xref: /openbmc/qemu/hw/usb/dev-uas.c (revision 3453f9a0)
10f58f68bSGerd Hoffmann /*
20f58f68bSGerd Hoffmann  * UAS (USB Attached SCSI) emulation
30f58f68bSGerd Hoffmann  *
40f58f68bSGerd Hoffmann  * Copyright Red Hat, Inc. 2012
50f58f68bSGerd Hoffmann  *
60f58f68bSGerd Hoffmann  * Author: Gerd Hoffmann <kraxel@redhat.com>
70f58f68bSGerd Hoffmann  *
80f58f68bSGerd Hoffmann  * This work is licensed under the terms of the GNU GPL, version 2 or later.
90f58f68bSGerd Hoffmann  * See the COPYING file in the top-level directory.
100f58f68bSGerd Hoffmann  */
110f58f68bSGerd Hoffmann 
120f58f68bSGerd Hoffmann #include "qemu-common.h"
131de7afc9SPaolo Bonzini #include "qemu/option.h"
141de7afc9SPaolo Bonzini #include "qemu/config-file.h"
150f58f68bSGerd Hoffmann #include "trace.h"
160f58f68bSGerd Hoffmann 
170f58f68bSGerd Hoffmann #include "hw/usb.h"
180f58f68bSGerd Hoffmann #include "hw/usb/desc.h"
190d09e41aSPaolo Bonzini #include "hw/scsi/scsi.h"
200d09e41aSPaolo Bonzini #include "block/scsi.h"
210f58f68bSGerd Hoffmann 
220f58f68bSGerd Hoffmann /* --------------------------------------------------------------------- */
230f58f68bSGerd Hoffmann 
240f58f68bSGerd Hoffmann #define UAS_UI_COMMAND              0x01
250f58f68bSGerd Hoffmann #define UAS_UI_SENSE                0x03
260f58f68bSGerd Hoffmann #define UAS_UI_RESPONSE             0x04
270f58f68bSGerd Hoffmann #define UAS_UI_TASK_MGMT            0x05
280f58f68bSGerd Hoffmann #define UAS_UI_READ_READY           0x06
290f58f68bSGerd Hoffmann #define UAS_UI_WRITE_READY          0x07
300f58f68bSGerd Hoffmann 
310f58f68bSGerd Hoffmann #define UAS_RC_TMF_COMPLETE         0x00
320f58f68bSGerd Hoffmann #define UAS_RC_INVALID_INFO_UNIT    0x02
330f58f68bSGerd Hoffmann #define UAS_RC_TMF_NOT_SUPPORTED    0x04
340f58f68bSGerd Hoffmann #define UAS_RC_TMF_FAILED           0x05
350f58f68bSGerd Hoffmann #define UAS_RC_TMF_SUCCEEDED        0x08
360f58f68bSGerd Hoffmann #define UAS_RC_INCORRECT_LUN        0x09
370f58f68bSGerd Hoffmann #define UAS_RC_OVERLAPPED_TAG       0x0a
380f58f68bSGerd Hoffmann 
390f58f68bSGerd Hoffmann #define UAS_TMF_ABORT_TASK          0x01
400f58f68bSGerd Hoffmann #define UAS_TMF_ABORT_TASK_SET      0x02
410f58f68bSGerd Hoffmann #define UAS_TMF_CLEAR_TASK_SET      0x04
420f58f68bSGerd Hoffmann #define UAS_TMF_LOGICAL_UNIT_RESET  0x08
430f58f68bSGerd Hoffmann #define UAS_TMF_I_T_NEXUS_RESET     0x10
440f58f68bSGerd Hoffmann #define UAS_TMF_CLEAR_ACA           0x40
450f58f68bSGerd Hoffmann #define UAS_TMF_QUERY_TASK          0x80
460f58f68bSGerd Hoffmann #define UAS_TMF_QUERY_TASK_SET      0x81
470f58f68bSGerd Hoffmann #define UAS_TMF_QUERY_ASYNC_EVENT   0x82
480f58f68bSGerd Hoffmann 
490f58f68bSGerd Hoffmann #define UAS_PIPE_ID_COMMAND         0x01
500f58f68bSGerd Hoffmann #define UAS_PIPE_ID_STATUS          0x02
510f58f68bSGerd Hoffmann #define UAS_PIPE_ID_DATA_IN         0x03
520f58f68bSGerd Hoffmann #define UAS_PIPE_ID_DATA_OUT        0x04
530f58f68bSGerd Hoffmann 
540f58f68bSGerd Hoffmann typedef struct {
550f58f68bSGerd Hoffmann     uint8_t    id;
560f58f68bSGerd Hoffmann     uint8_t    reserved;
570f58f68bSGerd Hoffmann     uint16_t   tag;
580f58f68bSGerd Hoffmann } QEMU_PACKED  uas_ui_header;
590f58f68bSGerd Hoffmann 
600f58f68bSGerd Hoffmann typedef struct {
610f58f68bSGerd Hoffmann     uint8_t    prio_taskattr;   /* 6:3 priority, 2:0 task attribute   */
620f58f68bSGerd Hoffmann     uint8_t    reserved_1;
630f58f68bSGerd Hoffmann     uint8_t    add_cdb_length;  /* 7:2 additional adb length (dwords) */
640f58f68bSGerd Hoffmann     uint8_t    reserved_2;
650f58f68bSGerd Hoffmann     uint64_t   lun;
660f58f68bSGerd Hoffmann     uint8_t    cdb[16];
670f58f68bSGerd Hoffmann     uint8_t    add_cdb[];
680f58f68bSGerd Hoffmann } QEMU_PACKED  uas_ui_command;
690f58f68bSGerd Hoffmann 
700f58f68bSGerd Hoffmann typedef struct {
710f58f68bSGerd Hoffmann     uint16_t   status_qualifier;
720f58f68bSGerd Hoffmann     uint8_t    status;
730f58f68bSGerd Hoffmann     uint8_t    reserved[7];
740f58f68bSGerd Hoffmann     uint16_t   sense_length;
750f58f68bSGerd Hoffmann     uint8_t    sense_data[18];
760f58f68bSGerd Hoffmann } QEMU_PACKED  uas_ui_sense;
770f58f68bSGerd Hoffmann 
780f58f68bSGerd Hoffmann typedef struct {
790f58f68bSGerd Hoffmann     uint16_t   add_response_info;
800f58f68bSGerd Hoffmann     uint8_t    response_code;
810f58f68bSGerd Hoffmann } QEMU_PACKED  uas_ui_response;
820f58f68bSGerd Hoffmann 
830f58f68bSGerd Hoffmann typedef struct {
840f58f68bSGerd Hoffmann     uint8_t    function;
850f58f68bSGerd Hoffmann     uint8_t    reserved;
860f58f68bSGerd Hoffmann     uint16_t   task_tag;
870f58f68bSGerd Hoffmann     uint64_t   lun;
880f58f68bSGerd Hoffmann } QEMU_PACKED  uas_ui_task_mgmt;
890f58f68bSGerd Hoffmann 
900f58f68bSGerd Hoffmann typedef struct {
910f58f68bSGerd Hoffmann     uas_ui_header  hdr;
920f58f68bSGerd Hoffmann     union {
930f58f68bSGerd Hoffmann         uas_ui_command   command;
940f58f68bSGerd Hoffmann         uas_ui_sense     sense;
950f58f68bSGerd Hoffmann         uas_ui_task_mgmt task;
960f58f68bSGerd Hoffmann         uas_ui_response  response;
970f58f68bSGerd Hoffmann     };
980f58f68bSGerd Hoffmann } QEMU_PACKED  uas_ui;
990f58f68bSGerd Hoffmann 
1000f58f68bSGerd Hoffmann /* --------------------------------------------------------------------- */
1010f58f68bSGerd Hoffmann 
10289a453d4SGerd Hoffmann #define UAS_STREAM_BM_ATTR  4
10389a453d4SGerd Hoffmann #define UAS_MAX_STREAMS     (1 << UAS_STREAM_BM_ATTR)
10489a453d4SGerd Hoffmann 
1050f58f68bSGerd Hoffmann typedef struct UASDevice UASDevice;
1060f58f68bSGerd Hoffmann typedef struct UASRequest UASRequest;
1070f58f68bSGerd Hoffmann typedef struct UASStatus UASStatus;
1080f58f68bSGerd Hoffmann 
1090f58f68bSGerd Hoffmann struct UASDevice {
1100f58f68bSGerd Hoffmann     USBDevice                 dev;
1110f58f68bSGerd Hoffmann     SCSIBus                   bus;
1120f58f68bSGerd Hoffmann     QEMUBH                    *status_bh;
1130f58f68bSGerd Hoffmann     QTAILQ_HEAD(, UASStatus)  results;
1140f58f68bSGerd Hoffmann     QTAILQ_HEAD(, UASRequest) requests;
11589a453d4SGerd Hoffmann 
1161556a8fcSGerd Hoffmann     /* properties */
1171556a8fcSGerd Hoffmann     uint32_t                  requestlog;
1181556a8fcSGerd Hoffmann 
11989a453d4SGerd Hoffmann     /* usb 2.0 only */
12089a453d4SGerd Hoffmann     USBPacket                 *status2;
12189a453d4SGerd Hoffmann     UASRequest                *datain2;
12289a453d4SGerd Hoffmann     UASRequest                *dataout2;
12389a453d4SGerd Hoffmann 
12489a453d4SGerd Hoffmann     /* usb 3.0 only */
1250478661eSHans de Goede     USBPacket                 *data3[UAS_MAX_STREAMS + 1];
1260478661eSHans de Goede     USBPacket                 *status3[UAS_MAX_STREAMS + 1];
1270f58f68bSGerd Hoffmann };
1280f58f68bSGerd Hoffmann 
1290f58f68bSGerd Hoffmann struct UASRequest {
1300f58f68bSGerd Hoffmann     uint16_t     tag;
1310f58f68bSGerd Hoffmann     uint64_t     lun;
1320f58f68bSGerd Hoffmann     UASDevice    *uas;
1330f58f68bSGerd Hoffmann     SCSIDevice   *dev;
1340f58f68bSGerd Hoffmann     SCSIRequest  *req;
