3 * Intel Management Engine Interface (Intel MEI) Linux driver
4 * Copyright (c) 2003-2012, Intel Corporation.
6 * This program is free software; you can redistribute it and/or modify it
7 * under the terms and conditions of the GNU General Public License,
8 * version 2, as published by the Free Software Foundation.
10 * This program is distributed in the hope it will be useful, but WITHOUT
11 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
12 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
17 #include <linux/kernel.h>
19 #include <linux/errno.h>
20 #include <linux/types.h>
21 #include <linux/fcntl.h>
22 #include <linux/aio.h>
23 #include <linux/ioctl.h>
24 #include <linux/cdev.h>
25 #include <linux/list.h>
26 #include <linux/delay.h>
27 #include <linux/sched.h>
28 #include <linux/uuid.h>
29 #include <linux/jiffies.h>
30 #include <linux/uaccess.h>
31 #include <linux/slab.h>
33 #include <linux/mei.h>
39 const uuid_le mei_amthif_guid
= UUID_LE(0x12f80028, 0xb4b7, 0x4b2d,
40 0xac, 0xa8, 0x46, 0xe0,
41 0xff, 0x65, 0x81, 0x4c);
44 * mei_amthif_reset_params - initializes mei device iamthif
46 * @dev: the device structure
48 void mei_amthif_reset_params(struct mei_device
*dev
)
50 /* reset iamthif parameters. */
51 dev
->iamthif_current_cb
= NULL
;
52 dev
->iamthif_msg_buf_size
= 0;
53 dev
->iamthif_msg_buf_index
= 0;
54 dev
->iamthif_canceled
= false;
55 dev
->iamthif_ioctl
= false;
56 dev
->iamthif_state
= MEI_IAMTHIF_IDLE
;
57 dev
->iamthif_timer
= 0;
58 dev
->iamthif_stall_timer
= 0;
59 dev
->iamthif_open_count
= 0;
63 * mei_amthif_host_init - mei initialization amthif client.
65 * @dev: the device structure
67 * Return: 0 on success, <0 on failure.
69 int mei_amthif_host_init(struct mei_device
*dev
)
71 struct mei_cl
*cl
= &dev
->iamthif_cl
;
72 struct mei_me_client
*me_cl
;
73 unsigned char *msg_buf
;
76 dev
->iamthif_state
= MEI_IAMTHIF_IDLE
;
80 me_cl
= mei_me_cl_by_uuid(dev
, &mei_amthif_guid
);
82 dev_info(dev
->dev
, "amthif: failed to find the client");
86 cl
->me_client_id
= me_cl
->client_id
;
87 cl
->cl_uuid
= me_cl
->props
.protocol_name
;
89 /* Assign iamthif_mtu to the value received from ME */
91 dev
->iamthif_mtu
= me_cl
->props
.max_msg_length
;
92 dev_dbg(dev
->dev
, "IAMTHIF_MTU = %d\n", dev
->iamthif_mtu
);
94 kfree(dev
->iamthif_msg_buf
);
95 dev
->iamthif_msg_buf
= NULL
;
97 /* allocate storage for ME message buffer */
98 msg_buf
= kcalloc(dev
->iamthif_mtu
,
99 sizeof(unsigned char), GFP_KERNEL
);
103 dev
->iamthif_msg_buf
= msg_buf
;
105 ret
= mei_cl_link(cl
, MEI_IAMTHIF_HOST_CLIENT_ID
);
109 "amthif: failed link client %d\n", ret
);
113 ret
= mei_cl_connect(cl
, NULL
);
115 dev
->iamthif_state
= MEI_IAMTHIF_IDLE
;
121 * mei_amthif_find_read_list_entry - finds a amthilist entry for current file
123 * @dev: the device structure
124 * @file: pointer to file object
126 * Return: returned a list entry on success, NULL on failure.
