agp: fix arbitrary kernel memory writes
[linux-2.6/linux-acpi-2.6/ibm-acpi-2.6.git] / drivers / char / agp / sgi-agp.c
blob0d426ae39c850adaa86e379a764ee315767f992f
1 /*
2 * This file is subject to the terms and conditions of the GNU General Public
3 * License. See the file "COPYING" in the main directory of this archive
4 * for more details.
6 * Copyright (C) 2003-2005 Silicon Graphics, Inc. All Rights Reserved.
7 */
9 /*
10 * SGI TIOCA AGPGART routines.
14 #include <linux/acpi.h>
15 #include <linux/module.h>
16 #include <linux/pci.h>
17 #include <linux/init.h>
18 #include <linux/agp_backend.h>
19 #include <asm/sn/addrs.h>
20 #include <asm/sn/io.h>
21 #include <asm/sn/pcidev.h>
22 #include <asm/sn/pcibus_provider_defs.h>
23 #include <asm/sn/tioca_provider.h>
24 #include "agp.h"
26 extern int agp_memory_reserved;
27 extern uint32_t tioca_gart_found;
28 extern struct list_head tioca_list;
29 static struct agp_bridge_data **sgi_tioca_agp_bridges;
32 * The aperature size and related information is set up at TIOCA init time.
33 * Values for this table will be extracted and filled in at
34 * sgi_tioca_fetch_size() time.
37 static struct aper_size_info_fixed sgi_tioca_sizes[] = {
38 {0, 0, 0},
41 static struct page *sgi_tioca_alloc_page(struct agp_bridge_data *bridge)
43 struct page *page;
44 int nid;
45 struct tioca_kernel *info =
46 (struct tioca_kernel *)bridge->dev_private_data;
48 nid = info->ca_closest_node;
49 page = alloc_pages_node(nid, GFP_KERNEL, 0);
50 if (!page)
51 return NULL;
53 get_page(page);
54 atomic_inc(&agp_bridge->current_memory_agp);
55 return page;
59 * Flush GART tlb's. Cannot selectively flush based on memory so the mem
60 * arg is ignored.
63 static void sgi_tioca_tlbflush(struct agp_memory *mem)
65 tioca_tlbflush(mem->bridge->dev_private_data);
69 * Given an address of a host physical page, turn it into a valid gart
70 * entry.
72 static unsigned long
73 sgi_tioca_mask_memory(struct agp_bridge_data *bridge, dma_addr_t addr,
74 int type)
76 return tioca_physpage_to_gart(addr);
79 static void sgi_tioca_agp_enable(struct agp_bridge_data *bridge, u32 mode)
81 tioca_fastwrite_enable(bridge->dev_private_data);
85 * sgi_tioca_configure() doesn't have anything to do since the base CA driver
86 * has alreay set up the GART.
89 static int sgi_tioca_configure(void)
91 return 0;
95 * Determine gfx aperature size. This has already been determined by the
96 * CA driver init, so just need to set agp_bridge values accordingly.
99 static int sgi_tioca_fetch_size(void)
101 struct tioca_kernel *info =
102 (struct tioca_kernel *)agp_bridge->dev_private_data;
104 sgi_tioca_sizes[0].size = info->ca_gfxap_size / MB(1);
105 sgi_tioca_sizes[0].num_entries = info->ca_gfxgart_entries;
107 return sgi_tioca_sizes[0].size;
110 static int sgi_tioca_create_gatt_table(struct agp_bridge_data *bridge)
112 struct tioca_kernel *info =
113 (struct tioca_kernel *)bridge->dev_private_data;
115 bridge->gatt_table_real = (u32 *) info->ca_gfxgart;
116 bridge->gatt_table = bridge->gatt_table_real;
117 bridge->gatt_bus_addr = info->ca_gfxgart_base;
119 return 0;
122 static int sgi_tioca_free_gatt_table(struct agp_bridge_data *bridge)
124 return 0;
127 static int sgi_tioca_insert_memory(struct agp_memory *mem, off_t pg_start,
128 int type)
130 int num_entries;
131 size_t i;
132 off_t j;
133 void *temp;
134 struct agp_bridge_data *bridge;
135 u64 *table;
137 bridge = mem->bridge;
138 if (!bridge)
139 return -EINVAL;
141 table = (u64 *)bridge->gatt_table;
143 temp = bridge->current_size;
145 switch (bridge->driver->size_type) {
146 case U8_APER_SIZE:
147 num_entries = A_SIZE_8(temp)->num_entries;
148 break;
149 case U16_APER_SIZE:
150 num_entries = A_SIZE_16(temp)->num_entries;
151 break;
152 case U32_APER_SIZE:
153 num_entries = A_SIZE_32(temp)->num_entries;
154 break;
155 case FIXED_APER_SIZE:
156 num_entries = A_SIZE_FIX(temp)->num_entries;
157 break;
158 case LVL2_APER_SIZE:
159 return -EINVAL;
160 break;
161 default:
162 num_entries = 0;
163 break;
166 num_entries -= agp_memory_reserved / PAGE_SIZE;
167 if (num_entries < 0)
168 num_entries = 0;
170 if (type != 0 || mem->type != 0) {
171 return -EINVAL;
174 if ((pg_start + mem->page_count) > num_entries)
175 return -EINVAL;
177 j = pg_start;
179 while (j < (pg_start + mem->page_count)) {
180 if (table[j])
181 return -EBUSY;
182 j++;
185 if (!mem->is_flushed) {
186 bridge->driver->cache_flush();
187 mem->is_flushed = true;
190 for (i = 0, j = pg_start; i < mem->page_count; i++, j++) {
191 table[j] =
192 bridge->driver->mask_memory(bridge,
193 page_to_phys(mem->pages[i]),
194 mem->type);
197 bridge->driver->tlb_flush(mem);
198 return 0;
201 static int sgi_tioca_remove_memory(struct agp_memory *mem, off_t pg_start,
202 int type)
204 size_t i;
205 struct agp_bridge_data *bridge;
206 u64 *table;
208 bridge = mem->bridge;
209 if (!bridge)
210 return -EINVAL;
212 if (type != 0 || mem->type != 0) {
213 return -EINVAL;
216 table = (u64 *)bridge->gatt_table;
218 for (i = pg_start; i < (mem->page_count + pg_start); i++) {
219 table[i] = 0;
222 bridge->driver->tlb_flush(mem);
223 return 0;
226 static void sgi_tioca_cache_flush(void)
231 * Cleanup. Nothing to do as the CA driver owns the GART.
