]> git.proxmox.com Git - mirror_ubuntu-hirsute-kernel.git/blame - drivers/char/toshiba.c
Crypto/chcr: fix gcm-aes and rfc4106-gcm failed tests
[mirror_ubuntu-hirsute-kernel.git] / drivers / char / toshiba.c
CommitLineData
2e97506a 1// SPDX-License-Identifier: GPL-2.0-or-later
1da177e4
LT
2/* toshiba.c -- Linux driver for accessing the SMM on Toshiba laptops
3 *
4 * Copyright (c) 1996-2001 Jonathan A. Buzzard (jonathan@buzzard.org.uk)
5 *
6 * Valuable assistance and patches from:
7 * Tom May <tom@you-bastards.com>
8 * Rob Napier <rnapier@employees.org>
9 *
10 * Fn status port numbers for machine ID's courtesy of
11 * 0xfc02: Scott Eisert <scott.e@sky-eye.com>
12 * 0xfc04: Steve VanDevender <stevev@efn.org>
13 * 0xfc08: Garth Berry <garth@itsbruce.net>
14 * 0xfc0a: Egbert Eich <eich@xfree86.org>
15 * 0xfc10: Andrew Lofthouse <Andrew.Lofthouse@robins.af.mil>
16 * 0xfc11: Spencer Olson <solson@novell.com>
17 * 0xfc13: Claudius Frankewitz <kryp@gmx.de>
18 * 0xfc15: Tom May <tom@you-bastards.com>
19 * 0xfc17: Dave Konrad <konrad@xenia.it>
20 * 0xfc1a: George Betzos <betzos@engr.colostate.edu>
21 * 0xfc1b: Munemasa Wada <munemasa@jnovel.co.jp>
22 * 0xfc1d: Arthur Liu <armie@slap.mine.nu>
23 * 0xfc5a: Jacques L'helgoualc'h <lhh@free.fr>
24 * 0xfcd1: Mr. Dave Konrad <konrad@xenia.it>
25 *
26 * WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
27 *
28 * This code is covered by the GNU GPL and you are free to make any
29 * changes you wish to it under the terms of the license. However the
30 * code has the potential to render your computer and/or someone else's
31 * unusable. Please proceed with care when modifying the code.
32 *
33 * Note: Unfortunately the laptop hardware can close the System Configuration
34 * Interface on it's own accord. It is therefore necessary for *all*
35 * programs using this driver to be aware that *any* SCI call can fail at
36 * *any* time. It is up to any program to be aware of this eventuality
37 * and take appropriate steps.
38 *
1da177e4
LT
39 * The information used to write this driver has been obtained by reverse
40 * engineering the software supplied by Toshiba for their portable computers in
41 * strict accordance with the European Council Directive 92/250/EEC on the legal
42 * protection of computer programs, and it's implementation into English Law by
43 * the Copyright (Computer Programs) Regulations 1992 (S.I. 1992 No.3233).
