]> git.proxmox.com Git - mirror_ubuntu-artful-kernel.git/blame - drivers/firewire/fw-cdev.c
firewire: cdev: reference-count client instances
[mirror_ubuntu-artful-kernel.git] / drivers / firewire / fw-cdev.c
CommitLineData
c781c06d
KH
1/*
2 * Char device for device raw access
19a15b93 3 *
c781c06d 4 * Copyright (C) 2005-2007 Kristian Hoegsberg <krh@bitplanet.net>
19a15b93
KH
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 *
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software Foundation,
18 * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
19 */
20
21#include <linux/module.h>
22#include <linux/kernel.h>
fb443036 23#include <linux/kref.h>
19a15b93
KH
24#include <linux/wait.h>
25#include <linux/errno.h>
26#include <linux/device.h>
27#include <linux/vmalloc.h>
d67cfb96 28#include <linux/mutex.h>
19a15b93 29#include <linux/poll.h>
a64408b9
SR
30#include <linux/preempt.h>
31#include <linux/time.h>
cf417e54 32#include <linux/spinlock.h>
19a15b93
KH
33#include <linux/delay.h>
34#include <linux/mm.h>
a3aca3da 35#include <linux/idr.h>
19a15b93 36#include <linux/compat.h>
9640d3d7 37#include <linux/firewire-cdev.h>
a64408b9 38#include <asm/system.h>
19a15b93
KH
39#include <asm/uaccess.h>
40#include "fw-transaction.h"
41#include "fw-topology.h"
42#include "fw-device.h"
19a15b93 43
3964a449 44struct client;
45ee3199
JF
45struct client_resource;
46typedef void (*client_resource_release_fn_t)(struct client *,
47 struct client_resource *);
3964a449 48struct client_resource {
45ee3199
JF
49 client_resource_release_fn_t release;
50 int handle;
3964a449
KH
51};
52
c781c06d
KH
53/*
54 * dequeue_event() just kfree()'s the event, so the event has to be
55 * the first field in the struct.
56 */
57
19a15b93
KH
58struct event {
59 struct { void *data; size_t size; } v[2];
60 struct list_head link;
61};
62
97bd9efa
KH
63struct bus_reset {
64 struct event event;
65 struct fw_cdev_event_bus_reset reset;
66};
67
19a15b93
KH
68struct response {
69 struct event event;
70 struct fw_transaction transaction;
71 struct client *client;
3964a449 72 struct client_resource resource;
19a15b93
KH
73 struct fw_cdev_event_response response;
74};
75
76struct iso_interrupt {
77 struct event event;
78 struct fw_cdev_event_iso_interrupt interrupt;
79};
80
81struct client {
344bbc4d 82 u32 version;
19a15b93 83 struct fw_device *device;
45ee3199 84
19a15b93 85 spinlock_t lock;
45ee3199
JF
86 bool in_shutdown;
87 struct idr resource_idr;
19a15b93 88 struct list_head event_list;
19a15b93 89 wait_queue_head_t wait;
da8ecffa 90 u64 bus_reset_closure;
9aad8125 91
19a15b93 92 struct fw_iso_context *iso_context;
abaa5743 93 u64 iso_closure;
9aad8125
KH
94 struct fw_iso_buffer buffer;
95 unsigned long vm_start;
97bd9efa
KH
96
97 struct list_head link;
fb443036 98 struct kref kref;
19a15b93
KH
99};
100
fb443036
SR
101static inline void client_get(struct client *client)
102{
103 kref_get(&client->kref);
104}
105
106static void client_release(struct kref *kref)
107{
108 struct client *client = container_of(kref, struct client, kref);
109
110 fw_device_put(client->device);
111 kfree(client);
112}
113
114static void client_put(struct client *client)
115{
116 kref_put(&client->kref, client_release);
117}
118
53dca511 119static inline void __user *u64_to_uptr(__u64 value)
19a15b93
KH
120{
121 return (void __user *)(unsigned long)value;
122}
123
53dca511 124static inline __u64 uptr_to_u64(void __user *ptr)
19a15b93
KH
125{
126 return (__u64)(unsigned long)ptr;
127}
128
129static int fw_device_op_open(struct inode *inode, struct file *file)
130{
131 struct fw_device *device;
132 struct client *client;
133
96b19062 134 device = fw_device_get_by_devt(inode->i_rdev);
a3aca3da
KH
135 if (device == NULL)
136 return -ENODEV;
19a15b93 137
551f4cb9
JF
138 if (fw_device_is_shutdown(device)) {
139 fw_device_put(device);
140 return -ENODEV;
141 }
142
2d826cc5 143 client = kzalloc(sizeof(*client), GFP_KERNEL);
96b19062
SR
144 if (client == NULL) {
145 fw_device_put(device);
19a15b93 146 return -ENOMEM;
96b19062 147 }
19a15b93 148
96b19062 149 client->device = device;
19a15b93 150 spin_lock_init(&client->lock);
45ee3199
JF
151 idr_init(&client->resource_idr);
152 INIT_LIST_HEAD(&client->event_list);
19a15b93 153 init_waitqueue_head(&client->wait);
fb443036 154 kref_init(&client->kref);
19a15b93
KH
155
156 file->private_data = client;
157
d67cfb96 158 mutex_lock(&device->client_list_mutex);
97bd9efa 159 list_add_tail(&client->link, &device->client_list);
d67cfb96 160 mutex_unlock(&device->client_list_mutex);
97bd9efa 161
19a15b93
KH
162 return 0;
163}
164
