Home | History | Annotate | Line # | Download | only in acpi
acpi_ec.c revision 1.102
      1 /*	$NetBSD: acpi_ec.c,v 1.102 2023/07/18 10:06:22 riastradh Exp $	*/
      2 
      3 /*-
      4  * Copyright (c) 2007 Joerg Sonnenberger <joerg (at) NetBSD.org>.
      5  * All rights reserved.
      6  *
      7  * Redistribution and use in source and binary forms, with or without
      8  * modification, are permitted provided that the following conditions
      9  * are met:
     10  *
     11  * 1. Redistributions of source code must retain the above copyright
     12  *    notice, this list of conditions and the following disclaimer.
     13  * 2. Redistributions in binary form must reproduce the above copyright
     14  *    notice, this list of conditions and the following disclaimer in
     15  *    the documentation and/or other materials provided with the
     16  *    distribution.
     17  *
     18  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
     19  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
     20  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
     21  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE
     22  * COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
     23  * INCIDENTAL, SPECIAL, EXEMPLARY OR CONSEQUENTIAL DAMAGES (INCLUDING,
     24  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
     25  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
     26  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
     27  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
     28  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     29  * SUCH DAMAGE.
     30  */
     31 
     32 /*
     33  * The ACPI Embedded Controller (EC) driver serves two different purposes:
     34  * - read and write access from ASL, e.g. to read battery state
     35  * - notification of ASL of System Control Interrupts.
     36  *
     37  * Lock order:
     38  *	sc_access_mtx (serializes EC transactions -- read, write, or SCI)
     39  *	-> ACPI global lock (excludes other ACPI access during EC transaction)
     40  *	-> sc_mtx (serializes state machine transitions and waits)
     41  *
     42  * SCIs are processed in a kernel thread.
     43  *
     44  * Read and write requests spin around for a short time as many requests
     45  * can be handled instantly by the EC.  During normal processing interrupt
     46  * mode is used exclusively.  At boot and resume time interrupts are not
     47  * working and the handlers just busy loop.
     48  *
     49  * A callout is scheduled to compensate for missing interrupts on some
     50  * hardware.  If the EC doesn't process a request for 5s, it is most likely
     51  * in a wedged state.  No method to reset the EC is currently known.
     52  *
     53  * Special care has to be taken to not poll the EC in a busy loop without
     54  * delay.  This can prevent processing of Power Button events. At least some
     55  * Lenovo Thinkpads seem to be implement the Power Button Override in the EC
     56  * and the only option to recover on those models is to cut off all power.
     57  */
     58 
     59 #include <sys/cdefs.h>
     60 __KERNEL_RCSID(0, "$NetBSD: acpi_ec.c,v 1.102 2023/07/18 10:06:22 riastradh Exp $");
     61 
     62 #ifdef _KERNEL_OPT
     63 #include "opt_acpi_ec.h"
     64 #endif
     65 
     66 #include <sys/param.h>
     67 #include <sys/callout.h>
     68 #include <sys/condvar.h>
     69 #include <sys/device.h>
     70 #include <sys/kernel.h>
     71 #include <sys/kthread.h>
     72 #include <sys/mutex.h>
     73 #include <sys/systm.h>
     74 
     75 #include <dev/acpi/acpireg.h>
     76 #include <dev/acpi/acpivar.h>
     77 #include <dev/acpi/acpi_ecvar.h>
     78 
     79 #define _COMPONENT          ACPI_EC_COMPONENT
     80 ACPI_MODULE_NAME            ("acpi_ec")
     81 
     82 /* Maximum time to wait for global ACPI lock in ms */
     83 #define	EC_LOCK_TIMEOUT		5
     84 
     85 /* Maximum time to poll for completion of a command  in ms */
     86 #define	EC_POLL_TIMEOUT		5
     87 
     88 /* Maximum time to give a single EC command in s */
     89 #define EC_CMD_TIMEOUT		10
     90 
     91 /* From ACPI 3.0b, chapter 12.3 */
     92 #define EC_COMMAND_READ		0x80
     93 #define	EC_COMMAND_WRITE	0x81
     94 #define	EC_COMMAND_BURST_EN	0x82
     95 #define	EC_COMMAND_BURST_DIS	0x83
     96 #define	EC_COMMAND_QUERY	0x84
     97 
     98 /* From ACPI 3.0b, chapter 12.2.1 */
     99 #define	EC_STATUS_OBF		0x01
    100 #define	EC_STATUS_IBF		0x02
    101 #define	EC_STATUS_CMD		0x08
    102 #define	EC_STATUS_BURST		0x10
    103 #define	EC_STATUS_SCI		0x20
