You need to sign in or sign up before continuing.
virtio.c 30.0 KB
Newer Older
A
aliguori 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
/*
 * Virtio Support
 *
 * Copyright IBM, Corp. 2007
 *
 * Authors:
 *  Anthony Liguori   <aliguori@us.ibm.com>
 *
 * This work is licensed under the terms of the GNU GPL, version 2.  See
 * the COPYING file in the top-level directory.
 *
 */

#include <inttypes.h>

16
#include "trace.h"
17
#include "qemu/error-report.h"
P
Paolo Bonzini 已提交
18
#include "hw/virtio/virtio.h"
19
#include "qemu/atomic.h"
P
Paolo Bonzini 已提交
20
#include "hw/virtio/virtio-bus.h"
A
aliguori 已提交
21

22 23 24 25
/* The alignment to use between consumer and producer parts of vring.
 * x86 pagesize again. */
#define VIRTIO_PCI_VRING_ALIGN         4096

A
aliguori 已提交
26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56
typedef struct VRingDesc
{
    uint64_t addr;
    uint32_t len;
    uint16_t flags;
    uint16_t next;
} VRingDesc;

typedef struct VRingAvail
{
    uint16_t flags;
    uint16_t idx;
    uint16_t ring[0];
} VRingAvail;

typedef struct VRingUsedElem
{
    uint32_t id;
    uint32_t len;
} VRingUsedElem;

typedef struct VRingUsed
{
    uint16_t flags;
    uint16_t idx;
    VRingUsedElem ring[0];
} VRingUsed;

typedef struct VRing
{
    unsigned int num;
A
Avi Kivity 已提交
57 58 59
    hwaddr desc;
    hwaddr avail;
    hwaddr used;
A
aliguori 已提交
60 61 62 63 64
} VRing;

struct VirtQueue
{
    VRing vring;
A
Avi Kivity 已提交
65
    hwaddr pa;
A
aliguori 已提交
66
    uint16_t last_avail_idx;
M
Michael S. Tsirkin 已提交
67 68 69 70 71 72 73 74 75
    /* Last used index value we have signalled on */
    uint16_t signalled_used;

    /* Last used index value we have signalled on */
    bool signalled_used_valid;

    /* Notification enabled? */
    bool notification;

76 77
    uint16_t queue_index;

A
aliguori 已提交
78
    int inuse;
M
Michael S. Tsirkin 已提交
79

80
    uint16_t vector;
A
aliguori 已提交
81
    void (*handle_output)(VirtIODevice *vdev, VirtQueue *vq);
82 83 84
    VirtIODevice *vdev;
    EventNotifier guest_notifier;
    EventNotifier host_notifier;
A
aliguori 已提交
85 86 87
};

/* virt queue functions */
P
Paul Brook 已提交
88
static void virtqueue_init(VirtQueue *vq)
A
aliguori 已提交
89
{
A
Avi Kivity 已提交
90
    hwaddr pa = vq->pa;
P
Paul Brook 已提交
91

A
aliguori 已提交
92 93
    vq->vring.desc = pa;
    vq->vring.avail = pa + vq->vring.num * sizeof(VRingDesc);
94 95 96
    vq->vring.used = vring_align(vq->vring.avail +
                                 offsetof(VRingAvail, ring[vq->vring.num]),
                                 VIRTIO_PCI_VRING_ALIGN);
A
aliguori 已提交
97 98
}

A
Avi Kivity 已提交
99
static inline uint64_t vring_desc_addr(hwaddr desc_pa, int i)
A
aliguori 已提交
100
{
A
Avi Kivity 已提交
101
    hwaddr pa;
102
    pa = desc_pa + sizeof(VRingDesc) * i + offsetof(VRingDesc, addr);
A
aliguori 已提交
103 104 105
    return ldq_phys(pa);
}

A
Avi Kivity 已提交
106
static inline uint32_t vring_desc_len(hwaddr desc_pa, int i)
A
aliguori 已提交
107
{
A
Avi Kivity 已提交
108
    hwaddr pa;
109
    pa = desc_pa + sizeof(VRingDesc) * i + offsetof(VRingDesc, len);
A
aliguori 已提交
110 111 112
    return ldl_phys(pa);
}

A
Avi Kivity 已提交
113
static inline uint16_t vring_desc_flags(hwaddr desc_pa, int i)
A
aliguori 已提交
114
{
A
Avi Kivity 已提交
115
    hwaddr pa;
116
    pa = desc_pa + sizeof(VRingDesc) * i + offsetof(VRingDesc, flags);
A
aliguori 已提交
117 118 119
    return lduw_phys(pa);
}

A
Avi Kivity 已提交
120
static inline uint16_t vring_desc_next(hwaddr desc_pa, int i)
A
aliguori 已提交
121
{
A
Avi Kivity 已提交
122
    hwaddr pa;
123
    pa = desc_pa + sizeof(VRingDesc) * i + offsetof(VRingDesc, next);
A
aliguori 已提交
124 125 126 127 128
    return lduw_phys(pa);
}

static inline uint16_t vring_avail_flags(VirtQueue *vq)
{
A
Avi Kivity 已提交
129
    hwaddr pa;
A
aliguori 已提交
130 131 132 133 134 135
    pa = vq->vring.avail + offsetof(VRingAvail, flags);
    return lduw_phys(pa);
}

static inline uint16_t vring_avail_idx(VirtQueue *vq)
{
A
Avi Kivity 已提交
136
    hwaddr pa;
A
aliguori 已提交
137 138 139 140 141 142
    pa = vq->vring.avail + offsetof(VRingAvail, idx);
    return lduw_phys(pa);
}

static inline uint16_t vring_avail_ring(VirtQueue *vq, int i)
{
A
Avi Kivity 已提交
143
    hwaddr pa;
A
aliguori 已提交
144 145 146 147
    pa = vq->vring.avail + offsetof(VRingAvail, ring[i]);
    return lduw_phys(pa);
}

M
Michael S. Tsirkin 已提交
148 149 150 151 152
static inline uint16_t vring_used_event(VirtQueue *vq)
{
    return vring_avail_ring(vq, vq->vring.num);
}