165static void queue_event(struct client *client, struct event *event,
166 void *data0, size_t size0, void *data1, size_t size1)
167{
168 unsigned long flags;
169
170 event->v[0].data = data0;
171 event->v[0].size = size0;
172 event->v[1].data = data1;
173 event->v[1].size = size1;
174
175 spin_lock_irqsave(&client->lock, flags);
45ee3199
JF
176 if (client->in_shutdown)
177 kfree(event);
178 else
179 list_add_tail(&event->link, &client->event_list);
19a15b93 180 spin_unlock_irqrestore(&client->lock, flags);
83431cba
JF
181
182 wake_up_interruptible(&client->wait);
19a15b93
KH
183}
184
53dca511
SR
185static int dequeue_event(struct client *client,
186 char __user *buffer, size_t count)
19a15b93
KH
187{
188 unsigned long flags;
189 struct event *event;
190 size_t size, total;
2dbd7d7e 191 int i, ret;
19a15b93 192
2dbd7d7e
SR
193 ret = wait_event_interruptible(client->wait,
194 !list_empty(&client->event_list) ||
195 fw_device_is_shutdown(client->device));
196 if (ret < 0)
197 return ret;
19a15b93 198
2603bf21
KH
199 if (list_empty(&client->event_list) &&
200 fw_device_is_shutdown(client->device))
201 return -ENODEV;
19a15b93 202
2603bf21 203 spin_lock_irqsave(&client->lock, flags);
a459b8ab 204 event = list_first_entry(&client->event_list, struct event, link);
19a15b93 205 list_del(&event->link);
19a15b93
KH
206 spin_unlock_irqrestore(&client->lock, flags);
207
19a15b93
KH
208 total = 0;
209 for (i = 0; i < ARRAY_SIZE(event->v) && total < count; i++) {
210 size = min(event->v[i].size, count - total);
2603bf21 211 if (copy_to_user(buffer + total, event->v[i].data, size)) {
2dbd7d7e 212 ret = -EFAULT;
19a15b93 213 goto out;
2603bf21 214 }
19a15b93
KH
215 total += size;
216 }
2dbd7d7e 217 ret = total;
19a15b93
KH
218
219 out:
220 kfree(event);
221
2dbd7d7e 222 return ret;
19a15b93
KH
223}
224
53dca511
SR
225static ssize_t fw_device_op_read(struct file *file, char __user *buffer,
226 size_t count, loff_t *offset)
19a15b93
KH
227{
228 struct client *client = file->private_data;
229
230 return dequeue_event(client, buffer, count);
231}
232
53dca511
SR
233static void fill_bus_reset_event(struct fw_cdev_event_bus_reset *event,
234 struct client *client)
344bbc4d 235{
da8ecffa 236 struct fw_card *card = client->device->card;
cf417e54
JF
237 unsigned long flags;
238
239 spin_lock_irqsave(&card->lock, flags);
344bbc4d 240
da8ecffa 241 event->closure = client->bus_reset_closure;
344bbc4d 242 event->type = FW_CDEV_EVENT_BUS_RESET;
cf5a56ac 243 event->generation = client->device->generation;
da8ecffa 244 event->node_id = client->device->node_id;
344bbc4d
KH
245 event->local_node_id = card->local_node->node_id;
246 event->bm_node_id = 0; /* FIXME: We don't track the BM. */
247 event->irm_node_id = card->irm_node->node_id;
248 event->root_node_id = card->root_node->node_id;
cf417e54
JF
249
250 spin_unlock_irqrestore(&card->lock, flags);
344bbc4d
KH
251}
252
53dca511
SR
253static void for_each_client(struct fw_device *device,
254 void (*callback)(struct client *client))
2603bf21 255{
2603bf21 256 struct client *c;
2603bf21 257
d67cfb96 258 mutex_lock(&device->client_list_mutex);
2603bf21
KH
259 list_for_each_entry(c, &device->client_list, link)
260 callback(c);
d67cfb96 261 mutex_unlock(&device->client_list_mutex);
2603bf21
KH
262}
263
53dca511 264static void queue_bus_reset_event(struct client *client)
97bd9efa
KH
265{
266 struct bus_reset *bus_reset;
97bd9efa 267
d67cfb96 268 bus_reset = kzalloc(sizeof(*bus_reset), GFP_KERNEL);
97bd9efa
KH
269 if (bus_reset == NULL) {
270 fw_notify("Out of memory when allocating bus reset event\n");
271 return;
272 }
273
da8ecffa 274 fill_bus_reset_event(&bus_reset->reset, client);
97bd9efa
KH
275
276 queue_event(client, &bus_reset->event,
2d826cc5 277 &bus_reset->reset, sizeof(bus_reset->reset), NULL, 0);
97bd9efa
KH
278}
279
280void fw_device_cdev_update(struct fw_device *device)
281{
2603bf21
KH
282 for_each_client(device, queue_bus_reset_event);
283}
97bd9efa 284
2603bf21
KH
285static void wake_up_client(struct client *client)
286{
287 wake_up_interruptible(&client->wait);
288}
97bd9efa 289
2603bf21
KH
290void fw_device_cdev_remove(struct fw_device *device)
291{
292 for_each_client(device, wake_up_client);
97bd9efa
KH
293}
294
4f259223 295static int ioctl_get_info(struct client *client, void *buffer)
19a15b93 296{
4f259223 297 struct fw_cdev_get_info *get_info = buffer;
344bbc4d 298 struct fw_cdev_event_bus_reset bus_reset;
c9755e14 299 unsigned long ret = 0;
344bbc4d 300
4f259223
KH
301 client->version = get_info->version;
302 get_info->version = FW_CDEV_VERSION;
cf417e54 303 get_info->card = client->device->card->index;