128 struct mei_cl_cb
*mei_amthif_find_read_list_entry(struct mei_device
*dev
,
131 struct mei_cl_cb
*cb
;
133 list_for_each_entry(cb
, &dev
->amthif_rd_complete_list
.list
, list
)
134 if (cb
->file_object
== file
)
141 * mei_amthif_read - read data from AMTHIF client
143 * @dev: the device structure
144 * @file: pointer to file object
145 * @ubuf: pointer to user data in user space
146 * @length: data length to read
147 * @offset: data read offset
149 * Locking: called under "dev->device_lock" lock
152 * returned data length on success,
153 * zero if no data to read,
154 * negative on failure.
156 int mei_amthif_read(struct mei_device
*dev
, struct file
*file
,
157 char __user
*ubuf
, size_t length
, loff_t
*offset
)
159 struct mei_cl
*cl
= file
->private_data
;
160 struct mei_cl_cb
*cb
;
161 unsigned long timeout
;
165 /* Only possible if we are in timeout */
167 dev_err(dev
->dev
, "bad file ext.\n");
171 dev_dbg(dev
->dev
, "checking amthif data\n");
172 cb
= mei_amthif_find_read_list_entry(dev
, file
);
174 /* Check for if we can block or not*/
175 if (cb
== NULL
&& file
->f_flags
& O_NONBLOCK
)
179 dev_dbg(dev
->dev
, "waiting for amthif data\n");
181 /* unlock the Mutex */
182 mutex_unlock(&dev
->device_lock
);
184 wait_ret
= wait_event_interruptible(dev
->iamthif_cl
.wait
,
185 (cb
= mei_amthif_find_read_list_entry(dev
, file
)));
187 /* Locking again the Mutex */
188 mutex_lock(&dev
->device_lock
);
193 dev_dbg(dev
->dev
, "woke up from sleep\n");
197 dev_dbg(dev
->dev
, "Got amthif data\n");
198 dev
->iamthif_timer
= 0;
201 timeout
= cb
->read_time
+
202 mei_secs_to_jiffies(MEI_IAMTHIF_READ_TIMER
);
203 dev_dbg(dev
->dev
, "amthif timeout = %lud\n",
206 if (time_after(jiffies
, timeout
)) {
207 dev_dbg(dev
->dev
, "amthif Time out\n");
208 /* 15 sec for the message has expired */
214 /* if the whole message will fit remove it from the list */
215 if (cb
->buf_idx
>= *offset
&& length
>= (cb
->buf_idx
- *offset
))
217 else if (cb
->buf_idx
> 0 && cb
->buf_idx
<= *offset
) {
218 /* end of the message has been reached */
223 /* else means that not full buffer will be read and do not
224 * remove message from deletion list
227 dev_dbg(dev
->dev
, "amthif cb->response_buffer size - %d\n",
228 cb
->response_buffer
.size
);
229 dev_dbg(dev
->dev
, "amthif cb->buf_idx - %lu\n", cb
->buf_idx
);
231 /* length is being truncated to PAGE_SIZE, however,
232 * the buf_idx may point beyond */
233 length
= min_t(size_t, length
, (cb
->buf_idx
- *offset
));
235 if (copy_to_user(ubuf
, cb
->response_buffer
.data
+ *offset
, length
)) {
236 dev_dbg(dev
->dev
, "failed to copy data to userland\n");
240 if ((*offset
+ length
) < cb
->buf_idx
) {
246 dev_dbg(dev
->dev
, "free amthif cb memory.\n");
254 * mei_amthif_send_cmd - send amthif command to the ME
256 * @dev: the device structure
257 * @cb: mei call back struct
259 * Return: 0 on success, <0 on failure.