    104 #define	EC_STATUS_SMI		0x40
    105 
    106 #define	EC_STATUS_FMT							      \
    107 	"\x10\10IGN7\7SMI\6SCI\5BURST\4CMD\3IGN2\2IBF\1OBF"
    108 
    109 static const struct device_compatible_entry compat_data[] = {
    110 	{ .compat = "PNP0C09" },
    111 	DEVICE_COMPAT_EOL
    112 };
    113 
    114 #define	EC_STATE_ENUM(F)						      \
    115 	F(EC_STATE_QUERY, "QUERY")					      \
    116 	F(EC_STATE_QUERY_VAL, "QUERY_VAL")				      \
    117 	F(EC_STATE_READ, "READ")					      \
    118 	F(EC_STATE_READ_ADDR, "READ_ADDR")				      \
    119 	F(EC_STATE_READ_VAL, "READ_VAL")				      \
    120 	F(EC_STATE_WRITE, "WRITE")					      \
    121 	F(EC_STATE_WRITE_ADDR, "WRITE_ADDR")				      \
    122 	F(EC_STATE_WRITE_VAL, "WRITE_VAL")				      \
    123 	F(EC_STATE_FREE, "FREE")					      \
    124 
    125 enum ec_state_t {
    126 #define	F(N, S)	N,
    127 	EC_STATE_ENUM(F)
    128 #undef F
    129 };
    130 
    131 #ifdef ACPIEC_DEBUG
    132 static const char *const acpiec_state_names[] = {
    133 #define F(N, S)	[N] = S,
    134 	EC_STATE_ENUM(F)
    135 #undef F
    136 };
    137 #endif
    138 
    139 struct acpiec_softc {
    140 	device_t sc_dev;
    141 
    142 	ACPI_HANDLE sc_ech;
    143 
    144 	ACPI_HANDLE sc_gpeh;
    145 	uint8_t sc_gpebit;
    146 
    147 	bus_space_tag_t sc_data_st;
    148 	bus_space_handle_t sc_data_sh;
    149 
    150 	bus_space_tag_t sc_csr_st;
    151 	bus_space_handle_t sc_csr_sh;
    152 
    153 	bool sc_need_global_lock;
    154 	uint32_t sc_global_lock;
    155 
    156 	kmutex_t sc_mtx, sc_access_mtx;
    157 	kcondvar_t sc_cv, sc_cv_sci;
    158 	enum ec_state_t sc_state;
    159 	bool sc_got_sci;
    160 	callout_t sc_pseudo_intr;
    161 
    162 	uint8_t sc_cur_addr, sc_cur_val;
    163 };
    164 
    165 #ifdef ACPIEC_DEBUG
    166 
    167 #define	ACPIEC_DEBUG_ENUM(F)						      \
    168 	F(ACPIEC_DEBUG_REG, "REG")					      \
    169 	F(ACPIEC_DEBUG_RW, "RW")					      \
    170 	F(ACPIEC_DEBUG_QUERY, "QUERY")					      \
    171 	F(ACPIEC_DEBUG_TRANSITION, "TRANSITION")			      \
    172 	F(ACPIEC_DEBUG_INTR, "INTR")					      \
    173 
    174 enum {
    175 #define	F(N, S)	N,
    176 	ACPIEC_DEBUG_ENUM(F)
    177 #undef F
    178 };
    179 
    180 static const char *const acpiec_debug_names[] = {
    181 #define	F(N, S)	[N] = S,
    182 	ACPIEC_DEBUG_ENUM(F)
    183 #undef F
    184 };
    185 
    186 int acpiec_debug = ACPIEC_DEBUG;
    187 
    188 #define	DPRINTF(n, sc, fmt, ...) do					      \
    189 {									      \
    190 	if (acpiec_debug & __BIT(n)) {					      \
    191 		char dprintbuf[16];					      \
    192 		const char *state;					      \
    193 									      \
    194 		/* paranoia */						      \
    195 		if ((sc)->sc_state < __arraycount(acpiec_state_names)) {      \
    196 			state = acpiec_state_names[(sc)->sc_state];	      \
    197 		} else {						      \
    198 			snprintf(dprintbuf, sizeof(dprintbuf), "0x%x",	      \
    199 			    (sc)->sc_state);				      \
    200 			state = dprintbuf;				      \
    201 		}							      \
    202 									      \
    203 		device_printf((sc)->sc_dev, "(%s) [%s] "fmt,		      \
    204 		    acpiec_debug_names[n], state, ##__VA_ARGS__);	      \
    205 	}								      \
    206 } while (0)
    207 
    208 #else
    209 
    210 #define	DPRINTF(n, sc, fmt, ...)	__nothing
    211 
    212 #endif
    213 
    214 static int acpiecdt_match(device_t, cfdata_t, void *);
    215 static void acpiecdt_attach(device_t, device_t, void *);
    216 
    217 static int acpiec_match(device_t, cfdata_t, void *);
    218 static void acpiec_attach(device_t, device_t, void *);
    219 
    220 static void acpiec_common_attach(device_t, device_t, ACPI_HANDLE,
    221     bus_space_tag_t, bus_addr_t, bus_space_tag_t, bus_addr_t,
    222     ACPI_HANDLE, uint8_t);
    223 
    224 static bool acpiec_suspend(device_t, const pmf_qual_t *);
    225 static bool acpiec_resume(device_t, const pmf_qual_t *);
    226 static bool acpiec_shutdown(device_t, int);
    227 
    228 static bool acpiec_parse_gpe_package(device_t, ACPI_HANDLE,
    229     ACPI_HANDLE *, uint8_t *);
    230 
    231 static void acpiec_callout(void *);
    232 static void acpiec_gpe_query(void *);
    233 static uint32_t acpiec_gpe_handler(ACPI_HANDLE, uint32_t, void *);
    234 static ACPI_STATUS acpiec_space_setup(ACPI_HANDLE, uint32_t, void *, void **);
    235 static ACPI_STATUS acpiec_space_handler(uint32_t, ACPI_PHYSICAL_ADDRESS,
    236     uint32_t, ACPI_INTEGER *, void *, void *);
    237 
    238 static void acpiec_gpe_state_machine(struct acpiec_softc *);
    239 
    240 CFATTACH_DECL_NEW(acpiec, sizeof(struct acpiec_softc),
