2 * USB Mass Storage Device emulation
4 * Copyright (c) 2006 CodeSourcery.
5 * Written by Paul Brook
7 * This code is licenced under the LGPL.
10 #include "qemu-common.h"
13 #include "scsi-disk.h"
19 #define DPRINTF(fmt, ...) \
20 do { printf("usb-msd: " fmt , ## __VA_ARGS__); } while (0)
22 #define DPRINTF(fmt, ...) do {} while(0)
26 #define MassStorageReset 0xff
27 #define GetMaxLun 0xfe
30 USB_MSDM_CBW
, /* Command Block. */
31 USB_MSDM_DATAOUT
, /* Tranfer data to device. */
32 USB_MSDM_DATAIN
, /* Transfer data from device. */
33 USB_MSDM_CSW
/* Command Status. */
50 /* For async completion. */
71 static const uint8_t qemu_msd_dev_descriptor
[] = {
72 0x12, /* u8 bLength; */
73 0x01, /* u8 bDescriptorType; Device */
74 0x00, 0x01, /* u16 bcdUSB; v1.0 */
76 0x00, /* u8 bDeviceClass; */
77 0x00, /* u8 bDeviceSubClass; */
78 0x00, /* u8 bDeviceProtocol; [ low/full speeds only ] */
79 0x08, /* u8 bMaxPacketSize0; 8 Bytes */
81 /* Vendor and product id are arbitrary. */
82 0x00, 0x00, /* u16 idVendor; */
83 0x00, 0x00, /* u16 idProduct; */
84 0x00, 0x00, /* u16 bcdDevice */
86 0x01, /* u8 iManufacturer; */
87 0x02, /* u8 iProduct; */
88 0x03, /* u8 iSerialNumber; */
89 0x01 /* u8 bNumConfigurations; */
92 static const uint8_t qemu_msd_config_descriptor
[] = {
94 /* one configuration */
95 0x09, /* u8 bLength; */
96 0x02, /* u8 bDescriptorType; Configuration */
97 0x20, 0x00, /* u16 wTotalLength; */
98 0x01, /* u8 bNumInterfaces; (1) */
99 0x01, /* u8 bConfigurationValue; */
100 0x00, /* u8 iConfiguration; */
101 0xc0, /* u8 bmAttributes;
106 0x00, /* u8 MaxPower; */
109 0x09, /* u8 if_bLength; */
110 0x04, /* u8 if_bDescriptorType; Interface */
111 0x00, /* u8 if_bInterfaceNumber; */
112 0x00, /* u8 if_bAlternateSetting; */
113 0x02, /* u8 if_bNumEndpoints; */
114 0x08, /* u8 if_bInterfaceClass; MASS STORAGE */
115 0x06, /* u8 if_bInterfaceSubClass; SCSI */
116 0x50, /* u8 if_bInterfaceProtocol; Bulk Only */
117 0x00, /* u8 if_iInterface; */
119 /* Bulk-In endpoint */
120 0x07, /* u8 ep_bLength; */
121 0x05, /* u8 ep_bDescriptorType; Endpoint */
122 0x81, /* u8 ep_bEndpointAddress; IN Endpoint 1 */
123 0x02, /* u8 ep_bmAttributes; Bulk */
124 0x40, 0x00, /* u16 ep_wMaxPacketSize; */
125 0x00, /* u8 ep_bInterval; */
127 /* Bulk-Out endpoint */
128 0x07, /* u8 ep_bLength; */
129 0x05, /* u8 ep_bDescriptorType; Endpoint */
130 0x02, /* u8 ep_bEndpointAddress; OUT Endpoint 2 */
131 0x02, /* u8 ep_bmAttributes; Bulk */
132 0x40, 0x00, /* u16 ep_wMaxPacketSize; */
133 0x00 /* u8 ep_bInterval; */
136 static void usb_msd_copy_data(MSDState
*s
)
140 if (len
> s
->scsi_len
)
142 if (s
->mode
== USB_MSDM_DATAIN
) {
143 memcpy(s