1da177e4
LT
44 */
45
46#define TOSH_VERSION "1.11 26/9/2001"
47#define TOSH_DEBUG 0
48
49#include <linux/module.h>
50#include <linux/kernel.h>
1da177e4
LT
51#include <linux/types.h>
52#include <linux/fcntl.h>
53#include <linux/miscdevice.h>
54#include <linux/ioport.h>
55#include <asm/io.h>
7c0f6ba6 56#include <linux/uaccess.h>
1da177e4
LT
57#include <linux/init.h>
58#include <linux/stat.h>
59#include <linux/proc_fs.h>
967bb77c 60#include <linux/seq_file.h>
613655fa 61#include <linux/mutex.h>
1da177e4
LT
62#include <linux/toshiba.h>
63
3f5f7e2e
DT
64MODULE_LICENSE("GPL");
65MODULE_AUTHOR("Jonathan Buzzard <jonathan@buzzard.org.uk>");
66MODULE_DESCRIPTION("Toshiba laptop SMM driver");
67MODULE_SUPPORTED_DEVICE("toshiba");
1da177e4 68
613655fa 69static DEFINE_MUTEX(tosh_mutex);
3f5f7e2e
DT
70static int tosh_fn;
71module_param_named(fn, tosh_fn, int, 0);
72MODULE_PARM_DESC(fn, "User specified Fn key detection port");
1da177e4 73
3f5f7e2e
DT
74static int tosh_id;
75static int tosh_bios;
76static int tosh_date;
77static int tosh_sci;
78static int tosh_fan;
1da177e4 79
3e8d95d9 80static long tosh_ioctl(struct file *, unsigned int,
1da177e4
LT
81 unsigned long);
82
83
62322d25 84static const struct file_operations tosh_fops = {
1da177e4 85 .owner = THIS_MODULE,
3e8d95d9 86 .unlocked_ioctl = tosh_ioctl,
6038f373 87 .llseek = noop_llseek,
1da177e4
LT
88};
89
90static struct miscdevice tosh_device = {
91 TOSH_MINOR_DEV,
92 "toshiba",
93 &tosh_fops
94};
95
96/*
97 * Read the Fn key status
98 */
99#ifdef CONFIG_PROC_FS
100static int tosh_fn_status(void)
101{
102 unsigned char scan;
103 unsigned long flags;
104
105 if (tosh_fn!=0) {
106 scan = inb(tosh_fn);
107 } else {
108 local_irq_save(flags);
109 outb(0x8e, 0xe4);
110 scan = inb(0xe5);
111 local_irq_restore(flags);
112 }
113
114 return (int) scan;
115}
116#endif
117
118
119/*
120 * For the Portage 610CT and the Tecra 700CS/700CDT emulate the HCI fan function
121 */
122static int tosh_emulate_fan(SMMRegisters *regs)
123{
124 unsigned long eax,ecx,flags;
125 unsigned char al;
126
127 eax = regs->eax & 0xff00;
128 ecx = regs->ecx & 0xffff;
129
130 /* Portage 610CT */
131
132 if (tosh_id==0xfccb) {
133 if (eax==0xfe00) {
134 /* fan status */
135 local_irq_save(flags);
136 outb(0xbe, 0xe4);
137 al = inb(0xe5);
138 local_irq_restore(flags);
139 regs->eax = 0x00;
140 regs->ecx = (unsigned int) (al & 0x01);
141 }
142 if ((eax==0xff00) && (ecx==0x0000)) {
143 /* fan off */
144 local_irq_save(flags);
145 outb(0xbe, 0xe4);
146 al = inb(0xe5);
147 outb(0xbe, 0xe4);
148 outb (al | 0x01, 0xe5);
149 local_irq_restore(flags);
150 regs->eax = 0x00;
151 regs->ecx = 0x00;
152 }
153 if ((eax==0xff00) && (ecx==0x0001)) {
154 /* fan on */
155 local_irq_save(flags);
156 outb(0xbe, 0xe4);
157 al = inb(0xe5);
158 outb(0xbe, 0xe4);
159 outb(al & 0xfe, 0xe5);
160 local_irq_restore(flags);
161 regs->eax = 0x00;
162 regs->ecx = 0x01;
163 }
164 }
165
166 /* Tecra 700CS/CDT */
167
168 if (tosh_id==0xfccc) {
