virtio-net.c 31.2 KB
Newer Older
A
aliguori 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13
/*
 * Virtio Network Device
 *
 * Copyright IBM, Corp. 2007
 *
 * Authors:
 *  Anthony Liguori   <aliguori@us.ibm.com>
 *
 * This work is licensed under the terms of the GNU GPL, version 2.  See
 * the COPYING file in the top-level directory.
 *
 */

14
#include "iov.h"
A
aliguori 已提交
15 16
#include "virtio.h"
#include "net.h"
17
#include "net/checksum.h"
18
#include "net/tap.h"
19
#include "qemu-error.h"
A
aliguori 已提交
20 21
#include "qemu-timer.h"
#include "virtio-net.h"
22
#include "vhost_net.h"
A
aliguori 已提交
23

24
#define VIRTIO_NET_VM_VERSION    11
25

26
#define MAC_TABLE_ENTRIES    64
27
#define MAX_VLAN    (1 << 12)   /* Per 802.1Q definition */
28

A
aliguori 已提交
29 30 31
typedef struct VirtIONet
{
    VirtIODevice vdev;
32
    uint8_t mac[ETH_ALEN];
33
    uint16_t status;
A
aliguori 已提交
34 35
    VirtQueue *rx_vq;
    VirtQueue *tx_vq;
36
    VirtQueue *ctrl_vq;
M
Mark McLoughlin 已提交
37
    NICState *nic;
A
aliguori 已提交
38
    QEMUTimer *tx_timer;
39
    QEMUBH *tx_bh;
40
    uint32_t tx_timeout;
41
    int32_t tx_burst;
42
    int tx_waiting;
M
Mark McLoughlin 已提交
43
    uint32_t has_vnet_hdr;
44
    uint8_t has_ufo;
45 46 47 48
    struct {
        VirtQueueElement elem;
        ssize_t len;
    } async_tx;
A
aliguori 已提交
49
    int mergeable_rx_bufs;
50 51
    uint8_t promisc;
    uint8_t allmulti;
52 53 54 55
    uint8_t alluni;
    uint8_t nomulti;
    uint8_t nouni;
    uint8_t nobcast;
56
    uint8_t vhost_started;
57 58
    struct {
        int in_use;
59
        int first_multi;
60 61
        uint8_t multi_overflow;
        uint8_t uni_overflow;
62 63
        uint8_t *macs;
    } mac_table;
64
    uint32_t *vlans;
65
    DeviceState *qdev;
A
aliguori 已提交
66 67 68 69 70 71 72 73 74 75 76
} VirtIONet;

/* TODO
 * - we could suppress RX interrupt if we were so inclined.
 */

static VirtIONet *to_virtio_net(VirtIODevice *vdev)
{
    return (VirtIONet *)vdev;
}

77
static void virtio_net_get_config(VirtIODevice *vdev, uint8_t *config)
A
aliguori 已提交
78 79 80 81
{
    VirtIONet *n = to_virtio_net(vdev);
    struct virtio_net_config netcfg;

82
    netcfg.status = lduw_p(&n->status);
83
    memcpy(netcfg.mac, n->mac, ETH_ALEN);
A
aliguori 已提交
84 85 86
    memcpy(config, &netcfg, sizeof(netcfg));
}

87 88 89 90 91 92 93
static void virtio_net_set_config(VirtIODevice *vdev, const uint8_t *config)
{
    VirtIONet *n = to_virtio_net(vdev);
    struct virtio_net_config netcfg;

    memcpy(&netcfg, config, sizeof(netcfg));

94 95
    if (memcmp(netcfg.mac, n->mac, ETH_ALEN)) {
        memcpy(n->mac, netcfg.mac, ETH_ALEN);
M
Mark McLoughlin 已提交
96
        qemu_format_nic_info_str(&n->nic->nc, n->mac);
97 98 99
    }
}

100 101 102
static bool virtio_net_started(VirtIONet *n, uint8_t status)
{
    return (status & VIRTIO_CONFIG_S_DRIVER_OK) &&
103
        (n->status & VIRTIO_NET_S_LINK_UP) && n->vdev.vm_running;
104 105 106
}

static void virtio_net_vhost_status(VirtIONet *n, uint8_t status)
107 108 109 110 111 112 113 114 115 116 117
{
    if (!n->nic->nc.peer) {
        return;
    }
    if (n->nic->nc.peer->info->type != NET_CLIENT_TYPE_TAP) {
        return;
    }

    if (!tap_get_vhost_net(n->nic->nc.peer)) {
        return;
    }
118
    if (!!n->vhost_started == virtio_net_started(n, status)) {
119 120 121
        return;
    }
    if (!n->vhost_started) {
122 123 124 125 126
        int r;
        if (!vhost_net_query(tap_get_vhost_net(n->nic->nc.peer), &n->vdev)) {
            return;
        }
        r = vhost_net_start(tap_get_vhost_net(n->nic->nc.peer), &n->vdev);
127
        if (r < 0) {
128 129
            error_report("unable to start vhost net: %d: "
                         "falling back on userspace virtio", -r);
130 131 132 133 134 135 136 137 138
        } else {
            n->vhost_started = 1;
        }
    } else {
        vhost_net_stop(tap_get_vhost_net(n->nic->nc.peer), &n->vdev);
        n->vhost_started = 0;
    }
}

139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164
static void virtio_net_set_status(struct VirtIODevice *vdev, uint8_t status)
{
    VirtIONet *n = to_virtio_net(vdev);

    virtio_net_vhost_status(n, status);

    if (!n->tx_waiting) {
        return;
    }

    if (virtio_net_started(n, status) && !n->vhost_started) {
        if (n->tx_timer) {
            qemu_mod_timer(n->tx_timer,
                           qemu_get_clock(vm_clock) + n->tx_timeout);
        } else {
            qemu_bh_schedule(n->tx_bh);
        }
    } else {
        if (n->tx_timer) {
            qemu_del_timer(n->tx_timer);
        } else {
            qemu_bh_cancel(n->tx_bh);
        }
    }
}

