1a9b74079SCorey Minyard /* 2a9b74079SCorey Minyard * QEMU ISA IPMI BT emulation 3a9b74079SCorey Minyard * 4a9b74079SCorey Minyard * Copyright (c) 2015 Corey Minyard, MontaVista Software, LLC 5a9b74079SCorey Minyard * 6a9b74079SCorey Minyard * Permission is hereby granted, free of charge, to any person obtaining a copy 7a9b74079SCorey Minyard * of this software and associated documentation files (the "Software"), to deal 8a9b74079SCorey Minyard * in the Software without restriction, including without limitation the rights 9a9b74079SCorey Minyard * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell 10a9b74079SCorey Minyard * copies of the Software, and to permit persons to whom the Software is 11a9b74079SCorey Minyard * furnished to do so, subject to the following conditions: 12a9b74079SCorey Minyard * 13a9b74079SCorey Minyard * The above copyright notice and this permission notice shall be included in 14a9b74079SCorey Minyard * all copies or substantial portions of the Software. 15a9b74079SCorey Minyard * 16a9b74079SCorey Minyard * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR 17a9b74079SCorey Minyard * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 18a9b74079SCorey Minyard * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL 19a9b74079SCorey Minyard * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER 20a9b74079SCorey Minyard * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, 21a9b74079SCorey Minyard * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN 22a9b74079SCorey Minyard * THE SOFTWARE. 23a9b74079SCorey Minyard */ 240b8fa32fSMarkus Armbruster 250430891cSPeter Maydell #include "qemu/osdep.h" 26efbb649dSCorey Minyard #include "qemu/log.h" 270b8fa32fSMarkus Armbruster #include "qemu/module.h" 28da34e65cSMarkus Armbruster #include "qapi/error.h" 29a9b74079SCorey Minyard #include "hw/ipmi/ipmi.h" 3064552b6bSMarkus Armbruster #include "hw/irq.h" 31a9b74079SCorey Minyard #include "hw/isa/isa.h" 32*a27bd6c7SMarkus Armbruster #include "hw/qdev-properties.h" 33d6454270SMarkus Armbruster #include "migration/vmstate.h" 34a9b74079SCorey Minyard 35a9b74079SCorey Minyard /* Control register */ 36a9b74079SCorey Minyard #define IPMI_BT_CLR_WR_BIT 0 37a9b74079SCorey Minyard #define IPMI_BT_CLR_RD_BIT 1 38a9b74079SCorey Minyard #define IPMI_BT_H2B_ATN_BIT 2 39a9b74079SCorey Minyard #define IPMI_BT_B2H_ATN_BIT 3 40a9b74079SCorey Minyard #define IPMI_BT_SMS_ATN_BIT 4 41a9b74079SCorey Minyard #define IPMI_BT_HBUSY_BIT 6 42a9b74079SCorey Minyard #define IPMI_BT_BBUSY_BIT 7 43a9b74079SCorey Minyard 44a9b74079SCorey Minyard #define IPMI_BT_GET_CLR_WR(d) (((d) >> IPMI_BT_CLR_WR_BIT) & 0x1) 45a9b74079SCorey Minyard 46a9b74079SCorey Minyard #define IPMI_BT_GET_CLR_RD(d) (((d) >> IPMI_BT_CLR_RD_BIT) & 0x1) 47a9b74079SCorey Minyard 48a9b74079SCorey Minyard #define IPMI_BT_GET_H2B_ATN(d) (((d) >> IPMI_BT_H2B_ATN_BIT) & 0x1) 49a9b74079SCorey Minyard 50a9b74079SCorey Minyard #define IPMI_BT_B2H_ATN_MASK (1 << IPMI_BT_B2H_ATN_BIT) 51a9b74079SCorey Minyard #define IPMI_BT_GET_B2H_ATN(d) (((d) >> IPMI_BT_B2H_ATN_BIT) & 0x1) 52cb9a05a4SCorey Minyard #define IPMI_BT_SET_B2H_ATN(d, v) ((d) = (((d) & ~IPMI_BT_B2H_ATN_MASK) | \ 53c9c47229SCorey Minyard (!!(v) << IPMI_BT_B2H_ATN_BIT))) 54a9b74079SCorey Minyard 55a9b74079SCorey Minyard #define IPMI_BT_SMS_ATN_MASK (1 << IPMI_BT_SMS_ATN_BIT) 56a9b74079SCorey Minyard #define IPMI_BT_GET_SMS_ATN(d) (((d) >> IPMI_BT_SMS_ATN_BIT) & 0x1) 57cb9a05a4SCorey Minyard #define IPMI_BT_SET_SMS_ATN(d, v) ((d) = (((d) & ~IPMI_BT_SMS_ATN_MASK) | \ 58c9c47229SCorey Minyard (!!