exec.c 77.4 KB
Newer Older
B
bellard 已提交
1
/*
2
 *  Virtual page mapping
3
 *
B
bellard 已提交
4 5 6 7 8 9 10 11 12 13 14 15 16
 *  Copyright (c) 2003 Fabrice Bellard
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
17
 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
B
bellard 已提交
18
 */
B
bellard 已提交
19
#include "config.h"
20
#ifndef _WIN32
B
bellard 已提交
21
#include <sys/types.h>
B
bellard 已提交
22 23
#include <sys/mman.h>
#endif
B
bellard 已提交
24

25
#include "qemu-common.h"
B
bellard 已提交
26
#include "cpu.h"
B
bellard 已提交
27
#include "tcg.h"
28
#include "hw/hw.h"
29
#include "hw/qdev.h"
30
#include "qemu/osdep.h"
31
#include "sysemu/kvm.h"
32
#include "sysemu/sysemu.h"
P
Paolo Bonzini 已提交
33
#include "hw/xen/xen.h"
34 35
#include "qemu/timer.h"
#include "qemu/config-file.h"
36
#include "qemu/error-report.h"
37
#include "exec/memory.h"
38
#include "sysemu/dma.h"
39
#include "exec/address-spaces.h"
40 41
#if defined(CONFIG_USER_ONLY)
#include <qemu.h>
J
Jun Nakajima 已提交
42
#else /* !CONFIG_USER_ONLY */
43
#include "sysemu/xen-mapcache.h"
44
#include "trace.h"
45
#endif
46
#include "exec/cpu-all.h"
B
bellard 已提交
47

48
#include "exec/cputlb.h"
49
#include "translate-all.h"
50

51
#include "exec/memory-internal.h"
52
#include "exec/ram_addr.h"
53

54 55
#include "qemu/range.h"

56
//#define DEBUG_SUBPAGE
T
ths 已提交
57

58
#if !defined(CONFIG_USER_ONLY)
59
static bool in_migration;
P
pbrook 已提交
60

P
Paolo Bonzini 已提交
61
RAMList ram_list = { .blocks = QTAILQ_HEAD_INITIALIZER(ram_list.blocks) };
A
Avi Kivity 已提交
62 63

static MemoryRegion *system_memory;
64
static MemoryRegion *system_io;
A
Avi Kivity 已提交
65

66 67
AddressSpace address_space_io;
AddressSpace address_space_memory;
68

69
MemoryRegion io_mem_rom, io_mem_notdirty;
70
static MemoryRegion io_mem_unassigned;
71

72 73 74
/* RAM is pre-allocated and passed into qemu_ram_alloc_from_ptr */
#define RAM_PREALLOC   (1 << 0)

75 76 77
/* RAM is mmap-ed with MAP_SHARED */
#define RAM_SHARED     (1 << 1)

78
#endif
79

A
Andreas Färber 已提交
80
struct CPUTailQ cpus = QTAILQ_HEAD_INITIALIZER(cpus);
B
bellard 已提交
81 82
/* current CPU in the current thread. It is only valid inside
   cpu_exec() */
83
DEFINE_TLS(CPUState *, current_cpu);
P
pbrook 已提交
84
/* 0 = Do not count executed instructions.
T
ths 已提交
85
   1 = Precise instruction counting.
P
pbrook 已提交
86
   2 = Adaptive rate instruction counting.  */
87
int use_icount;
B
bellard 已提交
88

89
#if !defined(CONFIG_USER_ONLY)
90

91 92 93
typedef struct PhysPageEntry PhysPageEntry;

struct PhysPageEntry {
M
Michael S. Tsirkin 已提交
94
    /* How many bits skip to next level (in units of L2_SIZE). 0 for a leaf. */
95
    uint32_t skip : 6;
M
Michael S. Tsirkin 已提交
96
     /* index into phys_sections (!skip) or phys_map_nodes (skip) */
97
    uint32_t ptr : 26;
98 99
};

100 101
#define PHYS_MAP_NODE_NIL (((uint32_t)~0) >> 6)

102
/* Size of the L2 (and L3, etc) page tables.  */
103
#define ADDR_SPACE_BITS 64
104

M
Michael S. Tsirkin 已提交
105
#define P_L2_BITS 9
106 107 108 109 110
#define P_L2_SIZE (1 << P_L2_BITS)

#define P_L2_LEVELS (((ADDR_SPACE_BITS - TARGET_PAGE_BITS - 1) / P_L2_BITS) + 1)

typedef PhysPageEntry Node[P_L2_SIZE];
111

112 113 114 115 116 117 118 119 120
typedef struct PhysPageMap {
    unsigned sections_nb;
    unsigned sections_nb_alloc;
    unsigned nodes_nb;
    unsigned nodes_nb_alloc;
    Node *nodes;
    MemoryRegionSection *sections;
} PhysPageMap;

121 122 123 124 125
struct AddressSpaceDispatch {
    /* This is a multi-level map on the physical address space.
     * The bottom level has pointers to MemoryRegionSections.
     */
    PhysPageEntry phys_map;
126
    PhysPageMap map;
127
    AddressSpace *as;
128 129
};

130 131 132
#define SUBPAGE_IDX(addr) ((addr) & ~TARGET_PAGE_MASK)
typedef struct subpage_t {
    MemoryRegion iomem;
133
    AddressSpace *as;
134 135 136 137
    hwaddr base;
    uint16_t sub_section[TARGET_PAGE_SIZE];
} subpage_t;

138 139 140 141
#define PHYS_SECTION_UNASSIGNED 0
#define PHYS_SECTION_NOTDIRTY 1
#define PHYS_SECTION_ROM 2
#define PHYS_SECTION_WATCH 3
142

143
static void io_mem_init(void);
A
Avi Kivity 已提交
144
static void memory_map_init(void);
145
static void tcg_commit(MemoryListener *listener);
146

147
static MemoryRegion io_mem_watch;
148
#endif
B
bellard 已提交
149

150
#if !defined(CONFIG_USER_ONLY)
151

152
static void phys_map_node_reserve(PhysPageMap *map, unsigned nodes)
153
{
154 155 156 157
    if (map->nodes_nb + nodes > map->nodes_nb_alloc) {
        map->nodes_nb_alloc = MAX(map->nodes_nb_alloc * 2, 16);
        map->nodes_nb_alloc = MAX(map->nodes_nb_alloc, map->nodes_nb + nodes);
        map->nodes = g_renew(Node, map->nodes, map->nodes_nb_alloc);
158
    }
159 160
}

161
static uint32_t phys_map_node_alloc(PhysPageMap *map)
162 163
{
    unsigned i;
164
    uint32_t ret;
165

166
    ret = map->nodes_nb++;
167
    assert(ret != PHYS_MAP_NODE_NIL);
168
    assert(ret != map->nodes_nb_alloc);
169
    for (i = 0; i < P_L2_SIZE; ++i) {
170 171
        map->nodes[ret][i].skip = 1;
        map->nodes[ret][i].ptr = PHYS_MAP_NODE_NIL;
172
    }
173
    return ret;
174 175
}

176 177
static void phys_page_set_level(PhysPageMap *map, PhysPageEntry *lp,
                                hwaddr *index, hwaddr *nb, uint16_t leaf,
178
                                int level)
179 180 181
{
    PhysPageEntry *p;
    int i;
182
    hwaddr step = (hwaddr)1 << (level * P_L2_BITS);
183

M
Michael S. Tsirkin 已提交
184
    if (lp->skip && lp->ptr == PHYS_MAP_NODE_NIL) {
185 186
        lp->ptr = phys_map_node_alloc(map);
        p = map->nodes[lp->ptr];
187
        if (level == 0) {
188
            for (i = 0; i < P_L2_SIZE; i++) {
M
Michael S. Tsirkin 已提交
189
                p[i].skip = 0;
190
                p[i].ptr = PHYS_SECTION_UNASSIGNED;
191
            }
P
pbrook 已提交
192
        }
193
    } else {
194
        p = map->nodes[lp->ptr];
B
bellard 已提交
195
    }
196
    lp = &p[(*index >> (level * P_L2_BITS)) & (P_L2_SIZE - 1)];
197

198
    while (*nb && lp < &p[P_L2_SIZE]) {
199
        if ((*index & (step - 1)) == 0 && *nb >= step) {
M
Michael S. Tsirkin 已提交
200
            lp->skip = 0;
201
            lp->ptr = leaf;
202 203
            *index += step;
            *nb -= step;
204
        } else {
205
            phys_page_set_level(map, lp, index, nb, leaf, level - 1);
206 207
        }
        ++lp;
208 209 210
    }
}

A
Avi Kivity 已提交
211
static void phys_page_set(AddressSpaceDispatch *d,
A
Avi Kivity 已提交
212
                          hwaddr index, hwaddr nb,
213
                          uint16_t leaf)
214
{
215
    /* Wildly overreserve - it doesn't matter much. */
216
    phys_map_node_reserve(&d->map, 3 * P_L2_LEVELS);
217

218
    phys_page_set_level(&d->map, &d->phys_map, &index, &nb, leaf, P_L2_LEVELS - 1);
B
bellard 已提交
219 220
}

221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278
/* Compact a non leaf page entry. Simply detect that the entry has a single child,
 * and update our entry so we can skip it and go directly to the destination.
 */
static void phys_page_compact(PhysPageEntry *lp, Node *nodes, unsigned long *compacted)
{
    unsigned valid_ptr = P_L2_SIZE;
    int valid = 0;
    PhysPageEntry *p;
    int i;

    if (lp->ptr == PHYS_MAP_NODE_NIL) {
        return;
    }

    p = nodes[lp->ptr];
    for (i = 0; i < P_L2_SIZE; i++) {
        if (p[i].ptr == PHYS_MAP_NODE_NIL) {
            continue;
        }

        valid_ptr = i;
        valid++;
        if (p[i].skip) {
            phys_page_compact(&p[i], nodes, compacted);
        }
    }

    /* We can only compress if there's only one child. */
    if (valid != 1) {
        return;
    }

    assert(valid_ptr < P_L2_SIZE);

    /* Don't compress if it won't fit in the # of bits we have. */
    if (lp->skip + p[valid_ptr].skip >= (1 << 3)) {
        return;
    }

    lp->ptr = p[valid_ptr].ptr;
    if (!p[valid_ptr].skip) {
        /* If our only child is a leaf, make this a leaf. */
        /* By design, we should have made this node a leaf to begin with so we
         * should never reach here.
         * But since it's so simple to handle this, let's do it just in case we
         * change this rule.
         */
        lp->skip = 0;
    } else {
        lp->skip += p[valid_ptr].skip;
    }
}

static void phys_page_compact_all(AddressSpaceDispatch *d, int nodes_nb)
{
    DECLARE_BITMAP(compacted, nodes_nb);

    if (d->phys_map.skip) {
279
        phys_page_compact(&d->phys_map, d->map.nodes, compacted);
280 281 282
    }
}

283
static MemoryRegionSection *phys_page_find(PhysPageEntry lp, hwaddr addr,
284
                                           Node *nodes, MemoryRegionSection *sections)
B
bellard 已提交
285
{
286
    PhysPageEntry *p;
287
    hwaddr index = addr >> TARGET_PAGE_BITS;
288
    int i;
289

M
Michael S. Tsirkin 已提交
290
    for (i = P_L2_LEVELS; lp.skip && (i -= lp.skip) >= 0;) {
291
        if (lp.ptr == PHYS_MAP_NODE_NIL) {
292
            return &sections[PHYS_SECTION_UNASSIGNED];
293
        }
294
        p = nodes[lp.ptr];
295
        lp = p[(index >> (i * P_L2_BITS)) & (P_L2_SIZE - 1)];
296
    }
297 298 299 300 301 302 303 304

    if (sections[lp.ptr].size.hi ||
        range_covers_byte(sections[lp.ptr].offset_within_address_space,
                          sections[lp.ptr].size.lo, addr)) {
        return &sections[lp.ptr];
    } else {
        return &sections[PHYS_SECTION_UNASSIGNED];
    }
305 306
}

B
Blue Swirl 已提交
307 308
bool memory_region_is_unassigned(MemoryRegion *mr)
{
P
Paolo Bonzini 已提交
309
    return mr != &io_mem_rom && mr != &io_mem_notdirty && !mr->rom_device
310
        && mr != &io_mem_watch;
B
bellard 已提交
311
}
312

313
static MemoryRegionSection *address_space_lookup_region(AddressSpaceDispatch *d,
314 315
                                                        hwaddr addr,
                                                        bool resolve_subpage)
316
{
317 318 319
    MemoryRegionSection *section;
    subpage_t *subpage;

320
    section = phys_page_find(d->phys_map, addr, d->map.nodes, d->map.sections);
321 322
    if (resolve_subpage && section->mr->subpage) {
        subpage = container_of(section->mr, subpage_t, iomem);
323
        section = &d->map.sections[subpage->sub_section[SUBPAGE_IDX(addr)]];
324 325
    }
    return section;
326 327
}

328
static MemoryRegionSection *
329
address_space_translate_internal(AddressSpaceDispatch *d, hwaddr addr, hwaddr *xlat,
330
                                 hwaddr *plen, bool resolve_subpage)
331 332
{
    MemoryRegionSection *section;
333
    Int128 diff;
334

335
    section = address_space_lookup_region(d, addr, resolve_subpage);
336 337 338 339 340 341 342
    /* Compute offset within MemoryRegionSection */
    addr -= section->offset_within_address_space;

    /* Compute offset within MemoryRegion */
    *xlat = addr + section->offset_within_region;

    diff = int128_sub(section->mr->size, int128_make64(addr));
343
    *plen = int128_get64(int128_min(diff, int128_make64(*plen)));
344 345
    return section;
}
346

