xref: /rk3399_rockchip-uboot/drivers/usb/gadget/f_rockusb.c (revision 469f3582a9079a648b2cd75bb63d2f8f02e4fa8f)
1 /*
2  * Copyright 2017 Rockchip Electronics Co., Ltd
3  * Frank Wang <frank.wang@rock-chips.com>
4  *
5  * SPDX-License-Identifier:	GPL-2.0+
6  */
7 
8 #include <asm/io.h>
9 #include <android_avb/avb_ops_user.h>
10 #include <android_avb/rk_avb_ops_user.h>
11 #include <asm/arch/boot_mode.h>
12 #include <asm/arch/chip_info.h>
13 #include <asm/arch/rk_atags.h>
14 #include <write_keybox.h>
15 #include <linux/mtd/mtd.h>
16 #include <optee_include/OpteeClientInterface.h>
17 #include <mmc.h>
18 #include <stdlib.h>
19 #include <usbplug.h>
20 
21 #ifdef CONFIG_ROCKCHIP_VENDOR_PARTITION
22 #include <asm/arch/vendor.h>
23 #endif
24 #include <rockusb.h>
25 
26 #define ROCKUSB_INTERFACE_CLASS	0xff
27 #define ROCKUSB_INTERFACE_SUB_CLASS	0x06
28 #define ROCKUSB_INTERFACE_PROTOCOL	0x05
29 
30 #define ROCKCHIP_FLASH_BLOCK_SIZE	1024
31 #define ROCKCHIP_FLASH_PAGE_SIZE	4
32 
33 static struct usb_interface_descriptor rkusb_intf_desc = {
34 	.bLength		= USB_DT_INTERFACE_SIZE,
35 	.bDescriptorType	= USB_DT_INTERFACE,
36 	.bInterfaceNumber	= 0x00,
37 	.bAlternateSetting	= 0x00,
38 	.bNumEndpoints		= 0x02,
39 	.bInterfaceClass	= ROCKUSB_INTERFACE_CLASS,
40 	.bInterfaceSubClass	= ROCKUSB_INTERFACE_SUB_CLASS,
41 	.bInterfaceProtocol	= ROCKUSB_INTERFACE_PROTOCOL,
42 };
43 
44 static struct usb_descriptor_header *rkusb_fs_function[] = {
45 	(struct usb_descriptor_header *)&rkusb_intf_desc,
46 	(struct usb_descriptor_header *)&fsg_fs_bulk_in_desc,
47 	(struct usb_descriptor_header *)&fsg_fs_bulk_out_desc,
48 	NULL,
49 };
50 
51 static struct usb_descriptor_header *rkusb_hs_function[] = {
52 	(struct usb_descriptor_header *)&rkusb_intf_desc,
53 	(struct usb_descriptor_header *)&fsg_hs_bulk_in_desc,
54 	(struct usb_descriptor_header *)&fsg_hs_bulk_out_desc,
55 	NULL,
56 };
57 
58 static struct usb_descriptor_header *rkusb_ss_function[] = {
59 	(struct usb_descriptor_header *)&rkusb_intf_desc,
60 	(struct usb_descriptor_header *)&fsg_ss_bulk_in_desc,
61 	(struct usb_descriptor_header *)&fsg_ss_bulk_in_comp_desc,
62 	(struct usb_descriptor_header *)&fsg_ss_bulk_out_desc,
63 	(struct usb_descriptor_header *)&fsg_ss_bulk_out_comp_desc,
64 	NULL,
65 };
66 
67 struct rk_flash_info {
68 	u32	flash_size;
69 	u16	block_size;
70 	u8	page_size;
71 	u8	ecc_bits;
72 	u8	access_time;
73 	u8	manufacturer;
74 	u8	flash_mask;
75 } __packed;
76 
77 static int rkusb_rst_code; /* The subcode in reset command (0xFF) */
78 
79 int g_dnl_bind_fixup(struct usb_device_descriptor *dev, const char *name)
80 {
81 	if (IS_RKUSB_UMS_DNL(name)) {
82 		/* Fix to Rockchip's VID and PID */
83 		dev->idVendor  = __constant_cpu_to_le16(0x2207);
84 		dev->idProduct = __constant_cpu_to_le16(CONFIG_ROCKUSB_G_DNL_PID);
85 
86 		/* Enumerate as a loader device */
87 #if defined(CONFIG_SUPPORT_USBPLUG)
88 		dev->bcdUSB = cpu_to_le16(0x0200);
89 #else
90 		dev->bcdUSB = cpu_to_le16(0x0201);
91 #endif
92 	} else if (!strncmp(name, "usb_dnl_fastboot", 16)) {
93 		/* Fix to Google's VID and PID */
94 		dev->idVendor  = __constant_cpu_to_le16(0x18d1);
95 		dev->idProduct = __constant_cpu_to_le16(0xd00d);
96 	} else if (!strncmp(name, "usb_dnl_dfu", 11)) {
97 		/* Fix to Rockchip's VID and PID for DFU */
98 		dev->idVendor  = cpu_to_le16(0x2207);
99 		dev->idProduct = cpu_to_le16(0x0107);
100 	} else if (!strncmp(name, "usb_dnl_ums", 11)) {
101 		dev->idVendor  = cpu_to_le16(0x2207);
102 		dev->idProduct = cpu_to_le16(0x0010);
103 	}
104 
105 	return 0;
106 }
107 
108 __maybe_unused
109 static inline void dump_cbw(struct fsg_bulk_cb_wrap *cbw)
110 {
111 	assert(!cbw);
112 
113 	debug("%s:\n", __func__);
114 	debug("Signature %x\n", cbw->Signature);
115 	debug("Tag %x\n", cbw->Tag);
116 	debug("DataTransferLength %x\n", cbw->DataTransferLength);
117 	debug("Flags %x\n", cbw->Flags);
118 	debug("LUN %x\n", cbw->Lun);
119 	debug("Length %x\n", cbw->Length);
120 	debug("OptionCode %x\n", cbw->CDB[0]);
121 	debug("SubCode %x\n", cbw->CDB[1]);
