xref: /qemu/hw/scsi/esp.c (revision dfaf55a19ab0e0afba8aa34c7fb04c1566e41519)
16f7e9aecSbellard /*
267e999beSbellard  * QEMU ESP/NCR53C9x emulation
36f7e9aecSbellard  *
44e9aec74Spbrook  * Copyright (c) 2005-2006 Fabrice Bellard
5fabaaf1dSHervé Poussineau  * Copyright (c) 2012 Herve Poussineau
678d68f31SMark Cave-Ayland  * Copyright (c) 2023 Mark Cave-Ayland
76f7e9aecSbellard  *
86f7e9aecSbellard  * Permission is hereby granted, free of charge, to any person obtaining a copy
96f7e9aecSbellard  * of this software and associated documentation files (the "Software"), to deal
106f7e9aecSbellard  * in the Software without restriction, including without limitation the rights
116f7e9aecSbellard  * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
126f7e9aecSbellard  * copies of the Software, and to permit persons to whom the Software is
136f7e9aecSbellard  * furnished to do so, subject to the following conditions:
146f7e9aecSbellard  *
156f7e9aecSbellard  * The above copyright notice and this permission notice shall be included in
166f7e9aecSbellard  * all copies or substantial portions of the Software.
176f7e9aecSbellard  *
186f7e9aecSbellard  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
196f7e9aecSbellard  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
206f7e9aecSbellard  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
216f7e9aecSbellard  * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
226f7e9aecSbellard  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
236f7e9aecSbellard  * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
246f7e9aecSbellard  * THE SOFTWARE.
256f7e9aecSbellard  */
265d20fa6bSblueswir1 
27a4ab4792SPeter Maydell #include "qemu/osdep.h"
2883c9f4caSPaolo Bonzini #include "hw/sysbus.h"
29d6454270SMarkus Armbruster #include "migration/vmstate.h"
3064552b6bSMarkus Armbruster #include "hw/irq.h"
310d09e41aSPaolo Bonzini #include "hw/scsi/esp.h"
32bf4b9889SBlue Swirl #include "trace.h"
331de7afc9SPaolo Bonzini #include "qemu/log.h"
340b8fa32fSMarkus Armbruster #include "qemu/module.h"
356f7e9aecSbellard 
3667e999beSbellard /*
375ad6bb97Sblueswir1  * On Sparc32, this is the ESP (NCR53C90) part of chip STP2000 (Master I/O),
385ad6bb97Sblueswir1  * also produced as NCR89C100. See
3967e999beSbellard  * http://www.ibiblio.org/pub/historic-linux/early-ports/Sparc/NCR/NCR89C100.txt
4067e999beSbellard  * and
4167e999beSbellard  * http://www.ibiblio.org/pub/historic-linux/early-ports/Sparc/NCR/NCR53C9X.txt
4274d71ea1SLaurent Vivier  *
4374d71ea1SLaurent Vivier  * On Macintosh Quadra it is a NCR53C96.
4467e999beSbellard  */
4567e999beSbellard 
46c73f96fdSblueswir1 static void esp_raise_irq(ESPState *s)
47c73f96fdSblueswir1 {
48c73f96fdSblueswir1     if (!(s->rregs[ESP_RSTAT] & STAT_INT)) {
49c73f96fdSblueswir1         s->rregs[ESP_RSTAT] |= STAT_INT;
50c73f96fdSblueswir1         qemu_irq_raise(s->irq);
51bf4b9889SBlue Swirl         trace_esp_raise_irq();
52c73f96fdSblueswir1     }
53c73f96fdSblueswir1 }
54c73f96fdSblueswir1 
55c73f96fdSblueswir1 static void esp_lower_irq(ESPState *s)
56c73f96fdSblueswir1 {
57c73f96fdSblueswir1     if (s->rregs[ESP_RSTAT] & STAT_INT) {
58c73f96fdSblueswir1         s->rregs[ESP_RSTAT] &= ~STAT_INT;
59c73f96fdSblueswir1         qemu_irq_lower(s->irq);
60bf4b9889SBlue Swirl         trace_esp_lower_irq();
61c73f96fdSblueswir1     }
62c73f96fdSblueswir1 }
63c73f96fdSblueswir1 
6474d71ea1SLaurent Vivier static void esp_raise_drq(ESPState *s)
6574d71ea1SLaurent Vivier {
66442de89aSMark Cave-Ayland     if (!(s->drq_state)) {
676dec7c0dSMark Cave-Ayland         qemu_irq_raise(s->drq_irq);
68960ebfd9SMark Cave-Ayland         trace_esp_raise_drq();
69442de89aSMark Cave-Ayland         s->drq_state = true;
70442de89aSMark Cave-Ayland     }
7174d71ea1SLaurent Vivier }
7274d71ea1SLaurent Vivier 
7374d71ea1SLaurent Vivier static void esp_lower_drq(ESPState *s)
7474d71ea1SLaurent Vivier {
75442de89aSMark Cave-Ayland     if (s->drq_state) {
766dec7c0dSMark Cave-Ayland         qemu_irq_lower(s->drq_irq);
77960ebfd9SMark Cave-Ayland         trace_esp_lower_drq();
78442de89aSMark Cave-Ayland         s->drq_state = false;
79442de89aSMark Cave-Ayland     }
8074d71ea1SLaurent Vivier }
8174d71ea1SLaurent Vivier 
822c1017bfSMark Cave-Ayland static const char *esp_phase_names[8] = {
832c1017bfSMark Cave-Ayland     "DATA OUT", "DATA IN", "COMMAND", "STATUS",
842c1017bfSMark Cave-Ayland     "(reserved)", "(reserved)", "MESSAGE OUT", "MESSAGE IN"
852c1017bfSMark Cave-Ayland };
862c1017bfSMark Cave-Ayland 
872c1017bfSMark Cave-Ayland static void esp_set_phase(ESPState *s, uint8_t phase)
882c1017bfSMark Cave-Ayland {
892c1017bfSMark Cave-Ayland     s->rregs[ESP_RSTAT] &= ~7;
902c1017bfSMark Cave-Ayland     s->rregs[ESP_RSTAT] |= phase;
912c1017bfSMark Cave-Ayland 
922c1017bfSMark Cave-Ayland     trace_esp_set_phase(esp_phase_names[phase]);
932c1017bfSMark Cave-Ayland }
942c1017bfSMark Cave-Ayland 
952c1017bfSMark Cave-Ayland static uint8_t esp_get_phase(ESPState *s)
962c1017bfSMark Cave-Ayland {
972c1017bfSMark Cave-Ayland     return s->rregs[ESP_RSTAT] & 7;
982c1017bfSMark Cave-Ayland }
992c1017bfSMark Cave-Ayland 
1009c7e23fcSHervé Poussineau void esp_dma_enable(ESPState *s, int irq, int level)
10173d74342SBlue Swirl {
10273d74342SBlue Swirl     if (level) {
10373d74342SBlue Swirl         s->dma_enabled = 1;
104bf4b9889SBlue Swirl         trace_esp_dma_enable();
10573d74342SBlue Swirl         if (s->dma_cb) {
10673d74342SBlue Swirl             s->dma_cb(s);
10773d74342SBlue Swirl             s->dma_cb = NULL;
10873d74342SBlue Swirl         }
10973d74342SBlue Swirl     } else {
110bf4b9889SBlue Swirl         trace_esp_dma_disable();
11173d74342SBlue Swirl         s->dma_enabled = 0;
11273d74342SBlue Swirl     }
11373d74342SBlue Swirl }
11473d74342SBlue Swirl 
1159c7e23fcSHervé Poussineau void esp_request_cancelled(SCSIRequest *req)
11694d3f98aSPaolo Bonzini {
117e6810db8SHervé Poussineau     ESPState *s = req->hba_private;
11894d3f98aSPaolo Bonzini 
11994d3f98aSPaolo Bonzini     if (req == s->current_req) {
12094d3f98aSPaolo Bonzini         scsi_req_unref(s->current_req);
12194d3f98aSPaolo Bonzini         s->current_req = NULL;
12294d3f98aSPaolo Bonzini         s->current_dev = NULL;
123324c8809SMark Cave-Ayland         s->async_len = 0;
12494d3f98aSPaolo Bonzini     }
12594d3f98aSPaolo Bonzini }
12694d3f98aSPaolo Bonzini 
127743d8736SMark Cave-Ayland static void esp_update_drq(ESPState *s)
128743d8736SMark Cave-Ayland {
129743d8736SMark Cave-Ayland     bool to_device;
130743d8736SMark Cave-Ayland 
131743d8736SMark Cave-Ayland     switch (esp_get_phase(s)) {
132743d8736SMark Cave-Ayland     case STAT_MO:
133743d8736SMark Cave-Ayland     case STAT_CD:
134743d8736SMark Cave-Ayland     case STAT_DO:
135743d8736SMark Cave-Ayland         to_device = true;
136743d8736SMark Cave-Ayland         break;
137743d8736SMark Cave-Ayland 
138743d8736SMark Cave-Ayland     case STAT_DI:
139743d8736SMark Cave-Ayland     case STAT_ST:
140743d8736SMark Cave-Ayland     case STAT_MI:
141743d8736SMark Cave-Ayland         to_device = false;
142743d8736SMark Cave-Ayland         break;
143743d8736SMark Cave-Ayland 
144743d8736SMark Cave-Ayland     default:
145743d8736SMark Cave-Ayland         return;
146743d8736SMark Cave-Ayland     }
147743d8736SMark Cave-Ayland 
148743d8736SMark Cave-Ayland     if (s->dma) {
149743d8736SMark Cave-Ayland         /* DMA request so update DRQ according to transfer direction */
150743d8736SMark Cave-Ayland         if (to_device) {
151743d8736SMark Cave-Ayland             if (fifo8_num_free(&s->fifo) < 2) {
152743d8736SMark Cave-Ayland                 esp_lower_drq(s);
153743d8736SMark Cave-Ayland             } else {
154743d8736SMark Cave-Ayland                 esp_raise_drq(s);
155743d8736SMark Cave-Ayland             }
156743d8736SMark Cave-Ayland         } else {
157743d8736SMark Cave-Ayland             if (fifo8_num_used(&s->fifo) < 2) {
158743d8736SMark Cave-Ayland                 esp_lower_drq(s);
159743d8736SMark Cave-Ayland             } else {
160743d8736SMark Cave-Ayland                 esp_raise_drq(s);
161743d8736SMark Cave-Ayland             }
162743d8736SMark Cave-Ayland         }
163743d8736SMark Cave-Ayland     } else {
164743d8736SMark Cave-Ayland         /* Not a DMA request */
165743d8736SMark Cave-Ayland         esp_lower_drq(s);
166743d8736SMark Cave-Ayland     }
167743d8736SMark Cave-Ayland }
168743d8736SMark Cave-Ayland 
1690e7dbe29SMark Cave-Ayland static void esp_fifo_push(ESPState *s, uint8_t val)
170042879fcSMark Cave-Ayland {
1710e7dbe29SMark Cave-Ayland     if (fifo8_num_used(&s->fifo) == s->fifo.capacity) {
172042879fcSMark Cave-Ayland         trace_esp_error_fifo_overrun();
173ffa3a5f2SMark Cave-Ayland     } else {
174ffa3a5f2SMark Cave-Ayland         fifo8_push(&s->fifo, val);
175042879fcSMark Cave-Ayland     }
176042879fcSMark Cave-Ayland 
177ffa3a5f2SMark Cave-Ayland     esp_update_drq(s);
178042879fcSMark Cave-Ayland }
179c5fef911SMark Cave-Ayland 
180266170f9SMark Cave-Ayland static void esp_fifo_push_buf(ESPState *s, uint8_t *buf, int len)
181266170f9SMark Cave-Ayland {
182266170f9SMark Cave-Ayland     fifo8_push_all(&s->fifo, buf, len);
183743d8736SMark Cave-Ayland     esp_update_drq(s);
184266170f9SMark Cave-Ayland }
185266170f9SMark Cave-Ayland 
18661fa150dSMark Cave-Ayland static uint8_t esp_fifo_pop(ESPState *s)
187042879fcSMark Cave-Ayland {
188ffa3a5f2SMark Cave-Ayland     uint8_t val;
189ffa3a5f2SMark Cave-Ayland 
19061fa150dSMark Cave-Ayland     if (fifo8_is_empty(&s->fifo)) {
191ffa3a5f2SMark Cave-Ayland         val = 0;
192ffa3a5f2SMark Cave-Ayland     } else {
193ffa3a5f2SMark Cave-Ayland         val = fifo8_pop(&s->fifo);
194042879fcSMark Cave-Ayland     }
195042879fcSMark Cave-Ayland 
196ffa3a5f2SMark Cave-Ayland     esp_update_drq(s);
197ffa3a5f2SMark Cave-Ayland     return val;
198023666daSMark Cave-Ayland }
199023666daSMark Cave-Ayland 
200d103d0dbSMark Cave-Ayland static uint32_t esp_fifo8_pop_buf(Fifo8 *fifo, uint8_t *dest, int maxlen)
2017b320a8eSMark Cave-Ayland {
2027b320a8eSMark Cave-Ayland     const uint8_t *buf;
20349c60d16SMark Cave-Ayland     uint32_t n, n2;
20449c60d16SMark Cave-Ayland     int len;
2057b320a8eSMark Cave-Ayland 
2067b320a8eSMark Cave-Ayland     if (maxlen == 0) {
2077b320a8eSMark Cave-Ayland         return 0;
2087b320a8eSMark Cave-Ayland     }
2097b320a8eSMark Cave-Ayland 
21049c60d16SMark Cave-Ayland     len = maxlen;
21149c60d16SMark Cave-Ayland     buf = fifo8_pop_buf(fifo, len, &n);
2127b320a8eSMark Cave-Ayland     if (dest) {
2137b320a8eSMark Cave-Ayland         memcpy(dest, buf, n);
2147b320a8eSMark Cave-Ayland     }
2157b320a8eSMark Cave-Ayland 
21649c60d16SMark Cave-Ayland     /* Add FIFO wraparound if needed */
21749c60d16SMark Cave-Ayland     len -= n;
21849c60d16SMark Cave-Ayland     len = MIN(len, fifo8_num_used(fifo));
21949c60d16SMark Cave-Ayland     if (len) {
22049c60d16SMark Cave-Ayland         buf = fifo8_pop_buf(fifo, len, &n2);
22149c60d16SMark Cave-Ayland         if (dest) {
22249c60d16SMark Cave-Ayland             memcpy(&dest[n], buf, n2);
22349c60d16SMark Cave-Ayland         }
22449c60d16SMark Cave-Ayland         n += n2;
22549c60d16SMark Cave-Ayland     }
22649c60d16SMark Cave-Ayland 
2277b320a8eSMark Cave-Ayland     return n;
2287b320a8eSMark Cave-Ayland }
2297b320a8eSMark Cave-Ayland 
230da838126SMark Cave-Ayland static uint32_t esp_fifo_pop_buf(ESPState *s, uint8_t *dest, int maxlen)
231d103d0dbSMark Cave-Ayland {
232743d8736SMark Cave-Ayland     uint32_t len = esp_fifo8_pop_buf(&s->fifo, dest, maxlen);
233743d8736SMark Cave-Ayland 
