qxl.c 77.1 KB
Newer Older
G
Gerd Hoffmann 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
/*
 * Copyright (C) 2010 Red Hat, Inc.
 *
 * written by Yaniv Kamay, Izik Eidus, Gerd Hoffmann
 * maintained by Gerd Hoffmann <kraxel@redhat.com>
 *
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License as
 * published by the Free Software Foundation; either version 2 or
 * (at your option) version 3 of the License.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, see <http://www.gnu.org/licenses/>.
 */

21
#include <zlib.h>
22
#include <stdint.h>
23

G
Gerd Hoffmann 已提交
24
#include "qemu-common.h"
25 26
#include "qemu/timer.h"
#include "qemu/queue.h"
27
#include "qemu/atomic.h"
28
#include "sysemu/sysemu.h"
A
Alon Levy 已提交
29
#include "trace.h"
G
Gerd Hoffmann 已提交
30

31
#include "qxl.h"
G
Gerd Hoffmann 已提交
32

33 34 35
/*
 * NOTE: SPICE_RING_PROD_ITEM accesses memory on the pci bar and as
 * such can be changed by the guest, so to avoid a guest trigerrable
36
 * abort we just qxl_set_guest_bug and set the return to NULL. Still
37 38
 * it may happen as a result of emulator bug as well.
 */
G
Gerd Hoffmann 已提交
39
#undef SPICE_RING_PROD_ITEM
40
#define SPICE_RING_PROD_ITEM(qxl, r, ret) {                             \
G
Gerd Hoffmann 已提交
41
        uint32_t prod = (r)->prod & SPICE_RING_INDEX_MASK(r);           \
42
        if (prod >= ARRAY_SIZE((r)->items)) {                           \
43
            qxl_set_guest_bug(qxl, "SPICE_RING_PROD_ITEM indices mismatch " \
44
                          "%u >= %zu", prod, ARRAY_SIZE((r)->items));   \
45 46
            ret = NULL;                                                 \
        } else {                                                        \
47
            ret = &(r)->items[prod].el;                                 \
G
Gerd Hoffmann 已提交
48 49 50 51
        }                                                               \
    }

#undef SPICE_RING_CONS_ITEM
52
#define SPICE_RING_CONS_ITEM(qxl, r, ret) {                             \
G
Gerd Hoffmann 已提交
53
        uint32_t cons = (r)->cons & SPICE_RING_INDEX_MASK(r);           \
54
        if (cons >= ARRAY_SIZE((r)->items)) {                           \
55
            qxl_set_guest_bug(qxl, "SPICE_RING_CONS_ITEM indices mismatch " \
56
                          "%u >= %zu", cons, ARRAY_SIZE((r)->items));   \
57 58
            ret = NULL;                                                 \
        } else {                                                        \
59
            ret = &(r)->items[cons].el;                                 \
G
Gerd Hoffmann 已提交
60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83
        }                                                               \
    }

#undef ALIGN
#define ALIGN(a, b) (((a) + ((b) - 1)) & ~((b) - 1))

#define PIXEL_SIZE 0.2936875 //1280x1024 is 14.8" x 11.9" 

#define QXL_MODE(_x, _y, _b, _o)                  \
    {   .x_res = _x,                              \
        .y_res = _y,                              \
        .bits  = _b,                              \
        .stride = (_x) * (_b) / 8,                \
        .x_mili = PIXEL_SIZE * (_x),              \
        .y_mili = PIXEL_SIZE * (_y),              \
        .orientation = _o,                        \
    }

#define QXL_MODE_16_32(x_res, y_res, orientation) \
    QXL_MODE(x_res, y_res, 16, orientation),      \
    QXL_MODE(x_res, y_res, 32, orientation)

#define QXL_MODE_EX(x_res, y_res)                 \
    QXL_MODE_16_32(x_res, y_res, 0),              \
A
Alon Levy 已提交
84
    QXL_MODE_16_32(x_res, y_res, 1)
G
Gerd Hoffmann 已提交
85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112

static QXLMode qxl_modes[] = {
    QXL_MODE_EX(640, 480),
    QXL_MODE_EX(800, 480),
    QXL_MODE_EX(800, 600),
    QXL_MODE_EX(832, 624),
    QXL_MODE_EX(960, 640),
    QXL_MODE_EX(1024, 600),
    QXL_MODE_EX(1024, 768),
    QXL_MODE_EX(1152, 864),
    QXL_MODE_EX(1152, 870),
    QXL_MODE_EX(1280, 720),
    QXL_MODE_EX(1280, 760),
    QXL_MODE_EX(1280, 768),
    QXL_MODE_EX(1280, 800),
    QXL_MODE_EX(1280, 960),
    QXL_MODE_EX(1280, 1024),
    QXL_MODE_EX(1360, 768),
    QXL_MODE_EX(1366, 768),
    QXL_MODE_EX(1400, 1050),
    QXL_MODE_EX(1440, 900),
    QXL_MODE_EX(1600, 900),
    QXL_MODE_EX(1600, 1200),
    QXL_MODE_EX(1680, 1050),
    QXL_MODE_EX(1920, 1080),
    /* these modes need more than 8 MB video memory */
    QXL_MODE_EX(1920, 1200),
    QXL_MODE_EX(1920, 1440),
113
    QXL_MODE_EX(2000, 2000),
G
Gerd Hoffmann 已提交
114
    QXL_MODE_EX(2048, 1536),
115
    QXL_MODE_EX(2048, 2048),
G
Gerd Hoffmann 已提交
116 117 118 119 120 121
    QXL_MODE_EX(2560, 1440),
    QXL_MODE_EX(2560, 1600),
    /* these modes need more than 16 MB video memory */
    QXL_MODE_EX(2560, 2048),
    QXL_MODE_EX(2800, 2100),
    QXL_MODE_EX(3200, 2400),
122
    /* these modes need more than 32 MB video memory */
G
Gerd Hoffmann 已提交
123 124
    QXL_MODE_EX(3840, 2160), /* 4k mainstream */
    QXL_MODE_EX(4096, 2160), /* 4k            */
125
    /* these modes need more than 64 MB video memory */
G
Gerd Hoffmann 已提交
126
    QXL_MODE_EX(7680, 4320), /* 8k mainstream */
127
    /* these modes need more than 128 MB video memory */
G
Gerd Hoffmann 已提交
128
    QXL_MODE_EX(8192, 4320), /* 8k            */
G
Gerd Hoffmann 已提交
129 130 131
};

static void qxl_send_events(PCIQXLDevice *d, uint32_t events);
132
static int qxl_destroy_primary(PCIQXLDevice *d, qxl_async_io async);
G
Gerd Hoffmann 已提交
133 134 135 136
static void qxl_reset_memslots(PCIQXLDevice *d);
static void qxl_reset_surfaces(PCIQXLDevice *d);
static void qxl_ring_set_dirty(PCIQXLDevice *qxl);

137 138
static void qxl_hw_update(void *opaque);

139
void qxl_set_guest_bug(PCIQXLDevice *qxl, const char *msg, ...)
140
{
A
Alon Levy 已提交
141
    trace_qxl_set_guest_bug(qxl->id);
142
    qxl_send_events(qxl, QXL_INTERRUPT_ERROR);
143
    qxl->guest_bug = 1;
144
    if (qxl->guestdebug) {
145 146 147 148 149 150
        va_list ap;
        va_start(ap, msg);
        fprintf(stderr, "qxl-%d: guest bug: ", qxl->id);
        vfprintf(stderr, msg, ap);
        fprintf(stderr, "\n");
        va_end(ap);
151 152 153
    }
}

154 155 156 157
static void qxl_clear_guest_bug(PCIQXLDevice *qxl)
{
    qxl->guest_bug = 0;
}
G
Gerd Hoffmann 已提交
158 159 160 161

void qxl_spice_update_area(PCIQXLDevice *qxl, uint32_t surface_id,
                           struct QXLRect *area, struct QXLRect *dirty_rects,
                           uint32_t num_dirty_rects,
162
                           uint32_t clear_dirty_region,
A
Alon Levy 已提交
163
                           qxl_async_io async, struct QXLCookie *cookie)
G
Gerd Hoffmann 已提交
164
{
A
Alon Levy 已提交
165 166 167 168
    trace_qxl_spice_update_area(qxl->id, surface_id, area->left, area->right,
                                area->top, area->bottom);
    trace_qxl_spice_update_area_rest(qxl->id, num_dirty_rects,
                                     clear_dirty_region);
169
    if (async == QXL_SYNC) {
170
        spice_qxl_update_area(&qxl->ssd.qxl, surface_id, area,
171 172
                        dirty_rects, num_dirty_rects, clear_dirty_region);
    } else {
A
Alon Levy 已提交
173
        assert(cookie != NULL);
174
        spice_qxl_update_area_async(&qxl->ssd.qxl, surface_id, area,
175
                                    clear_dirty_region, (uintptr_t)cookie);
176
    }
G
Gerd Hoffmann 已提交
177 178
}

179 180
static void qxl_spice_destroy_surface_wait_complete(PCIQXLDevice *qxl,
                                                    uint32_t id)
G
Gerd Hoffmann 已提交
181
{
A
Alon Levy 已提交
182
    trace_qxl_spice_destroy_surface_wait_complete(qxl->id, id);
183 184 185 186
    qemu_mutex_lock(&qxl->track_lock);
    qxl->guest_surfaces.cmds[id] = 0;
    qxl->guest_surfaces.count--;
    qemu_mutex_unlock(&qxl->track_lock);
G
Gerd Hoffmann 已提交
187 188
}

189 190 191
static void qxl_spice_destroy_surface_wait(PCIQXLDevice *qxl, uint32_t id,
                                           qxl_async_io async)
{
A
Alon Levy 已提交
192 193
    QXLCookie *cookie;

A
Alon Levy 已提交
194
    trace_qxl_spice_destroy_surface_wait(qxl->id, id, async);
195
    if (async) {
A
Alon Levy 已提交
196 197 198
        cookie = qxl_cookie_new(QXL_COOKIE_TYPE_IO,
                                QXL_IO_DESTROY_SURFACE_ASYNC);
        cookie->u.surface_id = id;
199
        spice_qxl_destroy_surface_async(&qxl->ssd.qxl, id, (uintptr_t)cookie);
200
    } else {
201
        spice_qxl_destroy_surface_wait(&qxl->ssd.qxl, id);
202
        qxl_spice_destroy_surface_wait_complete(qxl, id);
203 204 205
    }
}

206 207
static void qxl_spice_flush_surfaces_async(PCIQXLDevice *qxl)
{
A
Alon Levy 已提交
208 209
    trace_qxl_spice_flush_surfaces_async(qxl->id, qxl->guest_surfaces.count,
                                         qxl->num_free_res);
A
Alon Levy 已提交
210
    spice_qxl_flush_surfaces_async(&qxl->ssd.qxl,
211 212
        (uintptr_t)qxl_cookie_new(QXL_COOKIE_TYPE_IO,
                                  QXL_IO_FLUSH_SURFACES_ASYNC));
213 214
}

G
Gerd Hoffmann 已提交
215 216 217
void qxl_spice_loadvm_commands(PCIQXLDevice *qxl, struct QXLCommandExt *ext,
                               uint32_t count)
{
A
Alon Levy 已提交
218
    trace_qxl_spice_loadvm_commands(qxl->id, ext, count);
219
    spice_qxl_loadvm_commands(&qxl->ssd.qxl, ext, count);
G
Gerd Hoffmann 已提交
220 221 222 223
}

void qxl_spice_oom(PCIQXLDevice *qxl)
{
A
Alon Levy 已提交
224
    trace_qxl_spice_oom(qxl->id);
225
    spice_qxl_oom(&qxl->ssd.qxl);
G
Gerd Hoffmann 已提交
226 227 228 229
}

void qxl_spice_reset_memslots(PCIQXLDevice *qxl)
{
A
Alon Levy 已提交
230
    trace_qxl_spice_reset_memslots(qxl->id);
231
    spice_qxl_reset_memslots(&qxl->ssd.qxl);
G
Gerd Hoffmann 已提交
232 233
}

234
static void qxl_spice_destroy_surfaces_complete(PCIQXLDevice *qxl)
G
Gerd Hoffmann 已提交
235
{
A
Alon Levy 已提交
236
    trace_qxl_spice_destroy_surfaces_complete(qxl->id);
237
    qemu_mutex_lock(&qxl->track_lock);
238
    memset(qxl->guest_surfaces.cmds, 0,
239
           sizeof(qxl->guest_surfaces.cmds[0]) * qxl->ssd.num_surfaces);
240 241
    qxl->guest_surfaces.count = 0;
    qemu_mutex_unlock(&qxl->track_lock);
G
Gerd Hoffmann 已提交
242 243
}

244 245
static void qxl_spice_destroy_surfaces(PCIQXLDevice *qxl, qxl_async_io async)
{
A
Alon Levy 已提交
246
    trace_qxl_spice_destroy_surfaces(qxl->id, async);
247
    if (async) {
A
Alon Levy 已提交
248
        spice_qxl_destroy_surfaces_async(&qxl->ssd.qxl,
249 250
                (uintptr_t)qxl_cookie_new(QXL_COOKIE_TYPE_IO,
                                          QXL_IO_DESTROY_ALL_SURFACES_ASYNC));
251
    } else {
252
        spice_qxl_destroy_surfaces(&qxl->ssd.qxl);
253 254 255 256
        qxl_spice_destroy_surfaces_complete(qxl);
    }
}

257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273
static void qxl_spice_monitors_config_async(PCIQXLDevice *qxl, int replay)
{
    trace_qxl_spice_monitors_config(qxl->id);
    if (replay) {
        /*
         * don't use QXL_COOKIE_TYPE_IO:
         *  - we are not running yet (post_load), we will assert
         *    in send_events
         *  - this is not a guest io, but a reply, so async_io isn't set.
         */
        spice_qxl_monitors_config_async(&qxl->ssd.qxl,
                qxl->guest_monitors_config,
                MEMSLOT_GROUP_GUEST,
                (uintptr_t)qxl_cookie_new(
                    QXL_COOKIE_TYPE_POST_LOAD_MONITORS_CONFIG,
                    0));
    } else {
274 275
#if SPICE_SERVER_VERSION >= 0x000c06 /* release 0.12.6 */
        if (qxl->max_outputs) {
276
            spice_qxl_set_max_monitors(&qxl->ssd.qxl, qxl->max_outputs);
277 278
        }
#endif
279 280 281 282 283 284 285 286 287
        qxl->guest_monitors_config = qxl->ram->monitors_config;
        spice_qxl_monitors_config_async(&qxl->ssd.qxl,
                qxl->ram->monitors_config,
                MEMSLOT_GROUP_GUEST,
                (uintptr_t)qxl_cookie_new(QXL_COOKIE_TYPE_IO,
                                          QXL_IO_MONITORS_CONFIG_ASYNC));
    }
}

