firewire: cdev: add PHY packet reception
[pandora-kernel.git] / drivers / firewire / core-cdev.c
1 /*
2  * Char device for device raw access
3  *
4  * Copyright (C) 2005-2007  Kristian Hoegsberg <krh@bitplanet.net>
5  *
6  * This program is free software; you can redistribute it and/or modify
7  * it under the terms of the GNU General Public License as published by
8  * the Free Software Foundation; either version 2 of the License, or
9  * (at your option) any later version.
10  *
11  * This program is distributed in the hope that it will be useful,
12  * but WITHOUT ANY WARRANTY; without even the implied warranty of
13  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  * GNU General Public License for more details.
15  *
16  * You should have received a copy of the GNU General Public License
17  * along with this program; if not, write to the Free Software Foundation,
18  * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
19  */
20
21 #include <linux/bug.h>
22 #include <linux/compat.h>
23 #include <linux/delay.h>
24 #include <linux/device.h>
25 #include <linux/errno.h>
26 #include <linux/firewire.h>
27 #include <linux/firewire-cdev.h>
28 #include <linux/idr.h>
29 #include <linux/irqflags.h>
30 #include <linux/jiffies.h>
31 #include <linux/kernel.h>
32 #include <linux/kref.h>
33 #include <linux/mm.h>
34 #include <linux/module.h>
35 #include <linux/mutex.h>
36 #include <linux/poll.h>
37 #include <linux/sched.h>
38 #include <linux/spinlock.h>
39 #include <linux/string.h>
40 #include <linux/time.h>
41 #include <linux/uaccess.h>
42 #include <linux/vmalloc.h>
43 #include <linux/wait.h>
44 #include <linux/workqueue.h>
45
46 #include <asm/system.h>
47
48 #include "core.h"
49
50 /*
51  * ABI version history is documented in linux/firewire-cdev.h.
52  */
53 #define FW_CDEV_KERNEL_VERSION          4
54 #define FW_CDEV_VERSION_EVENT_REQUEST2  4
55
56 struct client {
57         u32 version;
58         struct fw_device *device;
59
60         spinlock_t lock;
61         bool in_shutdown;
62         struct idr resource_idr;
63         struct list_head event_list;
64         wait_queue_head_t wait;
65         u64 bus_reset_closure;
66
67         struct fw_iso_context *iso_context;
68         u64 iso_closure;
69         struct fw_iso_buffer buffer;
70         unsigned long vm_start;
71
72         struct list_head phy_receiver_link;
73         u64 phy_receiver_closure;
74
75         struct list_head link;
76         struct kref kref;
77 };
78
79 static inline void client_get(struct client *client)
80 {
81         kref_get(&client->kref);
82 }
83
84 static void client_release(struct kref *kref)
85 {
86         struct client *client = container_of(kref, struct client, kref);
87
88         fw_device_put(client->device);
89         kfree(client);
90 }
91
92 static void client_put(struct client *client)
93 {
94         kref_put(&client->kref, client_release);
95 }
96
97 struct client_resource;
98 typedef void (*client_resource_release_fn_t)(struct client *,
99                                              struct client_resource *);
100 struct client_resource {
101         client_resource_release_fn_t release;
102         int handle;
103 };
104
105 struct address_handler_resource {
106         struct client_resource resource;
107         struct fw_address_handler handler;
108         __u64 closure;
109         struct client *client;
110 };
111
112 struct outbound_transaction_resource {
113         struct client_resource resource;
114         struct fw_transaction transaction;
115 };
116
117 struct inbound_transaction_resource {
118         struct client_resource resource;
119         struct fw_card *card;
120         struct fw_request *request;
121         void *data;
122         size_t length;
123 };
124
125 struct descriptor_resource {
126         struct client_resource resource;
127         struct fw_descriptor descriptor;
128         u32 data[0];
129 };
130
131 struct iso_resource {
132         struct client_resource resource;
133         struct client *client;
134         /* Schedule work and access todo only with client->lock held. */
135         struct delayed_work work;
136         enum {ISO_RES_ALLOC, ISO_RES_REALLOC, ISO_RES_DEALLOC,
137               ISO_RES_ALLOC_ONCE, ISO_RES_DEALLOC_ONCE,} todo;
138         int generation;
139         u64 channels;
140         s32 bandwidth;
141         __be32 transaction_data[2];
142         struct iso_resource_event *e_alloc, *e_dealloc;
143 };
144
145 static void release_iso_resource(struct client *, struct client_resource *);
146
147 static void schedule_iso_resource(struct iso_resource *r, unsigned long delay)
148 {
149         client_get(r->client);
150         if (!schedule_delayed_work(&r->work, delay))
151                 client_put(r->client);
152 }
153
154 static void schedule_if_iso_resource(struct client_resource *resource)
155 {
156         if (resource->release == release_iso_resource)
157                 schedule_iso_resource(container_of(resource,
158                                         struct iso_resource, resource), 0);
159 }
160
161 /*
162  * dequeue_event() just kfree()'s the event, so the event has to be
163  * the first field in a struct XYZ_event.
164  */
165 struct event {
166         struct { void *data; size_t size; } v[2];
167         struct list_head link;
168 };
169
170 struct bus_reset_event {
171         struct event event;
172         struct fw_cdev_event_bus_reset reset;
173 };
174
175 struct outbound_transaction_event {
176         struct event event;
177         struct client *client;
178         struct outbound_transaction_resource r;
179         struct fw_cdev_event_response response;
180 };
181
182 struct inbound_transaction_event {
183         struct event event;
184         union {
185                 struct fw_cdev_event_request request;
186                 struct fw_cdev_event_request2 request2;
187         } req;
188 };
189
190 struct iso_interrupt_event {
191         struct event event;
192         struct fw_cdev_event_iso_interrupt interrupt;
193 };
194
195 struct iso_resource_event {
196         struct event event;
197         struct fw_cdev_event_iso_resource iso_resource;
198 };
199
200 struct outbound_phy_packet_event {
201         struct event event;
202         struct client *client;
203         struct fw_packet p;
204         struct fw_cdev_event_phy_packet phy_packet;
205 };
206
207 struct inbound_phy_packet_event {
208         struct event event;
209         struct fw_cdev_event_phy_packet phy_packet;
210 };
211
212 static inline void __user *u64_to_uptr(__u64 value)
213 {
214         return (void __user *)(unsigned long)value;
215 }
216
217 static inline __u64 uptr_to_u64(void __user *ptr)
218 {
219         return (__u64)(unsigned long)ptr;
220 }
221
222 static int fw_device_op_open(struct inode *inode, struct file *file)
223 {
224         struct fw_device *device;
225         struct client *client;
226
227         device = fw_device_get_by_devt(inode->i_rdev);
228         if (device == NULL)
229                 return -ENODEV;
230
231         if (fw_device_is_shutdown(device)) {
232                 fw_device_put(device);
233                 return -ENODEV;
234         }
235
236         client = kzalloc(sizeof(*client), GFP_KERNEL);
237         if (client == NULL) {
238                 fw_device_put(device);
239                 return -ENOMEM;
240         }
241
242         client->device = device;
243         spin_lock_init(&client->lock);
244         idr_init(&client->resource_idr);
245         INIT_LIST_HEAD(&client->event_list);
246         init_waitqueue_head(&client->wait);
247         INIT_LIST_HEAD(&client->phy_receiver_link);
248         kref_init(&client->kref);
249
250         file->private_data = client;
251
252         mutex_lock(&device->client_list_mutex);
253         list_add_tail(&client->link, &device->client_list);
254         mutex_unlock(&device->client_list_mutex);
255
256         return nonseekable_open(inode, file);
257 }
258
259 static void queue_event(struct client *client, struct event *event,
260                         void *data0, size_t size0, void *data1, size_t size1)
261 {
262         unsigned long flags;
263
264         event->v[0].data = data0;
265         event->v[0].size = size0;
266         event->v[1].data = data1;
267         event->v[1].size = size1;
268
269         spin_lock_irqsave(&client->lock, flags);
270         if (client->in_shutdown)
271                 kfree(event);
272         else
273                 list_add_tail(&event->link, &client->event_list);
274         spin_unlock_irqrestore(&client->lock, flags);
275
276         wake_up_interruptible(&client->wait);
277 }
278
279 static int dequeue_event(struct client *client,
280                          char __user *buffer, size_t count)
281 {
282         struct event *event;
283         size_t size, total;
284         int i, ret;
285
286         ret = wait_event_interruptible(client->wait,
287                         !list_empty(&client->event_list) ||
288                         fw_device_is_shutdown(client->device));
