• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (C) 2003-2008 Takahiro Hirofuchi
3  *
4  * This is free software; you can redistribute it and/or modify
5  * it under the terms of the GNU General Public License as published by
6  * the Free Software Foundation; either version 2 of the License, or
7  * (at your option) any later version.
8  *
9  * This is distributed in the hope that it will be useful,
10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12  * GNU General Public License for more details.
13  *
14  * You should have received a copy of the GNU General Public License
15  * along with this program; if not, write to the Free Software
16  * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307,
17  * USA.
18  */
19 
20 #include <linux/init.h>
21 #include <linux/file.h>
22 #include <linux/kernel.h>
23 #include <linux/kthread.h>
24 #include <linux/module.h>
25 #include <linux/platform_device.h>
26 #include <linux/slab.h>
27 
28 #include "usbip_common.h"
29 #include "vhci.h"
30 
31 #define DRIVER_AUTHOR "Takahiro Hirofuchi"
32 #define DRIVER_DESC "USB/IP 'Virtual' Host Controller (VHCI) Driver"
33 
34 /*
35  * TODO
36  *	- update root hub emulation
37  *	- move the emulation code to userland ?
38  *		porting to other operating systems
39  *		minimize kernel code
40  *	- add suspend/resume code
41  *	- clean up everything
42  */
43 
44 /* See usb gadget dummy hcd */
45 
46 static int vhci_hub_status(struct usb_hcd *hcd, char *buff);
47 static int vhci_hub_control(struct usb_hcd *hcd, u16 typeReq, u16 wValue,
48 			    u16 wIndex, char *buff, u16 wLength);
49 static int vhci_urb_enqueue(struct usb_hcd *hcd, struct urb *urb,
50 			    gfp_t mem_flags);
51 static int vhci_urb_dequeue(struct usb_hcd *hcd, struct urb *urb, int status);
52 static int vhci_start(struct usb_hcd *vhci_hcd);
53 static void vhci_stop(struct usb_hcd *hcd);
54 static int vhci_get_frame_number(struct usb_hcd *hcd);
55 
56 static const char driver_name[] = "vhci_hcd";
57 static const char driver_desc[] = "USB/IP Virtual Host Controller";
58 
59 struct vhci_hcd *the_controller;
60 
61 static const char * const bit_desc[] = {
62 	"CONNECTION",		/*0*/
63 	"ENABLE",		/*1*/
64 	"SUSPEND",		/*2*/
65 	"OVER_CURRENT",		/*3*/
66 	"RESET",		/*4*/
67 	"R5",			/*5*/
68 	"R6",			/*6*/
69 	"R7",			/*7*/
70 	"POWER",		/*8*/
71 	"LOWSPEED",		/*9*/
72 	"HIGHSPEED",		/*10*/
73 	"PORT_TEST",		/*11*/
74 	"INDICATOR",		/*12*/
75 	"R13",			/*13*/
76 	"R14",			/*14*/
77 	"R15",			/*15*/
78 	"C_CONNECTION",		/*16*/
79 	"C_ENABLE",		/*17*/
80 	"C_SUSPEND",		/*18*/
81 	"C_OVER_CURRENT",	/*19*/
82 	"C_RESET",		/*20*/
83 	"R21",			/*21*/
84 	"R22",			/*22*/
85 	"R23",			/*23*/
86 	"R24",			/*24*/
87 	"R25",			/*25*/
88 	"R26",			/*26*/
89 	"R27",			/*27*/
90 	"R28",			/*28*/
91 	"R29",			/*29*/
92 	"R30",			/*30*/
93 	"R31",			/*31*/
94 };
95 
dump_port_status_diff(u32 prev_status,u32 new_status)96 static void dump_port_status_diff(u32 prev_status, u32 new_status)
97 {
98 	int i = 0;
99 	u32 bit = 1;
100 
101 	pr_debug("status prev -> new: %08x -> %08x\n", prev_status, new_status);
102 	while (bit) {
103 		u32 prev = prev_status & bit;
104 		u32 new = new_status & bit;
105 		char change;
106 
107 		if (!prev && new)
108 			change = '+';
109 		else if (prev && !new)
110 			change = '-';
111 		else
112 			change = ' ';
113 
114 		if (prev || new)
115 			pr_debug(" %c%s\n", change, bit_desc[i]);
116 		bit <<= 1;
117 		i++;
118 	}
119 	pr_debug("\n");
120 }
121 
rh_port_connect(int rhport,enum usb_device_speed speed)122 void rh_port_connect(int rhport, enum usb_device_speed speed)
123 {
124 	usbip_dbg_vhci_rh("rh_port_connect %d\n", rhport);
125 
126 	spin_lock(&the_controller->lock);
127 
128 	the_controller->port_status[rhport] |= USB_PORT_STAT_CONNECTION
129 		| (1 << USB_PORT_FEAT_C_CONNECTION);
130 
131 	switch (speed) {
132 	case USB_SPEED_HIGH:
133 		the_controller->port_status[rhport] |= USB_PORT_STAT_HIGH_SPEED;
134 		break;
135 	case USB_SPEED_LOW:
136 		the_controller->port_status[rhport] |= USB_PORT_STAT_LOW_SPEED;
137 		break;
138 	default:
139 		break;
140 	}
141 
142 	spin_unlock(&the_controller->lock);
143 
144 	usb_hcd_poll_rh_status(vhci_to_hcd(the_controller));
145 }
146 
rh_port_disconnect(int rhport)147 static void rh_port_disconnect(int rhport)
148 {
149 	usbip_dbg_vhci_rh("rh_port_disconnect %d\n", rhport);
150 
151 	spin_lock(&the_controller->lock);
152 
153 	the_controller->port_status[rhport] &= ~USB_PORT_STAT_CONNECTION;
154 	the_controller->port_status[rhport] |=
155 					(1 << USB_PORT_FEAT_C_CONNECTION);
156 
157 	spin_unlock(&the_controller->lock);
158 	usb_hcd_poll_rh_status(vhci_to_hcd(the_controller));
159 }
160 
161 #define PORT_C_MASK				\
162 	((USB_PORT_STAT_C_CONNECTION		\
163 	  | USB_PORT_STAT_C_ENABLE		\
164 	  | USB_PORT_STAT_C_SUSPEND		\
165 	  | USB_PORT_STAT_C_OVERCURRENT		\
166 	  | USB_PORT_STAT_C_RESET) << 16)
167 
168 /*
169  * Returns 0 if the status hasn't changed, or the number of bytes in buf.
