pc.c 38.6 KB
Newer Older
B
bellard 已提交
1 2
/*
 * QEMU PC System Emulator
3
 *
B
bellard 已提交
4
 * Copyright (c) 2003-2004 Fabrice Bellard
5
 *
B
bellard 已提交
6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
 * Permission is hereby granted, free of charge, to any person obtaining a copy
 * of this software and associated documentation files (the "Software"), to deal
 * in the Software without restriction, including without limitation the rights
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
 * copies of the Software, and to permit persons to whom the Software is
 * furnished to do so, subject to the following conditions:
 *
 * The above copyright notice and this permission notice shall be included in
 * all copies or substantial portions of the Software.
 *
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
 * THE SOFTWARE.
 */
24
#include "hw/hw.h"
P
Paolo Bonzini 已提交
25 26 27 28
#include "hw/i386/pc.h"
#include "hw/char/serial.h"
#include "hw/i386/apic.h"
#include "hw/block/fdc.h"
29 30
#include "hw/ide.h"
#include "hw/pci/pci.h"
31
#include "monitor/monitor.h"
P
Paolo Bonzini 已提交
32 33 34
#include "hw/nvram/fw_cfg.h"
#include "hw/timer/hpet.h"
#include "hw/i386/smbios.h"
35
#include "hw/loader.h"
B
Blue Swirl 已提交
36
#include "elf.h"
37
#include "multiboot.h"
P
Paolo Bonzini 已提交
38 39 40
#include "hw/timer/mc146818rtc.h"
#include "hw/timer/i8254.h"
#include "hw/audio/pcspk.h"
41 42
#include "hw/pci/msi.h"
#include "hw/sysbus.h"
43 44
#include "sysemu/sysemu.h"
#include "sysemu/kvm.h"
45
#include "kvm_i386.h"
P
Paolo Bonzini 已提交
46
#include "hw/xen/xen.h"
47
#include "sysemu/blockdev.h"
P
Paolo Bonzini 已提交
48
#include "hw/block/block.h"
G
Gerd Hoffmann 已提交
49
#include "ui/qemu-spice.h"
50 51
#include "exec/memory.h"
#include "exec/address-spaces.h"
52
#include "sysemu/arch_init.h"
53
#include "qemu/bitmap.h"
54
#include "qemu/config-file.h"
55
#include "hw/acpi/acpi.h"
56
#include "hw/cpu/icc_bus.h"
57
#include "hw/boards.h"
B
bellard 已提交
58

B
Blue Swirl 已提交
59 60 61 62 63 64 65 66 67 68
/* debug PC/ISA interrupts */
//#define DEBUG_IRQ

#ifdef DEBUG_IRQ
#define DPRINTF(fmt, ...)                                       \
    do { printf("CPUIRQ: " fmt , ## __VA_ARGS__); } while (0)
#else
#define DPRINTF(fmt, ...)
#endif

69 70
/* Leave a chunk of memory at the top of RAM for the BIOS ACPI tables.  */
#define ACPI_DATA_SIZE       0x10000
71
#define BIOS_CFG_IOPORT 0x510
72
#define FW_CFG_ACPI_TABLES (FW_CFG_ARCH_LOCAL + 0)
73
#define FW_CFG_SMBIOS_ENTRIES (FW_CFG_ARCH_LOCAL + 1)
J
Jes Sorensen 已提交
74
#define FW_CFG_IRQ0_OVERRIDE (FW_CFG_ARCH_LOCAL + 2)
J
Jes Sorensen 已提交
75
#define FW_CFG_E820_TABLE (FW_CFG_ARCH_LOCAL + 3)
76
#define FW_CFG_HPET (FW_CFG_ARCH_LOCAL + 4)
B
bellard 已提交
77

78 79
#define IO_APIC_DEFAULT_ADDRESS 0xfec00000

J
Jes Sorensen 已提交
80 81 82 83 84 85
#define E820_NR_ENTRIES		16

struct e820_entry {
    uint64_t address;
    uint64_t length;
    uint32_t type;
86
} QEMU_PACKED __attribute((__aligned__(4)));
J
Jes Sorensen 已提交
87 88 89 90

struct e820_table {
    uint32_t count;
    struct e820_entry entry[E820_NR_ENTRIES];
91
} QEMU_PACKED __attribute((__aligned__(4)));
J
Jes Sorensen 已提交
92 93

static struct e820_table e820_table;
B
Blue Swirl 已提交
94
struct hpet_fw_config hpet_cfg = {.count = UINT8_MAX};
J
Jes Sorensen 已提交
95

J
Jan Kiszka 已提交
96
void gsi_handler(void *opaque, int n, int level)
97
{
J
Jan Kiszka 已提交
98
    GSIState *s = opaque;
99

J
Jan Kiszka 已提交
100 101 102
    DPRINTF("pc: %s GSI %d\n", level ? "raising" : "lowering", n);
    if (n < ISA_NUM_IRQS) {
        qemu_set_irq(s->i8259_irq[n], level);
A
Avi Kivity 已提交
103
    }
J
Jan Kiszka 已提交
104
    qemu_set_irq(s->ioapic_irq[n], level);
105
}
106

J
Julien Grall 已提交
107 108
static void ioport80_write(void *opaque, hwaddr addr, uint64_t data,
                           unsigned size)
B
bellard 已提交
109 110 111
{
}

112 113
static uint64_t ioport80_read(void *opaque, hwaddr addr, unsigned size)
{
114
    return 0xffffffffffffffffULL;
115 116
}

117
/* MSDOS compatibility mode FPU exception support */
P
pbrook 已提交
118
static qemu_irq ferr_irq;
119 120 121 122 123 124

void pc_register_ferr_irq(qemu_irq irq)
{
    ferr_irq = irq;
}

125 126 127
/* XXX: add IGNNE support */
void cpu_set_ferr(CPUX86State *s)
{
P
pbrook 已提交
128
    qemu_irq_raise(ferr_irq);
129 130
}

J
Julien Grall 已提交
131 132
static void ioportF0_write(void *opaque, hwaddr addr, uint64_t data,
                           unsigned size)
133
{
P
pbrook 已提交
134
    qemu_irq_lower(ferr_irq);
135 136
}

137 138
static uint64_t ioportF0_read(void *opaque, hwaddr addr, unsigned size)
{
139
    return 0xffffffffffffffffULL;
140 141
}

B
bellard 已提交
142 143 144
/* TSC handling */
uint64_t cpu_get_tsc(CPUX86State *env)
{
145
    return cpu_get_ticks();
B
bellard 已提交
146 147
}

B
bellard 已提交
148
/* SMM support */
149 150 151 152 153 154 155 156 157 158 159 160

static cpu_set_smm_t smm_set;
static void *smm_arg;

void cpu_smm_register(cpu_set_smm_t callback, void *arg)
{
    assert(smm_set == NULL);
    assert(smm_arg == NULL);
    smm_set = callback;
    smm_arg = arg;
}

A
Andreas Färber 已提交
161
void cpu_smm_update(CPUX86State *env)
B
bellard 已提交
162
{
163 164
    if (smm_set && smm_arg && env == first_cpu)
        smm_set(!!(env->hflags & HF_SMM_MASK), smm_arg);
B
bellard 已提交
165 166 167
}


B
bellard 已提交
168
/* IRQ handling */
A
Andreas Färber 已提交
169
int cpu_get_pic_interrupt(CPUX86State *env)
B
bellard 已提交
170 171 172
{
    int intno;

