usb: renesas_usbhs: gadget: fix NULL pointer dereference in ep_disable()
[pandora-kernel.git] / drivers / usb / renesas_usbhs / mod_gadget.c
1 /*
2  * Renesas USB driver
3  *
4  * Copyright (C) 2011 Renesas Solutions Corp.
5  * Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
15  *
16  */
17 #include <linux/dma-mapping.h>
18 #include <linux/io.h>
19 #include <linux/module.h>
20 #include <linux/platform_device.h>
21 #include <linux/usb/ch9.h>
22 #include <linux/usb/gadget.h>
23 #include "common.h"
24
25 /*
26  *              struct
27  */
28 struct usbhsg_request {
29         struct usb_request      req;
30         struct usbhs_pkt        pkt;
31 };
32
33 #define EP_NAME_SIZE 8
34 struct usbhsg_gpriv;
35 struct usbhsg_uep {
36         struct usb_ep            ep;
37         struct usbhs_pipe       *pipe;
38
39         char ep_name[EP_NAME_SIZE];
40
41         struct usbhsg_gpriv *gpriv;
42 };
43
44 struct usbhsg_gpriv {
45         struct usb_gadget        gadget;
46         struct usbhs_mod         mod;
47         struct list_head         link;
48
49         struct usbhsg_uep       *uep;
50         int                      uep_size;
51
52         struct usb_gadget_driver        *driver;
53
54         u32     status;
55 #define USBHSG_STATUS_STARTED           (1 << 0)
56 #define USBHSG_STATUS_REGISTERD         (1 << 1)
57 #define USBHSG_STATUS_WEDGE             (1 << 2)
58 };
59
60 struct usbhsg_recip_handle {
61         char *name;
62         int (*device)(struct usbhs_priv *priv, struct usbhsg_uep *uep,
63                       struct usb_ctrlrequest *ctrl);
64         int (*interface)(struct usbhs_priv *priv, struct usbhsg_uep *uep,
65                          struct usb_ctrlrequest *ctrl);
66         int (*endpoint)(struct usbhs_priv *priv, struct usbhsg_uep *uep,
67                         struct usb_ctrlrequest *ctrl);
68 };
69
70 /*
71  *              macro
72  */
73 #define usbhsg_priv_to_gpriv(priv)                      \
74         container_of(                                   \
75                 usbhs_mod_get(priv, USBHS_GADGET),      \
76                 struct usbhsg_gpriv, mod)
77
78 #define __usbhsg_for_each_uep(start, pos, g, i) \
79         for (i = start, pos = (g)->uep + i;     \
80              i < (g)->uep_size;                 \
81              i++, pos = (g)->uep + i)
82
83 #define usbhsg_for_each_uep(pos, gpriv, i)      \
84         __usbhsg_for_each_uep(1, pos, gpriv, i)
85
86 #define usbhsg_for_each_uep_with_dcp(pos, gpriv, i)     \
87         __usbhsg_for_each_uep(0, pos, gpriv, i)
88
89 #define usbhsg_gadget_to_gpriv(g)\
90         container_of(g, struct usbhsg_gpriv, gadget)
91
92 #define usbhsg_req_to_ureq(r)\
93         container_of(r, struct usbhsg_request, req)
94
95 #define usbhsg_ep_to_uep(e)             container_of(e, struct usbhsg_uep, ep)
96 #define usbhsg_gpriv_to_dev(gp)         usbhs_priv_to_dev((gp)->mod.priv)
97 #define usbhsg_gpriv_to_priv(gp)        ((gp)->mod.priv)
98 #define usbhsg_gpriv_to_dcp(gp)         ((gp)->uep)
99 #define usbhsg_gpriv_to_nth_uep(gp, i)  ((gp)->uep + i)
100 #define usbhsg_uep_to_gpriv(u)          ((u)->gpriv)
101 #define usbhsg_uep_to_pipe(u)           ((u)->pipe)
102 #define usbhsg_pipe_to_uep(p)           ((p)->mod_private)
103 #define usbhsg_is_dcp(u)                ((u) == usbhsg_gpriv_to_dcp((u)->gpriv))
104
105 #define usbhsg_ureq_to_pkt(u)           (&(u)->pkt)
106 #define usbhsg_pkt_to_ureq(i)   \
107         container_of(i, struct usbhsg_request, pkt)
108
109 #define usbhsg_is_not_connected(gp) ((gp)->gadget.speed == USB_SPEED_UNKNOWN)
110
111 /* status */
112 #define usbhsg_status_init(gp)   do {(gp)->status = 0; } while (0)
113 #define usbhsg_status_set(gp, b) (gp->status |=  b)
114 #define usbhsg_status_clr(gp, b) (gp->status &= ~b)
115 #define usbhsg_status_has(gp, b) (gp->status &   b)
116
117 /* controller */
118 LIST_HEAD(the_controller_link);
119
120 #define usbhsg_for_each_controller(gpriv)\
121         list_for_each_entry(gpriv, &the_controller_link, link)
122 #define usbhsg_controller_register(gpriv)\
123         list_add_tail(&(gpriv)->link, &the_controller_link)