170  * Ports are 0-indexed from the HCD point of view,
171  * and 1-indexed from the USB core pointer of view.
172  *
173  * @buf: a bitmap to show which port status has been changed.
174  *  bit  0: reserved
175  *  bit  1: the status of port 0 has been changed.
176  *  bit  2: the status of port 1 has been changed.
177  *  ...
178  */
vhci_hub_status(struct usb_hcd * hcd,char * buf)179 static int vhci_hub_status(struct usb_hcd *hcd, char *buf)
180 {
181 	struct vhci_hcd	*vhci;
182 	int		retval;
183 	int		rhport;
184 	int		changed = 0;
185 
186 	retval = DIV_ROUND_UP(VHCI_NPORTS + 1, 8);
187 	memset(buf, 0, retval);
188 
189 	vhci = hcd_to_vhci(hcd);
190 
191 	spin_lock(&vhci->lock);
192 	if (!HCD_HW_ACCESSIBLE(hcd)) {
193 		usbip_dbg_vhci_rh("hw accessible flag not on?\n");
194 		goto done;
195 	}
196 
197 	/* check pseudo status register for each port */
198 	for (rhport = 0; rhport < VHCI_NPORTS; rhport++) {
199 		if ((vhci->port_status[rhport] & PORT_C_MASK)) {
200 			/* The status of a port has been changed, */
201 			usbip_dbg_vhci_rh("port %d status changed\n", rhport);
202 
203 			buf[(rhport + 1) / 8] |= 1 << (rhport + 1) % 8;
204 			changed = 1;
205 		}
206 	}
207 
208 	pr_info("changed %d\n", changed);
209 
210 	if ((hcd->state == HC_STATE_SUSPENDED) && (changed == 1))
211 		usb_hcd_resume_root_hub(hcd);
212 
213 done:
214 	spin_unlock(&vhci->lock);
215 	return changed ? retval : 0;
216 }
217 
hub_descriptor(struct usb_hub_descriptor * desc)218 static inline void hub_descriptor(struct usb_hub_descriptor *desc)
219 {
220 	memset(desc, 0, sizeof(*desc));
221 	desc->bDescriptorType = 0x29;
222 	desc->bDescLength = 9;
223 	desc->wHubCharacteristics = (__force __u16)
224 		(__constant_cpu_to_le16(0x0001));
225 	desc->bNbrPorts = VHCI_NPORTS;
226 	desc->u.hs.DeviceRemovable[0] = 0xff;
227 	desc->u.hs.DeviceRemovable[1] = 0xff;
228 }
229 
vhci_hub_control(struct usb_hcd * hcd,u16 typeReq,u16 wValue,u16 wIndex,char * buf,u16 wLength)230 static int vhci_hub_control(struct usb_hcd *hcd, u16 typeReq, u16 wValue,
231 			    u16 wIndex, char *buf, u16 wLength)
232 {
233 	struct vhci_hcd	*dum;
234 	int             retval = 0;
235 	int		rhport;
236 
237 	u32 prev_port_status[VHCI_NPORTS];
238 
239 	if (!HCD_HW_ACCESSIBLE(hcd))
240 		return -ETIMEDOUT;
241 
242 	/*
243 	 * NOTE:
244 	 * wIndex shows the port number and begins from 1.
245 	 */
246 	usbip_dbg_vhci_rh("typeReq %x wValue %x wIndex %x\n", typeReq, wValue,
247 			  wIndex);
248 	if (wIndex > VHCI_NPORTS)
249 		pr_err("invalid port number %d\n", wIndex);
250 	rhport = ((__u8)(wIndex & 0x00ff)) - 1;
251 
252 	dum = hcd_to_vhci(hcd);
253 
254 	spin_lock(&dum->lock);
255 
256 	/* store old status and compare now and old later */
257 	if (usbip_dbg_flag_vhci_rh) {
258 		memcpy(prev_port_status, dum->port_status,
259 			sizeof(prev_port_status));
260 	}
261 
262 	switch (typeReq) {
263 	case ClearHubFeature:
264 		usbip_dbg_vhci_rh(" ClearHubFeature\n");
265 		break;
266 	case ClearPortFeature:
267 		switch (wValue) {
268 		case USB_PORT_FEAT_SUSPEND:
269 			if (dum->port_status[rhport] & USB_PORT_STAT_SUSPEND) {
270 				/* 20msec signaling */
271 				dum->resuming = 1;
272 				dum->re_timeout =
273 					jiffies + msecs_to_jiffies(20);
274 			}
275 			break;
276 		case USB_PORT_FEAT_POWER:
277 			usbip_dbg_vhci_rh(" ClearPortFeature: "
278 					  "USB_PORT_FEAT_POWER\n");
279 			dum->port_status[rhport] = 0;
280 			dum->resuming = 0;
281 			break;
282 		case USB_PORT_FEAT_C_RESET:
283 			usbip_dbg_vhci_rh(" ClearPortFeature: "
284 					  "USB_PORT_FEAT_C_RESET\n");
285 			switch (dum->vdev[rhport].speed) {
286 			case USB_SPEED_HIGH:
287 				dum->port_status[rhport] |=
288 					USB_PORT_STAT_HIGH_SPEED;
289 				break;
290 			case USB_SPEED_LOW:
291 				dum->port_status[rhport] |=
292 					USB_PORT_STAT_LOW_SPEED;
293 				break;
294 			default:
295 				break;
296 			}
297 		default:
298 			usbip_dbg_vhci_rh(" ClearPortFeature: default %x\n",
299 					  wValue);
300 			dum->port_status[rhport] &= ~(1 << wValue);
301 			break;
302 		}
303 		break;
304 	case GetHubDescriptor:
305 		usbip_dbg_vhci_rh(" GetHubDescriptor\n");
306 		hub_descriptor((struct usb_hub_descriptor *) buf);
307 		break;
308 	case GetHubStatus:
309 		usbip_dbg_vhci_rh(" GetHubStatus\n");
310 		*(__le32 *) buf = __constant_cpu_to_le32(0);
311 		break;
312 	case GetPortStatus:
313 		usbip_dbg_vhci_rh(" GetPortStatus port %x\n", wIndex);
314 		if (wIndex > VHCI_NPORTS || wIndex < 1) {
315 			pr_err("invalid port number %d\n", wIndex);
316 			retval = -EPIPE;
317 		}
318 
319 		/* we do not care about resume. */
320 
321 		/* whoever resets or resumes must GetPortStatus to
322 		 * complete it!!