G
Gerd Hoffmann 已提交
288 289
void qxl_spice_reset_image_cache(PCIQXLDevice *qxl)
{
A
Alon Levy 已提交
290
    trace_qxl_spice_reset_image_cache(qxl->id);
291
    spice_qxl_reset_image_cache(&qxl->ssd.qxl);
G
Gerd Hoffmann 已提交
292 293 294 295
}

void qxl_spice_reset_cursor(PCIQXLDevice *qxl)
{
A
Alon Levy 已提交
296
    trace_qxl_spice_reset_cursor(qxl->id);
297
    spice_qxl_reset_cursor(&qxl->ssd.qxl);
Y
Yonit Halperin 已提交
298 299 300
    qemu_mutex_lock(&qxl->track_lock);
    qxl->guest_cursor = 0;
    qemu_mutex_unlock(&qxl->track_lock);
G
Gerd Hoffmann 已提交
301 302 303 304
    if (qxl->ssd.cursor) {
        cursor_put(qxl->ssd.cursor);
    }
    qxl->ssd.cursor = cursor_builtin_hidden();
G
Gerd Hoffmann 已提交
305 306
}

G
Gerd Hoffmann 已提交
307 308
static ram_addr_t qxl_rom_size(void)
{
A
Alon Levy 已提交
309 310 311
    uint32_t required_rom_size = sizeof(QXLRom) + sizeof(QXLModes) +
                                 sizeof(qxl_modes);
    uint32_t rom_size = 8192; /* two pages */
312

G
Gerd Hoffmann 已提交
313
    QEMU_BUILD_BUG_ON(required_rom_size > rom_size);
G
Gerd Hoffmann 已提交
314 315 316 317 318
    return rom_size;
}

static void init_qxl_rom(PCIQXLDevice *d)
{
319
    QXLRom *rom = memory_region_get_ram_ptr(&d->rom_bar);
G
Gerd Hoffmann 已提交
320 321 322 323
    QXLModes *modes = (QXLModes *)(rom + 1);
    uint32_t ram_header_size;
    uint32_t surface0_area_size;
    uint32_t num_pages;
324 325
    uint32_t fb;
    int i, n;
G
Gerd Hoffmann 已提交
326 327 328 329 330 331 332 333 334 335 336 337

    memset(rom, 0, d->rom_size);

    rom->magic         = cpu_to_le32(QXL_ROM_MAGIC);
    rom->id            = cpu_to_le32(d->id);
    rom->log_level     = cpu_to_le32(d->guestdebug);
    rom->modes_offset  = cpu_to_le32(sizeof(QXLRom));

    rom->slot_gen_bits = MEMSLOT_GENERATION_BITS;
    rom->slot_id_bits  = MEMSLOT_SLOT_BITS;
    rom->slots_start   = 1;
    rom->slots_end     = NUM_MEMSLOTS - 1;
338
    rom->n_surfaces    = cpu_to_le32(d->ssd.num_surfaces);
G
Gerd Hoffmann 已提交
339

340
    for (i = 0, n = 0; i < ARRAY_SIZE(qxl_modes); i++) {
G
Gerd Hoffmann 已提交
341
        fb = qxl_modes[i].y_res * qxl_modes[i].stride;
342 343
        if (fb > d->vgamem_size) {
            continue;
G
Gerd Hoffmann 已提交
344
        }
345 346 347 348 349 350 351 352 353 354 355
        modes->modes[n].id          = cpu_to_le32(i);
        modes->modes[n].x_res       = cpu_to_le32(qxl_modes[i].x_res);
        modes->modes[n].y_res       = cpu_to_le32(qxl_modes[i].y_res);
        modes->modes[n].bits        = cpu_to_le32(qxl_modes[i].bits);
        modes->modes[n].stride      = cpu_to_le32(qxl_modes[i].stride);
        modes->modes[n].x_mili      = cpu_to_le32(qxl_modes[i].x_mili);
        modes->modes[n].y_mili      = cpu_to_le32(qxl_modes[i].y_mili);
        modes->modes[n].orientation = cpu_to_le32(qxl_modes[i].orientation);
        n++;
    }
    modes->n_modes     = cpu_to_le32(n);
G
Gerd Hoffmann 已提交
356 357

    ram_header_size    = ALIGN(sizeof(QXLRam), 4096);
358
    surface0_area_size = ALIGN(d->vgamem_size, 4096);
G
Gerd Hoffmann 已提交
359 360 361
    num_pages          = d->vga.vram_size;
    num_pages         -= ram_header_size;
    num_pages         -= surface0_area_size;
362
    num_pages          = num_pages / QXL_PAGE_SIZE;
G
Gerd Hoffmann 已提交
363

364 365
    assert(ram_header_size + surface0_area_size <= d->vga.vram_size);

G
Gerd Hoffmann 已提交
366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386
    rom->draw_area_offset   = cpu_to_le32(0);
    rom->surface0_area_size = cpu_to_le32(surface0_area_size);
    rom->pages_offset       = cpu_to_le32(surface0_area_size);
    rom->num_pages          = cpu_to_le32(num_pages);
    rom->ram_header_offset  = cpu_to_le32(d->vga.vram_size - ram_header_size);

    d->shadow_rom = *rom;
    d->rom        = rom;
    d->modes      = modes;
}

static void init_qxl_ram(PCIQXLDevice *d)
{
    uint8_t *buf;
    uint64_t *item;

    buf = d->vga.vram_ptr;
    d->ram = (QXLRam *)(buf + le32_to_cpu(d->shadow_rom.ram_header_offset));
    d->ram->magic       = cpu_to_le32(QXL_RAM_MAGIC);
    d->ram->int_pending = cpu_to_le32(0);
    d->ram->int_mask    = cpu_to_le32(0);
A
Alon Levy 已提交
387
    d->ram->update_surface = 0;
A
Anthony PERARD 已提交
388
    d->ram->monitors_config = 0;
G
Gerd Hoffmann 已提交
389 390 391
    SPICE_RING_INIT(&d->ram->cmd_ring);
    SPICE_RING_INIT(&d->ram->cursor_ring);
    SPICE_RING_INIT(&d->ram->release_ring);
392 393
    SPICE_RING_PROD_ITEM(d, &d->ram->release_ring, item);
    assert(item);
G
Gerd Hoffmann 已提交
394 395 396 397 398
    *item = 0;
    qxl_ring_set_dirty(d);
}

/* can be called from spice server thread context */
399
static void qxl_set_dirty(MemoryRegion *mr, ram_addr_t addr, ram_addr_t end)
G
Gerd Hoffmann 已提交
400
{
401
    memory_region_set_dirty(mr, addr, end - addr);
G
Gerd Hoffmann 已提交
402 403 404 405
}

static void qxl_rom_set_dirty(PCIQXLDevice *qxl)
{
406
    qxl_set_dirty(&qxl->rom_bar, 0, qxl->rom_size);
G
Gerd Hoffmann 已提交
407 408 409 410 411 412 413 414 415 416
}

/* called from spice server thread context only */
static void qxl_ram_set_dirty(PCIQXLDevice *qxl, void *ptr)
{
    void *base = qxl->vga.vram_ptr;
    intptr_t offset;

    offset = ptr - base;
    assert(offset < qxl->vga.vram_size);
G
Gerd Hoffmann 已提交
417
    qxl_set_dirty(&qxl->vga.vram, offset, offset + 3);
G
Gerd Hoffmann 已提交
418 419 420 421 422
}

/* can be called from spice server thread context */
static void qxl_ring_set_dirty(PCIQXLDevice *qxl)
{
423 424 425
    ram_addr_t addr = qxl->shadow_rom.ram_header_offset;
    ram_addr_t end  = qxl->vga.vram_size;
    qxl_set_dirty(&qxl->vga.vram, addr, end);
G
Gerd Hoffmann 已提交
426 427 428 429 430 431
}

/*
 * keep track of some command state, for savevm/loadvm.
 * called from spice server thread context only
 */
432
static int qxl_track_command(PCIQXLDevice *qxl, struct QXLCommandExt *ext)
G
Gerd Hoffmann 已提交
433 434 435 436 437
{
    switch (le32_to_cpu(ext->cmd.type)) {
    case QXL_CMD_SURFACE:
    {
        QXLSurfaceCmd *cmd = qxl_phys2virt(qxl, ext->cmd.data, ext->group_id);
438 439 440 441

        if (!cmd) {
            return 1;
        }
G
Gerd Hoffmann 已提交
442
        uint32_t id = le32_to_cpu(cmd->surface_id);
443

444
        if (id >= qxl->ssd.num_surfaces) {
445
            qxl_set_guest_bug(qxl, "QXL_CMD_SURFACE id %d >= %d", id,
446
                              qxl->ssd.num_surfaces);
447 448
            return 1;
        }
449 450 451 452 453 454
        if (cmd->type == QXL_SURFACE_CMD_CREATE &&
            (cmd->u.surface_create.stride & 0x03) != 0) {
            qxl_set_guest_bug(qxl, "QXL_CMD_SURFACE stride = %d %% 4 != 0\n",
                              cmd->u.surface_create.stride);
            return 1;
        }
455
        qemu_mutex_lock(&qxl->track_lock);
G
Gerd Hoffmann 已提交
456 457 458 459 460 461 462 463 464 465
        if (cmd->type == QXL_SURFACE_CMD_CREATE) {
            qxl->guest_surfaces.cmds[id] = ext->cmd.data;
            qxl->guest_surfaces.count++;
            if (qxl->guest_surfaces.max < qxl->guest_surfaces.count)
                qxl->guest_surfaces.max = qxl->guest_surfaces.count;
        }
        if (cmd->type == QXL_SURFACE_CMD_DESTROY) {
            qxl->guest_surfaces.cmds[id] = 0;
            qxl->guest_surfaces.count--;
        }
466
        qemu_mutex_unlock(&qxl->track_lock);
G
Gerd Hoffmann 已提交
467 468 469 470 471
        break;
    }
    case QXL_CMD_CURSOR:
    {
        QXLCursorCmd *cmd = qxl_phys2virt(qxl, ext->cmd.data, ext->group_id);
472 473 474 475

        if (!cmd) {
            return 1;
        }
G
Gerd Hoffmann 已提交
476
        if (cmd->type == QXL_CURSOR_SET) {
Y
Yonit Halperin 已提交
477
            qemu_mutex_lock(&qxl->track_lock);
G
Gerd Hoffmann 已提交
478
            qxl->guest_cursor = ext->cmd.data;
Y
Yonit Halperin 已提交
479
            qemu_mutex_unlock(&qxl->track_lock);
G
Gerd Hoffmann 已提交
480 481 482 483
        }
        break;
    }
    }
484
    return 0;
G
Gerd Hoffmann 已提交
485 486 487 488 489 490 491 492
}

/* spice display interface callbacks */

static void interface_attach_worker(QXLInstance *sin, QXLWorker *qxl_worker)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);

A
Alon Levy 已提交
493
    trace_qxl_interface_attach_worker(qxl->id);
G
Gerd Hoffmann 已提交
494 495 496 497 498 499 500
    qxl->ssd.worker = qxl_worker;
}

static void interface_set_compression_level(QXLInstance *sin, int level)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);

A
Alon Levy 已提交
501
    trace_qxl_interface_set_compression_level(qxl->id, level);
G
Gerd Hoffmann 已提交
502 503 504 505 506 507 508 509 510
    qxl->shadow_rom.compression_level = cpu_to_le32(level);
    qxl->rom->compression_level = cpu_to_le32(level);
    qxl_rom_set_dirty(qxl);
}

static void interface_set_mm_time(QXLInstance *sin, uint32_t mm_time)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);

511 512 513 514
    if (!qemu_spice_display_is_running(&qxl->ssd)) {
        return;
    }

A
Alon Levy 已提交
515
    trace_qxl_interface_set_mm_time(qxl->id, mm_time);
G
Gerd Hoffmann 已提交
516 517 518 519 520 521 522 523 524
    qxl->shadow_rom.mm_clock = cpu_to_le32(mm_time);
    qxl->rom->mm_clock = cpu_to_le32(mm_time);
    qxl_rom_set_dirty(qxl);
}

static void interface_get_init_info(QXLInstance *sin, QXLDevInitInfo *info)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);

A
Alon Levy 已提交
525
    trace_qxl_interface_get_init_info(qxl->id);
G
Gerd Hoffmann 已提交
526 527 528 529 530
    info->memslot_gen_bits = MEMSLOT_GENERATION_BITS;
    info->memslot_id_bits = MEMSLOT_SLOT_BITS;
    info->num_memslots = NUM_MEMSLOTS;
    info->num_memslots_groups = NUM_MEMSLOTS_GROUPS;
    info->internal_groupslot_id = 0;
531 532
    info->qxl_ram_size =
        le32_to_cpu(qxl->shadow_rom.num_pages) << QXL_PAGE_BITS;
533
    info->n_surfaces = qxl->ssd.num_surfaces;
G
Gerd Hoffmann 已提交
534 535
}

536 537 538 539 540 541 542 543 544 545 546 547 548 549 550
static const char *qxl_mode_to_string(int mode)
{
    switch (mode) {
    case QXL_MODE_COMPAT:
        return "compat";
    case QXL_MODE_NATIVE:
        return "native";
    case QXL_MODE_UNDEFINED:
        return "undefined";
    case QXL_MODE_VGA:
        return "vga";
    }
    return "INVALID";
}

A
Alon Levy 已提交
551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581
static const char *io_port_to_string(uint32_t io_port)
{
    if (io_port >= QXL_IO_RANGE_SIZE) {
        return "out of range";
    }
    static const char *io_port_to_string[QXL_IO_RANGE_SIZE + 1] = {
        [QXL_IO_NOTIFY_CMD]             = "QXL_IO_NOTIFY_CMD",
        [QXL_IO_NOTIFY_CURSOR]          = "QXL_IO_NOTIFY_CURSOR",
        [QXL_IO_UPDATE_AREA]            = "QXL_IO_UPDATE_AREA",
        [QXL_IO_UPDATE_IRQ]             = "QXL_IO_UPDATE_IRQ",
        [QXL_IO_NOTIFY_OOM]             = "QXL_IO_NOTIFY_OOM",
        [QXL_IO_RESET]                  = "QXL_IO_RESET",
        [QXL_IO_SET_MODE]               = "QXL_IO_SET_MODE",
        [QXL_IO_LOG]                    = "QXL_IO_LOG",
        [QXL_IO_MEMSLOT_ADD]            = "QXL_IO_MEMSLOT_ADD",
        [QXL_IO_MEMSLOT_DEL]            = "QXL_IO_MEMSLOT_DEL",
        [QXL_IO_DETACH_PRIMARY]         = "QXL_IO_DETACH_PRIMARY",
        [QXL_IO_ATTACH_PRIMARY]         = "QXL_IO_ATTACH_PRIMARY",
        [QXL_IO_CREATE_PRIMARY]         = "QXL_IO_CREATE_PRIMARY",
        [QXL_IO_DESTROY_PRIMARY]        = "QXL_IO_DESTROY_PRIMARY",
        [QXL_IO_DESTROY_SURFACE_WAIT]   = "QXL_IO_DESTROY_SURFACE_WAIT",
        [QXL_IO_DESTROY_ALL_SURFACES]   = "QXL_IO_DESTROY_ALL_SURFACES",
        [QXL_IO_UPDATE_AREA_ASYNC]      = "QXL_IO_UPDATE_AREA_ASYNC",
        [QXL_IO_MEMSLOT_ADD_ASYNC]      = "QXL_IO_MEMSLOT_ADD_ASYNC",
        [QXL_IO_CREATE_PRIMARY_ASYNC]   = "QXL_IO_CREATE_PRIMARY_ASYNC",
        [QXL_IO_DESTROY_PRIMARY_ASYNC]  = "QXL_IO_DESTROY_PRIMARY_ASYNC",
        [QXL_IO_DESTROY_SURFACE_ASYNC]  = "QXL_IO_DESTROY_SURFACE_ASYNC",
        [QXL_IO_DESTROY_ALL_SURFACES_ASYNC]
                                        = "QXL_IO_DESTROY_ALL_SURFACES_ASYNC",
        [QXL_IO_FLUSH_SURFACES_ASYNC]   = "QXL_IO_FLUSH_SURFACES_ASYNC",
        [QXL_IO_FLUSH_RELEASE]          = "QXL_IO_FLUSH_RELEASE",
582
        [QXL_IO_MONITORS_CONFIG_ASYNC]  = "QXL_IO_MONITORS_CONFIG_ASYNC",
A
Alon Levy 已提交
583 584 585 586
    };
    return io_port_to_string[io_port];
}

