]> git.proxmox.com Git - mirror_qemu.git/blame - hw/usb-msd.c
fix QemuOpts leak
[mirror_qemu.git] / hw / usb-msd.c
CommitLineData
5fafdf24 1/*
2e5d83bb
PB
2 * USB Mass Storage Device emulation
3 *
4 * Copyright (c) 2006 CodeSourcery.
5 * Written by Paul Brook
6 *
7 * This code is licenced under the LGPL.
8 */
9
87ecb68b 10#include "qemu-common.h"
7fc2f2c0
GH
11#include "qemu-option.h"
12#include "qemu-config.h"
87ecb68b 13#include "usb.h"
81bfd2f2 14#include "usb-desc.h"
43b443b6 15#include "scsi.h"
c0f4ce77 16#include "console.h"
b3e461d3 17#include "monitor.h"
666daa68 18#include "sysemu.h"
2446333c 19#include "blockdev.h"
2e5d83bb
PB
20
21//#define DEBUG_MSD
22
23#ifdef DEBUG_MSD
001faf32
BS
24#define DPRINTF(fmt, ...) \
25do { printf("usb-msd: " fmt , ## __VA_ARGS__); } while (0)
2e5d83bb 26#else
001faf32 27#define DPRINTF(fmt, ...) do {} while(0)
2e5d83bb
PB
28#endif
29
30/* USB requests. */
31#define MassStorageReset 0xff
32#define GetMaxLun 0xfe
33
34enum USBMSDMode {
35 USB_MSDM_CBW, /* Command Block. */
36 USB_MSDM_DATAOUT, /* Tranfer data to device. */
37 USB_MSDM_DATAIN, /* Transfer data from device. */
38 USB_MSDM_CSW /* Command Status. */
39};
40
41typedef struct {
42 USBDevice dev;
43 enum USBMSDMode mode;
a917d384
PB
44 uint32_t scsi_len;
45 uint8_t *scsi_buf;
46 uint32_t usb_len;
47 uint8_t *usb_buf;
2e5d83bb 48 uint32_t data_len;
a917d384 49 uint32_t residue;
2e5d83bb 50 uint32_t tag;
ca9c39fa 51 SCSIBus bus;
428c149b 52 BlockConf conf;
2e5d83bb 53 SCSIDevice *scsi_dev;
6bb7b867 54 uint32_t removable;
2e5d83bb 55 int result;
4d611c9a
PB
56 /* For async completion. */
57 USBPacket *packet;
2e5d83bb
PB
58} MSDState;
59
a917d384
PB
60struct usb_msd_cbw {
61 uint32_t sig;
62 uint32_t tag;
63 uint32_t data_len;
64 uint8_t flags;
65 uint8_t lun;
66 uint8_t cmd_len;
67 uint8_t cmd[16];
68};
69
70struct usb_msd_csw {
71 uint32_t sig;
72 uint32_t tag;
73 uint32_t residue;
74 uint8_t status;
75};
76
81bfd2f2
GH
77enum {
78 STR_MANUFACTURER = 1,
79 STR_PRODUCT,
80 STR_SERIALNUMBER,
ca0c730d
GH
81 STR_CONFIG_FULL,
82 STR_CONFIG_HIGH,
2e5d83bb
PB
83};
84
81bfd2f2
GH
85static const USBDescStrings desc_strings = {
86 [STR_MANUFACTURER] = "QEMU " QEMU_VERSION,
87 [STR_PRODUCT] = "QEMU USB HARDDRIVE",
88 [STR_SERIALNUMBER] = "1",
ca0c730d
GH
89 [STR_CONFIG_FULL] = "Full speed config (usb 1.1)",
90 [STR_CONFIG_HIGH] = "High speed config (usb 2.0)",
81bfd2f2
GH
91};
92
ca0c730d 93static const USBDescIface desc_iface_full = {
81bfd2f2
GH
94 .bInterfaceNumber = 0,
95 .bNumEndpoints = 2,
96 .bInterfaceClass = USB_CLASS_MASS_STORAGE,
97 .bInterfaceSubClass = 0x06, /* SCSI */
98 .bInterfaceProtocol = 0x50, /* Bulk */
99 .eps = (USBDescEndpoint[]) {
100 {
101 .bEndpointAddress = USB_DIR_IN | 0x01,