323 		 */
324 		if (dum->resuming && time_after(jiffies, dum->re_timeout)) {
325 			dum->port_status[rhport] |=
326 				(1 << USB_PORT_FEAT_C_SUSPEND);
327 			dum->port_status[rhport] &=
328 				~(1 << USB_PORT_FEAT_SUSPEND);
329 			dum->resuming = 0;
330 			dum->re_timeout = 0;
331 		}
332 
333 		if ((dum->port_status[rhport] & (1 << USB_PORT_FEAT_RESET)) !=
334 		    0 && time_after(jiffies, dum->re_timeout)) {
335 			dum->port_status[rhport] |=
336 				(1 << USB_PORT_FEAT_C_RESET);
337 			dum->port_status[rhport] &=
338 				~(1 << USB_PORT_FEAT_RESET);
339 			dum->re_timeout = 0;
340 
341 			if (dum->vdev[rhport].ud.status ==
342 			    VDEV_ST_NOTASSIGNED) {
343 				usbip_dbg_vhci_rh(" enable rhport %d "
344 						  "(status %u)\n",
345 						  rhport,
346 						  dum->vdev[rhport].ud.status);
347 				dum->port_status[rhport] |=
348 					USB_PORT_STAT_ENABLE;
349 			}
350 		}
351 		((u16 *) buf)[0] = cpu_to_le16(dum->port_status[rhport]);
352 		((u16 *) buf)[1] = cpu_to_le16(dum->port_status[rhport] >> 16);
353 
354 		usbip_dbg_vhci_rh(" GetPortStatus bye %x %x\n", ((u16 *)buf)[0],
355 				  ((u16 *)buf)[1]);
356 		break;
357 	case SetHubFeature:
358 		usbip_dbg_vhci_rh(" SetHubFeature\n");
359 		retval = -EPIPE;
360 		break;
361 	case SetPortFeature:
362 		switch (wValue) {
363 		case USB_PORT_FEAT_SUSPEND:
364 			usbip_dbg_vhci_rh(" SetPortFeature: "
365 					  "USB_PORT_FEAT_SUSPEND\n");
366 			break;
367 		case USB_PORT_FEAT_RESET:
368 			usbip_dbg_vhci_rh(" SetPortFeature: "
369 					  "USB_PORT_FEAT_RESET\n");
370 			/* if it's already running, disconnect first */
371 			if (dum->port_status[rhport] & USB_PORT_STAT_ENABLE) {
372 				dum->port_status[rhport] &=
373 					~(USB_PORT_STAT_ENABLE |
374 					  USB_PORT_STAT_LOW_SPEED |
375 					  USB_PORT_STAT_HIGH_SPEED);
376 				/* FIXME test that code path! */
377 			}
378 			/* 50msec reset signaling */
379 			dum->re_timeout = jiffies + msecs_to_jiffies(50);
380 
381 			/* FALLTHROUGH */
382 		default:
383 			usbip_dbg_vhci_rh(" SetPortFeature: default %d\n",
384 					  wValue);
385 			dum->port_status[rhport] |= (1 << wValue);
386 			break;
387 		}
388 		break;
389 
390 	default:
391 		pr_err("default: no such request\n");
392 
393 		/* "protocol stall" on error */
394 		retval = -EPIPE;
395 	}
396 
397 	if (usbip_dbg_flag_vhci_rh) {
398 		pr_debug("port %d\n", rhport);
399 		/* Only dump valid port status */
400 		if (rhport >= 0) {
401 			dump_port_status_diff(prev_port_status[rhport],
402 					      dum->port_status[rhport]);
403 		}
404 	}
405 	usbip_dbg_vhci_rh(" bye\n");
406 
407 	spin_unlock(&dum->lock);
408 
409 	return retval;
410 }
411 
get_vdev(struct usb_device * udev)412 static struct vhci_device *get_vdev(struct usb_device *udev)
413 {
414 	int i;
415 
416 	if (!udev)
417 		return NULL;
418 
419 	for (i = 0; i < VHCI_NPORTS; i++)
420 		if (the_controller->vdev[i].udev == udev)
421 			return port_to_vdev(i);
422 
423 	return NULL;
424 }
425 
vhci_tx_urb(struct urb * urb)426 static void vhci_tx_urb(struct urb *urb)
427 {
428 	struct vhci_device *vdev = get_vdev(urb->dev);
429 	struct vhci_priv *priv;
430 
431 	if (!vdev) {
432 		pr_err("could not get virtual device");
433 		return;
434 	}
435 
436 	priv = kzalloc(sizeof(struct vhci_priv), GFP_ATOMIC);
437 	if (!priv) {
438 		usbip_event_add(&vdev->ud, VDEV_EVENT_ERROR_MALLOC);
439 		return;
440 	}
441 
442 	spin_lock(&vdev->priv_lock);
443 
444 	priv->seqnum = atomic_inc_return(&the_controller->seqnum);
445 	if (priv->seqnum == 0xffff)
446 		dev_info(&urb->dev->dev, "seqnum max\n");
447 
448 	priv->vdev = vdev;
449 	priv->urb = urb;
450 
451 	urb->hcpriv = (void *) priv;
452 
453 	list_add_tail(&priv->list, &vdev->priv_tx);
454 
455 	wake_up(&vdev->waitq_tx);
456 	spin_unlock(&vdev->priv_lock);
457 }
458 
