1 // SPDX-License-Identifier: GPL-2.0+
2 /*
3 * Azoteq IQS550/572/525 Trackpad/Touchscreen Controller
4 *
5 * Copyright (C) 2018 Jeff LaBundy <jeff@labundy.com>
6 *
7 * These devices require firmware exported from a PC-based configuration tool
8 * made available by the vendor. Firmware files may be pushed to the device's
9 * nonvolatile memory by writing the filename to the 'fw_file' sysfs control.
10 *
11 * Link to PC-based configuration tool and datasheet: https://www.azoteq.com/
12 */
13
14 #include <linux/bits.h>
15 #include <linux/delay.h>
16 #include <linux/device.h>
17 #include <linux/err.h>
18 #include <linux/firmware.h>
19 #include <linux/gpio/consumer.h>
20 #include <linux/hex.h>
21 #include <linux/i2c.h>
22 #include <linux/input.h>
23 #include <linux/input/mt.h>
24 #include <linux/input/touchscreen.h>
25 #include <linux/interrupt.h>
26 #include <linux/kernel.h>
27 #include <linux/module.h>
28 #include <linux/slab.h>
29 #include <linux/unaligned.h>
30
31 #define IQS5XX_FW_FILE_LEN 64
32 #define IQS5XX_NUM_RETRIES 10
33 #define IQS5XX_NUM_CONTACTS 5
34 #define IQS5XX_WR_BYTES_MAX 2
35
36 #define IQS5XX_PROD_NUM_IQS550 40
37 #define IQS5XX_PROD_NUM_IQS572 58
38 #define IQS5XX_PROD_NUM_IQS525 52
39
40 #define IQS5XX_SHOW_RESET BIT(7)
41 #define IQS5XX_ACK_RESET BIT(7)
42
43 #define IQS5XX_SUSPEND BIT(0)
44 #define IQS5XX_RESUME 0
45
46 #define IQS5XX_SETUP_COMPLETE BIT(6)
47 #define IQS5XX_WDT BIT(5)
48 #define IQS5XX_ALP_REATI BIT(3)
49 #define IQS5XX_REATI BIT(2)
50
51 #define IQS5XX_TP_EVENT BIT(2)
52 #define IQS5XX_EVENT_MODE BIT(0)
53
54 #define IQS5XX_PROD_NUM 0x0000
55 #define IQS5XX_SYS_INFO0 0x000F
56 #define IQS5XX_SYS_INFO1 0x0010
57 #define IQS5XX_SYS_CTRL0 0x0431
58 #define IQS5XX_SYS_CTRL1 0x0432
59 #define IQS5XX_SYS_CFG0 0x058E
60 #define IQS5XX_SYS_CFG1 0x058F
61 #define IQS5XX_X_RES 0x066E
62 #define IQS5XX_Y_RES 0x0670
63 #define IQS5XX_EXP_FILE 0x0677
64 #define IQS5XX_CHKSM 0x83C0
65 #define IQS5XX_APP 0x8400
66 #define IQS5XX_CSTM 0xBE00
67 #define IQS5XX_PMAP_END 0xBFFF
68 #define IQS5XX_END_COMM 0xEEEE
69
70 #define IQS5XX_CHKSM_LEN (IQS5XX_APP - IQS5XX_CHKSM)
71 #define IQS5XX_APP_LEN (IQS5XX_CSTM - IQS5XX_APP)
72 #define IQS5XX_CSTM_LEN (IQS5XX_PMAP_END + 1 - IQS5XX_CSTM)
73 #define IQS5XX_PMAP_LEN (IQS5XX_PMAP_END + 1 - IQS5XX_CHKSM)
74
75 /* Length of firmware header in hexadecimal characters */
76 #define IQS5XX_REC_HDR_LEN_HEX (1 /* start */ + 2 /* size */ + \
77 4 /* addr */ + 2 /* type */)
78 #define IQS5XX_REC_HDR_SIZE 4 /* size + addr (2 bytes) + type, in bytes*/
79 #define IQS5XX_REC_DATA_SIZE 255 /* maximum size of the data portion */
80 #define IQS5XX_REC_TYPE_DATA 0x00
81 #define IQS5XX_REC_TYPE_EOF 0x01
82
83 #define IQS5XX_BL_ADDR_MASK 0x40
84 #define IQS5XX_BL_CMD_VER 0x00
85 #define IQS5XX_BL_CMD_READ 0x01
86 #define IQS5XX_BL_CMD_EXEC 0x02
87 #define IQS5XX_BL_CMD_CRC 0x03
88 #define IQS5XX_BL_BLK_LEN_MAX 64
89 #define IQS5XX_BL_ID 0x0200
90 #define IQS5XX_BL_STATUS_NONE 0xEE
91 #define IQS5XX_BL_CRC_PASS 0x00
92 #define IQS5XX_BL_CRC_FAIL 0x01
93 #define IQS5XX_BL_ATTEMPTS 3
94
95 struct iqs5xx_dev_id_info {
96 __be16 prod_num;
97 __be16 proj_num;
98 u8 major_ver;
99 u8 minor_ver;
100 u8 bl_status;
101 } __packed;
102
103 struct iqs5xx_touch_data {
104 __be16 abs_x;
105 __be16 abs_y;
106 __be16 strength;
107 u8 area;
108 } __packed;
109
110 struct iqs5xx_status {
111 u8 sys_info[2];
112 u8 num_active;
113 __be16 rel_x;
114 __be16 rel_y;
115 struct iqs5xx_touch_data touch_data[IQS5XX_NUM_CONTACTS];
116 } __packed;
117
118 struct iqs5xx_private {
119 struct i2c_client *client;
120 struct input_dev *input;
121 struct gpio_desc *reset_gpio;
122 struct touchscreen_properties prop;
123 struct mutex lock;
124 struct iqs5xx_dev_id_info dev_id_info;
125 u8 exp_file[2];
126 };
127
iqs5xx_read_burst(struct i2c_client * client,u16 reg,void * val,u16 len)128 static int iqs5xx_read_burst(struct i2c_client *client,
129 u16 reg, void *val, u16 len)
130 {
131 __be16 reg_buf = cpu_to_be16(reg);
132 int ret, i;
133 struct i2c_msg msg[] = {
134 {
135 .addr = client->addr,
136 .flags = 0,
137 .len = sizeof(reg_buf),
138 .buf = (u8 *)®_buf,
139 },
140 {
141 .addr = client->addr,
142 .flags = I2C_M_RD,
143 .len = len,
144 .buf = (u8 *)val,
145 },
146 };
147
148 /*
149 * The first addressing attempt outside of a communication window fails
150 * and must be retried, after which the device clock stretches until it
151 * is available.