347 348 349 350 351 352 353 354 355 356 357 358
static inline bool memory_access_is_direct(MemoryRegion *mr, bool is_write)
{
    if (memory_region_is_ram(mr)) {
        return !(is_write && mr->readonly);
    }
    if (memory_region_is_romd(mr)) {
        return !is_write;
    }

    return false;
}

359 360 361
MemoryRegion *address_space_translate(AddressSpace *as, hwaddr addr,
                                      hwaddr *xlat, hwaddr *plen,
                                      bool is_write)
362
{
A
Avi Kivity 已提交
363 364 365 366 367 368
    IOMMUTLBEntry iotlb;
    MemoryRegionSection *section;
    MemoryRegion *mr;
    hwaddr len = *plen;

    for (;;) {
369
        section = address_space_translate_internal(as->dispatch, addr, &addr, plen, true);
A
Avi Kivity 已提交
370 371 372 373 374 375
        mr = section->mr;

        if (!mr->iommu_ops) {
            break;
        }

376
        iotlb = mr->iommu_ops->translate(mr, addr, is_write);
A
Avi Kivity 已提交
377 378 379 380 381 382 383 384 385 386 387
        addr = ((iotlb.translated_addr & ~iotlb.addr_mask)
                | (addr & iotlb.addr_mask));
        len = MIN(len, (addr | iotlb.addr_mask) - addr + 1);
        if (!(iotlb.perm & (1 << is_write))) {
            mr = &io_mem_unassigned;
            break;
        }

        as = iotlb.target_as;
    }

388
    if (xen_enabled() && memory_access_is_direct(mr, is_write)) {
389 390 391 392
        hwaddr page = ((addr & TARGET_PAGE_MASK) + TARGET_PAGE_SIZE) - addr;
        len = MIN(page, len);
    }

A
Avi Kivity 已提交
393 394 395
    *plen = len;
    *xlat = addr;
    return mr;
396 397 398 399 400 401
}

MemoryRegionSection *
address_space_translate_for_iotlb(AddressSpace *as, hwaddr addr, hwaddr *xlat,
                                  hwaddr *plen)
{
A
Avi Kivity 已提交
402
    MemoryRegionSection *section;
403
    section = address_space_translate_internal(as->dispatch, addr, xlat, plen, false);
A
Avi Kivity 已提交
404 405 406

    assert(!section->mr->iommu_ops);
    return section;
407
}
408
#endif
B
bellard 已提交
409

410
void cpu_exec_init_all(void)
411
{
412
#if !defined(CONFIG_USER_ONLY)
413
    qemu_mutex_init(&ram_list.mutex);
414 415
    memory_map_init();
    io_mem_init();
416
#endif
417
}
418

419
#if !defined(CONFIG_USER_ONLY)
420 421

static int cpu_common_post_load(void *opaque, int version_id)
B
bellard 已提交
422
{
423
    CPUState *cpu = opaque;
B
bellard 已提交
424

425 426
    /* 0x01 was CPU_INTERRUPT_EXIT. This line can be removed when the
       version_id is increased. */
427
    cpu->interrupt_request &= ~0x01;
428
    tlb_flush(cpu, 1);
429 430

    return 0;
B
bellard 已提交
431
}
B
bellard 已提交
432

433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458
static int cpu_common_pre_load(void *opaque)
{
    CPUState *cpu = opaque;

    cpu->exception_index = 0;

    return 0;
}

static bool cpu_common_exception_index_needed(void *opaque)
{
    CPUState *cpu = opaque;

    return cpu->exception_index != 0;
}

static const VMStateDescription vmstate_cpu_common_exception_index = {
    .name = "cpu_common/exception_index",
    .version_id = 1,
    .minimum_version_id = 1,
    .fields = (VMStateField[]) {
        VMSTATE_INT32(exception_index, CPUState),
        VMSTATE_END_OF_LIST()
    }
};

459
const VMStateDescription vmstate_cpu_common = {
460 461 462
    .name = "cpu_common",
    .version_id = 1,
    .minimum_version_id = 1,
463
    .pre_load = cpu_common_pre_load,
464
    .post_load = cpu_common_post_load,
465
    .fields = (VMStateField[]) {
466 467
        VMSTATE_UINT32(halted, CPUState),
        VMSTATE_UINT32(interrupt_request, CPUState),
468
        VMSTATE_END_OF_LIST()
469 470 471 472 473 474 475 476
    },
    .subsections = (VMStateSubsection[]) {
        {
            .vmsd = &vmstate_cpu_common_exception_index,
            .needed = cpu_common_exception_index_needed,
        } , {
            /* empty */
        }
477 478
    }
};
479

480
#endif
B
bellard 已提交
481

482
CPUState *qemu_get_cpu(int index)
B
bellard 已提交
483
{
A
Andreas Färber 已提交
484
    CPUState *cpu;
B
bellard 已提交
485

A
Andreas Färber 已提交
486
    CPU_FOREACH(cpu) {
487
        if (cpu->cpu_index == index) {
A
Andreas Färber 已提交
488
            return cpu;
489
        }
B
bellard 已提交
490
    }
491

A
Andreas Färber 已提交
492
    return NULL;
B
bellard 已提交
493 494
}

495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510
#if !defined(CONFIG_USER_ONLY)
void tcg_cpu_address_space_init(CPUState *cpu, AddressSpace *as)
{
    /* We only support one address space per cpu at the moment.  */
    assert(cpu->as == as);

    if (cpu->tcg_as_listener) {
        memory_listener_unregister(cpu->tcg_as_listener);
    } else {
        cpu->tcg_as_listener = g_new0(MemoryListener, 1);
    }
    cpu->tcg_as_listener->commit = tcg_commit;
    memory_listener_register(cpu->tcg_as_listener, as);
}
#endif

511
void cpu_exec_init(CPUArchState *env)
B
bellard 已提交
512
{
513
    CPUState *cpu = ENV_GET_CPU(env);
514
    CPUClass *cc = CPU_GET_CLASS(cpu);
A
Andreas Färber 已提交
515
    CPUState *some_cpu;
516 517 518 519 520 521
    int cpu_index;

#if defined(CONFIG_USER_ONLY)
    cpu_list_lock();
#endif
    cpu_index = 0;
A
Andreas Färber 已提交
522
    CPU_FOREACH(some_cpu) {
523 524
        cpu_index++;
    }
525
    cpu->cpu_index = cpu_index;
526
    cpu->numa_node = 0;
527
    QTAILQ_INIT(&cpu->breakpoints);
528
    QTAILQ_INIT(&cpu->watchpoints);
529
#ifndef CONFIG_USER_ONLY
530
    cpu->as = &address_space_memory;
531 532
    cpu->thread_id = qemu_get_thread_id();
#endif
A
Andreas Färber 已提交
533
    QTAILQ_INSERT_TAIL(&cpus, cpu, node);
534 535 536
#if defined(CONFIG_USER_ONLY)
    cpu_list_unlock();
#endif
537 538 539
    if (qdev_get_vmsd(DEVICE(cpu)) == NULL) {
        vmstate_register(NULL, cpu_index, &vmstate_cpu_common, cpu);
    }
540 541 542
#if defined(CPU_SAVE_VERSION) && !defined(CONFIG_USER_ONLY)
    register_savevm(NULL, "cpu", cpu_index, CPU_SAVE_VERSION,
                    cpu_save, cpu_load, env);
543
    assert(cc->vmsd == NULL);
544
    assert(qdev_get_vmsd(DEVICE(cpu)) == NULL);
545
#endif
546 547 548
    if (cc->vmsd != NULL) {
        vmstate_register(NULL, cpu_index, cc->vmsd, cpu);
    }
B
bellard 已提交
549 550
}

B
bellard 已提交
551
#if defined(TARGET_HAS_ICE)
552
#if defined(CONFIG_USER_ONLY)
553
static void breakpoint_invalidate(CPUState *cpu, target_ulong pc)
554 555 556 557
{
    tb_invalidate_phys_page_range(pc, pc + 1, 0);
}
#else
558
static void breakpoint_invalidate(CPUState *cpu, target_ulong pc)
559
{
560 561
    hwaddr phys = cpu_get_phys_page_debug(cpu, pc);
    if (phys != -1) {
562
        tb_invalidate_phys_addr(cpu->as,
563
                                phys | (pc & ~TARGET_PAGE_MASK));
564
    }
565
}
B
bellard 已提交
566
#endif
567
#endif /* TARGET_HAS_ICE */
B
bellard 已提交
568

569
#if defined(CONFIG_USER_ONLY)
570
void cpu_watchpoint_remove_all(CPUState *cpu, int mask)
571 572 573 574

{
}

575
int cpu_watchpoint_insert(CPUState *cpu, vaddr addr, vaddr len,
576 577 578 579 580
                          int flags, CPUWatchpoint **watchpoint)
{
    return -ENOSYS;
}
#else
581
/* Add a watchpoint.  */
582
int cpu_watchpoint_insert(CPUState *cpu, vaddr addr, vaddr len,
583
                          int flags, CPUWatchpoint **watchpoint)
584
{
585
    CPUWatchpoint *wp;
586

587 588
    /* forbid ranges which are empty or run off the end of the address space */
    if (len == 0 || (addr + len - 1) <= addr) {
589 590
        error_report("tried to set invalid watchpoint at %"
                     VADDR_PRIx ", len=%" VADDR_PRIu, addr, len);
591 592
        return -EINVAL;
    }
593
    wp = g_malloc(sizeof(*wp));
594 595

    wp->vaddr = addr;
596
    wp->len = len;
597 598
    wp->flags = flags;

599
    /* keep all GDB-injected watchpoints in front */
600 601 602 603 604
    if (flags & BP_GDB) {
        QTAILQ_INSERT_HEAD(&cpu->watchpoints, wp, entry);
    } else {
        QTAILQ_INSERT_TAIL(&cpu->watchpoints, wp, entry);
    }
605

606
    tlb_flush_page(cpu, addr);
607 608 609 610

    if (watchpoint)
        *watchpoint = wp;
    return 0;
611 612
}

613
/* Remove a specific watchpoint.  */
614
int cpu_watchpoint_remove(CPUState *cpu, vaddr addr, vaddr len,
615
                          int flags)
616
{
617
    CPUWatchpoint *wp;
618

619
    QTAILQ_FOREACH(wp, &cpu->watchpoints, entry) {
620
        if (addr == wp->vaddr && len == wp->len
621
                && flags == (wp->flags & ~BP_WATCHPOINT_HIT)) {
622
            cpu_watchpoint_remove_by_ref(cpu, wp);
623 624 625
            return 0;
        }
    }
626
    return -ENOENT;
627 628
}

629
/* Remove a specific watchpoint by reference.  */
630
void cpu_watchpoint_remove_by_ref(CPUState *cpu, CPUWatchpoint *watchpoint)
631
{
632
    QTAILQ_REMOVE(&cpu->watchpoints, watchpoint, entry);
633

634
    tlb_flush_page(cpu, watchpoint->vaddr);
635

636
    g_free(watchpoint);
637 638 639
}

/* Remove all matching watchpoints.  */
640
void cpu_watchpoint_remove_all(CPUState *cpu, int mask)
641
{
642
    CPUWatchpoint *wp, *next;
643

644
    QTAILQ_FOREACH_SAFE(wp, &cpu->watchpoints, entry, next) {
645 646 647
        if (wp->flags & mask) {
            cpu_watchpoint_remove_by_ref(cpu, wp);
        }
648
    }
649
}
650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670

/* Return true if this watchpoint address matches the specified
 * access (ie the address range covered by the watchpoint overlaps
 * partially or completely with the address range covered by the
 * access).
 */
static inline bool cpu_watchpoint_address_matches(CPUWatchpoint *wp,
                                                  vaddr addr,
                                                  vaddr len)
{
    /* We know the lengths are non-zero, but a little caution is
     * required to avoid errors in the case where the range ends
     * exactly at the top of the address space and so addr + len
     * wraps round to zero.
     */
    vaddr wpend = wp->vaddr + wp->len - 1;
    vaddr addrend = addr + len - 1;

    return !(addr > wpend || wp->vaddr > addrend);
}

671
#endif
672

673
/* Add a breakpoint.  */
674
int cpu_breakpoint_insert(CPUState *cpu, vaddr pc, int flags,
675
                          CPUBreakpoint **breakpoint)
B
bellard 已提交
676
{
B
bellard 已提交
677
#if defined(TARGET_HAS_ICE)
678
    CPUBreakpoint *bp;
679

680
    bp = g_malloc(sizeof(*bp));
B
bellard 已提交
681

682 683 684
    bp->pc = pc;
    bp->flags = flags;

685
    /* keep all GDB-injected breakpoints in front */
686
    if (flags & BP_GDB) {
687
        QTAILQ_INSERT_HEAD(&cpu->breakpoints, bp, entry);
688
    } else {
689
        QTAILQ_INSERT_TAIL(&cpu->breakpoints, bp, entry);
690
    }
691

692
    breakpoint_invalidate(cpu, pc);
693

694
    if (breakpoint) {
695
        *breakpoint = bp;
696
    }
B
bellard 已提交
697 698
    return 0;
#else
699
    return -ENOSYS;
B
bellard 已提交
700 701 702
#endif
}

703
/* Remove a specific breakpoint.  */
704
int cpu_breakpoint_remove(CPUState *cpu, vaddr pc, int flags)
705
{
706
#if defined(TARGET_HAS_ICE)
707 708
    CPUBreakpoint *bp;

709
    QTAILQ_FOREACH(bp, &cpu->breakpoints, entry) {
710
        if (bp->pc == pc && bp->flags == flags) {
711
            cpu_breakpoint_remove_by_ref(cpu, bp);
712 713
            return 0;
        }
714
    }
715 716 717
    return -ENOENT;
#else
    return -ENOSYS;
718 719 720
#endif
}

721
/* Remove a specific breakpoint by reference.  */
722
void cpu_breakpoint_remove_by_ref(CPUState *cpu, CPUBreakpoint *breakpoint)
B
bellard 已提交
723
{
B
bellard 已提交
724
#if defined(TARGET_HAS_ICE)
725 726 727
    QTAILQ_REMOVE(&cpu->breakpoints, breakpoint, entry);

    breakpoint_invalidate(cpu, breakpoint->pc);
728

729
    g_free(breakpoint);
730 731 732 733
#endif
}

/* Remove all matching breakpoints. */
734
void cpu_breakpoint_remove_all(CPUState *cpu, int mask)
735 736
{
#if defined(TARGET_HAS_ICE)
737
    CPUBreakpoint *bp, *next;
738

