]> Git Repo - qemu.git/blob - hw/scsi-bus.c
ide: Reject invalid CHS geometry
[qemu.git] / hw / scsi-bus.c
1 #include "hw.h"
2 #include "qemu-error.h"
3 #include "scsi.h"
4 #include "scsi-defs.h"
5 #include "qdev.h"
6
7 static struct BusInfo scsi_bus_info = {
8     .name  = "SCSI",
9     .size  = sizeof(SCSIBus),
10     .props = (Property[]) {
11         DEFINE_PROP_UINT32("scsi-id", SCSIDevice, id, -1),
12         DEFINE_PROP_END_OF_LIST(),
13     },
14 };
15 static int next_scsi_bus;
16
17 /* Create a scsi bus, and attach devices to it.  */
18 void scsi_bus_new(SCSIBus *bus, DeviceState *host, int tcq, int ndev,
19                   scsi_completionfn complete)
20 {
21     qbus_create_inplace(&bus->qbus, &scsi_bus_info, host, NULL);
22     bus->busnr = next_scsi_bus++;
23     bus->tcq = tcq;
24     bus->ndev = ndev;
25     bus->complete = complete;
26     bus->qbus.allow_hotplug = 1;
27 }
28
29 static int scsi_qdev_init(DeviceState *qdev, DeviceInfo *base)
30 {
31     SCSIDevice *dev = DO_UPCAST(SCSIDevice, qdev, qdev);
32     SCSIDeviceInfo *info = DO_UPCAST(SCSIDeviceInfo, qdev, base);
33     SCSIBus *bus = DO_UPCAST(SCSIBus, qbus, dev->qdev.parent_bus);
34     int rc = -1;
35
36     if (dev->id == -1) {
37         for (dev->id = 0; dev->id < bus->ndev; dev->id++) {
38             if (bus->devs[dev->id] == NULL)
39                 break;
40         }
41     }
42     if (dev->id >= bus->ndev) {
43         error_report("bad scsi device id: %d", dev->id);
44         goto err;
45     }
46
47     if (bus->devs[dev->id]) {
48         qdev_free(&bus->devs[dev->id]->qdev);
49     }
50     bus->devs[dev->id] = dev;
51
52     dev->info = info;
53     QTAILQ_INIT(&dev->requests);
54     rc = dev->info->init(dev);
55     if (rc != 0) {
56         bus->devs[dev->id] = NULL;
57     }
58
59 err:
60     return rc;
61 }
62
63 static int scsi_qdev_exit(DeviceState *qdev)
64 {
65     SCSIDevice *dev = DO_UPCAST(SCSIDevice, qdev, qdev);
66     SCSIBus *bus = DO_UPCAST(SCSIBus, qbus, dev->qdev.parent_bus);
67
68     assert(bus->devs[dev->id] != NULL);
69     if (bus->devs[dev->id]->info->destroy) {
70         bus->devs[dev->id]->info->destroy(bus->devs[dev->id]);
71     }
72     bus->devs[dev->id] = NULL;
73     return 0;
74 }
75
76 void scsi_qdev_register(SCSIDeviceInfo *info)
77 {
78     info->qdev.bus_info = &scsi_bus_info;
79     info->qdev.init     = scsi_qdev_init;
80     info->qdev.unplug   = qdev_simple_unplug_cb;
81     info->qdev.exit     = scsi_qdev_exit;
82     qdev_register(&info->qdev);
83 }
84
85 /* handle legacy '-drive if=scsi,...' cmd line args */
86 SCSIDevice *scsi_bus_legacy_add_drive(SCSIBus *bus, BlockDriverState *bdrv, int unit)
87 {
88     const char *driver;
89     DeviceState *dev;
90
91     driver = bdrv_is_sg(bdrv) ? "scsi-generic" : "scsi-disk";
92     dev = qdev_create(&bus->qbus, driver);
93     qdev_prop_set_uint32(dev, "scsi-id", unit);
94     if (qdev_prop_set_drive(dev, "drive", bdrv) < 0) {
95         qdev_free(dev);
96         return NULL;
97     }
98     if (qdev_init(dev) < 0)
99         return NULL;
100     return DO_UPCAST(SCSIDevice, qdev, dev);
101 }
102
103 int scsi_bus_legacy_handle_cmdline(SCSIBus *bus)
104 {
105     Location loc;
106     DriveInfo *dinfo;
107     int res = 0, unit;
108
109     loc_push_none(&loc);
110     for (unit = 0; unit < MAX_SCSI_DEVS; unit++) {
111         dinfo = drive_get(IF_SCSI, bus->busnr, unit);
112         if (dinfo == NULL) {