M
Mark McLoughlin 已提交
165
static void virtio_net_set_link_status(VLANClientState *nc)
166
{
M
Mark McLoughlin 已提交
167
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
168 169
    uint16_t old_status = n->status;

M
Mark McLoughlin 已提交
170
    if (nc->link_down)
171 172 173 174 175 176
        n->status &= ~VIRTIO_NET_S_LINK_UP;
    else
        n->status |= VIRTIO_NET_S_LINK_UP;

    if (n->status != old_status)
        virtio_notify_config(&n->vdev);
177 178

    virtio_net_set_status(&n->vdev, n->vdev.status);
179 180
}

181 182 183 184 185 186 187
static void virtio_net_reset(VirtIODevice *vdev)
{
    VirtIONet *n = to_virtio_net(vdev);

    /* Reset back to compatibility mode */
    n->promisc = 1;
    n->allmulti = 0;
188 189 190 191
    n->alluni = 0;
    n->nomulti = 0;
    n->nouni = 0;
    n->nobcast = 0;
192

193
    /* Flush any MAC and VLAN filter table state */
194
    n->mac_table.in_use = 0;
195
    n->mac_table.first_multi = 0;
196 197
    n->mac_table.multi_overflow = 0;
    n->mac_table.uni_overflow = 0;
198
    memset(n->mac_table.macs, 0, MAC_TABLE_ENTRIES * ETH_ALEN);
199
    memset(n->vlans, 0, MAX_VLAN >> 3);
200 201
}

M
Mark McLoughlin 已提交
202 203
static int peer_has_vnet_hdr(VirtIONet *n)
{
M
Mark McLoughlin 已提交
204
    if (!n->nic->nc.peer)
M
Mark McLoughlin 已提交
205 206
        return 0;

207
    if (n->nic->nc.peer->info->type != NET_CLIENT_TYPE_TAP)
M
Mark McLoughlin 已提交
208 209
        return 0;

M
Mark McLoughlin 已提交
210
    n->has_vnet_hdr = tap_has_vnet_hdr(n->nic->nc.peer);
M
Mark McLoughlin 已提交
211 212 213 214

    return n->has_vnet_hdr;
}

215 216 217 218 219
static int peer_has_ufo(VirtIONet *n)
{
    if (!peer_has_vnet_hdr(n))
        return 0;

M
Mark McLoughlin 已提交
220
    n->has_ufo = tap_has_ufo(n->nic->nc.peer);
221 222 223 224

    return n->has_ufo;
}

225
static uint32_t virtio_net_get_features(VirtIODevice *vdev, uint32_t features)
A
aliguori 已提交
226
{
M
Mark McLoughlin 已提交
227
    VirtIONet *n = to_virtio_net(vdev);
A
aliguori 已提交
228

229 230
    features |= (1 << VIRTIO_NET_F_MAC);

M
Mark McLoughlin 已提交
231
    if (peer_has_vnet_hdr(n)) {
M
Mark McLoughlin 已提交
232
        tap_using_vnet_hdr(n->nic->nc.peer, 1);
233 234 235 236 237 238 239 240 241 242 243
    } else {
        features &= ~(0x1 << VIRTIO_NET_F_CSUM);
        features &= ~(0x1 << VIRTIO_NET_F_HOST_TSO4);
        features &= ~(0x1 << VIRTIO_NET_F_HOST_TSO6);
        features &= ~(0x1 << VIRTIO_NET_F_HOST_ECN);

        features &= ~(0x1 << VIRTIO_NET_F_GUEST_CSUM);
        features &= ~(0x1 << VIRTIO_NET_F_GUEST_TSO4);
        features &= ~(0x1 << VIRTIO_NET_F_GUEST_TSO6);
        features &= ~(0x1 << VIRTIO_NET_F_GUEST_ECN);
    }
M
Mark McLoughlin 已提交
244

245 246 247
    if (!peer_has_vnet_hdr(n) || !peer_has_ufo(n)) {
        features &= ~(0x1 << VIRTIO_NET_F_GUEST_UFO);
        features &= ~(0x1 << VIRTIO_NET_F_HOST_UFO);
M
Mark McLoughlin 已提交
248 249
    }

250 251 252 253 254 255 256 257
    if (!n->nic->nc.peer ||
        n->nic->nc.peer->info->type != NET_CLIENT_TYPE_TAP) {
        return features;
    }
    if (!tap_get_vhost_net(n->nic->nc.peer)) {
        return features;
    }
    return vhost_net_get_features(tap_get_vhost_net(n->nic->nc.peer), features);
A
aliguori 已提交
258 259
}

260 261 262 263 264 265 266
static uint32_t virtio_net_bad_features(VirtIODevice *vdev)
{
    uint32_t features = 0;

    /* Linux kernel 2.6.25.  It understood MAC (as everyone must),
     * but also these: */
    features |= (1 << VIRTIO_NET_F_MAC);
267 268 269 270
    features |= (1 << VIRTIO_NET_F_CSUM);
    features |= (1 << VIRTIO_NET_F_HOST_TSO4);
    features |= (1 << VIRTIO_NET_F_HOST_TSO6);
    features |= (1 << VIRTIO_NET_F_HOST_ECN);
271