A
aliguori 已提交
153 154
static inline void vring_used_ring_id(VirtQueue *vq, int i, uint32_t val)
{
A
Avi Kivity 已提交
155
    hwaddr pa;
A
aliguori 已提交
156 157 158 159 160 161
    pa = vq->vring.used + offsetof(VRingUsed, ring[i].id);
    stl_phys(pa, val);
}

static inline void vring_used_ring_len(VirtQueue *vq, int i, uint32_t val)
{
A
Avi Kivity 已提交
162
    hwaddr pa;
A
aliguori 已提交
163 164 165 166 167 168
    pa = vq->vring.used + offsetof(VRingUsed, ring[i].len);
    stl_phys(pa, val);
}

static uint16_t vring_used_idx(VirtQueue *vq)
{
A
Avi Kivity 已提交
169
    hwaddr pa;
A
aliguori 已提交
170 171 172 173
    pa = vq->vring.used + offsetof(VRingUsed, idx);
    return lduw_phys(pa);
}

M
Michael S. Tsirkin 已提交
174
static inline void vring_used_idx_set(VirtQueue *vq, uint16_t val)
A
aliguori 已提交
175
{
A
Avi Kivity 已提交
176
    hwaddr pa;
A
aliguori 已提交
177
    pa = vq->vring.used + offsetof(VRingUsed, idx);
M
Michael S. Tsirkin 已提交
178
    stw_phys(pa, val);
A
aliguori 已提交
179 180 181 182
}

static inline void vring_used_flags_set_bit(VirtQueue *vq, int mask)
{
A
Avi Kivity 已提交
183
    hwaddr pa;
A
aliguori 已提交
184 185 186 187 188 189
    pa = vq->vring.used + offsetof(VRingUsed, flags);
    stw_phys(pa, lduw_phys(pa) | mask);
}

static inline void vring_used_flags_unset_bit(VirtQueue *vq, int mask)
{
A
Avi Kivity 已提交
190
    hwaddr pa;
A
aliguori 已提交
191 192 193 194
    pa = vq->vring.used + offsetof(VRingUsed, flags);
    stw_phys(pa, lduw_phys(pa) & ~mask);
}

M
Michael S. Tsirkin 已提交
195 196
static inline void vring_avail_event(VirtQueue *vq, uint16_t val)
{
A
Avi Kivity 已提交
197
    hwaddr pa;
M
Michael S. Tsirkin 已提交
198 199 200 201 202 203 204
    if (!vq->notification) {
        return;
    }
    pa = vq->vring.used + offsetof(VRingUsed, ring[vq->vring.num]);
    stw_phys(pa, val);
}

A
aliguori 已提交
205 206
void virtio_queue_set_notification(VirtQueue *vq, int enable)
{
M
Michael S. Tsirkin 已提交
207 208 209 210
    vq->notification = enable;
    if (vq->vdev->guest_features & (1 << VIRTIO_RING_F_EVENT_IDX)) {
        vring_avail_event(vq, vring_avail_idx(vq));
    } else if (enable) {
A
aliguori 已提交
211
        vring_used_flags_unset_bit(vq, VRING_USED_F_NO_NOTIFY);
M
Michael S. Tsirkin 已提交
212
    } else {
A
aliguori 已提交
213
        vring_used_flags_set_bit(vq, VRING_USED_F_NO_NOTIFY);
M
Michael S. Tsirkin 已提交
214
    }
215 216 217 218
    if (enable) {
        /* Expose avail event/used flags before caller checks the avail idx. */
        smp_mb();
    }
A
aliguori 已提交
219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236
}

int virtio_queue_ready(VirtQueue *vq)
{
    return vq->vring.avail != 0;
}

int virtio_queue_empty(VirtQueue *vq)
{
    return vring_avail_idx(vq) == vq->last_avail_idx;
}

void virtqueue_fill(VirtQueue *vq, const VirtQueueElement *elem,
                    unsigned int len, unsigned int idx)
{
    unsigned int offset;
    int i;

237 238
    trace_virtqueue_fill(vq, elem, len, idx);

A
aliguori 已提交
239 240 241 242
    offset = 0;
    for (i = 0; i < elem->in_num; i++) {
        size_t size = MIN(len - offset, elem->in_sg[i].iov_len);

243 244 245
        cpu_physical_memory_unmap(elem->in_sg[i].iov_base,
                                  elem->in_sg[i].iov_len,
                                  1, size);
A
aliguori 已提交
246

247
        offset += size;
A
aliguori 已提交
248 249
    }

250 251 252 253 254
    for (i = 0; i < elem->out_num; i++)
        cpu_physical_memory_unmap(elem->out_sg[i].iov_base,
                                  elem->out_sg[i].iov_len,
                                  0, elem->out_sg[i].iov_len);

A
aliguori 已提交
255 256 257 258 259 260 261 262 263
    idx = (idx + vring_used_idx(vq)) % vq->vring.num;

    /* Get a pointer to the next entry in the used ring. */
    vring_used_ring_id(vq, idx, elem->index);
    vring_used_ring_len(vq, idx, len);
}

void virtqueue_flush(VirtQueue *vq, unsigned int count)
{
M
Michael S. Tsirkin 已提交
264
    uint16_t old, new;
A
aliguori 已提交
265
    /* Make sure buffer is written before we update index. */
266
    smp_wmb();
267
    trace_virtqueue_flush(vq, count);
M
Michael S. Tsirkin 已提交
268 269 270
    old = vring_used_idx(vq);
    new = old + count;
    vring_used_idx_set(vq, new);
A
aliguori 已提交
271
    vq->inuse -= count;
M
Michael S. Tsirkin 已提交
272 273
    if (unlikely((int16_t)(new - vq->signalled_used) < (uint16_t)(new - old)))
        vq->signalled_used_valid = false;
A
aliguori 已提交
274 275 276 277 278 279 280 281 282 283 284 285 286 287
}

void virtqueue_push(VirtQueue *vq, const VirtQueueElement *elem,
                    unsigned int len)
{
    virtqueue_fill(vq, elem, len, 0);
    virtqueue_flush(vq, 1);
}

static int virtqueue_num_heads(VirtQueue *vq, unsigned int idx)
{
    uint16_t num_heads = vring_avail_idx(vq) - idx;