234743d8736SMark Cave-Ayland     esp_update_drq(s);
235743d8736SMark Cave-Ayland     return len;
236d103d0dbSMark Cave-Ayland }
237d103d0dbSMark Cave-Ayland 
238c47b5835SMark Cave-Ayland static uint32_t esp_get_tc(ESPState *s)
239c47b5835SMark Cave-Ayland {
240c47b5835SMark Cave-Ayland     uint32_t dmalen;
241c47b5835SMark Cave-Ayland 
242c47b5835SMark Cave-Ayland     dmalen = s->rregs[ESP_TCLO];
243c47b5835SMark Cave-Ayland     dmalen |= s->rregs[ESP_TCMID] << 8;
244c47b5835SMark Cave-Ayland     dmalen |= s->rregs[ESP_TCHI] << 16;
245c47b5835SMark Cave-Ayland 
246c47b5835SMark Cave-Ayland     return dmalen;
247c47b5835SMark Cave-Ayland }
248c47b5835SMark Cave-Ayland 
249c47b5835SMark Cave-Ayland static void esp_set_tc(ESPState *s, uint32_t dmalen)
250c47b5835SMark Cave-Ayland {
251c5d7df28SMark Cave-Ayland     uint32_t old_tc = esp_get_tc(s);
252c5d7df28SMark Cave-Ayland 
253c47b5835SMark Cave-Ayland     s->rregs[ESP_TCLO] = dmalen;
254c47b5835SMark Cave-Ayland     s->rregs[ESP_TCMID] = dmalen >> 8;
255c47b5835SMark Cave-Ayland     s->rregs[ESP_TCHI] = dmalen >> 16;
256c5d7df28SMark Cave-Ayland 
257c5d7df28SMark Cave-Ayland     if (old_tc && dmalen == 0) {
258c5d7df28SMark Cave-Ayland         s->rregs[ESP_RSTAT] |= STAT_TC;
259c5d7df28SMark Cave-Ayland     }
260c47b5835SMark Cave-Ayland }
261c47b5835SMark Cave-Ayland 
262c04ed569SMark Cave-Ayland static uint32_t esp_get_stc(ESPState *s)
263c04ed569SMark Cave-Ayland {
264c04ed569SMark Cave-Ayland     uint32_t dmalen;
265c04ed569SMark Cave-Ayland 
266c04ed569SMark Cave-Ayland     dmalen = s->wregs[ESP_TCLO];
267c04ed569SMark Cave-Ayland     dmalen |= s->wregs[ESP_TCMID] << 8;
268c04ed569SMark Cave-Ayland     dmalen |= s->wregs[ESP_TCHI] << 16;
269c04ed569SMark Cave-Ayland 
270c04ed569SMark Cave-Ayland     return dmalen;
271c04ed569SMark Cave-Ayland }
272c04ed569SMark Cave-Ayland 
273761bef75SMark Cave-Ayland static uint8_t esp_pdma_read(ESPState *s)
274761bef75SMark Cave-Ayland {
2758da90e81SMark Cave-Ayland     uint8_t val;
2768da90e81SMark Cave-Ayland 
27761fa150dSMark Cave-Ayland     val = esp_fifo_pop(s);
2788da90e81SMark Cave-Ayland     return val;
279761bef75SMark Cave-Ayland }
280761bef75SMark Cave-Ayland 
281761bef75SMark Cave-Ayland static void esp_pdma_write(ESPState *s, uint8_t val)
282761bef75SMark Cave-Ayland {
2838da90e81SMark Cave-Ayland     uint32_t dmalen = esp_get_tc(s);
2848da90e81SMark Cave-Ayland 
2850e7dbe29SMark Cave-Ayland     esp_fifo_push(s, val);
2868da90e81SMark Cave-Ayland 
28760c57250SMark Cave-Ayland     if (dmalen && s->drq_state) {
2888da90e81SMark Cave-Ayland         dmalen--;
2898da90e81SMark Cave-Ayland         esp_set_tc(s, dmalen);
290761bef75SMark Cave-Ayland     }
29160c57250SMark Cave-Ayland }
292761bef75SMark Cave-Ayland 
293c7bce09cSMark Cave-Ayland static int esp_select(ESPState *s)
2946130b188SLaurent Vivier {
2956130b188SLaurent Vivier     int target;
2966130b188SLaurent Vivier 
2976130b188SLaurent Vivier     target = s->wregs[ESP_WBUSID] & BUSID_DID;
2986130b188SLaurent Vivier 
2996130b188SLaurent Vivier     s->ti_size = 0;
3009b2cdca2SMark Cave-Ayland     s->rregs[ESP_RSEQ] = SEQ_0;
3016130b188SLaurent Vivier 
302cf40a5e4SMark Cave-Ayland     if (s->current_req) {
303cf40a5e4SMark Cave-Ayland         /* Started a new command before the old one finished. Cancel it. */
304cf40a5e4SMark Cave-Ayland         scsi_req_cancel(s->current_req);
305cf40a5e4SMark Cave-Ayland     }
306cf40a5e4SMark Cave-Ayland 
3076130b188SLaurent Vivier     s->current_dev = scsi_device_find(&s->bus, 0, target, 0);
3086130b188SLaurent Vivier     if (!s->current_dev) {
3096130b188SLaurent Vivier         /* No such drive */
3106130b188SLaurent Vivier         s->rregs[ESP_RSTAT] = 0;
311cf1a7a9bSMark Cave-Ayland         s->rregs[ESP_RINTR] = INTR_DC;
3126130b188SLaurent Vivier         esp_raise_irq(s);
3136130b188SLaurent Vivier         return -1;
3146130b188SLaurent Vivier     }
3154e78f3bfSMark Cave-Ayland 
3164e78f3bfSMark Cave-Ayland     /*
3174e78f3bfSMark Cave-Ayland      * Note that we deliberately don't raise the IRQ here: this will be done
318c90b2792SMark Cave-Ayland      * either in esp_transfer_data() or esp_command_complete()
3194e78f3bfSMark Cave-Ayland      */
3206130b188SLaurent Vivier     return 0;
3216130b188SLaurent Vivier }
3226130b188SLaurent Vivier 
3233ee9a475SMark Cave-Ayland static void esp_do_dma(ESPState *s);
3243ee9a475SMark Cave-Ayland static void esp_do_nodma(ESPState *s);
3253ee9a475SMark Cave-Ayland 
3264eb86065SPaolo Bonzini static void do_command_phase(ESPState *s)
3279f149aa9Spbrook {
3287b320a8eSMark Cave-Ayland     uint32_t cmdlen;
3299f149aa9Spbrook     int32_t datalen;
330f48a7a6eSPaolo Bonzini     SCSIDevice *current_lun;
3317b320a8eSMark Cave-Ayland     uint8_t buf[ESP_CMDFIFO_SZ];
3329f149aa9Spbrook 
3334eb86065SPaolo Bonzini     trace_esp_do_command_phase(s->lun);
334023666daSMark Cave-Ayland     cmdlen = fifo8_num_used(&s->cmdfifo);
33599545751SMark Cave-Ayland     if (!cmdlen || !s->current_dev) {
33699545751SMark Cave-Ayland         return;
33799545751SMark Cave-Ayland     }
338f87d0487SMark Cave-Ayland     esp_fifo8_pop_buf(&s->cmdfifo, buf, cmdlen);
339023666daSMark Cave-Ayland 
3404eb86065SPaolo Bonzini     current_lun = scsi_device_find(&s->bus, 0, s->current_dev->id, s->lun);
341b22f83d8SAlexandra Diupina     if (!current_lun) {
342b22f83d8SAlexandra Diupina         /* No such drive */
343b22f83d8SAlexandra Diupina         s->rregs[ESP_RSTAT] = 0;
344b22f83d8SAlexandra Diupina         s->rregs[ESP_RINTR] = INTR_DC;
345b22f83d8SAlexandra Diupina         s->rregs[ESP_RSEQ] = SEQ_0;
346b22f83d8SAlexandra Diupina         esp_raise_irq(s);
347b22f83d8SAlexandra Diupina         return;
348b22f83d8SAlexandra Diupina     }
349b22f83d8SAlexandra Diupina 
350fe9d8927SJohn Millikin     s->current_req = scsi_req_new(current_lun, 0, s->lun, buf, cmdlen, s);
351c39ce112SPaolo Bonzini     datalen = scsi_req_enqueue(s->current_req);
35267e999beSbellard     s->ti_size = datalen;
353023666daSMark Cave-Ayland     fifo8_reset(&s->cmdfifo);
354c90b2792SMark Cave-Ayland     s->data_ready = false;
35567e999beSbellard     if (datalen != 0) {
3564e78f3bfSMark Cave-Ayland         /*
357c90b2792SMark Cave-Ayland          * Switch to DATA phase but wait until initial data xfer is
3584e78f3bfSMark Cave-Ayland          * complete before raising the command completion interrupt
3594e78f3bfSMark Cave-Ayland          */
360c90b2792SMark Cave-Ayland         if (datalen > 0) {
361abc139cdSMark Cave-Ayland             esp_set_phase(s, STAT_DI);
3624f6200f0Sbellard         } else {
363abc139cdSMark Cave-Ayland             esp_set_phase(s, STAT_DO);
3642f275b8fSbellard         }
3654e78f3bfSMark Cave-Ayland         scsi_req_continue(s->current_req);
3664e78f3bfSMark Cave-Ayland         return;
3674e78f3bfSMark Cave-Ayland     }
3684e78f3bfSMark Cave-Ayland }
3692f275b8fSbellard 
3704eb86065SPaolo Bonzini static void do_message_phase(ESPState *s)
371f2818f22SArtyom Tarasenko {
3724eb86065SPaolo Bonzini     if (s->cmdfifo_cdb_offset) {
3731828000bSMark Cave-Ayland         uint8_t message = fifo8_is_empty(&s->cmdfifo) ? 0 :
3741828000bSMark Cave-Ayland                           fifo8_pop(&s->cmdfifo);
375023666daSMark Cave-Ayland 
3764eb86065SPaolo Bonzini         trace_esp_do_identify(message);
3774eb86065SPaolo Bonzini         s->lun = message & 7;
378023666daSMark Cave-Ayland         s->cmdfifo_cdb_offset--;
3794eb86065SPaolo Bonzini     }
380f2818f22SArtyom Tarasenko 
381799d90d8SMark Cave-Ayland     /* Ignore extended messages for now */
382023666daSMark Cave-Ayland     if (s->cmdfifo_cdb_offset) {
3834eb86065SPaolo Bonzini         int len = MIN(s->cmdfifo_cdb_offset, fifo8_num_used(&s->cmdfifo));
3842260402bSMark Cave-Ayland         esp_fifo8_pop_buf(&s->cmdfifo, NULL, len);
385023666daSMark Cave-Ayland         s->cmdfifo_cdb_offset = 0;
386023666daSMark Cave-Ayland     }
3874eb86065SPaolo Bonzini }
388023666daSMark Cave-Ayland 
3894eb86065SPaolo Bonzini static void do_cmd(ESPState *s)
3904eb86065SPaolo Bonzini {
3914eb86065SPaolo Bonzini     do_message_phase(s);
3924eb86065SPaolo Bonzini     assert(s->cmdfifo_cdb_offset == 0);
3934eb86065SPaolo Bonzini     do_command_phase(s);
394f2818f22SArtyom Tarasenko }
395f2818f22SArtyom Tarasenko 
3969f149aa9Spbrook static void handle_satn(ESPState *s)
3979f149aa9Spbrook {
3981b26eaa1SHervé Poussineau     if (s->dma && !s->dma_enabled) {
39973d74342SBlue Swirl         s->dma_cb = handle_satn;
40073d74342SBlue Swirl         return;
40173d74342SBlue Swirl     }
402b46a43a2SMark Cave-Ayland 
4031bcaf71bSMark Cave-Ayland     if (esp_select(s) < 0) {
4041bcaf71bSMark Cave-Ayland         return;
4051bcaf71bSMark Cave-Ayland     }
4063ee9a475SMark Cave-Ayland 
4073ee9a475SMark Cave-Ayland     esp_set_phase(s, STAT_MO);
4083ee9a475SMark Cave-Ayland 
4093ee9a475SMark Cave-Ayland     if (s->dma) {
4103ee9a475SMark Cave-Ayland         esp_do_dma(s);
4113ee9a475SMark Cave-Ayland     } else {
412d39592ffSMark Cave-Ayland         esp_do_nodma(s);
4139f149aa9Spbrook     }
41494d5c79dSMark Cave-Ayland }
4159f149aa9Spbrook 
416f2818f22SArtyom Tarasenko static void handle_s_without_atn(ESPState *s)
417f2818f22SArtyom Tarasenko {
4181b26eaa1SHervé Poussineau     if (s->dma && !s->dma_enabled) {
41973d74342SBlue Swirl         s->dma_cb = handle_s_without_atn;
42073d74342SBlue Swirl         return;
42173d74342SBlue Swirl     }
422b46a43a2SMark Cave-Ayland 
4231bcaf71bSMark Cave-Ayland     if (esp_select(s) < 0) {
4241bcaf71bSMark Cave-Ayland         return;
4251bcaf71bSMark Cave-Ayland     }
4269ff0fd12SMark Cave-Ayland 
427abc139cdSMark Cave-Ayland     esp_set_phase(s, STAT_CD);
4289ff0fd12SMark Cave-Ayland     s->cmdfifo_cdb_offset = 0;
4299ff0fd12SMark Cave-Ayland 
4309ff0fd12SMark Cave-Ayland     if (s->dma) {
4319ff0fd12SMark Cave-Ayland         esp_do_dma(s);
4329ff0fd12SMark Cave-Ayland     } else {
433d39592ffSMark Cave-Ayland         esp_do_nodma(s);
434f2818f22SArtyom Tarasenko     }
435f2818f22SArtyom Tarasenko }
436f2818f22SArtyom Tarasenko 
4379f149aa9Spbrook static void handle_satn_stop(ESPState *s)
4389f149aa9Spbrook {
4391b26eaa1SHervé Poussineau     if (s->dma && !s->dma_enabled) {
44073d74342SBlue Swirl         s->dma_cb = handle_satn_stop;
44173d74342SBlue Swirl         return;
44273d74342SBlue Swirl     }
443b46a43a2SMark Cave-Ayland 
4441bcaf71bSMark Cave-Ayland     if (esp_select(s) < 0) {
4451bcaf71bSMark Cave-Ayland         return;
4461bcaf71bSMark Cave-Ayland     }
447db4d4150SMark Cave-Ayland 
448abc139cdSMark Cave-Ayland     esp_set_phase(s, STAT_MO);
4495d02add4SMark Cave-Ayland     s->cmdfifo_cdb_offset = 0;
450db4d4150SMark Cave-Ayland 
451db4d4150SMark Cave-Ayland     if (s->dma) {
452db4d4150SMark Cave-Ayland         esp_do_dma(s);
453db4d4150SMark Cave-Ayland     } else {
454d39592ffSMark Cave-Ayland         esp_do_nodma(s);
4559f149aa9Spbrook     }
4569f149aa9Spbrook }
4579f149aa9Spbrook 
458a6cad7cdSMark Cave-Ayland static void handle_pad(ESPState *s)
459a6cad7cdSMark Cave-Ayland {
460a6cad7cdSMark Cave-Ayland     if (s->dma) {
461a6cad7cdSMark Cave-Ayland         esp_do_dma(s);
462a6cad7cdSMark Cave-Ayland     } else {
463a6cad7cdSMark Cave-Ayland         esp_do_nodma(s);
464a6cad7cdSMark Cave-Ayland     }
465a6cad7cdSMark Cave-Ayland }
466a6cad7cdSMark Cave-Ayland 
4670fc5c15aSpbrook static void write_response(ESPState *s)
4682f275b8fSbellard {
469bf4b9889SBlue Swirl     trace_esp_write_response(s->status);
470042879fcSMark Cave-Ayland 
4718baa1472SMark Cave-Ayland     if (s->dma) {
4728baa1472SMark Cave-Ayland         esp_do_dma(s);
4738baa1472SMark Cave-Ayland     } else {