289         if (ret < 0)
290                 return ret;
291
292         if (list_empty(&client->event_list) &&
293                        fw_device_is_shutdown(client->device))
294                 return -ENODEV;
295
296         spin_lock_irq(&client->lock);
297         event = list_first_entry(&client->event_list, struct event, link);
298         list_del(&event->link);
299         spin_unlock_irq(&client->lock);
300
301         total = 0;
302         for (i = 0; i < ARRAY_SIZE(event->v) && total < count; i++) {
303                 size = min(event->v[i].size, count - total);
304                 if (copy_to_user(buffer + total, event->v[i].data, size)) {
305                         ret = -EFAULT;
306                         goto out;
307                 }
308                 total += size;
309         }
310         ret = total;
311
312  out:
313         kfree(event);
314
315         return ret;
316 }
317
318 static ssize_t fw_device_op_read(struct file *file, char __user *buffer,
319                                  size_t count, loff_t *offset)
320 {
321         struct client *client = file->private_data;
322
323         return dequeue_event(client, buffer, count);
324 }
325
326 static void fill_bus_reset_event(struct fw_cdev_event_bus_reset *event,
327                                  struct client *client)
328 {
329         struct fw_card *card = client->device->card;
330
331         spin_lock_irq(&card->lock);
332
333         event->closure       = client->bus_reset_closure;
334         event->type          = FW_CDEV_EVENT_BUS_RESET;
335         event->generation    = client->device->generation;
336         event->node_id       = client->device->node_id;
337         event->local_node_id = card->local_node->node_id;
338         event->bm_node_id    = card->bm_node_id;
339         event->irm_node_id   = card->irm_node->node_id;
340         event->root_node_id  = card->root_node->node_id;
341
342         spin_unlock_irq(&card->lock);
343 }
344
345 static void for_each_client(struct fw_device *device,
346                             void (*callback)(struct client *client))
347 {
348         struct client *c;
349
350         mutex_lock(&device->client_list_mutex);
351         list_for_each_entry(c, &device->client_list, link)
352                 callback(c);
353         mutex_unlock(&device->client_list_mutex);
354 }
355
356 static int schedule_reallocations(int id, void *p, void *data)
357 {
358         schedule_if_iso_resource(p);
359
360         return 0;
361 }
362
363 static void queue_bus_reset_event(struct client *client)
364 {
365         struct bus_reset_event *e;
366
367         e = kzalloc(sizeof(*e), GFP_KERNEL);
368         if (e == NULL) {
369                 fw_notify("Out of memory when allocating event\n");
370                 return;
371         }
372
373         fill_bus_reset_event(&e->reset, client);
374
375         queue_event(client, &e->event,
376                     &e->reset, sizeof(e->reset), NULL, 0);
377
378         spin_lock_irq(&client->lock);
379         idr_for_each(&client->resource_idr, schedule_reallocations, client);
380         spin_unlock_irq(&client->lock);
381 }
382
383 void fw_device_cdev_update(struct fw_device *device)
384 {
385         for_each_client(device, queue_bus_reset_event);
386 }
387
388 static void wake_up_client(struct client *client)
389 {
390         wake_up_interruptible(&client->wait);
391 }
392
393 void fw_device_cdev_remove(struct fw_device *device)
394 {
395         for_each_client(device, wake_up_client);
396 }
397
398 union ioctl_arg {
399         struct fw_cdev_get_info                 get_info;
400         struct fw_cdev_send_request             send_request;
401         struct fw_cdev_allocate                 allocate;
402         struct fw_cdev_deallocate               deallocate;
403         struct fw_cdev_send_response            send_response;
404         struct fw_cdev_initiate_bus_reset       initiate_bus_reset;
405         struct fw_cdev_add_descriptor           add_descriptor;
406         struct fw_cdev_remove_descriptor        remove_descriptor;
407         struct fw_cdev_create_iso_context       create_iso_context;
408         struct fw_cdev_queue_iso                queue_iso;
409         struct fw_cdev_start_iso                start_iso;
410         struct fw_cdev_stop_iso                 stop_iso;
411         struct fw_cdev_get_cycle_timer          get_cycle_timer;
412         struct fw_cdev_allocate_iso_resource    allocate_iso_resource;
413         struct fw_cdev_send_stream_packet       send_stream_packet;
414         struct fw_cdev_get_cycle_timer2         get_cycle_timer2;
415         struct fw_cdev_send_phy_packet          send_phy_packet;
416         struct fw_cdev_receive_phy_packets      receive_phy_packets;
417 };
418
419 static int ioctl_get_info(struct client *client, union ioctl_arg *arg)
420 {
421         struct fw_cdev_get_info *a = &arg->get_info;
422         struct fw_cdev_event_bus_reset bus_reset;
423         unsigned long ret = 0;
424
425         client->version = a->version;
426         a->version = FW_CDEV_KERNEL_VERSION;
427         a->card = client->device->card->index;
428
429         down_read(&fw_device_rwsem);
430
431         if (a->rom != 0) {
432                 size_t want = a->rom_length;
433                 size_t have = client->device->config_rom_length * 4;
434
435                 ret = copy_to_user(u64_to_uptr(a->rom),
436                                    client->device->config_rom, min(want, have));
437         }
438         a->rom_length = client->device->config_rom_length * 4;
439
440         up_read(&fw_device_rwsem);
441
442         if (ret != 0)
443                 return -EFAULT;
444
445         client->bus_reset_closure = a->bus_reset_closure;
446         if (a->bus_reset != 0) {
447                 fill_bus_reset_event(&bus_reset, client);
448                 if (copy_to_user(u64_to_uptr(a->bus_reset),
449                                  &bus_reset, sizeof(bus_reset)))
450                         return -EFAULT;
451         }
452
453         return 0;
454 }
455
456 static int add_client_resource(struct client *client,
457                                struct client_resource *resource, gfp_t gfp_mask)
458 {
459         unsigned long flags;
460         int ret;
461
462  retry:
463         if (idr_pre_get(&client->resource_idr, gfp_mask) == 0)
464                 return -ENOMEM;
465
466         spin_lock_irqsave(&client->lock, flags);
467         if (client->in_shutdown)
468                 ret = -ECANCELED;
469         else
470                 ret = idr_get_new(&client->resource_idr, resource,
471                                   &resource->handle);
472         if (ret >= 0) {
473                 client_get(client);
474                 schedule_if_iso_resource(resource);
475         }
476         spin_unlock_irqrestore(&client->lock, flags);
477
478         if (ret == -EAGAIN)
479                 goto retry;
480
481         return ret < 0 ? ret : 0;
482 }
483
484 static int release_client_resource(struct client *client, u32 handle,
485                                    client_resource_release_fn_t release,
486                                    struct client_resource **return_resource)
487 {
488         struct client_resource *resource;
489
490         spin_lock_irq(&client->lock);
491         if (client->in_shutdown)
492                 resource = NULL;
493         else
494                 resource = idr_find(&client->resource_idr, handle);
495         if (resource && resource->release == release)
496                 idr_remove(&client->resource_idr, handle);
497         spin_unlock_irq(&client->lock);
498
499         if (!(resource && resource->release == release))
500                 return -EINVAL;
501
502         if (return_resource)
503                 *return_resource = resource;
504         else
505                 resource->release(client, resource);
506
507         client_put(client);
508
509         return 0;
510 }
511
512 static void release_transaction(struct client *client,
513                                 struct client_resource *resource)
514 {
515         struct outbound_transaction_resource *r = container_of(resource,
516                         struct outbound_transaction_resource, resource);
517
518         fw_cancel_transaction(client->device->card, &r->transaction);
519 }
520
521 static void complete_transaction(struct fw_card *card, int rcode,
522                                  void *payload, size_t length, void *data)
523 {
524         struct outbound_transaction_event *e = data;
525         struct fw_cdev_event_response *rsp = &e->response;
526         struct client *client = e->client;
527         unsigned long flags;
528
529         if (length < rsp->length)
530                 rsp->length = length;
531         if (rcode == RCODE_COMPLETE)
532                 memcpy(rsp->data, payload, rsp->length);
533
534         spin_lock_irqsave(&client->lock, flags);
535         /*
536          * 1. If called while in shutdown, the idr tree must be left untouched.
