Statistics
| Branch: | Revision:

root / hw / usb-msd.c @ 1941d19c

History | View | Annotate | Download (11.8 kB)

1 2e5d83bb pbrook
/* 
2 2e5d83bb pbrook
 * USB Mass Storage Device emulation
3 2e5d83bb pbrook
 *
4 2e5d83bb pbrook
 * Copyright (c) 2006 CodeSourcery.
5 2e5d83bb pbrook
 * Written by Paul Brook
6 2e5d83bb pbrook
 *
7 2e5d83bb pbrook
 * This code is licenced under the LGPL.
8 2e5d83bb pbrook
 */
9 2e5d83bb pbrook
10 2e5d83bb pbrook
#include "vl.h"
11 2e5d83bb pbrook
12 2e5d83bb pbrook
//#define DEBUG_MSD
13 2e5d83bb pbrook
14 2e5d83bb pbrook
#ifdef DEBUG_MSD
15 2e5d83bb pbrook
#define DPRINTF(fmt, args...) \
16 2e5d83bb pbrook
do { printf("usb-msd: " fmt , ##args); } while (0)
17 2e5d83bb pbrook
#else
18 2e5d83bb pbrook
#define DPRINTF(fmt, args...) do {} while(0)
19 2e5d83bb pbrook
#endif
20 2e5d83bb pbrook
21 2e5d83bb pbrook
/* USB requests.  */
22 2e5d83bb pbrook
#define MassStorageReset  0xff
23 2e5d83bb pbrook
#define GetMaxLun         0xfe
24 2e5d83bb pbrook
25 2e5d83bb pbrook
enum USBMSDMode {
26 2e5d83bb pbrook
    USB_MSDM_CBW, /* Command Block.  */
27 2e5d83bb pbrook
    USB_MSDM_DATAOUT, /* Tranfer data to device.  */
28 2e5d83bb pbrook
    USB_MSDM_DATAIN, /* Transfer data from device.  */
29 2e5d83bb pbrook
    USB_MSDM_CSW /* Command Status.  */
30 2e5d83bb pbrook
};
31 2e5d83bb pbrook
32 2e5d83bb pbrook
typedef struct {
33 2e5d83bb pbrook
    USBDevice dev;
34 2e5d83bb pbrook
    enum USBMSDMode mode;
35 2e5d83bb pbrook
    uint32_t data_len;
36 4d611c9a pbrook
    uint32_t transfer_len;
37 2e5d83bb pbrook
    uint32_t tag;
38 2e5d83bb pbrook
    SCSIDevice *scsi_dev;
39 2e5d83bb pbrook
    int result;
40 4d611c9a pbrook
    /* For async completion.  */
41 4d611c9a pbrook
    USBPacket *packet;
42 2e5d83bb pbrook
} MSDState;
43 2e5d83bb pbrook
44 2e5d83bb pbrook
static const uint8_t qemu_msd_dev_descriptor[] = {
45 2e5d83bb pbrook
        0x12,       /*  u8 bLength; */
46 2e5d83bb pbrook
        0x01,       /*  u8 bDescriptorType; Device */
47 2e5d83bb pbrook
        0x10, 0x00, /*  u16 bcdUSB; v1.0 */
48 2e5d83bb pbrook
49 2e5d83bb pbrook
        0x00,            /*  u8  bDeviceClass; */
50 2e5d83bb pbrook
        0x00,            /*  u8  bDeviceSubClass; */
51 2e5d83bb pbrook
        0x00,       /*  u8  bDeviceProtocol; [ low/full speeds only ] */
52 2e5d83bb pbrook
        0x08,       /*  u8  bMaxPacketSize0; 8 Bytes */
53 2e5d83bb pbrook
54 2e5d83bb pbrook
        /* Vendor and product id are arbitrary.  */
55 2e5d83bb pbrook
        0x00, 0x00, /*  u16 idVendor; */
56 2e5d83bb pbrook
         0x00, 0x00, /*  u16 idProduct; */
57 2e5d83bb pbrook
        0x00, 0x00, /*  u16 bcdDevice */
58 2e5d83bb pbrook
59 2e5d83bb pbrook
        0x01,       /*  u8  iManufacturer; */
60 2e5d83bb pbrook
        0x02,       /*  u8  iProduct; */
61 2e5d83bb pbrook
        0x03,       /*  u8  iSerialNumber; */
62 2e5d83bb pbrook
        0x01        /*  u8  bNumConfigurations; */
63 2e5d83bb pbrook
};
64 2e5d83bb pbrook
65 2e5d83bb pbrook
static const uint8_t qemu_msd_config_descriptor[] = {
66 2e5d83bb pbrook
67 2e5d83bb pbrook
        /* one configuration */
68 2e5d83bb pbrook
        0x09,       /*  u8  bLength; */
69 2e5d83bb pbrook
        0x02,       /*  u8  bDescriptorType; Configuration */
70 2e5d83bb pbrook