102 .bmAttributes = USB_ENDPOINT_XFER_BULK,
103 .wMaxPacketSize = 64,
104 },{
105 .bEndpointAddress = USB_DIR_OUT | 0x02,
106 .bmAttributes = USB_ENDPOINT_XFER_BULK,
107 .wMaxPacketSize = 64,
108 },
109 }
110};
111
ca0c730d
GH
112static const USBDescDevice desc_device_full = {
113 .bcdUSB = 0x0200,
81bfd2f2
GH
114 .bMaxPacketSize0 = 8,
115 .bNumConfigurations = 1,
116 .confs = (USBDescConfig[]) {
117 {
118 .bNumInterfaces = 1,
119 .bConfigurationValue = 1,
ca0c730d 120 .iConfiguration = STR_CONFIG_FULL,
81bfd2f2 121 .bmAttributes = 0xc0,
ca0c730d
GH
122 .ifs = &desc_iface_full,
123 },
124 },
125};
126
127static const USBDescIface desc_iface_high = {
128 .bInterfaceNumber = 0,
129 .bNumEndpoints = 2,
130 .bInterfaceClass = USB_CLASS_MASS_STORAGE,
131 .bInterfaceSubClass = 0x06, /* SCSI */
132 .bInterfaceProtocol = 0x50, /* Bulk */
133 .eps = (USBDescEndpoint[]) {
134 {
135 .bEndpointAddress = USB_DIR_IN | 0x01,
136 .bmAttributes = USB_ENDPOINT_XFER_BULK,
137 .wMaxPacketSize = 512,
138 },{
139 .bEndpointAddress = USB_DIR_OUT | 0x02,
140 .bmAttributes = USB_ENDPOINT_XFER_BULK,
141 .wMaxPacketSize = 512,
142 },
143 }
144};
145
146static const USBDescDevice desc_device_high = {
147 .bcdUSB = 0x0200,
148 .bMaxPacketSize0 = 64,
149 .bNumConfigurations = 1,
150 .confs = (USBDescConfig[]) {
151 {
152 .bNumInterfaces = 1,
153 .bConfigurationValue = 1,
154 .iConfiguration = STR_CONFIG_HIGH,
155 .bmAttributes = 0xc0,
156 .ifs = &desc_iface_high,
81bfd2f2
GH
157 },
158 },
159};
160
161static const USBDesc desc = {
162 .id = {
163 .idVendor = 0,
164 .idProduct = 0,
165 .bcdDevice = 0,
166 .iManufacturer = STR_MANUFACTURER,
167 .iProduct = STR_PRODUCT,
168 .iSerialNumber = STR_SERIALNUMBER,
169 },
ca0c730d
GH
170 .full = &desc_device_full,
171 .high = &desc_device_high,
81bfd2f2 172 .str = desc_strings,
2e5d83bb
PB
173};
174
a917d384
PB
175static void usb_msd_copy_data(MSDState *s)
176{
177 uint32_t len;
178 len = s->usb_len;
179 if (len > s->scsi_len)
180 len = s->scsi_len;
181 if (s->mode == USB_MSDM_DATAIN) {
182 memcpy(s->usb_buf, s->scsi_buf, len);
183 } else {
184 memcpy(s->scsi_buf, s->usb_buf, len);
185 }
186 s->usb_len -= len;
187 s->scsi_len -= len;
188 s->usb_buf += len;
189 s->scsi_buf += len;
190 s->data_len -= len;
fa7935c1 191 if (s->scsi_len == 0 || s->data_len == 0) {
a917d384 192 if (s->mode == USB_MSDM_DATAIN) {
d52affa7 193 s->scsi_dev->info->read_data(s->scsi_dev, s->tag);
a917d384 194 } else if (s->mode == USB_MSDM_DATAOUT) {
d52affa7 195 s->scsi_dev->info->write_data(s->scsi_dev, s->tag);
a917d384
PB
196 }
197 }
198}
199
ab4797ad 200static void usb_msd_send_status(MSDState *s, USBPacket *p)
a917d384
PB
201{
202 struct usb_msd_csw csw;
ab4797ad 203 int len;
a917d384
PB
204
205 csw.sig = cpu_to_le32(0x53425355);
