json-parser: Fix segfault on malformed input
[qemu.git] / qemu-char.c
blob86c7c5a3f5de98ea86fd80692f935f40b9bcc5e4
1 /*
2 * QEMU System Emulator
4 * Copyright (c) 2003-2008 Fabrice Bellard
6 * Permission is hereby granted, free of charge, to any person obtaining a copy
7 * of this software and associated documentation files (the "Software"), to deal
8 * in the Software without restriction, including without limitation the rights
9 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
10 * copies of the Software, and to permit persons to whom the Software is
11 * furnished to do so, subject to the following conditions:
13 * The above copyright notice and this permission notice shall be included in
14 * all copies or substantial portions of the Software.
16 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
17 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
18 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
19 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
20 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
21 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
22 * THE SOFTWARE.
24 #include "qemu-common.h"
25 #include "net.h"
26 #include "monitor.h"
27 #include "console.h"
28 #include "sysemu.h"
29 #include "qemu-timer.h"
30 #include "qemu-char.h"
31 #include "block.h"
32 #include "hw/usb.h"
33 #include "hw/baum.h"
34 #include "hw/msmouse.h"
35 #include "qemu-objects.h"
37 #include <unistd.h>
38 #include <fcntl.h>
39 #include <signal.h>
40 #include <time.h>
41 #include <errno.h>
42 #include <sys/time.h>
43 #include <zlib.h>
45 #ifndef _WIN32
46 #include <sys/times.h>
47 #include <sys/wait.h>
48 #include <termios.h>
49 #include <sys/mman.h>
50 #include <sys/ioctl.h>
51 #include <sys/resource.h>
52 #include <sys/socket.h>
53 #include <netinet/in.h>
54 #include <net/if.h>
55 #include <arpa/inet.h>
56 #include <dirent.h>
57 #include <netdb.h>
58 #include <sys/select.h>
59 #ifdef CONFIG_BSD
60 #include <sys/stat.h>
61 #if defined(__FreeBSD__) || defined(__FreeBSD_kernel__)
62 #include <libutil.h>
63 #include <dev/ppbus/ppi.h>
64 #include <dev/ppbus/ppbconf.h>
65 #if defined(__GLIBC__)
66 #include <pty.h>
67 #endif
68 #elif defined(__DragonFly__)
69 #include <libutil.h>
70 #include <dev/misc/ppi/ppi.h>
71 #include <bus/ppbus/ppbconf.h>
72 #else
73 #include <util.h>
74 #endif
75 #else
76 #ifdef __linux__
77 #include <pty.h>
79 #include <linux/ppdev.h>
80 #include <linux/parport.h>
81 #endif
82 #ifdef __sun__
83 #include <sys/stat.h>
84 #include <sys/ethernet.h>
85 #include <sys/sockio.h>
86 #include <netinet/arp.h>
87 #include <netinet/in.h>
88 #include <netinet/in_systm.h>
89 #include <netinet/ip.h>
90 #include <netinet/ip_icmp.h> // must come after ip.h
91 #include <netinet/udp.h>
92 #include <netinet/tcp.h>
93 #include <net/if.h>
94 #include <syslog.h>
95 #include <stropts.h>
96 #endif
97 #endif
98 #endif
100 #include "qemu_socket.h"
102 #define READ_BUF_LEN 4096
104 /***********************************************************/
105 /* character device */
107 static QTAILQ_HEAD(CharDriverStateHead, CharDriverState) chardevs =
108 QTAILQ_HEAD_INITIALIZER(chardevs);
110 static void qemu_chr_event(CharDriverState *s, int event)
112 if (!s->chr_event)
113 return;
114 s->chr_event(s->handler_opaque, event);
117 static void qemu_chr_generic_open_bh(void *opaque)
119 CharDriverState *s = opaque;
120 qemu_chr_event(s, CHR_EVENT_OPENED);
121 qemu_bh_delete(s->bh);
122 s->bh = NULL;
125 void qemu_chr_generic_open(CharDriverState *s)
127 if (s->bh == NULL) {
128 s->bh = qemu_bh_new(qemu_chr_generic_open_bh, s);
129 qemu_bh_schedule(s->bh);
133 int qemu_chr_write(CharDriverState *s, const uint8_t *buf, int len)
135 return s->chr_write(s, buf, len);
138 int qemu_chr_ioctl(CharDriverState *s, int cmd, void *arg)
140 if (!s->chr_ioctl)
141 return -ENOTSUP;
142 return s->chr_ioctl(s, cmd, arg);
145 int qemu_chr_can_read(CharDriverState *s)
147 if (!s->chr_can_read)
148 return 0;
149 return s->chr_can_read(s->handler_opaque);
152 void qemu_chr_read(CharDriverState *s, uint8_t *buf, int len)
154 s->chr_read(s->handler_opaque, buf, len);
157 int qemu_chr_get_msgfd(CharDriverState *s)
159 return s->get_msgfd ? s->get_msgfd(s) : -1;
162 void qemu_chr_accept_input(CharDriverState *s)
164 if (s->chr_accept_input)
165 s->chr_accept_input(s);
168 void qemu_chr_printf(CharDriverState *s, const char *fmt, ...)
170 char buf[READ_BUF_LEN];
171 va_list ap;
172 va_start(ap, fmt);
173 vsnprintf(buf, sizeof(buf), fmt, ap);
174 qemu_chr_write(s, (uint8_t *)buf, strlen(buf));
175 va_end(ap);
178 void qemu_chr_send_event(CharDriverState *s, int event)
180 if (s->chr_send_event)
181 s->chr_send_event(s, event);
184 void qemu_chr_add_handlers(CharDriverState *s,
185 IOCanRWHandler *fd_can_read,
186 IOReadHandler *fd_read,
187 IOEventHandler *fd_event,
188 void *opaque)
190 s->chr_can_read = fd_can_read;
191 s->chr_read = fd_read;
192 s->chr_event = fd_event;
193 s->handler_opaque = opaque;
194 if (s->chr_update_read_handler)
195 s->chr_update_read_handler(s);
198 static int null_chr_write(CharDriverState *chr, const uint8_t *buf, int len)
200 return len;
203 static CharDriverState *qemu_chr_open_null(QemuOpts *opts)
205 CharDriverState *chr;
207 chr = qemu_mallocz(sizeof(CharDriverState));
208 chr->chr_write = null_chr_write;
209 return chr;
212 /* MUX driver for serial I/O splitting */
213 #define MAX_MUX 4
214 #define MUX_BUFFER_SIZE 32 /* Must be a power of 2. */
215 #define MUX_BUFFER_MASK (MUX_BUFFER_SIZE - 1)
216 typedef struct {
217 IOCanRWHandler *chr_can_read[MAX_MUX];
218 IOReadHandler *chr_read[MAX_MUX];
219 IOEventHandler *chr_event[MAX_MUX];
220 void *ext_opaque[MAX_MUX];
221 CharDriverState *drv;
222 int focus;
223 int mux_cnt;
224 int term_got_escape;
225 int max_size;
226 /* Intermediate input buffer allows to catch escape sequences even if the
227 currently active device is not accepting any input - but only until it
228 is full as well. */
229 unsigned char buffer[MAX_MUX][MUX_BUFFER_SIZE];
230 int prod[MAX_MUX];
231 int cons[MAX_MUX];
232 int timestamps;
233 int linestart;
234 int64_t timestamps_start;
235 } MuxDriver;
238 static int mux_chr_write(CharDriverState *chr, const uint8_t *buf, int len)
240 MuxDriver *d = chr->opaque;
241 int ret;
242 if (!d->timestamps) {
243 ret = d->drv->chr_write(d->drv, buf, len);
244 } else {
245 int i;
247 ret = 0;
248 for (i = 0; i < len; i++) {
249 if (d->linestart) {
250 char buf1[64];
251 int64_t ti;
252 int secs;
254 ti = qemu_get_clock(rt_clock);
255 if (d->timestamps_start == -1)
256 d->timestamps_start = ti;
257 ti -= d->timestamps_start;
258 secs = ti / 1000;
259 snprintf(buf1, sizeof(buf1),
260 "[%02d:%02d:%02d.%03d] ",
261 secs / 3600,
262 (secs / 60) % 60,
263 secs % 60,
264 (int)(ti % 1000));
265 d->drv->chr_write(d->drv, (uint8_t *)buf1, strlen(buf1));
266 d->linestart = 0;
268 ret += d->drv->chr_write(d->drv, buf+i, 1);
269 if (buf[i] == '\n') {
270 d->linestart = 1;
274 return ret;
277 static const char * const mux_help[] = {
278 "% h print this help\n\r",
279 "% x exit emulator\n\r",
280 "% s save disk data back to file (if -snapshot)\n\r",
281 "% t toggle console timestamps\n\r"
282 "% b send break (magic sysrq)\n\r",
283 "% c switch between console and monitor\n\r",
284 "% % sends %\n\r",
285 NULL
288 int term_escape_char = 0x01; /* ctrl-a is used for escape */
