spapr_vscsi.c 28 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969
  1. /*
  2. * QEMU PowerPC pSeries Logical Partition (aka sPAPR) hardware System Emulator
  3. *
  4. * PAPR Virtual SCSI, aka ibmvscsi
  5. *
  6. * Copyright (c) 2010,2011 Benjamin Herrenschmidt, IBM Corporation.
  7. *
  8. * Permission is hereby granted, free of charge, to any person obtaining a copy
  9. * of this software and associated documentation files (the "Software"), to deal
  10. * in the Software without restriction, including without limitation the rights
  11. * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
  12. * copies of the Software, and to permit persons to whom the Software is
  13. * furnished to do so, subject to the following conditions:
  14. *
  15. * The above copyright notice and this permission notice shall be included in
  16. * all copies or substantial portions of the Software.
  17. *
  18. * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
  19. * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
  20. * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
  21. * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
  22. * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
  23. * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
  24. * THE SOFTWARE.
  25. *
  26. * TODO:
  27. *
  28. * - Cleanups :-)
  29. * - Sort out better how to assign devices to VSCSI instances
  30. * - Fix residual counts
  31. * - Add indirect descriptors support
  32. * - Maybe do autosense (PAPR seems to mandate it, linux doesn't care)
  33. */
  34. #include "hw.h"
  35. #include "scsi.h"
  36. #include "scsi-defs.h"
  37. #include "net.h" /* Remove that when we can */
  38. #include "srp.h"
  39. #include "hw/qdev.h"
  40. #include "hw/spapr.h"
  41. #include "hw/spapr_vio.h"
  42. #include "hw/ppc-viosrp.h"
  43. #include <libfdt.h>
  44. /*#define DEBUG_VSCSI*/
  45. #ifdef DEBUG_VSCSI
  46. #define dprintf(fmt, ...) \
  47. do { fprintf(stderr, fmt, ## __VA_ARGS__); } while (0)
  48. #else
  49. #define dprintf(fmt, ...) \
  50. do { } while (0)
  51. #endif
  52. /*
  53. * Virtual SCSI device
  54. */
  55. /* Random numbers */
  56. #define VSCSI_MAX_SECTORS 4096
  57. #define VSCSI_REQ_LIMIT 24
  58. #define SCSI_SENSE_BUF_SIZE 96
  59. #define SRP_RSP_SENSE_DATA_LEN 18
  60. typedef union vscsi_crq {
  61. struct viosrp_crq s;
  62. uint8_t raw[16];
  63. } vscsi_crq;
  64. typedef struct vscsi_req {
  65. vscsi_crq crq;
  66. union viosrp_iu iu;
  67. /* SCSI request tracking */
  68. SCSIRequest *sreq;
  69. uint32_t qtag; /* qemu tag != srp tag */
  70. int lun;
  71. int active;
  72. long data_len;
  73. int writing;
  74. int senselen;
  75. uint8_t sense[SCSI_SENSE_BUF_SIZE];
  76. /* RDMA related bits */
  77. uint8_t dma_fmt;
  78. struct srp_direct_buf ext_desc;
  79. struct srp_direct_buf *cur_desc;
  80. struct srp_indirect_buf *ind_desc;
  81. int local_desc;
  82. int total_desc;
  83. } vscsi_req;
  84. typedef struct {
  85. VIOsPAPRDevice vdev;
  86. SCSIBus bus;
  87. vscsi_req reqs[VSCSI_REQ_LIMIT];
  88. } VSCSIState;
  89. /* XXX Debug only */
  90. static VSCSIState *dbg_vscsi_state;
  91. static struct vscsi_req *vscsi_get_req(VSCSIState *s)
  92. {
  93. vscsi_req *req;
  94. int i;
  95. for (i = 0; i < VSCSI_REQ_LIMIT; i++) {
  96. req = &s->reqs[i];
  97. if (!req->active) {
  98. memset(req, 0, sizeof(*req));
  99. req->qtag = i;
  100. req->active = 1;
  101. return req;
  102. }
  103. }
  104. return NULL;
  105. }
