1 /* 2 * 3 * Intel Management Engine Interface (Intel MEI) Linux driver 4 * Copyright (c) 2003-2018, Intel Corporation. 5 * 6 * This program is free software; you can redistribute it and/or modify it 7 * under the terms and conditions of the GNU General Public License, 8 * version 2, as published by the Free Software Foundation. 9 * 10 * This program is distributed in the hope it will be useful, but WITHOUT 11 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or 12 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for 13 * more details. 14 * 15 */ 16 17 #include <linux/kernel.h> 18 #include <linux/sched.h> 19 #include <linux/module.h> 20 #include <linux/moduleparam.h> 21 #include <linux/device.h> 22 #include <linux/slab.h> 23 #include <linux/uuid.h> 24 25 #include <linux/mei_cl_bus.h> 26 27 #include "mei_dev.h" 28 #include "client.h" 29 30 #define MEI_UUID_NFC_INFO UUID_LE(0xd2de1625, 0x382d, 0x417d, \ 31 0x48, 0xa4, 0xef, 0xab, 0xba, 0x8a, 0x12, 0x06) 32 33 static const uuid_le mei_nfc_info_guid = MEI_UUID_NFC_INFO; 34 35 #define MEI_UUID_NFC_HCI UUID_LE(0x0bb17a78, 0x2a8e, 0x4c50, \ 36 0x94, 0xd4, 0x50, 0x26, 0x67, 0x23, 0x77, 0x5c) 37 38 #define MEI_UUID_WD UUID_LE(0x05B79A6F, 0x4628, 0x4D7F, \ 39 0x89, 0x9D, 0xA9, 0x15, 0x14, 0xCB, 0x32, 0xAB) 40 41 #define MEI_UUID_MKHIF_FIX UUID_LE(0x55213584, 0x9a29, 0x4916, \ 42 0xba, 0xdf, 0xf, 0xb7, 0xed, 0x68, 0x2a, 0xeb) 43 44 #define MEI_UUID_ANY NULL_UUID_LE 45 46 /** 47 * number_of_connections - determine whether an client be on the bus 48 * according number of connections 49 * We support only clients: 50 * 1. with single connection 51 * 2. and fixed clients (max_number_of_connections == 0) 52 * 53 * @cldev: me clients device 54 */ 55 static void number_of_connections(struct mei_cl_device *cldev) 56 { 57 dev_dbg(&cldev->dev, "running hook %s\n", __func__); 58 59 if (cldev->me_cl->props.max_number_of_connections > 1) 60 cldev->do_match = 0; 61 } 62 63 /** 64 * blacklist - blacklist a client from the bus 65 * 66 * @cldev: me clients device 67 */ 68 static void blacklist(struct mei_cl_device *cldev) 69 { 70 dev_dbg(&cldev->dev, "running hook %s\n", __func__); 71 72 cldev->do_match = 0; 73 } 74 75 #define OSTYPE_LINUX 2 76 struct mei_os_ver { 77 __le16 build; 78 __le16 reserved1; 79 u8 os_type; 80 u8 major; 81 u8 minor; 82 u8 reserved2; 83 } __packed; 84 85 #define MKHI_FEATURE_PTT 0x10 86 87 struct mkhi_rule_id { 88 __le16 rule_type; 89 u8 feature_id; 90 u8 reserved; 91 } __packed; 92 93 struct mkhi_fwcaps { 94 struct mkhi_rule_id id; 95 u8 len; 96 u8 data[0]; 97 } __packed; 98 99 struct mkhi_fw_ver_block { 100 u16 minor; 101 u8 major; 102 u8 platform; 103 u16 buildno; 104 u16 hotfix; 105 } __packed; 106 107 struct mkhi_fw_ver { 108 struct mkhi_fw_ver_block ver[MEI_MAX_FW_VER_BLOCKS]; 109 } __packed; 110 111 #define MKHI_FWCAPS_GROUP_ID 0x3 112 #define MKHI_FWCAPS_SET_OS_VER_APP_RULE_CMD 6 113 #define MKHI_GEN_GROUP_ID 0xFF 114 #define MKHI_GEN_GET_FW_VERSION_CMD 0x2 115 struct mkhi_msg_hdr { 116 u8 group_id; 117 u8 command; 118 u8 reserved; 119 u8 result; 120 } __packed; 121 122 struct mkhi_msg { 123 struct mkhi_msg_hdr hdr; 124 u8 data[0]; 125 } __packed; 126 127 #define MKHI_OSVER_BUF_LEN (sizeof(struct mkhi_msg_hdr) + \ 128 sizeof(struct mkhi_fwcaps) + \ 