1 /* 2 * 3 * Intel Management Engine Interface (Intel MEI) Linux driver 4 * Copyright (c) 2003-2012, Intel Corporation. 5 * 6 * This program is free software; you can redistribute it and/or modify it 7 * under the terms and conditions of the GNU General Public License, 8 * version 2, as published by the Free Software Foundation. 9 * 10 * This program is distributed in the hope it will be useful, but WITHOUT 11 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or 12 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for 13 * more details. 14 * 15 */ 16 17 #include <linux/sched.h> 18 #include <linux/wait.h> 19 #include <linux/delay.h> 20 #include <linux/slab.h> 21 #include <linux/pm_runtime.h> 22 23 #include <linux/mei.h> 24 25 #include "mei_dev.h" 26 #include "hbm.h" 27 #include "client.h" 28 29 /** 30 * mei_me_cl_init - initialize me client 31 * 32 * @me_cl: me client 33 */ 34 void mei_me_cl_init(struct mei_me_client *me_cl) 35 { 36 INIT_LIST_HEAD(&me_cl->list); 37 kref_init(&me_cl->refcnt); 38 } 39 40 /** 41 * mei_me_cl_get - increases me client refcount 42 * 43 * @me_cl: me client 44 * 45 * Locking: called under "dev->device_lock" lock 46 * 47 * Return: me client or NULL 48 */ 49 struct mei_me_client *mei_me_cl_get(struct mei_me_client *me_cl) 50 { 51 if (me_cl && kref_get_unless_zero(&me_cl->refcnt)) 52 return me_cl; 53 54 return NULL; 55 } 56 57 /** 58 * mei_me_cl_release - free me client 59 * 60 * Locking: called under "dev->device_lock" lock 61 * 62 * @ref: me_client refcount 63 */ 64 static void mei_me_cl_release(struct kref *ref) 65 { 66 struct mei_me_client *me_cl = 67 container_of(ref, struct mei_me_client, refcnt); 68 69 kfree(me_cl); 70 } 71 72 /** 73 * mei_me_cl_put - decrease me client refcount and free client if necessary 74 * 75 * Locking: called under "dev->device_lock" lock 76 * 77 * @me_cl: me client 78 */ 79 void mei_me_cl_put(struct mei_me_client *me_cl) 80 { 81 if (me_cl) 82 kref_put(&me_cl->refcnt, mei_me_cl_release); 83 } 84 85 /** 86 * __mei_me_cl_del - delete me client from the list and decrease 87 * reference counter 88 * 89 * @dev: mei device 90 * @me_cl: me client 91 * 92 * Locking: dev->me_clients_rwsem 93 */ 94 static void __mei_me_cl_del(struct mei_device *dev, struct mei_me_client *me_cl) 95 { 96 if (!me_cl) 97 return; 98 99 list_del_init(&me_cl->list); 100 mei_me_cl_put(me_cl); 101 } 102 103 /** 104 * mei_me_cl_del - delete me client from the list and decrease 105 * reference counter 106 * 107 * @dev: mei device 108 * @me_cl: me client 109 */ 110 void mei_me_cl_del(struct mei_device *dev, struct mei_me_client *me_cl) 111 { 112 down_write(&dev->me_clients_rwsem); 113 __mei_me_cl_del(dev, me_cl); 114 up_write(&dev->me_clients_rwsem); 115 } 116 117 /** 118 * mei_me_cl_add - add me client to the list 119 * 120 * @dev: mei device 121 * @me_cl: me client 122 */ 123 void mei_me_cl_add(struct mei_device *dev, struct mei_me_client *me_cl) 124 { 125 down_write(&dev->me_clients_rwsem); 126 list_add(&me_cl->list, &dev->me_clients); 127 up_write(&dev->me_clients_rwsem); 128 } 129 130 /** 131 * __mei_me_cl_by_uuid - locate me client by uuid 132 * increases ref count 133 * 134 * @dev: mei device 135 * @uuid: me client uuid 136 * 137 * Return: me client or NULL if not found 138 * 139 * Locking: dev->me_clients_rwsem 140 */ 141 static struct mei_me_client *__mei_me_cl_by_uuid(struct mei_device *dev, 142 const uuid_le *uuid) 143 { 144 struct mei_me_client *me_cl; 145 const uuid_le *pn; 146 147 WARN_ON(!rwsem_is_locked(&dev->me_clients_rwsem)); 148 149 list_for_each_entry(me_cl, &dev->me_clients, list) { 150 pn = &me_cl->props.protocol_name; 151 if (uuid_le_cmp(*uuid, *pn) == 0) 152 return mei_me_cl_get(me_cl); 153 } 154 155 return NULL; 156 } 157 158 /** 159 * mei_me_cl_by_uuid - locate me client by uuid 160 * increases ref count 161 * 162 * @dev: mei device 163 * @uuid: me client uuid 164 * 165 * Return: me client or NULL if not found 166 * 167 * Locking: dev->me_clients_rwsem 168 */ 169 struct mei_me_client *mei_me_cl_by_uuid(struct mei_device *dev, 170 const uuid_le *uuid) 171 { 172 struct mei_me_client *me_cl; 173 174 down_read(&dev->me_clients_rwsem); 175 me_cl = __mei_me_cl_by_uuid(dev, uuid); 176 up_read(&dev->me_clients_rwsem); 177 178 return me_cl; 179 } 180 181 /** 182 * mei_me_cl_by_id - locate me client by client id 183 * increases ref count 184 * 185 * @dev: the device structure 186 * @client_id: me client id 187 * 188 * Return: me client or NULL if not found 189 * 190 * Locking: dev->me_clients_rwsem 191 */ 192 struct mei_me_client *mei_me_cl_by_id(struct mei_device *dev, u8 client_id) 193 { 194 195 struct mei_me_client *__me_cl, *me_cl = NULL; 196 197 down_read(&dev->me_clients_rwsem); 