289 static void mux_print_help(CharDriverState *chr)
291 int i, j;
292 char ebuf[15] = "Escape-Char";
293 char cbuf[50] = "\n\r";
295 if (term_escape_char > 0 && term_escape_char < 26) {
296 snprintf(cbuf, sizeof(cbuf), "\n\r");
297 snprintf(ebuf, sizeof(ebuf), "C-%c", term_escape_char - 1 + 'a');
298 } else {
299 snprintf(cbuf, sizeof(cbuf),
300 "\n\rEscape-Char set to Ascii: 0x%02x\n\r\n\r",
301 term_escape_char);
303 chr->chr_write(chr, (uint8_t *)cbuf, strlen(cbuf));
304 for (i = 0; mux_help[i] != NULL; i++) {
305 for (j=0; mux_help[i][j] != '\0'; j++) {
306 if (mux_help[i][j] == '%')
307 chr->chr_write(chr, (uint8_t *)ebuf, strlen(ebuf));
308 else
309 chr->chr_write(chr, (uint8_t *)&mux_help[i][j], 1);
314 static void mux_chr_send_event(MuxDriver *d, int mux_nr, int event)
316 if (d->chr_event[mux_nr])
317 d->chr_event[mux_nr](d->ext_opaque[mux_nr], event);
320 static int mux_proc_byte(CharDriverState *chr, MuxDriver *d, int ch)
322 if (d->term_got_escape) {
323 d->term_got_escape = 0;
324 if (ch == term_escape_char)
325 goto send_char;
326 switch(ch) {
327 case '?':
328 case 'h':
329 mux_print_help(chr);
330 break;
331 case 'x':
333 const char *term = "QEMU: Terminated\n\r";
334 chr->chr_write(chr,(uint8_t *)term,strlen(term));
335 exit(0);
336 break;
338 case 's':
340 DriveInfo *dinfo;
341 QTAILQ_FOREACH(dinfo, &drives, next) {
342 bdrv_commit(dinfo->bdrv);
345 break;
346 case 'b':
347 qemu_chr_event(chr, CHR_EVENT_BREAK);
348 break;
349 case 'c':
350 /* Switch to the next registered device */
351 mux_chr_send_event(d, d->focus, CHR_EVENT_MUX_OUT);
352 d->focus++;
353 if (d->focus >= d->mux_cnt)
354 d->focus = 0;
355 mux_chr_send_event(d, d->focus, CHR_EVENT_MUX_IN);
356 break;
357 case 't':
358 d->timestamps = !d->timestamps;
359 d->timestamps_start = -1;
360 d->linestart = 0;
361 break;
363 } else if (ch == term_escape_char) {
364 d->term_got_escape = 1;
365 } else {
366 send_char:
367 return 1;
369 return 0;
372 static void mux_chr_accept_input(CharDriverState *chr)
374 MuxDriver *d = chr->opaque;
375 int m = d->focus;
377 while (d->prod[m] != d->cons[m] &&
378 d->chr_can_read[m] &&
379 d->chr_can_read[m](d->ext_opaque[m])) {
380 d->chr_read[m](d->ext_opaque[m],
381 &d->buffer[m][d->cons[m]++ & MUX_BUFFER_MASK], 1);
385 static int mux_chr_can_read(void *opaque)
387 CharDriverState *chr = opaque;
388 MuxDriver *d = chr->opaque;
389 int m = d->focus;
391 if ((d->prod[m] - d->cons[m]) < MUX_BUFFER_SIZE)
392 return 1;
393 if (d->chr_can_read[m])
394 return d->chr_can_read[m](d->ext_opaque[m]);
395 return 0;
398 static void mux_chr_read(void *opaque, const uint8_t *buf, int size)
400 CharDriverState *chr = opaque;
401 MuxDriver *d = chr->opaque;
402 int m = d->focus;
403 int i;
405 mux_chr_accept_input (opaque);
407 for(i = 0; i < size; i++)
408 if (mux_proc_byte(chr, d, buf[i])) {
409 if (d->prod[m] == d->cons[m] &&
410 d->chr_can_read[m] &&
411 d->chr_can_read[m](d->ext_opaque[m]))
412 d->chr_read[m](d->ext_opaque[m], &buf[i], 1);
413 else
414 d->buffer[m][d->prod[m]++ & MUX_BUFFER_MASK] = buf[i];
418 static void mux_chr_event(void *opaque, int event)
420 CharDriverState *chr = opaque;
421 MuxDriver *d = chr->opaque;
422 int i;
424 /* Send the event to all registered listeners */
425 for (i = 0; i < d->mux_cnt; i++)
426 mux_chr_send_event(d, i, event);
429 static void mux_chr_update_read_handler(CharDriverState *chr)
431 MuxDriver *d = chr->opaque;
433 if (d->mux_cnt >= MAX_MUX) {
434 fprintf(stderr, "Cannot add I/O handlers, MUX array is full\n");
435 return;
437 d->ext_opaque[d->mux_cnt] = chr->handler_opaque;
438 d->chr_can_read[d->mux_cnt] = chr->chr_can_read;
439 d->chr_read[d->mux_cnt] = chr->chr_read;
440 d->chr_event[d->mux_cnt] = chr->chr_event;
441 /* Fix up the real driver with mux routines */
442 if (d->mux_cnt == 0) {
443 qemu_chr_add_handlers(d->drv, mux_chr_can_read, mux_chr_read,
444 mux_chr_event, chr);
446 if (d->focus != -1) {
447 mux_chr_send_event(d, d->focus, CHR_EVENT_MUX_OUT);
449 d->focus = d->mux_cnt;
450 d->mux_cnt++;
451 mux_chr_send_event(d, d->focus, CHR_EVENT_MUX_IN);
454 static CharDriverState *qemu_chr_open_mux(CharDriverState *drv)
456 CharDriverState *chr;
457 MuxDriver *d;
459 chr = qemu_mallocz(sizeof(CharDriverState));
460 d = qemu_mallocz(sizeof(MuxDriver));
462 chr->opaque = d;
463 d->drv = drv;
464 d->focus = -1;
465 chr->chr_write = mux_chr_write;
466 chr->chr_update_read_handler = mux_chr_update_read_handler;
467 chr->chr_accept_input = mux_chr_accept_input;
468 return chr;
472 #ifdef _WIN32
473 int send_all(int fd, const void *buf, int len1)
475 int ret, len;
477 len = len1;
478 while (len > 0) {
479 ret = send(fd, buf, len, 0);
480 if (ret < 0) {
481 errno = WSAGetLastError();
482 if (errno != WSAEWOULDBLOCK) {
483 return -1;
485 } else if (ret == 0) {
486 break;
487 } else {
488 buf += ret;
489 len -= ret;
492 return len1 - len;
495 #else
497 static int unix_write(int fd, const uint8_t *buf, int len1)
499 int ret, len;
501 len = len1;
502 while (len > 0) {
503 ret = write(fd, buf, len);
504 if (ret < 0) {
505 if (errno != EINTR && errno != EAGAIN)
506 return -1;
507 } else if (ret == 0) {
508 break;
509 } else {
510 buf += ret;
511 len -= ret;
514 return len1 - len;
517 int send_all(int fd, const void *buf, int len1)
519 return unix_write(fd, buf, len1);
521 #endif /* !_WIN32 */
523 #ifndef _WIN32
525 typedef struct {
526 int fd_in, fd_out;
527 int max_size;
528 } FDCharDriver;
530 #define STDIO_MAX_CLIENTS 1
531 static int stdio_nb_clients = 0;
533 static int fd_chr_write(CharDriverState *chr, const uint8_t *buf, int len)
535 FDCharDriver *s = chr->opaque;
536 return send_all(s->fd_out, buf, len);
539 static int fd_chr_read_poll(void *opaque)
541 CharDriverState *chr = opaque;
542 FDCharDriver *s = chr->opaque;
544 s->max_size = qemu_chr_can_read(chr);
545 return s->max_size;
548 static void fd_chr_read(void *opaque)
550 CharDriverState *chr = opaque;
551 FDCharDriver *s = chr->opaque;
552 int size, len;
553 uint8_t buf[READ_BUF_LEN];
555 len = sizeof(buf);
556 if (len > s->max_size)
557 len = s->max_size;
558 if (len == 0)
559 return;
560 size = read(s->fd_in, buf, len);
561 if (size == 0) {
562 /* FD has been closed. Remove it from the active list. */
563 qemu_set_fd_handler2(s->fd_in, NULL, NULL, NULL, NULL);
564 qemu_chr_event(chr, CHR_EVENT_CLOSED);
565 return;
567 if (size > 0) {
568 qemu_chr_read(chr, buf, size);
572 static void fd_chr_update_read_handler(CharDriverState *chr)
574 FDCharDriver *s = chr->opaque;
576 if (s->fd_in >= 0) {
577 if (display_type == DT_NOGRAPHIC && s->fd_in == 0) {
578 } else {
579 qemu_set_fd_handler2(s->fd_in, fd_chr_read_poll,
580 fd_chr_read, NULL, chr);
585 static void fd_chr_close(struct CharDriverState *chr)
587 FDCharDriver *s = chr->opaque;
589 if (s->fd_in >= 0) {
590 if (display_type == DT_NOGRAPHIC && s->fd_in == 0) {
591 } else {
592 qemu_set_fd_handler2(s->fd_in, NULL, NULL, NULL, NULL);
596 qemu_free(s);
597 qemu_chr_event(chr, CHR_EVENT_CLOSED);
600 /* open a character device to a unix fd */
601 static CharDriverState *qemu_chr_open_fd(int fd_in, int fd_out)
603 CharDriverState *chr;
604 FDCharDriver *s;
606 chr = qemu_mallocz(sizeof(CharDriverState));
607 s = qemu_mallocz(sizeof(FDCharDriver));
608 s->fd_in = fd_in;
609 s->fd_out = fd_out;
610 chr->opaque = s;
