1 // SPDX-License-Identifier: GPL-2.0-only
5 * Copyright (c) 2017-2020, Silicon Laboratories, Inc.
6 * Copyright (c) 2010, ST-Ericsson
8 #include <linux/firmware.h>
9 #include <linux/slab.h>
11 #include <linux/bitfield.h>
17 /* Addresses below are in SRAM area */
18 #define WFX_DNLD_FIFO 0x09004000
19 #define DNLD_BLOCK_SIZE 0x0400
20 #define DNLD_FIFO_SIZE 0x8000 /* (32 * DNLD_BLOCK_SIZE) */
21 /* Download Control Area (DCA) */
22 #define WFX_DCA_IMAGE_SIZE 0x0900C000
23 #define WFX_DCA_PUT 0x0900C004
24 #define WFX_DCA_GET 0x0900C008
25 #define WFX_DCA_HOST_STATUS 0x0900C00C
26 #define HOST_READY 0x87654321
27 #define HOST_INFO_READ 0xA753BD99
28 #define HOST_UPLOAD_PENDING 0xABCDDCBA
29 #define HOST_UPLOAD_COMPLETE 0xD4C64A99
30 #define HOST_OK_TO_JUMP 0x174FC882
31 #define WFX_DCA_NCP_STATUS 0x0900C010
32 #define NCP_NOT_READY 0x12345678
33 #define NCP_READY 0x87654321
34 #define NCP_INFO_READY 0xBD53EF99
35 #define NCP_DOWNLOAD_PENDING 0xABCDDCBA
36 #define NCP_DOWNLOAD_COMPLETE 0xCAFEFECA
37 #define NCP_AUTH_OK 0xD4C64A99
38 #define NCP_AUTH_FAIL 0x174FC882
39 #define NCP_PUB_KEY_RDY 0x7AB41D19
40 #define WFX_DCA_FW_SIGNATURE 0x0900C014
41 #define FW_SIGNATURE_SIZE 0x40
42 #define WFX_DCA_FW_HASH 0x0900C054
43 #define FW_HASH_SIZE 0x08
44 #define WFX_DCA_FW_VERSION 0x0900C05C
45 #define FW_VERSION_SIZE 0x04
46 #define WFX_DCA_RESERVED 0x0900C060
47 #define DCA_RESERVED_SIZE 0x20
48 #define WFX_STATUS_INFO 0x0900C080
49 #define WFX_BOOTLOADER_LABEL 0x0900C084
50 #define BOOTLOADER_LABEL_SIZE 0x3C
51 #define WFX_PTE_INFO 0x0900C0C0
52 #define PTE_INFO_KEYSET_IDX 0x0D
53 #define PTE_INFO_SIZE 0x10
54 #define WFX_ERR_INFO 0x0900C0D0
55 #define ERR_INVALID_SEC_TYPE 0x05
56 #define ERR_SIG_VERIF_FAILED 0x0F
57 #define ERR_AES_CTRL_KEY 0x10
58 #define ERR_ECC_PUB_KEY 0x11
59 #define ERR_MAC_KEY 0x18
61 #define DCA_TIMEOUT 50 /* milliseconds */
62 #define WAKEUP_TIMEOUT 200 /* milliseconds */
64 static const char * const fwio_errors
[] = {
65 [ERR_INVALID_SEC_TYPE
] = "Invalid section type or wrong encryption",
66 [ERR_SIG_VERIF_FAILED
] = "Signature verification failed",
67 [ERR_AES_CTRL_KEY
] = "AES control key not initialized",
68 [ERR_ECC_PUB_KEY
] = "ECC public key not initialized",
69 [ERR_MAC_KEY
] = "MAC key not initialized",
72 /* request_firmware() allocate data using vmalloc(). It is not compatible with underlying hardware
73 * that use DMA. Function below detect this case and allocate a bounce buffer if necessary.
75 * Notice that, in doubt, you can enable CONFIG_DEBUG_SG to ask kernel to detect this problem at
76 * runtime (else, kernel silently fail).
