commit bd7a3fe770ebd8391d1c7d072ff88e9e76d063eb upstream.
Andrey Konovalov reported a possible out-of-bounds problem for a USB interface
association descriptor. He writes:
It seems there's no proper size check of a USB_DT_INTERFACE_ASSOCIATION
descriptor. It's only checked that the size is >= 2 in
usb_parse_configuration(), so find_iad() might do out-of-bounds access
to intf_assoc->bInterfaceCount.
And he's right, we don't check for crazy descriptors of this type very well, so
resolve this problem. Yet another issue found by syzkaller...
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Tested-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[bwh: Backported to 3.2: adjust filename]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
CVE-2017-16531
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: I3eb1836f8ee2cc53243b21233c3a191d6e616e52
usb: gadget: f_fs: HACK: Round reads up to 512 bytes to work with dwc3
Signed-off-by: Arve Hjønnevåg <arve@android.com>
USB: f_fs: Fix epfile crash during composition switch
epfile's ep pointer may be NULL during adb transfer
and composition switch happening in parallel. As part
of composition switch, first it is set to NONE. Setting
sys.usb.config to NONE stops adb and disables the composition.
stop adb is not blocking call and adb still might be doing
epfile read/write for some time when function unbind is
ongoing making the data structures NULL.
To fix this crash, call usb_ep_dequeue only if ep->ep is
valid. Similarly in success case, return ep->status only
if ep->ep is valid otherwise return -ENODEV.
CRs-Fixed: 643663
Change-Id: Ic152fc1db31cad6f97b8d16d91350dad857a4bf9
Signed-off-by: Sujeet Kumar <ksujeet@codeaurora.org>
USB: gadget: f_fs: Release endpoint upon disable
Endpoints are claimed using usb_ep_autoconfig function,
It will choose an unclaimed usb_ep and prevent the endpoint
from being returned by a later autoconfig calls. We can mark
the driver_data pointer once ep_enable is done in bind.
If we cannot mark to null upon function disable the corresponding
endpoint is not allocated by a later autoconfig call. The current
code does not make the ep->driver_data to null upon function disable.
This is leading to unclaimed endpoints for later autoconfig calls.
Claim the endpoints by assigning ep->driver_data to NULL.
CRs-Fixed: 633673
Change-Id: I221b98ef36cc2a60d27507a2442061a30ed410f4
Signed-off-by: ChandanaKishori Chiluveru <cchilu@codeaurora.org>
USB: gagget: f_fs: Return error if TX req is queued during device offline
when USB cable is disconnected during TX data transfers, endpoints will
be disabled during function disable. If userspace client tries to queue
requests on disabled endpoints, driver will wait till endpoints are
enabled and then queues previous session requests. This results in kernel
driver and userspace driver out of sync and due to this, stall will be
seen. Hence fix this issue by returning error value if client tries to
queue requests on TX endpoint during device offline.
CRs-Fixed: 633497
Change-Id: I3e43b8a704367aff7fe8dd88159315aef811c51c
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
USB: f_fs: Fail stale read IOs after disconnect
After a USB disconnect, endpoints for adb are disabled.
After this no IO is allowed on the endpoints.
Since, adbd is not aware of this disconnect, it may
still perform read/writes IO. For adb writes, IOs are
failed, but for adb reads kernel waits untill endpoints
are enabled.
When a USB disconnect and adb read still queued
a buffer to kernel, ffs_epfile_io simply waits for
endpoint to be enabled. A next connect happens
and endpoints are enabled after set_alt, the adb
read stale buffer from previous session continues
and queues to endpoint.
All this time, adb did not close the epfile because
it did not get return status on the IOs which it
queued. This is an issue, because a new session
is not established and both userspace and kernel
goes out of sync.
To fix this issue, when endpoints are disbled
set epfile error. This epfile error is only cleared
in epfile open. This will ensure that after a USB
disconnect and connect, new session is established.
Also, return ENODEV if endpoints not enabled rather
than EINTR as EINTR case, and simply retries the
request. Incase usb_ep_queue failed, return -EIO
inspite of depend on return status from usb_ep_queue.