47483428f7aSMark Cave-Ayland         esp_do_nodma(s);
4752f275b8fSbellard     }
4768baa1472SMark Cave-Ayland }
4774f6200f0Sbellard 
4785aa0df40SMark Cave-Ayland static bool esp_cdb_ready(ESPState *s)
4795d02add4SMark Cave-Ayland {
4805aa0df40SMark Cave-Ayland     int len = fifo8_num_used(&s->cmdfifo) - s->cmdfifo_cdb_offset;
4815d02add4SMark Cave-Ayland     const uint8_t *pbuf;
4823cc70889SMark Cave-Ayland     uint32_t n;
4835aa0df40SMark Cave-Ayland     int cdblen;
4845d02add4SMark Cave-Ayland 
4855aa0df40SMark Cave-Ayland     if (len <= 0) {
4865aa0df40SMark Cave-Ayland         return false;
4875d02add4SMark Cave-Ayland     }
4885d02add4SMark Cave-Ayland 
4893cc70889SMark Cave-Ayland     pbuf = fifo8_peek_buf(&s->cmdfifo, len, &n);
4903cc70889SMark Cave-Ayland     if (n < len) {
4913cc70889SMark Cave-Ayland         /*
4923cc70889SMark Cave-Ayland          * In normal use the cmdfifo should never wrap, but include this check
4933cc70889SMark Cave-Ayland          * to prevent a malicious guest from reading past the end of the
4943cc70889SMark Cave-Ayland          * cmdfifo data buffer below
4953cc70889SMark Cave-Ayland          */
4963cc70889SMark Cave-Ayland         return false;
4973cc70889SMark Cave-Ayland     }
4983cc70889SMark Cave-Ayland 
4995aa0df40SMark Cave-Ayland     cdblen = scsi_cdb_length((uint8_t *)&pbuf[s->cmdfifo_cdb_offset]);
5005d02add4SMark Cave-Ayland 
5015aa0df40SMark Cave-Ayland     return cdblen < 0 ? false : (len >= cdblen);
5025d02add4SMark Cave-Ayland }
5035d02add4SMark Cave-Ayland 
504004826d0SMark Cave-Ayland static void esp_dma_ti_check(ESPState *s)
5054d611c9aSpbrook {
506af74b3c1SMark Cave-Ayland     if (esp_get_tc(s) == 0 && fifo8_num_used(&s->fifo) < 2) {
507cf47a41eSMark Cave-Ayland         s->rregs[ESP_RINTR] |= INTR_BS;
508c73f96fdSblueswir1         esp_raise_irq(s);
509af74b3c1SMark Cave-Ayland     }
5104d611c9aSpbrook }
511a917d384Spbrook 
512a917d384Spbrook static void esp_do_dma(ESPState *s)
513a917d384Spbrook {
514023666daSMark Cave-Ayland     uint32_t len, cmdlen;
515023666daSMark Cave-Ayland     uint8_t buf[ESP_CMDFIFO_SZ];
516a917d384Spbrook 
5176cc88d6bSMark Cave-Ayland     len = esp_get_tc(s);
518ad2725afSMark Cave-Ayland 
519ad2725afSMark Cave-Ayland     switch (esp_get_phase(s)) {
520ad2725afSMark Cave-Ayland     case STAT_MO:
52146b0c361SMark Cave-Ayland         if (s->dma_memory_read) {
52246b0c361SMark Cave-Ayland             len = MIN(len, fifo8_num_free(&s->cmdfifo));
52346b0c361SMark Cave-Ayland             s->dma_memory_read(s->dma_opaque, buf, len);
52446b0c361SMark Cave-Ayland             esp_set_tc(s, esp_get_tc(s) - len);
52546b0c361SMark Cave-Ayland         } else {
526da838126SMark Cave-Ayland             len = esp_fifo_pop_buf(s, buf, fifo8_num_used(&s->fifo));
52767ea170eSMark Cave-Ayland             len = MIN(fifo8_num_free(&s->cmdfifo), len);
52846b0c361SMark Cave-Ayland         }
52946b0c361SMark Cave-Ayland 
53067ea170eSMark Cave-Ayland         fifo8_push_all(&s->cmdfifo, buf, len);
53167ea170eSMark Cave-Ayland         s->cmdfifo_cdb_offset += len;
53246b0c361SMark Cave-Ayland 
5333ee9a475SMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
5343ee9a475SMark Cave-Ayland         case CMD_SELATN | CMD_DMA:
5353ee9a475SMark Cave-Ayland             if (fifo8_num_used(&s->cmdfifo) >= 1) {
5363ee9a475SMark Cave-Ayland                 /* First byte received, switch to command phase */
5373ee9a475SMark Cave-Ayland                 esp_set_phase(s, STAT_CD);
5389b2cdca2SMark Cave-Ayland                 s->rregs[ESP_RSEQ] = SEQ_CD;
5393ee9a475SMark Cave-Ayland                 s->cmdfifo_cdb_offset = 1;
5403ee9a475SMark Cave-Ayland 
5413ee9a475SMark Cave-Ayland                 if (fifo8_num_used(&s->cmdfifo) > 1) {
5423ee9a475SMark Cave-Ayland                     /* Process any additional command phase data */
5433ee9a475SMark Cave-Ayland                     esp_do_dma(s);
5443ee9a475SMark Cave-Ayland                 }
5453ee9a475SMark Cave-Ayland             }
5463ee9a475SMark Cave-Ayland             break;
5473ee9a475SMark Cave-Ayland 
548db4d4150SMark Cave-Ayland         case CMD_SELATNS | CMD_DMA:
549db4d4150SMark Cave-Ayland             if (fifo8_num_used(&s->cmdfifo) == 1) {
550db4d4150SMark Cave-Ayland                 /* First byte received, stop in message out phase */
5519b2cdca2SMark Cave-Ayland                 s->rregs[ESP_RSEQ] = SEQ_MO;
552db4d4150SMark Cave-Ayland                 s->cmdfifo_cdb_offset = 1;
553db4d4150SMark Cave-Ayland 
554db4d4150SMark Cave-Ayland                 /* Raise command completion interrupt */
555db4d4150SMark Cave-Ayland                 s->rregs[ESP_RINTR] |= INTR_BS | INTR_FC;
556db4d4150SMark Cave-Ayland                 esp_raise_irq(s);
557db4d4150SMark Cave-Ayland             }
558db4d4150SMark Cave-Ayland             break;
559db4d4150SMark Cave-Ayland 
5603fd325a2SMark Cave-Ayland         case CMD_TI | CMD_DMA:
56146b0c361SMark Cave-Ayland             /* ATN remains asserted until TC == 0 */
56246b0c361SMark Cave-Ayland             if (esp_get_tc(s) == 0) {
56346b0c361SMark Cave-Ayland                 esp_set_phase(s, STAT_CD);
564cb22ce50SMark Cave-Ayland                 s->rregs[ESP_CMD] = 0;
56546b0c361SMark Cave-Ayland                 s->rregs[ESP_RINTR] |= INTR_BS;
56646b0c361SMark Cave-Ayland                 esp_raise_irq(s);
56746b0c361SMark Cave-Ayland             }
56846b0c361SMark Cave-Ayland             break;
5693fd325a2SMark Cave-Ayland         }
5703fd325a2SMark Cave-Ayland         break;
57146b0c361SMark Cave-Ayland 
572ad2725afSMark Cave-Ayland     case STAT_CD:
573023666daSMark Cave-Ayland         cmdlen = fifo8_num_used(&s->cmdfifo);
574023666daSMark Cave-Ayland         trace_esp_do_dma(cmdlen, len);
57574d71ea1SLaurent Vivier         if (s->dma_memory_read) {
5760ebb5fd8SMark Cave-Ayland             len = MIN(len, fifo8_num_free(&s->cmdfifo));
577023666daSMark Cave-Ayland             s->dma_memory_read(s->dma_opaque, buf, len);
578023666daSMark Cave-Ayland             fifo8_push_all(&s->cmdfifo, buf, len);
579a0347651SMark Cave-Ayland             esp_set_tc(s, esp_get_tc(s) - len);
58074d71ea1SLaurent Vivier         } else {
581da838126SMark Cave-Ayland             len = esp_fifo_pop_buf(s, buf, fifo8_num_used(&s->fifo));
582406e8a3eSMark Cave-Ayland             len = MIN(fifo8_num_free(&s->cmdfifo), len);
583406e8a3eSMark Cave-Ayland             fifo8_push_all(&s->cmdfifo, buf, len);
5843c7f3c8bSMark Cave-Ayland         }
585023666daSMark Cave-Ayland         trace_esp_handle_ti_cmd(cmdlen);
58615407433SLaurent Vivier         s->ti_size = 0;
58746b0c361SMark Cave-Ayland         if (esp_get_tc(s) == 0) {
588799d90d8SMark Cave-Ayland             /* Command has been received */
589c959f218SMark Cave-Ayland             do_cmd(s);
590799d90d8SMark Cave-Ayland         }
591ad2725afSMark Cave-Ayland         break;
5921454dc76SMark Cave-Ayland 
5931454dc76SMark Cave-Ayland     case STAT_DO:
5940db89536SMark Cave-Ayland         if (!s->current_req) {
5950db89536SMark Cave-Ayland             return;
5960db89536SMark Cave-Ayland         }
597*dfaf55a1SMark Cave-Ayland         if (s->async_len == 0 && esp_get_tc(s)) {
598a917d384Spbrook             /* Defer until data is available.  */
599a917d384Spbrook             return;
600a917d384Spbrook         }
601a917d384Spbrook         if (len > s->async_len) {
602a917d384Spbrook             len = s->async_len;
603a917d384Spbrook         }
6040d17ce82SMark Cave-Ayland 
605a6cad7cdSMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
606a6cad7cdSMark Cave-Ayland         case CMD_TI | CMD_DMA:
60774d71ea1SLaurent Vivier             if (s->dma_memory_read) {
6088b17de88Sblueswir1                 s->dma_memory_read(s->dma_opaque, s->async_buf, len);
609f3666223SMark Cave-Ayland                 esp_set_tc(s, esp_get_tc(s) - len);
6100d17ce82SMark Cave-Ayland             } else {
6110d17ce82SMark Cave-Ayland                 /* Copy FIFO data to device */
6120d17ce82SMark Cave-Ayland                 len = MIN(s->async_len, ESP_FIFO_SZ);
6130d17ce82SMark Cave-Ayland                 len = MIN(len, fifo8_num_used(&s->fifo));
614da838126SMark Cave-Ayland                 len = esp_fifo_pop_buf(s, s->async_buf, len);
6150d17ce82SMark Cave-Ayland             }
6160d17ce82SMark Cave-Ayland 
617f3666223SMark Cave-Ayland             s->async_buf += len;
618f3666223SMark Cave-Ayland             s->async_len -= len;
619f3666223SMark Cave-Ayland             s->ti_size += len;
620a6cad7cdSMark Cave-Ayland             break;
621a6cad7cdSMark Cave-Ayland 
622a6cad7cdSMark Cave-Ayland         case CMD_PAD | CMD_DMA:
623a6cad7cdSMark Cave-Ayland             /* Copy TC zero bytes into the incoming stream */
624a6cad7cdSMark Cave-Ayland             if (!s->dma_memory_read) {
625a6cad7cdSMark Cave-Ayland                 len = MIN(s->async_len, ESP_FIFO_SZ);
626a6cad7cdSMark Cave-Ayland                 len = MIN(len, fifo8_num_free(&s->fifo));
627a6cad7cdSMark Cave-Ayland             }
628a6cad7cdSMark Cave-Ayland 
629a6cad7cdSMark Cave-Ayland             memset(s->async_buf, 0, len);
630a6cad7cdSMark Cave-Ayland 
631a6cad7cdSMark Cave-Ayland             s->async_buf += len;
632a6cad7cdSMark Cave-Ayland             s->async_len -= len;
633a6cad7cdSMark Cave-Ayland             s->ti_size += len;
634a6cad7cdSMark Cave-Ayland             break;
635a6cad7cdSMark Cave-Ayland         }
636f3666223SMark Cave-Ayland 
637e4e166c8SMark Cave-Ayland         if (s->async_len == 0 && fifo8_num_used(&s->fifo) < 2) {
638e4e166c8SMark Cave-Ayland             /* Defer until the scsi layer has completed */
639f3666223SMark Cave-Ayland             scsi_req_continue(s->current_req);
640f3666223SMark Cave-Ayland             return;
641f3666223SMark Cave-Ayland         }
642f3666223SMark Cave-Ayland 
643004826d0SMark Cave-Ayland         esp_dma_ti_check(s);
6441454dc76SMark Cave-Ayland         break;
6451454dc76SMark Cave-Ayland 
6461454dc76SMark Cave-Ayland     case STAT_DI:
6471454dc76SMark Cave-Ayland         if (!s->current_req) {
6481454dc76SMark Cave-Ayland             return;
6491454dc76SMark Cave-Ayland         }
650*dfaf55a1SMark Cave-Ayland         if (s->async_len == 0 && esp_get_tc(s)) {
6511454dc76SMark Cave-Ayland             /* Defer until data is available.  */
6521454dc76SMark Cave-Ayland             return;
6531454dc76SMark Cave-Ayland         }
6541454dc76SMark Cave-Ayland         if (len > s->async_len) {
6551454dc76SMark Cave-Ayland             len = s->async_len;
6561454dc76SMark Cave-Ayland         }
657c37cc88eSMark Cave-Ayland 
658a6cad7cdSMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
659a6cad7cdSMark Cave-Ayland         case CMD_TI | CMD_DMA:
66074d71ea1SLaurent Vivier             if (s->dma_memory_write) {
6618b17de88Sblueswir1                 s->dma_memory_write(s->dma_opaque, s->async_buf, len);
66274d71ea1SLaurent Vivier             } else {
66382141c8bSMark Cave-Ayland                 /* Copy device data to FIFO */
664042879fcSMark Cave-Ayland                 len = MIN(len, fifo8_num_free(&s->fifo));
665266170f9SMark Cave-Ayland                 esp_fifo_push_buf(s, s->async_buf, len);
666c37cc88eSMark Cave-Ayland             }
667c37cc88eSMark Cave-Ayland 
66882141c8bSMark Cave-Ayland             s->async_buf += len;
66982141c8bSMark Cave-Ayland             s->async_len -= len;
67082141c8bSMark Cave-Ayland             s->ti_size -= len;
67182141c8bSMark Cave-Ayland             esp_set_tc(s, esp_get_tc(s) - len);
672a6cad7cdSMark Cave-Ayland             break;
673a6cad7cdSMark Cave-Ayland 
674a6cad7cdSMark Cave-Ayland         case CMD_PAD | CMD_DMA:
675a6cad7cdSMark Cave-Ayland             /* Drop TC bytes from the incoming stream */
676a6cad7cdSMark Cave-Ayland             if (!s->dma_memory_write) {
677a6cad7cdSMark Cave-Ayland                 len = MIN(len, fifo8_num_free(&s->fifo));
678a6cad7cdSMark Cave-Ayland             }
679a6cad7cdSMark Cave-Ayland 
680a6cad7cdSMark Cave-Ayland             s->async_buf += len;
681a6cad7cdSMark Cave-Ayland             s->async_len -= len;
682a6cad7cdSMark Cave-Ayland             s->ti_size -= len;
683a6cad7cdSMark Cave-Ayland             esp_set_tc(s, esp_get_tc(s) - len);
684a6cad7cdSMark Cave-Ayland             break;
685a6cad7cdSMark Cave-Ayland         }
686e4e166c8SMark Cave-Ayland 
68702a3ce56SMark Cave-Ayland         if (s->async_len == 0 && s->ti_size == 0 && esp_get_tc(s)) {
68802a3ce56SMark Cave-Ayland             /* If the guest underflows TC then terminate SCSI request */
68902a3ce56SMark Cave-Ayland             scsi_req_continue(s->current_req);
69002a3ce56SMark Cave-Ayland             return;
69102a3ce56SMark Cave-Ayland         }
69202a3ce56SMark Cave-Ayland 
693e4e166c8SMark Cave-Ayland         if (s->async_len == 0 && fifo8_num_used(&s->fifo) < 2) {
694e4e166c8SMark Cave-Ayland             /* Defer until the scsi layer has completed */
695e4e166c8SMark Cave-Ayland             scsi_req_continue(s->current_req);
696e4e166c8SMark Cave-Ayland             return;
697e4e166c8SMark Cave-Ayland         }
698e4e166c8SMark Cave-Ayland 
699004826d0SMark Cave-Ayland         esp_dma_ti_check(s);
7001454dc76SMark Cave-Ayland         break;
7018baa1472SMark Cave-Ayland 
7028baa1472SMark Cave-Ayland     case STAT_ST:
7038baa1472SMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
7048baa1472SMark Cave-Ayland         case CMD_ICCS | CMD_DMA:
7058baa1472SMark Cave-Ayland             len = MIN(len, 1);
7068baa1472SMark Cave-Ayland 
7078baa1472SMark Cave-Ayland             if (len) {
7088baa1472SMark Cave-Ayland                 buf[0] = s->status;
7098baa1472SMark Cave-Ayland 
7108baa1472SMark Cave-Ayland                 if (s->dma_memory_write) {
7118baa1472SMark Cave-Ayland                     s->dma_memory_write(s->dma_opaque, buf, len);
7128baa1472SMark Cave-Ayland                 } else {
713266170f9SMark Cave-Ayland                     esp_fifo_push_buf(s, buf, len);
7148baa1472SMark Cave-Ayland                 }
7158baa1472SMark Cave-Ayland 
716421d1ca5SMark Cave-Ayland                 esp_set_tc(s, esp_get_tc(s) - len);
7178baa1472SMark Cave-Ayland                 esp_set_phase(s, STAT_MI);
7188baa1472SMark Cave-Ayland 
7198baa1472SMark Cave-Ayland                 if (esp_get_tc(s) > 0) {
7208baa1472SMark Cave-Ayland                     /* Process any message in phase data */
7218baa1472SMark Cave-Ayland                     esp_do_dma(s);
7228baa1472SMark Cave-Ayland                 }
7238baa1472SMark Cave-Ayland             }
7248baa1472SMark Cave-Ayland             break;
72502a3ce56SMark Cave-Ayland 
72602a3ce56SMark Cave-Ayland         default:
72702a3ce56SMark Cave-Ayland             /* Consume remaining data if the guest underflows TC */
72802a3ce56SMark Cave-Ayland             if (fifo8_num_used(&s->fifo) < 2) {
72902a3ce56SMark Cave-Ayland                 s->rregs[ESP_RINTR] |= INTR_BS;
73002a3ce56SMark Cave-Ayland                 esp_raise_irq(s);
73102a3ce56SMark Cave-Ayland             }
73202a3ce56SMark Cave-Ayland             break;
7338baa1472SMark Cave-Ayland         }
7348baa1472SMark Cave-Ayland         break;
7358baa1472SMark Cave-Ayland 
7368baa1472SMark Cave-Ayland     case STAT_MI:
7378baa1472SMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
7388baa1472SMark Cave-Ayland         case CMD_ICCS | CMD_DMA:
7398baa1472SMark Cave-Ayland             len = MIN(len, 1);
7408baa1472SMark Cave-Ayland 
7418baa1472SMark Cave-Ayland             if (len) {
7428baa1472SMark Cave-Ayland                 buf[0] = 0;
7438baa1472SMark Cave-Ayland 
7448baa1472SMark Cave-Ayland                 if (s->dma_memory_write) {
7458baa1472SMark Cave-Ayland                     s->dma_memory_write(s->dma_opaque, buf, len);
7468baa1472SMark Cave-Ayland                 } else {
747266170f9SMark Cave-Ayland                     esp_fifo_push_buf(s, buf, len);
7488baa1472SMark Cave-Ayland                 }
7498baa1472SMark Cave-Ayland 
750421d1ca5SMark Cave-Ayland                 esp_set_tc(s, esp_get_tc(s) - len);
751421d1ca5SMark Cave-Ayland 
7528baa1472SMark Cave-Ayland                 /* Raise end of command interrupt */
7530ee71db4SMark Cave-Ayland                 s->rregs[ESP_RINTR] |= INTR_FC;
7548baa1472SMark Cave-Ayland                 esp_raise_irq(s);
7558baa1472SMark Cave-Ayland             }
7568baa1472SMark Cave-Ayland             break;
7578baa1472SMark Cave-Ayland         }
7588baa1472SMark Cave-Ayland         break;
75974d71ea1SLaurent Vivier     }
760a917d384Spbrook }
761a917d384Spbrook 
762a1b8d389SMark Cave-Ayland static void esp_nodma_ti_dataout(ESPState *s)
763a1b8d389SMark Cave-Ayland {
764a1b8d389SMark Cave-Ayland     int len;
765a1b8d389SMark Cave-Ayland 
766a1b8d389SMark Cave-Ayland     if (!s->current_req) {
767a1b8d389SMark Cave-Ayland         return;
768a1b8d389SMark Cave-Ayland     }
769a1b8d389SMark Cave-Ayland     if (s->async_len == 0) {
770a1b8d389SMark Cave-Ayland         /* Defer until data is available.  */
771a1b8d389SMark Cave-Ayland         return;
772a1b8d389SMark Cave-Ayland     }
773a1b8d389SMark Cave-Ayland     len = MIN(s->async_len, ESP_FIFO_SZ);
774a1b8d389SMark Cave-Ayland     len = MIN(len, fifo8_num_used(&s->fifo));
775da838126SMark Cave-Ayland     esp_fifo_pop_buf(s, s->async_buf, len);
776a1b8d389SMark Cave-Ayland     s->async_buf += len;
777a1b8d389SMark Cave-Ayland     s->async_len -= len;
778a1b8d389SMark Cave-Ayland     s->ti_size += len;
779a1b8d389SMark Cave-Ayland 
780a1b8d389SMark Cave-Ayland     if (s->async_len == 0) {
781a1b8d389SMark Cave-Ayland         scsi_req_continue(s->current_req);
782a1b8d389SMark Cave-Ayland         return;
783a1b8d389SMark Cave-Ayland     }
784a1b8d389SMark Cave-Ayland 
785a1b8d389SMark Cave-Ayland     s->rregs[ESP_RINTR] |= INTR_BS;
786a1b8d389SMark Cave-Ayland     esp_raise_irq(s);
787a1b8d389SMark Cave-Ayland }
788a1b8d389SMark Cave-Ayland 
7891b9e48a5SMark Cave-Ayland static void esp_do_nodma(ESPState *s)
7901b9e48a5SMark Cave-Ayland {
7912572689bSMark Cave-Ayland     uint8_t buf[ESP_FIFO_SZ];
7927b320a8eSMark Cave-Ayland     uint32_t cmdlen;
7935a857339SMark Cave-Ayland     int len;
7941b9e48a5SMark Cave-Ayland 
79583e803deSMark Cave-Ayland     switch (esp_get_phase(s)) {
79683e803deSMark Cave-Ayland     case STAT_MO:
797215d2579SMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
798215d2579SMark Cave-Ayland         case CMD_SELATN:
7992572689bSMark Cave-Ayland             /* Copy FIFO into cmdfifo */
800da838126SMark Cave-Ayland             len = esp_fifo_pop_buf(s, buf, fifo8_num_used(&s->fifo));
8015a857339SMark Cave-Ayland             len = MIN(fifo8_num_free(&s->cmdfifo), len);
8025a857339SMark Cave-Ayland             fifo8_push_all(&s->cmdfifo, buf, len);
8032572689bSMark Cave-Ayland 
8045d02add4SMark Cave-Ayland             if (fifo8_num_used(&s->cmdfifo) >= 1) {
8055d02add4SMark Cave-Ayland                 /* First byte received, switch to command phase */
8065d02add4SMark Cave-Ayland                 esp_set_phase(s, STAT_CD);
8079b2cdca2SMark Cave-Ayland                 s->rregs[ESP_RSEQ] = SEQ_CD;
8085d02add4SMark Cave-Ayland                 s->cmdfifo_cdb_offset = 1;
8095d02add4SMark Cave-Ayland 
8105d02add4SMark Cave-Ayland                 if (fifo8_num_used(&s->cmdfifo) > 1) {
8115d02add4SMark Cave-Ayland                     /* Process any additional command phase data */
8125d02add4SMark Cave-Ayland                     esp_do_nodma(s);
8135d02add4SMark Cave-Ayland                 }
8145d02add4SMark Cave-Ayland             }
8155d02add4SMark Cave-Ayland             break;
8165d02add4SMark Cave-Ayland 
8175d02add4SMark Cave-Ayland         case CMD_SELATNS:
818215d2579SMark Cave-Ayland             /* Copy one byte from FIFO into cmdfifo */
8195a50644eSMark Cave-Ayland             len = esp_fifo_pop_buf(s, buf,
8205a50644eSMark Cave-Ayland                                    MIN(fifo8_num_used(&s->fifo), 1));
8215a857339SMark Cave-Ayland             len = MIN(fifo8_num_free(&s->cmdfifo), len);
8225a857339SMark Cave-Ayland             fifo8_push_all(&s->cmdfifo, buf, len);
823215d2579SMark Cave-Ayland 
824d39592ffSMark Cave-Ayland             if (fifo8_num_used(&s->cmdfifo) >= 1) {
8255d02add4SMark Cave-Ayland                 /* First byte received, stop in message out phase */
8269b2cdca2SMark Cave-Ayland                 s->rregs[ESP_RSEQ] = SEQ_MO;
8275d02add4SMark Cave-Ayland                 s->cmdfifo_cdb_offset = 1;
8285d02add4SMark Cave-Ayland 
8295d02add4SMark Cave-Ayland                 /* Raise command completion interrupt */
8305d02add4SMark Cave-Ayland                 s->rregs[ESP_RINTR] |= INTR_BS | INTR_FC;
8315d02add4SMark Cave-Ayland                 esp_raise_irq(s);
8325d02add4SMark Cave-Ayland             }
8335d02add4SMark Cave-Ayland             break;
8345d02add4SMark Cave-Ayland 
8355d02add4SMark Cave-Ayland         case CMD_TI:
836215d2579SMark Cave-Ayland             /* Copy FIFO into cmdfifo */
837da838126SMark Cave-Ayland             len = esp_fifo_pop_buf(s, buf, fifo8_num_used(&s->fifo));
8385a857339SMark Cave-Ayland             len = MIN(fifo8_num_free(&s->cmdfifo), len);
8395a857339SMark Cave-Ayland             fifo8_push_all(&s->cmdfifo, buf, len);
840215d2579SMark Cave-Ayland 
8415d02add4SMark Cave-Ayland             /* ATN remains asserted until FIFO empty */
8421b9e48a5SMark Cave-Ayland             s->cmdfifo_cdb_offset = fifo8_num_used(&s->cmdfifo);
843abc139cdSMark Cave-Ayland             esp_set_phase(s, STAT_CD);
844cb22ce50SMark Cave-Ayland             s->rregs[ESP_CMD] = 0;
8451b9e48a5SMark Cave-Ayland             s->rregs[ESP_RINTR] |= INTR_BS;
8461b9e48a5SMark Cave-Ayland             esp_raise_irq(s);
84779a6c7c6SMark Cave-Ayland             break;
8485d02add4SMark Cave-Ayland         }
8495d02add4SMark Cave-Ayland         break;
85079a6c7c6SMark Cave-Ayland 
85179a6c7c6SMark Cave-Ayland     case STAT_CD:
852acdee66dSMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
853acdee66dSMark Cave-Ayland         case CMD_TI:
85479a6c7c6SMark Cave-Ayland             /* Copy FIFO into cmdfifo */
855da838126SMark Cave-Ayland             len = esp_fifo_pop_buf(s, buf, fifo8_num_used(&s->fifo));
8565a857339SMark Cave-Ayland             len = MIN(fifo8_num_free(&s->cmdfifo), len);
8575a857339SMark Cave-Ayland             fifo8_push_all(&s->cmdfifo, buf, len);
85879a6c7c6SMark Cave-Ayland 
85979a6c7c6SMark Cave-Ayland             cmdlen = fifo8_num_used(&s->cmdfifo);
86079a6c7c6SMark Cave-Ayland             trace_esp_handle_ti_cmd(cmdlen);
86179a6c7c6SMark Cave-Ayland 
8625d02add4SMark Cave-Ayland             /* CDB may be transferred in one or more TI commands */
8635aa0df40SMark Cave-Ayland             if (esp_cdb_ready(s)) {
86479a6c7c6SMark Cave-Ayland                 /* Command has been received */
86579a6c7c6SMark Cave-Ayland                 do_cmd(s);
8665d02add4SMark Cave-Ayland             } else {
8675d02add4SMark Cave-Ayland                 /*
8685d02add4SMark Cave-Ayland                  * If data was transferred from the FIFO then raise bus
8695d02add4SMark Cave-Ayland                  * service interrupt to indicate transfer complete. Otherwise
8705d02add4SMark Cave-Ayland                  * defer until the next FIFO write.
