atmel_mxt_ts.c 59.3 KB
Newer Older
1
/*
2
 * Atmel maXTouch Touchscreen driver
3 4
 *
 * Copyright (C) 2010 Samsung Electronics Co.Ltd
5
 * Copyright (C) 2011-2014 Atmel Corporation
6 7
 * Copyright (C) 2012 Google, Inc.
 *
8 9 10 11 12 13 14 15 16 17
 * Author: Joonyoung Shim <jy0922.shim@samsung.com>
 *
 * This program is free software; you can redistribute  it and/or modify it
 * under  the terms of  the GNU General  Public License as published by the
 * Free Software Foundation;  either version 2 of the  License, or (at your
 * option) any later version.
 *
 */

#include <linux/module.h>
18 19
#include <linux/init.h>
#include <linux/completion.h>
20 21 22
#include <linux/delay.h>
#include <linux/firmware.h>
#include <linux/i2c.h>
23
#include <linux/i2c/atmel_mxt_ts.h>
24
#include <linux/input/mt.h>
25
#include <linux/interrupt.h>
26
#include <linux/of.h>
27
#include <linux/slab.h>
28
#include <asm/unaligned.h>
29 30

/* Version */
31 32 33
#define MXT_VER_20		20
#define MXT_VER_21		21
#define MXT_VER_22		22
34

35
/* Firmware files */
36
#define MXT_FW_NAME		"maxtouch.fw"
37 38
#define MXT_CFG_NAME		"maxtouch.cfg"
#define MXT_CFG_MAGIC		"OBP_RAW V1"
39 40

/* Registers */
41
#define MXT_INFO		0x00
42 43 44 45 46 47 48 49
#define MXT_FAMILY_ID		0x00
#define MXT_VARIANT_ID		0x01
#define MXT_VERSION		0x02
#define MXT_BUILD		0x03
#define MXT_MATRIX_X_SIZE	0x04
#define MXT_MATRIX_Y_SIZE	0x05
#define MXT_OBJECT_NUM		0x06
#define MXT_OBJECT_START	0x07
50

51
#define MXT_OBJECT_SIZE		6
52 53
#define MXT_INFO_CHECKSUM_SIZE	3
#define MXT_MAX_BLOCK_WRITE	256
54 55

/* Object types */
56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82
#define MXT_DEBUG_DIAGNOSTIC_T37	37
#define MXT_GEN_MESSAGE_T5		5
#define MXT_GEN_COMMAND_T6		6
#define MXT_GEN_POWER_T7		7
#define MXT_GEN_ACQUIRE_T8		8
#define MXT_GEN_DATASOURCE_T53		53
#define MXT_TOUCH_MULTI_T9		9
#define MXT_TOUCH_KEYARRAY_T15		15
#define MXT_TOUCH_PROXIMITY_T23		23
#define MXT_TOUCH_PROXKEY_T52		52
#define MXT_PROCI_GRIPFACE_T20		20
#define MXT_PROCG_NOISE_T22		22
#define MXT_PROCI_ONETOUCH_T24		24
#define MXT_PROCI_TWOTOUCH_T27		27
#define MXT_PROCI_GRIP_T40		40
#define MXT_PROCI_PALM_T41		41
#define MXT_PROCI_TOUCHSUPPRESSION_T42	42
#define MXT_PROCI_STYLUS_T47		47
#define MXT_PROCG_NOISESUPPRESSION_T48	48
#define MXT_SPT_COMMSCONFIG_T18		18
#define MXT_SPT_GPIOPWM_T19		19
#define MXT_SPT_SELFTEST_T25		25
#define MXT_SPT_CTECONFIG_T28		28
#define MXT_SPT_USERDATA_T38		38
#define MXT_SPT_DIGITIZER_T43		43
#define MXT_SPT_MESSAGECOUNT_T44	44
#define MXT_SPT_CTECONFIG_T46		46
83
#define MXT_TOUCH_MULTITOUCHSCREEN_T100 100
84

85 86 87
/* MXT_GEN_MESSAGE_T5 object */
#define MXT_RPTID_NOMSG		0xff

88
/* MXT_GEN_COMMAND_T6 field */
89 90 91 92 93 94
#define MXT_COMMAND_RESET	0
#define MXT_COMMAND_BACKUPNV	1
#define MXT_COMMAND_CALIBRATE	2
#define MXT_COMMAND_REPORTALL	3
#define MXT_COMMAND_DIAGNOSTIC	5

95 96
/* Define for T6 status byte */
#define MXT_T6_STATUS_RESET	(1 << 7)
97 98 99 100 101
#define MXT_T6_STATUS_OFL	(1 << 6)
#define MXT_T6_STATUS_SIGERR	(1 << 5)
#define MXT_T6_STATUS_CAL	(1 << 4)
#define MXT_T6_STATUS_CFGERR	(1 << 3)
#define MXT_T6_STATUS_COMSERR	(1 << 2)
102

103
/* MXT_GEN_POWER_T7 field */
104 105 106
#define MXT_POWER_IDLEACQINT	0
#define MXT_POWER_ACTVACQINT	1
#define MXT_POWER_ACTV2IDLETO	2
107

108
/* MXT_GEN_ACQUIRE_T8 field */
109 110 111 112 113 114 115 116
#define MXT_ACQUIRE_CHRGTIME	0
#define MXT_ACQUIRE_TCHDRIFT	2
#define MXT_ACQUIRE_DRIFTST	3
#define MXT_ACQUIRE_TCHAUTOCAL	4
#define MXT_ACQUIRE_SYNC	5
#define MXT_ACQUIRE_ATCHCALST	6
#define MXT_ACQUIRE_ATCHCALSTHR	7

117
/* MXT_TOUCH_MULTI_T9 field */
118
#define MXT_TOUCH_CTRL		0
119 120 121
#define MXT_T9_ORIENT		9
#define MXT_T9_RANGE		18

122 123 124 125 126 127 128 129 130 131
/* MXT_TOUCH_MULTI_T9 status */
#define MXT_T9_UNGRIP		(1 << 0)
#define MXT_T9_SUPPRESS		(1 << 1)
#define MXT_T9_AMP		(1 << 2)
#define MXT_T9_VECTOR		(1 << 3)
#define MXT_T9_MOVE		(1 << 4)
#define MXT_T9_RELEASE		(1 << 5)
#define MXT_T9_PRESS		(1 << 6)
#define MXT_T9_DETECT		(1 << 7)

132 133 134 135 136
struct t9_range {
	u16 x;
	u16 y;
} __packed;

137 138
/* MXT_TOUCH_MULTI_T9 orient */
#define MXT_T9_ORIENT_SWITCH	(1 << 0)
139

140
/* MXT_PROCI_GRIPFACE_T20 field */
141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169
#define MXT_GRIPFACE_CTRL	0
#define MXT_GRIPFACE_XLOGRIP	1
#define MXT_GRIPFACE_XHIGRIP	2
#define MXT_GRIPFACE_YLOGRIP	3
#define MXT_GRIPFACE_YHIGRIP	4
#define MXT_GRIPFACE_MAXTCHS	5
#define MXT_GRIPFACE_SZTHR1	7
#define MXT_GRIPFACE_SZTHR2	8
#define MXT_GRIPFACE_SHPTHR1	9
#define MXT_GRIPFACE_SHPTHR2	10
#define MXT_GRIPFACE_SUPEXTTO	11

/* MXT_PROCI_NOISE field */
#define MXT_NOISE_CTRL		0
#define MXT_NOISE_OUTFLEN	1
#define MXT_NOISE_GCAFUL_LSB	3
#define MXT_NOISE_GCAFUL_MSB	4
#define MXT_NOISE_GCAFLL_LSB	5
#define MXT_NOISE_GCAFLL_MSB	6
#define MXT_NOISE_ACTVGCAFVALID	7
#define MXT_NOISE_NOISETHR	8
#define MXT_NOISE_FREQHOPSCALE	10
#define MXT_NOISE_FREQ0		11
#define MXT_NOISE_FREQ1		12
#define MXT_NOISE_FREQ2		13
#define MXT_NOISE_FREQ3		14
#define MXT_NOISE_FREQ4		15
#define MXT_NOISE_IDLEGCAFVALID	16

170
/* MXT_SPT_COMMSCONFIG_T18 */
171 172 173
#define MXT_COMMS_CTRL		0
#define MXT_COMMS_CMD		1

174
/* MXT_SPT_CTECONFIG_T28 field */
175 176 177 178 179
#define MXT_CTE_CTRL		0
#define MXT_CTE_CMD		1
#define MXT_CTE_MODE		2
#define MXT_CTE_IDLEGCAFDEPTH	3
#define MXT_CTE_ACTVGCAFDEPTH	4
180
#define MXT_CTE_VOLTAGE		5
181 182 183 184

#define MXT_VOLTAGE_DEFAULT	2700000
#define MXT_VOLTAGE_STEP	10000

185
/* Define for MXT_GEN_COMMAND_T6 */
186
#define MXT_BOOT_VALUE		0xa5
187
#define MXT_RESET_VALUE		0x01
188
#define MXT_BACKUP_VALUE	0x55
189

190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219
/* T100 Multiple Touch Touchscreen */
#define MXT_T100_CTRL		0
#define MXT_T100_CFG1		1
#define MXT_T100_TCHAUX		3
#define MXT_T100_XRANGE		13
#define MXT_T100_YRANGE		24

#define MXT_T100_CFG_SWITCHXY	BIT(5)

#define MXT_T100_TCHAUX_VECT	BIT(0)
#define MXT_T100_TCHAUX_AMPL	BIT(1)
#define MXT_T100_TCHAUX_AREA	BIT(2)

#define MXT_T100_DETECT		BIT(7)
#define MXT_T100_TYPE_MASK	0x70

enum t100_type {
	MXT_T100_TYPE_FINGER		= 1,
	MXT_T100_TYPE_PASSIVE_STYLUS	= 2,
	MXT_T100_TYPE_HOVERING_FINGER	= 4,
	MXT_T100_TYPE_GLOVE		= 5,
	MXT_T100_TYPE_LARGE_TOUCH	= 6,
};

#define MXT_DISTANCE_ACTIVE_TOUCH	0
#define MXT_DISTANCE_HOVERING		1

#define MXT_TOUCH_MAJOR_DEFAULT		1
#define MXT_PRESSURE_DEFAULT		1

220
/* Delay times */
221 222
#define MXT_BACKUP_TIME		50	/* msec */
#define MXT_RESET_TIME		200	/* msec */
223
#define MXT_RESET_TIMEOUT	3000	/* msec */
224
#define MXT_CRC_TIMEOUT		1000	/* msec */
225 226
#define MXT_FW_RESET_TIME	3000	/* msec */
#define MXT_FW_CHG_TIMEOUT	300	/* msec */
227 228

/* Command to unlock bootloader */
229 230
#define MXT_UNLOCK_CMD_MSB	0xaa
#define MXT_UNLOCK_CMD_LSB	0xdc
231 232

/* Bootloader mode status */
233 234 235 236 237 238 239
#define MXT_WAITING_BOOTLOAD_CMD	0xc0	/* valid 7 6 bit only */
#define MXT_WAITING_FRAME_DATA	0x80	/* valid 7 6 bit only */
#define MXT_FRAME_CRC_CHECK	0x02
#define MXT_FRAME_CRC_FAIL	0x03
#define MXT_FRAME_CRC_PASS	0x04
#define MXT_APP_CRC_FAIL	0x40	/* valid 7 8 bit only */
#define MXT_BOOT_STATUS_MASK	0x3f
240 241
#define MXT_BOOT_EXTENDED_ID	(1 << 5)
#define MXT_BOOT_ID_MASK	0x1f
242 243