739
    QTAILQ_FOREACH_SAFE(bp, &cpu->breakpoints, entry, next) {
740 741 742
        if (bp->flags & mask) {
            cpu_breakpoint_remove_by_ref(cpu, bp);
        }
743
    }
B
bellard 已提交
744 745 746
#endif
}

B
bellard 已提交
747 748
/* enable or disable single step mode. EXCP_DEBUG is returned by the
   CPU loop after each instruction */
749
void cpu_single_step(CPUState *cpu, int enabled)
B
bellard 已提交
750
{
B
bellard 已提交
751
#if defined(TARGET_HAS_ICE)
752 753 754
    if (cpu->singlestep_enabled != enabled) {
        cpu->singlestep_enabled = enabled;
        if (kvm_enabled()) {
755
            kvm_update_guest_debug(cpu, 0);
756
        } else {
S
Stuart Brady 已提交
757
            /* must flush all the translated code to avoid inconsistencies */
758
            /* XXX: only flush what is necessary */
759
            CPUArchState *env = cpu->env_ptr;
760 761
            tb_flush(env);
        }
B
bellard 已提交
762 763 764 765
    }
#endif
}

766
void cpu_abort(CPUState *cpu, const char *fmt, ...)
B
bellard 已提交
767 768
{
    va_list ap;
P
pbrook 已提交
769
    va_list ap2;
B
bellard 已提交
770 771

    va_start(ap, fmt);
P
pbrook 已提交
772
    va_copy(ap2, ap);
B
bellard 已提交
773 774 775
    fprintf(stderr, "qemu: fatal: ");
    vfprintf(stderr, fmt, ap);
    fprintf(stderr, "\n");
776
    cpu_dump_state(cpu, stderr, fprintf, CPU_DUMP_FPU | CPU_DUMP_CCOP);
777 778 779 780
    if (qemu_log_enabled()) {
        qemu_log("qemu: fatal: ");
        qemu_log_vprintf(fmt, ap2);
        qemu_log("\n");
781
        log_cpu_state(cpu, CPU_DUMP_FPU | CPU_DUMP_CCOP);
782
        qemu_log_flush();
783
        qemu_log_close();
784
    }
P
pbrook 已提交
785
    va_end(ap2);
786
    va_end(ap);
787 788 789 790 791 792 793 794
#if defined(CONFIG_USER_ONLY)
    {
        struct sigaction act;
        sigfillset(&act.sa_mask);
        act.sa_handler = SIG_DFL;
        sigaction(SIGABRT, &act, NULL);
    }
#endif
B
bellard 已提交
795 796 797
    abort();
}

798
#if !defined(CONFIG_USER_ONLY)
P
Paolo Bonzini 已提交
799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821
static RAMBlock *qemu_get_ram_block(ram_addr_t addr)
{
    RAMBlock *block;

    /* The list is protected by the iothread lock here.  */
    block = ram_list.mru_block;
    if (block && addr - block->offset < block->length) {
        goto found;
    }
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
        if (addr - block->offset < block->length) {
            goto found;
        }
    }

    fprintf(stderr, "Bad ram offset %" PRIx64 "\n", (uint64_t)addr);
    abort();

found:
    ram_list.mru_block = block;
    return block;
}

822
static void tlb_reset_dirty_range_all(ram_addr_t start, ram_addr_t length)
J
Juan Quintela 已提交
823
{
P
Paolo Bonzini 已提交
824
    ram_addr_t start1;
825 826 827 828 829
    RAMBlock *block;
    ram_addr_t end;

    end = TARGET_PAGE_ALIGN(start + length);
    start &= TARGET_PAGE_MASK;
J
Juan Quintela 已提交
830

P
Paolo Bonzini 已提交
831 832 833 834
    block = qemu_get_ram_block(start);
    assert(block == qemu_get_ram_block(end - 1));
    start1 = (uintptr_t)block->host + (start - block->offset);
    cpu_tlb_reset_dirty_all(start1, length);
J
Juan Quintela 已提交
835 836
}

P
pbrook 已提交
837
/* Note: start and end must be within the same ram block.  */
838
void cpu_physical_memory_reset_dirty(ram_addr_t start, ram_addr_t length,
839
                                     unsigned client)
840 841 842
{
    if (length == 0)
        return;
843
    cpu_physical_memory_clear_dirty_range(start, length, client);
B
bellard 已提交
844

J
Juan Quintela 已提交
845
    if (tcg_enabled()) {
846
        tlb_reset_dirty_range_all(start, length);
P
pbrook 已提交
847
    }
848 849
}

850
static void cpu_physical_memory_set_dirty_tracking(bool enable)
A
aliguori 已提交
851 852 853 854
{
    in_migration = enable;
}

855
hwaddr memory_region_section_get_iotlb(CPUState *cpu,
856 857 858 859 860
                                       MemoryRegionSection *section,
                                       target_ulong vaddr,
                                       hwaddr paddr, hwaddr xlat,
                                       int prot,
                                       target_ulong *address)
B
Blue Swirl 已提交
861
{
A
Avi Kivity 已提交
862
    hwaddr iotlb;
B
Blue Swirl 已提交
863 864
    CPUWatchpoint *wp;

865
    if (memory_region_is_ram(section->mr)) {
B
Blue Swirl 已提交
866 867
        /* Normal RAM.  */
        iotlb = (memory_region_get_ram_addr(section->mr) & TARGET_PAGE_MASK)
868
            + xlat;
B
Blue Swirl 已提交
869
        if (!section->readonly) {
870
            iotlb |= PHYS_SECTION_NOTDIRTY;
B
Blue Swirl 已提交
871
        } else {
872
            iotlb |= PHYS_SECTION_ROM;
B
Blue Swirl 已提交
873 874
        }
    } else {
875
        iotlb = section - section->address_space->dispatch->map.sections;
876
        iotlb += xlat;
B
Blue Swirl 已提交
877 878 879 880
    }

    /* Make accesses to pages with watchpoints go via the
       watchpoint trap routines.  */
881
    QTAILQ_FOREACH(wp, &cpu->watchpoints, entry) {
882
        if (cpu_watchpoint_address_matches(wp, vaddr, TARGET_PAGE_SIZE)) {
B
Blue Swirl 已提交
883 884
            /* Avoid trapping reads of pages with a write breakpoint. */
            if ((prot & PAGE_WRITE) || (wp->flags & BP_MEM_READ)) {
885
                iotlb = PHYS_SECTION_WATCH + paddr;
B
Blue Swirl 已提交
886 887 888 889 890 891 892 893
                *address |= TLB_MMIO;
                break;
            }
        }
    }

    return iotlb;
}
894 895
#endif /* defined(CONFIG_USER_ONLY) */

896
#if !defined(CONFIG_USER_ONLY)
897

A
Anthony Liguori 已提交
898
static int subpage_register (subpage_t *mmio, uint32_t start, uint32_t end,
899
                             uint16_t section);
900
static subpage_t *subpage_init(AddressSpace *as, hwaddr base);
901

902
static void *(*phys_mem_alloc)(size_t size) = qemu_anon_ram_alloc;
903 904 905 906 907 908

/*
 * Set a custom physical guest memory alloator.
 * Accelerators with unusual needs may need this.  Hopefully, we can
 * get rid of it eventually.
 */
909
void phys_mem_set_alloc(void *(*alloc)(size_t))
910 911 912 913
{
    phys_mem_alloc = alloc;
}

914 915
static uint16_t phys_section_add(PhysPageMap *map,
                                 MemoryRegionSection *section)
916
{
917 918 919 920
    /* The physical section number is ORed with a page-aligned
     * pointer to produce the iotlb entries.  Thus it should
     * never overflow into the page-aligned value.
     */
921
    assert(map->sections_nb < TARGET_PAGE_SIZE);
922

923 924 925 926
    if (map->sections_nb == map->sections_nb_alloc) {
        map->sections_nb_alloc = MAX(map->sections_nb_alloc * 2, 16);
        map->sections = g_renew(MemoryRegionSection, map->sections,
                                map->sections_nb_alloc);
927
    }
928
    map->sections[map->sections_nb] = *section;
P
Paolo Bonzini 已提交
929
    memory_region_ref(section->mr);
930
    return map->sections_nb++;
931 932
}

933 934
static void phys_section_destroy(MemoryRegion *mr)
{
P
Paolo Bonzini 已提交
935 936
    memory_region_unref(mr);

937 938
    if (mr->subpage) {
        subpage_t *subpage = container_of(mr, subpage_t, iomem);
P
Peter Crosthwaite 已提交
939
        object_unref(OBJECT(&subpage->iomem));
940 941 942 943
        g_free(subpage);
    }
}

P
Paolo Bonzini 已提交
944
static void phys_sections_free(PhysPageMap *map)
945
{
946 947
    while (map->sections_nb > 0) {
        MemoryRegionSection *section = &map->sections[--map->sections_nb];
948 949
        phys_section_destroy(section->mr);
    }
950 951
    g_free(map->sections);
    g_free(map->nodes);
952 953
}

A
Avi Kivity 已提交
954
static void register_subpage(AddressSpaceDispatch *d, MemoryRegionSection *section)
955 956
{
    subpage_t *subpage;
A
Avi Kivity 已提交
957
    hwaddr base = section->offset_within_address_space
958
        & TARGET_PAGE_MASK;
959
    MemoryRegionSection *existing = phys_page_find(d->phys_map, base,
960
                                                   d->map.nodes, d->map.sections);
961 962
    MemoryRegionSection subsection = {
        .offset_within_address_space = base,
963
        .size = int128_make64(TARGET_PAGE_SIZE),
964
    };
A
Avi Kivity 已提交
965
    hwaddr start, end;
966

967
    assert(existing->mr->subpage || existing->mr == &io_mem_unassigned);
968

969
    if (!(existing->mr->subpage)) {
970
        subpage = subpage_init(d->as, base);
971
        subsection.address_space = d->as;
972
        subsection.mr = &subpage->iomem;
A
Avi Kivity 已提交
973
        phys_page_set(d, base >> TARGET_PAGE_BITS, 1,
974
                      phys_section_add(&d->map, &subsection));
975
    } else {
976
        subpage = container_of(existing->mr, subpage_t, iomem);
977 978
    }
    start = section->offset_within_address_space & ~TARGET_PAGE_MASK;
979
    end = start + int128_get64(section->size) - 1;
980 981
    subpage_register(subpage, start, end,
                     phys_section_add(&d->map, section));
982 983 984
}


985 986
static void register_multipage(AddressSpaceDispatch *d,
                               MemoryRegionSection *section)
987
{
A
Avi Kivity 已提交
988
    hwaddr start_addr = section->offset_within_address_space;
989
    uint16_t section_index = phys_section_add(&d->map, section);
990 991
    uint64_t num_pages = int128_get64(int128_rshift(section->size,
                                                    TARGET_PAGE_BITS));
992

993 994
    assert(num_pages);
    phys_page_set(d, start_addr >> TARGET_PAGE_BITS, num_pages, section_index);
995 996
}

A
Avi Kivity 已提交
997
static void mem_add(MemoryListener *listener, MemoryRegionSection *section)
998
{
999
    AddressSpace *as = container_of(listener, AddressSpace, dispatch_listener);
1000
    AddressSpaceDispatch *d = as->next_dispatch;
1001
    MemoryRegionSection now = *section, remain = *section;
1002
    Int128 page_size = int128_make64(TARGET_PAGE_SIZE);
1003

1004 1005 1006 1007
    if (now.offset_within_address_space & ~TARGET_PAGE_MASK) {
        uint64_t left = TARGET_PAGE_ALIGN(now.offset_within_address_space)
                       - now.offset_within_address_space;

1008
        now.size = int128_min(int128_make64(left), now.size);
A
Avi Kivity 已提交
1009
        register_subpage(d, &now);
1010
    } else {
1011
        now.size = int128_zero();
1012
    }
1013 1014 1015 1016
    while (int128_ne(remain.size, now.size)) {
        remain.size = int128_sub(remain.size, now.size);
        remain.offset_within_address_space += int128_get64(now.size);
        remain.offset_within_region += int128_get64(now.size);
1017
        now = remain;
1018
        if (int128_lt(remain.size, page_size)) {
1019
            register_subpage(d, &now);
1020
        } else if (remain.offset_within_address_space & ~TARGET_PAGE_MASK) {
1021
            now.size = page_size;
A
Avi Kivity 已提交
1022
            register_subpage(d, &now);
1023
        } else {
1024
            now.size = int128_and(now.size, int128_neg(page_size));
A
Avi Kivity 已提交
1025
            register_multipage(d, &now);
1026
        }
1027 1028 1029
    }
}

1030 1031 1032 1033 1034 1035
void qemu_flush_coalesced_mmio_buffer(void)
{
    if (kvm_enabled())
        kvm_flush_coalesced_mmio_buffer();
}

1036 1037 1038 1039 1040 1041 1042 1043 1044 1045
void qemu_mutex_lock_ramlist(void)
{
    qemu_mutex_lock(&ram_list.mutex);
}

void qemu_mutex_unlock_ramlist(void)
{
    qemu_mutex_unlock(&ram_list.mutex);
}

1046
#ifdef __linux__
1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057

#include <sys/vfs.h>

#define HUGETLBFS_MAGIC       0x958458f6

static long gethugepagesize(const char *path)
{
    struct statfs fs;
    int ret;

    do {
Y
Yoshiaki Tamura 已提交
1058
        ret = statfs(path, &fs);
1059 1060 1061
    } while (ret != 0 && errno == EINTR);

    if (ret != 0) {
Y
Yoshiaki Tamura 已提交
1062 1063
        perror(path);
        return 0;
1064 1065 1066
    }

    if (fs.f_type != HUGETLBFS_MAGIC)
Y
Yoshiaki Tamura 已提交
1067
        fprintf(stderr, "Warning: path not on HugeTLBFS: %s\n", path);
1068 1069 1070 1071

    return fs.f_bsize;
}

A
Alex Williamson 已提交
1072 1073
static void *file_ram_alloc(RAMBlock *block,
                            ram_addr_t memory,
1074 1075
                            const char *path,
                            Error **errp)
1076 1077
{
    char *filename;
1078 1079
    char *sanitized_name;
    char *c;
1080 1081 1082 1083 1084 1085
    void *area;
    int fd;
    unsigned long hpagesize;

    hpagesize = gethugepagesize(path);
    if (!hpagesize) {
1086
        goto error;
1087 1088 1089 1090 1091 1092 1093
    }

    if (memory < hpagesize) {
        return NULL;
    }

    if (kvm_enabled() && !kvm_has_sync_mmu()) {
1094 1095
        error_setg(errp,
                   "host lacks kvm mmu notifiers, -mem-path unsupported");
1096
        goto error;
1097 1098
    }

