3 * Intel Management Engine Interface (Intel MEI) Linux driver
4 * Copyright (c) 2003-2012, Intel Corporation.
6 * This program is free software; you can redistribute it and/or modify it
7 * under the terms and conditions of the GNU General Public License,
8 * version 2, as published by the Free Software Foundation.
10 * This program is distributed in the hope it will be useful, but WITHOUT
11 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
12 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
17 #include <linux/kernel.h>
19 #include <linux/errno.h>
20 #include <linux/types.h>
21 #include <linux/fcntl.h>
22 #include <linux/aio.h>
23 #include <linux/pci.h>
24 #include <linux/init.h>
25 #include <linux/ioctl.h>
26 #include <linux/cdev.h>
27 #include <linux/list.h>
28 #include <linux/delay.h>
29 #include <linux/sched.h>
30 #include <linux/uuid.h>
31 #include <linux/jiffies.h>
32 #include <linux/uaccess.h>
34 #include <linux/mei.h>
41 const uuid_le mei_amthif_guid = UUID_LE(0x12f80028, 0xb4b7, 0x4b2d,
42 0xac, 0xa8, 0x46, 0xe0,
43 0xff, 0x65, 0x81, 0x4c);
46 * mei_amthif_reset_params - initializes mei device iamthif
48 * @dev: the device structure
50 void mei_amthif_reset_params(struct mei_device *dev)
52 /* reset iamthif parameters. */
53 dev->iamthif_current_cb = NULL;
54 dev->iamthif_msg_buf_size = 0;
55 dev->iamthif_msg_buf_index = 0;
56 dev->iamthif_canceled = false;
57 dev->iamthif_ioctl = false;
58 dev->iamthif_state = MEI_IAMTHIF_IDLE;
59 dev->iamthif_timer = 0;
60 dev->iamthif_stall_timer = 0;
61 dev->iamthif_open_count = 0;
65 * mei_amthif_host_init - mei initialization amthif client.
67 * @dev: the device structure
70 int mei_amthif_host_init(struct mei_device *dev)
72 struct mei_cl *cl = &dev->iamthif_cl;
73 unsigned char *msg_buf;
76 dev->iamthif_state = MEI_IAMTHIF_IDLE;
80 i = mei_me_cl_by_uuid(dev, &mei_amthif_guid);
83 dev_info(&dev->pdev->dev,
84 "amthif: failed to find the client %d\n", ret);
88 cl->me_client_id = dev->me_clients[i].client_id;
90 /* Assign iamthif_mtu to the value received from ME */
92 dev->iamthif_mtu = dev->me_clients[i].props.max_msg_length;
93 dev_dbg(&dev->pdev->dev, "IAMTHIF_MTU = %d\n",
94 dev->me_clients[i].props.max_msg_length);
96 kfree(dev->iamthif_msg_buf);
97 dev->iamthif_msg_buf = NULL;
99 /* allocate storage for ME message buffer */
100 msg_buf = kcalloc(dev->iamthif_mtu,
101 sizeof(unsigned char), GFP_KERNEL);
103 dev_err(&dev->pdev->dev, "amthif: memory allocation for ME message buffer failed.\n");
107 dev->iamthif_msg_buf = msg_buf;
109 ret = mei_cl_link(cl, MEI_IAMTHIF_HOST_CLIENT_ID);
112 dev_err(&dev->pdev->dev,
113 "amthif: failed link client %d\n", ret);
117 cl->state = MEI_FILE_CONNECTING;
119 if (mei_hbm_cl_connect_req(dev, cl)) {
120 dev_dbg(&dev->pdev->dev, "amthif: Failed to connect to ME client\n");
121 cl->state = MEI_FILE_DISCONNECTED;
122 cl->host_client_id = 0;
124 cl->timer_count = MEI_CONNECT_TIMEOUT;
130 * mei_amthif_find_read_list_entry - finds a amthilist entry for current file
132 * @dev: the device structure
133 * @file: pointer to file object
135 * returns returned a list entry on success, NULL on failure.
137 struct mei_cl_cb *mei_amthif_find_read_list_entry(struct mei_device *dev,
140 struct mei_cl_cb *pos = NULL;
141 struct mei_cl_cb *next = NULL;
143 list_for_each_entry_safe(pos, next,
144 &dev->amthif_rd_complete_list.list, list) {
145 if (pos->cl && pos->cl == &dev->iamthif_cl &&
146 pos->file_object == file)
154 * mei_amthif_read - read data from AMTHIF client
156 * @dev: the device structure
157 * @if_num: minor number
158 * @file: pointer to file object
159 * @*ubuf: pointer to user data in user space
160 * @length: data length to read
161 * @offset: data read offset
163 * Locking: called under "dev->device_lock" lock
166 * returned data length on success,
167 * zero if no data to read,
168 * negative on failure.