/* Touchscreen absolute values */
244
#define MXT_MAX_AREA		0xff
245

246 247
#define MXT_PIXELS_PER_MM	20

248
struct mxt_info {
249 250 251 252 253 254 255 256 257
	u8 family_id;
	u8 variant_id;
	u8 version;
	u8 build;
	u8 matrix_xsize;
	u8 matrix_ysize;
	u8 object_num;
};

258
struct mxt_object {
259 260
	u8 type;
	u16 start_address;
261 262
	u8 size_minus_one;
	u8 instances_minus_one;
263
	u8 num_report_ids;
264
} __packed;
265 266

/* Each client has this additional data */
267
struct mxt_data {
268 269
	struct i2c_client *client;
	struct input_dev *input_dev;
270
	char phys[64];		/* device physical location */
271 272 273
	const struct mxt_platform_data *pdata;
	struct mxt_object *object_table;
	struct mxt_info info;
274
	unsigned int irq;
275 276
	unsigned int max_x;
	unsigned int max_y;
277
	bool in_bootloader;
278
	u16 mem_size;
279 280 281
	u8 t100_aux_ampl;
	u8 t100_aux_area;
	u8 t100_aux_vect;
282
	u8 max_reportid;
283
	u32 config_crc;
284
	u32 info_crc;
285
	u8 bootloader_addr;
286
	u8 *msg_buf;
287
	u8 t6_status;
288
	bool update_input;
289 290
	u8 last_message_count;
	u8 num_touchids;
291
	u8 multitouch;
292 293

	/* Cached parameters from object table */
294
	u16 T5_address;
295
	u8 T5_msg_size;
296
	u8 T6_reportid;
297
	u16 T6_address;
298
	u16 T7_address;
299 300
	u8 T9_reportid_min;
	u8 T9_reportid_max;
301
	u8 T19_reportid;
302
	u16 T44_address;
303 304
	u8 T100_reportid_min;
	u8 T100_reportid_max;
305 306 307

	/* for fw update in bootloader */
	struct completion bl_completion;
308 309 310

	/* for reset handling */
	struct completion reset_completion;
311 312 313

	/* for config update handling */
	struct completion crc_completion;
314 315
};

316 317 318 319 320 321 322 323 324 325
static size_t mxt_obj_size(const struct mxt_object *obj)
{
	return obj->size_minus_one + 1;
}

static size_t mxt_obj_instances(const struct mxt_object *obj)
{
	return obj->instances_minus_one + 1;
}

326
static bool mxt_object_readable(unsigned int type)
327 328
{
	switch (type) {
329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352
	case MXT_GEN_COMMAND_T6:
	case MXT_GEN_POWER_T7:
	case MXT_GEN_ACQUIRE_T8:
	case MXT_GEN_DATASOURCE_T53:
	case MXT_TOUCH_MULTI_T9:
	case MXT_TOUCH_KEYARRAY_T15:
	case MXT_TOUCH_PROXIMITY_T23:
	case MXT_TOUCH_PROXKEY_T52:
	case MXT_PROCI_GRIPFACE_T20:
	case MXT_PROCG_NOISE_T22:
	case MXT_PROCI_ONETOUCH_T24:
	case MXT_PROCI_TWOTOUCH_T27:
	case MXT_PROCI_GRIP_T40:
	case MXT_PROCI_PALM_T41:
	case MXT_PROCI_TOUCHSUPPRESSION_T42:
	case MXT_PROCI_STYLUS_T47:
	case MXT_PROCG_NOISESUPPRESSION_T48:
	case MXT_SPT_COMMSCONFIG_T18:
	case MXT_SPT_GPIOPWM_T19:
	case MXT_SPT_SELFTEST_T25:
	case MXT_SPT_CTECONFIG_T28:
	case MXT_SPT_USERDATA_T38:
	case MXT_SPT_DIGITIZER_T43:
	case MXT_SPT_CTECONFIG_T46:
353 354 355 356 357 358
		return true;
	default:
		return false;
	}
}

359
static void mxt_dump_message(struct mxt_data *data, u8 *message)
360
{
361 362
	dev_dbg(&data->client->dev, "message: %*ph\n",
		data->T5_msg_size, message);
363 364
}

365 366 367
static int mxt_wait_for_completion(struct mxt_data *data,
				   struct completion *comp,
				   unsigned int timeout_ms)
368 369 370 371 372 373 374 375 376 377 378 379 380 381 382
{
	struct device *dev = &data->client->dev;
	unsigned long timeout = msecs_to_jiffies(timeout_ms);
	long ret;

	ret = wait_for_completion_interruptible_timeout(comp, timeout);
	if (ret < 0) {
		return ret;
	} else if (ret == 0) {
		dev_err(dev, "Wait for completion timed out.\n");
		return -ETIMEDOUT;
	}
	return 0;
}

383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429
static int mxt_bootloader_read(struct mxt_data *data,
			       u8 *val, unsigned int count)
{
	int ret;
	struct i2c_msg msg;

	msg.addr = data->bootloader_addr;
	msg.flags = data->client->flags & I2C_M_TEN;
	msg.flags |= I2C_M_RD;
	msg.len = count;
	msg.buf = val;

	ret = i2c_transfer(data->client->adapter, &msg, 1);
	if (ret == 1) {
		ret = 0;
	} else {
		ret = ret < 0 ? ret : -EIO;
		dev_err(&data->client->dev, "%s: i2c recv failed (%d)\n",
			__func__, ret);
	}

	return ret;
}

static int mxt_bootloader_write(struct mxt_data *data,
				const u8 * const val, unsigned int count)
{
	int ret;
	struct i2c_msg msg;

	msg.addr = data->bootloader_addr;
	msg.flags = data->client->flags & I2C_M_TEN;
	msg.len = count;
	msg.buf = (u8 *)val;

	ret = i2c_transfer(data->client->adapter, &msg, 1);
	if (ret == 1) {
		ret = 0;
	} else {
		ret = ret < 0 ? ret : -EIO;
		dev_err(&data->client->dev, "%s: i2c send failed (%d)\n",
			__func__, ret);
	}

	return ret;
}

430
static int mxt_lookup_bootloader_address(struct mxt_data *data, bool retry)
431 432 433 434 435 436 437
{
	u8 appmode = data->client->addr;
	u8 bootloader;

	switch (appmode) {
	case 0x4a:
	case 0x4b:
438
		/* Chips after 1664S use different scheme */
439
		if (retry || data->info.family_id >= 0xa2) {
440 441 442 443
			bootloader = appmode - 0x24;
			break;
		}
		/* Fall through for normal case */
444 445 446 447 448 449
	case 0x4c:
	case 0x4d:
	case 0x5a:
	case 0x5b:
		bootloader = appmode - 0x26;
		break;
450

451 452 453 454 455 456 457 458 459 460 461
	default:
		dev_err(&data->client->dev,
			"Appmode i2c address 0x%02x not found\n",
			appmode);
		return -EINVAL;
	}

	data->bootloader_addr = bootloader;
	return 0;
}

462
static int mxt_probe_bootloader(struct mxt_data *data, bool alt_address)
463 464
{
	struct device *dev = &data->client->dev;
465
	int error;
466 467 468
	u8 val;
	bool crc_failure;

469 470 471
	error = mxt_lookup_bootloader_address(data, alt_address);
	if (error)
		return error;
472

473 474 475
	error = mxt_bootloader_read(data, &val, 1);
	if (error)
		return error;
476 477 478 479 480 481 482 483 484 485

	/* Check app crc fail mode */
	crc_failure = (val & ~MXT_BOOT_STATUS_MASK) == MXT_APP_CRC_FAIL;

	dev_err(dev, "Detected bootloader, status:%02X%s\n",
			val, crc_failure ? ", APP_CRC_FAIL" : "");

	return 0;
}

486 487 488 489 490 491 492 493
static u8 mxt_get_bootloader_version(struct mxt_data *data, u8 val)
{
	struct device *dev = &data->client->dev;
	u8 buf[3];

	if (val & MXT_BOOT_EXTENDED_ID) {
		if (mxt_bootloader_read(data, &buf[0], 3) != 0) {
			dev_err(dev, "%s: i2c failure\n", __func__);
494
			return val;
495 496 497 498 499 500 501 502 503 504 505 506
		}

		dev_dbg(dev, "Bootloader ID:%d Version:%d\n", buf[1], buf[2]);

		return buf[0];
	} else {
		dev_dbg(dev, "Bootloader ID:%d\n", val & MXT_BOOT_ID_MASK);

		return val;
	}
}

507 508
static int mxt_check_bootloader(struct mxt_data *data, unsigned int state,
				bool wait)
509
{
510
	struct device *dev = &data->client->dev;
511
	u8 val;
512
	int ret;
513 514

recheck:
515
	if (wait) {
516 517 518 519 520 521
		/*
		 * In application update mode, the interrupt
		 * line signals state transitions. We must wait for the
		 * CHG assertion before reading the status byte.
		 * Once the status byte has been read, the line is deasserted.
		 */
522 523
		ret = mxt_wait_for_completion(data, &data->bl_completion,
					      MXT_FW_CHG_TIMEOUT);
524 525 526 527 528 529 530
		if (ret) {
			/*
			 * TODO: handle -ERESTARTSYS better by terminating
			 * fw update process before returning to userspace
			 * by writing length 0x000 to device (iff we are in
			 * WAITING_FRAME_DATA state).
			 */
531
			dev_err(dev, "Update wait error %d\n", ret);
532 533 534 535
			return ret;
		}
	}

536 537 538
	ret = mxt_bootloader_read(data, &val, 1);
	if (ret)
		return ret;
539

540 541 542
	if (state == MXT_WAITING_BOOTLOAD_CMD)
		val = mxt_get_bootloader_version(data, val);

543
	switch (state) {
544 545
	case MXT_WAITING_BOOTLOAD_CMD:
	case MXT_WAITING_FRAME_DATA:
546
	case MXT_APP_CRC_FAIL:
547
		val &= ~MXT_BOOT_STATUS_MASK;
548
		break;
549
	case MXT_FRAME_CRC_PASS:
550
		if (val == MXT_FRAME_CRC_CHECK) {
551
			goto recheck;
552 553 554 555
		} else if (val == MXT_FRAME_CRC_FAIL) {
			dev_err(dev, "Bootloader CRC fail\n");
			return -EINVAL;
		}
556 557 558 559 560 561
		break;
	default:
		return -EINVAL;
	}

	if (val != state) {
562
		dev_err(dev, "Invalid bootloader state %02X != %02X\n",
563
			val, state);
564 565 566 567 568 569
		return -EINVAL;
	}

	return 0;
}

570
static int mxt_send_bootloader_cmd(struct mxt_data *data, bool unlock)
571
{
572
	int ret;
573 574
	u8 buf[2];

575 576 577 578 579 580 581
	if (unlock) {
		buf[0] = MXT_UNLOCK_CMD_LSB;
		buf[1] = MXT_UNLOCK_CMD_MSB;
	} else {
		buf[0] = 0x01;
		buf[1] = 0x01;
	}
582