152 */
153 for (i = 0; i < IQS5XX_NUM_RETRIES; i++) {
154 ret = i2c_transfer(client->adapter, msg, ARRAY_SIZE(msg));
155 if (ret == ARRAY_SIZE(msg))
156 return 0;
157
158 usleep_range(200, 300);
159 }
160
161 if (ret >= 0)
162 ret = -EIO;
163
164 dev_err(&client->dev, "Failed to read from address 0x%04X: %d\n",
165 reg, ret);
166
167 return ret;
168 }
169
iqs5xx_read_word(struct i2c_client * client,u16 reg,u16 * val)170 static int iqs5xx_read_word(struct i2c_client *client, u16 reg, u16 *val)
171 {
172 __be16 val_buf;
173 int error;
174
175 error = iqs5xx_read_burst(client, reg, &val_buf, sizeof(val_buf));
176 if (error)
177 return error;
178
179 *val = be16_to_cpu(val_buf);
180
181 return 0;
182 }
183
iqs5xx_write_burst(struct i2c_client * client,u16 reg,const void * val,u16 len)184 static int iqs5xx_write_burst(struct i2c_client *client,
185 u16 reg, const void *val, u16 len)
186 {
187 int ret, i;
188 u16 mlen = sizeof(reg) + len;
189 u8 mbuf[sizeof(reg) + IQS5XX_WR_BYTES_MAX];
190
191 if (len > IQS5XX_WR_BYTES_MAX)
192 return -EINVAL;
193
194 put_unaligned_be16(reg, mbuf);
195 memcpy(mbuf + sizeof(reg), val, len);
196
197 /*
198 * The first addressing attempt outside of a communication window fails
199 * and must be retried, after which the device clock stretches until it
200 * is available.
201 */
202 for (i = 0; i < IQS5XX_NUM_RETRIES; i++) {
203 ret = i2c_master_send(client, mbuf, mlen);
204 if (ret == mlen)
205 return 0;
206
207 usleep_range(200, 300);
208 }
209
210 if (ret >= 0)
211 ret = -EIO;
212
213 dev_err(&client->dev, "Failed to write to address 0x%04X: %d\n",
214 reg, ret);
215
216 return ret;
217 }
218
iqs5xx_write_word(struct i2c_client * client,u16 reg,u16 val)219 static int iqs5xx_write_word(struct i2c_client *client, u16 reg, u16 val)
220 {
221 __be16 val_buf = cpu_to_be16(val);
222
223 return iqs5xx_write_burst(client, reg, &val_buf, sizeof(val_buf));
224 }
225
iqs5xx_write_byte(struct i2c_client * client,u16 reg,u8 val)226 static int iqs5xx_write_byte(struct i2c_client *client, u16 reg, u8 val)
227 {
228 return iqs5xx_write_burst(client, reg, &val, sizeof(val));
229 }
230
iqs5xx_reset(struct i2c_client * client)231 static void iqs5xx_reset(struct i2c_client *client)
232 {
233 struct iqs5xx_private *iqs5xx = i2c_get_clientdata(client);
234
235 gpiod_set_value_cansleep(iqs5xx->reset_gpio, 1);
236 usleep_range(200, 300);
237
238 gpiod_set_value_cansleep(iqs5xx->reset_gpio, 0);
239 }
240
iqs5xx_bl_cmd(struct i2c_client * client,u8 bl_cmd,u16 bl_addr)241 static int iqs5xx_bl_cmd(struct i2c_client *client, u8 bl_cmd, u16 bl_addr)
242 {
243 struct i2c_msg msg;
244 int ret;
245 u8 mbuf[sizeof(bl_cmd) + sizeof(bl_addr)];
246
247 msg.addr = client->addr ^ IQS5XX_BL_ADDR_MASK;
248 msg.flags = 0;
249 msg.len = sizeof(bl_cmd);
250 msg.buf = mbuf;
251
252 *mbuf = bl_cmd;
253
254 switch (bl_cmd) {
255 case IQS5XX_BL_CMD_VER:
256 case IQS5XX_BL_CMD_CRC:
257 case IQS5XX_BL_CMD_EXEC:
258 break;
259 case IQS5XX_BL_CMD_READ:
260 msg.len += sizeof(bl_addr);
261 put_unaligned_be16(bl_addr, mbuf + sizeof(bl_cmd));
262 break;
263 default:
264 return -EINVAL;
265 }
266
267 ret = i2c_transfer(client->adapter, &msg, 1);
268 if (ret != 1)
269 goto msg_fail;
270
271 switch (bl_cmd) {
272 case IQS5XX_BL_CMD_VER:
273 msg.len = sizeof(u16);
274 break;
275 case IQS5XX_BL_CMD_CRC:
276 msg.len = sizeof(u8);
277 /*
278 * This delay saves the bus controller the trouble of having to
279 * tolerate a relatively long clock-stretching period while the
280 * CRC is calculated.