122 	debug("SectorAddr %x\n", get_unaligned_be32(&cbw->CDB[2]));
123 	debug("BlkSectors %x\n\n", get_unaligned_be16(&cbw->CDB[7]));
124 }
125 
126 static int rkusb_check_lun(struct fsg_common *common)
127 {
128 	struct fsg_lun *curlun;
129 
130 	/* Check the LUN */
131 	if (common->lun >= 0 && common->lun < common->nluns) {
132 		curlun = &common->luns[common->lun];
133 		if (common->cmnd[0] != SC_REQUEST_SENSE) {
134 			curlun->sense_data = SS_NO_SENSE;
135 			curlun->info_valid = 0;
136 		}
137 	} else {
138 		curlun = NULL;
139 		common->bad_lun_okay = 0;
140 
141 		/*
142 		 * INQUIRY and REQUEST SENSE commands are explicitly allowed
143 		 * to use unsupported LUNs; all others may not.
144 		 */
145 		if (common->cmnd[0] != SC_INQUIRY &&
146 		    common->cmnd[0] != SC_REQUEST_SENSE) {
147 			debug("unsupported LUN %d\n", common->lun);
148 			return -EINVAL;
149 		}
150 	}
151 
152 	return 0;
153 }
154 
155 static void __do_reset(struct usb_ep *ep, struct usb_request *req)
156 {
157 	u32 boot_flag = BOOT_NORMAL;
158 
159 	if (rkusb_rst_code == 0x03)
160 		boot_flag = BOOT_BROM_DOWNLOAD;
161 
162 	rkusb_rst_code = 0; /* restore to default */
163 	writel(boot_flag, (void *)CONFIG_ROCKCHIP_BOOT_MODE_REG);
164 
165 	do_reset(NULL, 0, 0, NULL);
166 }
167 
168 static int rkusb_do_reset(struct fsg_common *common,
169 			  struct fsg_buffhd *bh)
170 {
171 	common->data_size_from_cmnd = common->cmnd[4];
172 	common->residue = 0;
173 	bh->inreq->complete = __do_reset;
174 	bh->state = BUF_STATE_EMPTY;
175 
176 	rkusb_rst_code = !common->cmnd[1] ? 0xff : common->cmnd[1];
177 	return 0;
178 }
179 
180 __weak bool rkusb_usb3_capable(void)
181 {
182 	return false;
183 }
184 
185 static int rkusb_do_switch_to_usb3(struct fsg_common *common,
186 				   struct fsg_buffhd *bh)
187 {
188 	g_dnl_set_serialnumber((char *)&common->cmnd[1]);
189 	rkusb_switch_to_usb3_enable(true);
190 	bh->state = BUF_STATE_EMPTY;
191 
192 	return 0;
193 }
194 
195 static int rkusb_do_test_unit_ready(struct fsg_common *common,
196 				    struct fsg_buffhd *bh)
197 {
198 	struct blk_desc *desc = &ums[common->lun].block_dev;
199 
200 	if ((desc->if_type == IF_TYPE_MTD && desc->devnum == BLK_MTD_SPI_NOR) ||
201 	    desc->if_type == IF_TYPE_SPINOR)
202 		common->residue = 0x03 << 24; /* 128KB Max block xfer for SPI Nor */
203 	else
204 		common->residue = 0x06 << 24; /* Max block xfer support from host */
205 
206 	common->data_dir = DATA_DIR_NONE;
207 	bh->state = BUF_STATE_EMPTY;
208 
209 	return 0;
210 }
211 
212 static int rkusb_do_read_flash_id(struct fsg_common *common,
213 				  struct fsg_buffhd *bh)
214 {
215 	u8 *buf = (u8 *)bh->buf;
216 	u32 len = 5;
217 	enum if_type type = ums[common->lun].block_dev.if_type;
218 	u32 devnum = ums[common->lun].block_dev.devnum;
219 	const char *str;
220 
221 	switch (type) {
222 	case IF_TYPE_MMC:
223 		str = "EMMC ";
224 		break;
225 	case IF_TYPE_RKNAND:
226 		str = "NAND ";
227 		break;
228 	case IF_TYPE_MTD:
229 		if (devnum == BLK_MTD_SPI_NAND)
230 			str ="SNAND";
231 		else if (devnum == BLK_MTD_NAND)
232 			str = "NAND ";
233 		else
234 			str = "NOR  ";
235 		break;
236 	default:
237 		str = "UNKN "; /* unknown */
238 		break;
239 	}
240 
241 	memcpy((void *)&buf[0], str, len);
242 
243 	/* Set data xfer size */
244 	common->residue = common->data_size_from_cmnd = len;
245 	common->data_size = len;
246 
247 	return len;
248 }
249 
250 static int rkusb_do_test_bad_block(struct fsg_common *common,
251 				   struct fsg_buffhd *bh)
252 {
253 	u8 *buf = (u8 *)bh->buf;
254 	u32 len = 64;
255 
256 	memset((void *)&buf[0], 0, len);
257 
258 	/* Set data xfer size */
259 	common->residue = common->data_size_from_cmnd = len;
260 	common->data_size = len;
261 
262 	return len;
263 }
264 
265 static int rkusb_do_read_flash_info(struct fsg_common *common,
266 				    struct fsg_buffhd *bh)
267 {
268 	struct blk_desc *desc = &ums[common->lun].block_dev;
269 	u8 *buf = (u8 *)bh->buf;
270 	u32 len = sizeof(struct rk_flash_info);
271 	struct rk_flash_info finfo = {