vhci_urb_enqueue(struct usb_hcd * hcd,struct urb * urb,gfp_t mem_flags)459 static int vhci_urb_enqueue(struct usb_hcd *hcd, struct urb *urb,
460 			    gfp_t mem_flags)
461 {
462 	struct device *dev = &urb->dev->dev;
463 	int ret = 0;
464 	struct vhci_device *vdev;
465 
466 	usbip_dbg_vhci_hc("enter, usb_hcd %p urb %p mem_flags %d\n",
467 			  hcd, urb, mem_flags);
468 
469 	/* patch to usb_sg_init() is in 2.5.60 */
470 	BUG_ON(!urb->transfer_buffer && urb->transfer_buffer_length);
471 
472 	spin_lock(&the_controller->lock);
473 
474 	if (urb->status != -EINPROGRESS) {
475 		dev_err(dev, "URB already unlinked!, status %d\n", urb->status);
476 		spin_unlock(&the_controller->lock);
477 		return urb->status;
478 	}
479 
480 	vdev = port_to_vdev(urb->dev->portnum-1);
481 
482 	/* refuse enqueue for dead connection */
483 	spin_lock(&vdev->ud.lock);
484 	if (vdev->ud.status == VDEV_ST_NULL ||
485 	    vdev->ud.status == VDEV_ST_ERROR) {
486 		dev_err(dev, "enqueue for inactive port %d\n", vdev->rhport);
487 		spin_unlock(&vdev->ud.lock);
488 		spin_unlock(&the_controller->lock);
489 		return -ENODEV;
490 	}
491 	spin_unlock(&vdev->ud.lock);
492 
493 	ret = usb_hcd_link_urb_to_ep(hcd, urb);
494 	if (ret)
495 		goto no_need_unlink;
496 
497 	/*
498 	 * The enumeration process is as follows;
499 	 *
500 	 *  1. Get_Descriptor request to DevAddrs(0) EndPoint(0)
501 	 *     to get max packet length of default pipe
502 	 *
503 	 *  2. Set_Address request to DevAddr(0) EndPoint(0)
504 	 *
505 	 */
506 	if (usb_pipedevice(urb->pipe) == 0) {
507 		__u8 type = usb_pipetype(urb->pipe);
508 		struct usb_ctrlrequest *ctrlreq =
509 			(struct usb_ctrlrequest *) urb->setup_packet;
510 
511 		if (type != PIPE_CONTROL || !ctrlreq) {
512 			dev_err(dev, "invalid request to devnum 0\n");
513 			ret = -EINVAL;
514 			goto no_need_xmit;
515 		}
516 
517 		switch (ctrlreq->bRequest) {
518 		case USB_REQ_SET_ADDRESS:
519 			/* set_address may come when a device is reset */
520 			dev_info(dev, "SetAddress Request (%d) to port %d\n",
521 				 ctrlreq->wValue, vdev->rhport);
522 
523 			if (vdev->udev)
524 				usb_put_dev(vdev->udev);
525 			vdev->udev = usb_get_dev(urb->dev);
526 
527 			spin_lock(&vdev->ud.lock);
528 			vdev->ud.status = VDEV_ST_USED;
529 			spin_unlock(&vdev->ud.lock);
530 
531 			if (urb->status == -EINPROGRESS) {
532 				/* This request is successfully completed. */
533 				/* If not -EINPROGRESS, possibly unlinked. */
534 				urb->status = 0;
535 			}
536 
537 			goto no_need_xmit;
538 
539 		case USB_REQ_GET_DESCRIPTOR:
540 			if (ctrlreq->wValue == (USB_DT_DEVICE << 8))
541 				usbip_dbg_vhci_hc("Not yet?: "
542 						  "Get_Descriptor to device 0 "
543 						  "(get max pipe size)\n");
544 
545 			if (vdev->udev)
546 				usb_put_dev(vdev->udev);
547 			vdev->udev = usb_get_dev(urb->dev);
548 			goto out;
549 
550 		default:
551 			/* NOT REACHED */
552 			dev_err(dev, "invalid request to devnum 0 bRequest %u, "
553 				"wValue %u\n", ctrlreq->bRequest,
554 				ctrlreq->wValue);
555 			ret =  -EINVAL;
556 			goto no_need_xmit;
557 		}
558 
559 	}
560 
561 out:
562 	vhci_tx_urb(urb);
563 	spin_unlock(&the_controller->lock);
564 
565 	return 0;
566 
567 no_need_xmit:
568 	usb_hcd_unlink_urb_from_ep(hcd, urb);
569 no_need_unlink:
570 	spin_unlock(&the_controller->lock);
571 	usb_hcd_giveback_urb(vhci_to_hcd(the_controller), urb, urb->status);
572 	return ret;
573 }
574 
575 /*
576  * vhci_rx gives back the urb after receiving the reply of the urb.  If an
577  * unlink pdu is sent or not, vhci_rx receives a normal return pdu and gives
578  * back its urb. For the driver unlinking the urb, the content of the urb is
579  * not important, but the calling to its completion handler is important; the
580  * completion of unlinking is notified by the completion handler.