1099
    /* Make name safe to use with mkstemp by replacing '/' with '_'. */
1100
    sanitized_name = g_strdup(memory_region_name(block->mr));
1101 1102 1103 1104 1105 1106 1107 1108
    for (c = sanitized_name; *c != '\0'; c++) {
        if (*c == '/')
            *c = '_';
    }

    filename = g_strdup_printf("%s/qemu_back_mem.%s.XXXXXX", path,
                               sanitized_name);
    g_free(sanitized_name);
1109 1110 1111

    fd = mkstemp(filename);
    if (fd < 0) {
1112 1113
        error_setg_errno(errp, errno,
                         "unable to create backing store for hugepages");
1114
        g_free(filename);
1115
        goto error;
1116 1117
    }
    unlink(filename);
1118
    g_free(filename);
1119 1120 1121 1122 1123 1124 1125 1126 1127

    memory = (memory+hpagesize-1) & ~(hpagesize-1);

    /*
     * ftruncate is not supported by hugetlbfs in older
     * hosts, so don't bother bailing out on errors.
     * If anything goes wrong with it under other filesystems,
     * mmap will fail.
     */
1128
    if (ftruncate(fd, memory)) {
Y
Yoshiaki Tamura 已提交
1129
        perror("ftruncate");
1130
    }
1131

1132 1133 1134
    area = mmap(0, memory, PROT_READ | PROT_WRITE,
                (block->flags & RAM_SHARED ? MAP_SHARED : MAP_PRIVATE),
                fd, 0);
1135
    if (area == MAP_FAILED) {
1136 1137
        error_setg_errno(errp, errno,
                         "unable to map backing store for hugepages");
Y
Yoshiaki Tamura 已提交
1138
        close(fd);
1139
        goto error;
1140
    }
1141 1142

    if (mem_prealloc) {
1143
        os_mem_prealloc(fd, area, memory);
1144 1145
    }

A
Alex Williamson 已提交
1146
    block->fd = fd;
1147
    return area;
1148 1149 1150 1151 1152 1153

error:
    if (mem_prealloc) {
        exit(1);
    }
    return NULL;
1154 1155 1156
}
#endif

1157
static ram_addr_t find_ram_offset(ram_addr_t size)
A
Alex Williamson 已提交
1158 1159
{
    RAMBlock *block, *next_block;
A
Alex Williamson 已提交
1160
    ram_addr_t offset = RAM_ADDR_MAX, mingap = RAM_ADDR_MAX;
A
Alex Williamson 已提交
1161

1162 1163
    assert(size != 0); /* it would hand out same offset multiple times */

P
Paolo Bonzini 已提交
1164
    if (QTAILQ_EMPTY(&ram_list.blocks))
A
Alex Williamson 已提交
1165 1166
        return 0;

P
Paolo Bonzini 已提交
1167
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1168
        ram_addr_t end, next = RAM_ADDR_MAX;
A
Alex Williamson 已提交
1169 1170 1171

        end = block->offset + block->length;

P
Paolo Bonzini 已提交
1172
        QTAILQ_FOREACH(next_block, &ram_list.blocks, next) {
A
Alex Williamson 已提交
1173 1174 1175 1176 1177
            if (next_block->offset >= end) {
                next = MIN(next, next_block->offset);
            }
        }
        if (next - end >= size && next - end < mingap) {
A
Alex Williamson 已提交
1178
            offset = end;
A
Alex Williamson 已提交
1179 1180 1181
            mingap = next - end;
        }
    }
A
Alex Williamson 已提交
1182 1183 1184 1185 1186 1187 1188

    if (offset == RAM_ADDR_MAX) {
        fprintf(stderr, "Failed to find gap of requested size: %" PRIu64 "\n",
                (uint64_t)size);
        abort();
    }

A
Alex Williamson 已提交
1189 1190 1191
    return offset;
}

J
Juan Quintela 已提交
1192
ram_addr_t last_ram_offset(void)
1193 1194 1195 1196
{
    RAMBlock *block;
    ram_addr_t last = 0;

P
Paolo Bonzini 已提交
1197
    QTAILQ_FOREACH(block, &ram_list.blocks, next)
1198 1199 1200 1201 1202
        last = MAX(last, block->offset + block->length);

    return last;
}

1203 1204 1205 1206 1207
static void qemu_ram_setup_dump(void *addr, ram_addr_t size)
{
    int ret;

    /* Use MADV_DONTDUMP, if user doesn't want the guest memory in the core */
1208 1209
    if (!qemu_opt_get_bool(qemu_get_machine_opts(),
                           "dump-guest-core", true)) {
1210 1211 1212 1213 1214 1215 1216 1217 1218
        ret = qemu_madvise(addr, size, QEMU_MADV_DONTDUMP);
        if (ret) {
            perror("qemu_madvise");
            fprintf(stderr, "madvise doesn't support MADV_DONTDUMP, "
                            "but dump_guest_core=off specified\n");
        }
    }
}

1219
static RAMBlock *find_ram_block(ram_addr_t addr)
1220
{
1221
    RAMBlock *block;
1222

P
Paolo Bonzini 已提交
1223
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1224
        if (block->offset == addr) {
1225
            return block;
1226 1227
        }
    }
1228 1229 1230 1231 1232 1233 1234 1235 1236

    return NULL;
}

void qemu_ram_set_idstr(ram_addr_t addr, const char *name, DeviceState *dev)
{
    RAMBlock *new_block = find_ram_block(addr);
    RAMBlock *block;

1237 1238
    assert(new_block);
    assert(!new_block->idstr[0]);
1239

1240 1241
    if (dev) {
        char *id = qdev_get_dev_path(dev);
1242 1243
        if (id) {
            snprintf(new_block->idstr, sizeof(new_block->idstr), "%s/", id);
1244
            g_free(id);
1245 1246 1247 1248
        }
    }
    pstrcat(new_block->idstr, sizeof(new_block->idstr), name);

1249 1250
    /* This assumes the iothread lock is taken here too.  */
    qemu_mutex_lock_ramlist();
P
Paolo Bonzini 已提交
1251
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1252
        if (block != new_block && !strcmp(block->idstr, new_block->idstr)) {
1253 1254 1255 1256 1257
            fprintf(stderr, "RAMBlock \"%s\" already registered, abort!\n",
                    new_block->idstr);
            abort();
        }
    }
1258
    qemu_mutex_unlock_ramlist();
1259 1260
}

1261 1262 1263 1264 1265 1266 1267 1268 1269
void qemu_ram_unset_idstr(ram_addr_t addr)
{
    RAMBlock *block = find_ram_block(addr);

    if (block) {
        memset(block->idstr, 0, sizeof(block->idstr));
    }
}

1270 1271
static int memory_try_enable_merging(void *addr, size_t len)
{
1272
    if (!qemu_opt_get_bool(qemu_get_machine_opts(), "mem-merge", true)) {
1273 1274 1275 1276 1277 1278 1279
        /* disabled by the user */
        return 0;
    }

    return qemu_madvise(addr, len, QEMU_MADV_MERGEABLE);
}

1280
static ram_addr_t ram_block_add(RAMBlock *new_block)
1281
{
1282
    RAMBlock *block;
1283 1284 1285
    ram_addr_t old_ram_size, new_ram_size;

    old_ram_size = last_ram_offset() >> TARGET_PAGE_BITS;
1286

1287 1288
    /* This assumes the iothread lock is taken here too.  */
    qemu_mutex_lock_ramlist();
1289 1290 1291 1292 1293 1294 1295
    new_block->offset = find_ram_offset(new_block->length);

    if (!new_block->host) {
        if (xen_enabled()) {
            xen_ram_alloc(new_block->offset, new_block->length, new_block->mr);
        } else {
            new_block->host = phys_mem_alloc(new_block->length);
1296 1297
            if (!new_block->host) {
                fprintf(stderr, "Cannot set up guest memory '%s': %s\n",
1298
                        memory_region_name(new_block->mr), strerror(errno));
1299 1300
                exit(1);
            }
1301
            memory_try_enable_merging(new_block->host, new_block->length);
1302
        }
1303
    }
P
pbrook 已提交
1304

1305 1306 1307 1308 1309 1310 1311 1312 1313 1314 1315
    /* Keep the list sorted from biggest to smallest block.  */
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
        if (block->length < new_block->length) {
            break;
        }
    }
    if (block) {
        QTAILQ_INSERT_BEFORE(block, new_block, next);
    } else {
        QTAILQ_INSERT_TAIL(&ram_list.blocks, new_block, next);
    }
1316
    ram_list.mru_block = NULL;
P
pbrook 已提交
1317

U
Umesh Deshpande 已提交
1318
    ram_list.version++;
1319
    qemu_mutex_unlock_ramlist();
U
Umesh Deshpande 已提交
1320

1321 1322 1323
    new_ram_size = last_ram_offset() >> TARGET_PAGE_BITS;

    if (new_ram_size > old_ram_size) {
1324 1325 1326 1327 1328 1329
        int i;
        for (i = 0; i < DIRTY_MEMORY_NUM; i++) {
            ram_list.dirty_memory[i] =
                bitmap_zero_extend(ram_list.dirty_memory[i],
                                   old_ram_size, new_ram_size);
       }
1330
    }
1331
    cpu_physical_memory_set_dirty_range(new_block->offset, new_block->length);
P
pbrook 已提交
1332

1333 1334 1335
    qemu_ram_setup_dump(new_block->host, new_block->length);
    qemu_madvise(new_block->host, new_block->length, QEMU_MADV_HUGEPAGE);
    qemu_madvise(new_block->host, new_block->length, QEMU_MADV_DONTFORK);
1336

1337 1338 1339
    if (kvm_enabled()) {
        kvm_setup_guest_memory(new_block->host, new_block->length);
    }
1340

P
pbrook 已提交
1341 1342
    return new_block->offset;
}
B
bellard 已提交
1343

1344
#ifdef __linux__
1345
ram_addr_t qemu_ram_alloc_from_file(ram_addr_t size, MemoryRegion *mr,
1346
                                    bool share, const char *mem_path,
1347
                                    Error **errp)
1348 1349 1350 1351
{
    RAMBlock *new_block;

    if (xen_enabled()) {
1352 1353
        error_setg(errp, "-mem-path not supported with Xen");
        return -1;
1354 1355 1356 1357 1358 1359 1360 1361
    }

    if (phys_mem_alloc != qemu_anon_ram_alloc) {
        /*
         * file_ram_alloc() needs to allocate just like
         * phys_mem_alloc, but we haven't bothered to provide
         * a hook there.
         */
1362 1363 1364
        error_setg(errp,
                   "-mem-path not supported with this accelerator");
        return -1;
1365 1366 1367 1368 1369 1370
    }

    size = TARGET_PAGE_ALIGN(size);
    new_block = g_malloc0(sizeof(*new_block));
    new_block->mr = mr;
    new_block->length = size;
1371
    new_block->flags = share ? RAM_SHARED : 0;
1372 1373 1374 1375 1376 1377 1378
    new_block->host = file_ram_alloc(new_block, size,
                                     mem_path, errp);
    if (!new_block->host) {
        g_free(new_block);
        return -1;
    }

1379 1380
    return ram_block_add(new_block);
}
1381
#endif
1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394

ram_addr_t qemu_ram_alloc_from_ptr(ram_addr_t size, void *host,
                                   MemoryRegion *mr)
{
    RAMBlock *new_block;

    size = TARGET_PAGE_ALIGN(size);
    new_block = g_malloc0(sizeof(*new_block));
    new_block->mr = mr;
    new_block->length = size;
    new_block->fd = -1;
    new_block->host = host;
    if (host) {
1395
        new_block->flags |= RAM_PREALLOC;
1396 1397 1398 1399
    }
    return ram_block_add(new_block);
}

1400
ram_addr_t qemu_ram_alloc(ram_addr_t size, MemoryRegion *mr)
1401
{
1402
    return qemu_ram_alloc_from_ptr(size, NULL, mr);
1403 1404
}

1405 1406 1407 1408
void qemu_ram_free_from_ptr(ram_addr_t addr)
{
    RAMBlock *block;

1409 1410
    /* This assumes the iothread lock is taken here too.  */
    qemu_mutex_lock_ramlist();
P
Paolo Bonzini 已提交
1411
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1412
        if (addr == block->offset) {
P
Paolo Bonzini 已提交
1413
            QTAILQ_REMOVE(&ram_list.blocks, block, next);
1414
            ram_list.mru_block = NULL;
U
Umesh Deshpande 已提交
1415
            ram_list.version++;
1416
            g_free(block);
1417
            break;
1418 1419
        }
    }
1420
    qemu_mutex_unlock_ramlist();
1421 1422
}

A
Anthony Liguori 已提交
1423
void qemu_ram_free(ram_addr_t addr)
B
bellard 已提交
1424
{
A
Alex Williamson 已提交
1425 1426
    RAMBlock *block;