344bbc4d 304
c9755e14
SR
305 down_read(&fw_device_rwsem);
306
4f259223
KH
307 if (get_info->rom != 0) {
308 void __user *uptr = u64_to_uptr(get_info->rom);
309 size_t want = get_info->rom_length;
d84702a5 310 size_t have = client->device->config_rom_length * 4;
344bbc4d 311
c9755e14
SR
312 ret = copy_to_user(uptr, client->device->config_rom,
313 min(want, have));
344bbc4d 314 }
4f259223 315 get_info->rom_length = client->device->config_rom_length * 4;
344bbc4d 316
c9755e14
SR
317 up_read(&fw_device_rwsem);
318
319 if (ret != 0)
320 return -EFAULT;
321
4f259223
KH
322 client->bus_reset_closure = get_info->bus_reset_closure;
323 if (get_info->bus_reset != 0) {
324 void __user *uptr = u64_to_uptr(get_info->bus_reset);
344bbc4d 325
da8ecffa 326 fill_bus_reset_event(&bus_reset, client);
2d826cc5 327 if (copy_to_user(uptr, &bus_reset, sizeof(bus_reset)))
344bbc4d
KH
328 return -EFAULT;
329 }
19a15b93 330
19a15b93
KH
331 return 0;
332}
333
53dca511
SR
334static int add_client_resource(struct client *client,
335 struct client_resource *resource, gfp_t gfp_mask)
3964a449
KH
336{
337 unsigned long flags;
45ee3199
JF
338 int ret;
339
340 retry:
341 if (idr_pre_get(&client->resource_idr, gfp_mask) == 0)
342 return -ENOMEM;
3964a449
KH
343
344 spin_lock_irqsave(&client->lock, flags);
45ee3199
JF
345 if (client->in_shutdown)
346 ret = -ECANCELED;
347 else
348 ret = idr_get_new(&client->resource_idr, resource,
349 &resource->handle);
fb443036
SR
350 if (ret >= 0)
351 client_get(client);
3964a449 352 spin_unlock_irqrestore(&client->lock, flags);
45ee3199
JF
353
354 if (ret == -EAGAIN)
355 goto retry;
356
357 return ret < 0 ? ret : 0;
3964a449
KH
358}
359
53dca511
SR
360static int release_client_resource(struct client *client, u32 handle,
361 client_resource_release_fn_t release,
362 struct client_resource **resource)
3964a449
KH
363{
364 struct client_resource *r;
365 unsigned long flags;
366
367 spin_lock_irqsave(&client->lock, flags);
45ee3199
JF
368 if (client->in_shutdown)
369 r = NULL;
370 else
371 r = idr_find(&client->resource_idr, handle);
372 if (r && r->release == release)
373 idr_remove(&client->resource_idr, handle);
3964a449
KH
374 spin_unlock_irqrestore(&client->lock, flags);
375
45ee3199 376 if (!(r && r->release == release))
3964a449
KH
377 return -EINVAL;
378
379 if (resource)
380 *resource = r;
381 else
382 r->release(client, r);
383
fb443036
SR
384 client_put(client);
385
3964a449
KH
386 return 0;
387}
388
53dca511
SR
389static void release_transaction(struct client *client,
390 struct client_resource *resource)
3964a449
KH
391{
392 struct response *response =
393 container_of(resource, struct response, resource);
394
395 fw_cancel_transaction(client->device->card, &response->transaction);
396}
397
53dca511
SR
398static void complete_transaction(struct fw_card *card, int rcode,
399 void *payload, size_t length, void *data)
19a15b93
KH
400{
401 struct response *response = data;
402 struct client *client = response->client;
28cf6a04 403 unsigned long flags;
8401d92b 404 struct fw_cdev_event_response *r = &response->response;
19a15b93 405
8401d92b
DM
406 if (length < r->length)
407 r->length = length;
19a15b93 408 if (rcode == RCODE_COMPLETE)
8401d92b 409 memcpy(r->data, payload, r->length);
19a15b93 410
28cf6a04 411 spin_lock_irqsave(&client->lock, flags);
45ee3199 412 /*
fb443036
SR
413 * 1. If called while in shutdown, the idr tree must be left untouched.
414 * The idr handle will be removed and the client reference will be
415 * dropped later.
416 * 2. If the call chain was release_client_resource ->
417 * release_transaction -> complete_transaction (instead of a normal
418 * conclusion of the transaction), i.e. if this resource was already
419 * unregistered from the idr, the client reference will be dropped
420 * by release_client_resource and we must not drop it here.
45ee3199 421 */
fb443036
SR
422 if (!client->in_shutdown &&
423 idr_find(&client->resource_idr, response->resource.handle)) {
45ee3199 424 idr_remove(&client->resource_idr, response->resource.handle);
fb443036
SR
425 /* Drop the idr's reference */
426 client_put(client);
427 }
28cf6a04
KH
428 spin_unlock_irqrestore(&client->lock, flags);
429
8401d92b
DM
430 r->type = FW_CDEV_EVENT_RESPONSE;
431 r->rcode = rcode;
432
433 /*
434 * In the case that sizeof(*r) doesn't align with the position of the
435 * data, and the read is short, preserve an extra copy of the data
436 * to stay compatible with a pre-2.6.27 bug. Since the bug is harmless
437 * for short reads and some apps depended on it, this is both safe
438 * and prudent for compatibility.
