HID: hiddev: Fix slab-out-of-bounds write in hiddev_ioctl_usage()
[linux/fpc-iii.git] / drivers / parisc / lba_pci.c
blob1d288fa4f4d687ebf4e27610a37ae7a6a77abe44
1 /*
2 **
3 ** PCI Lower Bus Adapter (LBA) manager
4 **
5 ** (c) Copyright 1999,2000 Grant Grundler
6 ** (c) Copyright 1999,2000 Hewlett-Packard Company
7 **
8 ** This program is free software; you can redistribute it and/or modify
9 ** it under the terms of the GNU General Public License as published by
10 ** the Free Software Foundation; either version 2 of the License, or
11 ** (at your option) any later version.
14 ** This module primarily provides access to PCI bus (config/IOport
15 ** spaces) on platforms with an SBA/LBA chipset. A/B/C/J/L/N-class
16 ** with 4 digit model numbers - eg C3000 (and A400...sigh).
18 ** LBA driver isn't as simple as the Dino driver because:
19 ** (a) this chip has substantial bug fixes between revisions
20 ** (Only one Dino bug has a software workaround :^( )
21 ** (b) has more options which we don't (yet) support (DMA hints, OLARD)
22 ** (c) IRQ support lives in the I/O SAPIC driver (not with PCI driver)
23 ** (d) play nicely with both PAT and "Legacy" PA-RISC firmware (PDC).
24 ** (dino only deals with "Legacy" PDC)
26 ** LBA driver passes the I/O SAPIC HPA to the I/O SAPIC driver.
27 ** (I/O SAPIC is integratd in the LBA chip).
29 ** FIXME: Add support to SBA and LBA drivers for DMA hint sets
30 ** FIXME: Add support for PCI card hot-plug (OLARD).
33 #include <linux/delay.h>
34 #include <linux/types.h>
35 #include <linux/kernel.h>
36 #include <linux/spinlock.h>
37 #include <linux/init.h> /* for __init */
38 #include <linux/pci.h>
39 #include <linux/ioport.h>
40 #include <linux/slab.h>
42 #include <asm/byteorder.h>
43 #include <asm/pdc.h>
44 #include <asm/pdcpat.h>
45 #include <asm/page.h>
47 #include <asm/ropes.h>
48 #include <asm/hardware.h> /* for register_parisc_driver() stuff */
49 #include <asm/parisc-device.h>
50 #include <asm/io.h> /* read/write stuff */
52 #undef DEBUG_LBA /* general stuff */
53 #undef DEBUG_LBA_PORT /* debug I/O Port access */
54 #undef DEBUG_LBA_CFG /* debug Config Space Access (ie PCI Bus walk) */
55 #undef DEBUG_LBA_PAT /* debug PCI Resource Mgt code - PDC PAT only */
57 #undef FBB_SUPPORT /* Fast Back-Back xfers - NOT READY YET */
60 #ifdef DEBUG_LBA
61 #define DBG(x...) printk(x)
62 #else
63 #define DBG(x...)
64 #endif
66 #ifdef DEBUG_LBA_PORT
67 #define DBG_PORT(x...) printk(x)
68 #else
69 #define DBG_PORT(x...)
70 #endif
72 #ifdef DEBUG_LBA_CFG
73 #define DBG_CFG(x...) printk(x)
74 #else
75 #define DBG_CFG(x...)
76 #endif
78 #ifdef DEBUG_LBA_PAT
79 #define DBG_PAT(x...) printk(x)
80 #else
81 #define DBG_PAT(x...)
82 #endif
86 ** Config accessor functions only pass in the 8-bit bus number and not
87 ** the 8-bit "PCI Segment" number. Each LBA will be assigned a PCI bus
88 ** number based on what firmware wrote into the scratch register.
90 ** The "secondary" bus number is set to this before calling
91 ** pci_register_ops(). If any PPB's are present, the scan will
92 ** discover them and update the "secondary" and "subordinate"
93 ** fields in the pci_bus structure.
95 ** Changes in the configuration *may* result in a different
96 ** bus number for each LBA depending on what firmware does.
99 #define MODULE_NAME "LBA"
101 /* non-postable I/O port space, densely packed */
102 #define LBA_PORT_BASE (PCI_F_EXTEND | 0xfee00000UL)
103 static void __iomem *astro_iop_base __read_mostly;
105 static u32 lba_t32;
107 /* lba flags */
108 #define LBA_FLAG_SKIP_PROBE 0x10
110 #define LBA_SKIP_PROBE(d) ((d)->flags & LBA_FLAG_SKIP_PROBE)
113 /* Looks nice and keeps the compiler happy */
114 #define LBA_DEV(d) ({ \
115 void *__pdata = d; \
116 BUG_ON(!__pdata); \
117 (struct lba_device *)__pdata; })
120 ** Only allow 8 subsidiary busses per LBA
121 ** Problem is the PCI bus numbering is globally shared.
123 #define LBA_MAX_NUM_BUSES 8
125 /************************************
126 * LBA register read and write support
128 * BE WARNED: register writes are posted.
129 * (ie follow writes which must reach HW with a read)
131 #define READ_U8(addr) __raw_readb(addr)
132 #define READ_U16(addr) __raw_readw(addr)
133 #define READ_U32(addr) __raw_readl(addr)
134 #define WRITE_U8(value, addr) __raw_writeb(value, addr)
135 #define WRITE_U16(value, addr) __raw_writew(value, addr)
136 #define WRITE_U32(value, addr) __raw_writel(value, addr)
138 #define READ_REG8(addr) readb(addr)
139 #define READ_REG16(addr) readw(addr)
140 #define READ_REG32(addr) readl(addr)
141 #define READ_REG64(addr) readq(addr)
142 #define WRITE_REG8(value, addr) writeb(value, addr)
143 #define WRITE_REG16(value, addr) writew(value, addr)
144 #define WRITE_REG32(value, addr) writel(value, addr)
147 #define LBA_CFG_TOK(bus,dfn) ((u32) ((bus)<<16 | (dfn)<<8))
148 #define LBA_CFG_BUS(tok) ((u8) ((tok)>>16))
149 #define LBA_CFG_DEV(tok) ((u8) ((tok)>>11) & 0x1f)
150 #define LBA_CFG_FUNC(tok) ((u8) ((tok)>>8 ) & 0x7)
154 ** Extract LBA (Rope) number from HPA
155 ** REVISIT: 16 ropes for Stretch/Ike?
157 #define ROPES_PER_IOC 8
158 #define LBA_NUM(x) ((((unsigned long) x) >> 13) & (ROPES_PER_IOC-1))
161 static void
162 lba_dump_res(struct resource *r, int d)
164 int i;
166 if (NULL == r)
167 return;
169 printk(KERN_DEBUG "(%p)", r->parent);
170 for (i = d; i ; --i) printk(" ");
171 printk(KERN_DEBUG "%p [%lx,%lx]/%lx\n", r,
172 (long)r->start, (long)r->end, r->flags);
173 lba_dump_res(r->child, d+2);
174 lba_dump_res(r->sibling, d);
179 ** LBA rev 2.0, 2.1, 2.2, and 3.0 bus walks require a complex
180 ** workaround for cfg cycles:
181 ** -- preserve LBA state
182 ** -- prevent any DMA from occurring
183 ** -- turn on smart mode
184 ** -- probe with config writes before doing config reads
185 ** -- check ERROR_STATUS
186 ** -- clear ERROR_STATUS
187 ** -- restore LBA state
189 ** The workaround is only used for device discovery.
