2 * Copyright © 2018, 2021 Oracle and/or its affiliates.
4 * This work is licensed under the terms of the GNU GPL, version 2 or later.
5 * See the COPYING file in the top-level directory.
9 #include "qemu/osdep.h"
11 #include "hw/remote/proxy.h"
12 #include "hw/pci/pci.h"
13 #include "qapi/error.h"
14 #include "io/channel-util.h"
15 #include "hw/qdev-properties.h"
16 #include "monitor/monitor.h"
17 #include "migration/blocker.h"
18 #include "qemu/sockets.h"
19 #include "hw/remote/mpqemu-link.h"
20 #include "qemu/error-report.h"
21 #include "hw/remote/proxy-memory-listener.h"
22 #include "qom/object.h"
23 #include "qemu/event_notifier.h"
24 #include "sysemu/kvm.h"
25 #include "util/event_notifier-posix.c"
27 static void probe_pci_info(PCIDevice
*dev
, Error
**errp
);
28 static void proxy_device_reset(DeviceState
*dev
);
30 static void proxy_intx_update(PCIDevice
*pci_dev
)
32 PCIProxyDev
*dev
= PCI_PROXY_DEV(pci_dev
);
34 int pin
= pci_get_byte(pci_dev
->config
+ PCI_INTERRUPT_PIN
) - 1;
36 if (dev
->virq
!= -1) {
37 kvm_irqchip_remove_irqfd_notifier_gsi(kvm_state
, &dev
->intr
, dev
->virq
);
41 route
= pci_device_route_intx_to_irq(pci_dev
, pin
);
43 dev
->virq
= route
.irq
;
45 if (dev
->virq
!= -1) {
46 kvm_irqchip_add_irqfd_notifier_gsi(kvm_state
, &dev
->intr
,
47 &dev
->resample
, dev
->virq
);
51 static void setup_irqfd(PCIProxyDev
*dev
)
53 PCIDevice
*pci_dev
= PCI_DEVICE(dev
);
55 Error
*local_err
= NULL
;
57 event_notifier_init(&dev
->intr
, 0);
58 event_notifier_init(&dev
->resample
, 0);
60 memset(&msg
, 0, sizeof(MPQemuMsg
));
61 msg
.cmd
= MPQEMU_CMD_SET_IRQFD
;
63 msg
.fds
[0] = event_notifier_get_fd(&dev
->intr
);
64 msg
.fds
[1] = event_notifier_get_fd(&dev
->resample
);
67 if (!mpqemu_msg_send(&msg
, dev
->ioc
, &local_err
)) {
68 error_report_err(local_err
);
73 proxy_intx_update(pci_dev
);
75 pci_device_set_intx_routing_notifier(pci_dev
, proxy_intx_update
);
78 static void pci_proxy_dev_realize(PCIDevice
*device
, Error
**errp
)
81 PCIProxyDev
*dev
= PCI_PROXY_DEV(device
);
82 uint8_t *pci_conf
= device
->config
;
86 error_setg(errp
, "fd parameter not specified for %s",
91 fd
= monitor_fd_param(monitor_cur(), dev
->fd
, errp
);
93 error_prepend(errp
, "proxy: unable to parse fd %s: ", dev
->fd
);
97 if (!fd_is_socket(fd
)) {
98 error_setg(errp
, "proxy: fd %d is not a socket", fd
);
103 dev
->ioc
= qio_channel_new_fd(fd
, errp
);
109 error_setg(&dev
->migration_blocker
, "%s does not support migration",
111 if (migrate_add_blocker(dev
->migration_blocker
, errp
) < 0) {
112 error_free(dev
->migration_blocker
);
113 object_unref(dev
->ioc
);
117 qemu_mutex_init(&dev
->io_mutex
);
118 qio_channel_set_blocking(dev
->ioc
, true, NULL
);
120 pci_conf
[PCI_LATENCY_TIMER
] = 0xff;
121 pci_conf
[PCI_INTERRUPT_PIN
] = 0x01;
123 proxy_memory_listener_configure(&dev
->proxy_listener
, dev
->ioc
);
127 probe_pci_info(PCI_DEVICE(dev
), errp
);
130 static void pci_proxy_dev_exit(PCIDevice
*pdev
)
132 PCIProxyDev
*dev
= PCI_PROXY_DEV(pdev
);
135 qio_channel_close(dev
->ioc
, NULL
);
138 migrate_del_blocker(dev
->migration_blocker
);
140 error_free(dev
->migration_blocker
);