439 */
440 if (r->length <= sizeof(*r) - offsetof(typeof(*r), data))
441 queue_event(client, &response->event, r, sizeof(*r),
442 r->data, r->length);
443 else
444 queue_event(client, &response->event, r, sizeof(*r) + r->length,
445 NULL, 0);
fb443036
SR
446
447 /* Drop the transaction callback's reference */
448 client_put(client);
19a15b93
KH
449}
450
350958f9 451static int ioctl_send_request(struct client *client, void *buffer)
19a15b93
KH
452{
453 struct fw_device *device = client->device;
4f259223 454 struct fw_cdev_send_request *request = buffer;
19a15b93 455 struct response *response;
1f3125af 456 int ret;
19a15b93 457
19a15b93 458 /* What is the biggest size we'll accept, really? */
4f259223 459 if (request->length > 4096)
19a15b93
KH
460 return -EINVAL;
461
2d826cc5 462 response = kmalloc(sizeof(*response) + request->length, GFP_KERNEL);
19a15b93
KH
463 if (response == NULL)
464 return -ENOMEM;
465
466 response->client = client;
4f259223
KH
467 response->response.length = request->length;
468 response->response.closure = request->closure;
19a15b93 469
4f259223 470 if (request->data &&
19a15b93 471 copy_from_user(response->response.data,
4f259223 472 u64_to_uptr(request->data), request->length)) {
1f3125af 473 ret = -EFAULT;
45ee3199 474 goto failed;
1f3125af
SR
475 }
476
477 switch (request->tcode) {
478 case TCODE_WRITE_QUADLET_REQUEST:
479 case TCODE_WRITE_BLOCK_REQUEST:
480 case TCODE_READ_QUADLET_REQUEST:
481 case TCODE_READ_BLOCK_REQUEST:
482 case TCODE_LOCK_MASK_SWAP:
483 case TCODE_LOCK_COMPARE_SWAP:
484 case TCODE_LOCK_FETCH_ADD:
485 case TCODE_LOCK_LITTLE_ADD:
486 case TCODE_LOCK_BOUNDED_ADD:
487 case TCODE_LOCK_WRAP_ADD:
488 case TCODE_LOCK_VENDOR_DEPENDENT:
489 break;
490 default:
491 ret = -EINVAL;
45ee3199 492 goto failed;
19a15b93
KH
493 }
494
3964a449 495 response->resource.release = release_transaction;
45ee3199
JF
496 ret = add_client_resource(client, &response->resource, GFP_KERNEL);
497 if (ret < 0)
498 goto failed;
28cf6a04 499
fb443036
SR
500 /* Get a reference for the transaction callback */
501 client_get(client);
502
19a15b93 503 fw_send_request(device->card, &response->transaction,
4f259223 504 request->tcode & 0x1f,
907293d7 505 device->node->node_id,
4f259223 506 request->generation,
f1397490 507 device->max_speed,
4f259223
KH
508 request->offset,
509 response->response.data, request->length,
19a15b93
KH
510 complete_transaction, response);
511
4f259223 512 if (request->data)
2d826cc5 513 return sizeof(request) + request->length;
19a15b93 514 else
2d826cc5 515 return sizeof(request);
45ee3199 516 failed:
1f3125af
SR
517 kfree(response);
518
519 return ret;
19a15b93
KH
520}
521
522struct address_handler {
523 struct fw_address_handler handler;
524 __u64 closure;
525 struct client *client;
3964a449 526 struct client_resource resource;
19a15b93
KH
527};
528
529struct request {
530 struct fw_request *request;
531 void *data;
532 size_t length;
3964a449 533 struct client_resource resource;
19a15b93
KH
534};
535
536struct request_event {
537 struct event event;
538 struct fw_cdev_event_request request;
539};
540
53dca511
SR
541static void release_request(struct client *client,
542 struct client_resource *resource)
3964a449
KH
543{
544 struct request *request =
545 container_of(resource, struct request, resource);
546
547 fw_send_response(client->device->card, request->request,
548 RCODE_CONFLICT_ERROR);
549 kfree(request);
550}
551
53dca511
SR
552static void handle_request(struct fw_card *card, struct fw_request *r,
553 int tcode, int destination, int source,
554 int generation, int speed,
555 unsigned long long offset,
556 void *payload, size_t length, void *callback_data)
19a15b93
KH
557{
558 struct address_handler *handler = callback_data;
559 struct request *request;
560 struct request_event *e;
19a15b93 561 struct client *client = handler->client;
45ee3199 562 int ret;
19a15b93 563
2d826cc5
KH
564 request = kmalloc(sizeof(*request), GFP_ATOMIC);
565 e = kmalloc(sizeof(*e), GFP_ATOMIC);
45ee3199
JF
566 if (request == NULL || e == NULL)
567 goto failed;
19a15b93
KH
568
569 request->request = r;
570 request->data = payload;
571 request->length = length;
572
3964a449 573 request->resource.release = release_request;
45ee3199
JF
574 ret = add_client_resource(client, &request->resource, GFP_ATOMIC);
575 if (ret < 0)
576 goto failed;
19a15b93
KH
577
578 e->request.type = FW_CDEV_EVENT_REQUEST;
579 e->request.tcode = tcode;
580 e->request.offset = offset;
581 e->request.length = length;
3964a449 582 e->request.handle = request->resource.handle;
19a15b93
KH
583 e->request.closure = handler->closure;
584
585 queue_event(client, &e->event,
2d826cc5 586 &e->request, sizeof(e->request), payload, length);
45ee3199
JF
587 return;
588
589 failed:
590 kfree(request);
591 kfree(e);
592 fw_send_response(card, r, RCODE_CONFLICT_ERROR);
19a15b93
KH
593}
594
53dca511
SR
595static void release_address_handler(struct client *client,
