pc.c 38.6 KB
Newer Older
B
bellard 已提交
1 2
/*
 * QEMU PC System Emulator
3
 *
B
bellard 已提交
4
 * Copyright (c) 2003-2004 Fabrice Bellard
5
 *
B
bellard 已提交
6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
 * Permission is hereby granted, free of charge, to any person obtaining a copy
 * of this software and associated documentation files (the "Software"), to deal
 * in the Software without restriction, including without limitation the rights
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
 * copies of the Software, and to permit persons to whom the Software is
 * furnished to do so, subject to the following conditions:
 *
 * The above copyright notice and this permission notice shall be included in
 * all copies or substantial portions of the Software.
 *
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
 * THE SOFTWARE.
 */
24
#include "hw/hw.h"
P
Paolo Bonzini 已提交
25 26 27 28
#include "hw/i386/pc.h"
#include "hw/char/serial.h"
#include "hw/i386/apic.h"
#include "hw/block/fdc.h"
29 30
#include "hw/ide.h"
#include "hw/pci/pci.h"
31
#include "monitor/monitor.h"
P
Paolo Bonzini 已提交
32 33 34
#include "hw/nvram/fw_cfg.h"
#include "hw/timer/hpet.h"
#include "hw/i386/smbios.h"
35
#include "hw/loader.h"
B
Blue Swirl 已提交
36
#include "elf.h"
37
#include "multiboot.h"
P
Paolo Bonzini 已提交
38 39 40
#include "hw/timer/mc146818rtc.h"
#include "hw/timer/i8254.h"
#include "hw/audio/pcspk.h"
41 42
#include "hw/pci/msi.h"
#include "hw/sysbus.h"
43 44
#include "sysemu/sysemu.h"
#include "sysemu/kvm.h"
45
#include "kvm_i386.h"
P
Paolo Bonzini 已提交
46
#include "hw/xen/xen.h"
47
#include "sysemu/blockdev.h"
P
Paolo Bonzini 已提交
48
#include "hw/block/block.h"
G
Gerd Hoffmann 已提交
49
#include "ui/qemu-spice.h"
50 51
#include "exec/memory.h"
#include "exec/address-spaces.h"
52
#include "sysemu/arch_init.h"
53
#include "qemu/bitmap.h"
54
#include "qemu/config-file.h"
55
#include "hw/acpi/acpi.h"
56
#include "hw/cpu/icc_bus.h"
57
#include "hw/boards.h"
B
bellard 已提交
58

B
Blue Swirl 已提交
59 60 61 62 63 64 65 66 67 68
/* debug PC/ISA interrupts */
//#define DEBUG_IRQ

#ifdef DEBUG_IRQ
#define DPRINTF(fmt, ...)                                       \
    do { printf("CPUIRQ: " fmt , ## __VA_ARGS__); } while (0)
#else
#define DPRINTF(fmt, ...)
#endif

69 70
/* Leave a chunk of memory at the top of RAM for the BIOS ACPI tables.  */
#define ACPI_DATA_SIZE       0x10000
71
#define BIOS_CFG_IOPORT 0x510
72
#define FW_CFG_ACPI_TABLES (FW_CFG_ARCH_LOCAL + 0)
73
#define FW_CFG_SMBIOS_ENTRIES (FW_CFG_ARCH_LOCAL + 1)
J
Jes Sorensen 已提交
74
#define FW_CFG_IRQ0_OVERRIDE (FW_CFG_ARCH_LOCAL + 2)
J
Jes Sorensen 已提交
75
#define FW_CFG_E820_TABLE (FW_CFG_ARCH_LOCAL + 3)
76
#define FW_CFG_HPET (FW_CFG_ARCH_LOCAL + 4)
B
bellard 已提交
77

J
Jes Sorensen 已提交
78 79 80 81 82 83
#define E820_NR_ENTRIES		16

struct e820_entry {
    uint64_t address;
    uint64_t length;
    uint32_t type;
84
} QEMU_PACKED __attribute((__aligned__(4)));
J
Jes Sorensen 已提交
85 86 87 88

struct e820_table {
    uint32_t count;
    struct e820_entry entry[E820_NR_ENTRIES];
89
} QEMU_PACKED __attribute((__aligned__(4)));
J
Jes Sorensen 已提交
90 91

static struct e820_table e820_table;
B
Blue Swirl 已提交
92
struct hpet_fw_config hpet_cfg = {.count = UINT8_MAX};
J
Jes Sorensen 已提交
93

J
Jan Kiszka 已提交
94
void gsi_handler(void *opaque, int n, int level)
95
{
J
Jan Kiszka 已提交
96
    GSIState *s = opaque;
97

J
Jan Kiszka 已提交
98 99 100
    DPRINTF("pc: %s GSI %d\n", level ? "raising" : "lowering", n);
    if (n < ISA_NUM_IRQS) {
        qemu_set_irq(s->i8259_irq[n], level);
A
Avi Kivity 已提交
101
    }
J
Jan Kiszka 已提交
102
    qemu_set_irq(s->ioapic_irq[n], level);
103
}
104

J
Julien Grall 已提交
105 106
static void ioport80_write(void *opaque, hwaddr addr, uint64_t data,
                           unsigned size)
B
bellard 已提交
107 108 109
{
}

110 111
static uint64_t ioport80_read(void *opaque, hwaddr addr, unsigned size)
{
112
    return 0xffffffffffffffffULL;
113 114
}

115
/* MSDOS compatibility mode FPU exception support */
P
pbrook 已提交
116
static qemu_irq ferr_irq;
117 118 119 120 121 122

void pc_register_ferr_irq(qemu_irq irq)
{
    ferr_irq = irq;
}

123 124 125
/* XXX: add IGNNE support */
void cpu_set_ferr(CPUX86State *s)
{
P
pbrook 已提交
126
    qemu_irq_raise(ferr_irq);
127 128
}

J
Julien Grall 已提交
129 130
static void ioportF0_write(void *opaque, hwaddr addr, uint64_t data,
                           unsigned size)
131
{
P
pbrook 已提交
132
    qemu_irq_lower(ferr_irq);
133 134
}

135 136
static uint64_t ioportF0_read(void *opaque, hwaddr addr, unsigned size)
{
137
    return 0xffffffffffffffffULL;
138 139
}

B
bellard 已提交
140 141 142
/* TSC handling */
uint64_t cpu_get_tsc(CPUX86State *env)
{
143
    return cpu_get_ticks();
B
bellard 已提交
144 145
}

B
bellard 已提交
146
/* SMM support */
147 148 149 150 151 152 153 154 155 156 157 158

static cpu_set_smm_t smm_set;
static void *smm_arg;

void cpu_smm_register(cpu_set_smm_t callback, void *arg)
{
    assert(smm_set == NULL);
    assert(smm_arg == NULL);
    smm_set = callback;
    smm_arg = arg;
}

A
Andreas Färber 已提交
159
void cpu_smm_update(CPUX86State *env)
B
bellard 已提交
160
{
161
    if (smm_set && smm_arg && CPU(x86_env_get_cpu(env)) == first_cpu) {
162
        smm_set(!!(env->hflags & HF_SMM_MASK), smm_arg);
163
    }
B
bellard 已提交
164 165 166
}


B
bellard 已提交
167
/* IRQ handling */
A
Andreas Färber 已提交
168
int cpu_get_pic_interrupt(CPUX86State *env)
B
bellard 已提交
169 170 171
{
    int intno;

172
    intno = apic_get_interrupt(env->apic_state);
B
bellard 已提交
173 174 175 176
    if (intno >= 0) {
        return intno;
    }
    /* read the irq from the PIC */
177
    if (!apic_accept_pic_intr(env->apic_state)) {
178
        return -1;
179
    }
180

