]> git.proxmox.com Git - qemu.git/blame - hw/virtio-scsi.c
virtio-scsi: Fix some endian bugs with virtio-scsi
[qemu.git] / hw / virtio-scsi.c
CommitLineData
973abc7f
SH
1/*
2 * Virtio SCSI HBA
3 *
4 * Copyright IBM, Corp. 2010
5 * Copyright Red Hat, Inc. 2011
6 *
7 * Authors:
8 * Stefan Hajnoczi <stefanha@linux.vnet.ibm.com>
9 * Paolo Bonzini <pbonzini@redhat.com>
10 *
11 * This work is licensed under the terms of the GNU GPL, version 2 or later.
12 * See the COPYING file in the top-level directory.
13 *
14 */
15
16#include "virtio-scsi.h"
17#include <hw/scsi.h>
18#include <hw/scsi-defs.h>
19
20#define VIRTIO_SCSI_VQ_SIZE 128
21#define VIRTIO_SCSI_CDB_SIZE 32
22#define VIRTIO_SCSI_SENSE_SIZE 96
23#define VIRTIO_SCSI_MAX_CHANNEL 0
24#define VIRTIO_SCSI_MAX_TARGET 255
25#define VIRTIO_SCSI_MAX_LUN 16383
26
27/* Response codes */
28#define VIRTIO_SCSI_S_OK 0
29#define VIRTIO_SCSI_S_OVERRUN 1
30#define VIRTIO_SCSI_S_ABORTED 2
31#define VIRTIO_SCSI_S_BAD_TARGET 3
32#define VIRTIO_SCSI_S_RESET 4
33#define VIRTIO_SCSI_S_BUSY 5
34#define VIRTIO_SCSI_S_TRANSPORT_FAILURE 6
35#define VIRTIO_SCSI_S_TARGET_FAILURE 7
36#define VIRTIO_SCSI_S_NEXUS_FAILURE 8
37#define VIRTIO_SCSI_S_FAILURE 9
38#define VIRTIO_SCSI_S_FUNCTION_SUCCEEDED 10
39#define VIRTIO_SCSI_S_FUNCTION_REJECTED 11
40#define VIRTIO_SCSI_S_INCORRECT_LUN 12
41
42/* Controlq type codes. */
43#define VIRTIO_SCSI_T_TMF 0
44#define VIRTIO_SCSI_T_AN_QUERY 1
45#define VIRTIO_SCSI_T_AN_SUBSCRIBE 2
46
47/* Valid TMF subtypes. */
48#define VIRTIO_SCSI_T_TMF_ABORT_TASK 0
49#define VIRTIO_SCSI_T_TMF_ABORT_TASK_SET 1
50#define VIRTIO_SCSI_T_TMF_CLEAR_ACA 2
51#define VIRTIO_SCSI_T_TMF_CLEAR_TASK_SET 3
52#define VIRTIO_SCSI_T_TMF_I_T_NEXUS_RESET 4
53#define VIRTIO_SCSI_T_TMF_LOGICAL_UNIT_RESET 5
54#define VIRTIO_SCSI_T_TMF_QUERY_TASK 6
55#define VIRTIO_SCSI_T_TMF_QUERY_TASK_SET 7
56
57/* Events. */
58#define VIRTIO_SCSI_T_EVENTS_MISSED 0x80000000
59#define VIRTIO_SCSI_T_NO_EVENT 0
60#define VIRTIO_SCSI_T_TRANSPORT_RESET 1
61#define VIRTIO_SCSI_T_ASYNC_NOTIFY 2
feda01e4 62#define VIRTIO_SCSI_T_PARAM_CHANGE 3
973abc7f 63
b6866fee
CM
64/* Reasons for transport reset event */
65#define VIRTIO_SCSI_EVT_RESET_HARD 0
66#define VIRTIO_SCSI_EVT_RESET_RESCAN 1
67#define VIRTIO_SCSI_EVT_RESET_REMOVED 2
68
973abc7f
SH
69/* SCSI command request, followed by data-out */
70typedef struct {
71 uint8_t lun[8]; /* Logical Unit Number */
72 uint64_t tag; /* Command identifier */
73 uint8_t task_attr; /* Task attribute */
74 uint8_t prio;
75 uint8_t crn;
76 uint8_t cdb[];