(v) << IPMI_BT_SMS_ATN_BIT))) 59a9b74079SCorey Minyard 60a9b74079SCorey Minyard #define IPMI_BT_HBUSY_MASK (1 << IPMI_BT_HBUSY_BIT) 61a9b74079SCorey Minyard #define IPMI_BT_GET_HBUSY(d) (((d) >> IPMI_BT_HBUSY_BIT) & 0x1) 62cb9a05a4SCorey Minyard #define IPMI_BT_SET_HBUSY(d, v) ((d) = (((d) & ~IPMI_BT_HBUSY_MASK) | \ 63c9c47229SCorey Minyard (!!(v) << IPMI_BT_HBUSY_BIT))) 64a9b74079SCorey Minyard 65a9b74079SCorey Minyard #define IPMI_BT_BBUSY_MASK (1 << IPMI_BT_BBUSY_BIT) 66cb9a05a4SCorey Minyard #define IPMI_BT_SET_BBUSY(d, v) ((d) = (((d) & ~IPMI_BT_BBUSY_MASK) | \ 67c9c47229SCorey Minyard (!!(v) << IPMI_BT_BBUSY_BIT))) 68a9b74079SCorey Minyard 69a9b74079SCorey Minyard 70a9b74079SCorey Minyard /* Mask register */ 71a9b74079SCorey Minyard #define IPMI_BT_B2H_IRQ_EN_BIT 0 72a9b74079SCorey Minyard #define IPMI_BT_B2H_IRQ_BIT 1 73a9b74079SCorey Minyard 74a9b74079SCorey Minyard #define IPMI_BT_B2H_IRQ_EN_MASK (1 << IPMI_BT_B2H_IRQ_EN_BIT) 75a9b74079SCorey Minyard #define IPMI_BT_GET_B2H_IRQ_EN(d) (((d) >> IPMI_BT_B2H_IRQ_EN_BIT) & 0x1) 76cb9a05a4SCorey Minyard #define IPMI_BT_SET_B2H_IRQ_EN(d, v) ((d) = (((d) & ~IPMI_BT_B2H_IRQ_EN_MASK) |\ 77c9c47229SCorey Minyard (!!(v) << IPMI_BT_B2H_IRQ_EN_BIT))) 78a9b74079SCorey Minyard 79a9b74079SCorey Minyard #define IPMI_BT_B2H_IRQ_MASK (1 << IPMI_BT_B2H_IRQ_BIT) 80a9b74079SCorey Minyard #define IPMI_BT_GET_B2H_IRQ(d) (((d) >> IPMI_BT_B2H_IRQ_BIT) & 0x1) 81cb9a05a4SCorey Minyard #define IPMI_BT_SET_B2H_IRQ(d, v) ((d) = (((d) & ~IPMI_BT_B2H_IRQ_MASK) | \ 82c9c47229SCorey Minyard (!!(v) << IPMI_BT_B2H_IRQ_BIT))) 83a9b74079SCorey Minyard 84a9b74079SCorey Minyard typedef struct IPMIBT { 85a9b74079SCorey Minyard IPMIBmc *bmc; 86a9b74079SCorey Minyard 87a9b74079SCorey Minyard bool do_wake; 88a9b74079SCorey Minyard 89a9b74079SCorey Minyard qemu_irq irq; 90a9b74079SCorey Minyard 91a9b74079SCorey Minyard uint32_t io_base; 92a9b74079SCorey Minyard unsigned long io_length; 93a9b74079SCorey Minyard MemoryRegion io; 94a9b74079SCorey Minyard 95a9b74079SCorey Minyard bool obf_irq_set; 96a9b74079SCorey Minyard bool atn_irq_set; 97a9b74079SCorey Minyard bool use_irq; 98a9b74079SCorey Minyard bool irqs_enabled; 99a9b74079SCorey Minyard 100a9b74079SCorey Minyard uint8_t outmsg[MAX_IPMI_MSG_SIZE]; 101a9b74079SCorey Minyard uint32_t outpos; 102a9b74079SCorey Minyard uint32_t outlen; 103a9b74079SCorey Minyard 104a9b74079SCorey Minyard uint8_t inmsg[MAX_IPMI_MSG_SIZE]; 105a9b74079SCorey Minyard uint32_t inlen; 106a9b74079SCorey Minyard 107a9b74079SCorey Minyard uint8_t control_reg; 108a9b74079SCorey Minyard uint8_t mask_reg; 109a9b74079SCorey Minyard 110a9b74079SCorey Minyard /* 111a9b74079SCorey Minyard * This is a response number that we send with the command to make 112a9b74079SCorey Minyard * sure that the response matches the command. 113a9b74079SCorey Minyard */ 114a9b74079SCorey Minyard uint8_t waiting_rsp; 115a9b74079SCorey Minyard uint8_t waiting_seq; 116a9b74079SCorey Minyard } IPMIBT; 117a9b74079SCorey Minyard 118a9b74079SCorey Minyard #define IPMI_CMD_GET_BT_INTF_CAP 0x36 119a9b74079SCorey Minyard 120a9b74079SCorey Minyard static void ipmi_bt_handle_event(IPMIInterface *ii) 121a9b74079SCorey Minyard { 122a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 123a9b74079SCorey Minyard IPMIBT *ib = iic->get_backend_data(ii); 124a9b74079SCorey Minyard 125a9b74079SCorey Minyard if (ib->inlen < 4) { 126a9b74079SCorey Minyard goto out; 127a9b74079SCorey Minyard } 128a9b74079SCorey Minyard /* Note that overruns are handled by handle_command */ 129a9b74079SCorey Minyard if (ib->inmsg[0] != (ib->inlen - 1)) { 130a9b74079SCorey Minyard /* Length mismatch, just ignore. */ 131a9b74079SCorey Minyard IPMI_BT_SET_BBUSY(ib->control_reg, 1); 132a9b74079SCorey