fw-cdev.c 24.7 KB
Newer Older
1 2
/*
 * Char device for device raw access
3
 *
4
 * Copyright (C) 2005-2007  Kristian Hoegsberg <krh@bitplanet.net>
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software Foundation,
 * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
 */

#include <linux/module.h>
#include <linux/kernel.h>
#include <linux/wait.h>
#include <linux/errno.h>
#include <linux/device.h>
#include <linux/vmalloc.h>
#include <linux/poll.h>
28 29
#include <linux/preempt.h>
#include <linux/time.h>
30 31
#include <linux/delay.h>
#include <linux/mm.h>
32
#include <linux/idr.h>
33
#include <linux/compat.h>
34
#include <linux/firewire-cdev.h>
35
#include <asm/system.h>
36 37 38 39 40
#include <asm/uaccess.h>
#include "fw-transaction.h"
#include "fw-topology.h"
#include "fw-device.h"

41 42 43 44 45 46 47
struct client;
struct client_resource {
	struct list_head link;
	void (*release)(struct client *client, struct client_resource *r);
	u32 handle;
};

48 49 50 51 52
/*
 * dequeue_event() just kfree()'s the event, so the event has to be
 * the first field in the struct.
 */

53 54 55 56 57
struct event {
	struct { void *data; size_t size; } v[2];
	struct list_head link;
};

58 59 60 61 62
struct bus_reset {
	struct event event;
	struct fw_cdev_event_bus_reset reset;
};

63 64 65 66
struct response {
	struct event event;
	struct fw_transaction transaction;
	struct client *client;
67
	struct client_resource resource;
68 69 70 71 72 73 74 75 76
	struct fw_cdev_event_response response;
};

struct iso_interrupt {
	struct event event;
	struct fw_cdev_event_iso_interrupt interrupt;
};

struct client {
77
	u32 version;
78 79
	struct fw_device *device;
	spinlock_t lock;
80
	u32 resource_handle;
81
	struct list_head resource_list;
82 83
	struct list_head event_list;
	wait_queue_head_t wait;
84
	u64 bus_reset_closure;
85

86
	struct fw_iso_context *iso_context;
87
	u64 iso_closure;
88 89
	struct fw_iso_buffer buffer;
	unsigned long vm_start;
90 91

	struct list_head link;
92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109
};

static inline void __user *
u64_to_uptr(__u64 value)
{
	return (void __user *)(unsigned long)value;
}

static inline __u64
uptr_to_u64(void __user *ptr)
{
	return (__u64)(unsigned long)ptr;
}

static int fw_device_op_open(struct inode *inode, struct file *file)
{
	struct fw_device *device;
	struct client *client;
110
	unsigned long flags;
111

112 113 114
	device = fw_device_from_devt(inode->i_rdev);
	if (device == NULL)
		return -ENODEV;
115

116
	client = kzalloc(sizeof(*client), GFP_KERNEL);
117 118 119 120 121
	if (client == NULL)
		return -ENOMEM;

	client->device = fw_device_get(device);
	INIT_LIST_HEAD(&client->event_list);
122
	INIT_LIST_HEAD(&client->resource_list);
123 124 125 126 127
	spin_lock_init(&client->lock);
	init_waitqueue_head(&client->wait);

	file->private_data = client;

128 129 130 131
	spin_lock_irqsave(&device->card->lock, flags);
	list_add_tail(&client->link, &device->client_list);
	spin_unlock_irqrestore(&device->card->lock, flags);

132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152
	return 0;
}

static void queue_event(struct client *client, struct event *event,
			void *data0, size_t size0, void *data1, size_t size1)
{
	unsigned long flags;

	event->v[0].data = data0;
	event->v[0].size = size0;
	event->v[1].data = data1;
	event->v[1].size = size1;

	spin_lock_irqsave(&client->lock, flags);

	list_add_tail(&event->link, &client->event_list);
	wake_up_interruptible(&client->wait);

	spin_unlock_irqrestore(&client->lock, flags);
}

153 154
static int
dequeue_event(struct client *client, char __user *buffer, size_t count)
155 156 157 158
{
	unsigned long flags;
	struct event *event;
	size_t size, total;
159
	int i, retval;
160