1350f58f68bSGerd Hoffmann     USBPacket    *data;
1360f58f68bSGerd Hoffmann     bool         data_async;
1370f58f68bSGerd Hoffmann     bool         active;
1380f58f68bSGerd Hoffmann     bool         complete;
1390f58f68bSGerd Hoffmann     uint32_t     buf_off;
1400f58f68bSGerd Hoffmann     uint32_t     buf_size;
1410f58f68bSGerd Hoffmann     uint32_t     data_off;
1420f58f68bSGerd Hoffmann     uint32_t     data_size;
1430f58f68bSGerd Hoffmann     QTAILQ_ENTRY(UASRequest)  next;
1440f58f68bSGerd Hoffmann };
1450f58f68bSGerd Hoffmann 
1460f58f68bSGerd Hoffmann struct UASStatus {
14789a453d4SGerd Hoffmann     uint32_t                  stream;
1480f58f68bSGerd Hoffmann     uas_ui                    status;
1490f58f68bSGerd Hoffmann     uint32_t                  length;
1500f58f68bSGerd Hoffmann     QTAILQ_ENTRY(UASStatus)   next;
1510f58f68bSGerd Hoffmann };
1520f58f68bSGerd Hoffmann 
1530f58f68bSGerd Hoffmann /* --------------------------------------------------------------------- */
1540f58f68bSGerd Hoffmann 
1550f58f68bSGerd Hoffmann enum {
1560f58f68bSGerd Hoffmann     STR_MANUFACTURER = 1,
1570f58f68bSGerd Hoffmann     STR_PRODUCT,
1580f58f68bSGerd Hoffmann     STR_SERIALNUMBER,
1590f58f68bSGerd Hoffmann     STR_CONFIG_HIGH,
16089a453d4SGerd Hoffmann     STR_CONFIG_SUPER,
1610f58f68bSGerd Hoffmann };
1620f58f68bSGerd Hoffmann 
1630f58f68bSGerd Hoffmann static const USBDescStrings desc_strings = {
1640f58f68bSGerd Hoffmann     [STR_MANUFACTURER] = "QEMU",
1650f58f68bSGerd Hoffmann     [STR_PRODUCT]      = "USB Attached SCSI HBA",
1660f58f68bSGerd Hoffmann     [STR_SERIALNUMBER] = "27842",
1670f58f68bSGerd Hoffmann     [STR_CONFIG_HIGH]  = "High speed config (usb 2.0)",
16889a453d4SGerd Hoffmann     [STR_CONFIG_SUPER] = "Super speed config (usb 3.0)",
1690f58f68bSGerd Hoffmann };
1700f58f68bSGerd Hoffmann 
1710f58f68bSGerd Hoffmann static const USBDescIface desc_iface_high = {
1720f58f68bSGerd Hoffmann     .bInterfaceNumber              = 0,
1730f58f68bSGerd Hoffmann     .bNumEndpoints                 = 4,
1740f58f68bSGerd Hoffmann     .bInterfaceClass               = USB_CLASS_MASS_STORAGE,
1750f58f68bSGerd Hoffmann     .bInterfaceSubClass            = 0x06, /* SCSI */
1760f58f68bSGerd Hoffmann     .bInterfaceProtocol            = 0x62, /* UAS  */
1770f58f68bSGerd Hoffmann     .eps = (USBDescEndpoint[]) {
1780f58f68bSGerd Hoffmann         {
1790f58f68bSGerd Hoffmann             .bEndpointAddress      = USB_DIR_OUT | UAS_PIPE_ID_COMMAND,
1800f58f68bSGerd Hoffmann             .bmAttributes          = USB_ENDPOINT_XFER_BULK,
1810f58f68bSGerd Hoffmann             .wMaxPacketSize        = 512,
1820f58f68bSGerd Hoffmann             .extra = (uint8_t[]) {
1830f58f68bSGerd Hoffmann                 0x04,  /*  u8  bLength */
1840f58f68bSGerd Hoffmann                 0x24,  /*  u8  bDescriptorType */
1850f58f68bSGerd Hoffmann                 UAS_PIPE_ID_COMMAND,
1860f58f68bSGerd Hoffmann                 0x00,  /*  u8  bReserved */
1870f58f68bSGerd Hoffmann             },
1880f58f68bSGerd Hoffmann         },{
1890f58f68bSGerd Hoffmann             .bEndpointAddress      = USB_DIR_IN | UAS_PIPE_ID_STATUS,
1900f58f68bSGerd Hoffmann             .bmAttributes          = USB_ENDPOINT_XFER_BULK,
1910f58f68bSGerd Hoffmann             .wMaxPacketSize        = 512,
1920f58f68bSGerd Hoffmann             .extra = (uint8_t[]) {
1930f58f68bSGerd Hoffmann                 0x04,  /*  u8  bLength */
1940f58f68bSGerd Hoffmann                 0x24,  /*  u8  bDescriptorType */
1950f58f68bSGerd Hoffmann                 UAS_PIPE_ID_STATUS,
1960f58f68bSGerd Hoffmann                 0x00,  /*  u8  bReserved */
1970f58f68bSGerd Hoffmann             },
1980f58f68bSGerd Hoffmann         },{
1990f58f68bSGerd Hoffmann             .bEndpointAddress      = USB_DIR_IN | UAS_PIPE_ID_DATA_IN,
2000f58f68bSGerd Hoffmann             .bmAttributes          = USB_ENDPOINT_XFER_BULK,
2010f58f68bSGerd Hoffmann             .wMaxPacketSize        = 512,
2020f58f68bSGerd Hoffmann             .extra = (uint8_t[]) {
2030f58f68bSGerd Hoffmann                 0x04,  /*  u8  bLength */
2040f58f68bSGerd Hoffmann                 0x24,  /*  u8  bDescriptorType */
2050f58f68bSGerd Hoffmann                 UAS_PIPE_ID_DATA_IN,
2060f58f68bSGerd Hoffmann                 0x00,  /*  u8  bReserved */
2070f58f68bSGerd Hoffmann             },
2080f58f68bSGerd Hoffmann         },{
2090f58f68bSGerd Hoffmann             .bEndpointAddress      = USB_DIR_OUT | UAS_PIPE_ID_DATA_OUT,
2100f58f68bSGerd Hoffmann             .bmAttributes          = USB_ENDPOINT_XFER_BULK,
2110f58f68bSGerd Hoffmann             .wMaxPacketSize        = 512,
2120f58f68bSGerd Hoffmann             .extra = (uint8_t[]) {
2130f58f68bSGerd Hoffmann                 0x04,  /*  u8  bLength */
2140f58f68bSGerd Hoffmann                 0x24,  /*  u8  bDescriptorType */
2150f58f68bSGerd Hoffmann                 UAS_PIPE_ID_DATA_OUT,
2160f58f68bSGerd Hoffmann                 0x00,  /*  u8  bReserved */
2170f58f68bSGerd Hoffmann             },
2180f58f68bSGerd Hoffmann         },
2190f58f68bSGerd Hoffmann     }
2200f58f68bSGerd Hoffmann };
2210f58f68bSGerd Hoffmann 
22289a453d4SGerd Hoffmann static const USBDescIface desc_iface_super = {
22389a453d4SGerd Hoffmann     .bInterfaceNumber              = 0,
22489a453d4SGerd Hoffmann     .bNumEndpoints                 = 4,
22589a453d4SGerd Hoffmann     .bInterfaceClass               = USB_CLASS_MASS_STORAGE,
22689a453d4SGerd Hoffmann     .bInterfaceSubClass            = 0x06, /* SCSI */
22789a453d4SGerd Hoffmann     .bInterfaceProtocol            = 0x62, /* UAS  */
22889a453d4SGerd Hoffmann     .eps = (USBDescEndpoint[]) {
22989a453d4SGerd Hoffmann         {
23089a453d4SGerd Hoffmann             .bEndpointAddress      = USB_DIR_OUT | UAS_PIPE_ID_COMMAND,
23189a453d4SGerd Hoffmann             .bmAttributes          = USB_ENDPOINT_XFER_BULK,
23289a453d4SGerd Hoffmann             .wMaxPacketSize        = 1024,
23389a453d4SGerd Hoffmann             .bMaxBurst             = 15,
23489a453d4SGerd Hoffmann             .extra = (uint8_t[]) {
23589a453d4SGerd Hoffmann                 0x04,  /*  u8  bLength */
23689a453d4SGerd Hoffmann                 0x24,  /*  u8  bDescriptorType */
23789a453d4SGerd Hoffmann                 UAS_PIPE_ID_COMMAND,
23889a453d4SGerd Hoffmann                 0x00,  /*  u8  bReserved */
23989a453d4SGerd Hoffmann             },
24089a453d4SGerd Hoffmann         },{
24189a453d4SGerd Hoffmann             .bEndpointAddress      = USB_DIR_IN | UAS_PIPE_ID_STATUS,
24289a453d4SGerd Hoffmann             .bmAttributes          = USB_ENDPOINT_XFER_BULK,
24389a453d4SGerd Hoffmann             .wMaxPacketSize        = 1024,
24489a453d4SGerd Hoffmann             .bMaxBurst             = 15,
24589a453d4SGerd Hoffmann             .bmAttributes_super    = UAS_STREAM_BM_ATTR,
24689a453d4SGerd Hoffmann             .extra = (uint8_t[]) {
24789a453d4SGerd Hoffmann                 0x04,  /*  u8  bLength */
24889a453d4SGerd Hoffmann                 0x24,  /*  u8  bDescriptorType */
24989a453d4SGerd Hoffmann                 UAS_PIPE_ID_STATUS,
25089a453d4SGerd Hoffmann                 0x00,  /*  u8  bReserved */
