2 * QEMU JAZZ RC4030 chipset
4 * Copyright (c) 2007-2013 Hervé Poussineau
6 * Permission is hereby granted, free of charge, to any person obtaining a copy
7 * of this software and associated documentation files (the "Software"), to deal
8 * in the Software without restriction, including without limitation the rights
9 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
10 * copies of the Software, and to permit persons to whom the Software is
11 * furnished to do so, subject to the following conditions:
13 * The above copyright notice and this permission notice shall be included in
14 * all copies or substantial portions of the Software.
16 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
17 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
18 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
19 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
20 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
21 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
25 #include "qemu/osdep.h"
26 #include "qemu/units.h"
28 #include "hw/mips/mips.h"
29 #include "hw/sysbus.h"
30 #include "migration/vmstate.h"
31 #include "qapi/error.h"
32 #include "qemu/timer.h"
34 #include "qemu/module.h"
35 #include "exec/address-spaces.h"
37 #include "qom/object.h"
39 /********************************************************/
40 /* rc4030 emulation */
42 typedef struct dma_pagetable_entry
{
45 } QEMU_PACKED dma_pagetable_entry
;
47 #define DMA_PAGESIZE 4096
48 #define DMA_REG_ENABLE 1
49 #define DMA_REG_COUNT 2
50 #define DMA_REG_ADDRESS 3
52 #define DMA_FLAG_ENABLE 0x0001
53 #define DMA_FLAG_MEM_TO_DEV 0x0002
54 #define DMA_FLAG_TC_INTR 0x0100
55 #define DMA_FLAG_MEM_INTR 0x0200
56 #define DMA_FLAG_ADDR_INTR 0x0400
58 #define TYPE_RC4030 "rc4030"
59 typedef struct rc4030State rc4030State
;
60 DECLARE_INSTANCE_CHECKER(rc4030State
, RC4030
,
63 #define TYPE_RC4030_IOMMU_MEMORY_REGION "rc4030-iommu-memory-region"
69 uint32_t config
; /* 0x0000: RC4030 config register */
70 uint32_t revision
; /* 0x0008: RC4030 Revision register */
71 uint32_t invalid_address_register
; /* 0x0010: Invalid Address register */
74 uint32_t dma_regs
[8][4];
75 uint32_t dma_tl_base
; /* 0x0018: DMA transl. table base */
76 uint32_t dma_tl_limit
; /* 0x0020: DMA transl. table limit */
79 uint32_t cache_maint
; /* 0x0030: Cache Maintenance */
80 uint32_t remote_failed_address
; /* 0x0038: Remote Failed Address */
81 uint32_t memory_failed_address
; /* 0x0040: Memory Failed Address */
82 uint32_t cache_ptag
; /* 0x0048: I/O Cache Physical Tag */
83 uint32_t cache_ltag
; /* 0x0050: I/O Cache Logical Tag */
84 uint32_t cache_bmask
; /* 0x0058: I/O Cache Byte Mask */
86 uint32_t nmi_interrupt
; /* 0x0200: interrupt source */
87 uint32_t memory_refresh_rate
; /* 0x0210: memory refresh rate */
88 uint32_t nvram_protect