124 #define usbhsg_controller_unregister(gpriv)\
125         list_del_init(&(gpriv)->link)
126
127 /*
128  *              queue push/pop
129  */
130 static void usbhsg_queue_pop(struct usbhsg_uep *uep,
131                              struct usbhsg_request *ureq,
132                              int status)
133 {
134         struct usbhsg_gpriv *gpriv = usbhsg_uep_to_gpriv(uep);
135         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(uep);
136         struct device *dev = usbhsg_gpriv_to_dev(gpriv);
137
138         dev_dbg(dev, "pipe %d : queue pop\n", usbhs_pipe_number(pipe));
139
140         ureq->req.status = status;
141         ureq->req.complete(&uep->ep, &ureq->req);
142 }
143
144 static void usbhsg_queue_done(struct usbhs_priv *priv, struct usbhs_pkt *pkt)
145 {
146         struct usbhs_pipe *pipe = pkt->pipe;
147         struct usbhsg_uep *uep = usbhsg_pipe_to_uep(pipe);
148         struct usbhsg_request *ureq = usbhsg_pkt_to_ureq(pkt);
149
150         ureq->req.actual = pkt->actual;
151
152         usbhsg_queue_pop(uep, ureq, 0);
153 }
154
155 static void usbhsg_queue_push(struct usbhsg_uep *uep,
156                               struct usbhsg_request *ureq)
157 {
158         struct usbhsg_gpriv *gpriv = usbhsg_uep_to_gpriv(uep);
159         struct device *dev = usbhsg_gpriv_to_dev(gpriv);
160         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(uep);
161         struct usbhs_pkt *pkt = usbhsg_ureq_to_pkt(ureq);
162         struct usb_request *req = &ureq->req;
163
164         req->actual = 0;
165         req->status = -EINPROGRESS;
166         usbhs_pkt_push(pipe, pkt, usbhsg_queue_done,
167                        req->buf, req->length, req->zero);
168         usbhs_pkt_start(pipe);
169
170         dev_dbg(dev, "pipe %d : queue push (%d)\n",
171                 usbhs_pipe_number(pipe),
172                 req->length);
173 }
174
175 /*
176  *              dma map/unmap
177  */
178 static int usbhsg_dma_map(struct device *dev,
179                           struct usbhs_pkt *pkt,
180                           enum dma_data_direction dir)
181 {
182         struct usbhsg_request *ureq = usbhsg_pkt_to_ureq(pkt);
183         struct usb_request *req = &ureq->req;
184
185         if (pkt->dma != DMA_ADDR_INVALID) {
186                 dev_err(dev, "dma is already mapped\n");
187                 return -EIO;
188         }
189
190         if (req->dma == DMA_ADDR_INVALID) {
191                 pkt->dma = dma_map_single(dev, pkt->buf, pkt->length, dir);
192         } else {
193                 dma_sync_single_for_device(dev, req->dma, req->length, dir);
194                 pkt->dma = req->dma;
195         }
196
197         if (dma_mapping_error(dev, pkt->dma)) {
198                 dev_err(dev, "dma mapping error %x\n", pkt->dma);
199                 return -EIO;
200         }
201
202         return 0;
203 }
204
205 static int usbhsg_dma_unmap(struct device *dev,
206                             struct usbhs_pkt *pkt,
207                             enum dma_data_direction dir)
208 {
209         struct usbhsg_request *ureq = usbhsg_pkt_to_ureq(pkt);
210         struct usb_request *req = &ureq->req;
211
212         if (pkt->dma == DMA_ADDR_INVALID) {
213                 dev_err(dev, "dma is not mapped\n");
214                 return -EIO;
215         }
216
217         if (req->dma == DMA_ADDR_INVALID)
218                 dma_unmap_single(dev, pkt->dma, pkt->length, dir);
219         else
220                 dma_sync_single_for_cpu(dev, req->dma, req->length, dir);
221
222         pkt->dma = DMA_ADDR_INVALID;
223
224         return 0;
225 }
226
227 static int usbhsg_dma_map_ctrl(struct usbhs_pkt *pkt, int map)
228 {
229         struct usbhs_pipe *pipe = pkt->pipe;
230         struct usbhsg_uep *uep = usbhsg_pipe_to_uep(pipe);
231         struct usbhsg_gpriv *gpriv = usbhsg_uep_to_gpriv(uep);
232         struct device *dev = usbhsg_gpriv_to_dev(gpriv);
233         enum dma_data_direction dir;
234
235         dir = usbhs_pipe_is_dir_in(pipe) ? DMA_FROM_DEVICE : DMA_TO_DEVICE;
236
237         if (map)
