hcd-ehci.c 69.9 KB
Newer Older
G
Gerd Hoffmann 已提交
1 2 3 4
/*
 * QEMU USB EHCI Emulation
 *
 * Copyright(c) 2008  Emutex Ltd. (address@hidden)
5 6 7 8 9
 * Copyright(c) 2011-2012 Red Hat, Inc.
 *
 * Red Hat Authors:
 * Gerd Hoffmann <kraxel@redhat.com>
 * Hans de Goede <hdegoede@redhat.com>
G
Gerd Hoffmann 已提交
10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
 *
 * EHCI project was started by Mark Burkley, with contributions by
 * Niels de Vos.  David S. Ahern continued working on it.  Kevin Wolf,
 * Jan Kiszka and Vincent Palatin contributed bugfixes.
 *
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2 of the License, or(at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, see <http://www.gnu.org/licenses/>.
 */

30
#include "hw/usb/hcd-ehci.h"
G
Gerd Hoffmann 已提交
31 32 33 34 35

/* internal processing - reset HC to try and recover */
#define USB_RET_PROCERR   (-99)

/* Capability Registers Base Address - section 2.2 */
36 37 38 39
#define CAPLENGTH        0x0000  /* 1-byte, 0x0001 reserved */
#define HCIVERSION       0x0002  /* 2-bytes, i/f version # */
#define HCSPARAMS        0x0004  /* 4-bytes, structural params */
#define HCCPARAMS        0x0008  /* 4-bytes, capability params */
G
Gerd Hoffmann 已提交
40
#define EECP             HCCPARAMS + 1
41 42
#define HCSPPORTROUTE1   0x000c
#define HCSPPORTROUTE2   0x0010
G
Gerd Hoffmann 已提交
43

44
#define USBCMD           0x0000
G
Gerd Hoffmann 已提交
45 46 47 48 49 50 51 52 53 54 55 56 57
#define USBCMD_RUNSTOP   (1 << 0)      // run / Stop
#define USBCMD_HCRESET   (1 << 1)      // HC Reset
#define USBCMD_FLS       (3 << 2)      // Frame List Size
#define USBCMD_FLS_SH    2             // Frame List Size Shift
#define USBCMD_PSE       (1 << 4)      // Periodic Schedule Enable
#define USBCMD_ASE       (1 << 5)      // Asynch Schedule Enable
#define USBCMD_IAAD      (1 << 6)      // Int Asynch Advance Doorbell
#define USBCMD_LHCR      (1 << 7)      // Light Host Controller Reset
#define USBCMD_ASPMC     (3 << 8)      // Async Sched Park Mode Count
#define USBCMD_ASPME     (1 << 11)     // Async Sched Park Mode Enable
#define USBCMD_ITC       (0x7f << 16)  // Int Threshold Control
#define USBCMD_ITC_SH    16            // Int Threshold Control Shift

58
#define USBSTS           0x0004
G
Gerd Hoffmann 已提交
59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74
#define USBSTS_RO_MASK   0x0000003f
#define USBSTS_INT       (1 << 0)      // USB Interrupt
#define USBSTS_ERRINT    (1 << 1)      // Error Interrupt
#define USBSTS_PCD       (1 << 2)      // Port Change Detect
#define USBSTS_FLR       (1 << 3)      // Frame List Rollover
#define USBSTS_HSE       (1 << 4)      // Host System Error
#define USBSTS_IAA       (1 << 5)      // Interrupt on Async Advance
#define USBSTS_HALT      (1 << 12)     // HC Halted
#define USBSTS_REC       (1 << 13)     // Reclamation
#define USBSTS_PSS       (1 << 14)     // Periodic Schedule Status
#define USBSTS_ASS       (1 << 15)     // Asynchronous Schedule Status

/*
 *  Interrupt enable bits correspond to the interrupt active bits in USBSTS
 *  so no need to redefine here.
 */
75
#define USBINTR              0x0008
G
Gerd Hoffmann 已提交
76 77
#define USBINTR_MASK         0x0000003f

78 79 80 81
#define FRINDEX              0x000c
#define CTRLDSSEGMENT        0x0010
#define PERIODICLISTBASE     0x0014
#define ASYNCLISTADDR        0x0018
G
Gerd Hoffmann 已提交
82 83
#define ASYNCLISTADDR_MASK   0xffffffe0

84
#define CONFIGFLAG           0x0040
G
Gerd Hoffmann 已提交
85 86

/*
87
 * Bits that are reserved or are read-only are masked out of values
G
Gerd Hoffmann 已提交
88 89
 * written to us by software
 */
90
#define PORTSC_RO_MASK       0x007001c0
G
Gerd Hoffmann 已提交
91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113
#define PORTSC_RWC_MASK      0x0000002a
#define PORTSC_WKOC_E        (1 << 22)    // Wake on Over Current Enable
#define PORTSC_WKDS_E        (1 << 21)    // Wake on Disconnect Enable
#define PORTSC_WKCN_E        (1 << 20)    // Wake on Connect Enable
#define PORTSC_PTC           (15 << 16)   // Port Test Control
#define PORTSC_PTC_SH        16           // Port Test Control shift
#define PORTSC_PIC           (3 << 14)    // Port Indicator Control
#define PORTSC_PIC_SH        14           // Port Indicator Control Shift
#define PORTSC_POWNER        (1 << 13)    // Port Owner
#define PORTSC_PPOWER        (1 << 12)    // Port Power
#define PORTSC_LINESTAT      (3 << 10)    // Port Line Status
#define PORTSC_LINESTAT_SH   10           // Port Line Status Shift
#define PORTSC_PRESET        (1 << 8)     // Port Reset
#define PORTSC_SUSPEND       (1 << 7)     // Port Suspend
#define PORTSC_FPRES         (1 << 6)     // Force Port Resume
#define PORTSC_OCC           (1 << 5)     // Over Current Change
#define PORTSC_OCA           (1 << 4)     // Over Current Active
#define PORTSC_PEDC          (1 << 3)     // Port Enable/Disable Change
#define PORTSC_PED           (1 << 2)     // Port Enable/Disable
#define PORTSC_CSC           (1 << 1)     // Connect Status Change
#define PORTSC_CONNECT       (1 << 0)     // Current Connect Status

#define FRAME_TIMER_FREQ 1000
G
Gerd Hoffmann 已提交
114
#define FRAME_TIMER_NS   (1000000000 / FRAME_TIMER_FREQ)
G
Gerd Hoffmann 已提交
115 116 117 118

#define NB_MAXINTRATE    8        // Max rate at which controller issues ints
#define BUFF_SIZE        5*4096   // Max bytes to transfer per transaction
#define MAX_QH           100      // Max allowable queue heads in a chain
119
#define MIN_FR_PER_TICK  3        // Min frames to process when catching up
G
Gerd Hoffmann 已提交
120 121 122 123 124 125 126 127 128 129 130 131 132 133

/*  Internal periodic / asynchronous schedule state machine states
 */
typedef enum {
    EST_INACTIVE = 1000,
    EST_ACTIVE,
    EST_EXECUTING,
    EST_SLEEPING,
    /*  The following states are internal to the state machine function
    */
    EST_WAITLISTHEAD,
    EST_FETCHENTRY,
    EST_FETCHQH,
    EST_FETCHITD,
G
Gerd Hoffmann 已提交
134
    EST_FETCHSITD,
G
Gerd Hoffmann 已提交
135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153
    EST_ADVANCEQUEUE,
    EST_FETCHQTD,
    EST_EXECUTE,
    EST_WRITEBACK,
    EST_HORIZONTALQH
} EHCI_STATES;

/* macros for accessing fields within next link pointer entry */
#define NLPTR_GET(x)             ((x) & 0xffffffe0)
#define NLPTR_TYPE_GET(x)        (((x) >> 1) & 3)
#define NLPTR_TBIT(x)            ((x) & 1)  // 1=invalid, 0=valid

/* link pointer types */
#define NLPTR_TYPE_ITD           0     // isoc xfer descriptor
#define NLPTR_TYPE_QH            1     // queue head
#define NLPTR_TYPE_STITD         2     // split xaction, isoc xfer descriptor
#define NLPTR_TYPE_FSTN          3     // frame span traversal node

#define SET_LAST_RUN_CLOCK(s) \
G
Gerd Hoffmann 已提交
154
    (s)->last_run_ns = qemu_get_clock_ns(vm_clock);
G
Gerd Hoffmann 已提交
155 156 157 158 159 160 161 162 163 164 165 166

/* nifty macros from Arnon's EHCI version  */
#define get_field(data, field) \
    (((data) & field##_MASK) >> field##_SH)

#define set_field(data, newval, field) do { \
    uint32_t val = *data; \
    val &= ~ field##_MASK; \
    val |= ((newval) << field##_SH) & field##_MASK; \
    *data = val; \
    } while(0)

167
static const char *ehci_state_names[] = {
G
Gerd Hoffmann 已提交
168 169 170 171 172 173 174 175 176 177 178 179 180
    [EST_INACTIVE]     = "INACTIVE",
    [EST_ACTIVE]       = "ACTIVE",
    [EST_EXECUTING]    = "EXECUTING",
    [EST_SLEEPING]     = "SLEEPING",
    [EST_WAITLISTHEAD] = "WAITLISTHEAD",
    [EST_FETCHENTRY]   = "FETCH ENTRY",
    [EST_FETCHQH]      = "FETCH QH",
    [EST_FETCHITD]     = "FETCH ITD",
    [EST_ADVANCEQUEUE] = "ADVANCEQUEUE",
    [EST_FETCHQTD]     = "FETCH QTD",
    [EST_EXECUTE]      = "EXECUTE",
    [EST_WRITEBACK]    = "WRITEBACK",
    [EST_HORIZONTALQH] = "HORIZONTALQH",
181 182 183
};

static const char *ehci_mmio_names[] = {
G
Gerd Hoffmann 已提交
184 185 186 187 188 189 190
    [USBCMD]            = "USBCMD",
    [USBSTS]            = "USBSTS",
    [USBINTR]           = "USBINTR",
    [FRINDEX]           = "FRINDEX",
    [PERIODICLISTBASE]  = "P-LIST BASE",
    [ASYNCLISTADDR]     = "A-LIST ADDR",
    [CONFIGFLAG]        = "CONFIGFLAG",
191
};
G
Gerd Hoffmann 已提交
192

193 194
static int ehci_state_executing(EHCIQueue *q);
static int ehci_state_writeback(EHCIQueue *q);
195
static int ehci_fill_queue(EHCIPacket *p);
196

197
static const char *nr2str(const char **n, size_t len, uint32_t nr)
G
Gerd Hoffmann 已提交
198
{
199 200
    if (nr < len && n[nr] != NULL) {
        return n[nr];
G
Gerd Hoffmann 已提交
201
    } else {
202
        return "unknown";
G
Gerd Hoffmann 已提交
203 204 205
    }
}

206 207 208 209 210
static const char *state2str(uint32_t state)
{
    return nr2str(ehci_state_names, ARRAY_SIZE(ehci_state_names), state);
}

A
Avi Kivity 已提交
211
static const char *addr2str(hwaddr addr)
212
{
213
    return nr2str(ehci_mmio_names, ARRAY_SIZE(ehci_mmio_names), addr);
214 215
}

G
Gerd Hoffmann 已提交
216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269
static void ehci_trace_usbsts(uint32_t mask, int state)
{
    /* interrupts */
    if (mask & USBSTS_INT) {
        trace_usb_ehci_usbsts("INT", state);
    }
    if (mask & USBSTS_ERRINT) {
        trace_usb_ehci_usbsts("ERRINT", state);
    }
    if (mask & USBSTS_PCD) {
        trace_usb_ehci_usbsts("PCD", state);
    }
    if (mask & USBSTS_FLR) {
        trace_usb_ehci_usbsts("FLR", state);
    }
    if (mask & USBSTS_HSE) {
        trace_usb_ehci_usbsts("HSE", state);
    }
    if (mask & USBSTS_IAA) {
        trace_usb_ehci_usbsts("IAA", state);
    }

    /* status */
    if (mask & USBSTS_HALT) {
        trace_usb_ehci_usbsts("HALT", state);
    }
    if (mask & USBSTS_REC) {
        trace_usb_ehci_usbsts("REC", state);
    }
    if (mask & USBSTS_PSS) {
        trace_usb_ehci_usbsts("PSS", state);
    }
    if (mask & USBSTS_ASS) {
        trace_usb_ehci_usbsts("ASS", state);
    }
}

static inline void ehci_set_usbsts(EHCIState *s, int mask)
{
    if ((s->usbsts & mask) == mask) {
        return;
    }
    ehci_trace_usbsts(mask, 1);
    s->usbsts |= mask;
}

static inline void ehci_clear_usbsts(EHCIState *s, int mask)
{
    if ((s->usbsts & mask) == 0) {
        return;
    }
    ehci_trace_usbsts(mask, 0);
    s->usbsts &= ~mask;
}
G
Gerd Hoffmann 已提交
270

271 272
/* update irq line */
static inline void ehci_update_irq(EHCIState *s)
G
Gerd Hoffmann 已提交
273 274 275 276 277 278 279
{
    int level = 0;

    if ((s->usbsts & USBINTR_MASK) & s->usbintr) {
        level = 1;
    }

280
    trace_usb_ehci_irq(level, s->frindex, s->usbsts, s->usbintr);
G
Gerd Hoffmann 已提交
281 282 283
    qemu_set_irq(s->irq, level);
}

284 285
/* flag interrupt condition */
static inline void ehci_raise_irq(EHCIState *s, int intr)
G
Gerd Hoffmann 已提交
286
{
287 288 289 290 291 292
    if (intr & (USBSTS_PCD | USBSTS_FLR | USBSTS_HSE)) {
        s->usbsts |= intr;
        ehci_update_irq(s);
    } else {
        s->usbsts_pending |= intr;
    }
G
Gerd Hoffmann 已提交
293 294
}

295 296 297 298 299
/*
 * Commit pending interrupts (added via ehci_raise_irq),
 * at the rate allowed by "Interrupt Threshold Control".
 */
static inline void ehci_commit_irq(EHCIState *s)
G
Gerd Hoffmann 已提交
300
{
301 302
    uint32_t itc;

G
Gerd Hoffmann 已提交
303 304 305
    if (!s->usbsts_pending) {
        return;
    }
306 307 308 309 310 311
    if (s->usbsts_frindex > s->frindex) {
        return;
    }

    itc = (s->usbcmd >> 16) & 0xff;
    s->usbsts |= s->usbsts_pending;
G
Gerd Hoffmann 已提交
312
    s->usbsts_pending = 0;
313 314
    s->usbsts_frindex = s->frindex + itc;
    ehci_update_irq(s);
G
Gerd Hoffmann 已提交
315 316
}