537          *    The idr handle will be removed and the client reference will be
538          *    dropped later.
539          * 2. If the call chain was release_client_resource ->
540          *    release_transaction -> complete_transaction (instead of a normal
541          *    conclusion of the transaction), i.e. if this resource was already
542          *    unregistered from the idr, the client reference will be dropped
543          *    by release_client_resource and we must not drop it here.
544          */
545         if (!client->in_shutdown &&
546             idr_find(&client->resource_idr, e->r.resource.handle)) {
547                 idr_remove(&client->resource_idr, e->r.resource.handle);
548                 /* Drop the idr's reference */
549                 client_put(client);
550         }
551         spin_unlock_irqrestore(&client->lock, flags);
552
553         rsp->type = FW_CDEV_EVENT_RESPONSE;
554         rsp->rcode = rcode;
555
556         /*
557          * In the case that sizeof(*rsp) doesn't align with the position of the
558          * data, and the read is short, preserve an extra copy of the data
559          * to stay compatible with a pre-2.6.27 bug.  Since the bug is harmless
560          * for short reads and some apps depended on it, this is both safe
561          * and prudent for compatibility.
562          */
563         if (rsp->length <= sizeof(*rsp) - offsetof(typeof(*rsp), data))
564                 queue_event(client, &e->event, rsp, sizeof(*rsp),
565                             rsp->data, rsp->length);
566         else
567                 queue_event(client, &e->event, rsp, sizeof(*rsp) + rsp->length,
568                             NULL, 0);
569
570         /* Drop the transaction callback's reference */
571         client_put(client);
572 }
573
574 static int init_request(struct client *client,
575                         struct fw_cdev_send_request *request,
576                         int destination_id, int speed)
577 {
578         struct outbound_transaction_event *e;
579         int ret;
580
581         if (request->tcode != TCODE_STREAM_DATA &&
582             (request->length > 4096 || request->length > 512 << speed))
583                 return -EIO;
584
585         if (request->tcode == TCODE_WRITE_QUADLET_REQUEST &&
586             request->length < 4)
587                 return -EINVAL;
588
589         e = kmalloc(sizeof(*e) + request->length, GFP_KERNEL);
590         if (e == NULL)
591                 return -ENOMEM;
592
593         e->client = client;
594         e->response.length = request->length;
595         e->response.closure = request->closure;
596
597         if (request->data &&
598             copy_from_user(e->response.data,
599                            u64_to_uptr(request->data), request->length)) {
600                 ret = -EFAULT;
601                 goto failed;
602         }
603
604         e->r.resource.release = release_transaction;
605         ret = add_client_resource(client, &e->r.resource, GFP_KERNEL);
606         if (ret < 0)
607                 goto failed;
608
609         /* Get a reference for the transaction callback */
610         client_get(client);
611
612         fw_send_request(client->device->card, &e->r.transaction,
613                         request->tcode, destination_id, request->generation,
614                         speed, request->offset, e->response.data,
615                         request->length, complete_transaction, e);
616         return 0;
617
618  failed:
619         kfree(e);
620
621         return ret;
622 }
623
624 static int ioctl_send_request(struct client *client, union ioctl_arg *arg)
625 {
626         switch (arg->send_request.tcode) {
627         case TCODE_WRITE_QUADLET_REQUEST:
628         case TCODE_WRITE_BLOCK_REQUEST:
629         case TCODE_READ_QUADLET_REQUEST:
630         case TCODE_READ_BLOCK_REQUEST:
631         case TCODE_LOCK_MASK_SWAP:
632         case TCODE_LOCK_COMPARE_SWAP:
633         case TCODE_LOCK_FETCH_ADD:
634         case TCODE_LOCK_LITTLE_ADD:
635         case TCODE_LOCK_BOUNDED_ADD:
636         case TCODE_LOCK_WRAP_ADD:
637         case TCODE_LOCK_VENDOR_DEPENDENT:
638                 break;
639         default:
640                 return -EINVAL;
641         }
642
643         return init_request(client, &arg->send_request, client->device->node_id,
644                             client->device->max_speed);
645 }
646
647 static inline bool is_fcp_request(struct fw_request *request)
648 {
649         return request == NULL;
650 }
651
652 static void release_request(struct client *client,
653                             struct client_resource *resource)
654 {
655         struct inbound_transaction_resource *r = container_of(resource,
656                         struct inbound_transaction_resource, resource);
657
658         if (is_fcp_request(r->request))
659                 kfree(r->data);
660         else
661                 fw_send_response(r->card, r->request, RCODE_CONFLICT_ERROR);
662
663         fw_card_put(r->card);
664         kfree(r);
665 }
666
667 static void handle_request(struct fw_card *card, struct fw_request *request,
668                            int tcode, int destination, int source,
669                            int generation, unsigned long long offset,
670                            void *payload, size_t length, void *callback_data)
671 {
672         struct address_handler_resource *handler = callback_data;
673         struct inbound_transaction_resource *r;
674         struct inbound_transaction_event *e;
675         size_t event_size0;
676         void *fcp_frame = NULL;
677         int ret;
678
679         /* card may be different from handler->client->device->card */
680         fw_card_get(card);
681
682         r = kmalloc(sizeof(*r), GFP_ATOMIC);
683         e = kmalloc(sizeof(*e), GFP_ATOMIC);
684         if (r == NULL || e == NULL) {
685                 fw_notify("Out of memory when allocating event\n");
686                 goto failed;
687         }
688         r->card    = card;
689         r->request = request;
690         r->data    = payload;
691         r->length  = length;
692
693         if (is_fcp_request(request)) {
694                 /*
695                  * FIXME: Let core-transaction.c manage a
696                  * single reference-counted copy?
