exec.c 74.9 KB
Newer Older
B
bellard 已提交
1
/*
2
 *  Virtual page mapping
3
 *
B
bellard 已提交
4 5 6 7 8 9 10 11 12 13 14 15 16
 *  Copyright (c) 2003 Fabrice Bellard
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
17
 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
B
bellard 已提交
18
 */
B
bellard 已提交
19
#include "config.h"
B
bellard 已提交
20 21 22
#ifdef _WIN32
#include <windows.h>
#else
B
bellard 已提交
23
#include <sys/types.h>
B
bellard 已提交
24 25
#include <sys/mman.h>
#endif
B
bellard 已提交
26

27
#include "qemu-common.h"
B
bellard 已提交
28
#include "cpu.h"
B
bellard 已提交
29
#include "tcg.h"
30
#include "hw/hw.h"
31
#include "hw/qdev.h"
32
#include "qemu/osdep.h"
33
#include "sysemu/kvm.h"
34
#include "sysemu/sysemu.h"
P
Paolo Bonzini 已提交
35
#include "hw/xen/xen.h"
36 37
#include "qemu/timer.h"
#include "qemu/config-file.h"
38
#include "exec/memory.h"
39
#include "sysemu/dma.h"
40
#include "exec/address-spaces.h"
41 42
#if defined(CONFIG_USER_ONLY)
#include <qemu.h>
J
Jun Nakajima 已提交
43
#else /* !CONFIG_USER_ONLY */
44
#include "sysemu/xen-mapcache.h"
45
#include "trace.h"
46
#endif
47
#include "exec/cpu-all.h"
B
bellard 已提交
48

49
#include "exec/cputlb.h"
50
#include "translate-all.h"
51

52
#include "exec/memory-internal.h"
53
#include "qemu/cache-utils.h"
54

55 56
#include "qemu/range.h"

57
//#define DEBUG_SUBPAGE
T
ths 已提交
58

59
#if !defined(CONFIG_USER_ONLY)
A
aliguori 已提交
60
static int in_migration;
P
pbrook 已提交
61

P
Paolo Bonzini 已提交
62
RAMList ram_list = { .blocks = QTAILQ_HEAD_INITIALIZER(ram_list.blocks) };
A
Avi Kivity 已提交
63 64

static MemoryRegion *system_memory;
65
static MemoryRegion *system_io;
A
Avi Kivity 已提交
66

67 68
AddressSpace address_space_io;
AddressSpace address_space_memory;
69

70
MemoryRegion io_mem_rom, io_mem_notdirty;
71
static MemoryRegion io_mem_unassigned;
72

73
#endif
74

A
Andreas Färber 已提交
75
struct CPUTailQ cpus = QTAILQ_HEAD_INITIALIZER(cpus);
B
bellard 已提交
76 77
/* current CPU in the current thread. It is only valid inside
   cpu_exec() */
78
DEFINE_TLS(CPUState *, current_cpu);
P
pbrook 已提交
79
/* 0 = Do not count executed instructions.
T
ths 已提交
80
   1 = Precise instruction counting.
P
pbrook 已提交
81
   2 = Adaptive rate instruction counting.  */
82
int use_icount;
B
bellard 已提交
83

84
#if !defined(CONFIG_USER_ONLY)
85

86 87 88
typedef struct PhysPageEntry PhysPageEntry;

struct PhysPageEntry {
M
Michael S. Tsirkin 已提交
89
    /* How many bits skip to next level (in units of L2_SIZE). 0 for a leaf. */
90
    uint32_t skip : 6;
M
Michael S. Tsirkin 已提交
91
     /* index into phys_sections (!skip) or phys_map_nodes (skip) */
92
    uint32_t ptr : 26;
93 94
};

95 96
#define PHYS_MAP_NODE_NIL (((uint32_t)~0) >> 6)

97
/* Size of the L2 (and L3, etc) page tables.  */
98
#define ADDR_SPACE_BITS 64
99

M
Michael S. Tsirkin 已提交
100
#define P_L2_BITS 9
101 102 103 104 105
#define P_L2_SIZE (1 << P_L2_BITS)

#define P_L2_LEVELS (((ADDR_SPACE_BITS - TARGET_PAGE_BITS - 1) / P_L2_BITS) + 1)

typedef PhysPageEntry Node[P_L2_SIZE];
106

107 108 109 110 111 112 113 114 115
typedef struct PhysPageMap {
    unsigned sections_nb;
    unsigned sections_nb_alloc;
    unsigned nodes_nb;
    unsigned nodes_nb_alloc;
    Node *nodes;
    MemoryRegionSection *sections;
} PhysPageMap;

116 117 118 119 120
struct AddressSpaceDispatch {
    /* This is a multi-level map on the physical address space.
     * The bottom level has pointers to MemoryRegionSections.
     */
    PhysPageEntry phys_map;
121
    PhysPageMap map;
122
    AddressSpace *as;
123 124
};

125 126 127
#define SUBPAGE_IDX(addr) ((addr) & ~TARGET_PAGE_MASK)
typedef struct subpage_t {
    MemoryRegion iomem;
128
    AddressSpace *as;
129 130 131 132
    hwaddr base;
    uint16_t sub_section[TARGET_PAGE_SIZE];
} subpage_t;

133 134 135 136
#define PHYS_SECTION_UNASSIGNED 0
#define PHYS_SECTION_NOTDIRTY 1
#define PHYS_SECTION_ROM 2
#define PHYS_SECTION_WATCH 3
137

138
static void io_mem_init(void);
A
Avi Kivity 已提交
139
static void memory_map_init(void);
140

141
static MemoryRegion io_mem_watch;
142
#endif
B
bellard 已提交
143

144
#if !defined(CONFIG_USER_ONLY)
145

146
static void phys_map_node_reserve(PhysPageMap *map, unsigned nodes)
147
{
148 149 150 151
    if (map->nodes_nb + nodes > map->nodes_nb_alloc) {
        map->nodes_nb_alloc = MAX(map->nodes_nb_alloc * 2, 16);
        map->nodes_nb_alloc = MAX(map->nodes_nb_alloc, map->nodes_nb + nodes);
        map->nodes = g_renew(Node, map->nodes, map->nodes_nb_alloc);
152
    }
153 154
}

155
static uint32_t phys_map_node_alloc(PhysPageMap *map)
156 157
{
    unsigned i;
158
    uint32_t ret;
159

160
    ret = map->nodes_nb++;
161
    assert(ret != PHYS_MAP_NODE_NIL);
162
    assert(ret != map->nodes_nb_alloc);
163
    for (i = 0; i < P_L2_SIZE; ++i) {
164 165
        map->nodes[ret][i].skip = 1;
        map->nodes[ret][i].ptr = PHYS_MAP_NODE_NIL;
166
    }
167
    return ret;
168 169
}

170 171
static void phys_page_set_level(PhysPageMap *map, PhysPageEntry *lp,
                                hwaddr *index, hwaddr *nb, uint16_t leaf,
172
                                int level)
173 174 175
{
    PhysPageEntry *p;
    int i;
176
    hwaddr step = (hwaddr)1 << (level * P_L2_BITS);
177

M
Michael S. Tsirkin 已提交
178
    if (lp->skip && lp->ptr == PHYS_MAP_NODE_NIL) {
179 180
        lp->ptr = phys_map_node_alloc(map);
        p = map->nodes[lp->ptr];
181
        if (level == 0) {
182
            for (i = 0; i < P_L2_SIZE; i++) {
M
Michael S. Tsirkin 已提交
183
                p[i].skip = 0;
184
                p[i].ptr = PHYS_SECTION_UNASSIGNED;
185
            }
P
pbrook 已提交
186
        }
187
    } else {
188
        p = map->nodes[lp->ptr];
B
bellard 已提交
189
    }
190
    lp = &p[(*index >> (level * P_L2_BITS)) & (P_L2_SIZE - 1)];
191

192
    while (*nb && lp < &p[P_L2_SIZE]) {
193
        if ((*index & (step - 1)) == 0 && *nb >= step) {
M
Michael S. Tsirkin 已提交
194
            lp->skip = 0;
195
            lp->ptr = leaf;
196 197
            *index += step;
            *nb -= step;
198
        } else {
199
            phys_page_set_level(map, lp, index, nb, leaf, level - 1);
200 201
        }
        ++lp;
202 203 204
    }
}

A
Avi Kivity 已提交
205
static void phys_page_set(AddressSpaceDispatch *d,
A
Avi Kivity 已提交
206
                          hwaddr index, hwaddr nb,
207
                          uint16_t leaf)
208
{
209
    /* Wildly overreserve - it doesn't matter much. */
210
    phys_map_node_reserve(&d->map, 3 * P_L2_LEVELS);
211

212
    phys_page_set_level(&d->map, &d->phys_map, &index, &nb, leaf, P_L2_LEVELS - 1);
B
bellard 已提交
213 214
}

215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272
/* Compact a non leaf page entry. Simply detect that the entry has a single child,
 * and update our entry so we can skip it and go directly to the destination.
 */
static void phys_page_compact(PhysPageEntry *lp, Node *nodes, unsigned long *compacted)
{
    unsigned valid_ptr = P_L2_SIZE;
    int valid = 0;
    PhysPageEntry *p;
    int i;

    if (lp->ptr == PHYS_MAP_NODE_NIL) {
        return;
    }

    p = nodes[lp->ptr];
    for (i = 0; i < P_L2_SIZE; i++) {
        if (p[i].ptr == PHYS_MAP_NODE_NIL) {
            continue;
        }

        valid_ptr = i;
        valid++;
        if (p[i].skip) {
            phys_page_compact(&p[i], nodes, compacted);
        }
    }

    /* We can only compress if there's only one child. */
    if (valid != 1) {
        return;
    }

    assert(valid_ptr < P_L2_SIZE);

    /* Don't compress if it won't fit in the # of bits we have. */
    if (lp->skip + p[valid_ptr].skip >= (1 << 3)) {
        return;
    }

    lp->ptr = p[valid_ptr].ptr;
    if (!p[valid_ptr].skip) {
        /* If our only child is a leaf, make this a leaf. */
        /* By design, we should have made this node a leaf to begin with so we
         * should never reach here.
         * But since it's so simple to handle this, let's do it just in case we
         * change this rule.
         */
        lp->skip = 0;
    } else {
        lp->skip += p[valid_ptr].skip;
    }
}

static void phys_page_compact_all(AddressSpaceDispatch *d, int nodes_nb)
{
    DECLARE_BITMAP(compacted, nodes_nb);

    if (d->phys_map.skip) {
273
        phys_page_compact(&d->phys_map, d->map.nodes, compacted);
274 275 276
    }
}

277
static MemoryRegionSection *phys_page_find(PhysPageEntry lp, hwaddr addr,
278
                                           Node *nodes, MemoryRegionSection *sections)
B
bellard 已提交
279
{
280
    PhysPageEntry *p;
281
    hwaddr index = addr >> TARGET_PAGE_BITS;
282
    int i;
283

M
Michael S. Tsirkin 已提交
284
    for (i = P_L2_LEVELS; lp.skip && (i -= lp.skip) >= 0;) {
285
        if (lp.ptr == PHYS_MAP_NODE_NIL) {
286
            return &sections[PHYS_SECTION_UNASSIGNED];
287
        }
288
        p = nodes[lp.ptr];
289
        lp = p[(index >> (i * P_L2_BITS)) & (P_L2_SIZE - 1)];
290
    }
291 292 293 294 295 296 297 298

    if (sections[lp.ptr].size.hi ||
        range_covers_byte(sections[lp.ptr].offset_within_address_space,
                          sections[lp.ptr].size.lo, addr)) {
        return &sections[lp.ptr];
    } else {
        return &sections[PHYS_SECTION_UNASSIGNED];
    }
299 300
}

B
Blue Swirl 已提交
301 302
bool memory_region_is_unassigned(MemoryRegion *mr)
{
P
Paolo Bonzini 已提交
303
    return mr != &io_mem_rom && mr != &io_mem_notdirty && !mr->rom_device
304
        && mr != &io_mem_watch;
B
bellard 已提交
305
}
306

307
static MemoryRegionSection *address_space_lookup_region(AddressSpaceDispatch *d,
308 309
                                                        hwaddr addr,
                                                        bool resolve_subpage)
310
{
311 312 313
    MemoryRegionSection *section;
    subpage_t *subpage;

314
    section = phys_page_find(d->phys_map, addr, d->map.nodes, d->map.sections);
315 316
    if (resolve_subpage && section->mr->subpage) {
        subpage = container_of(section->mr, subpage_t, iomem);
317
        section = &d->map.sections[subpage->sub_section[SUBPAGE_IDX(addr)]];
318 319
    }
    return section;
320 321
}

322
static MemoryRegionSection *
323
address_space_translate_internal(AddressSpaceDispatch *d, hwaddr addr, hwaddr *xlat,
324
                                 hwaddr *plen, bool resolve_subpage)
325 326 327 328
{
    MemoryRegionSection *section;
    Int128 diff;

329
    section = address_space_lookup_region(d, addr, resolve_subpage);
330 331 332 333 334 335 336
    /* Compute offset within MemoryRegionSection */
    addr -= section->offset_within_address_space;

    /* Compute offset within MemoryRegion */
    *xlat = addr + section->offset_within_region;

    diff = int128_sub(section->mr->size, int128_make64(addr));
337
    *plen = int128_get64(int128_min(diff, int128_make64(*plen)));
338 339
    return section;
}
340