    /* Check it isn't doing very strange things with descriptor numbers. */
A
aliguori 已提交
288
    if (num_heads > vq->vring.num) {
289 290
        error_report("Guest moved used index from %u to %u",
                     idx, vring_avail_idx(vq));
A
aliguori 已提交
291 292
        exit(1);
    }
293 294 295 296 297
    /* On success, callers read a descriptor at vq->last_avail_idx.
     * Make sure descriptor read does not bypass avail index read. */
    if (num_heads) {
        smp_rmb();
    }
A
aliguori 已提交
298 299 300 301 302 303 304 305 306 307 308 309 310

    return num_heads;
}

static unsigned int virtqueue_get_head(VirtQueue *vq, unsigned int idx)
{
    unsigned int head;

    /* Grab the next descriptor number they're advertising, and increment
     * the index we've seen. */
    head = vring_avail_ring(vq, idx % vq->vring.num);

    /* If their number is silly, that's a fatal mistake. */
A
aliguori 已提交
311
    if (head >= vq->vring.num) {
312
        error_report("Guest says index %u is available", head);
A
aliguori 已提交
313 314
        exit(1);
    }
A
aliguori 已提交
315 316 317 318

    return head;
}

A
Avi Kivity 已提交
319
static unsigned virtqueue_next_desc(hwaddr desc_pa,
320
                                    unsigned int i, unsigned int max)
A
aliguori 已提交
321 322 323 324
{
    unsigned int next;

    /* If this descriptor says it doesn't chain, we're done. */
325 326
    if (!(vring_desc_flags(desc_pa, i) & VRING_DESC_F_NEXT))
        return max;
A
aliguori 已提交
327 328

    /* Check they're not leading us off end of descriptors. */
329
    next = vring_desc_next(desc_pa, i);
A
aliguori 已提交
330
    /* Make sure compiler knows to grab that: we don't want it changing! */
331
    smp_wmb();
A
aliguori 已提交
332

333
    if (next >= max) {
334
        error_report("Desc next is %u", next);
A
aliguori 已提交
335 336
        exit(1);
    }
A
aliguori 已提交
337 338 339 340

    return next;
}

341
void virtqueue_get_avail_bytes(VirtQueue *vq, unsigned int *in_bytes,
342 343
                               unsigned int *out_bytes,
                               unsigned max_in_bytes, unsigned max_out_bytes)
A
aliguori 已提交
344
{
345
    unsigned int idx;
346
    unsigned int total_bufs, in_total, out_total;
A
aliguori 已提交
347 348 349

    idx = vq->last_avail_idx;

350
    total_bufs = in_total = out_total = 0;
A
aliguori 已提交
351
    while (virtqueue_num_heads(vq, idx)) {
352
        unsigned int max, num_bufs, indirect = 0;
A
Avi Kivity 已提交
353
        hwaddr desc_pa;
A
aliguori 已提交
354 355
        int i;

356 357
        max = vq->vring.num;
        num_bufs = total_bufs;
A
aliguori 已提交
358
        i = virtqueue_get_head(vq, idx++);
359 360 361 362
        desc_pa = vq->vring.desc;

        if (vring_desc_flags(desc_pa, i) & VRING_DESC_F_INDIRECT) {
            if (vring_desc_len(desc_pa, i) % sizeof(VRingDesc)) {
363
                error_report("Invalid size for indirect buffer table");
364 365 366 367 368
                exit(1);
            }

            /* If we've got too many, that implies a descriptor loop. */
            if (num_bufs >= max) {
369
                error_report("Looped descriptor");
370 371 372 373 374 375 376 377 378 379
                exit(1);
            }

            /* loop over the indirect descriptor table */
            indirect = 1;
            max = vring_desc_len(desc_pa, i) / sizeof(VRingDesc);
            num_bufs = i = 0;
            desc_pa = vring_desc_addr(desc_pa, i);
        }

A
aliguori 已提交
380 381
        do {
            /* If we've got too many, that implies a descriptor loop. */
382
            if (++num_bufs > max) {
383
                error_report("Looped descriptor");
A
aliguori 已提交
384 385
                exit(1);
            }
A
aliguori 已提交
386

387
            if (vring_desc_flags(desc_pa, i) & VRING_DESC_F_WRITE) {
388
                in_total += vring_desc_len(desc_pa, i);
A
aliguori 已提交
389
            } else {
390
                out_total += vring_desc_len(desc_pa, i);
A
aliguori 已提交
391
            }
392 393 394
            if (in_total >= max_in_bytes && out_total >= max_out_bytes) {
                goto done;
            }
395
        } while ((i = virtqueue_next_desc(desc_pa, i, max)) != max);
396 397 398 399 400

        if (!indirect)
            total_bufs = num_bufs;
        else
            total_bufs++;
A
aliguori 已提交
401
    }
402
done:
403 404 405 406 407 408 409
    if (in_bytes) {
        *in_bytes = in_total;
    }
    if (out_bytes) {
        *out_bytes = out_total;
    }
}
A
aliguori 已提交
410

411 412 413 414 415
int virtqueue_avail_bytes(VirtQueue *vq, unsigned int in_bytes,
                          unsigned int out_bytes)
{
    unsigned int in_total, out_total;

416 417
    virtqueue_get_avail_bytes(vq, &in_total, &out_total, in_bytes, out_bytes);
    return in_bytes <= in_total && out_bytes <= out_total;
A
aliguori 已提交
418 419
}

