2 * SCSI Device emulation
4 * Copyright (c) 2006 CodeSourcery.
5 * Based on code by Fabrice Bellard
7 * Written by Paul Brook
9 * 2009-Dec-12 Artyom Tarasenko : implemented stamdard inquiry for the case
10 * when the allocation length of CDB is smaller
12 * 2009-Oct-13 Artyom Tarasenko : implemented the block descriptor in the
13 * MODE SENSE response.
15 * This code is licenced under the LGPL.
17 * Note that this file only handles the SCSI architecture model and device
18 * commands. Emulation of interface/link layer protocols is handled by
19 * the host adapter emulator.
25 #define DPRINTF(fmt, ...) \
26 do { printf("scsi-disk: " fmt , ## __VA_ARGS__); } while (0)
28 #define DPRINTF(fmt, ...) do {} while(0)
31 #define BADF(fmt, ...) \
32 do { fprintf(stderr, "scsi-disk: " fmt , ## __VA_ARGS__); } while (0)
34 #include "qemu-common.h"
35 #include "qemu-error.h"
37 #include "scsi-defs.h"
41 #define SCSI_DMA_BUF_SIZE 131072
42 #define SCSI_MAX_INQUIRY_LEN 256
44 #define SCSI_REQ_STATUS_RETRY 0x01
45 #define SCSI_REQ_STATUS_RETRY_TYPE_MASK 0x06
46 #define SCSI_REQ_STATUS_RETRY_READ 0x00
47 #define SCSI_REQ_STATUS_RETRY_WRITE 0x02
48 #define SCSI_REQ_STATUS_RETRY_FLUSH 0x04
50 typedef struct SCSIDiskState SCSIDiskState
;
52 typedef struct SCSIDiskReq
{
54 /* Both sector and sector_count are in terms of qemu 512 byte blocks. */
56 uint32_t sector_count
;
62 typedef enum { SCSI_HD
, SCSI_CD
} SCSIDriveKind
;
68 /* The qemu block layer uses a fixed 512 byte sector size.
69 This is the number of 512 byte blocks in a single scsi sector. */
77 SCSIDriveKind drive_kind
;
80 static int scsi_handle_rw_error(SCSIDiskReq
*r
, int error
, int type
);
81 static int scsi_disk_emulate_command(SCSIDiskReq
*r
, uint8_t *outbuf
);
83 static SCSIRequest
*scsi_new_request(SCSIDevice
*d
, uint32_t tag
,
84 uint32_t lun
, void *hba_private
)
86 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, d
);
90 req
= scsi_req_alloc(sizeof(SCSIDiskReq
), &s
->qdev
, tag
, lun
, hba_private
);
91 r
= DO_UPCAST(SCSIDiskReq
, req
, req
);
92 r
->iov
.iov_base
= qemu_blockalign(s
->bs
, SCSI_DMA_BUF_SIZE
);
96 static void scsi_free_request(SCSIRequest
*req
)
98 SCSIDiskReq
*r
= DO_UPCAST(SCSIDiskReq
, req
, req
);
100 qemu_vfree(r
->iov
.iov_base
);
103 static void scsi_disk_clear_sense(SCSIDiskState
*s
)
105 memset(&s
->sense
, 0, sizeof(s
->sense
));
108 static void scsi_req_set_status(SCSIDiskReq
*r
, int status
, SCSISense sense
)
110 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, r
->req
.dev
);
112 r
->req
.status
= status
;
116 /* Helper function for command completion. */
117 static void scsi_command_complete(SCSIDiskReq
*r
, int status
, SCSISense sense
)
119 DPRINTF("Command complete tag=0x%x status=%d sense=%d/%d/%d\n",
120 r
->req
.tag
, status
, sense
.key
, sense
.asc
, sense
.ascq
);
121 scsi_req_set_status(r
, status
, sense
);
122 scsi_req_complete(&r
->req
);
125 /* Cancel a pending data transfer. */
126 static void scsi_cancel_io(SCSIRequest
*req
)
128 SCSIDiskReq
*r
= DO_UPCAST(SCSIDiskReq
, req
, req
);
130 DPRINTF("Cancel tag=0x%x\n", req
->tag
);
132 bdrv_aio_cancel(r
->req
.aiocb
);
137 static void scsi_read_complete(void * opaque
, int ret
)
139 SCSIDiskReq
*r
= (SCSIDiskReq
*)opaque
;
145 if (scsi_handle_rw_error(r
, -ret
, SCSI_REQ_STATUS_RETRY_READ
)) {
150 DPRINTF("Data ready tag=0x%x len=%zd\n", r
->req
.tag
, r
->iov
.iov_len
);
152 n
= r
->iov
.iov_len
/ 512;
154 r
->sector_count
-= n
;
155 scsi_req_data(&r
->req
, r
->iov
.iov_len
);
159 /* Read more data from scsi device into buffer. */
160 static void scsi_read_data(SCSIRequest
*req
)
162 SCSIDiskReq
*r
= DO_UPCAST(SCSIDiskReq
, req
, req
);
163 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, r
->req
.dev
);
166 if (r
->sector_count
== (uint32_t)-1) {
167 DPRINTF("Read buf_len=%zd\n", r
->iov
.iov_len
);
169 scsi_req_data(&r
->req
, r
->iov
.iov_len
);
172 DPRINTF("Read sector_count=%d\n", r
->sector_count
);
173 if (r
->sector_count
== 0) {
174 scsi_command_complete(r
, GOOD
, SENSE_CODE(NO_SENSE
));
178 /* No data transfer may already be in progress */
179 assert(r
->req
.aiocb
== NULL
);
181 if (r
->req
.cmd
.mode
== SCSI_XFER_TO_DEV
) {
182 DPRINTF("Data transfer direction invalid\n");
183 scsi_read_complete(r
, -EINVAL
);
188 if (n
> SCSI_DMA_BUF_SIZE