78 * NOTE: it may also be possible to use 'pages' from struct firmware and avoid bounce buffer
80 static int wfx_sram_write_dma_safe(struct wfx_dev
*wdev
, u32 addr
, const u8
*buf
, size_t len
)
85 if (!virt_addr_valid(buf
)) {
86 tmp
= kmemdup(buf
, len
, GFP_KERNEL
);
92 ret
= wfx_sram_buf_write(wdev
, addr
, tmp
, len
);
98 static int get_firmware(struct wfx_dev
*wdev
, u32 keyset_chip
,
99 const struct firmware
**fw
, int *file_offset
)
106 snprintf(filename
, sizeof(filename
), "%s_%02X.sec",
107 wdev
->pdata
.file_fw
, keyset_chip
);
108 ret
= firmware_request_nowarn(fw
, filename
, wdev
->dev
);
110 dev_info(wdev
->dev
, "can't load %s, falling back to %s.sec\n",
111 filename
, wdev
->pdata
.file_fw
);
112 snprintf(filename
, sizeof(filename
), "%s.sec", wdev
->pdata
.file_fw
);
113 ret
= request_firmware(fw
, filename
, wdev
->dev
);
115 dev_err(wdev
->dev
, "can't load %s\n", filename
);
122 if (memcmp(data
, "KEYSET", 6) != 0) {
123 /* Legacy firmware format */
128 keyset_file
= (hex_to_bin(data
[6]) * 16) | hex_to_bin(data
[7]);
129 if (keyset_file
< 0) {
130 dev_err(wdev
->dev
, "%s corrupted\n", filename
);
131 release_firmware(*fw
);
136 if (keyset_file
!= keyset_chip
) {
137 dev_err(wdev
->dev
, "firmware keyset is incompatible with chip (file: 0x%02X, chip: 0x%02X)\n",
138 keyset_file
, keyset_chip
);
139 release_firmware(*fw
);
143 wdev
->keyset
= keyset_file
;
147 static int wait_ncp_status(struct wfx_dev
*wdev
, u32 status
)
155 ret
= wfx_sram_reg_read(wdev
, WFX_DCA_NCP_STATUS
, ®
);
161 if (ktime_after(now
, ktime_add_ms(start
, DCA_TIMEOUT
)))
164 if (ktime_compare(now
, start
))
165 dev_dbg(wdev
->dev
, "chip answer after %lldus\n", ktime_us_delta(now
, start
));
167 dev_dbg(wdev
->dev
, "chip answer immediately\n");
171 static int upload_firmware(struct wfx_dev
*wdev
, const u8
*data
, size_t len
)
174 u32 offs
, bytes_done
= 0;
177 if (len
% DNLD_BLOCK_SIZE
) {
178 dev_err(wdev
->dev
, "firmware size is not aligned. Buffer overrun will occur\n");
186 if (offs
+ DNLD_BLOCK_SIZE
- bytes_done
< DNLD_FIFO_SIZE
)
188 if (ktime_after(now
, ktime_add_ms(start
, DCA_TIMEOUT
)))
190 ret
= wfx_sram_reg_read(wdev
, WFX_DCA_GET
, &bytes_done
);
194 if (ktime_compare(now
, start
))
195 dev_dbg(wdev
->dev
, "answer after %lldus\n", ktime_us_delta(now
, start
));
197 ret
= wfx_sram_write_dma_safe(wdev
, WFX_DNLD_FIFO
+ (offs
% DNLD_FIFO_SIZE
),
198 data
+ offs
, DNLD_BLOCK_SIZE
);
202 /* The device seems to not support writing 0 in this register during first loop */
203 offs
+= DNLD_BLOCK_SIZE
;
204 ret
= wfx_sram_reg_write(wdev
, WFX_DCA_PUT
, offs
);
211 static void print_boot_status(struct wfx_dev
*wdev
)
215 wfx_sram_reg_read(wdev
, WFX_STATUS_INFO
, ®
);
216 if (reg
== 0x12345678)
218 wfx_sram_reg_read(wdev
, WFX_ERR_INFO
, ®
);
219 if (reg
< ARRAY_SIZE(fwio_errors
) && fwio_errors
[reg
])
220 dev_info(wdev
->dev
, "secure boot: %s\n", fwio_errors
[reg
]);
222 dev_info(wdev
->dev
, "secure boot: Error %#02x\n", reg
);
225 static int load_firmware_secure(struct wfx_dev
*wdev
)
227 const struct firmware
*fw
= NULL
;
234 BUILD_BUG_ON(PTE_INFO_SIZE
> BOOTLOADER_LABEL_SIZE
);
235 buf
= kmalloc(BOOTLOADER_LABEL_SIZE
+ 1, GFP_KERNEL
);
239 wfx_sram_reg_write(wdev
, WFX_DCA_HOST_STATUS
, HOST_READY
);
240 ret
= wait_ncp_status(wdev
, NCP_INFO_READY
);
244 wfx_sram_buf_read(wdev
, WFX_BOOTLOADER_LABEL
, buf
, BOOTLOADER_LABEL_SIZE
);
245 buf
[BOOTLOADER_LABEL_SIZE