596 struct client_resource *resource)
3964a449
KH
597{
598 struct address_handler *handler =
599 container_of(resource, struct address_handler, resource);
600
601 fw_core_remove_address_handler(&handler->handler);
602 kfree(handler);
603}
604
4f259223 605static int ioctl_allocate(struct client *client, void *buffer)
19a15b93 606{
4f259223 607 struct fw_cdev_allocate *request = buffer;
19a15b93 608 struct address_handler *handler;
19a15b93 609 struct fw_address_region region;
45ee3199 610 int ret;
19a15b93 611
2d826cc5 612 handler = kmalloc(sizeof(*handler), GFP_KERNEL);
19a15b93
KH
613 if (handler == NULL)
614 return -ENOMEM;
615
4f259223
KH
616 region.start = request->offset;
617 region.end = request->offset + request->length;
618 handler->handler.length = request->length;
19a15b93
KH
619 handler->handler.address_callback = handle_request;
620 handler->handler.callback_data = handler;
4f259223 621 handler->closure = request->closure;
19a15b93
KH
622 handler->client = client;
623
3e0b5f0d
SR
624 ret = fw_core_add_address_handler(&handler->handler, &region);
625 if (ret < 0) {
19a15b93 626 kfree(handler);
3e0b5f0d 627 return ret;
19a15b93
KH
628 }
629
3964a449 630 handler->resource.release = release_address_handler;
45ee3199
JF
631 ret = add_client_resource(client, &handler->resource, GFP_KERNEL);
632 if (ret < 0) {
633 release_address_handler(client, &handler->resource);
634 return ret;
635 }
4f259223 636 request->handle = handler->resource.handle;
19a15b93
KH
637
638 return 0;
639}
640
4f259223 641static int ioctl_deallocate(struct client *client, void *buffer)
9472316b 642{
4f259223 643 struct fw_cdev_deallocate *request = buffer;
9472316b 644
45ee3199
JF
645 return release_client_resource(client, request->handle,
646 release_address_handler, NULL);
9472316b
KH
647}
648
4f259223 649static int ioctl_send_response(struct client *client, void *buffer)
19a15b93 650{
4f259223 651 struct fw_cdev_send_response *request = buffer;
3964a449 652 struct client_resource *resource;
19a15b93 653 struct request *r;
19a15b93 654
45ee3199
JF
655 if (release_client_resource(client, request->handle,
656 release_request, &resource) < 0)
19a15b93 657 return -EINVAL;
45ee3199 658
3964a449 659 r = container_of(resource, struct request, resource);
4f259223
KH
660 if (request->length < r->length)
661 r->length = request->length;
662 if (copy_from_user(r->data, u64_to_uptr(request->data), r->length))
19a15b93
KH
663 return -EFAULT;
664
4f259223 665 fw_send_response(client->device->card, r->request, request->rcode);
19a15b93
KH
666 kfree(r);
667
668 return 0;
669}
670
4f259223 671static int ioctl_initiate_bus_reset(struct client *client, void *buffer)
5371842b 672{
4f259223 673 struct fw_cdev_initiate_bus_reset *request = buffer;
5371842b
KH
674 int short_reset;
675
4f259223 676 short_reset = (request->type == FW_CDEV_SHORT_RESET);
5371842b
KH
677
678 return fw_core_initiate_bus_reset(client->device->card, short_reset);
679}
680
66dea3e5
KH
681struct descriptor {
682 struct fw_descriptor d;
3964a449 683 struct client_resource resource;
66dea3e5
KH
684 u32 data[0];
685};
686
3964a449
KH
687static void release_descriptor(struct client *client,
688 struct client_resource *resource)
689{
690 struct descriptor *descriptor =
691 container_of(resource, struct descriptor, resource);
692
693 fw_core_remove_descriptor(&descriptor->d);
694 kfree(descriptor);
695}
696
4f259223 697static int ioctl_add_descriptor(struct client *client, void *buffer)
66dea3e5 698{
4f259223 699 struct fw_cdev_add_descriptor *request = buffer;
66dea3e5 700 struct descriptor *descriptor;
45ee3199 701 int ret;
66dea3e5 702
4f259223 703 if (request->length > 256)
66dea3e5
KH
704 return -EINVAL;
705
706 descriptor =
2d826cc5 707 kmalloc(sizeof(*descriptor) + request->length * 4, GFP_KERNEL);
66dea3e5
KH
708 if (descriptor == NULL)
709 return -ENOMEM;
710
711 if (copy_from_user(descriptor->data,
4f259223 712 u64_to_uptr(request->data), request->length * 4)) {
45ee3199
JF
713 ret = -EFAULT;
714 goto failed;
66dea3e5
KH
715 }
716
4f259223
KH
717 descriptor->d.length = request->length;
718 descriptor->d.immediate = request->immediate;
719 descriptor->d.key = request->key;
66dea3e5
KH
720 descriptor->d.data = descriptor->data;
721
45ee3199
JF
722 ret = fw_core_add_descriptor(&descriptor->d);
723 if (ret < 0)
724 goto failed;
66dea3e5 725
3964a449 726 descriptor->resource.release = release_descriptor;
45ee3199
JF
727 ret = add_client_resource(client, &descriptor->resource, GFP_KERNEL);
728 if (ret < 0) {
729 fw_core_remove_descriptor(&descriptor->d);
730 goto failed;
731 }
4f259223 732 request->handle = descriptor->resource.handle;
66dea3e5
KH
733
734 return 0;
45ee3199
JF
735 failed:
736 kfree(descriptor);
737
738 return ret;
66dea3e5
KH
739}
740
4f259223 741static int ioctl_remove_descriptor(struct client *client, void *buffer)
66dea3e5 742{
4f259223 743 struct fw_cdev_remove_descriptor *request = buffer;
