1 // SPDX-License-Identifier: GPL-2.0
2 /* Copyright (C) 2019-2020 Linaro Limited */
3 
4 #include <linux/acpi.h>
5 #include <linux/firmware.h>
6 #include <linux/module.h>
7 #include <linux/pci.h>
8 #include <linux/slab.h>
9 #include <asm/unaligned.h>
10 
11 #include "xhci.h"
12 #include "xhci-trace.h"
13 #include "xhci-pci.h"
14 
15 #define RENESAS_FW_VERSION				0x6C
16 #define RENESAS_ROM_CONFIG				0xF0
17 #define RENESAS_FW_STATUS				0xF4
18 #define RENESAS_FW_STATUS_MSB				0xF5
19 #define RENESAS_ROM_STATUS				0xF6
20 #define RENESAS_ROM_STATUS_MSB				0xF7
21 #define RENESAS_DATA0					0xF8
22 #define RENESAS_DATA1					0xFC
23 
24 #define RENESAS_FW_VERSION_FIELD			GENMASK(23, 7)
25 #define RENESAS_FW_VERSION_OFFSET			8
26 
27 #define RENESAS_FW_STATUS_DOWNLOAD_ENABLE		BIT(0)
28 #define RENESAS_FW_STATUS_LOCK				BIT(1)
29 #define RENESAS_FW_STATUS_RESULT			GENMASK(6, 4)
30   #define RENESAS_FW_STATUS_INVALID			0
31   #define RENESAS_FW_STATUS_SUCCESS			BIT(4)
32   #define RENESAS_FW_STATUS_ERROR			BIT(5)
33 #define RENESAS_FW_STATUS_SET_DATA0			BIT(8)
34 #define RENESAS_FW_STATUS_SET_DATA1			BIT(9)
35 
36 #define RENESAS_ROM_STATUS_ACCESS			BIT(0)
37 #define RENESAS_ROM_STATUS_ERASE			BIT(1)
38 #define RENESAS_ROM_STATUS_RELOAD			BIT(2)
39 #define RENESAS_ROM_STATUS_RESULT			GENMASK(6, 4)
40   #define RENESAS_ROM_STATUS_NO_RESULT			0
41   #define RENESAS_ROM_STATUS_SUCCESS			BIT(4)
42   #define RENESAS_ROM_STATUS_ERROR			BIT(5)
43 #define RENESAS_ROM_STATUS_SET_DATA0			BIT(8)
44 #define RENESAS_ROM_STATUS_SET_DATA1			BIT(9)
45 #define RENESAS_ROM_STATUS_ROM_EXISTS			BIT(15)
46 
47 #define RENESAS_ROM_ERASE_MAGIC				0x5A65726F
48 #define RENESAS_ROM_WRITE_MAGIC				0x53524F4D
49 
50 #define RENESAS_RETRY	10000
51 #define RENESAS_DELAY	10
52 
53 static int renesas_fw_download_image(struct pci_dev *dev,
54 				     const u32 *fw, size_t step, bool rom)
55 {
56 	size_t i;
57 	int err;
58 	u8 fw_status;
59 	bool data0_or_data1;
60 	u32 status_reg;
61 
62 	if (rom)
63 		status_reg = RENESAS_ROM_STATUS_MSB;
64 	else
65 		status_reg = RENESAS_FW_STATUS_MSB;
66 
67 	/*
68 	 * The hardware does alternate between two 32-bit pages.
69 	 * (This is because each row of the firmware is 8 bytes).
70 	 *
71 	 * for even steps we use DATA0, for odd steps DATA1.
72 	 */
73 	data0_or_data1 = (step & 1) == 1;
74 
75 	/* step+1. Read "Set DATAX" and confirm it is cleared. */
76 	for (i = 0; i < RENESAS_RETRY; i++) {
77 		err = pci_read_config_byte(dev, status_reg, &fw_status);
78 		if (err) {
79 			dev_err(&dev->dev, "Read Status failed: %d\n",
80 				pcibios_err_to_errno(err));
81 			return pcibios_err_to_errno(err);
82 		}
83 		if (!(fw_status & BIT(data0_or_data1)))
84 			break;
85 
86 		udelay(RENESAS_DELAY);
87 	}
88 	if (i == RENESAS_RETRY) {
89 		dev_err(&dev->dev, "Timeout for Set DATAX step: %zd\n", step);
90 		return -ETIMEDOUT;
91 	}
92 
93 	/*
94 	 * step+2. Write FW data to "DATAX".
