Statistics
| Branch: | Revision:

root / hw / scsi-bus.c @ ad2d30f7

History | View | Annotate | Download (16.6 kB)

1
#include "hw.h"
2
#include "qemu-error.h"
3
#include "scsi.h"
4
#include "scsi-defs.h"
5
#include "qdev.h"
6
#include "blockdev.h"
7
#include "trace.h"
8

    
9
static char *scsibus_get_fw_dev_path(DeviceState *dev);
10

    
11
static struct BusInfo scsi_bus_info = {
12
    .name  = "SCSI",
13
    .size  = sizeof(SCSIBus),
14
    .get_fw_dev_path = scsibus_get_fw_dev_path,
15
    .props = (Property[]) {
16
        DEFINE_PROP_UINT32("scsi-id", SCSIDevice, id, -1),
17
        DEFINE_PROP_END_OF_LIST(),
18
    },
19
};
20
static int next_scsi_bus;
21

    
22
/* Create a scsi bus, and attach devices to it.  */
23
void scsi_bus_new(SCSIBus *bus, DeviceState *host, int tcq, int ndev,
24
                  const SCSIBusOps *ops)
25
{
26
    qbus_create_inplace(&bus->qbus, &scsi_bus_info, host, NULL);
27
    bus->busnr = next_scsi_bus++;
28
    bus->tcq = tcq;
29
    bus->ndev = ndev;
30
    bus->ops = ops;
31
    bus->qbus.allow_hotplug = 1;
32
}
33

    
34
static int scsi_qdev_init(DeviceState *qdev, DeviceInfo *base)
35
{
36
    SCSIDevice *dev = DO_UPCAST(SCSIDevice, qdev, qdev);
37
    SCSIDeviceInfo *info = DO_UPCAST(SCSIDeviceInfo, qdev, base);
38
    SCSIBus *bus = DO_UPCAST(SCSIBus, qbus, dev->qdev.parent_bus);
39
    int rc = -1;
40

    
41
    if (dev->id == -1) {
42
        for (dev->id = 0; dev->id < bus->ndev; dev->id++) {
43
            if (bus->devs[dev->id] == NULL)
44
                break;
45
        }
46
    }
47
    if (dev->id >= bus->ndev) {
48
        error_report("bad scsi device id: %d", dev->id);
49
        goto err;
50
    }
51

    
52
    if (bus->devs[dev->id]) {
53
        qdev_free(&bus->devs[dev->id]->qdev);
54
    }
55
    bus->devs[dev->id] = dev;
56

    
57
    dev->info = info;
58
    QTAILQ_INIT(&dev->requests);
59
    rc = dev->info->init(dev);
60
    if (rc != 0) {
61
        bus->devs[dev->id] = NULL;
62
    }
63

    
64
err:
65
    return rc;
66
}
67

    
68
static int scsi_qdev_exit(DeviceState *qdev)
69
{
70
    SCSIDevice *dev = DO_UPCAST(SCSIDevice, qdev, qdev);
71
    SCSIBus *bus = DO_UPCAST(SCSIBus, qbus, dev->qdev.parent_bus);
72

    
73
    assert(bus->devs[dev->id] != NULL);
74
    if (bus->devs[dev->id]->info->destroy) {
75
        bus->devs[dev->id]->info->destroy(bus->devs[dev->id]);
76
    }
77
    bus->devs[dev->id] = NULL;
78
    return 0;
79
}
80

    
81
void scsi_qdev_register(SCSIDeviceInfo *info)
82
{
83
    info->qdev.bus_info = &scsi_bus_info;
84
    info->qdev.init     = scsi_qdev_init;
85
    info->qdev.unplug   = qdev_simple_unplug_cb;
86
    info->qdev.exit     = scsi_qdev_exit;
87
    qdev_register(&info->qdev);
88
}
89

    
90
/* handle legacy '-drive if=scsi,...' cmd line args */
91
SCSIDevice *scsi_bus_legacy_add_drive(SCSIBus *bus, BlockDriverState *bdrv,
92
                                      int unit, bool removable)
93
{
94
    const char *driver;
95
    DeviceState *dev;
96

