4 * Copyright (c) 2004 Fabrice Bellard
6 * Permission is hereby granted, free of charge, to any person obtaining a copy
7 * of this software and associated documentation files (the "Software"), to deal
8 * in the Software without restriction, including without limitation the rights
9 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
10 * copies of the Software, and to permit persons to whom the Software is
11 * furnished to do so, subject to the following conditions:
13 * The above copyright notice and this permission notice shall be included in
14 * all copies or substantial portions of the Software.
16 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
17 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
18 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
19 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
20 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
21 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
26 #include "pci_bridge.h"
27 #include "pci_internals.h"
33 #include "qmp-commands.h"
37 # define PCI_DPRINTF(format, ...) printf(format, ## __VA_ARGS__)
39 # define PCI_DPRINTF(format, ...) do { } while (0)
42 static void pcibus_dev_print(Monitor *mon, DeviceState *dev, int indent);
43 static char *pcibus_get_dev_path(DeviceState *dev);
44 static char *pcibus_get_fw_dev_path(DeviceState *dev);
45 static int pcibus_reset(BusState *qbus);
47 struct BusInfo pci_bus_info = {
49 .size = sizeof(PCIBus),
50 .print_dev = pcibus_dev_print,
51 .get_dev_path = pcibus_get_dev_path,
52 .get_fw_dev_path = pcibus_get_fw_dev_path,
53 .reset = pcibus_reset,
54 .props = (Property[]) {
55 DEFINE_PROP_PCI_DEVFN("addr", PCIDevice, devfn, -1),
56 DEFINE_PROP_STRING("romfile", PCIDevice, romfile),
57 DEFINE_PROP_UINT32("rombar", PCIDevice, rom_bar, 1),
58 DEFINE_PROP_BIT("multifunction", PCIDevice, cap_present,
59 QEMU_PCI_CAP_MULTIFUNCTION_BITNR, false),
60 DEFINE_PROP_BIT("command_serr_enable", PCIDevice, cap_present,
61 QEMU_PCI_CAP_SERR_BITNR, true),
62 DEFINE_PROP_END_OF_LIST()
66 static void pci_update_mappings(PCIDevice *d);
67 static void pci_set_irq(void *opaque, int irq_num, int level);
68 static int pci_add_option_rom(PCIDevice *pdev, bool is_default_rom);
69 static void pci_del_option_rom(PCIDevice *pdev);
71 static uint16_t pci_default_sub_vendor_id = PCI_SUBVENDOR_ID_REDHAT_QUMRANET;
72 static uint16_t pci_default_sub_device_id = PCI_SUBDEVICE_ID_QEMU;
77 QLIST_ENTRY(PCIHostBus) next;
79 static QLIST_HEAD(, PCIHostBus) host_buses;
81 static const VMStateDescription vmstate_pcibus = {
84 .minimum_version_id = 1,
85 .minimum_version_id_old = 1,
86 .fields = (VMStateField []) {
87 VMSTATE_INT32_EQUAL(nirq, PCIBus),
88 VMSTATE_VARRAY_INT32(irq_count, PCIBus, nirq, 0, vmstate_info_int32, int32_t),
93 static int pci_bar(PCIDevice *d, int reg)
97 if (reg != PCI_ROM_SLOT)
98 return PCI_BASE_ADDRESS_0 + reg * 4;
100 type = d->config[PCI_HEADER_TYPE] & ~PCI_HEADER_TYPE_MULTI_FUNCTION;
101 return type == PCI_HEADER_TYPE_BRIDGE ? PCI_ROM_ADDRESS1 : PCI_ROM_ADDRESS;
104 static inline int pci_irq_state(PCIDevice *d, int irq_num)
106 return (d->irq_state >> irq_num) & 0x1;
109 static inline void pci_set_irq_state(PCIDevice *d, int irq_num, int level)
111 d->irq_state &= ~(0x1 << irq_num);
112 d->irq_state |= level << irq_num;
115 static void pci_change_irq_level(PCIDevice *pci_dev, int irq_num, int change)
120 irq_num = bus->map_irq(pci_dev, irq_num);
123 pci_dev = bus->parent_dev;
125 bus->irq_count[irq_num] += change;
126 bus->set_irq(bus->irq_opaque, irq_num, bus->irq_count[irq_num] != 0);
129 int pci_bus_get_irq_level(PCIBus *bus, int irq_num)
131 assert(irq_num >= 0);
132 assert(irq_num < bus->nirq);
133 return !!bus->irq_count[irq_num];
136 /* Update interrupt status bit in config space on interrupt
138 static void pci_update_irq_status(PCIDevice *dev)
140 if (dev->irq_state) {
141 dev->config[PCI_STATUS] |= PCI_STATUS_INTERRUPT;
143 dev->config[PCI_STATUS] &= ~PCI_STATUS_INTERRUPT;
147 void pci_device_deassert_intx(PCIDevice *dev)
150 for (i = 0; i < PCI_NUM_PINS; ++i) {
151 qemu_set_irq(dev->irq[i], 0);
156 * This function is called on #RST and FLR.
157 * FLR if PCI_EXP_DEVCTL_BCR_FLR is set
159 void pci_device_reset(PCIDevice *dev)
163 qdev_reset_all(&dev->qdev);
166 pci_update_irq_status(dev);
167 pci_device_deassert_intx(dev);
168 /* Clear all writable bits */
169 pci_word_test_and_clear_mask(dev->config + PCI_COMMAND,
170 pci_get_word(dev->wmask + PCI_COMMAND) |
171 pci_get_word(dev->w1cmask + PCI_COMMAND));
172 pci_word_test_and_clear_mask(dev->config + PCI_STATUS,
173 pci_get_word(dev->wmask + PCI_STATUS) |
174 pci_get_word(dev->w1cmask + PCI_STATUS));
175 dev->config[PCI_CACHE_LINE_SIZE] = 0x0;
176 dev->config[PCI_INTERRUPT_LINE] = 0x0;
177 for (r = 0; r < PCI_NUM_REGIONS; ++r) {
178 PCIIORegion *region = &dev->io_regions[r];
183 if (!(region->type & PCI_BASE_ADDRESS_SPACE_IO) &&
184 region->type & PCI_BASE_ADDRESS_MEM_TYPE_64) {
185 pci_set_quad(dev->config + pci_bar(dev, r), region->type);
187 pci_set_long(dev->config + pci_bar(dev, r), region->type);
190 pci_update_mappings(dev);
194 * Trigger pci bus reset under a given bus.
195 * To be called on RST# assert.
197 void pci_bus_reset(PCIBus *bus)
201 for (i = 0; i < bus->nirq; i++) {
202 bus->irq_count[i] = 0;
204 for (i = 0; i < ARRAY_SIZE(bus->devices); ++i) {
205 if (bus->devices[i]) {
206 pci_device_reset(bus->devices[i]);
211 static int pcibus_reset(BusState *qbus)
213 pci_bus_reset(DO_UPCAST(PCIBus, qbus, qbus));
215 /* topology traverse is done by pci_bus_reset().
