virtio-scsi.c 20.7 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
/*
 * Virtio SCSI HBA
 *
 * Copyright IBM, Corp. 2010
 * Copyright Red Hat, Inc. 2011
 *
 * Authors:
 *   Stefan Hajnoczi    <stefanha@linux.vnet.ibm.com>
 *   Paolo Bonzini      <pbonzini@redhat.com>
 *
 * This work is licensed under the terms of the GNU GPL, version 2 or later.
 * See the COPYING file in the top-level directory.
 *
 */

P
Paolo Bonzini 已提交
16
#include "hw/virtio/virtio-scsi.h"
17
#include "qemu/error-report.h"
P
Paolo Bonzini 已提交
18 19 20
#include <hw/scsi/scsi.h>
#include <block/scsi.h>
#include <hw/virtio/virtio-bus.h>
21

22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42
typedef struct VirtIOSCSIReq {
    VirtIOSCSI *dev;
    VirtQueue *vq;
    VirtQueueElement elem;
    QEMUSGList qsgl;
    SCSIRequest *sreq;
    union {
        char                  *buf;
        VirtIOSCSICmdReq      *cmd;
        VirtIOSCSICtrlTMFReq  *tmf;
        VirtIOSCSICtrlANReq   *an;
    } req;
    union {
        char                  *buf;
        VirtIOSCSICmdResp     *cmd;
        VirtIOSCSICtrlTMFResp *tmf;
        VirtIOSCSICtrlANResp  *an;
        VirtIOSCSIEvent       *event;
    } resp;
} VirtIOSCSIReq;

43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58
static inline int virtio_scsi_get_lun(uint8_t *lun)
{
    return ((lun[2] << 8) | lun[3]) & 0x3FFF;
}

static inline SCSIDevice *virtio_scsi_device_find(VirtIOSCSI *s, uint8_t *lun)
{
    if (lun[0] != 1) {
        return NULL;
    }
    if (lun[2] != 0 && !(lun[2] >= 0x40 && lun[2] < 0x80)) {
        return NULL;
    }
    return scsi_device_find(&s->bus, 0, lun[1], virtio_scsi_get_lun(lun));
}

59 60 61 62
static void virtio_scsi_complete_req(VirtIOSCSIReq *req)
{
    VirtIOSCSI *s = req->dev;
    VirtQueue *vq = req->vq;
63
    VirtIODevice *vdev = VIRTIO_DEVICE(s);
64 65 66 67 68 69 70
    virtqueue_push(vq, &req->elem, req->qsgl.size + req->elem.in_sg[0].iov_len);
    qemu_sglist_destroy(&req->qsgl);
    if (req->sreq) {
        req->sreq->hba_private = NULL;
        scsi_req_unref(req->sreq);
    }
    g_free(req);
71
    virtio_notify(vdev, vq);
72 73 74 75 76 77 78 79
}

static void virtio_scsi_bad_req(void)
{
    error_report("wrong size for virtio-scsi headers");
    exit(1);
}

80
static void qemu_sgl_init_external(VirtIOSCSIReq *req, struct iovec *sg,
A
Avi Kivity 已提交
81
                                   hwaddr *addr, int num)
82
{
83 84 85
    QEMUSGList *qsgl = &req->qsgl;

    qemu_sglist_init(qsgl, DEVICE(req->dev), num, &address_space_memory);
86 87 88 89 90 91 92 93
    while (num--) {
        qemu_sglist_add(qsgl, *(addr++), (sg++)->iov_len);
    }
}

static void virtio_scsi_parse_req(VirtIOSCSI *s, VirtQueue *vq,
                                  VirtIOSCSIReq *req)
{
94
    assert(req->elem.in_num);
95 96 97
    req->vq = vq;
    req->dev = s;
    req->sreq = NULL;
98 99 100
    if (req->elem.out_num) {
        req->req.buf = req->elem.out_sg[0].iov_base;
    }
101 102 103
    req->resp.buf = req->elem.in_sg[0].iov_base;

    if (req->elem.out_num > 1) {
104
        qemu_sgl_init_external(req, &req->elem.out_sg[1],
105 106 107
                               &req->elem.out_addr[1],
                               req->elem.out_num - 1);
    } else {
108
        qemu_sgl_init_external(req, &req->elem.in_sg[1],
109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126
                               &req->elem.in_addr[1],
                               req->elem.in_num - 1);
    }
}