B
bellard 已提交
181 182 183 184
    intno = pic_read_irq(isa_pic);
    return intno;
}

P
pbrook 已提交
185
static void pic_irq_request(void *opaque, int irq, int level)
B
bellard 已提交
186
{
187 188 189
    CPUState *cs = first_cpu;
    X86CPU *cpu = X86_CPU(cs);
    CPUX86State *env = &cpu->env;
190

B
Blue Swirl 已提交
191
    DPRINTF("pic_irqs: %s irq %d\n", level? "raise" : "lower", irq);
A
aurel32 已提交
192
    if (env->apic_state) {
193 194 195
        while (cs) {
            cpu = X86_CPU(cs);
            env = &cpu->env;
196 197 198
            if (apic_accept_pic_intr(env->apic_state)) {
                apic_deliver_pic_intr(env->apic_state, level);
            }
199
            cs = cs->next_cpu;
A
aurel32 已提交
200 201
        }
    } else {
202
        if (level) {
203
            cpu_interrupt(cs, CPU_INTERRUPT_HARD);
204 205 206
        } else {
            cpu_reset_interrupt(cs, CPU_INTERRUPT_HARD);
        }
207
    }
B
bellard 已提交
208 209
}

B
bellard 已提交
210 211
/* PC cmos mappings */

B
bellard 已提交
212 213
#define REG_EQUIPMENT_BYTE          0x14

214
static int cmos_get_fd_drive_type(FDriveType fd0)
215 216 217 218
{
    int val;

    switch (fd0) {
219
    case FDRIVE_DRV_144:
220 221 222
        /* 1.44 Mb 3"5 drive */
        val = 4;
        break;
223
    case FDRIVE_DRV_288:
224 225 226
        /* 2.88 Mb 3"5 drive */
        val = 5;
        break;
227
    case FDRIVE_DRV_120:
228 229 230
        /* 1.2 Mb 5"5 drive */
        val = 2;
        break;
231
    case FDRIVE_DRV_NONE:
232 233 234 235 236 237 238
    default:
        val = 0;
        break;
    }
    return val;
}

239 240
static void cmos_init_hd(ISADevice *s, int type_ofs, int info_ofs,
                         int16_t cylinders, int8_t heads, int8_t sectors)
B
bellard 已提交
241 242 243 244 245 246 247 248 249 250 251 252 253
{
    rtc_set_memory(s, type_ofs, 47);
    rtc_set_memory(s, info_ofs, cylinders);
    rtc_set_memory(s, info_ofs + 1, cylinders >> 8);
    rtc_set_memory(s, info_ofs + 2, heads);
    rtc_set_memory(s, info_ofs + 3, 0xff);
    rtc_set_memory(s, info_ofs + 4, 0xff);
    rtc_set_memory(s, info_ofs + 5, 0xc0 | ((heads > 8) << 3));
    rtc_set_memory(s, info_ofs + 6, cylinders);
    rtc_set_memory(s, info_ofs + 7, cylinders >> 8);
    rtc_set_memory(s, info_ofs + 8, sectors);
}

254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270
/* convert boot_device letter to something recognizable by the bios */
static int boot_device2nibble(char boot_device)
{
    switch(boot_device) {
    case 'a':
    case 'b':
        return 0x01; /* floppy boot */
    case 'c':
        return 0x02; /* hard drive boot */
    case 'd':
        return 0x03; /* CD-ROM boot */
    case 'n':
        return 0x04; /* Network boot */
    }
    return 0;
}

271
static int set_boot_dev(ISADevice *s, const char *boot_device)
272 273 274 275 276 277 278
{
#define PC_MAX_BOOT_DEVICES 3
    int nbds, bds[3] = { 0, };
    int i;

    nbds = strlen(boot_device);
    if (nbds > PC_MAX_BOOT_DEVICES) {
279
        error_report("Too many boot devices for PC");
280 281 282 283 284
        return(1);
    }
    for (i = 0; i < nbds; i++) {
        bds[i] = boot_device2nibble(boot_device[i]);
        if (bds[i] == 0) {
285 286
            error_report("Invalid boot device for PC: '%c'",
                         boot_device[i]);
287 288 289 290
            return(1);
        }
    }
    rtc_set_memory(s, 0x3d, (bds[1] << 4) | bds[0]);
291
    rtc_set_memory(s, 0x38, (bds[2] << 4) | (fd_bootchk ? 0x0 : 0x1));
292 293 294
    return(0);
}

295 296
static int pc_boot_set(void *opaque, const char *boot_device)
{
297
    return set_boot_dev(opaque, boot_device);
298 299
}

300 301
typedef struct pc_cmos_init_late_arg {
    ISADevice *rtc_state;
302
    BusState *idebus[2];
303 304 305 306 307 308
} pc_cmos_init_late_arg;

static void pc_cmos_init_late(void *opaque)
{
    pc_cmos_init_late_arg *arg = opaque;
    ISADevice *s = arg->rtc_state;
309 310
    int16_t cylinders;
    int8_t heads, sectors;
311
    int val;
312
    int i, trans;
313

314 315 316 317 318 319 320 321 322 323 324 325
    val = 0;
    if (ide_get_geometry(arg->idebus[0], 0,
                         &cylinders, &heads, &sectors) >= 0) {
        cmos_init_hd(s, 0x19, 0x1b, cylinders, heads, sectors);
        val |= 0xf0;
    }
    if (ide_get_geometry(arg->idebus[0], 1,
                         &cylinders, &heads, &sectors) >= 0) {
        cmos_init_hd(s, 0x1a, 0x24, cylinders, heads, sectors);
        val |= 0x0f;
    }
    rtc_set_memory(s, 0x12, val);
326 327 328

    val = 0;
    for (i = 0; i < 4; i++) {
329 330 331 332 333 334
        /* NOTE: ide_get_geometry() returns the physical
           geometry.  It is always such that: 1 <= sects <= 63, 1
           <= heads <= 16, 1 <= cylinders <= 16383. The BIOS
           geometry can be different if a translation is done. */
        if (ide_get_geometry(arg->idebus[i / 2], i % 2,
                             &cylinders, &heads, &sectors) >= 0) {
335 336 337
            trans = ide_get_bios_chs_trans(arg->idebus[i / 2], i % 2) - 1;
            assert((trans & ~3) == 0);
            val |= trans << (i * 2);
338 339 340 341 342 343 344
        }
    }
    rtc_set_memory(s, 0x39, val);

    qemu_unregister_reset(pc_cmos_init_late, opaque);
}

345 346 347 348 349 350 351 352 353 354 355 356 357 358 359
typedef struct RTCCPUHotplugArg {
    Notifier cpu_added_notifier;
    ISADevice *rtc_state;
} RTCCPUHotplugArg;

static void rtc_notify_cpu_added(Notifier *notifier, void *data)
{
    RTCCPUHotplugArg *arg = container_of(notifier, RTCCPUHotplugArg,
                                         cpu_added_notifier);
    ISADevice *s = arg->rtc_state;

    /* increment the number of CPUs */
    rtc_set_memory(s, 0x5f, rtc_get_memory(s, 0x5f) + 1);
}

360
void pc_cmos_init(ram_addr_t ram_size, ram_addr_t above_4g_mem_size,
361
                  const char *boot_device,
K
Kevin Wolf 已提交
362
                  ISADevice *floppy, BusState *idebus0, BusState *idebus1,
B
Blue Swirl 已提交
363
                  ISADevice *s)
B
bellard 已提交
364
{
365
    int val, nb, i;
366
    FDriveType fd_type[2] = { FDRIVE_DRV_NONE, FDRIVE_DRV_NONE };
367
    static pc_cmos_init_late_arg arg;
368
    static RTCCPUHotplugArg cpu_hotplug_cb;
B
bellard 已提交
369 370