CRs-Fixed: 633497
Change-Id: I6e677e98ec28e5462b372ed290acdde251286f48
Signed-off-by: Sujeet Kumar <ksujeet@codeaurora.org>
USB: f_fs: Cutoff epfile IO before epfile could get freed
epfile may get freed and accessing epfile's error flag to
cut off IOs may lead to use after free.
Move the epfile error flag setting above in the order
so that it guaranteed to be valid.
CRs-Fixed: 668046
Change-Id: I0017513393ddb4fd288cd4e1c2adf9d5ee3bc660
Signed-off-by: Sujeet Kumar <ksujeet@codeaurora.org>
USB: f_fs: Check error status before doing epfile I/O
Set error status before disabling endpoint during function
disable and also check error status before handling I/O. If error
status is set, return error status to read/write calls made by
userspace. Also set file's private data to NULL during epfile
release.
CRs-Fixed: 671880
Change-Id: I14b5ee541dfc18a7802ef4a8033878a7729d9adb
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
USB: f_fs: Fix disconnect check during ongoing IO
F_FS function driver allocated ffs_eps and updates ffs_ep->ep
to corresponding usb_ep during func->bind and never clears it.
On bind it also saves ffs_ep context in epfile->ep.
During func->disable, it clears only ffs_ep context in epfile->ep
and on func->unbind it frees ffs_eps memory.
ffs_epfile_io routine currently relies on ffs_ep->ep (which is
never cleared and ffs_ep could be freed on unbind) to detect any
disconnect during active IO. This can result in various issues e.g.
use after free use of ffs_ep if unbind finished before epfile_io
could resume or "stop adbd" trying to dequeue a freed USB request
when epfile_io could execute only after F_FS got disabled as
'if (ep->ep)' check would be TRUE.
Fix this by checking stored ffs_ep context against latest epfile->ep
to figure out if endpoint got disabled or changed before acquiring
spin_lock.
Change-Id: I6bdcdf0dff0813ed7b2af8c24f544a22796b0369
Signed-off-by: Manu Gautam <mgautam@codeaurora.org>
USB: f_fs: Move ep completion out of stack
Allocating completion on the stack may lead to
invalid access when udc irq tries to complete
the request but interrupted completion returns
immediately. This happens because request is not
held to be dequeued anymore making the completion
invalid.
Move the completions in ffs data like it is for ep0.
CRs-Fixed: 653761
Change-Id: I15102538d1b5bee14dfa3c7b3fa1f8e3f767cf71
Signed-off-by: Sujeet Kumar <ksujeet@codeaurora.org>
usb: dwc3: gadget: Release gadget lock when handling suspend/resume
gadget_driver suspend/resume operations might require some
dwc3-gadget operations, such as enabling and disabling
endpoints. If the lock is not released, this can cause a
deadlock scenario.
Change-Id: I1e12de65e40492b115ab35de78c2352730649db5
Signed-off-by: Bar Weiner <bweiner@codeaurora.org>
usb: dwc3: gadget: Iterate only over valid endpoints
Make dwc3_gadget_resize_tx_fifos() iterate only over IN
endpoints that are actually present, based on the
num_in_eps parameter. This terminates the loop so as to
prevent dereferencing a potential NULL dwc->eps[i] where
i >= (num_in_eps + num_out_eps).
Change-Id: I07f711bfd380dce212e86b59cf417f84ca7eb006
Signed-off-by: Jack Pham <jackp@codeaurora.org>
usb: dwc3: gadget: Protect against ep disabling during completion
In dwc3_cleanup_done_reqs(), a potential race condition
could arise when dwc3_gadget_giveback() temporarily
releases the main spinlock. If during this window the
very endpoint being handled becomes disabled, it would
lead to a NULL pointer dereference in the code that
follows. Guard against this by making sure the endpoint
is still enabled after returning from the giveback call.
CRs-fixed: 628972
Change-Id: Ifdb823fff12747f699217d871a5959c85b5340f7
Signed-off-by: Jack Pham <jackp@codeaurora.org>
usb: dwc3: calculate the number of endpoints
hwparams2 holds the number of endpoints which
were selected during RTL generation, we can
use that on our driver.