/ 512)
189 n
= SCSI_DMA_BUF_SIZE
/ 512;
191 r
->iov
.iov_len
= n
* 512;
192 qemu_iovec_init_external(&r
->qiov
, &r
->iov
, 1);
193 r
->req
.aiocb
= bdrv_aio_readv(s
->bs
, r
->sector
, &r
->qiov
, n
,
194 scsi_read_complete
, r
);
195 if (r
->req
.aiocb
== NULL
) {
196 scsi_read_complete(r
, -EIO
);
200 static int scsi_handle_rw_error(SCSIDiskReq
*r
, int error
, int type
)
202 int is_read
= (type
== SCSI_REQ_STATUS_RETRY_READ
);
203 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, r
->req
.dev
);
204 BlockErrorAction action
= bdrv_get_on_error(s
->bs
, is_read
);
206 if (action
== BLOCK_ERR_IGNORE
) {
207 bdrv_mon_event(s
->bs
, BDRV_ACTION_IGNORE
, is_read
);
211 if ((error
== ENOSPC
&& action
== BLOCK_ERR_STOP_ENOSPC
)
212 || action
== BLOCK_ERR_STOP_ANY
) {
214 type
&= SCSI_REQ_STATUS_RETRY_TYPE_MASK
;
215 r
->status
|= SCSI_REQ_STATUS_RETRY
| type
;
217 bdrv_mon_event(s
->bs
, BDRV_ACTION_STOP
, is_read
);
218 vm_stop(VMSTOP_DISKFULL
);
220 if (type
== SCSI_REQ_STATUS_RETRY_READ
) {
221 scsi_req_data(&r
->req
, 0);
225 scsi_command_complete(r
, CHECK_CONDITION
,
226 SENSE_CODE(TARGET_FAILURE
));
229 scsi_command_complete(r
, CHECK_CONDITION
,
230 SENSE_CODE(INVALID_FIELD
));
233 scsi_command_complete(r
, CHECK_CONDITION
,
234 SENSE_CODE(IO_ERROR
));
237 bdrv_mon_event(s
->bs
, BDRV_ACTION_REPORT
, is_read
);
242 static void scsi_write_complete(void * opaque
, int ret
)
244 SCSIDiskReq
*r
= (SCSIDiskReq
*)opaque
;
251 if (scsi_handle_rw_error(r
, -ret
, SCSI_REQ_STATUS_RETRY_WRITE
)) {
256 n
= r
->iov
.iov_len
/ 512;
258 r
->sector_count
-= n
;
259 if (r
->sector_count
== 0) {
260 scsi_command_complete(r
, GOOD
, SENSE_CODE(NO_SENSE
));
262 len
= r
->sector_count
* 512;
263 if (len
> SCSI_DMA_BUF_SIZE
) {
264 len
= SCSI_DMA_BUF_SIZE
;
266 r
->iov
.iov_len
= len
;
267 DPRINTF("Write complete tag=0x%x more=%d\n", r
->req
.tag
, len
);
268 scsi_req_data(&r
->req
, len
);
272 static void scsi_write_data(SCSIRequest
*req
)
274 SCSIDiskReq
*r
= DO_UPCAST(SCSIDiskReq
, req
, req
);
275 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, r
->req
.dev
);
278 /* No data transfer may already be in progress */
279 assert(r
->req
.aiocb
== NULL
);
281 if (r
->req
.cmd
.mode
!= SCSI_XFER_TO_DEV
) {
282 DPRINTF("Data transfer direction invalid\n");
283 scsi_write_complete(r
, -EINVAL
);
287 n
= r
->iov
.iov_len
/ 512;
289 qemu_iovec_init_external(&r
->qiov
, &r
->iov
, 1);
290 r
->req
.aiocb
= bdrv_aio_writev(s
->bs
, r
->sector
, &r
->qiov
, n
,
291 scsi_write_complete
, r
);
292 if (r
->req
.aiocb
== NULL
) {
293 scsi_write_complete(r
, -ENOMEM
);
296 /* Invoke completion routine to fetch data from host. */
297 scsi_write_complete(r
, 0);
301 static void scsi_dma_restart_bh(void *opaque
)
303 SCSIDiskState
*s
= opaque
;
307 qemu_bh_delete(s
->bh
);
310 QTAILQ_FOREACH(req
, &s
->qdev
.requests
, next
) {
311 r
= DO_UPCAST(SCSIDiskReq
, req
, req
);
312 if (r
->status
& SCSI_REQ_STATUS_RETRY
) {
313 int status
= r
->status
;
317 ~(SCSI_REQ_STATUS_RETRY
| SCSI_REQ_STATUS_RETRY_TYPE_MASK
);
319 switch (status
& SCSI_REQ_STATUS_RETRY_TYPE_MASK
) {
320 case SCSI_REQ_STATUS_RETRY_READ
:
321 scsi_read_data(&r
->req
);
323 case SCSI_REQ_STATUS_RETRY_WRITE
:
324 scsi_write_data(&r
->req
);
326 case SCSI_REQ_STATUS_RETRY_FLUSH
:
327 ret
= scsi_disk_emulate_command(r
, r
->iov
.iov_base
);
329 scsi_command_complete(r
, GOOD
, SENSE_CODE(NO_SENSE
));
336 static void scsi_dma_restart_cb(void *opaque
, int running
, int reason
)
338 SCSIDiskState
*s
= opaque
;
344 s
->bh
= qemu_bh_new(scsi_dma_restart_bh
, s
);
345 qemu_bh_schedule(s
->bh
);
349 /* Return a pointer to the data buffer. */
350 static uint8_t *scsi_get_buf(SCSIRequest
*req
)
352 SCSIDiskReq
*r
= DO_UPCAST(SCSIDiskReq
, req
, req
);
354 return (uint8_t *)r
->iov
.iov_base
;
357 /* Copy sense information into the provided buffer */
358 static int scsi_get_sense(SCSIRequest
*req
, uint8_t *outbuf
, int len
)
360 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, req
->dev
);
362 return scsi_build_sense(s
->sense
, outbuf
, len
, len
> 14);
365 static int scsi_disk_emulate_inquiry(SCSIRequest
*req
, uint8_t *outbuf
)
367 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, req
->dev
);
370 if (req
->cmd
.buf
[1] & 0x2) {
371 /* Command support data - optional, not implemented */