173
    intno = apic_get_interrupt(env->apic_state);
B
bellard 已提交
174 175 176 177
    if (intno >= 0) {
        return intno;
    }
    /* read the irq from the PIC */
178
    if (!apic_accept_pic_intr(env->apic_state)) {
179
        return -1;
180
    }
181

B
bellard 已提交
182 183 184 185
    intno = pic_read_irq(isa_pic);
    return intno;
}

P
pbrook 已提交
186
static void pic_irq_request(void *opaque, int irq, int level)
B
bellard 已提交
187
{
A
Andreas Färber 已提交
188
    CPUX86State *env = first_cpu;
189

B
Blue Swirl 已提交
190
    DPRINTF("pic_irqs: %s irq %d\n", level? "raise" : "lower", irq);
A
aurel32 已提交
191 192
    if (env->apic_state) {
        while (env) {
193 194 195
            if (apic_accept_pic_intr(env->apic_state)) {
                apic_deliver_pic_intr(env->apic_state, level);
            }
A
aurel32 已提交
196 197 198
            env = env->next_cpu;
        }
    } else {
199 200
        CPUState *cs = CPU(x86_env_get_cpu(env));
        if (level) {
201
            cpu_interrupt(cs, CPU_INTERRUPT_HARD);
202 203 204
        } else {
            cpu_reset_interrupt(cs, CPU_INTERRUPT_HARD);
        }
205
    }
B
bellard 已提交
206 207
}

B
bellard 已提交
208 209
/* PC cmos mappings */

B
bellard 已提交
210 211
#define REG_EQUIPMENT_BYTE          0x14

212
static int cmos_get_fd_drive_type(FDriveType fd0)
213 214 215 216
{
    int val;

    switch (fd0) {
217
    case FDRIVE_DRV_144:
218 219 220
        /* 1.44 Mb 3"5 drive */
        val = 4;
        break;
221
    case FDRIVE_DRV_288:
222 223 224
        /* 2.88 Mb 3"5 drive */
        val = 5;
        break;
225
    case FDRIVE_DRV_120:
226 227 228
        /* 1.2 Mb 5"5 drive */
        val = 2;
        break;
229
    case FDRIVE_DRV_NONE:
230 231 232 233 234 235 236
    default:
        val = 0;
        break;
    }
    return val;
}

237 238
static void cmos_init_hd(ISADevice *s, int type_ofs, int info_ofs,
                         int16_t cylinders, int8_t heads, int8_t sectors)
B
bellard 已提交
239 240 241 242 243 244 245 246 247 248 249 250 251
{
    rtc_set_memory(s, type_ofs, 47);
    rtc_set_memory(s, info_ofs, cylinders);
    rtc_set_memory(s, info_ofs + 1, cylinders >> 8);
    rtc_set_memory(s, info_ofs + 2, heads);
    rtc_set_memory(s, info_ofs + 3, 0xff);
    rtc_set_memory(s, info_ofs + 4, 0xff);
    rtc_set_memory(s, info_ofs + 5, 0xc0 | ((heads > 8) << 3));
    rtc_set_memory(s, info_ofs + 6, cylinders);
    rtc_set_memory(s, info_ofs + 7, cylinders >> 8);
    rtc_set_memory(s, info_ofs + 8, sectors);
}

252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268
/* convert boot_device letter to something recognizable by the bios */
static int boot_device2nibble(char boot_device)
{
    switch(boot_device) {
    case 'a':
    case 'b':
        return 0x01; /* floppy boot */
    case 'c':
        return 0x02; /* hard drive boot */
    case 'd':
        return 0x03; /* CD-ROM boot */
    case 'n':
        return 0x04; /* Network boot */
    }
    return 0;
}

269
static int set_boot_dev(ISADevice *s, const char *boot_device)
270 271 272 273 274 275 276
{
#define PC_MAX_BOOT_DEVICES 3
    int nbds, bds[3] = { 0, };
    int i;

    nbds = strlen(boot_device);
    if (nbds > PC_MAX_BOOT_DEVICES) {
277
        error_report("Too many boot devices for PC");
278 279 280 281 282
        return(1);
    }
    for (i = 0; i < nbds; i++) {
        bds[i] = boot_device2nibble(boot_device[i]);
        if (bds[i] == 0) {
283 284
            error_report("Invalid boot device for PC: '%c'",
                         boot_device[i]);
285 286 287 288
            return(1);
        }
    }
    rtc_set_memory(s, 0x3d, (bds[1] << 4) | bds[0]);
289
    rtc_set_memory(s, 0x38, (bds[2] << 4) | (fd_bootchk ? 0x0 : 0x1));
290 291 292
    return(0);
}

293 294
static int pc_boot_set(void *opaque, const char *boot_device)
{
295
    return set_boot_dev(opaque, boot_device);
296 297
}

298 299
typedef struct pc_cmos_init_late_arg {
    ISADevice *rtc_state;
300
    BusState *idebus[2];
301 302 303 304 305 306
} pc_cmos_init_late_arg;

static void pc_cmos_init_late(void *opaque)
{
    pc_cmos_init_late_arg *arg = opaque;
    ISADevice *s = arg->rtc_state;
307 308
    int16_t cylinders;
    int8_t heads, sectors;
309
    int val;
310
    int i, trans;
311

312 313 314 315 316 317 318 319 320 321 322 323
    val = 0;
    if (ide_get_geometry(arg->idebus[0], 0,
                         &cylinders, &heads, &sectors) >= 0) {
        cmos_init_hd(s, 0x19, 0x1b, cylinders, heads, sectors);
        val |= 0xf0;
    }
    if (ide_get_geometry(arg->idebus[0], 1,
                         &cylinders, &heads, &sectors) >= 0) {
        cmos_init_hd(s, 0x1a, 0x24, cylinders, heads, sectors);
        val |= 0x0f;
    }
    rtc_set_memory(s, 0x12, val);
324 325 326

    val = 0;
    for (i = 0; i < 4; i++) {
327 328 329 330 331 332
        /* NOTE: ide_get_geometry() returns the physical
           geometry.  It is always such that: 1 <= sects <= 63, 1
           <= heads <= 16, 1 <= cylinders <= 16383. The BIOS
           geometry can be different if a translation is done. */
        if (ide_get_geometry(arg->idebus[i / 2], i % 2,
                             &cylinders, &heads, &sectors) >= 0) {
333 334 335
            trans = ide_get_bios_chs_trans(arg->idebus[i / 2], i % 2) - 1;
            assert((trans & ~3) == 0);
            val |= trans << (i * 2);
336 337 338 339 340 341 342
        }
    }
    rtc_set_memory(s, 0x39, val);

    qemu_unregister_reset(pc_cmos_init_late, opaque);
}

343 344 345 346 347 348 349 350 351 352 353 354 355 356 357
typedef struct RTCCPUHotplugArg {
    Notifier cpu_added_notifier;
    ISADevice *rtc_state;
} RTCCPUHotplugArg;

static void rtc_notify_cpu_added(Notifier *notifier, void *data)
{
    RTCCPUHotplugArg *arg = container_of(notifier, RTCCPUHotplugArg,
                                         cpu_added_notifier);
    ISADevice *s = arg->rtc_state;

    /* increment the number of CPUs */
    rtc_set_memory(s, 0x5f, rtc_get_memory(s, 0x5f) + 1);
}

358
void pc_cmos_init(ram_addr_t ram_size, ram_addr_t above_4g_mem_size,
359
                  const char *boot_device,
K
Kevin Wolf 已提交
360
                  ISADevice *floppy, BusState *idebus0, BusState *idebus1,
B
Blue Swirl 已提交
361
                  ISADevice *s)
B
bellard 已提交
362
{
363
    int val, nb, i;
364
    FDriveType fd_type[2] = { FDRIVE_DRV_NONE, FDRIVE_DRV_NONE };
365
    static pc_cmos_init_late_arg arg;
366
    static RTCCPUHotplugArg cpu_hotplug_cb;
B
bellard 已提交
367 368

