Ignore pci unplug requests for unpluggable devices (CVE-2011-1751)
[qemu.git] / ui / spice-display.c
blob15f0704eaf350d6346bc118c8b8172b2745d4bac
1 /*
2 * Copyright (C) 2010 Red Hat, Inc.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License as
6 * published by the Free Software Foundation; either version 2 or
7 * (at your option) version 3 of the License.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see <http://www.gnu.org/licenses/>.
18 #include <pthread.h>
20 #include "qemu-common.h"
21 #include "qemu-spice.h"
22 #include "qemu-timer.h"
23 #include "qemu-queue.h"
24 #include "monitor.h"
25 #include "console.h"
26 #include "sysemu.h"
28 #include "spice-display.h"
30 static int debug = 0;
32 static void GCC_FMT_ATTR(2, 3) dprint(int level, const char *fmt, ...)
34 va_list args;
36 if (level <= debug) {
37 va_start(args, fmt);
38 vfprintf(stderr, fmt, args);
39 va_end(args);
43 int qemu_spice_rect_is_empty(const QXLRect* r)
45 return r->top == r->bottom || r->left == r->right;
48 void qemu_spice_rect_union(QXLRect *dest, const QXLRect *r)
50 if (qemu_spice_rect_is_empty(r)) {
51 return;
54 if (qemu_spice_rect_is_empty(dest)) {
55 *dest = *r;
56 return;
59 dest->top = MIN(dest->top, r->top);
60 dest->left = MIN(dest->left, r->left);
61 dest->bottom = MAX(dest->bottom, r->bottom);
62 dest->right = MAX(dest->right, r->right);
65 static SimpleSpiceUpdate *qemu_spice_create_update(SimpleSpiceDisplay *ssd)
67 SimpleSpiceUpdate *update;
68 QXLDrawable *drawable;
69 QXLImage *image;
70 QXLCommand *cmd;
71 uint8_t *src, *dst;
72 int by, bw, bh;
74 if (qemu_spice_rect_is_empty(&ssd->dirty)) {
75 return NULL;
78 dprint(2, "%s: lr %d -> %d, tb -> %d -> %d\n", __FUNCTION__,
79 ssd->dirty.left, ssd->dirty.right,
80 ssd->dirty.top, ssd->dirty.bottom);
82 update = qemu_mallocz(sizeof(*update));
83 drawable = &update->drawable;
84 image = &update->image;
85 cmd = &update->ext.cmd;
87 bw = ssd->dirty.right - ssd->dirty.left;
88 bh = ssd->dirty.bottom - ssd->dirty.top;
89 update->bitmap = qemu_malloc(bw * bh * 4);
91 drawable->bbox = ssd->dirty;
92 drawable->clip.type = SPICE_CLIP_TYPE_NONE;
93 drawable->effect = QXL_EFFECT_OPAQUE;
94 drawable->release_info.id = (intptr_t)update;
95 drawable->type = QXL_DRAW_COPY;
96 drawable->surfaces_dest[0] = -1;
97 drawable->surfaces_dest[1] = -1;
98 drawable->surfaces_dest[2] = -1;
100 drawable->u.copy.rop_descriptor = SPICE_ROPD_OP_PUT;
101 drawable->u.copy.src_bitmap = (intptr_t)image;
102 drawable->u.copy.src_area.right = bw;
103 drawable->u.copy.src_area.bottom = bh;
105 QXL_SET_IMAGE_ID(image, QXL_IMAGE_GROUP_DEVICE, ssd->unique++);
106 image->descriptor.type = SPICE_IMAGE_TYPE_BITMAP;
107 image->bitmap.flags = QXL_BITMAP_DIRECT | QXL_BITMAP_TOP_DOWN;
108 image->bitmap.stride = bw * 4;
109 image->descriptor.width = image->bitmap.x = bw;
110 image->descriptor.height = image->bitmap.y = bh;
111 image->bitmap.data = (intptr_t)(update->bitmap);
112 image->bitmap.palette = 0;
113 image->bitmap.format = SPICE_BITMAP_FMT_32BIT;
115 if (ssd->conv == NULL) {
116 PixelFormat dst = qemu_default_pixelformat(32);
117 ssd->conv = qemu_pf_conv_get(&dst, &ssd->ds->surface->pf);
118 assert(ssd->conv);
121 src = ds_get_data(ssd->ds) +
122 ssd->dirty.top * ds_get_linesize(ssd->ds) +
123 ssd->dirty.left * ds_get_bytes_per_pixel(ssd->ds);
124 dst = update->bitmap;
125 for (by = 0; by < bh; by++) {
126 qemu_pf_conv_run(ssd->conv, dst, src, bw);
127 src += ds_get_linesize(ssd->ds);
128 dst += image->bitmap.stride;
131 cmd->type = QXL_CMD_DRAW;
132 cmd->data = (intptr_t)drawable;
134 memset(&ssd->dirty, 0, sizeof(ssd->dirty));
135 return update;
139 * Called from spice server thread context (via interface_release_ressource)
140 * We do *not* hold the global qemu mutex here, so extra care is needed
141 * when calling qemu functions. Qemu interfaces used:
142 * - qemu_free (underlying glibc free is re-entrant).