25189a453d4SGerd Hoffmann             },
25289a453d4SGerd Hoffmann         },{
25389a453d4SGerd Hoffmann             .bEndpointAddress      = USB_DIR_IN | UAS_PIPE_ID_DATA_IN,
25489a453d4SGerd Hoffmann             .bmAttributes          = USB_ENDPOINT_XFER_BULK,
25589a453d4SGerd Hoffmann             .wMaxPacketSize        = 1024,
25689a453d4SGerd Hoffmann             .bMaxBurst             = 15,
25789a453d4SGerd Hoffmann             .bmAttributes_super    = UAS_STREAM_BM_ATTR,
25889a453d4SGerd Hoffmann             .extra = (uint8_t[]) {
25989a453d4SGerd Hoffmann                 0x04,  /*  u8  bLength */
26089a453d4SGerd Hoffmann                 0x24,  /*  u8  bDescriptorType */
26189a453d4SGerd Hoffmann                 UAS_PIPE_ID_DATA_IN,
26289a453d4SGerd Hoffmann                 0x00,  /*  u8  bReserved */
26389a453d4SGerd Hoffmann             },
26489a453d4SGerd Hoffmann         },{
26589a453d4SGerd Hoffmann             .bEndpointAddress      = USB_DIR_OUT | UAS_PIPE_ID_DATA_OUT,
26689a453d4SGerd Hoffmann             .bmAttributes          = USB_ENDPOINT_XFER_BULK,
26789a453d4SGerd Hoffmann             .wMaxPacketSize        = 1024,
26889a453d4SGerd Hoffmann             .bMaxBurst             = 15,
26989a453d4SGerd Hoffmann             .bmAttributes_super    = UAS_STREAM_BM_ATTR,
27089a453d4SGerd Hoffmann             .extra = (uint8_t[]) {
27189a453d4SGerd Hoffmann                 0x04,  /*  u8  bLength */
27289a453d4SGerd Hoffmann                 0x24,  /*  u8  bDescriptorType */
27389a453d4SGerd Hoffmann                 UAS_PIPE_ID_DATA_OUT,
27489a453d4SGerd Hoffmann                 0x00,  /*  u8  bReserved */
27589a453d4SGerd Hoffmann             },
27689a453d4SGerd Hoffmann         },
27789a453d4SGerd Hoffmann     }
27889a453d4SGerd Hoffmann };
27989a453d4SGerd Hoffmann 
2800f58f68bSGerd Hoffmann static const USBDescDevice desc_device_high = {
2810f58f68bSGerd Hoffmann     .bcdUSB                        = 0x0200,
2820f58f68bSGerd Hoffmann     .bMaxPacketSize0               = 64,
2830f58f68bSGerd Hoffmann     .bNumConfigurations            = 1,
2840f58f68bSGerd Hoffmann     .confs = (USBDescConfig[]) {
2850f58f68bSGerd Hoffmann         {
2860f58f68bSGerd Hoffmann             .bNumInterfaces        = 1,
2870f58f68bSGerd Hoffmann             .bConfigurationValue   = 1,
2880f58f68bSGerd Hoffmann             .iConfiguration        = STR_CONFIG_HIGH,
2890f58f68bSGerd Hoffmann             .bmAttributes          = 0xc0,
2900f58f68bSGerd Hoffmann             .nif = 1,
2910f58f68bSGerd Hoffmann             .ifs = &desc_iface_high,
2920f58f68bSGerd Hoffmann         },
2930f58f68bSGerd Hoffmann     },
2940f58f68bSGerd Hoffmann };
2950f58f68bSGerd Hoffmann 
29689a453d4SGerd Hoffmann static const USBDescDevice desc_device_super = {
29789a453d4SGerd Hoffmann     .bcdUSB                        = 0x0300,
29889a453d4SGerd Hoffmann     .bMaxPacketSize0               = 64,
29989a453d4SGerd Hoffmann     .bNumConfigurations            = 1,
30089a453d4SGerd Hoffmann     .confs = (USBDescConfig[]) {
30189a453d4SGerd Hoffmann         {
30289a453d4SGerd Hoffmann             .bNumInterfaces        = 1,
30389a453d4SGerd Hoffmann             .bConfigurationValue   = 1,
30489a453d4SGerd Hoffmann             .iConfiguration        = STR_CONFIG_SUPER,
30589a453d4SGerd Hoffmann             .bmAttributes          = 0xc0,
30689a453d4SGerd Hoffmann             .nif = 1,
30789a453d4SGerd Hoffmann             .ifs = &desc_iface_super,
30889a453d4SGerd Hoffmann         },
30989a453d4SGerd Hoffmann     },
31089a453d4SGerd Hoffmann };
31189a453d4SGerd Hoffmann 
3120f58f68bSGerd Hoffmann static const USBDesc desc = {
3130f58f68bSGerd Hoffmann     .id = {
3140f58f68bSGerd Hoffmann         .idVendor          = 0x46f4, /* CRC16() of "QEMU" */
3150daf5304SGerd Hoffmann         .idProduct         = 0x0003,
3160f58f68bSGerd Hoffmann         .bcdDevice         = 0,
3170f58f68bSGerd Hoffmann         .iManufacturer     = STR_MANUFACTURER,
3180f58f68bSGerd Hoffmann         .iProduct          = STR_PRODUCT,
3190f58f68bSGerd Hoffmann         .iSerialNumber     = STR_SERIALNUMBER,
3200f58f68bSGerd Hoffmann     },
3210f58f68bSGerd Hoffmann     .high  = &desc_device_high,
32289a453d4SGerd Hoffmann     .super = &desc_device_super,
3230f58f68bSGerd Hoffmann     .str   = desc_strings,
3240f58f68bSGerd Hoffmann };
3250f58f68bSGerd Hoffmann 
3260f58f68bSGerd Hoffmann /* --------------------------------------------------------------------- */
3270f58f68bSGerd Hoffmann 
32889a453d4SGerd Hoffmann static bool uas_using_streams(UASDevice *uas)
32989a453d4SGerd Hoffmann {
33089a453d4SGerd Hoffmann     return uas->dev.speed == USB_SPEED_SUPER;
33189a453d4SGerd Hoffmann }
33289a453d4SGerd Hoffmann 
33389a453d4SGerd Hoffmann /* --------------------------------------------------------------------- */
33489a453d4SGerd Hoffmann 
33589a453d4SGerd Hoffmann static UASStatus *usb_uas_alloc_status(UASDevice *uas, uint8_t id, uint16_t tag)
3360f58f68bSGerd Hoffmann {
3370f58f68bSGerd Hoffmann     UASStatus *st = g_new0(UASStatus, 1);
3380f58f68bSGerd Hoffmann 
3390f58f68bSGerd Hoffmann     st->status.hdr.id = id;
3400f58f68bSGerd Hoffmann     st->status.hdr.tag = cpu_to_be16(tag);
3410f58f68bSGerd Hoffmann     st->length = sizeof(uas_ui_header);
34289a453d4SGerd Hoffmann     if (uas_using_streams(uas)) {
34389a453d4SGerd Hoffmann         st->stream = tag;
34489a453d4SGerd Hoffmann     }
3450f58f68bSGerd Hoffmann     return st;
3460f58f68bSGerd Hoffmann }
3470f58f68bSGerd Hoffmann 
3480f58f68bSGerd Hoffmann static void usb_uas_send_status_bh(void *opaque)
3490f58f68bSGerd Hoffmann {
3500f58f68bSGerd Hoffmann     UASDevice *uas = opaque;
35189a453d4SGerd Hoffmann     UASStatus *st;
35289a453d4SGerd Hoffmann     USBPacket *p;
3530f58f68bSGerd Hoffmann 
35489a453d4SGerd Hoffmann     while ((st = QTAILQ_FIRST(&uas->results)) != NULL) {
35589a453d4SGerd Hoffmann         if (uas_using_streams(uas)) {
35689a453d4SGerd Hoffmann             p = uas->status3[st->stream];
35789a453d4SGerd Hoffmann             uas->status3[st->stream] = NULL;
35889a453d4SGerd Hoffmann         } else {
35989a453d4SGerd Hoffmann             p = uas->status2;
36089a453d4SGerd Hoffmann             uas->status2 = NULL;
36189a453d4SGerd Hoffmann         }
36289a453d4SGerd Hoffmann         if (p == NULL) {
36389a453d4SGerd Hoffmann             break;
36489a453d4SGerd Hoffmann         }
3650f58f68bSGerd Hoffmann 
3660f58f68bSGerd Hoffmann         usb_packet_copy(p, &st->status, st->length);
3670f58f68bSGerd Hoffmann         QTAILQ_REMOVE(&uas->results, st, next);
3680f58f68bSGerd Hoffmann         g_free(st);
3690f58f68bSGerd Hoffmann 
3709a77a0f5SHans de Goede         p->status = USB_RET_SUCCESS; /* Clear previous ASYNC status */
3710f58f68bSGerd Hoffmann         usb_packet_complete(&uas->dev, p);
3720f58f68bSGerd Hoffmann     }
37389a453d4SGerd Hoffmann }
3740f58f68bSGerd Hoffmann 
3750f58f68bSGerd Hoffmann static void usb_uas_queue_status(UASDevice *uas, UASStatus *st, int length)
3760f58f68bSGerd Hoffmann {
37789a453d4SGerd Hoffmann     USBPacket *p = uas_using_streams(uas) ?
