2 * High Precisition Event Timer emulation
4 * Copyright (c) 2007 Alexander Graf
5 * Copyright (c) 2008 IBM Corporation
7 * Authors: Beth Kon <bkon@us.ibm.com>
9 * This library is free software; you can redistribute it and/or
10 * modify it under the terms of the GNU Lesser General Public
11 * License as published by the Free Software Foundation; either
12 * version 2 of the License, or (at your option) any later version.
14 * This library is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
17 * Lesser General Public License for more details.
19 * You should have received a copy of the GNU Lesser General Public
20 * License along with this library; if not, write to the Free Software
21 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston MA 02110-1301 USA
23 * *****************************************************************
25 * This driver attempts to emulate an HPET device in software.
31 #include "qemu-timer.h"
32 #include "hpet_emul.h"
36 #define dprintf printf
41 static HPETState
*hpet_statep
;
43 uint32_t hpet_in_legacy_mode(void)
46 return hpet_statep
->config
& HPET_CFG_LEGACY
;
51 static uint32_t timer_int_route(struct HPETTimer
*timer
)
54 route
= (timer
->config
& HPET_TN_INT_ROUTE_MASK
) >> HPET_TN_INT_ROUTE_SHIFT
;
58 static uint32_t hpet_enabled(void)
60 return hpet_statep
->config
& HPET_CFG_ENABLE
;
63 static uint32_t timer_is_periodic(HPETTimer
*t
)
65 return t
->config
& HPET_TN_PERIODIC
;
68 static uint32_t timer_enabled(HPETTimer
*t
)
70 return t
->config
& HPET_TN_ENABLE
;
73 static uint32_t hpet_time_after(uint64_t a
, uint64_t b
)
75 return ((int32_t)(b
) - (int32_t)(a
) < 0);
78 static uint32_t hpet_time_after64(uint64_t a
, uint64_t b
)
80 return ((int64_t)(b
) - (int64_t)(a
) < 0);
83 static uint64_t ticks_to_ns(uint64_t value
)
85 return (muldiv64(value
, HPET_CLK_PERIOD
, FS_PER_NS
));
88 static uint64_t ns_to_ticks(uint64_t value
)
90 return (muldiv64(value
, FS_PER_NS
, HPET_CLK_PERIOD
));
93 static uint64_t hpet_fixup_reg(uint64_t new, uint64_t old
, uint64_t mask
)
100 static int activating_bit(uint64_t old
, uint64_t new, uint64_t mask
)
102 return (!(old
& mask
) && (new & mask
));
105 static int deactivating_bit(uint64_t old
, uint64_t new, uint64_t mask
)
107 return ((old
& mask
) && !(new & mask
));
110 static uint64_t hpet_get_ticks(void)
113 ticks
= ns_to_ticks(qemu_get_clock(vm_clock
) + hpet_statep
->hpet_offset
);
118 * calculate diff between comparator value and current ticks
120 static inline uint64_t hpet_calculate_diff(HPETTimer
*t
, uint64_t current
)
123 if (t
->config
& HPET_TN_32BIT
) {
125 cmp
= (uint32_t)t
->cmp
;
126 diff
= cmp
- (uint32_t)current
;
127 diff
= (int32_t)diff
> 0 ? diff
: (uint32_t)0;
128 return (uint64_t)diff
;
132 diff
= cmp
- current
;
133 diff
= (int64_t)diff
> 0 ? diff
: (uint64_t)0;
138 static void update_irq(struct HPETTimer
*timer
)
143 if (timer
->tn
<= 1 && hpet_in_legacy_mode()) {
144 /* if LegacyReplacementRoute bit is set, HPET specification requires
145 * timer0 be routed to IRQ0 in NON-APIC or IRQ2 in the I/O APIC,
146 * timer1 be routed to IRQ8 in NON-APIC or IRQ8 in the I/O APIC.
