virtio.c 37.8 KB
Newer Older
A
aliguori 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
/*
 * Virtio Support
 *
 * Copyright IBM, Corp. 2007
 *
 * Authors:
 *  Anthony Liguori   <aliguori@us.ibm.com>
 *
 * This work is licensed under the terms of the GNU GPL, version 2.  See
 * the COPYING file in the top-level directory.
 *
 */

#include <inttypes.h>

16
#include "trace.h"
17
#include "exec/address-spaces.h"
18
#include "qemu/error-report.h"
P
Paolo Bonzini 已提交
19
#include "hw/virtio/virtio.h"
20
#include "qemu/atomic.h"
P
Paolo Bonzini 已提交
21
#include "hw/virtio/virtio-bus.h"
22
#include "migration/migration.h"
23
#include "hw/virtio/virtio-access.h"
A
aliguori 已提交
24

25 26 27 28 29
/*
 * The alignment to use between consumer and producer parts of vring.
 * x86 pagesize again. This is the default, used by transports like PCI
 * which don't provide a means for the guest to tell the host the alignment.
 */
30 31
#define VIRTIO_PCI_VRING_ALIGN         4096

A
aliguori 已提交
32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62
typedef struct VRingDesc
{
    uint64_t addr;
    uint32_t len;
    uint16_t flags;
    uint16_t next;
} VRingDesc;

typedef struct VRingAvail
{
    uint16_t flags;
    uint16_t idx;
    uint16_t ring[0];
} VRingAvail;

typedef struct VRingUsedElem
{
    uint32_t id;
    uint32_t len;
} VRingUsedElem;

typedef struct VRingUsed
{
    uint16_t flags;
    uint16_t idx;
    VRingUsedElem ring[0];
} VRingUsed;

typedef struct VRing
{
    unsigned int num;
63
    unsigned int align;
A
Avi Kivity 已提交
64 65 66
    hwaddr desc;
    hwaddr avail;
    hwaddr used;
A
aliguori 已提交
67 68 69 70 71
} VRing;

struct VirtQueue
{
    VRing vring;
A
Avi Kivity 已提交
72
    hwaddr pa;
A
aliguori 已提交
73
    uint16_t last_avail_idx;
M
Michael S. Tsirkin 已提交
74 75 76 77 78 79 80 81 82
    /* Last used index value we have signalled on */
    uint16_t signalled_used;

    /* Last used index value we have signalled on */
    bool signalled_used_valid;

    /* Notification enabled? */
    bool notification;

83 84
    uint16_t queue_index;

A
aliguori 已提交
85
    int inuse;
M
Michael S. Tsirkin 已提交
86

87
    uint16_t vector;
A
aliguori 已提交
88
    void (*handle_output)(VirtIODevice *vdev, VirtQueue *vq);
89 90 91
    VirtIODevice *vdev;
    EventNotifier guest_notifier;
    EventNotifier host_notifier;
92
    QLIST_ENTRY(VirtQueue) node;
A
aliguori 已提交
93 94 95
};

/* virt queue functions */
P
Paul Brook 已提交
96
static void virtqueue_init(VirtQueue *vq)
A
aliguori 已提交
97
{
A
Avi Kivity 已提交
98
    hwaddr pa = vq->pa;
P
Paul Brook 已提交
99

A
aliguori 已提交
100 101
    vq->vring.desc = pa;
    vq->vring.avail = pa + vq->vring.num * sizeof(VRingDesc);
102 103
    vq->vring.used = vring_align(vq->vring.avail +
                                 offsetof(VRingAvail, ring[vq->vring.num]),
104
                                 vq->vring.align);
A
aliguori 已提交
105 106
}

107 108
static inline uint64_t vring_desc_addr(VirtIODevice *vdev, hwaddr desc_pa,
                                       int i)
A
aliguori 已提交
109
{
A
Avi Kivity 已提交
110
    hwaddr pa;
111
    pa = desc_pa + sizeof(VRingDesc) * i + offsetof(VRingDesc, addr);
112
    return virtio_ldq_phys(vdev, pa);
A
aliguori 已提交
113 114
}

115
static inline uint32_t vring_desc_len(VirtIODevice *vdev, hwaddr desc_pa, int i)
A
aliguori 已提交
116
{
A
Avi Kivity 已提交
117
    hwaddr pa;
118
    pa = desc_pa + sizeof(VRingDesc) * i + offsetof(VRingDesc, len);
119
    return virtio_ldl_phys(vdev, pa);
A
aliguori 已提交
120 121
}

122 123
static inline uint16_t vring_desc_flags(VirtIODevice *vdev, hwaddr desc_pa,
                                        int i)
A
aliguori 已提交
124
{
A
Avi Kivity 已提交
125
    hwaddr pa;
126
    pa = desc_pa + sizeof(VRingDesc) * i + offsetof(VRingDesc, flags);
127
    return virtio_lduw_phys(vdev, pa);
A
aliguori 已提交
128 129
}

130 131
static inline uint16_t vring_desc_next(VirtIODevice *vdev, hwaddr desc_pa,
                                       int i)
A
aliguori 已提交
132
{
A
Avi Kivity 已提交
133
    hwaddr pa;
134
    pa = desc_pa + sizeof(VRingDesc) * i + offsetof(VRingDesc, next);
135
    return virtio_lduw_phys(vdev, pa);
A
aliguori 已提交
136 137 138 139
}

static inline uint16_t vring_avail_flags(VirtQueue *vq)
{
A
Avi Kivity 已提交
140
    hwaddr pa;
A
aliguori 已提交
141
    pa = vq->vring.avail + offsetof(VRingAvail, flags);
142
    return virtio_lduw_phys(vq->vdev, pa);
A
aliguori 已提交
143 144 145 146
}

static inline uint16_t vring_avail_idx(VirtQueue *vq)
{
A
Avi Kivity 已提交
147
    hwaddr pa;
A
aliguori 已提交
148
    pa = vq->vring.avail + offsetof(VRingAvail, idx);
149
    return virtio_lduw_phys(vq->vdev, pa);
A
aliguori 已提交
150 151 152 153
}

static inline uint16_t vring_avail_ring(VirtQueue *vq, int i)
{
A
Avi Kivity 已提交
154
    hwaddr pa;
A
aliguori 已提交
155
    pa = vq->vring.avail + offsetof(VRingAvail, ring[i]);
156
    return virtio_lduw_phys(vq->vdev, pa);
A
aliguori 已提交
157 158
}

159
static inline uint16_t vring_get_used_event(VirtQueue *vq)
M
Michael S. Tsirkin 已提交
160 161 162 163
{
    return vring_avail_ring(vq, vq->vring.num);
}

A
aliguori 已提交
164 165
static inline void vring_used_ring_id(VirtQueue *vq, int i, uint32_t val)
{
A
Avi Kivity 已提交
166
    hwaddr pa;
A
aliguori 已提交
167
    pa = vq->vring.used + offsetof(VRingUsed, ring[i].id);
168
    virtio_stl_phys(vq->vdev, pa, val);
A
aliguori 已提交
169 170 171 172
}

static inline void vring_used_ring_len(VirtQueue *vq, int i, uint32_t val)
{
A
Avi Kivity 已提交
173
    hwaddr pa;
A
aliguori 已提交
174
    pa = vq->vring.used + offsetof(VRingUsed, ring[i].len);
175
    virtio_stl_phys(vq->vdev, pa, val);
A
aliguori 已提交
176 177 178 179
}

static uint16_t vring_used_idx(VirtQueue *vq)
{
A
Avi Kivity 已提交
180
    hwaddr pa;
A
aliguori 已提交
181
    pa = vq->vring.used + offsetof(VRingUsed, idx);
182
    return virtio_lduw_phys(vq->vdev, pa);
A
aliguori 已提交
183 184
}

