blob: f9c57035c2ca12e879abf02ed35b282f41ae59f0 [file] [log] [blame]
Cyril Bur1aa096a2015-10-28 15:24:52 +11001/* Copyright 2015 IBM
2 *
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at
6 *
7 * http://www.apache.org/licenses/LICENSE-2.0
8 *
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
14 */
15
16#include <errno.h>
17#include <stdint.h>
18#include <stdio.h>
19#include <stdlib.h>
20#include <string.h>
21#include <fcntl.h>
22#include <unistd.h>
23#include <sys/stat.h>
24#include <sys/mman.h>
25#include <sys/timerfd.h>
26#include <syslog.h>
27#include <poll.h>
28#include <limits.h>
29#include <getopt.h>
30#include <time.h>
31#include <assert.h>
32
33#include <linux/bt-host.h>
34
35#include <systemd/sd-bus.h>
36
37#define PREFIX "[BTBRIDGED] "
38
39#define BT_HOST_PATH "/dev/bt-host"
40#define BT_HOST_TIMEOUT_SEC 1
41#define BT_MAX_MESSAGE 64
42
43#define DBUS_NAME "org.openbmc.HostIpmi"
44#define OBJ_NAME "/org/openbmc/HostIpmi/1"
45
46#define SD_BUS_FD 0
47#define BT_FD 1
48#define TIMER_FD 2
49#define TOTAL_FDS 3
50
51#define MSG_OUT(f_, ...) do { if (verbose) { printf(PREFIX); printf((f_), ##__VA_ARGS__); } } while(0)
52#define MSG_ERR(f_, ...) do { \
53 if (verbose) { \
54 fprintf(stderr, PREFIX); \
55 fprintf(stderr, (f_), ##__VA_ARGS__); \
56 } \
57 } while(0)
58
59struct ipmi_msg {
60 uint8_t netfn;
61 uint8_t lun;
62 uint8_t seq;
63 uint8_t cmd;
64 uint8_t cc; /* Only used on responses */
65 uint8_t *data;
66 size_t data_len;
67};
68
69struct bt_queue {
70 struct ipmi_msg req;
71 struct ipmi_msg rsp;
72 struct timespec start;
73 int expired;
74 sd_bus_message *call;
75 struct bt_queue *next;
76};
77
78struct btbridged_context{
79 int debug;
80 uint8_t last_seq;
81 int started;
82 struct pollfd fds[TOTAL_FDS];
83 struct sd_bus *bus;
84 struct bt_queue *bt_q;
85};
86
87static int running = 1;
88static int verbose;
89
90static struct bt_queue *bt_q_get_head(struct btbridged_context *context)
91{
92 return context ? context->bt_q : NULL;
93}
94
95static struct bt_queue *bt_q_get_seq(struct btbridged_context *context, uint8_t seq)
96{
97 struct bt_queue *t;
98
99 assert(context);
100
101 t = context->bt_q;
102
103 while (t && t->req.seq != seq)
104 t = t->next;
105
106 return t;
107}
108
109static struct bt_queue *bt_q_get_msg(struct btbridged_context *context)
110{
111 struct bt_queue *t;
112
113 assert(context);
114
115 t = context->bt_q;
116
117 while (t && (!t->call && !t->expired))
118 t = t->next;
119
120 return t;
121}
122
123static struct bt_queue *bt_q_enqueue(struct btbridged_context *context, uint8_t *bt_data)
124{
125 struct bt_queue *n;
126 struct bt_queue *bt_q;
127 int len;
128
129 assert(context && bt_data);
130
131 /*
132 * len here is the length of the array.