37889a453d4SGerd Hoffmann         uas->status3[st->stream] : uas->status2;
37989a453d4SGerd Hoffmann 
3800f58f68bSGerd Hoffmann     st->length += length;
3810f58f68bSGerd Hoffmann     QTAILQ_INSERT_TAIL(&uas->results, st, next);
38289a453d4SGerd Hoffmann     if (p) {
3830f58f68bSGerd Hoffmann         /*
3840f58f68bSGerd Hoffmann          * Just schedule bh make sure any in-flight data transaction
3850f58f68bSGerd Hoffmann          * is finished before completing (sending) the status packet.
3860f58f68bSGerd Hoffmann          */
3870f58f68bSGerd Hoffmann         qemu_bh_schedule(uas->status_bh);
3880f58f68bSGerd Hoffmann     } else {
3890f58f68bSGerd Hoffmann         USBEndpoint *ep = usb_ep_get(&uas->dev, USB_TOKEN_IN,
3900f58f68bSGerd Hoffmann                                      UAS_PIPE_ID_STATUS);
39189a453d4SGerd Hoffmann         usb_wakeup(ep, st->stream);
3920f58f68bSGerd Hoffmann     }
3930f58f68bSGerd Hoffmann }
3940f58f68bSGerd Hoffmann 
3950f58f68bSGerd Hoffmann static void usb_uas_queue_response(UASDevice *uas, uint16_t tag,
3960f58f68bSGerd Hoffmann                                    uint8_t code, uint16_t add_info)
3970f58f68bSGerd Hoffmann {
39889a453d4SGerd Hoffmann     UASStatus *st = usb_uas_alloc_status(uas, UAS_UI_RESPONSE, tag);
3990f58f68bSGerd Hoffmann 
4000f58f68bSGerd Hoffmann     trace_usb_uas_response(uas->dev.addr, tag, code);
4010f58f68bSGerd Hoffmann     st->status.response.response_code = code;
4020f58f68bSGerd Hoffmann     st->status.response.add_response_info = cpu_to_be16(add_info);
4030f58f68bSGerd Hoffmann     usb_uas_queue_status(uas, st, sizeof(uas_ui_response));
4040f58f68bSGerd Hoffmann }
4050f58f68bSGerd Hoffmann 
4060f58f68bSGerd Hoffmann static void usb_uas_queue_sense(UASRequest *req, uint8_t status)
4070f58f68bSGerd Hoffmann {
40889a453d4SGerd Hoffmann     UASStatus *st = usb_uas_alloc_status(req->uas, UAS_UI_SENSE, req->tag);
4090f58f68bSGerd Hoffmann     int len, slen = 0;
4100f58f68bSGerd Hoffmann 
4110f58f68bSGerd Hoffmann     trace_usb_uas_sense(req->uas->dev.addr, req->tag, status);
4120f58f68bSGerd Hoffmann     st->status.sense.status = status;
4130f58f68bSGerd Hoffmann     st->status.sense.status_qualifier = cpu_to_be16(0);
4140f58f68bSGerd Hoffmann     if (status != GOOD) {
4150f58f68bSGerd Hoffmann         slen = scsi_req_get_sense(req->req, st->status.sense.sense_data,
4160f58f68bSGerd Hoffmann                                   sizeof(st->status.sense.sense_data));
4170f58f68bSGerd Hoffmann         st->status.sense.sense_length = cpu_to_be16(slen);
4180f58f68bSGerd Hoffmann     }
4190f58f68bSGerd Hoffmann     len = sizeof(uas_ui_sense) - sizeof(st->status.sense.sense_data) + slen;
4200f58f68bSGerd Hoffmann     usb_uas_queue_status(req->uas, st, len);
4210f58f68bSGerd Hoffmann }
4220f58f68bSGerd Hoffmann 
423d4bfc7b9SHans de Goede static void usb_uas_queue_fake_sense(UASDevice *uas, uint16_t tag,
424d4bfc7b9SHans de Goede                                      struct SCSISense sense)
425d4bfc7b9SHans de Goede {
426d4bfc7b9SHans de Goede     UASStatus *st = usb_uas_alloc_status(uas, UAS_UI_SENSE, tag);
427d4bfc7b9SHans de Goede     int len, slen = 0;
428d4bfc7b9SHans de Goede 
429d4bfc7b9SHans de Goede     st->status.sense.status = CHECK_CONDITION;
430d4bfc7b9SHans de Goede     st->status.sense.status_qualifier = cpu_to_be16(0);
431d4bfc7b9SHans de Goede     st->status.sense.sense_data[0] = 0x70;
432d4bfc7b9SHans de Goede     st->status.sense.sense_data[2] = sense.key;
433d4bfc7b9SHans de Goede     st->status.sense.sense_data[7] = 10;
434d4bfc7b9SHans de Goede     st->status.sense.sense_data[12] = sense.asc;
435d4bfc7b9SHans de Goede     st->status.sense.sense_data[13] = sense.ascq;
436d4bfc7b9SHans de Goede     slen = 18;
437d4bfc7b9SHans de Goede     len = sizeof(uas_ui_sense) - sizeof(st->status.sense.sense_data) + slen;
438d4bfc7b9SHans de Goede     usb_uas_queue_status(uas, st, len);
439d4bfc7b9SHans de Goede }
440d4bfc7b9SHans de Goede 
4410f58f68bSGerd Hoffmann static void usb_uas_queue_read_ready(UASRequest *req)
4420f58f68bSGerd Hoffmann {
44389a453d4SGerd Hoffmann     UASStatus *st = usb_uas_alloc_status(req->uas, UAS_UI_READ_READY,
44489a453d4SGerd Hoffmann                                          req->tag);
4450f58f68bSGerd Hoffmann 
4460f58f68bSGerd Hoffmann     trace_usb_uas_read_ready(req->uas->dev.addr, req->tag);
4470f58f68bSGerd Hoffmann     usb_uas_queue_status(req->uas, st, 0);
4480f58f68bSGerd Hoffmann }
4490f58f68bSGerd Hoffmann 
4500f58f68bSGerd Hoffmann static void usb_uas_queue_write_ready(UASRequest *req)
4510f58f68bSGerd Hoffmann {
45289a453d4SGerd Hoffmann     UASStatus *st = usb_uas_alloc_status(req->uas, UAS_UI_WRITE_READY,
45389a453d4SGerd Hoffmann                                          req->tag);
4540f58f68bSGerd Hoffmann 
4550f58f68bSGerd Hoffmann     trace_usb_uas_write_ready(req->uas->dev.addr, req->tag);
4560f58f68bSGerd Hoffmann     usb_uas_queue_status(req->uas, st, 0);
4570f58f68bSGerd Hoffmann }
4580f58f68bSGerd Hoffmann 
4590f58f68bSGerd Hoffmann /* --------------------------------------------------------------------- */
4600f58f68bSGerd Hoffmann 
4610f58f68bSGerd Hoffmann static int usb_uas_get_lun(uint64_t lun64)
4620f58f68bSGerd Hoffmann {
4630f58f68bSGerd Hoffmann     return (lun64 >> 48) & 0xff;
4640f58f68bSGerd Hoffmann }
4650f58f68bSGerd Hoffmann 
4660f58f68bSGerd Hoffmann static SCSIDevice *usb_uas_get_dev(UASDevice *uas, uint64_t lun64)
4670f58f68bSGerd Hoffmann {
4680f58f68bSGerd Hoffmann     if ((lun64 >> 56) != 0x00) {
4690f58f68bSGerd Hoffmann         return NULL;
4700f58f68bSGerd Hoffmann     }
4710f58f68bSGerd Hoffmann     return scsi_device_find(&uas->bus, 0, 0, usb_uas_get_lun(lun64));
4720f58f68bSGerd Hoffmann }
4730f58f68bSGerd Hoffmann 
4740f58f68bSGerd Hoffmann static void usb_uas_complete_data_packet(UASRequest *req)
4750f58f68bSGerd Hoffmann {
4760f58f68bSGerd Hoffmann     USBPacket *p;
4770f58f68bSGerd Hoffmann 
4780f58f68bSGerd Hoffmann     if (!req->data_async) {
4790f58f68bSGerd Hoffmann         return;
4800f58f68bSGerd Hoffmann     }
4810f58f68bSGerd Hoffmann     p = req->data;
4820f58f68bSGerd Hoffmann     req->data = NULL;
4830f58f68bSGerd Hoffmann     req->data_async = false;
4849a77a0f5SHans de Goede     p->status = USB_RET_SUCCESS; /* Clear previous ASYNC status */
4850f58f68bSGerd Hoffmann     usb_packet_complete(&req->uas->dev, p);
