]> git.proxmox.com Git - qemu.git/blame - hw/virtio-scsi.c
Merge remote-tracking branch 'bonzini/scsi-next' into staging
[qemu.git] / hw / virtio-scsi.c
CommitLineData
973abc7f
SH
1/*
2 * Virtio SCSI HBA
3 *
4 * Copyright IBM, Corp. 2010
5 * Copyright Red Hat, Inc. 2011
6 *
7 * Authors:
8 * Stefan Hajnoczi <stefanha@linux.vnet.ibm.com>
9 * Paolo Bonzini <pbonzini@redhat.com>
10 *
11 * This work is licensed under the terms of the GNU GPL, version 2 or later.
12 * See the COPYING file in the top-level directory.
13 *
14 */
15
16#include "virtio-scsi.h"
17#include <hw/scsi.h>
18#include <hw/scsi-defs.h>
19
20#define VIRTIO_SCSI_VQ_SIZE 128
21#define VIRTIO_SCSI_CDB_SIZE 32
22#define VIRTIO_SCSI_SENSE_SIZE 96
23#define VIRTIO_SCSI_MAX_CHANNEL 0
24#define VIRTIO_SCSI_MAX_TARGET 255
25#define VIRTIO_SCSI_MAX_LUN 16383
26
b6866fee
CM
27/* Feature Bits */
28#define VIRTIO_SCSI_F_INOUT 0
29#define VIRTIO_SCSI_F_HOTPLUG 1
feda01e4 30#define VIRTIO_SCSI_F_CHANGE 2
b6866fee 31
973abc7f
SH
32/* Response codes */
33#define VIRTIO_SCSI_S_OK 0
34#define VIRTIO_SCSI_S_OVERRUN 1
35#define VIRTIO_SCSI_S_ABORTED 2
36#define VIRTIO_SCSI_S_BAD_TARGET 3
37#define VIRTIO_SCSI_S_RESET 4
38#define VIRTIO_SCSI_S_BUSY 5
39#define VIRTIO_SCSI_S_TRANSPORT_FAILURE 6
40#define VIRTIO_SCSI_S_TARGET_FAILURE 7
41#define VIRTIO_SCSI_S_NEXUS_FAILURE 8
42#define VIRTIO_SCSI_S_FAILURE 9
43#define VIRTIO_SCSI_S_FUNCTION_SUCCEEDED 10
44#define VIRTIO_SCSI_S_FUNCTION_REJECTED 11
45#define VIRTIO_SCSI_S_INCORRECT_LUN 12
46
47/* Controlq type codes. */
48#define VIRTIO_SCSI_T_TMF 0
49#define VIRTIO_SCSI_T_AN_QUERY 1
50#define VIRTIO_SCSI_T_AN_SUBSCRIBE 2
51
52/* Valid TMF subtypes. */
53#define VIRTIO_SCSI_T_TMF_ABORT_TASK 0
54#define VIRTIO_SCSI_T_TMF_ABORT_TASK_SET 1
55#define VIRTIO_SCSI_T_TMF_CLEAR_ACA 2
56#define VIRTIO_SCSI_T_TMF_CLEAR_TASK_SET 3
57#define VIRTIO_SCSI_T_TMF_I_T_NEXUS_RESET 4
58#define VIRTIO_SCSI_T_TMF_LOGICAL_UNIT_RESET 5
59#define VIRTIO_SCSI_T_TMF_QUERY_TASK 6
60#define VIRTIO_SCSI_T_TMF_QUERY_TASK_SET 7
61
62/* Events. */
63#define VIRTIO_SCSI_T_EVENTS_MISSED 0x80000000
64#define VIRTIO_SCSI_T_NO_EVENT 0
65#define VIRTIO_SCSI_T_TRANSPORT_RESET 1
66#define VIRTIO_SCSI_T_ASYNC_NOTIFY 2
feda01e4 67#define VIRTIO_SCSI_T_PARAM_CHANGE 3
973abc7f 68
b6866fee
CM
69/* Reasons for transport reset event */
70#define VIRTIO_SCSI_EVT_RESET_HARD 0
71#define VIRTIO_SCSI_EVT_RESET_RESCAN 1
72#define VIRTIO_SCSI_EVT_RESET_REMOVED 2
73
973abc7f
SH
74/* SCSI command request, followed by data-out */
75typedef struct {
76 uint8_t lun[8]; /* Logical Unit Number */