583 584 585
	ret = mxt_bootloader_write(data, buf, 2);
	if (ret)
		return ret;
586 587 588 589

	return 0;
}

590
static int __mxt_read_reg(struct i2c_client *client,
591 592 593 594
			       u16 reg, u16 len, void *val)
{
	struct i2c_msg xfer[2];
	u8 buf[2];
595
	int ret;
596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611

	buf[0] = reg & 0xff;
	buf[1] = (reg >> 8) & 0xff;

	/* Write register */
	xfer[0].addr = client->addr;
	xfer[0].flags = 0;
	xfer[0].len = 2;
	xfer[0].buf = buf;

	/* Read data */
	xfer[1].addr = client->addr;
	xfer[1].flags = I2C_M_RD;
	xfer[1].len = len;
	xfer[1].buf = val;

612 613 614 615 616 617 618 619
	ret = i2c_transfer(client->adapter, xfer, 2);
	if (ret == 2) {
		ret = 0;
	} else {
		if (ret >= 0)
			ret = -EIO;
		dev_err(&client->dev, "%s: i2c transfer failed (%d)\n",
			__func__, ret);
620 621
	}

622
	return ret;
623 624
}

625 626
static int __mxt_write_reg(struct i2c_client *client, u16 reg, u16 len,
			   const void *val)
627
{
628 629
	u8 *buf;
	size_t count;
630
	int ret;
631

632 633 634 635
	count = len + 2;
	buf = kmalloc(count, GFP_KERNEL);
	if (!buf)
		return -ENOMEM;
636 637 638

	buf[0] = reg & 0xff;
	buf[1] = (reg >> 8) & 0xff;
639
	memcpy(&buf[2], val, len);
640

641 642
	ret = i2c_master_send(client, buf, count);
	if (ret == count) {
643 644 645 646 647 648
		ret = 0;
	} else {
		if (ret >= 0)
			ret = -EIO;
		dev_err(&client->dev, "%s: i2c send failed (%d)\n",
			__func__, ret);
649 650
	}

651
	kfree(buf);
652
	return ret;
653 654
}

655
static int mxt_write_reg(struct i2c_client *client, u16 reg, u8 val)
656
{
657
	return __mxt_write_reg(client, reg, 1, &val);
658 659
}

660 661
static struct mxt_object *
mxt_get_object(struct mxt_data *data, u8 type)
662
{
663
	struct mxt_object *object;
664 665 666 667 668 669 670 671
	int i;

	for (i = 0; i < data->info.object_num; i++) {
		object = data->object_table + i;
		if (object->type == type)
			return object;
	}

672
	dev_warn(&data->client->dev, "Invalid object type T%u\n", type);
673 674 675
	return NULL;
}

676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708
static void mxt_proc_t6_messages(struct mxt_data *data, u8 *msg)
{
	struct device *dev = &data->client->dev;
	u8 status = msg[1];
	u32 crc = msg[2] | (msg[3] << 8) | (msg[4] << 16);

	complete(&data->crc_completion);

	if (crc != data->config_crc) {
		data->config_crc = crc;
		dev_dbg(dev, "T6 Config Checksum: 0x%06X\n", crc);
	}

	/* Detect reset */
	if (status & MXT_T6_STATUS_RESET)
		complete(&data->reset_completion);

	/* Output debug if status has changed */
	if (status != data->t6_status)
		dev_dbg(dev, "T6 Status 0x%02X%s%s%s%s%s%s%s\n",
			status,
			status == 0 ? " OK" : "",
			status & MXT_T6_STATUS_RESET ? " RESET" : "",
			status & MXT_T6_STATUS_OFL ? " OFL" : "",
			status & MXT_T6_STATUS_SIGERR ? " SIGERR" : "",
			status & MXT_T6_STATUS_CAL ? " CAL" : "",
			status & MXT_T6_STATUS_CFGERR ? " CFGERR" : "",
			status & MXT_T6_STATUS_COMSERR ? " COMSERR" : "");

	/* Save current status */
	data->t6_status = status;
}

709 710 711 712 713 714 715 716 717 718 719 720 721 722
static int mxt_write_object(struct mxt_data *data,
				 u8 type, u8 offset, u8 val)
{
	struct mxt_object *object;
	u16 reg;

	object = mxt_get_object(data, type);
	if (!object || offset >= mxt_obj_size(object))
		return -EINVAL;

	reg = object->start_address;
	return mxt_write_reg(data->client, reg + offset, val);
}

723
static void mxt_input_button(struct mxt_data *data, u8 *message)
724 725
{
	struct input_dev *input = data->input_dev;
726
	const struct mxt_platform_data *pdata = data->pdata;
727 728 729 730
	bool button;
	int i;

	/* Active-low switch */
731 732
	for (i = 0; i < pdata->t19_num_keys; i++) {
		if (pdata->t19_keymap[i] == KEY_RESERVED)
733
			continue;
734
		button = !(message[1] & (1 << i));
735
		input_report_key(input, pdata->t19_keymap[i], button);
736 737 738
	}
}

739
static void mxt_input_sync(struct mxt_data *data)
740
{
741 742 743
	input_mt_report_pointer_emulation(data->input_dev,
					  data->pdata->t19_num_keys);
	input_sync(data->input_dev);
744 745
}

746
static void mxt_proc_t9_message(struct mxt_data *data, u8 *message)
747 748
{
	struct device *dev = &data->client->dev;
749
	struct input_dev *input_dev = data->input_dev;
750 751
	int id;
	u8 status;
752 753 754
	int x;
	int y;
	int area;
755
	int amplitude;
756

757 758 759 760
	id = message[0] - data->T9_reportid_min;
	status = message[1];
	x = (message[2] << 4) | ((message[4] >> 4) & 0xf);
	y = (message[3] << 4) | ((message[4] & 0xf));
761 762

	/* Handle 10/12 bit switching */
763
	if (data->max_x < 1024)
764
		x >>= 2;
765
	if (data->max_y < 1024)
766
		y >>= 2;
767

768 769
	area = message[5];
	amplitude = message[6];
770

771 772 773
	dev_dbg(dev,
		"[%u] %c%c%c%c%c%c%c%c x: %5u y: %5u area: %3u amp: %3u\n",
		id,
774 775 776 777 778 779 780 781
		(status & MXT_T9_DETECT) ? 'D' : '.',
		(status & MXT_T9_PRESS) ? 'P' : '.',
		(status & MXT_T9_RELEASE) ? 'R' : '.',
		(status & MXT_T9_MOVE) ? 'M' : '.',
		(status & MXT_T9_VECTOR) ? 'V' : '.',
		(status & MXT_T9_AMP) ? 'A' : '.',
		(status & MXT_T9_SUPPRESS) ? 'S' : '.',
		(status & MXT_T9_UNGRIP) ? 'U' : '.',
782
		x, y, area, amplitude);
783

784 785
	input_mt_slot(input_dev, id);

786
	if (status & MXT_T9_DETECT) {
787 788 789 790 791 792 793 794
		/*
		 * Multiple bits may be set if the host is slow to read
		 * the status messages, indicating all the events that
		 * have happened.
		 */
		if (status & MXT_T9_RELEASE) {
			input_mt_report_slot_state(input_dev,
						   MT_TOOL_FINGER, 0);
795
			mxt_input_sync(data);
796 797 798 799
		}

		/* Touch active */
		input_mt_report_slot_state(input_dev, MT_TOOL_FINGER, 1);
800 801
		input_report_abs(input_dev, ABS_MT_POSITION_X, x);
		input_report_abs(input_dev, ABS_MT_POSITION_Y, y);
802
		input_report_abs(input_dev, ABS_MT_PRESSURE, amplitude);
803
		input_report_abs(input_dev, ABS_MT_TOUCH_MAJOR, area);
804 805 806
	} else {
		/* Touch no longer active, close out slot */
		input_mt_report_slot_state(input_dev, MT_TOOL_FINGER, 0);
807
	}
808 809

	data->update_input = true;
810 811
}

812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919
static void mxt_proc_t100_message(struct mxt_data *data, u8 *message)
{
	struct device *dev = &data->client->dev;
	struct input_dev *input_dev = data->input_dev;
	int id;
	u8 status;
	u8 type = 0;
	u16 x;
	u16 y;
	int distance = 0;
	int tool = 0;
	u8 major = 0;
	u8 pressure = 0;
	u8 orientation = 0;

	id = message[0] - data->T100_reportid_min - 2;

	/* ignore SCRSTATUS events */
	if (id < 0)
		return;

	status = message[1];
	x = get_unaligned_le16(&message[2]);
	y = get_unaligned_le16(&message[4]);

	if (status & MXT_T100_DETECT) {
		type = (status & MXT_T100_TYPE_MASK) >> 4;

		switch (type) {
		case MXT_T100_TYPE_HOVERING_FINGER:
			tool = MT_TOOL_FINGER;
			distance = MXT_DISTANCE_HOVERING;

			if (data->t100_aux_vect)
				orientation = message[data->t100_aux_vect];

			break;

		case MXT_T100_TYPE_FINGER:
		case MXT_T100_TYPE_GLOVE:
			tool = MT_TOOL_FINGER;
			distance = MXT_DISTANCE_ACTIVE_TOUCH;

			if (data->t100_aux_area)
				major = message[data->t100_aux_area];

			if (data->t100_aux_ampl)
				pressure = message[data->t100_aux_ampl];

			if (data->t100_aux_vect)
				orientation = message[data->t100_aux_vect];

			break;

		case MXT_T100_TYPE_PASSIVE_STYLUS:
			tool = MT_TOOL_PEN;

			/*
			 * Passive stylus is reported with size zero so
			 * hardcode.
			 */
			major = MXT_TOUCH_MAJOR_DEFAULT;

			if (data->t100_aux_ampl)
				pressure = message[data->t100_aux_ampl];

			break;

		case MXT_T100_TYPE_LARGE_TOUCH:
			/* Ignore suppressed touch */
			break;

		default:
			dev_dbg(dev, "Unexpected T100 type\n");
			return;
		}
	}

	/*
	 * Values reported should be non-zero if tool is touching the
	 * device
	 */
	if (!pressure && type != MXT_T100_TYPE_HOVERING_FINGER)
		pressure = MXT_PRESSURE_DEFAULT;

	input_mt_slot(input_dev, id);

	if (status & MXT_T100_DETECT) {
		dev_dbg(dev, "[%u] type:%u x:%u y:%u a:%02X p:%02X v:%02X\n",
			id, type, x, y, major, pressure, orientation);

		input_mt_report_slot_state(input_dev, tool, 1);
		input_report_abs(input_dev, ABS_MT_POSITION_X, x);
		input_report_abs(input_dev, ABS_MT_POSITION_Y, y);
		input_report_abs(input_dev, ABS_MT_TOUCH_MAJOR, major);
		input_report_abs(input_dev, ABS_MT_PRESSURE, pressure);
		input_report_abs(input_dev, ABS_MT_DISTANCE, distance);
		input_report_abs(input_dev, ABS_MT_ORIENTATION, orientation);
	} else {
		dev_dbg(dev, "[%u] release\n", id);