    /* various important CMOS locations needed by PC/Bochs bios */
B
bellard 已提交
369 370

    /* memory size */
371 372
    /* base memory (first MiB) */
    val = MIN(ram_size / 1024, 640);
B
bellard 已提交
373 374
    rtc_set_memory(s, 0x15, val);
    rtc_set_memory(s, 0x16, val >> 8);
375 376 377 378 379 380
    /* extended memory (next 64MiB) */
    if (ram_size > 1024 * 1024) {
        val = (ram_size - 1024 * 1024) / 1024;
    } else {
        val = 0;
    }
B
bellard 已提交
381 382
    if (val > 65535)
        val = 65535;
B
bellard 已提交
383 384 385 386
    rtc_set_memory(s, 0x17, val);
    rtc_set_memory(s, 0x18, val >> 8);
    rtc_set_memory(s, 0x30, val);
    rtc_set_memory(s, 0x31, val >> 8);
387 388 389 390
    /* memory between 16MiB and 4GiB */
    if (ram_size > 16 * 1024 * 1024) {
        val = (ram_size - 16 * 1024 * 1024) / 65536;
    } else {
B
bellard 已提交
391
        val = 0;
392
    }
B
bellard 已提交
393 394
    if (val > 65535)
        val = 65535;
B
bellard 已提交
395 396
    rtc_set_memory(s, 0x34, val);
    rtc_set_memory(s, 0x35, val >> 8);
397 398 399 400 401
    /* memory above 4GiB */
    val = above_4g_mem_size / 65536;
    rtc_set_memory(s, 0x5b, val);
    rtc_set_memory(s, 0x5c, val >> 8);
    rtc_set_memory(s, 0x5d, val >> 16);
402

A
aurel32 已提交
403 404
    /* set the number of CPU */
    rtc_set_memory(s, 0x5f, smp_cpus - 1);
405 406 407 408
    /* init CPU hotplug notifier */
    cpu_hotplug_cb.rtc_state = s;
    cpu_hotplug_cb.cpu_added_notifier.notify = rtc_notify_cpu_added;
    qemu_register_cpu_added_notifier(&cpu_hotplug_cb.cpu_added_notifier);
A
aurel32 已提交
409

410
    if (set_boot_dev(s, boot_device)) {
411 412
        exit(1);
    }
B
bellard 已提交
413

B
bellard 已提交
414
    /* floppy type */
K
Kevin Wolf 已提交
415 416
    if (floppy) {
        for (i = 0; i < 2; i++) {
417
            fd_type[i] = isa_fdc_get_drive_type(floppy, i);
B
Blue Swirl 已提交
418 419 420 421
        }
    }
    val = (cmos_get_fd_drive_type(fd_type[0]) << 4) |
        cmos_get_fd_drive_type(fd_type[1]);
B
bellard 已提交
422
    rtc_set_memory(s, 0x10, val);
423

B
bellard 已提交
424
    val = 0;
B
bellard 已提交
425
    nb = 0;
B
Blue Swirl 已提交
426
    if (fd_type[0] < FDRIVE_DRV_NONE) {
B
bellard 已提交
427
        nb++;
428
    }
B
Blue Swirl 已提交
429
    if (fd_type[1] < FDRIVE_DRV_NONE) {
B
bellard 已提交
430
        nb++;
431
    }
B
bellard 已提交
432 433 434 435
    switch (nb) {
    case 0:
        break;
    case 1:
B
bellard 已提交
436
        val |= 0x01; /* 1 drive, ready for boot */
B
bellard 已提交
437 438
        break;
    case 2:
B
bellard 已提交
439
        val |= 0x41; /* 2 drives, ready for boot */
B
bellard 已提交
440 441
        break;
    }
B
bellard 已提交
442 443 444 445
    val |= 0x02; /* FPU is there */
    val |= 0x04; /* PS/2 mouse installed */
    rtc_set_memory(s, REG_EQUIPMENT_BYTE, val);

B
bellard 已提交
446
    /* hard drives */
447
    arg.rtc_state = s;
448 449
    arg.idebus[0] = idebus0;
    arg.idebus[1] = idebus1;
450
    qemu_register_reset(pc_cmos_init_late, &arg);
B
bellard 已提交
451 452
}

A
Andreas Färber 已提交
453 454 455
#define TYPE_PORT92 "port92"
#define PORT92(obj) OBJECT_CHECK(Port92State, (obj), TYPE_PORT92)

456 457
/* port 92 stuff: could be split off */
typedef struct Port92State {
A
Andreas Färber 已提交
458 459
    ISADevice parent_obj;

460
    MemoryRegion io;
461 462 463 464
    uint8_t outport;
    qemu_irq *a20_out;
} Port92State;

465 466
static void port92_write(void *opaque, hwaddr addr, uint64_t val,
                         unsigned size)
467 468 469 470 471 472 473 474 475 476 477
{
    Port92State *s = opaque;

    DPRINTF("port92: write 0x%02x\n", val);
    s->outport = val;
    qemu_set_irq(*s->a20_out, (val >> 1) & 1);
    if (val & 1) {
        qemu_system_reset_request();
    }
}

478 479
static uint64_t port92_read(void *opaque, hwaddr addr,
                            unsigned size)
480 481 482 483 484 485 486 487 488 489 490
{
    Port92State *s = opaque;
    uint32_t ret;

    ret = s->outport;
    DPRINTF("port92: read 0x%02x\n", ret);
    return ret;
}

static void port92_init(ISADevice *dev, qemu_irq *a20_out)
{
A
Andreas Färber 已提交
491
    Port92State *s = PORT92(dev);
492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508

    s->a20_out = a20_out;
}

static const VMStateDescription vmstate_port92_isa = {
    .name = "port92",
    .version_id = 1,
    .minimum_version_id = 1,
    .minimum_version_id_old = 1,
    .fields      = (VMStateField []) {
        VMSTATE_UINT8(outport, Port92State),
        VMSTATE_END_OF_LIST()
    }
};

static void port92_reset(DeviceState *d)
{
A
Andreas Färber 已提交
509
    Port92State *s = PORT92(d);
510 511 512 513

    s->outport &= ~1;
}

514
static const MemoryRegionOps port92_ops = {
515 516 517 518 519 520 521
    .read = port92_read,
    .write = port92_write,
    .impl = {
        .min_access_size = 1,
        .max_access_size = 1,
    },
    .endianness = DEVICE_LITTLE_ENDIAN,
522 523
};

524
static void port92_initfn(Object *obj)
525
{
526
    Port92State *s = PORT92(obj);
527

528
    memory_region_init_io(&s->io, OBJECT(s), &port92_ops, s, "port92", 1);
529

530
    s->outport = 0;
531 532 533 534 535 536 537 538
}

static void port92_realizefn(DeviceState *dev, Error **errp)
{
    ISADevice *isadev = ISA_DEVICE(dev);
    Port92State *s = PORT92(dev);

    isa_register_ioport(isadev, &s->io, 0x92);
539 540
}

541 542
static void port92_class_initfn(ObjectClass *klass, void *data)
{
543
    DeviceClass *dc = DEVICE_CLASS(klass);
544

545
    dc->no_user = 1;
546
    dc->realize = port92_realizefn;
547 548
    dc->reset = port92_reset;
    dc->vmsd = &vmstate_port92_isa;
549 550
}