M
Michael S. Tsirkin 已提交
185
static inline void vring_used_idx_set(VirtQueue *vq, uint16_t val)
A
aliguori 已提交
186
{
A
Avi Kivity 已提交
187
    hwaddr pa;
A
aliguori 已提交
188
    pa = vq->vring.used + offsetof(VRingUsed, idx);
189
    virtio_stw_phys(vq->vdev, pa, val);
A
aliguori 已提交
190 191 192 193
}

static inline void vring_used_flags_set_bit(VirtQueue *vq, int mask)
{
194
    VirtIODevice *vdev = vq->vdev;
A
Avi Kivity 已提交
195
    hwaddr pa;
A
aliguori 已提交
196
    pa = vq->vring.used + offsetof(VRingUsed, flags);
197
    virtio_stw_phys(vdev, pa, virtio_lduw_phys(vdev, pa) | mask);
A
aliguori 已提交
198 199 200 201
}

static inline void vring_used_flags_unset_bit(VirtQueue *vq, int mask)
{
202
    VirtIODevice *vdev = vq->vdev;
A
Avi Kivity 已提交
203
    hwaddr pa;
A
aliguori 已提交
204
    pa = vq->vring.used + offsetof(VRingUsed, flags);
205
    virtio_stw_phys(vdev, pa, virtio_lduw_phys(vdev, pa) & ~mask);
A
aliguori 已提交
206 207
}

208
static inline void vring_set_avail_event(VirtQueue *vq, uint16_t val)
M
Michael S. Tsirkin 已提交
209
{
A
Avi Kivity 已提交
210
    hwaddr pa;
M
Michael S. Tsirkin 已提交
211 212 213 214
    if (!vq->notification) {
        return;
    }
    pa = vq->vring.used + offsetof(VRingUsed, ring[vq->vring.num]);
215
    virtio_stw_phys(vq->vdev, pa, val);
M
Michael S. Tsirkin 已提交
216 217
}

A
aliguori 已提交
218 219
void virtio_queue_set_notification(VirtQueue *vq, int enable)
{
M
Michael S. Tsirkin 已提交
220
    vq->notification = enable;
221
    if (virtio_has_feature(vq->vdev, VIRTIO_RING_F_EVENT_IDX)) {
222
        vring_set_avail_event(vq, vring_avail_idx(vq));
M
Michael S. Tsirkin 已提交
223
    } else if (enable) {
A
aliguori 已提交
224
        vring_used_flags_unset_bit(vq, VRING_USED_F_NO_NOTIFY);
M
Michael S. Tsirkin 已提交
225
    } else {
A
aliguori 已提交
226
        vring_used_flags_set_bit(vq, VRING_USED_F_NO_NOTIFY);
M
Michael S. Tsirkin 已提交
227
    }
228 229 230 231
    if (enable) {
        /* Expose avail event/used flags before caller checks the avail idx. */
        smp_mb();
    }
A
aliguori 已提交
232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249
}

int virtio_queue_ready(VirtQueue *vq)
{
    return vq->vring.avail != 0;
}

int virtio_queue_empty(VirtQueue *vq)
{
    return vring_avail_idx(vq) == vq->last_avail_idx;
}

void virtqueue_fill(VirtQueue *vq, const VirtQueueElement *elem,
                    unsigned int len, unsigned int idx)
{
    unsigned int offset;
    int i;

250 251
    trace_virtqueue_fill(vq, elem, len, idx);

A
aliguori 已提交
252 253 254 255
    offset = 0;
    for (i = 0; i < elem->in_num; i++) {
        size_t size = MIN(len - offset, elem->in_sg[i].iov_len);

256 257 258
        cpu_physical_memory_unmap(elem->in_sg[i].iov_base,
                                  elem->in_sg[i].iov_len,
                                  1, size);
A
aliguori 已提交
259

260
        offset += size;
A
aliguori 已提交
261 262
    }

263 264 265 266 267
    for (i = 0; i < elem->out_num; i++)
        cpu_physical_memory_unmap(elem->out_sg[i].iov_base,
                                  elem->out_sg[i].iov_len,
                                  0, elem->out_sg[i].iov_len);

A
aliguori 已提交
268 269 270 271 272 273 274 275 276
    idx = (idx + vring_used_idx(vq)) % vq->vring.num;

    /* Get a pointer to the next entry in the used ring. */
    vring_used_ring_id(vq, idx, elem->index);
    vring_used_ring_len(vq, idx, len);
}

void virtqueue_flush(VirtQueue *vq, unsigned int count)
{
M
Michael S. Tsirkin 已提交
277
    uint16_t old, new;
A
aliguori 已提交
278
    /* Make sure buffer is written before we update index. */
279
    smp_wmb();
280
    trace_virtqueue_flush(vq, count);
M
Michael S. Tsirkin 已提交
281 282 283
    old = vring_used_idx(vq);
    new = old + count;
    vring_used_idx_set(vq, new);
A
aliguori 已提交
284
    vq->inuse -= count;
M
Michael S. Tsirkin 已提交
285 286
    if (unlikely((int16_t)(new - vq->signalled_used) < (uint16_t)(new - old)))
        vq->signalled_used_valid = false;
A
aliguori 已提交
287 288 289 290 291 292 293 294 295 296 297 298 299 300
}

void virtqueue_push(VirtQueue *vq, const VirtQueueElement *elem,
                    unsigned int len)
{
    virtqueue_fill(vq, elem, len, 0);
    virtqueue_flush(vq, 1);
}

static int virtqueue_num_heads(VirtQueue *vq, unsigned int idx)
{
    uint16_t num_heads = vring_avail_idx(vq) - idx;

    /* Check it isn't doing very strange things with descriptor numbers. */
A
aliguori 已提交
301
    if (num_heads > vq->vring.num) {
302 303
        error_report("Guest moved used index from %u to %u",
                     idx, vring_avail_idx(vq));
A
aliguori 已提交
304 305
        exit(1);
    }
306 307 308 309 310
    /* On success, callers read a descriptor at vq->last_avail_idx.
     * Make sure descriptor read does not bypass avail index read. */
    if (num_heads) {
        smp_rmb();
    }
A
aliguori 已提交
311 312 313 314 315 316 317 318 319 320 321 322 323

    return num_heads;
}

static unsigned int virtqueue_get_head(VirtQueue *vq, unsigned int idx)
{
    unsigned int head;

    /* Grab the next descriptor number they're advertising, and increment
     * the index we've seen. */
    head = vring_avail_ring(vq, idx % vq->vring.num);

    /* If their number is silly, that's a fatal mistake. */
A
aliguori 已提交
324
    if (head >= vq->vring.num) {
325
        error_report("Guest says index %u is available", head);
A
aliguori 已提交
326 327
        exit(1);
    }
A
aliguori 已提交
328 329 330 331

    return head;
}

332
static unsigned virtqueue_next_desc(VirtIODevice *vdev, hwaddr desc_pa,
333
                                    unsigned int i, unsigned int max)
A
aliguori 已提交
334 335 336 337
{
    unsigned int next;

    /* If this descriptor says it doesn't chain, we're done. */
338
    if (!(vring_desc_flags(vdev, desc_pa, i) & VRING_DESC_F_NEXT)) {
339
        return max;
340
    }
A
aliguori 已提交
341 342