611 chr->chr_write = fd_chr_write;
612 chr->chr_update_read_handler = fd_chr_update_read_handler;
613 chr->chr_close = fd_chr_close;
615 qemu_chr_generic_open(chr);
617 return chr;
620 static CharDriverState *qemu_chr_open_file_out(QemuOpts *opts)
622 int fd_out;
624 TFR(fd_out = qemu_open(qemu_opt_get(opts, "path"),
625 O_WRONLY | O_TRUNC | O_CREAT | O_BINARY, 0666));
626 if (fd_out < 0)
627 return NULL;
628 return qemu_chr_open_fd(-1, fd_out);
631 static CharDriverState *qemu_chr_open_pipe(QemuOpts *opts)
633 int fd_in, fd_out;
634 char filename_in[256], filename_out[256];
635 const char *filename = qemu_opt_get(opts, "path");
637 if (filename == NULL) {
638 fprintf(stderr, "chardev: pipe: no filename given\n");
639 return NULL;
642 snprintf(filename_in, 256, "%s.in", filename);
643 snprintf(filename_out, 256, "%s.out", filename);
644 TFR(fd_in = qemu_open(filename_in, O_RDWR | O_BINARY));
645 TFR(fd_out = qemu_open(filename_out, O_RDWR | O_BINARY));
646 if (fd_in < 0 || fd_out < 0) {
647 if (fd_in >= 0)
648 close(fd_in);
649 if (fd_out >= 0)
650 close(fd_out);
651 TFR(fd_in = fd_out = open(filename, O_RDWR | O_BINARY));
652 if (fd_in < 0)
653 return NULL;
655 return qemu_chr_open_fd(fd_in, fd_out);
659 /* for STDIO, we handle the case where several clients use it
660 (nographic mode) */
662 #define TERM_FIFO_MAX_SIZE 1
664 static uint8_t term_fifo[TERM_FIFO_MAX_SIZE];
665 static int term_fifo_size;
667 static int stdio_read_poll(void *opaque)
669 CharDriverState *chr = opaque;
671 /* try to flush the queue if needed */
672 if (term_fifo_size != 0 && qemu_chr_can_read(chr) > 0) {
673 qemu_chr_read(chr, term_fifo, 1);
674 term_fifo_size = 0;
676 /* see if we can absorb more chars */
677 if (term_fifo_size == 0)
678 return 1;
679 else
680 return 0;
683 static void stdio_read(void *opaque)
685 int size;
686 uint8_t buf[1];
687 CharDriverState *chr = opaque;
689 size = read(0, buf, 1);
690 if (size == 0) {
691 /* stdin has been closed. Remove it from the active list. */
692 qemu_set_fd_handler2(0, NULL, NULL, NULL, NULL);
693 qemu_chr_event(chr, CHR_EVENT_CLOSED);
694 return;
696 if (size > 0) {
697 if (qemu_chr_can_read(chr) > 0) {
698 qemu_chr_read(chr, buf, 1);
699 } else if (term_fifo_size == 0) {
700 term_fifo[term_fifo_size++] = buf[0];
705 /* init terminal so that we can grab keys */
706 static struct termios oldtty;
707 static int old_fd0_flags;
708 static int term_atexit_done;
710 static void term_exit(void)
712 tcsetattr (0, TCSANOW, &oldtty);
713 fcntl(0, F_SETFL, old_fd0_flags);
716 static void term_init(QemuOpts *opts)
718 struct termios tty;
720 tcgetattr (0, &tty);
721 oldtty = tty;
722 old_fd0_flags = fcntl(0, F_GETFL);
724 tty.c_iflag &= ~(IGNBRK|BRKINT|PARMRK|ISTRIP
725 |INLCR|IGNCR|ICRNL|IXON);
726 tty.c_oflag |= OPOST;
727 tty.c_lflag &= ~(ECHO|ECHONL|ICANON|IEXTEN);
728 /* if graphical mode, we allow Ctrl-C handling */
729 if (!qemu_opt_get_bool(opts, "signal", display_type != DT_NOGRAPHIC))
730 tty.c_lflag &= ~ISIG;
731 tty.c_cflag &= ~(CSIZE|PARENB);
732 tty.c_cflag |= CS8;
733 tty.c_cc[VMIN] = 1;
734 tty.c_cc[VTIME] = 0;
736 tcsetattr (0, TCSANOW, &tty);
738 if (!term_atexit_done++)
739 atexit(term_exit);
741 fcntl(0, F_SETFL, O_NONBLOCK);
744 static void qemu_chr_close_stdio(struct CharDriverState *chr)
746 term_exit();
747 stdio_nb_clients--;
748 qemu_set_fd_handler2(0, NULL, NULL, NULL, NULL);
749 fd_chr_close(chr);
752 static CharDriverState *qemu_chr_open_stdio(QemuOpts *opts)
754 CharDriverState *chr;
756 if (stdio_nb_clients >= STDIO_MAX_CLIENTS)
757 return NULL;
758 chr = qemu_chr_open_fd(0, 1);
759 chr->chr_close = qemu_chr_close_stdio;
760 qemu_set_fd_handler2(0, stdio_read_poll, stdio_read, NULL, chr);
761 stdio_nb_clients++;
762 term_init(opts);
764 return chr;
767 #ifdef __sun__
768 /* Once Solaris has openpty(), this is going to be removed. */
769 static int openpty(int *amaster, int *aslave, char *name,
770 struct termios *termp, struct winsize *winp)
772 const char *slave;
773 int mfd = -1, sfd = -1;
775 *amaster = *aslave = -1;
777 mfd = open("/dev/ptmx", O_RDWR | O_NOCTTY);
778 if (mfd < 0)
779 goto err;
781 if (grantpt(mfd) == -1 || unlockpt(mfd) == -1)
782 goto err;
784 if ((slave = ptsname(mfd)) == NULL)
785 goto err;
787 if ((sfd = open(slave, O_RDONLY | O_NOCTTY)) == -1)
788 goto err;
790 if (ioctl(sfd, I_PUSH, "ptem") == -1 ||
791 (termp != NULL && tcgetattr(sfd, termp) < 0))
792 goto err;
794 if (amaster)
795 *amaster = mfd;
796 if (aslave)
797 *aslave = sfd;
798 if (winp)
799 ioctl(sfd, TIOCSWINSZ, winp);
801 return 0;
803 err:
804 if (sfd != -1)
805 close(sfd);
806 close(mfd);
807 return -1;
810 static void cfmakeraw (struct termios *termios_p)
812 termios_p->c_iflag &=
813 ~(IGNBRK|BRKINT|PARMRK|ISTRIP|INLCR|IGNCR|ICRNL|IXON);
814 termios_p->c_oflag &= ~OPOST;
815 termios_p->c_lflag &= ~(ECHO|ECHONL|ICANON|ISIG|IEXTEN);
816 termios_p->c_cflag &= ~(CSIZE|PARENB);
817 termios_p->c_cflag |= CS8;
819 termios_p->c_cc[VMIN] = 0;
820 termios_p->c_cc[VTIME] = 0;
822 #endif
824 #if defined(__linux__) || defined(__sun__) || defined(__FreeBSD__) \
825 || defined(__NetBSD__) || defined(__OpenBSD__) || defined(__DragonFly__) \
826 || defined(__GLIBC__)
828 typedef struct {
829 int fd;
830 int connected;
831 int polling;
832 int read_bytes;
833 QEMUTimer *timer;
834 } PtyCharDriver;
836 static void pty_chr_update_read_handler(CharDriverState *chr);
837 static void pty_chr_state(CharDriverState *chr, int connected);
839 static int pty_chr_write(CharDriverState *chr, const uint8_t *buf, int len)
841 PtyCharDriver *s = chr->opaque;
843 if (!s->connected) {
844 /* guest sends data, check for (re-)connect */
845 pty_chr_update_read_handler(chr);
846 return 0;
848 return send_all(s->fd, buf, len);
851 static int pty_chr_read_poll(void *opaque)
853 CharDriverState *chr = opaque;
854 PtyCharDriver *s = chr->opaque;
856 s->read_bytes = qemu_chr_can_read(chr);
857 return s->read_bytes;
860 static void pty_chr_read(void *opaque)
862 CharDriverState *chr = opaque;
863 PtyCharDriver *s = chr->opaque;
864 int size, len;
865 uint8_t buf[READ_BUF_LEN];
867 len = sizeof(buf);
868 if (len > s->read_bytes)
869 len = s->read_bytes;
870 if (len == 0)
871 return;
872 size = read(s->fd, buf, len);
873 if ((size == -1 && errno == EIO) ||
874 (size == 0)) {
875 pty_chr_state(chr, 0);
876 return;
878 if (size > 0) {
879 pty_chr_state(chr, 1);
880 qemu_chr_read(chr, buf, size);
884 static void pty_chr_update_read_handler(CharDriverState *chr)
886 PtyCharDriver *s = chr->opaque;
888 qemu_set_fd_handler2(s->fd, pty_chr_read_poll,
889 pty_chr_read, NULL, chr);
890 s->polling = 1;
892 * Short timeout here: just need wait long enougth that qemu makes
893 * it through the poll loop once. When reconnected we want a
894 * short timeout so we notice it almost instantly. Otherwise
895 * read() gives us -EIO instantly, making pty_chr_state() reset the
896 * timeout to the normal (much longer) poll interval before the
897 * timer triggers.
899 qemu_mod_timer(s->timer, qemu_get_clock(rt_clock) + 10);
902 static void pty_chr_state(CharDriverState *chr, int connected)
904 PtyCharDriver *s = chr->opaque;
906 if (!connected) {
907 qemu_set_fd_handler2(s->fd, NULL, NULL, NULL, NULL);
908 s->connected = 0;
909 s->polling = 0;
910 /* (re-)connect poll interval for idle guests: once per second.
