xref: /OK3568_Linux_fs/u-boot/drivers/usb/gadget/f_rockusb.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1 /*
2  * Copyright 2017 Rockchip Electronics Co., Ltd
3  * Frank Wang <frank.wang@rock-chips.com>
4  *
5  * SPDX-License-Identifier:	GPL-2.0+
6  */
7 
8 #include <asm/io.h>
9 #include <android_avb/avb_ops_user.h>
10 #include <android_avb/rk_avb_ops_user.h>
11 #include <asm/arch/boot_mode.h>
12 #include <asm/arch/chip_info.h>
13 #include <asm/arch/rk_atags.h>
14 #include <write_keybox.h>
15 #include <linux/mtd/mtd.h>
16 #include <optee_include/OpteeClientInterface.h>
17 
18 #ifdef CONFIG_ROCKCHIP_VENDOR_PARTITION
19 #include <asm/arch/vendor.h>
20 #endif
21 #include <rockusb.h>
22 
23 #define ROCKUSB_INTERFACE_CLASS	0xff
24 #define ROCKUSB_INTERFACE_SUB_CLASS	0x06
25 #define ROCKUSB_INTERFACE_PROTOCOL	0x05
26 
27 #define ROCKCHIP_FLASH_BLOCK_SIZE	1024
28 #define ROCKCHIP_FLASH_PAGE_SIZE	4
29 
30 static struct usb_interface_descriptor rkusb_intf_desc = {
31 	.bLength		= USB_DT_INTERFACE_SIZE,
32 	.bDescriptorType	= USB_DT_INTERFACE,
33 	.bInterfaceNumber	= 0x00,
34 	.bAlternateSetting	= 0x00,
35 	.bNumEndpoints		= 0x02,
36 	.bInterfaceClass	= ROCKUSB_INTERFACE_CLASS,
37 	.bInterfaceSubClass	= ROCKUSB_INTERFACE_SUB_CLASS,
38 	.bInterfaceProtocol	= ROCKUSB_INTERFACE_PROTOCOL,
39 };
40 
41 static struct usb_descriptor_header *rkusb_fs_function[] = {
42 	(struct usb_descriptor_header *)&rkusb_intf_desc,
43 	(struct usb_descriptor_header *)&fsg_fs_bulk_in_desc,
44 	(struct usb_descriptor_header *)&fsg_fs_bulk_out_desc,
45 	NULL,
46 };
47 
48 static struct usb_descriptor_header *rkusb_hs_function[] = {
49 	(struct usb_descriptor_header *)&rkusb_intf_desc,
50 	(struct usb_descriptor_header *)&fsg_hs_bulk_in_desc,
51 	(struct usb_descriptor_header *)&fsg_hs_bulk_out_desc,
52 	NULL,
53 };
54 
55 static struct usb_descriptor_header *rkusb_ss_function[] = {
56 	(struct usb_descriptor_header *)&rkusb_intf_desc,
57 	(struct usb_descriptor_header *)&fsg_ss_bulk_in_desc,
58 	(struct usb_descriptor_header *)&fsg_ss_bulk_in_comp_desc,
59 	(struct usb_descriptor_header *)&fsg_ss_bulk_out_desc,
60 	(struct usb_descriptor_header *)&fsg_ss_bulk_out_comp_desc,
61 	NULL,
62 };
63 
64 struct rk_flash_info {
65 	u32	flash_size;
66 	u16	block_size;
67 	u8	page_size;
68 	u8	ecc_bits;
69 	u8	access_time;
70 	u8	manufacturer;
71 	u8	flash_mask;
72 } __packed;
73 
74 static int rkusb_rst_code; /* The subcode in reset command (0xFF) */
75 
g_dnl_bind_fixup(struct usb_device_descriptor * dev,const char * name)76 int g_dnl_bind_fixup(struct usb_device_descriptor *dev, const char *name)
77 {
78 	if (IS_RKUSB_UMS_DNL(name)) {
79 		/* Fix to Rockchip's VID and PID */
80 		dev->idVendor  = __constant_cpu_to_le16(0x2207);
81 		dev->idProduct = __constant_cpu_to_le16(CONFIG_ROCKUSB_G_DNL_PID);
82 
83 		/* Enumerate as a loader device */
84 #if defined(CONFIG_SUPPORT_USBPLUG)
85 		dev->bcdUSB = cpu_to_le16(0x0200);
86 #else
87 		dev->bcdUSB = cpu_to_le16(0x0201);
88 #endif
89 	} else if (!strncmp(name, "usb_dnl_fastboot", 16)) {
90 		/* Fix to Google's VID and PID */
91 		dev->idVendor  = __constant_cpu_to_le16(0x18d1);
92 		dev->idProduct = __constant_cpu_to_le16(0xd00d);
93 	} else if (!strncmp(name, "usb_dnl_dfu", 11)) {
94 		/* Fix to Rockchip's VID and PID for DFU */
95 		dev->idVendor  = cpu_to_le16(0x2207);
96 		dev->idProduct = cpu_to_le16(0x0107);
97 	} else if (!strncmp(name, "usb_dnl_ums", 11)) {
98 		dev->idVendor  = cpu_to_le16(0x2207);
99 		dev->idProduct = cpu_to_le16(0x0010);
100 	}
101 
102 	return 0;
103 }
104 
105 __maybe_unused
dump_cbw(struct fsg_bulk_cb_wrap * cbw)106 static inline void dump_cbw(struct fsg_bulk_cb_wrap *cbw)
107 {
108 	assert(!cbw);
109 
110 	debug("%s:\n", __func__);
