microcode_intel.c 13.3 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3
/*
 *	Intel CPU Microcode Update Driver for Linux
 *
4
 *	Copyright (C) 2000-2006 Tigran Aivazian <tigran@aivazian.fsnet.co.uk>
5
 *		      2006	Shaohua Li <shaohua.li@intel.com>
L
Linus Torvalds 已提交
6 7
 *
 *	This driver allows to upgrade microcode on Intel processors
B
Ben Castricum 已提交
8
 *	belonging to IA-32 family - PentiumPro, Pentium II,
L
Linus Torvalds 已提交
9 10
 *	Pentium III, Xeon, Pentium 4, etc.
 *
B
Ben Castricum 已提交
11 12 13 14
 *	Reference: Section 8.11 of Volume 3a, IA-32 Intel? Architecture
 *	Software Developer's Manual
 *	Order Number 253668 or free download from:
 *
15
 *	http://developer.intel.com/Assets/PDF/manual/253668.pdf	
L
Linus Torvalds 已提交
16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57
 *
 *	For more information, go to http://www.urbanmyth.org/microcode
 *
 *	This program is free software; you can redistribute it and/or
 *	modify it under the terms of the GNU General Public License
 *	as published by the Free Software Foundation; either version
 *	2 of the License, or (at your option) any later version.
 *
 *	1.0	16 Feb 2000, Tigran Aivazian <tigran@sco.com>
 *		Initial release.
 *	1.01	18 Feb 2000, Tigran Aivazian <tigran@sco.com>
 *		Added read() support + cleanups.
 *	1.02	21 Feb 2000, Tigran Aivazian <tigran@sco.com>
 *		Added 'device trimming' support. open(O_WRONLY) zeroes
 *		and frees the saved copy of applied microcode.
 *	1.03	29 Feb 2000, Tigran Aivazian <tigran@sco.com>
 *		Made to use devfs (/dev/cpu/microcode) + cleanups.
 *	1.04	06 Jun 2000, Simon Trimmer <simon@veritas.com>
 *		Added misc device support (now uses both devfs and misc).
 *		Added MICROCODE_IOCFREE ioctl to clear memory.
 *	1.05	09 Jun 2000, Simon Trimmer <simon@veritas.com>
 *		Messages for error cases (non Intel & no suitable microcode).
 *	1.06	03 Aug 2000, Tigran Aivazian <tigran@veritas.com>
 *		Removed ->release(). Removed exclusive open and status bitmap.
 *		Added microcode_rwsem to serialize read()/write()/ioctl().
 *		Removed global kernel lock usage.
 *	1.07	07 Sep 2000, Tigran Aivazian <tigran@veritas.com>
 *		Write 0 to 0x8B msr and then cpuid before reading revision,
 *		so that it works even if there were no update done by the
 *		BIOS. Otherwise, reading from 0x8B gives junk (which happened
 *		to be 0 on my machine which is why it worked even when I
 *		disabled update by the BIOS)
 *		Thanks to Eric W. Biederman <ebiederman@lnxi.com> for the fix.
 *	1.08	11 Dec 2000, Richard Schaal <richard.schaal@intel.com> and
 *			     Tigran Aivazian <tigran@veritas.com>
 *		Intel Pentium 4 processor support and bugfixes.
 *	1.09	30 Oct 2001, Tigran Aivazian <tigran@veritas.com>
 *		Bugfix for HT (Hyper-Threading) enabled processors
 *		whereby processor resources are shared by all logical processors
 *		in a single CPU package.
 *	1.10	28 Feb 2002 Asit K Mallick <asit.k.mallick@intel.com> and
 *		Tigran Aivazian <tigran@veritas.com>,
58 59
 *		Serialize updates as required on HT processors due to
 *		speculative nature of implementation.
L
Linus Torvalds 已提交
60 61
 *	1.11	22 Mar 2002 Tigran Aivazian <tigran@veritas.com>
 *		Fix the panic when writing zero-length microcode chunk.
B
Ben Castricum 已提交
62
 *	1.12	29 Sep 2003 Nitin Kamble <nitin.a.kamble@intel.com>,
L
Linus Torvalds 已提交
63 64 65 66
 *		Jun Nakajima <jun.nakajima@intel.com>
 *		Support for the microcode updates in the new format.
 *	1.13	10 Oct 2003 Tigran Aivazian <tigran@veritas.com>
 *		Removed ->read() method and obsoleted MICROCODE_IOCFREE ioctl
B
Ben Castricum 已提交
67
 *		because we no longer hold a copy of applied microcode
L
Linus Torvalds 已提交
68 69 70 71 72
 *		in kernel memory.
 *	1.14	25 Jun 2004 Tigran Aivazian <tigran@veritas.com>
 *		Fix sigmatch() macro to handle old CPUs with pf == 0.
 *		Thanks to Stuart Swales for pointing out this bug.
 */
73 74 75