272
    return features;
273 274
}

A
aliguori 已提交
275 276 277 278 279
static void virtio_net_set_features(VirtIODevice *vdev, uint32_t features)
{
    VirtIONet *n = to_virtio_net(vdev);

    n->mergeable_rx_bufs = !!(features & (1 << VIRTIO_NET_F_MRG_RXBUF));
280 281

    if (n->has_vnet_hdr) {
M
Mark McLoughlin 已提交
282
        tap_set_offload(n->nic->nc.peer,
283 284 285
                        (features >> VIRTIO_NET_F_GUEST_CSUM) & 1,
                        (features >> VIRTIO_NET_F_GUEST_TSO4) & 1,
                        (features >> VIRTIO_NET_F_GUEST_TSO6) & 1,
286 287
                        (features >> VIRTIO_NET_F_GUEST_ECN)  & 1,
                        (features >> VIRTIO_NET_F_GUEST_UFO)  & 1);
288
    }
D
David L Stevens 已提交
289 290 291 292 293 294 295
    if (!n->nic->nc.peer ||
        n->nic->nc.peer->info->type != NET_CLIENT_TYPE_TAP) {
        return;
    }
    if (!tap_get_vhost_net(n->nic->nc.peer)) {
        return;
    }
296
    vhost_net_ack_features(tap_get_vhost_net(n->nic->nc.peer), features);
A
aliguori 已提交
297 298
}

299 300 301 302 303 304
static int virtio_net_handle_rx_mode(VirtIONet *n, uint8_t cmd,
                                     VirtQueueElement *elem)
{
    uint8_t on;

    if (elem->out_num != 2 || elem->out_sg[1].iov_len != sizeof(on)) {
305
        error_report("virtio-net ctrl invalid rx mode command");
306 307 308 309 310 311 312 313 314
        exit(1);
    }

    on = ldub_p(elem->out_sg[1].iov_base);

    if (cmd == VIRTIO_NET_CTRL_RX_MODE_PROMISC)
        n->promisc = on;
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_ALLMULTI)
        n->allmulti = on;
315 316 317 318 319 320 321 322
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_ALLUNI)
        n->alluni = on;
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_NOMULTI)
        n->nomulti = on;
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_NOUNI)
        n->nouni = on;
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_NOBCAST)
        n->nobcast = on;
323 324 325 326 327 328
    else
        return VIRTIO_NET_ERR;

    return VIRTIO_NET_OK;
}

329 330 331 332 333 334 335 336 337 338 339
static int virtio_net_handle_mac(VirtIONet *n, uint8_t cmd,
                                 VirtQueueElement *elem)
{
    struct virtio_net_ctrl_mac mac_data;

    if (cmd != VIRTIO_NET_CTRL_MAC_TABLE_SET || elem->out_num != 3 ||
        elem->out_sg[1].iov_len < sizeof(mac_data) ||
        elem->out_sg[2].iov_len < sizeof(mac_data))
        return VIRTIO_NET_ERR;

    n->mac_table.in_use = 0;
340
    n->mac_table.first_multi = 0;
341 342
    n->mac_table.uni_overflow = 0;
    n->mac_table.multi_overflow = 0;
343 344
    memset(n->mac_table.macs, 0, MAC_TABLE_ENTRIES * ETH_ALEN);

345
    mac_data.entries = ldl_p(elem->out_sg[1].iov_base);
346 347 348 349 350 351 352 353 354 355

    if (sizeof(mac_data.entries) +
        (mac_data.entries * ETH_ALEN) > elem->out_sg[1].iov_len)
        return VIRTIO_NET_ERR;

    if (mac_data.entries <= MAC_TABLE_ENTRIES) {
        memcpy(n->mac_table.macs, elem->out_sg[1].iov_base + sizeof(mac_data),
               mac_data.entries * ETH_ALEN);
        n->mac_table.in_use += mac_data.entries;
    } else {
356
        n->mac_table.uni_overflow = 1;
357 358
    }

359 360
    n->mac_table.first_multi = n->mac_table.in_use;

361
    mac_data.entries = ldl_p(elem->out_sg[2].iov_base);
362 363 364 365 366 367 368 369 370 371 372

    if (sizeof(mac_data.entries) +
        (mac_data.entries * ETH_ALEN) > elem->out_sg[2].iov_len)
        return VIRTIO_NET_ERR;

    if (mac_data.entries) {
        if (n->mac_table.in_use + mac_data.entries <= MAC_TABLE_ENTRIES) {
            memcpy(n->mac_table.macs + (n->mac_table.in_use * ETH_ALEN),
                   elem->out_sg[2].iov_base + sizeof(mac_data),
                   mac_data.entries * ETH_ALEN);
            n->mac_table.in_use += mac_data.entries;
373 374 375
        } else {
            n->mac_table.multi_overflow = 1;
        }
376 377 378 379 380
    }

    return VIRTIO_NET_OK;
}

381 382 383 384 385 386
static int virtio_net_handle_vlan_table(VirtIONet *n, uint8_t cmd,
                                        VirtQueueElement *elem)
{
    uint16_t vid;

    if (elem->out_num != 2 || elem->out_sg[1].iov_len != sizeof(vid)) {
387
        error_report("virtio-net ctrl invalid vlan command");
388 389 390
        return VIRTIO_NET_ERR;
    }

391
    vid = lduw_p(elem->out_sg[1].iov_base);
392 393 394 395 396 397 398 399 400 401 402 403 404 405

    if (vid >= MAX_VLAN)
        return VIRTIO_NET_ERR;

    if (cmd == VIRTIO_NET_CTRL_VLAN_ADD)
        n->vlans[vid >> 5] |= (1U << (vid & 0x1f));
    else if (cmd == VIRTIO_NET_CTRL_VLAN_DEL)
        n->vlans[vid >> 5] &= ~(1U << (vid & 0x1f));
    else
        return VIRTIO_NET_ERR;

    return VIRTIO_NET_OK;
}

406 407
static void virtio_net_handle_ctrl(VirtIODevice *vdev, VirtQueue *vq)
{
408
    VirtIONet *n = to_virtio_net(vdev);
409 410 411 412 413 414
    struct virtio_net_ctrl_hdr ctrl;
    virtio_net_ctrl_ack status = VIRTIO_NET_ERR;
    VirtQueueElement elem;

    while (virtqueue_pop(vq, &elem)) {
        if ((elem.in_num < 1) || (elem.out_num < 1)) {
415
            error_report("virtio-net ctrl missing headers");
416 417 418 419
            exit(1);
        }

        if (elem.out_sg[0].iov_len < sizeof(ctrl) ||
420
            elem.in_sg[elem.in_num - 1].iov_len < sizeof(status)) {
421
            error_report("virtio-net ctrl header not in correct element");
422 423 424 425 426 427
            exit(1);
        }

        ctrl.class = ldub_p(elem.out_sg[0].iov_base);
        ctrl.cmd = ldub_p(elem.out_sg[0].iov_base + sizeof(ctrl.class));