129 sizeof(struct mei_os_ver)) 130 static int mei_osver(struct mei_cl_device *cldev) 131 { 132 const size_t size = MKHI_OSVER_BUF_LEN; 133 char buf[MKHI_OSVER_BUF_LEN]; 134 struct mkhi_msg *req; 135 struct mkhi_fwcaps *fwcaps; 136 struct mei_os_ver *os_ver; 137 unsigned int mode = MEI_CL_IO_TX_BLOCKING | MEI_CL_IO_TX_INTERNAL; 138 139 memset(buf, 0, size); 140 141 req = (struct mkhi_msg *)buf; 142 req->hdr.group_id = MKHI_FWCAPS_GROUP_ID; 143 req->hdr.command = MKHI_FWCAPS_SET_OS_VER_APP_RULE_CMD; 144 145 fwcaps = (struct mkhi_fwcaps *)req->data; 146 147 fwcaps->id.rule_type = 0x0; 148 fwcaps->id.feature_id = MKHI_FEATURE_PTT; 149 fwcaps->len = sizeof(*os_ver); 150 os_ver = (struct mei_os_ver *)fwcaps->data; 151 os_ver->os_type = OSTYPE_LINUX; 152 153 return __mei_cl_send(cldev->cl, buf, size, mode); 154 } 155 156 #define MKHI_FWVER_BUF_LEN (sizeof(struct mkhi_msg_hdr) + \ 157 sizeof(struct mkhi_fw_ver)) 158 #define MKHI_FWVER_LEN(__num) (sizeof(struct mkhi_msg_hdr) + \ 159 sizeof(struct mkhi_fw_ver_block) * (__num)) 160 #define MKHI_RCV_TIMEOUT 500 /* receive timeout in msec */ 161 static int mei_fwver(struct mei_cl_device *cldev) 162 { 163 char buf[MKHI_FWVER_BUF_LEN]; 164 struct mkhi_msg *req; 165 struct mkhi_fw_ver *fwver; 166 int bytes_recv, ret, i; 167 168 memset(buf, 0, sizeof(buf)); 169 170 req = (struct mkhi_msg *)buf; 171 req->hdr.group_id = MKHI_GEN_GROUP_ID; 172 req->hdr.command = MKHI_GEN_GET_FW_VERSION_CMD; 173 174 ret = __mei_cl_send(cldev->cl, buf, sizeof(struct mkhi_msg_hdr), 175 MEI_CL_IO_TX_BLOCKING); 176 if (ret < 0) { 177 dev_err(&cldev->dev, "Could not send ReqFWVersion cmd\n"); 178 return ret; 179 } 180 181 ret = 0; 182 bytes_recv = __mei_cl_recv(cldev->cl, buf, sizeof(buf), 0, 183 MKHI_RCV_TIMEOUT); 184 if (bytes_recv < 0 || (size_t)bytes_recv < MKHI_FWVER_LEN(1)) { 185 /* 186 * Should be at least one version block, 187 * error out if nothing found 188 */ 189 dev_err(&cldev->dev, "Could not read FW version\n"); 190 return -EIO; 191 } 192 193 fwver = (struct mkhi_fw_ver *)req->data; 194 memset(cldev->bus->fw_ver, 0, sizeof(cldev->bus->fw_ver)); 195 for (i = 0; i < MEI_MAX_FW_VER_BLOCKS; i++) { 196 if ((size_t)bytes_recv < MKHI_FWVER_LEN(i + 1)) 197 break; 198 dev_dbg(&cldev->dev, "FW version%d %d:%d.%d.%d.%d\n", 199 i, fwver->ver[i].platform, 200 fwver->ver[i].major, fwver->ver[i].minor, 201 fwver->ver[i].hotfix, fwver->ver[i].buildno); 202 203 cldev->bus->fw_ver[i].platform = fwver->ver[i].platform; 204 cldev->bus->fw_ver[i].major = fwver->ver[i].major; 205 cldev->bus->fw_ver[i].minor = fwver->ver[i].minor; 206 cldev->bus->fw_ver[i].hotfix = fwver->ver[i].hotfix; 207 cldev->bus->fw_ver[i].buildno = fwver->ver[i].buildno; 208 } 209 210 return ret; 211 } 212 213 static void mei_mkhi_fix(struct mei_cl_device *cldev) 214 { 215 int ret; 216 217 ret = mei_cldev_enable(cldev); 218 if (ret) 219 return; 220 221 ret = mei_fwver(cldev); 222 if (ret < 0) 223 dev_err(&cldev->dev, "FW version command failed %d\n", ret); 224 225 if (cldev->bus->hbm_f_os_supported) { 226 ret = mei_osver(cldev); 227 if (ret < 0) 228 dev_err(&cldev->dev, "OS version command failed %d\n", 229 ret); 230 } 231 mei_cldev_disable(cldev); 232 } 233 234 /** 235 * mei_wd - wd client on the bus, change protocol version 236 * as the API has changed. 