#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt

I
Ingo Molnar 已提交
76 77 78 79
#include <linux/firmware.h>
#include <linux/uaccess.h>
#include <linux/kernel.h>
#include <linux/module.h>
80
#include <linux/vmalloc.h>
L
Linus Torvalds 已提交
81

82
#include <asm/microcode.h>
I
Ingo Molnar 已提交
83 84
#include <asm/processor.h>
#include <asm/msr.h>
L
Linus Torvalds 已提交
85

P
Peter Oruba 已提交
86
MODULE_DESCRIPTION("Microcode Update Driver");
87
MODULE_AUTHOR("Tigran Aivazian <tigran@aivazian.fsnet.co.uk>");
L
Linus Torvalds 已提交
88 89
MODULE_LICENSE("GPL");

90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121
struct microcode_header_intel {
	unsigned int            hdrver;
	unsigned int            rev;
	unsigned int            date;
	unsigned int            sig;
	unsigned int            cksum;
	unsigned int            ldrver;
	unsigned int            pf;
	unsigned int            datasize;
	unsigned int            totalsize;
	unsigned int            reserved[3];
};

struct microcode_intel {
	struct microcode_header_intel hdr;
	unsigned int            bits[0];
};

/* microcode format is extended from prescott processors */
struct extended_signature {
	unsigned int            sig;
	unsigned int            pf;
	unsigned int            cksum;
};

struct extended_sigtable {
	unsigned int            count;
	unsigned int            cksum;
	unsigned int            reserved[3];
	struct extended_signature sigs[0];
};

I
Ingo Molnar 已提交
122
#define DEFAULT_UCODE_DATASIZE	(2000)
123 124 125 126
#define MC_HEADER_SIZE		(sizeof(struct microcode_header_intel))
#define DEFAULT_UCODE_TOTALSIZE (DEFAULT_UCODE_DATASIZE + MC_HEADER_SIZE)
#define EXT_HEADER_SIZE		(sizeof(struct extended_sigtable))
#define EXT_SIGNATURE_SIZE	(sizeof(struct extended_signature))
P
Peter Oruba 已提交
127
#define DWSIZE			(sizeof(u32))
I
Ingo Molnar 已提交
128

L
Linus Torvalds 已提交
129
#define get_totalsize(mc) \
130 131 132 133
	(((struct microcode_intel *)mc)->hdr.totalsize ? \
	 ((struct microcode_intel *)mc)->hdr.totalsize : \
	 DEFAULT_UCODE_TOTALSIZE)

L
Linus Torvalds 已提交
134
#define get_datasize(mc) \
135 136
	(((struct microcode_intel *)mc)->hdr.datasize ? \
	 ((struct microcode_intel *)mc)->hdr.datasize : DEFAULT_UCODE_DATASIZE)
L
Linus Torvalds 已提交
137 138 139 140 141 142

#define sigmatch(s1, s2, p1, p2) \
	(((s1) == (s2)) && (((p1) & (p2)) || (((p1) == 0) && ((p2) == 0))))

#define exttable_size(et) ((et)->count * EXT_SIGNATURE_SIZE + EXT_HEADER_SIZE)

143
static int collect_cpu_info(int cpu_num, struct cpu_signature *csig)
L
Linus Torvalds 已提交
144
{
145
	struct cpuinfo_x86 *c = &cpu_data(cpu_num);
L
Linus Torvalds 已提交
146 147
	unsigned int val[2];

148
	memset(csig, 0, sizeof(*csig));
L
Linus Torvalds 已提交
149 150

	if (c->x86_vendor != X86_VENDOR_INTEL || c->x86 < 6 ||
P
Peter Oruba 已提交
151
	    cpu_has(c, X86_FEATURE_IA64)) {
152
		pr_err("CPU%d not a capable Intel processor\n", cpu_num);
153
		return -1;
154
	}
L
Linus Torvalds 已提交
155

156
	csig->sig = cpuid_eax(0x00000001);
157 158 159 160

	if ((c->x86_model >= 5) || (c->x86 > 6)) {
		/* get processor flags from MSR 0x17 */
		rdmsr(MSR_IA32_PLATFORM_ID, val[0], val[1]);
161
		csig->pf = 1 << ((val[1] >> 18) & 7);
L
Linus Torvalds 已提交
162 163
	}