1427 1428
    /* This assumes the iothread lock is taken here too.  */
    qemu_mutex_lock_ramlist();
P
Paolo Bonzini 已提交
1429
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
A
Alex Williamson 已提交
1430
        if (addr == block->offset) {
P
Paolo Bonzini 已提交
1431
            QTAILQ_REMOVE(&ram_list.blocks, block, next);
1432
            ram_list.mru_block = NULL;
U
Umesh Deshpande 已提交
1433
            ram_list.version++;
1434
            if (block->flags & RAM_PREALLOC) {
H
Huang Ying 已提交
1435
                ;
1436 1437
            } else if (xen_enabled()) {
                xen_invalidate_map_cache_entry(block->host);
1438
#ifndef _WIN32
1439 1440 1441
            } else if (block->fd >= 0) {
                munmap(block->host, block->length);
                close(block->fd);
1442
#endif
A
Alex Williamson 已提交
1443
            } else {
1444
                qemu_anon_ram_free(block->host, block->length);
A
Alex Williamson 已提交
1445
            }
1446
            g_free(block);
1447
            break;
A
Alex Williamson 已提交
1448 1449
        }
    }
1450
    qemu_mutex_unlock_ramlist();
A
Alex Williamson 已提交
1451

B
bellard 已提交
1452 1453
}

H
Huang Ying 已提交
1454 1455 1456 1457 1458 1459 1460 1461
#ifndef _WIN32
void qemu_ram_remap(ram_addr_t addr, ram_addr_t length)
{
    RAMBlock *block;
    ram_addr_t offset;
    int flags;
    void *area, *vaddr;

P
Paolo Bonzini 已提交
1462
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
H
Huang Ying 已提交
1463 1464 1465
        offset = addr - block->offset;
        if (offset < block->length) {
            vaddr = block->host + offset;
1466
            if (block->flags & RAM_PREALLOC) {
H
Huang Ying 已提交
1467
                ;
1468 1469
            } else if (xen_enabled()) {
                abort();
H
Huang Ying 已提交
1470 1471 1472
            } else {
                flags = MAP_FIXED;
                munmap(vaddr, length);
1473
                if (block->fd >= 0) {
1474 1475
                    flags |= (block->flags & RAM_SHARED ?
                              MAP_SHARED : MAP_PRIVATE);
1476 1477
                    area = mmap(vaddr, length, PROT_READ | PROT_WRITE,
                                flags, block->fd, offset);
H
Huang Ying 已提交
1478
                } else {
1479 1480 1481 1482 1483 1484 1485
                    /*
                     * Remap needs to match alloc.  Accelerators that
                     * set phys_mem_alloc never remap.  If they did,
                     * we'd need a remap hook here.
                     */
                    assert(phys_mem_alloc == qemu_anon_ram_alloc);

H
Huang Ying 已提交
1486 1487 1488 1489 1490
                    flags |= MAP_PRIVATE | MAP_ANONYMOUS;
                    area = mmap(vaddr, length, PROT_READ | PROT_WRITE,
                                flags, -1, 0);
                }
                if (area != vaddr) {
1491 1492
                    fprintf(stderr, "Could not remap addr: "
                            RAM_ADDR_FMT "@" RAM_ADDR_FMT "\n",
H
Huang Ying 已提交
1493 1494 1495
                            length, addr);
                    exit(1);
                }
1496
                memory_try_enable_merging(vaddr, length);
1497
                qemu_ram_setup_dump(vaddr, length);
H
Huang Ying 已提交
1498 1499 1500 1501 1502 1503 1504
            }
            return;
        }
    }
}
#endif /* !_WIN32 */

1505 1506 1507 1508 1509 1510 1511
int qemu_get_ram_fd(ram_addr_t addr)
{
    RAMBlock *block = qemu_get_ram_block(addr);

    return block->fd;
}

1512 1513 1514 1515 1516 1517 1518
void *qemu_get_ram_block_host_ptr(ram_addr_t addr)
{
    RAMBlock *block = qemu_get_ram_block(addr);

    return block->host;
}

1519 1520 1521 1522 1523 1524 1525 1526 1527 1528 1529 1530
/* Return a host pointer to ram allocated with qemu_ram_alloc.
   With the exception of the softmmu code in this file, this should
   only be used for local memory (e.g. video ram) that the device owns,
   and knows it isn't going to access beyond the end of the block.

   It should not be used for general purpose DMA.
   Use cpu_physical_memory_map/cpu_physical_memory_rw instead.
 */
void *qemu_get_ram_ptr(ram_addr_t addr)
{
    RAMBlock *block = qemu_get_ram_block(addr);

1531 1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543
    if (xen_enabled()) {
        /* We need to check if the requested address is in the RAM
         * because we don't want to map the entire memory in QEMU.
         * In that case just map until the end of the page.
         */
        if (block->offset == 0) {
            return xen_map_cache(addr, 0, 0);
        } else if (block->host == NULL) {
            block->host =
                xen_map_cache(block->offset, block->length, 1);
        }
    }
    return block->host + (addr - block->offset);
1544 1545
}

1546 1547
/* Return a host pointer to guest's ram. Similar to qemu_get_ram_ptr
 * but takes a size argument */
1548
static void *qemu_ram_ptr_length(ram_addr_t addr, hwaddr *size)
1549
{
1550 1551 1552
    if (*size == 0) {
        return NULL;
    }
1553
    if (xen_enabled()) {
J
Jan Kiszka 已提交
1554
        return xen_map_cache(addr, *size, 1);
1555
    } else {
1556 1557
        RAMBlock *block;

P
Paolo Bonzini 已提交
1558
        QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570
            if (addr - block->offset < block->length) {
                if (addr - block->offset + *size > block->length)
                    *size = block->length - addr + block->offset;
                return block->host + (addr - block->offset);
            }
        }

        fprintf(stderr, "Bad ram offset %" PRIx64 "\n", (uint64_t)addr);
        abort();
    }
}

1571 1572
/* Some of the softmmu routines need to translate from a host pointer
   (typically a TLB entry) back to a ram offset.  */
1573
MemoryRegion *qemu_ram_addr_from_host(void *ptr, ram_addr_t *ram_addr)
P
pbrook 已提交
1574
{
P
pbrook 已提交
1575 1576 1577
    RAMBlock *block;
    uint8_t *host = ptr;

1578
    if (xen_enabled()) {
J
Jan Kiszka 已提交
1579
        *ram_addr = xen_ram_addr_from_mapcache(ptr);
1580
        return qemu_get_ram_block(*ram_addr)->mr;
1581 1582
    }

1583 1584 1585 1586 1587
    block = ram_list.mru_block;
    if (block && block->host && host - block->host < block->length) {
        goto found;
    }

P
Paolo Bonzini 已提交
1588
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
J
Jun Nakajima 已提交
1589 1590 1591 1592
        /* This case append when the block is not mapped. */
        if (block->host == NULL) {
            continue;
        }
A
Alex Williamson 已提交
1593
        if (host - block->host < block->length) {
1594
            goto found;
A
Alex Williamson 已提交
1595
        }
P
pbrook 已提交
1596
    }
J
Jun Nakajima 已提交
1597

1598
    return NULL;
1599 1600 1601

found:
    *ram_addr = block->offset + (host - block->host);
1602
    return block->mr;
M
Marcelo Tosatti 已提交
1603
}
A
Alex Williamson 已提交
1604

A
Avi Kivity 已提交
1605
static void notdirty_mem_write(void *opaque, hwaddr ram_addr,
1606
                               uint64_t val, unsigned size)
1607
{
1608
    if (!cpu_physical_memory_get_dirty_flag(ram_addr, DIRTY_MEMORY_CODE)) {
1609
        tb_invalidate_phys_page_fast(ram_addr, size);
1610
    }
1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622
    switch (size) {
    case 1:
        stb_p(qemu_get_ram_ptr(ram_addr), val);
        break;
    case 2:
        stw_p(qemu_get_ram_ptr(ram_addr), val);
        break;
    case 4:
        stl_p(qemu_get_ram_ptr(ram_addr), val);
        break;
    default:
        abort();
1623
    }
1624
    cpu_physical_memory_set_dirty_range_nocode(ram_addr, size);
B
bellard 已提交
1625 1626
    /* we remove the notdirty callback only if the code has been
       flushed */
1627
    if (!cpu_physical_memory_is_clean(ram_addr)) {
1628
        CPUArchState *env = current_cpu->env_ptr;
1629
        tlb_set_dirty(env, current_cpu->mem_io_vaddr);
1630
    }
1631 1632
}

1633 1634 1635 1636 1637 1638
static bool notdirty_mem_accepts(void *opaque, hwaddr addr,
                                 unsigned size, bool is_write)
{
    return is_write;
}

1639 1640
static const MemoryRegionOps notdirty_mem_ops = {
    .write = notdirty_mem_write,
1641
    .valid.accepts = notdirty_mem_accepts,
1642
    .endianness = DEVICE_NATIVE_ENDIAN,
1643 1644
};

P
pbrook 已提交
1645
/* Generate a debug exception if a watchpoint has been hit.  */
1646
static void check_watchpoint(int offset, int len, int flags)
P
pbrook 已提交
1647
{
1648 1649
    CPUState *cpu = current_cpu;
    CPUArchState *env = cpu->env_ptr;
1650
    target_ulong pc, cs_base;
P
pbrook 已提交
1651
    target_ulong vaddr;
1652
    CPUWatchpoint *wp;
1653
    int cpu_flags;
P
pbrook 已提交
1654

1655
    if (cpu->watchpoint_hit) {
1656 1657 1658
        /* We re-entered the check after replacing the TB. Now raise
         * the debug interrupt so that is will trigger after the
         * current instruction. */
1659
        cpu_interrupt(cpu, CPU_INTERRUPT_DEBUG);
1660 1661
        return;
    }
1662
    vaddr = (cpu->mem_io_vaddr & TARGET_PAGE_MASK) + offset;
1663
    QTAILQ_FOREACH(wp, &cpu->watchpoints, entry) {
1664 1665
        if (cpu_watchpoint_address_matches(wp, vaddr, len)
            && (wp->flags & flags)) {
1666
            wp->flags |= BP_WATCHPOINT_HIT;
1667 1668
            if (!cpu->watchpoint_hit) {
                cpu->watchpoint_hit = wp;
1669
                tb_check_watchpoint(cpu);
1670
                if (wp->flags & BP_STOP_BEFORE_ACCESS) {
1671
                    cpu->exception_index = EXCP_DEBUG;
1672
                    cpu_loop_exit(cpu);
1673 1674
                } else {
                    cpu_get_tb_cpu_state(env, &pc, &cs_base, &cpu_flags);
1675
                    tb_gen_code(cpu, pc, cs_base, cpu_flags, 1);
1676
                    cpu_resume_from_signal(cpu, NULL);
1677
                }
1678
            }
1679 1680
        } else {
            wp->flags &= ~BP_WATCHPOINT_HIT;
P
pbrook 已提交
1681 1682 1683 1684
        }
    }
}

1685 1686 1687
/* Watchpoint access routines.  Watchpoints are inserted using TLB tricks,
   so these check for a hit then pass through to the normal out-of-line
   phys routines.  */
A
Avi Kivity 已提交
1688
static uint64_t watch_mem_read(void *opaque, hwaddr addr,
1689
                               unsigned size)
1690
{
1691
    check_watchpoint(addr & ~TARGET_PAGE_MASK, size, BP_MEM_READ);
1692
    switch (size) {
1693
    case 1: return ldub_phys(&address_space_memory, addr);
1694
    case 2: return lduw_phys(&address_space_memory, addr);
1695
    case 4: return ldl_phys(&address_space_memory, addr);
1696 1697
    default: abort();
    }
1698 1699
}

A
Avi Kivity 已提交
1700
static void watch_mem_write(void *opaque, hwaddr addr,
1701
                            uint64_t val, unsigned size)
1702
{
1703
    check_watchpoint(addr & ~TARGET_PAGE_MASK, size, BP_MEM_WRITE);
1704
    switch (size) {
1705
    case 1:
1706
        stb_phys(&address_space_memory, addr, val);
1707 1708
        break;
    case 2:
1709
        stw_phys(&address_space_memory, addr, val);
1710 1711
        break;
    case 4:
1712
        stl_phys(&address_space_memory, addr, val);
1713
        break;
1714 1715
    default: abort();
    }
1716 1717
}

1718 1719 1720 1721
static const MemoryRegionOps watch_mem_ops = {
    .read = watch_mem_read,
    .write = watch_mem_write,
    .endianness = DEVICE_NATIVE_ENDIAN,
1722 1723
};

A
Avi Kivity 已提交
1724
static uint64_t subpage_read(void *opaque, hwaddr addr,
1725
                             unsigned len)
1726
{
1727 1728
    subpage_t *subpage = opaque;
    uint8_t buf[4];
1729

1730
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1731
    printf("%s: subpage %p len %u addr " TARGET_FMT_plx "\n", __func__,
1732
           subpage, len, addr);
1733
#endif
1734 1735 1736 1737 1738 1739 1740 1741 1742 1743 1744
    address_space_read(subpage->as, addr + subpage->base, buf, len);
    switch (len) {
    case 1:
        return ldub_p(buf);
    case 2:
        return lduw_p(buf);
    case 4:
        return ldl_p(buf);
    default:
        abort();
    }
1745 1746
}

A
Avi Kivity 已提交
1747
static void subpage_write(void *opaque, hwaddr addr,
1748
                          uint64_t value, unsigned len)
1749
{
1750 1751 1752
    subpage_t *subpage = opaque;
    uint8_t buf[4];

1753
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1754
    printf("%s: subpage %p len %u addr " TARGET_FMT_plx
1755 1756
           " value %"PRIx64"\n",
           __func__, subpage, len, addr, value);
1757
#endif
1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771
    switch (len) {
    case 1:
        stb_p(buf, value);
        break;
    case 2:
        stw_p(buf, value);
        break;
    case 4:
        stl_p(buf, value);
        break;
    default:
        abort();
    }
    address_space_write(subpage->as, addr + subpage->base, buf, len);
1772 1773
}

1774
static bool subpage_accepts(void *opaque, hwaddr addr,
A
Amos Kong 已提交
1775
                            unsigned len, bool is_write)
1776
{
1777
    subpage_t *subpage = opaque;
1778
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1779
    printf("%s: subpage %p %c len %u addr " TARGET_FMT_plx "\n",
1780
           __func__, subpage, is_write ? 'w' : 'r', len, addr);
1781 1782
#endif