; /* 0x0220: NV ram protect register */
89 uint32_t rem_speed
[16];
90 uint32_t imr_jazz
; /* Local bus int enable mask */
91 uint32_t isr_jazz
; /* Local bus int source */
94 QEMUTimer
*periodic_timer
;
95 uint32_t itr
; /* Interval timer reload */
98 qemu_irq jazz_bus_irq
;
100 /* whole DMA memory region, root of DMA address space */
101 IOMMUMemoryRegion dma_mr
;
104 MemoryRegion iomem_chipset
;
105 MemoryRegion iomem_jazzio
;
108 static void set_next_tick(rc4030State
*s
)
111 qemu_irq_lower(s
->timer_irq
);
113 tm_hz
= 1000 / (s
->itr
+ 1);
115 timer_mod(s
->periodic_timer
, qemu_clock_get_ns(QEMU_CLOCK_VIRTUAL
) +
116 NANOSECONDS_PER_SECOND
/ tm_hz
);
119 /* called for accesses to rc4030 */
120 static uint64_t rc4030_read(void *opaque
, hwaddr addr
, unsigned int size
)
122 rc4030State
*s
= opaque
;
126 switch (addr
& ~0x3) {
127 /* Global config register */
131 /* Revision register */
135 /* Invalid Address register */
137 val
= s
->invalid_address_register
;
139 /* DMA transl. table base */
141 val
= s
->dma_tl_base
;
143 /* DMA transl. table limit */
145 val
= s
->dma_tl_limit
;
147 /* Remote Failed Address */
149 val
= s
->remote_failed_address
;
151 /* Memory Failed Address */
153 val
= s
->memory_failed_address
;
155 /* I/O Cache Byte Mask */
157 val
= s
->cache_bmask
;
159 if (s
->cache_bmask
== (uint32_t)-1) {
163 /* Remote Speed Registers */
180 val
= s
->rem_speed
[(addr
- 0x0070) >> 3];
182 /* DMA channel base address */
216 int entry
= (addr
- 0x0100) >> 5;
217 int idx
= (addr
& 0x1f) >> 3;
218 val
= s
->dma_regs
[entry
][idx
];
221 /* Interrupt source */
223 val
= s
->nmi_interrupt
;
229 /* Memory refresh rate */
231 val
= s
->memory_refresh_rate
;
233 /* NV ram protect register */
235 val
= s
->nvram_protect
;
237 /* Interval timer count */
240 qemu_irq_lower(s
->timer_irq
);
244 val
= 7; /* FIXME: should be read from EISA controller */
247 qemu_log_mask(LOG_GUEST_ERROR
,
248 "rc4030: invalid read at 0x%x", (int)addr
);
253 if ((addr
& ~3) != 0x230) {
254 trace_rc4030_read(addr
, val
);
260 static void rc4030_write(void *opaque
, hwaddr addr
, uint64_t data
,
263 rc4030State
*s
= opaque
;
267 trace_rc4030_write(addr
, val
);
269 switch (addr
& ~0x3) {
270 /* Global config register */
274 /* DMA transl. table base */
276 s
->dma_tl_base
= val
;
278 /* DMA transl. table limit */
280 s
->dma_tl_limit
= val
;
282 /* DMA transl. table invalidated */
285 /* Cache Maintenance */
287 s
->cache_maint
= val
;
289 /* I/O Cache Physical Tag */
293 /* I/O Cache Logical Tag */
297 /* I/O Cache Byte Mask */
299 s
->cache_bmask
|= val
; /* HACK */
301 /* I/O Cache Buffer Window */
304 if (s
->cache_ltag
== 0x80000001 && s
->cache_bmask
== 0xf0f0f0f) {
305 hwaddr dest
= s
->cache_ptag
& ~0x1;
306 dest
+= (s
->cache_maint
& 0x3) << 3;
307 cpu_physical_memory_write(dest
