4 * Copyright (c) 2005 Fabrice Bellard
6 * 2008 Generic packet handler rewrite by Max Krasnyansky
8 * Permission is hereby granted, free of charge, to any person obtaining a copy
9 * of this software and associated documentation files (the "Software"), to deal
10 * in the Software without restriction, including without limitation the rights
11 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
12 * copies of the Software, and to permit persons to whom the Software is
13 * furnished to do so, subject to the following conditions:
15 * The above copyright notice and this permission notice shall be included in
16 * all copies or substantial portions of the Software.
18 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
19 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
20 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
21 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
22 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
23 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
26 #include "qemu-common.h"
31 void usb_attach(USBPort
*port
)
33 USBDevice
*dev
= port
->dev
;
36 assert(dev
->attached
);
37 assert(dev
->state
== USB_STATE_NOTATTACHED
);
38 port
->ops
->attach(port
);
39 dev
->state
= USB_STATE_ATTACHED
;
40 usb_device_handle_attach(dev
);
43 void usb_detach(USBPort
*port
)
45 USBDevice
*dev
= port
->dev
;
48 assert(dev
->state
!= USB_STATE_NOTATTACHED
);
49 port
->ops
->detach(port
);
50 dev
->state
= USB_STATE_NOTATTACHED
;
53 void usb_port_reset(USBPort
*port
)
55 USBDevice
*dev
= port
->dev
;
60 usb_device_reset(dev
);
63 void usb_device_reset(USBDevice
*dev
)
65 if (dev
== NULL
|| !dev
->attached
) {
68 dev
->remote_wakeup
= 0;
70 dev
->state
= USB_STATE_DEFAULT
;
71 usb_device_handle_reset(dev
);
74 void usb_wakeup(USBEndpoint
*ep
)
76 USBDevice
*dev
= ep
->dev
;
77 USBBus
*bus
= usb_bus_from_device(dev
);
79 if (dev
->remote_wakeup
&& dev
->port
&& dev
->port
->ops
->wakeup
) {
80 dev
->port
->ops
->wakeup(dev
->port
);
82 if (bus
->ops
->wakeup_endpoint
) {
83 bus
->ops
->wakeup_endpoint(bus
, ep
);
87 /**********************/
89 /* generic USB device helpers (you are not forced to use them when
90 writing your USB device driver, but they help handling the
94 #define SETUP_STATE_IDLE 0
95 #define SETUP_STATE_SETUP 1
96 #define SETUP_STATE_DATA 2
97 #define SETUP_STATE_ACK 3
98 #define SETUP_STATE_PARAM 4
100 static int do_token_setup(USBDevice
*s
, USBPacket
*p
)
102 int request
, value
, index
;
105 if (p
->iov
.size
!= 8) {
106 return USB_RET_STALL
;
109 usb_packet_copy(p
, s
->setup_buf
, p
->iov
.size
);
110 s
->setup_len
= (s
->setup_buf
[7] << 8) | s
->setup_buf
[6];
113 request
= (s
->setup_buf
[0] << 8) | s
->setup_buf
[1];
114 value
= (s
->setup_buf
[3] << 8) | s
->setup_buf
[2];
115 index
= (s
->setup_buf
[5] << 8) | s
->setup_buf
[4];
117 if (s
->setup_buf
[0] & USB_DIR_IN
) {
118 ret
= usb_device_handle_control(s
, p
, request
, value
, index
,
119 s
->setup_len
, s
->data_buf
);
120 if (ret
== USB_RET_ASYNC
) {
121 s
->setup_state
= SETUP_STATE_SETUP
;
122 return USB_RET_ASYNC
;
127 if (ret
< s
->setup_len
)
129 s