4860f58f68bSGerd Hoffmann }
4870f58f68bSGerd Hoffmann 
4880f58f68bSGerd Hoffmann static void usb_uas_copy_data(UASRequest *req)
4890f58f68bSGerd Hoffmann {
4900f58f68bSGerd Hoffmann     uint32_t length;
4910f58f68bSGerd Hoffmann 
4920f58f68bSGerd Hoffmann     length = MIN(req->buf_size - req->buf_off,
4939a77a0f5SHans de Goede                  req->data->iov.size - req->data->actual_length);
4940f58f68bSGerd Hoffmann     trace_usb_uas_xfer_data(req->uas->dev.addr, req->tag, length,
4959a77a0f5SHans de Goede                             req->data->actual_length, req->data->iov.size,
4960f58f68bSGerd Hoffmann                             req->buf_off, req->buf_size);
4970f58f68bSGerd Hoffmann     usb_packet_copy(req->data, scsi_req_get_buf(req->req) + req->buf_off,
4980f58f68bSGerd Hoffmann                     length);
4990f58f68bSGerd Hoffmann     req->buf_off += length;
5000f58f68bSGerd Hoffmann     req->data_off += length;
5010f58f68bSGerd Hoffmann 
5029a77a0f5SHans de Goede     if (req->data->actual_length == req->data->iov.size) {
5030f58f68bSGerd Hoffmann         usb_uas_complete_data_packet(req);
5040f58f68bSGerd Hoffmann     }
5050f58f68bSGerd Hoffmann     if (req->buf_size && req->buf_off == req->buf_size) {
5060f58f68bSGerd Hoffmann         req->buf_off = 0;
5070f58f68bSGerd Hoffmann         req->buf_size = 0;
5080f58f68bSGerd Hoffmann         scsi_req_continue(req->req);
5090f58f68bSGerd Hoffmann     }
5100f58f68bSGerd Hoffmann }
5110f58f68bSGerd Hoffmann 
5120f58f68bSGerd Hoffmann static void usb_uas_start_next_transfer(UASDevice *uas)
5130f58f68bSGerd Hoffmann {
5140f58f68bSGerd Hoffmann     UASRequest *req;
5150f58f68bSGerd Hoffmann 
51689a453d4SGerd Hoffmann     if (uas_using_streams(uas)) {
51789a453d4SGerd Hoffmann         return;
51889a453d4SGerd Hoffmann     }
51989a453d4SGerd Hoffmann 
5200f58f68bSGerd Hoffmann     QTAILQ_FOREACH(req, &uas->requests, next) {
5210f58f68bSGerd Hoffmann         if (req->active || req->complete) {
5220f58f68bSGerd Hoffmann             continue;
5230f58f68bSGerd Hoffmann         }
52489a453d4SGerd Hoffmann         if (req->req->cmd.mode == SCSI_XFER_FROM_DEV && uas->datain2 == NULL) {
52589a453d4SGerd Hoffmann             uas->datain2 = req;
5260f58f68bSGerd Hoffmann             usb_uas_queue_read_ready(req);
5270f58f68bSGerd Hoffmann             req->active = true;
5280f58f68bSGerd Hoffmann             return;
5290f58f68bSGerd Hoffmann         }
53089a453d4SGerd Hoffmann         if (req->req->cmd.mode == SCSI_XFER_TO_DEV && uas->dataout2 == NULL) {
53189a453d4SGerd Hoffmann             uas->dataout2 = req;
5320f58f68bSGerd Hoffmann             usb_uas_queue_write_ready(req);
5330f58f68bSGerd Hoffmann             req->active = true;
5340f58f68bSGerd Hoffmann             return;
5350f58f68bSGerd Hoffmann         }
5360f58f68bSGerd Hoffmann     }
5370f58f68bSGerd Hoffmann }
5380f58f68bSGerd Hoffmann 
5390f58f68bSGerd Hoffmann static UASRequest *usb_uas_alloc_request(UASDevice *uas, uas_ui *ui)
5400f58f68bSGerd Hoffmann {
5410f58f68bSGerd Hoffmann     UASRequest *req;
5420f58f68bSGerd Hoffmann 
5430f58f68bSGerd Hoffmann     req = g_new0(UASRequest, 1);
5440f58f68bSGerd Hoffmann     req->uas = uas;
5450f58f68bSGerd Hoffmann     req->tag = be16_to_cpu(ui->hdr.tag);
5460f58f68bSGerd Hoffmann     req->lun = be64_to_cpu(ui->command.lun);
5470f58f68bSGerd Hoffmann     req->dev = usb_uas_get_dev(req->uas, req->lun);
5480f58f68bSGerd Hoffmann     return req;
5490f58f68bSGerd Hoffmann }
5500f58f68bSGerd Hoffmann 
5510f58f68bSGerd Hoffmann static void usb_uas_scsi_free_request(SCSIBus *bus, void *priv)
5520f58f68bSGerd Hoffmann {
5530f58f68bSGerd Hoffmann     UASRequest *req = priv;
5540f58f68bSGerd Hoffmann     UASDevice *uas = req->uas;
5550f58f68bSGerd Hoffmann 
55689a453d4SGerd Hoffmann     if (req == uas->datain2) {
55789a453d4SGerd Hoffmann         uas->datain2 = NULL;
5580f58f68bSGerd Hoffmann     }
55989a453d4SGerd Hoffmann     if (req == uas->dataout2) {
56089a453d4SGerd Hoffmann         uas->dataout2 = NULL;
5610f58f68bSGerd Hoffmann     }
5620f58f68bSGerd Hoffmann     QTAILQ_REMOVE(&uas->requests, req, next);
5630f58f68bSGerd Hoffmann     g_free(req);
564347e40ffSGerd Hoffmann     usb_uas_start_next_transfer(uas);
5650f58f68bSGerd Hoffmann }
5660f58f68bSGerd Hoffmann 
5670f58f68bSGerd Hoffmann static UASRequest *usb_uas_find_request(UASDevice *uas, uint16_t tag)
5680f58f68bSGerd Hoffmann {
5690f58f68bSGerd Hoffmann     UASRequest *req;
5700f58f68bSGerd Hoffmann 
5710f58f68bSGerd Hoffmann     QTAILQ_FOREACH(req, &uas->requests, next) {
5720f58f68bSGerd Hoffmann         if (req->tag == tag) {
5730f58f68bSGerd Hoffmann             return req;
5740f58f68bSGerd Hoffmann         }
5750f58f68bSGerd Hoffmann     }
5760f58f68bSGerd Hoffmann     return NULL;
5770f58f68bSGerd Hoffmann }
5780f58f68bSGerd Hoffmann 
5790f58f68bSGerd Hoffmann static void usb_uas_scsi_transfer_data(SCSIRequest *r, uint32_t len)
5800f58f68bSGerd Hoffmann {
5810f58f68bSGerd Hoffmann     UASRequest *req = r->hba_private;
5820f58f68bSGerd Hoffmann 
5830f58f68bSGerd Hoffmann     trace_usb_uas_scsi_data(req->uas->dev.addr, req->tag, len);
5840f58f68bSGerd Hoffmann     req->buf_off = 0;
5850f58f68bSGerd Hoffmann     req->buf_size = len;
5860f58f68bSGerd Hoffmann     if (req->data) {
5870f58f68bSGerd Hoffmann         usb_uas_copy_data(req);
5880f58f68bSGerd Hoffmann     } else {
5890f58f68bSGerd Hoffmann         usb_uas_start_next_transfer(req->uas);
5900f58f68bSGerd Hoffmann     }
5910f58f68bSGerd Hoffmann }
5920f58f68bSGerd Hoffmann 
5930f58f68bSGerd Hoffmann static void usb_uas_scsi_command_complete(SCSIRequest *r,
5940f58f68bSGerd Hoffmann                                           uint32_t status, size_t resid)
5950f58f68bSGerd Hoffmann {
5960f58f68bSGerd Hoffmann     UASRequest *req = r->hba_private;
5970f58f68bSGerd Hoffmann 
5980f58f68bSGerd Hoffmann     trace_usb_uas_scsi_complete(req->uas->dev.addr, req->tag, status, resid);
5990f58f68bSGerd Hoffmann     req->complete = true;
6000f58f68bSGerd Hoffmann     if (req->data) {
6010f58f68bSGerd Hoffmann         usb_uas_complete_data_packet(req);
6020f58f68bSGerd Hoffmann     }
6030f58f68bSGerd Hoffmann     usb_uas_queue_sense(req, status);
6040f58f68bSGerd Hoffmann     scsi_req_unref(req->req);
6050f58f68bSGerd Hoffmann }
6060f58f68bSGerd Hoffmann 
6070f58f68bSGerd Hoffmann static void usb_uas_scsi_request_cancelled(SCSIRequest *r)