Signed-off-by: Felipe Balbi <balbi@ti.com>
usb: dwc3: gadget: use num_(in|out)_eps from HW params
that way we will only tell gadget framework about
the endpoints we actually have.
Change-Id: Iabc6a5712b640a9f5b0310984650a4ac44e5f579
Signed-off-by: Felipe Balbi <balbi@ti.com>
usb: gadget: always update HS/SS descriptors and create a copy of them
HS and SS descriptors are staticaly created. They are updated during the
bind process with the endpoint address, string id or interface numbers.
After that, the descriptor chain is linked to struct usb_function which
is used by composite in order to serve the GET_DESCRIPTOR requests,
number of available configs and so on.
There is no need to assign the HS descriptor only if the UDC supports
HS speed because composite won't report those to the host if HS support
has not been reached. The same reasoning is valid for SS.
This patch makes sure each function updates HS/SS descriptors
unconditionally and uses the newly introduced helper function to create a
copy the descriptors for the speed which is supported by the UDC.
While at that, also rename f->descriptors to f->fs_descriptors in order
to make it more explicit what that means.
Change-Id: Id670fcc25b0a1cb3020722cfc6eda2e1b08441f1
Cc: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Felipe Balbi <balbi@ti.com>
USB: Add super speed descriptors for android functions
Update android function drivers like diag, adb, modem, rmnet, mtp
and accessory to operate in super speed. The burst capability is
not enabled for now.
Change-Id: Ie95cbfc9444c56c8268b70e2916713190699c71a
Signed-off-by: Pavankumar Kondeti <pkondeti@codeaurora.org>
usb: gadget: Finish conversion to fs_descriptor change
Change-Id: Iaf72d66bb5cd6b84f14c5aaeb01ffb286568c97b
usb: gadget: f_fs: Add support for SuperSpeed Mode
Allow userspace to pass SuperSpeed descriptors and
handle them in the driver accordingly.
This change doesn't modify existing desc_header and thereby
keeps the ABI changes backward compatible i.e. existing
userspace drivers compiled with old header (functionfs.h)
would continue to work with the updated kernel.
Change-Id: Ic27035fdef2a83828024348d75be1518e9f8c5c6
Signed-off-by: Manu Gautam <mgautam@codeaurora.org>
USB: f_fs: Set ffs->func to NULL after disabling endpoint in set_alt()
When adb root is performed, userspace will close and open ffs_epsfile.
Closing this file will call ffs_functionfs_callback() which does call
remove_config(). This will call ffs_function_eps_disable to disable
endpoints and then calls ffs_func_unbind(). Unbind() will also call
endpoint disable which might lead to disabling endpoint which is already
disabled. Hence set ffs->func to NULL after disabling endpoints in
set_alt().
CRs-Fixed: 557532
Change-Id: I3052bdee74a1793d4e003de4b991d353e5d699b0
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
usb: gadget: throttle IRQ rate for SuperSpeed
There was a merge error from commit 6e0c86d12 "USB: gadget:
u_ether: Fix data stall issue in RNDIS tethering mode"
that resulted in the accidental removal of checking if
the gadget is connected at SuperSpeed. Re-introduce this
check so that IRQs on the downlink path are throttled,
decreasing the load on the CPU.
Change-Id: Ic2aa1d433e0fded95c6e825a760e89f726360522
Signed-off-by: Jack Pham <jackp@codeaurora.org>
USB: mbim: Add super speed descriptors for MBIM function
This change adds super speed descriptors which is required to
get MBIM function to work with SSUSB mode. The burst
capability is not enabled for now.
CRs-Fixed: 626744
Change-Id: I2a492182c94265ab58014cac470448f61782625c
Signed-off-by: Mayank Rana <mrana@codeaurora.org>
usb: gadget: ECM: Add super speed descriptors for qc_ecm function
This change adds super speed descriptors which is required to get
ECM function to work with SSUSB mode.
CRs-Fixed: 627063
Change-Id: I275a32f6cb957b59bfdf1c5b5377ba6e189efb6d
Signed-off-by: Mayank Rana <mrana@codeaurora.org>
usb: gadget: Add file for USB HID function
This file the same as f_hid.c.