    /* Check they're not leading us off end of descriptors. */
343
    next = vring_desc_next(vdev, desc_pa, i);
A
aliguori 已提交
344
    /* Make sure compiler knows to grab that: we don't want it changing! */
345
    smp_wmb();
A
aliguori 已提交
346

347
    if (next >= max) {
348
        error_report("Desc next is %u", next);
A
aliguori 已提交
349 350
        exit(1);
    }
A
aliguori 已提交
351 352 353 354

    return next;
}

355
void virtqueue_get_avail_bytes(VirtQueue *vq, unsigned int *in_bytes,
356 357
                               unsigned int *out_bytes,
                               unsigned max_in_bytes, unsigned max_out_bytes)
A
aliguori 已提交
358
{
359
    unsigned int idx;
360
    unsigned int total_bufs, in_total, out_total;
A
aliguori 已提交
361 362 363

    idx = vq->last_avail_idx;

364
    total_bufs = in_total = out_total = 0;
A
aliguori 已提交
365
    while (virtqueue_num_heads(vq, idx)) {
366
        VirtIODevice *vdev = vq->vdev;
367
        unsigned int max, num_bufs, indirect = 0;
A
Avi Kivity 已提交
368
        hwaddr desc_pa;
A
aliguori 已提交
369 370
        int i;

371 372
        max = vq->vring.num;
        num_bufs = total_bufs;
A
aliguori 已提交
373
        i = virtqueue_get_head(vq, idx++);
374 375
        desc_pa = vq->vring.desc;

376 377
        if (vring_desc_flags(vdev, desc_pa, i) & VRING_DESC_F_INDIRECT) {
            if (vring_desc_len(vdev, desc_pa, i) % sizeof(VRingDesc)) {
378
                error_report("Invalid size for indirect buffer table");
379 380 381 382 383
                exit(1);
            }

            /* If we've got too many, that implies a descriptor loop. */
            if (num_bufs >= max) {
384
                error_report("Looped descriptor");
385 386 387 388 389
                exit(1);
            }

            /* loop over the indirect descriptor table */
            indirect = 1;
390 391
            max = vring_desc_len(vdev, desc_pa, i) / sizeof(VRingDesc);
            desc_pa = vring_desc_addr(vdev, desc_pa, i);
392
            num_bufs = i = 0;
393 394
        }

A
aliguori 已提交
395 396
        do {
            /* If we've got too many, that implies a descriptor loop. */
397
            if (++num_bufs > max) {
398
                error_report("Looped descriptor");
A
aliguori 已提交
399 400
                exit(1);
            }
A
aliguori 已提交
401

402 403
            if (vring_desc_flags(vdev, desc_pa, i) & VRING_DESC_F_WRITE) {
                in_total += vring_desc_len(vdev, desc_pa, i);
A
aliguori 已提交
404
            } else {
405
                out_total += vring_desc_len(vdev, desc_pa, i);
A
aliguori 已提交
406
            }
407 408 409
            if (in_total >= max_in_bytes && out_total >= max_out_bytes) {
                goto done;
            }
410
        } while ((i = virtqueue_next_desc(vdev, desc_pa, i, max)) != max);
411 412 413 414 415

        if (!indirect)
            total_bufs = num_bufs;
        else
            total_bufs++;
A
aliguori 已提交
416
    }
417
done:
418 419 420 421 422 423 424
    if (in_bytes) {
        *in_bytes = in_total;
    }
    if (out_bytes) {
        *out_bytes = out_total;
    }
}
A
aliguori 已提交
425

426 427 428 429 430
int virtqueue_avail_bytes(VirtQueue *vq, unsigned int in_bytes,
                          unsigned int out_bytes)
{
    unsigned int in_total, out_total;

431 432
    virtqueue_get_avail_bytes(vq, &in_total, &out_total, in_bytes, out_bytes);
    return in_bytes <= in_total && out_bytes <= out_total;
A
aliguori 已提交
433 434
}

A
Avi Kivity 已提交
435
void virtqueue_map_sg(struct iovec *sg, hwaddr *addr,
K
Kevin Wolf 已提交
436 437 438
    size_t num_sg, int is_write)
{
    unsigned int i;
A
Avi Kivity 已提交
439
    hwaddr len;
K
Kevin Wolf 已提交
440

441
    if (num_sg > VIRTQUEUE_MAX_SIZE) {
442 443 444 445 446
        error_report("virtio: map attempt out of bounds: %zd > %d",
                     num_sg, VIRTQUEUE_MAX_SIZE);
        exit(1);
    }

K
Kevin Wolf 已提交
447 448 449 450
    for (i = 0; i < num_sg; i++) {
        len = sg[i].iov_len;
        sg[i].iov_base = cpu_physical_memory_map(addr[i], &len, is_write);
        if (sg[i].iov_base == NULL || len != sg[i].iov_len) {
M
Michael Tokarev 已提交
451
            error_report("virtio: error trying to map MMIO memory");
K
Kevin Wolf 已提交
452 453 454 455 456
            exit(1);
        }
    }
}

A
aliguori 已提交
457 458
int virtqueue_pop(VirtQueue *vq, VirtQueueElement *elem)
{
459
    unsigned int i, head, max;
A
Avi Kivity 已提交
460
    hwaddr desc_pa = vq->vring.desc;
461
    VirtIODevice *vdev = vq->vdev;
A
aliguori 已提交
462 463 464 465 466 467 468

    if (!virtqueue_num_heads(vq, vq->last_avail_idx))
        return 0;

    /* When we start there are none of either input nor output. */
    elem->out_num = elem->in_num = 0;

469 470
    max = vq->vring.num;

A
aliguori 已提交
471
    i = head = virtqueue_get_head(vq, vq->last_avail_idx++);
472
    if (virtio_has_feature(vdev, VIRTIO_RING_F_EVENT_IDX)) {
473
        vring_set_avail_event(vq, vq->last_avail_idx);
M
Michael S. Tsirkin 已提交
474
    }
475

476 477
    if (vring_desc_flags(vdev, desc_pa, i) & VRING_DESC_F_INDIRECT) {
        if (vring_desc_len(vdev, desc_pa, i) % sizeof(VRingDesc)) {
478
            error_report("Invalid size for indirect buffer table");
479 480 481 482
            exit(1);
        }

        /* loop over the indirect descriptor table */
483 484
        max = vring_desc_len(vdev, desc_pa, i) / sizeof(VRingDesc);
        desc_pa = vring_desc_addr(vdev, desc_pa, i);
485 486 487
        i = 0;
    }

K
Kevin Wolf 已提交
488
    /* Collect all the descriptors */
A
aliguori 已提交
489 490 491
    do {
        struct iovec *sg;

492
        if (vring_desc_flags(vdev, desc_pa, i) & VRING_DESC_F_WRITE) {
493 494 495 496
            if (elem->in_num >= ARRAY_SIZE(elem->in_sg)) {
                error_report("Too many write descriptors in indirect table");
                exit(1);
            }
497
            elem->in_addr[elem->in_num] = vring_desc_addr(vdev, desc_pa, i);
A
aliguori 已提交
498
            sg = &elem->in_sg[elem->in_num++];
K
Kevin Wolf 已提交
499
        } else {
500 501 502 503
            if (elem->out_num >= ARRAY_SIZE(elem->out_sg)) {
                error_report("Too many read descriptors in indirect table");
                exit(1);
            }
504
            elem->out_addr[elem->out_num] = vring_desc_addr(vdev, desc_pa, i);
A
aliguori 已提交
505
            sg = &elem->out_sg[elem->out_num++];
K
Kevin Wolf 已提交
506
        }
A
aliguori 已提交
507

