a414008ea64c73280278201c6bd7bff016b16c60
[cascardo/linux.git] / drivers / base / firmware_class.c
1 /*
2  * firmware_class.c - Multi purpose firmware loading support
3  *
4  * Copyright (c) 2003 Manuel Estrada Sainz
5  *
6  * Please see Documentation/firmware_class/ for more information.
7  *
8  */
9
10 #include <linux/capability.h>
11 #include <linux/device.h>
12 #include <linux/module.h>
13 #include <linux/init.h>
14 #include <linux/timer.h>
15 #include <linux/vmalloc.h>
16 #include <linux/interrupt.h>
17 #include <linux/bitops.h>
18 #include <linux/mutex.h>
19 #include <linux/workqueue.h>
20 #include <linux/highmem.h>
21 #include <linux/firmware.h>
22 #include <linux/slab.h>
23 #include <linux/sched.h>
24 #include <linux/file.h>
25 #include <linux/list.h>
26 #include <linux/fs.h>
27 #include <linux/async.h>
28 #include <linux/pm.h>
29 #include <linux/suspend.h>
30 #include <linux/syscore_ops.h>
31 #include <linux/reboot.h>
32 #include <linux/security.h>
33
34 #include <generated/utsrelease.h>
35
36 #include "base.h"
37
38 MODULE_AUTHOR("Manuel Estrada Sainz");
39 MODULE_DESCRIPTION("Multi purpose firmware loading support");
40 MODULE_LICENSE("GPL");
41
42 /* Builtin firmware support */
43
44 #ifdef CONFIG_FW_LOADER
45
46 extern struct builtin_fw __start_builtin_fw[];
47 extern struct builtin_fw __end_builtin_fw[];
48
49 static bool fw_get_builtin_firmware(struct firmware *fw, const char *name)
50 {
51         struct builtin_fw *b_fw;
52
53         for (b_fw = __start_builtin_fw; b_fw != __end_builtin_fw; b_fw++) {
54                 if (strcmp(name, b_fw->name) == 0) {
55                         fw->size = b_fw->size;
56                         fw->data = b_fw->data;
57                         return true;
58                 }
59         }
60
61         return false;
62 }
63
64 static bool fw_is_builtin_firmware(const struct firmware *fw)
65 {
66         struct builtin_fw *b_fw;
67
68         for (b_fw = __start_builtin_fw; b_fw != __end_builtin_fw; b_fw++)
69                 if (fw->data == b_fw->data)
70                         return true;
71
72         return false;
73 }
74
75 #else /* Module case - no builtin firmware support */
76
77 static inline bool fw_get_builtin_firmware(struct firmware *fw, const char *name)
78 {
79         return false;
80 }
81
82 static inline bool fw_is_builtin_firmware(const struct firmware *fw)
83 {
84         return false;
85 }
86 #endif
87
88 enum {
89         FW_STATUS_LOADING,
90         FW_STATUS_DONE,
91         FW_STATUS_ABORT,
92 };
93
94 static int loading_timeout = 60;        /* In seconds */
95
96 static inline long firmware_loading_timeout(void)
97 {
98         return loading_timeout > 0 ? loading_timeout * HZ : MAX_JIFFY_OFFSET;
99 }
100
101 /* firmware behavior options */
102 #define FW_OPT_UEVENT   (1U << 0)
103 #define FW_OPT_NOWAIT   (1U << 1)
104 #ifdef CONFIG_FW_LOADER_USER_HELPER
105 #define FW_OPT_USERHELPER       (1U << 2)
106 #else
107 #define FW_OPT_USERHELPER       0
108 #endif
109 #ifdef CONFIG_FW_LOADER_USER_HELPER_FALLBACK
110 #define FW_OPT_FALLBACK         FW_OPT_USERHELPER
111 #else
112 #define FW_OPT_FALLBACK         0
113 #endif
114 #define FW_OPT_NO_WARN  (1U << 3)
115
116 struct firmware_cache {
117         /* firmware_buf instance will be added into the below list */
118         spinlock_t lock;
119         struct list_head head;
120         int state;
121
122 #ifdef CONFIG_PM_SLEEP
123         /*
124          * Names of firmware images which have been cached successfully
125          * will be added into the below list so that device uncache
126          * helper can trace which firmware images have been cached
127          * before.
128          */
129         spinlock_t name_lock;
130         struct list_head fw_names;
131
132         struct delayed_work work;
133
134         struct notifier_block   pm_notify;
135 #endif
136 };
137
138 struct firmware_buf {
139         struct kref ref;
140         struct list_head list;
141         struct completion completion;
142         struct firmware_cache *fwc;
143         unsigned long status;
144         void *data;
145         size_t size;
146 #ifdef CONFIG_FW_LOADER_USER_HELPER
147         bool is_paged_buf;
148         bool need_uevent;
149         struct page **pages;
150         int nr_pages;
151         int page_array_size;
152         struct list_head pending_list;
153 #endif
154         const char *fw_id;
155 };
156
157 struct fw_cache_entry {
158         struct list_head list;
159         const char *name;
160 };
161
162 struct fw_name_devm {
163         unsigned long magic;
164         const char *name;
165 };
166
167 #define to_fwbuf(d) container_of(d, struct firmware_buf, ref)
168
169 #define FW_LOADER_NO_CACHE      0
170 #define FW_LOADER_START_CACHE   1
171
172 static int fw_cache_piggyback_on_request(const char *name);
173
174 /* fw_lock could be moved to 'struct firmware_priv' but since it is just
175  * guarding for corner cases a global lock should be OK */
176 static DEFINE_MUTEX(fw_lock);
177
178 static struct firmware_cache fw_cache;
179
180 static struct firmware_buf *__allocate_fw_buf(const char *fw_name,
181                                               struct firmware_cache *fwc)
182 {
183         struct firmware_buf *buf;
184
185         buf = kzalloc(sizeof(*buf), GFP_ATOMIC);
186         if (!buf)
187                 return NULL;
188
189         buf->fw_id = kstrdup_const(fw_name, GFP_ATOMIC);
190         if (!buf->fw_id) {
191                 kfree(buf);
192                 return NULL;
193         }
194
195         kref_init(&buf->ref);
196         buf->fwc = fwc;
197         init_completion(&buf->completion);
198 #ifdef CONFIG_FW_LOADER_USER_HELPER
199         INIT_LIST_HEAD(&buf->pending_list);
200 #endif
201
202         pr_debug("%s: fw-%s buf=%p\n", __func__, fw_name, buf);
203
204         return buf;
205 }
206
207 static struct firmware_buf *__fw_lookup_buf(const char *fw_name)
208 {
209         struct firmware_buf *tmp;
210         struct firmware_cache *fwc = &fw_cache;
211
212         list_for_each_entry(tmp, &fwc->head, list)
213                 if (!strcmp(tmp->fw_id, fw_name))
214                         return tmp;
215         return NULL;
216 }
217
218 static int fw_lookup_and_allocate_buf(const char *fw_name,
219                                       struct firmware_cache *fwc,
220                                       struct firmware_buf **buf)
221 {
222         struct firmware_buf *tmp;
223
224         spin_lock(&fwc->lock);
225         tmp = __fw_lookup_buf(fw_name);
226         if (tmp) {
227                 kref_get(&tmp->ref);
228                 spin_unlock(&fwc->lock);
229                 *buf = tmp;
230                 return 1;
231         }
232         tmp = __allocate_fw_buf(fw_name, fwc);
233         if (tmp)
234                 list_add(&tmp->list, &fwc->head);
235         spin_unlock(&fwc->lock);
236
237         *buf = tmp;
238
239         return tmp ? 0 : -ENOMEM;
240 }
241
242 static void __fw_free_buf(struct kref *ref)
243         __releases(&fwc->lock)
244 {
245         struct firmware_buf *buf = to_fwbuf(ref);
246         struct firmware_cache *fwc = buf->fwc;
247
248         pr_debug("%s: fw-%s buf=%p data=%p size=%u\n",
249                  __func__, buf->fw_id, buf, buf->data,
250                  (unsigned int)buf->size);
251
252         list_del(&buf->list);
253         spin_unlock(&fwc->lock);
254
255 #ifdef CONFIG_FW_LOADER_USER_HELPER
256         if (buf->is_paged_buf) {
257                 int i;
258                 vunmap(buf->data);
259                 for (i = 0; i < buf->nr_pages; i++)
260                         __free_page(buf->pages[i]);
261                 kfree(buf->pages);
262         } else
263 #endif
264                 vfree(buf->data);
265         kfree_const(buf->fw_id);
266         kfree(buf);
267 }
268
269 static void fw_free_buf(struct firmware_buf *buf)
270 {
