virtio-net.c 31.0 KB
Newer Older
A
aliguori 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13
/*
 * Virtio Network Device
 *
 * Copyright IBM, Corp. 2007
 *
 * Authors:
 *  Anthony Liguori   <aliguori@us.ibm.com>
 *
 * This work is licensed under the terms of the GNU GPL, version 2.  See
 * the COPYING file in the top-level directory.
 *
 */

14
#include "iov.h"
A
aliguori 已提交
15 16
#include "virtio.h"
#include "net.h"
17
#include "net/checksum.h"
18
#include "net/tap.h"
19
#include "qemu-error.h"
A
aliguori 已提交
20 21
#include "qemu-timer.h"
#include "virtio-net.h"
22
#include "vhost_net.h"
A
aliguori 已提交
23

24
#define VIRTIO_NET_VM_VERSION    11
25

26
#define MAC_TABLE_ENTRIES    64
27
#define MAX_VLAN    (1 << 12)   /* Per 802.1Q definition */
28

A
aliguori 已提交
29 30 31
typedef struct VirtIONet
{
    VirtIODevice vdev;
32
    uint8_t mac[ETH_ALEN];
33
    uint16_t status;
A
aliguori 已提交
34 35
    VirtQueue *rx_vq;
    VirtQueue *tx_vq;
36
    VirtQueue *ctrl_vq;
M
Mark McLoughlin 已提交
37
    NICState *nic;
A
aliguori 已提交
38
    QEMUTimer *tx_timer;
39
    QEMUBH *tx_bh;
40
    uint32_t tx_timeout;
41
    int32_t tx_burst;
42
    int tx_waiting;
M
Mark McLoughlin 已提交
43
    uint32_t has_vnet_hdr;
44
    uint8_t has_ufo;
45 46 47 48
    struct {
        VirtQueueElement elem;
        ssize_t len;
    } async_tx;
A
aliguori 已提交
49
    int mergeable_rx_bufs;
50 51
    uint8_t promisc;
    uint8_t allmulti;
52 53 54 55
    uint8_t alluni;
    uint8_t nomulti;
    uint8_t nouni;
    uint8_t nobcast;
56
    uint8_t vhost_started;
57 58
    struct {
        int in_use;
59
        int first_multi;
60 61
        uint8_t multi_overflow;
        uint8_t uni_overflow;
62 63
        uint8_t *macs;
    } mac_table;
64
    uint32_t *vlans;
65
    DeviceState *qdev;
A
aliguori 已提交
66 67 68 69 70 71 72 73 74 75 76
} VirtIONet;

/* TODO
 * - we could suppress RX interrupt if we were so inclined.
 */

static VirtIONet *to_virtio_net(VirtIODevice *vdev)
{
    return (VirtIONet *)vdev;
}

77
static void virtio_net_get_config(VirtIODevice *vdev, uint8_t *config)
A
aliguori 已提交
78 79 80 81
{
    VirtIONet *n = to_virtio_net(vdev);
    struct virtio_net_config netcfg;

82
    netcfg.status = lduw_p(&n->status);
83
    memcpy(netcfg.mac, n->mac, ETH_ALEN);
A
aliguori 已提交
84 85 86
    memcpy(config, &netcfg, sizeof(netcfg));
}

87 88 89 90 91 92 93
static void virtio_net_set_config(VirtIODevice *vdev, const uint8_t *config)
{
    VirtIONet *n = to_virtio_net(vdev);
    struct virtio_net_config netcfg;

    memcpy(&netcfg, config, sizeof(netcfg));

94 95
    if (memcmp(netcfg.mac, n->mac, ETH_ALEN)) {
        memcpy(n->mac, netcfg.mac, ETH_ALEN);
M
Mark McLoughlin 已提交
96
        qemu_format_nic_info_str(&n->nic->nc, n->mac);
97 98 99
    }
}

100 101 102
static bool virtio_net_started(VirtIONet *n, uint8_t status)
{
    return (status & VIRTIO_CONFIG_S_DRIVER_OK) &&
103
        (n->status & VIRTIO_NET_S_LINK_UP) && n->vdev.vm_running;
104 105 106
}

static void virtio_net_vhost_status(VirtIONet *n, uint8_t status)
107 108 109 110 111 112 113 114 115 116 117
{
    if (!n->nic->nc.peer) {
        return;
    }
    if (n->nic->nc.peer->info->type != NET_CLIENT_TYPE_TAP) {
        return;
    }

    if (!tap_get_vhost_net(n->nic->nc.peer)) {
        return;
    }
118
    if (!!n->vhost_started == virtio_net_started(n, status)) {
119 120 121 122 123
        return;
    }
    if (!n->vhost_started) {
        int r = vhost_net_start(tap_get_vhost_net(n->nic->nc.peer), &n->vdev);
        if (r < 0) {
124 125
            error_report("unable to start vhost net: %d: "
                         "falling back on userspace virtio", -r);
126 127 128 129 130 131 132 133 134
        } else {
            n->vhost_started = 1;
        }
    } else {
        vhost_net_stop(tap_get_vhost_net(n->nic->nc.peer), &n->vdev);
        n->vhost_started = 0;
    }
}

135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160
static void virtio_net_set_status(struct VirtIODevice *vdev, uint8_t status)
{
    VirtIONet *n = to_virtio_net(vdev);

    virtio_net_vhost_status(n, status);

    if (!n->tx_waiting) {
        return;
    }

    if (virtio_net_started(n, status) && !n->vhost_started) {
        if (n->tx_timer) {
            qemu_mod_timer(n->tx_timer,
                           qemu_get_clock(vm_clock) + n->tx_timeout);
        } else {
            qemu_bh_schedule(n->tx_bh);
        }
    } else {
        if (n->tx_timer) {
            qemu_del_timer(n->tx_timer);
        } else {
            qemu_bh_cancel(n->tx_bh);
        }
    }
}