161 162 163 164 165
	retval = wait_event_interruptible(client->wait,
					  !list_empty(&client->event_list) ||
					  fw_device_is_shutdown(client->device));
	if (retval < 0)
		return retval;
166

167 168 169
	if (list_empty(&client->event_list) &&
		       fw_device_is_shutdown(client->device))
		return -ENODEV;
170

171
	spin_lock_irqsave(&client->lock, flags);
172 173 174 175 176 177 178
	event = container_of(client->event_list.next, struct event, link);
	list_del(&event->link);
	spin_unlock_irqrestore(&client->lock, flags);

	total = 0;
	for (i = 0; i < ARRAY_SIZE(event->v) && total < count; i++) {
		size = min(event->v[i].size, count - total);
179 180
		if (copy_to_user(buffer + total, event->v[i].data, size)) {
			retval = -EFAULT;
181
			goto out;
182
		}
183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201
		total += size;
	}
	retval = total;

 out:
	kfree(event);

	return retval;
}

static ssize_t
fw_device_op_read(struct file *file,
		  char __user *buffer, size_t count, loff_t *offset)
{
	struct client *client = file->private_data;

	return dequeue_event(client, buffer, count);
}

202 203
static void
fill_bus_reset_event(struct fw_cdev_event_bus_reset *event,
204
		     struct client *client)
205
{
206
	struct fw_card *card = client->device->card;
207

208
	event->closure	     = client->bus_reset_closure;
209
	event->type          = FW_CDEV_EVENT_BUS_RESET;
210
	event->node_id       = client->device->node_id;
211 212 213 214 215 216 217
	event->local_node_id = card->local_node->node_id;
	event->bm_node_id    = 0; /* FIXME: We don't track the BM. */
	event->irm_node_id   = card->irm_node->node_id;
	event->root_node_id  = card->root_node->node_id;
	event->generation    = card->generation;
}

218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233
static void
for_each_client(struct fw_device *device,
		void (*callback)(struct client *client))
{
	struct fw_card *card = device->card;
	struct client *c;
	unsigned long flags;

	spin_lock_irqsave(&card->lock, flags);

	list_for_each_entry(c, &device->client_list, link)
		callback(c);

	spin_unlock_irqrestore(&card->lock, flags);
}

234 235 236 237 238
static void
queue_bus_reset_event(struct client *client)
{
	struct bus_reset *bus_reset;

239
	bus_reset = kzalloc(sizeof(*bus_reset), GFP_ATOMIC);
240 241 242 243 244
	if (bus_reset == NULL) {
		fw_notify("Out of memory when allocating bus reset event\n");
		return;
	}

245
	fill_bus_reset_event(&bus_reset->reset, client);
246 247

	queue_event(client, &bus_reset->event,
248
		    &bus_reset->reset, sizeof(bus_reset->reset), NULL, 0);
249 250 251 252
}

void fw_device_cdev_update(struct fw_device *device)
{
253 254
	for_each_client(device, queue_bus_reset_event);
}
255

256 257 258 259
static void wake_up_client(struct client *client)
{
	wake_up_interruptible(&client->wait);
}
260

261 262 263
void fw_device_cdev_remove(struct fw_device *device)
{
	for_each_client(device, wake_up_client);
264 265
}

266
static int ioctl_get_info(struct client *client, void *buffer)
267
{
268
	struct fw_cdev_get_info *get_info = buffer;
269 270
	struct fw_cdev_event_bus_reset bus_reset;

271 272
	client->version = get_info->version;
	get_info->version = FW_CDEV_VERSION;
273

274 275 276
	if (get_info->rom != 0) {
		void __user *uptr = u64_to_uptr(get_info->rom);
		size_t want = get_info->rom_length;
277
		size_t have = client->device->config_rom_length * 4;
278