192 static int lba_device_present(u8 bus, u8 dfn, struct lba_device *d)
194 u8 first_bus = d->hba.hba_bus->busn_res.start;
195 u8 last_sub_bus = d->hba.hba_bus->busn_res.end;
197 if ((bus < first_bus) ||
198 (bus > last_sub_bus) ||
199 ((bus - first_bus) >= LBA_MAX_NUM_BUSES)) {
200 return 0;
203 return 1;
208 #define LBA_CFG_SETUP(d, tok) { \
209 /* Save contents of error config register. */ \
210 error_config = READ_REG32(d->hba.base_addr + LBA_ERROR_CONFIG); \
212 /* Save contents of status control register. */ \
213 status_control = READ_REG32(d->hba.base_addr + LBA_STAT_CTL); \
215 /* For LBA rev 2.0, 2.1, 2.2, and 3.0, we must disable DMA \
216 ** arbitration for full bus walks. \
217 */ \
218 /* Save contents of arb mask register. */ \
219 arb_mask = READ_REG32(d->hba.base_addr + LBA_ARB_MASK); \
221 /* \
222 * Turn off all device arbitration bits (i.e. everything \
223 * except arbitration enable bit). \
224 */ \
225 WRITE_REG32(0x1, d->hba.base_addr + LBA_ARB_MASK); \
227 /* \
228 * Set the smart mode bit so that master aborts don't cause \
229 * LBA to go into PCI fatal mode (required). \
230 */ \
231 WRITE_REG32(error_config | LBA_SMART_MODE, d->hba.base_addr + LBA_ERROR_CONFIG); \
235 #define LBA_CFG_PROBE(d, tok) { \
236 /* \
237 * Setup Vendor ID write and read back the address register \
238 * to make sure that LBA is the bus master. \
239 */ \
240 WRITE_REG32(tok | PCI_VENDOR_ID, (d)->hba.base_addr + LBA_PCI_CFG_ADDR);\
241 /* \
242 * Read address register to ensure that LBA is the bus master, \
243 * which implies that DMA traffic has stopped when DMA arb is off. \
244 */ \
245 lba_t32 = READ_REG32((d)->hba.base_addr + LBA_PCI_CFG_ADDR); \
246 /* \
247 * Generate a cfg write cycle (will have no affect on \
248 * Vendor ID register since read-only). \
249 */ \
250 WRITE_REG32(~0, (d)->hba.base_addr + LBA_PCI_CFG_DATA); \
251 /* \
252 * Make sure write has completed before proceeding further, \
253 * i.e. before setting clear enable. \
254 */ \
255 lba_t32 = READ_REG32((d)->hba.base_addr + LBA_PCI_CFG_ADDR); \
260 * HPREVISIT:
261 * -- Can't tell if config cycle got the error.
263 * OV bit is broken until rev 4.0, so can't use OV bit and
264 * LBA_ERROR_LOG_ADDR to tell if error belongs to config cycle.
266 * As of rev 4.0, no longer need the error check.
268 * -- Even if we could tell, we still want to return -1
269 * for **ANY** error (not just master abort).
271 * -- Only clear non-fatal errors (we don't want to bring
272 * LBA out of pci-fatal mode).
274 * Actually, there is still a race in which
275 * we could be clearing a fatal error. We will
276 * live with this during our initial bus walk
277 * until rev 4.0 (no driver activity during
278 * initial bus walk). The initial bus walk
279 * has race conditions concerning the use of
280 * smart mode as well.
283 #define LBA_MASTER_ABORT_ERROR 0xc
284 #define LBA_FATAL_ERROR 0x10
286 #define LBA_CFG_MASTER_ABORT_CHECK(d, base, tok, error) { \
287 u32 error_status = 0; \
288 /* \
289 * Set clear enable (CE) bit. Unset by HW when new \
290 * errors are logged -- LBA HW ERS section 14.3.3). \
291 */ \
292 WRITE_REG32(status_control | CLEAR_ERRLOG_ENABLE, base + LBA_STAT_CTL); \
293 error_status = READ_REG32(base + LBA_ERROR_STATUS); \
294 if ((error_status & 0x1f) != 0) { \
295 /* \
296 * Fail the config read request. \
297 */ \
298 error = 1; \
299 if ((error_status & LBA_FATAL_ERROR) == 0) { \
300 /* \
301 * Clear error status (if fatal bit not set) by setting \
302 * clear error log bit (CL). \
303 */ \
304 WRITE_REG32(status_control | CLEAR_ERRLOG, base + LBA_STAT_CTL); \
309 #define LBA_CFG_TR4_ADDR_SETUP(d, addr) \
310 WRITE_REG32(((addr) & ~3), (d)->hba.base_addr + LBA_PCI_CFG_ADDR);
312 #define LBA_CFG_ADDR_SETUP(d, addr) { \
313 WRITE_REG32(((addr) & ~3), (d)->hba.base_addr + LBA_PCI_CFG_ADDR); \
314 /* \
315 * Read address register to ensure that LBA is the bus master, \
316 * which implies that DMA traffic has stopped when DMA arb is off. \
317 */ \
318 lba_t32 = READ_REG32((d)->hba.base_addr + LBA_PCI_CFG_ADDR); \
322 #define LBA_CFG_RESTORE(d, base) { \
323 /* \
324 * Restore status control register (turn off clear enable). \
325 */ \
326 WRITE_REG32(status_control, base + LBA_STAT_CTL); \
327 /* \
328 * Restore error config register (turn off smart mode). \
329 */ \
330 WRITE_REG32(error_config, base + LBA_ERROR_CONFIG); \
331 /* \
332 * Restore arb mask register (reenables DMA arbitration). \
333 */ \
334 WRITE_REG32(arb_mask, base + LBA_ARB_MASK); \
339 static unsigned int
340 lba_rd_cfg(struct lba_device *d, u32 tok, u8 reg, u32 size)
342 u32 data = ~0U;
343 int error = 0;
344 u32 arb_mask = 0; /* used by LBA_CFG_SETUP/RESTORE */
345 u32 error_config = 0; /* used by LBA_CFG_SETUP/RESTORE */
346 u32 status_control = 0; /* used by LBA_CFG_SETUP/RESTORE */
348 LBA_CFG_SETUP(d, tok);
349 LBA_CFG_PROBE(d, tok);
350 LBA_CFG_MASTER_ABORT_CHECK(d, d->hba.base_addr, tok, error);
351 if (!error) {
352 void __iomem *data_reg = d->hba.base_addr + LBA_PCI_CFG_DATA;
354 LBA_CFG_ADDR_SETUP(d, tok | reg);
355 switch (size) {
356 case 1: data = (u32) READ_REG8(data_reg + (reg & 3)); break;
357 case 2: data = (u32) READ_REG16(data_reg+ (reg & 2)); break;
358 case 4: data = READ_REG32(data_reg); break;
361 LBA_CFG_RESTORE(d, d->hba.base_addr);
362 return(data);
366 static int elroy_cfg_read(struct pci_bus *bus, unsigned int devfn, int pos, int size, u32 *data)
368 struct lba_device *d = LBA_DEV(parisc_walk_tree(bus->bridge));
369 u32 local_bus = (bus->parent == NULL) ? 0 : bus->busn_res.start;
370 u32 tok = LBA_CFG_TOK(local_bus, devfn);
371 void __iomem *data_reg = d->hba.base_addr + LBA_PCI_CFG_DATA;
373 if ((pos > 255) || (devfn > 255))
374 return -EINVAL;
376 /* FIXME: B2K/C3600 workaround is always use old method... */
377 /* if (!LBA_SKIP_PROBE(d)) */ {
378 /* original - Generate config cycle on broken elroy
379 with risk we will miss PCI bus errors. */
380 *data = lba_rd_cfg(d, tok, pos, size);
381 DBG_CFG("%s(%x+%2x) -> 0x%x (a)\n", __func__, tok, pos, *data);
382 return 0;
385 if (LBA_SKIP_PROBE(d) && !lba_device_present(bus->busn_res.start, devfn, d)) {
386 DBG_CFG("%s(%x+%2x) -> -1 (b)\n", __func__, tok, pos);
387 /* either don't want to look or know device isn't present. */
388 *data = ~0U;
389 return(0);
392 /* Basic Algorithm
393 ** Should only get here on fully working LBA rev.
394 ** This is how simple the code should have been.
396 LBA_CFG_ADDR_SETUP(d, tok | pos);
397 switch(size) {
398 case 1: *data = READ_REG8 (data_reg + (pos & 3)); break;
399 case 2: *data = READ_REG16(data_reg + (pos & 2)); break;
400 case 4: *data = READ_REG32(data_reg); break;
402 DBG_CFG("%s(%x+%2x) -> 0x%x (c)\n", __func__, tok, pos, *data);
403 return 0;
407 static void
408 lba_wr_cfg(struct lba_device *d, u32 tok, u8 reg, u32 data, u32 size)
410 int error = 0;
411 u32 arb_mask = 0;
412 u32 error_config = 0;
413 u32 status_control = 0;
414 void __iomem *data_reg = d->hba.base_addr + LBA_PCI_CFG_DATA;
416 LBA_CFG_SETUP(d, tok);
417 LBA_CFG_ADDR_SETUP(d, tok | reg);
418 switch (size) {
419 case 1: WRITE_REG8 (data, data_reg + (reg & 3)); break;
420 case 2: WRITE_REG16(data, data_reg + (reg & 2)); break;
421 case 4: WRITE_REG32(data, data_reg); break;
423 LBA_CFG_MASTER_ABORT_CHECK(d, d->hba.base_addr, tok, error);
424 LBA_CFG_RESTORE(d, d->hba.base_addr);
429 * LBA 4.0 config write code implements non-postable semantics
430 * by doing a read of CONFIG ADDR after the write.