697                  */
698                 fcp_frame = kmemdup(payload, length, GFP_ATOMIC);
699                 if (fcp_frame == NULL)
700                         goto failed;
701
702                 r->data = fcp_frame;
703         }
704
705         r->resource.release = release_request;
706         ret = add_client_resource(handler->client, &r->resource, GFP_ATOMIC);
707         if (ret < 0)
708                 goto failed;
709
710         if (handler->client->version < FW_CDEV_VERSION_EVENT_REQUEST2) {
711                 struct fw_cdev_event_request *req = &e->req.request;
712
713                 if (tcode & 0x10)
714                         tcode = TCODE_LOCK_REQUEST;
715
716                 req->type       = FW_CDEV_EVENT_REQUEST;
717                 req->tcode      = tcode;
718                 req->offset     = offset;
719                 req->length     = length;
720                 req->handle     = r->resource.handle;
721                 req->closure    = handler->closure;
722                 event_size0     = sizeof(*req);
723         } else {
724                 struct fw_cdev_event_request2 *req = &e->req.request2;
725
726                 req->type       = FW_CDEV_EVENT_REQUEST2;
727                 req->tcode      = tcode;
728                 req->offset     = offset;
729                 req->source_node_id = source;
730                 req->destination_node_id = destination;
731                 req->card       = card->index;
732                 req->generation = generation;
733                 req->length     = length;
734                 req->handle     = r->resource.handle;
735                 req->closure    = handler->closure;
736                 event_size0     = sizeof(*req);
737         }
738
739         queue_event(handler->client, &e->event,
740                     &e->req, event_size0, r->data, length);
741         return;
742
743  failed:
744         kfree(r);
745         kfree(e);
746         kfree(fcp_frame);
747
748         if (!is_fcp_request(request))
749                 fw_send_response(card, request, RCODE_CONFLICT_ERROR);
750
751         fw_card_put(card);
752 }
753
754 static void release_address_handler(struct client *client,
755                                     struct client_resource *resource)
756 {
757         struct address_handler_resource *r =
758             container_of(resource, struct address_handler_resource, resource);
759
760         fw_core_remove_address_handler(&r->handler);
761         kfree(r);
762 }
763
764 static int ioctl_allocate(struct client *client, union ioctl_arg *arg)
765 {
766         struct fw_cdev_allocate *a = &arg->allocate;
767         struct address_handler_resource *r;
768         struct fw_address_region region;
769         int ret;
770
771         r = kmalloc(sizeof(*r), GFP_KERNEL);
772         if (r == NULL)
773                 return -ENOMEM;
774
775         region.start = a->offset;
776         region.end   = a->offset + a->length;
777         r->handler.length           = a->length;
778         r->handler.address_callback = handle_request;
779         r->handler.callback_data    = r;
780         r->closure   = a->closure;
781         r->client    = client;
782
783         ret = fw_core_add_address_handler(&r->handler, &region);
784         if (ret < 0) {
785                 kfree(r);
786                 return ret;
787         }
788
789         r->resource.release = release_address_handler;
790         ret = add_client_resource(client, &r->resource, GFP_KERNEL);
791         if (ret < 0) {
792                 release_address_handler(client, &r->resource);
793                 return ret;
794         }
795         a->handle = r->resource.handle;
796
797         return 0;
798 }
799
800 static int ioctl_deallocate(struct client *client, union ioctl_arg *arg)
801 {
802         return release_client_resource(client, arg->deallocate.handle,
803                                        release_address_handler, NULL);
804 }
805
806 static int ioctl_send_response(struct client *client, union ioctl_arg *arg)
807 {
808         struct fw_cdev_send_response *a = &arg->send_response;
809         struct client_resource *resource;
810         struct inbound_transaction_resource *r;
811         int ret = 0;
812
813         if (release_client_resource(client, a->handle,
814                                     release_request, &resource) < 0)
815                 return -EINVAL;
816
817         r = container_of(resource, struct inbound_transaction_resource,
818                          resource);
819         if (is_fcp_request(r->request))
820                 goto out;
821
822         if (a->length != fw_get_response_length(r->request)) {
823                 ret = -EINVAL;
824                 kfree(r->request);
825                 goto out;
826         }
827         if (copy_from_user(r->data, u64_to_uptr(a->data), a->length)) {
828                 ret = -EFAULT;
829                 kfree(r->request);
830                 goto out;
831         }
832         fw_send_response(r->card, r->request, a->rcode);
833  out:
834         fw_card_put(r->card);
835         kfree(r);
836
837         return ret;
838 }
839
840 static int ioctl_initiate_bus_reset(struct client *client, union ioctl_arg *arg)
841 {
842         fw_schedule_bus_reset(client->device->card, true,
843                         arg->initiate_bus_reset.type == FW_CDEV_SHORT_RESET);
844         return 0;
845 }
846
847 static void release_descriptor(struct client *client,
848                                struct client_resource *resource)
849 {
850         struct descriptor_resource *r =
851                 container_of(resource, struct descriptor_resource, resource);
852
853         fw_core_remove_descriptor(&r->descriptor);
854         kfree(r);
855 }
856
857 static int ioctl_add_descriptor(struct client *client, union ioctl_arg *arg)
858 {
859         struct fw_cdev_add_descriptor *a = &arg->add_descriptor;
860         struct descriptor_resource *r;
861         int ret;
862
863         /* Access policy: Allow this ioctl only on local nodes' device files. */
864         if (!client->device->is_local)
865                 return -ENOSYS;
866
867         if (a->length > 256)
868                 return -EINVAL;
869
870         r = kmalloc(sizeof(*r) + a->length * 4, GFP_KERNEL);
871         if (r == NULL)
872                 return -ENOMEM;
873
874         if (copy_from_user(r->data, u64_to_uptr(a->data), a->length * 4)) {
875                 ret = -EFAULT;
876                 goto failed;
877         }
878
879         r->descriptor.length    = a->length;
880         r->descriptor.immediate = a->immediate;
881         r->descriptor.key       = a->key;
882         r->descriptor.data      = r->data;
883
884         ret = fw_core_add_descriptor(&r->descriptor);
885         if (ret < 0)
886                 goto failed;
887
888         r->resource.release = release_descriptor;
889         ret = add_client_resource(client, &r->resource, GFP_KERNEL);
890         if (ret < 0) {
891                 fw_core_remove_descriptor(&r->descriptor);
892                 goto failed;
893         }
894         a->handle = r->resource.handle;
895
896         return 0;
897  failed:
898         kfree(r);
899
900         return ret;
901 }
902
903 static int ioctl_remove_descriptor(struct client *client, union ioctl_arg *arg)
904 {
905         return release_client_resource(client, arg->remove_descriptor.handle,
906                                        release_descriptor, NULL);
907 }
908
909 static void iso_callback(struct fw_iso_context *context, u32 cycle,
910                          size_t header_length, void *header, void *data)
911 {
912         struct client *client = data;
913         struct iso_interrupt_event *e;
914
915         e = kmalloc(sizeof(*e) + header_length, GFP_ATOMIC);
916         if (e == NULL) {
917                 fw_notify("Out of memory when allocating event\n");
918                 return;
919         }
920         e->interrupt.type      = FW_CDEV_EVENT_ISO_INTERRUPT;
921         e->interrupt.closure   = client->iso_closure;
922         e->interrupt.cycle     = cycle;
923         e->interrupt.header_length = header_length;
924         memcpy(e->interrupt.header, header, header_length);
925         queue_event(client, &e->event, &e->interrupt,
926                     sizeof(e->interrupt) + header_length, NULL, 0);
927 }
928
929 static int ioctl_create_iso_context(struct client *client, union ioctl_arg *arg)
930 {
931         struct fw_cdev_create_iso_context *a = &arg->create_iso_context;