77 uint64_t tag; /* Command identifier */
78 uint8_t task_attr; /* Task attribute */
79 uint8_t prio;
80 uint8_t crn;
81 uint8_t cdb[];
82} QEMU_PACKED VirtIOSCSICmdReq;
83
84/* Response, followed by sense data and data-in */
85typedef struct {
86 uint32_t sense_len; /* Sense data length */
87 uint32_t resid; /* Residual bytes in data buffer */
88 uint16_t status_qualifier; /* Status qualifier */
89 uint8_t status; /* Command completion status */
90 uint8_t response; /* Response values */
91 uint8_t sense[];
92} QEMU_PACKED VirtIOSCSICmdResp;
93
94/* Task Management Request */
95typedef struct {
96 uint32_t type;
97 uint32_t subtype;
98 uint8_t lun[8];
99 uint64_t tag;
100} QEMU_PACKED VirtIOSCSICtrlTMFReq;
101
102typedef struct {
103 uint8_t response;
104} QEMU_PACKED VirtIOSCSICtrlTMFResp;
105
106/* Asynchronous notification query/subscription */
107typedef struct {
108 uint32_t type;
109 uint8_t lun[8];
110 uint32_t event_requested;
111} QEMU_PACKED VirtIOSCSICtrlANReq;
112
113typedef struct {
114 uint32_t event_actual;
115 uint8_t response;
116} QEMU_PACKED VirtIOSCSICtrlANResp;
117
118typedef struct {
119 uint32_t event;
120 uint8_t lun[8];
121 uint32_t reason;
122} QEMU_PACKED VirtIOSCSIEvent;
123
124typedef struct {
125 uint32_t num_queues;
126 uint32_t seg_max;
127 uint32_t max_sectors;
128 uint32_t cmd_per_lun;
129 uint32_t event_info_size;
130 uint32_t sense_size;
131 uint32_t cdb_size;
132 uint16_t max_channel;
133 uint16_t max_target;
134 uint32_t max_lun;
135} QEMU_PACKED VirtIOSCSIConfig;
136
137typedef struct {
138 VirtIODevice vdev;
139 DeviceState *qdev;
140 VirtIOSCSIConf *conf;
141
2ccdcd8d 142 SCSIBus bus;
973abc7f
SH
143 uint32_t sense_size;
144 uint32_t cdb_size;
06114d72 145 int resetting;
64f64855 146 bool events_dropped;
d2ad7dd4
PB
147 VirtQueue *ctrl_vq;
148 VirtQueue *event_vq;
149 VirtQueue *cmd_vqs[0];
973abc7f
SH
150} VirtIOSCSI;
151
326799c0
SH
152typedef struct VirtIOSCSIReq {
153 VirtIOSCSI *dev;
154 VirtQueue *vq;
155 VirtQueueElement elem;
156 QEMUSGList qsgl;
157 SCSIRequest *sreq;
158 union {
159 char *buf;
160 VirtIOSCSICmdReq *cmd;
161 VirtIOSCSICtrlTMFReq *tmf;
162 VirtIOSCSICtrlANReq *an;
163 } req;
164 union {
165 char *buf;
166 VirtIOSCSICmdResp *cmd;
167 VirtIOSCSICtrlTMFResp *tmf;
168 VirtIOSCSICtrlANResp *an;
169 VirtIOSCSIEvent *event;
170 } resp;
171} VirtIOSCSIReq;
172
2ccdcd8d
PB
173static inline int virtio_scsi_get_lun(uint8_t *lun)
174{
175 return ((lun[2] << 8) | lun[3]) & 0x3FFF;
176}
177
178static inline SCSIDevice *virtio_scsi_device_find(VirtIOSCSI *s, uint8_t *lun)
179{
180 if (lun[0] != 1) {