G
Gerd Hoffmann 已提交
317 318 319 320 321 322 323 324 325 326 327
static void ehci_update_halt(EHCIState *s)
{
    if (s->usbcmd & USBCMD_RUNSTOP) {
        ehci_clear_usbsts(s, USBSTS_HALT);
    } else {
        if (s->astate == EST_INACTIVE && s->pstate == EST_INACTIVE) {
            ehci_set_usbsts(s, USBSTS_HALT);
        }
    }
}

328 329 330 331 332
static void ehci_set_state(EHCIState *s, int async, int state)
{
    if (async) {
        trace_usb_ehci_state("async", state2str(state));
        s->astate = state;
333 334
        if (s->astate == EST_INACTIVE) {
            ehci_clear_usbsts(s, USBSTS_ASS);
G
Gerd Hoffmann 已提交
335
            ehci_update_halt(s);
336 337 338
        } else {
            ehci_set_usbsts(s, USBSTS_ASS);
        }
339 340 341
    } else {
        trace_usb_ehci_state("periodic", state2str(state));
        s->pstate = state;
342 343
        if (s->pstate == EST_INACTIVE) {
            ehci_clear_usbsts(s, USBSTS_PSS);
G
Gerd Hoffmann 已提交
344
            ehci_update_halt(s);
345 346 347
        } else {
            ehci_set_usbsts(s, USBSTS_PSS);
        }
348 349 350 351 352 353 354 355
    }
}

static int ehci_get_state(EHCIState *s, int async)
{
    return async ? s->astate : s->pstate;
}

G
Gerd Hoffmann 已提交
356 357 358 359 360 361 362 363 364 365 366 367 368 369
static void ehci_set_fetch_addr(EHCIState *s, int async, uint32_t addr)
{
    if (async) {
        s->a_fetch_addr = addr;
    } else {
        s->p_fetch_addr = addr;
    }
}

static int ehci_get_fetch_addr(EHCIState *s, int async)
{
    return async ? s->a_fetch_addr : s->p_fetch_addr;
}

A
Avi Kivity 已提交
370
static void ehci_trace_qh(EHCIQueue *q, hwaddr addr, EHCIqh *qh)
371
{
372 373 374 375 376 377 378 379 380 381 382 383 384 385
    /* need three here due to argument count limits */
    trace_usb_ehci_qh_ptrs(q, addr, qh->next,
                           qh->current_qtd, qh->next_qtd, qh->altnext_qtd);
    trace_usb_ehci_qh_fields(addr,
                             get_field(qh->epchar, QH_EPCHAR_RL),
                             get_field(qh->epchar, QH_EPCHAR_MPLEN),
                             get_field(qh->epchar, QH_EPCHAR_EPS),
                             get_field(qh->epchar, QH_EPCHAR_EP),
                             get_field(qh->epchar, QH_EPCHAR_DEVADDR));
    trace_usb_ehci_qh_bits(addr,
                           (bool)(qh->epchar & QH_EPCHAR_C),
                           (bool)(qh->epchar & QH_EPCHAR_H),
                           (bool)(qh->epchar & QH_EPCHAR_DTC),
                           (bool)(qh->epchar & QH_EPCHAR_I));
386 387
}

A
Avi Kivity 已提交
388
static void ehci_trace_qtd(EHCIQueue *q, hwaddr addr, EHCIqtd *qtd)
389
{
390 391 392 393 394 395 396 397 398 399 400 401 402
    /* need three here due to argument count limits */
    trace_usb_ehci_qtd_ptrs(q, addr, qtd->next, qtd->altnext);
    trace_usb_ehci_qtd_fields(addr,
                              get_field(qtd->token, QTD_TOKEN_TBYTES),
                              get_field(qtd->token, QTD_TOKEN_CPAGE),
                              get_field(qtd->token, QTD_TOKEN_CERR),
                              get_field(qtd->token, QTD_TOKEN_PID));
    trace_usb_ehci_qtd_bits(addr,
                            (bool)(qtd->token & QTD_TOKEN_IOC),
                            (bool)(qtd->token & QTD_TOKEN_ACTIVE),
                            (bool)(qtd->token & QTD_TOKEN_HALT),
                            (bool)(qtd->token & QTD_TOKEN_BABBLE),
                            (bool)(qtd->token & QTD_TOKEN_XACTERR));
403 404
}

A
Avi Kivity 已提交
405
static void ehci_trace_itd(EHCIState *s, hwaddr addr, EHCIitd *itd)
406
{
G
Gerd Hoffmann 已提交
407 408 409 410 411
    trace_usb_ehci_itd(addr, itd->next,
                       get_field(itd->bufptr[1], ITD_BUFPTR_MAXPKT),
                       get_field(itd->bufptr[2], ITD_BUFPTR_MULT),
                       get_field(itd->bufptr[0], ITD_BUFPTR_EP),
                       get_field(itd->bufptr[0], ITD_BUFPTR_DEVADDR));
412 413
}

A
Avi Kivity 已提交
414
static void ehci_trace_sitd(EHCIState *s, hwaddr addr,
G
Gerd Hoffmann 已提交
415 416 417 418 419 420
                            EHCIsitd *sitd)
{
    trace_usb_ehci_sitd(addr, sitd->next,
                        (bool)(sitd->results & SITD_RESULTS_ACTIVE));
}

G
Gerd Hoffmann 已提交
421 422 423 424 425 426
static void ehci_trace_guest_bug(EHCIState *s, const char *message)
{
    trace_usb_ehci_guest_bug(message);
    fprintf(stderr, "ehci warning: %s\n", message);
}

427 428 429 430 431 432 433 434 435 436 437 438 439 440 441
static inline bool ehci_enabled(EHCIState *s)
{
    return s->usbcmd & USBCMD_RUNSTOP;
}

static inline bool ehci_async_enabled(EHCIState *s)
{
    return ehci_enabled(s) && (s->usbcmd & USBCMD_ASE);
}

static inline bool ehci_periodic_enabled(EHCIState *s)
{
    return ehci_enabled(s) && (s->usbcmd & USBCMD_PSE);
}

G
Gerd Hoffmann 已提交
442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457
/* packet management */

static EHCIPacket *ehci_alloc_packet(EHCIQueue *q)
{
    EHCIPacket *p;

    p = g_new0(EHCIPacket, 1);
    p->queue = q;
    usb_packet_init(&p->packet);
    QTAILQ_INSERT_TAIL(&q->packets, p, next);
    trace_usb_ehci_packet_action(p->queue, p, "alloc");
    return p;
}

static void ehci_free_packet(EHCIPacket *p)
{
458 459 460 461 462 463 464 465 466 467
    if (p->async == EHCI_ASYNC_FINISHED) {
        int state = ehci_get_state(p->queue->ehci, p->queue->async);
        /* This is a normal, but rare condition (cancel racing completion) */
        fprintf(stderr, "EHCI: Warning packet completed but not processed\n");
        ehci_state_executing(p->queue);
        ehci_state_writeback(p->queue);
        ehci_set_state(p->queue->ehci, p->queue->async, state);
        /* state_writeback recurses into us with async == EHCI_ASYNC_NONE!! */
        return;
    }
468
    trace_usb_ehci_packet_action(p->queue, p, "free");
469 470 471 472
    if (p->async == EHCI_ASYNC_INITIALIZED) {
        usb_packet_unmap(&p->packet, &p->sgl);
        qemu_sglist_destroy(&p->sgl);
    }
473 474 475 476 477
    if (p->async == EHCI_ASYNC_INFLIGHT) {
        usb_cancel_packet(&p->packet);
        usb_packet_unmap(&p->packet, &p->sgl);
        qemu_sglist_destroy(&p->sgl);
    }
G
Gerd Hoffmann 已提交
478 479 480 481 482
    QTAILQ_REMOVE(&p->queue->packets, p, next);
    usb_packet_cleanup(&p->packet);
    g_free(p);
}

G
Gerd Hoffmann 已提交
483 484
/* queue management */

G
Gerd Hoffmann 已提交
485
static EHCIQueue *ehci_alloc_queue(EHCIState *ehci, uint32_t addr, int async)
G
Gerd Hoffmann 已提交
486
{
487
    EHCIQueueHead *head = async ? &ehci->aqueues : &ehci->pqueues;
G
Gerd Hoffmann 已提交
488 489
    EHCIQueue *q;

490
    q = g_malloc0(sizeof(*q));
G
Gerd Hoffmann 已提交
491
    q->ehci = ehci;
G
Gerd Hoffmann 已提交
492
    q->qhaddr = addr;
493
    q->async = async;
G
Gerd Hoffmann 已提交
494
    QTAILQ_INIT(&q->packets);
495
    QTAILQ_INSERT_HEAD(head, q, next);
G
Gerd Hoffmann 已提交
496 497 498 499
    trace_usb_ehci_queue_action(q, "alloc");
    return q;
}

G
Gerd Hoffmann 已提交
500
static int ehci_cancel_queue(EHCIQueue *q)
G
Gerd Hoffmann 已提交
501 502
{
    EHCIPacket *p;
G
Gerd Hoffmann 已提交
503
    int packets = 0;
G
Gerd Hoffmann 已提交
504 505 506

    p = QTAILQ_FIRST(&q->packets);
    if (p == NULL) {
G
Gerd Hoffmann 已提交
507
        return 0;
G
Gerd Hoffmann 已提交
508 509 510 511 512
    }

    trace_usb_ehci_queue_action(q, "cancel");
    do {
        ehci_free_packet(p);
G
Gerd Hoffmann 已提交
513
        packets++;
G
Gerd Hoffmann 已提交
514
    } while ((p = QTAILQ_FIRST(&q->packets)) != NULL);
G
Gerd Hoffmann 已提交
515
    return packets;
G
Gerd Hoffmann 已提交
516 517
}

G
Gerd Hoffmann 已提交
518
static int ehci_reset_queue(EHCIQueue *q)
519
{
G
Gerd Hoffmann 已提交
520 521
    int packets;

522
    trace_usb_ehci_queue_action(q, "reset");
G
Gerd Hoffmann 已提交
523
    packets = ehci_cancel_queue(q);
524 525
    q->dev = NULL;
    q->qtdaddr = 0;
G
Gerd Hoffmann 已提交
526
    return packets;
527 528
}

529
static void ehci_free_queue(EHCIQueue *q, const char *warn)
G
Gerd Hoffmann 已提交
530
{
531
    EHCIQueueHead *head = q->async ? &q->ehci->aqueues : &q->ehci->pqueues;
532
    int cancelled;
G
Gerd Hoffmann 已提交
533

G
Gerd Hoffmann 已提交
534
    trace_usb_ehci_queue_action(q, "free");
535 536 537 538
    cancelled = ehci_cancel_queue(q);
    if (warn && cancelled > 0) {
        ehci_trace_guest_bug(q->ehci, warn);
    }
539
    QTAILQ_REMOVE(head, q, next);
540
    g_free(q);
G
Gerd Hoffmann 已提交
541 542
}

543 544
static EHCIQueue *ehci_find_queue_by_qh(EHCIState *ehci, uint32_t addr,
                                        int async)
G
Gerd Hoffmann 已提交
545
{
546
    EHCIQueueHead *head = async ? &ehci->aqueues : &ehci->pqueues;
G
Gerd Hoffmann 已提交
547 548
    EHCIQueue *q;

549
    QTAILQ_FOREACH(q, head, next) {
G
Gerd Hoffmann 已提交
550 551 552 553 554 555 556
        if (addr == q->qhaddr) {
            return q;
        }
    }
    return NULL;
}

557
static void ehci_queues_rip_unused(EHCIState *ehci, int async)
G
Gerd Hoffmann 已提交
558
{
559
    EHCIQueueHead *head = async ? &ehci->aqueues : &ehci->pqueues;
560
    const char *warn = async ? "guest unlinked busy QH" : NULL;
G
Gerd Hoffmann 已提交
561
    uint64_t maxage = FRAME_TIMER_NS * ehci->maxframes * 4;
G
Gerd Hoffmann 已提交
562 563
    EHCIQueue *q, *tmp;

564
    QTAILQ_FOREACH_SAFE(q, head, next, tmp) {
G
Gerd Hoffmann 已提交
565 566
        if (q->seen) {
            q->seen = 0;
G
Gerd Hoffmann 已提交
567
            q->ts = ehci->last_run_ns;
G
Gerd Hoffmann 已提交
568 569
            continue;
        }
570
        if (ehci->last_run_ns < q->ts + maxage) {
G
Gerd Hoffmann 已提交
571 572
            continue;
        }
573
        ehci_free_queue(q, warn);
G
Gerd Hoffmann 已提交
574 575 576
    }
}

577 578 579 580 581 582 583 584 585 586 587 588
static void ehci_queues_rip_unseen(EHCIState *ehci, int async)
{
    EHCIQueueHead *head = async ? &ehci->aqueues : &ehci->pqueues;
    EHCIQueue *q, *tmp;

    QTAILQ_FOREACH_SAFE(q, head, next, tmp) {
        if (!q->seen) {
            ehci_free_queue(q, NULL);
        }
    }
}

589
static void ehci_queues_rip_device(EHCIState *ehci, USBDevice *dev, int async)
590
{
591
    EHCIQueueHead *head = async ? &ehci->aqueues : &ehci->pqueues;
592 593
    EHCIQueue *q, *tmp;

594
    QTAILQ_FOREACH_SAFE(q, head, next, tmp) {
595
        if (q->dev != dev) {
596 597
            continue;
        }
598
        ehci_free_queue(q, NULL);
599 600 601
    }
}

602
static void ehci_queues_rip_all(EHCIState *ehci, int async)
G
Gerd Hoffmann 已提交
603
{
604
    EHCIQueueHead *head = async ? &ehci->aqueues : &ehci->pqueues;
605
    const char *warn = async ? "guest stopped busy async schedule" : NULL;
G
Gerd Hoffmann 已提交
606 607
    EHCIQueue *q, *tmp;

608
    QTAILQ_FOREACH_SAFE(q, head, next, tmp) {
609
        ehci_free_queue(q, warn);
G
Gerd Hoffmann 已提交
610 611 612
    }
}

G
Gerd Hoffmann 已提交
613 614 615 616 617 618
/* Attach or detach a device on root hub */

static void ehci_attach(USBPort *port)
{
    EHCIState *s = port->opaque;
    uint32_t *portsc = &s->portsc[port->index];
G
Gerd Hoffmann 已提交
619
    const char *owner = (*portsc & PORTSC_POWNER) ? "comp" : "ehci";
G
Gerd Hoffmann 已提交
620

G
Gerd Hoffmann 已提交
621
    trace_usb_ehci_port_attach(port->index, owner, port->dev->product_desc);
G
Gerd Hoffmann 已提交
622

623 624 625 626 627 628 629
    if (*portsc & PORTSC_POWNER) {
        USBPort *companion = s->companion_ports[port->index];
        companion->dev = port->dev;
        companion->ops->attach(companion);
        return;
    }

