1d4ef6694SJoris Giovannangeli /*-
2*7ce1da6aSMatthew Dillon * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
3*7ce1da6aSMatthew Dillon *
4d4ef6694SJoris Giovannangeli * Copyright (c) 2006, 2008 Stanislav Sedov <stas@FreeBSD.org>.
5d4ef6694SJoris Giovannangeli * All rights reserved.
6d4ef6694SJoris Giovannangeli *
7d4ef6694SJoris Giovannangeli * Redistribution and use in source and binary forms, with or without
8d4ef6694SJoris Giovannangeli * modification, are permitted provided that the following conditions
9d4ef6694SJoris Giovannangeli * are met:
10d4ef6694SJoris Giovannangeli * 1. Redistributions of source code must retain the above copyright
11d4ef6694SJoris Giovannangeli * notice, this list of conditions and the following disclaimer.
12d4ef6694SJoris Giovannangeli * 2. Redistributions in binary form must reproduce the above copyright
13d4ef6694SJoris Giovannangeli * notice, this list of conditions and the following disclaimer in the
14d4ef6694SJoris Giovannangeli * documentation and/or other materials provided with the distribution.
15d4ef6694SJoris Giovannangeli *
16d4ef6694SJoris Giovannangeli * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
17d4ef6694SJoris Giovannangeli * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
18d4ef6694SJoris Giovannangeli * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
19d4ef6694SJoris Giovannangeli * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
20d4ef6694SJoris Giovannangeli * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
21d4ef6694SJoris Giovannangeli * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
22d4ef6694SJoris Giovannangeli * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
23d4ef6694SJoris Giovannangeli * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
24d4ef6694SJoris Giovannangeli * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
25d4ef6694SJoris Giovannangeli * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
26d4ef6694SJoris Giovannangeli */
27d4ef6694SJoris Giovannangeli
28d4ef6694SJoris Giovannangeli #include <sys/cdefs.h>
29*7ce1da6aSMatthew Dillon __FBSDID("$FreeBSD$");
30d4ef6694SJoris Giovannangeli
31d4ef6694SJoris Giovannangeli #include <assert.h>
32d4ef6694SJoris Giovannangeli #include <stdio.h>
33d4ef6694SJoris Giovannangeli #include <stdlib.h>
34d4ef6694SJoris Giovannangeli #include <string.h>
35d4ef6694SJoris Giovannangeli #include <unistd.h>
36d4ef6694SJoris Giovannangeli #include <fcntl.h>
37d4ef6694SJoris Giovannangeli #include <err.h>
38d4ef6694SJoris Giovannangeli #include <errno.h>
39d4ef6694SJoris Giovannangeli
40d4ef6694SJoris Giovannangeli #include <sys/types.h>
41d4ef6694SJoris Giovannangeli #include <sys/stat.h>
42d4ef6694SJoris Giovannangeli #include <sys/mman.h>
43d4ef6694SJoris Giovannangeli #include <sys/ioctl.h>
44*7ce1da6aSMatthew Dillon #include <sys/ioccom.h>
45d4ef6694SJoris Giovannangeli #include <sys/cpuctl.h>
46d4ef6694SJoris Giovannangeli
47d4ef6694SJoris Giovannangeli #include <machine/cpufunc.h>
48d4ef6694SJoris Giovannangeli #include <machine/specialreg.h>
49d4ef6694SJoris Giovannangeli
50d4ef6694SJoris Giovannangeli #include "cpucontrol.h"
51d4ef6694SJoris Giovannangeli #include "intel.h"
52d4ef6694SJoris Giovannangeli
53d4ef6694SJoris Giovannangeli #define DEFAULT_UCODE_SIZE 2000 /* Size of update data if not specified. */
54d4ef6694SJoris Giovannangeli
55d4ef6694SJoris Giovannangeli int
intel_probe(int fd)56d4ef6694SJoris Giovannangeli intel_probe(int fd)
57d4ef6694SJoris Giovannangeli {
58d4ef6694SJoris Giovannangeli char vendor[13];
59d4ef6694SJoris Giovannangeli int error;
60d4ef6694SJoris Giovannangeli cpuctl_cpuid_args_t idargs = {