    
97
    driver = bdrv_is_sg(bdrv) ? "scsi-generic" : "scsi-disk";
98
    dev = qdev_create(&bus->qbus, driver);
99
    qdev_prop_set_uint32(dev, "scsi-id", unit);
100
    if (qdev_prop_exists(dev, "removable")) {
101
        qdev_prop_set_bit(dev, "removable", removable);
102
    }
103
    if (qdev_prop_set_drive(dev, "drive", bdrv) < 0) {
104
        qdev_free(dev);
105
        return NULL;
106
    }
107
    if (qdev_init(dev) < 0)
108
        return NULL;
109
    return DO_UPCAST(SCSIDevice, qdev, dev);
110
}
111

    
112
int scsi_bus_legacy_handle_cmdline(SCSIBus *bus)
113
{
114
    Location loc;
115
    DriveInfo *dinfo;
116
    int res = 0, unit;
117

    
118
    loc_push_none(&loc);
119
    for (unit = 0; unit < bus->ndev; unit++) {
120
        dinfo = drive_get(IF_SCSI, bus->busnr, unit);
121
        if (dinfo == NULL) {
122
            continue;
123
        }
124
        qemu_opts_loc_restore(dinfo->opts);
125
        if (!scsi_bus_legacy_add_drive(bus, dinfo->bdrv, unit, false)) {
126
            res = -1;
127
            break;
128
        }
129
    }
130
    loc_pop(&loc);
131
    return res;
132
}
133

    
134
SCSIRequest *scsi_req_alloc(size_t size, SCSIDevice *d, uint32_t tag, uint32_t lun)
135
{
136
    SCSIRequest *req;
137

    
138
    req = qemu_mallocz(size);
139
    /* Two references: one is passed back to the HBA, one is in d->requests.  */
140
    req->refcount = 2;
141
    req->bus = scsi_bus_from_device(d);
142
    req->dev = d;
143
    req->tag = tag;
144
    req->lun = lun;
145
    req->status = -1;
146
    req->enqueued = true;
147
    trace_scsi_req_alloc(req->dev->id, req->lun, req->tag);
148
    QTAILQ_INSERT_TAIL(&d->requests, req, next);
149
    return req;
150
}
151

    
152
SCSIRequest *scsi_req_find(SCSIDevice *d, uint32_t tag)
153
{
154
    SCSIRequest *req;
155

    
156
    QTAILQ_FOREACH(req, &d->requests, next) {
157
        if (req->tag == tag) {
158
            return req;
159
        }
160
    }
161
    return NULL;
162
}
163

    
164
void scsi_req_dequeue(SCSIRequest *req)
165
{
166
    trace_scsi_req_dequeue(req->dev->id, req->lun, req->tag);
167
    if (req->enqueued) {
168
        QTAILQ_REMOVE(&req->dev->requests, req, next);
169
        req->enqueued = false;
170
        scsi_req_unref(req);
171
    }
172
}
173

    
174
static int scsi_req_length(SCSIRequest *req, uint8_t *cmd)
175
{
176
    switch (cmd[0] >> 5) {
177
    case 0:
178
        req->cmd.xfer = cmd[4];
179
        req->cmd.len = 6;
180
        /* length 0 means 256 blocks */
181
        if (req->cmd.xfer == 0)
182
            req->cmd.xfer = 256;
183
        break;
184
    case 1:
185
    case 2:
186
        req->cmd.xfer = cmd[8] | (cmd[7] << 8);
187
        req->cmd.len = 10;
188
        break;
189
    case 4:
190
        req->cmd.xfer = cmd[13] | (cmd[12] << 8) | (cmd[11] << 16) | (cmd[10] << 24);
191
        req->cmd.len = 16;
192
        break;
193
    case 5:
194
        req->cmd.xfer = cmd[9] | (cmd[8] << 8) | (cmd[7] << 16) | (cmd[6] << 24);
195
        req->cmd.len = 12;
196
        break;
197
    default:
198
        trace_scsi_req_parse_bad(req->dev->id, req->lun, req->tag, cmd[0]);
199
        return -1;
200
    }
201

