New upstream version 17.11.4
[deb_dpdk.git] / lib / librte_vhost / virtio_net.c
1 /*-
2  *   BSD LICENSE
3  *
4  *   Copyright(c) 2010-2016 Intel Corporation. All rights reserved.
5  *   All rights reserved.
6  *
7  *   Redistribution and use in source and binary forms, with or without
8  *   modification, are permitted provided that the following conditions
9  *   are met:
10  *
11  *     * Redistributions of source code must retain the above copyright
12  *       notice, this list of conditions and the following disclaimer.
13  *     * Redistributions in binary form must reproduce the above copyright
14  *       notice, this list of conditions and the following disclaimer in
15  *       the documentation and/or other materials provided with the
16  *       distribution.
17  *     * Neither the name of Intel Corporation nor the names of its
18  *       contributors may be used to endorse or promote products derived
19  *       from this software without specific prior written permission.
20  *
21  *   THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
22  *   "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
23  *   LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
24  *   A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
25  *   OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
26  *   SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
27  *   LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
28  *   DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
29  *   THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
30  *   (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
31  *   OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32  */
33
34 #include <stdint.h>
35 #include <stdbool.h>
36 #include <linux/virtio_net.h>
37
38 #include <rte_mbuf.h>
39 #include <rte_memcpy.h>
40 #include <rte_ether.h>
41 #include <rte_ip.h>
42 #include <rte_vhost.h>
43 #include <rte_tcp.h>
44 #include <rte_udp.h>
45 #include <rte_sctp.h>
46 #include <rte_arp.h>
47 #include <rte_spinlock.h>
48 #include <rte_malloc.h>
49
50 #include "iotlb.h"
51 #include "vhost.h"
52
53 #define MAX_PKT_BURST 32
54
55 #define MAX_BATCH_LEN 256
56
57 static bool
58 is_valid_virt_queue_idx(uint32_t idx, int is_tx, uint32_t nr_vring)
59 {
60         return (is_tx ^ (idx & 1)) == 0 && idx < nr_vring;
61 }
62
63 static __rte_always_inline struct vring_desc *
64 alloc_copy_ind_table(struct virtio_net *dev, struct vhost_virtqueue *vq,
65                                          struct vring_desc *desc)
66 {
67         struct vring_desc *idesc;
68         uint64_t src, dst;
69         uint64_t len, remain = desc->len;
70         uint64_t desc_addr = desc->addr;
71
72         idesc = rte_malloc(__func__, desc->len, 0);
73         if (unlikely(!idesc))
74                 return 0;
75
76         dst = (uint64_t)(uintptr_t)idesc;
77
78         while (remain) {
79                 len = remain;
80                 src = vhost_iova_to_vva(dev, vq, desc_addr, &len,
81                                 VHOST_ACCESS_RO);
82                 if (unlikely(!src || !len)) {
83                         rte_free(idesc);
84                         return 0;
85                 }
86
87                 rte_memcpy((void *)(uintptr_t)dst, (void *)(uintptr_t)src, len);
88
89                 remain -= len;
90                 dst += len;
91                 desc_addr += len;
92         }
93
94         return idesc;
95 }
96
97 static __rte_always_inline void
98 free_ind_table(struct vring_desc *idesc)
99 {
100         rte_free(idesc);
101 }
102
103 static __rte_always_inline void
104 do_flush_shadow_used_ring(struct virtio_net *dev, struct vhost_virtqueue *vq,
105                           uint16_t to, uint16_t from, uint16_t size)
106 {
107         rte_memcpy(&vq->used->ring[to],
108                         &vq->shadow_used_ring[from],
109                         size * sizeof(struct vring_used_elem));
110         vhost_log_cache_used_vring(dev, vq,
111                         offsetof(struct vring_used, ring[to]),
112                         size * sizeof(struct vring_used_elem));
113 }
114
115 static __rte_always_inline void
116 flush_shadow_used_ring(struct virtio_net *dev, struct vhost_virtqueue *vq)
117 {
118         uint16_t used_idx = vq->last_used_idx & (vq->size - 1);
119
120         if (used_idx + vq->shadow_used_idx <= vq->size) {
121                 do_flush_shadow_used_ring(dev, vq, used_idx, 0,
122                                           vq->shadow_used_idx);
123         } else {
124                 uint16_t size;
125
126                 /* update used ring interval [used_idx, vq->size] */
127                 size = vq->size - used_idx;
128                 do_flush_shadow_used_ring(dev, vq, used_idx, 0, size);
129
130                 /* update the left half used ring interval [0, left_size] */
131                 do_flush_shadow_used_ring(dev, vq, 0, size,
132                                           vq->shadow_used_idx - size);
133         }
134         vq->last_used_idx += vq->shadow_used_idx;
135
136         rte_smp_wmb();
137
138         vhost_log_cache_sync(dev, vq);
139
140         *(volatile uint16_t *)&vq->used->idx += vq->shadow_used_idx;
141         vhost_log_used_vring(dev, vq, offsetof(struct vring_used, idx),
142                 sizeof(vq->used->idx));
143 }
144
145 static __rte_always_inline void
146 update_shadow_used_ring(struct vhost_virtqueue *vq,
147                          uint16_t desc_idx, uint16_t len)
148 {
149         uint16_t i = vq->shadow_used_idx++;
150
151         vq->shadow_used_ring[i].id  = desc_idx;
152         vq->shadow_used_ring[i].len = len;
153 }
154
155 static inline void
156 do_data_copy_enqueue(struct virtio_net *dev, struct vhost_virtqueue *vq)
157 {
158         struct batch_copy_elem *elem = vq->batch_copy_elems;
159         uint16_t count = vq->batch_copy_nb_elems;
160         int i;
161
162         for (i = 0; i < count; i++) {
163                 rte_memcpy(elem[i].dst, elem[i].src, elem[i].len);
164                 vhost_log_cache_write(dev, vq, elem[i].log_addr, elem[i].len);
165                 PRINT_PACKET(dev, (uintptr_t)elem[i].dst, elem[i].len, 0);
166         }
167 }
168
169 static inline void
170 do_data_copy_dequeue(struct vhost_virtqueue *vq)
171 {
172         struct batch_copy_elem *elem = vq->batch_copy_elems;
173         uint16_t count = vq->batch_copy_nb_elems;
174         int i;
175
176         for (i = 0; i < count; i++)
177                 rte_memcpy(elem[i].dst, elem[i].src, elem[i].len);
178 }
179
180 /* avoid write operation when necessary, to lessen cache issues */
181 #define ASSIGN_UNLESS_EQUAL(var, val) do {      \
182         if ((var) != (val))                     \
183                 (var) = (val);                  \
184 } while (0)
185
186 static void
187 virtio_enqueue_offload(struct rte_mbuf *m_buf, struct virtio_net_hdr *net_hdr)
188 {
189         uint64_t csum_l4 = m_buf->ol_flags & PKT_TX_L4_MASK;
190
191         if (m_buf->ol_flags & PKT_TX_TCP_SEG)