    /* various important CMOS locations needed by PC/Bochs bios */
B
bellard 已提交
371 372

    /* memory size */
373 374
    /* base memory (first MiB) */
    val = MIN(ram_size / 1024, 640);
B
bellard 已提交
375 376
    rtc_set_memory(s, 0x15, val);
    rtc_set_memory(s, 0x16, val >> 8);
377 378 379 380 381 382
    /* extended memory (next 64MiB) */
    if (ram_size > 1024 * 1024) {
        val = (ram_size - 1024 * 1024) / 1024;
    } else {
        val = 0;
    }
B
bellard 已提交
383 384
    if (val > 65535)
        val = 65535;
B
bellard 已提交
385 386 387 388
    rtc_set_memory(s, 0x17, val);
    rtc_set_memory(s, 0x18, val >> 8);
    rtc_set_memory(s, 0x30, val);
    rtc_set_memory(s, 0x31, val >> 8);
389 390 391 392
    /* memory between 16MiB and 4GiB */
    if (ram_size > 16 * 1024 * 1024) {
        val = (ram_size - 16 * 1024 * 1024) / 65536;
    } else {
B
bellard 已提交
393
        val = 0;
394
    }
B
bellard 已提交
395 396
    if (val > 65535)
        val = 65535;
B
bellard 已提交
397 398
    rtc_set_memory(s, 0x34, val);
    rtc_set_memory(s, 0x35, val >> 8);
399 400 401 402 403
    /* memory above 4GiB */
    val = above_4g_mem_size / 65536;
    rtc_set_memory(s, 0x5b, val);
    rtc_set_memory(s, 0x5c, val >> 8);
    rtc_set_memory(s, 0x5d, val >> 16);
404

A
aurel32 已提交
405 406
    /* set the number of CPU */
    rtc_set_memory(s, 0x5f, smp_cpus - 1);
407 408 409 410
    /* init CPU hotplug notifier */
    cpu_hotplug_cb.rtc_state = s;
    cpu_hotplug_cb.cpu_added_notifier.notify = rtc_notify_cpu_added;
    qemu_register_cpu_added_notifier(&cpu_hotplug_cb.cpu_added_notifier);
A
aurel32 已提交
411

412
    if (set_boot_dev(s, boot_device)) {
413 414
        exit(1);
    }
B
bellard 已提交
415

B
bellard 已提交
416
    /* floppy type */
K
Kevin Wolf 已提交
417 418
    if (floppy) {
        for (i = 0; i < 2; i++) {
419
            fd_type[i] = isa_fdc_get_drive_type(floppy, i);
B
Blue Swirl 已提交
420 421 422 423
        }
    }
    val = (cmos_get_fd_drive_type(fd_type[0]) << 4) |
        cmos_get_fd_drive_type(fd_type[1]);
B
bellard 已提交
424
    rtc_set_memory(s, 0x10, val);
425

B
bellard 已提交
426
    val = 0;
B
bellard 已提交
427
    nb = 0;
B
Blue Swirl 已提交
428
    if (fd_type[0] < FDRIVE_DRV_NONE) {
B
bellard 已提交
429
        nb++;
430
    }
B
Blue Swirl 已提交
431
    if (fd_type[1] < FDRIVE_DRV_NONE) {
B
bellard 已提交
432
        nb++;
433
    }
B
bellard 已提交
434 435 436 437
    switch (nb) {
    case 0:
        break;
    case 1:
B
bellard 已提交
438
        val |= 0x01; /* 1 drive, ready for boot */
B
bellard 已提交
439 440
        break;
    case 2:
B
bellard 已提交
441
        val |= 0x41; /* 2 drives, ready for boot */
B
bellard 已提交
442 443
        break;
    }
B
bellard 已提交
444 445 446 447
    val |= 0x02; /* FPU is there */
    val |= 0x04; /* PS/2 mouse installed */
    rtc_set_memory(s, REG_EQUIPMENT_BYTE, val);

B
bellard 已提交
448
    /* hard drives */
449
    arg.rtc_state = s;
450 451
    arg.idebus[0] = idebus0;
    arg.idebus[1] = idebus1;
452
    qemu_register_reset(pc_cmos_init_late, &arg);
B
bellard 已提交
453 454
}

A
Andreas Färber 已提交
455 456 457
#define TYPE_PORT92 "port92"
#define PORT92(obj) OBJECT_CHECK(Port92State, (obj), TYPE_PORT92)

458 459
/* port 92 stuff: could be split off */
typedef struct Port92State {
A
Andreas Färber 已提交
460 461
    ISADevice parent_obj;

462
    MemoryRegion io;
463 464 465 466
    uint8_t outport;
    qemu_irq *a20_out;
} Port92State;

467 468
static void port92_write(void *opaque, hwaddr addr, uint64_t val,
                         unsigned size)
469 470 471 472 473 474 475 476 477 478 479
{
    Port92State *s = opaque;

    DPRINTF("port92: write 0x%02x\n", val);
    s->outport = val;
    qemu_set_irq(*s->a20_out, (val >> 1) & 1);
    if (val & 1) {
        qemu_system_reset_request();
    }
}

480 481
static uint64_t port92_read(void *opaque, hwaddr addr,
                            unsigned size)
482 483 484 485 486 487 488 489 490 491 492
{
    Port92State *s = opaque;
    uint32_t ret;

    ret = s->outport;
    DPRINTF("port92: read 0x%02x\n", ret);
    return ret;
}

static void port92_init(ISADevice *dev, qemu_irq *a20_out)
{
A
Andreas Färber 已提交
493
    Port92State *s = PORT92(dev);
494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510

    s->a20_out = a20_out;
}

static const VMStateDescription vmstate_port92_isa = {
    .name = "port92",
    .version_id = 1,
    .minimum_version_id = 1,
    .minimum_version_id_old = 1,
    .fields      = (VMStateField []) {
        VMSTATE_UINT8(outport, Port92State),
        VMSTATE_END_OF_LIST()
    }
};

static void port92_reset(DeviceState *d)
{
A
Andreas Färber 已提交
511
    Port92State *s = PORT92(d);
512 513 514 515

    s->outport &= ~1;
}

516
static const MemoryRegionOps port92_ops = {
517 518 519 520 521 522 523
    .read = port92_read,
    .write = port92_write,
    .impl = {
        .min_access_size = 1,
        .max_access_size = 1,
    },
    .endianness = DEVICE_LITTLE_ENDIAN,
524 525
};

526
static void port92_initfn(Object *obj)
527
{
528
    Port92State *s = PORT92(obj);
529

530
    memory_region_init_io(&s->io, OBJECT(s), &port92_ops, s, "port92", 1);
531

532
    s->outport = 0;
533 534 535 536 537 538 539 540
}

static void port92_realizefn(DeviceState *dev, Error **errp)
{
    ISADevice *isadev = ISA_DEVICE(dev);
    Port92State *s = PORT92(dev);

    isa_register_ioport(isadev, &s->io, 0x92);
541 542
}

543 544
static void port92_class_initfn(ObjectClass *klass, void *data)
{
545
    DeviceClass *dc = DEVICE_CLASS(klass);
546

547
    dc->no_user = 1;
548
    dc->realize = port92_realizefn;
549 550
    dc->reset = port92_reset;
    dc->vmsd = &vmstate_port92_isa;
551 552
}