551
static const TypeInfo port92_info = {
A
Andreas Färber 已提交
552
    .name          = TYPE_PORT92,
553 554
    .parent        = TYPE_ISA_DEVICE,
    .instance_size = sizeof(Port92State),
555
    .instance_init = port92_initfn,
556
    .class_init    = port92_class_initfn,
557 558
};

A
Andreas Färber 已提交
559
static void port92_register_types(void)
560
{
561
    type_register_static(&port92_info);
562
}
A
Andreas Färber 已提交
563 564

type_init(port92_register_types)
565

B
Blue Swirl 已提交
566
static void handle_a20_line_change(void *opaque, int irq, int level)
567
{
568
    X86CPU *cpu = opaque;
B
bellard 已提交
569

B
Blue Swirl 已提交
570
    /* XXX: send to all CPUs ? */
571
    /* XXX: add logic to handle multiple A20 line sources */
572
    x86_cpu_set_a20(cpu, level);
B
bellard 已提交
573 574
}

J
Jes Sorensen 已提交
575 576
int e820_add_entry(uint64_t address, uint64_t length, uint32_t type)
{
577
    int index = le32_to_cpu(e820_table.count);
J
Jes Sorensen 已提交
578 579 580 581
    struct e820_entry *entry;

    if (index >= E820_NR_ENTRIES)
        return -EBUSY;
582
    entry = &e820_table.entry[index++];
J
Jes Sorensen 已提交
583

584 585 586
    entry->address = cpu_to_le64(address);
    entry->length = cpu_to_le64(length);
    entry->type = cpu_to_le32(type);
J
Jes Sorensen 已提交
587

588 589
    e820_table.count = cpu_to_le32(index);
    return index;
J
Jes Sorensen 已提交
590 591
}

592 593 594 595 596 597 598 599 600 601 602 603
/* Calculates the limit to CPU APIC ID values
 *
 * This function returns the limit for the APIC ID value, so that all
 * CPU APIC IDs are < pc_apic_id_limit().
 *
 * This is used for FW_CFG_MAX_CPUS. See comments on bochs_bios_init().
 */
static unsigned int pc_apic_id_limit(unsigned int max_cpus)
{
    return x86_cpu_apic_id_from_index(max_cpus - 1) + 1;
}

L
Laszlo Ersek 已提交
604
static FWCfgState *bochs_bios_init(void)
B
bellard 已提交
605
{
L
Laszlo Ersek 已提交
606
    FWCfgState *fw_cfg;
607 608
    uint8_t *smbios_table;
    size_t smbios_len;
609 610
    uint64_t *numa_fw_cfg;
    int i, j;
611
    unsigned int apic_id_limit = pc_apic_id_limit(max_cpus);
612 613

    fw_cfg = fw_cfg_init(BIOS_CFG_IOPORT, BIOS_CFG_IOPORT + 1, 0, 0);
614 615 616 617 618 619 620 621 622 623 624 625 626 627 628
    /* FW_CFG_MAX_CPUS is a bit confusing/problematic on x86:
     *
     * SeaBIOS needs FW_CFG_MAX_CPUS for CPU hotplug, but the CPU hotplug
     * QEMU<->SeaBIOS interface is not based on the "CPU index", but on the APIC
     * ID of hotplugged CPUs[1]. This means that FW_CFG_MAX_CPUS is not the
     * "maximum number of CPUs", but the "limit to the APIC ID values SeaBIOS
     * may see".
     *
     * So, this means we must not use max_cpus, here, but the maximum possible
     * APIC ID value, plus one.
     *
     * [1] The only kind of "CPU identifier" used between SeaBIOS and QEMU is
     *     the APIC ID, not the "CPU index"
     */
    fw_cfg_add_i16(fw_cfg, FW_CFG_MAX_CPUS, (uint16_t)apic_id_limit);
629
    fw_cfg_add_i32(fw_cfg, FW_CFG_ID, 1);
630
    fw_cfg_add_i64(fw_cfg, FW_CFG_RAM_SIZE, (uint64_t)ram_size);
631 632
    fw_cfg_add_bytes(fw_cfg, FW_CFG_ACPI_TABLES,
                     acpi_tables, acpi_tables_len);
633
    fw_cfg_add_i32(fw_cfg, FW_CFG_IRQ0_OVERRIDE, kvm_allows_irq0_override());
634 635 636 637 638

    smbios_table = smbios_get_table(&smbios_len);
    if (smbios_table)
        fw_cfg_add_bytes(fw_cfg, FW_CFG_SMBIOS_ENTRIES,
                         smbios_table, smbios_len);
639 640
    fw_cfg_add_bytes(fw_cfg, FW_CFG_E820_TABLE,
                     &e820_table, sizeof(e820_table));
641

642
    fw_cfg_add_bytes(fw_cfg, FW_CFG_HPET, &hpet_cfg, sizeof(hpet_cfg));
643 644 645 646
    /* allocate memory for the NUMA channel: one (64bit) word for the number
     * of nodes, one word for each VCPU->node and one word for each node to
     * hold the amount of memory.
     */
647
    numa_fw_cfg = g_new0(uint64_t, 1 + apic_id_limit + nb_numa_nodes);
648
    numa_fw_cfg[0] = cpu_to_le64(nb_numa_nodes);
649
    for (i = 0; i < max_cpus; i++) {
650 651
        unsigned int apic_id = x86_cpu_apic_id_from_index(i);
        assert(apic_id < apic_id_limit);
652
        for (j = 0; j < nb_numa_nodes; j++) {
653
            if (test_bit(i, node_cpumask[j])) {
654
                numa_fw_cfg[apic_id + 1] = cpu_to_le64(j);
655 656 657 658 659
                break;
            }
        }
    }
    for (i = 0; i < nb_numa_nodes; i++) {
660
        numa_fw_cfg[apic_id_limit + 1 + i] = cpu_to_le64(node_mem[i]);
661
    }
662
    fw_cfg_add_bytes(fw_cfg, FW_CFG_NUMA, numa_fw_cfg,
663 664
                     (1 + apic_id_limit + nb_numa_nodes) *
                     sizeof(*numa_fw_cfg));
A
Alexander Graf 已提交
665 666

    return fw_cfg;
B
bellard 已提交
667 668
}

T
ths 已提交
669 670 671 672 673 674 675 676 677 678 679 680 681 682
static long get_file_size(FILE *f)
{
    long where, size;

    /* XXX: on Unix systems, using fstat() probably makes more sense */

    where = ftell(f);
    fseek(f, 0, SEEK_END);
    size = ftell(f);
    fseek(f, where, SEEK_SET);

    return size;
}

L
Laszlo Ersek 已提交
683
static void load_linux(FWCfgState *fw_cfg,
684
                       const char *kernel_filename,
L
liguang 已提交
685 686
                       const char *initrd_filename,
                       const char *kernel_cmdline,
A
Avi Kivity 已提交
687
                       hwaddr max_ram_size)
T
ths 已提交
688 689
{
    uint16_t protocol;
P
Paul Brook 已提交
690
    int setup_size, kernel_size, initrd_size = 0, cmdline_size;
T
ths 已提交
691
    uint32_t initrd_max;
692
    uint8_t header[8192], *setup, *kernel, *initrd_data;
A
Avi Kivity 已提交
693
    hwaddr real_addr, prot_addr, cmdline_addr, initrd_addr = 0;
694
    FILE *f;
P
Pascal Terjan 已提交
695
    char *vmode;
T
ths 已提交
696 697 698 699 700 701 702

    /* Align to 16 bytes as a paranoia measure */
    cmdline_size = (strlen(kernel_cmdline)+16) & ~15;