192                 csum_l4 |= PKT_TX_TCP_CKSUM;
193
194         if (csum_l4) {
195                 net_hdr->flags = VIRTIO_NET_HDR_F_NEEDS_CSUM;
196                 net_hdr->csum_start = m_buf->l2_len + m_buf->l3_len;
197
198                 switch (csum_l4) {
199                 case PKT_TX_TCP_CKSUM:
200                         net_hdr->csum_offset = (offsetof(struct tcp_hdr,
201                                                 cksum));
202                         break;
203                 case PKT_TX_UDP_CKSUM:
204                         net_hdr->csum_offset = (offsetof(struct udp_hdr,
205                                                 dgram_cksum));
206                         break;
207                 case PKT_TX_SCTP_CKSUM:
208                         net_hdr->csum_offset = (offsetof(struct sctp_hdr,
209                                                 cksum));
210                         break;
211                 }
212         } else {
213                 ASSIGN_UNLESS_EQUAL(net_hdr->csum_start, 0);
214                 ASSIGN_UNLESS_EQUAL(net_hdr->csum_offset, 0);
215                 ASSIGN_UNLESS_EQUAL(net_hdr->flags, 0);
216         }
217
218         /* IP cksum verification cannot be bypassed, then calculate here */
219         if (m_buf->ol_flags & PKT_TX_IP_CKSUM) {
220                 struct ipv4_hdr *ipv4_hdr;
221
222                 ipv4_hdr = rte_pktmbuf_mtod_offset(m_buf, struct ipv4_hdr *,
223                                                    m_buf->l2_len);
224                 ipv4_hdr->hdr_checksum = rte_ipv4_cksum(ipv4_hdr);
225         }
226
227         if (m_buf->ol_flags & PKT_TX_TCP_SEG) {
228                 if (m_buf->ol_flags & PKT_TX_IPV4)
229                         net_hdr->gso_type = VIRTIO_NET_HDR_GSO_TCPV4;
230                 else
231                         net_hdr->gso_type = VIRTIO_NET_HDR_GSO_TCPV6;
232                 net_hdr->gso_size = m_buf->tso_segsz;
233                 net_hdr->hdr_len = m_buf->l2_len + m_buf->l3_len
234                                         + m_buf->l4_len;
235         } else {
236                 ASSIGN_UNLESS_EQUAL(net_hdr->gso_type, 0);
237                 ASSIGN_UNLESS_EQUAL(net_hdr->gso_size, 0);
238                 ASSIGN_UNLESS_EQUAL(net_hdr->hdr_len, 0);
239         }
240 }
241
242 static __rte_always_inline int
243 copy_mbuf_to_desc(struct virtio_net *dev, struct vhost_virtqueue *vq,
244                   struct vring_desc *descs, struct rte_mbuf *m,
245                   uint16_t desc_idx, uint32_t size)
246 {
247         uint32_t desc_avail, desc_offset;
248         uint32_t mbuf_avail, mbuf_offset;
249         uint32_t cpy_len;
250         uint64_t desc_chunck_len;
251         struct vring_desc *desc;
252         uint64_t desc_addr, desc_gaddr;
253         /* A counter to avoid desc dead loop chain */
254         uint16_t nr_desc = 1;
255         struct batch_copy_elem *batch_copy = vq->batch_copy_elems;
256         uint16_t copy_nb = vq->batch_copy_nb_elems;
257         int error = 0;
258
259         desc = &descs[desc_idx];
260         desc_chunck_len = desc->len;
261         desc_gaddr = desc->addr;
262         desc_addr = vhost_iova_to_vva(dev, vq, desc_gaddr,
263                                         &desc_chunck_len, VHOST_ACCESS_RW);
264         /*
265          * Checking of 'desc_addr' placed outside of 'unlikely' macro to avoid
266          * performance issue with some versions of gcc (4.8.4 and 5.3.0) which
267          * otherwise stores offset on the stack instead of in a register.
268          */
269         if (unlikely(desc->len < dev->vhost_hlen) || !desc_addr) {
270                 error = -1;
271                 goto out;
272         }
273
274         rte_prefetch0((void *)(uintptr_t)desc_addr);
275
276         if (likely(desc_chunck_len >= dev->vhost_hlen)) {
277                 virtio_enqueue_offload(m,
278                                 (struct virtio_net_hdr *)(uintptr_t)desc_addr);
279                 PRINT_PACKET(dev, (uintptr_t)desc_addr, dev->vhost_hlen, 0);
280                 vhost_log_cache_write(dev, vq, desc_gaddr, dev->vhost_hlen);
281         } else {
282                 struct virtio_net_hdr vnet_hdr;
283                 uint64_t remain = dev->vhost_hlen;
284                 uint64_t len;
285                 uint64_t src = (uint64_t)(uintptr_t)&vnet_hdr, dst;
286                 uint64_t guest_addr = desc_gaddr;
287
288                 virtio_enqueue_offload(m, &vnet_hdr);
289
290                 while (remain) {
291                         len = remain;
292                         dst = vhost_iova_to_vva(dev, vq, guest_addr,
293                                         &len, VHOST_ACCESS_RW);
294                         if (unlikely(!dst || !len)) {
295                                 error = -1;
296                                 goto out;
297                         }
298
299                         rte_memcpy((void *)(uintptr_t)dst,
300                                         (void *)(uintptr_t)src, len);
301
302                         PRINT_PACKET(dev, (uintptr_t)dst, (uint32_t)len, 0);
303                         vhost_log_cache_write(dev, vq, guest_addr, len);
304                         remain -= len;
305                         guest_addr += len;
306                         dst += len;
307                 }
308         }
309
310         desc_avail  = desc->len - dev->vhost_hlen;
311         if (unlikely(desc_chunck_len < dev->vhost_hlen)) {
312                 desc_chunck_len = desc_avail;
313                 desc_gaddr = desc->addr + dev->vhost_hlen;
314                 desc_addr = vhost_iova_to_vva(dev,
315                                 vq, desc_gaddr,
316                                 &desc_chunck_len,
317                                 VHOST_ACCESS_RW);
318                 if (unlikely(!desc_addr)) {
319                         error = -1;
320                         goto out;
321                 }
322
323                 desc_offset = 0;
324         } else {
325                 desc_offset = dev->vhost_hlen;
326                 desc_chunck_len -= dev->vhost_hlen;
327         }
328
329         mbuf_avail  = rte_pktmbuf_data_len(m);
330         mbuf_offset = 0;
331         while (mbuf_avail != 0 || m->next != NULL) {
332                 /* done with current mbuf, fetch next */
333                 if (mbuf_avail == 0) {
334                         m = m->next;
335
336                         mbuf_offset = 0;
337                         mbuf_avail  = rte_pktmbuf_data_len(m);
338                 }
339
340                 /* done with current desc buf, fetch next */
341                 if (desc_avail == 0) {
342                         if ((desc->flags & VRING_DESC_F_NEXT) == 0) {
343                                 /* Room in vring buffer is not enough */
344                                 error = -1;
345                                 goto out;
346                         }
347                         if (unlikely(desc->next >= size || ++nr_desc > size)) {
