1 // SPDX-License-Identifier: GPL-2.0
2 /*
3 * Management Component Transport Protocol (MCTP) - serial transport
4 * binding. This driver is an implementation of the DMTF specificiation
5 * "DSP0253 - Management Component Transport Protocol (MCTP) Serial Transport
6 * Binding", available at:
7 *
8 * https://www.dmtf.org/sites/default/files/standards/documents/DSP0253_1.0.0.pdf
9 *
10 * This driver provides DSP0253-type MCTP-over-serial transport using a Linux
11 * tty device, by setting the N_MCTP line discipline on the tty.
12 *
13 * Copyright (c) 2021 Code Construct
14 */
15
16 #include <linux/idr.h>
17 #include <linux/if_arp.h>
18 #include <linux/module.h>
19 #include <linux/skbuff.h>
20 #include <linux/tty.h>
21 #include <linux/workqueue.h>
22 #include <linux/crc-ccitt.h>
23
24 #include <linux/mctp.h>
25 #include <net/mctp.h>
26 #include <net/mctpdevice.h>
27 #include <net/pkt_sched.h>
28
29 #define MCTP_SERIAL_MTU 68 /* base mtu (64) + mctp header */
30 #define MCTP_SERIAL_FRAME_MTU (MCTP_SERIAL_MTU + 6) /* + serial framing */
31
32 #define MCTP_SERIAL_VERSION 0x1 /* DSP0253 defines a single version: 1 */
33
34 #define BUFSIZE MCTP_SERIAL_FRAME_MTU
35
36 #define BYTE_FRAME 0x7e
37 #define BYTE_ESC 0x7d
38
39 #define FCS_INIT 0xffff
40
41 static DEFINE_IDA(mctp_serial_ida);
42
43 enum mctp_serial_state {
44 STATE_IDLE,
45 STATE_START,
46 STATE_HEADER,
47 STATE_DATA,
48 STATE_ESCAPE,
49 STATE_TRAILER,
50 STATE_DONE,
51 STATE_ERR,
52 };
53
54 struct mctp_serial {
55 struct net_device *netdev;
56 struct tty_struct *tty;
57
58 int idx;
59
60 /* protects our rx & tx state machines; held during both paths */
61 spinlock_t lock;
62
63 struct work_struct tx_work;
64 enum mctp_serial_state txstate, rxstate;
65 u16 txfcs, rxfcs, rxfcs_rcvd;
66 unsigned int txlen, rxlen;
67 unsigned int txpos, rxpos;
68 unsigned char txbuf[BUFSIZE],
69 rxbuf[BUFSIZE];
70 };
71
needs_escape(unsigned char c)72 static bool needs_escape(unsigned char c)
73 {
74 return c == BYTE_ESC || c == BYTE_FRAME;
75 }
76
next_chunk_len(struct mctp_serial * dev)77 static int next_chunk_len(struct mctp_serial *dev)
78 {
79 int i;
80
81 /* either we have no bytes to send ... */
82 if (dev->txpos == dev->txlen)
83 return 0;
84
85 /* ... or the next byte to send is an escaped byte; requiring a
86 * single-byte chunk...
87 */
88 if (needs_escape(dev->txbuf[dev->txpos]))
89 return 1;
90
91 /* ... or we have one or more bytes up to the next escape - this chunk
92 * will be those non-escaped bytes, and does not include the escaped
93 * byte.