95 	 * "LSB is left" => force little endian
96 	 */
97 	err = pci_write_config_dword(dev, data0_or_data1 ?
98 				     RENESAS_DATA1 : RENESAS_DATA0,
99 				     (__force u32)cpu_to_le32(fw[step]));
100 	if (err) {
101 		dev_err(&dev->dev, "Write to DATAX failed: %d\n",
102 			pcibios_err_to_errno(err));
103 		return pcibios_err_to_errno(err);
104 	}
105 
106 	udelay(100);
107 
108 	/* step+3. Set "Set DATAX". */
109 	err = pci_write_config_byte(dev, status_reg, BIT(data0_or_data1));
110 	if (err) {
111 		dev_err(&dev->dev, "Write config for DATAX failed: %d\n",
112 			pcibios_err_to_errno(err));
113 		return pcibios_err_to_errno(err);
114 	}
115 
116 	return 0;
117 }
118 
119 static int renesas_fw_verify(const void *fw_data,
120 			     size_t length)
121 {
122 	u16 fw_version_pointer;
123 	u16 fw_version;
124 
125 	/*
126 	 * The Firmware's Data Format is describe in
127 	 * "6.3 Data Format" R19UH0078EJ0500 Rev.5.00 page 124
128 	 */
129 
130 	/*
131 	 * The bootrom chips of the big brother have sizes up to 64k, let's
132 	 * assume that's the biggest the firmware can get.
133 	 */
134 	if (length < 0x1000 || length >= 0x10000) {
135 		pr_err("firmware is size %zd is not (4k - 64k).",
136 			length);
137 		return -EINVAL;
138 	}
139 
140 	/* The First 2 bytes are fixed value (55aa). "LSB on Left" */
141 	if (get_unaligned_le16(fw_data) != 0x55aa) {
142 		pr_err("no valid firmware header found.");
143 		return -EINVAL;
144 	}
145 
146 	/* verify the firmware version position and print it. */
147 	fw_version_pointer = get_unaligned_le16(fw_data + 4);
148 	if (fw_version_pointer + 2 >= length) {
149 		pr_err("fw ver pointer is outside of the firmware image");
150 		return -EINVAL;
151 	}
152 
153 	fw_version = get_unaligned_le16(fw_data + fw_version_pointer);
154 	pr_err("got firmware version: %02x.", fw_version);
155 
156 	return 0;
157 }
158 
159 static bool renesas_check_rom(struct pci_dev *pdev)
160 {
161 	u16 rom_status;
162 	int retval;
163 
164 	/* Check if external ROM exists */
165 	retval = pci_read_config_word(pdev, RENESAS_ROM_STATUS, &rom_status);
166 	if (retval)
167 		return false;
168 
169 	rom_status &= RENESAS_ROM_STATUS_ROM_EXISTS;
170 	if (rom_status) {
171 		dev_dbg(&pdev->dev, "External ROM exists\n");
172 		return true; /* External ROM exists */
173 	}
174 
175 	return false;
176 }
177 
178 static int renesas_check_rom_state(struct pci_dev *pdev)
179 {
180 	u16 rom_state;
181 	u32 version;
182 	int err;
183 
184 	/* check FW version */
185 	err = pci_read_config_dword(pdev, RENESAS_FW_VERSION, &version);
186 	if (err)
187 		return pcibios_err_to_errno(err);
188 
189 	version &= RENESAS_FW_VERSION_FIELD;
190 	version = version >> RENESAS_FW_VERSION_OFFSET;
191 	dev_dbg(&pdev->dev, "Found ROM version: %x\n", version);
192 
193 	/*
194 	 * Test if ROM is present and loaded, if so we can skip everything
195 	 */
196 	err = pci_read_config_word(pdev, RENESAS_ROM_STATUS, &rom_state);
197 	if (err)
198 		return pcibios_err_to_errno(err);
199 
200 	if (rom_state & RENESAS_ROM_STATUS_ROM_EXISTS) {
201 		/* ROM exists */
202 		dev_dbg(&pdev->dev, "ROM exists\n");
203 
204 		/* Check the "Result Code" Bits (6:4) and act accordingly */
205 		switch (rom_state & RENESAS_ROM_STATUS_RESULT) {
206 		case RENESAS_ROM_STATUS_SUCCESS:
207 			return 0;
208 
209 		case RENESAS_ROM_STATUS_NO_RESULT: /* No result yet */
210 			dev_dbg(&pdev->dev, "Unknown ROM status ...\n");
211 			return -ENOENT;
212 
213 		case RENESAS_ROM_STATUS_ERROR: /* Error State */