348                                 error = -1;
349                                 goto out;
350                         }
351
352                         desc = &descs[desc->next];
353                         desc_chunck_len = desc->len;
354                         desc_gaddr = desc->addr;
355                         desc_addr = vhost_iova_to_vva(dev, vq, desc_gaddr,
356                                                         &desc_chunck_len,
357                                                         VHOST_ACCESS_RW);
358                         if (unlikely(!desc_addr)) {
359                                 error = -1;
360                                 goto out;
361                         }
362
363                         desc_offset = 0;
364                         desc_avail  = desc->len;
365                 } else if (unlikely(desc_chunck_len == 0)) {
366                         desc_chunck_len = desc_avail;
367                         desc_gaddr += desc_offset;
368                         desc_addr = vhost_iova_to_vva(dev,
369                                         vq, desc_gaddr,
370                                         &desc_chunck_len, VHOST_ACCESS_RW);
371                         if (unlikely(!desc_addr)) {
372                                 error = -1;
373                                 goto out;
374                         }
375                         desc_offset = 0;
376                 }
377
378                 cpy_len = RTE_MIN(desc_chunck_len, mbuf_avail);
379                 if (likely(cpy_len > MAX_BATCH_LEN || copy_nb >= vq->size)) {
380                         rte_memcpy((void *)((uintptr_t)(desc_addr +
381                                                         desc_offset)),
382                                 rte_pktmbuf_mtod_offset(m, void *, mbuf_offset),
383                                 cpy_len);
384                         vhost_log_cache_write(dev, vq, desc_gaddr + desc_offset,
385                                         cpy_len);
386                         PRINT_PACKET(dev, (uintptr_t)(desc_addr + desc_offset),
387                                      cpy_len, 0);
388                 } else {
389                         batch_copy[copy_nb].dst =
390                                 (void *)((uintptr_t)(desc_addr + desc_offset));
391                         batch_copy[copy_nb].src =
392                                 rte_pktmbuf_mtod_offset(m, void *, mbuf_offset);
393                         batch_copy[copy_nb].log_addr = desc_gaddr + desc_offset;
394                         batch_copy[copy_nb].len = cpy_len;
395                         copy_nb++;
396                 }
397
398                 mbuf_avail  -= cpy_len;
399                 mbuf_offset += cpy_len;
400                 desc_avail  -= cpy_len;
401                 desc_offset += cpy_len;
402                 desc_chunck_len -= cpy_len;
403         }
404
405 out:
406         vq->batch_copy_nb_elems = copy_nb;
407
408         return error;
409 }
410
411 /**
412  * This function adds buffers to the virtio devices RX virtqueue. Buffers can
413  * be received from the physical port or from another virtio device. A packet
414  * count is returned to indicate the number of packets that are successfully
415  * added to the RX queue. This function works when the mbuf is scattered, but
416  * it doesn't support the mergeable feature.
417  */
418 static __rte_always_inline uint32_t
419 virtio_dev_rx(struct virtio_net *dev, uint16_t queue_id,
420               struct rte_mbuf **pkts, uint32_t count)
421 {
422         struct vhost_virtqueue *vq;
423         uint16_t avail_idx, free_entries, start_idx;
424         uint16_t desc_indexes[MAX_PKT_BURST];
425         struct vring_desc *descs;
426         uint16_t used_idx;
427         uint32_t i, sz;
428
429         LOG_DEBUG(VHOST_DATA, "(%d) %s\n", dev->vid, __func__);
430         if (unlikely(!is_valid_virt_queue_idx(queue_id, 0, dev->nr_vring))) {
431                 RTE_LOG(ERR, VHOST_DATA, "(%d) %s: invalid virtqueue idx %d.\n",
432                         dev->vid, __func__, queue_id);
433                 return 0;
434         }
435
436         vq = dev->virtqueue[queue_id];
437
438         rte_spinlock_lock(&vq->access_lock);
439
440         if (unlikely(vq->enabled == 0))
441                 goto out_access_unlock;
442
443         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
444                 vhost_user_iotlb_rd_lock(vq);
445
446         if (unlikely(vq->access_ok == 0)) {
447                 if (unlikely(vring_translate(dev, vq) < 0)) {
448                         count = 0;
449                         goto out;
450                 }
451         }
452
453         avail_idx = *((volatile uint16_t *)&vq->avail->idx);
454         start_idx = vq->last_used_idx;
455         free_entries = avail_idx - start_idx;
456         count = RTE_MIN(count, free_entries);
457         count = RTE_MIN(count, (uint32_t)MAX_PKT_BURST);
458         if (count == 0)
459                 goto out;
460
461         LOG_DEBUG(VHOST_DATA, "(%d) start_idx %d | end_idx %d\n",
462                 dev->vid, start_idx, start_idx + count);
463
464         vq->batch_copy_nb_elems = 0;
465
466         /* Retrieve all of the desc indexes first to avoid caching issues. */
467         rte_prefetch0(&vq->avail->ring[start_idx & (vq->size - 1)]);
468         for (i = 0; i < count; i++) {
469                 used_idx = (start_idx + i) & (vq->size - 1);
470                 desc_indexes[i] = vq->avail->ring[used_idx];
471                 vq->used->ring[used_idx].id = desc_indexes[i];
472                 vq->used->ring[used_idx].len = pkts[i]->pkt_len +
473                                                dev->vhost_hlen;
474                 vhost_log_cache_used_vring(dev, vq,
475                         offsetof(struct vring_used, ring[used_idx]),
476                         sizeof(vq->used->ring[used_idx]));
477         }
478
479         rte_prefetch0(&vq->desc[desc_indexes[0]]);
480         for (i = 0; i < count; i++) {
481                 struct vring_desc *idesc = NULL;
482                 uint16_t desc_idx = desc_indexes[i];
483                 int err;
484
485                 if (vq->desc[desc_idx].flags & VRING_DESC_F_INDIRECT) {
486                         uint64_t dlen = vq->desc[desc_idx].len;
487                         descs = (struct vring_desc *)(uintptr_t)
488                                 vhost_iova_to_vva(dev,
489                                                 vq, vq->desc[desc_idx].addr,
490                                                 &dlen, VHOST_ACCESS_RO);
491                         if (unlikely(!descs)) {
492                                 count = i;
493                                 break;
494                         }
495
496                         if (unlikely(dlen < vq->desc[desc_idx].len)) {
497                                 /*
498                                  * The indirect desc table is not contiguous
499                                  * in process VA space, we have to copy it.
