scsi-bus.c 37.3 KB
Newer Older
1
#include "hw.h"
2
#include "qemu-error.h"
G
Gerd Hoffmann 已提交
3
#include "scsi.h"
4
#include "scsi-defs.h"
5
#include "qdev.h"
B
Blue Swirl 已提交
6
#include "blockdev.h"
7
#include "trace.h"
8

9
static char *scsibus_get_fw_dev_path(DeviceState *dev);
10
static int scsi_req_parse(SCSICommand *cmd, SCSIDevice *dev, uint8_t *buf);
11
static void scsi_req_dequeue(SCSIRequest *req);
12 13
static int scsi_build_sense(uint8_t *in_buf, int in_len,
                            uint8_t *buf, int len, bool fixed);
14

15 16 17
static struct BusInfo scsi_bus_info = {
    .name  = "SCSI",
    .size  = sizeof(SCSIBus),
18
    .get_fw_dev_path = scsibus_get_fw_dev_path,
19
    .props = (Property[]) {
P
Paolo Bonzini 已提交
20
        DEFINE_PROP_UINT32("channel", SCSIDevice, channel, 0),
21
        DEFINE_PROP_UINT32("scsi-id", SCSIDevice, id, -1),
P
Paolo Bonzini 已提交
22
        DEFINE_PROP_UINT32("lun", SCSIDevice, lun, -1),
23 24 25 26 27 28
        DEFINE_PROP_END_OF_LIST(),
    },
};
static int next_scsi_bus;

/* Create a scsi bus, and attach devices to it.  */
29
void scsi_bus_new(SCSIBus *bus, DeviceState *host, const SCSIBusInfo *info)
30
{
31
    qbus_create_inplace(&bus->qbus, &scsi_bus_info, host, NULL);
32
    bus->busnr = next_scsi_bus++;
33
    bus->info = info;
G
Gerd Hoffmann 已提交
34
    bus->qbus.allow_hotplug = 1;
35 36
}

37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83
static void scsi_dma_restart_bh(void *opaque)
{
    SCSIDevice *s = opaque;
    SCSIRequest *req, *next;

    qemu_bh_delete(s->bh);
    s->bh = NULL;

    QTAILQ_FOREACH_SAFE(req, &s->requests, next, next) {
        scsi_req_ref(req);
        if (req->retry) {
            req->retry = false;
            switch (req->cmd.mode) {
            case SCSI_XFER_FROM_DEV:
            case SCSI_XFER_TO_DEV:
                scsi_req_continue(req);
                break;
            case SCSI_XFER_NONE:
                scsi_req_dequeue(req);
                scsi_req_enqueue(req);
                break;
            }
        }
        scsi_req_unref(req);
    }
}

void scsi_req_retry(SCSIRequest *req)
{
    /* No need to save a reference, because scsi_dma_restart_bh just
     * looks at the request list.  */
    req->retry = true;
}

static void scsi_dma_restart_cb(void *opaque, int running, RunState state)
{
    SCSIDevice *s = opaque;

    if (!running) {
        return;
    }
    if (!s->bh) {
        s->bh = qemu_bh_new(scsi_dma_restart_bh, s);
        qemu_bh_schedule(s->bh);
    }
}

84 85 86 87 88
static int scsi_qdev_init(DeviceState *qdev, DeviceInfo *base)
{
    SCSIDevice *dev = DO_UPCAST(SCSIDevice, qdev, qdev);
    SCSIDeviceInfo *info = DO_UPCAST(SCSIDeviceInfo, qdev, base);
    SCSIBus *bus = DO_UPCAST(SCSIBus, qbus, dev->qdev.parent_bus);
P
Paolo Bonzini 已提交
89
    SCSIDevice *d;
G
Gerd Hoffmann 已提交
90
    int rc = -1;
91

P
Paolo Bonzini 已提交
92 93 94 95
    if (dev->channel > bus->info->max_channel) {
        error_report("bad scsi channel id: %d", dev->channel);
        goto err;
    }
P
Paolo Bonzini 已提交
96
    if (dev->id != -1 && dev->id > bus->info->max_target) {
97
        error_report("bad scsi device id: %d", dev->id);
98 99 100
        goto err;
    }

P
Paolo Bonzini 已提交
101 102 103 104 105 106
    if (dev->id == -1) {
        int id = -1;
        if (dev->lun == -1) {
            dev->lun = 0;
        }
        do {
P
Paolo Bonzini 已提交
107
            d = scsi_device_find(bus, dev->channel, ++id, dev->lun);
P
Paolo Bonzini 已提交
108 109 110 111 112 113 114 115 116
        } while (d && d->lun == dev->lun && id <= bus->info->max_target);
        if (id > bus->info->max_target) {
            error_report("no free target");
            goto err;
        }
        dev->id = id;
    } else if (dev->lun == -1) {
        int lun = -1;
        do {
P
Paolo Bonzini 已提交
117
            d = scsi_device_find(bus, dev->channel, dev->id, ++lun);
P
Paolo Bonzini 已提交
118 119 120 121 122 123 124
        } while (d && d->lun == lun && lun < bus->info->max_lun);
        if (lun > bus->info->max_lun) {
            error_report("no free lun");
            goto err;
        }
        dev->lun = lun;
    } else {
P
Paolo Bonzini 已提交
125
        d = scsi_device_find(bus, dev->channel, dev->id, dev->lun);
P
Paolo Bonzini 已提交
126 127 128
        if (dev->lun == d->lun && dev != d) {
            qdev_free(&d->qdev);
        }
129 130 131
    }

    dev->info = info;
132
    QTAILQ_INIT(&dev->requests);
G
Gerd Hoffmann 已提交
133
    rc = dev->info->init(dev);
134 135 136 137
    if (rc == 0) {
        dev->vmsentry = qemu_add_vm_change_state_handler(scsi_dma_restart_cb,
                                                         dev);
    }
138 139

err:
G
Gerd Hoffmann 已提交
140 141 142 143 144 145 146
    return rc;
}

static int scsi_qdev_exit(DeviceState *qdev)
{
    SCSIDevice *dev = DO_UPCAST(SCSIDevice, qdev, qdev);

147 148 149
    if (dev->vmsentry) {
        qemu_del_vm_change_state_handler(dev->vmsentry);
    }
150 151
    if (dev->info->destroy) {
        dev->info->destroy(dev);
G
Gerd Hoffmann 已提交
152 153
    }
    return 0;
154 155 156 157 158 159
}

void scsi_qdev_register(SCSIDeviceInfo *info)
{
    info->qdev.bus_info = &scsi_bus_info;
    info->qdev.init     = scsi_qdev_init;
G
Gerd Hoffmann 已提交
160
    info->qdev.unplug   = qdev_simple_unplug_cb;
G
Gerd Hoffmann 已提交
161
    info->qdev.exit     = scsi_qdev_exit;
162 163 164 165
    qdev_register(&info->qdev);
}

/* handle legacy '-drive if=scsi,...' cmd line args */
166 167
SCSIDevice *scsi_bus_legacy_add_drive(SCSIBus *bus, BlockDriverState *bdrv,
                                      int unit, bool removable)
168 169 170 171
{
    const char *driver;
    DeviceState *dev;

