core-cdev.c 49 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921
  1. // SPDX-License-Identifier: GPL-2.0-or-later
  2. /*
  3. * Char device for device raw access
  4. *
  5. * Copyright (C) 2005-2007 Kristian Hoegsberg <krh@bitplanet.net>
  6. */
  7. #include <linux/bug.h>
  8. #include <linux/compat.h>
  9. #include <linux/delay.h>
  10. #include <linux/device.h>
  11. #include <linux/dma-mapping.h>
  12. #include <linux/err.h>
  13. #include <linux/errno.h>
  14. #include <linux/firewire.h>
  15. #include <linux/firewire-cdev.h>
  16. #include <linux/irqflags.h>
  17. #include <linux/jiffies.h>
  18. #include <linux/kernel.h>
  19. #include <linux/kref.h>
  20. #include <linux/mm.h>
  21. #include <linux/module.h>
  22. #include <linux/mutex.h>
  23. #include <linux/poll.h>
  24. #include <linux/sched.h> /* required for linux/wait.h */
  25. #include <linux/slab.h>
  26. #include <linux/spinlock.h>
  27. #include <linux/string.h>
  28. #include <linux/time.h>
  29. #include <linux/uaccess.h>
  30. #include <linux/vmalloc.h>
  31. #include <linux/wait.h>
  32. #include <linux/workqueue.h>
  33. #include "core.h"
  34. #include <trace/events/firewire.h>
  35. #include "packet-header-definitions.h"
  36. /*
  37. * ABI version history is documented in linux/firewire-cdev.h.
  38. */
  39. #define FW_CDEV_KERNEL_VERSION 6
  40. #define FW_CDEV_VERSION_EVENT_REQUEST2 4
  41. #define FW_CDEV_VERSION_ALLOCATE_REGION_END 4
  42. #define FW_CDEV_VERSION_AUTO_FLUSH_ISO_OVERFLOW 5
  43. #define FW_CDEV_VERSION_EVENT_ASYNC_TSTAMP 6
  44. struct client {
  45. u32 version;
  46. struct fw_device *device;
  47. spinlock_t lock;
  48. bool in_shutdown;
  49. struct xarray resource_xa;
  50. struct list_head event_list;
  51. wait_queue_head_t wait;
  52. wait_queue_head_t tx_flush_wait;
  53. u64 bus_reset_closure;
  54. struct fw_iso_context *iso_context;
  55. u64 iso_closure;
  56. struct fw_iso_buffer buffer;
  57. unsigned long vm_start;
  58. bool buffer_is_mapped;
  59. struct list_head phy_receiver_link;
  60. u64 phy_receiver_closure;
  61. struct list_head link;
  62. struct kref kref;
  63. };
  64. static inline void client_get(struct client *client)
  65. {
  66. kref_get(&client->kref);
  67. }
  68. static void client_release(struct kref *kref)
  69. {
  70. struct client *client = container_of(kref, struct client, kref);
  71. fw_device_put(client->device);
  72. kfree(client);
  73. }
  74. static void client_put(struct client *client)
  75. {
  76. kref_put(&client->kref, client_release);
  77. }
  78. struct client_resource;
  79. typedef void (*client_resource_release_fn_t)(struct client *,
  80. struct client_resource *);
  81. struct client_resource {
  82. client_resource_release_fn_t release;
  83. int handle;
  84. };
  85. struct address_handler_resource {
  86. struct client_resource resource;
  87. struct fw_address_handler handler;
  88. __u64 closure;
  89. struct client *client;
  90. };
  91. struct outbound_transaction_resource {
  92. struct client_resource resource;
  93. struct fw_transaction transaction;
  94. };
  95. struct inbound_transaction_resource {
  96. struct client_resource resource;
  97. struct fw_card *card;
  98. struct fw_request *request;
  99. bool is_fcp;
  100. void *data;
  101. size_t length;
  102. };
  103. struct descriptor_resource {
  104. struct client_resource resource;
  105. struct fw_descriptor descriptor;
  106. u32 data[];
  107. };
  108. struct iso_resource {
  109. struct client_resource resource;
  110. struct client *client;
  111. /* Schedule work and access todo only with client->lock held. */
  112. struct delayed_work work;
  113. enum {ISO_RES_ALLOC, ISO_RES_REALLOC, ISO_RES_DEALLOC,
  114. ISO_RES_ALLOC_ONCE, ISO_RES_DEALLOC_ONCE,} todo;
  115. int generation;
  116. u64 channels;
  117. s32 bandwidth;
  118. struct iso_resource_event *e_alloc, *e_dealloc;
  119. };
  120. static struct address_handler_resource *to_address_handler_resource(struct client_resource *resource)
  121. {
  122. return container_of(resource, struct address_handler_resource, resource);
  123. }
  124. static struct inbound_transaction_resource *to_inbound_transaction_resource(struct client_resource *resource)
  125. {
  126. return container_of(resource, struct inbound_transaction_resource, resource);
  127. }
  128. static struct descriptor_resource *to_descriptor_resource(struct client_resource *resource)
  129. {
  130. return container_of(resource, struct descriptor_resource, resource);
  131. }
  132. static struct iso_resource *to_iso_resource(struct client_resource *resource)
  133. {
  134. return container_of(resource, struct iso_resource, resource);
  135. }
  136. static void release_iso_resource(struct client *, struct client_resource *);
  137. static int is_iso_resource(const struct client_resource *resource)
  138. {
  139. return resource->release == release_iso_resource;
  140. }
  141. static void release_transaction(struct client *client,
  142. struct client_resource *resource);
  143. static int is_outbound_transaction_resource(const struct client_resource *resource)
  144. {
  145. return resource->release == release_transaction;
  146. }
  147. static void schedule_iso_resource(struct iso_resource *r, unsigned long delay)
  148. {
  149. client_get(r->client);
  150. if (!queue_delayed_work(fw_workqueue, &r->work, delay))
  151. client_put(r->client);
  152. }
  153. /*
  154. * dequeue_event() just kfree()'s the event, so the event has to be
  155. * the first field in a struct XYZ_event.
  156. */
  157. struct event {
  158. struct { void *data; size_t size; } v[2];
  159. struct list_head link;
  160. };
  161. struct bus_reset_event {
  162. struct event event;
  163. struct fw_cdev_event_bus_reset reset;
  164. };
  165. struct outbound_transaction_event {
  166. struct event event;
  167. struct client *client;
  168. struct outbound_transaction_resource r;
  169. union {
  170. struct fw_cdev_event_response without_tstamp;
  171. struct fw_cdev_event_response2 with_tstamp;
  172. } rsp;
  173. };
  174. struct inbound_transaction_event {
  175. struct event event;
  176. union {
  177. struct fw_cdev_event_request request;
  178. struct fw_cdev_event_request2 request2;
  179. struct fw_cdev_event_request3 with_tstamp;
  180. } req;
  181. };
  182. struct iso_interrupt_event {
  183. struct event event;
  184. struct fw_cdev_event_iso_interrupt interrupt;
  185. };
  186. struct iso_interrupt_mc_event {
  187. struct event event;
  188. struct fw_cdev_event_iso_interrupt_mc interrupt;
  189. };
  190. struct iso_resource_event {
  191. struct event event;
  192. struct fw_cdev_event_iso_resource iso_resource;
  193. };
  194. struct outbound_phy_packet_event {
  195. struct event event;
  196. struct client *client;
  197. struct fw_packet p;
  198. union {
  199. struct fw_cdev_event_phy_packet without_tstamp;
  200. struct fw_cdev_event_phy_packet2 with_tstamp;
  201. } phy_packet;
  202. };
  203. struct inbound_phy_packet_event {
  204. struct event event;
  205. union {
  206. struct fw_cdev_event_phy_packet without_tstamp;
  207. struct fw_cdev_event_phy_packet2 with_tstamp;
  208. } phy_packet;
  209. };
  210. #ifdef CONFIG_COMPAT
  211. static void __user *u64_to_uptr(u64 value)
  212. {
  213. if (in_compat_syscall())
  214. return compat_ptr(value);
  215. else
  216. return (void __user *)(unsigned long)value;
  217. }
  218. static u64 uptr_to_u64(void __user *ptr)
  219. {
  220. if (in_compat_syscall())
  221. return ptr_to_compat(ptr);
  222. else
  223. return (u64)(unsigned long)ptr;
  224. }
  225. #else
  226. static inline void __user *u64_to_uptr(u64 value)
  227. {
  228. return (void __user *)(unsigned long)value;
  229. }
  230. static inline u64 uptr_to_u64(void __user *ptr)
  231. {
  232. return (u64)(unsigned long)ptr;
  233. }
  234. #endif /* CONFIG_COMPAT */
  235. static int fw_device_op_open(struct inode *inode, struct file *file)
  236. {
  237. struct fw_device *device;
  238. struct client *client;
  239. device = fw_device_get_by_devt(inode->i_rdev);
  240. if (device == NULL)
  241. return -ENODEV;
  242. if (fw_device_is_shutdown(device)) {
  243. fw_device_put(device);
  244. return -ENODEV;
  245. }
  246. client = kzalloc(sizeof(*client), GFP_KERNEL);
  247. if (client == NULL) {
  248. fw_device_put(device);
  249. return -ENOMEM;
  250. }
  251. client->device = device;
  252. spin_lock_init(&client->lock);
  253. xa_init_flags(&client->resource_xa, XA_FLAGS_ALLOC1 | XA_FLAGS_LOCK_BH);
  254. INIT_LIST_HEAD(&client->event_list);
  255. init_waitqueue_head(&client->wait);
  256. init_waitqueue_head(&client->tx_flush_wait);
  257. INIT_LIST_HEAD(&client->phy_receiver_link);
  258. INIT_LIST_HEAD(&client->link);
  259. kref_init(&client->kref);
  260. file->private_data = client;