->usb_buf
, s
->scsi_buf
, len
);
145 memcpy(s
->scsi_buf
, s
->usb_buf
, len
);
152 if (s
->scsi_len
== 0) {
153 if (s
->mode
== USB_MSDM_DATAIN
) {
154 s
->scsi_dev
->info
->read_data(s
->scsi_dev
, s
->tag
);
155 } else if (s
->mode
== USB_MSDM_DATAOUT
) {
156 s
->scsi_dev
->info
->write_data(s
->scsi_dev
, s
->tag
);
161 static void usb_msd_send_status(MSDState
*s
)
163 struct usb_msd_csw csw
;
165 csw
.sig
= cpu_to_le32(0x53425355);
166 csw
.tag
= cpu_to_le32(s
->tag
);
167 csw
.residue
= s
->residue
;
168 csw
.status
= s
->result
;
169 memcpy(s
->usb_buf
, &csw
, 13);
172 static void usb_msd_command_complete(SCSIBus
*bus
, int reason
, uint32_t tag
,
175 MSDState
*s
= DO_UPCAST(MSDState
, dev
.qdev
, bus
->qbus
.parent
);
176 USBPacket
*p
= s
->packet
;
179 fprintf(stderr
, "usb-msd: Unexpected SCSI Tag 0x%x\n", tag
);
181 if (reason
== SCSI_REASON_DONE
) {
182 DPRINTF("Command complete %d\n", arg
);
183 s
->residue
= s
->data_len
;
184 s
->result
= arg
!= 0;
186 if (s
->data_len
== 0 && s
->mode
== USB_MSDM_DATAOUT
) {
187 /* A deferred packet with no write data remaining must be
188 the status read packet. */
189 usb_msd_send_status(s
);
190 s
->mode
= USB_MSDM_CBW
;
193 s
->data_len
-= s
->usb_len
;
194 if (s
->mode
== USB_MSDM_DATAIN
)
195 memset(s
->usb_buf
, 0, s
->usb_len
);
198 if (s
->data_len
== 0)
199 s
->mode
= USB_MSDM_CSW
;
202 usb_packet_complete(p
);
203 } else if (s
->data_len
== 0) {
204 s
->mode
= USB_MSDM_CSW
;
209 s
->scsi_buf
= s
->scsi_dev
->info
->get_buf(s
->scsi_dev
, tag
);
211 usb_msd_copy_data(s
);
212 if (s
->usb_len
== 0) {
213 /* Set s->packet to NULL before calling usb_packet_complete
214 because annother request may be issued before
215 usb_packet_complete returns. */
216 DPRINTF("Packet complete %p\n", p
);
218 usb_packet_complete(p
);
223 static void usb_msd_handle_reset(USBDevice
*dev
)
225 MSDState
*s
= (MSDState
*)dev
;
228 s
->mode
= USB_MSDM_CBW
;
231 static int usb_msd_handle_control(USBDevice
*dev
, int request
, int value
,
232 int index
, int length
, uint8_t *data
)
234 MSDState
*s
= (MSDState
*)dev
;
238 case DeviceRequest
| USB_REQ_GET_STATUS
:
239 data
[0] = (1 << USB_DEVICE_SELF_POWERED
) |
240 (dev
->remote_wakeup
<< USB_DEVICE_REMOTE_WAKEUP
);
244 case DeviceOutRequest
| USB_REQ_CLEAR_FEATURE
:
245 if (value
== USB_DEVICE_REMOTE_WAKEUP
) {
246 dev
->remote_wakeup
= 0;
252 case DeviceOutRequest
| USB_REQ_SET_FEATURE
:
253 if (value
== USB_DEVICE_REMOTE_WAKEUP
) {
254 dev
->remote_wakeup
= 1;
260 case DeviceOutRequest
| USB_REQ_SET_ADDRESS
:
264 case DeviceRequest
| USB_REQ_GET_DESCRIPTOR
:
267 memcpy(data
, qemu_msd_dev_descriptor
,
268 sizeof(qemu_msd_dev_descriptor