238                 return usbhsg_dma_map(dev, pkt, dir);
239         else
240                 return usbhsg_dma_unmap(dev, pkt, dir);
241 }
242
243 /*
244  *              USB_TYPE_STANDARD / clear feature functions
245  */
246 static int usbhsg_recip_handler_std_control_done(struct usbhs_priv *priv,
247                                                  struct usbhsg_uep *uep,
248                                                  struct usb_ctrlrequest *ctrl)
249 {
250         struct usbhsg_gpriv *gpriv = usbhsg_priv_to_gpriv(priv);
251         struct usbhsg_uep *dcp = usbhsg_gpriv_to_dcp(gpriv);
252         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(dcp);
253
254         usbhs_dcp_control_transfer_done(pipe);
255
256         return 0;
257 }
258
259 static int usbhsg_recip_handler_std_clear_endpoint(struct usbhs_priv *priv,
260                                                    struct usbhsg_uep *uep,
261                                                    struct usb_ctrlrequest *ctrl)
262 {
263         struct usbhsg_gpriv *gpriv = usbhsg_uep_to_gpriv(uep);
264         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(uep);
265
266         if (!usbhsg_status_has(gpriv, USBHSG_STATUS_WEDGE)) {
267                 usbhs_pipe_disable(pipe);
268                 usbhs_pipe_sequence_data0(pipe);
269                 usbhs_pipe_enable(pipe);
270         }
271
272         usbhsg_recip_handler_std_control_done(priv, uep, ctrl);
273
274         return 0;
275 }
276
277 struct usbhsg_recip_handle req_clear_feature = {
278         .name           = "clear feature",
279         .device         = usbhsg_recip_handler_std_control_done,
280         .interface      = usbhsg_recip_handler_std_control_done,
281         .endpoint       = usbhsg_recip_handler_std_clear_endpoint,
282 };
283
284 /*
285  *              USB_TYPE handler
286  */
287 static int usbhsg_recip_run_handle(struct usbhs_priv *priv,
288                                    struct usbhsg_recip_handle *handler,
289                                    struct usb_ctrlrequest *ctrl)
290 {
291         struct usbhsg_gpriv *gpriv = usbhsg_priv_to_gpriv(priv);
292         struct device *dev = usbhsg_gpriv_to_dev(gpriv);
293         struct usbhsg_uep *uep;
294         struct usbhs_pipe *pipe;
295         int recip = ctrl->bRequestType & USB_RECIP_MASK;
296         int nth = le16_to_cpu(ctrl->wIndex) & USB_ENDPOINT_NUMBER_MASK;
297         int ret;
298         int (*func)(struct usbhs_priv *priv, struct usbhsg_uep *uep,
299                     struct usb_ctrlrequest *ctrl);
300         char *msg;
301
302         uep = usbhsg_gpriv_to_nth_uep(gpriv, nth);
303         pipe = usbhsg_uep_to_pipe(uep);
304         if (!pipe) {
305                 dev_err(dev, "wrong recip request\n");
306                 ret = -EINVAL;
307                 goto usbhsg_recip_run_handle_end;
308         }
309
310         switch (recip) {
311         case USB_RECIP_DEVICE:
312                 msg     = "DEVICE";
313                 func    = handler->device;
314                 break;
315         case USB_RECIP_INTERFACE:
316                 msg     = "INTERFACE";
317                 func    = handler->interface;
318                 break;
319         case USB_RECIP_ENDPOINT:
320                 msg     = "ENDPOINT";
321                 func    = handler->endpoint;
322                 break;
323         default:
324                 dev_warn(dev, "unsupported RECIP(%d)\n", recip);
325                 func = NULL;
326                 ret = -EINVAL;
327         }
328
329         if (func) {
330                 unsigned long flags;
331
332                 dev_dbg(dev, "%s (pipe %d :%s)\n", handler->name, nth, msg);
333
334                 /********************  spin lock ********************/
335                 usbhs_lock(priv, flags);
336                 ret = func(priv, uep, ctrl);
337                 usbhs_unlock(priv, flags);
338                 /********************  spin unlock ******************/
339         }
340
341 usbhsg_recip_run_handle_end:
342         usbhs_pkt_start(pipe);
343
344         return ret;
345 }
346
347 /*
348  *              irq functions