198 list_for_each_entry(__me_cl, &dev->me_clients, list) { 199 if (__me_cl->client_id == client_id) { 200 me_cl = mei_me_cl_get(__me_cl); 201 break; 202 } 203 } 204 up_read(&dev->me_clients_rwsem); 205 206 return me_cl; 207 } 208 209 /** 210 * __mei_me_cl_by_uuid_id - locate me client by client id and uuid 211 * increases ref count 212 * 213 * @dev: the device structure 214 * @uuid: me client uuid 215 * @client_id: me client id 216 * 217 * Return: me client or null if not found 218 * 219 * Locking: dev->me_clients_rwsem 220 */ 221 static struct mei_me_client *__mei_me_cl_by_uuid_id(struct mei_device *dev, 222 const uuid_le *uuid, u8 client_id) 223 { 224 struct mei_me_client *me_cl; 225 const uuid_le *pn; 226 227 WARN_ON(!rwsem_is_locked(&dev->me_clients_rwsem)); 228 229 list_for_each_entry(me_cl, &dev->me_clients, list) { 230 pn = &me_cl->props.protocol_name; 231 if (uuid_le_cmp(*uuid, *pn) == 0 && 232 me_cl->client_id == client_id) 233 return mei_me_cl_get(me_cl); 234 } 235 236 return NULL; 237 } 238 239 240 /** 241 * mei_me_cl_by_uuid_id - locate me client by client id and uuid 242 * increases ref count 243 * 244 * @dev: the device structure 245 * @uuid: me client uuid 246 * @client_id: me client id 247 * 248 * Return: me client or null if not found 249 */ 250 struct mei_me_client *mei_me_cl_by_uuid_id(struct mei_device *dev, 251 const uuid_le *uuid, u8 client_id) 252 { 253 struct mei_me_client *me_cl; 254 255 down_read(&dev->me_clients_rwsem); 256 me_cl = __mei_me_cl_by_uuid_id(dev, uuid, client_id); 257 up_read(&dev->me_clients_rwsem); 258 259 return me_cl; 260 } 261 262 /** 263 * mei_me_cl_rm_by_uuid - remove all me clients matching uuid 264 * 265 * @dev: the device structure 266 * @uuid: me client uuid 267 * 268 * Locking: called under "dev->device_lock" lock 269 */ 270 void mei_me_cl_rm_by_uuid(struct mei_device *dev, const uuid_le *uuid) 271 { 272 struct mei_me_client *me_cl; 273 274 dev_dbg(dev->dev, "remove %pUl\n", uuid); 275 276 down_write(&dev->me_clients_rwsem); 277 me_cl = __mei_me_cl_by_uuid(dev, uuid); 278 __mei_me_cl_del(dev, me_cl); 279 up_write(&dev->me_clients_rwsem); 280 } 281 282 /** 283 * mei_me_cl_rm_by_uuid_id - remove all me clients matching client id 284 * 285 * @dev: the device structure 286 * @uuid: me client uuid 287 * @id: me client id 288 * 289 * Locking: called under "dev->device_lock" lock 290 */ 291 void mei_me_cl_rm_by_uuid_id(struct mei_device *dev, const uuid_le *uuid, u8 id) 292 { 293 struct mei_me_client *me_cl; 294 295 dev_dbg(dev->dev, "remove %pUl %d\n", uuid, id); 296 297 down_write(&dev->me_clients_rwsem); 298 me_cl = __mei_me_cl_by_uuid_id(dev, uuid, id); 299 __mei_me_cl_del(dev, me_cl); 300 up_write(&dev->me_clients_rwsem); 301 } 302 303 /** 304 * mei_me_cl_rm_all - remove all me clients 305 * 306 * @dev: the device structure 307 * 308 * Locking: called under "dev->device_lock" lock 309 */ 310 void mei_me_cl_rm_all(struct mei_device *dev) 311 { 312 struct mei_me_client *me_cl, *next; 313 314 down_write(&dev->me_clients_rwsem); 315 list_for_each_entry_safe(me_cl, next, &dev->me_clients, list) 316 __mei_me_cl_del(dev, me_cl); 317 up_write(&dev->me_clients_rwsem); 318 } 319 320 /** 321 * mei_cl_cmp_id - tells if the clients are the same 322 * 323 * @cl1: host client 1 324 * @cl2: host client 2 325 * 326 * Return: true - if the clients has same host and me ids 327 * false - otherwise 328 */ 329 static inline bool mei_cl_cmp_id(const struct mei_cl *cl1, 330 const struct mei_cl *cl2) 331 { 332 return cl1 && cl2 && 333 (cl1->host_client_id == cl2->host_client_id) && 334 (mei_cl_me_id(cl1) == mei_cl_me_id(cl2)); 335 } 336 337 /** 338 * mei_io_cb_free - free mei_cb_private related memory 339 * 340 * @cb: mei callback struct 341 */ 342 void mei_io_cb_free(struct mei_cl_cb *cb) 343 { 344 if (cb == NULL) 345 return; 346 347 list_del(&cb->list); 348 kfree(cb->buf.data); 349 kfree(cb); 350 } 351 352 /** 353 * mei_io_cb_init - allocate and initialize io callback 354 * 355 * @cl: mei client 356 * @type: operation type 357 * @fp: pointer to file structure 358 * 359 * Return: mei_cl_cb pointer or NULL; 360 */ 361 struct mei_cl_cb *mei_io_cb_init(struct mei_cl *cl, enum mei_cb_file_ops type, 362 struct file *fp) 363 { 364 struct mei_cl_cb *cb; 365 366 cb = kzalloc(sizeof(struct mei_cl_cb), GFP_KERNEL); 367 if (!cb) 368 return NULL; 369 370 INIT_LIST_HEAD(&cb->list); 371 cb->file_object = fp; 372 cb->cl = cl; 373 cb->buf_idx = 0; 374 cb->fop_type = type; 375 return cb; 376 } 377 378 /** 379 * __mei_io_list_flush - removes and frees cbs belonging to cl. 380 * 381 * @list: an instance of our list structure 382 * @cl: host client, can be NULL for flushing the whole list 383 * @free: whether to