77} QEMU_PACKED VirtIOSCSICmdReq;
78
79/* Response, followed by sense data and data-in */
80typedef struct {
81 uint32_t sense_len; /* Sense data length */
82 uint32_t resid; /* Residual bytes in data buffer */
83 uint16_t status_qualifier; /* Status qualifier */
84 uint8_t status; /* Command completion status */
85 uint8_t response; /* Response values */
86 uint8_t sense[];
87} QEMU_PACKED VirtIOSCSICmdResp;
88
89/* Task Management Request */
90typedef struct {
91 uint32_t type;
92 uint32_t subtype;
93 uint8_t lun[8];
94 uint64_t tag;
95} QEMU_PACKED VirtIOSCSICtrlTMFReq;
96
97typedef struct {
98 uint8_t response;
99} QEMU_PACKED VirtIOSCSICtrlTMFResp;
100
101/* Asynchronous notification query/subscription */
102typedef struct {
103 uint32_t type;
104 uint8_t lun[8];
105 uint32_t event_requested;
106} QEMU_PACKED VirtIOSCSICtrlANReq;
107
108typedef struct {
109 uint32_t event_actual;
110 uint8_t response;
111} QEMU_PACKED VirtIOSCSICtrlANResp;
112
113typedef struct {
114 uint32_t event;
115 uint8_t lun[8];
116 uint32_t reason;
117} QEMU_PACKED VirtIOSCSIEvent;
118
119typedef struct {
120 uint32_t num_queues;
121 uint32_t seg_max;
122 uint32_t max_sectors;
123 uint32_t cmd_per_lun;
124 uint32_t event_info_size;
125 uint32_t sense_size;
126 uint32_t cdb_size;
127 uint16_t max_channel;
128 uint16_t max_target;
129 uint32_t max_lun;
130} QEMU_PACKED VirtIOSCSIConfig;
131
132typedef struct {
133 VirtIODevice vdev;
134 DeviceState *qdev;
135 VirtIOSCSIConf *conf;
136
2ccdcd8d 137 SCSIBus bus;
973abc7f
SH
138 uint32_t sense_size;
139 uint32_t cdb_size;
06114d72 140 int resetting;
64f64855 141 bool events_dropped;
d2ad7dd4
PB
142 VirtQueue *ctrl_vq;
143 VirtQueue *event_vq;
144 VirtQueue *cmd_vqs[0];
973abc7f
SH
145} VirtIOSCSI;
146
326799c0
SH
147typedef struct VirtIOSCSIReq {
148 VirtIOSCSI *dev;
149 VirtQueue *vq;
150 VirtQueueElement elem;
151 QEMUSGList qsgl;
152 SCSIRequest *sreq;
153 union {
154 char *buf;
155 VirtIOSCSICmdReq *cmd;
156 VirtIOSCSICtrlTMFReq *tmf;
157 VirtIOSCSICtrlANReq *an;
158 } req;
159 union {
160 char *buf;
161 VirtIOSCSICmdResp *cmd;
162 VirtIOSCSICtrlTMFResp *tmf;
163 VirtIOSCSICtrlANResp *an;
164 VirtIOSCSIEvent *event;
165 } resp;
166} VirtIOSCSIReq;
167
2ccdcd8d
PB
168static inline int virtio_scsi_get_lun(uint8_t *lun)
169{
170 return ((lun[2] << 8) | lun[3]) & 0x3FFF;
171}
172
173static inline SCSIDevice *virtio_scsi_device_find(VirtIOSCSI *s, uint8_t *lun)
174{
175 if (lun[0] != 1) {
176 return NULL;
177 }
178 if (lun[2] != 0 && !(lun[2] >= 0x40 && lun[2] < 0x80)) {