1783
    return address_space_access_valid(subpage->as, addr + subpage->base,
A
Amos Kong 已提交
1784
                                      len, is_write);
1785 1786
}

1787 1788 1789
static const MemoryRegionOps subpage_ops = {
    .read = subpage_read,
    .write = subpage_write,
1790
    .valid.accepts = subpage_accepts,
1791
    .endianness = DEVICE_NATIVE_ENDIAN,
1792 1793
};

A
Anthony Liguori 已提交
1794
static int subpage_register (subpage_t *mmio, uint32_t start, uint32_t end,
1795
                             uint16_t section)
1796 1797 1798 1799 1800 1801 1802 1803
{
    int idx, eidx;

    if (start >= TARGET_PAGE_SIZE || end >= TARGET_PAGE_SIZE)
        return -1;
    idx = SUBPAGE_IDX(start);
    eidx = SUBPAGE_IDX(end);
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1804 1805
    printf("%s: %p start %08x end %08x idx %08x eidx %08x section %d\n",
           __func__, mmio, start, end, idx, eidx, section);
1806 1807
#endif
    for (; idx <= eidx; idx++) {
1808
        mmio->sub_section[idx] = section;
1809 1810 1811 1812 1813
    }

    return 0;
}

1814
static subpage_t *subpage_init(AddressSpace *as, hwaddr base)
1815
{
A
Anthony Liguori 已提交
1816
    subpage_t *mmio;
1817

1818
    mmio = g_malloc0(sizeof(subpage_t));
1819

1820
    mmio->as = as;
1821
    mmio->base = base;
1822
    memory_region_init_io(&mmio->iomem, NULL, &subpage_ops, mmio,
P
Peter Crosthwaite 已提交
1823
                          NULL, TARGET_PAGE_SIZE);
A
Avi Kivity 已提交
1824
    mmio->iomem.subpage = true;
1825
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1826 1827
    printf("%s: %p base " TARGET_FMT_plx " len %08x\n", __func__,
           mmio, base, TARGET_PAGE_SIZE);
1828
#endif
1829
    subpage_register(mmio, 0, TARGET_PAGE_SIZE-1, PHYS_SECTION_UNASSIGNED);
1830 1831 1832 1833

    return mmio;
}

1834 1835
static uint16_t dummy_section(PhysPageMap *map, AddressSpace *as,
                              MemoryRegion *mr)
1836
{
1837
    assert(as);
1838
    MemoryRegionSection section = {
1839
        .address_space = as,
1840 1841 1842
        .mr = mr,
        .offset_within_address_space = 0,
        .offset_within_region = 0,
1843
        .size = int128_2_64(),
1844 1845
    };

1846
    return phys_section_add(map, &section);
1847 1848
}

1849
MemoryRegion *iotlb_to_region(AddressSpace *as, hwaddr index)
1850
{
1851
    return as->dispatch->map.sections[index & ~TARGET_PAGE_MASK].mr;
1852 1853
}

A
Avi Kivity 已提交
1854 1855
static void io_mem_init(void)
{
1856
    memory_region_init_io(&io_mem_rom, NULL, &unassigned_mem_ops, NULL, NULL, UINT64_MAX);
1857
    memory_region_init_io(&io_mem_unassigned, NULL, &unassigned_mem_ops, NULL,
1858
                          NULL, UINT64_MAX);
1859
    memory_region_init_io(&io_mem_notdirty, NULL, &notdirty_mem_ops, NULL,
1860
                          NULL, UINT64_MAX);
1861
    memory_region_init_io(&io_mem_watch, NULL, &watch_mem_ops, NULL,
1862
                          NULL, UINT64_MAX);
A
Avi Kivity 已提交
1863 1864
}

A
Avi Kivity 已提交
1865
static void mem_begin(MemoryListener *listener)
1866 1867
{
    AddressSpace *as = container_of(listener, AddressSpace, dispatch_listener);
1868 1869 1870
    AddressSpaceDispatch *d = g_new0(AddressSpaceDispatch, 1);
    uint16_t n;

1871
    n = dummy_section(&d->map, as, &io_mem_unassigned);
1872
    assert(n == PHYS_SECTION_UNASSIGNED);
1873
    n = dummy_section(&d->map, as, &io_mem_notdirty);
1874
    assert(n == PHYS_SECTION_NOTDIRTY);
1875
    n = dummy_section(&d->map, as, &io_mem_rom);
1876
    assert(n == PHYS_SECTION_ROM);
1877
    n = dummy_section(&d->map, as, &io_mem_watch);
1878
    assert(n == PHYS_SECTION_WATCH);
1879

M
Michael S. Tsirkin 已提交
1880
    d->phys_map  = (PhysPageEntry) { .ptr = PHYS_MAP_NODE_NIL, .skip = 1 };
1881 1882 1883 1884 1885
    d->as = as;
    as->next_dispatch = d;
}

static void mem_commit(MemoryListener *listener)
A
Avi Kivity 已提交
1886
{
1887
    AddressSpace *as = container_of(listener, AddressSpace, dispatch_listener);
1888 1889 1890
    AddressSpaceDispatch *cur = as->dispatch;
    AddressSpaceDispatch *next = as->next_dispatch;

1891
    phys_page_compact_all(next, next->map.nodes_nb);
1892

1893
    as->dispatch = next;
1894

1895 1896 1897 1898
    if (cur) {
        phys_sections_free(&cur->map);
        g_free(cur);
    }
1899 1900
}

1901
static void tcg_commit(MemoryListener *listener)
1902
{
1903
    CPUState *cpu;
1904 1905 1906 1907

    /* since each CPU stores ram addresses in its TLB cache, we must
       reset the modified entries */
    /* XXX: slow ! */
A
Andreas Färber 已提交
1908
    CPU_FOREACH(cpu) {
1909 1910 1911 1912 1913
        /* FIXME: Disentangle the cpu.h circular files deps so we can
           directly get the right CPU from listener.  */
        if (cpu->tcg_as_listener != listener) {
            continue;
        }
1914
        tlb_flush(cpu, 1);
1915
    }
1916 1917
}

1918 1919
static void core_log_global_start(MemoryListener *listener)
{
1920
    cpu_physical_memory_set_dirty_tracking(true);
1921 1922 1923 1924
}

static void core_log_global_stop(MemoryListener *listener)
{
1925
    cpu_physical_memory_set_dirty_tracking(false);
1926 1927 1928 1929 1930
}

static MemoryListener core_memory_listener = {
    .log_global_start = core_log_global_start,
    .log_global_stop = core_log_global_stop,
A
Avi Kivity 已提交
1931
    .priority = 1,
1932 1933
};

A
Avi Kivity 已提交
1934 1935
void address_space_init_dispatch(AddressSpace *as)
{
1936
    as->dispatch = NULL;
1937
    as->dispatch_listener = (MemoryListener) {
A
Avi Kivity 已提交
1938
        .begin = mem_begin,
1939
        .commit = mem_commit,
A
Avi Kivity 已提交
1940 1941 1942 1943
        .region_add = mem_add,
        .region_nop = mem_add,
        .priority = 0,
    };
1944
    memory_listener_register(&as->dispatch_listener, as);
A
Avi Kivity 已提交
1945 1946
}

A
Avi Kivity 已提交
1947 1948 1949 1950
void address_space_destroy_dispatch(AddressSpace *as)
{
    AddressSpaceDispatch *d = as->dispatch;

1951
    memory_listener_unregister(&as->dispatch_listener);
A
Avi Kivity 已提交
1952 1953 1954 1955
    g_free(d);
    as->dispatch = NULL;
}

A
Avi Kivity 已提交
1956 1957
static void memory_map_init(void)
{
1958
    system_memory = g_malloc(sizeof(*system_memory));
1959

1960
    memory_region_init(system_memory, NULL, "system", UINT64_MAX);
1961
    address_space_init(&address_space_memory, system_memory, "memory");
1962

1963
    system_io = g_malloc(sizeof(*system_io));
1964 1965
    memory_region_init_io(system_io, NULL, &unassigned_io_ops, NULL, "io",
                          65536);
1966
    address_space_init(&address_space_io, system_io, "I/O");
1967

1968
    memory_listener_register(&core_memory_listener, &address_space_memory);
A
Avi Kivity 已提交
1969 1970 1971 1972 1973 1974 1975
}

MemoryRegion *get_system_memory(void)
{
    return system_memory;
}

1976 1977 1978 1979 1980
MemoryRegion *get_system_io(void)
{
    return system_io;
}

1981 1982
#endif /* !defined(CONFIG_USER_ONLY) */

B
bellard 已提交
1983 1984
/* physical memory access (slow version, mainly for debug) */
#if defined(CONFIG_USER_ONLY)
1985
int cpu_memory_rw_debug(CPUState *cpu, target_ulong addr,
P
Paul Brook 已提交
1986
                        uint8_t *buf, int len, int is_write)
B
bellard 已提交
1987 1988 1989
{
    int l, flags;
    target_ulong page;
1990
    void * p;
B
bellard 已提交
1991 1992 1993 1994 1995 1996 1997 1998

    while (len > 0) {
        page = addr & TARGET_PAGE_MASK;
        l = (page + TARGET_PAGE_SIZE) - addr;
        if (l > len)
            l = len;
        flags = page_get_flags(page);
        if (!(flags & PAGE_VALID))
P
Paul Brook 已提交
1999
            return -1;
B
bellard 已提交
2000 2001
        if (is_write) {
            if (!(flags & PAGE_WRITE))
P
Paul Brook 已提交
2002
                return -1;
2003
            /* XXX: this code should not depend on lock_user */
A
aurel32 已提交
2004
            if (!(p = lock_user(VERIFY_WRITE, addr, l, 0)))
P
Paul Brook 已提交
2005
                return -1;
A
aurel32 已提交
2006 2007
            memcpy(p, buf, l);
            unlock_user(p, addr, l);
B
bellard 已提交
2008 2009
        } else {
            if (!(flags & PAGE_READ))
P
Paul Brook 已提交
2010
                return -1;
2011
            /* XXX: this code should not depend on lock_user */
A
aurel32 已提交
2012
            if (!(p = lock_user(VERIFY_READ, addr, l, 1)))
P
Paul Brook 已提交
2013
                return -1;
A
aurel32 已提交
2014
            memcpy(buf, p, l);
A
aurel32 已提交
2015
            unlock_user(p, addr, 0);
B
bellard 已提交
2016 2017 2018 2019 2020
        }
        len -= l;
        buf += l;
        addr += l;
    }
P
Paul Brook 已提交
2021
    return 0;
B
bellard 已提交
2022
}
B
bellard 已提交
2023

B
bellard 已提交
2024
#else
2025

A
Avi Kivity 已提交
2026 2027
static void invalidate_and_set_dirty(hwaddr addr,
                                     hwaddr length)
2028
{
2029
    if (cpu_physical_memory_is_clean(addr)) {
2030 2031 2032
        /* invalidate code */
        tb_invalidate_phys_page_range(addr, addr + length, 0);
        /* set dirty bit */
2033
        cpu_physical_memory_set_dirty_range_nocode(addr, length);
2034
    }
2035
    xen_modified_memory(addr, length);
2036 2037
}

2038
static int memory_access_size(MemoryRegion *mr, unsigned l, hwaddr addr)
2039
{
2040
    unsigned access_size_max = mr->ops->valid.max_access_size;
2041 2042 2043 2044 2045 2046 2047 2048 2049 2050 2051 2052 2053

    /* Regions are assumed to support 1-4 byte accesses unless
       otherwise specified.  */
    if (access_size_max == 0) {
        access_size_max = 4;
    }

    /* Bound the maximum access by the alignment of the address.  */
    if (!mr->ops->impl.unaligned) {
        unsigned align_size_max = addr & -addr;
        if (align_size_max != 0 && align_size_max < access_size_max) {
            access_size_max = align_size_max;
        }
2054
    }
2055 2056 2057 2058

    /* Don't attempt accesses larger than the maximum.  */
    if (l > access_size_max) {
        l = access_size_max;
2059
    }
2060 2061 2062
    if (l & (l - 1)) {
        l = 1 << (qemu_fls(l) - 1);
    }
2063 2064

    return l;
2065 2066
}

2067
bool address_space_rw(AddressSpace *as, hwaddr addr, uint8_t *buf,
A
Avi Kivity 已提交
2068
                      int len, bool is_write)
B
bellard 已提交
2069
{
2070
    hwaddr l;
B
bellard 已提交
2071
    uint8_t *ptr;
2072
    uint64_t val;
2073
    hwaddr addr1;
2074
    MemoryRegion *mr;
2075
    bool error = false;
2076

B
bellard 已提交
2077
    while (len > 0) {
2078
        l = len;
2079
        mr = address_space_translate(as, addr, &addr1, &l, is_write);
2080