272 		.block_size = ROCKCHIP_FLASH_BLOCK_SIZE,
273 		.ecc_bits = 0,
274 		.page_size = ROCKCHIP_FLASH_PAGE_SIZE,
275 		.access_time = 40,
276 		.manufacturer = 0,
277 		.flash_mask = 0
278 	};
279 
280 	finfo.flash_size = (u32)desc->lba;
281 
282 	if (desc->if_type == IF_TYPE_MTD &&
283 	    (desc->devnum == BLK_MTD_NAND ||
284 	    desc->devnum == BLK_MTD_SPI_NAND)) {
285 		struct mtd_info *mtd = (struct mtd_info *)desc->bdev->priv;
286 
287 		if (mtd) {
288 			finfo.block_size = mtd->erasesize >> 9;
289 			finfo.page_size = mtd->writesize >> 9;
290 		}
291 	}
292 
293 	if (desc->if_type == IF_TYPE_MTD && desc->devnum == BLK_MTD_SPI_NOR) {
294 		/* RV1126/RK3308 mtd spinor keep the former upgrade mode */
295 #if !defined(CONFIG_ROCKCHIP_RV1126) && !defined(CONFIG_ROCKCHIP_RK3308)
296 		finfo.block_size = 0x80; /* Aligned to 64KB */
297 #else
298 		finfo.block_size = ROCKCHIP_FLASH_BLOCK_SIZE;
299 #endif
300 	}
301 
302 	debug("Flash info: block_size= %x page_size= %x\n", finfo.block_size,
303 	      finfo.page_size);
304 
305 	if (finfo.flash_size)
306 		finfo.flash_mask = 1;
307 
308 	memset((void *)&buf[0], 0, len);
309 	memcpy((void *)&buf[0], (void *)&finfo, len);
310 
311 	/* Set data xfer size */
312 	common->residue = common->data_size_from_cmnd = len;
313         /* legacy upgrade_tool does not set correct transfer size */
314 	common->data_size = len;
315 
316 	return len;
317 }
318 
319 static int rkusb_do_get_chip_info(struct fsg_common *common,
320 				  struct fsg_buffhd *bh)
321 {
322 	u8 *buf = (u8 *)bh->buf;
323 	u32 len = common->data_size;
324 	u32 chip_info[4];
325 
326 	memset((void *)chip_info, 0, sizeof(chip_info));
327 	rockchip_rockusb_get_chip_info(chip_info);
328 
329 	memset((void *)&buf[0], 0, len);
330 	memcpy((void *)&buf[0], (void *)chip_info, len);
331 
332 	/* Set data xfer size */
333 	common->residue = common->data_size_from_cmnd = len;
334 
335 	return len;
336 }
337 
338 static int rkusb_do_lba_erase(struct fsg_common *common,
339 			      struct fsg_buffhd *bh)
340 {
341 	struct fsg_lun *curlun = &common->luns[common->lun];
342 	u32 lba, amount;
343 	loff_t file_offset;
344 	int rc;
345 
346 	lba = get_unaligned_be32(&common->cmnd[2]);
347 	if (lba >= curlun->num_sectors) {
348 		curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE;
349 		rc = -EINVAL;
350 		goto out;
351 	}
352 
353 	file_offset = ((loff_t) lba) << 9;
354 	amount = get_unaligned_be16(&common->cmnd[7]) << 9;
355 	if (unlikely(amount == 0)) {
356 		curlun->sense_data = SS_INVALID_FIELD_IN_CDB;
357 		rc = -EIO;
358 		goto out;
359 	}
360 
361 	/* Perform the erase */
362 	rc = ums[common->lun].erase_sector(&ums[common->lun],
363 			       file_offset / SECTOR_SIZE,
364 			       amount / SECTOR_SIZE);
365 	if (!rc) {
366 		curlun->sense_data = SS_MEDIUM_NOT_PRESENT;
367 		rc = -EIO;
368 	}
369 
370 out:
371 	common->data_dir = DATA_DIR_NONE;
372 	bh->state = BUF_STATE_EMPTY;
373 
374 	return rc;
375 }
376 
377 static int rkusb_do_erase_force(struct fsg_common *common,
378 				struct fsg_buffhd *bh)
379 {
380 	struct blk_desc *desc = &ums[common->lun].block_dev;
381 	struct fsg_lun *curlun = &common->luns[common->lun];
382 	u16 block_size = ROCKCHIP_FLASH_BLOCK_SIZE;
383 	u32 lba, amount;
384 	loff_t file_offset;
385 	int rc;
386 
387 	lba = get_unaligned_be32(&common->cmnd[2]);
388 	if (lba >= curlun->num_sectors) {
389 		curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE;
390 		rc = -EINVAL;
391 		goto out;
392 	}
393 
394 	if (desc->if_type == IF_TYPE_MTD &&
395 	    (desc->devnum == BLK_MTD_NAND ||
396 	    desc->devnum == BLK_MTD_SPI_NAND)) {
397 		struct mtd_info *mtd = (struct mtd_info *)desc->bdev->priv;
398 
399 		if (mtd)
400 			block_size = mtd->erasesize >> 9;
401 	}
402 
403 	file_offset = ((loff_t)lba) * block_size;
404 	amount = get_unaligned_be16(&common->cmnd[7]) * block_size;
405 
406 	debug("%s lba= %x, nsec= %x\n", __func__, lba,
407 	      (u32)get_unaligned_be16(&common->cmnd[7]));
408 
409 	if (unlikely(amount == 0)) {
410 		curlun->sense_data = SS_INVALID_FIELD_IN_CDB;