214 		default: /* All other states are marked as "Reserved states" */
215 			dev_err(&pdev->dev, "Invalid ROM..");
216 			break;
217 		}
218 	}
219 
220 	return -EIO;
221 }
222 
223 static int renesas_fw_check_running(struct pci_dev *pdev)
224 {
225 	u8 fw_state;
226 	int err;
227 
228 	/*
229 	 * Test if the device is actually needing the firmware. As most
230 	 * BIOSes will initialize the device for us. If the device is
231 	 * initialized.
232 	 */
233 	err = pci_read_config_byte(pdev, RENESAS_FW_STATUS, &fw_state);
234 	if (err)
235 		return pcibios_err_to_errno(err);
236 
237 	/*
238 	 * Check if "FW Download Lock" is locked. If it is and the FW is
239 	 * ready we can simply continue. If the FW is not ready, we have
240 	 * to give up.
241 	 */
242 	if (fw_state & RENESAS_FW_STATUS_LOCK) {
243 		dev_dbg(&pdev->dev, "FW Download Lock is engaged.");
244 
245 		if (fw_state & RENESAS_FW_STATUS_SUCCESS)
246 			return 0;
247 
248 		dev_err(&pdev->dev,
249 			"FW Download Lock is set and FW is not ready. Giving Up.");
250 		return -EIO;
251 	}
252 
253 	/*
254 	 * Check if "FW Download Enable" is set. If someone (us?) tampered
255 	 * with it and it can't be reset, we have to give up too... and
256 	 * ask for a forgiveness and a reboot.
257 	 */
258 	if (fw_state & RENESAS_FW_STATUS_DOWNLOAD_ENABLE) {
259 		dev_err(&pdev->dev,
260 			"FW Download Enable is stale. Giving Up (poweroff/reboot needed).");
261 		return -EIO;
262 	}
263 
264 	/* Otherwise, Check the "Result Code" Bits (6:4) and act accordingly */
265 	switch (fw_state & RENESAS_FW_STATUS_RESULT) {
266 	case 0: /* No result yet */
267 		dev_dbg(&pdev->dev, "FW is not ready/loaded yet.");
268 
269 		/* tell the caller, that this device needs the firmware. */
270 		return 1;
271 
272 	case RENESAS_FW_STATUS_SUCCESS: /* Success, device should be working. */
273 		dev_dbg(&pdev->dev, "FW is ready.");
274 		return 0;
275 
276 	case RENESAS_FW_STATUS_ERROR: /* Error State */
277 		dev_err(&pdev->dev,
278 			"hardware is in an error state. Giving up (poweroff/reboot needed).");
279 		return -ENODEV;
280 
281 	default: /* All other states are marked as "Reserved states" */
282 		dev_err(&pdev->dev,
283 			"hardware is in an invalid state %lx. Giving up (poweroff/reboot needed).",
284 			(fw_state & RENESAS_FW_STATUS_RESULT) >> 4);
285 		return -EINVAL;
286 	}
287 }
288 
289 static int renesas_fw_download(struct pci_dev *pdev,
290 			       const struct firmware *fw)
291 {
292 	const u32 *fw_data = (const u32 *)fw->data;
293 	size_t i;
294 	int err;
295 	u8 fw_status;
296 
297 	/*
298 	 * For more information and the big picture: please look at the
299 	 * "Firmware Download Sequence" in "7.1 FW Download Interface"
300 	 * of R19UH0078EJ0500 Rev.5.00 page 131
301 	 */
302 
303 	/*
304 	 * 0. Set "FW Download Enable" bit in the
305 	 * "FW Download Control & Status Register" at 0xF4
306 	 */
307 	err = pci_write_config_byte(pdev, RENESAS_FW_STATUS,
308 				    RENESAS_FW_STATUS_DOWNLOAD_ENABLE);
309 	if (err)
310 		return pcibios_err_to_errno(err);
311 
312 	/* 1 - 10 follow one step after the other. */
313 	for (i = 0; i < fw->size / 4; i++) {
314 		err = renesas_fw_download_image(pdev, fw_data, i, false);
315 		if (err) {
316 			dev_err(&pdev->dev,
317 				"Firmware Download Step %zd failed at position %zd bytes with (%d).",
318 				i, i * 4, err);
319 			return err;
320 		}
321 	}
322 
323 	/*
324 	 * This sequence continues until the last data is written to
325 	 * "DATA0" or "DATA1". Naturally, we wait until "SET DATA0/1"
326 	 * is cleared by the hardware beforehand.