553
static const TypeInfo port92_info = {
A
Andreas Färber 已提交
554
    .name          = TYPE_PORT92,
555 556
    .parent        = TYPE_ISA_DEVICE,
    .instance_size = sizeof(Port92State),
557
    .instance_init = port92_initfn,
558
    .class_init    = port92_class_initfn,
559 560
};

A
Andreas Färber 已提交
561
static void port92_register_types(void)
562
{
563
    type_register_static(&port92_info);
564
}
A
Andreas Färber 已提交
565 566

type_init(port92_register_types)
567

B
Blue Swirl 已提交
568
static void handle_a20_line_change(void *opaque, int irq, int level)
569
{
570
    X86CPU *cpu = opaque;
B
bellard 已提交
571

B
Blue Swirl 已提交
572
    /* XXX: send to all CPUs ? */
573
    /* XXX: add logic to handle multiple A20 line sources */
574
    x86_cpu_set_a20(cpu, level);
B
bellard 已提交
575 576
}

J
Jes Sorensen 已提交
577 578
int e820_add_entry(uint64_t address, uint64_t length, uint32_t type)
{
579
    int index = le32_to_cpu(e820_table.count);
J
Jes Sorensen 已提交
580 581 582 583
    struct e820_entry *entry;

    if (index >= E820_NR_ENTRIES)
        return -EBUSY;
584
    entry = &e820_table.entry[index++];
J
Jes Sorensen 已提交
585

586 587 588
    entry->address = cpu_to_le64(address);
    entry->length = cpu_to_le64(length);
    entry->type = cpu_to_le32(type);
J
Jes Sorensen 已提交
589

590 591
    e820_table.count = cpu_to_le32(index);
    return index;
J
Jes Sorensen 已提交
592 593
}

594 595 596 597 598 599 600 601 602 603 604 605
/* Calculates the limit to CPU APIC ID values
 *
 * This function returns the limit for the APIC ID value, so that all
 * CPU APIC IDs are < pc_apic_id_limit().
 *
 * This is used for FW_CFG_MAX_CPUS. See comments on bochs_bios_init().
 */
static unsigned int pc_apic_id_limit(unsigned int max_cpus)
{
    return x86_cpu_apic_id_from_index(max_cpus - 1) + 1;
}

L
Laszlo Ersek 已提交
606
static FWCfgState *bochs_bios_init(void)
B
bellard 已提交
607
{
L
Laszlo Ersek 已提交
608
    FWCfgState *fw_cfg;
609 610
    uint8_t *smbios_table;
    size_t smbios_len;
611 612
    uint64_t *numa_fw_cfg;
    int i, j;
613
    unsigned int apic_id_limit = pc_apic_id_limit(max_cpus);
614 615

    fw_cfg = fw_cfg_init(BIOS_CFG_IOPORT, BIOS_CFG_IOPORT + 1, 0, 0);
616 617 618 619 620 621 622 623 624 625 626 627 628 629 630
    /* FW_CFG_MAX_CPUS is a bit confusing/problematic on x86:
     *
     * SeaBIOS needs FW_CFG_MAX_CPUS for CPU hotplug, but the CPU hotplug
     * QEMU<->SeaBIOS interface is not based on the "CPU index", but on the APIC
     * ID of hotplugged CPUs[1]. This means that FW_CFG_MAX_CPUS is not the
     * "maximum number of CPUs", but the "limit to the APIC ID values SeaBIOS
     * may see".
     *
     * So, this means we must not use max_cpus, here, but the maximum possible
     * APIC ID value, plus one.
     *
     * [1] The only kind of "CPU identifier" used between SeaBIOS and QEMU is
     *     the APIC ID, not the "CPU index"
     */
    fw_cfg_add_i16(fw_cfg, FW_CFG_MAX_CPUS, (uint16_t)apic_id_limit);
631
    fw_cfg_add_i32(fw_cfg, FW_CFG_ID, 1);
632
    fw_cfg_add_i64(fw_cfg, FW_CFG_RAM_SIZE, (uint64_t)ram_size);
633 634
    fw_cfg_add_bytes(fw_cfg, FW_CFG_ACPI_TABLES,
                     acpi_tables, acpi_tables_len);
635
    fw_cfg_add_i32(fw_cfg, FW_CFG_IRQ0_OVERRIDE, kvm_allows_irq0_override());
636 637 638 639 640

    smbios_table = smbios_get_table(&smbios_len);
    if (smbios_table)
        fw_cfg_add_bytes(fw_cfg, FW_CFG_SMBIOS_ENTRIES,
                         smbios_table, smbios_len);
641 642
    fw_cfg_add_bytes(fw_cfg, FW_CFG_E820_TABLE,
                     &e820_table, sizeof(e820_table));
643

644
    fw_cfg_add_bytes(fw_cfg, FW_CFG_HPET, &hpet_cfg, sizeof(hpet_cfg));
645 646 647 648
    /* allocate memory for the NUMA channel: one (64bit) word for the number
     * of nodes, one word for each VCPU->node and one word for each node to
     * hold the amount of memory.
     */
649
    numa_fw_cfg = g_new0(uint64_t, 1 + apic_id_limit + nb_numa_nodes);
650
    numa_fw_cfg[0] = cpu_to_le64(nb_numa_nodes);
651
    for (i = 0; i < max_cpus; i++) {
652 653
        unsigned int apic_id = x86_cpu_apic_id_from_index(i);
        assert(apic_id < apic_id_limit);
654
        for (j = 0; j < nb_numa_nodes; j++) {
655
            if (test_bit(i, node_cpumask[j])) {
656
                numa_fw_cfg[apic_id + 1] = cpu_to_le64(j);
657 658 659 660 661
                break;
            }
        }
    }
    for (i = 0; i < nb_numa_nodes; i++) {
662
        numa_fw_cfg[apic_id_limit + 1 + i] = cpu_to_le64(node_mem[i]);
663
    }
664
    fw_cfg_add_bytes(fw_cfg, FW_CFG_NUMA, numa_fw_cfg,
665 666
                     (1 + apic_id_limit + nb_numa_nodes) *
                     sizeof(*numa_fw_cfg));
A
Alexander Graf 已提交
667 668

    return fw_cfg;
B
bellard 已提交
669 670
}

T
ths 已提交
671 672 673 674 675 676 677 678 679 680 681 682 683 684
static long get_file_size(FILE *f)
{
    long where, size;

    /* XXX: on Unix systems, using fstat() probably makes more sense */

    where = ftell(f);
    fseek(f, 0, SEEK_END);
    size = ftell(f);
    fseek(f, where, SEEK_SET);

    return size;
}

L
Laszlo Ersek 已提交
685
static void load_linux(FWCfgState *fw_cfg,
686
                       const char *kernel_filename,
L
liguang 已提交
687 688
                       const char *initrd_filename,
                       const char *kernel_cmdline,
A
Avi Kivity 已提交
689
                       hwaddr max_ram_size)
T
ths 已提交
690 691
{
    uint16_t protocol;
P
Paul Brook 已提交
692
    int setup_size, kernel_size, initrd_size = 0, cmdline_size;
T
ths 已提交
693
    uint32_t initrd_max;
694
    uint8_t header[8192], *setup, *kernel, *initrd_data;
A
Avi Kivity 已提交
695
    hwaddr real_addr, prot_addr, cmdline_addr, initrd_addr = 0;
696
    FILE *f;
P
Pascal Terjan 已提交
697
    char *vmode;
T
ths 已提交
698 699 700 701 702 703 704

    /* Align to 16 bytes as a paranoia measure */
    cmdline_size = (strlen(kernel_cmdline)+16) & ~15;

