vmware_vga.c 37.1 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
/*
 * QEMU VMware-SVGA "chipset".
 *
 * Copyright (c) 2007 Andrzej Zaborowski  <balrog@zabor.org>
 *
 * Permission is hereby granted, free of charge, to any person obtaining a copy
 * of this software and associated documentation files (the "Software"), to deal
 * in the Software without restriction, including without limitation the rights
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
 * copies of the Software, and to permit persons to whom the Software is
 * furnished to do so, subject to the following conditions:
 *
 * The above copyright notice and this permission notice shall be included in
 * all copies or substantial portions of the Software.
 *
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
 * THE SOFTWARE.
 */
24 25
#include "hw/hw.h"
#include "hw/loader.h"
26
#include "trace.h"
27
#include "ui/console.h"
28
#include "ui/vnc.h"
29
#include "hw/pci/pci.h"
30

J
Jan Kiszka 已提交
31
#undef VERBOSE
32 33 34 35
#define HW_RECT_ACCEL
#define HW_FILL_ACCEL
#define HW_MOUSE_ACCEL

36
#include "vga_int.h"
37 38

/* See http://vmware-svga.sf.net/ for some documentation on VMWare SVGA */
39 40

struct vmsvga_state_s {
41
    VGACommonState vga;
42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57

    int invalidated;
    int enable;
    int config;
    struct {
        int id;
        int x;
        int y;
        int on;
    } cursor;

    int index;
    int scratch_size;
    uint32_t *scratch;
    int new_width;
    int new_height;
58
    int new_depth;
59 60 61 62
    uint32_t guest;
    uint32_t svgaid;
    int syncing;

63
    MemoryRegion fifo_ram;
64 65 66
    uint8_t *fifo_ptr;
    unsigned int fifo_size;

67 68
    union {
        uint32_t *fifo;
69
        struct QEMU_PACKED {
70 71 72 73 74 75 76 77 78
            uint32_t min;
            uint32_t max;
            uint32_t next_cmd;
            uint32_t stop;
            /* Add registers here when adding capabilities.  */
            uint32_t fifo[0];
        } *cmd;
    };

B
BALATON Zoltan 已提交
79
#define REDRAW_FIFO_LEN  512
80 81 82 83 84 85
    struct vmsvga_rect_s {
        int x, y, w, h;
    } redraw_fifo[REDRAW_FIFO_LEN];
    int redraw_fifo_first, redraw_fifo_last;
};

86 87 88 89 90
#define TYPE_VMWARE_SVGA "vmware-svga"

#define VMWARE_SVGA(obj) \
    OBJECT_CHECK(struct pci_vmsvga_state_s, (obj), TYPE_VMWARE_SVGA)

91
struct pci_vmsvga_state_s {
92 93 94 95
    /*< private >*/
    PCIDevice parent_obj;
    /*< public >*/

96
    struct vmsvga_state_s chip;
97
    MemoryRegion io_bar;
98 99
};

B
BALATON Zoltan 已提交
100 101 102 103 104
#define SVGA_MAGIC              0x900000UL
#define SVGA_MAKE_ID(ver)       (SVGA_MAGIC << 8 | (ver))
#define SVGA_ID_0               SVGA_MAKE_ID(0)
#define SVGA_ID_1               SVGA_MAKE_ID(1)
#define SVGA_ID_2               SVGA_MAKE_ID(2)
105

B
BALATON Zoltan 已提交
106 107 108 109
#define SVGA_LEGACY_BASE_PORT   0x4560
#define SVGA_INDEX_PORT         0x0
#define SVGA_VALUE_PORT         0x1
#define SVGA_BIOS_PORT          0x2
110 111 112 113

#define SVGA_VERSION_2

#ifdef SVGA_VERSION_2
B
BALATON Zoltan 已提交
114 115 116 117 118
# define SVGA_ID                SVGA_ID_2
# define SVGA_IO_BASE           SVGA_LEGACY_BASE_PORT
# define SVGA_IO_MUL            1
# define SVGA_FIFO_SIZE         0x10000
# define SVGA_PCI_DEVICE_ID     PCI_DEVICE_ID_VMWARE_SVGA2
119
#else
B
BALATON Zoltan 已提交
120 121 122 123 124
# define SVGA_ID                SVGA_ID_1
# define SVGA_IO_BASE           SVGA_LEGACY_BASE_PORT
# define SVGA_IO_MUL            4
# define SVGA_FIFO_SIZE         0x10000
# define SVGA_PCI_DEVICE_ID     PCI_DEVICE_ID_VMWARE_SVGA
125 126 127 128 129 130 131 132 133 134 135
#endif

enum {
    /* ID 0, 1 and 2 registers */
    SVGA_REG_ID = 0,
    SVGA_REG_ENABLE = 1,
    SVGA_REG_WIDTH = 2,
    SVGA_REG_HEIGHT = 3,
    SVGA_REG_MAX_WIDTH = 4,
    SVGA_REG_MAX_HEIGHT = 5,
    SVGA_REG_DEPTH = 6,
B
BALATON Zoltan 已提交
136
    SVGA_REG_BITS_PER_PIXEL = 7,        /* Current bpp in the guest */
137 138 139 140 141 142 143 144 145 146 147 148
    SVGA_REG_PSEUDOCOLOR = 8,
    SVGA_REG_RED_MASK = 9,
    SVGA_REG_GREEN_MASK = 10,
    SVGA_REG_BLUE_MASK = 11,
    SVGA_REG_BYTES_PER_LINE = 12,
    SVGA_REG_FB_START = 13,
    SVGA_REG_FB_OFFSET = 14,
    SVGA_REG_VRAM_SIZE = 15,
    SVGA_REG_FB_SIZE = 16,

    /* ID 1 and 2 registers */
    SVGA_REG_CAPABILITIES = 17,
B
BALATON Zoltan 已提交
149
    SVGA_REG_MEM_START = 18,            /* Memory for command FIFO */
150
    SVGA_REG_MEM_SIZE = 19,
B
BALATON Zoltan 已提交
151 152 153 154 155 156 157 158 159 160 161 162 163 164 165
    SVGA_REG_CONFIG_DONE = 20,          /* Set when memory area configured */
    SVGA_REG_SYNC = 21,                 /* Write to force synchronization */
    SVGA_REG_BUSY = 22,                 /* Read to check if sync is done */
    SVGA_REG_GUEST_ID = 23,             /* Set guest OS identifier */
    SVGA_REG_CURSOR_ID = 24,            /* ID of cursor */
    SVGA_REG_CURSOR_X = 25,             /* Set cursor X position */
    SVGA_REG_CURSOR_Y = 26,             /* Set cursor Y position */
    SVGA_REG_CURSOR_ON = 27,            /* Turn cursor on/off */
    SVGA_REG_HOST_BITS_PER_PIXEL = 28,  /* Current bpp in the host */
    SVGA_REG_SCRATCH_SIZE = 29,         /* Number of scratch registers */
    SVGA_REG_MEM_REGS = 30,             /* Number of FIFO registers */
    SVGA_REG_NUM_DISPLAYS = 31,         /* Number of guest displays */
    SVGA_REG_PITCHLOCK = 32,            /* Fixed pitch for all modes */