free the cbs 384 */ 385 static void __mei_io_list_flush(struct mei_cl_cb *list, 386 struct mei_cl *cl, bool free) 387 { 388 struct mei_cl_cb *cb, *next; 389 390 /* enable removing everything if no cl is specified */ 391 list_for_each_entry_safe(cb, next, &list->list, list) { 392 if (!cl || mei_cl_cmp_id(cl, cb->cl)) { 393 list_del_init(&cb->list); 394 if (free) 395 mei_io_cb_free(cb); 396 } 397 } 398 } 399 400 /** 401 * mei_io_list_flush - removes list entry belonging to cl. 402 * 403 * @list: An instance of our list structure 404 * @cl: host client 405 */ 406 void mei_io_list_flush(struct mei_cl_cb *list, struct mei_cl *cl) 407 { 408 __mei_io_list_flush(list, cl, false); 409 } 410 411 /** 412 * mei_io_list_free - removes cb belonging to cl and free them 413 * 414 * @list: An instance of our list structure 415 * @cl: host client 416 */ 417 static inline void mei_io_list_free(struct mei_cl_cb *list, struct mei_cl *cl) 418 { 419 __mei_io_list_flush(list, cl, true); 420 } 421 422 /** 423 * mei_io_cb_alloc_buf - allocate callback buffer 424 * 425 * @cb: io callback structure 426 * @length: size of the buffer 427 * 428 * Return: 0 on success 429 * -EINVAL if cb is NULL 430 * -ENOMEM if allocation failed 431 */ 432 int mei_io_cb_alloc_buf(struct mei_cl_cb *cb, size_t length) 433 { 434 if (!cb) 435 return -EINVAL; 436 437 if (length == 0) 438 return 0; 439 440 cb->buf.data = kmalloc(length, GFP_KERNEL); 441 if (!cb->buf.data) 442 return -ENOMEM; 443 cb->buf.size = length; 444 return 0; 445 } 446 447 /** 448 * mei_cl_alloc_cb - a convenient wrapper for allocating read cb 449 * 450 * @cl: host client 451 * @length: size of the buffer 452 * @type: operation type 453 * @fp: associated file pointer (might be NULL) 454 * 455 * Return: cb on success and NULL on failure 456 */ 457 struct mei_cl_cb *mei_cl_alloc_cb(struct mei_cl *cl, size_t length, 458 enum mei_cb_file_ops type, struct file *fp) 459 { 460 struct mei_cl_cb *cb; 461 462 cb = mei_io_cb_init(cl, type, fp); 463 if (!cb) 464 return NULL; 465 466 if (mei_io_cb_alloc_buf(cb, length)) { 467 mei_io_cb_free(cb); 468 return NULL; 469 } 470 471 return cb; 472 } 473 474 /** 475 * mei_cl_read_cb - find this cl's callback in the read list 476 * for a specific file 477 * 478 * @cl: host client 479 * @fp: file pointer (matching cb file object), may be NULL 480 * 481 * Return: cb on success, NULL if cb is not found 482 */ 483 struct mei_cl_cb *mei_cl_read_cb(const struct mei_cl *cl, const struct file *fp) 484 { 485 struct mei_cl_cb *cb; 486 487 list_for_each_entry(cb, &cl->rd_completed, list) 488 if (!fp || fp == cb->file_object) 489 return cb; 490 491 return NULL; 492 } 493 494 /** 495 * mei_cl_read_cb_flush - free client's read pending and completed cbs 496 * for a specific file 497 * 498 * @cl: host client 499 * @fp: file pointer (matching cb file object), may be NULL 500 */ 501 void mei_cl_read_cb_flush(const struct mei_cl *cl, const struct file *fp) 502 { 503 struct mei_cl_cb *cb, *next; 504 505 list_for_each_entry_safe(cb, next, &cl->rd_completed, list) 506 if (!fp || fp == cb->file_object) 507 mei_io_cb_free(cb); 508 509 510 list_for_each_entry_safe(cb, next, &cl->rd_pending, list) 511 if (!fp || fp == cb->file_object) 512 mei_io_cb_free(cb); 513 } 514 515 /** 516 * mei_cl_flush_queues - flushes queue lists belonging to cl. 517 * 518 * @cl: host client 519 * @fp: file pointer (matching cb file object), may be NULL 520 * 521 * Return: 0 on success, -EINVAL if cl or cl->dev is NULL. 522 */ 523 int mei_cl_flush_queues(struct mei_cl *cl, const struct file *fp) 524 { 525 struct mei_device *dev; 526 527 if (WARN_ON(!cl || !cl->dev)) 528 return -EINVAL; 529 530 dev = cl->dev; 531 532 cl_dbg(dev, cl, "remove list entry belonging to cl\n"); 533 mei_io_list_free(&cl->dev->write_list, cl); 534 mei_io_list_free(&cl->dev->write_waiting_list, cl); 535 mei_io_list_flush(&cl->dev->ctrl_wr_list, cl); 536 mei_io_list_flush(&cl->dev->ctrl_rd_list, cl); 537 mei_io_list_flush(&cl->dev->amthif_cmd_list, cl); 538 mei_io_list_flush(&cl->dev->amthif_rd_complete_list, cl); 539 540 mei_cl_read_cb_flush(cl, fp); 541 542 return 0; 543 } 544 545 546 /** 547 * mei_cl_init - initializes cl. 548 * 549 * @cl: host client to be initialized 550 * @dev: mei device 551 */ 552 void mei_cl_init(struct mei_cl *cl, struct mei_device *dev) 553 { 554 memset(cl, 0, sizeof(struct mei_cl)); 555 init_waitqueue_head(&cl->wait); 556 init_waitqueue_head(&cl->rx_wait); 557 init_waitqueue_head(&cl->tx_wait); 558 INIT_LIST_HEAD(&cl->rd_completed); 559 INIT_LIST_HEAD(&cl->rd_pending); 560 INIT_LIST_HEAD(&cl->link); 561 INIT_LIST_HEAD(&cl->device_link); 562 cl->writing_state = MEI_IDLE; 563 cl->state = MEI_FILE_INITIALIZING; 564 cl->dev = dev; 565 } 566 567 /** 568 * mei_cl_allocate - allocates cl structure and sets it up. 569 * 570 * @dev: mei device 571 * Return: The allocated file or NULL on failure 572 */ 573 struct mei_cl *mei_cl_allocate(struct mei_device *dev) 574 { 575 struct mei_cl *cl; 576 577 cl = kmalloc(sizeof(struct mei_cl), GFP_KERNEL); 578 if (!cl) 579 return NULL; 580 581 mei_cl_init(cl, dev); 582 583 return cl; 584 } 585 586 /** 587 * mei_cl_link - allocate host id in the host map 588 * 589 * @cl: host client 590 * @id: fixed host id or MEI_HOST_CLIENT_ID_ANY (-1) for generic one 591 * 592 * Return: 0 on success 593 * -EINVAL on incorrect values 594 * -EMFILE if open count exceeded. 