    /* load the kernel header */
    f = fopen(kernel_filename, "rb");
    if (!f || !(kernel_size = get_file_size(f)) ||
L
liguang 已提交
703 704 705 706 707
        fread(header, 1, MIN(ARRAY_SIZE(header), kernel_size), f) !=
        MIN(ARRAY_SIZE(header), kernel_size)) {
        fprintf(stderr, "qemu: could not load kernel '%s': %s\n",
                kernel_filename, strerror(errno));
        exit(1);
T
ths 已提交
708 709 710
    }

    /* kernel protocol version */
B
bellard 已提交
711
#if 0
T
ths 已提交
712
    fprintf(stderr, "header magic: %#x\n", ldl_p(header+0x202));
B
bellard 已提交
713
#endif
L
liguang 已提交
714 715 716 717 718
    if (ldl_p(header+0x202) == 0x53726448) {
        protocol = lduw_p(header+0x206);
    } else {
        /* This looks like a multiboot kernel. If it is, let's stop
           treating it like a Linux kernel. */
719
        if (load_multiboot(fw_cfg, f, kernel_filename, initrd_filename,
L
liguang 已提交
720
                           kernel_cmdline, kernel_size, header)) {
B
Blue Swirl 已提交
721
            return;
L
liguang 已提交
722 723
        }
        protocol = 0;
A
Alexander Graf 已提交
724
    }
T
ths 已提交
725 726

    if (protocol < 0x200 || !(header[0x211] & 0x01)) {
L
liguang 已提交
727 728 729 730
        /* Low kernel */
        real_addr    = 0x90000;
        cmdline_addr = 0x9a000 - cmdline_size;
        prot_addr    = 0x10000;
T
ths 已提交
731
    } else if (protocol < 0x202) {
L
liguang 已提交
732 733 734 735
        /* High but ancient kernel */
        real_addr    = 0x90000;
        cmdline_addr = 0x9a000 - cmdline_size;
        prot_addr    = 0x100000;
T
ths 已提交
736
    } else {
L
liguang 已提交
737 738 739 740
        /* High and recent kernel */
        real_addr    = 0x10000;
        cmdline_addr = 0x20000;
        prot_addr    = 0x100000;
T
ths 已提交
741 742
    }

B
bellard 已提交
743
#if 0
T
ths 已提交
744
    fprintf(stderr,
L
liguang 已提交
745 746 747 748 749 750
            "qemu: real_addr     = 0x" TARGET_FMT_plx "\n"
            "qemu: cmdline_addr  = 0x" TARGET_FMT_plx "\n"
            "qemu: prot_addr     = 0x" TARGET_FMT_plx "\n",
            real_addr,
            cmdline_addr,
            prot_addr);
B
bellard 已提交
751
#endif
T
ths 已提交
752 753

    /* highest address for loading the initrd */
L
liguang 已提交
754 755 756 757 758
    if (protocol >= 0x203) {
        initrd_max = ldl_p(header+0x22c);
    } else {
        initrd_max = 0x37ffffff;
    }
T
ths 已提交
759

G
Glauber Costa 已提交
760 761
    if (initrd_max >= max_ram_size-ACPI_DATA_SIZE)
    	initrd_max = max_ram_size-ACPI_DATA_SIZE-1;
T
ths 已提交
762

763 764
    fw_cfg_add_i32(fw_cfg, FW_CFG_CMDLINE_ADDR, cmdline_addr);
    fw_cfg_add_i32(fw_cfg, FW_CFG_CMDLINE_SIZE, strlen(kernel_cmdline)+1);
765
    fw_cfg_add_string(fw_cfg, FW_CFG_CMDLINE_DATA, kernel_cmdline);
T
ths 已提交
766 767

    if (protocol >= 0x202) {
L
liguang 已提交
768
        stl_p(header+0x228, cmdline_addr);
T
ths 已提交
769
    } else {
L
liguang 已提交
770 771
        stw_p(header+0x20, 0xA33F);
        stw_p(header+0x22, cmdline_addr-real_addr);
T
ths 已提交
772 773
    }

P
Pascal Terjan 已提交
774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791
    /* handle vga= parameter */
    vmode = strstr(kernel_cmdline, "vga=");
    if (vmode) {
        unsigned int video_mode;
        /* skip "vga=" */
        vmode += 4;
        if (!strncmp(vmode, "normal", 6)) {
            video_mode = 0xffff;
        } else if (!strncmp(vmode, "ext", 3)) {
            video_mode = 0xfffe;
        } else if (!strncmp(vmode, "ask", 3)) {
            video_mode = 0xfffd;
        } else {
            video_mode = strtol(vmode, NULL, 0);
        }
        stw_p(header+0x1fa, video_mode);
    }

T
ths 已提交
792
    /* loader type */
S
Stefan Weil 已提交
793
    /* High nybble = B reserved for QEMU; low nybble is revision number.
T
ths 已提交
794 795
       If this code is substantially changed, you may want to consider
       incrementing the revision. */
L
liguang 已提交
796 797 798
    if (protocol >= 0x200) {
        header[0x210] = 0xB0;
    }
T
ths 已提交
799 800
    /* heap */
    if (protocol >= 0x201) {
L
liguang 已提交
801 802
        header[0x211] |= 0x80;	/* CAN_USE_HEAP */
        stw_p(header+0x224, cmdline_addr-real_addr-0x200);
T
ths 已提交
803 804 805 806
    }

    /* load initrd */
    if (initrd_filename) {
L
liguang 已提交
807 808 809 810
        if (protocol < 0x200) {
            fprintf(stderr, "qemu: linux kernel too old to load a ram disk\n");
            exit(1);
        }
T
ths 已提交
811

L
liguang 已提交
812
        initrd_size = get_image_size(initrd_filename);
M
M. Mohan Kumar 已提交
813 814 815 816 817 818
        if (initrd_size < 0) {
            fprintf(stderr, "qemu: error reading initrd %s\n",
                    initrd_filename);
            exit(1);
        }

819
        initrd_addr = (initrd_max-initrd_size) & ~4095;
820

821
        initrd_data = g_malloc(initrd_size);
822 823 824 825 826
        load_image(initrd_filename, initrd_data);

        fw_cfg_add_i32(fw_cfg, FW_CFG_INITRD_ADDR, initrd_addr);
        fw_cfg_add_i32(fw_cfg, FW_CFG_INITRD_SIZE, initrd_size);
        fw_cfg_add_bytes(fw_cfg, FW_CFG_INITRD_DATA, initrd_data, initrd_size);
T
ths 已提交
827

L
liguang 已提交
828 829
        stl_p(header+0x218, initrd_addr);
        stl_p(header+0x21c, initrd_size);
T
ths 已提交
830 831
    }

832
    /* load kernel and setup */
T
ths 已提交
833
    setup_size = header[0x1f1];
L
liguang 已提交
834 835 836
    if (setup_size == 0) {
        setup_size = 4;
    }
T
ths 已提交
837
    setup_size = (setup_size+1)*512;
838
    kernel_size -= setup_size;
T
ths 已提交
839