M
Mark McLoughlin 已提交
161
static void virtio_net_set_link_status(VLANClientState *nc)
162
{
M
Mark McLoughlin 已提交
163
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
164 165
    uint16_t old_status = n->status;

M
Mark McLoughlin 已提交
166
    if (nc->link_down)
167 168 169 170 171 172
        n->status &= ~VIRTIO_NET_S_LINK_UP;
    else
        n->status |= VIRTIO_NET_S_LINK_UP;

    if (n->status != old_status)
        virtio_notify_config(&n->vdev);
173 174

    virtio_net_set_status(&n->vdev, n->vdev.status);
175 176
}

177 178 179 180 181 182 183
static void virtio_net_reset(VirtIODevice *vdev)
{
    VirtIONet *n = to_virtio_net(vdev);

    /* Reset back to compatibility mode */
    n->promisc = 1;
    n->allmulti = 0;
184 185 186 187
    n->alluni = 0;
    n->nomulti = 0;
    n->nouni = 0;
    n->nobcast = 0;
188

189
    /* Flush any MAC and VLAN filter table state */
190
    n->mac_table.in_use = 0;
191
    n->mac_table.first_multi = 0;
192 193
    n->mac_table.multi_overflow = 0;
    n->mac_table.uni_overflow = 0;
194
    memset(n->mac_table.macs, 0, MAC_TABLE_ENTRIES * ETH_ALEN);
195
    memset(n->vlans, 0, MAX_VLAN >> 3);
196 197
}

M
Mark McLoughlin 已提交
198 199
static int peer_has_vnet_hdr(VirtIONet *n)
{
M
Mark McLoughlin 已提交
200
    if (!n->nic->nc.peer)
M
Mark McLoughlin 已提交
201 202
        return 0;

203
    if (n->nic->nc.peer->info->type != NET_CLIENT_TYPE_TAP)
M
Mark McLoughlin 已提交
204 205
        return 0;

M
Mark McLoughlin 已提交
206
    n->has_vnet_hdr = tap_has_vnet_hdr(n->nic->nc.peer);
M
Mark McLoughlin 已提交
207 208 209 210

    return n->has_vnet_hdr;
}

211 212 213 214 215
static int peer_has_ufo(VirtIONet *n)
{
    if (!peer_has_vnet_hdr(n))
        return 0;

M
Mark McLoughlin 已提交
216
    n->has_ufo = tap_has_ufo(n->nic->nc.peer);
217 218 219 220

    return n->has_ufo;
}

221
static uint32_t virtio_net_get_features(VirtIODevice *vdev, uint32_t features)
A
aliguori 已提交
222
{
M
Mark McLoughlin 已提交
223
    VirtIONet *n = to_virtio_net(vdev);
A
aliguori 已提交
224

225 226
    features |= (1 << VIRTIO_NET_F_MAC);

M
Mark McLoughlin 已提交
227
    if (peer_has_vnet_hdr(n)) {
M
Mark McLoughlin 已提交
228
        tap_using_vnet_hdr(n->nic->nc.peer, 1);
229 230 231 232 233 234 235 236 237 238 239
    } else {
        features &= ~(0x1 << VIRTIO_NET_F_CSUM);
        features &= ~(0x1 << VIRTIO_NET_F_HOST_TSO4);
        features &= ~(0x1 << VIRTIO_NET_F_HOST_TSO6);
        features &= ~(0x1 << VIRTIO_NET_F_HOST_ECN);

        features &= ~(0x1 << VIRTIO_NET_F_GUEST_CSUM);
        features &= ~(0x1 << VIRTIO_NET_F_GUEST_TSO4);
        features &= ~(0x1 << VIRTIO_NET_F_GUEST_TSO6);
        features &= ~(0x1 << VIRTIO_NET_F_GUEST_ECN);
    }
M
Mark McLoughlin 已提交
240

241 242 243
    if (!peer_has_vnet_hdr(n) || !peer_has_ufo(n)) {
        features &= ~(0x1 << VIRTIO_NET_F_GUEST_UFO);
        features &= ~(0x1 << VIRTIO_NET_F_HOST_UFO);
M
Mark McLoughlin 已提交
244 245
    }

246 247 248 249 250 251 252 253
    if (!n->nic->nc.peer ||
        n->nic->nc.peer->info->type != NET_CLIENT_TYPE_TAP) {
        return features;
    }
    if (!tap_get_vhost_net(n->nic->nc.peer)) {
        return features;
    }
    return vhost_net_get_features(tap_get_vhost_net(n->nic->nc.peer), features);
A
aliguori 已提交
254 255
}

256 257 258 259 260 261 262
static uint32_t virtio_net_bad_features(VirtIODevice *vdev)
{
    uint32_t features = 0;

    /* Linux kernel 2.6.25.  It understood MAC (as everyone must),
     * but also these: */
    features |= (1 << VIRTIO_NET_F_MAC);
263 264 265 266
    features |= (1 << VIRTIO_NET_F_CSUM);
    features |= (1 << VIRTIO_NET_F_HOST_TSO4);
    features |= (1 << VIRTIO_NET_F_HOST_TSO6);
    features |= (1 << VIRTIO_NET_F_HOST_ECN);
267

268
    return features;
269 270
}

A
aliguori 已提交
271 272 273 274 275
static void virtio_net_set_features(VirtIODevice *vdev, uint32_t features)
{
    VirtIONet *n = to_virtio_net(vdev);

    n->mergeable_rx_bufs = !!(features & (1 << VIRTIO_NET_F_MRG_RXBUF));
276 277

    if (n->has_vnet_hdr) {
M
Mark McLoughlin 已提交
278
        tap_set_offload(n->nic->nc.peer,
279 280 281
                        (features >> VIRTIO_NET_F_GUEST_CSUM) & 1,
                        (features >> VIRTIO_NET_F_GUEST_TSO4) & 1,
                        (features >> VIRTIO_NET_F_GUEST_TSO6) & 1,
282 283
                        (features >> VIRTIO_NET_F_GUEST_ECN)  & 1,
                        (features >> VIRTIO_NET_F_GUEST_UFO)  & 1);
284
    }
D
David L Stevens 已提交
285 286 287 288 289 290 291
    if (!n->nic->nc.peer ||
        n->nic->nc.peer->info->type != NET_CLIENT_TYPE_TAP) {
        return;
    }
    if (!tap_get_vhost_net(n->nic->nc.peer)) {
        return;
    }
292
    vhost_net_ack_features(tap_get_vhost_net(n->nic->nc.peer), features);
A
aliguori 已提交
293 294
}