932         struct fw_iso_context *context;
933
934         BUILD_BUG_ON(FW_CDEV_ISO_CONTEXT_TRANSMIT != FW_ISO_CONTEXT_TRANSMIT ||
935                      FW_CDEV_ISO_CONTEXT_RECEIVE  != FW_ISO_CONTEXT_RECEIVE);
936
937         if (a->channel > 63)
938                 return -EINVAL;
939
940         switch (a->type) {
941         case FW_ISO_CONTEXT_RECEIVE:
942                 if (a->header_size < 4 || (a->header_size & 3))
943                         return -EINVAL;
944                 break;
945
946         case FW_ISO_CONTEXT_TRANSMIT:
947                 if (a->speed > SCODE_3200)
948                         return -EINVAL;
949                 break;
950
951         default:
952                 return -EINVAL;
953         }
954
955         context = fw_iso_context_create(client->device->card, a->type,
956                                         a->channel, a->speed, a->header_size,
957                                         iso_callback, client);
958         if (IS_ERR(context))
959                 return PTR_ERR(context);
960
961         /* We only support one context at this time. */
962         spin_lock_irq(&client->lock);
963         if (client->iso_context != NULL) {
964                 spin_unlock_irq(&client->lock);
965                 fw_iso_context_destroy(context);
966                 return -EBUSY;
967         }
968         client->iso_closure = a->closure;
969         client->iso_context = context;
970         spin_unlock_irq(&client->lock);
971
972         a->handle = 0;
973
974         return 0;
975 }
976
977 /* Macros for decoding the iso packet control header. */
978 #define GET_PAYLOAD_LENGTH(v)   ((v) & 0xffff)
979 #define GET_INTERRUPT(v)        (((v) >> 16) & 0x01)
980 #define GET_SKIP(v)             (((v) >> 17) & 0x01)
981 #define GET_TAG(v)              (((v) >> 18) & 0x03)
982 #define GET_SY(v)               (((v) >> 20) & 0x0f)
983 #define GET_HEADER_LENGTH(v)    (((v) >> 24) & 0xff)
984
985 static int ioctl_queue_iso(struct client *client, union ioctl_arg *arg)
986 {
987         struct fw_cdev_queue_iso *a = &arg->queue_iso;
988         struct fw_cdev_iso_packet __user *p, *end, *next;
989         struct fw_iso_context *ctx = client->iso_context;
990         unsigned long payload, buffer_end, header_length;
991         u32 control;
992         int count;
993         struct {
994                 struct fw_iso_packet packet;
995                 u8 header[256];
996         } u;
997
998         if (ctx == NULL || a->handle != 0)
999                 return -EINVAL;
1000
1001         /*
1002          * If the user passes a non-NULL data pointer, has mmap()'ed
1003          * the iso buffer, and the pointer points inside the buffer,
1004          * we setup the payload pointers accordingly.  Otherwise we
1005          * set them both to 0, which will still let packets with
1006          * payload_length == 0 through.  In other words, if no packets
1007          * use the indirect payload, the iso buffer need not be mapped
1008          * and the a->data pointer is ignored.
1009          */
1010
1011         payload = (unsigned long)a->data - client->vm_start;
1012         buffer_end = client->buffer.page_count << PAGE_SHIFT;
1013         if (a->data == 0 || client->buffer.pages == NULL ||
1014             payload >= buffer_end) {
1015                 payload = 0;
1016                 buffer_end = 0;
1017         }
1018
1019         p = (struct fw_cdev_iso_packet __user *)u64_to_uptr(a->packets);
1020
1021         if (!access_ok(VERIFY_READ, p, a->size))
1022                 return -EFAULT;
1023
1024         end = (void __user *)p + a->size;
1025         count = 0;
1026         while (p < end) {
1027                 if (get_user(control, &p->control))
1028                         return -EFAULT;
1029                 u.packet.payload_length = GET_PAYLOAD_LENGTH(control);
1030                 u.packet.interrupt = GET_INTERRUPT(control);
1031                 u.packet.skip = GET_SKIP(control);
1032                 u.packet.tag = GET_TAG(control);
1033                 u.packet.sy = GET_SY(control);
1034                 u.packet.header_length = GET_HEADER_LENGTH(control);
1035
1036                 if (ctx->type == FW_ISO_CONTEXT_TRANSMIT) {
1037                         if (u.packet.header_length % 4 != 0)
1038                                 return -EINVAL;
1039                         header_length = u.packet.header_length;
1040                 } else {
1041                         /*
1042                          * We require that header_length is a multiple of
1043                          * the fixed header size, ctx->header_size.
1044                          */
1045                         if (ctx->header_size == 0) {
1046                                 if (u.packet.header_length > 0)
1047                                         return -EINVAL;
1048                         } else if (u.packet.header_length == 0 ||
1049                                    u.packet.header_length % ctx->header_size != 0) {
1050                                 return -EINVAL;
1051                         }
1052                         header_length = 0;
1053                 }
1054
1055                 next = (struct fw_cdev_iso_packet __user *)
1056                         &p->header[header_length / 4];
1057                 if (next > end)
1058                         return -EINVAL;
1059                 if (__copy_from_user
1060                     (u.packet.header, p->header, header_length))
1061                         return -EFAULT;
1062                 if (u.packet.skip && ctx->type == FW_ISO_CONTEXT_TRANSMIT &&
1063                     u.packet.header_length + u.packet.payload_length > 0)
1064                         return -EINVAL;
1065                 if (payload + u.packet.payload_length > buffer_end)
1066                         return -EINVAL;
1067
1068                 if (fw_iso_context_queue(ctx, &u.packet,
1069                                          &client->buffer, payload))
1070                         break;
1071
1072                 p = next;
1073                 payload += u.packet.payload_length;
1074                 count++;
1075         }
1076
1077         a->size    -= uptr_to_u64(p) - a->packets;
1078         a->packets  = uptr_to_u64(p);
1079         a->data     = client->vm_start + payload;
1080
1081         return count;
1082 }
1083
1084 static int ioctl_start_iso(struct client *client, union ioctl_arg *arg)
1085 {
1086         struct fw_cdev_start_iso *a = &arg->start_iso;
1087
1088         BUILD_BUG_ON(
1089             FW_CDEV_ISO_CONTEXT_MATCH_TAG0 != FW_ISO_CONTEXT_MATCH_TAG0 ||
1090             FW_CDEV_ISO_CONTEXT_MATCH_TAG1 != FW_ISO_CONTEXT_MATCH_TAG1 ||
1091             FW_CDEV_ISO_CONTEXT_MATCH_TAG2 != FW_ISO_CONTEXT_MATCH_TAG2 ||
1092             FW_CDEV_ISO_CONTEXT_MATCH_TAG3 != FW_ISO_CONTEXT_MATCH_TAG3 ||
1093             FW_CDEV_ISO_CONTEXT_MATCH_ALL_TAGS != FW_ISO_CONTEXT_MATCH_ALL_TAGS);
1094
1095         if (client->iso_context == NULL || a->handle != 0)
1096                 return -EINVAL;
1097
1098         if (client->iso_context->type == FW_ISO_CONTEXT_RECEIVE &&
1099             (a->tags == 0 || a->tags > 15 || a->sync > 15))
1100                 return -EINVAL;
1101
1102         return fw_iso_context_start(client->iso_context,
1103                                     a->cycle, a->sync, a->tags);
1104 }
1105
1106 static int ioctl_stop_iso(struct client *client, union ioctl_arg *arg)
1107 {
1108         struct fw_cdev_stop_iso *a = &arg->stop_iso;
1109
1110         if (client->iso_context == NULL || a->handle != 0)
1111                 return -EINVAL;
1112
1113         return fw_iso_context_stop(client->iso_context);
1114 }
1115
1116 static int ioctl_get_cycle_timer2(struct client *client, union ioctl_arg *arg)
1117 {
1118         struct fw_cdev_get_cycle_timer2 *a = &arg->get_cycle_timer2;
1119         struct fw_card *card = client->device->card;
1120         struct timespec ts = {0, 0};
1121         u32 cycle_time;
1122         int ret = 0;
1123
1124         local_irq_disable();
1125
1126         cycle_time = card->driver->read_csr(card, CSR_CYCLE_TIME);
1127
1128         switch (a->clk_id) {
1129         case CLOCK_REALTIME:      getnstimeofday(&ts);                   break;
1130         case CLOCK_MONOTONIC:     do_posix_clock_monotonic_gettime(&ts); break;
1131         case CLOCK_MONOTONIC_RAW: getrawmonotonic(&ts);                  break;
1132         default:
1133                 ret = -EINVAL;
1134         }
1135
1136         local_irq_enable();
1137