142 proxy_memory_listener_deconfigure(&dev
->proxy_listener
);
144 event_notifier_cleanup(&dev
->intr
);
145 event_notifier_cleanup(&dev
->resample
);
148 static void config_op_send(PCIProxyDev
*pdev
, uint32_t addr
, uint32_t *val
,
149 int len
, unsigned int op
)
151 MPQemuMsg msg
= { 0 };
152 uint64_t ret
= -EINVAL
;
153 Error
*local_err
= NULL
;
156 msg
.data
.pci_conf_data
.addr
= addr
;
157 msg
.data
.pci_conf_data
.val
= (op
== MPQEMU_CMD_PCI_CFGWRITE
) ? *val
: 0;
158 msg
.data
.pci_conf_data
.len
= len
;
159 msg
.size
= sizeof(PciConfDataMsg
);
161 ret
= mpqemu_msg_send_and_await_reply(&msg
, pdev
, &local_err
);
163 error_report_err(local_err
);
166 if (ret
== UINT64_MAX
) {
167 error_report("Failed to perform PCI config %s operation",
168 (op
== MPQEMU_CMD_PCI_CFGREAD
) ? "READ" : "WRITE");
171 if (op
== MPQEMU_CMD_PCI_CFGREAD
) {
172 *val
= (uint32_t)ret
;
176 static uint32_t pci_proxy_read_config(PCIDevice
*d
, uint32_t addr
, int len
)
180 config_op_send(PCI_PROXY_DEV(d
), addr
, &val
, len
, MPQEMU_CMD_PCI_CFGREAD
);
185 static void pci_proxy_write_config(PCIDevice
*d
, uint32_t addr
, uint32_t val
,
189 * Some of the functions access the copy of remote device's PCI config
190 * space which is cached in the proxy device. Therefore, maintain
193 pci_default_write_config(d
, addr
, val
, len
);
195 config_op_send(PCI_PROXY_DEV(d
), addr
, &val
, len
, MPQEMU_CMD_PCI_CFGWRITE
);
198 static Property proxy_properties
[] = {
199 DEFINE_PROP_STRING("fd", PCIProxyDev
, fd
),
200 DEFINE_PROP_END_OF_LIST(),
203 static void pci_proxy_dev_class_init(ObjectClass
*klass
, void *data
)
205 DeviceClass
*dc
= DEVICE_CLASS(klass
);
206 PCIDeviceClass
*k
= PCI_DEVICE_CLASS(klass
);
208 k
->realize
= pci_proxy_dev_realize
;
209 k
->exit
= pci_proxy_dev_exit
;
210 k
->config_read
= pci_proxy_read_config
;
211 k
->config_write
= pci_proxy_write_config
;
213 dc
->reset
= proxy_device_reset
;
215 device_class_set_props(dc
, proxy_properties
);
218 static const TypeInfo pci_proxy_dev_type_info
= {
219 .name
= TYPE_PCI_PROXY_DEV
,
220 .parent
= TYPE_PCI_DEVICE
,
221 .instance_size
= sizeof(PCIProxyDev
),
222 .class_init
= pci_proxy_dev_class_init
,
223 .interfaces
= (InterfaceInfo
[]) {
224 { INTERFACE_CONVENTIONAL_PCI_DEVICE
},
229 static void pci_proxy_dev_register_types(void)
231 type_register_static(&pci_proxy_dev_type_info
);
234 type_init(pci_proxy_dev_register_types
)
236 static void send_bar_access_msg(PCIProxyDev
*pdev
, MemoryRegion
*mr
,
237 bool write
, hwaddr addr
, uint64_t *val
,
238 unsigned size
, bool memory
)
240 MPQemuMsg msg
= { 0 };
242 Error
*local_err
= NULL
;
244 msg
.size
= sizeof(BarAccessMsg
);
245 msg
.data
.bar_access
.addr
= mr
->addr
+ addr
;
246 msg
.data
.bar_access
.size
= size
;
247 msg
.data
.bar_access
.memory
= memory
;
250 msg
.cmd
= MPQEMU_CMD_BAR_WRITE
;
251 msg
.data
.bar_access
.val
= *val
;
253 msg
.cmd
= MPQEMU_CMD_BAR_READ
;
256 ret
= mpqemu_msg_send_and_await_reply(&msg
, pdev
, &local_err
);
258 error_report_err(local_err
);
266 static void proxy_bar_write(void *opaque
, hwaddr addr
, uint64_t val
,
269 ProxyMemoryRegion
*pmr
= opaque
;
271 send_bar_access_msg(pmr
->dev