295 296 297 298 299 300
static int virtio_net_handle_rx_mode(VirtIONet *n, uint8_t cmd,
                                     VirtQueueElement *elem)
{
    uint8_t on;

    if (elem->out_num != 2 || elem->out_sg[1].iov_len != sizeof(on)) {
301
        error_report("virtio-net ctrl invalid rx mode command");
302 303 304 305 306 307 308 309 310
        exit(1);
    }

    on = ldub_p(elem->out_sg[1].iov_base);

    if (cmd == VIRTIO_NET_CTRL_RX_MODE_PROMISC)
        n->promisc = on;
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_ALLMULTI)
        n->allmulti = on;
311 312 313 314 315 316 317 318
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_ALLUNI)
        n->alluni = on;
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_NOMULTI)
        n->nomulti = on;
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_NOUNI)
        n->nouni = on;
    else if (cmd == VIRTIO_NET_CTRL_RX_MODE_NOBCAST)
        n->nobcast = on;
319 320 321 322 323 324
    else
        return VIRTIO_NET_ERR;

    return VIRTIO_NET_OK;
}

325 326 327 328 329 330 331 332 333 334 335
static int virtio_net_handle_mac(VirtIONet *n, uint8_t cmd,
                                 VirtQueueElement *elem)
{
    struct virtio_net_ctrl_mac mac_data;

    if (cmd != VIRTIO_NET_CTRL_MAC_TABLE_SET || elem->out_num != 3 ||
        elem->out_sg[1].iov_len < sizeof(mac_data) ||
        elem->out_sg[2].iov_len < sizeof(mac_data))
        return VIRTIO_NET_ERR;

    n->mac_table.in_use = 0;
336
    n->mac_table.first_multi = 0;
337 338
    n->mac_table.uni_overflow = 0;
    n->mac_table.multi_overflow = 0;
339 340
    memset(n->mac_table.macs, 0, MAC_TABLE_ENTRIES * ETH_ALEN);

341
    mac_data.entries = ldl_p(elem->out_sg[1].iov_base);
342 343 344 345 346 347 348 349 350 351

    if (sizeof(mac_data.entries) +
        (mac_data.entries * ETH_ALEN) > elem->out_sg[1].iov_len)
        return VIRTIO_NET_ERR;

    if (mac_data.entries <= MAC_TABLE_ENTRIES) {
        memcpy(n->mac_table.macs, elem->out_sg[1].iov_base + sizeof(mac_data),
               mac_data.entries * ETH_ALEN);
        n->mac_table.in_use += mac_data.entries;
    } else {
352
        n->mac_table.uni_overflow = 1;
353 354
    }

355 356
    n->mac_table.first_multi = n->mac_table.in_use;

357
    mac_data.entries = ldl_p(elem->out_sg[2].iov_base);
358 359 360 361 362 363 364 365 366 367 368

    if (sizeof(mac_data.entries) +
        (mac_data.entries * ETH_ALEN) > elem->out_sg[2].iov_len)
        return VIRTIO_NET_ERR;

    if (mac_data.entries) {
        if (n->mac_table.in_use + mac_data.entries <= MAC_TABLE_ENTRIES) {
            memcpy(n->mac_table.macs + (n->mac_table.in_use * ETH_ALEN),
                   elem->out_sg[2].iov_base + sizeof(mac_data),
                   mac_data.entries * ETH_ALEN);
            n->mac_table.in_use += mac_data.entries;
369 370 371
        } else {
            n->mac_table.multi_overflow = 1;
        }
372 373 374 375 376
    }

    return VIRTIO_NET_OK;
}

377 378 379 380 381 382
static int virtio_net_handle_vlan_table(VirtIONet *n, uint8_t cmd,
                                        VirtQueueElement *elem)
{
    uint16_t vid;

    if (elem->out_num != 2 || elem->out_sg[1].iov_len != sizeof(vid)) {
383
        error_report("virtio-net ctrl invalid vlan command");
384 385 386
        return VIRTIO_NET_ERR;
    }

387
    vid = lduw_p(elem->out_sg[1].iov_base);
388 389 390 391 392 393 394 395 396 397 398 399 400 401

    if (vid >= MAX_VLAN)
        return VIRTIO_NET_ERR;

    if (cmd == VIRTIO_NET_CTRL_VLAN_ADD)
        n->vlans[vid >> 5] |= (1U << (vid & 0x1f));
    else if (cmd == VIRTIO_NET_CTRL_VLAN_DEL)
        n->vlans[vid >> 5] &= ~(1U << (vid & 0x1f));
    else
        return VIRTIO_NET_ERR;

    return VIRTIO_NET_OK;
}

402 403
static void virtio_net_handle_ctrl(VirtIODevice *vdev, VirtQueue *vq)
{
404
    VirtIONet *n = to_virtio_net(vdev);
405 406 407 408 409 410
    struct virtio_net_ctrl_hdr ctrl;
    virtio_net_ctrl_ack status = VIRTIO_NET_ERR;
    VirtQueueElement elem;

    while (virtqueue_pop(vq, &elem)) {
        if ((elem.in_num < 1) || (elem.out_num < 1)) {
411
            error_report("virtio-net ctrl missing headers");
412 413 414 415
            exit(1);
        }

        if (elem.out_sg[0].iov_len < sizeof(ctrl) ||
416
            elem.in_sg[elem.in_num - 1].iov_len < sizeof(status)) {
417
            error_report("virtio-net ctrl header not in correct element");
418 419 420 421 422 423
            exit(1);
        }

        ctrl.class = ldub_p(elem.out_sg[0].iov_base);
        ctrl.cmd = ldub_p(elem.out_sg[0].iov_base + sizeof(ctrl.class));