216 Tell qbus/qdev walker not to traverse the tree */
220 static void pci_host_bus_register(int domain, PCIBus *bus)
222 struct PCIHostBus *host;
223 host = g_malloc0(sizeof(*host));
224 host->domain = domain;
226 QLIST_INSERT_HEAD(&host_buses, host, next);
229 PCIBus *pci_find_root_bus(int domain)
231 struct PCIHostBus *host;
233 QLIST_FOREACH(host, &host_buses, next) {
234 if (host->domain == domain) {
242 int pci_find_domain(const PCIBus *bus)
245 struct PCIHostBus *host;
247 /* obtain root bus */
248 while ((d = bus->parent_dev) != NULL) {
252 QLIST_FOREACH(host, &host_buses, next) {
253 if (host->bus == bus) {
258 abort(); /* should not be reached */
262 void pci_bus_new_inplace(PCIBus *bus, DeviceState *parent,
264 MemoryRegion *address_space_mem,
265 MemoryRegion *address_space_io,
268 qbus_create_inplace(&bus->qbus, &pci_bus_info, parent, name);
269 assert(PCI_FUNC(devfn_min) == 0);
270 bus->devfn_min = devfn_min;
271 bus->address_space_mem = address_space_mem;
272 bus->address_space_io = address_space_io;
275 QLIST_INIT(&bus->child);
276 pci_host_bus_register(0, bus); /* for now only pci domain 0 is supported */
278 vmstate_register(NULL, -1, &vmstate_pcibus, bus);
281 PCIBus *pci_bus_new(DeviceState *parent, const char *name,
282 MemoryRegion *address_space_mem,
283 MemoryRegion *address_space_io,
288 bus = g_malloc0(sizeof(*bus));
289 bus->qbus.qdev_allocated = 1;
290 pci_bus_new_inplace(bus, parent, name, address_space_mem,
291 address_space_io, devfn_min);
295 void pci_bus_irqs(PCIBus *bus, pci_set_irq_fn set_irq, pci_map_irq_fn map_irq,
296 void *irq_opaque, int nirq)
298 bus->set_irq = set_irq;
299 bus->map_irq = map_irq;
300 bus->irq_opaque = irq_opaque;
302 bus->irq_count = g_malloc0(nirq * sizeof(bus->irq_count[0]));
305 void pci_bus_hotplug(PCIBus *bus, pci_hotplug_fn hotplug, DeviceState *qdev)
307 bus->qbus.allow_hotplug = 1;
308 bus->hotplug = hotplug;
309 bus->hotplug_qdev = qdev;
312 PCIBus *pci_register_bus(DeviceState *parent, const char *name,
313 pci_set_irq_fn set_irq, pci_map_irq_fn map_irq,
315 MemoryRegion *address_space_mem,
316 MemoryRegion *address_space_io,
317 uint8_t devfn_min, int nirq)
321 bus = pci_bus_new(parent, name, address_space_mem,
322 address_space_io, devfn_min);
323 pci_bus_irqs(bus, set_irq, map_irq, irq_opaque, nirq);
327 int pci_bus_num(PCIBus *s)
330 return 0; /* pci host bridge */
331 return s->parent_dev->config[PCI_SECONDARY_BUS];
334 static int get_pci_config_device(QEMUFile *f, void *pv, size_t size)
336 PCIDevice *s = container_of(pv, PCIDevice, config);
340 assert(size == pci_config_size(s));
341 config = g_malloc(size);
343 qemu_get_buffer(f, config, size);
344 for (i = 0; i < size; ++i) {
345 if ((config[i] ^ s->config[i]) &
346 s->cmask[i] & ~s->wmask[i] & ~s->w1cmask[i]) {
351 memcpy(s->config, config, size);
353 pci_update_mappings(s);
359 /* just put buffer */
360 static void put_pci_config_device(QEMUFile *f, void *pv, size_t size)
362 const uint8_t **v = pv;
363 assert(size == pci_config_size(container_of(pv, PCIDevice, config)));
364 qemu_put_buffer(f, *v, size);
367 static VMStateInfo vmstate_info_pci_config = {
368 .name = "pci config",
369 .get = get_pci_config_device,
370 .put = put_pci_config_device,
373 static int get_pci_irq_state(QEMUFile *f, void *pv, size_t size)
375 PCIDevice *s = container_of(pv, PCIDevice, irq_state);
376 uint32_t irq_state[PCI_NUM_PINS];
378 for (i = 0; i < PCI_NUM_PINS; ++i) {
379 irq_state[i] = qemu_get_be32(f);
380 if (irq_state[i] != 0x1 && irq_state[i] != 0) {
381 fprintf(stderr, "irq state %d: must be 0 or 1.\n",
387 for (i = 0; i < PCI_NUM_PINS; ++i) {
388 pci_set_irq_state(s, i, irq_state[i]);
394 static void put_pci_irq_state(QEMUFile *f, void *pv, size_t size)
397 PCIDevice *s = container_of(pv, PCIDevice, irq_state);
399 for (i = 0; i < PCI_NUM_PINS; ++i) {
400 qemu_put_be32(f, pci_irq_state(s, i));
404 static VMStateInfo vmstate_info_pci_irq_state = {
405 .name = "pci irq state",
406 .get = get_pci_irq_state,
407 .put = put_pci_irq_state,
410 const VMStateDescription vmstate_pci_device = {
413 .minimum_version_id = 1,
414 .minimum_version_id_old = 1,
415 .fields = (VMStateField []) {
416 VMSTATE_INT32_LE(version_id, PCIDevice),
417 VMSTATE_BUFFER_UNSAFE_INFO(config, PCIDevice, 0,
418 vmstate_info_pci_config,
419 PCI_CONFIG_SPACE_SIZE),
420 VMSTATE_BUFFER_UNSAFE_INFO(irq_state, PCIDevice, 2,
421 vmstate_info_pci_irq_state,
422 PCI_NUM_PINS * sizeof(int32_t)),
423 VMSTATE_END_OF_LIST()
427 const VMStateDescription vmstate_pcie_device = {
430 .minimum_version_id = 1,
431 .minimum_version_id_old = 1,
432 .fields = (VMStateField []) {
433 VMSTATE_INT32_LE(version_id, PCIDevice),
434 VMSTATE_BUFFER_UNSAFE_INFO(config, PCIDevice, 0,
435 vmstate_info_pci_config,
436 PCIE_CONFIG_SPACE_SIZE),
437 VMSTATE_BUFFER_UNSAFE_INFO(irq_state, PCIDevice, 2,
438 vmstate_info_pci_irq_state,
439 PCI_NUM_PINS * sizeof(int32_t)),
440 VMSTATE_END_OF_LIST()
444 static inline const VMStateDescription *pci_get_vmstate(PCIDevice *s)
446 return pci_is_express(s) ? &vmstate_pcie_device : &vmstate_pci_device;
449 void pci_device_save(PCIDevice *s, QEMUFile *f)
451 /* Clear interrupt status bit: it is implicit
452 * in irq_state which we are saving.
453 * This makes us compatible with old devices
454 * which never set or clear this bit. */
455 s->config[PCI_STATUS] &= ~PCI_STATUS_INTERRUPT;
456 vmstate_save_state(f, pci_get_vmstate(s), s);
457 /* Restore the interrupt status bit. */
458 pci_update_irq_status(s);
461 int pci_device_load(PCIDevice *s, QEMUFile *f)
464 ret = vmstate_load_state(f, pci_get_vmstate(s), s, s->version_id);
465 /* Restore the interrupt status bit. */
466 pci_update_irq_status(s);
470 static void pci_set_default_subsystem_id(PCIDevice *pci_dev)
472 pci_set_word(pci_dev->config + PCI_SUBSYSTEM_VENDOR_ID,
473 pci_default_sub_vendor_id);
474 pci_set_word(pci_dev->config + PCI_SUBSYSTEM_ID,
475 pci_default_sub_device_id);
479 * Parse [[<domain>:]<bus>:]<slot>, return -1 on error if funcp == NULL
480 * [[<domain>:]<bus>:]<slot>.<func>, return -1 on error
482 int pci_parse_devaddr(const char *addr, int *domp, int *busp,
483 unsigned int *slotp, unsigned int *funcp)
488 unsigned long dom = 0, bus = 0;
489 unsigned int slot = 0;
490 unsigned int func = 0;
493 val = strtoul(p, &e, 16);
499 val = strtoul(p, &e, 16);
506 val = strtoul(p, &e, 16);
519 val = strtoul(p, &e, 16);
526 /* if funcp == NULL func is 0 */
527 if (dom > 0xffff || bus > 0xff || slot > 0x1f || func > 7)
533 /* Note: QEMU doesn't implement domains other than 0 */
534 if (!pci_find_bus(pci_find_root_bus(dom), bus))
545 int pci_read_devaddr(Monitor *mon, const char *addr, int *domp, int *busp,
548 /* strip legacy tag */
549 if (!strncmp(addr, "pci_addr=", 9)) {
552 if (pci_parse_devaddr(addr, domp, busp, slotp, NULL)) {
553 monitor_printf(mon, "Invalid pci address\n");
559 PCIBus *pci_get_bus_devfn(int *devfnp, const char *devaddr)
566 return pci_find_bus(pci_find_root_bus(0), 0);
569 if (pci_parse_devaddr(devaddr, &dom, &bus, &slot, NULL) < 0) {
573 *devfnp = PCI_DEVFN(slot, 0);
574 return pci_find_bus(pci_find_root_bus(dom), bus);
577 static void pci_init_cmask(PCIDevice *dev)
579 pci_set_word(dev->cmask + PCI_VENDOR_ID, 0xffff);
580 pci_set_word(dev->cmask + PCI_DEVICE_ID, 0xffff);
581 dev->cmask[PCI_STATUS] = PCI_STATUS_CAP_LIST;
582 dev->cmask[PCI_REVISION_ID] = 0xff;
583 dev->cmask[PCI_CLASS_PROG] = 0xff;
584 pci_set_word(dev->cmask + PCI_CLASS_DEVICE, 0xffff);
585 dev->cmask[PCI_HEADER_TYPE] = 0xff;
586 dev->cmask[PCI_CAPABILITY_LIST] = 0xff;
589 static void pci_init_wmask(PCIDevice *dev)
591 int config_size = pci_config_size(dev);
593 dev->wmask[PCI_CACHE_LINE_SIZE] = 0xff;
594 dev->wmask[PCI_INTERRUPT_LINE] = 0xff;
595 pci_set_word(dev->wmask + PCI_COMMAND,
596 PCI_COMMAND_IO | PCI_COMMAND_MEMORY | PCI_COMMAND_MASTER |
597 PCI_COMMAND_INTX_DISABLE);
598 if (dev->cap_present & QEMU_PCI_CAP_SERR) {
599 pci_word_test_and_set_mask(dev->wmask + PCI_COMMAND, PCI_COMMAND_SERR);
602 memset(dev->wmask + PCI_CONFIG_HEADER_SIZE, 0xff,
603 config_size - PCI_CONFIG_HEADER_SIZE);
606 static void pci_init_w1cmask(PCIDevice *dev)
609 * Note: It's okay to set w1cmask even for readonly bits as
610 * long as their value is hardwired to 0.