164
	csig->rev = c->microcode;
165 166
	pr_info("CPU%d sig=0x%x, pf=0x%x, revision=0x%x\n",
		cpu_num, csig->sig, csig->pf, csig->rev);
167 168

	return 0;
L
Linus Torvalds 已提交
169 170
}

D
Dmitry Adamushko 已提交
171
static inline int update_match_cpu(struct cpu_signature *csig, int sig, int pf)
L
Linus Torvalds 已提交
172
{
D
Dmitry Adamushko 已提交
173 174
	return (!sigmatch(sig, csig->sig, pf, csig->pf)) ? 0 : 1;
}
L
Linus Torvalds 已提交
175

176
static inline int
I
Ingo Molnar 已提交
177
update_match_revision(struct microcode_header_intel *mc_header, int rev)
D
Dmitry Adamushko 已提交
178 179
{
	return (mc_header->rev <= rev) ? 0 : 1;
L
Linus Torvalds 已提交
180 181
}

P
Peter Oruba 已提交
182
static int microcode_sanity_check(void *mc)
L
Linus Torvalds 已提交
183
{
I
Ingo Molnar 已提交
184
	unsigned long total_size, data_size, ext_table_size;
185
	struct microcode_header_intel *mc_header = mc;
186 187
	struct extended_sigtable *ext_header = NULL;
	int sum, orig_sum, ext_sigcount = 0, i;
I
Ingo Molnar 已提交
188
	struct extended_signature *ext_sig;
189 190 191

	total_size = get_totalsize(mc_header);
	data_size = get_datasize(mc_header);
I
Ingo Molnar 已提交
192

193
	if (data_size + MC_HEADER_SIZE > total_size) {
194
		pr_err("error! Bad data size in microcode data file\n");
195 196
		return -EINVAL;
	}
L
Linus Torvalds 已提交
197

198
	if (mc_header->ldrver != 1 || mc_header->hdrver != 1) {
199
		pr_err("error! Unknown microcode update format\n");
200 201 202 203 204 205
		return -EINVAL;
	}
	ext_table_size = total_size - (MC_HEADER_SIZE + data_size);
	if (ext_table_size) {
		if ((ext_table_size < EXT_HEADER_SIZE)
		 || ((ext_table_size - EXT_HEADER_SIZE) % EXT_SIGNATURE_SIZE)) {
206
			pr_err("error! Small exttable size in microcode data file\n");
207
			return -EINVAL;
L
Linus Torvalds 已提交
208
		}
209 210
		ext_header = mc + MC_HEADER_SIZE + data_size;
		if (ext_table_size != exttable_size(ext_header)) {
211
			pr_err("error! Bad exttable size in microcode data file\n");
212
			return -EFAULT;
L
Linus Torvalds 已提交
213
		}
214 215
		ext_sigcount = ext_header->count;
	}
L
Linus Torvalds 已提交
216

217 218 219
	/* check extended table checksum */
	if (ext_table_size) {
		int ext_table_sum = 0;
220
		int *ext_tablep = (int *)ext_header;
221 222 223 224 225

		i = ext_table_size / DWSIZE;
		while (i--)
			ext_table_sum += ext_tablep[i];
		if (ext_table_sum) {
226
			pr_warning("aborting, bad extended signature table checksum\n");
227
			return -EINVAL;
L
Linus Torvalds 已提交
228
		}
229
	}
L
Linus Torvalds 已提交
230

231 232 233 234 235 236
	/* calculate the checksum */
	orig_sum = 0;
	i = (MC_HEADER_SIZE + data_size) / DWSIZE;
	while (i--)
		orig_sum += ((int *)mc)[i];
	if (orig_sum) {
237
		pr_err("aborting, bad checksum\n");
238 239 240 241 242 243
		return -EINVAL;
	}
	if (!ext_table_size)
		return 0;
	/* check extended signature checksum */
	for (i = 0; i < ext_sigcount; i++) {
J
Jan Engelhardt 已提交
244 245
		ext_sig = (void *)ext_header + EXT_HEADER_SIZE +
			  EXT_SIGNATURE_SIZE * i;
246 247 248 249
		sum = orig_sum
			- (mc_header->sig + mc_header->pf + mc_header->cksum)
			+ (ext_sig->sig + ext_sig->pf + ext_sig->cksum);
		if (sum) {
250
			pr_err("aborting, bad checksum\n");
251
			return -EINVAL;
L
Linus Torvalds 已提交
252
		}
253 254 255
	}
	return 0;
}
256