1138         a->tv_sec      = ts.tv_sec;
1139         a->tv_nsec     = ts.tv_nsec;
1140         a->cycle_timer = cycle_time;
1141
1142         return ret;
1143 }
1144
1145 static int ioctl_get_cycle_timer(struct client *client, union ioctl_arg *arg)
1146 {
1147         struct fw_cdev_get_cycle_timer *a = &arg->get_cycle_timer;
1148         struct fw_cdev_get_cycle_timer2 ct2;
1149
1150         ct2.clk_id = CLOCK_REALTIME;
1151         ioctl_get_cycle_timer2(client, (union ioctl_arg *)&ct2);
1152
1153         a->local_time = ct2.tv_sec * USEC_PER_SEC + ct2.tv_nsec / NSEC_PER_USEC;
1154         a->cycle_timer = ct2.cycle_timer;
1155
1156         return 0;
1157 }
1158
1159 static void iso_resource_work(struct work_struct *work)
1160 {
1161         struct iso_resource_event *e;
1162         struct iso_resource *r =
1163                         container_of(work, struct iso_resource, work.work);
1164         struct client *client = r->client;
1165         int generation, channel, bandwidth, todo;
1166         bool skip, free, success;
1167
1168         spin_lock_irq(&client->lock);
1169         generation = client->device->generation;
1170         todo = r->todo;
1171         /* Allow 1000ms grace period for other reallocations. */
1172         if (todo == ISO_RES_ALLOC &&
1173             time_is_after_jiffies(client->device->card->reset_jiffies + HZ)) {
1174                 schedule_iso_resource(r, DIV_ROUND_UP(HZ, 3));
1175                 skip = true;
1176         } else {
1177                 /* We could be called twice within the same generation. */
1178                 skip = todo == ISO_RES_REALLOC &&
1179                        r->generation == generation;
1180         }
1181         free = todo == ISO_RES_DEALLOC ||
1182                todo == ISO_RES_ALLOC_ONCE ||
1183                todo == ISO_RES_DEALLOC_ONCE;
1184         r->generation = generation;
1185         spin_unlock_irq(&client->lock);
1186
1187         if (skip)
1188                 goto out;
1189
1190         bandwidth = r->bandwidth;
1191
1192         fw_iso_resource_manage(client->device->card, generation,
1193                         r->channels, &channel, &bandwidth,
1194                         todo == ISO_RES_ALLOC ||
1195                         todo == ISO_RES_REALLOC ||
1196                         todo == ISO_RES_ALLOC_ONCE,
1197                         r->transaction_data);
1198         /*
1199          * Is this generation outdated already?  As long as this resource sticks
1200          * in the idr, it will be scheduled again for a newer generation or at
1201          * shutdown.
1202          */
1203         if (channel == -EAGAIN &&
1204             (todo == ISO_RES_ALLOC || todo == ISO_RES_REALLOC))
1205                 goto out;
1206
1207         success = channel >= 0 || bandwidth > 0;
1208
1209         spin_lock_irq(&client->lock);
1210         /*
1211          * Transit from allocation to reallocation, except if the client
1212          * requested deallocation in the meantime.
1213          */
1214         if (r->todo == ISO_RES_ALLOC)
1215                 r->todo = ISO_RES_REALLOC;
1216         /*
1217          * Allocation or reallocation failure?  Pull this resource out of the
1218          * idr and prepare for deletion, unless the client is shutting down.
1219          */
1220         if (r->todo == ISO_RES_REALLOC && !success &&
1221             !client->in_shutdown &&
1222             idr_find(&client->resource_idr, r->resource.handle)) {
1223                 idr_remove(&client->resource_idr, r->resource.handle);
1224                 client_put(client);
1225                 free = true;
1226         }
1227         spin_unlock_irq(&client->lock);
1228
1229         if (todo == ISO_RES_ALLOC && channel >= 0)
1230                 r->channels = 1ULL << channel;
1231
1232         if (todo == ISO_RES_REALLOC && success)
1233                 goto out;
1234
1235         if (todo == ISO_RES_ALLOC || todo == ISO_RES_ALLOC_ONCE) {
1236                 e = r->e_alloc;
1237                 r->e_alloc = NULL;
1238         } else {
1239                 e = r->e_dealloc;
1240                 r->e_dealloc = NULL;
1241         }
1242         e->iso_resource.handle    = r->resource.handle;
1243         e->iso_resource.channel   = channel;
1244         e->iso_resource.bandwidth = bandwidth;
1245
1246         queue_event(client, &e->event,
1247                     &e->iso_resource, sizeof(e->iso_resource), NULL, 0);
1248
1249         if (free) {
1250                 cancel_delayed_work(&r->work);
1251                 kfree(r->e_alloc);
1252                 kfree(r->e_dealloc);
1253                 kfree(r);
1254         }
1255  out:
1256         client_put(client);
1257 }
1258
1259 static void release_iso_resource(struct client *client,
1260                                  struct client_resource *resource)
1261 {
1262         struct iso_resource *r =
1263                 container_of(resource, struct iso_resource, resource);
1264
1265         spin_lock_irq(&client->lock);
1266         r->todo = ISO_RES_DEALLOC;
1267         schedule_iso_resource(r, 0);
1268         spin_unlock_irq(&client->lock);
1269 }
1270
1271 static int init_iso_resource(struct client *client,
1272                 struct fw_cdev_allocate_iso_resource *request, int todo)
1273 {
1274         struct iso_resource_event *e1, *e2;
1275         struct iso_resource *r;
1276         int ret;
1277
1278         if ((request->channels == 0 && request->bandwidth == 0) ||
1279             request->bandwidth > BANDWIDTH_AVAILABLE_INITIAL ||
1280             request->bandwidth < 0)
1281                 return -EINVAL;
1282
1283         r  = kmalloc(sizeof(*r), GFP_KERNEL);
1284         e1 = kmalloc(sizeof(*e1), GFP_KERNEL);
1285         e2 = kmalloc(sizeof(*e2), GFP_KERNEL);
1286         if (r == NULL || e1 == NULL || e2 == NULL) {
1287                 ret = -ENOMEM;
1288                 goto fail;
1289         }
1290
1291         INIT_DELAYED_WORK(&r->work, iso_resource_work);
1292         r->client       = client;
1293         r->todo         = todo;
1294         r->generation   = -1;
1295         r->channels     = request->channels;
1296         r->bandwidth    = request->bandwidth;
1297         r->e_alloc      = e1;
1298         r->e_dealloc    = e2;
1299
1300         e1->iso_resource.closure = request->closure;
1301         e1->iso_resource.type    = FW_CDEV_EVENT_ISO_RESOURCE_ALLOCATED;
1302         e2->iso_resource.closure = request->closure;
1303         e2->iso_resource.type    = FW_CDEV_EVENT_ISO_RESOURCE_DEALLOCATED;
1304
1305         if (todo == ISO_RES_ALLOC) {
1306                 r->resource.release = release_iso_resource;
1307                 ret = add_client_resource(client, &r->resource, GFP_KERNEL);
1308                 if (ret < 0)
1309                         goto fail;
1310         } else {
1311                 r->resource.release = NULL;
1312                 r->resource.handle = -1;
1313                 schedule_iso_resource(r, 0);
1314         }
1315         request->handle = r->resource.handle;
1316
1317         return 0;
1318  fail:
1319         kfree(r);
1320         kfree(e1);
1321         kfree(e2);
1322
1323         return ret;
1324 }
1325
1326 static int ioctl_allocate_iso_resource(struct client *client,
1327                                        union ioctl_arg *arg)
1328 {
1329         return init_iso_resource(client,
1330                         &arg->allocate_iso_resource, ISO_RES_ALLOC);
1331 }
1332
1333 static int ioctl_deallocate_iso_resource(struct client *client,
1334                                          union ioctl_arg *arg)
1335 {
1336         return release_client_resource(client,
1337                         arg->deallocate.handle, release_iso_resource, NULL);
1338 }
1339
1340 static int ioctl_allocate_iso_resource_once(struct client *client,
1341                                             union ioctl_arg *arg)
1342 {
1343         return init_iso_resource(client,
1344                         &arg->allocate_iso_resource, ISO_RES_ALLOC_ONCE);
1345 }
1346
1347 static int ioctl_deallocate_iso_resource_once(struct client *client,
1348                                               union ioctl_arg *arg)
1349 {
1350         return init_iso_resource(client,
1351                         &arg->allocate_iso_resource, ISO_RES_DEALLOC_ONCE);
1352 }
1353
1354 /*
1355  * Returns a speed code:  Maximum speed to or from this device,
1356  * limited by the device's link speed, the local node's link speed,
1357  * and all PHY port speeds between the two links.