    /* load the kernel header */
    f = fopen(kernel_filename, "rb");
    if (!f || !(kernel_size = get_file_size(f)) ||
L
liguang 已提交
705 706 707 708 709
        fread(header, 1, MIN(ARRAY_SIZE(header), kernel_size), f) !=
        MIN(ARRAY_SIZE(header), kernel_size)) {
        fprintf(stderr, "qemu: could not load kernel '%s': %s\n",
                kernel_filename, strerror(errno));
        exit(1);
T
ths 已提交
710 711 712
    }

    /* kernel protocol version */
B
bellard 已提交
713
#if 0
T
ths 已提交
714
    fprintf(stderr, "header magic: %#x\n", ldl_p(header+0x202));
B
bellard 已提交
715
#endif
L
liguang 已提交
716 717 718 719 720
    if (ldl_p(header+0x202) == 0x53726448) {
        protocol = lduw_p(header+0x206);
    } else {
        /* This looks like a multiboot kernel. If it is, let's stop
           treating it like a Linux kernel. */
721
        if (load_multiboot(fw_cfg, f, kernel_filename, initrd_filename,
L
liguang 已提交
722
                           kernel_cmdline, kernel_size, header)) {
B
Blue Swirl 已提交
723
            return;
L
liguang 已提交
724 725
        }
        protocol = 0;
A
Alexander Graf 已提交
726
    }
T
ths 已提交
727 728

    if (protocol < 0x200 || !(header[0x211] & 0x01)) {
L
liguang 已提交
729 730 731 732
        /* Low kernel */
        real_addr    = 0x90000;
        cmdline_addr = 0x9a000 - cmdline_size;
        prot_addr    = 0x10000;
T
ths 已提交
733
    } else if (protocol < 0x202) {
L
liguang 已提交
734 735 736 737
        /* High but ancient kernel */
        real_addr    = 0x90000;
        cmdline_addr = 0x9a000 - cmdline_size;
        prot_addr    = 0x100000;
T
ths 已提交
738
    } else {
L
liguang 已提交
739 740 741 742
        /* High and recent kernel */
        real_addr    = 0x10000;
        cmdline_addr = 0x20000;
        prot_addr    = 0x100000;
T
ths 已提交
743 744
    }

B
bellard 已提交
745
#if 0
T
ths 已提交
746
    fprintf(stderr,
L
liguang 已提交
747 748 749 750 751 752
            "qemu: real_addr     = 0x" TARGET_FMT_plx "\n"
            "qemu: cmdline_addr  = 0x" TARGET_FMT_plx "\n"
            "qemu: prot_addr     = 0x" TARGET_FMT_plx "\n",
            real_addr,
            cmdline_addr,
            prot_addr);
B
bellard 已提交
753
#endif
T
ths 已提交
754 755

    /* highest address for loading the initrd */
L
liguang 已提交
756 757 758 759 760
    if (protocol >= 0x203) {
        initrd_max = ldl_p(header+0x22c);
    } else {
        initrd_max = 0x37ffffff;
    }
T
ths 已提交
761

G
Glauber Costa 已提交
762 763
    if (initrd_max >= max_ram_size-ACPI_DATA_SIZE)
    	initrd_max = max_ram_size-ACPI_DATA_SIZE-1;
T
ths 已提交
764

765 766
    fw_cfg_add_i32(fw_cfg, FW_CFG_CMDLINE_ADDR, cmdline_addr);
    fw_cfg_add_i32(fw_cfg, FW_CFG_CMDLINE_SIZE, strlen(kernel_cmdline)+1);
767
    fw_cfg_add_string(fw_cfg, FW_CFG_CMDLINE_DATA, kernel_cmdline);
T
ths 已提交
768 769

    if (protocol >= 0x202) {
L
liguang 已提交
770
        stl_p(header+0x228, cmdline_addr);
T
ths 已提交
771
    } else {
L
liguang 已提交
772 773
        stw_p(header+0x20, 0xA33F);
        stw_p(header+0x22, cmdline_addr-real_addr);
T
ths 已提交
774 775
    }

P
Pascal Terjan 已提交
776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793
    /* handle vga= parameter */
    vmode = strstr(kernel_cmdline, "vga=");
    if (vmode) {
        unsigned int video_mode;
        /* skip "vga=" */
        vmode += 4;
        if (!strncmp(vmode, "normal", 6)) {
            video_mode = 0xffff;
        } else if (!strncmp(vmode, "ext", 3)) {
            video_mode = 0xfffe;
        } else if (!strncmp(vmode, "ask", 3)) {
            video_mode = 0xfffd;
        } else {
            video_mode = strtol(vmode, NULL, 0);
        }
        stw_p(header+0x1fa, video_mode);
    }

T
ths 已提交
794
    /* loader type */
S
Stefan Weil 已提交
795
    /* High nybble = B reserved for QEMU; low nybble is revision number.
T
ths 已提交
796 797
       If this code is substantially changed, you may want to consider
       incrementing the revision. */
L
liguang 已提交
798 799 800
    if (protocol >= 0x200) {
        header[0x210] = 0xB0;
    }
T
ths 已提交
801 802
    /* heap */
    if (protocol >= 0x201) {
L
liguang 已提交
803 804
        header[0x211] |= 0x80;	/* CAN_USE_HEAP */
        stw_p(header+0x224, cmdline_addr-real_addr-0x200);
T
ths 已提交
805 806 807 808
    }

    /* load initrd */
    if (initrd_filename) {
L
liguang 已提交
809 810 811 812
        if (protocol < 0x200) {
            fprintf(stderr, "qemu: linux kernel too old to load a ram disk\n");
            exit(1);
        }
T
ths 已提交
813

L
liguang 已提交
814
        initrd_size = get_image_size(initrd_filename);
M
M. Mohan Kumar 已提交
815 816 817 818 819 820
        if (initrd_size < 0) {
            fprintf(stderr, "qemu: error reading initrd %s\n",
                    initrd_filename);
            exit(1);
        }

821
        initrd_addr = (initrd_max-initrd_size) & ~4095;
822

823
        initrd_data = g_malloc(initrd_size);
824 825 826 827 828
        load_image(initrd_filename, initrd_data);

        fw_cfg_add_i32(fw_cfg, FW_CFG_INITRD_ADDR, initrd_addr);
        fw_cfg_add_i32(fw_cfg, FW_CFG_INITRD_SIZE, initrd_size);
        fw_cfg_add_bytes(fw_cfg, FW_CFG_INITRD_DATA, initrd_data, initrd_size);
T
ths 已提交
829

L
liguang 已提交
830 831
        stl_p(header+0x218, initrd_addr);
        stl_p(header+0x21c, initrd_size);
T
ths 已提交
832 833
    }

834
    /* load kernel and setup */
T
ths 已提交
835
    setup_size = header[0x1f1];
L
liguang 已提交
836 837 838
    if (setup_size == 0) {
        setup_size = 4;
    }
T
ths 已提交
839
    setup_size = (setup_size+1)*512;
840
    kernel_size -= setup_size;
T
ths 已提交
841