271         struct firmware_cache *fwc = buf->fwc;
272         spin_lock(&fwc->lock);
273         if (!kref_put(&buf->ref, __fw_free_buf))
274                 spin_unlock(&fwc->lock);
275 }
276
277 /* direct firmware loading support */
278 static char fw_path_para[256];
279 static const char * const fw_path[] = {
280         fw_path_para,
281         "/lib/firmware/updates/" UTS_RELEASE,
282         "/lib/firmware/updates",
283         "/lib/firmware/" UTS_RELEASE,
284         "/lib/firmware"
285 };
286
287 /*
288  * Typical usage is that passing 'firmware_class.path=$CUSTOMIZED_PATH'
289  * from kernel command line because firmware_class is generally built in
290  * kernel instead of module.
291  */
292 module_param_string(path, fw_path_para, sizeof(fw_path_para), 0644);
293 MODULE_PARM_DESC(path, "customized firmware image search path with a higher priority than default path");
294
295 static void fw_finish_direct_load(struct device *device,
296                                   struct firmware_buf *buf)
297 {
298         mutex_lock(&fw_lock);
299         set_bit(FW_STATUS_DONE, &buf->status);
300         complete_all(&buf->completion);
301         mutex_unlock(&fw_lock);
302 }
303
304 static int fw_get_filesystem_firmware(struct device *device,
305                                        struct firmware_buf *buf)
306 {
307         loff_t size;
308         int i, len;
309         int rc = -ENOENT;
310         char *path;
311
312         path = __getname();
313         if (!path)
314                 return -ENOMEM;
315
316         for (i = 0; i < ARRAY_SIZE(fw_path); i++) {
317                 /* skip the unset customized path */
318                 if (!fw_path[i][0])
319                         continue;
320
321                 len = snprintf(path, PATH_MAX, "%s/%s",
322                                fw_path[i], buf->fw_id);
323                 if (len >= PATH_MAX) {
324                         rc = -ENAMETOOLONG;
325                         break;
326                 }
327
328                 buf->size = 0;
329                 rc = kernel_read_file_from_path(path, &buf->data, &size,
330                                                 INT_MAX, READING_FIRMWARE);
331                 if (rc) {
332                         dev_warn(device, "loading %s failed with error %d\n",
333                                  path, rc);
334                         continue;
335                 }
336                 dev_dbg(device, "direct-loading %s\n", buf->fw_id);
337                 buf->size = size;
338                 fw_finish_direct_load(device, buf);
339                 break;
340         }
341         __putname(path);
342
343         return rc;
344 }
345
346 /* firmware holds the ownership of pages */
347 static void firmware_free_data(const struct firmware *fw)
348 {
349         /* Loaded directly? */
350         if (!fw->priv) {
351                 vfree(fw->data);
352                 return;
353         }
354         fw_free_buf(fw->priv);
355 }
356
357 /* store the pages buffer info firmware from buf */
358 static void fw_set_page_data(struct firmware_buf *buf, struct firmware *fw)
359 {
360         fw->priv = buf;
361 #ifdef CONFIG_FW_LOADER_USER_HELPER
362         fw->pages = buf->pages;
363 #endif
364         fw->size = buf->size;
365         fw->data = buf->data;
366
367         pr_debug("%s: fw-%s buf=%p data=%p size=%u\n",
368                  __func__, buf->fw_id, buf, buf->data,
369                  (unsigned int)buf->size);
370 }
371
372 #ifdef CONFIG_PM_SLEEP
373 static void fw_name_devm_release(struct device *dev, void *res)
374 {
375         struct fw_name_devm *fwn = res;
376
377         if (fwn->magic == (unsigned long)&fw_cache)
378                 pr_debug("%s: fw_name-%s devm-%p released\n",
379                                 __func__, fwn->name, res);
380         kfree_const(fwn->name);
381 }
382
383 static int fw_devm_match(struct device *dev, void *res,
384                 void *match_data)
385 {
386         struct fw_name_devm *fwn = res;
387
388         return (fwn->magic == (unsigned long)&fw_cache) &&
389                 !strcmp(fwn->name, match_data);
390 }
391
392 static struct fw_name_devm *fw_find_devm_name(struct device *dev,
393                 const char *name)
394 {
395         struct fw_name_devm *fwn;
396
397         fwn = devres_find(dev, fw_name_devm_release,
398                           fw_devm_match, (void *)name);
399         return fwn;
400 }
401
402 /* add firmware name into devres list */
403 static int fw_add_devm_name(struct device *dev, const char *name)
404 {
405         struct fw_name_devm *fwn;
406
407         fwn = fw_find_devm_name(dev, name);
408         if (fwn)
409                 return 1;
410
411         fwn = devres_alloc(fw_name_devm_release, sizeof(struct fw_name_devm),
412                            GFP_KERNEL);
413         if (!fwn)
414                 return -ENOMEM;
415         fwn->name = kstrdup_const(name, GFP_KERNEL);
416         if (!fwn->name) {
417                 devres_free(fwn);
418                 return -ENOMEM;
419         }
420
421         fwn->magic = (unsigned long)&fw_cache;
422         devres_add(dev, fwn);
423
424         return 0;
425 }
426 #else
427 static int fw_add_devm_name(struct device *dev, const char *name)
428 {
429         return 0;
430 }
431 #endif
432
433
434 /*
435  * user-mode helper code
436  */
437 #ifdef CONFIG_FW_LOADER_USER_HELPER
438 struct firmware_priv {
439         bool nowait;
440         struct device dev;
441         struct firmware_buf *buf;
442         struct firmware *fw;
443 };
444
445 static struct firmware_priv *to_firmware_priv(struct device *dev)
446 {
447         return container_of(dev, struct firmware_priv, dev);
448 }
449
450 static void __fw_load_abort(struct firmware_buf *buf)
451 {
452         /*
453          * There is a small window in which user can write to 'loading'
454          * between loading done and disappearance of 'loading'
455          */
456         if (test_bit(FW_STATUS_DONE, &buf->status))
457                 return;
458
459         list_del_init(&buf->pending_list);
460         set_bit(FW_STATUS_ABORT, &buf->status);
461         complete_all(&buf->completion);
462 }
463
464 static void fw_load_abort(struct firmware_priv *fw_priv)
465 {
466         struct firmware_buf *buf = fw_priv->buf;
467
468         __fw_load_abort(buf);
469
470         /* avoid user action after loading abort */
471         fw_priv->buf = NULL;
472 }
473
474 #define is_fw_load_aborted(buf) \
475         test_bit(FW_STATUS_ABORT, &(buf)->status)
476
477 static LIST_HEAD(pending_fw_head);
478
479 /* reboot notifier for avoid deadlock with usermode_lock */
480 static int fw_shutdown_notify(struct notifier_block *unused1,
481                               unsigned long unused2, void *unused3)
482 {
483         mutex_lock(&fw_lock);
484         while (!list_empty(&pending_fw_head))
485                 __fw_load_abort(list_first_entry(&pending_fw_head,
486                                                struct firmware_buf,
487                                                pending_list));
488         mutex_unlock(&fw_lock);
489         return NOTIFY_DONE;
490 }
491
492 static struct notifier_block fw_shutdown_nb = {
493         .notifier_call = fw_shutdown_notify,
494 };
495
496 static ssize_t timeout_show(struct class *class, struct class_attribute *attr,
497                             char *buf)
498 {
499         return sprintf(buf, "%d\n", loading_timeout);
500 }
501
502 /**
503  * firmware_timeout_store - set number of seconds to wait for firmware
504  * @class: device class pointer
505  * @attr: device attribute pointer
506  * @buf: buffer to scan for timeout value
507  * @count: number of bytes in @buf
508  *
509  *      Sets the number of seconds to wait for the firmware.  Once
510  *      this expires an error will be returned to the driver and no
511  *      firmware will be provided.