424 425
        if (ctrl.class == VIRTIO_NET_CTRL_RX_MODE)
            status = virtio_net_handle_rx_mode(n, ctrl.cmd, &elem);
426 427
        else if (ctrl.class == VIRTIO_NET_CTRL_MAC)
            status = virtio_net_handle_mac(n, ctrl.cmd, &elem);
428 429
        else if (ctrl.class == VIRTIO_NET_CTRL_VLAN)
            status = virtio_net_handle_vlan_table(n, ctrl.cmd, &elem);
430

431 432 433 434 435 436 437
        stb_p(elem.in_sg[elem.in_num - 1].iov_base, status);

        virtqueue_push(vq, &elem, sizeof(status));
        virtio_notify(vdev, vq);
    }
}

A
aliguori 已提交
438 439 440 441
/* RX */

static void virtio_net_handle_rx(VirtIODevice *vdev, VirtQueue *vq)
{
442 443
    VirtIONet *n = to_virtio_net(vdev);

M
Mark McLoughlin 已提交
444
    qemu_flush_queued_packets(&n->nic->nc);
445 446 447 448

    /* We now have RX buffers, signal to the IO thread to break out of the
     * select to re-poll the tap file descriptor */
    qemu_notify_event();
A
aliguori 已提交
449 450
}

M
Mark McLoughlin 已提交
451
static int virtio_net_can_receive(VLANClientState *nc)
A
aliguori 已提交
452
{
M
Mark McLoughlin 已提交
453
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
454
    if (!n->vdev.vm_running) {
455 456
        return 0;
    }
457

A
aliguori 已提交
458 459 460 461
    if (!virtio_queue_ready(n->rx_vq) ||
        !(n->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK))
        return 0;

462 463 464 465 466
    return 1;
}

static int virtio_net_has_buffers(VirtIONet *n, int bufsize)
{
A
aliguori 已提交
467 468 469 470
    if (virtio_queue_empty(n->rx_vq) ||
        (n->mergeable_rx_bufs &&
         !virtqueue_avail_bytes(n->rx_vq, bufsize, 0))) {
        virtio_queue_set_notification(n->rx_vq, 1);
471 472 473 474 475 476 477 478 479

        /* To avoid a race condition where the guest has made some buffers
         * available after the above check but before notification was
         * enabled, check for available buffers again.
         */
        if (virtio_queue_empty(n->rx_vq) ||
            (n->mergeable_rx_bufs &&
             !virtqueue_avail_bytes(n->rx_vq, bufsize, 0)))
            return 0;
A
aliguori 已提交
480 481 482 483 484 485
    }

    virtio_queue_set_notification(n->rx_vq, 0);
    return 1;
}

A
Anthony Liguori 已提交
486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513
/* dhclient uses AF_PACKET but doesn't pass auxdata to the kernel so
 * it never finds out that the packets don't have valid checksums.  This
 * causes dhclient to get upset.  Fedora's carried a patch for ages to
 * fix this with Xen but it hasn't appeared in an upstream release of
 * dhclient yet.
 *
 * To avoid breaking existing guests, we catch udp packets and add
 * checksums.  This is terrible but it's better than hacking the guest
 * kernels.
 *
 * N.B. if we introduce a zero-copy API, this operation is no longer free so
 * we should provide a mechanism to disable it to avoid polluting the host
 * cache.
 */
static void work_around_broken_dhclient(struct virtio_net_hdr *hdr,
                                        const uint8_t *buf, size_t size)
{
    if ((hdr->flags & VIRTIO_NET_HDR_F_NEEDS_CSUM) && /* missing csum */
        (size > 27 && size < 1500) && /* normal sized MTU */
        (buf[12] == 0x08 && buf[13] == 0x00) && /* ethertype == IPv4 */
        (buf[23] == 17) && /* ip.protocol == UDP */
        (buf[34] == 0 && buf[35] == 67)) { /* udp.srcport == bootps */
        /* FIXME this cast is evil */
        net_checksum_calculate((uint8_t *)buf, size);
        hdr->flags &= ~VIRTIO_NET_HDR_F_NEEDS_CSUM;
    }
}

A
aliguori 已提交
514
static int receive_header(VirtIONet *n, struct iovec *iov, int iovcnt,
A
aliguori 已提交
515
                          const void *buf, size_t size, size_t hdr_len)
A
aliguori 已提交
516
{
517
    struct virtio_net_hdr *hdr = (struct virtio_net_hdr *)iov[0].iov_base;
A
aliguori 已提交
518 519 520 521 522
    int offset = 0;

    hdr->flags = 0;
    hdr->gso_type = VIRTIO_NET_HDR_GSO_NONE;

M
Mark McLoughlin 已提交
523 524 525
    if (n->has_vnet_hdr) {
        memcpy(hdr, buf, sizeof(*hdr));
        offset = sizeof(*hdr);
A
Anthony Liguori 已提交
526
        work_around_broken_dhclient(hdr, buf + offset, size - offset);
M
Mark McLoughlin 已提交
527 528
    }

A
aliguori 已提交
529 530 531 532 533 534 535 536 537
    /* We only ever receive a struct virtio_net_hdr from the tapfd,
     * but we may be passing along a larger header to the guest.
     */
    iov[0].iov_base += hdr_len;
    iov[0].iov_len  -= hdr_len;

    return offset;
}

538 539 540
static int receive_filter(VirtIONet *n, const uint8_t *buf, int size)
{
    static const uint8_t bcast[] = {0xff, 0xff, 0xff, 0xff, 0xff, 0xff};
541
    static const uint8_t vlan[] = {0x81, 0x00};
542
    uint8_t *ptr = (uint8_t *)buf;
543
    int i;
544 545 546 547

    if (n->promisc)
        return 1;