    SVGA_PALETTE_BASE = 1024,           /* Base of SVGA color map */
166 167 168 169
    SVGA_PALETTE_END  = SVGA_PALETTE_BASE + 767,
    SVGA_SCRATCH_BASE = SVGA_PALETTE_BASE + 768,
};

B
BALATON Zoltan 已提交
170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188
#define SVGA_CAP_NONE                   0
#define SVGA_CAP_RECT_FILL              (1 << 0)
#define SVGA_CAP_RECT_COPY              (1 << 1)
#define SVGA_CAP_RECT_PAT_FILL          (1 << 2)
#define SVGA_CAP_LEGACY_OFFSCREEN       (1 << 3)
#define SVGA_CAP_RASTER_OP              (1 << 4)
#define SVGA_CAP_CURSOR                 (1 << 5)
#define SVGA_CAP_CURSOR_BYPASS          (1 << 6)
#define SVGA_CAP_CURSOR_BYPASS_2        (1 << 7)
#define SVGA_CAP_8BIT_EMULATION         (1 << 8)
#define SVGA_CAP_ALPHA_CURSOR           (1 << 9)
#define SVGA_CAP_GLYPH                  (1 << 10)
#define SVGA_CAP_GLYPH_CLIPPING         (1 << 11)
#define SVGA_CAP_OFFSCREEN_1            (1 << 12)
#define SVGA_CAP_ALPHA_BLEND            (1 << 13)
#define SVGA_CAP_3D                     (1 << 14)
#define SVGA_CAP_EXTENDED_FIFO          (1 << 15)
#define SVGA_CAP_MULTIMON               (1 << 16)
#define SVGA_CAP_PITCHLOCK              (1 << 17)
189 190 191 192 193 194 195 196 197

/*
 * FIFO offsets (seen as an array of 32-bit words)
 */
enum {
    /*
     * The original defined FIFO offsets
     */
    SVGA_FIFO_MIN = 0,
B
BALATON Zoltan 已提交
198
    SVGA_FIFO_MAX,      /* The distance from MIN to MAX must be at least 10K */
199 200 201 202 203 204 205 206 207 208 209 210 211
    SVGA_FIFO_NEXT_CMD,
    SVGA_FIFO_STOP,

    /*
     * Additional offsets added as of SVGA_CAP_EXTENDED_FIFO
     */
    SVGA_FIFO_CAPABILITIES = 4,
    SVGA_FIFO_FLAGS,
    SVGA_FIFO_FENCE,
    SVGA_FIFO_3D_HWVERSION,
    SVGA_FIFO_PITCHLOCK,
};

B
BALATON Zoltan 已提交
212 213 214 215
#define SVGA_FIFO_CAP_NONE              0
#define SVGA_FIFO_CAP_FENCE             (1 << 0)
#define SVGA_FIFO_CAP_ACCELFRONT        (1 << 1)
#define SVGA_FIFO_CAP_PITCHLOCK         (1 << 2)
216

B
BALATON Zoltan 已提交
217 218
#define SVGA_FIFO_FLAG_NONE             0
#define SVGA_FIFO_FLAG_ACCELFRONT       (1 << 0)
219 220

/* These values can probably be changed arbitrarily.  */
B
BALATON Zoltan 已提交
221
#define SVGA_SCRATCH_SIZE               0x8000
222
#define SVGA_MAX_WIDTH                  ROUND_UP(2360, VNC_DIRTY_PIXELS_PER_BIT)
B
BALATON Zoltan 已提交
223
#define SVGA_MAX_HEIGHT                 1770
224 225

#ifdef VERBOSE
B
BALATON Zoltan 已提交
226
# define GUEST_OS_BASE          0x5001
227
static const char *vmsvga_guest_id[] = {
228 229 230 231 232 233 234 235 236
    [0x00] = "Dos",
    [0x01] = "Windows 3.1",
    [0x02] = "Windows 95",
    [0x03] = "Windows 98",
    [0x04] = "Windows ME",
    [0x05] = "Windows NT",
    [0x06] = "Windows 2000",
    [0x07] = "Linux",
    [0x08] = "OS/2",
237
    [0x09] = "an unknown OS",
238 239
    [0x0a] = "BSD",
    [0x0b] = "Whistler",
240 241 242 243 244 245 246 247 248
    [0x0c] = "an unknown OS",
    [0x0d] = "an unknown OS",
    [0x0e] = "an unknown OS",
    [0x0f] = "an unknown OS",
    [0x10] = "an unknown OS",
    [0x11] = "an unknown OS",
    [0x12] = "an unknown OS",
    [0x13] = "an unknown OS",
    [0x14] = "an unknown OS",
249
    [0x15] = "Windows 2003",
250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297
};
#endif

enum {
    SVGA_CMD_INVALID_CMD = 0,
    SVGA_CMD_UPDATE = 1,
    SVGA_CMD_RECT_FILL = 2,
    SVGA_CMD_RECT_COPY = 3,
    SVGA_CMD_DEFINE_BITMAP = 4,
    SVGA_CMD_DEFINE_BITMAP_SCANLINE = 5,
    SVGA_CMD_DEFINE_PIXMAP = 6,
    SVGA_CMD_DEFINE_PIXMAP_SCANLINE = 7,
    SVGA_CMD_RECT_BITMAP_FILL = 8,
    SVGA_CMD_RECT_PIXMAP_FILL = 9,
    SVGA_CMD_RECT_BITMAP_COPY = 10,
    SVGA_CMD_RECT_PIXMAP_COPY = 11,
    SVGA_CMD_FREE_OBJECT = 12,
    SVGA_CMD_RECT_ROP_FILL = 13,
    SVGA_CMD_RECT_ROP_COPY = 14,
    SVGA_CMD_RECT_ROP_BITMAP_FILL = 15,
    SVGA_CMD_RECT_ROP_PIXMAP_FILL = 16,
    SVGA_CMD_RECT_ROP_BITMAP_COPY = 17,
    SVGA_CMD_RECT_ROP_PIXMAP_COPY = 18,
    SVGA_CMD_DEFINE_CURSOR = 19,
    SVGA_CMD_DISPLAY_CURSOR = 20,
    SVGA_CMD_MOVE_CURSOR = 21,
    SVGA_CMD_DEFINE_ALPHA_CURSOR = 22,
    SVGA_CMD_DRAW_GLYPH = 23,
    SVGA_CMD_DRAW_GLYPH_CLIPPED = 24,
    SVGA_CMD_UPDATE_VERBOSE = 25,
    SVGA_CMD_SURFACE_FILL = 26,
    SVGA_CMD_SURFACE_COPY = 27,
    SVGA_CMD_SURFACE_ALPHA_BLEND = 28,
    SVGA_CMD_FRONT_ROP_FILL = 29,
    SVGA_CMD_FENCE = 30,
};

/* Legal values for the SVGA_REG_CURSOR_ON register in cursor bypass mode */
enum {
    SVGA_CURSOR_ON_HIDE = 0,
    SVGA_CURSOR_ON_SHOW = 1,
    SVGA_CURSOR_ON_REMOVE_FROM_FB = 2,
    SVGA_CURSOR_ON_RESTORE_TO_FB = 3,
};

static inline void vmsvga_update_rect(struct vmsvga_state_s *s,
                int x, int y, int w, int h)
{
298
    DisplaySurface *surface = qemu_console_surface(s->vga.con);
299 300 301 302 303 304 305
    int line;
    int bypl;
    int width;
    int start;
    uint8_t *src;
    uint8_t *dst;