179 return NULL;
180 }
181 return scsi_device_find(&s->bus, 0, lun[1], virtio_scsi_get_lun(lun));
182}
183
326799c0
SH
184static void virtio_scsi_complete_req(VirtIOSCSIReq *req)
185{
186 VirtIOSCSI *s = req->dev;
187 VirtQueue *vq = req->vq;
188 virtqueue_push(vq, &req->elem, req->qsgl.size + req->elem.in_sg[0].iov_len);
189 qemu_sglist_destroy(&req->qsgl);
190 if (req->sreq) {
191 req->sreq->hba_private = NULL;
192 scsi_req_unref(req->sreq);
193 }
194 g_free(req);
195 virtio_notify(&s->vdev, vq);
196}
197
198static void virtio_scsi_bad_req(void)
199{
200 error_report("wrong size for virtio-scsi headers");
201 exit(1);
202}
203
204static void qemu_sgl_init_external(QEMUSGList *qsgl, struct iovec *sg,
205 target_phys_addr_t *addr, int num)
206{
207 memset(qsgl, 0, sizeof(*qsgl));
208 while (num--) {
209 qemu_sglist_add(qsgl, *(addr++), (sg++)->iov_len);
210 }
211}
212
213static void virtio_scsi_parse_req(VirtIOSCSI *s, VirtQueue *vq,
214 VirtIOSCSIReq *req)
215{
b6866fee 216 assert(req->elem.in_num);
326799c0
SH
217 req->vq = vq;
218 req->dev = s;
219 req->sreq = NULL;
b6866fee
CM
220 if (req->elem.out_num) {
221 req->req.buf = req->elem.out_sg[0].iov_base;
222 }
326799c0
SH
223 req->resp.buf = req->elem.in_sg[0].iov_base;
224
225 if (req->elem.out_num > 1) {
226 qemu_sgl_init_external(&req->qsgl, &req->elem.out_sg[1],
227 &req->elem.out_addr[1],
228 req->elem.out_num - 1);
229 } else {
230 qemu_sgl_init_external(&req->qsgl, &req->elem.in_sg[1],
231 &req->elem.in_addr[1],
232 req->elem.in_num - 1);
233 }
234}
235
236static VirtIOSCSIReq *virtio_scsi_pop_req(VirtIOSCSI *s, VirtQueue *vq)
237{
238 VirtIOSCSIReq *req;
239 req = g_malloc(sizeof(*req));
240 if (!virtqueue_pop(vq, &req->elem)) {
241 g_free(req);
242 return NULL;
243 }
244
245 virtio_scsi_parse_req(s, vq, req);
246 return req;
247}
248
5db1764c
PB
249static void virtio_scsi_save_request(QEMUFile *f, SCSIRequest *sreq)
250{
251 VirtIOSCSIReq *req = sreq->hba_private;
d2ad7dd4 252 uint32_t n = virtio_queue_get_id(req->vq) - 2;
5db1764c 253
d2ad7dd4 254 assert(n < req->dev->conf->num_queues);
fcf104a7 255 qemu_put_be32s(f, &n);
5db1764c
PB
256 qemu_put_buffer(f, (unsigned char *)&req->elem, sizeof(req->elem));
257}
258
259static void *virtio_scsi_load_request(QEMUFile *f, SCSIRequest *sreq)
260{
261 SCSIBus *bus = sreq->bus;
262 VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
263 VirtIOSCSIReq *req;
fcf104a7 264 uint32_t n;
5db1764c
PB
265
266 req = g_malloc(sizeof(*req));
fcf104a7 267 qemu_get_be32s(f, &n);
d2ad7dd4 268 assert(n < s->conf->num_queues);