349  *
350  * it will be called from usbhs_interrupt
351  */
352 static int usbhsg_irq_dev_state(struct usbhs_priv *priv,
353                                 struct usbhs_irq_state *irq_state)
354 {
355         struct usbhsg_gpriv *gpriv = usbhsg_priv_to_gpriv(priv);
356         struct device *dev = usbhsg_gpriv_to_dev(gpriv);
357
358         gpriv->gadget.speed = usbhs_bus_get_speed(priv);
359
360         dev_dbg(dev, "state = %x : speed : %d\n",
361                 usbhs_status_get_device_state(irq_state),
362                 gpriv->gadget.speed);
363
364         return 0;
365 }
366
367 static int usbhsg_irq_ctrl_stage(struct usbhs_priv *priv,
368                                  struct usbhs_irq_state *irq_state)
369 {
370         struct usbhsg_gpriv *gpriv = usbhsg_priv_to_gpriv(priv);
371         struct usbhsg_uep *dcp = usbhsg_gpriv_to_dcp(gpriv);
372         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(dcp);
373         struct device *dev = usbhsg_gpriv_to_dev(gpriv);
374         struct usb_ctrlrequest ctrl;
375         struct usbhsg_recip_handle *recip_handler = NULL;
376         int stage = usbhs_status_get_ctrl_stage(irq_state);
377         int ret = 0;
378
379         dev_dbg(dev, "stage = %d\n", stage);
380
381         /*
382          * see Manual
383          *
384          *  "Operation"
385          *  - "Interrupt Function"
386          *    - "Control Transfer Stage Transition Interrupt"
387          *      - Fig. "Control Transfer Stage Transitions"
388          */
389
390         switch (stage) {
391         case READ_DATA_STAGE:
392                 pipe->handler = &usbhs_fifo_pio_push_handler;
393                 break;
394         case WRITE_DATA_STAGE:
395                 pipe->handler = &usbhs_fifo_pio_pop_handler;
396                 break;
397         case NODATA_STATUS_STAGE:
398                 pipe->handler = &usbhs_ctrl_stage_end_handler;
399                 break;
400         default:
401                 return ret;
402         }
403
404         /*
405          * get usb request
406          */
407         usbhs_usbreq_get_val(priv, &ctrl);
408
409         switch (ctrl.bRequestType & USB_TYPE_MASK) {
410         case USB_TYPE_STANDARD:
411                 switch (ctrl.bRequest) {
412                 case USB_REQ_CLEAR_FEATURE:
413                         recip_handler = &req_clear_feature;
414                         break;
415                 }
416         }
417
418         /*
419          * setup stage / run recip
420          */
421         if (recip_handler)
422                 ret = usbhsg_recip_run_handle(priv, recip_handler, &ctrl);
423         else
424                 ret = gpriv->driver->setup(&gpriv->gadget, &ctrl);
425
426         if (ret < 0)
427                 usbhs_pipe_stall(pipe);
428
429         return ret;
430 }
431
432 /*
433  *
434  *              usb_dcp_ops
435  *
436  */
437 static int usbhsg_pipe_disable(struct usbhsg_uep *uep)
438 {
439         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(uep);
440         struct usbhs_pkt *pkt;
441
442         usbhs_pipe_disable(pipe);
443
444         while (1) {
445                 pkt = usbhs_pkt_pop(pipe, NULL);
446                 if (!pkt)
447                         break;
448         }
449
450         return 0;
451 }
452
453 static void usbhsg_uep_init(struct usbhsg_gpriv *gpriv)
454 {
455         int i;
456         struct usbhsg_uep *uep;
457
458         usbhsg_for_each_uep_with_dcp(uep, gpriv, i)
459                 uep->pipe = NULL;
460 }
461
462 /*
463  *
464  *              usb_ep_ops
465  *
466  */
467 static int usbhsg_ep_enable(struct usb_ep *ep,
468                          const struct usb_endpoint_descriptor *desc)
469 {
470         struct usbhsg_uep *uep   = usbhsg_ep_to_uep(ep);
471         struct usbhsg_gpriv *gpriv = usbhsg_uep_to_gpriv(uep);
472         struct usbhs_priv *priv = usbhsg_gpriv_to_priv(gpriv);
473         struct usbhs_pipe *pipe;
474         int ret = -EIO;
475
476         /*
477          * if it already have pipe,
478          * nothing to do
479          */
480         if (uep->pipe) {
