1 // SPDX-License-Identifier: GPL-2.0
3 * Copyright (c) 2015-2018, Intel Corporation.
6 #define pr_fmt(fmt) "kcs-bmc: " fmt
8 #include <linux/errno.h>
10 #include <linux/ipmi_bmc.h>
11 #include <linux/list.h>
12 #include <linux/miscdevice.h>
13 #include <linux/module.h>
14 #include <linux/mutex.h>
15 #include <linux/platform_device.h>
16 #include <linux/poll.h>
17 #include <linux/sched.h>
18 #include <linux/slab.h>
20 #include "kcs_bmc_client.h"
22 /* Different phases of the KCS BMC module.
24 * BMC should not be expecting nor sending any data.
25 * KCS_PHASE_WRITE_START:
26 * BMC is receiving a WRITE_START command from system software.
27 * KCS_PHASE_WRITE_DATA:
28 * BMC is receiving a data byte from system software.
29 * KCS_PHASE_WRITE_END_CMD:
30 * BMC is waiting a last data byte from system software.
31 * KCS_PHASE_WRITE_DONE:
32 * BMC has received the whole request from system software.
33 * KCS_PHASE_WAIT_READ:
34 * BMC is waiting the response from the upper IPMI service.
36 * BMC is transferring the response to system software.
37 * KCS_PHASE_ABORT_ERROR1:
38 * BMC is waiting error status request from system software.
39 * KCS_PHASE_ABORT_ERROR2:
40 * BMC is waiting for idle status afer error from system software.
42 * BMC has detected a protocol violation at the interface level.
44 enum kcs_ipmi_phases
{
47 KCS_PHASE_WRITE_START
,
49 KCS_PHASE_WRITE_END_CMD
,
55 KCS_PHASE_ABORT_ERROR1
,
56 KCS_PHASE_ABORT_ERROR2
,
60 /* IPMI 2.0 - Table 9-4, KCS Interface Status Codes */
61 enum kcs_ipmi_errors
{
63 KCS_ABORTED_BY_COMMAND
= 0x01,
64 KCS_ILLEGAL_CONTROL_CODE
= 0x02,
65 KCS_LENGTH_ERROR
= 0x06,
66 KCS_UNSPECIFIED_ERROR
= 0xFF
70 struct list_head entry
;
72 struct kcs_bmc_client client
;
76 enum kcs_ipmi_phases phase
;
77 enum kcs_ipmi_errors error
;
79 wait_queue_head_t queue
;
91 struct miscdevice miscdev
;
94 #define DEVICE_NAME "ipmi-kcs"
96 #define KCS_MSG_BUFSIZ 1000
98 #define KCS_ZERO_DATA 0
100 /* IPMI 2.0 - Table 9-1, KCS Interface Status Register Bits */
101 #define KCS_STATUS_STATE(state) (state << 6)
102 #define KCS_STATUS_STATE_MASK GENMASK(7, 6)
103 #define KCS_STATUS_CMD_DAT BIT(3)
104 #define KCS_STATUS_SMS_ATN BIT(2)
105 #define KCS_STATUS_IBF BIT(1)
106 #define KCS_STATUS_OBF BIT(0)
108 /* IPMI 2.0 - Table 9-2, KCS Interface State Bits */
116 /* IPMI 2.0 - Table 9-3, KCS Interface Control Codes */
117 #define KCS_CMD_GET_STATUS_ABORT 0x60
118 #define KCS_CMD_WRITE_START 0x61
119 #define KCS_CMD_WRITE_END 0x62
120 #define KCS_CMD_READ_BYTE 0x68