172
    driver = bdrv_is_sg(bdrv) ? "scsi-generic" : "scsi-disk";
173 174
    dev = qdev_create(&bus->qbus, driver);
    qdev_prop_set_uint32(dev, "scsi-id", unit);
175 176 177
    if (qdev_prop_exists(dev, "removable")) {
        qdev_prop_set_bit(dev, "removable", removable);
    }
178 179 180 181
    if (qdev_prop_set_drive(dev, "drive", bdrv) < 0) {
        qdev_free(dev);
        return NULL;
    }
182 183
    if (qdev_init(dev) < 0)
        return NULL;
184 185 186
    return DO_UPCAST(SCSIDevice, qdev, dev);
}

187
int scsi_bus_legacy_handle_cmdline(SCSIBus *bus)
188
{
189
    Location loc;
190
    DriveInfo *dinfo;
191
    int res = 0, unit;
192

193
    loc_push_none(&loc);
P
Paolo Bonzini 已提交
194
    for (unit = 0; unit < bus->info->max_target; unit++) {
195 196 197 198
        dinfo = drive_get(IF_SCSI, bus->busnr, unit);
        if (dinfo == NULL) {
            continue;
        }
199
        qemu_opts_loc_restore(dinfo->opts);
200
        if (!scsi_bus_legacy_add_drive(bus, dinfo->bdrv, unit, false)) {
201 202 203
            res = -1;
            break;
        }
204
    }
205
    loc_pop(&loc);
206
    return res;
207
}
208

209 210 211 212 213 214 215 216 217
/* SCSIReqOps implementation for invalid commands.  */

static int32_t scsi_invalid_command(SCSIRequest *req, uint8_t *buf)
{
    scsi_req_build_sense(req, SENSE_CODE(INVALID_OPCODE));
    scsi_req_complete(req, CHECK_CONDITION);
    return 0;
}

P
Paolo Bonzini 已提交
218
static const struct SCSIReqOps reqops_invalid_opcode = {
219 220 221 222
    .size         = sizeof(SCSIRequest),
    .send_command = scsi_invalid_command
};

223 224 225 226 227 228 229 230 231 232 233 234 235
/* SCSIReqOps implementation for unit attention conditions.  */

static int32_t scsi_unit_attention(SCSIRequest *req, uint8_t *buf)
{
    if (req->dev && req->dev->unit_attention.key == UNIT_ATTENTION) {
        scsi_req_build_sense(req, req->dev->unit_attention);
    } else if (req->bus->unit_attention.key == UNIT_ATTENTION) {
        scsi_req_build_sense(req, req->bus->unit_attention);
    }
    scsi_req_complete(req, CHECK_CONDITION);
    return 0;
}

P
Paolo Bonzini 已提交
236
static const struct SCSIReqOps reqops_unit_attention = {
237 238 239 240
    .size         = sizeof(SCSIRequest),
    .send_command = scsi_unit_attention
};

241 242 243 244 245 246 247 248
/* SCSIReqOps implementation for REPORT LUNS and for commands sent to
   an invalid LUN.  */

typedef struct SCSITargetReq SCSITargetReq;

struct SCSITargetReq {
    SCSIRequest req;
    int len;
249
    uint8_t buf[2056];
250 251 252 253 254 255 256 257 258 259 260 261 262 263
};

static void store_lun(uint8_t *outbuf, int lun)
{
    if (lun < 256) {
        outbuf[1] = lun;
        return;
    }
    outbuf[1] = (lun & 255);
    outbuf[0] = (lun >> 8) | 0x40;
}

static bool scsi_target_emulate_report_luns(SCSITargetReq *r)
{
264 265
    DeviceState *qdev;
    int i, len, n;
P
Paolo Bonzini 已提交
266
    int channel, id;
267 268
    bool found_lun0;

269 270 271 272 273 274
    if (r->req.cmd.xfer < 16) {
        return false;
    }
    if (r->req.cmd.buf[2] > 2) {
        return false;
    }
P
Paolo Bonzini 已提交
275
    channel = r->req.dev->channel;
276 277 278 279 280 281
    id = r->req.dev->id;
    found_lun0 = false;
    n = 0;
    QTAILQ_FOREACH(qdev, &r->req.bus->qbus.children, sibling) {
        SCSIDevice *dev = DO_UPCAST(SCSIDevice, qdev, qdev);

P
Paolo Bonzini 已提交
282
        if (dev->channel == channel && dev->id == id) {
283 284 285 286 287 288 289 290 291 292 293 294 295 296 297
            if (dev->lun == 0) {
                found_lun0 = true;
            }
            n += 8;
        }
    }
    if (!found_lun0) {
        n += 8;
    }
    len = MIN(n + 8, r->req.cmd.xfer & ~7);
    if (len > sizeof(r->buf)) {
        /* TODO: > 256 LUNs? */
        return false;
    }

298
    memset(r->buf, 0, len);
299 300 301 302 303
    stl_be_p(&r->buf, n);
    i = found_lun0 ? 8 : 16;
    QTAILQ_FOREACH(qdev, &r->req.bus->qbus.children, sibling) {
        SCSIDevice *dev = DO_UPCAST(SCSIDevice, qdev, qdev);

P
Paolo Bonzini 已提交
304
        if (dev->channel == channel && dev->id == id) {
305 306 307
            store_lun(&r->buf[i], dev->lun);
            i += 8;
        }
308
    }
309 310
    assert(i == n + 8);
    r->len = len;
311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368
    return true;
}

static bool scsi_target_emulate_inquiry(SCSITargetReq *r)
{
    assert(r->req.dev->lun != r->req.lun);
    if (r->req.cmd.buf[1] & 0x2) {
        /* Command support data - optional, not implemented */
        return false;
    }

    if (r->req.cmd.buf[1] & 0x1) {
        /* Vital product data */
        uint8_t page_code = r->req.cmd.buf[2];
        if (r->req.cmd.xfer < 4) {
            return false;
        }

        r->buf[r->len++] = page_code ; /* this page */
        r->buf[r->len++] = 0x00;

        switch (page_code) {
        case 0x00: /* Supported page codes, mandatory */
        {
            int pages;
            pages = r->len++;
            r->buf[r->len++] = 0x00; /* list of supported pages (this page) */
            r->buf[pages] = r->len - pages - 1; /* number of pages */
            break;
        }
        default:
            return false;
        }
        /* done with EVPD */
        assert(r->len < sizeof(r->buf));
        r->len = MIN(r->req.cmd.xfer, r->len);
        return true;
    }

    /* Standard INQUIRY data */
    if (r->req.cmd.buf[2] != 0) {
        return false;
    }