M
Mark McLoughlin 已提交
548 549 550 551
    if (n->has_vnet_hdr) {
        ptr += sizeof(struct virtio_net_hdr);
    }

552 553 554 555 556 557
    if (!memcmp(&ptr[12], vlan, sizeof(vlan))) {
        int vid = be16_to_cpup((uint16_t *)(ptr + 14)) & 0xfff;
        if (!(n->vlans[vid >> 5] & (1U << (vid & 0x1f))))
            return 0;
    }

558 559
    if (ptr[0] & 1) { // multicast
        if (!memcmp(ptr, bcast, sizeof(bcast))) {
560 561 562
            return !n->nobcast;
        } else if (n->nomulti) {
            return 0;
563
        } else if (n->allmulti || n->mac_table.multi_overflow) {
564 565
            return 1;
        }
566 567 568 569 570 571

        for (i = n->mac_table.first_multi; i < n->mac_table.in_use; i++) {
            if (!memcmp(ptr, &n->mac_table.macs[i * ETH_ALEN], ETH_ALEN)) {
                return 1;
            }
        }
572
    } else { // unicast
573 574 575
        if (n->nouni) {
            return 0;
        } else if (n->alluni || n->mac_table.uni_overflow) {
576 577
            return 1;
        } else if (!memcmp(ptr, n->mac, ETH_ALEN)) {
578 579
            return 1;
        }
580

581 582 583 584 585
        for (i = 0; i < n->mac_table.first_multi; i++) {
            if (!memcmp(ptr, &n->mac_table.macs[i * ETH_ALEN], ETH_ALEN)) {
                return 1;
            }
        }
586 587
    }

588 589 590
    return 0;
}

M
Mark McLoughlin 已提交
591
static ssize_t virtio_net_receive(VLANClientState *nc, const uint8_t *buf, size_t size)
A
aliguori 已提交
592
{
M
Mark McLoughlin 已提交
593
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
A
aliguori 已提交
594
    struct virtio_net_hdr_mrg_rxbuf *mhdr = NULL;
595
    size_t guest_hdr_len, offset, i, host_hdr_len;
A
aliguori 已提交
596

M
Mark McLoughlin 已提交
597
    if (!virtio_net_can_receive(&n->nic->nc))
598 599
        return -1;

600
    /* hdr_len refers to the header we supply to the guest */
601
    guest_hdr_len = n->mergeable_rx_bufs ?
602 603 604
        sizeof(struct virtio_net_hdr_mrg_rxbuf) : sizeof(struct virtio_net_hdr);


605 606
    host_hdr_len = n->has_vnet_hdr ? sizeof(struct virtio_net_hdr) : 0;
    if (!virtio_net_has_buffers(n, size + guest_hdr_len - host_hdr_len))
607
        return 0;
A
aliguori 已提交
608

609
    if (!receive_filter(n, buf, size))
610
        return size;
611

A
aliguori 已提交
612 613 614 615 616 617 618
    offset = i = 0;

    while (offset < size) {
        VirtQueueElement elem;
        int len, total;
        struct iovec sg[VIRTQUEUE_MAX_SIZE];

A
Amit Shah 已提交
619
        total = 0;
A
aliguori 已提交
620

621
        if (virtqueue_pop(n->rx_vq, &elem) == 0) {
A
aliguori 已提交
622
            if (i == 0)
623
                return -1;
624
            error_report("virtio-net unexpected empty queue: "
625
                    "i %zd mergeable %d offset %zd, size %zd, "
626
                    "guest hdr len %zd, host hdr len %zd guest features 0x%x",
627 628
                    i, n->mergeable_rx_bufs, offset, size,
                    guest_hdr_len, host_hdr_len, n->vdev.guest_features);
A
aliguori 已提交
629 630 631 632
            exit(1);
        }

        if (elem.in_num < 1) {
633
            error_report("virtio-net receive queue contains no in buffers");
A
aliguori 已提交
634 635 636
            exit(1);
        }

637
        if (!n->mergeable_rx_bufs && elem.in_sg[0].iov_len != guest_hdr_len) {
638
            error_report("virtio-net header not in first element");
A
aliguori 已提交
639 640 641 642 643 644 645 646 647 648
            exit(1);
        }

        memcpy(&sg, &elem.in_sg[0], sizeof(sg[0]) * elem.in_num);

        if (i == 0) {
            if (n->mergeable_rx_bufs)
                mhdr = (struct virtio_net_hdr_mrg_rxbuf *)sg[0].iov_base;

            offset += receive_header(n, sg, elem.in_num,
649 650
                                     buf + offset, size - offset, guest_hdr_len);
            total += guest_hdr_len;
A
aliguori 已提交
651 652 653
        }

        /* copy in packet.  ugh */
654 655
        len = iov_from_buf(sg, elem.in_num,
                           buf + offset, size - offset);
A
aliguori 已提交
656
        total += len;
657 658 659 660 661 662
        offset += len;
        /* If buffers can't be merged, at this point we
         * must have consumed the complete packet.
         * Otherwise, drop it. */
        if (!n->mergeable_rx_bufs && offset < size) {
#if 0
663 664 665 666 667
            error_report("virtio-net truncated non-mergeable packet: "
                         "i %zd mergeable %d offset %zd, size %zd, "
                         "guest hdr len %zd, host hdr len %zd",
                         i, n->mergeable_rx_bufs,
                         offset, size, guest_hdr_len, host_hdr_len);
668 669 670
#endif
            return size;
        }
A
aliguori 已提交
671 672 673 674 675

        /* signal other side */
        virtqueue_fill(n->rx_vq, &elem, total, i++);
    }