111 	debug("Signature %x\n", cbw->Signature);
112 	debug("Tag %x\n", cbw->Tag);
113 	debug("DataTransferLength %x\n", cbw->DataTransferLength);
114 	debug("Flags %x\n", cbw->Flags);
115 	debug("LUN %x\n", cbw->Lun);
116 	debug("Length %x\n", cbw->Length);
117 	debug("OptionCode %x\n", cbw->CDB[0]);
118 	debug("SubCode %x\n", cbw->CDB[1]);
119 	debug("SectorAddr %x\n", get_unaligned_be32(&cbw->CDB[2]));
120 	debug("BlkSectors %x\n\n", get_unaligned_be16(&cbw->CDB[7]));
121 }
122 
rkusb_check_lun(struct fsg_common * common)123 static int rkusb_check_lun(struct fsg_common *common)
124 {
125 	struct fsg_lun *curlun;
126 
127 	/* Check the LUN */
128 	if (common->lun >= 0 && common->lun < common->nluns) {
129 		curlun = &common->luns[common->lun];
130 		if (common->cmnd[0] != SC_REQUEST_SENSE) {
131 			curlun->sense_data = SS_NO_SENSE;
132 			curlun->info_valid = 0;
133 		}
134 	} else {
135 		curlun = NULL;
136 		common->bad_lun_okay = 0;
137 
138 		/*
139 		 * INQUIRY and REQUEST SENSE commands are explicitly allowed
140 		 * to use unsupported LUNs; all others may not.
141 		 */
142 		if (common->cmnd[0] != SC_INQUIRY &&
143 		    common->cmnd[0] != SC_REQUEST_SENSE) {
144 			debug("unsupported LUN %d\n", common->lun);
145 			return -EINVAL;
146 		}
147 	}
148 
149 	return 0;
150 }
151 
__do_reset(struct usb_ep * ep,struct usb_request * req)152 static void __do_reset(struct usb_ep *ep, struct usb_request *req)
153 {
154 	u32 boot_flag = BOOT_NORMAL;
155 
156 	if (rkusb_rst_code == 0x03)
157 		boot_flag = BOOT_BROM_DOWNLOAD;
158 
159 	rkusb_rst_code = 0; /* restore to default */
160 	writel(boot_flag, (void *)CONFIG_ROCKCHIP_BOOT_MODE_REG);
161 
162 	do_reset(NULL, 0, 0, NULL);
163 }
164 
rkusb_do_reset(struct fsg_common * common,struct fsg_buffhd * bh)165 static int rkusb_do_reset(struct fsg_common *common,
166 			  struct fsg_buffhd *bh)
167 {
168 	common->data_size_from_cmnd = common->cmnd[4];
169 	common->residue = 0;
170 	bh->inreq->complete = __do_reset;
171 	bh->state = BUF_STATE_EMPTY;
172 
173 	rkusb_rst_code = !common->cmnd[1] ? 0xff : common->cmnd[1];
174 	return 0;
175 }
176 
rkusb_do_test_unit_ready(struct fsg_common * common,struct fsg_buffhd * bh)177 static int rkusb_do_test_unit_ready(struct fsg_common *common,
178 				    struct fsg_buffhd *bh)
179 {
180 	struct blk_desc *desc = &ums[common->lun].block_dev;
181 
182 	if ((desc->if_type == IF_TYPE_MTD && desc->devnum == BLK_MTD_SPI_NOR) ||
183 	    desc->if_type == IF_TYPE_SPINOR)
184 		common->residue = 0x03 << 24; /* 128KB Max block xfer for SPI Nor */
185 	else
186 		common->residue = 0x06 << 24; /* Max block xfer support from host */
187 
188 	common->data_dir = DATA_DIR_NONE;
189 	bh->state = BUF_STATE_EMPTY;
190 
191 	return 0;
192 }
193 
rkusb_do_read_flash_id(struct fsg_common * common,struct fsg_buffhd * bh)194 static int rkusb_do_read_flash_id(struct fsg_common *common,
195 				  struct fsg_buffhd *bh)
196 {
197 	u8 *buf = (u8 *)bh->buf;
198 	u32 len = 5;
199 	enum if_type type = ums[common->lun].block_dev.if_type;
200 	u32 devnum = ums[common->lun].block_dev.devnum;
201 	const char *str;
202 
203 	switch (type) {
204 	case IF_TYPE_MMC:
205 		str = "EMMC ";
206 		break;
207 	case IF_TYPE_RKNAND:
208 		str = "NAND ";
209 		break;
210 	case IF_TYPE_MTD:
211 		if (devnum == BLK_MTD_SPI_NAND)
212 			str ="SNAND";
213 		else if (devnum == BLK_MTD_NAND)
214 			str = "NAND ";
215 		else
216 			str = "NOR  ";
217 		break;
218 	default:
219 		str = "UNKN "; /* unknown */
220 		break;
221 	}
222 
223 	memcpy((void *)&buf[0], str, len);
224 
225 	/* Set data xfer size */
226 	common->residue = common->data_size_from_cmnd = len;
227 	common->data_size = len;
228 
229 	return len;
230 }
231 