, &val
, 4);
310 /* Remote Speed Registers */
327 s
->rem_speed
[(addr
- 0x0070) >> 3] = val
;
329 /* DMA channel base address */
363 int entry
= (addr
- 0x0100) >> 5;
364 int idx
= (addr
& 0x1f) >> 3;
365 s
->dma_regs
[entry
][idx
] = val
;
368 /* Memory refresh rate */
370 s
->memory_refresh_rate
= val
;
372 /* Interval timer reload */
374 s
->itr
= val
& 0x01FF;
375 qemu_irq_lower(s
->timer_irq
);
382 qemu_log_mask(LOG_GUEST_ERROR
,
383 "rc4030: invalid write of 0x%02x at 0x%x",
389 static const MemoryRegionOps rc4030_ops
= {
391 .write
= rc4030_write
,
392 .impl
.min_access_size
= 4,
393 .impl
.max_access_size
= 4,
394 .endianness
= DEVICE_NATIVE_ENDIAN
,
397 static void update_jazz_irq(rc4030State
*s
)
401 pending
= s
->isr_jazz
& s
->imr_jazz
;
404 qemu_irq_raise(s
->jazz_bus_irq
);
406 qemu_irq_lower(s
->jazz_bus_irq
);
410 static void rc4030_irq_jazz_request(void *opaque
, int irq
, int level
)
412 rc4030State
*s
= opaque
;
415 s
->isr_jazz
|= 1 << irq
;
417 s
->isr_jazz
&= ~(1 << irq
);
423 static void rc4030_periodic_timer(void *opaque
)
425 rc4030State
*s
= opaque
;
428 qemu_irq_raise(s
->timer_irq
);
431 static uint64_t jazzio_read(void *opaque
, hwaddr addr
, unsigned int size
)
433 rc4030State
*s
= opaque
;
439 /* Local bus int source */
441 uint32_t pending
= s
->isr_jazz
& s
->imr_jazz
;
446 val
= (irq
+ 1) << 2;
454 /* Local bus int enable mask */
459 qemu_log_mask(LOG_GUEST_ERROR
,
460 "rc4030/jazzio: invalid read at 0x%x", (int)addr
);
465 trace_jazzio_read(addr
, val
);
470 static void jazzio_write(void *opaque
, hwaddr addr
, uint64_t data
,
473 rc4030State
*s
= opaque
;
477 trace_jazzio_write(addr
, val
);
480 /* Local bus int enable mask */
486 qemu_log_mask(LOG_GUEST_ERROR
,
487 "rc4030/jazzio: invalid write of 0x%02x at 0x%x",
493 static const MemoryRegionOps jazzio_ops
= {
495 .write
= jazzio_write
,
496 .impl
.min_access_size
= 2,
497 .impl
.max_access_size
= 2,
498 .endianness
= DEVICE_NATIVE_ENDIAN
,
501 static IOMMUTLBEntry
rc4030_dma_translate(IOMMUMemoryRegion
*iommu
, hwaddr addr
,
502 IOMMUAccessFlags flag
, int iommu_idx
)
504 rc4030State
*s
= container_of(iommu
, rc4030State
, dma_mr
);
505 IOMMUTLBEntry ret
= {
506 .target_as
= &address_space_memory
,
507 .iova
= addr
& ~(DMA_PAGESIZE
- 1),
508 .translated_addr
= 0,
509 .addr_mask
= DMA_PAGESIZE
- 1,
512 uint64_t i
, entry_address
;
513 dma_pagetable_entry entry
;
515 i
= addr
/ DMA_PAGESIZE
;
516 if (i
< s
->dma_tl_limit
/ sizeof(entry
)) {
517 entry_address
= (s
->dma_tl_base
& 0x7fffffff) + i
* sizeof(entry
);
518 if (address_space_read(ret
.target_as
, entry_address
,
519 MEMTXATTRS_UNSPECIFIED
, &entry
, sizeof(entry
))
521 ret
.translated_addr
= entry
.frame
& ~(DMA_PAGESIZE
- 1);
529 static void rc4030_reset(DeviceState
*dev
)
531 rc4030State
*s
= RC4030(dev
);
534 s