170 int mei_amthif_read(struct mei_device *dev, struct file *file,
171 char __user *ubuf, size_t length, loff_t *offset)
175 struct mei_cl_cb *cb = NULL;
176 struct mei_cl *cl = file->private_data;
177 unsigned long timeout;
180 /* Only Posible if we are in timeout */
181 if (!cl || cl != &dev->iamthif_cl) {
182 dev_dbg(&dev->pdev->dev, "bad file ext.\n");
186 i = mei_me_cl_by_id(dev, dev->iamthif_cl.me_client_id);
189 dev_dbg(&dev->pdev->dev, "amthif client not found.\n");
192 dev_dbg(&dev->pdev->dev, "checking amthif data\n");
193 cb = mei_amthif_find_read_list_entry(dev, file);
195 /* Check for if we can block or not*/
196 if (cb == NULL && file->f_flags & O_NONBLOCK)
200 dev_dbg(&dev->pdev->dev, "waiting for amthif data\n");
202 /* unlock the Mutex */
203 mutex_unlock(&dev->device_lock);
205 wait_ret = wait_event_interruptible(dev->iamthif_cl.wait,
206 (cb = mei_amthif_find_read_list_entry(dev, file)));
208 /* Locking again the Mutex */
209 mutex_lock(&dev->device_lock);
214 dev_dbg(&dev->pdev->dev, "woke up from sleep\n");
218 dev_dbg(&dev->pdev->dev, "Got amthif data\n");
219 dev->iamthif_timer = 0;
222 timeout = cb->read_time +
223 mei_secs_to_jiffies(MEI_IAMTHIF_READ_TIMER);
224 dev_dbg(&dev->pdev->dev, "amthif timeout = %lud\n",
227 if (time_after(jiffies, timeout)) {
228 dev_dbg(&dev->pdev->dev, "amthif Time out\n");
229 /* 15 sec for the message has expired */
235 /* if the whole message will fit remove it from the list */
236 if (cb->buf_idx >= *offset && length >= (cb->buf_idx - *offset))
238 else if (cb->buf_idx > 0 && cb->buf_idx <= *offset) {
239 /* end of the message has been reached */
244 /* else means that not full buffer will be read and do not
245 * remove message from deletion list
248 dev_dbg(&dev->pdev->dev, "amthif cb->response_buffer size - %d\n",
249 cb->response_buffer.size);
250 dev_dbg(&dev->pdev->dev, "amthif cb->buf_idx - %lu\n", cb->buf_idx);
252 /* length is being turncated to PAGE_SIZE, however,
253 * the buf_idx may point beyond */
254 length = min_t(size_t, length, (cb->buf_idx - *offset));
256 if (copy_to_user(ubuf, cb->response_buffer.data + *offset, length))
260 if ((*offset + length) < cb->buf_idx) {
266 dev_dbg(&dev->pdev->dev, "free amthif cb memory.\n");
274 * mei_amthif_send_cmd - send amthif command to the ME
276 * @dev: the device structure
277 * @cb: mei call back struct
279 * returns 0 on success, <0 on failure.