    241     acpiec_match, acpiec_attach, NULL, NULL);
    242 
    243 CFATTACH_DECL_NEW(acpiecdt, sizeof(struct acpiec_softc),
    244     acpiecdt_match, acpiecdt_attach, NULL, NULL);
    245 
    246 static device_t ec_singleton = NULL;
    247 static bool acpiec_cold = false;
    248 
    249 static bool
    250 acpiecdt_find(device_t parent, ACPI_HANDLE *ec_handle,
    251     bus_addr_t *cmd_reg, bus_addr_t *data_reg, uint8_t *gpebit)
    252 {
    253 	ACPI_TABLE_ECDT *ecdt;
    254 	ACPI_STATUS rv;
    255 
    256 	rv = AcpiGetTable(ACPI_SIG_ECDT, 1, (ACPI_TABLE_HEADER **)&ecdt);
    257 	if (ACPI_FAILURE(rv))
    258 		return false;
    259 
    260 	if (ecdt->Control.BitWidth != 8 || ecdt->Data.BitWidth != 8) {
    261 		aprint_error_dev(parent,
    262 		    "ECDT register width invalid (%u/%u)\n",
    263 		    ecdt->Control.BitWidth, ecdt->Data.BitWidth);
    264 		return false;
    265 	}
    266 
    267 	rv = AcpiGetHandle(ACPI_ROOT_OBJECT, ecdt->Id, ec_handle);
    268 	if (ACPI_FAILURE(rv)) {
    269 		aprint_error_dev(parent,
    270 		    "failed to look up EC object %s: %s\n",
    271 		    ecdt->Id, AcpiFormatException(rv));
    272 		return false;
    273 	}
    274 
    275 	*cmd_reg = ecdt->Control.Address;
    276 	*data_reg = ecdt->Data.Address;
    277 	*gpebit = ecdt->Gpe;
    278 
    279 	return true;
    280 }
    281 
    282 static int
    283 acpiecdt_match(device_t parent, cfdata_t match, void *aux)
    284 {
    285 	ACPI_HANDLE ec_handle;
    286 	bus_addr_t cmd_reg, data_reg;
    287 	uint8_t gpebit;
    288 
    289 	if (acpiecdt_find(parent, &ec_handle, &cmd_reg, &data_reg, &gpebit))
    290 		return 1;
    291 	else
    292 		return 0;
    293 }
    294 
    295 static void
    296 acpiecdt_attach(device_t parent, device_t self, void *aux)
    297 {
    298 	struct acpibus_attach_args *aa = aux;
    299 	ACPI_HANDLE ec_handle;
    300 	bus_addr_t cmd_reg, data_reg;
    301 	uint8_t gpebit;
    302 
    303 	if (!acpiecdt_find(parent, &ec_handle, &cmd_reg, &data_reg, &gpebit))
    304 		panic("ECDT disappeared");
    305 
    306 	aprint_naive("\n");
    307 	aprint_normal(": ACPI Embedded Controller via ECDT\n");
    308 
    309 	acpiec_common_attach(parent, self, ec_handle, aa->aa_iot, cmd_reg,
    310 	    aa->aa_iot, data_reg, NULL, gpebit);
    311 }
    312 
    313 static int
    314 acpiec_match(device_t parent, cfdata_t match, void *aux)
    315 {
    316 	struct acpi_attach_args *aa = aux;
    317 
    318 	return acpi_compatible_match(aa, compat_data);
    319 }
    320 
    321 static void
    322 acpiec_attach(device_t parent, device_t self, void *aux)
    323 {
    324 	struct acpi_attach_args *aa = aux;
    325 	struct acpi_resources ec_res;
    326 	struct acpi_io *io0, *io1;
    327 	ACPI_HANDLE gpe_handle;
    328 	uint8_t gpebit;
    329 	ACPI_STATUS rv;
    330 
    331 	if (ec_singleton != NULL) {
    332 		aprint_naive(": using %s\n", device_xname(ec_singleton));
    333 		aprint_normal(": using %s\n", device_xname(ec_singleton));
    334 		goto fail0;
    335 	}
    336 
    337 	if (!acpi_device_present(aa->aa_node->ad_handle)) {
    338 		aprint_normal(": not present\n");
    339 		goto fail0;
    340 	}
    341 
    342 	if (!acpiec_parse_gpe_package(self, aa->aa_node->ad_handle,
    343 				      &gpe_handle, &gpebit))
    344 		goto fail0;
    345 
    346 	rv = acpi_resource_parse(self, aa->aa_node->ad_handle, "_CRS",
    347 	    &ec_res, &acpi_resource_parse_ops_default);
    348 	if (rv != AE_OK) {
    349 		aprint_error_dev(self, "resource parsing failed: %s\n",
    350 		    AcpiFormatException(rv));
    351 		goto fail0;
    352 	}
    353 
    354 	if ((io0 = acpi_res_io(&ec_res, 0)) == NULL) {
    355 		aprint_error_dev(self, "no data register resource\n");
    356 		goto fail1;
    357 	}
    358 	if ((io1 = acpi_res_io(&ec_res, 1)) == NULL) {
    359 		aprint_error_dev(self, "no CSR register resource\n");
    360 		goto fail1;
    361 	}
    362 
    363 	acpiec_common_attach(parent, self, aa->aa_node->ad_handle,
    364 	    aa->aa_iot, io1->ar_base, aa->aa_iot, io0->ar_base,
    365 	    gpe_handle, gpebit);
    366 
    367 	acpi_resource_cleanup(&ec_res);
    368 	return;
    369 
    370 fail1:	acpi_resource_cleanup(&ec_res);
    371 fail0:	if (!pmf_device_register(self, NULL, NULL))
    372 		aprint_error_dev(self, "couldn't establish power handler\n");
    373 }
    374 
    375 static void
    376 acpiec_common_attach(device_t parent, device_t self,
    377     ACPI_HANDLE ec_handle, bus_space_tag_t cmdt, bus_addr_t cmd_reg,
    378     bus_space_tag_t datat, bus_addr_t data_reg,
