exec.c 121.0 KB
Newer Older
B
bellard 已提交
1
/*
B
bellard 已提交
2
 *  virtual page mapping and translated block handling
3
 *
B
bellard 已提交
4 5 6 7 8 9 10 11 12 13 14 15 16
 *  Copyright (c) 2003 Fabrice Bellard
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
17
 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
B
bellard 已提交
18
 */
B
bellard 已提交
19
#include "config.h"
B
bellard 已提交
20 21 22
#ifdef _WIN32
#include <windows.h>
#else
B
bellard 已提交
23
#include <sys/types.h>
B
bellard 已提交
24 25
#include <sys/mman.h>
#endif
B
bellard 已提交
26

27
#include "qemu-common.h"
B
bellard 已提交
28
#include "cpu.h"
B
bellard 已提交
29
#include "tcg.h"
30
#include "hw/hw.h"
31
#include "hw/qdev.h"
A
aliguori 已提交
32
#include "osdep.h"
A
aliguori 已提交
33
#include "kvm.h"
J
Jun Nakajima 已提交
34
#include "hw/xen.h"
B
Blue Swirl 已提交
35
#include "qemu-timer.h"
A
Avi Kivity 已提交
36 37
#include "memory.h"
#include "exec-memory.h"
38 39
#if defined(CONFIG_USER_ONLY)
#include <qemu.h>
40 41 42 43 44 45 46 47 48 49 50 51 52 53 54
#if defined(__FreeBSD__) || defined(__FreeBSD_kernel__)
#include <sys/param.h>
#if __FreeBSD_version >= 700104
#define HAVE_KINFO_GETVMMAP
#define sigqueue sigqueue_freebsd  /* avoid redefinition */
#include <sys/time.h>
#include <sys/proc.h>
#include <machine/profile.h>
#define _KERNEL
#include <sys/user.h>
#undef _KERNEL
#undef sigqueue
#include <libutil.h>
#endif
#endif
J
Jun Nakajima 已提交
55 56
#else /* !CONFIG_USER_ONLY */
#include "xen-mapcache.h"
57
#include "trace.h"
58
#endif
B
bellard 已提交
59

60 61
#include "cputlb.h"

A
Avi Kivity 已提交
62
#include "memory-internal.h"
63

B
bellard 已提交
64
//#define DEBUG_TB_INVALIDATE
B
bellard 已提交
65
//#define DEBUG_FLUSH
P
pbrook 已提交
66
//#define DEBUG_UNASSIGNED
B
bellard 已提交
67 68

/* make various TB consistency checks */
69
//#define DEBUG_TB_CHECK
B
bellard 已提交
70

T
ths 已提交
71
//#define DEBUG_IOPORT
72
//#define DEBUG_SUBPAGE
T
ths 已提交
73

74 75 76 77 78
#if !defined(CONFIG_USER_ONLY)
/* TB consistency checks only implemented for usermode emulation.  */
#undef DEBUG_TB_CHECK
#endif

79 80
#define SMC_BITMAP_USE_THRESHOLD 10

B
blueswir1 已提交
81
static TranslationBlock *tbs;
82
static int code_gen_max_blocks;
83
TranslationBlock *tb_phys_hash[CODE_GEN_PHYS_HASH_SIZE];
B
blueswir1 已提交
84
static int nb_tbs;
B
bellard 已提交
85
/* any access to the tbs or the page table must use this lock */
A
Anthony Liguori 已提交
86
spinlock_t tb_lock = SPIN_LOCK_UNLOCKED;
B
bellard 已提交
87

88
uint8_t *code_gen_prologue;
B
blueswir1 已提交
89
static uint8_t *code_gen_buffer;
90
static size_t code_gen_buffer_size;
91
/* threshold to flush the translated code buffer */
92
static size_t code_gen_buffer_max_size;
93
static uint8_t *code_gen_ptr;
B
bellard 已提交
94

95
#if !defined(CONFIG_USER_ONLY)
96
int phys_ram_fd;
A
aliguori 已提交
97
static int in_migration;
P
pbrook 已提交
98

P
Paolo Bonzini 已提交
99
RAMList ram_list = { .blocks = QLIST_HEAD_INITIALIZER(ram_list.blocks) };
A
Avi Kivity 已提交
100 101

static MemoryRegion *system_memory;
102
static MemoryRegion *system_io;
A
Avi Kivity 已提交
103

104 105
AddressSpace address_space_io;
AddressSpace address_space_memory;
106

107
MemoryRegion io_mem_ram, io_mem_rom, io_mem_unassigned, io_mem_notdirty;
108
static MemoryRegion io_mem_subpage_ram;
109

110
#endif
111

112
CPUArchState *first_cpu;
B
bellard 已提交
113 114
/* current CPU in the current thread. It is only valid inside
   cpu_exec() */
115
DEFINE_TLS(CPUArchState *,cpu_single_env);
P
pbrook 已提交
116
/* 0 = Do not count executed instructions.
T
ths 已提交
117
   1 = Precise instruction counting.
P
pbrook 已提交
118 119
   2 = Adaptive rate instruction counting.  */
int use_icount = 0;
B
bellard 已提交
120

B
bellard 已提交
121
typedef struct PageDesc {
B
bellard 已提交
122
    /* list of TBs intersecting this ram page */
B
bellard 已提交
123
    TranslationBlock *first_tb;
124 125 126 127 128 129 130
    /* in order to optimize self modifying code, we count the number
       of lookups we do to a given page to use a bitmap */
    unsigned int code_write_count;
    uint8_t *code_bitmap;
#if defined(CONFIG_USER_ONLY)
    unsigned long flags;
#endif
B
bellard 已提交
131 132
} PageDesc;

P
Paul Brook 已提交
133
/* In system mode we want L1_MAP to be based on ram offsets,
134 135
   while in user mode we want it to be based on virtual addresses.  */
#if !defined(CONFIG_USER_ONLY)
P
Paul Brook 已提交
136 137 138
#if HOST_LONG_BITS < TARGET_PHYS_ADDR_SPACE_BITS
# define L1_MAP_ADDR_SPACE_BITS  HOST_LONG_BITS
#else
139
# define L1_MAP_ADDR_SPACE_BITS  TARGET_PHYS_ADDR_SPACE_BITS
P
Paul Brook 已提交
140
#endif
141
#else
142
# define L1_MAP_ADDR_SPACE_BITS  TARGET_VIRT_ADDR_SPACE_BITS
143
#endif
B
bellard 已提交
144

145 146
/* Size of the L2 (and L3, etc) page tables.  */
#define L2_BITS 10
B
bellard 已提交
147 148
#define L2_SIZE (1 << L2_BITS)

149 150 151
#define P_L2_LEVELS \
    (((TARGET_PHYS_ADDR_SPACE_BITS - TARGET_PAGE_BITS - 1) / L2_BITS) + 1)

152 153 154 155 156 157 158 159 160 161 162 163 164 165
/* The bits remaining after N lower levels of page tables.  */
#define V_L1_BITS_REM \
    ((L1_MAP_ADDR_SPACE_BITS - TARGET_PAGE_BITS) % L2_BITS)

#if V_L1_BITS_REM < 4
#define V_L1_BITS  (V_L1_BITS_REM + L2_BITS)
#else
#define V_L1_BITS  V_L1_BITS_REM
#endif

#define V_L1_SIZE  ((target_ulong)1 << V_L1_BITS)

#define V_L1_SHIFT (L1_MAP_ADDR_SPACE_BITS - TARGET_PAGE_BITS - V_L1_BITS)

166 167 168
uintptr_t qemu_real_host_page_size;
uintptr_t qemu_host_page_size;
uintptr_t qemu_host_page_mask;
B
bellard 已提交
169

170 171 172
/* This is a multi-level map on the virtual address space.
   The bottom level has pointers to PageDesc.  */
static void *l1_map[V_L1_SIZE];
B
bellard 已提交
173

174
#if !defined(CONFIG_USER_ONLY)
175

176 177 178
static MemoryRegionSection *phys_sections;
static unsigned phys_sections_nb, phys_sections_nb_alloc;
static uint16_t phys_section_unassigned;
179 180 181
static uint16_t phys_section_notdirty;
static uint16_t phys_section_rom;
static uint16_t phys_section_watch;
182

183 184 185 186
/* Simple allocator for PhysPageEntry nodes */
static PhysPageEntry (*phys_map_nodes)[L2_SIZE];
static unsigned phys_map_nodes_nb, phys_map_nodes_nb_alloc;

187
#define PHYS_MAP_NODE_NIL (((uint16_t)~0) >> 1)
188

189
static void io_mem_init(void);
A
Avi Kivity 已提交
190
static void memory_map_init(void);
191

192
static MemoryRegion io_mem_watch;
193
#endif
194

B
bellard 已提交
195 196 197 198
/* statistics */
static int tb_flush_count;
static int tb_phys_invalidate_count;

199
#ifdef _WIN32
200
static inline void map_exec(void *addr, long size)
201 202 203 204 205 206 207
{
    DWORD old_protect;
    VirtualProtect(addr, size,
                   PAGE_EXECUTE_READWRITE, &old_protect);
    
}
#else
208
static inline void map_exec(void *addr, long size)
209
{
210
    unsigned long start, end, page_size;
211
    
212
    page_size = getpagesize();
213
    start = (unsigned long)addr;
214
    start &= ~(page_size - 1);
215 216
    
    end = (unsigned long)addr + size;
217 218
    end += page_size - 1;
    end &= ~(page_size - 1);
219 220 221 222 223 224
    
    mprotect((void *)start, end - start,
             PROT_READ | PROT_WRITE | PROT_EXEC);
}
#endif

B
bellard 已提交
225
static void page_init(void)
B
bellard 已提交
226
{
227
    /* NOTE: we can always suppose that qemu_host_page_size >=
B
bellard 已提交
228
       TARGET_PAGE_SIZE */
229 230 231 232 233 234 235 236 237 238
#ifdef _WIN32
    {
        SYSTEM_INFO system_info;

        GetSystemInfo(&system_info);
        qemu_real_host_page_size = system_info.dwPageSize;
    }
#else
    qemu_real_host_page_size = getpagesize();
#endif
239 240 241 242 243
    if (qemu_host_page_size == 0)
        qemu_host_page_size = qemu_real_host_page_size;
    if (qemu_host_page_size < TARGET_PAGE_SIZE)
        qemu_host_page_size = TARGET_PAGE_SIZE;
    qemu_host_page_mask = ~(qemu_host_page_size - 1);
244

P
Paul Brook 已提交
245
#if defined(CONFIG_BSD) && defined(CONFIG_USER_ONLY)
246
    {
247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263
#ifdef HAVE_KINFO_GETVMMAP
        struct kinfo_vmentry *freep;
        int i, cnt;

        freep = kinfo_getvmmap(getpid(), &cnt);
        if (freep) {
            mmap_lock();
            for (i = 0; i < cnt; i++) {
                unsigned long startaddr, endaddr;

                startaddr = freep[i].kve_start;
                endaddr = freep[i].kve_end;
                if (h2g_valid(startaddr)) {
                    startaddr = h2g(startaddr) & TARGET_PAGE_MASK;

                    if (h2g_valid(endaddr)) {
                        endaddr = h2g(endaddr);
264
                        page_set_flags(startaddr, endaddr, PAGE_RESERVED);
265 266 267
                    } else {
#if TARGET_ABI_BITS <= L1_MAP_ADDR_SPACE_BITS
                        endaddr = ~0ul;
268
                        page_set_flags(startaddr, endaddr, PAGE_RESERVED);
269 270 271 272 273 274 275 276
#endif
                    }
                }
            }
            free(freep);
            mmap_unlock();
        }
#else
277 278
        FILE *f;

P
pbrook 已提交
279
        last_brk = (unsigned long)sbrk(0);
280

281
        f = fopen("/compat/linux/proc/self/maps", "r");
282
        if (f) {
283 284
            mmap_lock();

285
            do {
286 287 288 289 290 291 292 293 294 295 296 297 298 299
                unsigned long startaddr, endaddr;
                int n;

                n = fscanf (f, "%lx-%lx %*[^\n]\n", &startaddr, &endaddr);

                if (n == 2 && h2g_valid(startaddr)) {
                    startaddr = h2g(startaddr) & TARGET_PAGE_MASK;

                    if (h2g_valid(endaddr)) {
                        endaddr = h2g(endaddr);
                    } else {
                        endaddr = ~0ul;
                    }
                    page_set_flags(startaddr, endaddr, PAGE_RESERVED);
300 301
                }
            } while (!feof(f));
302

303
            fclose(f);
304
            mmap_unlock();
305
        }
306
#endif
307 308
    }
#endif
B
bellard 已提交
309 310
}

P
Paul Brook 已提交
311
static PageDesc *page_find_alloc(tb_page_addr_t index, int alloc)
B
bellard 已提交
312
{
P
Paul Brook 已提交
313 314 315 316
    PageDesc *pd;
    void **lp;
    int i;

317
#if defined(CONFIG_USER_ONLY)
318
    /* We can't use g_malloc because it may recurse into a locked mutex. */
319 320 321 322 323 324 325
# define ALLOC(P, SIZE)                                 \
    do {                                                \
        P = mmap(NULL, SIZE, PROT_READ | PROT_WRITE,    \
                 MAP_PRIVATE | MAP_ANONYMOUS, -1, 0);   \
    } while (0)
#else
# define ALLOC(P, SIZE) \
326
    do { P = g_malloc0(SIZE); } while (0)
327
#endif
328

329 330 331 332 333 334 335 336 337 338 339 340 341
    /* Level 1.  Always allocated.  */
    lp = l1_map + ((index >> V_L1_SHIFT) & (V_L1_SIZE - 1));

    /* Level 2..N-1.  */
    for (i = V_L1_SHIFT / L2_BITS - 1; i > 0; i--) {
        void **p = *lp;

        if (p == NULL) {
            if (!alloc) {
                return NULL;
            }
            ALLOC(p, sizeof(void *) * L2_SIZE);
            *lp = p;
342
        }
343 344 345 346 347 348 349 350 351 352 353

        lp = p + ((index >> (i * L2_BITS)) & (L2_SIZE - 1));
    }

    pd = *lp;
    if (pd == NULL) {
        if (!alloc) {
            return NULL;
        }
        ALLOC(pd, sizeof(PageDesc) * L2_SIZE);
        *lp = pd;
B
bellard 已提交
354
    }
355 356 357 358

#undef ALLOC

    return pd + (index & (L2_SIZE - 1));
B
bellard 已提交
359 360
}

P
Paul Brook 已提交
361
static inline PageDesc *page_find(tb_page_addr_t index)
B
bellard 已提交
362
{
363
    return page_find_alloc(index, 0);
B
bellard 已提交
364 365
}

366
#if !defined(CONFIG_USER_ONLY)
367

368
static void phys_map_node_reserve(unsigned nodes)
369
{
370
    if (phys_map_nodes_nb + nodes > phys_map_nodes_nb_alloc) {
371 372
        typedef PhysPageEntry Node[L2_SIZE];
        phys_map_nodes_nb_alloc = MAX(phys_map_nodes_nb_alloc * 2, 16);
373 374
        phys_map_nodes_nb_alloc = MAX(phys_map_nodes_nb_alloc,
                                      phys_map_nodes_nb + nodes);
375 376 377
        phys_map_nodes = g_renew(Node, phys_map_nodes,
                                 phys_map_nodes_nb_alloc);
    }
378 379 380 381 382 383 384 385 386 387
}

static uint16_t phys_map_node_alloc(void)
{
    unsigned i;
    uint16_t ret;

    ret = phys_map_nodes_nb++;
    assert(ret != PHYS_MAP_NODE_NIL);
    assert(ret != phys_map_nodes_nb_alloc);
388
    for (i = 0; i < L2_SIZE; ++i) {
389
        phys_map_nodes[ret][i].is_leaf = 0;
390
        phys_map_nodes[ret][i].ptr = PHYS_MAP_NODE_NIL;
391
    }
392
    return ret;
393 394 395 396 397 398 399
}

static void phys_map_nodes_reset(void)
{
    phys_map_nodes_nb = 0;
}

B
bellard 已提交
400

A
Avi Kivity 已提交
401 402
static void phys_page_set_level(PhysPageEntry *lp, hwaddr *index,
                                hwaddr *nb, uint16_t leaf,
403
                                int level)
404 405 406
{
    PhysPageEntry *p;
    int i;
A
Avi Kivity 已提交
407
    hwaddr step = (hwaddr)1 << (level * L2_BITS);
408

409
    if (!lp->is_leaf && lp->ptr == PHYS_MAP_NODE_NIL) {
410 411
        lp->ptr = phys_map_node_alloc();
        p = phys_map_nodes[lp->ptr];
412 413
        if (level == 0) {
            for (i = 0; i < L2_SIZE; i++) {
414
                p[i].is_leaf = 1;
415
                p[i].ptr = phys_section_unassigned;
416
            }
P
pbrook 已提交
417
        }
418
    } else {
419
        p = phys_map_nodes[lp->ptr];
B
bellard 已提交
420
    }
421
    lp = &p[(*index >> (level * L2_BITS)) & (L2_SIZE - 1)];
422

423
    while (*nb && lp < &p[L2_SIZE]) {
424 425
        if ((*index & (step - 1)) == 0 && *nb >= step) {
            lp->is_leaf = true;
426
            lp->ptr = leaf;
427 428
            *index += step;
            *nb -= step;
429 430 431 432
        } else {
            phys_page_set_level(lp, index, nb, leaf, level - 1);
        }
        ++lp;
433 434 435
    }
}

A
Avi Kivity 已提交
436
static void phys_page_set(AddressSpaceDispatch *d,
A
Avi Kivity 已提交
437
                          hwaddr index, hwaddr nb,
438
                          uint16_t leaf)
439
{
440
    /* Wildly overreserve - it doesn't matter much. */
441
    phys_map_node_reserve(3 * P_L2_LEVELS);
442

A
Avi Kivity 已提交
443
    phys_page_set_level(&d->phys_map, &index, &nb, leaf, P_L2_LEVELS - 1);
B
bellard 已提交
444 445
}

A
Avi Kivity 已提交
446
MemoryRegionSection *phys_page_find(AddressSpaceDispatch *d, hwaddr index)
B
bellard 已提交
447
{
A
Avi Kivity 已提交
448
    PhysPageEntry lp = d->phys_map;
449 450 451
    PhysPageEntry *p;
    int i;
    uint16_t s_index = phys_section_unassigned;
452

453
    for (i = P_L2_LEVELS - 1; i >= 0 && !lp.is_leaf; i--) {
454
        if (lp.ptr == PHYS_MAP_NODE_NIL) {
455 456
            goto not_found;
        }
457
        p = phys_map_nodes[lp.ptr];
458
        lp = p[(index >> (i * L2_BITS)) & (L2_SIZE - 1)];
459
    }
460

461
    s_index = lp.ptr;
462
not_found:
463 464 465
    return &phys_sections[s_index];
}

B
Blue Swirl 已提交
466 467 468 469 470 471 472
bool memory_region_is_unassigned(MemoryRegion *mr)
{
    return mr != &io_mem_ram && mr != &io_mem_rom
        && mr != &io_mem_notdirty && !mr->rom_device
        && mr != &io_mem_watch;
}

P
pbrook 已提交
473 474
#define mmap_lock() do { } while(0)
#define mmap_unlock() do { } while(0)
475
#endif
B
bellard 已提交
476

477
#if defined(CONFIG_USER_ONLY)
S
Stuart Brady 已提交
478
/* Currently it is not recommended to allocate big chunks of data in
479 480 481
   user mode. It will change when a dedicated libc will be used.  */
/* ??? 64-bit hosts ought to have no problem mmaping data outside the
   region in which the guest needs to run.  Revisit this.  */
482 483 484
#define USE_STATIC_CODE_GEN_BUFFER
#endif

485 486 487 488 489 490
/* ??? Should configure for this, not list operating systems here.  */
#if (defined(__linux__) \
    || defined(__FreeBSD__) || defined(__FreeBSD_kernel__) \
    || defined(__DragonFly__) || defined(__OpenBSD__) \
    || defined(__NetBSD__))
# define USE_MMAP
491 492
#endif

493 494 495 496
/* Minimum size of the code gen buffer.  This number is randomly chosen,
   but not so small that we can't have a fair number of TB's live.  */
#define MIN_CODE_GEN_BUFFER_SIZE     (1024u * 1024)

497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512
/* Maximum size of the code gen buffer we'd like to use.  Unless otherwise
   indicated, this is constrained by the range of direct branches on the
   host cpu, as used by the TCG implementation of goto_tb.  */
#if defined(__x86_64__)
# define MAX_CODE_GEN_BUFFER_SIZE  (2ul * 1024 * 1024 * 1024)
#elif defined(__sparc__)
# define MAX_CODE_GEN_BUFFER_SIZE  (2ul * 1024 * 1024 * 1024)
#elif defined(__arm__)
# define MAX_CODE_GEN_BUFFER_SIZE  (16u * 1024 * 1024)
#elif defined(__s390x__)
  /* We have a +- 4GB range on the branches; leave some slop.  */
# define MAX_CODE_GEN_BUFFER_SIZE  (3ul * 1024 * 1024 * 1024)
#else
# define MAX_CODE_GEN_BUFFER_SIZE  ((size_t)-1)
#endif

513 514 515 516 517
#define DEFAULT_CODE_GEN_BUFFER_SIZE_1 (32u * 1024 * 1024)

#define DEFAULT_CODE_GEN_BUFFER_SIZE \
  (DEFAULT_CODE_GEN_BUFFER_SIZE_1 < MAX_CODE_GEN_BUFFER_SIZE \
   ? DEFAULT_CODE_GEN_BUFFER_SIZE_1 : MAX_CODE_GEN_BUFFER_SIZE)
518 519

static inline size_t size_code_gen_buffer(size_t tb_size)
520
{
521 522
    /* Size the buffer.  */
    if (tb_size == 0) {
523
#ifdef USE_STATIC_CODE_GEN_BUFFER
524
        tb_size = DEFAULT_CODE_GEN_BUFFER_SIZE;
525
#else
526 527 528 529 530
        /* ??? Needs adjustments.  */
        /* ??? If we relax the requirement that CONFIG_USER_ONLY use the
           static buffer, we could size this on RESERVED_VA, on the text
           segment size of the executable, or continue to use the default.  */
        tb_size = (unsigned long)(ram_size / 4);
531
#endif
532
    }
533 534
    if (tb_size < MIN_CODE_GEN_BUFFER_SIZE) {
        tb_size = MIN_CODE_GEN_BUFFER_SIZE;
535
    }
536 537
    if (tb_size > MAX_CODE_GEN_BUFFER_SIZE) {
        tb_size = MAX_CODE_GEN_BUFFER_SIZE;
538
    }
539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561
    code_gen_buffer_size = tb_size;
    return tb_size;
}