341 342 343
MemoryRegion *address_space_translate(AddressSpace *as, hwaddr addr,
                                      hwaddr *xlat, hwaddr *plen,
                                      bool is_write)
344
{
A
Avi Kivity 已提交
345 346 347 348 349 350
    IOMMUTLBEntry iotlb;
    MemoryRegionSection *section;
    MemoryRegion *mr;
    hwaddr len = *plen;

    for (;;) {
351
        section = address_space_translate_internal(as->dispatch, addr, &addr, plen, true);
A
Avi Kivity 已提交
352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372
        mr = section->mr;

        if (!mr->iommu_ops) {
            break;
        }

        iotlb = mr->iommu_ops->translate(mr, addr);
        addr = ((iotlb.translated_addr & ~iotlb.addr_mask)
                | (addr & iotlb.addr_mask));
        len = MIN(len, (addr | iotlb.addr_mask) - addr + 1);
        if (!(iotlb.perm & (1 << is_write))) {
            mr = &io_mem_unassigned;
            break;
        }

        as = iotlb.target_as;
    }

    *plen = len;
    *xlat = addr;
    return mr;
373 374 375 376 377 378
}

MemoryRegionSection *
address_space_translate_for_iotlb(AddressSpace *as, hwaddr addr, hwaddr *xlat,
                                  hwaddr *plen)
{
A
Avi Kivity 已提交
379
    MemoryRegionSection *section;
380
    section = address_space_translate_internal(as->dispatch, addr, xlat, plen, false);
A
Avi Kivity 已提交
381 382 383

    assert(!section->mr->iommu_ops);
    return section;
384
}
385
#endif
B
bellard 已提交
386

387
void cpu_exec_init_all(void)
388
{
389
#if !defined(CONFIG_USER_ONLY)
390
    qemu_mutex_init(&ram_list.mutex);
391 392
    memory_map_init();
    io_mem_init();
393
#endif
394
}
395

396
#if !defined(CONFIG_USER_ONLY)
397 398

static int cpu_common_post_load(void *opaque, int version_id)
B
bellard 已提交
399
{
400
    CPUState *cpu = opaque;
B
bellard 已提交
401

402 403
    /* 0x01 was CPU_INTERRUPT_EXIT. This line can be removed when the
       version_id is increased. */
404 405
    cpu->interrupt_request &= ~0x01;
    tlb_flush(cpu->env_ptr, 1);
406 407

    return 0;
B
bellard 已提交
408
}
B
bellard 已提交
409

410
const VMStateDescription vmstate_cpu_common = {
411 412 413 414 415 416
    .name = "cpu_common",
    .version_id = 1,
    .minimum_version_id = 1,
    .minimum_version_id_old = 1,
    .post_load = cpu_common_post_load,
    .fields      = (VMStateField []) {
417 418
        VMSTATE_UINT32(halted, CPUState),
        VMSTATE_UINT32(interrupt_request, CPUState),
419 420 421
        VMSTATE_END_OF_LIST()
    }
};
422

423
#endif
B
bellard 已提交
424

425
CPUState *qemu_get_cpu(int index)
B
bellard 已提交
426
{
A
Andreas Färber 已提交
427
    CPUState *cpu;
B
bellard 已提交
428

A
Andreas Färber 已提交
429
    CPU_FOREACH(cpu) {
430
        if (cpu->cpu_index == index) {
A
Andreas Färber 已提交
431
            return cpu;
432
        }
B
bellard 已提交
433
    }
434

A
Andreas Färber 已提交
435
    return NULL;
B
bellard 已提交
436 437
}

438
void cpu_exec_init(CPUArchState *env)
B
bellard 已提交
439
{
440
    CPUState *cpu = ENV_GET_CPU(env);
441
    CPUClass *cc = CPU_GET_CLASS(cpu);
A
Andreas Färber 已提交
442
    CPUState *some_cpu;
443 444 445 446 447 448
    int cpu_index;

#if defined(CONFIG_USER_ONLY)
    cpu_list_lock();
#endif
    cpu_index = 0;
A
Andreas Färber 已提交
449
    CPU_FOREACH(some_cpu) {
450 451
        cpu_index++;
    }
452
    cpu->cpu_index = cpu_index;
453
    cpu->numa_node = 0;
454 455 456 457 458
    QTAILQ_INIT(&env->breakpoints);
    QTAILQ_INIT(&env->watchpoints);
#ifndef CONFIG_USER_ONLY
    cpu->thread_id = qemu_get_thread_id();
#endif
A
Andreas Färber 已提交
459
    QTAILQ_INSERT_TAIL(&cpus, cpu, node);
460 461 462
#if defined(CONFIG_USER_ONLY)
    cpu_list_unlock();
#endif
463 464 465
    if (qdev_get_vmsd(DEVICE(cpu)) == NULL) {
        vmstate_register(NULL, cpu_index, &vmstate_cpu_common, cpu);
    }
466 467 468
#if defined(CPU_SAVE_VERSION) && !defined(CONFIG_USER_ONLY)
    register_savevm(NULL, "cpu", cpu_index, CPU_SAVE_VERSION,
                    cpu_save, cpu_load, env);
469
    assert(cc->vmsd == NULL);
470
    assert(qdev_get_vmsd(DEVICE(cpu)) == NULL);
471
#endif
472 473 474
    if (cc->vmsd != NULL) {
        vmstate_register(NULL, cpu_index, cc->vmsd, cpu);
    }
B
bellard 已提交
475 476
}

B
bellard 已提交
477
#if defined(TARGET_HAS_ICE)
478
#if defined(CONFIG_USER_ONLY)
479
static void breakpoint_invalidate(CPUState *cpu, target_ulong pc)
480 481 482 483
{
    tb_invalidate_phys_page_range(pc, pc + 1, 0);
}
#else
484
static void breakpoint_invalidate(CPUState *cpu, target_ulong pc)
485
{
486 487 488 489
    hwaddr phys = cpu_get_phys_page_debug(cpu, pc);
    if (phys != -1) {
        tb_invalidate_phys_addr(phys | (pc & ~TARGET_PAGE_MASK));
    }
490
}
B
bellard 已提交
491
#endif
492
#endif /* TARGET_HAS_ICE */
B
bellard 已提交
493

494
#if defined(CONFIG_USER_ONLY)
495
void cpu_watchpoint_remove_all(CPUArchState *env, int mask)
496 497 498 499

{
}

500
int cpu_watchpoint_insert(CPUArchState *env, target_ulong addr, target_ulong len,
501 502 503 504 505
                          int flags, CPUWatchpoint **watchpoint)
{
    return -ENOSYS;
}
#else
506
/* Add a watchpoint.  */
507
int cpu_watchpoint_insert(CPUArchState *env, target_ulong addr, target_ulong len,
508
                          int flags, CPUWatchpoint **watchpoint)
509
{
510
    target_ulong len_mask = ~(len - 1);
511
    CPUWatchpoint *wp;
512

513
    /* sanity checks: allow power-of-2 lengths, deny unaligned watchpoints */
514 515
    if ((len & (len - 1)) || (addr & ~len_mask) ||
            len == 0 || len > TARGET_PAGE_SIZE) {
516 517 518 519
        fprintf(stderr, "qemu: tried to set invalid watchpoint at "
                TARGET_FMT_lx ", len=" TARGET_FMT_lu "\n", addr, len);
        return -EINVAL;
    }
520
    wp = g_malloc(sizeof(*wp));
521 522

    wp->vaddr = addr;
523
    wp->len_mask = len_mask;
524 525
    wp->flags = flags;

526
    /* keep all GDB-injected watchpoints in front */
527
    if (flags & BP_GDB)
B
Blue Swirl 已提交
528
        QTAILQ_INSERT_HEAD(&env->watchpoints, wp, entry);
529
    else
B
Blue Swirl 已提交
530
        QTAILQ_INSERT_TAIL(&env->watchpoints, wp, entry);
531 532

    tlb_flush_page(env, addr);
533 534 535 536

    if (watchpoint)
        *watchpoint = wp;
    return 0;
537 538
}

539
/* Remove a specific watchpoint.  */
540
int cpu_watchpoint_remove(CPUArchState *env, target_ulong addr, target_ulong len,
541
                          int flags)
542
{
543
    target_ulong len_mask = ~(len - 1);
544
    CPUWatchpoint *wp;
545

B
Blue Swirl 已提交
546
    QTAILQ_FOREACH(wp, &env->watchpoints, entry) {
547
        if (addr == wp->vaddr && len_mask == wp->len_mask
548
                && flags == (wp->flags & ~BP_WATCHPOINT_HIT)) {
549
            cpu_watchpoint_remove_by_ref(env, wp);
550 551 552
            return 0;
        }
    }
553
    return -ENOENT;
554 555
}

556
/* Remove a specific watchpoint by reference.  */
557
void cpu_watchpoint_remove_by_ref(CPUArchState *env, CPUWatchpoint *watchpoint)
558
{
B
Blue Swirl 已提交
559
    QTAILQ_REMOVE(&env->watchpoints, watchpoint, entry);
560

561 562
    tlb_flush_page(env, watchpoint->vaddr);

563
    g_free(watchpoint);
564 565 566
}

/* Remove all matching watchpoints.  */
567
void cpu_watchpoint_remove_all(CPUArchState *env, int mask)
568
{
569
    CPUWatchpoint *wp, *next;
570

B
Blue Swirl 已提交
571
    QTAILQ_FOREACH_SAFE(wp, &env->watchpoints, entry, next) {
572 573
        if (wp->flags & mask)
            cpu_watchpoint_remove_by_ref(env, wp);
574
    }
575
}
576
#endif
577

578
/* Add a breakpoint.  */
579
int cpu_breakpoint_insert(CPUArchState *env, target_ulong pc, int flags,
580
                          CPUBreakpoint **breakpoint)
B
bellard 已提交
581
{
B
bellard 已提交
582
#if defined(TARGET_HAS_ICE)
583
    CPUBreakpoint *bp;
584

585
    bp = g_malloc(sizeof(*bp));
B
bellard 已提交
586

587 588 589
    bp->pc = pc;
    bp->flags = flags;

590
    /* keep all GDB-injected breakpoints in front */
591
    if (flags & BP_GDB) {
B
Blue Swirl 已提交
592
        QTAILQ_INSERT_HEAD(&env->breakpoints, bp, entry);
593
    } else {
B
Blue Swirl 已提交
594
        QTAILQ_INSERT_TAIL(&env->breakpoints, bp, entry);
595
    }
596

597
    breakpoint_invalidate(ENV_GET_CPU(env), pc);
598

599
    if (breakpoint) {
600
        *breakpoint = bp;
601
    }
B
bellard 已提交
602 603
    return 0;
#else
604
    return -ENOSYS;
B
bellard 已提交
605 606 607
#endif
}

608
/* Remove a specific breakpoint.  */
609
int cpu_breakpoint_remove(CPUArchState *env, target_ulong pc, int flags)
610
{
611
#if defined(TARGET_HAS_ICE)
612 613
    CPUBreakpoint *bp;

B
Blue Swirl 已提交
614
    QTAILQ_FOREACH(bp, &env->breakpoints, entry) {
615 616 617 618
        if (bp->pc == pc && bp->flags == flags) {
            cpu_breakpoint_remove_by_ref(env, bp);
            return 0;
        }
619
    }
620 621 622
    return -ENOENT;
#else
    return -ENOSYS;
623 624 625
#endif
}

626
/* Remove a specific breakpoint by reference.  */
627
void cpu_breakpoint_remove_by_ref(CPUArchState *env, CPUBreakpoint *breakpoint)
B
bellard 已提交
628
{
B
bellard 已提交
629
#if defined(TARGET_HAS_ICE)
B
Blue Swirl 已提交
630
    QTAILQ_REMOVE(&env->breakpoints, breakpoint, entry);
B
bellard 已提交
631

632
    breakpoint_invalidate(ENV_GET_CPU(env), breakpoint->pc);
633

634
    g_free(breakpoint);
635 636 637 638
#endif
}

/* Remove all matching breakpoints. */
639
void cpu_breakpoint_remove_all(CPUArchState *env, int mask)
640 641
{
#if defined(TARGET_HAS_ICE)
642
    CPUBreakpoint *bp, *next;
643

B
Blue Swirl 已提交
644
    QTAILQ_FOREACH_SAFE(bp, &env->breakpoints, entry, next) {
645 646
        if (bp->flags & mask)
            cpu_breakpoint_remove_by_ref(env, bp);
647
    }
B
bellard 已提交
648 649 650
#endif
}

B
bellard 已提交
651 652
/* enable or disable single step mode. EXCP_DEBUG is returned by the
   CPU loop after each instruction */
653
void cpu_single_step(CPUState *cpu, int enabled)
B
bellard 已提交
654
{
B
bellard 已提交
655
#if defined(TARGET_HAS_ICE)
656 657 658
    if (cpu->singlestep_enabled != enabled) {
        cpu->singlestep_enabled = enabled;
        if (kvm_enabled()) {
659
            kvm_update_guest_debug(cpu, 0);
660
        } else {
S
Stuart Brady 已提交
661
            /* must flush all the translated code to avoid inconsistencies */
662
            /* XXX: only flush what is necessary */
663
            CPUArchState *env = cpu->env_ptr;
664 665
            tb_flush(env);
        }
B
bellard 已提交
666 667 668 669
    }
#endif
}