G
Gerd Hoffmann 已提交
587 588 589 590 591 592 593
/* called from spice server thread context only */
static int interface_get_command(QXLInstance *sin, struct QXLCommandExt *ext)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);
    SimpleSpiceUpdate *update;
    QXLCommandRing *ring;
    QXLCommand *cmd;
594
    int notify, ret;
G
Gerd Hoffmann 已提交
595

A
Alon Levy 已提交
596 597
    trace_qxl_ring_command_check(qxl->id, qxl_mode_to_string(qxl->mode));

G
Gerd Hoffmann 已提交
598 599
    switch (qxl->mode) {
    case QXL_MODE_VGA:
600 601
        ret = false;
        qemu_mutex_lock(&qxl->ssd.lock);
602 603 604
        update = QTAILQ_FIRST(&qxl->ssd.updates);
        if (update != NULL) {
            QTAILQ_REMOVE(&qxl->ssd.updates, update, next);
605 606
            *ext = update->ext;
            ret = true;
G
Gerd Hoffmann 已提交
607
        }
608
        qemu_mutex_unlock(&qxl->ssd.lock);
A
Alon Levy 已提交
609
        if (ret) {
A
Alon Levy 已提交
610
            trace_qxl_ring_command_get(qxl->id, qxl_mode_to_string(qxl->mode));
A
Alon Levy 已提交
611 612
            qxl_log_command(qxl, "vga", ext);
        }
613
        return ret;
G
Gerd Hoffmann 已提交
614 615 616 617
    case QXL_MODE_COMPAT:
    case QXL_MODE_NATIVE:
    case QXL_MODE_UNDEFINED:
        ring = &qxl->ram->cmd_ring;
618
        if (qxl->guest_bug || SPICE_RING_IS_EMPTY(ring)) {
G
Gerd Hoffmann 已提交
619 620
            return false;
        }
621 622 623 624
        SPICE_RING_CONS_ITEM(qxl, ring, cmd);
        if (!cmd) {
            return false;
        }
G
Gerd Hoffmann 已提交
625 626 627 628 629 630 631 632 633 634 635
        ext->cmd      = *cmd;
        ext->group_id = MEMSLOT_GROUP_GUEST;
        ext->flags    = qxl->cmdflags;
        SPICE_RING_POP(ring, notify);
        qxl_ring_set_dirty(qxl);
        if (notify) {
            qxl_send_events(qxl, QXL_INTERRUPT_DISPLAY);
        }
        qxl->guest_primary.commands++;
        qxl_track_command(qxl, ext);
        qxl_log_command(qxl, "cmd", ext);
636
        trace_qxl_ring_command_get(qxl->id, qxl_mode_to_string(qxl->mode));
G
Gerd Hoffmann 已提交
637 638 639 640 641 642 643 644 645 646 647 648
        return true;
    default:
        return false;
    }
}

/* called from spice server thread context only */
static int interface_req_cmd_notification(QXLInstance *sin)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);
    int wait = 1;

A
Alon Levy 已提交
649
    trace_qxl_ring_command_req_notification(qxl->id);
G
Gerd Hoffmann 已提交
650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686
    switch (qxl->mode) {
    case QXL_MODE_COMPAT:
    case QXL_MODE_NATIVE:
    case QXL_MODE_UNDEFINED:
        SPICE_RING_CONS_WAIT(&qxl->ram->cmd_ring, wait);
        qxl_ring_set_dirty(qxl);
        break;
    default:
        /* nothing */
        break;
    }
    return wait;
}

/* called from spice server thread context only */
static inline void qxl_push_free_res(PCIQXLDevice *d, int flush)
{
    QXLReleaseRing *ring = &d->ram->release_ring;
    uint64_t *item;
    int notify;

#define QXL_FREE_BUNCH_SIZE 32

    if (ring->prod - ring->cons + 1 == ring->num_items) {
        /* ring full -- can't push */
        return;
    }
    if (!flush && d->oom_running) {
        /* collect everything from oom handler before pushing */
        return;
    }
    if (!flush && d->num_free_res < QXL_FREE_BUNCH_SIZE) {
        /* collect a bit more before pushing */
        return;
    }

    SPICE_RING_PUSH(ring, notify);
A
Alon Levy 已提交
687 688 689 690 691
    trace_qxl_ring_res_push(d->id, qxl_mode_to_string(d->mode),
           d->guest_surfaces.count, d->num_free_res,
           d->last_release, notify ? "yes" : "no");
    trace_qxl_ring_res_push_rest(d->id, ring->prod - ring->cons,
           ring->num_items, ring->prod, ring->cons);
G
Gerd Hoffmann 已提交
692 693 694
    if (notify) {
        qxl_send_events(d, QXL_INTERRUPT_DISPLAY);
    }
695 696 697 698
    SPICE_RING_PROD_ITEM(d, ring, item);
    if (!item) {
        return;
    }
G
Gerd Hoffmann 已提交
699 700 701 702 703 704 705 706
    *item = 0;
    d->num_free_res = 0;
    d->last_release = NULL;
    qxl_ring_set_dirty(d);
}

/* called from spice server thread context only */
static void interface_release_resource(QXLInstance *sin,
707
                                       QXLReleaseInfoExt ext)
G
Gerd Hoffmann 已提交
708 709 710 711 712 713 714
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);
    QXLReleaseRing *ring;
    uint64_t *item, id;

    if (ext.group_id == MEMSLOT_GROUP_HOST) {
        /* host group -> vga mode update request */
G
Gerd Hoffmann 已提交
715
        QXLCommandExt *cmdext = (void *)(intptr_t)(ext.info->id);
G
Gerd Hoffmann 已提交
716 717 718 719
        SimpleSpiceUpdate *update;
        g_assert(cmdext->cmd.type == QXL_CMD_DRAW);
        update = container_of(cmdext, SimpleSpiceUpdate, ext);
        qemu_spice_destroy_update(&qxl->ssd, update);
G
Gerd Hoffmann 已提交
720 721 722 723 724 725 726 727
        return;
    }

    /*
     * ext->info points into guest-visible memory
     * pci bar 0, $command.release_info
     */
    ring = &qxl->ram->release_ring;
728 729 730 731
    SPICE_RING_PROD_ITEM(qxl, ring, item);
    if (!item) {
        return;
    }
G
Gerd Hoffmann 已提交
732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747
    if (*item == 0) {
        /* stick head into the ring */
        id = ext.info->id;
        ext.info->next = 0;
        qxl_ram_set_dirty(qxl, &ext.info->next);
        *item = id;
        qxl_ring_set_dirty(qxl);
    } else {
        /* append item to the list */
        qxl->last_release->next = ext.info->id;
        qxl_ram_set_dirty(qxl, &qxl->last_release->next);
        ext.info->next = 0;
        qxl_ram_set_dirty(qxl, &ext.info->next);
    }
    qxl->last_release = ext.info;
    qxl->num_free_res++;
A
Alon Levy 已提交
748
    trace_qxl_ring_res_put(qxl->id, qxl->num_free_res);
G
Gerd Hoffmann 已提交
749 750 751 752 753 754 755 756 757 758 759
    qxl_push_free_res(qxl, 0);
}

/* called from spice server thread context only */
static int interface_get_cursor_command(QXLInstance *sin, struct QXLCommandExt *ext)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);
    QXLCursorRing *ring;
    QXLCommand *cmd;
    int notify;

A
Alon Levy 已提交
760 761
    trace_qxl_ring_cursor_check(qxl->id, qxl_mode_to_string(qxl->mode));

G
Gerd Hoffmann 已提交
762 763 764 765 766 767 768 769
    switch (qxl->mode) {
    case QXL_MODE_COMPAT:
    case QXL_MODE_NATIVE:
    case QXL_MODE_UNDEFINED:
        ring = &qxl->ram->cursor_ring;
        if (SPICE_RING_IS_EMPTY(ring)) {
            return false;
        }
770 771 772 773
        SPICE_RING_CONS_ITEM(qxl, ring, cmd);
        if (!cmd) {
            return false;
        }
G
Gerd Hoffmann 已提交
774 775 776 777 778 779 780 781 782 783 784 785 786 787
        ext->cmd      = *cmd;
        ext->group_id = MEMSLOT_GROUP_GUEST;
        ext->flags    = qxl->cmdflags;
        SPICE_RING_POP(ring, notify);
        qxl_ring_set_dirty(qxl);
        if (notify) {
            qxl_send_events(qxl, QXL_INTERRUPT_CURSOR);
        }
        qxl->guest_primary.commands++;
        qxl_track_command(qxl, ext);
        qxl_log_command(qxl, "csr", ext);
        if (qxl->id == 0) {
            qxl_render_cursor(qxl, ext);
        }
A
Alon Levy 已提交
788
        trace_qxl_ring_cursor_get(qxl->id, qxl_mode_to_string(qxl->mode));
G
Gerd Hoffmann 已提交
789 790 791 792 793 794 795 796 797 798 799 800
        return true;
    default:
        return false;
    }
}

/* called from spice server thread context only */
static int interface_req_cursor_notification(QXLInstance *sin)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);
    int wait = 1;

A
Alon Levy 已提交
801
    trace_qxl_ring_cursor_req_notification(qxl->id);
G
Gerd Hoffmann 已提交
802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818
    switch (qxl->mode) {
    case QXL_MODE_COMPAT:
    case QXL_MODE_NATIVE:
    case QXL_MODE_UNDEFINED:
        SPICE_RING_CONS_WAIT(&qxl->ram->cursor_ring, wait);
        qxl_ring_set_dirty(qxl);
        break;
    default:
        /* nothing */
        break;
    }
    return wait;
}

/* called from spice server thread context */
static void interface_notify_update(QXLInstance *sin, uint32_t update_id)
{
819 820 821 822 823 824 825
    /*
     * Called by spice-server as a result of a QXL_CMD_UPDATE which is not in
     * use by xf86-video-qxl and is defined out in the qxl windows driver.
     * Probably was at some earlier version that is prior to git start (2009),
     * and is still guest trigerrable.
     */
    fprintf(stderr, "%s: deprecated\n", __func__);
G
Gerd Hoffmann 已提交
826 827 828 829 830 831 832 833 834 835 836 837 838 839 840
}

/* called from spice server thread context only */
static int interface_flush_resources(QXLInstance *sin)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);
    int ret;

    ret = qxl->num_free_res;
    if (ret) {
        qxl_push_free_res(qxl, 1);
    }
    return ret;
}

841 842 843
static void qxl_create_guest_primary_complete(PCIQXLDevice *d);

/* called from spice server thread context only */
A
Alon Levy 已提交
844
static void interface_async_complete_io(PCIQXLDevice *qxl, QXLCookie *cookie)
845 846 847 848 849 850 851 852
{
    uint32_t current_async;

    qemu_mutex_lock(&qxl->async_lock);
    current_async = qxl->current_async;
    qxl->current_async = QXL_UNDEFINED_IO;
    qemu_mutex_unlock(&qxl->async_lock);

A
Alon Levy 已提交
853
    trace_qxl_interface_async_complete_io(qxl->id, current_async, cookie);
A
Alon Levy 已提交
854 855 856 857 858 859
    if (!cookie) {
        fprintf(stderr, "qxl: %s: error, cookie is NULL\n", __func__);
        return;
    }
    if (cookie && current_async != cookie->io) {
        fprintf(stderr,
A
Alon Levy 已提交
860 861
                "qxl: %s: error: current_async = %d != %"
                PRId64 " = cookie->io\n", __func__, current_async, cookie->io);
A
Alon Levy 已提交
862
    }
863
    switch (current_async) {
A
Alon Levy 已提交
864 865 866 867
    case QXL_IO_MEMSLOT_ADD_ASYNC:
    case QXL_IO_DESTROY_PRIMARY_ASYNC:
    case QXL_IO_UPDATE_AREA_ASYNC:
    case QXL_IO_FLUSH_SURFACES_ASYNC:
868
    case QXL_IO_MONITORS_CONFIG_ASYNC:
A
Alon Levy 已提交
869
        break;
870 871 872 873 874 875 876
    case QXL_IO_CREATE_PRIMARY_ASYNC:
        qxl_create_guest_primary_complete(qxl);
        break;
    case QXL_IO_DESTROY_ALL_SURFACES_ASYNC:
        qxl_spice_destroy_surfaces_complete(qxl);
        break;
    case QXL_IO_DESTROY_SURFACE_ASYNC:
A
Alon Levy 已提交
877
        qxl_spice_destroy_surface_wait_complete(qxl, cookie->u.surface_id);
878
        break;
A
Alon Levy 已提交
879 880 881
    default:
        fprintf(stderr, "qxl: %s: unexpected current_async %d\n", __func__,
                current_async);
882 883 884 885
    }
    qxl_send_events(qxl, QXL_INTERRUPT_IO_CMD);
}

A
Alon Levy 已提交
886 887 888 889 890 891 892 893 894 895 896 897 898 899
/* called from spice server thread context only */
static void interface_update_area_complete(QXLInstance *sin,
        uint32_t surface_id,
        QXLRect *dirty, uint32_t num_updated_rects)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);
    int i;
    int qxl_i;

    qemu_mutex_lock(&qxl->ssd.lock);
    if (surface_id != 0 || !qxl->render_update_cookie_num) {
        qemu_mutex_unlock(&qxl->ssd.lock);
        return;
    }
A
Alon Levy 已提交
900 901 902
    trace_qxl_interface_update_area_complete(qxl->id, surface_id, dirty->left,
            dirty->right, dirty->top, dirty->bottom);
    trace_qxl_interface_update_area_complete_rest(qxl->id, num_updated_rects);
A
Alon Levy 已提交
903 904 905 906
    if (qxl->num_dirty_rects + num_updated_rects > QXL_NUM_DIRTY_RECTS) {
        /*
         * overflow - treat this as a full update. Not expected to be common.
         */
A
Alon Levy 已提交
907 908
        trace_qxl_interface_update_area_complete_overflow(qxl->id,
                                                          QXL_NUM_DIRTY_RECTS);
A
Alon Levy 已提交
909 910 911 912 913 914 915 916 917 918 919 920 921 922 923
        qxl->guest_primary.resized = 1;
    }
    if (qxl->guest_primary.resized) {
        /*
         * Don't bother copying or scheduling the bh since we will flip
         * the whole area anyway on completion of the update_area async call
         */
        qemu_mutex_unlock(&qxl->ssd.lock);
        return;
    }
    qxl_i = qxl->num_dirty_rects;
    for (i = 0; i < num_updated_rects; i++) {
        qxl->dirty[qxl_i++] = dirty[i];
    }
    qxl->num_dirty_rects += num_updated_rects;
A
Alon Levy 已提交
924 925
    trace_qxl_interface_update_area_complete_schedule_bh(qxl->id,
                                                         qxl->num_dirty_rects);
A
Alon Levy 已提交
926 927 928 929
    qemu_bh_schedule(qxl->update_area_bh);
    qemu_mutex_unlock(&qxl->ssd.lock);
}