Change-Id: I951b3067f477c3cb502c8320693ab11df90150d2
Signed-off-by: muluhe <muluhe@codeaurora.org>
Signed-off-by: Aravind Asam <aasam@codeaurora.org>
Signed-off-by: Ameya Thakur <ameyat@codeaurora.org>
usb: gadget: Enable HID function for charging mode
Provide HID function for only charging mode, in this mode device
enumerated as one input device.
Change-Id: I769adf76807b8a28adcc298de0536fa779176016
Signed-off-by: Mulu He <muluhe@codeaurora.org>
usb: gadget: composite: Fix USB version number for L1
When usb version number is greater than 2.01 USB-CV expects to find a
Super Speed USB Device Capability descriptor. When we want to enable BOS
descriptor capabilities for a high-speed device the USB version number
should be 2.01.
CRs-Fixed: 521752
Change-Id: Ic75b5e570b3c2df8e67370389dfddc8de6fb72d4
Signed-off-by: Shimrit Malichi <smalichi@codeaurora.org>
usb: gadget: Fix compilation of f_mbim driver after SS updates
Change-Id: I72e7dfa5c8f3905bbe57e227ebb7e7035d8b671c
[haggertk: port to samsung_msm8974, don't pick this for your own use]
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This is needed for MTP to know if writes are aligned to packet size.
Change-Id: If504511e649d46eb8d52f1fafeda071dddeec263
Signed-off-by: Jerry Zhang <zhangjerry@google.com>
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Driver supports using one of the two HSPHYs with the
controller based on the DT flag. There are two different
HS_PHY_CTRL registers for these PHYs. Based on the PHY
selected select the correct HS_PHY_CTRL register.
Change-Id: I4c85708a4d7daf645fa5cbff0e3906541fdb7b1f
Signed-off-by: Manu Gautam <mgautam@codeaurora.org>
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
DPSE/DMSE HV interrupt helps detect cable connection event during
TCXO shutdown and/or VDDMIN. Device working in host mode also can
enter LPM with PHY retention and these interrupts can wake up the
device when there is external device(eg. mouse) connecting.
As per HW specification, enable USB2_PHY_DMSE_INTEN/USB2_PHY_DPSE_INTEN
bits of USB_OTG_HS_PHY_CTRL register when USB module enters LPM with
retention mode, and disable these two bits when USB module exits LPM
with retention mode.
CRs-Fixed: 780259
Change-Id: I7b139547246cd64396c69f71da658f91d5f63812
Signed-off-by: Guoping Yu <guopingy@codeaurora.org>
Add counting of UI or USB transfers completion interrupts
so that it can be used to determine USB transfers or
BUS usage. This is a simple approach which gives
reasonable accuracy to avoid counting actual bytes
that got transferred over USB.
Change-Id: I1ee3c6997e40ee5db1da26af1e68fced06ea2de4
Signed-off-by: Manu Gautam <mgautam@codeaurora.org>
If Host Cable (ID_GND) is disconnected in system suspend then
it results in race between device removal and device pm_resume.
PM core does't handle this correctly and sometimes frees up
parent device before children are resumed. To avoid this race
make sure that system has resumed completely before handling
ID_FLOAT (or host cable disconnect) event.
CRs-fixed: 652870, 651561
Change-Id: Id0956a9677d819d3fa3f17f54965cae38f2ee31d
Signed-off-by: Manu Gautam <mgautam@codeaurora.org>
Signed-off-by: Saket Saurabh <ssaurabh@codeaurora.org>
Once DCP is detected, ext_chg_active is set to true and DCP uevent
reached to user space. The hvdcp main thread mark dcp_connected to
true and wakesup the detector thread to do hvdcp detection. But before
the detector thread gets a chance to run, DCP is removed. The disconnect
uevent reached the user space and the hvdcp main thread marks the
dcp_connected to false and it will not call any ioctl call. As
ext_chg_active is still set to true, it is waiting for 3 seconds while
processing usb disconnect.
Also it is possible that DCP uevent is reached to the user space much
before ext_chg_active flag is set to true in otg state machine work which
later leads to timeout of 3 seconds later while processing usb disconnect.