rkusb_do_test_bad_block(struct fsg_common * common,struct fsg_buffhd * bh)232 static int rkusb_do_test_bad_block(struct fsg_common *common,
233 				   struct fsg_buffhd *bh)
234 {
235 	u8 *buf = (u8 *)bh->buf;
236 	u32 len = 64;
237 
238 	memset((void *)&buf[0], 0, len);
239 
240 	/* Set data xfer size */
241 	common->residue = common->data_size_from_cmnd = len;
242 	common->data_size = len;
243 
244 	return len;
245 }
246 
rkusb_do_read_flash_info(struct fsg_common * common,struct fsg_buffhd * bh)247 static int rkusb_do_read_flash_info(struct fsg_common *common,
248 				    struct fsg_buffhd *bh)
249 {
250 	struct blk_desc *desc = &ums[common->lun].block_dev;
251 	u8 *buf = (u8 *)bh->buf;
252 	u32 len = sizeof(struct rk_flash_info);
253 	struct rk_flash_info finfo = {
254 		.block_size = ROCKCHIP_FLASH_BLOCK_SIZE,
255 		.ecc_bits = 0,
256 		.page_size = ROCKCHIP_FLASH_PAGE_SIZE,
257 		.access_time = 40,
258 		.manufacturer = 0,
259 		.flash_mask = 0
260 	};
261 
262 	finfo.flash_size = (u32)desc->lba;
263 
264 	if (desc->if_type == IF_TYPE_MTD &&
265 	    (desc->devnum == BLK_MTD_NAND ||
266 	    desc->devnum == BLK_MTD_SPI_NAND)) {
267 		struct mtd_info *mtd = (struct mtd_info *)desc->bdev->priv;
268 
269 		if (mtd) {
270 			finfo.block_size = mtd->erasesize >> 9;
271 			finfo.page_size = mtd->writesize >> 9;
272 		}
273 	}
274 
275 	if (desc->if_type == IF_TYPE_MTD && desc->devnum == BLK_MTD_SPI_NOR) {
276 		/* RV1126/RK3308 mtd spinor keep the former upgrade mode */
277 #if !defined(CONFIG_ROCKCHIP_RV1126) && !defined(CONFIG_ROCKCHIP_RK3308)
278 		finfo.block_size = 0x80; /* Aligned to 64KB */
279 #else
280 		finfo.block_size = ROCKCHIP_FLASH_BLOCK_SIZE;
281 #endif
282 	}
283 
284 	debug("Flash info: block_size= %x page_size= %x\n", finfo.block_size,
285 	      finfo.page_size);
286 
287 	if (finfo.flash_size)
288 		finfo.flash_mask = 1;
289 
290 	memset((void *)&buf[0], 0, len);
291 	memcpy((void *)&buf[0], (void *)&finfo, len);
292 
293 	/* Set data xfer size */
294 	common->residue = common->data_size_from_cmnd = len;
295         /* legacy upgrade_tool does not set correct transfer size */
296 	common->data_size = len;
297 
298 	return len;
299 }
300 
rkusb_do_get_chip_info(struct fsg_common * common,struct fsg_buffhd * bh)301 static int rkusb_do_get_chip_info(struct fsg_common *common,
302 				  struct fsg_buffhd *bh)
303 {
304 	u8 *buf = (u8 *)bh->buf;
305 	u32 len = common->data_size;
306 	u32 chip_info[4];
307 
308 	memset((void *)chip_info, 0, sizeof(chip_info));
309 	rockchip_rockusb_get_chip_info(chip_info);
310 
311 	memset((void *)&buf[0], 0, len);
312 	memcpy((void *)&buf[0], (void *)chip_info, len);
313 
314 	/* Set data xfer size */
315 	common->residue = common->data_size_from_cmnd = len;
316 
317 	return len;
318 }
319 
rkusb_do_lba_erase(struct fsg_common * common,struct fsg_buffhd * bh)320 static int rkusb_do_lba_erase(struct fsg_common *common,
321 			      struct fsg_buffhd *bh)
322 {
323 	struct fsg_lun *curlun = &common->luns[common->lun];
324 	u32 lba, amount;
325 	loff_t file_offset;
326 	int rc;
327 
328 	lba = get_unaligned_be32(&common->cmnd[2]);
329 	if (lba >= curlun->num_sectors) {
330 		curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE;
331 		rc = -EINVAL;
332 		goto out;
333 	}
334 
335 	file_offset = ((loff_t) lba) << 9;
336 	amount = get_unaligned_be16(&common->cmnd[7]) << 9;
337 	if (unlikely(amount == 0)) {
338 		curlun->sense_data = SS_INVALID_FIELD_IN_CDB;
339 		rc = -EIO;
340 		goto out;
341 	}
342 
343 	/* Perform the erase */
344 	rc = ums[common->lun].erase_sector(&ums[common->lun],
345 			       file_offset / SECTOR_SIZE,
346 			       amount / SECTOR_SIZE);
347 	if (!rc) {
348 		curlun->sense_data = SS_MEDIUM_NOT_PRESENT;