		/* close out slot */
		input_mt_report_slot_state(input_dev, 0, 0);
	}

	data->update_input = true;
}

920
static int mxt_proc_message(struct mxt_data *data, u8 *message)
921
{
922 923 924 925 926 927 928 929 930 931 932 933 934
	u8 report_id = message[0];

	if (report_id == MXT_RPTID_NOMSG)
		return 0;

	if (report_id == data->T6_reportid) {
		mxt_proc_t6_messages(data, message);
	} else if (!data->input_dev) {
		/*
		 * Do not report events if input device
		 * is not yet registered.
		 */
		mxt_dump_message(data, message);
935 936
	} else if (report_id >= data->T9_reportid_min &&
		   report_id <= data->T9_reportid_max) {
937
		mxt_proc_t9_message(data, message);
938 939 940
	} else if (report_id >= data->T100_reportid_min &&
		   report_id <= data->T100_reportid_max) {
		mxt_proc_t100_message(data, message);
941 942 943 944 945 946 947 948
	} else if (report_id == data->T19_reportid) {
		mxt_input_button(data, message);
		data->update_input = true;
	} else {
		mxt_dump_message(data, message);
	}

	return 1;
949 950
}

951
static int mxt_read_and_process_messages(struct mxt_data *data, u8 count)
952 953
{
	struct device *dev = &data->client->dev;
954
	int ret;
955 956 957 958 959 960
	int i;
	u8 num_valid = 0;

	/* Safety check for msg_buf */
	if (count > data->max_reportid)
		return -EINVAL;
961

962
	/* Process remaining messages if necessary */
963
	ret = __mxt_read_reg(data->client, data->T5_address,
964
				data->T5_msg_size * count, data->msg_buf);
965
	if (ret) {
966
		dev_err(dev, "Failed to read %u messages (%d)\n", count, ret);
967 968
		return ret;
	}
969

970 971 972 973 974 975 976 977 978 979
	for (i = 0;  i < count; i++) {
		ret = mxt_proc_message(data,
			data->msg_buf + data->T5_msg_size * i);

		if (ret == 1)
			num_valid++;
	}

	/* return number of messages read */
	return num_valid;
980
}
981

982
static irqreturn_t mxt_process_messages_t44(struct mxt_data *data)
983
{
984
	struct device *dev = &data->client->dev;
985
	int ret;
986
	u8 count, num_left;
987

988 989 990 991 992 993 994 995 996 997 998
	/* Read T44 and T5 together */
	ret = __mxt_read_reg(data->client, data->T44_address,
		data->T5_msg_size + 1, data->msg_buf);
	if (ret) {
		dev_err(dev, "Failed to read T44 and T5 (%d)\n", ret);
		return IRQ_NONE;
	}

	count = data->msg_buf[0];

	if (count == 0) {
999 1000 1001 1002 1003 1004
		/*
		 * This condition is caused by the CHG line being configured
		 * in Mode 0. It results in unnecessary I2C operations but it
		 * is benign.
		 */
		dev_dbg(dev, "Interrupt triggered but zero messages\n");
1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022
		return IRQ_NONE;
	} else if (count > data->max_reportid) {
		dev_err(dev, "T44 count %d exceeded max report id\n", count);
		count = data->max_reportid;
	}

	/* Process first message */
	ret = mxt_proc_message(data, data->msg_buf + 1);
	if (ret < 0) {
		dev_warn(dev, "Unexpected invalid message\n");
		return IRQ_NONE;
	}

	num_left = count - 1;

	/* Process remaining messages if necessary */
	if (num_left) {
		ret = mxt_read_and_process_messages(data, num_left);
1023
		if (ret < 0)
1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081
			goto end;
		else if (ret != num_left)
			dev_warn(dev, "Unexpected invalid message\n");
	}

end:
	if (data->update_input) {
		mxt_input_sync(data);
		data->update_input = false;
	}

	return IRQ_HANDLED;
}

static int mxt_process_messages_until_invalid(struct mxt_data *data)
{
	struct device *dev = &data->client->dev;
	int count, read;
	u8 tries = 2;

	count = data->max_reportid;

	/* Read messages until we force an invalid */
	do {
		read = mxt_read_and_process_messages(data, count);
		if (read < count)
			return 0;
	} while (--tries);

	if (data->update_input) {
		mxt_input_sync(data);
		data->update_input = false;
	}

	dev_err(dev, "CHG pin isn't cleared\n");
	return -EBUSY;
}

static irqreturn_t mxt_process_messages(struct mxt_data *data)
{
	int total_handled, num_handled;
	u8 count = data->last_message_count;

	if (count < 1 || count > data->max_reportid)
		count = 1;

	/* include final invalid message */
	total_handled = mxt_read_and_process_messages(data, count + 1);
	if (total_handled < 0)
		return IRQ_NONE;
	/* if there were invalid messages, then we are done */
	else if (total_handled <= count)
		goto update_count;

	/* keep reading two msgs until one is invalid or reportid limit */
	do {
		num_handled = mxt_read_and_process_messages(data, 2);
		if (num_handled < 0)
1082
			return IRQ_NONE;
1083 1084 1085 1086 1087 1088 1089 1090 1091

		total_handled += num_handled;

		if (num_handled < 2)
			break;
	} while (total_handled < data->num_touchids);

update_count:
	data->last_message_count = total_handled;
1092 1093

	if (data->update_input) {
1094
		mxt_input_sync(data);
1095 1096
		data->update_input = false;
	}
1097

1098 1099 1100
	return IRQ_HANDLED;
}

1101 1102 1103 1104 1105 1106 1107 1108 1109 1110
static irqreturn_t mxt_interrupt(int irq, void *dev_id)
{
	struct mxt_data *data = dev_id;

	if (data->in_bootloader) {
		/* bootloader state transition completion */
		complete(&data->bl_completion);
		return IRQ_HANDLED;
	}

1111 1112 1113
	if (!data->object_table)
		return IRQ_HANDLED;

1114 1115 1116 1117 1118
	if (data->T44_address) {
		return mxt_process_messages_t44(data);
	} else {
		return mxt_process_messages(data);
	}
1119 1120
}

1121 1122 1123 1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172 1173
static int mxt_t6_command(struct mxt_data *data, u16 cmd_offset,
			  u8 value, bool wait)
{
	u16 reg;
	u8 command_register;
	int timeout_counter = 0;
	int ret;

	reg = data->T6_address + cmd_offset;

	ret = mxt_write_reg(data->client, reg, value);
	if (ret)
		return ret;

	if (!wait)
		return 0;

	do {
		msleep(20);
		ret = __mxt_read_reg(data->client, reg, 1, &command_register);
		if (ret)
			return ret;
	} while (command_register != 0 && timeout_counter++ <= 100);

	if (timeout_counter > 100) {
		dev_err(&data->client->dev, "Command failed!\n");
		return -EIO;
	}

	return 0;
}

static int mxt_soft_reset(struct mxt_data *data)
{
	struct device *dev = &data->client->dev;
	int ret = 0;

	dev_info(dev, "Resetting chip\n");

	reinit_completion(&data->reset_completion);

	ret = mxt_t6_command(data, MXT_COMMAND_RESET, MXT_RESET_VALUE, false);
	if (ret)
		return ret;

	ret = mxt_wait_for_completion(data, &data->reset_completion,
				      MXT_RESET_TIMEOUT);
	if (ret)
		return ret;

	return 0;
}

1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191
static void mxt_update_crc(struct mxt_data *data, u8 cmd, u8 value)
{
	/*
	 * On failure, CRC is set to 0 and config will always be
	 * downloaded.
	 */
	data->config_crc = 0;
	reinit_completion(&data->crc_completion);

	mxt_t6_command(data, cmd, value, true);

	/*
	 * Wait for crc message. On failure, CRC is set to 0 and config will
	 * always be downloaded.
	 */
	mxt_wait_for_completion(data, &data->crc_completion, MXT_CRC_TIMEOUT);
}

1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230
static void mxt_calc_crc24(u32 *crc, u8 firstbyte, u8 secondbyte)
{
	static const unsigned int crcpoly = 0x80001B;
	u32 result;
	u32 data_word;

	data_word = (secondbyte << 8) | firstbyte;
	result = ((*crc << 1) ^ data_word);

	if (result & 0x1000000)
		result ^= crcpoly;

	*crc = result;
}

static u32 mxt_calculate_crc(u8 *base, off_t start_off, off_t end_off)
{
	u32 crc = 0;
	u8 *ptr = base + start_off;
	u8 *last_val = base + end_off - 1;

	if (end_off < start_off)
		return -EINVAL;

	while (ptr < last_val) {
		mxt_calc_crc24(&crc, *ptr, *(ptr + 1));
		ptr += 2;
	}

	/* if len is odd, fill the last byte with 0 */
	if (ptr == last_val)
		mxt_calc_crc24(&crc, *ptr, 0);

	/* Mask to 24-bit */
	crc &= 0x00FFFFFF;

	return crc;
}

1231 1232 1233 1234 1235 1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264
static int mxt_prepare_cfg_mem(struct mxt_data *data,
			       const struct firmware *cfg,
			       unsigned int data_pos,
			       unsigned int cfg_start_ofs,
			       u8 *config_mem,
			       size_t config_mem_size)
{
	struct device *dev = &data->client->dev;
	struct mxt_object *object;
	unsigned int type, instance, size, byte_offset;
	int offset;
	int ret;
	int i;
	u16 reg;
	u8 val;

	while (data_pos < cfg->size) {
		/* Read type, instance, length */
		ret = sscanf(cfg->data + data_pos, "%x %x %x%n",
			     &type, &instance, &size, &offset);
		if (ret == 0) {
			/* EOF */
			break;
		} else if (ret != 3) {
			dev_err(dev, "Bad format: failed to parse object\n");
			return -EINVAL;
		}
		data_pos += offset;

		object = mxt_get_object(data, type);
		if (!object) {
			/* Skip object */
			for (i = 0; i < size; i++) {
				ret = sscanf(cfg->data + data_pos, "%hhx%n",
1265 1266 1267 1268 1269 1270
					     &val, &offset);
				if (ret != 1) {
					dev_err(dev, "Bad format in T%d at %d\n",
						type, i);
					return -EINVAL;
				}
1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300 1301 1302 1303 1304 1305 1306 1307 1308 1309
				data_pos += offset;
			}
			continue;
		}

		if (size > mxt_obj_size(object)) {
			/*
			 * Either we are in fallback mode due to wrong
			 * config or config from a later fw version,
			 * or the file is corrupt or hand-edited.
			 */
			dev_warn(dev, "Discarding %zu byte(s) in T%u\n",
				 size - mxt_obj_size(object), type);
		} else if (mxt_obj_size(object) > size) {
			/*
			 * If firmware is upgraded, new bytes may be added to
			 * end of objects. It is generally forward compatible
			 * to zero these bytes - previous behaviour will be
			 * retained. However this does invalidate the CRC and
			 * will force fallback mode until the configuration is
			 * updated. We warn here but do nothing else - the
			 * malloc has zeroed the entire configuration.
			 */
			dev_warn(dev, "Zeroing %zu byte(s) in T%d\n",
				 mxt_obj_size(object) - size, type);
		}

		if (instance >= mxt_obj_instances(object)) {
			dev_err(dev, "Object instances exceeded!\n");
			return -EINVAL;
		}

		reg = object->start_address + mxt_obj_size(object) * instance;

		for (i = 0; i < size; i++) {
			ret = sscanf(cfg->data + data_pos, "%hhx%n",
				     &val,
				     &offset);
			if (ret != 1) {
1310 1311
				dev_err(dev, "Bad format in T%d at %d\n",
					type, i);
1312 1313 1314 1315 1316 1317 1318 1319 1320
				return -EINVAL;
			}
			data_pos += offset;

			if (i > mxt_obj_size(object))
				continue;

			byte_offset = reg + i - cfg_start_ofs;