133 * Helpfully BT doesn't count the length byte
134 */
135 len = bt_data[0] + 1;
136 if (len < 4) {
137 MSG_ERR("Trying to queue a BT message with a short length (%d)\n", len);
138 return NULL;
139 }
140
141 bt_q = context->bt_q;
142
143 n = calloc(1, sizeof(struct bt_queue));
144 if (!n)
145 return NULL;
146
147 if (context->debug) {
148 n->req.data = malloc(len - 4);
149 if (n->req.data)
150 n->req.data = memcpy(n->req.data, bt_data + 4, len - 4);
151 }
152 n->req.data_len = len - 4;
153 /* Don't count the lenfn/ln, seq and command */
154 n->req.netfn = bt_data[1] >> 2;
155 n->req.lun = bt_data[1] & 0x3;
156 n->req.seq = bt_data[2];
157 n->req.cmd = bt_data[3];
158 if (clock_gettime(CLOCK_MONOTONIC, &n->start) == -1) {
159 MSG_ERR("Couldn't clock_gettime(): %s\n", strerror(errno));
160 free(n);
161 return NULL;
162 }
163 if (!bt_q) {
164 context->bt_q = n;
165 } else {
166 struct bt_queue *t = bt_q;
167
168 while (t->next)
169 t = t->next;
170
171 t->next = n;
172 }
173
174 return n;
175}
176
177static void bt_q_free(struct bt_queue *bt_q)
178{
179 if (!bt_q)
180 return;
181
182 /* Unrefing sd_bus_message should free(rsp.data) */
183 if (bt_q->call)
184 sd_bus_message_unref(bt_q->call);
185
186 free(bt_q->req.data);
187 free(bt_q);
188}
189
190static struct bt_queue *bt_q_drop(struct btbridged_context *context, struct bt_queue *element)
191{
192 struct bt_queue *r;
193 struct bt_queue *bt_q;
194
195 assert(context);
196
197 bt_q = context->bt_q;
198 if (!element || !bt_q)
199 return NULL;
200
201
202 r = bt_q;
203 if (r == bt_q) {
204 context->bt_q = bt_q->next;
205 } else {
206 while (r && r->next != element)
207 r = r->next;
208
209 if (!r) {
210 MSG_ERR("Didn't find element %p in queue\n", element);
211 bt_q_free(element);
212 return NULL;
213 }
214 r->next = r->next->next;
215 }
216 bt_q_free(element);
217
218 return context->bt_q;
219}
220
221static struct bt_queue *bt_q_dequeue(struct btbridged_context *context)
222{
223 struct bt_queue *r;
224 struct bt_queue *bt_q;
225
226 assert(context);
227
228 bt_q = context->bt_q;
229 if (!bt_q) {
230 MSG_ERR("Dequeuing empty queue!\n");
231 return NULL;
232 }
233
234 r = bt_q->next;
235 bt_q_free(bt_q);
236 context->bt_q = r;
237
238 return r;
239}
240
241static int method_send_sms_atn(sd_bus_message *msg, void *userdata, sd_bus_error *ret_error)
242{
243 int r, bt_fd = *(int *)userdata;
244 MSG_OUT("Sending SMS_ATN ioctl() to %s\n", BT_HOST_PATH);
245 r = ioctl(bt_fd, BT_HOST_IOCTL_SMS_ATN);
246 if (r == -1) {
247 r = errno;
248 MSG_ERR("Couldn't ioctl() to %s: %s\n", BT_HOST_PATH, strerror(r));
249 return sd_bus_reply_method_errno(msg, errno, ret_error);
250 }
251
252 r = 0;
253 return sd_bus_reply_method_return(msg, "x", r);
254}
255
256static int method_send_message(sd_bus_message *msg, void *userdata, sd_bus_error *ret_error)
257{
258 struct btbridged_context *context;
259 struct bt_queue *bt_msg;
260 uint8_t *data, *all_data;
261 size_t data_sz, all_data_sz;
262 uint8_t netfn, lun, seq, cmd, cc;
263 uint64_t cookie;
264 /*
265 * Doesn't say it anywhere explicitly but it looks like returning 0 or
266 * negative is BAD...