G
Gerd Hoffmann 已提交
630 631 632
    *portsc |= PORTSC_CONNECT;
    *portsc |= PORTSC_CSC;

633 634
    ehci_raise_irq(s, USBSTS_PCD);
    ehci_commit_irq(s);
G
Gerd Hoffmann 已提交
635 636 637 638 639 640
}

static void ehci_detach(USBPort *port)
{
    EHCIState *s = port->opaque;
    uint32_t *portsc = &s->portsc[port->index];
G
Gerd Hoffmann 已提交
641
    const char *owner = (*portsc & PORTSC_POWNER) ? "comp" : "ehci";
G
Gerd Hoffmann 已提交
642

G
Gerd Hoffmann 已提交
643
    trace_usb_ehci_port_detach(port->index, owner);
G
Gerd Hoffmann 已提交
644

645 646 647 648
    if (*portsc & PORTSC_POWNER) {
        USBPort *companion = s->companion_ports[port->index];
        companion->ops->detach(companion);
        companion->dev = NULL;
649 650 651 652 653
        /*
         * EHCI spec 4.2.2: "When a disconnect occurs... On the event,
         * the port ownership is returned immediately to the EHCI controller."
         */
        *portsc &= ~PORTSC_POWNER;
654 655 656
        return;
    }

657 658
    ehci_queues_rip_device(s, port->dev, 0);
    ehci_queues_rip_device(s, port->dev, 1);
659

660
    *portsc &= ~(PORTSC_CONNECT|PORTSC_PED);
G
Gerd Hoffmann 已提交
661 662
    *portsc |= PORTSC_CSC;

663 664
    ehci_raise_irq(s, USBSTS_PCD);
    ehci_commit_irq(s);
G
Gerd Hoffmann 已提交
665 666
}

667 668 669
static void ehci_child_detach(USBPort *port, USBDevice *child)
{
    EHCIState *s = port->opaque;
670 671 672 673 674 675 676
    uint32_t portsc = s->portsc[port->index];

    if (portsc & PORTSC_POWNER) {
        USBPort *companion = s->companion_ports[port->index];
        companion->ops->child_detach(companion, child);
        return;
    }
677

678 679
    ehci_queues_rip_device(s, child, 0);
    ehci_queues_rip_device(s, child, 1);
680 681
}

682 683 684 685 686 687 688 689 690 691
static void ehci_wakeup(USBPort *port)
{
    EHCIState *s = port->opaque;
    uint32_t portsc = s->portsc[port->index];

    if (portsc & PORTSC_POWNER) {
        USBPort *companion = s->companion_ports[port->index];
        if (companion->ops->wakeup) {
            companion->ops->wakeup(companion);
        }
692
        return;
693
    }
694 695

    qemu_bh_schedule(s->async_bh);
696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733
}

static int ehci_register_companion(USBBus *bus, USBPort *ports[],
                                   uint32_t portcount, uint32_t firstport)
{
    EHCIState *s = container_of(bus, EHCIState, bus);
    uint32_t i;

    if (firstport + portcount > NB_PORTS) {
        qerror_report(QERR_INVALID_PARAMETER_VALUE, "firstport",
                      "firstport on masterbus");
        error_printf_unless_qmp(
            "firstport value of %u makes companion take ports %u - %u, which "
            "is outside of the valid range of 0 - %u\n", firstport, firstport,
            firstport + portcount - 1, NB_PORTS - 1);
        return -1;
    }

    for (i = 0; i < portcount; i++) {
        if (s->companion_ports[firstport + i]) {
            qerror_report(QERR_INVALID_PARAMETER_VALUE, "masterbus",
                          "an USB masterbus");
            error_printf_unless_qmp(
                "port %u on masterbus %s already has a companion assigned\n",
                firstport + i, bus->qbus.name);
            return -1;
        }
    }

    for (i = 0; i < portcount; i++) {
        s->companion_ports[firstport + i] = ports[i];
        s->ports[firstport + i].speedmask |=
            USB_SPEED_MASK_LOW | USB_SPEED_MASK_FULL;
        /* Ensure devs attached before the initial reset go to the companion */
        s->portsc[firstport + i] = PORTSC_POWNER;
    }

    s->companion_count++;
734
    s->caps[0x05] = (s->companion_count << 4) | portcount;
735 736 737 738

    return 0;
}

739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758
static USBDevice *ehci_find_device(EHCIState *ehci, uint8_t addr)
{
    USBDevice *dev;
    USBPort *port;
    int i;

    for (i = 0; i < NB_PORTS; i++) {
        port = &ehci->ports[i];
        if (!(ehci->portsc[i] & PORTSC_PED)) {
            DPRINTF("Port %d not enabled\n", i);
            continue;
        }
        dev = usb_find_device(port, addr);
        if (dev != NULL) {
            return dev;
        }
    }
    return NULL;
}

G
Gerd Hoffmann 已提交
759 760 761 762 763
/* 4.1 host controller initialization */
static void ehci_reset(void *opaque)
{
    EHCIState *s = opaque;
    int i;
764
    USBDevice *devs[NB_PORTS];
G
Gerd Hoffmann 已提交
765

G
Gerd Hoffmann 已提交
766
    trace_usb_ehci_reset();
G
Gerd Hoffmann 已提交
767

768 769 770 771 772 773
    /*
     * Do the detach before touching portsc, so that it correctly gets send to
     * us or to our companion based on PORTSC_POWNER before the reset.
     */
    for(i = 0; i < NB_PORTS; i++) {
        devs[i] = s->ports[i].dev;
774 775
        if (devs[i] && devs[i]->attached) {
            usb_detach(&s->ports[i]);
776 777 778
        }
    }

779 780
    memset(&s->opreg, 0x00, sizeof(s->opreg));
    memset(&s->portsc, 0x00, sizeof(s->portsc));
G
Gerd Hoffmann 已提交
781 782 783

    s->usbcmd = NB_MAXINTRATE << USBCMD_ITC_SH;
    s->usbsts = USBSTS_HALT;
784 785
    s->usbsts_pending = 0;
    s->usbsts_frindex = 0;
G
Gerd Hoffmann 已提交
786 787 788 789 790

    s->astate = EST_INACTIVE;
    s->pstate = EST_INACTIVE;

    for(i = 0; i < NB_PORTS; i++) {
791 792 793 794 795
        if (s->companion_ports[i]) {
            s->portsc[i] = PORTSC_POWNER | PORTSC_PPOWER;
        } else {
            s->portsc[i] = PORTSC_PPOWER;
        }
796 797
        if (devs[i] && devs[i]->attached) {
            usb_attach(&s->ports[i]);
G
Gerd Hoffmann 已提交
798
            usb_device_reset(devs[i]);
G
Gerd Hoffmann 已提交
799 800
        }
    }
801 802
    ehci_queues_rip_all(s, 0);
    ehci_queues_rip_all(s, 1);
G
Gerd Hoffmann 已提交
803
    qemu_del_timer(s->frame_timer);
804
    qemu_bh_cancel(s->async_bh);
G
Gerd Hoffmann 已提交
805 806
}

A
Avi Kivity 已提交
807
static uint64_t ehci_caps_read(void *ptr, hwaddr addr,
808
                               unsigned size)
G
Gerd Hoffmann 已提交
809 810
{
    EHCIState *s = ptr;
811
    return s->caps[addr];
G
Gerd Hoffmann 已提交
812 813
}

A
Avi Kivity 已提交
814
static uint64_t ehci_opreg_read(void *ptr, hwaddr addr,
815
                                unsigned size)
G
Gerd Hoffmann 已提交
816 817 818 819
{
    EHCIState *s = ptr;
    uint32_t val;

820
    val = s->opreg[addr >> 2];
821
    trace_usb_ehci_opreg_read(addr + s->opregbase, addr2str(addr), val);
G
Gerd Hoffmann 已提交
822 823 824
    return val;
}

A
Avi Kivity 已提交
825
static uint64_t ehci_port_read(void *ptr, hwaddr addr,
826
                               unsigned size)
G
Gerd Hoffmann 已提交
827 828 829 830
{
    EHCIState *s = ptr;
    uint32_t val;

831 832
    val = s->portsc[addr >> 2];
    trace_usb_ehci_portsc_read(addr + PORTSC_BEGIN, addr >> 2, val);
G
Gerd Hoffmann 已提交
833 834 835
    return val;
}

836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851
static void handle_port_owner_write(EHCIState *s, int port, uint32_t owner)
{
    USBDevice *dev = s->ports[port].dev;
    uint32_t *portsc = &s->portsc[port];
    uint32_t orig;

    if (s->companion_ports[port] == NULL)
        return;

    owner = owner & PORTSC_POWNER;
    orig  = *portsc & PORTSC_POWNER;

    if (!(owner ^ orig)) {
        return;
    }

852 853
    if (dev && dev->attached) {
        usb_detach(&s->ports[port]);
854 855 856 857 858
    }

    *portsc &= ~PORTSC_POWNER;
    *portsc |= owner;

859 860
    if (dev && dev->attached) {
        usb_attach(&s->ports[port]);
861 862 863
    }
}

A
Avi Kivity 已提交
864
static void ehci_port_write(void *ptr, hwaddr addr,
865
                            uint64_t val, unsigned size)
G
Gerd Hoffmann 已提交
866
{
867 868
    EHCIState *s = ptr;
    int port = addr >> 2;
G
Gerd Hoffmann 已提交
869
    uint32_t *portsc = &s->portsc[port];
870
    uint32_t old = *portsc;
G
Gerd Hoffmann 已提交
871 872
    USBDevice *dev = s->ports[port].dev;

873 874
    trace_usb_ehci_portsc_write(addr + PORTSC_BEGIN, addr >> 2, val);

875 876 877 878
    /* Clear rwc bits */
    *portsc &= ~(val & PORTSC_RWC_MASK);
    /* The guest may clear, but not set the PED bit */
    *portsc &= val | ~PORTSC_PED;
879 880 881
    /* POWNER is masked out by RO_MASK as it is RO when we've no companion */
    handle_port_owner_write(s, port, val);
    /* And finally apply RO_MASK */
G
Gerd Hoffmann 已提交
882 883 884
    val &= PORTSC_RO_MASK;

    if ((val & PORTSC_PRESET) && !(*portsc & PORTSC_PRESET)) {
G
Gerd Hoffmann 已提交
885
        trace_usb_ehci_port_reset(port, 1);
G
Gerd Hoffmann 已提交
886 887 888
    }

    if (!(val & PORTSC_PRESET) &&(*portsc & PORTSC_PRESET)) {
G
Gerd Hoffmann 已提交
889
        trace_usb_ehci_port_reset(port, 0);
890
        if (dev && dev->attached) {
G
Gerd Hoffmann 已提交
891
            usb_port_reset(&s->ports[port]);
G
Gerd Hoffmann 已提交
892 893 894
            *portsc &= ~PORTSC_CSC;
        }

895 896
        /*
         *  Table 2.16 Set the enable bit(and enable bit change) to indicate
G
Gerd Hoffmann 已提交
897 898
         *  to SW that this port has a high speed device attached
         */
899
        if (dev && dev->attached && (dev->speedmask & USB_SPEED_MASK_HIGH)) {
900 901
            val |= PORTSC_PED;
        }
G
Gerd Hoffmann 已提交
902 903 904 905
    }

    *portsc &= ~PORTSC_RO_MASK;
    *portsc |= val;
906
    trace_usb_ehci_portsc_change(addr + PORTSC_BEGIN, addr >> 2, *portsc, old);
G
Gerd Hoffmann 已提交
907 908
}

A
Avi Kivity 已提交
909
static void ehci_opreg_write(void *ptr, hwaddr addr,
910
                             uint64_t val, unsigned size)
G
Gerd Hoffmann 已提交
911 912
{
    EHCIState *s = ptr;
913
    uint32_t *mmio = s->opreg + (addr >> 2);
G
Gerd Hoffmann 已提交
914
    uint32_t old = *mmio;
G
Gerd Hoffmann 已提交
915
    int i;
G
Gerd Hoffmann 已提交
916

917
    trace_usb_ehci_opreg_write(addr + s->opregbase, addr2str(addr), val);
G
Gerd Hoffmann 已提交
918

919
    switch (addr) {
G
Gerd Hoffmann 已提交
920
    case USBCMD:
G
Gerd Hoffmann 已提交
921 922 923 924 925 926
        if (val & USBCMD_HCRESET) {
            ehci_reset(s);
            val = s->usbcmd;
            break;
        }

927 928 929
        /* not supporting dynamic frame list size at the moment */
        if ((val & USBCMD_FLS) && !(s->usbcmd & USBCMD_FLS)) {
            fprintf(stderr, "attempt to set frame list size -- value %d\n",
930
                    (int)val & USBCMD_FLS);
931 932 933
            val &= ~USBCMD_FLS;
        }

934 935 936 937 938 939 940
        if (val & USBCMD_IAAD) {
            /*
             * Process IAAD immediately, otherwise the Linux IAAD watchdog may
             * trigger and re-use a qh without us seeing the unlink.
             */
            s->async_stepdown = 0;
            qemu_bh_schedule(s->async_bh);
G
Gerd Hoffmann 已提交
941
            trace_usb_ehci_doorbell_ring();
942 943
        }

G
Gerd Hoffmann 已提交
944 945
        if (((USBCMD_RUNSTOP | USBCMD_PSE | USBCMD_ASE) & val) !=
            ((USBCMD_RUNSTOP | USBCMD_PSE | USBCMD_ASE) & s->usbcmd)) {
G
Gerd Hoffmann 已提交
946
            if (s->pstate == EST_INACTIVE) {
G
Gerd Hoffmann 已提交
947 948
                SET_LAST_RUN_CLOCK(s);
            }
949
            s->usbcmd = val; /* Set usbcmd for ehci_update_halt() */
G
Gerd Hoffmann 已提交
950
            ehci_update_halt(s);
G
Gerd Hoffmann 已提交
951
            s->async_stepdown = 0;
952
            qemu_bh_schedule(s->async_bh);
G
Gerd Hoffmann 已提交
953 954 955 956
        }
        break;

    case USBSTS:
J
Jim Meyering 已提交
957 958
        val &= USBSTS_RO_MASK;              // bits 6 through 31 are RO
        ehci_clear_usbsts(s, val);          // bits 0 through 5 are R/WC
G
Gerd Hoffmann 已提交
959
        val = s->usbsts;
960
        ehci_update_irq(s);
G
Gerd Hoffmann 已提交
961 962 963 964 965 966
        break;

    case USBINTR:
        val &= USBINTR_MASK;
        break;

967 968 969 970
    case FRINDEX:
        val &= 0x00003ff8; /* frindex is 14bits and always a multiple of 8 */
        break;