262 static int mei_amthif_send_cmd(struct mei_device
*dev
, struct mei_cl_cb
*cb
)
264 struct mei_msg_hdr mei_hdr
;
270 dev_dbg(dev
->dev
, "write data to amthif client.\n");
272 dev
->iamthif_state
= MEI_IAMTHIF_WRITING
;
273 dev
->iamthif_current_cb
= cb
;
274 dev
->iamthif_file_object
= cb
->file_object
;
275 dev
->iamthif_canceled
= false;
276 dev
->iamthif_ioctl
= true;
277 dev
->iamthif_msg_buf_size
= cb
->request_buffer
.size
;
278 memcpy(dev
->iamthif_msg_buf
, cb
->request_buffer
.data
,
279 cb
->request_buffer
.size
);
281 ret
= mei_cl_flow_ctrl_creds(&dev
->iamthif_cl
);
285 if (ret
&& mei_hbuf_acquire(dev
)) {
287 if (cb
->request_buffer
.size
> mei_hbuf_max_len(dev
)) {
288 mei_hdr
.length
= mei_hbuf_max_len(dev
);
289 mei_hdr
.msg_complete
= 0;
291 mei_hdr
.length
= cb
->request_buffer
.size
;
292 mei_hdr
.msg_complete
= 1;
295 mei_hdr
.host_addr
= dev
->iamthif_cl
.host_client_id
;
296 mei_hdr
.me_addr
= dev
->iamthif_cl
.me_client_id
;
297 mei_hdr
.reserved
= 0;
298 mei_hdr
.internal
= 0;
299 dev
->iamthif_msg_buf_index
+= mei_hdr
.length
;
300 ret
= mei_write_message(dev
, &mei_hdr
, dev
->iamthif_msg_buf
);
304 if (mei_hdr
.msg_complete
) {
305 if (mei_cl_flow_ctrl_reduce(&dev
->iamthif_cl
))
307 dev
->iamthif_flow_control_pending
= true;
308 dev
->iamthif_state
= MEI_IAMTHIF_FLOW_CONTROL
;
309 dev_dbg(dev
->dev
, "add amthif cb to write waiting list\n");
310 dev
->iamthif_current_cb
= cb
;
311 dev
->iamthif_file_object
= cb
->file_object
;
312 list_add_tail(&cb
->list
, &dev
->write_waiting_list
.list
);
314 dev_dbg(dev
->dev
, "message does not complete, so add amthif cb to write list.\n");
315 list_add_tail(&cb
->list
, &dev
->write_list
.list
);
318 list_add_tail(&cb
->list
, &dev
->write_list
.list
);
324 * mei_amthif_write - write amthif data to amthif client
326 * @dev: the device structure
327 * @cb: mei call back struct
329 * Return: 0 on success, <0 on failure.
332 int mei_amthif_write(struct mei_device
*dev
, struct mei_cl_cb
*cb
)
339 ret
= mei_io_cb_alloc_resp_buf(cb
, dev
->iamthif_mtu
);
343 cb
->fop_type
= MEI_FOP_WRITE
;
345 if (!list_empty(&dev
->amthif_cmd_list
.list
) ||
346 dev
->iamthif_state
!= MEI_IAMTHIF_IDLE
) {
348 "amthif state = %d\n", dev
->iamthif_state
);
349 dev_dbg(dev
->dev
, "AMTHIF: add cb to the wait list\n");
350 list_add_tail(&cb
->list
, &dev
->amthif_cmd_list
.list
);
353 return mei_amthif_send_cmd(dev
, cb
);
356 * mei_amthif_run_next_cmd - send next amt command from queue
358 * @dev: the device structure
360 void mei_amthif_run_next_cmd(struct mei_device
*dev
)
362 struct mei_cl_cb
*cb
;
368 dev
->iamthif_msg_buf_size
= 0;
369 dev
->iamthif_msg_buf_index
= 0;
370 dev
->iamthif_canceled
= false;
371 dev
->iamthif_ioctl
= true;
372 dev
->iamthif_state
= MEI_IAMTHIF_IDLE
;
373 dev
->iamthif_timer
= 0;
374 dev
->iamthif_file_object
= NULL
;
376 dev_dbg(dev