1358  */
1359 static int ioctl_get_speed(struct client *client, union ioctl_arg *arg)
1360 {
1361         return client->device->max_speed;
1362 }
1363
1364 static int ioctl_send_broadcast_request(struct client *client,
1365                                         union ioctl_arg *arg)
1366 {
1367         struct fw_cdev_send_request *a = &arg->send_request;
1368
1369         switch (a->tcode) {
1370         case TCODE_WRITE_QUADLET_REQUEST:
1371         case TCODE_WRITE_BLOCK_REQUEST:
1372                 break;
1373         default:
1374                 return -EINVAL;
1375         }
1376
1377         /* Security policy: Only allow accesses to Units Space. */
1378         if (a->offset < CSR_REGISTER_BASE + CSR_CONFIG_ROM_END)
1379                 return -EACCES;
1380
1381         return init_request(client, a, LOCAL_BUS | 0x3f, SCODE_100);
1382 }
1383
1384 static int ioctl_send_stream_packet(struct client *client, union ioctl_arg *arg)
1385 {
1386         struct fw_cdev_send_stream_packet *a = &arg->send_stream_packet;
1387         struct fw_cdev_send_request request;
1388         int dest;
1389
1390         if (a->speed > client->device->card->link_speed ||
1391             a->length > 1024 << a->speed)
1392                 return -EIO;
1393
1394         if (a->tag > 3 || a->channel > 63 || a->sy > 15)
1395                 return -EINVAL;
1396
1397         dest = fw_stream_packet_destination_id(a->tag, a->channel, a->sy);
1398         request.tcode           = TCODE_STREAM_DATA;
1399         request.length          = a->length;
1400         request.closure         = a->closure;
1401         request.data            = a->data;
1402         request.generation      = a->generation;
1403
1404         return init_request(client, &request, dest, a->speed);
1405 }
1406
1407 static void outbound_phy_packet_callback(struct fw_packet *packet,
1408                                          struct fw_card *card, int status)
1409 {
1410         struct outbound_phy_packet_event *e =
1411                 container_of(packet, struct outbound_phy_packet_event, p);
1412
1413         switch (status) {
1414         /* expected: */
1415         case ACK_COMPLETE:      e->phy_packet.rcode = RCODE_COMPLETE;   break;
1416         /* should never happen with PHY packets: */
1417         case ACK_PENDING:       e->phy_packet.rcode = RCODE_COMPLETE;   break;
1418         case ACK_BUSY_X:
1419         case ACK_BUSY_A:
1420         case ACK_BUSY_B:        e->phy_packet.rcode = RCODE_BUSY;       break;
1421         case ACK_DATA_ERROR:    e->phy_packet.rcode = RCODE_DATA_ERROR; break;
1422         case ACK_TYPE_ERROR:    e->phy_packet.rcode = RCODE_TYPE_ERROR; break;
1423         /* stale generation; cancelled; on certain controllers: no ack */
1424         default:                e->phy_packet.rcode = status;           break;
1425         }
1426
1427         queue_event(e->client, &e->event,
1428                     &e->phy_packet, sizeof(e->phy_packet), NULL, 0);
1429         client_put(e->client);
1430 }
1431
1432 static int ioctl_send_phy_packet(struct client *client, union ioctl_arg *arg)
1433 {
1434         struct fw_cdev_send_phy_packet *a = &arg->send_phy_packet;
1435         struct fw_card *card = client->device->card;
1436         struct outbound_phy_packet_event *e;
1437
1438         /* Access policy: Allow this ioctl only on local nodes' device files. */
1439         if (!client->device->is_local)
1440                 return -ENOSYS;
1441
1442         e = kzalloc(sizeof(*e), GFP_KERNEL);
1443         if (e == NULL)
1444                 return -ENOMEM;
1445
1446         client_get(client);
1447         e->client               = client;
1448         e->p.speed              = SCODE_100;
1449         e->p.generation         = a->generation;
1450         e->p.header[0]          = a->data[0];
1451         e->p.header[1]          = a->data[1];
1452         e->p.header_length      = 8;
1453         e->p.callback           = outbound_phy_packet_callback;
1454         e->phy_packet.closure   = a->closure;
1455         e->phy_packet.type      = FW_CDEV_EVENT_PHY_PACKET_SENT;
1456
1457         card->driver->send_request(card, &e->p);
1458
1459         return 0;
1460 }
1461
1462 static int ioctl_receive_phy_packets(struct client *client, union ioctl_arg *arg)
1463 {
1464         struct fw_cdev_receive_phy_packets *a = &arg->receive_phy_packets;
1465         struct fw_card *card = client->device->card;
1466
1467         /* Access policy: Allow this ioctl only on local nodes' device files. */
1468         if (!client->device->is_local)
1469                 return -ENOSYS;
1470
1471         spin_lock_irq(&card->lock);
1472
1473         list_move_tail(&client->phy_receiver_link, &card->phy_receiver_list);
1474         client->phy_receiver_closure = a->closure;
1475
1476         spin_unlock_irq(&card->lock);
1477
1478         return 0;
1479 }
1480
1481 void fw_cdev_handle_phy_packet(struct fw_card *card, struct fw_packet *p)
1482 {
1483         struct client *client;
1484         struct inbound_phy_packet_event *e;
1485         unsigned long flags;
1486
1487         spin_lock_irqsave(&card->lock, flags);
1488
1489         list_for_each_entry(client, &card->phy_receiver_list, phy_receiver_link) {
1490                 e = kmalloc(sizeof(*e) + 8, GFP_ATOMIC);
1491                 if (e == NULL) {
1492                         fw_notify("Out of memory when allocating event\n");
1493                         break;
1494                 }
1495                 e->phy_packet.closure   = client->phy_receiver_closure;
1496                 e->phy_packet.type      = FW_CDEV_EVENT_PHY_PACKET_RECEIVED;
1497                 e->phy_packet.rcode     = RCODE_COMPLETE;
1498                 e->phy_packet.length    = 8;
1499                 e->phy_packet.data[0]   = p->header[1];
1500                 e->phy_packet.data[1]   = p->header[2];
1501                 queue_event(client, &e->event,
1502                             &e->phy_packet, sizeof(e->phy_packet) + 8, NULL, 0);
1503         }
1504
1505         spin_unlock_irqrestore(&card->lock, flags);
1506 }
1507
1508 static int (* const ioctl_handlers[])(struct client *, union ioctl_arg *) = {
1509         [0x00] = ioctl_get_info,
1510         [0x01] = ioctl_send_request,
1511         [0x02] = ioctl_allocate,
1512         [0x03] = ioctl_deallocate,
1513         [0x04] = ioctl_send_response,
1514         [0x05] = ioctl_initiate_bus_reset,
1515         [0x06] = ioctl_add_descriptor,