->setup_state
= SETUP_STATE_DATA
;
131 if (s
->setup_len
> sizeof(s
->data_buf
)) {
133 "usb_generic_handle_packet: ctrl buffer too small (%d > %zu)\n",
134 s
->setup_len
, sizeof(s
->data_buf
));
135 return USB_RET_STALL
;
137 if (s
->setup_len
== 0)
138 s
->setup_state
= SETUP_STATE_ACK
;
140 s
->setup_state
= SETUP_STATE_DATA
;
146 static int do_token_in(USBDevice
*s
, USBPacket
*p
)
148 int request
, value
, index
;
151 assert(p
->ep
->nr
== 0);
153 request
= (s
->setup_buf
[0] << 8) | s
->setup_buf
[1];
154 value
= (s
->setup_buf
[3] << 8) | s
->setup_buf
[2];
155 index
= (s
->setup_buf
[5] << 8) | s
->setup_buf
[4];
157 switch(s
->setup_state
) {
158 case SETUP_STATE_ACK
:
159 if (!(s
->setup_buf
[0] & USB_DIR_IN
)) {
160 ret
= usb_device_handle_control(s
, p
, request
, value
, index
,
161 s
->setup_len
, s
->data_buf
);
162 if (ret
== USB_RET_ASYNC
) {
163 return USB_RET_ASYNC
;
165 s
->setup_state
= SETUP_STATE_IDLE
;
174 case SETUP_STATE_DATA
:
175 if (s
->setup_buf
[0] & USB_DIR_IN
) {
176 int len
= s
->setup_len
- s
->setup_index
;
177 if (len
> p
->iov
.size
) {
180 usb_packet_copy(p
, s
->data_buf
+ s
->setup_index
, len
);
181 s
->setup_index
+= len
;
182 if (s
->setup_index
>= s
->setup_len
)
183 s
->setup_state
= SETUP_STATE_ACK
;
187 s
->setup_state
= SETUP_STATE_IDLE
;
188 return USB_RET_STALL
;
191 return USB_RET_STALL
;
195 static int do_token_out(USBDevice
*s
, USBPacket
*p
)
197 assert(p
->ep
->nr
== 0);
199 switch(s
->setup_state
) {
200 case SETUP_STATE_ACK
:
201 if (s
->setup_buf
[0] & USB_DIR_IN
) {
202 s
->setup_state
= SETUP_STATE_IDLE
;
205 /* ignore additional output */
209 case SETUP_STATE_DATA
:
210 if (!(s
->setup_buf
[0] & USB_DIR_IN
)) {
211 int len
= s
->setup_len
- s
->setup_index
;
212 if (len
> p
->iov
.size
) {
215 usb_packet_copy(p
, s
->data_buf
+ s
->setup_index
, len
);
216 s
->setup_index
+= len
;
217 if (s
->setup_index
>= s
->setup_len
)
218 s
->setup_state
= SETUP_STATE_ACK
;
222 s
->setup_state
= SETUP_STATE_IDLE
;
223 return USB_RET_STALL
;
226 return USB_RET_STALL
;
230 static int do_parameter(USBDevice
*s
, USBPacket
*p
)
232 int request
, value
, index
;
235 for (i
= 0; i
< 8; i
++) {
236 s
->setup_buf
[i
] = p
->parameter
>> (i
*8);
239 s
->setup_state
= SETUP_STATE_PARAM
;
240 s
->setup_len
= (s
->setup_buf
[7] << 8) | s
->setup_buf
[6];
243 request
= (s
->setup_buf
[0] << 8) | s
->setup_buf
[1];
244 value
= (s
->setup_buf
[3] << 8) | s
->setup_buf
[2];
245 index
= (s
->setup_buf
[5] << 8) | s
->setup_buf
[4];
247 if (s
->setup_len
> sizeof(s
->data_buf
)) {
249 "usb_generic_handle_packet: ctrl buffer too small (%d > %zu)\n",
250 s
->setup_len
, sizeof(s
->data_buf
));
251 return USB_RET_STALL
;
254 if (p
->pid
== USB_TOKEN_OUT
) {
255 usb_packet_copy(p
, s
->data_buf
, s
->setup_len
);
258 ret
= usb_device_handle_control(s
, p
, request
, value
, index
,
259 s
->setup_len
, s
->data_buf
);
264 if (ret
< s
->setup_len
) {
267 if (p
->pid
== USB_TOKEN_IN
) {
268 usb_packet_copy(p
, s
->data_buf
, s
->setup_len
);
274 /* ctrl complete function for devices which use usb_generic_handle_packet and