A
Avi Kivity 已提交
420
void virtqueue_map_sg(struct iovec *sg, hwaddr *addr,
K
Kevin Wolf 已提交
421 422 423
    size_t num_sg, int is_write)
{
    unsigned int i;
A
Avi Kivity 已提交
424
    hwaddr len;
K
Kevin Wolf 已提交
425 426 427 428 429

    for (i = 0; i < num_sg; i++) {
        len = sg[i].iov_len;
        sg[i].iov_base = cpu_physical_memory_map(addr[i], &len, is_write);
        if (sg[i].iov_base == NULL || len != sg[i].iov_len) {
430
            error_report("virtio: trying to map MMIO memory");
K
Kevin Wolf 已提交
431 432 433 434 435
            exit(1);
        }
    }
}

A
aliguori 已提交
436 437
int virtqueue_pop(VirtQueue *vq, VirtQueueElement *elem)
{
438
    unsigned int i, head, max;
A
Avi Kivity 已提交
439
    hwaddr desc_pa = vq->vring.desc;
A
aliguori 已提交
440 441 442 443 444 445 446

    if (!virtqueue_num_heads(vq, vq->last_avail_idx))
        return 0;

    /* When we start there are none of either input nor output. */
    elem->out_num = elem->in_num = 0;

447 448
    max = vq->vring.num;

A
aliguori 已提交
449
    i = head = virtqueue_get_head(vq, vq->last_avail_idx++);
M
Michael S. Tsirkin 已提交
450 451 452
    if (vq->vdev->guest_features & (1 << VIRTIO_RING_F_EVENT_IDX)) {
        vring_avail_event(vq, vring_avail_idx(vq));
    }
453 454 455

    if (vring_desc_flags(desc_pa, i) & VRING_DESC_F_INDIRECT) {
        if (vring_desc_len(desc_pa, i) % sizeof(VRingDesc)) {
456
            error_report("Invalid size for indirect buffer table");
457 458 459 460 461 462 463 464 465
            exit(1);
        }

        /* loop over the indirect descriptor table */
        max = vring_desc_len(desc_pa, i) / sizeof(VRingDesc);
        desc_pa = vring_desc_addr(desc_pa, i);
        i = 0;
    }

K
Kevin Wolf 已提交
466
    /* Collect all the descriptors */
A
aliguori 已提交
467 468 469
    do {
        struct iovec *sg;

470
        if (vring_desc_flags(desc_pa, i) & VRING_DESC_F_WRITE) {
471 472 473 474
            if (elem->in_num >= ARRAY_SIZE(elem->in_sg)) {
                error_report("Too many write descriptors in indirect table");
                exit(1);
            }
475
            elem->in_addr[elem->in_num] = vring_desc_addr(desc_pa, i);
A
aliguori 已提交
476
            sg = &elem->in_sg[elem->in_num++];
K
Kevin Wolf 已提交
477
        } else {
478 479 480 481
            if (elem->out_num >= ARRAY_SIZE(elem->out_sg)) {
                error_report("Too many read descriptors in indirect table");
                exit(1);
            }
K
Kevin Wolf 已提交
482
            elem->out_addr[elem->out_num] = vring_desc_addr(desc_pa, i);
A
aliguori 已提交
483
            sg = &elem->out_sg[elem->out_num++];
K
Kevin Wolf 已提交
484
        }
A
aliguori 已提交
485

486
        sg->iov_len = vring_desc_len(desc_pa, i);
A
aliguori 已提交
487 488

        /* If we've got too many, that implies a descriptor loop. */
489
        if ((elem->in_num + elem->out_num) > max) {
490
            error_report("Looped descriptor");
A
aliguori 已提交
491 492
            exit(1);
        }
493
    } while ((i = virtqueue_next_desc(desc_pa, i, max)) != max);
A
aliguori 已提交
494

K
Kevin Wolf 已提交
495 496 497 498
    /* Now map what we have collected */
    virtqueue_map_sg(elem->in_sg, elem->in_addr, elem->in_num, 1);
    virtqueue_map_sg(elem->out_sg, elem->out_addr, elem->out_num, 0);

A
aliguori 已提交
499 500 501 502
    elem->index = head;

    vq->inuse++;

503
    trace_virtqueue_pop(vq, elem, elem->in_num, elem->out_num);
A
aliguori 已提交
504 505 506 507
    return elem->in_num + elem->out_num;
}

/* virtio device */
508 509
static void virtio_notify_vector(VirtIODevice *vdev, uint16_t vector)
{
K
KONRAD Frederic 已提交
510 511 512 513 514
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);

    if (k->notify) {
        k->notify(qbus->parent, vector);
515 516
    }
}
A
aliguori 已提交
517

P
Paul Brook 已提交
518
void virtio_update_irq(VirtIODevice *vdev)
A
aliguori 已提交
519
{
520
    virtio_notify_vector(vdev, VIRTIO_NO_VECTOR);
A
aliguori 已提交
521 522
}

523 524
void virtio_set_status(VirtIODevice *vdev, uint8_t val)
{
525
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
526 527
    trace_virtio_set_status(vdev, val);

528 529
    if (k->set_status) {
        k->set_status(vdev, val);
530 531 532 533
    }
    vdev->status = val;
}

P
Paul Brook 已提交
534
void virtio_reset(void *opaque)
A
aliguori 已提交
535 536
{
    VirtIODevice *vdev = opaque;
537
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
538 539
    int i;

540 541
    virtio_set_status(vdev, 0);

542 543 544
    if (k->reset) {
        k->reset(vdev);
    }
A
aliguori 已提交
545

546
    vdev->guest_features = 0;
A
aliguori 已提交
547 548 549
    vdev->queue_sel = 0;
    vdev->status = 0;
    vdev->isr = 0;
550 551
    vdev->config_vector = VIRTIO_NO_VECTOR;
    virtio_notify_vector(vdev, vdev->config_vector);
A
aliguori 已提交
552 553 554 555 556 557

    for(i = 0; i < VIRTIO_PCI_QUEUE_MAX; i++) {
        vdev->vq[i].vring.desc = 0;
        vdev->vq[i].vring.avail = 0;
        vdev->vq[i].vring.used = 0;
        vdev->vq[i].last_avail_idx = 0;
P
Paul Brook 已提交
558
        vdev->vq[i].pa = 0;
559
        vdev->vq[i].vector = VIRTIO_NO_VECTOR;
M
Michael S. Tsirkin 已提交
560 561 562
        vdev->vq[i].signalled_used = 0;
        vdev->vq[i].signalled_used_valid = false;
        vdev->vq[i].notification = true;
A
aliguori 已提交
563 564 565
    }
}