Minyard ib->inlen = 0; 133a9b74079SCorey Minyard goto out; 134a9b74079SCorey Minyard } 135a9b74079SCorey Minyard if ((ib->inmsg[1] == (IPMI_NETFN_APP << 2)) && 136a9b74079SCorey Minyard (ib->inmsg[3] == IPMI_CMD_GET_BT_INTF_CAP)) { 137a9b74079SCorey Minyard /* We handle this one ourselves. */ 138a9b74079SCorey Minyard ib->outmsg[0] = 9; 139a9b74079SCorey Minyard ib->outmsg[1] = ib->inmsg[1] | 0x04; 140a9b74079SCorey Minyard ib->outmsg[2] = ib->inmsg[2]; 141a9b74079SCorey Minyard ib->outmsg[3] = ib->inmsg[3]; 142a9b74079SCorey Minyard ib->outmsg[4] = 0; 143a9b74079SCorey Minyard ib->outmsg[5] = 1; /* Only support 1 outstanding request. */ 144a9b74079SCorey Minyard if (sizeof(ib->inmsg) > 0xff) { /* Input buffer size */ 145a9b74079SCorey Minyard ib->outmsg[6] = 0xff; 146a9b74079SCorey Minyard } else { 147a9b74079SCorey Minyard ib->outmsg[6] = (unsigned char) sizeof(ib->inmsg); 148a9b74079SCorey Minyard } 149a9b74079SCorey Minyard if (sizeof(ib->outmsg) > 0xff) { /* Output buffer size */ 150a9b74079SCorey Minyard ib->outmsg[7] = 0xff; 151a9b74079SCorey Minyard } else { 152a9b74079SCorey Minyard ib->outmsg[7] = (unsigned char) sizeof(ib->outmsg); 153a9b74079SCorey Minyard } 154a9b74079SCorey Minyard ib->outmsg[8] = 10; /* Max request to response time */ 155a9b74079SCorey Minyard ib->outmsg[9] = 0; /* Don't recommend retries */ 156a9b74079SCorey Minyard ib->outlen = 10; 157a9b74079SCorey Minyard IPMI_BT_SET_BBUSY(ib->control_reg, 0); 158a9b74079SCorey Minyard IPMI_BT_SET_B2H_ATN(ib->control_reg, 1); 159a9b74079SCorey Minyard if (ib->use_irq && ib->irqs_enabled && 160a9b74079SCorey Minyard !IPMI_BT_GET_B2H_IRQ(ib->mask_reg) && 161a9b74079SCorey Minyard IPMI_BT_GET_B2H_IRQ_EN(ib->mask_reg)) { 162a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ(ib->mask_reg, 1); 163a9b74079SCorey Minyard qemu_irq_raise(ib->irq); 164a9b74079SCorey Minyard } 165a9b74079SCorey Minyard goto out; 166a9b74079SCorey Minyard } 167a9b74079SCorey Minyard ib->waiting_seq = ib->inmsg[2]; 168a9b74079SCorey Minyard ib->inmsg[2] = ib->inmsg[1]; 169a9b74079SCorey Minyard { 170a9b74079SCorey Minyard IPMIBmcClass *bk = IPMI_BMC_GET_CLASS(ib->bmc); 171a9b74079SCorey Minyard bk->handle_command(ib->bmc, ib->inmsg + 2, ib->inlen - 2, 172a9b74079SCorey Minyard sizeof(ib->inmsg), ib->waiting_rsp); 173a9b74079SCorey Minyard } 174a9b74079SCorey Minyard out: 175a9b74079SCorey Minyard return; 176a9b74079SCorey Minyard } 177a9b74079SCorey Minyard 178a9b74079SCorey Minyard static void ipmi_bt_handle_rsp(IPMIInterface *ii, uint8_t msg_id, 179a9b74079SCorey Minyard unsigned char *rsp, unsigned int rsp_len) 180a9b74079SCorey Minyard { 181a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 182a9b74079SCorey Minyard IPMIBT *ib = iic->get_backend_data(ii); 183a9b74079SCorey Minyard 184a9b74079SCorey Minyard if (ib->waiting_rsp == msg_id) { 185a9b74079SCorey Minyard ib->waiting_rsp++; 186a9b74079SCorey Minyard if (rsp_len > (sizeof(ib->outmsg) - 2)) { 187a9b74079SCorey Minyard ib->outmsg[0] = 4; 188a9b74079SCorey Minyard ib->outmsg[1] = rsp[0]; 189a9b74079SCorey Minyard ib->outmsg[2] = ib->waiting_seq; 190a9b74079SCorey Minyard ib->outmsg[3] = rsp[1]; 191a9b74079SCorey Minyard ib->outmsg[4] = IPMI_CC_CANNOT_RETURN_REQ_NUM_BYTES; 192a9b74079SCorey Minyard ib->outlen = 5; 193a9b74079SCorey Minyard } else { 194a9b74079SCorey Minyard ib->outmsg[0] = rsp_len + 1; 195a9b74079SCorey Minyard ib->outmsg[1] = rsp[0]; 196a9b74079SCorey Minyard ib->outmsg[2] = ib->waiting_seq; 197a9b74079SCorey Minyard memcpy(ib->outmsg + 3, rsp + 1, rsp_len - 1); 198a9b74079SCorey Minyard ib->outlen = rsp_len + 2; 199a9b74079SCorey Minyard } 200a9b74079SCorey