  106. static void vscsi_put_req(vscsi_req *req)
  107. {
  108. if (req->sreq != NULL) {
  109. scsi_req_unref(req->sreq);
  110. }
  111. req->sreq = NULL;
  112. req->active = 0;
  113. }
  114. static SCSIDevice *vscsi_device_find(SCSIBus *bus, uint64_t srp_lun, int *lun)
  115. {
  116. int channel = 0, id = 0;
  117. retry:
  118. switch (srp_lun >> 62) {
  119. case 0:
  120. if ((srp_lun >> 56) != 0) {
  121. channel = (srp_lun >> 56) & 0x3f;
  122. id = (srp_lun >> 48) & 0xff;
  123. srp_lun <<= 16;
  124. goto retry;
  125. }
  126. *lun = (srp_lun >> 48) & 0xff;
  127. break;
  128. case 1:
  129. *lun = (srp_lun >> 48) & 0x3fff;
  130. break;
  131. case 2:
  132. channel = (srp_lun >> 53) & 0x7;
  133. id = (srp_lun >> 56) & 0x3f;
  134. *lun = (srp_lun >> 48) & 0x1f;
  135. break;
  136. case 3:
  137. *lun = -1;
  138. return NULL;
  139. default:
  140. abort();
  141. }
  142. return scsi_device_find(bus, channel, id, *lun);
  143. }
  144. static int vscsi_send_iu(VSCSIState *s, vscsi_req *req,
  145. uint64_t length, uint8_t format)
  146. {
  147. long rc, rc1;
  148. /* First copy the SRP */
  149. rc = spapr_tce_dma_write(&s->vdev, req->crq.s.IU_data_ptr,
  150. &req->iu, length);
  151. if (rc) {
  152. fprintf(stderr, "vscsi_send_iu: DMA write failure !\n");
  153. }
  154. req->crq.s.valid = 0x80;
  155. req->crq.s.format = format;
  156. req->crq.s.reserved = 0x00;
  157. req->crq.s.timeout = cpu_to_be16(0x0000);
  158. req->crq.s.IU_length = cpu_to_be16(length);
  159. req->crq.s.IU_data_ptr = req->iu.srp.rsp.tag; /* right byte order */
  160. if (rc == 0) {
  161. req->crq.s.status = 0x99; /* Just needs to be non-zero */
  162. } else {
  163. req->crq.s.status = 0x00;
  164. }
  165. rc1 = spapr_vio_send_crq(&s->vdev, req->crq.raw);
  166. if (rc1) {
  167. fprintf(stderr, "vscsi_send_iu: Error sending response\n");
  168. return rc1;
  169. }
  170. return rc;
  171. }
  172. static void vscsi_makeup_sense(VSCSIState *s, vscsi_req *req,
  173. uint8_t key, uint8_t asc, uint8_t ascq)
  174. {
  175. req->senselen = SRP_RSP_SENSE_DATA_LEN;
  176. /* Valid bit and 'current errors' */
  177. req->sense[0] = (0x1 << 7 | 0x70);
  178. /* Sense key */
  179. req->sense[2] = key;
  180. /* Additional sense length */
  181. req->sense[7] = 0xa; /* 10 bytes */
  182. /* Additional sense code */
  183. req->sense[12] = asc;
  184. req->sense[13] = ascq;
  185. }
  186. static int vscsi_send_rsp(VSCSIState *s, vscsi_req *req,
  187. uint8_t status, int32_t res_in, int32_t res_out)
  188. {
  189. union viosrp_iu *iu = &req->iu;
  190. uint64_t tag = iu->srp.rsp.tag;
  191. int total_len = sizeof(iu->srp.rsp);
  192. dprintf("VSCSI: Sending resp status: 0x%x, "
  193. "res_in: %d, res_out: %d\n", status, res_in, res_out);
  194. memset(iu, 0, sizeof(struct srp_rsp));
  195. iu->srp.rsp.opcode = SRP_RSP;
  196. iu->srp.rsp.req_lim_delta = cpu_to_be32(1);
  197. iu->srp.rsp.tag = tag;
  198. /* Handle residuals */
  199. if (res_in < 0) {
  200. iu->srp.rsp.flags |= SRP_RSP_FLAG_DIUNDER;
  201. res_in = -res_in;
  202. } else if (res_in) {
  203. iu->srp.rsp.flags |= SRP_RSP_FLAG_DIOVER;
  204. }
  205. if (res_out < 0) {
  206. iu->srp.rsp.flags |= SRP_RSP_FLAG_DOUNDER;
  207. res_out = -res_out;
  208. } else if (res_out) {
  209. iu->srp.rsp.flags |= SRP_RSP_FLAG_DOOVER;
  210. }
  211. iu->srp.rsp.data_in_res_cnt = cpu_to_be32(res_in);
  212. iu->srp.rsp.data_out_res_cnt = cpu_to_be32(res_out);
  213. /* We don't do response data */