500                                  */
501                                 idesc = alloc_copy_ind_table(dev, vq,
502                                                         &vq->desc[desc_idx]);
503                                 if (unlikely(!idesc))
504                                         break;
505
506                                 descs = idesc;
507                         }
508
509                         desc_idx = 0;
510                         sz = vq->desc[desc_idx].len / sizeof(*descs);
511                 } else {
512                         descs = vq->desc;
513                         sz = vq->size;
514                 }
515
516                 err = copy_mbuf_to_desc(dev, vq, descs, pkts[i], desc_idx, sz);
517                 if (unlikely(err)) {
518                         count = i;
519                         free_ind_table(idesc);
520                         break;
521                 }
522
523                 if (i + 1 < count)
524                         rte_prefetch0(&vq->desc[desc_indexes[i+1]]);
525
526                 if (unlikely(!!idesc))
527                         free_ind_table(idesc);
528         }
529
530         do_data_copy_enqueue(dev, vq);
531
532         rte_smp_wmb();
533
534         vhost_log_cache_sync(dev, vq);
535
536         *(volatile uint16_t *)&vq->used->idx += count;
537         vq->last_used_idx += count;
538         vhost_log_used_vring(dev, vq,
539                 offsetof(struct vring_used, idx),
540                 sizeof(vq->used->idx));
541
542         /* flush used->idx update before we read avail->flags. */
543         rte_mb();
544
545         /* Kick the guest if necessary. */
546         if (!(vq->avail->flags & VRING_AVAIL_F_NO_INTERRUPT)
547                         && (vq->callfd >= 0))
548                 eventfd_write(vq->callfd, (eventfd_t)1);
549 out:
550         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
551                 vhost_user_iotlb_rd_unlock(vq);
552
553 out_access_unlock:
554         rte_spinlock_unlock(&vq->access_lock);
555
556         return count;
557 }
558
559 static __rte_always_inline int
560 fill_vec_buf(struct virtio_net *dev, struct vhost_virtqueue *vq,
561                          uint32_t avail_idx, uint32_t *vec_idx,
562                          struct buf_vector *buf_vec, uint16_t *desc_chain_head,
563                          uint16_t *desc_chain_len)
564 {
565         uint16_t idx = vq->avail->ring[avail_idx & (vq->size - 1)];
566         uint32_t vec_id = *vec_idx;
567         uint32_t len    = 0;
568         uint64_t dlen;
569         struct vring_desc *descs = vq->desc;
570         struct vring_desc *idesc = NULL;
571
572         *desc_chain_head = idx;
573
574         if (vq->desc[idx].flags & VRING_DESC_F_INDIRECT) {
575                 dlen = vq->desc[idx].len;
576                 descs = (struct vring_desc *)(uintptr_t)
577                         vhost_iova_to_vva(dev, vq, vq->desc[idx].addr,
578                                                 &dlen,
579                                                 VHOST_ACCESS_RO);
580                 if (unlikely(!descs))
581                         return -1;
582
583                 if (unlikely(dlen < vq->desc[idx].len)) {
584                         /*
585                          * The indirect desc table is not contiguous
586                          * in process VA space, we have to copy it.
587                          */
588                         idesc = alloc_copy_ind_table(dev, vq, &vq->desc[idx]);
589                         if (unlikely(!idesc))
590                                 return -1;
591
592                         descs = idesc;
593                 }
594
595                 idx = 0;
596         }
597
598         while (1) {
599                 if (unlikely(vec_id >= BUF_VECTOR_MAX || idx >= vq->size)) {
600                         free_ind_table(idesc);
601                         return -1;
602                 }
603
604                 len += descs[idx].len;
605                 buf_vec[vec_id].buf_addr = descs[idx].addr;
606                 buf_vec[vec_id].buf_len  = descs[idx].len;
607                 buf_vec[vec_id].desc_idx = idx;
608                 vec_id++;
609
610                 if ((descs[idx].flags & VRING_DESC_F_NEXT) == 0)
611                         break;
612
613                 idx = descs[idx].next;
614         }
615
616         *desc_chain_len = len;
617         *vec_idx = vec_id;
618
619         if (unlikely(!!idesc))
620                 free_ind_table(idesc);
621
622         return 0;
623 }
624
625 /*
626  * Returns -1 on fail, 0 on success
627  */
628 static inline int
629 reserve_avail_buf_mergeable(struct virtio_net *dev, struct vhost_virtqueue *vq,
630                                 uint32_t size, struct buf_vector *buf_vec,
631                                 uint16_t *num_buffers, uint16_t avail_head)
632 {
633         uint16_t cur_idx;
634         uint32_t vec_idx = 0;
635         uint16_t tries = 0;
636
637         uint16_t head_idx = 0;
638         uint16_t len = 0;
639
640         *num_buffers = 0;
641         cur_idx  = vq->last_avail_idx;
642
643         while (size > 0) {
644                 if (unlikely(cur_idx == avail_head))
645                         return -1;
646
647                 if (unlikely(fill_vec_buf(dev, vq, cur_idx, &vec_idx, buf_vec,
648                                                 &head_idx, &len) < 0))
649                         return -1;
650                 len = RTE_MIN(len, size);
651                 update_shadow_used_ring(vq, head_idx, len);
652                 size -= len;
653
654                 cur_idx++;
655                 tries++;
656                 *num_buffers += 1;
657
658                 /*
659                  * if we tried all available ring items, and still
660                  * can't get enough buf, it means something abnormal
661                  * happened.