411 		rc = -EIO;
412 		goto out;
413 	}
414 
415 	/* Perform the erase */
416 	rc = ums[common->lun].erase_sector(&ums[common->lun],
417 					   file_offset,
418 					   amount);
419 	if (!rc) {
420 		curlun->sense_data = SS_MEDIUM_NOT_PRESENT;
421 		rc = -EIO;
422 	}
423 
424 out:
425 	common->data_dir = DATA_DIR_NONE;
426 	bh->state = BUF_STATE_EMPTY;
427 
428 	return rc;
429 }
430 
431 #ifdef CONFIG_ROCKCHIP_VENDOR_PARTITION
432 static int rkusb_do_vs_write(struct fsg_common *common)
433 {
434 	struct fsg_lun		*curlun = &common->luns[common->lun];
435 	u16			type = get_unaligned_be16(&common->cmnd[4]);
436 	struct vendor_item	*vhead;
437 	struct fsg_buffhd	*bh;
438 	void			*data;
439 	int			rc;
440 
441 	if (common->data_size >= (u32)65536) {
442 		/* _MUST_ small than 64K */
443 		curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE;
444 		return -EINVAL;
445 	}
446 
447 	common->residue         = common->data_size;
448 	common->usb_amount_left = common->data_size;
449 
450 	/* Carry out the file writes */
451 	if (unlikely(common->data_size == 0))
452 		return -EIO; /* No data to write */
453 
454 	for (;;) {
455 		if (common->usb_amount_left > 0) {
456 			/* Wait for the next buffer to become available */
457 			bh = common->next_buffhd_to_fill;
458 			if (bh->state != BUF_STATE_EMPTY)
459 				goto wait;
460 
461 			/* Request the next buffer */
462 			common->usb_amount_left      -= common->data_size;
463 			bh->outreq->length	     = common->data_size;
464 			bh->bulk_out_intended_length = common->data_size;
465 			bh->outreq->short_not_ok     = 1;
466 
467 			START_TRANSFER_OR(common, bulk_out, bh->outreq,
468 					  &bh->outreq_busy, &bh->state)
469 				/*
470 				 * Don't know what to do if
471 				 * common->fsg is NULL
472 				 */
473 				return -EIO;
474 			common->next_buffhd_to_fill = bh->next;
475 		} else {
476 			/* Then, wait for the data to become available */
477 			bh = common->next_buffhd_to_drain;
478 			if (bh->state != BUF_STATE_FULL)
479 				goto wait;
480 
481 			common->next_buffhd_to_drain = bh->next;
482 			bh->state = BUF_STATE_EMPTY;
483 
484 			/* Did something go wrong with the transfer? */
485 			if (bh->outreq->status != 0) {
486 				curlun->sense_data = SS_COMMUNICATION_FAILURE;
487 				curlun->info_valid = 1;
488 				break;
489 			}
490 
491 			/* Perform the write */
492 			vhead = (struct vendor_item *)bh->buf;
493 			data  = bh->buf + sizeof(struct vendor_item);
494 
495 			if (!type) {
496 				#ifndef CONFIG_SUPPORT_USBPLUG
497 				if (vhead->id == HDCP_14_HDMI_ID ||
498 				    vhead->id == HDCP_14_HDMIRX_ID ||
499 				    vhead->id == HDCP_14_DP_ID) {
500 					rc = vendor_handle_hdcp(vhead);
501 					if (rc < 0) {
502 						curlun->sense_data = SS_WRITE_ERROR;
503 						return -EIO;
504 					}
505 				}
506 				#endif
507 
508 				/* Vendor storage */
509 				rc = vendor_storage_write(vhead->id,
510 							  (char __user *)data,
511 							  vhead->size);
512 				if (rc < 0) {
513 					curlun->sense_data = SS_WRITE_ERROR;
514 					return -EIO;
515 				}
516 			} else if (type == 1) {
517 				/* RPMB */
518 				rc =
519 				write_keybox_to_secure_storage((u8 *)data,
520 							       vhead->size);
521 				if (rc < 0) {
522 					curlun->sense_data = SS_WRITE_ERROR;
523 					return -EIO;
524 				}
525 			} else if (type == 2) {
526 				/* security storage */
527 #ifdef CONFIG_RK_AVB_LIBAVB_USER
528 				debug("%s call rk_avb_write_perm_attr %d, %d\n",
529 				      __func__, vhead->id, vhead->size);
530 				rc = rk_avb_write_perm_attr(vhead->id,
531 							    (char __user *)data,
532 							    vhead->size);
533 				if (rc < 0) {
534 					curlun->sense_data = SS_WRITE_ERROR;
535 					return -EIO;
536 				}
537 #else
538 				printf("Please enable CONFIG_RK_AVB_LIBAVB_USER\n");
539 #endif
540 			} else if (type == 3) {
541 				/* efuse or otp*/
542 #ifdef CONFIG_OPTEE_CLIENT
543 				if (memcmp(data, "TAEK", 4) == 0) {
544 					if (vhead->size - 8 != 32) {
545 						printf("check ta encryption key size fail!\n");