237 * 238 * @cldev: me clients device 239 */ 240 #if IS_ENABLED(CONFIG_INTEL_MEI_ME) 241 #include <linux/pci.h> 242 #include "hw-me-regs.h" 243 static void mei_wd(struct mei_cl_device *cldev) 244 { 245 struct pci_dev *pdev = to_pci_dev(cldev->dev.parent); 246 247 dev_dbg(&cldev->dev, "running hook %s\n", __func__); 248 if (pdev->device == MEI_DEV_ID_WPT_LP || 249 pdev->device == MEI_DEV_ID_SPT || 250 pdev->device == MEI_DEV_ID_SPT_H) 251 cldev->me_cl->props.protocol_version = 0x2; 252 253 cldev->do_match = 1; 254 } 255 #else 256 static inline void mei_wd(struct mei_cl_device *cldev) {} 257 #endif /* CONFIG_INTEL_MEI_ME */ 258 259 struct mei_nfc_cmd { 260 u8 command; 261 u8 status; 262 u16 req_id; 263 u32 reserved; 264 u16 data_size; 265 u8 sub_command; 266 u8 data[]; 267 } __packed; 268 269 struct mei_nfc_reply { 270 u8 command; 271 u8 status; 272 u16 req_id; 273 u32 reserved; 274 u16 data_size; 275 u8 sub_command; 276 u8 reply_status; 277 u8 data[]; 278 } __packed; 279 280 struct mei_nfc_if_version { 281 u8 radio_version_sw[3]; 282 u8 reserved[3]; 283 u8 radio_version_hw[3]; 284 u8 i2c_addr; 285 u8 fw_ivn; 286 u8 vendor_id; 287 u8 radio_type; 288 } __packed; 289 290 291 #define MEI_NFC_CMD_MAINTENANCE 0x00 292 #define MEI_NFC_SUBCMD_IF_VERSION 0x01 293 294 /* Vendors */ 295 #define MEI_NFC_VENDOR_INSIDE 0x00 296 #define MEI_NFC_VENDOR_NXP 0x01 297 298 /* Radio types */ 299 #define MEI_NFC_VENDOR_INSIDE_UREAD 0x00 300 #define MEI_NFC_VENDOR_NXP_PN544 0x01 301 302 /** 303 * mei_nfc_if_version - get NFC interface version 304 * 305 * @cl: host client (nfc info) 306 * @ver: NFC interface version to be filled in 307 * 308 * Return: 0 on success; < 0 otherwise 309 */ 310 static int mei_nfc_if_version(struct mei_cl *cl, 311 struct mei_nfc_if_version *ver) 312 { 313 struct mei_device *bus; 314 struct mei_nfc_cmd cmd = { 315 .command = MEI_NFC_CMD_MAINTENANCE, 316 .data_size = 1, 317 .sub_command = MEI_NFC_SUBCMD_IF_VERSION, 318 }; 319 struct mei_nfc_reply *reply = NULL; 320 size_t if_version_length; 321 int bytes_recv, ret; 322 323 bus = cl->dev; 324 325 WARN_ON(mutex_is_locked(&bus->device_lock)); 326 327 ret = __mei_cl_send(cl, (u8 *)&cmd, sizeof(struct mei_nfc_cmd), 328 MEI_CL_IO_TX_BLOCKING); 329 if (ret < 0) { 330 dev_err(bus->dev, "Could not send IF version cmd\n"); 331 return ret; 332 } 333 334 /* to be sure on the stack we alloc memory */ 335 if_version_length = sizeof(struct mei_nfc_reply) + 336 sizeof(struct mei_nfc_if_version); 337 338 reply = kzalloc(if_version_length, GFP_KERNEL); 339 if (!reply) 340 return -ENOMEM; 341 342 ret = 0; 343 bytes_recv = __mei_cl_recv(cl, (u8 *)reply, if_version_length, 0, 0); 344 if (bytes_recv < 0 || (size_t)bytes_recv < if_version_length) { 345 dev_err(bus->dev, "Could not read IF version\n"); 346 ret = -EIO; 347 goto err; 348 } 349 350 memcpy(ver, reply->data, sizeof(struct mei_nfc_if_version)); 351 352 dev_info(bus->dev, "NFC MEI VERSION: IVN 0x%x Vendor ID 0x%x Type 0x%x\n", 353 ver->fw_ivn, ver->vendor_id, ver->radio_type); 354 355 err: 356 kfree(reply); 357 return ret; 358 } 359 360 /** 361 * mei_nfc_radio_name - derive nfc radio name from the interface version 362 * 363 * @ver: NFC radio version 364 * 365 * Return: radio name string 366 */ 367 static