428 429
        if (ctrl.class == VIRTIO_NET_CTRL_RX_MODE)
            status = virtio_net_handle_rx_mode(n, ctrl.cmd, &elem);
430 431
        else if (ctrl.class == VIRTIO_NET_CTRL_MAC)
            status = virtio_net_handle_mac(n, ctrl.cmd, &elem);
432 433
        else if (ctrl.class == VIRTIO_NET_CTRL_VLAN)
            status = virtio_net_handle_vlan_table(n, ctrl.cmd, &elem);
434

435 436 437 438 439 440 441
        stb_p(elem.in_sg[elem.in_num - 1].iov_base, status);

        virtqueue_push(vq, &elem, sizeof(status));
        virtio_notify(vdev, vq);
    }
}

A
aliguori 已提交
442 443 444 445
/* RX */

static void virtio_net_handle_rx(VirtIODevice *vdev, VirtQueue *vq)
{
446 447
    VirtIONet *n = to_virtio_net(vdev);

M
Mark McLoughlin 已提交
448
    qemu_flush_queued_packets(&n->nic->nc);
449 450 451 452

    /* We now have RX buffers, signal to the IO thread to break out of the
     * select to re-poll the tap file descriptor */
    qemu_notify_event();
A
aliguori 已提交
453 454
}

M
Mark McLoughlin 已提交
455
static int virtio_net_can_receive(VLANClientState *nc)
A
aliguori 已提交
456
{
M
Mark McLoughlin 已提交
457
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
458
    if (!n->vdev.vm_running) {
459 460
        return 0;
    }
461

A
aliguori 已提交
462 463 464 465
    if (!virtio_queue_ready(n->rx_vq) ||
        !(n->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK))
        return 0;

466 467 468 469 470
    return 1;
}

static int virtio_net_has_buffers(VirtIONet *n, int bufsize)
{
A
aliguori 已提交
471 472 473 474
    if (virtio_queue_empty(n->rx_vq) ||
        (n->mergeable_rx_bufs &&
         !virtqueue_avail_bytes(n->rx_vq, bufsize, 0))) {
        virtio_queue_set_notification(n->rx_vq, 1);
475 476 477 478 479 480 481 482 483

        /* To avoid a race condition where the guest has made some buffers
         * available after the above check but before notification was
         * enabled, check for available buffers again.
         */
        if (virtio_queue_empty(n->rx_vq) ||
            (n->mergeable_rx_bufs &&
             !virtqueue_avail_bytes(n->rx_vq, bufsize, 0)))
            return 0;
A
aliguori 已提交
484 485 486 487 488 489
    }

    virtio_queue_set_notification(n->rx_vq, 0);
    return 1;
}

A
Anthony Liguori 已提交
490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517
/* dhclient uses AF_PACKET but doesn't pass auxdata to the kernel so
 * it never finds out that the packets don't have valid checksums.  This
 * causes dhclient to get upset.  Fedora's carried a patch for ages to
 * fix this with Xen but it hasn't appeared in an upstream release of
 * dhclient yet.
 *
 * To avoid breaking existing guests, we catch udp packets and add
 * checksums.  This is terrible but it's better than hacking the guest
 * kernels.
 *
 * N.B. if we introduce a zero-copy API, this operation is no longer free so
 * we should provide a mechanism to disable it to avoid polluting the host
 * cache.
 */
static void work_around_broken_dhclient(struct virtio_net_hdr *hdr,
                                        const uint8_t *buf, size_t size)
{
    if ((hdr->flags & VIRTIO_NET_HDR_F_NEEDS_CSUM) && /* missing csum */
        (size > 27 && size < 1500) && /* normal sized MTU */
        (buf[12] == 0x08 && buf[13] == 0x00) && /* ethertype == IPv4 */
        (buf[23] == 17) && /* ip.protocol == UDP */
        (buf[34] == 0 && buf[35] == 67)) { /* udp.srcport == bootps */
        /* FIXME this cast is evil */
        net_checksum_calculate((uint8_t *)buf, size);
        hdr->flags &= ~VIRTIO_NET_HDR_F_NEEDS_CSUM;
    }
}

A
aliguori 已提交
518
static int receive_header(VirtIONet *n, struct iovec *iov, int iovcnt,
A
aliguori 已提交
519
                          const void *buf, size_t size, size_t hdr_len)
A
aliguori 已提交
520
{
521
    struct virtio_net_hdr *hdr = (struct virtio_net_hdr *)iov[0].iov_base;
A
aliguori 已提交
522 523 524 525 526
    int offset = 0;

    hdr->flags = 0;
    hdr->gso_type = VIRTIO_NET_HDR_GSO_NONE;

M
Mark McLoughlin 已提交
527 528 529
    if (n->has_vnet_hdr) {
        memcpy(hdr, buf, sizeof(*hdr));
        offset = sizeof(*hdr);
A
Anthony Liguori 已提交
530
        work_around_broken_dhclient(hdr, buf + offset, size - offset);
M
Mark McLoughlin 已提交
531 532
    }

A
aliguori 已提交
533 534 535 536 537 538 539 540 541
    /* We only ever receive a struct virtio_net_hdr from the tapfd,
     * but we may be passing along a larger header to the guest.
     */
    iov[0].iov_base += hdr_len;
    iov[0].iov_len  -= hdr_len;

    return offset;
}

542 543 544
static int receive_filter(VirtIONet *n, const uint8_t *buf, int size)
{
    static const uint8_t bcast[] = {0xff, 0xff, 0xff, 0xff, 0xff, 0xff};
545
    static const uint8_t vlan[] = {0x81, 0x00};
546
    uint8_t *ptr = (uint8_t *)buf;
547
    int i;
548 549 550 551

    if (n->promisc)
        return 1;