B
bellard 已提交
2081
        if (is_write) {
2082 2083
            if (!memory_access_is_direct(mr, is_write)) {
                l = memory_access_size(mr, l, addr1);
2084
                /* XXX: could force current_cpu to NULL to avoid
B
bellard 已提交
2085
                   potential bugs */
2086 2087 2088 2089 2090 2091 2092
                switch (l) {
                case 8:
                    /* 64 bit write access */
                    val = ldq_p(buf);
                    error |= io_mem_write(mr, addr1, val, 8);
                    break;
                case 4:
B
bellard 已提交
2093
                    /* 32 bit write access */
B
bellard 已提交
2094
                    val = ldl_p(buf);
2095
                    error |= io_mem_write(mr, addr1, val, 4);
2096 2097
                    break;
                case 2:
B
bellard 已提交
2098
                    /* 16 bit write access */
B
bellard 已提交
2099
                    val = lduw_p(buf);
2100
                    error |= io_mem_write(mr, addr1, val, 2);
2101 2102
                    break;
                case 1:
B
bellard 已提交
2103
                    /* 8 bit write access */
B
bellard 已提交
2104
                    val = ldub_p(buf);
2105
                    error |= io_mem_write(mr, addr1, val, 1);
2106 2107 2108
                    break;
                default:
                    abort();
B
bellard 已提交
2109
                }
2110
            } else {
2111
                addr1 += memory_region_get_ram_addr(mr);
B
bellard 已提交
2112
                /* RAM case */
P
pbrook 已提交
2113
                ptr = qemu_get_ram_ptr(addr1);
B
bellard 已提交
2114
                memcpy(ptr, buf, l);
2115
                invalidate_and_set_dirty(addr1, l);
B
bellard 已提交
2116 2117
            }
        } else {
2118
            if (!memory_access_is_direct(mr, is_write)) {
B
bellard 已提交
2119
                /* I/O case */
2120
                l = memory_access_size(mr, l, addr1);
2121 2122 2123 2124 2125 2126 2127
                switch (l) {
                case 8:
                    /* 64 bit read access */
                    error |= io_mem_read(mr, addr1, &val, 8);
                    stq_p(buf, val);
                    break;
                case 4:
B
bellard 已提交
2128
                    /* 32 bit read access */
2129
                    error |= io_mem_read(mr, addr1, &val, 4);
B
bellard 已提交
2130
                    stl_p(buf, val);
2131 2132
                    break;
                case 2:
B
bellard 已提交
2133
                    /* 16 bit read access */
2134
                    error |= io_mem_read(mr, addr1, &val, 2);
B
bellard 已提交
2135
                    stw_p(buf, val);
2136 2137
                    break;
                case 1:
B
bellard 已提交
2138
                    /* 8 bit read access */
2139
                    error |= io_mem_read(mr, addr1, &val, 1);
B
bellard 已提交
2140
                    stb_p(buf, val);
2141 2142 2143
                    break;
                default:
                    abort();
B
bellard 已提交
2144 2145 2146
                }
            } else {
                /* RAM case */
2147
                ptr = qemu_get_ram_ptr(mr->ram_addr + addr1);
2148
                memcpy(buf, ptr, l);
B
bellard 已提交
2149 2150 2151 2152 2153 2154
            }
        }
        len -= l;
        buf += l;
        addr += l;
    }
2155 2156

    return error;
B
bellard 已提交
2157
}
B
bellard 已提交
2158

2159
bool address_space_write(AddressSpace *as, hwaddr addr,
A
Avi Kivity 已提交
2160 2161
                         const uint8_t *buf, int len)
{
2162
    return address_space_rw(as, addr, (uint8_t *)buf, len, true);
A
Avi Kivity 已提交
2163 2164
}

2165
bool address_space_read(AddressSpace *as, hwaddr addr, uint8_t *buf, int len)
A
Avi Kivity 已提交
2166
{
2167
    return address_space_rw(as, addr, buf, len, false);
A
Avi Kivity 已提交
2168 2169 2170
}


A
Avi Kivity 已提交
2171
void cpu_physical_memory_rw(hwaddr addr, uint8_t *buf,
A
Avi Kivity 已提交
2172 2173
                            int len, int is_write)
{
2174
    address_space_rw(&address_space_memory, addr, buf, len, is_write);
A
Avi Kivity 已提交
2175 2176
}

2177 2178 2179 2180 2181
enum write_rom_type {
    WRITE_DATA,
    FLUSH_CACHE,
};

2182
static inline void cpu_physical_memory_write_rom_internal(AddressSpace *as,
2183
    hwaddr addr, const uint8_t *buf, int len, enum write_rom_type type)
B
bellard 已提交
2184
{
2185
    hwaddr l;
B
bellard 已提交
2186
    uint8_t *ptr;
2187
    hwaddr addr1;
2188
    MemoryRegion *mr;
2189

B
bellard 已提交
2190
    while (len > 0) {
2191
        l = len;
2192
        mr = address_space_translate(as, addr, &addr1, &l, true);
2193

2194 2195
        if (!(memory_region_is_ram(mr) ||
              memory_region_is_romd(mr))) {
B
bellard 已提交
2196 2197
            /* do nothing */
        } else {
2198
            addr1 += memory_region_get_ram_addr(mr);
B
bellard 已提交
2199
            /* ROM/RAM case */
P
pbrook 已提交
2200
            ptr = qemu_get_ram_ptr(addr1);
2201 2202 2203 2204 2205 2206 2207 2208 2209
            switch (type) {
            case WRITE_DATA:
                memcpy(ptr, buf, l);
                invalidate_and_set_dirty(addr1, l);
                break;
            case FLUSH_CACHE:
                flush_icache_range((uintptr_t)ptr, (uintptr_t)ptr + l);
                break;
            }
B
bellard 已提交
2210 2211 2212 2213 2214 2215 2216
        }
        len -= l;
        buf += l;
        addr += l;
    }
}

2217
/* used for ROM loading : can write in RAM and ROM */
2218
void cpu_physical_memory_write_rom(AddressSpace *as, hwaddr addr,
2219 2220
                                   const uint8_t *buf, int len)
{
2221
    cpu_physical_memory_write_rom_internal(as, addr, buf, len, WRITE_DATA);
2222 2223 2224 2225 2226 2227 2228 2229 2230 2231 2232 2233 2234 2235
}

void cpu_flush_icache_range(hwaddr start, int len)
{
    /*
     * This function should do the same thing as an icache flush that was
     * triggered from within the guest. For TCG we are always cache coherent,
     * so there is no need to flush anything. For KVM / Xen we need to flush
     * the host's instruction cache at least.
     */
    if (tcg_enabled()) {
        return;
    }

2236 2237
    cpu_physical_memory_write_rom_internal(&address_space_memory,
                                           start, NULL, len, FLUSH_CACHE);
2238 2239
}

2240
typedef struct {
2241
    MemoryRegion *mr;
2242
    void *buffer;
A
Avi Kivity 已提交
2243 2244
    hwaddr addr;
    hwaddr len;
2245 2246 2247 2248
} BounceBuffer;

static BounceBuffer bounce;

2249 2250 2251
typedef struct MapClient {
    void *opaque;
    void (*callback)(void *opaque);
B
Blue Swirl 已提交
2252
    QLIST_ENTRY(MapClient) link;
2253 2254
} MapClient;

B
Blue Swirl 已提交
2255 2256
static QLIST_HEAD(map_client_list, MapClient) map_client_list
    = QLIST_HEAD_INITIALIZER(map_client_list);
2257 2258 2259

void *cpu_register_map_client(void *opaque, void (*callback)(void *opaque))
{
2260
    MapClient *client = g_malloc(sizeof(*client));
2261 2262 2263

    client->opaque = opaque;
    client->callback = callback;
B
Blue Swirl 已提交
2264
    QLIST_INSERT_HEAD(&map_client_list, client, link);
2265 2266 2267
    return client;
}

B
Blue Swirl 已提交
2268
static void cpu_unregister_map_client(void *_client)
2269 2270 2271
{
    MapClient *client = (MapClient *)_client;

B
Blue Swirl 已提交
2272
    QLIST_REMOVE(client, link);
2273
    g_free(client);
2274 2275 2276 2277 2278 2279
}

static void cpu_notify_map_clients(void)
{
    MapClient *client;

B
Blue Swirl 已提交
2280 2281
    while (!QLIST_EMPTY(&map_client_list)) {
        client = QLIST_FIRST(&map_client_list);
2282
        client->callback(client->opaque);
2283
        cpu_unregister_map_client(client);
2284 2285 2286
    }
}

2287 2288
bool address_space_access_valid(AddressSpace *as, hwaddr addr, int len, bool is_write)
{
2289
    MemoryRegion *mr;
2290 2291 2292 2293
    hwaddr l, xlat;

    while (len > 0) {
        l = len;
2294 2295 2296 2297
        mr = address_space_translate(as, addr, &xlat, &l, is_write);
        if (!memory_access_is_direct(mr, is_write)) {
            l = memory_access_size(mr, l, addr);
            if (!memory_region_access_valid(mr, xlat, l, is_write)) {
2298 2299 2300 2301 2302 2303 2304 2305 2306 2307
                return false;
            }
        }

        len -= l;
        addr += l;
    }
    return true;
}

2308 2309 2310 2311
/* Map a physical memory region into a host virtual address.
 * May map a subset of the requested range, given by and returned in *plen.
 * May return NULL if resources needed to perform the mapping are exhausted.
 * Use only for reads OR writes - not for read-modify-write operations.
2312 2313
 * Use cpu_register_map_client() to know when retrying the map operation is
 * likely to succeed.
2314
 */
A
Avi Kivity 已提交
2315
void *address_space_map(AddressSpace *as,
A
Avi Kivity 已提交
2316 2317
                        hwaddr addr,
                        hwaddr *plen,
A
Avi Kivity 已提交
2318
                        bool is_write)
2319
{
A
Avi Kivity 已提交
2320
    hwaddr len = *plen;
2321 2322 2323 2324
    hwaddr done = 0;
    hwaddr l, xlat, base;
    MemoryRegion *mr, *this_mr;
    ram_addr_t raddr;
2325

2326 2327 2328
    if (len == 0) {
        return NULL;
    }
2329

2330 2331 2332 2333 2334
    l = len;
    mr = address_space_translate(as, addr, &xlat, &l, is_write);
    if (!memory_access_is_direct(mr, is_write)) {
        if (bounce.buffer) {
            return NULL;
2335
        }
2336 2337 2338
        /* Avoid unbounded allocations */
        l = MIN(l, TARGET_PAGE_SIZE);
        bounce.buffer = qemu_memalign(TARGET_PAGE_SIZE, l);
2339 2340
        bounce.addr = addr;
        bounce.len = l;
2341 2342 2343

        memory_region_ref(mr);
        bounce.mr = mr;
2344 2345
        if (!is_write) {
            address_space_read(as, addr, bounce.buffer, l);
2346
        }
2347

2348 2349 2350 2351 2352 2353 2354 2355
        *plen = l;
        return bounce.buffer;
    }

    base = xlat;
    raddr = memory_region_get_ram_addr(mr);

    for (;;) {
2356 2357
        len -= l;
        addr += l;
2358 2359 2360 2361 2362 2363 2364 2365 2366 2367
        done += l;
        if (len == 0) {
            break;
        }

        l = len;
        this_mr = address_space_translate(as, addr, &xlat, &l, is_write);
        if (this_mr != mr || xlat != base + done) {
            break;
        }
2368
    }
2369

2370
    memory_region_ref(mr);
2371 2372
    *plen = done;
    return qemu_ram_ptr_length(raddr + base, plen);
2373 2374
}

A
Avi Kivity 已提交
2375
/* Unmaps a memory region previously mapped by address_space_map().
2376 2377 2378
 * Will also mark the memory as dirty if is_write == 1.  access_len gives
 * the amount of memory that was actually read or written by the caller.
 */
A
Avi Kivity 已提交
2379 2380
void address_space_unmap(AddressSpace *as, void *buffer, hwaddr len,
                         int is_write, hwaddr access_len)
2381 2382
{
    if (buffer != bounce.buffer) {
2383 2384 2385 2386 2387
        MemoryRegion *mr;
        ram_addr_t addr1;

        mr = qemu_ram_addr_from_host(buffer, &addr1);
        assert(mr != NULL);
2388
        if (is_write) {
2389
            invalidate_and_set_dirty(addr1, access_len);
2390
        }
2391
        if (xen_enabled()) {
J
Jan Kiszka 已提交
2392
            xen_invalidate_map_cache_entry(buffer);
A
Anthony PERARD 已提交
2393
        }
2394
        memory_region_unref(mr);
2395 2396 2397
        return;
    }
    if (is_write) {
A
Avi Kivity 已提交
2398
        address_space_write(as, bounce.addr, bounce.buffer, access_len);
2399
    }
2400
    qemu_vfree(bounce.buffer);
2401
    bounce.buffer = NULL;
2402
    memory_region_unref(bounce.mr);
2403
    cpu_notify_map_clients();
2404
}
B
bellard 已提交
2405

A
Avi Kivity 已提交
2406 2407
void *cpu_physical_memory_map(hwaddr addr,
                              hwaddr *plen,
A
Avi Kivity 已提交
2408 2409 2410 2411 2412
                              int is_write)
{
    return address_space_map(&address_space_memory, addr, plen, is_write);
}

A
Avi Kivity 已提交
2413 2414
void cpu_physical_memory_unmap(void *buffer, hwaddr len,
                               int is_write, hwaddr access_len)
A
Avi Kivity 已提交
2415 2416 2417 2418
{
    return address_space_unmap(&address_space_memory, buffer, len, is_write, access_len);
}

B
bellard 已提交
2419
/* warning: addr must be aligned */
2420
static inline uint32_t ldl_phys_internal(AddressSpace *as, hwaddr addr,
2421
                                         enum device_endian endian)
B
bellard 已提交
2422 2423
{
    uint8_t *ptr;
2424
    uint64_t val;
2425
    MemoryRegion *mr;
2426 2427
    hwaddr l = 4;
    hwaddr addr1;
B
bellard 已提交
2428

2429
    mr = address_space_translate(as, addr, &addr1, &l, false);
2430
    if (l < 4 || !memory_access_is_direct(mr, false)) {
B
bellard 已提交
2431
        /* I/O case */
2432
        io_mem_read(mr, addr1, &val, 4);
2433 2434 2435 2436 2437 2438 2439 2440 2441
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap32(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap32(val);
        }
#endif
B
bellard 已提交
2442 2443
    } else {
        /* RAM case */
2444
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(mr)
2445
                                & TARGET_PAGE_MASK)
2446
                               + addr1);
2447 2448 2449 2450 2451 2452 2453 2454 2455 2456 2457
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            val = ldl_le_p(ptr);
            break;
        case DEVICE_BIG_ENDIAN:
            val = ldl_be_p(ptr);
            break;
        default:
            val = ldl_p(ptr);
            break;
        }
B
bellard 已提交
2458 2459 2460 2461
    }
    return val;
}

2462
uint32_t ldl_phys(AddressSpace *as, hwaddr addr)
2463
{
2464
    return ldl_phys_internal(as, addr, DEVICE_NATIVE_ENDIAN);
2465 2466
}