595 */ 596 int mei_cl_link(struct mei_cl *cl, int id) 597 { 598 struct mei_device *dev; 599 long open_handle_count; 600 601 if (WARN_ON(!cl || !cl->dev)) 602 return -EINVAL; 603 604 dev = cl->dev; 605 606 /* If Id is not assigned get one*/ 607 if (id == MEI_HOST_CLIENT_ID_ANY) 608 id = find_first_zero_bit(dev->host_clients_map, 609 MEI_CLIENTS_MAX); 610 611 if (id >= MEI_CLIENTS_MAX) { 612 dev_err(dev->dev, "id exceeded %d", MEI_CLIENTS_MAX); 613 return -EMFILE; 614 } 615 616 open_handle_count = dev->open_handle_count + dev->iamthif_open_count; 617 if (open_handle_count >= MEI_MAX_OPEN_HANDLE_COUNT) { 618 dev_err(dev->dev, "open_handle_count exceeded %d", 619 MEI_MAX_OPEN_HANDLE_COUNT); 620 return -EMFILE; 621 } 622 623 dev->open_handle_count++; 624 625 cl->host_client_id = id; 626 list_add_tail(&cl->link, &dev->file_list); 627 628 set_bit(id, dev->host_clients_map); 629 630 cl->state = MEI_FILE_INITIALIZING; 631 632 cl_dbg(dev, cl, "link cl\n"); 633 return 0; 634 } 635 636 /** 637 * mei_cl_unlink - remove host client from the list 638 * 639 * @cl: host client 640 * 641 * Return: always 0 642 */ 643 int mei_cl_unlink(struct mei_cl *cl) 644 { 645 struct mei_device *dev; 646 647 /* don't shout on error exit path */ 648 if (!cl) 649 return 0; 650 651 /* wd and amthif might not be initialized */ 652 if (!cl->dev) 653 return 0; 654 655 dev = cl->dev; 656 657 cl_dbg(dev, cl, "unlink client"); 658 659 if (dev->open_handle_count > 0) 660 dev->open_handle_count--; 661 662 /* never clear the 0 bit */ 663 if (cl->host_client_id) 664 clear_bit(cl->host_client_id, dev->host_clients_map); 665 666 list_del_init(&cl->link); 667 668 cl->state = MEI_FILE_INITIALIZING; 669 670 return 0; 671 } 672 673 674 void mei_host_client_init(struct work_struct *work) 675 { 676 struct mei_device *dev = 677 container_of(work, struct mei_device, init_work); 678 struct mei_me_client *me_cl; 679 680 mutex_lock(&dev->device_lock); 681 682 683 me_cl = mei_me_cl_by_uuid(dev, &mei_amthif_guid); 684 if (me_cl) 685 mei_amthif_host_init(dev, me_cl); 686 mei_me_cl_put(me_cl); 687 688 me_cl = mei_me_cl_by_uuid(dev, &mei_wd_guid); 689 if (me_cl) 690 mei_wd_host_init(dev, me_cl); 691 mei_me_cl_put(me_cl); 692 693 me_cl = mei_me_cl_by_uuid(dev, &mei_nfc_guid); 694 if (me_cl) 695 mei_nfc_host_init(dev, me_cl); 696 mei_me_cl_put(me_cl); 697 698 699 dev->dev_state = MEI_DEV_ENABLED; 700 dev->reset_count = 0; 701 mutex_unlock(&dev->device_lock); 702 703 pm_runtime_mark_last_busy(dev->dev); 704 dev_dbg(dev->dev, "rpm: autosuspend\n"); 705 pm_runtime_autosuspend(dev->dev); 706 } 707 708 /** 709 * mei_hbuf_acquire - try to acquire host buffer 710 * 711 * @dev: the device structure 712 * Return: true if host buffer was acquired 713 */ 714 bool mei_hbuf_acquire(struct mei_device *dev) 715 { 716 if (mei_pg_state(dev) == MEI_PG_ON || 717 dev->pg_event == MEI_PG_EVENT_WAIT) { 718 dev_dbg(dev->dev, "device is in pg\n"); 719 return false; 720 } 721 722 if (!dev->hbuf_is_ready) { 723 dev_dbg(dev->dev, "hbuf is not ready\n"); 724 return false; 725 } 726 727 dev->hbuf_is_ready = false; 728 729 return true; 730 } 731 732 /** 733 * mei_cl_set_disconnected - set disconnected state and clear 734 * associated states and resources 735 * 736 * @cl: host client 737 */ 738 void mei_cl_set_disconnected(struct mei_cl *cl) 739 { 740 struct mei_device *dev = cl->dev; 741 742 if (cl->state == MEI_FILE_DISCONNECTED || 743 cl->state == MEI_FILE_INITIALIZING) 744 return; 745 746 cl->state = MEI_FILE_DISCONNECTED; 747 mei_io_list_flush(&dev->ctrl_rd_list, cl); 748 mei_io_list_flush(&dev->ctrl_wr_list, cl); 749 cl->mei_flow_ctrl_creds = 0; 750 cl->timer_count = 0; 751 752 if (!cl->me_cl) 753 return; 754 755 if (!WARN_ON(cl->me_cl->connect_count == 0)) 756 cl->me_cl->connect_count--; 757 758 mei_me_cl_put(cl->me_cl); 759 cl->me_cl = NULL; 760 } 761 762 static int mei_cl_set_connecting(struct mei_cl *cl, struct mei_me_client *me_cl) 763 { 764 if (!mei_me_cl_get(me_cl)) 765 return -ENOENT; 766 767 /* only one connection is allowed for fixed address clients */ 768 if (me_cl->props.fixed_address) { 769 if (me_cl->connect_count) { 770 mei_me_cl_put(me_cl); 771 return -EBUSY; 772 } 773 } 774 775 cl->me_cl = me_cl; 776 cl->state = MEI_FILE_CONNECTING; 777 cl->me_cl->connect_count++; 778 779 return 0; 780 } 781 782 /* 783 * mei_cl_send_disconnect - send disconnect request 784 * 785 * @cl: host client 786 * @cb: callback block 787 * 788 * Return: 0, OK; otherwise, error. 