M
Mark McLoughlin 已提交
552 553 554 555
    if (n->has_vnet_hdr) {
        ptr += sizeof(struct virtio_net_hdr);
    }

556 557 558 559 560 561
    if (!memcmp(&ptr[12], vlan, sizeof(vlan))) {
        int vid = be16_to_cpup((uint16_t *)(ptr + 14)) & 0xfff;
        if (!(n->vlans[vid >> 5] & (1U << (vid & 0x1f))))
            return 0;
    }

562 563
    if (ptr[0] & 1) { // multicast
        if (!memcmp(ptr, bcast, sizeof(bcast))) {
564 565 566
            return !n->nobcast;
        } else if (n->nomulti) {
            return 0;
567
        } else if (n->allmulti || n->mac_table.multi_overflow) {
568 569
            return 1;
        }
570 571 572 573 574 575

        for (i = n->mac_table.first_multi; i < n->mac_table.in_use; i++) {
            if (!memcmp(ptr, &n->mac_table.macs[i * ETH_ALEN], ETH_ALEN)) {
                return 1;
            }
        }
576
    } else { // unicast
577 578 579
        if (n->nouni) {
            return 0;
        } else if (n->alluni || n->mac_table.uni_overflow) {
580 581
            return 1;
        } else if (!memcmp(ptr, n->mac, ETH_ALEN)) {
582 583
            return 1;
        }
584

585 586 587 588 589
        for (i = 0; i < n->mac_table.first_multi; i++) {
            if (!memcmp(ptr, &n->mac_table.macs[i * ETH_ALEN], ETH_ALEN)) {
                return 1;
            }
        }
590 591
    }

592 593 594
    return 0;
}

M
Mark McLoughlin 已提交
595
static ssize_t virtio_net_receive(VLANClientState *nc, const uint8_t *buf, size_t size)
A
aliguori 已提交
596
{
M
Mark McLoughlin 已提交
597
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
A
aliguori 已提交
598
    struct virtio_net_hdr_mrg_rxbuf *mhdr = NULL;
599
    size_t guest_hdr_len, offset, i, host_hdr_len;
A
aliguori 已提交
600

M
Mark McLoughlin 已提交
601
    if (!virtio_net_can_receive(&n->nic->nc))
602 603
        return -1;

604
    /* hdr_len refers to the header we supply to the guest */
605
    guest_hdr_len = n->mergeable_rx_bufs ?
606 607 608
        sizeof(struct virtio_net_hdr_mrg_rxbuf) : sizeof(struct virtio_net_hdr);


609 610
    host_hdr_len = n->has_vnet_hdr ? sizeof(struct virtio_net_hdr) : 0;
    if (!virtio_net_has_buffers(n, size + guest_hdr_len - host_hdr_len))
611
        return 0;
A
aliguori 已提交
612

613
    if (!receive_filter(n, buf, size))
614
        return size;
615

A
aliguori 已提交
616 617 618 619 620 621 622
    offset = i = 0;

    while (offset < size) {
        VirtQueueElement elem;
        int len, total;
        struct iovec sg[VIRTQUEUE_MAX_SIZE];

A
Amit Shah 已提交
623
        total = 0;
A
aliguori 已提交
624

625
        if (virtqueue_pop(n->rx_vq, &elem) == 0) {
A
aliguori 已提交
626
            if (i == 0)
627
                return -1;
628
            error_report("virtio-net unexpected empty queue: "
629
                    "i %zd mergeable %d offset %zd, size %zd, "
630
                    "guest hdr len %zd, host hdr len %zd guest features 0x%x",
631 632
                    i, n->mergeable_rx_bufs, offset, size,
                    guest_hdr_len, host_hdr_len, n->vdev.guest_features);
A
aliguori 已提交
633 634 635 636
            exit(1);
        }

        if (elem.in_num < 1) {
637
            error_report("virtio-net receive queue contains no in buffers");
A
aliguori 已提交
638 639 640
            exit(1);
        }

641
        if (!n->mergeable_rx_bufs && elem.in_sg[0].iov_len != guest_hdr_len) {
642
            error_report("virtio-net header not in first element");
A
aliguori 已提交
643 644 645 646 647 648 649 650 651 652
            exit(1);
        }

        memcpy(&sg, &elem.in_sg[0], sizeof(sg[0]) * elem.in_num);

        if (i == 0) {
            if (n->mergeable_rx_bufs)
                mhdr = (struct virtio_net_hdr_mrg_rxbuf *)sg[0].iov_base;

            offset += receive_header(n, sg, elem.in_num,
653 654
                                     buf + offset, size - offset, guest_hdr_len);
            total += guest_hdr_len;
A
aliguori 已提交
655 656 657
        }

        /* copy in packet.  ugh */
658 659
        len = iov_from_buf(sg, elem.in_num,
                           buf + offset, size - offset);
A
aliguori 已提交
660
        total += len;
661 662 663 664 665 666
        offset += len;
        /* If buffers can't be merged, at this point we
         * must have consumed the complete packet.
         * Otherwise, drop it. */
        if (!n->mergeable_rx_bufs && offset < size) {
#if 0
667 668 669 670 671
            error_report("virtio-net truncated non-mergeable packet: "
                         "i %zd mergeable %d offset %zd, size %zd, "
                         "guest hdr len %zd, host hdr len %zd",
                         i, n->mergeable_rx_bufs,
                         offset, size, guest_hdr_len, host_hdr_len);
672 673 674
#endif
            return size;
        }
A
aliguori 已提交
675 676 677 678 679