508
        sg->iov_len = vring_desc_len(vdev, desc_pa, i);
A
aliguori 已提交
509 510

        /* If we've got too many, that implies a descriptor loop. */
511
        if ((elem->in_num + elem->out_num) > max) {
512
            error_report("Looped descriptor");
A
aliguori 已提交
513 514
            exit(1);
        }
515
    } while ((i = virtqueue_next_desc(vdev, desc_pa, i, max)) != max);
A
aliguori 已提交
516

K
Kevin Wolf 已提交
517 518 519 520
    /* Now map what we have collected */
    virtqueue_map_sg(elem->in_sg, elem->in_addr, elem->in_num, 1);
    virtqueue_map_sg(elem->out_sg, elem->out_addr, elem->out_num, 0);

A
aliguori 已提交
521 522 523 524
    elem->index = head;

    vq->inuse++;

525
    trace_virtqueue_pop(vq, elem, elem->in_num, elem->out_num);
A
aliguori 已提交
526 527 528 529
    return elem->in_num + elem->out_num;
}

/* virtio device */
530 531
static void virtio_notify_vector(VirtIODevice *vdev, uint16_t vector)
{
K
KONRAD Frederic 已提交
532 533 534 535 536
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);

    if (k->notify) {
        k->notify(qbus->parent, vector);
537 538
    }
}
A
aliguori 已提交
539

P
Paul Brook 已提交
540
void virtio_update_irq(VirtIODevice *vdev)
A
aliguori 已提交
541
{
542
    virtio_notify_vector(vdev, VIRTIO_NO_VECTOR);
A
aliguori 已提交
543 544
}

545 546
void virtio_set_status(VirtIODevice *vdev, uint8_t val)
{
547
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
548 549
    trace_virtio_set_status(vdev, val);

550 551
    if (k->set_status) {
        k->set_status(vdev, val);
552 553 554 555
    }
    vdev->status = val;
}

556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576
bool target_words_bigendian(void);
static enum virtio_device_endian virtio_default_endian(void)
{
    if (target_words_bigendian()) {
        return VIRTIO_DEVICE_ENDIAN_BIG;
    } else {
        return VIRTIO_DEVICE_ENDIAN_LITTLE;
    }
}

static enum virtio_device_endian virtio_current_cpu_endian(void)
{
    CPUClass *cc = CPU_GET_CLASS(current_cpu);

    if (cc->virtio_is_big_endian(current_cpu)) {
        return VIRTIO_DEVICE_ENDIAN_BIG;
    } else {
        return VIRTIO_DEVICE_ENDIAN_LITTLE;
    }
}

P
Paul Brook 已提交
577
void virtio_reset(void *opaque)
A
aliguori 已提交
578 579
{
    VirtIODevice *vdev = opaque;
580
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
581 582
    int i;

583
    virtio_set_status(vdev, 0);
584 585 586 587 588 589 590
    if (current_cpu) {
        /* Guest initiated reset */
        vdev->device_endian = virtio_current_cpu_endian();
    } else {
        /* System reset */
        vdev->device_endian = virtio_default_endian();
    }
591

592 593 594
    if (k->reset) {
        k->reset(vdev);
    }
A
aliguori 已提交
595

596
    vdev->guest_features = 0;
A
aliguori 已提交
597 598 599
    vdev->queue_sel = 0;
    vdev->status = 0;
    vdev->isr = 0;
600 601
    vdev->config_vector = VIRTIO_NO_VECTOR;
    virtio_notify_vector(vdev, vdev->config_vector);
A
aliguori 已提交
602

603
    for(i = 0; i < VIRTIO_QUEUE_MAX; i++) {
A
aliguori 已提交
604 605 606 607
        vdev->vq[i].vring.desc = 0;
        vdev->vq[i].vring.avail = 0;
        vdev->vq[i].vring.used = 0;
        vdev->vq[i].last_avail_idx = 0;
P
Paul Brook 已提交
608
        vdev->vq[i].pa = 0;
609
        virtio_queue_set_vector(vdev, i, VIRTIO_NO_VECTOR);
M
Michael S. Tsirkin 已提交
610 611 612
        vdev->vq[i].signalled_used = 0;
        vdev->vq[i].signalled_used_valid = false;
        vdev->vq[i].notification = true;
A
aliguori 已提交
613 614 615
    }
}

P
Paul Brook 已提交
616
uint32_t virtio_config_readb(VirtIODevice *vdev, uint32_t addr)
A
aliguori 已提交
617
{
618
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
619 620
    uint8_t val;

621
    if (addr + sizeof(val) > vdev->config_len) {
A
aliguori 已提交
622
        return (uint32_t)-1;
623 624 625
    }

    k->get_config(vdev, vdev->config);
A
aliguori 已提交
626

627
    val = ldub_p(vdev->config + addr);
A
aliguori 已提交
628 629 630
    return val;
}

P
Paul Brook 已提交
631
uint32_t virtio_config_readw(VirtIODevice *vdev, uint32_t addr)
A
aliguori 已提交
632
{
633
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
634 635
    uint16_t val;

636
    if (addr + sizeof(val) > vdev->config_len) {
A
aliguori 已提交
637
        return (uint32_t)-1;
638 639 640
    }

    k->get_config(vdev, vdev->config);
A
aliguori 已提交
641

642
    val = lduw_p(vdev->config + addr);
A
aliguori 已提交
643 644 645
    return val;
}

P
Paul Brook 已提交
646
uint32_t virtio_config_readl(VirtIODevice *vdev, uint32_t addr)
A
aliguori 已提交
647
{
648
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
649 650
    uint32_t val;

651
    if (addr + sizeof(val) > vdev->config_len) {
A
aliguori 已提交
652
        return (uint32_t)-1;
653 654 655
    }

    k->get_config(vdev, vdev->config);
A
aliguori 已提交
656

657
    val = ldl_p(vdev->config + addr);
A
aliguori 已提交
658 659 660
    return val;
}

P
Paul Brook 已提交
661
void virtio_config_writeb(VirtIODevice *vdev, uint32_t addr, uint32_t data)
A
aliguori 已提交
662
{
663
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
664 665
    uint8_t val = data;

666
    if (addr + sizeof(val) > vdev->config_len) {
A
aliguori 已提交
667
        return;
668
    }
A
aliguori 已提交
669

670
    stb_p(vdev->config + addr, val);
A
aliguori 已提交
671

672 673 674
    if (k->set_config) {
        k->set_config(vdev, vdev->config);
    }
A
aliguori 已提交
675 676
}

P
Paul Brook 已提交
677
void virtio_config_writew(VirtIODevice *vdev, uint32_t addr, uint32_t data)
A
aliguori 已提交
678
{
679
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
680 681
    uint16_t val = data;

682
    if (addr + sizeof(val) > vdev->config_len) {
A
aliguori 已提交
683
        return;
684
    }
A
aliguori 已提交
685

686
    stw_p(vdev->config + addr, val);
A
aliguori 已提交
687

688 689 690
    if (k->set_config) {
        k->set_config(vdev, vdev->config);
    }
A
aliguori 已提交
691 692
}

P
Paul Brook 已提交
693
void virtio_config_writel(VirtIODevice *vdev, uint32_t addr, uint32_t data)
A
aliguori 已提交
694
{
695
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
696 697
    uint32_t val = data;