const char *mei_nfc_radio_name(struct mei_nfc_if_version *ver) 368 { 369 370 if (ver->vendor_id == MEI_NFC_VENDOR_INSIDE) { 371 if (ver->radio_type == MEI_NFC_VENDOR_INSIDE_UREAD) 372 return "microread"; 373 } 374 375 if (ver->vendor_id == MEI_NFC_VENDOR_NXP) { 376 if (ver->radio_type == MEI_NFC_VENDOR_NXP_PN544) 377 return "pn544"; 378 } 379 380 return NULL; 381 } 382 383 /** 384 * mei_nfc - The nfc fixup function. The function retrieves nfc radio 385 * name and set is as device attribute so we can load 386 * the proper device driver for it 387 * 388 * @cldev: me client device (nfc) 389 */ 390 static void mei_nfc(struct mei_cl_device *cldev) 391 { 392 struct mei_device *bus; 393 struct mei_cl *cl; 394 struct mei_me_client *me_cl = NULL; 395 struct mei_nfc_if_version ver; 396 const char *radio_name = NULL; 397 int ret; 398 399 bus = cldev->bus; 400 401 dev_dbg(&cldev->dev, "running hook %s\n", __func__); 402 403 mutex_lock(&bus->device_lock); 404 /* we need to connect to INFO GUID */ 405 cl = mei_cl_alloc_linked(bus); 406 if (IS_ERR(cl)) { 407 ret = PTR_ERR(cl); 408 cl = NULL; 409 dev_err(bus->dev, "nfc hook alloc failed %d\n", ret); 410 goto out; 411 } 412 413 me_cl = mei_me_cl_by_uuid(bus, &mei_nfc_info_guid); 414 if (!me_cl) { 415 ret = -ENOTTY; 416 dev_err(bus->dev, "Cannot find nfc info %d\n", ret); 417 goto out; 418 } 419 420 ret = mei_cl_connect(cl, me_cl, NULL); 421 if (ret < 0) { 422 dev_err(&cldev->dev, "Can't connect to the NFC INFO ME ret = %d\n", 423 ret); 424 goto out; 425 } 426 427 mutex_unlock(&bus->device_lock); 428 429 ret = mei_nfc_if_version(cl, &ver); 430 if (ret) 431 goto disconnect; 432 433 radio_name = mei_nfc_radio_name(&ver); 434 435 if (!radio_name) { 436 ret = -ENOENT; 437 dev_err(&cldev->dev, "Can't get the NFC interface version ret = %d\n", 438 ret); 439 goto disconnect; 440 } 441 442 dev_dbg(bus->dev, "nfc radio %s\n", radio_name); 443 strlcpy(cldev->name, radio_name, sizeof(cldev->name)); 444 445 disconnect: 446 mutex_lock(&bus->device_lock); 447 if (mei_cl_disconnect(cl) < 0) 448 dev_err(bus->dev, "Can't disconnect the NFC INFO ME\n"); 449 450 mei_cl_flush_queues(cl, NULL); 451 452 out: 453 mei_cl_unlink(cl); 454 mutex_unlock(&bus->device_lock); 455 mei_me_cl_put(me_cl); 456 kfree(cl); 457 458 if (ret) 459 cldev->do_match = 0; 460 461 dev_dbg(bus->dev, "end of fixup match = %d\n", cldev->do_match); 462 } 463 464 #define MEI_FIXUP(_uuid, _hook) { _uuid, _hook } 465 466 static struct mei_fixup { 467 468 const uuid_le uuid; 469 void (*hook)(struct mei_cl_device *cldev); 470 } mei_fixups[] = { 471 MEI_FIXUP(MEI_UUID_ANY, number_of_connections), 472 MEI_FIXUP(MEI_UUID_NFC_INFO, blacklist), 473 MEI_FIXUP(MEI_UUID_NFC_HCI, mei_nfc), 474 MEI_FIXUP(MEI_UUID_WD, mei_wd), 475 MEI_FIXUP(MEI_UUID_MKHIF_FIX, mei_mkhi_fix), 476 }; 477 478 /** 479 * mei_cldev_fixup - run fixup handlers 480 * 481 * @cldev: me client device 482 */ 483 void mei_cl_bus_dev_fixup(struct mei_cl_device *cldev) 484 { 485 struct mei_fixup *f; 486 const uuid_le *uuid = mei_me_cl_uuid(cldev->me_cl); 487 size_t i; 488 489 for (i = 0; i < ARRAY_SIZE(mei_fixups); i++) { 490 491 f = &mei_fixups[i]; 492 if (uuid_le_cmp(f->uuid, MEI_UUID_ANY) == 0 || 493 uuid_le_cmp(f->uuid, *uuid) == 0) 494 f->hook(cldev); 495 } 496 } 497 498