206 csw.tag = cpu_to_le32(s->tag);
207 csw.residue = s->residue;
208 csw.status = s->result;
ab4797ad
GH
209
210 len = MIN(sizeof(csw), p->len);
211 memcpy(p->data, &csw, len);
a917d384
PB
212}
213
d52affa7 214static void usb_msd_command_complete(SCSIBus *bus, int reason, uint32_t tag,
a917d384 215 uint32_t arg)
2e5d83bb 216{
d52affa7 217 MSDState *s = DO_UPCAST(MSDState, dev.qdev, bus->qbus.parent);
a917d384 218 USBPacket *p = s->packet;
4d611c9a 219
a917d384
PB
220 if (tag != s->tag) {
221 fprintf(stderr, "usb-msd: Unexpected SCSI Tag 0x%x\n", tag);
222 }
4d611c9a 223 if (reason == SCSI_REASON_DONE) {
a917d384
PB
224 DPRINTF("Command complete %d\n", arg);
225 s->residue = s->data_len;
226 s->result = arg != 0;
227 if (s->packet) {
228 if (s->data_len == 0 && s->mode == USB_MSDM_DATAOUT) {
229 /* A deferred packet with no write data remaining must be
230 the status read packet. */
ab4797ad 231 usb_msd_send_status(s, p);
a917d384
PB
232 s->mode = USB_MSDM_CBW;
233 } else {
234 if (s->data_len) {
235 s->data_len -= s->usb_len;
236 if (s->mode == USB_MSDM_DATAIN)
237 memset(s->usb_buf, 0, s->usb_len);
238 s->usb_len = 0;
239 }
240 if (s->data_len == 0)
241 s->mode = USB_MSDM_CSW;
242 }
243 s->packet = NULL;
244 usb_packet_complete(p);
245 } else if (s->data_len == 0) {
246 s->mode = USB_MSDM_CSW;
247 }
248 return;
4d611c9a 249 }
a917d384 250 s->scsi_len = arg;
d52affa7 251 s->scsi_buf = s->scsi_dev->info->get_buf(s->scsi_dev, tag);
a917d384
PB
252 if (p) {
253 usb_msd_copy_data(s);
254 if (s->usb_len == 0) {
255 /* Set s->packet to NULL before calling usb_packet_complete
256 because annother request may be issued before
257 usb_packet_complete returns. */
258 DPRINTF("Packet complete %p\n", p);
259 s->packet = NULL;
260 usb_packet_complete(p);
261 }
4d611c9a 262 }
2e5d83bb
PB
263}
264
059809e4 265static void usb_msd_handle_reset(USBDevice *dev)
2e5d83bb
PB
266{
267 MSDState *s = (MSDState *)dev;
268
269 DPRINTF("Reset\n");
270 s->mode = USB_MSDM_CBW;
2e5d83bb
PB
271}
272
273static int usb_msd_handle_control(USBDevice *dev, int request, int value,
274 int index, int length, uint8_t *data)
275{
276 MSDState *s = (MSDState *)dev;
81bfd2f2 277 int ret;
2e5d83bb 278
81bfd2f2
GH
279 ret = usb_desc_handle_control(dev, request, value, index, length, data);
280 if (ret >= 0) {
281 return ret;
282 }
283
284 ret = 0;
2e5d83bb 285 switch (request) {
2e5d83bb
PB
286 case DeviceRequest | USB_REQ_GET_INTERFACE:
287 data[0] = 0;
288 ret = 1;
289 break;
290 case DeviceOutRequest | USB_REQ_SET_INTERFACE:
291 ret = 0;
292 break;
293 case EndpointOutRequest | USB_REQ_CLEAR_FEATURE:
e5322f76
APR
294 ret = 0;
295 break;
296 case InterfaceOutRequest | USB_REQ_SET_INTERFACE:
2e5d83bb
PB
297 ret = 0;
298 break;
299 /* Class specific requests. */