372 BADF("optional INQUIRY command support request not implemented\n");
376 if (req
->cmd
.buf
[1] & 0x1) {
377 /* Vital product data */
378 uint8_t page_code
= req
->cmd
.buf
[2];
379 if (req
->cmd
.xfer
< 4) {
380 BADF("Error: Inquiry (EVPD[%02X]) buffer size %zd is "
381 "less than 4\n", page_code
, req
->cmd
.xfer
);
385 if (s
->drive_kind
== SCSI_CD
) {
386 outbuf
[buflen
++] = 5;
388 outbuf
[buflen
++] = 0;
390 outbuf
[buflen
++] = page_code
; // this page
391 outbuf
[buflen
++] = 0x00;
394 case 0x00: /* Supported page codes, mandatory */
397 DPRINTF("Inquiry EVPD[Supported pages] "
398 "buffer size %zd\n", req
->cmd
.xfer
);
400 outbuf
[buflen
++] = 0x00; // list of supported pages (this page)
402 outbuf
[buflen
++] = 0x80; // unit serial number
403 outbuf
[buflen
++] = 0x83; // device identification
404 if (s
->drive_kind
== SCSI_HD
) {
405 outbuf
[buflen
++] = 0xb0; // block limits
406 outbuf
[buflen
++] = 0xb2; // thin provisioning
408 outbuf
[pages
] = buflen
- pages
- 1; // number of pages
411 case 0x80: /* Device serial number, optional */
416 DPRINTF("Inquiry (EVPD[Serial number] not supported\n");
420 l
= strlen(s
->serial
);
421 if (l
> req
->cmd
.xfer
)
426 DPRINTF("Inquiry EVPD[Serial number] "
427 "buffer size %zd\n", req
->cmd
.xfer
);
428 outbuf
[buflen
++] = l
;
429 memcpy(outbuf
+buflen
, s
->serial
, l
);
434 case 0x83: /* Device identification page, mandatory */
436 int max_len
= 255 - 8;
437 int id_len
= strlen(bdrv_get_device_name(s
->bs
));
439 if (id_len
> max_len
)
441 DPRINTF("Inquiry EVPD[Device identification] "
442 "buffer size %zd\n", req
->cmd
.xfer
);
444 outbuf
[buflen
++] = 4 + id_len
;
445 outbuf
[buflen
++] = 0x2; // ASCII
446 outbuf
[buflen
++] = 0; // not officially assigned
447 outbuf
[buflen
++] = 0; // reserved
448 outbuf
[buflen
++] = id_len
; // length of data following
450 memcpy(outbuf
+buflen
, bdrv_get_device_name(s
->bs
), id_len
);
454 case 0xb0: /* block limits */
456 unsigned int unmap_sectors
=
457 s
->qdev
.conf
.discard_granularity
/ s
->qdev
.blocksize
;
458 unsigned int min_io_size
=
459 s
->qdev
.conf
.min_io_size
/ s
->qdev
.blocksize
;
460 unsigned int opt_io_size
=
461 s
->qdev
.conf
.opt_io_size
/ s
->qdev
.blocksize
;
463 if (s
->drive_kind
== SCSI_CD
) {
464 DPRINTF("Inquiry (EVPD[%02X] not supported for CDROM\n",
468 /* required VPD size with unmap support */
469 outbuf
[3] = buflen
= 0x3c;
471 memset(outbuf
+ 4, 0, buflen
- 4);
473 /* optimal transfer length granularity */
474 outbuf
[6] = (min_io_size
>> 8) & 0xff;
475 outbuf
[7] = min_io_size
& 0xff;
477 /* optimal transfer length */
478 outbuf
[12] = (opt_io_size
>> 24) & 0xff;
479 outbuf
[13] = (opt_io_size
>> 16) & 0xff;
480 outbuf
[14] = (opt_io_size
>> 8) & 0xff;
481 outbuf
[15] = opt_io_size
& 0xff;
483 /* optimal unmap granularity */
484 outbuf
[28] = (unmap_sectors
>> 24) & 0xff;
485 outbuf
[29] = (unmap_sectors
>> 16) & 0xff;
486 outbuf
[30] = (unmap_sectors
>> 8) & 0xff;
487 outbuf
[31] = unmap_sectors
& 0xff;
490 case 0xb2: /* thin provisioning */
492 outbuf
[3] = buflen
= 8;
494 outbuf
[5] = 0x40; /* write same with unmap supported */
500 BADF("Error: unsupported Inquiry (EVPD[%02X]) "
501 "buffer size %zd\n", page_code
, req
->cmd
.xfer
);
508 /* Standard INQUIRY data */
509 if (req
->cmd
.buf
[2] != 0) {
510 BADF("Error: Inquiry (STANDARD) page or code "
511 "is non-zero [%02X]\n", req
->cmd
.buf
[2]);
516 if (req
->cmd
.xfer
< 5) {
517 BADF("Error: Inquiry (STANDARD) buffer size %zd "
518 "is less than 5\n", req
->cmd
.xfer
);
522 buflen
= req
->cmd
.xfer
;
523 if (buflen
> SCSI_MAX_INQUIRY_LEN
)
524 buflen
= SCSI_MAX_INQUIRY_LEN
;
526 memset(outbuf
, 0, buflen
);
529 outbuf
[0] = 0x7f; /* LUN not supported */
533 if (s
->drive_kind
== SCSI_CD
) {
536 memcpy(&outbuf
[16], "QEMU CD-ROM ", 16);
539 outbuf
[1] = s
->removable
? 0x80 : 0;
540 memcpy(&outbuf
[16], "QEMU HARDDISK ", 16);
542 memcpy(&outbuf
[8], "QEMU ", 8);
543 memset(&outbuf
[32], 0, 4);
544 memcpy(&outbuf
[32], s
->version
, MIN(4, strlen(s
->version
)));
546 * We claim conformance to SPC-3, which is required for guests
547 * to ask for modern features like READ CAPACITY(16) or the
548 * block characteristics VPD page by default. Not all of SPC-3
549 * is actually implemented, but we're good enough.