512  *
513  *      Note: zero means 'wait forever'.
514  **/
515 static ssize_t timeout_store(struct class *class, struct class_attribute *attr,
516                              const char *buf, size_t count)
517 {
518         loading_timeout = simple_strtol(buf, NULL, 10);
519         if (loading_timeout < 0)
520                 loading_timeout = 0;
521
522         return count;
523 }
524
525 static struct class_attribute firmware_class_attrs[] = {
526         __ATTR_RW(timeout),
527         __ATTR_NULL
528 };
529
530 static void fw_dev_release(struct device *dev)
531 {
532         struct firmware_priv *fw_priv = to_firmware_priv(dev);
533
534         kfree(fw_priv);
535 }
536
537 static int do_firmware_uevent(struct firmware_priv *fw_priv, struct kobj_uevent_env *env)
538 {
539         if (add_uevent_var(env, "FIRMWARE=%s", fw_priv->buf->fw_id))
540                 return -ENOMEM;
541         if (add_uevent_var(env, "TIMEOUT=%i", loading_timeout))
542                 return -ENOMEM;
543         if (add_uevent_var(env, "ASYNC=%d", fw_priv->nowait))
544                 return -ENOMEM;
545
546         return 0;
547 }
548
549 static int firmware_uevent(struct device *dev, struct kobj_uevent_env *env)
550 {
551         struct firmware_priv *fw_priv = to_firmware_priv(dev);
552         int err = 0;
553
554         mutex_lock(&fw_lock);
555         if (fw_priv->buf)
556                 err = do_firmware_uevent(fw_priv, env);
557         mutex_unlock(&fw_lock);
558         return err;
559 }
560
561 static struct class firmware_class = {
562         .name           = "firmware",
563         .class_attrs    = firmware_class_attrs,
564         .dev_uevent     = firmware_uevent,
565         .dev_release    = fw_dev_release,
566 };
567
568 static ssize_t firmware_loading_show(struct device *dev,
569                                      struct device_attribute *attr, char *buf)
570 {
571         struct firmware_priv *fw_priv = to_firmware_priv(dev);
572         int loading = 0;
573
574         mutex_lock(&fw_lock);
575         if (fw_priv->buf)
576                 loading = test_bit(FW_STATUS_LOADING, &fw_priv->buf->status);
577         mutex_unlock(&fw_lock);
578
579         return sprintf(buf, "%d\n", loading);
580 }
581
582 /* Some architectures don't have PAGE_KERNEL_RO */
583 #ifndef PAGE_KERNEL_RO
584 #define PAGE_KERNEL_RO PAGE_KERNEL
585 #endif
586
587 /* one pages buffer should be mapped/unmapped only once */
588 static int fw_map_pages_buf(struct firmware_buf *buf)
589 {
590         if (!buf->is_paged_buf)
591                 return 0;
592
593         vunmap(buf->data);
594         buf->data = vmap(buf->pages, buf->nr_pages, 0, PAGE_KERNEL_RO);
595         if (!buf->data)
596                 return -ENOMEM;
597         return 0;
598 }
599
600 /**
601  * firmware_loading_store - set value in the 'loading' control file
602  * @dev: device pointer
603  * @attr: device attribute pointer
604  * @buf: buffer to scan for loading control value
605  * @count: number of bytes in @buf
606  *
607  *      The relevant values are:
608  *
609  *       1: Start a load, discarding any previous partial load.
610  *       0: Conclude the load and hand the data to the driver code.
611  *      -1: Conclude the load with an error and discard any written data.
612  **/
613 static ssize_t firmware_loading_store(struct device *dev,
614                                       struct device_attribute *attr,
615                                       const char *buf, size_t count)
616 {
617         struct firmware_priv *fw_priv = to_firmware_priv(dev);
618         struct firmware_buf *fw_buf;
619         ssize_t written = count;
620         int loading = simple_strtol(buf, NULL, 10);
621         int i;
622
623         mutex_lock(&fw_lock);
624         fw_buf = fw_priv->buf;
625         if (!fw_buf)
626                 goto out;
627
628         switch (loading) {
629         case 1:
630                 /* discarding any previous partial load */
631                 if (!test_bit(FW_STATUS_DONE, &fw_buf->status)) {
632                         for (i = 0; i < fw_buf->nr_pages; i++)
633                                 __free_page(fw_buf->pages[i]);
634                         kfree(fw_buf->pages);
635                         fw_buf->pages = NULL;
636                         fw_buf->page_array_size = 0;
637                         fw_buf->nr_pages = 0;
638                         set_bit(FW_STATUS_LOADING, &fw_buf->status);
639                 }
640                 break;
641         case 0:
642                 if (test_bit(FW_STATUS_LOADING, &fw_buf->status)) {
643                         int rc;
644
645                         set_bit(FW_STATUS_DONE, &fw_buf->status);
646                         clear_bit(FW_STATUS_LOADING, &fw_buf->status);
647
648                         /*
649                          * Several loading requests may be pending on
650                          * one same firmware buf, so let all requests
651                          * see the mapped 'buf->data' once the loading
652                          * is completed.