789 */ 790 static int mei_cl_send_disconnect(struct mei_cl *cl, struct mei_cl_cb *cb) 791 { 792 struct mei_device *dev; 793 int ret; 794 795 dev = cl->dev; 796 797 ret = mei_hbm_cl_disconnect_req(dev, cl); 798 cl->status = ret; 799 if (ret) { 800 cl->state = MEI_FILE_DISCONNECT_REPLY; 801 return ret; 802 } 803 804 list_move_tail(&cb->list, &dev->ctrl_rd_list.list); 805 cl->timer_count = MEI_CONNECT_TIMEOUT; 806 807 return 0; 808 } 809 810 /** 811 * mei_cl_irq_disconnect - processes close related operation from 812 * interrupt thread context - send disconnect request 813 * 814 * @cl: client 815 * @cb: callback block. 816 * @cmpl_list: complete list. 817 * 818 * Return: 0, OK; otherwise, error. 819 */ 820 int mei_cl_irq_disconnect(struct mei_cl *cl, struct mei_cl_cb *cb, 821 struct mei_cl_cb *cmpl_list) 822 { 823 struct mei_device *dev = cl->dev; 824 u32 msg_slots; 825 int slots; 826 int ret; 827 828 msg_slots = mei_data2slots(sizeof(struct hbm_client_connect_request)); 829 slots = mei_hbuf_empty_slots(dev); 830 831 if (slots < msg_slots) 832 return -EMSGSIZE; 833 834 ret = mei_cl_send_disconnect(cl, cb); 835 if (ret) 836 list_move_tail(&cb->list, &cmpl_list->list); 837 838 return ret; 839 } 840 841 842 843 /** 844 * mei_cl_disconnect - disconnect host client from the me one 845 * 846 * @cl: host client 847 * 848 * Locking: called under "dev->device_lock" lock 849 * 850 * Return: 0 on success, <0 on failure. 851 */ 852 int mei_cl_disconnect(struct mei_cl *cl) 853 { 854 struct mei_device *dev; 855 struct mei_cl_cb *cb; 856 int rets; 857 858 if (WARN_ON(!cl || !cl->dev)) 859 return -ENODEV; 860 861 dev = cl->dev; 862 863 cl_dbg(dev, cl, "disconnecting"); 864 865 if (!mei_cl_is_connected(cl)) 866 return 0; 867 868 if (mei_cl_is_fixed_address(cl)) { 869 mei_cl_set_disconnected(cl); 870 return 0; 871 } 872 873 rets = pm_runtime_get(dev->dev); 874 if (rets < 0 && rets != -EINPROGRESS) { 875 pm_runtime_put_noidle(dev->dev); 876 cl_err(dev, cl, "rpm: get failed %d\n", rets); 877 return rets; 878 } 879 880 cl->state = MEI_FILE_DISCONNECTING; 881 882 cb = mei_io_cb_init(cl, MEI_FOP_DISCONNECT, NULL); 883 rets = cb ? 0 : -ENOMEM; 884 if (rets) 885 goto out; 886 887 cl_dbg(dev, cl, "add disconnect cb to control write list\n"); 888 list_add_tail(&cb->list, &dev->ctrl_wr_list.list); 889 890 if (mei_hbuf_acquire(dev)) { 891 rets = mei_cl_send_disconnect(cl, cb); 892 if (rets) { 893 cl_err(dev, cl, "failed to disconnect.\n"); 894 goto out; 895 } 896 } 897 898 mutex_unlock(&dev->device_lock); 899 wait_event_timeout(cl->wait, cl->state == MEI_FILE_DISCONNECT_REPLY, 900 mei_secs_to_jiffies(MEI_CL_CONNECT_TIMEOUT)); 901 mutex_lock(&dev->device_lock); 902 903 rets = cl->status; 904 if (cl->state != MEI_FILE_DISCONNECT_REPLY) { 905 cl_dbg(dev, cl, "timeout on disconnect from FW client.\n"); 906 rets = -ETIME; 907 } 908 909 out: 910 /* we disconnect also on error */ 911 mei_cl_set_disconnected(cl); 912 if (!rets) 913 cl_dbg(dev, cl, "successfully disconnected from FW client.\n"); 914 915 cl_dbg(dev, cl, "rpm: autosuspend\n"); 916 pm_runtime_mark_last_busy(dev->dev); 917 pm_runtime_put_autosuspend(dev->dev); 918 919 mei_io_cb_free(cb); 920 return rets; 921 } 922 923 924 /** 925 * mei_cl_is_other_connecting - checks if other 926 * client with the same me client id is connecting 927 * 928 * @cl: private data of the file object 929 * 930 * Return: true if other client is connected, false - otherwise. 931 */ 932 static bool mei_cl_is_other_connecting(struct mei_cl *cl) 933 { 934 struct mei_device *dev; 935 struct mei_cl_cb *cb; 936 937 dev = cl->dev; 938 939 list_for_each_entry(cb, &dev->ctrl_rd_list.list, list) { 940 if (cb->fop_type == MEI_FOP_CONNECT && 941 mei_cl_me_id(cl) == mei_cl_me_id(cb->cl)) 942 return true; 943 } 944 945 return false; 946 } 947 948 /** 949 * mei_cl_send_connect - send connect request 950 * 951 * @cl: host client 952 * @cb: callback block 953 * 954 * Return: 0, OK; otherwise, error. 955 */ 956 static int mei_cl_send_connect(struct mei_cl *cl, struct mei_cl_cb *cb) 957 { 958 struct mei_device *dev; 959 int ret; 960 961 dev = cl->dev; 962 963 ret = mei_hbm_cl_connect_req(dev, cl); 964 cl->status = ret; 965 if (ret) { 966 cl->state = MEI_FILE_DISCONNECT_REPLY; 967 return ret; 968 } 969 970 list_move_tail(&cb->list, &dev->ctrl_rd_list.list); 971 cl->timer_count = MEI_CONNECT_TIMEOUT; 972 return 0; 973 } 974 975 /** 976 * mei_cl_irq_connect - send connect request in irq_thread context 977 * 978 * @cl: host client 979 * @cb: callback block 980 * @cmpl_list: complete list 981 * 982 * Return: 0, OK; otherwise, error. 