Fix these issues by maintaining different states for ext_chg_active. Upon
DCP disconnect, if the ext_chg_active value is still default, mark it to
inactive. This avoid the 3 seconds wait timeout while processing the usb
disconnect.
CRs-Fixed: 671181
Change-Id: Ic4aa6745e994a007bd6bd2e75d4f44fb8f7ac9c1
Signed-off-by: Saket Saurabh <ssaurabh@codeaurora.org>
Add support for MSM_USB_EXT_CHG_TYPE ioctl in driver for userspace to
notify kernel whether charger connected is external charger or not.
CRs-Fixed: 652965
Change-Id: I13095b4183efe3cfc690b7a9cb4f3c2d3cb4ee73
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
As part of USB disconnect event, msm_otg_suspend() executes and USB
enters into low power mode and pm_done flag is set to true. In the
scenario in which before the msm_otg_suspend() finished executing,
then USB connect event came in, in this case msm_otg_suspend() returns
-EBUSY. And later USB connect event is processed. As device is already
in resumed state, hence pm_done flag is never set to false. So on
next USB connect pm usage counter gets incremented in msm_otg_sm_work()
and device cannot enter into sleep state.
Fix the issue by clearing pm_done flag to false as part of usb connect
in msm_otg_sm_work().
CRs-fixed: 649434
Change-Id: Ibc36221b2f8b781322fa741b1b6639dd813c0810
Signed-off-by: Saket Saurabh <ssaurabh@codeaurora.org>
Currently HSPHY SUSP bit is set while starting host mode and
it is not cleared till stopping host mode. As part of urb dequeue,
xhci stack will queue stop endpoint command for flushing endpoint
which is getting timedout due to this HSPHY SUSP bit. Hence clear
this bit before queuing stop endpoint command and set it back after
stop endpoint command completion. Otherwise xhci stack treats this
timeout as fatal error and halts host controller.
Crs-Fixed: 580268
Change-Id: I784407386e6f87bcabd8569fcbae4e3af167144d
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
USB UICC cards can support multiple partitions which can be
exposed to the host via USB mass storage function. The number
of partitions of UICC card may vary for each target. Hence
create a device tree property to accept the required luns.
CRs-Fixed: 639635
Change-Id: I5bf5e9acd9fed72adffe469b602ab2d431ccfa3e
Signed-off-by: Pavankumar Kondeti <pkondeti@codeaurora.org>
On some platforms, host only port is used for connecting peripherals
like uicc card. Userspace will come to know uicc card insertion and
use sysfs interface to activate driver and binds driver. Hence fail
probe for uicc card till userspace activates this driver through
sysfs.
Userspace has to run following commands to activate driver:
1. echo Y > /sys/module/ehci_msm2/parameters/uicc_card_present
2. echo msm_ehci_host > /sys/bus/platform/mdrivers/msm_ehci_host/bind
Also external vbus is not required for uicc card and hence don't fail
probe if no external vbus.
CRs-Fixed: 616098
Change-Id: I821bb2cabf4b5ba46fef71ac48a7df0b7aa74bf6
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
Implement VOLTAGE_NOW property for power supply so that usb_in
value can be read at any time through this sysfs entry by
userspace.
To read usb_in value,
cat /sys/class/power_supply/usb/voltage_now
CRs-Fixed: 599547
Change-Id: I8f9bf4077282fbe32304b667793dab8009e68243
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
Add support for new ioctls for userspace to let kernel driver
know about new voltage request being negogiated and also result
whether the request is successful or not, when HVDCP charger is
connected.
Change-Id: I9f36949fc7888274171aa1724da45a11704b7fec
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
When device is in system suspend and USB charger is disconnected,
then due to VBUS clear IRQ from PMIC, the device will be PM resumed.
Now shortly if PMIC driver detects valid VBUS it will handle VBUS
set condition,notifies to msm_otg and msm_otg will kick in charger
detection mechanism. During PM resume, in dmp_complete() it will
call a pm_runtime_put_sync(), which will immediately kick off the
PM runtime idle and suspend routines.
dpm_complete()
->device_complete()
->pm_runtime_put_sync()
->rpm_idle()
->rpm_suspend()
The PM resume also runs in a separate worker queue, so it is not
guaranteed that it will finish executing before we finish the charger
detection stage. During this case there is a race if dpm_complete()
returns before charger detection starts. Return of dmp_cpmplete()
before charger detection will make USB to enter LPM. As USB will be
in LPM now and if charger detection starts then it will lead to
unclocked access.