670
void cpu_abort(CPUArchState *env, const char *fmt, ...)
B
bellard 已提交
671
{
672
    CPUState *cpu = ENV_GET_CPU(env);
B
bellard 已提交
673
    va_list ap;
P
pbrook 已提交
674
    va_list ap2;
B
bellard 已提交
675 676

    va_start(ap, fmt);
P
pbrook 已提交
677
    va_copy(ap2, ap);
B
bellard 已提交
678 679 680
    fprintf(stderr, "qemu: fatal: ");
    vfprintf(stderr, fmt, ap);
    fprintf(stderr, "\n");
681
    cpu_dump_state(cpu, stderr, fprintf, CPU_DUMP_FPU | CPU_DUMP_CCOP);
682 683 684 685
    if (qemu_log_enabled()) {
        qemu_log("qemu: fatal: ");
        qemu_log_vprintf(fmt, ap2);
        qemu_log("\n");
686
        log_cpu_state(cpu, CPU_DUMP_FPU | CPU_DUMP_CCOP);
687
        qemu_log_flush();
688
        qemu_log_close();
689
    }
P
pbrook 已提交
690
    va_end(ap2);
691
    va_end(ap);
692 693 694 695 696 697 698 699
#if defined(CONFIG_USER_ONLY)
    {
        struct sigaction act;
        sigfillset(&act.sa_mask);
        act.sa_handler = SIG_DFL;
        sigaction(SIGABRT, &act, NULL);
    }
#endif
B
bellard 已提交
700 701 702
    abort();
}

703
#if !defined(CONFIG_USER_ONLY)
P
Paolo Bonzini 已提交
704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726
static RAMBlock *qemu_get_ram_block(ram_addr_t addr)
{
    RAMBlock *block;

    /* The list is protected by the iothread lock here.  */
    block = ram_list.mru_block;
    if (block && addr - block->offset < block->length) {
        goto found;
    }
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
        if (addr - block->offset < block->length) {
            goto found;
        }
    }

    fprintf(stderr, "Bad ram offset %" PRIx64 "\n", (uint64_t)addr);
    abort();

found:
    ram_list.mru_block = block;
    return block;
}

J
Juan Quintela 已提交
727 728 729
static void tlb_reset_dirty_range_all(ram_addr_t start, ram_addr_t end,
                                      uintptr_t length)
{
P
Paolo Bonzini 已提交
730 731
    RAMBlock *block;
    ram_addr_t start1;
J
Juan Quintela 已提交
732

P
Paolo Bonzini 已提交
733 734 735 736
    block = qemu_get_ram_block(start);
    assert(block == qemu_get_ram_block(end - 1));
    start1 = (uintptr_t)block->host + (start - block->offset);
    cpu_tlb_reset_dirty_all(start1, length);
J
Juan Quintela 已提交
737 738
}

P
pbrook 已提交
739
/* Note: start and end must be within the same ram block.  */
A
Anthony Liguori 已提交
740
void cpu_physical_memory_reset_dirty(ram_addr_t start, ram_addr_t end,
741
                                     unsigned client)
742
{
J
Juan Quintela 已提交
743
    uintptr_t length;
744 745 746 747 748 749 750

    start &= TARGET_PAGE_MASK;
    end = TARGET_PAGE_ALIGN(end);

    length = end - start;
    if (length == 0)
        return;
751
    cpu_physical_memory_mask_dirty_range(start, length, client);
B
bellard 已提交
752

J
Juan Quintela 已提交
753 754
    if (tcg_enabled()) {
        tlb_reset_dirty_range_all(start, end, length);
P
pbrook 已提交
755
    }
756 757
}

B
Blue Swirl 已提交
758
static int cpu_physical_memory_set_dirty_tracking(int enable)
A
aliguori 已提交
759
{
M
Michael S. Tsirkin 已提交
760
    int ret = 0;
A
aliguori 已提交
761
    in_migration = enable;
M
Michael S. Tsirkin 已提交
762
    return ret;
A
aliguori 已提交
763 764
}

A
Avi Kivity 已提交
765
hwaddr memory_region_section_get_iotlb(CPUArchState *env,
766 767 768 769 770
                                       MemoryRegionSection *section,
                                       target_ulong vaddr,
                                       hwaddr paddr, hwaddr xlat,
                                       int prot,
                                       target_ulong *address)
B
Blue Swirl 已提交
771
{
A
Avi Kivity 已提交
772
    hwaddr iotlb;
B
Blue Swirl 已提交
773 774
    CPUWatchpoint *wp;

775
    if (memory_region_is_ram(section->mr)) {
B
Blue Swirl 已提交
776 777
        /* Normal RAM.  */
        iotlb = (memory_region_get_ram_addr(section->mr) & TARGET_PAGE_MASK)
778
            + xlat;
B
Blue Swirl 已提交
779
        if (!section->readonly) {
780
            iotlb |= PHYS_SECTION_NOTDIRTY;
B
Blue Swirl 已提交
781
        } else {
782
            iotlb |= PHYS_SECTION_ROM;
B
Blue Swirl 已提交
783 784
        }
    } else {
785
        iotlb = section - address_space_memory.dispatch->map.sections;
786
        iotlb += xlat;
B
Blue Swirl 已提交
787 788 789 790 791 792 793 794
    }

    /* Make accesses to pages with watchpoints go via the
       watchpoint trap routines.  */
    QTAILQ_FOREACH(wp, &env->watchpoints, entry) {
        if (vaddr == (wp->vaddr & TARGET_PAGE_MASK)) {
            /* Avoid trapping reads of pages with a write breakpoint. */
            if ((prot & PAGE_WRITE) || (wp->flags & BP_MEM_READ)) {
795
                iotlb = PHYS_SECTION_WATCH + paddr;
B
Blue Swirl 已提交
796 797 798 799 800 801 802 803
                *address |= TLB_MMIO;
                break;
            }
        }
    }

    return iotlb;
}
804 805
#endif /* defined(CONFIG_USER_ONLY) */

806
#if !defined(CONFIG_USER_ONLY)
807

A
Anthony Liguori 已提交
808
static int subpage_register (subpage_t *mmio, uint32_t start, uint32_t end,
809
                             uint16_t section);
810
static subpage_t *subpage_init(AddressSpace *as, hwaddr base);
811

812
static void *(*phys_mem_alloc)(size_t size) = qemu_anon_ram_alloc;
813 814 815 816 817 818

/*
 * Set a custom physical guest memory alloator.
 * Accelerators with unusual needs may need this.  Hopefully, we can
 * get rid of it eventually.
 */
819
void phys_mem_set_alloc(void *(*alloc)(size_t))
820 821 822 823
{
    phys_mem_alloc = alloc;
}

824 825
static uint16_t phys_section_add(PhysPageMap *map,
                                 MemoryRegionSection *section)
826
{
827 828 829 830
    /* The physical section number is ORed with a page-aligned
     * pointer to produce the iotlb entries.  Thus it should
     * never overflow into the page-aligned value.
     */
831
    assert(map->sections_nb < TARGET_PAGE_SIZE);
832

833 834 835 836
    if (map->sections_nb == map->sections_nb_alloc) {
        map->sections_nb_alloc = MAX(map->sections_nb_alloc * 2, 16);
        map->sections = g_renew(MemoryRegionSection, map->sections,
                                map->sections_nb_alloc);
837
    }
838
    map->sections[map->sections_nb] = *section;
P
Paolo Bonzini 已提交
839
    memory_region_ref(section->mr);
840
    return map->sections_nb++;
841 842
}

843 844
static void phys_section_destroy(MemoryRegion *mr)
{
P
Paolo Bonzini 已提交
845 846
    memory_region_unref(mr);

847 848 849 850 851 852 853
    if (mr->subpage) {
        subpage_t *subpage = container_of(mr, subpage_t, iomem);
        memory_region_destroy(&subpage->iomem);
        g_free(subpage);
    }
}

P
Paolo Bonzini 已提交
854
static void phys_sections_free(PhysPageMap *map)
855
{
856 857
    while (map->sections_nb > 0) {
        MemoryRegionSection *section = &map->sections[--map->sections_nb];
858 859
        phys_section_destroy(section->mr);
    }
860 861
    g_free(map->sections);
    g_free(map->nodes);
862 863
}

A
Avi Kivity 已提交
864
static void register_subpage(AddressSpaceDispatch *d, MemoryRegionSection *section)
865 866
{
    subpage_t *subpage;
A
Avi Kivity 已提交
867
    hwaddr base = section->offset_within_address_space
868
        & TARGET_PAGE_MASK;
869
    MemoryRegionSection *existing = phys_page_find(d->phys_map, base,
870
                                                   d->map.nodes, d->map.sections);
871 872
    MemoryRegionSection subsection = {
        .offset_within_address_space = base,
873
        .size = int128_make64(TARGET_PAGE_SIZE),
874
    };
A
Avi Kivity 已提交
875
    hwaddr start, end;
876

877
    assert(existing->mr->subpage || existing->mr == &io_mem_unassigned);
878

879
    if (!(existing->mr->subpage)) {
880
        subpage = subpage_init(d->as, base);
881
        subsection.mr = &subpage->iomem;
A
Avi Kivity 已提交
882
        phys_page_set(d, base >> TARGET_PAGE_BITS, 1,
883
                      phys_section_add(&d->map, &subsection));
884
    } else {
885
        subpage = container_of(existing->mr, subpage_t, iomem);
886 887
    }
    start = section->offset_within_address_space & ~TARGET_PAGE_MASK;
888
    end = start + int128_get64(section->size) - 1;
889 890
    subpage_register(subpage, start, end,
                     phys_section_add(&d->map, section));
891 892 893
}


894 895
static void register_multipage(AddressSpaceDispatch *d,
                               MemoryRegionSection *section)
896
{
A
Avi Kivity 已提交
897
    hwaddr start_addr = section->offset_within_address_space;
898
    uint16_t section_index = phys_section_add(&d->map, section);
899 900
    uint64_t num_pages = int128_get64(int128_rshift(section->size,
                                                    TARGET_PAGE_BITS));
901

902 903
    assert(num_pages);
    phys_page_set(d, start_addr >> TARGET_PAGE_BITS, num_pages, section_index);
904 905
}

A
Avi Kivity 已提交
906
static void mem_add(MemoryListener *listener, MemoryRegionSection *section)
907
{
908
    AddressSpace *as = container_of(listener, AddressSpace, dispatch_listener);
909
    AddressSpaceDispatch *d = as->next_dispatch;
910
    MemoryRegionSection now = *section, remain = *section;
911
    Int128 page_size = int128_make64(TARGET_PAGE_SIZE);
912

913 914 915 916
    if (now.offset_within_address_space & ~TARGET_PAGE_MASK) {
        uint64_t left = TARGET_PAGE_ALIGN(now.offset_within_address_space)
                       - now.offset_within_address_space;

917
        now.size = int128_min(int128_make64(left), now.size);
A
Avi Kivity 已提交
918
        register_subpage(d, &now);
919
    } else {
920
        now.size = int128_zero();
921
    }
922 923 924 925
    while (int128_ne(remain.size, now.size)) {
        remain.size = int128_sub(remain.size, now.size);
        remain.offset_within_address_space += int128_get64(now.size);
        remain.offset_within_region += int128_get64(now.size);
926
        now = remain;
927
        if (int128_lt(remain.size, page_size)) {
928
            register_subpage(d, &now);
929
        } else if (remain.offset_within_address_space & ~TARGET_PAGE_MASK) {
930
            now.size = page_size;
A
Avi Kivity 已提交
931
            register_subpage(d, &now);
932
        } else {
933
            now.size = int128_and(now.size, int128_neg(page_size));
A
Avi Kivity 已提交
934
            register_multipage(d, &now);
935
        }
936 937 938
    }
}

939 940 941 942 943 944
void qemu_flush_coalesced_mmio_buffer(void)
{
    if (kvm_enabled())
        kvm_flush_coalesced_mmio_buffer();
}

945 946 947 948 949 950 951 952 953 954
void qemu_mutex_lock_ramlist(void)
{
    qemu_mutex_lock(&ram_list.mutex);
}

void qemu_mutex_unlock_ramlist(void)
{
    qemu_mutex_unlock(&ram_list.mutex);
}

955
#ifdef __linux__
956 957 958 959 960 961 962 963 964 965 966

#include <sys/vfs.h>

#define HUGETLBFS_MAGIC       0x958458f6

static long gethugepagesize(const char *path)
{
    struct statfs fs;
    int ret;

    do {
Y
Yoshiaki Tamura 已提交
967
        ret = statfs(path, &fs);
968 969 970
    } while (ret != 0 && errno == EINTR);

    if (ret != 0) {
Y
Yoshiaki Tamura 已提交
971 972
        perror(path);
        return 0;
973 974 975
    }

    if (fs.f_type != HUGETLBFS_MAGIC)
Y
Yoshiaki Tamura 已提交
976
        fprintf(stderr, "Warning: path not on HugeTLBFS: %s\n", path);
977 978 979 980

    return fs.f_bsize;
}

981 982 983 984 985 986 987
static sigjmp_buf sigjump;

static void sigbus_handler(int signal)
{
    siglongjmp(sigjump, 1);
}

A
Alex Williamson 已提交
988 989 990
static void *file_ram_alloc(RAMBlock *block,
                            ram_addr_t memory,
                            const char *path)
991 992
{
    char *filename;
993 994
    char *sanitized_name;
    char *c;
995 996 997 998 999 1000
    void *area;
    int fd;
    unsigned long hpagesize;

    hpagesize = gethugepagesize(path);
    if (!hpagesize) {
Y
Yoshiaki Tamura 已提交
1001
        return NULL;
1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012
    }

    if (memory < hpagesize) {
        return NULL;
    }

    if (kvm_enabled() && !kvm_has_sync_mmu()) {
        fprintf(stderr, "host lacks kvm mmu notifiers, -mem-path unsupported\n");
        return NULL;
    }