281 */
282 msleep(50);
283 break;
284 case IQS5XX_BL_CMD_EXEC:
285 usleep_range(10000, 10100);
286 fallthrough;
287 default:
288 return 0;
289 }
290
291 msg.flags = I2C_M_RD;
292
293 ret = i2c_transfer(client->adapter, &msg, 1);
294 if (ret != 1)
295 goto msg_fail;
296
297 if (bl_cmd == IQS5XX_BL_CMD_VER &&
298 get_unaligned_be16(mbuf) != IQS5XX_BL_ID) {
299 dev_err(&client->dev, "Unrecognized bootloader ID: 0x%04X\n",
300 get_unaligned_be16(mbuf));
301 return -EINVAL;
302 }
303
304 if (bl_cmd == IQS5XX_BL_CMD_CRC && *mbuf != IQS5XX_BL_CRC_PASS) {
305 dev_err(&client->dev, "Bootloader CRC failed\n");
306 return -EIO;
307 }
308
309 return 0;
310
311 msg_fail:
312 if (ret >= 0)
313 ret = -EIO;
314
315 if (bl_cmd != IQS5XX_BL_CMD_VER)
316 dev_err(&client->dev,
317 "Unsuccessful bootloader command 0x%02X: %d\n",
318 bl_cmd, ret);
319
320 return ret;
321 }
322
iqs5xx_bl_open(struct i2c_client * client)323 static int iqs5xx_bl_open(struct i2c_client *client)
324 {
325 int error, i, j;
326
327 /*
328 * The device opens a bootloader polling window for 2 ms following the
329 * release of reset. If the host cannot establish communication during
330 * this time frame, it must cycle reset again.
331 */
332 for (i = 0; i < IQS5XX_BL_ATTEMPTS; i++) {
333 iqs5xx_reset(client);
334 usleep_range(350, 400);
335
336 for (j = 0; j < IQS5XX_NUM_RETRIES; j++) {
337 error = iqs5xx_bl_cmd(client, IQS5XX_BL_CMD_VER, 0);
338 if (!error)
339 usleep_range(10000, 10100);
340 else if (error != -EINVAL)
341 continue;
342
343 return error;
344 }
345 }
346
347 dev_err(&client->dev, "Failed to open bootloader: %d\n", error);
348
349 return error;
350 }
351
iqs5xx_bl_write(struct i2c_client * client,u16 bl_addr,const u8 * pmap_data,u16 pmap_len)352 static int iqs5xx_bl_write(struct i2c_client *client,
353 u16 bl_addr, const u8 *pmap_data, u16 pmap_len)
354 {
355 struct i2c_msg msg;
356 int ret, i;
357 u8 mbuf[sizeof(bl_addr) + IQS5XX_BL_BLK_LEN_MAX];
358
359 if (pmap_len % IQS5XX_BL_BLK_LEN_MAX)
360 return -EINVAL;
361
362 msg.addr = client->addr ^ IQS5XX_BL_ADDR_MASK;
363 msg.flags = 0;
364 msg.len = sizeof(mbuf);
365 msg.buf = mbuf;
366
367 for (i = 0; i < pmap_len; i += IQS5XX_BL_BLK_LEN_MAX) {
368 put_unaligned_be16(bl_addr + i, mbuf);
369 memcpy(mbuf + sizeof(bl_addr), pmap_data + i,
370 sizeof(mbuf) - sizeof(bl_addr));
371
372 ret = i2c_transfer(client->adapter, &msg, 1);
373 if (ret != 1)
374 goto msg_fail;
375
376 usleep_range(10000, 10100);
377 }
378
379 return 0;
380
381 msg_fail:
382 if (ret >= 0)
383 ret = -EIO;
384
385 dev_err(&client->dev, "Failed to write block at address 0x%04X: %d\n",
386 bl_addr + i, ret);
387
388 return ret;
389 }
390
iqs5xx_bl_verify(struct i2c_client * client,u16 bl_addr,const u8 * pmap_data,u16 pmap_len)391 static int iqs5xx_bl_verify(struct i2c_client *client,
392 u16 bl_addr, const u8 *pmap_data, u16 pmap_len)
393 {
394 struct i2c_msg msg;
395 int ret, i;
396 u8 bl_data[IQS5XX_BL_BLK_LEN_MAX];
397
398 if (pmap_len % IQS5XX_BL_BLK_LEN_MAX)
399 return -EINVAL;
400
401 msg.addr = client->addr ^ IQS5XX_BL_ADDR_MASK;
402 msg.flags = I2C_M_RD;
403 msg.len = sizeof(bl_data);