94 */
95 for (i = 1; i + dev->txpos < dev->txlen; i++) {
96 if (needs_escape(dev->txbuf[dev->txpos + i]))
97 break;
98 }
99
100 return i;
101 }
102
write_chunk(struct mctp_serial * dev,unsigned char * buf,int len)103 static int write_chunk(struct mctp_serial *dev, unsigned char *buf, int len)
104 {
105 return dev->tty->ops->write(dev->tty, buf, len);
106 }
107
mctp_serial_tx_work(struct work_struct * work)108 static void mctp_serial_tx_work(struct work_struct *work)
109 {
110 struct mctp_serial *dev = container_of(work, struct mctp_serial,
111 tx_work);
112 unsigned char c, buf[3];
113 unsigned long flags;
114 int len, txlen;
115
116 spin_lock_irqsave(&dev->lock, flags);
117
118 /* txstate represents the next thing to send */
119 switch (dev->txstate) {
120 case STATE_START:
121 dev->txpos = 0;
122 fallthrough;
123 case STATE_HEADER:
124 buf[0] = BYTE_FRAME;
125 buf[1] = MCTP_SERIAL_VERSION;
126 buf[2] = dev->txlen;
127
128 if (!dev->txpos)
129 dev->txfcs = crc_ccitt(FCS_INIT, buf + 1, 2);
130
131 txlen = write_chunk(dev, buf + dev->txpos, 3 - dev->txpos);
132 if (txlen <= 0) {
133 dev->txstate = STATE_ERR;
134 } else {
135 dev->txpos += txlen;
136 if (dev->txpos == 3) {
137 dev->txstate = STATE_DATA;
138 dev->txpos = 0;
139 }
140 }
141 break;
142
143 case STATE_ESCAPE:
144 buf[0] = dev->txbuf[dev->txpos] & ~0x20;
145 txlen = write_chunk(dev, buf, 1);
146 if (txlen <= 0) {
147 dev->txstate = STATE_ERR;
148 } else {
149 dev->txpos += txlen;
150 if (dev->txpos == dev->txlen) {
151 dev->txstate = STATE_TRAILER;
152 dev->txpos = 0;
153 }
154 }
155
156 break;
157
158 case STATE_DATA:
159 len = next_chunk_len(dev);
160 if (len) {
161 c = dev->txbuf[dev->txpos];
162 if (len == 1 && needs_escape(c)) {
163 buf[0] = BYTE_ESC;
164 buf[1] = c & ~0x20;
165 dev->txfcs = crc_ccitt_byte(dev->txfcs, c);
166 txlen = write_chunk(dev, buf, 2);
167 if (txlen == 2)
168 dev->txpos++;
169 else if (txlen == 1)
170 dev->txstate = STATE_ESCAPE;
171 else
172 dev->txstate = STATE_ERR;
173 } else {
174 txlen = write_chunk(dev,
175 dev->txbuf + dev->txpos,
176 len);
177 if (txlen <= 0) {
178 dev->txstate = STATE_ERR;
179 } else {
180 dev->txfcs = crc_ccitt(dev->txfcs,
181 dev->txbuf +
182 dev->txpos,
183 txlen);
184 dev->txpos += txlen;
185 }
186 }
187 if (dev->txstate == STATE_DATA &&
188 dev->txpos == dev->txlen) {
189 dev->txstate = STATE_TRAILER;
190 dev->txpos = 0;
191 }
192 break;
193 }
194 dev->txstate = STATE_TRAILER;
195 dev->txpos = 0;
196 fallthrough;
197
198 case STATE_TRAILER:
199 buf[0] = dev->txfcs >> 8;
200 buf[1] = dev->txfcs & 0xff;
201 buf[2] = BYTE_FRAME;
202 txlen = write_chunk(dev, buf + dev->txpos, 3 - dev->txpos);
203 if (txlen <= 0) {
204 dev->txstate = STATE_ERR;
205 } else {
206 dev->txpos += txlen;
207 if (dev->txpos == 3) {
208 dev->txstate = STATE_DONE;
209 dev->txpos = 0;
210 }
211 }
212 break;
213 default:
214 netdev_err_once(dev->netdev, "invalid tx state %d\n",
215 dev->txstate);
216 }
217
218 if (dev->txstate == STATE_DONE) {
219 dev->netdev->stats.tx_packets++;
220 dev->netdev->stats.tx_bytes += dev->txlen;
221 dev->txlen = 0;
222 dev->txpos = 0;
223 clear_bit(TTY_DO_WRITE_WAKEUP, &dev->tty->flags);
224 dev->txstate = STATE_IDLE;
225 spin_unlock_irqrestore(&dev->lock, flags);
226
227 netif_wake_queue(dev->netdev);
228 } else {
229 spin_unlock_irqrestore(&dev->lock, flags);
230 }
231 }
232
mctp_serial_tx(struct sk_buff * skb,struct net_device * ndev)233 static netdev_tx_t mctp_serial_tx(struct sk_buff *skb, struct net_device *ndev)
234 {
235 struct mctp_serial *dev = netdev_priv(ndev);
236 unsigned long flags;
237
238 WARN_ON(dev->txstate != STATE_IDLE);
239
