Changes in 4.9.249 spi: bcm2835aux: Fix use-after-free on unbind spi: bcm2835aux: Restore err assignment in bcm2835aux_spi_probe iwlwifi: pcie: limit memory read spin time arm64: dts: rockchip: Assign a fixed index to mmc devices on rk3399 boards. ARC: stack unwinding: don't assume non-current task is sleeping platform/x86: acer-wmi: add automatic keyboard background light toggle key as KEY_LIGHTS_TOGGLE Input: cm109 - do not stomp on control URB Input: i8042 - add Acer laptops to the i8042 reset list pinctrl: amd: remove debounce filter setting in IRQ type setting scsi: be2iscsi: Revert "Fix a theoretical leak in beiscsi_create_eqs()" spi: Prevent adding devices below an unregistering controller net/mlx4_en: Avoid scheduling restart task if it is already running tcp: fix cwnd-limited bug for TSO deferral where we send nothing net: stmmac: delete the eee_ctrl_timer after napi disabled net: stmmac: dwmac-meson8b: fix mask definition of the m250_sel mux net: bridge: vlan: fix error return code in __vlan_add() mac80211: mesh: fix mesh_pathtbl_init() error path USB: dummy-hcd: Fix uninitialized array use in init() USB: add RESET_RESUME quirk for Snapscan 1212 ALSA: usb-audio: Fix potential out-of-bounds shift ALSA: usb-audio: Fix control 'access overflow' errors from chmap xhci: Give USB2 ports time to enter U3 in bus suspend USB: sisusbvga: Make console support depend on BROKEN ALSA: pcm: oss: Fix potential out-of-bounds shift serial: 8250_omap: Avoid FIFO corruption caused by MDR1 access pinctrl: merrifield: Set default bias in case no particular value given pinctrl: baytrail: Avoid clearing debounce value when turning it off scsi: bnx2i: Requires MMU can: softing: softing_netdev_open(): fix error handling RDMA/cm: Fix an attempt to use non-valid pointer when cleaning timewait kernel/cpu: add arch override for clear_tasks_mm_cpumask() mm handling drm/tegra: sor: Disable clocks on error in tegra_sor_init() scsi: mpt3sas: Increase IOCInit request timeout to 30s dm table: Remove BUG_ON(in_interrupt()) soc/tegra: fuse: Fix index bug in get_process_id USB: serial: option: add interface-number sanity check to flag handling USB: gadget: f_acm: add support for SuperSpeed Plus USB: gadget: f_midi: setup SuperSpeed Plus descriptors USB: gadget: f_rndis: fix bitrate for SuperSpeed and above usb: gadget: f_fs: Re-use SS descriptors for SuperSpeedPlus usb: chipidea: ci_hdrc_imx: Pass DISABLE_DEVICE_STREAMING flag to imx6ul ARM: dts: exynos: fix roles of USB 3.0 ports on Odroid XU ARM: dts: exynos: fix USB 3.0 VBUS control and over-current pins on Exynos5410 ARM: dts: exynos: fix USB 3.0 pins supply being turned off on Odroid XU HID: i2c-hid: add Vero K147 to descriptor override serial_core: Check for port state when tty is in error state media: msi2500: assign SPI bus number dynamically md: fix a warning caused by a race between concurrent md_ioctl()s Bluetooth: Fix slab-out-of-bounds read in hci_le_direct_adv_report_evt() drm/gma500: fix double free of gma_connector RDMA/rxe: Compute PSN windows correctly ARM: p2v: fix handling of LPAE translation in BE mode crypto: talitos - Fix return type of current_desc_hdr() spi: img-spfi: fix reference leak in img_spfi_resume ASoC: pcm: DRAIN support reactivation arm64: dts: exynos: Correct psci compatible used on Exynos7 Bluetooth: Fix null pointer dereference in hci_event_packet() spi: spi-ti-qspi: fix reference leak in ti_qspi_setup spi: tegra20-slink: fix reference leak in slink ops of tegra20 spi: tegra20-sflash: fix reference leak in