Minyard IPMI_BT_SET_BBUSY(ib->control_reg, 0); 201a9b74079SCorey Minyard IPMI_BT_SET_B2H_ATN(ib->control_reg, 1); 202a9b74079SCorey Minyard if (ib->use_irq && ib->irqs_enabled && 203a9b74079SCorey Minyard !IPMI_BT_GET_B2H_IRQ(ib->mask_reg) && 204a9b74079SCorey Minyard IPMI_BT_GET_B2H_IRQ_EN(ib->mask_reg)) { 205a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ(ib->mask_reg, 1); 206a9b74079SCorey Minyard qemu_irq_raise(ib->irq); 207a9b74079SCorey Minyard } 208a9b74079SCorey Minyard } 209a9b74079SCorey Minyard } 210a9b74079SCorey Minyard 211a9b74079SCorey Minyard 212a9b74079SCorey Minyard static uint64_t ipmi_bt_ioport_read(void *opaque, hwaddr addr, unsigned size) 213a9b74079SCorey Minyard { 214a9b74079SCorey Minyard IPMIInterface *ii = opaque; 215a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 216a9b74079SCorey Minyard IPMIBT *ib = iic->get_backend_data(ii); 217a9b74079SCorey Minyard uint32_t ret = 0xff; 218a9b74079SCorey Minyard 219a9b74079SCorey Minyard switch (addr & 3) { 220a9b74079SCorey Minyard case 0: 221a9b74079SCorey Minyard ret = ib->control_reg; 222a9b74079SCorey Minyard break; 223a9b74079SCorey Minyard case 1: 224a9b74079SCorey Minyard if (ib->outpos < ib->outlen) { 225a9b74079SCorey Minyard ret = ib->outmsg[ib->outpos]; 226a9b74079SCorey Minyard ib->outpos++; 227a9b74079SCorey Minyard if (ib->outpos == ib->outlen) { 228a9b74079SCorey Minyard ib->outpos = 0; 229a9b74079SCorey Minyard ib->outlen = 0; 230a9b74079SCorey Minyard } 231a9b74079SCorey Minyard } else { 232a9b74079SCorey Minyard ret = 0xff; 233a9b74079SCorey Minyard } 234a9b74079SCorey Minyard break; 235a9b74079SCorey Minyard case 2: 236a9b74079SCorey Minyard ret = ib->mask_reg; 237a9b74079SCorey Minyard break; 238a9b74079SCorey Minyard } 239a9b74079SCorey Minyard return ret; 240a9b74079SCorey Minyard } 241a9b74079SCorey Minyard 242a9b74079SCorey Minyard static void ipmi_bt_signal(IPMIBT *ib, IPMIInterface *ii) 243a9b74079SCorey Minyard { 244a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 245a9b74079SCorey Minyard 246a9b74079SCorey Minyard ib->do_wake = 1; 247a9b74079SCorey Minyard while (ib->do_wake) { 248a9b74079SCorey Minyard ib->do_wake = 0; 249a9b74079SCorey Minyard iic->handle_if_event(ii); 250a9b74079SCorey Minyard } 251a9b74079SCorey Minyard } 252a9b74079SCorey Minyard 253a9b74079SCorey Minyard static void ipmi_bt_ioport_write(void *opaque, hwaddr addr, uint64_t val, 254a9b74079SCorey Minyard unsigned size) 255a9b74079SCorey Minyard { 256a9b74079SCorey Minyard IPMIInterface *ii = opaque; 257a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 258a9b74079SCorey Minyard IPMIBT *ib = iic->get_backend_data(ii); 259a9b74079SCorey Minyard 260a9b74079SCorey Minyard switch (addr & 3) { 261a9b74079SCorey Minyard case 0: 262a9b74079SCorey Minyard if (IPMI_BT_GET_CLR_WR(val)) { 263a9b74079SCorey Minyard ib->inlen = 0; 264a9b74079SCorey Minyard } 265a9b74079SCorey Minyard if (IPMI_BT_GET_CLR_RD(val)) { 266a9b74079SCorey Minyard ib->outpos = 0; 267a9b74079SCorey Minyard } 268a9b74079SCorey Minyard if (IPMI_BT_GET_B2H_ATN(val)) { 269a9b74079SCorey Minyard IPMI_BT_SET_B2H_ATN(ib->control_reg, 0); 270a9b74079SCorey Minyard } 271a9b74079SCorey Minyard if (IPMI_BT_GET_SMS_ATN(val)) { 272a9b74079SCorey Minyard IPMI_BT_SET_SMS_ATN(ib->control_reg, 0); 273a9b74079SCorey Minyard } 274a9b74079SCorey Minyard if (IPMI_BT_GET_HBUSY(val)) { 275a9b74079SCorey Minyard /* Toggle */ 276a9b74079SCorey Minyard IPMI_BT_SET_HBUSY(ib->control_reg, 277a9b74079SCorey Minyard !IPMI_BT_GET_HBUSY(ib->control_reg)); 278a9b74079SCorey Minyard } 279a9b74079SCorey Minyard if (IPMI_BT_GET_H2B_ATN(val)) { 280a9b74079SCorey Minyard