1321
			if (byte_offset >= 0 && byte_offset < config_mem_size) {
1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361
				*(config_mem + byte_offset) = val;
			} else {
				dev_err(dev, "Bad object: reg:%d, T%d, ofs=%d\n",
					reg, object->type, byte_offset);
				return -EINVAL;
			}
		}
	}

	return 0;
}

static int mxt_upload_cfg_mem(struct mxt_data *data, unsigned int cfg_start,
			      u8 *config_mem, size_t config_mem_size)
{
	unsigned int byte_offset = 0;
	int error;

	/* Write configuration as blocks */
	while (byte_offset < config_mem_size) {
		unsigned int size = config_mem_size - byte_offset;

		if (size > MXT_MAX_BLOCK_WRITE)
			size = MXT_MAX_BLOCK_WRITE;

		error = __mxt_write_reg(data->client,
					cfg_start + byte_offset,
					size, config_mem + byte_offset);
		if (error) {
			dev_err(&data->client->dev,
				"Config write error, ret=%d\n", error);
			return error;
		}

		byte_offset += size;
	}

	return 0;
}

1362 1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379 1380 1381
/*
 * mxt_update_cfg - download configuration to chip
 *
 * Atmel Raw Config File Format
 *
 * The first four lines of the raw config file contain:
 *  1) Version
 *  2) Chip ID Information (first 7 bytes of device memory)
 *  3) Chip Information Block 24-bit CRC Checksum
 *  4) Chip Configuration 24-bit CRC Checksum
 *
 * The rest of the file consists of one line per object instance:
 *   <TYPE> <INSTANCE> <SIZE> <CONTENTS>
 *
 *   <TYPE> - 2-byte object type as hex
 *   <INSTANCE> - 2-byte object instance number as hex
 *   <SIZE> - 2-byte object size as hex
 *   <CONTENTS> - array of <SIZE> 1-byte hex values
 */
static int mxt_update_cfg(struct mxt_data *data, const struct firmware *cfg)
1382 1383
{
	struct device *dev = &data->client->dev;
1384
	struct mxt_info cfg_info;
1385
	int ret;
1386
	int offset;
1387
	int data_pos;
1388
	int i;
1389 1390 1391 1392
	int cfg_start_ofs;
	u32 info_crc, config_crc, calculated_crc;
	u8 *config_mem;
	size_t config_mem_size;
1393

1394 1395 1396 1397
	mxt_update_crc(data, MXT_COMMAND_REPORTALL, 1);

	if (strncmp(cfg->data, MXT_CFG_MAGIC, strlen(MXT_CFG_MAGIC))) {
		dev_err(dev, "Unrecognised config file\n");
1398
		return -EINVAL;
1399 1400
	}

1401
	data_pos = strlen(MXT_CFG_MAGIC);
1402 1403 1404

	/* Load information block and check */
	for (i = 0; i < sizeof(struct mxt_info); i++) {
1405
		ret = sscanf(cfg->data + data_pos, "%hhx%n",
1406 1407 1408 1409
			     (unsigned char *)&cfg_info + i,
			     &offset);
		if (ret != 1) {
			dev_err(dev, "Bad format\n");
1410
			return -EINVAL;
1411
		}
1412

1413
		data_pos += offset;
1414 1415
	}

1416 1417
	if (cfg_info.family_id != data->info.family_id) {
		dev_err(dev, "Family ID mismatch!\n");
1418
		return -EINVAL;
1419
	}
1420

1421 1422
	if (cfg_info.variant_id != data->info.variant_id) {
		dev_err(dev, "Variant ID mismatch!\n");
1423
		return -EINVAL;
1424
	}
1425

1426 1427
	/* Read CRCs */
	ret = sscanf(cfg->data + data_pos, "%x%n", &info_crc, &offset);
1428 1429
	if (ret != 1) {
		dev_err(dev, "Bad format: failed to parse Info CRC\n");
1430
		return -EINVAL;
1431
	}
1432
	data_pos += offset;
1433

1434
	ret = sscanf(cfg->data + data_pos, "%x%n", &config_crc, &offset);
1435 1436
	if (ret != 1) {
		dev_err(dev, "Bad format: failed to parse Config CRC\n");
1437
		return -EINVAL;
1438
	}
1439
	data_pos += offset;
1440

1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452
	/*
	 * The Info Block CRC is calculated over mxt_info and the object
	 * table. If it does not match then we are trying to load the
	 * configuration from a different chip or firmware version, so
	 * the configuration CRC is invalid anyway.
	 */
	if (info_crc == data->info_crc) {
		if (config_crc == 0 || data->config_crc == 0) {
			dev_info(dev, "CRC zero, attempting to apply config\n");
		} else if (config_crc == data->config_crc) {
			dev_dbg(dev, "Config CRC 0x%06X: OK\n",
				 data->config_crc);
1453
			return 0;
1454 1455 1456 1457 1458 1459 1460 1461
		} else {
			dev_info(dev, "Config CRC 0x%06X: does not match file 0x%06X\n",
				 data->config_crc, config_crc);
		}
	} else {
		dev_warn(dev,
			 "Warning: Info CRC error - device=0x%06X file=0x%06X\n",
			 data->info_crc, info_crc);
1462 1463
	}

1464 1465 1466 1467 1468 1469 1470 1471
	/* Malloc memory to store configuration */
	cfg_start_ofs = MXT_OBJECT_START +
			data->info.object_num * sizeof(struct mxt_object) +
			MXT_INFO_CHECKSUM_SIZE;
	config_mem_size = data->mem_size - cfg_start_ofs;
	config_mem = kzalloc(config_mem_size, GFP_KERNEL);
	if (!config_mem) {
		dev_err(dev, "Failed to allocate memory\n");
1472
		return -ENOMEM;
1473
	}
1474

1475 1476 1477 1478
	ret = mxt_prepare_cfg_mem(data, cfg, data_pos, cfg_start_ofs,
				  config_mem, config_mem_size);
	if (ret)
		goto release_mem;
1479

1480 1481 1482 1483 1484 1485 1486
	/* Calculate crc of the received configs (not the raw config file) */
	if (data->T7_address < cfg_start_ofs) {
		dev_err(dev, "Bad T7 address, T7addr = %x, config offset %x\n",
			data->T7_address, cfg_start_ofs);
		ret = 0;
		goto release_mem;
	}
1487

1488 1489 1490 1491
	calculated_crc = mxt_calculate_crc(config_mem,
					   data->T7_address - cfg_start_ofs,
					   config_mem_size);

1492
	if (config_crc > 0 && config_crc != calculated_crc)
1493 1494 1495
		dev_warn(dev, "Config CRC error, calculated=%06X, file=%06X\n",
			 calculated_crc, config_crc);

1496 1497 1498 1499
	ret = mxt_upload_cfg_mem(data, cfg_start_ofs,
				 config_mem, config_mem_size);
	if (ret)
		goto release_mem;
1500

1501 1502 1503 1504
	mxt_update_crc(data, MXT_COMMAND_BACKUPNV, MXT_BACKUP_VALUE);

	ret = mxt_soft_reset(data);
	if (ret)
1505
		goto release_mem;
1506 1507 1508

	dev_info(dev, "Config successfully updated\n");

1509 1510
release_mem:
	kfree(config_mem);
1511
	return ret;
1512 1513
}

1514 1515 1516 1517 1518 1519
static int mxt_acquire_irq(struct mxt_data *data)
{
	int error;

	enable_irq(data->irq);

1520
	error = mxt_process_messages_until_invalid(data);
1521 1522 1523 1524 1525 1526
	if (error)
		return error;

	return 0;
}

1527
static int mxt_get_info(struct mxt_data *data)
1528 1529
{
	struct i2c_client *client = data->client;
1530
	struct mxt_info *info = &data->info;
1531 1532
	int error;

1533 1534
	/* Read 7-byte info block starting at address 0 */
	error = __mxt_read_reg(client, MXT_INFO, sizeof(*info), info);
1535 1536 1537 1538 1539 1540
	if (error)
		return error;

	return 0;
}

1541
static void mxt_free_input_device(struct mxt_data *data)
1542
{
1543 1544 1545 1546 1547
	if (data->input_dev) {
		input_unregister_device(data->input_dev);
		data->input_dev = NULL;
	}
}
1548

1549 1550
static void mxt_free_object_table(struct mxt_data *data)
{
1551 1552 1553 1554
	kfree(data->object_table);
	data->object_table = NULL;
	kfree(data->msg_buf);
	data->msg_buf = NULL;
1555
	data->T5_address = 0;
1556 1557 1558 1559 1560 1561
	data->T5_msg_size = 0;
	data->T6_reportid = 0;
	data->T7_address = 0;
	data->T9_reportid_min = 0;
	data->T9_reportid_max = 0;
	data->T19_reportid = 0;
1562
	data->T44_address = 0;
1563 1564
	data->T100_reportid_min = 0;
	data->T100_reportid_max = 0;
1565
	data->max_reportid = 0;
1566 1567
}

1568
static int mxt_get_object_table(struct mxt_data *data)
1569
{
1570 1571
	struct i2c_client *client = data->client;
	size_t table_size;
1572
	struct mxt_object *object_table;
1573 1574
	int error;
	int i;
1575
	u8 reportid;
1576
	u16 end_address;
1577 1578

	table_size = data->info.object_num * sizeof(struct mxt_object);
1579 1580 1581 1582 1583 1584
	object_table = kzalloc(table_size, GFP_KERNEL);
	if (!object_table) {
		dev_err(&data->client->dev, "Failed to allocate memory\n");
		return -ENOMEM;
	}

1585
	error = __mxt_read_reg(client, MXT_OBJECT_START, table_size,
1586 1587 1588
			object_table);
	if (error) {
		kfree(object_table);
1589
		return error;
1590
	}
1591

1592 1593
	/* Valid Report IDs start counting from 1 */
	reportid = 1;
1594
	data->mem_size = 0;
1595
	for (i = 0; i < data->info.object_num; i++) {
1596
		struct mxt_object *object = object_table + i;
1597
		u8 min_id, max_id;
1598