tegra_sflash_resume spi: tegra114: fix reference leak in tegra spi ops RDMa/mthca: Work around -Wenum-conversion warning MIPS: BCM47XX: fix kconfig dependency bug for BCM47XX_BCMA staging: greybus: codecs: Fix reference counter leak in error handling media: solo6x10: fix missing snd_card_free in error handling case drm/omap: dmm_tiler: fix return error code in omap_dmm_probe() Input: ads7846 - fix integer overflow on Rt calculation Input: ads7846 - fix unaligned access on 7845 powerpc/feature: Fix CPU_FTRS_ALWAYS by removing CPU_FTRS_GENERIC_32 crypto: omap-aes - Fix PM disable depth imbalance in omap_aes_probe soc: ti: knav_qmss: fix reference leak in knav_queue_probe soc: ti: Fix reference imbalance in knav_dma_probe drivers: soc: ti: knav_qmss_queue: Fix error return code in knav_queue_probe RDMA/cxgb4: Validate the number of CQEs memstick: fix a double-free bug in memstick_check ARM: dts: at91: sama5d4_xplained: add pincontrol for USB Host ARM: dts: at91: sama5d3_xplained: add pincontrol for USB Host orinoco: Move context allocation after processing the skb cw1200: fix missing destroy_workqueue() on error in cw1200_init_common media: siano: fix memory leak of debugfs members in smsdvb_hotplug mips: cdmm: fix use-after-free in mips_cdmm_bus_discover HSI: omap_ssi: Don't jump to free ID in ssi_add_controller() ARM: dts: at91: at91sam9rl: fix ADC triggers NFSv4.2: condition READDIR's mask for security label based on LSM state SUNRPC: xprt_load_transport() needs to support the netid "rdma6" lockd: don't use interval-based rebinding over TCP NFS: switch nfsiod to be an UNBOUND workqueue. vfio-pci: Use io_remap_pfn_range() for PCI IO memory media: saa7146: fix array overflow in vidioc_s_audio() clocksource/drivers/cadence_ttc: Fix memory leak in ttc_setup_clockevent() pinctrl: falcon: add missing put_device() call in pinctrl_falcon_probe() memstick: r592: Fix error return in r592_probe() ASoC: jz4740-i2s: add missed checks for clk_get() dm ioctl: fix error return code in target_message clocksource/drivers/arm_arch_timer: Correct fault programming of CNTKCTL_EL1.EVNTI cpufreq: highbank: Add missing MODULE_DEVICE_TABLE cpufreq: st: Add missing MODULE_DEVICE_TABLE cpufreq: loongson1: Add missing MODULE_ALIAS cpufreq: scpi: Add missing MODULE_ALIAS scsi: pm80xx: Fix error return in pm8001_pci_probe() seq_buf: Avoid type mismatch for seq_buf_init scsi: fnic: Fix error return code in fnic_probe() powerpc/pseries/hibernation: drop pseries_suspend_begin() from suspend ops usb: ehci-omap: Fix PM disable depth umbalance in ehci_hcd_omap_probe usb: oxu210hp-hcd: Fix memory leak in oxu_create speakup: fix uninitialized flush_lock nfsd: Fix message level for normal termination nfs_common: need lock during iterate through the list x86/kprobes: Restore BTF if the single-stepping is cancelled clk: tegra: Fix duplicated SE clock entry extcon: max77693: Fix modalias string ASoC: wm_adsp: remove "ctl" from list on error in wm_adsp_create_control() irqchip/alpine-msi: Fix freeing of interrupts on allocation error path um: chan_xterm: Fix fd leak nfc: s3fwrn5: Release the nfc firmware powerpc/ps3: use dma_mapping_error() checkpatch: fix unescaped left brace net: bcmgenet: Fix a resource leak in an error handling path in the probe functin net: allwinner: Fix some resources leak in the error handling path of the probe and in the remove function net: korina: fix return value watchdog: qcom: Avoid context switch in restart handler clk: ti: Fix memleak in ti_fapll_synth_setup perf record: Fix