f3571b1a 300 case ClassInterfaceOutRequest | MassStorageReset:
2e5d83bb
PB
301 /* Reset state ready for the next CBW. */
302 s->mode = USB_MSDM_CBW;
303 ret = 0;
304 break;
f3571b1a 305 case ClassInterfaceRequest | GetMaxLun:
2e5d83bb
PB
306 data[0] = 0;
307 ret = 1;
308 break;
309 default:
2e5d83bb
PB
310 ret = USB_RET_STALL;
311 break;
312 }
313 return ret;
314}
315
4d611c9a
PB
316static void usb_msd_cancel_io(USBPacket *p, void *opaque)
317{
318 MSDState *s = opaque;
d52affa7 319 s->scsi_dev->info->cancel_io(s->scsi_dev, s->tag);
4d611c9a 320 s->packet = NULL;
a917d384 321 s->scsi_len = 0;
4d611c9a
PB
322}
323
324static int usb_msd_handle_data(USBDevice *dev, USBPacket *p)
2e5d83bb
PB
325{
326 MSDState *s = (MSDState *)dev;
327 int ret = 0;
328 struct usb_msd_cbw cbw;
4d611c9a
PB
329 uint8_t devep = p->devep;
330 uint8_t *data = p->data;
331 int len = p->len;
2e5d83bb 332
4d611c9a 333 switch (p->pid) {
2e5d83bb
PB
334 case USB_TOKEN_OUT:
335 if (devep != 2)
336 goto fail;
337
338 switch (s->mode) {
339 case USB_MSDM_CBW:
340 if (len != 31) {
341 fprintf(stderr, "usb-msd: Bad CBW size");
342 goto fail;
343 }
344 memcpy(&cbw, data, 31);
345 if (le32_to_cpu(cbw.sig) != 0x43425355) {
346 fprintf(stderr, "usb-msd: Bad signature %08x\n",
347 le32_to_cpu(cbw.sig));
348 goto fail;
349 }
350 DPRINTF("Command on LUN %d\n", cbw.lun);
351 if (cbw.lun != 0) {
352 fprintf(stderr, "usb-msd: Bad LUN %d\n", cbw.lun);
353 goto fail;
354 }
355 s->tag = le32_to_cpu(cbw.tag);
356 s->data_len = le32_to_cpu(cbw.data_len);
357 if (s->data_len == 0) {
358 s->mode = USB_MSDM_CSW;
359 } else if (cbw.flags & 0x80) {
360 s->mode = USB_MSDM_DATAIN;
361 } else {
362 s->mode = USB_MSDM_DATAOUT;
363 }
364 DPRINTF("Command tag 0x%x flags %08x len %d data %d\n",
365 s->tag, cbw.flags, cbw.cmd_len, s->data_len);
a917d384 366 s->residue = 0;
d52affa7 367 s->scsi_dev->info->send_command(s->scsi_dev, s->tag, cbw.cmd, 0);
a917d384
PB
368 /* ??? Should check that USB and SCSI data transfer
369 directions match. */
370 if (s->residue == 0) {
371 if (s->mode == USB_MSDM_DATAIN) {
d52affa7 372 s->scsi_dev->info->read_data(s->scsi_dev, s->tag);
a917d384 373 } else if (s->mode == USB_MSDM_DATAOUT) {
d52affa7 374 s->scsi_dev->info->write_data(s->scsi_dev, s->tag);
a917d384
PB
375 }
376 }
2e5d83bb
PB
377 ret = len;
378 break;
379
380 case USB_MSDM_DATAOUT:
381 DPRINTF("Data out %d/%d\n", len, s->data_len);
382 if (len > s->data_len)
383 goto fail;
384
a917d384
PB
385 s->usb_buf = data;
386 s->usb_len = len;
387 if (s->scsi_len) {
388 usb_msd_copy_data(s);
389 }
390 if (s->residue && s->usb_len) {
391 s->data_len -= s->usb_len;
392 if (s->data_len == 0)
393 s->mode = USB_MSDM_CSW;
394 s->usb_len = 0;
395 }
396 if (s->usb_len) {
4d611c9a
PB