842 843
    setup  = g_malloc(setup_size);
    kernel = g_malloc(kernel_size);
844
    fseek(f, 0, SEEK_SET);
845 846 847 848 849 850 851 852
    if (fread(setup, 1, setup_size, f) != setup_size) {
        fprintf(stderr, "fread() failed\n");
        exit(1);
    }
    if (fread(kernel, 1, kernel_size, f) != kernel_size) {
        fprintf(stderr, "fread() failed\n");
        exit(1);
    }
T
ths 已提交
853
    fclose(f);
854
    memcpy(setup, header, MIN(sizeof(header), setup_size));
855 856 857 858 859 860 861 862 863

    fw_cfg_add_i32(fw_cfg, FW_CFG_KERNEL_ADDR, prot_addr);
    fw_cfg_add_i32(fw_cfg, FW_CFG_KERNEL_SIZE, kernel_size);
    fw_cfg_add_bytes(fw_cfg, FW_CFG_KERNEL_DATA, kernel, kernel_size);

    fw_cfg_add_i32(fw_cfg, FW_CFG_SETUP_ADDR, real_addr);
    fw_cfg_add_i32(fw_cfg, FW_CFG_SETUP_SIZE, setup_size);
    fw_cfg_add_bytes(fw_cfg, FW_CFG_SETUP_DATA, setup, setup_size);

G
Gleb Natapov 已提交
864 865
    option_rom[nb_option_roms].name = "linuxboot.bin";
    option_rom[nb_option_roms].bootindex = 0;
866
    nb_option_roms++;
T
ths 已提交
867 868
}

B
bellard 已提交
869 870
#define NE2000_NB_MAX 6

B
Blue Swirl 已提交
871 872 873
static const int ne2000_io[NE2000_NB_MAX] = { 0x300, 0x320, 0x340, 0x360,
                                              0x280, 0x380 };
static const int ne2000_irq[NE2000_NB_MAX] = { 9, 10, 11, 3, 4, 5 };
B
bellard 已提交
874

B
Blue Swirl 已提交
875 876
static const int parallel_io[MAX_PARALLEL_PORTS] = { 0x378, 0x278, 0x3bc };
static const int parallel_irq[MAX_PARALLEL_PORTS] = { 7, 7, 7 };
877

878
void pc_init_ne2k_isa(ISABus *bus, NICInfo *nd)
879 880 881 882 883
{
    static int nb_ne2k = 0;

    if (nb_ne2k == NE2000_NB_MAX)
        return;
884
    isa_ne2000_init(bus, ne2000_io[nb_ne2k],
G
Gerd Hoffmann 已提交
885
                    ne2000_irq[nb_ne2k], nd);
886 887 888
    nb_ne2k++;
}

B
Blue Swirl 已提交
889
DeviceState *cpu_get_current_apic(void)
890
{
891 892 893
    if (current_cpu) {
        X86CPU *cpu = X86_CPU(current_cpu);
        return cpu->env.apic_state;
894 895 896 897 898
    } else {
        return NULL;
    }
}

899
void pc_acpi_smi_interrupt(void *opaque, int irq, int level)
B
Blue Swirl 已提交
900
{
901
    X86CPU *cpu = opaque;
B
Blue Swirl 已提交
902 903

    if (level) {
904
        cpu_interrupt(CPU(cpu), CPU_INTERRUPT_SMI);
B
Blue Swirl 已提交
905 906 907
    }
}

908 909
static X86CPU *pc_new_cpu(const char *cpu_model, int64_t apic_id,
                          DeviceState *icc_bridge, Error **errp)
910 911 912 913
{
    X86CPU *cpu;
    Error *local_err = NULL;

914
    cpu = cpu_x86_create(cpu_model, icc_bridge, errp);
915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931
    if (!cpu) {
        return cpu;
    }

    object_property_set_int(OBJECT(cpu), apic_id, "apic-id", &local_err);
    object_property_set_bool(OBJECT(cpu), true, "realized", &local_err);

    if (local_err) {
        if (cpu != NULL) {
            object_unref(OBJECT(cpu));
            cpu = NULL;
        }
        error_propagate(errp, local_err);
    }
    return cpu;
}

932 933 934 935 936 937 938
static const char *current_cpu_model;

void pc_hot_add_cpu(const int64_t id, Error **errp)
{
    DeviceState *icc_bridge;
    int64_t apic_id = x86_cpu_apic_id_from_index(id);

939 940 941 942 943
    if (id < 0) {
        error_setg(errp, "Invalid CPU id: %" PRIi64, id);
        return;
    }

944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960
    if (cpu_exists(apic_id)) {
        error_setg(errp, "Unable to add CPU: %" PRIi64
                   ", it already exists", id);
        return;
    }

    if (id >= max_cpus) {
        error_setg(errp, "Unable to add CPU: %" PRIi64
                   ", max allowed: %d", id, max_cpus - 1);
        return;
    }

    icc_bridge = DEVICE(object_resolve_path_type("icc-bridge",
                                                 TYPE_ICC_BRIDGE, NULL));
    pc_new_cpu(current_cpu_model, apic_id, icc_bridge, errp);
}

961
void pc_cpus_init(const char *cpu_model, DeviceState *icc_bridge)
962 963
{
    int i;
964
    X86CPU *cpu = NULL;
965
    Error *error = NULL;
966 967 968 969 970 971 972 973 974

    /* init CPUs */
    if (cpu_model == NULL) {
#ifdef TARGET_X86_64
        cpu_model = "qemu64";
#else
        cpu_model = "qemu32";
#endif
    }
975
    current_cpu_model = cpu_model;
976

977
    for (i = 0; i < smp_cpus; i++) {
978 979
        cpu = pc_new_cpu(cpu_model, x86_cpu_apic_id_from_index(i),
                         icc_bridge, &error);
980 981 982
        if (error) {
            fprintf(stderr, "%s\n", error_get_pretty(error));
            error_free(error);
983 984
            exit(1);
        }
985
    }
986 987 988 989 990 991 992

    /* map APIC MMIO area if CPU has APIC */
    if (cpu && cpu->env.apic_state) {
        /* XXX: what if the base changes? */
        sysbus_mmio_map_overlap(SYS_BUS_DEVICE(icc_bridge), 0,
                                APIC_DEFAULT_ADDRESS, 0x1000);
    }
993 994
}

995 996 997 998 999 1000 1001 1002 1003 1004 1005
/* pci-info ROM file. Little endian format */
typedef struct PcRomPciInfo {
    uint64_t w32_min;
    uint64_t w32_max;
    uint64_t w64_min;
    uint64_t w64_max;
} PcRomPciInfo;

static void pc_fw_cfg_guest_info(PcGuestInfo *guest_info)
{
    PcRomPciInfo *info;
1006
    if (!guest_info->has_pci_info || !guest_info->fw_cfg) {
1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019
        return;
    }

    info = g_malloc(sizeof *info);
    info->w32_min = cpu_to_le64(guest_info->pci_info.w32.begin);
    info->w32_max = cpu_to_le64(guest_info->pci_info.w32.end);
    info->w64_min = cpu_to_le64(guest_info->pci_info.w64.begin);
    info->w64_max = cpu_to_le64(guest_info->pci_info.w64.end);
    /* Pass PCI hole info to guest via a side channel.
     * Required so guest PCI enumeration does the right thing. */
    fw_cfg_add_file(guest_info->fw_cfg, "etc/pci-info", info, sizeof *info);
}

1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030
typedef struct PcGuestInfoState {
    PcGuestInfo info;
    Notifier machine_done;
} PcGuestInfoState;

static
void pc_guest_info_machine_done(Notifier *notifier, void *data)
{
    PcGuestInfoState *guest_info_state = container_of(notifier,
                                                      PcGuestInfoState,
                                                      machine_done);
1031
    pc_fw_cfg_guest_info(&guest_info_state->info);
1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062
}