433 static int elroy_cfg_write(struct pci_bus *bus, unsigned int devfn, int pos, int size, u32 data)
435 struct lba_device *d = LBA_DEV(parisc_walk_tree(bus->bridge));
436 u32 local_bus = (bus->parent == NULL) ? 0 : bus->busn_res.start;
437 u32 tok = LBA_CFG_TOK(local_bus,devfn);
439 if ((pos > 255) || (devfn > 255))
440 return -EINVAL;
442 if (!LBA_SKIP_PROBE(d)) {
443 /* Original Workaround */
444 lba_wr_cfg(d, tok, pos, (u32) data, size);
445 DBG_CFG("%s(%x+%2x) = 0x%x (a)\n", __func__, tok, pos,data);
446 return 0;
449 if (LBA_SKIP_PROBE(d) && (!lba_device_present(bus->busn_res.start, devfn, d))) {
450 DBG_CFG("%s(%x+%2x) = 0x%x (b)\n", __func__, tok, pos,data);
451 return 1; /* New Workaround */
454 DBG_CFG("%s(%x+%2x) = 0x%x (c)\n", __func__, tok, pos, data);
456 /* Basic Algorithm */
457 LBA_CFG_ADDR_SETUP(d, tok | pos);
458 switch(size) {
459 case 1: WRITE_REG8 (data, d->hba.base_addr + LBA_PCI_CFG_DATA + (pos & 3));
460 break;
461 case 2: WRITE_REG16(data, d->hba.base_addr + LBA_PCI_CFG_DATA + (pos & 2));
462 break;
463 case 4: WRITE_REG32(data, d->hba.base_addr + LBA_PCI_CFG_DATA);
464 break;
466 /* flush posted write */
467 lba_t32 = READ_REG32(d->hba.base_addr + LBA_PCI_CFG_ADDR);
468 return 0;
472 static struct pci_ops elroy_cfg_ops = {
473 .read = elroy_cfg_read,
474 .write = elroy_cfg_write,
478 * The mercury_cfg_ops are slightly misnamed; they're also used for Elroy
479 * TR4.0 as no additional bugs were found in this areea between Elroy and
480 * Mercury
483 static int mercury_cfg_read(struct pci_bus *bus, unsigned int devfn, int pos, int size, u32 *data)
485 struct lba_device *d = LBA_DEV(parisc_walk_tree(bus->bridge));
486 u32 local_bus = (bus->parent == NULL) ? 0 : bus->busn_res.start;
487 u32 tok = LBA_CFG_TOK(local_bus, devfn);
488 void __iomem *data_reg = d->hba.base_addr + LBA_PCI_CFG_DATA;
490 if ((pos > 255) || (devfn > 255))
491 return -EINVAL;
493 LBA_CFG_TR4_ADDR_SETUP(d, tok | pos);
494 switch(size) {
495 case 1:
496 *data = READ_REG8(data_reg + (pos & 3));
497 break;
498 case 2:
499 *data = READ_REG16(data_reg + (pos & 2));
500 break;
501 case 4:
502 *data = READ_REG32(data_reg); break;
503 break;
506 DBG_CFG("mercury_cfg_read(%x+%2x) -> 0x%x\n", tok, pos, *data);
507 return 0;
511 * LBA 4.0 config write code implements non-postable semantics
512 * by doing a read of CONFIG ADDR after the write.
515 static int mercury_cfg_write(struct pci_bus *bus, unsigned int devfn, int pos, int size, u32 data)
517 struct lba_device *d = LBA_DEV(parisc_walk_tree(bus->bridge));
518 void __iomem *data_reg = d->hba.base_addr + LBA_PCI_CFG_DATA;
519 u32 local_bus = (bus->parent == NULL) ? 0 : bus->busn_res.start;
520 u32 tok = LBA_CFG_TOK(local_bus,devfn);
522 if ((pos > 255) || (devfn > 255))
523 return -EINVAL;
525 DBG_CFG("%s(%x+%2x) <- 0x%x (c)\n", __func__, tok, pos, data);
527 LBA_CFG_TR4_ADDR_SETUP(d, tok | pos);
528 switch(size) {
529 case 1:
530 WRITE_REG8 (data, data_reg + (pos & 3));
531 break;
532 case 2:
533 WRITE_REG16(data, data_reg + (pos & 2));
534 break;
535 case 4:
536 WRITE_REG32(data, data_reg);
537 break;
540 /* flush posted write */
541 lba_t32 = READ_U32(d->hba.base_addr + LBA_PCI_CFG_ADDR);
542 return 0;
545 static struct pci_ops mercury_cfg_ops = {
546 .read = mercury_cfg_read,
547 .write = mercury_cfg_write,
551 static void
552 lba_bios_init(void)
554 DBG(MODULE_NAME ": lba_bios_init\n");
558 #ifdef CONFIG_64BIT
561 * truncate_pat_collision: Deal with overlaps or outright collisions
562 * between PAT PDC reported ranges.
564 * Broken PA8800 firmware will report lmmio range that
565 * overlaps with CPU HPA. Just truncate the lmmio range.
567 * BEWARE: conflicts with this lmmio range may be an
568 * elmmio range which is pointing down another rope.
570 * FIXME: only deals with one collision per range...theoretically we
571 * could have several. Supporting more than one collision will get messy.
573 static unsigned long
574 truncate_pat_collision(struct resource *root, struct resource *new)
576 unsigned long start = new->start;
577 unsigned long end = new->end;
578 struct resource *tmp = root->child;
580 if (end <= start || start < root->start || !tmp)
581 return 0;
583 /* find first overlap */
584 while (tmp && tmp->end < start)
585 tmp = tmp->sibling;
587 /* no entries overlap */
588 if (!tmp) return 0;
590 /* found one that starts behind the new one
591 ** Don't need to do anything.
593 if (tmp->start >= end) return 0;
595 if (tmp->start <= start) {
596 /* "front" of new one overlaps */
597 new->start = tmp->end + 1;
599 if (tmp->end >= end) {
600 /* AACCKK! totally overlaps! drop this range. */
601 return 1;
605 if (tmp->end < end ) {
606 /* "end" of new one overlaps */
607 new->end = tmp->start - 1;
610 printk(KERN_WARNING "LBA: Truncating lmmio_space [%lx/%lx] "
611 "to [%lx,%lx]\n",
612 start, end,
613 (long)new->start, (long)new->end );
615 return 0; /* truncation successful */
619 * extend_lmmio_len: extend lmmio range to maximum length
621 * This is needed at least on C8000 systems to get the ATI FireGL card
622 * working. On other systems we will currently not extend the lmmio space.
624 static unsigned long
625 extend_lmmio_len(unsigned long start, unsigned long end, unsigned long lba_len)
627 struct resource *tmp;
629 /* exit if not a C8000 */
630 if (boot_cpu_data.cpu_type < mako)
631 return end;
633 pr_debug("LMMIO mismatch: PAT length = 0x%lx, MASK register = 0x%lx\n",
634 end - start, lba_len);
636 lba_len = min(lba_len+1, 256UL*1024*1024); /* limit to 256 MB */
638 pr_debug("LBA: lmmio_space [0x%lx-0x%lx] - original\n", start, end);
641 end += lba_len;
642 if (end < start) /* fix overflow */
643 end = -1ULL;
645 pr_debug("LBA: lmmio_space [0x%lx-0x%lx] - current\n", start, end);
647 /* first overlap */
648 for (tmp = iomem_resource.child; tmp; tmp = tmp->sibling) {
649 pr_debug("LBA: testing %pR\n", tmp);
650 if (tmp->start == start)
651 continue; /* ignore ourself */
652 if (tmp->end < start)
653 continue;
654 if (tmp->start > end)
655 continue;
656 if (end >= tmp->start)
657 end = tmp->start - 1;
660 pr_info("LBA: lmmio_space [0x%lx-0x%lx] - new\n", start, end);
662 /* return new end */
663 return end;
666 #else
667 #define truncate_pat_collision(r,n) (0)
668 #endif
671 ** The algorithm is generic code.
672 ** But it needs to access local data structures to get the IRQ base.
673 ** Could make this a "pci_fixup_irq(bus, region)" but not sure
674 ** it's worth it.
676 ** Called by do_pci_scan_bus() immediately after each PCI bus is walked.
677 ** Resources aren't allocated until recursive buswalk below HBA is completed.