61d4ef6694SJoris Giovannangeli .level = 0,
62d4ef6694SJoris Giovannangeli };
63d4ef6694SJoris Giovannangeli
64d4ef6694SJoris Giovannangeli error = ioctl(fd, CPUCTL_CPUID, &idargs);
65d4ef6694SJoris Giovannangeli if (error < 0) {
66d4ef6694SJoris Giovannangeli WARN(0, "ioctl()");
67d4ef6694SJoris Giovannangeli return (1);
68d4ef6694SJoris Giovannangeli }
69d4ef6694SJoris Giovannangeli ((uint32_t *)vendor)[0] = idargs.data[1];
70d4ef6694SJoris Giovannangeli ((uint32_t *)vendor)[1] = idargs.data[3];
71d4ef6694SJoris Giovannangeli ((uint32_t *)vendor)[2] = idargs.data[2];
72d4ef6694SJoris Giovannangeli vendor[12] = '\0';
73d4ef6694SJoris Giovannangeli if (strncmp(vendor, INTEL_VENDOR_ID, sizeof(INTEL_VENDOR_ID)) != 0)
74d4ef6694SJoris Giovannangeli return (1);
75d4ef6694SJoris Giovannangeli return (0);
76d4ef6694SJoris Giovannangeli }
77d4ef6694SJoris Giovannangeli
78d4ef6694SJoris Giovannangeli void
intel_update(const char * dev,const char * path)79d4ef6694SJoris Giovannangeli intel_update(const char *dev, const char *path)
80d4ef6694SJoris Giovannangeli {
81d4ef6694SJoris Giovannangeli int fd, devfd;
82d4ef6694SJoris Giovannangeli struct stat st;
83d4ef6694SJoris Giovannangeli uint32_t *fw_image;
84d4ef6694SJoris Giovannangeli int have_ext_table;
85d4ef6694SJoris Giovannangeli uint32_t sum;
86d4ef6694SJoris Giovannangeli unsigned int i;
87d4ef6694SJoris Giovannangeli size_t payload_size;
88d4ef6694SJoris Giovannangeli intel_fw_header_t *fw_header;
89d4ef6694SJoris Giovannangeli intel_cpu_signature_t *ext_table;
90d4ef6694SJoris Giovannangeli intel_ext_header_t *ext_header;
91*7ce1da6aSMatthew Dillon uint32_t sig, signature, flags;
92d4ef6694SJoris Giovannangeli int32_t revision;
93d4ef6694SJoris Giovannangeli ssize_t ext_size;
94d4ef6694SJoris Giovannangeli size_t ext_table_size;
95d4ef6694SJoris Giovannangeli void *fw_data;
96d4ef6694SJoris Giovannangeli size_t data_size, total_size;
97d4ef6694SJoris Giovannangeli cpuctl_msr_args_t msrargs = {
98d4ef6694SJoris Giovannangeli .msr = MSR_IA32_PLATFORM_ID,
99d4ef6694SJoris Giovannangeli };
100d4ef6694SJoris Giovannangeli cpuctl_cpuid_args_t idargs = {
101d4ef6694SJoris Giovannangeli .level = 1, /* Signature. */
102d4ef6694SJoris Giovannangeli };
103d4ef6694SJoris Giovannangeli cpuctl_update_args_t args;
104d4ef6694SJoris Giovannangeli int error;
105d4ef6694SJoris Giovannangeli
106d4ef6694SJoris Giovannangeli assert(path);
107d4ef6694SJoris Giovannangeli assert(dev);
108d4ef6694SJoris Giovannangeli
109d4ef6694SJoris Giovannangeli fd = -1;
110d4ef6694SJoris Giovannangeli fw_image = MAP_FAILED;
111d4ef6694SJoris Giovannangeli ext_table = NULL;
112d4ef6694SJoris Giovannangeli ext_header = NULL;
113d4ef6694SJoris Giovannangeli devfd = open(dev, O_RDWR);
114d4ef6694SJoris Giovannangeli if (devfd < 0) {
115d4ef6694SJoris Giovannangeli WARN(0, "could not open %s for writing", dev);
116d4ef6694SJoris Giovannangeli return;
117d4ef6694SJoris Giovannangeli }
118d4ef6694SJoris Giovannangeli error = ioctl(devfd, CPUCTL_CPUID, &idargs);
119d4ef6694SJoris Giovannangeli if (error < 0) {
120d4ef6694SJoris Giovannangeli WARN(0, "ioctl(%s)", dev);
121d4ef6694SJoris Giovannangeli goto fail;
122d4ef6694SJoris Giovannangeli }
123d4ef6694SJoris Giovannangeli signature = idargs.data[0];
124d4ef6694SJoris Giovannangeli error = ioctl(devfd, CPUCTL_RDMSR, &msrargs);
125d4ef6694SJoris Giovannangeli if (error < 0) {
126d4ef6694SJoris Giovannangeli WARN(0, "ioctl(%s)", dev);
127d4ef6694SJoris Giovannangeli goto fail;
128d4ef6694SJoris Giovannangeli }
129d4ef6694SJoris Giovannangeli
130d4ef6694SJoris Giovannangeli /*
131d4ef6694SJoris Giovannangeli * MSR_IA32_PLATFORM_ID contains flag in BCD in bits 52-50.