122 static inline void set_state(struct kcs_bmc_ipmi
*priv
, u8 state
)
124 kcs_bmc_update_status(priv
->client
.dev
, KCS_STATUS_STATE_MASK
, KCS_STATUS_STATE(state
));
127 static void kcs_bmc_ipmi_force_abort(struct kcs_bmc_ipmi
*priv
)
129 set_state(priv
, ERROR_STATE
);
130 kcs_bmc_read_data(priv
->client
.dev
);
131 kcs_bmc_write_data(priv
->client
.dev
, KCS_ZERO_DATA
);
133 priv
->phase
= KCS_PHASE_ERROR
;
134 priv
->data_in_avail
= false;
135 priv
->data_in_idx
= 0;
138 static void kcs_bmc_ipmi_handle_data(struct kcs_bmc_ipmi
*priv
)
140 struct kcs_bmc_device
*dev
;
143 dev
= priv
->client
.dev
;
145 switch (priv
->phase
) {
146 case KCS_PHASE_WRITE_START
:
147 priv
->phase
= KCS_PHASE_WRITE_DATA
;
150 case KCS_PHASE_WRITE_DATA
:
151 if (priv
->data_in_idx
< KCS_MSG_BUFSIZ
) {
152 set_state(priv
, WRITE_STATE
);
153 kcs_bmc_write_data(dev
, KCS_ZERO_DATA
);
154 priv
->data_in
[priv
->data_in_idx
++] = kcs_bmc_read_data(dev
);
156 kcs_bmc_ipmi_force_abort(priv
);
157 priv
->error
= KCS_LENGTH_ERROR
;
161 case KCS_PHASE_WRITE_END_CMD
:
162 if (priv
->data_in_idx
< KCS_MSG_BUFSIZ
) {
163 set_state(priv
, READ_STATE
);
164 priv
->data_in
[priv
->data_in_idx
++] = kcs_bmc_read_data(dev
);
165 priv
->phase
= KCS_PHASE_WRITE_DONE
;
166 priv
->data_in_avail
= true;
167 wake_up_interruptible(&priv
->queue
);
169 kcs_bmc_ipmi_force_abort(priv
);
170 priv
->error
= KCS_LENGTH_ERROR
;
175 if (priv
->data_out_idx
== priv
->data_out_len
)
176 set_state(priv
, IDLE_STATE
);
178 data
= kcs_bmc_read_data(dev
);
179 if (data
!= KCS_CMD_READ_BYTE
) {
180 set_state(priv
, ERROR_STATE
);
181 kcs_bmc_write_data(dev
, KCS_ZERO_DATA
);
185 if (priv
->data_out_idx
== priv
->data_out_len
) {
186 kcs_bmc_write_data(dev
, KCS_ZERO_DATA
);
187 priv
->phase
= KCS_PHASE_IDLE
;
191 kcs_bmc_write_data(dev
, priv
->data_out
[priv
->data_out_idx
++]);
194 case KCS_PHASE_ABORT_ERROR1
:
195 set_state(priv
, READ_STATE
);
196 kcs_bmc_read_data(dev
);
197 kcs_bmc_write_data(dev
, priv
->error
);
198 priv
->phase
= KCS_PHASE_ABORT_ERROR2
;
201 case KCS_PHASE_ABORT_ERROR2
:
202 set_state(priv
, IDLE_STATE
);
203 kcs_bmc_read_data(dev
);
204 kcs_bmc_write_data(dev
, KCS_ZERO_DATA
);
205 priv
->phase
= KCS_PHASE_IDLE
;
209 kcs_bmc_ipmi_force_abort(priv
);
214 static void kcs_bmc_ipmi_handle_cmd(struct kcs_bmc_ipmi
*priv
)
218 set_state(priv
, WRITE_STATE
);
219 kcs_bmc_write_data(priv
->client
.dev
, KCS_ZERO_DATA
);
221 cmd
= kcs_bmc_read_data(priv
->client
.dev
);
223 case KCS_CMD_WRITE_START