148 if (timer
->tn
== 0) {
149 irq
=timer
->state
->irqs
[0];
151 irq
=timer
->state
->irqs
[8];
153 route
=timer_int_route(timer
);
154 irq
=timer
->state
->irqs
[route
];
156 if (timer_enabled(timer
) && hpet_enabled()) {
161 static void hpet_save(QEMUFile
*f
, void *opaque
)
163 HPETState
*s
= opaque
;
165 qemu_put_be64s(f
, &s
->config
);
166 qemu_put_be64s(f
, &s
->isr
);
167 /* save current counter value */
168 s
->hpet_counter
= hpet_get_ticks();
169 qemu_put_be64s(f
, &s
->hpet_counter
);
171 for (i
= 0; i
< HPET_NUM_TIMERS
; i
++) {
172 qemu_put_8s(f
, &s
->timer
[i
].tn
);
173 qemu_put_be64s(f
, &s
->timer
[i
].config
);
174 qemu_put_be64s(f
, &s
->timer
[i
].cmp
);
175 qemu_put_be64s(f
, &s
->timer
[i
].fsb
);
176 qemu_put_be64s(f
, &s
->timer
[i
].period
);
177 qemu_put_8s(f
, &s
->timer
[i
].wrap_flag
);
178 if (s
->timer
[i
].qemu_timer
) {
179 qemu_put_timer(f
, s
->timer
[i
].qemu_timer
);
184 static int hpet_load(QEMUFile
*f
, void *opaque
, int version_id
)
186 HPETState
*s
= opaque
;
192 qemu_get_be64s(f
, &s
->config
);
193 qemu_get_be64s(f
, &s
->isr
);
194 qemu_get_be64s(f
, &s
->hpet_counter
);
195 /* Recalculate the offset between the main counter and guest time */
196 s
->hpet_offset
= ticks_to_ns(s
->hpet_counter
) - qemu_get_clock(vm_clock
);
198 for (i
= 0; i
< HPET_NUM_TIMERS
; i
++) {
199 qemu_get_8s(f
, &s
->timer
[i
].tn
);
200 qemu_get_be64s(f
, &s
->timer
[i
].config
);
201 qemu_get_be64s(f
, &s
->timer
[i
].cmp
);
202 qemu_get_be64s(f
, &s
->timer
[i
].fsb
);
203 qemu_get_be64s(f
, &s
->timer
[i
].period
);
204 qemu_get_8s(f
, &s
->timer
[i
].wrap_flag
);
205 if (s
->timer
[i
].qemu_timer
) {
206 qemu_get_timer(f
, s
->timer
[i
].qemu_timer
);
213 * timer expiration callback
215 static void hpet_timer(void *opaque
)
217 HPETTimer
*t
= (HPETTimer
*)opaque
;
220 uint64_t period
= t
->period
;
221 uint64_t cur_tick
= hpet_get_ticks();
223 if (timer_is_periodic(t
) && period
!= 0) {
224 if (t
->config
& HPET_TN_32BIT
) {
225 while (hpet_time_after(cur_tick
, t
->cmp
))
226 t
->cmp
= (uint32_t)(t
->cmp
+ t
->period
);
228 while (hpet_time_after64(cur_tick
, t
->cmp
))
231 diff
= hpet_calculate_diff(t
, cur_tick
);
232 qemu_mod_timer(t
->qemu_timer
, qemu_get_clock(vm_clock
)
233 + (int64_t)ticks_to_ns(diff
));
234 } else if (t
->config
& HPET_TN_32BIT
&& !timer_is_periodic(t
)) {
236 diff
= hpet_calculate_diff(t
, cur_tick
);
237 qemu_mod_timer(t
->qemu_timer
, qemu_get_clock(vm_clock
)
238 + (int64_t)ticks_to_ns(diff
));
245 static void hpet_set_timer(HPETTimer
*t
)
248 uint32_t wrap_diff
; /* how many ticks until we wrap? */
249 uint64_t cur_tick
= hpet_get_ticks();
251 /* whenever new timer is being set up, make sure wrap_flag is 0 */
253 diff
= hpet_calculate_diff(t
, cur_tick
);
255 /* hpet spec says in one-shot 32-bit mode, generate an interrupt when
256 * counter wraps in addition to an interrupt with comparator match.