404 msg.buf = bl_data;
405
406 for (i = 0; i < pmap_len; i += IQS5XX_BL_BLK_LEN_MAX) {
407 ret = iqs5xx_bl_cmd(client, IQS5XX_BL_CMD_READ, bl_addr + i);
408 if (ret)
409 return ret;
410
411 ret = i2c_transfer(client->adapter, &msg, 1);
412 if (ret != 1)
413 goto msg_fail;
414
415 if (memcmp(bl_data, pmap_data + i, sizeof(bl_data))) {
416 dev_err(&client->dev,
417 "Failed to verify block at address 0x%04X\n",
418 bl_addr + i);
419 return -EIO;
420 }
421 }
422
423 return 0;
424
425 msg_fail:
426 if (ret >= 0)
427 ret = -EIO;
428
429 dev_err(&client->dev, "Failed to read block at address 0x%04X: %d\n",
430 bl_addr + i, ret);
431
432 return ret;
433 }
434
iqs5xx_set_state(struct i2c_client * client,u8 state)435 static int iqs5xx_set_state(struct i2c_client *client, u8 state)
436 {
437 struct iqs5xx_private *iqs5xx = i2c_get_clientdata(client);
438 int error1, error2;
439
440 if (!iqs5xx->dev_id_info.bl_status)
441 return 0;
442
443 guard(mutex)(&iqs5xx->lock);
444
445 /*
446 * Addressing the device outside of a communication window prompts it
447 * to assert the RDY output, so disable the interrupt line to prevent
448 * the handler from servicing a false interrupt.
449 */
450 guard(disable_irq)(&client->irq);
451
452 error1 = iqs5xx_write_byte(client, IQS5XX_SYS_CTRL1, state);
453 error2 = iqs5xx_write_byte(client, IQS5XX_END_COMM, 0);
454
455 usleep_range(50, 100);
456
457 return error1 ?: error2;
458 }
459
iqs5xx_open(struct input_dev * input)460 static int iqs5xx_open(struct input_dev *input)
461 {
462 struct iqs5xx_private *iqs5xx = input_get_drvdata(input);
463
464 return iqs5xx_set_state(iqs5xx->client, IQS5XX_RESUME);
465 }
466
iqs5xx_close(struct input_dev * input)467 static void iqs5xx_close(struct input_dev *input)
468 {
469 struct iqs5xx_private *iqs5xx = input_get_drvdata(input);
470
471 iqs5xx_set_state(iqs5xx->client, IQS5XX_SUSPEND);
472 }
473
iqs5xx_axis_init(struct i2c_client * client)474 static int iqs5xx_axis_init(struct i2c_client *client)
475 {
476 struct iqs5xx_private *iqs5xx = i2c_get_clientdata(client);
477 struct touchscreen_properties *prop = &iqs5xx->prop;
478 struct input_dev *input = iqs5xx->input;
479 u16 max_x, max_y;
480 int error;
481
482 if (!input) {
483 input = devm_input_allocate_device(&client->dev);
484 if (!input)
485 return -ENOMEM;
486
487 input->name = client->name;
488 input->id.bustype = BUS_I2C;
489 input->open = iqs5xx_open;
490 input->close = iqs5xx_close;
491
492 input_set_drvdata(input, iqs5xx);
493 iqs5xx->input = input;
494 }
495
496 error = iqs5xx_read_word(client, IQS5XX_X_RES, &max_x);
497 if (error)
498 return error;
499
500 error = iqs5xx_read_word(client, IQS5XX_Y_RES, &max_y);
501 if (error)
502 return error;
503
504 input_set_abs_params(input, ABS_MT_POSITION_X, 0, max_x, 0, 0);
505 input_set_abs_params(input, ABS_MT_POSITION_Y, 0, max_y, 0, 0);
506 input_set_abs_params(input, ABS_MT_PRESSURE, 0, U16_MAX, 0, 0);
507
508 touchscreen_parse_properties(input, true, prop);
509
510 /*
511 * The device reserves 0xFFFF for coordinates that correspond to slots
512 * which are not in a state of touch.
