1 // SPDX-License-Identifier: GPL-2.0 OR BSD-3-Clause
2 /*
3  * Copyright(c) 2020-2021 Intel Corporation
4  */
5 
6 #include "iwl-drv.h"
7 #include "pnvm.h"
8 #include "iwl-prph.h"
9 #include "iwl-io.h"
10 #include "fw/api/commands.h"
11 #include "fw/api/nvm-reg.h"
12 #include "fw/api/alive.h"
13 #include "fw/uefi.h"
14 
15 struct iwl_pnvm_section {
16 	__le32 offset;
17 	const u8 data[];
18 } __packed;
19 
20 static bool iwl_pnvm_complete_fn(struct iwl_notif_wait_data *notif_wait,
21 				 struct iwl_rx_packet *pkt, void *data)
22 {
23 	struct iwl_trans *trans = (struct iwl_trans *)data;
24 	struct iwl_pnvm_init_complete_ntfy *pnvm_ntf = (void *)pkt->data;
25 
26 	IWL_DEBUG_FW(trans,
27 		     "PNVM complete notification received with status %d\n",
28 		     le32_to_cpu(pnvm_ntf->status));
29 
30 	return true;
31 }
32 
33 static int iwl_pnvm_handle_section(struct iwl_trans *trans, const u8 *data,
34 				   size_t len)
35 {
36 	struct iwl_ucode_tlv *tlv;
37 	u32 sha1 = 0;
38 	u16 mac_type = 0, rf_id = 0;
39 	u8 *pnvm_data = NULL, *tmp;
40 	bool hw_match = false;
41 	u32 size = 0;
42 	int ret;
43 
44 	IWL_DEBUG_FW(trans, "Handling PNVM section\n");
45 
46 	while (len >= sizeof(*tlv)) {
47 		u32 tlv_len, tlv_type;
48 
49 		len -= sizeof(*tlv);
50 		tlv = (void *)data;
51 
52 		tlv_len = le32_to_cpu(tlv->length);
53 		tlv_type = le32_to_cpu(tlv->type);
54 
55 		if (len < tlv_len) {
56 			IWL_ERR(trans, "invalid TLV len: %zd/%u\n",
57 				len, tlv_len);
58 			ret = -EINVAL;
59 			goto out;
60 		}
61 
62 		data += sizeof(*tlv);
63 
64 		switch (tlv_type) {
65 		case IWL_UCODE_TLV_PNVM_VERSION:
66 			if (tlv_len < sizeof(__le32)) {
67 				IWL_DEBUG_FW(trans,
68 					     "Invalid size for IWL_UCODE_TLV_PNVM_VERSION (expected %zd, got %d)\n",
69 					     sizeof(__le32), tlv_len);
70 				break;
71 			}
72 
73 			sha1 = le32_to_cpup((__le32 *)data);
74 
75 			IWL_DEBUG_FW(trans,
76 				     "Got IWL_UCODE_TLV_PNVM_VERSION %0x\n",
77 				     sha1);
78 			break;
79 		case IWL_UCODE_TLV_HW_TYPE:
80 			if (tlv_len < 2 * sizeof(__le16)) {
81 				IWL_DEBUG_FW(trans,
82 					     "Invalid size for IWL_UCODE_TLV_HW_TYPE (expected %zd, got %d)\n",
83 					     2 * sizeof(__le16), tlv_len);
84 				break;
85 			}
86 
87 			if (hw_match)
88 				break;
89 
90 			mac_type = le16_to_cpup((__le16 *)data);
91 			rf_id = le16_to_cpup((__le16 *)(data + sizeof(__le16)));
92 
93 			IWL_DEBUG_FW(trans,
94 				     "Got IWL_UCODE_TLV_HW_TYPE mac_type 0x%0x rf_id 0x%0x\n",
95 				     mac_type, rf_id);
96 
97 			if (mac_type == CSR_HW_REV_TYPE(trans->hw_rev) &&
98 			    rf_id == CSR_HW_RFID_TYPE(trans->hw_rf_id))
99 				hw_match = true;
100 			break;
101 		case IWL_UCODE_TLV_SEC_RT: {
102 			struct iwl_pnvm_section *section = (void *)data;
103 			u32 data_len = tlv_len - sizeof(*section);
104 
105 			IWL_DEBUG_FW(trans,
106 				     "Got IWL_UCODE_TLV_SEC_RT len %d\n",
107 				     tlv_len);
108 
109 			/* TODO: remove, this is a deprecated separator */
110 			if (le32_to_cpup((__le32 *)data) == 0xddddeeee) {
111 				IWL_DEBUG_FW(trans, "Ignoring separator.\n");
112 				break;
113 			}
114 
115 			IWL_DEBUG_FW(trans, "Adding data (size %d)\n",