memory leak when using '--user-regs=?' to list registers qlcnic: Fix error code in probe clk: s2mps11: Fix a resource leak in error handling paths in the probe function cfg80211: initialize rekey_data Input: cros_ec_keyb - send 'scancodes' in addition to key events Input: goodix - add upside-down quirk for Teclast X98 Pro tablet media: gspca: Fix memory leak in probe media: sunxi-cir: ensure IR is handled when it is continuous media: netup_unidvb: Don't leak SPI master in probe error path Input: cyapa_gen6 - fix out-of-bounds stack access Revert "ACPI / resources: Use AE_CTRL_TERMINATE to terminate resources walks" ACPI: PNP: compare the string length in the matching_id() ALSA: pcm: oss: Fix a few more UBSAN fixes ALSA: usb-audio: Disable sample read check if firmware doesn't give back s390/dasd: prevent inconsistent LCU device data s390/dasd: fix list corruption of pavgroup group list s390/dasd: fix list corruption of lcu list staging: comedi: mf6x4: Fix AI end-of-conversion detection powerpc/perf: Exclude kernel samples while counting events in user space. USB: serial: mos7720: fix parallel-port state restore USB: serial: keyspan_pda: fix dropped unthrottle interrupts USB: serial: keyspan_pda: fix write deadlock USB: serial: keyspan_pda: fix stalled writes USB: serial: keyspan_pda: fix write-wakeup use-after-free USB: serial: keyspan_pda: fix tx-unthrottle use-after-free USB: serial: keyspan_pda: fix write unthrottling btrfs: quota: Set rescan progress to (u64)-1 if we hit last leaf btrfs: scrub: Don't use inode page cache in scrub_handle_errored_block() Btrfs: fix selftests failure due to uninitialized i_mode in test inodes btrfs: fix return value mixup in btrfs_get_extent ext4: fix a memory leak of ext4_free_data KVM: arm64: Introduce handling of AArch32 TTBCR2 traps powerpc/xmon: Change printk() to pr_cont() ceph: fix race in concurrent __ceph_remove_cap invocations jffs2: Fix GC exit abnormally jfs: Fix array index bounds check in dbAdjTree drm/dp_aux_dev: check aux_dev before use in drm_dp_aux_dev_get_by_minor() spi: spi-sh: Fix use-after-free on unbind spi: davinci: Fix use-after-free on unbind spi: pic32: Don't leak DMA channels in probe error path spi: rb4xx: Don't leak SPI master in probe error path spi: sc18is602: Don't leak SPI master in probe error path spi: st-ssc4: Fix unbalanced pm_runtime_disable() in probe error path soc: qcom: smp2p: Safely acquire spinlock without IRQs mtd: parser: cmdline: Fix parsing of part-names with colons iio: buffer: Fix demux update iio: adc: rockchip_saradc: fix missing clk_disable_unprepare() on error in rockchip_saradc_resume iio:pressure:mpl3115: Force alignment of buffer clk: mvebu: a3700: fix the XTAL MODE pin to MPP1_9 xen-blkback: set ring->xenblkd to NULL after kthread_stop() PCI: Fix pci_slot_release() NULL pointer dereference Linux 4.9.249 Signed-off-by: Greg Kroah-Hartman <gregkh@google.com> Change-Id: I4829a32e2ea6e76eefea716f35f42ee02b75c265
532 lines
12 KiB
C
532 lines
12 KiB
C
/*
|
|
* NCI based driver for Samsung S3FWRN5 NFC chip
|
|
*
|
|
* Copyright (C) 2015 Samsung Electrnoics
|
|
* Robert Baldyga <r.baldyga@samsung.com>
|
|
*
|
|
* This program is free software; you can redistribute it and/or modify it
|
|
* under the terms and conditions of the GNU General Public License,
|
|
* version 2 or later, as published by the Free Software Foundation.
|
|
*
|
|
* This program is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License
|
|
* along with this program; if not, see <http://www.gnu.org/licenses/>.