1013 1014 1015 1016 1017 1018 1019 1020 1021 1022
    /* Make name safe to use with mkstemp by replacing '/' with '_'. */
    sanitized_name = g_strdup(block->mr->name);
    for (c = sanitized_name; *c != '\0'; c++) {
        if (*c == '/')
            *c = '_';
    }

    filename = g_strdup_printf("%s/qemu_back_mem.%s.XXXXXX", path,
                               sanitized_name);
    g_free(sanitized_name);
1023 1024 1025

    fd = mkstemp(filename);
    if (fd < 0) {
Y
Yoshiaki Tamura 已提交
1026
        perror("unable to create backing store for hugepages");
1027
        g_free(filename);
Y
Yoshiaki Tamura 已提交
1028
        return NULL;
1029 1030
    }
    unlink(filename);
1031
    g_free(filename);
1032 1033 1034 1035 1036 1037 1038 1039 1040 1041

    memory = (memory+hpagesize-1) & ~(hpagesize-1);

    /*
     * ftruncate is not supported by hugetlbfs in older
     * hosts, so don't bother bailing out on errors.
     * If anything goes wrong with it under other filesystems,
     * mmap will fail.
     */
    if (ftruncate(fd, memory))
Y
Yoshiaki Tamura 已提交
1042
        perror("ftruncate");
1043 1044 1045

    area = mmap(0, memory, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);
    if (area == MAP_FAILED) {
Y
Yoshiaki Tamura 已提交
1046 1047 1048
        perror("file_ram_alloc: can't mmap RAM pages");
        close(fd);
        return (NULL);
1049
    }
1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089

    if (mem_prealloc) {
        int ret, i;
        struct sigaction act, oldact;
        sigset_t set, oldset;

        memset(&act, 0, sizeof(act));
        act.sa_handler = &sigbus_handler;
        act.sa_flags = 0;

        ret = sigaction(SIGBUS, &act, &oldact);
        if (ret) {
            perror("file_ram_alloc: failed to install signal handler");
            exit(1);
        }

        /* unblock SIGBUS */
        sigemptyset(&set);
        sigaddset(&set, SIGBUS);
        pthread_sigmask(SIG_UNBLOCK, &set, &oldset);

        if (sigsetjmp(sigjump, 1)) {
            fprintf(stderr, "file_ram_alloc: failed to preallocate pages\n");
            exit(1);
        }

        /* MAP_POPULATE silently ignores failures */
        for (i = 0; i < (memory/hpagesize)-1; i++) {
            memset(area + (hpagesize*i), 0, 1);
        }

        ret = sigaction(SIGBUS, &oldact, NULL);
        if (ret) {
            perror("file_ram_alloc: failed to reinstall signal handler");
            exit(1);
        }

        pthread_sigmask(SIG_SETMASK, &oldset, NULL);
    }

A
Alex Williamson 已提交
1090
    block->fd = fd;
1091 1092
    return area;
}
1093 1094 1095 1096 1097 1098 1099 1100
#else
static void *file_ram_alloc(RAMBlock *block,
                            ram_addr_t memory,
                            const char *path)
{
    fprintf(stderr, "-mem-path not supported on this host\n");
    exit(1);
}
1101 1102
#endif

1103
static ram_addr_t find_ram_offset(ram_addr_t size)
A
Alex Williamson 已提交
1104 1105
{
    RAMBlock *block, *next_block;
A
Alex Williamson 已提交
1106
    ram_addr_t offset = RAM_ADDR_MAX, mingap = RAM_ADDR_MAX;
A
Alex Williamson 已提交
1107

1108 1109
    assert(size != 0); /* it would hand out same offset multiple times */

P
Paolo Bonzini 已提交
1110
    if (QTAILQ_EMPTY(&ram_list.blocks))
A
Alex Williamson 已提交
1111 1112
        return 0;

P
Paolo Bonzini 已提交
1113
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1114
        ram_addr_t end, next = RAM_ADDR_MAX;
A
Alex Williamson 已提交
1115 1116 1117

        end = block->offset + block->length;

P
Paolo Bonzini 已提交
1118
        QTAILQ_FOREACH(next_block, &ram_list.blocks, next) {
A
Alex Williamson 已提交
1119 1120 1121 1122 1123
            if (next_block->offset >= end) {
                next = MIN(next, next_block->offset);
            }
        }
        if (next - end >= size && next - end < mingap) {
A
Alex Williamson 已提交
1124
            offset = end;
A
Alex Williamson 已提交
1125 1126 1127
            mingap = next - end;
        }
    }
A
Alex Williamson 已提交
1128 1129 1130 1131 1132 1133 1134

    if (offset == RAM_ADDR_MAX) {
        fprintf(stderr, "Failed to find gap of requested size: %" PRIu64 "\n",
                (uint64_t)size);
        abort();
    }

A
Alex Williamson 已提交
1135 1136 1137
    return offset;
}

J
Juan Quintela 已提交
1138
ram_addr_t last_ram_offset(void)
1139 1140 1141 1142
{
    RAMBlock *block;
    ram_addr_t last = 0;

P
Paolo Bonzini 已提交
1143
    QTAILQ_FOREACH(block, &ram_list.blocks, next)
1144 1145 1146 1147 1148
        last = MAX(last, block->offset + block->length);

    return last;
}

1149 1150 1151 1152 1153
static void qemu_ram_setup_dump(void *addr, ram_addr_t size)
{
    int ret;

    /* Use MADV_DONTDUMP, if user doesn't want the guest memory in the core */
1154 1155
    if (!qemu_opt_get_bool(qemu_get_machine_opts(),
                           "dump-guest-core", true)) {
1156 1157 1158 1159 1160 1161 1162 1163 1164
        ret = qemu_madvise(addr, size, QEMU_MADV_DONTDUMP);
        if (ret) {
            perror("qemu_madvise");
            fprintf(stderr, "madvise doesn't support MADV_DONTDUMP, "
                            "but dump_guest_core=off specified\n");
        }
    }
}

1165
void qemu_ram_set_idstr(ram_addr_t addr, const char *name, DeviceState *dev)
1166 1167 1168
{
    RAMBlock *new_block, *block;

1169
    new_block = NULL;
P
Paolo Bonzini 已提交
1170
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1171 1172 1173 1174 1175 1176 1177
        if (block->offset == addr) {
            new_block = block;
            break;
        }
    }
    assert(new_block);
    assert(!new_block->idstr[0]);
1178

1179 1180
    if (dev) {
        char *id = qdev_get_dev_path(dev);
1181 1182
        if (id) {
            snprintf(new_block->idstr, sizeof(new_block->idstr), "%s/", id);
1183
            g_free(id);
1184 1185 1186 1187
        }
    }
    pstrcat(new_block->idstr, sizeof(new_block->idstr), name);

1188 1189
    /* This assumes the iothread lock is taken here too.  */
    qemu_mutex_lock_ramlist();
P
Paolo Bonzini 已提交
1190
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1191
        if (block != new_block && !strcmp(block->idstr, new_block->idstr)) {
1192 1193 1194 1195 1196
            fprintf(stderr, "RAMBlock \"%s\" already registered, abort!\n",
                    new_block->idstr);
            abort();
        }
    }
1197
    qemu_mutex_unlock_ramlist();
1198 1199
}

1200 1201
static int memory_try_enable_merging(void *addr, size_t len)
{
1202
    if (!qemu_opt_get_bool(qemu_get_machine_opts(), "mem-merge", true)) {
1203 1204 1205 1206 1207 1208 1209
        /* disabled by the user */
        return 0;
    }

    return qemu_madvise(addr, len, QEMU_MADV_MERGEABLE);
}

1210 1211 1212
ram_addr_t qemu_ram_alloc_from_ptr(ram_addr_t size, void *host,
                                   MemoryRegion *mr)
{
1213
    RAMBlock *block, *new_block;
1214 1215 1216

    size = TARGET_PAGE_ALIGN(size);
    new_block = g_malloc0(sizeof(*new_block));
1217
    new_block->fd = -1;
1218

1219 1220
    /* This assumes the iothread lock is taken here too.  */
    qemu_mutex_lock_ramlist();
A
Avi Kivity 已提交
1221
    new_block->mr = mr;
J
Jun Nakajima 已提交
1222
    new_block->offset = find_ram_offset(size);
1223 1224
    if (host) {
        new_block->host = host;
H
Huang Ying 已提交
1225
        new_block->flags |= RAM_PREALLOC_MASK;
1226 1227 1228 1229 1230 1231
    } else if (xen_enabled()) {
        if (mem_path) {
            fprintf(stderr, "-mem-path not supported with Xen\n");
            exit(1);
        }
        xen_ram_alloc(new_block->offset, size, mr);
1232 1233
    } else {
        if (mem_path) {
1234 1235 1236 1237 1238 1239 1240 1241 1242 1243
            if (phys_mem_alloc != qemu_anon_ram_alloc) {
                /*
                 * file_ram_alloc() needs to allocate just like
                 * phys_mem_alloc, but we haven't bothered to provide
                 * a hook there.
                 */
                fprintf(stderr,
                        "-mem-path not supported with this accelerator\n");
                exit(1);
            }
1244
            new_block->host = file_ram_alloc(new_block, size, mem_path);
1245 1246
        }
        if (!new_block->host) {
1247
            new_block->host = phys_mem_alloc(size);
1248 1249 1250 1251 1252
            if (!new_block->host) {
                fprintf(stderr, "Cannot set up guest memory '%s': %s\n",
                        new_block->mr->name, strerror(errno));
                exit(1);
            }
1253
            memory_try_enable_merging(new_block->host, size);
1254
        }
1255
    }
P
pbrook 已提交
1256 1257
    new_block->length = size;

1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268
    /* Keep the list sorted from biggest to smallest block.  */
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
        if (block->length < new_block->length) {
            break;
        }
    }
    if (block) {
        QTAILQ_INSERT_BEFORE(block, new_block, next);
    } else {
        QTAILQ_INSERT_TAIL(&ram_list.blocks, new_block, next);
    }
1269
    ram_list.mru_block = NULL;
P
pbrook 已提交
1270

U
Umesh Deshpande 已提交
1271
    ram_list.version++;
1272
    qemu_mutex_unlock_ramlist();
U
Umesh Deshpande 已提交
1273

1274
    ram_list.phys_dirty = g_realloc(ram_list.phys_dirty,
A
Alex Williamson 已提交
1275
                                       last_ram_offset() >> TARGET_PAGE_BITS);
1276 1277
    memset(ram_list.phys_dirty + (new_block->offset >> TARGET_PAGE_BITS),
           0, size >> TARGET_PAGE_BITS);
1278
    cpu_physical_memory_set_dirty_range(new_block->offset, size);
P
pbrook 已提交
1279

1280
    qemu_ram_setup_dump(new_block->host, size);
1281
    qemu_madvise(new_block->host, size, QEMU_MADV_HUGEPAGE);
1282
    qemu_madvise(new_block->host, size, QEMU_MADV_DONTFORK);
1283

1284 1285 1286
    if (kvm_enabled())
        kvm_setup_guest_memory(new_block->host, size);

P
pbrook 已提交
1287 1288
    return new_block->offset;
}
B
bellard 已提交
1289

1290
ram_addr_t qemu_ram_alloc(ram_addr_t size, MemoryRegion *mr)
1291
{
1292
    return qemu_ram_alloc_from_ptr(size, NULL, mr);
1293 1294
}

1295 1296 1297 1298
void qemu_ram_free_from_ptr(ram_addr_t addr)
{
    RAMBlock *block;

1299 1300
    /* This assumes the iothread lock is taken here too.  */
    qemu_mutex_lock_ramlist();
P
Paolo Bonzini 已提交
1301
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1302
        if (addr == block->offset) {
P
Paolo Bonzini 已提交
1303
            QTAILQ_REMOVE(&ram_list.blocks, block, next);
1304
            ram_list.mru_block = NULL;
U
Umesh Deshpande 已提交
1305
            ram_list.version++;
1306
            g_free(block);
1307
            break;
1308 1309
        }
    }
1310
    qemu_mutex_unlock_ramlist();
1311 1312
}

A
Anthony Liguori 已提交
1313
void qemu_ram_free(ram_addr_t addr)
B
bellard 已提交
1314
{
A
Alex Williamson 已提交
1315 1316
    RAMBlock *block;

1317 1318
    /* This assumes the iothread lock is taken here too.  */
    qemu_mutex_lock_ramlist();
P
Paolo Bonzini 已提交
1319
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
A
Alex Williamson 已提交
1320
        if (addr == block->offset) {
P
Paolo Bonzini 已提交
1321
            QTAILQ_REMOVE(&ram_list.blocks, block, next);
1322
            ram_list.mru_block = NULL;
U
Umesh Deshpande 已提交
1323
            ram_list.version++;
H
Huang Ying 已提交
1324 1325
            if (block->flags & RAM_PREALLOC_MASK) {
                ;
1326 1327
            } else if (xen_enabled()) {
                xen_invalidate_map_cache_entry(block->host);
1328
#ifndef _WIN32
1329 1330 1331
            } else if (block->fd >= 0) {
                munmap(block->host, block->length);
                close(block->fd);
1332
#endif
A
Alex Williamson 已提交
1333
            } else {
1334
                qemu_anon_ram_free(block->host, block->length);
A
Alex Williamson 已提交
1335
            }
1336
            g_free(block);
1337
            break;
A
Alex Williamson 已提交
1338 1339
        }
    }
1340
    qemu_mutex_unlock_ramlist();
A
Alex Williamson 已提交
1341

B
bellard 已提交
1342 1343
}

H
Huang Ying 已提交
1344 1345 1346 1347 1348 1349 1350 1351
#ifndef _WIN32
void qemu_ram_remap(ram_addr_t addr, ram_addr_t length)
{
    RAMBlock *block;
    ram_addr_t offset;
    int flags;
    void *area, *vaddr;