->dev
, "complete amthif cmd_list cb.\n");
378 cb
= list_first_entry_or_null(&dev
->amthif_cmd_list
.list
,
383 ret
= mei_amthif_send_cmd(dev
, cb
);
385 dev_warn(dev
->dev
, "amthif write failed status = %d\n", ret
);
389 unsigned int mei_amthif_poll(struct mei_device
*dev
,
390 struct file
*file
, poll_table
*wait
)
392 unsigned int mask
= 0;
394 poll_wait(file
, &dev
->iamthif_cl
.wait
, wait
);
396 mutex_lock(&dev
->device_lock
);
397 if (!mei_cl_is_connected(&dev
->iamthif_cl
)) {
401 } else if (dev
->iamthif_state
== MEI_IAMTHIF_READ_COMPLETE
&&
402 dev
->iamthif_file_object
== file
) {
404 mask
|= (POLLIN
| POLLRDNORM
);
405 dev_dbg(dev
->dev
, "run next amthif cb\n");
406 mei_amthif_run_next_cmd(dev
);
408 mutex_unlock(&dev
->device_lock
);
416 * mei_amthif_irq_write - write iamthif command in irq thread context.
418 * @cl: private data of the file object.
419 * @cb: callback block.
420 * @cmpl_list: complete list.
422 * Return: 0, OK; otherwise, error.
424 int mei_amthif_irq_write(struct mei_cl
*cl
, struct mei_cl_cb
*cb
,
425 struct mei_cl_cb
*cmpl_list
)
427 struct mei_device
*dev
= cl
->dev
;
428 struct mei_msg_hdr mei_hdr
;
429 size_t len
= dev
->iamthif_msg_buf_size
- dev
->iamthif_msg_buf_index
;
430 u32 msg_slots
= mei_data2slots(len
);
434 rets
= mei_cl_flow_ctrl_creds(cl
);
439 cl_dbg(dev
, cl
, "No flow control credentials: not sending.\n");
443 mei_hdr
.host_addr
= cl
->host_client_id
;
444 mei_hdr
.me_addr
= cl
->me_client_id
;
445 mei_hdr
.reserved
= 0;
446 mei_hdr
.internal
= 0;
448 slots
= mei_hbuf_empty_slots(dev
);
450 if (slots
>= msg_slots
) {
451 mei_hdr
.length
= len
;
452 mei_hdr
.msg_complete
= 1;
453 /* Split the message only if we can write the whole host buffer */
454 } else if (slots
== dev
->hbuf_depth
) {
456 len
= (slots
* sizeof(u32
)) - sizeof(struct mei_msg_hdr
);
457 mei_hdr
.length
= len
;
458 mei_hdr
.msg_complete
= 0;
460 /* wait for next time the host buffer is empty */
464 dev_dbg(dev
->dev
, MEI_HDR_FMT
, MEI_HDR_PRM(&mei_hdr
));
466 rets
= mei_write_message(dev
, &mei_hdr
,
467 dev
->iamthif_msg_buf
+ dev
->iamthif_msg_buf_index
);
469 dev
->iamthif_state
= MEI_IAMTHIF_IDLE
;
475 if (mei_cl_flow_ctrl_reduce(cl
))
478 dev
->iamthif_msg_buf_index
+= mei_hdr
.length
;
481 if (mei_hdr
.msg_complete
) {
482 dev
->iamthif_state
= MEI_IAMTHIF_FLOW_CONTROL
;
483 dev
->iamthif_flow_control_pending
= true;
485 /* save iamthif cb sent to amthif client */
486 cb
->buf_idx
= dev
->iamthif_msg_buf_index
;
487 dev
->iamthif_current_cb
= cb
;
489 list_move_tail(&cb
->list
, &dev
->write_waiting_list
.list
);
497 * mei_amthif_irq_read_msg - read routine after ISR to
498 * handle the read amthif message
500 * @dev: the device structure
501 * @mei_hdr: header of amthif message
502 * @complete_list: An instance of our list structure
504 * Return: 0 on success, <0 on failure.