1599
		le16_to_cpus(&object->start_address);
1600 1601

		if (object->num_report_ids) {
1602
			min_id = reportid;
1603
			reportid += object->num_report_ids *
1604
					mxt_obj_instances(object);
1605 1606 1607 1608 1609 1610 1611
			max_id = reportid - 1;
		} else {
			min_id = 0;
			max_id = 0;
		}

		dev_dbg(&data->client->dev,
1612
			"T%u Start:%u Size:%zu Instances:%zu Report IDs:%u-%u\n",
1613 1614 1615
			object->type, object->start_address,
			mxt_obj_size(object), mxt_obj_instances(object),
			min_id, max_id);
1616 1617

		switch (object->type) {
1618
		case MXT_GEN_MESSAGE_T5:
1619 1620
			if (data->info.family_id == 0x80 &&
			    data->info.version < 0x20) {
1621
				/*
1622 1623 1624
				 * On mXT224 firmware versions prior to V2.0
				 * read and discard unused CRC byte otherwise
				 * DMA reads are misaligned.
1625 1626 1627 1628 1629 1630
				 */
				data->T5_msg_size = mxt_obj_size(object);
			} else {
				/* CRC not enabled, so skip last byte */
				data->T5_msg_size = mxt_obj_size(object) - 1;
			}
1631
			data->T5_address = object->start_address;
1632
			break;
1633 1634
		case MXT_GEN_COMMAND_T6:
			data->T6_reportid = min_id;
1635
			data->T6_address = object->start_address;
1636
			break;
1637 1638 1639
		case MXT_GEN_POWER_T7:
			data->T7_address = object->start_address;
			break;
1640
		case MXT_TOUCH_MULTI_T9:
1641
			data->multitouch = MXT_TOUCH_MULTI_T9;
1642 1643
			data->T9_reportid_min = min_id;
			data->T9_reportid_max = max_id;
1644 1645 1646 1647 1648
			data->num_touchids = object->num_report_ids
						* mxt_obj_instances(object);
			break;
		case MXT_SPT_MESSAGECOUNT_T44:
			data->T44_address = object->start_address;
1649
			break;
1650 1651 1652
		case MXT_SPT_GPIOPWM_T19:
			data->T19_reportid = min_id;
			break;
1653 1654 1655 1656 1657 1658 1659
		case MXT_TOUCH_MULTITOUCHSCREEN_T100:
			data->multitouch = MXT_TOUCH_MULTITOUCHSCREEN_T100;
			data->T100_reportid_min = min_id;
			data->T100_reportid_max = max_id;
			/* first two report IDs reserved */
			data->num_touchids = object->num_report_ids - 2;
			break;
1660
		}
1661 1662 1663 1664 1665 1666

		end_address = object->start_address
			+ mxt_obj_size(object) * mxt_obj_instances(object) - 1;

		if (end_address >= data->mem_size)
			data->mem_size = end_address + 1;
1667 1668
	}

1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680
	/* Store maximum reportid */
	data->max_reportid = reportid;

	/* If T44 exists, T5 position has to be directly after */
	if (data->T44_address && (data->T5_address != data->T44_address + 1)) {
		dev_err(&client->dev, "Invalid T44 position\n");
		error = -EINVAL;
		goto free_object_table;
	}

	data->msg_buf = kcalloc(data->max_reportid,
				data->T5_msg_size, GFP_KERNEL);
1681 1682 1683 1684 1685 1686
	if (!data->msg_buf) {
		dev_err(&client->dev, "Failed to allocate message buffer\n");
		error = -ENOMEM;
		goto free_object_table;
	}

1687 1688
	data->object_table = object_table;

1689 1690
	return 0;

1691 1692 1693
free_object_table:
	mxt_free_object_table(data);
	return error;
1694 1695
}

1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706 1707 1708 1709 1710 1711 1712 1713 1714 1715 1716 1717 1718 1719 1720 1721 1722 1723 1724 1725 1726 1727 1728 1729
static int mxt_read_t9_resolution(struct mxt_data *data)
{
	struct i2c_client *client = data->client;
	int error;
	struct t9_range range;
	unsigned char orient;
	struct mxt_object *object;

	object = mxt_get_object(data, MXT_TOUCH_MULTI_T9);
	if (!object)
		return -EINVAL;

	error = __mxt_read_reg(client,
			       object->start_address + MXT_T9_RANGE,
			       sizeof(range), &range);
	if (error)
		return error;

	le16_to_cpus(&range.x);
	le16_to_cpus(&range.y);

	error =  __mxt_read_reg(client,
				object->start_address + MXT_T9_ORIENT,
				1, &orient);
	if (error)
		return error;

	/* Handle default values */
	if (range.x == 0)
		range.x = 1023;

	if (range.y == 0)
		range.y = 1023;

1730
	if (orient & MXT_T9_ORIENT_SWITCH) {
1731 1732 1733 1734 1735 1736 1737 1738 1739 1740 1741 1742 1743
		data->max_x = range.y;
		data->max_y = range.x;
	} else {
		data->max_x = range.x;
		data->max_y = range.y;
	}

	dev_dbg(&client->dev,
		"Touchscreen size X%uY%u\n", data->max_x, data->max_y);

	return 0;
}

1744 1745 1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790 1791 1792 1793 1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821
static int mxt_read_t100_config(struct mxt_data *data)
{
	struct i2c_client *client = data->client;
	int error;
	struct mxt_object *object;
	u16 range_x, range_y;
	u8 cfg, tchaux;
	u8 aux;

	object = mxt_get_object(data, MXT_TOUCH_MULTITOUCHSCREEN_T100);
	if (!object)
		return -EINVAL;

	error = __mxt_read_reg(client,
			       object->start_address + MXT_T100_XRANGE,
			       sizeof(range_x), &range_x);
	if (error)
		return error;

	le16_to_cpus(&range_x);

	error = __mxt_read_reg(client,
			       object->start_address + MXT_T100_YRANGE,
			       sizeof(range_y), &range_y);
	if (error)
		return error;

	le16_to_cpus(&range_y);

	error =  __mxt_read_reg(client,
				object->start_address + MXT_T100_CFG1,
				1, &cfg);
	if (error)
		return error;

	error =  __mxt_read_reg(client,
				object->start_address + MXT_T100_TCHAUX,
				1, &tchaux);
	if (error)
		return error;

	/* Handle default values */
	if (range_x == 0)
		range_x = 1023;

	if (range_y == 0)
		range_y = 1023;

	if (cfg & MXT_T100_CFG_SWITCHXY) {
		data->max_x = range_y;
		data->max_y = range_x;
	} else {
		data->max_x = range_x;
		data->max_y = range_y;
	}

	/* allocate aux bytes */
	aux = 6;

	if (tchaux & MXT_T100_TCHAUX_VECT)
		data->t100_aux_vect = aux++;

	if (tchaux & MXT_T100_TCHAUX_AMPL)
		data->t100_aux_ampl = aux++;

	if (tchaux & MXT_T100_TCHAUX_AREA)
		data->t100_aux_area = aux++;

	dev_dbg(&client->dev,
		"T100 aux mappings vect:%u ampl:%u area:%u\n",
		data->t100_aux_vect, data->t100_aux_ampl, data->t100_aux_area);

	dev_info(&client->dev,
		 "T100 Touchscreen size X%uY%u\n", data->max_x, data->max_y);

	return 0;
}

1822 1823 1824
static int mxt_input_open(struct input_dev *dev);
static void mxt_input_close(struct input_dev *dev);

1825 1826 1827 1828 1829 1830 1831 1832 1833 1834 1835 1836 1837 1838 1839 1840 1841 1842 1843 1844 1845 1846 1847
static void mxt_set_up_as_touchpad(struct input_dev *input_dev,
				   struct mxt_data *data)
{
	const struct mxt_platform_data *pdata = data->pdata;
	int i;

	input_dev->name = "Atmel maXTouch Touchpad";

	__set_bit(INPUT_PROP_BUTTONPAD, input_dev->propbit);

	input_abs_set_res(input_dev, ABS_X, MXT_PIXELS_PER_MM);
	input_abs_set_res(input_dev, ABS_Y, MXT_PIXELS_PER_MM);
	input_abs_set_res(input_dev, ABS_MT_POSITION_X,
			  MXT_PIXELS_PER_MM);
	input_abs_set_res(input_dev, ABS_MT_POSITION_Y,
			  MXT_PIXELS_PER_MM);

	for (i = 0; i < pdata->t19_num_keys; i++)
		if (pdata->t19_keymap[i] != KEY_RESERVED)
			input_set_capability(input_dev, EV_KEY,
					     pdata->t19_keymap[i]);
}

1848
static int mxt_initialize_input_device(struct mxt_data *data)
1849 1850
{
	const struct mxt_platform_data *pdata = data->pdata;
1851
	struct device *dev = &data->client->dev;
1852 1853 1854 1855 1856
	struct input_dev *input_dev;
	int error;
	unsigned int num_mt_slots;
	unsigned int mt_flags = 0;

1857 1858 1859 1860 1861 1862 1863 1864 1865 1866 1867 1868 1869 1870 1871 1872 1873 1874 1875
	switch (data->multitouch) {
	case MXT_TOUCH_MULTI_T9:
		num_mt_slots = data->T9_reportid_max - data->T9_reportid_min + 1;
		error = mxt_read_t9_resolution(data);
		if (error)
			dev_warn(dev, "Failed to initialize T9 resolution\n");
		break;

	case MXT_TOUCH_MULTITOUCHSCREEN_T100:
		num_mt_slots = data->num_touchids;
		error = mxt_read_t100_config(data);
		if (error)
			dev_warn(dev, "Failed to read T100 config\n");
		break;

	default:
		dev_err(dev, "Invalid multitouch object\n");
		return -EINVAL;
	}
1876 1877 1878 1879 1880 1881 1882 1883 1884 1885 1886 1887 1888 1889

	input_dev = input_allocate_device();
	if (!input_dev) {
		dev_err(dev, "Failed to allocate memory\n");
		return -ENOMEM;
	}

	input_dev->name = "Atmel maXTouch Touchscreen";
	input_dev->phys = data->phys;
	input_dev->id.bustype = BUS_I2C;
	input_dev->dev.parent = dev;
	input_dev->open = mxt_input_open;
	input_dev->close = mxt_input_close;

1890
	input_set_capability(input_dev, EV_KEY, BTN_TOUCH);
1891 1892

	/* For single touch */
1893 1894 1895 1896 1897 1898 1899 1900
	input_set_abs_params(input_dev, ABS_X, 0, data->max_x, 0, 0);
	input_set_abs_params(input_dev, ABS_Y, 0, data->max_y, 0, 0);

	if (data->multitouch == MXT_TOUCH_MULTI_T9 ||
	    (data->multitouch == MXT_TOUCH_MULTITOUCHSCREEN_T100 &&
	     data->t100_aux_ampl)) {
		input_set_abs_params(input_dev, ABS_PRESSURE, 0, 255, 0, 0);
	}
1901

1902 1903 1904 1905 1906 1907
	/* If device has buttons we assume it is a touchpad */
	if (pdata->t19_num_keys) {
		mxt_set_up_as_touchpad(input_dev, data);
		mt_flags |= INPUT_MT_POINTER;
	}

1908 1909 1910 1911 1912 1913 1914
	/* For multi touch */
	error = input_mt_init_slots(input_dev, num_mt_slots, mt_flags);
	if (error) {
		dev_err(dev, "Error %d initialising slots\n", error);
		goto err_free_mem;
	}

1915 1916 1917 1918 1919 1920 1921 1922 1923
	if (data->multitouch == MXT_TOUCH_MULTITOUCHSCREEN_T100) {
		input_set_abs_params(input_dev, ABS_MT_TOOL_TYPE,
				     0, MT_TOOL_MAX, 0, 0);
		input_set_abs_params(input_dev, ABS_MT_DISTANCE,
				     MXT_DISTANCE_ACTIVE_TOUCH,
				     MXT_DISTANCE_HOVERING,
				     0, 0);
	}