653                          * */
654                         rc = fw_map_pages_buf(fw_buf);
655                         if (rc)
656                                 dev_err(dev, "%s: map pages failed\n",
657                                         __func__);
658                         else
659                                 rc = security_kernel_post_read_file(NULL,
660                                                 fw_buf->data, fw_buf->size,
661                                                 READING_FIRMWARE);
662
663                         /*
664                          * Same logic as fw_load_abort, only the DONE bit
665                          * is ignored and we set ABORT only on failure.
666                          */
667                         list_del_init(&fw_buf->pending_list);
668                         if (rc) {
669                                 set_bit(FW_STATUS_ABORT, &fw_buf->status);
670                                 written = rc;
671                         }
672                         complete_all(&fw_buf->completion);
673                         break;
674                 }
675                 /* fallthrough */
676         default:
677                 dev_err(dev, "%s: unexpected value (%d)\n", __func__, loading);
678                 /* fallthrough */
679         case -1:
680                 fw_load_abort(fw_priv);
681                 break;
682         }
683 out:
684         mutex_unlock(&fw_lock);
685         return written;
686 }
687
688 static DEVICE_ATTR(loading, 0644, firmware_loading_show, firmware_loading_store);
689
690 static ssize_t firmware_data_read(struct file *filp, struct kobject *kobj,
691                                   struct bin_attribute *bin_attr,
692                                   char *buffer, loff_t offset, size_t count)
693 {
694         struct device *dev = kobj_to_dev(kobj);
695         struct firmware_priv *fw_priv = to_firmware_priv(dev);
696         struct firmware_buf *buf;
697         ssize_t ret_count;
698
699         mutex_lock(&fw_lock);
700         buf = fw_priv->buf;
701         if (!buf || test_bit(FW_STATUS_DONE, &buf->status)) {
702                 ret_count = -ENODEV;
703                 goto out;
704         }
705         if (offset > buf->size) {
706                 ret_count = 0;
707                 goto out;
708         }
709         if (count > buf->size - offset)
710                 count = buf->size - offset;
711
712         ret_count = count;
713
714         while (count) {
715                 void *page_data;
716                 int page_nr = offset >> PAGE_SHIFT;
717                 int page_ofs = offset & (PAGE_SIZE-1);
718                 int page_cnt = min_t(size_t, PAGE_SIZE - page_ofs, count);
719
720                 page_data = kmap(buf->pages[page_nr]);
721
722                 memcpy(buffer, page_data + page_ofs, page_cnt);
723
724                 kunmap(buf->pages[page_nr]);
725                 buffer += page_cnt;
726                 offset += page_cnt;
727                 count -= page_cnt;
728         }
729 out:
730         mutex_unlock(&fw_lock);
731         return ret_count;
732 }
733
734 static int fw_realloc_buffer(struct firmware_priv *fw_priv, int min_size)
735 {
736         struct firmware_buf *buf = fw_priv->buf;
737         int pages_needed = PAGE_ALIGN(min_size) >> PAGE_SHIFT;
738
739         /* If the array of pages is too small, grow it... */
740         if (buf->page_array_size < pages_needed) {
741                 int new_array_size = max(pages_needed,
742                                          buf->page_array_size * 2);
743                 struct page **new_pages;
744
745                 new_pages = kmalloc(new_array_size * sizeof(void *),
746                                     GFP_KERNEL);
747                 if (!new_pages) {
748                         fw_load_abort(fw_priv);
749                         return -ENOMEM;
750                 }
751                 memcpy(new_pages, buf->pages,
752                        buf->page_array_size * sizeof(void *));
753                 memset(&new_pages[buf->page_array_size], 0, sizeof(void *) *
754                        (new_array_size - buf->page_array_size));
755                 kfree(buf->pages);
756                 buf->pages = new_pages;
757                 buf->page_array_size = new_array_size;
758         }
759
760         while (buf->nr_pages < pages_needed) {
761                 buf->pages[buf->nr_pages] =
762                         alloc_page(GFP_KERNEL | __GFP_HIGHMEM);
763
764                 if (!buf->pages[buf->nr_pages]) {
765                         fw_load_abort(fw_priv);
766                         return -ENOMEM;
767                 }
768                 buf->nr_pages++;
769         }
770         return 0;
771 }
772
773 /**
774  * firmware_data_write - write method for firmware
775  * @filp: open sysfs file
776  * @kobj: kobject for the device
777  * @bin_attr: bin_attr structure
778  * @buffer: buffer being written
779  * @offset: buffer offset for write in total data store area
780  * @count: buffer size
781  *
782  *      Data written to the 'data' attribute will be later handed to
783  *      the driver as a firmware image.
784  **/
785 static ssize_t firmware_data_write(struct file *filp, struct kobject *kobj,
786                                    struct bin_attribute *bin_attr,
787                                    char *buffer, loff_t offset, size_t count)
788 {
789         struct device *dev = kobj_to_dev(kobj);
790         struct firmware_priv *fw_priv = to_firmware_priv(dev);
791         struct firmware_buf *buf;
792         ssize_t retval;
793
794         if (!capable(CAP_SYS_RAWIO))
795                 return -EPERM;
796
797         mutex_lock(&fw_lock);
798         buf = fw_priv->buf;
799         if (!buf || test_bit(FW_STATUS_DONE, &buf->status)) {
800                 retval = -ENODEV;
801                 goto out;
802         }
803
804         retval = fw_realloc_buffer(fw_priv, offset + count);
805         if (retval)
806                 goto out;
807
808         retval = count;
809
810         while (count) {
811                 void *page_data;
812                 int page_nr = offset >> PAGE_SHIFT;
813                 int page_ofs = offset & (PAGE_SIZE - 1);
814                 int page_cnt = min_t(size_t, PAGE_SIZE - page_ofs, count);
815
816                 page_data = kmap(buf->pages[page_nr]);
817
818                 memcpy(page_data + page_ofs, buffer, page_cnt);
819
820                 kunmap(buf->pages[page_nr]);
821                 buffer += page_cnt;
822                 offset += page_cnt;
823                 count -= page_cnt;
824         }
825
826         buf->size = max_t(size_t, offset, buf->size);
827 out:
828         mutex_unlock(&fw_lock);
829         return retval;
830 }
831
832 static struct bin_attribute firmware_attr_data = {
833         .attr = { .name = "data", .mode = 0644 },
834         .size = 0,
835         .read = firmware_data_read,
836         .write = firmware_data_write,
837 };
838
839 static struct attribute *fw_dev_attrs[] = {
840         &dev_attr_loading.attr,
841         NULL
842 };
843
844 static struct bin_attribute *fw_dev_bin_attrs[] = {
845         &firmware_attr_data,
846         NULL
847 };
848
849 static const struct attribute_group fw_dev_attr_group = {
850         .attrs = fw_dev_attrs,
851         .bin_attrs = fw_dev_bin_attrs,
852 };
853
854 static const struct attribute_group *fw_dev_attr_groups[] = {
855         &fw_dev_attr_group,
856         NULL
857 };
858