552 outbuf
[3] = 2; /* Format 2 */
555 outbuf
[4] = buflen
- 5; /* Additional Length = (Len - 1) - 4 */
557 /* If the allocation length of CDB is too small,
558 the additional length is not adjusted */
562 /* Sync data transfer and TCQ. */
563 outbuf
[7] = 0x10 | (req
->bus
->tcq
? 0x02 : 0);
567 static int mode_sense_page(SCSIRequest
*req
, int page
, uint8_t *p
,
570 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, req
->dev
);
571 BlockDriverState
*bdrv
= s
->bs
;
572 int cylinders
, heads
, secs
;
575 * If Changeable Values are requested, a mask denoting those mode parameters
576 * that are changeable shall be returned. As we currently don't support
577 * parameter changes via MODE_SELECT all bits are returned set to zero.
578 * The buffer was already menset to zero by the caller of this function.
581 case 4: /* Rigid disk device geometry page. */
584 if (page_control
== 1) { /* Changeable Values */
587 /* if a geometry hint is available, use it */
588 bdrv_get_geometry_hint(bdrv
, &cylinders
, &heads
, &secs
);
589 p
[2] = (cylinders
>> 16) & 0xff;
590 p
[3] = (cylinders
>> 8) & 0xff;
591 p
[4] = cylinders
& 0xff;
593 /* Write precomp start cylinder, disabled */
594 p
[6] = (cylinders
>> 16) & 0xff;
595 p
[7] = (cylinders
>> 8) & 0xff;
596 p
[8] = cylinders
& 0xff;
597 /* Reduced current start cylinder, disabled */
598 p
[9] = (cylinders
>> 16) & 0xff;
599 p
[10] = (cylinders
>> 8) & 0xff;
600 p
[11] = cylinders
& 0xff;
601 /* Device step rate [ns], 200ns */
604 /* Landing zone cylinder */
608 /* Medium rotation rate [rpm], 5400 rpm */
609 p
[20] = (5400 >> 8) & 0xff;
613 case 5: /* Flexible disk device geometry page. */
616 if (page_control
== 1) { /* Changeable Values */
619 /* Transfer rate [kbit/s], 5Mbit/s */
622 /* if a geometry hint is available, use it */
623 bdrv_get_geometry_hint(bdrv
, &cylinders
, &heads
, &secs
);
626 p
[6] = s
->cluster_size
* 2;
627 p
[8] = (cylinders
>> 8) & 0xff;
628 p
[9] = cylinders
& 0xff;
629 /* Write precomp start cylinder, disabled */
630 p
[10] = (cylinders
>> 8) & 0xff;
631 p
[11] = cylinders
& 0xff;
632 /* Reduced current start cylinder, disabled */
633 p
[12] = (cylinders
>> 8) & 0xff;
634 p
[13] = cylinders
& 0xff;
635 /* Device step rate [100us], 100us */
638 /* Device step pulse width [us], 1us */
640 /* Device head settle delay [100us], 100us */
643 /* Motor on delay [0.1s], 0.1s */
645 /* Motor off delay [0.1s], 0.1s */
647 /* Medium rotation rate [rpm], 5400 rpm */
648 p
[28] = (5400 >> 8) & 0xff;
652 case 8: /* Caching page. */
655 if (page_control
== 1) { /* Changeable Values */
658 if (bdrv_enable_write_cache(s
->bs
)) {
663 case 0x2a: /* CD Capabilities and Mechanical Status page. */
664 if (s
->drive_kind
!= SCSI_CD
)
668 if (page_control
== 1) { /* Changeable Values */
671 p
[2] = 3; // CD-R & CD-RW read
672 p
[3] = 0; // Writing not supported
673 p
[4] = 0x7f; /* Audio, composite, digital out,
674 mode 2 form 1&2, multi session */
675 p
[5] = 0xff; /* CD DA, DA accurate, RW supported,
676 RW corrected, C2 errors, ISRC,
678 p
[6] = 0x2d | (bdrv_is_locked(s
->bs
)? 2 : 0);
679 /* Locking supported, jumper present, eject, tray */
680 p
[7] = 0; /* no volume & mute control, no
682 p
[8] = (50 * 176) >> 8; // 50x read speed
683 p
[9] = (50 * 176) & 0xff;
684 p
[10] = 0 >> 8; // No volume
686 p
[12] = 2048 >> 8; // 2M buffer
688 p
[14] = (16 * 176) >> 8; // 16x read speed current
689 p
[15] = (16 * 176) & 0xff;
690 p
[18] = (16 * 176) >> 8; // 16x write speed
691 p
[19] = (16 * 176) & 0xff;
692 p
[20] = (16 * 176) >> 8; // 16x write speed current
693 p
[21] = (16 * 176) & 0xff;
701 static int scsi_disk_emulate_mode_sense(SCSIRequest
*req
, uint8_t *outbuf
)
703 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, req
->dev
);
705 int page
, dbd
, buflen