->config
= 0x410; /* some boards seem to accept 0x104 too */
536 s
->invalid_address_register
= 0;
538 memset(s
->dma_regs
, 0, sizeof(s
->dma_regs
));
540 s
->remote_failed_address
= s
->memory_failed_address
= 0;
542 s
->cache_ptag
= s
->cache_ltag
= 0;
545 s
->memory_refresh_rate
= 0x18186;
546 s
->nvram_protect
= 7;
547 for (i
= 0; i
< 15; i
++) {
550 s
->imr_jazz
= 0x10; /* XXX: required by firmware, but why? */
555 qemu_irq_lower(s
->timer_irq
);
556 qemu_irq_lower(s
->jazz_bus_irq
);
559 static int rc4030_post_load(void *opaque
, int version_id
)
561 rc4030State
*s
= opaque
;
569 static const VMStateDescription vmstate_rc4030
= {
572 .post_load
= rc4030_post_load
,
573 .fields
= (VMStateField
[]) {
574 VMSTATE_UINT32(config
, rc4030State
),
575 VMSTATE_UINT32(invalid_address_register
, rc4030State
),
576 VMSTATE_UINT32_2DARRAY(dma_regs
, rc4030State
, 8, 4),
577 VMSTATE_UINT32(dma_tl_base
, rc4030State
),
578 VMSTATE_UINT32(dma_tl_limit
, rc4030State
),
579 VMSTATE_UINT32(cache_maint
, rc4030State
),
580 VMSTATE_UINT32(remote_failed_address
, rc4030State
),
581 VMSTATE_UINT32(memory_failed_address
, rc4030State
),
582 VMSTATE_UINT32(cache_ptag
, rc4030State
),
583 VMSTATE_UINT32(cache_ltag
, rc4030State
),
584 VMSTATE_UINT32(cache_bmask
, rc4030State
),
585 VMSTATE_UINT32(memory_refresh_rate
, rc4030State
),
586 VMSTATE_UINT32(nvram_protect
, rc4030State
),
587 VMSTATE_UINT32_ARRAY(rem_speed
, rc4030State
, 16),
588 VMSTATE_UINT32(imr_jazz
, rc4030State
),
589 VMSTATE_UINT32(isr_jazz
, rc4030State
),
590 VMSTATE_UINT32(itr
, rc4030State
),
591 VMSTATE_END_OF_LIST()
595 static void rc4030_do_dma(void *opaque
, int n
, uint8_t *buf
,
596 int len
, bool is_write
)
598 rc4030State
*s
= opaque
;
602 s
->dma_regs
[n
][DMA_REG_ENABLE
] &=
603 ~(DMA_FLAG_TC_INTR
| DMA_FLAG_MEM_INTR
| DMA_FLAG_ADDR_INTR
);
605 /* Check DMA channel consistency */
606 dev_to_mem
= (s
->dma_regs
[n
][DMA_REG_ENABLE
] & DMA_FLAG_MEM_TO_DEV
) ? 0 : 1;
607 if (!(s
->dma_regs
[n
][DMA_REG_ENABLE
] & DMA_FLAG_ENABLE
) ||
608 (is_write
!= dev_to_mem
)) {
609 s
->dma_regs
[n
][DMA_REG_ENABLE
] |= DMA_FLAG_MEM_INTR
;
610 s
->nmi_interrupt
|= 1 << n
;
614 /* Get start address and len */
615 if (len
> s
->dma_regs
[n
][DMA_REG_COUNT
]) {
616 len
= s
->dma_regs
[n
][DMA_REG_COUNT
];
618 dma_addr
= s
->dma_regs
[n
][DMA_REG_ADDRESS
];
620 /* Read/write data at right place */
621 address_space_rw(&s
->dma_as
, dma_addr
, MEMTXATTRS_UNSPECIFIED
,
624 s
->dma_regs
[n
][DMA_REG_ENABLE
] |= DMA_FLAG_TC_INTR
;
625 s
->dma_regs
[n
][DMA_REG_COUNT
] -= len
;
628 struct rc4030DMAState
{
633 void rc4030_dma_read(void *dma
, uint8_t *buf
, int len
)
636 rc4030_do_dma(s
->opaque
, s
->n
, buf
, len
, false);
639 void rc4030_dma_write(void *dma
, uint8_t *buf
, int len
)
642 rc4030_do_dma(s
->opaque
, s
->n
, buf
, len