  261. return nonseekable_open(inode, file);
  262. }
  263. static void queue_event(struct client *client, struct event *event,
  264. void *data0, size_t size0, void *data1, size_t size1)
  265. {
  266. event->v[0].data = data0;
  267. event->v[0].size = size0;
  268. event->v[1].data = data1;
  269. event->v[1].size = size1;
  270. scoped_guard(spinlock_irqsave, &client->lock) {
  271. if (client->in_shutdown)
  272. kfree(event);
  273. else
  274. list_add_tail(&event->link, &client->event_list);
  275. }
  276. wake_up_interruptible(&client->wait);
  277. }
  278. static int dequeue_event(struct client *client,
  279. char __user *buffer, size_t count)
  280. {
  281. struct event *event;
  282. size_t size, total;
  283. int i, ret;
  284. ret = wait_event_interruptible(client->wait,
  285. !list_empty(&client->event_list) ||
  286. fw_device_is_shutdown(client->device));
  287. if (ret < 0)
  288. return ret;
  289. if (list_empty(&client->event_list) &&
  290. fw_device_is_shutdown(client->device))
  291. return -ENODEV;
  292. scoped_guard(spinlock_irq, &client->lock) {
  293. event = list_first_entry(&client->event_list, struct event, link);
  294. list_del(&event->link);
  295. }
  296. total = 0;
  297. for (i = 0; i < ARRAY_SIZE(event->v) && total < count; i++) {
  298. size = min(event->v[i].size, count - total);
  299. if (copy_to_user(buffer + total, event->v[i].data, size)) {
  300. ret = -EFAULT;
  301. goto out;
  302. }
  303. total += size;
  304. }
  305. ret = total;
  306. out:
  307. kfree(event);
  308. return ret;
  309. }
  310. static ssize_t fw_device_op_read(struct file *file, char __user *buffer,
  311. size_t count, loff_t *offset)
  312. {
  313. struct client *client = file->private_data;
  314. return dequeue_event(client, buffer, count);
  315. }
  316. static void fill_bus_reset_event(struct fw_cdev_event_bus_reset *event,
  317. struct client *client)
  318. {
  319. struct fw_card *card = client->device->card;
  320. guard(spinlock_irq)(&card->lock);
  321. event->closure = client->bus_reset_closure;
  322. event->type = FW_CDEV_EVENT_BUS_RESET;
  323. event->generation = client->device->generation;
  324. event->node_id = client->device->node_id;
  325. event->local_node_id = card->local_node->node_id;
  326. event->bm_node_id = card->bm_node_id;
  327. event->irm_node_id = card->irm_node->node_id;
  328. event->root_node_id = card->root_node->node_id;
  329. }
  330. static void for_each_client(struct fw_device *device,
  331. void (*callback)(struct client *client))
  332. {
  333. struct client *c;
  334. guard(mutex)(&device->client_list_mutex);
  335. list_for_each_entry(c, &device->client_list, link)
  336. callback(c);
  337. }
  338. static void queue_bus_reset_event(struct client *client)
  339. {
  340. struct bus_reset_event *e;
  341. struct client_resource *resource;
  342. unsigned long index;
  343. e = kzalloc(sizeof(*e), GFP_KERNEL);
  344. if (e == NULL)
  345. return;
  346. fill_bus_reset_event(&e->reset, client);
  347. queue_event(client, &e->event,
  348. &e->reset, sizeof(e->reset), NULL, 0);
  349. guard(spinlock_irq)(&client->lock);
  350. xa_for_each(&client->resource_xa, index, resource) {
  351. if (is_iso_resource(resource))
  352. schedule_iso_resource(to_iso_resource(resource), 0);
  353. }
  354. }
  355. void fw_device_cdev_update(struct fw_device *device)
  356. {
  357. for_each_client(device, queue_bus_reset_event);
  358. }
  359. static void wake_up_client(struct client *client)
  360. {
  361. wake_up_interruptible(&client->wait);
  362. }
  363. void fw_device_cdev_remove(struct fw_device *device)
  364. {
  365. for_each_client(device, wake_up_client);
  366. }
  367. union ioctl_arg {
  368. struct fw_cdev_get_info get_info;
  369. struct fw_cdev_send_request send_request;
  370. struct fw_cdev_allocate allocate;
  371. struct fw_cdev_deallocate deallocate;
  372. struct fw_cdev_send_response send_response;
  373. struct fw_cdev_initiate_bus_reset initiate_bus_reset;
  374. struct fw_cdev_add_descriptor add_descriptor;
  375. struct fw_cdev_remove_descriptor remove_descriptor;
  376. struct fw_cdev_create_iso_context create_iso_context;
  377. struct fw_cdev_queue_iso queue_iso;
  378. struct fw_cdev_start_iso start_iso;
  379. struct fw_cdev_stop_iso stop_iso;
  380. struct fw_cdev_get_cycle_timer get_cycle_timer;
  381. struct fw_cdev_allocate_iso_resource allocate_iso_resource;
  382. struct fw_cdev_send_stream_packet send_stream_packet;
  383. struct fw_cdev_get_cycle_timer2 get_cycle_timer2;
  384. struct fw_cdev_send_phy_packet send_phy_packet;
  385. struct fw_cdev_receive_phy_packets receive_phy_packets;
  386. struct fw_cdev_set_iso_channels set_iso_channels;
  387. struct fw_cdev_flush_iso flush_iso;
  388. };
  389. static int ioctl_get_info(struct client *client, union ioctl_arg *arg)
  390. {
  391. struct fw_cdev_get_info *a = &arg->get_info;
  392. struct fw_cdev_event_bus_reset bus_reset;
  393. unsigned long ret = 0;
  394. client->version = a->version;
  395. a->version = FW_CDEV_KERNEL_VERSION;
  396. a->card = client->device->card->index;
  397. scoped_guard(rwsem_read, &fw_device_rwsem) {
  398. if (a->rom != 0) {
  399. size_t want = a->rom_length;
  400. size_t have = client->device->config_rom_length * 4;
  401. ret = copy_to_user(u64_to_uptr(a->rom), client->device->config_rom,
  402. min(want, have));
  403. if (ret != 0)
  404. return -EFAULT;
  405. }
  406. a->rom_length = client->device->config_rom_length * 4;
  407. }
  408. guard(mutex)(&client->device->client_list_mutex);
  409. client->bus_reset_closure = a->bus_reset_closure;
  410. if (a->bus_reset != 0) {
  411. fill_bus_reset_event(&bus_reset, client);
  412. /* unaligned size of bus_reset is 36 bytes */
  413. ret = copy_to_user(u64_to_uptr(a->bus_reset), &bus_reset, 36);
  414. }
  415. if (ret == 0 && list_empty(&client->link))
  416. list_add_tail(&client->link, &client->device->client_list);
  417. return ret ? -EFAULT : 0;
  418. }
  419. static int add_client_resource(struct client *client, struct client_resource *resource,
  420. gfp_t gfp_mask)
  421. {
  422. int ret;
  423. scoped_guard(spinlock_irqsave, &client->lock) {
  424. u32 index;
  425. if (client->in_shutdown) {
  426. ret = -ECANCELED;
  427. } else {
  428. if (gfpflags_allow_blocking(gfp_mask)) {
  429. ret = xa_alloc(&client->resource_xa, &index, resource, xa_limit_32b,
  430. GFP_NOWAIT);
  431. } else {
  432. ret = xa_alloc_bh(&client->resource_xa, &index, resource,
  433. xa_limit_32b, GFP_NOWAIT);
  434. }
  435. }
  436. if (ret >= 0) {
  437. resource->handle = index;
  438. client_get(client);
  439. if (is_iso_resource(resource))
  440. schedule_iso_resource(to_iso_resource(resource), 0);
  441. }
  442. }
  443. return ret < 0 ? ret : 0;
  444. }
  445. static int release_client_resource(struct client *client, u32 handle,
  446. client_resource_release_fn_t release,
  447. struct client_resource **return_resource)
  448. {
  449. unsigned long index = handle;
  450. struct client_resource *resource;
  451. scoped_guard(spinlock_irq, &client->lock) {
  452. if (client->in_shutdown)
  453. return -EINVAL;
  454. resource = xa_load(&client->resource_xa, index);
  455. if (!resource || resource->release != release)
  456. return -EINVAL;
  457. xa_erase(&client->resource_xa, handle);
  458. }
  459. if (return_resource)
  460. *return_resource = resource;
  461. else
  462. resource->release(client, resource);
  463. client_put(client);
  464. return 0;
  465. }
  466. static void release_transaction(struct client *client,
  467. struct client_resource *resource)
  468. {
  469. }
  470. static void complete_transaction(struct fw_card *card, int rcode, u32 request_tstamp,
  471. u32 response_tstamp, void *payload, size_t length, void *data)
  472. {
  473. struct outbound_transaction_event *e = data;
  474. struct client *client = e->client;
  475. unsigned long index = e->r.resource.handle;
  476. scoped_guard(spinlock_irqsave, &client->lock) {
  477. xa_erase(&client->resource_xa, index);
  478. if (client->in_shutdown)
  479. wake_up(&client->tx_flush_wait);
  480. }
  481. switch (e->rsp.without_tstamp.type) {
  482. case FW_CDEV_EVENT_RESPONSE:
  483. {
  484. struct fw_cdev_event_response *rsp = &e->rsp.without_tstamp;
  485. if (length < rsp->length)
  486. rsp->length = length;
  487. if (rcode == RCODE_COMPLETE)
  488. memcpy(rsp->data, payload, rsp->length);
  489. rsp->rcode = rcode;
  490. // In the case that sizeof(*rsp) doesn't align with the position of the
  491. // data, and the read is short, preserve an extra copy of the data
  492. // to stay compatible with a pre-2.6.27 bug. Since the bug is harmless
  493. // for short reads and some apps depended on it, this is both safe
  494. // and prudent for compatibility.