    379     ACPI_HANDLE gpe_handle, uint8_t gpebit)
    380 {
    381 	struct acpiec_softc *sc = device_private(self);
    382 	ACPI_STATUS rv;
    383 	ACPI_INTEGER val;
    384 
    385 	sc->sc_dev = self;
    386 
    387 	sc->sc_csr_st = cmdt;
    388 	sc->sc_data_st = datat;
    389 
    390 	sc->sc_ech = ec_handle;
    391 	sc->sc_gpeh = gpe_handle;
    392 	sc->sc_gpebit = gpebit;
    393 
    394 	sc->sc_state = EC_STATE_FREE;
    395 	mutex_init(&sc->sc_mtx, MUTEX_DRIVER, IPL_TTY);
    396 	mutex_init(&sc->sc_access_mtx, MUTEX_DEFAULT, IPL_NONE);
    397 	cv_init(&sc->sc_cv, "eccv");
    398 	cv_init(&sc->sc_cv_sci, "ecsci");
    399 
    400 	if (bus_space_map(sc->sc_data_st, data_reg, 1, 0,
    401 	    &sc->sc_data_sh) != 0) {
    402 		aprint_error_dev(self, "unable to map data register\n");
    403 		return;
    404 	}
    405 
    406 	if (bus_space_map(sc->sc_csr_st, cmd_reg, 1, 0, &sc->sc_csr_sh) != 0) {
    407 		aprint_error_dev(self, "unable to map CSR register\n");
    408 		goto post_data_map;
    409 	}
    410 
    411 	rv = acpi_eval_integer(sc->sc_ech, "_GLK", &val);
    412 	if (rv == AE_OK) {
    413 		sc->sc_need_global_lock = val != 0;
    414 	} else if (rv != AE_NOT_FOUND) {
    415 		aprint_error_dev(self, "unable to evaluate _GLK: %s\n",
    416 		    AcpiFormatException(rv));
    417 		goto post_csr_map;
    418 	} else {
    419 		sc->sc_need_global_lock = false;
    420 	}
    421 	if (sc->sc_need_global_lock)
    422 		aprint_normal_dev(self, "using global ACPI lock\n");
    423 
    424 	callout_init(&sc->sc_pseudo_intr, CALLOUT_MPSAFE);
    425 	callout_setfunc(&sc->sc_pseudo_intr, acpiec_callout, sc);
    426 
    427 	rv = AcpiInstallAddressSpaceHandler(sc->sc_ech, ACPI_ADR_SPACE_EC,
    428 	    acpiec_space_handler, acpiec_space_setup, self);
    429 	if (rv != AE_OK) {
    430 		aprint_error_dev(self,
    431 		    "unable to install address space handler: %s\n",
    432 		    AcpiFormatException(rv));
    433 		goto post_csr_map;
    434 	}
    435 
    436 	rv = AcpiInstallGpeHandler(sc->sc_gpeh, sc->sc_gpebit,
    437 	    ACPI_GPE_EDGE_TRIGGERED, acpiec_gpe_handler, sc);
    438 	if (rv != AE_OK) {
    439 		aprint_error_dev(self, "unable to install GPE handler: %s\n",
    440 		    AcpiFormatException(rv));
    441 		goto post_csr_map;
    442 	}
    443 
    444 	rv = AcpiEnableGpe(sc->sc_gpeh, sc->sc_gpebit);
    445 	if (rv != AE_OK) {
    446 		aprint_error_dev(self, "unable to enable GPE: %s\n",
    447 		    AcpiFormatException(rv));
    448 		goto post_csr_map;
    449 	}
    450 
    451 	if (kthread_create(PRI_NONE, KTHREAD_MPSAFE, NULL, acpiec_gpe_query,
    452 		           self, NULL, "acpiec sci thread")) {
    453 		aprint_error_dev(self, "unable to create query kthread\n");
    454 		goto post_csr_map;
    455 	}
    456 
    457 	ec_singleton = self;
    458 
    459 	if (!pmf_device_register1(self, acpiec_suspend, acpiec_resume,
    460 	    acpiec_shutdown))
    461 		aprint_error_dev(self, "couldn't establish power handler\n");
    462 
    463 	return;
    464 
    465 post_csr_map:
    466 	(void)AcpiRemoveGpeHandler(sc->sc_gpeh, sc->sc_gpebit,
    467 	    acpiec_gpe_handler);
    468 	(void)AcpiRemoveAddressSpaceHandler(sc->sc_ech,
    469 	    ACPI_ADR_SPACE_EC, acpiec_space_handler);
    470 	bus_space_unmap(sc->sc_csr_st, sc->sc_csr_sh, 1);
    471 post_data_map:
    472 	bus_space_unmap(sc->sc_data_st, sc->sc_data_sh, 1);
    473 	if (!pmf_device_register(self, NULL, NULL))
    474 		aprint_error_dev(self, "couldn't establish power handler\n");
    475 }
    476 
    477 static bool
    478 acpiec_suspend(device_t dv, const pmf_qual_t *qual)
    479 {
    480 
    481 	acpiec_cold = true;
    482 
    483 	return true;
    484 }
    485 
    486 static bool
    487 acpiec_resume(device_t dv, const pmf_qual_t *qual)
    488 {
    489 
    490 	acpiec_cold = false;
    491 
    492 	return true;
    493 }
    494 
    495 static bool
    496 acpiec_shutdown(device_t dv, int how)
    497 {
    498 
    499 	acpiec_cold = true;
    500 	return true;
    501 }
    502 
    503 static bool
    504 acpiec_parse_gpe_package(device_t self, ACPI_HANDLE ec_handle,
    505     ACPI_HANDLE *gpe_handle, uint8_t *gpebit)
    506 {
    507 	ACPI_BUFFER buf;
    508 	ACPI_OBJECT *p, *c;
    509 	ACPI_STATUS rv;
    510 
    511 	rv = acpi_eval_struct(ec_handle, "_GPE", &buf);
    512 	if (rv != AE_OK) {
    513 		aprint_error_dev(self, "unable to evaluate _GPE: %s\n",
    514 		    AcpiFormatException(rv));
    515 		return false;
    516 	}
    517 
    518 	p = buf.Pointer;
    519 
    520 	if (p->Type == ACPI_TYPE_INTEGER) {
    521 		*gpe_handle = NULL;