:
224 priv
->phase
= KCS_PHASE_WRITE_START
;
225 priv
->error
= KCS_NO_ERROR
;
226 priv
->data_in_avail
= false;
227 priv
->data_in_idx
= 0;
230 case KCS_CMD_WRITE_END
:
231 if (priv
->phase
!= KCS_PHASE_WRITE_DATA
) {
232 kcs_bmc_ipmi_force_abort(priv
);
236 priv
->phase
= KCS_PHASE_WRITE_END_CMD
;
239 case KCS_CMD_GET_STATUS_ABORT
:
240 if (priv
->error
== KCS_NO_ERROR
)
241 priv
->error
= KCS_ABORTED_BY_COMMAND
;
243 priv
->phase
= KCS_PHASE_ABORT_ERROR1
;
244 priv
->data_in_avail
= false;
245 priv
->data_in_idx
= 0;
249 kcs_bmc_ipmi_force_abort(priv
);
250 priv
->error
= KCS_ILLEGAL_CONTROL_CODE
;
255 static inline struct kcs_bmc_ipmi
*client_to_kcs_bmc_ipmi(struct kcs_bmc_client
*client
)
257 return container_of(client
, struct kcs_bmc_ipmi
, client
);
260 static irqreturn_t
kcs_bmc_ipmi_event(struct kcs_bmc_client
*client
)
262 struct kcs_bmc_ipmi
*priv
;
266 priv
= client_to_kcs_bmc_ipmi(client
);
270 spin_lock(&priv
->lock
);
272 status
= kcs_bmc_read_status(client
->dev
);
273 if (status
& KCS_STATUS_IBF
) {
274 if (status
& KCS_STATUS_CMD_DAT
)
275 kcs_bmc_ipmi_handle_cmd(priv
);
277 kcs_bmc_ipmi_handle_data(priv
);
284 spin_unlock(&priv
->lock
);
289 static const struct kcs_bmc_client_ops kcs_bmc_ipmi_client_ops
= {
290 .event
= kcs_bmc_ipmi_event
,
293 static inline struct kcs_bmc_ipmi
*to_kcs_bmc(struct file
*filp
)
295 return container_of(filp
->private_data
, struct kcs_bmc_ipmi
, miscdev
);
298 static int kcs_bmc_ipmi_open(struct inode
*inode
, struct file
*filp
)
300 struct kcs_bmc_ipmi
*priv
= to_kcs_bmc(filp
);
302 return kcs_bmc_enable_device(priv
->client
.dev
, &priv
->client
);
305 static __poll_t
kcs_bmc_ipmi_poll(struct file
*filp
, poll_table
*wait
)
307 struct kcs_bmc_ipmi
*priv
= to_kcs_bmc(filp
);
310 poll_wait(filp
, &priv
->queue
, wait
);
312 spin_lock_irq(&priv
->lock
);
313 if (priv
->data_in_avail
)
315 spin_unlock_irq(&priv
->lock
);
320 static ssize_t
kcs_bmc_ipmi_read(struct file
*filp
, char __user
*buf
,
321 size_t count
, loff_t
*ppos
)
323 struct kcs_bmc_ipmi
*priv
= to_kcs_bmc(filp
);
328 if (!(filp
->f_flags
& O_NONBLOCK
))
329 wait_event_interruptible(priv
->queue
,
330 priv
->data_in_avail
);
332 mutex_lock(&priv
->mutex
);
334 spin_lock_irq(&priv
->lock
);
335 data_avail
= priv
->data_in_avail
;
337 data_len
= priv
->data_in_idx
;
338 memcpy(priv
->kbuffer
, priv
->data_in
, data_len
);
340 spin_unlock_irq(&priv
->lock
);
347 if (count
< data_len
) {
348 pr_err("channel=%u with too large data : %zu\n",
349 priv