  495. if (rsp->length <= sizeof(*rsp) - offsetof(typeof(*rsp), data))
  496. queue_event(client, &e->event, rsp, sizeof(*rsp), rsp->data, rsp->length);
  497. else
  498. queue_event(client, &e->event, rsp, sizeof(*rsp) + rsp->length, NULL, 0);
  499. break;
  500. }
  501. case FW_CDEV_EVENT_RESPONSE2:
  502. {
  503. struct fw_cdev_event_response2 *rsp = &e->rsp.with_tstamp;
  504. if (length < rsp->length)
  505. rsp->length = length;
  506. if (rcode == RCODE_COMPLETE)
  507. memcpy(rsp->data, payload, rsp->length);
  508. rsp->rcode = rcode;
  509. rsp->request_tstamp = request_tstamp;
  510. rsp->response_tstamp = response_tstamp;
  511. queue_event(client, &e->event, rsp, sizeof(*rsp) + rsp->length, NULL, 0);
  512. break;
  513. }
  514. default:
  515. WARN_ON(1);
  516. break;
  517. }
  518. // Drop the xarray's reference.
  519. client_put(client);
  520. }
  521. static int init_request(struct client *client,
  522. struct fw_cdev_send_request *request,
  523. int destination_id, int speed)
  524. {
  525. struct outbound_transaction_event *e;
  526. void *payload;
  527. int ret;
  528. if (request->tcode != TCODE_STREAM_DATA &&
  529. (request->length > 4096 || request->length > 512 << speed))
  530. return -EIO;
  531. if (request->tcode == TCODE_WRITE_QUADLET_REQUEST &&
  532. request->length < 4)
  533. return -EINVAL;
  534. e = kmalloc(sizeof(*e) + request->length, GFP_KERNEL);
  535. if (e == NULL)
  536. return -ENOMEM;
  537. e->client = client;
  538. if (client->version < FW_CDEV_VERSION_EVENT_ASYNC_TSTAMP) {
  539. struct fw_cdev_event_response *rsp = &e->rsp.without_tstamp;
  540. rsp->type = FW_CDEV_EVENT_RESPONSE;
  541. rsp->length = request->length;
  542. rsp->closure = request->closure;
  543. payload = rsp->data;
  544. } else {
  545. struct fw_cdev_event_response2 *rsp = &e->rsp.with_tstamp;
  546. rsp->type = FW_CDEV_EVENT_RESPONSE2;
  547. rsp->length = request->length;
  548. rsp->closure = request->closure;
  549. payload = rsp->data;
  550. }
  551. if (request->data && copy_from_user(payload, u64_to_uptr(request->data), request->length)) {
  552. ret = -EFAULT;
  553. goto failed;
  554. }
  555. e->r.resource.release = release_transaction;
  556. ret = add_client_resource(client, &e->r.resource, GFP_KERNEL);
  557. if (ret < 0)
  558. goto failed;
  559. fw_send_request_with_tstamp(client->device->card, &e->r.transaction, request->tcode,
  560. destination_id, request->generation, speed, request->offset,
  561. payload, request->length, complete_transaction, e);
  562. return 0;
  563. failed:
  564. kfree(e);
  565. return ret;
  566. }
  567. static int ioctl_send_request(struct client *client, union ioctl_arg *arg)
  568. {
  569. switch (arg->send_request.tcode) {
  570. case TCODE_WRITE_QUADLET_REQUEST:
  571. case TCODE_WRITE_BLOCK_REQUEST:
  572. case TCODE_READ_QUADLET_REQUEST:
  573. case TCODE_READ_BLOCK_REQUEST:
  574. case TCODE_LOCK_MASK_SWAP:
  575. case TCODE_LOCK_COMPARE_SWAP:
  576. case TCODE_LOCK_FETCH_ADD:
  577. case TCODE_LOCK_LITTLE_ADD:
  578. case TCODE_LOCK_BOUNDED_ADD:
  579. case TCODE_LOCK_WRAP_ADD:
  580. case TCODE_LOCK_VENDOR_DEPENDENT:
  581. break;
  582. default:
  583. return -EINVAL;
  584. }
  585. return init_request(client, &arg->send_request, client->device->node_id,
  586. client->device->max_speed);
  587. }
  588. static void release_request(struct client *client,
  589. struct client_resource *resource)
  590. {
  591. struct inbound_transaction_resource *r = to_inbound_transaction_resource(resource);
  592. if (r->is_fcp)
  593. fw_request_put(r->request);
  594. else
  595. fw_send_response(r->card, r->request, RCODE_CONFLICT_ERROR);
  596. fw_card_put(r->card);
  597. kfree(r);
  598. }
  599. static void handle_request(struct fw_card *card, struct fw_request *request,
  600. int tcode, int destination, int source,
  601. int generation, unsigned long long offset,
  602. void *payload, size_t length, void *callback_data)
  603. {
  604. struct address_handler_resource *handler = callback_data;
  605. bool is_fcp = is_in_fcp_region(offset, length);
  606. struct inbound_transaction_resource *r;
  607. struct inbound_transaction_event *e;
  608. size_t event_size0;
  609. int ret;
  610. /* card may be different from handler->client->device->card */
  611. fw_card_get(card);
  612. // Extend the lifetime of data for request so that its payload is safely accessible in
  613. // the process context for the client.