481                 usbhs_pipe_clear(uep->pipe);
482                 usbhs_pipe_sequence_data0(uep->pipe);
483                 return 0;
484         }
485
486         pipe = usbhs_pipe_malloc(priv,
487                                  usb_endpoint_type(desc),
488                                  usb_endpoint_dir_in(desc));
489         if (pipe) {
490                 uep->pipe               = pipe;
491                 pipe->mod_private       = uep;
492
493                 /* set epnum / maxp */
494                 usbhs_pipe_config_update(pipe, 0,
495                                          usb_endpoint_num(desc),
496                                          usb_endpoint_maxp(desc));
497
498                 /*
499                  * usbhs_fifo_dma_push/pop_handler try to
500                  * use dmaengine if possible.
501                  * It will use pio handler if impossible.
502                  */
503                 if (usb_endpoint_dir_in(desc))
504                         pipe->handler = &usbhs_fifo_dma_push_handler;
505                 else
506                         pipe->handler = &usbhs_fifo_dma_pop_handler;
507
508                 ret = 0;
509         }
510
511         return ret;
512 }
513
514 static int usbhsg_ep_disable(struct usb_ep *ep)
515 {
516         struct usbhsg_uep *uep = usbhsg_ep_to_uep(ep);
517         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(uep);
518
519         if (!pipe)
520                 return -EINVAL;
521
522         return usbhsg_pipe_disable(uep);
523 }
524
525 static struct usb_request *usbhsg_ep_alloc_request(struct usb_ep *ep,
526                                                    gfp_t gfp_flags)
527 {
528         struct usbhsg_request *ureq;
529
530         ureq = kzalloc(sizeof *ureq, gfp_flags);
531         if (!ureq)
532                 return NULL;
533
534         usbhs_pkt_init(usbhsg_ureq_to_pkt(ureq));
535
536         ureq->req.dma = DMA_ADDR_INVALID;
537
538         return &ureq->req;
539 }
540
541 static void usbhsg_ep_free_request(struct usb_ep *ep,
542                                    struct usb_request *req)
543 {
544         struct usbhsg_request *ureq = usbhsg_req_to_ureq(req);
545
546         WARN_ON(!list_empty(&ureq->pkt.node));
547         kfree(ureq);
548 }
549
550 static int usbhsg_ep_queue(struct usb_ep *ep, struct usb_request *req,
551                           gfp_t gfp_flags)
552 {
553         struct usbhsg_uep *uep = usbhsg_ep_to_uep(ep);
554         struct usbhsg_gpriv *gpriv = usbhsg_uep_to_gpriv(uep);
555         struct usbhsg_request *ureq = usbhsg_req_to_ureq(req);
556         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(uep);
557
558         /* param check */
559         if (usbhsg_is_not_connected(gpriv)      ||
560             unlikely(!gpriv->driver)            ||
561             unlikely(!pipe))
562                 return -ESHUTDOWN;
563
564         usbhsg_queue_push(uep, ureq);
565
566         return 0;
567 }
568
569 static int usbhsg_ep_dequeue(struct usb_ep *ep, struct usb_request *req)
570 {
571         struct usbhsg_uep *uep = usbhsg_ep_to_uep(ep);
572         struct usbhsg_request *ureq = usbhsg_req_to_ureq(req);
573         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(uep);
574
575         usbhs_pkt_pop(pipe, usbhsg_ureq_to_pkt(ureq));
576         usbhsg_queue_pop(uep, ureq, -ECONNRESET);
577
578         return 0;
579 }
580
581 static int __usbhsg_ep_set_halt_wedge(struct usb_ep *ep, int halt, int wedge)
582 {
583         struct usbhsg_uep *uep = usbhsg_ep_to_uep(ep);
584         struct usbhs_pipe *pipe = usbhsg_uep_to_pipe(uep);
585         struct usbhsg_gpriv *gpriv = usbhsg_uep_to_gpriv(uep);
586         struct usbhs_priv *priv = usbhsg_gpriv_to_priv(gpriv);
587         struct device *dev = usbhsg_gpriv_to_dev(gpriv);
588         unsigned long flags;
589
590         usbhsg_pipe_disable(uep);
591
592         dev_dbg(dev, "set halt %d (pipe %d)\n",
593                 halt, usbhs_pipe_number(pipe));
594
595         /********************  spin lock ********************/
596         usbhs_lock(priv, flags);
597
598         if (halt)