662                  */
663                 if (unlikely(tries >= vq->size))
664                         return -1;
665         }
666
667         return 0;
668 }
669
670 static __rte_always_inline int
671 copy_mbuf_to_desc_mergeable(struct virtio_net *dev, struct vhost_virtqueue *vq,
672                             struct rte_mbuf *m, struct buf_vector *buf_vec,
673                             uint16_t num_buffers)
674 {
675         uint32_t vec_idx = 0;
676         uint64_t desc_addr, desc_gaddr;
677         uint32_t mbuf_offset, mbuf_avail;
678         uint32_t desc_offset, desc_avail;
679         uint32_t cpy_len;
680         uint64_t desc_chunck_len;
681         uint64_t hdr_addr, hdr_phys_addr;
682         struct rte_mbuf *hdr_mbuf;
683         struct batch_copy_elem *batch_copy = vq->batch_copy_elems;
684         struct virtio_net_hdr_mrg_rxbuf tmp_hdr, *hdr = NULL;
685         uint16_t copy_nb = vq->batch_copy_nb_elems;
686         int error = 0;
687
688         if (unlikely(m == NULL)) {
689                 error = -1;
690                 goto out;
691         }
692
693         desc_chunck_len = buf_vec[vec_idx].buf_len;
694         desc_gaddr = buf_vec[vec_idx].buf_addr;
695         desc_addr = vhost_iova_to_vva(dev, vq,
696                                         desc_gaddr,
697                                         &desc_chunck_len,
698                                         VHOST_ACCESS_RW);
699         if (buf_vec[vec_idx].buf_len < dev->vhost_hlen || !desc_addr) {
700                 error = -1;
701                 goto out;
702         }
703
704         hdr_mbuf = m;
705         hdr_addr = desc_addr;
706         if (unlikely(desc_chunck_len < dev->vhost_hlen))
707                 hdr = &tmp_hdr;
708         else
709                 hdr = (struct virtio_net_hdr_mrg_rxbuf *)(uintptr_t)hdr_addr;
710         hdr_phys_addr = desc_gaddr;
711         rte_prefetch0((void *)(uintptr_t)hdr_addr);
712
713         LOG_DEBUG(VHOST_DATA, "(%d) RX: num merge buffers %d\n",
714                 dev->vid, num_buffers);
715
716         desc_avail  = buf_vec[vec_idx].buf_len - dev->vhost_hlen;
717         if (unlikely(desc_chunck_len < dev->vhost_hlen)) {
718                 desc_chunck_len = desc_avail;
719                 desc_gaddr += dev->vhost_hlen;
720                 desc_addr = vhost_iova_to_vva(dev, vq,
721                                 desc_gaddr,
722                                 &desc_chunck_len,
723                                 VHOST_ACCESS_RW);
724                 if (unlikely(!desc_addr)) {
725                         error = -1;
726                         goto out;
727                 }
728
729                 desc_offset = 0;
730         } else {
731                 desc_offset = dev->vhost_hlen;
732                 desc_chunck_len -= dev->vhost_hlen;
733         }
734
735
736         mbuf_avail  = rte_pktmbuf_data_len(m);
737         mbuf_offset = 0;
738         while (mbuf_avail != 0 || m->next != NULL) {
739                 /* done with current desc buf, get the next one */
740                 if (desc_avail == 0) {
741                         vec_idx++;
742                         desc_chunck_len = buf_vec[vec_idx].buf_len;
743                         desc_gaddr = buf_vec[vec_idx].buf_addr;
744                         desc_addr =
745                                 vhost_iova_to_vva(dev, vq,
746                                         desc_gaddr,
747                                         &desc_chunck_len,
748                                         VHOST_ACCESS_RW);
749                         if (unlikely(!desc_addr)) {
750                                 error = -1;
751                                 goto out;
752                         }
753
754                         /* Prefetch buffer address. */
755                         rte_prefetch0((void *)(uintptr_t)desc_addr);
756                         desc_offset = 0;
757                         desc_avail  = buf_vec[vec_idx].buf_len;
758                 } else if (unlikely(desc_chunck_len == 0)) {
759                         desc_chunck_len = desc_avail;
760                         desc_gaddr += desc_offset;
761                         desc_addr = vhost_iova_to_vva(dev, vq,
762                                         desc_gaddr,
763                                         &desc_chunck_len, VHOST_ACCESS_RW);
764                         if (unlikely(!desc_addr)) {
765                                 error = -1;
766                                 goto out;
767                         }
768                         desc_offset = 0;
769                 }
770
771                 /* done with current mbuf, get the next one */
772                 if (mbuf_avail == 0) {
773                         m = m->next;
774
775                         mbuf_offset = 0;
776                         mbuf_avail  = rte_pktmbuf_data_len(m);
777                 }
778
779                 if (hdr_addr) {
780                         virtio_enqueue_offload(hdr_mbuf, &hdr->hdr);
781                         ASSIGN_UNLESS_EQUAL(hdr->num_buffers, num_buffers);
782
783                         if (unlikely(hdr == &tmp_hdr)) {
784                                 uint64_t len;
785                                 uint64_t remain = dev->vhost_hlen;
786                                 uint64_t src = (uint64_t)(uintptr_t)hdr, dst;
787                                 uint64_t guest_addr = hdr_phys_addr;
788
789                                 while (remain) {
790                                         len = remain;
791                                         dst = vhost_iova_to_vva(dev, vq,
792                                                         guest_addr, &len,
793                                                         VHOST_ACCESS_RW);
794                                         if (unlikely(!dst || !len)) {
795                                                 error = -1;
796                                                 goto out;
797                                         }
798
799                                         rte_memcpy((void *)(uintptr_t)dst,
800                                                         (void *)(uintptr_t)src,
801                                                         len);
802
803                                         PRINT_PACKET(dev, (uintptr_t)dst,
804                                                         (uint32_t)len, 0);
805                                         vhost_log_cache_write(dev, vq,
806                                                         guest_addr, len);
807
808                                         remain -= len;
809                                         guest_addr += len;
810                                         dst += len;
811                                 }
812                         } else {
813                                 PRINT_PACKET(dev, (uintptr_t)hdr_addr,
814                                                 dev->vhost_hlen, 0);
815                                 vhost_log_cache_write(dev, vq, hdr_phys_addr,