        0x20, 0x00, /*  u16 wTotalLength; */
71 2e5d83bb pbrook
        0x01,       /*  u8  bNumInterfaces; (1) */
72 2e5d83bb pbrook
        0x01,       /*  u8  bConfigurationValue; */
73 2e5d83bb pbrook
        0x00,       /*  u8  iConfiguration; */
74 2e5d83bb pbrook
        0xc0,       /*  u8  bmAttributes; 
75 2e5d83bb pbrook
                                 Bit 7: must be set,
76 2e5d83bb pbrook
                                     6: Self-powered,
77 2e5d83bb pbrook
                                     5: Remote wakeup,
78 2e5d83bb pbrook
                                     4..0: resvd */
79 2e5d83bb pbrook
        0x00,       /*  u8  MaxPower; */
80 2e5d83bb pbrook
      
81 2e5d83bb pbrook
        /* one interface */
82 2e5d83bb pbrook
        0x09,       /*  u8  if_bLength; */
83 2e5d83bb pbrook
        0x04,       /*  u8  if_bDescriptorType; Interface */
84 2e5d83bb pbrook
        0x00,       /*  u8  if_bInterfaceNumber; */
85 2e5d83bb pbrook
        0x00,       /*  u8  if_bAlternateSetting; */
86 2e5d83bb pbrook
        0x02,       /*  u8  if_bNumEndpoints; */
87 2e5d83bb pbrook
        0x08,       /*  u8  if_bInterfaceClass; MASS STORAGE */
88 2e5d83bb pbrook
        0x06,       /*  u8  if_bInterfaceSubClass; SCSI */
89 2e5d83bb pbrook
        0x50,       /*  u8  if_bInterfaceProtocol; Bulk Only */
90 2e5d83bb pbrook
        0x00,       /*  u8  if_iInterface; */
91 2e5d83bb pbrook
     
92 2e5d83bb pbrook
        /* Bulk-In endpoint */
93 2e5d83bb pbrook
        0x07,       /*  u8  ep_bLength; */
94 2e5d83bb pbrook
        0x05,       /*  u8  ep_bDescriptorType; Endpoint */
95 2e5d83bb pbrook
        0x81,       /*  u8  ep_bEndpointAddress; IN Endpoint 1 */
96 2e5d83bb pbrook
         0x02,       /*  u8  ep_bmAttributes; Bulk */
97 2e5d83bb pbrook
         0x40, 0x00, /*  u16 ep_wMaxPacketSize; */
98 2e5d83bb pbrook
        0x00,       /*  u8  ep_bInterval; */
99 2e5d83bb pbrook
100 2e5d83bb pbrook
        /* Bulk-Out endpoint */
101 2e5d83bb pbrook
        0x07,       /*  u8  ep_bLength; */
102 2e5d83bb pbrook
        0x05,       /*  u8  ep_bDescriptorType; Endpoint */
103 2e5d83bb pbrook
        0x02,       /*  u8  ep_bEndpointAddress; OUT Endpoint 2 */
104 2e5d83bb pbrook
         0x02,       /*  u8  ep_bmAttributes; Bulk */
105 2e5d83bb pbrook
         0x40, 0x00, /*  u16 ep_wMaxPacketSize; */
106 2e5d83bb pbrook
        0x00        /*  u8  ep_bInterval; */
107 2e5d83bb pbrook
};
108 2e5d83bb pbrook
109 4d611c9a pbrook
static void usb_msd_command_complete(void *opaque, uint32_t reason, int fail)
110 2e5d83bb pbrook
{
111 2e5d83bb pbrook
    MSDState *s = (MSDState *)opaque;
112 4d611c9a pbrook
    USBPacket *p;
113 4d611c9a pbrook
114 4d611c9a pbrook
    s->data_len -= s->transfer_len;
115 4d611c9a pbrook
    s->transfer_len = 0;
116 4d611c9a pbrook
    if (reason == SCSI_REASON_DONE) {
117 4d611c9a pbrook
        DPRINTF("Command complete %d\n", fail);
118 4d611c9a pbrook
        s->result = fail;
119 4d611c9a pbrook
        s->mode = USB_MSDM_CSW;
120 4d611c9a pbrook
    }
121 4d611c9a pbrook
    if (s->packet) {
122 4d611c9a pbrook
        /* Set s->packet to NULL before calling usb_packet_complete because
123 4d611c9a pbrook
           annother request may be issues before usb_packet_complete returns.