840 841
    setup  = g_malloc(setup_size);
    kernel = g_malloc(kernel_size);
842
    fseek(f, 0, SEEK_SET);
843 844 845 846 847 848 849 850
    if (fread(setup, 1, setup_size, f) != setup_size) {
        fprintf(stderr, "fread() failed\n");
        exit(1);
    }
    if (fread(kernel, 1, kernel_size, f) != kernel_size) {
        fprintf(stderr, "fread() failed\n");
        exit(1);
    }
T
ths 已提交
851
    fclose(f);
852
    memcpy(setup, header, MIN(sizeof(header), setup_size));
853 854 855 856 857 858 859 860 861

    fw_cfg_add_i32(fw_cfg, FW_CFG_KERNEL_ADDR, prot_addr);
    fw_cfg_add_i32(fw_cfg, FW_CFG_KERNEL_SIZE, kernel_size);
    fw_cfg_add_bytes(fw_cfg, FW_CFG_KERNEL_DATA, kernel, kernel_size);

    fw_cfg_add_i32(fw_cfg, FW_CFG_SETUP_ADDR, real_addr);
    fw_cfg_add_i32(fw_cfg, FW_CFG_SETUP_SIZE, setup_size);
    fw_cfg_add_bytes(fw_cfg, FW_CFG_SETUP_DATA, setup, setup_size);

G
Gleb Natapov 已提交
862 863
    option_rom[nb_option_roms].name = "linuxboot.bin";
    option_rom[nb_option_roms].bootindex = 0;
864
    nb_option_roms++;
T
ths 已提交
865 866
}

B
bellard 已提交
867 868
#define NE2000_NB_MAX 6

B
Blue Swirl 已提交
869 870 871
static const int ne2000_io[NE2000_NB_MAX] = { 0x300, 0x320, 0x340, 0x360,
                                              0x280, 0x380 };
static const int ne2000_irq[NE2000_NB_MAX] = { 9, 10, 11, 3, 4, 5 };
B
bellard 已提交
872

B
Blue Swirl 已提交
873 874
static const int parallel_io[MAX_PARALLEL_PORTS] = { 0x378, 0x278, 0x3bc };
static const int parallel_irq[MAX_PARALLEL_PORTS] = { 7, 7, 7 };
875

876
void pc_init_ne2k_isa(ISABus *bus, NICInfo *nd)
877 878 879 880 881
{
    static int nb_ne2k = 0;

    if (nb_ne2k == NE2000_NB_MAX)
        return;
882
    isa_ne2000_init(bus, ne2000_io[nb_ne2k],
G
Gerd Hoffmann 已提交
883
                    ne2000_irq[nb_ne2k], nd);
884 885 886
    nb_ne2k++;
}

B
Blue Swirl 已提交
887
DeviceState *cpu_get_current_apic(void)
888
{
889 890 891
    if (current_cpu) {
        X86CPU *cpu = X86_CPU(current_cpu);
        return cpu->env.apic_state;
892 893 894 895 896
    } else {
        return NULL;
    }
}

897
void pc_acpi_smi_interrupt(void *opaque, int irq, int level)
B
Blue Swirl 已提交
898
{
899
    X86CPU *cpu = opaque;
B
Blue Swirl 已提交
900 901

    if (level) {
902
        cpu_interrupt(CPU(cpu), CPU_INTERRUPT_SMI);
B
Blue Swirl 已提交
903 904 905
    }
}

906 907
static X86CPU *pc_new_cpu(const char *cpu_model, int64_t apic_id,
                          DeviceState *icc_bridge, Error **errp)
908 909 910 911
{
    X86CPU *cpu;
    Error *local_err = NULL;

912
    cpu = cpu_x86_create(cpu_model, icc_bridge, errp);
913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929
    if (!cpu) {
        return cpu;
    }

    object_property_set_int(OBJECT(cpu), apic_id, "apic-id", &local_err);
    object_property_set_bool(OBJECT(cpu), true, "realized", &local_err);

    if (local_err) {
        if (cpu != NULL) {
            object_unref(OBJECT(cpu));
            cpu = NULL;
        }
        error_propagate(errp, local_err);
    }
    return cpu;
}

930 931 932 933 934 935 936
static const char *current_cpu_model;

void pc_hot_add_cpu(const int64_t id, Error **errp)
{
    DeviceState *icc_bridge;
    int64_t apic_id = x86_cpu_apic_id_from_index(id);

937 938 939 940 941
    if (id < 0) {
        error_setg(errp, "Invalid CPU id: %" PRIi64, id);
        return;
    }

942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958
    if (cpu_exists(apic_id)) {
        error_setg(errp, "Unable to add CPU: %" PRIi64
                   ", it already exists", id);
        return;
    }

    if (id >= max_cpus) {
        error_setg(errp, "Unable to add CPU: %" PRIi64
                   ", max allowed: %d", id, max_cpus - 1);
        return;
    }

    icc_bridge = DEVICE(object_resolve_path_type("icc-bridge",
                                                 TYPE_ICC_BRIDGE, NULL));
    pc_new_cpu(current_cpu_model, apic_id, icc_bridge, errp);
}

959
void pc_cpus_init(const char *cpu_model, DeviceState *icc_bridge)
960 961
{
    int i;
962
    X86CPU *cpu = NULL;
963
    Error *error = NULL;
964 965 966 967 968 969 970 971 972

    /* init CPUs */
    if (cpu_model == NULL) {
#ifdef TARGET_X86_64
        cpu_model = "qemu64";
#else
        cpu_model = "qemu32";
#endif
    }
973
    current_cpu_model = cpu_model;
974

975
    for (i = 0; i < smp_cpus; i++) {
976 977
        cpu = pc_new_cpu(cpu_model, x86_cpu_apic_id_from_index(i),
                         icc_bridge, &error);
978 979 980
        if (error) {
            fprintf(stderr, "%s\n", error_get_pretty(error));
            error_free(error);
981 982
            exit(1);
        }
983
    }
984 985 986 987 988 989 990

    /* map APIC MMIO area if CPU has APIC */
    if (cpu && cpu->env.apic_state) {
        /* XXX: what if the base changes? */
        sysbus_mmio_map_overlap(SYS_BUS_DEVICE(icc_bridge), 0,
                                APIC_DEFAULT_ADDRESS, 0x1000);
    }
991 992
}

993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017
/* pci-info ROM file. Little endian format */
typedef struct PcRomPciInfo {
    uint64_t w32_min;
    uint64_t w32_max;
    uint64_t w64_min;
    uint64_t w64_max;
} PcRomPciInfo;

static void pc_fw_cfg_guest_info(PcGuestInfo *guest_info)
{
    PcRomPciInfo *info;
    if (!guest_info->has_pci_info) {
        return;
    }

    info = g_malloc(sizeof *info);
    info->w32_min = cpu_to_le64(guest_info->pci_info.w32.begin);
    info->w32_max = cpu_to_le64(guest_info->pci_info.w32.end);
    info->w64_min = cpu_to_le64(guest_info->pci_info.w64.begin);
    info->w64_max = cpu_to_le64(guest_info->pci_info.w64.end);
    /* Pass PCI hole info to guest via a side channel.
     * Required so guest PCI enumeration does the right thing. */
    fw_cfg_add_file(guest_info->fw_cfg, "etc/pci-info", info, sizeof *info);
}

1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028
typedef struct PcGuestInfoState {
    PcGuestInfo info;
    Notifier machine_done;
} PcGuestInfoState;

static
void pc_guest_info_machine_done(Notifier *notifier, void *data)
{
    PcGuestInfoState *guest_info_state = container_of(notifier,
                                                      PcGuestInfoState,
                                                      machine_done);
1029
    pc_fw_cfg_guest_info(&guest_info_state->info);
1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060
}