679 static void
680 lba_fixup_bus(struct pci_bus *bus)
682 struct pci_dev *dev;
683 #ifdef FBB_SUPPORT
684 u16 status;
685 #endif
686 struct lba_device *ldev = LBA_DEV(parisc_walk_tree(bus->bridge));
688 DBG("lba_fixup_bus(0x%p) bus %d platform_data 0x%p\n",
689 bus, (int)bus->busn_res.start, bus->bridge->platform_data);
692 ** Properly Setup MMIO resources for this bus.
693 ** pci_alloc_primary_bus() mangles this.
695 if (bus->parent) {
696 int i;
697 /* PCI-PCI Bridge */
698 pci_read_bridge_bases(bus);
699 for (i = PCI_BRIDGE_RESOURCES; i < PCI_NUM_RESOURCES; i++)
700 pci_claim_bridge_resource(bus->self, i);
701 } else {
702 /* Host-PCI Bridge */
703 int err;
705 DBG("lba_fixup_bus() %s [%lx/%lx]/%lx\n",
706 ldev->hba.io_space.name,
707 ldev->hba.io_space.start, ldev->hba.io_space.end,
708 ldev->hba.io_space.flags);
709 DBG("lba_fixup_bus() %s [%lx/%lx]/%lx\n",
710 ldev->hba.lmmio_space.name,
711 ldev->hba.lmmio_space.start, ldev->hba.lmmio_space.end,
712 ldev->hba.lmmio_space.flags);
714 err = request_resource(&ioport_resource, &(ldev->hba.io_space));
715 if (err < 0) {
716 lba_dump_res(&ioport_resource, 2);
717 BUG();
720 if (ldev->hba.elmmio_space.flags) {
721 err = request_resource(&iomem_resource,
722 &(ldev->hba.elmmio_space));
723 if (err < 0) {
725 printk("FAILED: lba_fixup_bus() request for "
726 "elmmio_space [%lx/%lx]\n",
727 (long)ldev->hba.elmmio_space.start,
728 (long)ldev->hba.elmmio_space.end);
730 /* lba_dump_res(&iomem_resource, 2); */
731 /* BUG(); */
735 if (ldev->hba.lmmio_space.flags) {
736 err = request_resource(&iomem_resource, &(ldev->hba.lmmio_space));
737 if (err < 0) {
738 printk(KERN_ERR "FAILED: lba_fixup_bus() request for "
739 "lmmio_space [%lx/%lx]\n",
740 (long)ldev->hba.lmmio_space.start,
741 (long)ldev->hba.lmmio_space.end);
745 #ifdef CONFIG_64BIT
746 /* GMMIO is distributed range. Every LBA/Rope gets part it. */
747 if (ldev->hba.gmmio_space.flags) {
748 err = request_resource(&iomem_resource, &(ldev->hba.gmmio_space));
749 if (err < 0) {
750 printk("FAILED: lba_fixup_bus() request for "
751 "gmmio_space [%lx/%lx]\n",
752 (long)ldev->hba.gmmio_space.start,
753 (long)ldev->hba.gmmio_space.end);
754 lba_dump_res(&iomem_resource, 2);
755 BUG();
758 #endif
762 list_for_each_entry(dev, &bus->devices, bus_list) {
763 int i;
765 DBG("lba_fixup_bus() %s\n", pci_name(dev));
767 /* Virtualize Device/Bridge Resources. */
768 for (i = 0; i < PCI_BRIDGE_RESOURCES; i++) {
769 struct resource *res = &dev->resource[i];
771 /* If resource not allocated - skip it */
772 if (!res->start)
773 continue;
776 ** FIXME: this will result in whinging for devices
777 ** that share expansion ROMs (think quad tulip), but
778 ** isn't harmful.
780 pci_claim_resource(dev, i);
783 #ifdef FBB_SUPPORT
785 ** If one device does not support FBB transfers,
786 ** No one on the bus can be allowed to use them.
788 (void) pci_read_config_word(dev, PCI_STATUS, &status);
789 bus->bridge_ctl &= ~(status & PCI_STATUS_FAST_BACK);
790 #endif
793 ** P2PB's have no IRQs. ignore them.
795 if ((dev->class >> 8) == PCI_CLASS_BRIDGE_PCI)
796 continue;
798 /* Adjust INTERRUPT_LINE for this dev */
799 iosapic_fixup_irq(ldev->iosapic_obj, dev);
802 #ifdef FBB_SUPPORT
803 /* FIXME/REVISIT - finish figuring out to set FBB on both
804 ** pci_setup_bridge() clobbers PCI_BRIDGE_CONTROL.
805 ** Can't fixup here anyway....garr...
807 if (fbb_enable) {
808 if (bus->parent) {
809 u8 control;
810 /* enable on PPB */
811 (void) pci_read_config_byte(bus->self, PCI_BRIDGE_CONTROL, &control);
812 (void) pci_write_config_byte(bus->self, PCI_BRIDGE_CONTROL, control | PCI_STATUS_FAST_BACK);
814 } else {
815 /* enable on LBA */
817 fbb_enable = PCI_COMMAND_FAST_BACK;
820 /* Lastly enable FBB/PERR/SERR on all devices too */
821 list_for_each_entry(dev, &bus->devices, bus_list) {
822 (void) pci_read_config_word(dev, PCI_COMMAND, &status);
823 status |= PCI_COMMAND_PARITY | PCI_COMMAND_SERR | fbb_enable;
824 (void) pci_write_config_word(dev, PCI_COMMAND, status);
826 #endif
830 static struct pci_bios_ops lba_bios_ops = {
831 .init = lba_bios_init,
832 .fixup_bus = lba_fixup_bus,
838 /*******************************************************
840 ** LBA Sprockets "I/O Port" Space Accessor Functions
842 ** This set of accessor functions is intended for use with
843 ** "legacy firmware" (ie Sprockets on Allegro/Forte boxes).
845 ** Many PCI devices don't require use of I/O port space (eg Tulip,
846 ** NCR720) since they export the same registers to both MMIO and
847 ** I/O port space. In general I/O port space is slower than
848 ** MMIO since drivers are designed so PIO writes can be posted.
850 ********************************************************/
852 #define LBA_PORT_IN(size, mask) \
853 static u##size lba_astro_in##size (struct pci_hba_data *d, u16 addr) \
855 u##size t; \
856 t = READ_REG##size(astro_iop_base + addr); \
857 DBG_PORT(" 0x%x\n", t); \
858 return (t); \
861 LBA_PORT_IN( 8, 3)
862 LBA_PORT_IN(16, 2)
863 LBA_PORT_IN(32, 0)
868 ** BUG X4107: Ordering broken - DMA RD return can bypass PIO WR
870 ** Fixed in Elroy 2.2. The READ_U32(..., LBA_FUNC_ID) below is
871 ** guarantee non-postable completion semantics - not avoid X4107.
872 ** The READ_U32 only guarantees the write data gets to elroy but
873 ** out to the PCI bus. We can't read stuff from I/O port space
874 ** since we don't know what has side-effects. Attempting to read
875 ** from configuration space would be suicidal given the number of
876 ** bugs in that elroy functionality.
878 ** Description:
879 ** DMA read results can improperly pass PIO writes (X4107). The
880 ** result of this bug is that if a processor modifies a location in
881 ** memory after having issued PIO writes, the PIO writes are not
882 ** guaranteed to be completed before a PCI device is allowed to see
883 ** the modified data in a DMA read.
885 ** Note that IKE bug X3719 in TR1 IKEs will result in the same
886 ** symptom.
888 ** Workaround:
889 ** The workaround for this bug is to always follow a PIO write with
890 ** a PIO read to the same bus before starting DMA on that PCI bus.
893 #define LBA_PORT_OUT(size, mask) \
894 static void lba_astro_out##size (struct pci_hba_data *d, u16 addr, u##size val) \
896 DBG_PORT("%s(0x%p, 0x%x, 0x%x)\n", __func__, d, addr, val); \
897 WRITE_REG##size(val, astro_iop_base + addr); \
898 if (LBA_DEV(d)->hw_rev < 3) \
899 lba_t32 = READ_U32(d->base_addr + LBA_FUNC_ID); \
902 LBA_PORT_OUT( 8, 3)
903 LBA_PORT_OUT(16, 2)
904 LBA_PORT_OUT(32, 0)
907 static struct pci_port_ops lba_astro_port_ops = {
908 .inb = lba_astro_in8,
909 .inw = lba_astro_in16,
910 .inl = lba_astro_in32,
911 .outb = lba_astro_out8,
912 .outw = lba_astro_out16,
913 .outl = lba_astro_out32
917 #ifdef CONFIG_64BIT
918 #define PIOP_TO_GMMIO(lba, addr) \
919 ((lba)->iop_base + (((addr)&0xFFFC)<<10) + ((addr)&3))
921 /*******************************************************
923 ** LBA PAT "I/O Port" Space Accessor Functions
925 ** This set of accessor functions is intended for use with
926 ** "PAT PDC" firmware (ie Prelude/Rhapsody/Piranha boxes).