8715d02add4SMark Cave-Ayland                  */
8725a857339SMark Cave-Ayland                 if (len) {
8735d02add4SMark Cave-Ayland                     /* Raise interrupt to indicate transfer complete */
8745d02add4SMark Cave-Ayland                     s->rregs[ESP_RINTR] |= INTR_BS;
8755d02add4SMark Cave-Ayland                     esp_raise_irq(s);
8765d02add4SMark Cave-Ayland                 }
8775d02add4SMark Cave-Ayland             }
8785d02add4SMark Cave-Ayland             break;
8795d02add4SMark Cave-Ayland 
8808ba32048SMark Cave-Ayland         case CMD_SEL | CMD_DMA:
8818ba32048SMark Cave-Ayland         case CMD_SELATN | CMD_DMA:
882acdee66dSMark Cave-Ayland             /* Copy FIFO into cmdfifo */
883da838126SMark Cave-Ayland             len = esp_fifo_pop_buf(s, buf, fifo8_num_used(&s->fifo));
8845a857339SMark Cave-Ayland             len = MIN(fifo8_num_free(&s->cmdfifo), len);
8855a857339SMark Cave-Ayland             fifo8_push_all(&s->cmdfifo, buf, len);
886acdee66dSMark Cave-Ayland 
8878ba32048SMark Cave-Ayland             /* Handle when DMA transfer is terminated by non-DMA FIFO write */
8885aa0df40SMark Cave-Ayland             if (esp_cdb_ready(s)) {
8898ba32048SMark Cave-Ayland                 /* Command has been received */
8908ba32048SMark Cave-Ayland                 do_cmd(s);
8918ba32048SMark Cave-Ayland             }
8928ba32048SMark Cave-Ayland             break;
8938ba32048SMark Cave-Ayland 
8945d02add4SMark Cave-Ayland         case CMD_SEL:
8955d02add4SMark Cave-Ayland         case CMD_SELATN:
896acdee66dSMark Cave-Ayland             /* FIFO already contain entire CDB: copy to cmdfifo and execute */
897da838126SMark Cave-Ayland             len = esp_fifo_pop_buf(s, buf, fifo8_num_used(&s->fifo));
8985a857339SMark Cave-Ayland             len = MIN(fifo8_num_free(&s->cmdfifo), len);
8995a857339SMark Cave-Ayland             fifo8_push_all(&s->cmdfifo, buf, len);
900acdee66dSMark Cave-Ayland 
9015d02add4SMark Cave-Ayland             do_cmd(s);
9025d02add4SMark Cave-Ayland             break;
9035d02add4SMark Cave-Ayland         }
90483e803deSMark Cave-Ayland         break;
9051b9e48a5SMark Cave-Ayland 
9069d1aa52bSMark Cave-Ayland     case STAT_DO:
9075d02add4SMark Cave-Ayland         /* Accumulate data in FIFO until non-DMA TI is executed */
9089d1aa52bSMark Cave-Ayland         break;
9099d1aa52bSMark Cave-Ayland 
9109d1aa52bSMark Cave-Ayland     case STAT_DI:
9119d1aa52bSMark Cave-Ayland         if (!s->current_req) {
9129d1aa52bSMark Cave-Ayland             return;
9139d1aa52bSMark Cave-Ayland         }
9149d1aa52bSMark Cave-Ayland         if (s->async_len == 0) {
9159d1aa52bSMark Cave-Ayland             /* Defer until data is available.  */
9169d1aa52bSMark Cave-Ayland             return;
9179d1aa52bSMark Cave-Ayland         }
9186ef2cabcSMark Cave-Ayland         if (fifo8_is_empty(&s->fifo)) {
9191f46d1c3SMark Cave-Ayland             esp_fifo_push(s, s->async_buf[0]);
9206ef2cabcSMark Cave-Ayland             s->async_buf++;
9216ef2cabcSMark Cave-Ayland             s->async_len--;
9226ef2cabcSMark Cave-Ayland             s->ti_size--;
9236ef2cabcSMark Cave-Ayland         }
9241b9e48a5SMark Cave-Ayland 
9251b9e48a5SMark Cave-Ayland         if (s->async_len == 0) {
9261b9e48a5SMark Cave-Ayland             scsi_req_continue(s->current_req);
9271b9e48a5SMark Cave-Ayland             return;
9281b9e48a5SMark Cave-Ayland         }
9291b9e48a5SMark Cave-Ayland 
9309655f72cSMark Cave-Ayland         /* If preloading the FIFO, defer until TI command issued */
9319655f72cSMark Cave-Ayland         if (s->rregs[ESP_CMD] != CMD_TI) {
9329655f72cSMark Cave-Ayland             return;
9339655f72cSMark Cave-Ayland         }
9349655f72cSMark Cave-Ayland 
9351b9e48a5SMark Cave-Ayland         s->rregs[ESP_RINTR] |= INTR_BS;
9361b9e48a5SMark Cave-Ayland         esp_raise_irq(s);
9379d1aa52bSMark Cave-Ayland         break;
93883428f7aSMark Cave-Ayland 
93983428f7aSMark Cave-Ayland     case STAT_ST:
94083428f7aSMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
94183428f7aSMark Cave-Ayland         case CMD_ICCS:
9421f46d1c3SMark Cave-Ayland             esp_fifo_push(s, s->status);
94383428f7aSMark Cave-Ayland             esp_set_phase(s, STAT_MI);
94483428f7aSMark Cave-Ayland 
94583428f7aSMark Cave-Ayland             /* Process any message in phase data */
94683428f7aSMark Cave-Ayland             esp_do_nodma(s);
94783428f7aSMark Cave-Ayland             break;
94883428f7aSMark Cave-Ayland         }
94983428f7aSMark Cave-Ayland         break;
95083428f7aSMark Cave-Ayland 
95183428f7aSMark Cave-Ayland     case STAT_MI:
95283428f7aSMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
95383428f7aSMark Cave-Ayland         case CMD_ICCS:
9541f46d1c3SMark Cave-Ayland             esp_fifo_push(s, 0);
95583428f7aSMark Cave-Ayland 
9560ee71db4SMark Cave-Ayland             /* Raise end of command interrupt */
9570ee71db4SMark Cave-Ayland             s->rregs[ESP_RINTR] |= INTR_FC;
95883428f7aSMark Cave-Ayland             esp_raise_irq(s);
95983428f7aSMark Cave-Ayland             break;
96083428f7aSMark Cave-Ayland         }
96183428f7aSMark Cave-Ayland         break;
9629d1aa52bSMark Cave-Ayland     }
9631b9e48a5SMark Cave-Ayland }
9641b9e48a5SMark Cave-Ayland 
9654aaa6ac3SMark Cave-Ayland void esp_command_complete(SCSIRequest *req, size_t resid)
966a917d384Spbrook {
9674aaa6ac3SMark Cave-Ayland     ESPState *s = req->hba_private;
9685a83e83eSMark Cave-Ayland     int to_device = (esp_get_phase(s) == STAT_DO);
9694aaa6ac3SMark Cave-Ayland 
970bf4b9889SBlue Swirl     trace_esp_command_complete();
9716ef2cabcSMark Cave-Ayland 
9726ef2cabcSMark Cave-Ayland     /*
9736ef2cabcSMark Cave-Ayland      * Non-DMA transfers from the target will leave the last byte in
9746ef2cabcSMark Cave-Ayland      * the FIFO so don't reset ti_size in this case
9756ef2cabcSMark Cave-Ayland      */
9766ef2cabcSMark Cave-Ayland     if (s->dma || to_device) {
977c6df7102SPaolo Bonzini         if (s->ti_size != 0) {
978bf4b9889SBlue Swirl             trace_esp_command_complete_unexpected();
979c6df7102SPaolo Bonzini         }
9806ef2cabcSMark Cave-Ayland     }
9816ef2cabcSMark Cave-Ayland 
982a917d384Spbrook     s->async_len = 0;
9834aaa6ac3SMark Cave-Ayland     if (req->status) {
984bf4b9889SBlue Swirl         trace_esp_command_complete_fail();
985c6df7102SPaolo Bonzini     }
9864aaa6ac3SMark Cave-Ayland     s->status = req->status;
9876ef2cabcSMark Cave-Ayland 
9886ef2cabcSMark Cave-Ayland     /*
989cb988199SMark Cave-Ayland      * Switch to status phase. For non-DMA transfers from the target the last
990cb988199SMark Cave-Ayland      * byte is still in the FIFO
9916ef2cabcSMark Cave-Ayland      */
9928bb22495SMark Cave-Ayland     s->ti_size = 0;
9938bb22495SMark Cave-Ayland 
9948bb22495SMark Cave-Ayland     switch (s->rregs[ESP_CMD]) {
9958bb22495SMark Cave-Ayland     case CMD_SEL | CMD_DMA:
9968bb22495SMark Cave-Ayland     case CMD_SEL:
9978bb22495SMark Cave-Ayland     case CMD_SELATN | CMD_DMA:
9988bb22495SMark Cave-Ayland     case CMD_SELATN:
999cb988199SMark Cave-Ayland         /*
10008bb22495SMark Cave-Ayland          * No data phase for sequencer command so raise deferred bus service
1001c90b2792SMark Cave-Ayland          * and function complete interrupt
1002cb988199SMark Cave-Ayland          */
1003c90b2792SMark Cave-Ayland         s->rregs[ESP_RINTR] |= INTR_BS | INTR_FC;
10049b2cdca2SMark Cave-Ayland         s->rregs[ESP_RSEQ] = SEQ_CD;
10058bb22495SMark Cave-Ayland         break;
1006cb22ce50SMark Cave-Ayland 
1007cb22ce50SMark Cave-Ayland     case CMD_TI | CMD_DMA:
1008cb22ce50SMark Cave-Ayland     case CMD_TI:
1009cb22ce50SMark Cave-Ayland         s->rregs[ESP_CMD] = 0;
1010cb22ce50SMark Cave-Ayland         break;
10116ef2cabcSMark Cave-Ayland     }
10126ef2cabcSMark Cave-Ayland 
10138bb22495SMark Cave-Ayland     /* Raise bus service interrupt to indicate change to STATUS phase */
10148bb22495SMark Cave-Ayland     esp_set_phase(s, STAT_ST);
10158bb22495SMark Cave-Ayland     s->rregs[ESP_RINTR] |= INTR_BS;
10168bb22495SMark Cave-Ayland     esp_raise_irq(s);
101702a3ce56SMark Cave-Ayland 
10185c6c0e51SHannes Reinecke     if (s->current_req) {
10195c6c0e51SHannes Reinecke         scsi_req_unref(s->current_req);
10205c6c0e51SHannes Reinecke         s->current_req = NULL;
1021a917d384Spbrook         s->current_dev = NULL;
10225c6c0e51SHannes Reinecke     }
1023c6df7102SPaolo Bonzini }
1024c6df7102SPaolo Bonzini 
10259c7e23fcSHervé Poussineau void esp_transfer_data(SCSIRequest *req, uint32_t len)
1026c6df7102SPaolo Bonzini {
1027e6810db8SHervé Poussineau     ESPState *s = req->hba_private;
10286cc88d6bSMark Cave-Ayland     uint32_t dmalen = esp_get_tc(s);
1029c6df7102SPaolo Bonzini 
10306cc88d6bSMark Cave-Ayland     trace_esp_transfer_data(dmalen, s->ti_size);
1031aba1f023SPaolo Bonzini     s->async_len = len;
10320c34459bSPaolo Bonzini     s->async_buf = scsi_req_get_buf(req);
10334e78f3bfSMark Cave-Ayland 
1034c90b2792SMark Cave-Ayland     if (!s->data_ready) {
1035a4608fa0SMark Cave-Ayland         s->data_ready = true;
1036a4608fa0SMark Cave-Ayland 
1037a4608fa0SMark Cave-Ayland         switch (s->rregs[ESP_CMD]) {
1038a4608fa0SMark Cave-Ayland         case CMD_SEL | CMD_DMA:
1039a4608fa0SMark Cave-Ayland         case CMD_SEL:
1040a4608fa0SMark Cave-Ayland         case CMD_SELATN | CMD_DMA:
1041a4608fa0SMark Cave-Ayland         case CMD_SELATN:
1042c90b2792SMark Cave-Ayland             /*
1043c90b2792SMark Cave-Ayland              * Initial incoming data xfer is complete for sequencer command
1044c90b2792SMark Cave-Ayland              * so raise deferred bus service and function complete interrupt
1045c90b2792SMark Cave-Ayland              */
1046c90b2792SMark Cave-Ayland              s->rregs[ESP_RINTR] |= INTR_BS | INTR_FC;
10479b2cdca2SMark Cave-Ayland              s->rregs[ESP_RSEQ] = SEQ_CD;
1048c90b2792SMark Cave-Ayland              break;
1049c90b2792SMark Cave-Ayland 
1050a4608fa0SMark Cave-Ayland         case CMD_SELATNS | CMD_DMA:
1051a4608fa0SMark Cave-Ayland         case CMD_SELATNS:
10524e78f3bfSMark Cave-Ayland             /*
10534e78f3bfSMark Cave-Ayland              * Initial incoming data xfer is complete so raise command
10544e78f3bfSMark Cave-Ayland              * completion interrupt
10554e78f3bfSMark Cave-Ayland              */
10564e78f3bfSMark Cave-Ayland              s->rregs[ESP_RINTR] |= INTR_BS;
10579b2cdca2SMark Cave-Ayland              s->rregs[ESP_RSEQ] = SEQ_MO;
1058a4608fa0SMark Cave-Ayland              break;
1059a4608fa0SMark Cave-Ayland 
1060a4608fa0SMark Cave-Ayland         case CMD_TI | CMD_DMA:
1061a4608fa0SMark Cave-Ayland         case CMD_TI:
1062a4608fa0SMark Cave-Ayland             /*
1063a4608fa0SMark Cave-Ayland              * Bus service interrupt raised because of initial change to
1064a4608fa0SMark Cave-Ayland              * DATA phase
1065a4608fa0SMark Cave-Ayland              */
1066cb22ce50SMark Cave-Ayland             s->rregs[ESP_CMD] = 0;
1067a4608fa0SMark Cave-Ayland             s->rregs[ESP_RINTR] |= INTR_BS;
1068a4608fa0SMark Cave-Ayland             break;
1069a4608fa0SMark Cave-Ayland         }
1070c90b2792SMark Cave-Ayland 
1071c90b2792SMark Cave-Ayland         esp_raise_irq(s);
10724e78f3bfSMark Cave-Ayland     }
10734e78f3bfSMark Cave-Ayland 
10741b9e48a5SMark Cave-Ayland     /*
10751b9e48a5SMark Cave-Ayland      * Always perform the initial transfer upon reception of the next TI
10761b9e48a5SMark Cave-Ayland      * command to ensure the DMA/non-DMA status of the command is correct.