282 static int mei_amthif_send_cmd(struct mei_device *dev, struct mei_cl_cb *cb)
284 struct mei_msg_hdr mei_hdr;
290 dev_dbg(&dev->pdev->dev, "write data to amthif client.\n");
292 dev->iamthif_state = MEI_IAMTHIF_WRITING;
293 dev->iamthif_current_cb = cb;
294 dev->iamthif_file_object = cb->file_object;
295 dev->iamthif_canceled = false;
296 dev->iamthif_ioctl = true;
297 dev->iamthif_msg_buf_size = cb->request_buffer.size;
298 memcpy(dev->iamthif_msg_buf, cb->request_buffer.data,
299 cb->request_buffer.size);
301 ret = mei_cl_flow_ctrl_creds(&dev->iamthif_cl);
305 if (ret && dev->hbuf_is_ready) {
307 dev->hbuf_is_ready = false;
308 if (cb->request_buffer.size > mei_hbuf_max_len(dev)) {
309 mei_hdr.length = mei_hbuf_max_len(dev);
310 mei_hdr.msg_complete = 0;
312 mei_hdr.length = cb->request_buffer.size;
313 mei_hdr.msg_complete = 1;
316 mei_hdr.host_addr = dev->iamthif_cl.host_client_id;
317 mei_hdr.me_addr = dev->iamthif_cl.me_client_id;
318 mei_hdr.reserved = 0;
319 dev->iamthif_msg_buf_index += mei_hdr.length;
320 ret = mei_write_message(dev, &mei_hdr, dev->iamthif_msg_buf);
324 if (mei_hdr.msg_complete) {
325 if (mei_cl_flow_ctrl_reduce(&dev->iamthif_cl))
327 dev->iamthif_flow_control_pending = true;
328 dev->iamthif_state = MEI_IAMTHIF_FLOW_CONTROL;
329 dev_dbg(&dev->pdev->dev, "add amthif cb to write waiting list\n");
330 dev->iamthif_current_cb = cb;
331 dev->iamthif_file_object = cb->file_object;
332 list_add_tail(&cb->list, &dev->write_waiting_list.list);
334 dev_dbg(&dev->pdev->dev, "message does not complete, so add amthif cb to write list.\n");
335 list_add_tail(&cb->list, &dev->write_list.list);
338 if (!dev->hbuf_is_ready)
339 dev_dbg(&dev->pdev->dev, "host buffer is not empty");
341 dev_dbg(&dev->pdev->dev, "No flow control credentials, so add iamthif cb to write list.\n");
342 list_add_tail(&cb->list, &dev->write_list.list);
348 * mei_amthif_write - write amthif data to amthif client
350 * @dev: the device structure
351 * @cb: mei call back struct
353 * returns 0 on success, <0 on failure.
356 int mei_amthif_write(struct mei_device *dev, struct mei_cl_cb *cb)
363 ret = mei_io_cb_alloc_resp_buf(cb, dev->iamthif_mtu);
367 cb->fop_type = MEI_FOP_IOCTL;
369 if (!list_empty(&dev->amthif_cmd_list.list) ||
370 dev->iamthif_state != MEI_IAMTHIF_IDLE) {
371 dev_dbg(&dev->pdev->dev,
372 "amthif state = %d\n", dev->iamthif_state);
373 dev_dbg(&dev->pdev->dev, "AMTHIF: add cb to the wait list\n");
374 list_add_tail(&cb->list, &dev->amthif_cmd_list.list);
377 return mei_amthif_send_cmd(dev, cb);
380 * mei_amthif_run_next_cmd
382 * @dev: the device structure
384 * returns 0 on success, <0 on failure.
386 void mei_amthif_run_next_cmd(struct mei_device *dev)
388 struct mei_cl_cb *pos = NULL;
389 struct mei_cl_cb *next = NULL;
395 dev->iamthif_msg_buf_size = 0;
396 dev->iamthif_msg_buf_index = 0;
397 dev->iamthif_canceled = false;
398 dev->iamthif_ioctl = true;
399 dev->iamthif_state = MEI_IAMTHIF_IDLE;
400 dev->iamthif_timer = 0;
401 dev->iamthif_file_object = NULL;
403 dev_dbg(&dev->pdev->dev, "complete amthif cmd_list cb.\n");
405 list_for_each_entry_safe(pos, next, &dev->amthif_cmd_list.list, list) {
406 list_del(&pos->list);
408 if (pos->cl && pos->cl == &dev->iamthif_cl) {
409 status = mei_amthif_send_cmd(dev, pos);
411 dev_dbg(&dev->pdev->dev,
412 "amthif write failed status = %d\n",
422 unsigned int mei_amthif_poll(struct mei_device *dev,
423 struct file *file, poll_table *wait)
425 unsigned int mask = 0;
427 poll_wait(file, &dev->iamthif_cl.wait, wait);
429 mutex_lock(&dev->device_lock);
430 if (!mei_cl_is_connected(&dev->iamthif_cl)) {
434 } else if (dev->iamthif_state == MEI_IAMTHIF_READ_COMPLETE &&
435 dev->iamthif_file_object == file) {
437 mask |= (POLLIN | POLLRDNORM);
438 dev_dbg(&dev->pdev->dev, "run next amthif cb\n");
439 mei_amthif_run_next_cmd(dev);
441 mutex_unlock(&dev->device_lock);
449 * mei_amthif_irq_write_completed - processes completed iamthif operation.
451 * @dev: the device structure.
452 * @slots: free slots.
453 * @cb_pos: callback block.
454 * @cl: private data of the file object.
455 * @cmpl_list: complete list.
457 * returns 0, OK; otherwise, error.