Fixing the issue by handling the pm usage count using the variable
pm_done in msm_otg. When USB charger is disconnected and msm_otg
processes the disconnect event it marks the pm_done to true. Later
when USB charger is connected , mark the pm_done to false in
msm_otg_runtime_resume(). If pm_done is true increment the pm counter
using pm_runtime_get_sync. This handles the race case when PM resume
thread returns before the charger detection starts.
CRs-Fixed: 599143
Change-Id: I6de19fe850e24efa03ea71c7d14e388c15cf2f97
Signed-off-by: Saket Saurabh <ssaurabh@codeaurora.org>
HCD_OLD_ENUM HCD flag is introduced to use old (or short) enumeration
scheme for the devices attached on the corresponding USB bus. The old
enumeration scheme is used by the MSM HSIC controller to avoid multiple
reset during enumeration. This is useful when a known device is attached
to the USB bus, which is the case with MSM HSIC. When a HSIC HUB is
connected, any device can be connected on the HSIC USB bus. The new
enumeration scheme supports wide variety of USB devices. Hence limit
the old enumeration scheme request of a HCD to only root ports.
Change-Id: I6035c2a766787819eb8d0e1fa774e0c79d6e958b
Signed-off-by: Pavankumar Kondeti <pkondeti@codeaurora.org>
This module implements a bridge driver which allows user space
to communicate with USB smart card devices. This module provides
/dev/ccid_bridge device file which allows read/write/ioctl methods.
The ioctls facilitate control and interrupt transfers. The bulk
transfers are implemented via read and write. The interrupt
endpoint is optional and not all devices may support it.
Change-Id: I67ac7c7d15fb65c8f6a2cc9f9c81343da074aab7
Signed-off-by: Pavankumar Kondeti <pkondeti@codeaurora.org>
As a part of usb disconnect, usb will be put into low power mode
by putting phy into retention, voting for xo shutdown and vdd
minimization, also turning off LDOs. But on 8x10 platform,turning
off regulators is causing leakage current due to hardware limitation.
Hence add support for vdd minimization without putting phy into
retention to prevent power consumption. Also disable id pull up
as recommended by hardware team.
CRs-Fixed: 585073
Change-Id: Ie484f93e561664681501337be407e4f8038ac74a
Signed-off-by: Saket Saurabh <ssaurabh@codeaurora.org>
Supported different usb functions' has different throughput requirement.
USB controller supports streaming mode feature which enables double
buffering scheme on both IN and OUT endpoint, and reduces number of
NAKs for IN transfer. Hence noticeble throughput is increased with it.
Currently streaming mode is disable with USB controller. As supported
usb functions'like mtp, rndis are required to have higher throughput.
Add support which allows to enable streaming mode with usb controller
in device mode when particular function based composition is being enabled.
CRs-Fixed: 550553
Change-Id: Ibf6f3dc3f3b821647ba9beb15ed735a85c8ed586
Signed-off-by: Mayank Rana <mrana@codeaurora.org>
With AHB2AHB Bypass Mode, USB 2.0 Core is running using PNOC clock
and runs synchronous to PNOC which provides better throughput.
AHB2AHB Bypass mode can be enable with USB controller using
USB_AHBMODE register. It has below requirement :
- It should be enable before setting kicking USB controller
(i.e. setting R/S bit).
- PNOC should be running at MAX speed to get better throughput.
- While doing asynchronous clock reset with USB core, it is required
to disable this functionality as PNOC clock can't be disable and
re-enable as it is performed with other USB core clock.