279 280
		if (copy_to_user(uptr, client->device->config_rom,
				 min(want, have)))
281 282
			return -EFAULT;
	}
283
	get_info->rom_length = client->device->config_rom_length * 4;
284

285 286 287
	client->bus_reset_closure = get_info->bus_reset_closure;
	if (get_info->bus_reset != 0) {
		void __user *uptr = u64_to_uptr(get_info->bus_reset);
288

289
		fill_bus_reset_event(&bus_reset, client);
290
		if (copy_to_user(uptr, &bus_reset, sizeof(bus_reset)))
291 292
			return -EFAULT;
	}
293

294
	get_info->card = client->device->card->index;
295 296 297 298

	return 0;
}

299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345
static void
add_client_resource(struct client *client, struct client_resource *resource)
{
	unsigned long flags;

	spin_lock_irqsave(&client->lock, flags);
	list_add_tail(&resource->link, &client->resource_list);
	resource->handle = client->resource_handle++;
	spin_unlock_irqrestore(&client->lock, flags);
}

static int
release_client_resource(struct client *client, u32 handle,
			struct client_resource **resource)
{
	struct client_resource *r;
	unsigned long flags;

	spin_lock_irqsave(&client->lock, flags);
	list_for_each_entry(r, &client->resource_list, link) {
		if (r->handle == handle) {
			list_del(&r->link);
			break;
		}
	}
	spin_unlock_irqrestore(&client->lock, flags);

	if (&r->link == &client->resource_list)
		return -EINVAL;

	if (resource)
		*resource = r;
	else
		r->release(client, r);

	return 0;
}

static void
release_transaction(struct client *client, struct client_resource *resource)
{
	struct response *response =
		container_of(resource, struct response, resource);

	fw_cancel_transaction(client->device->card, &response->transaction);
}

346 347 348 349 350 351
static void
complete_transaction(struct fw_card *card, int rcode,
		     void *payload, size_t length, void *data)
{
	struct response *response = data;
	struct client *client = response->client;
352
	unsigned long flags;
353 354 355 356 357 358 359

	if (length < response->response.length)
		response->response.length = length;
	if (rcode == RCODE_COMPLETE)
		memcpy(response->response.data, payload,
		       response->response.length);

360
	spin_lock_irqsave(&client->lock, flags);
361
	list_del(&response->resource.link);
362 363
	spin_unlock_irqrestore(&client->lock, flags);

364 365 366
	response->response.type   = FW_CDEV_EVENT_RESPONSE;
	response->response.rcode  = rcode;
	queue_event(client, &response->event,
367
		    &response->response, sizeof(response->response),
368 369 370
		    response->response.data, response->response.length);
}

J
Jeff Garzik 已提交
371
static int ioctl_send_request(struct client *client, void *buffer)
372 373
{
	struct fw_device *device = client->device;
374
	struct fw_cdev_send_request *request = buffer;
375 376 377
	struct response *response;

	/* What is the biggest size we'll accept, really? */
378
	if (request->length > 4096)
379 380
		return -EINVAL;

381
	response = kmalloc(sizeof(*response) + request->length, GFP_KERNEL);
382 383 384 385
	if (response == NULL)
		return -ENOMEM;

	response->client = client;
386 387
	response->response.length = request->length;
	response->response.closure = request->closure;
388

389
	if (request->data &&
390
	    copy_from_user(response->response.data,
391
			   u64_to_uptr(request->data), request->length)) {
392 393 394 395
		kfree(response);
		return -EFAULT;
	}

396 397
	response->resource.release = release_transaction;
	add_client_resource(client, &response->resource);
398

399
	fw_send_request(device->card, &response->transaction,
400
			request->tcode & 0x1f,
401
			device->node->node_id,
402
			request->generation,
403
			device->max_speed,
404 405
			request->offset,
			response->response.data, request->length,
406 407
			complete_transaction, response);