234 static void sgi_tioca_cleanup(void)
238 static struct agp_bridge_data *sgi_tioca_find_bridge(struct pci_dev *pdev)
240 struct agp_bridge_data *bridge;
242 list_for_each_entry(bridge, &agp_bridges, list) {
243 if (bridge->dev->bus == pdev->bus)
244 break;
246 return bridge;
249 const struct agp_bridge_driver sgi_tioca_driver = {
250 .owner = THIS_MODULE,
251 .size_type = U16_APER_SIZE,
252 .configure = sgi_tioca_configure,
253 .fetch_size = sgi_tioca_fetch_size,
254 .cleanup = sgi_tioca_cleanup,
255 .tlb_flush = sgi_tioca_tlbflush,
256 .mask_memory = sgi_tioca_mask_memory,
257 .agp_enable = sgi_tioca_agp_enable,
258 .cache_flush = sgi_tioca_cache_flush,
259 .create_gatt_table = sgi_tioca_create_gatt_table,
260 .free_gatt_table = sgi_tioca_free_gatt_table,
261 .insert_memory = sgi_tioca_insert_memory,
262 .remove_memory = sgi_tioca_remove_memory,
263 .alloc_by_type = agp_generic_alloc_by_type,
264 .free_by_type = agp_generic_free_by_type,
265 .agp_alloc_page = sgi_tioca_alloc_page,
266 .agp_destroy_page = agp_generic_destroy_page,
267 .agp_type_to_mask_type = agp_generic_type_to_mask_type,
268 .cant_use_aperture = true,
269 .needs_scratch_page = false,
270 .num_aperture_sizes = 1,
273 static int __devinit agp_sgi_init(void)
275 unsigned int j;
276 struct tioca_kernel *info;
277 struct pci_dev *pdev = NULL;
279 if (tioca_gart_found)
280 printk(KERN_INFO PFX "SGI TIO CA GART driver initialized.\n");
281 else
282 return 0;
284 sgi_tioca_agp_bridges = kmalloc(tioca_gart_found *
285 sizeof(struct agp_bridge_data *),
286 GFP_KERNEL);
287 if (!sgi_tioca_agp_bridges)
288 return -ENOMEM;
290 j = 0;
291 list_for_each_entry(info, &tioca_list, ca_list) {
292 struct list_head *tmp;
293 if (list_empty(info->ca_devices))
294 continue;
295 list_for_each(tmp, info->ca_devices) {
296 u8 cap_ptr;
297 pdev = pci_dev_b(tmp);
298 if (pdev->class != (PCI_CLASS_DISPLAY_VGA << 8))
299 continue;
300 cap_ptr = pci_find_capability(pdev, PCI_CAP_ID_AGP);
301 if (!cap_ptr)
302 continue;
304 sgi_tioca_agp_bridges[j] = agp_alloc_bridge();
305 printk(KERN_INFO PFX "bridge %d = 0x%p\n", j,
306 sgi_tioca_agp_bridges[j]);
307 if (sgi_tioca_agp_bridges[j]) {
308 sgi_tioca_agp_bridges[j]->dev = pdev;
309 sgi_tioca_agp_bridges[j]->dev_private_data = info;
310 sgi_tioca_agp_bridges[j]->driver = &sgi_tioca_driver;
311 sgi_tioca_agp_bridges[j]->gart_bus_addr =
312 info->ca_gfxap_base;
313 sgi_tioca_agp_bridges[j]->mode = (0x7D << 24) | /* 126 requests */
314 (0x1 << 9) | /* SBA supported */
315 (0x1 << 5) | /* 64-bit addresses supported */
316 (0x1 << 4) | /* FW supported */
317 (0x1 << 3) | /* AGP 3.0 mode */
318 0x2; /* 8x transfer only */
319 sgi_tioca_agp_bridges[j]->current_size =
320 sgi_tioca_agp_bridges[j]->previous_size =
321 (void *)&sgi_tioca_sizes[0];
322 agp_add_bridge(sgi_tioca_agp_bridges[j]);
324 j++;
327 agp_find_bridge = &sgi_tioca_find_bridge;
328 return 0;
331 static void __devexit agp_sgi_cleanup(void)
333 kfree(sgi_tioca_agp_bridges);
334 sgi_tioca_agp_bridges = NULL;
337 module_init(agp_sgi_init);
338 module_exit(agp_sgi_cleanup);
340 MODULE_LICENSE("GPL and additional rights");