        /* signal other side */
        virtqueue_fill(n->rx_vq, &elem, total, i++);
    }

680 681 682
    if (mhdr) {
        mhdr->num_buffers = lduw_p(&i);
    }
A
aliguori 已提交
683 684 685

    virtqueue_flush(n->rx_vq, i);
    virtio_notify(&n->vdev, n->rx_vq);
686 687

    return size;
A
aliguori 已提交
688 689
}

690
static int32_t virtio_net_flush_tx(VirtIONet *n, VirtQueue *vq);
691

M
Mark McLoughlin 已提交
692
static void virtio_net_tx_complete(VLANClientState *nc, ssize_t len)
693
{
M
Mark McLoughlin 已提交
694
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
695 696 697 698 699 700 701 702 703 704

    virtqueue_push(n->tx_vq, &n->async_tx.elem, n->async_tx.len);
    virtio_notify(&n->vdev, n->tx_vq);

    n->async_tx.elem.out_num = n->async_tx.len = 0;

    virtio_queue_set_notification(n->tx_vq, 1);
    virtio_net_flush_tx(n, n->tx_vq);
}

A
aliguori 已提交
705
/* TX */
706
static int32_t virtio_net_flush_tx(VirtIONet *n, VirtQueue *vq)
A
aliguori 已提交
707 708
{
    VirtQueueElement elem;
709 710 711 712
    int32_t num_packets = 0;
    if (!(n->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK)) {
        return num_packets;
    }
A
aliguori 已提交
713

714
    assert(n->vdev.vm_running);
715

716 717
    if (n->async_tx.elem.out_num) {
        virtio_queue_set_notification(n->tx_vq, 0);
718
        return num_packets;
719 720
    }

A
aliguori 已提交
721
    while (virtqueue_pop(vq, &elem)) {
722
        ssize_t ret, len = 0;
A
aliguori 已提交
723 724 725 726 727 728 729 730 731 732
        unsigned int out_num = elem.out_num;
        struct iovec *out_sg = &elem.out_sg[0];
        unsigned hdr_len;

        /* hdr_len refers to the header received from the guest */
        hdr_len = n->mergeable_rx_bufs ?
            sizeof(struct virtio_net_hdr_mrg_rxbuf) :
            sizeof(struct virtio_net_hdr);

        if (out_num < 1 || out_sg->iov_len != hdr_len) {
733
            error_report("virtio-net header not in first element");
A
aliguori 已提交
734 735 736 737
            exit(1);
        }

        /* ignore the header if GSO is not supported */
M
Mark McLoughlin 已提交
738
        if (!n->has_vnet_hdr) {
A
aliguori 已提交
739 740 741 742 743 744 745 746 747 748
            out_num--;
            out_sg++;
            len += hdr_len;
        } else if (n->mergeable_rx_bufs) {
            /* tapfd expects a struct virtio_net_hdr */
            hdr_len -= sizeof(struct virtio_net_hdr);
            out_sg->iov_len -= hdr_len;
            len += hdr_len;
        }

M
Mark McLoughlin 已提交
749
        ret = qemu_sendv_packet_async(&n->nic->nc, out_sg, out_num,
750 751 752 753 754
                                      virtio_net_tx_complete);
        if (ret == 0) {
            virtio_queue_set_notification(n->tx_vq, 0);
            n->async_tx.elem = elem;
            n->async_tx.len  = len;
755
            return -EBUSY;
756 757 758
        }

        len += ret;
A
aliguori 已提交
759 760 761

        virtqueue_push(vq, &elem, len);
        virtio_notify(&n->vdev, vq);
762 763 764 765

        if (++num_packets >= n->tx_burst) {
            break;
        }
A
aliguori 已提交
766
    }
767
    return num_packets;
A
aliguori 已提交
768 769
}

770
static void virtio_net_handle_tx_timer(VirtIODevice *vdev, VirtQueue *vq)
A
aliguori 已提交
771 772 773
{
    VirtIONet *n = to_virtio_net(vdev);

774
    /* This happens when device was stopped but VCPU wasn't. */
775
    if (!n->vdev.vm_running) {
776 777 778 779
        n->tx_waiting = 1;
        return;
    }

780
    if (n->tx_waiting) {
A
aliguori 已提交
781 782
        virtio_queue_set_notification(vq, 1);
        qemu_del_timer(n->tx_timer);
783
        n->tx_waiting = 0;
A
aliguori 已提交
784 785 786
        virtio_net_flush_tx(n, vq);
    } else {
        qemu_mod_timer(n->tx_timer,
787
                       qemu_get_clock(vm_clock) + n->tx_timeout);
788
        n->tx_waiting = 1;
A
aliguori 已提交
789 790 791 792
        virtio_queue_set_notification(vq, 0);
    }
}

793 794 795 796 797 798 799
static void virtio_net_handle_tx_bh(VirtIODevice *vdev, VirtQueue *vq)
{
    VirtIONet *n = to_virtio_net(vdev);

    if (unlikely(n->tx_waiting)) {
        return;
    }
800 801
    n->tx_waiting = 1;
    /* This happens when device was stopped but VCPU wasn't. */
802
    if (!n->vdev.vm_running) {
803 804
        return;
    }
805 806 807 808
    virtio_queue_set_notification(vq, 0);
    qemu_bh_schedule(n->tx_bh);
}

A
aliguori 已提交
809 810 811
static void virtio_net_tx_timer(void *opaque)
{
    VirtIONet *n = opaque;
812
    assert(n->vdev.vm_running);
A
aliguori 已提交
813

814
    n->tx_waiting = 0;
A
aliguori 已提交
815 816 817 818 819 820 821 822 823

    /* Just in case the driver is not ready on more */
    if (!(n->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK))
        return;

    virtio_queue_set_notification(n->tx_vq, 1);
    virtio_net_flush_tx(n, n->tx_vq);
}

824 825 826 827 828
static void virtio_net_tx_bh(void *opaque)
{
    VirtIONet *n = opaque;
    int32_t ret;