132d4ef6694SJoris Giovannangeli */
133d4ef6694SJoris Giovannangeli flags = 1 << ((msrargs.data >> 50) & 7);
134d4ef6694SJoris Giovannangeli msrargs.msr = MSR_BIOS_SIGN;
135d4ef6694SJoris Giovannangeli error = ioctl(devfd, CPUCTL_RDMSR, &msrargs);
136d4ef6694SJoris Giovannangeli if (error < 0) {
137d4ef6694SJoris Giovannangeli WARN(0, "ioctl(%s)", dev);
138d4ef6694SJoris Giovannangeli goto fail;
139d4ef6694SJoris Giovannangeli }
140d4ef6694SJoris Giovannangeli revision = msrargs.data >> 32; /* Revision in the high dword. */
141d4ef6694SJoris Giovannangeli WARNX(2, "found cpu type %#x family %#x model %#x stepping %#x.",
142d4ef6694SJoris Giovannangeli (signature >> 12) & 0x03, (signature >> 8) & 0x0f,
143d4ef6694SJoris Giovannangeli (signature >> 4) & 0x0f, (signature >> 0) & 0x0f);
144d4ef6694SJoris Giovannangeli /*
145d4ef6694SJoris Giovannangeli * Open firmware image.
146d4ef6694SJoris Giovannangeli */
147d4ef6694SJoris Giovannangeli fd = open(path, O_RDONLY, 0);
148d4ef6694SJoris Giovannangeli if (fd < 0) {
149d4ef6694SJoris Giovannangeli WARN(0, "open(%s)", path);
150*7ce1da6aSMatthew Dillon goto fail;
151d4ef6694SJoris Giovannangeli }
152d4ef6694SJoris Giovannangeli error = fstat(fd, &st);
153d4ef6694SJoris Giovannangeli if (error != 0) {
154d4ef6694SJoris Giovannangeli WARN(0, "fstat(%s)", path);
155d4ef6694SJoris Giovannangeli goto fail;
156d4ef6694SJoris Giovannangeli }
157d4ef6694SJoris Giovannangeli if (st.st_size < 0 || (unsigned)st.st_size < sizeof(*fw_header)) {
158d4ef6694SJoris Giovannangeli WARNX(2, "file too short: %s", path);
159d4ef6694SJoris Giovannangeli goto fail;
160d4ef6694SJoris Giovannangeli }
161d4ef6694SJoris Giovannangeli
162d4ef6694SJoris Giovannangeli /*
163d4ef6694SJoris Giovannangeli * mmap the whole image.
164d4ef6694SJoris Giovannangeli */
165d4ef6694SJoris Giovannangeli fw_image = (uint32_t *)mmap(NULL, st.st_size, PROT_READ,
166d4ef6694SJoris Giovannangeli MAP_PRIVATE, fd, 0);
167d4ef6694SJoris Giovannangeli if (fw_image == MAP_FAILED) {
168d4ef6694SJoris Giovannangeli WARN(0, "mmap(%s)", path);
169d4ef6694SJoris Giovannangeli goto fail;
170d4ef6694SJoris Giovannangeli }
171d4ef6694SJoris Giovannangeli fw_header = (intel_fw_header_t *)fw_image;
172d4ef6694SJoris Giovannangeli if (fw_header->header_version != INTEL_HEADER_VERSION ||
173d4ef6694SJoris Giovannangeli fw_header->loader_revision != INTEL_LOADER_REVISION) {
174d4ef6694SJoris Giovannangeli WARNX(2, "%s is not a valid intel firmware: version mismatch",
175d4ef6694SJoris Giovannangeli path);
176d4ef6694SJoris Giovannangeli goto fail;
177d4ef6694SJoris Giovannangeli }
178d4ef6694SJoris Giovannangeli /*
179d4ef6694SJoris Giovannangeli * According to spec, if data_size == 0, then size of ucode = 2000.