  214. /* iu->srp.rsp.flags &= ~SRP_RSP_FLAG_RSPVALID; */
  215. iu->srp.rsp.resp_data_len = cpu_to_be32(0);
  216. /* Handle success vs. failure */
  217. iu->srp.rsp.status = status;
  218. if (status) {
  219. iu->srp.rsp.sol_not = (iu->srp.cmd.sol_not & 0x04) >> 2;
  220. if (req->senselen) {
  221. req->iu.srp.rsp.flags |= SRP_RSP_FLAG_SNSVALID;
  222. req->iu.srp.rsp.sense_data_len = cpu_to_be32(req->senselen);
  223. memcpy(req->iu.srp.rsp.data, req->sense, req->senselen);
  224. total_len += req->senselen;
  225. }
  226. } else {
  227. iu->srp.rsp.sol_not = (iu->srp.cmd.sol_not & 0x02) >> 1;
  228. }
  229. vscsi_send_iu(s, req, total_len, VIOSRP_SRP_FORMAT);
  230. return 0;
  231. }
  232. static inline void vscsi_swap_desc(struct srp_direct_buf *desc)
  233. {
  234. desc->va = be64_to_cpu(desc->va);
  235. desc->len = be32_to_cpu(desc->len);
  236. }
  237. static int vscsi_srp_direct_data(VSCSIState *s, vscsi_req *req,
  238. uint8_t *buf, uint32_t len)
  239. {
  240. struct srp_direct_buf *md = req->cur_desc;
  241. uint32_t llen;
  242. int rc = 0;
  243. dprintf("VSCSI: direct segment 0x%x bytes, va=0x%llx desc len=0x%x\n",
  244. len, (unsigned long long)md->va, md->len);
  245. llen = MIN(len, md->len);
  246. if (llen) {
  247. if (req->writing) { /* writing = to device = reading from memory */
  248. rc = spapr_tce_dma_read(&s->vdev, md->va, buf, llen);
  249. } else {
  250. rc = spapr_tce_dma_write(&s->vdev, md->va, buf, llen);
  251. }
  252. }
  253. md->len -= llen;
  254. md->va += llen;
  255. if (rc) {
  256. return -1;
  257. }
  258. return llen;
  259. }
  260. static int vscsi_srp_indirect_data(VSCSIState *s, vscsi_req *req,
  261. uint8_t *buf, uint32_t len)
  262. {
  263. struct srp_direct_buf *td = &req->ind_desc->table_desc;
  264. struct srp_direct_buf *md = req->cur_desc;
  265. int rc = 0;
  266. uint32_t llen, total = 0;
  267. dprintf("VSCSI: indirect segment 0x%x bytes, td va=0x%llx len=0x%x\n",
  268. len, (unsigned long long)td->va, td->len);
  269. /* While we have data ... */
  270. while (len) {
  271. /* If we have a descriptor but it's empty, go fetch a new one */
  272. if (md && md->len == 0) {
  273. /* More local available, use one */
  274. if (req->local_desc) {
  275. md = ++req->cur_desc;
  276. --req->local_desc;
  277. --req->total_desc;
  278. td->va += sizeof(struct srp_direct_buf);
  279. } else {
  280. md = req->cur_desc = NULL;
  281. }
  282. }
  283. /* No descriptor at hand, fetch one */
  284. if (!md) {
  285. if (!req->total_desc) {
  286. dprintf("VSCSI: Out of descriptors !\n");
  287. break;
  288. }
  289. md = req->cur_desc = &req->ext_desc;
  290. dprintf("VSCSI: Reading desc from 0x%llx\n",
  291. (unsigned long long)td->va);
  292. rc = spapr_tce_dma_read(&s->vdev, td->va, md,
  293. sizeof(struct srp_direct_buf));
  294. if (rc) {
  295. dprintf("VSCSI: tce_dma_read -> %d reading ext_desc\n", rc);
  296. break;
  297. }
  298. vscsi_swap_desc(md);
  299. td->va += sizeof(struct srp_direct_buf);
  300. --req->total_desc;
  301. }
  302. dprintf("VSCSI: [desc va=0x%llx,len=0x%x] remaining=0x%x\n",
  303. (unsigned long long)md->va, md->len, len);
  304. /* Perform transfer */
  305. llen = MIN(len, md->len);
  306. if (req->writing) { /* writing = to device = reading from memory */
  307. rc = spapr_tce_dma_read(&s->vdev, md->va, buf, llen);
  308. } else {
  309. rc = spapr_tce_dma_write(&s->vdev, md->va, buf, llen);
  310. }
  311. if (rc) {
  312. dprintf("VSCSI: tce_dma_r/w(%d) -> %d\n", req->writing, rc);