513 */
514 if (prop->max_x >= U16_MAX || prop->max_y >= U16_MAX) {
515 dev_err(&client->dev, "Invalid touchscreen size: %u*%u\n",
516 prop->max_x, prop->max_y);
517 return -EINVAL;
518 }
519
520 if (prop->max_x != max_x) {
521 error = iqs5xx_write_word(client, IQS5XX_X_RES, prop->max_x);
522 if (error)
523 return error;
524 }
525
526 if (prop->max_y != max_y) {
527 error = iqs5xx_write_word(client, IQS5XX_Y_RES, prop->max_y);
528 if (error)
529 return error;
530 }
531
532 error = input_mt_init_slots(input, IQS5XX_NUM_CONTACTS,
533 INPUT_MT_DIRECT);
534 if (error)
535 dev_err(&client->dev, "Failed to initialize slots: %d\n",
536 error);
537
538 return error;
539 }
540
iqs5xx_dev_init(struct i2c_client * client)541 static int iqs5xx_dev_init(struct i2c_client *client)
542 {
543 struct iqs5xx_private *iqs5xx = i2c_get_clientdata(client);
544 struct iqs5xx_dev_id_info *dev_id_info;
545 int error;
546 u8 buf[sizeof(*dev_id_info) + 1];
547
548 error = iqs5xx_read_burst(client, IQS5XX_PROD_NUM,
549 &buf[1], sizeof(*dev_id_info));
550 if (error)
551 return iqs5xx_bl_open(client);
552
553 /*
554 * A000 and B000 devices use 8-bit and 16-bit addressing, respectively.
555 * Querying an A000 device's version information with 16-bit addressing
556 * gives the appearance that the data is shifted by one byte; a nonzero
557 * leading array element suggests this could be the case (in which case
558 * the missing zero is prepended).
559 */
560 buf[0] = 0;
561 dev_id_info = (struct iqs5xx_dev_id_info *)&buf[buf[1] ? 0 : 1];
562
563 switch (be16_to_cpu(dev_id_info->prod_num)) {
564 case IQS5XX_PROD_NUM_IQS550:
565 case IQS5XX_PROD_NUM_IQS572:
566 case IQS5XX_PROD_NUM_IQS525:
567 break;
568 default:
569 dev_err(&client->dev, "Unrecognized product number: %u\n",
570 be16_to_cpu(dev_id_info->prod_num));
571 return -EINVAL;
572 }
573
574 /*
575 * With the product number recognized yet shifted by one byte, open the
576 * bootloader and wait for user space to convert the A000 device into a
577 * B000 device via new firmware.
578 */
579 if (buf[1]) {
580 dev_err(&client->dev, "Opening bootloader for A000 device\n");
581 return iqs5xx_bl_open(client);
582 }
583
584 error = iqs5xx_read_burst(client, IQS5XX_EXP_FILE,
585 iqs5xx->exp_file, sizeof(iqs5xx->exp_file));
586 if (error)
587 return error;
588
589 error = iqs5xx_axis_init(client);
590 if (error)
591 return error;
592
593 error = iqs5xx_write_byte(client, IQS5XX_SYS_CTRL0, IQS5XX_ACK_RESET);
594 if (error)
595 return error;
596
597 error = iqs5xx_write_byte(client, IQS5XX_SYS_CFG0,
598 IQS5XX_SETUP_COMPLETE | IQS5XX_WDT |
599 IQS5XX_ALP_REATI | IQS5XX_REATI);
600 if (error)
601 return error;
602
603 error = iqs5xx_write_byte(client, IQS5XX_SYS_CFG1,
604 IQS5XX_TP_EVENT | IQS5XX_EVENT_MODE);
605 if (error)
606 return error;
607
608 error = iqs5xx_write_byte(client, IQS5XX_END_COMM, 0);
609 if (error)
610 return error;
611
612 iqs5xx->dev_id_info = *dev_id_info;
613
614 /*
615 * The following delay allows ATI to complete before the open and close
616 * callbacks are free to elicit I2C communication. Any attempts to read
617 * from or write to the device during this time may face extended clock
618 * stretching and prompt the I2C controller to report an error.
619 */
620 msleep(250);
621
622 return 0;
623 }
624
iqs5xx_irq(int irq,void * data)625 static irqreturn_t iqs5xx_irq(int irq, void *data)
626 {
627 struct iqs5xx_private *iqs5xx = data;
628 struct iqs5xx_status status;
629 struct i2c_client *client = iqs5xx->client;
630 struct input_dev *input = iqs5xx->input;
631 int error, i;
632
633 /*
634 * This check is purely a precaution, as the device does not assert the
635 * RDY output during bootloader mode. If the device operates outside of
636 * bootloader mode, the input device is guaranteed to be allocated.
637 */
638 if (!iqs5xx->dev_id_info.bl_status)
639 return IRQ_NONE;
640
641 error = iqs5xx_read_burst(client, IQS5XX_SYS_INFO0,
642 &status, sizeof(status));
643 if (error)
644 return IRQ_NONE;
645
646 if (status.sys_info[0] & IQS5XX_SHOW_RESET) {
647 dev_err(&client->dev, "Unexpected device reset\n");
648
649 error = iqs5xx_dev_init(client);
650 if (error) {
651 dev_err(&client->dev,
652 "Failed to re-initialize device: %d\n", error);
653 return IRQ_NONE;
654 }
655
656 return IRQ_HANDLED;
657 }
658
659 for (i = 0; i < ARRAY_SIZE(status.touch_data); i++) {
660 struct iqs5xx_touch_data *touch_data = &status.touch_data[i];
661 u16 pressure = be16_to_cpu(touch_data->strength);
662
663 input_mt_slot(input, i);
664 if (input_mt_report_slot_state(input, MT_TOOL_FINGER,
665 pressure != 0)) {
666 touchscreen_report_pos(input, &iqs5xx->prop,
667 be16_to_cpu(touch_data->abs_x),
668 be16_to_cpu(touch_data->abs_y),
669 true);
670 input_report_abs(input, ABS_MT_PRESSURE, pressure);
671 }
672 }
673
674 input_mt_sync_frame(input);
675 input_sync(input);
676
677 error = iqs5xx_write_byte(client, IQS5XX_END_COMM, 0);
678 if (error)
679 return IRQ_NONE;
680
681 /*
682 * Once the communication window is closed, a small delay is added to
683 * ensure the device's RDY output has been deasserted by the time the
684 * interrupt handler returns.