IPMI_BT_SET_BBUSY(ib->control_reg, 1); 281a9b74079SCorey Minyard ipmi_bt_signal(ib, ii); 282a9b74079SCorey Minyard } 283a9b74079SCorey Minyard break; 284a9b74079SCorey Minyard 285a9b74079SCorey Minyard case 1: 286a9b74079SCorey Minyard if (ib->inlen < sizeof(ib->inmsg)) { 287a9b74079SCorey Minyard ib->inmsg[ib->inlen] = val; 288a9b74079SCorey Minyard } 289a9b74079SCorey Minyard ib->inlen++; 290a9b74079SCorey Minyard break; 291a9b74079SCorey Minyard 292a9b74079SCorey Minyard case 2: 293a9b74079SCorey Minyard if (IPMI_BT_GET_B2H_IRQ_EN(val) != 294a9b74079SCorey Minyard IPMI_BT_GET_B2H_IRQ_EN(ib->mask_reg)) { 295a9b74079SCorey Minyard if (IPMI_BT_GET_B2H_IRQ_EN(val)) { 296a9b74079SCorey Minyard if (IPMI_BT_GET_B2H_ATN(ib->control_reg) || 297a9b74079SCorey Minyard IPMI_BT_GET_SMS_ATN(ib->control_reg)) { 298a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ(ib->mask_reg, 1); 299a9b74079SCorey Minyard qemu_irq_raise(ib->irq); 300a9b74079SCorey Minyard } 301a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ_EN(ib->mask_reg, 1); 302a9b74079SCorey Minyard } else { 303a9b74079SCorey Minyard if (IPMI_BT_GET_B2H_IRQ(ib->mask_reg)) { 304a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ(ib->mask_reg, 0); 305a9b74079SCorey Minyard qemu_irq_lower(ib->irq); 306a9b74079SCorey Minyard } 307a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ_EN(ib->mask_reg, 0); 308a9b74079SCorey Minyard } 309a9b74079SCorey Minyard } 310a9b74079SCorey Minyard if (IPMI_BT_GET_B2H_IRQ(val) && IPMI_BT_GET_B2H_IRQ(ib->mask_reg)) { 311a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ(ib->mask_reg, 0); 312a9b74079SCorey Minyard qemu_irq_lower(ib->irq); 313a9b74079SCorey Minyard } 314a9b74079SCorey Minyard break; 315a9b74079SCorey Minyard } 316a9b74079SCorey Minyard } 317a9b74079SCorey Minyard 318a9b74079SCorey Minyard static const MemoryRegionOps ipmi_bt_io_ops = { 319a9b74079SCorey Minyard .read = ipmi_bt_ioport_read, 320a9b74079SCorey Minyard .write = ipmi_bt_ioport_write, 321a9b74079SCorey Minyard .impl = { 322a9b74079SCorey Minyard .min_access_size = 1, 323a9b74079SCorey Minyard .max_access_size = 1, 324a9b74079SCorey Minyard }, 325a9b74079SCorey Minyard .endianness = DEVICE_LITTLE_ENDIAN, 326a9b74079SCorey Minyard }; 327a9b74079SCorey Minyard 328a9b74079SCorey Minyard static void ipmi_bt_set_atn(IPMIInterface *ii, int val, int irq) 329a9b74079SCorey Minyard { 330a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 331a9b74079SCorey Minyard IPMIBT *ib = iic->get_backend_data(ii); 332a9b74079SCorey Minyard 333a9b74079SCorey Minyard if (!!val == IPMI_BT_GET_SMS_ATN(ib->control_reg)) { 334a9b74079SCorey Minyard return; 335a9b74079SCorey Minyard } 336a9b74079SCorey Minyard 337a9b74079SCorey Minyard IPMI_BT_SET_SMS_ATN(ib->control_reg, val); 338a9b74079SCorey Minyard if (val) { 339a9b74079SCorey Minyard if (irq && ib->use_irq && ib->irqs_enabled && 340a9b74079SCorey Minyard !IPMI_BT_GET_B2H_ATN(ib->control_reg) && 341a9b74079SCorey Minyard IPMI_BT_GET_B2H_IRQ_EN(ib->mask_reg)) { 342a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ(ib->mask_reg, 1); 343a9b74079SCorey Minyard qemu_irq_raise(ib->irq); 344a9b74079SCorey Minyard } 345a9b74079SCorey Minyard } else { 346a9b74079SCorey Minyard if (!IPMI_BT_GET_B2H_ATN(ib->control_reg) && 347a9b74079SCorey Minyard IPMI_BT_GET_B2H_IRQ(ib->mask_reg)) { 348a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ(ib->mask_reg, 0); 349a9b74079SCorey Minyard qemu_irq_lower(ib->irq); 350a9b74079SCorey Minyard } 351a9b74079SCorey Minyard } 352a9b74079SCorey Minyard } 353a9b74079SCorey Minyard 354a9b74079SCorey Minyard static void ipmi_bt_handle_reset(IPMIInterface *ii, bool