    
202
    switch(cmd[0]) {
203
    case TEST_UNIT_READY:
204
    case REZERO_UNIT:
205
    case START_STOP:
206
    case SEEK_6:
207
    case WRITE_FILEMARKS:
208
    case SPACE:
209
    case RESERVE:
210
    case RELEASE:
211
    case ERASE:
212
    case ALLOW_MEDIUM_REMOVAL:
213
    case VERIFY:
214
    case SEEK_10:
215
    case SYNCHRONIZE_CACHE:
216
    case LOCK_UNLOCK_CACHE:
217
    case LOAD_UNLOAD:
218
    case SET_CD_SPEED:
219
    case SET_LIMITS:
220
    case WRITE_LONG:
221
    case MOVE_MEDIUM:
222
    case UPDATE_BLOCK:
223
        req->cmd.xfer = 0;
224
        break;
225
    case MODE_SENSE:
226
        break;
227
    case WRITE_SAME:
228
        req->cmd.xfer = 1;
229
        break;
230
    case READ_CAPACITY:
231
        req->cmd.xfer = 8;
232
        break;
233
    case READ_BLOCK_LIMITS:
234
        req->cmd.xfer = 6;
235
        break;
236
    case READ_POSITION:
237
        req->cmd.xfer = 20;
238
        break;
239
    case SEND_VOLUME_TAG:
240
        req->cmd.xfer *= 40;
241
        break;
242
    case MEDIUM_SCAN:
243
        req->cmd.xfer *= 8;
244
        break;
245
    case WRITE_10:
246
    case WRITE_VERIFY:
247
    case WRITE_6:
248
    case WRITE_12:
249
    case WRITE_VERIFY_12:
250
    case WRITE_16:
251
    case WRITE_VERIFY_16:
252
        req->cmd.xfer *= req->dev->blocksize;
253
        break;
254
    case READ_10:
255
    case READ_6:
256
    case READ_REVERSE:
257
    case RECOVER_BUFFERED_DATA:
258
    case READ_12:
259
    case READ_16:
260
        req->cmd.xfer *= req->dev->blocksize;
261
        break;
262
    case INQUIRY:
263
        req->cmd.xfer = cmd[4] | (cmd[3] << 8);
264
        break;
265
    case MAINTENANCE_OUT:
266
    case MAINTENANCE_IN:
267
        if (req->dev->type == TYPE_ROM) {
268
            /* GPCMD_REPORT_KEY and GPCMD_SEND_KEY from multi media commands */
269
            req->cmd.xfer = cmd[9] | (cmd[8] << 8);
270
        }
271
        break;
272
    }
273
    return 0;
274
}
275

    
276
static int scsi_req_stream_length(SCSIRequest *req, uint8_t *cmd)
277
{
278
    switch(cmd[0]) {
279
    /* stream commands */
280
    case READ_6:
281
    case READ_REVERSE:
282
    case RECOVER_BUFFERED_DATA:
283
    case WRITE_6:
284
        req->cmd.len = 6;
285
        req->cmd.xfer = cmd[4] | (cmd[3] << 8) | (cmd[2] << 16);
286
        if (cmd[1] & 0x01) /* fixed */
287
            req->cmd.xfer *= req->dev->blocksize;
288
        break;
289
    case REWIND:
290
    case START_STOP:
291
        req->cmd.len = 6;
292
        req->cmd.xfer = 0;
293
        break;
294
    /* generic commands */
295
    default:
296
        return scsi_req_length(req, cmd);
297
    }
298
    return 0;
299
}
300

    
301
static void scsi_req_xfer_mode(SCSIRequest *req)
302
{
303
    switch (req->cmd.buf[0]) {
304
    case WRITE_6:
305
    case WRITE_10:
306
    case WRITE_VERIFY:
307
    case WRITE_12:
308
    case WRITE_VERIFY_12:
309
    case WRITE_16:
310
    case WRITE_VERIFY_16:
311
    case COPY:
312
    case COPY_VERIFY:
313
    case COMPARE:
314
    case CHANGE_DEFINITION:
315
    case LOG_SELECT:
316
    case MODE_SELECT:
317
    case MODE_SELECT_10:
318
    case SEND_DIAGNOSTIC:
319
    case WRITE_BUFFER:
320
    case FORMAT_UNIT:
321
    case REASSIGN_BLOCKS:
322
    case SEARCH_EQUAL:
323
    case SEARCH_HIGH:
324
    case SEARCH_LOW:
325
    case UPDATE_BLOCK:
326
    case WRITE_LONG:
327
    case WRITE_SAME:
328
    case SEARCH_HIGH_12:
329
    case SEARCH_EQUAL_12:
330
    case SEARCH_LOW_12:
331
    case SET_WINDOW:
332
    case MEDIUM_SCAN:
333
    case SEND_VOLUME_TAG:
334
    case WRITE_LONG_2:
335
    case PERSISTENT_RESERVE_OUT:
336
    case MAINTENANCE_OUT:
337
        req->cmd.mode = SCSI_XFER_TO_DEV;
338
        break;
339
    default:
340
        if (req->cmd.xfer)
341
            req->cmd.mode = SCSI_XFER_FROM_DEV;
342
        else {
343
            req->cmd.mode = SCSI_XFER_NONE;
344
        }
345
        break;
346
    }
347
}
348