928 ** This uses the PIOP space located in the first 64MB of GMMIO.
929 ** Each rope gets a full 64*KB* (ie 4 bytes per page) this way.
930 ** bits 1:0 stay the same. bits 15:2 become 25:12.
931 ** Then add the base and we can generate an I/O Port cycle.
932 ********************************************************/
933 #undef LBA_PORT_IN
934 #define LBA_PORT_IN(size, mask) \
935 static u##size lba_pat_in##size (struct pci_hba_data *l, u16 addr) \
937 u##size t; \
938 DBG_PORT("%s(0x%p, 0x%x) ->", __func__, l, addr); \
939 t = READ_REG##size(PIOP_TO_GMMIO(LBA_DEV(l), addr)); \
940 DBG_PORT(" 0x%x\n", t); \
941 return (t); \
944 LBA_PORT_IN( 8, 3)
945 LBA_PORT_IN(16, 2)
946 LBA_PORT_IN(32, 0)
949 #undef LBA_PORT_OUT
950 #define LBA_PORT_OUT(size, mask) \
951 static void lba_pat_out##size (struct pci_hba_data *l, u16 addr, u##size val) \
953 void __iomem *where = PIOP_TO_GMMIO(LBA_DEV(l), addr); \
954 DBG_PORT("%s(0x%p, 0x%x, 0x%x)\n", __func__, l, addr, val); \
955 WRITE_REG##size(val, where); \
956 /* flush the I/O down to the elroy at least */ \
957 lba_t32 = READ_U32(l->base_addr + LBA_FUNC_ID); \
960 LBA_PORT_OUT( 8, 3)
961 LBA_PORT_OUT(16, 2)
962 LBA_PORT_OUT(32, 0)
965 static struct pci_port_ops lba_pat_port_ops = {
966 .inb = lba_pat_in8,
967 .inw = lba_pat_in16,
968 .inl = lba_pat_in32,
969 .outb = lba_pat_out8,
970 .outw = lba_pat_out16,
971 .outl = lba_pat_out32
977 ** make range information from PDC available to PCI subsystem.
978 ** We make the PDC call here in order to get the PCI bus range
979 ** numbers. The rest will get forwarded in pcibios_fixup_bus().
980 ** We don't have a struct pci_bus assigned to us yet.
982 static void
983 lba_pat_resources(struct parisc_device *pa_dev, struct lba_device *lba_dev)
985 unsigned long bytecnt;
986 long io_count;
987 long status; /* PDC return status */
988 long pa_count;
989 pdc_pat_cell_mod_maddr_block_t *pa_pdc_cell; /* PA_VIEW */
990 pdc_pat_cell_mod_maddr_block_t *io_pdc_cell; /* IO_VIEW */
991 int i;
993 pa_pdc_cell = kzalloc(sizeof(pdc_pat_cell_mod_maddr_block_t), GFP_KERNEL);
994 if (!pa_pdc_cell)
995 return;
997 io_pdc_cell = kzalloc(sizeof(pdc_pat_cell_mod_maddr_block_t), GFP_KERNEL);
998 if (!io_pdc_cell) {
999 kfree(pa_pdc_cell);
1000 return;
1003 /* return cell module (IO view) */
1004 status = pdc_pat_cell_module(&bytecnt, pa_dev->pcell_loc, pa_dev->mod_index,
1005 PA_VIEW, pa_pdc_cell);
1006 pa_count = pa_pdc_cell->mod[1];
1008 status |= pdc_pat_cell_module(&bytecnt, pa_dev->pcell_loc, pa_dev->mod_index,
1009 IO_VIEW, io_pdc_cell);
1010 io_count = io_pdc_cell->mod[1];
1012 /* We've already done this once for device discovery...*/
1013 if (status != PDC_OK) {
1014 panic("pdc_pat_cell_module() call failed for LBA!\n");
1017 if (PAT_GET_ENTITY(pa_pdc_cell->mod_info) != PAT_ENTITY_LBA) {
1018 panic("pdc_pat_cell_module() entity returned != PAT_ENTITY_LBA!\n");
1022 ** Inspect the resources PAT tells us about
1024 for (i = 0; i < pa_count; i++) {
1025 struct {
1026 unsigned long type;
1027 unsigned long start;
1028 unsigned long end; /* aka finish */
1029 } *p, *io;
1030 struct resource *r;
1032 p = (void *) &(pa_pdc_cell->mod[2+i*3]);
1033 io = (void *) &(io_pdc_cell->mod[2+i*3]);
1035 /* Convert the PAT range data to PCI "struct resource" */
1036 switch(p->type & 0xff) {
1037 case PAT_PBNUM:
1038 lba_dev->hba.bus_num.start = p->start;
1039 lba_dev->hba.bus_num.end = p->end;
1040 lba_dev->hba.bus_num.flags = IORESOURCE_BUS;
1041 break;
1043 case PAT_LMMIO:
1044 /* used to fix up pre-initialized MEM BARs */
1045 if (!lba_dev->hba.lmmio_space.flags) {
1046 unsigned long lba_len;
1048 lba_len = ~READ_REG32(lba_dev->hba.base_addr
1049 + LBA_LMMIO_MASK);
1050 if ((p->end - p->start) != lba_len)
1051 p->end = extend_lmmio_len(p->start,
1052 p->end, lba_len);
1054 sprintf(lba_dev->hba.lmmio_name,
1055 "PCI%02x LMMIO",
1056 (int)lba_dev->hba.bus_num.start);
1057 lba_dev->hba.lmmio_space_offset = p->start -
1058 io->start;
1059 r = &lba_dev->hba.lmmio_space;
1060 r->name = lba_dev->hba.lmmio_name;
1061 } else if (!lba_dev->hba.elmmio_space.flags) {
1062 sprintf(lba_dev->hba.elmmio_name,
1063 "PCI%02x ELMMIO",
1064 (int)lba_dev->hba.bus_num.start);
1065 r = &lba_dev->hba.elmmio_space;
1066 r->name = lba_dev->hba.elmmio_name;
1067 } else {
1068 printk(KERN_WARNING MODULE_NAME
1069 " only supports 2 LMMIO resources!\n");
1070 break;
1073 r->start = p->start;
1074 r->end = p->end;
1075 r->flags = IORESOURCE_MEM;
1076 r->parent = r->sibling = r->child = NULL;
1077 break;
1079 case PAT_GMMIO:
1080 /* MMIO space > 4GB phys addr; for 64-bit BAR */
1081 sprintf(lba_dev->hba.gmmio_name, "PCI%02x GMMIO",
1082 (int)lba_dev->hba.bus_num.start);
1083 r = &lba_dev->hba.gmmio_space;
1084 r->name = lba_dev->hba.gmmio_name;
1085 r->start = p->start;
1086 r->end = p->end;
1087 r->flags = IORESOURCE_MEM;
1088 r->parent = r->sibling = r->child = NULL;
1089 break;
1091 case PAT_NPIOP:
1092 printk(KERN_WARNING MODULE_NAME
1093 " range[%d] : ignoring NPIOP (0x%lx)\n",
1094 i, p->start);
1095 break;
1097 case PAT_PIOP:
1099 ** Postable I/O port space is per PCI host adapter.
1100 ** base of 64MB PIOP region
1102 lba_dev->iop_base = ioremap_nocache(p->start, 64 * 1024 * 1024);
1104 sprintf(lba_dev->hba.io_name, "PCI%02x Ports",
1105 (int)lba_dev->hba.bus_num.start);
1106 r = &lba_dev->hba.io_space;
1107 r->name = lba_dev->hba.io_name;
1108 r->start = HBA_PORT_BASE(lba_dev->hba.hba_num);
1109 r->end = r->start + HBA_PORT_SPACE_SIZE - 1;
1110 r->flags = IORESOURCE_IO;
1111 r->parent = r->sibling = r->child = NULL;
1112 break;
1114 default:
1115 printk(KERN_WARNING MODULE_NAME
1116 " range[%d] : unknown pat range type (0x%lx)\n",
1117 i, p->type & 0xff);
1118 break;
1122 kfree(pa_pdc_cell);
1123 kfree(io_pdc_cell);
1125 #else
1126 /* keep compiler from complaining about missing declarations */
1127 #define lba_pat_port_ops lba_astro_port_ops
1128 #define lba_pat_resources(pa_dev, lba_dev)
1129 #endif /* CONFIG_64BIT */
1132 extern void sba_distributed_lmmio(struct parisc_device *, struct resource *);
1133 extern void sba_directed_lmmio(struct parisc_device *, struct resource *);
1136 static void
1137 lba_legacy_resources(struct parisc_device *pa_dev, struct lba_device *lba_dev)
1139 struct resource *r;
1140 int lba_num;
1142 lba_dev->hba.lmmio_space_offset = PCI_F_EXTEND;
1145 ** With "legacy" firmware, the lowest byte of FW_SCRATCH
1146 ** represents bus->secondary and the second byte represents
1147 ** bus->subsidiary (i.e. highest PPB programmed by firmware).