408
	if (request->data)
409
		return sizeof(request) + request->length;
410
	else
411
		return sizeof(request);
412 413 414 415 416 417
}

struct address_handler {
	struct fw_address_handler handler;
	__u64 closure;
	struct client *client;
418
	struct client_resource resource;
419 420 421 422 423 424
};

struct request {
	struct fw_request *request;
	void *data;
	size_t length;
425
	struct client_resource resource;
426 427 428 429 430 431 432
};

struct request_event {
	struct event event;
	struct fw_cdev_event_request request;
};

433 434 435 436 437 438 439 440 441 442 443
static void
release_request(struct client *client, struct client_resource *resource)
{
	struct request *request =
		container_of(resource, struct request, resource);

	fw_send_response(client->device->card, request->request,
			 RCODE_CONFLICT_ERROR);
	kfree(request);
}

444 445 446 447 448 449 450 451 452 453 454 455
static void
handle_request(struct fw_card *card, struct fw_request *r,
	       int tcode, int destination, int source,
	       int generation, int speed,
	       unsigned long long offset,
	       void *payload, size_t length, void *callback_data)
{
	struct address_handler *handler = callback_data;
	struct request *request;
	struct request_event *e;
	struct client *client = handler->client;

456 457
	request = kmalloc(sizeof(*request), GFP_ATOMIC);
	e = kmalloc(sizeof(*e), GFP_ATOMIC);
458 459 460 461 462 463 464 465 466 467 468
	if (request == NULL || e == NULL) {
		kfree(request);
		kfree(e);
		fw_send_response(card, r, RCODE_CONFLICT_ERROR);
		return;
	}

	request->request = r;
	request->data    = payload;
	request->length  = length;

469 470
	request->resource.release = release_request;
	add_client_resource(client, &request->resource);
471 472 473 474 475

	e->request.type    = FW_CDEV_EVENT_REQUEST;
	e->request.tcode   = tcode;
	e->request.offset  = offset;
	e->request.length  = length;
476
	e->request.handle  = request->resource.handle;
477 478 479
	e->request.closure = handler->closure;

	queue_event(client, &e->event,
480
		    &e->request, sizeof(e->request), payload, length);
481 482
}

483 484 485 486 487 488 489 490 491 492 493
static void
release_address_handler(struct client *client,
			struct client_resource *resource)
{
	struct address_handler *handler =
		container_of(resource, struct address_handler, resource);

	fw_core_remove_address_handler(&handler->handler);
	kfree(handler);
}

494
static int ioctl_allocate(struct client *client, void *buffer)
495
{
496
	struct fw_cdev_allocate *request = buffer;
497 498 499
	struct address_handler *handler;
	struct fw_address_region region;

500
	handler = kmalloc(sizeof(*handler), GFP_KERNEL);
501 502 503
	if (handler == NULL)
		return -ENOMEM;

504 505 506
	region.start = request->offset;
	region.end = request->offset + request->length;
	handler->handler.length = request->length;
507 508
	handler->handler.address_callback = handle_request;
	handler->handler.callback_data = handler;
509
	handler->closure = request->closure;
510 511 512 513 514 515 516
	handler->client = client;

	if (fw_core_add_address_handler(&handler->handler, &region) < 0) {
		kfree(handler);
		return -EBUSY;
	}

517 518
	handler->resource.release = release_address_handler;
	add_client_resource(client, &handler->resource);
519
	request->handle = handler->resource.handle;
520 521 522 523

	return 0;
}

524
static int ioctl_deallocate(struct client *client, void *buffer)
525
{
526
	struct fw_cdev_deallocate *request = buffer;
527

528
	return release_client_resource(client, request->handle, NULL);
529 530
}

531
static int ioctl_send_response(struct client *client, void *buffer)
532
{
533
	struct fw_cdev_send_response *request = buffer;
534
	struct client_resource *resource;
535 536
	struct request *r;

537
	if (release_client_resource(client, request->handle, &resource) < 0)
538
		return -EINVAL;
539
	r = container_of(resource, struct request, resource);
540 541 542
	if (request->length < r->length)
		r->length = request->length;
	if (copy_from_user(r->data, u64_to_uptr(request->data), r->length))
543 544
		return -EFAULT;