    
349
static uint64_t scsi_req_lba(SCSIRequest *req)
350
{
351
    uint8_t *buf = req->cmd.buf;
352
    uint64_t lba;
353

    
354
    switch (buf[0] >> 5) {
355
    case 0:
356
        lba = (uint64_t) buf[3] | ((uint64_t) buf[2] << 8) |
357
              (((uint64_t) buf[1] & 0x1f) << 16);
358
        break;
359
    case 1:
360
    case 2:
361
        lba = (uint64_t) buf[5] | ((uint64_t) buf[4] << 8) |
362
              ((uint64_t) buf[3] << 16) | ((uint64_t) buf[2] << 24);
363
        break;
364
    case 4:
365
        lba = (uint64_t) buf[9] | ((uint64_t) buf[8] << 8) |
366
              ((uint64_t) buf[7] << 16) | ((uint64_t) buf[6] << 24) |
367
              ((uint64_t) buf[5] << 32) | ((uint64_t) buf[4] << 40) |
368
              ((uint64_t) buf[3] << 48) | ((uint64_t) buf[2] << 56);
369
        break;
370
    case 5:
371
        lba = (uint64_t) buf[5] | ((uint64_t) buf[4] << 8) |
372
              ((uint64_t) buf[3] << 16) | ((uint64_t) buf[2] << 24);
373
        break;
374
    default:
375
        lba = -1;
376

    
377
    }
378
    return lba;
379
}
380

    
381
int scsi_req_parse(SCSIRequest *req, uint8_t *buf)
382
{
383
    int rc;
384

    
385
    if (req->dev->type == TYPE_TAPE) {
386
        rc = scsi_req_stream_length(req, buf);
387
    } else {
388
        rc = scsi_req_length(req, buf);
389
    }
390
    if (rc != 0)
391
        return rc;
392

    
393
    memcpy(req->cmd.buf, buf, req->cmd.len);
394
    scsi_req_xfer_mode(req);
395
    req->cmd.lba = scsi_req_lba(req);
396
    trace_scsi_req_parsed(req->dev->id, req->lun, req->tag, buf[0],
397
                          req->cmd.mode, req->cmd.xfer, req->cmd.lba);
398
    return 0;
399
}
400

    
401
static const char *scsi_command_name(uint8_t cmd)
402
{
403
    static const char *names[] = {
404
        [ TEST_UNIT_READY          ] = "TEST_UNIT_READY",
405
        [ REZERO_UNIT              ] = "REZERO_UNIT",
406
        /* REWIND and REZERO_UNIT use the same operation code */
407
        [ REQUEST_SENSE            ] = "REQUEST_SENSE",
408
        [ FORMAT_UNIT              ] = "FORMAT_UNIT",
409
        [ READ_BLOCK_LIMITS        ] = "READ_BLOCK_LIMITS",
410
        [ REASSIGN_BLOCKS          ] = "REASSIGN_BLOCKS",
411
        [ READ_6                   ] = "READ_6",
412
        [ WRITE_6                  ] = "WRITE_6",
413
        [ SEEK_6                   ] = "SEEK_6",
414
        [ READ_REVERSE             ] = "READ_REVERSE",
415
        [ WRITE_FILEMARKS          ] = "WRITE_FILEMARKS",
416
        [ SPACE                    ] = "SPACE",
417
        [ INQUIRY                  ] = "INQUIRY",
418
        [ RECOVER_BUFFERED_DATA    ] = "RECOVER_BUFFERED_DATA",
419
        [ MAINTENANCE_IN           ] = "MAINTENANCE_IN",
420
        [ MAINTENANCE_OUT          ] = "MAINTENANCE_OUT",
421
        [ MODE_SELECT              ] = "MODE_SELECT",
422
        [ RESERVE                  ] = "RESERVE",
423
        [ RELEASE                  ] = "RELEASE",
424
        [ COPY                     ] = "COPY",
425
        [ ERASE                    ] = "ERASE",
426
        [ MODE_SENSE               ] = "MODE_SENSE",
427
        [ START_STOP               ] = "START_STOP",
428
        [ RECEIVE_DIAGNOSTIC       ] = "RECEIVE_DIAGNOSTIC",
429
        [ SEND_DIAGNOSTIC          ] = "SEND_DIAGNOSTIC",
430
        [ ALLOW_MEDIUM_REMOVAL     ] = "ALLOW_MEDIUM_REMOVAL",
431