1924 1925 1926 1927
	input_set_abs_params(input_dev, ABS_MT_POSITION_X,
			     0, data->max_x, 0, 0);
	input_set_abs_params(input_dev, ABS_MT_POSITION_Y,
			     0, data->max_y, 0, 0);
1928 1929 1930 1931 1932 1933 1934 1935 1936 1937 1938 1939 1940 1941 1942 1943 1944 1945 1946 1947 1948 1949 1950 1951 1952 1953 1954 1955 1956 1957 1958 1959

	if (data->multitouch == MXT_TOUCH_MULTI_T9 ||
	    (data->multitouch == MXT_TOUCH_MULTITOUCHSCREEN_T100 &&
	     data->t100_aux_area)) {
		input_set_abs_params(input_dev, ABS_MT_TOUCH_MAJOR,
				     0, MXT_MAX_AREA, 0, 0);
	}

	if (data->multitouch == MXT_TOUCH_MULTI_T9 ||
	    (data->multitouch == MXT_TOUCH_MULTITOUCHSCREEN_T100 &&
	     data->t100_aux_ampl)) {
		input_set_abs_params(input_dev, ABS_MT_PRESSURE,
				     0, 255, 0, 0);
	}

	if (data->multitouch == MXT_TOUCH_MULTITOUCHSCREEN_T100 &&
	    data->t100_aux_vect) {
		input_set_abs_params(input_dev, ABS_MT_ORIENTATION,
				     0, 255, 0, 0);
	}

	if (data->multitouch == MXT_TOUCH_MULTITOUCHSCREEN_T100 &&
	    data->t100_aux_ampl) {
		input_set_abs_params(input_dev, ABS_MT_PRESSURE,
				     0, 255, 0, 0);
	}

	if (data->multitouch == MXT_TOUCH_MULTITOUCHSCREEN_T100 &&
	    data->t100_aux_vect) {
		input_set_abs_params(input_dev, ABS_MT_ORIENTATION,
				     0, 255, 0, 0);
	}
1960 1961 1962 1963 1964 1965 1966 1967 1968 1969 1970 1971 1972 1973 1974 1975 1976 1977

	input_set_drvdata(input_dev, data);

	error = input_register_device(input_dev);
	if (error) {
		dev_err(dev, "Error %d registering input device\n", error);
		goto err_free_mem;
	}

	data->input_dev = input_dev;

	return 0;

err_free_mem:
	input_free_device(input_dev);
	return error;
}

1978 1979 1980 1981 1982 1983
static int mxt_configure_objects(struct mxt_data *data,
				 const struct firmware *cfg);

static void mxt_config_cb(const struct firmware *cfg, void *ctx)
{
	mxt_configure_objects(ctx, cfg);
1984
	release_firmware(cfg);
1985 1986
}

1987
static int mxt_initialize(struct mxt_data *data)
1988 1989
{
	struct i2c_client *client = data->client;
1990
	int recovery_attempts = 0;
1991 1992
	int error;

1993 1994 1995 1996 1997 1998 1999
	while (1) {
		error = mxt_get_info(data);
		if (!error)
			break;

		/* Check bootloader state */
		error = mxt_probe_bootloader(data, false);
2000
		if (error) {
2001 2002 2003
			dev_info(&client->dev, "Trying alternate bootloader address\n");
			error = mxt_probe_bootloader(data, true);
			if (error) {
2004 2005 2006
				/* Chip is not in appmode or bootloader mode */
				return error;
			}
2007
		}
2008

2009 2010 2011 2012 2013 2014 2015 2016 2017
		/* OK, we are in bootloader, see if we can recover */
		if (++recovery_attempts > 1) {
			dev_err(&client->dev, "Could not recover from bootloader mode\n");
			/*
			 * We can reflash from this state, so do not
			 * abort initialization.
			 */
			data->in_bootloader = true;
			return 0;
2018
		}
2019 2020 2021 2022

		/* Attempt to exit bootloader into app mode */
		mxt_send_bootloader_cmd(data, false);
		msleep(MXT_FW_RESET_TIME);
2023
	}
2024 2025

	/* Get object table information */
2026
	error = mxt_get_object_table(data);
2027 2028
	if (error) {
		dev_err(&client->dev, "Error %d reading object table\n", error);
2029
		return error;
2030
	}
2031

2032
	error = mxt_acquire_irq(data);
2033 2034 2035
	if (error)
		goto err_free_object_table;

2036 2037 2038 2039 2040 2041 2042 2043
	error = request_firmware_nowait(THIS_MODULE, true, MXT_CFG_NAME,
					&client->dev, GFP_KERNEL, data,
					mxt_config_cb);
	if (error) {
		dev_err(&client->dev, "Failed to invoke firmware loader: %d\n",
			error);
		goto err_free_object_table;
	}
2044 2045 2046 2047 2048 2049 2050 2051 2052 2053 2054 2055 2056 2057 2058 2059 2060 2061 2062

	return 0;

err_free_object_table:
	mxt_free_object_table(data);
	return error;
}

static int mxt_configure_objects(struct mxt_data *data,
				 const struct firmware *cfg)
{
	struct device *dev = &data->client->dev;
	struct mxt_info *info = &data->info;
	int error;

	if (cfg) {
		error = mxt_update_cfg(data, cfg);
		if (error)
			dev_warn(dev, "Error %d updating config\n", error);
2063
	}
2064

2065 2066 2067 2068 2069 2070 2071
	if (data->multitouch) {
		error = mxt_initialize_input_device(data);
		if (error)
			return error;
	} else {
		dev_warn(dev, "No touch object detected\n");
	}
2072

2073
	dev_info(dev,
2074 2075 2076
		 "Family: %u Variant: %u Firmware V%u.%u.%02X Objects: %u\n",
		 info->family_id, info->variant_id, info->version >> 4,
		 info->version & 0xf, info->build, info->object_num);
2077 2078 2079 2080

	return 0;
}

2081 2082 2083 2084 2085 2086 2087 2088 2089 2090 2091 2092 2093 2094 2095 2096 2097 2098 2099 2100
/* Firmware Version is returned as Major.Minor.Build */
static ssize_t mxt_fw_version_show(struct device *dev,
				   struct device_attribute *attr, char *buf)
{
	struct mxt_data *data = dev_get_drvdata(dev);
	struct mxt_info *info = &data->info;
	return scnprintf(buf, PAGE_SIZE, "%u.%u.%02X\n",
			 info->version >> 4, info->version & 0xf, info->build);
}

/* Hardware Version is returned as FamilyID.VariantID */
static ssize_t mxt_hw_version_show(struct device *dev,
				   struct device_attribute *attr, char *buf)
{
	struct mxt_data *data = dev_get_drvdata(dev);
	struct mxt_info *info = &data->info;
	return scnprintf(buf, PAGE_SIZE, "%u.%u\n",
			 info->family_id, info->variant_id);
}

2101 2102 2103 2104 2105 2106
static ssize_t mxt_show_instance(char *buf, int count,
				 struct mxt_object *object, int instance,
				 const u8 *val)
{
	int i;

2107
	if (mxt_obj_instances(object) > 1)
2108 2109 2110
		count += scnprintf(buf + count, PAGE_SIZE - count,
				   "Instance %u\n", instance);

2111
	for (i = 0; i < mxt_obj_size(object); i++)
2112 2113 2114 2115 2116 2117 2118
		count += scnprintf(buf + count, PAGE_SIZE - count,
				"\t[%2u]: %02x (%d)\n", i, val[i], val[i]);
	count += scnprintf(buf + count, PAGE_SIZE - count, "\n");

	return count;
}

2119
static ssize_t mxt_object_show(struct device *dev,
2120 2121
				    struct device_attribute *attr, char *buf)
{
2122 2123
	struct mxt_data *data = dev_get_drvdata(dev);
	struct mxt_object *object;
2124 2125 2126
	int count = 0;
	int i, j;
	int error;
2127
	u8 *obuf;
2128

2129 2130 2131 2132
	/* Pre-allocate buffer large enough to hold max sized object. */
	obuf = kmalloc(256, GFP_KERNEL);
	if (!obuf)
		return -ENOMEM;
2133

2134
	error = 0;
2135 2136 2137
	for (i = 0; i < data->info.object_num; i++) {
		object = data->object_table + i;

2138
		if (!mxt_object_readable(object->type))
2139 2140
			continue;

2141 2142
		count += scnprintf(buf + count, PAGE_SIZE - count,
				"T%u:\n", object->type);
2143

2144 2145
		for (j = 0; j < mxt_obj_instances(object); j++) {
			u16 size = mxt_obj_size(object);
2146
			u16 addr = object->start_address + j * size;
2147

2148
			error = __mxt_read_reg(data->client, addr, size, obuf);
2149
			if (error)
2150
				goto done;
2151

2152
			count = mxt_show_instance(buf, count, object, j, obuf);
2153 2154 2155
		}
	}

2156
done:
2157 2158
	kfree(obuf);
	return error ?: count;
2159 2160
}

2161 2162 2163 2164 2165 2166 2167 2168 2169 2170 2171 2172 2173 2174 2175 2176 2177 2178 2179 2180 2181 2182 2183 2184
static int mxt_check_firmware_format(struct device *dev,
				     const struct firmware *fw)
{
	unsigned int pos = 0;
	char c;

	while (pos < fw->size) {
		c = *(fw->data + pos);

		if (c < '0' || (c > '9' && c < 'A') || c > 'F')
			return 0;

		pos++;
	}

	/*
	 * To convert file try:
	 * xxd -r -p mXTXXX__APP_VX-X-XX.enc > maxtouch.fw
	 */
	dev_err(dev, "Aborting: firmware file must be in binary format\n");

	return -EINVAL;
}

2185
static int mxt_load_fw(struct device *dev, const char *fn)
2186
{
2187
	struct mxt_data *data = dev_get_drvdata(dev);
2188 2189 2190
	const struct firmware *fw = NULL;
	unsigned int frame_size;
	unsigned int pos = 0;
2191
	unsigned int retry = 0;
2192
	unsigned int frame = 0;
2193 2194 2195 2196 2197 2198 2199 2200
	int ret;

	ret = request_firmware(&fw, fn, dev);
	if (ret) {
		dev_err(dev, "Unable to open firmware %s\n", fn);
		return ret;
	}

2201 2202 2203 2204 2205
	/* Check for incorrect enc file */
	ret = mxt_check_firmware_format(dev, fw);
	if (ret)
		goto release_firmware;

2206 2207 2208
	if (!data->in_bootloader) {
		/* Change to the bootloader mode */
		data->in_bootloader = true;
2209

2210 2211 2212 2213
		ret = mxt_t6_command(data, MXT_COMMAND_RESET,
				     MXT_BOOT_VALUE, false);
		if (ret)
			goto release_firmware;
2214

2215
		msleep(MXT_RESET_TIME);
2216 2217 2218 2219 2220

		/* Do not need to scan since we know family ID */
		ret = mxt_lookup_bootloader_address(data, 0);
		if (ret)
			goto release_firmware;
2221 2222 2223

		mxt_free_input_device(data);
		mxt_free_object_table(data);
2224 2225
	} else {
		enable_irq(data->irq);
2226
	}
2227

2228 2229
	reinit_completion(&data->bl_completion);

2230 2231 2232 2233 2234 2235 2236 2237
	ret = mxt_check_bootloader(data, MXT_WAITING_BOOTLOAD_CMD, false);
	if (ret) {
		/* Bootloader may still be unlocked from previous attempt */
		ret = mxt_check_bootloader(data, MXT_WAITING_FRAME_DATA, false);
		if (ret)
			goto disable_irq;
	} else {
		dev_info(dev, "Unlocking bootloader\n");
2238

2239
		/* Unlock bootloader */
2240
		ret = mxt_send_bootloader_cmd(data, true);
2241 2242 2243
		if (ret)
			goto disable_irq;
	}
2244 2245

	while (pos < fw->size) {
2246
		ret = mxt_check_bootloader(data, MXT_WAITING_FRAME_DATA, true);
2247
		if (ret)
2248
			goto disable_irq;
2249 2250 2251

		frame_size = ((*(fw->data + pos) << 8) | *(fw->data + pos + 1));