  614. if (is_fcp)
  615. fw_request_get(request);
  616. r = kmalloc(sizeof(*r), GFP_ATOMIC);
  617. e = kmalloc(sizeof(*e), GFP_ATOMIC);
  618. if (r == NULL || e == NULL)
  619. goto failed;
  620. r->card = card;
  621. r->request = request;
  622. r->is_fcp = is_fcp;
  623. r->data = payload;
  624. r->length = length;
  625. r->resource.release = release_request;
  626. ret = add_client_resource(handler->client, &r->resource, GFP_ATOMIC);
  627. if (ret < 0)
  628. goto failed;
  629. if (handler->client->version < FW_CDEV_VERSION_EVENT_REQUEST2) {
  630. struct fw_cdev_event_request *req = &e->req.request;
  631. if (tcode & 0x10)
  632. tcode = TCODE_LOCK_REQUEST;
  633. req->type = FW_CDEV_EVENT_REQUEST;
  634. req->tcode = tcode;
  635. req->offset = offset;
  636. req->length = length;
  637. req->handle = r->resource.handle;
  638. req->closure = handler->closure;
  639. event_size0 = sizeof(*req);
  640. } else if (handler->client->version < FW_CDEV_VERSION_EVENT_ASYNC_TSTAMP) {
  641. struct fw_cdev_event_request2 *req = &e->req.request2;
  642. req->type = FW_CDEV_EVENT_REQUEST2;
  643. req->tcode = tcode;
  644. req->offset = offset;
  645. req->source_node_id = source;
  646. req->destination_node_id = destination;
  647. req->card = card->index;
  648. req->generation = generation;
  649. req->length = length;
  650. req->handle = r->resource.handle;
  651. req->closure = handler->closure;
  652. event_size0 = sizeof(*req);
  653. } else {
  654. struct fw_cdev_event_request3 *req = &e->req.with_tstamp;
  655. req->type = FW_CDEV_EVENT_REQUEST3;
  656. req->tcode = tcode;
  657. req->offset = offset;
  658. req->source_node_id = source;
  659. req->destination_node_id = destination;
  660. req->card = card->index;
  661. req->generation = generation;
  662. req->length = length;
  663. req->handle = r->resource.handle;
  664. req->closure = handler->closure;
  665. req->tstamp = fw_request_get_timestamp(request);
  666. event_size0 = sizeof(*req);
  667. }
  668. queue_event(handler->client, &e->event,
  669. &e->req, event_size0, r->data, length);
  670. return;
  671. failed:
  672. kfree(r);
  673. kfree(e);
  674. if (!is_fcp)
  675. fw_send_response(card, request, RCODE_CONFLICT_ERROR);
  676. else
  677. fw_request_put(request);
  678. fw_card_put(card);
  679. }
  680. static void release_address_handler(struct client *client,
  681. struct client_resource *resource)
  682. {
  683. struct address_handler_resource *r = to_address_handler_resource(resource);
  684. fw_core_remove_address_handler(&r->handler);
  685. kfree(r);
  686. }
  687. static int ioctl_allocate(struct client *client, union ioctl_arg *arg)
  688. {
  689. struct fw_cdev_allocate *a = &arg->allocate;
  690. struct address_handler_resource *r;
  691. struct fw_address_region region;
  692. int ret;
  693. r = kmalloc(sizeof(*r), GFP_KERNEL);
  694. if (r == NULL)
  695. return -ENOMEM;
  696. region.start = a->offset;
  697. if (client->version < FW_CDEV_VERSION_ALLOCATE_REGION_END)
  698. region.end = a->offset + a->length;
  699. else
  700. region.end = a->region_end;
  701. r->handler.length = a->length;
  702. r->handler.address_callback = handle_request;
  703. r->handler.callback_data = r;
  704. r->closure = a->closure;
  705. r->client = client;
  706. ret = fw_core_add_address_handler(&r->handler, &region);
  707. if (ret < 0) {
  708. kfree(r);
  709. return ret;
  710. }
  711. a->offset = r->handler.offset;
  712. r->resource.release = release_address_handler;
  713. ret = add_client_resource(client, &r->resource, GFP_KERNEL);
  714. if (ret < 0) {
  715. release_address_handler(client, &r->resource);
  716. return ret;
  717. }
  718. a->handle = r->resource.handle;
  719. return 0;
  720. }
  721. static int ioctl_deallocate(struct client *client, union ioctl_arg *arg)
  722. {
  723. return release_client_resource(client, arg->deallocate.handle,
  724. release_address_handler, NULL);
  725. }
  726. static int ioctl_send_response(struct client *client, union ioctl_arg *arg)
  727. {
  728. struct fw_cdev_send_response *a = &arg->send_response;
  729. struct client_resource *resource;
  730. struct inbound_transaction_resource *r;
  731. int ret = 0;
  732. if (release_client_resource(client, a->handle,
  733. release_request, &resource) < 0)
  734. return -EINVAL;
  735. r = to_inbound_transaction_resource(resource);
  736. if (r->is_fcp) {
  737. fw_request_put(r->request);
  738. goto out;
  739. }
  740. if (a->length != fw_get_response_length(r->request)) {
  741. ret = -EINVAL;
  742. fw_request_put(r->request);
  743. goto out;
  744. }
  745. if (copy_from_user(r->data, u64_to_uptr(a->data), a->length)) {
  746. ret = -EFAULT;
  747. fw_request_put(r->request);
  748. goto out;
  749. }
  750. fw_send_response(r->card, r->request, a->rcode);
  751. out:
  752. fw_card_put(r->card);
  753. kfree(r);
  754. return ret;
  755. }
  756. static int ioctl_initiate_bus_reset(struct client *client, union ioctl_arg *arg)
  757. {
  758. fw_schedule_bus_reset(client->device->card, true,
  759. arg->initiate_bus_reset.type == FW_CDEV_SHORT_RESET);
  760. return 0;
  761. }
  762. static void release_descriptor(struct client *client,
  763. struct client_resource *resource)
  764. {
  765. struct descriptor_resource *r = to_descriptor_resource(resource);
  766. fw_core_remove_descriptor(&r->descriptor);
  767. kfree(r);
  768. }
  769. static int ioctl_add_descriptor(struct client *client, union ioctl_arg *arg)
  770. {
  771. struct fw_cdev_add_descriptor *a = &arg->add_descriptor;
  772. struct descriptor_resource *r;
  773. int ret;
  774. /* Access policy: Allow this ioctl only on local nodes' device files. */
  775. if (!client->device->is_local)
  776. return -ENOSYS;
  777. if (a->length > 256)
  778. return -EINVAL;
  779. r = kmalloc(sizeof(*r) + a->length * 4, GFP_KERNEL);
  780. if (r == NULL)
  781. return -ENOMEM;
  782. if (copy_from_user(r->data, u64_to_uptr(a->data), a->length * 4)) {
  783. ret = -EFAULT;
  784. goto failed;
  785. }
  786. r->descriptor.length = a->length;
  787. r->descriptor.immediate = a->immediate;
  788. r->descriptor.key = a->key;
  789. r->descriptor.data = r->data;
  790. ret = fw_core_add_descriptor(&r->descriptor);
  791. if (ret < 0)
  792. goto failed;
  793. r->resource.release = release_descriptor;
  794. ret = add_client_resource(client, &r->resource, GFP_KERNEL);
  795. if (ret < 0) {
  796. fw_core_remove_descriptor(&r->descriptor);
  797. goto failed;
  798. }
  799. a->handle = r->resource.handle;
  800. return 0;
  801. failed:
  802. kfree(r);
  803. return ret;
  804. }
  805. static int ioctl_remove_descriptor(struct client *client, union ioctl_arg *arg)
  806. {
  807. return release_client_resource(client, arg->remove_descriptor.handle,
  808. release_descriptor, NULL);
  809. }
  810. static void iso_callback(struct fw_iso_context *context, u32 cycle,
  811. size_t header_length, void *header, void *data)
  812. {
  813. struct client *client = data;
  814. struct iso_interrupt_event *e;
  815. e = kmalloc(sizeof(*e) + header_length, GFP_KERNEL);
  816. if (e == NULL)
  817. return;
  818. e->interrupt.type = FW_CDEV_EVENT_ISO_INTERRUPT;
  819. e->interrupt.closure = client->iso_closure;
  820. e->interrupt.cycle = cycle;
  821. e->interrupt.header_length = header_length;
  822. memcpy(e->interrupt.header, header, header_length);
  823. queue_event(client, &e->event, &e->interrupt,
  824. sizeof(e->interrupt) + header_length, NULL, 0);
  825. }
  826. static void iso_mc_callback(struct fw_iso_context *context,
  827. dma_addr_t completed, void *data)
  828. {
  829. struct client *client = data;
  830. struct iso_interrupt_mc_event *e;
  831. e = kmalloc(sizeof(*e), GFP_KERNEL);
  832. if (e == NULL)
  833. return;
  834. e->interrupt.type = FW_CDEV_EVENT_ISO_INTERRUPT_MULTICHANNEL;
  835. e->interrupt.closure = client->iso_closure;
  836. e->interrupt.completed = fw_iso_buffer_lookup(&client->buffer,
  837. completed);
  838. queue_event(client, &e->event, &e->interrupt,
  839. sizeof(e->interrupt), NULL, 0);
  840. }
  841. static enum dma_data_direction iso_dma_direction(struct fw_iso_context *context)
  842. {
  843. if (context->type == FW_ISO_CONTEXT_TRANSMIT)
  844. return DMA_TO_DEVICE;
  845. else
  846. return DMA_FROM_DEVICE;
  847. }
  848. static struct fw_iso_context *fw_iso_mc_context_create(struct fw_card *card,
  849. fw_iso_mc_callback_t callback,
  850. void *callback_data)
  851. {
  852. struct fw_iso_context *ctx;
  853. ctx = fw_iso_context_create(card, FW_ISO_CONTEXT_RECEIVE_MULTICHANNEL,
  854. 0, 0, 0, NULL, callback_data);
  855. if (!IS_ERR(ctx))
  856. ctx->callback.mc = callback;
  857. return ctx;
  858. }
  859. static int ioctl_create_iso_context(struct client *client, union ioctl_arg *arg)
  860. {
  861. struct fw_cdev_create_iso_context *a = &arg->create_iso_context;
  862. struct fw_iso_context *context;
  863. union fw_iso_callback cb;
  864. int ret;
  865. BUILD_BUG_ON(FW_CDEV_ISO_CONTEXT_TRANSMIT != FW_ISO_CONTEXT_TRANSMIT ||
  866. FW_CDEV_ISO_CONTEXT_RECEIVE != FW_ISO_CONTEXT_RECEIVE ||
  867. FW_CDEV_ISO_CONTEXT_RECEIVE_MULTICHANNEL !=
  868. FW_ISO_CONTEXT_RECEIVE_MULTICHANNEL);
  869. switch (a->type) {
  870. case FW_ISO_CONTEXT_TRANSMIT:
  871. if (a->speed > SCODE_3200 || a->channel > 63)
  872. return -EINVAL;
  873. cb.sc = iso_callback;
  874. break;
  875. case FW_ISO_CONTEXT_RECEIVE:
  876. if (a->header_size < 4 || (a->header_size & 3) ||
  877. a->channel > 63)
  878. return -EINVAL;
  879. cb.sc = iso_callback;
  880. break;
  881. case FW_ISO_CONTEXT_RECEIVE_MULTICHANNEL:
  882. cb.mc = iso_mc_callback;
  883. break;
  884. default:
  885. return -EINVAL;
  886. }
  887. if (a->type == FW_ISO_CONTEXT_RECEIVE_MULTICHANNEL)
  888. context = fw_iso_mc_context_create(client->device->card, cb.mc,
  889. client);
  890. else
  891. context = fw_iso_context_create(client->device->card, a->type,
  892. a->channel, a->speed,
  893. a->header_size, cb.sc, client);
  894. if (IS_ERR(context))
  895. return PTR_ERR(context);
  896. if (client->version < FW_CDEV_VERSION_AUTO_FLUSH_ISO_OVERFLOW)
  897. context->drop_overflow_headers = true;
  898. // We only support one context at this time.