240 if (skb->len > MCTP_SERIAL_MTU) {
241 dev->netdev->stats.tx_dropped++;
242 goto out;
243 }
244
245 spin_lock_irqsave(&dev->lock, flags);
246 netif_stop_queue(dev->netdev);
247 skb_copy_bits(skb, 0, dev->txbuf, skb->len);
248 dev->txpos = 0;
249 dev->txlen = skb->len;
250 dev->txstate = STATE_START;
251 spin_unlock_irqrestore(&dev->lock, flags);
252
253 set_bit(TTY_DO_WRITE_WAKEUP, &dev->tty->flags);
254 schedule_work(&dev->tx_work);
255
256 out:
257 kfree_skb(skb);
258 return NETDEV_TX_OK;
259 }
260
mctp_serial_tty_write_wakeup(struct tty_struct * tty)261 static void mctp_serial_tty_write_wakeup(struct tty_struct *tty)
262 {
263 struct mctp_serial *dev = tty->disc_data;
264
265 schedule_work(&dev->tx_work);
266 }
267
mctp_serial_rx(struct mctp_serial * dev)268 static void mctp_serial_rx(struct mctp_serial *dev)
269 {
270 struct mctp_skb_cb *cb;
271 struct sk_buff *skb;
272
273 if (dev->rxfcs != dev->rxfcs_rcvd) {
274 dev->netdev->stats.rx_dropped++;
275 dev->netdev->stats.rx_crc_errors++;
276 return;
277 }
278
279 skb = netdev_alloc_skb(dev->netdev, dev->rxlen);
280 if (!skb) {
281 dev->netdev->stats.rx_dropped++;
282 return;
283 }
284
285 skb->protocol = htons(ETH_P_MCTP);
286 skb_put_data(skb, dev->rxbuf, dev->rxlen);
287 skb_reset_network_header(skb);
288
289 cb = __mctp_cb(skb);
290 cb->halen = 0;
291
292 netif_rx(skb);
293 dev->netdev->stats.rx_packets++;
294 dev->netdev->stats.rx_bytes += dev->rxlen;
295 }
296
mctp_serial_push_header(struct mctp_serial * dev,unsigned char c)297 static void mctp_serial_push_header(struct mctp_serial *dev, unsigned char c)
298 {
299 switch (dev->rxpos) {
300 case 0:
301 if (c == BYTE_FRAME)
302 dev->rxpos++;
303 else
304 dev->rxstate = STATE_ERR;
305 break;
306 case 1:
307 if (c == MCTP_SERIAL_VERSION) {
308 dev->rxpos++;
309 dev->rxfcs = crc_ccitt_byte(FCS_INIT, c);
310 } else {
311 dev->rxstate = STATE_ERR;
312 }
313 break;
314 case 2:
315 if (c > MCTP_SERIAL_FRAME_MTU) {
316 dev->rxstate = STATE_ERR;
317 } else {
318 dev->rxlen = c;
319 dev->rxpos = 0;
320 dev->rxstate = STATE_DATA;
321 dev->rxfcs = crc_ccitt_byte(dev->rxfcs, c);
322 }
323 break;
324 }
325 }
326
mctp_serial_push_trailer(struct mctp_serial * dev,unsigned char c)327 static void mctp_serial_push_trailer(struct mctp_serial *dev, unsigned char c)
328 {
329 switch (dev->rxpos) {
330 case 0:
331 dev->rxfcs_rcvd = c << 8;
332 dev->rxpos++;
333 break;
334 case 1:
335 dev->rxfcs_rcvd |= c;
336 dev->rxpos++;
337 break;
338 case 2:
339 if (c != BYTE_FRAME) {
340 dev->rxstate = STATE_ERR;
341 } else {
342 mctp_serial_rx(dev);
343 dev->rxlen = 0;
344 dev->rxpos = 0;
345 dev->rxstate = STATE_IDLE;
346 }
347 break;
348 }
349 }
350
mctp_serial_push(struct mctp_serial * dev,unsigned char c)351 static void mctp_serial_push(struct mctp_serial *dev, unsigned char c)
352 {
353 switch (dev->rxstate) {
354 case STATE_IDLE:
355 dev->rxstate = STATE_HEADER;
356 fallthrough;
357 case STATE_HEADER:
358 mctp_serial_push_header(dev, c);
359 break;
360
361 case STATE_ESCAPE:
362 c |= 0x20;
363 fallthrough;
364 case STATE_DATA:
365 if (dev->rxstate != STATE_ESCAPE && c == BYTE_ESC) {
366 dev->rxstate = STATE_ESCAPE;
367 } else {
368 dev->rxfcs = crc_ccitt_byte(dev->rxfcs, c);
369 dev->rxbuf[dev->rxpos] = c;
370 dev->rxpos++;
371 dev->rxstate = STATE_DATA;
372 if (dev->rxpos == dev->rxlen) {
373 dev->rxpos = 0;
374 dev->rxstate = STATE_TRAILER;
375 }
376 }
377 break;
378
379 case STATE_TRAILER:
380 mctp_serial_push_trailer(dev, c);
381 break;
382
383 case STATE_ERR:
384 if (c == BYTE_FRAME)
385 dev->rxstate = STATE_IDLE;
386 break;
387
388 default:
389 netdev_err_once(dev->netdev, "invalid rx state %d\n",
