cec-pin-error-inj.rst 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329
  1. .. SPDX-License-Identifier: GFDL-1.1-no-invariants-or-later
  2. .. _cec_pin_error_inj:
  3. CEC Pin Framework Error Injection
  4. =================================
  5. The CEC Pin Framework is a core CEC framework for CEC hardware that only
  6. has low-level support for the CEC bus. Most hardware today will have
  7. high-level CEC support where the hardware deals with driving the CEC bus,
  8. but some older devices aren't that fancy. However, this framework also
  9. allows you to connect the CEC pin to a GPIO on e.g. a Raspberry Pi and
  10. you have now made a CEC adapter.
  11. What makes doing this so interesting is that since we have full control
  12. over the bus it is easy to support error injection. This is ideal to
  13. test how well CEC adapters can handle error conditions.
  14. Currently only the cec-gpio driver (when the CEC line is directly
  15. connected to a pull-up GPIO line) and the AllWinner A10/A20 drm driver
  16. support this framework.
  17. If ``CONFIG_CEC_PIN_ERROR_INJ`` is enabled, then error injection is available
  18. through debugfs. Specifically, in ``/sys/kernel/debug/cec/cecX/`` there is
  19. now an ``error-inj`` file.
  20. .. note::
  21. The error injection commands are not a stable ABI and may change in the
  22. future.
  23. With ``cat error-inj`` you can see both the possible commands and the current
  24. error injection status::
  25. $ cat /sys/kernel/debug/cec/cec0/error-inj
  26. # Clear error injections:
  27. # clear clear all rx and tx error injections
  28. # rx-clear clear all rx error injections
  29. # tx-clear clear all tx error injections
  30. # <op> clear clear all rx and tx error injections for <op>
  31. # <op> rx-clear clear all rx error injections for <op>
  32. # <op> tx-clear clear all tx error injections for <op>
  33. #
  34. # RX error injection:
  35. # <op>[,<mode>] rx-nack NACK the message instead of sending an ACK
  36. # <op>[,<mode>] rx-low-drive <bit> force a low-drive condition at this bit position
  37. # <op>[,<mode>] rx-add-byte add a spurious byte to the received CEC message
  38. # <op>[,<mode>] rx-remove-byte remove the last byte from the received CEC message
  39. # any[,<mode>] rx-arb-lost [<poll>] generate a POLL message to trigger an arbitration lost
  40. #
  41. # TX error injection settings:
  42. # tx-ignore-nack-until-eom ignore early NACKs until EOM
  43. # tx-custom-low-usecs <usecs> define the 'low' time for the custom pulse
  44. # tx-custom-high-usecs <usecs> define the 'high' time for the custom pulse
  45. # tx-custom-pulse transmit the custom pulse once the bus is idle
  46. #
  47. # TX error injection:
  48. # <op>[,<mode>] tx-no-eom don't set the EOM bit
  49. # <op>[,<mode>] tx-early-eom set the EOM bit one byte too soon
  50. # <op>[,<mode>] tx-add-bytes <num> append <num> (1-255) spurious bytes to the message
  51. # <op>[,<mode>] tx-remove-byte drop the last byte from the message
  52. # <op>[,<mode>] tx-short-bit <bit> make this bit shorter than allowed
  53. # <op>[,<mode>] tx-long-bit <bit> make this bit longer than allowed
  54. # <op>[,<mode>] tx-custom-bit <bit> send the custom pulse instead of this bit
  55. # <op>[,<mode>] tx-short-start send a start pulse that's too short
  56. # <op>[,<mode>] tx-long-start send a start pulse that's too long
  57. # <op>[,<mode>] tx-custom-start send the custom pulse instead of the start pulse
  58. # <op>[,<mode>] tx-last-bit <bit> stop sending after this bit
  59. # <op>[,<mode>] tx-low-drive <bit> force a low-drive condition at this bit position
  60. #
  61. # <op> CEC message opcode (0-255) or 'any'
  62. # <mode> 'once' (default), 'always', 'toggle' or 'off'
  63. # <bit> CEC message bit (0-159)
  64. # 10 bits per 'byte': bits 0-7: data, bit 8: EOM, bit 9: ACK
  65. # <poll> CEC poll message used to test arbitration lost (0x00-0xff, default 0x0f)
  66. # <usecs> microseconds (0-10000000, default 1000)
  67. clear
  68. You can write error injection commands to ``error-inj`` using
  69. ``echo 'cmd' >error-inj`` or ``cat cmd.txt >error-inj``. The ``cat error-inj``
  70. output contains the current error commands. You can save the output to a file
  71. and use it as an input to ``error-inj`` later.