124 4d611c9a pbrook
         */
125 4d611c9a pbrook
        DPRINTF("Packet complete %p\n", p);
126 4d611c9a pbrook
        p = s->packet;
127 4d611c9a pbrook
        s->packet = NULL;
128 4d611c9a pbrook
        usb_packet_complete(p);
129 4d611c9a pbrook
    }
130 2e5d83bb pbrook
}
131 2e5d83bb pbrook
132 059809e4 bellard
static void usb_msd_handle_reset(USBDevice *dev)
133 2e5d83bb pbrook
{
134 2e5d83bb pbrook
    MSDState *s = (MSDState *)dev;
135 2e5d83bb pbrook
136 2e5d83bb pbrook
    DPRINTF("Reset\n");
137 2e5d83bb pbrook
    s->mode = USB_MSDM_CBW;
138 2e5d83bb pbrook
}
139 2e5d83bb pbrook
140 2e5d83bb pbrook
static int usb_msd_handle_control(USBDevice *dev, int request, int value,
141 2e5d83bb pbrook
                                  int index, int length, uint8_t *data)
142 2e5d83bb pbrook
{
143 2e5d83bb pbrook
    MSDState *s = (MSDState *)dev;
144 2e5d83bb pbrook
    int ret = 0;
145 2e5d83bb pbrook
146 2e5d83bb pbrook
    switch (request) {
147 2e5d83bb pbrook
    case DeviceRequest | USB_REQ_GET_STATUS:
148 2e5d83bb pbrook
        data[0] = (1 << USB_DEVICE_SELF_POWERED) |
149 2e5d83bb pbrook
            (dev->remote_wakeup << USB_DEVICE_REMOTE_WAKEUP);
150 2e5d83bb pbrook
        data[1] = 0x00;
151 2e5d83bb pbrook
        ret = 2;
152 2e5d83bb pbrook
        break;
153 2e5d83bb pbrook
    case DeviceOutRequest | USB_REQ_CLEAR_FEATURE:
154 2e5d83bb pbrook
        if (value == USB_DEVICE_REMOTE_WAKEUP) {
155 2e5d83bb pbrook
            dev->remote_wakeup = 0;
156 2e5d83bb pbrook
        } else {
157 2e5d83bb pbrook
            goto fail;
158 2e5d83bb pbrook
        }
159 2e5d83bb pbrook
        ret = 0;
160 2e5d83bb pbrook
        break;
161 2e5d83bb pbrook
    case DeviceOutRequest | USB_REQ_SET_FEATURE:
162 2e5d83bb pbrook
        if (value == USB_DEVICE_REMOTE_WAKEUP) {
163 2e5d83bb pbrook
            dev->remote_wakeup = 1;
164 2e5d83bb pbrook
        } else {
165 2e5d83bb pbrook
            goto fail;
166 2e5d83bb pbrook
        }
167 2e5d83bb pbrook
        ret = 0;
168 2e5d83bb pbrook
        break;
169 2e5d83bb pbrook
    case DeviceOutRequest | USB_REQ_SET_ADDRESS:
170 2e5d83bb pbrook
        dev->addr = value;
171 2e5d83bb pbrook
        ret = 0;
172 2e5d83bb pbrook
        break;
173 2e5d83bb pbrook
    case DeviceRequest | USB_REQ_GET_DESCRIPTOR:
174 2e5d83bb pbrook
        switch(value >> 8) {
175 2e5d83bb pbrook
        case USB_DT_DEVICE:
176 2e5d83bb pbrook
            memcpy(data, qemu_msd_dev_descriptor, 
177 2e5d83bb pbrook
                   sizeof(qemu_msd_dev_descriptor));
178 2e5d83bb pbrook
            ret = sizeof(qemu_msd_dev_descriptor);
179 2e5d83bb pbrook
            break;
180 2e5d83bb pbrook
        case USB_DT_CONFIG:
181 2e5d83bb pbrook
            memcpy(data, qemu_msd_config_descriptor, 
182 2e5d83bb pbrook
                   sizeof(qemu_msd_config_descriptor));
183 2e5d83bb pbrook
            ret = sizeof(qemu_msd_config_descriptor);
184 2e5d83bb pbrook