5db1764c 269 qemu_get_buffer(f, (unsigned char *)&req->elem, sizeof(req->elem));
d2ad7dd4 270 virtio_scsi_parse_req(s, s->cmd_vqs[n], req);
5db1764c
PB
271
272 scsi_req_ref(sreq);
273 req->sreq = sreq;
274 if (req->sreq->cmd.mode != SCSI_XFER_NONE) {
275 int req_mode =
276 (req->elem.in_num > 1 ? SCSI_XFER_FROM_DEV : SCSI_XFER_TO_DEV);
277
278 assert(req->sreq->cmd.mode == req_mode);
279 }
280 return req;
281}
282
06114d72 283static void virtio_scsi_do_tmf(VirtIOSCSI *s, VirtIOSCSIReq *req)
326799c0 284{
06114d72
PB
285 SCSIDevice *d = virtio_scsi_device_find(s, req->req.tmf->lun);
286 SCSIRequest *r, *next;
0866aca1 287 BusChild *kid;
06114d72
PB
288 int target;
289
290 /* Here VIRTIO_SCSI_S_OK means "FUNCTION COMPLETE". */
291 req->resp.tmf->response = VIRTIO_SCSI_S_OK;
292
293 switch (req->req.tmf->subtype) {
294 case VIRTIO_SCSI_T_TMF_ABORT_TASK:
295 case VIRTIO_SCSI_T_TMF_QUERY_TASK:
296 if (!d) {
297 goto fail;
298 }
299 if (d->lun != virtio_scsi_get_lun(req->req.tmf->lun)) {
300 goto incorrect_lun;
301 }
302 QTAILQ_FOREACH_SAFE(r, &d->requests, next, next) {
4dd7c82c
PB
303 VirtIOSCSIReq *cmd_req = r->hba_private;
304 if (cmd_req && cmd_req->req.cmd->tag == req->req.tmf->tag) {
06114d72
PB
305 break;
306 }
307 }
4dd7c82c
PB
308 if (r) {
309 /*
310 * Assert that the request has not been completed yet, we
311 * check for it in the loop above.
312 */
313 assert(r->hba_private);
06114d72
PB
314 if (req->req.tmf->subtype == VIRTIO_SCSI_T_TMF_QUERY_TASK) {
315 /* "If the specified command is present in the task set, then
316 * return a service response set to FUNCTION SUCCEEDED".
317 */
318 req->resp.tmf->response = VIRTIO_SCSI_S_FUNCTION_SUCCEEDED;
319 } else {
320 scsi_req_cancel(r);
321 }
322 }
323 break;
324
325 case VIRTIO_SCSI_T_TMF_LOGICAL_UNIT_RESET:
326 if (!d) {
327 goto fail;
328 }
329 if (d->lun != virtio_scsi_get_lun(req->req.tmf->lun)) {
330 goto incorrect_lun;
331 }
332 s->resetting++;
333 qdev_reset_all(&d->qdev);
334 s->resetting--;
335 break;
336
337 case VIRTIO_SCSI_T_TMF_ABORT_TASK_SET:
338 case VIRTIO_SCSI_T_TMF_CLEAR_TASK_SET:
339 case VIRTIO_SCSI_T_TMF_QUERY_TASK_SET:
340 if (!d) {
341 goto fail;
342 }
343 if (d->lun != virtio_scsi_get_lun(req->req.tmf->lun)) {
344 goto incorrect_lun;
345 }
346 QTAILQ_FOREACH_SAFE(r, &d->requests, next, next) {
347 if (r->hba_private) {
348 if (req->req.tmf->subtype == VIRTIO_SCSI_T_TMF_QUERY_TASK_SET) {
349 /* "If there is any command present in the task set, then
350 * return a service response set to FUNCTION SUCCEEDED".