180d4ef6694SJoris Giovannangeli */
181d4ef6694SJoris Giovannangeli if (fw_header->data_size == 0)
182d4ef6694SJoris Giovannangeli data_size = DEFAULT_UCODE_SIZE;
183d4ef6694SJoris Giovannangeli else
184d4ef6694SJoris Giovannangeli data_size = fw_header->data_size;
185d4ef6694SJoris Giovannangeli if (fw_header->total_size == 0)
186d4ef6694SJoris Giovannangeli total_size = data_size + sizeof(*fw_header);
187d4ef6694SJoris Giovannangeli else
188d4ef6694SJoris Giovannangeli total_size = fw_header->total_size;
189d4ef6694SJoris Giovannangeli if (total_size > (unsigned)st.st_size || st.st_size < 0) {
190d4ef6694SJoris Giovannangeli WARNX(2, "file too short: %s", path);
191d4ef6694SJoris Giovannangeli goto fail;
192d4ef6694SJoris Giovannangeli }
193d4ef6694SJoris Giovannangeli payload_size = data_size + sizeof(*fw_header);
194d4ef6694SJoris Giovannangeli
195d4ef6694SJoris Giovannangeli /*
196d4ef6694SJoris Giovannangeli * Check the primary checksum.
197d4ef6694SJoris Giovannangeli */
198d4ef6694SJoris Giovannangeli sum = 0;
199d4ef6694SJoris Giovannangeli for (i = 0; i < (payload_size / sizeof(uint32_t)); i++)
200d4ef6694SJoris Giovannangeli sum += *((uint32_t *)fw_image + i);
201d4ef6694SJoris Giovannangeli if (sum != 0) {
202d4ef6694SJoris Giovannangeli WARNX(2, "%s: update data checksum invalid", path);
203d4ef6694SJoris Giovannangeli goto fail;
204d4ef6694SJoris Giovannangeli }
205d4ef6694SJoris Giovannangeli
206d4ef6694SJoris Giovannangeli /*
207d4ef6694SJoris Giovannangeli * Check if there is an extended signature table.
208d4ef6694SJoris Giovannangeli */
209d4ef6694SJoris Giovannangeli ext_size = total_size - payload_size;
210d4ef6694SJoris Giovannangeli have_ext_table = 0;
211d4ef6694SJoris Giovannangeli
212d4ef6694SJoris Giovannangeli if (ext_size > (signed)sizeof(*ext_header)) {
213d4ef6694SJoris Giovannangeli ext_header =
214d4ef6694SJoris Giovannangeli (intel_ext_header_t *)((char *)fw_image + payload_size);
215d4ef6694SJoris Giovannangeli ext_table = (intel_cpu_signature_t *)(ext_header + 1);
216d4ef6694SJoris Giovannangeli
217d4ef6694SJoris Giovannangeli /*
218d4ef6694SJoris Giovannangeli * Check the extended table size.
219d4ef6694SJoris Giovannangeli */
220d4ef6694SJoris Giovannangeli ext_table_size = sizeof(*ext_header) +
221d4ef6694SJoris Giovannangeli ext_header->sig_count * sizeof(*ext_table);
222d4ef6694SJoris Giovannangeli if (ext_table_size + payload_size > total_size) {
223d4ef6694SJoris Giovannangeli WARNX(2, "%s: broken extended signature table", path);
224d4ef6694SJoris Giovannangeli goto no_table;
225d4ef6694SJoris Giovannangeli }
226d4ef6694SJoris Giovannangeli
227d4ef6694SJoris Giovannangeli /*
228d4ef6694SJoris Giovannangeli * Check the extended table signature.