P
Paul Brook 已提交
566
uint32_t virtio_config_readb(VirtIODevice *vdev, uint32_t addr)
A
aliguori 已提交
567
{
568
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
569 570
    uint8_t val;

571
    k->get_config(vdev, vdev->config);
A
aliguori 已提交
572 573 574 575

    if (addr > (vdev->config_len - sizeof(val)))
        return (uint32_t)-1;

576
    val = ldub_p(vdev->config + addr);
A
aliguori 已提交
577 578 579
    return val;
}

P
Paul Brook 已提交
580
uint32_t virtio_config_readw(VirtIODevice *vdev, uint32_t addr)
A
aliguori 已提交
581
{
582
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
583 584
    uint16_t val;

585
    k->get_config(vdev, vdev->config);
A
aliguori 已提交
586 587 588 589

    if (addr > (vdev->config_len - sizeof(val)))
        return (uint32_t)-1;

590
    val = lduw_p(vdev->config + addr);
A
aliguori 已提交
591 592 593
    return val;
}

P
Paul Brook 已提交
594
uint32_t virtio_config_readl(VirtIODevice *vdev, uint32_t addr)
A
aliguori 已提交
595
{
596
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
597 598
    uint32_t val;

599
    k->get_config(vdev, vdev->config);
A
aliguori 已提交
600 601 602 603

    if (addr > (vdev->config_len - sizeof(val)))
        return (uint32_t)-1;

604
    val = ldl_p(vdev->config + addr);
A
aliguori 已提交
605 606 607
    return val;
}

P
Paul Brook 已提交
608
void virtio_config_writeb(VirtIODevice *vdev, uint32_t addr, uint32_t data)
A
aliguori 已提交
609
{
610
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
611 612 613 614 615
    uint8_t val = data;

    if (addr > (vdev->config_len - sizeof(val)))
        return;

616
    stb_p(vdev->config + addr, val);
A
aliguori 已提交
617

618 619 620
    if (k->set_config) {
        k->set_config(vdev, vdev->config);
    }
A
aliguori 已提交
621 622
}

P
Paul Brook 已提交
623
void virtio_config_writew(VirtIODevice *vdev, uint32_t addr, uint32_t data)
A
aliguori 已提交
624
{
625
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
626 627 628 629 630
    uint16_t val = data;

    if (addr > (vdev->config_len - sizeof(val)))
        return;

631
    stw_p(vdev->config + addr, val);
A
aliguori 已提交
632

633 634 635
    if (k->set_config) {
        k->set_config(vdev, vdev->config);
    }
A
aliguori 已提交
636 637
}

P
Paul Brook 已提交
638
void virtio_config_writel(VirtIODevice *vdev, uint32_t addr, uint32_t data)
A
aliguori 已提交
639
{
640
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
A
aliguori 已提交
641 642 643 644 645
    uint32_t val = data;

    if (addr > (vdev->config_len - sizeof(val)))
        return;

646
    stl_p(vdev->config + addr, val);
A
aliguori 已提交
647

648 649 650
    if (k->set_config) {
        k->set_config(vdev, vdev->config);
    }
A
aliguori 已提交
651 652
}

A
Avi Kivity 已提交
653
void virtio_queue_set_addr(VirtIODevice *vdev, int n, hwaddr addr)
A
aliguori 已提交
654
{
655 656
    vdev->vq[n].pa = addr;
    virtqueue_init(&vdev->vq[n]);
P
Paul Brook 已提交
657 658
}

A
Avi Kivity 已提交
659
hwaddr virtio_queue_get_addr(VirtIODevice *vdev, int n)
P
Paul Brook 已提交
660 661 662 663 664 665 666 667
{
    return vdev->vq[n].pa;
}

int virtio_queue_get_num(VirtIODevice *vdev, int n)
{
    return vdev->vq[n].vring.num;
}
A
aliguori 已提交
668

P
Paolo Bonzini 已提交
669 670 671 672 673 674 675
int virtio_queue_get_id(VirtQueue *vq)
{
    VirtIODevice *vdev = vq->vdev;
    assert(vq >= &vdev->vq[0] && vq < &vdev->vq[VIRTIO_PCI_QUEUE_MAX]);
    return vq - &vdev->vq[0];
}

676 677 678 679 680 681 682 683 684
void virtio_queue_notify_vq(VirtQueue *vq)
{
    if (vq->vring.desc) {
        VirtIODevice *vdev = vq->vdev;
        trace_virtio_queue_notify(vdev, vq - vdev->vq, vq);
        vq->handle_output(vdev, vq);
    }
}

P
Paul Brook 已提交
685 686
void virtio_queue_notify(VirtIODevice *vdev, int n)
{
687
    virtio_queue_notify_vq(&vdev->vq[n]);
A
aliguori 已提交
688 689
}

690 691 692 693 694 695 696 697 698 699 700 701
uint16_t virtio_queue_vector(VirtIODevice *vdev, int n)
{
    return n < VIRTIO_PCI_QUEUE_MAX ? vdev->vq[n].vector :
        VIRTIO_NO_VECTOR;
}

void virtio_queue_set_vector(VirtIODevice *vdev, int n, uint16_t vector)
{
    if (n < VIRTIO_PCI_QUEUE_MAX)
        vdev->vq[n].vector = vector;
}