911 * We check more frequently in case the guests sends data to
912 * the virtual device linked to our pty. */
913 qemu_mod_timer(s->timer, qemu_get_clock(rt_clock) + 1000);
914 } else {
915 if (!s->connected)
916 qemu_chr_generic_open(chr);
917 s->connected = 1;
921 static void pty_chr_timer(void *opaque)
923 struct CharDriverState *chr = opaque;
924 PtyCharDriver *s = chr->opaque;
926 if (s->connected)
927 return;
928 if (s->polling) {
929 /* If we arrive here without polling being cleared due
930 * read returning -EIO, then we are (re-)connected */
931 pty_chr_state(chr, 1);
932 return;
935 /* Next poll ... */
936 pty_chr_update_read_handler(chr);
939 static void pty_chr_close(struct CharDriverState *chr)
941 PtyCharDriver *s = chr->opaque;
943 qemu_set_fd_handler2(s->fd, NULL, NULL, NULL, NULL);
944 close(s->fd);
945 qemu_del_timer(s->timer);
946 qemu_free_timer(s->timer);
947 qemu_free(s);
948 qemu_chr_event(chr, CHR_EVENT_CLOSED);
951 static CharDriverState *qemu_chr_open_pty(QemuOpts *opts)
953 CharDriverState *chr;
954 PtyCharDriver *s;
955 struct termios tty;
956 int slave_fd, len;
957 #if defined(__OpenBSD__) || defined(__DragonFly__)
958 char pty_name[PATH_MAX];
959 #define q_ptsname(x) pty_name
960 #else
961 char *pty_name = NULL;
962 #define q_ptsname(x) ptsname(x)
963 #endif
965 chr = qemu_mallocz(sizeof(CharDriverState));
966 s = qemu_mallocz(sizeof(PtyCharDriver));
968 if (openpty(&s->fd, &slave_fd, pty_name, NULL, NULL) < 0) {
969 return NULL;
972 /* Set raw attributes on the pty. */
973 tcgetattr(slave_fd, &tty);
974 cfmakeraw(&tty);
975 tcsetattr(slave_fd, TCSAFLUSH, &tty);
976 close(slave_fd);
978 len = strlen(q_ptsname(s->fd)) + 5;
979 chr->filename = qemu_malloc(len);
980 snprintf(chr->filename, len, "pty:%s", q_ptsname(s->fd));
981 qemu_opt_set(opts, "path", q_ptsname(s->fd));
982 fprintf(stderr, "char device redirected to %s\n", q_ptsname(s->fd));
984 chr->opaque = s;
985 chr->chr_write = pty_chr_write;
986 chr->chr_update_read_handler = pty_chr_update_read_handler;
987 chr->chr_close = pty_chr_close;
989 s->timer = qemu_new_timer(rt_clock, pty_chr_timer, chr);
991 return chr;
994 static void tty_serial_init(int fd, int speed,
995 int parity, int data_bits, int stop_bits)
997 struct termios tty;
998 speed_t spd;
1000 #if 0
1001 printf("tty_serial_init: speed=%d parity=%c data=%d stop=%d\n",
1002 speed, parity, data_bits, stop_bits);
1003 #endif
1004 tcgetattr (fd, &tty);
1006 #define check_speed(val) if (speed <= val) { spd = B##val; break; }
1007 speed = speed * 10 / 11;
1008 do {
1009 check_speed(50);
1010 check_speed(75);
1011 check_speed(110);
1012 check_speed(134);
1013 check_speed(150);
1014 check_speed(200);
1015 check_speed(300);
1016 check_speed(600);
1017 check_speed(1200);
1018 check_speed(1800);
1019 check_speed(2400);
1020 check_speed(4800);
1021 check_speed(9600);
1022 check_speed(19200);
1023 check_speed(38400);
1024 /* Non-Posix values follow. They may be unsupported on some systems. */
1025 check_speed(57600);
1026 check_speed(115200);
1027 #ifdef B230400
1028 check_speed(230400);
1029 #endif
1030 #ifdef B460800
1031 check_speed(460800);
1032 #endif
1033 #ifdef B500000
1034 check_speed(500000);
1035 #endif
1036 #ifdef B576000
1037 check_speed(576000);
1038 #endif
1039 #ifdef B921600
1040 check_speed(921600);
1041 #endif
1042 #ifdef B1000000
1043 check_speed(1000000);
1044 #endif
1045 #ifdef B1152000
1046 check_speed(1152000);
1047 #endif
1048 #ifdef B1500000
1049 check_speed(1500000);
1050 #endif
1051 #ifdef B2000000
1052 check_speed(2000000);
1053 #endif
1054 #ifdef B2500000
1055 check_speed(2500000);
1056 #endif
1057 #ifdef B3000000
1058 check_speed(3000000);
1059 #endif
1060 #ifdef B3500000
1061 check_speed(3500000);
1062 #endif
1063 #ifdef B4000000
1064 check_speed(4000000);
1065 #endif
1066 spd = B115200;
1067 } while (0);
1069 cfsetispeed(&tty, spd);
1070 cfsetospeed(&tty, spd);
1072 tty.c_iflag &= ~(IGNBRK|BRKINT|PARMRK|ISTRIP
1073 |INLCR|IGNCR|ICRNL|IXON);
1074 tty.c_oflag |= OPOST;
1075 tty.c_lflag &= ~(ECHO|ECHONL|ICANON|IEXTEN|ISIG);
1076 tty.c_cflag &= ~(CSIZE|PARENB|PARODD|CRTSCTS|CSTOPB);
1077 switch(data_bits) {
1078 default:
1079 case 8:
1080 tty.c_cflag |= CS8;
1081 break;
1082 case 7:
1083 tty.c_cflag |= CS7;
1084 break;
1085 case 6:
1086 tty.c_cflag |= CS6;
1087 break;
1088 case 5:
1089 tty.c_cflag |= CS5;
1090 break;
1092 switch(parity) {
1093 default:
1094 case 'N':
1095 break;
1096 case 'E':
1097 tty.c_cflag |= PARENB;
1098 break;
1099 case 'O':
1100 tty.c_cflag |= PARENB | PARODD;
1101 break;
1103 if (stop_bits == 2)
1104 tty.c_cflag |= CSTOPB;
1106 tcsetattr (fd, TCSANOW, &tty);
1109 static int tty_serial_ioctl(CharDriverState *chr, int cmd, void *arg)
1111 FDCharDriver *s = chr->opaque;
1113 switch(cmd) {
1114 case CHR_IOCTL_SERIAL_SET_PARAMS:
1116 QEMUSerialSetParams *ssp = arg;
1117 tty_serial_init(s->fd_in, ssp->speed, ssp->parity,
1118 ssp->data_bits, ssp->stop_bits);
1120 break;
1121 case CHR_IOCTL_SERIAL_SET_BREAK:
1123 int enable = *(int *)arg;
1124 if (enable)
1125 tcsendbreak(s->fd_in, 1);
1127 break;
1128 case CHR_IOCTL_SERIAL_GET_TIOCM:
1130 int sarg = 0;
1131 int *targ = (int *)arg;
1132 ioctl(s->fd_in, TIOCMGET, &sarg);
1133 *targ = 0;
1134 if (sarg & TIOCM_CTS)
1135 *targ |= CHR_TIOCM_CTS;
1136 if (sarg & TIOCM_CAR)
1137 *targ |= CHR_TIOCM_CAR;
1138 if (sarg & TIOCM_DSR)
1139 *targ |= CHR_TIOCM_DSR;
1140 if (sarg & TIOCM_RI)
1141 *targ |= CHR_TIOCM_RI;
1142 if (sarg & TIOCM_DTR)
1143 *targ |= CHR_TIOCM_DTR;
1144 if (sarg & TIOCM_RTS)
1145 *targ |= CHR_TIOCM_RTS;
1147 break;
1148 case CHR_IOCTL_SERIAL_SET_TIOCM:
1150 int sarg = *(int *)arg;
1151 int targ = 0;
1152 ioctl(s->fd_in, TIOCMGET, &targ);
1153 targ &= ~(CHR_TIOCM_CTS | CHR_TIOCM_CAR | CHR_TIOCM_DSR
1154 | CHR_TIOCM_RI | CHR_TIOCM_DTR | CHR_TIOCM_RTS);
1155 if (sarg & CHR_TIOCM_CTS)
1156 targ |= TIOCM_CTS;
1157 if (sarg & CHR_TIOCM_CAR)
1158 targ |= TIOCM_CAR;
1159 if (sarg & CHR_TIOCM_DSR)
1160 targ |= TIOCM_DSR;
1161 if (sarg & CHR_TIOCM_RI)
1162 targ |= TIOCM_RI;
1163 if (sarg & CHR_TIOCM_DTR)
1164 targ |= TIOCM_DTR;
1165 if (sarg & CHR_TIOCM_RTS)
1166 targ |= TIOCM_RTS;
1167 ioctl(s->fd_in, TIOCMSET, &targ);
1169 break;
1170 default:
1171 return -ENOTSUP;
1173 return 0;
1176 static void qemu_chr_close_tty(CharDriverState *chr)
1178 FDCharDriver *s = chr->opaque;
1179 int fd = -1;
1181 if (s) {
1182 fd = s->fd_in;
1185 fd_chr_close(chr);
1187 if (fd >= 0) {
1188 close(fd);
1192 static CharDriverState *qemu_chr_open_tty(QemuOpts *opts)
1194 const char *filename = qemu_opt_get(opts, "path");
1195 CharDriverState *chr;
1196 int fd;
1198 TFR(fd = open(filename, O_RDWR | O_NONBLOCK));
1199 if (fd < 0) {
1200 return NULL;
1202 tty_serial_init(fd, 115200, 'N', 8, 1);
1203 chr = qemu_chr_open_fd(fd, fd);
1204 if (!chr) {
1205 close(fd);
1206 return NULL;
1208 chr->chr_ioctl = tty_serial_ioctl;
1209 chr->chr_close = qemu_chr_close_tty;
1210 return chr;
1212 #else /* ! __linux__ && ! __sun__ */
1213 static CharDriverState *qemu_chr_open_pty(void)
1215 return NULL;
1217 #endif /* __linux__ || __sun__ */
1219 #if defined(__linux__)
1220 typedef struct {
1221 int fd;
1222 int mode;
1223 } ParallelCharDriver;
1225 static int pp_hw_mode(ParallelCharDriver *s, uint16_t mode)
1227 if (s->mode != mode) {
1228 int m = mode;
1229 if (ioctl(s->fd, PPSETMODE, &m) < 0)
1230 return 0;
1231 s->mode = mode;
1233 return 1;
1236 static int pp_ioctl(CharDriverState *chr, int cmd, void *arg)
1238 ParallelCharDriver *drv = chr->opaque;
1239 int fd = drv->fd;
1240 uint8_t b;
1242 switch(cmd) {
1243 case CHR_IOCTL_PP_READ_DATA:
1244 if (ioctl(fd, PPRDATA, &b) < 0)
1245 return -ENOTSUP;
1246 *(uint8_t *)arg = b;
1247 break;
1248 case CHR_IOCTL_PP_WRITE_DATA:
1249 b = *(uint8_t *)arg;
1250 if (ioctl(fd, PPWDATA, &b) < 0)
1251 return -ENOTSUP;
1252 break;
1253 case CHR_IOCTL_PP_READ_CONTROL:
1254 if (ioctl(fd, PPRCONTROL, &b) < 0)
1255 return -ENOTSUP;
1256 /* Linux gives only the lowest bits, and no way to know data