113             continue;
114         }
115         qemu_opts_loc_restore(dinfo->opts);
116         if (!scsi_bus_legacy_add_drive(bus, dinfo->bdrv, unit)) {
117             res = -1;
118             break;
119         }
120     }
121     loc_pop(&loc);
122     return res;
123 }
124
125 void scsi_dev_clear_sense(SCSIDevice *dev)
126 {
127     memset(&dev->sense, 0, sizeof(dev->sense));
128 }
129
130 void scsi_dev_set_sense(SCSIDevice *dev, uint8_t key)
131 {
132     dev->sense.key = key;
133 }
134
135 SCSIRequest *scsi_req_alloc(size_t size, SCSIDevice *d, uint32_t tag, uint32_t lun)
136 {
137     SCSIRequest *req;
138
139     req = qemu_mallocz(size);
140     req->bus = scsi_bus_from_device(d);
141     req->dev = d;
142     req->tag = tag;
143     req->lun = lun;
144     req->status = -1;
145     QTAILQ_INSERT_TAIL(&d->requests, req, next);
146     return req;
147 }
148
149 SCSIRequest *scsi_req_find(SCSIDevice *d, uint32_t tag)
150 {
151     SCSIRequest *req;
152
153     QTAILQ_FOREACH(req, &d->requests, next) {
154         if (req->tag == tag) {
155             return req;
156         }
157     }
158     return NULL;
159 }
160
161 void scsi_req_free(SCSIRequest *req)
162 {
163     QTAILQ_REMOVE(&req->dev->requests, req, next);
164     qemu_free(req);
165 }
166
167 static int scsi_req_length(SCSIRequest *req, uint8_t *cmd)
168 {
169     switch (cmd[0] >> 5) {
170     case 0:
171         req->cmd.xfer = cmd[4];
172         req->cmd.len = 6;
173         /* length 0 means 256 blocks */
174         if (req->cmd.xfer == 0)
175             req->cmd.xfer = 256;
176         break;
177     case 1:
178     case 2:
179         req->cmd.xfer = cmd[8] | (cmd[7] << 8);
180         req->cmd.len = 10;
181         break;
182     case 4:
183         req->cmd.xfer = cmd[13] | (cmd[12] << 8) | (cmd[11] << 16) | (cmd[10] << 24);
184         req->cmd.len = 16;
185         break;
186     case 5:
187         req->cmd.xfer = cmd[9] | (cmd[8] << 8) | (cmd[7] << 16) | (cmd[6] << 24);
188         req->cmd.len = 12;
189         break;
190     default:
191         return -1;
192     }
193
194     switch(cmd[0]) {
195     case TEST_UNIT_READY:
196     case REZERO_UNIT:
197     case START_STOP:
198     case SEEK_6:
199     case WRITE_FILEMARKS:
200     case SPACE:
201     case ERASE:
202     case ALLOW_MEDIUM_REMOVAL:
203     case VERIFY:
204     case SEEK_10:
205     case SYNCHRONIZE_CACHE:
206     case LOCK_UNLOCK_CACHE:
207     case LOAD_UNLOAD:
208     case SET_CD_SPEED:
209     case SET_LIMITS:
210     case WRITE_LONG:
211     case MOVE_MEDIUM:
212     case UPDATE_BLOCK:
213         req->cmd.xfer = 0;
214         break;
215     case MODE_SENSE:
216         break;
217     case WRITE_SAME:
218         req->cmd.xfer = 1;
219         break;
220     case READ_CAPACITY:
221         req->cmd.xfer = 8;
222         break;
223     case READ_BLOCK_LIMITS:
224         req->cmd.xfer = 6;
225         break;
226     case READ_POSITION:
227         req->cmd.xfer = 20;
228         break;
229     case SEND_VOLUME_TAG:
230         req->cmd.xfer *= 40;
231         break;
232     case MEDIUM_SCAN:
233         req->cmd.xfer *= 8;
234         break;
235     case WRITE_10:
236     case WRITE_VERIFY:
237     case WRITE_6:
238     case WRITE_12:
239     case WRITE_VERIFY_12:
240     case WRITE_16:
241     case WRITE_VERIFY_16:
242         req->cmd.xfer *= req->dev->blocksize;
243         break;
244     case READ_10:
245     case READ_6:
246     case READ_REVERSE:
247     case RECOVER_BUFFERED_DATA:
248     case READ_12:
249     case READ_16:
250         req->cmd.xfer *= req->dev->blocksize;
251         break;
252     case INQUIRY:
253         req->cmd.xfer = cmd[4] | (cmd[3] << 8);
254         break;
255     case MAINTENANCE_OUT:
256     case MAINTENANCE_IN:
257         if (req->dev->type == TYPE_ROM) {
258             /* GPCMD_REPORT_KEY and GPCMD_SEND_KEY from multi media commands */
259             req->cmd.xfer = cmd[9] | (cmd[8] << 8);
260         }
261         break;
262     }
263     return 0;
264 }
265
266 static int scsi_req_stream_length(SCSIRequest *req, uint8_t *cmd)
267 {
268     switch(cmd[0]) {
269     /* stream commands */
270     case READ_6:
271     case READ_REVERSE:
272     case RECOVER_BUFFERED_DATA:
273     case WRITE_6:
274         req->cmd.len = 6;
275         req->cmd.xfer = cmd[4] | (cmd[3] << 8) | (cmd[2] << 16);
276         if (cmd[1] & 0x01) /* fixed */
277             req->cmd.xfer *= req->dev->blocksize;
278         break;
279     case REWIND:
280     case START_STOP:
281         req->cmd.len = 6;
282         req->cmd.xfer = 0;
283         break;
284     /* generic commands */
285     default:
286         return scsi_req_length(req, cmd);
287     }
288     return 0;
289 }
290
291 static void scsi_req_xfer_mode(SCSIRequest *req)
292 {
293     switch (req->cmd.buf[0]) {
294     case WRITE_6:
295     case WRITE_10:
296     case WRITE_VERIFY:
297     case WRITE_12:
298     case WRITE_VERIFY_12:
299     case WRITE_16:
300     case WRITE_VERIFY_16:
301     case COPY:
302     case COPY_VERIFY:
303     case COMPARE:
304     case CHANGE_DEFINITION:
305     case LOG_SELECT:
306     case MODE_SELECT:
307     case MODE_SELECT_10:
308     case SEND_DIAGNOSTIC:
309     case WRITE_BUFFER:
310     case FORMAT_UNIT:
311     case REASSIGN_BLOCKS:
312     case RESERVE:
313     case SEARCH_EQUAL:
314     case SEARCH_HIGH:
315     case SEARCH_LOW:
316     case UPDATE_BLOCK:
317     case WRITE_LONG:
318     case WRITE_SAME:
319     case SEARCH_HIGH_12:
320     case SEARCH_EQUAL_12:
321     case SEARCH_LOW_12:
322     case SET_WINDOW:
323     case MEDIUM_SCAN:
324     case SEND_VOLUME_TAG:
325     case WRITE_LONG_2:
326     case PERSISTENT_RESERVE_OUT:
327     case MAINTENANCE_OUT:
328         req->cmd.mode = SCSI_XFER_TO_DEV;
329         break;
330     default:
331         if (req->cmd.xfer)
332             req->cmd.mode = SCSI_XFER_FROM_DEV;
333         else {
334             req->cmd.mode = SCSI_XFER_NONE;
335         }
336         break;
337     }
338 }
339
340 static uint64_t scsi_req_lba(SCSIRequest *req)
341 {
342     uint8_t *buf = req->cmd.buf;
343     uint64_t lba;
344
345     switch (buf[0] >> 5) {
346     case 0:
347         lba = (uint64_t) buf[3] | ((uint64_t) buf[2] << 8) |
348               (((uint64_t) buf[1] & 0x1f) << 16);
349         break;
350     case 1:
351     case 2:
352         lba = (uint64_t) buf[5] | ((uint64_t) buf[4] << 8) |
353               ((uint64_t) buf[3] << 16) | ((uint64_t) buf[2] << 24);
354         break;
355     case 4:
356         lba = (uint64_t) buf[9] | ((uint64_t) buf[8] << 8) |
357               ((uint64_t) buf[7] << 16) | ((uint64_t) buf[6] << 24) |
358               ((uint64_t) buf[5] << 32) | ((uint64_t) buf[4] << 40) |
359               ((uint64_t) buf[3] << 48) | ((uint64_t) buf[2] << 56);
360         break;
361     case 5:
362         lba = (uint64_t) buf[5] | ((uint64_t) buf[4] << 8) |
363               ((uint64_t) buf[3] << 16) | ((uint64_t) buf[2] << 24);
364         break;
365     default:
366         lba = -1;
367
368     }
369     return lba;
370 }
371
372 int scsi_req_parse(SCSIRequest *req, uint8_t *buf)
373 {
374     int rc;
375
376     if (req->dev->type == TYPE_TAPE) {
377         rc = scsi_req_stream_length(req, buf);
378     } else {
379         rc = scsi_req_length(req, buf);
380     }
381     if (rc != 0)
382         return rc;
383
384     memcpy(req->cmd.buf, buf, req->cmd.len);
385     scsi_req_xfer_mode(req);
386     req->cmd.lba = scsi_req_lba(req);
387     return 0;
388 }
389
390 static const char *scsi_command_name(uint8_t cmd)
391 {
392     static const char *names[] = {
393         [ TEST_UNIT_READY          ] = "TEST_UNIT_READY",
394         [ REZERO_UNIT              ] = "REZERO_UNIT",
395         /* REWIND and REZERO_UNIT use the same operation code */
396         [ REQUEST_SENSE            ] = "REQUEST_SENSE",
397         [ FORMAT_UNIT              ] = "FORMAT_UNIT",
398         [ READ_BLOCK_LIMITS        ] = "READ_BLOCK_LIMITS",
399         [ REASSIGN_BLOCKS          ] = "REASSIGN_BLOCKS",
400         [ READ_6                   ] = "READ_6",
401         [ WRITE_6                  ] = "WRITE_6",
402         [ SEEK_6                   ] = "SEEK_6",
403         [ READ_REVERSE             ] = "READ_REVERSE",
404         [ WRITE_FILEMARKS          ] = "WRITE_FILEMARKS",
405         [ SPACE                    ] = "SPACE",
406         [ INQUIRY                  ] = "INQUIRY",
407         [ RECOVER_BUFFERED_DATA    ] = "RECOVER_BUFFERED_DATA",
408         [ MAINTENANCE_IN           ] = "MAINTENANCE_IN",
409         [ MAINTENANCE_OUT          ] = "MAINTENANCE_OUT",
410         [ MODE_SELECT              ] = "MODE_SELECT",
411         [ RESERVE                  ] = "RESERVE",
412         [ RELEASE                  ] = "RELEASE",
413         [ COPY                     ] = "COPY",
414         [ ERASE                    ] = "ERASE",
415         [ MODE_SENSE               ] = "MODE_SENSE",
416         [ START_STOP               ] = "START_STOP",
417         [ RECEIVE_DIAGNOSTIC       ] = "RECEIVE_DIAGNOSTIC",
418         [ SEND_DIAGNOSTIC          ] = "SEND_DIAGNOSTIC",
419         [ ALLOW_MEDIUM_REMOVAL     ] = "ALLOW_MEDIUM_REMOVAL",
420
421         [ SET_WINDOW               ] = "SET_WINDOW",
422         [ READ_CAPACITY            ] = "READ_CAPACITY",
423         [ READ_10                  ] = "READ_10",
424         [ WRITE_10                 ] = "WRITE_10",
425         [ SEEK_10                  ] = "SEEK_10",
426         [ WRITE_VERIFY             ] = "WRITE_VERIFY",
427         [ VERIFY                   ] = "VERIFY",
428         [ SEARCH_HIGH              ] = "SEARCH_HIGH",
429         [ SEARCH_EQUAL             ] = "SEARCH_EQUAL",
430         [ SEARCH_LOW               ] = "SEARCH_LOW",
431         [ SET_LIMITS               ] = "SET_LIMITS",
432         [ PRE_FETCH                ] = "PRE_FETCH",
433         /* READ_POSITION and PRE_FETCH use the same operation code */
434         [ SYNCHRONIZE_CACHE        ] = "SYNCHRONIZE_CACHE",
435         [ LOCK_UNLOCK_CACHE        ] = "LOCK_UNLOCK_CACHE",
436         [ READ_DEFECT_DATA         ] = "READ_DEFECT_DATA",
437         [ MEDIUM_SCAN              ] = "MEDIUM_SCAN",
438         [ COMPARE                  ] = "COMPARE",