676 677 678
    if (mhdr) {
        mhdr->num_buffers = lduw_p(&i);
    }
A
aliguori 已提交
679 680 681

    virtqueue_flush(n->rx_vq, i);
    virtio_notify(&n->vdev, n->rx_vq);
682 683

    return size;
A
aliguori 已提交
684 685
}

686
static int32_t virtio_net_flush_tx(VirtIONet *n, VirtQueue *vq);
687

M
Mark McLoughlin 已提交
688
static void virtio_net_tx_complete(VLANClientState *nc, ssize_t len)
689
{
M
Mark McLoughlin 已提交
690
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
691 692 693 694 695 696 697 698 699 700

    virtqueue_push(n->tx_vq, &n->async_tx.elem, n->async_tx.len);
    virtio_notify(&n->vdev, n->tx_vq);

    n->async_tx.elem.out_num = n->async_tx.len = 0;

    virtio_queue_set_notification(n->tx_vq, 1);
    virtio_net_flush_tx(n, n->tx_vq);
}

A
aliguori 已提交
701
/* TX */
702
static int32_t virtio_net_flush_tx(VirtIONet *n, VirtQueue *vq)
A
aliguori 已提交
703 704
{
    VirtQueueElement elem;
705 706 707 708
    int32_t num_packets = 0;
    if (!(n->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK)) {
        return num_packets;
    }
A
aliguori 已提交
709

710
    assert(n->vdev.vm_running);
711

712 713
    if (n->async_tx.elem.out_num) {
        virtio_queue_set_notification(n->tx_vq, 0);
714
        return num_packets;
715 716
    }

A
aliguori 已提交
717
    while (virtqueue_pop(vq, &elem)) {
718
        ssize_t ret, len = 0;
A
aliguori 已提交
719 720 721 722 723 724 725 726 727 728
        unsigned int out_num = elem.out_num;
        struct iovec *out_sg = &elem.out_sg[0];
        unsigned hdr_len;

        /* hdr_len refers to the header received from the guest */
        hdr_len = n->mergeable_rx_bufs ?
            sizeof(struct virtio_net_hdr_mrg_rxbuf) :
            sizeof(struct virtio_net_hdr);

        if (out_num < 1 || out_sg->iov_len != hdr_len) {
729
            error_report("virtio-net header not in first element");
A
aliguori 已提交
730 731 732 733
            exit(1);
        }

        /* ignore the header if GSO is not supported */
M
Mark McLoughlin 已提交
734
        if (!n->has_vnet_hdr) {
A
aliguori 已提交
735 736 737 738 739 740 741 742 743 744
            out_num--;
            out_sg++;
            len += hdr_len;
        } else if (n->mergeable_rx_bufs) {
            /* tapfd expects a struct virtio_net_hdr */
            hdr_len -= sizeof(struct virtio_net_hdr);
            out_sg->iov_len -= hdr_len;
            len += hdr_len;
        }

M
Mark McLoughlin 已提交
745
        ret = qemu_sendv_packet_async(&n->nic->nc, out_sg, out_num,
746 747 748 749 750
                                      virtio_net_tx_complete);
        if (ret == 0) {
            virtio_queue_set_notification(n->tx_vq, 0);
            n->async_tx.elem = elem;
            n->async_tx.len  = len;
751
            return -EBUSY;
752 753 754
        }

        len += ret;
A
aliguori 已提交
755 756 757

        virtqueue_push(vq, &elem, len);
        virtio_notify(&n->vdev, vq);
758 759 760 761

        if (++num_packets >= n->tx_burst) {
            break;
        }
A
aliguori 已提交
762
    }
763
    return num_packets;
A
aliguori 已提交
764 765
}

766
static void virtio_net_handle_tx_timer(VirtIODevice *vdev, VirtQueue *vq)
A
aliguori 已提交
767 768 769
{
    VirtIONet *n = to_virtio_net(vdev);

770
    /* This happens when device was stopped but VCPU wasn't. */
771
    if (!n->vdev.vm_running) {
772 773 774 775
        n->tx_waiting = 1;
        return;
    }

776
    if (n->tx_waiting) {
A
aliguori 已提交
777 778
        virtio_queue_set_notification(vq, 1);
        qemu_del_timer(n->tx_timer);
779
        n->tx_waiting = 0;
A
aliguori 已提交
780 781 782
        virtio_net_flush_tx(n, vq);
    } else {
        qemu_mod_timer(n->tx_timer,
783
                       qemu_get_clock(vm_clock) + n->tx_timeout);
784
        n->tx_waiting = 1;
A
aliguori 已提交
785 786 787 788
        virtio_queue_set_notification(vq, 0);
    }
}

789 790 791 792 793 794 795
static void virtio_net_handle_tx_bh(VirtIODevice *vdev, VirtQueue *vq)
{
    VirtIONet *n = to_virtio_net(vdev);

    if (unlikely(n->tx_waiting)) {
        return;
    }
796 797
    n->tx_waiting = 1;
    /* This happens when device was stopped but VCPU wasn't. */
798
    if (!n->vdev.vm_running) {
799 800
        return;
    }
801 802 803 804
    virtio_queue_set_notification(vq, 0);
    qemu_bh_schedule(n->tx_bh);
}

A
aliguori 已提交
805 806 807
static void virtio_net_tx_timer(void *opaque)
{
    VirtIONet *n = opaque;
808
    assert(n->vdev.vm_running);
A
aliguori 已提交
809

810
    n->tx_waiting = 0;
A
aliguori 已提交
811 812 813 814 815 816 817 818 819

    /* Just in case the driver is not ready on more */
    if (!(n->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK))
        return;

    virtio_queue_set_notification(n->tx_vq, 1);
    virtio_net_flush_tx(n, n->tx_vq);
}

820 821 822 823 824
static void virtio_net_tx_bh(void *opaque)
{
    VirtIONet *n = opaque;
    int32_t ret;

825
    assert(n->vdev.vm_running);
826

827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856
    n->tx_waiting = 0;