306 307 308 309 310 311 312 313 314
    if (x < 0) {
        fprintf(stderr, "%s: update x was < 0 (%d)\n", __func__, x);
        w += x;
        x = 0;
    }
    if (w < 0) {
        fprintf(stderr, "%s: update w was < 0 (%d)\n", __func__, w);
        w = 0;
    }
315
    if (x + w > surface_width(surface)) {
316
        fprintf(stderr, "%s: update width too large x: %d, w: %d\n",
B
BALATON Zoltan 已提交
317
                __func__, x, w);
318 319
        x = MIN(x, surface_width(surface));
        w = surface_width(surface) - x;
320 321
    }

322 323 324 325 326 327 328 329 330
    if (y < 0) {
        fprintf(stderr, "%s: update y was < 0 (%d)\n",  __func__, y);
        h += y;
        y = 0;
    }
    if (h < 0) {
        fprintf(stderr, "%s: update h was < 0 (%d)\n",  __func__, h);
        h = 0;
    }
331
    if (y + h > surface_height(surface)) {
332
        fprintf(stderr, "%s: update height too large y: %d, h: %d\n",
B
BALATON Zoltan 已提交
333
                __func__, y, h);
334 335
        y = MIN(y, surface_height(surface));
        h = surface_height(surface) - y;
336 337
    }

338 339 340
    bypl = surface_stride(surface);
    width = surface_bytes_per_pixel(surface) * w;
    start = surface_bytes_per_pixel(surface) * x + bypl * y;
341
    src = s->vga.vram_ptr + start;
342
    dst = surface_data(surface) + start;
343

B
BALATON Zoltan 已提交
344
    for (line = h; line > 0; line--, src += bypl, dst += bypl) {
345
        memcpy(dst, src, width);
B
BALATON Zoltan 已提交
346
    }
347
    dpy_gfx_update(s->vga.con, x, y, w, h);
348 349 350 351 352
}

static inline void vmsvga_update_rect_delayed(struct vmsvga_state_s *s,
                int x, int y, int w, int h)
{
B
BALATON Zoltan 已提交
353 354
    struct vmsvga_rect_s *rect = &s->redraw_fifo[s->redraw_fifo_last++];

355 356 357 358 359 360 361 362 363 364
    s->redraw_fifo_last &= REDRAW_FIFO_LEN - 1;
    rect->x = x;
    rect->y = y;
    rect->w = w;
    rect->h = h;
}

static inline void vmsvga_update_rect_flush(struct vmsvga_state_s *s)
{
    struct vmsvga_rect_s *rect;
B
BALATON Zoltan 已提交
365

366 367 368 369 370 371 372
    if (s->invalidated) {
        s->redraw_fifo_first = s->redraw_fifo_last;
        return;
    }
    /* Overlapping region updates can be optimised out here - if someone
     * knows a smart algorithm to do that, please share.  */
    while (s->redraw_fifo_first != s->redraw_fifo_last) {
B
BALATON Zoltan 已提交
373
        rect = &s->redraw_fifo[s->redraw_fifo_first++];
374 375 376 377 378 379 380 381 382
        s->redraw_fifo_first &= REDRAW_FIFO_LEN - 1;
        vmsvga_update_rect(s, rect->x, rect->y, rect->w, rect->h);
    }
}

#ifdef HW_RECT_ACCEL
static inline void vmsvga_copy_rect(struct vmsvga_state_s *s,
                int x0, int y0, int x1, int y1, int w, int h)
{
383
    DisplaySurface *surface = qemu_console_surface(s->vga.con);
384
    uint8_t *vram = s->vga.vram_ptr;
385 386
    int bypl = surface_stride(surface);
    int bypp = surface_bytes_per_pixel(surface);
387
    int width = bypp * w;
388 389 390
    int line = h;
    uint8_t *ptr[2];

391
    if (y1 > y0) {
392 393
        ptr[0] = vram + bypp * x0 + bypl * (y0 + h - 1);
        ptr[1] = vram + bypp * x1 + bypl * (y1 + h - 1);
394 395 396 397
        for (; line > 0; line --, ptr[0] -= bypl, ptr[1] -= bypl) {
            memmove(ptr[1], ptr[0], width);
        }
    } else {
398 399
        ptr[0] = vram + bypp * x0 + bypl * y0;
        ptr[1] = vram + bypp * x1 + bypl * y1;
400 401
        for (; line > 0; line --, ptr[0] += bypl, ptr[1] += bypl) {
            memmove(ptr[1], ptr[0], width);
402 403 404 405 406 407 408 409 410 411 412
        }
    }

    vmsvga_update_rect_delayed(s, x1, y1, w, h);
}
#endif

#ifdef HW_FILL_ACCEL
static inline void vmsvga_fill_rect(struct vmsvga_state_s *s,
                uint32_t c, int x, int y, int w, int h)
{
413 414 415
    DisplaySurface *surface = qemu_console_surface(s->vga.con);
    int bypl = surface_stride(surface);
    int width = surface_bytes_per_pixel(surface) * w;
416 417
    int line = h;
    int column;
418
    uint8_t *fst;
419 420 421 422
    uint8_t *dst;
    uint8_t *src;
    uint8_t col[4];

423 424 425 426 427
    col[0] = c;
    col[1] = c >> 8;
    col[2] = c >> 16;
    col[3] = c >> 24;

428
    fst = s->vga.vram_ptr + surface_bytes_per_pixel(surface) * x + bypl * y;
429

430 431 432 433 434
    if (line--) {
        dst = fst;
        src = col;
        for (column = width; column > 0; column--) {
            *(dst++) = *(src++);
435
            if (src - col == surface_bytes_per_pixel(surface)) {
436
                src = col;
437 438
            }
        }
439 440 441 442 443
        dst = fst;
        for (; line > 0; line--) {
            dst += bypl;
            memcpy(dst, fst, width);
        }
444 445 446 447 448 449 450 451 452 453 454 455 456 457
    }

    vmsvga_update_rect_delayed(s, x, y, w, h);
}
#endif

struct vmsvga_cursor_definition_s {
    int width;
    int height;
    int id;
    int bpp;
    int hot_x;
    int hot_y;
    uint32_t mask[1024];
D
Dave Airlie 已提交
458
    uint32_t image[4096];
459 460
};

B
BALATON Zoltan 已提交
461 462
#define SVGA_BITMAP_SIZE(w, h)          ((((w) + 31) >> 5) * (h))
#define SVGA_PIXMAP_SIZE(w, h, bpp)     (((((w) * (bpp)) + 31) >> 5) * (h))
463 464 465 466 467