A
aliguori 已提交
702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720
VirtQueue *virtio_add_queue(VirtIODevice *vdev, int queue_size,
                            void (*handle_output)(VirtIODevice *, VirtQueue *))
{
    int i;

    for (i = 0; i < VIRTIO_PCI_QUEUE_MAX; i++) {
        if (vdev->vq[i].vring.num == 0)
            break;
    }

    if (i == VIRTIO_PCI_QUEUE_MAX || queue_size > VIRTQUEUE_MAX_SIZE)
        abort();

    vdev->vq[i].vring.num = queue_size;
    vdev->vq[i].handle_output = handle_output;

    return &vdev->vq[i];
}

721 722 723 724 725 726 727 728 729
void virtio_del_queue(VirtIODevice *vdev, int n)
{
    if (n < 0 || n >= VIRTIO_PCI_QUEUE_MAX) {
        abort();
    }

    vdev->vq[n].vring.num = 0;
}

730 731
void virtio_irq(VirtQueue *vq)
{
732
    trace_virtio_irq(vq);
733 734 735 736
    vq->vdev->isr |= 0x01;
    virtio_notify_vector(vq->vdev, vq->vector);
}

M
Michael S. Tsirkin 已提交
737 738 739 740
/* Assuming a given event_idx value from the other size, if
 * we have just incremented index from old to new_idx,
 * should we trigger an event? */
static inline int vring_need_event(uint16_t event, uint16_t new, uint16_t old)
A
aliguori 已提交
741
{
M
Michael S. Tsirkin 已提交
742 743 744 745 746 747 748 749 750 751 752 753
	/* Note: Xen has similar logic for notification hold-off
	 * in include/xen/interface/io/ring.h with req_event and req_prod
	 * corresponding to event_idx + 1 and new respectively.
	 * Note also that req_event and req_prod in Xen start at 1,
	 * event indexes in virtio start at 0. */
	return (uint16_t)(new - event - 1) < (uint16_t)(new - old);
}

static bool vring_notify(VirtIODevice *vdev, VirtQueue *vq)
{
    uint16_t old, new;
    bool v;
754 755
    /* We need to expose used array entries before checking used event. */
    smp_mb();
756
    /* Always notify when queue is empty (when feature acknowledge) */
M
Michael S. Tsirkin 已提交
757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775
    if (((vdev->guest_features & (1 << VIRTIO_F_NOTIFY_ON_EMPTY)) &&
         !vq->inuse && vring_avail_idx(vq) == vq->last_avail_idx)) {
        return true;
    }

    if (!(vdev->guest_features & (1 << VIRTIO_RING_F_EVENT_IDX))) {
        return !(vring_avail_flags(vq) & VRING_AVAIL_F_NO_INTERRUPT);
    }

    v = vq->signalled_used_valid;
    vq->signalled_used_valid = true;
    old = vq->signalled_used;
    new = vq->signalled_used = vring_used_idx(vq);
    return !v || vring_need_event(vring_used_event(vq), new, old);
}

void virtio_notify(VirtIODevice *vdev, VirtQueue *vq)
{
    if (!vring_notify(vdev, vq)) {
A
aliguori 已提交
776
        return;
M
Michael S. Tsirkin 已提交
777
    }
A
aliguori 已提交
778

779
    trace_virtio_notify(vdev, vq);
A
aliguori 已提交
780
    vdev->isr |= 0x01;
781
    virtio_notify_vector(vdev, vq->vector);
A
aliguori 已提交
782 783 784 785
}

void virtio_notify_config(VirtIODevice *vdev)
{
786 787 788
    if (!(vdev->status & VIRTIO_CONFIG_S_DRIVER_OK))
        return;

A
aliguori 已提交
789
    vdev->isr |= 0x03;
790
    virtio_notify_vector(vdev, vdev->config_vector);
A
aliguori 已提交
791 792 793 794
}

void virtio_save(VirtIODevice *vdev, QEMUFile *f)
{
K
KONRAD Frederic 已提交
795 796
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);
A
aliguori 已提交
797 798
    int i;

K
KONRAD Frederic 已提交
799 800 801
    if (k->save_config) {
        k->save_config(qbus->parent, f);
    }
A
aliguori 已提交
802 803 804 805

    qemu_put_8s(f, &vdev->status);
    qemu_put_8s(f, &vdev->isr);
    qemu_put_be16s(f, &vdev->queue_sel);
806
    qemu_put_be32s(f, &vdev->guest_features);
A
aliguori 已提交
807 808 809 810 811 812 813 814 815 816 817 818 819 820 821
    qemu_put_be32(f, vdev->config_len);
    qemu_put_buffer(f, vdev->config, vdev->config_len);

    for (i = 0; i < VIRTIO_PCI_QUEUE_MAX; i++) {
        if (vdev->vq[i].vring.num == 0)
            break;
    }

    qemu_put_be32(f, i);

    for (i = 0; i < VIRTIO_PCI_QUEUE_MAX; i++) {
        if (vdev->vq[i].vring.num == 0)
            break;

        qemu_put_be32(f, vdev->vq[i].vring.num);
P
Paul Brook 已提交
822
        qemu_put_be64(f, vdev->vq[i].pa);
A
aliguori 已提交
823
        qemu_put_be16s(f, &vdev->vq[i].last_avail_idx);
K
KONRAD Frederic 已提交
824 825 826
        if (k->save_queue) {
            k->save_queue(qbus->parent, i, f);
        }
A
aliguori 已提交
827 828 829
    }
}

830 831
int virtio_set_features(VirtIODevice *vdev, uint32_t val)
{
K
KONRAD Frederic 已提交
832 833
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *vbusk = VIRTIO_BUS_GET_CLASS(qbus);
834
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(vdev);
K
KONRAD Frederic 已提交
835
    uint32_t supported_features = vbusk->get_features(qbus->parent);
836 837 838
    bool bad = (val & ~supported_features) != 0;

    val &= supported_features;
839 840
    if (k->set_features) {
        k->set_features(vdev, val);
841 842 843 844 845
    }
    vdev->guest_features = val;
    return bad ? -1 : 0;
}

846
int virtio_load(VirtIODevice *vdev, QEMUFile *f)
A
aliguori 已提交
847
{
848
    int num, i, ret;
849
    uint32_t features;
850
    uint32_t supported_features;
K
KONRAD Frederic 已提交
851 852
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);
A
aliguori 已提交
853