599                 usbhs_pipe_stall(pipe);
600         else
601                 usbhs_pipe_disable(pipe);
602
603         if (halt && wedge)
604                 usbhsg_status_set(gpriv, USBHSG_STATUS_WEDGE);
605         else
606                 usbhsg_status_clr(gpriv, USBHSG_STATUS_WEDGE);
607
608         usbhs_unlock(priv, flags);
609         /********************  spin unlock ******************/
610
611         return 0;
612 }
613
614 static int usbhsg_ep_set_halt(struct usb_ep *ep, int value)
615 {
616         return __usbhsg_ep_set_halt_wedge(ep, value, 0);
617 }
618
619 static int usbhsg_ep_set_wedge(struct usb_ep *ep)
620 {
621         return __usbhsg_ep_set_halt_wedge(ep, 1, 1);
622 }
623
624 static struct usb_ep_ops usbhsg_ep_ops = {
625         .enable         = usbhsg_ep_enable,
626         .disable        = usbhsg_ep_disable,
627
628         .alloc_request  = usbhsg_ep_alloc_request,
629         .free_request   = usbhsg_ep_free_request,
630
631         .queue          = usbhsg_ep_queue,
632         .dequeue        = usbhsg_ep_dequeue,
633
634         .set_halt       = usbhsg_ep_set_halt,
635         .set_wedge      = usbhsg_ep_set_wedge,
636 };
637
638 /*
639  *              usb module start/end
640  */
641 static int usbhsg_try_start(struct usbhs_priv *priv, u32 status)
642 {
643         struct usbhsg_gpriv *gpriv = usbhsg_priv_to_gpriv(priv);
644         struct usbhsg_uep *dcp = usbhsg_gpriv_to_dcp(gpriv);
645         struct usbhs_mod *mod = usbhs_mod_get_current(priv);
646         struct device *dev = usbhs_priv_to_dev(priv);
647         unsigned long flags;
648         int ret = 0;
649
650         /********************  spin lock ********************/
651         usbhs_lock(priv, flags);
652
653         usbhsg_status_set(gpriv, status);
654         if (!(usbhsg_status_has(gpriv, USBHSG_STATUS_STARTED) &&
655               usbhsg_status_has(gpriv, USBHSG_STATUS_REGISTERD)))
656                 ret = -1; /* not ready */
657
658         usbhs_unlock(priv, flags);
659         /********************  spin unlock ********************/
660
661         if (ret < 0)
662                 return 0; /* not ready is not error */
663
664         /*
665          * enable interrupt and systems if ready
666          */
667         dev_dbg(dev, "start gadget\n");
668
669         /*
670          * pipe initialize and enable DCP
671          */
672         usbhs_pipe_init(priv,
673                         usbhsg_dma_map_ctrl);
674         usbhs_fifo_init(priv);
675         usbhsg_uep_init(gpriv);
676
677         /* dcp init */
678         dcp->pipe               = usbhs_dcp_malloc(priv);
679         dcp->pipe->mod_private  = dcp;
680         usbhs_pipe_config_update(dcp->pipe, 0, 0, 64);
681
682         /*
683          * system config enble
684          * - HI speed
685          * - function
686          * - usb module
687          */
688         usbhs_sys_hispeed_ctrl(priv, 1);
689         usbhs_sys_function_ctrl(priv, 1);
690         usbhs_sys_usb_ctrl(priv, 1);
691
692         /*
693          * enable irq callback
694          */
695         mod->irq_dev_state      = usbhsg_irq_dev_state;
696         mod->irq_ctrl_stage     = usbhsg_irq_ctrl_stage;
697         usbhs_irq_callback_update(priv, mod);
698
699         return 0;
700 }
701
702 static int usbhsg_try_stop(struct usbhs_priv *priv, u32 status)
703 {
704         struct usbhsg_gpriv *gpriv = usbhsg_priv_to_gpriv(priv);
705         struct usbhs_mod *mod = usbhs_mod_get_current(priv);
706         struct usbhsg_uep *dcp = usbhsg_gpriv_to_dcp(gpriv);
707         struct device *dev = usbhs_priv_to_dev(priv);
708         unsigned long flags;
709         int ret = 0;
710
711         /********************  spin lock ********************/
712         usbhs_lock(priv, flags);
713
714         usbhsg_status_clr(gpriv, status);
715         if (!usbhsg_status_has(gpriv, USBHSG_STATUS_STARTED) &&
716             !usbhsg_status_has(gpriv, USBHSG_STATUS_REGISTERD))
717                 ret = -1; /* already done */
718
719         usbhs_unlock(priv, flags);
720         /********************  spin unlock ********************/
721