275 may return USB_RET_ASYNC from their handle_control callback. Device code
276 which does this *must* call this function instead of the normal
277 usb_packet_complete to complete their async control packets. */
278 void usb_generic_async_ctrl_complete(USBDevice
*s
, USBPacket
*p
)
281 s
->setup_state
= SETUP_STATE_IDLE
;
284 switch (s
->setup_state
) {
285 case SETUP_STATE_SETUP
:
286 if (p
->result
< s
->setup_len
) {
287 s
->setup_len
= p
->result
;
289 s
->setup_state
= SETUP_STATE_DATA
;
293 case SETUP_STATE_ACK
:
294 s
->setup_state
= SETUP_STATE_IDLE
;
298 case SETUP_STATE_PARAM
:
299 if (p
->result
< s
->setup_len
) {
300 s
->setup_len
= p
->result
;
302 if (p
->pid
== USB_TOKEN_IN
) {
304 usb_packet_copy(p
, s
->data_buf
, s
->setup_len
);
311 usb_packet_complete(s
, p
);
314 /* XXX: fix overflow */
315 int set_usb_string(uint8_t *buf
, const char *str
)
324 for(i
= 0; i
< len
; i
++) {
331 USBDevice
*usb_find_device(USBPort
*port
, uint8_t addr
)
333 USBDevice
*dev
= port
->dev
;
335 if (dev
== NULL
|| !dev
->attached
|| dev
->state
!= USB_STATE_DEFAULT
) {
338 if (dev
->addr
== addr
) {
341 return usb_device_find_device(dev
, addr
);
344 static int usb_process_one(USBPacket
*p
)
346 USBDevice
*dev
= p
->ep
->dev
;
348 if (p
->ep
->nr
== 0) {
351 return do_parameter(dev
, p
);
354 case USB_TOKEN_SETUP
:
355 return do_token_setup(dev
, p
);
357 return do_token_in(dev
, p
);
359 return do_token_out(dev
, p
);
361 return USB_RET_STALL
;
365 return usb_device_handle_data(dev
, p
);
369 /* Hand over a packet to a device for processing. Return value
370 USB_RET_ASYNC indicates the processing isn't finished yet, the
371 driver will call usb_packet_complete() when done processing it. */
372 int usb_handle_packet(USBDevice
*dev
, USBPacket
*p
)
377 return USB_RET_NODEV
;
379 assert(dev
== p
->ep
->dev
);
380 assert(dev
->state
== USB_STATE_DEFAULT
);
381 usb_packet_check_state(p
, USB_PACKET_SETUP
);
382 assert(p
->ep
!= NULL
);
384 if (QTAILQ_EMPTY(&p
->ep
->queue
) || p
->ep
->pipeline
) {
385 ret
= usb_process_one(p
);
386 if (ret
== USB_RET_ASYNC
) {
387 usb_packet_set_state(p
, USB_PACKET_ASYNC
);
388 QTAILQ_INSERT_TAIL(&p
->ep
->queue
, p
, queue
);
391 usb_packet_set_state(p
, USB_PACKET_COMPLETE
);
395 usb_packet_set_state(p
, USB_PACKET_QUEUED
);
396 QTAILQ_INSERT_TAIL(&p
->ep
->queue
, p
, queue
);
401 /* Notify the controller that an async packet is complete. This should only
402 be called for packets previously deferred by returning USB_RET_ASYNC from
404 void usb_packet_complete(USBDevice
*dev
, USBPacket
*p
)
406 USBEndpoint
*ep
= p
->ep
;
409 usb_packet_check_state(p
, USB_PACKET_ASYNC
);
410 assert(QTAILQ_FIRST(&ep
->queue
) == p
);
411 usb_packet_set_state(p
, USB_PACKET_COMPLETE
);
412 QTAILQ_REMOVE(&ep
->queue
, p
, queue
);
413 dev
->port
->ops
->complete(dev
->port
, p
);
415 while (!QTAILQ_EMPTY(&ep
->queue
)) {
416 p
= QTAILQ_FIRST(&ep
->queue
);
417 if (p
->state
== USB_PACKET_ASYNC
) {
420 usb_packet_check_state(p
, USB_PACKET_QUEUED
);
421 ret
= usb_process_one(p
);
422 if (ret
== USB_RET_ASYNC
) {
423 usb_packet_set_state(p
, USB_PACKET_ASYNC
);
427 usb_packet_set_state(p
