2 * QEMU educational PCI device
4 * Copyright (c) 2012-2015 Jiri Slaby
6 * Permission is hereby granted, free of charge, to any person obtaining a
7 * copy of this software and associated documentation files (the "Software"),
8 * to deal in the Software without restriction, including without limitation
9 * the rights to use, copy, modify, merge, publish, distribute, sublicense,
10 * and/or sell copies of the Software, and to permit persons to whom the
11 * Software is furnished to do so, subject to the following conditions:
13 * The above copyright notice and this permission notice shall be included in
14 * all copies or substantial portions of the Software.
16 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
17 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
18 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
19 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
20 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
21 * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
22 * DEALINGS IN THE SOFTWARE.
25 #include "qemu/osdep.h"
27 #include "qemu/units.h"
28 #include "hw/pci/pci.h"
29 #include "hw/pci/msi.h"
30 #include "qemu/timer.h"
31 #include "qom/object.h"
32 #include "qemu/main-loop.h" /* iothread mutex */
33 #include "qemu/module.h"
34 #include "qapi/visitor.h"
36 #define TYPE_PCI_EDU_DEVICE "edu"
37 typedef struct EduState EduState
;
38 DECLARE_INSTANCE_CHECKER(EduState
, EDU
,
41 #define FACT_IRQ 0x00000001
42 #define DMA_IRQ 0x00000100
44 #define DMA_START 0x40000
58 #define EDU_STATUS_COMPUTING 0x01
59 #define EDU_STATUS_IRQFACT 0x80
64 #define EDU_DMA_RUN 0x1
65 #define EDU_DMA_DIR(cmd) (((cmd) & 0x2) >> 1)
66 # define EDU_DMA_FROM_PCI 0
67 # define EDU_DMA_TO_PCI 1
68 #define EDU_DMA_IRQ 0x4
76 char dma_buf
[DMA_SIZE
];
80 static bool edu_msi_enabled(EduState
*edu
)
82 return msi_enabled(&edu
->pdev
);
85 static void edu_raise_irq(EduState
*edu
, uint32_t val
)
87 edu
->irq_status
|= val
;
88 if (edu
->irq_status
) {
89 if (edu_msi_enabled(edu
)) {
90 msi_notify(&edu
->pdev
, 0);
92 pci_set_irq(&edu
->pdev
, 1);
97 static void edu_lower_irq(EduState
*edu
, uint32_t val
)
99 edu
->irq_status
&= ~val
;
101 if (!edu
->irq_status
&& !edu_msi_enabled(edu
)) {
102 pci_set_irq(&edu
->pdev
, 0);
106 static void edu_check_range(uint64_t xfer_start
, uint64_t xfer_size
,
107 uint64_t dma_start
, uint64_t dma_size
)
109 uint64_t xfer_end
= xfer_start
+ xfer_size
;
110 uint64_t dma_end
= dma_start
+ dma_size
;
113 * 1. ensure we aren't overflowing
114 * 2. ensure that xfer is within dma address range
116 if (dma_end
>= dma_start
&& xfer_end
>= xfer_start
&&
117 xfer_start
>= dma_start
&& xfer_end
<= dma_end
) {
121 qemu_log_mask(LOG_GUEST_ERROR
,
122 "EDU: DMA range 0x%016"PRIx64
"-0x%016"PRIx64
123 " out of bounds (0x%016"PRIx64
"-0x%016"PRIx64
")!",
124 xfer_start
, xfer_end
- 1, dma_start
, dma_end
- 1);
127 static dma_addr_t
edu_clamp_addr(const EduState
*edu
, dma_addr_t addr
)
129 dma_addr_t res
= addr
& edu
->dma_mask
;
132 qemu_log_mask(LOG_GUEST_ERROR
,
133 "EDU: clamping DMA 0x%016"PRIx64
" to 0x%016"PRIx64
"!",
140 static void edu_dma_timer(void *opaque
)
142 EduState
*edu
= opaque
;
143 bool raise_irq
= false;
145 if (!(edu
->dma
.cmd
& EDU_DMA_RUN
)) {
149 if (EDU_DMA_DIR(edu
->dma
.cmd