722         if (ret < 0)
723                 return 0; /* already done is not error */
724
725         /*
726          * disable interrupt and systems if 1st try
727          */
728         usbhs_fifo_quit(priv);
729
730         /* disable all irq */
731         mod->irq_dev_state      = NULL;
732         mod->irq_ctrl_stage     = NULL;
733         usbhs_irq_callback_update(priv, mod);
734
735         gpriv->gadget.speed = USB_SPEED_UNKNOWN;
736
737         /* disable sys */
738         usbhs_sys_hispeed_ctrl(priv, 0);
739         usbhs_sys_function_ctrl(priv, 0);
740         usbhs_sys_usb_ctrl(priv, 0);
741
742         usbhsg_pipe_disable(dcp);
743
744         dev_dbg(dev, "stop gadget\n");
745
746         return 0;
747 }
748
749 /*
750  *
751  *              linux usb function
752  *
753  */
754 static int usbhsg_gadget_start(struct usb_gadget *gadget,
755                 struct usb_gadget_driver *driver)
756 {
757         struct usbhsg_gpriv *gpriv = usbhsg_gadget_to_gpriv(gadget);
758         struct usbhs_priv *priv = usbhsg_gpriv_to_priv(gpriv);
759
760         if (!driver             ||
761             !driver->setup      ||
762             driver->speed < USB_SPEED_FULL)
763                 return -EINVAL;
764
765         /* first hook up the driver ... */
766         gpriv->driver = driver;
767         gpriv->gadget.dev.driver = &driver->driver;
768
769         return usbhsg_try_start(priv, USBHSG_STATUS_REGISTERD);
770 }
771
772 static int usbhsg_gadget_stop(struct usb_gadget *gadget,
773                 struct usb_gadget_driver *driver)
774 {
775         struct usbhsg_gpriv *gpriv = usbhsg_gadget_to_gpriv(gadget);
776         struct usbhs_priv *priv = usbhsg_gpriv_to_priv(gpriv);
777
778         if (!driver             ||
779             !driver->unbind)
780                 return -EINVAL;
781
782         usbhsg_try_stop(priv, USBHSG_STATUS_REGISTERD);
783         gpriv->gadget.dev.driver = NULL;
784         gpriv->driver = NULL;
785
786         return 0;
787 }
788
789 /*
790  *              usb gadget ops
791  */
792 static int usbhsg_get_frame(struct usb_gadget *gadget)
793 {
794         struct usbhsg_gpriv *gpriv = usbhsg_gadget_to_gpriv(gadget);
795         struct usbhs_priv *priv = usbhsg_gpriv_to_priv(gpriv);
796
797         return usbhs_frame_get_num(priv);
798 }
799
800 static struct usb_gadget_ops usbhsg_gadget_ops = {
801         .get_frame              = usbhsg_get_frame,
802         .udc_start              = usbhsg_gadget_start,
803         .udc_stop               = usbhsg_gadget_stop,
804 };
805
806 static int usbhsg_start(struct usbhs_priv *priv)
807 {
808         return usbhsg_try_start(priv, USBHSG_STATUS_STARTED);
809 }
810
811 static int usbhsg_stop(struct usbhs_priv *priv)
812 {
813         struct usbhsg_gpriv *gpriv = usbhsg_priv_to_gpriv(priv);
814
815         /* cable disconnect */
816         if (gpriv->driver &&
817             gpriv->driver->disconnect)
818                 gpriv->driver->disconnect(&gpriv->gadget);
819
820         return usbhsg_try_stop(priv, USBHSG_STATUS_STARTED);
821 }
822
823 static void usbhs_mod_gadget_release(struct device *pdev)
824 {
825         /* do nothing */
826 }
827
828 int usbhs_mod_gadget_probe(struct usbhs_priv *priv)
829 {
830         struct usbhsg_gpriv *gpriv;
831         struct usbhsg_uep *uep;
832         struct device *dev = usbhs_priv_to_dev(priv);
833         int pipe_size = usbhs_get_dparam(priv, pipe_size);
834         int i;
835         int ret;
836
837         gpriv = kzalloc(sizeof(struct usbhsg_gpriv), GFP_KERNEL);
838         if (!gpriv) {
839                 dev_err(dev, "Could not allocate gadget priv\n");
840                 return -ENOMEM;
841         }
842
843         uep = kzalloc(sizeof(struct usbhsg_uep) * pipe_size, GFP_KERNEL);
844         if (!uep) {
845                 dev_err(dev, "Could not allocate ep\n");
846                 ret = -ENOMEM;
847                 goto usbhs_mod_gadget_probe_err_gpriv;
848         }
849
850         /*
851          * CAUTION
852          *
853          * There is no guarantee that it is possible to access usb module here.
