,
510 struct mei_msg_hdr *mei_hdr,
511 struct mei_cl_cb *complete_list)
513 struct mei_cl_cb *cb;
514 unsigned char *buffer;
516 BUG_ON(mei_hdr->me_addr != dev->iamthif_cl.me_client_id);
517 BUG_ON(dev->iamthif_state != MEI_IAMTHIF_READING);
519 buffer = dev->iamthif_msg_buf + dev->iamthif_msg_buf_index;
520 BUG_ON(dev->iamthif_mtu < dev->iamthif_msg_buf_index + mei_hdr->length);
522 mei_read_slots(dev, buffer, mei_hdr->length);
524 dev->iamthif_msg_buf_index += mei_hdr->length;
526 if (!mei_hdr->msg_complete)
529 dev_dbg(dev->dev, "amthif_message_buffer_index =%d\n",
532 dev_dbg(dev->dev, "completed amthif read.\n ");
533 if (!dev->iamthif_current_cb)
536 cb = dev->iamthif_current_cb;
537 dev->iamthif_current_cb = NULL;
539 dev->iamthif_stall_timer = 0;
540 cb->buf_idx = dev->iamthif_msg_buf_index;
541 cb->read_time = jiffies;
542 if (dev->iamthif_ioctl) {
543 /* found the iamthif cb */
544 dev_dbg(dev->dev, "complete the amthif read cb.\n ");
545 dev_dbg(dev->dev, "add the amthif read cb to complete.\n ");
546 list_add_tail(&cb->list, &complete_list->list);
552 * mei_amthif_irq_read - prepares to read amthif data.
554 * @dev: the device structure.
555 * @slots: free slots.
557 * Return: 0, OK; otherwise, error.
559 int mei_amthif_irq_read(struct mei_device *dev, s32 *slots)
561 u32 msg_slots = mei_data2slots(sizeof(struct hbm_flow_control));
563 if (*slots < msg_slots)
568 if (mei_hbm_cl_flow_control_req(dev, &dev->iamthif_cl)) {
569 dev_dbg(dev->dev, "iamthif flow control failed\n");
573 dev_dbg(dev->dev, "iamthif flow control success\n");
574 dev->iamthif_state = MEI_IAMTHIF_READING;
575 dev->iamthif_flow_control_pending = false;
576 dev->iamthif_msg_buf_index = 0;
577 dev->iamthif_msg_buf_size = 0;
578 dev->iamthif_stall_timer = MEI_IAMTHIF_STALL_TIMER;
579 dev->hbuf_is_ready = mei_hbuf_is_ready(dev);
584 * mei_amthif_complete - complete amthif callback.
586 * @dev: the device structure.
587 * @cb: callback block.
589 void mei_amthif_complete(struct mei_device *dev, struct mei_cl_cb *cb)
591 if (dev->iamthif_canceled != 1) {
592 dev->iamthif_state = MEI_IAMTHIF_READ_COMPLETE;
593 dev->iamthif_stall_timer = 0;
594 memcpy(cb->response_buffer.data,
595 dev->iamthif_msg_buf,
596 dev->iamthif_msg_buf_index);
597 list_add_tail(&cb->list, &dev->amthif_rd_complete_list.list);
598 dev_dbg(dev->dev, "amthif read completed\n");
599 dev->iamthif_timer = jiffies;
600 dev_dbg(dev->dev, "dev->iamthif_timer = %ld\n",
603 mei_amthif_run_next_cmd(dev);
606 dev_dbg(dev->dev, "completing amthif call back.\n");
607 wake_up_interruptible(&dev->iamthif_cl.wait);
611 * mei_clear_list - removes all callbacks associated with file
614 * @dev: device structure.
615 * @file: file structure
616 * @mei_cb_list: callbacks list
618 * mei_clear_list is called to clear resources associated with file
619 * when application calls close function or Ctrl-C was pressed
621 * Return: true if callback removed from the list, false otherwise
623 static bool mei_clear_list(struct mei_device *dev,
624 const struct file *file, struct list_head *mei_cb_list)
626 struct mei_cl_cb *cb_pos = NULL;
627 struct mei_cl_cb *cb_next = NULL;
628 bool removed = false;
630 /* list all list member */
631 list_for_each_entry_safe(cb_pos, cb_next, mei_cb_list, list) {
632 /* check if list member associated with a file */
633 if (file == cb_pos->file_object) {
634 /* remove member from the list */
635 list_del(&cb_pos->list);
636 /* check if cb equal to current iamthif cb */
637 if (dev->iamthif_current_cb == cb_pos) {
638 dev->iamthif_current_cb = NULL;
639 /* send flow control to iamthif client */
640 mei_hbm_cl_flow_control_req(dev,
643 /* free all allocated buffers */
644 mei_io_cb_free(cb_pos);
653 * mei_clear_lists - removes all callbacks associated with file
655 * @dev: device structure
656 * @file: file structure
658 * mei_clear_lists is called to clear resources associated with file
659 * when application calls close function or Ctrl-C was pressed
661 * Return: true if callback removed from the list, false otherwise
663 static bool mei_clear_lists(struct mei_device *dev, struct file *file)
665 bool removed = false;
667 /* remove callbacks associated with a file */
668 mei_clear_list(dev, file, &dev->amthif_cmd_list.list);
669 if (mei_clear_list(dev, file, &dev->amthif_rd_complete_list.list))
672 mei_clear_list(dev, file, &dev->ctrl_rd_list.list);
674 if (mei_clear_list(dev, file, &dev->ctrl_wr_list.list))
677 if (mei_clear_list(dev, file, &dev->write_waiting_list.list))
680 if (mei_clear_list(dev, file, &dev->write_list.list))
683 /* check if iamthif_current_cb not NULL */
684 if (dev->iamthif_current_cb && !removed) {
685 /* check file and iamthif current cb association */
686 if (dev->iamthif_current_cb->file_object == file) {
688 mei_io_cb_free(dev->iamthif_current_cb);
689 dev->iamthif_current_cb = NULL;
697 * mei_amthif_release - the release function
699 * @dev: device structure
700 * @file: pointer to file structure
702 * Return: 0 on success, <0 on error
704 int mei_amthif_release(struct mei_device *dev, struct file *file)
706 if (dev->iamthif_open_count > 0)
707 dev->iamthif_open_count--;
709 if (dev->iamthif_file_object == file &&
710 dev->iamthif_state != MEI_IAMTHIF_IDLE) {
712 dev_dbg(dev->dev, "amthif canceled iamthif state %d\n",
714 dev->iamthif_canceled = true;
715 if (dev->iamthif_state == MEI_IAMTHIF_READ_COMPLETE) {
716 dev_dbg(dev->dev, "run next amthif iamthif cb\n");
717 mei_amthif_run_next_cmd(dev);
721 if (mei_clear_lists(dev, file))
722 dev->iamthif_state = MEI_IAMTHIF_IDLE;