    
432
        [ SET_WINDOW               ] = "SET_WINDOW",
433
        [ READ_CAPACITY            ] = "READ_CAPACITY",
434
        [ READ_10                  ] = "READ_10",
435
        [ WRITE_10                 ] = "WRITE_10",
436
        [ SEEK_10                  ] = "SEEK_10",
437
        [ WRITE_VERIFY             ] = "WRITE_VERIFY",
438
        [ VERIFY                   ] = "VERIFY",
439
        [ SEARCH_HIGH              ] = "SEARCH_HIGH",
440
        [ SEARCH_EQUAL             ] = "SEARCH_EQUAL",
441
        [ SEARCH_LOW               ] = "SEARCH_LOW",
442
        [ SET_LIMITS               ] = "SET_LIMITS",
443
        [ PRE_FETCH                ] = "PRE_FETCH",
444
        /* READ_POSITION and PRE_FETCH use the same operation code */
445
        [ SYNCHRONIZE_CACHE        ] = "SYNCHRONIZE_CACHE",
446
        [ LOCK_UNLOCK_CACHE        ] = "LOCK_UNLOCK_CACHE",
447
        [ READ_DEFECT_DATA         ] = "READ_DEFECT_DATA",
448
        [ MEDIUM_SCAN              ] = "MEDIUM_SCAN",
449
        [ COMPARE                  ] = "COMPARE",
450
        [ COPY_VERIFY              ] = "COPY_VERIFY",
451
        [ WRITE_BUFFER             ] = "WRITE_BUFFER",
452
        [ READ_BUFFER              ] = "READ_BUFFER",
453
        [ UPDATE_BLOCK             ] = "UPDATE_BLOCK",
454
        [ READ_LONG                ] = "READ_LONG",
455
        [ WRITE_LONG               ] = "WRITE_LONG",
456
        [ CHANGE_DEFINITION        ] = "CHANGE_DEFINITION",
457
        [ WRITE_SAME               ] = "WRITE_SAME",
458
        [ READ_TOC                 ] = "READ_TOC",
459
        [ LOG_SELECT               ] = "LOG_SELECT",
460
        [ LOG_SENSE                ] = "LOG_SENSE",
461
        [ MODE_SELECT_10           ] = "MODE_SELECT_10",
462
        [ RESERVE_10               ] = "RESERVE_10",
463
        [ RELEASE_10               ] = "RELEASE_10",
464
        [ MODE_SENSE_10            ] = "MODE_SENSE_10",
465
        [ PERSISTENT_RESERVE_IN    ] = "PERSISTENT_RESERVE_IN",
466
        [ PERSISTENT_RESERVE_OUT   ] = "PERSISTENT_RESERVE_OUT",
467
        [ MOVE_MEDIUM              ] = "MOVE_MEDIUM",
468
        [ READ_12                  ] = "READ_12",
469
        [ WRITE_12                 ] = "WRITE_12",
470
        [ WRITE_VERIFY_12          ] = "WRITE_VERIFY_12",
471
        [ SEARCH_HIGH_12           ] = "SEARCH_HIGH_12",
472
        [ SEARCH_EQUAL_12          ] = "SEARCH_EQUAL_12",
473
        [ SEARCH_LOW_12            ] = "SEARCH_LOW_12",
474
        [ READ_ELEMENT_STATUS      ] = "READ_ELEMENT_STATUS",
475
        [ SEND_VOLUME_TAG          ] = "SEND_VOLUME_TAG",
476
        [ WRITE_LONG_2             ] = "WRITE_LONG_2",
477