is_cold) 355a9b74079SCorey Minyard { 356a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 357a9b74079SCorey Minyard IPMIBT *ib = iic->get_backend_data(ii); 358a9b74079SCorey Minyard 359a9b74079SCorey Minyard if (is_cold) { 360a9b74079SCorey Minyard /* Disable the BT interrupt on reset */ 361a9b74079SCorey Minyard if (IPMI_BT_GET_B2H_IRQ(ib->mask_reg)) { 362a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ(ib->mask_reg, 0); 363a9b74079SCorey Minyard qemu_irq_lower(ib->irq); 364a9b74079SCorey Minyard } 365a9b74079SCorey Minyard IPMI_BT_SET_B2H_IRQ_EN(ib->mask_reg, 0); 366a9b74079SCorey Minyard } 367a9b74079SCorey Minyard } 368a9b74079SCorey Minyard 369a9b74079SCorey Minyard static void ipmi_bt_set_irq_enable(IPMIInterface *ii, int val) 370a9b74079SCorey Minyard { 371a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 372a9b74079SCorey Minyard IPMIBT *ib = iic->get_backend_data(ii); 373a9b74079SCorey Minyard 374a9b74079SCorey Minyard ib->irqs_enabled = val; 375a9b74079SCorey Minyard } 376a9b74079SCorey Minyard 377a9b74079SCorey Minyard static void ipmi_bt_init(IPMIInterface *ii, Error **errp) 378a9b74079SCorey Minyard { 379a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 380a9b74079SCorey Minyard IPMIBT *ib = iic->get_backend_data(ii); 381a9b74079SCorey Minyard 382a9b74079SCorey Minyard ib->io_length = 3; 383a9b74079SCorey Minyard 384a9b74079SCorey Minyard memory_region_init_io(&ib->io, NULL, &ipmi_bt_io_ops, ii, "ipmi-bt", 3); 385a9b74079SCorey Minyard } 386a9b74079SCorey Minyard 387a9b74079SCorey Minyard 388a9b74079SCorey Minyard #define TYPE_ISA_IPMI_BT "isa-ipmi-bt" 389a9b74079SCorey Minyard #define ISA_IPMI_BT(obj) OBJECT_CHECK(ISAIPMIBTDevice, (obj), \ 390a9b74079SCorey Minyard TYPE_ISA_IPMI_BT) 391a9b74079SCorey Minyard 392a9b74079SCorey Minyard typedef struct ISAIPMIBTDevice { 393a9b74079SCorey Minyard ISADevice dev; 394f4014512SPeter Maydell int32_t isairq; 395a9b74079SCorey Minyard IPMIBT bt; 39615139b8eSCorey Minyard uint32_t uuid; 397a9b74079SCorey Minyard } ISAIPMIBTDevice; 398a9b74079SCorey Minyard 39915139b8eSCorey Minyard static void ipmi_bt_get_fwinfo(struct IPMIInterface *ii, IPMIFwInfo *info) 40015139b8eSCorey Minyard { 40115139b8eSCorey Minyard ISAIPMIBTDevice *iib = ISA_IPMI_BT(ii); 40215139b8eSCorey Minyard 40315139b8eSCorey Minyard info->interface_name = "bt"; 40415139b8eSCorey Minyard info->interface_type = IPMI_SMBIOS_BT; 40515139b8eSCorey Minyard info->ipmi_spec_major_revision = 2; 40615139b8eSCorey Minyard info->ipmi_spec_minor_revision = 0; 40715139b8eSCorey Minyard info->base_address = iib->bt.io_base; 40815139b8eSCorey Minyard info->register_length = iib->bt.io_length; 40915139b8eSCorey Minyard info->register_spacing = 1; 41015139b8eSCorey Minyard info->memspace = IPMI_MEMSPACE_IO; 41115139b8eSCorey Minyard info->irq_type = IPMI_LEVEL_IRQ; 41215139b8eSCorey Minyard info->interrupt_number = iib->isairq; 41315139b8eSCorey Minyard info->i2c_slave_address = iib->bt.bmc->slave_addr; 41415139b8eSCorey Minyard info->uuid = iib->uuid; 41515139b8eSCorey Minyard } 41615139b8eSCorey Minyard 41715139b8eSCorey Minyard static void ipmi_bt_class_init(IPMIInterfaceClass *iic) 41815139b8eSCorey Minyard { 41915139b8eSCorey Minyard iic->init = ipmi_bt_init; 42015139b8eSCorey Minyard iic->set_atn = ipmi_bt_set_atn; 42115139b8eSCorey Minyard iic->handle_rsp = ipmi_bt_handle_rsp; 42215139b8eSCorey Minyard iic->handle_if_event = ipmi_bt_handle_event; 42315139b8eSCorey Minyard iic->set_irq_enable = ipmi_bt_set_irq_enable; 42415139b8eSCorey Minyard iic->reset = ipmi_bt_handle_reset; 42515139b8eSCorey Minyard iic->get_fwinfo = ipmi_bt_get_fwinfo; 42615139b8eSCorey