397 DPRINTF("Deferring packet %p\n", p);
398 usb_defer_packet(p, usb_msd_cancel_io, s);
399 s->packet = p;
400 ret = USB_RET_ASYNC;
a917d384
PB
401 } else {
402 ret = len;
4d611c9a 403 }
2e5d83bb
PB
404 break;
405
406 default:
407 DPRINTF("Unexpected write (len %d)\n", len);
408 goto fail;
409 }
410 break;
411
412 case USB_TOKEN_IN:
413 if (devep != 1)
414 goto fail;
415
416 switch (s->mode) {
a917d384
PB
417 case USB_MSDM_DATAOUT:
418 if (s->data_len != 0 || len < 13)
419 goto fail;
420 /* Waiting for SCSI write to complete. */
421 usb_defer_packet(p, usb_msd_cancel_io, s);
422 s->packet = p;
423 ret = USB_RET_ASYNC;
424 break;
425
2e5d83bb
PB
426 case USB_MSDM_CSW:
427 DPRINTF("Command status %d tag 0x%x, len %d\n",
428 s->result, s->tag, len);
429 if (len < 13)
430 goto fail;
431
ab4797ad 432 usb_msd_send_status(s, p);
2e5d83bb 433 s->mode = USB_MSDM_CBW;
a917d384 434 ret = 13;
2e5d83bb
PB
435 break;
436
437 case USB_MSDM_DATAIN:
fa7935c1 438 DPRINTF("Data in %d/%d, scsi_len %d\n", len, s->data_len, s->scsi_len);
2e5d83bb
PB
439 if (len > s->data_len)
440 len = s->data_len;
a917d384
PB
441 s->usb_buf = data;
442 s->usb_len = len;
443 if (s->scsi_len) {
444 usb_msd_copy_data(s);
445 }
446 if (s->residue && s->usb_len) {
447 s->data_len -= s->usb_len;
448 memset(s->usb_buf, 0, s->usb_len);
449 if (s->data_len == 0)
450 s->mode = USB_MSDM_CSW;
451 s->usb_len = 0;
452 }
453 if (s->usb_len) {
4d611c9a
PB
454 DPRINTF("Deferring packet %p\n", p);
455 usb_defer_packet(p, usb_msd_cancel_io, s);
456 s->packet = p;
457 ret = USB_RET_ASYNC;
a917d384
PB
458 } else {
459 ret = len;
4d611c9a 460 }
2e5d83bb
PB
461 break;
462
463 default:
464 DPRINTF("Unexpected read (len %d)\n", len);
465 goto fail;
466 }
467 break;
468
469 default:
470 DPRINTF("Bad token\n");
471 fail:
472 ret = USB_RET_STALL;
473 break;
474 }
475
476 return ret;
477}
478
b3e461d3
GH
479static void usb_msd_password_cb(void *opaque, int err)
480{
481 MSDState *s = opaque;
482
483 if (!err)
484 usb_device_attach(&s->dev);
485 else
486 qdev_unplug(&s->dev.qdev);
487}
488
806b6024
GH
489static int usb_msd_initfn(USBDevice *dev)
490{
491 MSDState *s = DO_UPCAST(MSDState, dev, dev);
f8b6cc00 492 BlockDriverState *bs = s->conf.bs;
4a1e1bc4 493 DriveInfo *dinfo;
806b6024 494
f8b6cc00 495 if (!bs) {
1ecda02b 496 error_report("usb-msd: drive property not set");
7fc2f2c0
GH
497 return -1;
498 }
499
14bafc54
MA
500 /*
501 * Hack alert: this pretends to be a block device, but it's really
502 * a SCSI bus that can serve only a single device, which it
18846dee
MA
503 * creates automatically. But first it needs to detach from its
504 * blockdev, or else scsi_bus_legacy_add_drive() dies when it
505 * attaches again.
14bafc54
MA
506 *
507 * The hack is probably a bad idea.