816                                                 dev->vhost_hlen);
817                         }
818
819                         hdr_addr = 0;
820                 }
821
822                 cpy_len = RTE_MIN(desc_chunck_len, mbuf_avail);
823
824                 if (likely(cpy_len > MAX_BATCH_LEN || copy_nb >= vq->size)) {
825                         rte_memcpy((void *)((uintptr_t)(desc_addr +
826                                                         desc_offset)),
827                                 rte_pktmbuf_mtod_offset(m, void *, mbuf_offset),
828                                 cpy_len);
829                         vhost_log_cache_write(dev, vq, desc_gaddr + desc_offset,
830                                         cpy_len);
831                         PRINT_PACKET(dev, (uintptr_t)(desc_addr + desc_offset),
832                                 cpy_len, 0);
833                 } else {
834                         batch_copy[copy_nb].dst =
835                                 (void *)((uintptr_t)(desc_addr + desc_offset));
836                         batch_copy[copy_nb].src =
837                                 rte_pktmbuf_mtod_offset(m, void *, mbuf_offset);
838                         batch_copy[copy_nb].log_addr = desc_gaddr + desc_offset;
839                         batch_copy[copy_nb].len = cpy_len;
840                         copy_nb++;
841                 }
842
843                 mbuf_avail  -= cpy_len;
844                 mbuf_offset += cpy_len;
845                 desc_avail  -= cpy_len;
846                 desc_offset += cpy_len;
847                 desc_chunck_len -= cpy_len;
848         }
849
850 out:
851         vq->batch_copy_nb_elems = copy_nb;
852
853         return error;
854 }
855
856 static __rte_always_inline uint32_t
857 virtio_dev_merge_rx(struct virtio_net *dev, uint16_t queue_id,
858         struct rte_mbuf **pkts, uint32_t count)
859 {
860         struct vhost_virtqueue *vq;
861         uint32_t pkt_idx = 0;
862         uint16_t num_buffers;
863         struct buf_vector buf_vec[BUF_VECTOR_MAX];
864         uint16_t avail_head;
865
866         LOG_DEBUG(VHOST_DATA, "(%d) %s\n", dev->vid, __func__);
867         if (unlikely(!is_valid_virt_queue_idx(queue_id, 0, dev->nr_vring))) {
868                 RTE_LOG(ERR, VHOST_DATA, "(%d) %s: invalid virtqueue idx %d.\n",
869                         dev->vid, __func__, queue_id);
870                 return 0;
871         }
872
873         vq = dev->virtqueue[queue_id];
874
875         rte_spinlock_lock(&vq->access_lock);
876
877         if (unlikely(vq->enabled == 0))
878                 goto out_access_unlock;
879
880         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
881                 vhost_user_iotlb_rd_lock(vq);
882
883         if (unlikely(vq->access_ok == 0))
884                 if (unlikely(vring_translate(dev, vq) < 0))
885                         goto out;
886
887         count = RTE_MIN((uint32_t)MAX_PKT_BURST, count);
888         if (count == 0)
889                 goto out;
890
891         vq->batch_copy_nb_elems = 0;
892
893         rte_prefetch0(&vq->avail->ring[vq->last_avail_idx & (vq->size - 1)]);
894
895         vq->shadow_used_idx = 0;
896         avail_head = *((volatile uint16_t *)&vq->avail->idx);
897         for (pkt_idx = 0; pkt_idx < count; pkt_idx++) {
898                 uint32_t pkt_len = pkts[pkt_idx]->pkt_len + dev->vhost_hlen;
899
900                 if (unlikely(reserve_avail_buf_mergeable(dev, vq,
901                                                 pkt_len, buf_vec, &num_buffers,
902                                                 avail_head) < 0)) {
903                         LOG_DEBUG(VHOST_DATA,
904                                 "(%d) failed to get enough desc from vring\n",
905                                 dev->vid);
906                         vq->shadow_used_idx -= num_buffers;
907                         break;
908                 }
909
910                 LOG_DEBUG(VHOST_DATA, "(%d) current index %d | end index %d\n",
911                         dev->vid, vq->last_avail_idx,
912                         vq->last_avail_idx + num_buffers);
913
914                 if (copy_mbuf_to_desc_mergeable(dev, vq, pkts[pkt_idx],
915                                                 buf_vec, num_buffers) < 0) {
916                         vq->shadow_used_idx -= num_buffers;
917                         break;
918                 }
919
920                 vq->last_avail_idx += num_buffers;
921         }
922
923         do_data_copy_enqueue(dev, vq);
924
925         if (likely(vq->shadow_used_idx)) {
926                 flush_shadow_used_ring(dev, vq);
927
928                 /* flush used->idx update before we read avail->flags. */
929                 rte_mb();
930
931                 /* Kick the guest if necessary. */
932                 if (!(vq->avail->flags & VRING_AVAIL_F_NO_INTERRUPT)
933                                 && (vq->callfd >= 0))
934                         eventfd_write(vq->callfd, (eventfd_t)1);
935         }
936
937 out:
938         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
939                 vhost_user_iotlb_rd_unlock(vq);
940
941 out_access_unlock:
942         rte_spinlock_unlock(&vq->access_lock);
943
944         return pkt_idx;
945 }
946
947 uint16_t
948 rte_vhost_enqueue_burst(int vid, uint16_t queue_id,
949         struct rte_mbuf **pkts, uint16_t count)
950 {
951         struct virtio_net *dev = get_device(vid);
952
953         if (!dev)
954                 return 0;
955
956         if (dev->features & (1 << VIRTIO_NET_F_MRG_RXBUF))
957                 return virtio_dev_merge_rx(dev, queue_id, pkts, count);
958         else
959                 return virtio_dev_rx(dev, queue_id, pkts, count);
960 }
961
962 static inline bool
963 virtio_net_with_host_offload(struct virtio_net *dev)
964 {
965         if (dev->features &
966                         ((1ULL << VIRTIO_NET_F_CSUM) |
967                          (1ULL << VIRTIO_NET_F_HOST_ECN) |
968                          (1ULL << VIRTIO_NET_F_HOST_TSO4) |
969                          (1ULL << VIRTIO_NET_F_HOST_TSO6) |
970                          (1ULL << VIRTIO_NET_F_HOST_UFO)))
971                 return true;
972
973         return false;
974 }
975
976 static void
977 parse_ethernet(struct rte_mbuf *m, uint16_t *l4_proto, void **l4_hdr)
978 {
979         struct ipv4_hdr *ipv4_hdr;
980         struct ipv6_hdr *ipv6_hdr;
981         void *l3_hdr = NULL;
982         struct ether_hdr *eth_hdr;
983         uint16_t ethertype;
984
985         eth_hdr = rte_pktmbuf_mtod(m, struct ether_hdr *);
986
987         m->l2_len = sizeof(struct ether_hdr);
988         ethertype = rte_be_to_cpu_16(eth_hdr->ether_type);
989
990         if (ethertype == ETHER_TYPE_VLAN) {
991                 struct vlan_hdr *vlan_hdr = (struct vlan_hdr *)(eth_hdr + 1);
992
993                 m->l2_len += sizeof(struct vlan_hdr);
994                 ethertype = rte_be_to_cpu_16(vlan_hdr->eth_proto);
995         }
996
997         l3_hdr = (char *)eth_hdr + m->l2_len;
998
999         switch (ethertype) {