A
Alon Levy 已提交
930 931 932 933
/* called from spice server thread context only */
static void interface_async_complete(QXLInstance *sin, uint64_t cookie_token)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);
934
    QXLCookie *cookie = (QXLCookie *)(uintptr_t)cookie_token;
A
Alon Levy 已提交
935 936 937 938

    switch (cookie->type) {
    case QXL_COOKIE_TYPE_IO:
        interface_async_complete_io(qxl, cookie);
A
Alon Levy 已提交
939 940 941 942
        g_free(cookie);
        break;
    case QXL_COOKIE_TYPE_RENDER_UPDATE_AREA:
        qxl_render_update_area_done(qxl, cookie);
A
Alon Levy 已提交
943
        break;
944 945
    case QXL_COOKIE_TYPE_POST_LOAD_MONITORS_CONFIG:
        break;
A
Alon Levy 已提交
946 947 948
    default:
        fprintf(stderr, "qxl: %s: unexpected cookie type %d\n",
                __func__, cookie->type);
A
Alon Levy 已提交
949
        g_free(cookie);
A
Alon Levy 已提交
950 951 952
    }
}

953 954 955 956 957 958 959
/* called from spice server thread context only */
static void interface_set_client_capabilities(QXLInstance *sin,
                                              uint8_t client_present,
                                              uint8_t caps[58])
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);

960 961 962 963 964 965
    if (qxl->revision < 4) {
        trace_qxl_set_client_capabilities_unsupported_by_revision(qxl->id,
                                                              qxl->revision);
        return;
    }

966 967 968 969 970
    if (runstate_check(RUN_STATE_INMIGRATE) ||
        runstate_check(RUN_STATE_POSTMIGRATE)) {
        return;
    }

971
    qxl->shadow_rom.client_present = client_present;
972 973
    memcpy(qxl->shadow_rom.client_capabilities, caps,
           sizeof(qxl->shadow_rom.client_capabilities));
974
    qxl->rom->client_present = client_present;
975 976
    memcpy(qxl->rom->client_capabilities, caps,
           sizeof(qxl->rom->client_capabilities));
977 978 979 980 981
    qxl_rom_set_dirty(qxl);

    qxl_send_events(qxl, QXL_INTERRUPT_CLIENT);
}

982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998
static uint32_t qxl_crc32(const uint8_t *p, unsigned len)
{
    /*
     * zlib xors the seed with 0xffffffff, and xors the result
     * again with 0xffffffff; Both are not done with linux's crc32,
     * which we want to be compatible with, so undo that.
     */
    return crc32(0xffffffff, p, len) ^ 0xffffffff;
}

/* called from main context only */
static int interface_client_monitors_config(QXLInstance *sin,
                                        VDAgentMonitorsConfig *monitors_config)
{
    PCIQXLDevice *qxl = container_of(sin, PCIQXLDevice, ssd.qxl);
    QXLRom *rom = memory_region_get_ram_ptr(&qxl->rom_bar);
    int i;
999
    unsigned max_outputs = ARRAY_SIZE(rom->client_monitors_config.heads);
1000

1001 1002 1003 1004 1005
    if (qxl->revision < 4) {
        trace_qxl_client_monitors_config_unsupported_by_device(qxl->id,
                                                               qxl->revision);
        return 0;
    }
1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021
    /*
     * Older windows drivers set int_mask to 0 when their ISR is called,
     * then later set it to ~0. So it doesn't relate to the actual interrupts
     * handled. However, they are old, so clearly they don't support this
     * interrupt
     */
    if (qxl->ram->int_mask == 0 || qxl->ram->int_mask == ~0 ||
        !(qxl->ram->int_mask & QXL_INTERRUPT_CLIENT_MONITORS_CONFIG)) {
        trace_qxl_client_monitors_config_unsupported_by_guest(qxl->id,
                                                            qxl->ram->int_mask,
                                                            monitors_config);
        return 0;
    }
    if (!monitors_config) {
        return 1;
    }
1022 1023 1024 1025 1026 1027 1028 1029

#if SPICE_SERVER_VERSION >= 0x000c06 /* release 0.12.6 */
    /* limit number of outputs based on setting limit */
    if (qxl->max_outputs && qxl->max_outputs <= max_outputs) {
        max_outputs = qxl->max_outputs;
    }
#endif

1030 1031 1032 1033
    memset(&rom->client_monitors_config, 0,
           sizeof(rom->client_monitors_config));
    rom->client_monitors_config.count = monitors_config->num_of_monitors;
    /* monitors_config->flags ignored */
1034
    if (rom->client_monitors_config.count >= max_outputs) {
1035 1036
        trace_qxl_client_monitors_config_capped(qxl->id,
                                monitors_config->num_of_monitors,
1037 1038
                                max_outputs);
        rom->client_monitors_config.count = max_outputs;
1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062
    }
    for (i = 0 ; i < rom->client_monitors_config.count ; ++i) {
        VDAgentMonConfig *monitor = &monitors_config->monitors[i];
        QXLURect *rect = &rom->client_monitors_config.heads[i];
        /* monitor->depth ignored */
        rect->left = monitor->x;
        rect->top = monitor->y;
        rect->right = monitor->x + monitor->width;
        rect->bottom = monitor->y + monitor->height;
    }
    rom->client_monitors_config_crc = qxl_crc32(
            (const uint8_t *)&rom->client_monitors_config,
            sizeof(rom->client_monitors_config));
    trace_qxl_client_monitors_config_crc(qxl->id,
            sizeof(rom->client_monitors_config),
            rom->client_monitors_config_crc);

    trace_qxl_interrupt_client_monitors_config(qxl->id,
                        rom->client_monitors_config.count,
                        rom->client_monitors_config.heads);
    qxl_send_events(qxl, QXL_INTERRUPT_CLIENT_MONITORS_CONFIG);
    return 1;
}

G
Gerd Hoffmann 已提交
1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081
static const QXLInterface qxl_interface = {
    .base.type               = SPICE_INTERFACE_QXL,
    .base.description        = "qxl gpu",
    .base.major_version      = SPICE_INTERFACE_QXL_MAJOR,
    .base.minor_version      = SPICE_INTERFACE_QXL_MINOR,

    .attache_worker          = interface_attach_worker,
    .set_compression_level   = interface_set_compression_level,
    .set_mm_time             = interface_set_mm_time,
    .get_init_info           = interface_get_init_info,

    /* the callbacks below are called from spice server thread context */
    .get_command             = interface_get_command,
    .req_cmd_notification    = interface_req_cmd_notification,
    .release_resource        = interface_release_resource,
    .get_cursor_command      = interface_get_cursor_command,
    .req_cursor_notification = interface_req_cursor_notification,
    .notify_update           = interface_notify_update,
    .flush_resources         = interface_flush_resources,
1082
    .async_complete          = interface_async_complete,
A
Alon Levy 已提交
1083
    .update_area_complete    = interface_update_area_complete,
1084
    .set_client_capabilities = interface_set_client_capabilities,
1085
    .client_monitors_config = interface_client_monitors_config,
G
Gerd Hoffmann 已提交
1086 1087
};

1088 1089 1090 1091
static const GraphicHwOps qxl_ops = {
    .gfx_update  = qxl_hw_update,
};

G
Gerd Hoffmann 已提交
1092 1093 1094 1095 1096
static void qxl_enter_vga_mode(PCIQXLDevice *d)
{
    if (d->mode == QXL_MODE_VGA) {
        return;
    }
A
Alon Levy 已提交
1097
    trace_qxl_enter_vga_mode(d->id);
1098 1099 1100
#if SPICE_SERVER_VERSION >= 0x000c03 /* release 0.12.3 */
    spice_qxl_driver_unload(&d->ssd.qxl);
#endif
1101
    graphic_console_set_hwops(d->ssd.dcl.con, d->vga.hw_ops, &d->vga);
1102
    update_displaychangelistener(&d->ssd.dcl, GUI_REFRESH_INTERVAL_DEFAULT);
G
Gerd Hoffmann 已提交
1103 1104
    qemu_spice_create_host_primary(&d->ssd);
    d->mode = QXL_MODE_VGA;
1105
    vga_dirty_log_start(&d->vga);
1106
    graphic_hw_update(d->vga.con);
G
Gerd Hoffmann 已提交
1107 1108 1109 1110 1111 1112 1113
}

static void qxl_exit_vga_mode(PCIQXLDevice *d)
{
    if (d->mode != QXL_MODE_VGA) {
        return;
    }
A
Alon Levy 已提交
1114
    trace_qxl_exit_vga_mode(d->id);
1115
    graphic_console_set_hwops(d->ssd.dcl.con, &qxl_ops, d);
1116
    update_displaychangelistener(&d->ssd.dcl, GUI_REFRESH_INTERVAL_IDLE);
1117
    vga_dirty_log_stop(&d->vga);
1118
    qxl_destroy_primary(d, QXL_SYNC);
G
Gerd Hoffmann 已提交
1119 1120
}

1121
static void qxl_update_irq(PCIQXLDevice *d)
G
Gerd Hoffmann 已提交
1122 1123 1124 1125
{
    uint32_t pending = le32_to_cpu(d->ram->int_pending);
    uint32_t mask    = le32_to_cpu(d->ram->int_mask);
    int level = !!(pending & mask);
1126
    pci_set_irq(&d->pci, level);
G
Gerd Hoffmann 已提交
1127 1128 1129 1130 1131 1132
    qxl_ring_set_dirty(d);
}

static void qxl_check_state(PCIQXLDevice *d)
{
    QXLRam *ram = d->ram;
1133
    int spice_display_running = qemu_spice_display_is_running(&d->ssd);
G
Gerd Hoffmann 已提交
1134

1135 1136
    assert(!spice_display_running || SPICE_RING_IS_EMPTY(&ram->cmd_ring));
    assert(!spice_display_running || SPICE_RING_IS_EMPTY(&ram->cursor_ring));
G
Gerd Hoffmann 已提交
1137 1138 1139 1140 1141 1142
}

static void qxl_reset_state(PCIQXLDevice *d)
{
    QXLRom *rom = d->rom;

1143
    qxl_check_state(d);
G
Gerd Hoffmann 已提交
1144 1145 1146 1147 1148 1149 1150
    d->shadow_rom.update_id = cpu_to_le32(0);
    *rom = d->shadow_rom;
    qxl_rom_set_dirty(d);
    init_qxl_ram(d);
    d->num_free_res = 0;
    d->last_release = NULL;
    memset(&d->ssd.dirty, 0, sizeof(d->ssd.dirty));
A
Alon Levy 已提交
1151
    qxl_update_irq(d);
G
Gerd Hoffmann 已提交
1152 1153 1154 1155
}

static void qxl_soft_reset(PCIQXLDevice *d)
{
A
Alon Levy 已提交
1156
    trace_qxl_soft_reset(d->id);
G
Gerd Hoffmann 已提交
1157
    qxl_check_state(d);
1158
    qxl_clear_guest_bug(d);
1159
    d->current_async = QXL_UNDEFINED_IO;
G
Gerd Hoffmann 已提交
1160 1161 1162 1163 1164 1165 1166 1167 1168 1169

    if (d->id == 0) {
        qxl_enter_vga_mode(d);
    } else {
        d->mode = QXL_MODE_UNDEFINED;
    }
}

static void qxl_hard_reset(PCIQXLDevice *d, int loadvm)
{
1170 1171
    bool startstop = qemu_spice_display_is_running(&d->ssd);

A
Alon Levy 已提交
1172
    trace_qxl_hard_reset(d->id, loadvm);
G
Gerd Hoffmann 已提交
1173

1174 1175 1176 1177
    if (startstop) {
        qemu_spice_display_stop();
    }

G
Gerd Hoffmann 已提交
1178 1179
    qxl_spice_reset_cursor(d);
    qxl_spice_reset_image_cache(d);
G
Gerd Hoffmann 已提交
1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190
    qxl_reset_surfaces(d);
    qxl_reset_memslots(d);

    /* pre loadvm reset must not touch QXLRam.  This lives in
     * device memory, is migrated together with RAM and thus
     * already loaded at this point */
    if (!loadvm) {
        qxl_reset_state(d);
    }
    qemu_spice_create_host_memslot(&d->ssd);
    qxl_soft_reset(d);
1191 1192 1193 1194

    if (startstop) {
        qemu_spice_display_start();
    }
G
Gerd Hoffmann 已提交
1195 1196 1197 1198
}

static void qxl_reset_handler(DeviceState *dev)
{
G
Gonglei 已提交
1199
    PCIQXLDevice *d = PCI_QXL(PCI_DEVICE(dev));
A
Alon Levy 已提交
1200

G
Gerd Hoffmann 已提交
1201 1202 1203 1204 1205 1206 1207 1208
    qxl_hard_reset(d, 0);
}

static void qxl_vga_ioport_write(void *opaque, uint32_t addr, uint32_t val)
{
    VGACommonState *vga = opaque;
    PCIQXLDevice *qxl = container_of(vga, PCIQXLDevice, vga);

A
Alon Levy 已提交
1209
    trace_qxl_io_write_vga(qxl->id, qxl_mode_to_string(qxl->mode), addr, val);
G
Gerd Hoffmann 已提交
1210
    if (qxl->mode != QXL_MODE_VGA) {
1211
        qxl_destroy_primary(qxl, QXL_SYNC);
G
Gerd Hoffmann 已提交
1212 1213 1214 1215 1216
        qxl_soft_reset(qxl);
    }
    vga_ioport_write(opaque, addr, val);
}

G
Gerd Hoffmann 已提交
1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230
static const MemoryRegionPortio qxl_vga_portio_list[] = {
    { 0x04,  2, 1, .read  = vga_ioport_read,
                   .write = qxl_vga_ioport_write }, /* 3b4 */
    { 0x0a,  1, 1, .read  = vga_ioport_read,
                   .write = qxl_vga_ioport_write }, /* 3ba */
    { 0x10, 16, 1, .read  = vga_ioport_read,
                   .write = qxl_vga_ioport_write }, /* 3c0 */
    { 0x24,  2, 1, .read  = vga_ioport_read,
                   .write = qxl_vga_ioport_write }, /* 3d4 */
    { 0x2a,  1, 1, .read  = vga_ioport_read,
                   .write = qxl_vga_ioport_write }, /* 3da */
    PORTIO_END_OF_LIST(),
};