66dea3e5 744
45ee3199
JF
745 return release_client_resource(client, request->handle,
746 release_descriptor, NULL);
66dea3e5
KH
747}
748
53dca511
SR
749static void iso_callback(struct fw_iso_context *context, u32 cycle,
750 size_t header_length, void *header, void *data)
19a15b93
KH
751{
752 struct client *client = data;
930e4b7f 753 struct iso_interrupt *irq;
19a15b93 754
930e4b7f
SR
755 irq = kzalloc(sizeof(*irq) + header_length, GFP_ATOMIC);
756 if (irq == NULL)
19a15b93
KH
757 return;
758
930e4b7f
SR
759 irq->interrupt.type = FW_CDEV_EVENT_ISO_INTERRUPT;
760 irq->interrupt.closure = client->iso_closure;
761 irq->interrupt.cycle = cycle;
762 irq->interrupt.header_length = header_length;
763 memcpy(irq->interrupt.header, header, header_length);
764 queue_event(client, &irq->event, &irq->interrupt,
765 sizeof(irq->interrupt) + header_length, NULL, 0);
19a15b93
KH
766}
767
4f259223 768static int ioctl_create_iso_context(struct client *client, void *buffer)
19a15b93 769{
4f259223 770 struct fw_cdev_create_iso_context *request = buffer;
24315c5e 771 struct fw_iso_context *context;
19a15b93 772
fae60312
SR
773 /* We only support one context at this time. */
774 if (client->iso_context != NULL)
775 return -EBUSY;
776
4f259223 777 if (request->channel > 63)
21efb3cf
KH
778 return -EINVAL;
779
4f259223 780 switch (request->type) {
c70dc788 781 case FW_ISO_CONTEXT_RECEIVE:
4f259223 782 if (request->header_size < 4 || (request->header_size & 3))
c70dc788 783 return -EINVAL;
98b6cbe8 784
c70dc788
KH
785 break;
786
787 case FW_ISO_CONTEXT_TRANSMIT:
4f259223 788 if (request->speed > SCODE_3200)
c70dc788
KH
789 return -EINVAL;
790
791 break;
792
793 default:
21efb3cf 794 return -EINVAL;
c70dc788
KH
795 }
796
24315c5e
KH
797 context = fw_iso_context_create(client->device->card,
798 request->type,
799 request->channel,
800 request->speed,
801 request->header_size,
802 iso_callback, client);
803 if (IS_ERR(context))
804 return PTR_ERR(context);
805
abaa5743 806 client->iso_closure = request->closure;
24315c5e 807 client->iso_context = context;
19a15b93 808
abaa5743
KH
809 /* We only support one context at this time. */
810 request->handle = 0;
811
19a15b93
KH
812 return 0;
813}
814
1ca31ae7
KH
815/* Macros for decoding the iso packet control header. */
816#define GET_PAYLOAD_LENGTH(v) ((v) & 0xffff)
817#define GET_INTERRUPT(v) (((v) >> 16) & 0x01)
818#define GET_SKIP(v) (((v) >> 17) & 0x01)
7a100344
SR
819#define GET_TAG(v) (((v) >> 18) & 0x03)
820#define GET_SY(v) (((v) >> 20) & 0x0f)
1ca31ae7
KH
821#define GET_HEADER_LENGTH(v) (((v) >> 24) & 0xff)
822
4f259223 823static int ioctl_queue_iso(struct client *client, void *buffer)
19a15b93 824{
4f259223 825 struct fw_cdev_queue_iso *request = buffer;
19a15b93 826 struct fw_cdev_iso_packet __user *p, *end, *next;
9b32d5f3 827 struct fw_iso_context *ctx = client->iso_context;
ef370ee7 828 unsigned long payload, buffer_end, header_length;
1ca31ae7 829 u32 control;
19a15b93
KH
830 int count;
831 struct {
832 struct fw_iso_packet packet;
833 u8 header[256];
834 } u;
835
abaa5743 836 if (ctx == NULL || request->handle != 0)
19a15b93 837 return -EINVAL;
19a15b93 838
c781c06d
KH
839 /*
840 * If the user passes a non-NULL data pointer, has mmap()'ed
19a15b93
KH
841 * the iso buffer, and the pointer points inside the buffer,
842 * we setup the payload pointers accordingly. Otherwise we
9aad8125 843 * set them both to 0, which will still let packets with
19a15b93
KH
844 * payload_length == 0 through. In other words, if no packets
845 * use the indirect payload, the iso buffer need not be mapped
c781c06d
KH
846 * and the request->data pointer is ignored.
847 */
19a15b93 848
4f259223 849 payload = (unsigned long)request->data - client->vm_start;
ef370ee7 850 buffer_end = client->buffer.page_count << PAGE_SHIFT;
4f259223 851 if (request->data == 0 || client->buffer.pages == NULL ||
ef370ee7 852 payload >= buffer_end) {
9aad8125 853 payload = 0;
ef370ee7 854 buffer_end = 0;
19a15b93
KH
855 }
856
1ccc9147
AV
857 p = (struct fw_cdev_iso_packet __user *)u64_to_uptr(request->packets);
858
859 if (!access_ok(VERIFY_READ, p, request->size))
19a15b93
KH
860 return -EFAULT;
861
4f259223 862 end = (void __user *)p + request->size;
19a15b93
KH
863 count = 0;
864 while (p < end) {
1ca31ae7 865 if (get_user(control, &p->control))
19a15b93 866 return -EFAULT;
1ca31ae7
KH
867 u.packet.payload_length = GET_PAYLOAD_LENGTH(control);
868 u.packet.interrupt = GET_INTERRUPT(control);
869 u.packet.skip = GET_SKIP(control);
870 u.packet.tag = GET_TAG(control);
871 u.packet.sy = GET_SY(control);
872 u.packet.header_length = GET_HEADER_LENGTH(control);
295e3feb 873
9b32d5f3 874 if (ctx->type == FW_ISO_CONTEXT_TRANSMIT) {
295e3feb
KH
875 header_length = u.packet.header_length;
876 } else {
c781c06d
KH
877 /*
878 * We require that header_length is a multiple of
879 * the fixed header size, ctx->header_size.