  313. break;
  314. }
  315. dprintf("VSCSI: data: %02x %02x %02x %02x...\n",
  316. buf[0], buf[1], buf[2], buf[3]);
  317. len -= llen;
  318. buf += llen;
  319. total += llen;
  320. md->va += llen;
  321. md->len -= llen;
  322. }
  323. return rc ? -1 : total;
  324. }
  325. static int vscsi_srp_transfer_data(VSCSIState *s, vscsi_req *req,
  326. int writing, uint8_t *buf, uint32_t len)
  327. {
  328. int err = 0;
  329. switch (req->dma_fmt) {
  330. case SRP_NO_DATA_DESC:
  331. dprintf("VSCSI: no data desc transfer, skipping 0x%x bytes\n", len);
  332. break;
  333. case SRP_DATA_DESC_DIRECT:
  334. err = vscsi_srp_direct_data(s, req, buf, len);
  335. break;
  336. case SRP_DATA_DESC_INDIRECT:
  337. err = vscsi_srp_indirect_data(s, req, buf, len);
  338. break;
  339. }
  340. return err;
  341. }
  342. /* Bits from linux srp */
  343. static int data_out_desc_size(struct srp_cmd *cmd)
  344. {
  345. int size = 0;
  346. uint8_t fmt = cmd->buf_fmt >> 4;
  347. switch (fmt) {
  348. case SRP_NO_DATA_DESC:
  349. break;
  350. case SRP_DATA_DESC_DIRECT:
  351. size = sizeof(struct srp_direct_buf);
  352. break;
  353. case SRP_DATA_DESC_INDIRECT:
  354. size = sizeof(struct srp_indirect_buf) +
  355. sizeof(struct srp_direct_buf)*cmd->data_out_desc_cnt;
  356. break;
  357. default:
  358. break;
  359. }
  360. return size;
  361. }
  362. static int vscsi_preprocess_desc(vscsi_req *req)
  363. {
  364. struct srp_cmd *cmd = &req->iu.srp.cmd;
  365. int offset, i;
  366. offset = cmd->add_cdb_len & ~3;
  367. if (req->writing) {
  368. req->dma_fmt = cmd->buf_fmt >> 4;
  369. } else {
  370. offset += data_out_desc_size(cmd);
  371. req->dma_fmt = cmd->buf_fmt & ((1U << 4) - 1);
  372. }
  373. switch (req->dma_fmt) {
  374. case SRP_NO_DATA_DESC:
  375. break;
  376. case SRP_DATA_DESC_DIRECT:
  377. req->cur_desc = (struct srp_direct_buf *)(cmd->add_data + offset);
  378. req->total_desc = req->local_desc = 1;
  379. vscsi_swap_desc(req->cur_desc);
  380. dprintf("VSCSI: using direct RDMA %s, 0x%x bytes MD: 0x%llx\n",
  381. req->writing ? "write" : "read",
  382. req->cur_desc->len, (unsigned long long)req->cur_desc->va);
  383. break;
  384. case SRP_DATA_DESC_INDIRECT:
  385. req->ind_desc = (struct srp_indirect_buf *)(cmd->add_data + offset);
  386. vscsi_swap_desc(&req->ind_desc->table_desc);
  387. req->total_desc = req->ind_desc->table_desc.len /
  388. sizeof(struct srp_direct_buf);
  389. req->local_desc = req->writing ? cmd->data_out_desc_cnt :
  390. cmd->data_in_desc_cnt;
  391. for (i = 0; i < req->local_desc; i++) {
  392. vscsi_swap_desc(&req->ind_desc->desc_list[i]);
  393. }
  394. req->cur_desc = req->local_desc ? &req->ind_desc->desc_list[0] : NULL;
  395. dprintf("VSCSI: using indirect RDMA %s, 0x%x bytes %d descs "
  396. "(%d local) VA: 0x%llx\n",
  397. req->writing ? "read" : "write",
  398. be32_to_cpu(req->ind_desc->len),
  399. req->total_desc, req->local_desc,
  400. (unsigned long long)req->ind_desc->table_desc.va);
  401. break;
  402. default:
  403. fprintf(stderr,
  404. "vscsi_preprocess_desc: Unknown format %x\n", req->dma_fmt);
  405. return -1;
  406. }
  407. return 0;
  408. }
  409. /* Callback to indicate that the SCSI layer has completed a transfer. */
  410. static void vscsi_transfer_data(SCSIRequest *sreq, uint32_t len)
  411. {
  412. VSCSIState *s = DO_UPCAST(VSCSIState, vdev.qdev, sreq->bus->qbus.parent);
  413. vscsi_req *req = sreq->hba_private;
  414. uint8_t *buf;
  415. int rc = 0;