581  *
582  *
583  * CLIENT SIDE
584  *
585  * - When vhci_hcd receives RET_SUBMIT,
586  *
587  *	- case 1a). the urb of the pdu is not unlinking.
588  *		- normal case
589  *		=> just give back the urb
590  *
591  *	- case 1b). the urb of the pdu is unlinking.
592  *		- usbip.ko will return a reply of the unlinking request.
593  *		=> give back the urb now and go to case 2b).
594  *
595  * - When vhci_hcd receives RET_UNLINK,
596  *
597  *	- case 2a). a submit request is still pending in vhci_hcd.
598  *		- urb was really pending in usbip.ko and urb_unlink_urb() was
599  *		  completed there.
600  *		=> free a pending submit request
601  *		=> notify unlink completeness by giving back the urb
602  *
603  *	- case 2b). a submit request is *not* pending in vhci_hcd.
604  *		- urb was already given back to the core driver.
605  *		=> do not give back the urb
606  *
607  *
608  * SERVER SIDE
609  *
610  * - When usbip receives CMD_UNLINK,
611  *
612  *	- case 3a). the urb of the unlink request is now in submission.
613  *		=> do usb_unlink_urb().
614  *		=> after the unlink is completed, send RET_UNLINK.
615  *
616  *	- case 3b). the urb of the unlink request is not in submission.
617  *		- may be already completed or never be received
618  *		=> send RET_UNLINK
619  *
620  */
vhci_urb_dequeue(struct usb_hcd * hcd,struct urb * urb,int status)621 static int vhci_urb_dequeue(struct usb_hcd *hcd, struct urb *urb, int status)
622 {
623 	struct vhci_priv *priv;
624 	struct vhci_device *vdev;
625 
626 	pr_info("dequeue a urb %p\n", urb);
627 
628 	spin_lock(&the_controller->lock);
629 
630 	priv = urb->hcpriv;
631 	if (!priv) {
632 		/* URB was never linked! or will be soon given back by
633 		 * vhci_rx. */
634 		spin_unlock(&the_controller->lock);
635 		return 0;
636 	}
637 
638 	{
639 		int ret = 0;
640 		ret = usb_hcd_check_unlink_urb(hcd, urb, status);
641 		if (ret) {
642 			spin_unlock(&the_controller->lock);
643 			return ret;
644 		}
645 	}
646 
647 	 /* send unlink request here? */
648 	vdev = priv->vdev;
649 
650 	if (!vdev->ud.tcp_socket) {
651 		/* tcp connection is closed */
652 		spin_lock(&vdev->priv_lock);
653 
654 		pr_info("device %p seems to be disconnected\n", vdev);
655 		list_del(&priv->list);
656 		kfree(priv);
657 		urb->hcpriv = NULL;
658 
659 		spin_unlock(&vdev->priv_lock);
660 
661 		/*
662 		 * If tcp connection is alive, we have sent CMD_UNLINK.
663 		 * vhci_rx will receive RET_UNLINK and give back the URB.
664 		 * Otherwise, we give back it here.
665 		 */
666 		pr_info("gives back urb %p\n", urb);
667 
668 		usb_hcd_unlink_urb_from_ep(hcd, urb);
669 
670 		spin_unlock(&the_controller->lock);
671 		usb_hcd_giveback_urb(vhci_to_hcd(the_controller), urb,
672 				     urb->status);
673 		spin_lock(&the_controller->lock);
674 
675 	} else {
676 		/* tcp connection is alive */
677 		struct vhci_unlink *unlink;
678 
679 		spin_lock(&vdev->priv_lock);
680 
681 		/* setup CMD_UNLINK pdu */
682 		unlink = kzalloc(sizeof(struct vhci_unlink), GFP_ATOMIC);
683 		if (!unlink) {
684 			spin_unlock(&vdev->priv_lock);
685 			spin_unlock(&the_controller->lock);
686 			usbip_event_add(&vdev->ud, VDEV_EVENT_ERROR_MALLOC);
687 			return -ENOMEM;
688 		}
689 
690 		unlink->seqnum = atomic_inc_return(&the_controller->seqnum);
691 		if (unlink->seqnum == 0xffff)
692 			pr_info("seqnum max\n");
693 
694 		unlink->unlink_seqnum = priv->seqnum;
695 
696 		pr_info("device %p seems to be still connected\n", vdev);
697 
698 		/* send cmd_unlink and try to cancel the pending URB in the
699 		 * peer */
700 		list_add_tail(&unlink->list, &vdev->unlink_tx);
701 		wake_up(&vdev->waitq_tx);
702 
703 		spin_unlock(&vdev->priv_lock);
704 	}
705 
706 	spin_unlock(&the_controller->lock);
707 
708 	usbip_dbg_vhci_hc("leave\n");
709 	return 0;
710 }
711 
vhci_device_unlink_cleanup(struct vhci_device * vdev)712 static void vhci_device_unlink_cleanup(struct vhci_device *vdev)
713 {
714 	struct vhci_unlink *unlink, *tmp;
715 
716 	spin_lock(&the_controller->lock);
717 	spin_lock(&vdev->priv_lock);
718 
719 	list_for_each_entry_safe(unlink, tmp, &vdev->unlink_tx, list) {
720 		pr_info("unlink cleanup tx %lu\n", unlink->unlink_seqnum);
721 		list_del(&unlink->list);
722 		kfree(unlink);
723 	}
724 
725 	while (!list_empty(&vdev->unlink_rx)) {
726 		struct urb *urb;
727 
728 		unlink = list_first_entry(&vdev->unlink_rx, struct vhci_unlink,
729 			list);
730 
731 		/* give back URB of unanswered unlink request */
732 		pr_info("unlink cleanup rx %lu\n", unlink->unlink_seqnum);
733 
734 		urb = pickup_urb_and_free_priv(vdev, unlink->unlink_seqnum);
735 		if (!urb) {
736 			pr_info("the urb (seqnum %lu) was already given back\n",
737 				unlink->unlink_seqnum);
738 			list_del(&unlink->list);
739 			kfree(unlink);
740 			continue;
741 		}
742 
743 		urb->status = -ENODEV;
744 
745 		usb_hcd_unlink_urb_from_ep(vhci_to_hcd(the_controller), urb);
746 
747 		list_del(&unlink->list);
748 
749 		spin_unlock(&vdev->priv_lock);
750 		spin_unlock(&the_controller->lock);
751 
752 		usb_hcd_giveback_urb(vhci_to_hcd(the_controller), urb,
753 				     urb->status);
754 
755 		spin_lock(&the_controller->lock);
756 		spin_lock(&vdev->priv_lock);
757 
758 		kfree(unlink);
759 	}
760 
761 	spin_unlock(&vdev->priv_lock);
762 	spin_unlock(&the_controller->lock);
763 }
764 
765 /*
766  * The important thing is that only one context begins cleanup.