, page_control
;
707 uint8_t dev_specific_param
;
709 dbd
= req
->cmd
.buf
[1] & 0x8;
710 page
= req
->cmd
.buf
[2] & 0x3f;
711 page_control
= (req
->cmd
.buf
[2] & 0xc0) >> 6;
712 DPRINTF("Mode Sense(%d) (page %d, xfer %zd, page_control %d)\n",
713 (req
->cmd
.buf
[0] == MODE_SENSE
) ? 6 : 10, page
, req
->cmd
.xfer
, page_control
);
714 memset(outbuf
, 0, req
->cmd
.xfer
);
717 if (bdrv_is_read_only(s
->bs
)) {
718 dev_specific_param
= 0x80; /* Readonly. */
720 dev_specific_param
= 0x00;
723 if (req
->cmd
.buf
[0] == MODE_SENSE
) {
724 p
[1] = 0; /* Default media type. */
725 p
[2] = dev_specific_param
;
726 p
[3] = 0; /* Block descriptor length. */
728 } else { /* MODE_SENSE_10 */
729 p
[2] = 0; /* Default media type. */
730 p
[3] = dev_specific_param
;
731 p
[6] = p
[7] = 0; /* Block descriptor length. */
735 bdrv_get_geometry(s
->bs
, &nb_sectors
);
736 if (!dbd
&& nb_sectors
) {
737 if (req
->cmd
.buf
[0] == MODE_SENSE
) {
738 outbuf
[3] = 8; /* Block descriptor length */
739 } else { /* MODE_SENSE_10 */
740 outbuf
[7] = 8; /* Block descriptor length */
742 nb_sectors
/= s
->cluster_size
;
743 if (nb_sectors
> 0xffffff)
745 p
[0] = 0; /* media density code */
746 p
[1] = (nb_sectors
>> 16) & 0xff;
747 p
[2] = (nb_sectors
>> 8) & 0xff;
748 p
[3] = nb_sectors
& 0xff;
749 p
[4] = 0; /* reserved */
750 p
[5] = 0; /* bytes 5-7 are the sector size in bytes */
751 p
[6] = s
->cluster_size
* 2;
756 if (page_control
== 3) { /* Saved Values */
757 return -1; /* ILLEGAL_REQUEST */
765 p
+= mode_sense_page(req
, page
, p
, page_control
);
768 p
+= mode_sense_page(req
, 0x08, p
, page_control
);
769 p
+= mode_sense_page(req
, 0x2a, p
, page_control
);
772 return -1; /* ILLEGAL_REQUEST */
777 * The mode data length field specifies the length in bytes of the
778 * following data that is available to be transferred. The mode data
779 * length does not include itself.
781 if (req
->cmd
.buf
[0] == MODE_SENSE
) {
782 outbuf
[0] = buflen
- 1;
783 } else { /* MODE_SENSE_10 */
784 outbuf
[0] = ((buflen
- 2) >> 8) & 0xff;
785 outbuf
[1] = (buflen
- 2) & 0xff;
787 if (buflen
> req
->cmd
.xfer
)
788 buflen
= req
->cmd
.xfer
;
792 static int scsi_disk_emulate_read_toc(SCSIRequest
*req
, uint8_t *outbuf
)
794 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, req
->dev
);
795 int start_track
, format
, msf
, toclen
;
798 msf
= req
->cmd
.buf
[1] & 2;
799 format
= req
->cmd
.buf
[2] & 0xf;
800 start_track
= req
->cmd
.buf
[6];
801 bdrv_get_geometry(s
->bs
, &nb_sectors
);
802 DPRINTF("Read TOC (track %d format %d msf %d)\n", start_track
, format
, msf
>> 1);
803 nb_sectors
/= s
->cluster_size
;
806 toclen
= cdrom_read_toc(nb_sectors
, outbuf
, msf
, start_track
);
809 /* multi session : only a single session defined */
811 memset(outbuf
, 0, 12);
817 toclen
= cdrom_read_toc_raw(nb_sectors
, outbuf
, msf
, start_track
);
822 if (toclen
> req
->cmd
.xfer
)
823 toclen
= req
->cmd
.xfer
;
827 static int scsi_disk_emulate_command(SCSIDiskReq
*r
, uint8_t *outbuf
)
829 SCSIRequest
*req
= &r
->req
;
830 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, req
->dev
);
835 switch (req
->cmd
.buf
[0]) {
836 case TEST_UNIT_READY
:
837 if (!bdrv_is_inserted(s
->bs
))
841 if (req
->cmd
.xfer
< 4)
842 goto illegal_request
;
843 buflen
= scsi_build_sense(s
->sense
, outbuf
, req
->cmd
.xfer
,
845 scsi_disk_clear_sense(s
);
848 buflen
= scsi_disk_emulate_inquiry(req
, outbuf
);
850 goto illegal_request
;
854 buflen
= scsi_disk_emulate_mode_sense(req
, outbuf
);
856 goto illegal_request
;
859 buflen
= scsi_disk_emulate_read_toc(req
, outbuf
);
861 goto illegal_request
;
864 if (req
->cmd
.buf
[1] & 1)
865 goto illegal_request
;
868 if (req
->cmd
.buf
[1] & 3)
869 goto illegal_request
;
872 if (req
->cmd
.buf
[1] & 1)
873 goto illegal_request
;
876 if (req