829
    assert(n->vdev.vm_running);
830

831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860
    n->tx_waiting = 0;

    /* Just in case the driver is not ready on more */
    if (unlikely(!(n->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK)))
        return;

    ret = virtio_net_flush_tx(n, n->tx_vq);
    if (ret == -EBUSY) {
        return; /* Notification re-enable handled by tx_complete */
    }

    /* If we flush a full burst of packets, assume there are
     * more coming and immediately reschedule */
    if (ret >= n->tx_burst) {
        qemu_bh_schedule(n->tx_bh);
        n->tx_waiting = 1;
        return;
    }

    /* If less than a full burst, re-enable notification and flush
     * anything that may have come in while we weren't looking.  If
     * we find something, assume the guest is still active and reschedule */
    virtio_queue_set_notification(n->tx_vq, 1);
    if (virtio_net_flush_tx(n, n->tx_vq) > 0) {
        virtio_queue_set_notification(n->tx_vq, 0);
        qemu_bh_schedule(n->tx_bh);
        n->tx_waiting = 1;
    }
}

A
aliguori 已提交
861 862 863 864
static void virtio_net_save(QEMUFile *f, void *opaque)
{
    VirtIONet *n = opaque;

865 866 867
    /* At this point, backend must be stopped, otherwise
     * it might keep writing to memory. */
    assert(!n->vhost_started);
A
aliguori 已提交
868 869
    virtio_save(&n->vdev, f);

870
    qemu_put_buffer(f, n->mac, ETH_ALEN);
871
    qemu_put_be32(f, n->tx_waiting);
872
    qemu_put_be32(f, n->mergeable_rx_bufs);
873
    qemu_put_be16(f, n->status);
874 875
    qemu_put_byte(f, n->promisc);
    qemu_put_byte(f, n->allmulti);
876 877
    qemu_put_be32(f, n->mac_table.in_use);
    qemu_put_buffer(f, n->mac_table.macs, n->mac_table.in_use * ETH_ALEN);
878
    qemu_put_buffer(f, (uint8_t *)n->vlans, MAX_VLAN >> 3);
M
Mark McLoughlin 已提交
879
    qemu_put_be32(f, n->has_vnet_hdr);
880 881
    qemu_put_byte(f, n->mac_table.multi_overflow);
    qemu_put_byte(f, n->mac_table.uni_overflow);
882 883 884 885
    qemu_put_byte(f, n->alluni);
    qemu_put_byte(f, n->nomulti);
    qemu_put_byte(f, n->nouni);
    qemu_put_byte(f, n->nobcast);
886
    qemu_put_byte(f, n->has_ufo);
A
aliguori 已提交
887 888 889 890 891
}

static int virtio_net_load(QEMUFile *f, void *opaque, int version_id)
{
    VirtIONet *n = opaque;
892
    int i;
A
aliguori 已提交
893

894
    if (version_id < 2 || version_id > VIRTIO_NET_VM_VERSION)
A
aliguori 已提交
895 896 897 898
        return -EINVAL;

    virtio_load(&n->vdev, f);

899
    qemu_get_buffer(f, n->mac, ETH_ALEN);
900
    n->tx_waiting = qemu_get_be32(f);
901
    n->mergeable_rx_bufs = qemu_get_be32(f);
A
aliguori 已提交
902

903 904 905
    if (version_id >= 3)
        n->status = qemu_get_be16(f);

906
    if (version_id >= 4) {
907 908 909 910 911 912 913
        if (version_id < 8) {
            n->promisc = qemu_get_be32(f);
            n->allmulti = qemu_get_be32(f);
        } else {
            n->promisc = qemu_get_byte(f);
            n->allmulti = qemu_get_byte(f);
        }
914 915
    }

916 917 918 919 920 921 922 923
    if (version_id >= 5) {
        n->mac_table.in_use = qemu_get_be32(f);
        /* MAC_TABLE_ENTRIES may be different from the saved image */
        if (n->mac_table.in_use <= MAC_TABLE_ENTRIES) {
            qemu_get_buffer(f, n->mac_table.macs,
                            n->mac_table.in_use * ETH_ALEN);
        } else if (n->mac_table.in_use) {
            qemu_fseek(f, n->mac_table.in_use * ETH_ALEN, SEEK_CUR);
924
            n->mac_table.multi_overflow = n->mac_table.uni_overflow = 1;
925 926 927 928
            n->mac_table.in_use = 0;
        }
    }
 
929 930 931
    if (version_id >= 6)
        qemu_get_buffer(f, (uint8_t *)n->vlans, MAX_VLAN >> 3);

M
Mark McLoughlin 已提交
932 933
    if (version_id >= 7) {
        if (qemu_get_be32(f) && !peer_has_vnet_hdr(n)) {
934
            error_report("virtio-net: saved image requires vnet_hdr=on");
M
Mark McLoughlin 已提交
935 936 937 938
            return -1;
        }

        if (n->has_vnet_hdr) {
M
Mark McLoughlin 已提交
939 940
            tap_using_vnet_hdr(n->nic->nc.peer, 1);
            tap_set_offload(n->nic->nc.peer,
941 942 943 944 945
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_CSUM) & 1,
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_TSO4) & 1,
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_TSO6) & 1,
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_ECN)  & 1,
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_UFO)  & 1);
M
Mark McLoughlin 已提交
946
        }
947 948
    }

949 950 951 952 953
    if (version_id >= 9) {
        n->mac_table.multi_overflow = qemu_get_byte(f);
        n->mac_table.uni_overflow = qemu_get_byte(f);
    }

954 955 956 957 958 959 960
    if (version_id >= 10) {
        n->alluni = qemu_get_byte(f);
        n->nomulti = qemu_get_byte(f);
        n->nouni = qemu_get_byte(f);
        n->nobcast = qemu_get_byte(f);
    }