859 static struct firmware_priv *
860 fw_create_instance(struct firmware *firmware, const char *fw_name,
861                    struct device *device, unsigned int opt_flags)
862 {
863         struct firmware_priv *fw_priv;
864         struct device *f_dev;
865
866         fw_priv = kzalloc(sizeof(*fw_priv), GFP_KERNEL);
867         if (!fw_priv) {
868                 fw_priv = ERR_PTR(-ENOMEM);
869                 goto exit;
870         }
871
872         fw_priv->nowait = !!(opt_flags & FW_OPT_NOWAIT);
873         fw_priv->fw = firmware;
874         f_dev = &fw_priv->dev;
875
876         device_initialize(f_dev);
877         dev_set_name(f_dev, "%s", fw_name);
878         f_dev->parent = device;
879         f_dev->class = &firmware_class;
880         f_dev->groups = fw_dev_attr_groups;
881 exit:
882         return fw_priv;
883 }
884
885 /* load a firmware via user helper */
886 static int _request_firmware_load(struct firmware_priv *fw_priv,
887                                   unsigned int opt_flags, long timeout)
888 {
889         int retval = 0;
890         struct device *f_dev = &fw_priv->dev;
891         struct firmware_buf *buf = fw_priv->buf;
892
893         /* fall back on userspace loading */
894         buf->is_paged_buf = true;
895
896         dev_set_uevent_suppress(f_dev, true);
897
898         retval = device_add(f_dev);
899         if (retval) {
900                 dev_err(f_dev, "%s: device_register failed\n", __func__);
901                 goto err_put_dev;
902         }
903
904         mutex_lock(&fw_lock);
905         list_add(&buf->pending_list, &pending_fw_head);
906         mutex_unlock(&fw_lock);
907
908         if (opt_flags & FW_OPT_UEVENT) {
909                 buf->need_uevent = true;
910                 dev_set_uevent_suppress(f_dev, false);
911                 dev_dbg(f_dev, "firmware: requesting %s\n", buf->fw_id);
912                 kobject_uevent(&fw_priv->dev.kobj, KOBJ_ADD);
913         } else {
914                 timeout = MAX_JIFFY_OFFSET;
915         }
916
917         retval = wait_for_completion_interruptible_timeout(&buf->completion,
918                         timeout);
919         if (retval == -ERESTARTSYS || !retval) {
920                 mutex_lock(&fw_lock);
921                 fw_load_abort(fw_priv);
922                 mutex_unlock(&fw_lock);
923         } else if (retval > 0) {
924                 retval = 0;
925         }
926
927         if (is_fw_load_aborted(buf))
928                 retval = -EAGAIN;
929         else if (!buf->data)
930                 retval = -ENOMEM;
931
932         device_del(f_dev);
933 err_put_dev:
934         put_device(f_dev);
935         return retval;
936 }
937
938 static int fw_load_from_user_helper(struct firmware *firmware,
939                                     const char *name, struct device *device,
940                                     unsigned int opt_flags, long timeout)
941 {
942         struct firmware_priv *fw_priv;
943
944         fw_priv = fw_create_instance(firmware, name, device, opt_flags);
945         if (IS_ERR(fw_priv))
946                 return PTR_ERR(fw_priv);
947
948         fw_priv->buf = firmware->priv;
949         return _request_firmware_load(fw_priv, opt_flags, timeout);
950 }
951
952 #ifdef CONFIG_PM_SLEEP
953 /* kill pending requests without uevent to avoid blocking suspend */
954 static void kill_requests_without_uevent(void)
955 {
956         struct firmware_buf *buf;
957         struct firmware_buf *next;
958
959         mutex_lock(&fw_lock);
960         list_for_each_entry_safe(buf, next, &pending_fw_head, pending_list) {
961                 if (!buf->need_uevent)
962                          __fw_load_abort(buf);
963         }
964         mutex_unlock(&fw_lock);
965 }
966 #endif
967
968 #else /* CONFIG_FW_LOADER_USER_HELPER */
969 static inline int
970 fw_load_from_user_helper(struct firmware *firmware, const char *name,
971                          struct device *device, unsigned int opt_flags,
972                          long timeout)
973 {
974         return -ENOENT;
975 }
976
977 /* No abort during direct loading */
978 #define is_fw_load_aborted(buf) false
979
980 #ifdef CONFIG_PM_SLEEP
981 static inline void kill_requests_without_uevent(void) { }
982 #endif
983
984 #endif /* CONFIG_FW_LOADER_USER_HELPER */
985
986
987 /* wait until the shared firmware_buf becomes ready (or error) */
988 static int sync_cached_firmware_buf(struct firmware_buf *buf)
989 {
990         int ret = 0;
991
992         mutex_lock(&fw_lock);
993         while (!test_bit(FW_STATUS_DONE, &buf->status)) {
994                 if (is_fw_load_aborted(buf)) {
995                         ret = -ENOENT;
996                         break;
997                 }
998                 mutex_unlock(&fw_lock);
999                 ret = wait_for_completion_interruptible(&buf->completion);
1000                 mutex_lock(&fw_lock);
1001         }
1002         mutex_unlock(&fw_lock);
1003         return ret;
1004 }
1005
1006 /* prepare firmware and firmware_buf structs;
1007  * return 0 if a firmware is already assigned, 1 if need to load one,
1008  * or a negative error code
1009  */
1010 static int
1011 _request_firmware_prepare(struct firmware **firmware_p, const char *name,
1012                           struct device *device)
1013 {
1014         struct firmware *firmware;
1015         struct firmware_buf *buf;
1016         int ret;
1017
1018         *firmware_p = firmware = kzalloc(sizeof(*firmware), GFP_KERNEL);
1019         if (!firmware) {
1020                 dev_err(device, "%s: kmalloc(struct firmware) failed\n",
1021                         __func__);
1022                 return -ENOMEM;
1023         }
1024
1025         if (fw_get_builtin_firmware(firmware, name)) {
1026                 dev_dbg(device, "using built-in %s\n", name);
1027                 return 0; /* assigned */
1028         }
1029
1030         ret = fw_lookup_and_allocate_buf(name, &fw_cache, &buf);
1031
1032         /*
1033          * bind with 'buf' now to avoid warning in failure path
1034          * of requesting firmware.
1035          */
1036         firmware->priv = buf;
1037
1038         if (ret > 0) {
1039                 ret = sync_cached_firmware_buf(buf);
1040                 if (!ret) {
1041                         fw_set_page_data(buf, firmware);
1042                         return 0; /* assigned */
1043                 }
1044         }
1045
1046         if (ret < 0)
1047                 return ret;
1048         return 1; /* need to load */
1049 }
1050
1051 static int assign_firmware_buf(struct firmware *fw, struct device *device,
1052                                unsigned int opt_flags)
1053 {
1054         struct firmware_buf *buf = fw->priv;
1055
1056         mutex_lock(&fw_lock);
1057         if (!buf->size || is_fw_load_aborted(buf)) {
1058                 mutex_unlock(&fw_lock);
1059                 return -ENOENT;
1060         }
1061
1062         /*
1063          * add firmware name into devres list so that we can auto cache
1064          * and uncache firmware for device.
1065          *
1066          * device may has been deleted already, but the problem
1067          * should be fixed in devres or driver core.
1068          */
1069         /* don't cache firmware handled without uevent */
1070         if (device && (opt_flags & FW_OPT_UEVENT))
1071                 fw_add_devm_name(device, buf->fw_id);
1072
1073         /*
1074          * After caching firmware image is started, let it piggyback
1075          * on request firmware.
