1 // SPDX-License-Identifier: GPL-2.0 2 /* Copyright (C) 2019-2020 Linaro Limited */ 3 4 #include <linux/acpi.h> 5 #include <linux/firmware.h> 6 #include <linux/module.h> 7 #include <linux/pci.h> 8 #include <linux/slab.h> 9 #include <asm/unaligned.h> 10 11 #include "xhci.h" 12 #include "xhci-trace.h" 13 #include "xhci-pci.h" 14 15 #define RENESAS_FW_VERSION 0x6C 16 #define RENESAS_ROM_CONFIG 0xF0 17 #define RENESAS_FW_STATUS 0xF4 18 #define RENESAS_FW_STATUS_MSB 0xF5 19 #define RENESAS_ROM_STATUS 0xF6 20 #define RENESAS_ROM_STATUS_MSB 0xF7 21 #define RENESAS_DATA0 0xF8 22 #define RENESAS_DATA1 0xFC 23 24 #define RENESAS_FW_VERSION_FIELD GENMASK(23, 7) 25 #define RENESAS_FW_VERSION_OFFSET 8 26 27 #define RENESAS_FW_STATUS_DOWNLOAD_ENABLE BIT(0) 28 #define RENESAS_FW_STATUS_LOCK BIT(1) 29 #define RENESAS_FW_STATUS_RESULT GENMASK(6, 4) 30 #define RENESAS_FW_STATUS_INVALID 0 31 #define RENESAS_FW_STATUS_SUCCESS BIT(4) 32 #define RENESAS_FW_STATUS_ERROR BIT(5) 33 #define RENESAS_FW_STATUS_SET_DATA0 BIT(8) 34 #define RENESAS_FW_STATUS_SET_DATA1 BIT(9) 35 36 #define RENESAS_ROM_STATUS_ACCESS BIT(0) 37 #define RENESAS_ROM_STATUS_ERASE BIT(1) 38 #define RENESAS_ROM_STATUS_RELOAD BIT(2) 39 #define RENESAS_ROM_STATUS_RESULT GENMASK(6, 4) 40 #define RENESAS_ROM_STATUS_NO_RESULT 0 41 #define RENESAS_ROM_STATUS_SUCCESS BIT(4) 42 #define RENESAS_ROM_STATUS_ERROR BIT(5) 43 #define RENESAS_ROM_STATUS_SET_DATA0 BIT(8) 44 #define RENESAS_ROM_STATUS_SET_DATA1 BIT(9) 45 #define RENESAS_ROM_STATUS_ROM_EXISTS BIT(15) 46 47 #define RENESAS_ROM_ERASE_MAGIC 0x5A65726F 48 #define RENESAS_ROM_WRITE_MAGIC 0x53524F4D 49 50 #define RENESAS_RETRY 10000 51 #define RENESAS_DELAY 10 52 53 static int renesas_fw_download_image(struct pci_dev *dev, 54 const u32 *fw, size_t step, bool rom) 55 { 56 size_t i; 57 int err; 58 u8 fw_status; 59 bool data0_or_data1; 60 u32 status_reg; 61 62 if (rom) 63 status_reg = RENESAS_ROM_STATUS_MSB; 64 else 65 status_reg = RENESAS_FW_STATUS_MSB; 66 67 /* 68 * The hardware does alternate between two 32-bit pages. 69 * (This is because each row of the firmware is 8 bytes). 70 * 71 * for even steps we use DATA0, for odd steps DATA1. 72 */ 73 data0_or_data1 = (step & 1) == 1; 74 75 /* step+1. Read "Set DATAX" and confirm it is cleared. */ 76 for (i = 0; i < RENESAS_RETRY; i++) { 77 err = pci_read_config_byte(dev, status_reg, &fw_status); 78 if (err) { 79 dev_err(&dev->dev, "Read Status failed: %d\n", 80 pcibios_err_to_errno(err)); 81 return pcibios_err_to_errno(err); 82 } 83 if (!(fw_status & BIT(data0_or_data1))) 84 break; 85 86 udelay(RENESAS_DELAY); 87 } 88 if (i == RENESAS_RETRY) { 89 dev_err(&dev->dev, "Timeout for Set DATAX step: %zd\n", step); 90 return -ETIMEDOUT; 91 } 92 93 /* 94 * step+2. Write FW data to "DATAX". 95 * "LSB is left" => force little endian 96 */ 97 err = pci_write_config_dword(dev, data0_or_data1 ? 