PcGuestInfo *pc_guest_info_init(ram_addr_t below_4g_mem_size,
                                ram_addr_t above_4g_mem_size)
{
    PcGuestInfoState *guest_info_state = g_malloc0(sizeof *guest_info_state);
    PcGuestInfo *guest_info = &guest_info_state->info;

    guest_info->pci_info.w32.end = IO_APIC_DEFAULT_ADDRESS;
    if (sizeof(hwaddr) == 4) {
        guest_info->pci_info.w64.begin = 0;
        guest_info->pci_info.w64.end = 0;
    } else {
        /*
         * BIOS does not set MTRR entries for the 64 bit window, so no need to
         * align address to power of two.  Align address at 1G, this makes sure
         * it can be exactly covered with a PAT entry even when using huge
         * pages.
         */
        guest_info->pci_info.w64.begin =
            ROUND_UP((0x1ULL << 32) + above_4g_mem_size, 0x1ULL << 30);
        guest_info->pci_info.w64.end = guest_info->pci_info.w64.begin +
            (0x1ULL << 62);
        assert(guest_info->pci_info.w64.begin <= guest_info->pci_info.w64.end);
    }

    guest_info_state->machine_done.notify = pc_guest_info_machine_done;
    qemu_add_machine_init_done_notifier(&guest_info_state->machine_done);
    return guest_info;
}

G
Gerd Hoffmann 已提交
1061 1062
void pc_acpi_init(const char *default_dsdt)
{
1063
    char *filename;
G
Gerd Hoffmann 已提交
1064 1065 1066 1067 1068 1069 1070 1071 1072

    if (acpi_tables != NULL) {
        /* manually set via -acpitable, leave it alone */
        return;
    }

    filename = qemu_find_file(QEMU_FILE_TYPE_BIOS, default_dsdt);
    if (filename == NULL) {
        fprintf(stderr, "WARNING: failed to find %s\n", default_dsdt);
1073 1074 1075 1076
    } else {
        char *arg;
        QemuOpts *opts;
        Error *err = NULL;
G
Gerd Hoffmann 已提交
1077

1078
        arg = g_strdup_printf("file=%s", filename);
1079

1080 1081 1082
        /* creates a deep copy of "arg" */
        opts = qemu_opts_parse(qemu_find_opts("acpi"), arg, 0);
        g_assert(opts != NULL);
1083

1084 1085 1086 1087 1088 1089 1090 1091
        acpi_table_add(opts, &err);
        if (err) {
            fprintf(stderr, "WARNING: failed to load %s: %s\n", filename,
                    error_get_pretty(err));
            error_free(err);
        }
        g_free(arg);
        g_free(filename);
G
Gerd Hoffmann 已提交
1092 1093 1094
    }
}

L
Laszlo Ersek 已提交
1095 1096 1097 1098 1099 1100 1101
FWCfgState *pc_memory_init(MemoryRegion *system_memory,
                           const char *kernel_filename,
                           const char *kernel_cmdline,
                           const char *initrd_filename,
                           ram_addr_t below_4g_mem_size,
                           ram_addr_t above_4g_mem_size,
                           MemoryRegion *rom_memory,
1102 1103
                           MemoryRegion **ram_memory,
                           PcGuestInfo *guest_info)
B
bellard 已提交
1104
{
1105 1106
    int linux_boot, i;
    MemoryRegion *ram, *option_rom_mr;
1107
    MemoryRegion *ram_below_4g, *ram_above_4g;
L
Laszlo Ersek 已提交
1108
    FWCfgState *fw_cfg;
1109

B
bellard 已提交
1110 1111
    linux_boot = (kernel_filename != NULL);

1112
    /* Allocate RAM.  We allocate it as a single memory region and use
D
Dong Xu Wang 已提交
1113
     * aliases to address portions of it, mostly for backwards compatibility
1114 1115
     * with older qemus that used qemu_ram_alloc().
     */
1116
    ram = g_malloc(sizeof(*ram));
1117
    memory_region_init_ram(ram, NULL, "pc.ram",
1118
                           below_4g_mem_size + above_4g_mem_size);
1119
    vmstate_register_ram_global(ram);
A
Avi Kivity 已提交
1120
    *ram_memory = ram;
1121
    ram_below_4g = g_malloc(sizeof(*ram_below_4g));
1122
    memory_region_init_alias(ram_below_4g, NULL, "ram-below-4g", ram,
1123 1124
                             0, below_4g_mem_size);
    memory_region_add_subregion(system_memory, 0, ram_below_4g);
1125
    if (above_4g_mem_size > 0) {
1126
        ram_above_4g = g_malloc(sizeof(*ram_above_4g));
1127
        memory_region_init_alias(ram_above_4g, NULL, "ram-above-4g", ram,
1128 1129 1130
                                 below_4g_mem_size, above_4g_mem_size);
        memory_region_add_subregion(system_memory, 0x100000000ULL,
                                    ram_above_4g);
1131
    }
1132

1133 1134 1135

    /* Initialize PC system firmware */
    pc_system_firmware_init(rom_memory);
1136

1137
    option_rom_mr = g_malloc(sizeof(*option_rom_mr));
1138
    memory_region_init_ram(option_rom_mr, NULL, "pc.rom", PC_ROM_SIZE);
1139
    vmstate_register_ram_global(option_rom_mr);
1140
    memory_region_add_subregion_overlap(rom_memory,
1141 1142 1143
                                        PC_ROM_MIN_VGA,
                                        option_rom_mr,
                                        1);
1144

A
Alexander Graf 已提交
1145
    fw_cfg = bochs_bios_init();
G
Gerd Hoffmann 已提交
1146
    rom_set_fw(fw_cfg);
A
Alexander Graf 已提交
1147

1148
    if (linux_boot) {
1149
        load_linux(fw_cfg, kernel_filename, initrd_filename, kernel_cmdline, below_4g_mem_size);
1150 1151 1152
    }

    for (i = 0; i < nb_option_roms; i++) {
G
Gleb Natapov 已提交
1153
        rom_add_option(option_rom[i].name, option_rom[i].bootindex);
1154
    }
1155
    guest_info->fw_cfg = fw_cfg;
1156
    return fw_cfg;
1157 1158
}

1159 1160 1161 1162 1163
qemu_irq *pc_allocate_cpu_irq(void)
{
    return qemu_allocate_irqs(pic_irq_request, NULL, 1);
}

1164
DeviceState *pc_vga_init(ISABus *isa_bus, PCIBus *pci_bus)
1165
{
1166 1167
    DeviceState *dev = NULL;

1168 1169 1170 1171 1172
    if (pci_bus) {
        PCIDevice *pcidev = pci_vga_init(pci_bus);
        dev = pcidev ? &pcidev->qdev : NULL;
    } else if (isa_bus) {
        ISADevice *isadev = isa_vga_init(isa_bus);
A
Andreas Färber 已提交
1173
        dev = isadev ? DEVICE(isadev) : NULL;
1174
    }
1175
    return dev;
1176 1177
}

B
Blue Swirl 已提交
1178 1179
static void cpu_request_exit(void *opaque, int irq, int level)
{
1180
    CPUState *cpu = current_cpu;
B
Blue Swirl 已提交
1181

1182 1183
    if (cpu && level) {
        cpu_exit(cpu);
B
Blue Swirl 已提交
1184 1185 1186
    }
}

J
Julien Grall 已提交
1187 1188
static const MemoryRegionOps ioport80_io_ops = {
    .write = ioport80_write,
1189
    .read = ioport80_read,
J
Julien Grall 已提交
1190 1191 1192 1193 1194 1195 1196 1197 1198
    .endianness = DEVICE_NATIVE_ENDIAN,
    .impl = {
        .min_access_size = 1,
        .max_access_size = 1,
    },
};

static const MemoryRegionOps ioportF0_io_ops = {
    .write = ioportF0_write,
1199
    .read = ioportF0_read,
J
Julien Grall 已提交
1200 1201 1202 1203 1204 1205 1206
    .endianness = DEVICE_NATIVE_ENDIAN,
    .impl = {
        .min_access_size = 1,
        .max_access_size = 1,
    },
};