1000         case ETHER_TYPE_IPv4:
1001                 ipv4_hdr = l3_hdr;
1002                 *l4_proto = ipv4_hdr->next_proto_id;
1003                 m->l3_len = (ipv4_hdr->version_ihl & 0x0f) * 4;
1004                 *l4_hdr = (char *)l3_hdr + m->l3_len;
1005                 m->ol_flags |= PKT_TX_IPV4;
1006                 break;
1007         case ETHER_TYPE_IPv6:
1008                 ipv6_hdr = l3_hdr;
1009                 *l4_proto = ipv6_hdr->proto;
1010                 m->l3_len = sizeof(struct ipv6_hdr);
1011                 *l4_hdr = (char *)l3_hdr + m->l3_len;
1012                 m->ol_flags |= PKT_TX_IPV6;
1013                 break;
1014         default:
1015                 m->l3_len = 0;
1016                 *l4_proto = 0;
1017                 *l4_hdr = NULL;
1018                 break;
1019         }
1020 }
1021
1022 static __rte_always_inline void
1023 vhost_dequeue_offload(struct virtio_net_hdr *hdr, struct rte_mbuf *m)
1024 {
1025         uint16_t l4_proto = 0;
1026         void *l4_hdr = NULL;
1027         struct tcp_hdr *tcp_hdr = NULL;
1028
1029         if (hdr->flags == 0 && hdr->gso_type == VIRTIO_NET_HDR_GSO_NONE)
1030                 return;
1031
1032         parse_ethernet(m, &l4_proto, &l4_hdr);
1033         if (hdr->flags == VIRTIO_NET_HDR_F_NEEDS_CSUM) {
1034                 if (hdr->csum_start == (m->l2_len + m->l3_len)) {
1035                         switch (hdr->csum_offset) {
1036                         case (offsetof(struct tcp_hdr, cksum)):
1037                                 if (l4_proto == IPPROTO_TCP)
1038                                         m->ol_flags |= PKT_TX_TCP_CKSUM;
1039                                 break;
1040                         case (offsetof(struct udp_hdr, dgram_cksum)):
1041                                 if (l4_proto == IPPROTO_UDP)
1042                                         m->ol_flags |= PKT_TX_UDP_CKSUM;
1043                                 break;
1044                         case (offsetof(struct sctp_hdr, cksum)):
1045                                 if (l4_proto == IPPROTO_SCTP)
1046                                         m->ol_flags |= PKT_TX_SCTP_CKSUM;
1047                                 break;
1048                         default:
1049                                 break;
1050                         }
1051                 }
1052         }
1053
1054         if (l4_hdr && hdr->gso_type != VIRTIO_NET_HDR_GSO_NONE) {
1055                 switch (hdr->gso_type & ~VIRTIO_NET_HDR_GSO_ECN) {
1056                 case VIRTIO_NET_HDR_GSO_TCPV4:
1057                 case VIRTIO_NET_HDR_GSO_TCPV6:
1058                         tcp_hdr = l4_hdr;
1059                         m->ol_flags |= PKT_TX_TCP_SEG;
1060                         m->tso_segsz = hdr->gso_size;
1061                         m->l4_len = (tcp_hdr->data_off & 0xf0) >> 2;
1062                         break;
1063                 default:
1064                         RTE_LOG(WARNING, VHOST_DATA,
1065                                 "unsupported gso type %u.\n", hdr->gso_type);
1066                         break;
1067                 }
1068         }
1069 }
1070
1071 #define RARP_PKT_SIZE   64
1072
1073 static int
1074 make_rarp_packet(struct rte_mbuf *rarp_mbuf, const struct ether_addr *mac)
1075 {
1076         struct ether_hdr *eth_hdr;
1077         struct arp_hdr  *rarp;
1078
1079         if (rarp_mbuf->buf_len < 64) {
1080                 RTE_LOG(WARNING, VHOST_DATA,
1081                         "failed to make RARP; mbuf size too small %u (< %d)\n",
1082                         rarp_mbuf->buf_len, RARP_PKT_SIZE);
1083                 return -1;
1084         }
1085
1086         /* Ethernet header. */
1087         eth_hdr = rte_pktmbuf_mtod_offset(rarp_mbuf, struct ether_hdr *, 0);
1088         memset(eth_hdr->d_addr.addr_bytes, 0xff, ETHER_ADDR_LEN);
1089         ether_addr_copy(mac, &eth_hdr->s_addr);
1090         eth_hdr->ether_type = htons(ETHER_TYPE_RARP);
1091
1092         /* RARP header. */
1093         rarp = (struct arp_hdr *)(eth_hdr + 1);
1094         rarp->arp_hrd = htons(ARP_HRD_ETHER);
1095         rarp->arp_pro = htons(ETHER_TYPE_IPv4);
1096         rarp->arp_hln = ETHER_ADDR_LEN;
1097         rarp->arp_pln = 4;
1098         rarp->arp_op  = htons(ARP_OP_REVREQUEST);
1099
1100         ether_addr_copy(mac, &rarp->arp_data.arp_sha);
1101         ether_addr_copy(mac, &rarp->arp_data.arp_tha);
1102         memset(&rarp->arp_data.arp_sip, 0x00, 4);
1103         memset(&rarp->arp_data.arp_tip, 0x00, 4);
1104
1105         rarp_mbuf->pkt_len  = rarp_mbuf->data_len = RARP_PKT_SIZE;
1106
1107         return 0;
1108 }
1109
1110 static __rte_always_inline void
1111 put_zmbuf(struct zcopy_mbuf *zmbuf)
1112 {
1113         zmbuf->in_use = 0;
1114 }
1115
1116 static __rte_always_inline int
1117 copy_desc_to_mbuf(struct virtio_net *dev, struct vhost_virtqueue *vq,
1118                   struct vring_desc *descs, uint16_t max_desc,
1119                   struct rte_mbuf *m, uint16_t desc_idx,
1120                   struct rte_mempool *mbuf_pool)
1121 {
1122         struct vring_desc *desc;
1123         uint64_t desc_addr, desc_gaddr;
1124         uint32_t desc_avail, desc_offset;
1125         uint32_t mbuf_avail, mbuf_offset;
1126         uint32_t cpy_len;
1127         uint64_t desc_chunck_len;
1128         struct rte_mbuf *cur = m, *prev = m;
1129         struct virtio_net_hdr tmp_hdr;
1130         struct virtio_net_hdr *hdr = NULL;
1131         /* A counter to avoid desc dead loop chain */
1132         uint32_t nr_desc = 1;
1133         struct batch_copy_elem *batch_copy = vq->batch_copy_elems;
1134         uint16_t copy_nb = vq->batch_copy_nb_elems;
1135         int error = 0;
1136
1137         desc = &descs[desc_idx];
1138         if (unlikely((desc->len < dev->vhost_hlen)) ||
1139                         (desc->flags & VRING_DESC_F_INDIRECT)) {
1140                 error = -1;
1141                 goto out;
1142         }
1143
1144         desc_chunck_len = desc->len;
1145         desc_gaddr = desc->addr;
1146         desc_addr = vhost_iova_to_vva(dev,
1147                                         vq, desc_gaddr,
1148                                         &desc_chunck_len,
1149                                         VHOST_ACCESS_RO);
1150         if (unlikely(!desc_addr)) {
1151                 error = -1;
1152                 goto out;
1153         }
1154
1155         if (virtio_net_with_host_offload(dev)) {
1156                 if (unlikely(desc_chunck_len < sizeof(struct virtio_net_hdr))) {
1157                         uint64_t len = desc_chunck_len;
1158                         uint64_t remain = sizeof(struct virtio_net_hdr);
1159                         uint64_t src = desc_addr;
1160                         uint64_t dst = (uint64_t)(uintptr_t)&tmp_hdr;
1161                         uint64_t guest_addr = desc_gaddr;
1162
1163                         /*
1164                          * No luck, the virtio-net header doesn't fit
1165                          * in a contiguous virtual area.