439         [ COPY_VERIFY              ] = "COPY_VERIFY",
440         [ WRITE_BUFFER             ] = "WRITE_BUFFER",
441         [ READ_BUFFER              ] = "READ_BUFFER",
442         [ UPDATE_BLOCK             ] = "UPDATE_BLOCK",
443         [ READ_LONG                ] = "READ_LONG",
444         [ WRITE_LONG               ] = "WRITE_LONG",
445         [ CHANGE_DEFINITION        ] = "CHANGE_DEFINITION",
446         [ WRITE_SAME               ] = "WRITE_SAME",
447         [ READ_TOC                 ] = "READ_TOC",
448         [ LOG_SELECT               ] = "LOG_SELECT",
449         [ LOG_SENSE                ] = "LOG_SENSE",
450         [ MODE_SELECT_10           ] = "MODE_SELECT_10",
451         [ RESERVE_10               ] = "RESERVE_10",
452         [ RELEASE_10               ] = "RELEASE_10",
453         [ MODE_SENSE_10            ] = "MODE_SENSE_10",
454         [ PERSISTENT_RESERVE_IN    ] = "PERSISTENT_RESERVE_IN",
455         [ PERSISTENT_RESERVE_OUT   ] = "PERSISTENT_RESERVE_OUT",
456         [ MOVE_MEDIUM              ] = "MOVE_MEDIUM",
457         [ READ_12                  ] = "READ_12",
458         [ WRITE_12                 ] = "WRITE_12",
459         [ WRITE_VERIFY_12          ] = "WRITE_VERIFY_12",
460         [ SEARCH_HIGH_12           ] = "SEARCH_HIGH_12",
461         [ SEARCH_EQUAL_12          ] = "SEARCH_EQUAL_12",
462         [ SEARCH_LOW_12            ] = "SEARCH_LOW_12",
463         [ READ_ELEMENT_STATUS      ] = "READ_ELEMENT_STATUS",
464         [ SEND_VOLUME_TAG          ] = "SEND_VOLUME_TAG",
465         [ WRITE_LONG_2             ] = "WRITE_LONG_2",
466
467         [ REPORT_DENSITY_SUPPORT   ] = "REPORT_DENSITY_SUPPORT",
468         [ GET_CONFIGURATION        ] = "GET_CONFIGURATION",
469         [ READ_16                  ] = "READ_16",
470         [ WRITE_16                 ] = "WRITE_16",
471         [ WRITE_VERIFY_16          ] = "WRITE_VERIFY_16",
472         [ SERVICE_ACTION_IN        ] = "SERVICE_ACTION_IN",
473         [ REPORT_LUNS              ] = "REPORT_LUNS",
474         [ LOAD_UNLOAD              ] = "LOAD_UNLOAD",
475         [ SET_CD_SPEED             ] = "SET_CD_SPEED",
476         [ BLANK                    ] = "BLANK",
477     };
478
479     if (cmd >= ARRAY_SIZE(names) || names[cmd] == NULL)
480         return "*UNKNOWN*";
481     return names[cmd];
482 }
483
484 void scsi_req_print(SCSIRequest *req)
485 {
486     FILE *fp = stderr;
487     int i;
488
489     fprintf(fp, "[%s id=%d] %s",
490             req->dev->qdev.parent_bus->name,
491             req->dev->id,
492             scsi_command_name(req->cmd.buf[0]));
493     for (i = 1; i < req->cmd.len; i++) {
494         fprintf(fp, " 0x%02x", req->cmd.buf[i]);
495     }
496     switch (req->cmd.mode) {
497     case SCSI_XFER_NONE:
498         fprintf(fp, " - none\n");
499         break;
500     case SCSI_XFER_FROM_DEV:
501         fprintf(fp, " - from-dev len=%zd\n", req->cmd.xfer);
502         break;
503     case SCSI_XFER_TO_DEV:
504         fprintf(fp, " - to-dev len=%zd\n", req->cmd.xfer);
505         break;
506     default:
507         fprintf(fp, " - Oops\n");
508         break;
509     }
510 }
511
512 void scsi_req_complete(SCSIRequest *req)
513 {
514     assert(req->status != -1);
515     req->bus->complete(req->bus, SCSI_REASON_DONE,
516                        req->tag,
517                        req->status);
518 }
This page took 0.053645 seconds and 4 git commands to generate.