, USB_PACKET_COMPLETE
);
428 QTAILQ_REMOVE(&ep
->queue
, p
, queue
);
429 dev
->port
->ops
->complete(dev
->port
, p
);
433 /* Cancel an active packet. The packed must have been deferred by
434 returning USB_RET_ASYNC from handle_packet, and not yet
436 void usb_cancel_packet(USBPacket
* p
)
438 bool callback
= (p
->state
== USB_PACKET_ASYNC
);
439 assert(usb_packet_is_inflight(p
));
440 usb_packet_set_state(p
, USB_PACKET_CANCELED
);
441 QTAILQ_REMOVE(&p
->ep
->queue
, p
, queue
);
443 usb_device_cancel_packet(p
->ep
->dev
, p
);
448 void usb_packet_init(USBPacket
*p
)
450 qemu_iovec_init(&p
->iov
, 1);
453 static const char *usb_packet_state_name(USBPacketState state
)
455 static const char *name
[] = {
456 [USB_PACKET_UNDEFINED
] = "undef",
457 [USB_PACKET_SETUP
] = "setup",
458 [USB_PACKET_QUEUED
] = "queued",
459 [USB_PACKET_ASYNC
] = "async",
460 [USB_PACKET_COMPLETE
] = "complete",
461 [USB_PACKET_CANCELED
] = "canceled",
463 if (state
< ARRAY_SIZE(name
)) {
469 void usb_packet_check_state(USBPacket
*p
, USBPacketState expected
)
474 if (p
->state
== expected
) {
478 bus
= usb_bus_from_device(dev
);
479 trace_usb_packet_state_fault(bus
->busnr
, dev
->port
->path
, p
->ep
->nr
, p
,
480 usb_packet_state_name(p
->state
),
481 usb_packet_state_name(expected
));
482 assert(!"usb packet state check failed");
485 void usb_packet_set_state(USBPacket
*p
, USBPacketState state
)
488 USBDevice
*dev
= p
->ep
->dev
;
489 USBBus
*bus
= usb_bus_from_device(dev
);
490 trace_usb_packet_state_change(bus
->busnr
, dev
->port
->path
, p
->ep
->nr
, p
,
491 usb_packet_state_name(p
->state
),
492 usb_packet_state_name(state
));
494 trace_usb_packet_state_change(-1, "", -1, p
,
495 usb_packet_state_name(p
->state
),
496 usb_packet_state_name(state
));
501 void usb_packet_setup(USBPacket
*p
, int pid
, USBEndpoint
*ep
)
503 assert(!usb_packet_is_inflight(p
));
504 assert(p
->iov
.iov
!= NULL
);
509 qemu_iovec_reset(&p
->iov
);
510 usb_packet_set_state(p
, USB_PACKET_SETUP
);
513 void usb_packet_addbuf(USBPacket
*p
, void *ptr
, size_t len
)
515 qemu_iovec_add(&p
->iov
, ptr
, len
);
518 void usb_packet_copy(USBPacket
*p
, void *ptr
, size_t bytes
)
520 assert(p
->result
>= 0);
521 assert(p
->result
+ bytes
<= p
->iov
.size
);
523 case USB_TOKEN_SETUP
:
525 iov_to_buf(p
->iov
.iov
, p
->iov
.niov
, ptr
, p
->result
, bytes
);
528 iov_from_buf(p
->iov
.iov
, p
->iov
.niov
, ptr
, p
->result
, bytes
);
531 fprintf(stderr
, "%s: invalid pid: %x\n", __func__
, p
->pid
);
537 void usb_packet_skip(USBPacket
*p
, size_t bytes
)
539 assert(p
->result
>= 0);
540 assert(p
->result
+ bytes
<= p
->iov
.size
);
541 if (p
->pid
== USB_TOKEN_IN
) {
542 iov_clear(p
->iov
.iov
, p
->iov
.niov
, p
->result
, bytes
);
547 void usb_packet_cleanup(USBPacket
*p
)
549 assert(!usb_packet_is_inflight(p
));
550 qemu_iovec_destroy(&p
->iov
);
553 void usb_ep_init(USBDevice
*dev
)
558 dev
->ep_ctl
.type
= USB_ENDPOINT_XFER_CONTROL
;
559 dev
->ep_ctl
.ifnum
= 0;
560 dev
->ep_ctl
.dev
= dev
;
561 dev
->ep_ctl
.pipeline
= false;
562 QTAILQ_INIT(&dev
->ep_ctl
.queue
);
563 for (ep
= 0; ep
< USB_MAX_ENDPOINTS