10771b9e48a5SMark Cave-Ayland      * It is not possible to use s->dma directly in the section below as
10781b9e48a5SMark Cave-Ayland      * some OSs send non-DMA NOP commands after a DMA transfer. Hence if the
10791b9e48a5SMark Cave-Ayland      * async data transfer is delayed then s->dma is set incorrectly.
10801b9e48a5SMark Cave-Ayland      */
10811b9e48a5SMark Cave-Ayland 
108282003450SMark Cave-Ayland     if (s->rregs[ESP_CMD] == (CMD_TI | CMD_DMA)) {
1083a79e767aSMark Cave-Ayland         /* When the SCSI layer returns more data, raise deferred INTR_BS */
1084004826d0SMark Cave-Ayland         esp_dma_ti_check(s);
1085a79e767aSMark Cave-Ayland 
1086a79e767aSMark Cave-Ayland         esp_do_dma(s);
108782003450SMark Cave-Ayland     } else if (s->rregs[ESP_CMD] == CMD_TI) {
10881b9e48a5SMark Cave-Ayland         esp_do_nodma(s);
10891b9e48a5SMark Cave-Ayland     }
1090a917d384Spbrook }
10912e5d83bbSpbrook 
10922f275b8fSbellard static void handle_ti(ESPState *s)
10932f275b8fSbellard {
10941b9e48a5SMark Cave-Ayland     uint32_t dmalen;
10952f275b8fSbellard 
10967246e160SHervé Poussineau     if (s->dma && !s->dma_enabled) {
10977246e160SHervé Poussineau         s->dma_cb = handle_ti;
10987246e160SHervé Poussineau         return;
10997246e160SHervé Poussineau     }
11007246e160SHervé Poussineau 
11014f6200f0Sbellard     if (s->dma) {
11021b9e48a5SMark Cave-Ayland         dmalen = esp_get_tc(s);
1103b76624deSMark Cave-Ayland         trace_esp_handle_ti(dmalen);
11044d611c9aSpbrook         esp_do_dma(s);
1105799d90d8SMark Cave-Ayland     } else {
11061b9e48a5SMark Cave-Ayland         trace_esp_handle_ti(s->ti_size);
11071b9e48a5SMark Cave-Ayland         esp_do_nodma(s);
11085d02add4SMark Cave-Ayland 
11095d02add4SMark Cave-Ayland         if (esp_get_phase(s) == STAT_DO) {
11105d02add4SMark Cave-Ayland             esp_nodma_ti_dataout(s);
11115d02add4SMark Cave-Ayland         }
11124f6200f0Sbellard     }
11132f275b8fSbellard }
11142f275b8fSbellard 
11159c7e23fcSHervé Poussineau void esp_hard_reset(ESPState *s)
11166f7e9aecSbellard {
11175aca8c3bSblueswir1     memset(s->rregs, 0, ESP_REGS);
11185aca8c3bSblueswir1     memset(s->wregs, 0, ESP_REGS);
1119c9cf45c1SHannes Reinecke     s->tchi_written = 0;
11204e9aec74Spbrook     s->ti_size = 0;
11213f26c975SMark Cave-Ayland     s->async_len = 0;
1122042879fcSMark Cave-Ayland     fifo8_reset(&s->fifo);
1123023666daSMark Cave-Ayland     fifo8_reset(&s->cmdfifo);
11244e9aec74Spbrook     s->dma = 0;
112573d74342SBlue Swirl     s->dma_cb = NULL;
11268dea1dd4Sblueswir1 
11278dea1dd4Sblueswir1     s->rregs[ESP_CFG1] = 7;
11286f7e9aecSbellard }
11296f7e9aecSbellard 
1130a391fdbcSHervé Poussineau static void esp_soft_reset(ESPState *s)
113185948643SBlue Swirl {
113285948643SBlue Swirl     qemu_irq_lower(s->irq);
11336dec7c0dSMark Cave-Ayland     qemu_irq_lower(s->drq_irq);
1134a391fdbcSHervé Poussineau     esp_hard_reset(s);
113585948643SBlue Swirl }
113685948643SBlue Swirl 
1137c6e51f1bSJohn Millikin static void esp_bus_reset(ESPState *s)
1138c6e51f1bSJohn Millikin {
11394a5fc890SPeter Maydell     bus_cold_reset(BUS(&s->bus));
1140c6e51f1bSJohn Millikin }
1141c6e51f1bSJohn Millikin 
1142a391fdbcSHervé Poussineau static void parent_esp_reset(ESPState *s, int irq, int level)
11432d069babSblueswir1 {
114485948643SBlue Swirl     if (level) {
1145a391fdbcSHervé Poussineau         esp_soft_reset(s);
114685948643SBlue Swirl     }
11472d069babSblueswir1 }
11482d069babSblueswir1 
1149f21fe39dSMark Cave-Ayland static void esp_run_cmd(ESPState *s)
1150f21fe39dSMark Cave-Ayland {
1151f21fe39dSMark Cave-Ayland     uint8_t cmd = s->rregs[ESP_CMD];
1152f21fe39dSMark Cave-Ayland 
1153f21fe39dSMark Cave-Ayland     if (cmd & CMD_DMA) {
1154f21fe39dSMark Cave-Ayland         s->dma = 1;
1155f21fe39dSMark Cave-Ayland         /* Reload DMA counter.  */
1156f21fe39dSMark Cave-Ayland         if (esp_get_stc(s) == 0) {
1157f21fe39dSMark Cave-Ayland             esp_set_tc(s, 0x10000);
1158f21fe39dSMark Cave-Ayland         } else {
1159f21fe39dSMark Cave-Ayland             esp_set_tc(s, esp_get_stc(s));
1160f21fe39dSMark Cave-Ayland         }
1161f21fe39dSMark Cave-Ayland     } else {
1162f21fe39dSMark Cave-Ayland         s->dma = 0;
1163f21fe39dSMark Cave-Ayland     }
1164f21fe39dSMark Cave-Ayland     switch (cmd & CMD_CMD) {
1165f21fe39dSMark Cave-Ayland     case CMD_NOP:
1166f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_nop(cmd);
1167f21fe39dSMark Cave-Ayland         break;
1168f21fe39dSMark Cave-Ayland     case CMD_FLUSH:
1169f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_flush(cmd);
1170f21fe39dSMark Cave-Ayland         fifo8_reset(&s->fifo);
1171f21fe39dSMark Cave-Ayland         break;
1172f21fe39dSMark Cave-Ayland     case CMD_RESET:
1173f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_reset(cmd);
1174f21fe39dSMark Cave-Ayland         esp_soft_reset(s);
1175f21fe39dSMark Cave-Ayland         break;
1176f21fe39dSMark Cave-Ayland     case CMD_BUSRESET:
1177f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_bus_reset(cmd);
1178f21fe39dSMark Cave-Ayland         esp_bus_reset(s);
1179f21fe39dSMark Cave-Ayland         if (!(s->wregs[ESP_CFG1] & CFG1_RESREPT)) {
1180f21fe39dSMark Cave-Ayland             s->rregs[ESP_RINTR] |= INTR_RST;
1181f21fe39dSMark Cave-Ayland             esp_raise_irq(s);
1182f21fe39dSMark Cave-Ayland         }
1183f21fe39dSMark Cave-Ayland         break;
1184f21fe39dSMark Cave-Ayland     case CMD_TI:
1185f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_ti(cmd);
1186f21fe39dSMark Cave-Ayland         handle_ti(s);
1187f21fe39dSMark Cave-Ayland         break;
1188f21fe39dSMark Cave-Ayland     case CMD_ICCS:
1189f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_iccs(cmd);
1190f21fe39dSMark Cave-Ayland         write_response(s);
1191f21fe39dSMark Cave-Ayland         break;
1192f21fe39dSMark Cave-Ayland     case CMD_MSGACC:
1193f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_msgacc(cmd);
1194f21fe39dSMark Cave-Ayland         s->rregs[ESP_RINTR] |= INTR_DC;
1195f21fe39dSMark Cave-Ayland         s->rregs[ESP_RSEQ] = 0;
1196f21fe39dSMark Cave-Ayland         s->rregs[ESP_RFLAGS] = 0;
1197f21fe39dSMark Cave-Ayland         esp_raise_irq(s);
1198f21fe39dSMark Cave-Ayland         break;
1199f21fe39dSMark Cave-Ayland     case CMD_PAD:
1200f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_pad(cmd);
1201a6cad7cdSMark Cave-Ayland         handle_pad(s);
1202f21fe39dSMark Cave-Ayland         break;
1203f21fe39dSMark Cave-Ayland     case CMD_SATN:
1204f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_satn(cmd);
1205f21fe39dSMark Cave-Ayland         break;
1206f21fe39dSMark Cave-Ayland     case CMD_RSTATN:
1207f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_rstatn(cmd);
1208f21fe39dSMark Cave-Ayland         break;
1209f21fe39dSMark Cave-Ayland     case CMD_SEL:
1210f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_sel(cmd);
1211f21fe39dSMark Cave-Ayland         handle_s_without_atn(s);
1212f21fe39dSMark Cave-Ayland         break;
1213f21fe39dSMark Cave-Ayland     case CMD_SELATN:
1214f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_selatn(cmd);
1215f21fe39dSMark Cave-Ayland         handle_satn(s);
1216f21fe39dSMark Cave-Ayland         break;
1217f21fe39dSMark Cave-Ayland     case CMD_SELATNS:
1218f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_selatns(cmd);
1219f21fe39dSMark Cave-Ayland         handle_satn_stop(s);
1220f21fe39dSMark Cave-Ayland         break;
1221f21fe39dSMark Cave-Ayland     case CMD_ENSEL:
1222f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_ensel(cmd);
1223f21fe39dSMark Cave-Ayland         s->rregs[ESP_RINTR] = 0;
1224f21fe39dSMark Cave-Ayland         break;
1225f21fe39dSMark Cave-Ayland     case CMD_DISSEL:
1226f21fe39dSMark Cave-Ayland         trace_esp_mem_writeb_cmd_dissel(cmd);
1227f21fe39dSMark Cave-Ayland         s->rregs[ESP_RINTR] = 0;
1228f21fe39dSMark Cave-Ayland         esp_raise_irq(s);
1229f21fe39dSMark Cave-Ayland         break;
1230f21fe39dSMark Cave-Ayland     default:
1231f21fe39dSMark Cave-Ayland         trace_esp_error_unhandled_command(cmd);
1232f21fe39dSMark Cave-Ayland         break;
1233f21fe39dSMark Cave-Ayland     }
1234f21fe39dSMark Cave-Ayland }
1235f21fe39dSMark Cave-Ayland 
12369c7e23fcSHervé Poussineau uint64_t esp_reg_read(ESPState *s, uint32_t saddr)
123773d74342SBlue Swirl {
1238b630c075SMark Cave-Ayland     uint32_t val;
123973d74342SBlue Swirl 
12406f7e9aecSbellard     switch (saddr) {
12415ad6bb97Sblueswir1     case ESP_FIFO:
124261fa150dSMark Cave-Ayland         s->rregs[ESP_FIFO] = esp_fifo_pop(s);
1243b630c075SMark Cave-Ayland         val = s->rregs[ESP_FIFO];
12444f6200f0Sbellard         break;
12455ad6bb97Sblueswir1     case ESP_RINTR:
124694d5c79dSMark Cave-Ayland         /*
124794d5c79dSMark Cave-Ayland          * Clear sequence step, interrupt register and all status bits
124894d5c79dSMark Cave-Ayland          * except TC
124994d5c79dSMark Cave-Ayland          */
1250b630c075SMark Cave-Ayland         val = s->rregs[ESP_RINTR];
12512814df28SBlue Swirl         s->rregs[ESP_RINTR] = 0;
1252d294b77aSMark Cave-Ayland         esp_lower_irq(s);
1253d68212cdSMark Cave-Ayland         s->rregs[ESP_RSTAT] &= STAT_TC | 7;
1254af947a3dSMark Cave-Ayland         /*
1255af947a3dSMark Cave-Ayland          * According to the datasheet ESP_RSEQ should be cleared, but as the
1256af947a3dSMark Cave-Ayland          * emulation currently defers information transfers to the next TI
1257af947a3dSMark Cave-Ayland          * command leave it for now so that pedantic guests such as the old
1258af947a3dSMark Cave-Ayland          * Linux 2.6 driver see the correct flags before the next SCSI phase
1259af947a3dSMark Cave-Ayland          * transition.