    522 		*gpebit = p->Integer.Value;
    523 		ACPI_FREE(p);
    524 		return true;
    525 	}
    526 
    527 	if (p->Type != ACPI_TYPE_PACKAGE) {
    528 		aprint_error_dev(self, "_GPE is neither integer nor package\n");
    529 		ACPI_FREE(p);
    530 		return false;
    531 	}
    532 
    533 	if (p->Package.Count != 2) {
    534 		aprint_error_dev(self,
    535 		    "_GPE package does not contain 2 elements\n");
    536 		ACPI_FREE(p);
    537 		return false;
    538 	}
    539 
    540 	c = &p->Package.Elements[0];
    541 	rv = acpi_eval_reference_handle(c, gpe_handle);
    542 
    543 	if (ACPI_FAILURE(rv)) {
    544 		aprint_error_dev(self, "failed to evaluate _GPE handle\n");
    545 		ACPI_FREE(p);
    546 		return false;
    547 	}
    548 
    549 	c = &p->Package.Elements[1];
    550 
    551 	if (c->Type != ACPI_TYPE_INTEGER) {
    552 		aprint_error_dev(self,
    553 		    "_GPE package needs integer as 2nd field\n");
    554 		ACPI_FREE(p);
    555 		return false;
    556 	}
    557 	*gpebit = c->Integer.Value;
    558 	ACPI_FREE(p);
    559 	return true;
    560 }
    561 
    562 static uint8_t
    563 acpiec_read_data(struct acpiec_softc *sc)
    564 {
    565 	uint8_t x;
    566 
    567 	KASSERT(mutex_owned(&sc->sc_mtx));
    568 
    569 	x = bus_space_read_1(sc->sc_data_st, sc->sc_data_sh, 0);
    570 	DPRINTF(ACPIEC_DEBUG_REG, sc, "read data=0x%"PRIx8"\n", x);
    571 
    572 	return x;
    573 }
    574 
    575 static void
    576 acpiec_write_data(struct acpiec_softc *sc, uint8_t val)
    577 {
    578 
    579 	KASSERT(mutex_owned(&sc->sc_mtx));
    580 
    581 	DPRINTF(ACPIEC_DEBUG_REG, sc, "write data=0x%"PRIx8"\n", val);
    582 	bus_space_write_1(sc->sc_data_st, sc->sc_data_sh, 0, val);
    583 }
    584 
    585 static uint8_t
    586 acpiec_read_status(struct acpiec_softc *sc)
    587 {
    588 	uint8_t x;
    589 
    590 	KASSERT(mutex_owned(&sc->sc_mtx));
    591 
    592 	x = bus_space_read_1(sc->sc_csr_st, sc->sc_csr_sh, 0);
    593 	DPRINTF(ACPIEC_DEBUG_REG, sc, "read status=0x%"PRIx8"\n", x);
    594 
    595 	return x;
    596 }
    597 
    598 static void
    599 acpiec_write_command(struct acpiec_softc *sc, uint8_t cmd)
    600 {
    601 
    602 	KASSERT(mutex_owned(&sc->sc_mtx));
    603 
    604 	DPRINTF(ACPIEC_DEBUG_REG, sc, "write command=0x%"PRIx8"\n", cmd);
    605 	bus_space_write_1(sc->sc_csr_st, sc->sc_csr_sh, 0, cmd);
    606 }
    607 
    608 static ACPI_STATUS
    609 acpiec_space_setup(ACPI_HANDLE region, uint32_t func, void *arg,
    610     void **region_arg)
    611 {
    612 
    613 	if (func == ACPI_REGION_DEACTIVATE)
    614 		*region_arg = NULL;
    615 	else
    616 		*region_arg = arg;
    617 
    618 	return AE_OK;
    619 }
    620 
    621 static void
    622 acpiec_lock(struct acpiec_softc *sc)
    623 {
    624 	ACPI_STATUS rv;
    625 
    626 	mutex_enter(&sc->sc_access_mtx);
    627 
    628 	if (sc->sc_need_global_lock) {
    629 		rv = AcpiAcquireGlobalLock(EC_LOCK_TIMEOUT,
    630 		    &sc->sc_global_lock);
    631 		if (rv != AE_OK) {
    632 			aprint_error_dev(sc->sc_dev,
    633 			    "failed to acquire global lock: %s\n",
    634 			    AcpiFormatException(rv));
    635 			return;
    636 		}
    637 	}
    638 }
    639 
    640 static void
    641 acpiec_unlock(struct acpiec_softc *sc)
    642 {
    643 	ACPI_STATUS rv;
    644 
    645 	if (sc->sc_need_global_lock) {
    646 		rv = AcpiReleaseGlobalLock(sc->sc_global_lock);
    647 		if (rv != AE_OK) {
    648 			aprint_error_dev(sc->sc_dev,
    649 			    "failed to release global lock: %s\n",
    650 			    AcpiFormatException(rv));
    651 		}
    652 	}
    653 	mutex_exit(&sc->sc_access_mtx);
    654 }
    655 
    656 static ACPI_STATUS
    657 acpiec_wait_timeout(struct acpiec_softc *sc)
    658 {
    659 	device_t dv = sc->sc_dev;
    660 	int i;
    661 
    662 	for (i = 0; i < EC_POLL_TIMEOUT; ++i) {
    663 		acpiec_gpe_state_machine(sc);
    664 		if (sc->sc_state == EC_STATE_FREE)
    665 			return AE_OK;
    666 		delay(1);
    667 	}
    668 
    669 	if (cold || acpiec_cold) {
    670 		int timeo = 1000 * EC_CMD_TIMEOUT;
    671 
    672 		while (sc->sc_state != EC_STATE_FREE && timeo-- > 0) {
    673 			delay(1000);
    674 			acpiec_gpe_state_machine(sc);
    675 		}
    676 		if (sc->sc_state != EC_STATE_FREE) {
    677 			aprint_error_dev(dv, "command timed out, state %d\n",
    678 			    sc->sc_state);
    679 			return AE_ERROR;
    680 		}
    681 	} else {
    682 		const unsigned deadline = getticks() + EC_CMD_TIMEOUT*hz;
    683 		unsigned delta;
    684 
    685 		while (sc->sc_state != EC_STATE_FREE &&