880 */
9b32d5f3
KH
881 if (ctx->header_size == 0) {
882 if (u.packet.header_length > 0)
883 return -EINVAL;
884 } else if (u.packet.header_length % ctx->header_size != 0) {
295e3feb 885 return -EINVAL;
9b32d5f3 886 }
295e3feb
KH
887 header_length = 0;
888 }
889
19a15b93 890 next = (struct fw_cdev_iso_packet __user *)
295e3feb 891 &p->header[header_length / 4];
19a15b93
KH
892 if (next > end)
893 return -EINVAL;
894 if (__copy_from_user
295e3feb 895 (u.packet.header, p->header, header_length))
19a15b93 896 return -EFAULT;
98b6cbe8 897 if (u.packet.skip && ctx->type == FW_ISO_CONTEXT_TRANSMIT &&
19a15b93
KH
898 u.packet.header_length + u.packet.payload_length > 0)
899 return -EINVAL;
ef370ee7 900 if (payload + u.packet.payload_length > buffer_end)
19a15b93
KH
901 return -EINVAL;
902
9b32d5f3
KH
903 if (fw_iso_context_queue(ctx, &u.packet,
904 &client->buffer, payload))
19a15b93
KH
905 break;
906
907 p = next;
908 payload += u.packet.payload_length;
909 count++;
910 }
911
4f259223
KH
912 request->size -= uptr_to_u64(p) - request->packets;
913 request->packets = uptr_to_u64(p);
914 request->data = client->vm_start + payload;
19a15b93
KH
915
916 return count;
917}
918
4f259223 919static int ioctl_start_iso(struct client *client, void *buffer)
19a15b93 920{
4f259223 921 struct fw_cdev_start_iso *request = buffer;
19a15b93 922
fae60312 923 if (client->iso_context == NULL || request->handle != 0)
abaa5743 924 return -EINVAL;
fae60312 925
eb0306ea 926 if (client->iso_context->type == FW_ISO_CONTEXT_RECEIVE) {
4f259223 927 if (request->tags == 0 || request->tags > 15)
eb0306ea
KH
928 return -EINVAL;
929
4f259223 930 if (request->sync > 15)
eb0306ea
KH
931 return -EINVAL;
932 }
933
4f259223
KH
934 return fw_iso_context_start(client->iso_context, request->cycle,
935 request->sync, request->tags);
19a15b93
KH
936}
937
4f259223 938static int ioctl_stop_iso(struct client *client, void *buffer)
b8295668 939{
abaa5743
KH
940 struct fw_cdev_stop_iso *request = buffer;
941
fae60312 942 if (client->iso_context == NULL || request->handle != 0)
abaa5743
KH
943 return -EINVAL;
944
b8295668
KH
945 return fw_iso_context_stop(client->iso_context);
946}
947
a64408b9
SR
948static int ioctl_get_cycle_timer(struct client *client, void *buffer)
949{
950 struct fw_cdev_get_cycle_timer *request = buffer;
951 struct fw_card *card = client->device->card;
952 unsigned long long bus_time;
953 struct timeval tv;
954 unsigned long flags;
955
956 preempt_disable();
957 local_irq_save(flags);
958
959 bus_time = card->driver->get_bus_time(card);
960 do_gettimeofday(&tv);
961
962 local_irq_restore(flags);
963 preempt_enable();
964
965 request->local_time = tv.tv_sec * 1000000ULL + tv.tv_usec;
966 request->cycle_timer = bus_time & 0xffffffff;
967 return 0;
968}
969
4f259223
KH
970static int (* const ioctl_handlers[])(struct client *client, void *buffer) = {
971 ioctl_get_info,
972 ioctl_send_request,
973 ioctl_allocate,
974 ioctl_deallocate,
975 ioctl_send_response,
976 ioctl_initiate_bus_reset,
977 ioctl_add_descriptor,
978 ioctl_remove_descriptor,
979 ioctl_create_iso_context,
980 ioctl_queue_iso,
981 ioctl_start_iso,
982 ioctl_stop_iso,
a64408b9 983 ioctl_get_cycle_timer,
4f259223
KH
984};
985
53dca511
SR
986static int dispatch_ioctl(struct client *client,
987 unsigned int cmd, void __user *arg)
19a15b93 988{
4f259223 989 char buffer[256];
2dbd7d7e 990 int ret;
4f259223
KH
991
992 if (_IOC_TYPE(cmd) != '#' ||
993 _IOC_NR(cmd) >= ARRAY_SIZE(ioctl_handlers))
19a15b93 994 return -EINVAL;
4f259223
KH
995
996 if (_IOC_DIR(cmd) & _IOC_WRITE) {
2d826cc5 997 if (_IOC_SIZE(cmd) > sizeof(buffer) ||
4f259223
KH
998 copy_from_user(buffer, arg, _IOC_SIZE(cmd)))
999 return -EFAULT;
1000 }
1001
2dbd7d7e
SR
1002 ret = ioctl_handlers[_IOC_NR(cmd)](client, buffer);
1003 if (ret < 0)
1004 return ret;
4f259223
KH
1005
1006 if (_IOC_DIR(cmd) & _IOC_READ) {
2d826cc5 1007 if (_IOC_SIZE(cmd) > sizeof(buffer) ||
4f259223
KH
1008 copy_to_user(arg, buffer, _IOC_SIZE(cmd)))
1009 return -EFAULT;
19a15b93 1010 }
4f259223 1011
2dbd7d7e 1012 return ret;
19a15b93
KH
1013}
1014
53dca511
SR
1015static long fw_device_op_ioctl(struct file *file,
1016 unsigned int cmd, unsigned long arg)
19a15b93
KH
1017{
1018 struct client *client = file->private_data;