181 return NULL;
182 }
183 if (lun[2] != 0 && !(lun[2] >= 0x40 && lun[2] < 0x80)) {
184 return NULL;
185 }
186 return scsi_device_find(&s->bus, 0, lun[1], virtio_scsi_get_lun(lun));
187}
188
326799c0
SH
189static void virtio_scsi_complete_req(VirtIOSCSIReq *req)
190{
191 VirtIOSCSI *s = req->dev;
192 VirtQueue *vq = req->vq;
193 virtqueue_push(vq, &req->elem, req->qsgl.size + req->elem.in_sg[0].iov_len);
194 qemu_sglist_destroy(&req->qsgl);
195 if (req->sreq) {
196 req->sreq->hba_private = NULL;
197 scsi_req_unref(req->sreq);
198 }
199 g_free(req);
200 virtio_notify(&s->vdev, vq);
201}
202
203static void virtio_scsi_bad_req(void)
204{
205 error_report("wrong size for virtio-scsi headers");
206 exit(1);
207}
208
209static void qemu_sgl_init_external(QEMUSGList *qsgl, struct iovec *sg,
210 target_phys_addr_t *addr, int num)
211{
212 memset(qsgl, 0, sizeof(*qsgl));
213 while (num--) {
214 qemu_sglist_add(qsgl, *(addr++), (sg++)->iov_len);
215 }
216}
217
218static void virtio_scsi_parse_req(VirtIOSCSI *s, VirtQueue *vq,
219 VirtIOSCSIReq *req)
220{
b6866fee 221 assert(req->elem.in_num);
326799c0
SH
222 req->vq = vq;
223 req->dev = s;
224 req->sreq = NULL;
b6866fee
CM
225 if (req->elem.out_num) {
226 req->req.buf = req->elem.out_sg[0].iov_base;
227 }
326799c0
SH
228 req->resp.buf = req->elem.in_sg[0].iov_base;
229
230 if (req->elem.out_num > 1) {
231 qemu_sgl_init_external(&req->qsgl, &req->elem.out_sg[1],
232 &req->elem.out_addr[1],
233 req->elem.out_num - 1);
234 } else {
235 qemu_sgl_init_external(&req->qsgl, &req->elem.in_sg[1],
236 &req->elem.in_addr[1],
237 req->elem.in_num - 1);
238 }
239}
240
241static VirtIOSCSIReq *virtio_scsi_pop_req(VirtIOSCSI *s, VirtQueue *vq)
242{
243 VirtIOSCSIReq *req;
244 req = g_malloc(sizeof(*req));
245 if (!virtqueue_pop(vq, &req->elem)) {
246 g_free(req);
247 return NULL;
248 }
249
250 virtio_scsi_parse_req(s, vq, req);
251 return req;
252}
253
5db1764c
PB
254static void virtio_scsi_save_request(QEMUFile *f, SCSIRequest *sreq)
255{
256 VirtIOSCSIReq *req = sreq->hba_private;
d2ad7dd4 257 uint32_t n = virtio_queue_get_id(req->vq) - 2;
5db1764c 258
d2ad7dd4 259 assert(n < req->dev->conf->num_queues);
fcf104a7 260 qemu_put_be32s(f, &n);
5db1764c
PB
261 qemu_put_buffer(f, (unsigned char *)&req->elem, sizeof(req->elem));
262}
263
264static void *virtio_scsi_load_request(QEMUFile *f, SCSIRequest *sreq)
265{
266 SCSIBus *bus = sreq->bus;
267 VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
268 VirtIOSCSIReq *req;
fcf104a7 269 uint32_t n;
5db1764c
PB
270
271 req = g_malloc(sizeof(*req));
fcf104a7 272 qemu_get_be32s(f, &n);