->client
.dev
->channel
, data_len
);
351 spin_lock_irq(&priv
->lock
);
352 kcs_bmc_ipmi_force_abort(priv
);
353 spin_unlock_irq(&priv
->lock
);
359 if (copy_to_user(buf
, priv
->kbuffer
, data_len
)) {
366 spin_lock_irq(&priv
->lock
);
367 if (priv
->phase
== KCS_PHASE_WRITE_DONE
) {
368 priv
->phase
= KCS_PHASE_WAIT_READ
;
369 priv
->data_in_avail
= false;
370 priv
->data_in_idx
= 0;
374 spin_unlock_irq(&priv
->lock
);
377 mutex_unlock(&priv
->mutex
);
382 static ssize_t
kcs_bmc_ipmi_write(struct file
*filp
, const char __user
*buf
,
383 size_t count
, loff_t
*ppos
)
385 struct kcs_bmc_ipmi
*priv
= to_kcs_bmc(filp
);
388 /* a minimum response size '3' : netfn + cmd + ccode */
389 if (count
< 3 || count
> KCS_MSG_BUFSIZ
)
392 mutex_lock(&priv
->mutex
);
394 if (copy_from_user(priv
->kbuffer
, buf
, count
)) {
399 spin_lock_irq(&priv
->lock
);
400 if (priv
->phase
== KCS_PHASE_WAIT_READ
) {
401 priv
->phase
= KCS_PHASE_READ
;
402 priv
->data_out_idx
= 1;
403 priv
->data_out_len
= count
;
404 memcpy(priv
->data_out
, priv
->kbuffer
, count
);
405 kcs_bmc_write_data(priv
->client
.dev
, priv
->data_out
[0]);
410 spin_unlock_irq(&priv
->lock
);
413 mutex_unlock(&priv
->mutex
);
418 static long kcs_bmc_ipmi_ioctl(struct file
*filp
, unsigned int cmd
,
421 struct kcs_bmc_ipmi
*priv
= to_kcs_bmc(filp
);
424 spin_lock_irq(&priv
->lock
);
427 case IPMI_BMC_IOCTL_SET_SMS_ATN
:
428 kcs_bmc_update_status(priv
->client
.dev
, KCS_STATUS_SMS_ATN
, KCS_STATUS_SMS_ATN
);
431 case IPMI_BMC_IOCTL_CLEAR_SMS_ATN
:
432 kcs_bmc_update_status(priv
->client
.dev
, KCS_STATUS_SMS_ATN
, 0);
435 case IPMI_BMC_IOCTL_FORCE_ABORT
:
436 kcs_bmc_ipmi_force_abort(priv
);
444 spin_unlock_irq(&priv
->lock
);
449 static int kcs_bmc_ipmi_release(struct inode
*inode
, struct file
*filp
)
451 struct kcs_bmc_ipmi
*priv
= to_kcs_bmc(filp
);
453 kcs_bmc_ipmi_force_abort(priv
);
454 kcs_bmc_disable_device(priv
->client
.dev
, &priv
->client
);
459 static const struct file_operations kcs_bmc_ipmi_fops
= {
460 .owner
= THIS_MODULE
,
461 .open
= kcs_bmc_ipmi_open
,
462 .read
= kcs_bmc_ipmi_read
,
463 .write
= kcs_bmc_ipmi_write
,
464 .release
= kcs_bmc_ipmi_release
,
465 .poll
= kcs_bmc_ipmi_poll
,
466 .unlocked_ioctl
= kcs_bmc_ipmi_ioctl
,
469 static DEFINE_SPINLOCK(kcs_bmc_ipmi_instances_lock
);
470 static LIST_HEAD(kcs_bmc_ipmi_instances
);
472 static int kcs_bmc_ipmi_add_device(struct kcs_bmc_device
*kcs_bmc
)
474 struct kcs_bmc_ipmi
*priv
;
477 priv
= devm_kzalloc(kcs_bmc
->dev
, sizeof(*priv