1019
551f4cb9
JF
1020 if (fw_device_is_shutdown(client->device))
1021 return -ENODEV;
1022
19a15b93
KH
1023 return dispatch_ioctl(client, cmd, (void __user *) arg);
1024}
1025
1026#ifdef CONFIG_COMPAT
53dca511
SR
1027static long fw_device_op_compat_ioctl(struct file *file,
1028 unsigned int cmd, unsigned long arg)
19a15b93
KH
1029{
1030 struct client *client = file->private_data;
1031
551f4cb9
JF
1032 if (fw_device_is_shutdown(client->device))
1033 return -ENODEV;
1034
19a15b93
KH
1035 return dispatch_ioctl(client, cmd, compat_ptr(arg));
1036}
1037#endif
1038
1039static int fw_device_op_mmap(struct file *file, struct vm_area_struct *vma)
1040{
1041 struct client *client = file->private_data;
9aad8125
KH
1042 enum dma_data_direction direction;
1043 unsigned long size;
2dbd7d7e 1044 int page_count, ret;
9aad8125 1045
551f4cb9
JF
1046 if (fw_device_is_shutdown(client->device))
1047 return -ENODEV;
1048
9aad8125
KH
1049 /* FIXME: We could support multiple buffers, but we don't. */
1050 if (client->buffer.pages != NULL)
1051 return -EBUSY;
1052
1053 if (!(vma->vm_flags & VM_SHARED))
1054 return -EINVAL;
19a15b93 1055
9aad8125 1056 if (vma->vm_start & ~PAGE_MASK)
19a15b93
KH
1057 return -EINVAL;
1058
1059 client->vm_start = vma->vm_start;
9aad8125
KH
1060 size = vma->vm_end - vma->vm_start;
1061 page_count = size >> PAGE_SHIFT;
1062 if (size & ~PAGE_MASK)
1063 return -EINVAL;
1064
1065 if (vma->vm_flags & VM_WRITE)
1066 direction = DMA_TO_DEVICE;
1067 else
1068 direction = DMA_FROM_DEVICE;
1069
2dbd7d7e
SR
1070 ret = fw_iso_buffer_init(&client->buffer, client->device->card,
1071 page_count, direction);
1072 if (ret < 0)
1073 return ret;
19a15b93 1074
2dbd7d7e
SR
1075 ret = fw_iso_buffer_map(&client->buffer, vma);
1076 if (ret < 0)
9aad8125
KH
1077 fw_iso_buffer_destroy(&client->buffer, client->device->card);
1078
2dbd7d7e 1079 return ret;
19a15b93
KH
1080}
1081
45ee3199
JF
1082static int shutdown_resource(int id, void *p, void *data)
1083{
1084 struct client_resource *r = p;
1085 struct client *client = data;
1086
1087 r->release(client, r);
fb443036 1088 client_put(client);
45ee3199
JF
1089
1090 return 0;
1091}
1092
19a15b93
KH
1093static int fw_device_op_release(struct inode *inode, struct file *file)
1094{
1095 struct client *client = file->private_data;
2603bf21 1096 struct event *e, *next_e;
45ee3199 1097 unsigned long flags;
19a15b93 1098
97811e34
SR
1099 mutex_lock(&client->device->client_list_mutex);
1100 list_del(&client->link);
1101 mutex_unlock(&client->device->client_list_mutex);
1102
9aad8125
KH
1103 if (client->buffer.pages)
1104 fw_iso_buffer_destroy(&client->buffer, client->device->card);
1105
19a15b93
KH
1106 if (client->iso_context)
1107 fw_iso_context_destroy(client->iso_context);
1108
45ee3199
JF
1109 /* Freeze client->resource_idr and client->event_list */
1110 spin_lock_irqsave(&client->lock, flags);
1111 client->in_shutdown = true;
1112 spin_unlock_irqrestore(&client->lock, flags);
66dea3e5 1113
45ee3199
JF
1114 idr_for_each(&client->resource_idr, shutdown_resource, client);
1115 idr_remove_all(&client->resource_idr);
1116 idr_destroy(&client->resource_idr);
28cf6a04 1117
2603bf21
KH
1118 list_for_each_entry_safe(e, next_e, &client->event_list, link)
1119 kfree(e);
19a15b93 1120
fb443036 1121 client_put(client);
19a15b93
KH
1122
1123 return 0;
1124}
1125
1126static unsigned int fw_device_op_poll(struct file *file, poll_table * pt)
1127{
1128 struct client *client = file->private_data;
2603bf21 1129 unsigned int mask = 0;
19a15b93
KH
1130
1131 poll_wait(file, &client->wait, pt);
1132
2603bf21
KH
1133 if (fw_device_is_shutdown(client->device))
1134 mask |= POLLHUP | POLLERR;
19a15b93 1135 if (!list_empty(&client->event_list))
2603bf21
KH
1136 mask |= POLLIN | POLLRDNORM;
1137
1138 return mask;
19a15b93
KH
1139}
1140
21ebcd12 1141const struct file_operations fw_device_ops = {
19a15b93
KH
1142 .owner = THIS_MODULE,
1143 .open = fw_device_op_open,
1144 .read = fw_device_op_read,
1145 .unlocked_ioctl = fw_device_op_ioctl,
1146 .poll = fw_device_op_poll,
1147 .release = fw_device_op_release,
1148 .mmap = fw_device_op_mmap,
1149
1150#ifdef CONFIG_COMPAT
5af4e5ea 1151 .compat_ioctl = fw_device_op_compat_ioctl,
19a15b93
KH
1152#endif
1153};