116 				     data_len);
117 
118 			tmp = krealloc(pnvm_data, size + data_len, GFP_KERNEL);
119 			if (!tmp) {
120 				IWL_DEBUG_FW(trans,
121 					     "Couldn't allocate (more) pnvm_data\n");
122 
123 				ret = -ENOMEM;
124 				goto out;
125 			}
126 
127 			pnvm_data = tmp;
128 
129 			memcpy(pnvm_data + size, section->data, data_len);
130 
131 			size += data_len;
132 
133 			break;
134 		}
135 		case IWL_UCODE_TLV_PNVM_SKU:
136 			IWL_DEBUG_FW(trans,
137 				     "New PNVM section started, stop parsing.\n");
138 			goto done;
139 		default:
140 			IWL_DEBUG_FW(trans, "Found TLV 0x%0x, len %d\n",
141 				     tlv_type, tlv_len);
142 			break;
143 		}
144 
145 		len -= ALIGN(tlv_len, 4);
146 		data += ALIGN(tlv_len, 4);
147 	}
148 
149 done:
150 	if (!hw_match) {
151 		IWL_DEBUG_FW(trans,
152 			     "HW mismatch, skipping PNVM section (need mac_type 0x%x rf_id 0x%x)\n",
153 			     CSR_HW_REV_TYPE(trans->hw_rev),
154 			     CSR_HW_RFID_TYPE(trans->hw_rf_id));
155 		ret = -ENOENT;
156 		goto out;
157 	}
158 
159 	if (!size) {
160 		IWL_DEBUG_FW(trans, "Empty PNVM, skipping.\n");
161 		ret = -ENOENT;
162 		goto out;
163 	}
164 
165 	IWL_INFO(trans, "loaded PNVM version 0x%0x\n", sha1);
166 
167 	ret = iwl_trans_set_pnvm(trans, pnvm_data, size);
168 out:
169 	kfree(pnvm_data);
170 	return ret;
171 }
172 
173 static int iwl_pnvm_parse(struct iwl_trans *trans, const u8 *data,
174 			  size_t len)
175 {
176 	struct iwl_ucode_tlv *tlv;
177 
178 	IWL_DEBUG_FW(trans, "Parsing PNVM file\n");
179 
180 	while (len >= sizeof(*tlv)) {
181 		u32 tlv_len, tlv_type;
182 
183 		len -= sizeof(*tlv);
184 		tlv = (void *)data;
185 
186 		tlv_len = le32_to_cpu(tlv->length);
187 		tlv_type = le32_to_cpu(tlv->type);
188 
189 		if (len < tlv_len) {
190 			IWL_ERR(trans, "invalid TLV len: %zd/%u\n",
191 				len, tlv_len);
192 			return -EINVAL;
193 		}
194 
195 		if (tlv_type == IWL_UCODE_TLV_PNVM_SKU) {
196 			struct iwl_sku_id *sku_id =
197 				(void *)(data + sizeof(*tlv));
198 
199 			IWL_DEBUG_FW(trans,
200 				     "Got IWL_UCODE_TLV_PNVM_SKU len %d\n",
201 				     tlv_len);
202 			IWL_DEBUG_FW(trans, "sku_id 0x%0x 0x%0x 0x%0x\n",
203 				     le32_to_cpu(sku_id->data[0]),
204 				     le32_to_cpu(sku_id->data[1]),
205 				     le32_to_cpu(sku_id->data[2]));
206 
207 			data += sizeof(*tlv) + ALIGN(tlv_len, 4);
208 			len -= ALIGN(tlv_len, 4);
209 
210 			if (trans->sku_id[0] == le32_to_cpu(sku_id->data[0]) &&
211 			    trans->sku_id[1] == le32_to_cpu(sku_id->data[1]) &&
212 			    trans->sku_id[2] == le32_to_cpu(sku_id->data[2])) {
213 				int ret;
214 
215 				ret = iwl_pnvm_handle_section(trans, data, len);
216 				if (!ret)
217 					return 0;
218 			} else {
219 				IWL_DEBUG_FW(trans, "SKU ID didn't match!\n");
220 			}
221 		} else {
222 			data += sizeof(*tlv) + ALIGN(tlv_len, 4);
223 			len -= ALIGN(tlv_len, 4);
224 		}
225 	}
226 
227 	return -ENOENT;
228 }
229 
230 static int iwl_pnvm_get_from_fs(struct iwl_trans *trans, u8 **data, size_t *len)
231 {
232 	const struct firmware *pnvm;
233 	char pnvm_name[64];
234 	int ret;
235 
236 	/*
237 	 * The prefix unfortunately includes a hyphen at the end, so
238 	 * don't add the dot here...