612 pci_set_word(dev->w1cmask + PCI_STATUS,
613 PCI_STATUS_PARITY | PCI_STATUS_SIG_TARGET_ABORT |
614 PCI_STATUS_REC_TARGET_ABORT | PCI_STATUS_REC_MASTER_ABORT |
615 PCI_STATUS_SIG_SYSTEM_ERROR | PCI_STATUS_DETECTED_PARITY);
618 static void pci_init_wmask_bridge(PCIDevice *d)
620 /* PCI_PRIMARY_BUS, PCI_SECONDARY_BUS, PCI_SUBORDINATE_BUS and
621 PCI_SEC_LETENCY_TIMER */
622 memset(d->wmask + PCI_PRIMARY_BUS, 0xff, 4);
625 d->wmask[PCI_IO_BASE] = PCI_IO_RANGE_MASK & 0xff;
626 d->wmask[PCI_IO_LIMIT] = PCI_IO_RANGE_MASK & 0xff;
627 pci_set_word(d->wmask + PCI_MEMORY_BASE,
628 PCI_MEMORY_RANGE_MASK & 0xffff);
629 pci_set_word(d->wmask + PCI_MEMORY_LIMIT,
630 PCI_MEMORY_RANGE_MASK & 0xffff);
631 pci_set_word(d->wmask + PCI_PREF_MEMORY_BASE,
632 PCI_PREF_RANGE_MASK & 0xffff);
633 pci_set_word(d->wmask + PCI_PREF_MEMORY_LIMIT,
634 PCI_PREF_RANGE_MASK & 0xffff);
636 /* PCI_PREF_BASE_UPPER32 and PCI_PREF_LIMIT_UPPER32 */
637 memset(d->wmask + PCI_PREF_BASE_UPPER32, 0xff, 8);
639 /* TODO: add this define to pci_regs.h in linux and then in qemu. */
640 #define PCI_BRIDGE_CTL_VGA_16BIT 0x10 /* VGA 16-bit decode */
641 #define PCI_BRIDGE_CTL_DISCARD 0x100 /* Primary discard timer */
642 #define PCI_BRIDGE_CTL_SEC_DISCARD 0x200 /* Secondary discard timer */
643 #define PCI_BRIDGE_CTL_DISCARD_STATUS 0x400 /* Discard timer status */
644 #define PCI_BRIDGE_CTL_DISCARD_SERR 0x800 /* Discard timer SERR# enable */
645 pci_set_word(d->wmask + PCI_BRIDGE_CONTROL,
646 PCI_BRIDGE_CTL_PARITY |
647 PCI_BRIDGE_CTL_SERR |
650 PCI_BRIDGE_CTL_VGA_16BIT |
651 PCI_BRIDGE_CTL_MASTER_ABORT |
652 PCI_BRIDGE_CTL_BUS_RESET |
653 PCI_BRIDGE_CTL_FAST_BACK |
654 PCI_BRIDGE_CTL_DISCARD |
655 PCI_BRIDGE_CTL_SEC_DISCARD |
656 PCI_BRIDGE_CTL_DISCARD_SERR);
657 /* Below does not do anything as we never set this bit, put here for
659 pci_set_word(d->w1cmask + PCI_BRIDGE_CONTROL,
660 PCI_BRIDGE_CTL_DISCARD_STATUS);
663 static int pci_init_multifunction(PCIBus *bus, PCIDevice *dev)
665 uint8_t slot = PCI_SLOT(dev->devfn);
668 if (dev->cap_present & QEMU_PCI_CAP_MULTIFUNCTION) {
669 dev->config[PCI_HEADER_TYPE] |= PCI_HEADER_TYPE_MULTI_FUNCTION;
673 * multifunction bit is interpreted in two ways as follows.
674 * - all functions must set the bit to 1.
676 * - function 0 must set the bit, but the rest function (> 0)
677 * is allowed to leave the bit to 0.
678 * Example: PIIX3(also in qemu), PIIX4(also in qemu), ICH10,
680 * So OS (at least Linux) checks the bit of only function 0,
681 * and doesn't see the bit of function > 0.
683 * The below check allows both interpretation.
685 if (PCI_FUNC(dev->devfn)) {
686 PCIDevice *f0 = bus->devices[PCI_DEVFN(slot, 0)];
687 if (f0 && !(f0->cap_present & QEMU_PCI_CAP_MULTIFUNCTION)) {
688 /* function 0 should set multifunction bit */
689 error_report("PCI: single function device can't be populated "
690 "in function %x.%x", slot, PCI_FUNC(dev->devfn));
696 if (dev->cap_present & QEMU_PCI_CAP_MULTIFUNCTION) {
699 /* function 0 indicates single function, so function > 0 must be NULL */
700 for (func = 1; func < PCI_FUNC_MAX; ++func) {
701 if (bus->devices[PCI_DEVFN(slot, func)]) {
702 error_report("PCI: %x.0 indicates single function, "
703 "but %x.%x is already populated.",
711 static void pci_config_alloc(PCIDevice *pci_dev)
713 int config_size = pci_config_size(pci_dev);
715 pci_dev->config = g_malloc0(config_size);
716 pci_dev->cmask = g_malloc0(config_size);
717 pci_dev->wmask = g_malloc0(config_size);
718 pci_dev->w1cmask = g_malloc0(config_size);
719 pci_dev->used = g_malloc0(config_size);
722 static void pci_config_free(PCIDevice *pci_dev)
724 g_free(pci_dev->config);
725 g_free(pci_dev->cmask);
726 g_free(pci_dev->wmask);
727 g_free(pci_dev->w1cmask);
728 g_free(pci_dev->used);
731 /* -1 for devfn means auto assign */
732 static PCIDevice *do_pci_register_device(PCIDevice *pci_dev, PCIBus *bus,
733 const char *name, int devfn,
734 const PCIDeviceInfo *info)
736 PCIConfigReadFunc *config_read = info->config_read;
737 PCIConfigWriteFunc *config_write = info->config_write;
740 for(devfn = bus->devfn_min ; devfn < ARRAY_SIZE(bus->devices);
741 devfn += PCI_FUNC_MAX) {
742 if (!bus->devices[devfn])
745 error_report("PCI: no slot/function available for %s, all in use", name);
748 } else if (bus->devices[devfn]) {
749 error_report("PCI: slot %d function %d not available for %s, in use by %s",
750 PCI_SLOT(devfn), PCI_FUNC(devfn), name, bus->devices[devfn]->name);
754 pci_dev->devfn = devfn;
755 pstrcpy(pci_dev->name, sizeof(pci_dev->name), name);
756 pci_dev->irq_state = 0;
757 pci_config_alloc(pci_dev);
759 pci_config_set_vendor_id(pci_dev->config, info->vendor_id);
760 pci_config_set_device_id(pci_dev->config, info->device_id);
761 pci_config_set_revision(pci_dev->config, info->revision);
762 pci_config_set_class(pci_dev->config, info->class_id);
764 if (!info->is_bridge) {
765 if (info->subsystem_vendor_id || info->subsystem_id) {
766 pci_set_word(pci_dev->config + PCI_SUBSYSTEM_VENDOR_ID,
767 info->subsystem_vendor_id);
768 pci_set_word(pci_dev->config + PCI_SUBSYSTEM_ID,
771 pci_set_default_subsystem_id(pci_dev);
774 /* subsystem_vendor_id/subsystem_id are only for header type 0 */
775 assert(!info->subsystem_vendor_id);
776 assert(!info->subsystem_id);
778 pci_init_cmask(pci_dev);
779 pci_init_wmask(pci_dev);
780 pci_init_w1cmask(pci_dev);
781 if (info->is_bridge) {
782 pci_init_wmask_bridge(pci_dev);
784 if (pci_init_multifunction(bus, pci_dev)) {
785 pci_config_free(pci_dev);