983 */ 984 int mei_cl_irq_connect(struct mei_cl *cl, struct mei_cl_cb *cb, 985 struct mei_cl_cb *cmpl_list) 986 { 987 struct mei_device *dev = cl->dev; 988 u32 msg_slots; 989 int slots; 990 int rets; 991 992 msg_slots = mei_data2slots(sizeof(struct hbm_client_connect_request)); 993 slots = mei_hbuf_empty_slots(dev); 994 995 if (mei_cl_is_other_connecting(cl)) 996 return 0; 997 998 if (slots < msg_slots) 999 return -EMSGSIZE; 1000 1001 rets = mei_cl_send_connect(cl, cb); 1002 if (rets) 1003 list_move_tail(&cb->list, &cmpl_list->list); 1004 1005 return rets; 1006 } 1007 1008 /** 1009 * mei_cl_connect - connect host client to the me one 1010 * 1011 * @cl: host client 1012 * @me_cl: me client 1013 * @file: pointer to file structure 1014 * 1015 * Locking: called under "dev->device_lock" lock 1016 * 1017 * Return: 0 on success, <0 on failure. 1018 */ 1019 int mei_cl_connect(struct mei_cl *cl, struct mei_me_client *me_cl, 1020 struct file *file) 1021 { 1022 struct mei_device *dev; 1023 struct mei_cl_cb *cb; 1024 int rets; 1025 1026 if (WARN_ON(!cl || !cl->dev || !me_cl)) 1027 return -ENODEV; 1028 1029 dev = cl->dev; 1030 1031 rets = mei_cl_set_connecting(cl, me_cl); 1032 if (rets) 1033 return rets; 1034 1035 if (mei_cl_is_fixed_address(cl)) { 1036 cl->state = MEI_FILE_CONNECTED; 1037 return 0; 1038 } 1039 1040 rets = pm_runtime_get(dev->dev); 1041 if (rets < 0 && rets != -EINPROGRESS) { 1042 pm_runtime_put_noidle(dev->dev); 1043 cl_err(dev, cl, "rpm: get failed %d\n", rets); 1044 goto nortpm; 1045 } 1046 1047 cb = mei_io_cb_init(cl, MEI_FOP_CONNECT, file); 1048 rets = cb ? 0 : -ENOMEM; 1049 if (rets) 1050 goto out; 1051 1052 list_add_tail(&cb->list, &dev->ctrl_wr_list.list); 1053 1054 /* run hbuf acquire last so we don't have to undo */ 1055 if (!mei_cl_is_other_connecting(cl) && mei_hbuf_acquire(dev)) { 1056 rets = mei_cl_send_connect(cl, cb); 1057 if (rets) 1058 goto out; 1059 } 1060 1061 mutex_unlock(&dev->device_lock); 1062 wait_event_timeout(cl->wait, 1063 (cl->state == MEI_FILE_CONNECTED || 1064 cl->state == MEI_FILE_DISCONNECT_REPLY), 1065 mei_secs_to_jiffies(MEI_CL_CONNECT_TIMEOUT)); 1066 mutex_lock(&dev->device_lock); 1067 1068 if (!mei_cl_is_connected(cl)) { 1069 /* timeout or something went really wrong */ 1070 if (!cl->status) 1071 cl->status = -EFAULT; 1072 } 1073 1074 rets = cl->status; 1075 out: 1076 cl_dbg(dev, cl, "rpm: autosuspend\n"); 1077 pm_runtime_mark_last_busy(dev->dev); 1078 pm_runtime_put_autosuspend(dev->dev); 1079 1080 mei_io_cb_free(cb); 1081 1082 nortpm: 1083 if (!mei_cl_is_connected(cl)) 1084 mei_cl_set_disconnected(cl); 1085 1086 return rets; 1087 } 1088 1089 /** 1090 * mei_cl_alloc_linked - allocate and link host client 1091 * 1092 * @dev: the device structure 1093 * @id: fixed host id or MEI_HOST_CLIENT_ID_ANY (-1) for generic one 1094 * 1095 * Return: cl on success ERR_PTR on failure 1096 */ 1097 struct mei_cl *mei_cl_alloc_linked(struct mei_device *dev, int id) 1098 { 1099 struct mei_cl *cl; 1100 int ret; 1101 1102 cl = mei_cl_allocate(dev); 1103 if (!cl) { 1104 ret = -ENOMEM; 1105 goto err; 1106 } 1107 1108 ret = mei_cl_link(cl, id); 1109 if (ret) 1110 goto err; 1111 1112 return cl; 1113 err: 1114 kfree(cl); 1115 return ERR_PTR(ret); 1116 } 1117 1118 1119 1120 /** 1121 * mei_cl_flow_ctrl_creds - checks flow_control credits for cl. 1122 * 1123 * @cl: private data of the file object 1124 * 1125 * Return: 1 if mei_flow_ctrl_creds >0, 0 - otherwise. 1126 */ 1127 int mei_cl_flow_ctrl_creds(struct mei_cl *cl) 1128 { 1129 int rets; 1130 1131 if (WARN_ON(!cl || !cl->me_cl)) 1132 return -EINVAL; 1133 1134 if (cl->mei_flow_ctrl_creds > 0) 1135 return 1; 1136 1137 if (mei_cl_is_fixed_address(cl)) { 1138 rets = mei_cl_read_start(cl, mei_cl_mtu(cl), NULL); 1139 if (rets && rets != -EBUSY) 1140 return rets; 1141 return 1; 1142 } 1143 1144 if (mei_cl_is_single_recv_buf(cl)) { 1145 if (cl->me_cl->mei_flow_ctrl_creds > 0) 1146 return 1; 1147 } 1148 return 0; 1149 } 1150 1151 /** 1152 * mei_cl_flow_ctrl_reduce - reduces flow_control. 1153 * 1154 * @cl: private data of the file object 1155 * 1156 * Return: 1157 * 0 on success 1158 * -EINVAL when ctrl credits are <= 0 1159 */ 1160 int mei_cl_flow_ctrl_reduce(struct mei_cl *cl) 1161 { 1162 if (WARN_ON(!cl || !cl->me_cl)) 1163 return -EINVAL; 1164 1165 if (mei_cl_is_fixed_address(cl)) 1166 return 0; 1167 1168 if (mei_cl_is_single_recv_buf(cl)) { 1169 if (WARN_ON(cl->me_cl->mei_flow_ctrl_creds <= 0)) 1170 return -EINVAL; 1171 cl->me_cl->mei_flow_ctrl_creds--; 1172 } else { 1173 if (WARN_ON(cl->mei_flow_ctrl_creds <= 0)) 1174 return -EINVAL; 1175 cl->mei_flow_ctrl_creds--; 1176 } 1177 return 0; 1178 } 1179 1180 /** 1181 * mei_cl_read_start - the start read client message function. 