169 if (eax==0xfe00) {
170 /* fan status */
171 local_irq_save(flags);
172 outb(0xe0, 0xe4);
173 al = inb(0xe5);
174 local_irq_restore(flags);
175 regs->eax = 0x00;
176 regs->ecx = al & 0x01;
177 }
178 if ((eax==0xff00) && (ecx==0x0000)) {
179 /* fan off */
180 local_irq_save(flags);
181 outb(0xe0, 0xe4);
182 al = inb(0xe5);
183 outw(0xe0 | ((al & 0xfe) << 8), 0xe4);
184 local_irq_restore(flags);
185 regs->eax = 0x00;
186 regs->ecx = 0x00;
187 }
188 if ((eax==0xff00) && (ecx==0x0001)) {
189 /* fan on */
190 local_irq_save(flags);
191 outb(0xe0, 0xe4);
192 al = inb(0xe5);
193 outw(0xe0 | ((al | 0x01) << 8), 0xe4);
194 local_irq_restore(flags);
195 regs->eax = 0x00;
196 regs->ecx = 0x01;
197 }
198 }
199
200 return 0;
201}
202
203
204/*
205 * Put the laptop into System Management Mode
206 */
207int tosh_smm(SMMRegisters *regs)
208{
209 int eax;
210
211 asm ("# load the values into the registers\n\t" \
212 "pushl %%eax\n\t" \
213 "movl 0(%%eax),%%edx\n\t" \
214 "push %%edx\n\t" \
215 "movl 4(%%eax),%%ebx\n\t" \
216 "movl 8(%%eax),%%ecx\n\t" \
217 "movl 12(%%eax),%%edx\n\t" \
218 "movl 16(%%eax),%%esi\n\t" \
219 "movl 20(%%eax),%%edi\n\t" \
220 "popl %%eax\n\t" \
221 "# call the System Management mode\n\t" \
222 "inb $0xb2,%%al\n\t"
223 "# fill out the memory with the values in the registers\n\t" \
224 "xchgl %%eax,(%%esp)\n\t"
225 "movl %%ebx,4(%%eax)\n\t" \
226 "movl %%ecx,8(%%eax)\n\t" \
227 "movl %%edx,12(%%eax)\n\t" \
228 "movl %%esi,16(%%eax)\n\t" \
229 "movl %%edi,20(%%eax)\n\t" \
230 "popl %%edx\n\t" \
231 "movl %%edx,0(%%eax)\n\t" \
232 "# setup the return value to the carry flag\n\t" \
233 "lahf\n\t" \
234 "shrl $8,%%eax\n\t" \
235 "andl $1,%%eax\n" \
236 : "=a" (eax)
237 : "a" (regs)
238 : "%ebx", "%ecx", "%edx", "%esi", "%edi", "memory");
239
240 return eax;
241}
0bf93226 242EXPORT_SYMBOL(tosh_smm);
1da177e4
LT
243
244
3e8d95d9 245static long tosh_ioctl(struct file *fp, unsigned int cmd, unsigned long arg)
1da177e4
LT
246{
247 SMMRegisters regs;
248 SMMRegisters __user *argp = (SMMRegisters __user *)arg;
249 unsigned short ax,bx;
250 int err;
251
252 if (!argp)
253 return -EINVAL;
254
255 if (copy_from_user(&regs, argp, sizeof(SMMRegisters)))
256 return -EFAULT;
257
258 switch (cmd) {
259 case TOSH_SMM:
260 ax = regs.eax & 0xff00;
261 bx = regs.ebx & 0xffff;
262 /* block HCI calls to read/write memory & PCI devices */
263 if (((ax==0xff00) || (ax==0xfe00)) && (bx>0x0069))
264 return -EINVAL;
265
266 /* do we need to emulate the fan ? */
613655fa 267 mutex_lock(&tosh_mutex);
1da177e4
LT
268 if (tosh_fan==1) {
269 if (((ax==0xf300) || (ax==0xf400)) && (bx==0x0004)) {
270 err = tosh_emulate_fan(&regs);
613655fa 271 mutex_unlock(&tosh_mutex);
1da177e4
LT
272 break;
273 }
274 }
275 err = tosh_smm(&regs);
613655fa 276 mutex_unlock(&tosh_mutex);
1da177e4
LT
277 break;
278 default:
279 return -EINVAL;
280 }
281
282 if (copy_to_user(argp, &regs, sizeof(SMMRegisters)))
283 return -EFAULT;
284
285 return (err==0) ? 0:-EINVAL;
286}