|
|
*/
|
|
|
|
#include <linux/completion.h>
|
|
#include <linux/firmware.h>
|
|
#include <crypto/hash.h>
|
|
#include <crypto/sha.h>
|
|
|
|
#include "s3fwrn5.h"
|
|
#include "firmware.h"
|
|
|
|
struct s3fwrn5_fw_version {
|
|
__u8 major;
|
|
__u8 build1;
|
|
__u8 build2;
|
|
__u8 target;
|
|
};
|
|
|
|
static int s3fwrn5_fw_send_msg(struct s3fwrn5_fw_info *fw_info,
|
|
struct sk_buff *msg, struct sk_buff **rsp)
|
|
{
|
|
struct s3fwrn5_info *info =
|
|
container_of(fw_info, struct s3fwrn5_info, fw_info);
|
|
long ret;
|
|
|
|
reinit_completion(&fw_info->completion);
|
|
|
|
ret = s3fwrn5_write(info, msg);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
ret = wait_for_completion_interruptible_timeout(
|
|
&fw_info->completion, msecs_to_jiffies(1000));
|
|
if (ret < 0)
|
|
return ret;
|
|
else if (ret == 0)
|
|
return -ENXIO;
|
|
|
|
if (!fw_info->rsp)
|
|
return -EINVAL;
|
|
|
|
*rsp = fw_info->rsp;
|
|
fw_info->rsp = NULL;
|
|
|
|
return 0;
|
|
}
|
|
|
|
static int s3fwrn5_fw_prep_msg(struct s3fwrn5_fw_info *fw_info,
|
|
struct sk_buff **msg, u8 type, u8 code, const void *data, u16 len)
|
|
{
|
|
struct s3fwrn5_fw_header hdr;
|
|
struct sk_buff *skb;
|
|
|
|
hdr.type = type | fw_info->parity;
|
|
fw_info->parity ^= 0x80;
|
|
hdr.code = code;
|
|
hdr.len = len;
|
|
|
|
skb = alloc_skb(S3FWRN5_FW_HDR_SIZE + len, GFP_KERNEL);
|
|
if (!skb)
|
|
return -ENOMEM;
|
|
|
|
memcpy(skb_put(skb, S3FWRN5_FW_HDR_SIZE), &hdr, S3FWRN5_FW_HDR_SIZE);
|
|
if (len)
|
|
memcpy(skb_put(skb, len), data, len);
|
|
|
|
*msg = skb;
|
|
|
|
return 0;
|
|
}
|
|
|
|
static int s3fwrn5_fw_get_bootinfo(struct s3fwrn5_fw_info *fw_info,
|
|
struct s3fwrn5_fw_cmd_get_bootinfo_rsp *bootinfo)
|
|
{
|
|
struct sk_buff *msg, *rsp = NULL;
|
|
struct s3fwrn5_fw_header *hdr;
|
|
int ret;
|
|
|
|
/* Send GET_BOOTINFO command */
|
|
|
|
ret = s3fwrn5_fw_prep_msg(fw_info, &msg, S3FWRN5_FW_MSG_CMD,
|
|
S3FWRN5_FW_CMD_GET_BOOTINFO, NULL, 0);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
ret = s3fwrn5_fw_send_msg(fw_info, msg, &rsp);
|
|
kfree_skb(msg);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
hdr = (struct s3fwrn5_fw_header *) rsp->data;
|
|
if (hdr->code != S3FWRN5_FW_RET_SUCCESS) {
|
|
ret = -EINVAL;
|
|
goto out;
|
|
}
|
|
|
|
memcpy(bootinfo, rsp->data + S3FWRN5_FW_HDR_SIZE, 10);
|
|
|
|
out:
|
|
kfree_skb(rsp);
|
|
return ret;
|
|
}
|
|
|
|
static int s3fwrn5_fw_enter_update_mode(struct s3fwrn5_fw_info *fw_info,