506 int mei_amthif_irq_read_msg(struct mei_device
*dev
,
507 struct mei_msg_hdr
*mei_hdr
,
508 struct mei_cl_cb
*complete_list
)
510 struct mei_cl_cb
*cb
;
511 unsigned char *buffer
;
513 BUG_ON(mei_hdr
->me_addr
!= dev
->iamthif_cl
.me_client_id
);
514 BUG_ON(dev
->iamthif_state
!= MEI_IAMTHIF_READING
);
516 buffer
= dev
->iamthif_msg_buf
+ dev
->iamthif_msg_buf_index
;
517 BUG_ON(dev
->iamthif_mtu
< dev
->iamthif_msg_buf_index
+ mei_hdr
->length
);
519 mei_read_slots(dev
, buffer
, mei_hdr
->length
);
521 dev
->iamthif_msg_buf_index
+= mei_hdr
->length
;
523 if (!mei_hdr
->msg_complete
)
526 dev_dbg(dev
->dev
, "amthif_message_buffer_index =%d\n",
529 dev_dbg(dev
->dev
, "completed amthif read.\n ");
530 if (!dev
->iamthif_current_cb
)
533 cb
= dev
->iamthif_current_cb
;
534 dev
->iamthif_current_cb
= NULL
;
536 dev
->iamthif_stall_timer
= 0;
537 cb
->buf_idx
= dev
->iamthif_msg_buf_index
;
538 cb
->read_time
= jiffies
;
539 if (dev
->iamthif_ioctl
) {
540 /* found the iamthif cb */
541 dev_dbg(dev
->dev
, "complete the amthif read cb.\n ");
542 dev_dbg(dev
->dev
, "add the amthif read cb to complete.\n ");
543 list_add_tail(&cb
->list
, &complete_list
->list
);
549 * mei_amthif_irq_read - prepares to read amthif data.
551 * @dev: the device structure.
552 * @slots: free slots.
554 * Return: 0, OK; otherwise, error.
556 int mei_amthif_irq_read(struct mei_device
*dev
, s32
*slots
)
558 u32 msg_slots
= mei_data2slots(sizeof(struct hbm_flow_control
));
560 if (*slots
< msg_slots
)
565 if (mei_hbm_cl_flow_control_req(dev
, &dev
->iamthif_cl
)) {
566 dev_dbg(dev
->dev
, "iamthif flow control failed\n");
570 dev_dbg(dev
->dev
, "iamthif flow control success\n");
571 dev
->iamthif_state
= MEI_IAMTHIF_READING
;
572 dev
->iamthif_flow_control_pending
= false;
573 dev
->iamthif_msg_buf_index
= 0;
574 dev
->iamthif_msg_buf_size
= 0;
575 dev
->iamthif_stall_timer
= MEI_IAMTHIF_STALL_TIMER
;
576 dev
->hbuf_is_ready
= mei_hbuf_is_ready(dev
);
581 * mei_amthif_complete - complete amthif callback.
583 * @dev: the device structure.
584 * @cb: callback block.
586 void mei_amthif_complete(struct mei_device
*dev
, struct mei_cl_cb
*cb
)
588 if (dev
->iamthif_canceled
!= 1) {
589 dev
->iamthif_state
= MEI_IAMTHIF_READ_COMPLETE
;
590 dev
->iamthif_stall_timer
= 0;
591 memcpy(cb
->response_buffer
.data
,
592 dev
->iamthif_msg_buf
,
593 dev
->iamthif_msg_buf_index
);
594 list_add_tail(&cb
->list
, &dev
->amthif_rd_complete_list
.list
);
595 dev_dbg(dev
->dev
, "amthif read completed\n");
596 dev
->iamthif_timer
= jiffies
;
597 dev_dbg(dev
->dev
, "dev->iamthif_timer = %ld\n",
600 mei_amthif_run_next_cmd(dev
);
603 dev_dbg(dev
->dev
, "completing amthif call back.\n");
604 wake_up_interruptible(&dev
->iamthif_cl
.wait
);
608 * mei_clear_list - removes all callbacks associated with file
611 * @dev: device structure.