d2ad7dd4 273 assert(n < s->conf->num_queues);
5db1764c 274 qemu_get_buffer(f, (unsigned char *)&req->elem, sizeof(req->elem));
d2ad7dd4 275 virtio_scsi_parse_req(s, s->cmd_vqs[n], req);
5db1764c
PB
276
277 scsi_req_ref(sreq);
278 req->sreq = sreq;
279 if (req->sreq->cmd.mode != SCSI_XFER_NONE) {
280 int req_mode =
281 (req->elem.in_num > 1 ? SCSI_XFER_FROM_DEV : SCSI_XFER_TO_DEV);
282
283 assert(req->sreq->cmd.mode == req_mode);
284 }
285 return req;
286}
287
06114d72 288static void virtio_scsi_do_tmf(VirtIOSCSI *s, VirtIOSCSIReq *req)
326799c0 289{
06114d72
PB
290 SCSIDevice *d = virtio_scsi_device_find(s, req->req.tmf->lun);
291 SCSIRequest *r, *next;
0866aca1 292 BusChild *kid;
06114d72
PB
293 int target;
294
295 /* Here VIRTIO_SCSI_S_OK means "FUNCTION COMPLETE". */
296 req->resp.tmf->response = VIRTIO_SCSI_S_OK;
297
298 switch (req->req.tmf->subtype) {
299 case VIRTIO_SCSI_T_TMF_ABORT_TASK:
300 case VIRTIO_SCSI_T_TMF_QUERY_TASK:
301 if (!d) {
302 goto fail;
303 }
304 if (d->lun != virtio_scsi_get_lun(req->req.tmf->lun)) {
305 goto incorrect_lun;
306 }
307 QTAILQ_FOREACH_SAFE(r, &d->requests, next, next) {
4dd7c82c
PB
308 VirtIOSCSIReq *cmd_req = r->hba_private;
309 if (cmd_req && cmd_req->req.cmd->tag == req->req.tmf->tag) {
06114d72
PB
310 break;
311 }
312 }
4dd7c82c
PB
313 if (r) {
314 /*
315 * Assert that the request has not been completed yet, we
316 * check for it in the loop above.
317 */
318 assert(r->hba_private);
06114d72
PB
319 if (req->req.tmf->subtype == VIRTIO_SCSI_T_TMF_QUERY_TASK) {
320 /* "If the specified command is present in the task set, then
321 * return a service response set to FUNCTION SUCCEEDED".
322 */
323 req->resp.tmf->response = VIRTIO_SCSI_S_FUNCTION_SUCCEEDED;
324 } else {
325 scsi_req_cancel(r);
326 }
327 }
328 break;
329
330 case VIRTIO_SCSI_T_TMF_LOGICAL_UNIT_RESET:
331 if (!d) {
332 goto fail;
333 }
334 if (d->lun != virtio_scsi_get_lun(req->req.tmf->lun)) {
335 goto incorrect_lun;
336 }
337 s->resetting++;
338 qdev_reset_all(&d->qdev);
339 s->resetting--;
340 break;
341
342 case VIRTIO_SCSI_T_TMF_ABORT_TASK_SET:
343 case VIRTIO_SCSI_T_TMF_CLEAR_TASK_SET:
344 case VIRTIO_SCSI_T_TMF_QUERY_TASK_SET:
345 if (!d) {
346 goto fail;
347 }
348 if (d->lun != virtio_scsi_get_lun(req->req.tmf->lun)) {
349 goto incorrect_lun;
350 }
351 QTAILQ_FOREACH_SAFE(r, &d->requests, next, next) {
352 if (r->hba_private) {
353 if (req->req.tmf->subtype == VIRTIO_SCSI_T_TMF_QUERY_TASK_SET) {
354 /* "If there is any command present in the task set, then
355 * return a service response set to FUNCTION SUCCEEDED".