1257 direction! For better compatibility set the fixed upper
1258 bits. */
1259 *(uint8_t *)arg = b | 0xc0;
1260 break;
1261 case CHR_IOCTL_PP_WRITE_CONTROL:
1262 b = *(uint8_t *)arg;
1263 if (ioctl(fd, PPWCONTROL, &b) < 0)
1264 return -ENOTSUP;
1265 break;
1266 case CHR_IOCTL_PP_READ_STATUS:
1267 if (ioctl(fd, PPRSTATUS, &b) < 0)
1268 return -ENOTSUP;
1269 *(uint8_t *)arg = b;
1270 break;
1271 case CHR_IOCTL_PP_DATA_DIR:
1272 if (ioctl(fd, PPDATADIR, (int *)arg) < 0)
1273 return -ENOTSUP;
1274 break;
1275 case CHR_IOCTL_PP_EPP_READ_ADDR:
1276 if (pp_hw_mode(drv, IEEE1284_MODE_EPP|IEEE1284_ADDR)) {
1277 struct ParallelIOArg *parg = arg;
1278 int n = read(fd, parg->buffer, parg->count);
1279 if (n != parg->count) {
1280 return -EIO;
1283 break;
1284 case CHR_IOCTL_PP_EPP_READ:
1285 if (pp_hw_mode(drv, IEEE1284_MODE_EPP)) {
1286 struct ParallelIOArg *parg = arg;
1287 int n = read(fd, parg->buffer, parg->count);
1288 if (n != parg->count) {
1289 return -EIO;
1292 break;
1293 case CHR_IOCTL_PP_EPP_WRITE_ADDR:
1294 if (pp_hw_mode(drv, IEEE1284_MODE_EPP|IEEE1284_ADDR)) {
1295 struct ParallelIOArg *parg = arg;
1296 int n = write(fd, parg->buffer, parg->count);
1297 if (n != parg->count) {
1298 return -EIO;
1301 break;
1302 case CHR_IOCTL_PP_EPP_WRITE:
1303 if (pp_hw_mode(drv, IEEE1284_MODE_EPP)) {
1304 struct ParallelIOArg *parg = arg;
1305 int n = write(fd, parg->buffer, parg->count);
1306 if (n != parg->count) {
1307 return -EIO;
1310 break;
1311 default:
1312 return -ENOTSUP;
1314 return 0;
1317 static void pp_close(CharDriverState *chr)
1319 ParallelCharDriver *drv = chr->opaque;
1320 int fd = drv->fd;
1322 pp_hw_mode(drv, IEEE1284_MODE_COMPAT);
1323 ioctl(fd, PPRELEASE);
1324 close(fd);
1325 qemu_free(drv);
1326 qemu_chr_event(chr, CHR_EVENT_CLOSED);
1329 static CharDriverState *qemu_chr_open_pp(QemuOpts *opts)
1331 const char *filename = qemu_opt_get(opts, "path");
1332 CharDriverState *chr;
1333 ParallelCharDriver *drv;
1334 int fd;
1336 TFR(fd = open(filename, O_RDWR));
1337 if (fd < 0)
1338 return NULL;
1340 if (ioctl(fd, PPCLAIM) < 0) {
1341 close(fd);
1342 return NULL;
1345 drv = qemu_mallocz(sizeof(ParallelCharDriver));
1346 drv->fd = fd;
1347 drv->mode = IEEE1284_MODE_COMPAT;
1349 chr = qemu_mallocz(sizeof(CharDriverState));
1350 chr->chr_write = null_chr_write;
1351 chr->chr_ioctl = pp_ioctl;
1352 chr->chr_close = pp_close;
1353 chr->opaque = drv;
1355 qemu_chr_generic_open(chr);
1357 return chr;
1359 #endif /* __linux__ */
1361 #if defined(__FreeBSD__) || defined(__FreeBSD_kernel__) || defined(__DragonFly__)
1362 static int pp_ioctl(CharDriverState *chr, int cmd, void *arg)
1364 int fd = (int)chr->opaque;
1365 uint8_t b;
1367 switch(cmd) {
1368 case CHR_IOCTL_PP_READ_DATA:
1369 if (ioctl(fd, PPIGDATA, &b) < 0)
1370 return -ENOTSUP;
1371 *(uint8_t *)arg = b;
1372 break;
1373 case CHR_IOCTL_PP_WRITE_DATA:
1374 b = *(uint8_t *)arg;
1375 if (ioctl(fd, PPISDATA, &b) < 0)
1376 return -ENOTSUP;
1377 break;
1378 case CHR_IOCTL_PP_READ_CONTROL:
1379 if (ioctl(fd, PPIGCTRL, &b) < 0)
1380 return -ENOTSUP;
1381 *(uint8_t *)arg = b;
1382 break;
1383 case CHR_IOCTL_PP_WRITE_CONTROL:
1384 b = *(uint8_t *)arg;
1385 if (ioctl(fd, PPISCTRL, &b) < 0)
1386 return -ENOTSUP;
1387 break;
1388 case CHR_IOCTL_PP_READ_STATUS:
1389 if (ioctl(fd, PPIGSTATUS, &b) < 0)
1390 return -ENOTSUP;
1391 *(uint8_t *)arg = b;
1392 break;
1393 default:
1394 return -ENOTSUP;
1396 return 0;
1399 static CharDriverState *qemu_chr_open_pp(QemuOpts *opts)
1401 const char *filename = qemu_opt_get(opts, "path");
1402 CharDriverState *chr;
1403 int fd;
1405 fd = open(filename, O_RDWR);
1406 if (fd < 0)
1407 return NULL;
1409 chr = qemu_mallocz(sizeof(CharDriverState));
1410 chr->opaque = (void *)fd;
1411 chr->chr_write = null_chr_write;
1412 chr->chr_ioctl = pp_ioctl;
1413 return chr;
1415 #endif
1417 #else /* _WIN32 */
1419 typedef struct {
1420 int max_size;
1421 HANDLE hcom, hrecv, hsend;
1422 OVERLAPPED orecv, osend;
1423 BOOL fpipe;
1424 DWORD len;
1425 } WinCharState;
1427 #define NSENDBUF 2048
1428 #define NRECVBUF 2048
1429 #define MAXCONNECT 1
1430 #define NTIMEOUT 5000
1432 static int win_chr_poll(void *opaque);
1433 static int win_chr_pipe_poll(void *opaque);
1435 static void win_chr_close(CharDriverState *chr)
1437 WinCharState *s = chr->opaque;
1439 if (s->hsend) {
1440 CloseHandle(s->hsend);
1441 s->hsend = NULL;
1443 if (s->hrecv) {
1444 CloseHandle(s->hrecv);
1445 s->hrecv = NULL;
1447 if (s->hcom) {
1448 CloseHandle(s->hcom);
1449 s->hcom = NULL;
1451 if (s->fpipe)
1452 qemu_del_polling_cb(win_chr_pipe_poll, chr);
1453 else
1454 qemu_del_polling_cb(win_chr_poll, chr);
1456 qemu_chr_event(chr, CHR_EVENT_CLOSED);
1459 static int win_chr_init(CharDriverState *chr, const char *filename)
1461 WinCharState *s = chr->opaque;
1462 COMMCONFIG comcfg;
1463 COMMTIMEOUTS cto = { 0, 0, 0, 0, 0};
1464 COMSTAT comstat;
1465 DWORD size;
1466 DWORD err;
1468 s->hsend = CreateEvent(NULL, TRUE, FALSE, NULL);
1469 if (!s->hsend) {
1470 fprintf(stderr, "Failed CreateEvent\n");
1471 goto fail;
1473 s->hrecv = CreateEvent(NULL, TRUE, FALSE, NULL);
1474 if (!s->hrecv) {
1475 fprintf(stderr, "Failed CreateEvent\n");
1476 goto fail;
1479 s->hcom = CreateFile(filename, GENERIC_READ|GENERIC_WRITE, 0, NULL,
1480 OPEN_EXISTING, FILE_FLAG_OVERLAPPED, 0);
1481 if (s->hcom == INVALID_HANDLE_VALUE) {
1482 fprintf(stderr, "Failed CreateFile (%lu)\n", GetLastError());
1483 s->hcom = NULL;
1484 goto fail;
1487 if (!SetupComm(s->hcom, NRECVBUF, NSENDBUF)) {
1488 fprintf(stderr, "Failed SetupComm\n");
1489 goto fail;
1492 ZeroMemory(&comcfg, sizeof(COMMCONFIG));
1493 size = sizeof(COMMCONFIG);
1494 GetDefaultCommConfig(filename, &comcfg, &size);
1495 comcfg.dcb.DCBlength = sizeof(DCB);
1496 CommConfigDialog(filename, NULL, &comcfg);
1498 if (!SetCommState(s->hcom, &comcfg.dcb)) {
1499 fprintf(stderr, "Failed SetCommState\n");
1500 goto fail;
1503 if (!SetCommMask(s->hcom, EV_ERR)) {
1504 fprintf(stderr, "Failed SetCommMask\n");
1505 goto fail;
1508 cto.ReadIntervalTimeout = MAXDWORD;
1509 if (!SetCommTimeouts(s->hcom, &cto)) {
1510 fprintf(stderr, "Failed SetCommTimeouts\n");
1511 goto fail;
1514 if (!ClearCommError(s->hcom, &err, &comstat)) {
1515 fprintf(stderr, "Failed ClearCommError\n");
1516 goto fail;
1518 qemu_add_polling_cb(win_chr_poll, chr);
1519 return 0;
1521 fail:
1522 win_chr_close(chr);
1523 return -1;
1526 static int win_chr_write(CharDriverState *chr, const uint8_t *buf, int len1)
1528 WinCharState *s = chr->opaque;
1529 DWORD len, ret, size, err;
1531 len = len1;
1532 ZeroMemory(&s->osend, sizeof(s->osend));
1533 s->osend.hEvent = s->hsend;
1534 while (len > 0) {
1535 if (s->hsend)
1536 ret = WriteFile(s->hcom, buf, len, &size, &s->osend);
1537 else
1538 ret = WriteFile(s->hcom, buf, len, &size, NULL);
1539 if (!ret) {
1540 err = GetLastError();
1541 if (err == ERROR_IO_PENDING) {
1542 ret = GetOverlappedResult(s->hcom, &s->osend, &size, TRUE);
1543 if (ret) {
1544 buf += size;
1545 len -= size;
1546 } else {
1547 break;
1549 } else {
1550 break;
1552 } else {
1553 buf += size;
1554 len -= size;
1557 return len1 - len;
1560 static int win_chr_read_poll(CharDriverState *chr)
1562 WinCharState *s = chr->opaque;
1564 s->max_size = qemu_chr_can_read(chr);
1565 return s->max_size;
1568 static void win_chr_readfile(CharDriverState *chr)
1570 WinCharState *s = chr->opaque;
1571 int ret, err;
1572 uint8_t buf[READ_BUF_LEN];
1573 DWORD size;
1575 ZeroMemory(&s->orecv, sizeof(s->orecv));
1576 s->orecv.hEvent = s->hrecv;
1577 ret = ReadFile(s->hcom, buf, s->len, &size, &s->orecv);
1578 if (!ret) {
1579 err = GetLastError();
1580 if (err == ERROR_IO_PENDING) {
1581 ret = GetOverlappedResult(s->hcom, &s->orecv, &size, TRUE);
1585 if (size > 0) {
1586 qemu_chr_read(chr, buf, size);
1590 static void win_chr_read(CharDriverState *chr)
1592 WinCharState *s = chr->opaque;
1594 if (s->len > s->max_size)
1595 s->len = s->max_size;
1596 if (s->len == 0)
1597 return;