            break;
185 2e5d83bb pbrook
        case USB_DT_STRING:
186 2e5d83bb pbrook
            switch(value & 0xff) {
187 2e5d83bb pbrook
            case 0:
188 2e5d83bb pbrook
                /* language ids */
189 2e5d83bb pbrook
                data[0] = 4;
190 2e5d83bb pbrook
                data[1] = 3;
191 2e5d83bb pbrook
                data[2] = 0x09;
192 2e5d83bb pbrook
                data[3] = 0x04;
193 2e5d83bb pbrook
                ret = 4;
194 2e5d83bb pbrook
                break;
195 2e5d83bb pbrook
            case 1:
196 2e5d83bb pbrook
                /* vendor description */
197 2e5d83bb pbrook
                ret = set_usb_string(data, "QEMU " QEMU_VERSION);
198 2e5d83bb pbrook
                break;
199 2e5d83bb pbrook
            case 2:
200 2e5d83bb pbrook
                /* product description */
201 2e5d83bb pbrook
                ret = set_usb_string(data, "QEMU USB HARDDRIVE");
202 2e5d83bb pbrook
                break;
203 2e5d83bb pbrook
            case 3:
204 2e5d83bb pbrook
                /* serial number */
205 2e5d83bb pbrook
                ret = set_usb_string(data, "1");
206 2e5d83bb pbrook
                break;
207 2e5d83bb pbrook
            default:
208 2e5d83bb pbrook
                goto fail;
209 2e5d83bb pbrook
            }
210 2e5d83bb pbrook
            break;
211 2e5d83bb pbrook
        default:
212 2e5d83bb pbrook
            goto fail;
213 2e5d83bb pbrook
        }
214 2e5d83bb pbrook
        break;
215 2e5d83bb pbrook
    case DeviceRequest | USB_REQ_GET_CONFIGURATION:
216 2e5d83bb pbrook
        data[0] = 1;
217 2e5d83bb pbrook
        ret = 1;
218 2e5d83bb pbrook
        break;
219 2e5d83bb pbrook
    case DeviceOutRequest | USB_REQ_SET_CONFIGURATION:
220 2e5d83bb pbrook
        ret = 0;
221 2e5d83bb pbrook
        break;
222 2e5d83bb pbrook
    case DeviceRequest | USB_REQ_GET_INTERFACE:
223 2e5d83bb pbrook
        data[0] = 0;
224 2e5d83bb pbrook
        ret = 1;
225 2e5d83bb pbrook
        break;
226 2e5d83bb pbrook
    case DeviceOutRequest | USB_REQ_SET_INTERFACE:
227 2e5d83bb pbrook
        ret = 0;
228 2e5d83bb pbrook
        break;
229 2e5d83bb pbrook
    case EndpointOutRequest | USB_REQ_CLEAR_FEATURE:
230 2e5d83bb pbrook
        if (value == 0 && index != 0x81) { /* clear ep halt */
231 2e5d83bb pbrook
            goto fail;
232 2e5d83bb pbrook
        }
233 2e5d83bb pbrook
        ret = 0;
234 2e5d83bb pbrook
        break;
235 2e5d83bb pbrook
        /* Class specific requests.  */
236 2e5d83bb pbrook
    case MassStorageReset:
237 2e5d83bb pbrook
        /* Reset state ready for the next CBW.  */
238 2e5d83bb pbrook
        s->mode = USB_MSDM_CBW;
239 2e5d83bb pbrook
        ret = 0;
240 2e5d83bb pbrook
        break;
241 2e5d83bb pbrook
    case GetMaxLun:
242 2e5d83bb pbrook
        data[0] = 0;
243 2e5d83bb pbrook
        ret = 1;
244 2e5d83bb pbrook
        break;
245 2e5d83bb pbrook
    default:
246 2e5d83bb pbrook