1182 * 1183 * @cl: host client 1184 * @length: number of bytes to read 1185 * @fp: pointer to file structure 1186 * 1187 * Return: 0 on success, <0 on failure. 1188 */ 1189 int mei_cl_read_start(struct mei_cl *cl, size_t length, struct file *fp) 1190 { 1191 struct mei_device *dev; 1192 struct mei_cl_cb *cb; 1193 int rets; 1194 1195 if (WARN_ON(!cl || !cl->dev)) 1196 return -ENODEV; 1197 1198 dev = cl->dev; 1199 1200 if (!mei_cl_is_connected(cl)) 1201 return -ENODEV; 1202 1203 /* HW currently supports only one pending read */ 1204 if (!list_empty(&cl->rd_pending)) 1205 return -EBUSY; 1206 1207 if (!mei_me_cl_is_active(cl->me_cl)) { 1208 cl_err(dev, cl, "no such me client\n"); 1209 return -ENOTTY; 1210 } 1211 1212 /* always allocate at least client max message */ 1213 length = max_t(size_t, length, mei_cl_mtu(cl)); 1214 cb = mei_cl_alloc_cb(cl, length, MEI_FOP_READ, fp); 1215 if (!cb) 1216 return -ENOMEM; 1217 1218 if (mei_cl_is_fixed_address(cl)) { 1219 list_add_tail(&cb->list, &cl->rd_pending); 1220 return 0; 1221 } 1222 1223 rets = pm_runtime_get(dev->dev); 1224 if (rets < 0 && rets != -EINPROGRESS) { 1225 pm_runtime_put_noidle(dev->dev); 1226 cl_err(dev, cl, "rpm: get failed %d\n", rets); 1227 goto nortpm; 1228 } 1229 1230 if (mei_hbuf_acquire(dev)) { 1231 rets = mei_hbm_cl_flow_control_req(dev, cl); 1232 if (rets < 0) 1233 goto out; 1234 1235 list_add_tail(&cb->list, &cl->rd_pending); 1236 } else { 1237 rets = 0; 1238 list_add_tail(&cb->list, &dev->ctrl_wr_list.list); 1239 } 1240 1241 out: 1242 cl_dbg(dev, cl, "rpm: autosuspend\n"); 1243 pm_runtime_mark_last_busy(dev->dev); 1244 pm_runtime_put_autosuspend(dev->dev); 1245 nortpm: 1246 if (rets) 1247 mei_io_cb_free(cb); 1248 1249 return rets; 1250 } 1251 1252 /** 1253 * mei_cl_irq_write - write a message to device 1254 * from the interrupt thread context 1255 * 1256 * @cl: client 1257 * @cb: callback block. 1258 * @cmpl_list: complete list. 1259 * 1260 * Return: 0, OK; otherwise error. 1261 */ 1262 int mei_cl_irq_write(struct mei_cl *cl, struct mei_cl_cb *cb, 1263 struct mei_cl_cb *cmpl_list) 1264 { 1265 struct mei_device *dev; 1266 struct mei_msg_data *buf; 1267 struct mei_msg_hdr mei_hdr; 1268 size_t len; 1269 u32 msg_slots; 1270 int slots; 1271 int rets; 1272 bool first_chunk; 1273 1274 if (WARN_ON(!cl || !cl->dev)) 1275 return -ENODEV; 1276 1277 dev = cl->dev; 1278 1279 buf = &cb->buf; 1280 1281 first_chunk = cb->buf_idx == 0; 1282 1283 rets = first_chunk ? mei_cl_flow_ctrl_creds(cl) : 1; 1284 if (rets < 0) 1285 return rets; 1286 1287 if (rets == 0) { 1288 cl_dbg(dev, cl, "No flow control credentials: not sending.\n"); 1289 return 0; 1290 } 1291 1292 slots = mei_hbuf_empty_slots(dev); 1293 len = buf->size - cb->buf_idx; 1294 msg_slots = mei_data2slots(len); 1295 1296 mei_hdr.host_addr = mei_cl_host_addr(cl); 1297 mei_hdr.me_addr = mei_cl_me_id(cl); 1298 mei_hdr.reserved = 0; 1299 mei_hdr.internal = cb->internal; 1300 1301 if (slots >= msg_slots) { 1302 mei_hdr.length = len; 1303 mei_hdr.msg_complete = 1; 1304 /* Split the message only if we can write the whole host buffer */ 1305 } else if (slots == dev->hbuf_depth) { 1306 msg_slots = slots; 1307 len = (slots * sizeof(u32)) - sizeof(struct mei_msg_hdr); 1308 mei_hdr.length = len; 1309 mei_hdr.msg_complete = 0; 1310 } else { 1311 /* wait for next time the host buffer is empty */ 1312 return 0; 1313 } 1314 1315 cl_dbg(dev, cl, "buf: size = %d idx = %lu\n", 1316 cb->buf.size, cb->buf_idx); 1317 1318 rets = mei_write_message(dev, &mei_hdr, buf->data + cb->buf_idx); 1319 if (rets) { 1320 cl->status = rets; 1321 list_move_tail(&cb->list, &cmpl_list->list); 1322 return rets; 1323 } 1324 1325 cl->status = 0; 1326 cl->writing_state = MEI_WRITING; 1327 cb->buf_idx += mei_hdr.length; 1328 cb->completed = mei_hdr.msg_complete == 1; 1329 1330 if (first_chunk) { 1331 if (mei_cl_flow_ctrl_reduce(cl)) 1332 return -EIO; 1333 } 1334 1335 if (mei_hdr.msg_complete) 1336 list_move_tail(&cb->list, &dev->write_waiting_list.list); 1337 1338 return 0; 1339 } 1340 1341 /** 1342 * mei_cl_write - submit a write cb to mei device 1343 * assumes device_lock is locked 1344 * 1345 * @cl: host client 1346 * @cb: write callback with filled data 1347 * @blocking: block until completed 1348 * 1349 * Return: number of bytes sent on success, <0 on failure. 