    /* PAGE CODE == 0 */
    if (r->req.cmd.xfer < 5) {
        return -1;
    }

    r->len = MIN(r->req.cmd.xfer, 36);
    memset(r->buf, 0, r->len);
    if (r->req.lun != 0) {
        r->buf[0] = TYPE_NO_LUN;
    } else {
        r->buf[0] = TYPE_NOT_PRESENT | TYPE_INACTIVE;
        r->buf[2] = 5; /* Version */
        r->buf[3] = 2 | 0x10; /* HiSup, response data format */
        r->buf[4] = r->len - 5; /* Additional Length = (Len - 1) - 4 */
369
        r->buf[7] = 0x10 | (r->req.bus->info->tcq ? 0x02 : 0); /* Sync, TCQ.  */
370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391
        memcpy(&r->buf[8], "QEMU    ", 8);
        memcpy(&r->buf[16], "QEMU TARGET     ", 16);
        strncpy((char *) &r->buf[32], QEMU_VERSION, 4);
    }
    return true;
}

static int32_t scsi_target_send_command(SCSIRequest *req, uint8_t *buf)
{
    SCSITargetReq *r = DO_UPCAST(SCSITargetReq, req, req);

    switch (buf[0]) {
    case REPORT_LUNS:
        if (!scsi_target_emulate_report_luns(r)) {
            goto illegal_request;
        }
        break;
    case INQUIRY:
        if (!scsi_target_emulate_inquiry(r)) {
            goto illegal_request;
        }
        break;
392 393 394 395
    case REQUEST_SENSE:
        if (req->cmd.xfer < 4) {
            goto illegal_request;
        }
396 397
        r->len = scsi_device_get_sense(r->req.dev, r->buf,
                                       MIN(req->cmd.xfer, sizeof r->buf),
398
                                       (req->cmd.buf[1] & 1) == 0);
399 400 401 402 403 404 405
        if (r->req.dev->sense_is_ua) {
            if (r->req.dev->info->unit_attention_reported) {
                r->req.dev->info->unit_attention_reported(req->dev);
            }
            r->req.dev->sense_len = 0;
            r->req.dev->sense_is_ua = false;
        }
406
        break;
407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443
    default:
        scsi_req_build_sense(req, SENSE_CODE(LUN_NOT_SUPPORTED));
        scsi_req_complete(req, CHECK_CONDITION);
        return 0;
    illegal_request:
        scsi_req_build_sense(req, SENSE_CODE(INVALID_FIELD));
        scsi_req_complete(req, CHECK_CONDITION);
        return 0;
    }

    if (!r->len) {
        scsi_req_complete(req, GOOD);
    }
    return r->len;
}

static void scsi_target_read_data(SCSIRequest *req)
{
    SCSITargetReq *r = DO_UPCAST(SCSITargetReq, req, req);
    uint32_t n;

    n = r->len;
    if (n > 0) {
        r->len = 0;
        scsi_req_data(&r->req, n);
    } else {
        scsi_req_complete(&r->req, GOOD);
    }
}

static uint8_t *scsi_target_get_buf(SCSIRequest *req)
{
    SCSITargetReq *r = DO_UPCAST(SCSITargetReq, req, req);

    return r->buf;
}

P
Paolo Bonzini 已提交
444
static const struct SCSIReqOps reqops_target_command = {
445 446 447 448 449 450 451
    .size         = sizeof(SCSITargetReq),
    .send_command = scsi_target_send_command,
    .read_data    = scsi_target_read_data,
    .get_buf      = scsi_target_get_buf,
};


P
Paolo Bonzini 已提交
452 453
SCSIRequest *scsi_req_alloc(const SCSIReqOps *reqops, SCSIDevice *d,
                            uint32_t tag, uint32_t lun, void *hba_private)
454 455 456
{
    SCSIRequest *req;

457
    req = g_malloc0(reqops->size);
458
    req->refcount = 1;
459 460 461 462
    req->bus = scsi_bus_from_device(d);
    req->dev = d;
    req->tag = tag;
    req->lun = lun;
463
    req->hba_private = hba_private;
G
Gerd Hoffmann 已提交
464
    req->status = -1;
465
    req->sense_len = 0;
P
Paolo Bonzini 已提交
466
    req->ops = reqops;
467
    trace_scsi_req_alloc(req->dev->id, req->lun, req->tag);
468 469 470
    return req;
}

471
SCSIRequest *scsi_req_new(SCSIDevice *d, uint32_t tag, uint32_t lun,
472
                          uint8_t *buf, void *hba_private)
P
Paolo Bonzini 已提交
473
{
474
    SCSIBus *bus = DO_UPCAST(SCSIBus, qbus, d->qdev.parent_bus);
475
    SCSIRequest *req;
476 477 478 479 480 481 482 483
    SCSICommand cmd;

    if (scsi_req_parse(&cmd, d, buf) != 0) {
        trace_scsi_req_parse_bad(d->id, lun, tag, buf[0]);
        req = scsi_req_alloc(&reqops_invalid_opcode, d, tag, lun, hba_private);
    } else {
        trace_scsi_req_parsed(d->id, lun, tag, buf[0],
                              cmd.mode, cmd.xfer);
484
        if (cmd.lba != -1) {
485 486 487
            trace_scsi_req_parsed_lba(d->id, lun, tag, buf[0],
                                      cmd.lba);
        }
488

489 490 491 492 493
        if ((d->unit_attention.key == UNIT_ATTENTION ||
             bus->unit_attention.key == UNIT_ATTENTION) &&
            (buf[0] != INQUIRY &&
             buf[0] != REPORT_LUNS &&
             buf[0] != GET_CONFIGURATION &&
494 495 496 497 498 499 500
             buf[0] != GET_EVENT_STATUS_NOTIFICATION &&

             /*
              * If we already have a pending unit attention condition,
              * report this one before triggering another one.
              */
             !(buf[0] == REQUEST_SENSE && d->sense_is_ua))) {
501 502 503
            req = scsi_req_alloc(&reqops_unit_attention, d, tag, lun,
                                 hba_private);
        } else if (lun != d->lun ||
504 505
            buf[0] == REPORT_LUNS ||
            buf[0] == REQUEST_SENSE) {
506 507 508
            req = scsi_req_alloc(&reqops_target_command, d, tag, lun,
                                 hba_private);
        } else {
P
Paolo Bonzini 已提交
509
            req = d->info->alloc_req(d, tag, lun, buf, hba_private);
510
        }
511 512 513
    }

    req->cmd = cmd;
514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530
    switch (buf[0]) {
    case INQUIRY:
        trace_scsi_inquiry(d->id, lun, tag, cmd.buf[1], cmd.buf[2]);
        break;
    case TEST_UNIT_READY:
        trace_scsi_test_unit_ready(d->id, lun, tag);
        break;
    case REPORT_LUNS:
        trace_scsi_report_luns(d->id, lun, tag);
        break;
    case REQUEST_SENSE:
        trace_scsi_request_sense(d->id, lun, tag);
        break;
    default:
        break;
    }

531
    return req;
P
Paolo Bonzini 已提交
532 533
}

P
Paolo Bonzini 已提交
534 535
uint8_t *scsi_req_get_buf(SCSIRequest *req)
{
536
    return req->ops->get_buf(req);
P
Paolo Bonzini 已提交
537 538
}

539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577
static void scsi_clear_unit_attention(SCSIRequest *req)
{
    SCSISense *ua;
    if (req->dev->unit_attention.key != UNIT_ATTENTION &&
        req->bus->unit_attention.key != UNIT_ATTENTION) {
        return;
    }

    /*
     * If an INQUIRY command enters the enabled command state,
     * the device server shall [not] clear any unit attention condition;
     * See also MMC-6, paragraphs 6.5 and 6.6.2.
     */
    if (req->cmd.buf[0] == INQUIRY ||
        req->cmd.buf[0] == GET_CONFIGURATION ||
        req->cmd.buf[0] == GET_EVENT_STATUS_NOTIFICATION) {
        return;
    }

    if (req->dev->unit_attention.key == UNIT_ATTENTION) {
        ua = &req->dev->unit_attention;
    } else {
        ua = &req->bus->unit_attention;
    }