1260af947a3dSMark Cave-Ayland          *
1261af947a3dSMark Cave-Ayland          * s->rregs[ESP_RSEQ] = SEQ_0;
1262af947a3dSMark Cave-Ayland          */
1263b630c075SMark Cave-Ayland         break;
1264c9cf45c1SHannes Reinecke     case ESP_TCHI:
1265c9cf45c1SHannes Reinecke         /* Return the unique id if the value has never been written */
1266c9cf45c1SHannes Reinecke         if (!s->tchi_written) {
1267b630c075SMark Cave-Ayland             val = s->chip_id;
1268b630c075SMark Cave-Ayland         } else {
1269b630c075SMark Cave-Ayland             val = s->rregs[saddr];
1270c9cf45c1SHannes Reinecke         }
1271b630c075SMark Cave-Ayland         break;
1272238ec4d7SMark Cave-Ayland      case ESP_RFLAGS:
1273238ec4d7SMark Cave-Ayland         /* Bottom 5 bits indicate number of bytes in FIFO */
1274238ec4d7SMark Cave-Ayland         val = fifo8_num_used(&s->fifo);
1275238ec4d7SMark Cave-Ayland         break;
12766f7e9aecSbellard     default:
1277b630c075SMark Cave-Ayland         val = s->rregs[saddr];
12786f7e9aecSbellard         break;
12796f7e9aecSbellard     }
1280b630c075SMark Cave-Ayland 
1281b630c075SMark Cave-Ayland     trace_esp_mem_readb(saddr, val);
1282b630c075SMark Cave-Ayland     return val;
12836f7e9aecSbellard }
12846f7e9aecSbellard 
12859c7e23fcSHervé Poussineau void esp_reg_write(ESPState *s, uint32_t saddr, uint64_t val)
12866f7e9aecSbellard {
1287bf4b9889SBlue Swirl     trace_esp_mem_writeb(saddr, s->wregs[saddr], val);
12886f7e9aecSbellard     switch (saddr) {
1289c9cf45c1SHannes Reinecke     case ESP_TCHI:
1290c9cf45c1SHannes Reinecke         s->tchi_written = true;
1291c9cf45c1SHannes Reinecke         /* fall through */
12925ad6bb97Sblueswir1     case ESP_TCLO:
12935ad6bb97Sblueswir1     case ESP_TCMID:
12945ad6bb97Sblueswir1         s->rregs[ESP_RSTAT] &= ~STAT_TC;
12954f6200f0Sbellard         break;
12965ad6bb97Sblueswir1     case ESP_FIFO:
12972572689bSMark Cave-Ayland         if (!fifo8_is_full(&s->fifo)) {
12980e7dbe29SMark Cave-Ayland             esp_fifo_push(s, val);
12992572689bSMark Cave-Ayland         }
13005d02add4SMark Cave-Ayland         esp_do_nodma(s);
13014f6200f0Sbellard         break;
13025ad6bb97Sblueswir1     case ESP_CMD:
13034f6200f0Sbellard         s->rregs[saddr] = val;
1304f21fe39dSMark Cave-Ayland         esp_run_cmd(s);
13056f7e9aecSbellard         break;
13065ad6bb97Sblueswir1     case ESP_WBUSID ... ESP_WSYNO:
13074f6200f0Sbellard         break;
13085ad6bb97Sblueswir1     case ESP_CFG1:
13099ea73f8bSPaolo Bonzini     case ESP_CFG2: case ESP_CFG3:
13109ea73f8bSPaolo Bonzini     case ESP_RES3: case ESP_RES4:
13114f6200f0Sbellard         s->rregs[saddr] = val;
13124f6200f0Sbellard         break;
13135ad6bb97Sblueswir1     case ESP_WCCF ... ESP_WTEST:
13144f6200f0Sbellard         break;
13156f7e9aecSbellard     default:
13163af4e9aaSHervé Poussineau         trace_esp_error_invalid_write(val, saddr);
13178dea1dd4Sblueswir1         return;
13186f7e9aecSbellard     }
13192f275b8fSbellard     s->wregs[saddr] = val;
13206f7e9aecSbellard }
13216f7e9aecSbellard 
1322a8170e5eSAvi Kivity static bool esp_mem_accepts(void *opaque, hwaddr addr,
13238372d383SPeter Maydell                             unsigned size, bool is_write,
13248372d383SPeter Maydell                             MemTxAttrs attrs)
132567bb5314SAvi Kivity {
132667bb5314SAvi Kivity     return (size == 1) || (is_write && size == 4);
132767bb5314SAvi Kivity }
13286f7e9aecSbellard 
13296cc88d6bSMark Cave-Ayland static bool esp_is_before_version_5(void *opaque, int version_id)
13306cc88d6bSMark Cave-Ayland {
13316cc88d6bSMark Cave-Ayland     ESPState *s = ESP(opaque);
13326cc88d6bSMark Cave-Ayland 
13336cc88d6bSMark Cave-Ayland     version_id = MIN(version_id, s->mig_version_id);
13346cc88d6bSMark Cave-Ayland     return version_id < 5;
13356cc88d6bSMark Cave-Ayland }
13366cc88d6bSMark Cave-Ayland 
13374e78f3bfSMark Cave-Ayland static bool esp_is_version_5(void *opaque, int version_id)
13384e78f3bfSMark Cave-Ayland {
13394e78f3bfSMark Cave-Ayland     ESPState *s = ESP(opaque);
13404e78f3bfSMark Cave-Ayland 
13414e78f3bfSMark Cave-Ayland     version_id = MIN(version_id, s->mig_version_id);
13420bcd5a18SMark Cave-Ayland     return version_id >= 5;
13434e78f3bfSMark Cave-Ayland }
13444e78f3bfSMark Cave-Ayland 
13454eb86065SPaolo Bonzini static bool esp_is_version_6(void *opaque, int version_id)
13464eb86065SPaolo Bonzini {
13474eb86065SPaolo Bonzini     ESPState *s = ESP(opaque);
13484eb86065SPaolo Bonzini 
13494eb86065SPaolo Bonzini     version_id = MIN(version_id, s->mig_version_id);
13504eb86065SPaolo Bonzini     return version_id >= 6;
13514eb86065SPaolo Bonzini }
13524eb86065SPaolo Bonzini 
135382003450SMark Cave-Ayland static bool esp_is_between_version_5_and_6(void *opaque, int version_id)
135482003450SMark Cave-Ayland {
135582003450SMark Cave-Ayland     ESPState *s = ESP(opaque);
135682003450SMark Cave-Ayland 
135782003450SMark Cave-Ayland     version_id = MIN(version_id, s->mig_version_id);
135882003450SMark Cave-Ayland     return version_id >= 5 && version_id <= 6;
135982003450SMark Cave-Ayland }
136082003450SMark Cave-Ayland 
1361ff4a1dabSMark Cave-Ayland int esp_pre_save(void *opaque)
13620bd005beSMark Cave-Ayland {
1363ff4a1dabSMark Cave-Ayland     ESPState *s = ESP(object_resolve_path_component(
1364ff4a1dabSMark Cave-Ayland                       OBJECT(opaque), "esp"));
13650bd005beSMark Cave-Ayland 
13660bd005beSMark Cave-Ayland     s->mig_version_id = vmstate_esp.version_id;
13670bd005beSMark Cave-Ayland     return 0;
13680bd005beSMark Cave-Ayland }
13690bd005beSMark Cave-Ayland 
13700bd005beSMark Cave-Ayland static int esp_post_load(void *opaque, int version_id)
13710bd005beSMark Cave-Ayland {
13720bd005beSMark Cave-Ayland     ESPState *s = ESP(opaque);
1373042879fcSMark Cave-Ayland     int len, i;
13740bd005beSMark Cave-Ayland 
13756cc88d6bSMark Cave-Ayland     version_id = MIN(version_id, s->mig_version_id);
13766cc88d6bSMark Cave-Ayland 
13776cc88d6bSMark Cave-Ayland     if (version_id < 5) {
13786cc88d6bSMark Cave-Ayland         esp_set_tc(s, s->mig_dma_left);
1379042879fcSMark Cave-Ayland 
1380042879fcSMark Cave-Ayland         /* Migrate ti_buf to fifo */
1381042879fcSMark Cave-Ayland         len = s->mig_ti_wptr - s->mig_ti_rptr;
1382042879fcSMark Cave-Ayland         for (i = 0; i < len; i++) {
1383042879fcSMark Cave-Ayland             fifo8_push(&s->fifo, s->mig_ti_buf[i]);
1384042879fcSMark Cave-Ayland         }
1385023666daSMark Cave-Ayland 
1386023666daSMark Cave-Ayland         /* Migrate cmdbuf to cmdfifo */
1387023666daSMark Cave-Ayland         for (i = 0; i < s->mig_cmdlen; i++) {
1388023666daSMark Cave-Ayland             fifo8_push(&s->cmdfifo, s->mig_cmdbuf[i]);
1389023666daSMark Cave-Ayland         }
13906cc88d6bSMark Cave-Ayland     }
13916cc88d6bSMark Cave-Ayland 
13920bd005beSMark Cave-Ayland     s->mig_version_id = vmstate_esp.version_id;
13930bd005beSMark Cave-Ayland     return 0;
13940bd005beSMark Cave-Ayland }
13950bd005beSMark Cave-Ayland 
13969c7e23fcSHervé Poussineau const VMStateDescription vmstate_esp = {
1397cc9952f3SBlue Swirl     .name = "esp",
139882003450SMark Cave-Ayland     .version_id = 7,
1399cc9952f3SBlue Swirl     .minimum_version_id = 3,
14000bd005beSMark Cave-Ayland     .post_load = esp_post_load,
14012d7b39a6SRichard Henderson     .fields = (const VMStateField[]) {
1402cc9952f3SBlue Swirl         VMSTATE_BUFFER(rregs, ESPState),
1403cc9952f3SBlue Swirl         VMSTATE_BUFFER(wregs, ESPState),
1404cc9952f3SBlue Swirl         VMSTATE_INT32(ti_size, ESPState),
1405042879fcSMark Cave-Ayland         VMSTATE_UINT32_TEST(mig_ti_rptr, ESPState, esp_is_before_version_5),
1406042879fcSMark Cave-Ayland         VMSTATE_UINT32_TEST(mig_ti_wptr, ESPState, esp_is_before_version_5),
1407042879fcSMark Cave-Ayland         VMSTATE_BUFFER_TEST(mig_ti_buf, ESPState, esp_is_before_version_5),
14083944966dSPaolo Bonzini         VMSTATE_UINT32(status, ESPState),
14094aaa6ac3SMark Cave-Ayland         VMSTATE_UINT32_TEST(mig_deferred_status, ESPState,
14104aaa6ac3SMark Cave-Ayland                             esp_is_before_version_5),
14114aaa6ac3SMark Cave-Ayland         VMSTATE_BOOL_TEST(mig_deferred_complete, ESPState,
14124aaa6ac3SMark Cave-Ayland                           esp_is_before_version_5),
1413cc9952f3SBlue Swirl         VMSTATE_UINT32(dma, ESPState),
1414023666daSMark Cave-Ayland         VMSTATE_STATIC_BUFFER(mig_cmdbuf, ESPState, 0,
1415023666daSMark Cave-Ayland                               esp_is_before_version_5, 0, 16),
1416023666daSMark Cave-Ayland         VMSTATE_STATIC_BUFFER(mig_cmdbuf, ESPState, 4,
1417023666daSMark Cave-Ayland                               esp_is_before_version_5, 16,
1418023666daSMark Cave-Ayland                               sizeof(typeof_field(ESPState, mig_cmdbuf))),
1419023666daSMark Cave-Ayland         VMSTATE_UINT32_TEST(mig_cmdlen, ESPState, esp_is_before_version_5),
1420cc9952f3SBlue Swirl         VMSTATE_UINT32(do_cmd, ESPState),
14216cc88d6bSMark Cave-Ayland         VMSTATE_UINT32_TEST(mig_dma_left, ESPState, esp_is_before_version_5),
14228dded6deSMark Cave-Ayland         VMSTATE_BOOL_TEST(data_ready, ESPState, esp_is_version_5),
1423023666daSMark Cave-Ayland         VMSTATE_UINT8_TEST(cmdfifo_cdb_offset, ESPState, esp_is_version_5),
1424042879fcSMark Cave-Ayland         VMSTATE_FIFO8_TEST(fifo, ESPState, esp_is_version_5),
1425023666daSMark Cave-Ayland         VMSTATE_FIFO8_TEST(cmdfifo, ESPState, esp_is_version_5),
142682003450SMark Cave-Ayland         VMSTATE_UINT8_TEST(mig_ti_cmd, ESPState,
142782003450SMark Cave-Ayland                            esp_is_between_version_5_and_6),
14284eb86065SPaolo Bonzini         VMSTATE_UINT8_TEST(lun, ESPState, esp_is_version_6),
1429442de89aSMark Cave-Ayland         VMSTATE_BOOL(drq_state, ESPState),
1430cc9952f3SBlue Swirl         VMSTATE_END_OF_LIST()
143174d71ea1SLaurent Vivier     },
1432cc9952f3SBlue Swirl };
14336f7e9aecSbellard 
1434a8170e5eSAvi Kivity static void sysbus_esp_mem_write(void *opaque, hwaddr addr,
1435a391fdbcSHervé Poussineau                                  uint64_t val, unsigned int size)
1436a391fdbcSHervé Poussineau {
1437a391fdbcSHervé Poussineau     SysBusESPState *sysbus = opaque;
1438eb169c76SMark Cave-Ayland     ESPState *s = ESP(&sysbus->esp);
1439a391fdbcSHervé Poussineau     uint32_t saddr;
1440a391fdbcSHervé Poussineau 
1441a391fdbcSHervé Poussineau     saddr = addr >> sysbus->it_shift;
1442eb169c76SMark Cave-Ayland     esp_reg_write(s, saddr, val);
1443a391fdbcSHervé Poussineau }
1444a391fdbcSHervé Poussineau 
1445a8170e5eSAvi Kivity static uint64_t sysbus_esp_mem_read(void *opaque, hwaddr addr,
1446a391fdbcSHervé Poussineau                                     unsigned int size)
1447a391fdbcSHervé Poussineau {
1448a391fdbcSHervé Poussineau     SysBusESPState *sysbus = opaque;
1449eb169c76SMark Cave-Ayland     ESPState *s = ESP(&sysbus->esp);
1450a391fdbcSHervé Poussineau     uint32_t saddr;
1451a391fdbcSHervé Poussineau 
1452a391fdbcSHervé Poussineau     saddr = addr >> sysbus->it_shift;
1453eb169c76SMark Cave-Ayland     return esp_reg_read(s, saddr);