    
478
        [ REPORT_DENSITY_SUPPORT   ] = "REPORT_DENSITY_SUPPORT",
479
        [ GET_CONFIGURATION        ] = "GET_CONFIGURATION",
480
        [ READ_16                  ] = "READ_16",
481
        [ WRITE_16                 ] = "WRITE_16",
482
        [ WRITE_VERIFY_16          ] = "WRITE_VERIFY_16",
483
        [ SERVICE_ACTION_IN        ] = "SERVICE_ACTION_IN",
484
        [ REPORT_LUNS              ] = "REPORT_LUNS",
485
        [ LOAD_UNLOAD              ] = "LOAD_UNLOAD",
486
        [ SET_CD_SPEED             ] = "SET_CD_SPEED",
487
        [ BLANK                    ] = "BLANK",
488
    };
489

    
490
    if (cmd >= ARRAY_SIZE(names) || names[cmd] == NULL)
491
        return "*UNKNOWN*";
492
    return names[cmd];
493
}
494

    
495
SCSIRequest *scsi_req_ref(SCSIRequest *req)
496
{
497
    req->refcount++;
498
    return req;
499
}
500

    
501
void scsi_req_unref(SCSIRequest *req)
502
{
503
    if (--req->refcount == 0) {
504
        if (req->dev->info->free_req) {
505
            req->dev->info->free_req(req);
506
        }
507
        qemu_free(req);
508
    }
509
}
510

    
511
/* Called by the devices when data is ready for the HBA.  The HBA should
512
   start a DMA operation to read or fill the device's data buffer.
513
   Once it completes, calling one of req->dev->info->read_data or
514
   req->dev->info->write_data (depending on the direction of the
515
   transfer) will restart I/O.  */
516
void scsi_req_data(SCSIRequest *req, int len)
517
{
518
    trace_scsi_req_data(req->dev->id, req->lun, req->tag, len);
519
    req->bus->ops->complete(req->bus, SCSI_REASON_DATA, req->tag, len);
520
}
521

    
522
void scsi_req_print(SCSIRequest *req)
523
{
524
    FILE *fp = stderr;
525
    int i;
526

    
527
    fprintf(fp, "[%s id=%d] %s",
528
            req->dev->qdev.parent_bus->name,
529
            req->dev->id,
530
            scsi_command_name(req->cmd.buf[0]));
531
    for (i = 1; i < req->cmd.len; i++) {
532
        fprintf(fp, " 0x%02x", req->cmd.buf[i]);
533
    }
534
    switch (req->cmd.mode) {
535
    case SCSI_XFER_NONE:
536
        fprintf(fp, " - none\n");
537
        break;
538
    case SCSI_XFER_FROM_DEV:
539
        fprintf(fp, " - from-dev len=%zd\n", req->cmd.xfer);
540
        break;
541
    case SCSI_XFER_TO_DEV:
542
        fprintf(fp, " - to-dev len=%zd\n", req->cmd.xfer);
543
        break;
544
    default:
545
        fprintf(fp, " - Oops\n");
546
        break;
547
    }
548
}
549

    
550
void scsi_req_complete(SCSIRequest *req)
551
{
552
    assert(req->status != -1);
553
    scsi_req_ref(req);
554
    scsi_req_dequeue(req);
555
    req->bus->ops->complete(req->bus, SCSI_REASON_DONE,
556
                            req->tag,
557
                            req->status);
558
    scsi_req_unref(req);
559
}
560

    
561
static char *scsibus_get_fw_dev_path(DeviceState *dev)
562
{
563
    SCSIDevice *d = (SCSIDevice*)dev;
564
    SCSIBus *bus = scsi_bus_from_device(d);
565
    char path[100];
566
    int i;
567

    
568
    for (i = 0; i < bus->ndev; i++) {
569
        if (bus->devs[i] == d) {
570
            break;
571
        }
572
    }
573

    
574
    assert(i != bus->ndev);
575

    
576
    snprintf(path, sizeof(path), "%s@%x", qdev_fw_name(dev), i);
577

    
578
    return strdup(path);
579
}