    686 		    (delta = deadline - getticks()) < INT_MAX)
    687 			(void)cv_timedwait(&sc->sc_cv, &sc->sc_mtx, delta);
    688 		if (sc->sc_state != EC_STATE_FREE) {
    689 			aprint_error_dev(dv,
    690 			    "command takes over %d sec...\n",
    691 			    EC_CMD_TIMEOUT);
    692 			return AE_ERROR;
    693 		}
    694 	}
    695 
    696 	return AE_OK;
    697 }
    698 
    699 static ACPI_STATUS
    700 acpiec_read(device_t dv, uint8_t addr, uint8_t *val)
    701 {
    702 	struct acpiec_softc *sc = device_private(dv);
    703 	ACPI_STATUS rv;
    704 
    705 	acpiec_lock(sc);
    706 	mutex_enter(&sc->sc_mtx);
    707 
    708 	DPRINTF(ACPIEC_DEBUG_RW, sc,
    709 	    "pid %ld %s, lid %ld%s%s: read addr 0x%"PRIx8"\n",
    710 	    (long)curproc->p_pid, curproc->p_comm,
    711 	    (long)curlwp->l_lid, curlwp->l_name ? " " : "",
    712 	    curlwp->l_name ? curlwp->l_name : "",
    713 	    addr);
    714 
    715 	KASSERT(sc->sc_state == EC_STATE_FREE);
    716 
    717 	sc->sc_cur_addr = addr;
    718 	sc->sc_state = EC_STATE_READ;
    719 
    720 	rv = acpiec_wait_timeout(sc);
    721 	if (ACPI_FAILURE(rv))
    722 		goto out;
    723 
    724 	DPRINTF(ACPIEC_DEBUG_RW, sc,
    725 	    "pid %ld %s, lid %ld%s%s: read addr 0x%"PRIx8": 0x%"PRIx8"\n",
    726 	    (long)curproc->p_pid, curproc->p_comm,
    727 	    (long)curlwp->l_lid, curlwp->l_name ? " " : "",
    728 	    curlwp->l_name ? curlwp->l_name : "",
    729 	    addr, sc->sc_cur_val);
    730 
    731 	*val = sc->sc_cur_val;
    732 
    733 out:	mutex_exit(&sc->sc_mtx);
    734 	acpiec_unlock(sc);
    735 	return rv;
    736 }
    737 
    738 static ACPI_STATUS
    739 acpiec_write(device_t dv, uint8_t addr, uint8_t val)
    740 {
    741 	struct acpiec_softc *sc = device_private(dv);
    742 	ACPI_STATUS rv;
    743 
    744 	acpiec_lock(sc);
    745 	mutex_enter(&sc->sc_mtx);
    746 
    747 	DPRINTF(ACPIEC_DEBUG_RW, sc,
    748 	    "pid %ld %s, lid %ld%s%s write addr 0x%"PRIx8": 0x%"PRIx8"\n",
    749 	    (long)curproc->p_pid, curproc->p_comm,
    750 	    (long)curlwp->l_lid, curlwp->l_name ? " " : "",
    751 	    curlwp->l_name ? curlwp->l_name : "",
    752 	    addr, val);
    753 
    754 	KASSERT(sc->sc_state == EC_STATE_FREE);
    755 
    756 	sc->sc_cur_addr = addr;
    757 	sc->sc_cur_val = val;
    758 	sc->sc_state = EC_STATE_WRITE;
    759 
    760 	rv = acpiec_wait_timeout(sc);
    761 	if (ACPI_FAILURE(rv))
    762 		goto out;
    763 
    764 	DPRINTF(ACPIEC_DEBUG_RW, sc,
    765 	    "pid %ld %s, lid %ld%s%s: write addr 0x%"PRIx8": 0x%"PRIx8
    766 	    " done\n",
    767 	    (long)curproc->p_pid, curproc->p_comm,
    768 	    (long)curlwp->l_lid, curlwp->l_name ? " " : "",
    769 	    curlwp->l_name ? curlwp->l_name : "",
    770 	    addr, val);
    771 
    772 out:	mutex_exit(&sc->sc_mtx);
    773 	acpiec_unlock(sc);
    774 	return rv;
    775 }
    776 
    777 /*
    778  * acpiec_space_handler(func, paddr, bitwidth, value, arg, region_arg)
    779  *
    780  *	Transfer bitwidth/8 bytes of data between paddr and *value:
    781  *	from paddr to *value when func is ACPI_READ, and the other way
    782  *	when func is ACPI_WRITE.  arg is the acpiec(4) or acpiecdt(4)
    783  *	device.  region_arg is ignored (XXX why? determined by
    784  *	acpiec_space_setup but never used by anything that I can see).
    785  *
    786  *	The caller always provides storage at *value large enough for
    787  *	an ACPI_INTEGER object, i.e., a 64-bit integer.  However,
    788  *	bitwidth may be larger; in this case the caller provides larger
    789  *	storage at *value, e.g. 128 bits as documented in
    790  *	<https://gnats.netbsd.org/55206>.
    791  *
    792  *	On reads, this fully initializes one ACPI_INTEGER's worth of
    793  *	data at *value, even if bitwidth < 64.  The integer is
    794  *	interpreted in host byte order; in other words, bytes of data
    795  *	are transferred in order between paddr and (uint8_t *)value.
    796  *	The transfer is not atomic; it may go byte-by-byte.
    797  *
    798  *	XXX This only really makes sense on little-endian systems.
    799  *	E.g., thinkpad_acpi.c assumes that a single byte is transferred
    800  *	in the low-order bits of the result.  A big-endian system could
    801  *	read a 64-bit integer in big-endian (and it did for a while!),
    802  *	but what should it do for larger reads?  Unclear!
    803  *
    804  *	XXX It's not clear whether the object at *value is always
    805  *	_aligned_ adequately for an ACPI_INTEGER object.  Currently it
    806  *	always is as long as malloc, used by AcpiOsAllocate, returns
    807  *	64-bit-aligned data.