545
	fw_send_response(client->device->card, r->request, request->rcode);
546 547 548 549 550
	kfree(r);

	return 0;
}

551
static int ioctl_initiate_bus_reset(struct client *client, void *buffer)
552
{
553
	struct fw_cdev_initiate_bus_reset *request = buffer;
554 555
	int short_reset;

556
	short_reset = (request->type == FW_CDEV_SHORT_RESET);
557 558 559 560

	return fw_core_initiate_bus_reset(client->device->card, short_reset);
}

561 562
struct descriptor {
	struct fw_descriptor d;
563
	struct client_resource resource;
564 565 566
	u32 data[0];
};

567 568 569 570 571 572 573 574 575 576
static void release_descriptor(struct client *client,
			       struct client_resource *resource)
{
	struct descriptor *descriptor =
		container_of(resource, struct descriptor, resource);

	fw_core_remove_descriptor(&descriptor->d);
	kfree(descriptor);
}

577
static int ioctl_add_descriptor(struct client *client, void *buffer)
578
{
579
	struct fw_cdev_add_descriptor *request = buffer;
580 581 582
	struct descriptor *descriptor;
	int retval;

583
	if (request->length > 256)
584 585 586
		return -EINVAL;

	descriptor =
587
		kmalloc(sizeof(*descriptor) + request->length * 4, GFP_KERNEL);
588 589 590 591
	if (descriptor == NULL)
		return -ENOMEM;

	if (copy_from_user(descriptor->data,
592
			   u64_to_uptr(request->data), request->length * 4)) {
593 594 595 596
		kfree(descriptor);
		return -EFAULT;
	}

597 598 599
	descriptor->d.length = request->length;
	descriptor->d.immediate = request->immediate;
	descriptor->d.key = request->key;
600 601 602 603 604 605 606 607
	descriptor->d.data = descriptor->data;

	retval = fw_core_add_descriptor(&descriptor->d);
	if (retval < 0) {
		kfree(descriptor);
		return retval;
	}

608 609
	descriptor->resource.release = release_descriptor;
	add_client_resource(client, &descriptor->resource);
610
	request->handle = descriptor->resource.handle;
611 612 613 614

	return 0;
}

615
static int ioctl_remove_descriptor(struct client *client, void *buffer)
616
{
617
	struct fw_cdev_remove_descriptor *request = buffer;
618

619
	return release_client_resource(client, request->handle, NULL);
620 621
}

622
static void
623 624
iso_callback(struct fw_iso_context *context, u32 cycle,
	     size_t header_length, void *header, void *data)
625 626
{
	struct client *client = data;
627
	struct iso_interrupt *irq;
628

629 630
	irq = kzalloc(sizeof(*irq) + header_length, GFP_ATOMIC);
	if (irq == NULL)
631 632
		return;

633 634 635 636 637 638 639
	irq->interrupt.type      = FW_CDEV_EVENT_ISO_INTERRUPT;
	irq->interrupt.closure   = client->iso_closure;
	irq->interrupt.cycle     = cycle;
	irq->interrupt.header_length = header_length;
	memcpy(irq->interrupt.header, header, header_length);
	queue_event(client, &irq->event, &irq->interrupt,
		    sizeof(irq->interrupt) + header_length, NULL, 0);
640 641
}

642
static int ioctl_create_iso_context(struct client *client, void *buffer)
643
{
644
	struct fw_cdev_create_iso_context *request = buffer;
645
	struct fw_iso_context *context;
646

647
	if (request->channel > 63)
648 649
		return -EINVAL;

650
	switch (request->type) {
651
	case FW_ISO_CONTEXT_RECEIVE:
652
		if (request->header_size < 4 || (request->header_size & 3))
653
			return -EINVAL;
654