K
KONRAD Frederic 已提交
854 855
    if (k->load_config) {
        ret = k->load_config(qbus->parent, f);
856 857 858
        if (ret)
            return ret;
    }
A
aliguori 已提交
859 860 861 862

    qemu_get_8s(f, &vdev->status);
    qemu_get_8s(f, &vdev->isr);
    qemu_get_be16s(f, &vdev->queue_sel);
863
    qemu_get_be32s(f, &features);
864 865

    if (virtio_set_features(vdev, features) < 0) {
K
KONRAD Frederic 已提交
866
        supported_features = k->get_features(qbus->parent);
867 868
        error_report("Features 0x%x unsupported. Allowed features: 0x%x",
                     features, supported_features);
869 870
        return -1;
    }
A
aliguori 已提交
871 872 873 874 875 876 877
    vdev->config_len = qemu_get_be32(f);
    qemu_get_buffer(f, vdev->config, vdev->config_len);

    num = qemu_get_be32(f);

    for (i = 0; i < num; i++) {
        vdev->vq[i].vring.num = qemu_get_be32(f);
P
Paul Brook 已提交
878
        vdev->vq[i].pa = qemu_get_be64(f);
A
aliguori 已提交
879
        qemu_get_be16s(f, &vdev->vq[i].last_avail_idx);
M
Michael S. Tsirkin 已提交
880 881
        vdev->vq[i].signalled_used_valid = false;
        vdev->vq[i].notification = true;
A
aliguori 已提交
882

P
Paul Brook 已提交
883
        if (vdev->vq[i].pa) {
M
Michael S. Tsirkin 已提交
884
            uint16_t nheads;
P
Paul Brook 已提交
885
            virtqueue_init(&vdev->vq[i]);
M
Michael S. Tsirkin 已提交
886 887 888 889
            nheads = vring_avail_idx(&vdev->vq[i]) - vdev->vq[i].last_avail_idx;
            /* Check it isn't doing very strange things with descriptor numbers. */
            if (nheads > vdev->vq[i].vring.num) {
                error_report("VQ %d size 0x%x Guest index 0x%x "
890
                             "inconsistent with Host index 0x%x: delta 0x%x",
M
Michael S. Tsirkin 已提交
891 892 893 894 895 896 897
                             i, vdev->vq[i].vring.num,
                             vring_avail_idx(&vdev->vq[i]),
                             vdev->vq[i].last_avail_idx, nheads);
                return -1;
            }
        } else if (vdev->vq[i].last_avail_idx) {
            error_report("VQ %d address 0x0 "
898
                         "inconsistent with Host index 0x%x",
M
Michael S. Tsirkin 已提交
899 900
                         i, vdev->vq[i].last_avail_idx);
                return -1;
901
	}
K
KONRAD Frederic 已提交
902 903
        if (k->load_queue) {
            ret = k->load_queue(qbus->parent, i, f);
904 905
            if (ret)
                return ret;
906
        }
A
aliguori 已提交
907 908
    }

909
    virtio_notify_vector(vdev, VIRTIO_NO_VECTOR);
910
    return 0;
A
aliguori 已提交
911 912
}

913
void virtio_cleanup(VirtIODevice *vdev)
914
{
915
    qemu_del_vm_change_state_handler(vdev->vmstate);
916
    g_free(vdev->config);
917
    g_free(vdev->vq);
918 919
}

920
static void virtio_vmstate_change(void *opaque, int running, RunState state)
921 922
{
    VirtIODevice *vdev = opaque;
K
KONRAD Frederic 已提交
923 924
    BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
    VirtioBusClass *k = VIRTIO_BUS_GET_CLASS(qbus);
925 926 927 928 929 930 931
    bool backend_run = running && (vdev->status & VIRTIO_CONFIG_S_DRIVER_OK);
    vdev->vm_running = running;

    if (backend_run) {
        virtio_set_status(vdev, vdev->status);
    }

K
KONRAD Frederic 已提交
932 933
    if (k->vmstate_change) {
        k->vmstate_change(qbus->parent, backend_run);
934 935 936 937 938 939 940
    }

    if (!backend_run) {
        virtio_set_status(vdev, vdev->status);
    }
}

941 942
void virtio_init(VirtIODevice *vdev, const char *name,
                 uint16_t device_id, size_t config_size)
A
aliguori 已提交
943
{
944
    int i;
P
Paul Brook 已提交
945
    vdev->device_id = device_id;
A
aliguori 已提交
946 947 948
    vdev->status = 0;
    vdev->isr = 0;
    vdev->queue_sel = 0;
949
    vdev->config_vector = VIRTIO_NO_VECTOR;
950
    vdev->vq = g_malloc0(sizeof(VirtQueue) * VIRTIO_PCI_QUEUE_MAX);
951
    vdev->vm_running = runstate_is_running();
952
    for (i = 0; i < VIRTIO_PCI_QUEUE_MAX; i++) {
953
        vdev->vq[i].vector = VIRTIO_NO_VECTOR;
954
        vdev->vq[i].vdev = vdev;
955
        vdev->vq[i].queue_index = i;
956
    }
A
aliguori 已提交
957 958 959

    vdev->name = name;
    vdev->config_len = config_size;
960
    if (vdev->config_len) {
961
        vdev->config = g_malloc0(config_size);
962
    } else {
A
aliguori 已提交
963
        vdev->config = NULL;
964 965 966 967
    }
    vdev->vmstate = qemu_add_vm_change_state_handler(virtio_vmstate_change,
                                                     vdev);
}
A
aliguori 已提交
968

A
Avi Kivity 已提交
969
hwaddr virtio_queue_get_desc_addr(VirtIODevice *vdev, int n)
970 971 972 973
{
    return vdev->vq[n].vring.desc;
}

A
Avi Kivity 已提交
974
hwaddr virtio_queue_get_avail_addr(VirtIODevice *vdev, int n)
975 976 977 978
{
    return vdev->vq[n].vring.avail;
}

A
Avi Kivity 已提交
979
hwaddr virtio_queue_get_used_addr(VirtIODevice *vdev, int n)
980 981 982 983
{
    return vdev->vq[n].vring.used;
}