    808  */
    809 static ACPI_STATUS
    810 acpiec_space_handler(uint32_t func, ACPI_PHYSICAL_ADDRESS paddr,
    811     uint32_t width, ACPI_INTEGER *value, void *arg, void *region_arg)
    812 {
    813 	device_t dv;
    814 	ACPI_STATUS rv;
    815 	uint8_t addr, *buf;
    816 	unsigned int i;
    817 
    818 	if (paddr > 0xff || width % 8 != 0 ||
    819 	    value == NULL || arg == NULL || paddr + width / 8 > 0x100)
    820 		return AE_BAD_PARAMETER;
    821 
    822 	addr = paddr;
    823 	dv = arg;
    824 	buf = (uint8_t *)value;
    825 
    826 	rv = AE_OK;
    827 
    828 	switch (func) {
    829 	case ACPI_READ:
    830 		for (i = 0; i < width; i += 8, ++addr, ++buf) {
    831 			rv = acpiec_read(dv, addr, buf);
    832 			if (rv != AE_OK)
    833 				break;
    834 		}
    835 		/*
    836 		 * Make sure to fully initialize at least an
    837 		 * ACPI_INTEGER-sized object.
    838 		 */
    839 		for (; i < sizeof(*value)*8; i += 8, ++buf)
    840 			*buf = 0;
    841 		break;
    842 	case ACPI_WRITE:
    843 		for (i = 0; i < width; i += 8, ++addr, ++buf) {
    844 			rv = acpiec_write(dv, addr, *buf);
    845 			if (rv != AE_OK)
    846 				break;
    847 		}
    848 		break;
    849 	default:
    850 		aprint_error("%s: invalid Address Space function called: %x\n",
    851 		    device_xname(dv), (unsigned int)func);
    852 		return AE_BAD_PARAMETER;
    853 	}
    854 
    855 	return rv;
    856 }
    857 
    858 static void
    859 acpiec_wait(struct acpiec_softc *sc)
    860 {
    861 	int i;
    862 
    863 	/*
    864 	 * First, attempt to get the query by polling.
    865 	 */
    866 	for (i = 0; i < EC_POLL_TIMEOUT; ++i) {
    867 		acpiec_gpe_state_machine(sc);
    868 		if (sc->sc_state == EC_STATE_FREE)
    869 			return;
    870 		delay(1);
    871 	}
    872 
    873 	/*
    874 	 * Polling timed out.  Try waiting for interrupts -- either GPE
    875 	 * interrupts, or periodic callouts in case GPE interrupts are
    876 	 * broken.
    877 	 */
    878 	DPRINTF(ACPIEC_DEBUG_QUERY, sc, "SCI polling timeout\n");
    879 	while (sc->sc_state != EC_STATE_FREE)
    880 		cv_wait(&sc->sc_cv, &sc->sc_mtx);
    881 }
    882 
    883 static void
    884 acpiec_gpe_query(void *arg)
    885 {
    886 	device_t dv = arg;
    887 	struct acpiec_softc *sc = device_private(dv);
    888 	uint8_t reg;
    889 	char qxx[5];
    890 	ACPI_STATUS rv;
    891 
    892 loop:
    893 	/*
    894 	 * Wait until the EC sends an SCI requesting a query.
    895 	 */
    896 	mutex_enter(&sc->sc_mtx);
    897 	while (!sc->sc_got_sci)
    898 		cv_wait(&sc->sc_cv_sci, &sc->sc_mtx);
    899 	DPRINTF(ACPIEC_DEBUG_QUERY, sc, "SCI query requested\n");
    900 	mutex_exit(&sc->sc_mtx);
    901 
    902 	/*
    903 	 * EC wants to submit a query to us.  Exclude concurrent reads
    904 	 * and writes while we handle it.
    905 	 */
    906 	acpiec_lock(sc);
    907 	mutex_enter(&sc->sc_mtx);
    908 
    909 	DPRINTF(ACPIEC_DEBUG_QUERY, sc, "SCI query\n");
    910 
    911 	KASSERT(sc->sc_state == EC_STATE_FREE);
    912 
    913 	/* The Query command can always be issued, so be defensive here. */
    914 	KASSERT(sc->sc_got_sci);
    915 	sc->sc_got_sci = false;
    916 	sc->sc_state = EC_STATE_QUERY;
    917 
    918 	acpiec_wait(sc);
    919 
    920 	reg = sc->sc_cur_val;
    921 	DPRINTF(ACPIEC_DEBUG_QUERY, sc, "SCI query: 0x%"PRIx8"\n", reg);
    922 
    923 	mutex_exit(&sc->sc_mtx);
    924 	acpiec_unlock(sc);
    925 
    926 	if (reg == 0)
    927 		goto loop; /* Spurious query result */
    928 
    929 	/*
    930 	 * Evaluate _Qxx to respond to the controller.