G
Gerd Hoffmann 已提交
971 972 973 974
    case CONFIGFLAG:
        val &= 0x1;
        if (val) {
            for(i = 0; i < NB_PORTS; i++)
975
                handle_port_owner_write(s, i, 0);
G
Gerd Hoffmann 已提交
976 977 978 979
        }
        break;

    case PERIODICLISTBASE:
980
        if (ehci_periodic_enabled(s)) {
G
Gerd Hoffmann 已提交
981 982 983 984 985 986 987
            fprintf(stderr,
              "ehci: PERIODIC list base register set while periodic schedule\n"
              "      is enabled and HC is enabled\n");
        }
        break;

    case ASYNCLISTADDR:
988
        if (ehci_async_enabled(s)) {
G
Gerd Hoffmann 已提交
989 990 991 992 993 994 995
            fprintf(stderr,
              "ehci: ASYNC list address register set while async schedule\n"
              "      is enabled and HC is enabled\n");
        }
        break;
    }

G
Gerd Hoffmann 已提交
996
    *mmio = val;
997 998
    trace_usb_ehci_opreg_change(addr + s->opregbase, addr2str(addr),
                                *mmio, old);
G
Gerd Hoffmann 已提交
999 1000 1001 1002 1003 1004
}


// TODO : Put in common header file, duplication from usb-ohci.c

/* Get an array of dwords from main memory */
1005 1006
static inline int get_dwords(EHCIState *ehci, uint32_t addr,
                             uint32_t *buf, int num)
G
Gerd Hoffmann 已提交
1007 1008 1009 1010
{
    int i;

    for(i = 0; i < num; i++, buf++, addr += sizeof(*buf)) {
1011
        dma_memory_read(ehci->dma, addr, buf, sizeof(*buf));
G
Gerd Hoffmann 已提交
1012 1013 1014 1015 1016 1017 1018
        *buf = le32_to_cpu(*buf);
    }

    return 1;
}

/* Put an array of dwords in to main memory */
1019 1020
static inline int put_dwords(EHCIState *ehci, uint32_t addr,
                             uint32_t *buf, int num)
G
Gerd Hoffmann 已提交
1021 1022 1023 1024 1025
{
    int i;

    for(i = 0; i < num; i++, buf++, addr += sizeof(*buf)) {
        uint32_t tmp = cpu_to_le32(*buf);
1026
        dma_memory_write(ehci->dma, addr, &tmp, sizeof(tmp));
G
Gerd Hoffmann 已提交
1027 1028 1029 1030 1031
    }

    return 1;
}

G
Gerd Hoffmann 已提交
1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048
/*
 *  Write the qh back to guest physical memory.  This step isn't
 *  in the EHCI spec but we need to do it since we don't share
 *  physical memory with our guest VM.
 *
 *  The first three dwords are read-only for the EHCI, so skip them
 *  when writing back the qh.
 */
static void ehci_flush_qh(EHCIQueue *q)
{
    uint32_t *qh = (uint32_t *) &q->qh;
    uint32_t dwords = sizeof(EHCIqh) >> 2;
    uint32_t addr = NLPTR_GET(q->qhaddr);

    put_dwords(q->ehci, addr + 3 * sizeof(uint32_t), qh + 3, dwords - 3);
}

G
Gerd Hoffmann 已提交
1049 1050
// 4.10.2

G
Gerd Hoffmann 已提交
1051
static int ehci_qh_do_overlay(EHCIQueue *q)
G
Gerd Hoffmann 已提交
1052
{
G
Gerd Hoffmann 已提交
1053
    EHCIPacket *p = QTAILQ_FIRST(&q->packets);
G
Gerd Hoffmann 已提交
1054 1055 1056 1057 1058 1059
    int i;
    int dtoggle;
    int ping;
    int eps;
    int reload;

G
Gerd Hoffmann 已提交
1060 1061 1062
    assert(p != NULL);
    assert(p->qtdaddr == q->qtdaddr);

G
Gerd Hoffmann 已提交
1063 1064
    // remember values in fields to preserve in qh after overlay

G
Gerd Hoffmann 已提交
1065 1066
    dtoggle = q->qh.token & QTD_TOKEN_DTOGGLE;
    ping    = q->qh.token & QTD_TOKEN_PING;
G
Gerd Hoffmann 已提交
1067

G
Gerd Hoffmann 已提交
1068 1069 1070 1071
    q->qh.current_qtd = p->qtdaddr;
    q->qh.next_qtd    = p->qtd.next;
    q->qh.altnext_qtd = p->qtd.altnext;
    q->qh.token       = p->qtd.token;
G
Gerd Hoffmann 已提交
1072 1073


G
Gerd Hoffmann 已提交
1074
    eps = get_field(q->qh.epchar, QH_EPCHAR_EPS);
G
Gerd Hoffmann 已提交
1075
    if (eps == EHCI_QH_EPS_HIGH) {
G
Gerd Hoffmann 已提交
1076 1077
        q->qh.token &= ~QTD_TOKEN_PING;
        q->qh.token |= ping;
G
Gerd Hoffmann 已提交
1078 1079
    }

G
Gerd Hoffmann 已提交
1080 1081
    reload = get_field(q->qh.epchar, QH_EPCHAR_RL);
    set_field(&q->qh.altnext_qtd, reload, QH_ALTNEXT_NAKCNT);
G
Gerd Hoffmann 已提交
1082 1083

    for (i = 0; i < 5; i++) {
G
Gerd Hoffmann 已提交
1084
        q->qh.bufptr[i] = p->qtd.bufptr[i];
G
Gerd Hoffmann 已提交
1085 1086
    }

G
Gerd Hoffmann 已提交
1087
    if (!(q->qh.epchar & QH_EPCHAR_DTC)) {
G
Gerd Hoffmann 已提交
1088
        // preserve QH DT bit
G
Gerd Hoffmann 已提交
1089 1090
        q->qh.token &= ~QTD_TOKEN_DTOGGLE;
        q->qh.token |= dtoggle;
G
Gerd Hoffmann 已提交
1091 1092
    }

G
Gerd Hoffmann 已提交
1093 1094
    q->qh.bufptr[1] &= ~BUFPTR_CPROGMASK_MASK;
    q->qh.bufptr[2] &= ~BUFPTR_FRAMETAG_MASK;
G
Gerd Hoffmann 已提交
1095

G
Gerd Hoffmann 已提交
1096
    ehci_flush_qh(q);
G
Gerd Hoffmann 已提交
1097 1098 1099 1100

    return 0;
}

G
Gerd Hoffmann 已提交
1101
static int ehci_init_transfer(EHCIPacket *p)
G
Gerd Hoffmann 已提交
1102
{
1103
    uint32_t cpage, offset, bytes, plen;
1104
    dma_addr_t page;
G
Gerd Hoffmann 已提交
1105

G
Gerd Hoffmann 已提交
1106 1107 1108
    cpage  = get_field(p->qtd.token, QTD_TOKEN_CPAGE);
    bytes  = get_field(p->qtd.token, QTD_TOKEN_TBYTES);
    offset = p->qtd.bufptr[0] & ~QTD_BUFPTR_MASK;
1109
    qemu_sglist_init(&p->sgl, 5, p->queue->ehci->dma);
G
Gerd Hoffmann 已提交
1110

1111 1112 1113 1114 1115
    while (bytes > 0) {
        if (cpage > 4) {
            fprintf(stderr, "cpage out of range (%d)\n", cpage);
            return USB_RET_PROCERR;
        }
G
Gerd Hoffmann 已提交
1116

G
Gerd Hoffmann 已提交
1117
        page  = p->qtd.bufptr[cpage] & QTD_BUFPTR_MASK;
1118 1119 1120 1121 1122 1123
        page += offset;
        plen  = bytes;
        if (plen > 4096 - offset) {
            plen = 4096 - offset;
            offset = 0;
            cpage++;
G
Gerd Hoffmann 已提交
1124 1125
        }

G
Gerd Hoffmann 已提交
1126
        qemu_sglist_add(&p->sgl, page, plen);
1127 1128 1129 1130
        bytes -= plen;
    }
    return 0;
}
G
Gerd Hoffmann 已提交
1131

1132 1133 1134
static void ehci_finish_transfer(EHCIQueue *q, int status)
{
    uint32_t cpage, offset;
G
Gerd Hoffmann 已提交
1135

1136 1137 1138 1139
    if (status > 0) {
        /* update cpage & offset */
        cpage  = get_field(q->qh.token, QTD_TOKEN_CPAGE);
        offset = q->qh.bufptr[0] & ~QTD_BUFPTR_MASK;
G
Gerd Hoffmann 已提交
1140

1141 1142 1143
        offset += status;
        cpage  += offset >> QTD_BUFPTR_SH;
        offset &= ~QTD_BUFPTR_MASK;
G
Gerd Hoffmann 已提交
1144

1145 1146 1147 1148
        set_field(&q->qh.token, cpage, QTD_TOKEN_CPAGE);
        q->qh.bufptr[0] &= QTD_BUFPTR_MASK;
        q->qh.bufptr[0] |= offset;
    }
G
Gerd Hoffmann 已提交
1149 1150
}

1151
static void ehci_async_complete_packet(USBPort *port, USBPacket *packet)
G
Gerd Hoffmann 已提交
1152
{
G
Gerd Hoffmann 已提交
1153
    EHCIPacket *p;
1154 1155 1156 1157 1158 1159 1160 1161
    EHCIState *s = port->opaque;
    uint32_t portsc = s->portsc[port->index];

    if (portsc & PORTSC_POWNER) {
        USBPort *companion = s->companion_ports[port->index];
        companion->ops->complete(companion, packet);
        return;
    }
G
Gerd Hoffmann 已提交
1162

G
Gerd Hoffmann 已提交
1163 1164
    p = container_of(packet, EHCIPacket, packet);
    assert(p->async == EHCI_ASYNC_INFLIGHT);
1165

1166
    if (packet->status == USB_RET_REMOVE_FROM_QUEUE) {
1167 1168 1169 1170 1171 1172
        trace_usb_ehci_packet_action(p->queue, p, "remove");
        ehci_free_packet(p);
        return;
    }

    trace_usb_ehci_packet_action(p->queue, p, "wakeup");
G
Gerd Hoffmann 已提交
1173
    p->async = EHCI_ASYNC_FINISHED;
1174
    p->usb_status = packet->status ? packet->status : packet->actual_length;
1175 1176 1177 1178

    if (p->queue->async) {
        qemu_bh_schedule(p->queue->ehci->async_bh);
    }
G
Gerd Hoffmann 已提交
1179 1180
}

G
Gerd Hoffmann 已提交
1181
static void ehci_execute_complete(EHCIQueue *q)
G
Gerd Hoffmann 已提交
1182
{
G
Gerd Hoffmann 已提交
1183 1184 1185 1186
    EHCIPacket *p = QTAILQ_FIRST(&q->packets);

    assert(p != NULL);
    assert(p->qtdaddr == q->qtdaddr);
1187 1188
    assert(p->async == EHCI_ASYNC_INITIALIZED ||
           p->async == EHCI_ASYNC_FINISHED);
G
Gerd Hoffmann 已提交
1189 1190

    DPRINTF("execute_complete: qhaddr 0x%x, next %x, qtdaddr 0x%x, status %d\n",
G
Gerd Hoffmann 已提交
1191
            q->qhaddr, q->qh.next, q->qtdaddr, q->usb_status);
G
Gerd Hoffmann 已提交
1192

G
Gerd Hoffmann 已提交
1193 1194
    if (p->usb_status < 0) {
        switch (p->usb_status) {
H
Hans de Goede 已提交
1195
        case USB_RET_IOERROR:
G
Gerd Hoffmann 已提交
1196
        case USB_RET_NODEV:
G
Gerd Hoffmann 已提交
1197
            q->qh.token |= (QTD_TOKEN_HALT | QTD_TOKEN_XACTERR);
H
Hans de Goede 已提交
1198
            set_field(&q->qh.token, 0, QTD_TOKEN_CERR);
1199
            ehci_raise_irq(q->ehci, USBSTS_ERRINT);
G
Gerd Hoffmann 已提交
1200 1201
            break;
        case USB_RET_STALL:
G
Gerd Hoffmann 已提交
1202
            q->qh.token |= QTD_TOKEN_HALT;
1203
            ehci_raise_irq(q->ehci, USBSTS_ERRINT);
G
Gerd Hoffmann 已提交
1204 1205
            break;
        case USB_RET_NAK:
1206 1207
            set_field(&q->qh.altnext_qtd, 0, QH_ALTNEXT_NAKCNT);
            return; /* We're not done yet with this transaction */
G
Gerd Hoffmann 已提交
1208
        case USB_RET_BABBLE:
G
Gerd Hoffmann 已提交
1209
            q->qh.token |= (QTD_TOKEN_HALT | QTD_TOKEN_BABBLE);
1210
            ehci_raise_irq(q->ehci, USBSTS_ERRINT);
G
Gerd Hoffmann 已提交
1211 1212
            break;
        default:
G
Gerd Hoffmann 已提交
1213
            /* should not be triggerable */
G
Gerd Hoffmann 已提交
1214
            fprintf(stderr, "USB invalid response %d\n", p->usb_status);
G
Gerd Hoffmann 已提交
1215
            assert(0);
G
Gerd Hoffmann 已提交
1216 1217 1218 1219
            break;
        }
    } else {
        // TODO check 4.12 for splits
1220
        uint32_t tbytes = get_field(q->qh.token, QTD_TOKEN_TBYTES);
G
Gerd Hoffmann 已提交
1221

1222 1223
        if (tbytes && p->pid == USB_TOKEN_IN) {
            tbytes -= p->usb_status;
1224 1225 1226 1227
            if (tbytes) {
                /* 4.15.1.2 must raise int on a short input packet */
                ehci_raise_irq(q->ehci, USBSTS_INT);
            }
G
Gerd Hoffmann 已提交
1228
        } else {
1229
            tbytes = 0;
G
Gerd Hoffmann 已提交
1230 1231
        }

1232 1233
        DPRINTF("updating tbytes to %d\n", tbytes);
        set_field(&q->qh.token, tbytes, QTD_TOKEN_TBYTES);
G
Gerd Hoffmann 已提交
1234
    }
G
Gerd Hoffmann 已提交
1235
    ehci_finish_transfer(q, p->usb_status);
1236
    usb_packet_unmap(&p->packet, &p->sgl);
G
Gerd Hoffmann 已提交
1237
    qemu_sglist_destroy(&p->sgl);
1238
    p->async = EHCI_ASYNC_NONE;
G
Gerd Hoffmann 已提交
1239

G
Gerd Hoffmann 已提交
1240 1241
    q->qh.token ^= QTD_TOKEN_DTOGGLE;
    q->qh.token &= ~QTD_TOKEN_ACTIVE;
G
Gerd Hoffmann 已提交
1242