#ifdef USE_STATIC_CODE_GEN_BUFFER
static uint8_t static_code_gen_buffer[DEFAULT_CODE_GEN_BUFFER_SIZE]
    __attribute__((aligned(CODE_GEN_ALIGN)));

static inline void *alloc_code_gen_buffer(void)
{
    map_exec(static_code_gen_buffer, code_gen_buffer_size);
    return static_code_gen_buffer;
}
#elif defined(USE_MMAP)
static inline void *alloc_code_gen_buffer(void)
{
    int flags = MAP_PRIVATE | MAP_ANONYMOUS;
    uintptr_t start = 0;
    void *buf;

    /* Constrain the position of the buffer based on the host cpu.
       Note that these addresses are chosen in concert with the
       addresses assigned in the relevant linker script file.  */
562 563 564 565 566 567
# if defined(__PIE__) || defined(__PIC__)
    /* Don't bother setting a preferred location if we're building
       a position-independent executable.  We're more likely to get
       an address near the main executable if we let the kernel
       choose the address.  */
# elif defined(__x86_64__) && defined(MAP_32BIT)
568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584
    /* Force the memory down into low memory with the executable.
       Leave the choice of exact location with the kernel.  */
    flags |= MAP_32BIT;
    /* Cannot expect to map more than 800MB in low memory.  */
    if (code_gen_buffer_size > 800u * 1024 * 1024) {
        code_gen_buffer_size = 800u * 1024 * 1024;
    }
# elif defined(__sparc__)
    start = 0x40000000ul;
# elif defined(__s390x__)
    start = 0x90000000ul;
# endif

    buf = mmap((void *)start, code_gen_buffer_size,
               PROT_WRITE | PROT_READ | PROT_EXEC, flags, -1, 0);
    return buf == MAP_FAILED ? NULL : buf;
}
585
#else
586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604
static inline void *alloc_code_gen_buffer(void)
{
    void *buf = g_malloc(code_gen_buffer_size);
    if (buf) {
        map_exec(buf, code_gen_buffer_size);
    }
    return buf;
}
#endif /* USE_STATIC_CODE_GEN_BUFFER, USE_MMAP */

static inline void code_gen_alloc(size_t tb_size)
{
    code_gen_buffer_size = size_code_gen_buffer(tb_size);
    code_gen_buffer = alloc_code_gen_buffer();
    if (code_gen_buffer == NULL) {
        fprintf(stderr, "Could not allocate dynamic translator buffer\n");
        exit(1);
    }

605 606 607 608 609 610 611 612
    /* Steal room for the prologue at the end of the buffer.  This ensures
       (via the MAX_CODE_GEN_BUFFER_SIZE limits above) that direct branches
       from TB's to the prologue are going to be in range.  It also means
       that we don't need to mark (additional) portions of the data segment
       as executable.  */
    code_gen_prologue = code_gen_buffer + code_gen_buffer_size - 1024;
    code_gen_buffer_size -= 1024;

613 614
    code_gen_buffer_max_size = code_gen_buffer_size -
        (TCG_MAX_OP_SIZE * OPC_BUF_SIZE);
615
    code_gen_max_blocks = code_gen_buffer_size / CODE_GEN_AVG_BLOCK_SIZE;
616
    tbs = g_malloc(code_gen_max_blocks * sizeof(TranslationBlock));
617 618 619 620 621
}

/* Must be called before using the QEMU cpus. 'tb_size' is the size
   (in bytes) allocated to the translation buffer. Zero means default
   size. */
622
void tcg_exec_init(unsigned long tb_size)
623 624 625 626
{
    cpu_gen_init();
    code_gen_alloc(tb_size);
    code_gen_ptr = code_gen_buffer;
627
    tcg_register_jit(code_gen_buffer, code_gen_buffer_size);
628
    page_init();
629 630 631 632 633
#if !defined(CONFIG_USER_ONLY) || !defined(CONFIG_USE_GUEST_BASE)
    /* There's no guest base to take into account, so go ahead and
       initialize the prologue now.  */
    tcg_prologue_init(&tcg_ctx);
#endif
634 635
}

636 637 638 639 640 641 642 643 644 645 646 647 648
bool tcg_enabled(void)
{
    return code_gen_buffer != NULL;
}

void cpu_exec_init_all(void)
{
#if !defined(CONFIG_USER_ONLY)
    memory_map_init();
    io_mem_init();
#endif
}

649 650
#if defined(CPU_SAVE_VERSION) && !defined(CONFIG_USER_ONLY)

651
static int cpu_common_post_load(void *opaque, int version_id)
J
Juan Quintela 已提交
652
{
653
    CPUArchState *env = opaque;
654

655 656 657
    /* 0x01 was CPU_INTERRUPT_EXIT. This line can be removed when the
       version_id is increased. */
    env->interrupt_request &= ~0x01;
658 659 660 661
    tlb_flush(env, 1);

    return 0;
}
J
Juan Quintela 已提交
662 663 664 665 666 667 668 669

static const VMStateDescription vmstate_cpu_common = {
    .name = "cpu_common",
    .version_id = 1,
    .minimum_version_id = 1,
    .minimum_version_id_old = 1,
    .post_load = cpu_common_post_load,
    .fields      = (VMStateField []) {
670 671
        VMSTATE_UINT32(halted, CPUArchState),
        VMSTATE_UINT32(interrupt_request, CPUArchState),
J
Juan Quintela 已提交
672 673 674
        VMSTATE_END_OF_LIST()
    }
};
675 676
#endif

677
CPUArchState *qemu_get_cpu(int cpu)
G
Glauber Costa 已提交
678
{
679
    CPUArchState *env = first_cpu;
G
Glauber Costa 已提交
680 681 682 683 684 685 686 687 688 689

    while (env) {
        if (env->cpu_index == cpu)
            break;
        env = env->next_cpu;
    }

    return env;
}

690
void cpu_exec_init(CPUArchState *env)
B
bellard 已提交
691
{
692
    CPUArchState **penv;
B
bellard 已提交
693 694
    int cpu_index;

695 696 697
#if defined(CONFIG_USER_ONLY)
    cpu_list_lock();
#endif
B
bellard 已提交
698 699 700 701
    env->next_cpu = NULL;
    penv = &first_cpu;
    cpu_index = 0;
    while (*penv != NULL) {
702
        penv = &(*penv)->next_cpu;
B
bellard 已提交
703 704 705
        cpu_index++;
    }
    env->cpu_index = cpu_index;
706
    env->numa_node = 0;
B
Blue Swirl 已提交
707 708
    QTAILQ_INIT(&env->breakpoints);
    QTAILQ_INIT(&env->watchpoints);
J
Jan Kiszka 已提交
709 710 711
#ifndef CONFIG_USER_ONLY
    env->thread_id = qemu_get_thread_id();
#endif
B
bellard 已提交
712
    *penv = env;
713 714 715
#if defined(CONFIG_USER_ONLY)
    cpu_list_unlock();
#endif
716
#if defined(CPU_SAVE_VERSION) && !defined(CONFIG_USER_ONLY)
A
Alex Williamson 已提交
717 718
    vmstate_register(NULL, cpu_index, &vmstate_cpu_common, env);
    register_savevm(NULL, "cpu", cpu_index, CPU_SAVE_VERSION,
719 720
                    cpu_save, cpu_load, env);
#endif
B
bellard 已提交
721 722
}

T
Tristan Gingold 已提交
723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748
/* Allocate a new translation block. Flush the translation buffer if
   too many translation blocks or too much generated code. */
static TranslationBlock *tb_alloc(target_ulong pc)
{
    TranslationBlock *tb;

    if (nb_tbs >= code_gen_max_blocks ||
        (code_gen_ptr - code_gen_buffer) >= code_gen_buffer_max_size)
        return NULL;
    tb = &tbs[nb_tbs++];
    tb->pc = pc;
    tb->cflags = 0;
    return tb;
}

void tb_free(TranslationBlock *tb)
{
    /* In practice this is mostly used for single use temporary TB
       Ignore the hard cases and just back up if this TB happens to
       be the last one generated.  */
    if (nb_tbs > 0 && tb == &tbs[nb_tbs - 1]) {
        code_gen_ptr = tb->tc_ptr;
        nb_tbs--;
    }
}

749 750 751
static inline void invalidate_page_bitmap(PageDesc *p)
{
    if (p->code_bitmap) {
752
        g_free(p->code_bitmap);
753 754 755 756 757
        p->code_bitmap = NULL;
    }
    p->code_write_count = 0;
}

758 759 760
/* Set to NULL all the 'first_tb' fields in all PageDescs. */

static void page_flush_tb_1 (int level, void **lp)
B
bellard 已提交
761
{
762
    int i;
B
bellard 已提交
763

764 765 766 767 768
    if (*lp == NULL) {
        return;
    }
    if (level == 0) {
        PageDesc *pd = *lp;
P
Paul Brook 已提交
769
        for (i = 0; i < L2_SIZE; ++i) {
770 771
            pd[i].first_tb = NULL;
            invalidate_page_bitmap(pd + i);
B
bellard 已提交
772
        }
773 774
    } else {
        void **pp = *lp;
P
Paul Brook 已提交
775
        for (i = 0; i < L2_SIZE; ++i) {
776 777 778 779 780 781 782 783 784 785
            page_flush_tb_1 (level - 1, pp + i);
        }
    }
}

static void page_flush_tb(void)
{
    int i;
    for (i = 0; i < V_L1_SIZE; i++) {
        page_flush_tb_1(V_L1_SHIFT / L2_BITS - 1, l1_map + i);
B
bellard 已提交
786 787 788 789
    }
}

/* flush all the translation blocks */
B
bellard 已提交
790
/* XXX: tb_flush is currently not thread safe */
791
void tb_flush(CPUArchState *env1)
B
bellard 已提交
792
{
793
    CPUArchState *env;
794
#if defined(DEBUG_FLUSH)
B
blueswir1 已提交
795 796 797 798
    printf("qemu: flush code_size=%ld nb_tbs=%d avg_tb_size=%ld\n",
           (unsigned long)(code_gen_ptr - code_gen_buffer),
           nb_tbs, nb_tbs > 0 ?
           ((unsigned long)(code_gen_ptr - code_gen_buffer)) / nb_tbs : 0);
B
bellard 已提交
799
#endif
800
    if ((unsigned long)(code_gen_ptr - code_gen_buffer) > code_gen_buffer_size)
P
pbrook 已提交
801 802
        cpu_abort(env1, "Internal error: code buffer overflow\n");

B
bellard 已提交
803
    nb_tbs = 0;
804

B
bellard 已提交
805 806 807
    for(env = first_cpu; env != NULL; env = env->next_cpu) {
        memset (env->tb_jmp_cache, 0, TB_JMP_CACHE_SIZE * sizeof (void *));
    }
808

B
bellard 已提交
809
    memset (tb_phys_hash, 0, CODE_GEN_PHYS_HASH_SIZE * sizeof (void *));
B
bellard 已提交
810
    page_flush_tb();
811

B
bellard 已提交
812
    code_gen_ptr = code_gen_buffer;
B
bellard 已提交
813 814
    /* XXX: flush processor icache at this point if cache flush is
       expensive */
B
bellard 已提交
815
    tb_flush_count++;
B
bellard 已提交
816 817 818 819
}

#ifdef DEBUG_TB_CHECK

J
j_mayer 已提交
820
static void tb_invalidate_check(target_ulong address)
B
bellard 已提交
821 822 823 824
{
    TranslationBlock *tb;
    int i;
    address &= TARGET_PAGE_MASK;
825 826
    for(i = 0;i < CODE_GEN_PHYS_HASH_SIZE; i++) {
        for(tb = tb_phys_hash[i]; tb != NULL; tb = tb->phys_hash_next) {
B
bellard 已提交
827 828
            if (!(address + TARGET_PAGE_SIZE <= tb->pc ||
                  address >= tb->pc + tb->size)) {
829 830
                printf("ERROR invalidate: address=" TARGET_FMT_lx
                       " PC=%08lx size=%04x\n",
831
                       address, (long)tb->pc, tb->size);
B
bellard 已提交
832 833 834 835 836 837 838 839 840 841
            }
        }
    }
}

/* verify that all the pages have correct rights for code */
static void tb_page_check(void)
{
    TranslationBlock *tb;
    int i, flags1, flags2;
842

843 844
    for(i = 0;i < CODE_GEN_PHYS_HASH_SIZE; i++) {
        for(tb = tb_phys_hash[i]; tb != NULL; tb = tb->phys_hash_next) {
B
bellard 已提交
845 846 847 848
            flags1 = page_get_flags(tb->pc);
            flags2 = page_get_flags(tb->pc + tb->size - 1);
            if ((flags1 & PAGE_WRITE) || (flags2 & PAGE_WRITE)) {
                printf("ERROR page flags: PC=%08lx size=%04x f1=%x f2=%x\n",
849
                       (long)tb->pc, tb->size, flags1, flags2);
B
bellard 已提交
850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871
            }
        }
    }
}

#endif

/* invalidate one TB */
static inline void tb_remove(TranslationBlock **ptb, TranslationBlock *tb,
                             int next_offset)
{
    TranslationBlock *tb1;
    for(;;) {
        tb1 = *ptb;
        if (tb1 == tb) {
            *ptb = *(TranslationBlock **)((char *)tb1 + next_offset);
            break;
        }
        ptb = (TranslationBlock **)((char *)tb1 + next_offset);
    }
}

872 873 874 875 876 877 878
static inline void tb_page_remove(TranslationBlock **ptb, TranslationBlock *tb)
{
    TranslationBlock *tb1;
    unsigned int n1;

    for(;;) {
        tb1 = *ptb;
S
Stefan Weil 已提交
879 880
        n1 = (uintptr_t)tb1 & 3;
        tb1 = (TranslationBlock *)((uintptr_t)tb1 & ~3);
881 882 883 884 885 886 887 888
        if (tb1 == tb) {
            *ptb = tb1->page_next[n1];
            break;
        }
        ptb = &tb1->page_next[n1];
    }
}

B
bellard 已提交
889 890 891 892 893 894 895 896 897 898 899
static inline void tb_jmp_remove(TranslationBlock *tb, int n)
{
    TranslationBlock *tb1, **ptb;
    unsigned int n1;

    ptb = &tb->jmp_next[n];
    tb1 = *ptb;
    if (tb1) {
        /* find tb(n) in circular list */
        for(;;) {
            tb1 = *ptb;
S
Stefan Weil 已提交
900 901
            n1 = (uintptr_t)tb1 & 3;
            tb1 = (TranslationBlock *)((uintptr_t)tb1 & ~3);
B
bellard 已提交
902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920
            if (n1 == n && tb1 == tb)
                break;
            if (n1 == 2) {
                ptb = &tb1->jmp_first;
            } else {
                ptb = &tb1->jmp_next[n1];
            }
        }
        /* now we can suppress tb(n) from the list */
        *ptb = tb->jmp_next[n];

        tb->jmp_next[n] = NULL;
    }
}

/* reset the jump entry 'n' of a TB so that it is not chained to
   another TB */
static inline void tb_reset_jump(TranslationBlock *tb, int n)
{
S
Stefan Weil 已提交
921
    tb_set_jmp_target(tb, n, (uintptr_t)(tb->tc_ptr + tb->tb_next_offset[n]));
B
bellard 已提交
922 923
}

P
Paul Brook 已提交
924
void tb_phys_invalidate(TranslationBlock *tb, tb_page_addr_t page_addr)
B
bellard 已提交
925
{
926
    CPUArchState *env;
927
    PageDesc *p;
B
bellard 已提交
928
    unsigned int h, n1;
P
Paul Brook 已提交
929
    tb_page_addr_t phys_pc;
930
    TranslationBlock *tb1, *tb2;
931

932 933 934
    /* remove the TB from the hash list */
    phys_pc = tb->page_addr[0] + (tb->pc & ~TARGET_PAGE_MASK);
    h = tb_phys_hash_func(phys_pc);
935
    tb_remove(&tb_phys_hash[h], tb,
936 937 938 939 940 941 942 943 944 945 946 947 948 949
              offsetof(TranslationBlock, phys_hash_next));

    /* remove the TB from the page list */
    if (tb->page_addr[0] != page_addr) {
        p = page_find(tb->page_addr[0] >> TARGET_PAGE_BITS);
        tb_page_remove(&p->first_tb, tb);
        invalidate_page_bitmap(p);
    }
    if (tb->page_addr[1] != -1 && tb->page_addr[1] != page_addr) {
        p = page_find(tb->page_addr[1] >> TARGET_PAGE_BITS);
        tb_page_remove(&p->first_tb, tb);
        invalidate_page_bitmap(p);
    }

950
    tb_invalidated_flag = 1;
951

B
bellard 已提交
952
    /* remove the TB from the hash list */
953
    h = tb_jmp_cache_hash_func(tb->pc);
B
bellard 已提交
954 955 956 957
    for(env = first_cpu; env != NULL; env = env->next_cpu) {
        if (env->tb_jmp_cache[h] == tb)
            env->tb_jmp_cache[h] = NULL;
    }
B
bellard 已提交
958 959 960 961 962 963 964 965

    /* suppress this TB from the two jump lists */
    tb_jmp_remove(tb, 0);
    tb_jmp_remove(tb, 1);

    /* suppress any remaining jumps to this TB */
    tb1 = tb->jmp_first;
    for(;;) {
S
Stefan Weil 已提交
966
        n1 = (uintptr_t)tb1 & 3;
B
bellard 已提交
967 968
        if (n1 == 2)
            break;
S
Stefan Weil 已提交
969
        tb1 = (TranslationBlock *)((uintptr_t)tb1 & ~3);
B
bellard 已提交
970 971 972 973 974
        tb2 = tb1->jmp_next[n1];
        tb_reset_jump(tb1, n1);
        tb1->jmp_next[n1] = NULL;
        tb1 = tb2;
    }
S
Stefan Weil 已提交
975
    tb->jmp_first = (TranslationBlock *)((uintptr_t)tb | 2); /* fail safe */
976

B
bellard 已提交
977
    tb_phys_invalidate_count++;
978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010
}

static inline void set_bits(uint8_t *tab, int start, int len)
{
    int end, mask, end1;

    end = start + len;
    tab += start >> 3;
    mask = 0xff << (start & 7);
    if ((start & ~7) == (end & ~7)) {
        if (start < end) {
            mask &= ~(0xff << (end & 7));
            *tab |= mask;
        }
    } else {
        *tab++ |= mask;
        start = (start + 8) & ~7;
        end1 = end & ~7;
        while (start < end1) {
            *tab++ = 0xff;
            start += 8;
        }
        if (start < end) {
            mask = ~(0xff << (end & 7));
            *tab |= mask;
        }
    }
}

static void build_page_bitmap(PageDesc *p)
{
    int n, tb_start, tb_end;
    TranslationBlock *tb;
1011

1012
    p->code_bitmap = g_malloc0(TARGET_PAGE_SIZE / 8);
1013 1014 1015

    tb = p->first_tb;
    while (tb != NULL) {
S
Stefan Weil 已提交
1016 1017
        n = (uintptr_t)tb & 3;
        tb = (TranslationBlock *)((uintptr_t)tb & ~3);
1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034
        /* NOTE: this is subtle as a TB may span two physical pages */
        if (n == 0) {
            /* NOTE: tb_end may be after the end of the page, but
               it is not a problem */
            tb_start = tb->pc & ~TARGET_PAGE_MASK;
            tb_end = tb_start + tb->size;
            if (tb_end > TARGET_PAGE_SIZE)
                tb_end = TARGET_PAGE_SIZE;
        } else {
            tb_start = 0;
            tb_end = ((tb->pc + tb->size) & ~TARGET_PAGE_MASK);
        }
        set_bits(p->code_bitmap, tb_start, tb_end - tb_start);
        tb = tb->page_next[n];
    }
}

1035
TranslationBlock *tb_gen_code(CPUArchState *env,
P
pbrook 已提交
1036 1037
                              target_ulong pc, target_ulong cs_base,
                              int flags, int cflags)
B
bellard 已提交
1038 1039 1040
{
    TranslationBlock *tb;
    uint8_t *tc_ptr;
P
Paul Brook 已提交
1041 1042
    tb_page_addr_t phys_pc, phys_page2;
    target_ulong virt_page2;
B
bellard 已提交
1043 1044
    int code_gen_size;

P
Paul Brook 已提交
1045
    phys_pc = get_page_addr_code(env, pc);
B
bellard 已提交
1046
    tb = tb_alloc(pc);
B
bellard 已提交
1047 1048 1049 1050
    if (!tb) {
        /* flush must be done */
        tb_flush(env);
        /* cannot fail at this point */
B
bellard 已提交
1051
        tb = tb_alloc(pc);
P
pbrook 已提交
1052 1053
        /* Don't forget to invalidate previous TB info.  */
        tb_invalidated_flag = 1;
B
bellard 已提交
1054 1055 1056 1057 1058 1059
    }
    tc_ptr = code_gen_ptr;
    tb->tc_ptr = tc_ptr;
    tb->cs_base = cs_base;
    tb->flags = flags;
    tb->cflags = cflags;
1060
    cpu_gen_code(env, tb, &code_gen_size);
S
Stefan Weil 已提交
1061 1062
    code_gen_ptr = (void *)(((uintptr_t)code_gen_ptr + code_gen_size +
                             CODE_GEN_ALIGN - 1) & ~(CODE_GEN_ALIGN - 1));
1063

B
bellard 已提交
1064
    /* check next page if needed */
B
bellard 已提交
1065
    virt_page2 = (pc + tb->size - 1) & TARGET_PAGE_MASK;
B
bellard 已提交
1066
    phys_page2 = -1;
B
bellard 已提交
1067
    if ((pc & TARGET_PAGE_MASK) != virt_page2) {
P
Paul Brook 已提交
1068
        phys_page2 = get_page_addr_code(env, virt_page2);
B
bellard 已提交
1069
    }
P
Paul Brook 已提交
1070
    tb_link_page(tb, phys_pc, phys_page2);
P
pbrook 已提交
1071
    return tb;
B
bellard 已提交
1072
}
1073

1074
/*
1075 1076 1077 1078 1079
 * Invalidate all TBs which intersect with the target physical address range
 * [start;end[. NOTE: start and end may refer to *different* physical pages.
 * 'is_cpu_write_access' should be true if called from a real cpu write
 * access: the virtual CPU will exit the current TB if code is modified inside
 * this TB.
1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090
 */
void tb_invalidate_phys_range(tb_page_addr_t start, tb_page_addr_t end,
                              int is_cpu_write_access)
{
    while (start < end) {
        tb_invalidate_phys_page_range(start, end, is_cpu_write_access);
        start &= TARGET_PAGE_MASK;
        start += TARGET_PAGE_SIZE;
    }
}