->cmd
.buf
[1] & 3)
877 goto illegal_request
;
880 if (s
->drive_kind
== SCSI_CD
&& (req
->cmd
.buf
[4] & 2)) {
881 /* load/eject medium */
882 bdrv_eject(s
->bs
, !(req
->cmd
.buf
[4] & 1));
885 case ALLOW_MEDIUM_REMOVAL
:
886 bdrv_set_locked(s
->bs
, req
->cmd
.buf
[4] & 1);
889 /* The normal LEN field for this command is zero. */
890 memset(outbuf
, 0, 8);
891 bdrv_get_geometry(s
->bs
, &nb_sectors
);
894 nb_sectors
/= s
->cluster_size
;
895 /* Returned value is the address of the last sector. */
897 /* Remember the new size for read/write sanity checking. */
898 s
->max_lba
= nb_sectors
;
899 /* Clip to 2TB, instead of returning capacity modulo 2TB. */
900 if (nb_sectors
> UINT32_MAX
)
901 nb_sectors
= UINT32_MAX
;
902 outbuf
[0] = (nb_sectors
>> 24) & 0xff;
903 outbuf
[1] = (nb_sectors
>> 16) & 0xff;
904 outbuf
[2] = (nb_sectors
>> 8) & 0xff;
905 outbuf
[3] = nb_sectors
& 0xff;
908 outbuf
[6] = s
->cluster_size
* 2;
912 case SYNCHRONIZE_CACHE
:
913 ret
= bdrv_flush(s
->bs
);
915 if (scsi_handle_rw_error(r
, -ret
, SCSI_REQ_STATUS_RETRY_FLUSH
)) {
920 case GET_CONFIGURATION
:
921 memset(outbuf
, 0, 8);
922 /* ??? This should probably return much more information. For now
923 just return the basic header indicating the CD-ROM profile. */
924 outbuf
[7] = 8; // CD-ROM
927 case SERVICE_ACTION_IN
:
928 /* Service Action In subcommands. */
929 if ((req
->cmd
.buf
[1] & 31) == 0x10) {
930 DPRINTF("SAI READ CAPACITY(16)\n");
931 memset(outbuf
, 0, req
->cmd
.xfer
);
932 bdrv_get_geometry(s
->bs
, &nb_sectors
);
935 nb_sectors
/= s
->cluster_size
;
936 /* Returned value is the address of the last sector. */
938 /* Remember the new size for read/write sanity checking. */
939 s
->max_lba
= nb_sectors
;
940 outbuf
[0] = (nb_sectors
>> 56) & 0xff;
941 outbuf
[1] = (nb_sectors
>> 48) & 0xff;
942 outbuf
[2] = (nb_sectors
>> 40) & 0xff;
943 outbuf
[3] = (nb_sectors
>> 32) & 0xff;
944 outbuf
[4] = (nb_sectors
>> 24) & 0xff;
945 outbuf
[5] = (nb_sectors
>> 16) & 0xff;
946 outbuf
[6] = (nb_sectors
>> 8) & 0xff;
947 outbuf
[7] = nb_sectors
& 0xff;
950 outbuf
[10] = s
->cluster_size
* 2;
953 outbuf
[13] = get_physical_block_exp(&s
->qdev
.conf
);
955 /* set TPE bit if the format supports discard */
956 if (s
->qdev
.conf
.discard_granularity
) {
960 /* Protection, exponent and lowest lba field left blank. */
961 buflen
= req
->cmd
.xfer
;
964 DPRINTF("Unsupported Service Action In\n");
965 goto illegal_request
;
967 if (req
->cmd
.xfer
< 16)
968 goto illegal_request
;
969 memset(outbuf
, 0, 16);
976 DPRINTF("Rezero Unit\n");
977 if (!bdrv_is_inserted(s
->bs
)) {
982 scsi_command_complete(r
, CHECK_CONDITION
, SENSE_CODE(INVALID_OPCODE
));
985 scsi_req_set_status(r
, GOOD
, SENSE_CODE(NO_SENSE
));
989 if (!bdrv_is_inserted(s
->bs
)) {
990 scsi_command_complete(r
, CHECK_CONDITION
, SENSE_CODE(NO_MEDIUM
));
992 scsi_command_complete(r
, CHECK_CONDITION
, SENSE_CODE(LUN_NOT_READY
));
997 scsi_command_complete(r
, CHECK_CONDITION
, SENSE_CODE(INVALID_FIELD
));
1001 /* Execute a scsi command. Returns the length of the data expected by the
1002 command. This will be Positive for data transfers from the device
1003 (eg. disk reads), negative for transfers to the device (eg. disk writes),
1004 and zero if the command does not transfer any data. */
1006 static int32_t scsi_send_command(SCSIRequest
*req
, uint8_t *buf
)
1008 SCSIDiskReq
*r
= DO_UPCAST(SCSIDiskReq
, req
, req
);
1009 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, req
->dev
);
1016 outbuf
= (uint8_t *)r
->iov
.iov_base
;
1017 DPRINTF("Command: lun=%d tag=0x%x data=0x%02x", req
->lun
, req
->tag
, buf
[0]);
1019 if (scsi_req_parse(&r
->req
, buf
) != 0) {
1020 BADF("Unsupported command length, command %x\n", command
);
1021 scsi_command_complete(r
, CHECK_CONDITION