, true);
645 static rc4030_dma
*rc4030_allocate_dmas(void *opaque
, int n
)
648 struct rc4030DMAState
*p
;
651 s
= (rc4030_dma
*)g_new0(rc4030_dma
, n
);
652 p
= (struct rc4030DMAState
*)g_new0(struct rc4030DMAState
, n
);
653 for (i
= 0; i
< n
; i
++) {
662 static void rc4030_initfn(Object
*obj
)
664 DeviceState
*dev
= DEVICE(obj
);
665 rc4030State
*s
= RC4030(obj
);
666 SysBusDevice
*sysbus
= SYS_BUS_DEVICE(obj
);
668 qdev_init_gpio_in(dev
, rc4030_irq_jazz_request
, 16);
670 sysbus_init_irq(sysbus
, &s
->timer_irq
);
671 sysbus_init_irq(sysbus
, &s
->jazz_bus_irq
);
673 sysbus_init_mmio(sysbus
, &s
->iomem_chipset
);
674 sysbus_init_mmio(sysbus
, &s
->iomem_jazzio
);
677 static void rc4030_realize(DeviceState
*dev
, Error
**errp
)
679 rc4030State
*s
= RC4030(dev
);
680 Object
*o
= OBJECT(dev
);
682 s
->periodic_timer
= timer_new_ns(QEMU_CLOCK_VIRTUAL
,
683 rc4030_periodic_timer
, s
);
685 memory_region_init_io(&s
->iomem_chipset
, o
, &rc4030_ops
, s
,
686 "rc4030.chipset", 0x300);
687 memory_region_init_io(&s
->iomem_jazzio
, o
, &jazzio_ops
, s
,
688 "rc4030.jazzio", 0x00001000);
690 memory_region_init_iommu(&s
->dma_mr
, sizeof(s
->dma_mr
),
691 TYPE_RC4030_IOMMU_MEMORY_REGION
,
692 o
, "rc4030.dma", 4 * GiB
);
693 address_space_init(&s
->dma_as
, MEMORY_REGION(&s
->dma_mr
), "rc4030-dma");
696 static void rc4030_unrealize(DeviceState
*dev
)
698 rc4030State
*s
= RC4030(dev
);
700 timer_free(s
->periodic_timer
);
702 address_space_destroy(&s
->dma_as
);
703 object_unparent(OBJECT(&s
->dma_mr
));
706 static void rc4030_class_init(ObjectClass
*klass
, void *class_data
)
708 DeviceClass
*dc
= DEVICE_CLASS(klass
);
710 dc
->realize
= rc4030_realize
;
711 dc
->unrealize
= rc4030_unrealize
;
712 dc
->reset
= rc4030_reset
;
713 dc
->vmsd
= &vmstate_rc4030
;
716 static const TypeInfo rc4030_info
= {
718 .parent
= TYPE_SYS_BUS_DEVICE
,
719 .instance_size
= sizeof(rc4030State
),
720 .instance_init
= rc4030_initfn
,
721 .class_init
= rc4030_class_init
,
724 static void rc4030_iommu_memory_region_class_init(ObjectClass
*klass
,
727 IOMMUMemoryRegionClass
*imrc
= IOMMU_MEMORY_REGION_CLASS(klass
);
729 imrc
->translate
= rc4030_dma_translate
;
732 static const TypeInfo rc4030_iommu_memory_region_info
= {
733 .parent
= TYPE_IOMMU_MEMORY_REGION
,
734 .name
= TYPE_RC4030_IOMMU_MEMORY_REGION
,
735 .class_init
= rc4030_iommu_memory_region_class_init
,
738 static void rc4030_register_types(void)
740 type_register_static(&rc4030_info
);
741 type_register_static(&rc4030_iommu_memory_region_info
);
744 type_init(rc4030_register_types
)
746 DeviceState
*rc4030_init(rc4030_dma
**dmas
, IOMMUMemoryRegion
**dma_mr
)
750 dev
= qdev_new(TYPE_RC4030
);
751 sysbus_realize_and_unref(SYS_BUS_DEVICE(dev
), &error_fatal
);
753 *dmas
= rc4030_allocate_dmas(dev
, 4);
754 *dma_mr
= &RC4030(dev
)->dma_mr
;