698
    if (addr + sizeof(val) > vdev->config_len) {
A
aliguori 已提交
699
        return;
700
    }
A
aliguori 已提交
701

702
    stl_p(vdev->config + addr, val);
A
aliguori 已提交
703

704 705 706
    if (k->set_config) {
        k->set_config(vdev, vdev->config);
    }
A
aliguori 已提交
707 708
}

A
Avi Kivity 已提交
709
void virtio_queue_set_addr(VirtIODevice *vdev, int n, hwaddr addr)
A
aliguori 已提交
710
{
711 712
    vdev->vq[n].pa = addr;
    virtqueue_init(&vdev->vq[n]);
P
Paul Brook 已提交
713 714
}

A
Avi Kivity 已提交
715
hwaddr virtio_queue_get_addr(VirtIODevice *vdev, int n)
P
Paul Brook 已提交
716 717 718 719
{
    return vdev->vq[n].pa;
}

720 721
void virtio_queue_set_num(VirtIODevice *vdev, int n, int num)
{
722 723 724 725 726 727 728
    /* Don't allow guest to flip queue between existent and
     * nonexistent states, or to set it to an invalid size.
     */
    if (!!num != !!vdev->vq[n].vring.num ||
        num > VIRTQUEUE_MAX_SIZE ||
        num < 0) {
        return;
729
    }
730 731
    vdev->vq[n].vring.num = num;
    virtqueue_init(&vdev->vq[n]);
732 733
}

734 735 736 737 738 739 740 741 742 743
VirtQueue *virtio_vector_first_queue(VirtIODevice *vdev, uint16_t vector)
{
    return QLIST_FIRST(&vdev->vector_queues[vector]);
}

VirtQueue *virtio_vector_next_queue(VirtQueue *vq)
{
    return QLIST_NEXT(vq, node);
}

P
Paul Brook 已提交
744 745 746 747
int virtio_queue_get_num(VirtIODevice *vdev, int n)
{
    return vdev->vq[n].vring.num;
}
A
aliguori 已提交
748

749 750 751 752
int virtio_get_num_queues(VirtIODevice *vdev)
{
    int i;

753
    for (i = 0; i < VIRTIO_QUEUE_MAX; i++) {
754 755 756 757 758 759 760 761
        if (!virtio_queue_get_num(vdev, i)) {
            break;
        }
    }

    return i;
}

P
Paolo Bonzini 已提交
762 763 764
int virtio_queue_get_id(VirtQueue *vq)
{
    VirtIODevice *vdev = vq->vdev;
765
    assert(vq >= &vdev->vq[0] && vq < &vdev->vq[VIRTIO_QUEUE_MAX]);
P
Paolo Bonzini 已提交
766 767 768
    return vq - &vdev->vq[0];
}

769 770 771 772 773 774 775 776 777 778 779 780 781 782 783
void virtio_queue_set_align(VirtIODevice *vdev, int n, int align)
{
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);

    /* Check that the transport told us it was going to do this
     * (so a buggy transport will immediately assert rather than
     * silently failing to migrate this state)
     */
    assert(k->has_variable_vring_alignment);

    vdev->vq[n].vring.align = align;
    virtqueue_init(&vdev->vq[n]);
}

784 785
void virtio_queue_notify_vq(VirtQueue *vq)
{
786
    if (vq->vring.desc && vq->handle_output) {
787
        VirtIODevice *vdev = vq->vdev;
788

789 790 791 792 793
        trace_virtio_queue_notify(vdev, vq - vdev->vq, vq);
        vq->handle_output(vdev, vq);
    }
}

P
Paul Brook 已提交
794 795
void virtio_queue_notify(VirtIODevice *vdev, int n)
{
796
    virtio_queue_notify_vq(&vdev->vq[n]);
A
aliguori 已提交
797 798
}

799 800
uint16_t virtio_queue_vector(VirtIODevice *vdev, int n)
{
801
    return n < VIRTIO_QUEUE_MAX ? vdev->vq[n].vector :
802 803 804 805 806
        VIRTIO_NO_VECTOR;
}

void virtio_queue_set_vector(VirtIODevice *vdev, int n, uint16_t vector)
{
807 808
    VirtQueue *vq = &vdev->vq[n];

809
    if (n < VIRTIO_QUEUE_MAX) {
810 811 812 813
        if (vdev->vector_queues &&
            vdev->vq[n].vector != VIRTIO_NO_VECTOR) {
            QLIST_REMOVE(vq, node);
        }
814
        vdev->vq[n].vector = vector;
815 816 817 818 819
        if (vdev->vector_queues &&
            vector != VIRTIO_NO_VECTOR) {
            QLIST_INSERT_HEAD(&vdev->vector_queues[vector], vq, node);
        }
    }
820 821
}

A
aliguori 已提交
822 823 824 825 826
VirtQueue *virtio_add_queue(VirtIODevice *vdev, int queue_size,
                            void (*handle_output)(VirtIODevice *, VirtQueue *))
{
    int i;

827
    for (i = 0; i < VIRTIO_QUEUE_MAX; i++) {
A
aliguori 已提交
828 829 830 831
        if (vdev->vq[i].vring.num == 0)
            break;
    }

832
    if (i == VIRTIO_QUEUE_MAX || queue_size > VIRTQUEUE_MAX_SIZE)
A
aliguori 已提交
833 834 835
        abort();

    vdev->vq[i].vring.num = queue_size;
836
    vdev->vq[i].vring.align = VIRTIO_PCI_VRING_ALIGN;
A
aliguori 已提交
837 838 839 840 841
    vdev->vq[i].handle_output = handle_output;

    return &vdev->vq[i];
}

842 843
void virtio_del_queue(VirtIODevice *vdev, int n)
{
844
    if (n < 0 || n >= VIRTIO_QUEUE_MAX) {
845 846 847 848 849 850
        abort();
    }

    vdev->vq[n].vring.num = 0;
}

851 852
void virtio_irq(VirtQueue *vq)
{
853
    trace_virtio_irq(vq);
854 855 856 857
    vq->vdev->isr |= 0x01;
    virtio_notify_vector(vq->vdev, vq->vector);
}

M
Michael S. Tsirkin 已提交
858 859 860 861
static bool vring_notify(VirtIODevice *vdev, VirtQueue *vq)
{
    uint16_t old, new;
    bool v;
862 863
    /* We need to expose used array entries before checking used event. */
    smp_mb();
864
    /* Always notify when queue is empty (when feature acknowledge) */
865 866
    if (virtio_has_feature(vdev, VIRTIO_F_NOTIFY_ON_EMPTY) &&
        !vq->inuse && vring_avail_idx(vq) == vq->last_avail_idx) {
M
Michael S. Tsirkin 已提交
867 868 869
        return true;
    }

870
    if (!virtio_has_feature(vdev, VIRTIO_RING_F_EVENT_IDX)) {
M
Michael S. Tsirkin 已提交
871 872 873 874 875 876 877
        return !(vring_avail_flags(vq) & VRING_AVAIL_F_NO_INTERRUPT);
    }

    v = vq->signalled_used_valid;
    vq->signalled_used_valid = true;
    old = vq->signalled_used;
    new = vq->signalled_used = vring_used_idx(vq);
878
    return !v || vring_need_event(vring_get_used_event(vq), new, old);
M
Michael S. Tsirkin 已提交
879 880 881 882 883
}

void virtio_notify(VirtIODevice *vdev, VirtQueue *vq)
{
    if (!vring_notify(vdev, vq)) {
A
aliguori 已提交
884
        return;
M
Michael S. Tsirkin 已提交
885
    }
A
aliguori 已提交
886