6080f58f68bSGerd Hoffmann {
6090f58f68bSGerd Hoffmann     UASRequest *req = r->hba_private;
6100f58f68bSGerd Hoffmann 
6110f58f68bSGerd Hoffmann     /* FIXME: queue notification to status pipe? */
6120f58f68bSGerd Hoffmann     scsi_req_unref(req->req);
6130f58f68bSGerd Hoffmann }
6140f58f68bSGerd Hoffmann 
6150f58f68bSGerd Hoffmann static const struct SCSIBusInfo usb_uas_scsi_info = {
6160f58f68bSGerd Hoffmann     .tcq = true,
6170f58f68bSGerd Hoffmann     .max_target = 0,
6180f58f68bSGerd Hoffmann     .max_lun = 255,
6190f58f68bSGerd Hoffmann 
6200f58f68bSGerd Hoffmann     .transfer_data = usb_uas_scsi_transfer_data,
6210f58f68bSGerd Hoffmann     .complete = usb_uas_scsi_command_complete,
6220f58f68bSGerd Hoffmann     .cancel = usb_uas_scsi_request_cancelled,
6230f58f68bSGerd Hoffmann     .free_request = usb_uas_scsi_free_request,
6240f58f68bSGerd Hoffmann };
6250f58f68bSGerd Hoffmann 
6260f58f68bSGerd Hoffmann /* --------------------------------------------------------------------- */
6270f58f68bSGerd Hoffmann 
6280f58f68bSGerd Hoffmann static void usb_uas_handle_reset(USBDevice *dev)
6290f58f68bSGerd Hoffmann {
6300f58f68bSGerd Hoffmann     UASDevice *uas = DO_UPCAST(UASDevice, dev, dev);
6310f58f68bSGerd Hoffmann     UASRequest *req, *nreq;
6320f58f68bSGerd Hoffmann     UASStatus *st, *nst;
6330f58f68bSGerd Hoffmann 
6340f58f68bSGerd Hoffmann     trace_usb_uas_reset(dev->addr);
6350f58f68bSGerd Hoffmann     QTAILQ_FOREACH_SAFE(req, &uas->requests, next, nreq) {
6360f58f68bSGerd Hoffmann         scsi_req_cancel(req->req);
6370f58f68bSGerd Hoffmann     }
6380f58f68bSGerd Hoffmann     QTAILQ_FOREACH_SAFE(st, &uas->results, next, nst) {
6390f58f68bSGerd Hoffmann         QTAILQ_REMOVE(&uas->results, st, next);
6400f58f68bSGerd Hoffmann         g_free(st);
6410f58f68bSGerd Hoffmann     }
6420f58f68bSGerd Hoffmann }
6430f58f68bSGerd Hoffmann 
6449a77a0f5SHans de Goede static void usb_uas_handle_control(USBDevice *dev, USBPacket *p,
6450f58f68bSGerd Hoffmann                int request, int value, int index, int length, uint8_t *data)
6460f58f68bSGerd Hoffmann {
6470f58f68bSGerd Hoffmann     int ret;
6480f58f68bSGerd Hoffmann 
6490f58f68bSGerd Hoffmann     ret = usb_desc_handle_control(dev, p, request, value, index, length, data);
6500f58f68bSGerd Hoffmann     if (ret >= 0) {
6519a77a0f5SHans de Goede         return;
6520f58f68bSGerd Hoffmann     }
6530f58f68bSGerd Hoffmann     fprintf(stderr, "%s: unhandled control request\n", __func__);
6549a77a0f5SHans de Goede     p->status = USB_RET_STALL;
6550f58f68bSGerd Hoffmann }
6560f58f68bSGerd Hoffmann 
6570f58f68bSGerd Hoffmann static void usb_uas_cancel_io(USBDevice *dev, USBPacket *p)
6580f58f68bSGerd Hoffmann {
6590f58f68bSGerd Hoffmann     UASDevice *uas = DO_UPCAST(UASDevice, dev, dev);
6600f58f68bSGerd Hoffmann     UASRequest *req, *nreq;
66189a453d4SGerd Hoffmann     int i;
6620f58f68bSGerd Hoffmann 
66389a453d4SGerd Hoffmann     if (uas->status2 == p) {
66489a453d4SGerd Hoffmann         uas->status2 = NULL;
6650f58f68bSGerd Hoffmann         qemu_bh_cancel(uas->status_bh);
6660f58f68bSGerd Hoffmann         return;
6670f58f68bSGerd Hoffmann     }
66889a453d4SGerd Hoffmann     if (uas_using_streams(uas)) {
6690478661eSHans de Goede         for (i = 0; i <= UAS_MAX_STREAMS; i++) {
67089a453d4SGerd Hoffmann             if (uas->status3[i] == p) {
67189a453d4SGerd Hoffmann                 uas->status3[i] = NULL;
67289a453d4SGerd Hoffmann                 return;
67389a453d4SGerd Hoffmann             }
67489a453d4SGerd Hoffmann             if (uas->data3[i] == p) {
67589a453d4SGerd Hoffmann                 uas->data3[i] = NULL;
67689a453d4SGerd Hoffmann                 return;
67789a453d4SGerd Hoffmann             }
67889a453d4SGerd Hoffmann         }
67989a453d4SGerd Hoffmann     }
6800f58f68bSGerd Hoffmann     QTAILQ_FOREACH_SAFE(req, &uas->requests, next, nreq) {
6810f58f68bSGerd Hoffmann         if (req->data == p) {
6820f58f68bSGerd Hoffmann             req->data = NULL;
6830f58f68bSGerd Hoffmann             return;
6840f58f68bSGerd Hoffmann         }
6850f58f68bSGerd Hoffmann     }
6860f58f68bSGerd Hoffmann     assert(!"canceled usb packet not found");
6870f58f68bSGerd Hoffmann }
6880f58f68bSGerd Hoffmann 
6890f58f68bSGerd Hoffmann static void usb_uas_command(UASDevice *uas, uas_ui *ui)
6900f58f68bSGerd Hoffmann {
6910f58f68bSGerd Hoffmann     UASRequest *req;
6920f58f68bSGerd Hoffmann     uint32_t len;
693d4bfc7b9SHans de Goede     uint16_t tag = be16_to_cpu(ui->hdr.tag);
6940f58f68bSGerd Hoffmann 
695*3453f9a0SHans de Goede     if (uas_using_streams(uas) && tag > UAS_MAX_STREAMS) {
696*3453f9a0SHans de Goede         goto invalid_tag;
697*3453f9a0SHans de Goede     }
698d4bfc7b9SHans de Goede     req = usb_uas_find_request(uas, tag);
6990f58f68bSGerd Hoffmann     if (req) {
7000f58f68bSGerd Hoffmann         goto overlapped_tag;
7010f58f68bSGerd Hoffmann     }
7020f58f68bSGerd Hoffmann     req = usb_uas_alloc_request(uas, ui);
7030f58f68bSGerd Hoffmann     if (req->dev == NULL) {
7040f58f68bSGerd Hoffmann         goto bad_target;
7050f58f68bSGerd Hoffmann     }
7060f58f68bSGerd Hoffmann 
7070f58f68bSGerd Hoffmann     trace_usb_uas_command(uas->dev.addr, req->tag,
7080f58f68bSGerd Hoffmann                           usb_uas_get_lun(req->lun),
7090f58f68bSGerd Hoffmann                           req->lun >> 32, req->lun & 0xffffffff);
7100f58f68bSGerd Hoffmann     QTAILQ_INSERT_TAIL(&uas->requests, req, next);
71189a453d4SGerd Hoffmann     if (uas_using_streams(uas) && uas->data3[req->tag] != NULL) {
71289a453d4SGerd Hoffmann         req->data = uas->data3[req->tag];
71389a453d4SGerd Hoffmann         req->data_async = true;
71489a453d4SGerd Hoffmann         uas->data3[req->tag] = NULL;
71589a453d4SGerd Hoffmann     }
71689a453d4SGerd Hoffmann 
7170f58f68bSGerd Hoffmann     req->req = scsi_req_new(req->dev, req->tag,
7180f58f68bSGerd Hoffmann                             usb_uas_get_lun(req->lun),
7190f58f68bSGerd Hoffmann                             ui->command.cdb, req);
7201556a8fcSGerd Hoffmann     if (uas->requestlog) {
72189a453d4SGerd Hoffmann         scsi_req_print(req->req);
7221556a8fcSGerd Hoffmann     }
7230f58f68bSGerd Hoffmann     len = scsi_req_enqueue(req->req);
7240f58f68bSGerd Hoffmann     if (len) {
7250f58f68bSGerd Hoffmann         req->data_size = len;
7260f58f68bSGerd Hoffmann         scsi_req_continue(req->req);