349 		rc = -EIO;
350 	}
351 
352 out:
353 	common->data_dir = DATA_DIR_NONE;
354 	bh->state = BUF_STATE_EMPTY;
355 
356 	return rc;
357 }
358 
rkusb_do_erase_force(struct fsg_common * common,struct fsg_buffhd * bh)359 static int rkusb_do_erase_force(struct fsg_common *common,
360 				struct fsg_buffhd *bh)
361 {
362 	struct blk_desc *desc = &ums[common->lun].block_dev;
363 	struct fsg_lun *curlun = &common->luns[common->lun];
364 	u16 block_size = ROCKCHIP_FLASH_BLOCK_SIZE;
365 	u32 lba, amount;
366 	loff_t file_offset;
367 	int rc;
368 
369 	lba = get_unaligned_be32(&common->cmnd[2]);
370 	if (lba >= curlun->num_sectors) {
371 		curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE;
372 		rc = -EINVAL;
373 		goto out;
374 	}
375 
376 	if (desc->if_type == IF_TYPE_MTD &&
377 	    (desc->devnum == BLK_MTD_NAND ||
378 	    desc->devnum == BLK_MTD_SPI_NAND)) {
379 		struct mtd_info *mtd = (struct mtd_info *)desc->bdev->priv;
380 
381 		if (mtd)
382 			block_size = mtd->erasesize >> 9;
383 	}
384 
385 	file_offset = ((loff_t)lba) * block_size;
386 	amount = get_unaligned_be16(&common->cmnd[7]) * block_size;
387 
388 	debug("%s lba= %x, nsec= %x\n", __func__, lba,
389 	      (u32)get_unaligned_be16(&common->cmnd[7]));
390 
391 	if (unlikely(amount == 0)) {
392 		curlun->sense_data = SS_INVALID_FIELD_IN_CDB;
393 		rc = -EIO;
394 		goto out;
395 	}
396 
397 	/* Perform the erase */
398 	rc = ums[common->lun].erase_sector(&ums[common->lun],
399 					   file_offset,
400 					   amount);
401 	if (!rc) {
402 		curlun->sense_data = SS_MEDIUM_NOT_PRESENT;
403 		rc = -EIO;
404 	}
405 
406 out:
407 	common->data_dir = DATA_DIR_NONE;
408 	bh->state = BUF_STATE_EMPTY;
409 
410 	return rc;
411 }
412 
413 #ifdef CONFIG_ROCKCHIP_VENDOR_PARTITION
rkusb_do_vs_write(struct fsg_common * common)414 static int rkusb_do_vs_write(struct fsg_common *common)
415 {
416 	struct fsg_lun		*curlun = &common->luns[common->lun];
417 	u16			type = get_unaligned_be16(&common->cmnd[4]);
418 	struct vendor_item	*vhead;
419 	struct fsg_buffhd	*bh;
420 	void			*data;
421 	int			rc;
422 
423 	if (common->data_size >= (u32)65536) {
424 		/* _MUST_ small than 64K */
425 		curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE;
426 		return -EINVAL;
427 	}
428 
429 	common->residue         = common->data_size;
430 	common->usb_amount_left = common->data_size;
431 
432 	/* Carry out the file writes */
433 	if (unlikely(common->data_size == 0))
434 		return -EIO; /* No data to write */
435 
436 	for (;;) {
437 		if (common->usb_amount_left > 0) {
438 			/* Wait for the next buffer to become available */
439 			bh = common->next_buffhd_to_fill;
440 			if (bh->state != BUF_STATE_EMPTY)
441 				goto wait;
442 
443 			/* Request the next buffer */
444 			common->usb_amount_left      -= common->data_size;
445 			bh->outreq->length	     = common->data_size;
446 			bh->bulk_out_intended_length = common->data_size;
447 			bh->outreq->short_not_ok     = 1;
448 
449 			START_TRANSFER_OR(common, bulk_out, bh->outreq,
450 					  &bh->outreq_busy, &bh->state)
451 				/*
452 				 * Don't know what to do if
453 				 * common->fsg is NULL
454 				 */
455 				return -EIO;
456 			common->next_buffhd_to_fill = bh->next;
457 		} else {
458 			/* Then, wait for the data to become available */
459 			bh = common->next_buffhd_to_drain;
460 			if (bh->state != BUF_STATE_FULL)
461 				goto wait;
462 
463 			common->next_buffhd_to_drain = bh->next;
464 			bh->state = BUF_STATE_EMPTY;
465 
466 			/* Did something go wrong with the transfer? */
467 			if (bh->outreq->status != 0) {
468 				curlun->sense_data = SS_COMMUNICATION_FAILURE;
469 				curlun->info_valid = 1;
470 				break;
471 			}
472 
473 			/* Perform the write */