351 */
352 req->resp.tmf->response = VIRTIO_SCSI_S_FUNCTION_SUCCEEDED;
353 break;
354 } else {
355 scsi_req_cancel(r);
356 }
357 }
358 }
359 break;
360
361 case VIRTIO_SCSI_T_TMF_I_T_NEXUS_RESET:
362 target = req->req.tmf->lun[1];
363 s->resetting++;
0866aca1
AL
364 QTAILQ_FOREACH(kid, &s->bus.qbus.children, sibling) {
365 d = DO_UPCAST(SCSIDevice, qdev, kid->child);
06114d72
PB
366 if (d->channel == 0 && d->id == target) {
367 qdev_reset_all(&d->qdev);
368 }
369 }
370 s->resetting--;
371 break;
372
373 case VIRTIO_SCSI_T_TMF_CLEAR_ACA:
374 default:
375 req->resp.tmf->response = VIRTIO_SCSI_S_FUNCTION_REJECTED;
376 break;
326799c0
SH
377 }
378
06114d72
PB
379 return;
380
381incorrect_lun:
382 req->resp.tmf->response = VIRTIO_SCSI_S_INCORRECT_LUN;
383 return;
384
385fail:
386 req->resp.tmf->response = VIRTIO_SCSI_S_BAD_TARGET;
326799c0
SH
387}
388
973abc7f
SH
389static void virtio_scsi_handle_ctrl(VirtIODevice *vdev, VirtQueue *vq)
390{
326799c0
SH
391 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
392 VirtIOSCSIReq *req;
393
394 while ((req = virtio_scsi_pop_req(s, vq))) {
06114d72
PB
395 int out_size, in_size;
396 if (req->elem.out_num < 1 || req->elem.in_num < 1) {
397 virtio_scsi_bad_req();
398 continue;
399 }
400
401 out_size = req->elem.out_sg[0].iov_len;
402 in_size = req->elem.in_sg[0].iov_len;
403 if (req->req.tmf->type == VIRTIO_SCSI_T_TMF) {
404 if (out_size < sizeof(VirtIOSCSICtrlTMFReq) ||
405 in_size < sizeof(VirtIOSCSICtrlTMFResp)) {
406 virtio_scsi_bad_req();
407 }
408 virtio_scsi_do_tmf(s, req);
409
410 } else if (req->req.tmf->type == VIRTIO_SCSI_T_AN_QUERY ||
411 req->req.tmf->type == VIRTIO_SCSI_T_AN_SUBSCRIBE) {
412 if (out_size < sizeof(VirtIOSCSICtrlANReq) ||
413 in_size < sizeof(VirtIOSCSICtrlANResp)) {
414 virtio_scsi_bad_req();
415 }
416 req->resp.an->event_actual = 0;
417 req->resp.an->response = VIRTIO_SCSI_S_OK;
418 }
419 virtio_scsi_complete_req(req);
326799c0
SH
420 }
421}
422
2ccdcd8d
PB
423static void virtio_scsi_command_complete(SCSIRequest *r, uint32_t status,
424 size_t resid)
425{
426 VirtIOSCSIReq *req = r->hba_private;
ea08f3a4 427 uint32_t sense_len;
2ccdcd8d
PB
428
429 req->resp.cmd->response = VIRTIO_SCSI_S_OK;
430 req->resp.cmd->status = status;
431 if (req->resp.cmd->status == GOOD) {
ea08f3a4 432 req->resp.cmd->resid = tswap32(resid);
2ccdcd8d
PB
433 } else {
434 req->resp.cmd->resid = 0;
ea08f3a4
DG
435 sense_len = scsi_req_get_sense(r, req->resp.cmd->sense,
436 VIRTIO_SCSI_SENSE_SIZE);
437 req->resp.cmd->sense_len = tswap32(sense_len);
2ccdcd8d
PB
438 }
439 virtio_scsi_complete_req(req);
440}
441
442static QEMUSGList *virtio_scsi_get_sg_list(SCSIRequest *r)
443{
444 VirtIOSCSIReq *req = r->hba_private;
445
446 return &req->qsgl;
447}
448
449static void virtio_scsi_request_cancelled(SCSIRequest *r)
450{
451 VirtIOSCSIReq *req = r->hba_private;
452
453 if (!req) {
454 return;
455 }
06114d72
PB
456 if (req->dev->resetting) {
457 req->resp.cmd->response = VIRTIO_SCSI_S_RESET;
458 } else {
459 req->resp.cmd->response = VIRTIO_SCSI_S_ABORTED;
460 }
2ccdcd8d
PB
461 virtio_scsi_complete_req(req);
462}
463
464static void virtio_scsi_fail_cmd_req(VirtIOSCSIReq *req)
326799c0
SH
465{
466 req->resp.cmd->response = VIRTIO_SCSI_S_FAILURE;
467 virtio_scsi_complete_req(req);
973abc7f
SH
468}
469
470static void virtio_scsi_handle_cmd(VirtIODevice *vdev, VirtQueue *vq)