287
288
289/*
290 * Print the information for /proc/toshiba
291 */
292#ifdef CONFIG_PROC_FS
967bb77c 293static int proc_toshiba_show(struct seq_file *m, void *v)
1da177e4 294{
1da177e4
LT
295 int key;
296
1da177e4
LT
297 key = tosh_fn_status();
298
299 /* Arguments
300 0) Linux driver version (this will change if format changes)
301 1) Machine ID
302 2) SCI version
303 3) BIOS version (major, minor)
304 4) BIOS date (in SCI date format)
305 5) Fn Key status
306 */
967bb77c 307 seq_printf(m, "1.1 0x%04x %d.%d %d.%d 0x%04x 0x%02x\n",
1da177e4
LT
308 tosh_id,
309 (tosh_sci & 0xff00)>>8,
310 tosh_sci & 0xff,
311 (tosh_bios & 0xff00)>>8,
312 tosh_bios & 0xff,
313 tosh_date,
314 key);
967bb77c
AD
315 return 0;
316}
1da177e4
LT
317#endif
318
319
320/*
321 * Determine which port to use for the Fn key status
322 */
323static void tosh_set_fn_port(void)
324{
325 switch (tosh_id) {
326 case 0xfc02: case 0xfc04: case 0xfc09: case 0xfc0a: case 0xfc10:
327 case 0xfc11: case 0xfc13: case 0xfc15: case 0xfc1a: case 0xfc1b:
328 case 0xfc5a:
329 tosh_fn = 0x62;
330 break;
331 case 0xfc08: case 0xfc17: case 0xfc1d: case 0xfcd1: case 0xfce0:
332 case 0xfce2:
333 tosh_fn = 0x68;
334 break;
335 default:
336 tosh_fn = 0x00;
337 break;
338 }
339
340 return;
341}
342
343
344/*
345 * Get the machine identification number of the current model
346 */
ef5a4c8b 347static int tosh_get_machine_id(void __iomem *bios)
1da177e4
LT
348{
349 int id;
350 SMMRegisters regs;
351 unsigned short bx,cx;
352 unsigned long address;
353
ef5a4c8b 354 id = (0x100*(int) readb(bios+0xfffe))+((int) readb(bios+0xfffa));
3f5f7e2e 355
1da177e4
LT
356 /* do we have a SCTTable machine identication number on our hands */
357
358 if (id==0xfc2f) {
359
360 /* start by getting a pointer into the BIOS */
361
362 regs.eax = 0xc000;
363 regs.ebx = 0x0000;
364 regs.ecx = 0x0000;
365 tosh_smm(&regs);
366 bx = (unsigned short) (regs.ebx & 0xffff);
367
368 /* At this point in the Toshiba routines under MS Windows
369 the bx register holds 0xe6f5. However my code is producing
370 a different value! For the time being I will just fudge the
371 value. This has been verified on a Satellite Pro 430CDT,
372 Tecra 750CDT, Tecra 780DVD and Satellite 310CDT. */
373#if TOSH_DEBUG
13c1d4b3 374 pr_debug("toshiba: debugging ID ebx=0x%04x\n", regs.ebx);
1da177e4
LT
375#endif
376 bx = 0xe6f5;
377
378 /* now twiddle with our pointer a bit */
379
ef5a4c8b
AV
380 address = bx;
381 cx = readw(bios + address);
382 address = 9+bx+cx;
383 cx = readw(bios + address);
384 address = 0xa+cx;
385 cx = readw(bios + address);
1da177e4
LT
386
387 /* now construct our machine identification number */
388
389 id = ((cx & 0xff)<<8)+((cx & 0xff00)>>8);
390 }
391
392 return id;
393}
394
395
396/*
397 * Probe for the presence of a Toshiba laptop
398 *
399 * returns and non-zero if unable to detect the presence of a Toshiba
400 * laptop, otherwise zero and determines the Machine ID, BIOS version and
401 * date, and SCI version.