1350 */ 1351 int mei_cl_write(struct mei_cl *cl, struct mei_cl_cb *cb, bool blocking) 1352 { 1353 struct mei_device *dev; 1354 struct mei_msg_data *buf; 1355 struct mei_msg_hdr mei_hdr; 1356 int rets; 1357 1358 1359 if (WARN_ON(!cl || !cl->dev)) 1360 return -ENODEV; 1361 1362 if (WARN_ON(!cb)) 1363 return -EINVAL; 1364 1365 dev = cl->dev; 1366 1367 1368 buf = &cb->buf; 1369 1370 cl_dbg(dev, cl, "size=%d\n", buf->size); 1371 1372 rets = pm_runtime_get(dev->dev); 1373 if (rets < 0 && rets != -EINPROGRESS) { 1374 pm_runtime_put_noidle(dev->dev); 1375 cl_err(dev, cl, "rpm: get failed %d\n", rets); 1376 return rets; 1377 } 1378 1379 cb->buf_idx = 0; 1380 cl->writing_state = MEI_IDLE; 1381 1382 mei_hdr.host_addr = mei_cl_host_addr(cl); 1383 mei_hdr.me_addr = mei_cl_me_id(cl); 1384 mei_hdr.reserved = 0; 1385 mei_hdr.msg_complete = 0; 1386 mei_hdr.internal = cb->internal; 1387 1388 rets = mei_cl_flow_ctrl_creds(cl); 1389 if (rets < 0) 1390 goto err; 1391 1392 if (rets == 0) { 1393 cl_dbg(dev, cl, "No flow control credentials: not sending.\n"); 1394 rets = buf->size; 1395 goto out; 1396 } 1397 if (!mei_hbuf_acquire(dev)) { 1398 cl_dbg(dev, cl, "Cannot acquire the host buffer: not sending.\n"); 1399 rets = buf->size; 1400 goto out; 1401 } 1402 1403 /* Check for a maximum length */ 1404 if (buf->size > mei_hbuf_max_len(dev)) { 1405 mei_hdr.length = mei_hbuf_max_len(dev); 1406 mei_hdr.msg_complete = 0; 1407 } else { 1408 mei_hdr.length = buf->size; 1409 mei_hdr.msg_complete = 1; 1410 } 1411 1412 rets = mei_write_message(dev, &mei_hdr, buf->data); 1413 if (rets) 1414 goto err; 1415 1416 rets = mei_cl_flow_ctrl_reduce(cl); 1417 if (rets) 1418 goto err; 1419 1420 cl->writing_state = MEI_WRITING; 1421 cb->buf_idx = mei_hdr.length; 1422 cb->completed = mei_hdr.msg_complete == 1; 1423 1424 out: 1425 if (mei_hdr.msg_complete) 1426 list_add_tail(&cb->list, &dev->write_waiting_list.list); 1427 else 1428 list_add_tail(&cb->list, &dev->write_list.list); 1429 1430 if (blocking && cl->writing_state != MEI_WRITE_COMPLETE) { 1431 1432 mutex_unlock(&dev->device_lock); 1433 rets = wait_event_interruptible(cl->tx_wait, 1434 cl->writing_state == MEI_WRITE_COMPLETE); 1435 mutex_lock(&dev->device_lock); 1436 /* wait_event_interruptible returns -ERESTARTSYS */ 1437 if (rets) { 1438 if (signal_pending(current)) 1439 rets = -EINTR; 1440 goto err; 1441 } 1442 } 1443 1444 rets = buf->size; 1445 err: 1446 cl_dbg(dev, cl, "rpm: autosuspend\n"); 1447 pm_runtime_mark_last_busy(dev->dev); 1448 pm_runtime_put_autosuspend(dev->dev); 1449 1450 return rets; 1451 } 1452 1453 1454 /** 1455 * mei_cl_complete - processes completed operation for a client 1456 * 1457 * @cl: private data of the file object. 1458 * @cb: callback block. 1459 */ 1460 void mei_cl_complete(struct mei_cl *cl, struct mei_cl_cb *cb) 1461 { 1462 struct mei_device *dev = cl->dev; 1463 1464 switch (cb->fop_type) { 1465 case MEI_FOP_WRITE: 1466 mei_io_cb_free(cb); 1467 cl->writing_state = MEI_WRITE_COMPLETE; 1468 if (waitqueue_active(&cl->tx_wait)) { 1469 wake_up_interruptible(&cl->tx_wait); 1470 } else { 1471 pm_runtime_mark_last_busy(dev->dev); 1472 pm_request_autosuspend(dev->dev); 1473 } 1474 break; 1475 1476 case MEI_FOP_READ: 1477 list_add_tail(&cb->list, &cl->rd_completed); 1478 if (waitqueue_active(&cl->rx_wait)) 1479 wake_up_interruptible_all(&cl->rx_wait); 1480 else 1481 mei_cl_bus_rx_event(cl); 1482 break; 1483 1484 case MEI_FOP_CONNECT: 1485 case MEI_FOP_DISCONNECT: 1486 if (waitqueue_active(&cl->wait)) 1487 wake_up(&cl->wait); 1488 1489 break; 1490 default: 1491 BUG_ON(0); 1492 } 1493 } 1494 1495 1496 /** 1497 * mei_cl_all_disconnect - disconnect forcefully all connected clients 1498 * 1499 * @dev: mei device 1500 */ 1501 void mei_cl_all_disconnect(struct mei_device *dev) 1502 { 1503 struct mei_cl *cl; 1504 1505 list_for_each_entry(cl, &dev->file_list, link) 1506 mei_cl_set_disconnected(cl); 1507 } 1508 1509 1510 /** 1511 * mei_cl_all_wakeup - wake up all readers and writers they can be interrupted 1512 * 1513 * @dev: mei device 1514 */ 1515 void mei_cl_all_wakeup(struct mei_device *dev) 1516 { 1517 struct mei_cl *cl; 1518 1519 list_for_each_entry(cl, &dev->file_list, link) { 1520 if (waitqueue_active(&cl->rx_wait)) { 1521 cl_dbg(dev, cl, "Waking up reading client!\n"); 1522 wake_up_interruptible(&cl->rx_wait); 1523 } 1524 if (waitqueue_active(&cl->tx_wait)) { 1525 cl_dbg(dev, cl, "Waking up writing client!\n"); 1526 wake_up_interruptible(&cl->tx_wait); 1527 } 1528 } 1529 } 1530 1531 /** 1532 * mei_cl_all_write_clear - clear all pending writes 1533 * 1534 * @dev: mei device 1535 */ 1536 void mei_cl_all_write_clear(struct mei_device *dev) 1537 { 1538 mei_io_list_free(&dev->write_list, NULL); 1539 mei_io_list_free(&dev->write_waiting_list, NULL); 1540 } 1541 1542 1543