474 			vhead = (struct vendor_item *)bh->buf;
475 			data  = bh->buf + sizeof(struct vendor_item);
476 
477 			if (!type) {
478 				if (vhead->id == HDCP_14_HDMI_ID ||
479 				    vhead->id == HDCP_14_HDMIRX_ID ||
480 				    vhead->id == HDCP_14_DP_ID) {
481 					rc = vendor_handle_hdcp(vhead);
482 					if (rc < 0) {
483 						curlun->sense_data = SS_WRITE_ERROR;
484 						return -EIO;
485 					}
486 				}
487 
488 				/* Vendor storage */
489 				rc = vendor_storage_write(vhead->id,
490 							  (char __user *)data,
491 							  vhead->size);
492 				if (rc < 0) {
493 					curlun->sense_data = SS_WRITE_ERROR;
494 					return -EIO;
495 				}
496 			} else if (type == 1) {
497 				/* RPMB */
498 				rc =
499 				write_keybox_to_secure_storage((u8 *)data,
500 							       vhead->size);
501 				if (rc < 0) {
502 					curlun->sense_data = SS_WRITE_ERROR;
503 					return -EIO;
504 				}
505 			} else if (type == 2) {
506 				/* security storage */
507 #ifdef CONFIG_RK_AVB_LIBAVB_USER
508 				debug("%s call rk_avb_write_perm_attr %d, %d\n",
509 				      __func__, vhead->id, vhead->size);
510 				rc = rk_avb_write_perm_attr(vhead->id,
511 							    (char __user *)data,
512 							    vhead->size);
513 				if (rc < 0) {
514 					curlun->sense_data = SS_WRITE_ERROR;
515 					return -EIO;
516 				}
517 #else
518 				printf("Please enable CONFIG_RK_AVB_LIBAVB_USER\n");
519 #endif
520 			} else if (type == 3) {
521 				/* efuse or otp*/
522 #ifdef CONFIG_OPTEE_CLIENT
523 				if (memcmp(data, "TAEK", 4) == 0) {
524 					if (vhead->size - 8 != 32) {
525 						printf("check ta encryption key size fail!\n");
526 						curlun->sense_data = SS_WRITE_ERROR;
527 						return -EIO;
528 					}
529 					if (trusty_write_ta_encryption_key((uint32_t *)(data + 8), 8) != 0) {
530 						printf("trusty_write_ta_encryption_key error!");
531 						curlun->sense_data = SS_WRITE_ERROR;
532 						return -EIO;
533 					}
534 				} else if (memcmp(data, "EHUK", 4) == 0) {
535 					if (vhead->size - 8 != 32) {
536 						printf("check oem huk size fail!\n");
537 						curlun->sense_data = SS_WRITE_ERROR;
538 						return -EIO;
539 					}
540 					if (trusty_write_oem_huk((uint32_t *)(data + 8), 8) != 0) {
541 						printf("trusty_write_oem_huk error!");
542 						curlun->sense_data = SS_WRITE_ERROR;
543 						return -EIO;
544 					}
545 				} else {
546 					printf("Unknown tag\n");
547 					curlun->sense_data = SS_WRITE_ERROR;
548 					return -EIO;
549 				}
550 #else
551 				printf("Please enable CONFIG_OPTEE_CLIENT\n");
552 #endif
553 			} else {
554 				return -EINVAL;
555 			}
556 
557 			common->residue -= common->data_size;
558 
559 			/* Did the host decide to stop early? */
560 			if (bh->outreq->actual != bh->outreq->length)
561 				common->short_packet_received = 1;
562 			break; /* Command done */
563 		}
564 wait:
565 		/* Wait for something to happen */
566 		rc = sleep_thread(common);
567 		if (rc)
568 			return rc;
569 	}
570 
571 	return -EIO; /* No default reply */
572 }
573 
rkusb_do_vs_read(struct fsg_common * common)574 static int rkusb_do_vs_read(struct fsg_common *common)
575 {
576 	struct fsg_lun		*curlun = &common->luns[common->lun];
577 	u16			type = get_unaligned_be16(&common->cmnd[4]);
578 	struct vendor_item	*vhead;
579 	struct fsg_buffhd	*bh;
580 	void			*data;
581 	int			rc;
582 
583 	if (common->data_size >= (u32)65536) {
584 		/* _MUST_ small than 64K */
585 		curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE;
586 		return -EINVAL;
587 	}
588 
589 	common->residue         = common->data_size;
590 	common->usb_amount_left = common->data_size;
591 
592 	/* Carry out the file reads */
593 	if (unlikely(common->data_size == 0))
594 		return -EIO; /* No default reply */