390 dev->rxstate);
391 }
392 }
393
mctp_serial_tty_receive_buf(struct tty_struct * tty,const u8 * c,const u8 * f,size_t len)394 static void mctp_serial_tty_receive_buf(struct tty_struct *tty, const u8 *c,
395 const u8 *f, size_t len)
396 {
397 struct mctp_serial *dev = tty->disc_data;
398 int i;
399
400 if (!netif_running(dev->netdev))
401 return;
402
403 /* we don't (currently) use the flag bytes, just data. */
404 for (i = 0; i < len; i++)
405 mctp_serial_push(dev, c[i]);
406 }
407
mctp_serial_uninit(struct net_device * ndev)408 static void mctp_serial_uninit(struct net_device *ndev)
409 {
410 struct mctp_serial *dev = netdev_priv(ndev);
411
412 cancel_work_sync(&dev->tx_work);
413 }
414
415 static const struct net_device_ops mctp_serial_netdev_ops = {
416 .ndo_start_xmit = mctp_serial_tx,
417 .ndo_uninit = mctp_serial_uninit,
418 };
419
mctp_serial_setup(struct net_device * ndev)420 static void mctp_serial_setup(struct net_device *ndev)
421 {
422 ndev->type = ARPHRD_MCTP;
423
424 /* we limit at the fixed MTU, which is also the MCTP-standard
425 * baseline MTU, so is also our minimum
426 */
427 ndev->mtu = MCTP_SERIAL_MTU;
428 ndev->max_mtu = MCTP_SERIAL_MTU;
429 ndev->min_mtu = MCTP_SERIAL_MTU;
430
431 ndev->hard_header_len = 0;
432 ndev->addr_len = 0;
433 ndev->tx_queue_len = DEFAULT_TX_QUEUE_LEN;
434 ndev->flags = IFF_NOARP;
435 ndev->netdev_ops = &mctp_serial_netdev_ops;
436 ndev->needs_free_netdev = true;
437 }
438
mctp_serial_open(struct tty_struct * tty)439 static int mctp_serial_open(struct tty_struct *tty)
440 {
441 struct mctp_serial *dev;
442 struct net_device *ndev;
443 char name[32];
444 int idx, rc;
445
446 if (!capable(CAP_NET_ADMIN))
447 return -EPERM;
448
449 if (!tty->ops->write)
450 return -EOPNOTSUPP;
451
452 idx = ida_alloc(&mctp_serial_ida, GFP_KERNEL);
453 if (idx < 0)
454 return idx;
455
456 snprintf(name, sizeof(name), "mctpserial%d", idx);
457 ndev = alloc_netdev(sizeof(*dev), name, NET_NAME_ENUM,
458 mctp_serial_setup);
459 if (!ndev) {
460 rc = -ENOMEM;
461 goto free_ida;
462 }
463
464 dev = netdev_priv(ndev);
465 dev->idx = idx;
466 dev->tty = tty;
467 dev->netdev = ndev;
468 dev->txstate = STATE_IDLE;
469 dev->rxstate = STATE_IDLE;
470 spin_lock_init(&dev->lock);
471 INIT_WORK(&dev->tx_work, mctp_serial_tx_work);
472
473 rc = mctp_register_netdev(ndev, NULL, MCTP_PHYS_BINDING_SERIAL);
474 if (rc)
475 goto free_netdev;
476
477 tty->receive_room = 64 * 1024;
478 tty->disc_data = dev;
479
480 return 0;
481
482 free_netdev:
483 free_netdev(ndev);
484
485 free_ida:
486 ida_free(&mctp_serial_ida, idx);
487 return rc;
488 }
489
mctp_serial_close(struct tty_struct * tty)490 static void mctp_serial_close(struct tty_struct *tty)
491 {
492 struct mctp_serial *dev = tty->disc_data;
493 int idx = dev->idx;
494
495 mctp_unregister_netdev(dev->netdev);
496 ida_free(&mctp_serial_ida, idx);
497 }
498
499 static struct tty_ldisc_ops mctp_ldisc = {
500 .owner = THIS_MODULE,
501 .num = N_MCTP,
502 .name = "mctp",
503 .open = mctp_serial_open,
504 .close = mctp_serial_close,
505 .receive_buf = mctp_serial_tty_receive_buf,
506 .write_wakeup = mctp_serial_tty_write_wakeup,
507 };
508
mctp_serial_init(void)509 static int __init mctp_serial_init(void)
510 {
511 return tty_register_ldisc(&mctp_ldisc);
512 }
513
mctp_serial_exit(void)514 static void __exit mctp_serial_exit(void)
515 {
516 tty_unregister_ldisc(&mctp_ldisc);
517 }
518
519 module_init(mctp_serial_init);
520 module_exit(mctp_serial_exit);
521
522 MODULE_LICENSE("GPL v2");
523 MODULE_AUTHOR("Jeremy Kerr <jk@codeconstruct.com.au>");
524 MODULE_DESCRIPTION("MCTP Serial transport");
525