655 656 657
		break;

	case FW_ISO_CONTEXT_TRANSMIT:
658
		if (request->speed > SCODE_3200)
659 660 661 662 663
			return -EINVAL;

		break;

	default:
664
		return -EINVAL;
665 666
	}

667 668 669 670 671 672 673 674 675
	context =  fw_iso_context_create(client->device->card,
					 request->type,
					 request->channel,
					 request->speed,
					 request->header_size,
					 iso_callback, client);
	if (IS_ERR(context))
		return PTR_ERR(context);

676
	client->iso_closure = request->closure;
677
	client->iso_context = context;
678

679 680 681
	/* We only support one context at this time. */
	request->handle = 0;

682 683 684
	return 0;
}

685 686 687 688 689 690 691 692
/* Macros for decoding the iso packet control header. */
#define GET_PAYLOAD_LENGTH(v)	((v) & 0xffff)
#define GET_INTERRUPT(v)	(((v) >> 16) & 0x01)
#define GET_SKIP(v)		(((v) >> 17) & 0x01)
#define GET_TAG(v)		(((v) >> 18) & 0x02)
#define GET_SY(v)		(((v) >> 20) & 0x04)
#define GET_HEADER_LENGTH(v)	(((v) >> 24) & 0xff)

693
static int ioctl_queue_iso(struct client *client, void *buffer)
694
{
695
	struct fw_cdev_queue_iso *request = buffer;
696
	struct fw_cdev_iso_packet __user *p, *end, *next;
697
	struct fw_iso_context *ctx = client->iso_context;
698
	unsigned long payload, buffer_end, header_length;
699
	u32 control;
700 701 702 703 704 705
	int count;
	struct {
		struct fw_iso_packet packet;
		u8 header[256];
	} u;

706
	if (ctx == NULL || request->handle != 0)
707 708
		return -EINVAL;

709 710
	/*
	 * If the user passes a non-NULL data pointer, has mmap()'ed
711 712
	 * the iso buffer, and the pointer points inside the buffer,
	 * we setup the payload pointers accordingly.  Otherwise we
713
	 * set them both to 0, which will still let packets with
714 715
	 * payload_length == 0 through.  In other words, if no packets
	 * use the indirect payload, the iso buffer need not be mapped
716 717
	 * and the request->data pointer is ignored.
	 */
718

719
	payload = (unsigned long)request->data - client->vm_start;
720
	buffer_end = client->buffer.page_count << PAGE_SHIFT;
721
	if (request->data == 0 || client->buffer.pages == NULL ||
722
	    payload >= buffer_end) {
723
		payload = 0;
724
		buffer_end = 0;
725 726
	}

A
Al Viro 已提交
727 728 729
	p = (struct fw_cdev_iso_packet __user *)u64_to_uptr(request->packets);

	if (!access_ok(VERIFY_READ, p, request->size))
730 731
		return -EFAULT;

732
	end = (void __user *)p + request->size;
733 734
	count = 0;
	while (p < end) {
735
		if (get_user(control, &p->control))
736
			return -EFAULT;
737 738 739 740 741 742
		u.packet.payload_length = GET_PAYLOAD_LENGTH(control);
		u.packet.interrupt = GET_INTERRUPT(control);
		u.packet.skip = GET_SKIP(control);
		u.packet.tag = GET_TAG(control);
		u.packet.sy = GET_SY(control);
		u.packet.header_length = GET_HEADER_LENGTH(control);
743

744
		if (ctx->type == FW_ISO_CONTEXT_TRANSMIT) {
745 746
			header_length = u.packet.header_length;
		} else {
747 748 749 750
			/*
			 * We require that header_length is a multiple of
			 * the fixed header size, ctx->header_size.
			 */
751 752 753 754
			if (ctx->header_size == 0) {
				if (u.packet.header_length > 0)
					return -EINVAL;
			} else if (u.packet.header_length % ctx->header_size != 0) {
755
				return -EINVAL;
756
			}
757 758 759
			header_length = 0;
		}