  72. Basic Syntax
  73. ------------
  74. Leading spaces/tabs are ignored. If the next character is a ``#`` or the end
  75. of the line was reached, then the whole line is ignored. Otherwise a command
  76. is expected.
  77. The error injection commands fall in two main groups: those relating to
  78. receiving CEC messages and those relating to transmitting CEC messages. In
  79. addition, there are commands to clear existing error injection commands and
  80. to create custom pulses on the CEC bus.
  81. Most error injection commands can be executed for specific CEC opcodes or for
  82. all opcodes (``any``). Each command also has a 'mode' which can be ``off``
  83. (can be used to turn off an existing error injection command), ``once``
  84. (the default) which will trigger the error injection only once for the next
  85. received or transmitted message, ``always`` to always trigger the error
  86. injection and ``toggle`` to toggle the error injection on or off for every
  87. transmit or receive.
  88. So '``any rx-nack``' will NACK the next received CEC message,
  89. '``any,always rx-nack``' will NACK all received CEC messages and
  90. '``0x82,toggle rx-nack``' will only NACK if an Active Source message was
  91. received and do that only for every other received message.
  92. After an error was injected with mode ``once`` the error injection command
  93. is cleared automatically, so ``once`` is a one-time deal.
  94. All combinations of ``<op>`` and error injection commands can co-exist. So
  95. this is fine::
  96. 0x9e tx-add-bytes 1
  97. 0x9e tx-early-eom
  98. 0x9f tx-add-bytes 2
  99. any rx-nack
  100. All four error injection commands will be active simultaneously.
  101. However, if the same ``<op>`` and command combination is specified,
  102. but with different arguments::
  103. 0x9e tx-add-bytes 1
  104. 0x9e tx-add-bytes 2
  105. Then the second will overwrite the first.
  106. Clear Error Injections
  107. ----------------------
  108. ``clear``
  109. Clear all error injections.
  110. ``rx-clear``
  111. Clear all receive error injections
  112. ``tx-clear``
  113. Clear all transmit error injections
  114. ``<op> clear``
  115. Clear all error injections for the given opcode.
  116. ``<op> rx-clear``
  117. Clear all receive error injections for the given opcode.
  118. ``<op> tx-clear``
  119. Clear all transmit error injections for the given opcode.
  120. Receive Messages
  121. ----------------
  122. ``<op>[,<mode>] rx-nack``
  123. NACK broadcast messages and messages directed to this CEC adapter.
  124. Every byte of the message will be NACKed in case the transmitter
  125. keeps transmitting after the first byte was NACKed.
  126. ``<op>[,<mode>] rx-low-drive <bit>``
  127. Force a Low Drive condition at this bit position. If <op> specifies
  128. a specific CEC opcode then the bit position must be at least 18,
  129. otherwise the opcode hasn't been received yet. This tests if the
  130. transmitter can handle the Low Drive condition correctly and reports
  131. the error correctly. Note that a Low Drive in the first 4 bits can also
  132. be interpreted as an Arbitration Lost condition by the transmitter.
  133. This is implementation dependent.
  134. ``<op>[,<mode>] rx-add-byte``
  135. Add a spurious 0x55 byte to the received CEC message, provided
  136. the message was 15 bytes long or less. This is useful to test
  137. the high-level protocol since spurious bytes should be ignored.