|
|
const void *hash_data, u16 hash_size,
|
|
const void *sig_data, u16 sig_size)
|
|
{
|
|
struct s3fwrn5_fw_cmd_enter_updatemode args;
|
|
struct sk_buff *msg, *rsp = NULL;
|
|
struct s3fwrn5_fw_header *hdr;
|
|
int ret;
|
|
|
|
/* Send ENTER_UPDATE_MODE command */
|
|
|
|
args.hashcode_size = hash_size;
|
|
args.signature_size = sig_size;
|
|
|
|
ret = s3fwrn5_fw_prep_msg(fw_info, &msg, S3FWRN5_FW_MSG_CMD,
|
|
S3FWRN5_FW_CMD_ENTER_UPDATE_MODE, &args, sizeof(args));
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
ret = s3fwrn5_fw_send_msg(fw_info, msg, &rsp);
|
|
kfree_skb(msg);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
hdr = (struct s3fwrn5_fw_header *) rsp->data;
|
|
if (hdr->code != S3FWRN5_FW_RET_SUCCESS) {
|
|
ret = -EPROTO;
|
|
goto out;
|
|
}
|
|
|
|
kfree_skb(rsp);
|
|
|
|
/* Send hashcode data */
|
|
|
|
ret = s3fwrn5_fw_prep_msg(fw_info, &msg, S3FWRN5_FW_MSG_DATA, 0,
|
|
hash_data, hash_size);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
ret = s3fwrn5_fw_send_msg(fw_info, msg, &rsp);
|
|
kfree_skb(msg);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
hdr = (struct s3fwrn5_fw_header *) rsp->data;
|
|
if (hdr->code != S3FWRN5_FW_RET_SUCCESS) {
|
|
ret = -EPROTO;
|
|
goto out;
|
|
}
|
|
|
|
kfree_skb(rsp);
|
|
|
|
/* Send signature data */
|
|
|
|
ret = s3fwrn5_fw_prep_msg(fw_info, &msg, S3FWRN5_FW_MSG_DATA, 0,
|
|
sig_data, sig_size);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
ret = s3fwrn5_fw_send_msg(fw_info, msg, &rsp);
|
|
kfree_skb(msg);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
hdr = (struct s3fwrn5_fw_header *) rsp->data;
|
|
if (hdr->code != S3FWRN5_FW_RET_SUCCESS)
|
|
ret = -EPROTO;
|
|
|
|
out:
|
|
kfree_skb(rsp);
|
|
return ret;
|
|
}
|
|
|
|
static int s3fwrn5_fw_update_sector(struct s3fwrn5_fw_info *fw_info,
|
|
u32 base_addr, const void *data)
|
|
{
|
|
struct s3fwrn5_fw_cmd_update_sector args;
|
|
struct sk_buff *msg, *rsp = NULL;
|
|
struct s3fwrn5_fw_header *hdr;
|
|
int ret, i;
|
|
|
|
/* Send UPDATE_SECTOR command */
|
|
|
|
args.base_address = base_addr;
|
|
|
|
ret = s3fwrn5_fw_prep_msg(fw_info, &msg, S3FWRN5_FW_MSG_CMD,
|
|
S3FWRN5_FW_CMD_UPDATE_SECTOR, &args, sizeof(args));
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
ret = s3fwrn5_fw_send_msg(fw_info, msg, &rsp);
|
|
kfree_skb(msg);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
hdr = (struct s3fwrn5_fw_header *) rsp->data;
|
|
if (hdr->code != S3FWRN5_FW_RET_SUCCESS) {