2252
		/* Take account of CRC bytes */
2253 2254 2255
		frame_size += 2;

		/* Write one frame to device */
2256 2257 2258
		ret = mxt_bootloader_write(data, fw->data + pos, frame_size);
		if (ret)
			goto disable_irq;
2259

2260
		ret = mxt_check_bootloader(data, MXT_FRAME_CRC_PASS, true);
2261 2262 2263 2264 2265
		if (ret) {
			retry++;

			/* Back off by 20ms per retry */
			msleep(retry * 20);
2266

2267 2268 2269 2270 2271 2272 2273
			if (retry > 20) {
				dev_err(dev, "Retry count exceeded\n");
				goto disable_irq;
			}
		} else {
			retry = 0;
			pos += frame_size;
2274
			frame++;
2275
		}
2276

2277 2278 2279
		if (frame % 50 == 0)
			dev_dbg(dev, "Sent %d frames, %d/%zd bytes\n",
				frame, pos, fw->size);
2280 2281
	}

2282
	/* Wait for flash. */
2283 2284
	ret = mxt_wait_for_completion(data, &data->bl_completion,
				      MXT_FW_RESET_TIME);
2285 2286 2287
	if (ret)
		goto disable_irq;

2288 2289
	dev_dbg(dev, "Sent %d frames, %d bytes\n", frame, pos);

2290 2291 2292 2293 2294
	/*
	 * Wait for device to reset. Some bootloader versions do not assert
	 * the CHG line after bootloading has finished, so ignore potential
	 * errors.
	 */
2295
	mxt_wait_for_completion(data, &data->bl_completion, MXT_FW_RESET_TIME);
2296

2297 2298 2299 2300
	data->in_bootloader = false;

disable_irq:
	disable_irq(data->irq);
2301
release_firmware:
2302 2303 2304 2305
	release_firmware(fw);
	return ret;
}

2306
static ssize_t mxt_update_fw_store(struct device *dev,
2307 2308 2309
					struct device_attribute *attr,
					const char *buf, size_t count)
{
2310
	struct mxt_data *data = dev_get_drvdata(dev);
2311 2312
	int error;

2313
	error = mxt_load_fw(dev, MXT_FW_NAME);
2314 2315 2316 2317
	if (error) {
		dev_err(dev, "The firmware update failed(%d)\n", error);
		count = error;
	} else {
2318 2319
		dev_info(dev, "The firmware update succeeded\n");

2320
		error = mxt_initialize(data);
2321 2322 2323
		if (error)
			return error;
	}
2324

2325 2326 2327
	return count;
}

2328 2329
static DEVICE_ATTR(fw_version, S_IRUGO, mxt_fw_version_show, NULL);
static DEVICE_ATTR(hw_version, S_IRUGO, mxt_hw_version_show, NULL);
2330 2331
static DEVICE_ATTR(object, S_IRUGO, mxt_object_show, NULL);
static DEVICE_ATTR(update_fw, S_IWUSR, NULL, mxt_update_fw_store);
2332

2333
static struct attribute *mxt_attrs[] = {
2334 2335
	&dev_attr_fw_version.attr,
	&dev_attr_hw_version.attr,
2336 2337 2338 2339 2340
	&dev_attr_object.attr,
	&dev_attr_update_fw.attr,
	NULL
};

2341 2342
static const struct attribute_group mxt_attr_group = {
	.attrs = mxt_attrs,
2343 2344
};

2345
static void mxt_start(struct mxt_data *data)
2346
{
2347
	/* Touch enable */
2348
	mxt_write_object(data, data->multitouch, MXT_TOUCH_CTRL, 0x83);
2349 2350
}

2351
static void mxt_stop(struct mxt_data *data)
2352
{
2353
	/* Touch disable */
2354
	mxt_write_object(data, data->multitouch, MXT_TOUCH_CTRL, 0);
2355 2356
}

2357
static int mxt_input_open(struct input_dev *dev)
2358
{
2359
	struct mxt_data *data = input_get_drvdata(dev);
2360

2361
	mxt_start(data);
2362 2363 2364 2365

	return 0;
}

2366
static void mxt_input_close(struct input_dev *dev)
2367
{
2368
	struct mxt_data *data = input_get_drvdata(dev);
2369

2370
	mxt_stop(data);
2371 2372
}

2373 2374 2375 2376 2377 2378 2379 2380 2381 2382 2383 2384 2385 2386 2387 2388 2389 2390 2391 2392 2393 2394 2395 2396 2397 2398 2399 2400 2401 2402 2403 2404 2405 2406 2407 2408 2409 2410 2411 2412 2413 2414 2415 2416 2417 2418 2419 2420
#ifdef CONFIG_OF
static struct mxt_platform_data *mxt_parse_dt(struct i2c_client *client)
{
	struct mxt_platform_data *pdata;
	u32 *keymap;
	u32 keycode;
	int proplen, i, ret;

	if (!client->dev.of_node)
		return ERR_PTR(-ENODEV);

	pdata = devm_kzalloc(&client->dev, sizeof(*pdata), GFP_KERNEL);
	if (!pdata)
		return ERR_PTR(-ENOMEM);

	if (of_find_property(client->dev.of_node, "linux,gpio-keymap",
			     &proplen)) {
		pdata->t19_num_keys = proplen / sizeof(u32);

		keymap = devm_kzalloc(&client->dev,
				pdata->t19_num_keys * sizeof(keymap[0]),
				GFP_KERNEL);
		if (!keymap)
			return ERR_PTR(-ENOMEM);

		for (i = 0; i < pdata->t19_num_keys; i++) {
			ret = of_property_read_u32_index(client->dev.of_node,
					"linux,gpio-keymap", i, &keycode);
			if (ret)
				keycode = KEY_RESERVED;

			keymap[i] = keycode;
		}

		pdata->t19_keymap = keymap;
	}

	return pdata;
}
#else
static struct mxt_platform_data *mxt_parse_dt(struct i2c_client *client)
{
	dev_dbg(&client->dev, "No platform data specified\n");
	return ERR_PTR(-EINVAL);
}
#endif

static int mxt_probe(struct i2c_client *client, const struct i2c_device_id *id)
2421
{
2422
	struct mxt_data *data;
2423
	const struct mxt_platform_data *pdata;
2424 2425
	int error;

2426 2427 2428 2429 2430 2431
	pdata = dev_get_platdata(&client->dev);
	if (!pdata) {
		pdata = mxt_parse_dt(client);
		if (IS_ERR(pdata))
			return PTR_ERR(pdata);
	}
2432

2433
	data = kzalloc(sizeof(struct mxt_data), GFP_KERNEL);
2434
	if (!data) {
2435
		dev_err(&client->dev, "Failed to allocate memory\n");
2436
		return -ENOMEM;
2437 2438
	}

2439 2440
	snprintf(data->phys, sizeof(data->phys), "i2c-%u-%04x/input0",
		 client->adapter->nr, client->addr);
2441

2442 2443 2444
	data->client = client;
	data->pdata = pdata;
	data->irq = client->irq;
2445
	i2c_set_clientdata(client, data);
2446

2447
	init_completion(&data->bl_completion);
2448
	init_completion(&data->reset_completion);
2449
	init_completion(&data->crc_completion);
2450

2451 2452 2453 2454 2455 2456 2457 2458 2459 2460
	error = request_threaded_irq(client->irq, NULL, mxt_interrupt,
				     pdata->irqflags | IRQF_ONESHOT,
				     client->name, data);
	if (error) {
		dev_err(&client->dev, "Failed to register interrupt\n");
		goto err_free_mem;
	}

	disable_irq(client->irq);

2461 2462
	error = mxt_initialize(data);
	if (error)
2463
		goto err_free_irq;
2464

2465
	error = sysfs_create_group(&client->dev.kobj, &mxt_attr_group);
2466 2467 2468
	if (error) {
		dev_err(&client->dev, "Failure %d creating sysfs group\n",
			error);
2469
		goto err_free_object;
2470
	}
2471 2472 2473 2474

	return 0;

err_free_object:
2475
	mxt_free_input_device(data);
2476
	mxt_free_object_table(data);
2477 2478
err_free_irq:
	free_irq(client->irq, data);
2479 2480 2481 2482 2483
err_free_mem:
	kfree(data);
	return error;
}

B
Bill Pemberton 已提交
2484
static int mxt_remove(struct i2c_client *client)
2485
{
2486
	struct mxt_data *data = i2c_get_clientdata(client);
2487

2488
	sysfs_remove_group(&client->dev.kobj, &mxt_attr_group);
2489
	free_irq(data->irq, data);
2490
	mxt_free_input_device(data);
2491
	mxt_free_object_table(data);
2492 2493 2494 2495 2496
	kfree(data);

	return 0;
}

2497
static int __maybe_unused mxt_suspend(struct device *dev)
2498
{
2499
	struct i2c_client *client = to_i2c_client(dev);
2500
	struct mxt_data *data = i2c_get_clientdata(client);
2501 2502 2503 2504 2505
	struct input_dev *input_dev = data->input_dev;

	mutex_lock(&input_dev->mutex);

	if (input_dev->users)
2506
		mxt_stop(data);
2507 2508 2509 2510 2511 2512

	mutex_unlock(&input_dev->mutex);

	return 0;
}

2513
static int __maybe_unused mxt_resume(struct device *dev)
2514
{
2515
	struct i2c_client *client = to_i2c_client(dev);
2516
	struct mxt_data *data = i2c_get_clientdata(client);
2517 2518
	struct input_dev *input_dev = data->input_dev;

2519 2520
	mxt_soft_reset(data);

2521 2522 2523
	mutex_lock(&input_dev->mutex);

	if (input_dev->users)
2524
		mxt_start(data);
2525 2526 2527 2528 2529 2530

	mutex_unlock(&input_dev->mutex);

	return 0;
}

2531 2532
static SIMPLE_DEV_PM_OPS(mxt_pm_ops, mxt_suspend, mxt_resume);

2533 2534 2535 2536 2537 2538
static const struct of_device_id mxt_of_match[] = {
	{ .compatible = "atmel,maxtouch", },
	{},
};
MODULE_DEVICE_TABLE(of, mxt_of_match);

2539
static const struct i2c_device_id mxt_id[] = {
2540
	{ "qt602240_ts", 0 },
2541
	{ "atmel_mxt_ts", 0 },
2542
	{ "atmel_mxt_tp", 0 },
2543
	{ "mXT224", 0 },
2544 2545
	{ }
};
2546
MODULE_DEVICE_TABLE(i2c, mxt_id);
2547

2548
static struct i2c_driver mxt_driver = {
2549
	.driver = {
2550
		.name	= "atmel_mxt_ts",
2551
		.owner	= THIS_MODULE,
2552
		.of_match_table = of_match_ptr(mxt_of_match),
2553
		.pm	= &mxt_pm_ops,
2554
	},
2555
	.probe		= mxt_probe,
B
Bill Pemberton 已提交
2556
	.remove		= mxt_remove,
2557
	.id_table	= mxt_id,
2558 2559
};

2560
module_i2c_driver(mxt_driver);
2561 2562 2563

/* Module information */
MODULE_AUTHOR("Joonyoung Shim <jy0922.shim@samsung.com>");
2564
MODULE_DESCRIPTION("Atmel maXTouch Touchscreen driver");
2565
MODULE_LICENSE("GPL");