1091 1092 1093 1094 1095 1096 1097
/*
 * Invalidate all TBs which intersect with the target physical address range
 * [start;end[. NOTE: start and end must refer to the *same* physical page.
 * 'is_cpu_write_access' should be true if called from a real cpu write
 * access: the virtual CPU will exit the current TB if code is modified inside
 * this TB.
 */
P
Paul Brook 已提交
1098
void tb_invalidate_phys_page_range(tb_page_addr_t start, tb_page_addr_t end,
B
bellard 已提交
1099 1100
                                   int is_cpu_write_access)
{
1101
    TranslationBlock *tb, *tb_next, *saved_tb;
1102
    CPUArchState *env = cpu_single_env;
P
Paul Brook 已提交
1103
    tb_page_addr_t tb_start, tb_end;
1104 1105 1106 1107 1108 1109 1110 1111 1112 1113
    PageDesc *p;
    int n;
#ifdef TARGET_HAS_PRECISE_SMC
    int current_tb_not_found = is_cpu_write_access;
    TranslationBlock *current_tb = NULL;
    int current_tb_modified = 0;
    target_ulong current_pc = 0;
    target_ulong current_cs_base = 0;
    int current_flags = 0;
#endif /* TARGET_HAS_PRECISE_SMC */
1114 1115

    p = page_find(start >> TARGET_PAGE_BITS);
1116
    if (!p)
1117
        return;
1118
    if (!p->code_bitmap &&
B
bellard 已提交
1119 1120
        ++p->code_write_count >= SMC_BITMAP_USE_THRESHOLD &&
        is_cpu_write_access) {
1121 1122 1123 1124 1125 1126 1127 1128
        /* build code bitmap */
        build_page_bitmap(p);
    }

    /* we remove all the TBs in the range [start, end[ */
    /* XXX: see if in some cases it could be faster to invalidate all the code */
    tb = p->first_tb;
    while (tb != NULL) {
S
Stefan Weil 已提交
1129 1130
        n = (uintptr_t)tb & 3;
        tb = (TranslationBlock *)((uintptr_t)tb & ~3);
1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142
        tb_next = tb->page_next[n];
        /* NOTE: this is subtle as a TB may span two physical pages */
        if (n == 0) {
            /* NOTE: tb_end may be after the end of the page, but
               it is not a problem */
            tb_start = tb->page_addr[0] + (tb->pc & ~TARGET_PAGE_MASK);
            tb_end = tb_start + tb->size;
        } else {
            tb_start = tb->page_addr[1];
            tb_end = tb_start + ((tb->pc + tb->size) & ~TARGET_PAGE_MASK);
        }
        if (!(tb_end <= start || tb_start >= end)) {
B
bellard 已提交
1143 1144 1145 1146
#ifdef TARGET_HAS_PRECISE_SMC
            if (current_tb_not_found) {
                current_tb_not_found = 0;
                current_tb = NULL;
P
pbrook 已提交
1147
                if (env->mem_io_pc) {
B
bellard 已提交
1148
                    /* now we have a real cpu fault */
P
pbrook 已提交
1149
                    current_tb = tb_find_pc(env->mem_io_pc);
B
bellard 已提交
1150 1151 1152
                }
            }
            if (current_tb == tb &&
P
pbrook 已提交
1153
                (current_tb->cflags & CF_COUNT_MASK) != 1) {
B
bellard 已提交
1154 1155 1156 1157 1158
                /* If we are modifying the current TB, we must stop
                its execution. We could be more precise by checking
                that the modification is after the current PC, but it
                would require a specialized function to partially
                restore the CPU state */
1159

B
bellard 已提交
1160
                current_tb_modified = 1;
1161
                cpu_restore_state(current_tb, env, env->mem_io_pc);
1162 1163
                cpu_get_tb_cpu_state(env, &current_pc, &current_cs_base,
                                     &current_flags);
B
bellard 已提交
1164 1165
            }
#endif /* TARGET_HAS_PRECISE_SMC */
1166 1167 1168 1169 1170 1171 1172
            /* we need to do that to handle the case where a signal
               occurs while doing tb_phys_invalidate() */
            saved_tb = NULL;
            if (env) {
                saved_tb = env->current_tb;
                env->current_tb = NULL;
            }
1173
            tb_phys_invalidate(tb, -1);
1174 1175 1176 1177 1178
            if (env) {
                env->current_tb = saved_tb;
                if (env->interrupt_request && env->current_tb)
                    cpu_interrupt(env, env->interrupt_request);
            }
1179 1180 1181 1182 1183 1184 1185
        }
        tb = tb_next;
    }
#if !defined(CONFIG_USER_ONLY)
    /* if no code remaining, no need to continue to use slow writes */
    if (!p->first_tb) {
        invalidate_page_bitmap(p);
B
bellard 已提交
1186
        if (is_cpu_write_access) {
P
pbrook 已提交
1187
            tlb_unprotect_code_phys(env, start, env->mem_io_vaddr);
B
bellard 已提交
1188 1189 1190 1191 1192 1193 1194 1195
        }
    }
#endif
#ifdef TARGET_HAS_PRECISE_SMC
    if (current_tb_modified) {
        /* we generate a block containing just the instruction
           modifying the memory. It will ensure that it cannot modify
           itself */
1196
        env->current_tb = NULL;
P
pbrook 已提交
1197
        tb_gen_code(env, current_pc, current_cs_base, current_flags, 1);
B
bellard 已提交
1198
        cpu_resume_from_signal(env, NULL);
1199
    }
B
bellard 已提交
1200
#endif
1201
}
B
bellard 已提交
1202

1203
/* len must be <= 8 and start must be a multiple of len */
P
Paul Brook 已提交
1204
static inline void tb_invalidate_phys_page_fast(tb_page_addr_t start, int len)
1205 1206 1207
{
    PageDesc *p;
    int offset, b;
1208
#if 0
B
bellard 已提交
1209
    if (1) {
1210 1211 1212
        qemu_log("modifying code at 0x%x size=%d EIP=%x PC=%08x\n",
                  cpu_single_env->mem_io_vaddr, len,
                  cpu_single_env->eip,
S
Stefan Weil 已提交
1213 1214
                  cpu_single_env->eip +
                  (intptr_t)cpu_single_env->segs[R_CS].base);
1215 1216
    }
#endif
1217
    p = page_find(start >> TARGET_PAGE_BITS);
1218
    if (!p)
1219 1220 1221 1222 1223 1224 1225 1226
        return;
    if (p->code_bitmap) {
        offset = start & ~TARGET_PAGE_MASK;
        b = p->code_bitmap[offset >> 3] >> (offset & 7);
        if (b & ((1 << len) - 1))
            goto do_invalidate;
    } else {
    do_invalidate:
B
bellard 已提交
1227
        tb_invalidate_phys_page_range(start, start + len, 1);
1228 1229 1230 1231
    }
}

#if !defined(CONFIG_SOFTMMU)
P
Paul Brook 已提交
1232
static void tb_invalidate_phys_page(tb_page_addr_t addr,
1233
                                    uintptr_t pc, void *puc)
1234
{
1235
    TranslationBlock *tb;
1236
    PageDesc *p;
1237
    int n;
B
bellard 已提交
1238
#ifdef TARGET_HAS_PRECISE_SMC
1239
    TranslationBlock *current_tb = NULL;
1240
    CPUArchState *env = cpu_single_env;
1241 1242 1243 1244
    int current_tb_modified = 0;
    target_ulong current_pc = 0;
    target_ulong current_cs_base = 0;
    int current_flags = 0;
B
bellard 已提交
1245
#endif
1246 1247 1248

    addr &= TARGET_PAGE_MASK;
    p = page_find(addr >> TARGET_PAGE_BITS);
1249
    if (!p)
1250 1251
        return;
    tb = p->first_tb;
B
bellard 已提交
1252 1253 1254 1255 1256
#ifdef TARGET_HAS_PRECISE_SMC
    if (tb && pc != 0) {
        current_tb = tb_find_pc(pc);
    }
#endif
1257
    while (tb != NULL) {
S
Stefan Weil 已提交
1258 1259
        n = (uintptr_t)tb & 3;
        tb = (TranslationBlock *)((uintptr_t)tb & ~3);
B
bellard 已提交
1260 1261
#ifdef TARGET_HAS_PRECISE_SMC
        if (current_tb == tb &&
P
pbrook 已提交
1262
            (current_tb->cflags & CF_COUNT_MASK) != 1) {
B
bellard 已提交
1263 1264 1265 1266 1267
                /* If we are modifying the current TB, we must stop
                   its execution. We could be more precise by checking
                   that the modification is after the current PC, but it
                   would require a specialized function to partially
                   restore the CPU state */
1268

B
bellard 已提交
1269
            current_tb_modified = 1;
1270
            cpu_restore_state(current_tb, env, pc);
1271 1272
            cpu_get_tb_cpu_state(env, &current_pc, &current_cs_base,
                                 &current_flags);
B
bellard 已提交
1273 1274
        }
#endif /* TARGET_HAS_PRECISE_SMC */
1275 1276 1277
        tb_phys_invalidate(tb, addr);
        tb = tb->page_next[n];
    }
B
bellard 已提交
1278
    p->first_tb = NULL;
B
bellard 已提交
1279 1280 1281 1282 1283
#ifdef TARGET_HAS_PRECISE_SMC
    if (current_tb_modified) {
        /* we generate a block containing just the instruction
           modifying the memory. It will ensure that it cannot modify
           itself */
1284
        env->current_tb = NULL;
P
pbrook 已提交
1285
        tb_gen_code(env, current_pc, current_cs_base, current_flags, 1);
B
bellard 已提交
1286 1287 1288
        cpu_resume_from_signal(env, puc);
    }
#endif
B
bellard 已提交
1289
}
1290
#endif
B
bellard 已提交
1291 1292

/* add the tb in the target page and protect it if necessary */
1293
static inline void tb_alloc_page(TranslationBlock *tb,
P
Paul Brook 已提交
1294
                                 unsigned int n, tb_page_addr_t page_addr)
B
bellard 已提交
1295 1296
{
    PageDesc *p;
1297 1298 1299
#ifndef CONFIG_USER_ONLY
    bool page_already_protected;
#endif
1300 1301

    tb->page_addr[n] = page_addr;
1302
    p = page_find_alloc(page_addr >> TARGET_PAGE_BITS, 1);
1303
    tb->page_next[n] = p->first_tb;
1304 1305 1306
#ifndef CONFIG_USER_ONLY
    page_already_protected = p->first_tb != NULL;
#endif
S
Stefan Weil 已提交
1307
    p->first_tb = (TranslationBlock *)((uintptr_t)tb | n);
1308
    invalidate_page_bitmap(p);
B
bellard 已提交
1309

1310
#if defined(TARGET_HAS_SMC) || 1
B
bellard 已提交
1311

1312
#if defined(CONFIG_USER_ONLY)
B
bellard 已提交
1313
    if (p->flags & PAGE_WRITE) {
1314 1315
        target_ulong addr;
        PageDesc *p2;
1316 1317
        int prot;

B
bellard 已提交
1318 1319
        /* force the host page as non writable (writes will have a
           page fault + mprotect overhead) */
1320
        page_addr &= qemu_host_page_mask;
B
bellard 已提交
1321
        prot = 0;
1322 1323 1324 1325 1326 1327 1328 1329 1330
        for(addr = page_addr; addr < page_addr + qemu_host_page_size;
            addr += TARGET_PAGE_SIZE) {

            p2 = page_find (addr >> TARGET_PAGE_BITS);
            if (!p2)
                continue;
            prot |= p2->flags;
            p2->flags &= ~PAGE_WRITE;
          }
1331
        mprotect(g2h(page_addr), qemu_host_page_size,
B
bellard 已提交
1332 1333
                 (prot & PAGE_BITS) & ~PAGE_WRITE);
#ifdef DEBUG_TB_INVALIDATE
B
blueswir1 已提交
1334
        printf("protecting code page: 0x" TARGET_FMT_lx "\n",
1335
               page_addr);
B
bellard 已提交
1336 1337
#endif
    }
1338 1339 1340 1341
#else
    /* if some code is already present, then the pages are already
       protected. So we handle the case where only the first TB is
       allocated in a physical page */
1342
    if (!page_already_protected) {
B
bellard 已提交
1343
        tlb_protect_code(page_addr);
1344 1345
    }
#endif
B
bellard 已提交
1346 1347

#endif /* TARGET_HAS_SMC */
B
bellard 已提交
1348 1349
}

1350 1351
/* add a new TB and link it to the physical page tables. phys_page2 is
   (-1) to indicate that only one page contains the TB. */
P
Paul Brook 已提交
1352 1353
void tb_link_page(TranslationBlock *tb,
                  tb_page_addr_t phys_pc, tb_page_addr_t phys_page2)
B
bellard 已提交
1354
{
1355 1356 1357
    unsigned int h;
    TranslationBlock **ptb;

P
pbrook 已提交
1358 1359 1360
    /* Grab the mmap lock to stop another thread invalidating this TB
       before we are done.  */
    mmap_lock();
1361 1362 1363 1364 1365
    /* add in the physical hash table */
    h = tb_phys_hash_func(phys_pc);
    ptb = &tb_phys_hash[h];
    tb->phys_hash_next = *ptb;
    *ptb = tb;
B
bellard 已提交
1366 1367

    /* add in the page list */
1368 1369 1370 1371 1372 1373
    tb_alloc_page(tb, 0, phys_pc & TARGET_PAGE_MASK);
    if (phys_page2 != -1)
        tb_alloc_page(tb, 1, phys_page2);
    else
        tb->page_addr[1] = -1;

S
Stefan Weil 已提交
1374
    tb->jmp_first = (TranslationBlock *)((uintptr_t)tb | 2);
B
bellard 已提交
1375 1376 1377 1378 1379 1380 1381 1382
    tb->jmp_next[0] = NULL;
    tb->jmp_next[1] = NULL;

    /* init original jump addresses */
    if (tb->tb_next_offset[0] != 0xffff)
        tb_reset_jump(tb, 0);
    if (tb->tb_next_offset[1] != 0xffff)
        tb_reset_jump(tb, 1);
1383 1384 1385 1386

#ifdef DEBUG_TB_CHECK
    tb_page_check();
#endif
P
pbrook 已提交
1387
    mmap_unlock();
B
bellard 已提交
1388 1389
}

1390 1391
/* find the TB 'tb' such that tb[0].tc_ptr <= tc_ptr <
   tb[1].tc_ptr. Return NULL if not found */
1392
TranslationBlock *tb_find_pc(uintptr_t tc_ptr)
B
bellard 已提交
1393
{
1394
    int m_min, m_max, m;
S
Stefan Weil 已提交
1395
    uintptr_t v;
1396
    TranslationBlock *tb;
B
bellard 已提交
1397 1398 1399

    if (nb_tbs <= 0)
        return NULL;
S
Stefan Weil 已提交
1400 1401
    if (tc_ptr < (uintptr_t)code_gen_buffer ||
        tc_ptr >= (uintptr_t)code_gen_ptr) {
B
bellard 已提交
1402
        return NULL;
S
Stefan Weil 已提交
1403
    }
B
bellard 已提交
1404 1405 1406 1407 1408 1409
    /* binary search (cf Knuth) */
    m_min = 0;
    m_max = nb_tbs - 1;
    while (m_min <= m_max) {
        m = (m_min + m_max) >> 1;
        tb = &tbs[m];
S
Stefan Weil 已提交
1410
        v = (uintptr_t)tb->tc_ptr;
B
bellard 已提交
1411 1412 1413 1414 1415 1416 1417
        if (v == tc_ptr)
            return tb;
        else if (tc_ptr < v) {
            m_max = m - 1;
        } else {
            m_min = m + 1;
        }
1418
    }
B
bellard 已提交
1419 1420
    return &tbs[m_max];
}
B
bellard 已提交
1421

B
bellard 已提交
1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432
static void tb_reset_jump_recursive(TranslationBlock *tb);

static inline void tb_reset_jump_recursive2(TranslationBlock *tb, int n)
{
    TranslationBlock *tb1, *tb_next, **ptb;
    unsigned int n1;

    tb1 = tb->jmp_next[n];
    if (tb1 != NULL) {
        /* find head of list */
        for(;;) {
S
Stefan Weil 已提交
1433 1434
            n1 = (uintptr_t)tb1 & 3;
            tb1 = (TranslationBlock *)((uintptr_t)tb1 & ~3);
B
bellard 已提交
1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445
            if (n1 == 2)
                break;
            tb1 = tb1->jmp_next[n1];
        }
        /* we are now sure now that tb jumps to tb1 */
        tb_next = tb1;

        /* remove tb from the jmp_first list */
        ptb = &tb_next->jmp_first;
        for(;;) {
            tb1 = *ptb;
S
Stefan Weil 已提交
1446 1447
            n1 = (uintptr_t)tb1 & 3;
            tb1 = (TranslationBlock *)((uintptr_t)tb1 & ~3);
B
bellard 已提交
1448 1449 1450 1451 1452 1453
            if (n1 == n && tb1 == tb)
                break;
            ptb = &tb1->jmp_next[n1];
        }
        *ptb = tb->jmp_next[n];
        tb->jmp_next[n] = NULL;
1454

B
bellard 已提交
1455 1456 1457
        /* suppress the jump to next tb in generated code */
        tb_reset_jump(tb, n);

1458
        /* suppress jumps in the tb on which we could have jumped */
B
bellard 已提交
1459 1460 1461 1462 1463 1464 1465 1466 1467 1468
        tb_reset_jump_recursive(tb_next);
    }
}

static void tb_reset_jump_recursive(TranslationBlock *tb)
{
    tb_reset_jump_recursive2(tb, 0);
    tb_reset_jump_recursive2(tb, 1);
}

B
bellard 已提交
1469
#if defined(TARGET_HAS_ICE)
1470
#if defined(CONFIG_USER_ONLY)
1471
static void breakpoint_invalidate(CPUArchState *env, target_ulong pc)
1472 1473 1474 1475
{
    tb_invalidate_phys_page_range(pc, pc + 1, 0);
}
#else
A
Avi Kivity 已提交
1476
void tb_invalidate_phys_addr(hwaddr addr)
B
bellard 已提交
1477
{
A
Anthony Liguori 已提交
1478
    ram_addr_t ram_addr;
1479
    MemoryRegionSection *section;
B
bellard 已提交
1480

A
Avi Kivity 已提交
1481
    section = phys_page_find(address_space_memory.dispatch, addr >> TARGET_PAGE_BITS);
1482 1483
    if (!(memory_region_is_ram(section->mr)
          || (section->mr->rom_device && section->mr->readable))) {
1484 1485
        return;
    }
1486
    ram_addr = (memory_region_get_ram_addr(section->mr) & TARGET_PAGE_MASK)
1487
        + memory_region_section_addr(section, addr);
P
pbrook 已提交
1488
    tb_invalidate_phys_page_range(ram_addr, ram_addr + 1, 0);
B
bellard 已提交
1489
}
1490 1491 1492

static void breakpoint_invalidate(CPUArchState *env, target_ulong pc)
{
1493 1494
    tb_invalidate_phys_addr(cpu_get_phys_page_debug(env, pc) |
            (pc & ~TARGET_PAGE_MASK));
1495
}
B
bellard 已提交
1496
#endif
1497
#endif /* TARGET_HAS_ICE */
B
bellard 已提交
1498

1499
#if defined(CONFIG_USER_ONLY)
1500
void cpu_watchpoint_remove_all(CPUArchState *env, int mask)
1501 1502 1503 1504

{
}

1505
int cpu_watchpoint_insert(CPUArchState *env, target_ulong addr, target_ulong len,
1506 1507 1508 1509 1510
                          int flags, CPUWatchpoint **watchpoint)
{
    return -ENOSYS;
}
#else
1511
/* Add a watchpoint.  */
1512
int cpu_watchpoint_insert(CPUArchState *env, target_ulong addr, target_ulong len,
1513
                          int flags, CPUWatchpoint **watchpoint)
1514
{
1515
    target_ulong len_mask = ~(len - 1);
1516
    CPUWatchpoint *wp;
1517

1518
    /* sanity checks: allow power-of-2 lengths, deny unaligned watchpoints */
1519 1520
    if ((len & (len - 1)) || (addr & ~len_mask) ||
            len == 0 || len > TARGET_PAGE_SIZE) {
1521 1522 1523 1524
        fprintf(stderr, "qemu: tried to set invalid watchpoint at "
                TARGET_FMT_lx ", len=" TARGET_FMT_lu "\n", addr, len);
        return -EINVAL;
    }
1525
    wp = g_malloc(sizeof(*wp));
1526 1527

    wp->vaddr = addr;
1528
    wp->len_mask = len_mask;
1529 1530
    wp->flags = flags;

1531
    /* keep all GDB-injected watchpoints in front */
1532
    if (flags & BP_GDB)
B
Blue Swirl 已提交
1533
        QTAILQ_INSERT_HEAD(&env->watchpoints, wp, entry);
1534
    else
B
Blue Swirl 已提交
1535
        QTAILQ_INSERT_TAIL(&env->watchpoints, wp, entry);
1536 1537

    tlb_flush_page(env, addr);
1538 1539 1540 1541

    if (watchpoint)
        *watchpoint = wp;
    return 0;
1542 1543
}

1544
/* Remove a specific watchpoint.  */
1545
int cpu_watchpoint_remove(CPUArchState *env, target_ulong addr, target_ulong len,
1546
                          int flags)
1547
{
1548
    target_ulong len_mask = ~(len - 1);
1549
    CPUWatchpoint *wp;
1550

B
Blue Swirl 已提交
1551
    QTAILQ_FOREACH(wp, &env->watchpoints, entry) {
1552
        if (addr == wp->vaddr && len_mask == wp->len_mask
1553
                && flags == (wp->flags & ~BP_WATCHPOINT_HIT)) {
1554
            cpu_watchpoint_remove_by_ref(env, wp);
1555 1556 1557
            return 0;
        }
    }
1558
    return -ENOENT;
1559 1560
}

1561
/* Remove a specific watchpoint by reference.  */
1562
void cpu_watchpoint_remove_by_ref(CPUArchState *env, CPUWatchpoint *watchpoint)
1563
{
B
Blue Swirl 已提交
1564
    QTAILQ_REMOVE(&env->watchpoints, watchpoint, entry);
1565

1566 1567
    tlb_flush_page(env, watchpoint->vaddr);

1568
    g_free(watchpoint);
1569 1570 1571
}

/* Remove all matching watchpoints.  */
1572
void cpu_watchpoint_remove_all(CPUArchState *env, int mask)
1573
{
1574
    CPUWatchpoint *wp, *next;
1575

B
Blue Swirl 已提交
1576
    QTAILQ_FOREACH_SAFE(wp, &env->watchpoints, entry, next) {
1577 1578
        if (wp->flags & mask)
            cpu_watchpoint_remove_by_ref(env, wp);
1579
    }
1580
}
1581
#endif
1582