1148 ** PCI bus walk *should* end up with the same result.
1149 ** FIXME: But we don't have sanity checks in PCI or LBA.
1151 lba_num = READ_REG32(lba_dev->hba.base_addr + LBA_FW_SCRATCH);
1152 r = &(lba_dev->hba.bus_num);
1153 r->name = "LBA PCI Busses";
1154 r->start = lba_num & 0xff;
1155 r->end = (lba_num>>8) & 0xff;
1156 r->flags = IORESOURCE_BUS;
1158 /* Set up local PCI Bus resources - we don't need them for
1159 ** Legacy boxes but it's nice to see in /proc/iomem.
1161 r = &(lba_dev->hba.lmmio_space);
1162 sprintf(lba_dev->hba.lmmio_name, "PCI%02x LMMIO",
1163 (int)lba_dev->hba.bus_num.start);
1164 r->name = lba_dev->hba.lmmio_name;
1166 #if 1
1167 /* We want the CPU -> IO routing of addresses.
1168 * The SBA BASE/MASK registers control CPU -> IO routing.
1169 * Ask SBA what is routed to this rope/LBA.
1171 sba_distributed_lmmio(pa_dev, r);
1172 #else
1174 * The LBA BASE/MASK registers control IO -> System routing.
1176 * The following code works but doesn't get us what we want.
1177 * Well, only because firmware (v5.0) on C3000 doesn't program
1178 * the LBA BASE/MASE registers to be the exact inverse of
1179 * the corresponding SBA registers. Other Astro/Pluto
1180 * based platform firmware may do it right.
1182 * Should someone want to mess with MSI, they may need to
1183 * reprogram LBA BASE/MASK registers. Thus preserve the code
1184 * below until MSI is known to work on C3000/A500/N4000/RP3440.
1186 * Using the code below, /proc/iomem shows:
1187 * ...
1188 * f0000000-f0ffffff : PCI00 LMMIO
1189 * f05d0000-f05d0000 : lcd_data
1190 * f05d0008-f05d0008 : lcd_cmd
1191 * f1000000-f1ffffff : PCI01 LMMIO
1192 * f4000000-f4ffffff : PCI02 LMMIO
1193 * f4000000-f4001fff : sym53c8xx
1194 * f4002000-f4003fff : sym53c8xx
1195 * f4004000-f40043ff : sym53c8xx
1196 * f4005000-f40053ff : sym53c8xx
1197 * f4007000-f4007fff : ohci_hcd
1198 * f4008000-f40083ff : tulip
1199 * f6000000-f6ffffff : PCI03 LMMIO
1200 * f8000000-fbffffff : PCI00 ELMMIO
1201 * fa100000-fa4fffff : stifb mmio
1202 * fb000000-fb1fffff : stifb fb
1204 * But everything listed under PCI02 actually lives under PCI00.
1205 * This is clearly wrong.
1207 * Asking SBA how things are routed tells the correct story:
1208 * LMMIO_BASE/MASK/ROUTE f4000001 fc000000 00000000
1209 * DIR0_BASE/MASK/ROUTE fa000001 fe000000 00000006
1210 * DIR1_BASE/MASK/ROUTE f9000001 ff000000 00000004
1211 * DIR2_BASE/MASK/ROUTE f0000000 fc000000 00000000
1212 * DIR3_BASE/MASK/ROUTE f0000000 fc000000 00000000
1214 * Which looks like this in /proc/iomem:
1215 * f4000000-f47fffff : PCI00 LMMIO
1216 * f4000000-f4001fff : sym53c8xx
1217 * ...[deteled core devices - same as above]...
1218 * f4008000-f40083ff : tulip
1219 * f4800000-f4ffffff : PCI01 LMMIO
1220 * f6000000-f67fffff : PCI02 LMMIO
1221 * f7000000-f77fffff : PCI03 LMMIO
1222 * f9000000-f9ffffff : PCI02 ELMMIO
1223 * fa000000-fbffffff : PCI03 ELMMIO
1224 * fa100000-fa4fffff : stifb mmio
1225 * fb000000-fb1fffff : stifb fb
1227 * ie all Built-in core are under now correctly under PCI00.
1228 * The "PCI02 ELMMIO" directed range is for:
1229 * +-[02]---03.0 3Dfx Interactive, Inc. Voodoo 2
1231 * All is well now.
1233 r->start = READ_REG32(lba_dev->hba.base_addr + LBA_LMMIO_BASE);
1234 if (r->start & 1) {
1235 unsigned long rsize;
1237 r->flags = IORESOURCE_MEM;
1238 /* mmio_mask also clears Enable bit */
1239 r->start &= mmio_mask;
1240 r->start = PCI_HOST_ADDR(HBA_DATA(lba_dev), r->start);
1241 rsize = ~ READ_REG32(lba_dev->hba.base_addr + LBA_LMMIO_MASK);
1244 ** Each rope only gets part of the distributed range.
1245 ** Adjust "window" for this rope.
1247 rsize /= ROPES_PER_IOC;
1248 r->start += (rsize + 1) * LBA_NUM(pa_dev->hpa.start);
1249 r->end = r->start + rsize;
1250 } else {
1251 r->end = r->start = 0; /* Not enabled. */
1253 #endif
1256 ** "Directed" ranges are used when the "distributed range" isn't
1257 ** sufficient for all devices below a given LBA. Typically devices
1258 ** like graphics cards or X25 may need a directed range when the
1259 ** bus has multiple slots (ie multiple devices) or the device
1260 ** needs more than the typical 4 or 8MB a distributed range offers.
1262 ** The main reason for ignoring it now frigging complications.
1263 ** Directed ranges may overlap (and have precedence) over
1264 ** distributed ranges. Or a distributed range assigned to a unused
1265 ** rope may be used by a directed range on a different rope.
1266 ** Support for graphics devices may require fixing this
1267 ** since they may be assigned a directed range which overlaps
1268 ** an existing (but unused portion of) distributed range.