887
    trace_virtio_notify(vdev, vq);
A
aliguori 已提交
888
    vdev->isr |= 0x01;
889
    virtio_notify_vector(vdev, vq->vector);
A
aliguori 已提交
890 891 892 893
}

void virtio_notify_config(VirtIODevice *vdev)
{
894 895 896
    if (!(vdev->status & VIRTIO_CONFIG_S_DRIVER_OK))
        return;

A
aliguori 已提交
897
    vdev->isr |= 0x03;
898
    virtio_notify_vector(vdev, vdev->config_vector);
A
aliguori 已提交
899 900
}

901 902 903 904 905 906 907 908
static bool virtio_device_endian_needed(void *opaque)
{
    VirtIODevice *vdev = opaque;

    assert(vdev->device_endian != VIRTIO_DEVICE_ENDIAN_UNKNOWN);
    return vdev->device_endian != virtio_default_endian();
}

G
Gerd Hoffmann 已提交
909 910 911 912 913 914 915
static bool virtio_64bit_features_needed(void *opaque)
{
    VirtIODevice *vdev = opaque;

    return (vdev->host_features >> 32) != 0;
}

916 917 918 919 920 921 922 923 924 925
static const VMStateDescription vmstate_virtio_device_endian = {
    .name = "virtio/device_endian",
    .version_id = 1,
    .minimum_version_id = 1,
    .fields = (VMStateField[]) {
        VMSTATE_UINT8(device_endian, VirtIODevice),
        VMSTATE_END_OF_LIST()
    }
};

G
Gerd Hoffmann 已提交
926 927 928 929 930 931 932 933 934 935
static const VMStateDescription vmstate_virtio_64bit_features = {
    .name = "virtio/64bit_features",
    .version_id = 1,
    .minimum_version_id = 1,
    .fields = (VMStateField[]) {
        VMSTATE_UINT64(guest_features, VirtIODevice),
        VMSTATE_END_OF_LIST()
    }
};

936 937 938 939 940 941 942
static const VMStateDescription vmstate_virtio = {
    .name = "virtio",
    .version_id = 1,
    .minimum_version_id = 1,
    .minimum_version_id_old = 1,
    .fields = (VMStateField[]) {
        VMSTATE_END_OF_LIST()
943 944 945 946 947 948
    },
    .subsections = (VMStateSubsection[]) {
        {
            .vmsd = &vmstate_virtio_device_endian,
            .needed = &virtio_device_endian_needed
        },
G
Gerd Hoffmann 已提交
949 950 951 952
        {
            .vmsd = &vmstate_virtio_64bit_features,
            .needed = &virtio_64bit_features_needed
        },
953
        { 0 }
954 955 956
    }
};

A
aliguori 已提交
957 958
void virtio_save(VirtIODevice *vdev, QEMUFile *f)
{
K
KONRAD Frederic 已提交
959 960
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);
961
    VirtioDeviceClass *vdc = VIRTIO_DEVICE_GET_CLASS(vdev);
G
Gerd Hoffmann 已提交
962
    uint32_t guest_features_lo = (vdev->guest_features & 0xffffffff);
A
aliguori 已提交
963 964
    int i;

K
KONRAD Frederic 已提交
965 966 967
    if (k->save_config) {
        k->save_config(qbus->parent, f);
    }
A
aliguori 已提交
968 969 970 971

    qemu_put_8s(f, &vdev->status);
    qemu_put_8s(f, &vdev->isr);
    qemu_put_be16s(f, &vdev->queue_sel);
G
Gerd Hoffmann 已提交
972
    qemu_put_be32s(f, &guest_features_lo);
A
aliguori 已提交
973 974 975
    qemu_put_be32(f, vdev->config_len);
    qemu_put_buffer(f, vdev->config, vdev->config_len);

976
    for (i = 0; i < VIRTIO_QUEUE_MAX; i++) {
A
aliguori 已提交
977 978 979 980 981 982
        if (vdev->vq[i].vring.num == 0)
            break;
    }

    qemu_put_be32(f, i);

983
    for (i = 0; i < VIRTIO_QUEUE_MAX; i++) {
A
aliguori 已提交
984 985 986 987
        if (vdev->vq[i].vring.num == 0)
            break;

        qemu_put_be32(f, vdev->vq[i].vring.num);
988 989 990
        if (k->has_variable_vring_alignment) {
            qemu_put_be32(f, vdev->vq[i].vring.align);
        }
P
Paul Brook 已提交
991
        qemu_put_be64(f, vdev->vq[i].pa);
A
aliguori 已提交
992
        qemu_put_be16s(f, &vdev->vq[i].last_avail_idx);
K
KONRAD Frederic 已提交
993 994 995
        if (k->save_queue) {
            k->save_queue(qbus->parent, i, f);
        }
A
aliguori 已提交
996
    }
997 998 999 1000

    if (vdc->save != NULL) {
        vdc->save(vdev, f);
    }
1001 1002

    /* Subsections */
1003
    vmstate_save_state(f, &vmstate_virtio, vdev, NULL);
A
aliguori 已提交
1004 1005
}

G
Gerd Hoffmann 已提交
1006
int virtio_set_features(VirtIODevice *vdev, uint64_t val)
1007
{
1008
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
C
Cornelia Huck 已提交
1009
    bool bad = (val & ~(vdev->host_features)) != 0;
1010

C
Cornelia Huck 已提交
1011
    val &= vdev->host_features;
1012 1013
    if (k->set_features) {
        k->set_features(vdev, val);
1014 1015 1016 1017 1018
    }
    vdev->guest_features = val;
    return bad ? -1 : 0;
}

1019
int virtio_load(VirtIODevice *vdev, QEMUFile *f, int version_id)
A
aliguori 已提交
1020
{
1021
    int i, ret;
1022
    int32_t config_len;
1023
    uint32_t num;
1024
    uint32_t features;
K
KONRAD Frederic 已提交
1025 1026
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);
1027
    VirtioDeviceClass *vdc = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
1028

1029 1030 1031 1032 1033 1034
    /*
     * We poison the endianness to ensure it does not get used before
     * subsections have been loaded.
     */
    vdev->device_endian = VIRTIO_DEVICE_ENDIAN_UNKNOWN;

K
KONRAD Frederic 已提交
1035 1036
    if (k->load_config) {
        ret = k->load_config(qbus->parent, f);
1037 1038 1039
        if (ret)
            return ret;
    }
A
aliguori 已提交
1040 1041 1042 1043

    qemu_get_8s(f, &vdev->status);
    qemu_get_8s(f, &vdev->isr);
    qemu_get_be16s(f, &vdev->queue_sel);
1044
    if (vdev->queue_sel >= VIRTIO_QUEUE_MAX) {
1045 1046
        return -1;
    }
1047
    qemu_get_be32s(f, &features);
1048

1049
    config_len = qemu_get_be32(f);
1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060

    /*
     * There are cases where the incoming config can be bigger or smaller
     * than what we have; so load what we have space for, and skip
     * any excess that's in the stream.
     */
    qemu_get_buffer(f, vdev->config, MIN(config_len, vdev->config_len));

    while (config_len > vdev->config_len) {
        qemu_get_byte(f);
        config_len--;
1061
    }
A
aliguori 已提交
1062 1063 1064

    num = qemu_get_be32(f);

1065
    if (num > VIRTIO_QUEUE_MAX) {
1066 1067 1068 1069
        error_report("Invalid number of PCI queues: 0x%x", num);
        return -1;
    }