1207
void pc_basic_device_init(ISABus *isa_bus, qemu_irq *gsi,
1208
                          ISADevice **rtc_state,
K
Kevin Wolf 已提交
1209
                          ISADevice **floppy,
1210
                          bool no_vmport)
1211 1212 1213
{
    int i;
    DriveInfo *fd[MAX_FD];
1214 1215 1216
    DeviceState *hpet = NULL;
    int pit_isa_irq = 0;
    qemu_irq pit_alt_irq = NULL;
1217
    qemu_irq rtc_irq = NULL;
B
Blue Swirl 已提交
1218
    qemu_irq *a20_line;
1219
    ISADevice *i8042, *port92, *vmmouse, *pit = NULL;
B
Blue Swirl 已提交
1220
    qemu_irq *cpu_exit_irq;
J
Julien Grall 已提交
1221 1222
    MemoryRegion *ioport80_io = g_new(MemoryRegion, 1);
    MemoryRegion *ioportF0_io = g_new(MemoryRegion, 1);
1223

1224
    memory_region_init_io(ioport80_io, NULL, &ioport80_io_ops, NULL, "ioport80", 1);
J
Julien Grall 已提交
1225
    memory_region_add_subregion(isa_bus->address_space_io, 0x80, ioport80_io);
1226

1227
    memory_region_init_io(ioportF0_io, NULL, &ioportF0_io_ops, NULL, "ioportF0", 1);
J
Julien Grall 已提交
1228
    memory_region_add_subregion(isa_bus->address_space_io, 0xf0, ioportF0_io);
1229

1230 1231 1232 1233 1234 1235 1236
    /*
     * Check if an HPET shall be created.
     *
     * Without KVM_CAP_PIT_STATE2, we cannot switch off the in-kernel PIT
     * when the HPET wants to take over. Thus we have to disable the latter.
     */
    if (!no_hpet && (!kvm_irqchip_in_kernel() || kvm_has_pit_state2())) {
1237
        hpet = sysbus_try_create_simple("hpet", HPET_BASE, NULL);
J
Jan Kiszka 已提交
1238

B
Blue Swirl 已提交
1239
        if (hpet) {
J
Jan Kiszka 已提交
1240
            for (i = 0; i < GSI_NUM_PINS; i++) {
1241
                sysbus_connect_irq(SYS_BUS_DEVICE(hpet), i, gsi[i]);
B
Blue Swirl 已提交
1242
            }
1243 1244 1245
            pit_isa_irq = -1;
            pit_alt_irq = qdev_get_gpio_in(hpet, HPET_LEGACY_PIT_INT);
            rtc_irq = qdev_get_gpio_in(hpet, HPET_LEGACY_RTC_INT);
J
Jan Kiszka 已提交
1246
        }
1247
    }
1248
    *rtc_state = rtc_init(isa_bus, 2000, rtc_irq);
1249 1250 1251

    qemu_register_boot_set(pc_boot_set, *rtc_state);

1252 1253 1254 1255 1256 1257 1258 1259
    if (!xen_enabled()) {
        if (kvm_irqchip_in_kernel()) {
            pit = kvm_pit_init(isa_bus, 0x40);
        } else {
            pit = pit_init(isa_bus, 0x40, pit_isa_irq, pit_alt_irq);
        }
        if (hpet) {
            /* connect PIT to output control line of the HPET */
A
Andreas Färber 已提交
1260
            qdev_connect_gpio_out(hpet, 0, qdev_get_gpio_in(DEVICE(pit), 0));
1261 1262
        }
        pcspk_init(isa_bus, pit);
1263
    }
1264 1265 1266

    for(i = 0; i < MAX_SERIAL_PORTS; i++) {
        if (serial_hds[i]) {
1267
            serial_isa_init(isa_bus, i, serial_hds[i]);
1268 1269 1270 1271 1272
        }
    }

    for(i = 0; i < MAX_PARALLEL_PORTS; i++) {
        if (parallel_hds[i]) {
1273
            parallel_init(isa_bus, i, parallel_hds[i]);
1274 1275 1276
        }
    }

1277 1278
    a20_line = qemu_allocate_irqs(handle_a20_line_change,
                                  x86_env_get_cpu(first_cpu), 2);
1279
    i8042 = isa_create_simple(isa_bus, "i8042");
1280
    i8042_setup_a20_line(i8042, &a20_line[0]);
1281
    if (!no_vmport) {
1282 1283
        vmport_init(isa_bus);
        vmmouse = isa_try_create(isa_bus, "vmmouse");
1284 1285 1286
    } else {
        vmmouse = NULL;
    }
B
Blue Swirl 已提交
1287
    if (vmmouse) {
A
Andreas Färber 已提交
1288 1289 1290
        DeviceState *dev = DEVICE(vmmouse);
        qdev_prop_set_ptr(dev, "ps2_mouse", i8042);
        qdev_init_nofail(dev);
B
Blue Swirl 已提交
1291
    }
1292
    port92 = isa_create_simple(isa_bus, "port92");
1293
    port92_init(port92, &a20_line[1]);
B
Blue Swirl 已提交
1294

B
Blue Swirl 已提交
1295 1296
    cpu_exit_irq = qemu_allocate_irqs(cpu_request_exit, NULL, 1);
    DMA_init(0, cpu_exit_irq);
1297 1298 1299 1300

    for(i = 0; i < MAX_FD; i++) {
        fd[i] = drive_get(IF_FLOPPY, 0, i);
    }
1301
    *floppy = fdctrl_init_isa(isa_bus, fd);
1302 1303
}

1304 1305 1306 1307 1308 1309 1310 1311 1312 1313
void pc_nic_init(ISABus *isa_bus, PCIBus *pci_bus)
{
    int i;

    for (i = 0; i < nb_nics; i++) {
        NICInfo *nd = &nd_table[i];

        if (!pci_bus || (nd->model && strcmp(nd->model, "ne2k_isa") == 0)) {
            pc_init_ne2k_isa(isa_bus, nd);
        } else {
1314
            pci_nic_init_nofail(nd, pci_bus, "e1000", NULL);
1315 1316 1317 1318
        }
    }
}

1319
void pc_pci_device_init(PCIBus *pci_bus)
1320 1321 1322 1323 1324 1325 1326 1327 1328
{
    int max_bus;
    int bus;

    max_bus = drive_get_max_bus(IF_SCSI);
    for (bus = 0; bus <= max_bus; bus++) {
        pci_create_simple(pci_bus, -1, "lsi53c895a");
    }
}
1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345

void ioapic_init_gsi(GSIState *gsi_state, const char *parent_name)
{
    DeviceState *dev;
    SysBusDevice *d;
    unsigned int i;

    if (kvm_irqchip_in_kernel()) {
        dev = qdev_create(NULL, "kvm-ioapic");
    } else {
        dev = qdev_create(NULL, "ioapic");
    }
    if (parent_name) {
        object_property_add_child(object_resolve_path(parent_name, NULL),
                                  "ioapic", OBJECT(dev), NULL);
    }
    qdev_init_nofail(dev);
1346
    d = SYS_BUS_DEVICE(dev);
1347
    sysbus_mmio_map(d, 0, IO_APIC_DEFAULT_ADDRESS);
1348 1349 1350 1351 1352

    for (i = 0; i < IOAPIC_NUM_PINS; i++) {
        gsi_state->ioapic_irq[i] = qdev_get_gpio_in(dev, i);
    }
}