P
Paolo Bonzini 已提交
1352
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
H
Huang Ying 已提交
1353 1354 1355 1356 1357
        offset = addr - block->offset;
        if (offset < block->length) {
            vaddr = block->host + offset;
            if (block->flags & RAM_PREALLOC_MASK) {
                ;
1358 1359
            } else if (xen_enabled()) {
                abort();
H
Huang Ying 已提交
1360 1361 1362
            } else {
                flags = MAP_FIXED;
                munmap(vaddr, length);
1363
                if (block->fd >= 0) {
H
Huang Ying 已提交
1364
#ifdef MAP_POPULATE
1365 1366
                    flags |= mem_prealloc ? MAP_POPULATE | MAP_SHARED :
                        MAP_PRIVATE;
1367
#else
1368
                    flags |= MAP_PRIVATE;
H
Huang Ying 已提交
1369
#endif
1370 1371
                    area = mmap(vaddr, length, PROT_READ | PROT_WRITE,
                                flags, block->fd, offset);
H
Huang Ying 已提交
1372
                } else {
1373 1374 1375 1376 1377 1378 1379
                    /*
                     * Remap needs to match alloc.  Accelerators that
                     * set phys_mem_alloc never remap.  If they did,
                     * we'd need a remap hook here.
                     */
                    assert(phys_mem_alloc == qemu_anon_ram_alloc);

H
Huang Ying 已提交
1380 1381 1382 1383 1384
                    flags |= MAP_PRIVATE | MAP_ANONYMOUS;
                    area = mmap(vaddr, length, PROT_READ | PROT_WRITE,
                                flags, -1, 0);
                }
                if (area != vaddr) {
1385 1386
                    fprintf(stderr, "Could not remap addr: "
                            RAM_ADDR_FMT "@" RAM_ADDR_FMT "\n",
H
Huang Ying 已提交
1387 1388 1389
                            length, addr);
                    exit(1);
                }
1390
                memory_try_enable_merging(vaddr, length);
1391
                qemu_ram_setup_dump(vaddr, length);
H
Huang Ying 已提交
1392 1393 1394 1395 1396 1397 1398
            }
            return;
        }
    }
}
#endif /* !_WIN32 */

1399 1400 1401 1402 1403 1404 1405 1406 1407 1408 1409 1410
/* Return a host pointer to ram allocated with qemu_ram_alloc.
   With the exception of the softmmu code in this file, this should
   only be used for local memory (e.g. video ram) that the device owns,
   and knows it isn't going to access beyond the end of the block.

   It should not be used for general purpose DMA.
   Use cpu_physical_memory_map/cpu_physical_memory_rw instead.
 */
void *qemu_get_ram_ptr(ram_addr_t addr)
{
    RAMBlock *block = qemu_get_ram_block(addr);

1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423
    if (xen_enabled()) {
        /* We need to check if the requested address is in the RAM
         * because we don't want to map the entire memory in QEMU.
         * In that case just map until the end of the page.
         */
        if (block->offset == 0) {
            return xen_map_cache(addr, 0, 0);
        } else if (block->host == NULL) {
            block->host =
                xen_map_cache(block->offset, block->length, 1);
        }
    }
    return block->host + (addr - block->offset);
1424 1425
}

1426 1427
/* Return a host pointer to guest's ram. Similar to qemu_get_ram_ptr
 * but takes a size argument */
1428
static void *qemu_ram_ptr_length(ram_addr_t addr, hwaddr *size)
1429
{
1430 1431 1432
    if (*size == 0) {
        return NULL;
    }
1433
    if (xen_enabled()) {
J
Jan Kiszka 已提交
1434
        return xen_map_cache(addr, *size, 1);
1435
    } else {
1436 1437
        RAMBlock *block;

P
Paolo Bonzini 已提交
1438
        QTAILQ_FOREACH(block, &ram_list.blocks, next) {
1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450
            if (addr - block->offset < block->length) {
                if (addr - block->offset + *size > block->length)
                    *size = block->length - addr + block->offset;
                return block->host + (addr - block->offset);
            }
        }

        fprintf(stderr, "Bad ram offset %" PRIx64 "\n", (uint64_t)addr);
        abort();
    }
}

1451 1452
/* Some of the softmmu routines need to translate from a host pointer
   (typically a TLB entry) back to a ram offset.  */
1453
MemoryRegion *qemu_ram_addr_from_host(void *ptr, ram_addr_t *ram_addr)
P
pbrook 已提交
1454
{
P
pbrook 已提交
1455 1456 1457
    RAMBlock *block;
    uint8_t *host = ptr;

1458
    if (xen_enabled()) {
J
Jan Kiszka 已提交
1459
        *ram_addr = xen_ram_addr_from_mapcache(ptr);
1460
        return qemu_get_ram_block(*ram_addr)->mr;
1461 1462
    }

1463 1464 1465 1466 1467
    block = ram_list.mru_block;
    if (block && block->host && host - block->host < block->length) {
        goto found;
    }

P
Paolo Bonzini 已提交
1468
    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
J
Jun Nakajima 已提交
1469 1470 1471 1472
        /* This case append when the block is not mapped. */
        if (block->host == NULL) {
            continue;
        }
A
Alex Williamson 已提交
1473
        if (host - block->host < block->length) {
1474
            goto found;
A
Alex Williamson 已提交
1475
        }
P
pbrook 已提交
1476
    }
J
Jun Nakajima 已提交
1477

1478
    return NULL;
1479 1480 1481

found:
    *ram_addr = block->offset + (host - block->host);
1482
    return block->mr;
M
Marcelo Tosatti 已提交
1483
}
A
Alex Williamson 已提交
1484

A
Avi Kivity 已提交
1485
static void notdirty_mem_write(void *opaque, hwaddr ram_addr,
1486
                               uint64_t val, unsigned size)
1487
{
1488
    if (!cpu_physical_memory_get_dirty_flag(ram_addr, DIRTY_MEMORY_CODE)) {
1489
        tb_invalidate_phys_page_fast(ram_addr, size);
1490
    }
1491 1492 1493 1494 1495 1496 1497 1498 1499 1500 1501 1502
    switch (size) {
    case 1:
        stb_p(qemu_get_ram_ptr(ram_addr), val);
        break;
    case 2:
        stw_p(qemu_get_ram_ptr(ram_addr), val);
        break;
    case 4:
        stl_p(qemu_get_ram_ptr(ram_addr), val);
        break;
    default:
        abort();
1503
    }
1504 1505
    cpu_physical_memory_set_dirty_flag(ram_addr, DIRTY_MEMORY_MIGRATION);
    cpu_physical_memory_set_dirty_flag(ram_addr, DIRTY_MEMORY_VGA);
B
bellard 已提交
1506 1507
    /* we remove the notdirty callback only if the code has been
       flushed */
1508
    if (cpu_physical_memory_is_dirty(ram_addr)) {
1509 1510 1511
        CPUArchState *env = current_cpu->env_ptr;
        tlb_set_dirty(env, env->mem_io_vaddr);
    }
1512 1513
}

1514 1515 1516 1517 1518 1519
static bool notdirty_mem_accepts(void *opaque, hwaddr addr,
                                 unsigned size, bool is_write)
{
    return is_write;
}

1520 1521
static const MemoryRegionOps notdirty_mem_ops = {
    .write = notdirty_mem_write,
1522
    .valid.accepts = notdirty_mem_accepts,
1523
    .endianness = DEVICE_NATIVE_ENDIAN,
1524 1525
};

P
pbrook 已提交
1526
/* Generate a debug exception if a watchpoint has been hit.  */
1527
static void check_watchpoint(int offset, int len_mask, int flags)
P
pbrook 已提交
1528
{
1529
    CPUArchState *env = current_cpu->env_ptr;
1530
    target_ulong pc, cs_base;
P
pbrook 已提交
1531
    target_ulong vaddr;
1532
    CPUWatchpoint *wp;
1533
    int cpu_flags;
P
pbrook 已提交
1534

1535 1536 1537 1538
    if (env->watchpoint_hit) {
        /* We re-entered the check after replacing the TB. Now raise
         * the debug interrupt so that is will trigger after the
         * current instruction. */
1539
        cpu_interrupt(ENV_GET_CPU(env), CPU_INTERRUPT_DEBUG);
1540 1541
        return;
    }
P
pbrook 已提交
1542
    vaddr = (env->mem_io_vaddr & TARGET_PAGE_MASK) + offset;
B
Blue Swirl 已提交
1543
    QTAILQ_FOREACH(wp, &env->watchpoints, entry) {
1544 1545
        if ((vaddr == (wp->vaddr & len_mask) ||
             (vaddr & wp->len_mask) == wp->vaddr) && (wp->flags & flags)) {
1546 1547 1548
            wp->flags |= BP_WATCHPOINT_HIT;
            if (!env->watchpoint_hit) {
                env->watchpoint_hit = wp;
B
Blue Swirl 已提交
1549
                tb_check_watchpoint(env);
1550 1551
                if (wp->flags & BP_STOP_BEFORE_ACCESS) {
                    env->exception_index = EXCP_DEBUG;
1552
                    cpu_loop_exit(env);
1553 1554 1555
                } else {
                    cpu_get_tb_cpu_state(env, &pc, &cs_base, &cpu_flags);
                    tb_gen_code(env, pc, cs_base, cpu_flags, 1);
1556
                    cpu_resume_from_signal(env, NULL);
1557
                }
1558
            }
1559 1560
        } else {
            wp->flags &= ~BP_WATCHPOINT_HIT;
P
pbrook 已提交
1561 1562 1563 1564
        }
    }
}

1565 1566 1567
/* Watchpoint access routines.  Watchpoints are inserted using TLB tricks,
   so these check for a hit then pass through to the normal out-of-line
   phys routines.  */
A
Avi Kivity 已提交
1568
static uint64_t watch_mem_read(void *opaque, hwaddr addr,
1569
                               unsigned size)
1570
{
1571 1572 1573 1574 1575 1576 1577
    check_watchpoint(addr & ~TARGET_PAGE_MASK, ~(size - 1), BP_MEM_READ);
    switch (size) {
    case 1: return ldub_phys(addr);
    case 2: return lduw_phys(addr);
    case 4: return ldl_phys(addr);
    default: abort();
    }
1578 1579
}

A
Avi Kivity 已提交
1580
static void watch_mem_write(void *opaque, hwaddr addr,
1581
                            uint64_t val, unsigned size)
1582
{
1583 1584
    check_watchpoint(addr & ~TARGET_PAGE_MASK, ~(size - 1), BP_MEM_WRITE);
    switch (size) {
1585 1586 1587 1588 1589 1590 1591 1592 1593
    case 1:
        stb_phys(addr, val);
        break;
    case 2:
        stw_phys(addr, val);
        break;
    case 4:
        stl_phys(addr, val);
        break;
1594 1595
    default: abort();
    }
1596 1597
}

1598 1599 1600 1601
static const MemoryRegionOps watch_mem_ops = {
    .read = watch_mem_read,
    .write = watch_mem_write,
    .endianness = DEVICE_NATIVE_ENDIAN,
1602 1603
};

A
Avi Kivity 已提交
1604
static uint64_t subpage_read(void *opaque, hwaddr addr,
1605
                             unsigned len)
1606
{
1607 1608
    subpage_t *subpage = opaque;
    uint8_t buf[4];
1609

1610
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1611
    printf("%s: subpage %p len %u addr " TARGET_FMT_plx "\n", __func__,
1612
           subpage, len, addr);
1613
#endif
1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624
    address_space_read(subpage->as, addr + subpage->base, buf, len);
    switch (len) {
    case 1:
        return ldub_p(buf);
    case 2:
        return lduw_p(buf);
    case 4:
        return ldl_p(buf);
    default:
        abort();
    }
1625 1626
}

A
Avi Kivity 已提交
1627
static void subpage_write(void *opaque, hwaddr addr,
1628
                          uint64_t value, unsigned len)
1629
{
1630 1631 1632
    subpage_t *subpage = opaque;
    uint8_t buf[4];

1633
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1634
    printf("%s: subpage %p len %u addr " TARGET_FMT_plx
1635 1636
           " value %"PRIx64"\n",
           __func__, subpage, len, addr, value);
1637
#endif
1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651
    switch (len) {
    case 1:
        stb_p(buf, value);
        break;
    case 2:
        stw_p(buf, value);
        break;
    case 4:
        stl_p(buf, value);
        break;
    default:
        abort();
    }
    address_space_write(subpage->as, addr + subpage->base, buf, len);
1652 1653
}

1654
static bool subpage_accepts(void *opaque, hwaddr addr,
A
Amos Kong 已提交
1655
                            unsigned len, bool is_write)
1656
{
1657
    subpage_t *subpage = opaque;
1658
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1659
    printf("%s: subpage %p %c len %u addr " TARGET_FMT_plx "\n",
1660
           __func__, subpage, is_write ? 'w' : 'r', len, addr);
1661 1662
#endif

1663
    return address_space_access_valid(subpage->as, addr + subpage->base,
A
Amos Kong 已提交
1664
                                      len, is_write);
1665 1666
}

1667 1668 1669
static const MemoryRegionOps subpage_ops = {
    .read = subpage_read,
    .write = subpage_write,
1670
    .valid.accepts = subpage_accepts,
1671
    .endianness = DEVICE_NATIVE_ENDIAN,
1672 1673
};

A
Anthony Liguori 已提交
1674
static int subpage_register (subpage_t *mmio, uint32_t start, uint32_t end,
1675
                             uint16_t section)
1676 1677 1678 1679 1680 1681 1682 1683
{
    int idx, eidx;

    if (start >= TARGET_PAGE_SIZE || end >= TARGET_PAGE_SIZE)
        return -1;
    idx = SUBPAGE_IDX(start);
    eidx = SUBPAGE_IDX(end);
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1684 1685
    printf("%s: %p start %08x end %08x idx %08x eidx %08x section %d\n",
           __func__, mmio, start, end, idx, eidx, section);
1686 1687
#endif
    for (; idx <= eidx; idx++) {
1688
        mmio->sub_section[idx] = section;
1689 1690 1691 1692 1693
    }

    return 0;
}

1694
static subpage_t *subpage_init(AddressSpace *as, hwaddr base)
1695
{
A
Anthony Liguori 已提交
1696
    subpage_t *mmio;
1697