    931 	 */
    932 	snprintf(qxx, sizeof(qxx), "_Q%02X", (unsigned int)reg);
    933 	rv = AcpiEvaluateObject(sc->sc_ech, qxx, NULL, NULL);
    934 	if (rv != AE_OK && rv != AE_NOT_FOUND) {
    935 		aprint_error_dev(dv, "GPE query method %s failed: %s",
    936 		    qxx, AcpiFormatException(rv));
    937 	}
    938 
    939 	goto loop;
    940 }
    941 
    942 static void
    943 acpiec_gpe_state_machine(struct acpiec_softc *sc)
    944 {
    945 	uint8_t reg;
    946 
    947 	KASSERT(mutex_owned(&sc->sc_mtx));
    948 
    949 	reg = acpiec_read_status(sc);
    950 
    951 #ifdef ACPIEC_DEBUG
    952 	if (acpiec_debug & __BIT(ACPIEC_DEBUG_TRANSITION)) {
    953 		char buf[128];
    954 
    955 		snprintb(buf, sizeof(buf), EC_STATUS_FMT, reg);
    956 		DPRINTF(ACPIEC_DEBUG_TRANSITION, sc, "%s\n", buf);
    957 	}
    958 #endif
    959 
    960 	switch (sc->sc_state) {
    961 	case EC_STATE_QUERY:
    962 		if ((reg & EC_STATUS_IBF) != 0)
    963 			break; /* Nothing of interest here. */
    964 		acpiec_write_command(sc, EC_COMMAND_QUERY);
    965 		sc->sc_state = EC_STATE_QUERY_VAL;
    966 		break;
    967 
    968 	case EC_STATE_QUERY_VAL:
    969 		if ((reg & EC_STATUS_OBF) == 0)
    970 			break; /* Nothing of interest here. */
    971 		sc->sc_cur_val = acpiec_read_data(sc);
    972 		sc->sc_state = EC_STATE_FREE;
    973 		cv_signal(&sc->sc_cv);
    974 		break;
    975 
    976 	case EC_STATE_READ:
    977 		if ((reg & EC_STATUS_IBF) != 0)
    978 			break; /* Nothing of interest here. */
    979 		acpiec_write_command(sc, EC_COMMAND_READ);
    980 		sc->sc_state = EC_STATE_READ_ADDR;
    981 		break;
    982 
    983 	case EC_STATE_READ_ADDR:
    984 		if ((reg & EC_STATUS_IBF) != 0)
    985 			break; /* Nothing of interest here. */
    986 		acpiec_write_data(sc, sc->sc_cur_addr);
    987 		sc->sc_state = EC_STATE_READ_VAL;
    988 		break;
    989 
    990 	case EC_STATE_READ_VAL:
    991 		if ((reg & EC_STATUS_OBF) == 0)
    992 			break; /* Nothing of interest here. */
    993 		sc->sc_cur_val = acpiec_read_data(sc);
    994 		sc->sc_state = EC_STATE_FREE;
    995 		cv_signal(&sc->sc_cv);
    996 		break;
    997 
    998 	case EC_STATE_WRITE:
    999 		if ((reg & EC_STATUS_IBF) != 0)
   1000 			break; /* Nothing of interest here. */
   1001 		acpiec_write_command(sc, EC_COMMAND_WRITE);
   1002 		sc->sc_state = EC_STATE_WRITE_ADDR;
   1003 		break;
   1004 
   1005 	case EC_STATE_WRITE_ADDR:
   1006 		if ((reg & EC_STATUS_IBF) != 0)
   1007 			break; /* Nothing of interest here. */
   1008 		acpiec_write_data(sc, sc->sc_cur_addr);
   1009 		sc->sc_state = EC_STATE_WRITE_VAL;
   1010 		break;
   1011 
   1012 	case EC_STATE_WRITE_VAL:
   1013 		if ((reg & EC_STATUS_IBF) != 0)
   1014 			break; /* Nothing of interest here. */
   1015 		sc->sc_state = EC_STATE_FREE;
   1016 		cv_signal(&sc->sc_cv);
   1017 		acpiec_write_data(sc, sc->sc_cur_val);
   1018 		break;
   1019 
   1020 	case EC_STATE_FREE:
   1021 		break;
   1022 
   1023 	default:
   1024 		panic("invalid state");
   1025 	}
   1026 
   1027 	/*
   1028 	 * If we just ended a transaction, and an SCI was requested,
   1029 	 * notify the SCI thread.
   1030 	 */
   1031 	if (sc->sc_state == EC_STATE_FREE) {
   1032 		if (reg & EC_STATUS_SCI) {
   1033 			DPRINTF(ACPIEC_DEBUG_TRANSITION, sc,
   1034 			    "wake SCI thread\n");
   1035 			sc->sc_got_sci = true;
   1036 			cv_signal(&sc->sc_cv_sci);
   1037 		}
   1038 	}
   1039 
   1040 	/*
   1041 	 * In case GPE interrupts are broken, poll once per tick for EC
   1042 	 * status updates while a transaction is still pending.
   1043 	 */
   1044 	if (sc->sc_state != EC_STATE_FREE) {
   1045 		DPRINTF(ACPIEC_DEBUG_INTR, sc, "schedule callout\n");
   1046 		callout_schedule(&sc->sc_pseudo_intr, 1);
   1047 	}
   1048 
   1049 	DPRINTF(ACPIEC_DEBUG_TRANSITION, sc, "return\n");
   1050 }
   1051 
   1052 static void
   1053 acpiec_callout(void *arg)
   1054 {
   1055 	struct acpiec_softc *sc = arg;
   1056 
   1057 	mutex_enter(&sc->sc_mtx);
   1058 	DPRINTF(ACPIEC_DEBUG_INTR, sc, "callout\n");
   1059 	acpiec_gpe_state_machine(sc);
   1060 	mutex_exit(&sc->sc_mtx);
   1061 }
   1062 
   1063 static uint32_t
   1064 acpiec_gpe_handler(ACPI_HANDLE hdl, uint32_t gpebit, void *arg)
   1065 {
   1066 	struct acpiec_softc *sc = arg;
   1067 
   1068 	mutex_enter(&sc->sc_mtx);
   1069 	DPRINTF(ACPIEC_DEBUG_INTR, sc, "GPE\n");
   1070 	acpiec_gpe_state_machine(sc);
   1071 	mutex_exit(&sc->sc_mtx);
   1072 
   1073 	return ACPI_INTERRUPT_HANDLED | ACPI_REENABLE_GPE;
   1074 }
   1075 
   1076 ACPI_STATUS
   1077 acpiec_bus_read(device_t dv, u_int addr, ACPI_INTEGER *val, int width)
   1078 {
   1079 	return acpiec_space_handler(ACPI_READ, addr, width * 8, val, dv, NULL);
   1080 }
   1081 
   1082 ACPI_STATUS
   1083 acpiec_bus_write(device_t dv, u_int addr, ACPI_INTEGER val, int width)
   1084 {
   1085 	return acpiec_space_handler(ACPI_WRITE, addr, width * 8, &val, dv,
   1086 	    NULL);
   1087 }
   1088 
   1089 ACPI_HANDLE
   1090 acpiec_get_handle(device_t dv)
   1091 {
   1092 	struct acpiec_softc *sc = device_private(dv);
   1093 
   1094 	return sc->sc_ech;
   1095 }
   1096