1599 win_chr_readfile(chr);
1602 static int win_chr_poll(void *opaque)
1604 CharDriverState *chr = opaque;
1605 WinCharState *s = chr->opaque;
1606 COMSTAT status;
1607 DWORD comerr;
1609 ClearCommError(s->hcom, &comerr, &status);
1610 if (status.cbInQue > 0) {
1611 s->len = status.cbInQue;
1612 win_chr_read_poll(chr);
1613 win_chr_read(chr);
1614 return 1;
1616 return 0;
1619 static CharDriverState *qemu_chr_open_win(QemuOpts *opts)
1621 const char *filename = qemu_opt_get(opts, "path");
1622 CharDriverState *chr;
1623 WinCharState *s;
1625 chr = qemu_mallocz(sizeof(CharDriverState));
1626 s = qemu_mallocz(sizeof(WinCharState));
1627 chr->opaque = s;
1628 chr->chr_write = win_chr_write;
1629 chr->chr_close = win_chr_close;
1631 if (win_chr_init(chr, filename) < 0) {
1632 free(s);
1633 free(chr);
1634 return NULL;
1636 qemu_chr_generic_open(chr);
1637 return chr;
1640 static int win_chr_pipe_poll(void *opaque)
1642 CharDriverState *chr = opaque;
1643 WinCharState *s = chr->opaque;
1644 DWORD size;
1646 PeekNamedPipe(s->hcom, NULL, 0, NULL, &size, NULL);
1647 if (size > 0) {
1648 s->len = size;
1649 win_chr_read_poll(chr);
1650 win_chr_read(chr);
1651 return 1;
1653 return 0;
1656 static int win_chr_pipe_init(CharDriverState *chr, const char *filename)
1658 WinCharState *s = chr->opaque;
1659 OVERLAPPED ov;
1660 int ret;
1661 DWORD size;
1662 char openname[256];
1664 s->fpipe = TRUE;
1666 s->hsend = CreateEvent(NULL, TRUE, FALSE, NULL);
1667 if (!s->hsend) {
1668 fprintf(stderr, "Failed CreateEvent\n");
1669 goto fail;
1671 s->hrecv = CreateEvent(NULL, TRUE, FALSE, NULL);
1672 if (!s->hrecv) {
1673 fprintf(stderr, "Failed CreateEvent\n");
1674 goto fail;
1677 snprintf(openname, sizeof(openname), "\\\\.\\pipe\\%s", filename);
1678 s->hcom = CreateNamedPipe(openname, PIPE_ACCESS_DUPLEX | FILE_FLAG_OVERLAPPED,
1679 PIPE_TYPE_BYTE | PIPE_READMODE_BYTE |
1680 PIPE_WAIT,
1681 MAXCONNECT, NSENDBUF, NRECVBUF, NTIMEOUT, NULL);
1682 if (s->hcom == INVALID_HANDLE_VALUE) {
1683 fprintf(stderr, "Failed CreateNamedPipe (%lu)\n", GetLastError());
1684 s->hcom = NULL;
1685 goto fail;
1688 ZeroMemory(&ov, sizeof(ov));
1689 ov.hEvent = CreateEvent(NULL, TRUE, FALSE, NULL);
1690 ret = ConnectNamedPipe(s->hcom, &ov);
1691 if (ret) {
1692 fprintf(stderr, "Failed ConnectNamedPipe\n");
1693 goto fail;
1696 ret = GetOverlappedResult(s->hcom, &ov, &size, TRUE);
1697 if (!ret) {
1698 fprintf(stderr, "Failed GetOverlappedResult\n");
1699 if (ov.hEvent) {
1700 CloseHandle(ov.hEvent);
1701 ov.hEvent = NULL;
1703 goto fail;
1706 if (ov.hEvent) {
1707 CloseHandle(ov.hEvent);
1708 ov.hEvent = NULL;
1710 qemu_add_polling_cb(win_chr_pipe_poll, chr);
1711 return 0;
1713 fail:
1714 win_chr_close(chr);
1715 return -1;
1719 static CharDriverState *qemu_chr_open_win_pipe(QemuOpts *opts)
1721 const char *filename = qemu_opt_get(opts, "path");
1722 CharDriverState *chr;
1723 WinCharState *s;
1725 chr = qemu_mallocz(sizeof(CharDriverState));
1726 s = qemu_mallocz(sizeof(WinCharState));
1727 chr->opaque = s;
1728 chr->chr_write = win_chr_write;
1729 chr->chr_close = win_chr_close;
1731 if (win_chr_pipe_init(chr, filename) < 0) {
1732 free(s);
1733 free(chr);
1734 return NULL;
1736 qemu_chr_generic_open(chr);
1737 return chr;
1740 static CharDriverState *qemu_chr_open_win_file(HANDLE fd_out)
1742 CharDriverState *chr;
1743 WinCharState *s;
1745 chr = qemu_mallocz(sizeof(CharDriverState));
1746 s = qemu_mallocz(sizeof(WinCharState));
1747 s->hcom = fd_out;
1748 chr->opaque = s;
1749 chr->chr_write = win_chr_write;
1750 qemu_chr_generic_open(chr);
1751 return chr;
1754 static CharDriverState *qemu_chr_open_win_con(QemuOpts *opts)
1756 return qemu_chr_open_win_file(GetStdHandle(STD_OUTPUT_HANDLE));
1759 static CharDriverState *qemu_chr_open_win_file_out(QemuOpts *opts)
1761 const char *file_out = qemu_opt_get(opts, "path");
1762 HANDLE fd_out;
1764 fd_out = CreateFile(file_out, GENERIC_WRITE, FILE_SHARE_READ, NULL,
1765 OPEN_ALWAYS, FILE_ATTRIBUTE_NORMAL, NULL);
1766 if (fd_out == INVALID_HANDLE_VALUE)
1767 return NULL;
1769 return qemu_chr_open_win_file(fd_out);
1771 #endif /* !_WIN32 */
1773 /***********************************************************/
1774 /* UDP Net console */
1776 typedef struct {
1777 int fd;
1778 uint8_t buf[READ_BUF_LEN];
1779 int bufcnt;
1780 int bufptr;
1781 int max_size;
1782 } NetCharDriver;
1784 static int udp_chr_write(CharDriverState *chr, const uint8_t *buf, int len)
1786 NetCharDriver *s = chr->opaque;
1788 return send(s->fd, (const void *)buf, len, 0);
1791 static int udp_chr_read_poll(void *opaque)
1793 CharDriverState *chr = opaque;
1794 NetCharDriver *s = chr->opaque;
1796 s->max_size = qemu_chr_can_read(chr);
1798 /* If there were any stray characters in the queue process them
1799 * first
1801 while (s->max_size > 0 && s->bufptr < s->bufcnt) {
1802 qemu_chr_read(chr, &s->buf[s->bufptr], 1);
1803 s->bufptr++;
1804 s->max_size = qemu_chr_can_read(chr);
1806 return s->max_size;
1809 static void udp_chr_read(void *opaque)
1811 CharDriverState *chr = opaque;
1812 NetCharDriver *s = chr->opaque;
1814 if (s->max_size == 0)
1815 return;
1816 s->bufcnt = recv(s->fd, (void *)s->buf, sizeof(s->buf), 0);
1817 s->bufptr = s->bufcnt;
1818 if (s->bufcnt <= 0)
1819 return;
1821 s->bufptr = 0;
1822 while (s->max_size > 0 && s->bufptr < s->bufcnt) {
1823 qemu_chr_read(chr, &s->buf[s->bufptr], 1);
1824 s->bufptr++;
1825 s->max_size = qemu_chr_can_read(chr);
1829 static void udp_chr_update_read_handler(CharDriverState *chr)
1831 NetCharDriver *s = chr->opaque;
1833 if (s->fd >= 0) {
1834 qemu_set_fd_handler2(s->fd, udp_chr_read_poll,
1835 udp_chr_read, NULL, chr);
1839 static void udp_chr_close(CharDriverState *chr)
1841 NetCharDriver *s = chr->opaque;
1842 if (s->fd >= 0) {
1843 qemu_set_fd_handler(s->fd, NULL, NULL, NULL);
1844 closesocket(s->fd);
1846 qemu_free(s);
1847 qemu_chr_event(chr, CHR_EVENT_CLOSED);
1850 static CharDriverState *qemu_chr_open_udp(QemuOpts *opts)
1852 CharDriverState *chr = NULL;
1853 NetCharDriver *s = NULL;
1854 int fd = -1;
1856 chr = qemu_mallocz(sizeof(CharDriverState));
1857 s = qemu_mallocz(sizeof(NetCharDriver));
1859 fd = inet_dgram_opts(opts);
1860 if (fd < 0) {
1861 fprintf(stderr, "inet_dgram_opts failed\n");
1862 goto return_err;
1865 s->fd = fd;
1866 s->bufcnt = 0;
1867 s->bufptr = 0;
1868 chr->opaque = s;
1869 chr->chr_write = udp_chr_write;
1870 chr->chr_update_read_handler = udp_chr_update_read_handler;
1871 chr->chr_close = udp_chr_close;
1872 return chr;
1874 return_err:
1875 if (chr)
1876 free(chr);
1877 if (s)
1878 free(s);
1879 if (fd >= 0)
1880 closesocket(fd);
1881 return NULL;
1884 /***********************************************************/
1885 /* TCP Net console */
1887 typedef struct {
1888 int fd, listen_fd;
1889 int connected;
1890 int max_size;
1891 int do_telnetopt;
1892 int do_nodelay;
1893 int is_unix;
1894 int msgfd;
1895 } TCPCharDriver;
1897 static void tcp_chr_accept(void *opaque);
1899 static int tcp_chr_write(CharDriverState *chr, const uint8_t *buf, int len)
1901 TCPCharDriver *s = chr->opaque;
1902 if (s->connected) {
1903 return send_all(s->fd, buf, len);
1904 } else {
1905 /* XXX: indicate an error ? */
1906 return len;
1910 static int tcp_chr_read_poll(void *opaque)
1912 CharDriverState *chr = opaque;
1913 TCPCharDriver *s = chr->opaque;
1914 if (!s->connected)
1915 return 0;
1916 s->max_size = qemu_chr_can_read(chr);
1917 return s->max_size;
1920 #define IAC 255
1921 #define IAC_BREAK 243
1922 static void tcp_chr_process_IAC_bytes(CharDriverState *chr,
1923 TCPCharDriver *s,
1924 uint8_t *buf, int *size)
1926 /* Handle any telnet client's basic IAC options to satisfy char by
1927 * char mode with no echo. All IAC options will be removed from
1928 * the buf and the do_telnetopt variable will be used to track the
1929 * state of the width of the IAC information.
1931 * IAC commands come in sets of 3 bytes with the exception of the
1932 * "IAC BREAK" command and the double IAC.