|
|
ret = -EPROTO;
|
|
goto err;
|
|
}
|
|
|
|
kfree_skb(rsp);
|
|
|
|
/* Send data split into 256-byte packets */
|
|
|
|
for (i = 0; i < 16; ++i) {
|
|
ret = s3fwrn5_fw_prep_msg(fw_info, &msg,
|
|
S3FWRN5_FW_MSG_DATA, 0, data+256*i, 256);
|
|
if (ret < 0)
|
|
break;
|
|
|
|
ret = s3fwrn5_fw_send_msg(fw_info, msg, &rsp);
|
|
kfree_skb(msg);
|
|
if (ret < 0)
|
|
break;
|
|
|
|
hdr = (struct s3fwrn5_fw_header *) rsp->data;
|
|
if (hdr->code != S3FWRN5_FW_RET_SUCCESS) {
|
|
ret = -EPROTO;
|
|
goto err;
|
|
}
|
|
|
|
kfree_skb(rsp);
|
|
}
|
|
|
|
return ret;
|
|
|
|
err:
|
|
kfree_skb(rsp);
|
|
return ret;
|
|
}
|
|
|
|
static int s3fwrn5_fw_complete_update_mode(struct s3fwrn5_fw_info *fw_info)
|
|
{
|
|
struct sk_buff *msg, *rsp = NULL;
|
|
struct s3fwrn5_fw_header *hdr;
|
|
int ret;
|
|
|
|
/* Send COMPLETE_UPDATE_MODE command */
|
|
|
|
ret = s3fwrn5_fw_prep_msg(fw_info, &msg, S3FWRN5_FW_MSG_CMD,
|
|
S3FWRN5_FW_CMD_COMPLETE_UPDATE_MODE, NULL, 0);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
ret = s3fwrn5_fw_send_msg(fw_info, msg, &rsp);
|
|
kfree_skb(msg);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
hdr = (struct s3fwrn5_fw_header *) rsp->data;
|
|
if (hdr->code != S3FWRN5_FW_RET_SUCCESS)
|
|
ret = -EPROTO;
|
|
|
|
kfree_skb(rsp);
|
|
|
|
return ret;
|
|
}
|
|
|
|
/*
|
|
* Firmware header stucture:
|
|
*
|
|
* 0x00 - 0x0B : Date and time string (w/o NUL termination)
|
|
* 0x10 - 0x13 : Firmware version
|
|
* 0x14 - 0x17 : Signature address
|
|
* 0x18 - 0x1B : Signature size
|
|
* 0x1C - 0x1F : Firmware image address
|
|
* 0x20 - 0x23 : Firmware sectors count
|
|
* 0x24 - 0x27 : Custom signature address
|
|
* 0x28 - 0x2B : Custom signature size
|
|
*/
|
|
|
|
#define S3FWRN5_FW_IMAGE_HEADER_SIZE 44
|
|
|
|
static int s3fwrn5_fw_request_firmware(struct s3fwrn5_fw_info *fw_info)
|
|
{
|
|
struct s3fwrn5_fw_image *fw = &fw_info->fw;
|
|
u32 sig_off;
|
|
u32 image_off;
|
|
u32 custom_sig_off;
|
|
int ret;
|
|
|
|
ret = request_firmware(&fw->fw, fw_info->fw_name,
|
|
&fw_info->ndev->nfc_dev->dev);
|
|
if (ret < 0)
|
|
return ret;
|
|
|
|
if (fw->fw->size < S3FWRN5_FW_IMAGE_HEADER_SIZE) {
|
|
release_firmware(fw->fw);
|
|
return -EINVAL;
|
|
}
|
|
|
|
memcpy(fw->date, fw->fw->data + 0x00, 12);
|
|
fw->date[12] = '\0';
|
|
|
|
memcpy(&fw->version, fw->fw->data + 0x10, 4);
|
|
|
|
memcpy(&sig_off, fw->fw->data + 0x14, 4);
|
|
fw->sig = fw->fw->data + sig_off;
|
|