356 */
357 req->resp.tmf->response = VIRTIO_SCSI_S_FUNCTION_SUCCEEDED;
358 break;
359 } else {
360 scsi_req_cancel(r);
361 }
362 }
363 }
364 break;
365
366 case VIRTIO_SCSI_T_TMF_I_T_NEXUS_RESET:
367 target = req->req.tmf->lun[1];
368 s->resetting++;
0866aca1
AL
369 QTAILQ_FOREACH(kid, &s->bus.qbus.children, sibling) {
370 d = DO_UPCAST(SCSIDevice, qdev, kid->child);
06114d72
PB
371 if (d->channel == 0 && d->id == target) {
372 qdev_reset_all(&d->qdev);
373 }
374 }
375 s->resetting--;
376 break;
377
378 case VIRTIO_SCSI_T_TMF_CLEAR_ACA:
379 default:
380 req->resp.tmf->response = VIRTIO_SCSI_S_FUNCTION_REJECTED;
381 break;
326799c0
SH
382 }
383
06114d72
PB
384 return;
385
386incorrect_lun:
387 req->resp.tmf->response = VIRTIO_SCSI_S_INCORRECT_LUN;
388 return;
389
390fail:
391 req->resp.tmf->response = VIRTIO_SCSI_S_BAD_TARGET;
326799c0
SH
392}
393
973abc7f
SH
394static void virtio_scsi_handle_ctrl(VirtIODevice *vdev, VirtQueue *vq)
395{
326799c0
SH
396 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
397 VirtIOSCSIReq *req;
398
399 while ((req = virtio_scsi_pop_req(s, vq))) {
06114d72
PB
400 int out_size, in_size;
401 if (req->elem.out_num < 1 || req->elem.in_num < 1) {
402 virtio_scsi_bad_req();
403 continue;
404 }
405
406 out_size = req->elem.out_sg[0].iov_len;
407 in_size = req->elem.in_sg[0].iov_len;
408 if (req->req.tmf->type == VIRTIO_SCSI_T_TMF) {
409 if (out_size < sizeof(VirtIOSCSICtrlTMFReq) ||
410 in_size < sizeof(VirtIOSCSICtrlTMFResp)) {
411 virtio_scsi_bad_req();
412 }
413 virtio_scsi_do_tmf(s, req);
414
415 } else if (req->req.tmf->type == VIRTIO_SCSI_T_AN_QUERY ||
416 req->req.tmf->type == VIRTIO_SCSI_T_AN_SUBSCRIBE) {
417 if (out_size < sizeof(VirtIOSCSICtrlANReq) ||
418 in_size < sizeof(VirtIOSCSICtrlANResp)) {
419 virtio_scsi_bad_req();
420 }
421 req->resp.an->event_actual = 0;
422 req->resp.an->response = VIRTIO_SCSI_S_OK;
423 }
424 virtio_scsi_complete_req(req);
326799c0
SH
425 }
426}
427
2ccdcd8d
PB
428static void virtio_scsi_command_complete(SCSIRequest *r, uint32_t status,
429 size_t resid)
430{
431 VirtIOSCSIReq *req = r->hba_private;
432
433 req->resp.cmd->response = VIRTIO_SCSI_S_OK;
434 req->resp.cmd->status = status;
435 if (req->resp.cmd->status == GOOD) {
436 req->resp.cmd->resid = resid;
437 } else {
438 req->resp.cmd->resid = 0;
439 req->resp.cmd->sense_len =
440 scsi_req_get_sense(r, req->resp.cmd->sense, VIRTIO_SCSI_SENSE_SIZE);
441 }
442 virtio_scsi_complete_req(req);
443}
444
445static QEMUSGList *virtio_scsi_get_sg_list(SCSIRequest *r)
446{
447 VirtIOSCSIReq *req = r->hba_private;
448
449 return &req->qsgl;
450}
451
452static void virtio_scsi_request_cancelled(SCSIRequest *r)
453{
454 VirtIOSCSIReq *req = r->hba_private;
455
456 if (!req) {
457 return;
458 }
06114d72
PB
459 if (req->dev->resetting) {
460 req->resp.cmd->response = VIRTIO_SCSI_S_RESET;
461 } else {
462 req->resp.cmd->response = VIRTIO_SCSI_S_ABORTED;
463 }
2ccdcd8d
PB
464 virtio_scsi_complete_req(req);
465}
466
467static void virtio_scsi_fail_cmd_req(VirtIOSCSIReq *req)
326799c0
SH
468{
469 req->resp.cmd->response = VIRTIO_SCSI_S_FAILURE;
470 virtio_scsi_complete_req(req);
973abc7f
SH
471}
472
473static void virtio_scsi_handle_cmd(VirtIODevice *vdev, VirtQueue *vq)
474{
326799c0
SH
475 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
476 VirtIOSCSIReq *req;
2ccdcd8d 477 int n;