  416. dprintf("VSCSI: SCSI xfer complete tag=0x%x len=0x%x, req=%p\n",
  417. sreq->tag, len, req);
  418. if (req == NULL) {
  419. fprintf(stderr, "VSCSI: Can't find request for tag 0x%x\n", sreq->tag);
  420. return;
  421. }
  422. if (len) {
  423. buf = scsi_req_get_buf(sreq);
  424. rc = vscsi_srp_transfer_data(s, req, req->writing, buf, len);
  425. }
  426. if (rc < 0) {
  427. fprintf(stderr, "VSCSI: RDMA error rc=%d!\n", rc);
  428. vscsi_makeup_sense(s, req, HARDWARE_ERROR, 0, 0);
  429. scsi_req_abort(req->sreq, CHECK_CONDITION);
  430. return;
  431. }
  432. /* Start next chunk */
  433. req->data_len -= rc;
  434. scsi_req_continue(sreq);
  435. }
  436. /* Callback to indicate that the SCSI layer has completed a transfer. */
  437. static void vscsi_command_complete(SCSIRequest *sreq, uint32_t status)
  438. {
  439. VSCSIState *s = DO_UPCAST(VSCSIState, vdev.qdev, sreq->bus->qbus.parent);
  440. vscsi_req *req = sreq->hba_private;
  441. int32_t res_in = 0, res_out = 0;
  442. dprintf("VSCSI: SCSI cmd complete, r=0x%x tag=0x%x status=0x%x, req=%p\n",
  443. reason, sreq->tag, status, req);
  444. if (req == NULL) {
  445. fprintf(stderr, "VSCSI: Can't find request for tag 0x%x\n", sreq->tag);
  446. return;
  447. }
  448. if (status == CHECK_CONDITION) {
  449. req->senselen = scsi_req_get_sense(req->sreq, req->sense,
  450. sizeof(req->sense));
  451. dprintf("VSCSI: Sense data, %d bytes:\n", len);
  452. dprintf(" %02x %02x %02x %02x %02x %02x %02x %02x\n",
  453. req->sense[0], req->sense[1], req->sense[2], req->sense[3],
  454. req->sense[4], req->sense[5], req->sense[6], req->sense[7]);
  455. dprintf(" %02x %02x %02x %02x %02x %02x %02x %02x\n",
  456. req->sense[8], req->sense[9], req->sense[10], req->sense[11],
  457. req->sense[12], req->sense[13], req->sense[14], req->sense[15]);
  458. }
  459. dprintf("VSCSI: Command complete err=%d\n", status);
  460. if (status == 0) {
  461. /* We handle overflows, not underflows for normal commands,
  462. * but hopefully nobody cares
  463. */
  464. if (req->writing) {
  465. res_out = req->data_len;
  466. } else {
  467. res_in = req->data_len;
  468. }
  469. }
  470. vscsi_send_rsp(s, req, status, res_in, res_out);
  471. vscsi_put_req(req);
  472. }
  473. static void vscsi_request_cancelled(SCSIRequest *sreq)
  474. {
  475. vscsi_req *req = sreq->hba_private;
  476. vscsi_put_req(req);
  477. }
  478. static void vscsi_process_login(VSCSIState *s, vscsi_req *req)
  479. {
  480. union viosrp_iu *iu = &req->iu;
  481. struct srp_login_rsp *rsp = &iu->srp.login_rsp;
  482. uint64_t tag = iu->srp.rsp.tag;
  483. dprintf("VSCSI: Got login, sendin response !\n");
  484. /* TODO handle case that requested size is wrong and
  485. * buffer format is wrong
  486. */
  487. memset(iu, 0, sizeof(struct srp_login_rsp));
  488. rsp->opcode = SRP_LOGIN_RSP;
  489. /* Don't advertise quite as many request as we support to
  490. * keep room for management stuff etc...
  491. */
  492. rsp->req_lim_delta = cpu_to_be32(VSCSI_REQ_LIMIT-2);
  493. rsp->tag = tag;
  494. rsp->max_it_iu_len = cpu_to_be32(sizeof(union srp_iu));
  495. rsp->max_ti_iu_len = cpu_to_be32(sizeof(union srp_iu));
  496. /* direct and indirect */
  497. rsp->buf_fmt = cpu_to_be16(SRP_BUF_FORMAT_DIRECT | SRP_BUF_FORMAT_INDIRECT);
  498. vscsi_send_iu(s, req, sizeof(*rsp), VIOSRP_SRP_FORMAT);
  499. }
  500. static void vscsi_inquiry_no_target(VSCSIState *s, vscsi_req *req)
  501. {
  502. uint8_t *cdb = req->iu.srp.cmd.cdb;