767  * This is why error handling and cleanup become simple.
768  * We do not want to consider race condition as possible.
769  */
vhci_shutdown_connection(struct usbip_device * ud)770 static void vhci_shutdown_connection(struct usbip_device *ud)
771 {
772 	struct vhci_device *vdev = container_of(ud, struct vhci_device, ud);
773 
774 	/* need this? see stub_dev.c */
775 	if (ud->tcp_socket) {
776 		pr_debug("shutdown tcp_socket %p\n", ud->tcp_socket);
777 		kernel_sock_shutdown(ud->tcp_socket, SHUT_RDWR);
778 	}
779 
780 	/* kill threads related to this sdev */
781 	if (vdev->ud.tcp_rx) {
782 		kthread_stop_put(vdev->ud.tcp_rx);
783 		vdev->ud.tcp_rx = NULL;
784 	}
785 	if (vdev->ud.tcp_tx) {
786 		kthread_stop_put(vdev->ud.tcp_tx);
787 		vdev->ud.tcp_tx = NULL;
788 	}
789 	pr_info("stop threads\n");
790 
791 	/* active connection is closed */
792 	if (vdev->ud.tcp_socket) {
793 		fput(vdev->ud.tcp_socket->file);
794 		vdev->ud.tcp_socket = NULL;
795 	}
796 	pr_info("release socket\n");
797 
798 	vhci_device_unlink_cleanup(vdev);
799 
800 	/*
801 	 * rh_port_disconnect() is a trigger of ...
802 	 *   usb_disable_device():
803 	 *	disable all the endpoints for a USB device.
804 	 *   usb_disable_endpoint():
805 	 *	disable endpoints. pending urbs are unlinked(dequeued).
806 	 *
807 	 * NOTE: After calling rh_port_disconnect(), the USB device drivers of a
808 	 * detached device should release used urbs in a cleanup function (i.e.
809 	 * xxx_disconnect()). Therefore, vhci_hcd does not need to release
810 	 * pushed urbs and their private data in this function.
811 	 *
812 	 * NOTE: vhci_dequeue() must be considered carefully. When shutting down
813 	 * a connection, vhci_shutdown_connection() expects vhci_dequeue()
814 	 * gives back pushed urbs and frees their private data by request of
815 	 * the cleanup function of a USB driver. When unlinking a urb with an
816 	 * active connection, vhci_dequeue() does not give back the urb which
817 	 * is actually given back by vhci_rx after receiving its return pdu.
818 	 *
819 	 */
820 	rh_port_disconnect(vdev->rhport);
821 
822 	pr_info("disconnect device\n");
823 }
824 
825 
vhci_device_reset(struct usbip_device * ud)826 static void vhci_device_reset(struct usbip_device *ud)
827 {
828 	struct vhci_device *vdev = container_of(ud, struct vhci_device, ud);
829 
830 	spin_lock(&ud->lock);
831 
832 	vdev->speed  = 0;
833 	vdev->devid  = 0;
834 
835 	if (vdev->udev)
836 		usb_put_dev(vdev->udev);
837 	vdev->udev = NULL;
838 
839 	if (ud->tcp_socket) {
840 		fput(ud->tcp_socket->file);
841 		ud->tcp_socket = NULL;
842 	}
843 	ud->status = VDEV_ST_NULL;
844 
845 	spin_unlock(&ud->lock);
846 }
847 
vhci_device_unusable(struct usbip_device * ud)848 static void vhci_device_unusable(struct usbip_device *ud)
849 {
850 	spin_lock(&ud->lock);
851 	ud->status = VDEV_ST_ERROR;
852 	spin_unlock(&ud->lock);
853 }
854 
vhci_device_init(struct vhci_device * vdev)855 static void vhci_device_init(struct vhci_device *vdev)
856 {
857 	memset(vdev, 0, sizeof(*vdev));
858 
859 	vdev->ud.side   = USBIP_VHCI;
860 	vdev->ud.status = VDEV_ST_NULL;
861 	spin_lock_init(&vdev->ud.lock);
862 
863 	INIT_LIST_HEAD(&vdev->priv_rx);
864 	INIT_LIST_HEAD(&vdev->priv_tx);
865 	INIT_LIST_HEAD(&vdev->unlink_tx);
866 	INIT_LIST_HEAD(&vdev->unlink_rx);
867 	spin_lock_init(&vdev->priv_lock);
868 
869 	init_waitqueue_head(&vdev->waitq_tx);
870 
871 	vdev->ud.eh_ops.shutdown = vhci_shutdown_connection;
872 	vdev->ud.eh_ops.reset = vhci_device_reset;
873 	vdev->ud.eh_ops.unusable = vhci_device_unusable;
874 
875 	usbip_start_eh(&vdev->ud);
876 }
877 
vhci_start(struct usb_hcd * hcd)878 static int vhci_start(struct usb_hcd *hcd)
879 {
880 	struct vhci_hcd *vhci = hcd_to_vhci(hcd);
881 	int rhport;
882 	int err = 0;
883 