258 if (t
->config
& HPET_TN_32BIT
&& !timer_is_periodic(t
)) {
259 wrap_diff
= 0xffffffff - (uint32_t)cur_tick
;
260 if (wrap_diff
< (uint32_t)diff
) {
265 qemu_mod_timer(t
->qemu_timer
, qemu_get_clock(vm_clock
)
266 + (int64_t)ticks_to_ns(diff
));
269 static void hpet_del_timer(HPETTimer
*t
)
271 qemu_del_timer(t
->qemu_timer
);
275 static uint32_t hpet_ram_readb(void *opaque
, target_phys_addr_t addr
)
277 printf("qemu: hpet_read b at %" PRIx64
"\n", addr
);
281 static uint32_t hpet_ram_readw(void *opaque
, target_phys_addr_t addr
)
283 printf("qemu: hpet_read w at %" PRIx64
"\n", addr
);
288 static uint32_t hpet_ram_readl(void *opaque
, target_phys_addr_t addr
)
290 HPETState
*s
= (HPETState
*)opaque
;
291 uint64_t cur_tick
, index
;
293 dprintf("qemu: Enter hpet_ram_readl at %" PRIx64
"\n", addr
);
295 /*address range of all TN regs*/
296 if (index
>= 0x100 && index
<= 0x3ff) {
297 uint8_t timer_id
= (addr
- 0x100) / 0x20;
298 if (timer_id
> HPET_NUM_TIMERS
- 1) {
299 printf("qemu: timer id out of range\n");
302 HPETTimer
*timer
= &s
->timer
[timer_id
];
304 switch ((addr
- 0x100) % 0x20) {
306 return timer
->config
;
307 case HPET_TN_CFG
+ 4: // Interrupt capabilities
308 return timer
->config
>> 32;
309 case HPET_TN_CMP
: // comparator register
311 case HPET_TN_CMP
+ 4:
312 return timer
->cmp
>> 32;
314 return timer
->fsb
>> 32;
316 dprintf("qemu: invalid hpet_ram_readl\n");
322 return s
->capability
;
324 return s
->capability
>> 32;
328 dprintf("qemu: invalid HPET_CFG + 4 hpet_ram_readl \n");
332 cur_tick
= hpet_get_ticks();
334 cur_tick
= s
->hpet_counter
;
335 dprintf("qemu: reading counter = %" PRIx64
"\n", cur_tick
);
337 case HPET_COUNTER
+ 4:
339 cur_tick
= hpet_get_ticks();
341 cur_tick
= s
->hpet_counter
;
342 dprintf("qemu: reading counter + 4 = %" PRIx64
"\n", cur_tick
);
343 return cur_tick
>> 32;
347 dprintf("qemu: invalid hpet_ram_readl\n");
355 static void hpet_ram_writeb(void *opaque
, target_phys_addr_t addr
,
358 printf("qemu: invalid hpet_write b at %" PRIx64
" = %#x\n",
362 static void hpet_ram_writew(void *opaque
, target_phys_addr_t addr
,
365 printf("qemu: invalid hpet_write w at %" PRIx64
" = %#x\n",
370 static void hpet_ram_writel(void *opaque
, target_phys_addr_t addr
,
374 HPETState
*s
= (HPETState
*)opaque
;
375 uint64_t old_val
, new_val
, index
;
377 dprintf("qemu: Enter hpet_ram_writel at %" PRIx64
" = %#x\n", addr
, value
);
379 old_val
= hpet_ram_readl(opaque
, addr
);
382 /*address range of all TN regs*/
383 if (index
>= 0x100 && index
<= 0x3ff) {
384 uint8_t timer_id
= (addr
- 0x100) / 0x20;
385 dprintf("qemu: hpet_ram_writel timer_id = %#x \n", timer_id
);
386 HPETTimer
*timer
= &s
->timer
[timer_id
];
388 switch ((addr
- 0x100) % 0x20) {
390 dprintf("qemu: hpet_ram_writel HPET_TN_CFG\n");
391 timer
->config
= hpet_fixup_reg(new_val
, old_val
, 0x3e4e);
392 if (new_val
& HPET_TN_32BIT
) {
393 timer
->cmp
= (uint32_t)timer
->cmp
;
394 timer
->period
= (uint32_t)timer
->period
;
396 if (new_val
& HPET_TIMER_TYPE_LEVEL
) {
397 printf("qemu: level-triggered hpet not supported\n");
402 case HPET_TN_CFG
+ 4: // Interrupt capabilities
403 dprintf("qemu: invalid HPET_TN_CFG+4 write\n");
405 case HPET_TN_CMP
: // comparator register
406 dprintf("qemu: hpet_ram_writel HPET_TN_CMP \n");
407 if (timer
->config
& HPET_TN_32BIT
)
408 new_val
= (uint32_t)new_val
;
409 if (!timer_is_periodic(timer
) ||
410 (timer
->config
& HPET_TN_SETVAL
))
411 timer
->cmp
= (timer
->cmp
& 0xffffffff00000000ULL
)
415 * FIXME: Clamp period to reasonable min value?
416 * Clamp period to reasonable max value
418 new_val
&= (timer
->config
& HPET_TN_32BIT
? ~0u : ~0ull) >> 1;
419 timer
->period
= (timer
->period
& 0xffffffff00000000ULL
)
422 timer
->config
&= ~HPET_TN_SETVAL
;
424 hpet_set_timer(timer
);
426 case HPET_TN_CMP
+ 4: // comparator register high order
427 dprintf("qemu: hpet_ram_writel HPET_TN_CMP + 4\n");
428 if (!timer_is_periodic(timer
) ||
429 (timer
->config
& HPET_TN_SETVAL
))
430 timer
->cmp
= (timer
->cmp
& 0xffffffffULL
)
434 * FIXME: Clamp period to reasonable min value?