    /*
     * If a REPORT LUNS command enters the enabled command state, [...]
     * the device server shall clear any pending unit attention condition
     * with an additional sense code of REPORTED LUNS DATA HAS CHANGED.
     */
    if (req->cmd.buf[0] == REPORT_LUNS &&
        !(ua->asc == SENSE_CODE(REPORTED_LUNS_CHANGED).asc &&
          ua->ascq == SENSE_CODE(REPORTED_LUNS_CHANGED).ascq)) {
        return;
    }

    *ua = SENSE_CODE(NO_SENSE);
}

578 579
int scsi_req_get_sense(SCSIRequest *req, uint8_t *buf, int len)
{
580 581
    int ret;

582 583
    assert(len >= 14);
    if (!req->sense_len) {
584 585
        return 0;
    }
586 587 588 589 590 591 592 593 594 595

    ret = scsi_build_sense(req->sense, req->sense_len, buf, len, true);

    /*
     * FIXME: clearing unit attention conditions upon autosense should be done
     * only if the UA_INTLCK_CTRL field in the Control mode page is set to 00b
     * (SAM-5, 5.14).
     *
     * We assume UA_INTLCK_CTRL to be 00b for HBAs that support autosense, and
     * 10b for HBAs that do not support it (do not call scsi_req_get_sense).
596
     * Here we handle unit attention clearing for UA_INTLCK_CTRL == 00b.
597
     */
598 599 600 601 602 603 604
    if (req->dev->sense_is_ua) {
        if (req->dev->info->unit_attention_reported) {
            req->dev->info->unit_attention_reported(req->dev);
        }
        req->dev->sense_len = 0;
        req->dev->sense_is_ua = false;
    }
605
    return ret;
606 607 608 609 610 611 612 613 614 615 616 617 618 619
}

int scsi_device_get_sense(SCSIDevice *dev, uint8_t *buf, int len, bool fixed)
{
    return scsi_build_sense(dev->sense, dev->sense_len, buf, len, fixed);
}

void scsi_req_build_sense(SCSIRequest *req, SCSISense sense)
{
    trace_scsi_req_build_sense(req->dev->id, req->lun, req->tag,
                               sense.key, sense.asc, sense.ascq);
    memset(req->sense, 0, 18);
    req->sense[0] = 0xf0;
    req->sense[2] = sense.key;
620
    req->sense[7] = 10;
621 622 623
    req->sense[12] = sense.asc;
    req->sense[13] = sense.ascq;
    req->sense_len = 18;
624 625
}

626
int32_t scsi_req_enqueue(SCSIRequest *req)
627
{
628 629
    int32_t rc;

630 631 632 633
    assert(!req->enqueued);
    scsi_req_ref(req);
    req->enqueued = true;
    QTAILQ_INSERT_TAIL(&req->dev->requests, req, next);
634 635

    scsi_req_ref(req);
636
    rc = req->ops->send_command(req, req->cmd.buf);
637 638
    scsi_req_unref(req);
    return rc;
639 640
}

641
static void scsi_req_dequeue(SCSIRequest *req)
642
{
643
    trace_scsi_req_dequeue(req->dev->id, req->lun, req->tag);
644
    req->retry = false;
645 646 647
    if (req->enqueued) {
        QTAILQ_REMOVE(&req->dev->requests, req, next);
        req->enqueued = false;
P
Paolo Bonzini 已提交
648
        scsi_req_unref(req);
649 650 651
    }
}

P
Paolo Bonzini 已提交
652
static int scsi_req_length(SCSICommand *cmd, SCSIDevice *dev, uint8_t *buf)
653
{
P
Paolo Bonzini 已提交
654
    switch (buf[0] >> 5) {
655
    case 0:
P
Paolo Bonzini 已提交
656 657
        cmd->xfer = buf[4];
        cmd->len = 6;
658
        /* length 0 means 256 blocks */
P
Paolo Bonzini 已提交
659 660 661
        if (cmd->xfer == 0) {
            cmd->xfer = 256;
        }
662 663 664
        break;
    case 1:
    case 2:
665
        cmd->xfer = lduw_be_p(&buf[7]);
P
Paolo Bonzini 已提交
666
        cmd->len = 10;
667 668
        break;
    case 4:
669
        cmd->xfer = ldl_be_p(&buf[10]);
P
Paolo Bonzini 已提交
670
        cmd->len = 16;
671 672
        break;
    case 5:
673
        cmd->xfer = ldl_be_p(&buf[6]);
P
Paolo Bonzini 已提交
674
        cmd->len = 12;
675 676 677 678 679
        break;
    default:
        return -1;
    }

P
Paolo Bonzini 已提交
680
    switch (buf[0]) {
681
    case TEST_UNIT_READY:
682
    case REWIND:
683
    case START_STOP:
P
Paolo Bonzini 已提交
684
    case SET_CAPACITY:
685 686
    case WRITE_FILEMARKS:
    case SPACE:
687 688
    case RESERVE:
    case RELEASE:
689 690
    case ERASE:
    case ALLOW_MEDIUM_REMOVAL:
691
    case VERIFY_10:
692 693 694 695 696 697
    case SEEK_10:
    case SYNCHRONIZE_CACHE:
    case LOCK_UNLOCK_CACHE:
    case LOAD_UNLOAD:
    case SET_CD_SPEED:
    case SET_LIMITS:
698
    case WRITE_LONG_10:
699 700
    case MOVE_MEDIUM:
    case UPDATE_BLOCK:
P
Paolo Bonzini 已提交
701
        cmd->xfer = 0;
702 703 704
        break;
    case MODE_SENSE:
        break;
705
    case WRITE_SAME_10:
P
Paolo Bonzini 已提交
706
        cmd->xfer = 1;
707
        break;
708
    case READ_CAPACITY_10:
P
Paolo Bonzini 已提交
709
        cmd->xfer = 8;
710 711
        break;
    case READ_BLOCK_LIMITS:
P
Paolo Bonzini 已提交
712
        cmd->xfer = 6;
713 714
        break;
    case READ_POSITION:
P
Paolo Bonzini 已提交
715
        cmd->xfer = 20;
716 717
        break;
    case SEND_VOLUME_TAG:
P
Paolo Bonzini 已提交
718
        cmd->xfer *= 40;
719 720
        break;
    case MEDIUM_SCAN:
P
Paolo Bonzini 已提交
721
        cmd->xfer *= 8;
722 723
        break;
    case WRITE_10:
724
    case WRITE_VERIFY_10:
725 726 727
    case WRITE_6:
    case WRITE_12:
    case WRITE_VERIFY_12:
G
Gerd Hoffmann 已提交
728 729
    case WRITE_16:
    case WRITE_VERIFY_16:
P
Paolo Bonzini 已提交
730
        cmd->xfer *= dev->blocksize;
731 732 733 734 735 736
        break;
    case READ_10:
    case READ_6:
    case READ_REVERSE:
    case RECOVER_BUFFERED_DATA:
    case READ_12:
G
Gerd Hoffmann 已提交
737
    case READ_16:
P
Paolo Bonzini 已提交
738
        cmd->xfer *= dev->blocksize;
739 740
        break;
    case INQUIRY:
P
Paolo Bonzini 已提交
741
        cmd->xfer = buf[4] | (buf[3] << 8);
742
        break;
743 744
    case MAINTENANCE_OUT:
    case MAINTENANCE_IN:
P
Paolo Bonzini 已提交
745
        if (dev->type == TYPE_ROM) {
746
            /* GPCMD_REPORT_KEY and GPCMD_SEND_KEY from multi media commands */
P
Paolo Bonzini 已提交
747
            cmd->xfer = buf[9] | (buf[8] << 8);
748 749
        }
        break;
750 751 752 753
    }
    return 0;
}