  138. ``<op>[,<mode>] rx-remove-byte``
  139. Remove the last byte from the received CEC message, provided it
  140. was at least 2 bytes long. This is useful to test the high-level
  141. protocol since messages that are too short should be ignored.
  142. ``<op>[,<mode>] rx-arb-lost <poll>``
  143. Generate a POLL message to trigger an Arbitration Lost condition.
  144. This command is only allowed for ``<op>`` values of ``next`` or ``all``.
  145. As soon as a start bit has been received the CEC adapter will switch
  146. to transmit mode and it will transmit a POLL message. By default this is
  147. 0x0f, but it can also be specified explicitly via the ``<poll>`` argument.
  148. This command can be used to test the Arbitration Lost condition in
  149. the remote CEC transmitter. Arbitration happens when two CEC adapters
  150. start sending a message at the same time. In that case the initiator
  151. with the most leading zeroes wins and the other transmitter has to
  152. stop transmitting ('Arbitration Lost'). This is very hard to test,
  153. except by using this error injection command.
  154. This does not work if the remote CEC transmitter has logical address
  155. 0 ('TV') since that will always win.
  156. Transmit Messages
  157. -----------------
  158. ``tx-ignore-nack-until-eom``
  159. This setting changes the behavior of transmitting CEC messages. Normally
  160. as soon as the receiver NACKs a byte the transmit will stop, but the
  161. specification also allows that the full message is transmitted and only
  162. at the end will the transmitter look at the ACK bit. This is not
  163. recommended behavior since there is no point in keeping the CEC bus busy
  164. for longer than is strictly needed. Especially given how slow the bus is.
  165. This setting can be used to test how well a receiver deals with
  166. transmitters that ignore NACKs until the very end of the message.
  167. ``<op>[,<mode>] tx-no-eom``
  168. Don't set the EOM bit. Normally the last byte of the message has the EOM
  169. (End-Of-Message) bit set. With this command the transmit will just stop
  170. without ever sending an EOM. This can be used to test how a receiver
  171. handles this case. Normally receivers have a time-out after which
  172. they will go back to the Idle state.
  173. ``<op>[,<mode>] tx-early-eom``
  174. Set the EOM bit one byte too soon. This obviously only works for messages
  175. of two bytes or more. The EOM bit will be set for the second-to-last byte
  176. and not for the final byte. The receiver should ignore the last byte in
  177. this case. Since the resulting message is likely to be too short for this
  178. same reason the whole message is typically ignored. The receiver should be
  179. in Idle state after the last byte was transmitted.
  180. ``<op>[,<mode>] tx-add-bytes <num>``
  181. Append ``<num>`` (1-255) spurious bytes to the message. The extra bytes
  182. have the value of the byte position in the message. So if you transmit a
  183. two byte message (e.g. a Get CEC Version message) and add 2 bytes, then
  184. the full message received by the remote CEC adapter is
  185. ``0x40 0x9f 0x02 0x03``.
  186. This command can be used to test buffer overflows in the receiver. E.g.
  187. what does it do when it receives more than the maximum message size of 16
  188. bytes.
  189. ``<op>[,<mode>] tx-remove-byte``
  190. Drop the last byte from the message, provided the message is at least
  191. two bytes long. The receiver should ignore messages that are too short.
  192. ``<op>[,<mode>] tx-short-bit <bit>``
  193. Make this bit period shorter than allowed. The bit position cannot be
  194. an Ack bit. If <op> specifies a specific CEC opcode then the bit position
  195. must be at least 18, otherwise the opcode hasn't been received yet.
  196. Normally the period of a data bit is between 2.05 and 2.75 milliseconds.
  197. With this command the period of this bit is 1.8 milliseconds, this is
  198. done by reducing the time the CEC bus is high. This bit period is less
  199. than is allowed and the receiver should respond with a Low Drive
  200. condition.