1231 1232
static int qxl_add_memslot(PCIQXLDevice *d, uint32_t slot_id, uint64_t delta,
                           qxl_async_io async)
G
Gerd Hoffmann 已提交
1233 1234 1235 1236
{
    static const int regions[] = {
        QXL_RAM_RANGE_INDEX,
        QXL_VRAM_RANGE_INDEX,
G
Gerd Hoffmann 已提交
1237
        QXL_VRAM64_RANGE_INDEX,
G
Gerd Hoffmann 已提交
1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250
    };
    uint64_t guest_start;
    uint64_t guest_end;
    int pci_region;
    pcibus_t pci_start;
    pcibus_t pci_end;
    intptr_t virt_start;
    QXLDevMemSlot memslot;
    int i;

    guest_start = le64_to_cpu(d->guest_slots[slot_id].slot.mem_start);
    guest_end   = le64_to_cpu(d->guest_slots[slot_id].slot.mem_end);

A
Alon Levy 已提交
1251
    trace_qxl_memslot_add_guest(d->id, slot_id, guest_start, guest_end);
G
Gerd Hoffmann 已提交
1252

1253
    if (slot_id >= NUM_MEMSLOTS) {
1254
        qxl_set_guest_bug(d, "%s: slot_id >= NUM_MEMSLOTS %d >= %d", __func__,
1255 1256 1257 1258
                      slot_id, NUM_MEMSLOTS);
        return 1;
    }
    if (guest_start > guest_end) {
1259
        qxl_set_guest_bug(d, "%s: guest_start > guest_end 0x%" PRIx64
1260 1261 1262
                         " > 0x%" PRIx64, __func__, guest_start, guest_end);
        return 1;
    }
G
Gerd Hoffmann 已提交
1263 1264 1265 1266 1267 1268 1269 1270 1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282

    for (i = 0; i < ARRAY_SIZE(regions); i++) {
        pci_region = regions[i];
        pci_start = d->pci.io_regions[pci_region].addr;
        pci_end = pci_start + d->pci.io_regions[pci_region].size;
        /* mapped? */
        if (pci_start == -1) {
            continue;
        }
        /* start address in range ? */
        if (guest_start < pci_start || guest_start > pci_end) {
            continue;
        }
        /* end address in range ? */
        if (guest_end > pci_end) {
            continue;
        }
        /* passed */
        break;
    }
1283
    if (i == ARRAY_SIZE(regions)) {
1284
        qxl_set_guest_bug(d, "%s: finished loop without match", __func__);
1285 1286
        return 1;
    }
G
Gerd Hoffmann 已提交
1287 1288 1289

    switch (pci_region) {
    case QXL_RAM_RANGE_INDEX:
1290
        virt_start = (intptr_t)memory_region_get_ram_ptr(&d->vga.vram);
G
Gerd Hoffmann 已提交
1291 1292
        break;
    case QXL_VRAM_RANGE_INDEX:
G
Gerd Hoffmann 已提交
1293
    case 4 /* vram 64bit */:
1294
        virt_start = (intptr_t)memory_region_get_ram_ptr(&d->vram_bar);
G
Gerd Hoffmann 已提交
1295 1296 1297
        break;
    default:
        /* should not happen */
1298
        qxl_set_guest_bug(d, "%s: pci_region = %d", __func__, pci_region);
1299
        return 1;
G
Gerd Hoffmann 已提交
1300 1301 1302 1303 1304 1305 1306 1307 1308 1309
    }

    memslot.slot_id = slot_id;
    memslot.slot_group_id = MEMSLOT_GROUP_GUEST; /* guest group */
    memslot.virt_start = virt_start + (guest_start - pci_start);
    memslot.virt_end   = virt_start + (guest_end   - pci_start);
    memslot.addr_delta = memslot.virt_start - delta;
    memslot.generation = d->rom->slot_generation = 0;
    qxl_rom_set_dirty(d);

1310
    qemu_spice_add_memslot(&d->ssd, &memslot, async);
G
Gerd Hoffmann 已提交
1311 1312 1313 1314
    d->guest_slots[slot_id].ptr = (void*)memslot.virt_start;
    d->guest_slots[slot_id].size = memslot.virt_end - memslot.virt_start;
    d->guest_slots[slot_id].delta = delta;
    d->guest_slots[slot_id].active = 1;
1315
    return 0;
G
Gerd Hoffmann 已提交
1316 1317 1318 1319
}

static void qxl_del_memslot(PCIQXLDevice *d, uint32_t slot_id)
{
1320
    qemu_spice_del_memslot(&d->ssd, MEMSLOT_GROUP_HOST, slot_id);
G
Gerd Hoffmann 已提交
1321 1322 1323 1324 1325
    d->guest_slots[slot_id].active = 0;
}

static void qxl_reset_memslots(PCIQXLDevice *d)
{
G
Gerd Hoffmann 已提交
1326
    qxl_spice_reset_memslots(d);
G
Gerd Hoffmann 已提交
1327 1328 1329 1330 1331
    memset(&d->guest_slots, 0, sizeof(d->guest_slots));
}

static void qxl_reset_surfaces(PCIQXLDevice *d)
{
A
Alon Levy 已提交
1332
    trace_qxl_reset_surfaces(d->id);
G
Gerd Hoffmann 已提交
1333
    d->mode = QXL_MODE_UNDEFINED;
1334
    qxl_spice_destroy_surfaces(d, QXL_SYNC);
G
Gerd Hoffmann 已提交
1335 1336
}

1337
/* can be also called from spice server thread context */
G
Gerd Hoffmann 已提交
1338 1339 1340 1341 1342 1343 1344 1345
void *qxl_phys2virt(PCIQXLDevice *qxl, QXLPHYSICAL pqxl, int group_id)
{
    uint64_t phys   = le64_to_cpu(pqxl);
    uint32_t slot   = (phys >> (64 -  8)) & 0xff;
    uint64_t offset = phys & 0xffffffffffff;

    switch (group_id) {
    case MEMSLOT_GROUP_HOST:
G
Gerd Hoffmann 已提交
1346
        return (void *)(intptr_t)offset;
G
Gerd Hoffmann 已提交
1347
    case MEMSLOT_GROUP_GUEST:
1348
        if (slot >= NUM_MEMSLOTS) {
1349 1350
            qxl_set_guest_bug(qxl, "slot too large %d >= %d", slot,
                              NUM_MEMSLOTS);
1351 1352 1353
            return NULL;
        }
        if (!qxl->guest_slots[slot].active) {
1354
            qxl_set_guest_bug(qxl, "inactive slot %d\n", slot);
1355 1356 1357
            return NULL;
        }
        if (offset < qxl->guest_slots[slot].delta) {
1358 1359
            qxl_set_guest_bug(qxl,
                          "slot %d offset %"PRIu64" < delta %"PRIu64"\n",
1360 1361 1362
                          slot, offset, qxl->guest_slots[slot].delta);
            return NULL;
        }
G
Gerd Hoffmann 已提交
1363
        offset -= qxl->guest_slots[slot].delta;
1364
        if (offset > qxl->guest_slots[slot].size) {
1365 1366
            qxl_set_guest_bug(qxl,
                          "slot %d offset %"PRIu64" > size %"PRIu64"\n",
1367 1368 1369
                          slot, offset, qxl->guest_slots[slot].size);
            return NULL;
        }
G
Gerd Hoffmann 已提交
1370 1371
        return qxl->guest_slots[slot].ptr + offset;
    }
1372
    return NULL;
G
Gerd Hoffmann 已提交
1373 1374
}

1375 1376 1377 1378 1379 1380 1381 1382
static void qxl_create_guest_primary_complete(PCIQXLDevice *qxl)
{
    /* for local rendering */
    qxl_render_resize(qxl);
}

static void qxl_create_guest_primary(PCIQXLDevice *qxl, int loadvm,
                                     qxl_async_io async)
G
Gerd Hoffmann 已提交
1383 1384 1385
{
    QXLDevSurfaceCreate surface;
    QXLSurfaceCreate *sc = &qxl->guest_primary.surface;
1386
    uint32_t requested_height = le32_to_cpu(sc->height);
1387 1388
    int requested_stride = le32_to_cpu(sc->stride);

1389 1390 1391 1392 1393 1394 1395
    if (requested_stride == INT32_MIN ||
        abs(requested_stride) * (uint64_t)requested_height
                                        > qxl->vgamem_size) {
        qxl_set_guest_bug(qxl, "%s: requested primary larger than framebuffer"
                               " stride %d x height %" PRIu32 " > %" PRIu32,
                               __func__, requested_stride, requested_height,
                               qxl->vgamem_size);
1396 1397
        return;
    }
G
Gerd Hoffmann 已提交
1398

1399
    if (qxl->mode == QXL_MODE_NATIVE) {
1400
        qxl_set_guest_bug(qxl, "%s: nop since already in QXL_MODE_NATIVE",
1401 1402
                      __func__);
    }
G
Gerd Hoffmann 已提交
1403 1404 1405 1406 1407 1408 1409 1410 1411 1412
    qxl_exit_vga_mode(qxl);

    surface.format     = le32_to_cpu(sc->format);
    surface.height     = le32_to_cpu(sc->height);
    surface.mem        = le64_to_cpu(sc->mem);
    surface.position   = le32_to_cpu(sc->position);
    surface.stride     = le32_to_cpu(sc->stride);
    surface.width      = le32_to_cpu(sc->width);
    surface.type       = le32_to_cpu(sc->type);
    surface.flags      = le32_to_cpu(sc->flags);
A
Alon Levy 已提交
1413 1414 1415 1416
    trace_qxl_create_guest_primary(qxl->id, sc->width, sc->height, sc->mem,
                                   sc->format, sc->position);
    trace_qxl_create_guest_primary_rest(qxl->id, sc->stride, sc->type,
                                        sc->flags);
G
Gerd Hoffmann 已提交
1417

1418 1419 1420 1421 1422 1423
    if ((surface.stride & 0x3) != 0) {
        qxl_set_guest_bug(qxl, "primary surface stride = %d %% 4 != 0",
                          surface.stride);
        return;
    }

G
Gerd Hoffmann 已提交
1424 1425 1426 1427 1428 1429 1430 1431
    surface.mouse_mode = true;
    surface.group_id   = MEMSLOT_GROUP_GUEST;
    if (loadvm) {
        surface.flags |= QXL_SURF_FLAG_KEEP_DATA;
    }

    qxl->mode = QXL_MODE_NATIVE;
    qxl->cmdflags = 0;
1432
    qemu_spice_create_primary_surface(&qxl->ssd, 0, &surface, async);
G
Gerd Hoffmann 已提交
1433

1434 1435 1436
    if (async == QXL_SYNC) {
        qxl_create_guest_primary_complete(qxl);
    }
G
Gerd Hoffmann 已提交
1437 1438
}

1439 1440 1441
/* return 1 if surface destoy was initiated (in QXL_ASYNC case) or
 * done (in QXL_SYNC case), 0 otherwise. */
static int qxl_destroy_primary(PCIQXLDevice *d, qxl_async_io async)
G
Gerd Hoffmann 已提交
1442 1443
{
    if (d->mode == QXL_MODE_UNDEFINED) {
1444
        return 0;
G
Gerd Hoffmann 已提交
1445
    }
A
Alon Levy 已提交
1446
    trace_qxl_destroy_primary(d->id);
G
Gerd Hoffmann 已提交
1447
    d->mode = QXL_MODE_UNDEFINED;
1448
    qemu_spice_destroy_primary_surface(&d->ssd, 0, async);
Y
Yonit Halperin 已提交
1449
    qxl_spice_reset_cursor(d);
1450
    return 1;
G
Gerd Hoffmann 已提交
1451 1452
}

G
Gerd Hoffmann 已提交
1453
static void qxl_set_mode(PCIQXLDevice *d, unsigned int modenr, int loadvm)
G
Gerd Hoffmann 已提交
1454 1455 1456 1457 1458 1459 1460 1461 1462
{
    pcibus_t start = d->pci.io_regions[QXL_RAM_RANGE_INDEX].addr;
    pcibus_t end   = d->pci.io_regions[QXL_RAM_RANGE_INDEX].size + start;
    QXLMode *mode = d->modes->modes + modenr;
    uint64_t devmem = d->pci.io_regions[QXL_RAM_RANGE_INDEX].addr;
    QXLMemSlot slot = {
        .mem_start = start,
        .mem_end = end
    };
G
Gerd Hoffmann 已提交
1463 1464 1465 1466 1467 1468

    if (modenr >= d->modes->n_modes) {
        qxl_set_guest_bug(d, "mode number out of range");
        return;
    }

G
Gerd Hoffmann 已提交
1469 1470 1471 1472 1473 1474 1475 1476 1477 1478
    QXLSurfaceCreate surface = {
        .width      = mode->x_res,
        .height     = mode->y_res,
        .stride     = -mode->x_res * 4,
        .format     = SPICE_SURFACE_FMT_32_xRGB,
        .flags      = loadvm ? QXL_SURF_FLAG_KEEP_DATA : 0,
        .mouse_mode = true,
        .mem        = devmem + d->shadow_rom.draw_area_offset,
    };

A
Alon Levy 已提交
1479 1480
    trace_qxl_set_mode(d->id, modenr, mode->x_res, mode->y_res, mode->bits,
                       devmem);
G
Gerd Hoffmann 已提交
1481 1482 1483 1484 1485
    if (!loadvm) {
        qxl_hard_reset(d, 0);
    }

    d->guest_slots[0].slot = slot;
1486
    assert(qxl_add_memslot(d, 0, devmem, QXL_SYNC) == 0);
G
Gerd Hoffmann 已提交
1487 1488

    d->guest_primary.surface = surface;
1489
    qxl_create_guest_primary(d, 0, QXL_SYNC);
G
Gerd Hoffmann 已提交
1490 1491 1492 1493 1494 1495 1496 1497 1498 1499 1500

    d->mode = QXL_MODE_COMPAT;
    d->cmdflags = QXL_COMMAND_FLAG_COMPAT;
    if (mode->bits == 16) {
        d->cmdflags |= QXL_COMMAND_FLAG_COMPAT_16BPP;
    }
    d->shadow_rom.mode = cpu_to_le32(modenr);
    d->rom->mode = cpu_to_le32(modenr);
    qxl_rom_set_dirty(d);
}

A
Avi Kivity 已提交
1501
static void ioport_write(void *opaque, hwaddr addr,
1502
                         uint64_t val, unsigned size)
G
Gerd Hoffmann 已提交
1503 1504
{
    PCIQXLDevice *d = opaque;
1505
    uint32_t io_port = addr;
1506 1507
    qxl_async_io async = QXL_SYNC;
    uint32_t orig_io_port = io_port;
G
Gerd Hoffmann 已提交
1508

1509
    if (d->guest_bug && io_port != QXL_IO_RESET) {
1510 1511 1512
        return;
    }

1513
    if (d->revision <= QXL_REVISION_STABLE_V10 &&
1514
        io_port > QXL_IO_FLUSH_RELEASE) {
1515 1516 1517 1518 1519
        qxl_set_guest_bug(d, "unsupported io %d for revision %d\n",
            io_port, d->revision);
        return;
    }