267 */
268 int r = 1;
269
270 context = (struct btbridged_context *)userdata;
271 if (!context) {
272 sd_bus_error_set_const(ret_error, "org.openbmc.error", "Internal error");
273 r = 0;
274 goto out;
275 }
276 r = sd_bus_message_read(msg, "yyyyy", &netfn, &lun, &seq, &cmd, &cc);
277 if (r < 0) {
278 MSG_ERR("Couldn't parse leading bytes of message: %s\n", strerror(-r));
279 sd_bus_error_set_const(ret_error, "org.openbmc.error", "Bad message");
280 r = -EINVAL;
281 goto out;
282 }
283 r = sd_bus_message_read_array(msg, 'y', (const void **)&data, &data_sz);
284 if (r < 0) {
285 MSG_ERR("Couldn't parse data bytes of message: %s\n", strerror(-r));
286 sd_bus_error_set_const(ret_error, "org.openbmc.error", "Bad message data");
287 r = -EINVAL;
288 goto out;
289 }
290
291 bt_msg = bt_q_get_seq(context, seq);
292 if (!bt_msg) {
293 sd_bus_error_set_const(ret_error, "org.openbmc.error", "No matching request");
294 MSG_ERR("Failed to find matching request for dbus method with seq: 0x%02x\n", seq);
295 r = -EINVAL;
296 goto out;
297 }
298 MSG_OUT("Recieved a dbus response for msg with seq 0x%02x\n", seq);
299 bt_msg->call = sd_bus_message_ref(msg);
300 bt_msg->rsp.netfn = netfn;
301 bt_msg->rsp.lun = lun;
302 bt_msg->rsp.seq = seq;
303 bt_msg->rsp.cmd = cmd;
304 bt_msg->rsp.cc = cc;
305 bt_msg->rsp.data_len = data_sz;
306 /* Because we've ref'ed the msg, I hope we don't need to memcpy data */
307 bt_msg->rsp.data = data;
308
309 /* Now that we have a response */
310 context->fds[BT_FD].events |= POLLOUT;
311
312out:
313 return r;
314}
315
316static int bt_host_write(struct btbridged_context *context, struct bt_queue *bt_msg)
317{
318 struct bt_queue *head;
319 uint8_t data[BT_MAX_MESSAGE] = { 0 };
320 sd_bus_message *msg = NULL;
321 int r, len;
322
323 assert(context);
324
325 if (!bt_msg)
326 return -EINVAL;
327
328 head = bt_q_get_head(context);
329 if (bt_msg == head) {
330 struct itimerspec ts;
331 /* Need to adjust the timer */
332 ts.it_interval.tv_sec = 0;
333 ts.it_interval.tv_nsec = 0;
334 if (head->next) {
335 ts.it_value = head->next->start;
336 ts.it_value.tv_sec += BT_HOST_TIMEOUT_SEC;
337 MSG_OUT("Adjusting timer for next element\n");
338 } else {
339 ts.it_value.tv_nsec = 0;
340 ts.it_value.tv_sec = 0;
341 MSG_OUT("Disabling timer, no elements remain in queue\n");
342 }
343 r = timerfd_settime(context->fds[TIMER_FD].fd, TFD_TIMER_ABSTIME, &ts, NULL);
344 if (r == -1)
345 MSG_ERR("Couldn't set timerfd\n");
346 }
347 data[1] = (bt_msg->rsp.netfn << 2) | (bt_msg->rsp.lun & 0x3);
348 data[2] = bt_msg->rsp.seq;
349 data[3] = bt_msg->rsp.cmd;
350 data[4] = bt_msg->rsp.cc;
351 if (bt_msg->rsp.data_len > sizeof(data) - 5) {
352 MSG_ERR("Response message size (%d) too big, truncating\n", bt_msg->rsp.data_len);
353 bt_msg->rsp.data_len = sizeof(data) - 5;
354 }
355 /* netfn/len + seq + cmd + cc = 4 */
356 data[0] = bt_msg->rsp.data_len + 4;
357 if (bt_msg->rsp.data_len)
358 memcpy(data + 5, bt_msg->rsp.data, bt_msg->rsp.data_len);
359 /* Count the data[0] byte */
360 len = write(context->fds[BT_FD].fd, data, data[0] + 1);
361 if (r == -1) {
362 r = errno;
363 MSG_ERR("Error writing to %s: %s\n", BT_HOST_PATH, strerror(errno));
364 if (bt_msg->call) {
365 r = sd_bus_message_new_method_errno(bt_msg->call, &msg, r, NULL);
366 if (r < 0)
367 MSG_ERR("Couldn't create response error\n");
368 }
369 goto out;
370 } else {
371 if (len != data[0] + 1)