Minyard } 42715139b8eSCorey Minyard 428a9b74079SCorey Minyard static void isa_ipmi_bt_realize(DeviceState *dev, Error **errp) 429a9b74079SCorey Minyard { 430a9b74079SCorey Minyard ISADevice *isadev = ISA_DEVICE(dev); 431a9b74079SCorey Minyard ISAIPMIBTDevice *iib = ISA_IPMI_BT(dev); 432a9b74079SCorey Minyard IPMIInterface *ii = IPMI_INTERFACE(dev); 433a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_GET_CLASS(ii); 434a9b74079SCorey Minyard 435a9b74079SCorey Minyard if (!iib->bt.bmc) { 436a9b74079SCorey Minyard error_setg(errp, "IPMI device requires a bmc attribute to be set"); 437a9b74079SCorey Minyard return; 438a9b74079SCorey Minyard } 439a9b74079SCorey Minyard 44015139b8eSCorey Minyard iib->uuid = ipmi_next_uuid(); 44115139b8eSCorey Minyard 442a9b74079SCorey Minyard iib->bt.bmc->intf = ii; 443a9b74079SCorey Minyard 444a9b74079SCorey Minyard iic->init(ii, errp); 445a9b74079SCorey Minyard if (*errp) 446a9b74079SCorey Minyard return; 447a9b74079SCorey Minyard 448a9b74079SCorey Minyard if (iib->isairq > 0) { 449a9b74079SCorey Minyard isa_init_irq(isadev, &iib->bt.irq, iib->isairq); 450a9b74079SCorey Minyard iib->bt.use_irq = 1; 451a9b74079SCorey Minyard } 452a9b74079SCorey Minyard 453a9b74079SCorey Minyard qdev_set_legacy_instance_id(dev, iib->bt.io_base, iib->bt.io_length); 454a9b74079SCorey Minyard 455a9b74079SCorey Minyard isa_register_ioport(isadev, &iib->bt.io, iib->bt.io_base); 456a9b74079SCorey Minyard } 457a9b74079SCorey Minyard 458efbb649dSCorey Minyard static int ipmi_bt_vmstate_post_load(void *opaque, int version) 459efbb649dSCorey Minyard { 460efbb649dSCorey Minyard IPMIBT *ib = opaque; 461efbb649dSCorey Minyard 462efbb649dSCorey Minyard /* Make sure all the values are sane. */ 463efbb649dSCorey Minyard if (ib->outpos >= MAX_IPMI_MSG_SIZE || ib->outlen >= MAX_IPMI_MSG_SIZE || 464efbb649dSCorey Minyard ib->outpos >= ib->outlen) { 465efbb649dSCorey Minyard qemu_log_mask(LOG_GUEST_ERROR, 466efbb649dSCorey Minyard "ipmi:bt: vmstate transfer received bad out values: %d %d\n", 467efbb649dSCorey Minyard ib->outpos, ib->outlen); 468efbb649dSCorey Minyard ib->outpos = 0; 469efbb649dSCorey Minyard ib->outlen = 0; 470efbb649dSCorey Minyard } 471efbb649dSCorey Minyard 472efbb649dSCorey Minyard if (ib->inlen >= MAX_IPMI_MSG_SIZE) { 473efbb649dSCorey Minyard qemu_log_mask(LOG_GUEST_ERROR, 474efbb649dSCorey Minyard "ipmi:bt: vmstate transfer received bad in value: %d\n", 475efbb649dSCorey Minyard ib->inlen); 476efbb649dSCorey Minyard ib->inlen = 0; 477efbb649dSCorey Minyard } 478efbb649dSCorey Minyard 479efbb649dSCorey Minyard return 0; 480efbb649dSCorey Minyard } 481efbb649dSCorey Minyard 482efbb649dSCorey Minyard const VMStateDescription vmstate_IPMIBT = { 483efbb649dSCorey Minyard .name = TYPE_IPMI_INTERFACE_PREFIX "bt", 484bd66bcfcSCorey Minyard .version_id = 1, 485bd66bcfcSCorey Minyard .minimum_version_id = 1, 486efbb649dSCorey Minyard .post_load = ipmi_bt_vmstate_post_load, 487bd66bcfcSCorey Minyard .fields = (VMStateField[]) { 488efbb649dSCorey Minyard VMSTATE_BOOL(obf_irq_set, IPMIBT), 489efbb649dSCorey Minyard VMSTATE_BOOL(atn_irq_set, IPMIBT), 490efbb649dSCorey Minyard VMSTATE_BOOL(irqs_enabled, IPMIBT), 491efbb649dSCorey Minyard VMSTATE_UINT32(outpos, IPMIBT), 492efbb649dSCorey Minyard VMSTATE_UINT32(outlen, IPMIBT), 493efbb649dSCorey Minyard VMSTATE_UINT8_ARRAY(outmsg, IPMIBT, MAX_IPMI_MSG_SIZE), 494efbb649dSCorey Minyard VMSTATE_UINT32(inlen, IPMIBT), 495efbb649dSCorey Minyard VMSTATE_UINT8_ARRAY(inmsg, IPMIBT, MAX_IPMI_MSG_SIZE), 496efbb649dSCorey Minyard VMSTATE_UINT8(control_reg, IPMIBT), 497efbb649dSCorey Minyard VMSTATE_UINT8(mask_reg, IPMIBT), 498efbb649dSCorey