612 * @file: file structure
613 * @mei_cb_list: callbacks list
615 * mei_clear_list is called to clear resources associated with file
616 * when application calls close function or Ctrl-C was pressed
618 * Return: true if callback removed from the list, false otherwise
620 static bool mei_clear_list(struct mei_device
*dev
,
621 const struct file
*file
, struct list_head
*mei_cb_list
)
623 struct mei_cl_cb
*cb_pos
= NULL
;
624 struct mei_cl_cb
*cb_next
= NULL
;
625 bool removed
= false;
627 /* list all list member */
628 list_for_each_entry_safe(cb_pos
, cb_next
, mei_cb_list
, list
) {
629 /* check if list member associated with a file */
630 if (file
== cb_pos
->file_object
) {
631 /* remove member from the list */
632 list_del(&cb_pos
->list
);
633 /* check if cb equal to current iamthif cb */
634 if (dev
->iamthif_current_cb
== cb_pos
) {
635 dev
->iamthif_current_cb
= NULL
;
636 /* send flow control to iamthif client */
637 mei_hbm_cl_flow_control_req(dev
,
640 /* free all allocated buffers */
641 mei_io_cb_free(cb_pos
);
650 * mei_clear_lists - removes all callbacks associated with file
652 * @dev: device structure
653 * @file: file structure
655 * mei_clear_lists is called to clear resources associated with file
656 * when application calls close function or Ctrl-C was pressed
658 * Return: true if callback removed from the list, false otherwise
660 static bool mei_clear_lists(struct mei_device
*dev
, struct file
*file
)
662 bool removed
= false;
664 /* remove callbacks associated with a file */
665 mei_clear_list(dev
, file
, &dev
->amthif_cmd_list
.list
);
666 if (mei_clear_list(dev
, file
, &dev
->amthif_rd_complete_list
.list
))
669 mei_clear_list(dev
, file
, &dev
->ctrl_rd_list
.list
);
671 if (mei_clear_list(dev
, file
, &dev
->ctrl_wr_list
.list
))
674 if (mei_clear_list(dev
, file
, &dev
->write_waiting_list
.list
))
677 if (mei_clear_list(dev
, file
, &dev
->write_list
.list
))
680 /* check if iamthif_current_cb not NULL */
681 if (dev
->iamthif_current_cb
&& !removed
) {
682 /* check file and iamthif current cb association */
683 if (dev
->iamthif_current_cb
->file_object
== file
) {
685 mei_io_cb_free(dev
->iamthif_current_cb
);
686 dev
->iamthif_current_cb
= NULL
;
694 * mei_amthif_release - the release function
696 * @dev: device structure
697 * @file: pointer to file structure
699 * Return: 0 on success, <0 on error
701 int mei_amthif_release(struct mei_device
*dev
, struct file
*file
)
703 if (dev
->iamthif_open_count
> 0)
704 dev
->iamthif_open_count
--;
706 if (dev
->iamthif_file_object
== file
&&
707 dev
->iamthif_state
!= MEI_IAMTHIF_IDLE
) {
709 dev_dbg(dev
->dev
, "amthif canceled iamthif state %d\n",
711 dev
->iamthif_canceled
= true;
712 if (dev
->iamthif_state
== MEI_IAMTHIF_READ_COMPLETE
) {
713 dev_dbg(dev
->dev
, "run next amthif iamthif cb\n");
714 mei_amthif_run_next_cmd(dev
);
718 if (mei_clear_lists(dev
, file
))
719 dev
->iamthif_state
= MEI_IAMTHIF_IDLE
;