#ifdef HW_MOUSE_ACCEL
static inline void vmsvga_cursor_define(struct vmsvga_state_s *s,
                struct vmsvga_cursor_definition_s *c)
{
468 469 470 471 472 473 474 475
    QEMUCursor *qc;
    int i, pixels;

    qc = cursor_alloc(c->width, c->height);
    qc->hot_x = c->hot_x;
    qc->hot_y = c->hot_y;
    switch (c->bpp) {
    case 1:
B
BALATON Zoltan 已提交
476 477
        cursor_set_mono(qc, 0xffffff, 0x000000, (void *)c->image,
                        1, (void *)c->mask);
478 479 480 481 482 483
#ifdef DEBUG
        cursor_print_ascii_art(qc, "vmware/mono");
#endif
        break;
    case 32:
        /* fill alpha channel from mask, set color to zero */
B
BALATON Zoltan 已提交
484 485
        cursor_set_mono(qc, 0x000000, 0x000000, (void *)c->mask,
                        1, (void *)c->mask);
486 487 488 489 490 491 492 493 494 495 496
        /* add in rgb values */
        pixels = c->width * c->height;
        for (i = 0; i < pixels; i++) {
            qc->data[i] |= c->image[i] & 0xffffff;
        }
#ifdef DEBUG
        cursor_print_ascii_art(qc, "vmware/32bit");
#endif
        break;
    default:
        fprintf(stderr, "%s: unhandled bpp %d, using fallback cursor\n",
B
BALATON Zoltan 已提交
497
                __func__, c->bpp);
498 499 500
        cursor_put(qc);
        qc = cursor_builtin_left_ptr();
    }
501

502
    dpy_cursor_define(s->vga.con, qc);
503
    cursor_put(qc);
504 505 506
}
#endif

B
BALATON Zoltan 已提交
507
#define CMD(f)  le32_to_cpu(s->cmd->f)
508

509
static inline int vmsvga_fifo_length(struct vmsvga_state_s *s)
510
{
511
    int num;
B
BALATON Zoltan 已提交
512 513

    if (!s->config || !s->enable) {
514
        return 0;
B
BALATON Zoltan 已提交
515
    }
516
    num = CMD(next_cmd) - CMD(stop);
B
BALATON Zoltan 已提交
517
    if (num < 0) {
518
        num += CMD(max) - CMD(min);
B
BALATON Zoltan 已提交
519
    }
520
    return num >> 2;
521 522
}

523
static inline uint32_t vmsvga_fifo_read_raw(struct vmsvga_state_s *s)
524
{
525
    uint32_t cmd = s->fifo[CMD(stop) >> 2];
B
BALATON Zoltan 已提交
526

527
    s->cmd->stop = cpu_to_le32(CMD(stop) + 4);
B
BALATON Zoltan 已提交
528
    if (CMD(stop) >= CMD(max)) {
529
        s->cmd->stop = s->cmd->min;
B
BALATON Zoltan 已提交
530
    }
531 532 533
    return cmd;
}

534 535 536 537 538
static inline uint32_t vmsvga_fifo_read(struct vmsvga_state_s *s)
{
    return le32_to_cpu(vmsvga_fifo_read_raw(s));
}

539 540 541
static void vmsvga_fifo_run(struct vmsvga_state_s *s)
{
    uint32_t cmd, colour;
542
    int args, len;
543 544
    int x, y, dx, dy, width, height;
    struct vmsvga_cursor_definition_s cursor;
545 546 547 548 549 550 551
    uint32_t cmd_start;

    len = vmsvga_fifo_length(s);
    while (len > 0) {
        /* May need to go back to the start of the command if incomplete */
        cmd_start = s->cmd->stop;

552 553 554
        switch (cmd = vmsvga_fifo_read(s)) {
        case SVGA_CMD_UPDATE:
        case SVGA_CMD_UPDATE_VERBOSE:
555
            len -= 5;
B
BALATON Zoltan 已提交
556
            if (len < 0) {
557
                goto rewind;
B
BALATON Zoltan 已提交
558
            }
559

560 561 562 563 564 565 566 567
            x = vmsvga_fifo_read(s);
            y = vmsvga_fifo_read(s);
            width = vmsvga_fifo_read(s);
            height = vmsvga_fifo_read(s);
            vmsvga_update_rect_delayed(s, x, y, width, height);
            break;

        case SVGA_CMD_RECT_FILL:
568
            len -= 6;
B
BALATON Zoltan 已提交
569
            if (len < 0) {
570
                goto rewind;
B
BALATON Zoltan 已提交
571
            }
572

573 574 575 576 577 578 579 580 581
            colour = vmsvga_fifo_read(s);
            x = vmsvga_fifo_read(s);
            y = vmsvga_fifo_read(s);
            width = vmsvga_fifo_read(s);
            height = vmsvga_fifo_read(s);
#ifdef HW_FILL_ACCEL
            vmsvga_fill_rect(s, colour, x, y, width, height);
            break;
#else
582
            args = 0;
583 584 585 586
            goto badcmd;
#endif

        case SVGA_CMD_RECT_COPY:
587
            len -= 7;
B
BALATON Zoltan 已提交
588
            if (len < 0) {
589
                goto rewind;
B
BALATON Zoltan 已提交
590
            }
591

592 593 594 595 596 597 598 599 600 601
            x = vmsvga_fifo_read(s);
            y = vmsvga_fifo_read(s);
            dx = vmsvga_fifo_read(s);
            dy = vmsvga_fifo_read(s);
            width = vmsvga_fifo_read(s);
            height = vmsvga_fifo_read(s);
#ifdef HW_RECT_ACCEL
            vmsvga_copy_rect(s, x, y, dx, dy, width, height);
            break;
#else
602
            args = 0;
603 604 605 606
            goto badcmd;
#endif

        case SVGA_CMD_DEFINE_CURSOR:
607
            len -= 8;
B
BALATON Zoltan 已提交
608
            if (len < 0) {
609
                goto rewind;
B
BALATON Zoltan 已提交
610
            }
611

612 613 614 615 616 617 618
            cursor.id = vmsvga_fifo_read(s);
            cursor.hot_x = vmsvga_fifo_read(s);
            cursor.hot_y = vmsvga_fifo_read(s);
            cursor.width = x = vmsvga_fifo_read(s);
            cursor.height = y = vmsvga_fifo_read(s);
            vmsvga_fifo_read(s);
            cursor.bpp = vmsvga_fifo_read(s);
619

620
            args = SVGA_BITMAP_SIZE(x, y) + SVGA_PIXMAP_SIZE(x, y, cursor.bpp);
621
            if (SVGA_BITMAP_SIZE(x, y) > sizeof cursor.mask ||
B
BALATON Zoltan 已提交
622
                SVGA_PIXMAP_SIZE(x, y, cursor.bpp) > sizeof cursor.image) {
623
                    goto badcmd;
B
BALATON Zoltan 已提交
624
            }
625 626

            len -= args;
B
BALATON Zoltan 已提交
627
            if (len < 0) {
628
                goto rewind;
B
BALATON Zoltan 已提交
629
            }
630

B
BALATON Zoltan 已提交
631
            for (args = 0; args < SVGA_BITMAP_SIZE(x, y); args++) {
632
                cursor.mask[args] = vmsvga_fifo_read_raw(s);
B
BALATON Zoltan 已提交
633 634
            }
            for (args = 0; args < SVGA_PIXMAP_SIZE(x, y, cursor.bpp); args++) {
635
                cursor.image[args] = vmsvga_fifo_read_raw(s);
B
BALATON Zoltan 已提交
636
            }
637 638 639 640 641 642 643 644 645 646 647 648 649
#ifdef HW_MOUSE_ACCEL
            vmsvga_cursor_define(s, &cursor);
            break;
#else
            args = 0;
            goto badcmd;
#endif