  503. uint8_t resp_data[36];
  504. int rc, len, alen;
  505. /* We dont do EVPD. Also check that page_code is 0 */
  506. if ((cdb[1] & 0x01) || (cdb[1] & 0x01) || cdb[2] != 0) {
  507. /* Send INVALID FIELD IN CDB */
  508. vscsi_makeup_sense(s, req, ILLEGAL_REQUEST, 0x24, 0);
  509. vscsi_send_rsp(s, req, CHECK_CONDITION, 0, 0);
  510. return;
  511. }
  512. alen = cdb[3];
  513. alen = (alen << 8) | cdb[4];
  514. len = MIN(alen, 36);
  515. /* Fake up inquiry using PQ=3 */
  516. memset(resp_data, 0, 36);
  517. resp_data[0] = 0x7f; /* Not capable of supporting a device here */
  518. resp_data[2] = 0x06; /* SPS-4 */
  519. resp_data[3] = 0x02; /* Resp data format */
  520. resp_data[4] = 36 - 5; /* Additional length */
  521. resp_data[7] = 0x10; /* Sync transfers */
  522. memcpy(&resp_data[16], "QEMU EMPTY ", 16);
  523. memcpy(&resp_data[8], "QEMU ", 8);
  524. req->writing = 0;
  525. vscsi_preprocess_desc(req);
  526. rc = vscsi_srp_transfer_data(s, req, 0, resp_data, len);
  527. if (rc < 0) {
  528. vscsi_makeup_sense(s, req, HARDWARE_ERROR, 0, 0);
  529. vscsi_send_rsp(s, req, CHECK_CONDITION, 0, 0);
  530. } else {
  531. vscsi_send_rsp(s, req, 0, 36 - rc, 0);
  532. }
  533. }
  534. static int vscsi_queue_cmd(VSCSIState *s, vscsi_req *req)
  535. {
  536. union srp_iu *srp = &req->iu.srp;
  537. SCSIDevice *sdev;
  538. int n, lun;
  539. sdev = vscsi_device_find(&s->bus, be64_to_cpu(srp->cmd.lun), &lun);
  540. if (!sdev) {
  541. dprintf("VSCSI: Command for lun %08" PRIx64 " with no drive\n", be64_to_cpu(srp->cmd.lun));
  542. if (srp->cmd.cdb[0] == INQUIRY) {
  543. vscsi_inquiry_no_target(s, req);
  544. } else {
  545. vscsi_makeup_sense(s, req, ILLEGAL_REQUEST, 0x24, 0x00);
  546. vscsi_send_rsp(s, req, CHECK_CONDITION, 0, 0);
  547. } return 1;
  548. }
  549. req->lun = lun;
  550. req->sreq = scsi_req_new(sdev, req->qtag, lun, srp->cmd.cdb, req);
  551. n = scsi_req_enqueue(req->sreq);
  552. dprintf("VSCSI: Queued command tag 0x%x CMD 0x%x ID %d LUN %d ret: %d\n",
  553. req->qtag, srp->cmd.cdb[0], id, lun, n);
  554. if (n) {
  555. /* Transfer direction must be set before preprocessing the
  556. * descriptors
  557. */
  558. req->writing = (n < 1);
  559. /* Preprocess RDMA descriptors */
  560. vscsi_preprocess_desc(req);
  561. /* Get transfer direction and initiate transfer */
  562. if (n > 0) {
  563. req->data_len = n;
  564. } else if (n < 0) {
  565. req->data_len = -n;
  566. }
  567. scsi_req_continue(req->sreq);
  568. }
  569. /* Don't touch req here, it may have been recycled already */
  570. return 0;
  571. }
  572. static int vscsi_process_tsk_mgmt(VSCSIState *s, vscsi_req *req)
  573. {
  574. union viosrp_iu *iu = &req->iu;
  575. int fn;
  576. fprintf(stderr, "vscsi_process_tsk_mgmt %02x\n",
  577. iu->srp.tsk_mgmt.tsk_mgmt_func);
  578. switch (iu->srp.tsk_mgmt.tsk_mgmt_func) {
  579. #if 0 /* We really don't deal with these for now */
  580. case SRP_TSK_ABORT_TASK:
  581. fn = ABORT_TASK;
  582. break;
  583. case SRP_TSK_ABORT_TASK_SET:
  584. fn = ABORT_TASK_SET;
  585. break;
  586. case SRP_TSK_CLEAR_TASK_SET:
  587. fn = CLEAR_TASK_SET;
  588. break;
  589. case SRP_TSK_LUN_RESET:
  590. fn = LOGICAL_UNIT_RESET;
  591. break;
  592. case SRP_TSK_CLEAR_ACA:
  593. fn = CLEAR_ACA;
  594. break;
  595. #endif
  596. default:
  597. fn = 0;
  598. }
  599. if (fn) {
  600. /* XXX Send/Handle target task management */
  601. ;
  602. } else {
  603. vscsi_makeup_sense(s, req, ILLEGAL_REQUEST, 0x20, 0);