884 	usbip_dbg_vhci_hc("enter vhci_start\n");
885 
886 	/* initialize private data of usb_hcd */
887 
888 	for (rhport = 0; rhport < VHCI_NPORTS; rhport++) {
889 		struct vhci_device *vdev = &vhci->vdev[rhport];
890 		vhci_device_init(vdev);
891 		vdev->rhport = rhport;
892 	}
893 
894 	atomic_set(&vhci->seqnum, 0);
895 	spin_lock_init(&vhci->lock);
896 
897 	hcd->power_budget = 0; /* no limit */
898 	hcd->uses_new_polling = 1;
899 
900 	/* vhci_hcd is now ready to be controlled through sysfs */
901 	err = sysfs_create_group(&vhci_dev(vhci)->kobj, &dev_attr_group);
902 	if (err) {
903 		pr_err("create sysfs files\n");
904 		return err;
905 	}
906 
907 	return 0;
908 }
909 
vhci_stop(struct usb_hcd * hcd)910 static void vhci_stop(struct usb_hcd *hcd)
911 {
912 	struct vhci_hcd *vhci = hcd_to_vhci(hcd);
913 	int rhport = 0;
914 
915 	usbip_dbg_vhci_hc("stop VHCI controller\n");
916 
917 	/* 1. remove the userland interface of vhci_hcd */
918 	sysfs_remove_group(&vhci_dev(vhci)->kobj, &dev_attr_group);
919 
920 	/* 2. shutdown all the ports of vhci_hcd */
921 	for (rhport = 0 ; rhport < VHCI_NPORTS; rhport++) {
922 		struct vhci_device *vdev = &vhci->vdev[rhport];
923 
924 		usbip_event_add(&vdev->ud, VDEV_EVENT_REMOVED);
925 		usbip_stop_eh(&vdev->ud);
926 	}
927 }
928 
vhci_get_frame_number(struct usb_hcd * hcd)929 static int vhci_get_frame_number(struct usb_hcd *hcd)
930 {
931 	pr_err("Not yet implemented\n");
932 	return 0;
933 }
934 
935 #ifdef CONFIG_PM
936 
937 /* FIXME: suspend/resume */
vhci_bus_suspend(struct usb_hcd * hcd)938 static int vhci_bus_suspend(struct usb_hcd *hcd)
939 {
940 	struct vhci_hcd *vhci = hcd_to_vhci(hcd);
941 
942 	dev_dbg(&hcd->self.root_hub->dev, "%s\n", __func__);
943 
944 	spin_lock(&vhci->lock);
945 	hcd->state = HC_STATE_SUSPENDED;
946 	spin_unlock(&vhci->lock);
947 
948 	return 0;
949 }
950 
vhci_bus_resume(struct usb_hcd * hcd)951 static int vhci_bus_resume(struct usb_hcd *hcd)
952 {
953 	struct vhci_hcd *vhci = hcd_to_vhci(hcd);
954 	int rc = 0;
955 
956 	dev_dbg(&hcd->self.root_hub->dev, "%s\n", __func__);
957 
958 	spin_lock(&vhci->lock);
959 	if (!HCD_HW_ACCESSIBLE(hcd))
960 		rc = -ESHUTDOWN;
961 	else
962 		hcd->state = HC_STATE_RUNNING;
963 	spin_unlock(&vhci->lock);
964 
965 	return rc;
966 }
967 
968 #else
969 
970 #define vhci_bus_suspend      NULL
971 #define vhci_bus_resume       NULL
972 #endif
973 
974 static struct hc_driver vhci_hc_driver = {
975 	.description	= driver_name,
976 	.product_desc	= driver_desc,
977 	.hcd_priv_size	= sizeof(struct vhci_hcd),
978 
979 	.flags		= HCD_USB2,
980 
981 	.start		= vhci_start,
982 	.stop		= vhci_stop,
983 
984 	.urb_enqueue	= vhci_urb_enqueue,
985 	.urb_dequeue	= vhci_urb_dequeue,
986 
987 	.get_frame_number = vhci_get_frame_number,
988 
989 	.hub_status_data = vhci_hub_status,
990 	.hub_control    = vhci_hub_control,
991 	.bus_suspend	= vhci_bus_suspend,
992 	.bus_resume	= vhci_bus_resume,
993 };
994 
vhci_hcd_probe(struct platform_device * pdev)995 static int vhci_hcd_probe(struct platform_device *pdev)
996 {
997 	struct usb_hcd		*hcd;
998 	int			ret;
999 
1000 	usbip_dbg_vhci_hc("name %s id %d\n", pdev->name, pdev->id);
1001 
1002 	/* will be removed */
1003 	if (pdev->dev.dma_mask) {
1004 		dev_info(&pdev->dev, "vhci_hcd DMA not supported\n");
1005 		return -EINVAL;
1006 	}
1007 
1008 	/*
1009 	 * Allocate and initialize hcd.
1010 	 * Our private data is also allocated automatically.
1011 	 */
1012 	hcd = usb_create_hcd(&vhci_hc_driver, &pdev->dev, dev_name(&pdev->dev));
1013 	if (!hcd) {
1014 		pr_err("create hcd failed\n");
1015 		return -ENOMEM;
1016 	}
1017 	hcd->has_tt = 1;
1018 
1019 	/* this is private data for vhci_hcd */
1020 	the_controller = hcd_to_vhci(hcd);
1021 
1022 	/*
1023 	 * Finish generic HCD structure initialization and register.