        /*
         * Other commands that we at least know the number of arguments
         * for so we can avoid FIFO desync if driver uses them illegally.
         */
        case SVGA_CMD_DEFINE_ALPHA_CURSOR:
650
            len -= 6;
B
BALATON Zoltan 已提交
651
            if (len < 0) {
652
                goto rewind;
B
BALATON Zoltan 已提交
653
            }
654 655 656 657 658 659 660 661 662 663 664 665 666 667
            vmsvga_fifo_read(s);
            vmsvga_fifo_read(s);
            vmsvga_fifo_read(s);
            x = vmsvga_fifo_read(s);
            y = vmsvga_fifo_read(s);
            args = x * y;
            goto badcmd;
        case SVGA_CMD_RECT_ROP_FILL:
            args = 6;
            goto badcmd;
        case SVGA_CMD_RECT_ROP_COPY:
            args = 7;
            goto badcmd;
        case SVGA_CMD_DRAW_GLYPH_CLIPPED:
668
            len -= 4;
B
BALATON Zoltan 已提交
669
            if (len < 0) {
670
                goto rewind;
B
BALATON Zoltan 已提交
671
            }
672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691
            vmsvga_fifo_read(s);
            vmsvga_fifo_read(s);
            args = 7 + (vmsvga_fifo_read(s) >> 2);
            goto badcmd;
        case SVGA_CMD_SURFACE_ALPHA_BLEND:
            args = 12;
            goto badcmd;

        /*
         * Other commands that are not listed as depending on any
         * CAPABILITIES bits, but are not described in the README either.
         */
        case SVGA_CMD_SURFACE_FILL:
        case SVGA_CMD_SURFACE_COPY:
        case SVGA_CMD_FRONT_ROP_FILL:
        case SVGA_CMD_FENCE:
        case SVGA_CMD_INVALID_CMD:
            break; /* Nop */

        default:
692
            args = 0;
693
        badcmd:
694
            len -= args;
B
BALATON Zoltan 已提交
695
            if (len < 0) {
696
                goto rewind;
B
BALATON Zoltan 已提交
697 698
            }
            while (args--) {
699
                vmsvga_fifo_read(s);
B
BALATON Zoltan 已提交
700
            }
701
            printf("%s: Unknown command 0x%02x in SVGA command FIFO\n",
B
BALATON Zoltan 已提交
702
                   __func__, cmd);
703
            break;
704 705 706 707

        rewind:
            s->cmd->stop = cmd_start;
            break;
708
        }
709
    }
710 711 712 713 714 715

    s->syncing = 0;
}

static uint32_t vmsvga_index_read(void *opaque, uint32_t address)
{
716
    struct vmsvga_state_s *s = opaque;
B
BALATON Zoltan 已提交
717

718 719 720 721 722
    return s->index;
}

static void vmsvga_index_write(void *opaque, uint32_t address, uint32_t index)
{
723
    struct vmsvga_state_s *s = opaque;
B
BALATON Zoltan 已提交
724

725 726 727 728 729 730
    s->index = index;
}

static uint32_t vmsvga_value_read(void *opaque, uint32_t address)
{
    uint32_t caps;
731
    struct vmsvga_state_s *s = opaque;
732
    DisplaySurface *surface = qemu_console_surface(s->vga.con);
733
    PixelFormat pf;
734
    uint32_t ret;
B
BALATON Zoltan 已提交
735

736 737
    switch (s->index) {
    case SVGA_REG_ID:
738 739
        ret = s->svgaid;
        break;
740 741

    case SVGA_REG_ENABLE:
742 743
        ret = s->enable;
        break;
744 745

    case SVGA_REG_WIDTH:
746
        ret = s->new_width ? s->new_width : surface_width(surface);
747
        break;
748 749

    case SVGA_REG_HEIGHT:
750
        ret = s->new_height ? s->new_height : surface_height(surface);
751
        break;
752 753

    case SVGA_REG_MAX_WIDTH:
754 755
        ret = SVGA_MAX_WIDTH;
        break;
756 757

    case SVGA_REG_MAX_HEIGHT:
758 759
        ret = SVGA_MAX_HEIGHT;
        break;
760 761

    case SVGA_REG_DEPTH:
762
        ret = (s->new_depth == 32) ? 24 : s->new_depth;
763
        break;
764 765

    case SVGA_REG_BITS_PER_PIXEL:
766 767
    case SVGA_REG_HOST_BITS_PER_PIXEL:
        ret = s->new_depth;
768
        break;
769 770

    case SVGA_REG_PSEUDOCOLOR:
771 772
        ret = 0x0;
        break;
773 774

    case SVGA_REG_RED_MASK:
775 776
        pf = qemu_default_pixelformat(s->new_depth);
        ret = pf.rmask;
777
        break;
778

779
    case SVGA_REG_GREEN_MASK:
780 781
        pf = qemu_default_pixelformat(s->new_depth);
        ret = pf.gmask;
782
        break;
783

784
    case SVGA_REG_BLUE_MASK:
785 786
        pf = qemu_default_pixelformat(s->new_depth);
        ret = pf.bmask;
787
        break;
788 789

    case SVGA_REG_BYTES_PER_LINE:
790 791 792 793 794
        if (s->new_width) {
            ret = (s->new_depth * s->new_width) / 8;
        } else {
            ret = surface_stride(surface);
        }
795
        break;
796

797 798 799
    case SVGA_REG_FB_START: {
        struct pci_vmsvga_state_s *pci_vmsvga
            = container_of(s, struct pci_vmsvga_state_s, chip);
800
        ret = pci_get_bar_addr(PCI_DEVICE(pci_vmsvga), 1);
801
        break;
802
    }
803 804

    case SVGA_REG_FB_OFFSET:
805 806
        ret = 0x0;
        break;
807 808

    case SVGA_REG_VRAM_SIZE:
809 810
        ret = s->vga.vram_size; /* No physical VRAM besides the framebuffer */
        break;
811 812

    case SVGA_REG_FB_SIZE:
813 814
        ret = s->vga.vram_size;
        break;
815 816 817 818 819 820 821 822 823 824

    case SVGA_REG_CAPABILITIES:
        caps = SVGA_CAP_NONE;
#ifdef HW_RECT_ACCEL
        caps |= SVGA_CAP_RECT_COPY;
#endif
#ifdef HW_FILL_ACCEL
        caps |= SVGA_CAP_RECT_FILL;
#endif
#ifdef HW_MOUSE_ACCEL
825
        if (dpy_cursor_define_supported(s->vga.con)) {
826 827
            caps |= SVGA_CAP_CURSOR | SVGA_CAP_CURSOR_BYPASS_2 |
                    SVGA_CAP_CURSOR_BYPASS;
828
        }
829
#endif
830 831
        ret = caps;
        break;
832