144 void qemu_spice_destroy_update(SimpleSpiceDisplay *sdpy, SimpleSpiceUpdate *update)
146 qemu_free(update->bitmap);
147 qemu_free(update);
150 void qemu_spice_create_host_memslot(SimpleSpiceDisplay *ssd)
152 QXLDevMemSlot memslot;
154 dprint(1, "%s:\n", __FUNCTION__);
156 memset(&memslot, 0, sizeof(memslot));
157 memslot.slot_group_id = MEMSLOT_GROUP_HOST;
158 memslot.virt_end = ~0;
159 ssd->worker->add_memslot(ssd->worker, &memslot);
162 void qemu_spice_create_host_primary(SimpleSpiceDisplay *ssd)
164 QXLDevSurfaceCreate surface;
166 dprint(1, "%s: %dx%d\n", __FUNCTION__,
167 ds_get_width(ssd->ds), ds_get_height(ssd->ds));
169 surface.format = SPICE_SURFACE_FMT_32_xRGB;
170 surface.width = ds_get_width(ssd->ds);
171 surface.height = ds_get_height(ssd->ds);
172 surface.stride = -surface.width * 4;
173 surface.mouse_mode = true;
174 surface.flags = 0;
175 surface.type = 0;
176 surface.mem = (intptr_t)ssd->buf;
177 surface.group_id = MEMSLOT_GROUP_HOST;
179 ssd->worker->create_primary_surface(ssd->worker, 0, &surface);
182 void qemu_spice_destroy_host_primary(SimpleSpiceDisplay *ssd)
184 dprint(1, "%s:\n", __FUNCTION__);
186 ssd->worker->destroy_primary_surface(ssd->worker, 0);
189 void qemu_spice_vm_change_state_handler(void *opaque, int running, int reason)
191 SimpleSpiceDisplay *ssd = opaque;
193 if (running) {
194 ssd->worker->start(ssd->worker);
195 } else {
196 ssd->worker->stop(ssd->worker);
198 ssd->running = running;
201 /* display listener callbacks */
203 void qemu_spice_display_update(SimpleSpiceDisplay *ssd,
204 int x, int y, int w, int h)
206 QXLRect update_area;
208 dprint(2, "%s: x %d y %d w %d h %d\n", __FUNCTION__, x, y, w, h);
209 update_area.left = x,
210 update_area.right = x + w;
211 update_area.top = y;
212 update_area.bottom = y + h;
214 if (qemu_spice_rect_is_empty(&ssd->dirty)) {
215 ssd->notify++;
217 qemu_spice_rect_union(&ssd->dirty, &update_area);
220 void qemu_spice_display_resize(SimpleSpiceDisplay *ssd)
222 dprint(1, "%s:\n", __FUNCTION__);
224 memset(&ssd->dirty, 0, sizeof(ssd->dirty));
225 qemu_pf_conv_put(ssd->conv);
226 ssd->conv = NULL;
228 qemu_mutex_lock(&ssd->lock);
229 if (ssd->update != NULL) {
230 qemu_spice_destroy_update(ssd, ssd->update);
231 ssd->update = NULL;
233 qemu_mutex_unlock(&ssd->lock);
234 qemu_spice_destroy_host_primary(ssd);
235 qemu_spice_create_host_primary(ssd);
237 memset(&ssd->dirty, 0, sizeof(ssd->dirty));
238 ssd->notify++;
241 void qemu_spice_display_refresh(SimpleSpiceDisplay *ssd)
243 dprint(3, "%s:\n", __FUNCTION__);
244 vga_hw_update();
246 qemu_mutex_lock(&ssd->lock);
247 if (ssd->update == NULL) {
248 ssd->update = qemu_spice_create_update(ssd);
249 ssd->notify++;
251 if (ssd->cursor) {
252 ssd->ds->cursor_define(ssd->cursor);
253 cursor_put(ssd->cursor);
254 ssd->cursor = NULL;
256 if (ssd->mouse_x != -1 && ssd->mouse_y != -1) {
257 ssd->ds->mouse_set(ssd->mouse_x, ssd->mouse_y, 1);
258 ssd->mouse_x = -1;
259 ssd->mouse_y = -1;
261 qemu_mutex_unlock(&ssd->lock);
263 if (ssd->notify) {
264 ssd->notify = 0;
265 ssd->worker->wakeup(ssd->worker);
266 dprint(2, "%s: notify\n", __FUNCTION__);
270 /* spice display interface callbacks */
272 static void interface_attach_worker(QXLInstance *sin, QXLWorker *qxl_worker)
274 SimpleSpiceDisplay *ssd = container_of(sin, SimpleSpiceDisplay, qxl);
276 dprint(1, "%s:\n", __FUNCTION__);
277 ssd->worker = qxl_worker;
280 static void interface_set_compression_level(QXLInstance *sin, int level)
282 dprint(1, "%s:\n", __FUNCTION__);
283 /* nothing to do */
286 static void interface_set_mm_time(QXLInstance *sin, uint32_t mm_time)
288 dprint(3, "%s:\n", __FUNCTION__);
289 /* nothing to do */
292 static void interface_get_init_info(QXLInstance *sin, QXLDevInitInfo *info)