372 MSG_ERR("Possible short write to %s, desired len: %d, written len: %d\n", BT_HOST_PATH, data[0] + 1, len);
373 else
374 MSG_OUT("Successfully wrote %d of %d bytes to %s\n", len, data[0] + 1, BT_HOST_PATH);
375
376 if (bt_msg->call) {
377 r = sd_bus_message_new_method_return(bt_msg->call, &msg);
378 if (r < 0) {
379 MSG_ERR("Couldn't create response message\n");
380 goto out;
381 }
382 r = 0; /* Just to be explicit about what we're sending back */
383 r = sd_bus_message_append(msg, "x", r);
384 if (r < 0) {
385 MSG_ERR("Couldn't append result to response\n");
386 goto out;
387 }
388
389 }
390 }
391
392out:
393 if (bt_msg->call) {
394 if (sd_bus_send(context->bus, msg, NULL) < 0)
395 MSG_ERR("Couldn't send response message\n");
396 sd_bus_message_unref(msg);
397 }
398 bt_q_drop(context, bt_msg);
399
400 /*
401 * There isn't another message ready to be sent so turn off POLLOUT
402 */
403 if (!bt_q_get_msg(context)) {
404 MSG_OUT("Turning off POLLOUT for the BT in poll()\n");
405 context->fds[BT_FD].events = POLLIN;
406 }
407
408 return r;
409}
410
411static int dispatch_timer(struct btbridged_context *context)
412{
413 int r = 0;
414 if (context->fds[TIMER_FD].revents & POLLIN) {
415 sd_bus_message *msg;
416 struct bt_queue *head;
417
418 head = bt_q_get_head(context);
419 if (!head) {
420 /* Odd, timer expired but we didn't have a message to timeout */
421 MSG_ERR("No message found to send timeout\n");
422 return 0;
423 }
424 if (head->call) {
425 r = sd_bus_message_new_method_errno(head->call, &msg, ETIMEDOUT, NULL);
426 if (r < 0) {
427 MSG_ERR("Couldn't create response error\n");
428 } else {
429 if (sd_bus_send(context->bus, msg, NULL) < 0)
430 MSG_ERR("Couldn't send response message\n");
431 sd_bus_message_unref(msg);
432 }
433 MSG_ERR("Message with seq 0x%02x is being timed out despite "
434 "appearing to have been responded to. Slow BT?\n", head->rsp.seq);
435 }
436
437 /* Set expiry */
438 head->expired = 1;
439 head->rsp.seq = head->req.seq;
440 head->rsp.netfn = head->req.netfn + 1;
441 head->rsp.lun = head->req.lun;
442 head->rsp.cc = 0xce; /* Command response could not be provided */
443 head->rsp.cmd = head->req.cmd;
444 /* These should already be zeroed but best to be sure */
445 head->rsp.data_len = 0;
446 head->rsp.data = NULL;
447 head->call = NULL;
448 MSG_OUT("Timeout on msg with seq: 0x%02x\n", head->rsp.seq);
449 /* Turn on POLLOUT so we'll write this one next */
450 context->fds[BT_FD].events |= POLLOUT;
451 }
452
453 return 0;
454}
455
456static int dispatch_sd_bus(struct btbridged_context *context)
457{
458 int r = 0;
459 if (context->fds[SD_BUS_FD].revents) {
460 r = sd_bus_process(context->bus, NULL);
461 if (r > 0)
462 MSG_OUT("Processed %d dbus events\n", r);
463 }
464
465 return r;
466}
467
468static int dispatch_bt(struct btbridged_context *context)
469{
470 int err = 0;
471 int r;
472
473 assert(context);
474
475 if (context->fds[BT_FD].revents & POLLIN) {
476 int data_len;
477 struct bt_queue *new;
478 uint8_t data[BT_MAX_MESSAGE] = { 0 };
479
480 r = read(context->fds[BT_FD].fd, data, sizeof(data));
481 if (r < 0) {
482 MSG_ERR("Couldn't read from bt: %s\n", strerror(-r));
483 goto out1;
484 }
485 if (r < data[0] + 1) {
486 MSG_ERR("Short read from bt (%d)\n", r);
487 r = -EINVAL;
488 goto out1;
489 }
490
491 /*
492 * If the host sent us a retry, the seq number will not have
493 * incremented. Drop the message otherwise we might send duplicate
494 * responses.