  899. guard(spinlock_irq)(&client->lock);
  900. if (client->iso_context != NULL) {
  901. fw_iso_context_destroy(context);
  902. return -EBUSY;
  903. }
  904. if (!client->buffer_is_mapped) {
  905. ret = fw_iso_buffer_map_dma(&client->buffer,
  906. client->device->card,
  907. iso_dma_direction(context));
  908. if (ret < 0) {
  909. fw_iso_context_destroy(context);
  910. return ret;
  911. }
  912. client->buffer_is_mapped = true;
  913. }
  914. client->iso_closure = a->closure;
  915. client->iso_context = context;
  916. a->handle = 0;
  917. return 0;
  918. }
  919. static int ioctl_set_iso_channels(struct client *client, union ioctl_arg *arg)
  920. {
  921. struct fw_cdev_set_iso_channels *a = &arg->set_iso_channels;
  922. struct fw_iso_context *ctx = client->iso_context;
  923. if (ctx == NULL || a->handle != 0)
  924. return -EINVAL;
  925. return fw_iso_context_set_channels(ctx, &a->channels);
  926. }
  927. /* Macros for decoding the iso packet control header. */
  928. #define GET_PAYLOAD_LENGTH(v) ((v) & 0xffff)
  929. #define GET_INTERRUPT(v) (((v) >> 16) & 0x01)
  930. #define GET_SKIP(v) (((v) >> 17) & 0x01)
  931. #define GET_TAG(v) (((v) >> 18) & 0x03)
  932. #define GET_SY(v) (((v) >> 20) & 0x0f)
  933. #define GET_HEADER_LENGTH(v) (((v) >> 24) & 0xff)
  934. static int ioctl_queue_iso(struct client *client, union ioctl_arg *arg)
  935. {
  936. struct fw_cdev_queue_iso *a = &arg->queue_iso;
  937. struct fw_cdev_iso_packet __user *p, *end, *next;
  938. struct fw_iso_context *ctx = client->iso_context;
  939. unsigned long payload, buffer_end, transmit_header_bytes = 0;
  940. u32 control;
  941. int count;
  942. struct {
  943. struct fw_iso_packet packet;
  944. u8 header[256];
  945. } u;
  946. if (ctx == NULL || a->handle != 0)
  947. return -EINVAL;
  948. /*
  949. * If the user passes a non-NULL data pointer, has mmap()'ed
  950. * the iso buffer, and the pointer points inside the buffer,
  951. * we setup the payload pointers accordingly. Otherwise we
  952. * set them both to 0, which will still let packets with
  953. * payload_length == 0 through. In other words, if no packets
  954. * use the indirect payload, the iso buffer need not be mapped
  955. * and the a->data pointer is ignored.
  956. */
  957. payload = (unsigned long)a->data - client->vm_start;
  958. buffer_end = client->buffer.page_count << PAGE_SHIFT;
  959. if (a->data == 0 || client->buffer.pages == NULL ||
  960. payload >= buffer_end) {
  961. payload = 0;
  962. buffer_end = 0;
  963. }
  964. if (ctx->type == FW_ISO_CONTEXT_RECEIVE_MULTICHANNEL && payload & 3)
  965. return -EINVAL;
  966. p = (struct fw_cdev_iso_packet __user *)u64_to_uptr(a->packets);
  967. end = (void __user *)p + a->size;
  968. count = 0;
  969. while (p < end) {
  970. if (get_user(control, &p->control))
  971. return -EFAULT;
  972. u.packet.payload_length = GET_PAYLOAD_LENGTH(control);
  973. u.packet.interrupt = GET_INTERRUPT(control);
  974. u.packet.skip = GET_SKIP(control);
  975. u.packet.tag = GET_TAG(control);
  976. u.packet.sy = GET_SY(control);
  977. u.packet.header_length = GET_HEADER_LENGTH(control);
  978. switch (ctx->type) {
  979. case FW_ISO_CONTEXT_TRANSMIT:
  980. if (u.packet.header_length & 3)
  981. return -EINVAL;
  982. transmit_header_bytes = u.packet.header_length;
  983. break;
  984. case FW_ISO_CONTEXT_RECEIVE:
  985. if (u.packet.header_length == 0 ||
  986. u.packet.header_length % ctx->header_size != 0)
  987. return -EINVAL;
  988. break;
  989. case FW_ISO_CONTEXT_RECEIVE_MULTICHANNEL:
  990. if (u.packet.payload_length == 0 ||
  991. u.packet.payload_length & 3)
  992. return -EINVAL;
  993. break;
  994. }
  995. next = (struct fw_cdev_iso_packet __user *)
  996. &p->header[transmit_header_bytes / 4];
  997. if (next > end)
  998. return -EINVAL;
  999. if (copy_from_user
  1000. (u.packet.header, p->header, transmit_header_bytes))
  1001. return -EFAULT;
  1002. if (u.packet.skip && ctx->type == FW_ISO_CONTEXT_TRANSMIT &&
  1003. u.packet.header_length + u.packet.payload_length > 0)
  1004. return -EINVAL;
  1005. if (payload + u.packet.payload_length > buffer_end)
  1006. return -EINVAL;
  1007. if (fw_iso_context_queue(ctx, &u.packet,
  1008. &client->buffer, payload))
  1009. break;
  1010. p = next;
  1011. payload += u.packet.payload_length;
  1012. count++;
  1013. }
  1014. fw_iso_context_queue_flush(ctx);
  1015. a->size -= uptr_to_u64(p) - a->packets;
  1016. a->packets = uptr_to_u64(p);
  1017. a->data = client->vm_start + payload;
  1018. return count;
  1019. }
  1020. static int ioctl_start_iso(struct client *client, union ioctl_arg *arg)
  1021. {
  1022. struct fw_cdev_start_iso *a = &arg->start_iso;
  1023. BUILD_BUG_ON(
  1024. FW_CDEV_ISO_CONTEXT_MATCH_TAG0 != FW_ISO_CONTEXT_MATCH_TAG0 ||
  1025. FW_CDEV_ISO_CONTEXT_MATCH_TAG1 != FW_ISO_CONTEXT_MATCH_TAG1 ||
  1026. FW_CDEV_ISO_CONTEXT_MATCH_TAG2 != FW_ISO_CONTEXT_MATCH_TAG2 ||
  1027. FW_CDEV_ISO_CONTEXT_MATCH_TAG3 != FW_ISO_CONTEXT_MATCH_TAG3 ||
  1028. FW_CDEV_ISO_CONTEXT_MATCH_ALL_TAGS != FW_ISO_CONTEXT_MATCH_ALL_TAGS);
  1029. if (client->iso_context == NULL || a->handle != 0)
  1030. return -EINVAL;
  1031. if (client->iso_context->type == FW_ISO_CONTEXT_RECEIVE &&
  1032. (a->tags == 0 || a->tags > 15 || a->sync > 15))
  1033. return -EINVAL;
  1034. return fw_iso_context_start(client->iso_context,
  1035. a->cycle, a->sync, a->tags);
  1036. }
  1037. static int ioctl_stop_iso(struct client *client, union ioctl_arg *arg)
  1038. {
  1039. struct fw_cdev_stop_iso *a = &arg->stop_iso;
  1040. if (client->iso_context == NULL || a->handle != 0)
  1041. return -EINVAL;
  1042. return fw_iso_context_stop(client->iso_context);
  1043. }
  1044. static int ioctl_flush_iso(struct client *client, union ioctl_arg *arg)
  1045. {
  1046. struct fw_cdev_flush_iso *a = &arg->flush_iso;
  1047. if (client->iso_context == NULL || a->handle != 0)
  1048. return -EINVAL;
  1049. return fw_iso_context_flush_completions(client->iso_context);
  1050. }
  1051. static int ioctl_get_cycle_timer2(struct client *client, union ioctl_arg *arg)
  1052. {
  1053. struct fw_cdev_get_cycle_timer2 *a = &arg->get_cycle_timer2;
  1054. struct fw_card *card = client->device->card;
  1055. struct timespec64 ts = {0, 0};
  1056. u32 cycle_time = 0;
  1057. int ret;
  1058. guard(irq)();
  1059. ret = fw_card_read_cycle_time(card, &cycle_time);
  1060. if (ret < 0)
  1061. return ret;
  1062. switch (a->clk_id) {
  1063. case CLOCK_REALTIME: ktime_get_real_ts64(&ts); break;
  1064. case CLOCK_MONOTONIC: ktime_get_ts64(&ts); break;
  1065. case CLOCK_MONOTONIC_RAW: ktime_get_raw_ts64(&ts); break;
  1066. default:
  1067. return -EINVAL;
  1068. }
  1069. a->tv_sec = ts.tv_sec;