1935 int i;
1936 int j = 0;
1938 for (i = 0; i < *size; i++) {
1939 if (s->do_telnetopt > 1) {
1940 if ((unsigned char)buf[i] == IAC && s->do_telnetopt == 2) {
1941 /* Double IAC means send an IAC */
1942 if (j != i)
1943 buf[j] = buf[i];
1944 j++;
1945 s->do_telnetopt = 1;
1946 } else {
1947 if ((unsigned char)buf[i] == IAC_BREAK && s->do_telnetopt == 2) {
1948 /* Handle IAC break commands by sending a serial break */
1949 qemu_chr_event(chr, CHR_EVENT_BREAK);
1950 s->do_telnetopt++;
1952 s->do_telnetopt++;
1954 if (s->do_telnetopt >= 4) {
1955 s->do_telnetopt = 1;
1957 } else {
1958 if ((unsigned char)buf[i] == IAC) {
1959 s->do_telnetopt = 2;
1960 } else {
1961 if (j != i)
1962 buf[j] = buf[i];
1963 j++;
1967 *size = j;
1970 static int tcp_get_msgfd(CharDriverState *chr)
1972 TCPCharDriver *s = chr->opaque;
1974 return s->msgfd;
1977 #ifndef _WIN32
1978 static void unix_process_msgfd(CharDriverState *chr, struct msghdr *msg)
1980 TCPCharDriver *s = chr->opaque;
1981 struct cmsghdr *cmsg;
1983 for (cmsg = CMSG_FIRSTHDR(msg); cmsg; cmsg = CMSG_NXTHDR(msg, cmsg)) {
1984 int fd;
1986 if (cmsg->cmsg_len != CMSG_LEN(sizeof(int)) ||
1987 cmsg->cmsg_level != SOL_SOCKET ||
1988 cmsg->cmsg_type != SCM_RIGHTS)
1989 continue;
1991 fd = *((int *)CMSG_DATA(cmsg));
1992 if (fd < 0)
1993 continue;
1995 if (s->msgfd != -1)
1996 close(s->msgfd);
1997 s->msgfd = fd;
2001 static ssize_t tcp_chr_recv(CharDriverState *chr, char *buf, size_t len)
2003 TCPCharDriver *s = chr->opaque;
2004 struct msghdr msg = { NULL, };
2005 struct iovec iov[1];
2006 union {
2007 struct cmsghdr cmsg;
2008 char control[CMSG_SPACE(sizeof(int))];
2009 } msg_control;
2010 ssize_t ret;
2012 iov[0].iov_base = buf;
2013 iov[0].iov_len = len;
2015 msg.msg_iov = iov;
2016 msg.msg_iovlen = 1;
2017 msg.msg_control = &msg_control;
2018 msg.msg_controllen = sizeof(msg_control);
2020 ret = recvmsg(s->fd, &msg, 0);
2021 if (ret > 0 && s->is_unix)
2022 unix_process_msgfd(chr, &msg);
2024 return ret;
2026 #else
2027 static ssize_t tcp_chr_recv(CharDriverState *chr, char *buf, size_t len)
2029 TCPCharDriver *s = chr->opaque;
2030 return recv(s->fd, buf, len, 0);
2032 #endif
2034 static void tcp_chr_read(void *opaque)
2036 CharDriverState *chr = opaque;
2037 TCPCharDriver *s = chr->opaque;
2038 uint8_t buf[READ_BUF_LEN];
2039 int len, size;
2041 if (!s->connected || s->max_size <= 0)
2042 return;
2043 len = sizeof(buf);
2044 if (len > s->max_size)
2045 len = s->max_size;
2046 size = tcp_chr_recv(chr, (void *)buf, len);
2047 if (size == 0) {
2048 /* connection closed */
2049 s->connected = 0;
2050 if (s->listen_fd >= 0) {
2051 qemu_set_fd_handler(s->listen_fd, tcp_chr_accept, NULL, chr);
2053 qemu_set_fd_handler(s->fd, NULL, NULL, NULL);
2054 closesocket(s->fd);
2055 s->fd = -1;
2056 qemu_chr_event(chr, CHR_EVENT_CLOSED);
2057 } else if (size > 0) {
2058 if (s->do_telnetopt)
2059 tcp_chr_process_IAC_bytes(chr, s, buf, &size);
2060 if (size > 0)
2061 qemu_chr_read(chr, buf, size);
2062 if (s->msgfd != -1) {
2063 close(s->msgfd);
2064 s->msgfd = -1;
2069 static void tcp_chr_connect(void *opaque)
2071 CharDriverState *chr = opaque;
2072 TCPCharDriver *s = chr->opaque;
2074 s->connected = 1;
2075 qemu_set_fd_handler2(s->fd, tcp_chr_read_poll,
2076 tcp_chr_read, NULL, chr);
2077 qemu_chr_generic_open(chr);
2080 #define IACSET(x,a,b,c) x[0] = a; x[1] = b; x[2] = c;
2081 static void tcp_chr_telnet_init(int fd)
2083 char buf[3];
2084 /* Send the telnet negotion to put telnet in binary, no echo, single char mode */
2085 IACSET(buf, 0xff, 0xfb, 0x01); /* IAC WILL ECHO */
2086 send(fd, (char *)buf, 3, 0);
2087 IACSET(buf, 0xff, 0xfb, 0x03); /* IAC WILL Suppress go ahead */
2088 send(fd, (char *)buf, 3, 0);
2089 IACSET(buf, 0xff, 0xfb, 0x00); /* IAC WILL Binary */
2090 send(fd, (char *)buf, 3, 0);
2091 IACSET(buf, 0xff, 0xfd, 0x00); /* IAC DO Binary */
2092 send(fd, (char *)buf, 3, 0);
2095 static void socket_set_nodelay(int fd)
2097 int val = 1;
2098 setsockopt(fd, IPPROTO_TCP, TCP_NODELAY, (char *)&val, sizeof(val));
2101 static void tcp_chr_accept(void *opaque)
2103 CharDriverState *chr = opaque;
2104 TCPCharDriver *s = chr->opaque;
2105 struct sockaddr_in saddr;
2106 #ifndef _WIN32
2107 struct sockaddr_un uaddr;
2108 #endif
2109 struct sockaddr *addr;
2110 socklen_t len;
2111 int fd;
2113 for(;;) {
2114 #ifndef _WIN32
2115 if (s->is_unix) {
2116 len = sizeof(uaddr);
2117 addr = (struct sockaddr *)&uaddr;
2118 } else
2119 #endif
2121 len = sizeof(saddr);
2122 addr = (struct sockaddr *)&saddr;
2124 fd = qemu_accept(s->listen_fd, addr, &len);
2125 if (fd < 0 && errno != EINTR) {
2126 return;
2127 } else if (fd >= 0) {
2128 if (s->do_telnetopt)
2129 tcp_chr_telnet_init(fd);
2130 break;
2133 socket_set_nonblock(fd);
2134 if (s->do_nodelay)
2135 socket_set_nodelay(fd);
2136 s->fd = fd;
2137 qemu_set_fd_handler(s->listen_fd, NULL, NULL, NULL);
2138 tcp_chr_connect(chr);
2141 static void tcp_chr_close(CharDriverState *chr)
2143 TCPCharDriver *s = chr->opaque;
2144 if (s->fd >= 0) {
2145 qemu_set_fd_handler(s->fd, NULL, NULL, NULL);
2146 closesocket(s->fd);
2148 if (s->listen_fd >= 0) {
2149 qemu_set_fd_handler(s->listen_fd, NULL, NULL, NULL);
2150 closesocket(s->listen_fd);
2152 qemu_free(s);
2153 qemu_chr_event(chr, CHR_EVENT_CLOSED);
2156 static CharDriverState *qemu_chr_open_socket(QemuOpts *opts)
2158 CharDriverState *chr = NULL;
2159 TCPCharDriver *s = NULL;
2160 int fd = -1;
2161 int is_listen;
2162 int is_waitconnect;
2163 int do_nodelay;
2164 int is_unix;
2165 int is_telnet;
2167 is_listen = qemu_opt_get_bool(opts, "server", 0);
2168 is_waitconnect = qemu_opt_get_bool(opts, "wait", 1);
2169 is_telnet = qemu_opt_get_bool(opts, "telnet", 0);
2170 do_nodelay = !qemu_opt_get_bool(opts, "delay", 1);
2171 is_unix = qemu_opt_get(opts, "path") != NULL;
2172 if (!is_listen)
2173 is_waitconnect = 0;
2175 chr = qemu_mallocz(sizeof(CharDriverState));
2176 s = qemu_mallocz(sizeof(TCPCharDriver));
2178 if (is_unix) {
2179 if (is_listen) {
2180 fd = unix_listen_opts(opts);
2181 } else {
2182 fd = unix_connect_opts(opts);
2184 } else {
2185 if (is_listen) {
2186 fd = inet_listen_opts(opts, 0);
2187 } else {
2188 fd = inet_connect_opts(opts);
2191 if (fd < 0)
2192 goto fail;
2194 if (!is_waitconnect)
2195 socket_set_nonblock(fd);
2197 s->connected = 0;
2198 s->fd = -1;
2199 s->listen_fd = -1;
2200 s->msgfd = -1;
2201 s->is_unix = is_unix;
2202 s->do_nodelay = do_nodelay && !is_unix;
2204 chr->opaque = s;
2205 chr->chr_write = tcp_chr_write;
2206 chr->chr_close = tcp_chr_close;
2207 chr->get_msgfd = tcp_get_msgfd;
2209 if (is_listen) {
2210 s->listen_fd = fd;
2211 qemu_set_fd_handler(s->listen_fd, tcp_chr_accept, NULL, chr);
2212 if (is_telnet)
2213 s->do_telnetopt = 1;
2215 } else {
2216 s->connected = 1;
2217 s->fd = fd;
2218 socket_set_nodelay(fd);
2219 tcp_chr_connect(chr);
2222 /* for "info chardev" monitor command */
2223 chr->filename = qemu_malloc(256);
2224 if (is_unix) {
2225 snprintf(chr->filename, 256, "unix:%s%s",
2226 qemu_opt_get(opts, "path"),
2227 qemu_opt_get_bool(opts, "server", 0) ? ",server" : "");
2228 } else if (is_telnet) {
2229 snprintf(chr->filename, 256, "telnet:%s:%s%s",
2230 qemu_opt_get(opts, "host"), qemu_opt_get(opts, "port"),
2231 qemu_opt_get_bool(opts, "server", 0) ? ",server" : "");
2232 } else {
2233 snprintf(chr->filename, 256, "tcp:%s:%s%s",
2234 qemu_opt_get(opts, "host"), qemu_opt_get(opts, "port"),
2235 qemu_opt_get_bool(opts, "server", 0) ? ",server" : "");
2238 if (is_listen && is_waitconnect) {
2239 printf("QEMU waiting for connection on: %s\n",
2240 chr->filename);
2241 tcp_chr_accept(chr);
2242 socket_set_nonblock(s->listen_fd);
2244 return chr;
2246 fail:
2247 if (fd >= 0)
2248 closesocket(fd);
2249 qemu_free(s);
2250 qemu_free(chr);
2251 return NULL;
2254 QemuOpts *qemu_chr_parse_compat(const char *label, const char *filename)
2256 char host[65], port[33], width[8], height[8];
2257 int pos;
2258 const char *p;
2259 QemuOpts *opts;
2261 opts = qemu_opts_create(&qemu_chardev_opts, label, 1);