memcpy(&fw->sig_size, fw->fw->data + 0x18, 4);
|
|
|
|
memcpy(&image_off, fw->fw->data + 0x1C, 4);
|
|
fw->image = fw->fw->data + image_off;
|
|
memcpy(&fw->image_sectors, fw->fw->data + 0x20, 4);
|
|
|
|
memcpy(&custom_sig_off, fw->fw->data + 0x24, 4);
|
|
fw->custom_sig = fw->fw->data + custom_sig_off;
|
|
memcpy(&fw->custom_sig_size, fw->fw->data + 0x28, 4);
|
|
|
|
return 0;
|
|
}
|
|
|
|
static void s3fwrn5_fw_release_firmware(struct s3fwrn5_fw_info *fw_info)
|
|
{
|
|
release_firmware(fw_info->fw.fw);
|
|
}
|
|
|
|
static int s3fwrn5_fw_get_base_addr(
|
|
struct s3fwrn5_fw_cmd_get_bootinfo_rsp *bootinfo, u32 *base_addr)
|
|
{
|
|
int i;
|
|
struct {
|
|
u8 version[4];
|
|
u32 base_addr;
|
|
} match[] = {
|
|
{{0x05, 0x00, 0x00, 0x00}, 0x00005000},
|
|
{{0x05, 0x00, 0x00, 0x01}, 0x00003000},
|
|
{{0x05, 0x00, 0x00, 0x02}, 0x00003000},
|
|
{{0x05, 0x00, 0x00, 0x03}, 0x00003000},
|
|
{{0x05, 0x00, 0x00, 0x05}, 0x00003000}
|
|
};
|
|
|
|
for (i = 0; i < ARRAY_SIZE(match); ++i)
|
|
if (bootinfo->hw_version[0] == match[i].version[0] &&
|
|
bootinfo->hw_version[1] == match[i].version[1] &&
|
|
bootinfo->hw_version[3] == match[i].version[3]) {
|
|
*base_addr = match[i].base_addr;
|
|
return 0;
|
|
}
|
|
|
|
return -EINVAL;
|
|
}
|
|
|
|
static inline bool
|
|
s3fwrn5_fw_is_custom(struct s3fwrn5_fw_cmd_get_bootinfo_rsp *bootinfo)
|
|
{
|
|
return !!bootinfo->hw_version[2];
|
|
}
|
|
|
|
int s3fwrn5_fw_setup(struct s3fwrn5_fw_info *fw_info)
|
|
{
|
|
struct s3fwrn5_fw_cmd_get_bootinfo_rsp bootinfo;
|
|
int ret;
|
|
|
|
/* Get firmware data */
|
|
|
|
ret = s3fwrn5_fw_request_firmware(fw_info);
|
|
if (ret < 0) {
|
|
dev_err(&fw_info->ndev->nfc_dev->dev,
|
|
"Failed to get fw file, ret=%02x\n", ret);
|
|
return ret;
|
|
}
|
|
|
|
/* Get bootloader info */
|
|
|
|
ret = s3fwrn5_fw_get_bootinfo(fw_info, &bootinfo);
|
|
if (ret < 0) {
|
|
dev_err(&fw_info->ndev->nfc_dev->dev,
|
|
"Failed to get bootinfo, ret=%02x\n", ret);
|
|
goto err;
|
|
}
|
|
|
|
/* Match hardware version to obtain firmware base address */
|
|
|
|
ret = s3fwrn5_fw_get_base_addr(&bootinfo, &fw_info->base_addr);
|
|
if (ret < 0) {
|
|
dev_err(&fw_info->ndev->nfc_dev->dev,
|
|
"Unknown hardware version\n");
|
|
goto err;
|
|
}
|
|
|
|
fw_info->sector_size = bootinfo.sector_size;
|
|
|
|
fw_info->sig_size = s3fwrn5_fw_is_custom(&bootinfo) ?
|
|
fw_info->fw.custom_sig_size : fw_info->fw.sig_size;
|
|
fw_info->sig = s3fwrn5_fw_is_custom(&bootinfo) ?