471{
326799c0
SH
472 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
473 VirtIOSCSIReq *req;
2ccdcd8d 474 int n;
326799c0
SH
475
476 while ((req = virtio_scsi_pop_req(s, vq))) {
2ccdcd8d 477 SCSIDevice *d;
326799c0
SH
478 int out_size, in_size;
479 if (req->elem.out_num < 1 || req->elem.in_num < 1) {
480 virtio_scsi_bad_req();
481 }
482
483 out_size = req->elem.out_sg[0].iov_len;
484 in_size = req->elem.in_sg[0].iov_len;
485 if (out_size < sizeof(VirtIOSCSICmdReq) + s->cdb_size ||
486 in_size < sizeof(VirtIOSCSICmdResp) + s->sense_size) {
487 virtio_scsi_bad_req();
488 }
489
490 if (req->elem.out_num > 1 && req->elem.in_num > 1) {
2ccdcd8d 491 virtio_scsi_fail_cmd_req(req);
326799c0
SH
492 continue;
493 }
494
2ccdcd8d
PB
495 d = virtio_scsi_device_find(s, req->req.cmd->lun);
496 if (!d) {
497 req->resp.cmd->response = VIRTIO_SCSI_S_BAD_TARGET;
498 virtio_scsi_complete_req(req);
499 continue;
500 }
501 req->sreq = scsi_req_new(d, req->req.cmd->tag,
502 virtio_scsi_get_lun(req->req.cmd->lun),
503 req->req.cmd->cdb, req);
504
505 if (req->sreq->cmd.mode != SCSI_XFER_NONE) {
506 int req_mode =
507 (req->elem.in_num > 1 ? SCSI_XFER_FROM_DEV : SCSI_XFER_TO_DEV);
508
509 if (req->sreq->cmd.mode != req_mode ||
510 req->sreq->cmd.xfer > req->qsgl.size) {
511 req->resp.cmd->response = VIRTIO_SCSI_S_OVERRUN;
512 virtio_scsi_complete_req(req);
513 continue;
514 }
515 }
516
517 n = scsi_req_enqueue(req->sreq);
518 if (n) {
519 scsi_req_continue(req->sreq);
520 }
326799c0 521 }
973abc7f
SH
522}
523
524static void virtio_scsi_get_config(VirtIODevice *vdev,
525 uint8_t *config)
526{
527 VirtIOSCSIConfig *scsiconf = (VirtIOSCSIConfig *)config;
528 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
529
530 stl_raw(&scsiconf->num_queues, s->conf->num_queues);
531 stl_raw(&scsiconf->seg_max, 128 - 2);
532 stl_raw(&scsiconf->max_sectors, s->conf->max_sectors);
533 stl_raw(&scsiconf->cmd_per_lun, s->conf->cmd_per_lun);
534 stl_raw(&scsiconf->event_info_size, sizeof(VirtIOSCSIEvent));
535 stl_raw(&scsiconf->sense_size, s->sense_size);
536 stl_raw(&scsiconf->cdb_size, s->cdb_size);
537 stl_raw(&scsiconf->max_channel, VIRTIO_SCSI_MAX_CHANNEL);
538 stl_raw(&scsiconf->max_target, VIRTIO_SCSI_MAX_TARGET);
539 stl_raw(&scsiconf->max_lun, VIRTIO_SCSI_MAX_LUN);
540}
541
542static void virtio_scsi_set_config(VirtIODevice *vdev,
543 const uint8_t *config)
544{
545 VirtIOSCSIConfig *scsiconf = (VirtIOSCSIConfig *)config;
546 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
547
548 if ((uint32_t) ldl_raw(&scsiconf->sense_size) >= 65536 ||
549 (uint32_t) ldl_raw(&scsiconf->cdb_size) >= 256) {
550 error_report("bad data written to virtio-scsi configuration space");
551 exit(1);
552 }
553
554 s->sense_size = ldl_raw(&scsiconf->sense_size);
555 s->cdb_size = ldl_raw(&scsiconf->cdb_size);
556}
557
558static uint32_t virtio_scsi_get_features(VirtIODevice *vdev,
559 uint32_t requested_features)
560{
561 return requested_features;
562}
563
564static void virtio_scsi_reset(VirtIODevice *vdev)
565{
566 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
567
568 s->sense_size = VIRTIO_SCSI_SENSE_SIZE;
569 s->cdb_size = VIRTIO_SCSI_CDB_SIZE;
2baa1beb 570 s->events_dropped = false;
973abc7f
SH
571}
572
5db1764c
PB
573/* The device does not have anything to save beyond the virtio data.