961 962
    if (version_id >= 11) {
        if (qemu_get_byte(f) && !peer_has_ufo(n)) {
963
            error_report("virtio-net: saved image requires TUN_F_UFO support");
964 965 966 967
            return -1;
        }
    }

968 969 970 971 972 973 974
    /* Find the first multicast entry in the saved MAC filter */
    for (i = 0; i < n->mac_table.in_use; i++) {
        if (n->mac_table.macs[i * ETH_ALEN] & 1) {
            break;
        }
    }
    n->mac_table.first_multi = i;
A
aliguori 已提交
975 976 977
    return 0;
}

M
Mark McLoughlin 已提交
978
static void virtio_net_cleanup(VLANClientState *nc)
979
{
M
Mark McLoughlin 已提交
980
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
981

M
Mark McLoughlin 已提交
982
    n->nic = NULL;
983 984
}

M
Mark McLoughlin 已提交
985 986 987 988 989 990 991 992 993
static NetClientInfo net_virtio_info = {
    .type = NET_CLIENT_TYPE_NIC,
    .size = sizeof(NICState),
    .can_receive = virtio_net_can_receive,
    .receive = virtio_net_receive,
        .cleanup = virtio_net_cleanup,
    .link_status_changed = virtio_net_set_link_status,
};

994 995
VirtIODevice *virtio_net_init(DeviceState *dev, NICConf *conf,
                              virtio_net_conf *net)
A
aliguori 已提交
996 997 998
{
    VirtIONet *n;

P
Paul Brook 已提交
999 1000 1001
    n = (VirtIONet *)virtio_common_init("virtio-net", VIRTIO_ID_NET,
                                        sizeof(struct virtio_net_config),
                                        sizeof(VirtIONet));
A
aliguori 已提交
1002

1003 1004
    n->vdev.get_config = virtio_net_get_config;
    n->vdev.set_config = virtio_net_set_config;
A
aliguori 已提交
1005 1006
    n->vdev.get_features = virtio_net_get_features;
    n->vdev.set_features = virtio_net_set_features;
1007
    n->vdev.bad_features = virtio_net_bad_features;
1008
    n->vdev.reset = virtio_net_reset;
1009
    n->vdev.set_status = virtio_net_set_status;
A
aliguori 已提交
1010
    n->rx_vq = virtio_add_queue(&n->vdev, 256, virtio_net_handle_rx);
1011 1012

    if (net->tx && strcmp(net->tx, "timer") && strcmp(net->tx, "bh")) {
1013 1014 1015 1016
        error_report("virtio-net: "
                     "Unknown option tx=%s, valid options: \"timer\" \"bh\"",
                     net->tx);
        error_report("Defaulting to \"bh\"");
1017 1018 1019 1020 1021 1022 1023 1024 1025 1026
    }

    if (net->tx && !strcmp(net->tx, "timer")) {
        n->tx_vq = virtio_add_queue(&n->vdev, 256, virtio_net_handle_tx_timer);
        n->tx_timer = qemu_new_timer(vm_clock, virtio_net_tx_timer, n);
        n->tx_timeout = net->txtimer;
    } else {
        n->tx_vq = virtio_add_queue(&n->vdev, 256, virtio_net_handle_tx_bh);
        n->tx_bh = qemu_bh_new(virtio_net_tx_bh, n);
    }
1027
    n->ctrl_vq = virtio_add_queue(&n->vdev, 64, virtio_net_handle_ctrl);
1028
    qemu_macaddr_default_if_unset(&conf->macaddr);
1029
    memcpy(&n->mac[0], &conf->macaddr, sizeof(n->mac));
1030
    n->status = VIRTIO_NET_S_LINK_UP;
A
aliguori 已提交
1031

M
Mark McLoughlin 已提交
1032 1033 1034
    n->nic = qemu_new_nic(&net_virtio_info, conf, dev->info->name, dev->id, n);

    qemu_format_nic_info_str(&n->nic->nc, conf->macaddr.a);
1035

1036
    n->tx_waiting = 0;
1037
    n->tx_burst = net->txburst;
A
aliguori 已提交
1038
    n->mergeable_rx_bufs = 0;
1039
    n->promisc = 1; /* for compatibility */
A
aliguori 已提交
1040

1041 1042
    n->mac_table.macs = qemu_mallocz(MAC_TABLE_ENTRIES * ETH_ALEN);

1043 1044
    n->vlans = qemu_mallocz(MAX_VLAN >> 3);

1045 1046
    n->qdev = dev;
    register_savevm(dev, "virtio-net", -1, VIRTIO_NET_VM_VERSION,
A
aliguori 已提交
1047
                    virtio_net_save, virtio_net_load, n);
P
Paul Brook 已提交
1048

1049 1050
    add_boot_device_path(conf->bootindex, dev, "/ethernet-phy@0");

P
Paul Brook 已提交
1051
    return &n->vdev;
P
Paul Brook 已提交
1052
}
1053 1054 1055 1056

void virtio_net_exit(VirtIODevice *vdev)
{
    VirtIONet *n = DO_UPCAST(VirtIONet, vdev, vdev);
1057

1058 1059
    /* This will stop vhost backend if appropriate. */
    virtio_net_set_status(vdev, 0);
1060

M
Mark McLoughlin 已提交
1061
    qemu_purge_queued_packets(&n->nic->nc);
1062

1063
    unregister_savevm(n->qdev, "virtio-net", n);
1064 1065 1066 1067

    qemu_free(n->mac_table.macs);
    qemu_free(n->vlans);

1068 1069 1070 1071 1072 1073
    if (n->tx_timer) {
        qemu_del_timer(n->tx_timer);
        qemu_free_timer(n->tx_timer);
    } else {
        qemu_bh_delete(n->tx_bh);
    }
1074 1075

    virtio_cleanup(&n->vdev);
M
Mark McLoughlin 已提交
1076
    qemu_del_vlan_client(&n->nic->nc);
1077
}