    /* Just in case the driver is not ready on more */
    if (unlikely(!(n->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK)))
        return;

    ret = virtio_net_flush_tx(n, n->tx_vq);
    if (ret == -EBUSY) {
        return; /* Notification re-enable handled by tx_complete */
    }

    /* If we flush a full burst of packets, assume there are
     * more coming and immediately reschedule */
    if (ret >= n->tx_burst) {
        qemu_bh_schedule(n->tx_bh);
        n->tx_waiting = 1;
        return;
    }

    /* If less than a full burst, re-enable notification and flush
     * anything that may have come in while we weren't looking.  If
     * we find something, assume the guest is still active and reschedule */
    virtio_queue_set_notification(n->tx_vq, 1);
    if (virtio_net_flush_tx(n, n->tx_vq) > 0) {
        virtio_queue_set_notification(n->tx_vq, 0);
        qemu_bh_schedule(n->tx_bh);
        n->tx_waiting = 1;
    }
}

A
aliguori 已提交
857 858 859 860
static void virtio_net_save(QEMUFile *f, void *opaque)
{
    VirtIONet *n = opaque;

861 862 863
    /* At this point, backend must be stopped, otherwise
     * it might keep writing to memory. */
    assert(!n->vhost_started);
A
aliguori 已提交
864 865
    virtio_save(&n->vdev, f);

866
    qemu_put_buffer(f, n->mac, ETH_ALEN);
867
    qemu_put_be32(f, n->tx_waiting);
868
    qemu_put_be32(f, n->mergeable_rx_bufs);
869
    qemu_put_be16(f, n->status);
870 871
    qemu_put_byte(f, n->promisc);
    qemu_put_byte(f, n->allmulti);
872 873
    qemu_put_be32(f, n->mac_table.in_use);
    qemu_put_buffer(f, n->mac_table.macs, n->mac_table.in_use * ETH_ALEN);
874
    qemu_put_buffer(f, (uint8_t *)n->vlans, MAX_VLAN >> 3);
M
Mark McLoughlin 已提交
875
    qemu_put_be32(f, n->has_vnet_hdr);
876 877
    qemu_put_byte(f, n->mac_table.multi_overflow);
    qemu_put_byte(f, n->mac_table.uni_overflow);
878 879 880 881
    qemu_put_byte(f, n->alluni);
    qemu_put_byte(f, n->nomulti);
    qemu_put_byte(f, n->nouni);
    qemu_put_byte(f, n->nobcast);
882
    qemu_put_byte(f, n->has_ufo);
A
aliguori 已提交
883 884 885 886 887
}

static int virtio_net_load(QEMUFile *f, void *opaque, int version_id)
{
    VirtIONet *n = opaque;
888
    int i;
A
aliguori 已提交
889

890
    if (version_id < 2 || version_id > VIRTIO_NET_VM_VERSION)
A
aliguori 已提交
891 892 893 894
        return -EINVAL;

    virtio_load(&n->vdev, f);

895
    qemu_get_buffer(f, n->mac, ETH_ALEN);
896
    n->tx_waiting = qemu_get_be32(f);
897
    n->mergeable_rx_bufs = qemu_get_be32(f);
A
aliguori 已提交
898

899 900 901
    if (version_id >= 3)
        n->status = qemu_get_be16(f);

902
    if (version_id >= 4) {
903 904 905 906 907 908 909
        if (version_id < 8) {
            n->promisc = qemu_get_be32(f);
            n->allmulti = qemu_get_be32(f);
        } else {
            n->promisc = qemu_get_byte(f);
            n->allmulti = qemu_get_byte(f);
        }
910 911
    }

912 913 914 915 916 917 918 919
    if (version_id >= 5) {
        n->mac_table.in_use = qemu_get_be32(f);
        /* MAC_TABLE_ENTRIES may be different from the saved image */
        if (n->mac_table.in_use <= MAC_TABLE_ENTRIES) {
            qemu_get_buffer(f, n->mac_table.macs,
                            n->mac_table.in_use * ETH_ALEN);
        } else if (n->mac_table.in_use) {
            qemu_fseek(f, n->mac_table.in_use * ETH_ALEN, SEEK_CUR);
920
            n->mac_table.multi_overflow = n->mac_table.uni_overflow = 1;
921 922 923 924
            n->mac_table.in_use = 0;
        }
    }
 
925 926 927
    if (version_id >= 6)
        qemu_get_buffer(f, (uint8_t *)n->vlans, MAX_VLAN >> 3);

M
Mark McLoughlin 已提交
928 929
    if (version_id >= 7) {
        if (qemu_get_be32(f) && !peer_has_vnet_hdr(n)) {
930
            error_report("virtio-net: saved image requires vnet_hdr=on");
M
Mark McLoughlin 已提交
931 932 933 934
            return -1;
        }

        if (n->has_vnet_hdr) {
M
Mark McLoughlin 已提交
935 936
            tap_using_vnet_hdr(n->nic->nc.peer, 1);
            tap_set_offload(n->nic->nc.peer,
937 938 939 940 941
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_CSUM) & 1,
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_TSO4) & 1,
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_TSO6) & 1,
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_ECN)  & 1,
                    (n->vdev.guest_features >> VIRTIO_NET_F_GUEST_UFO)  & 1);
M
Mark McLoughlin 已提交
942
        }
943 944
    }

945 946 947 948 949
    if (version_id >= 9) {
        n->mac_table.multi_overflow = qemu_get_byte(f);
        n->mac_table.uni_overflow = qemu_get_byte(f);
    }

950 951 952 953 954 955 956
    if (version_id >= 10) {
        n->alluni = qemu_get_byte(f);
        n->nomulti = qemu_get_byte(f);
        n->nouni = qemu_get_byte(f);
        n->nobcast = qemu_get_byte(f);
    }