790 config_read = pci_default_read_config;
792 config_write = pci_default_write_config;
793 pci_dev->config_read = config_read;
794 pci_dev->config_write = config_write;
795 bus->devices[devfn] = pci_dev;
796 pci_dev->irq = qemu_allocate_irqs(pci_set_irq, pci_dev, PCI_NUM_PINS);
797 pci_dev->version_id = 2; /* Current pci device vmstate version */
801 static void do_pci_unregister_device(PCIDevice *pci_dev)
803 qemu_free_irqs(pci_dev->irq);
804 pci_dev->bus->devices[pci_dev->devfn] = NULL;
805 pci_config_free(pci_dev);
808 /* TODO: obsolete. eliminate this once all pci devices are qdevifed. */
809 PCIDevice *pci_register_device(PCIBus *bus, const char *name,
810 int instance_size, int devfn,
811 PCIConfigReadFunc *config_read,
812 PCIConfigWriteFunc *config_write)
815 PCIDeviceInfo info = {
816 .config_read = config_read,
817 .config_write = config_write,
820 pci_dev = g_malloc0(instance_size);
821 pci_dev = do_pci_register_device(pci_dev, bus, name, devfn, &info);
822 if (pci_dev == NULL) {
823 hw_error("PCI: can't register device\n");
828 static void pci_unregister_io_regions(PCIDevice *pci_dev)
833 for(i = 0; i < PCI_NUM_REGIONS; i++) {
834 r = &pci_dev->io_regions[i];
835 if (!r->size || r->addr == PCI_BAR_UNMAPPED)
837 memory_region_del_subregion(r->address_space, r->memory);
841 static int pci_unregister_device(DeviceState *dev)
843 PCIDevice *pci_dev = DO_UPCAST(PCIDevice, qdev, dev);
844 PCIDeviceInfo *info = DO_UPCAST(PCIDeviceInfo, qdev, dev->info);
848 ret = info->exit(pci_dev);
852 pci_unregister_io_regions(pci_dev);
853 pci_del_option_rom(pci_dev);
854 g_free(pci_dev->romfile);
855 do_pci_unregister_device(pci_dev);
859 void pci_register_bar(PCIDevice *pci_dev, int region_num,
860 uint8_t type, MemoryRegion *memory)
865 pcibus_t size = memory_region_size(memory);
867 assert(region_num >= 0);
868 assert(region_num < PCI_NUM_REGIONS);
869 if (size & (size-1)) {
870 fprintf(stderr, "ERROR: PCI region size must be pow2 "
871 "type=0x%x, size=0x%"FMT_PCIBUS"\n", type, size);
875 r = &pci_dev->io_regions[region_num];
876 r->addr = PCI_BAR_UNMAPPED;
882 addr = pci_bar(pci_dev, region_num);
883 if (region_num == PCI_ROM_SLOT) {
884 /* ROM enable bit is writable */
885 wmask |= PCI_ROM_ADDRESS_ENABLE;
887 pci_set_long(pci_dev->config + addr, type);
888 if (!(r->type & PCI_BASE_ADDRESS_SPACE_IO) &&
889 r->type & PCI_BASE_ADDRESS_MEM_TYPE_64) {
890 pci_set_quad(pci_dev->wmask + addr, wmask);
891 pci_set_quad(pci_dev->cmask + addr, ~0ULL);
893 pci_set_long(pci_dev->wmask + addr, wmask & 0xffffffff);
894 pci_set_long(pci_dev->cmask + addr, 0xffffffff);
896 pci_dev->io_regions[region_num].memory = memory;
897 pci_dev->io_regions[region_num].address_space
898 = type & PCI_BASE_ADDRESS_SPACE_IO
899 ? pci_dev->bus->address_space_io
900 : pci_dev->bus->address_space_mem;
903 pcibus_t pci_get_bar_addr(PCIDevice *pci_dev, int region_num)
905 return pci_dev->io_regions[region_num].addr;
908 static pcibus_t pci_bar_address(PCIDevice *d,
909 int reg, uint8_t type, pcibus_t size)
911 pcibus_t new_addr, last_addr;
912 int bar = pci_bar(d, reg);
913 uint16_t cmd = pci_get_word(d->config + PCI_COMMAND);
915 if (type & PCI_BASE_ADDRESS_SPACE_IO) {
916 if (!(cmd & PCI_COMMAND_IO)) {
917 return PCI_BAR_UNMAPPED;
919 new_addr = pci_get_long(d->config + bar) & ~(size - 1);
920 last_addr = new_addr + size - 1;
921 /* NOTE: we have only 64K ioports on PC */
922 if (last_addr <= new_addr || new_addr == 0 || last_addr > UINT16_MAX) {
923 return PCI_BAR_UNMAPPED;
928 if (!(cmd & PCI_COMMAND_MEMORY)) {
929 return PCI_BAR_UNMAPPED;
931 if (type & PCI_BASE_ADDRESS_MEM_TYPE_64) {
932 new_addr = pci_get_quad(d->config + bar);
934 new_addr = pci_get_long(d->config + bar);
936 /* the ROM slot has a specific enable bit */
937 if (reg == PCI_ROM_SLOT && !(new_addr & PCI_ROM_ADDRESS_ENABLE)) {
938 return PCI_BAR_UNMAPPED;
940 new_addr &= ~(size - 1);
941 last_addr = new_addr + size - 1;
942 /* NOTE: we do not support wrapping */
943 /* XXX: as we cannot support really dynamic
944 mappings, we handle specific values as invalid
946 if (last_addr <= new_addr || new_addr == 0 ||
947 last_addr == PCI_BAR_UNMAPPED) {
948 return PCI_BAR_UNMAPPED;
951 /* Now pcibus_t is 64bit.
952 * Check if 32 bit BAR wraps around explicitly.
953 * Without this, PC ide doesn't work well.
954 * TODO: remove this work around.
956 if (!(type & PCI_BASE_ADDRESS_MEM_TYPE_64) && last_addr >= UINT32_MAX) {
957 return PCI_BAR_UNMAPPED;
961 * OS is allowed to set BAR beyond its addressable
962 * bits. For example, 32 bit OS can set 64bit bar
963 * to >4G. Check it. TODO: we might need to support
964 * it in the future for e.g. PAE.
966 if (last_addr >= TARGET_PHYS_ADDR_MAX) {
967 return PCI_BAR_UNMAPPED;
973 static void pci_update_mappings(PCIDevice *d)
979 for(i = 0; i < PCI_NUM_REGIONS; i++) {
980 r = &d->io_regions[i];
982 /* this region isn't registered */
986 new_addr = pci_bar_address(d, i, r->type, r->size);
988 /* This bar isn't changed */
989 if (new_addr == r->addr)
992 /* now do the real mapping */
993 if (r->addr != PCI_BAR_UNMAPPED) {
994 memory_region_del_subregion(r->address_space, r->memory);
997 if (r->addr != PCI_BAR_UNMAPPED) {
998 memory_region_add_subregion_overlap(r->address_space,
999 r->addr, r->memory, 1);
1004 static inline int pci_irq_disabled(PCIDevice *d)
1006 return pci_get_word(d->config + PCI_COMMAND) & PCI_COMMAND_INTX_DISABLE;
1009 /* Called after interrupt disabled field update in config space,
1010 * assert/deassert interrupts if necessary.