574 * Request data is saved with callbacks from SCSI devices.
575 */
576static void virtio_scsi_save(QEMUFile *f, void *opaque)
577{
578 VirtIOSCSI *s = opaque;
579 virtio_save(&s->vdev, f);
580}
581
582static int virtio_scsi_load(QEMUFile *f, void *opaque, int version_id)
583{
584 VirtIOSCSI *s = opaque;
2a633c46
OW
585 int ret;
586
587 ret = virtio_load(&s->vdev, f);
588 if (ret) {
589 return ret;
590 }
5db1764c
PB
591 return 0;
592}
593
b6866fee
CM
594static void virtio_scsi_push_event(VirtIOSCSI *s, SCSIDevice *dev,
595 uint32_t event, uint32_t reason)
596{
597 VirtIOSCSIReq *req = virtio_scsi_pop_req(s, s->event_vq);
598 VirtIOSCSIEvent *evt;
64f64855 599 int in_size;
b6866fee 600
64f64855
PB
601 if (!req) {
602 s->events_dropped = true;
603 return;
604 }
b6866fee 605
64f64855
PB
606 if (req->elem.out_num || req->elem.in_num != 1) {
607 virtio_scsi_bad_req();
608 }
b6866fee 609
64f64855
PB
610 if (s->events_dropped) {
611 event |= VIRTIO_SCSI_T_EVENTS_MISSED;
612 s->events_dropped = false;
613 }
614
615 in_size = req->elem.in_sg[0].iov_len;
616 if (in_size < sizeof(VirtIOSCSIEvent)) {
617 virtio_scsi_bad_req();
618 }
619
620 evt = req->resp.event;
621 memset(evt, 0, sizeof(VirtIOSCSIEvent));
622 evt->event = event;
623 evt->reason = reason;
624 if (!dev) {
625 assert(event == VIRTIO_SCSI_T_NO_EVENT);
626 } else {
b6866fee
CM
627 evt->lun[0] = 1;
628 evt->lun[1] = dev->id;
629
630 /* Linux wants us to keep the same encoding we use for REPORT LUNS. */
631 if (dev->lun >= 256) {
632 evt->lun[2] = (dev->lun >> 8) | 0x40;
633 }
634 evt->lun[3] = dev->lun & 0xFF;
64f64855
PB
635 }
636 virtio_scsi_complete_req(req);
637}
638
639static void virtio_scsi_handle_event(VirtIODevice *vdev, VirtQueue *vq)
640{
641 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
642
643 if (s->events_dropped) {
644 virtio_scsi_push_event(s, NULL, VIRTIO_SCSI_T_NO_EVENT, 0);
b6866fee
CM
645 }
646}
647
feda01e4
PB
648static void virtio_scsi_change(SCSIBus *bus, SCSIDevice *dev, SCSISense sense)
649{
650 VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
651
652 if (((s->vdev.guest_features >> VIRTIO_SCSI_F_CHANGE) & 1) &&
653 (s->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK) &&
654 dev->type != TYPE_ROM) {
655 virtio_scsi_push_event(s, dev, VIRTIO_SCSI_T_PARAM_CHANGE,
656 sense.asc | (sense.ascq << 8));
657 }
658}
659
b6866fee
CM
660static void virtio_scsi_hotplug(SCSIBus *bus, SCSIDevice *dev)
661{
662 VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
663
664 if (((s->vdev.guest_features >> VIRTIO_SCSI_F_HOTPLUG) & 1) &&
665 (s->vdev.status & VIRTIO_CONFIG_S_DRIVER_OK)) {