833 834 835
    case SVGA_REG_MEM_START: {
        struct pci_vmsvga_state_s *pci_vmsvga
            = container_of(s, struct pci_vmsvga_state_s, chip);
836
        ret = pci_get_bar_addr(PCI_DEVICE(pci_vmsvga), 2);
837
        break;
838
    }
839 840

    case SVGA_REG_MEM_SIZE:
841 842
        ret = s->fifo_size;
        break;
843 844

    case SVGA_REG_CONFIG_DONE:
845 846
        ret = s->config;
        break;
847 848 849

    case SVGA_REG_SYNC:
    case SVGA_REG_BUSY:
850 851
        ret = s->syncing;
        break;
852 853

    case SVGA_REG_GUEST_ID:
854 855
        ret = s->guest;
        break;
856 857

    case SVGA_REG_CURSOR_ID:
858 859
        ret = s->cursor.id;
        break;
860 861

    case SVGA_REG_CURSOR_X:
862 863
        ret = s->cursor.x;
        break;
864 865

    case SVGA_REG_CURSOR_Y:
866
        ret = s->cursor.y;
867
        break;
868 869

    case SVGA_REG_CURSOR_ON:
870 871
        ret = s->cursor.on;
        break;
872 873

    case SVGA_REG_SCRATCH_SIZE:
874 875
        ret = s->scratch_size;
        break;
876 877 878 879 880

    case SVGA_REG_MEM_REGS:
    case SVGA_REG_NUM_DISPLAYS:
    case SVGA_REG_PITCHLOCK:
    case SVGA_PALETTE_BASE ... SVGA_PALETTE_END:
881 882
        ret = 0;
        break;
883 884 885

    default:
        if (s->index >= SVGA_SCRATCH_BASE &&
B
BALATON Zoltan 已提交
886
            s->index < SVGA_SCRATCH_BASE + s->scratch_size) {
887 888
            ret = s->scratch[s->index - SVGA_SCRATCH_BASE];
            break;
B
BALATON Zoltan 已提交
889 890
        }
        printf("%s: Bad register %02x\n", __func__, s->index);
891 892
        ret = 0;
        break;
893 894
    }

895 896 897 898 899 900 901 902
    if (s->index >= SVGA_SCRATCH_BASE) {
        trace_vmware_scratch_read(s->index, ret);
    } else if (s->index >= SVGA_PALETTE_BASE) {
        trace_vmware_palette_read(s->index, ret);
    } else {
        trace_vmware_value_read(s->index, ret);
    }
    return ret;
903 904 905 906
}

static void vmsvga_value_write(void *opaque, uint32_t address, uint32_t value)
{
907
    struct vmsvga_state_s *s = opaque;
B
BALATON Zoltan 已提交
908

909 910 911 912 913 914 915
    if (s->index >= SVGA_SCRATCH_BASE) {
        trace_vmware_scratch_write(s->index, value);
    } else if (s->index >= SVGA_PALETTE_BASE) {
        trace_vmware_palette_write(s->index, value);
    } else {
        trace_vmware_value_write(s->index, value);
    }
916 917
    switch (s->index) {
    case SVGA_REG_ID:
B
BALATON Zoltan 已提交
918
        if (value == SVGA_ID_2 || value == SVGA_ID_1 || value == SVGA_ID_0) {
919
            s->svgaid = value;
B
BALATON Zoltan 已提交
920
        }
921 922 923
        break;

    case SVGA_REG_ENABLE:
924
        s->enable = !!value;
925
        s->invalidated = 1;
G
Gerd Hoffmann 已提交
926
        s->vga.hw_ops->invalidate(&s->vga);
927
        if (s->enable && s->config) {
928 929 930 931
            vga_dirty_log_stop(&s->vga);
        } else {
            vga_dirty_log_start(&s->vga);
        }
932 933 934
        break;

    case SVGA_REG_WIDTH:
935 936 937 938 939 940
        if (value <= SVGA_MAX_WIDTH) {
            s->new_width = value;
            s->invalidated = 1;
        } else {
            printf("%s: Bad width: %i\n", __func__, value);
        }
941 942 943
        break;

    case SVGA_REG_HEIGHT:
944 945 946 947 948 949
        if (value <= SVGA_MAX_HEIGHT) {
            s->new_height = value;
            s->invalidated = 1;
        } else {
            printf("%s: Bad height: %i\n", __func__, value);
        }
950 951 952
        break;

    case SVGA_REG_BITS_PER_PIXEL:
953
        if (value != 32) {
954
            printf("%s: Bad bits per pixel: %i bits\n", __func__, value);
955
            s->config = 0;
956
            s->invalidated = 1;
957 958 959 960 961
        }
        break;

    case SVGA_REG_CONFIG_DONE:
        if (value) {
962
            s->fifo = (uint32_t *) s->fifo_ptr;
963
            /* Check range and alignment.  */
B
BALATON Zoltan 已提交
964
            if ((CMD(min) | CMD(max) | CMD(next_cmd) | CMD(stop)) & 3) {
965
                break;
B
BALATON Zoltan 已提交
966 967
            }
            if (CMD(min) < (uint8_t *) s->cmd->fifo - (uint8_t *) s->fifo) {
968
                break;
B
BALATON Zoltan 已提交
969 970
            }
            if (CMD(max) > SVGA_FIFO_SIZE) {
971
                break;
B
BALATON Zoltan 已提交
972 973
            }
            if (CMD(max) < CMD(min) + 10 * 1024) {
974
                break;
B
BALATON Zoltan 已提交
975
            }
976
            vga_dirty_log_stop(&s->vga);
977
        }
978
        s->config = !!value;
979 980 981 982 983 984 985 986 987 988 989
        break;

    case SVGA_REG_SYNC:
        s->syncing = 1;
        vmsvga_fifo_run(s); /* Or should we just wait for update_display? */
        break;

    case SVGA_REG_GUEST_ID:
        s->guest = value;
#ifdef VERBOSE
        if (value >= GUEST_OS_BASE && value < GUEST_OS_BASE +
B
BALATON Zoltan 已提交
990 991 992 993
            ARRAY_SIZE(vmsvga_guest_id)) {
            printf("%s: guest runs %s.\n", __func__,
                   vmsvga_guest_id[value - GUEST_OS_BASE]);
        }
994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012
#endif
        break;

    case SVGA_REG_CURSOR_ID:
        s->cursor.id = value;
        break;

    case SVGA_REG_CURSOR_X:
        s->cursor.x = value;
        break;

    case SVGA_REG_CURSOR_Y:
        s->cursor.y = value;
        break;

    case SVGA_REG_CURSOR_ON:
        s->cursor.on |= (value == SVGA_CURSOR_ON_SHOW);
        s->cursor.on &= (value != SVGA_CURSOR_ON_HIDE);
#ifdef HW_MOUSE_ACCEL
1013
        if (value <= SVGA_CURSOR_ON_SHOW) {
1014
            dpy_mouse_set(s->vga.con, s->cursor.x, s->cursor.y, s->cursor.on);
1015
        }
1016 1017 1018
#endif
        break;

1019
    case SVGA_REG_DEPTH:
1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031
    case SVGA_REG_MEM_REGS:
    case SVGA_REG_NUM_DISPLAYS:
    case SVGA_REG_PITCHLOCK:
    case SVGA_PALETTE_BASE ... SVGA_PALETTE_END:
        break;

    default:
        if (s->index >= SVGA_SCRATCH_BASE &&
                s->index < SVGA_SCRATCH_BASE + s->scratch_size) {
            s->scratch[s->index - SVGA_SCRATCH_BASE] = value;
            break;
        }
B
BALATON Zoltan 已提交
1032
        printf("%s: Bad register %02x\n", __func__, s->index);
1033 1034 1035 1036 1037
    }
}

static uint32_t vmsvga_bios_read(void *opaque, uint32_t address)
{
B
BALATON Zoltan 已提交
1038
    printf("%s: what are we supposed to return?\n", __func__);
1039 1040 1041 1042 1043
    return 0xcafe;
}

static void vmsvga_bios_write(void *opaque, uint32_t address, uint32_t data)
{
B
BALATON Zoltan 已提交
1044
    printf("%s: what are we supposed to do with (%08x)?\n", __func__, data);
1045 1046
}