));
269 ret
= sizeof(qemu_msd_dev_descriptor
);
272 memcpy(data
, qemu_msd_config_descriptor
,
273 sizeof(qemu_msd_config_descriptor
));
274 ret
= sizeof(qemu_msd_config_descriptor
);
277 switch(value
& 0xff) {
287 /* vendor description */
288 ret
= set_usb_string(data
, "QEMU " QEMU_VERSION
);
291 /* product description */
292 ret
= set_usb_string(data
, "QEMU USB HARDDRIVE");
296 ret
= set_usb_string(data
, "1");
306 case DeviceRequest
| USB_REQ_GET_CONFIGURATION
:
310 case DeviceOutRequest
| USB_REQ_SET_CONFIGURATION
:
313 case DeviceRequest
| USB_REQ_GET_INTERFACE
:
317 case DeviceOutRequest
| USB_REQ_SET_INTERFACE
:
320 case EndpointOutRequest
| USB_REQ_CLEAR_FEATURE
:
321 if (value
== 0 && index
!= 0x81) { /* clear ep halt */
326 /* Class specific requests. */
327 case MassStorageReset
:
328 /* Reset state ready for the next CBW. */
329 s
->mode
= USB_MSDM_CBW
;
344 static void usb_msd_cancel_io(USBPacket
*p
, void *opaque
)
346 MSDState
*s
= opaque
;
347 s
->scsi_dev
->info
->cancel_io(s
->scsi_dev
, s
->tag
);
352 static int usb_msd_handle_data(USBDevice
*dev
, USBPacket
*p
)
354 MSDState
*s
= (MSDState
*)dev
;
356 struct usb_msd_cbw cbw
;
357 uint8_t devep
= p
->devep
;
358 uint8_t *data
= p
->data
;
369 fprintf(stderr
, "usb-msd: Bad CBW size");
372 memcpy(&cbw
, data
, 31);
373 if (le32_to_cpu(cbw
.sig
) != 0x43425355) {
374 fprintf(stderr
, "usb-msd: Bad signature %08x\n",
375 le32_to_cpu(cbw
.sig
));
378 DPRINTF("Command on LUN %d\n", cbw
.lun
);
380 fprintf(stderr
, "usb-msd: Bad LUN %d\n", cbw
.lun
);
383 s
->tag
= le32_to_cpu(cbw
.tag
);
384 s
->data_len
= le32_to_cpu(cbw
.data_len
);
385 if (s
->data_len
== 0) {
386 s
->mode
= USB_MSDM_CSW
;
387 } else if (cbw
.flags
& 0x80) {
388 s
->mode
= USB_MSDM_DATAIN
;
390 s
->mode
= USB_MSDM_DATAOUT
;
392 DPRINTF("Command tag 0x%x flags %08x len %d data %d\n",
393 s
->tag
, cbw
.flags
, cbw
.cmd_len
, s
->data_len
);
395 s
->scsi_dev
->info
->send_command(s
->scsi_dev
, s
->tag
, cbw
.cmd
, 0);
396 /* ??? Should check that USB and SCSI data transfer
398 if (s
->residue
== 0) {
399 if (s
->mode
== USB_MSDM_DATAIN
) {
400 s
->scsi_dev
->info
->read_data(s
->scsi_dev
, s
->tag
);
401 } else if (s
->mode
== USB_MSDM_DATAOUT
) {
402 s
->scsi_dev
->info
->write_data(s
->scsi_dev
, s
->tag
);
408 case USB_MSDM_DATAOUT
:
409 DPRINTF("Data out %d/%d\n", len
, s
->data_len
);
410 if (len
> s
->data_len
)
416 usb_msd_copy_data(s
);
418 if (s
->residue
&& s
->usb_len
) {
419 s
->data_len
-= s
->usb_len
;
420 if (s
->data_len
== 0)
421 s
->mode
= USB_MSDM_CSW
;
425 DPRINTF("Deferring packet %p\n", p
);
426 usb_defer_packet(p
, usb_msd_cancel_io
, s
);