    fail:
247 2e5d83bb pbrook
        ret = USB_RET_STALL;
248 2e5d83bb pbrook
        break;
249 2e5d83bb pbrook
    }
250 2e5d83bb pbrook
    return ret;
251 2e5d83bb pbrook
}
252 2e5d83bb pbrook
253 2e5d83bb pbrook
struct usb_msd_cbw {
254 2e5d83bb pbrook
    uint32_t sig;
255 2e5d83bb pbrook
    uint32_t tag;
256 2e5d83bb pbrook
    uint32_t data_len;
257 2e5d83bb pbrook
    uint8_t flags;
258 2e5d83bb pbrook
    uint8_t lun;
259 2e5d83bb pbrook
    uint8_t cmd_len;
260 2e5d83bb pbrook
    uint8_t cmd[16];
261 2e5d83bb pbrook
};
262 2e5d83bb pbrook
263 2e5d83bb pbrook
struct usb_msd_csw {
264 2e5d83bb pbrook
    uint32_t sig;
265 2e5d83bb pbrook
    uint32_t tag;
266 2e5d83bb pbrook
    uint32_t residue;
267 2e5d83bb pbrook
    uint8_t status;
268 2e5d83bb pbrook
};
269 2e5d83bb pbrook
270 4d611c9a pbrook
static void usb_msd_cancel_io(USBPacket *p, void *opaque)
271 4d611c9a pbrook
{
272 4d611c9a pbrook
    MSDState *s = opaque;
273 4d611c9a pbrook
    scsi_cancel_io(s->scsi_dev);
274 4d611c9a pbrook
    s->packet = NULL;
275 4d611c9a pbrook
}
276 4d611c9a pbrook
277 4d611c9a pbrook
static int usb_msd_handle_data(USBDevice *dev, USBPacket *p)
278 2e5d83bb pbrook
{
279 2e5d83bb pbrook
    MSDState *s = (MSDState *)dev;
280 2e5d83bb pbrook
    int ret = 0;
281 2e5d83bb pbrook
    struct usb_msd_cbw cbw;
282 2e5d83bb pbrook
    struct usb_msd_csw csw;
283 4d611c9a pbrook
    uint8_t devep = p->devep;
284 4d611c9a pbrook
    uint8_t *data = p->data;
285 4d611c9a pbrook
    int len = p->len;
286 2e5d83bb pbrook
287 4d611c9a pbrook
    switch (p->pid) {
288 2e5d83bb pbrook
    case USB_TOKEN_OUT:
289 2e5d83bb pbrook
        if (devep != 2)
290 2e5d83bb pbrook
            goto fail;
291 2e5d83bb pbrook
292 2e5d83bb pbrook
        switch (s->mode) {
293 2e5d83bb pbrook
        case USB_MSDM_CBW:
294 2e5d83bb pbrook
            if (len != 31) {
295 2e5d83bb pbrook
                fprintf(stderr, "usb-msd: Bad CBW size");
296 2e5d83bb pbrook
                goto fail;
297 2e5d83bb pbrook
            }
298 2e5d83bb pbrook
            memcpy(&cbw, data, 31);
299 2e5d83bb pbrook
            if (le32_to_cpu(cbw.sig) != 0x43425355) {
300 2e5d83bb pbrook
                fprintf(stderr, "usb-msd: Bad signature %08x\n",
301 2e5d83bb pbrook
                        le32_to_cpu(cbw.sig));
302 2e5d83bb pbrook
                goto fail;
303 2e5d83bb pbrook
            }
304 2e5d83bb pbrook
            DPRINTF("Command on LUN %d\n", cbw.lun);
305 2e5d83bb pbrook
            if (cbw.lun != 0) {
306 2e5d83bb pbrook
                fprintf(stderr, "usb-msd: Bad LUN %d\n", cbw.lun);
307 2e5d83bb pbrook
                goto fail;
308 2e5d83bb pbrook
            }
309 2e5d83bb pbrook
            s->tag = le32_to_cpu(cbw.tag);
310 2e5d83bb pbrook
            s->data_len = le32_to_cpu(cbw.data_len);
311 2e5d83bb pbrook
            if (s->data_len == 0) {
312 2e5d83bb pbrook
                s->mode = USB_MSDM_CSW;