G
Gerd Hoffmann 已提交
1520 1521 1522 1523 1524 1525
    switch (io_port) {
    case QXL_IO_RESET:
    case QXL_IO_SET_MODE:
    case QXL_IO_MEMSLOT_ADD:
    case QXL_IO_MEMSLOT_DEL:
    case QXL_IO_CREATE_PRIMARY:
1526
    case QXL_IO_UPDATE_IRQ:
A
Alon Levy 已提交
1527
    case QXL_IO_LOG:
1528 1529
    case QXL_IO_MEMSLOT_ADD_ASYNC:
    case QXL_IO_CREATE_PRIMARY_ASYNC:
G
Gerd Hoffmann 已提交
1530 1531
        break;
    default:
1532
        if (d->mode != QXL_MODE_VGA) {
G
Gerd Hoffmann 已提交
1533
            break;
1534
        }
A
Alon Levy 已提交
1535
        trace_qxl_io_unexpected_vga_mode(d->id,
A
Alon Levy 已提交
1536
            addr, val, io_port_to_string(io_port));
1537 1538
        /* be nice to buggy guest drivers */
        if (io_port >= QXL_IO_UPDATE_AREA_ASYNC &&
1539
            io_port < QXL_IO_RANGE_SIZE) {
1540 1541
            qxl_send_events(d, QXL_INTERRUPT_IO_CMD);
        }
G
Gerd Hoffmann 已提交
1542 1543 1544
        return;
    }

1545 1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561 1562 1563 1564
    /* we change the io_port to avoid ifdeffery in the main switch */
    orig_io_port = io_port;
    switch (io_port) {
    case QXL_IO_UPDATE_AREA_ASYNC:
        io_port = QXL_IO_UPDATE_AREA;
        goto async_common;
    case QXL_IO_MEMSLOT_ADD_ASYNC:
        io_port = QXL_IO_MEMSLOT_ADD;
        goto async_common;
    case QXL_IO_CREATE_PRIMARY_ASYNC:
        io_port = QXL_IO_CREATE_PRIMARY;
        goto async_common;
    case QXL_IO_DESTROY_PRIMARY_ASYNC:
        io_port = QXL_IO_DESTROY_PRIMARY;
        goto async_common;
    case QXL_IO_DESTROY_SURFACE_ASYNC:
        io_port = QXL_IO_DESTROY_SURFACE_WAIT;
        goto async_common;
    case QXL_IO_DESTROY_ALL_SURFACES_ASYNC:
        io_port = QXL_IO_DESTROY_ALL_SURFACES;
1565 1566
        goto async_common;
    case QXL_IO_FLUSH_SURFACES_ASYNC:
1567
    case QXL_IO_MONITORS_CONFIG_ASYNC:
1568 1569 1570 1571
async_common:
        async = QXL_ASYNC;
        qemu_mutex_lock(&d->async_lock);
        if (d->current_async != QXL_UNDEFINED_IO) {
1572
            qxl_set_guest_bug(d, "%d async started before last (%d) complete",
1573 1574 1575 1576 1577 1578 1579 1580 1581 1582
                io_port, d->current_async);
            qemu_mutex_unlock(&d->async_lock);
            return;
        }
        d->current_async = orig_io_port;
        qemu_mutex_unlock(&d->async_lock);
        break;
    default:
        break;
    }
G
Gerd Hoffmann 已提交
1583 1584 1585
    trace_qxl_io_write(d->id, qxl_mode_to_string(d->mode),
                       addr, io_port_to_string(addr),
                       val, size, async);
1586

G
Gerd Hoffmann 已提交
1587 1588 1589
    switch (io_port) {
    case QXL_IO_UPDATE_AREA:
    {
A
Alon Levy 已提交
1590
        QXLCookie *cookie = NULL;
G
Gerd Hoffmann 已提交
1591
        QXLRect update = d->ram->update_area;
A
Alon Levy 已提交
1592

1593
        if (d->ram->update_surface > d->ssd.num_surfaces) {
1594 1595
            qxl_set_guest_bug(d, "QXL_IO_UPDATE_AREA: invalid surface id %d\n",
                              d->ram->update_surface);
1596
            break;
1597
        }
1598 1599
        if (update.left >= update.right || update.top >= update.bottom ||
            update.left < 0 || update.top < 0) {
1600 1601 1602
            qxl_set_guest_bug(d,
                    "QXL_IO_UPDATE_AREA: invalid area (%ux%u)x(%ux%u)\n",
                    update.left, update.top, update.right, update.bottom);
1603 1604 1605 1606 1607
            if (update.left == update.right || update.top == update.bottom) {
                /* old drivers may provide empty area, keep going */
                qxl_clear_guest_bug(d);
                goto cancel_async;
            }
D
Dunrong Huang 已提交
1608 1609
            break;
        }
A
Alon Levy 已提交
1610 1611 1612 1613 1614
        if (async == QXL_ASYNC) {
            cookie = qxl_cookie_new(QXL_COOKIE_TYPE_IO,
                                    QXL_IO_UPDATE_AREA_ASYNC);
            cookie->u.area = update;
        }
G
Gerd Hoffmann 已提交
1615
        qxl_spice_update_area(d, d->ram->update_surface,
A
Alon Levy 已提交
1616 1617
                              cookie ? &cookie->u.area : &update,
                              NULL, 0, 0, async, cookie);
G
Gerd Hoffmann 已提交
1618 1619 1620
        break;
    }
    case QXL_IO_NOTIFY_CMD:
1621
        qemu_spice_wakeup(&d->ssd);
G
Gerd Hoffmann 已提交
1622 1623
        break;
    case QXL_IO_NOTIFY_CURSOR:
1624
        qemu_spice_wakeup(&d->ssd);
G
Gerd Hoffmann 已提交
1625 1626
        break;
    case QXL_IO_UPDATE_IRQ:
1627
        qxl_update_irq(d);
G
Gerd Hoffmann 已提交
1628 1629 1630 1631 1632 1633
        break;
    case QXL_IO_NOTIFY_OOM:
        if (!SPICE_RING_IS_EMPTY(&d->ram->release_ring)) {
            break;
        }
        d->oom_running = 1;
G
Gerd Hoffmann 已提交
1634
        qxl_spice_oom(d);
G
Gerd Hoffmann 已提交
1635 1636 1637 1638 1639 1640
        d->oom_running = 0;
        break;
    case QXL_IO_SET_MODE:
        qxl_set_mode(d, val, 0);
        break;
    case QXL_IO_LOG:
A
Alon Levy 已提交
1641
        trace_qxl_io_log(d->id, d->ram->log_buf);
G
Gerd Hoffmann 已提交
1642
        if (d->guestdebug) {
P
Peter Maydell 已提交
1643
            fprintf(stderr, "qxl/guest-%d: %" PRId64 ": %s", d->id,
1644
                    qemu_clock_get_ns(QEMU_CLOCK_VIRTUAL), d->ram->log_buf);
G
Gerd Hoffmann 已提交
1645 1646 1647 1648 1649 1650
        }
        break;
    case QXL_IO_RESET:
        qxl_hard_reset(d, 0);
        break;
    case QXL_IO_MEMSLOT_ADD:
1651
        if (val >= NUM_MEMSLOTS) {
1652
            qxl_set_guest_bug(d, "QXL_IO_MEMSLOT_ADD: val out of range");
1653 1654 1655
            break;
        }
        if (d->guest_slots[val].active) {
1656 1657
            qxl_set_guest_bug(d,
                        "QXL_IO_MEMSLOT_ADD: memory slot already active");
1658 1659
            break;
        }
G
Gerd Hoffmann 已提交
1660
        d->guest_slots[val].slot = d->ram->mem_slot;
1661
        qxl_add_memslot(d, val, 0, async);
G
Gerd Hoffmann 已提交
1662 1663
        break;
    case QXL_IO_MEMSLOT_DEL:
1664
        if (val >= NUM_MEMSLOTS) {
1665
            qxl_set_guest_bug(d, "QXL_IO_MEMSLOT_DEL: val out of range");
1666 1667
            break;
        }
G
Gerd Hoffmann 已提交
1668 1669 1670
        qxl_del_memslot(d, val);
        break;
    case QXL_IO_CREATE_PRIMARY:
1671
        if (val != 0) {
1672
            qxl_set_guest_bug(d, "QXL_IO_CREATE_PRIMARY (async=%d): val != 0",
1673 1674
                          async);
            goto cancel_async;
1675
        }
G
Gerd Hoffmann 已提交
1676
        d->guest_primary.surface = d->ram->create_surface;
1677
        qxl_create_guest_primary(d, 0, async);
G
Gerd Hoffmann 已提交
1678 1679
        break;
    case QXL_IO_DESTROY_PRIMARY:
1680
        if (val != 0) {
1681
            qxl_set_guest_bug(d, "QXL_IO_DESTROY_PRIMARY (async=%d): val != 0",
1682 1683 1684 1685
                          async);
            goto cancel_async;
        }
        if (!qxl_destroy_primary(d, async)) {
A
Alon Levy 已提交
1686 1687
            trace_qxl_io_destroy_primary_ignored(d->id,
                                                 qxl_mode_to_string(d->mode));
1688
            goto cancel_async;
1689
        }
G
Gerd Hoffmann 已提交
1690 1691
        break;
    case QXL_IO_DESTROY_SURFACE_WAIT:
1692
        if (val >= d->ssd.num_surfaces) {
1693
            qxl_set_guest_bug(d, "QXL_IO_DESTROY_SURFACE (async=%d):"
1694
                             "%" PRIu64 " >= NUM_SURFACES", async, val);
1695 1696 1697
            goto cancel_async;
        }
        qxl_spice_destroy_surface_wait(d, val, async);
G
Gerd Hoffmann 已提交
1698
        break;
1699 1700 1701 1702 1703 1704 1705 1706 1707 1708 1709 1710 1711
    case QXL_IO_FLUSH_RELEASE: {
        QXLReleaseRing *ring = &d->ram->release_ring;
        if (ring->prod - ring->cons + 1 == ring->num_items) {
            fprintf(stderr,
                "ERROR: no flush, full release ring [p%d,%dc]\n",
                ring->prod, ring->cons);
        }
        qxl_push_free_res(d, 1 /* flush */);
        break;
    }
    case QXL_IO_FLUSH_SURFACES_ASYNC:
        qxl_spice_flush_surfaces_async(d);
        break;
G
Gerd Hoffmann 已提交
1712
    case QXL_IO_DESTROY_ALL_SURFACES:
1713 1714
        d->mode = QXL_MODE_UNDEFINED;
        qxl_spice_destroy_surfaces(d, async);
G
Gerd Hoffmann 已提交
1715
        break;
1716 1717 1718
    case QXL_IO_MONITORS_CONFIG_ASYNC:
        qxl_spice_monitors_config_async(d, 0);
        break;
G
Gerd Hoffmann 已提交
1719
    default:
1720
        qxl_set_guest_bug(d, "%s: unexpected ioport=0x%x\n", __func__, io_port);
G
Gerd Hoffmann 已提交
1721
    }
1722 1723 1724 1725 1726 1727 1728 1729
    return;
cancel_async:
    if (async) {
        qxl_send_events(d, QXL_INTERRUPT_IO_CMD);
        qemu_mutex_lock(&d->async_lock);
        d->current_async = QXL_UNDEFINED_IO;
        qemu_mutex_unlock(&d->async_lock);
    }
G
Gerd Hoffmann 已提交
1730 1731
}

A
Avi Kivity 已提交
1732
static uint64_t ioport_read(void *opaque, hwaddr addr,
1733
                            unsigned size)
G
Gerd Hoffmann 已提交
1734
{
A
Alon Levy 已提交
1735
    PCIQXLDevice *qxl = opaque;
G
Gerd Hoffmann 已提交
1736

A
Alon Levy 已提交
1737
    trace_qxl_io_read_unexpected(qxl->id);
G
Gerd Hoffmann 已提交
1738 1739 1740
    return 0xff;
}

1741 1742 1743 1744 1745 1746 1747 1748
static const MemoryRegionOps qxl_io_ops = {
    .read = ioport_read,
    .write = ioport_write,
    .valid = {
        .min_access_size = 1,
        .max_access_size = 1,
    },
};
G
Gerd Hoffmann 已提交
1749

1750
static void qxl_update_irq_bh(void *opaque)
G
Gerd Hoffmann 已提交
1751 1752
{
    PCIQXLDevice *d = opaque;
1753
    qxl_update_irq(d);
G
Gerd Hoffmann 已提交
1754 1755 1756 1757 1758 1759 1760
}

static void qxl_send_events(PCIQXLDevice *d, uint32_t events)
{
    uint32_t old_pending;
    uint32_t le_events = cpu_to_le32(events);

A
Alon Levy 已提交
1761
    trace_qxl_send_events(d->id, events);
1762 1763 1764 1765 1766 1767 1768
    if (!qemu_spice_display_is_running(&d->ssd)) {
        /* spice-server tracks guest running state and should not do this */
        fprintf(stderr, "%s: spice-server bug: guest stopped, ignoring\n",
                __func__);
        trace_qxl_send_events_vm_stopped(d->id, events);
        return;
    }
1769
    old_pending = atomic_fetch_or(&d->ram->int_pending, le_events);
G
Gerd Hoffmann 已提交
1770 1771 1772
    if ((old_pending & le_events) == le_events) {
        return;
    }
1773
    qemu_bh_schedule(d->update_irq);
G
Gerd Hoffmann 已提交
1774 1775 1776 1777 1778 1779 1780 1781
}

/* graphics console */

static void qxl_hw_update(void *opaque)
{
    PCIQXLDevice *qxl = opaque;

1782
    qxl_render_update(qxl);
G
Gerd Hoffmann 已提交
1783 1784
}

1785 1786
static void qxl_dirty_surfaces(PCIQXLDevice *qxl)
{
1787
    uintptr_t vram_start;
1788 1789
    int i;

1790
    if (qxl->mode != QXL_MODE_NATIVE && qxl->mode != QXL_MODE_COMPAT) {
1791 1792 1793 1794 1795 1796 1797
        return;
    }

    /* dirty the primary surface */
    qxl_set_dirty(&qxl->vga.vram, qxl->shadow_rom.draw_area_offset,
                  qxl->shadow_rom.surface0_area_size);

1798
    vram_start = (uintptr_t)memory_region_get_ram_ptr(&qxl->vram_bar);
1799 1800

    /* dirty the off-screen surfaces */
1801
    for (i = 0; i < qxl->ssd.num_surfaces; i++) {
1802 1803 1804 1805 1806 1807 1808 1809 1810 1811
        QXLSurfaceCmd *cmd;
        intptr_t surface_offset;
        int surface_size;

        if (qxl->guest_surfaces.cmds[i] == 0) {
            continue;
        }

        cmd = qxl_phys2virt(qxl, qxl->guest_surfaces.cmds[i],
                            MEMSLOT_GROUP_GUEST);
1812
        assert(cmd);
1813 1814 1815 1816
        assert(cmd->type == QXL_SURFACE_CMD_CREATE);
        surface_offset = (intptr_t)qxl_phys2virt(qxl,
                                                 cmd->u.surface_create.data,
                                                 MEMSLOT_GROUP_GUEST);
1817
        assert(surface_offset);
1818 1819 1820
        surface_offset -= vram_start;
        surface_size = cmd->u.surface_create.height *
                       abs(cmd->u.surface_create.stride);
A
Alon Levy 已提交
1821
        trace_qxl_surfaces_dirty(qxl->id, i, (int)surface_offset, surface_size);
1822 1823 1824 1825
        qxl_set_dirty(&qxl->vram_bar, surface_offset, surface_size);
    }
}