1076          */
1077         if (buf->fwc->state == FW_LOADER_START_CACHE) {
1078                 if (fw_cache_piggyback_on_request(buf->fw_id))
1079                         kref_get(&buf->ref);
1080         }
1081
1082         /* pass the pages buffer to driver at the last minute */
1083         fw_set_page_data(buf, fw);
1084         mutex_unlock(&fw_lock);
1085         return 0;
1086 }
1087
1088 /* called from request_firmware() and request_firmware_work_func() */
1089 static int
1090 _request_firmware(const struct firmware **firmware_p, const char *name,
1091                   struct device *device, unsigned int opt_flags)
1092 {
1093         struct firmware *fw = NULL;
1094         long timeout;
1095         int ret;
1096
1097         if (!firmware_p)
1098                 return -EINVAL;
1099
1100         if (!name || name[0] == '\0') {
1101                 ret = -EINVAL;
1102                 goto out;
1103         }
1104
1105         ret = _request_firmware_prepare(&fw, name, device);
1106         if (ret <= 0) /* error or already assigned */
1107                 goto out;
1108
1109         ret = 0;
1110         timeout = firmware_loading_timeout();
1111         if (opt_flags & FW_OPT_NOWAIT) {
1112                 timeout = usermodehelper_read_lock_wait(timeout);
1113                 if (!timeout) {
1114                         dev_dbg(device, "firmware: %s loading timed out\n",
1115                                 name);
1116                         ret = -EBUSY;
1117                         goto out;
1118                 }
1119         } else {
1120                 ret = usermodehelper_read_trylock();
1121                 if (WARN_ON(ret)) {
1122                         dev_err(device, "firmware: %s will not be loaded\n",
1123                                 name);
1124                         goto out;
1125                 }
1126         }
1127
1128         ret = fw_get_filesystem_firmware(device, fw->priv);
1129         if (ret) {
1130                 if (!(opt_flags & FW_OPT_NO_WARN))
1131                         dev_warn(device,
1132                                  "Direct firmware load for %s failed with error %d\n",
1133                                  name, ret);
1134                 if (opt_flags & FW_OPT_USERHELPER) {
1135                         dev_warn(device, "Falling back to user helper\n");
1136                         ret = fw_load_from_user_helper(fw, name, device,
1137                                                        opt_flags, timeout);
1138                 }
1139         }
1140
1141         if (!ret)
1142                 ret = assign_firmware_buf(fw, device, opt_flags);
1143
1144         usermodehelper_read_unlock();
1145
1146  out:
1147         if (ret < 0) {
1148                 release_firmware(fw);
1149                 fw = NULL;
1150         }
1151
1152         *firmware_p = fw;
1153         return ret;
1154 }
1155
1156 /**
1157  * request_firmware: - send firmware request and wait for it
1158  * @firmware_p: pointer to firmware image
1159  * @name: name of firmware file
1160  * @device: device for which firmware is being loaded
1161  *
1162  *      @firmware_p will be used to return a firmware image by the name
1163  *      of @name for device @device.
1164  *
1165  *      Should be called from user context where sleeping is allowed.
1166  *
1167  *      @name will be used as $FIRMWARE in the uevent environment and
1168  *      should be distinctive enough not to be confused with any other
1169  *      firmware image for this or any other device.
1170  *
1171  *      Caller must hold the reference count of @device.
1172  *
1173  *      The function can be called safely inside device's suspend and
1174  *      resume callback.
1175  **/
1176 int
1177 request_firmware(const struct firmware **firmware_p, const char *name,
1178                  struct device *device)
1179 {
1180         int ret;
1181
1182         /* Need to pin this module until return */
1183         __module_get(THIS_MODULE);
1184         ret = _request_firmware(firmware_p, name, device,
1185                                 FW_OPT_UEVENT | FW_OPT_FALLBACK);
1186         module_put(THIS_MODULE);
1187         return ret;
1188 }
1189 EXPORT_SYMBOL(request_firmware);
1190
1191 /**
1192  * request_firmware_direct: - load firmware directly without usermode helper
1193  * @firmware_p: pointer to firmware image
1194  * @name: name of firmware file
1195  * @device: device for which firmware is being loaded
1196  *
1197  * This function works pretty much like request_firmware(), but this doesn't
1198  * fall back to usermode helper even if the firmware couldn't be loaded
1199  * directly from fs.  Hence it's useful for loading optional firmwares, which
1200  * aren't always present, without extra long timeouts of udev.
1201  **/
1202 int request_firmware_direct(const struct firmware **firmware_p,
1203                             const char *name, struct device *device)
1204 {
1205         int ret;
1206
1207         __module_get(THIS_MODULE);
1208         ret = _request_firmware(firmware_p, name, device,
1209                                 FW_OPT_UEVENT | FW_OPT_NO_WARN);
1210         module_put(THIS_MODULE);
1211         return ret;
1212 }
1213 EXPORT_SYMBOL_GPL(request_firmware_direct);
1214
1215 /**
1216  * release_firmware: - release the resource associated with a firmware image
1217  * @fw: firmware resource to release
1218  **/
1219 void release_firmware(const struct firmware *fw)
1220 {
1221         if (fw) {
1222                 if (!fw_is_builtin_firmware(fw))
1223                         firmware_free_data(fw);
1224                 kfree(fw);
1225         }
1226 }
1227 EXPORT_SYMBOL(release_firmware);
1228
1229 /* Async support */
1230 struct firmware_work {
1231         struct work_struct work;
1232         struct module *module;
1233         const char *name;
1234         struct device *device;
1235         void *context;
1236         void (*cont)(const struct firmware *fw, void *context);
1237         unsigned int opt_flags;
1238 };
1239
1240 static void request_firmware_work_func(struct work_struct *work)
1241 {
1242         struct firmware_work *fw_work;
1243         const struct firmware *fw;
1244
1245         fw_work = container_of(work, struct firmware_work, work);
1246
1247         _request_firmware(&fw, fw_work->name, fw_work->device,
1248                           fw_work->opt_flags);
1249         fw_work->cont(fw, fw_work->context);
1250         put_device(fw_work->device); /* taken in request_firmware_nowait() */
1251
1252         module_put(fw_work->module);
1253         kfree_const(fw_work->name);
1254         kfree(fw_work);
1255 }
1256
1257 /**
1258  * request_firmware_nowait - asynchronous version of request_firmware
1259  * @module: module requesting the firmware
1260  * @uevent: sends uevent to copy the firmware image if this flag
1261  *      is non-zero else the firmware copy must be done manually.
1262  * @name: name of firmware file
1263  * @device: device for which firmware is being loaded
1264  * @gfp: allocation flags
1265  * @context: will be passed over to @cont, and
1266  *      @fw may be %NULL if firmware request fails.
1267  * @cont: function will be called asynchronously when the firmware
1268  *      request is over.
1269  *
1270  *      Caller must hold the reference count of @device.
1271  *
1272  *      Asynchronous variant of request_firmware() for user contexts:
1273  *              - sleep for as small periods as possible since it may
1274  *              increase kernel boot time of built-in device drivers
1275  *              requesting firmware in their ->probe() methods, if
1276  *              @gfp is GFP_KERNEL.
1277  *
1278  *              - can't sleep at all if @gfp is GFP_ATOMIC.