  604. vscsi_send_rsp(s, req, CHECK_CONDITION, 0, 0);
  605. }
  606. return !fn;
  607. }
  608. static int vscsi_handle_srp_req(VSCSIState *s, vscsi_req *req)
  609. {
  610. union srp_iu *srp = &req->iu.srp;
  611. int done = 1;
  612. uint8_t opcode = srp->rsp.opcode;
  613. switch (opcode) {
  614. case SRP_LOGIN_REQ:
  615. vscsi_process_login(s, req);
  616. break;
  617. case SRP_TSK_MGMT:
  618. done = vscsi_process_tsk_mgmt(s, req);
  619. break;
  620. case SRP_CMD:
  621. done = vscsi_queue_cmd(s, req);
  622. break;
  623. case SRP_LOGIN_RSP:
  624. case SRP_I_LOGOUT:
  625. case SRP_T_LOGOUT:
  626. case SRP_RSP:
  627. case SRP_CRED_REQ:
  628. case SRP_CRED_RSP:
  629. case SRP_AER_REQ:
  630. case SRP_AER_RSP:
  631. fprintf(stderr, "VSCSI: Unsupported opcode %02x\n", opcode);
  632. break;
  633. default:
  634. fprintf(stderr, "VSCSI: Unknown type %02x\n", opcode);
  635. }
  636. return done;
  637. }
  638. static int vscsi_send_adapter_info(VSCSIState *s, vscsi_req *req)
  639. {
  640. struct viosrp_adapter_info *sinfo;
  641. struct mad_adapter_info_data info;
  642. int rc;
  643. sinfo = &req->iu.mad.adapter_info;
  644. #if 0 /* What for ? */
  645. rc = spapr_tce_dma_read(&s->vdev, be64_to_cpu(sinfo->buffer),
  646. &info, be16_to_cpu(sinfo->common.length));
  647. if (rc) {
  648. fprintf(stderr, "vscsi_send_adapter_info: DMA read failure !\n");
  649. }
  650. #endif
  651. memset(&info, 0, sizeof(info));
  652. strcpy(info.srp_version, SRP_VERSION);
  653. strncpy(info.partition_name, "qemu", sizeof("qemu"));
  654. info.partition_number = cpu_to_be32(0);
  655. info.mad_version = cpu_to_be32(1);
  656. info.os_type = cpu_to_be32(2);
  657. info.port_max_txu[0] = cpu_to_be32(VSCSI_MAX_SECTORS << 9);
  658. rc = spapr_tce_dma_write(&s->vdev, be64_to_cpu(sinfo->buffer),
  659. &info, be16_to_cpu(sinfo->common.length));
  660. if (rc) {
  661. fprintf(stderr, "vscsi_send_adapter_info: DMA write failure !\n");
  662. }
  663. sinfo->common.status = rc ? cpu_to_be32(1) : 0;
  664. return vscsi_send_iu(s, req, sizeof(*sinfo), VIOSRP_MAD_FORMAT);
  665. }
  666. static int vscsi_handle_mad_req(VSCSIState *s, vscsi_req *req)
  667. {
  668. union mad_iu *mad = &req->iu.mad;
  669. switch (be32_to_cpu(mad->empty_iu.common.type)) {
  670. case VIOSRP_EMPTY_IU_TYPE:
  671. fprintf(stderr, "Unsupported EMPTY MAD IU\n");
  672. break;
  673. case VIOSRP_ERROR_LOG_TYPE:
  674. fprintf(stderr, "Unsupported ERROR LOG MAD IU\n");
  675. mad->error_log.common.status = cpu_to_be16(1);
  676. vscsi_send_iu(s, req, sizeof(mad->error_log), VIOSRP_MAD_FORMAT);
  677. break;
  678. case VIOSRP_ADAPTER_INFO_TYPE:
  679. vscsi_send_adapter_info(s, req);
  680. break;
  681. case VIOSRP_HOST_CONFIG_TYPE:
  682. mad->host_config.common.status = cpu_to_be16(1);
  683. vscsi_send_iu(s, req, sizeof(mad->host_config), VIOSRP_MAD_FORMAT);
  684. break;
  685. default:
  686. fprintf(stderr, "VSCSI: Unknown MAD type %02x\n",
  687. be32_to_cpu(mad->empty_iu.common.type));
  688. }
  689. return 1;
  690. }
  691. static void vscsi_got_payload(VSCSIState *s, vscsi_crq *crq)
  692. {
  693. vscsi_req *req;
  694. int done;
  695. req = vscsi_get_req(s);
  696. if (req == NULL) {
  697. fprintf(stderr, "VSCSI: Failed to get a request !\n");
  698. return;
  699. }
  700. /* We only support a limited number of descriptors, we know
  701. * the ibmvscsi driver uses up to 10 max, so it should fit
  702. * in our 256 bytes IUs. If not we'll have to increase the size
  703. * of the structure.