98 RENESAS_DATA1 : RENESAS_DATA0, 99 (__force u32)cpu_to_le32(fw[step])); 100 if (err) { 101 dev_err(&dev->dev, "Write to DATAX failed: %d\n", 102 pcibios_err_to_errno(err)); 103 return pcibios_err_to_errno(err); 104 } 105 106 udelay(100); 107 108 /* step+3. Set "Set DATAX". */ 109 err = pci_write_config_byte(dev, status_reg, BIT(data0_or_data1)); 110 if (err) { 111 dev_err(&dev->dev, "Write config for DATAX failed: %d\n", 112 pcibios_err_to_errno(err)); 113 return pcibios_err_to_errno(err); 114 } 115 116 return 0; 117 } 118 119 static int renesas_fw_verify(const void *fw_data, 120 size_t length) 121 { 122 u16 fw_version_pointer; 123 u16 fw_version; 124 125 /* 126 * The Firmware's Data Format is describe in 127 * "6.3 Data Format" R19UH0078EJ0500 Rev.5.00 page 124 128 */ 129 130 /* 131 * The bootrom chips of the big brother have sizes up to 64k, let's 132 * assume that's the biggest the firmware can get. 133 */ 134 if (length < 0x1000 || length >= 0x10000) { 135 pr_err("firmware is size %zd is not (4k - 64k).", 136 length); 137 return -EINVAL; 138 } 139 140 /* The First 2 bytes are fixed value (55aa). "LSB on Left" */ 141 if (get_unaligned_le16(fw_data) != 0x55aa) { 142 pr_err("no valid firmware header found."); 143 return -EINVAL; 144 } 145 146 /* verify the firmware version position and print it. */ 147 fw_version_pointer = get_unaligned_le16(fw_data + 4); 148 if (fw_version_pointer + 2 >= length) { 149 pr_err("fw ver pointer is outside of the firmware image"); 150 return -EINVAL; 151 } 152 153 fw_version = get_unaligned_le16(fw_data + fw_version_pointer); 154 pr_err("got firmware version: %02x.", fw_version); 155 156 return 0; 157 } 158 159 static bool renesas_check_rom(struct pci_dev *pdev) 160 { 161 u16 rom_status; 162 int retval; 163 164 /* Check if external ROM exists */ 165 retval = pci_read_config_word(pdev, RENESAS_ROM_STATUS, &rom_status); 166 if (retval) 167 return false; 168 169 rom_status &= RENESAS_ROM_STATUS_ROM_EXISTS; 170 if (rom_status) { 171 dev_dbg(&pdev->dev, "External ROM exists\n"); 172 return true; /* External ROM exists */ 173 } 174 175 return false; 176 } 177 178 static int renesas_check_rom_state(struct pci_dev *pdev) 179 { 180 u16 rom_state; 181 u32 version; 182 int err; 183 184 /* check FW version */ 185 err = pci_read_config_dword(pdev, RENESAS_FW_VERSION, &version); 186 if (err) 187 return pcibios_err_to_errno(err); 188 189 version &= RENESAS_FW_VERSION_FIELD; 190 version = version >> RENESAS_FW_VERSION_OFFSET; 191 dev_dbg(&pdev->dev, "Found ROM version: %x\n", version); 192 193 /* 194 * Test if ROM is present and loaded, if so we can skip everything 195 */ 196 err = pci_read_config_word(pdev, RENESAS_ROM_STATUS, &rom_state); 197 if (err) 198 return pcibios_err_to_errno(err); 199 200 if (rom_state & RENESAS_ROM_STATUS_ROM_EXISTS) { 201 /* ROM exists */ 202 dev_dbg(&pdev->dev, "ROM exists\n"); 203 204 /* Check the "Result Code" Bits (6:4) and act accordingly */ 205 switch (rom_state & RENESAS_ROM_STATUS_RESULT) { 206 case RENESAS_ROM_STATUS_SUCCESS: 207 return 0; 208 209 case RENESAS_ROM_STATUS_NO_RESULT: /* No result yet */ 210 dev_dbg(&pdev->dev, "Unknown ROM status ...