1279  **/
1280 int
1281 request_firmware_nowait(
1282         struct module *module, bool uevent,
1283         const char *name, struct device *device, gfp_t gfp, void *context,
1284         void (*cont)(const struct firmware *fw, void *context))
1285 {
1286         struct firmware_work *fw_work;
1287
1288         fw_work = kzalloc(sizeof(struct firmware_work), gfp);
1289         if (!fw_work)
1290                 return -ENOMEM;
1291
1292         fw_work->module = module;
1293         fw_work->name = kstrdup_const(name, gfp);
1294         if (!fw_work->name) {
1295                 kfree(fw_work);
1296                 return -ENOMEM;
1297         }
1298         fw_work->device = device;
1299         fw_work->context = context;
1300         fw_work->cont = cont;
1301         fw_work->opt_flags = FW_OPT_NOWAIT | FW_OPT_FALLBACK |
1302                 (uevent ? FW_OPT_UEVENT : FW_OPT_USERHELPER);
1303
1304         if (!try_module_get(module)) {
1305                 kfree_const(fw_work->name);
1306                 kfree(fw_work);
1307                 return -EFAULT;
1308         }
1309
1310         get_device(fw_work->device);
1311         INIT_WORK(&fw_work->work, request_firmware_work_func);
1312         schedule_work(&fw_work->work);
1313         return 0;
1314 }
1315 EXPORT_SYMBOL(request_firmware_nowait);
1316
1317 #ifdef CONFIG_PM_SLEEP
1318 static ASYNC_DOMAIN_EXCLUSIVE(fw_cache_domain);
1319
1320 /**
1321  * cache_firmware - cache one firmware image in kernel memory space
1322  * @fw_name: the firmware image name
1323  *
1324  * Cache firmware in kernel memory so that drivers can use it when
1325  * system isn't ready for them to request firmware image from userspace.
1326  * Once it returns successfully, driver can use request_firmware or its
1327  * nowait version to get the cached firmware without any interacting
1328  * with userspace
1329  *
1330  * Return 0 if the firmware image has been cached successfully
1331  * Return !0 otherwise
1332  *
1333  */
1334 static int cache_firmware(const char *fw_name)
1335 {
1336         int ret;
1337         const struct firmware *fw;
1338
1339         pr_debug("%s: %s\n", __func__, fw_name);
1340
1341         ret = request_firmware(&fw, fw_name, NULL);
1342         if (!ret)
1343                 kfree(fw);
1344
1345         pr_debug("%s: %s ret=%d\n", __func__, fw_name, ret);
1346
1347         return ret;
1348 }
1349
1350 static struct firmware_buf *fw_lookup_buf(const char *fw_name)
1351 {
1352         struct firmware_buf *tmp;
1353         struct firmware_cache *fwc = &fw_cache;
1354
1355         spin_lock(&fwc->lock);
1356         tmp = __fw_lookup_buf(fw_name);
1357         spin_unlock(&fwc->lock);
1358
1359         return tmp;
1360 }
1361
1362 /**
1363  * uncache_firmware - remove one cached firmware image
1364  * @fw_name: the firmware image name
1365  *
1366  * Uncache one firmware image which has been cached successfully
1367  * before.
1368  *
1369  * Return 0 if the firmware cache has been removed successfully
1370  * Return !0 otherwise
1371  *
1372  */
1373 static int uncache_firmware(const char *fw_name)
1374 {
1375         struct firmware_buf *buf;
1376         struct firmware fw;
1377
1378         pr_debug("%s: %s\n", __func__, fw_name);
1379
1380         if (fw_get_builtin_firmware(&fw, fw_name))
1381                 return 0;
1382
1383         buf = fw_lookup_buf(fw_name);
1384         if (buf) {
1385                 fw_free_buf(buf);
1386                 return 0;
1387         }
1388
1389         return -EINVAL;
1390 }
1391
1392 static struct fw_cache_entry *alloc_fw_cache_entry(const char *name)
1393 {
1394         struct fw_cache_entry *fce;
1395
1396         fce = kzalloc(sizeof(*fce), GFP_ATOMIC);
1397         if (!fce)
1398                 goto exit;
1399
1400         fce->name = kstrdup_const(name, GFP_ATOMIC);
1401         if (!fce->name) {
1402                 kfree(fce);
1403                 fce = NULL;
1404                 goto exit;
1405         }
1406 exit:
1407         return fce;
1408 }
1409
1410 static int __fw_entry_found(const char *name)
1411 {
1412         struct firmware_cache *fwc = &fw_cache;
1413         struct fw_cache_entry *fce;
1414
1415         list_for_each_entry(fce, &fwc->fw_names, list) {
1416                 if (!strcmp(fce->name, name))
1417                         return 1;
1418         }
1419         return 0;
1420 }
1421
1422 static int fw_cache_piggyback_on_request(const char *name)
1423 {
1424         struct firmware_cache *fwc = &fw_cache;
1425         struct fw_cache_entry *fce;
1426         int ret = 0;
1427
1428         spin_lock(&fwc->name_lock);
1429         if (__fw_entry_found(name))
1430                 goto found;
1431
1432         fce = alloc_fw_cache_entry(name);
1433         if (fce) {
1434                 ret = 1;
1435                 list_add(&fce->list, &fwc->fw_names);
1436                 pr_debug("%s: fw: %s\n", __func__, name);
1437         }
1438 found:
1439         spin_unlock(&fwc->name_lock);
1440         return ret;
1441 }
1442
1443 static void free_fw_cache_entry(struct fw_cache_entry *fce)
1444 {
1445         kfree_const(fce->name);
1446         kfree(fce);
1447 }
1448
1449 static void __async_dev_cache_fw_image(void *fw_entry,
1450                                        async_cookie_t cookie)
1451 {
1452         struct fw_cache_entry *fce = fw_entry;
1453         struct firmware_cache *fwc = &fw_cache;
1454         int ret;
1455
1456         ret = cache_firmware(fce->name);
1457         if (ret) {
1458                 spin_lock(&fwc->name_lock);
1459                 list_del(&fce->list);
1460                 spin_unlock(&fwc->name_lock);
1461
1462                 free_fw_cache_entry(fce);
1463         }
1464 }
1465
1466 /* called with dev->devres_lock held */
1467 static void dev_create_fw_entry(struct device *dev, void *res,
1468                                 void *data)
1469 {
1470         struct fw_name_devm *fwn = res;
1471         const char *fw_name = fwn->name;
1472         struct list_head *head = data;
1473         struct fw_cache_entry *fce;
1474
1475         fce = alloc_fw_cache_entry(fw_name);
1476         if (fce)
1477                 list_add(&fce->list, head);
1478 }
1479
1480 static int devm_name_match(struct device *dev, void *res,
1481                            void *match_data)
1482 {
1483         struct fw_name_devm *fwn = res;
1484         return (fwn->magic == (unsigned long)match_data);
1485 }
1486
1487 static void dev_cache_fw_image(struct device *dev, void *data)
1488 {
1489         LIST_HEAD(todo);
1490         struct fw_cache_entry *fce;
1491         struct fw_cache_entry *fce_next;
1492         struct firmware_cache *fwc = &fw_cache;
1493
1494         devres_for_each_res(dev, fw_name_devm_release,
1495                             devm_name_match, &fw_cache,
1496                             dev_create_fw_entry, &todo);
1497
1498         list_for_each_entry_safe(fce, fce_next, &todo, list) {
1499                 list_del(&fce->list);
1500
1501                 spin_lock(&fwc->name_lock);
1502                 /* only one cache entry for one firmware */
1503                 if (!__fw_entry_found(fce->name)) {
1504                         list_add(&fce->list, &fwc->fw_names);
1505                 } else {
1506                         free_fw_cache_entry(fce);
1507                         fce = NULL;
1508                 }
1509                 spin_unlock(&fwc->name_lock);
1510
1511                 if (fce)
1512                         async_schedule_domain(__async_dev_cache_fw_image,
1513                                               (void *)fce,
1514                                               &fw_cache_domain);
1515         }
1516 }
1517
1518 static void __device_uncache_fw_images(void)
1519 {
1520         struct firmware_cache *fwc = &fw_cache;
1521         struct fw_cache_entry *fce;
1522
1523         spin_lock(&fwc->name_lock);
1524         while (!list_empty(&fwc->fw_names)) {
1525                 fce = list_entry(fwc->fw_names.next,
1526                                 struct fw_cache_entry, list);
1527                 list_del(&fce->list);
1528                 spin_unlock(&fwc->name_lock);
1529
1530                 uncache_firmware(fce->name);
1531                 free_fw_cache_entry(fce);
1532
1533                 spin_lock(&fwc->name_lock);
1534         }
1535         spin_unlock(&fwc->name_lock);
1536 }
1537
1538 /**
1539  * device_cache_fw_images - cache devices' firmware
1540  *
1541  * If one device called request_firmware or its nowait version
1542  * successfully before, the firmware names are recored into the
1543  * device's devres link list, so device_cache_fw_images can call
1544  * cache_firmware() to cache these firmwares for the device,
1545  * then the device driver can load its firmwares easily at
1546  * time when system is not ready to complete loading firmware.