685 */
686 usleep_range(50, 100);
687
688 return IRQ_HANDLED;
689 }
690
iqs5xx_fw_file_parse(struct i2c_client * client,const char * fw_file,u8 * pmap)691 static int iqs5xx_fw_file_parse(struct i2c_client *client,
692 const char *fw_file, u8 *pmap)
693 {
694 size_t pos = 0;
695 int error, i;
696 u16 rec_num = 1;
697 u16 rec_addr;
698 u8 rec_len, rec_type, rec_chksm, chksm;
699 u8 rec_hdr[IQS5XX_REC_HDR_SIZE];
700 u8 rec_data[IQS5XX_REC_DATA_SIZE];
701
702 /*
703 * Firmware exported from the vendor's configuration tool deviates from
704 * standard ihex as follows: (1) the checksum for records corresponding
705 * to user-exported settings is not recalculated, and (2) an address of
706 * 0xFFFF is used for the EOF record.
707 *
708 * Because the ihex2fw tool tolerates neither (1) nor (2), the slightly
709 * nonstandard ihex firmware is parsed directly by the driver.
710 */
711 const struct firmware *fw __free(firmware) = NULL;
712 error = request_firmware(&fw, fw_file, &client->dev);
713 if (error) {
714 dev_err(&client->dev, "Failed to request firmware %s: %d\n",
715 fw_file, error);
716 return error;
717 }
718
719 do {
720 if (pos + IQS5XX_REC_HDR_LEN_HEX > fw->size) {
721 dev_err(&client->dev, "Insufficient firmware size\n");
722 return -EINVAL;
723 }
724
725 if (fw->data[pos] != ':') {
726 dev_err(&client->dev, "Invalid start at record %u\n",
727 rec_num);
728 return -EINVAL;
729 }
730
731 /* Convert all 3 fields (length, address, and type) in one go */
732 error = hex2bin(rec_hdr, &fw->data[pos + 1], sizeof(rec_hdr));
733 if (error) {
734 dev_err(&client->dev, "Invalid header at record %u\n",
735 rec_num);
736 return error;
737 }
738 pos += IQS5XX_REC_HDR_LEN_HEX;
739
740 rec_len = *rec_hdr;
741 rec_addr = get_unaligned_be16(rec_hdr + sizeof(rec_len));
742 rec_type = *(rec_hdr + sizeof(rec_len) + sizeof(rec_addr));
743
744 /*
745 * Check if we have enough data for the data portion of the
746 * record, as well as the checksum byte. Everything is doubled
747 * because data is in ASCII HEX and not binary format.
748 */
749 if (pos + (rec_len + sizeof(rec_chksm)) * 2 > fw->size) {
750 dev_err(&client->dev, "Insufficient firmware size\n");
751 return -EINVAL;
752 }
753
754 error = hex2bin(rec_data, &fw->data[pos], rec_len);
755 if (error) {
756 dev_err(&client->dev, "Invalid data at record %u\n",
757 rec_num);
758 return error;
759 }
760 pos += rec_len * 2;
761
762 error = hex2bin(&rec_chksm, &fw->data[pos], sizeof(rec_chksm));
763 if (error) {
764 dev_err(&client->dev, "Invalid checksum at record %u\n",
765 rec_num);
766 return error;
767 }
768 pos += 2;
769
770 chksm = 0;
771 for (i = 0; i < sizeof(rec_hdr); i++)
772 chksm += rec_hdr[i];
773 for (i = 0; i < rec_len; i++)
774 chksm += rec_data[i];
775 chksm = ~chksm + 1;
776
777 if (chksm != rec_chksm && rec_addr < IQS5XX_CSTM) {
778 dev_err(&client->dev,
779 "Incorrect checksum at record %u\n",
780 rec_num);
781 error = -EINVAL;
782 break;
783 }
784
785 switch (rec_type) {
786 case IQS5XX_REC_TYPE_DATA:
787 if (rec_addr < IQS5XX_CHKSM ||
788 rec_addr > IQS5XX_PMAP_END ||
789 rec_len > IQS5XX_PMAP_END + 1 - rec_addr) {
790 dev_err(&client->dev,
791 "Invalid address at record %u\n",
792 rec_num);