508 */
18846dee 509 bdrv_detach(bs, &s->dev.qdev);
f8b6cc00 510 s->conf.bs = NULL;
14bafc54 511
4a1e1bc4
GH
512 dinfo = drive_get_by_blockdev(bs);
513 if (dinfo && dinfo->serial) {
514 usb_desc_set_string(dev, STR_SERIALNUMBER, dinfo->serial);
515 }
516
a980a065 517 usb_desc_init(dev);
ca9c39fa 518 scsi_bus_new(&s->bus, &s->dev.qdev, 0, 1, usb_msd_command_complete);
6bb7b867 519 s->scsi_dev = scsi_bus_legacy_add_drive(&s->bus, bs, 0, !!s->removable);
fa66b909
MA
520 if (!s->scsi_dev) {
521 return -1;
522 }
cb23117b 523 s->bus.qbus.allow_hotplug = 0;
7fc2f2c0 524 usb_msd_handle_reset(dev);
b3e461d3 525
f8b6cc00 526 if (bdrv_key_required(bs)) {
a4426488 527 if (cur_mon) {
f8b6cc00 528 monitor_read_bdrv_key_start(cur_mon, bs, usb_msd_password_cb, s);
b3e461d3
GH
529 s->dev.auto_attach = 0;
530 } else {
531 autostart = 0;
532 }
533 }
534
806b6024
GH
535 return 0;
536}
537
b3e461d3 538static USBDevice *usb_msd_init(const char *filename)
2e5d83bb 539{
7fc2f2c0
GH
540 static int nr=0;
541 char id[8];
542 QemuOpts *opts;
543 DriveInfo *dinfo;
806b6024 544 USBDevice *dev;
334c0241
AJ
545 const char *p1;
546 char fmt[32];
547
7fc2f2c0
GH
548 /* parse -usbdevice disk: syntax into drive opts */
549 snprintf(id, sizeof(id), "usb%d", nr++);
3329f07b 550 opts = qemu_opts_create(qemu_find_opts("drive"), id, 0);
7fc2f2c0 551
334c0241
AJ
552 p1 = strchr(filename, ':');
553 if (p1++) {
554 const char *p2;
555
556 if (strstart(filename, "format=", &p2)) {
557 int len = MIN(p1 - p2, sizeof(fmt));
558 pstrcpy(fmt, len, p2);
7fc2f2c0 559 qemu_opt_set(opts, "format", fmt);
334c0241
AJ
560 } else if (*filename != ':') {
561 printf("unrecognized USB mass-storage option %s\n", filename);
562 return NULL;
563 }
334c0241
AJ
564 filename = p1;
565 }
334c0241
AJ
566 if (!*filename) {
567 printf("block device specification needed\n");
568 return NULL;
569 }
7fc2f2c0
GH
570 qemu_opt_set(opts, "file", filename);
571 qemu_opt_set(opts, "if", "none");
2e5d83bb 572
7fc2f2c0 573 /* create host drive */
319ae529 574 dinfo = drive_init(opts, 0);
7fc2f2c0
GH
575 if (!dinfo) {
576 qemu_opts_del(opts);
806b6024 577 return NULL;
7fc2f2c0 578 }
2e5d83bb 579
7fc2f2c0 580 /* create guest device */
556cd098 581 dev = usb_create(NULL /* FIXME */, "usb-storage");
d44168ff
PB
582 if (!dev) {
583 return NULL;
584 }
18846dee
MA
585 if (qdev_prop_set_drive(&dev->qdev, "drive", dinfo->bdrv) < 0) {
586 qdev_free(&dev->qdev);
587 return NULL;
588 }
33e66b86
MA
589 if (qdev_init(&dev->qdev) < 0)
590 return NULL;
1f6e24e7 591
7fc2f2c0 592 return dev;
2e5d83bb 593}
bb5fc20f 594
806b6024 595static struct USBDeviceInfo msd_info = {
06384698 596 .product_desc = "QEMU USB MSD",
556cd098 597 .qdev.name = "usb-storage",
806b6024 598 .qdev.size = sizeof(MSDState),
81bfd2f2 599 .usb_desc = &desc,
806b6024
GH
600 .init = usb_msd_initfn,
601 .handle_packet = usb_generic_handle_packet,
ca0c730d 602 .handle_attach = usb_desc_attach,
806b6024
GH
603 .handle_reset = usb_msd_handle_reset,
604 .handle_control = usb_msd_handle_control,
605 .handle_data = usb_msd_handle_data,
b3e461d3
GH
606 .usbdevice_name = "disk",
607 .usbdevice_init = usb_msd_init,
7fc2f2c0 608 .qdev.props = (Property[]) {
428c149b 609 DEFINE_BLOCK_PROPERTIES(MSDState, conf),
6bb7b867 610 DEFINE_PROP_BIT("removable", MSDState, removable, 0, false),
7fc2f2c0
GH
611 DEFINE_PROP_END_OF_LIST(),
612 },
806b6024
GH
613};
614
615static void usb_msd_register_devices(void)
616{
617 usb_qdev_register(&msd_info);
618}
619device_init(usb_msd_register_devices)