static VirtIOSCSIReq *virtio_scsi_pop_req(VirtIOSCSI *s, VirtQueue *vq)
{
    VirtIOSCSIReq *req;
    req = g_malloc(sizeof(*req));
    if (!virtqueue_pop(vq, &req->elem)) {
        g_free(req);
        return NULL;
    }

    virtio_scsi_parse_req(s, vq, req);
    return req;
}

127 128 129
static void virtio_scsi_save_request(QEMUFile *f, SCSIRequest *sreq)
{
    VirtIOSCSIReq *req = sreq->hba_private;
130
    VirtIOSCSICommon *vs = VIRTIO_SCSI_COMMON(req->dev);
131
    uint32_t n = virtio_queue_get_id(req->vq) - 2;
132

133
    assert(n < vs->conf.num_queues);
134
    qemu_put_be32s(f, &n);
135 136 137 138 139 140 141
    qemu_put_buffer(f, (unsigned char *)&req->elem, sizeof(req->elem));
}

static void *virtio_scsi_load_request(QEMUFile *f, SCSIRequest *sreq)
{
    SCSIBus *bus = sreq->bus;
    VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
142
    VirtIOSCSICommon *vs = VIRTIO_SCSI_COMMON(s);
143
    VirtIOSCSIReq *req;
144
    uint32_t n;
145 146

    req = g_malloc(sizeof(*req));
147
    qemu_get_be32s(f, &n);
148
    assert(n < vs->conf.num_queues);
149
    qemu_get_buffer(f, (unsigned char *)&req->elem, sizeof(req->elem));
150
    virtio_scsi_parse_req(s, vs->cmd_vqs[n], req);
151 152 153 154 155 156 157 158 159 160 161 162

    scsi_req_ref(sreq);
    req->sreq = sreq;
    if (req->sreq->cmd.mode != SCSI_XFER_NONE) {
        int req_mode =
            (req->elem.in_num > 1 ? SCSI_XFER_FROM_DEV : SCSI_XFER_TO_DEV);

        assert(req->sreq->cmd.mode == req_mode);
    }
    return req;
}

163
static void virtio_scsi_do_tmf(VirtIOSCSI *s, VirtIOSCSIReq *req)
164
{
165 166
    SCSIDevice *d = virtio_scsi_device_find(s, req->req.tmf->lun);
    SCSIRequest *r, *next;
A
Anthony Liguori 已提交
167
    BusChild *kid;
168 169 170 171 172 173 174 175 176 177 178 179 180 181 182
    int target;

    /* Here VIRTIO_SCSI_S_OK means "FUNCTION COMPLETE".  */
    req->resp.tmf->response = VIRTIO_SCSI_S_OK;

    switch (req->req.tmf->subtype) {
    case VIRTIO_SCSI_T_TMF_ABORT_TASK:
    case VIRTIO_SCSI_T_TMF_QUERY_TASK:
        if (!d) {
            goto fail;
        }
        if (d->lun != virtio_scsi_get_lun(req->req.tmf->lun)) {
            goto incorrect_lun;
        }
        QTAILQ_FOREACH_SAFE(r, &d->requests, next, next) {
183 184
            VirtIOSCSIReq *cmd_req = r->hba_private;
            if (cmd_req && cmd_req->req.cmd->tag == req->req.tmf->tag) {
185 186 187
                break;
            }
        }
188 189 190 191 192 193
        if (r) {
            /*
             * Assert that the request has not been completed yet, we
             * check for it in the loop above.
             */
            assert(r->hba_private);
194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243
            if (req->req.tmf->subtype == VIRTIO_SCSI_T_TMF_QUERY_TASK) {
                /* "If the specified command is present in the task set, then
                 * return a service response set to FUNCTION SUCCEEDED".
                 */
                req->resp.tmf->response = VIRTIO_SCSI_S_FUNCTION_SUCCEEDED;
            } else {
                scsi_req_cancel(r);
            }
        }
        break;

    case VIRTIO_SCSI_T_TMF_LOGICAL_UNIT_RESET:
        if (!d) {
            goto fail;
        }
        if (d->lun != virtio_scsi_get_lun(req->req.tmf->lun)) {
            goto incorrect_lun;
        }
        s->resetting++;
        qdev_reset_all(&d->qdev);
        s->resetting--;
        break;