1698
    mmio = g_malloc0(sizeof(subpage_t));
1699

1700
    mmio->as = as;
1701
    mmio->base = base;
1702
    memory_region_init_io(&mmio->iomem, NULL, &subpage_ops, mmio,
1703
                          "subpage", TARGET_PAGE_SIZE);
A
Avi Kivity 已提交
1704
    mmio->iomem.subpage = true;
1705
#if defined(DEBUG_SUBPAGE)
A
Amos Kong 已提交
1706 1707
    printf("%s: %p base " TARGET_FMT_plx " len %08x\n", __func__,
           mmio, base, TARGET_PAGE_SIZE);
1708
#endif
1709
    subpage_register(mmio, 0, TARGET_PAGE_SIZE-1, PHYS_SECTION_UNASSIGNED);
1710 1711 1712 1713

    return mmio;
}

1714
static uint16_t dummy_section(PhysPageMap *map, MemoryRegion *mr)
1715 1716 1717 1718 1719
{
    MemoryRegionSection section = {
        .mr = mr,
        .offset_within_address_space = 0,
        .offset_within_region = 0,
1720
        .size = int128_2_64(),
1721 1722
    };

1723
    return phys_section_add(map, &section);
1724 1725
}

A
Avi Kivity 已提交
1726
MemoryRegion *iotlb_to_region(hwaddr index)
1727
{
1728 1729
    return address_space_memory.dispatch->map.sections[
           index & ~TARGET_PAGE_MASK].mr;
1730 1731
}

A
Avi Kivity 已提交
1732 1733
static void io_mem_init(void)
{
1734 1735
    memory_region_init_io(&io_mem_rom, NULL, &unassigned_mem_ops, NULL, "rom", UINT64_MAX);
    memory_region_init_io(&io_mem_unassigned, NULL, &unassigned_mem_ops, NULL,
1736
                          "unassigned", UINT64_MAX);
1737
    memory_region_init_io(&io_mem_notdirty, NULL, &notdirty_mem_ops, NULL,
1738
                          "notdirty", UINT64_MAX);
1739
    memory_region_init_io(&io_mem_watch, NULL, &watch_mem_ops, NULL,
1740
                          "watch", UINT64_MAX);
A
Avi Kivity 已提交
1741 1742
}

A
Avi Kivity 已提交
1743
static void mem_begin(MemoryListener *listener)
1744 1745
{
    AddressSpace *as = container_of(listener, AddressSpace, dispatch_listener);
1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756
    AddressSpaceDispatch *d = g_new0(AddressSpaceDispatch, 1);
    uint16_t n;

    n = dummy_section(&d->map, &io_mem_unassigned);
    assert(n == PHYS_SECTION_UNASSIGNED);
    n = dummy_section(&d->map, &io_mem_notdirty);
    assert(n == PHYS_SECTION_NOTDIRTY);
    n = dummy_section(&d->map, &io_mem_rom);
    assert(n == PHYS_SECTION_ROM);
    n = dummy_section(&d->map, &io_mem_watch);
    assert(n == PHYS_SECTION_WATCH);
1757

M
Michael S. Tsirkin 已提交
1758
    d->phys_map  = (PhysPageEntry) { .ptr = PHYS_MAP_NODE_NIL, .skip = 1 };
1759 1760 1761 1762 1763
    d->as = as;
    as->next_dispatch = d;
}

static void mem_commit(MemoryListener *listener)
A
Avi Kivity 已提交
1764
{
1765
    AddressSpace *as = container_of(listener, AddressSpace, dispatch_listener);
1766 1767 1768
    AddressSpaceDispatch *cur = as->dispatch;
    AddressSpaceDispatch *next = as->next_dispatch;

1769
    phys_page_compact_all(next, next->map.nodes_nb);
1770

1771
    as->dispatch = next;
1772

1773 1774 1775 1776
    if (cur) {
        phys_sections_free(&cur->map);
        g_free(cur);
    }
1777 1778
}

1779
static void tcg_commit(MemoryListener *listener)
1780
{
1781
    CPUState *cpu;
1782 1783 1784 1785

    /* since each CPU stores ram addresses in its TLB cache, we must
       reset the modified entries */
    /* XXX: slow ! */
A
Andreas Färber 已提交
1786
    CPU_FOREACH(cpu) {
1787 1788
        CPUArchState *env = cpu->env_ptr;

1789 1790
        tlb_flush(env, 1);
    }
1791 1792
}

1793 1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804 1805
static void core_log_global_start(MemoryListener *listener)
{
    cpu_physical_memory_set_dirty_tracking(1);
}

static void core_log_global_stop(MemoryListener *listener)
{
    cpu_physical_memory_set_dirty_tracking(0);
}

static MemoryListener core_memory_listener = {
    .log_global_start = core_log_global_start,
    .log_global_stop = core_log_global_stop,
A
Avi Kivity 已提交
1806
    .priority = 1,
1807 1808
};

1809 1810 1811 1812
static MemoryListener tcg_memory_listener = {
    .commit = tcg_commit,
};

A
Avi Kivity 已提交
1813 1814
void address_space_init_dispatch(AddressSpace *as)
{
1815
    as->dispatch = NULL;
1816
    as->dispatch_listener = (MemoryListener) {
A
Avi Kivity 已提交
1817
        .begin = mem_begin,
1818
        .commit = mem_commit,
A
Avi Kivity 已提交
1819 1820 1821 1822
        .region_add = mem_add,
        .region_nop = mem_add,
        .priority = 0,
    };
1823
    memory_listener_register(&as->dispatch_listener, as);
A
Avi Kivity 已提交
1824 1825
}

A
Avi Kivity 已提交
1826 1827 1828 1829
void address_space_destroy_dispatch(AddressSpace *as)
{
    AddressSpaceDispatch *d = as->dispatch;

1830
    memory_listener_unregister(&as->dispatch_listener);
A
Avi Kivity 已提交
1831 1832 1833 1834
    g_free(d);
    as->dispatch = NULL;
}

A
Avi Kivity 已提交
1835 1836
static void memory_map_init(void)
{
1837
    system_memory = g_malloc(sizeof(*system_memory));
1838

1839
    memory_region_init(system_memory, NULL, "system", UINT64_MAX);
1840
    address_space_init(&address_space_memory, system_memory, "memory");
1841

1842
    system_io = g_malloc(sizeof(*system_io));
1843 1844
    memory_region_init_io(system_io, NULL, &unassigned_io_ops, NULL, "io",
                          65536);
1845
    address_space_init(&address_space_io, system_io, "I/O");
1846

1847
    memory_listener_register(&core_memory_listener, &address_space_memory);
1848 1849 1850
    if (tcg_enabled()) {
        memory_listener_register(&tcg_memory_listener, &address_space_memory);
    }
A
Avi Kivity 已提交
1851 1852 1853 1854 1855 1856 1857
}

MemoryRegion *get_system_memory(void)
{
    return system_memory;
}

1858 1859 1860 1861 1862
MemoryRegion *get_system_io(void)
{
    return system_io;
}

1863 1864
#endif /* !defined(CONFIG_USER_ONLY) */

B
bellard 已提交
1865 1866
/* physical memory access (slow version, mainly for debug) */
#if defined(CONFIG_USER_ONLY)
1867
int cpu_memory_rw_debug(CPUState *cpu, target_ulong addr,
P
Paul Brook 已提交
1868
                        uint8_t *buf, int len, int is_write)
B
bellard 已提交
1869 1870 1871
{
    int l, flags;
    target_ulong page;
1872
    void * p;
B
bellard 已提交
1873 1874 1875 1876 1877 1878 1879 1880

    while (len > 0) {
        page = addr & TARGET_PAGE_MASK;
        l = (page + TARGET_PAGE_SIZE) - addr;
        if (l > len)
            l = len;
        flags = page_get_flags(page);
        if (!(flags & PAGE_VALID))
P
Paul Brook 已提交
1881
            return -1;
B
bellard 已提交
1882 1883
        if (is_write) {
            if (!(flags & PAGE_WRITE))
P
Paul Brook 已提交
1884
                return -1;
1885
            /* XXX: this code should not depend on lock_user */
A
aurel32 已提交
1886
            if (!(p = lock_user(VERIFY_WRITE, addr, l, 0)))
P
Paul Brook 已提交
1887
                return -1;
A
aurel32 已提交
1888 1889
            memcpy(p, buf, l);
            unlock_user(p, addr, l);
B
bellard 已提交
1890 1891
        } else {
            if (!(flags & PAGE_READ))
P
Paul Brook 已提交
1892
                return -1;
1893
            /* XXX: this code should not depend on lock_user */
A
aurel32 已提交
1894
            if (!(p = lock_user(VERIFY_READ, addr, l, 1)))
P
Paul Brook 已提交
1895
                return -1;
A
aurel32 已提交
1896
            memcpy(buf, p, l);
A
aurel32 已提交
1897
            unlock_user(p, addr, 0);
B
bellard 已提交
1898 1899 1900 1901 1902
        }
        len -= l;
        buf += l;
        addr += l;
    }
P
Paul Brook 已提交
1903
    return 0;
B
bellard 已提交
1904
}
B
bellard 已提交
1905

B
bellard 已提交
1906
#else
1907

A
Avi Kivity 已提交
1908 1909
static void invalidate_and_set_dirty(hwaddr addr,
                                     hwaddr length)
1910 1911 1912 1913 1914
{
    if (!cpu_physical_memory_is_dirty(addr)) {
        /* invalidate code */
        tb_invalidate_phys_page_range(addr, addr + length, 0);
        /* set dirty bit */
1915 1916
        cpu_physical_memory_set_dirty_flag(addr, DIRTY_MEMORY_VGA);
        cpu_physical_memory_set_dirty_flag(addr, DIRTY_MEMORY_MIGRATION);
1917
    }
1918
    xen_modified_memory(addr, length);
1919 1920
}

1921 1922 1923 1924 1925 1926 1927 1928 1929 1930 1931 1932
static inline bool memory_access_is_direct(MemoryRegion *mr, bool is_write)
{
    if (memory_region_is_ram(mr)) {
        return !(is_write && mr->readonly);
    }
    if (memory_region_is_romd(mr)) {
        return !is_write;
    }

    return false;
}

1933
static int memory_access_size(MemoryRegion *mr, unsigned l, hwaddr addr)
1934
{
1935
    unsigned access_size_max = mr->ops->valid.max_access_size;
1936 1937 1938 1939 1940 1941 1942 1943 1944 1945 1946 1947 1948

    /* Regions are assumed to support 1-4 byte accesses unless
       otherwise specified.  */
    if (access_size_max == 0) {
        access_size_max = 4;
    }

    /* Bound the maximum access by the alignment of the address.  */
    if (!mr->ops->impl.unaligned) {
        unsigned align_size_max = addr & -addr;
        if (align_size_max != 0 && align_size_max < access_size_max) {
            access_size_max = align_size_max;
        }
1949
    }
1950 1951 1952 1953

    /* Don't attempt accesses larger than the maximum.  */
    if (l > access_size_max) {
        l = access_size_max;
1954
    }
1955 1956 1957
    if (l & (l - 1)) {
        l = 1 << (qemu_fls(l) - 1);
    }
1958 1959

    return l;
1960 1961
}

1962
bool address_space_rw(AddressSpace *as, hwaddr addr, uint8_t *buf,
A
Avi Kivity 已提交
1963
                      int len, bool is_write)
B
bellard 已提交
1964
{
1965
    hwaddr l;
B
bellard 已提交
1966
    uint8_t *ptr;
1967
    uint64_t val;
1968
    hwaddr addr1;
1969
    MemoryRegion *mr;
1970
    bool error = false;
1971

B
bellard 已提交
1972
    while (len > 0) {
1973
        l = len;
1974
        mr = address_space_translate(as, addr, &addr1, &l, is_write);
1975