793 return -EINVAL;
794 }
795
796 memcpy(pmap + rec_addr - IQS5XX_CHKSM,
797 rec_data, rec_len);
798 break;
799
800 case IQS5XX_REC_TYPE_EOF:
801 break;
802
803 default:
804 dev_err(&client->dev, "Invalid type at record %u\n",
805 rec_num);
806 return -EINVAL;
807 }
808
809 rec_num++;
810 while (pos < fw->size) {
811 if (*(fw->data + pos) == ':')
812 break;
813 pos++;
814 }
815 } while (rec_type != IQS5XX_REC_TYPE_EOF);
816
817 return 0;
818 }
819
iqs5xx_update_firmware(struct iqs5xx_private * iqs5xx,const u8 * pmap)820 static int iqs5xx_update_firmware(struct iqs5xx_private *iqs5xx, const u8 *pmap)
821 {
822 struct i2c_client *client = iqs5xx->client;
823 int error;
824
825 iqs5xx->dev_id_info.bl_status = 0;
826
827 error = iqs5xx_bl_cmd(client, IQS5XX_BL_CMD_VER, 0);
828 if (error) {
829 error = iqs5xx_bl_open(client);
830 if (error)
831 return error;
832 }
833
834 error = iqs5xx_bl_write(client, IQS5XX_CHKSM, pmap, IQS5XX_PMAP_LEN);
835 if (error)
836 return error;
837
838 error = iqs5xx_bl_cmd(client, IQS5XX_BL_CMD_CRC, 0);
839 if (error)
840 return error;
841
842 error = iqs5xx_bl_verify(client, IQS5XX_CSTM,
843 pmap + IQS5XX_CHKSM_LEN + IQS5XX_APP_LEN,
844 IQS5XX_CSTM_LEN);
845 if (error)
846 return error;
847
848 return 0;
849 }
850
iqs5xx_fw_file_write(struct i2c_client * client,const char * fw_file)851 static int iqs5xx_fw_file_write(struct i2c_client *client, const char *fw_file)
852 {
853 struct iqs5xx_private *iqs5xx = i2c_get_clientdata(client);
854 int error, error_init = 0;
855
856 u8 *pmap __free(kfree) = kzalloc(IQS5XX_PMAP_LEN, GFP_KERNEL);
857 if (!pmap)
858 return -ENOMEM;
859
860 error = iqs5xx_fw_file_parse(client, fw_file, pmap);
861 if (error)
862 return error;
863
864 guard(mutex)(&iqs5xx->lock);
865
866 /*
867 * Disable the interrupt line in case the first attempt(s) to enter the
868 * bootloader don't happen quickly enough, in which case the device may
869 * assert the RDY output until the next attempt.
870 */
871 guard(disable_irq)(&client->irq);
872
873 error = iqs5xx_update_firmware(iqs5xx, pmap);
874
875 iqs5xx_reset(client);
876 usleep_range(15000, 15100);
877
878 error_init = iqs5xx_dev_init(client);
879 if (!iqs5xx->dev_id_info.bl_status)
880 error_init = error_init ? : -EINVAL;
881
882 return error ?: error_init;
883 }
884
fw_file_store(struct device * dev,struct device_attribute * attr,const char * buf,size_t count)885 static ssize_t fw_file_store(struct device *dev,
886 struct device_attribute *attr, const char *buf,
887 size_t count)
888 {
889 struct iqs5xx_private *iqs5xx = dev_get_drvdata(dev);
890 struct i2c_client *client = iqs5xx->client;
891 size_t len = count;
892 bool input_reg = !iqs5xx->input;
893 char fw_file[IQS5XX_FW_FILE_LEN + 1];
894 int error;
895
896 if (!len)
897 return -EINVAL;
898
899 if (buf[len - 1] == '\n')
900 len--;
901
902 if (len > IQS5XX_FW_FILE_LEN)
903 return -ENAMETOOLONG;
904
905 memcpy(fw_file, buf, len);
906 fw_file[len] = '\0';
907
908 error = iqs5xx_fw_file_write(client, fw_file);
909 if (error)
910 return error;
911
912 /*
913 * If the input device was not allocated already, it is guaranteed to
914 * be allocated by this point and can finally be registered.