1011 * Gets original interrupt disable bit value (before update). */
1012 static void pci_update_irq_disabled(PCIDevice *d, int was_irq_disabled)
1014 int i, disabled = pci_irq_disabled(d);
1015 if (disabled == was_irq_disabled)
1017 for (i = 0; i < PCI_NUM_PINS; ++i) {
1018 int state = pci_irq_state(d, i);
1019 pci_change_irq_level(d, i, disabled ? -state : state);
1023 uint32_t pci_default_read_config(PCIDevice *d,
1024 uint32_t address, int len)
1028 memcpy(&val, d->config + address, len);
1029 return le32_to_cpu(val);
1032 void pci_default_write_config(PCIDevice *d, uint32_t addr, uint32_t val, int l)
1034 int i, was_irq_disabled = pci_irq_disabled(d);
1036 for (i = 0; i < l; val >>= 8, ++i) {
1037 uint8_t wmask = d->wmask[addr + i];
1038 uint8_t w1cmask = d->w1cmask[addr + i];
1039 assert(!(wmask & w1cmask));
1040 d->config[addr + i] = (d->config[addr + i] & ~wmask) | (val & wmask);
1041 d->config[addr + i] &= ~(val & w1cmask); /* W1C: Write 1 to Clear */
1043 if (ranges_overlap(addr, l, PCI_BASE_ADDRESS_0, 24) ||
1044 ranges_overlap(addr, l, PCI_ROM_ADDRESS, 4) ||
1045 ranges_overlap(addr, l, PCI_ROM_ADDRESS1, 4) ||
1046 range_covers_byte(addr, l, PCI_COMMAND))
1047 pci_update_mappings(d);
1049 if (range_covers_byte(addr, l, PCI_COMMAND))
1050 pci_update_irq_disabled(d, was_irq_disabled);
1053 /***********************************************************/
1054 /* generic PCI irq support */
1056 /* 0 <= irq_num <= 3. level must be 0 or 1 */
1057 static void pci_set_irq(void *opaque, int irq_num, int level)
1059 PCIDevice *pci_dev = opaque;
1062 change = level - pci_irq_state(pci_dev, irq_num);
1066 pci_set_irq_state(pci_dev, irq_num, level);
1067 pci_update_irq_status(pci_dev);
1068 if (pci_irq_disabled(pci_dev))
1070 pci_change_irq_level(pci_dev, irq_num, change);
1073 /***********************************************************/
1074 /* monitor info on PCI */
1079 const char *fw_name;
1080 uint16_t fw_ign_bits;
1083 static const pci_class_desc pci_class_descriptions[] =
1085 { 0x0001, "VGA controller", "display"},
1086 { 0x0100, "SCSI controller", "scsi"},
1087 { 0x0101, "IDE controller", "ide"},
1088 { 0x0102, "Floppy controller", "fdc"},
1089 { 0x0103, "IPI controller", "ipi"},
1090 { 0x0104, "RAID controller", "raid"},
1091 { 0x0106, "SATA controller"},
1092 { 0x0107, "SAS controller"},
1093 { 0x0180, "Storage controller"},
1094 { 0x0200, "Ethernet controller", "ethernet"},
1095 { 0x0201, "Token Ring controller", "token-ring"},
1096 { 0x0202, "FDDI controller", "fddi"},
1097 { 0x0203, "ATM controller", "atm"},
1098 { 0x0280, "Network controller"},
1099 { 0x0300, "VGA controller", "display", 0x00ff},
1100 { 0x0301, "XGA controller"},
1101 { 0x0302, "3D controller"},
1102 { 0x0380, "Display controller"},
1103 { 0x0400, "Video controller", "video"},
1104 { 0x0401, "Audio controller", "sound"},
1106 { 0x0403, "Audio controller", "sound"},
1107 { 0x0480, "Multimedia controller"},
1108 { 0x0500, "RAM controller", "memory"},
1109 { 0x0501, "Flash controller", "flash"},
1110 { 0x0580, "Memory controller"},
1111 { 0x0600, "Host bridge", "host"},
1112 { 0x0601, "ISA bridge", "isa"},
1113 { 0x0602, "EISA bridge", "eisa"},
1114 { 0x0603, "MC bridge", "mca"},
1115 { 0x0604, "PCI bridge", "pci"},
1116 { 0x0605, "PCMCIA bridge", "pcmcia"},
1117 { 0x0606, "NUBUS bridge", "nubus"},
1118 { 0x0607, "CARDBUS bridge", "cardbus"},
1119 { 0x0608, "RACEWAY bridge"},
1120 { 0x0680, "Bridge"},
1121 { 0x0700, "Serial port", "serial"},
1122 { 0x0701, "Parallel port", "parallel"},
1123 { 0x0800, "Interrupt controller", "interrupt-controller"},
1124 { 0x0801, "DMA controller", "dma-controller"},
1125 { 0x0802, "Timer", "timer"},
1126 { 0x0803, "RTC", "rtc"},
1127 { 0x0900, "Keyboard", "keyboard"},
1128 { 0x0901, "Pen", "pen"},
1129 { 0x0902, "Mouse", "mouse"},
1130 { 0x0A00, "Dock station", "dock", 0x00ff},
1131 { 0x0B00, "i386 cpu", "cpu", 0x00ff},
1132 { 0x0c00, "Fireware contorller", "fireware"},
1133 { 0x0c01, "Access bus controller", "access-bus"},
1134 { 0x0c02, "SSA controller", "ssa"},
1135 { 0x0c03, "USB controller", "usb"},
1136 { 0x0c04, "Fibre channel controller", "fibre-channel"},
1140 static void pci_for_each_device_under_bus(PCIBus *bus,
1141 void (*fn)(PCIBus *b, PCIDevice *d))
1146 for(devfn = 0; devfn < ARRAY_SIZE(bus->devices); devfn++) {
1147 d = bus->devices[devfn];
1154 void pci_for_each_device(PCIBus *bus, int bus_num,
1155 void (*fn)(PCIBus *b, PCIDevice *d))
1157 bus = pci_find_bus(bus, bus_num);
1160 pci_for_each_device_under_bus(bus, fn);
1164 static const pci_class_desc *get_class_desc(int class)
1166 const pci_class_desc *desc;
1168 desc = pci_class_descriptions;
1169 while (desc->desc && class != desc->class) {
1176 static PciDeviceInfoList *qmp_query_pci_devices(PCIBus *bus, int bus_num);
1178 static PciMemoryRegionList *qmp_query_pci_regions(const PCIDevice *dev)
1180 PciMemoryRegionList *head = NULL, *cur_item = NULL;
1183 for (i = 0; i < PCI_NUM_REGIONS; i++) {
1184 const PCIIORegion *r = &dev->io_regions[i];
1185 PciMemoryRegionList *region;
1191 region = g_malloc0(sizeof(*region));
1192 region->value = g_malloc0(sizeof(*region->value));
1194 if (r->type & PCI_BASE_ADDRESS_SPACE_IO) {
1195 region->value->type = g_strdup("io");
1197 region->value->type = g_strdup("memory");
1198 region->value->has_prefetch = true;
1199 region->value->prefetch = !!(r->type & PCI_BASE_ADDRESS_MEM_PREFETCH);
1200 region->value->has_mem_type_64 = true;
1201 region->value->mem_type_64 = !!(r->type & PCI_BASE_ADDRESS_MEM_TYPE_64);
1204 region->value->bar = i;
1205 region->value->address = r->addr;
1206 region->value->size = r->size;
1208 /* XXX: waiting for the qapi to support GSList */
1210 head = cur_item = region;
1212 cur_item->next = region;
1220 static PciBridgeInfo *qmp_query_pci_bridge(PCIDevice *dev, PCIBus *bus,
1223 PciBridgeInfo *info;
1225 info = g_malloc0(sizeof(*info));
1227 info->bus.number = dev->config[PCI_PRIMARY_BUS];
1228 info->bus.secondary = dev->config[PCI_SECONDARY_BUS];
1229 info->bus.subordinate = dev->config[PCI_SUBORDINATE_BUS];
1231 info->bus.io_range = g_malloc0(sizeof(*info->bus.io_range));
1232 info->bus.io_range->base = pci_bridge_get_base(dev, PCI_BASE_ADDRESS_SPACE_IO);
1233 info->bus.io_range->limit = pci_bridge_get_limit(dev, PCI_BASE_ADDRESS_SPACE_IO);