495 * This should deal with when last_seq is 0xff with overflow back
496 * to zero.
497 */
498 if (data[2] != context->last_seq + 1 && context->started) {
499 MSG_ERR("Received a retry from the host, dropping seq 0x%02x vs 0x%02x\n", data[2], context->last_seq);
500 r = 0;
501 goto out1;
502 }
503 context->started = 1;
504 context->last_seq = data[2];
505
506 new = bt_q_enqueue(context, data);
507 if (!new) {
508 r = -ENOMEM;
509 goto out1;
510 }
511 if (new == bt_q_get_head(context)) {
512 struct itimerspec ts;
513 /*
514 * Enqueued onto an empty list, setup a timer for sending a
515 * timeout
516 */
517 ts.it_interval.tv_sec = 0;
518 ts.it_interval.tv_nsec = 0;
519 ts.it_value.tv_nsec = 0;
520 ts.it_value.tv_sec = BT_HOST_TIMEOUT_SEC;
521 r = timerfd_settime(context->fds[TIMER_FD].fd, 0, &ts, NULL);
522 if (r == -1)
523 MSG_ERR("Couldn't set timerfd\n");
524 }
525
526 MSG_OUT("Sending dbus signal with netfn 0x%02x, lun 0x%02x, seq 0x%02x, cmd 0x%02x\n",
527 new->req.netfn, new->req.lun, new->req.seq, new->req.cmd);
528 /* Note we only actually keep the request data in the queue when debugging */
529 r = sd_bus_emit_signal(context->bus, OBJ_NAME, DBUS_NAME, "receivedMessage", "yyyyay",
530 new->req.netfn, new->req.lun, new->req.seq, new->req.cmd,
531 new->req.data_len, data+4);
532 if (r < 0) {
533 MSG_ERR("Couldn't emit dbus signal: %s\n", strerror(-r));
534 goto out1;
535 }
536 r = 0;
537out1:
538 err = r;
539 }
540
541 if (context->fds[BT_FD].revents & POLLOUT) {
542 struct bt_queue *bt_msg;
543 bt_msg = bt_q_get_msg(context);
544 if (!bt_msg) {
545 /* Odd, this shouldn't really happen */
546 MSG_ERR("Got a POLLOUT on %s but no message is ready to be written\n");
547 r = 0;
548 goto out;
549 }
550 r = bt_host_write(context, bt_msg);
551 if (r < 0)
552 MSG_ERR("Problem putting request with netfn 0x%02x, lun 0x%02x, seq 0x%02x, cmd 0x%02x, cc 0x%02x\n"
553 "out to %s", BT_HOST_PATH, bt_msg->rsp.netfn, bt_msg->rsp.lun, bt_msg->rsp.seq,
554 bt_msg->rsp.cmd, bt_msg->rsp.cc);
555 else
556 MSG_OUT("Completed request with netfn 0x%02x, lun 0x%02x, seq 0x%02x, cmd 0x%02x, cc 0x%02x\n",
557 bt_msg->rsp.netfn, bt_msg->rsp.lun, bt_msg->rsp.seq, bt_msg->rsp.cmd, bt_msg->rsp.cc);
558 }
559out:
560 return err ? err : r;
561}
562
563static void usage(const char *name)
564{
565 fprintf(stderr, "Usage %s\n", name);
566 fprintf(stderr, "\t--verbose\t Be verbose\n\n");
567}
568
569static const sd_bus_vtable ipmid_vtable[] = {
570 SD_BUS_VTABLE_START(0),
571 SD_BUS_METHOD("sendMessage", "yyyyyay", "x", &method_send_message, SD_BUS_VTABLE_UNPRIVILEGED),
572 SD_BUS_METHOD("setAttention", "", "x", &method_send_sms_atn, SD_BUS_VTABLE_UNPRIVILEGED),
573 SD_BUS_SIGNAL("receivedMessage", "yyyyay", 0),
574 SD_BUS_VTABLE_END
575};
576
577int main(int argc, char *argv[]) {
578 struct btbridged_context context;
579 struct bt_queue *bt_q;
580 const char *path;
581 const char *name = argv[0];
582 int opt, polled, r, daemonise;
583 uint8_t buf[BT_MAX_MESSAGE];
584