) == EDU_DMA_FROM_PCI
) {
150 uint64_t dst
= edu
->dma
.dst
;
151 edu_check_range(dst
, edu
->dma
.cnt
, DMA_START
, DMA_SIZE
);
153 pci_dma_read(&edu
->pdev
, edu_clamp_addr(edu
, edu
->dma
.src
),
154 edu
->dma_buf
+ dst
, edu
->dma
.cnt
);
156 uint64_t src
= edu
->dma
.src
;
157 edu_check_range(src
, edu
->dma
.cnt
, DMA_START
, DMA_SIZE
);
159 pci_dma_write(&edu
->pdev
, edu_clamp_addr(edu
, edu
->dma
.dst
),
160 edu
->dma_buf
+ src
, edu
->dma
.cnt
);
163 edu
->dma
.cmd
&= ~EDU_DMA_RUN
;
164 if (edu
->dma
.cmd
& EDU_DMA_IRQ
) {
169 edu_raise_irq(edu
, DMA_IRQ
);
173 static void dma_rw(EduState
*edu
, bool write
, dma_addr_t
*val
, dma_addr_t
*dma
,
176 if (write
&& (edu
->dma
.cmd
& EDU_DMA_RUN
)) {
187 timer_mod(&edu
->dma_timer
, qemu_clock_get_ms(QEMU_CLOCK_VIRTUAL
) + 100);
191 static uint64_t edu_mmio_read(void *opaque
, hwaddr addr
, unsigned size
)
193 EduState
*edu
= opaque
;
194 uint64_t val
= ~0ULL;
196 if (addr
< 0x80 && size
!= 4) {
200 if (addr
>= 0x80 && size
!= 4 && size
!= 8) {
212 qemu_mutex_lock(&edu
->thr_mutex
);
214 qemu_mutex_unlock(&edu
->thr_mutex
);
217 val
= qatomic_read(&edu
->status
);
220 val
= edu
->irq_status
;
223 dma_rw(edu
, false, &val
, &edu
->dma
.src
, false);
226 dma_rw(edu
, false, &val
, &edu
->dma
.dst
, false);
229 dma_rw(edu
, false, &val
, &edu
->dma
.cnt
, false);
232 dma_rw(edu
, false, &val
, &edu
->dma
.cmd
, false);
239 static void edu_mmio_write(void *opaque
, hwaddr addr
, uint64_t val
,
242 EduState
*edu
= opaque
;
244 if (addr
< 0x80 && size
!= 4) {
248 if (addr
>= 0x80 && size
!= 4 && size
!= 8) {
257 if (qatomic_read(&edu
->status
) & EDU_STATUS_COMPUTING
) {
260 /* EDU_STATUS_COMPUTING cannot go 0->1 concurrently, because it is only
261 * set in this function and it is under the iothread mutex.
263 qemu_mutex_lock(&edu
->thr_mutex
);
265 qatomic_or(&edu
->status
, EDU_STATUS_COMPUTING
);
266 qemu_cond_signal(&edu
->thr_cond
);
267 qemu_mutex_unlock(&edu
->thr_mutex
);
270 if (val
& EDU_STATUS_IRQFACT
) {
271 qatomic_or(&edu
->status
, EDU_STATUS_IRQFACT
);
272 /* Order check of the COMPUTING flag after setting IRQFACT. */
275 qatomic_and(&edu
->status
, ~EDU_STATUS_IRQFACT
);
279 edu_raise_irq(edu
, val
);
282 edu_lower_irq(edu
, val
);
285 dma_rw(edu
, true, &val
, &edu
->dma
.src
, false);
288 dma_rw(edu
, true, &val
, &edu
->dma
.dst
, false);
291 dma_rw(edu
, true, &val
, &edu
->dma
.cnt
, false);
294 if (!(val
& EDU_DMA_RUN
)) {
297 dma_rw(edu
, true, &val
, &edu
->dma
.cmd
, true);
302 static const MemoryRegionOps edu_mmio_ops
= {
303 .read
= edu_mmio_read
,
304 .write
= edu_mmio_write
,
305 .endianness
= DEVICE_NATIVE_ENDIAN
,
307 .min_access_size
= 4,
308 .max_access_size
= 8,
311 .min_access_size
= 4,
312 .max_access_size
= 8,
318 * We purposely use a thread, so that users are forced to wait for the status
321 static void *edu_fact_thread(void *opaque
)
323 EduState
*edu
= opaque
;
326 uint32_t val
, ret
= 1;
328 qemu_mutex_lock(&edu
->thr_mutex
);
329 while ((qatomic_read(&edu
->status
) & EDU_STATUS_COMPUTING
) == 0 &&
331 qemu_cond_wait(&edu
->thr_cond
, &edu
->thr_mutex
);
335 qemu_mutex_unlock(&edu
->thr_mutex
);
340 qemu_mutex_unlock(&edu
->thr_mutex
);
347 * We should sleep for a random period here, so that students are
348 * forced to check the status properly.