    case VIRTIO_SCSI_T_TMF_ABORT_TASK_SET:
    case VIRTIO_SCSI_T_TMF_CLEAR_TASK_SET:
    case VIRTIO_SCSI_T_TMF_QUERY_TASK_SET:
        if (!d) {
            goto fail;
        }
        if (d->lun != virtio_scsi_get_lun(req->req.tmf->lun)) {
            goto incorrect_lun;
        }
        QTAILQ_FOREACH_SAFE(r, &d->requests, next, next) {
            if (r->hba_private) {
                if (req->req.tmf->subtype == VIRTIO_SCSI_T_TMF_QUERY_TASK_SET) {
                    /* "If there is any command present in the task set, then
                     * return a service response set to FUNCTION SUCCEEDED".
                     */
                    req->resp.tmf->response = VIRTIO_SCSI_S_FUNCTION_SUCCEEDED;
                    break;
                } else {
                    scsi_req_cancel(r);
                }
            }
        }
        break;

    case VIRTIO_SCSI_T_TMF_I_T_NEXUS_RESET:
        target = req->req.tmf->lun[1];
        s->resetting++;
A
Anthony Liguori 已提交
244 245
        QTAILQ_FOREACH(kid, &s->bus.qbus.children, sibling) {
             d = DO_UPCAST(SCSIDevice, qdev, kid->child);
246 247 248 249 250 251 252 253 254 255 256
             if (d->channel == 0 && d->id == target) {
                qdev_reset_all(&d->qdev);
             }
        }
        s->resetting--;
        break;

    case VIRTIO_SCSI_T_TMF_CLEAR_ACA:
    default:
        req->resp.tmf->response = VIRTIO_SCSI_S_FUNCTION_REJECTED;
        break;
257 258
    }

259 260 261 262 263 264 265 266
    return;

incorrect_lun:
    req->resp.tmf->response = VIRTIO_SCSI_S_INCORRECT_LUN;
    return;

fail:
    req->resp.tmf->response = VIRTIO_SCSI_S_BAD_TARGET;
267 268
}

269 270
static void virtio_scsi_handle_ctrl(VirtIODevice *vdev, VirtQueue *vq)
{
271 272 273 274
    VirtIOSCSI *s = (VirtIOSCSI *)vdev;
    VirtIOSCSIReq *req;

    while ((req = virtio_scsi_pop_req(s, vq))) {
275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299
        int out_size, in_size;
        if (req->elem.out_num < 1 || req->elem.in_num < 1) {
            virtio_scsi_bad_req();
            continue;
        }

        out_size = req->elem.out_sg[0].iov_len;
        in_size = req->elem.in_sg[0].iov_len;
        if (req->req.tmf->type == VIRTIO_SCSI_T_TMF) {
            if (out_size < sizeof(VirtIOSCSICtrlTMFReq) ||
                in_size < sizeof(VirtIOSCSICtrlTMFResp)) {
                virtio_scsi_bad_req();
            }
            virtio_scsi_do_tmf(s, req);

        } else if (req->req.tmf->type == VIRTIO_SCSI_T_AN_QUERY ||
                   req->req.tmf->type == VIRTIO_SCSI_T_AN_SUBSCRIBE) {
            if (out_size < sizeof(VirtIOSCSICtrlANReq) ||
                in_size < sizeof(VirtIOSCSICtrlANResp)) {
                virtio_scsi_bad_req();
            }
            req->resp.an->event_actual = 0;
            req->resp.an->response = VIRTIO_SCSI_S_OK;
        }
        virtio_scsi_complete_req(req);
300 301 302
    }
}

303 304 305 306
static void virtio_scsi_command_complete(SCSIRequest *r, uint32_t status,
                                         size_t resid)
{
    VirtIOSCSIReq *req = r->hba_private;
307
    uint32_t sense_len;
308