595 
596 	for (;;) {
597 		/* Wait for the next buffer to become available */
598 		bh = common->next_buffhd_to_fill;
599 		while (bh->state != BUF_STATE_EMPTY) {
600 			rc = sleep_thread(common);
601 			if (rc)
602 				return rc;
603 		}
604 
605 		memset(bh->buf, 0, FSG_BUFLEN);
606 		vhead = (struct vendor_item *)bh->buf;
607 		data  = bh->buf + sizeof(struct vendor_item);
608 		vhead->id = get_unaligned_be16(&common->cmnd[2]);
609 
610 		if (!type) {
611 			/* Vendor storage */
612 			rc = vendor_storage_read(vhead->id,
613 						 (char __user *)data,
614 						 common->data_size);
615 			if (!rc) {
616 				curlun->sense_data = SS_UNRECOVERED_READ_ERROR;
617 				return -EIO;
618 			}
619 			vhead->size = rc;
620 		} else if (type == 1) {
621 			/* RPMB */
622 			rc =
623 			read_raw_data_from_secure_storage((u8 *)data,
624 							  common->data_size);
625 			if (!rc) {
626 				curlun->sense_data = SS_UNRECOVERED_READ_ERROR;
627 				return -EIO;
628 			}
629 			vhead->size = rc;
630 		} else if (type == 2) {
631 			/* security storage */
632 #ifdef CONFIG_RK_AVB_LIBAVB_USER
633 			rc = rk_avb_read_perm_attr(vhead->id,
634 						   (char __user *)data,
635 						   vhead->size);
636 			if (rc < 0)
637 				return -EIO;
638 			vhead->size = rc;
639 #else
640 			printf("Please enable CONFIG_RK_AVB_LIBAVB_USER!\n");
641 #endif
642 		} else {
643 			return -EINVAL;
644 		}
645 
646 		common->residue   -= common->data_size;
647 		bh->inreq->length = common->data_size;
648 		bh->state         = BUF_STATE_FULL;
649 
650 		break; /* No more left to read */
651 	}
652 
653 	return -EIO; /* No default reply */
654 }
655 #endif
656 
rkusb_do_get_storage_info(struct fsg_common * common,struct fsg_buffhd * bh)657 static int rkusb_do_get_storage_info(struct fsg_common *common,
658 				     struct fsg_buffhd *bh)
659 {
660 	enum if_type type = ums[common->lun].block_dev.if_type;
661 	int devnum = ums[common->lun].block_dev.devnum;
662 	u32 media = BOOT_TYPE_UNKNOWN;
663 	u32 len = common->data_size;
664 	u8 *buf = (u8 *)bh->buf;
665 
666 	if (len > 4)
667 		len = 4;
668 
669 	switch (type) {
670 	case IF_TYPE_MMC:
671 		media = BOOT_TYPE_EMMC;
672 		break;
673 
674 	case IF_TYPE_SD:
675 		media = BOOT_TYPE_SD0;
676 		break;
677 
678 	case IF_TYPE_MTD:
679 		if (devnum == BLK_MTD_SPI_NAND)
680 			media = BOOT_TYPE_MTD_BLK_SPI_NAND;
681 		else if (devnum == BLK_MTD_NAND)
682 			media = BOOT_TYPE_NAND;
683 		else
684 			media = BOOT_TYPE_MTD_BLK_SPI_NOR;
685 		break;
686 
687 	case IF_TYPE_SCSI:
688 		media = BOOT_TYPE_SATA;
689 		break;
690 
691 	case IF_TYPE_RKNAND:
692 		media = BOOT_TYPE_NAND;
693 		break;
694 
695 	case IF_TYPE_NVME:
696 		media = BOOT_TYPE_PCIE;
697 		break;
698 
699 	default:
700 		break;
701 	}
702 
703 	memcpy((void *)&buf[0], (void *)&media, len);
704 	common->residue = len;
705 	common->data_size_from_cmnd = len;
706 
707 	return len;
708 }
709 
rkusb_do_read_capacity(struct fsg_common * common,struct fsg_buffhd * bh)710 static int rkusb_do_read_capacity(struct fsg_common *common,
711 				  struct fsg_buffhd *bh)
712 {
713 	u8 *buf = (u8 *)bh->buf;
714 	u32 len = common->data_size;
715 	enum if_type type = ums[common->lun].block_dev.if_type;
716 	int devnum = ums[common->lun].block_dev.devnum;
717 
718 	/*
719 	 * bit[0]: Direct LBA, 0: Disabled;
720 	 * bit[1]: Vendor Storage API, 0: Disabed (default);
721 	 * bit[2]: First 4M Access, 0: Disabled;
722 	 * bit[3]: Read LBA On, 0: Disabed (default);
723 	 * bit[4]: New Vendor Storage API, 0: Disabed;
724 	 * bit[5]: Read uart data from ram
725 	 * bit[6]: Read IDB config
726 	 * bit[7]: Read SecureMode
727 	 * bit[8]: New IDB feature
728 	 * bit[9]: Get storage media info
729 	 * bit[10:63}: Reserved.