1243
    if (q->qh.token & QTD_TOKEN_IOC) {
1244
        ehci_raise_irq(q->ehci, USBSTS_INT);
1245 1246 1247
        if (q->async) {
            q->ehci->int_req_by_async = true;
        }
G
Gerd Hoffmann 已提交
1248 1249 1250 1251 1252
    }
}

// 4.10.3

G
Gerd Hoffmann 已提交
1253
static int ehci_execute(EHCIPacket *p, const char *action)
G
Gerd Hoffmann 已提交
1254
{
1255
    USBEndpoint *ep;
G
Gerd Hoffmann 已提交
1256
    int endp;
1257
    bool spd;
G
Gerd Hoffmann 已提交
1258

1259 1260 1261
    assert(p->async == EHCI_ASYNC_NONE ||
           p->async == EHCI_ASYNC_INITIALIZED);

1262 1263
    if (!(p->qtd.token & QTD_TOKEN_ACTIVE)) {
        fprintf(stderr, "Attempting to execute inactive qtd\n");
G
Gerd Hoffmann 已提交
1264 1265 1266
        return USB_RET_PROCERR;
    }

1267
    if (get_field(p->qtd.token, QTD_TOKEN_TBYTES) > BUFF_SIZE) {
1268 1269
        ehci_trace_guest_bug(p->queue->ehci,
                             "guest requested more bytes than allowed");
G
Gerd Hoffmann 已提交
1270 1271 1272
        return USB_RET_PROCERR;
    }

1273
    p->pid = (p->qtd.token & QTD_TOKEN_PID_MASK) >> QTD_TOKEN_PID_SH;
G
Gerd Hoffmann 已提交
1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286
    switch (p->pid) {
    case 0:
        p->pid = USB_TOKEN_OUT;
        break;
    case 1:
        p->pid = USB_TOKEN_IN;
        break;
    case 2:
        p->pid = USB_TOKEN_SETUP;
        break;
    default:
        fprintf(stderr, "bad token\n");
        break;
G
Gerd Hoffmann 已提交
1287 1288
    }

1289
    endp = get_field(p->queue->qh.epchar, QH_EPCHAR_EP);
1290
    ep = usb_ep_get(p->queue->dev, p->pid, endp);
G
Gerd Hoffmann 已提交
1291

1292 1293 1294 1295 1296
    if (p->async == EHCI_ASYNC_NONE) {
        if (ehci_init_transfer(p) != 0) {
            return USB_RET_PROCERR;
        }

1297
        spd = (p->pid == USB_TOKEN_IN && NLPTR_TBIT(p->qtd.altnext) == 0);
1298 1299
        usb_packet_setup(&p->packet, p->pid, ep, p->qtdaddr, spd,
                         (p->qtd.token & QTD_TOKEN_IOC) != 0);
1300 1301 1302
        usb_packet_map(&p->packet, &p->sgl);
        p->async = EHCI_ASYNC_INITIALIZED;
    }
1303

G
Gerd Hoffmann 已提交
1304
    trace_usb_ehci_packet_action(p->queue, p, action);
1305 1306 1307 1308 1309
    usb_handle_packet(p->queue->dev, &p->packet);
    DPRINTF("submit: qh 0x%x next 0x%x qtd 0x%x pid 0x%x len %zd endp 0x%x "
            "status %d actual_length %d\n", p->queue->qhaddr, p->qtd.next,
            p->qtdaddr, p->pid, p->packet.iov.size, endp, p->packet.status,
            p->packet.actual_length);
G
Gerd Hoffmann 已提交
1310

1311
    if (p->packet.actual_length > BUFF_SIZE) {
G
Gerd Hoffmann 已提交
1312 1313 1314 1315
        fprintf(stderr, "ret from usb_handle_packet > BUFF_SIZE\n");
        return USB_RET_PROCERR;
    }

1316 1317 1318 1319 1320
    if (p->packet.status == USB_RET_SUCCESS) {
        return p->packet.actual_length;
    } else {
        return p->packet.status;
    }
G
Gerd Hoffmann 已提交
1321 1322 1323 1324 1325 1326
}

/*  4.7.2
 */

static int ehci_process_itd(EHCIState *ehci,
G
Gerd Hoffmann 已提交
1327 1328
                            EHCIitd *itd,
                            uint32_t addr)
G
Gerd Hoffmann 已提交
1329 1330
{
    USBDevice *dev;
1331
    USBEndpoint *ep;
G
Gerd Hoffmann 已提交
1332
    int ret;
1333
    uint32_t i, len, pid, dir, devaddr, endp;
G
Gerd Hoffmann 已提交
1334
    uint32_t pg, off, ptr1, ptr2, max, mult;
G
Gerd Hoffmann 已提交
1335 1336

    dir =(itd->bufptr[1] & ITD_BUFPTR_DIRECTION);
G
Gerd Hoffmann 已提交
1337
    devaddr = get_field(itd->bufptr[0], ITD_BUFPTR_DEVADDR);
G
Gerd Hoffmann 已提交
1338
    endp = get_field(itd->bufptr[0], ITD_BUFPTR_EP);
G
Gerd Hoffmann 已提交
1339 1340
    max = get_field(itd->bufptr[1], ITD_BUFPTR_MAXPKT);
    mult = get_field(itd->bufptr[2], ITD_BUFPTR_MULT);
G
Gerd Hoffmann 已提交
1341 1342 1343

    for(i = 0; i < 8; i++) {
        if (itd->transact[i] & ITD_XACT_ACTIVE) {
G
Gerd Hoffmann 已提交
1344 1345 1346 1347 1348 1349 1350 1351 1352
            pg   = get_field(itd->transact[i], ITD_XACT_PGSEL);
            off  = itd->transact[i] & ITD_XACT_OFFSET_MASK;
            ptr1 = (itd->bufptr[pg] & ITD_BUFPTR_MASK);
            ptr2 = (itd->bufptr[pg+1] & ITD_BUFPTR_MASK);
            len  = get_field(itd->transact[i], ITD_XACT_LENGTH);

            if (len > max * mult) {
                len = max * mult;
            }
G
Gerd Hoffmann 已提交
1353 1354 1355 1356 1357

            if (len > BUFF_SIZE) {
                return USB_RET_PROCERR;
            }

1358
            qemu_sglist_init(&ehci->isgl, 2, ehci->dma);
G
Gerd Hoffmann 已提交
1359 1360
            if (off + len > 4096) {
                /* transfer crosses page border */
1361 1362 1363 1364
                uint32_t len2 = off + len - 4096;
                uint32_t len1 = len - len2;
                qemu_sglist_add(&ehci->isgl, ptr1 + off, len1);
                qemu_sglist_add(&ehci->isgl, ptr2, len2);
G
Gerd Hoffmann 已提交
1365
            } else {
1366
                qemu_sglist_add(&ehci->isgl, ptr1 + off, len);
G
Gerd Hoffmann 已提交
1367
            }
G
Gerd Hoffmann 已提交
1368

1369
            pid = dir ? USB_TOKEN_IN : USB_TOKEN_OUT;
G
Gerd Hoffmann 已提交
1370

1371 1372
            dev = ehci_find_device(ehci, devaddr);
            ep = usb_ep_get(dev, pid, endp);
1373
            if (ep && ep->type == USB_ENDPOINT_XFER_ISOC) {
1374 1375
                usb_packet_setup(&ehci->ipacket, pid, ep, addr, false,
                                 (itd->transact[i] & ITD_XACT_IOC) != 0);
G
Gerd Hoffmann 已提交
1376
                usb_packet_map(&ehci->ipacket, &ehci->isgl);
1377
                usb_handle_packet(dev, &ehci->ipacket);
1378
                usb_packet_unmap(&ehci->ipacket, &ehci->isgl);
1379 1380
                ret = (ehci->ipacket.status == USB_RET_SUCCESS) ?
                      ehci->ipacket.actual_length : ehci->ipacket.status;
G
Gerd Hoffmann 已提交
1381 1382 1383 1384
            } else {
                DPRINTF("ISOCH: attempt to addess non-iso endpoint\n");
                ret = USB_RET_NAK;
            }
1385 1386
            qemu_sglist_destroy(&ehci->isgl);

1387
            if (ret < 0) {
1388 1389 1390 1391
                switch (ret) {
                default:
                    fprintf(stderr, "Unexpected iso usb result: %d\n", ret);
                    /* Fall through */
H
Hans de Goede 已提交
1392
                case USB_RET_IOERROR:
1393 1394 1395 1396
                case USB_RET_NODEV:
                    /* 3.3.2: XACTERR is only allowed on IN transactions */
                    if (dir) {
                        itd->transact[i] |= ITD_XACT_XACTERR;
1397
                        ehci_raise_irq(ehci, USBSTS_ERRINT);
1398 1399 1400 1401
                    }
                    break;
                case USB_RET_BABBLE:
                    itd->transact[i] |= ITD_XACT_BABBLE;
1402
                    ehci_raise_irq(ehci, USBSTS_ERRINT);
1403
                    break;
1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415 1416
                case USB_RET_NAK:
                    /* no data for us, so do a zero-length transfer */
                    ret = 0;
                    break;
                }
            }
            if (ret >= 0) {
                if (!dir) {
                    /* OUT */
                    set_field(&itd->transact[i], len - ret, ITD_XACT_LENGTH);
                } else {
                    /* IN */
                    set_field(&itd->transact[i], ret, ITD_XACT_LENGTH);
G
Gerd Hoffmann 已提交
1417 1418
                }
            }
1419
            if (itd->transact[i] & ITD_XACT_IOC) {
1420
                ehci_raise_irq(ehci, USBSTS_INT);
1421
            }
G
Gerd Hoffmann 已提交
1422
            itd->transact[i] &= ~ITD_XACT_ACTIVE;
G
Gerd Hoffmann 已提交
1423 1424 1425 1426 1427
        }
    }
    return 0;
}

G
Gerd Hoffmann 已提交
1428

G
Gerd Hoffmann 已提交
1429 1430 1431
/*  This state is the entry point for asynchronous schedule
 *  processing.  Entry here consitutes a EHCI start event state (4.8.5)
 */
1432
static int ehci_state_waitlisthead(EHCIState *ehci,  int async)
G
Gerd Hoffmann 已提交
1433
{
G
Gerd Hoffmann 已提交
1434
    EHCIqh qh;
G
Gerd Hoffmann 已提交
1435 1436 1437 1438 1439 1440
    int i = 0;
    int again = 0;
    uint32_t entry = ehci->asynclistaddr;

    /* set reclamation flag at start event (4.8.6) */
    if (async) {
G
Gerd Hoffmann 已提交
1441
        ehci_set_usbsts(ehci, USBSTS_REC);
G
Gerd Hoffmann 已提交
1442 1443
    }

1444
    ehci_queues_rip_unused(ehci, async);
G
Gerd Hoffmann 已提交
1445

G
Gerd Hoffmann 已提交
1446 1447
    /*  Find the head of the list (4.9.1.1) */
    for(i = 0; i < MAX_QH; i++) {
1448 1449
        get_dwords(ehci, NLPTR_GET(entry), (uint32_t *) &qh,
                   sizeof(EHCIqh) >> 2);
G
Gerd Hoffmann 已提交
1450
        ehci_trace_qh(NULL, NLPTR_GET(entry), &qh);
G
Gerd Hoffmann 已提交
1451

G
Gerd Hoffmann 已提交
1452
        if (qh.epchar & QH_EPCHAR_H) {
G
Gerd Hoffmann 已提交
1453 1454 1455 1456
            if (async) {
                entry |= (NLPTR_TYPE_QH << 1);
            }

G
Gerd Hoffmann 已提交
1457
            ehci_set_fetch_addr(ehci, async, entry);
1458
            ehci_set_state(ehci, async, EST_FETCHENTRY);
G
Gerd Hoffmann 已提交
1459 1460 1461 1462
            again = 1;
            goto out;
        }

G
Gerd Hoffmann 已提交
1463
        entry = qh.next;
G
Gerd Hoffmann 已提交
1464 1465 1466 1467 1468 1469 1470
        if (entry == ehci->asynclistaddr) {
            break;
        }
    }

    /* no head found for list. */

1471
    ehci_set_state(ehci, async, EST_ACTIVE);
G
Gerd Hoffmann 已提交
1472 1473 1474 1475 1476 1477 1478 1479 1480

out:
    return again;
}


/*  This state is the entry point for periodic schedule processing as
 *  well as being a continuation state for async processing.
 */
1481
static int ehci_state_fetchentry(EHCIState *ehci, int async)
G
Gerd Hoffmann 已提交
1482 1483
{
    int again = 0;
G
Gerd Hoffmann 已提交
1484
    uint32_t entry = ehci_get_fetch_addr(ehci, async);
G
Gerd Hoffmann 已提交
1485

1486
    if (NLPTR_TBIT(entry)) {
1487
        ehci_set_state(ehci, async, EST_ACTIVE);
G
Gerd Hoffmann 已提交
1488 1489 1490 1491 1492 1493 1494 1495 1496 1497 1498
        goto out;
    }

    /* section 4.8, only QH in async schedule */
    if (async && (NLPTR_TYPE_GET(entry) != NLPTR_TYPE_QH)) {
        fprintf(stderr, "non queue head request in async schedule\n");
        return -1;
    }

    switch (NLPTR_TYPE_GET(entry)) {
    case NLPTR_TYPE_QH:
1499
        ehci_set_state(ehci, async, EST_FETCHQH);
G
Gerd Hoffmann 已提交
1500 1501 1502 1503
        again = 1;
        break;

    case NLPTR_TYPE_ITD:
1504
        ehci_set_state(ehci, async, EST_FETCHITD);
G
Gerd Hoffmann 已提交
1505 1506 1507
        again = 1;
        break;

G
Gerd Hoffmann 已提交
1508 1509 1510 1511 1512
    case NLPTR_TYPE_STITD:
        ehci_set_state(ehci, async, EST_FETCHSITD);
        again = 1;
        break;

G
Gerd Hoffmann 已提交
1513
    default:
G
Gerd Hoffmann 已提交
1514
        /* TODO: handle FSTN type */
G
Gerd Hoffmann 已提交
1515 1516 1517 1518 1519 1520 1521 1522 1523
        fprintf(stderr, "FETCHENTRY: entry at %X is of type %d "
                "which is not supported yet\n", entry, NLPTR_TYPE_GET(entry));
        return -1;
    }

out:
    return again;
}

G
Gerd Hoffmann 已提交
1524
static EHCIQueue *ehci_state_fetchqh(EHCIState *ehci, int async)
G
Gerd Hoffmann 已提交
1525
{
G
Gerd Hoffmann 已提交
1526
    EHCIPacket *p;
1527
    uint32_t entry, devaddr, endp;
G
Gerd Hoffmann 已提交
1528
    EHCIQueue *q;
1529
    EHCIqh qh;
G
Gerd Hoffmann 已提交
1530