\n"); 211 return -ENOENT; 212 213 case RENESAS_ROM_STATUS_ERROR: /* Error State */ 214 default: /* All other states are marked as "Reserved states" */ 215 dev_err(&pdev->dev, "Invalid ROM.."); 216 break; 217 } 218 } 219 220 return -EIO; 221 } 222 223 static int renesas_fw_check_running(struct pci_dev *pdev) 224 { 225 u8 fw_state; 226 int err; 227 228 /* 229 * Test if the device is actually needing the firmware. As most 230 * BIOSes will initialize the device for us. If the device is 231 * initialized. 232 */ 233 err = pci_read_config_byte(pdev, RENESAS_FW_STATUS, &fw_state); 234 if (err) 235 return pcibios_err_to_errno(err); 236 237 /* 238 * Check if "FW Download Lock" is locked. If it is and the FW is 239 * ready we can simply continue. If the FW is not ready, we have 240 * to give up. 241 */ 242 if (fw_state & RENESAS_FW_STATUS_LOCK) { 243 dev_dbg(&pdev->dev, "FW Download Lock is engaged."); 244 245 if (fw_state & RENESAS_FW_STATUS_SUCCESS) 246 return 0; 247 248 dev_err(&pdev->dev, 249 "FW Download Lock is set and FW is not ready. Giving Up."); 250 return -EIO; 251 } 252 253 /* 254 * Check if "FW Download Enable" is set. If someone (us?) tampered 255 * with it and it can't be reset, we have to give up too... and 256 * ask for a forgiveness and a reboot. 257 */ 258 if (fw_state & RENESAS_FW_STATUS_DOWNLOAD_ENABLE) { 259 dev_err(&pdev->dev, 260 "FW Download Enable is stale. Giving Up (poweroff/reboot needed)."); 261 return -EIO; 262 } 263 264 /* Otherwise, Check the "Result Code" Bits (6:4) and act accordingly */ 265 switch (fw_state & RENESAS_FW_STATUS_RESULT) { 266 case 0: /* No result yet */ 267 dev_dbg(&pdev->dev, "FW is not ready/loaded yet."); 268 269 /* tell the caller, that this device needs the firmware. */ 270 return 1; 271 272 case RENESAS_FW_STATUS_SUCCESS: /* Success, device should be working. */ 273 dev_dbg(&pdev->dev, "FW is ready."); 274 return 0; 275 276 case RENESAS_FW_STATUS_ERROR: /* Error State */ 277 dev_err(&pdev->dev, 278 "hardware is in an error state. Giving up (poweroff/reboot needed)."); 279 return -ENODEV; 280 281 default: /* All other states are marked as "Reserved states" */ 282 dev_err(&pdev->dev, 283 "hardware is in an invalid state %lx. Giving up (poweroff/reboot needed).", 284 (fw_state & RENESAS_FW_STATUS_RESULT) >> 4); 285 return -EINVAL; 286 } 287 } 288 289 static int renesas_fw_download(struct pci_dev *pdev, 290 const struct firmware *fw) 291 { 292 const u32 *fw_data = (const u32 *)fw->data; 293 size_t i; 294 int err; 295 u8 fw_status; 296 297 /* 298 * For more information and the big picture: please look at the 299 * "Firmware Download Sequence" in "7.1 FW Download Interface" 300 * of