854          * Don't accesses to it.
855          * The accesse will be enable after "usbhsg_start"
856          */
857
858         /*
859          * register itself
860          */
861         usbhs_mod_register(priv, &gpriv->mod, USBHS_GADGET);
862
863         /* init gpriv */
864         gpriv->mod.name         = "gadget";
865         gpriv->mod.start        = usbhsg_start;
866         gpriv->mod.stop         = usbhsg_stop;
867         gpriv->uep              = uep;
868         gpriv->uep_size         = pipe_size;
869         usbhsg_status_init(gpriv);
870
871         /*
872          * init gadget
873          */
874         dev_set_name(&gpriv->gadget.dev, "gadget");
875         gpriv->gadget.dev.parent        = dev;
876         gpriv->gadget.dev.release       = usbhs_mod_gadget_release;
877         gpriv->gadget.name              = "renesas_usbhs_udc";
878         gpriv->gadget.ops               = &usbhsg_gadget_ops;
879         gpriv->gadget.is_dualspeed      = 1;
880         ret = device_register(&gpriv->gadget.dev);
881         if (ret < 0)
882                 goto err_add_udc;
883
884         INIT_LIST_HEAD(&gpriv->gadget.ep_list);
885
886         /*
887          * init usb_ep
888          */
889         usbhsg_for_each_uep_with_dcp(uep, gpriv, i) {
890                 uep->gpriv      = gpriv;
891                 snprintf(uep->ep_name, EP_NAME_SIZE, "ep%d", i);
892
893                 uep->ep.name            = uep->ep_name;
894                 uep->ep.ops             = &usbhsg_ep_ops;
895                 INIT_LIST_HEAD(&uep->ep.ep_list);
896
897                 /* init DCP */
898                 if (usbhsg_is_dcp(uep)) {
899                         gpriv->gadget.ep0 = &uep->ep;
900                         uep->ep.maxpacket = 64;
901                 }
902                 /* init normal pipe */
903                 else {
904                         uep->ep.maxpacket = 512;
905                         list_add_tail(&uep->ep.ep_list, &gpriv->gadget.ep_list);
906                 }
907         }
908
909         usbhsg_controller_register(gpriv);
910
911         ret = usb_add_gadget_udc(dev, &gpriv->gadget);
912         if (ret)
913                 goto err_register;
914
915
916         dev_info(dev, "gadget probed\n");
917
918         return 0;
919
920 err_register:
921         device_unregister(&gpriv->gadget.dev);
922 err_add_udc:
923         kfree(gpriv->uep);
924
925 usbhs_mod_gadget_probe_err_gpriv:
926         kfree(gpriv);
927
928         return ret;
929 }
930
931 void usbhs_mod_gadget_remove(struct usbhs_priv *priv)
932 {
933         struct usbhsg_gpriv *gpriv = usbhsg_priv_to_gpriv(priv);
934
935         usb_del_gadget_udc(&gpriv->gadget);
936
937         device_unregister(&gpriv->gadget.dev);
938
939         usbhsg_controller_unregister(gpriv);
940
941         kfree(gpriv->uep);
942         kfree(gpriv);
943 }