G
Gerd Hoffmann 已提交
1531
    entry = ehci_get_fetch_addr(ehci, async);
1532
    q = ehci_find_queue_by_qh(ehci, entry, async);
G
Gerd Hoffmann 已提交
1533
    if (NULL == q) {
G
Gerd Hoffmann 已提交
1534
        q = ehci_alloc_queue(ehci, entry, async);
G
Gerd Hoffmann 已提交
1535
    }
G
Gerd Hoffmann 已提交
1536
    p = QTAILQ_FIRST(&q->packets);
G
Gerd Hoffmann 已提交
1537

G
Gerd Hoffmann 已提交
1538
    q->seen++;
G
Gerd Hoffmann 已提交
1539 1540 1541 1542 1543 1544
    if (q->seen > 1) {
        /* we are going in circles -- stop processing */
        ehci_set_state(ehci, async, EST_ACTIVE);
        q = NULL;
        goto out;
    }
G
Gerd Hoffmann 已提交
1545

1546
    get_dwords(ehci, NLPTR_GET(q->qhaddr),
1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560
               (uint32_t *) &qh, sizeof(EHCIqh) >> 2);
    ehci_trace_qh(q, NLPTR_GET(q->qhaddr), &qh);

    /*
     * The overlay area of the qh should never be changed by the guest,
     * except when idle, in which case the reset is a nop.
     */
    devaddr = get_field(qh.epchar, QH_EPCHAR_DEVADDR);
    endp    = get_field(qh.epchar, QH_EPCHAR_EP);
    if ((devaddr != get_field(q->qh.epchar, QH_EPCHAR_DEVADDR)) ||
        (endp    != get_field(q->qh.epchar, QH_EPCHAR_EP)) ||
        (memcmp(&qh.current_qtd, &q->qh.current_qtd,
                                 9 * sizeof(uint32_t)) != 0) ||
        (q->dev != NULL && q->dev->addr != devaddr)) {
G
Gerd Hoffmann 已提交
1561 1562 1563
        if (ehci_reset_queue(q) > 0) {
            ehci_trace_guest_bug(ehci, "guest updated active QH");
        }
1564 1565 1566 1567
        p = NULL;
    }
    q->qh = qh;

1568 1569 1570 1571 1572
    q->transact_ctr = get_field(q->qh.epcap, QH_EPCAP_MULT);
    if (q->transact_ctr == 0) { /* Guest bug in some versions of windows */
        q->transact_ctr = 4;
    }

1573 1574 1575 1576
    if (q->dev == NULL) {
        q->dev = ehci_find_device(q->ehci, devaddr);
    }

G
Gerd Hoffmann 已提交
1577
    if (p && p->async == EHCI_ASYNC_FINISHED) {
G
Gerd Hoffmann 已提交
1578
        /* I/O finished -- continue processing queue */
G
Gerd Hoffmann 已提交
1579
        trace_usb_ehci_packet_action(p->queue, p, "complete");
G
Gerd Hoffmann 已提交
1580 1581 1582
        ehci_set_state(ehci, async, EST_EXECUTING);
        goto out;
    }
G
Gerd Hoffmann 已提交
1583 1584

    if (async && (q->qh.epchar & QH_EPCHAR_H)) {
G
Gerd Hoffmann 已提交
1585 1586 1587

        /*  EHCI spec version 1.0 Section 4.8.3 & 4.10.1 */
        if (ehci->usbsts & USBSTS_REC) {
G
Gerd Hoffmann 已提交
1588
            ehci_clear_usbsts(ehci, USBSTS_REC);
G
Gerd Hoffmann 已提交
1589 1590
        } else {
            DPRINTF("FETCHQH:  QH 0x%08x. H-bit set, reclamation status reset"
G
Gerd Hoffmann 已提交
1591
                       " - done processing\n", q->qhaddr);
1592
            ehci_set_state(ehci, async, EST_ACTIVE);
G
Gerd Hoffmann 已提交
1593
            q = NULL;
G
Gerd Hoffmann 已提交
1594 1595 1596 1597 1598
            goto out;
        }
    }

#if EHCI_DEBUG
G
Gerd Hoffmann 已提交
1599
    if (q->qhaddr != q->qh.next) {
G
Gerd Hoffmann 已提交
1600
    DPRINTF("FETCHQH:  QH 0x%08x (h %x halt %x active %x) next 0x%08x\n",
G
Gerd Hoffmann 已提交
1601 1602 1603 1604 1605
               q->qhaddr,
               q->qh.epchar & QH_EPCHAR_H,
               q->qh.token & QTD_TOKEN_HALT,
               q->qh.token & QTD_TOKEN_ACTIVE,
               q->qh.next);
G
Gerd Hoffmann 已提交
1606 1607 1608
    }
#endif

G
Gerd Hoffmann 已提交
1609
    if (q->qh.token & QTD_TOKEN_HALT) {
1610
        ehci_set_state(ehci, async, EST_HORIZONTALQH);
G
Gerd Hoffmann 已提交
1611

1612 1613
    } else if ((q->qh.token & QTD_TOKEN_ACTIVE) &&
               (NLPTR_TBIT(q->qh.current_qtd) == 0)) {
G
Gerd Hoffmann 已提交
1614
        q->qtdaddr = q->qh.current_qtd;
1615
        ehci_set_state(ehci, async, EST_FETCHQTD);
G
Gerd Hoffmann 已提交
1616 1617 1618

    } else {
        /*  EHCI spec version 1.0 Section 4.10.2 */
1619
        ehci_set_state(ehci, async, EST_ADVANCEQUEUE);
G
Gerd Hoffmann 已提交
1620 1621 1622
    }

out:
G
Gerd Hoffmann 已提交
1623
    return q;
G
Gerd Hoffmann 已提交
1624 1625
}

1626
static int ehci_state_fetchitd(EHCIState *ehci, int async)
G
Gerd Hoffmann 已提交
1627
{
G
Gerd Hoffmann 已提交
1628
    uint32_t entry;
G
Gerd Hoffmann 已提交
1629 1630
    EHCIitd itd;

G
Gerd Hoffmann 已提交
1631 1632 1633
    assert(!async);
    entry = ehci_get_fetch_addr(ehci, async);

1634
    get_dwords(ehci, NLPTR_GET(entry), (uint32_t *) &itd,
G
Gerd Hoffmann 已提交
1635
               sizeof(EHCIitd) >> 2);
G
Gerd Hoffmann 已提交
1636
    ehci_trace_itd(ehci, entry, &itd);
G
Gerd Hoffmann 已提交
1637

G
Gerd Hoffmann 已提交
1638
    if (ehci_process_itd(ehci, &itd, entry) != 0) {
G
Gerd Hoffmann 已提交
1639 1640 1641
        return -1;
    }

1642 1643
    put_dwords(ehci, NLPTR_GET(entry), (uint32_t *) &itd,
               sizeof(EHCIitd) >> 2);
G
Gerd Hoffmann 已提交
1644
    ehci_set_fetch_addr(ehci, async, itd.next);
1645
    ehci_set_state(ehci, async, EST_FETCHENTRY);
G
Gerd Hoffmann 已提交
1646 1647 1648 1649

    return 1;
}

G
Gerd Hoffmann 已提交
1650 1651 1652 1653 1654 1655 1656 1657
static int ehci_state_fetchsitd(EHCIState *ehci, int async)
{
    uint32_t entry;
    EHCIsitd sitd;

    assert(!async);
    entry = ehci_get_fetch_addr(ehci, async);

1658
    get_dwords(ehci, NLPTR_GET(entry), (uint32_t *)&sitd,
G
Gerd Hoffmann 已提交
1659 1660 1661 1662 1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673
               sizeof(EHCIsitd) >> 2);
    ehci_trace_sitd(ehci, entry, &sitd);

    if (!(sitd.results & SITD_RESULTS_ACTIVE)) {
        /* siTD is not active, nothing to do */;
    } else {
        /* TODO: split transfers are not implemented */
        fprintf(stderr, "WARNING: Skipping active siTD\n");
    }

    ehci_set_fetch_addr(ehci, async, sitd.next);
    ehci_set_state(ehci, async, EST_FETCHENTRY);
    return 1;
}

G
Gerd Hoffmann 已提交
1674
/* Section 4.10.2 - paragraph 3 */
1675
static int ehci_state_advqueue(EHCIQueue *q)
G
Gerd Hoffmann 已提交
1676 1677 1678 1679 1680 1681 1682
{
#if 0
    /* TO-DO: 4.10.2 - paragraph 2
     * if I-bit is set to 1 and QH is not active
     * go to horizontal QH
     */
    if (I-bit set) {
1683
        ehci_set_state(ehci, async, EST_HORIZONTALQH);
G
Gerd Hoffmann 已提交
1684 1685 1686 1687 1688 1689 1690
        goto out;
    }
#endif

    /*
     * want data and alt-next qTD is valid
     */
G
Gerd Hoffmann 已提交
1691 1692 1693
    if (((q->qh.token & QTD_TOKEN_TBYTES_MASK) != 0) &&
        (NLPTR_TBIT(q->qh.altnext_qtd) == 0)) {
        q->qtdaddr = q->qh.altnext_qtd;
1694
        ehci_set_state(q->ehci, q->async, EST_FETCHQTD);
G
Gerd Hoffmann 已提交
1695 1696 1697 1698

    /*
     *  next qTD is valid
     */
1699
    } else if (NLPTR_TBIT(q->qh.next_qtd) == 0) {
G
Gerd Hoffmann 已提交
1700
        q->qtdaddr = q->qh.next_qtd;
1701
        ehci_set_state(q->ehci, q->async, EST_FETCHQTD);
G
Gerd Hoffmann 已提交
1702 1703 1704 1705 1706

    /*
     *  no valid qTD, try next QH
     */
    } else {
1707
        ehci_set_state(q->ehci, q->async, EST_HORIZONTALQH);
G
Gerd Hoffmann 已提交
1708 1709 1710 1711 1712 1713
    }

    return 1;
}

/* Section 4.10.2 - paragraph 4 */
1714
static int ehci_state_fetchqtd(EHCIQueue *q)
G
Gerd Hoffmann 已提交
1715
{
G
Gerd Hoffmann 已提交
1716 1717
    EHCIqtd qtd;
    EHCIPacket *p;
1718
    int again = 1;
G
Gerd Hoffmann 已提交
1719

G
Gerd Hoffmann 已提交
1720
    get_dwords(q->ehci, NLPTR_GET(q->qtdaddr), (uint32_t *) &qtd,
1721
               sizeof(EHCIqtd) >> 2);
G
Gerd Hoffmann 已提交
1722
    ehci_trace_qtd(q, NLPTR_GET(q->qtdaddr), &qtd);
G
Gerd Hoffmann 已提交
1723

G
Gerd Hoffmann 已提交
1724 1725
    p = QTAILQ_FIRST(&q->packets);
    if (p != NULL) {
1726 1727 1728 1729 1730
        if (p->qtdaddr != q->qtdaddr ||
            (!NLPTR_TBIT(p->qtd.next) && (p->qtd.next != qtd.next)) ||
            (!NLPTR_TBIT(p->qtd.altnext) && (p->qtd.altnext != qtd.altnext)) ||
            p->qtd.bufptr[0] != qtd.bufptr[0]) {
            ehci_cancel_queue(q);
G
Gerd Hoffmann 已提交
1731
            ehci_trace_guest_bug(q->ehci, "guest updated active QH or qTD");
1732 1733 1734 1735 1736 1737 1738 1739 1740 1741 1742 1743 1744 1745 1746
            p = NULL;
        } else {
            p->qtd = qtd;
            ehci_qh_do_overlay(q);
        }
    }

    if (!(qtd.token & QTD_TOKEN_ACTIVE)) {
        if (p != NULL) {
            /* transfer canceled by guest (clear active) */
            ehci_cancel_queue(q);
            p = NULL;
        }
        ehci_set_state(q->ehci, q->async, EST_HORIZONTALQH);
    } else if (p != NULL) {
1747 1748
        switch (p->async) {
        case EHCI_ASYNC_NONE:
1749
        case EHCI_ASYNC_INITIALIZED:
1750
            /* Not yet executed (MULT), or previously nacked (int) packet */
1751 1752
            ehci_set_state(q->ehci, q->async, EST_EXECUTE);
            break;
1753
        case EHCI_ASYNC_INFLIGHT:
1754 1755 1756
            /* Check if the guest has added new tds to the queue */
            again = (ehci_fill_queue(QTAILQ_LAST(&q->packets, pkts_head)) ==
                     USB_RET_PROCERR) ? -1 : 1;
1757
            /* Unfinished async handled packet, go horizontal */
1758
            ehci_set_state(q->ehci, q->async, EST_HORIZONTALQH);
1759 1760
            break;
        case EHCI_ASYNC_FINISHED:
1761 1762 1763 1764
            /*
             * We get here when advqueue moves to a packet which is already
             * finished, which can happen with packets queued up by fill_queue
             */
1765
            ehci_set_state(q->ehci, q->async, EST_EXECUTING);
1766
            break;
G
Gerd Hoffmann 已提交
1767
        }
1768
    } else {
G
Gerd Hoffmann 已提交
1769 1770 1771
        p = ehci_alloc_packet(q);
        p->qtdaddr = q->qtdaddr;
        p->qtd = qtd;
1772
        ehci_set_state(q->ehci, q->async, EST_EXECUTE);
G
Gerd Hoffmann 已提交
1773 1774 1775 1776 1777
    }

    return again;
}

1778
static int ehci_state_horizqh(EHCIQueue *q)
G
Gerd Hoffmann 已提交
1779 1780 1781
{
    int again = 0;