CRs-Fixed: 550553
Change-Id: I9feac91b8885a393a13a039e9c89d63d0af2aed6
Signed-off-by: Mayank Rana <mrana@codeaurora.org>
Enable coarse-det-usb irq for charger OVP monitor. When insert a
high voltage charger, coarse-det-usb irq trigger, after wait for
usb valid debounce time, check the OVP condition, and report usb
health state; When an OVP happened in the process of charging, a
falling usbin valid_irq trigger, check OVP condition in usb plug
out condition, and report the usb health state.
Userspace can use the charger health state change to pop up
warning message when a charger, which exceeds the OVP threshold,
is connected.
Change-Id: Idedcdd7084aa24505675cf016d869444a89ca46c
Signed-off-by: Wu Fenglin <fenglinw@codeaurora.org>
Some USB controllers have different IRQ line to exit from
LPM. This is ASYNC IRQ. If this IRQ is present, we dont
need to enable or disable the USB interrupt during otg
suspend and resume respectively.
There is a new requirement for XO shutdown during idle.
To allow XO in idle CPU states. When CPU is idle, if an
irq is enabled and is not capable of waking up from xo,
the xo shutdown is aborted. Hence non-wakeup capable irq
must be disabled.
Change-Id: I3197a1b413a1bf849db3572442cc8dbc5f264b53
CRs-Fixed: 520531
Signed-off-by: Sujeet Kumar <ksujeet@codeaurora.org>
UMS(usb mass storage) need a new lun for internal
storage.So add a new lun number for internal mass storage.
Change-Id: I17ccb8f85d458567a1f1b35366b8b0834397601f
Signed-off-by: Jin Wu <jinw@codeaurora.org>
Currently dwc3 driver will allocate fifo size of maximum endpoint
packet size for TX endpoints depending on operating speed. Due
to this, double buffering may not work for TX endpoints in both high
speed and superspeed. Hence implement policy that allocates 3KB of
fifo for all bulk and isochronous endpoints irrespective of speed.
Policy is to allocate 3KB for bulk and isochronous endpoints and
allocate maximum packet size for control and interrupt endpoints.
This policy will improve the TX throughput numbers for function
drivers like MTP, mass storage. But side effect is we can't accomodate
more than nine bulk + isochronous endpoints in non QDSS composition
and five bulk + isochronous endpoints in QDSS composition. Otherwise
last interfaces in the USB composition will not work.
CRs-Fixed: 532070
Change-Id: I5e947f21f25fada7829c84eba45980295497cfbc
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
On few legacy platforms, USB PHY is having dedicated reset clk.
It is used to reset USB PHY after putting USB PHY into low power
mode and for calibration of USB PHY. Putting USB PHY into low
power mode is causing ulpi read/write timeout as expected USB PHY
reset clk is not available on newer platform. Hence remove USB PHY
reset clk usage and related reset code.
For 28nm PHY, Reset USB PHY after resestting USB LINK. Also reset
USB PHY using USB_PHY_PON bit with USB_OTG_HS_PHY_CTRL register
after programming USB PHY Override registers as suggested with
hardware programming guidelines. Also debug out important USB
register when ulpi read/write timeout is seen with USB PHY.
CRs-Fixed: 511102
CRs-Fixed: 511397
Change-Id: I8f0f49211a64aa6eac7643cd91a652aed40132e3
Signed-off-by: Mayank Rana <mrana@codeaurora.org>
USB PHY is provided sleep clock on few platform which is
required to enable for USB PHY functionality. Hence add
support to vote sleep clock if it exists.
CRs-Fixed: 518353
Change-Id: I67006bfe3fbe9b3ad3e1d1e2ddb0e8e060437bd7
Signed-off-by: Mayank Rana <mrana@codeaurora.org>
There can be SOFs underway after suspending the port
(setting susp bit) which leads to phy lockup or unexpected
device disconnections on some platforms. Fix for this is to halt
the controller before setting port suspend bit to avoid such issues.
There are similar SOF related PHY issues for RESET and RESUME.
There already exists a platform_data or DT parameter:
'phy_sof_workaround' which enables all these SOF related workarounds.
But, some hardwares have RESET and RESUME SOF issues fixed but only
SUSPEND SOF issues is present. For these add pdata and DT parameter
to enable only SUSPEND SOF workaround.