2467
uint32_t ldl_le_phys(AddressSpace *as, hwaddr addr)
2468
{
2469
    return ldl_phys_internal(as, addr, DEVICE_LITTLE_ENDIAN);
2470 2471
}

2472
uint32_t ldl_be_phys(AddressSpace *as, hwaddr addr)
2473
{
2474
    return ldl_phys_internal(as, addr, DEVICE_BIG_ENDIAN);
2475 2476
}

B
bellard 已提交
2477
/* warning: addr must be aligned */
2478
static inline uint64_t ldq_phys_internal(AddressSpace *as, hwaddr addr,
2479
                                         enum device_endian endian)
B
bellard 已提交
2480 2481 2482
{
    uint8_t *ptr;
    uint64_t val;
2483
    MemoryRegion *mr;
2484 2485
    hwaddr l = 8;
    hwaddr addr1;
B
bellard 已提交
2486

2487
    mr = address_space_translate(as, addr, &addr1, &l,
2488 2489
                                 false);
    if (l < 8 || !memory_access_is_direct(mr, false)) {
B
bellard 已提交
2490
        /* I/O case */
2491
        io_mem_read(mr, addr1, &val, 8);
2492 2493 2494 2495 2496 2497 2498 2499
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap64(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap64(val);
        }
B
bellard 已提交
2500 2501 2502
#endif
    } else {
        /* RAM case */
2503
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(mr)
2504
                                & TARGET_PAGE_MASK)
2505
                               + addr1);
2506 2507 2508 2509 2510 2511 2512 2513 2514 2515 2516
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            val = ldq_le_p(ptr);
            break;
        case DEVICE_BIG_ENDIAN:
            val = ldq_be_p(ptr);
            break;
        default:
            val = ldq_p(ptr);
            break;
        }
B
bellard 已提交
2517 2518 2519 2520
    }
    return val;
}

2521
uint64_t ldq_phys(AddressSpace *as, hwaddr addr)
2522
{
2523
    return ldq_phys_internal(as, addr, DEVICE_NATIVE_ENDIAN);
2524 2525
}

2526
uint64_t ldq_le_phys(AddressSpace *as, hwaddr addr)
2527
{
2528
    return ldq_phys_internal(as, addr, DEVICE_LITTLE_ENDIAN);
2529 2530
}

2531
uint64_t ldq_be_phys(AddressSpace *as, hwaddr addr)
2532
{
2533
    return ldq_phys_internal(as, addr, DEVICE_BIG_ENDIAN);
2534 2535
}

B
bellard 已提交
2536
/* XXX: optimize */
2537
uint32_t ldub_phys(AddressSpace *as, hwaddr addr)
B
bellard 已提交
2538 2539
{
    uint8_t val;
2540
    address_space_rw(as, addr, &val, 1, 0);
B
bellard 已提交
2541 2542 2543
    return val;
}

2544
/* warning: addr must be aligned */
2545
static inline uint32_t lduw_phys_internal(AddressSpace *as, hwaddr addr,
2546
                                          enum device_endian endian)
B
bellard 已提交
2547
{
2548 2549
    uint8_t *ptr;
    uint64_t val;
2550
    MemoryRegion *mr;
2551 2552
    hwaddr l = 2;
    hwaddr addr1;
2553

2554
    mr = address_space_translate(as, addr, &addr1, &l,
2555 2556
                                 false);
    if (l < 2 || !memory_access_is_direct(mr, false)) {
2557
        /* I/O case */
2558
        io_mem_read(mr, addr1, &val, 2);
2559 2560 2561 2562 2563 2564 2565 2566 2567
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap16(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap16(val);
        }
#endif
2568 2569
    } else {
        /* RAM case */
2570
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(mr)
2571
                                & TARGET_PAGE_MASK)
2572
                               + addr1);
2573 2574 2575 2576 2577 2578 2579 2580 2581 2582 2583
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            val = lduw_le_p(ptr);
            break;
        case DEVICE_BIG_ENDIAN:
            val = lduw_be_p(ptr);
            break;
        default:
            val = lduw_p(ptr);
            break;
        }
2584 2585
    }
    return val;
B
bellard 已提交
2586 2587
}

2588
uint32_t lduw_phys(AddressSpace *as, hwaddr addr)
2589
{
2590
    return lduw_phys_internal(as, addr, DEVICE_NATIVE_ENDIAN);
2591 2592
}

2593
uint32_t lduw_le_phys(AddressSpace *as, hwaddr addr)
2594
{
2595
    return lduw_phys_internal(as, addr, DEVICE_LITTLE_ENDIAN);
2596 2597
}

2598
uint32_t lduw_be_phys(AddressSpace *as, hwaddr addr)
2599
{
2600
    return lduw_phys_internal(as, addr, DEVICE_BIG_ENDIAN);
2601 2602
}

B
bellard 已提交
2603 2604 2605
/* warning: addr must be aligned. The ram page is not masked as dirty
   and the code inside is not invalidated. It is useful if the dirty
   bits are used to track modified PTEs */
2606
void stl_phys_notdirty(AddressSpace *as, hwaddr addr, uint32_t val)
B
bellard 已提交
2607 2608
{
    uint8_t *ptr;
2609
    MemoryRegion *mr;
2610 2611
    hwaddr l = 4;
    hwaddr addr1;
B
bellard 已提交
2612

2613
    mr = address_space_translate(as, addr, &addr1, &l,
2614 2615 2616
                                 true);
    if (l < 4 || !memory_access_is_direct(mr, true)) {
        io_mem_write(mr, addr1, val, 4);
B
bellard 已提交
2617
    } else {
2618
        addr1 += memory_region_get_ram_addr(mr) & TARGET_PAGE_MASK;
P
pbrook 已提交
2619
        ptr = qemu_get_ram_ptr(addr1);
B
bellard 已提交
2620
        stl_p(ptr, val);
A
aliguori 已提交
2621 2622

        if (unlikely(in_migration)) {
2623
            if (cpu_physical_memory_is_clean(addr1)) {
A
aliguori 已提交
2624 2625 2626
                /* invalidate code */
                tb_invalidate_phys_page_range(addr1, addr1 + 4, 0);
                /* set dirty bit */
2627
                cpu_physical_memory_set_dirty_range_nocode(addr1, 4);
A
aliguori 已提交
2628 2629
            }
        }
B
bellard 已提交
2630 2631 2632 2633
    }
}

/* warning: addr must be aligned */
2634 2635
static inline void stl_phys_internal(AddressSpace *as,
                                     hwaddr addr, uint32_t val,
2636
                                     enum device_endian endian)
B
bellard 已提交
2637 2638
{
    uint8_t *ptr;
2639
    MemoryRegion *mr;
2640 2641
    hwaddr l = 4;
    hwaddr addr1;
B
bellard 已提交
2642

2643
    mr = address_space_translate(as, addr, &addr1, &l,
2644 2645
                                 true);
    if (l < 4 || !memory_access_is_direct(mr, true)) {
2646 2647 2648 2649 2650 2651 2652 2653 2654
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap32(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap32(val);
        }
#endif
2655
        io_mem_write(mr, addr1, val, 4);
B
bellard 已提交
2656 2657
    } else {
        /* RAM case */
2658
        addr1 += memory_region_get_ram_addr(mr) & TARGET_PAGE_MASK;
P
pbrook 已提交
2659
        ptr = qemu_get_ram_ptr(addr1);
2660 2661 2662 2663 2664 2665 2666 2667 2668 2669 2670
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            stl_le_p(ptr, val);
            break;
        case DEVICE_BIG_ENDIAN:
            stl_be_p(ptr, val);
            break;
        default:
            stl_p(ptr, val);
            break;
        }
2671
        invalidate_and_set_dirty(addr1, 4);
B
bellard 已提交
2672 2673 2674
    }
}

2675
void stl_phys(AddressSpace *as, hwaddr addr, uint32_t val)
2676
{
2677
    stl_phys_internal(as, addr, val, DEVICE_NATIVE_ENDIAN);
2678 2679
}

2680
void stl_le_phys(AddressSpace *as, hwaddr addr, uint32_t val)
2681
{
2682
    stl_phys_internal(as, addr, val, DEVICE_LITTLE_ENDIAN);
2683 2684
}

2685
void stl_be_phys(AddressSpace *as, hwaddr addr, uint32_t val)
2686
{
2687
    stl_phys_internal(as, addr, val, DEVICE_BIG_ENDIAN);
2688 2689
}

B
bellard 已提交
2690
/* XXX: optimize */
2691
void stb_phys(AddressSpace *as, hwaddr addr, uint32_t val)
B
bellard 已提交
2692 2693
{
    uint8_t v = val;
2694
    address_space_rw(as, addr, &v, 1, 1);
B
bellard 已提交
2695 2696
}

2697
/* warning: addr must be aligned */
2698 2699
static inline void stw_phys_internal(AddressSpace *as,
                                     hwaddr addr, uint32_t val,
2700
                                     enum device_endian endian)
B
bellard 已提交
2701
{
2702
    uint8_t *ptr;
2703
    MemoryRegion *mr;
2704 2705
    hwaddr l = 2;
    hwaddr addr1;
2706

2707
    mr = address_space_translate(as, addr, &addr1, &l, true);
2708
    if (l < 2 || !memory_access_is_direct(mr, true)) {
2709 2710 2711 2712 2713 2714 2715 2716 2717
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap16(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap16(val);
        }
#endif
2718
        io_mem_write(mr, addr1, val, 2);
2719 2720
    } else {
        /* RAM case */
2721
        addr1 += memory_region_get_ram_addr(mr) & TARGET_PAGE_MASK;
2722
        ptr = qemu_get_ram_ptr(addr1);
2723 2724 2725 2726 2727 2728 2729 2730 2731 2732 2733
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            stw_le_p(ptr, val);
            break;
        case DEVICE_BIG_ENDIAN:
            stw_be_p(ptr, val);
            break;
        default:
            stw_p(ptr, val);
            break;
        }
2734
        invalidate_and_set_dirty(addr1, 2);
2735
    }
B
bellard 已提交
2736 2737
}

2738
void stw_phys(AddressSpace *as, hwaddr addr, uint32_t val)
2739
{
2740
    stw_phys_internal(as, addr, val, DEVICE_NATIVE_ENDIAN);
2741 2742
}

2743
void stw_le_phys(AddressSpace *as, hwaddr addr, uint32_t val)
2744
{
2745
    stw_phys_internal(as, addr, val, DEVICE_LITTLE_ENDIAN);
2746 2747
}

2748
void stw_be_phys(AddressSpace *as, hwaddr addr, uint32_t val)
2749
{
2750
    stw_phys_internal(as, addr, val, DEVICE_BIG_ENDIAN);
2751 2752
}

B
bellard 已提交
2753
/* XXX: optimize */
2754
void stq_phys(AddressSpace *as, hwaddr addr, uint64_t val)
B
bellard 已提交
2755 2756
{
    val = tswap64(val);
2757
    address_space_rw(as, addr, (void *) &val, 8, 1);
B
bellard 已提交
2758 2759
}

2760
void stq_le_phys(AddressSpace *as, hwaddr addr, uint64_t val)
2761 2762
{
    val = cpu_to_le64(val);
2763
    address_space_rw(as, addr, (void *) &val, 8, 1);
2764 2765
}

2766
void stq_be_phys(AddressSpace *as, hwaddr addr, uint64_t val)
2767 2768
{
    val = cpu_to_be64(val);
2769
    address_space_rw(as, addr, (void *) &val, 8, 1);
2770 2771
}

2772
/* virtual memory access for debug (includes writing to ROM) */
2773
int cpu_memory_rw_debug(CPUState *cpu, target_ulong addr,
2774
                        uint8_t *buf, int len, int is_write)
B
bellard 已提交
2775 2776
{
    int l;
A
Avi Kivity 已提交
2777
    hwaddr phys_addr;
2778
    target_ulong page;
B
bellard 已提交
2779 2780 2781

    while (len > 0) {
        page = addr & TARGET_PAGE_MASK;
2782
        phys_addr = cpu_get_phys_page_debug(cpu, page);
B
bellard 已提交
2783 2784 2785 2786 2787 2788
        /* if no physical page mapped, return an error */
        if (phys_addr == -1)
            return -1;
        l = (page + TARGET_PAGE_SIZE) - addr;
        if (l > len)
            l = len;
2789
        phys_addr += (addr & ~TARGET_PAGE_MASK);
2790 2791 2792 2793 2794
        if (is_write) {
            cpu_physical_memory_write_rom(cpu->as, phys_addr, buf, l);
        } else {
            address_space_rw(cpu->as, phys_addr, buf, l, 0);
        }
B
bellard 已提交
2795 2796 2797 2798 2799 2800
        len -= l;
        buf += l;
        addr += l;
    }
    return 0;
}
P
Paul Brook 已提交
2801
#endif
B
bellard 已提交
2802

2803 2804 2805 2806
/*
 * A helper function for the _utterly broken_ virtio device model to find out if
 * it's running on a big endian machine. Don't do this at home kids!
 */
2807 2808
bool target_words_bigendian(void);
bool target_words_bigendian(void)
2809 2810 2811 2812 2813 2814 2815 2816
{
#if defined(TARGET_WORDS_BIGENDIAN)
    return true;
#else
    return false;
#endif
}

2817
#ifndef CONFIG_USER_ONLY
A
Avi Kivity 已提交
2818
bool cpu_physical_memory_is_io(hwaddr phys_addr)
2819
{
2820
    MemoryRegion*mr;
2821
    hwaddr l = 1;
2822

2823 2824
    mr = address_space_translate(&address_space_memory,
                                 phys_addr, &phys_addr, &l, false);
2825

2826 2827
    return !(memory_region_is_ram(mr) ||
             memory_region_is_romd(mr));
2828
}
2829 2830 2831 2832 2833 2834 2835 2836 2837

void qemu_ram_foreach_block(RAMBlockIterFunc func, void *opaque)
{
    RAMBlock *block;

    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
        func(block->host, block->offset, block->length, opaque);
    }
}
2838
#endif