294 SimpleSpiceDisplay *ssd = container_of(sin, SimpleSpiceDisplay, qxl);
296 info->memslot_gen_bits = MEMSLOT_GENERATION_BITS;
297 info->memslot_id_bits = MEMSLOT_SLOT_BITS;
298 info->num_memslots = NUM_MEMSLOTS;
299 info->num_memslots_groups = NUM_MEMSLOTS_GROUPS;
300 info->internal_groupslot_id = 0;
301 info->qxl_ram_size = ssd->bufsize;
302 info->n_surfaces = NUM_SURFACES;
305 static int interface_get_command(QXLInstance *sin, struct QXLCommandExt *ext)
307 SimpleSpiceDisplay *ssd = container_of(sin, SimpleSpiceDisplay, qxl);
308 SimpleSpiceUpdate *update;
309 int ret = false;
311 dprint(3, "%s:\n", __FUNCTION__);
313 qemu_mutex_lock(&ssd->lock);
314 if (ssd->update != NULL) {
315 update = ssd->update;
316 ssd->update = NULL;
317 *ext = update->ext;
318 ret = true;
320 qemu_mutex_unlock(&ssd->lock);
322 return ret;
325 static int interface_req_cmd_notification(QXLInstance *sin)
327 dprint(1, "%s:\n", __FUNCTION__);
328 return 1;
331 static void interface_release_resource(QXLInstance *sin,
332 struct QXLReleaseInfoExt ext)
334 SimpleSpiceDisplay *ssd = container_of(sin, SimpleSpiceDisplay, qxl);
335 uintptr_t id;
337 dprint(2, "%s:\n", __FUNCTION__);
338 id = ext.info->id;
339 qemu_spice_destroy_update(ssd, (void*)id);
342 static int interface_get_cursor_command(QXLInstance *sin, struct QXLCommandExt *ext)
344 dprint(3, "%s:\n", __FUNCTION__);
345 return false;
348 static int interface_req_cursor_notification(QXLInstance *sin)
350 dprint(1, "%s:\n", __FUNCTION__);
351 return 1;
354 static void interface_notify_update(QXLInstance *sin, uint32_t update_id)
356 fprintf(stderr, "%s: abort()\n", __FUNCTION__);
357 abort();
360 static int interface_flush_resources(QXLInstance *sin)
362 fprintf(stderr, "%s: abort()\n", __FUNCTION__);
363 abort();
364 return 0;
367 static const QXLInterface dpy_interface = {
368 .base.type = SPICE_INTERFACE_QXL,
369 .base.description = "qemu simple display",
370 .base.major_version = SPICE_INTERFACE_QXL_MAJOR,
371 .base.minor_version = SPICE_INTERFACE_QXL_MINOR,
373 .attache_worker = interface_attach_worker,
374 .set_compression_level = interface_set_compression_level,
375 .set_mm_time = interface_set_mm_time,
376 .get_init_info = interface_get_init_info,
378 /* the callbacks below are called from spice server thread context */
379 .get_command = interface_get_command,
380 .req_cmd_notification = interface_req_cmd_notification,
381 .release_resource = interface_release_resource,
382 .get_cursor_command = interface_get_cursor_command,
383 .req_cursor_notification = interface_req_cursor_notification,
384 .notify_update = interface_notify_update,
385 .flush_resources = interface_flush_resources,
388 static SimpleSpiceDisplay sdpy;
390 static void display_update(struct DisplayState *ds, int x, int y, int w, int h)
392 qemu_spice_display_update(&sdpy, x, y, w, h);
395 static void display_resize(struct DisplayState *ds)
397 qemu_spice_display_resize(&sdpy);
400 static void display_refresh(struct DisplayState *ds)
402 qemu_spice_display_refresh(&sdpy);
405 static DisplayChangeListener display_listener = {
406 .dpy_update = display_update,
407 .dpy_resize = display_resize,
408 .dpy_refresh = display_refresh,
411 void qemu_spice_display_init(DisplayState *ds)
413 assert(sdpy.ds == NULL);
414 sdpy.ds = ds;
415 qemu_mutex_init(&sdpy.lock);
416 sdpy.mouse_x = -1;
417 sdpy.mouse_y = -1;
418 sdpy.bufsize = (16 * 1024 * 1024);
419 sdpy.buf = qemu_malloc(sdpy.bufsize);
420 register_displaychangelistener(ds, &display_listener);
422 sdpy.qxl.base.sif = &dpy_interface.base;
423 qemu_spice_add_interface(&sdpy.qxl.base);
424 assert(sdpy.worker);
426 qemu_add_vm_change_state_handler(qemu_spice_vm_change_state_handler, &sdpy);
427 qemu_spice_create_host_memslot(&sdpy);
428 qemu_spice_create_host_primary(&sdpy);