A
aliguori 已提交
1070 1071
    for (i = 0; i < num; i++) {
        vdev->vq[i].vring.num = qemu_get_be32(f);
1072 1073 1074
        if (k->has_variable_vring_alignment) {
            vdev->vq[i].vring.align = qemu_get_be32(f);
        }
P
Paul Brook 已提交
1075
        vdev->vq[i].pa = qemu_get_be64(f);
A
aliguori 已提交
1076
        qemu_get_be16s(f, &vdev->vq[i].last_avail_idx);
M
Michael S. Tsirkin 已提交
1077 1078
        vdev->vq[i].signalled_used_valid = false;
        vdev->vq[i].notification = true;
A
aliguori 已提交
1079

P
Paul Brook 已提交
1080 1081
        if (vdev->vq[i].pa) {
            virtqueue_init(&vdev->vq[i]);
M
Michael S. Tsirkin 已提交
1082 1083
        } else if (vdev->vq[i].last_avail_idx) {
            error_report("VQ %d address 0x0 "
1084
                         "inconsistent with Host index 0x%x",
M
Michael S. Tsirkin 已提交
1085 1086
                         i, vdev->vq[i].last_avail_idx);
                return -1;
1087
	}
K
KONRAD Frederic 已提交
1088 1089
        if (k->load_queue) {
            ret = k->load_queue(qbus->parent, i, f);
1090 1091
            if (ret)
                return ret;
1092
        }
A
aliguori 已提交
1093 1094
    }

1095
    virtio_notify_vector(vdev, VIRTIO_NO_VECTOR);
1096 1097

    if (vdc->load != NULL) {
1098 1099 1100 1101
        ret = vdc->load(vdev, f, version_id);
        if (ret) {
            return ret;
        }
1102 1103
    }

1104 1105 1106 1107 1108 1109 1110 1111 1112 1113
    /* Subsections */
    ret = vmstate_load_state(f, &vmstate_virtio, vdev, 1);
    if (ret) {
        return ret;
    }

    if (vdev->device_endian == VIRTIO_DEVICE_ENDIAN_UNKNOWN) {
        vdev->device_endian = virtio_default_endian();
    }

G
Gerd Hoffmann 已提交
1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135
    if (virtio_64bit_features_needed(vdev)) {
        /*
         * Subsection load filled vdev->guest_features.  Run them
         * through virtio_set_features to sanity-check them against
         * host_features.
         */
        uint64_t features64 = vdev->guest_features;
        if (virtio_set_features(vdev, features64) < 0) {
            error_report("Features 0x%" PRIx64 " unsupported. "
                         "Allowed features: 0x%" PRIx64,
                         features64, vdev->host_features);
            return -1;
        }
    } else {
        if (virtio_set_features(vdev, features) < 0) {
            error_report("Features 0x%x unsupported. "
                         "Allowed features: 0x%" PRIx64,
                         features, vdev->host_features);
            return -1;
        }
    }

1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149 1150 1151 1152
    for (i = 0; i < num; i++) {
        if (vdev->vq[i].pa) {
            uint16_t nheads;
            nheads = vring_avail_idx(&vdev->vq[i]) - vdev->vq[i].last_avail_idx;
            /* Check it isn't doing strange things with descriptor numbers. */
            if (nheads > vdev->vq[i].vring.num) {
                error_report("VQ %d size 0x%x Guest index 0x%x "
                             "inconsistent with Host index 0x%x: delta 0x%x",
                             i, vdev->vq[i].vring.num,
                             vring_avail_idx(&vdev->vq[i]),
                             vdev->vq[i].last_avail_idx, nheads);
                return -1;
            }
        }
    }

    return 0;
A
aliguori 已提交
1153 1154
}

1155
void virtio_cleanup(VirtIODevice *vdev)
1156
{
1157
    qemu_del_vm_change_state_handler(vdev->vmstate);
1158
    g_free(vdev->config);
1159
    g_free(vdev->vq);
1160
    g_free(vdev->vector_queues);
1161 1162
}

1163
static void virtio_vmstate_change(void *opaque, int running, RunState state)
1164 1165
{
    VirtIODevice *vdev = opaque;
K
KONRAD Frederic 已提交
1166 1167
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);
1168
    bool backend_run = running && (vdev->status & VIRTIO_CONFIG_S_DRIVER_OK);
1169
    vdev->vm_running = running;
1170 1171 1172 1173 1174

    if (backend_run) {
        virtio_set_status(vdev, vdev->status);
    }

K
KONRAD Frederic 已提交
1175 1176
    if (k->vmstate_change) {
        k->vmstate_change(qbus->parent, backend_run);
1177 1178 1179 1180 1181 1182 1183
    }

    if (!backend_run) {
        virtio_set_status(vdev, vdev->status);
    }
}

1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194
void virtio_instance_init_common(Object *proxy_obj, void *data,
                                 size_t vdev_size, const char *vdev_name)
{
    DeviceState *vdev = data;

    object_initialize(vdev, vdev_size, vdev_name);
    object_property_add_child(proxy_obj, "virtio-backend", OBJECT(vdev), NULL);
    object_unref(OBJECT(vdev));
    qdev_alias_all_properties(vdev, proxy_obj);
}

1195 1196
void virtio_init(VirtIODevice *vdev, const char *name,
                 uint16_t device_id, size_t config_size)
A
aliguori 已提交
1197
{
1198 1199
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);
1200
    int i;
1201 1202 1203 1204 1205 1206 1207
    int nvectors = k->query_nvectors ? k->query_nvectors(qbus->parent) : 0;

    if (nvectors) {
        vdev->vector_queues =
            g_malloc0(sizeof(*vdev->vector_queues) * nvectors);
    }

P
Paul Brook 已提交
1208
    vdev->device_id = device_id;
A
aliguori 已提交
1209 1210 1211
    vdev->status = 0;
    vdev->isr = 0;
    vdev->queue_sel = 0;
1212
    vdev->config_vector = VIRTIO_NO_VECTOR;
1213
    vdev->vq = g_malloc0(sizeof(VirtQueue) * VIRTIO_QUEUE_MAX);
1214
    vdev->vm_running = runstate_is_running();
1215
    for (i = 0; i < VIRTIO_QUEUE_MAX; i++) {
1216
        vdev->vq[i].vector = VIRTIO_NO_VECTOR;
1217
        vdev->vq[i].vdev = vdev;
1218
        vdev->vq[i].queue_index = i;
1219
    }
A
aliguori 已提交
1220 1221 1222

    vdev->name = name;
    vdev->config_len = config_size;
1223
    if (vdev->config_len) {
1224
        vdev->config = g_malloc0(config_size);
1225
    } else {
A
aliguori 已提交
1226
        vdev->config = NULL;
1227 1228 1229
    }
    vdev->vmstate = qemu_add_vm_change_state_handler(virtio_vmstate_change,
                                                     vdev);
1230
    vdev->device_endian = virtio_default_endian();
1231
}
A
aliguori 已提交
1232

A
Avi Kivity 已提交
1233
hwaddr virtio_queue_get_desc_addr(VirtIODevice *vdev, int n)
1234 1235 1236 1237
{
    return vdev->vq[n].vring.desc;
}

A
Avi Kivity 已提交
1238
hwaddr virtio_queue_get_avail_addr(VirtIODevice *vdev, int n)
1239 1240 1241 1242
{
    return vdev->vq[n].vring.avail;
}