P
Paolo Bonzini 已提交
754
static int scsi_req_stream_length(SCSICommand *cmd, SCSIDevice *dev, uint8_t *buf)
755
{
P
Paolo Bonzini 已提交
756
    switch (buf[0]) {
757 758 759 760 761
    /* stream commands */
    case READ_6:
    case READ_REVERSE:
    case RECOVER_BUFFERED_DATA:
    case WRITE_6:
P
Paolo Bonzini 已提交
762 763 764 765 766
        cmd->len = 6;
        cmd->xfer = buf[4] | (buf[3] << 8) | (buf[2] << 16);
        if (buf[1] & 0x01) { /* fixed */
            cmd->xfer *= dev->blocksize;
        }
767 768 769
        break;
    case REWIND:
    case START_STOP:
P
Paolo Bonzini 已提交
770 771
        cmd->len = 6;
        cmd->xfer = 0;
772 773 774
        break;
    /* generic commands */
    default:
P
Paolo Bonzini 已提交
775
        return scsi_req_length(cmd, dev, buf);
776 777 778 779
    }
    return 0;
}

P
Paolo Bonzini 已提交
780
static void scsi_cmd_xfer_mode(SCSICommand *cmd)
G
Gerd Hoffmann 已提交
781
{
P
Paolo Bonzini 已提交
782
    switch (cmd->buf[0]) {
G
Gerd Hoffmann 已提交
783 784
    case WRITE_6:
    case WRITE_10:
785
    case WRITE_VERIFY_10:
G
Gerd Hoffmann 已提交
786 787
    case WRITE_12:
    case WRITE_VERIFY_12:
G
Gerd Hoffmann 已提交
788 789
    case WRITE_16:
    case WRITE_VERIFY_16:
G
Gerd Hoffmann 已提交
790 791 792 793 794 795 796 797 798 799 800 801 802 803 804
    case COPY:
    case COPY_VERIFY:
    case COMPARE:
    case CHANGE_DEFINITION:
    case LOG_SELECT:
    case MODE_SELECT:
    case MODE_SELECT_10:
    case SEND_DIAGNOSTIC:
    case WRITE_BUFFER:
    case FORMAT_UNIT:
    case REASSIGN_BLOCKS:
    case SEARCH_EQUAL:
    case SEARCH_HIGH:
    case SEARCH_LOW:
    case UPDATE_BLOCK:
805 806
    case WRITE_LONG_10:
    case WRITE_SAME_10:
G
Gerd Hoffmann 已提交
807 808 809 810 811
    case SEARCH_HIGH_12:
    case SEARCH_EQUAL_12:
    case SEARCH_LOW_12:
    case MEDIUM_SCAN:
    case SEND_VOLUME_TAG:
812
    case PERSISTENT_RESERVE_OUT:
813
    case MAINTENANCE_OUT:
P
Paolo Bonzini 已提交
814
        cmd->mode = SCSI_XFER_TO_DEV;
G
Gerd Hoffmann 已提交
815 816
        break;
    default:
P
Paolo Bonzini 已提交
817 818
        if (cmd->xfer)
            cmd->mode = SCSI_XFER_FROM_DEV;
G
Gerd Hoffmann 已提交
819
        else {
P
Paolo Bonzini 已提交
820
            cmd->mode = SCSI_XFER_NONE;
G
Gerd Hoffmann 已提交
821 822 823 824 825
        }
        break;
    }
}

P
Paolo Bonzini 已提交
826
static uint64_t scsi_cmd_lba(SCSICommand *cmd)
827
{
P
Paolo Bonzini 已提交
828
    uint8_t *buf = cmd->buf;
829 830 831 832
    uint64_t lba;

    switch (buf[0] >> 5) {
    case 0:
833
        lba = ldl_be_p(&buf[0]) & 0x1fffff;
834 835 836
        break;
    case 1:
    case 2:
837 838
    case 5:
        lba = ldl_be_p(&buf[2]);
839 840
        break;
    case 4:
841
        lba = ldq_be_p(&buf[2]);
842 843 844 845 846 847 848 849
        break;
    default:
        lba = -1;

    }
    return lba;
}

850
int scsi_req_parse(SCSICommand *cmd, SCSIDevice *dev, uint8_t *buf)
851 852 853
{
    int rc;

854 855
    if (dev->type == TYPE_TAPE) {
        rc = scsi_req_stream_length(cmd, dev, buf);
856
    } else {
857
        rc = scsi_req_length(cmd, dev, buf);
858 859 860 861
    }
    if (rc != 0)
        return rc;

862 863 864
    memcpy(cmd->buf, buf, cmd->len);
    scsi_cmd_xfer_mode(cmd);
    cmd->lba = scsi_cmd_lba(cmd);
865 866
    return 0;
}
G
Gerd Hoffmann 已提交
867

868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886
/*
 * Predefined sense codes
 */

/* No sense data available */
const struct SCSISense sense_code_NO_SENSE = {
    .key = NO_SENSE , .asc = 0x00 , .ascq = 0x00
};

/* LUN not ready, Manual intervention required */
const struct SCSISense sense_code_LUN_NOT_READY = {
    .key = NOT_READY, .asc = 0x04, .ascq = 0x03
};

/* LUN not ready, Medium not present */
const struct SCSISense sense_code_NO_MEDIUM = {
    .key = NOT_READY, .asc = 0x3a, .ascq = 0x00
};

887 888 889 890 891
/* LUN not ready, medium removal prevented */
const struct SCSISense sense_code_NOT_READY_REMOVAL_PREVENTED = {
    .key = NOT_READY, .asc = 0x53, .ascq = 0x00
};

892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916
/* Hardware error, internal target failure */
const struct SCSISense sense_code_TARGET_FAILURE = {
    .key = HARDWARE_ERROR, .asc = 0x44, .ascq = 0x00
};

/* Illegal request, invalid command operation code */
const struct SCSISense sense_code_INVALID_OPCODE = {
    .key = ILLEGAL_REQUEST, .asc = 0x20, .ascq = 0x00
};

/* Illegal request, LBA out of range */
const struct SCSISense sense_code_LBA_OUT_OF_RANGE = {
    .key = ILLEGAL_REQUEST, .asc = 0x21, .ascq = 0x00
};

/* Illegal request, Invalid field in CDB */
const struct SCSISense sense_code_INVALID_FIELD = {
    .key = ILLEGAL_REQUEST, .asc = 0x24, .ascq = 0x00
};

/* Illegal request, LUN not supported */
const struct SCSISense sense_code_LUN_NOT_SUPPORTED = {
    .key = ILLEGAL_REQUEST, .asc = 0x25, .ascq = 0x00
};