229d4ef6694SJoris Giovannangeli */
230d4ef6694SJoris Giovannangeli sum = 0;
231d4ef6694SJoris Giovannangeli for (i = 0; i < (ext_table_size / sizeof(uint32_t)); i++)
232d4ef6694SJoris Giovannangeli sum += *((uint32_t *)ext_header + i);
233d4ef6694SJoris Giovannangeli if (sum != 0) {
234*7ce1da6aSMatthew Dillon WARNX(2,
235*7ce1da6aSMatthew Dillon "%s: extended signature table checksum invalid",
236d4ef6694SJoris Giovannangeli path);
237d4ef6694SJoris Giovannangeli goto no_table;
238d4ef6694SJoris Giovannangeli }
239d4ef6694SJoris Giovannangeli have_ext_table = 1;
240d4ef6694SJoris Giovannangeli }
241d4ef6694SJoris Giovannangeli
242d4ef6694SJoris Giovannangeli no_table:
243d4ef6694SJoris Giovannangeli fw_data = fw_header + 1; /* Pointer to the update data. */
244d4ef6694SJoris Giovannangeli
245d4ef6694SJoris Giovannangeli /*
246d4ef6694SJoris Giovannangeli * Check if the given image is ok for this cpu.
247d4ef6694SJoris Giovannangeli */
248d4ef6694SJoris Giovannangeli if (signature == fw_header->cpu_signature &&
249d4ef6694SJoris Giovannangeli (flags & fw_header->cpu_flags) != 0)
250d4ef6694SJoris Giovannangeli goto matched;
251d4ef6694SJoris Giovannangeli else if (have_ext_table != 0) {
252d4ef6694SJoris Giovannangeli for (i = 0; i < ext_header->sig_count; i++) {
253*7ce1da6aSMatthew Dillon sig = ext_table[i].cpu_signature;
254d4ef6694SJoris Giovannangeli if (signature == sig &&
255d4ef6694SJoris Giovannangeli (flags & ext_table[i].cpu_flags) != 0)
256d4ef6694SJoris Giovannangeli goto matched;
257d4ef6694SJoris Giovannangeli }
258d4ef6694SJoris Giovannangeli } else
259d4ef6694SJoris Giovannangeli goto fail;
260d4ef6694SJoris Giovannangeli
261d4ef6694SJoris Giovannangeli matched:
262d4ef6694SJoris Giovannangeli if (revision >= fw_header->revision) {
263d4ef6694SJoris Giovannangeli WARNX(1, "skipping %s of rev %#x: up to date",
264d4ef6694SJoris Giovannangeli path, fw_header->revision);
265*7ce1da6aSMatthew Dillon goto fail;
266d4ef6694SJoris Giovannangeli }
267d4ef6694SJoris Giovannangeli fprintf(stderr, "%s: updating cpu %s from rev %#x to rev %#x... ",
268d4ef6694SJoris Giovannangeli path, dev, revision, fw_header->revision);
269d4ef6694SJoris Giovannangeli args.data = fw_data;
270d4ef6694SJoris Giovannangeli args.size = data_size;
271d4ef6694SJoris Giovannangeli error = ioctl(devfd, CPUCTL_UPDATE, &args);
272d4ef6694SJoris Giovannangeli if (error < 0) {
273d4ef6694SJoris Giovannangeli error = errno;
274d4ef6694SJoris Giovannangeli fprintf(stderr, "failed.\n");
275d4ef6694SJoris Giovannangeli errno = error;
276d4ef6694SJoris Giovannangeli WARN(0, "ioctl()");
277d4ef6694SJoris Giovannangeli goto fail;
278d4ef6694SJoris Giovannangeli }
279d4ef6694SJoris Giovannangeli fprintf(stderr, "done.\n");
280d4ef6694SJoris Giovannangeli
281d4ef6694SJoris Giovannangeli fail:
282d4ef6694SJoris Giovannangeli if (fw_image != MAP_FAILED)
283d4ef6694SJoris Giovannangeli if (munmap(fw_image, st.st_size) != 0)
284d4ef6694SJoris Giovannangeli warn("munmap(%s)", path);
285d4ef6694SJoris Giovannangeli if (devfd >= 0)
286d4ef6694SJoris Giovannangeli close(devfd);
287d4ef6694SJoris Giovannangeli if (fd >= 0)
288d4ef6694SJoris Giovannangeli close(fd);
289d4ef6694SJoris Giovannangeli }
290