|
|
fw_info->fw.custom_sig : fw_info->fw.sig;
|
|
|
|
return 0;
|
|
|
|
err:
|
|
s3fwrn5_fw_release_firmware(fw_info);
|
|
return ret;
|
|
}
|
|
|
|
bool s3fwrn5_fw_check_version(struct s3fwrn5_fw_info *fw_info, u32 version)
|
|
{
|
|
struct s3fwrn5_fw_version *new = (void *) &fw_info->fw.version;
|
|
struct s3fwrn5_fw_version *old = (void *) &version;
|
|
|
|
if (new->major > old->major)
|
|
return true;
|
|
if (new->build1 > old->build1)
|
|
return true;
|
|
if (new->build2 > old->build2)
|
|
return true;
|
|
|
|
return false;
|
|
}
|
|
|
|
int s3fwrn5_fw_download(struct s3fwrn5_fw_info *fw_info)
|
|
{
|
|
struct s3fwrn5_fw_image *fw = &fw_info->fw;
|
|
u8 hash_data[SHA1_DIGEST_SIZE];
|
|
struct crypto_shash *tfm;
|
|
u32 image_size, off;
|
|
int ret;
|
|
|
|
image_size = fw_info->sector_size * fw->image_sectors;
|
|
|
|
/* Compute SHA of firmware data */
|
|
|
|
tfm = crypto_alloc_shash("sha1", 0, 0);
|
|
if (IS_ERR(tfm)) {
|
|
ret = PTR_ERR(tfm);
|
|
dev_err(&fw_info->ndev->nfc_dev->dev,
|
|
"Cannot allocate shash (code=%d)\n", ret);
|
|
goto out;
|
|
}
|
|
|
|
{
|
|
SHASH_DESC_ON_STACK(desc, tfm);
|
|
|
|
desc->tfm = tfm;
|
|
desc->flags = CRYPTO_TFM_REQ_MAY_SLEEP;
|
|
|
|
ret = crypto_shash_digest(desc, fw->image, image_size,
|
|
hash_data);
|
|
shash_desc_zero(desc);
|
|
}
|
|
|
|
crypto_free_shash(tfm);
|
|
if (ret) {
|
|
dev_err(&fw_info->ndev->nfc_dev->dev,
|
|
"Cannot compute hash (code=%d)\n", ret);
|
|
goto out;
|
|
}
|
|
|
|
/* Firmware update process */
|
|
|
|
dev_info(&fw_info->ndev->nfc_dev->dev,
|
|
"Firmware update: %s\n", fw_info->fw_name);
|
|
|
|
ret = s3fwrn5_fw_enter_update_mode(fw_info, hash_data,
|
|
SHA1_DIGEST_SIZE, fw_info->sig, fw_info->sig_size);
|
|
if (ret < 0) {
|
|
dev_err(&fw_info->ndev->nfc_dev->dev,
|
|
"Unable to enter update mode\n");
|
|
goto out;
|
|
}
|
|
|
|
for (off = 0; off < image_size; off += fw_info->sector_size) {
|
|
ret = s3fwrn5_fw_update_sector(fw_info,
|
|
fw_info->base_addr + off, fw->image + off);
|
|
if (ret < 0) {
|
|
dev_err(&fw_info->ndev->nfc_dev->dev,
|
|
"Firmware update error (code=%d)\n", ret);
|
|
goto out;
|
|
}
|
|
}
|
|
|
|
ret = s3fwrn5_fw_complete_update_mode(fw_info);
|
|
if (ret < 0) {
|
|
dev_err(&fw_info->ndev->nfc_dev->dev,
|
|
"Unable to complete update mode\n");
|
|
goto out;
|
|
}
|
|
|
|
dev_info(&fw_info->ndev->nfc_dev->dev,
|
|
"Firmware update: success\n");
|
|
|
|
out:
|
|
return ret;
|
|
}
|
|
|
|
void s3fwrn5_fw_init(struct s3fwrn5_fw_info *fw_info, const char *fw_name)
|
|
{
|
|
fw_info->parity = 0x00;
|
|
fw_info->rsp = NULL;
|
|
fw_info->fw.fw = NULL;
|
|
strcpy(fw_info->fw_name, fw_name);
|
|
init_completion(&fw_info->completion);
|
|
}
|
|
|
|
void s3fwrn5_fw_cleanup(struct s3fwrn5_fw_info *fw_info)
|
|
{
|
|
s3fwrn5_fw_release_firmware(fw_info);
|
|
}
|
|
|
|
int s3fwrn5_fw_recv_frame(struct nci_dev *ndev, struct sk_buff *skb)
|
|
{
|
|
struct s3fwrn5_info *info = nci_get_drvdata(ndev);
|
|
struct s3fwrn5_fw_info *fw_info = &info->fw_info;
|
|
|
|
BUG_ON(fw_info->rsp);
|
|
|
|
fw_info->rsp = skb;
|
|
|
|
complete(&fw_info->completion);
|
|
|
|
return 0;
|
|
}
|