327 	 */
328 	for (i = 0; i < RENESAS_RETRY; i++) {
329 		err = pci_read_config_byte(pdev, RENESAS_FW_STATUS_MSB,
330 					   &fw_status);
331 		if (err)
332 			return pcibios_err_to_errno(err);
333 		if (!(fw_status & (BIT(0) | BIT(1))))
334 			break;
335 
336 		udelay(RENESAS_DELAY);
337 	}
338 	if (i == RENESAS_RETRY)
339 		dev_warn(&pdev->dev, "Final Firmware Download step timed out.");
340 
341 	/*
342 	 * 11. After finishing writing the last data of FW, the
343 	 * System Software must clear "FW Download Enable"
344 	 */
345 	err = pci_write_config_byte(pdev, RENESAS_FW_STATUS, 0);
346 	if (err)
347 		return pcibios_err_to_errno(err);
348 
349 	/* 12. Read "Result Code" and confirm it is good. */
350 	for (i = 0; i < RENESAS_RETRY; i++) {
351 		err = pci_read_config_byte(pdev, RENESAS_FW_STATUS, &fw_status);
352 		if (err)
353 			return pcibios_err_to_errno(err);
354 		if (fw_status & RENESAS_FW_STATUS_SUCCESS)
355 			break;
356 
357 		udelay(RENESAS_DELAY);
358 	}
359 	if (i == RENESAS_RETRY) {
360 		/* Timed out / Error - let's see if we can fix this */
361 		err = renesas_fw_check_running(pdev);
362 		switch (err) {
363 		case 0: /*
364 			 * we shouldn't end up here.
365 			 * maybe it took a little bit longer.
366 			 * But all should be well?
367 			 */
368 			break;
369 
370 		case 1: /* (No result yet! */
371 			dev_err(&pdev->dev, "FW Load timedout");
372 			return -ETIMEDOUT;
373 
374 		default:
375 			return err;
376 		}
377 	}
378 
379 	return 0;
380 }
381 
382 static void renesas_rom_erase(struct pci_dev *pdev)
383 {
384 	int retval, i;
385 	u8 status;
386 
387 	dev_dbg(&pdev->dev, "Performing ROM Erase...\n");
388 	retval = pci_write_config_dword(pdev, RENESAS_DATA0,
389 					RENESAS_ROM_ERASE_MAGIC);
390 	if (retval) {
391 		dev_err(&pdev->dev, "ROM erase, magic word write failed: %d\n",
392 			pcibios_err_to_errno(retval));
393 		return;
394 	}
395 
396 	retval = pci_read_config_byte(pdev, RENESAS_ROM_STATUS, &status);
397 	if (retval) {
398 		dev_err(&pdev->dev, "ROM status read failed: %d\n",
399 			pcibios_err_to_errno(retval));
400 		return;
401 	}
402 	status |= RENESAS_ROM_STATUS_ERASE;
403 	retval = pci_write_config_byte(pdev, RENESAS_ROM_STATUS, status);
404 	if (retval) {
405 		dev_err(&pdev->dev, "ROM erase set word write failed\n");
406 		return;
407 	}
408 
409 	/* sleep a bit while ROM is erased */
410 	msleep(20);
411 
412 	for (i = 0; i < RENESAS_RETRY; i++) {
413 		retval = pci_read_config_byte(pdev, RENESAS_ROM_STATUS,
414 					      &status);
415 		status &= RENESAS_ROM_STATUS_ERASE;
416 		if (!status)
417 			break;
418 
419 		mdelay(RENESAS_DELAY);
420 	}
421 
422 	if (i == RENESAS_RETRY)
423 		dev_dbg(&pdev->dev, "Chip erase timedout: %x\n", status);
424 
425 	dev_dbg(&pdev->dev, "ROM Erase... Done success\n");
426 }