1047
static inline void vmsvga_check_size(struct vmsvga_state_s *s)
1048
{
1049 1050 1051
    DisplaySurface *surface = qemu_console_surface(s->vga.con);

    if (s->new_width != surface_width(surface) ||
1052 1053 1054 1055 1056 1057 1058 1059
        s->new_height != surface_height(surface) ||
        s->new_depth != surface_bits_per_pixel(surface)) {
        int stride = (s->new_depth * s->new_width) / 8;
        trace_vmware_setmode(s->new_width, s->new_height, s->new_depth);
        surface = qemu_create_displaysurface_from(s->new_width, s->new_height,
                                                  s->new_depth, stride,
                                                  s->vga.vram_ptr, false);
        dpy_gfx_replace_surface(s->vga.con, surface);
1060 1061 1062 1063 1064 1065
        s->invalidated = 1;
    }
}

static void vmsvga_update_display(void *opaque)
{
1066
    struct vmsvga_state_s *s = opaque;
1067
    DisplaySurface *surface;
1068 1069
    bool dirty = false;

1070
    if (!s->enable) {
G
Gerd Hoffmann 已提交
1071
        s->vga.hw_ops->gfx_update(&s->vga);
1072 1073 1074
        return;
    }

1075
    vmsvga_check_size(s);
1076
    surface = qemu_console_surface(s->vga.con);
1077 1078 1079 1080 1081 1082 1083 1084

    vmsvga_fifo_run(s);
    vmsvga_update_rect_flush(s);

    /*
     * Is it more efficient to look at vram VGA-dirty bits or wait
     * for the driver to issue SVGA_CMD_UPDATE?
     */
1085 1086 1087
    if (memory_region_is_logging(&s->vga.vram)) {
        vga_sync_dirty_bitmap(&s->vga);
        dirty = memory_region_get_dirty(&s->vga.vram, 0,
1088
            surface_stride(surface) * surface_height(surface),
1089 1090 1091
            DIRTY_MEMORY_VGA);
    }
    if (s->invalidated || dirty) {
1092
        s->invalidated = 0;
1093 1094
        dpy_gfx_update(s->vga.con, 0, 0,
                   surface_width(surface), surface_height(surface));
1095 1096 1097
    }
    if (dirty) {
        memory_region_reset_dirty(&s->vga.vram, 0,
1098
            surface_stride(surface) * surface_height(surface),
1099
            DIRTY_MEMORY_VGA);
1100 1101 1102
    }
}

J
Jan Kiszka 已提交
1103
static void vmsvga_reset(DeviceState *dev)
1104
{
1105
    struct pci_vmsvga_state_s *pci = VMWARE_SVGA(dev);
J
Jan Kiszka 已提交
1106 1107
    struct vmsvga_state_s *s = &pci->chip;

1108 1109 1110 1111 1112 1113 1114 1115
    s->index = 0;
    s->enable = 0;
    s->config = 0;
    s->svgaid = SVGA_ID;
    s->cursor.on = 0;
    s->redraw_fifo_first = 0;
    s->redraw_fifo_last = 0;
    s->syncing = 0;
1116 1117

    vga_dirty_log_start(&s->vga);
1118 1119 1120 1121
}

static void vmsvga_invalidate_display(void *opaque)
{
1122
    struct vmsvga_state_s *s = opaque;
1123
    if (!s->enable) {
G
Gerd Hoffmann 已提交
1124
        s->vga.hw_ops->invalidate(&s->vga);
1125 1126 1127 1128 1129 1130
        return;
    }

    s->invalidated = 1;
}

A
Anthony Liguori 已提交
1131
static void vmsvga_text_update(void *opaque, console_ch_t *chardata)
B
balrog 已提交
1132
{
1133
    struct vmsvga_state_s *s = opaque;
B
balrog 已提交
1134

G
Gerd Hoffmann 已提交
1135 1136
    if (s->vga.hw_ops->text_update) {
        s->vga.hw_ops->text_update(&s->vga, chardata);
B
BALATON Zoltan 已提交
1137
    }
B
balrog 已提交
1138 1139
}

J
Juan Quintela 已提交
1140
static int vmsvga_post_load(void *opaque, int version_id)
1141
{
J
Juan Quintela 已提交
1142
    struct vmsvga_state_s *s = opaque;
1143 1144

    s->invalidated = 1;
B
BALATON Zoltan 已提交
1145
    if (s->config) {
1146
        s->fifo = (uint32_t *) s->fifo_ptr;
B
BALATON Zoltan 已提交
1147
    }
1148 1149 1150
    return 0;
}

B
Blue Swirl 已提交
1151
static const VMStateDescription vmstate_vmware_vga_internal = {
J
Juan Quintela 已提交
1152 1153 1154 1155
    .name = "vmware_vga_internal",
    .version_id = 0,
    .minimum_version_id = 0,
    .post_load = vmsvga_post_load,
1156
    .fields = (VMStateField[]) {
1157
        VMSTATE_INT32_EQUAL(new_depth, struct vmsvga_state_s),
J
Juan Quintela 已提交
1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171
        VMSTATE_INT32(enable, struct vmsvga_state_s),
        VMSTATE_INT32(config, struct vmsvga_state_s),
        VMSTATE_INT32(cursor.id, struct vmsvga_state_s),
        VMSTATE_INT32(cursor.x, struct vmsvga_state_s),
        VMSTATE_INT32(cursor.y, struct vmsvga_state_s),
        VMSTATE_INT32(cursor.on, struct vmsvga_state_s),
        VMSTATE_INT32(index, struct vmsvga_state_s),
        VMSTATE_VARRAY_INT32(scratch, struct vmsvga_state_s,
                             scratch_size, 0, vmstate_info_uint32, uint32_t),
        VMSTATE_INT32(new_width, struct vmsvga_state_s),
        VMSTATE_INT32(new_height, struct vmsvga_state_s),
        VMSTATE_UINT32(guest, struct vmsvga_state_s),
        VMSTATE_UINT32(svgaid, struct vmsvga_state_s),
        VMSTATE_INT32(syncing, struct vmsvga_state_s),
1172
        VMSTATE_UNUSED(4), /* was fb_size */
J
Juan Quintela 已提交
1173 1174 1175 1176
        VMSTATE_END_OF_LIST()
    }
};

B
Blue Swirl 已提交
1177
static const VMStateDescription vmstate_vmware_vga = {
J
Juan Quintela 已提交
1178 1179 1180
    .name = "vmware_vga",
    .version_id = 0,
    .minimum_version_id = 0,
1181
    .fields = (VMStateField[]) {
1182
        VMSTATE_PCI_DEVICE(parent_obj, struct pci_vmsvga_state_s),
J
Juan Quintela 已提交
1183 1184 1185 1186 1187 1188
        VMSTATE_STRUCT(chip, struct pci_vmsvga_state_s, 0,
                       vmstate_vmware_vga_internal, struct vmsvga_state_s),
        VMSTATE_END_OF_LIST()
    }
};