1547  */
1548 static void device_cache_fw_images(void)
1549 {
1550         struct firmware_cache *fwc = &fw_cache;
1551         int old_timeout;
1552         DEFINE_WAIT(wait);
1553
1554         pr_debug("%s\n", __func__);
1555
1556         /* cancel uncache work */
1557         cancel_delayed_work_sync(&fwc->work);
1558
1559         /*
1560          * use small loading timeout for caching devices' firmware
1561          * because all these firmware images have been loaded
1562          * successfully at lease once, also system is ready for
1563          * completing firmware loading now. The maximum size of
1564          * firmware in current distributions is about 2M bytes,
1565          * so 10 secs should be enough.
1566          */
1567         old_timeout = loading_timeout;
1568         loading_timeout = 10;
1569
1570         mutex_lock(&fw_lock);
1571         fwc->state = FW_LOADER_START_CACHE;
1572         dpm_for_each_dev(NULL, dev_cache_fw_image);
1573         mutex_unlock(&fw_lock);
1574
1575         /* wait for completion of caching firmware for all devices */
1576         async_synchronize_full_domain(&fw_cache_domain);
1577
1578         loading_timeout = old_timeout;
1579 }
1580
1581 /**
1582  * device_uncache_fw_images - uncache devices' firmware
1583  *
1584  * uncache all firmwares which have been cached successfully
1585  * by device_uncache_fw_images earlier
1586  */
1587 static void device_uncache_fw_images(void)
1588 {
1589         pr_debug("%s\n", __func__);
1590         __device_uncache_fw_images();
1591 }
1592
1593 static void device_uncache_fw_images_work(struct work_struct *work)
1594 {
1595         device_uncache_fw_images();
1596 }
1597
1598 /**
1599  * device_uncache_fw_images_delay - uncache devices firmwares
1600  * @delay: number of milliseconds to delay uncache device firmwares
1601  *
1602  * uncache all devices's firmwares which has been cached successfully
1603  * by device_cache_fw_images after @delay milliseconds.
1604  */
1605 static void device_uncache_fw_images_delay(unsigned long delay)
1606 {
1607         queue_delayed_work(system_power_efficient_wq, &fw_cache.work,
1608                            msecs_to_jiffies(delay));
1609 }
1610
1611 static int fw_pm_notify(struct notifier_block *notify_block,
1612                         unsigned long mode, void *unused)
1613 {
1614         switch (mode) {
1615         case PM_HIBERNATION_PREPARE:
1616         case PM_SUSPEND_PREPARE:
1617         case PM_RESTORE_PREPARE:
1618                 kill_requests_without_uevent();
1619                 device_cache_fw_images();
1620                 break;
1621
1622         case PM_POST_SUSPEND:
1623         case PM_POST_HIBERNATION:
1624         case PM_POST_RESTORE:
1625                 /*
1626                  * In case that system sleep failed and syscore_suspend is
1627                  * not called.
1628                  */
1629                 mutex_lock(&fw_lock);
1630                 fw_cache.state = FW_LOADER_NO_CACHE;
1631                 mutex_unlock(&fw_lock);
1632
1633                 device_uncache_fw_images_delay(10 * MSEC_PER_SEC);
1634                 break;
1635         }
1636
1637         return 0;
1638 }
1639
1640 /* stop caching firmware once syscore_suspend is reached */
1641 static int fw_suspend(void)
1642 {
1643         fw_cache.state = FW_LOADER_NO_CACHE;
1644         return 0;
1645 }
1646
1647 static struct syscore_ops fw_syscore_ops = {
1648         .suspend = fw_suspend,
1649 };
1650 #else
1651 static int fw_cache_piggyback_on_request(const char *name)
1652 {
1653         return 0;
1654 }
1655 #endif
1656
1657 static void __init fw_cache_init(void)
1658 {
1659         spin_lock_init(&fw_cache.lock);
1660         INIT_LIST_HEAD(&fw_cache.head);
1661         fw_cache.state = FW_LOADER_NO_CACHE;
1662
1663 #ifdef CONFIG_PM_SLEEP
1664         spin_lock_init(&fw_cache.name_lock);
1665         INIT_LIST_HEAD(&fw_cache.fw_names);
1666
1667         INIT_DELAYED_WORK(&fw_cache.work,
1668                           device_uncache_fw_images_work);
1669
1670         fw_cache.pm_notify.notifier_call = fw_pm_notify;
1671         register_pm_notifier(&fw_cache.pm_notify);
1672
1673         register_syscore_ops(&fw_syscore_ops);
1674 #endif
1675 }
1676
1677 static int __init firmware_class_init(void)
1678 {
1679         fw_cache_init();
1680 #ifdef CONFIG_FW_LOADER_USER_HELPER
1681         register_reboot_notifier(&fw_shutdown_nb);
1682         return class_register(&firmware_class);
1683 #else
1684         return 0;
1685 #endif
1686 }
1687
1688 static void __exit firmware_class_exit(void)
1689 {
1690 #ifdef CONFIG_PM_SLEEP
1691         unregister_syscore_ops(&fw_syscore_ops);
1692         unregister_pm_notifier(&fw_cache.pm_notify);
1693 #endif
1694 #ifdef CONFIG_FW_LOADER_USER_HELPER
1695         unregister_reboot_notifier(&fw_shutdown_nb);
1696         class_unregister(&firmware_class);
1697 #endif
1698 }
1699
1700 fs_initcall(firmware_class_init);
1701 module_exit(firmware_class_exit);