546 						curlun->sense_data = SS_WRITE_ERROR;
547 						return -EIO;
548 					}
549 					if (trusty_write_ta_encryption_key((uint32_t *)(data + 8), 8) != 0) {
550 						printf("trusty_write_ta_encryption_key error!");
551 						curlun->sense_data = SS_WRITE_ERROR;
552 						return -EIO;
553 					}
554 				} else if (memcmp(data, "EHUK", 4) == 0) {
555 					if (vhead->size - 8 != 32) {
556 						printf("check oem huk size fail!\n");
557 						curlun->sense_data = SS_WRITE_ERROR;
558 						return -EIO;
559 					}
560 					if (trusty_write_oem_huk((uint32_t *)(data + 8), 8) != 0) {
561 						printf("trusty_write_oem_huk error!");
562 						curlun->sense_data = SS_WRITE_ERROR;
563 						return -EIO;
564 					}
565 				} else {
566 					printf("Unknown tag\n");
567 					curlun->sense_data = SS_WRITE_ERROR;
568 					return -EIO;
569 				}
570 #else
571 				printf("Please enable CONFIG_OPTEE_CLIENT\n");
572 #endif
573 			} else {
574 				return -EINVAL;
575 			}
576 
577 			common->residue -= common->data_size;
578 
579 			/* Did the host decide to stop early? */
580 			if (bh->outreq->actual != bh->outreq->length)
581 				common->short_packet_received = 1;
582 			break; /* Command done */
583 		}
584 wait:
585 		/* Wait for something to happen */
586 		rc = sleep_thread(common);
587 		if (rc)
588 			return rc;
589 	}
590 
591 	return -EIO; /* No default reply */
592 }
593 
594 static int rkusb_do_vs_read(struct fsg_common *common)
595 {
596 	struct fsg_lun		*curlun = &common->luns[common->lun];
597 	u16			type = get_unaligned_be16(&common->cmnd[4]);
598 	struct vendor_item	*vhead;
599 	struct fsg_buffhd	*bh;
600 	void			*data;
601 	int			rc;
602 
603 	if (common->data_size >= (u32)65536) {
604 		/* _MUST_ small than 64K */
605 		curlun->sense_data = SS_LOGICAL_BLOCK_ADDRESS_OUT_OF_RANGE;
606 		return -EINVAL;
607 	}
608 
609 	common->residue         = common->data_size;
610 	common->usb_amount_left = common->data_size;
611 
612 	/* Carry out the file reads */
613 	if (unlikely(common->data_size == 0))
614 		return -EIO; /* No default reply */
615 
616 	for (;;) {
617 		/* Wait for the next buffer to become available */
618 		bh = common->next_buffhd_to_fill;
619 		while (bh->state != BUF_STATE_EMPTY) {
620 			rc = sleep_thread(common);
621 			if (rc)
622 				return rc;
623 		}
624 
625 		memset(bh->buf, 0, FSG_BUFLEN);
626 		vhead = (struct vendor_item *)bh->buf;
627 		data  = bh->buf + sizeof(struct vendor_item);
628 		vhead->id = get_unaligned_be16(&common->cmnd[2]);
629 
630 		if (!type) {
631 			/* Vendor storage */
632 			rc = vendor_storage_read(vhead->id,
633 						 (char __user *)data,
634 						 common->data_size);
635 			if (!rc) {
636 				curlun->sense_data = SS_UNRECOVERED_READ_ERROR;
637 				return -EIO;
638 			}
639 			vhead->size = rc;
640 		} else if (type == 1) {
641 			/* RPMB */
642 			rc =
643 			read_raw_data_from_secure_storage((u8 *)data,
644 							  common->data_size);
645 			if (!rc) {
646 				curlun->sense_data = SS_UNRECOVERED_READ_ERROR;
647 				return -EIO;
648 			}
649 			vhead->size = rc;
650 		} else if (type == 2) {
651 			/* security storage */
652 #ifdef CONFIG_RK_AVB_LIBAVB_USER
653 			rc = rk_avb_read_perm_attr(vhead->id,
654 						   (char __user *)data,
655 						   vhead->size);
656 			if (rc < 0)
657 				return -EIO;
658 			vhead->size = rc;
659 #else
660 			printf("Please enable CONFIG_RK_AVB_LIBAVB_USER!\n");
661 #endif
662 		} else if (type == 3) {
663 			/* efuse or otp*/
664 #ifdef CONFIG_OPTEE_CLIENT
665 			if (vhead->id == 120) {
666 				u8 value;
667 				char *written_str = "key is written!";
668 				char *not_written_str = "key is not written!";
669 				if (trusty_ta_encryption_key_is_written(&value) != 0) {
670 					printf("trusty_ta_encryption_key_is_written error!");
671 					return -EIO;
672 				}
673 				if (value) {
674 					memcpy(data, written_str, strlen(written_str));
675 					vhead->size = strlen(written_str);
676 				} else {
677 					memcpy(data, not_written_str, strlen(not_written_str));
678 					vhead->size = strlen(not_written_str);