  704. */
  705. if (crq->s.IU_length > sizeof(union viosrp_iu)) {
  706. fprintf(stderr, "VSCSI: SRP IU too long (%d bytes) !\n",
  707. crq->s.IU_length);
  708. return;
  709. }
  710. /* XXX Handle failure differently ? */
  711. if (spapr_tce_dma_read(&s->vdev, crq->s.IU_data_ptr, &req->iu,
  712. crq->s.IU_length)) {
  713. fprintf(stderr, "vscsi_got_payload: DMA read failure !\n");
  714. g_free(req);
  715. }
  716. memcpy(&req->crq, crq, sizeof(vscsi_crq));
  717. if (crq->s.format == VIOSRP_MAD_FORMAT) {
  718. done = vscsi_handle_mad_req(s, req);
  719. } else {
  720. done = vscsi_handle_srp_req(s, req);
  721. }
  722. if (done) {
  723. vscsi_put_req(req);
  724. }
  725. }
  726. static int vscsi_do_crq(struct VIOsPAPRDevice *dev, uint8_t *crq_data)
  727. {
  728. VSCSIState *s = DO_UPCAST(VSCSIState, vdev, dev);
  729. vscsi_crq crq;
  730. memcpy(crq.raw, crq_data, 16);
  731. crq.s.timeout = be16_to_cpu(crq.s.timeout);
  732. crq.s.IU_length = be16_to_cpu(crq.s.IU_length);
  733. crq.s.IU_data_ptr = be64_to_cpu(crq.s.IU_data_ptr);
  734. dprintf("VSCSI: do_crq %02x %02x ...\n", crq.raw[0], crq.raw[1]);
  735. switch (crq.s.valid) {
  736. case 0xc0: /* Init command/response */
  737. /* Respond to initialization request */
  738. if (crq.s.format == 0x01) {
  739. memset(crq.raw, 0, 16);
  740. crq.s.valid = 0xc0;
  741. crq.s.format = 0x02;
  742. spapr_vio_send_crq(dev, crq.raw);
  743. }
  744. /* Note that in hotplug cases, we might get a 0x02
  745. * as a result of us emitting the init request
  746. */
  747. break;
  748. case 0xff: /* Link event */
  749. /* Not handled for now */
  750. break;
  751. case 0x80: /* Payloads */
  752. switch (crq.s.format) {
  753. case VIOSRP_SRP_FORMAT: /* AKA VSCSI request */
  754. case VIOSRP_MAD_FORMAT: /* AKA VSCSI response */
  755. vscsi_got_payload(s, &crq);
  756. break;
  757. case VIOSRP_OS400_FORMAT:
  758. case VIOSRP_AIX_FORMAT:
  759. case VIOSRP_LINUX_FORMAT:
  760. case VIOSRP_INLINE_FORMAT:
  761. fprintf(stderr, "vscsi_do_srq: Unsupported payload format %02x\n",
  762. crq.s.format);
  763. break;
  764. default:
  765. fprintf(stderr, "vscsi_do_srq: Unknown payload format %02x\n",
  766. crq.s.format);
  767. }
  768. break;
  769. default:
  770. fprintf(stderr, "vscsi_do_crq: unknown CRQ %02x %02x ...\n",
  771. crq.raw[0], crq.raw[1]);
  772. };
  773. return 0;
  774. }
  775. static const struct SCSIBusInfo vscsi_scsi_info = {
  776. .tcq = true,
  777. .max_channel = 7, /* logical unit addressing format */
  778. .max_target = 63,
  779. .max_lun = 31,
  780. .transfer_data = vscsi_transfer_data,
  781. .complete = vscsi_command_complete,
  782. .cancel = vscsi_request_cancelled
  783. };
  784. static int spapr_vscsi_init(VIOsPAPRDevice *dev)
  785. {
  786. VSCSIState *s = DO_UPCAST(VSCSIState, vdev, dev);
  787. int i;
  788. dbg_vscsi_state = s;
  789. /* Initialize qemu request tags */
  790. memset(s->reqs, 0, sizeof(s->reqs));
  791. for (i = 0; i < VSCSI_REQ_LIMIT; i++) {
  792. s->reqs[i].qtag = i;
  793. }
  794. dev->crq.SendFunc = vscsi_do_crq;
  795. scsi_bus_new(&s->bus, &dev->qdev, &vscsi_scsi_info);
  796. if (!dev->qdev.hotplugged) {
  797. scsi_bus_legacy_handle_cmdline(&s->bus);
  798. }
  799. return 0;
  800. }
  801. void spapr_vscsi_create(VIOsPAPRBus *bus, uint32_t reg)
  802. {
  803. DeviceState *dev;
  804. dev = qdev_create(&bus->bus, "spapr-vscsi");
  805. qdev_prop_set_uint32(dev, "reg", reg);
  806. qdev_init_nofail(dev);
  807. }
  808. static int spapr_vscsi_devnode(VIOsPAPRDevice *dev, void *fdt, int node_off)
  809. {
  810. int ret;
  811. ret = fdt_setprop_cell(fdt, node_off, "#address-cells", 2);
  812. if (ret < 0) {
  813. return ret;
  814. }
  815. ret = fdt_setprop_cell(fdt, node_off, "#size-cells", 0);
  816. if (ret < 0) {
  817. return ret;
  818. }
  819. return 0;
  820. }
  821. static VIOsPAPRDeviceInfo spapr_vscsi = {
  822. .init = spapr_vscsi_init,
  823. .devnode = spapr_vscsi_devnode,
  824. .dt_name = "v-scsi",
  825. .dt_type = "vscsi",
  826. .dt_compatible = "IBM,v-scsi",
  827. .signal_mask = 0x00000001,
  828. .qdev.name = "spapr-vscsi",
  829. .qdev.size = sizeof(VSCSIState),
  830. .qdev.props = (Property[]) {
  831. DEFINE_SPAPR_PROPERTIES(VSCSIState, vdev, 0x2000, 0x10000000),
  832. DEFINE_PROP_END_OF_LIST(),
  833. },
  834. };
  835. static void spapr_vscsi_register(void)
  836. {
  837. spapr_vio_bus_register_withprop(&spapr_vscsi);
  838. }
  839. device_init(spapr_vscsi_register);