326799c0
SH
478
479 while ((req = virtio_scsi_pop_req(s, vq))) {
2ccdcd8d 480 SCSIDevice *d;
326799c0
SH
481 int out_size, in_size;
482 if (req->elem.out_num < 1 || req->elem.in_num < 1) {
483 virtio_scsi_bad_req();
484 }
485
486 out_size = req->elem.out_sg[0].iov_len;
487 in_size = req->elem.in_sg[0].iov_len;
488 if (out_size < sizeof(VirtIOSCSICmdReq) + s->cdb_size ||
489 in_size < sizeof(VirtIOSCSICmdResp) + s->sense_size) {
490 virtio_scsi_bad_req();
491 }
492
493 if (req->elem.out_num > 1 && req->elem.in_num > 1) {
2ccdcd8d 494 virtio_scsi_fail_cmd_req(req);
326799c0
SH
495 continue;
496 }
497
2ccdcd8d
PB
498 d = virtio_scsi_device_find(s, req->req.cmd->lun);
499 if (!d) {
500 req->resp.cmd->response = VIRTIO_SCSI_S_BAD_TARGET;
501 virtio_scsi_complete_req(req);
502 continue;
503 }
504 req->sreq = scsi_req_new(d, req->req.cmd->tag,
505 virtio_scsi_get_lun(req->req.cmd->lun),
506 req->req.cmd->cdb, req);
507
508 if (req->sreq->cmd.mode != SCSI_XFER_NONE) {
509 int req_mode =
510 (req->elem.in_num > 1 ? SCSI_XFER_FROM_DEV : SCSI_XFER_TO_DEV);
511
512 if (req->sreq->cmd.mode != req_mode ||
513 req->sreq->cmd.xfer > req->qsgl.size) {
514 req->resp.cmd->response = VIRTIO_SCSI_S_OVERRUN;
515 virtio_scsi_complete_req(req);
516 continue;
517 }
518 }
519
520 n = scsi_req_enqueue(req->sreq);
521 if (n) {
522 scsi_req_continue(req->sreq);
523 }
326799c0 524 }
973abc7f
SH
525}
526
527static void virtio_scsi_get_config(VirtIODevice *vdev,
528 uint8_t *config)
529{
530 VirtIOSCSIConfig *scsiconf = (VirtIOSCSIConfig *)config;
531 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
532
533 stl_raw(&scsiconf->num_queues, s->conf->num_queues);
534 stl_raw(&scsiconf->seg_max, 128 - 2);
535 stl_raw(&scsiconf->max_sectors, s->conf->max_sectors);
536 stl_raw(&scsiconf->cmd_per_lun, s->conf->cmd_per_lun);
537 stl_raw(&scsiconf->event_info_size, sizeof(VirtIOSCSIEvent));
538 stl_raw(&scsiconf->sense_size, s->sense_size);
539 stl_raw(&scsiconf->cdb_size, s->cdb_size);
540 stl_raw(&scsiconf->max_channel, VIRTIO_SCSI_MAX_CHANNEL);
541 stl_raw(&scsiconf->max_target, VIRTIO_SCSI_MAX_TARGET);
542 stl_raw(&scsiconf->max_lun, VIRTIO_SCSI_MAX_LUN);
543}
544
545static void virtio_scsi_set_config(VirtIODevice *vdev,
546 const uint8_t *config)
547{
548 VirtIOSCSIConfig *scsiconf = (VirtIOSCSIConfig *)config;
549 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
550
551 if ((uint32_t) ldl_raw(&scsiconf->sense_size) >= 65536 ||
552 (uint32_t) ldl_raw(&scsiconf->cdb_size) >= 256) {
553 error_report("bad data written to virtio-scsi configuration space");
554 exit(1);
555 }
556
557 s->sense_size = ldl_raw(&scsiconf->sense_size);
558 s->cdb_size = ldl_raw(&scsiconf->cdb_size);
559}
560
561static uint32_t virtio_scsi_get_features(VirtIODevice *vdev,
562 uint32_t requested_features)
563{
b6866fee 564 requested_features |= (1UL << VIRTIO_SCSI_F_HOTPLUG);
feda01e4 565 requested_features |= (1UL << VIRTIO_SCSI_F_CHANGE);
973abc7f
SH
566 return requested_features;
567}
568
569static void virtio_scsi_reset(VirtIODevice *vdev)
570{
571 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
572
573 s->sense_size = VIRTIO_SCSI_SENSE_SIZE;
574 s->cdb_size = VIRTIO_SCSI_CDB_SIZE;
2baa1beb 575 s->events_dropped = false;
973abc7f
SH
576}
577
5db1764c
PB
578/* The device does not have anything to save beyond the virtio data.