1583
/* Add a breakpoint.  */
1584
int cpu_breakpoint_insert(CPUArchState *env, target_ulong pc, int flags,
1585
                          CPUBreakpoint **breakpoint)
B
bellard 已提交
1586
{
B
bellard 已提交
1587
#if defined(TARGET_HAS_ICE)
1588
    CPUBreakpoint *bp;
1589

1590
    bp = g_malloc(sizeof(*bp));
B
bellard 已提交
1591

1592 1593 1594
    bp->pc = pc;
    bp->flags = flags;

1595
    /* keep all GDB-injected breakpoints in front */
1596
    if (flags & BP_GDB)
B
Blue Swirl 已提交
1597
        QTAILQ_INSERT_HEAD(&env->breakpoints, bp, entry);
1598
    else
B
Blue Swirl 已提交
1599
        QTAILQ_INSERT_TAIL(&env->breakpoints, bp, entry);
1600

B
bellard 已提交
1601
    breakpoint_invalidate(env, pc);
1602 1603 1604

    if (breakpoint)
        *breakpoint = bp;
B
bellard 已提交
1605 1606
    return 0;
#else
1607
    return -ENOSYS;
B
bellard 已提交
1608 1609 1610
#endif
}

1611
/* Remove a specific breakpoint.  */
1612
int cpu_breakpoint_remove(CPUArchState *env, target_ulong pc, int flags)
1613
{
1614
#if defined(TARGET_HAS_ICE)
1615 1616
    CPUBreakpoint *bp;

B
Blue Swirl 已提交
1617
    QTAILQ_FOREACH(bp, &env->breakpoints, entry) {
1618 1619 1620 1621
        if (bp->pc == pc && bp->flags == flags) {
            cpu_breakpoint_remove_by_ref(env, bp);
            return 0;
        }
1622
    }
1623 1624 1625
    return -ENOENT;
#else
    return -ENOSYS;
1626 1627 1628
#endif
}

1629
/* Remove a specific breakpoint by reference.  */
1630
void cpu_breakpoint_remove_by_ref(CPUArchState *env, CPUBreakpoint *breakpoint)
B
bellard 已提交
1631
{
B
bellard 已提交
1632
#if defined(TARGET_HAS_ICE)
B
Blue Swirl 已提交
1633
    QTAILQ_REMOVE(&env->breakpoints, breakpoint, entry);
B
bellard 已提交
1634

1635 1636
    breakpoint_invalidate(env, breakpoint->pc);

1637
    g_free(breakpoint);
1638 1639 1640 1641
#endif
}

/* Remove all matching breakpoints. */
1642
void cpu_breakpoint_remove_all(CPUArchState *env, int mask)
1643 1644
{
#if defined(TARGET_HAS_ICE)
1645
    CPUBreakpoint *bp, *next;
1646

B
Blue Swirl 已提交
1647
    QTAILQ_FOREACH_SAFE(bp, &env->breakpoints, entry, next) {
1648 1649
        if (bp->flags & mask)
            cpu_breakpoint_remove_by_ref(env, bp);
1650
    }
B
bellard 已提交
1651 1652 1653
#endif
}

B
bellard 已提交
1654 1655
/* enable or disable single step mode. EXCP_DEBUG is returned by the
   CPU loop after each instruction */
1656
void cpu_single_step(CPUArchState *env, int enabled)
B
bellard 已提交
1657
{
B
bellard 已提交
1658
#if defined(TARGET_HAS_ICE)
B
bellard 已提交
1659 1660
    if (env->singlestep_enabled != enabled) {
        env->singlestep_enabled = enabled;
1661 1662 1663
        if (kvm_enabled())
            kvm_update_guest_debug(env, 0);
        else {
S
Stuart Brady 已提交
1664
            /* must flush all the translated code to avoid inconsistencies */
1665 1666 1667
            /* XXX: only flush what is necessary */
            tb_flush(env);
        }
B
bellard 已提交
1668 1669 1670 1671
    }
#endif
}

1672
static void cpu_unlink_tb(CPUArchState *env)
B
bellard 已提交
1673
{
1674 1675 1676 1677
    /* FIXME: TB unchaining isn't SMP safe.  For now just ignore the
       problem and hope the cpu will stop of its own accord.  For userspace
       emulation this often isn't actually as bad as it sounds.  Often
       signals are used primarily to interrupt blocking syscalls.  */
B
bellard 已提交
1678
    TranslationBlock *tb;
A
Anthony Liguori 已提交
1679
    static spinlock_t interrupt_lock = SPIN_LOCK_UNLOCKED;
1680

R
Riku Voipio 已提交
1681
    spin_lock(&interrupt_lock);
1682 1683 1684
    tb = env->current_tb;
    /* if the cpu is currently executing code, we must unlink it and
       all the potentially executing TB */
1685
    if (tb) {
1686 1687
        env->current_tb = NULL;
        tb_reset_jump_recursive(tb);
1688
    }
R
Riku Voipio 已提交
1689
    spin_unlock(&interrupt_lock);
1690 1691
}

1692
#ifndef CONFIG_USER_ONLY
1693
/* mask must never be zero, except for A20 change call */
1694
static void tcg_handle_interrupt(CPUArchState *env, int mask)
1695 1696
{
    int old_mask;
1697

P
pbrook 已提交
1698
    old_mask = env->interrupt_request;
B
bellard 已提交
1699
    env->interrupt_request |= mask;
1700

1701 1702 1703 1704
    /*
     * If called from iothread context, wake the target cpu in
     * case its halted.
     */
J
Jan Kiszka 已提交
1705
    if (!qemu_cpu_is_self(env)) {
1706 1707 1708 1709
        qemu_cpu_kick(env);
        return;
    }

P
pbrook 已提交
1710
    if (use_icount) {
P
pbrook 已提交
1711
        env->icount_decr.u16.high = 0xffff;
P
pbrook 已提交
1712
        if (!can_do_io(env)
1713
            && (mask & ~old_mask) != 0) {
P
pbrook 已提交
1714 1715 1716
            cpu_abort(env, "Raised interrupt while not in I/O function");
        }
    } else {
1717
        cpu_unlink_tb(env);
B
bellard 已提交
1718 1719 1720
    }
}

1721 1722
CPUInterruptHandler cpu_interrupt_handler = tcg_handle_interrupt;

1723 1724
#else /* CONFIG_USER_ONLY */

1725
void cpu_interrupt(CPUArchState *env, int mask)
1726 1727 1728 1729 1730 1731
{
    env->interrupt_request |= mask;
    cpu_unlink_tb(env);
}
#endif /* CONFIG_USER_ONLY */

1732
void cpu_reset_interrupt(CPUArchState *env, int mask)
1733 1734 1735 1736
{
    env->interrupt_request &= ~mask;
}

1737
void cpu_exit(CPUArchState *env)
1738 1739 1740 1741 1742
{
    env->exit_request = 1;
    cpu_unlink_tb(env);
}

1743
void cpu_abort(CPUArchState *env, const char *fmt, ...)
B
bellard 已提交
1744 1745
{
    va_list ap;
P
pbrook 已提交
1746
    va_list ap2;
B
bellard 已提交
1747 1748

    va_start(ap, fmt);
P
pbrook 已提交
1749
    va_copy(ap2, ap);
B
bellard 已提交
1750 1751 1752
    fprintf(stderr, "qemu: fatal: ");
    vfprintf(stderr, fmt, ap);
    fprintf(stderr, "\n");
1753
    cpu_dump_state(env, stderr, fprintf, CPU_DUMP_FPU | CPU_DUMP_CCOP);
1754 1755 1756 1757
    if (qemu_log_enabled()) {
        qemu_log("qemu: fatal: ");
        qemu_log_vprintf(fmt, ap2);
        qemu_log("\n");
1758
        log_cpu_state(env, CPU_DUMP_FPU | CPU_DUMP_CCOP);
1759
        qemu_log_flush();
1760
        qemu_log_close();
1761
    }
P
pbrook 已提交
1762
    va_end(ap2);
1763
    va_end(ap);
1764 1765 1766 1767 1768 1769 1770 1771
#if defined(CONFIG_USER_ONLY)
    {
        struct sigaction act;
        sigfillset(&act.sa_mask);
        act.sa_handler = SIG_DFL;
        sigaction(SIGABRT, &act, NULL);
    }
#endif
B
bellard 已提交
1772 1773 1774
    abort();
}

1775
CPUArchState *cpu_copy(CPUArchState *env)
1776
{
1777 1778
    CPUArchState *new_env = cpu_init(env->cpu_model_str);
    CPUArchState *next_cpu = new_env->next_cpu;
1779
    int cpu_index = new_env->cpu_index;
1780 1781 1782 1783 1784
#if defined(TARGET_HAS_ICE)
    CPUBreakpoint *bp;
    CPUWatchpoint *wp;
#endif

1785
    memcpy(new_env, env, sizeof(CPUArchState));
1786 1787

    /* Preserve chaining and index. */
1788 1789
    new_env->next_cpu = next_cpu;
    new_env->cpu_index = cpu_index;
1790 1791 1792 1793

    /* Clone all break/watchpoints.
       Note: Once we support ptrace with hw-debug register access, make sure
       BP_CPU break/watchpoints are handled correctly on clone. */
B
Blue Swirl 已提交
1794 1795
    QTAILQ_INIT(&env->breakpoints);
    QTAILQ_INIT(&env->watchpoints);
1796
#if defined(TARGET_HAS_ICE)
B
Blue Swirl 已提交
1797
    QTAILQ_FOREACH(bp, &env->breakpoints, entry) {
1798 1799
        cpu_breakpoint_insert(new_env, bp->pc, bp->flags, NULL);
    }
B
Blue Swirl 已提交
1800
    QTAILQ_FOREACH(wp, &env->watchpoints, entry) {
1801 1802 1803 1804 1805
        cpu_watchpoint_insert(new_env, wp->vaddr, (~wp->len_mask) + 1,
                              wp->flags, NULL);
    }
#endif

1806 1807 1808
    return new_env;
}

1809
#if !defined(CONFIG_USER_ONLY)
1810
void tb_flush_jmp_cache(CPUArchState *env, target_ulong addr)
1811 1812 1813 1814 1815 1816 1817
{
    unsigned int i;

    /* Discard jump cache entries for any tb which might potentially
       overlap the flushed page.  */
    i = tb_jmp_cache_hash_page(addr - TARGET_PAGE_SIZE);
    memset (&env->tb_jmp_cache[i], 0, 
Y
Yoshiaki Tamura 已提交
1818
            TB_JMP_PAGE_SIZE * sizeof(TranslationBlock *));
1819 1820 1821

    i = tb_jmp_cache_hash_page(addr);
    memset (&env->tb_jmp_cache[i], 0, 
Y
Yoshiaki Tamura 已提交
1822
            TB_JMP_PAGE_SIZE * sizeof(TranslationBlock *));
1823 1824
}

J
Juan Quintela 已提交
1825 1826 1827 1828 1829 1830 1831 1832 1833 1834 1835 1836 1837 1838 1839 1840 1841 1842
static void tlb_reset_dirty_range_all(ram_addr_t start, ram_addr_t end,
                                      uintptr_t length)
{
    uintptr_t start1;

    /* we modify the TLB cache so that the dirty bit will be set again
       when accessing the range */
    start1 = (uintptr_t)qemu_safe_ram_ptr(start);
    /* Check that we don't span multiple blocks - this breaks the
       address comparisons below.  */
    if ((uintptr_t)qemu_safe_ram_ptr(end - 1) - start1
            != (end - 1) - start) {
        abort();
    }
    cpu_tlb_reset_dirty_all(start1, length);

}

P
pbrook 已提交
1843
/* Note: start and end must be within the same ram block.  */
A
Anthony Liguori 已提交
1844
void cpu_physical_memory_reset_dirty(ram_addr_t start, ram_addr_t end,
B
bellard 已提交
1845
                                     int dirty_flags)
1846
{
J
Juan Quintela 已提交
1847
    uintptr_t length;
1848 1849 1850 1851 1852 1853 1854

    start &= TARGET_PAGE_MASK;
    end = TARGET_PAGE_ALIGN(end);

    length = end - start;
    if (length == 0)
        return;
1855
    cpu_physical_memory_mask_dirty_range(start, length, dirty_flags);
B
bellard 已提交
1856

J
Juan Quintela 已提交
1857 1858
    if (tcg_enabled()) {
        tlb_reset_dirty_range_all(start, end, length);
P
pbrook 已提交
1859
    }
1860 1861
}

A
aliguori 已提交
1862 1863
int cpu_physical_memory_set_dirty_tracking(int enable)
{
M
Michael S. Tsirkin 已提交
1864
    int ret = 0;
A
aliguori 已提交
1865
    in_migration = enable;
M
Michael S. Tsirkin 已提交
1866
    return ret;
A
aliguori 已提交
1867 1868
}

A
Avi Kivity 已提交
1869
hwaddr memory_region_section_get_iotlb(CPUArchState *env,
B
Blue Swirl 已提交
1870 1871
                                                   MemoryRegionSection *section,
                                                   target_ulong vaddr,
A
Avi Kivity 已提交
1872
                                                   hwaddr paddr,
B
Blue Swirl 已提交
1873 1874 1875
                                                   int prot,
                                                   target_ulong *address)
{
A
Avi Kivity 已提交
1876
    hwaddr iotlb;
B
Blue Swirl 已提交
1877 1878
    CPUWatchpoint *wp;

1879
    if (memory_region_is_ram(section->mr)) {
B
Blue Swirl 已提交
1880 1881
        /* Normal RAM.  */
        iotlb = (memory_region_get_ram_addr(section->mr) & TARGET_PAGE_MASK)
1882
            + memory_region_section_addr(section, paddr);
B
Blue Swirl 已提交
1883 1884 1885 1886 1887 1888 1889 1890 1891 1892 1893 1894 1895
        if (!section->readonly) {
            iotlb |= phys_section_notdirty;
        } else {
            iotlb |= phys_section_rom;
        }
    } else {
        /* IO handlers are currently passed a physical address.
           It would be nice to pass an offset from the base address
           of that region.  This would avoid having to special case RAM,
           and avoid full address decoding in every device.
           We can't use the high bits of pd for this because
           IO_MEM_ROMD uses these as a ram address.  */
        iotlb = section - phys_sections;
1896
        iotlb += memory_region_section_addr(section, paddr);
B
Blue Swirl 已提交
1897 1898 1899 1900 1901 1902 1903 1904 1905 1906 1907 1908 1909 1910 1911 1912 1913 1914
    }

    /* Make accesses to pages with watchpoints go via the
       watchpoint trap routines.  */
    QTAILQ_FOREACH(wp, &env->watchpoints, entry) {
        if (vaddr == (wp->vaddr & TARGET_PAGE_MASK)) {
            /* Avoid trapping reads of pages with a write breakpoint. */
            if ((prot & PAGE_WRITE) || (wp->flags & BP_MEM_READ)) {
                iotlb = phys_section_watch + paddr;
                *address |= TLB_MMIO;
                break;
            }
        }
    }

    return iotlb;
}

1915
#else
1916 1917 1918 1919
/*
 * Walks guest process memory "regions" one by one
 * and calls callback function 'fn' for each region.
 */
1920 1921 1922 1923 1924

struct walk_memory_regions_data
{
    walk_memory_regions_fn fn;
    void *priv;
S
Stefan Weil 已提交
1925
    uintptr_t start;
1926 1927 1928 1929
    int prot;
};

static int walk_memory_regions_end(struct walk_memory_regions_data *data,
P
Paul Brook 已提交
1930
                                   abi_ulong end, int new_prot)
1931 1932 1933 1934 1935 1936 1937 1938 1939 1940 1941 1942 1943 1944 1945
{
    if (data->start != -1ul) {
        int rc = data->fn(data->priv, data->start, end, data->prot);
        if (rc != 0) {
            return rc;
        }
    }

    data->start = (new_prot ? end : -1ul);
    data->prot = new_prot;

    return 0;
}

static int walk_memory_regions_1(struct walk_memory_regions_data *data,
P
Paul Brook 已提交
1946
                                 abi_ulong base, int level, void **lp)
1947
{
P
Paul Brook 已提交
1948
    abi_ulong pa;
1949 1950 1951 1952 1953 1954 1955 1956
    int i, rc;

    if (*lp == NULL) {
        return walk_memory_regions_end(data, base, 0);
    }

    if (level == 0) {
        PageDesc *pd = *lp;
P
Paul Brook 已提交
1957
        for (i = 0; i < L2_SIZE; ++i) {
1958 1959 1960 1961 1962 1963 1964
            int prot = pd[i].flags;

            pa = base | (i << TARGET_PAGE_BITS);
            if (prot != data->prot) {
                rc = walk_memory_regions_end(data, pa, prot);
                if (rc != 0) {
                    return rc;
1965 1966
                }
            }
1967 1968 1969
        }
    } else {
        void **pp = *lp;
P
Paul Brook 已提交
1970
        for (i = 0; i < L2_SIZE; ++i) {
P
Paul Brook 已提交
1971 1972
            pa = base | ((abi_ulong)i <<
                (TARGET_PAGE_BITS + L2_BITS * level));
1973 1974 1975 1976 1977 1978 1979 1980 1981 1982 1983 1984 1985
            rc = walk_memory_regions_1(data, pa, level - 1, pp + i);
            if (rc != 0) {
                return rc;
            }
        }
    }

    return 0;
}

int walk_memory_regions(void *priv, walk_memory_regions_fn fn)
{
    struct walk_memory_regions_data data;
S
Stefan Weil 已提交
1986
    uintptr_t i;
1987 1988 1989 1990 1991 1992 1993

    data.fn = fn;
    data.priv = priv;
    data.start = -1ul;
    data.prot = 0;

    for (i = 0; i < V_L1_SIZE; i++) {
P
Paul Brook 已提交
1994
        int rc = walk_memory_regions_1(&data, (abi_ulong)i << V_L1_SHIFT,
1995 1996 1997
                                       V_L1_SHIFT / L2_BITS - 1, l1_map + i);
        if (rc != 0) {
            return rc;
1998
        }
1999
    }
2000 2001

    return walk_memory_regions_end(&data, 0, 0);
2002 2003
}

P
Paul Brook 已提交
2004 2005
static int dump_region(void *priv, abi_ulong start,
    abi_ulong end, unsigned long prot)
2006 2007 2008
{
    FILE *f = (FILE *)priv;

P
Paul Brook 已提交
2009 2010
    (void) fprintf(f, TARGET_ABI_FMT_lx"-"TARGET_ABI_FMT_lx
        " "TARGET_ABI_FMT_lx" %c%c%c\n",
2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024
        start, end, end - start,
        ((prot & PAGE_READ) ? 'r' : '-'),
        ((prot & PAGE_WRITE) ? 'w' : '-'),
        ((prot & PAGE_EXEC) ? 'x' : '-'));

    return (0);
}

/* dump memory mappings */
void page_dump(FILE *f)
{
    (void) fprintf(f, "%-8s %-8s %-8s %s\n",
            "start", "end", "size", "prot");
    walk_memory_regions(f, dump_region);
2025 2026
}

2027
int page_get_flags(target_ulong address)
2028
{
2029 2030 2031
    PageDesc *p;

    p = page_find(address >> TARGET_PAGE_BITS);
2032
    if (!p)
2033 2034 2035 2036
        return 0;
    return p->flags;
}

2037 2038 2039
/* Modify the flags of a page and invalidate the code if necessary.
   The flag PAGE_WRITE_ORG is positioned automatically depending
   on PAGE_WRITE.  The mmap_lock should already be held.  */
2040
void page_set_flags(target_ulong start, target_ulong end, int flags)
2041
{
2042 2043 2044 2045 2046
    target_ulong addr, len;

    /* This function should never be called with addresses outside the
       guest address space.  If this assert fires, it probably indicates
       a missing call to h2g_valid.  */
P
Paul Brook 已提交
2047 2048
#if TARGET_ABI_BITS > L1_MAP_ADDR_SPACE_BITS
    assert(end < ((abi_ulong)1 << L1_MAP_ADDR_SPACE_BITS));
2049 2050
#endif
    assert(start < end);
2051 2052 2053

    start = start & TARGET_PAGE_MASK;
    end = TARGET_PAGE_ALIGN(end);
2054 2055

    if (flags & PAGE_WRITE) {
2056
        flags |= PAGE_WRITE_ORG;
2057 2058 2059 2060 2061 2062 2063 2064 2065
    }

    for (addr = start, len = end - start;
         len != 0;
         len -= TARGET_PAGE_SIZE, addr += TARGET_PAGE_SIZE) {
        PageDesc *p = page_find_alloc(addr >> TARGET_PAGE_BITS, 1);

        /* If the write protection bit is set, then we invalidate
           the code inside.  */
2066
        if (!(p->flags & PAGE_WRITE) &&
2067 2068
            (flags & PAGE_WRITE) &&
            p->first_tb) {
B
bellard 已提交
2069
            tb_invalidate_phys_page(addr, 0, NULL);
2070 2071 2072
        }
        p->flags = flags;
    }
2073 2074
}

2075 2076 2077 2078 2079 2080
int page_check_range(target_ulong start, target_ulong len, int flags)
{
    PageDesc *p;
    target_ulong end;
    target_ulong addr;

2081 2082 2083
    /* This function should never be called with addresses outside the
       guest address space.  If this assert fires, it probably indicates
       a missing call to h2g_valid.  */
2084 2085
#if TARGET_ABI_BITS > L1_MAP_ADDR_SPACE_BITS
    assert(start < ((abi_ulong)1 << L1_MAP_ADDR_SPACE_BITS));
2086 2087
#endif

R
Richard Henderson 已提交
2088 2089 2090
    if (len == 0) {
        return 0;
    }
2091 2092
    if (start + len - 1 < start) {
        /* We've wrapped around.  */
2093
        return -1;
2094
    }
2095

2096 2097 2098
    end = TARGET_PAGE_ALIGN(start+len); /* must do before we loose bits in the next step */
    start = start & TARGET_PAGE_MASK;

2099 2100 2101
    for (addr = start, len = end - start;
         len != 0;
         len -= TARGET_PAGE_SIZE, addr += TARGET_PAGE_SIZE) {
2102 2103 2104 2105 2106 2107
        p = page_find(addr >> TARGET_PAGE_BITS);
        if( !p )
            return -1;
        if( !(p->flags & PAGE_VALID) )
            return -1;

2108
        if ((flags & PAGE_READ) && !(p->flags & PAGE_READ))
2109
            return -1;
2110 2111 2112 2113 2114 2115 2116 2117 2118 2119 2120
        if (flags & PAGE_WRITE) {
            if (!(p->flags & PAGE_WRITE_ORG))
                return -1;
            /* unprotect the page if it was put read-only because it
               contains translated code */
            if (!(p->flags & PAGE_WRITE)) {
                if (!page_unprotect(addr, 0, NULL))
                    return -1;
            }
            return 0;
        }
2121 2122 2123 2124
    }
    return 0;
}