917 918 919 920 921 922
/* Illegal request, Saving parameters not supported */
const struct SCSISense sense_code_SAVING_PARAMS_NOT_SUPPORTED = {
    .key = ILLEGAL_REQUEST, .asc = 0x39, .ascq = 0x00
};

/* Illegal request, Incompatible medium installed */
923
const struct SCSISense sense_code_INCOMPATIBLE_FORMAT = {
924 925 926
    .key = ILLEGAL_REQUEST, .asc = 0x30, .ascq = 0x00
};

927 928 929 930 931
/* Illegal request, medium removal prevented */
const struct SCSISense sense_code_ILLEGAL_REQ_REMOVAL_PREVENTED = {
    .key = ILLEGAL_REQUEST, .asc = 0x53, .ascq = 0x00
};

932 933 934 935 936 937 938 939 940 941 942 943 944 945 946
/* Command aborted, I/O process terminated */
const struct SCSISense sense_code_IO_ERROR = {
    .key = ABORTED_COMMAND, .asc = 0x00, .ascq = 0x06
};

/* Command aborted, I_T Nexus loss occurred */
const struct SCSISense sense_code_I_T_NEXUS_LOSS = {
    .key = ABORTED_COMMAND, .asc = 0x29, .ascq = 0x07
};

/* Command aborted, Logical Unit failure */
const struct SCSISense sense_code_LUN_FAILURE = {
    .key = ABORTED_COMMAND, .asc = 0x3e, .ascq = 0x01
};

947 948 949 950 951
/* Unit attention, Power on, reset or bus device reset occurred */
const struct SCSISense sense_code_RESET = {
    .key = UNIT_ATTENTION, .asc = 0x29, .ascq = 0x00
};

952 953 954 955 956
/* Unit attention, No medium */
const struct SCSISense sense_code_UNIT_ATTENTION_NO_MEDIUM = {
    .key = UNIT_ATTENTION, .asc = 0x3a, .ascq = 0x00
};

957 958 959 960 961 962 963 964 965 966 967 968 969 970 971
/* Unit attention, Medium may have changed */
const struct SCSISense sense_code_MEDIUM_CHANGED = {
    .key = UNIT_ATTENTION, .asc = 0x28, .ascq = 0x00
};

/* Unit attention, Reported LUNs data has changed */
const struct SCSISense sense_code_REPORTED_LUNS_CHANGED = {
    .key = UNIT_ATTENTION, .asc = 0x3f, .ascq = 0x0e
};

/* Unit attention, Device internal reset */
const struct SCSISense sense_code_DEVICE_INTERNAL_RESET = {
    .key = UNIT_ATTENTION, .asc = 0x29, .ascq = 0x04
};

972 973 974
/*
 * scsi_build_sense
 *
975
 * Convert between fixed and descriptor sense buffers
976
 */
977 978
int scsi_build_sense(uint8_t *in_buf, int in_len,
                     uint8_t *buf, int len, bool fixed)
979
{
980 981
    bool fixed_in;
    SCSISense sense;
982 983 984 985
    if (!fixed && len < 8) {
        return 0;
    }

986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008
    if (in_len == 0) {
        sense.key = NO_SENSE;
        sense.asc = 0;
        sense.ascq = 0;
    } else {
        fixed_in = (in_buf[0] & 2) == 0;

        if (fixed == fixed_in) {
            memcpy(buf, in_buf, MIN(len, in_len));
            return MIN(len, in_len);
        }

        if (fixed_in) {
            sense.key = in_buf[2];
            sense.asc = in_buf[12];
            sense.ascq = in_buf[13];
        } else {
            sense.key = in_buf[1];
            sense.asc = in_buf[2];
            sense.ascq = in_buf[3];
        }
    }

1009 1010 1011 1012 1013
    memset(buf, 0, len);
    if (fixed) {
        /* Return fixed format sense buffer */
        buf[0] = 0xf0;
        buf[2] = sense.key;
1014
        buf[7] = 10;
1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027
        buf[12] = sense.asc;
        buf[13] = sense.ascq;
        return MIN(len, 18);
    } else {
        /* Return descriptor format sense buffer */
        buf[0] = 0x72;
        buf[1] = sense.key;
        buf[2] = sense.asc;
        buf[3] = sense.ascq;
        return 8;
    }
}