  1070. a->tv_nsec = ts.tv_nsec;
  1071. a->cycle_timer = cycle_time;
  1072. return 0;
  1073. }
  1074. static int ioctl_get_cycle_timer(struct client *client, union ioctl_arg *arg)
  1075. {
  1076. struct fw_cdev_get_cycle_timer *a = &arg->get_cycle_timer;
  1077. struct fw_cdev_get_cycle_timer2 ct2;
  1078. ct2.clk_id = CLOCK_REALTIME;
  1079. ioctl_get_cycle_timer2(client, (union ioctl_arg *)&ct2);
  1080. a->local_time = ct2.tv_sec * USEC_PER_SEC + ct2.tv_nsec / NSEC_PER_USEC;
  1081. a->cycle_timer = ct2.cycle_timer;
  1082. return 0;
  1083. }
  1084. static void iso_resource_work(struct work_struct *work)
  1085. {
  1086. struct iso_resource_event *e;
  1087. struct iso_resource *r =
  1088. container_of(work, struct iso_resource, work.work);
  1089. struct client *client = r->client;
  1090. unsigned long index = r->resource.handle;
  1091. int generation, channel, bandwidth, todo;
  1092. bool skip, free, success;
  1093. scoped_guard(spinlock_irq, &client->lock) {
  1094. generation = client->device->generation;
  1095. todo = r->todo;
  1096. // Allow 1000ms grace period for other reallocations.
  1097. if (todo == ISO_RES_ALLOC &&
  1098. time_before64(get_jiffies_64(), client->device->card->reset_jiffies + HZ)) {
  1099. schedule_iso_resource(r, DIV_ROUND_UP(HZ, 3));
  1100. skip = true;
  1101. } else {
  1102. // We could be called twice within the same generation.
  1103. skip = todo == ISO_RES_REALLOC &&
  1104. r->generation == generation;
  1105. }
  1106. free = todo == ISO_RES_DEALLOC ||
  1107. todo == ISO_RES_ALLOC_ONCE ||
  1108. todo == ISO_RES_DEALLOC_ONCE;
  1109. r->generation = generation;
  1110. }
  1111. if (skip)
  1112. goto out;
  1113. bandwidth = r->bandwidth;
  1114. fw_iso_resource_manage(client->device->card, generation,
  1115. r->channels, &channel, &bandwidth,
  1116. todo == ISO_RES_ALLOC ||
  1117. todo == ISO_RES_REALLOC ||
  1118. todo == ISO_RES_ALLOC_ONCE);
  1119. /*
  1120. * Is this generation outdated already? As long as this resource sticks
  1121. * in the xarray, it will be scheduled again for a newer generation or at
  1122. * shutdown.
  1123. */
  1124. if (channel == -EAGAIN &&
  1125. (todo == ISO_RES_ALLOC || todo == ISO_RES_REALLOC))
  1126. goto out;
  1127. success = channel >= 0 || bandwidth > 0;
  1128. scoped_guard(spinlock_irq, &client->lock) {
  1129. // Transit from allocation to reallocation, except if the client
  1130. // requested deallocation in the meantime.
  1131. if (r->todo == ISO_RES_ALLOC)
  1132. r->todo = ISO_RES_REALLOC;
  1133. // Allocation or reallocation failure? Pull this resource out of the
  1134. // xarray and prepare for deletion, unless the client is shutting down.
  1135. if (r->todo == ISO_RES_REALLOC && !success &&
  1136. !client->in_shutdown &&
  1137. xa_erase(&client->resource_xa, index)) {
  1138. client_put(client);
  1139. free = true;
  1140. }
  1141. }
  1142. if (todo == ISO_RES_ALLOC && channel >= 0)
  1143. r->channels = 1ULL << channel;
  1144. if (todo == ISO_RES_REALLOC && success)
  1145. goto out;
  1146. if (todo == ISO_RES_ALLOC || todo == ISO_RES_ALLOC_ONCE) {
  1147. e = r->e_alloc;
  1148. r->e_alloc = NULL;
  1149. } else {
  1150. e = r->e_dealloc;
  1151. r->e_dealloc = NULL;
  1152. }
  1153. e->iso_resource.handle = r->resource.handle;
  1154. e->iso_resource.channel = channel;
  1155. e->iso_resource.bandwidth = bandwidth;
  1156. queue_event(client, &e->event,
  1157. &e->iso_resource, sizeof(e->iso_resource), NULL, 0);
  1158. if (free) {
  1159. cancel_delayed_work(&r->work);
  1160. kfree(r->e_alloc);
  1161. kfree(r->e_dealloc);
  1162. kfree(r);
  1163. }
  1164. out:
  1165. client_put(client);
  1166. }
  1167. static void release_iso_resource(struct client *client,
  1168. struct client_resource *resource)
  1169. {
  1170. struct iso_resource *r = to_iso_resource(resource);
  1171. guard(spinlock_irq)(&client->lock);
  1172. r->todo = ISO_RES_DEALLOC;
  1173. schedule_iso_resource(r, 0);
  1174. }
  1175. static int init_iso_resource(struct client *client,
  1176. struct fw_cdev_allocate_iso_resource *request, int todo)
  1177. {
  1178. struct iso_resource_event *e1, *e2;
  1179. struct iso_resource *r;
  1180. int ret;
  1181. if ((request->channels == 0 && request->bandwidth == 0) ||
  1182. request->bandwidth > BANDWIDTH_AVAILABLE_INITIAL)
  1183. return -EINVAL;
  1184. r = kmalloc(sizeof(*r), GFP_KERNEL);
  1185. e1 = kmalloc(sizeof(*e1), GFP_KERNEL);
  1186. e2 = kmalloc(sizeof(*e2), GFP_KERNEL);
  1187. if (r == NULL || e1 == NULL || e2 == NULL) {
  1188. ret = -ENOMEM;
  1189. goto fail;
  1190. }
  1191. INIT_DELAYED_WORK(&r->work, iso_resource_work);
  1192. r->client = client;
  1193. r->todo = todo;
  1194. r->generation = -1;
  1195. r->channels = request->channels;
  1196. r->bandwidth = request->bandwidth;
  1197. r->e_alloc = e1;
  1198. r->e_dealloc = e2;
  1199. e1->iso_resource.closure = request->closure;
  1200. e1->iso_resource.type = FW_CDEV_EVENT_ISO_RESOURCE_ALLOCATED;
  1201. e2->iso_resource.closure = request->closure;
  1202. e2->iso_resource.type = FW_CDEV_EVENT_ISO_RESOURCE_DEALLOCATED;
  1203. if (todo == ISO_RES_ALLOC) {
  1204. r->resource.release = release_iso_resource;
  1205. ret = add_client_resource(client, &r->resource, GFP_KERNEL);
  1206. if (ret < 0)
  1207. goto fail;
  1208. } else {
  1209. r->resource.release = NULL;
  1210. r->resource.handle = -1;
  1211. schedule_iso_resource(r, 0);
  1212. }
  1213. request->handle = r->resource.handle;
  1214. return 0;
  1215. fail:
  1216. kfree(r);
  1217. kfree(e1);
  1218. kfree(e2);
  1219. return ret;
  1220. }
  1221. static int ioctl_allocate_iso_resource(struct client *client,
  1222. union ioctl_arg *arg)
  1223. {
  1224. return init_iso_resource(client,
  1225. &arg->allocate_iso_resource, ISO_RES_ALLOC);
  1226. }
  1227. static int ioctl_deallocate_iso_resource(struct client *client,
  1228. union ioctl_arg *arg)
  1229. {
  1230. return release_client_resource(client,
  1231. arg->deallocate.handle, release_iso_resource, NULL);
  1232. }
  1233. static int ioctl_allocate_iso_resource_once(struct client *client,
  1234. union ioctl_arg *arg)
  1235. {
  1236. return init_iso_resource(client,
  1237. &arg->allocate_iso_resource, ISO_RES_ALLOC_ONCE);
  1238. }
  1239. static int ioctl_deallocate_iso_resource_once(struct client *client,
  1240. union ioctl_arg *arg)
  1241. {
  1242. return init_iso_resource(client,
  1243. &arg->allocate_iso_resource, ISO_RES_DEALLOC_ONCE);
  1244. }
  1245. /*
  1246. * Returns a speed code: Maximum speed to or from this device,
  1247. * limited by the device's link speed, the local node's link speed,
  1248. * and all PHY port speeds between the two links.