309 310 311 312
    if (r->io_canceled) {
        return;
    }

313 314 315
    req->resp.cmd->response = VIRTIO_SCSI_S_OK;
    req->resp.cmd->status = status;
    if (req->resp.cmd->status == GOOD) {
316
        req->resp.cmd->resid = tswap32(resid);
317 318
    } else {
        req->resp.cmd->resid = 0;
319 320 321
        sense_len = scsi_req_get_sense(r, req->resp.cmd->sense,
                                       VIRTIO_SCSI_SENSE_SIZE);
        req->resp.cmd->sense_len = tswap32(sense_len);
322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339
    }
    virtio_scsi_complete_req(req);
}

static QEMUSGList *virtio_scsi_get_sg_list(SCSIRequest *r)
{
    VirtIOSCSIReq *req = r->hba_private;

    return &req->qsgl;
}

static void virtio_scsi_request_cancelled(SCSIRequest *r)
{
    VirtIOSCSIReq *req = r->hba_private;

    if (!req) {
        return;
    }
340 341 342 343 344
    if (req->dev->resetting) {
        req->resp.cmd->response = VIRTIO_SCSI_S_RESET;
    } else {
        req->resp.cmd->response = VIRTIO_SCSI_S_ABORTED;
    }
345 346 347 348
    virtio_scsi_complete_req(req);
}

static void virtio_scsi_fail_cmd_req(VirtIOSCSIReq *req)
349 350 351
{
    req->resp.cmd->response = VIRTIO_SCSI_S_FAILURE;
    virtio_scsi_complete_req(req);
352 353 354 355
}

static void virtio_scsi_handle_cmd(VirtIODevice *vdev, VirtQueue *vq)
{
356
    /* use non-QOM casts in the data path */
357
    VirtIOSCSI *s = (VirtIOSCSI *)vdev;
358 359
    VirtIOSCSICommon *vs = &s->parent_obj;

360
    VirtIOSCSIReq *req;
361
    int n;
362 363

    while ((req = virtio_scsi_pop_req(s, vq))) {
364
        SCSIDevice *d;
365 366 367 368 369 370 371
        int out_size, in_size;
        if (req->elem.out_num < 1 || req->elem.in_num < 1) {
            virtio_scsi_bad_req();
        }

        out_size = req->elem.out_sg[0].iov_len;
        in_size = req->elem.in_sg[0].iov_len;
372 373
        if (out_size < sizeof(VirtIOSCSICmdReq) + vs->cdb_size ||
            in_size < sizeof(VirtIOSCSICmdResp) + vs->sense_size) {
374 375 376 377
            virtio_scsi_bad_req();
        }

        if (req->elem.out_num > 1 && req->elem.in_num > 1) {
378
            virtio_scsi_fail_cmd_req(req);
379 380 381
            continue;
        }

382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407
        d = virtio_scsi_device_find(s, req->req.cmd->lun);
        if (!d) {
            req->resp.cmd->response = VIRTIO_SCSI_S_BAD_TARGET;
            virtio_scsi_complete_req(req);
            continue;
        }
        req->sreq = scsi_req_new(d, req->req.cmd->tag,
                                 virtio_scsi_get_lun(req->req.cmd->lun),
                                 req->req.cmd->cdb, req);

        if (req->sreq->cmd.mode != SCSI_XFER_NONE) {
            int req_mode =
                (req->elem.in_num > 1 ? SCSI_XFER_FROM_DEV : SCSI_XFER_TO_DEV);

            if (req->sreq->cmd.mode != req_mode ||
                req->sreq->cmd.xfer > req->qsgl.size) {
                req->resp.cmd->response = VIRTIO_SCSI_S_OVERRUN;
                virtio_scsi_complete_req(req);
                continue;
            }
        }

        n = scsi_req_enqueue(req->sreq);
        if (n) {
            scsi_req_continue(req->sreq);
        }
408
    }
409 410 411 412 413 414
}

static void virtio_scsi_get_config(VirtIODevice *vdev,
                                   uint8_t *config)
{
    VirtIOSCSIConfig *scsiconf = (VirtIOSCSIConfig *)config;
415
    VirtIOSCSICommon *s = VIRTIO_SCSI_COMMON(vdev);
416