), GFP_KERNEL
);
481 spin_lock_init(&priv
->lock
);
482 mutex_init(&priv
->mutex
);
484 init_waitqueue_head(&priv
->queue
);
486 priv
->client
.dev
= kcs_bmc
;
487 priv
->client
.ops
= &kcs_bmc_ipmi_client_ops
;
488 priv
->data_in
= devm_kmalloc(kcs_bmc
->dev
, KCS_MSG_BUFSIZ
, GFP_KERNEL
);
489 priv
->data_out
= devm_kmalloc(kcs_bmc
->dev
, KCS_MSG_BUFSIZ
, GFP_KERNEL
);
490 priv
->kbuffer
= devm_kmalloc(kcs_bmc
->dev
, KCS_MSG_BUFSIZ
, GFP_KERNEL
);
492 priv
->miscdev
.minor
= MISC_DYNAMIC_MINOR
;
493 priv
->miscdev
.name
= devm_kasprintf(kcs_bmc
->dev
, GFP_KERNEL
, "%s%u", DEVICE_NAME
,
495 if (!priv
->data_in
|| !priv
->data_out
|| !priv
->kbuffer
|| !priv
->miscdev
.name
)
498 priv
->miscdev
.fops
= &kcs_bmc_ipmi_fops
;
500 rc
= misc_register(&priv
->miscdev
);
502 dev_err(kcs_bmc
->dev
, "Unable to register device: %d\n", rc
);
506 spin_lock_irq(&kcs_bmc_ipmi_instances_lock
);
507 list_add(&priv
->entry
, &kcs_bmc_ipmi_instances
);
508 spin_unlock_irq(&kcs_bmc_ipmi_instances_lock
);
510 dev_info(kcs_bmc
->dev
, "Initialised IPMI client for channel %d", kcs_bmc
->channel
);
515 static int kcs_bmc_ipmi_remove_device(struct kcs_bmc_device
*kcs_bmc
)
517 struct kcs_bmc_ipmi
*priv
= NULL
, *pos
;
519 spin_lock_irq(&kcs_bmc_ipmi_instances_lock
);
520 list_for_each_entry(pos
, &kcs_bmc_ipmi_instances
, entry
) {
521 if (pos
->client
.dev
== kcs_bmc
) {
523 list_del(&pos
->entry
);
527 spin_unlock_irq(&kcs_bmc_ipmi_instances_lock
);
532 misc_deregister(&priv
->miscdev
);
533 kcs_bmc_disable_device(priv
->client
.dev
, &priv
->client
);
534 devm_kfree(kcs_bmc
->dev
, priv
->kbuffer
);
535 devm_kfree(kcs_bmc
->dev
, priv
->data_out
);
536 devm_kfree(kcs_bmc
->dev
, priv
->data_in
);
537 devm_kfree(kcs_bmc
->dev
, priv
);
542 static const struct kcs_bmc_driver_ops kcs_bmc_ipmi_driver_ops
= {
543 .add_device
= kcs_bmc_ipmi_add_device
,
544 .remove_device
= kcs_bmc_ipmi_remove_device
,
547 static struct kcs_bmc_driver kcs_bmc_ipmi_driver
= {
548 .ops
= &kcs_bmc_ipmi_driver_ops
,
551 static int __init
kcs_bmc_ipmi_init(void)
553 kcs_bmc_register_driver(&kcs_bmc_ipmi_driver
);
557 module_init(kcs_bmc_ipmi_init
);
559 static void __exit
kcs_bmc_ipmi_exit(void)
561 kcs_bmc_unregister_driver(&kcs_bmc_ipmi_driver
);
563 module_exit(kcs_bmc_ipmi_exit
);
565 MODULE_LICENSE("GPL v2");
566 MODULE_AUTHOR("Haiyue Wang <haiyue.wang@linux.intel.com>");
567 MODULE_AUTHOR("Andrew Jeffery <andrew@aj.id.au>");
568 MODULE_DESCRIPTION("KCS BMC to handle the IPMI request from system software");