7270f58f68bSGerd Hoffmann     }
7280f58f68bSGerd Hoffmann     return;
7290f58f68bSGerd Hoffmann 
730*3453f9a0SHans de Goede invalid_tag:
731*3453f9a0SHans de Goede     usb_uas_queue_fake_sense(uas, tag, sense_code_INVALID_TAG);
732*3453f9a0SHans de Goede     return;
733*3453f9a0SHans de Goede 
7340f58f68bSGerd Hoffmann overlapped_tag:
735d4bfc7b9SHans de Goede     usb_uas_queue_fake_sense(uas, tag, sense_code_OVERLAPPED_COMMANDS);
7360f58f68bSGerd Hoffmann     return;
7370f58f68bSGerd Hoffmann 
7380f58f68bSGerd Hoffmann bad_target:
739d4bfc7b9SHans de Goede     usb_uas_queue_fake_sense(uas, tag, sense_code_LUN_NOT_SUPPORTED);
7400f58f68bSGerd Hoffmann     g_free(req);
7410f58f68bSGerd Hoffmann }
7420f58f68bSGerd Hoffmann 
7430f58f68bSGerd Hoffmann static void usb_uas_task(UASDevice *uas, uas_ui *ui)
7440f58f68bSGerd Hoffmann {
7450f58f68bSGerd Hoffmann     uint16_t tag = be16_to_cpu(ui->hdr.tag);
7460f58f68bSGerd Hoffmann     uint64_t lun64 = be64_to_cpu(ui->task.lun);
7470f58f68bSGerd Hoffmann     SCSIDevice *dev = usb_uas_get_dev(uas, lun64);
7480f58f68bSGerd Hoffmann     int lun = usb_uas_get_lun(lun64);
7490f58f68bSGerd Hoffmann     UASRequest *req;
7500f58f68bSGerd Hoffmann     uint16_t task_tag;
7510f58f68bSGerd Hoffmann 
752*3453f9a0SHans de Goede     if (uas_using_streams(uas) && tag > UAS_MAX_STREAMS) {
753*3453f9a0SHans de Goede         goto invalid_tag;
754*3453f9a0SHans de Goede     }
7550f58f68bSGerd Hoffmann     req = usb_uas_find_request(uas, be16_to_cpu(ui->hdr.tag));
7560f58f68bSGerd Hoffmann     if (req) {
7570f58f68bSGerd Hoffmann         goto overlapped_tag;
7580f58f68bSGerd Hoffmann     }
7595eb6d9e3SHans de Goede     if (dev == NULL) {
7605eb6d9e3SHans de Goede         goto incorrect_lun;
7615eb6d9e3SHans de Goede     }
7620f58f68bSGerd Hoffmann 
7630f58f68bSGerd Hoffmann     switch (ui->task.function) {
7640f58f68bSGerd Hoffmann     case UAS_TMF_ABORT_TASK:
7650f58f68bSGerd Hoffmann         task_tag = be16_to_cpu(ui->task.task_tag);
7660f58f68bSGerd Hoffmann         trace_usb_uas_tmf_abort_task(uas->dev.addr, tag, task_tag);
7670f58f68bSGerd Hoffmann         req = usb_uas_find_request(uas, task_tag);
7680f58f68bSGerd Hoffmann         if (req && req->dev == dev) {
7690f58f68bSGerd Hoffmann             scsi_req_cancel(req->req);
7700f58f68bSGerd Hoffmann         }
7710f58f68bSGerd Hoffmann         usb_uas_queue_response(uas, tag, UAS_RC_TMF_COMPLETE, 0);
7720f58f68bSGerd Hoffmann         break;
7730f58f68bSGerd Hoffmann 
7740f58f68bSGerd Hoffmann     case UAS_TMF_LOGICAL_UNIT_RESET:
7750f58f68bSGerd Hoffmann         trace_usb_uas_tmf_logical_unit_reset(uas->dev.addr, tag, lun);
7760f58f68bSGerd Hoffmann         qdev_reset_all(&dev->qdev);
7770f58f68bSGerd Hoffmann         usb_uas_queue_response(uas, tag, UAS_RC_TMF_COMPLETE, 0);
7780f58f68bSGerd Hoffmann         break;
7790f58f68bSGerd Hoffmann 
7800f58f68bSGerd Hoffmann     default:
7810f58f68bSGerd Hoffmann         trace_usb_uas_tmf_unsupported(uas->dev.addr, tag, ui->task.function);
7820f58f68bSGerd Hoffmann         usb_uas_queue_response(uas, tag, UAS_RC_TMF_NOT_SUPPORTED, 0);
7830f58f68bSGerd Hoffmann         break;
7840f58f68bSGerd Hoffmann     }
7850f58f68bSGerd Hoffmann     return;
7860f58f68bSGerd Hoffmann 
787*3453f9a0SHans de Goede invalid_tag:
788*3453f9a0SHans de Goede     usb_uas_queue_response(uas, tag, UAS_RC_INVALID_INFO_UNIT, 0);
789*3453f9a0SHans de Goede     return;
790*3453f9a0SHans de Goede 
7910f58f68bSGerd Hoffmann overlapped_tag:
7920f58f68bSGerd Hoffmann     usb_uas_queue_response(uas, req->tag, UAS_RC_OVERLAPPED_TAG, 0);
7930f58f68bSGerd Hoffmann     return;
7940f58f68bSGerd Hoffmann 
7950f58f68bSGerd Hoffmann incorrect_lun:
7960f58f68bSGerd Hoffmann     usb_uas_queue_response(uas, tag, UAS_RC_INCORRECT_LUN, 0);
7970f58f68bSGerd Hoffmann }
7980f58f68bSGerd Hoffmann 
7999a77a0f5SHans de Goede static void usb_uas_handle_data(USBDevice *dev, USBPacket *p)
8000f58f68bSGerd Hoffmann {
8010f58f68bSGerd Hoffmann     UASDevice *uas = DO_UPCAST(UASDevice, dev, dev);
8020f58f68bSGerd Hoffmann     uas_ui ui;
8030f58f68bSGerd Hoffmann     UASStatus *st;
8040f58f68bSGerd Hoffmann     UASRequest *req;
8059a77a0f5SHans de Goede     int length;
8060f58f68bSGerd Hoffmann 
8070f58f68bSGerd Hoffmann     switch (p->ep->nr) {
8080f58f68bSGerd Hoffmann     case UAS_PIPE_ID_COMMAND:
8090f58f68bSGerd Hoffmann         length = MIN(sizeof(ui), p->iov.size);
8100f58f68bSGerd Hoffmann         usb_packet_copy(p, &ui, length);
8110f58f68bSGerd Hoffmann         switch (ui.hdr.id) {
8120f58f68bSGerd Hoffmann         case UAS_UI_COMMAND:
8130f58f68bSGerd Hoffmann             usb_uas_command(uas, &ui);
8140f58f68bSGerd Hoffmann             break;
8150f58f68bSGerd Hoffmann         case UAS_UI_TASK_MGMT:
8160f58f68bSGerd Hoffmann             usb_uas_task(uas, &ui);
8170f58f68bSGerd Hoffmann             break;
8180f58f68bSGerd Hoffmann         default:
8190f58f68bSGerd Hoffmann             fprintf(stderr, "%s: unknown command ui: id 0x%x\n",
8200f58f68bSGerd Hoffmann                     __func__, ui.hdr.id);
8219a77a0f5SHans de Goede             p->status = USB_RET_STALL;
8220f58f68bSGerd Hoffmann             break;
8230f58f68bSGerd Hoffmann         }
8240f58f68bSGerd Hoffmann         break;
8250f58f68bSGerd Hoffmann     case UAS_PIPE_ID_STATUS:
82689a453d4SGerd Hoffmann         if (p->stream) {
82789a453d4SGerd Hoffmann             QTAILQ_FOREACH(st, &uas->results, next) {
82889a453d4SGerd Hoffmann                 if (st->stream == p->stream) {
82989a453d4SGerd Hoffmann                     break;
83089a453d4SGerd Hoffmann                 }
83189a453d4SGerd Hoffmann             }
8320f58f68bSGerd Hoffmann             if (st == NULL) {
83389a453d4SGerd Hoffmann                 assert(uas->status3[p->stream] == NULL);
83489a453d4SGerd Hoffmann                 uas->status3[p->stream] = p;
8359a77a0f5SHans de Goede                 p->status = USB_RET_ASYNC;
8360f58f68bSGerd Hoffmann                 break;
8370f58f68bSGerd Hoffmann             }
83889a453d4SGerd Hoffmann         } else {
83989a453d4SGerd Hoffmann             st = QTAILQ_FIRST(&uas->results);
84089a453d4SGerd Hoffmann             if (st == NULL) {
84189a453d4SGerd Hoffmann                 assert(uas->status2 == NULL);
84289a453d4SGerd Hoffmann                 uas->status2 = p;
84389a453d4SGerd Hoffmann                 p->status = USB_RET_ASYNC;