, &pmr
->mr
, true, addr
, &val
, size
,
275 static uint64_t proxy_bar_read(void *opaque
, hwaddr addr
, unsigned size
)
277 ProxyMemoryRegion
*pmr
= opaque
;
280 send_bar_access_msg(pmr
->dev
, &pmr
->mr
, false, addr
, &val
, size
,
286 const MemoryRegionOps proxy_mr_ops
= {
287 .read
= proxy_bar_read
,
288 .write
= proxy_bar_write
,
289 .endianness
= DEVICE_NATIVE_ENDIAN
,
291 .min_access_size
= 1,
292 .max_access_size
= 8,
296 static void probe_pci_info(PCIDevice
*dev
, Error
**errp
)
298 PCIDeviceClass
*pc
= PCI_DEVICE_GET_CLASS(dev
);
299 uint32_t orig_val
, new_val
, base_class
, val
;
300 PCIProxyDev
*pdev
= PCI_PROXY_DEV(dev
);
301 DeviceClass
*dc
= DEVICE_CLASS(pc
);
305 config_op_send(pdev
, PCI_VENDOR_ID
, &val
, 2, MPQEMU_CMD_PCI_CFGREAD
);
306 pc
->vendor_id
= (uint16_t)val
;
308 config_op_send(pdev
, PCI_DEVICE_ID
, &val
, 2, MPQEMU_CMD_PCI_CFGREAD
);
309 pc
->device_id
= (uint16_t)val
;
311 config_op_send(pdev
, PCI_CLASS_DEVICE
, &val
, 2, MPQEMU_CMD_PCI_CFGREAD
);
312 pc
->class_id
= (uint16_t)val
;
314 config_op_send(pdev
, PCI_SUBSYSTEM_ID
, &val
, 2, MPQEMU_CMD_PCI_CFGREAD
);
315 pc
->subsystem_id
= (uint16_t)val
;
317 base_class
= pc
->class_id
>> 4;
318 switch (base_class
) {
319 case PCI_BASE_CLASS_BRIDGE
:
320 set_bit(DEVICE_CATEGORY_BRIDGE
, dc
->categories
);
322 case PCI_BASE_CLASS_STORAGE
:
323 set_bit(DEVICE_CATEGORY_STORAGE
, dc
->categories
);
325 case PCI_BASE_CLASS_NETWORK
:
326 case PCI_BASE_CLASS_WIRELESS
:
327 set_bit(DEVICE_CATEGORY_NETWORK
, dc
->categories
);
329 case PCI_BASE_CLASS_INPUT
:
330 set_bit(DEVICE_CATEGORY_INPUT
, dc
->categories
);
332 case PCI_BASE_CLASS_DISPLAY
:
333 set_bit(DEVICE_CATEGORY_DISPLAY
, dc
->categories
);
335 case PCI_BASE_CLASS_PROCESSOR
:
336 set_bit(DEVICE_CATEGORY_CPU
, dc
->categories
);
339 set_bit(DEVICE_CATEGORY_MISC
, dc
->categories
);
343 for (i
= 0; i
< PCI_NUM_REGIONS
; i
++) {
344 config_op_send(pdev
, PCI_BASE_ADDRESS_0
+ (4 * i
), &orig_val
, 4,
345 MPQEMU_CMD_PCI_CFGREAD
);
346 new_val
= 0xffffffff;
347 config_op_send(pdev
, PCI_BASE_ADDRESS_0
+ (4 * i
), &new_val
, 4,
348 MPQEMU_CMD_PCI_CFGWRITE
);
349 config_op_send(pdev
, PCI_BASE_ADDRESS_0
+ (4 * i
), &new_val
, 4,
350 MPQEMU_CMD_PCI_CFGREAD
);
351 size
= (~(new_val
& 0xFFFFFFF0)) + 1;
352 config_op_send(pdev
, PCI_BASE_ADDRESS_0
+ (4 * i
), &orig_val
, 4,
353 MPQEMU_CMD_PCI_CFGWRITE
);
354 type
= (new_val
& 0x1) ?
355 PCI_BASE_ADDRESS_SPACE_IO
: PCI_BASE_ADDRESS_SPACE_MEMORY
;
358 g_autofree
char *name
= g_strdup_printf("bar-region-%d", i
);
359 pdev
->region
[i
].dev
= pdev
;
360 pdev
->region
[i
].present
= true;
361 if (type
== PCI_BASE_ADDRESS_SPACE_MEMORY
) {
362 pdev
->region
[i
].memory
= true;
364 memory_region_init_io(&pdev
->region
[i
].mr
, OBJECT(pdev
),
365 &proxy_mr_ops
, &pdev
->region
[i
],
367 pci_register_bar(dev
, i
, type
, &pdev
->region
[i
].mr
);
372 static void proxy_device_reset(DeviceState
*dev
)
374 PCIProxyDev
*pdev
= PCI_PROXY_DEV(dev
);
375 MPQemuMsg msg
= { 0 };
376 Error
*local_err
= NULL
;
378 msg
.cmd
= MPQEMU_CMD_DEVICE_RESET
;
381 mpqemu_msg_send_and_await_reply(&msg
, pdev
, &local_err
);
383 error_report_err(local_err
);