1516         [0x07] = ioctl_remove_descriptor,
1517         [0x08] = ioctl_create_iso_context,
1518         [0x09] = ioctl_queue_iso,
1519         [0x0a] = ioctl_start_iso,
1520         [0x0b] = ioctl_stop_iso,
1521         [0x0c] = ioctl_get_cycle_timer,
1522         [0x0d] = ioctl_allocate_iso_resource,
1523         [0x0e] = ioctl_deallocate_iso_resource,
1524         [0x0f] = ioctl_allocate_iso_resource_once,
1525         [0x10] = ioctl_deallocate_iso_resource_once,
1526         [0x11] = ioctl_get_speed,
1527         [0x12] = ioctl_send_broadcast_request,
1528         [0x13] = ioctl_send_stream_packet,
1529         [0x14] = ioctl_get_cycle_timer2,
1530         [0x15] = ioctl_send_phy_packet,
1531         [0x16] = ioctl_receive_phy_packets,
1532 };
1533
1534 static int dispatch_ioctl(struct client *client,
1535                           unsigned int cmd, void __user *arg)
1536 {
1537         union ioctl_arg buffer;
1538         int ret;
1539
1540         if (fw_device_is_shutdown(client->device))
1541                 return -ENODEV;
1542
1543         if (_IOC_TYPE(cmd) != '#' ||
1544             _IOC_NR(cmd) >= ARRAY_SIZE(ioctl_handlers) ||
1545             _IOC_SIZE(cmd) > sizeof(buffer))
1546                 return -EINVAL;
1547
1548         if (_IOC_DIR(cmd) == _IOC_READ)
1549                 memset(&buffer, 0, _IOC_SIZE(cmd));
1550
1551         if (_IOC_DIR(cmd) & _IOC_WRITE)
1552                 if (copy_from_user(&buffer, arg, _IOC_SIZE(cmd)))
1553                         return -EFAULT;
1554
1555         ret = ioctl_handlers[_IOC_NR(cmd)](client, &buffer);
1556         if (ret < 0)
1557                 return ret;
1558
1559         if (_IOC_DIR(cmd) & _IOC_READ)
1560                 if (copy_to_user(arg, &buffer, _IOC_SIZE(cmd)))
1561                         return -EFAULT;
1562
1563         return ret;
1564 }
1565
1566 static long fw_device_op_ioctl(struct file *file,
1567                                unsigned int cmd, unsigned long arg)
1568 {
1569         return dispatch_ioctl(file->private_data, cmd, (void __user *)arg);
1570 }
1571
1572 #ifdef CONFIG_COMPAT
1573 static long fw_device_op_compat_ioctl(struct file *file,
1574                                       unsigned int cmd, unsigned long arg)
1575 {
1576         return dispatch_ioctl(file->private_data, cmd, compat_ptr(arg));
1577 }
1578 #endif
1579
1580 static int fw_device_op_mmap(struct file *file, struct vm_area_struct *vma)
1581 {
1582         struct client *client = file->private_data;
1583         enum dma_data_direction direction;
1584         unsigned long size;
1585         int page_count, ret;
1586
1587         if (fw_device_is_shutdown(client->device))
1588                 return -ENODEV;
1589
1590         /* FIXME: We could support multiple buffers, but we don't. */
1591         if (client->buffer.pages != NULL)
1592                 return -EBUSY;
1593
1594         if (!(vma->vm_flags & VM_SHARED))
1595                 return -EINVAL;
1596
1597         if (vma->vm_start & ~PAGE_MASK)
1598                 return -EINVAL;
1599
1600         client->vm_start = vma->vm_start;
1601         size = vma->vm_end - vma->vm_start;
1602         page_count = size >> PAGE_SHIFT;
1603         if (size & ~PAGE_MASK)
1604                 return -EINVAL;
1605
1606         if (vma->vm_flags & VM_WRITE)
1607                 direction = DMA_TO_DEVICE;
1608         else
1609                 direction = DMA_FROM_DEVICE;
1610
1611         ret = fw_iso_buffer_init(&client->buffer, client->device->card,
1612                                  page_count, direction);
1613         if (ret < 0)
1614                 return ret;
1615
1616         ret = fw_iso_buffer_map(&client->buffer, vma);
1617         if (ret < 0)
1618                 fw_iso_buffer_destroy(&client->buffer, client->device->card);
1619
1620         return ret;
1621 }
1622
1623 static int shutdown_resource(int id, void *p, void *data)
1624 {
1625         struct client_resource *resource = p;
1626         struct client *client = data;
1627
1628         resource->release(client, resource);
1629         client_put(client);
1630
1631         return 0;
1632 }
1633
1634 static int fw_device_op_release(struct inode *inode, struct file *file)
1635 {
1636         struct client *client = file->private_data;
1637         struct event *event, *next_event;
1638
1639         spin_lock_irq(&client->device->card->lock);
1640         list_del(&client->phy_receiver_link);
1641         spin_unlock_irq(&client->device->card->lock);
1642
1643         mutex_lock(&client->device->client_list_mutex);
1644         list_del(&client->link);
1645         mutex_unlock(&client->device->client_list_mutex);
1646
1647         if (client->iso_context)
1648                 fw_iso_context_destroy(client->iso_context);
1649
1650         if (client->buffer.pages)
1651                 fw_iso_buffer_destroy(&client->buffer, client->device->card);
1652
1653         /* Freeze client->resource_idr and client->event_list */
1654         spin_lock_irq(&client->lock);
1655         client->in_shutdown = true;
1656         spin_unlock_irq(&client->lock);
1657
1658         idr_for_each(&client->resource_idr, shutdown_resource, client);
1659         idr_remove_all(&client->resource_idr);
1660         idr_destroy(&client->resource_idr);
1661
1662         list_for_each_entry_safe(event, next_event, &client->event_list, link)
1663                 kfree(event);
1664
1665         client_put(client);
1666
1667         return 0;
1668 }
1669
1670 static unsigned int fw_device_op_poll(struct file *file, poll_table * pt)
1671 {
1672         struct client *client = file->private_data;
1673         unsigned int mask = 0;
1674
1675         poll_wait(file, &client->wait, pt);
1676
1677         if (fw_device_is_shutdown(client->device))
1678                 mask |= POLLHUP | POLLERR;
1679         if (!list_empty(&client->event_list))
1680                 mask |= POLLIN | POLLRDNORM;
1681
1682         return mask;
1683 }
1684
1685 const struct file_operations fw_device_ops = {
1686         .owner          = THIS_MODULE,
1687         .llseek         = no_llseek,
1688         .open           = fw_device_op_open,
1689         .read           = fw_device_op_read,
1690         .unlocked_ioctl = fw_device_op_ioctl,
1691         .mmap           = fw_device_op_mmap,
1692         .release        = fw_device_op_release,
1693         .poll           = fw_device_op_poll,
1694 #ifdef CONFIG_COMPAT
1695         .compat_ioctl   = fw_device_op_compat_ioctl,
1696 #endif
1697 };