417
    stl_raw(&scsiconf->num_queues, s->conf.num_queues);
418
    stl_raw(&scsiconf->seg_max, 128 - 2);
419 420
    stl_raw(&scsiconf->max_sectors, s->conf.max_sectors);
    stl_raw(&scsiconf->cmd_per_lun, s->conf.cmd_per_lun);
421 422 423
    stl_raw(&scsiconf->event_info_size, sizeof(VirtIOSCSIEvent));
    stl_raw(&scsiconf->sense_size, s->sense_size);
    stl_raw(&scsiconf->cdb_size, s->cdb_size);
424 425
    stw_raw(&scsiconf->max_channel, VIRTIO_SCSI_MAX_CHANNEL);
    stw_raw(&scsiconf->max_target, VIRTIO_SCSI_MAX_TARGET);
426 427 428 429 430 431 432
    stl_raw(&scsiconf->max_lun, VIRTIO_SCSI_MAX_LUN);
}

static void virtio_scsi_set_config(VirtIODevice *vdev,
                                   const uint8_t *config)
{
    VirtIOSCSIConfig *scsiconf = (VirtIOSCSIConfig *)config;
433
    VirtIOSCSICommon *vs = VIRTIO_SCSI_COMMON(vdev);
434 435 436 437 438 439 440

    if ((uint32_t) ldl_raw(&scsiconf->sense_size) >= 65536 ||
        (uint32_t) ldl_raw(&scsiconf->cdb_size) >= 256) {
        error_report("bad data written to virtio-scsi configuration space");
        exit(1);
    }

441 442
    vs->sense_size = ldl_raw(&scsiconf->sense_size);
    vs->cdb_size = ldl_raw(&scsiconf->cdb_size);
443 444 445 446 447 448 449 450 451 452
}

static uint32_t virtio_scsi_get_features(VirtIODevice *vdev,
                                         uint32_t requested_features)
{
    return requested_features;
}

static void virtio_scsi_reset(VirtIODevice *vdev)
{
453 454
    VirtIOSCSI *s = VIRTIO_SCSI(vdev);
    VirtIOSCSICommon *vs = VIRTIO_SCSI_COMMON(vdev);
455

456 457 458 459
    s->resetting++;
    qbus_reset_all(&s->bus.qbus);
    s->resetting--;

460 461
    vs->sense_size = VIRTIO_SCSI_SENSE_SIZE;
    vs->cdb_size = VIRTIO_SCSI_CDB_SIZE;
462
    s->events_dropped = false;
463 464
}

465 466 467 468 469
/* The device does not have anything to save beyond the virtio data.
 * Request data is saved with callbacks from SCSI devices.
 */
static void virtio_scsi_save(QEMUFile *f, void *opaque)
{
470 471
    VirtIODevice *vdev = VIRTIO_DEVICE(opaque);
    virtio_save(vdev, f);
472 473 474 475
}

static int virtio_scsi_load(QEMUFile *f, void *opaque, int version_id)
{
476
    VirtIODevice *vdev = VIRTIO_DEVICE(opaque);
477 478
    int ret;

479
    ret = virtio_load(vdev, f);
480 481 482
    if (ret) {
        return ret;
    }
483 484 485
    return 0;
}

486 487 488
static void virtio_scsi_push_event(VirtIOSCSI *s, SCSIDevice *dev,
                                   uint32_t event, uint32_t reason)
{
489 490
    VirtIOSCSICommon *vs = VIRTIO_SCSI_COMMON(s);
    VirtIOSCSIReq *req = virtio_scsi_pop_req(s, vs->event_vq);
491
    VirtIOSCSIEvent *evt;
492
    VirtIODevice *vdev = VIRTIO_DEVICE(s);
493
    int in_size;
494

495
    if (!(vdev->status & VIRTIO_CONFIG_S_DRIVER_OK)) {
496 497 498
        return;
    }

499 500 501 502
    if (!req) {
        s->events_dropped = true;
        return;
    }
503

504 505 506
    if (req->elem.out_num || req->elem.in_num != 1) {
        virtio_scsi_bad_req();
    }
507

508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524
    if (s->events_dropped) {
        event |= VIRTIO_SCSI_T_EVENTS_MISSED;
        s->events_dropped = false;
    }

    in_size = req->elem.in_sg[0].iov_len;
    if (in_size < sizeof(VirtIOSCSIEvent)) {
        virtio_scsi_bad_req();
    }

    evt = req->resp.event;
    memset(evt, 0, sizeof(VirtIOSCSIEvent));
    evt->event = event;
    evt->reason = reason;
    if (!dev) {
        assert(event == VIRTIO_SCSI_T_NO_EVENT);
    } else {
525 526 527 528 529 530 531 532
        evt->lun[0] = 1;
        evt->lun[1] = dev->id;