1826 1827
static void qxl_vm_change_state_handler(void *opaque, int running,
                                        RunState state)
G
Gerd Hoffmann 已提交
1828 1829 1830
{
    PCIQXLDevice *qxl = opaque;

1831 1832 1833
    if (running) {
        /*
         * if qxl_send_events was called from spice server context before
1834
         * migration ended, qxl_update_irq for these events might not have been
1835 1836
         * called
         */
1837
         qxl_update_irq(qxl);
1838 1839 1840
    } else {
        /* make sure surfaces are saved before migration */
        qxl_dirty_surfaces(qxl);
G
Gerd Hoffmann 已提交
1841 1842 1843 1844 1845
    }
}

/* display change listener */

1846 1847
static void display_update(DisplayChangeListener *dcl,
                           int x, int y, int w, int h)
G
Gerd Hoffmann 已提交
1848
{
G
Gerd Hoffmann 已提交
1849 1850 1851 1852
    PCIQXLDevice *qxl = container_of(dcl, PCIQXLDevice, ssd.dcl);

    if (qxl->mode == QXL_MODE_VGA) {
        qemu_spice_display_update(&qxl->ssd, x, y, w, h);
G
Gerd Hoffmann 已提交
1853 1854 1855
    }
}

1856 1857
static void display_switch(DisplayChangeListener *dcl,
                           struct DisplaySurface *surface)
G
Gerd Hoffmann 已提交
1858
{
G
Gerd Hoffmann 已提交
1859 1860
    PCIQXLDevice *qxl = container_of(dcl, PCIQXLDevice, ssd.dcl);

G
Gerd Hoffmann 已提交
1861
    qxl->ssd.ds = surface;
G
Gerd Hoffmann 已提交
1862
    if (qxl->mode == QXL_MODE_VGA) {
1863
        qemu_spice_display_switch(&qxl->ssd, surface);
G
Gerd Hoffmann 已提交
1864 1865 1866
    }
}

1867
static void display_refresh(DisplayChangeListener *dcl)
G
Gerd Hoffmann 已提交
1868
{
G
Gerd Hoffmann 已提交
1869 1870 1871 1872
    PCIQXLDevice *qxl = container_of(dcl, PCIQXLDevice, ssd.dcl);

    if (qxl->mode == QXL_MODE_VGA) {
        qemu_spice_display_refresh(&qxl->ssd);
G
Gerd Hoffmann 已提交
1873 1874 1875
    }
}

1876 1877
static DisplayChangeListenerOps display_listener_ops = {
    .dpy_name        = "spice/qxl",
1878
    .dpy_gfx_update  = display_update,
1879
    .dpy_gfx_switch  = display_switch,
1880
    .dpy_refresh     = display_refresh,
G
Gerd Hoffmann 已提交
1881 1882
};

1883
static void qxl_init_ramsize(PCIQXLDevice *qxl)
1884
{
1885 1886 1887 1888
    /* vga mode framebuffer / primary surface (bar 0, first part) */
    if (qxl->vgamem_size_mb < 8) {
        qxl->vgamem_size_mb = 8;
    }
1889 1890 1891 1892 1893 1894
    /* XXX: we round vgamem_size_mb up to a nearest power of two and it must be
     * less than vga_common_init()'s maximum on qxl->vga.vram_size (512 now).
     */
    if (qxl->vgamem_size_mb > 256) {
        qxl->vgamem_size_mb = 256;
    }
1895 1896 1897
    qxl->vgamem_size = qxl->vgamem_size_mb * 1024 * 1024;

    /* vga ram (bar 0, total) */
1898 1899 1900
    if (qxl->ram_size_mb != -1) {
        qxl->vga.vram_size = qxl->ram_size_mb * 1024 * 1024;
    }
1901 1902
    if (qxl->vga.vram_size < qxl->vgamem_size * 2) {
        qxl->vga.vram_size = qxl->vgamem_size * 2;
1903 1904
    }

G
Gerd Hoffmann 已提交
1905 1906 1907 1908 1909 1910 1911 1912 1913
    /* vram32 (surfaces, 32bit, bar 1) */
    if (qxl->vram32_size_mb != -1) {
        qxl->vram32_size = qxl->vram32_size_mb * 1024 * 1024;
    }
    if (qxl->vram32_size < 4096) {
        qxl->vram32_size = 4096;
    }

    /* vram (surfaces, 64bit, bar 4+5) */
1914 1915 1916
    if (qxl->vram_size_mb != -1) {
        qxl->vram_size = qxl->vram_size_mb * 1024 * 1024;
    }
G
Gerd Hoffmann 已提交
1917 1918
    if (qxl->vram_size < qxl->vram32_size) {
        qxl->vram_size = qxl->vram32_size;
1919
    }
G
Gerd Hoffmann 已提交
1920

1921
    if (qxl->revision == 1) {
G
Gerd Hoffmann 已提交
1922
        qxl->vram32_size = 4096;
1923 1924
        qxl->vram_size = 4096;
    }
1925 1926 1927 1928
    qxl->vgamem_size = pow2ceil(qxl->vgamem_size);
    qxl->vga.vram_size = pow2ceil(qxl->vga.vram_size);
    qxl->vram32_size = pow2ceil(qxl->vram32_size);
    qxl->vram_size = pow2ceil(qxl->vram_size);
1929 1930
}

M
Markus Armbruster 已提交
1931
static void qxl_realize_common(PCIQXLDevice *qxl, Error **errp)
G
Gerd Hoffmann 已提交
1932 1933 1934 1935 1936 1937 1938 1939
{
    uint8_t* config = qxl->pci.config;
    uint32_t pci_device_rev;
    uint32_t io_size;

    qxl->mode = QXL_MODE_UNDEFINED;
    qxl->generation = 1;
    qxl->num_memslots = NUM_MEMSLOTS;
1940
    qemu_mutex_init(&qxl->track_lock);
1941 1942
    qemu_mutex_init(&qxl->async_lock);
    qxl->current_async = QXL_UNDEFINED_IO;
1943
    qxl->guest_bug = 0;
G
Gerd Hoffmann 已提交
1944 1945 1946 1947

    switch (qxl->revision) {
    case 1: /* spice 0.4 -- qxl-1 */
        pci_device_rev = QXL_REVISION_STABLE_V04;
1948
        io_size = 8;
G
Gerd Hoffmann 已提交
1949 1950 1951
        break;
    case 2: /* spice 0.6 -- qxl-2 */
        pci_device_rev = QXL_REVISION_STABLE_V06;
1952
        io_size = 16;
G
Gerd Hoffmann 已提交
1953
        break;
G
Gerd Hoffmann 已提交
1954
    case 3: /* qxl-3 */
1955 1956 1957 1958 1959
        pci_device_rev = QXL_REVISION_STABLE_V10;
        io_size = 32; /* PCI region size must be pow2 */
        break;
    case 4: /* qxl-4 */
        pci_device_rev = QXL_REVISION_STABLE_V12;
1960
        io_size = pow2ceil(QXL_IO_RANGE_SIZE);
G
Gerd Hoffmann 已提交
1961
        break;
A
Alon Levy 已提交
1962
    default:
M
Markus Armbruster 已提交
1963 1964 1965
        error_setg(errp, "Invalid revision %d for qxl device (max %d)",
                   qxl->revision, QXL_DEFAULT_REVISION);
        return;
G
Gerd Hoffmann 已提交
1966 1967 1968 1969 1970 1971
    }

    pci_set_byte(&config[PCI_REVISION_ID], pci_device_rev);
    pci_set_byte(&config[PCI_INTERRUPT_PIN], 1);

    qxl->rom_size = qxl_rom_size();
1972
    memory_region_init_ram(&qxl->rom_bar, OBJECT(qxl), "qxl.vrom",
1973
                           qxl->rom_size, &error_fatal);
1974
    vmstate_register_ram(&qxl->rom_bar, &qxl->pci.qdev);
G
Gerd Hoffmann 已提交
1975 1976 1977
    init_qxl_rom(qxl);
    init_qxl_ram(qxl);

1978
    qxl->guest_surfaces.cmds = g_new0(QXLPHYSICAL, qxl->ssd.num_surfaces);
1979
    memory_region_init_ram(&qxl->vram_bar, OBJECT(qxl), "qxl.vram",
1980
                           qxl->vram_size, &error_fatal);
1981
    vmstate_register_ram(&qxl->vram_bar, &qxl->pci.qdev);
1982 1983
    memory_region_init_alias(&qxl->vram32_bar, OBJECT(qxl), "qxl.vram32",
                             &qxl->vram_bar, 0, qxl->vram32_size);
G
Gerd Hoffmann 已提交
1984

1985
    memory_region_init_io(&qxl->io_bar, OBJECT(qxl), &qxl_io_ops, qxl,
1986 1987 1988 1989
                          "qxl-ioports", io_size);
    if (qxl->id == 0) {
        vga_dirty_log_start(&qxl->vga);
    }
1990
    memory_region_set_flush_coalesced(&qxl->io_bar);
1991 1992


1993 1994
    pci_register_bar(&qxl->pci, QXL_IO_RANGE_INDEX,
                     PCI_BASE_ADDRESS_SPACE_IO, &qxl->io_bar);
G
Gerd Hoffmann 已提交
1995

1996 1997
    pci_register_bar(&qxl->pci, QXL_ROM_RANGE_INDEX,
                     PCI_BASE_ADDRESS_SPACE_MEMORY, &qxl->rom_bar);
G
Gerd Hoffmann 已提交
1998

1999 2000
    pci_register_bar(&qxl->pci, QXL_RAM_RANGE_INDEX,
                     PCI_BASE_ADDRESS_SPACE_MEMORY, &qxl->vga.vram);
G
Gerd Hoffmann 已提交
2001

2002
    pci_register_bar(&qxl->pci, QXL_VRAM_RANGE_INDEX,
G
Gerd Hoffmann 已提交
2003 2004 2005 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024 2025
                     PCI_BASE_ADDRESS_SPACE_MEMORY, &qxl->vram32_bar);

    if (qxl->vram32_size < qxl->vram_size) {
        /*
         * Make the 64bit vram bar show up only in case it is
         * configured to be larger than the 32bit vram bar.
         */
        pci_register_bar(&qxl->pci, QXL_VRAM64_RANGE_INDEX,
                         PCI_BASE_ADDRESS_SPACE_MEMORY |
                         PCI_BASE_ADDRESS_MEM_TYPE_64 |
                         PCI_BASE_ADDRESS_MEM_PREFETCH,
                         &qxl->vram_bar);
    }

    /* print pci bar details */
    dprint(qxl, 1, "ram/%s: %d MB [region 0]\n",
           qxl->id == 0 ? "pri" : "sec",
           qxl->vga.vram_size / (1024*1024));
    dprint(qxl, 1, "vram/32: %d MB [region 1]\n",
           qxl->vram32_size / (1024*1024));
    dprint(qxl, 1, "vram/64: %d MB %s\n",
           qxl->vram_size / (1024*1024),
           qxl->vram32_size < qxl->vram_size ? "[region 4]" : "[unmapped]");
G
Gerd Hoffmann 已提交
2026 2027

    qxl->ssd.qxl.base.sif = &qxl_interface.base;
G
Gerd Hoffmann 已提交
2028
    if (qemu_spice_add_display_interface(&qxl->ssd.qxl, qxl->vga.con) != 0) {
M
Markus Armbruster 已提交
2029 2030 2031
        error_setg(errp, "qxl interface %d.%d not supported by spice-server",
                   SPICE_INTERFACE_QXL_MAJOR, SPICE_INTERFACE_QXL_MINOR);
        return;
2032
    }
G
Gerd Hoffmann 已提交
2033 2034
    qemu_add_vm_change_state_handler(qxl_vm_change_state_handler, qxl);

2035
    qxl->update_irq = qemu_bh_new(qxl_update_irq_bh, qxl);
G
Gerd Hoffmann 已提交
2036 2037
    qxl_reset_state(qxl);

A
Alon Levy 已提交
2038
    qxl->update_area_bh = qemu_bh_new(qxl_render_update_area_bh, qxl);
2039
    qxl->ssd.cursor_bh = qemu_bh_new(qemu_spice_cursor_refresh_bh, &qxl->ssd);
G
Gerd Hoffmann 已提交
2040 2041
}

M
Markus Armbruster 已提交
2042
static void qxl_realize_primary(PCIDevice *dev, Error **errp)
G
Gerd Hoffmann 已提交
2043
{
G
Gonglei 已提交
2044
    PCIQXLDevice *qxl = PCI_QXL(dev);
G
Gerd Hoffmann 已提交
2045
    VGACommonState *vga = &qxl->vga;
M
Markus Armbruster 已提交
2046
    Error *local_err = NULL;
G
Gerd Hoffmann 已提交
2047 2048

    qxl->id = 0;
2049
    qxl_init_ramsize(qxl);
2050
    vga->vbe_size = qxl->vgamem_size;
G
Gerd Hoffmann 已提交
2051
    vga->vram_size_mb = qxl->vga.vram_size >> 20;
G
Gerd Hoffmann 已提交
2052
    vga_common_init(vga, OBJECT(dev), true);
P
Paolo Bonzini 已提交
2053 2054
    vga_init(vga, OBJECT(dev),
             pci_address_space(dev), pci_address_space_io(dev), false);
2055
    portio_list_init(&qxl->vga_port_list, OBJECT(dev), qxl_vga_portio_list,
2056
                     vga, "vga");
2057 2058
    portio_list_set_flush_coalesced(&qxl->vga_port_list);
    portio_list_add(&qxl->vga_port_list, pci_address_space_io(dev), 0x3b0);
G
Gerd Hoffmann 已提交
2059

2060
    vga->con = graphic_console_init(DEVICE(dev), 0, &qxl_ops, qxl);
2061
    qemu_spice_display_init_common(&qxl->ssd);
G
Gerd Hoffmann 已提交
2062

M
Markus Armbruster 已提交
2063 2064 2065 2066
    qxl_realize_common(qxl, &local_err);
    if (local_err) {
        error_propagate(errp, local_err);
        return;
G
Gerd Hoffmann 已提交
2067 2068
    }

2069
    qxl->ssd.dcl.ops = &display_listener_ops;
2070
    qxl->ssd.dcl.con = vga->con;
2071
    register_displaychangelistener(&qxl->ssd.dcl);
G
Gerd Hoffmann 已提交
2072 2073
}