2125
/* called from signal handler: invalidate the code and unprotect the
S
Stuart Brady 已提交
2126
   page. Return TRUE if the fault was successfully handled. */
2127
int page_unprotect(target_ulong address, uintptr_t pc, void *puc)
2128
{
2129 2130
    unsigned int prot;
    PageDesc *p;
2131
    target_ulong host_start, host_end, addr;
2132

P
pbrook 已提交
2133 2134 2135 2136 2137
    /* Technically this isn't safe inside a signal handler.  However we
       know this only ever happens in a synchronous SEGV handler, so in
       practice it seems to be ok.  */
    mmap_lock();

2138 2139
    p = page_find(address >> TARGET_PAGE_BITS);
    if (!p) {
P
pbrook 已提交
2140
        mmap_unlock();
2141
        return 0;
P
pbrook 已提交
2142
    }
2143

2144 2145
    /* if the page was really writable, then we change its
       protection back to writable */
2146 2147 2148 2149 2150 2151 2152 2153 2154 2155
    if ((p->flags & PAGE_WRITE_ORG) && !(p->flags & PAGE_WRITE)) {
        host_start = address & qemu_host_page_mask;
        host_end = host_start + qemu_host_page_size;

        prot = 0;
        for (addr = host_start ; addr < host_end ; addr += TARGET_PAGE_SIZE) {
            p = page_find(addr >> TARGET_PAGE_BITS);
            p->flags |= PAGE_WRITE;
            prot |= p->flags;

2156 2157
            /* and since the content will be modified, we must invalidate
               the corresponding translated code. */
2158
            tb_invalidate_phys_page(addr, pc, puc);
2159
#ifdef DEBUG_TB_CHECK
2160
            tb_invalidate_check(addr);
2161 2162
#endif
        }
2163 2164 2165 2166 2167
        mprotect((void *)g2h(host_start), qemu_host_page_size,
                 prot & PAGE_BITS);

        mmap_unlock();
        return 1;
2168
    }
P
pbrook 已提交
2169
    mmap_unlock();
2170 2171 2172 2173
    return 0;
}
#endif /* defined(CONFIG_USER_ONLY) */

2174
#if !defined(CONFIG_USER_ONLY)
2175

P
Paul Brook 已提交
2176 2177
#define SUBPAGE_IDX(addr) ((addr) & ~TARGET_PAGE_MASK)
typedef struct subpage_t {
2178
    MemoryRegion iomem;
A
Avi Kivity 已提交
2179
    hwaddr base;
2180
    uint16_t sub_section[TARGET_PAGE_SIZE];
P
Paul Brook 已提交
2181 2182
} subpage_t;

A
Anthony Liguori 已提交
2183
static int subpage_register (subpage_t *mmio, uint32_t start, uint32_t end,
2184
                             uint16_t section);
A
Avi Kivity 已提交
2185
static subpage_t *subpage_init(hwaddr base);
2186
static void destroy_page_desc(uint16_t section_index)
2187
{
2188 2189
    MemoryRegionSection *section = &phys_sections[section_index];
    MemoryRegion *mr = section->mr;
2190 2191 2192 2193 2194 2195 2196 2197

    if (mr->subpage) {
        subpage_t *subpage = container_of(mr, subpage_t, iomem);
        memory_region_destroy(&subpage->iomem);
        g_free(subpage);
    }
}

2198
static void destroy_l2_mapping(PhysPageEntry *lp, unsigned level)
2199 2200
{
    unsigned i;
2201
    PhysPageEntry *p;
2202

2203
    if (lp->ptr == PHYS_MAP_NODE_NIL) {
2204 2205 2206
        return;
    }

2207
    p = phys_map_nodes[lp->ptr];
2208
    for (i = 0; i < L2_SIZE; ++i) {
2209
        if (!p[i].is_leaf) {
2210
            destroy_l2_mapping(&p[i], level - 1);
2211
        } else {
2212
            destroy_page_desc(p[i].ptr);
2213 2214
        }
    }
2215
    lp->is_leaf = 0;
2216
    lp->ptr = PHYS_MAP_NODE_NIL;
2217 2218
}

A
Avi Kivity 已提交
2219
static void destroy_all_mappings(AddressSpaceDispatch *d)
2220
{
A
Avi Kivity 已提交
2221
    destroy_l2_mapping(&d->phys_map, P_L2_LEVELS - 1);
2222
    phys_map_nodes_reset();
2223 2224
}

2225 2226 2227 2228 2229 2230 2231 2232 2233 2234 2235 2236 2237 2238 2239 2240
static uint16_t phys_section_add(MemoryRegionSection *section)
{
    if (phys_sections_nb == phys_sections_nb_alloc) {
        phys_sections_nb_alloc = MAX(phys_sections_nb_alloc * 2, 16);
        phys_sections = g_renew(MemoryRegionSection, phys_sections,
                                phys_sections_nb_alloc);
    }
    phys_sections[phys_sections_nb] = *section;
    return phys_sections_nb++;
}

static void phys_sections_clear(void)
{
    phys_sections_nb = 0;
}

A
Avi Kivity 已提交
2241
static void register_subpage(AddressSpaceDispatch *d, MemoryRegionSection *section)
2242 2243
{
    subpage_t *subpage;
A
Avi Kivity 已提交
2244
    hwaddr base = section->offset_within_address_space
2245
        & TARGET_PAGE_MASK;
A
Avi Kivity 已提交
2246
    MemoryRegionSection *existing = phys_page_find(d, base >> TARGET_PAGE_BITS);
2247 2248 2249 2250
    MemoryRegionSection subsection = {
        .offset_within_address_space = base,
        .size = TARGET_PAGE_SIZE,
    };
A
Avi Kivity 已提交
2251
    hwaddr start, end;
2252

2253
    assert(existing->mr->subpage || existing->mr == &io_mem_unassigned);
2254

2255
    if (!(existing->mr->subpage)) {
2256 2257
        subpage = subpage_init(base);
        subsection.mr = &subpage->iomem;
A
Avi Kivity 已提交
2258
        phys_page_set(d, base >> TARGET_PAGE_BITS, 1,
2259
                      phys_section_add(&subsection));
2260
    } else {
2261
        subpage = container_of(existing->mr, subpage_t, iomem);
2262 2263
    }
    start = section->offset_within_address_space & ~TARGET_PAGE_MASK;
2264
    end = start + section->size - 1;
2265 2266 2267 2268
    subpage_register(subpage, start, end, phys_section_add(section));
}


A
Avi Kivity 已提交
2269
static void register_multipage(AddressSpaceDispatch *d, MemoryRegionSection *section)
2270
{
A
Avi Kivity 已提交
2271
    hwaddr start_addr = section->offset_within_address_space;
2272
    ram_addr_t size = section->size;
A
Avi Kivity 已提交
2273
    hwaddr addr;
2274
    uint16_t section_index = phys_section_add(section);
2275

2276
    assert(size);
M
Michael S. Tsirkin 已提交
2277

2278
    addr = start_addr;
A
Avi Kivity 已提交
2279
    phys_page_set(d, addr >> TARGET_PAGE_BITS, size >> TARGET_PAGE_BITS,
2280
                  section_index);
2281 2282
}

A
Avi Kivity 已提交
2283
static void mem_add(MemoryListener *listener, MemoryRegionSection *section)
2284
{
A
Avi Kivity 已提交
2285
    AddressSpaceDispatch *d = container_of(listener, AddressSpaceDispatch, listener);
2286 2287 2288 2289 2290 2291 2292
    MemoryRegionSection now = *section, remain = *section;

    if ((now.offset_within_address_space & ~TARGET_PAGE_MASK)
        || (now.size < TARGET_PAGE_SIZE)) {
        now.size = MIN(TARGET_PAGE_ALIGN(now.offset_within_address_space)
                       - now.offset_within_address_space,
                       now.size);
A
Avi Kivity 已提交
2293
        register_subpage(d, &now);
2294 2295 2296 2297
        remain.size -= now.size;
        remain.offset_within_address_space += now.size;
        remain.offset_within_region += now.size;
    }
2298 2299 2300 2301
    while (remain.size >= TARGET_PAGE_SIZE) {
        now = remain;
        if (remain.offset_within_region & ~TARGET_PAGE_MASK) {
            now.size = TARGET_PAGE_SIZE;
A
Avi Kivity 已提交
2302
            register_subpage(d, &now);
2303 2304
        } else {
            now.size &= TARGET_PAGE_MASK;
A
Avi Kivity 已提交
2305
            register_multipage(d, &now);
2306
        }
2307 2308 2309 2310 2311 2312
        remain.size -= now.size;
        remain.offset_within_address_space += now.size;
        remain.offset_within_region += now.size;
    }
    now = remain;
    if (now.size) {
A
Avi Kivity 已提交
2313
        register_subpage(d, &now);
2314 2315 2316
    }
}

2317 2318 2319 2320 2321 2322
void qemu_flush_coalesced_mmio_buffer(void)
{
    if (kvm_enabled())
        kvm_flush_coalesced_mmio_buffer();
}

2323 2324 2325 2326 2327 2328 2329 2330 2331 2332 2333 2334
#if defined(__linux__) && !defined(TARGET_S390X)

#include <sys/vfs.h>

#define HUGETLBFS_MAGIC       0x958458f6

static long gethugepagesize(const char *path)
{
    struct statfs fs;
    int ret;

    do {
Y
Yoshiaki Tamura 已提交
2335
        ret = statfs(path, &fs);
2336 2337 2338
    } while (ret != 0 && errno == EINTR);

    if (ret != 0) {
Y
Yoshiaki Tamura 已提交
2339 2340
        perror(path);
        return 0;
2341 2342 2343
    }

    if (fs.f_type != HUGETLBFS_MAGIC)
Y
Yoshiaki Tamura 已提交
2344
        fprintf(stderr, "Warning: path not on HugeTLBFS: %s\n", path);
2345 2346 2347 2348

    return fs.f_bsize;
}

A
Alex Williamson 已提交
2349 2350 2351
static void *file_ram_alloc(RAMBlock *block,
                            ram_addr_t memory,
                            const char *path)
2352 2353 2354 2355 2356 2357 2358 2359 2360 2361 2362
{
    char *filename;
    void *area;
    int fd;
#ifdef MAP_POPULATE
    int flags;
#endif
    unsigned long hpagesize;

    hpagesize = gethugepagesize(path);
    if (!hpagesize) {
Y
Yoshiaki Tamura 已提交
2363
        return NULL;
2364 2365 2366 2367 2368 2369 2370 2371 2372 2373 2374 2375
    }

    if (memory < hpagesize) {
        return NULL;
    }

    if (kvm_enabled() && !kvm_has_sync_mmu()) {
        fprintf(stderr, "host lacks kvm mmu notifiers, -mem-path unsupported\n");
        return NULL;
    }

    if (asprintf(&filename, "%s/qemu_back_mem.XXXXXX", path) == -1) {
Y
Yoshiaki Tamura 已提交
2376
        return NULL;
2377 2378 2379 2380
    }

    fd = mkstemp(filename);
    if (fd < 0) {
Y
Yoshiaki Tamura 已提交
2381 2382 2383
        perror("unable to create backing store for hugepages");
        free(filename);
        return NULL;
2384 2385 2386 2387 2388 2389 2390 2391 2392 2393 2394 2395 2396
    }
    unlink(filename);
    free(filename);

    memory = (memory+hpagesize-1) & ~(hpagesize-1);

    /*
     * ftruncate is not supported by hugetlbfs in older
     * hosts, so don't bother bailing out on errors.
     * If anything goes wrong with it under other filesystems,
     * mmap will fail.
     */
    if (ftruncate(fd, memory))
Y
Yoshiaki Tamura 已提交
2397
        perror("ftruncate");
2398 2399 2400 2401 2402 2403 2404 2405 2406 2407 2408 2409

#ifdef MAP_POPULATE
    /* NB: MAP_POPULATE won't exhaustively alloc all phys pages in the case
     * MAP_PRIVATE is requested.  For mem_prealloc we mmap as MAP_SHARED
     * to sidestep this quirk.
     */
    flags = mem_prealloc ? MAP_POPULATE | MAP_SHARED : MAP_PRIVATE;
    area = mmap(0, memory, PROT_READ | PROT_WRITE, flags, fd, 0);
#else
    area = mmap(0, memory, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);
#endif
    if (area == MAP_FAILED) {
Y
Yoshiaki Tamura 已提交
2410 2411 2412
        perror("file_ram_alloc: can't mmap RAM pages");
        close(fd);
        return (NULL);
2413
    }
A
Alex Williamson 已提交
2414
    block->fd = fd;
2415 2416 2417 2418
    return area;
}
#endif

2419
static ram_addr_t find_ram_offset(ram_addr_t size)
A
Alex Williamson 已提交
2420 2421
{
    RAMBlock *block, *next_block;
A
Alex Williamson 已提交
2422
    ram_addr_t offset = RAM_ADDR_MAX, mingap = RAM_ADDR_MAX;
A
Alex Williamson 已提交
2423 2424 2425 2426 2427

    if (QLIST_EMPTY(&ram_list.blocks))
        return 0;

    QLIST_FOREACH(block, &ram_list.blocks, next) {
2428
        ram_addr_t end, next = RAM_ADDR_MAX;
A
Alex Williamson 已提交
2429 2430 2431 2432 2433 2434 2435 2436 2437

        end = block->offset + block->length;

        QLIST_FOREACH(next_block, &ram_list.blocks, next) {
            if (next_block->offset >= end) {
                next = MIN(next, next_block->offset);
            }
        }
        if (next - end >= size && next - end < mingap) {
A
Alex Williamson 已提交
2438
            offset = end;
A
Alex Williamson 已提交
2439 2440 2441
            mingap = next - end;
        }
    }
A
Alex Williamson 已提交
2442 2443 2444 2445 2446 2447 2448

    if (offset == RAM_ADDR_MAX) {
        fprintf(stderr, "Failed to find gap of requested size: %" PRIu64 "\n",
                (uint64_t)size);
        abort();
    }

A
Alex Williamson 已提交
2449 2450 2451
    return offset;
}

J
Juan Quintela 已提交
2452
ram_addr_t last_ram_offset(void)
2453 2454 2455 2456 2457 2458 2459 2460 2461 2462
{
    RAMBlock *block;
    ram_addr_t last = 0;

    QLIST_FOREACH(block, &ram_list.blocks, next)
        last = MAX(last, block->offset + block->length);

    return last;
}

2463 2464 2465 2466 2467 2468 2469 2470 2471 2472 2473 2474 2475 2476 2477 2478 2479 2480
static void qemu_ram_setup_dump(void *addr, ram_addr_t size)
{
    int ret;
    QemuOpts *machine_opts;

    /* Use MADV_DONTDUMP, if user doesn't want the guest memory in the core */
    machine_opts = qemu_opts_find(qemu_find_opts("machine"), 0);
    if (machine_opts &&
        !qemu_opt_get_bool(machine_opts, "dump-guest-core", true)) {
        ret = qemu_madvise(addr, size, QEMU_MADV_DONTDUMP);
        if (ret) {
            perror("qemu_madvise");
            fprintf(stderr, "madvise doesn't support MADV_DONTDUMP, "
                            "but dump_guest_core=off specified\n");
        }
    }
}

2481
void qemu_ram_set_idstr(ram_addr_t addr, const char *name, DeviceState *dev)
2482 2483 2484
{
    RAMBlock *new_block, *block;

2485 2486 2487 2488 2489 2490 2491 2492 2493
    new_block = NULL;
    QLIST_FOREACH(block, &ram_list.blocks, next) {
        if (block->offset == addr) {
            new_block = block;
            break;
        }
    }
    assert(new_block);
    assert(!new_block->idstr[0]);
2494

2495 2496
    if (dev) {
        char *id = qdev_get_dev_path(dev);
2497 2498
        if (id) {
            snprintf(new_block->idstr, sizeof(new_block->idstr), "%s/", id);
2499
            g_free(id);
2500 2501 2502 2503 2504
        }
    }
    pstrcat(new_block->idstr, sizeof(new_block->idstr), name);

    QLIST_FOREACH(block, &ram_list.blocks, next) {
2505
        if (block != new_block && !strcmp(block->idstr, new_block->idstr)) {
2506 2507 2508 2509 2510
            fprintf(stderr, "RAMBlock \"%s\" already registered, abort!\n",
                    new_block->idstr);
            abort();
        }
    }
2511 2512
}

2513 2514 2515 2516 2517 2518 2519 2520 2521 2522 2523 2524 2525
static int memory_try_enable_merging(void *addr, size_t len)
{
    QemuOpts *opts;

    opts = qemu_opts_find(qemu_find_opts("machine"), 0);
    if (opts && !qemu_opt_get_bool(opts, "mem-merge", true)) {
        /* disabled by the user */
        return 0;
    }

    return qemu_madvise(addr, len, QEMU_MADV_MERGEABLE);
}

2526 2527 2528 2529 2530 2531 2532
ram_addr_t qemu_ram_alloc_from_ptr(ram_addr_t size, void *host,
                                   MemoryRegion *mr)
{
    RAMBlock *new_block;

    size = TARGET_PAGE_ALIGN(size);
    new_block = g_malloc0(sizeof(*new_block));
2533

A
Avi Kivity 已提交
2534
    new_block->mr = mr;
J
Jun Nakajima 已提交
2535
    new_block->offset = find_ram_offset(size);
2536 2537
    if (host) {
        new_block->host = host;
H
Huang Ying 已提交
2538
        new_block->flags |= RAM_PREALLOC_MASK;
2539 2540
    } else {
        if (mem_path) {
2541
#if defined (__linux__) && !defined(TARGET_S390X)
2542 2543 2544
            new_block->host = file_ram_alloc(new_block, size, mem_path);
            if (!new_block->host) {
                new_block->host = qemu_vmalloc(size);
2545
                memory_try_enable_merging(new_block->host, size);
2546
            }
2547
#else
2548 2549
            fprintf(stderr, "-mem-path option unsupported\n");
            exit(1);
2550
#endif
2551
        } else {
2552
            if (xen_enabled()) {
2553
                xen_ram_alloc(new_block->offset, size, mr);
2554 2555 2556
            } else if (kvm_enabled()) {
                /* some s390/kvm configurations have special constraints */
                new_block->host = kvm_vmalloc(size);
J
Jun Nakajima 已提交
2557 2558 2559
            } else {
                new_block->host = qemu_vmalloc(size);
            }
2560
            memory_try_enable_merging(new_block->host, size);
2561
        }
2562
    }
P
pbrook 已提交
2563 2564
    new_block->length = size;

A
Alex Williamson 已提交
2565
    QLIST_INSERT_HEAD(&ram_list.blocks, new_block, next);
P
pbrook 已提交
2566

2567
    ram_list.phys_dirty = g_realloc(ram_list.phys_dirty,
A
Alex Williamson 已提交
2568
                                       last_ram_offset() >> TARGET_PAGE_BITS);
2569 2570
    memset(ram_list.phys_dirty + (new_block->offset >> TARGET_PAGE_BITS),
           0, size >> TARGET_PAGE_BITS);
J
Juan Quintela 已提交
2571
    cpu_physical_memory_set_dirty_range(new_block->offset, size, 0xff);
P
pbrook 已提交
2572

2573
    qemu_ram_setup_dump(new_block->host, size);
2574
    qemu_madvise(new_block->host, size, QEMU_MADV_HUGEPAGE);
2575

2576 2577 2578
    if (kvm_enabled())
        kvm_setup_guest_memory(new_block->host, size);

P
pbrook 已提交
2579 2580
    return new_block->offset;
}
B
bellard 已提交
2581

2582
ram_addr_t qemu_ram_alloc(ram_addr_t size, MemoryRegion *mr)
2583
{
2584
    return qemu_ram_alloc_from_ptr(size, NULL, mr);
2585 2586
}

2587 2588 2589 2590 2591 2592 2593
void qemu_ram_free_from_ptr(ram_addr_t addr)
{
    RAMBlock *block;

    QLIST_FOREACH(block, &ram_list.blocks, next) {
        if (addr == block->offset) {
            QLIST_REMOVE(block, next);
2594
            g_free(block);
2595 2596 2597 2598 2599
            return;
        }
    }
}

A
Anthony Liguori 已提交
2600
void qemu_ram_free(ram_addr_t addr)
B
bellard 已提交
2601
{
A
Alex Williamson 已提交
2602 2603 2604 2605 2606
    RAMBlock *block;

    QLIST_FOREACH(block, &ram_list.blocks, next) {
        if (addr == block->offset) {
            QLIST_REMOVE(block, next);
H
Huang Ying 已提交
2607 2608 2609
            if (block->flags & RAM_PREALLOC_MASK) {
                ;
            } else if (mem_path) {
A
Alex Williamson 已提交
2610 2611 2612 2613 2614 2615 2616
#if defined (__linux__) && !defined(TARGET_S390X)
                if (block->fd) {
                    munmap(block->host, block->length);
                    close(block->fd);
                } else {
                    qemu_vfree(block->host);
                }
2617 2618
#else
                abort();
A
Alex Williamson 已提交
2619 2620 2621 2622 2623
#endif
            } else {
#if defined(TARGET_S390X) && defined(CONFIG_KVM)
                munmap(block->host, block->length);
#else
2624
                if (xen_enabled()) {
J
Jan Kiszka 已提交
2625
                    xen_invalidate_map_cache_entry(block->host);
J
Jun Nakajima 已提交
2626 2627 2628
                } else {
                    qemu_vfree(block->host);
                }
A
Alex Williamson 已提交
2629 2630
#endif
            }
2631
            g_free(block);
A
Alex Williamson 已提交
2632 2633 2634 2635
            return;
        }
    }

B
bellard 已提交
2636 2637
}

H
Huang Ying 已提交
2638 2639 2640 2641 2642 2643 2644 2645 2646 2647 2648 2649 2650 2651 2652 2653 2654 2655 2656 2657 2658 2659 2660 2661 2662 2663 2664 2665 2666 2667 2668 2669 2670
#ifndef _WIN32
void qemu_ram_remap(ram_addr_t addr, ram_addr_t length)
{
    RAMBlock *block;
    ram_addr_t offset;
    int flags;
    void *area, *vaddr;

    QLIST_FOREACH(block, &ram_list.blocks, next) {
        offset = addr - block->offset;
        if (offset < block->length) {
            vaddr = block->host + offset;
            if (block->flags & RAM_PREALLOC_MASK) {
                ;
            } else {
                flags = MAP_FIXED;
                munmap(vaddr, length);
                if (mem_path) {
#if defined(__linux__) && !defined(TARGET_S390X)
                    if (block->fd) {
#ifdef MAP_POPULATE
                        flags |= mem_prealloc ? MAP_POPULATE | MAP_SHARED :
                            MAP_PRIVATE;
#else
                        flags |= MAP_PRIVATE;
#endif
                        area = mmap(vaddr, length, PROT_READ | PROT_WRITE,
                                    flags, block->fd, offset);
                    } else {
                        flags |= MAP_PRIVATE | MAP_ANONYMOUS;
                        area = mmap(vaddr, length, PROT_READ | PROT_WRITE,
                                    flags, -1, 0);
                    }
2671 2672
#else
                    abort();
H
Huang Ying 已提交
2673 2674 2675 2676 2677 2678 2679 2680 2681 2682 2683 2684 2685
#endif
                } else {
#if defined(TARGET_S390X) && defined(CONFIG_KVM)
                    flags |= MAP_SHARED | MAP_ANONYMOUS;
                    area = mmap(vaddr, length, PROT_EXEC|PROT_READ|PROT_WRITE,
                                flags, -1, 0);
#else
                    flags |= MAP_PRIVATE | MAP_ANONYMOUS;
                    area = mmap(vaddr, length, PROT_READ | PROT_WRITE,
                                flags, -1, 0);
#endif
                }
                if (area != vaddr) {
2686 2687
                    fprintf(stderr, "Could not remap addr: "
                            RAM_ADDR_FMT "@" RAM_ADDR_FMT "\n",
H
Huang Ying 已提交
2688 2689 2690
                            length, addr);
                    exit(1);
                }
2691
                memory_try_enable_merging(vaddr, length);
2692
                qemu_ram_setup_dump(vaddr, length);
H
Huang Ying 已提交
2693 2694 2695 2696 2697 2698 2699
            }
            return;
        }
    }
}
#endif /* !_WIN32 */

2700
/* Return a host pointer to ram allocated with qemu_ram_alloc.
P
pbrook 已提交
2701 2702 2703 2704 2705 2706 2707
   With the exception of the softmmu code in this file, this should
   only be used for local memory (e.g. video ram) that the device owns,
   and knows it isn't going to access beyond the end of the block.