957 958
    if (version_id >= 11) {
        if (qemu_get_byte(f) && !peer_has_ufo(n)) {
959
            error_report("virtio-net: saved image requires TUN_F_UFO support");
960 961 962 963
            return -1;
        }
    }

964 965 966 967 968 969 970
    /* Find the first multicast entry in the saved MAC filter */
    for (i = 0; i < n->mac_table.in_use; i++) {
        if (n->mac_table.macs[i * ETH_ALEN] & 1) {
            break;
        }
    }
    n->mac_table.first_multi = i;
A
aliguori 已提交
971 972 973
    return 0;
}

M
Mark McLoughlin 已提交
974
static void virtio_net_cleanup(VLANClientState *nc)
975
{
M
Mark McLoughlin 已提交
976
    VirtIONet *n = DO_UPCAST(NICState, nc, nc)->opaque;
977

M
Mark McLoughlin 已提交
978
    n->nic = NULL;
979 980
}

M
Mark McLoughlin 已提交
981 982 983 984 985 986 987 988 989
static NetClientInfo net_virtio_info = {
    .type = NET_CLIENT_TYPE_NIC,
    .size = sizeof(NICState),
    .can_receive = virtio_net_can_receive,
    .receive = virtio_net_receive,
        .cleanup = virtio_net_cleanup,
    .link_status_changed = virtio_net_set_link_status,
};

990 991
VirtIODevice *virtio_net_init(DeviceState *dev, NICConf *conf,
                              virtio_net_conf *net)
A
aliguori 已提交
992 993 994
{
    VirtIONet *n;

P
Paul Brook 已提交
995 996 997
    n = (VirtIONet *)virtio_common_init("virtio-net", VIRTIO_ID_NET,
                                        sizeof(struct virtio_net_config),
                                        sizeof(VirtIONet));
A
aliguori 已提交
998

999 1000
    n->vdev.get_config = virtio_net_get_config;
    n->vdev.set_config = virtio_net_set_config;
A
aliguori 已提交
1001 1002
    n->vdev.get_features = virtio_net_get_features;
    n->vdev.set_features = virtio_net_set_features;
1003
    n->vdev.bad_features = virtio_net_bad_features;
1004
    n->vdev.reset = virtio_net_reset;
1005
    n->vdev.set_status = virtio_net_set_status;
A
aliguori 已提交
1006
    n->rx_vq = virtio_add_queue(&n->vdev, 256, virtio_net_handle_rx);
1007 1008

    if (net->tx && strcmp(net->tx, "timer") && strcmp(net->tx, "bh")) {
1009 1010 1011 1012
        error_report("virtio-net: "
                     "Unknown option tx=%s, valid options: \"timer\" \"bh\"",
                     net->tx);
        error_report("Defaulting to \"bh\"");
1013 1014 1015 1016 1017 1018 1019 1020 1021 1022
    }

    if (net->tx && !strcmp(net->tx, "timer")) {
        n->tx_vq = virtio_add_queue(&n->vdev, 256, virtio_net_handle_tx_timer);
        n->tx_timer = qemu_new_timer(vm_clock, virtio_net_tx_timer, n);
        n->tx_timeout = net->txtimer;
    } else {
        n->tx_vq = virtio_add_queue(&n->vdev, 256, virtio_net_handle_tx_bh);
        n->tx_bh = qemu_bh_new(virtio_net_tx_bh, n);
    }
1023
    n->ctrl_vq = virtio_add_queue(&n->vdev, 64, virtio_net_handle_ctrl);
1024
    qemu_macaddr_default_if_unset(&conf->macaddr);
1025
    memcpy(&n->mac[0], &conf->macaddr, sizeof(n->mac));
1026
    n->status = VIRTIO_NET_S_LINK_UP;
A
aliguori 已提交
1027

M
Mark McLoughlin 已提交
1028 1029 1030
    n->nic = qemu_new_nic(&net_virtio_info, conf, dev->info->name, dev->id, n);

    qemu_format_nic_info_str(&n->nic->nc, conf->macaddr.a);
1031

1032
    n->tx_waiting = 0;
1033
    n->tx_burst = net->txburst;
A
aliguori 已提交
1034
    n->mergeable_rx_bufs = 0;
1035
    n->promisc = 1; /* for compatibility */
A
aliguori 已提交
1036

1037 1038
    n->mac_table.macs = qemu_mallocz(MAC_TABLE_ENTRIES * ETH_ALEN);

1039 1040
    n->vlans = qemu_mallocz(MAX_VLAN >> 3);

1041 1042
    n->qdev = dev;
    register_savevm(dev, "virtio-net", -1, VIRTIO_NET_VM_VERSION,
A
aliguori 已提交
1043
                    virtio_net_save, virtio_net_load, n);
P
Paul Brook 已提交
1044

1045 1046
    add_boot_device_path(conf->bootindex, dev, "/ethernet-phy@0");

P
Paul Brook 已提交
1047
    return &n->vdev;
P
Paul Brook 已提交
1048
}
1049 1050 1051 1052

void virtio_net_exit(VirtIODevice *vdev)
{
    VirtIONet *n = DO_UPCAST(VirtIONet, vdev, vdev);
1053

1054 1055
    /* This will stop vhost backend if appropriate. */
    virtio_net_set_status(vdev, 0);
1056

M
Mark McLoughlin 已提交
1057
    qemu_purge_queued_packets(&n->nic->nc);
1058

1059
    unregister_savevm(n->qdev, "virtio-net", n);
1060 1061 1062 1063

    qemu_free(n->mac_table.macs);
    qemu_free(n->vlans);

1064 1065 1066 1067 1068 1069
    if (n->tx_timer) {
        qemu_del_timer(n->tx_timer);
        qemu_free_timer(n->tx_timer);
    } else {
        qemu_bh_delete(n->tx_bh);
    }
1070 1071

    virtio_cleanup(&n->vdev);
M
Mark McLoughlin 已提交
1072
    qemu_del_vlan_client(&n->nic->nc);
1073
}