1235 info->bus.memory_range = g_malloc0(sizeof(*info->bus.memory_range));
1236 info->bus.memory_range->base = pci_bridge_get_base(dev, PCI_BASE_ADDRESS_SPACE_MEMORY);
1237 info->bus.memory_range->limit = pci_bridge_get_limit(dev, PCI_BASE_ADDRESS_SPACE_MEMORY);
1239 info->bus.prefetchable_range = g_malloc0(sizeof(*info->bus.prefetchable_range));
1240 info->bus.prefetchable_range->base = pci_bridge_get_base(dev, PCI_BASE_ADDRESS_MEM_PREFETCH);
1241 info->bus.prefetchable_range->limit = pci_bridge_get_limit(dev, PCI_BASE_ADDRESS_MEM_PREFETCH);
1243 if (dev->config[PCI_SECONDARY_BUS] != 0) {
1244 PCIBus *child_bus = pci_find_bus(bus, dev->config[PCI_SECONDARY_BUS]);
1246 info->has_devices = true;
1247 info->devices = qmp_query_pci_devices(child_bus, dev->config[PCI_SECONDARY_BUS]);
1254 static PciDeviceInfo *qmp_query_pci_device(PCIDevice *dev, PCIBus *bus,
1257 const pci_class_desc *desc;
1258 PciDeviceInfo *info;
1262 info = g_malloc0(sizeof(*info));
1263 info->bus = bus_num;
1264 info->slot = PCI_SLOT(dev->devfn);
1265 info->function = PCI_FUNC(dev->devfn);
1267 class = pci_get_word(dev->config + PCI_CLASS_DEVICE);
1268 info->class_info.class = class;
1269 desc = get_class_desc(class);
1271 info->class_info.has_desc = true;
1272 info->class_info.desc = g_strdup(desc->desc);
1275 info->id.vendor = pci_get_word(dev->config + PCI_VENDOR_ID);
1276 info->id.device = pci_get_word(dev->config + PCI_DEVICE_ID);
1277 info->regions = qmp_query_pci_regions(dev);
1278 info->qdev_id = g_strdup(dev->qdev.id ? dev->qdev.id : "");
1280 if (dev->config[PCI_INTERRUPT_PIN] != 0) {
1281 info->has_irq = true;
1282 info->irq = dev->config[PCI_INTERRUPT_LINE];
1285 type = dev->config[PCI_HEADER_TYPE] & ~PCI_HEADER_TYPE_MULTI_FUNCTION;
1286 if (type == PCI_HEADER_TYPE_BRIDGE) {
1287 info->has_pci_bridge = true;
1288 info->pci_bridge = qmp_query_pci_bridge(dev, bus, bus_num);
1294 static PciDeviceInfoList *qmp_query_pci_devices(PCIBus *bus, int bus_num)
1296 PciDeviceInfoList *info, *head = NULL, *cur_item = NULL;
1300 for (devfn = 0; devfn < ARRAY_SIZE(bus->devices); devfn++) {
1301 dev = bus->devices[devfn];
1303 info = g_malloc0(sizeof(*info));
1304 info->value = qmp_query_pci_device(dev, bus, bus_num);
1306 /* XXX: waiting for the qapi to support GSList */
1308 head = cur_item = info;
1310 cur_item->next = info;
1319 static PciInfo *qmp_query_pci_bus(PCIBus *bus, int bus_num)
1321 PciInfo *info = NULL;
1323 bus = pci_find_bus(bus, bus_num);
1325 info = g_malloc0(sizeof(*info));
1326 info->bus = bus_num;
1327 info->devices = qmp_query_pci_devices(bus, bus_num);
1333 PciInfoList *qmp_query_pci(Error **errp)
1335 PciInfoList *info, *head = NULL, *cur_item = NULL;
1336 struct PCIHostBus *host;
1338 QLIST_FOREACH(host, &host_buses, next) {
1339 info = g_malloc0(sizeof(*info));
1340 info->value = qmp_query_pci_bus(host->bus, 0);
1342 /* XXX: waiting for the qapi to support GSList */
1344 head = cur_item = info;
1346 cur_item->next = info;
1354 static const char * const pci_nic_models[] = {
1366 static const char * const pci_nic_names[] = {
1378 /* Initialize a PCI NIC. */
1379 /* FIXME callers should check for failure, but don't */
1380 PCIDevice *pci_nic_init(NICInfo *nd, const char *default_model,
1381 const char *default_devaddr)
1383 const char *devaddr = nd->devaddr ? nd->devaddr : default_devaddr;
1390 i = qemu_find_nic_model(nd, pci_nic_models, default_model);
1394 bus = pci_get_bus_devfn(&devfn, devaddr);
1396 error_report("Invalid PCI device address %s for device %s",
1397 devaddr, pci_nic_names[i]);
1401 pci_dev = pci_create(bus, devfn, pci_nic_names[i]);
1402 dev = &pci_dev->qdev;
1403 qdev_set_nic_properties(dev, nd);
1404 if (qdev_init(dev) < 0)
1409 PCIDevice *pci_nic_init_nofail(NICInfo *nd, const char *default_model,
1410 const char *default_devaddr)
1414 if (qemu_show_nic_models(nd->model, pci_nic_models))
1417 res = pci_nic_init(nd, default_model, default_devaddr);
1423 /* Whether a given bus number is in range of the secondary
1424 * bus of the given bridge device. */
1425 static bool pci_secondary_bus_in_range(PCIDevice *dev, int bus_num)
1427 return !(pci_get_word(dev->config + PCI_BRIDGE_CONTROL) &
1428 PCI_BRIDGE_CTL_BUS_RESET) /* Don't walk the bus if it's reset. */ &&
1429 dev->config[PCI_SECONDARY_BUS] < bus_num &&
1430 bus_num <= dev->config[PCI_SUBORDINATE_BUS];
1433 PCIBus *pci_find_bus(PCIBus *bus, int bus_num)
1441 if (pci_bus_num(bus) == bus_num) {
1445 /* Consider all bus numbers in range for the host pci bridge. */
1446 if (bus->parent_dev &&
1447 !pci_secondary_bus_in_range(bus->parent_dev, bus_num)) {
1452 for (; bus; bus = sec) {
1453 QLIST_FOREACH(sec, &bus->child, sibling) {
1454 assert(sec->parent_dev);
1455 if (sec->parent_dev->config[PCI_SECONDARY_BUS] == bus_num) {
1458 if (pci_secondary_bus_in_range(sec->parent_dev, bus_num)) {
1467 PCIDevice *pci_find_device(PCIBus *bus, int bus_num, uint8_t devfn)
1469 bus = pci_find_bus(bus, bus_num);
1474 return bus->devices[devfn];
1477 static int pci_qdev_init(DeviceState *qdev, DeviceInfo *base)
1479 PCIDevice *pci_dev = (PCIDevice *)qdev;
1480 PCIDeviceInfo *info = container_of(base, PCIDeviceInfo, qdev);
1483 bool is_default_rom;
1485 /* initialize cap_present for pci_is_express() and pci_config_size() */
1486 if (info->is_express) {
1487 pci_dev->cap_present |= QEMU_PCI_CAP_EXPRESS;
1490 bus = FROM_QBUS(PCIBus, qdev_get_parent_bus(qdev));
1491 pci_dev = do_pci_register_device(pci_dev, bus, base->name,
1492 pci_dev->devfn, info);
1493 if (pci_dev == NULL)
1495 if (qdev->hotplugged && info->no_hotplug) {
1496 qerror_report(QERR_DEVICE_NO_HOTPLUG, info->qdev.name);
1497 do_pci_unregister_device(pci_dev);
1501 rc = info->init(pci_dev);
1503 do_pci_unregister_device(pci_dev);
1509 is_default_rom = false;
1510 if (pci_dev->romfile == NULL && info->romfile != NULL) {
1511 pci_dev->romfile = g_strdup(info->romfile);
1512 is_default_rom = true;
1514 pci_add_option_rom(pci_dev, is_default_rom);
1517 /* Let buses differentiate between hotplug and when device is
1518 * enabled during qemu machine creation. */
1519 rc = bus->hotplug(bus->hotplug_qdev, pci_dev,
1520 qdev->hotplugged ? PCI_HOTPLUG_ENABLED:
1521 PCI_COLDPLUG_ENABLED);
1523 int r = pci_unregister_device(&pci_dev->qdev);