   It should not be used for general purpose DMA.
   Use cpu_physical_memory_map/cpu_physical_memory_rw instead.
 */
A
Anthony Liguori 已提交
2708
void *qemu_get_ram_ptr(ram_addr_t addr)
2709
{
P
pbrook 已提交
2710 2711
    RAMBlock *block;

A
Alex Williamson 已提交
2712 2713
    QLIST_FOREACH(block, &ram_list.blocks, next) {
        if (addr - block->offset < block->length) {
2714 2715 2716 2717 2718
            /* Move this entry to to start of the list.  */
            if (block != QLIST_FIRST(&ram_list.blocks)) {
                QLIST_REMOVE(block, next);
                QLIST_INSERT_HEAD(&ram_list.blocks, block, next);
            }
2719
            if (xen_enabled()) {
J
Jun Nakajima 已提交
2720 2721
                /* We need to check if the requested address is in the RAM
                 * because we don't want to map the entire memory in QEMU.
2722
                 * In that case just map until the end of the page.
J
Jun Nakajima 已提交
2723 2724
                 */
                if (block->offset == 0) {
J
Jan Kiszka 已提交
2725
                    return xen_map_cache(addr, 0, 0);
J
Jun Nakajima 已提交
2726
                } else if (block->host == NULL) {
J
Jan Kiszka 已提交
2727 2728
                    block->host =
                        xen_map_cache(block->offset, block->length, 1);
J
Jun Nakajima 已提交
2729 2730
                }
            }
A
Alex Williamson 已提交
2731 2732
            return block->host + (addr - block->offset);
        }
P
pbrook 已提交
2733
    }
A
Alex Williamson 已提交
2734 2735 2736 2737 2738

    fprintf(stderr, "Bad ram offset %" PRIx64 "\n", (uint64_t)addr);
    abort();

    return NULL;
2739 2740
}

2741 2742 2743 2744 2745 2746 2747 2748 2749
/* Return a host pointer to ram allocated with qemu_ram_alloc.
 * Same as qemu_get_ram_ptr but avoid reordering ramblocks.
 */
void *qemu_safe_ram_ptr(ram_addr_t addr)
{
    RAMBlock *block;

    QLIST_FOREACH(block, &ram_list.blocks, next) {
        if (addr - block->offset < block->length) {
2750
            if (xen_enabled()) {
J
Jun Nakajima 已提交
2751 2752
                /* We need to check if the requested address is in the RAM
                 * because we don't want to map the entire memory in QEMU.
2753
                 * In that case just map until the end of the page.
J
Jun Nakajima 已提交
2754 2755
                 */
                if (block->offset == 0) {
J
Jan Kiszka 已提交
2756
                    return xen_map_cache(addr, 0, 0);
J
Jun Nakajima 已提交
2757
                } else if (block->host == NULL) {
J
Jan Kiszka 已提交
2758 2759
                    block->host =
                        xen_map_cache(block->offset, block->length, 1);
J
Jun Nakajima 已提交
2760 2761
                }
            }
2762 2763 2764 2765 2766 2767 2768 2769 2770 2771
            return block->host + (addr - block->offset);
        }
    }

    fprintf(stderr, "Bad ram offset %" PRIx64 "\n", (uint64_t)addr);
    abort();

    return NULL;
}

2772 2773
/* Return a host pointer to guest's ram. Similar to qemu_get_ram_ptr
 * but takes a size argument */
2774
void *qemu_ram_ptr_length(ram_addr_t addr, ram_addr_t *size)
2775
{
2776 2777 2778
    if (*size == 0) {
        return NULL;
    }
2779
    if (xen_enabled()) {
J
Jan Kiszka 已提交
2780
        return xen_map_cache(addr, *size, 1);
2781
    } else {
2782 2783 2784 2785 2786 2787 2788 2789 2790 2791 2792 2793 2794 2795 2796
        RAMBlock *block;

        QLIST_FOREACH(block, &ram_list.blocks, next) {
            if (addr - block->offset < block->length) {
                if (addr - block->offset + *size > block->length)
                    *size = block->length - addr + block->offset;
                return block->host + (addr - block->offset);
            }
        }

        fprintf(stderr, "Bad ram offset %" PRIx64 "\n", (uint64_t)addr);
        abort();
    }
}

A
Anthony PERARD 已提交
2797 2798 2799 2800 2801
void qemu_put_ram_ptr(void *addr)
{
    trace_qemu_put_ram_ptr(addr);
}

M
Marcelo Tosatti 已提交
2802
int qemu_ram_addr_from_host(void *ptr, ram_addr_t *ram_addr)
P
pbrook 已提交
2803
{
P
pbrook 已提交
2804 2805 2806
    RAMBlock *block;
    uint8_t *host = ptr;

2807
    if (xen_enabled()) {
J
Jan Kiszka 已提交
2808
        *ram_addr = xen_ram_addr_from_mapcache(ptr);
2809 2810 2811
        return 0;
    }

A
Alex Williamson 已提交
2812
    QLIST_FOREACH(block, &ram_list.blocks, next) {
J
Jun Nakajima 已提交
2813 2814 2815 2816
        /* This case append when the block is not mapped. */
        if (block->host == NULL) {
            continue;
        }
A
Alex Williamson 已提交
2817
        if (host - block->host < block->length) {
M
Marcelo Tosatti 已提交
2818 2819
            *ram_addr = block->offset + (host - block->host);
            return 0;
A
Alex Williamson 已提交
2820
        }
P
pbrook 已提交
2821
    }
J
Jun Nakajima 已提交
2822

M
Marcelo Tosatti 已提交
2823 2824
    return -1;
}
A
Alex Williamson 已提交
2825

M
Marcelo Tosatti 已提交
2826 2827 2828 2829 2830
/* Some of the softmmu routines need to translate from a host pointer
   (typically a TLB entry) back to a ram offset.  */
ram_addr_t qemu_ram_addr_from_host_nofail(void *ptr)
{
    ram_addr_t ram_addr;
A
Alex Williamson 已提交
2831

M
Marcelo Tosatti 已提交
2832 2833 2834 2835 2836
    if (qemu_ram_addr_from_host(ptr, &ram_addr)) {
        fprintf(stderr, "Bad ram pointer %p\n", ptr);
        abort();
    }
    return ram_addr;
P
pbrook 已提交
2837 2838
}

A
Avi Kivity 已提交
2839
static uint64_t unassigned_mem_read(void *opaque, hwaddr addr,
2840
                                    unsigned size)
2841 2842 2843 2844
{
#ifdef DEBUG_UNASSIGNED
    printf("Unassigned mem read " TARGET_FMT_plx "\n", addr);
#endif
2845
#if defined(TARGET_ALPHA) || defined(TARGET_SPARC) || defined(TARGET_MICROBLAZE)
2846
    cpu_unassigned_access(cpu_single_env, addr, 0, 0, 0, size);
2847 2848 2849 2850
#endif
    return 0;
}

A
Avi Kivity 已提交
2851
static void unassigned_mem_write(void *opaque, hwaddr addr,
2852
                                 uint64_t val, unsigned size)
2853 2854
{
#ifdef DEBUG_UNASSIGNED
2855
    printf("Unassigned mem write " TARGET_FMT_plx " = 0x%"PRIx64"\n", addr, val);
2856
#endif
2857
#if defined(TARGET_ALPHA) || defined(TARGET_SPARC) || defined(TARGET_MICROBLAZE)
2858
    cpu_unassigned_access(cpu_single_env, addr, 1, 0, 0, size);
P
pbrook 已提交
2859
#endif
2860 2861
}

2862 2863 2864 2865 2866
static const MemoryRegionOps unassigned_mem_ops = {
    .read = unassigned_mem_read,
    .write = unassigned_mem_write,
    .endianness = DEVICE_NATIVE_ENDIAN,
};
2867

A
Avi Kivity 已提交
2868
static uint64_t error_mem_read(void *opaque, hwaddr addr,
2869
                               unsigned size)
2870
{
2871
    abort();
2872 2873
}

A
Avi Kivity 已提交
2874
static void error_mem_write(void *opaque, hwaddr addr,
2875
                            uint64_t value, unsigned size)
2876
{
2877
    abort();
2878 2879
}

2880 2881 2882 2883
static const MemoryRegionOps error_mem_ops = {
    .read = error_mem_read,
    .write = error_mem_write,
    .endianness = DEVICE_NATIVE_ENDIAN,
2884 2885
};

2886 2887 2888 2889
static const MemoryRegionOps rom_mem_ops = {
    .read = error_mem_read,
    .write = unassigned_mem_write,
    .endianness = DEVICE_NATIVE_ENDIAN,
2890 2891
};

A
Avi Kivity 已提交
2892
static void notdirty_mem_write(void *opaque, hwaddr ram_addr,
2893
                               uint64_t val, unsigned size)
2894
{
2895
    int dirty_flags;
2896
    dirty_flags = cpu_physical_memory_get_dirty_flags(ram_addr);
2897
    if (!(dirty_flags & CODE_DIRTY_FLAG)) {
2898
#if !defined(CONFIG_USER_ONLY)
2899
        tb_invalidate_phys_page_fast(ram_addr, size);
2900
        dirty_flags = cpu_physical_memory_get_dirty_flags(ram_addr);
2901
#endif
2902
    }
2903 2904 2905 2906 2907 2908 2909 2910 2911 2912 2913 2914
    switch (size) {
    case 1:
        stb_p(qemu_get_ram_ptr(ram_addr), val);
        break;
    case 2:
        stw_p(qemu_get_ram_ptr(ram_addr), val);
        break;
    case 4:
        stl_p(qemu_get_ram_ptr(ram_addr), val);
        break;
    default:
        abort();
2915
    }
B
bellard 已提交
2916
    dirty_flags |= (0xff & ~CODE_DIRTY_FLAG);
2917
    cpu_physical_memory_set_dirty_flags(ram_addr, dirty_flags);
B
bellard 已提交
2918 2919 2920
    /* we remove the notdirty callback only if the code has been
       flushed */
    if (dirty_flags == 0xff)
P
pbrook 已提交
2921
        tlb_set_dirty(cpu_single_env, cpu_single_env->mem_io_vaddr);
2922 2923
}

2924 2925 2926 2927
static const MemoryRegionOps notdirty_mem_ops = {
    .read = error_mem_read,
    .write = notdirty_mem_write,
    .endianness = DEVICE_NATIVE_ENDIAN,
2928 2929
};

P
pbrook 已提交
2930
/* Generate a debug exception if a watchpoint has been hit.  */
2931
static void check_watchpoint(int offset, int len_mask, int flags)
P
pbrook 已提交
2932
{
2933
    CPUArchState *env = cpu_single_env;
2934 2935
    target_ulong pc, cs_base;
    TranslationBlock *tb;
P
pbrook 已提交
2936
    target_ulong vaddr;
2937
    CPUWatchpoint *wp;
2938
    int cpu_flags;
P
pbrook 已提交
2939

2940 2941 2942 2943 2944 2945 2946
    if (env->watchpoint_hit) {
        /* We re-entered the check after replacing the TB. Now raise
         * the debug interrupt so that is will trigger after the
         * current instruction. */
        cpu_interrupt(env, CPU_INTERRUPT_DEBUG);
        return;
    }
P
pbrook 已提交
2947
    vaddr = (env->mem_io_vaddr & TARGET_PAGE_MASK) + offset;
B
Blue Swirl 已提交
2948
    QTAILQ_FOREACH(wp, &env->watchpoints, entry) {
2949 2950
        if ((vaddr == (wp->vaddr & len_mask) ||
             (vaddr & wp->len_mask) == wp->vaddr) && (wp->flags & flags)) {
2951 2952 2953 2954 2955 2956 2957 2958
            wp->flags |= BP_WATCHPOINT_HIT;
            if (!env->watchpoint_hit) {
                env->watchpoint_hit = wp;
                tb = tb_find_pc(env->mem_io_pc);
                if (!tb) {
                    cpu_abort(env, "check_watchpoint: could not find TB for "
                              "pc=%p", (void *)env->mem_io_pc);
                }
2959
                cpu_restore_state(tb, env, env->mem_io_pc);
2960 2961 2962
                tb_phys_invalidate(tb, -1);
                if (wp->flags & BP_STOP_BEFORE_ACCESS) {
                    env->exception_index = EXCP_DEBUG;
2963
                    cpu_loop_exit(env);
2964 2965 2966
                } else {
                    cpu_get_tb_cpu_state(env, &pc, &cs_base, &cpu_flags);
                    tb_gen_code(env, pc, cs_base, cpu_flags, 1);
2967
                    cpu_resume_from_signal(env, NULL);
2968
                }
2969
            }
2970 2971
        } else {
            wp->flags &= ~BP_WATCHPOINT_HIT;
P
pbrook 已提交
2972 2973 2974 2975
        }
    }
}

2976 2977 2978
/* Watchpoint access routines.  Watchpoints are inserted using TLB tricks,
   so these check for a hit then pass through to the normal out-of-line
   phys routines.  */
A
Avi Kivity 已提交
2979
static uint64_t watch_mem_read(void *opaque, hwaddr addr,
2980
                               unsigned size)
2981
{
2982 2983 2984 2985 2986 2987 2988
    check_watchpoint(addr & ~TARGET_PAGE_MASK, ~(size - 1), BP_MEM_READ);
    switch (size) {
    case 1: return ldub_phys(addr);
    case 2: return lduw_phys(addr);
    case 4: return ldl_phys(addr);
    default: abort();
    }
2989 2990
}

A
Avi Kivity 已提交
2991
static void watch_mem_write(void *opaque, hwaddr addr,
2992
                            uint64_t val, unsigned size)
2993
{
2994 2995
    check_watchpoint(addr & ~TARGET_PAGE_MASK, ~(size - 1), BP_MEM_WRITE);
    switch (size) {
2996 2997 2998 2999 3000 3001 3002 3003 3004
    case 1:
        stb_phys(addr, val);
        break;
    case 2:
        stw_phys(addr, val);
        break;
    case 4:
        stl_phys(addr, val);
        break;
3005 3006
    default: abort();
    }
3007 3008
}

3009 3010 3011 3012
static const MemoryRegionOps watch_mem_ops = {
    .read = watch_mem_read,
    .write = watch_mem_write,
    .endianness = DEVICE_NATIVE_ENDIAN,
3013 3014
};

A
Avi Kivity 已提交
3015
static uint64_t subpage_read(void *opaque, hwaddr addr,
3016
                             unsigned len)
3017
{
3018
    subpage_t *mmio = opaque;
R
Richard Henderson 已提交
3019
    unsigned int idx = SUBPAGE_IDX(addr);
3020
    MemoryRegionSection *section;
3021 3022 3023 3024 3025
#if defined(DEBUG_SUBPAGE)
    printf("%s: subpage %p len %d addr " TARGET_FMT_plx " idx %d\n", __func__,
           mmio, len, addr, idx);
#endif

3026 3027 3028 3029
    section = &phys_sections[mmio->sub_section[idx]];
    addr += mmio->base;
    addr -= section->offset_within_address_space;
    addr += section->offset_within_region;
3030
    return io_mem_read(section->mr, addr, len);
3031 3032
}

A
Avi Kivity 已提交
3033
static void subpage_write(void *opaque, hwaddr addr,
3034
                          uint64_t value, unsigned len)
3035
{
3036
    subpage_t *mmio = opaque;
R
Richard Henderson 已提交
3037
    unsigned int idx = SUBPAGE_IDX(addr);
3038
    MemoryRegionSection *section;
3039
#if defined(DEBUG_SUBPAGE)
3040 3041
    printf("%s: subpage %p len %d addr " TARGET_FMT_plx
           " idx %d value %"PRIx64"\n",
R
Richard Henderson 已提交
3042
           __func__, mmio, len, addr, idx, value);
3043
#endif
R
Richard Henderson 已提交
3044

3045 3046 3047 3048
    section = &phys_sections[mmio->sub_section[idx]];
    addr += mmio->base;
    addr -= section->offset_within_address_space;
    addr += section->offset_within_region;
3049
    io_mem_write(section->mr, addr, value, len);
3050 3051
}

3052 3053 3054 3055
static const MemoryRegionOps subpage_ops = {
    .read = subpage_read,
    .write = subpage_write,
    .endianness = DEVICE_NATIVE_ENDIAN,
3056 3057
};

A
Avi Kivity 已提交
3058
static uint64_t subpage_ram_read(void *opaque, hwaddr addr,
3059
                                 unsigned size)
3060 3061 3062
{
    ram_addr_t raddr = addr;
    void *ptr = qemu_get_ram_ptr(raddr);
3063 3064 3065 3066 3067 3068
    switch (size) {
    case 1: return ldub_p(ptr);
    case 2: return lduw_p(ptr);
    case 4: return ldl_p(ptr);
    default: abort();
    }
3069 3070
}

A
Avi Kivity 已提交
3071
static void subpage_ram_write(void *opaque, hwaddr addr,
3072
                              uint64_t value, unsigned size)
3073 3074 3075
{
    ram_addr_t raddr = addr;
    void *ptr = qemu_get_ram_ptr(raddr);
3076 3077 3078 3079 3080 3081
    switch (size) {
    case 1: return stb_p(ptr, value);
    case 2: return stw_p(ptr, value);
    case 4: return stl_p(ptr, value);
    default: abort();
    }
3082 3083
}

3084 3085 3086 3087
static const MemoryRegionOps subpage_ram_ops = {
    .read = subpage_ram_read,
    .write = subpage_ram_write,
    .endianness = DEVICE_NATIVE_ENDIAN,
3088 3089
};

A
Anthony Liguori 已提交
3090
static int subpage_register (subpage_t *mmio, uint32_t start, uint32_t end,
3091
                             uint16_t section)
3092 3093 3094 3095 3096 3097 3098 3099
{
    int idx, eidx;

    if (start >= TARGET_PAGE_SIZE || end >= TARGET_PAGE_SIZE)
        return -1;
    idx = SUBPAGE_IDX(start);
    eidx = SUBPAGE_IDX(end);
#if defined(DEBUG_SUBPAGE)
3100
    printf("%s: %p start %08x end %08x idx %08x eidx %08x mem %ld\n", __func__,
3101 3102
           mmio, start, end, idx, eidx, memory);
#endif
3103 3104 3105 3106
    if (memory_region_is_ram(phys_sections[section].mr)) {
        MemoryRegionSection new_section = phys_sections[section];
        new_section.mr = &io_mem_subpage_ram;
        section = phys_section_add(&new_section);
3107
    }
3108
    for (; idx <= eidx; idx++) {
3109
        mmio->sub_section[idx] = section;
3110 3111 3112 3113 3114
    }

    return 0;
}

A
Avi Kivity 已提交
3115
static subpage_t *subpage_init(hwaddr base)
3116
{
A
Anthony Liguori 已提交
3117
    subpage_t *mmio;
3118

3119
    mmio = g_malloc0(sizeof(subpage_t));
3120 3121

    mmio->base = base;
3122 3123
    memory_region_init_io(&mmio->iomem, &subpage_ops, mmio,
                          "subpage", TARGET_PAGE_SIZE);
A
Avi Kivity 已提交
3124
    mmio->iomem.subpage = true;
3125
#if defined(DEBUG_SUBPAGE)
3126 3127
    printf("%s: %p base " TARGET_FMT_plx " len %08x %d\n", __func__,
           mmio, base, TARGET_PAGE_SIZE, subpage_memory);
3128
#endif
3129
    subpage_register(mmio, 0, TARGET_PAGE_SIZE-1, phys_section_unassigned);
3130 3131 3132 3133

    return mmio;
}

3134 3135 3136 3137 3138 3139 3140 3141 3142 3143 3144 3145
static uint16_t dummy_section(MemoryRegion *mr)
{
    MemoryRegionSection section = {
        .mr = mr,
        .offset_within_address_space = 0,
        .offset_within_region = 0,
        .size = UINT64_MAX,
    };

    return phys_section_add(&section);
}

A
Avi Kivity 已提交
3146
MemoryRegion *iotlb_to_region(hwaddr index)
3147
{
3148
    return phys_sections[index & ~TARGET_PAGE_MASK].mr;
3149 3150
}

A
Avi Kivity 已提交
3151 3152
static void io_mem_init(void)
{
3153 3154 3155 3156 3157 3158
    memory_region_init_io(&io_mem_ram, &error_mem_ops, NULL, "ram", UINT64_MAX);
    memory_region_init_io(&io_mem_rom, &rom_mem_ops, NULL, "rom", UINT64_MAX);
    memory_region_init_io(&io_mem_unassigned, &unassigned_mem_ops, NULL,
                          "unassigned", UINT64_MAX);
    memory_region_init_io(&io_mem_notdirty, &notdirty_mem_ops, NULL,
                          "notdirty", UINT64_MAX);
3159 3160
    memory_region_init_io(&io_mem_subpage_ram, &subpage_ram_ops, NULL,
                          "subpage-ram", UINT64_MAX);
3161 3162
    memory_region_init_io(&io_mem_watch, &watch_mem_ops, NULL,
                          "watch", UINT64_MAX);
A
Avi Kivity 已提交
3163 3164
}