459 int mei_amthif_irq_write_complete(struct mei_cl *cl, struct mei_cl_cb *cb,
460 s32 *slots, struct mei_cl_cb *cmpl_list)
462 struct mei_device *dev = cl->dev;
463 struct mei_msg_hdr mei_hdr;
464 size_t len = dev->iamthif_msg_buf_size - dev->iamthif_msg_buf_index;
465 u32 msg_slots = mei_data2slots(len);
468 rets = mei_cl_flow_ctrl_creds(cl);
473 cl_dbg(dev, cl, "No flow control credentials: not sending.\n");
477 mei_hdr.host_addr = cl->host_client_id;
478 mei_hdr.me_addr = cl->me_client_id;
479 mei_hdr.reserved = 0;
481 if (*slots >= msg_slots) {
482 mei_hdr.length = len;
483 mei_hdr.msg_complete = 1;
484 /* Split the message only if we can write the whole host buffer */
485 } else if (*slots == dev->hbuf_depth) {
487 len = (*slots * sizeof(u32)) - sizeof(struct mei_msg_hdr);
488 mei_hdr.length = len;
489 mei_hdr.msg_complete = 0;
491 /* wait for next time the host buffer is empty */
495 dev_dbg(&dev->pdev->dev, MEI_HDR_FMT, MEI_HDR_PRM(&mei_hdr));
498 rets = mei_write_message(dev, &mei_hdr,
499 dev->iamthif_msg_buf + dev->iamthif_msg_buf_index);
501 dev->iamthif_state = MEI_IAMTHIF_IDLE;
507 if (mei_cl_flow_ctrl_reduce(cl))
510 dev->iamthif_msg_buf_index += mei_hdr.length;
513 if (mei_hdr.msg_complete) {
514 dev->iamthif_state = MEI_IAMTHIF_FLOW_CONTROL;
515 dev->iamthif_flow_control_pending = true;
517 /* save iamthif cb sent to amthif client */
518 cb->buf_idx = dev->iamthif_msg_buf_index;
519 dev->iamthif_current_cb = cb;
521 list_move_tail(&cb->list, &dev->write_waiting_list.list);
529 * mei_amthif_irq_read_message - read routine after ISR to
530 * handle the read amthif message
532 * @dev: the device structure
533 * @mei_hdr: header of amthif message
534 * @complete_list: An instance of our list structure
536 * returns 0 on success, <0 on failure.
538 int mei_amthif_irq_read_msg(struct mei_device *dev,
539 struct mei_msg_hdr *mei_hdr,
540 struct mei_cl_cb *complete_list)
542 struct mei_cl_cb *cb;
543 unsigned char *buffer;
545 BUG_ON(mei_hdr->me_addr != dev->iamthif_cl.me_client_id);
546 BUG_ON(dev->iamthif_state != MEI_IAMTHIF_READING);
548 buffer = dev->iamthif_msg_buf + dev->iamthif_msg_buf_index;
549 BUG_ON(dev->iamthif_mtu < dev->iamthif_msg_buf_index + mei_hdr->length);
551 mei_read_slots(dev, buffer, mei_hdr->length);
553 dev->iamthif_msg_buf_index += mei_hdr->length;
555 if (!mei_hdr->msg_complete)
558 dev_dbg(&dev->pdev->dev, "amthif_message_buffer_index =%d\n",
561 dev_dbg(&dev->pdev->dev, "completed amthif read.\n ");
562 if (!dev->iamthif_current_cb)
565 cb = dev->iamthif_current_cb;
566 dev->iamthif_current_cb = NULL;
571 dev->iamthif_stall_timer = 0;
572 cb->buf_idx = dev->iamthif_msg_buf_index;
573 cb->read_time = jiffies;
574 if (dev->iamthif_ioctl && cb->cl == &dev->iamthif_cl) {
575 /* found the iamthif cb */
576 dev_dbg(&dev->pdev->dev, "complete the amthif read cb.\n ");
577 dev_dbg(&dev->pdev->dev, "add the amthif read cb to complete.\n ");
578 list_add_tail(&cb->list, &complete_list->list);
584 * mei_amthif_irq_read - prepares to read amthif data.
586 * @dev: the device structure.
587 * @slots: free slots.
589 * returns 0, OK; otherwise, error.
591 int mei_amthif_irq_read(struct mei_device *dev, s32 *slots)
593 u32 msg_slots = mei_data2slots(sizeof(struct hbm_flow_control));
595 if (*slots < msg_slots)
600 if (mei_hbm_cl_flow_control_req(dev, &dev->iamthif_cl)) {
601 dev_dbg(&dev->pdev->dev, "iamthif flow control failed\n");
605 dev_dbg(&dev->pdev->dev, "iamthif flow control success\n");
606 dev->iamthif_state = MEI_IAMTHIF_READING;
607 dev->iamthif_flow_control_pending = false;
608 dev->iamthif_msg_buf_index = 0;
609 dev->iamthif_msg_buf_size = 0;
610 dev->iamthif_stall_timer = MEI_IAMTHIF_STALL_TIMER;
611 dev->hbuf_is_ready = mei_hbuf_is_ready(dev);
616 * mei_amthif_complete - complete amthif callback.