B
bellard 已提交
1976
        if (is_write) {
1977 1978
            if (!memory_access_is_direct(mr, is_write)) {
                l = memory_access_size(mr, l, addr1);
1979
                /* XXX: could force current_cpu to NULL to avoid
B
bellard 已提交
1980
                   potential bugs */
1981 1982 1983 1984 1985 1986 1987
                switch (l) {
                case 8:
                    /* 64 bit write access */
                    val = ldq_p(buf);
                    error |= io_mem_write(mr, addr1, val, 8);
                    break;
                case 4:
B
bellard 已提交
1988
                    /* 32 bit write access */
B
bellard 已提交
1989
                    val = ldl_p(buf);
1990
                    error |= io_mem_write(mr, addr1, val, 4);
1991 1992
                    break;
                case 2:
B
bellard 已提交
1993
                    /* 16 bit write access */
B
bellard 已提交
1994
                    val = lduw_p(buf);
1995
                    error |= io_mem_write(mr, addr1, val, 2);
1996 1997
                    break;
                case 1:
B
bellard 已提交
1998
                    /* 8 bit write access */
B
bellard 已提交
1999
                    val = ldub_p(buf);
2000
                    error |= io_mem_write(mr, addr1, val, 1);
2001 2002 2003
                    break;
                default:
                    abort();
B
bellard 已提交
2004
                }
2005
            } else {
2006
                addr1 += memory_region_get_ram_addr(mr);
B
bellard 已提交
2007
                /* RAM case */
P
pbrook 已提交
2008
                ptr = qemu_get_ram_ptr(addr1);
B
bellard 已提交
2009
                memcpy(ptr, buf, l);
2010
                invalidate_and_set_dirty(addr1, l);
B
bellard 已提交
2011 2012
            }
        } else {
2013
            if (!memory_access_is_direct(mr, is_write)) {
B
bellard 已提交
2014
                /* I/O case */
2015
                l = memory_access_size(mr, l, addr1);
2016 2017 2018 2019 2020 2021 2022
                switch (l) {
                case 8:
                    /* 64 bit read access */
                    error |= io_mem_read(mr, addr1, &val, 8);
                    stq_p(buf, val);
                    break;
                case 4:
B
bellard 已提交
2023
                    /* 32 bit read access */
2024
                    error |= io_mem_read(mr, addr1, &val, 4);
B
bellard 已提交
2025
                    stl_p(buf, val);
2026 2027
                    break;
                case 2:
B
bellard 已提交
2028
                    /* 16 bit read access */
2029
                    error |= io_mem_read(mr, addr1, &val, 2);
B
bellard 已提交
2030
                    stw_p(buf, val);
2031 2032
                    break;
                case 1:
B
bellard 已提交
2033
                    /* 8 bit read access */
2034
                    error |= io_mem_read(mr, addr1, &val, 1);
B
bellard 已提交
2035
                    stb_p(buf, val);
2036 2037 2038
                    break;
                default:
                    abort();
B
bellard 已提交
2039 2040 2041
                }
            } else {
                /* RAM case */
2042
                ptr = qemu_get_ram_ptr(mr->ram_addr + addr1);
2043
                memcpy(buf, ptr, l);
B
bellard 已提交
2044 2045 2046 2047 2048 2049
            }
        }
        len -= l;
        buf += l;
        addr += l;
    }
2050 2051

    return error;
B
bellard 已提交
2052
}
B
bellard 已提交
2053

2054
bool address_space_write(AddressSpace *as, hwaddr addr,
A
Avi Kivity 已提交
2055 2056
                         const uint8_t *buf, int len)
{
2057
    return address_space_rw(as, addr, (uint8_t *)buf, len, true);
A
Avi Kivity 已提交
2058 2059
}

2060
bool address_space_read(AddressSpace *as, hwaddr addr, uint8_t *buf, int len)
A
Avi Kivity 已提交
2061
{
2062
    return address_space_rw(as, addr, buf, len, false);
A
Avi Kivity 已提交
2063 2064 2065
}


A
Avi Kivity 已提交
2066
void cpu_physical_memory_rw(hwaddr addr, uint8_t *buf,
A
Avi Kivity 已提交
2067 2068
                            int len, int is_write)
{
2069
    address_space_rw(&address_space_memory, addr, buf, len, is_write);
A
Avi Kivity 已提交
2070 2071
}

2072 2073 2074 2075 2076 2077 2078
enum write_rom_type {
    WRITE_DATA,
    FLUSH_CACHE,
};

static inline void cpu_physical_memory_write_rom_internal(
    hwaddr addr, const uint8_t *buf, int len, enum write_rom_type type)
B
bellard 已提交
2079
{
2080
    hwaddr l;
B
bellard 已提交
2081
    uint8_t *ptr;
2082
    hwaddr addr1;
2083
    MemoryRegion *mr;
2084

B
bellard 已提交
2085
    while (len > 0) {
2086
        l = len;
2087 2088
        mr = address_space_translate(&address_space_memory,
                                     addr, &addr1, &l, true);
2089

2090 2091
        if (!(memory_region_is_ram(mr) ||
              memory_region_is_romd(mr))) {
B
bellard 已提交
2092 2093
            /* do nothing */
        } else {
2094
            addr1 += memory_region_get_ram_addr(mr);
B
bellard 已提交
2095
            /* ROM/RAM case */
P
pbrook 已提交
2096
            ptr = qemu_get_ram_ptr(addr1);
2097 2098 2099 2100 2101 2102 2103 2104 2105
            switch (type) {
            case WRITE_DATA:
                memcpy(ptr, buf, l);
                invalidate_and_set_dirty(addr1, l);
                break;
            case FLUSH_CACHE:
                flush_icache_range((uintptr_t)ptr, (uintptr_t)ptr + l);
                break;
            }
B
bellard 已提交
2106 2107 2108 2109 2110 2111 2112
        }
        len -= l;
        buf += l;
        addr += l;
    }
}

2113 2114 2115 2116 2117 2118 2119 2120 2121 2122 2123 2124 2125 2126 2127 2128 2129 2130 2131 2132 2133 2134
/* used for ROM loading : can write in RAM and ROM */
void cpu_physical_memory_write_rom(hwaddr addr,
                                   const uint8_t *buf, int len)
{
    cpu_physical_memory_write_rom_internal(addr, buf, len, WRITE_DATA);
}

void cpu_flush_icache_range(hwaddr start, int len)
{
    /*
     * This function should do the same thing as an icache flush that was
     * triggered from within the guest. For TCG we are always cache coherent,
     * so there is no need to flush anything. For KVM / Xen we need to flush
     * the host's instruction cache at least.
     */
    if (tcg_enabled()) {
        return;
    }

    cpu_physical_memory_write_rom_internal(start, NULL, len, FLUSH_CACHE);
}

2135
typedef struct {
2136
    MemoryRegion *mr;
2137
    void *buffer;
A
Avi Kivity 已提交
2138 2139
    hwaddr addr;
    hwaddr len;
2140 2141 2142 2143
} BounceBuffer;

static BounceBuffer bounce;

2144 2145 2146
typedef struct MapClient {
    void *opaque;
    void (*callback)(void *opaque);
B
Blue Swirl 已提交
2147
    QLIST_ENTRY(MapClient) link;
2148 2149
} MapClient;

B
Blue Swirl 已提交
2150 2151
static QLIST_HEAD(map_client_list, MapClient) map_client_list
    = QLIST_HEAD_INITIALIZER(map_client_list);
2152 2153 2154

void *cpu_register_map_client(void *opaque, void (*callback)(void *opaque))
{
2155
    MapClient *client = g_malloc(sizeof(*client));
2156 2157 2158

    client->opaque = opaque;
    client->callback = callback;
B
Blue Swirl 已提交
2159
    QLIST_INSERT_HEAD(&map_client_list, client, link);
2160 2161 2162
    return client;
}

B
Blue Swirl 已提交
2163
static void cpu_unregister_map_client(void *_client)
2164 2165 2166
{
    MapClient *client = (MapClient *)_client;

B
Blue Swirl 已提交
2167
    QLIST_REMOVE(client, link);
2168
    g_free(client);
2169 2170 2171 2172 2173 2174
}

static void cpu_notify_map_clients(void)
{
    MapClient *client;

B
Blue Swirl 已提交
2175 2176
    while (!QLIST_EMPTY(&map_client_list)) {
        client = QLIST_FIRST(&map_client_list);
2177
        client->callback(client->opaque);
2178
        cpu_unregister_map_client(client);
2179 2180 2181
    }
}

2182 2183
bool address_space_access_valid(AddressSpace *as, hwaddr addr, int len, bool is_write)
{
2184
    MemoryRegion *mr;
2185 2186 2187 2188
    hwaddr l, xlat;

    while (len > 0) {
        l = len;
2189 2190 2191 2192
        mr = address_space_translate(as, addr, &xlat, &l, is_write);
        if (!memory_access_is_direct(mr, is_write)) {
            l = memory_access_size(mr, l, addr);
            if (!memory_region_access_valid(mr, xlat, l, is_write)) {
2193 2194 2195 2196 2197 2198 2199 2200 2201 2202
                return false;
            }
        }

        len -= l;
        addr += l;
    }
    return true;
}

2203 2204 2205 2206
/* Map a physical memory region into a host virtual address.
 * May map a subset of the requested range, given by and returned in *plen.
 * May return NULL if resources needed to perform the mapping are exhausted.
 * Use only for reads OR writes - not for read-modify-write operations.
2207 2208
 * Use cpu_register_map_client() to know when retrying the map operation is
 * likely to succeed.
2209
 */
A
Avi Kivity 已提交
2210
void *address_space_map(AddressSpace *as,
A
Avi Kivity 已提交
2211 2212
                        hwaddr addr,
                        hwaddr *plen,
A
Avi Kivity 已提交
2213
                        bool is_write)
2214
{
A
Avi Kivity 已提交
2215
    hwaddr len = *plen;
2216 2217 2218 2219
    hwaddr done = 0;
    hwaddr l, xlat, base;
    MemoryRegion *mr, *this_mr;
    ram_addr_t raddr;
2220

2221 2222 2223
    if (len == 0) {
        return NULL;
    }
2224

2225 2226 2227 2228 2229
    l = len;
    mr = address_space_translate(as, addr, &xlat, &l, is_write);
    if (!memory_access_is_direct(mr, is_write)) {
        if (bounce.buffer) {
            return NULL;
2230
        }
2231 2232 2233
        /* Avoid unbounded allocations */
        l = MIN(l, TARGET_PAGE_SIZE);
        bounce.buffer = qemu_memalign(TARGET_PAGE_SIZE, l);
2234 2235
        bounce.addr = addr;
        bounce.len = l;
2236 2237 2238

        memory_region_ref(mr);
        bounce.mr = mr;
2239 2240
        if (!is_write) {
            address_space_read(as, addr, bounce.buffer, l);
2241
        }
2242

2243 2244 2245 2246 2247 2248 2249 2250
        *plen = l;
        return bounce.buffer;
    }

    base = xlat;
    raddr = memory_region_get_ram_addr(mr);

    for (;;) {
2251 2252
        len -= l;
        addr += l;
2253 2254 2255 2256 2257 2258 2259 2260 2261 2262
        done += l;
        if (len == 0) {
            break;
        }

        l = len;
        this_mr = address_space_translate(as, addr, &xlat, &l, is_write);
        if (this_mr != mr || xlat != base + done) {
            break;
        }
2263
    }
2264

2265
    memory_region_ref(mr);
2266 2267
    *plen = done;
    return qemu_ram_ptr_length(raddr + base, plen);
2268 2269
}

A
Avi Kivity 已提交
2270
/* Unmaps a memory region previously mapped by address_space_map().
2271 2272 2273
 * Will also mark the memory as dirty if is_write == 1.  access_len gives
 * the amount of memory that was actually read or written by the caller.
 */
A
Avi Kivity 已提交
2274 2275
void address_space_unmap(AddressSpace *as, void *buffer, hwaddr len,
                         int is_write, hwaddr access_len)
2276 2277
{
    if (buffer != bounce.buffer) {
2278 2279 2280 2281 2282
        MemoryRegion *mr;
        ram_addr_t addr1;

        mr = qemu_ram_addr_from_host(buffer, &addr1);
        assert(mr != NULL);
2283 2284 2285 2286 2287 2288
        if (is_write) {
            while (access_len) {
                unsigned l;
                l = TARGET_PAGE_SIZE;
                if (l > access_len)
                    l = access_len;
2289
                invalidate_and_set_dirty(addr1, l);
2290 2291 2292 2293
                addr1 += l;
                access_len -= l;
            }
        }
2294
        if (xen_enabled()) {
J
Jan Kiszka 已提交
2295
            xen_invalidate_map_cache_entry(buffer);
A
Anthony PERARD 已提交
2296
        }
2297
        memory_region_unref(mr);
2298 2299 2300
        return;
    }
    if (is_write) {
A
Avi Kivity 已提交
2301
        address_space_write(as, bounce.addr, bounce.buffer, access_len);
2302
    }
2303
    qemu_vfree(bounce.buffer);
2304
    bounce.buffer = NULL;
2305
    memory_region_unref(bounce.mr);
2306
    cpu_notify_map_clients();
2307
}
B
bellard 已提交
2308

A
Avi Kivity 已提交
2309 2310
void *cpu_physical_memory_map(hwaddr addr,
                              hwaddr *plen,
A
Avi Kivity 已提交
2311 2312 2313 2314 2315
                              int is_write)
{
    return address_space_map(&address_space_memory, addr, plen, is_write);
}

A
Avi Kivity 已提交
2316 2317
void cpu_physical_memory_unmap(void *buffer, hwaddr len,
                               int is_write, hwaddr access_len)
A
Avi Kivity 已提交
2318 2319 2320 2321
{
    return address_space_unmap(&address_space_memory, buffer, len, is_write, access_len);
}

B
bellard 已提交
2322
/* warning: addr must be aligned */
A
Avi Kivity 已提交
2323
static inline uint32_t ldl_phys_internal(hwaddr addr,
2324
                                         enum device_endian endian)
B
bellard 已提交
2325 2326
{
    uint8_t *ptr;
2327
    uint64_t val;
2328
    MemoryRegion *mr;
2329 2330
    hwaddr l = 4;
    hwaddr addr1;
B
bellard 已提交
2331

2332 2333 2334
    mr = address_space_translate(&address_space_memory, addr, &addr1, &l,
                                 false);
    if (l < 4 || !memory_access_is_direct(mr, false)) {
B
bellard 已提交
2335
        /* I/O case */
2336
        io_mem_read(mr, addr1, &val, 4);
2337 2338 2339 2340 2341 2342 2343 2344 2345
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap32(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap32(val);
        }
#endif
B
bellard 已提交
2346 2347
    } else {
        /* RAM case */
2348
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(mr)
2349
                                & TARGET_PAGE_MASK)
2350
                               + addr1);
2351 2352 2353 2354 2355 2356 2357 2358 2359 2360 2361
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            val = ldl_le_p(ptr);
            break;
        case DEVICE_BIG_ENDIAN:
            val = ldl_be_p(ptr);
            break;
        default:
            val = ldl_p(ptr);
            break;
        }
B
bellard 已提交
2362 2363 2364 2365
    }
    return val;
}