1782 1783 1784
    if (ehci_get_fetch_addr(q->ehci, q->async) != q->qh.next) {
        ehci_set_fetch_addr(q->ehci, q->async, q->qh.next);
        ehci_set_state(q->ehci, q->async, EST_FETCHENTRY);
G
Gerd Hoffmann 已提交
1785 1786
        again = 1;
    } else {
1787
        ehci_set_state(q->ehci, q->async, EST_ACTIVE);
G
Gerd Hoffmann 已提交
1788 1789 1790 1791 1792
    }

    return again;
}

1793
static int ehci_fill_queue(EHCIPacket *p)
G
Gerd Hoffmann 已提交
1794
{
1795
    USBEndpoint *ep = p->packet.ep;
G
Gerd Hoffmann 已提交
1796 1797
    EHCIQueue *q = p->queue;
    EHCIqtd qtd = p->qtd;
1798
    uint32_t qtdaddr, start_addr = p->qtdaddr;
G
Gerd Hoffmann 已提交
1799 1800 1801 1802 1803 1804

    for (;;) {
        if (NLPTR_TBIT(qtd.next) != 0) {
            break;
        }
        qtdaddr = qtd.next;
1805 1806 1807 1808 1809 1810 1811
        /*
         * Detect circular td lists, Windows creates these, counting on the
         * active bit going low after execution to make the queue stop.
         */
        if (qtdaddr == start_addr) {
            break;
        }
G
Gerd Hoffmann 已提交
1812 1813 1814 1815 1816 1817 1818 1819 1820 1821
        get_dwords(q->ehci, NLPTR_GET(qtdaddr),
                   (uint32_t *) &qtd, sizeof(EHCIqtd) >> 2);
        ehci_trace_qtd(q, NLPTR_GET(qtdaddr), &qtd);
        if (!(qtd.token & QTD_TOKEN_ACTIVE)) {
            break;
        }
        p = ehci_alloc_packet(q);
        p->qtdaddr = qtdaddr;
        p->qtd = qtd;
        p->usb_status = ehci_execute(p, "queue");
1822 1823 1824
        if (p->usb_status == USB_RET_PROCERR) {
            break;
        }
1825
        assert(p->usb_status == USB_RET_ASYNC);
G
Gerd Hoffmann 已提交
1826 1827
        p->async = EHCI_ASYNC_INFLIGHT;
    }
1828 1829 1830
    if (p->usb_status != USB_RET_PROCERR) {
        usb_device_flush_ep_queue(ep->dev, ep);
    }
1831
    return p->usb_status;
G
Gerd Hoffmann 已提交
1832 1833
}

1834
static int ehci_state_execute(EHCIQueue *q)
G
Gerd Hoffmann 已提交
1835
{
G
Gerd Hoffmann 已提交
1836
    EHCIPacket *p = QTAILQ_FIRST(&q->packets);
G
Gerd Hoffmann 已提交
1837 1838
    int again = 0;

G
Gerd Hoffmann 已提交
1839 1840 1841
    assert(p != NULL);
    assert(p->qtdaddr == q->qtdaddr);

G
Gerd Hoffmann 已提交
1842
    if (ehci_qh_do_overlay(q) != 0) {
G
Gerd Hoffmann 已提交
1843 1844 1845 1846 1847 1848
        return -1;
    }

    // TODO verify enough time remains in the uframe as in 4.4.1.1
    // TODO write back ptr to async list when done or out of time

1849 1850 1851 1852 1853
    /* 4.10.3, bottom of page 82, go horizontal on transaction counter == 0 */
    if (!q->async && q->transact_ctr == 0) {
        ehci_set_state(q->ehci, q->async, EST_HORIZONTALQH);
        again = 1;
        goto out;
G
Gerd Hoffmann 已提交
1854 1855
    }

1856
    if (q->async) {
G
Gerd Hoffmann 已提交
1857
        ehci_set_usbsts(q->ehci, USBSTS_REC);
G
Gerd Hoffmann 已提交
1858 1859
    }

G
Gerd Hoffmann 已提交
1860
    p->usb_status = ehci_execute(p, "process");
G
Gerd Hoffmann 已提交
1861
    if (p->usb_status == USB_RET_PROCERR) {
G
Gerd Hoffmann 已提交
1862 1863 1864
        again = -1;
        goto out;
    }
G
Gerd Hoffmann 已提交
1865
    if (p->usb_status == USB_RET_ASYNC) {
G
Gerd Hoffmann 已提交
1866
        ehci_flush_qh(q);
G
Gerd Hoffmann 已提交
1867
        trace_usb_ehci_packet_action(p->queue, p, "async");
G
Gerd Hoffmann 已提交
1868
        p->async = EHCI_ASYNC_INFLIGHT;
1869
        ehci_set_state(q->ehci, q->async, EST_HORIZONTALQH);
1870 1871 1872 1873 1874
        if (q->async) {
            again = (ehci_fill_queue(p) == USB_RET_PROCERR) ? -1 : 1;
        } else {
            again = 1;
        }
G
Gerd Hoffmann 已提交
1875
        goto out;
G
Gerd Hoffmann 已提交
1876 1877
    }

1878
    ehci_set_state(q->ehci, q->async, EST_EXECUTING);
G
Gerd Hoffmann 已提交
1879 1880
    again = 1;

G
Gerd Hoffmann 已提交
1881 1882 1883 1884
out:
    return again;
}

1885
static int ehci_state_executing(EHCIQueue *q)
G
Gerd Hoffmann 已提交
1886
{
G
Gerd Hoffmann 已提交
1887
    EHCIPacket *p = QTAILQ_FIRST(&q->packets);
G
Gerd Hoffmann 已提交
1888

G
Gerd Hoffmann 已提交
1889 1890 1891
    assert(p != NULL);
    assert(p->qtdaddr == q->qtdaddr);

G
Gerd Hoffmann 已提交
1892
    ehci_execute_complete(q);
G
Gerd Hoffmann 已提交
1893

1894 1895 1896
    /* 4.10.3 */
    if (!q->async && q->transact_ctr > 0) {
        q->transact_ctr--;
G
Gerd Hoffmann 已提交
1897 1898 1899
    }

    /* 4.10.5 */
G
Gerd Hoffmann 已提交
1900
    if (p->usb_status == USB_RET_NAK) {
1901
        ehci_set_state(q->ehci, q->async, EST_HORIZONTALQH);
G
Gerd Hoffmann 已提交
1902
    } else {
1903
        ehci_set_state(q->ehci, q->async, EST_WRITEBACK);
G
Gerd Hoffmann 已提交
1904 1905
    }

G
Gerd Hoffmann 已提交
1906
    ehci_flush_qh(q);
1907
    return 1;
G
Gerd Hoffmann 已提交
1908 1909 1910
}


1911
static int ehci_state_writeback(EHCIQueue *q)
G
Gerd Hoffmann 已提交
1912
{
G
Gerd Hoffmann 已提交
1913
    EHCIPacket *p = QTAILQ_FIRST(&q->packets);
G
Gerd Hoffmann 已提交
1914
    uint32_t *qtd, addr;
G
Gerd Hoffmann 已提交
1915 1916 1917
    int again = 0;

    /*  Write back the QTD from the QH area */
G
Gerd Hoffmann 已提交
1918 1919 1920 1921
    assert(p != NULL);
    assert(p->qtdaddr == q->qtdaddr);

    ehci_trace_qtd(q, NLPTR_GET(p->qtdaddr), (EHCIqtd *) &q->qh.next_qtd);
G
Gerd Hoffmann 已提交
1922 1923 1924
    qtd = (uint32_t *) &q->qh.next_qtd;
    addr = NLPTR_GET(p->qtdaddr);
    put_dwords(q->ehci, addr + 2 * sizeof(uint32_t), qtd + 2, 2);
G
Gerd Hoffmann 已提交
1925
    ehci_free_packet(p);
G
Gerd Hoffmann 已提交
1926

G
Gerd Hoffmann 已提交
1927 1928 1929 1930 1931 1932 1933
    /*
     * EHCI specs say go horizontal here.
     *
     * We can also advance the queue here for performance reasons.  We
     * need to take care to only take that shortcut in case we've
     * processed the qtd just written back without errors, i.e. halt
     * bit is clear.
G
Gerd Hoffmann 已提交
1934
     */
G
Gerd Hoffmann 已提交
1935
    if (q->qh.token & QTD_TOKEN_HALT) {
1936
        ehci_set_state(q->ehci, q->async, EST_HORIZONTALQH);
G
Gerd Hoffmann 已提交
1937 1938
        again = 1;
    } else {
1939
        ehci_set_state(q->ehci, q->async, EST_ADVANCEQUEUE);
G
Gerd Hoffmann 已提交
1940
        again = 1;
G
Gerd Hoffmann 已提交
1941
    }
G
Gerd Hoffmann 已提交
1942 1943 1944 1945 1946 1947 1948
    return again;
}

/*
 * This is the state machine that is common to both async and periodic
 */

1949
static void ehci_advance_state(EHCIState *ehci, int async)
G
Gerd Hoffmann 已提交
1950
{
G
Gerd Hoffmann 已提交
1951
    EHCIQueue *q = NULL;
G
Gerd Hoffmann 已提交
1952 1953 1954
    int again;

    do {
1955
        switch(ehci_get_state(ehci, async)) {
G
Gerd Hoffmann 已提交
1956
        case EST_WAITLISTHEAD:
1957
            again = ehci_state_waitlisthead(ehci, async);
G
Gerd Hoffmann 已提交
1958 1959 1960
            break;

        case EST_FETCHENTRY:
1961
            again = ehci_state_fetchentry(ehci, async);
G
Gerd Hoffmann 已提交
1962 1963 1964
            break;

        case EST_FETCHQH:
G
Gerd Hoffmann 已提交
1965
            q = ehci_state_fetchqh(ehci, async);
1966 1967 1968 1969 1970 1971
            if (q != NULL) {
                assert(q->async == async);
                again = 1;
            } else {
                again = 0;
            }
G
Gerd Hoffmann 已提交
1972 1973 1974
            break;

        case EST_FETCHITD:
1975
            again = ehci_state_fetchitd(ehci, async);
G
Gerd Hoffmann 已提交
1976 1977
            break;

G
Gerd Hoffmann 已提交
1978 1979 1980 1981
        case EST_FETCHSITD:
            again = ehci_state_fetchsitd(ehci, async);
            break;

G
Gerd Hoffmann 已提交
1982
        case EST_ADVANCEQUEUE:
1983
            again = ehci_state_advqueue(q);
G
Gerd Hoffmann 已提交
1984 1985 1986
            break;

        case EST_FETCHQTD:
1987
            again = ehci_state_fetchqtd(q);
G
Gerd Hoffmann 已提交
1988 1989 1990
            break;

        case EST_HORIZONTALQH:
1991
            again = ehci_state_horizqh(q);
G
Gerd Hoffmann 已提交
1992 1993 1994
            break;

        case EST_EXECUTE:
1995
            again = ehci_state_execute(q);
G
Gerd Hoffmann 已提交
1996 1997 1998
            if (async) {
                ehci->async_stepdown = 0;
            }
G
Gerd Hoffmann 已提交
1999 2000 2001
            break;

        case EST_EXECUTING:
G
Gerd Hoffmann 已提交
2002
            assert(q != NULL);
G
Gerd Hoffmann 已提交
2003 2004 2005
            if (async) {
                ehci->async_stepdown = 0;
            }
2006
            again = ehci_state_executing(q);
G
Gerd Hoffmann 已提交
2007 2008 2009
            break;

        case EST_WRITEBACK:
G
Gerd Hoffmann 已提交
2010
            assert(q != NULL);
2011
            again = ehci_state_writeback(q);
G
Gerd Hoffmann 已提交
2012 2013 2014 2015 2016
            break;

        default:
            fprintf(stderr, "Bad state!\n");
            again = -1;
G
Gerd Hoffmann 已提交
2017
            assert(0);
G
Gerd Hoffmann 已提交
2018 2019 2020 2021 2022 2023 2024 2025 2026 2027 2028 2029 2030 2031
            break;
        }

        if (again < 0) {
            fprintf(stderr, "processing error - resetting ehci HC\n");
            ehci_reset(ehci);
            again = 0;
        }
    }
    while (again);
}

static void ehci_advance_async_state(EHCIState *ehci)
{
2032
    const int async = 1;
G
Gerd Hoffmann 已提交
2033

2034
    switch(ehci_get_state(ehci, async)) {
G
Gerd Hoffmann 已提交
2035
    case EST_INACTIVE:
2036
        if (!ehci_async_enabled(ehci)) {
G
Gerd Hoffmann 已提交
2037 2038
            break;
        }
2039
        ehci_set_state(ehci, async, EST_ACTIVE);
G
Gerd Hoffmann 已提交
2040 2041 2042
        // No break, fall through to ACTIVE

    case EST_ACTIVE:
2043
        if (!ehci_async_enabled(ehci)) {
2044
            ehci_queues_rip_all(ehci, async);
2045
            ehci_set_state(ehci, async, EST_INACTIVE);
G
Gerd Hoffmann 已提交
2046 2047 2048
            break;
        }

2049
        /* make sure guest has acknowledged the doorbell interrupt */
G
Gerd Hoffmann 已提交
2050 2051 2052 2053 2054 2055 2056 2057 2058 2059 2060
        /* TO-DO: is this really needed? */
        if (ehci->usbsts & USBSTS_IAA) {
            DPRINTF("IAA status bit still set.\n");
            break;
        }

        /* check that address register has been set */
        if (ehci->asynclistaddr == 0) {
            break;
        }

2061 2062
        ehci_set_state(ehci, async, EST_WAITLISTHEAD);
        ehci_advance_state(ehci, async);
2063 2064 2065 2066 2067 2068 2069

        /* If the doorbell is set, the guest wants to make a change to the
         * schedule. The host controller needs to release cached data.
         * (section 4.8.2)
         */
        if (ehci->usbcmd & USBCMD_IAAD) {
            /* Remove all unseen qhs from the async qhs queue */
2070
            ehci_queues_rip_unseen(ehci, async);
G
Gerd Hoffmann 已提交
2071
            trace_usb_ehci_doorbell_ack();
2072
            ehci->usbcmd &= ~USBCMD_IAAD;
2073
            ehci_raise_irq(ehci, USBSTS_IAA);
2074
        }
G
Gerd Hoffmann 已提交
2075 2076 2077 2078 2079 2080
        break;

    default:
        /* this should only be due to a developer mistake */
        fprintf(stderr, "ehci: Bad asynchronous state %d. "
                "Resetting to active\n", ehci->astate);
G
Gerd Hoffmann 已提交
2081
        assert(0);
G
Gerd Hoffmann 已提交
2082 2083 2084 2085 2086 2087 2088
    }
}

static void ehci_advance_periodic_state(EHCIState *ehci)
{
    uint32_t entry;
    uint32_t list;
2089
    const int async = 0;
G
Gerd Hoffmann 已提交
2090 2091 2092

    // 4.6

2093
    switch(ehci_get_state(ehci, async)) {
G
Gerd Hoffmann 已提交
2094
    case EST_INACTIVE:
2095
        if (!(ehci->frindex & 7) && ehci_periodic_enabled(ehci)) {
2096
            ehci_set_state(ehci, async, EST_ACTIVE);
G
Gerd Hoffmann 已提交
2097 2098 2099 2100 2101
            // No break, fall through to ACTIVE
        } else
            break;

    case EST_ACTIVE:
2102
        if (!(ehci->frindex & 7) && !ehci_periodic_enabled(ehci)) {
2103
            ehci_queues_rip_all(ehci, async);
2104
            ehci_set_state(ehci, async, EST_INACTIVE);
G
Gerd Hoffmann 已提交
2105 2106 2107 2108 2109 2110 2111 2112 2113 2114
            break;
        }

        list = ehci->periodiclistbase & 0xfffff000;
        /* check that register has been set */
        if (list == 0) {
            break;
        }
        list |= ((ehci->frindex & 0x1ff8) >> 1);