427 
428 static bool renesas_setup_rom(struct pci_dev *pdev, const struct firmware *fw)
429 {
430 	const u32 *fw_data = (const u32 *)fw->data;
431 	int err, i;
432 	u8 status;
433 
434 	/* 2. Write magic word to Data0 */
435 	err = pci_write_config_dword(pdev, RENESAS_DATA0,
436 				     RENESAS_ROM_WRITE_MAGIC);
437 	if (err)
438 		return false;
439 
440 	/* 3. Set External ROM access */
441 	err = pci_write_config_byte(pdev, RENESAS_ROM_STATUS,
442 				    RENESAS_ROM_STATUS_ACCESS);
443 	if (err)
444 		goto remove_bypass;
445 
446 	/* 4. Check the result */
447 	err = pci_read_config_byte(pdev, RENESAS_ROM_STATUS, &status);
448 	if (err)
449 		goto remove_bypass;
450 	status &= GENMASK(6, 4);
451 	if (status) {
452 		dev_err(&pdev->dev,
453 			"setting external rom failed: %x\n", status);
454 		goto remove_bypass;
455 	}
456 
457 	/* 5 to 16 Write FW to DATA0/1 while checking SetData0/1 */
458 	for (i = 0; i < fw->size / 4; i++) {
459 		err = renesas_fw_download_image(pdev, fw_data, i, true);
460 		if (err) {
461 			dev_err(&pdev->dev,
462 				"ROM Download Step %d failed at position %d bytes with (%d)\n",
463 				 i, i * 4, err);
464 			goto remove_bypass;
465 		}
466 	}
467 
468 	/*
469 	 * wait till DATA0/1 is cleared
470 	 */
471 	for (i = 0; i < RENESAS_RETRY; i++) {
472 		err = pci_read_config_byte(pdev, RENESAS_ROM_STATUS_MSB,
473 					   &status);
474 		if (err)
475 			goto remove_bypass;
476 		if (!(status & (BIT(0) | BIT(1))))
477 			break;
478 
479 		udelay(RENESAS_DELAY);
480 	}
481 	if (i == RENESAS_RETRY) {
482 		dev_err(&pdev->dev, "Final Firmware ROM Download step timed out\n");
483 		goto remove_bypass;
484 	}
485 
486 	/* 17. Remove bypass */
487 	err = pci_write_config_byte(pdev, RENESAS_ROM_STATUS, 0);
488 	if (err)
489 		return false;
490 
491 	udelay(10);
492 
493 	/* 18. check result */
494 	for (i = 0; i < RENESAS_RETRY; i++) {
495 		err = pci_read_config_byte(pdev, RENESAS_ROM_STATUS, &status);
496 		if (err) {
497 			dev_err(&pdev->dev, "Read ROM status failed:%d\n",
498 				pcibios_err_to_errno(err));
499 			return false;
500 		}
501 		status &= RENESAS_ROM_STATUS_RESULT;
502 		if (status ==  RENESAS_ROM_STATUS_SUCCESS) {
503 			dev_dbg(&pdev->dev, "Download ROM success\n");
504 			break;
505 		}
506 		udelay(RENESAS_DELAY);
507 	}
508 	if (i == RENESAS_RETRY) { /* Timed out */
509 		dev_err(&pdev->dev,
510 			"Download to external ROM TO: %x\n", status);
511 		return false;
512 	}
513 
514 	dev_dbg(&pdev->dev, "Download to external ROM succeeded\n");
515 
516 	/* Last step set Reload */
517 	err = pci_write_config_byte(pdev, RENESAS_ROM_STATUS,
518 				    RENESAS_ROM_STATUS_RELOAD);
519 	if (err) {
520 		dev_err(&pdev->dev, "Set ROM execute failed: %d\n",
521 			pcibios_err_to_errno(err));
522 		return false;
523 	}
524 
525 	/*