1454a391fdbcSHervé Poussineau }
1455a391fdbcSHervé Poussineau 
1456a391fdbcSHervé Poussineau static const MemoryRegionOps sysbus_esp_mem_ops = {
1457a391fdbcSHervé Poussineau     .read = sysbus_esp_mem_read,
1458a391fdbcSHervé Poussineau     .write = sysbus_esp_mem_write,
1459a391fdbcSHervé Poussineau     .endianness = DEVICE_NATIVE_ENDIAN,
1460a391fdbcSHervé Poussineau     .valid.accepts = esp_mem_accepts,
1461a391fdbcSHervé Poussineau };
1462a391fdbcSHervé Poussineau 
146374d71ea1SLaurent Vivier static void sysbus_esp_pdma_write(void *opaque, hwaddr addr,
146474d71ea1SLaurent Vivier                                   uint64_t val, unsigned int size)
146574d71ea1SLaurent Vivier {
146674d71ea1SLaurent Vivier     SysBusESPState *sysbus = opaque;
1467eb169c76SMark Cave-Ayland     ESPState *s = ESP(&sysbus->esp);
146874d71ea1SLaurent Vivier 
1469960ebfd9SMark Cave-Ayland     trace_esp_pdma_write(size);
1470960ebfd9SMark Cave-Ayland 
147174d71ea1SLaurent Vivier     switch (size) {
147274d71ea1SLaurent Vivier     case 1:
1473761bef75SMark Cave-Ayland         esp_pdma_write(s, val);
147474d71ea1SLaurent Vivier         break;
147574d71ea1SLaurent Vivier     case 2:
1476761bef75SMark Cave-Ayland         esp_pdma_write(s, val >> 8);
1477761bef75SMark Cave-Ayland         esp_pdma_write(s, val);
147874d71ea1SLaurent Vivier         break;
147974d71ea1SLaurent Vivier     }
1480b46a43a2SMark Cave-Ayland     esp_do_dma(s);
148174d71ea1SLaurent Vivier }
148274d71ea1SLaurent Vivier 
148374d71ea1SLaurent Vivier static uint64_t sysbus_esp_pdma_read(void *opaque, hwaddr addr,
148474d71ea1SLaurent Vivier                                      unsigned int size)
148574d71ea1SLaurent Vivier {
148674d71ea1SLaurent Vivier     SysBusESPState *sysbus = opaque;
1487eb169c76SMark Cave-Ayland     ESPState *s = ESP(&sysbus->esp);
148874d71ea1SLaurent Vivier     uint64_t val = 0;
148974d71ea1SLaurent Vivier 
1490960ebfd9SMark Cave-Ayland     trace_esp_pdma_read(size);
1491960ebfd9SMark Cave-Ayland 
149274d71ea1SLaurent Vivier     switch (size) {
149374d71ea1SLaurent Vivier     case 1:
1494761bef75SMark Cave-Ayland         val = esp_pdma_read(s);
149574d71ea1SLaurent Vivier         break;
149674d71ea1SLaurent Vivier     case 2:
1497761bef75SMark Cave-Ayland         val = esp_pdma_read(s);
1498761bef75SMark Cave-Ayland         val = (val << 8) | esp_pdma_read(s);
149974d71ea1SLaurent Vivier         break;
150074d71ea1SLaurent Vivier     }
1501b46a43a2SMark Cave-Ayland     esp_do_dma(s);
150274d71ea1SLaurent Vivier     return val;
150374d71ea1SLaurent Vivier }
150474d71ea1SLaurent Vivier 
1505a7a22088SMark Cave-Ayland static void *esp_load_request(QEMUFile *f, SCSIRequest *req)
1506a7a22088SMark Cave-Ayland {
1507a7a22088SMark Cave-Ayland     ESPState *s = container_of(req->bus, ESPState, bus);
1508a7a22088SMark Cave-Ayland 
1509a7a22088SMark Cave-Ayland     scsi_req_ref(req);
1510a7a22088SMark Cave-Ayland     s->current_req = req;
1511a7a22088SMark Cave-Ayland     return s;
1512a7a22088SMark Cave-Ayland }
1513a7a22088SMark Cave-Ayland 
151474d71ea1SLaurent Vivier static const MemoryRegionOps sysbus_esp_pdma_ops = {
151574d71ea1SLaurent Vivier     .read = sysbus_esp_pdma_read,
151674d71ea1SLaurent Vivier     .write = sysbus_esp_pdma_write,
151774d71ea1SLaurent Vivier     .endianness = DEVICE_NATIVE_ENDIAN,
151874d71ea1SLaurent Vivier     .valid.min_access_size = 1,
1519cf1b8286SMark Cave-Ayland     .valid.max_access_size = 4,
1520cf1b8286SMark Cave-Ayland     .impl.min_access_size = 1,
1521cf1b8286SMark Cave-Ayland     .impl.max_access_size = 2,
152274d71ea1SLaurent Vivier };
152374d71ea1SLaurent Vivier 
1524afd4030cSPaolo Bonzini static const struct SCSIBusInfo esp_scsi_info = {
1525afd4030cSPaolo Bonzini     .tcq = false,
15267e0380b9SPaolo Bonzini     .max_target = ESP_MAX_DEVS,
15277e0380b9SPaolo Bonzini     .max_lun = 7,
1528afd4030cSPaolo Bonzini 
1529a7a22088SMark Cave-Ayland     .load_request = esp_load_request,
1530c6df7102SPaolo Bonzini     .transfer_data = esp_transfer_data,
153194d3f98aSPaolo Bonzini     .complete = esp_command_complete,
153294d3f98aSPaolo Bonzini     .cancel = esp_request_cancelled
1533cfdc1bb0SPaolo Bonzini };
1534cfdc1bb0SPaolo Bonzini 
1535a391fdbcSHervé Poussineau static void sysbus_esp_gpio_demux(void *opaque, int irq, int level)
1536cfb9de9cSPaul Brook {
153784fbefedSMark Cave-Ayland     SysBusESPState *sysbus = SYSBUS_ESP(opaque);
1538eb169c76SMark Cave-Ayland     ESPState *s = ESP(&sysbus->esp);
1539a391fdbcSHervé Poussineau 
1540a391fdbcSHervé Poussineau     switch (irq) {
1541a391fdbcSHervé Poussineau     case 0:
1542a391fdbcSHervé Poussineau         parent_esp_reset(s, irq, level);
1543a391fdbcSHervé Poussineau         break;
1544a391fdbcSHervé Poussineau     case 1:
1545b86dc5cbSMark Cave-Ayland         esp_dma_enable(s, irq, level);
1546a391fdbcSHervé Poussineau         break;
1547a391fdbcSHervé Poussineau     }
1548a391fdbcSHervé Poussineau }
1549a391fdbcSHervé Poussineau 
1550b09318caSHu Tao static void sysbus_esp_realize(DeviceState *dev, Error **errp)
1551a391fdbcSHervé Poussineau {
1552b09318caSHu Tao     SysBusDevice *sbd = SYS_BUS_DEVICE(dev);
155384fbefedSMark Cave-Ayland     SysBusESPState *sysbus = SYSBUS_ESP(dev);
1554eb169c76SMark Cave-Ayland     ESPState *s = ESP(&sysbus->esp);
1555eb169c76SMark Cave-Ayland 
1556eb169c76SMark Cave-Ayland     if (!qdev_realize(DEVICE(s), NULL, errp)) {
1557eb169c76SMark Cave-Ayland         return;
1558eb169c76SMark Cave-Ayland     }
15596f7e9aecSbellard 
1560b09318caSHu Tao     sysbus_init_irq(sbd, &s->irq);
15616dec7c0dSMark Cave-Ayland     sysbus_init_irq(sbd, &s->drq_irq);
1562a391fdbcSHervé Poussineau     assert(sysbus->it_shift != -1);
15636f7e9aecSbellard 
1564d32e4b3dSHervé Poussineau     s->chip_id = TCHI_FAS100A;
156529776739SPaolo Bonzini     memory_region_init_io(&sysbus->iomem, OBJECT(sysbus), &sysbus_esp_mem_ops,
156674d71ea1SLaurent Vivier                           sysbus, "esp-regs", ESP_REGS << sysbus->it_shift);
1567b09318caSHu Tao     sysbus_init_mmio(sbd, &sysbus->iomem);
156874d71ea1SLaurent Vivier     memory_region_init_io(&sysbus->pdma, OBJECT(sysbus), &sysbus_esp_pdma_ops,
1569cf1b8286SMark Cave-Ayland                           sysbus, "esp-pdma", 4);
157074d71ea1SLaurent Vivier     sysbus_init_mmio(sbd, &sysbus->pdma);
15716f7e9aecSbellard 
1572b09318caSHu Tao     qdev_init_gpio_in(dev, sysbus_esp_gpio_demux, 2);
15732d069babSblueswir1 
1574739e95f5SPeter Maydell     scsi_bus_init(&s->bus, sizeof(s->bus), dev, &esp_scsi_info);
157567e999beSbellard }
1576cfb9de9cSPaul Brook 
1577a391fdbcSHervé Poussineau static void sysbus_esp_hard_reset(DeviceState *dev)
1578a391fdbcSHervé Poussineau {
157984fbefedSMark Cave-Ayland     SysBusESPState *sysbus = SYSBUS_ESP(dev);
1580eb169c76SMark Cave-Ayland     ESPState *s = ESP(&sysbus->esp);
1581eb169c76SMark Cave-Ayland 
1582eb169c76SMark Cave-Ayland     esp_hard_reset(s);
1583eb169c76SMark Cave-Ayland }
1584eb169c76SMark Cave-Ayland 
1585eb169c76SMark Cave-Ayland static void sysbus_esp_init(Object *obj)
1586eb169c76SMark Cave-Ayland {
1587eb169c76SMark Cave-Ayland     SysBusESPState *sysbus = SYSBUS_ESP(obj);
1588eb169c76SMark Cave-Ayland 
1589eb169c76SMark Cave-Ayland     object_initialize_child(obj, "esp", &sysbus->esp, TYPE_ESP);
1590a391fdbcSHervé Poussineau }
1591a391fdbcSHervé Poussineau 
1592a391fdbcSHervé Poussineau static const VMStateDescription vmstate_sysbus_esp_scsi = {
1593a391fdbcSHervé Poussineau     .name = "sysbusespscsi",
15940bd005beSMark Cave-Ayland     .version_id = 2,
1595ea84a442SGuenter Roeck     .minimum_version_id = 1,
1596ff4a1dabSMark Cave-Ayland     .pre_save = esp_pre_save,
15972d7b39a6SRichard Henderson     .fields = (const VMStateField[]) {
15980bd005beSMark Cave-Ayland         VMSTATE_UINT8_V(esp.mig_version_id, SysBusESPState, 2),
1599a391fdbcSHervé Poussineau         VMSTATE_STRUCT(esp, SysBusESPState, 0, vmstate_esp, ESPState),
1600a391fdbcSHervé Poussineau         VMSTATE_END_OF_LIST()
1601a391fdbcSHervé Poussineau     }
1602999e12bbSAnthony Liguori };
1603999e12bbSAnthony Liguori 
1604a391fdbcSHervé Poussineau static void sysbus_esp_class_init(ObjectClass *klass, void *data)
1605999e12bbSAnthony Liguori {
160639bffca2SAnthony Liguori     DeviceClass *dc = DEVICE_CLASS(klass);
1607999e12bbSAnthony Liguori 
1608b09318caSHu Tao     dc->realize = sysbus_esp_realize;
1609a391fdbcSHervé Poussineau     dc->reset = sysbus_esp_hard_reset;
1610a391fdbcSHervé Poussineau     dc->vmsd = &vmstate_sysbus_esp_scsi;
1611125ee0edSMarcel Apfelbaum     set_bit(DEVICE_CATEGORY_STORAGE, dc->categories);
161263235df8SBlue Swirl }
1613999e12bbSAnthony Liguori 
1614042879fcSMark Cave-Ayland static void esp_finalize(Object *obj)
1615042879fcSMark Cave-Ayland {
1616042879fcSMark Cave-Ayland     ESPState *s = ESP(obj);
1617042879fcSMark Cave-Ayland 
1618042879fcSMark Cave-Ayland     fifo8_destroy(&s->fifo);
1619023666daSMark Cave-Ayland     fifo8_destroy(&s->cmdfifo);
1620042879fcSMark Cave-Ayland }
1621042879fcSMark Cave-Ayland 
1622042879fcSMark Cave-Ayland static void esp_init(Object *obj)
1623042879fcSMark Cave-Ayland {
1624042879fcSMark Cave-Ayland     ESPState *s = ESP(obj);
1625042879fcSMark Cave-Ayland 
1626042879fcSMark Cave-Ayland     fifo8_create(&s->fifo, ESP_FIFO_SZ);
1627023666daSMark Cave-Ayland     fifo8_create(&s->cmdfifo, ESP_CMDFIFO_SZ);
1628042879fcSMark Cave-Ayland }
1629042879fcSMark Cave-Ayland 
1630eb169c76SMark Cave-Ayland static void esp_class_init(ObjectClass *klass, void *data)
1631eb169c76SMark Cave-Ayland {
1632eb169c76SMark Cave-Ayland     DeviceClass *dc = DEVICE_CLASS(klass);
1633eb169c76SMark Cave-Ayland 
1634eb169c76SMark Cave-Ayland     /* internal device for sysbusesp/pciespscsi, not user-creatable */
1635eb169c76SMark Cave-Ayland     dc->user_creatable = false;
1636eb169c76SMark Cave-Ayland     set_bit(DEVICE_CATEGORY_STORAGE, dc->categories);
1637eb169c76SMark Cave-Ayland }
1638eb169c76SMark Cave-Ayland 
1639499f4089SMark Cave-Ayland static const TypeInfo esp_info_types[] = {
1640499f4089SMark Cave-Ayland     {
1641499f4089SMark Cave-Ayland         .name          = TYPE_SYSBUS_ESP,
1642499f4089SMark Cave-Ayland         .parent        = TYPE_SYS_BUS_DEVICE,
1643499f4089SMark Cave-Ayland         .instance_init = sysbus_esp_init,
1644499f4089SMark Cave-Ayland         .instance_size = sizeof(SysBusESPState),
1645499f4089SMark Cave-Ayland         .class_init    = sysbus_esp_class_init,
1646499f4089SMark Cave-Ayland     },
1647499f4089SMark Cave-Ayland     {
1648eb169c76SMark Cave-Ayland         .name = TYPE_ESP,
1649eb169c76SMark Cave-Ayland         .parent = TYPE_DEVICE,
1650042879fcSMark Cave-Ayland         .instance_init = esp_init,
1651042879fcSMark Cave-Ayland         .instance_finalize = esp_finalize,
1652eb169c76SMark Cave-Ayland         .instance_size = sizeof(ESPState),
1653eb169c76SMark Cave-Ayland         .class_init = esp_class_init,
1654499f4089SMark Cave-Ayland     },
1655eb169c76SMark Cave-Ayland };
1656eb169c76SMark Cave-Ayland 
1657499f4089SMark Cave-Ayland DEFINE_TYPES(esp_info_types)
1658