679 				}
680 			} else {
681 				printf("Unknown tag\n");
682 				return -EIO;
683 			}
684 #else
685 			printf("Please enable CONFIG_OPTEE_CLIENT\n");
686 #endif
687 		} else {
688 			return -EINVAL;
689 		}
690 
691 		common->residue   -= common->data_size;
692 		bh->inreq->length = common->data_size;
693 		bh->state         = BUF_STATE_FULL;
694 
695 		break; /* No more left to read */
696 	}
697 
698 	return -EIO; /* No default reply */
699 }
700 #endif
701 
702 static int rkusb_do_switch_storage(struct fsg_common *common)
703 {
704 	enum if_type type, cur_type = ums[common->lun].block_dev.if_type;
705 	int devnum, cur_devnum = ums[common->lun].block_dev.devnum;
706 	struct blk_desc *block_dev;
707 	u32 media = BOOT_TYPE_UNKNOWN;
708 
709 	media = 1 << common->cmnd[1];
710 
711 	switch (media) {
712 #ifdef CONFIG_MMC
713 	case BOOT_TYPE_EMMC:
714 		type = IF_TYPE_MMC;
715 		devnum = 0;
716 		mmc_initialize(gd->bd);
717 		break;
718 #endif
719 	case BOOT_TYPE_MTD_BLK_NAND:
720 		type = IF_TYPE_MTD;
721 		devnum = 0;
722 		break;
723 	case BOOT_TYPE_MTD_BLK_SPI_NAND:
724 		type = IF_TYPE_MTD;
725 		devnum = 1;
726 		break;
727 	case BOOT_TYPE_MTD_BLK_SPI_NOR:
728 		type = IF_TYPE_MTD;
729 		devnum = 2;
730 		break;
731 	default:
732 		printf("Bootdev 0x%x is not support\n", media);
733 		return -ENODEV;
734 	}
735 
736 	if (cur_type == type && cur_devnum == devnum)
737 		return 0;
738 
739 #if CONFIG_IS_ENABLED(SUPPORT_USBPLUG)
740 	block_dev = usbplug_blk_get_devnum_by_type(type, devnum);
741 #else
742 	block_dev = blk_get_devnum_by_type(type, devnum);
743 #endif
744 	if (!block_dev) {
745 		printf("Bootdev if_type=%d num=%d toggle fail\n", type, devnum);
746 		return -ENODEV;
747 	}
748 
749 	ums[common->lun].num_sectors = block_dev->lba;
750 	ums[common->lun].block_dev = *block_dev;
751 
752 	printf("RKUSB: LUN %d, dev %d, hwpart %d, sector %#x, count %#x\n",
753 	       0,
754 	       ums[common->lun].block_dev.devnum,
755 	       ums[common->lun].block_dev.hwpart,
756 	       ums[common->lun].start_sector,
757 	       ums[common->lun].num_sectors);
758 
759 	return 0;
760 }
761 
762 static int rkusb_do_get_storage_info(struct fsg_common *common,
763 				     struct fsg_buffhd *bh)
764 {
765 	enum if_type type = ums[common->lun].block_dev.if_type;
766 	int devnum = ums[common->lun].block_dev.devnum;
767 	u32 media = BOOT_TYPE_UNKNOWN;
768 	u32 len = common->data_size;
769 	u8 *buf = (u8 *)bh->buf;
770 
771 	if (len > 4)
772 		len = 4;
773 
774 	switch (type) {
775 	case IF_TYPE_MMC:
776 		media = BOOT_TYPE_EMMC;
777 		break;
778 
779 	case IF_TYPE_SD:
780 		media = BOOT_TYPE_SD0;
781 		break;
782 
783 	case IF_TYPE_MTD:
784 		if (devnum == BLK_MTD_SPI_NAND)
785 			media = BOOT_TYPE_MTD_BLK_SPI_NAND;
786 		else if (devnum == BLK_MTD_NAND)
787 			media = BOOT_TYPE_NAND;
788 		else
789 			media = BOOT_TYPE_MTD_BLK_SPI_NOR;
790 		break;
791 
792 	case IF_TYPE_SCSI:
793 		media = BOOT_TYPE_SATA;
794 		break;
795 
796 	case IF_TYPE_RKNAND:
797 		media = BOOT_TYPE_NAND;
798 		break;
799 
800 	case IF_TYPE_NVME:
801 		media = BOOT_TYPE_PCIE;
802 		break;
803 
804 	default:
805 		break;
806 	}
807 
808 	memcpy((void *)&buf[0], (void *)&media, len);
809 	common->residue = len;
810 	common->data_size_from_cmnd = len;
811 
812 	return len;
813 }
814 
815 static int rkusb_do_read_capacity(struct fsg_common *common,
816 				  struct fsg_buffhd *bh)
817 {
818 	u8 *buf = (u8 *)bh->buf;
819 	u32 len = common->data_size;
820 	enum if_type type = ums[common->lun].block_dev.if_type;
821 	int devnum = ums[common->lun].block_dev.devnum;
822 
823 	/*
824 	 * bit[0]: Direct LBA, 0: Disabled;
825 	 * bit[1]: Vendor Storage API, 0: Disabed (default);
826 	 * bit[2]: First 4M Access, 0: Disabled;
827 	 * bit[3]: Read LBA On, 0: Disabed (default);
828 	 * bit[4]: New Vendor Storage API, 0: Disabed;
829 	 * bit[5]: Read uart data from ram
830 	 * bit[6]: Read IDB config
831 	 * bit[7]: Read SecureMode
832 	 * bit[8]: New IDB feature
833 	 * bit[9]: Get storage media info
834 	 * bit[10:63}: Reserved.