666 virtio_scsi_push_event(s, dev, VIRTIO_SCSI_T_TRANSPORT_RESET,
667 VIRTIO_SCSI_EVT_RESET_RESCAN);
668 }
669}
670
671static void virtio_scsi_hot_unplug(SCSIBus *bus, SCSIDevice *dev)
672{
673 VirtIOSCSI *s = container_of(bus, VirtIOSCSI, bus);
674
675 if ((s->vdev.guest_features >> VIRTIO_SCSI_F_HOTPLUG) & 1) {
676 virtio_scsi_push_event(s, dev, VIRTIO_SCSI_T_TRANSPORT_RESET,
677 VIRTIO_SCSI_EVT_RESET_REMOVED);
678 }
679}
680
2ccdcd8d
PB
681static struct SCSIBusInfo virtio_scsi_scsi_info = {
682 .tcq = true,
683 .max_channel = VIRTIO_SCSI_MAX_CHANNEL,
684 .max_target = VIRTIO_SCSI_MAX_TARGET,
685 .max_lun = VIRTIO_SCSI_MAX_LUN,
686
687 .complete = virtio_scsi_command_complete,
688 .cancel = virtio_scsi_request_cancelled,
feda01e4 689 .change = virtio_scsi_change,
b6866fee
CM
690 .hotplug = virtio_scsi_hotplug,
691 .hot_unplug = virtio_scsi_hot_unplug,
2ccdcd8d 692 .get_sg_list = virtio_scsi_get_sg_list,
5db1764c
PB
693 .save_request = virtio_scsi_save_request,
694 .load_request = virtio_scsi_load_request,
2ccdcd8d
PB
695};
696
973abc7f
SH
697VirtIODevice *virtio_scsi_init(DeviceState *dev, VirtIOSCSIConf *proxyconf)
698{
699 VirtIOSCSI *s;
5db1764c 700 static int virtio_scsi_id;
d2ad7dd4
PB
701 size_t sz;
702 int i;
973abc7f 703
d2ad7dd4 704 sz = sizeof(VirtIOSCSI) + proxyconf->num_queues * sizeof(VirtQueue *);
973abc7f 705 s = (VirtIOSCSI *)virtio_common_init("virtio-scsi", VIRTIO_ID_SCSI,
d2ad7dd4 706 sizeof(VirtIOSCSIConfig), sz);
973abc7f
SH
707
708 s->qdev = dev;
709 s->conf = proxyconf;
710
711 /* TODO set up vdev function pointers */
712 s->vdev.get_config = virtio_scsi_get_config;
713 s->vdev.set_config = virtio_scsi_set_config;
714 s->vdev.get_features = virtio_scsi_get_features;
715 s->vdev.reset = virtio_scsi_reset;
716
717 s->ctrl_vq = virtio_add_queue(&s->vdev, VIRTIO_SCSI_VQ_SIZE,
718 virtio_scsi_handle_ctrl);
719 s->event_vq = virtio_add_queue(&s->vdev, VIRTIO_SCSI_VQ_SIZE,
619d7ae9 720 virtio_scsi_handle_event);
d2ad7dd4
PB
721 for (i = 0; i < s->conf->num_queues; i++) {
722 s->cmd_vqs[i] = virtio_add_queue(&s->vdev, VIRTIO_SCSI_VQ_SIZE,
723 virtio_scsi_handle_cmd);
724 }
973abc7f 725
2ccdcd8d
PB
726 scsi_bus_new(&s->bus, dev, &virtio_scsi_scsi_info);
727 if (!dev->hotplugged) {
728 scsi_bus_legacy_handle_cmdline(&s->bus);
729 }
730
5db1764c
PB
731 register_savevm(dev, "virtio-scsi", virtio_scsi_id++, 1,
732 virtio_scsi_save, virtio_scsi_load, s);
973abc7f
SH
733
734 return &s->vdev;
735}
736
737void virtio_scsi_exit(VirtIODevice *vdev)
738{
eb2fa764
PB
739 VirtIOSCSI *s = (VirtIOSCSI *)vdev;
740 unregister_savevm(s->qdev, "virtio-scsi", s);
973abc7f
SH
741 virtio_cleanup(vdev);
742}