, SENSE_CODE(INVALID_OPCODE
));
1027 for (i
= 1; i
< r
->req
.cmd
.len
; i
++) {
1028 printf(" 0x%02x", buf
[i
]);
1035 /* Only LUN 0 supported. */
1036 DPRINTF("Unimplemented LUN %d\n", req
->lun
);
1037 if (command
!= REQUEST_SENSE
&& command
!= INQUIRY
) {
1038 scsi_command_complete(r
, CHECK_CONDITION
,
1039 SENSE_CODE(LUN_NOT_SUPPORTED
));
1044 case TEST_UNIT_READY
:
1054 case ALLOW_MEDIUM_REMOVAL
:
1056 case SYNCHRONIZE_CACHE
:
1058 case GET_CONFIGURATION
:
1059 case SERVICE_ACTION_IN
:
1063 rc
= scsi_disk_emulate_command(r
, outbuf
);
1068 r
->iov
.iov_len
= rc
;
1074 len
= r
->req
.cmd
.xfer
/ s
->qdev
.blocksize
;
1075 DPRINTF("Read (sector %" PRId64
", count %d)\n", r
->req
.cmd
.lba
, len
);
1076 if (r
->req
.cmd
.lba
> s
->max_lba
)
1078 r
->sector
= r
->req
.cmd
.lba
* s
->cluster_size
;
1079 r
->sector_count
= len
* s
->cluster_size
;
1086 case WRITE_VERIFY_12
:
1087 case WRITE_VERIFY_16
:
1088 len
= r
->req
.cmd
.xfer
/ s
->qdev
.blocksize
;
1089 DPRINTF("Write %s(sector %" PRId64
", count %d)\n",
1090 (command
& 0xe) == 0xe ? "And Verify " : "",
1091 r
->req
.cmd
.lba
, len
);
1092 if (r
->req
.cmd
.lba
> s
->max_lba
)
1094 r
->sector
= r
->req
.cmd
.lba
* s
->cluster_size
;
1095 r
->sector_count
= len
* s
->cluster_size
;
1098 DPRINTF("Mode Select(6) (len %lu)\n", (long)r
->req
.cmd
.xfer
);
1099 /* We don't support mode parameter changes.
1100 Allow the mode parameter header + block descriptors only. */
1101 if (r
->req
.cmd
.xfer
> 12) {
1105 case MODE_SELECT_10
:
1106 DPRINTF("Mode Select(10) (len %lu)\n", (long)r
->req
.cmd
.xfer
);
1107 /* We don't support mode parameter changes.
1108 Allow the mode parameter header + block descriptors only. */
1109 if (r
->req
.cmd
.xfer
> 16) {
1115 DPRINTF("Seek(%d) (sector %" PRId64
")\n", command
== SEEK_6
? 6 : 10,
1117 if (r
->req
.cmd
.lba
> s
->max_lba
) {
1122 len
= r
->req
.cmd
.xfer
/ s
->qdev
.blocksize
;
1124 DPRINTF("WRITE SAME(16) (sector %" PRId64
", count %d)\n",
1125 r
->req
.cmd
.lba
, len
);
1127 if (r
->req
.cmd
.lba
> s
->max_lba
) {
1132 * We only support WRITE SAME with the unmap bit set for now.
1134 if (!(buf
[1] & 0x8)) {
1138 rc
= bdrv_discard(s
->bs
, r
->req
.cmd
.lba
* s
->cluster_size
,
1139 len
* s
->cluster_size
);
1141 /* XXX: better error code ?*/
1147 DPRINTF("Unknown SCSI command (%2.2x)\n", buf
[0]);
1148 scsi_command_complete(r
, CHECK_CONDITION
, SENSE_CODE(INVALID_OPCODE
));
1151 scsi_command_complete(r
, CHECK_CONDITION
, SENSE_CODE(INVALID_FIELD
));
1154 scsi_command_complete(r
, CHECK_CONDITION
, SENSE_CODE(LBA_OUT_OF_RANGE
));
1157 if (r
->sector_count
== 0 && r
->iov
.iov_len
== 0) {
1158 scsi_command_complete(r
, GOOD
, SENSE_CODE(NO_SENSE
));
1160 len
= r
->sector_count
* 512 + r
->iov
.iov_len
;
1161 if (r
->req
.cmd
.mode
== SCSI_XFER_TO_DEV
) {
1164 if (!r
->sector_count
)
1165 r
->sector_count
= -1;
1170 static void scsi_disk_reset(DeviceState
*dev
)
1172 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
.qdev
, dev
);
1173 uint64_t nb_sectors
;
1175 scsi_device_purge_requests(&s
->qdev
);
1177 bdrv_get_geometry(s
->bs
, &nb_sectors
);
1178 nb_sectors
/= s
->cluster_size
;
1182 s
->max_lba
= nb_sectors
;
1185 static void scsi_destroy(SCSIDevice
*dev
)
1187 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, dev
);
1189 scsi_device_purge_requests(&s
->qdev
);
1190 blockdev_mark_auto_del(s
->qdev
.conf
.bs
);
1193 static int scsi_initfn(SCSIDevice
*dev
, SCSIDriveKind kind
)
1195 SCSIDiskState
*s
= DO_UPCAST(SCSIDiskState
, qdev
, dev
);
1198 if (!s
->qdev
.conf
.bs
) {
1199 error_report("scsi-disk: drive property not set");
1202 s
->bs
= s
->qdev
.conf
.bs
;
1203 s
->drive_kind
= kind
;
1205 if (kind
== SCSI_HD
&& !bdrv_is_inserted(s
->bs
)) {
1206 error_report("Device needs media, but drive is empty");