526 	 * wait till Reload is cleared
527 	 */
528 	for (i = 0; i < RENESAS_RETRY; i++) {
529 		err = pci_read_config_byte(pdev, RENESAS_ROM_STATUS, &status);
530 		if (err)
531 			return false;
532 		if (!(status & RENESAS_ROM_STATUS_RELOAD))
533 			break;
534 
535 		udelay(RENESAS_DELAY);
536 	}
537 	if (i == RENESAS_RETRY) {
538 		dev_err(&pdev->dev, "ROM Exec timed out: %x\n", status);
539 		return false;
540 	}
541 
542 	return true;
543 
544 remove_bypass:
545 	pci_write_config_byte(pdev, RENESAS_ROM_STATUS, 0);
546 	return false;
547 }
548 
549 static int renesas_load_fw(struct pci_dev *pdev, const struct firmware *fw)
550 {
551 	int err = 0;
552 	bool rom;
553 
554 	/* Check if the device has external ROM */
555 	rom = renesas_check_rom(pdev);
556 	if (rom) {
557 		/* perform chip erase first */
558 		renesas_rom_erase(pdev);
559 
560 		/* lets try loading fw on ROM first */
561 		rom = renesas_setup_rom(pdev, fw);
562 		if (!rom) {
563 			dev_dbg(&pdev->dev,
564 				"ROM load failed, falling back on FW load\n");
565 		} else {
566 			dev_dbg(&pdev->dev,
567 				"ROM load success\n");
568 			goto exit;
569 		}
570 	}
571 
572 	err = renesas_fw_download(pdev, fw);
573 
574 exit:
575 	if (err)
576 		dev_err(&pdev->dev, "firmware failed to download (%d).", err);
577 	return err;
578 }
579 
580 int renesas_xhci_check_request_fw(struct pci_dev *pdev,
581 				  const struct pci_device_id *id)
582 {
583 	struct xhci_driver_data *driver_data =
584 			(struct xhci_driver_data *)id->driver_data;
585 	const char *fw_name = driver_data->firmware;
586 	const struct firmware *fw;
587 	bool has_rom;
588 	int err;
589 
590 	/* Check if device has ROM and loaded, if so skip everything */
591 	has_rom = renesas_check_rom(pdev);
592 	if (has_rom) {
593 		err = renesas_check_rom_state(pdev);
594 		if (!err)
595 			return 0;
596 		else if (err != -ENOENT)
597 			has_rom = false;
598 	}
599 
600 	err = renesas_fw_check_running(pdev);
601 	/* Continue ahead, if the firmware is already running. */
602 	if (!err)
603 		return 0;
604 
605 	/* no firmware interface available */
606 	if (err != 1)
607 		return has_rom ? 0 : err;
608 
609 	pci_dev_get(pdev);
610 	err = firmware_request_nowarn(&fw, fw_name, &pdev->dev);
611 	pci_dev_put(pdev);
612 	if (err) {
613 		if (has_rom) {
614 			dev_info(&pdev->dev, "failed to load firmware %s, fallback to ROM\n",
615 				 fw_name);
616 			return 0;
617 		}
618 		dev_err(&pdev->dev, "failed to load firmware %s: %d\n",
619 			fw_name, err);
620 		return err;
621 	}
622 
623 	err = renesas_fw_verify(fw->data, fw->size);
624 	if (err)
625 		goto exit;
626 
627 	err = renesas_load_fw(pdev, fw);
628 exit:
629 	release_firmware(fw);
630 	return err;
631 }
632 EXPORT_SYMBOL_GPL(renesas_xhci_check_request_fw);
633 
634 MODULE_LICENSE("GPL v2");
635