1531 static int pci_unplug_device(DeviceState *qdev)
1533 PCIDevice *dev = DO_UPCAST(PCIDevice, qdev, qdev);
1534 PCIDeviceInfo *info = container_of(qdev->info, PCIDeviceInfo, qdev);
1536 if (info->no_hotplug) {
1537 qerror_report(QERR_DEVICE_NO_HOTPLUG, info->qdev.name);
1540 return dev->bus->hotplug(dev->bus->hotplug_qdev, dev,
1541 PCI_HOTPLUG_DISABLED);
1544 void pci_qdev_register(PCIDeviceInfo *info)
1546 info->qdev.init = pci_qdev_init;
1547 info->qdev.unplug = pci_unplug_device;
1548 info->qdev.exit = pci_unregister_device;
1549 info->qdev.bus_info = &pci_bus_info;
1550 qdev_register(&info->qdev);
1553 void pci_qdev_register_many(PCIDeviceInfo *info)
1555 while (info->qdev.name) {
1556 pci_qdev_register(info);
1561 PCIDevice *pci_create_multifunction(PCIBus *bus, int devfn, bool multifunction,
1566 dev = qdev_create(&bus->qbus, name);
1567 qdev_prop_set_uint32(dev, "addr", devfn);
1568 qdev_prop_set_bit(dev, "multifunction", multifunction);
1569 return DO_UPCAST(PCIDevice, qdev, dev);
1572 PCIDevice *pci_create_simple_multifunction(PCIBus *bus, int devfn,
1576 PCIDevice *dev = pci_create_multifunction(bus, devfn, multifunction, name);
1577 qdev_init_nofail(&dev->qdev);
1581 PCIDevice *pci_create(PCIBus *bus, int devfn, const char *name)
1583 return pci_create_multifunction(bus, devfn, false, name);
1586 PCIDevice *pci_create_simple(PCIBus *bus, int devfn, const char *name)
1588 return pci_create_simple_multifunction(bus, devfn, false, name);
1591 static int pci_find_space(PCIDevice *pdev, uint8_t size)
1593 int config_size = pci_config_size(pdev);
1594 int offset = PCI_CONFIG_HEADER_SIZE;
1596 for (i = PCI_CONFIG_HEADER_SIZE; i < config_size; ++i)
1599 else if (i - offset + 1 == size)
1604 static uint8_t pci_find_capability_list(PCIDevice *pdev, uint8_t cap_id,
1609 if (!(pdev->config[PCI_STATUS] & PCI_STATUS_CAP_LIST))
1612 for (prev = PCI_CAPABILITY_LIST; (next = pdev->config[prev]);
1613 prev = next + PCI_CAP_LIST_NEXT)
1614 if (pdev->config[next + PCI_CAP_LIST_ID] == cap_id)
1622 static uint8_t pci_find_capability_at_offset(PCIDevice *pdev, uint8_t offset)
1624 uint8_t next, prev, found = 0;
1626 if (!(pdev->used[offset])) {
1630 assert(pdev->config[PCI_STATUS] & PCI_STATUS_CAP_LIST);
1632 for (prev = PCI_CAPABILITY_LIST; (next = pdev->config[prev]);
1633 prev = next + PCI_CAP_LIST_NEXT) {
1634 if (next <= offset && next > found) {
1641 /* Patch the PCI vendor and device ids in a PCI rom image if necessary.
1642 This is needed for an option rom which is used for more than one device. */
1643 static void pci_patch_ids(PCIDevice *pdev, uint8_t *ptr, int size)
1647 uint16_t rom_vendor_id;
1648 uint16_t rom_device_id;
1650 uint16_t pcir_offset;
1653 /* Words in rom data are little endian (like in PCI configuration),
1654 so they can be read / written with pci_get_word / pci_set_word. */
1656 /* Only a valid rom will be patched. */
1657 rom_magic = pci_get_word(ptr);
1658 if (rom_magic != 0xaa55) {
1659 PCI_DPRINTF("Bad ROM magic %04x\n", rom_magic);
1662 pcir_offset = pci_get_word(ptr + 0x18);
1663 if (pcir_offset + 8 >= size || memcmp(ptr + pcir_offset, "PCIR", 4)) {
1664 PCI_DPRINTF("Bad PCIR offset 0x%x or signature\n", pcir_offset);
1668 vendor_id = pci_get_word(pdev->config + PCI_VENDOR_ID);
1669 device_id = pci_get_word(pdev->config + PCI_DEVICE_ID);
1670 rom_vendor_id = pci_get_word(ptr + pcir_offset + 4);
1671 rom_device_id = pci_get_word(ptr + pcir_offset + 6);
1673 PCI_DPRINTF("%s: ROM id %04x%04x / PCI id %04x%04x\n", pdev->romfile,
1674 vendor_id, device_id, rom_vendor_id, rom_device_id);
1678 if (vendor_id != rom_vendor_id) {
1679 /* Patch vendor id and checksum (at offset 6 for etherboot roms). */
1680 checksum += (uint8_t)rom_vendor_id + (uint8_t)(rom_vendor_id >> 8);
1681 checksum -= (uint8_t)vendor_id + (uint8_t)(vendor_id >> 8);
1682 PCI_DPRINTF("ROM checksum %02x / %02x\n", ptr[6], checksum);
1684 pci_set_word(ptr + pcir_offset + 4, vendor_id);
1687 if (device_id != rom_device_id) {
1688 /* Patch device id and checksum (at offset 6 for etherboot roms). */
1689 checksum += (uint8_t)rom_device_id + (uint8_t)(rom_device_id >> 8);
1690 checksum -= (uint8_t)device_id + (uint8_t)(device_id >> 8);
1691 PCI_DPRINTF("ROM checksum %02x / %02x\n", ptr[6], checksum);
1693 pci_set_word(ptr + pcir_offset + 6, device_id);
1697 /* Add an option rom for the device */
1698 static int pci_add_option_rom(PCIDevice *pdev, bool is_default_rom)
1707 if (strlen(pdev->romfile) == 0)
1710 if (!pdev->rom_bar) {
1712 * Load rom via fw_cfg instead of creating a rom bar,
1713 * for 0.11 compatibility.
1715 int class = pci_get_word(pdev->config + PCI_CLASS_DEVICE);
1716 if (class == 0x0300) {
1717 rom_add_vga(pdev->romfile);
1719 rom_add_option(pdev->romfile, -1);
1724 path = qemu_find_file(QEMU_FILE_TYPE_BIOS, pdev->romfile);
1726 path = g_strdup(pdev->romfile);
1729 size = get_image_size(path);
1731 error_report("%s: failed to find romfile \"%s\"",
1732 __FUNCTION__, pdev->romfile);
1736 if (size & (size - 1)) {
1737 size = 1 << qemu_fls(size);
1740 if (pdev->qdev.info->vmsd)
1741 snprintf(name, sizeof(name), "%s.rom", pdev->qdev.info->vmsd->name);
1743 snprintf(name, sizeof(name), "%s.rom", pdev->qdev.info->name);
1744 pdev->has_rom = true;
1745 memory_region_init_ram(&pdev->rom, name, size);
1746 vmstate_register_ram(&pdev->rom, &pdev->qdev);
1747 ptr = memory_region_get_ram_ptr(&pdev->rom);
1748 load_image(path, ptr);
1751 if (is_default_rom) {
1752 /* Only the default rom images will be patched (if needed). */
1753 pci_patch_ids(pdev, ptr, size);
1756 qemu_put_ram_ptr(ptr);
1758 pci_register_bar(pdev, PCI_ROM_SLOT, 0, &pdev->rom);
1763 static void pci_del_option_rom(PCIDevice *pdev)
1768 vmstate_unregister_ram(&pdev->rom, &pdev->qdev);
1769 memory_region_destroy(&pdev->rom);
1770 pdev->has_rom = false;
1775 * Reserve space and add capability to the linked list in pci config space
1778 * Find and reserve space and add capability to the linked list
1779 * in pci config space */
1780 int pci_add_capability(PCIDevice *pdev, uint8_t cap_id,
1781 uint8_t offset, uint8_t size)
1784 int i, overlapping_cap;
1787 offset = pci_find_space(pdev, size);
1792 /* Verify that capabilities don't overlap. Note: device assignment
1793 * depends on this check to verify that the device is not broken.