618 * @dev: the device structure.
619 * @cb_pos: callback block.
621 void mei_amthif_complete(struct mei_device *dev, struct mei_cl_cb *cb)
623 if (dev->iamthif_canceled != 1) {
624 dev->iamthif_state = MEI_IAMTHIF_READ_COMPLETE;
625 dev->iamthif_stall_timer = 0;
626 memcpy(cb->response_buffer.data,
627 dev->iamthif_msg_buf,
628 dev->iamthif_msg_buf_index);
629 list_add_tail(&cb->list, &dev->amthif_rd_complete_list.list);
630 dev_dbg(&dev->pdev->dev, "amthif read completed\n");
631 dev->iamthif_timer = jiffies;
632 dev_dbg(&dev->pdev->dev, "dev->iamthif_timer = %ld\n",
635 mei_amthif_run_next_cmd(dev);
638 dev_dbg(&dev->pdev->dev, "completing amthif call back.\n");
639 wake_up_interruptible(&dev->iamthif_cl.wait);
643 * mei_clear_list - removes all callbacks associated with file
646 * @dev: device structure.
647 * @file: file structure
648 * @mei_cb_list: callbacks list
650 * mei_clear_list is called to clear resources associated with file
651 * when application calls close function or Ctrl-C was pressed
653 * returns true if callback removed from the list, false otherwise
655 static bool mei_clear_list(struct mei_device *dev,
656 const struct file *file, struct list_head *mei_cb_list)
658 struct mei_cl_cb *cb_pos = NULL;
659 struct mei_cl_cb *cb_next = NULL;
660 bool removed = false;
662 /* list all list member */
663 list_for_each_entry_safe(cb_pos, cb_next, mei_cb_list, list) {
664 /* check if list member associated with a file */
665 if (file == cb_pos->file_object) {
666 /* remove member from the list */
667 list_del(&cb_pos->list);
668 /* check if cb equal to current iamthif cb */
669 if (dev->iamthif_current_cb == cb_pos) {
670 dev->iamthif_current_cb = NULL;
671 /* send flow control to iamthif client */
672 mei_hbm_cl_flow_control_req(dev,
675 /* free all allocated buffers */
676 mei_io_cb_free(cb_pos);
685 * mei_clear_lists - removes all callbacks associated with file
687 * @dev: device structure
688 * @file: file structure
690 * mei_clear_lists is called to clear resources associated with file
691 * when application calls close function or Ctrl-C was pressed
693 * returns true if callback removed from the list, false otherwise
695 static bool mei_clear_lists(struct mei_device *dev, struct file *file)
697 bool removed = false;
699 /* remove callbacks associated with a file */
700 mei_clear_list(dev, file, &dev->amthif_cmd_list.list);
701 if (mei_clear_list(dev, file, &dev->amthif_rd_complete_list.list))
704 mei_clear_list(dev, file, &dev->ctrl_rd_list.list);
706 if (mei_clear_list(dev, file, &dev->ctrl_wr_list.list))
709 if (mei_clear_list(dev, file, &dev->write_waiting_list.list))
712 if (mei_clear_list(dev, file, &dev->write_list.list))
715 /* check if iamthif_current_cb not NULL */
716 if (dev->iamthif_current_cb && !removed) {
717 /* check file and iamthif current cb association */
718 if (dev->iamthif_current_cb->file_object == file) {
720 mei_io_cb_free(dev->iamthif_current_cb);
721 dev->iamthif_current_cb = NULL;
729 * mei_amthif_release - the release function
731 * @dev: device structure
732 * @file: pointer to file structure
734 * returns 0 on success, <0 on error
736 int mei_amthif_release(struct mei_device *dev, struct file *file)
738 if (dev->iamthif_open_count > 0)
739 dev->iamthif_open_count--;
741 if (dev->iamthif_file_object == file &&
742 dev->iamthif_state != MEI_IAMTHIF_IDLE) {
744 dev_dbg(&dev->pdev->dev, "amthif canceled iamthif state %d\n",
746 dev->iamthif_canceled = true;
747 if (dev->iamthif_state == MEI_IAMTHIF_READ_COMPLETE) {
748 dev_dbg(&dev->pdev->dev, "run next amthif iamthif cb\n");
749 mei_amthif_run_next_cmd(dev);
753 if (mei_clear_lists(dev, file))
754 dev->iamthif_state = MEI_IAMTHIF_IDLE;