M
Markus Armbruster 已提交
2074
static void qxl_realize_secondary(PCIDevice *dev, Error **errp)
G
Gerd Hoffmann 已提交
2075 2076
{
    static int device_id = 1;
G
Gonglei 已提交
2077
    PCIQXLDevice *qxl = PCI_QXL(dev);
G
Gerd Hoffmann 已提交
2078 2079

    qxl->id = device_id++;
2080
    qxl_init_ramsize(qxl);
2081
    memory_region_init_ram(&qxl->vga.vram, OBJECT(dev), "qxl.vgavram",
2082
                           qxl->vga.vram_size, &error_fatal);
2083
    vmstate_register_ram(&qxl->vga.vram, &qxl->pci.qdev);
2084
    qxl->vga.vram_ptr = memory_region_get_ram_ptr(&qxl->vga.vram);
2085
    qxl->vga.con = graphic_console_init(DEVICE(dev), 0, &qxl_ops, qxl);
G
Gerd Hoffmann 已提交
2086

M
Markus Armbruster 已提交
2087
    qxl_realize_common(qxl, errp);
G
Gerd Hoffmann 已提交
2088 2089 2090 2091 2092 2093 2094
}

static void qxl_pre_save(void *opaque)
{
    PCIQXLDevice* d = opaque;
    uint8_t *ram_start = d->vga.vram_ptr;

A
Alon Levy 已提交
2095
    trace_qxl_pre_save(d->id);
G
Gerd Hoffmann 已提交
2096 2097 2098 2099 2100 2101 2102 2103 2104 2105 2106 2107
    if (d->last_release == NULL) {
        d->last_release_offset = 0;
    } else {
        d->last_release_offset = (uint8_t *)d->last_release - ram_start;
    }
    assert(d->last_release_offset < d->vga.vram_size);
}

static int qxl_pre_load(void *opaque)
{
    PCIQXLDevice* d = opaque;

A
Alon Levy 已提交
2108
    trace_qxl_pre_load(d->id);
G
Gerd Hoffmann 已提交
2109 2110 2111 2112 2113
    qxl_hard_reset(d, 1);
    qxl_exit_vga_mode(d);
    return 0;
}

2114 2115 2116 2117 2118 2119 2120 2121 2122 2123 2124 2125
static void qxl_create_memslots(PCIQXLDevice *d)
{
    int i;

    for (i = 0; i < NUM_MEMSLOTS; i++) {
        if (!d->guest_slots[i].active) {
            continue;
        }
        qxl_add_memslot(d, i, 0, QXL_SYNC);
    }
}

G
Gerd Hoffmann 已提交
2126 2127 2128 2129 2130
static int qxl_post_load(void *opaque, int version)
{
    PCIQXLDevice* d = opaque;
    uint8_t *ram_start = d->vga.vram_ptr;
    QXLCommandExt *cmds;
2131
    int in, out, newmode;
G
Gerd Hoffmann 已提交
2132 2133 2134 2135 2136 2137 2138 2139 2140 2141

    assert(d->last_release_offset < d->vga.vram_size);
    if (d->last_release_offset == 0) {
        d->last_release = NULL;
    } else {
        d->last_release = (QXLReleaseInfo *)(ram_start + d->last_release_offset);
    }

    d->modes = (QXLModes*)((uint8_t*)d->rom + d->rom->modes_offset);

A
Alon Levy 已提交
2142
    trace_qxl_post_load(d->id, qxl_mode_to_string(d->mode));
G
Gerd Hoffmann 已提交
2143 2144
    newmode = d->mode;
    d->mode = QXL_MODE_UNDEFINED;
2145

G
Gerd Hoffmann 已提交
2146 2147
    switch (newmode) {
    case QXL_MODE_UNDEFINED:
2148
        qxl_create_memslots(d);
G
Gerd Hoffmann 已提交
2149 2150
        break;
    case QXL_MODE_VGA:
2151
        qxl_create_memslots(d);
G
Gerd Hoffmann 已提交
2152 2153 2154
        qxl_enter_vga_mode(d);
        break;
    case QXL_MODE_NATIVE:
2155
        qxl_create_memslots(d);
2156
        qxl_create_guest_primary(d, 1, QXL_SYNC);
G
Gerd Hoffmann 已提交
2157 2158

        /* replay surface-create and cursor-set commands */
2159
        cmds = g_new0(QXLCommandExt, d->ssd.num_surfaces + 1);
2160
        for (in = 0, out = 0; in < d->ssd.num_surfaces; in++) {
G
Gerd Hoffmann 已提交
2161 2162 2163 2164 2165 2166 2167 2168
            if (d->guest_surfaces.cmds[in] == 0) {
                continue;
            }
            cmds[out].cmd.data = d->guest_surfaces.cmds[in];
            cmds[out].cmd.type = QXL_CMD_SURFACE;
            cmds[out].group_id = MEMSLOT_GROUP_GUEST;
            out++;
        }
Y
Yonit Halperin 已提交
2169 2170 2171 2172 2173 2174
        if (d->guest_cursor) {
            cmds[out].cmd.data = d->guest_cursor;
            cmds[out].cmd.type = QXL_CMD_CURSOR;
            cmds[out].group_id = MEMSLOT_GROUP_GUEST;
            out++;
        }
G
Gerd Hoffmann 已提交
2175
        qxl_spice_loadvm_commands(d, cmds, out);
2176
        g_free(cmds);
2177 2178 2179
        if (d->guest_monitors_config) {
            qxl_spice_monitors_config_async(d, 1);
        }
G
Gerd Hoffmann 已提交
2180 2181
        break;
    case QXL_MODE_COMPAT:
2182 2183
        /* note: no need to call qxl_create_memslots, qxl_set_mode
         * creates the mem slot. */
G
Gerd Hoffmann 已提交
2184 2185 2186 2187 2188 2189
        qxl_set_mode(d, d->shadow_rom.mode, 1);
        break;
    }
    return 0;
}

2190
#define QXL_SAVE_VERSION 21
G
Gerd Hoffmann 已提交
2191

2192 2193 2194 2195 2196 2197 2198 2199
static bool qxl_monitors_config_needed(void *opaque)
{
    PCIQXLDevice *qxl = opaque;

    return qxl->guest_monitors_config != 0;
}


G
Gerd Hoffmann 已提交
2200 2201 2202 2203 2204 2205 2206 2207 2208 2209 2210 2211 2212 2213 2214 2215 2216 2217 2218 2219 2220 2221 2222 2223 2224 2225 2226 2227 2228 2229
static VMStateDescription qxl_memslot = {
    .name               = "qxl-memslot",
    .version_id         = QXL_SAVE_VERSION,
    .minimum_version_id = QXL_SAVE_VERSION,
    .fields = (VMStateField[]) {
        VMSTATE_UINT64(slot.mem_start, struct guest_slots),
        VMSTATE_UINT64(slot.mem_end,   struct guest_slots),
        VMSTATE_UINT32(active,         struct guest_slots),
        VMSTATE_END_OF_LIST()
    }
};

static VMStateDescription qxl_surface = {
    .name               = "qxl-surface",
    .version_id         = QXL_SAVE_VERSION,
    .minimum_version_id = QXL_SAVE_VERSION,
    .fields = (VMStateField[]) {
        VMSTATE_UINT32(width,      QXLSurfaceCreate),
        VMSTATE_UINT32(height,     QXLSurfaceCreate),
        VMSTATE_INT32(stride,      QXLSurfaceCreate),
        VMSTATE_UINT32(format,     QXLSurfaceCreate),
        VMSTATE_UINT32(position,   QXLSurfaceCreate),
        VMSTATE_UINT32(mouse_mode, QXLSurfaceCreate),
        VMSTATE_UINT32(flags,      QXLSurfaceCreate),
        VMSTATE_UINT32(type,       QXLSurfaceCreate),
        VMSTATE_UINT64(mem,        QXLSurfaceCreate),
        VMSTATE_END_OF_LIST()
    }
};

2230 2231 2232 2233
static VMStateDescription qxl_vmstate_monitors_config = {
    .name               = "qxl/monitors-config",
    .version_id         = 1,
    .minimum_version_id = 1,
2234
    .needed = qxl_monitors_config_needed,
2235 2236 2237 2238 2239 2240
    .fields = (VMStateField[]) {
        VMSTATE_UINT64(guest_monitors_config, PCIQXLDevice),
        VMSTATE_END_OF_LIST()
    },
};

G
Gerd Hoffmann 已提交
2241 2242 2243 2244 2245 2246 2247
static VMStateDescription qxl_vmstate = {
    .name               = "qxl",
    .version_id         = QXL_SAVE_VERSION,
    .minimum_version_id = QXL_SAVE_VERSION,
    .pre_save           = qxl_pre_save,
    .pre_load           = qxl_pre_load,
    .post_load          = qxl_post_load,
2248
    .fields = (VMStateField[]) {
G
Gerd Hoffmann 已提交
2249 2250 2251 2252 2253 2254 2255
        VMSTATE_PCI_DEVICE(pci, PCIQXLDevice),
        VMSTATE_STRUCT(vga, PCIQXLDevice, 0, vmstate_vga_common, VGACommonState),
        VMSTATE_UINT32(shadow_rom.mode, PCIQXLDevice),
        VMSTATE_UINT32(num_free_res, PCIQXLDevice),
        VMSTATE_UINT32(last_release_offset, PCIQXLDevice),
        VMSTATE_UINT32(mode, PCIQXLDevice),
        VMSTATE_UINT32(ssd.unique, PCIQXLDevice),
2256 2257 2258 2259 2260
        VMSTATE_INT32_EQUAL(num_memslots, PCIQXLDevice),
        VMSTATE_STRUCT_ARRAY(guest_slots, PCIQXLDevice, NUM_MEMSLOTS, 0,
                             qxl_memslot, struct guest_slots),
        VMSTATE_STRUCT(guest_primary.surface, PCIQXLDevice, 0,
                       qxl_surface, QXLSurfaceCreate),
2261 2262 2263 2264
        VMSTATE_INT32_EQUAL(ssd.num_surfaces, PCIQXLDevice),
        VMSTATE_VARRAY_INT32(guest_surfaces.cmds, PCIQXLDevice,
                             ssd.num_surfaces, 0,
                             vmstate_info_uint64, uint64_t),
2265
        VMSTATE_UINT64(guest_cursor, PCIQXLDevice),
G
Gerd Hoffmann 已提交
2266 2267
        VMSTATE_END_OF_LIST()
    },
2268 2269 2270
    .subsections = (const VMStateDescription*[]) {
        &qxl_vmstate_monitors_config,
        NULL
2271
    }
G
Gerd Hoffmann 已提交
2272 2273
};

G
Gerd Hoffmann 已提交
2274 2275 2276
static Property qxl_properties[] = {
        DEFINE_PROP_UINT32("ram_size", PCIQXLDevice, vga.vram_size,
                           64 * 1024 * 1024),
G
Gerd Hoffmann 已提交
2277
        DEFINE_PROP_UINT32("vram_size", PCIQXLDevice, vram32_size,
G
Gerd Hoffmann 已提交
2278 2279 2280 2281 2282 2283
                           64 * 1024 * 1024),
        DEFINE_PROP_UINT32("revision", PCIQXLDevice, revision,
                           QXL_DEFAULT_REVISION),
        DEFINE_PROP_UINT32("debug", PCIQXLDevice, debug, 0),
        DEFINE_PROP_UINT32("guestdebug", PCIQXLDevice, guestdebug, 0),
        DEFINE_PROP_UINT32("cmdlog", PCIQXLDevice, cmdlog, 0),
2284
        DEFINE_PROP_UINT32("ram_size_mb",  PCIQXLDevice, ram_size_mb, -1),
2285 2286
        DEFINE_PROP_UINT32("vram_size_mb", PCIQXLDevice, vram32_size_mb, -1),
        DEFINE_PROP_UINT32("vram64_size_mb", PCIQXLDevice, vram_size_mb, -1),
G
Gerd Hoffmann 已提交
2287
        DEFINE_PROP_UINT32("vgamem_mb", PCIQXLDevice, vgamem_size_mb, 16),
2288
        DEFINE_PROP_INT32("surfaces", PCIQXLDevice, ssd.num_surfaces, 1024),
2289 2290 2291
#if SPICE_SERVER_VERSION >= 0x000c06 /* release 0.12.6 */
        DEFINE_PROP_UINT16("max_outputs", PCIQXLDevice, max_outputs, 0),
#endif
G
Gerd Hoffmann 已提交
2292 2293 2294
        DEFINE_PROP_END_OF_LIST(),
};

G
Gonglei 已提交
2295
static void qxl_pci_class_init(ObjectClass *klass, void *data)
2296
{
2297
    DeviceClass *dc = DEVICE_CLASS(klass);
2298 2299 2300 2301
    PCIDeviceClass *k = PCI_DEVICE_CLASS(klass);

    k->vendor_id = REDHAT_PCI_VENDOR_ID;
    k->device_id = QXL_DEVICE_ID_STABLE;
2302
    set_bit(DEVICE_CATEGORY_DISPLAY, dc->categories);
2303 2304 2305
    dc->reset = qxl_reset_handler;
    dc->vmsd = &qxl_vmstate;
    dc->props = qxl_properties;
G
Gonglei 已提交
2306 2307 2308 2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322 2323 2324
}

static const TypeInfo qxl_pci_type_info = {
    .name = TYPE_PCI_QXL,
    .parent = TYPE_PCI_DEVICE,
    .instance_size = sizeof(PCIQXLDevice),
    .abstract = true,
    .class_init = qxl_pci_class_init,
};

static void qxl_primary_class_init(ObjectClass *klass, void *data)
{
    DeviceClass *dc = DEVICE_CLASS(klass);
    PCIDeviceClass *k = PCI_DEVICE_CLASS(klass);

    k->realize = qxl_realize_primary;
    k->romfile = "vgabios-qxl.bin";
    k->class_id = PCI_CLASS_DISPLAY_VGA;
    dc->desc = "Spice QXL GPU (primary, vga compatible)";
2325
    dc->hotpluggable = false;
2326 2327
}

2328
static const TypeInfo qxl_primary_info = {
2329
    .name          = "qxl-vga",
G
Gonglei 已提交
2330
    .parent        = TYPE_PCI_QXL,
2331
    .class_init    = qxl_primary_class_init,
G
Gerd Hoffmann 已提交
2332 2333
};

2334 2335
static void qxl_secondary_class_init(ObjectClass *klass, void *data)
{
2336
    DeviceClass *dc = DEVICE_CLASS(klass);
2337 2338
    PCIDeviceClass *k = PCI_DEVICE_CLASS(klass);

M
Markus Armbruster 已提交
2339
    k->realize = qxl_realize_secondary;
2340
    k->class_id = PCI_CLASS_DISPLAY_OTHER;
2341
    dc->desc = "Spice QXL GPU (secondary)";
2342 2343
}

2344
static const TypeInfo qxl_secondary_info = {
2345
    .name          = "qxl",
G
Gonglei 已提交
2346
    .parent        = TYPE_PCI_QXL,
2347
    .class_init    = qxl_secondary_class_init,
G
Gerd Hoffmann 已提交
2348 2349
};

A
Andreas Färber 已提交
2350
static void qxl_register_types(void)
G
Gerd Hoffmann 已提交
2351
{
G
Gonglei 已提交
2352
    type_register_static(&qxl_pci_type_info);
2353 2354
    type_register_static(&qxl_primary_info);
    type_register_static(&qxl_secondary_info);
G
Gerd Hoffmann 已提交
2355 2356
}

A
Andreas Färber 已提交
2357
type_init(qxl_register_types)