R19UH0078EJ0500 Rev.5.00 page 131 301 */ 302 303 /* 304 * 0. Set "FW Download Enable" bit in the 305 * "FW Download Control & Status Register" at 0xF4 306 */ 307 err = pci_write_config_byte(pdev, RENESAS_FW_STATUS, 308 RENESAS_FW_STATUS_DOWNLOAD_ENABLE); 309 if (err) 310 return pcibios_err_to_errno(err); 311 312 /* 1 - 10 follow one step after the other. */ 313 for (i = 0; i < fw->size / 4; i++) { 314 err = renesas_fw_download_image(pdev, fw_data, i, false); 315 if (err) { 316 dev_err(&pdev->dev, 317 "Firmware Download Step %zd failed at position %zd bytes with (%d).", 318 i, i * 4, err); 319 return err; 320 } 321 } 322 323 /* 324 * This sequence continues until the last data is written to 325 * "DATA0" or "DATA1". Naturally, we wait until "SET DATA0/1" 326 * is cleared by the hardware beforehand. 327 */ 328 for (i = 0; i < RENESAS_RETRY; i++) { 329 err = pci_read_config_byte(pdev, RENESAS_FW_STATUS_MSB, 330 &fw_status); 331 if (err) 332 return pcibios_err_to_errno(err); 333 if (!(fw_status & (BIT(0) | BIT(1)))) 334 break; 335 336 udelay(RENESAS_DELAY); 337 } 338 if (i == RENESAS_RETRY) 339 dev_warn(&pdev->dev, "Final Firmware Download step timed out."); 340 341 /* 342 * 11. After finishing writing the last data of FW, the 343 * System Software must clear "FW Download Enable" 344 */ 345 err = pci_write_config_byte(pdev, RENESAS_FW_STATUS, 0); 346 if (err) 347 return pcibios_err_to_errno(err); 348 349 /* 12. Read "Result Code" and confirm it is good. */ 350 for (i = 0; i < RENESAS_RETRY; i++) { 351 err = pci_read_config_byte(pdev, RENESAS_FW_STATUS, &fw_status); 352 if (err) 353 return pcibios_err_to_errno(err); 354 if (fw_status & RENESAS_FW_STATUS_SUCCESS) 355 break; 356 357 udelay(RENESAS_DELAY); 358 } 359 if (i == RENESAS_RETRY) { 360 /* Timed out / Error - let's see if we can fix this */ 361 err = renesas_fw_check_running(pdev); 362 switch (err) { 363 case 0: /* 364 * we shouldn't end up here. 365 * maybe it took a little bit longer. 366 * But all should be well? 367 */ 368 break; 369 370 case 1: /* (No result yet! */ 371 dev_err(&pdev->dev, "FW Load timedout"); 372 return -ETIMEDOUT; 373 374 default: 375 return err; 376 } 377 } 378 379 return 0; 380 } 381 382 static void renesas_rom_erase(struct pci_dev *pdev) 383 { 384 int retval, i; 385 u8 status; 386 387 dev_dbg(&pdev->dev, "Performing ROM Erase...\n"); 388 retval = pci_write_config_dword(pdev, RENESAS_DATA0, 389 RENESAS_ROM_ERASE_MAGIC); 390 if (retval) { 391 dev_err(&pdev->dev, "ROM erase, magic word write failed: %d\n", 392 pcibios_err_to_errno(retval)); 393 return; 394 } 395 396 retval = pci_read_config_byte(pdev, RENESAS_ROM_STATUS, &status); 397 if (retval) { 398 dev_err(&pdev->dev, "ROM status read failed: %d\n", 399 pcibios_err_to_errno(retval)); 400 return; 401 } 402 status |= RENESAS_ROM_STATUS_ERASE; 403 retval = pci_write_config_byte(pdev, RENESAS_ROM_STATUS, status); 404 if (retval) { 