PcGuestInfo *pc_guest_info_init(ram_addr_t below_4g_mem_size,
                                ram_addr_t above_4g_mem_size)
{
    PcGuestInfoState *guest_info_state = g_malloc0(sizeof *guest_info_state);
    PcGuestInfo *guest_info = &guest_info_state->info;

    guest_info->pci_info.w32.end = IO_APIC_DEFAULT_ADDRESS;
    if (sizeof(hwaddr) == 4) {
        guest_info->pci_info.w64.begin = 0;
        guest_info->pci_info.w64.end = 0;
    } else {
        /*
         * BIOS does not set MTRR entries for the 64 bit window, so no need to
         * align address to power of two.  Align address at 1G, this makes sure
         * it can be exactly covered with a PAT entry even when using huge
         * pages.
         */
        guest_info->pci_info.w64.begin =
            ROUND_UP((0x1ULL << 32) + above_4g_mem_size, 0x1ULL << 30);
        guest_info->pci_info.w64.end = guest_info->pci_info.w64.begin +
            (0x1ULL << 62);
        assert(guest_info->pci_info.w64.begin <= guest_info->pci_info.w64.end);
    }

    guest_info_state->machine_done.notify = pc_guest_info_machine_done;
    qemu_add_machine_init_done_notifier(&guest_info_state->machine_done);
    return guest_info;
}

G
Gerd Hoffmann 已提交
1063 1064
void pc_acpi_init(const char *default_dsdt)
{
1065
    char *filename;
G
Gerd Hoffmann 已提交
1066 1067 1068 1069 1070 1071 1072 1073 1074

    if (acpi_tables != NULL) {
        /* manually set via -acpitable, leave it alone */
        return;
    }

    filename = qemu_find_file(QEMU_FILE_TYPE_BIOS, default_dsdt);
    if (filename == NULL) {
        fprintf(stderr, "WARNING: failed to find %s\n", default_dsdt);
1075 1076 1077 1078
    } else {
        char *arg;
        QemuOpts *opts;
        Error *err = NULL;
G
Gerd Hoffmann 已提交
1079

1080
        arg = g_strdup_printf("file=%s", filename);
1081

1082 1083 1084
        /* creates a deep copy of "arg" */
        opts = qemu_opts_parse(qemu_find_opts("acpi"), arg, 0);
        g_assert(opts != NULL);
1085

1086 1087 1088 1089 1090 1091 1092 1093
        acpi_table_add(opts, &err);
        if (err) {
            fprintf(stderr, "WARNING: failed to load %s: %s\n", filename,
                    error_get_pretty(err));
            error_free(err);
        }
        g_free(arg);
        g_free(filename);
G
Gerd Hoffmann 已提交
1094 1095 1096
    }
}

L
Laszlo Ersek 已提交
1097 1098 1099 1100 1101 1102 1103
FWCfgState *pc_memory_init(MemoryRegion *system_memory,
                           const char *kernel_filename,
                           const char *kernel_cmdline,
                           const char *initrd_filename,
                           ram_addr_t below_4g_mem_size,
                           ram_addr_t above_4g_mem_size,
                           MemoryRegion *rom_memory,
1104 1105
                           MemoryRegion **ram_memory,
                           PcGuestInfo *guest_info)
B
bellard 已提交
1106
{
1107 1108
    int linux_boot, i;
    MemoryRegion *ram, *option_rom_mr;
1109
    MemoryRegion *ram_below_4g, *ram_above_4g;
L
Laszlo Ersek 已提交
1110
    FWCfgState *fw_cfg;
1111

B
bellard 已提交
1112 1113
    linux_boot = (kernel_filename != NULL);

1114
    /* Allocate RAM.  We allocate it as a single memory region and use
D
Dong Xu Wang 已提交
1115
     * aliases to address portions of it, mostly for backwards compatibility
1116 1117
     * with older qemus that used qemu_ram_alloc().
     */
1118
    ram = g_malloc(sizeof(*ram));
1119
    memory_region_init_ram(ram, NULL, "pc.ram",
1120
                           below_4g_mem_size + above_4g_mem_size);
1121
    vmstate_register_ram_global(ram);
A
Avi Kivity 已提交
1122
    *ram_memory = ram;
1123
    ram_below_4g = g_malloc(sizeof(*ram_below_4g));
1124
    memory_region_init_alias(ram_below_4g, NULL, "ram-below-4g", ram,
1125 1126
                             0, below_4g_mem_size);
    memory_region_add_subregion(system_memory, 0, ram_below_4g);
1127
    if (above_4g_mem_size > 0) {
1128
        ram_above_4g = g_malloc(sizeof(*ram_above_4g));
1129
        memory_region_init_alias(ram_above_4g, NULL, "ram-above-4g", ram,
1130 1131 1132
                                 below_4g_mem_size, above_4g_mem_size);
        memory_region_add_subregion(system_memory, 0x100000000ULL,
                                    ram_above_4g);
1133
    }
1134

1135 1136 1137

    /* Initialize PC system firmware */
    pc_system_firmware_init(rom_memory);
1138

1139
    option_rom_mr = g_malloc(sizeof(*option_rom_mr));
1140
    memory_region_init_ram(option_rom_mr, NULL, "pc.rom", PC_ROM_SIZE);
1141
    vmstate_register_ram_global(option_rom_mr);
1142
    memory_region_add_subregion_overlap(rom_memory,
1143 1144 1145
                                        PC_ROM_MIN_VGA,
                                        option_rom_mr,
                                        1);
1146

A
Alexander Graf 已提交
1147
    fw_cfg = bochs_bios_init();
G
Gerd Hoffmann 已提交
1148
    rom_set_fw(fw_cfg);
A
Alexander Graf 已提交
1149

1150
    if (linux_boot) {
1151
        load_linux(fw_cfg, kernel_filename, initrd_filename, kernel_cmdline, below_4g_mem_size);
1152 1153 1154
    }

    for (i = 0; i < nb_option_roms; i++) {
G
Gleb Natapov 已提交
1155
        rom_add_option(option_rom[i].name, option_rom[i].bootindex);
1156
    }
1157
    guest_info->fw_cfg = fw_cfg;
1158
    return fw_cfg;
1159 1160
}

1161 1162 1163 1164 1165
qemu_irq *pc_allocate_cpu_irq(void)
{
    return qemu_allocate_irqs(pic_irq_request, NULL, 1);
}

1166
DeviceState *pc_vga_init(ISABus *isa_bus, PCIBus *pci_bus)
1167
{
1168 1169
    DeviceState *dev = NULL;

1170 1171 1172 1173 1174
    if (pci_bus) {
        PCIDevice *pcidev = pci_vga_init(pci_bus);
        dev = pcidev ? &pcidev->qdev : NULL;
    } else if (isa_bus) {
        ISADevice *isadev = isa_vga_init(isa_bus);
A
Andreas Färber 已提交
1175
        dev = isadev ? DEVICE(isadev) : NULL;
1176
    }
1177
    return dev;
1178 1179
}

B
Blue Swirl 已提交
1180 1181
static void cpu_request_exit(void *opaque, int irq, int level)
{
1182
    CPUState *cpu = current_cpu;
B
Blue Swirl 已提交
1183

1184 1185
    if (cpu && level) {
        cpu_exit(cpu);
B
Blue Swirl 已提交
1186 1187 1188
    }
}

J
Julien Grall 已提交
1189 1190
static const MemoryRegionOps ioport80_io_ops = {
    .write = ioport80_write,
1191
    .read = ioport80_read,
J
Julien Grall 已提交
1192 1193 1194 1195 1196 1197 1198 1199 1200
    .endianness = DEVICE_NATIVE_ENDIAN,
    .impl = {
        .min_access_size = 1,
        .max_access_size = 1,
    },
};

static const MemoryRegionOps ioportF0_io_ops = {
    .write = ioportF0_write,
1201
    .read = ioportF0_read,
J
Julien Grall 已提交
1202 1203 1204 1205 1206 1207 1208
    .endianness = DEVICE_NATIVE_ENDIAN,
    .impl = {
        .min_access_size = 1,
        .max_access_size = 1,
    },
};