435 DPRINTF("Unexpected write (len %d)\n", len
);
445 case USB_MSDM_DATAOUT
:
446 if (s
->data_len
!= 0 || len
< 13)
448 /* Waiting for SCSI write to complete. */
449 usb_defer_packet(p
, usb_msd_cancel_io
, s
);
455 DPRINTF("Command status %d tag 0x%x, len %d\n",
456 s
->result
, s
->tag
, len
);
462 usb_msd_send_status(s
);
463 s
->mode
= USB_MSDM_CBW
;
467 case USB_MSDM_DATAIN
:
468 DPRINTF("Data in %d/%d\n", len
, s
->data_len
);
469 if (len
> s
->data_len
)
474 usb_msd_copy_data(s
);
476 if (s
->residue
&& s
->usb_len
) {
477 s
->data_len
-= s
->usb_len
;
478 memset(s
->usb_buf
, 0, s
->usb_len
);
479 if (s
->data_len
== 0)
480 s
->mode
= USB_MSDM_CSW
;
484 DPRINTF("Deferring packet %p\n", p
);
485 usb_defer_packet(p
, usb_msd_cancel_io
, s
);
494 DPRINTF("Unexpected read (len %d)\n", len
);
500 DPRINTF("Bad token\n");
509 static void usb_msd_handle_destroy(USBDevice
*dev
)
511 MSDState
*s
= (MSDState
*)dev
;
513 s
->scsi_dev
->info
->destroy(s
->scsi_dev
);
518 static int usb_msd_initfn(USBDevice
*dev
)
520 MSDState
*s
= DO_UPCAST(MSDState
, dev
, dev
);
522 s
->dev
.speed
= USB_SPEED_FULL
;
526 USBDevice
*usb_msd_init(const char *filename
)
530 BlockDriverState
*bdrv
;
531 BlockDriver
*drv
= NULL
;
535 p1
= strchr(filename
, ':');
539 if (strstart(filename
, "format=", &p2
)) {
540 int len
= MIN(p1
- p2
, sizeof(fmt
));
541 pstrcpy(fmt
, len
, p2
);
543 drv
= bdrv_find_format(fmt
);
545 printf("invalid format %s\n", fmt
);
548 } else if (*filename
!= ':') {
549 printf("unrecognized USB mass-storage option %s\n", filename
);
557 printf("block device specification needed\n");
561 bdrv
= bdrv_new("usb");
562 if (bdrv_open2(bdrv
, filename
, 0, drv
) < 0)
565 dev
= usb_create_simple(NULL
/* FIXME */, "QEMU USB MSD");
566 s
= DO_UPCAST(MSDState
, dev
, dev
);
568 snprintf(s
->dev
.devname
, sizeof(s
->dev
.devname
), "QEMU USB MSD(%.16s)",
571 s
->bus
= scsi_bus_new(&s
->dev
.qdev
, 0, 1, usb_msd_command_complete
);
573 s
->scsi_dev
= scsi_disk_init(s
->bus
, bdrv
);
575 usb_msd_handle_reset((USBDevice
*)s
);
576 return (USBDevice
*)s
;
579 BlockDriverState
*usb_msd_get_bdrv(USBDevice
*dev
)
581 MSDState
*s
= (MSDState
*)dev
;
586 static struct USBDeviceInfo msd_info
= {
587 .qdev
.name
= "QEMU USB MSD",
588 .qdev
.size
= sizeof(MSDState
),
589 .init
= usb_msd_initfn
,
590 .handle_packet
= usb_generic_handle_packet
,
591 .handle_reset
= usb_msd_handle_reset
,
592 .handle_control
= usb_msd_handle_control
,
593 .handle_data
= usb_msd_handle_data
,
594 .handle_destroy
= usb_msd_handle_destroy
,
597 static void usb_msd_register_devices(void)
599 usb_qdev_register(&msd_info
);
601 device_init(usb_msd_register_devices
)