CRs-fixed: 510136
Change-Id: I57d7fb11616e96b606f9f0c80bf3222fca27bb5d
Signed-off-by: Manu Gautam <mgautam@codeaurora.org>
Since it might take 150ms for QCA6234 to initialize from boot code
when receiving HSIC bus reset.
Add delay between the HSIC bus reset and enumeration.
Change-Id: I78520e290e7b7c5e8c686a303cb1cd63bde520ae
Signed-off-by: Ming-yi Lin <mylin@codeaurora.org>
Allow voltage_max property to be written from user space. The USB
power supply input voltage can be limited by writing into
/sys/class/power_supply/usb/voltage_max sysfs file. The user space
charger detection application uses this property value to place
an appropriate voltage request to the charger.
Change-Id: Id997a97dee073d0d8f877b58470ca2f70e89065e
Signed-off-by: Pavankumar Kondeti <pkondeti@codeaurora.org>
Currently msm_otg driver allows VDD minimization during host bus
suspend and depends on MPM for USB remote wakeup on platforms,
where D+ and D- lines are routed to MPM. As part of VDD minimization,
PHY will be put into retention state in which pull down resistors
are disabled. This scenario could cause issues without HW rework of
connecting pull down resistors on data lines. Hence don't allow
XO shutdown during host bus suspend if session is active.
Change-Id: Ic7274072cc4f266574cf45030bcadc469091c333
Signed-off-by: Vijayavardhan Vennapusa <vvreddy@codeaurora.org>
The userspace charger detection takes place when a standard dedicated
charger is connected. We handover the detection part to userspace
after detecting the dedicated charger. Create a character device
called /dev/usb_ext_chg to expose hardware register access and a
mechanism to vote against low power mode. Add POWER_SUPPLY_PROP_TYPE
property to power_supply_property array to send charger type information
in power supply uevent.
CRs-Fixed: 500279
Change-Id: I538601a423e5bc87e98d29690c0da50b96f8e481
Signed-off-by: Pavankumar Kondeti <pkondeti@codeaurora.org>
Remove usage of the global context variable in the gadget and DBM
functions by passing a dwc3_msm pointer directly. This will allow
the driver to eventually support multiple instances.
Change-Id: I0fdc5d703b3fd445e83226534f07743461c96f4c
Signed-off-by: Jack Pham <jackp@codeaurora.org>
Remove usage of the global context variable in the MHL functions by
adding an additional parameter to the callback function signature.
This will allow the driver to eventually support multiple instances.
Change-Id: I9e01838f6c0d51b5cd210e46d151b2ed9179d087
Signed-off-by: Jack Pham <jackp@codeaurora.org>
For bam2bam scenarios, the usb bam driver starts low power mode (lpm)
after bus suspend or cable disconnect and after the handshake with
the ipa peer bam is completed.
So far, only msm otg state machine was responsible for setting the core
into lpm. The problem is that in some race conditions, for example when
disconnection of the pipes in usb bam happened sooner than the
disconnection in the msm otg state machine, the lpm was started too soon
by the usb bam, therefore caused a crash for accessing lpm HW by the
msm otg.
This change make sure that the usb bam will not start lpm unless the
msm otg state machine has been tried to do so. In that case the usb bam
will save this state as 'pending' lpm, and will start the lpm later in
case the handshake with the ipa has not finished yet.
CRs-Fixed: 509452
Change-Id: I2f2697589e2e45d91b57d31bec6aebd6d2b8110f
Signed-off-by: Ido Shayevitz <idos@codeaurora.org>
/dev/usb_ext_chg device file interface supports mmap and its current
implementation allows any address for mapping. Fix it by mapping only
charger block register address space. The user space does not need to
pass any physical address in mmap. Implement an ioctl to tell the
offset from which the first charger block register is available. User
space adds this offset to the virtual address returned by mmap to access
charger detection registers.
The MSM_USB_EXT_CHG_INFO ioctl also returns the charger block type
(QSCRATCH/ULPI) to user space. Use the ioctl interface for blocking
low power mode while charger detection takes place in user space.
Change-Id: Ie27988e1989564124b40cf7c40c8eb67dac99c65
Signed-off-by: Pavankumar Kondeti <pkondeti@codeaurora.org>