405 dev_err(&pdev->dev, "ROM erase set word write failed\n"); 406 return; 407 } 408 409 /* sleep a bit while ROM is erased */ 410 msleep(20); 411 412 for (i = 0; i < RENESAS_RETRY; i++) { 413 retval = pci_read_config_byte(pdev, RENESAS_ROM_STATUS, 414 &status); 415 status &= RENESAS_ROM_STATUS_ERASE; 416 if (!status) 417 break; 418 419 mdelay(RENESAS_DELAY); 420 } 421 422 if (i == RENESAS_RETRY) 423 dev_dbg(&pdev->dev, "Chip erase timedout: %x\n", status); 424 425 dev_dbg(&pdev->dev, "ROM Erase... Done success\n"); 426 } 427 428 static bool renesas_setup_rom(struct pci_dev *pdev, const struct firmware *fw) 429 { 430 const u32 *fw_data = (const u32 *)fw->data; 431 int err, i; 432 u8 status; 433 434 /* 2. Write magic word to Data0 */ 435 err = pci_write_config_dword(pdev, RENESAS_DATA0, 436 RENESAS_ROM_WRITE_MAGIC); 437 if (err) 438 return false; 439 440 /* 3. Set External ROM access */ 441 err = pci_write_config_byte(pdev, RENESAS_ROM_STATUS, 442 RENESAS_ROM_STATUS_ACCESS); 443 if (err) 444 goto remove_bypass; 445 446 /* 4. Check the result */ 447 err = pci_read_config_byte(pdev, RENESAS_ROM_STATUS, &status); 448 if (err) 449 goto remove_bypass; 450 status &= GENMASK(6, 4); 451 if (status) { 452 dev_err(&pdev->dev, 453 "setting external rom failed: %x\n", status); 454 goto remove_bypass; 455 } 456 457 /* 5 to 16 Write FW to DATA0/1 while checking SetData0/1 */ 458 for (i = 0; i < fw->size / 4; i++) { 459 err = renesas_fw_download_image(pdev, fw_data, i, true); 460 if (err) { 461 dev_err(&pdev->dev, 462 "ROM Download Step %d failed at position %d bytes with (%d)\n", 463 i, i * 4, err); 464 goto remove_bypass; 465 } 466 } 467 468 /* 469 * wait till DATA0/1 is cleared 470 */ 471 for (i = 0; i < RENESAS_RETRY; i++) { 472 err = pci_read_config_byte(pdev, RENESAS_ROM_STATUS_MSB, 473 &status); 474 if (err) 475 goto remove_bypass; 476 if (!(status & (BIT(0) | BIT(1)))) 477 break; 478 479 udelay(RENESAS_DELAY); 480 } 481 if (i == RENESAS_RETRY) { 482 dev_err(&pdev->dev, "Final Firmware ROM Download step timed out\n"); 483 goto remove_bypass; 484 } 485 486 /* 17. Remove bypass */ 487 err = pci_write_config_byte(pdev, RENESAS_ROM_STATUS, 0); 488 if (err) 489 return false; 490 491 udelay(10); 492 493 /* 18. check result */ 494 for (i = 0; i < RENESAS_RETRY; i++) { 495 err = pci_read_config_byte(pdev, RENESAS_ROM_STATUS, &status); 496 if (err) { 497 dev_err(&pdev->dev, "Read ROM status failed:%d\n", 498 pcibios_err_to_errno(err)); 499 return false; 500 } 501 status &= RENESAS_ROM_STATUS_RESULT; 502 if (status == RENESAS_ROM_STATUS_SUCCESS) { 503 dev_dbg(&pdev->dev, "Download ROM success\n"); 504 break; 505 } 506 udelay(RENESAS_DELAY); 507 } 508 if (i == RENESAS_RETRY) { /* Timed out */ 509 dev_err(&pdev->dev, 510 "Download to external ROM TO: %x\n", status); 511 return false; 512 } 513 514 dev_dbg(&pdev->dev, "Download to external ROM succeeded\n"); 515 516 /* Last step set Reload */ 517 err = pci_write_config_byte(pdev, RENESAS_ROM_STATUS, 518 RENESAS_ROM_STATUS_RELOAD); 519 if (err) { 520 dev_err(&pdev->dev, "Set ROM execute failed: %d\n", 521 pcibios_err_to_errno(err)); 522 return false; 523 } 524 525 /* 526 * wait till Reload is cleared 527 */ 528 for (i = 0; i < RENESAS_RETRY; i++) { 529 err = pci_read_config_byte(pdev, RENESAS_ROM_STATUS, &status); 530 if (err) 531 return false; 532 if (!(status & RENESAS_ROM_STATUS_RELOAD)) 533 break; 534 535 udelay(RENESAS_DELAY); 536 } 537 if (i == RENESAS_RETRY) { 538 dev_err(&pdev->dev, "ROM Exec timed out: %x\n", status); 539 return false; 540 } 541 542 return true; 543 544 remove_bypass: 545 pci_write_config_byte(pdev, RENESAS_ROM_STATUS, 0); 546 return false; 547 } 548 549 static int renesas_load_fw(struct pci_dev *pdev, const struct firmware *fw) 550 { 551 int err = 0; 552 bool rom; 553 554 /* Check if the device has external ROM */ 555 rom = renesas_check_rom(pdev); 556 if (rom) { 557 /* perform chip erase first */ 558 renesas_rom_erase(pdev); 559 560 /* lets try loading fw on ROM first */ 561 rom = renesas_setup_rom(pdev, fw); 562 if (!rom) { 563 dev_dbg(&pdev->dev, 564 "ROM load failed, falling back on FW load\n"); 565 } else { 566 dev_dbg(&pdev->dev, 567 "ROM load success\n"); 568 goto exit; 569 } 570 } 571 572 err = renesas_fw_download(pdev, fw); 573 574 exit: 575 if (err) 576 dev_err(&pdev->dev, "firmware failed to download (%d).", err); 577 return err; 578 } 579 580 int renesas_xhci_check_request_fw(struct pci_dev *pdev, 581 const struct pci_device_id *id) 582 { 583 struct xhci_driver_data *driver_data = 584 (struct xhci_driver_data *)id->driver_data; 585 const char *fw_name = driver_data->firmware; 586 const struct firmware *fw; 587 bool has_rom; 588 int err; 589 590 /* Check if device has ROM and loaded, if so skip everything */ 591 has_rom = renesas_check_rom(pdev); 592 if (has_rom) { 593 err = renesas_check_rom_state(pdev); 594 if (!err) 595 return 0; 596 else if (err != -ENOENT) 597 has_rom = false; 598 } 599 600 err = renesas_fw_check_running(pdev); 601 /* Continue ahead, if the firmware is already running. */ 602 if (!err) 603 return 0; 604 605 /* no firmware interface available */ 606 if (err != 1) 607 return has_rom ? 0 : err; 608 609 pci_dev_get(pdev); 610 err = firmware_request_nowarn(&fw, fw_name, &pdev->dev); 611 pci_dev_put(pdev); 612 if (err) { 613 if (has_rom) { 614 dev_info(&pdev->dev, "failed to load firmware %s, fallback to ROM\n", 615 fw_name); 616 return 0; 617 } 618 dev_err(&pdev->dev, "failed to load firmware %s: %d\n", 619 fw_name, err); 620 return err; 621 } 622 623 err = renesas_fw_verify(fw->data, fw->size); 624 if (err) 625 goto exit; 626 627 err = renesas_load_fw(pdev, fw); 628 exit: 629 release_firmware(fw); 630 return err; 631 } 632 EXPORT_SYMBOL_GPL(renesas_xhci_check_request_fw); 633 634 MODULE_LICENSE("GPL v2"); 635