1209
void pc_basic_device_init(ISABus *isa_bus, qemu_irq *gsi,
1210
                          ISADevice **rtc_state,
K
Kevin Wolf 已提交
1211
                          ISADevice **floppy,
1212
                          bool no_vmport)
1213 1214 1215
{
    int i;
    DriveInfo *fd[MAX_FD];
1216 1217 1218
    DeviceState *hpet = NULL;
    int pit_isa_irq = 0;
    qemu_irq pit_alt_irq = NULL;
1219
    qemu_irq rtc_irq = NULL;
B
Blue Swirl 已提交
1220
    qemu_irq *a20_line;
1221
    ISADevice *i8042, *port92, *vmmouse, *pit = NULL;
B
Blue Swirl 已提交
1222
    qemu_irq *cpu_exit_irq;
J
Julien Grall 已提交
1223 1224
    MemoryRegion *ioport80_io = g_new(MemoryRegion, 1);
    MemoryRegion *ioportF0_io = g_new(MemoryRegion, 1);
1225

1226
    memory_region_init_io(ioport80_io, NULL, &ioport80_io_ops, NULL, "ioport80", 1);
J
Julien Grall 已提交
1227
    memory_region_add_subregion(isa_bus->address_space_io, 0x80, ioport80_io);
1228

1229
    memory_region_init_io(ioportF0_io, NULL, &ioportF0_io_ops, NULL, "ioportF0", 1);
J
Julien Grall 已提交
1230
    memory_region_add_subregion(isa_bus->address_space_io, 0xf0, ioportF0_io);
1231

1232 1233 1234 1235 1236 1237 1238
    /*
     * Check if an HPET shall be created.
     *
     * Without KVM_CAP_PIT_STATE2, we cannot switch off the in-kernel PIT
     * when the HPET wants to take over. Thus we have to disable the latter.
     */
    if (!no_hpet && (!kvm_irqchip_in_kernel() || kvm_has_pit_state2())) {
1239
        hpet = sysbus_try_create_simple("hpet", HPET_BASE, NULL);
J
Jan Kiszka 已提交
1240

B
Blue Swirl 已提交
1241
        if (hpet) {
J
Jan Kiszka 已提交
1242
            for (i = 0; i < GSI_NUM_PINS; i++) {
1243
                sysbus_connect_irq(SYS_BUS_DEVICE(hpet), i, gsi[i]);
B
Blue Swirl 已提交
1244
            }
1245 1246 1247
            pit_isa_irq = -1;
            pit_alt_irq = qdev_get_gpio_in(hpet, HPET_LEGACY_PIT_INT);
            rtc_irq = qdev_get_gpio_in(hpet, HPET_LEGACY_RTC_INT);
J
Jan Kiszka 已提交
1248
        }
1249
    }
1250
    *rtc_state = rtc_init(isa_bus, 2000, rtc_irq);
1251 1252 1253

    qemu_register_boot_set(pc_boot_set, *rtc_state);

1254 1255 1256 1257 1258 1259 1260 1261
    if (!xen_enabled()) {
        if (kvm_irqchip_in_kernel()) {
            pit = kvm_pit_init(isa_bus, 0x40);
        } else {
            pit = pit_init(isa_bus, 0x40, pit_isa_irq, pit_alt_irq);
        }
        if (hpet) {
            /* connect PIT to output control line of the HPET */
A
Andreas Färber 已提交
1262
            qdev_connect_gpio_out(hpet, 0, qdev_get_gpio_in(DEVICE(pit), 0));
1263 1264
        }
        pcspk_init(isa_bus, pit);
1265
    }
1266 1267 1268

    for(i = 0; i < MAX_SERIAL_PORTS; i++) {
        if (serial_hds[i]) {
1269
            serial_isa_init(isa_bus, i, serial_hds[i]);
1270 1271 1272 1273 1274
        }
    }

    for(i = 0; i < MAX_PARALLEL_PORTS; i++) {
        if (parallel_hds[i]) {
1275
            parallel_init(isa_bus, i, parallel_hds[i]);
1276 1277 1278
        }
    }

1279
    a20_line = qemu_allocate_irqs(handle_a20_line_change, first_cpu, 2);
1280
    i8042 = isa_create_simple(isa_bus, "i8042");
1281
    i8042_setup_a20_line(i8042, &a20_line[0]);
1282
    if (!no_vmport) {
1283 1284
        vmport_init(isa_bus);
        vmmouse = isa_try_create(isa_bus, "vmmouse");
1285 1286 1287
    } else {
        vmmouse = NULL;
    }
B
Blue Swirl 已提交
1288
    if (vmmouse) {
A
Andreas Färber 已提交
1289 1290 1291
        DeviceState *dev = DEVICE(vmmouse);
        qdev_prop_set_ptr(dev, "ps2_mouse", i8042);
        qdev_init_nofail(dev);
B
Blue Swirl 已提交
1292
    }
1293
    port92 = isa_create_simple(isa_bus, "port92");
1294
    port92_init(port92, &a20_line[1]);
B
Blue Swirl 已提交
1295

B
Blue Swirl 已提交
1296 1297
    cpu_exit_irq = qemu_allocate_irqs(cpu_request_exit, NULL, 1);
    DMA_init(0, cpu_exit_irq);
1298 1299 1300 1301

    for(i = 0; i < MAX_FD; i++) {
        fd[i] = drive_get(IF_FLOPPY, 0, i);
    }
1302
    *floppy = fdctrl_init_isa(isa_bus, fd);
1303 1304
}

1305 1306 1307 1308 1309 1310 1311 1312 1313 1314
void pc_nic_init(ISABus *isa_bus, PCIBus *pci_bus)
{
    int i;

    for (i = 0; i < nb_nics; i++) {
        NICInfo *nd = &nd_table[i];

        if (!pci_bus || (nd->model && strcmp(nd->model, "ne2k_isa") == 0)) {
            pc_init_ne2k_isa(isa_bus, nd);
        } else {
1315
            pci_nic_init_nofail(nd, pci_bus, "e1000", NULL);
1316 1317 1318 1319
        }
    }
}

1320
void pc_pci_device_init(PCIBus *pci_bus)
1321 1322 1323 1324 1325 1326 1327 1328 1329
{
    int max_bus;
    int bus;

    max_bus = drive_get_max_bus(IF_SCSI);
    for (bus = 0; bus <= max_bus; bus++) {
        pci_create_simple(pci_bus, -1, "lsi53c895a");
    }
}
1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346

void ioapic_init_gsi(GSIState *gsi_state, const char *parent_name)
{
    DeviceState *dev;
    SysBusDevice *d;
    unsigned int i;

    if (kvm_irqchip_in_kernel()) {
        dev = qdev_create(NULL, "kvm-ioapic");
    } else {
        dev = qdev_create(NULL, "ioapic");
    }
    if (parent_name) {
        object_property_add_child(object_resolve_path(parent_name, NULL),
                                  "ioapic", OBJECT(dev), NULL);
    }
    qdev_init_nofail(dev);
1347
    d = SYS_BUS_DEVICE(dev);
1348
    sysbus_mmio_map(d, 0, IO_APIC_DEFAULT_ADDRESS);
1349 1350 1351 1352 1353

    for (i = 0; i < IOAPIC_NUM_PINS; i++) {
        gsi_state->ioapic_irq[i] = qdev_get_gpio_in(dev, i);
    }
}