G
Gerd Hoffmann 已提交
1028 1029 1030 1031
static const char *scsi_command_name(uint8_t cmd)
{
    static const char *names[] = {
        [ TEST_UNIT_READY          ] = "TEST_UNIT_READY",
1032
        [ REWIND                   ] = "REWIND",
G
Gerd Hoffmann 已提交
1033 1034 1035 1036 1037 1038
        [ REQUEST_SENSE            ] = "REQUEST_SENSE",
        [ FORMAT_UNIT              ] = "FORMAT_UNIT",
        [ READ_BLOCK_LIMITS        ] = "READ_BLOCK_LIMITS",
        [ REASSIGN_BLOCKS          ] = "REASSIGN_BLOCKS",
        [ READ_6                   ] = "READ_6",
        [ WRITE_6                  ] = "WRITE_6",
P
Paolo Bonzini 已提交
1039
        [ SET_CAPACITY             ] = "SET_CAPACITY",
G
Gerd Hoffmann 已提交
1040 1041 1042 1043 1044
        [ READ_REVERSE             ] = "READ_REVERSE",
        [ WRITE_FILEMARKS          ] = "WRITE_FILEMARKS",
        [ SPACE                    ] = "SPACE",
        [ INQUIRY                  ] = "INQUIRY",
        [ RECOVER_BUFFERED_DATA    ] = "RECOVER_BUFFERED_DATA",
1045 1046
        [ MAINTENANCE_IN           ] = "MAINTENANCE_IN",
        [ MAINTENANCE_OUT          ] = "MAINTENANCE_OUT",
G
Gerd Hoffmann 已提交
1047 1048 1049 1050 1051 1052 1053 1054 1055 1056
        [ MODE_SELECT              ] = "MODE_SELECT",
        [ RESERVE                  ] = "RESERVE",
        [ RELEASE                  ] = "RELEASE",
        [ COPY                     ] = "COPY",
        [ ERASE                    ] = "ERASE",
        [ MODE_SENSE               ] = "MODE_SENSE",
        [ START_STOP               ] = "START_STOP",
        [ RECEIVE_DIAGNOSTIC       ] = "RECEIVE_DIAGNOSTIC",
        [ SEND_DIAGNOSTIC          ] = "SEND_DIAGNOSTIC",
        [ ALLOW_MEDIUM_REMOVAL     ] = "ALLOW_MEDIUM_REMOVAL",
1057
        [ READ_CAPACITY_10         ] = "READ_CAPACITY_10",
G
Gerd Hoffmann 已提交
1058 1059 1060
        [ READ_10                  ] = "READ_10",
        [ WRITE_10                 ] = "WRITE_10",
        [ SEEK_10                  ] = "SEEK_10",
1061 1062
        [ WRITE_VERIFY_10          ] = "WRITE_VERIFY_10",
        [ VERIFY_10                ] = "VERIFY_10",
G
Gerd Hoffmann 已提交
1063 1064 1065 1066
        [ SEARCH_HIGH              ] = "SEARCH_HIGH",
        [ SEARCH_EQUAL             ] = "SEARCH_EQUAL",
        [ SEARCH_LOW               ] = "SEARCH_LOW",
        [ SET_LIMITS               ] = "SET_LIMITS",
P
Paolo Bonzini 已提交
1067
        [ PRE_FETCH                ] = "PRE_FETCH/READ_POSITION",
1068
        /* READ_POSITION and PRE_FETCH use the same operation code */
G
Gerd Hoffmann 已提交
1069 1070 1071 1072 1073 1074 1075 1076 1077
        [ SYNCHRONIZE_CACHE        ] = "SYNCHRONIZE_CACHE",
        [ LOCK_UNLOCK_CACHE        ] = "LOCK_UNLOCK_CACHE",
        [ READ_DEFECT_DATA         ] = "READ_DEFECT_DATA",
        [ MEDIUM_SCAN              ] = "MEDIUM_SCAN",
        [ COMPARE                  ] = "COMPARE",
        [ COPY_VERIFY              ] = "COPY_VERIFY",
        [ WRITE_BUFFER             ] = "WRITE_BUFFER",
        [ READ_BUFFER              ] = "READ_BUFFER",
        [ UPDATE_BLOCK             ] = "UPDATE_BLOCK",
1078 1079
        [ READ_LONG_10             ] = "READ_LONG_10",
        [ WRITE_LONG_10            ] = "WRITE_LONG_10",
G
Gerd Hoffmann 已提交
1080
        [ CHANGE_DEFINITION        ] = "CHANGE_DEFINITION",
1081 1082
        [ WRITE_SAME_10            ] = "WRITE_SAME_10",
        [ UNMAP                    ] = "UNMAP",
G
Gerd Hoffmann 已提交
1083
        [ READ_TOC                 ] = "READ_TOC",
1084 1085
        [ REPORT_DENSITY_SUPPORT   ] = "REPORT_DENSITY_SUPPORT",
        [ GET_CONFIGURATION        ] = "GET_CONFIGURATION",
G
Gerd Hoffmann 已提交
1086 1087 1088 1089 1090 1091 1092 1093
        [ LOG_SELECT               ] = "LOG_SELECT",
        [ LOG_SENSE                ] = "LOG_SENSE",
        [ MODE_SELECT_10           ] = "MODE_SELECT_10",
        [ RESERVE_10               ] = "RESERVE_10",
        [ RELEASE_10               ] = "RELEASE_10",
        [ MODE_SENSE_10            ] = "MODE_SENSE_10",
        [ PERSISTENT_RESERVE_IN    ] = "PERSISTENT_RESERVE_IN",
        [ PERSISTENT_RESERVE_OUT   ] = "PERSISTENT_RESERVE_OUT",
1094 1095 1096 1097 1098 1099 1100 1101 1102 1103
        [ WRITE_FILEMARKS_16       ] = "WRITE_FILEMARKS_16",
        [ EXTENDED_COPY            ] = "EXTENDED_COPY",
        [ ATA_PASSTHROUGH          ] = "ATA_PASSTHROUGH",
        [ ACCESS_CONTROL_IN        ] = "ACCESS_CONTROL_IN",
        [ ACCESS_CONTROL_OUT       ] = "ACCESS_CONTROL_OUT",
        [ READ_16                  ] = "READ_16",
        [ COMPARE_AND_WRITE        ] = "COMPARE_AND_WRITE",
        [ WRITE_16                 ] = "WRITE_16",
        [ WRITE_VERIFY_16          ] = "WRITE_VERIFY_16",
        [ VERIFY_16                ] = "VERIFY_16",
P
Paolo Bonzini 已提交
1104 1105 1106
        [ PRE_FETCH_16             ] = "PRE_FETCH_16",
        [ SYNCHRONIZE_CACHE_16     ] = "SPACE_16/SYNCHRONIZE_CACHE_16",
        /* SPACE_16 and SYNCHRONIZE_CACHE_16 use the same operation code */
1107
        [ LOCATE_16                ] = "LOCATE_16",
P
Paolo Bonzini 已提交
1108
        [ WRITE_SAME_16            ] = "ERASE_16/WRITE_SAME_16",
1109
        /* ERASE_16 and WRITE_SAME_16 use the same operation code */
1110
        [ SERVICE_ACTION_IN_16     ] = "SERVICE_ACTION_IN_16",
1111 1112 1113
        [ WRITE_LONG_16            ] = "WRITE_LONG_16",
        [ REPORT_LUNS              ] = "REPORT_LUNS",
        [ BLANK                    ] = "BLANK",
G
Gerd Hoffmann 已提交
1114
        [ MOVE_MEDIUM              ] = "MOVE_MEDIUM",
1115
        [ LOAD_UNLOAD              ] = "LOAD_UNLOAD",
G
Gerd Hoffmann 已提交
1116 1117
        [ READ_12                  ] = "READ_12",
        [ WRITE_12                 ] = "WRITE_12",
P
Paolo Bonzini 已提交
1118 1119
        [ ERASE_12                 ] = "ERASE_12/GET_PERFORMANCE",
        /* ERASE_12 and GET_PERFORMANCE use the same operation code */
1120
        [ SERVICE_ACTION_IN_12     ] = "SERVICE_ACTION_IN_12",
G
Gerd Hoffmann 已提交
1121
        [ WRITE_VERIFY_12          ] = "WRITE_VERIFY_12",
1122
        [ VERIFY_12                ] = "VERIFY_12",
G
Gerd Hoffmann 已提交
1123 1124 1125 1126
        [ SEARCH_HIGH_12           ] = "SEARCH_HIGH_12",
        [ SEARCH_EQUAL_12          ] = "SEARCH_EQUAL_12",
        [ SEARCH_LOW_12            ] = "SEARCH_LOW_12",
        [ READ_ELEMENT_STATUS      ] = "READ_ELEMENT_STATUS",
P
Paolo Bonzini 已提交
1127 1128 1129
        [ SEND_VOLUME_TAG          ] = "SEND_VOLUME_TAG/SET_STREAMING",
        /* SEND_VOLUME_TAG and SET_STREAMING use the same operation code */
        [ READ_CD                  ] = "READ_CD",
1130
        [ READ_DEFECT_DATA_12      ] = "READ_DEFECT_DATA_12",
P
Paolo Bonzini 已提交
1131 1132 1133 1134
        [ READ_DVD_STRUCTURE       ] = "READ_DVD_STRUCTURE",
        [ RESERVE_TRACK            ] = "RESERVE_TRACK",
        [ SEND_CUE_SHEET           ] = "SEND_CUE_SHEET",
        [ SEND_DVD_STRUCTURE       ] = "SEND_DVD_STRUCTURE",
G
Gerd Hoffmann 已提交
1135
        [ SET_CD_SPEED             ] = "SET_CD_SPEED",
P
Paolo Bonzini 已提交
1136 1137 1138
        [ SET_READ_AHEAD           ] = "SET_READ_AHEAD",
        [ ALLOW_OVERWRITE          ] = "ALLOW_OVERWRITE",
        [ MECHANISM_STATUS         ] = "MECHANISM_STATUS",
G
Gerd Hoffmann 已提交
1139 1140 1141 1142 1143 1144 1145
    };

    if (cmd >= ARRAY_SIZE(names) || names[cmd] == NULL)
        return "*UNKNOWN*";
    return names[cmd];
}