  201. This command is ignored for 0 bits in bit positions 0 to 3. This is
  202. because the receiver also looks for an Arbitration Lost condition in
  203. those first four bits and it is undefined what will happen if it
  204. sees a too-short 0 bit.
  205. ``<op>[,<mode>] tx-long-bit <bit>``
  206. Make this bit period longer than is valid. The bit position cannot be
  207. an Ack bit. If <op> specifies a specific CEC opcode then the bit position
  208. must be at least 18, otherwise the opcode hasn't been received yet.
  209. Normally the period of a data bit is between 2.05 and 2.75 milliseconds.
  210. With this command the period of this bit is 2.9 milliseconds, this is
  211. done by increasing the time the CEC bus is high.
  212. Even though this bit period is longer than is valid it is undefined what
  213. a receiver will do. It might just accept it, or it might time out and
  214. return to Idle state. Unfortunately the CEC specification is silent about
  215. this.
  216. This command is ignored for 0 bits in bit positions 0 to 3. This is
  217. because the receiver also looks for an Arbitration Lost condition in
  218. those first four bits and it is undefined what will happen if it
  219. sees a too-long 0 bit.
  220. ``<op>[,<mode>] tx-short-start``
  221. Make this start bit period shorter than allowed. Normally the period of
  222. a start bit is between 4.3 and 4.7 milliseconds. With this command the
  223. period of the start bit is 4.1 milliseconds, this is done by reducing
  224. the time the CEC bus is high. This start bit period is less than is
  225. allowed and the receiver should return to Idle state when this is detected.
  226. ``<op>[,<mode>] tx-long-start``
  227. Make this start bit period longer than is valid. Normally the period of
  228. a start bit is between 4.3 and 4.7 milliseconds. With this command the
  229. period of the start bit is 5 milliseconds, this is done by increasing
  230. the time the CEC bus is high. This start bit period is more than is
  231. valid and the receiver should return to Idle state when this is detected.
  232. Even though this start bit period is longer than is valid it is undefined
  233. what a receiver will do. It might just accept it, or it might time out and
  234. return to Idle state. Unfortunately the CEC specification is silent about
  235. this.
  236. ``<op>[,<mode>] tx-last-bit <bit>``
  237. Just stop transmitting after this bit. If <op> specifies a specific CEC
  238. opcode then the bit position must be at least 18, otherwise the opcode
  239. hasn't been received yet. This command can be used to test how the receiver
  240. reacts when a message just suddenly stops. It should time out and go back
  241. to Idle state.
  242. ``<op>[,<mode>] tx-low-drive <bit>``
  243. Force a Low Drive condition at this bit position. If <op> specifies a
  244. specific CEC opcode then the bit position must be at least 18, otherwise
  245. the opcode hasn't been received yet. This can be used to test how the
  246. receiver handles Low Drive conditions. Note that if this happens at bit
  247. positions 0-3 the receiver can interpret this as an Arbitration Lost
  248. condition. This is implementation dependent.
  249. Custom Pulses
  250. -------------
  251. ``tx-custom-low-usecs <usecs>``
  252. This defines the duration in microseconds that the custom pulse pulls
  253. the CEC line low. The default is 1000 microseconds.
  254. ``tx-custom-high-usecs <usecs>``
  255. This defines the duration in microseconds that the custom pulse keeps the
  256. CEC line high (unless another CEC adapter pulls it low in that time).
  257. The default is 1000 microseconds. The total period of the custom pulse is
  258. ``tx-custom-low-usecs + tx-custom-high-usecs``.
  259. ``<op>[,<mode>] tx-custom-bit <bit>``
  260. Send the custom bit instead of a regular data bit. The bit position cannot
  261. be an Ack bit. If <op> specifies a specific CEC opcode then the bit
  262. position must be at least 18, otherwise the opcode hasn't been received yet.
  263. ``<op>[,<mode>] tx-custom-start``
  264. Send the custom bit instead of a regular start bit.
  265. ``tx-custom-pulse``
  266. Transmit a single custom pulse as soon as the CEC bus is idle.