  1249. */
  1250. static int ioctl_get_speed(struct client *client, union ioctl_arg *arg)
  1251. {
  1252. return client->device->max_speed;
  1253. }
  1254. static int ioctl_send_broadcast_request(struct client *client,
  1255. union ioctl_arg *arg)
  1256. {
  1257. struct fw_cdev_send_request *a = &arg->send_request;
  1258. switch (a->tcode) {
  1259. case TCODE_WRITE_QUADLET_REQUEST:
  1260. case TCODE_WRITE_BLOCK_REQUEST:
  1261. break;
  1262. default:
  1263. return -EINVAL;
  1264. }
  1265. /* Security policy: Only allow accesses to Units Space. */
  1266. if (a->offset < CSR_REGISTER_BASE + CSR_CONFIG_ROM_END)
  1267. return -EACCES;
  1268. return init_request(client, a, LOCAL_BUS | 0x3f, SCODE_100);
  1269. }
  1270. static int ioctl_send_stream_packet(struct client *client, union ioctl_arg *arg)
  1271. {
  1272. struct fw_cdev_send_stream_packet *a = &arg->send_stream_packet;
  1273. struct fw_cdev_send_request request;
  1274. int dest;
  1275. if (a->speed > client->device->card->link_speed ||
  1276. a->length > 1024 << a->speed)
  1277. return -EIO;
  1278. if (a->tag > 3 || a->channel > 63 || a->sy > 15)
  1279. return -EINVAL;
  1280. dest = fw_stream_packet_destination_id(a->tag, a->channel, a->sy);
  1281. request.tcode = TCODE_STREAM_DATA;
  1282. request.length = a->length;
  1283. request.closure = a->closure;
  1284. request.data = a->data;
  1285. request.generation = a->generation;
  1286. return init_request(client, &request, dest, a->speed);
  1287. }
  1288. static void outbound_phy_packet_callback(struct fw_packet *packet,
  1289. struct fw_card *card, int status)
  1290. {
  1291. struct outbound_phy_packet_event *e =
  1292. container_of(packet, struct outbound_phy_packet_event, p);
  1293. struct client *e_client = e->client;
  1294. u32 rcode;
  1295. trace_async_phy_outbound_complete((uintptr_t)packet, card->index, status, packet->generation,
  1296. packet->timestamp);
  1297. switch (status) {
  1298. // expected:
  1299. case ACK_COMPLETE:
  1300. rcode = RCODE_COMPLETE;
  1301. break;
  1302. // should never happen with PHY packets:
  1303. case ACK_PENDING:
  1304. rcode = RCODE_COMPLETE;
  1305. break;
  1306. case ACK_BUSY_X:
  1307. case ACK_BUSY_A:
  1308. case ACK_BUSY_B:
  1309. rcode = RCODE_BUSY;
  1310. break;
  1311. case ACK_DATA_ERROR:
  1312. rcode = RCODE_DATA_ERROR;
  1313. break;
  1314. case ACK_TYPE_ERROR:
  1315. rcode = RCODE_TYPE_ERROR;
  1316. break;
  1317. // stale generation; cancelled; on certain controllers: no ack
  1318. default:
  1319. rcode = status;
  1320. break;
  1321. }
  1322. switch (e->phy_packet.without_tstamp.type) {
  1323. case FW_CDEV_EVENT_PHY_PACKET_SENT:
  1324. {
  1325. struct fw_cdev_event_phy_packet *pp = &e->phy_packet.without_tstamp;
  1326. pp->rcode = rcode;
  1327. pp->data[0] = packet->timestamp;
  1328. queue_event(e->client, &e->event, &e->phy_packet, sizeof(*pp) + pp->length,
  1329. NULL, 0);
  1330. break;
  1331. }
  1332. case FW_CDEV_EVENT_PHY_PACKET_SENT2:
  1333. {
  1334. struct fw_cdev_event_phy_packet2 *pp = &e->phy_packet.with_tstamp;
  1335. pp->rcode = rcode;
  1336. pp->tstamp = packet->timestamp;
  1337. queue_event(e->client, &e->event, &e->phy_packet, sizeof(*pp) + pp->length,
  1338. NULL, 0);
  1339. break;
  1340. }
  1341. default:
  1342. WARN_ON(1);
  1343. break;
  1344. }
  1345. client_put(e_client);
  1346. }
  1347. static int ioctl_send_phy_packet(struct client *client, union ioctl_arg *arg)
  1348. {
  1349. struct fw_cdev_send_phy_packet *a = &arg->send_phy_packet;
  1350. struct fw_card *card = client->device->card;
  1351. struct outbound_phy_packet_event *e;
  1352. /* Access policy: Allow this ioctl only on local nodes' device files. */
  1353. if (!client->device->is_local)
  1354. return -ENOSYS;
  1355. e = kzalloc(sizeof(*e) + sizeof(a->data), GFP_KERNEL);
  1356. if (e == NULL)
  1357. return -ENOMEM;
  1358. client_get(client);
  1359. e->client = client;
  1360. e->p.speed = SCODE_100;
  1361. e->p.generation = a->generation;
  1362. async_header_set_tcode(e->p.header, TCODE_LINK_INTERNAL);
  1363. e->p.header[1] = a->data[0];
  1364. e->p.header[2] = a->data[1];
  1365. e->p.header_length = 12;
  1366. e->p.callback = outbound_phy_packet_callback;
  1367. if (client->version < FW_CDEV_VERSION_EVENT_ASYNC_TSTAMP) {
  1368. struct fw_cdev_event_phy_packet *pp = &e->phy_packet.without_tstamp;
  1369. pp->closure = a->closure;
  1370. pp->type = FW_CDEV_EVENT_PHY_PACKET_SENT;
  1371. if (is_ping_packet(a->data))
  1372. pp->length = 4;
  1373. } else {
  1374. struct fw_cdev_event_phy_packet2 *pp = &e->phy_packet.with_tstamp;
  1375. pp->closure = a->closure;
  1376. pp->type = FW_CDEV_EVENT_PHY_PACKET_SENT2;
  1377. // Keep the data field so that application can match the response event to the
  1378. // request.