G
Gerd Hoffmann 已提交
1189 1190 1191 1192 1193 1194
static const GraphicHwOps vmsvga_ops = {
    .invalidate  = vmsvga_invalidate_display,
    .gfx_update  = vmsvga_update_display,
    .text_update = vmsvga_text_update,
};

1195
static void vmsvga_init(DeviceState *dev, struct vmsvga_state_s *s,
1196
                        MemoryRegion *address_space, MemoryRegion *io)
1197 1198
{
    s->scratch_size = SVGA_SCRATCH_SIZE;
1199
    s->scratch = g_malloc(s->scratch_size * 4);
1200

1201
    s->vga.con = graphic_console_init(dev, 0, &vmsvga_ops, s);
1202

1203
    s->fifo_size = SVGA_FIFO_SIZE;
1204
    memory_region_init_ram(&s->fifo_ram, NULL, "vmsvga.fifo", s->fifo_size);
1205
    vmstate_register_ram_global(&s->fifo_ram);
1206
    s->fifo_ptr = memory_region_get_ram_ptr(&s->fifo_ram);
1207

G
Gerd Hoffmann 已提交
1208
    vga_common_init(&s->vga, OBJECT(dev), true);
P
Paolo Bonzini 已提交
1209
    vga_init(&s->vga, OBJECT(dev), address_space, io, true);
A
Alex Williamson 已提交
1210
    vmstate_register(NULL, 0, &vmstate_vga_common, &s->vga);
1211
    s->new_depth = 32;
1212 1213
}

1214
static uint64_t vmsvga_io_read(void *opaque, hwaddr addr, unsigned size)
1215
{
1216 1217 1218 1219 1220 1221 1222 1223
    struct vmsvga_state_s *s = opaque;

    switch (addr) {
    case SVGA_IO_MUL * SVGA_INDEX_PORT: return vmsvga_index_read(s, addr);
    case SVGA_IO_MUL * SVGA_VALUE_PORT: return vmsvga_value_read(s, addr);
    case SVGA_IO_MUL * SVGA_BIOS_PORT: return vmsvga_bios_read(s, addr);
    default: return -1u;
    }
1224 1225
}

A
Avi Kivity 已提交
1226
static void vmsvga_io_write(void *opaque, hwaddr addr,
1227
                            uint64_t data, unsigned size)
1228
{
1229
    struct vmsvga_state_s *s = opaque;
1230

1231 1232
    switch (addr) {
    case SVGA_IO_MUL * SVGA_INDEX_PORT:
B
Blue Swirl 已提交
1233 1234
        vmsvga_index_write(s, addr, data);
        break;
1235
    case SVGA_IO_MUL * SVGA_VALUE_PORT:
B
Blue Swirl 已提交
1236 1237
        vmsvga_value_write(s, addr, data);
        break;
1238
    case SVGA_IO_MUL * SVGA_BIOS_PORT:
B
Blue Swirl 已提交
1239 1240
        vmsvga_bios_write(s, addr, data);
        break;
1241
    }
1242 1243
}

1244 1245 1246 1247 1248 1249 1250
static const MemoryRegionOps vmsvga_io_ops = {
    .read = vmsvga_io_read,
    .write = vmsvga_io_write,
    .endianness = DEVICE_LITTLE_ENDIAN,
    .valid = {
        .min_access_size = 4,
        .max_access_size = 4,
1251 1252 1253 1254
        .unaligned = true,
    },
    .impl = {
        .unaligned = true,
1255 1256
    },
};
1257

1258
static int pci_vmsvga_initfn(PCIDevice *dev)
1259
{
1260
    struct pci_vmsvga_state_s *s = VMWARE_SVGA(dev);
1261

1262 1263 1264
    dev->config[PCI_CACHE_LINE_SIZE] = 0x08;
    dev->config[PCI_LATENCY_TIMER] = 0x40;
    dev->config[PCI_INTERRUPT_LINE] = 0xff;          /* End */
1265

1266
    memory_region_init_io(&s->io_bar, NULL, &vmsvga_io_ops, &s->chip,
1267
                          "vmsvga-io", 0x10);
1268
    memory_region_set_flush_coalesced(&s->io_bar);
1269
    pci_register_bar(dev, 0, PCI_BASE_ADDRESS_SPACE_IO, &s->io_bar);
1270

1271 1272
    vmsvga_init(DEVICE(dev), &s->chip,
                pci_address_space(dev), pci_address_space_io(dev));
1273

1274
    pci_register_bar(dev, 1, PCI_BASE_ADDRESS_MEM_PREFETCH,
1275
                     &s->chip.vga.vram);
1276
    pci_register_bar(dev, 2, PCI_BASE_ADDRESS_MEM_PREFETCH,
1277
                     &s->chip.fifo_ram);
1278

1279 1280
    if (!dev->rom_bar) {
        /* compatibility with pc-0.13 and older */
P
Paolo Bonzini 已提交
1281
        vga_init_vbe(&s->chip.vga, OBJECT(dev), pci_address_space(dev));
1282 1283
    }

1284
    return 0;
1285
}
G
Gerd Hoffmann 已提交
1286

G
Gerd Hoffmann 已提交
1287 1288
static Property vga_vmware_properties[] = {
    DEFINE_PROP_UINT32("vgamem_mb", struct pci_vmsvga_state_s,
G
Gerd Hoffmann 已提交
1289
                       chip.vga.vram_size_mb, 16),
G
Gerd Hoffmann 已提交
1290 1291 1292
    DEFINE_PROP_END_OF_LIST(),
};

1293 1294
static void vmsvga_class_init(ObjectClass *klass, void *data)
{
1295
    DeviceClass *dc = DEVICE_CLASS(klass);
1296 1297 1298 1299 1300 1301 1302 1303 1304
    PCIDeviceClass *k = PCI_DEVICE_CLASS(klass);

    k->init = pci_vmsvga_initfn;
    k->romfile = "vgabios-vmware.bin";
    k->vendor_id = PCI_VENDOR_ID_VMWARE;
    k->device_id = SVGA_PCI_DEVICE_ID;
    k->class_id = PCI_CLASS_DISPLAY_VGA;
    k->subsystem_vendor_id = PCI_VENDOR_ID_VMWARE;
    k->subsystem_id = SVGA_PCI_DEVICE_ID;
1305 1306
    dc->reset = vmsvga_reset;
    dc->vmsd = &vmstate_vmware_vga;
G
Gerd Hoffmann 已提交
1307
    dc->props = vga_vmware_properties;
1308
    dc->hotpluggable = false;
1309
    set_bit(DEVICE_CATEGORY_DISPLAY, dc->categories);
1310 1311
}

1312
static const TypeInfo vmsvga_info = {
1313
    .name          = TYPE_VMWARE_SVGA,
1314 1315 1316
    .parent        = TYPE_PCI_DEVICE,
    .instance_size = sizeof(struct pci_vmsvga_state_s),
    .class_init    = vmsvga_class_init,
G
Gerd Hoffmann 已提交
1317 1318
};

A
Andreas Färber 已提交
1319
static void vmsvga_register_types(void)
G
Gerd Hoffmann 已提交
1320
{
1321
    type_register_static(&vmsvga_info);
G
Gerd Hoffmann 已提交
1322
}
A
Andreas Färber 已提交
1323 1324

type_init(vmsvga_register_types)