84489a453d4SGerd Hoffmann                 break;
84589a453d4SGerd Hoffmann             }
84689a453d4SGerd Hoffmann         }
8470f58f68bSGerd Hoffmann         usb_packet_copy(p, &st->status, st->length);
8480f58f68bSGerd Hoffmann         QTAILQ_REMOVE(&uas->results, st, next);
8490f58f68bSGerd Hoffmann         g_free(st);
8500f58f68bSGerd Hoffmann         break;
8510f58f68bSGerd Hoffmann     case UAS_PIPE_ID_DATA_IN:
8520f58f68bSGerd Hoffmann     case UAS_PIPE_ID_DATA_OUT:
85389a453d4SGerd Hoffmann         if (p->stream) {
85489a453d4SGerd Hoffmann             req = usb_uas_find_request(uas, p->stream);
85589a453d4SGerd Hoffmann         } else {
85689a453d4SGerd Hoffmann             req = (p->ep->nr == UAS_PIPE_ID_DATA_IN)
85789a453d4SGerd Hoffmann                 ? uas->datain2 : uas->dataout2;
85889a453d4SGerd Hoffmann         }
8590f58f68bSGerd Hoffmann         if (req == NULL) {
86089a453d4SGerd Hoffmann             if (p->stream) {
86189a453d4SGerd Hoffmann                 assert(uas->data3[p->stream] == NULL);
86289a453d4SGerd Hoffmann                 uas->data3[p->stream] = p;
86389a453d4SGerd Hoffmann                 p->status = USB_RET_ASYNC;
86489a453d4SGerd Hoffmann                 break;
86589a453d4SGerd Hoffmann             } else {
8660f58f68bSGerd Hoffmann                 fprintf(stderr, "%s: no inflight request\n", __func__);
8679a77a0f5SHans de Goede                 p->status = USB_RET_STALL;
8680f58f68bSGerd Hoffmann                 break;
8690f58f68bSGerd Hoffmann             }
87089a453d4SGerd Hoffmann         }
8710f58f68bSGerd Hoffmann         scsi_req_ref(req->req);
8720f58f68bSGerd Hoffmann         req->data = p;
8730f58f68bSGerd Hoffmann         usb_uas_copy_data(req);
8749a77a0f5SHans de Goede         if (p->actual_length == p->iov.size || req->complete) {
8750f58f68bSGerd Hoffmann             req->data = NULL;
8760f58f68bSGerd Hoffmann         } else {
8770f58f68bSGerd Hoffmann             req->data_async = true;
8789a77a0f5SHans de Goede             p->status = USB_RET_ASYNC;
8790f58f68bSGerd Hoffmann         }
8800f58f68bSGerd Hoffmann         scsi_req_unref(req->req);
8810f58f68bSGerd Hoffmann         usb_uas_start_next_transfer(uas);
8820f58f68bSGerd Hoffmann         break;
8830f58f68bSGerd Hoffmann     default:
8840f58f68bSGerd Hoffmann         fprintf(stderr, "%s: invalid endpoint %d\n", __func__, p->ep->nr);
8859a77a0f5SHans de Goede         p->status = USB_RET_STALL;
8860f58f68bSGerd Hoffmann         break;
8870f58f68bSGerd Hoffmann     }
8880f58f68bSGerd Hoffmann }
8890f58f68bSGerd Hoffmann 
8900f58f68bSGerd Hoffmann static void usb_uas_handle_destroy(USBDevice *dev)
8910f58f68bSGerd Hoffmann {
8920f58f68bSGerd Hoffmann     UASDevice *uas = DO_UPCAST(UASDevice, dev, dev);
8930f58f68bSGerd Hoffmann 
8940f58f68bSGerd Hoffmann     qemu_bh_delete(uas->status_bh);
8950f58f68bSGerd Hoffmann }
8960f58f68bSGerd Hoffmann 
8970f58f68bSGerd Hoffmann static int usb_uas_init(USBDevice *dev)
8980f58f68bSGerd Hoffmann {
8990f58f68bSGerd Hoffmann     UASDevice *uas = DO_UPCAST(UASDevice, dev, dev);
9000f58f68bSGerd Hoffmann 
9010f58f68bSGerd Hoffmann     usb_desc_create_serial(dev);
9020f58f68bSGerd Hoffmann     usb_desc_init(dev);
9030f58f68bSGerd Hoffmann 
9040f58f68bSGerd Hoffmann     QTAILQ_INIT(&uas->results);
9050f58f68bSGerd Hoffmann     QTAILQ_INIT(&uas->requests);
9060f58f68bSGerd Hoffmann     uas->status_bh = qemu_bh_new(usb_uas_send_status_bh, uas);
9070f58f68bSGerd Hoffmann 
908b1187b51SAndreas Färber     scsi_bus_new(&uas->bus, sizeof(uas->bus), DEVICE(dev),
909b1187b51SAndreas Färber                  &usb_uas_scsi_info, NULL);
9100f58f68bSGerd Hoffmann 
9110f58f68bSGerd Hoffmann     return 0;
9120f58f68bSGerd Hoffmann }
9130f58f68bSGerd Hoffmann 
9140f58f68bSGerd Hoffmann static const VMStateDescription vmstate_usb_uas = {
9150f58f68bSGerd Hoffmann     .name = "usb-uas",
9160f58f68bSGerd Hoffmann     .unmigratable = 1,
9170f58f68bSGerd Hoffmann     .fields = (VMStateField[]) {
9180f58f68bSGerd Hoffmann         VMSTATE_USB_DEVICE(dev, UASDevice),
9190f58f68bSGerd Hoffmann         VMSTATE_END_OF_LIST()
9200f58f68bSGerd Hoffmann     }
9210f58f68bSGerd Hoffmann };
9220f58f68bSGerd Hoffmann 
9231556a8fcSGerd Hoffmann static Property uas_properties[] = {
9241556a8fcSGerd Hoffmann     DEFINE_PROP_UINT32("log-scsi-req", UASDevice, requestlog, 0),
9251556a8fcSGerd Hoffmann     DEFINE_PROP_END_OF_LIST(),
9261556a8fcSGerd Hoffmann };
9271556a8fcSGerd Hoffmann 
9280f58f68bSGerd Hoffmann static void usb_uas_class_initfn(ObjectClass *klass, void *data)
9290f58f68bSGerd Hoffmann {
9300f58f68bSGerd Hoffmann     DeviceClass *dc = DEVICE_CLASS(klass);
9310f58f68bSGerd Hoffmann     USBDeviceClass *uc = USB_DEVICE_CLASS(klass);
9320f58f68bSGerd Hoffmann 
9330f58f68bSGerd Hoffmann     uc->init           = usb_uas_init;
9340f58f68bSGerd Hoffmann     uc->product_desc   = desc_strings[STR_PRODUCT];
9350f58f68bSGerd Hoffmann     uc->usb_desc       = &desc;
9360f58f68bSGerd Hoffmann     uc->cancel_packet  = usb_uas_cancel_io;
9370f58f68bSGerd Hoffmann     uc->handle_attach  = usb_desc_attach;
9380f58f68bSGerd Hoffmann     uc->handle_reset   = usb_uas_handle_reset;
9390f58f68bSGerd Hoffmann     uc->handle_control = usb_uas_handle_control;
9400f58f68bSGerd Hoffmann     uc->handle_data    = usb_uas_handle_data;
9410f58f68bSGerd Hoffmann     uc->handle_destroy = usb_uas_handle_destroy;
942125ee0edSMarcel Apfelbaum     set_bit(DEVICE_CATEGORY_STORAGE, dc->categories);
9430f58f68bSGerd Hoffmann     dc->fw_name = "storage";
9440f58f68bSGerd Hoffmann     dc->vmsd = &vmstate_usb_uas;
9451556a8fcSGerd Hoffmann     dc->props = uas_properties;
9460f58f68bSGerd Hoffmann }
9470f58f68bSGerd Hoffmann 
9488c43a6f0SAndreas Färber static const TypeInfo uas_info = {
9490f58f68bSGerd Hoffmann     .name          = "usb-uas",
9500f58f68bSGerd Hoffmann     .parent        = TYPE_USB_DEVICE,
9510f58f68bSGerd Hoffmann     .instance_size = sizeof(UASDevice),
9520f58f68bSGerd Hoffmann     .class_init    = usb_uas_class_initfn,
9530f58f68bSGerd Hoffmann };
9540f58f68bSGerd Hoffmann 
9550f58f68bSGerd Hoffmann static void usb_uas_register_types(void)
9560f58f68bSGerd Hoffmann {
9570f58f68bSGerd Hoffmann     type_register_static(&uas_info);
9580f58f68bSGerd Hoffmann }
9590f58f68bSGerd Hoffmann 
9600f58f68bSGerd Hoffmann type_init(usb_uas_register_types)
961