351 qemu_mutex_lock(&edu
->thr_mutex
);
353 qemu_mutex_unlock(&edu
->thr_mutex
);
354 qatomic_and(&edu
->status
, ~EDU_STATUS_COMPUTING
);
356 /* Clear COMPUTING flag before checking IRQFACT. */
359 if (qatomic_read(&edu
->status
) & EDU_STATUS_IRQFACT
) {
361 edu_raise_irq(edu
, FACT_IRQ
);
369 static void pci_edu_realize(PCIDevice
*pdev
, Error
**errp
)
371 EduState
*edu
= EDU(pdev
);
372 uint8_t *pci_conf
= pdev
->config
;
374 pci_config_set_interrupt_pin(pci_conf
, 1);
376 if (msi_init(pdev
, 0, 1, true, false, errp
)) {
380 timer_init_ms(&edu
->dma_timer
, QEMU_CLOCK_VIRTUAL
, edu_dma_timer
, edu
);
382 qemu_mutex_init(&edu
->thr_mutex
);
383 qemu_cond_init(&edu
->thr_cond
);
384 qemu_thread_create(&edu
->thread
, "edu", edu_fact_thread
,
385 edu
, QEMU_THREAD_JOINABLE
);
387 memory_region_init_io(&edu
->mmio
, OBJECT(edu
), &edu_mmio_ops
, edu
,
388 "edu-mmio", 1 * MiB
);
389 pci_register_bar(pdev
, 0, PCI_BASE_ADDRESS_SPACE_MEMORY
, &edu
->mmio
);
392 static void pci_edu_uninit(PCIDevice
*pdev
)
394 EduState
*edu
= EDU(pdev
);
396 qemu_mutex_lock(&edu
->thr_mutex
);
397 edu
->stopping
= true;
398 qemu_mutex_unlock(&edu
->thr_mutex
);
399 qemu_cond_signal(&edu
->thr_cond
);
400 qemu_thread_join(&edu
->thread
);
402 qemu_cond_destroy(&edu
->thr_cond
);
403 qemu_mutex_destroy(&edu
->thr_mutex
);
405 timer_del(&edu
->dma_timer
);
409 static void edu_instance_init(Object
*obj
)
411 EduState
*edu
= EDU(obj
);
413 edu
->dma_mask
= (1UL << 28) - 1;
414 object_property_add_uint64_ptr(obj
, "dma_mask",
415 &edu
->dma_mask
, OBJ_PROP_FLAG_READWRITE
);
418 static void edu_class_init(ObjectClass
*class, void *data
)
420 DeviceClass
*dc
= DEVICE_CLASS(class);
421 PCIDeviceClass
*k
= PCI_DEVICE_CLASS(class);
423 k
->realize
= pci_edu_realize
;
424 k
->exit
= pci_edu_uninit
;
425 k
->vendor_id
= PCI_VENDOR_ID_QEMU
;
426 k
->device_id
= 0x11e8;
428 k
->class_id
= PCI_CLASS_OTHERS
;
429 set_bit(DEVICE_CATEGORY_MISC
, dc
->categories
);
432 static void pci_edu_register_types(void)
434 static InterfaceInfo interfaces
[] = {
435 { INTERFACE_CONVENTIONAL_PCI_DEVICE
},
438 static const TypeInfo edu_info
= {
439 .name
= TYPE_PCI_EDU_DEVICE
,
440 .parent
= TYPE_PCI_DEVICE
,
441 .instance_size
= sizeof(EduState
),
442 .instance_init
= edu_instance_init
,
443 .class_init
= edu_class_init
,
444 .interfaces
= interfaces
,
447 type_register_static(&edu_info
);
449 type_init(pci_edu_register_types
)