435 * Clamp period to reasonable max value
437 new_val
&= (timer
->config
438 & HPET_TN_32BIT
? ~0u : ~0ull) >> 1;
439 timer
->period
= (timer
->period
& 0xffffffffULL
)
442 timer
->config
&= ~HPET_TN_SETVAL
;
444 hpet_set_timer(timer
);
446 case HPET_TN_ROUTE
+ 4:
447 dprintf("qemu: hpet_ram_writel HPET_TN_ROUTE + 4\n");
450 dprintf("qemu: invalid hpet_ram_writel\n");
459 s
->config
= hpet_fixup_reg(new_val
, old_val
, 0x3);
460 if (activating_bit(old_val
, new_val
, HPET_CFG_ENABLE
)) {
461 /* Enable main counter and interrupt generation. */
462 s
->hpet_offset
= ticks_to_ns(s
->hpet_counter
)
463 - qemu_get_clock(vm_clock
);
464 for (i
= 0; i
< HPET_NUM_TIMERS
; i
++)
465 if ((&s
->timer
[i
])->cmp
!= ~0ULL)
466 hpet_set_timer(&s
->timer
[i
]);
468 else if (deactivating_bit(old_val
, new_val
, HPET_CFG_ENABLE
)) {
469 /* Halt main counter and disable interrupt generation. */
470 s
->hpet_counter
= hpet_get_ticks();
471 for (i
= 0; i
< HPET_NUM_TIMERS
; i
++)
472 hpet_del_timer(&s
->timer
[i
]);
474 /* i8254 and RTC are disabled when HPET is in legacy mode */
475 if (activating_bit(old_val
, new_val
, HPET_CFG_LEGACY
)) {
477 } else if (deactivating_bit(old_val
, new_val
, HPET_CFG_LEGACY
)) {
482 dprintf("qemu: invalid HPET_CFG+4 write \n");
485 /* FIXME: need to handle level-triggered interrupts */
489 printf("qemu: Writing counter while HPET enabled!\n");
490 s
->hpet_counter
= (s
->hpet_counter
& 0xffffffff00000000ULL
)
492 dprintf("qemu: HPET counter written. ctr = %#x -> %" PRIx64
"\n",
493 value
, s
->hpet_counter
);
495 case HPET_COUNTER
+ 4:
497 printf("qemu: Writing counter while HPET enabled!\n");
498 s
->hpet_counter
= (s
->hpet_counter
& 0xffffffffULL
)
499 | (((uint64_t)value
) << 32);
500 dprintf("qemu: HPET counter + 4 written. ctr = %#x -> %" PRIx64
"\n",
501 value
, s
->hpet_counter
);
504 dprintf("qemu: invalid hpet_ram_writel\n");
510 static CPUReadMemoryFunc
*hpet_ram_read
[] = {
521 static CPUWriteMemoryFunc
*hpet_ram_write
[] = {
532 static void hpet_reset(void *opaque
) {
533 HPETState
*s
= opaque
;
535 static int count
= 0;
537 for (i
=0; i
<HPET_NUM_TIMERS
; i
++) {
538 HPETTimer
*timer
= &s
->timer
[i
];
539 hpet_del_timer(timer
);
542 timer
->config
= HPET_TN_PERIODIC_CAP
| HPET_TN_SIZE_CAP
;
543 /* advertise availability of irqs 5,10,11 */
544 timer
->config
|= 0x00000c20ULL
<< 32;
546 timer
->period
= 0ULL;
547 timer
->wrap_flag
= 0;
550 s
->hpet_counter
= 0ULL;
551 s
->hpet_offset
= 0ULL;
552 /* 64-bit main counter; 3 timers supported; LegacyReplacementRoute. */
553 s
->capability
= 0x8086a201ULL
;
554 s
->capability
|= ((HPET_CLK_PERIOD
) << 32);
556 /* we don't enable pit when hpet_reset is first called (by hpet_init)
557 * because hpet is taking over for pit here. On subsequent invocations,
558 * hpet_reset is called due to system reset. At this point control must
559 * be returned to pit until SW reenables hpet.
566 void hpet_init(qemu_irq
*irq
) {
570 dprintf ("hpet_init\n");
572 s
= qemu_mallocz(sizeof(HPETState
));
575 for (i
=0; i
<HPET_NUM_TIMERS
; i
++) {
576 HPETTimer
*timer
= &s
->timer
[i
];
577 timer
->qemu_timer
= qemu_new_timer(vm_clock
, hpet_timer
, timer
);
580 register_savevm("hpet", -1, 1, hpet_save
, hpet_load
, s
);
581 qemu_register_reset(hpet_reset
, s
);
583 iomemtype
= cpu_register_io_memory(0, hpet_ram_read
,
585 cpu_register_physical_memory(HPET_BASE
, 0x400, iomemtype
);