835 	 */
836 	memset((void *)&buf[0], 0, len);
837 	if (type == IF_TYPE_MMC || type == IF_TYPE_SD || type == IF_TYPE_NVME)
838 		buf[0] = BIT(0) | BIT(2) | BIT(4);
839 	else
840 		buf[0] = BIT(0) | BIT(4);
841 
842 	if (type == IF_TYPE_MTD &&
843 	    (devnum == BLK_MTD_NAND ||
844 	    devnum == BLK_MTD_SPI_NAND))
845 		buf[0] |= (1 << 6);
846 
847 #if !defined(CONFIG_ROCKCHIP_RV1126) && !defined(CONFIG_ROCKCHIP_RK3308)
848 	if (type == IF_TYPE_MTD && devnum == BLK_MTD_SPI_NOR)
849 		buf[0] |= (1 << 6);
850 #endif
851 
852 #if defined(CONFIG_ROCKCHIP_NEW_IDB)
853 	buf[1] = BIT(0);
854 #endif
855 	buf[1] |= BIT(1); /* Switch Storage */
856 	buf[1] |= BIT(2); /* LBAwrite Parity */
857 
858 	if (rkusb_usb3_capable() && !rkusb_force_usb2_enabled())
859 		buf[1] |= BIT(4);
860 	else
861 		buf[1] &= ~BIT(4);
862 
863 	/* Set data xfer size */
864 	common->residue = len;
865 	common->data_size_from_cmnd = len;
866 
867 	return len;
868 }
869 
870 static void rkusb_fixup_cbwcb(struct fsg_common *common,
871 			      struct fsg_buffhd *bh)
872 {
873 	struct usb_request      *req = bh->outreq;
874 	struct fsg_bulk_cb_wrap *cbw = req->buf;
875 
876 	/* FIXME cbw.DataTransferLength was not set by Upgrade Tool */
877 	common->data_size = le32_to_cpu(cbw->DataTransferLength);
878 	if (common->data_size == 0) {
879 		common->data_size =
880 		get_unaligned_be16(&common->cmnd[7]) << 9;
881 		printf("Trasfer Length NOT set, please use new version tool\n");
882 		debug("%s %d, cmnd1 %x\n", __func__,
883 		      get_unaligned_be16(&common->cmnd[7]),
884 		      get_unaligned_be16(&common->cmnd[1]));
885 	}
886 	if (cbw->Flags & USB_BULK_IN_FLAG)
887 		common->data_dir = DATA_DIR_TO_HOST;
888 	else
889 		common->data_dir = DATA_DIR_FROM_HOST;
890 
891 	/* Not support */
892 	common->cmnd[1] = 0;
893 }
894 
895 static int rkusb_cmd_process(struct fsg_common *common,
896 			     struct fsg_buffhd *bh, int *reply)
897 {
898 	struct usb_request	*req = bh->outreq;
899 	struct fsg_bulk_cb_wrap	*cbw = req->buf;
900 	int rc;
901 
902 	dump_cbw(cbw);
903 
904 	if (rkusb_check_lun(common)) {
905 		*reply = -EINVAL;
906 		return RKUSB_RC_ERROR;
907 	}
908 
909 	switch (common->cmnd[0]) {
910 	case RKUSB_TEST_UNIT_READY:
911 		*reply = rkusb_do_test_unit_ready(common, bh);
912 		rc = RKUSB_RC_FINISHED;
913 		break;
914 
915 	case RKUSB_READ_FLASH_ID:
916 		*reply = rkusb_do_read_flash_id(common, bh);
917 		rc = RKUSB_RC_FINISHED;
918 		break;
919 
920 	case RKUSB_TEST_BAD_BLOCK:
921 		*reply = rkusb_do_test_bad_block(common, bh);
922 		rc = RKUSB_RC_FINISHED;
923 		break;
924 
925 	case RKUSB_ERASE_10_FORCE:
926 		*reply = rkusb_do_erase_force(common, bh);
927 		rc = RKUSB_RC_FINISHED;
928 		break;
929 
930 	case RKUSB_LBA_READ_10:
931 		rkusb_fixup_cbwcb(common, bh);
932 		common->cmnd[0] = SC_READ_10;
933 		common->cmnd[1] = 0; /* Not support */
934 		rc = RKUSB_RC_CONTINUE;
935 		break;
936 
937 	case RKUSB_LBA_WRITE_10:
938 		rkusb_fixup_cbwcb(common, bh);
939 		common->cmnd[0] = SC_WRITE_10;
940 		common->cmnd[1] = 0; /* Not support */
941 		rc = RKUSB_RC_CONTINUE;
942 		break;
943 
944 	case RKUSB_READ_FLASH_INFO:
945 		*reply = rkusb_do_read_flash_info(common, bh);
946 		rc = RKUSB_RC_FINISHED;
947 		break;
948 
949 	case RKUSB_GET_CHIP_VER:
950 		*reply = rkusb_do_get_chip_info(common, bh);
951 		rc = RKUSB_RC_FINISHED;
952 		break;
953 
954 	case RKUSB_LBA_ERASE:
955 		*reply = rkusb_do_lba_erase(common, bh);
956 		rc = RKUSB_RC_FINISHED;
957 		break;
958 
959 #ifdef CONFIG_ROCKCHIP_VENDOR_PARTITION
960 	case RKUSB_VS_WRITE:
961 		*reply = rkusb_do_vs_write(common);
962 		rc = RKUSB_RC_FINISHED;
963 		break;
964 
965 	case RKUSB_VS_READ:
966 		*reply = rkusb_do_vs_read(common);
967 		rc = RKUSB_RC_FINISHED;
968 		break;
969 #endif
970 	case RKUSB_SWITCH_STORAGE:
971 		*reply = rkusb_do_switch_storage(common);
972 		rc = RKUSB_RC_FINISHED;
973 		break;
974 	case RKUSB_GET_STORAGE_MEDIA:
975 		*reply = rkusb_do_get_storage_info(common, bh);
976 		rc = RKUSB_RC_FINISHED;
977 		break;
978 
979 	case RKUSB_READ_CAPACITY:
980 		*reply = rkusb_do_read_capacity(common, bh);
981 		rc = RKUSB_RC_FINISHED;
982 		break;
983 
984 	case RKUSB_SWITCH_USB3:
985 		*reply = rkusb_do_switch_to_usb3(common, bh);
986 		rc = RKUSB_RC_FINISHED;
987 		break;
988 
989 	case RKUSB_RESET:
990 		*reply = rkusb_do_reset(common, bh);
991 		rc = RKUSB_RC_FINISHED;
992 		break;
993 
994 	case RKUSB_READ_10:
995 	case RKUSB_WRITE_10:
996 		printf("CMD Not support, pls use new version Tool\n");
997 	case RKUSB_SET_DEVICE_ID:
998 	case RKUSB_ERASE_10:
999 	case RKUSB_WRITE_SPARE:
1000 	case RKUSB_READ_SPARE:
1001 	case RKUSB_GET_VERSION:
1002 	case RKUSB_ERASE_SYS_DISK:
1003 	case RKUSB_SDRAM_READ_10:
1004 	case RKUSB_SDRAM_WRITE_10:
1005 	case RKUSB_SDRAM_EXECUTE:
1006 	case RKUSB_LOW_FORMAT:
1007 	case RKUSB_SET_RESET_FLAG:
1008 	case RKUSB_SPI_READ_10:
1009 	case RKUSB_SPI_WRITE_10:
1010 	case RKUSB_SESSION:
1011 		/* Fall through */
1012 	default:
1013 		rc = RKUSB_RC_UNKNOWN_CMND;
1014 		break;
1015 	}
1016 
1017 	return rc;
1018 }
1019 
1020 int rkusb_do_check_parity(struct fsg_common *common)
1021 {
1022 	int ret = 0, rc;
1023 	u32 parity, i, usb_parity, lba, len;
1024 	static u32 usb_check_buffer[1024 * 256];
1025 
1026 	usb_parity = common->cmnd[9] | (common->cmnd[10] << 8) |
1027 			(common->cmnd[11] << 16) | (common->cmnd[12] << 24);
1028 
1029 	if (common->cmnd[0] == SC_WRITE_10 && (usb_parity)) {
1030 		lba = get_unaligned_be32(&common->cmnd[2]);
1031 		len = common->data_size_from_cmnd >> 9;
1032 		rc = blk_dread(&ums[common->lun].block_dev, lba, len, usb_check_buffer);
1033 		parity = 0x000055aa;
1034 		for (i = 0; i < len * 128; i++)
1035 			parity += usb_check_buffer[i];
1036 		if (!rc || parity != usb_parity)
1037 			common->phase_error = 1;
1038 	}
1039 
1040 	return ret;
1041 }
1042 
1043 DECLARE_GADGET_BIND_CALLBACK(rkusb_ums_dnl, fsg_add);
1044