A
Avi Kivity 已提交
2366
uint32_t ldl_phys(hwaddr addr)
2367 2368 2369 2370
{
    return ldl_phys_internal(addr, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
2371
uint32_t ldl_le_phys(hwaddr addr)
2372 2373 2374 2375
{
    return ldl_phys_internal(addr, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
2376
uint32_t ldl_be_phys(hwaddr addr)
2377 2378 2379 2380
{
    return ldl_phys_internal(addr, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
2381
/* warning: addr must be aligned */
A
Avi Kivity 已提交
2382
static inline uint64_t ldq_phys_internal(hwaddr addr,
2383
                                         enum device_endian endian)
B
bellard 已提交
2384 2385 2386
{
    uint8_t *ptr;
    uint64_t val;
2387
    MemoryRegion *mr;
2388 2389
    hwaddr l = 8;
    hwaddr addr1;
B
bellard 已提交
2390

2391 2392 2393
    mr = address_space_translate(&address_space_memory, addr, &addr1, &l,
                                 false);
    if (l < 8 || !memory_access_is_direct(mr, false)) {
B
bellard 已提交
2394
        /* I/O case */
2395
        io_mem_read(mr, addr1, &val, 8);
2396 2397 2398 2399 2400 2401 2402 2403
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap64(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap64(val);
        }
B
bellard 已提交
2404 2405 2406
#endif
    } else {
        /* RAM case */
2407
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(mr)
2408
                                & TARGET_PAGE_MASK)
2409
                               + addr1);
2410 2411 2412 2413 2414 2415 2416 2417 2418 2419 2420
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            val = ldq_le_p(ptr);
            break;
        case DEVICE_BIG_ENDIAN:
            val = ldq_be_p(ptr);
            break;
        default:
            val = ldq_p(ptr);
            break;
        }
B
bellard 已提交
2421 2422 2423 2424
    }
    return val;
}

A
Avi Kivity 已提交
2425
uint64_t ldq_phys(hwaddr addr)
2426 2427 2428 2429
{
    return ldq_phys_internal(addr, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
2430
uint64_t ldq_le_phys(hwaddr addr)
2431 2432 2433 2434
{
    return ldq_phys_internal(addr, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
2435
uint64_t ldq_be_phys(hwaddr addr)
2436 2437 2438 2439
{
    return ldq_phys_internal(addr, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
2440
/* XXX: optimize */
A
Avi Kivity 已提交
2441
uint32_t ldub_phys(hwaddr addr)
B
bellard 已提交
2442 2443 2444 2445 2446 2447
{
    uint8_t val;
    cpu_physical_memory_read(addr, &val, 1);
    return val;
}

2448
/* warning: addr must be aligned */
A
Avi Kivity 已提交
2449
static inline uint32_t lduw_phys_internal(hwaddr addr,
2450
                                          enum device_endian endian)
B
bellard 已提交
2451
{
2452 2453
    uint8_t *ptr;
    uint64_t val;
2454
    MemoryRegion *mr;
2455 2456
    hwaddr l = 2;
    hwaddr addr1;
2457

2458 2459 2460
    mr = address_space_translate(&address_space_memory, addr, &addr1, &l,
                                 false);
    if (l < 2 || !memory_access_is_direct(mr, false)) {
2461
        /* I/O case */
2462
        io_mem_read(mr, addr1, &val, 2);
2463 2464 2465 2466 2467 2468 2469 2470 2471
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap16(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap16(val);
        }
#endif
2472 2473
    } else {
        /* RAM case */
2474
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(mr)
2475
                                & TARGET_PAGE_MASK)
2476
                               + addr1);
2477 2478 2479 2480 2481 2482 2483 2484 2485 2486 2487
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            val = lduw_le_p(ptr);
            break;
        case DEVICE_BIG_ENDIAN:
            val = lduw_be_p(ptr);
            break;
        default:
            val = lduw_p(ptr);
            break;
        }
2488 2489
    }
    return val;
B
bellard 已提交
2490 2491
}

A
Avi Kivity 已提交
2492
uint32_t lduw_phys(hwaddr addr)
2493 2494 2495 2496
{
    return lduw_phys_internal(addr, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
2497
uint32_t lduw_le_phys(hwaddr addr)
2498 2499 2500 2501
{
    return lduw_phys_internal(addr, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
2502
uint32_t lduw_be_phys(hwaddr addr)
2503 2504 2505 2506
{
    return lduw_phys_internal(addr, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
2507 2508 2509
/* warning: addr must be aligned. The ram page is not masked as dirty
   and the code inside is not invalidated. It is useful if the dirty
   bits are used to track modified PTEs */
A
Avi Kivity 已提交
2510
void stl_phys_notdirty(hwaddr addr, uint32_t val)
B
bellard 已提交
2511 2512
{
    uint8_t *ptr;
2513
    MemoryRegion *mr;
2514 2515
    hwaddr l = 4;
    hwaddr addr1;
B
bellard 已提交
2516

2517 2518 2519 2520
    mr = address_space_translate(&address_space_memory, addr, &addr1, &l,
                                 true);
    if (l < 4 || !memory_access_is_direct(mr, true)) {
        io_mem_write(mr, addr1, val, 4);
B
bellard 已提交
2521
    } else {
2522
        addr1 += memory_region_get_ram_addr(mr) & TARGET_PAGE_MASK;
P
pbrook 已提交
2523
        ptr = qemu_get_ram_ptr(addr1);
B
bellard 已提交
2524
        stl_p(ptr, val);
A
aliguori 已提交
2525 2526 2527 2528 2529 2530

        if (unlikely(in_migration)) {
            if (!cpu_physical_memory_is_dirty(addr1)) {
                /* invalidate code */
                tb_invalidate_phys_page_range(addr1, addr1 + 4, 0);
                /* set dirty bit */
2531 2532 2533
                cpu_physical_memory_set_dirty_flag(addr1,
                                                   DIRTY_MEMORY_MIGRATION);
                cpu_physical_memory_set_dirty_flag(addr1, DIRTY_MEMORY_VGA);
A
aliguori 已提交
2534 2535
            }
        }
B
bellard 已提交
2536 2537 2538 2539
    }
}

/* warning: addr must be aligned */
A
Avi Kivity 已提交
2540
static inline void stl_phys_internal(hwaddr addr, uint32_t val,
2541
                                     enum device_endian endian)
B
bellard 已提交
2542 2543
{
    uint8_t *ptr;
2544
    MemoryRegion *mr;
2545 2546
    hwaddr l = 4;
    hwaddr addr1;
B
bellard 已提交
2547

2548 2549 2550
    mr = address_space_translate(&address_space_memory, addr, &addr1, &l,
                                 true);
    if (l < 4 || !memory_access_is_direct(mr, true)) {
2551 2552 2553 2554 2555 2556 2557 2558 2559
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap32(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap32(val);
        }
#endif
2560
        io_mem_write(mr, addr1, val, 4);
B
bellard 已提交
2561 2562
    } else {
        /* RAM case */
2563
        addr1 += memory_region_get_ram_addr(mr) & TARGET_PAGE_MASK;
P
pbrook 已提交
2564
        ptr = qemu_get_ram_ptr(addr1);
2565 2566 2567 2568 2569 2570 2571 2572 2573 2574 2575
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            stl_le_p(ptr, val);
            break;
        case DEVICE_BIG_ENDIAN:
            stl_be_p(ptr, val);
            break;
        default:
            stl_p(ptr, val);
            break;
        }
2576
        invalidate_and_set_dirty(addr1, 4);
B
bellard 已提交
2577 2578 2579
    }
}

A
Avi Kivity 已提交
2580
void stl_phys(hwaddr addr, uint32_t val)
2581 2582 2583 2584
{
    stl_phys_internal(addr, val, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
2585
void stl_le_phys(hwaddr addr, uint32_t val)
2586 2587 2588 2589
{
    stl_phys_internal(addr, val, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
2590
void stl_be_phys(hwaddr addr, uint32_t val)
2591 2592 2593 2594
{
    stl_phys_internal(addr, val, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
2595
/* XXX: optimize */
A
Avi Kivity 已提交
2596
void stb_phys(hwaddr addr, uint32_t val)
B
bellard 已提交
2597 2598 2599 2600 2601
{
    uint8_t v = val;
    cpu_physical_memory_write(addr, &v, 1);
}

2602
/* warning: addr must be aligned */
A
Avi Kivity 已提交
2603
static inline void stw_phys_internal(hwaddr addr, uint32_t val,
2604
                                     enum device_endian endian)
B
bellard 已提交
2605
{
2606
    uint8_t *ptr;
2607
    MemoryRegion *mr;
2608 2609
    hwaddr l = 2;
    hwaddr addr1;
2610

2611 2612 2613
    mr = address_space_translate(&address_space_memory, addr, &addr1, &l,
                                 true);
    if (l < 2 || !memory_access_is_direct(mr, true)) {
2614 2615 2616 2617 2618 2619 2620 2621 2622
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap16(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap16(val);
        }
#endif
2623
        io_mem_write(mr, addr1, val, 2);
2624 2625
    } else {
        /* RAM case */
2626
        addr1 += memory_region_get_ram_addr(mr) & TARGET_PAGE_MASK;
2627
        ptr = qemu_get_ram_ptr(addr1);
2628 2629 2630 2631 2632 2633 2634 2635 2636 2637 2638
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            stw_le_p(ptr, val);
            break;
        case DEVICE_BIG_ENDIAN:
            stw_be_p(ptr, val);
            break;
        default:
            stw_p(ptr, val);
            break;
        }
2639
        invalidate_and_set_dirty(addr1, 2);
2640
    }
B
bellard 已提交
2641 2642
}

A
Avi Kivity 已提交
2643
void stw_phys(hwaddr addr, uint32_t val)
2644 2645 2646 2647
{
    stw_phys_internal(addr, val, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
2648
void stw_le_phys(hwaddr addr, uint32_t val)
2649 2650 2651 2652
{
    stw_phys_internal(addr, val, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
2653
void stw_be_phys(hwaddr addr, uint32_t val)
2654 2655 2656 2657
{
    stw_phys_internal(addr, val, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
2658
/* XXX: optimize */
A
Avi Kivity 已提交
2659
void stq_phys(hwaddr addr, uint64_t val)
B
bellard 已提交
2660 2661
{
    val = tswap64(val);
2662
    cpu_physical_memory_write(addr, &val, 8);
B
bellard 已提交
2663 2664
}

A
Avi Kivity 已提交
2665
void stq_le_phys(hwaddr addr, uint64_t val)
2666 2667 2668 2669 2670
{
    val = cpu_to_le64(val);
    cpu_physical_memory_write(addr, &val, 8);
}

A
Avi Kivity 已提交
2671
void stq_be_phys(hwaddr addr, uint64_t val)
2672 2673 2674 2675 2676
{
    val = cpu_to_be64(val);
    cpu_physical_memory_write(addr, &val, 8);
}

2677
/* virtual memory access for debug (includes writing to ROM) */
2678
int cpu_memory_rw_debug(CPUState *cpu, target_ulong addr,
2679
                        uint8_t *buf, int len, int is_write)
B
bellard 已提交
2680 2681
{
    int l;
A
Avi Kivity 已提交
2682
    hwaddr phys_addr;
2683
    target_ulong page;
B
bellard 已提交
2684 2685 2686

    while (len > 0) {
        page = addr & TARGET_PAGE_MASK;
2687
        phys_addr = cpu_get_phys_page_debug(cpu, page);
B
bellard 已提交
2688 2689 2690 2691 2692 2693
        /* if no physical page mapped, return an error */
        if (phys_addr == -1)
            return -1;
        l = (page + TARGET_PAGE_SIZE) - addr;
        if (l > len)
            l = len;
2694 2695 2696 2697 2698
        phys_addr += (addr & ~TARGET_PAGE_MASK);
        if (is_write)
            cpu_physical_memory_write_rom(phys_addr, buf, l);
        else
            cpu_physical_memory_rw(phys_addr, buf, l, is_write);
B
bellard 已提交
2699 2700 2701 2702 2703 2704
        len -= l;
        buf += l;
        addr += l;
    }
    return 0;
}
P
Paul Brook 已提交
2705
#endif
B
bellard 已提交
2706

2707 2708 2709 2710 2711 2712 2713 2714 2715 2716 2717 2718 2719 2720 2721 2722 2723 2724
#if !defined(CONFIG_USER_ONLY)

/*
 * A helper function for the _utterly broken_ virtio device model to find out if
 * it's running on a big endian machine. Don't do this at home kids!
 */
bool virtio_is_big_endian(void);
bool virtio_is_big_endian(void)
{
#if defined(TARGET_WORDS_BIGENDIAN)
    return true;
#else
    return false;
#endif
}

#endif

2725
#ifndef CONFIG_USER_ONLY
A
Avi Kivity 已提交
2726
bool cpu_physical_memory_is_io(hwaddr phys_addr)
2727
{
2728
    MemoryRegion*mr;
2729
    hwaddr l = 1;
2730

2731 2732
    mr = address_space_translate(&address_space_memory,
                                 phys_addr, &phys_addr, &l, false);
2733

2734 2735
    return !(memory_region_is_ram(mr) ||
             memory_region_is_romd(mr));
2736
}
2737 2738 2739 2740 2741 2742 2743 2744 2745

void qemu_ram_foreach_block(RAMBlockIterFunc func, void *opaque)
{
    RAMBlock *block;

    QTAILQ_FOREACH(block, &ram_list.blocks, next) {
        func(block->host, block->offset, block->length, opaque);
    }
}
2746
#endif