313 2e5d83bb pbrook
            } else if (cbw.flags & 0x80) {
314 2e5d83bb pbrook
                s->mode = USB_MSDM_DATAIN;
315 2e5d83bb pbrook
            } else {
316 2e5d83bb pbrook
                s->mode = USB_MSDM_DATAOUT;
317 2e5d83bb pbrook
            }
318 2e5d83bb pbrook
            DPRINTF("Command tag 0x%x flags %08x len %d data %d\n",
319 2e5d83bb pbrook
                    s->tag, cbw.flags, cbw.cmd_len, s->data_len);
320 0fc5c15a pbrook
            scsi_send_command(s->scsi_dev, s->tag, cbw.cmd, 0);
321 2e5d83bb pbrook
            ret = len;
322 2e5d83bb pbrook
            break;
323 2e5d83bb pbrook
324 2e5d83bb pbrook
        case USB_MSDM_DATAOUT:
325 2e5d83bb pbrook
            DPRINTF("Data out %d/%d\n", len, s->data_len);
326 2e5d83bb pbrook
            if (len > s->data_len)
327 2e5d83bb pbrook
                goto fail;
328 2e5d83bb pbrook
329 4d611c9a pbrook
            s->transfer_len = len;
330 2e5d83bb pbrook
            if (scsi_write_data(s->scsi_dev, data, len))
331 2e5d83bb pbrook
                goto fail;
332 2e5d83bb pbrook
333 4d611c9a pbrook
            if (s->transfer_len == 0) {
334 4d611c9a pbrook
                ret = len;
335 4d611c9a pbrook
            } else {
336 4d611c9a pbrook
                DPRINTF("Deferring packet %p\n", p);
337 4d611c9a pbrook
                usb_defer_packet(p, usb_msd_cancel_io, s);
338 4d611c9a pbrook
                s->packet = p;
339 4d611c9a pbrook
                ret = USB_RET_ASYNC;
340 4d611c9a pbrook
            }
341 2e5d83bb pbrook
            break;
342 2e5d83bb pbrook
343 2e5d83bb pbrook
        default:
344 2e5d83bb pbrook
            DPRINTF("Unexpected write (len %d)\n", len);
345 2e5d83bb pbrook
            goto fail;
346 2e5d83bb pbrook
        }
347 2e5d83bb pbrook
        break;
348 2e5d83bb pbrook
349 2e5d83bb pbrook
    case USB_TOKEN_IN:
350 2e5d83bb pbrook
        if (devep != 1)
351 2e5d83bb pbrook
            goto fail;
352 2e5d83bb pbrook
353 2e5d83bb pbrook
        switch (s->mode) {
354 2e5d83bb pbrook
        case USB_MSDM_CSW:
355 2e5d83bb pbrook
            DPRINTF("Command status %d tag 0x%x, len %d\n",
356 2e5d83bb pbrook
                    s->result, s->tag, len);
357 2e5d83bb pbrook
            if (len < 13)
358 2e5d83bb pbrook
                goto fail;
359 2e5d83bb pbrook
360 2e5d83bb pbrook
            csw.sig = cpu_to_le32(0x53425355);
361 2e5d83bb pbrook
            csw.tag = cpu_to_le32(s->tag);
362 2e5d83bb pbrook
            csw.residue = 0;
363 2e5d83bb pbrook
            csw.status = s->result;
364 2e5d83bb pbrook
            memcpy(data, &csw, 13);
365 2e5d83bb pbrook
            ret = 13;
366 2e5d83bb pbrook
            s->mode = USB_MSDM_CBW;
367 2e5d83bb pbrook
            break;
368 2e5d83bb pbrook
369 2e5d83bb pbrook
        case USB_MSDM_DATAIN:
370 2e5d83bb pbrook
            DPRINTF("Data in %d/%d\n", len, s->data_len);
371 2e5d83bb pbrook
            if (len > s->data_len)