  1379. pp->length = sizeof(a->data);
  1380. memcpy(pp->data, a->data, sizeof(a->data));
  1381. }
  1382. trace_async_phy_outbound_initiate((uintptr_t)&e->p, card->index, e->p.generation,
  1383. e->p.header[1], e->p.header[2]);
  1384. card->driver->send_request(card, &e->p);
  1385. return 0;
  1386. }
  1387. static int ioctl_receive_phy_packets(struct client *client, union ioctl_arg *arg)
  1388. {
  1389. struct fw_cdev_receive_phy_packets *a = &arg->receive_phy_packets;
  1390. struct fw_card *card = client->device->card;
  1391. /* Access policy: Allow this ioctl only on local nodes' device files. */
  1392. if (!client->device->is_local)
  1393. return -ENOSYS;
  1394. guard(spinlock_irq)(&card->lock);
  1395. list_move_tail(&client->phy_receiver_link, &card->phy_receiver_list);
  1396. client->phy_receiver_closure = a->closure;
  1397. return 0;
  1398. }
  1399. void fw_cdev_handle_phy_packet(struct fw_card *card, struct fw_packet *p)
  1400. {
  1401. struct client *client;
  1402. guard(spinlock_irqsave)(&card->lock);
  1403. list_for_each_entry(client, &card->phy_receiver_list, phy_receiver_link) {
  1404. struct inbound_phy_packet_event *e = kmalloc(sizeof(*e) + 8, GFP_ATOMIC);
  1405. if (e == NULL)
  1406. break;
  1407. if (client->version < FW_CDEV_VERSION_EVENT_ASYNC_TSTAMP) {
  1408. struct fw_cdev_event_phy_packet *pp = &e->phy_packet.without_tstamp;
  1409. pp->closure = client->phy_receiver_closure;
  1410. pp->type = FW_CDEV_EVENT_PHY_PACKET_RECEIVED;
  1411. pp->rcode = RCODE_COMPLETE;
  1412. pp->length = 8;
  1413. pp->data[0] = p->header[1];
  1414. pp->data[1] = p->header[2];
  1415. queue_event(client, &e->event, &e->phy_packet, sizeof(*pp) + 8, NULL, 0);
  1416. } else {
  1417. struct fw_cdev_event_phy_packet2 *pp = &e->phy_packet.with_tstamp;
  1418. pp = &e->phy_packet.with_tstamp;
  1419. pp->closure = client->phy_receiver_closure;
  1420. pp->type = FW_CDEV_EVENT_PHY_PACKET_RECEIVED2;
  1421. pp->rcode = RCODE_COMPLETE;
  1422. pp->length = 8;
  1423. pp->tstamp = p->timestamp;
  1424. pp->data[0] = p->header[1];
  1425. pp->data[1] = p->header[2];
  1426. queue_event(client, &e->event, &e->phy_packet, sizeof(*pp) + 8, NULL, 0);
  1427. }
  1428. }
  1429. }
  1430. static int (* const ioctl_handlers[])(struct client *, union ioctl_arg *) = {
  1431. [0x00] = ioctl_get_info,
  1432. [0x01] = ioctl_send_request,
  1433. [0x02] = ioctl_allocate,
  1434. [0x03] = ioctl_deallocate,
  1435. [0x04] = ioctl_send_response,
  1436. [0x05] = ioctl_initiate_bus_reset,
  1437. [0x06] = ioctl_add_descriptor,
  1438. [0x07] = ioctl_remove_descriptor,
  1439. [0x08] = ioctl_create_iso_context,
  1440. [0x09] = ioctl_queue_iso,
  1441. [0x0a] = ioctl_start_iso,
  1442. [0x0b] = ioctl_stop_iso,
  1443. [0x0c] = ioctl_get_cycle_timer,
  1444. [0x0d] = ioctl_allocate_iso_resource,
  1445. [0x0e] = ioctl_deallocate_iso_resource,
  1446. [0x0f] = ioctl_allocate_iso_resource_once,
  1447. [0x10] = ioctl_deallocate_iso_resource_once,
  1448. [0x11] = ioctl_get_speed,
  1449. [0x12] = ioctl_send_broadcast_request,
  1450. [0x13] = ioctl_send_stream_packet,
  1451. [0x14] = ioctl_get_cycle_timer2,
  1452. [0x15] = ioctl_send_phy_packet,
  1453. [0x16] = ioctl_receive_phy_packets,
  1454. [0x17] = ioctl_set_iso_channels,
  1455. [0x18] = ioctl_flush_iso,
  1456. };
  1457. static int dispatch_ioctl(struct client *client,
  1458. unsigned int cmd, void __user *arg)
  1459. {
  1460. union ioctl_arg buffer;
  1461. int ret;
  1462. if (fw_device_is_shutdown(client->device))
  1463. return -ENODEV;
  1464. if (_IOC_TYPE(cmd) != '#' ||
  1465. _IOC_NR(cmd) >= ARRAY_SIZE(ioctl_handlers) ||
  1466. _IOC_SIZE(cmd) > sizeof(buffer))
  1467. return -ENOTTY;
  1468. memset(&buffer, 0, sizeof(buffer));
  1469. if (_IOC_DIR(cmd) & _IOC_WRITE)
  1470. if (copy_from_user(&buffer, arg, _IOC_SIZE(cmd)))
  1471. return -EFAULT;
  1472. ret = ioctl_handlers[_IOC_NR(cmd)](client, &buffer);
  1473. if (ret < 0)
  1474. return ret;
  1475. if (_IOC_DIR(cmd) & _IOC_READ)
  1476. if (copy_to_user(arg, &buffer, _IOC_SIZE(cmd)))
  1477. return -EFAULT;
  1478. return ret;
  1479. }
  1480. static long fw_device_op_ioctl(struct file *file,
  1481. unsigned int cmd, unsigned long arg)
  1482. {
  1483. return dispatch_ioctl(file->private_data, cmd, (void __user *)arg);
  1484. }
  1485. static int fw_device_op_mmap(struct file *file, struct vm_area_struct *vma)
  1486. {
  1487. struct client *client = file->private_data;
  1488. unsigned long size;
  1489. int page_count, ret;
  1490. if (fw_device_is_shutdown(client->device))
  1491. return -ENODEV;
  1492. /* FIXME: We could support multiple buffers, but we don't. */
  1493. if (client->buffer.pages != NULL)
  1494. return -EBUSY;
  1495. if (!(vma->vm_flags & VM_SHARED))
  1496. return -EINVAL;
  1497. if (vma->vm_start & ~PAGE_MASK)
  1498. return -EINVAL;
  1499. client->vm_start = vma->vm_start;
  1500. size = vma->vm_end - vma->vm_start;
  1501. page_count = size >> PAGE_SHIFT;
  1502. if (size & ~PAGE_MASK)
  1503. return -EINVAL;
  1504. ret = fw_iso_buffer_alloc(&client->buffer, page_count);
  1505. if (ret < 0)
  1506. return ret;
  1507. scoped_guard(spinlock_irq, &client->lock) {
  1508. if (client->iso_context) {
  1509. ret = fw_iso_buffer_map_dma(&client->buffer, client->device->card,
  1510. iso_dma_direction(client->iso_context));
  1511. if (ret < 0)
  1512. goto fail;
  1513. client->buffer_is_mapped = true;
  1514. }
  1515. }
  1516. ret = vm_map_pages_zero(vma, client->buffer.pages,
  1517. client->buffer.page_count);
  1518. if (ret < 0)
  1519. goto fail;
  1520. return 0;
  1521. fail:
  1522. fw_iso_buffer_destroy(&client->buffer, client->device->card);
  1523. return ret;
  1524. }
  1525. static bool has_outbound_transactions(struct client *client)
  1526. {
  1527. struct client_resource *resource;
  1528. unsigned long index;
  1529. guard(spinlock_irq)(&client->lock);
  1530. xa_for_each(&client->resource_xa, index, resource) {
  1531. if (is_outbound_transaction_resource(resource))
  1532. return true;
  1533. }
  1534. return false;
  1535. }
  1536. static int fw_device_op_release(struct inode *inode, struct file *file)
  1537. {
  1538. struct client *client = file->private_data;
  1539. struct event *event, *next_event;
  1540. struct client_resource *resource;
  1541. unsigned long index;
  1542. scoped_guard(spinlock_irq, &client->device->card->lock)
  1543. list_del(&client->phy_receiver_link);
  1544. scoped_guard(mutex, &client->device->client_list_mutex)
  1545. list_del(&client->link);
  1546. if (client->iso_context)
  1547. fw_iso_context_destroy(client->iso_context);
  1548. if (client->buffer.pages)
  1549. fw_iso_buffer_destroy(&client->buffer, client->device->card);
  1550. // Freeze client->resource_xa and client->event_list.
  1551. scoped_guard(spinlock_irq, &client->lock)
  1552. client->in_shutdown = true;
  1553. wait_event(client->tx_flush_wait, !has_outbound_transactions(client));
  1554. xa_for_each(&client->resource_xa, index, resource) {
  1555. resource->release(client, resource);
  1556. client_put(client);
  1557. }
  1558. xa_destroy(&client->resource_xa);
  1559. list_for_each_entry_safe(event, next_event, &client->event_list, link)
  1560. kfree(event);
  1561. client_put(client);
  1562. return 0;
  1563. }
  1564. static __poll_t fw_device_op_poll(struct file *file, poll_table * pt)
  1565. {
  1566. struct client *client = file->private_data;
  1567. __poll_t mask = 0;
  1568. poll_wait(file, &client->wait, pt);
  1569. if (fw_device_is_shutdown(client->device))
  1570. mask |= EPOLLHUP | EPOLLERR;
  1571. if (!list_empty(&client->event_list))
  1572. mask |= EPOLLIN | EPOLLRDNORM;
  1573. return mask;
  1574. }
  1575. const struct file_operations fw_device_ops = {
  1576. .owner = THIS_MODULE,
  1577. .open = fw_device_op_open,
  1578. .read = fw_device_op_read,
  1579. .unlocked_ioctl = fw_device_op_ioctl,
  1580. .mmap = fw_device_op_mmap,
  1581. .release = fw_device_op_release,
  1582. .poll = fw_device_op_poll,
  1583. .compat_ioctl = compat_ptr_ioctl,
  1584. };