A
Avi Kivity 已提交
1243
hwaddr virtio_queue_get_used_addr(VirtIODevice *vdev, int n)
1244 1245 1246 1247
{
    return vdev->vq[n].vring.used;
}

A
Avi Kivity 已提交
1248
hwaddr virtio_queue_get_ring_addr(VirtIODevice *vdev, int n)
1249 1250 1251 1252
{
    return vdev->vq[n].vring.desc;
}

A
Avi Kivity 已提交
1253
hwaddr virtio_queue_get_desc_size(VirtIODevice *vdev, int n)
1254 1255 1256 1257
{
    return sizeof(VRingDesc) * vdev->vq[n].vring.num;
}

A
Avi Kivity 已提交
1258
hwaddr virtio_queue_get_avail_size(VirtIODevice *vdev, int n)
1259 1260
{
    return offsetof(VRingAvail, ring) +
1261
        sizeof(uint64_t) * vdev->vq[n].vring.num;
1262 1263
}

A
Avi Kivity 已提交
1264
hwaddr virtio_queue_get_used_size(VirtIODevice *vdev, int n)
1265 1266 1267 1268 1269
{
    return offsetof(VRingUsed, ring) +
        sizeof(VRingUsedElem) * vdev->vq[n].vring.num;
}

A
Avi Kivity 已提交
1270
hwaddr virtio_queue_get_ring_size(VirtIODevice *vdev, int n)
1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285
{
    return vdev->vq[n].vring.used - vdev->vq[n].vring.desc +
	    virtio_queue_get_used_size(vdev, n);
}

uint16_t virtio_queue_get_last_avail_idx(VirtIODevice *vdev, int n)
{
    return vdev->vq[n].last_avail_idx;
}

void virtio_queue_set_last_avail_idx(VirtIODevice *vdev, int n, uint16_t idx)
{
    vdev->vq[n].last_avail_idx = idx;
}

1286 1287 1288 1289 1290
void virtio_queue_invalidate_signalled_used(VirtIODevice *vdev, int n)
{
    vdev->vq[n].signalled_used_valid = false;
}

1291 1292 1293 1294 1295
VirtQueue *virtio_get_queue(VirtIODevice *vdev, int n)
{
    return vdev->vq + n;
}

1296 1297 1298 1299 1300
uint16_t virtio_get_queue_index(VirtQueue *vq)
{
    return vq->queue_index;
}

1301 1302 1303 1304 1305 1306 1307 1308 1309 1310 1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324
static void virtio_queue_guest_notifier_read(EventNotifier *n)
{
    VirtQueue *vq = container_of(n, VirtQueue, guest_notifier);
    if (event_notifier_test_and_clear(n)) {
        virtio_irq(vq);
    }
}

void virtio_queue_set_guest_notifier_fd_handler(VirtQueue *vq, bool assign,
                                                bool with_irqfd)
{
    if (assign && !with_irqfd) {
        event_notifier_set_handler(&vq->guest_notifier,
                                   virtio_queue_guest_notifier_read);
    } else {
        event_notifier_set_handler(&vq->guest_notifier, NULL);
    }
    if (!assign) {
        /* Test and clear notifier before closing it,
         * in case poll callback didn't have time to run. */
        virtio_queue_guest_notifier_read(&vq->guest_notifier);
    }
}

1325 1326 1327 1328
EventNotifier *virtio_queue_get_guest_notifier(VirtQueue *vq)
{
    return &vq->guest_notifier;
}
1329 1330 1331 1332 1333 1334 1335 1336 1337

static void virtio_queue_host_notifier_read(EventNotifier *n)
{
    VirtQueue *vq = container_of(n, VirtQueue, host_notifier);
    if (event_notifier_test_and_clear(n)) {
        virtio_queue_notify_vq(vq);
    }
}

P
Paolo Bonzini 已提交
1338 1339
void virtio_queue_set_host_notifier_fd_handler(VirtQueue *vq, bool assign,
                                               bool set_handler)
1340
{
P
Paolo Bonzini 已提交
1341
    if (assign && set_handler) {
1342 1343 1344 1345
        event_notifier_set_handler(&vq->host_notifier,
                                   virtio_queue_host_notifier_read);
    } else {
        event_notifier_set_handler(&vq->host_notifier, NULL);
P
Paolo Bonzini 已提交
1346 1347
    }
    if (!assign) {
1348 1349 1350 1351 1352 1353
        /* Test and clear notifier before after disabling event,
         * in case poll callback didn't have time to run. */
        virtio_queue_host_notifier_read(&vq->host_notifier);
    }
}

1354 1355 1356 1357
EventNotifier *virtio_queue_get_host_notifier(VirtQueue *vq)
{
    return &vq->host_notifier;
}
1358

1359 1360
void virtio_device_set_child_bus_name(VirtIODevice *vdev, char *bus_name)
{
1361
    g_free(vdev->bus_name);
1362
    vdev->bus_name = g_strdup(bus_name);
1363 1364
}

1365 1366 1367 1368 1369 1370 1371 1372 1373 1374 1375 1376
static void virtio_device_realize(DeviceState *dev, Error **errp)
{
    VirtIODevice *vdev = VIRTIO_DEVICE(dev);
    VirtioDeviceClass *vdc = VIRTIO_DEVICE_GET_CLASS(dev);
    Error *err = NULL;

    if (vdc->realize != NULL) {
        vdc->realize(dev, &err);
        if (err != NULL) {
            error_propagate(errp, err);
            return;
        }
1377
    }
J
Jason Wang 已提交
1378 1379 1380 1381 1382 1383

    virtio_bus_device_plugged(vdev, &err);
    if (err != NULL) {
        error_propagate(errp, err);
        return;
    }
1384 1385
}

1386
static void virtio_device_unrealize(DeviceState *dev, Error **errp)
1387
{
1388
    VirtIODevice *vdev = VIRTIO_DEVICE(dev);
1389 1390
    VirtioDeviceClass *vdc = VIRTIO_DEVICE_GET_CLASS(dev);
    Error *err = NULL;
1391

1392 1393
    virtio_bus_device_unplugged(vdev);

1394 1395 1396 1397 1398 1399
    if (vdc->unrealize != NULL) {
        vdc->unrealize(dev, &err);
        if (err != NULL) {
            error_propagate(errp, err);
            return;
        }
1400
    }
1401

1402 1403
    g_free(vdev->bus_name);
    vdev->bus_name = NULL;
1404 1405
}

C
Cornelia Huck 已提交
1406 1407 1408 1409 1410
static Property virtio_properties[] = {
    DEFINE_VIRTIO_COMMON_FEATURES(VirtIODevice, host_features),
    DEFINE_PROP_END_OF_LIST(),
};

1411 1412 1413 1414
static void virtio_device_class_init(ObjectClass *klass, void *data)
{
    /* Set the default value here. */
    DeviceClass *dc = DEVICE_CLASS(klass);
1415 1416 1417

    dc->realize = virtio_device_realize;
    dc->unrealize = virtio_device_unrealize;
1418
    dc->bus_type = TYPE_VIRTIO_BUS;
C
Cornelia Huck 已提交
1419
    dc->props = virtio_properties;
1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436
}

static const TypeInfo virtio_device_info = {
    .name = TYPE_VIRTIO_DEVICE,
    .parent = TYPE_DEVICE,
    .instance_size = sizeof(VirtIODevice),
    .class_init = virtio_device_class_init,
    .abstract = true,
    .class_size = sizeof(VirtioDeviceClass),
};

static void virtio_register_types(void)
{
    type_register_static(&virtio_device_info);
}

type_init(virtio_register_types)