257 258 259 260
/*
 * return 0 - no update found
 * return 1 - found update
 */
D
Dmitry Adamushko 已提交
261 262
static int
get_matching_microcode(struct cpu_signature *cpu_sig, void *mc, int rev)
263
{
264
	struct microcode_header_intel *mc_header = mc;
265 266 267 268 269
	struct extended_sigtable *ext_header;
	unsigned long total_size = get_totalsize(mc_header);
	int ext_sigcount, i;
	struct extended_signature *ext_sig;

D
Dmitry Adamushko 已提交
270 271 272 273 274
	if (!update_match_revision(mc_header, rev))
		return 0;

	if (update_match_cpu(cpu_sig, mc_header->sig, mc_header->pf))
		return 1;
275

D
Dmitry Adamushko 已提交
276
	/* Look for ext. headers: */
277 278 279
	if (total_size <= get_datasize(mc_header) + MC_HEADER_SIZE)
		return 0;

J
Jan Engelhardt 已提交
280
	ext_header = mc + get_datasize(mc_header) + MC_HEADER_SIZE;
281
	ext_sigcount = ext_header->count;
J
Jan Engelhardt 已提交
282
	ext_sig = (void *)ext_header + EXT_HEADER_SIZE;
D
Dmitry Adamushko 已提交
283

284
	for (i = 0; i < ext_sigcount; i++) {
D
Dmitry Adamushko 已提交
285 286
		if (update_match_cpu(cpu_sig, ext_sig->sig, ext_sig->pf))
			return 1;
287 288 289
		ext_sig++;
	}
	return 0;
L
Linus Torvalds 已提交
290 291
}

292
static int apply_microcode(int cpu)
L
Linus Torvalds 已提交
293
{
I
Ingo Molnar 已提交
294 295
	struct microcode_intel *mc_intel;
	struct ucode_cpu_info *uci;
L
Linus Torvalds 已提交
296
	unsigned int val[2];
297 298
	int cpu_num = raw_smp_processor_id();
	struct cpuinfo_x86 *c = &cpu_data(cpu_num);
I
Ingo Molnar 已提交
299 300 301

	uci = ucode_cpu_info + cpu;
	mc_intel = uci->mc;
L
Linus Torvalds 已提交
302

303 304 305
	/* We should bind the task to the CPU */
	BUG_ON(cpu_num != cpu);

306
	if (mc_intel == NULL)
307
		return 0;
L
Linus Torvalds 已提交
308 309 310

	/* write microcode via MSR 0x79 */
	wrmsr(MSR_IA32_UCODE_WRITE,
311 312
	      (unsigned long) mc_intel->bits,
	      (unsigned long) mc_intel->bits >> 16 >> 16);
L
Linus Torvalds 已提交
313 314
	wrmsr(MSR_IA32_UCODE_REV, 0, 0);

315
	/* As documented in the SDM: Do a CPUID 1 here */
316
	sync_core();
317

L
Linus Torvalds 已提交
318 319 320
	/* get the current revision from MSR 0x8B */
	rdmsr(MSR_IA32_UCODE_REV, val[0], val[1]);

321
	if (val[1] != mc_intel->hdr.rev) {
322 323
		pr_err("CPU%d update to revision 0x%x failed\n",
		       cpu_num, mc_intel->hdr.rev);
324
		return -1;
325
	}
326
	pr_info("CPU%d updated to revision 0x%x, date = %04x-%02x-%02x\n",
327
		cpu_num, val[1],
328 329 330
		mc_intel->hdr.date & 0xffff,
		mc_intel->hdr.date >> 24,
		(mc_intel->hdr.date >> 16) & 0xff);
I
Ingo Molnar 已提交
331

332
	uci->cpu_sig.rev = val[1];
333
	c->microcode = val[1];
334 335

	return 0;
L
Linus Torvalds 已提交
336 337
}

338 339
static enum ucode_state generic_load_microcode(int cpu, void *data, size_t size,
				int (*get_ucode_data)(void *, const void *, size_t))
340
{
D
Dmitry Adamushko 已提交
341
	struct ucode_cpu_info *uci = ucode_cpu_info + cpu;
342
	u8 *ucode_ptr = data, *new_mc = NULL, *mc = NULL;
D
Dmitry Adamushko 已提交
343 344
	int new_rev = uci->cpu_sig.rev;
	unsigned int leftover = size;
345
	enum ucode_state state = UCODE_OK;
346
	unsigned int curr_mc_size = 0;
347

D
Dmitry Adamushko 已提交
348 349 350
	while (leftover) {
		struct microcode_header_intel mc_header;
		unsigned int mc_size;
351

D
Dmitry Adamushko 已提交
352 353
		if (get_ucode_data(&mc_header, ucode_ptr, sizeof(mc_header)))
			break;
354