585 static struct option long_options[] = {
586 {"verbose", no_argument, &verbose, 1},
587 {0, 0, 0, 0}
588 };
589
590 context.started = 0;
591 context.debug = 0;
592 context.bt_q = NULL;
593
594 while ((opt = getopt_long(argc, argv, "", long_options, NULL)) != -1) {
595 switch (opt) {
596 case 0:
597 MSG_OUT("Found verbosity flag\n");
598 break;
599 default:
600 usage(name);
601 exit(EXIT_FAILURE);
602 }
603 }
604
605 MSG_OUT("Starting\n");
606 r = sd_bus_default_system(&context.bus);
607 if (r < 0) {
608 MSG_ERR("Failed to connect to system bus: %s\n", strerror(-r));
609 goto finish;
610 }
611
612 MSG_OUT("Registering dbus methods/signals\n");
613 r = sd_bus_add_object_vtable(context.bus,
614 NULL,
615 OBJ_NAME,
616 DBUS_NAME,
617 ipmid_vtable,
618 &context);
619 if (r < 0) {
620 MSG_ERR("Failed to issue method call: %s\n", strerror(-r));
621 goto finish;
622 }
623
624 MSG_OUT("Requesting dbus name: %s\n", DBUS_NAME);
625 r = sd_bus_request_name(context.bus, DBUS_NAME, SD_BUS_NAME_ALLOW_REPLACEMENT|SD_BUS_NAME_REPLACE_EXISTING);
626 if (r < 0) {
627 MSG_ERR("Failed to acquire service name: %s\n", strerror(-r));
628 goto finish;
629 }
630
631 MSG_OUT("Getting dbus file descriptors\n");
632 context.fds[SD_BUS_FD].fd = sd_bus_get_fd(context.bus);
633 if (context.fds[SD_BUS_FD].fd < 0) {
634 r = -errno;
635 MSG_OUT("Couldn't get the bus file descriptor: %s\n", strerror(errno));
636 goto finish;
637 }
638
639 MSG_OUT("Opening %s\n", BT_HOST_PATH);
640 context.fds[BT_FD].fd = open(BT_HOST_PATH, O_RDWR | O_NONBLOCK);
641 if (context.fds[BT_FD].fd < 0) {
642 r = -errno;
643 MSG_ERR("Couldn't open %s with flags O_RDWR: %s\n", BT_HOST_PATH, strerror(errno));
644 goto finish;
645 }
646
647 MSG_OUT("Creating timer fd\n");
648 context.fds[TIMER_FD].fd = timerfd_create(CLOCK_MONOTONIC, 0);
649 if (context.fds[TIMER_FD].fd < 0) {
650 r = -errno;
651 MSG_ERR("Couldn't create timer fd: %s\n", strerror(errno));
652 goto finish;
653 }
654 context.fds[SD_BUS_FD].events = POLLIN;
655 context.fds[BT_FD].events = POLLIN;
656 context.fds[TIMER_FD].events = POLLIN;
657
658 MSG_OUT("Entering polling loop\n");
659
660 while (running) {
661 polled = poll(context.fds, TOTAL_FDS, 1000);
662 if (polled == 0)
663 continue;
664 if (polled < 0) {
665 r = -errno;
666 MSG_ERR("Error from poll(): %s\n", strerror(errno));
667 goto finish;
668 }
669 r = dispatch_sd_bus(&context);
670 if (r < 0) {
671 MSG_ERR("Error handling dbus event: %s\n", strerror(-r));
672 goto finish;
673 }
674 r = dispatch_bt(&context);
675 if (r < 0) {
676 MSG_ERR("Error handling BT event: %s\n", strerror(-r));
677 goto finish;
678 }
679 r = dispatch_timer(&context);
680 if (r < 0) {
681 MSG_ERR("Error handling timer event: %s\n", strerror(-r));
682 goto finish;
683 }
684 }
685
686finish:
687 if (bt_q_get_head(&context)) {
688 MSG_ERR("Unresponded BT Message!\n");
689 while (bt_q_dequeue(&context));
690 }
691 close(context.fds[BT_FD].fd);
692 close(context.fds[TIMER_FD].fd);
693 sd_bus_unref(context.bus);
694
695 return r;
696}
697