        /* Linux wants us to keep the same encoding we use for REPORT LUNS.  */
        if (dev->lun >= 256) {
            evt->lun[2] = (dev->lun >> 8) | 0x40;
        }
        evt->lun[3] = dev->lun & 0xFF;
533 534 535 536 537 538
    }
    virtio_scsi_complete_req(req);
}

static void virtio_scsi_handle_event(VirtIODevice *vdev, VirtQueue *vq)
{
539
    VirtIOSCSI *s = VIRTIO_SCSI(vdev);
540 541 542

    if (s->events_dropped) {
        virtio_scsi_push_event(s, NULL, VIRTIO_SCSI_T_NO_EVENT, 0);
543 544 545
    }
}

546 547 548
static void virtio_scsi_change(SCSIBus *bus, SCSIDevice *dev, SCSISense sense)
{
    VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
549
    VirtIODevice *vdev = VIRTIO_DEVICE(s);
550

551
    if (((vdev->guest_features >> VIRTIO_SCSI_F_CHANGE) & 1) &&
552 553 554 555 556 557
        dev->type != TYPE_ROM) {
        virtio_scsi_push_event(s, dev, VIRTIO_SCSI_T_PARAM_CHANGE,
                               sense.asc | (sense.ascq << 8));
    }
}

558 559 560
static void virtio_scsi_hotplug(SCSIBus *bus, SCSIDevice *dev)
{
    VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
561
    VirtIODevice *vdev = VIRTIO_DEVICE(s);
562

563
    if ((vdev->guest_features >> VIRTIO_SCSI_F_HOTPLUG) & 1) {
564 565 566 567 568 569 570 571
        virtio_scsi_push_event(s, dev, VIRTIO_SCSI_T_TRANSPORT_RESET,
                               VIRTIO_SCSI_EVT_RESET_RESCAN);
    }
}

static void virtio_scsi_hot_unplug(SCSIBus *bus, SCSIDevice *dev)
{
    VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
572
    VirtIODevice *vdev = VIRTIO_DEVICE(s);
573

574
    if ((vdev->guest_features >> VIRTIO_SCSI_F_HOTPLUG) & 1) {
575 576 577 578 579
        virtio_scsi_push_event(s, dev, VIRTIO_SCSI_T_TRANSPORT_RESET,
                               VIRTIO_SCSI_EVT_RESET_REMOVED);
    }
}

580 581 582 583 584 585 586 587
static struct SCSIBusInfo virtio_scsi_scsi_info = {
    .tcq = true,
    .max_channel = VIRTIO_SCSI_MAX_CHANNEL,
    .max_target = VIRTIO_SCSI_MAX_TARGET,
    .max_lun = VIRTIO_SCSI_MAX_LUN,

    .complete = virtio_scsi_command_complete,
    .cancel = virtio_scsi_request_cancelled,
588
    .change = virtio_scsi_change,
589 590
    .hotplug = virtio_scsi_hotplug,
    .hot_unplug = virtio_scsi_hot_unplug,
591
    .get_sg_list = virtio_scsi_get_sg_list,
592 593
    .save_request = virtio_scsi_save_request,
    .load_request = virtio_scsi_load_request,
594 595
};

596
void virtio_scsi_common_realize(DeviceState *dev, Error **errp)
597
{
598 599
    VirtIODevice *vdev = VIRTIO_DEVICE(dev);
    VirtIOSCSICommon *s = VIRTIO_SCSI_COMMON(dev);
600
    int i;
601

602
    virtio_init(vdev, "virtio-scsi", VIRTIO_ID_SCSI,
603
                sizeof(VirtIOSCSIConfig));
604

605
    s->cmd_vqs = g_malloc0(s->conf.num_queues * sizeof(VirtQueue *));
606 607
    s->sense_size = VIRTIO_SCSI_SENSE_SIZE;
    s->cdb_size = VIRTIO_SCSI_CDB_SIZE;
608

609 610 611
    s->ctrl_vq = virtio_add_queue(vdev, VIRTIO_SCSI_VQ_SIZE,
                                  virtio_scsi_handle_ctrl);
    s->event_vq = virtio_add_queue(vdev, VIRTIO_SCSI_VQ_SIZE,
612
                                   virtio_scsi_handle_event);
613
    for (i = 0; i < s->conf.num_queues; i++) {
614
        s->cmd_vqs[i] = virtio_add_queue(vdev, VIRTIO_SCSI_VQ_SIZE,
615 616
                                         virtio_scsi_handle_cmd);
    }
617 618
}