372 2e5d83bb pbrook
                len = s->data_len;
373 2e5d83bb pbrook
374 4d611c9a pbrook
            s->transfer_len = len;
375 2e5d83bb pbrook
            if (scsi_read_data(s->scsi_dev, data, len))
376 2e5d83bb pbrook
                goto fail;
377 2e5d83bb pbrook
378 4d611c9a pbrook
            if (s->transfer_len == 0) {
379 4d611c9a pbrook
                ret = len;
380 4d611c9a pbrook
            } else {
381 4d611c9a pbrook
                DPRINTF("Deferring packet %p\n", p);
382 4d611c9a pbrook
                usb_defer_packet(p, usb_msd_cancel_io, s);
383 4d611c9a pbrook
                s->packet = p;
384 4d611c9a pbrook
                ret = USB_RET_ASYNC;
385 4d611c9a pbrook
            }
386 2e5d83bb pbrook
            break;
387 2e5d83bb pbrook
388 2e5d83bb pbrook
        default:
389 2e5d83bb pbrook
            DPRINTF("Unexpected read (len %d)\n", len);
390 2e5d83bb pbrook
            goto fail;
391 2e5d83bb pbrook
        }
392 2e5d83bb pbrook
        break;
393 2e5d83bb pbrook
394 2e5d83bb pbrook
    default:
395 2e5d83bb pbrook
        DPRINTF("Bad token\n");
396 2e5d83bb pbrook
    fail:
397 2e5d83bb pbrook
        ret = USB_RET_STALL;
398 2e5d83bb pbrook
        break;
399 2e5d83bb pbrook
    }
400 2e5d83bb pbrook
401 2e5d83bb pbrook
    return ret;
402 2e5d83bb pbrook
}
403 2e5d83bb pbrook
404 059809e4 bellard
static void usb_msd_handle_destroy(USBDevice *dev)
405 059809e4 bellard
{
406 059809e4 bellard
    MSDState *s = (MSDState *)dev;
407 059809e4 bellard
408 059809e4 bellard
    scsi_disk_destroy(s->scsi_dev);
409 059809e4 bellard
    qemu_free(s);
410 059809e4 bellard
}
411 2e5d83bb pbrook
412 2e5d83bb pbrook
USBDevice *usb_msd_init(const char *filename)
413 2e5d83bb pbrook
{
414 2e5d83bb pbrook
    MSDState *s;
415 2e5d83bb pbrook
    BlockDriverState *bdrv;
416 2e5d83bb pbrook
417 2e5d83bb pbrook
    s = qemu_mallocz(sizeof(MSDState));
418 2e5d83bb pbrook
    if (!s)
419 2e5d83bb pbrook
        return NULL;
420 2e5d83bb pbrook
421 2e5d83bb pbrook
    bdrv = bdrv_new("usb");
422 2e5d83bb pbrook
    bdrv_open(bdrv, filename, 0);
423 2e5d83bb pbrook
424 2e5d83bb pbrook
    s->dev.speed = USB_SPEED_FULL;
425 2e5d83bb pbrook
    s->dev.handle_packet = usb_generic_handle_packet;
426 2e5d83bb pbrook
427 2e5d83bb pbrook
    s->dev.handle_reset = usb_msd_handle_reset;
428 2e5d83bb pbrook
    s->dev.handle_control = usb_msd_handle_control;
429 2e5d83bb pbrook
    s->dev.handle_data = usb_msd_handle_data;
430 059809e4 bellard
    s->dev.handle_destroy = usb_msd_handle_destroy;
431 2e5d83bb pbrook
432 1f6e24e7 bellard
    snprintf(s->dev.devname, sizeof(s->dev.devname), "QEMU USB MSD(%.16s)",
433 1f6e24e7 bellard
             filename);
434 1f6e24e7 bellard
435 2e5d83bb pbrook
    s->scsi_dev = scsi_disk_init(bdrv, usb_msd_command_complete, s);
436 059809e4 bellard
    usb_msd_handle_reset((USBDevice *)s);
437 2e5d83bb pbrook
    return (USBDevice *)s;
438 2e5d83bb pbrook
}