760
		next = (struct fw_cdev_iso_packet __user *)
761
			&p->header[header_length / 4];
762 763 764
		if (next > end)
			return -EINVAL;
		if (__copy_from_user
765
		    (u.packet.header, p->header, header_length))
766
			return -EFAULT;
767
		if (u.packet.skip && ctx->type == FW_ISO_CONTEXT_TRANSMIT &&
768 769
		    u.packet.header_length + u.packet.payload_length > 0)
			return -EINVAL;
770
		if (payload + u.packet.payload_length > buffer_end)
771 772
			return -EINVAL;

773 774
		if (fw_iso_context_queue(ctx, &u.packet,
					 &client->buffer, payload))
775 776 777 778 779 780 781
			break;

		p = next;
		payload += u.packet.payload_length;
		count++;
	}

782 783 784
	request->size    -= uptr_to_u64(p) - request->packets;
	request->packets  = uptr_to_u64(p);
	request->data     = client->vm_start + payload;
785 786 787 788

	return count;
}

789
static int ioctl_start_iso(struct client *client, void *buffer)
790
{
791
	struct fw_cdev_start_iso *request = buffer;
792

793 794
	if (request->handle != 0)
		return -EINVAL;
795
	if (client->iso_context->type == FW_ISO_CONTEXT_RECEIVE) {
796
		if (request->tags == 0 || request->tags > 15)
797 798
			return -EINVAL;

799
		if (request->sync > 15)
800 801 802
			return -EINVAL;
	}

803 804
	return fw_iso_context_start(client->iso_context, request->cycle,
				    request->sync, request->tags);
805 806
}

807
static int ioctl_stop_iso(struct client *client, void *buffer)
808
{
809 810 811 812 813
	struct fw_cdev_stop_iso *request = buffer;

	if (request->handle != 0)
		return -EINVAL;

814 815 816
	return fw_iso_context_stop(client->iso_context);
}

817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838
static int ioctl_get_cycle_timer(struct client *client, void *buffer)
{
	struct fw_cdev_get_cycle_timer *request = buffer;
	struct fw_card *card = client->device->card;
	unsigned long long bus_time;
	struct timeval tv;
	unsigned long flags;

	preempt_disable();
	local_irq_save(flags);

	bus_time = card->driver->get_bus_time(card);
	do_gettimeofday(&tv);

	local_irq_restore(flags);
	preempt_enable();

	request->local_time = tv.tv_sec * 1000000ULL + tv.tv_usec;
	request->cycle_timer = bus_time & 0xffffffff;
	return 0;
}

839 840 841 842 843 844 845 846 847 848 849 850 851
static int (* const ioctl_handlers[])(struct client *client, void *buffer) = {
	ioctl_get_info,
	ioctl_send_request,
	ioctl_allocate,
	ioctl_deallocate,
	ioctl_send_response,
	ioctl_initiate_bus_reset,
	ioctl_add_descriptor,
	ioctl_remove_descriptor,
	ioctl_create_iso_context,
	ioctl_queue_iso,
	ioctl_start_iso,
	ioctl_stop_iso,
852
	ioctl_get_cycle_timer,
853 854
};

855 856 857
static int
dispatch_ioctl(struct client *client, unsigned int cmd, void __user *arg)
{
858 859 860 861 862
	char buffer[256];
	int retval;

	if (_IOC_TYPE(cmd) != '#' ||
	    _IOC_NR(cmd) >= ARRAY_SIZE(ioctl_handlers))
863
		return -EINVAL;
864 865

	if (_IOC_DIR(cmd) & _IOC_WRITE) {
866
		if (_IOC_SIZE(cmd) > sizeof(buffer) ||
867 868 869 870 871 872 873 874 875
		    copy_from_user(buffer, arg, _IOC_SIZE(cmd)))
			return -EFAULT;
	}

	retval = ioctl_handlers[_IOC_NR(cmd)](client, buffer);
	if (retval < 0)
		return retval;

	if (_IOC_DIR(cmd) & _IOC_READ) {
876
		if (_IOC_SIZE(cmd) > sizeof(buffer) ||
877 878
		    copy_to_user(arg, buffer, _IOC_SIZE(cmd)))
			return -EFAULT;
879
	}
880 881