A
Avi Kivity 已提交
984
hwaddr virtio_queue_get_ring_addr(VirtIODevice *vdev, int n)
985 986 987 988
{
    return vdev->vq[n].vring.desc;
}

A
Avi Kivity 已提交
989
hwaddr virtio_queue_get_desc_size(VirtIODevice *vdev, int n)
990 991 992 993
{
    return sizeof(VRingDesc) * vdev->vq[n].vring.num;
}

A
Avi Kivity 已提交
994
hwaddr virtio_queue_get_avail_size(VirtIODevice *vdev, int n)
995 996
{
    return offsetof(VRingAvail, ring) +
997
        sizeof(uint64_t) * vdev->vq[n].vring.num;
998 999
}

A
Avi Kivity 已提交
1000
hwaddr virtio_queue_get_used_size(VirtIODevice *vdev, int n)
1001 1002 1003 1004 1005
{
    return offsetof(VRingUsed, ring) +
        sizeof(VRingUsedElem) * vdev->vq[n].vring.num;
}

A
Avi Kivity 已提交
1006
hwaddr virtio_queue_get_ring_size(VirtIODevice *vdev, int n)
1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026
{
    return vdev->vq[n].vring.used - vdev->vq[n].vring.desc +
	    virtio_queue_get_used_size(vdev, n);
}

uint16_t virtio_queue_get_last_avail_idx(VirtIODevice *vdev, int n)
{
    return vdev->vq[n].last_avail_idx;
}

void virtio_queue_set_last_avail_idx(VirtIODevice *vdev, int n, uint16_t idx)
{
    vdev->vq[n].last_avail_idx = idx;
}

VirtQueue *virtio_get_queue(VirtIODevice *vdev, int n)
{
    return vdev->vq + n;
}

1027 1028 1029 1030 1031
uint16_t virtio_get_queue_index(VirtQueue *vq)
{
    return vq->queue_index;
}

1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055
static void virtio_queue_guest_notifier_read(EventNotifier *n)
{
    VirtQueue *vq = container_of(n, VirtQueue, guest_notifier);
    if (event_notifier_test_and_clear(n)) {
        virtio_irq(vq);
    }
}

void virtio_queue_set_guest_notifier_fd_handler(VirtQueue *vq, bool assign,
                                                bool with_irqfd)
{
    if (assign && !with_irqfd) {
        event_notifier_set_handler(&vq->guest_notifier,
                                   virtio_queue_guest_notifier_read);
    } else {
        event_notifier_set_handler(&vq->guest_notifier, NULL);
    }
    if (!assign) {
        /* Test and clear notifier before closing it,
         * in case poll callback didn't have time to run. */
        virtio_queue_guest_notifier_read(&vq->guest_notifier);
    }
}

1056 1057 1058 1059
EventNotifier *virtio_queue_get_guest_notifier(VirtQueue *vq)
{
    return &vq->guest_notifier;
}
1060 1061 1062 1063 1064 1065 1066 1067 1068

static void virtio_queue_host_notifier_read(EventNotifier *n)
{
    VirtQueue *vq = container_of(n, VirtQueue, host_notifier);
    if (event_notifier_test_and_clear(n)) {
        virtio_queue_notify_vq(vq);
    }
}

P
Paolo Bonzini 已提交
1069 1070
void virtio_queue_set_host_notifier_fd_handler(VirtQueue *vq, bool assign,
                                               bool set_handler)
1071
{
P
Paolo Bonzini 已提交
1072
    if (assign && set_handler) {
1073 1074 1075 1076
        event_notifier_set_handler(&vq->host_notifier,
                                   virtio_queue_host_notifier_read);
    } else {
        event_notifier_set_handler(&vq->host_notifier, NULL);
P
Paolo Bonzini 已提交
1077 1078
    }
    if (!assign) {
1079 1080 1081 1082 1083 1084
        /* Test and clear notifier before after disabling event,
         * in case poll callback didn't have time to run. */
        virtio_queue_host_notifier_read(&vq->host_notifier);
    }
}

1085 1086 1087 1088
EventNotifier *virtio_queue_get_host_notifier(VirtQueue *vq)
{
    return &vq->host_notifier;
}
1089

1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101
void virtio_device_set_child_bus_name(VirtIODevice *vdev, char *bus_name)
{
    if (vdev->bus_name) {
        g_free(vdev->bus_name);
        vdev->bus_name = NULL;
    }

    if (bus_name) {
        vdev->bus_name = g_strdup(bus_name);
    }
}

1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113
static int virtio_device_init(DeviceState *qdev)
{
    VirtIODevice *vdev = VIRTIO_DEVICE(qdev);
    VirtioDeviceClass *k = VIRTIO_DEVICE_GET_CLASS(qdev);
    assert(k->init != NULL);
    if (k->init(vdev) < 0) {
        return -1;
    }
    virtio_bus_plug_device(vdev);
    return 0;
}

1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124
static int virtio_device_exit(DeviceState *qdev)
{
    VirtIODevice *vdev = VIRTIO_DEVICE(qdev);

    if (vdev->bus_name) {
        g_free(vdev->bus_name);
        vdev->bus_name = NULL;
    }
    return 0;
}

1125 1126 1127 1128 1129
static void virtio_device_class_init(ObjectClass *klass, void *data)
{
    /* Set the default value here. */
    DeviceClass *dc = DEVICE_CLASS(klass);
    dc->init = virtio_device_init;
1130
    dc->exit = virtio_device_exit;
1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148
    dc->bus_type = TYPE_VIRTIO_BUS;
}

static const TypeInfo virtio_device_info = {
    .name = TYPE_VIRTIO_DEVICE,
    .parent = TYPE_DEVICE,
    .instance_size = sizeof(VirtIODevice),
    .class_init = virtio_device_class_init,
    .abstract = true,
    .class_size = sizeof(VirtioDeviceClass),
};

static void virtio_register_types(void)
{
    type_register_static(&virtio_device_info);
}

type_init(virtio_register_types)