915 */
916 if (input_reg) {
917 error = input_register_device(iqs5xx->input);
918 if (error) {
919 dev_err(&client->dev,
920 "Failed to register device: %d\n",
921 error);
922 return error;
923 }
924 }
925
926 return count;
927 }
928
fw_info_show(struct device * dev,struct device_attribute * attr,char * buf)929 static ssize_t fw_info_show(struct device *dev,
930 struct device_attribute *attr, char *buf)
931 {
932 struct iqs5xx_private *iqs5xx = dev_get_drvdata(dev);
933
934 if (!iqs5xx->dev_id_info.bl_status)
935 return -ENODATA;
936
937 return sysfs_emit(buf, "%u.%u.%u.%u:%u.%u\n",
938 be16_to_cpu(iqs5xx->dev_id_info.prod_num),
939 be16_to_cpu(iqs5xx->dev_id_info.proj_num),
940 iqs5xx->dev_id_info.major_ver,
941 iqs5xx->dev_id_info.minor_ver,
942 iqs5xx->exp_file[0], iqs5xx->exp_file[1]);
943 }
944
945 static DEVICE_ATTR_WO(fw_file);
946 static DEVICE_ATTR_RO(fw_info);
947
948 static struct attribute *iqs5xx_attrs[] = {
949 &dev_attr_fw_file.attr,
950 &dev_attr_fw_info.attr,
951 NULL,
952 };
953
iqs5xx_attr_is_visible(struct kobject * kobj,struct attribute * attr,int i)954 static umode_t iqs5xx_attr_is_visible(struct kobject *kobj,
955 struct attribute *attr, int i)
956 {
957 struct device *dev = kobj_to_dev(kobj);
958 struct iqs5xx_private *iqs5xx = dev_get_drvdata(dev);
959
960 if (attr == &dev_attr_fw_file.attr &&
961 (iqs5xx->dev_id_info.bl_status == IQS5XX_BL_STATUS_NONE ||
962 !iqs5xx->reset_gpio))
963 return 0;
964
965 return attr->mode;
966 }
967
968 static const struct attribute_group iqs5xx_group = {
969 .is_visible = iqs5xx_attr_is_visible,
970 .attrs = iqs5xx_attrs,
971 };
972 __ATTRIBUTE_GROUPS(iqs5xx);
973
iqs5xx_suspend(struct device * dev)974 static int iqs5xx_suspend(struct device *dev)
975 {
976 struct iqs5xx_private *iqs5xx = dev_get_drvdata(dev);
977 struct input_dev *input = iqs5xx->input;
978
979 if (!input || device_may_wakeup(dev))
980 return 0;
981
982 guard(mutex)(&input->mutex);
983 if (input_device_enabled(input))
984 return iqs5xx_set_state(iqs5xx->client, IQS5XX_SUSPEND);
985
986 return 0;
987 }
988
iqs5xx_resume(struct device * dev)989 static int iqs5xx_resume(struct device *dev)
990 {
991 struct iqs5xx_private *iqs5xx = dev_get_drvdata(dev);
992 struct input_dev *input = iqs5xx->input;
993
994 if (!input || device_may_wakeup(dev))
995 return 0;
996
997 guard(mutex)(&input->mutex);
998 if (input_device_enabled(input))
999 return iqs5xx_set_state(iqs5xx->client, IQS5XX_RESUME);
1000
1001 return 0;
1002 }
1003
1004 static DEFINE_SIMPLE_DEV_PM_OPS(iqs5xx_pm, iqs5xx_suspend, iqs5xx_resume);
1005
iqs5xx_probe(struct i2c_client * client)1006 static int iqs5xx_probe(struct i2c_client *client)
1007 {
1008 struct iqs5xx_private *iqs5xx;
1009 int error;
1010
1011 iqs5xx = devm_kzalloc(&client->dev, sizeof(*iqs5xx), GFP_KERNEL);
1012 if (!iqs5xx)
1013 return -ENOMEM;
1014
1015 i2c_set_clientdata(client, iqs5xx);
1016 iqs5xx->client = client;
1017
1018 iqs5xx->reset_gpio = devm_gpiod_get_optional(&client->dev,
1019 "reset", GPIOD_OUT_LOW);
1020 if (IS_ERR(iqs5xx->reset_gpio)) {
1021 error = PTR_ERR(iqs5xx->reset_gpio);
1022 dev_err(&client->dev, "Failed to request GPIO: %d\n", error);
1023 return error;
1024 }
1025
1026 mutex_init(&iqs5xx->lock);
1027
1028 error = iqs5xx_dev_init(client);
1029 if (error)
1030 return error;
1031
1032 error = devm_request_threaded_irq(&client->dev, client->irq,
1033 NULL, iqs5xx_irq, IRQF_ONESHOT,
1034 client->name, iqs5xx);
1035 if (error) {
1036 dev_err(&client->dev, "Failed to request IRQ: %d\n", error);
1037 return error;
1038 }
1039
1040 if (iqs5xx->input) {
1041 error = input_register_device(iqs5xx->input);
1042 if (error)
1043 dev_err(&client->dev,
1044 "Failed to register device: %d\n",
1045 error);
1046 }
1047
1048 return error;
1049 }
1050
1051 static const struct i2c_device_id iqs5xx_id[] = {
1052 { .name = "iqs550" },
1053 { .name = "iqs572" },
1054 { .name = "iqs525" },
1055 { }
1056 };
1057 MODULE_DEVICE_TABLE(i2c, iqs5xx_id);
1058
1059 static const struct of_device_id iqs5xx_of_match[] = {
1060 { .compatible = "azoteq,iqs550" },
1061 { .compatible = "azoteq,iqs572" },
1062 { .compatible = "azoteq,iqs525" },
1063 { }
1064 };
1065 MODULE_DEVICE_TABLE(of, iqs5xx_of_match);
1066
1067 static struct i2c_driver iqs5xx_i2c_driver = {
1068 .driver = {
1069 .name = "iqs5xx",
1070 .dev_groups = iqs5xx_groups,
1071 .of_match_table = iqs5xx_of_match,
1072 .pm = pm_sleep_ptr(&iqs5xx_pm),
1073 },
1074 .id_table = iqs5xx_id,
1075 .probe = iqs5xx_probe,
1076 };
1077 module_i2c_driver(iqs5xx_i2c_driver);
1078
1079 MODULE_AUTHOR("Jeff LaBundy <jeff@labundy.com>");
1080 MODULE_DESCRIPTION("Azoteq IQS550/572/525 Trackpad/Touchscreen Controller");
1081 MODULE_LICENSE("GPL");
1082