579 * Request data is saved with callbacks from SCSI devices.
580 */
581static void virtio_scsi_save(QEMUFile *f, void *opaque)
582{
583 VirtIOSCSI *s = opaque;
584 virtio_save(&s->vdev, f);
585}
586
587static int virtio_scsi_load(QEMUFile *f, void *opaque, int version_id)
588{
589 VirtIOSCSI *s = opaque;
2a633c46
OW
590 int ret;
591
592 ret = virtio_load(&s->vdev, f);
593 if (ret) {
594 return ret;
595 }
5db1764c
PB
596 return 0;
597}
598
b6866fee
CM
599static void virtio_scsi_push_event(VirtIOSCSI *s, SCSIDevice *dev,
600 uint32_t event, uint32_t reason)
601{
602 VirtIOSCSIReq *req = virtio_scsi_pop_req(s, s->event_vq);
603 VirtIOSCSIEvent *evt;
64f64855 604 int in_size;
b6866fee 605
64f64855
PB
606 if (!req) {
607 s->events_dropped = true;
608 return;
609 }
b6866fee 610
64f64855
PB
611 if (req->elem.out_num || req->elem.in_num != 1) {
612 virtio_scsi_bad_req();
613 }
b6866fee 614
64f64855
PB
615 if (s->events_dropped) {
616 event |= VIRTIO_SCSI_T_EVENTS_MISSED;
617 s->events_dropped = false;
618 }
619
620 in_size = req->elem.in_sg[0].iov_len;
621 if (in_size < sizeof(VirtIOSCSIEvent)) {
622 virtio_scsi_bad_req();
623 }
624
625 evt = req->resp.event;
626 memset(evt, 0, sizeof(VirtIOSCSIEvent));
627 evt->event = event;
628 evt->reason = reason;
629 if (!dev) {
630 assert(event == VIRTIO_SCSI_T_NO_EVENT);
631 } else {
b6866fee
CM
632 evt->lun[0] = 1;
633 evt->lun[1] = dev->id;
634
635 /* Linux wants us to keep the same encoding we use for REPORT LUNS. */
636 if (dev->lun >= 256) {
637 evt->lun[2] = (dev->lun >> 8) | 0x40;
638 }
639 evt->lun[3] = dev->lun & 0xFF;
64f64855
PB
640 }
641 virtio_scsi_complete_req(req);
642}
643
644static void virtio_scsi_handle_event(VirtIODevice *vdev, VirtQueue *vq)
645{
646 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
647
648 if (s->events_dropped) {
649 virtio_scsi_push_event(s, NULL, VIRTIO_SCSI_T_NO_EVENT, 0);
b6866fee
CM
650 }
651}
652
feda01e4
PB
653static void virtio_scsi_change(SCSIBus *bus, SCSIDevice *dev, SCSISense sense)
654{
655 VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
656
657 if (((s->vdev.guest_features >> VIRTIO_SCSI_F_CHANGE) & 1) &&
658 (s->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK) &&
659 dev->type != TYPE_ROM) {
660 virtio_scsi_push_event(s, dev, VIRTIO_SCSI_T_PARAM_CHANGE,
661 sense.asc | (sense.ascq << 8));
662 }
663}
664
b6866fee
CM
665static void virtio_scsi_hotplug(SCSIBus *bus, SCSIDevice *dev)
666{
667 VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
668
669 if (((s->vdev.guest_features >> VIRTIO_SCSI_F_HOTPLUG) & 1) &&
670 (s->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK)) {