; ep
++) {
564 dev
->ep_in
[ep
].nr
= ep
+ 1;
565 dev
->ep_out
[ep
].nr
= ep
+ 1;
566 dev
->ep_in
[ep
].pid
= USB_TOKEN_IN
;
567 dev
->ep_out
[ep
].pid
= USB_TOKEN_OUT
;
568 dev
->ep_in
[ep
].type
= USB_ENDPOINT_XFER_INVALID
;
569 dev
->ep_out
[ep
].type
= USB_ENDPOINT_XFER_INVALID
;
570 dev
->ep_in
[ep
].ifnum
= 0;
571 dev
->ep_out
[ep
].ifnum
= 0;
572 dev
->ep_in
[ep
].dev
= dev
;
573 dev
->ep_out
[ep
].dev
= dev
;
574 dev
->ep_in
[ep
].pipeline
= false;
575 dev
->ep_out
[ep
].pipeline
= false;
576 QTAILQ_INIT(&dev
->ep_in
[ep
].queue
);
577 QTAILQ_INIT(&dev
->ep_out
[ep
].queue
);
581 void usb_ep_dump(USBDevice
*dev
)
583 static const char *tname
[] = {
584 [USB_ENDPOINT_XFER_CONTROL
] = "control",
585 [USB_ENDPOINT_XFER_ISOC
] = "isoc",
586 [USB_ENDPOINT_XFER_BULK
] = "bulk",
587 [USB_ENDPOINT_XFER_INT
] = "int",
589 int ifnum
, ep
, first
;
591 fprintf(stderr
, "Device \"%s\", config %d\n",
592 dev
->product_desc
, dev
->configuration
);
593 for (ifnum
= 0; ifnum
< 16; ifnum
++) {
595 for (ep
= 0; ep
< USB_MAX_ENDPOINTS
; ep
++) {
596 if (dev
->ep_in
[ep
].type
!= USB_ENDPOINT_XFER_INVALID
&&
597 dev
->ep_in
[ep
].ifnum
== ifnum
) {
600 fprintf(stderr
, " Interface %d, alternative %d\n",
601 ifnum
, dev
->altsetting
[ifnum
]);
603 fprintf(stderr
, " Endpoint %d, IN, %s, %d max\n", ep
,
604 tname
[dev
->ep_in
[ep
].type
],
605 dev
->ep_in
[ep
].max_packet_size
);
607 if (dev
->ep_out
[ep
].type
!= USB_ENDPOINT_XFER_INVALID
&&
608 dev
->ep_out
[ep
].ifnum
== ifnum
) {
611 fprintf(stderr
, " Interface %d, alternative %d\n",
612 ifnum
, dev
->altsetting
[ifnum
]);
614 fprintf(stderr
, " Endpoint %d, OUT, %s, %d max\n", ep
,
615 tname
[dev
->ep_out
[ep
].type
],
616 dev
->ep_out
[ep
].max_packet_size
);
620 fprintf(stderr
, "--\n");
623 struct USBEndpoint
*usb_ep_get(USBDevice
*dev
, int pid
, int ep
)
625 struct USBEndpoint
*eps
;
630 eps
= (pid
== USB_TOKEN_IN
) ? dev
->ep_in
: dev
->ep_out
;
634 assert(pid
== USB_TOKEN_IN
|| pid
== USB_TOKEN_OUT
);
635 assert(ep
> 0 && ep
<= USB_MAX_ENDPOINTS
);
639 uint8_t usb_ep_get_type(USBDevice
*dev
, int pid
, int ep
)
641 struct USBEndpoint
*uep
= usb_ep_get(dev
, pid
, ep
);
645 void usb_ep_set_type(USBDevice
*dev
, int pid
, int ep
, uint8_t type
)
647 struct USBEndpoint
*uep
= usb_ep_get(dev
, pid
, ep
);
651 uint8_t usb_ep_get_ifnum(USBDevice
*dev
, int pid
, int ep
)
653 struct USBEndpoint
*uep
= usb_ep_get(dev
, pid
, ep
);
657 void usb_ep_set_ifnum(USBDevice
*dev
, int pid
, int ep
, uint8_t ifnum
)
659 struct USBEndpoint
*uep
= usb_ep_get(dev
, pid
, ep
);
663 void usb_ep_set_max_packet_size(USBDevice
*dev
, int pid
, int ep
,
666 struct USBEndpoint
*uep
= usb_ep_get(dev
, pid
, ep
);
667 int size
, microframes
;
670 switch ((raw
>> 11) & 3) {
681 uep
->max_packet_size
= size
* microframes
;
684 int usb_ep_get_max_packet_size(USBDevice
*dev
, int pid
, int ep
)
686 struct USBEndpoint
*uep
= usb_ep_get(dev
, pid
, ep
);
687 return uep
->max_packet_size
;
690 void usb_ep_set_pipeline(USBDevice
*dev
, int pid
, int ep
, bool enabled
)
692 struct USBEndpoint
*uep
= usb_ep_get(dev
, pid
, ep
);
693 uep
->pipeline
= enabled
;