730 	 */
731 	memset((void *)&buf[0], 0, len);
732 	if (type == IF_TYPE_MMC || type == IF_TYPE_SD || type == IF_TYPE_NVME)
733 		buf[0] = BIT(0) | BIT(2) | BIT(4);
734 	else
735 		buf[0] = BIT(0) | BIT(4);
736 
737 	if (type == IF_TYPE_MTD &&
738 	    (devnum == BLK_MTD_NAND ||
739 	    devnum == BLK_MTD_SPI_NAND))
740 		buf[0] |= (1 << 6);
741 
742 #if !defined(CONFIG_ROCKCHIP_RV1126) && !defined(CONFIG_ROCKCHIP_RK3308)
743 	if (type == IF_TYPE_MTD && devnum == BLK_MTD_SPI_NOR)
744 		buf[0] |= (1 << 6);
745 #endif
746 
747 #if defined(CONFIG_ROCKCHIP_NEW_IDB)
748 	buf[1] = BIT(0);
749 #endif
750 	buf[1] |= BIT(1); /* Switch Storage */
751 	buf[1] |= BIT(2); /* LBAwrite Parity */
752 
753 	/* Set data xfer size */
754 	common->residue = len;
755 	common->data_size_from_cmnd = len;
756 
757 	return len;
758 }
759 
rkusb_fixup_cbwcb(struct fsg_common * common,struct fsg_buffhd * bh)760 static void rkusb_fixup_cbwcb(struct fsg_common *common,
761 			      struct fsg_buffhd *bh)
762 {
763 	struct usb_request      *req = bh->outreq;
764 	struct fsg_bulk_cb_wrap *cbw = req->buf;
765 
766 	/* FIXME cbw.DataTransferLength was not set by Upgrade Tool */
767 	common->data_size = le32_to_cpu(cbw->DataTransferLength);
768 	if (common->data_size == 0) {
769 		common->data_size =
770 		get_unaligned_be16(&common->cmnd[7]) << 9;
771 		printf("Trasfer Length NOT set, please use new version tool\n");
772 		debug("%s %d, cmnd1 %x\n", __func__,
773 		      get_unaligned_be16(&common->cmnd[7]),
774 		      get_unaligned_be16(&common->cmnd[1]));
775 	}
776 	if (cbw->Flags & USB_BULK_IN_FLAG)
777 		common->data_dir = DATA_DIR_TO_HOST;
778 	else
779 		common->data_dir = DATA_DIR_FROM_HOST;
780 
781 	/* Not support */
782 	common->cmnd[1] = 0;
783 }
784 
rkusb_cmd_process(struct fsg_common * common,struct fsg_buffhd * bh,int * reply)785 static int rkusb_cmd_process(struct fsg_common *common,
786 			     struct fsg_buffhd *bh, int *reply)
787 {
788 	struct usb_request	*req = bh->outreq;
789 	struct fsg_bulk_cb_wrap	*cbw = req->buf;
790 	int rc;
791 
792 	dump_cbw(cbw);
793 
794 	if (rkusb_check_lun(common)) {
795 		*reply = -EINVAL;
796 		return RKUSB_RC_ERROR;
797 	}
798 
799 	switch (common->cmnd[0]) {
800 	case RKUSB_TEST_UNIT_READY:
801 		*reply = rkusb_do_test_unit_ready(common, bh);
802 		rc = RKUSB_RC_FINISHED;
803 		break;
804 
805 	case RKUSB_READ_FLASH_ID:
806 		*reply = rkusb_do_read_flash_id(common, bh);
807 		rc = RKUSB_RC_FINISHED;
808 		break;
809 
810 	case RKUSB_TEST_BAD_BLOCK:
811 		*reply = rkusb_do_test_bad_block(common, bh);
812 		rc = RKUSB_RC_FINISHED;
813 		break;
814 
815 	case RKUSB_ERASE_10_FORCE:
816 		*reply = rkusb_do_erase_force(common, bh);
817 		rc = RKUSB_RC_FINISHED;
818 		break;
819 
820 	case RKUSB_LBA_READ_10:
821 		rkusb_fixup_cbwcb(common, bh);
822 		common->cmnd[0] = SC_READ_10;