A
Avi Kivity 已提交
3165 3166 3167 3168 3169 3170 3171 3172
static void mem_begin(MemoryListener *listener)
{
    AddressSpaceDispatch *d = container_of(listener, AddressSpaceDispatch, listener);

    destroy_all_mappings(d);
    d->phys_map.ptr = PHYS_MAP_NODE_NIL;
}

3173 3174
static void core_begin(MemoryListener *listener)
{
3175 3176
    phys_sections_clear();
    phys_section_unassigned = dummy_section(&io_mem_unassigned);
3177 3178 3179
    phys_section_notdirty = dummy_section(&io_mem_notdirty);
    phys_section_rom = dummy_section(&io_mem_rom);
    phys_section_watch = dummy_section(&io_mem_watch);
3180 3181
}

3182
static void tcg_commit(MemoryListener *listener)
3183
{
3184
    CPUArchState *env;
3185 3186 3187 3188 3189 3190 3191

    /* since each CPU stores ram addresses in its TLB cache, we must
       reset the modified entries */
    /* XXX: slow ! */
    for(env = first_cpu; env != NULL; env = env->next_cpu) {
        tlb_flush(env, 1);
    }
3192 3193
}

3194 3195 3196 3197 3198 3199 3200 3201 3202 3203
static void core_log_global_start(MemoryListener *listener)
{
    cpu_physical_memory_set_dirty_tracking(1);
}

static void core_log_global_stop(MemoryListener *listener)
{
    cpu_physical_memory_set_dirty_tracking(0);
}

3204 3205 3206
static void io_region_add(MemoryListener *listener,
                          MemoryRegionSection *section)
{
A
Avi Kivity 已提交
3207 3208 3209 3210 3211
    MemoryRegionIORange *mrio = g_new(MemoryRegionIORange, 1);

    mrio->mr = section->mr;
    mrio->offset = section->offset_within_region;
    iorange_init(&mrio->iorange, &memory_region_iorange_ops,
3212
                 section->offset_within_address_space, section->size);
A
Avi Kivity 已提交
3213
    ioport_register(&mrio->iorange);
3214 3215 3216 3217 3218 3219 3220 3221
}

static void io_region_del(MemoryListener *listener,
                          MemoryRegionSection *section)
{
    isa_unassign_ioport(section->offset_within_address_space, section->size);
}

3222
static MemoryListener core_memory_listener = {
3223
    .begin = core_begin,
3224 3225
    .log_global_start = core_log_global_start,
    .log_global_stop = core_log_global_stop,
A
Avi Kivity 已提交
3226
    .priority = 1,
3227 3228
};

3229 3230 3231 3232 3233 3234
static MemoryListener io_memory_listener = {
    .region_add = io_region_add,
    .region_del = io_region_del,
    .priority = 0,
};

3235 3236 3237 3238
static MemoryListener tcg_memory_listener = {
    .commit = tcg_commit,
};

A
Avi Kivity 已提交
3239 3240 3241 3242 3243 3244 3245 3246 3247 3248 3249 3250 3251 3252 3253
void address_space_init_dispatch(AddressSpace *as)
{
    AddressSpaceDispatch *d = g_new(AddressSpaceDispatch, 1);

    d->phys_map  = (PhysPageEntry) { .ptr = PHYS_MAP_NODE_NIL, .is_leaf = 0 };
    d->listener = (MemoryListener) {
        .begin = mem_begin,
        .region_add = mem_add,
        .region_nop = mem_add,
        .priority = 0,
    };
    as->dispatch = d;
    memory_listener_register(&d->listener, as);
}

A
Avi Kivity 已提交
3254 3255 3256 3257 3258 3259 3260 3261 3262 3263
void address_space_destroy_dispatch(AddressSpace *as)
{
    AddressSpaceDispatch *d = as->dispatch;

    memory_listener_unregister(&d->listener);
    destroy_l2_mapping(&d->phys_map, P_L2_LEVELS - 1);
    g_free(d);
    as->dispatch = NULL;
}

A
Avi Kivity 已提交
3264 3265
static void memory_map_init(void)
{
3266
    system_memory = g_malloc(sizeof(*system_memory));
A
Avi Kivity 已提交
3267
    memory_region_init(system_memory, "system", INT64_MAX);
3268 3269
    address_space_init(&address_space_memory, system_memory);
    address_space_memory.name = "memory";
3270

3271
    system_io = g_malloc(sizeof(*system_io));
3272
    memory_region_init(system_io, "io", 65536);
3273 3274
    address_space_init(&address_space_io, system_io);
    address_space_io.name = "I/O";
3275

3276 3277 3278
    memory_listener_register(&core_memory_listener, &address_space_memory);
    memory_listener_register(&io_memory_listener, &address_space_io);
    memory_listener_register(&tcg_memory_listener, &address_space_memory);
A
Avi Kivity 已提交
3279 3280 3281 3282 3283 3284 3285
}

MemoryRegion *get_system_memory(void)
{
    return system_memory;
}

3286 3287 3288 3289 3290
MemoryRegion *get_system_io(void)
{
    return system_io;
}

3291 3292
#endif /* !defined(CONFIG_USER_ONLY) */

B
bellard 已提交
3293 3294
/* physical memory access (slow version, mainly for debug) */
#if defined(CONFIG_USER_ONLY)
3295
int cpu_memory_rw_debug(CPUArchState *env, target_ulong addr,
P
Paul Brook 已提交
3296
                        uint8_t *buf, int len, int is_write)
B
bellard 已提交
3297 3298 3299
{
    int l, flags;
    target_ulong page;
3300
    void * p;
B
bellard 已提交
3301 3302 3303 3304 3305 3306 3307 3308

    while (len > 0) {
        page = addr & TARGET_PAGE_MASK;
        l = (page + TARGET_PAGE_SIZE) - addr;
        if (l > len)
            l = len;
        flags = page_get_flags(page);
        if (!(flags & PAGE_VALID))
P
Paul Brook 已提交
3309
            return -1;
B
bellard 已提交
3310 3311
        if (is_write) {
            if (!(flags & PAGE_WRITE))
P
Paul Brook 已提交
3312
                return -1;
3313
            /* XXX: this code should not depend on lock_user */
A
aurel32 已提交
3314
            if (!(p = lock_user(VERIFY_WRITE, addr, l, 0)))
P
Paul Brook 已提交
3315
                return -1;
A
aurel32 已提交
3316 3317
            memcpy(p, buf, l);
            unlock_user(p, addr, l);
B
bellard 已提交
3318 3319
        } else {
            if (!(flags & PAGE_READ))
P
Paul Brook 已提交
3320
                return -1;
3321
            /* XXX: this code should not depend on lock_user */
A
aurel32 已提交
3322
            if (!(p = lock_user(VERIFY_READ, addr, l, 1)))
P
Paul Brook 已提交
3323
                return -1;
A
aurel32 已提交
3324
            memcpy(buf, p, l);
A
aurel32 已提交
3325
            unlock_user(p, addr, 0);
B
bellard 已提交
3326 3327 3328 3329 3330
        }
        len -= l;
        buf += l;
        addr += l;
    }
P
Paul Brook 已提交
3331
    return 0;
B
bellard 已提交
3332
}
B
bellard 已提交
3333

B
bellard 已提交
3334
#else
3335

A
Avi Kivity 已提交
3336 3337
static void invalidate_and_set_dirty(hwaddr addr,
                                     hwaddr length)
3338 3339 3340 3341 3342 3343 3344
{
    if (!cpu_physical_memory_is_dirty(addr)) {
        /* invalidate code */
        tb_invalidate_phys_page_range(addr, addr + length, 0);
        /* set dirty bit */
        cpu_physical_memory_set_dirty_flags(addr, (0xff & ~CODE_DIRTY_FLAG));
    }
3345
    xen_modified_memory(addr, length);
3346 3347
}

A
Avi Kivity 已提交
3348
void address_space_rw(AddressSpace *as, hwaddr addr, uint8_t *buf,
A
Avi Kivity 已提交
3349
                      int len, bool is_write)
B
bellard 已提交
3350
{
A
Avi Kivity 已提交
3351
    AddressSpaceDispatch *d = as->dispatch;
3352
    int l;
B
bellard 已提交
3353 3354
    uint8_t *ptr;
    uint32_t val;
A
Avi Kivity 已提交
3355
    hwaddr page;
3356
    MemoryRegionSection *section;
3357

B
bellard 已提交
3358 3359 3360 3361 3362
    while (len > 0) {
        page = addr & TARGET_PAGE_MASK;
        l = (page + TARGET_PAGE_SIZE) - addr;
        if (l > len)
            l = len;
A
Avi Kivity 已提交
3363
        section = phys_page_find(d, page >> TARGET_PAGE_BITS);
3364

B
bellard 已提交
3365
        if (is_write) {
3366
            if (!memory_region_is_ram(section->mr)) {
A
Avi Kivity 已提交
3367
                hwaddr addr1;
3368
                addr1 = memory_region_section_addr(section, addr);
B
bellard 已提交
3369 3370
                /* XXX: could force cpu_single_env to NULL to avoid
                   potential bugs */
3371
                if (l >= 4 && ((addr1 & 3) == 0)) {
B
bellard 已提交
3372
                    /* 32 bit write access */
B
bellard 已提交
3373
                    val = ldl_p(buf);
3374
                    io_mem_write(section->mr, addr1, val, 4);
B
bellard 已提交
3375
                    l = 4;
3376
                } else if (l >= 2 && ((addr1 & 1) == 0)) {
B
bellard 已提交
3377
                    /* 16 bit write access */
B
bellard 已提交
3378
                    val = lduw_p(buf);
3379
                    io_mem_write(section->mr, addr1, val, 2);
B
bellard 已提交
3380 3381
                    l = 2;
                } else {
B
bellard 已提交
3382
                    /* 8 bit write access */
B
bellard 已提交
3383
                    val = ldub_p(buf);
3384
                    io_mem_write(section->mr, addr1, val, 1);
B
bellard 已提交
3385 3386
                    l = 1;
                }
3387
            } else if (!section->readonly) {
3388
                ram_addr_t addr1;
3389
                addr1 = memory_region_get_ram_addr(section->mr)
3390
                    + memory_region_section_addr(section, addr);
B
bellard 已提交
3391
                /* RAM case */
P
pbrook 已提交
3392
                ptr = qemu_get_ram_ptr(addr1);
B
bellard 已提交
3393
                memcpy(ptr, buf, l);
3394
                invalidate_and_set_dirty(addr1, l);
A
Anthony PERARD 已提交
3395
                qemu_put_ram_ptr(ptr);
B
bellard 已提交
3396 3397
            }
        } else {
3398 3399
            if (!(memory_region_is_ram(section->mr) ||
                  memory_region_is_romd(section->mr))) {
A
Avi Kivity 已提交
3400
                hwaddr addr1;
B
bellard 已提交
3401
                /* I/O case */
3402
                addr1 = memory_region_section_addr(section, addr);
3403
                if (l >= 4 && ((addr1 & 3) == 0)) {
B
bellard 已提交
3404
                    /* 32 bit read access */
3405
                    val = io_mem_read(section->mr, addr1, 4);
B
bellard 已提交
3406
                    stl_p(buf, val);
B
bellard 已提交
3407
                    l = 4;
3408
                } else if (l >= 2 && ((addr1 & 1) == 0)) {
B
bellard 已提交
3409
                    /* 16 bit read access */
3410
                    val = io_mem_read(section->mr, addr1, 2);
B
bellard 已提交
3411
                    stw_p(buf, val);
B
bellard 已提交
3412 3413
                    l = 2;
                } else {
B
bellard 已提交
3414
                    /* 8 bit read access */
3415
                    val = io_mem_read(section->mr, addr1, 1);
B
bellard 已提交
3416
                    stb_p(buf, val);
B
bellard 已提交
3417 3418 3419 3420
                    l = 1;
                }
            } else {
                /* RAM case */
3421
                ptr = qemu_get_ram_ptr(section->mr->ram_addr
3422 3423
                                       + memory_region_section_addr(section,
                                                                    addr));
3424
                memcpy(buf, ptr, l);
A
Anthony PERARD 已提交
3425
                qemu_put_ram_ptr(ptr);
B
bellard 已提交
3426 3427 3428 3429 3430 3431 3432
            }
        }
        len -= l;
        buf += l;
        addr += l;
    }
}
B
bellard 已提交
3433

A
Avi Kivity 已提交
3434
void address_space_write(AddressSpace *as, hwaddr addr,
A
Avi Kivity 已提交
3435 3436 3437 3438 3439 3440 3441 3442 3443 3444 3445 3446
                         const uint8_t *buf, int len)
{
    address_space_rw(as, addr, (uint8_t *)buf, len, true);
}

/**
 * address_space_read: read from an address space.
 *
 * @as: #AddressSpace to be accessed
 * @addr: address within that address space
 * @buf: buffer with the data transferred
 */
A
Avi Kivity 已提交
3447
void address_space_read(AddressSpace *as, hwaddr addr, uint8_t *buf, int len)
A
Avi Kivity 已提交
3448 3449 3450 3451 3452
{
    address_space_rw(as, addr, buf, len, false);
}


A
Avi Kivity 已提交
3453
void cpu_physical_memory_rw(hwaddr addr, uint8_t *buf,
A
Avi Kivity 已提交
3454 3455 3456 3457 3458
                            int len, int is_write)
{
    return address_space_rw(&address_space_memory, addr, buf, len, is_write);
}

B
bellard 已提交
3459
/* used for ROM loading : can write in RAM and ROM */
A
Avi Kivity 已提交
3460
void cpu_physical_memory_write_rom(hwaddr addr,
B
bellard 已提交
3461 3462
                                   const uint8_t *buf, int len)
{
A
Avi Kivity 已提交
3463
    AddressSpaceDispatch *d = address_space_memory.dispatch;
B
bellard 已提交
3464 3465
    int l;
    uint8_t *ptr;
A
Avi Kivity 已提交
3466
    hwaddr page;
3467
    MemoryRegionSection *section;
3468

B
bellard 已提交
3469 3470 3471 3472 3473
    while (len > 0) {
        page = addr & TARGET_PAGE_MASK;
        l = (page + TARGET_PAGE_SIZE) - addr;
        if (l > len)
            l = len;
A
Avi Kivity 已提交
3474
        section = phys_page_find(d, page >> TARGET_PAGE_BITS);
3475

3476 3477
        if (!(memory_region_is_ram(section->mr) ||
              memory_region_is_romd(section->mr))) {
B
bellard 已提交
3478 3479 3480
            /* do nothing */
        } else {
            unsigned long addr1;
3481
            addr1 = memory_region_get_ram_addr(section->mr)
3482
                + memory_region_section_addr(section, addr);
B
bellard 已提交
3483
            /* ROM/RAM case */
P
pbrook 已提交
3484
            ptr = qemu_get_ram_ptr(addr1);
B
bellard 已提交
3485
            memcpy(ptr, buf, l);
3486
            invalidate_and_set_dirty(addr1, l);
A
Anthony PERARD 已提交
3487
            qemu_put_ram_ptr(ptr);
B
bellard 已提交
3488 3489 3490 3491 3492 3493 3494
        }
        len -= l;
        buf += l;
        addr += l;
    }
}

3495 3496
typedef struct {
    void *buffer;
A
Avi Kivity 已提交
3497 3498
    hwaddr addr;
    hwaddr len;
3499 3500 3501 3502
} BounceBuffer;

static BounceBuffer bounce;

3503 3504 3505
typedef struct MapClient {
    void *opaque;
    void (*callback)(void *opaque);
B
Blue Swirl 已提交
3506
    QLIST_ENTRY(MapClient) link;
3507 3508
} MapClient;

B
Blue Swirl 已提交
3509 3510
static QLIST_HEAD(map_client_list, MapClient) map_client_list
    = QLIST_HEAD_INITIALIZER(map_client_list);
3511 3512 3513

void *cpu_register_map_client(void *opaque, void (*callback)(void *opaque))
{
3514
    MapClient *client = g_malloc(sizeof(*client));
3515 3516 3517

    client->opaque = opaque;
    client->callback = callback;
B
Blue Swirl 已提交
3518
    QLIST_INSERT_HEAD(&map_client_list, client, link);
3519 3520 3521 3522 3523 3524 3525
    return client;
}

void cpu_unregister_map_client(void *_client)
{
    MapClient *client = (MapClient *)_client;

B
Blue Swirl 已提交
3526
    QLIST_REMOVE(client, link);
3527
    g_free(client);
3528 3529 3530 3531 3532 3533
}

static void cpu_notify_map_clients(void)
{
    MapClient *client;

B
Blue Swirl 已提交
3534 3535
    while (!QLIST_EMPTY(&map_client_list)) {
        client = QLIST_FIRST(&map_client_list);
3536
        client->callback(client->opaque);
3537
        cpu_unregister_map_client(client);
3538 3539 3540
    }
}

3541 3542 3543 3544
/* Map a physical memory region into a host virtual address.
 * May map a subset of the requested range, given by and returned in *plen.
 * May return NULL if resources needed to perform the mapping are exhausted.
 * Use only for reads OR writes - not for read-modify-write operations.
3545 3546
 * Use cpu_register_map_client() to know when retrying the map operation is
 * likely to succeed.
3547
 */
A
Avi Kivity 已提交
3548
void *address_space_map(AddressSpace *as,
A
Avi Kivity 已提交
3549 3550
                        hwaddr addr,
                        hwaddr *plen,
A
Avi Kivity 已提交
3551
                        bool is_write)
3552
{
A
Avi Kivity 已提交
3553
    AddressSpaceDispatch *d = as->dispatch;
A
Avi Kivity 已提交
3554 3555
    hwaddr len = *plen;
    hwaddr todo = 0;
3556
    int l;
A
Avi Kivity 已提交
3557
    hwaddr page;
3558
    MemoryRegionSection *section;
3559
    ram_addr_t raddr = RAM_ADDR_MAX;
3560 3561
    ram_addr_t rlen;
    void *ret;
3562 3563 3564 3565 3566 3567

    while (len > 0) {
        page = addr & TARGET_PAGE_MASK;
        l = (page + TARGET_PAGE_SIZE) - addr;
        if (l > len)
            l = len;
A
Avi Kivity 已提交
3568
        section = phys_page_find(d, page >> TARGET_PAGE_BITS);
3569

3570
        if (!(memory_region_is_ram(section->mr) && !section->readonly)) {
3571
            if (todo || bounce.buffer) {
3572 3573 3574 3575 3576 3577
                break;
            }
            bounce.buffer = qemu_memalign(TARGET_PAGE_SIZE, TARGET_PAGE_SIZE);
            bounce.addr = addr;
            bounce.len = l;
            if (!is_write) {
A
Avi Kivity 已提交
3578
                address_space_read(as, addr, bounce.buffer, l);
3579
            }
3580 3581 3582

            *plen = l;
            return bounce.buffer;
3583
        }
3584
        if (!todo) {
3585
            raddr = memory_region_get_ram_addr(section->mr)
3586
                + memory_region_section_addr(section, addr);
3587
        }
3588 3589 3590

        len -= l;
        addr += l;
3591
        todo += l;
3592
    }
3593 3594 3595 3596
    rlen = todo;
    ret = qemu_ram_ptr_length(raddr, &rlen);
    *plen = rlen;
    return ret;
3597 3598
}

A
Avi Kivity 已提交
3599
/* Unmaps a memory region previously mapped by address_space_map().
3600 3601 3602
 * Will also mark the memory as dirty if is_write == 1.  access_len gives
 * the amount of memory that was actually read or written by the caller.
 */
A
Avi Kivity 已提交
3603 3604
void address_space_unmap(AddressSpace *as, void *buffer, hwaddr len,
                         int is_write, hwaddr access_len)
3605 3606 3607
{
    if (buffer != bounce.buffer) {
        if (is_write) {
M
Marcelo Tosatti 已提交
3608
            ram_addr_t addr1 = qemu_ram_addr_from_host_nofail(buffer);
3609 3610 3611 3612 3613
            while (access_len) {
                unsigned l;
                l = TARGET_PAGE_SIZE;
                if (l > access_len)
                    l = access_len;
3614
                invalidate_and_set_dirty(addr1, l);
3615 3616 3617 3618
                addr1 += l;
                access_len -= l;
            }
        }
3619
        if (xen_enabled()) {
J
Jan Kiszka 已提交
3620
            xen_invalidate_map_cache_entry(buffer);
A
Anthony PERARD 已提交
3621
        }
3622 3623 3624
        return;
    }
    if (is_write) {
A
Avi Kivity 已提交
3625
        address_space_write(as, bounce.addr, bounce.buffer, access_len);
3626
    }
3627
    qemu_vfree(bounce.buffer);
3628
    bounce.buffer = NULL;
3629
    cpu_notify_map_clients();
3630
}
B
bellard 已提交
3631

A
Avi Kivity 已提交
3632 3633
void *cpu_physical_memory_map(hwaddr addr,
                              hwaddr *plen,
A
Avi Kivity 已提交
3634 3635 3636 3637 3638
                              int is_write)
{
    return address_space_map(&address_space_memory, addr, plen, is_write);
}

A
Avi Kivity 已提交
3639 3640
void cpu_physical_memory_unmap(void *buffer, hwaddr len,
                               int is_write, hwaddr access_len)
A
Avi Kivity 已提交
3641 3642 3643 3644
{
    return address_space_unmap(&address_space_memory, buffer, len, is_write, access_len);
}

B
bellard 已提交
3645
/* warning: addr must be aligned */
A
Avi Kivity 已提交
3646
static inline uint32_t ldl_phys_internal(hwaddr addr,
3647
                                         enum device_endian endian)
B
bellard 已提交
3648 3649 3650
{
    uint8_t *ptr;
    uint32_t val;
3651
    MemoryRegionSection *section;
B
bellard 已提交
3652

A
Avi Kivity 已提交
3653
    section = phys_page_find(address_space_memory.dispatch, addr >> TARGET_PAGE_BITS);
3654

3655 3656
    if (!(memory_region_is_ram(section->mr) ||
          memory_region_is_romd(section->mr))) {
B
bellard 已提交
3657
        /* I/O case */
3658
        addr = memory_region_section_addr(section, addr);
3659
        val = io_mem_read(section->mr, addr, 4);
3660 3661 3662 3663 3664 3665 3666 3667 3668
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap32(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap32(val);
        }
#endif
B
bellard 已提交
3669 3670
    } else {
        /* RAM case */
3671
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(section->mr)
3672
                                & TARGET_PAGE_MASK)
3673
                               + memory_region_section_addr(section, addr));
3674 3675 3676 3677 3678 3679 3680 3681 3682 3683 3684
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            val = ldl_le_p(ptr);
            break;
        case DEVICE_BIG_ENDIAN:
            val = ldl_be_p(ptr);
            break;
        default:
            val = ldl_p(ptr);
            break;
        }
B
bellard 已提交
3685 3686 3687 3688
    }
    return val;
}