1270 r = &(lba_dev->hba.elmmio_space);
1271 sprintf(lba_dev->hba.elmmio_name, "PCI%02x ELMMIO",
1272 (int)lba_dev->hba.bus_num.start);
1273 r->name = lba_dev->hba.elmmio_name;
1275 #if 1
1276 /* See comment which precedes call to sba_directed_lmmio() */
1277 sba_directed_lmmio(pa_dev, r);
1278 #else
1279 r->start = READ_REG32(lba_dev->hba.base_addr + LBA_ELMMIO_BASE);
1281 if (r->start & 1) {
1282 unsigned long rsize;
1283 r->flags = IORESOURCE_MEM;
1284 /* mmio_mask also clears Enable bit */
1285 r->start &= mmio_mask;
1286 r->start = PCI_HOST_ADDR(HBA_DATA(lba_dev), r->start);
1287 rsize = READ_REG32(lba_dev->hba.base_addr + LBA_ELMMIO_MASK);
1288 r->end = r->start + ~rsize;
1290 #endif
1292 r = &(lba_dev->hba.io_space);
1293 sprintf(lba_dev->hba.io_name, "PCI%02x Ports",
1294 (int)lba_dev->hba.bus_num.start);
1295 r->name = lba_dev->hba.io_name;
1296 r->flags = IORESOURCE_IO;
1297 r->start = READ_REG32(lba_dev->hba.base_addr + LBA_IOS_BASE) & ~1L;
1298 r->end = r->start + (READ_REG32(lba_dev->hba.base_addr + LBA_IOS_MASK) ^ (HBA_PORT_SPACE_SIZE - 1));
1300 /* Virtualize the I/O Port space ranges */
1301 lba_num = HBA_PORT_BASE(lba_dev->hba.hba_num);
1302 r->start |= lba_num;
1303 r->end |= lba_num;
1307 /**************************************************************************
1309 ** LBA initialization code (HW and SW)
1311 ** o identify LBA chip itself
1312 ** o initialize LBA chip modes (HardFail)
1313 ** o FIXME: initialize DMA hints for reasonable defaults
1314 ** o enable configuration functions
1315 ** o call pci_register_ops() to discover devs (fixup/fixup_bus get invoked)
1317 **************************************************************************/
1319 static int __init
1320 lba_hw_init(struct lba_device *d)
1322 u32 stat;
1323 u32 bus_reset; /* PDC_PAT_BUG */
1325 #if 0
1326 printk(KERN_DEBUG "LBA %lx STAT_CTL %Lx ERROR_CFG %Lx STATUS %Lx DMA_CTL %Lx\n",
1327 d->hba.base_addr,
1328 READ_REG64(d->hba.base_addr + LBA_STAT_CTL),
1329 READ_REG64(d->hba.base_addr + LBA_ERROR_CONFIG),
1330 READ_REG64(d->hba.base_addr + LBA_ERROR_STATUS),
1331 READ_REG64(d->hba.base_addr + LBA_DMA_CTL) );
1332 printk(KERN_DEBUG " ARB mask %Lx pri %Lx mode %Lx mtlt %Lx\n",
1333 READ_REG64(d->hba.base_addr + LBA_ARB_MASK),
1334 READ_REG64(d->hba.base_addr + LBA_ARB_PRI),
1335 READ_REG64(d->hba.base_addr + LBA_ARB_MODE),
1336 READ_REG64(d->hba.base_addr + LBA_ARB_MTLT) );
1337 printk(KERN_DEBUG " HINT cfg 0x%Lx\n",
1338 READ_REG64(d->hba.base_addr + LBA_HINT_CFG));
1339 printk(KERN_DEBUG " HINT reg ");
1340 { int i;
1341 for (i=LBA_HINT_BASE; i< (14*8 + LBA_HINT_BASE); i+=8)
1342 printk(" %Lx", READ_REG64(d->hba.base_addr + i));
1344 printk("\n");
1345 #endif /* DEBUG_LBA_PAT */
1347 #ifdef CONFIG_64BIT
1349 * FIXME add support for PDC_PAT_IO "Get slot status" - OLAR support
1350 * Only N-Class and up can really make use of Get slot status.
1351 * maybe L-class too but I've never played with it there.
1353 #endif
1355 /* PDC_PAT_BUG: exhibited in rev 40.48 on L2000 */
1356 bus_reset = READ_REG32(d->hba.base_addr + LBA_STAT_CTL + 4) & 1;
1357 if (bus_reset) {
1358 printk(KERN_DEBUG "NOTICE: PCI bus reset still asserted! (clearing)\n");
1361 stat = READ_REG32(d->hba.base_addr + LBA_ERROR_CONFIG);
1362 if (stat & LBA_SMART_MODE) {
1363 printk(KERN_DEBUG "NOTICE: LBA in SMART mode! (cleared)\n");
1364 stat &= ~LBA_SMART_MODE;
1365 WRITE_REG32(stat, d->hba.base_addr + LBA_ERROR_CONFIG);
1370 * Hard Fail vs. Soft Fail on PCI "Master Abort".
1372 * "Master Abort" means the MMIO transaction timed out - usually due to
1373 * the device not responding to an MMIO read. We would like HF to be
1374 * enabled to find driver problems, though it means the system will
1375 * crash with a HPMC.
1377 * In SoftFail mode "~0L" is returned as a result of a timeout on the
1378 * pci bus. This is like how PCI busses on x86 and most other
1379 * architectures behave. In order to increase compatibility with
1380 * existing (x86) PCI hardware and existing Linux drivers we enable
1381 * Soft Faul mode on PA-RISC now too.
1383 stat = READ_REG32(d->hba.base_addr + LBA_STAT_CTL);
1384 #if defined(ENABLE_HARDFAIL)
1385 WRITE_REG32(stat | HF_ENABLE, d->hba.base_addr + LBA_STAT_CTL);
1386 #else
1387 WRITE_REG32(stat & ~HF_ENABLE, d->hba.base_addr + LBA_STAT_CTL);
1388 #endif
1391 ** Writing a zero to STAT_CTL.rf (bit 0) will clear reset signal
1392 ** if it's not already set. If we just cleared the PCI Bus Reset
1393 ** signal, wait a bit for the PCI devices to recover and setup.
1395 if (bus_reset)
1396 mdelay(pci_post_reset_delay);
1398 if (0 == READ_REG32(d->hba.base_addr + LBA_ARB_MASK)) {
1400 ** PDC_PAT_BUG: PDC rev 40.48 on L2000.
1401 ** B2000/C3600/J6000 also have this problem?
1403 ** Elroys with hot pluggable slots don't get configured
1404 ** correctly if the slot is empty. ARB_MASK is set to 0
1405 ** and we can't master transactions on the bus if it's
1406 ** not at least one. 0x3 enables elroy and first slot.
1408 printk(KERN_DEBUG "NOTICE: Enabling PCI Arbitration\n");
1409 WRITE_REG32(0x3, d->hba.base_addr + LBA_ARB_MASK);
1413 ** FIXME: Hint registers are programmed with default hint
1414 ** values by firmware. Hints should be sane even if we
1415 ** can't reprogram them the way drivers want.
1417 return 0;
1421 * Unfortunately, when firmware numbers busses, it doesn't take into account
1422 * Cardbus bridges. So we have to renumber the busses to suit ourselves.
1423 * Elroy/Mercury don't actually know what bus number they're attached to;
1424 * we use bus 0 to indicate the directly attached bus and any other bus
1425 * number will be taken care of by the PCI-PCI bridge.
1427 static unsigned int lba_next_bus = 0;
1430 * Determine if lba should claim this chip (return 0) or not (return 1).
1431 * If so, initialize the chip and tell other partners in crime they
1432 * have work to do.
1434 static int __init
1435 lba_driver_probe(struct parisc_device *dev)
1437 struct lba_device *lba_dev;
1438 LIST_HEAD(resources);
1439 struct pci_bus *lba_bus;
1440 struct pci_ops *cfg_ops;
1441 u32 func_class;
1442 void *tmp_obj;
1443 char *version;
1444 void __iomem *addr = ioremap_nocache(dev->hpa.start, 4096);
1445 int max;
1447 /* Read HW Rev First */
1448 func_class = READ_REG32(addr + LBA_FCLASS);
1450 if (IS_ELROY(dev)) {
1451 func_class &= 0xf;
1452 switch (func_class) {
1453 case 0: version = "TR1.0"; break;
1454 case 1: version = "TR2.0"; break;
1455 case 2: version = "TR2.1"; break;
1456 case 3: version = "TR2.2"; break;
1457 case 4: version = "TR3.0"; break;
1458 case 5: version = "TR4.0"; break;
1459 default: version = "TR4+";
1462 printk(KERN_INFO "Elroy version %s (0x%x) found at 0x%lx\n",
1463 version, func_class & 0xf, (long)dev->hpa.start);
1465 if (func_class < 2) {
1466 printk(KERN_WARNING "Can't support LBA older than "
1467 "TR2.1 - continuing under adversity.\n");
1470 #if 0
1471 /* Elroy TR4.0 should work with simple algorithm.
1472 But it doesn't. Still missing something. *sigh*
1474 if (func_class > 4) {
1475 cfg_ops = &mercury_cfg_ops;
1476 } else
1477 #endif
1479 cfg_ops = &elroy_cfg_ops;
1482 } else if (IS_MERCURY(dev) || IS_QUICKSILVER(dev)) {
1483 int major, minor;
1485 func_class &= 0xff;
1486 major = func_class >> 4, minor = func_class & 0xf;
1488 /* We could use one printk for both Elroy and Mercury,
1489 * but for the mask for func_class.
1491 printk(KERN_INFO "%s version TR%d.%d (0x%x) found at 0x%lx\n",
1492 IS_MERCURY(dev) ? "Mercury" : "Quicksilver", major,
1493 minor, func_class, (long)dev->hpa.start);
1495 cfg_ops = &mercury_cfg_ops;
1496 } else {
1497 printk(KERN_ERR "Unknown LBA found at 0x%lx\n",
1498 (long)dev->hpa.start);
1499 return -ENODEV;
1502 /* Tell I/O SAPIC driver we have a IRQ handler/region. */
1503 tmp_obj = iosapic_register(dev->hpa.start + LBA_IOSAPIC_BASE);
1505 /* NOTE: PCI devices (e.g. 103c:1005 graphics card) which don't
1506 ** have an IRT entry will get NULL back from iosapic code.