P
Paolo Bonzini 已提交
1146 1147 1148 1149 1150 1151 1152 1153 1154
SCSIRequest *scsi_req_ref(SCSIRequest *req)
{
    req->refcount++;
    return req;
}

void scsi_req_unref(SCSIRequest *req)
{
    if (--req->refcount == 0) {
1155 1156
        if (req->ops->free_req) {
            req->ops->free_req(req);
P
Paolo Bonzini 已提交
1157
        }
1158
        g_free(req);
P
Paolo Bonzini 已提交
1159 1160 1161
    }
}

1162 1163 1164 1165 1166 1167
/* Tell the device that we finished processing this chunk of I/O.  It
   will start the next chunk or complete the command.  */
void scsi_req_continue(SCSIRequest *req)
{
    trace_scsi_req_continue(req->dev->id, req->lun, req->tag);
    if (req->cmd.mode == SCSI_XFER_TO_DEV) {
1168
        req->ops->write_data(req);
1169
    } else {
1170
        req->ops->read_data(req);
1171 1172 1173
    }
}

P
Paolo Bonzini 已提交
1174 1175
/* Called by the devices when data is ready for the HBA.  The HBA should
   start a DMA operation to read or fill the device's data buffer.
1176
   Once it completes, calling scsi_req_continue will restart I/O.  */
P
Paolo Bonzini 已提交
1177 1178
void scsi_req_data(SCSIRequest *req, int len)
{
1179 1180 1181 1182 1183 1184
    if (req->io_canceled) {
        trace_scsi_req_data_canceled(req->dev->id, req->lun, req->tag, len);
    } else {
        trace_scsi_req_data(req->dev->id, req->lun, req->tag, len);
        req->bus->info->transfer_data(req, len);
    }
P
Paolo Bonzini 已提交
1185 1186
}

G
Gerd Hoffmann 已提交
1187 1188 1189 1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214
void scsi_req_print(SCSIRequest *req)
{
    FILE *fp = stderr;
    int i;

    fprintf(fp, "[%s id=%d] %s",
            req->dev->qdev.parent_bus->name,
            req->dev->id,
            scsi_command_name(req->cmd.buf[0]));
    for (i = 1; i < req->cmd.len; i++) {
        fprintf(fp, " 0x%02x", req->cmd.buf[i]);
    }
    switch (req->cmd.mode) {
    case SCSI_XFER_NONE:
        fprintf(fp, " - none\n");
        break;
    case SCSI_XFER_FROM_DEV:
        fprintf(fp, " - from-dev len=%zd\n", req->cmd.xfer);
        break;
    case SCSI_XFER_TO_DEV:
        fprintf(fp, " - to-dev len=%zd\n", req->cmd.xfer);
        break;
    default:
        fprintf(fp, " - Oops\n");
        break;
    }
}

1215
void scsi_req_complete(SCSIRequest *req, int status)
G
Gerd Hoffmann 已提交
1216
{
1217 1218
    assert(req->status == -1);
    req->status = status;
1219 1220 1221 1222 1223 1224 1225 1226

    assert(req->sense_len < sizeof(req->sense));
    if (status == GOOD) {
        req->sense_len = 0;
    }

    if (req->sense_len) {
        memcpy(req->dev->sense, req->sense, req->sense_len);
1227 1228 1229 1230 1231
        req->dev->sense_len = req->sense_len;
        req->dev->sense_is_ua = (req->ops == &reqops_unit_attention);
    } else {
        req->dev->sense_len = 0;
        req->dev->sense_is_ua = false;
1232 1233
    }

1234 1235 1236 1237 1238 1239 1240
    /*
     * Unit attention state is now stored in the device's sense buffer
     * if the HBA didn't do autosense.  Clear the pending unit attention
     * flags.
     */
    scsi_clear_unit_attention(req);

P
Paolo Bonzini 已提交
1241
    scsi_req_ref(req);
1242
    scsi_req_dequeue(req);
1243
    req->bus->info->complete(req, req->status);
P
Paolo Bonzini 已提交
1244
    scsi_req_unref(req);
G
Gerd Hoffmann 已提交
1245
}
1246

P
Paolo Bonzini 已提交
1247 1248
void scsi_req_cancel(SCSIRequest *req)
{
1249 1250
    if (!req->enqueued) {
        return;
P
Paolo Bonzini 已提交
1251 1252 1253
    }
    scsi_req_ref(req);
    scsi_req_dequeue(req);
1254 1255 1256 1257
    req->io_canceled = true;
    if (req->ops->cancel_io) {
        req->ops->cancel_io(req);
    }
1258 1259
    if (req->bus->info->cancel) {
        req->bus->info->cancel(req);
P
Paolo Bonzini 已提交
1260 1261 1262 1263
    }
    scsi_req_unref(req);
}

P
Paolo Bonzini 已提交
1264 1265
void scsi_req_abort(SCSIRequest *req, int status)
{
1266 1267 1268 1269 1270 1271
    if (!req->enqueued) {
        return;
    }
    scsi_req_ref(req);
    scsi_req_dequeue(req);
    req->io_canceled = true;
1272 1273
    if (req->ops->cancel_io) {
        req->ops->cancel_io(req);
P
Paolo Bonzini 已提交
1274
    }
1275
    scsi_req_complete(req, status);
1276
    scsi_req_unref(req);
P
Paolo Bonzini 已提交
1277 1278
}

1279
void scsi_device_purge_requests(SCSIDevice *sdev, SCSISense sense)
P
Paolo Bonzini 已提交
1280 1281 1282 1283 1284
{
    SCSIRequest *req;

    while (!QTAILQ_EMPTY(&sdev->requests)) {
        req = QTAILQ_FIRST(&sdev->requests);
P
Paolo Bonzini 已提交
1285
        scsi_req_cancel(req);
P
Paolo Bonzini 已提交
1286
    }
1287
    sdev->unit_attention = sense;
P
Paolo Bonzini 已提交
1288 1289
}

1290 1291
static char *scsibus_get_fw_dev_path(DeviceState *dev)
{
Z
Zhi Yong Wu 已提交
1292
    SCSIDevice *d = DO_UPCAST(SCSIDevice, qdev, dev);
1293 1294
    char path[100];

P
Paolo Bonzini 已提交
1295
    snprintf(path, sizeof(path), "%s@%d,%d,%d", qdev_fw_name(dev),
P
Paolo Bonzini 已提交
1296
             d->channel, d->id, d->lun);
1297

1298 1299 1300
    return strdup(path);
}

P
Paolo Bonzini 已提交
1301
SCSIDevice *scsi_device_find(SCSIBus *bus, int channel, int id, int lun)
1302 1303 1304
{
    DeviceState *qdev;
    SCSIDevice *target_dev = NULL;
1305

1306 1307
    QTAILQ_FOREACH_REVERSE(qdev, &bus->qbus.children, ChildrenHead, sibling) {
        SCSIDevice *dev = DO_UPCAST(SCSIDevice, qdev, qdev);
1308

P
Paolo Bonzini 已提交
1309
        if (dev->channel == channel && dev->id == id) {
1310 1311 1312 1313 1314 1315 1316
            if (dev->lun == lun) {
                return dev;
            }
            target_dev = dev;
        }
    }
    return target_dev;
1317
}