671 virtio_scsi_push_event(s, dev, VIRTIO_SCSI_T_TRANSPORT_RESET,
672 VIRTIO_SCSI_EVT_RESET_RESCAN);
673 }
674}
675
676static void virtio_scsi_hot_unplug(SCSIBus *bus, SCSIDevice *dev)
677{
678 VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
679
680 if ((s->vdev.guest_features >> VIRTIO_SCSI_F_HOTPLUG) & 1) {
681 virtio_scsi_push_event(s, dev, VIRTIO_SCSI_T_TRANSPORT_RESET,
682 VIRTIO_SCSI_EVT_RESET_REMOVED);
683 }
684}
685
2ccdcd8d
PB
686static struct SCSIBusInfo virtio_scsi_scsi_info = {
687 .tcq = true,
688 .max_channel = VIRTIO_SCSI_MAX_CHANNEL,
689 .max_target = VIRTIO_SCSI_MAX_TARGET,
690 .max_lun = VIRTIO_SCSI_MAX_LUN,
691
692 .complete = virtio_scsi_command_complete,
693 .cancel = virtio_scsi_request_cancelled,
feda01e4 694 .change = virtio_scsi_change,
b6866fee
CM
695 .hotplug = virtio_scsi_hotplug,
696 .hot_unplug = virtio_scsi_hot_unplug,
2ccdcd8d 697 .get_sg_list = virtio_scsi_get_sg_list,
5db1764c
PB
698 .save_request = virtio_scsi_save_request,
699 .load_request = virtio_scsi_load_request,
2ccdcd8d
PB
700};
701
973abc7f
SH
702VirtIODevice *virtio_scsi_init(DeviceState *dev, VirtIOSCSIConf *proxyconf)
703{
704 VirtIOSCSI *s;
5db1764c 705 static int virtio_scsi_id;
d2ad7dd4
PB
706 size_t sz;
707 int i;
973abc7f 708
d2ad7dd4 709 sz = sizeof(VirtIOSCSI) + proxyconf->num_queues * sizeof(VirtQueue *);
973abc7f 710 s = (VirtIOSCSI *)virtio_common_init("virtio-scsi", VIRTIO_ID_SCSI,
d2ad7dd4 711 sizeof(VirtIOSCSIConfig), sz);
973abc7f
SH
712
713 s->qdev = dev;
714 s->conf = proxyconf;
715
716 /* TODO set up vdev function pointers */
717 s->vdev.get_config = virtio_scsi_get_config;
718 s->vdev.set_config = virtio_scsi_set_config;
719 s->vdev.get_features = virtio_scsi_get_features;
720 s->vdev.reset = virtio_scsi_reset;
721
722 s->ctrl_vq = virtio_add_queue(&s->vdev, VIRTIO_SCSI_VQ_SIZE,
723 virtio_scsi_handle_ctrl);
724 s->event_vq = virtio_add_queue(&s->vdev, VIRTIO_SCSI_VQ_SIZE,
619d7ae9 725 virtio_scsi_handle_event);
d2ad7dd4
PB
726 for (i = 0; i < s->conf->num_queues; i++) {
727 s->cmd_vqs[i] = virtio_add_queue(&s->vdev, VIRTIO_SCSI_VQ_SIZE,
728 virtio_scsi_handle_cmd);
729 }
973abc7f 730
2ccdcd8d
PB
731 scsi_bus_new(&s->bus, dev, &virtio_scsi_scsi_info);
732 if (!dev->hotplugged) {
733 scsi_bus_legacy_handle_cmdline(&s->bus);
734 }
735
5db1764c
PB
736 register_savevm(dev, "virtio-scsi", virtio_scsi_id++, 1,
737 virtio_scsi_save, virtio_scsi_load, s);
973abc7f
SH
738
739 return &s->vdev;
740}
741
742void virtio_scsi_exit(VirtIODevice *vdev)
743{
eb2fa764
PB
744 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
745 unregister_savevm(s->qdev, "virtio-scsi", s);
973abc7f
SH
746 virtio_cleanup(vdev);
747}