1024 	 * Call the driver's reset() and start() routines.
1025 	 */
1026 	ret = usb_add_hcd(hcd, 0, 0);
1027 	if (ret != 0) {
1028 		pr_err("usb_add_hcd failed %d\n", ret);
1029 		usb_put_hcd(hcd);
1030 		the_controller = NULL;
1031 		return ret;
1032 	}
1033 
1034 	usbip_dbg_vhci_hc("bye\n");
1035 	return 0;
1036 }
1037 
vhci_hcd_remove(struct platform_device * pdev)1038 static int vhci_hcd_remove(struct platform_device *pdev)
1039 {
1040 	struct usb_hcd	*hcd;
1041 
1042 	hcd = platform_get_drvdata(pdev);
1043 	if (!hcd)
1044 		return 0;
1045 
1046 	/*
1047 	 * Disconnects the root hub,
1048 	 * then reverses the effects of usb_add_hcd(),
1049 	 * invoking the HCD's stop() methods.
1050 	 */
1051 	usb_remove_hcd(hcd);
1052 	usb_put_hcd(hcd);
1053 	the_controller = NULL;
1054 
1055 	return 0;
1056 }
1057 
1058 #ifdef CONFIG_PM
1059 
1060 /* what should happen for USB/IP under suspend/resume? */
vhci_hcd_suspend(struct platform_device * pdev,pm_message_t state)1061 static int vhci_hcd_suspend(struct platform_device *pdev, pm_message_t state)
1062 {
1063 	struct usb_hcd *hcd;
1064 	int rhport = 0;
1065 	int connected = 0;
1066 	int ret = 0;
1067 
1068 	hcd = platform_get_drvdata(pdev);
1069 
1070 	spin_lock(&the_controller->lock);
1071 
1072 	for (rhport = 0; rhport < VHCI_NPORTS; rhport++)
1073 		if (the_controller->port_status[rhport] &
1074 		    USB_PORT_STAT_CONNECTION)
1075 			connected += 1;
1076 
1077 	spin_unlock(&the_controller->lock);
1078 
1079 	if (connected > 0) {
1080 		dev_info(&pdev->dev, "We have %d active connection%s. Do not "
1081 			 "suspend.\n", connected, (connected == 1 ? "" : "s"));
1082 		ret =  -EBUSY;
1083 	} else {
1084 		dev_info(&pdev->dev, "suspend vhci_hcd");
1085 		clear_bit(HCD_FLAG_HW_ACCESSIBLE, &hcd->flags);
1086 	}
1087 
1088 	return ret;
1089 }
1090 
vhci_hcd_resume(struct platform_device * pdev)1091 static int vhci_hcd_resume(struct platform_device *pdev)
1092 {
1093 	struct usb_hcd *hcd;
1094 
1095 	dev_dbg(&pdev->dev, "%s\n", __func__);
1096 
1097 	hcd = platform_get_drvdata(pdev);
1098 	set_bit(HCD_FLAG_HW_ACCESSIBLE, &hcd->flags);
1099 	usb_hcd_poll_rh_status(hcd);
1100 
1101 	return 0;
1102 }
1103 
1104 #else
1105 
1106 #define vhci_hcd_suspend	NULL
1107 #define vhci_hcd_resume		NULL
1108 
1109 #endif
1110 
1111 static struct platform_driver vhci_driver = {
1112 	.probe	= vhci_hcd_probe,
1113 	.remove	= vhci_hcd_remove,
1114 	.suspend = vhci_hcd_suspend,
1115 	.resume	= vhci_hcd_resume,
1116 	.driver	= {
1117 		.name = (char *) driver_name,
1118 		.owner = THIS_MODULE,
1119 	},
1120 };
1121 
1122 /*
1123  * The VHCI 'device' is 'virtual'; not a real plug&play hardware.
1124  * We need to add this virtual device as a platform device arbitrarily:
1125  *	1. platform_device_register()
1126  */
the_pdev_release(struct device * dev)1127 static void the_pdev_release(struct device *dev)
1128 {
1129 	return;
1130 }
1131 
1132 static struct platform_device the_pdev = {
1133 	/* should be the same name as driver_name */
1134 	.name = (char *) driver_name,
1135 	.id = -1,
1136 	.dev = {
1137 		.release = the_pdev_release,
1138 	},
1139 };
1140 
vhci_hcd_init(void)1141 static int __init vhci_hcd_init(void)
1142 {
1143 	int ret;
1144 
1145 	if (usb_disabled())
1146 		return -ENODEV;
1147 
1148 	ret = platform_driver_register(&vhci_driver);
1149 	if (ret < 0)
1150 		goto err_driver_register;
1151 
1152 	ret = platform_device_register(&the_pdev);
1153 	if (ret < 0)
1154 		goto err_platform_device_register;
1155 
1156 	pr_info(DRIVER_DESC " v" USBIP_VERSION "\n");
1157 	return ret;
1158 
1159 err_platform_device_register:
1160 	platform_driver_unregister(&vhci_driver);
1161 err_driver_register:
1162 	return ret;
1163 }
1164 
vhci_hcd_exit(void)1165 static void __exit vhci_hcd_exit(void)
1166 {
1167 	platform_device_unregister(&the_pdev);
1168 	platform_driver_unregister(&vhci_driver);
1169 }
1170 
1171 module_init(vhci_hcd_init);
1172 module_exit(vhci_hcd_exit);
1173 
1174 MODULE_AUTHOR(DRIVER_AUTHOR);
1175 MODULE_DESCRIPTION(DRIVER_DESC);
1176 MODULE_LICENSE("GPL");
1177 MODULE_VERSION(USBIP_VERSION);
1178