1211 /* try to fall back to value set with legacy -drive serial=... */
1212 dinfo
= drive_get_by_blockdev(s
->bs
);
1213 if (*dinfo
->serial
) {
1214 s
->serial
= qemu_strdup(dinfo
->serial
);
1219 s
->version
= qemu_strdup(QEMU_VERSION
);
1222 if (bdrv_is_sg(s
->bs
)) {
1223 error_report("scsi-disk: unwanted /dev/sg*");
1227 if (kind
== SCSI_CD
) {
1228 s
->qdev
.blocksize
= 2048;
1230 s
->qdev
.blocksize
= s
->qdev
.conf
.logical_block_size
;
1232 s
->cluster_size
= s
->qdev
.blocksize
/ 512;
1233 s
->bs
->buffer_alignment
= s
->qdev
.blocksize
;
1235 s
->qdev
.type
= TYPE_DISK
;
1236 qemu_add_vm_change_state_handler(scsi_dma_restart_cb
, s
);
1237 bdrv_set_removable(s
->bs
, kind
== SCSI_CD
);
1238 add_boot_device_path(s
->qdev
.conf
.bootindex
, &dev
->qdev
, ",0");
1242 static int scsi_hd_initfn(SCSIDevice
*dev
)
1244 return scsi_initfn(dev
, SCSI_HD
);
1247 static int scsi_cd_initfn(SCSIDevice
*dev
)
1249 return scsi_initfn(dev
, SCSI_CD
);
1252 static int scsi_disk_initfn(SCSIDevice
*dev
)
1257 if (!dev
->conf
.bs
) {
1258 kind
= SCSI_HD
; /* will die in scsi_initfn() */
1260 dinfo
= drive_get_by_blockdev(dev
->conf
.bs
);
1261 kind
= dinfo
->media_cd
? SCSI_CD
: SCSI_HD
;
1264 return scsi_initfn(dev
, kind
);
1267 #define DEFINE_SCSI_DISK_PROPERTIES() \
1268 DEFINE_BLOCK_PROPERTIES(SCSIDiskState, qdev.conf), \
1269 DEFINE_PROP_STRING("ver", SCSIDiskState, version), \
1270 DEFINE_PROP_STRING("serial", SCSIDiskState, serial)
1272 static SCSIDeviceInfo scsi_disk_info
[] = {
1274 .qdev
.name
= "scsi-hd",
1275 .qdev
.fw_name
= "disk",
1276 .qdev
.desc
= "virtual SCSI disk",
1277 .qdev
.size
= sizeof(SCSIDiskState
),
1278 .qdev
.reset
= scsi_disk_reset
,
1279 .init
= scsi_hd_initfn
,
1280 .destroy
= scsi_destroy
,
1281 .alloc_req
= scsi_new_request
,
1282 .free_req
= scsi_free_request
,
1283 .send_command
= scsi_send_command
,
1284 .read_data
= scsi_read_data
,
1285 .write_data
= scsi_write_data
,
1286 .cancel_io
= scsi_cancel_io
,
1287 .get_buf
= scsi_get_buf
,
1288 .get_sense
= scsi_get_sense
,
1289 .qdev
.props
= (Property
[]) {
1290 DEFINE_SCSI_DISK_PROPERTIES(),
1291 DEFINE_PROP_BIT("removable", SCSIDiskState
, removable
, 0, false),
1292 DEFINE_PROP_END_OF_LIST(),
1295 .qdev
.name
= "scsi-cd",
1296 .qdev
.fw_name
= "disk",
1297 .qdev
.desc
= "virtual SCSI CD-ROM",
1298 .qdev
.size
= sizeof(SCSIDiskState
),
1299 .qdev
.reset
= scsi_disk_reset
,
1300 .init
= scsi_cd_initfn
,
1301 .destroy
= scsi_destroy
,
1302 .alloc_req
= scsi_new_request
,
1303 .free_req
= scsi_free_request
,
1304 .send_command
= scsi_send_command
,
1305 .read_data
= scsi_read_data
,
1306 .write_data
= scsi_write_data
,
1307 .cancel_io
= scsi_cancel_io
,
1308 .get_buf
= scsi_get_buf
,
1309 .get_sense
= scsi_get_sense
,
1310 .qdev
.props
= (Property
[]) {
1311 DEFINE_SCSI_DISK_PROPERTIES(),
1312 DEFINE_PROP_END_OF_LIST(),
1315 .qdev
.name
= "scsi-disk", /* legacy -device scsi-disk */
1316 .qdev
.fw_name
= "disk",
1317 .qdev
.desc
= "virtual SCSI disk or CD-ROM (legacy)",
1318 .qdev
.size
= sizeof(SCSIDiskState
),
1319 .qdev
.reset
= scsi_disk_reset
,
1320 .init
= scsi_disk_initfn
,
1321 .destroy
= scsi_destroy
,
1322 .alloc_req
= scsi_new_request
,
1323 .free_req
= scsi_free_request
,
1324 .send_command
= scsi_send_command
,
1325 .read_data
= scsi_read_data
,
1326 .write_data
= scsi_write_data
,
1327 .cancel_io
= scsi_cancel_io
,
1328 .get_buf
= scsi_get_buf
,
1329 .get_sense
= scsi_get_sense
,
1330 .qdev
.props
= (Property
[]) {
1331 DEFINE_SCSI_DISK_PROPERTIES(),
1332 DEFINE_PROP_BIT("removable", SCSIDiskState
, removable
, 0, false),
1333 DEFINE_PROP_END_OF_LIST(),
1338 static void scsi_disk_register_devices(void)
1342 for (i
= 0; i
< ARRAY_SIZE(scsi_disk_info
); i
++) {
1343 scsi_qdev_register(&scsi_disk_info
[i
]);
1346 device_init(scsi_disk_register_devices
)