823 		common->cmnd[1] = 0; /* Not support */
824 		rc = RKUSB_RC_CONTINUE;
825 		break;
826 
827 	case RKUSB_LBA_WRITE_10:
828 		rkusb_fixup_cbwcb(common, bh);
829 		common->cmnd[0] = SC_WRITE_10;
830 		common->cmnd[1] = 0; /* Not support */
831 		rc = RKUSB_RC_CONTINUE;
832 		break;
833 
834 	case RKUSB_READ_FLASH_INFO:
835 		*reply = rkusb_do_read_flash_info(common, bh);
836 		rc = RKUSB_RC_FINISHED;
837 		break;
838 
839 	case RKUSB_GET_CHIP_VER:
840 		*reply = rkusb_do_get_chip_info(common, bh);
841 		rc = RKUSB_RC_FINISHED;
842 		break;
843 
844 	case RKUSB_LBA_ERASE:
845 		*reply = rkusb_do_lba_erase(common, bh);
846 		rc = RKUSB_RC_FINISHED;
847 		break;
848 
849 #ifdef CONFIG_ROCKCHIP_VENDOR_PARTITION
850 	case RKUSB_VS_WRITE:
851 		*reply = rkusb_do_vs_write(common);
852 		rc = RKUSB_RC_FINISHED;
853 		break;
854 
855 	case RKUSB_VS_READ:
856 		*reply = rkusb_do_vs_read(common);
857 		rc = RKUSB_RC_FINISHED;
858 		break;
859 #endif
860 	case RKUSB_GET_STORAGE_MEDIA:
861 		*reply = rkusb_do_get_storage_info(common, bh);
862 		rc = RKUSB_RC_FINISHED;
863 		break;
864 
865 	case RKUSB_READ_CAPACITY:
866 		*reply = rkusb_do_read_capacity(common, bh);
867 		rc = RKUSB_RC_FINISHED;
868 		break;
869 
870 	case RKUSB_RESET:
871 		*reply = rkusb_do_reset(common, bh);
872 		rc = RKUSB_RC_FINISHED;
873 		break;
874 
875 	case RKUSB_READ_10:
876 	case RKUSB_WRITE_10:
877 		printf("CMD Not support, pls use new version Tool\n");
878 	case RKUSB_SET_DEVICE_ID:
879 	case RKUSB_ERASE_10:
880 	case RKUSB_WRITE_SPARE:
881 	case RKUSB_READ_SPARE:
882 	case RKUSB_GET_VERSION:
883 	case RKUSB_ERASE_SYS_DISK:
884 	case RKUSB_SDRAM_READ_10:
885 	case RKUSB_SDRAM_WRITE_10:
886 	case RKUSB_SDRAM_EXECUTE:
887 	case RKUSB_LOW_FORMAT:
888 	case RKUSB_SET_RESET_FLAG:
889 	case RKUSB_SPI_READ_10:
890 	case RKUSB_SPI_WRITE_10:
891 	case RKUSB_SESSION:
892 		/* Fall through */
893 	default:
894 		rc = RKUSB_RC_UNKNOWN_CMND;
895 		break;
896 	}
897 
898 	return rc;
899 }
900 
rkusb_do_check_parity(struct fsg_common * common)901 int rkusb_do_check_parity(struct fsg_common *common)
902 {
903 	int ret = 0, rc;
904 	u32 parity, i, usb_parity, lba, len;
905 	static u32 usb_check_buffer[1024 * 256];
906 
907 	usb_parity = common->cmnd[9] | (common->cmnd[10] << 8) |
908 			(common->cmnd[11] << 16) | (common->cmnd[12] << 24);
909 
910 	if (common->cmnd[0] == SC_WRITE_10 && (usb_parity)) {
911 		lba = get_unaligned_be32(&common->cmnd[2]);
912 		len = common->data_size_from_cmnd >> 9;
913 		rc = blk_dread(&ums[common->lun].block_dev, lba, len, usb_check_buffer);
914 		parity = 0x000055aa;
915 		for (i = 0; i < len * 128; i++)
916 			parity += usb_check_buffer[i];
917 		if (!rc || parity != usb_parity)
918 			common->phase_error = 1;
919 	}
920 
921 	return ret;
922 }
923 
924 DECLARE_GADGET_BIND_CALLBACK(rkusb_ums_dnl, fsg_add);
925