239 	 */
240 	snprintf(pnvm_name, sizeof(pnvm_name), "%spnvm",
241 		 trans->cfg->fw_name_pre);
242 
243 	/* ...but replace the hyphen with the dot here. */
244 	if (strlen(trans->cfg->fw_name_pre) < sizeof(pnvm_name))
245 		pnvm_name[strlen(trans->cfg->fw_name_pre) - 1] = '.';
246 
247 	ret = firmware_request_nowarn(&pnvm, pnvm_name, trans->dev);
248 	if (ret) {
249 		IWL_DEBUG_FW(trans, "PNVM file %s not found %d\n",
250 			     pnvm_name, ret);
251 		return ret;
252 	}
253 
254 	*data = kmemdup(pnvm->data, pnvm->size, GFP_KERNEL);
255 	if (!*data)
256 		return -ENOMEM;
257 
258 	*len = pnvm->size;
259 
260 	return 0;
261 }
262 
263 int iwl_pnvm_load(struct iwl_trans *trans,
264 		  struct iwl_notif_wait_data *notif_wait)
265 {
266 	u8 *data;
267 	size_t len;
268 	struct pnvm_sku_package *package;
269 	struct iwl_notification_wait pnvm_wait;
270 	static const u16 ntf_cmds[] = { WIDE_ID(REGULATORY_AND_NVM_GROUP,
271 						PNVM_INIT_COMPLETE_NTFY) };
272 	int ret;
273 
274 	/* if the SKU_ID is empty, there's nothing to do */
275 	if (!trans->sku_id[0] && !trans->sku_id[1] && !trans->sku_id[2])
276 		return 0;
277 
278 	/*
279 	 * If we already loaded (or tried to load) it before, we just
280 	 * need to set it again.
281 	 */
282 	if (trans->pnvm_loaded) {
283 		ret = iwl_trans_set_pnvm(trans, NULL, 0);
284 		if (ret)
285 			return ret;
286 		goto skip_parse;
287 	}
288 
289 	/* First attempt to get the PNVM from BIOS */
290 	package = iwl_uefi_get_pnvm(trans, &len);
291 	if (!IS_ERR_OR_NULL(package)) {
292 		data = kmemdup(package->data, len, GFP_KERNEL);
293 
294 		/* free package regardless of whether kmemdup succeeded */
295 		kfree(package);
296 
297 		if (data) {
298 			/* we need only the data size */
299 			len -= sizeof(*package);
300 			goto parse;
301 		}
302 	}
303 
304 	/* If it's not available, try from the filesystem */
305 	ret = iwl_pnvm_get_from_fs(trans, &data, &len);
306 	if (ret) {
307 		/*
308 		 * Pretend we've loaded it - at least we've tried and
309 		 * couldn't load it at all, so there's no point in
310 		 * trying again over and over.
311 		 */
312 		trans->pnvm_loaded = true;
313 
314 		goto skip_parse;
315 	}
316 
317 parse:
318 	iwl_pnvm_parse(trans, data, len);
319 
320 	kfree(data);
321 
322 skip_parse:
323 	data = NULL;
324 	/* now try to get the reduce power table, if not loaded yet */
325 	if (!trans->reduce_power_loaded) {
326 		data = iwl_uefi_get_reduced_power(trans, &len);
327 		if (IS_ERR_OR_NULL(data)) {
328 			/*
329 			 * Pretend we've loaded it - at least we've tried and
330 			 * couldn't load it at all, so there's no point in
331 			 * trying again over and over.
332 			 */
333 			trans->reduce_power_loaded = true;
334 
335 			goto skip_reduce_power;
336 		}
337 	}
338 
339 	ret = iwl_trans_set_reduce_power(trans, data, len);
340 	if (ret)
341 		IWL_DEBUG_FW(trans,
342 			     "Failed to set reduce power table %d\n",
343 			     ret);
344 	kfree(data);
345 
346 skip_reduce_power:
347 	iwl_init_notification_wait(notif_wait, &pnvm_wait,
348 				   ntf_cmds, ARRAY_SIZE(ntf_cmds),
349 				   iwl_pnvm_complete_fn, trans);
350 
351 	/* kick the doorbell */
352 	iwl_write_umac_prph(trans, UREG_DOORBELL_TO_ISR6,
353 			    UREG_DOORBELL_TO_ISR6_PNVM);
354 
355 	return iwl_wait_notification(notif_wait, &pnvm_wait,
356 				     MVM_UCODE_PNVM_TIMEOUT);
357 }
358 IWL_EXPORT_SYMBOL(iwl_pnvm_load);
359