1509 lba_dev = kzalloc(sizeof(struct lba_device), GFP_KERNEL);
1510 if (!lba_dev) {
1511 printk(KERN_ERR "lba_init_chip - couldn't alloc lba_device\n");
1512 return(1);
1516 /* ---------- First : initialize data we already have --------- */
1518 lba_dev->hw_rev = func_class;
1519 lba_dev->hba.base_addr = addr;
1520 lba_dev->hba.dev = dev;
1521 lba_dev->iosapic_obj = tmp_obj; /* save interrupt handle */
1522 lba_dev->hba.iommu = sba_get_iommu(dev); /* get iommu data */
1523 parisc_set_drvdata(dev, lba_dev);
1525 /* ------------ Second : initialize common stuff ---------- */
1526 pci_bios = &lba_bios_ops;
1527 pcibios_register_hba(HBA_DATA(lba_dev));
1528 spin_lock_init(&lba_dev->lba_lock);
1530 if (lba_hw_init(lba_dev))
1531 return(1);
1533 /* ---------- Third : setup I/O Port and MMIO resources --------- */
1535 if (is_pdc_pat()) {
1536 /* PDC PAT firmware uses PIOP region of GMMIO space. */
1537 pci_port = &lba_pat_port_ops;
1538 /* Go ask PDC PAT what resources this LBA has */
1539 lba_pat_resources(dev, lba_dev);
1540 } else {
1541 if (!astro_iop_base) {
1542 /* Sprockets PDC uses NPIOP region */
1543 astro_iop_base = ioremap_nocache(LBA_PORT_BASE, 64 * 1024);
1544 pci_port = &lba_astro_port_ops;
1547 /* Poke the chip a bit for /proc output */
1548 lba_legacy_resources(dev, lba_dev);
1551 if (lba_dev->hba.bus_num.start < lba_next_bus)
1552 lba_dev->hba.bus_num.start = lba_next_bus;
1554 /* Overlaps with elmmio can (and should) fail here.
1555 * We will prune (or ignore) the distributed range.
1557 * FIXME: SBA code should register all elmmio ranges first.
1558 * that would take care of elmmio ranges routed
1559 * to a different rope (already discovered) from
1560 * getting registered *after* LBA code has already
1561 * registered it's distributed lmmio range.
1563 if (truncate_pat_collision(&iomem_resource,
1564 &(lba_dev->hba.lmmio_space))) {
1565 printk(KERN_WARNING "LBA: lmmio_space [%lx/%lx] duplicate!\n",
1566 (long)lba_dev->hba.lmmio_space.start,
1567 (long)lba_dev->hba.lmmio_space.end);
1568 lba_dev->hba.lmmio_space.flags = 0;
1571 pci_add_resource_offset(&resources, &lba_dev->hba.io_space,
1572 HBA_PORT_BASE(lba_dev->hba.hba_num));
1573 if (lba_dev->hba.elmmio_space.flags)
1574 pci_add_resource_offset(&resources, &lba_dev->hba.elmmio_space,
1575 lba_dev->hba.lmmio_space_offset);
1576 if (lba_dev->hba.lmmio_space.flags)
1577 pci_add_resource_offset(&resources, &lba_dev->hba.lmmio_space,
1578 lba_dev->hba.lmmio_space_offset);
1579 if (lba_dev->hba.gmmio_space.flags) {
1580 /* Not registering GMMIO space - according to docs it's not
1581 * even used on HP-UX. */
1582 /* pci_add_resource(&resources, &lba_dev->hba.gmmio_space); */
1585 pci_add_resource(&resources, &lba_dev->hba.bus_num);
1587 dev->dev.platform_data = lba_dev;
1588 lba_bus = lba_dev->hba.hba_bus =
1589 pci_create_root_bus(&dev->dev, lba_dev->hba.bus_num.start,
1590 cfg_ops, NULL, &resources);
1591 if (!lba_bus) {
1592 pci_free_resource_list(&resources);
1593 return 0;
1596 max = pci_scan_child_bus(lba_bus);
1598 /* This is in lieu of calling pci_assign_unassigned_resources() */
1599 if (is_pdc_pat()) {
1600 /* assign resources to un-initialized devices */
1602 DBG_PAT("LBA pci_bus_size_bridges()\n");
1603 pci_bus_size_bridges(lba_bus);
1605 DBG_PAT("LBA pci_bus_assign_resources()\n");
1606 pci_bus_assign_resources(lba_bus);
1608 #ifdef DEBUG_LBA_PAT
1609 DBG_PAT("\nLBA PIOP resource tree\n");
1610 lba_dump_res(&lba_dev->hba.io_space, 2);
1611 DBG_PAT("\nLBA LMMIO resource tree\n");
1612 lba_dump_res(&lba_dev->hba.lmmio_space, 2);
1613 #endif
1617 ** Once PCI register ops has walked the bus, access to config
1618 ** space is restricted. Avoids master aborts on config cycles.
1619 ** Early LBA revs go fatal on *any* master abort.
1621 if (cfg_ops == &elroy_cfg_ops) {
1622 lba_dev->flags |= LBA_FLAG_SKIP_PROBE;
1625 lba_next_bus = max + 1;
1626 pci_bus_add_devices(lba_bus);
1628 /* Whew! Finally done! Tell services we got this one covered. */
1629 return 0;
1632 static struct parisc_device_id lba_tbl[] = {
1633 { HPHW_BRIDGE, HVERSION_REV_ANY_ID, ELROY_HVERS, 0xa },
1634 { HPHW_BRIDGE, HVERSION_REV_ANY_ID, MERCURY_HVERS, 0xa },
1635 { HPHW_BRIDGE, HVERSION_REV_ANY_ID, QUICKSILVER_HVERS, 0xa },
1636 { 0, }
1639 static struct parisc_driver lba_driver = {
1640 .name = MODULE_NAME,
1641 .id_table = lba_tbl,
1642 .probe = lba_driver_probe,
1646 ** One time initialization to let the world know the LBA was found.
1647 ** Must be called exactly once before pci_init().
1649 void __init lba_init(void)
1651 register_parisc_driver(&lba_driver);
1655 ** Initialize the IBASE/IMASK registers for LBA (Elroy).
1656 ** Only called from sba_iommu.c in order to route ranges (MMIO vs DMA).
1657 ** sba_iommu is responsible for locking (none needed at init time).
1659 void lba_set_iregs(struct parisc_device *lba, u32 ibase, u32 imask)
1661 void __iomem * base_addr = ioremap_nocache(lba->hpa.start, 4096);
1663 imask <<= 2; /* adjust for hints - 2 more bits */
1665 /* Make sure we aren't trying to set bits that aren't writeable. */
1666 WARN_ON((ibase & 0x001fffff) != 0);
1667 WARN_ON((imask & 0x001fffff) != 0);
1669 DBG("%s() ibase 0x%x imask 0x%x\n", __func__, ibase, imask);
1670 WRITE_REG32( imask, base_addr + LBA_IMASK);
1671 WRITE_REG32( ibase, base_addr + LBA_IBASE);
1672 iounmap(base_addr);
1677 * The design of the Diva management card in rp34x0 machines (rp3410, rp3440)
1678 * seems rushed, so that many built-in components simply don't work.
1679 * The following quirks disable the serial AUX port and the built-in ATI RV100
1680 * Radeon 7000 graphics card which both don't have any external connectors and
1681 * thus are useless, and even worse, e.g. the AUX port occupies ttyS0 and as
1682 * such makes those machines the only PARISC machines on which we can't use
1683 * ttyS0 as boot console.
1685 static void quirk_diva_ati_card(struct pci_dev *dev)
1687 if (dev->subsystem_vendor != PCI_VENDOR_ID_HP ||
1688 dev->subsystem_device != 0x1292)
1689 return;
1691 dev_info(&dev->dev, "Hiding Diva built-in ATI card");
1692 dev->device = 0;
1694 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_ATI, PCI_DEVICE_ID_ATI_RADEON_QY,
1695 quirk_diva_ati_card);
1697 static void quirk_diva_aux_disable(struct pci_dev *dev)
1699 if (dev->subsystem_vendor != PCI_VENDOR_ID_HP ||
1700 dev->subsystem_device != 0x1291)
1701 return;
1703 dev_info(&dev->dev, "Hiding Diva built-in AUX serial device");
1704 dev->device = 0;
1706 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_HP, PCI_DEVICE_ID_HP_DIVA_AUX,
1707 quirk_diva_aux_disable);