619
static void virtio_scsi_device_realize(DeviceState *dev, Error **errp)
620
{
621
    VirtIODevice *vdev = VIRTIO_DEVICE(dev);
622
    VirtIOSCSI *s = VIRTIO_SCSI(dev);
623
    static int virtio_scsi_id;
624
    Error *err = NULL;
625

626 627 628 629
    virtio_scsi_common_realize(dev, &err);
    if (err != NULL) {
        error_propagate(errp, err);
        return;
630 631
    }

632
    scsi_bus_new(&s->bus, sizeof(s->bus), dev,
633
                 &virtio_scsi_scsi_info, vdev->bus_name);
634

635
    if (!dev->hotplugged) {
636 637
        scsi_bus_legacy_handle_cmdline(&s->bus, &err);
        if (err != NULL) {
638 639
            error_propagate(errp, err);
            return;
640
        }
641 642
    }

643
    register_savevm(dev, "virtio-scsi", virtio_scsi_id++, 1,
644
                    virtio_scsi_save, virtio_scsi_load, s);
645 646
}

647
void virtio_scsi_common_unrealize(DeviceState *dev, Error **errp)
648
{
649 650
    VirtIODevice *vdev = VIRTIO_DEVICE(dev);
    VirtIOSCSICommon *vs = VIRTIO_SCSI_COMMON(dev);
651 652

    g_free(vs->cmd_vqs);
653
    virtio_cleanup(vdev);
654 655
}

656
static void virtio_scsi_device_unrealize(DeviceState *dev, Error **errp)
657
{
658 659 660
    VirtIOSCSI *s = VIRTIO_SCSI(dev);

    unregister_savevm(dev, "virtio-scsi", s);
661

662
    virtio_scsi_common_unrealize(dev, errp);
663 664 665
}

static Property virtio_scsi_properties[] = {
666
    DEFINE_VIRTIO_SCSI_PROPERTIES(VirtIOSCSI, parent_obj.conf),
667 668 669
    DEFINE_PROP_END_OF_LIST(),
};

670 671 672
static void virtio_scsi_common_class_init(ObjectClass *klass, void *data)
{
    VirtioDeviceClass *vdc = VIRTIO_DEVICE_CLASS(klass);
673
    DeviceClass *dc = DEVICE_CLASS(klass);
674 675

    vdc->get_config = virtio_scsi_get_config;
676
    set_bit(DEVICE_CATEGORY_STORAGE, dc->categories);
677 678
}

679 680 681 682
static void virtio_scsi_class_init(ObjectClass *klass, void *data)
{
    DeviceClass *dc = DEVICE_CLASS(klass);
    VirtioDeviceClass *vdc = VIRTIO_DEVICE_CLASS(klass);
683

684
    dc->props = virtio_scsi_properties;
685
    set_bit(DEVICE_CATEGORY_STORAGE, dc->categories);
686
    vdc->realize = virtio_scsi_device_realize;
687
    vdc->unrealize = virtio_scsi_device_unrealize;
688 689 690 691 692
    vdc->set_config = virtio_scsi_set_config;
    vdc->get_features = virtio_scsi_get_features;
    vdc->reset = virtio_scsi_reset;
}

693 694 695 696
static const TypeInfo virtio_scsi_common_info = {
    .name = TYPE_VIRTIO_SCSI_COMMON,
    .parent = TYPE_VIRTIO_DEVICE,
    .instance_size = sizeof(VirtIOSCSICommon),
697
    .abstract = true,
698 699 700
    .class_init = virtio_scsi_common_class_init,
};

701 702
static const TypeInfo virtio_scsi_info = {
    .name = TYPE_VIRTIO_SCSI,
703
    .parent = TYPE_VIRTIO_SCSI_COMMON,
704 705 706 707 708 709
    .instance_size = sizeof(VirtIOSCSI),
    .class_init = virtio_scsi_class_init,
};

static void virtio_register_types(void)
{
710
    type_register_static(&virtio_scsi_common_info);
711 712 713 714
    type_register_static(&virtio_scsi_info);
}

type_init(virtio_register_types)