2115
        dma_memory_read(ehci->dma, list, &entry, sizeof entry);
G
Gerd Hoffmann 已提交
2116 2117 2118 2119
        entry = le32_to_cpu(entry);

        DPRINTF("PERIODIC state adv fr=%d.  [%08X] -> %08X\n",
                ehci->frindex / 8, list, entry);
G
Gerd Hoffmann 已提交
2120
        ehci_set_fetch_addr(ehci, async,entry);
2121 2122
        ehci_set_state(ehci, async, EST_FETCHENTRY);
        ehci_advance_state(ehci, async);
2123
        ehci_queues_rip_unused(ehci, async);
G
Gerd Hoffmann 已提交
2124 2125 2126 2127 2128 2129
        break;

    default:
        /* this should only be due to a developer mistake */
        fprintf(stderr, "ehci: Bad periodic state %d. "
                "Resetting to active\n", ehci->pstate);
G
Gerd Hoffmann 已提交
2130
        assert(0);
G
Gerd Hoffmann 已提交
2131 2132 2133
    }
}

G
Gerd Hoffmann 已提交
2134 2135 2136 2137 2138 2139 2140 2141 2142 2143 2144 2145
static void ehci_update_frindex(EHCIState *ehci, int frames)
{
    int i;

    if (!ehci_enabled(ehci)) {
        return;
    }

    for (i = 0; i < frames; i++) {
        ehci->frindex += 8;

        if (ehci->frindex == 0x00002000) {
2146
            ehci_raise_irq(ehci, USBSTS_FLR);
G
Gerd Hoffmann 已提交
2147 2148 2149
        }

        if (ehci->frindex == 0x00004000) {
2150
            ehci_raise_irq(ehci, USBSTS_FLR);
G
Gerd Hoffmann 已提交
2151
            ehci->frindex = 0;
2152
            if (ehci->usbsts_frindex >= 0x00004000) {
2153 2154 2155 2156
                ehci->usbsts_frindex -= 0x00004000;
            } else {
                ehci->usbsts_frindex = 0;
            }
G
Gerd Hoffmann 已提交
2157 2158 2159 2160
        }
    }
}

G
Gerd Hoffmann 已提交
2161 2162 2163
static void ehci_frame_timer(void *opaque)
{
    EHCIState *ehci = opaque;
2164
    int need_timer = 0;
G
Gerd Hoffmann 已提交
2165
    int64_t expire_time, t_now;
G
Gerd Hoffmann 已提交
2166
    uint64_t ns_elapsed;
G
Gerd Hoffmann 已提交
2167
    int frames, skipped_frames;
G
Gerd Hoffmann 已提交
2168 2169 2170
    int i;

    t_now = qemu_get_clock_ns(vm_clock);
G
Gerd Hoffmann 已提交
2171 2172
    ns_elapsed = t_now - ehci->last_run_ns;
    frames = ns_elapsed / FRAME_TIMER_NS;
G
Gerd Hoffmann 已提交
2173

G
Gerd Hoffmann 已提交
2174
    if (ehci_periodic_enabled(ehci) || ehci->pstate != EST_INACTIVE) {
2175
        need_timer++;
2176
        ehci->async_stepdown = 0;
G
Gerd Hoffmann 已提交
2177

G
Gerd Hoffmann 已提交
2178 2179 2180 2181 2182 2183 2184 2185
        if (frames > ehci->maxframes) {
            skipped_frames = frames - ehci->maxframes;
            ehci_update_frindex(ehci, skipped_frames);
            ehci->last_run_ns += FRAME_TIMER_NS * skipped_frames;
            frames -= skipped_frames;
            DPRINTF("WARNING - EHCI skipped %d frames\n", skipped_frames);
        }

G
Gerd Hoffmann 已提交
2186
        for (i = 0; i < frames; i++) {
2187 2188 2189 2190 2191 2192 2193 2194 2195 2196 2197 2198 2199
            /*
             * If we're running behind schedule, we should not catch up
             * too fast, as that will make some guests unhappy:
             * 1) We must process a minimum of MIN_FR_PER_TICK frames,
             *    otherwise we will never catch up
             * 2) Process frames until the guest has requested an irq (IOC)
             */
            if (i >= MIN_FR_PER_TICK) {
                ehci_commit_irq(ehci);
                if ((ehci->usbsts & USBINTR_MASK) & ehci->usbintr) {
                    break;
                }
            }
G
Gerd Hoffmann 已提交
2200
            ehci_update_frindex(ehci, 1);
G
Gerd Hoffmann 已提交
2201
            ehci_advance_periodic_state(ehci);
G
Gerd Hoffmann 已提交
2202 2203 2204 2205 2206 2207 2208 2209
            ehci->last_run_ns += FRAME_TIMER_NS;
        }
    } else {
        if (ehci->async_stepdown < ehci->maxframes / 2) {
            ehci->async_stepdown++;
        }
        ehci_update_frindex(ehci, frames);
        ehci->last_run_ns += FRAME_TIMER_NS * frames;
G
Gerd Hoffmann 已提交
2210 2211 2212 2213 2214
    }

    /*  Async is not inside loop since it executes everything it can once
     *  called
     */
G
Gerd Hoffmann 已提交
2215
    if (ehci_async_enabled(ehci) || ehci->astate != EST_INACTIVE) {
2216
        need_timer++;
2217
        ehci_advance_async_state(ehci);
G
Gerd Hoffmann 已提交
2218
    }
G
Gerd Hoffmann 已提交
2219

2220 2221 2222 2223
    ehci_commit_irq(ehci);
    if (ehci->usbsts_pending) {
        need_timer++;
        ehci->async_stepdown = 0;
G
Gerd Hoffmann 已提交
2224
    }
2225

2226
    if (need_timer) {
2227 2228 2229 2230 2231 2232 2233
        /* If we've raised int, we speed up the timer, so that we quickly
         * notice any new packets queued up in response */
        if (ehci->int_req_by_async && (ehci->usbsts & USBSTS_INT)) {
            expire_time = t_now + get_ticks_per_sec() / (FRAME_TIMER_FREQ * 2);
            ehci->int_req_by_async = false;
        } else {
            expire_time = t_now + (get_ticks_per_sec()
2234
                               * (ehci->async_stepdown+1) / FRAME_TIMER_FREQ);
2235
        }
2236 2237
        qemu_mod_timer(ehci->frame_timer, expire_time);
    }
G
Gerd Hoffmann 已提交
2238 2239
}

2240 2241 2242 2243 2244 2245 2246 2247 2248 2249 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259 2260 2261
static const MemoryRegionOps ehci_mmio_caps_ops = {
    .read = ehci_caps_read,
    .valid.min_access_size = 1,
    .valid.max_access_size = 4,
    .impl.min_access_size = 1,
    .impl.max_access_size = 1,
    .endianness = DEVICE_LITTLE_ENDIAN,
};

static const MemoryRegionOps ehci_mmio_opreg_ops = {
    .read = ehci_opreg_read,
    .write = ehci_opreg_write,
    .valid.min_access_size = 4,
    .valid.max_access_size = 4,
    .endianness = DEVICE_LITTLE_ENDIAN,
};

static const MemoryRegionOps ehci_mmio_port_ops = {
    .read = ehci_port_read,
    .write = ehci_port_write,
    .valid.min_access_size = 4,
    .valid.max_access_size = 4,
A
Avi Kivity 已提交
2262
    .endianness = DEVICE_LITTLE_ENDIAN,
G
Gerd Hoffmann 已提交
2263 2264 2265 2266 2267
};

static USBPortOps ehci_port_ops = {
    .attach = ehci_attach,
    .detach = ehci_detach,
2268
    .child_detach = ehci_child_detach,
2269
    .wakeup = ehci_wakeup,
G
Gerd Hoffmann 已提交
2270 2271 2272
    .complete = ehci_async_complete_packet,
};

2273
static USBBusOps ehci_bus_ops = {
2274
    .register_companion = ehci_register_companion,
2275 2276
};

G
Gerd Hoffmann 已提交
2277 2278 2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291 2292 2293 2294 2295 2296
static int usb_ehci_post_load(void *opaque, int version_id)
{
    EHCIState *s = opaque;
    int i;

    for (i = 0; i < NB_PORTS; i++) {
        USBPort *companion = s->companion_ports[i];
        if (companion == NULL) {
            continue;
        }
        if (s->portsc[i] & PORTSC_POWNER) {
            companion->dev = s->ports[i].dev;
        } else {
            companion->dev = NULL;
        }
    }

    return 0;
}

2297 2298 2299 2300 2301 2302 2303 2304 2305 2306 2307 2308 2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322
static void usb_ehci_vm_state_change(void *opaque, int running, RunState state)
{
    EHCIState *ehci = opaque;

    /*
     * We don't migrate the EHCIQueue-s, instead we rebuild them for the
     * schedule in guest memory. We must do the rebuilt ASAP, so that
     * USB-devices which have async handled packages have a packet in the
     * ep queue to match the completion with.
     */
    if (state == RUN_STATE_RUNNING) {
        ehci_advance_async_state(ehci);
    }

    /*
     * The schedule rebuilt from guest memory could cause the migration dest
     * to miss a QH unlink, and fail to cancel packets, since the unlinked QH
     * will never have existed on the destination. Therefor we must flush the
     * async schedule on savevm to catch any not yet noticed unlinks.
     */
    if (state == RUN_STATE_SAVE_VM) {
        ehci_advance_async_state(ehci);
        ehci_queues_rip_unseen(ehci, 1);
    }
}

2323
const VMStateDescription vmstate_ehci = {
P
Peter Crosthwaite 已提交
2324
    .name        = "ehci-core",
2325 2326
    .version_id  = 2,
    .minimum_version_id  = 1,
G
Gerd Hoffmann 已提交
2327 2328 2329 2330 2331
    .post_load   = usb_ehci_post_load,
    .fields      = (VMStateField[]) {
        /* mmio registers */
        VMSTATE_UINT32(usbcmd, EHCIState),
        VMSTATE_UINT32(usbsts, EHCIState),
2332 2333
        VMSTATE_UINT32_V(usbsts_pending, EHCIState, 2),
        VMSTATE_UINT32_V(usbsts_frindex, EHCIState, 2),
G
Gerd Hoffmann 已提交
2334 2335 2336 2337 2338 2339 2340 2341 2342 2343 2344 2345 2346 2347 2348 2349 2350 2351 2352 2353 2354 2355 2356
        VMSTATE_UINT32(usbintr, EHCIState),
        VMSTATE_UINT32(frindex, EHCIState),
        VMSTATE_UINT32(ctrldssegment, EHCIState),
        VMSTATE_UINT32(periodiclistbase, EHCIState),
        VMSTATE_UINT32(asynclistaddr, EHCIState),
        VMSTATE_UINT32(configflag, EHCIState),
        VMSTATE_UINT32(portsc[0], EHCIState),
        VMSTATE_UINT32(portsc[1], EHCIState),
        VMSTATE_UINT32(portsc[2], EHCIState),
        VMSTATE_UINT32(portsc[3], EHCIState),
        VMSTATE_UINT32(portsc[4], EHCIState),
        VMSTATE_UINT32(portsc[5], EHCIState),
        /* frame timer */
        VMSTATE_TIMER(frame_timer, EHCIState),
        VMSTATE_UINT64(last_run_ns, EHCIState),
        VMSTATE_UINT32(async_stepdown, EHCIState),
        /* schedule state */
        VMSTATE_UINT32(astate, EHCIState),
        VMSTATE_UINT32(pstate, EHCIState),
        VMSTATE_UINT32(a_fetch_addr, EHCIState),
        VMSTATE_UINT32(p_fetch_addr, EHCIState),
        VMSTATE_END_OF_LIST()
    }
G
Gerd Hoffmann 已提交
2357 2358
};

2359
void usb_ehci_initfn(EHCIState *s, DeviceState *dev)
G
Gerd Hoffmann 已提交
2360 2361 2362
{
    int i;

2363
    /* 2.2 host controller interface version */
2364
    s->caps[0x00] = (uint8_t)(s->opregbase - s->capsbase);
2365 2366 2367 2368 2369 2370 2371 2372 2373 2374
    s->caps[0x01] = 0x00;
    s->caps[0x02] = 0x00;
    s->caps[0x03] = 0x01;        /* HC version */
    s->caps[0x04] = NB_PORTS;    /* Number of downstream ports */
    s->caps[0x05] = 0x00;        /* No companion ports at present */
    s->caps[0x06] = 0x00;
    s->caps[0x07] = 0x00;
    s->caps[0x08] = 0x80;        /* We can cache whole frame, no 64-bit */
    s->caps[0x0a] = 0x00;
    s->caps[0x0b] = 0x00;
G
Gerd Hoffmann 已提交
2375

P
Peter Crosthwaite 已提交
2376
    usb_bus_new(&s->bus, &ehci_bus_ops, dev);
G
Gerd Hoffmann 已提交
2377 2378 2379 2380 2381 2382 2383
    for(i = 0; i < NB_PORTS; i++) {
        usb_register_port(&s->bus, &s->ports[i], s, i, &ehci_port_ops,
                          USB_SPEED_MASK_HIGH);
        s->ports[i].dev = 0;
    }

    s->frame_timer = qemu_new_timer_ns(vm_clock, ehci_frame_timer, s);
2384
    s->async_bh = qemu_bh_new(ehci_frame_timer, s);
2385 2386
    QTAILQ_INIT(&s->aqueues);
    QTAILQ_INIT(&s->pqueues);
2387
    usb_packet_init(&s->ipacket);
G
Gerd Hoffmann 已提交
2388 2389

    qemu_register_reset(ehci_reset, s);
2390
    qemu_add_vm_change_state_handler(usb_ehci_vm_state_change, s);
G
Gerd Hoffmann 已提交
2391

2392 2393
    memory_region_init(&s->mem, "ehci", MMIO_SIZE);
    memory_region_init_io(&s->mem_caps, &ehci_mmio_caps_ops, s,
2394
                          "capabilities", CAPA_SIZE);
2395
    memory_region_init_io(&s->mem_opreg, &ehci_mmio_opreg_ops, s,
2396
                          "operational", PORTSC_BEGIN);
2397 2398 2399
    memory_region_init_io(&s->mem_ports, &ehci_mmio_port_ops, s,
                          "ports", PORTSC_END - PORTSC_BEGIN);

2400 2401 2402 2403
    memory_region_add_subregion(&s->mem, s->capsbase, &s->mem_caps);
    memory_region_add_subregion(&s->mem, s->opregbase, &s->mem_opreg);
    memory_region_add_subregion(&s->mem, s->opregbase + PORTSC_BEGIN,
                                &s->mem_ports);
P
Peter Crosthwaite 已提交
2404 2405
}

G
Gerd Hoffmann 已提交
2406 2407 2408
/*
 * vim: expandtab ts=4
 */