] = 0;
246 dev_dbg(wdev
->dev
, "bootloader: \"%s\"\n", buf
);
248 wfx_sram_buf_read(wdev
, WFX_PTE_INFO
, buf
, PTE_INFO_SIZE
);
249 ret
= get_firmware(wdev
, buf
[PTE_INFO_KEYSET_IDX
], &fw
, &fw_offset
);
252 header_size
= fw_offset
+ FW_SIGNATURE_SIZE
+ FW_HASH_SIZE
;
254 wfx_sram_reg_write(wdev
, WFX_DCA_HOST_STATUS
, HOST_INFO_READ
);
255 ret
= wait_ncp_status(wdev
, NCP_READY
);
259 wfx_sram_reg_write(wdev
, WFX_DNLD_FIFO
, 0xFFFFFFFF); /* Fifo init */
260 wfx_sram_write_dma_safe(wdev
, WFX_DCA_FW_VERSION
, "\x01\x00\x00\x00", FW_VERSION_SIZE
);
261 wfx_sram_write_dma_safe(wdev
, WFX_DCA_FW_SIGNATURE
, fw
->data
+ fw_offset
,
263 wfx_sram_write_dma_safe(wdev
, WFX_DCA_FW_HASH
, fw
->data
+ fw_offset
+ FW_SIGNATURE_SIZE
,
265 wfx_sram_reg_write(wdev
, WFX_DCA_IMAGE_SIZE
, fw
->size
- header_size
);
266 wfx_sram_reg_write(wdev
, WFX_DCA_HOST_STATUS
, HOST_UPLOAD_PENDING
);
267 ret
= wait_ncp_status(wdev
, NCP_DOWNLOAD_PENDING
);
272 ret
= upload_firmware(wdev
, fw
->data
+ header_size
, fw
->size
- header_size
);
275 dev_dbg(wdev
->dev
, "firmware load after %lldus\n",
276 ktime_us_delta(ktime_get(), start
));
278 wfx_sram_reg_write(wdev
, WFX_DCA_HOST_STATUS
, HOST_UPLOAD_COMPLETE
);
279 ret
= wait_ncp_status(wdev
, NCP_AUTH_OK
);
280 /* Legacy ROM support */
282 ret
= wait_ncp_status(wdev
, NCP_PUB_KEY_RDY
);
285 wfx_sram_reg_write(wdev
, WFX_DCA_HOST_STATUS
, HOST_OK_TO_JUMP
);
289 release_firmware(fw
);
291 print_boot_status(wdev
);
295 static int init_gpr(struct wfx_dev
*wdev
)
298 static const struct {
309 for (i
= 0; i
< ARRAY_SIZE(gpr_init
); i
++) {
310 ret
= wfx_igpr_reg_write(wdev
, gpr_init
[i
].index
, gpr_init
[i
].value
);
313 dev_dbg(wdev
->dev
, " index %02x: %08x\n", gpr_init
[i
].index
, gpr_init
[i
].value
);
318 int wfx_init_device(struct wfx_dev
*wdev
)
321 int hw_revision
, hw_type
;
322 int wakeup_timeout
= 50; /* ms */
326 reg
= CFG_DIRECT_ACCESS_MODE
| CFG_CPU_RESET
| CFG_BYTE_ORDER_ABCD
;
327 if (wdev
->pdata
.use_rising_clk
)
328 reg
|= CFG_CLK_RISE_EDGE
;
329 ret
= wfx_config_reg_write(wdev
, reg
);
331 dev_err(wdev
->dev
, "bus returned an error during first write access. Host configuration error?\n");
335 ret
= wfx_config_reg_read(wdev
, ®
);
337 dev_err(wdev
->dev
, "bus returned an error during first read access. Bus configuration error?\n");
340 if (reg
== 0 || reg
== ~0) {
341 dev_err(wdev
->dev
, "chip mute. Bus configuration error or chip wasn't reset?\n");
344 dev_dbg(wdev
->dev
, "initial config register value: %08x\n", reg
);
346 hw_revision
= FIELD_GET(CFG_DEVICE_ID_MAJOR
, reg
);
347 if (hw_revision
== 0) {
348 dev_err(wdev
->dev
, "bad hardware revision number: %d\n", hw_revision
);
351 hw_type
= FIELD_GET(CFG_DEVICE_ID_TYPE
, reg
);
353 dev_notice(wdev
->dev
, "development hardware detected\n");
354 wakeup_timeout
= 2000;
357 ret
= init_gpr(wdev
);
361 ret
= wfx_control_reg_write(wdev
, CTRL_WLAN_WAKEUP
);
366 ret
= wfx_control_reg_read(wdev
, ®
);
368 if (reg
& CTRL_WLAN_READY
)
370 if (ktime_after(now
, ktime_add_ms(start
, wakeup_timeout
))) {
371 dev_err(wdev
->dev
, "chip didn't wake up. Chip wasn't reset?\n");
375 dev_dbg(wdev
->dev
, "chip wake up after %lldus\n", ktime_us_delta(now
, start
));
377 ret
= wfx_config_reg_write_bits(wdev
, CFG_CPU_RESET
, 0);
380 ret
= load_firmware_secure(wdev
);
383 return wfx_config_reg_write_bits(wdev
,
384 CFG_DIRECT_ACCESS_MODE
|
385 CFG_IRQ_ENABLE_DATA
|
387 CFG_IRQ_ENABLE_DATA
);