402 */
403static int tosh_probe(void)
404{
405 int i,major,minor,day,year,month,flag;
406 unsigned char signature[7] = { 0x54,0x4f,0x53,0x48,0x49,0x42,0x41 };
407 SMMRegisters regs;
48166932 408 void __iomem *bios = ioremap(0xf0000, 0x10000);
ef5a4c8b
AV
409
410 if (!bios)
411 return -ENOMEM;
1da177e4
LT
412
413 /* extra sanity check for the string "TOSHIBA" in the BIOS because
414 some machines that are not Toshiba's pass the next test */
415
416 for (i=0;i<7;i++) {
ef5a4c8b 417 if (readb(bios+0xe010+i)!=signature[i]) {
13c1d4b3 418 pr_err("toshiba: not a supported Toshiba laptop\n");
ef5a4c8b 419 iounmap(bios);
1da177e4
LT
420 return -ENODEV;
421 }
422 }
423
424 /* call the Toshiba SCI support check routine */
3f5f7e2e 425
1da177e4
LT
426 regs.eax = 0xf0f0;
427 regs.ebx = 0x0000;
428 regs.ecx = 0x0000;
429 flag = tosh_smm(&regs);
430
431 /* if this is not a Toshiba laptop carry flag is set and ah=0x86 */
432
433 if ((flag==1) || ((regs.eax & 0xff00)==0x8600)) {
13c1d4b3 434 pr_err("toshiba: not a supported Toshiba laptop\n");
ef5a4c8b 435 iounmap(bios);
1da177e4
LT
436 return -ENODEV;
437 }
438
439 /* if we get this far then we are running on a Toshiba (probably)! */
440
441 tosh_sci = regs.edx & 0xffff;
3f5f7e2e 442
1da177e4
LT
443 /* next get the machine ID of the current laptop */
444
ef5a4c8b 445 tosh_id = tosh_get_machine_id(bios);
1da177e4
LT
446
447 /* get the BIOS version */
448
ef5a4c8b
AV
449 major = readb(bios+0xe009)-'0';
450 minor = ((readb(bios+0xe00b)-'0')*10)+(readb(bios+0xe00c)-'0');
1da177e4
LT
451 tosh_bios = (major*0x100)+minor;
452
453 /* get the BIOS date */
454
ef5a4c8b
AV
455 day = ((readb(bios+0xfff5)-'0')*10)+(readb(bios+0xfff6)-'0');
456 month = ((readb(bios+0xfff8)-'0')*10)+(readb(bios+0xfff9)-'0');
457 year = ((readb(bios+0xfffb)-'0')*10)+(readb(bios+0xfffc)-'0');
1da177e4
LT
458 tosh_date = (((year-90) & 0x1f)<<10) | ((month & 0xf)<<6)
459 | ((day & 0x1f)<<1);
460
461
462 /* in theory we should check the ports we are going to use for the
463 fn key detection (and the fan on the Portage 610/Tecra700), and
464 then request them to stop other drivers using them. However as
465 the keyboard driver grabs 0x60-0x6f and the pic driver grabs
466 0xa0-0xbf we can't. We just have to live dangerously and use the
467 ports anyway, oh boy! */
468
469 /* do we need to emulate the fan? */
470
471 if ((tosh_id==0xfccb) || (tosh_id==0xfccc))
472 tosh_fan = 1;
473
ef5a4c8b
AV
474 iounmap(bios);
475
1da177e4
LT
476 return 0;
477}
478
3f5f7e2e 479static int __init toshiba_init(void)
1da177e4
LT
480{
481 int retval;
482 /* are we running on a Toshiba laptop */
483
3f5f7e2e
DT
484 if (tosh_probe())
485 return -ENODEV;
1da177e4 486
13c1d4b3 487 pr_info("Toshiba System Management Mode driver v" TOSH_VERSION "\n");
1da177e4
LT
488
489 /* set the port to use for Fn status if not specified as a parameter */
490 if (tosh_fn==0x00)
491 tosh_set_fn_port();
492
493 /* register the device file */
494 retval = misc_register(&tosh_device);
3f5f7e2e 495 if (retval < 0)
1da177e4
LT
496 return retval;
497
498#ifdef CONFIG_PROC_FS
967bb77c
AD
499 {
500 struct proc_dir_entry *pde;
501
3f3942ac 502 pde = proc_create_single("toshiba", 0, NULL, proc_toshiba_show);
967bb77c
AD
503 if (!pde) {
504 misc_deregister(&tosh_device);
505 return -ENOMEM;
506 }
1da177e4
LT
507 }
508#endif
509
510 return 0;
511}
512
3f5f7e2e 513static void __exit toshiba_exit(void)
1da177e4 514{
1da177e4 515 remove_proc_entry("toshiba", NULL);
1da177e4
LT
516 misc_deregister(&tosh_device);
517}
1da177e4 518
3f5f7e2e
DT
519module_init(toshiba_init);
520module_exit(toshiba_exit);
1da177e4 521