A
Avi Kivity 已提交
3689
uint32_t ldl_phys(hwaddr addr)
3690 3691 3692 3693
{
    return ldl_phys_internal(addr, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
3694
uint32_t ldl_le_phys(hwaddr addr)
3695 3696 3697 3698
{
    return ldl_phys_internal(addr, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
3699
uint32_t ldl_be_phys(hwaddr addr)
3700 3701 3702 3703
{
    return ldl_phys_internal(addr, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
3704
/* warning: addr must be aligned */
A
Avi Kivity 已提交
3705
static inline uint64_t ldq_phys_internal(hwaddr addr,
3706
                                         enum device_endian endian)
B
bellard 已提交
3707 3708 3709
{
    uint8_t *ptr;
    uint64_t val;
3710
    MemoryRegionSection *section;
B
bellard 已提交
3711

A
Avi Kivity 已提交
3712
    section = phys_page_find(address_space_memory.dispatch, addr >> TARGET_PAGE_BITS);
3713

3714 3715
    if (!(memory_region_is_ram(section->mr) ||
          memory_region_is_romd(section->mr))) {
B
bellard 已提交
3716
        /* I/O case */
3717
        addr = memory_region_section_addr(section, addr);
3718 3719 3720

        /* XXX This is broken when device endian != cpu endian.
               Fix and add "endian" variable check */
B
bellard 已提交
3721
#ifdef TARGET_WORDS_BIGENDIAN
3722 3723
        val = io_mem_read(section->mr, addr, 4) << 32;
        val |= io_mem_read(section->mr, addr + 4, 4);
B
bellard 已提交
3724
#else
3725 3726
        val = io_mem_read(section->mr, addr, 4);
        val |= io_mem_read(section->mr, addr + 4, 4) << 32;
B
bellard 已提交
3727 3728 3729
#endif
    } else {
        /* RAM case */
3730
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(section->mr)
3731
                                & TARGET_PAGE_MASK)
3732
                               + memory_region_section_addr(section, addr));
3733 3734 3735 3736 3737 3738 3739 3740 3741 3742 3743
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            val = ldq_le_p(ptr);
            break;
        case DEVICE_BIG_ENDIAN:
            val = ldq_be_p(ptr);
            break;
        default:
            val = ldq_p(ptr);
            break;
        }
B
bellard 已提交
3744 3745 3746 3747
    }
    return val;
}

A
Avi Kivity 已提交
3748
uint64_t ldq_phys(hwaddr addr)
3749 3750 3751 3752
{
    return ldq_phys_internal(addr, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
3753
uint64_t ldq_le_phys(hwaddr addr)
3754 3755 3756 3757
{
    return ldq_phys_internal(addr, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
3758
uint64_t ldq_be_phys(hwaddr addr)
3759 3760 3761 3762
{
    return ldq_phys_internal(addr, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
3763
/* XXX: optimize */
A
Avi Kivity 已提交
3764
uint32_t ldub_phys(hwaddr addr)
B
bellard 已提交
3765 3766 3767 3768 3769 3770
{
    uint8_t val;
    cpu_physical_memory_read(addr, &val, 1);
    return val;
}

3771
/* warning: addr must be aligned */
A
Avi Kivity 已提交
3772
static inline uint32_t lduw_phys_internal(hwaddr addr,
3773
                                          enum device_endian endian)
B
bellard 已提交
3774
{
3775 3776
    uint8_t *ptr;
    uint64_t val;
3777
    MemoryRegionSection *section;
3778

A
Avi Kivity 已提交
3779
    section = phys_page_find(address_space_memory.dispatch, addr >> TARGET_PAGE_BITS);
3780

3781 3782
    if (!(memory_region_is_ram(section->mr) ||
          memory_region_is_romd(section->mr))) {
3783
        /* I/O case */
3784
        addr = memory_region_section_addr(section, addr);
3785
        val = io_mem_read(section->mr, addr, 2);
3786 3787 3788 3789 3790 3791 3792 3793 3794
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap16(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap16(val);
        }
#endif
3795 3796
    } else {
        /* RAM case */
3797
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(section->mr)
3798
                                & TARGET_PAGE_MASK)
3799
                               + memory_region_section_addr(section, addr));
3800 3801 3802 3803 3804 3805 3806 3807 3808 3809 3810
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            val = lduw_le_p(ptr);
            break;
        case DEVICE_BIG_ENDIAN:
            val = lduw_be_p(ptr);
            break;
        default:
            val = lduw_p(ptr);
            break;
        }
3811 3812
    }
    return val;
B
bellard 已提交
3813 3814
}

A
Avi Kivity 已提交
3815
uint32_t lduw_phys(hwaddr addr)
3816 3817 3818 3819
{
    return lduw_phys_internal(addr, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
3820
uint32_t lduw_le_phys(hwaddr addr)
3821 3822 3823 3824
{
    return lduw_phys_internal(addr, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
3825
uint32_t lduw_be_phys(hwaddr addr)
3826 3827 3828 3829
{
    return lduw_phys_internal(addr, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
3830 3831 3832
/* warning: addr must be aligned. The ram page is not masked as dirty
   and the code inside is not invalidated. It is useful if the dirty
   bits are used to track modified PTEs */
A
Avi Kivity 已提交
3833
void stl_phys_notdirty(hwaddr addr, uint32_t val)
B
bellard 已提交
3834 3835
{
    uint8_t *ptr;
3836
    MemoryRegionSection *section;
B
bellard 已提交
3837

A
Avi Kivity 已提交
3838
    section = phys_page_find(address_space_memory.dispatch, addr >> TARGET_PAGE_BITS);
3839

3840
    if (!memory_region_is_ram(section->mr) || section->readonly) {
3841
        addr = memory_region_section_addr(section, addr);
3842
        if (memory_region_is_ram(section->mr)) {
3843
            section = &phys_sections[phys_section_rom];
3844
        }
3845
        io_mem_write(section->mr, addr, val, 4);
B
bellard 已提交
3846
    } else {
3847
        unsigned long addr1 = (memory_region_get_ram_addr(section->mr)
3848
                               & TARGET_PAGE_MASK)
3849
            + memory_region_section_addr(section, addr);
P
pbrook 已提交
3850
        ptr = qemu_get_ram_ptr(addr1);
B
bellard 已提交
3851
        stl_p(ptr, val);
A
aliguori 已提交
3852 3853 3854 3855 3856 3857

        if (unlikely(in_migration)) {
            if (!cpu_physical_memory_is_dirty(addr1)) {
                /* invalidate code */
                tb_invalidate_phys_page_range(addr1, addr1 + 4, 0);
                /* set dirty bit */
3858 3859
                cpu_physical_memory_set_dirty_flags(
                    addr1, (0xff & ~CODE_DIRTY_FLAG));
A
aliguori 已提交
3860 3861
            }
        }
B
bellard 已提交
3862 3863 3864
    }
}

A
Avi Kivity 已提交
3865
void stq_phys_notdirty(hwaddr addr, uint64_t val)
J
j_mayer 已提交
3866 3867
{
    uint8_t *ptr;
3868
    MemoryRegionSection *section;
J
j_mayer 已提交
3869

A
Avi Kivity 已提交
3870
    section = phys_page_find(address_space_memory.dispatch, addr >> TARGET_PAGE_BITS);
3871

3872
    if (!memory_region_is_ram(section->mr) || section->readonly) {
3873
        addr = memory_region_section_addr(section, addr);
3874
        if (memory_region_is_ram(section->mr)) {
3875
            section = &phys_sections[phys_section_rom];
3876
        }
J
j_mayer 已提交
3877
#ifdef TARGET_WORDS_BIGENDIAN
3878 3879
        io_mem_write(section->mr, addr, val >> 32, 4);
        io_mem_write(section->mr, addr + 4, (uint32_t)val, 4);
J
j_mayer 已提交
3880
#else
3881 3882
        io_mem_write(section->mr, addr, (uint32_t)val, 4);
        io_mem_write(section->mr, addr + 4, val >> 32, 4);
J
j_mayer 已提交
3883 3884
#endif
    } else {
3885
        ptr = qemu_get_ram_ptr((memory_region_get_ram_addr(section->mr)
3886
                                & TARGET_PAGE_MASK)
3887
                               + memory_region_section_addr(section, addr));
J
j_mayer 已提交
3888 3889 3890 3891
        stq_p(ptr, val);
    }
}

B
bellard 已提交
3892
/* warning: addr must be aligned */
A
Avi Kivity 已提交
3893
static inline void stl_phys_internal(hwaddr addr, uint32_t val,
3894
                                     enum device_endian endian)
B
bellard 已提交
3895 3896
{
    uint8_t *ptr;
3897
    MemoryRegionSection *section;
B
bellard 已提交
3898

A
Avi Kivity 已提交
3899
    section = phys_page_find(address_space_memory.dispatch, addr >> TARGET_PAGE_BITS);
3900

3901
    if (!memory_region_is_ram(section->mr) || section->readonly) {
3902
        addr = memory_region_section_addr(section, addr);
3903
        if (memory_region_is_ram(section->mr)) {
3904
            section = &phys_sections[phys_section_rom];
3905
        }
3906 3907 3908 3909 3910 3911 3912 3913 3914
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap32(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap32(val);
        }
#endif
3915
        io_mem_write(section->mr, addr, val, 4);
B
bellard 已提交
3916 3917
    } else {
        unsigned long addr1;
3918
        addr1 = (memory_region_get_ram_addr(section->mr) & TARGET_PAGE_MASK)
3919
            + memory_region_section_addr(section, addr);
B
bellard 已提交
3920
        /* RAM case */
P
pbrook 已提交
3921
        ptr = qemu_get_ram_ptr(addr1);
3922 3923 3924 3925 3926 3927 3928 3929 3930 3931 3932
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            stl_le_p(ptr, val);
            break;
        case DEVICE_BIG_ENDIAN:
            stl_be_p(ptr, val);
            break;
        default:
            stl_p(ptr, val);
            break;
        }
3933
        invalidate_and_set_dirty(addr1, 4);
B
bellard 已提交
3934 3935 3936
    }
}

A
Avi Kivity 已提交
3937
void stl_phys(hwaddr addr, uint32_t val)
3938 3939 3940 3941
{
    stl_phys_internal(addr, val, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
3942
void stl_le_phys(hwaddr addr, uint32_t val)
3943 3944 3945 3946
{
    stl_phys_internal(addr, val, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
3947
void stl_be_phys(hwaddr addr, uint32_t val)
3948 3949 3950 3951
{
    stl_phys_internal(addr, val, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
3952
/* XXX: optimize */
A
Avi Kivity 已提交
3953
void stb_phys(hwaddr addr, uint32_t val)
B
bellard 已提交
3954 3955 3956 3957 3958
{
    uint8_t v = val;
    cpu_physical_memory_write(addr, &v, 1);
}

3959
/* warning: addr must be aligned */
A
Avi Kivity 已提交
3960
static inline void stw_phys_internal(hwaddr addr, uint32_t val,
3961
                                     enum device_endian endian)
B
bellard 已提交
3962
{
3963
    uint8_t *ptr;
3964
    MemoryRegionSection *section;
3965

A
Avi Kivity 已提交
3966
    section = phys_page_find(address_space_memory.dispatch, addr >> TARGET_PAGE_BITS);
3967

3968
    if (!memory_region_is_ram(section->mr) || section->readonly) {
3969
        addr = memory_region_section_addr(section, addr);
3970
        if (memory_region_is_ram(section->mr)) {
3971
            section = &phys_sections[phys_section_rom];
3972
        }
3973 3974 3975 3976 3977 3978 3979 3980 3981
#if defined(TARGET_WORDS_BIGENDIAN)
        if (endian == DEVICE_LITTLE_ENDIAN) {
            val = bswap16(val);
        }
#else
        if (endian == DEVICE_BIG_ENDIAN) {
            val = bswap16(val);
        }
#endif
3982
        io_mem_write(section->mr, addr, val, 2);
3983 3984
    } else {
        unsigned long addr1;
3985
        addr1 = (memory_region_get_ram_addr(section->mr) & TARGET_PAGE_MASK)
3986
            + memory_region_section_addr(section, addr);
3987 3988
        /* RAM case */
        ptr = qemu_get_ram_ptr(addr1);
3989 3990 3991 3992 3993 3994 3995 3996 3997 3998 3999
        switch (endian) {
        case DEVICE_LITTLE_ENDIAN:
            stw_le_p(ptr, val);
            break;
        case DEVICE_BIG_ENDIAN:
            stw_be_p(ptr, val);
            break;
        default:
            stw_p(ptr, val);
            break;
        }
4000
        invalidate_and_set_dirty(addr1, 2);
4001
    }
B
bellard 已提交
4002 4003
}

A
Avi Kivity 已提交
4004
void stw_phys(hwaddr addr, uint32_t val)
4005 4006 4007 4008
{
    stw_phys_internal(addr, val, DEVICE_NATIVE_ENDIAN);
}

A
Avi Kivity 已提交
4009
void stw_le_phys(hwaddr addr, uint32_t val)
4010 4011 4012 4013
{
    stw_phys_internal(addr, val, DEVICE_LITTLE_ENDIAN);
}

A
Avi Kivity 已提交
4014
void stw_be_phys(hwaddr addr, uint32_t val)
4015 4016 4017 4018
{
    stw_phys_internal(addr, val, DEVICE_BIG_ENDIAN);
}

B
bellard 已提交
4019
/* XXX: optimize */
A
Avi Kivity 已提交
4020
void stq_phys(hwaddr addr, uint64_t val)
B
bellard 已提交
4021 4022
{
    val = tswap64(val);
4023
    cpu_physical_memory_write(addr, &val, 8);
B
bellard 已提交
4024 4025
}

A
Avi Kivity 已提交
4026
void stq_le_phys(hwaddr addr, uint64_t val)
4027 4028 4029 4030 4031
{
    val = cpu_to_le64(val);
    cpu_physical_memory_write(addr, &val, 8);
}

A
Avi Kivity 已提交
4032
void stq_be_phys(hwaddr addr, uint64_t val)
4033 4034 4035 4036 4037
{
    val = cpu_to_be64(val);
    cpu_physical_memory_write(addr, &val, 8);
}

4038
/* virtual memory access for debug (includes writing to ROM) */
4039
int cpu_memory_rw_debug(CPUArchState *env, target_ulong addr,
4040
                        uint8_t *buf, int len, int is_write)
B
bellard 已提交
4041 4042
{
    int l;
A
Avi Kivity 已提交
4043
    hwaddr phys_addr;
4044
    target_ulong page;
B
bellard 已提交
4045 4046 4047 4048 4049 4050 4051 4052 4053 4054

    while (len > 0) {
        page = addr & TARGET_PAGE_MASK;
        phys_addr = cpu_get_phys_page_debug(env, page);
        /* if no physical page mapped, return an error */
        if (phys_addr == -1)
            return -1;
        l = (page + TARGET_PAGE_SIZE) - addr;
        if (l > len)
            l = len;
4055 4056 4057 4058 4059
        phys_addr += (addr & ~TARGET_PAGE_MASK);
        if (is_write)
            cpu_physical_memory_write_rom(phys_addr, buf, l);
        else
            cpu_physical_memory_rw(phys_addr, buf, l, is_write);
B
bellard 已提交
4060 4061 4062 4063 4064 4065
        len -= l;
        buf += l;
        addr += l;
    }
    return 0;
}
P
Paul Brook 已提交
4066
#endif
B
bellard 已提交
4067

P
pbrook 已提交
4068 4069
/* in deterministic execution mode, instructions doing device I/Os
   must be at the end of the TB */
4070
void cpu_io_recompile(CPUArchState *env, uintptr_t retaddr)
P
pbrook 已提交
4071 4072 4073 4074 4075 4076
{
    TranslationBlock *tb;
    uint32_t n, cflags;
    target_ulong pc, cs_base;
    uint64_t flags;

4077
    tb = tb_find_pc(retaddr);
P
pbrook 已提交
4078 4079
    if (!tb) {
        cpu_abort(env, "cpu_io_recompile: could not find TB for pc=%p", 
4080
                  (void *)retaddr);
P
pbrook 已提交
4081 4082
    }
    n = env->icount_decr.u16.low + tb->icount;
4083
    cpu_restore_state(tb, env, retaddr);
P
pbrook 已提交
4084
    /* Calculate how many instructions had been executed before the fault
T
ths 已提交
4085
       occurred.  */
P
pbrook 已提交
4086 4087 4088 4089 4090
    n = n - env->icount_decr.u16.low;
    /* Generate a new TB ending on the I/O insn.  */
    n++;
    /* On MIPS and SH, delay slot instructions can only be restarted if
       they were already the first instruction in the TB.  If this is not
T
ths 已提交
4091
       the first instruction in a TB then re-execute the preceding
P
pbrook 已提交
4092 4093 4094 4095 4096 4097 4098 4099 4100 4101 4102 4103 4104 4105 4106 4107 4108 4109 4110 4111 4112 4113 4114 4115 4116 4117 4118
       branch.  */
#if defined(TARGET_MIPS)
    if ((env->hflags & MIPS_HFLAG_BMASK) != 0 && n > 1) {
        env->active_tc.PC -= 4;
        env->icount_decr.u16.low++;
        env->hflags &= ~MIPS_HFLAG_BMASK;
    }
#elif defined(TARGET_SH4)
    if ((env->flags & ((DELAY_SLOT | DELAY_SLOT_CONDITIONAL))) != 0
            && n > 1) {
        env->pc -= 2;
        env->icount_decr.u16.low++;
        env->flags &= ~(DELAY_SLOT | DELAY_SLOT_CONDITIONAL);
    }
#endif
    /* This should never happen.  */
    if (n > CF_COUNT_MASK)
        cpu_abort(env, "TB too big during recompile");

    cflags = n | CF_LAST_IO;
    pc = tb->pc;
    cs_base = tb->cs_base;
    flags = tb->flags;
    tb_phys_invalidate(tb, -1);
    /* FIXME: In theory this could raise an exception.  In practice
       we have already translated the block once so it's probably ok.  */
    tb_gen_code(env, pc, cs_base, flags, cflags);
T
ths 已提交
4119
    /* TODO: If env->pc != tb->pc (i.e. the faulting instruction was not
P
pbrook 已提交
4120 4121 4122 4123 4124 4125 4126
       the first in the TB) then we end up generating a whole new TB and
       repeating the fault, which is horribly inefficient.
       Better would be to execute just this insn uncached, or generate a
       second new TB.  */
    cpu_resume_from_signal(env, NULL);
}

4127 4128
#if !defined(CONFIG_USER_ONLY)

4129
void dump_exec_info(FILE *f, fprintf_function cpu_fprintf)
B
bellard 已提交
4130 4131 4132 4133
{
    int i, target_code_size, max_target_code_size;
    int direct_jmp_count, direct_jmp2_count, cross_page;
    TranslationBlock *tb;
4134

B
bellard 已提交
4135 4136 4137 4138 4139 4140 4141 4142 4143 4144 4145 4146 4147 4148 4149 4150 4151 4152 4153 4154
    target_code_size = 0;
    max_target_code_size = 0;
    cross_page = 0;
    direct_jmp_count = 0;
    direct_jmp2_count = 0;
    for(i = 0; i < nb_tbs; i++) {
        tb = &tbs[i];
        target_code_size += tb->size;
        if (tb->size > max_target_code_size)
            max_target_code_size = tb->size;
        if (tb->page_addr[1] != -1)
            cross_page++;
        if (tb->tb_next_offset[0] != 0xffff) {
            direct_jmp_count++;
            if (tb->tb_next_offset[1] != 0xffff) {
                direct_jmp2_count++;
            }
        }
    }
    /* XXX: avoid using doubles ? */
B
bellard 已提交
4155
    cpu_fprintf(f, "Translation buffer state:\n");
4156
    cpu_fprintf(f, "gen code size       %td/%zd\n",
4157 4158 4159
                code_gen_ptr - code_gen_buffer, code_gen_buffer_max_size);
    cpu_fprintf(f, "TB count            %d/%d\n", 
                nb_tbs, code_gen_max_blocks);
4160
    cpu_fprintf(f, "TB avg target size  %d max=%d bytes\n",
B
bellard 已提交
4161 4162
                nb_tbs ? target_code_size / nb_tbs : 0,
                max_target_code_size);
4163
    cpu_fprintf(f, "TB avg host size    %td bytes (expansion ratio: %0.1f)\n",
B
bellard 已提交
4164 4165
                nb_tbs ? (code_gen_ptr - code_gen_buffer) / nb_tbs : 0,
                target_code_size ? (double) (code_gen_ptr - code_gen_buffer) / target_code_size : 0);
4166 4167
    cpu_fprintf(f, "cross page TB count %d (%d%%)\n",
            cross_page,
B
bellard 已提交
4168 4169
            nb_tbs ? (cross_page * 100) / nb_tbs : 0);
    cpu_fprintf(f, "direct jump count   %d (%d%%) (2 jumps=%d %d%%)\n",
4170
                direct_jmp_count,
B
bellard 已提交
4171 4172 4173
                nb_tbs ? (direct_jmp_count * 100) / nb_tbs : 0,
                direct_jmp2_count,
                nb_tbs ? (direct_jmp2_count * 100) / nb_tbs : 0);
B
bellard 已提交
4174
    cpu_fprintf(f, "\nStatistics:\n");
B
bellard 已提交
4175 4176 4177
    cpu_fprintf(f, "TB flush count      %d\n", tb_flush_count);
    cpu_fprintf(f, "TB invalidate count %d\n", tb_phys_invalidate_count);
    cpu_fprintf(f, "TLB flush count     %d\n", tlb_flush_count);
B
bellard 已提交
4178
    tcg_dump_info(f, cpu_fprintf);
B
bellard 已提交
4179 4180
}

4181 4182 4183 4184 4185 4186 4187 4188 4189 4190 4191 4192 4193 4194
/*
 * A helper function for the _utterly broken_ virtio device model to find out if
 * it's running on a big endian machine. Don't do this at home kids!
 */
bool virtio_is_big_endian(void);
bool virtio_is_big_endian(void)
{
#if defined(TARGET_WORDS_BIGENDIAN)
    return true;
#else
    return false;
#endif
}

B
bellard 已提交
4195
#endif
4196 4197

#ifndef CONFIG_USER_ONLY
A
Avi Kivity 已提交
4198
bool cpu_physical_memory_is_io(hwaddr phys_addr)
4199 4200 4201
{
    MemoryRegionSection *section;

A
Avi Kivity 已提交
4202 4203
    section = phys_page_find(address_space_memory.dispatch,
                             phys_addr >> TARGET_PAGE_BITS);
4204 4205 4206 4207 4208

    return !(memory_region_is_ram(section->mr) ||
             memory_region_is_romd(section->mr));
}
#endif