Minyard VMSTATE_UINT8(waiting_rsp, IPMIBT), 499efbb649dSCorey Minyard VMSTATE_UINT8(waiting_seq, IPMIBT), 500efbb649dSCorey Minyard VMSTATE_END_OF_LIST() 501efbb649dSCorey Minyard } 502efbb649dSCorey Minyard }; 503efbb649dSCorey Minyard 504efbb649dSCorey Minyard static const VMStateDescription vmstate_ISAIPMIBTDevice = { 505efbb649dSCorey Minyard .name = TYPE_IPMI_INTERFACE_PREFIX "isa-bt", 506efbb649dSCorey Minyard .version_id = 2, 507efbb649dSCorey Minyard .minimum_version_id = 2, 508efbb649dSCorey Minyard /* 509efbb649dSCorey Minyard * Version 1 had messed up the array transfer, it's not even usable 510efbb649dSCorey Minyard * because it used VMSTATE_VBUFFER_UINT32, but it did not transfer 511efbb649dSCorey Minyard * the buffer length, so random things would happen. 512efbb649dSCorey Minyard */ 513efbb649dSCorey Minyard .fields = (VMStateField[]) { 514efbb649dSCorey Minyard VMSTATE_STRUCT(bt, ISAIPMIBTDevice, 1, vmstate_IPMIBT, IPMIBT), 515bd66bcfcSCorey Minyard VMSTATE_END_OF_LIST() 516bd66bcfcSCorey Minyard } 517bd66bcfcSCorey Minyard }; 518bd66bcfcSCorey Minyard 519a9b74079SCorey Minyard static void isa_ipmi_bt_init(Object *obj) 520a9b74079SCorey Minyard { 521a9b74079SCorey Minyard ISAIPMIBTDevice *iib = ISA_IPMI_BT(obj); 522a9b74079SCorey Minyard 523a9b74079SCorey Minyard ipmi_bmc_find_and_link(obj, (Object **) &iib->bt.bmc); 524bd66bcfcSCorey Minyard 525bd66bcfcSCorey Minyard vmstate_register(NULL, 0, &vmstate_ISAIPMIBTDevice, iib); 526a9b74079SCorey Minyard } 527a9b74079SCorey Minyard 528a9b74079SCorey Minyard static void *isa_ipmi_bt_get_backend_data(IPMIInterface *ii) 529a9b74079SCorey Minyard { 530a9b74079SCorey Minyard ISAIPMIBTDevice *iib = ISA_IPMI_BT(ii); 531a9b74079SCorey Minyard 532a9b74079SCorey Minyard return &iib->bt; 533a9b74079SCorey Minyard } 534a9b74079SCorey Minyard 535a9b74079SCorey Minyard static Property ipmi_isa_properties[] = { 536a9b74079SCorey Minyard DEFINE_PROP_UINT32("ioport", ISAIPMIBTDevice, bt.io_base, 0xe4), 537a9b74079SCorey Minyard DEFINE_PROP_INT32("irq", ISAIPMIBTDevice, isairq, 5), 538a9b74079SCorey Minyard DEFINE_PROP_END_OF_LIST(), 539a9b74079SCorey Minyard }; 540a9b74079SCorey Minyard 541a9b74079SCorey Minyard static void isa_ipmi_bt_class_init(ObjectClass *oc, void *data) 542a9b74079SCorey Minyard { 543a9b74079SCorey Minyard DeviceClass *dc = DEVICE_CLASS(oc); 544a9b74079SCorey Minyard IPMIInterfaceClass *iic = IPMI_INTERFACE_CLASS(oc); 545a9b74079SCorey Minyard 546a9b74079SCorey Minyard dc->realize = isa_ipmi_bt_realize; 547a9b74079SCorey Minyard dc->props = ipmi_isa_properties; 548a9b74079SCorey Minyard 549a9b74079SCorey Minyard iic->get_backend_data = isa_ipmi_bt_get_backend_data; 550a9b74079SCorey Minyard ipmi_bt_class_init(iic); 551a9b74079SCorey Minyard } 552a9b74079SCorey Minyard 553a9b74079SCorey Minyard static const TypeInfo isa_ipmi_bt_info = { 554a9b74079SCorey Minyard .name = TYPE_ISA_IPMI_BT, 555a9b74079SCorey Minyard .parent = TYPE_ISA_DEVICE, 556a9b74079SCorey Minyard .instance_size = sizeof(ISAIPMIBTDevice), 557a9b74079SCorey Minyard .instance_init = isa_ipmi_bt_init, 558a9b74079SCorey Minyard .class_init = isa_ipmi_bt_class_init, 559a9b74079SCorey Minyard .interfaces = (InterfaceInfo[]) { 560a9b74079SCorey Minyard { TYPE_IPMI_INTERFACE }, 561a9b74079SCorey Minyard { } 562a9b74079SCorey Minyard } 563a9b74079SCorey Minyard }; 564a9b74079SCorey Minyard 565a9b74079SCorey Minyard static void ipmi_register_types(void) 566a9b74079SCorey Minyard { 567a9b74079SCorey Minyard type_register_static(&isa_ipmi_bt_info); 568a9b74079SCorey Minyard } 569a9b74079SCorey Minyard 570a9b74079SCorey Minyard type_init(ipmi_register_types) 571