1794 * Should never trigger for emulated devices, but it's helpful
1795 * for debugging these. */
1796 for (i = offset; i < offset + size; i++) {
1797 overlapping_cap = pci_find_capability_at_offset(pdev, i);
1798 if (overlapping_cap) {
1799 fprintf(stderr, "ERROR: %04x:%02x:%02x.%x "
1800 "Attempt to add PCI capability %x at offset "
1801 "%x overlaps existing capability %x at offset %x\n",
1802 pci_find_domain(pdev->bus), pci_bus_num(pdev->bus),
1803 PCI_SLOT(pdev->devfn), PCI_FUNC(pdev->devfn),
1804 cap_id, offset, overlapping_cap, i);
1810 config = pdev->config + offset;
1811 config[PCI_CAP_LIST_ID] = cap_id;
1812 config[PCI_CAP_LIST_NEXT] = pdev->config[PCI_CAPABILITY_LIST];
1813 pdev->config[PCI_CAPABILITY_LIST] = offset;
1814 pdev->config[PCI_STATUS] |= PCI_STATUS_CAP_LIST;
1815 memset(pdev->used + offset, 0xFF, size);
1816 /* Make capability read-only by default */
1817 memset(pdev->wmask + offset, 0, size);
1818 /* Check capability by default */
1819 memset(pdev->cmask + offset, 0xFF, size);
1823 /* Unlink capability from the pci config space. */
1824 void pci_del_capability(PCIDevice *pdev, uint8_t cap_id, uint8_t size)
1826 uint8_t prev, offset = pci_find_capability_list(pdev, cap_id, &prev);
1829 pdev->config[prev] = pdev->config[offset + PCI_CAP_LIST_NEXT];
1830 /* Make capability writable again */
1831 memset(pdev->wmask + offset, 0xff, size);
1832 memset(pdev->w1cmask + offset, 0, size);
1833 /* Clear cmask as device-specific registers can't be checked */
1834 memset(pdev->cmask + offset, 0, size);
1835 memset(pdev->used + offset, 0, size);
1837 if (!pdev->config[PCI_CAPABILITY_LIST])
1838 pdev->config[PCI_STATUS] &= ~PCI_STATUS_CAP_LIST;
1841 uint8_t pci_find_capability(PCIDevice *pdev, uint8_t cap_id)
1843 return pci_find_capability_list(pdev, cap_id, NULL);
1846 static void pcibus_dev_print(Monitor *mon, DeviceState *dev, int indent)
1848 PCIDevice *d = (PCIDevice *)dev;
1849 const pci_class_desc *desc;
1854 class = pci_get_word(d->config + PCI_CLASS_DEVICE);
1855 desc = pci_class_descriptions;
1856 while (desc->desc && class != desc->class)
1859 snprintf(ctxt, sizeof(ctxt), "%s", desc->desc);
1861 snprintf(ctxt, sizeof(ctxt), "Class %04x", class);
1864 monitor_printf(mon, "%*sclass %s, addr %02x:%02x.%x, "
1865 "pci id %04x:%04x (sub %04x:%04x)\n",
1866 indent, "", ctxt, pci_bus_num(d->bus),
1867 PCI_SLOT(d->devfn), PCI_FUNC(d->devfn),
1868 pci_get_word(d->config + PCI_VENDOR_ID),
1869 pci_get_word(d->config + PCI_DEVICE_ID),
1870 pci_get_word(d->config + PCI_SUBSYSTEM_VENDOR_ID),
1871 pci_get_word(d->config + PCI_SUBSYSTEM_ID));
1872 for (i = 0; i < PCI_NUM_REGIONS; i++) {
1873 r = &d->io_regions[i];
1876 monitor_printf(mon, "%*sbar %d: %s at 0x%"FMT_PCIBUS
1877 " [0x%"FMT_PCIBUS"]\n",
1879 i, r->type & PCI_BASE_ADDRESS_SPACE_IO ? "i/o" : "mem",
1880 r->addr, r->addr + r->size - 1);
1884 static char *pci_dev_fw_name(DeviceState *dev, char *buf, int len)
1886 PCIDevice *d = (PCIDevice *)dev;
1887 const char *name = NULL;
1888 const pci_class_desc *desc = pci_class_descriptions;
1889 int class = pci_get_word(d->config + PCI_CLASS_DEVICE);
1891 while (desc->desc &&
1892 (class & ~desc->fw_ign_bits) !=
1893 (desc->class & ~desc->fw_ign_bits)) {
1898 name = desc->fw_name;
1902 pstrcpy(buf, len, name);
1904 snprintf(buf, len, "pci%04x,%04x",
1905 pci_get_word(d->config + PCI_VENDOR_ID),
1906 pci_get_word(d->config + PCI_DEVICE_ID));
1912 static char *pcibus_get_fw_dev_path(DeviceState *dev)
1914 PCIDevice *d = (PCIDevice *)dev;
1915 char path[50], name[33];
1918 off = snprintf(path, sizeof(path), "%s@%x",
1919 pci_dev_fw_name(dev, name, sizeof name),
1920 PCI_SLOT(d->devfn));
1921 if (PCI_FUNC(d->devfn))
1922 snprintf(path + off, sizeof(path) + off, ",%x", PCI_FUNC(d->devfn));
1923 return strdup(path);
1926 static char *pcibus_get_dev_path(DeviceState *dev)
1928 PCIDevice *d = container_of(dev, PCIDevice, qdev);
1931 /* Path format: Domain:00:Slot.Function:Slot.Function....:Slot.Function.
1932 * 00 is added here to make this format compatible with
1933 * domain:Bus:Slot.Func for systems without nested PCI bridges.
1934 * Slot.Function list specifies the slot and function numbers for all
1935 * devices on the path from root to the specific device. */
1936 char domain[] = "DDDD:00";
1937 char slot[] = ":SS.F";
1938 int domain_len = sizeof domain - 1 /* For '\0' */;
1939 int slot_len = sizeof slot - 1 /* For '\0' */;
1944 /* Calculate # of slots on path between device and root. */;
1946 for (t = d; t; t = t->bus->parent_dev) {
1950 path_len = domain_len + slot_len * slot_depth;
1952 /* Allocate memory, fill in the terminating null byte. */
1953 path = g_malloc(path_len + 1 /* For '\0' */);
1954 path[path_len] = '\0';
1956 /* First field is the domain. */
1957 s = snprintf(domain, sizeof domain, "%04x:00", pci_find_domain(d->bus));
1958 assert(s == domain_len);
1959 memcpy(path, domain, domain_len);
1961 /* Fill in slot numbers. We walk up from device to root, so need to print
1962 * them in the reverse order, last to first. */
1963 p = path + path_len;
1964 for (t = d; t; t = t->bus->parent_dev) {
1966 s = snprintf(slot, sizeof slot, ":%02x.%x",
1967 PCI_SLOT(t->devfn), PCI_FUNC(t->devfn));
1968 assert(s == slot_len);
1969 memcpy(p, slot, slot_len);
1975 static int pci_qdev_find_recursive(PCIBus *bus,
1976 const char *id, PCIDevice **pdev)
1978 DeviceState *qdev = qdev_find_recursive(&bus->qbus, id);
1983 /* roughly check if given qdev is pci device */
1984 if (qdev->info->init == &pci_qdev_init &&
1985 qdev->parent_bus->info == &pci_bus_info) {
1986 *pdev = DO_UPCAST(PCIDevice, qdev, qdev);
1992 int pci_qdev_find_device(const char *id, PCIDevice **pdev)
1994 struct PCIHostBus *host;
1997 QLIST_FOREACH(host, &host_buses, next) {
1998 int tmp = pci_qdev_find_recursive(host->bus, id, pdev);
2003 if (tmp != -ENODEV) {
2011 MemoryRegion *pci_address_space(PCIDevice *dev)
2013 return dev->bus->address_space_mem;
2016 MemoryRegion *pci_address_space_io(PCIDevice *dev)
2018 return dev->bus->address_space_io;