	return 0;
882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906
}

static long
fw_device_op_ioctl(struct file *file,
		   unsigned int cmd, unsigned long arg)
{
	struct client *client = file->private_data;

	return dispatch_ioctl(client, cmd, (void __user *) arg);
}

#ifdef CONFIG_COMPAT
static long
fw_device_op_compat_ioctl(struct file *file,
			  unsigned int cmd, unsigned long arg)
{
	struct client *client = file->private_data;

	return dispatch_ioctl(client, cmd, compat_ptr(arg));
}
#endif

static int fw_device_op_mmap(struct file *file, struct vm_area_struct *vma)
{
	struct client *client = file->private_data;
907 908 909 910 911 912 913 914 915 916
	enum dma_data_direction direction;
	unsigned long size;
	int page_count, retval;

	/* FIXME: We could support multiple buffers, but we don't. */
	if (client->buffer.pages != NULL)
		return -EBUSY;

	if (!(vma->vm_flags & VM_SHARED))
		return -EINVAL;
917

918
	if (vma->vm_start & ~PAGE_MASK)
919 920 921
		return -EINVAL;

	client->vm_start = vma->vm_start;
922 923 924 925 926 927 928 929 930 931 932 933 934 935
	size = vma->vm_end - vma->vm_start;
	page_count = size >> PAGE_SHIFT;
	if (size & ~PAGE_MASK)
		return -EINVAL;

	if (vma->vm_flags & VM_WRITE)
		direction = DMA_TO_DEVICE;
	else
		direction = DMA_FROM_DEVICE;

	retval = fw_iso_buffer_init(&client->buffer, client->device->card,
				    page_count, direction);
	if (retval < 0)
		return retval;
936

937 938 939 940 941
	retval = fw_iso_buffer_map(&client->buffer, vma);
	if (retval < 0)
		fw_iso_buffer_destroy(&client->buffer, client->device->card);

	return retval;
942 943 944 945 946
}

static int fw_device_op_release(struct inode *inode, struct file *file)
{
	struct client *client = file->private_data;
947
	struct event *e, *next_e;
948
	struct client_resource *r, *next_r;
949
	unsigned long flags;
950

951 952 953
	if (client->buffer.pages)
		fw_iso_buffer_destroy(&client->buffer, client->device->card);

954 955 956
	if (client->iso_context)
		fw_iso_context_destroy(client->iso_context);

957 958
	list_for_each_entry_safe(r, next_r, &client->resource_list, link)
		r->release(client, r);
959

960 961 962 963
	/*
	 * FIXME: We should wait for the async tasklets to stop
	 * running before freeing the memory.
	 */
964

965 966
	list_for_each_entry_safe(e, next_e, &client->event_list, link)
		kfree(e);
967

968 969 970 971
	spin_lock_irqsave(&client->device->card->lock, flags);
	list_del(&client->link);
	spin_unlock_irqrestore(&client->device->card->lock, flags);

972 973 974 975 976 977 978 979 980
	fw_device_put(client->device);
	kfree(client);

	return 0;
}

static unsigned int fw_device_op_poll(struct file *file, poll_table * pt)
{
	struct client *client = file->private_data;
981
	unsigned int mask = 0;
982 983 984

	poll_wait(file, &client->wait, pt);

985 986
	if (fw_device_is_shutdown(client->device))
		mask |= POLLHUP | POLLERR;
987
	if (!list_empty(&client->event_list))
988 989 990
		mask |= POLLIN | POLLRDNORM;

	return mask;
991 992
}

993
const struct file_operations fw_device_ops = {
994 995 996 997 998 999 1000 1001 1002
	.owner		= THIS_MODULE,
	.open		= fw_device_op_open,
	.read		= fw_device_op_read,
	.unlocked_ioctl	= fw_device_op_ioctl,
	.poll		= fw_device_op_poll,
	.release	= fw_device_op_release,
	.mmap		= fw_device_op_mmap,

#ifdef CONFIG_COMPAT
1003
	.compat_ioctl	= fw_device_op_compat_ioctl,
1004 1005
#endif
};