D
Dmitry Adamushko 已提交
355 356
		mc_size = get_totalsize(&mc_header);
		if (!mc_size || mc_size > leftover) {
357
			pr_err("error! Bad data in microcode data file\n");
D
Dmitry Adamushko 已提交
358 359
			break;
		}
360

361 362
		/* For performance reasons, reuse mc area when possible */
		if (!mc || mc_size > curr_mc_size) {
363
			vfree(mc);
364 365 366 367 368
			mc = vmalloc(mc_size);
			if (!mc)
				break;
			curr_mc_size = mc_size;
		}
D
Dmitry Adamushko 已提交
369 370 371 372 373 374 375

		if (get_ucode_data(mc, ucode_ptr, mc_size) ||
		    microcode_sanity_check(mc) < 0) {
			break;
		}

		if (get_matching_microcode(&uci->cpu_sig, mc, new_rev)) {
376
			vfree(new_mc);
D
Dmitry Adamushko 已提交
377 378
			new_rev = mc_header.rev;
			new_mc  = mc;
379 380
			mc = NULL;	/* trigger new vmalloc */
		}
D
Dmitry Adamushko 已提交
381 382 383

		ucode_ptr += mc_size;
		leftover  -= mc_size;
384 385
	}

386
	vfree(mc);
387

388
	if (leftover) {
389
		vfree(new_mc);
390
		state = UCODE_ERROR;
I
Ingo Molnar 已提交
391
		goto out;
392
	}
I
Ingo Molnar 已提交
393

394 395
	if (!new_mc) {
		state = UCODE_NFOUND;
I
Ingo Molnar 已提交
396
		goto out;
397
	}
D
Dmitry Adamushko 已提交
398

399
	vfree(uci->mc);
I
Ingo Molnar 已提交
400 401
	uci->mc = (struct microcode_intel *)new_mc;

402 403
	pr_debug("CPU%d found a matching microcode update with version 0x%x (current=0x%x)\n",
		 cpu, new_rev, uci->cpu_sig.rev);
404 405
out:
	return state;
406 407
}

D
Dmitry Adamushko 已提交
408 409 410 411 412
static int get_ucode_fw(void *to, const void *from, size_t n)
{
	memcpy(to, from, n);
	return 0;
}
413

414
static enum ucode_state request_microcode_fw(int cpu, struct device *device)
415 416
{
	char name[30];
417
	struct cpuinfo_x86 *c = &cpu_data(cpu);
418
	const struct firmware *firmware;
419
	enum ucode_state ret;
420

P
Peter Oruba 已提交
421
	sprintf(name, "intel-ucode/%02x-%02x-%02x",
422
		c->x86, c->x86_model, c->x86_mask);
423 424

	if (request_firmware(&firmware, name, device)) {
425
		pr_debug("data file %s load failed\n", name);
426
		return UCODE_NFOUND;
427
	}
D
Dmitry Adamushko 已提交
428

429 430
	ret = generic_load_microcode(cpu, (void *)firmware->data,
				     firmware->size, &get_ucode_fw);
D
Dmitry Adamushko 已提交
431

432 433
	release_firmware(firmware);

D
Dmitry Adamushko 已提交
434 435 436 437 438 439 440 441
	return ret;
}

static int get_ucode_user(void *to, const void *from, size_t n)
{
	return copy_from_user(to, from, n);
}

442 443
static enum ucode_state
request_microcode_user(int cpu, const void __user *buf, size_t size)
D
Dmitry Adamushko 已提交
444
{
445
	return generic_load_microcode(cpu, (void *)buf, size, &get_ucode_user);
446 447
}

P
Peter Oruba 已提交
448
static void microcode_fini_cpu(int cpu)
449 450 451
{
	struct ucode_cpu_info *uci = ucode_cpu_info + cpu;

452 453
	vfree(uci->mc);
	uci->mc = NULL;
454
}
P
Peter Oruba 已提交
455

H
Hannes Eder 已提交
456
static struct microcode_ops microcode_intel_ops = {
D
Dmitry Adamushko 已提交
457 458
	.request_microcode_user		  = request_microcode_user,
	.request_microcode_fw             = request_microcode_fw,
P
Peter Oruba 已提交
459 460 461 462 463
	.collect_cpu_info                 = collect_cpu_info,
	.apply_microcode                  = apply_microcode,
	.microcode_fini_cpu               = microcode_fini_cpu,
};

464
struct microcode_ops * __init init_intel_microcode(void)
P
Peter Oruba 已提交
465
{
466
	return &microcode_intel_ops;
P
Peter Oruba 已提交
467 468
}