2262 if (NULL == opts)
2263 return NULL;
2265 if (strstart(filename, "mon:", &p)) {
2266 filename = p;
2267 qemu_opt_set(opts, "mux", "on");
2270 if (strcmp(filename, "null") == 0 ||
2271 strcmp(filename, "pty") == 0 ||
2272 strcmp(filename, "msmouse") == 0 ||
2273 strcmp(filename, "braille") == 0 ||
2274 strcmp(filename, "stdio") == 0) {
2275 qemu_opt_set(opts, "backend", filename);
2276 return opts;
2278 if (strstart(filename, "vc", &p)) {
2279 qemu_opt_set(opts, "backend", "vc");
2280 if (*p == ':') {
2281 if (sscanf(p+1, "%8[0-9]x%8[0-9]", width, height) == 2) {
2282 /* pixels */
2283 qemu_opt_set(opts, "width", width);
2284 qemu_opt_set(opts, "height", height);
2285 } else if (sscanf(p+1, "%8[0-9]Cx%8[0-9]C", width, height) == 2) {
2286 /* chars */
2287 qemu_opt_set(opts, "cols", width);
2288 qemu_opt_set(opts, "rows", height);
2289 } else {
2290 goto fail;
2293 return opts;
2295 if (strcmp(filename, "con:") == 0) {
2296 qemu_opt_set(opts, "backend", "console");
2297 return opts;
2299 if (strstart(filename, "COM", NULL)) {
2300 qemu_opt_set(opts, "backend", "serial");
2301 qemu_opt_set(opts, "path", filename);
2302 return opts;
2304 if (strstart(filename, "file:", &p)) {
2305 qemu_opt_set(opts, "backend", "file");
2306 qemu_opt_set(opts, "path", p);
2307 return opts;
2309 if (strstart(filename, "pipe:", &p)) {
2310 qemu_opt_set(opts, "backend", "pipe");
2311 qemu_opt_set(opts, "path", p);
2312 return opts;
2314 if (strstart(filename, "tcp:", &p) ||
2315 strstart(filename, "telnet:", &p)) {
2316 if (sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2) {
2317 host[0] = 0;
2318 if (sscanf(p, ":%32[^,]%n", port, &pos) < 1)
2319 goto fail;
2321 qemu_opt_set(opts, "backend", "socket");
2322 qemu_opt_set(opts, "host", host);
2323 qemu_opt_set(opts, "port", port);
2324 if (p[pos] == ',') {
2325 if (qemu_opts_do_parse(opts, p+pos+1, NULL) != 0)
2326 goto fail;
2328 if (strstart(filename, "telnet:", &p))
2329 qemu_opt_set(opts, "telnet", "on");
2330 return opts;
2332 if (strstart(filename, "udp:", &p)) {
2333 qemu_opt_set(opts, "backend", "udp");
2334 if (sscanf(p, "%64[^:]:%32[^@,]%n", host, port, &pos) < 2) {
2335 host[0] = 0;
2336 if (sscanf(p, ":%32[^,]%n", port, &pos) < 1) {
2337 goto fail;
2340 qemu_opt_set(opts, "host", host);
2341 qemu_opt_set(opts, "port", port);
2342 if (p[pos] == '@') {
2343 p += pos + 1;
2344 if (sscanf(p, "%64[^:]:%32[^,]%n", host, port, &pos) < 2) {
2345 host[0] = 0;
2346 if (sscanf(p, ":%32[^,]%n", port, &pos) < 1) {
2347 goto fail;
2350 qemu_opt_set(opts, "localaddr", host);
2351 qemu_opt_set(opts, "localport", port);
2353 return opts;
2355 if (strstart(filename, "unix:", &p)) {
2356 qemu_opt_set(opts, "backend", "socket");
2357 if (qemu_opts_do_parse(opts, p, "path") != 0)
2358 goto fail;
2359 return opts;
2361 if (strstart(filename, "/dev/parport", NULL) ||
2362 strstart(filename, "/dev/ppi", NULL)) {
2363 qemu_opt_set(opts, "backend", "parport");
2364 qemu_opt_set(opts, "path", filename);
2365 return opts;
2367 if (strstart(filename, "/dev/", NULL)) {
2368 qemu_opt_set(opts, "backend", "tty");
2369 qemu_opt_set(opts, "path", filename);
2370 return opts;
2373 fail:
2374 qemu_opts_del(opts);
2375 return NULL;
2378 static const struct {
2379 const char *name;
2380 CharDriverState *(*open)(QemuOpts *opts);
2381 } backend_table[] = {
2382 { .name = "null", .open = qemu_chr_open_null },
2383 { .name = "socket", .open = qemu_chr_open_socket },
2384 { .name = "udp", .open = qemu_chr_open_udp },
2385 { .name = "msmouse", .open = qemu_chr_open_msmouse },
2386 { .name = "vc", .open = text_console_init },
2387 #ifdef _WIN32
2388 { .name = "file", .open = qemu_chr_open_win_file_out },
2389 { .name = "pipe", .open = qemu_chr_open_win_pipe },
2390 { .name = "console", .open = qemu_chr_open_win_con },
2391 { .name = "serial", .open = qemu_chr_open_win },
2392 #else
2393 { .name = "file", .open = qemu_chr_open_file_out },
2394 { .name = "pipe", .open = qemu_chr_open_pipe },
2395 { .name = "pty", .open = qemu_chr_open_pty },
2396 { .name = "stdio", .open = qemu_chr_open_stdio },
2397 #endif
2398 #ifdef CONFIG_BRLAPI
2399 { .name = "braille", .open = chr_baum_init },
2400 #endif
2401 #if defined(__linux__) || defined(__sun__) || defined(__FreeBSD__) \
2402 || defined(__NetBSD__) || defined(__OpenBSD__) || defined(__DragonFly__) \
2403 || defined(__FreeBSD_kernel__)
2404 { .name = "tty", .open = qemu_chr_open_tty },
2405 #endif
2406 #if defined(__linux__) || defined(__FreeBSD__) || defined(__DragonFly__) \
2407 || defined(__FreeBSD_kernel__)
2408 { .name = "parport", .open = qemu_chr_open_pp },
2409 #endif
2412 CharDriverState *qemu_chr_open_opts(QemuOpts *opts,
2413 void (*init)(struct CharDriverState *s))
2415 CharDriverState *chr;
2416 int i;
2418 if (qemu_opts_id(opts) == NULL) {
2419 fprintf(stderr, "chardev: no id specified\n");
2420 return NULL;
2423 for (i = 0; i < ARRAY_SIZE(backend_table); i++) {
2424 if (strcmp(backend_table[i].name, qemu_opt_get(opts, "backend")) == 0)
2425 break;
2427 if (i == ARRAY_SIZE(backend_table)) {
2428 fprintf(stderr, "chardev: backend \"%s\" not found\n",
2429 qemu_opt_get(opts, "backend"));
2430 return NULL;
2433 chr = backend_table[i].open(opts);
2434 if (!chr) {
2435 fprintf(stderr, "chardev: opening backend \"%s\" failed\n",
2436 qemu_opt_get(opts, "backend"));
2437 return NULL;
2440 if (!chr->filename)
2441 chr->filename = qemu_strdup(qemu_opt_get(opts, "backend"));
2442 chr->init = init;
2443 QTAILQ_INSERT_TAIL(&chardevs, chr, next);
2445 if (qemu_opt_get_bool(opts, "mux", 0)) {
2446 CharDriverState *base = chr;
2447 int len = strlen(qemu_opts_id(opts)) + 6;
2448 base->label = qemu_malloc(len);
2449 snprintf(base->label, len, "%s-base", qemu_opts_id(opts));
2450 chr = qemu_chr_open_mux(base);
2451 chr->filename = base->filename;
2452 QTAILQ_INSERT_TAIL(&chardevs, chr, next);
2454 chr->label = qemu_strdup(qemu_opts_id(opts));
2455 return chr;
2458 CharDriverState *qemu_chr_open(const char *label, const char *filename, void (*init)(struct CharDriverState *s))
2460 const char *p;
2461 CharDriverState *chr;
2462 QemuOpts *opts;
2464 if (strstart(filename, "chardev:", &p)) {
2465 return qemu_chr_find(p);
2468 opts = qemu_chr_parse_compat(label, filename);
2469 if (!opts)
2470 return NULL;
2472 chr = qemu_chr_open_opts(opts, init);
2473 if (chr && qemu_opt_get_bool(opts, "mux", 0)) {
2474 monitor_init(chr, MONITOR_USE_READLINE);
2476 return chr;
2479 void qemu_chr_close(CharDriverState *chr)
2481 QTAILQ_REMOVE(&chardevs, chr, next);
2482 if (chr->chr_close)
2483 chr->chr_close(chr);
2484 qemu_free(chr->filename);
2485 qemu_free(chr->label);
2486 qemu_free(chr);
2489 static void qemu_chr_qlist_iter(QObject *obj, void *opaque)
2491 QDict *chr_dict;
2492 Monitor *mon = opaque;
2494 chr_dict = qobject_to_qdict(obj);
2495 monitor_printf(mon, "%s: filename=%s\n", qdict_get_str(chr_dict, "label"),
2496 qdict_get_str(chr_dict, "filename"));
2499 void qemu_chr_info_print(Monitor *mon, const QObject *ret_data)
2501 qlist_iter(qobject_to_qlist(ret_data), qemu_chr_qlist_iter, mon);
2505 * qemu_chr_info(): Character devices information
2507 * Each device is represented by a QDict. The returned QObject is a QList
2508 * of all devices.
2510 * The QDict contains the following:
2512 * - "label": device's label
2513 * - "filename": device's file
2515 * Example:
2517 * [ { "label": "monitor", "filename", "stdio" },
2518 * { "label": "serial0", "filename": "vc" } ]
2520 void qemu_chr_info(Monitor *mon, QObject **ret_data)
2522 QList *chr_list;
2523 CharDriverState *chr;
2525 chr_list = qlist_new();
2527 QTAILQ_FOREACH(chr, &chardevs, next) {
2528 QObject *obj = qobject_from_jsonf("{ 'label': %s, 'filename': %s }",
2529 chr->label, chr->filename);
2530 qlist_append_obj(chr_list, obj);
2533 *ret_data = QOBJECT(chr_list);
2536 CharDriverState *qemu_chr_find(const char *name)
2538 CharDriverState *chr;
2540 QTAILQ_FOREACH(chr, &chardevs, next) {
2541 if (strcmp(chr->label, name) != 0)
2542 continue;
2543 return chr;
2545 return NULL;