1166                          */
1167                         while (remain) {
1168                                 len = remain;
1169                                 src = vhost_iova_to_vva(dev, vq,
1170                                                 guest_addr, &len,
1171                                                 VHOST_ACCESS_RO);
1172                                 if (unlikely(!src || !len)) {
1173                                         error = -1;
1174                                         goto out;
1175                                 }
1176
1177                                 rte_memcpy((void *)(uintptr_t)dst,
1178                                                    (void *)(uintptr_t)src, len);
1179
1180                                 guest_addr += len;
1181                                 remain -= len;
1182                                 dst += len;
1183                         }
1184
1185                         hdr = &tmp_hdr;
1186                 } else {
1187                         hdr = (struct virtio_net_hdr *)((uintptr_t)desc_addr);
1188                         rte_prefetch0(hdr);
1189                 }
1190         }
1191
1192         /*
1193          * A virtio driver normally uses at least 2 desc buffers
1194          * for Tx: the first for storing the header, and others
1195          * for storing the data.
1196          */
1197         if (likely((desc->len == dev->vhost_hlen) &&
1198                    (desc->flags & VRING_DESC_F_NEXT) != 0)) {
1199                 desc = &descs[desc->next];
1200                 if (unlikely(desc->flags & VRING_DESC_F_INDIRECT)) {
1201                         error = -1;
1202                         goto out;
1203                 }
1204
1205                 desc_chunck_len = desc->len;
1206                 desc_gaddr = desc->addr;
1207                 desc_addr = vhost_iova_to_vva(dev,
1208                                                         vq, desc_gaddr,
1209                                                         &desc_chunck_len,
1210                                                         VHOST_ACCESS_RO);
1211                 if (unlikely(!desc_addr)) {
1212                         error = -1;
1213                         goto out;
1214                 }
1215
1216                 desc_offset = 0;
1217                 desc_avail  = desc->len;
1218                 nr_desc    += 1;
1219         } else {
1220                 desc_avail  = desc->len - dev->vhost_hlen;
1221
1222                 if (unlikely(desc_chunck_len < dev->vhost_hlen)) {
1223                         desc_chunck_len = desc_avail;
1224                         desc_gaddr += dev->vhost_hlen;
1225                         desc_addr = vhost_iova_to_vva(dev,
1226                                         vq, desc_gaddr,
1227                                         &desc_chunck_len,
1228                                         VHOST_ACCESS_RO);
1229                         if (unlikely(!desc_addr)) {
1230                                 error = -1;
1231                                 goto out;
1232                         }
1233
1234                         desc_offset = 0;
1235                 } else {
1236                         desc_offset = dev->vhost_hlen;
1237                         desc_chunck_len -= dev->vhost_hlen;
1238                 }
1239         }
1240
1241         rte_prefetch0((void *)(uintptr_t)(desc_addr + desc_offset));
1242
1243         PRINT_PACKET(dev, (uintptr_t)(desc_addr + desc_offset),
1244                         (uint32_t)desc_chunck_len, 0);
1245
1246         mbuf_offset = 0;
1247         mbuf_avail  = m->buf_len - RTE_PKTMBUF_HEADROOM;
1248         while (1) {
1249                 uint64_t hpa;
1250
1251                 cpy_len = RTE_MIN(desc_chunck_len, mbuf_avail);
1252
1253                 /*
1254                  * A desc buf might across two host physical pages that are
1255                  * not continuous. In such case (gpa_to_hpa returns 0), data
1256                  * will be copied even though zero copy is enabled.
1257                  */
1258                 if (unlikely(dev->dequeue_zero_copy && (hpa = gpa_to_hpa(dev,
1259                                         desc_gaddr + desc_offset, cpy_len)))) {
1260                         cur->data_len = cpy_len;
1261                         cur->data_off = 0;
1262                         cur->buf_addr = (void *)(uintptr_t)(desc_addr
1263                                 + desc_offset);
1264                         cur->buf_iova = hpa;
1265
1266                         /*
1267                          * In zero copy mode, one mbuf can only reference data
1268                          * for one or partial of one desc buff.
1269                          */
1270                         mbuf_avail = cpy_len;
1271                 } else {
1272                         if (likely(cpy_len > MAX_BATCH_LEN ||
1273                                    copy_nb >= vq->size ||
1274                                    (hdr && cur == m) ||
1275                                    desc->len != desc_chunck_len)) {
1276                                 rte_memcpy(rte_pktmbuf_mtod_offset(cur, void *,
1277                                                                    mbuf_offset),
1278                                            (void *)((uintptr_t)(desc_addr +
1279                                                                 desc_offset)),
1280                                            cpy_len);
1281                         } else {
1282                                 batch_copy[copy_nb].dst =
1283                                         rte_pktmbuf_mtod_offset(cur, void *,
1284                                                                 mbuf_offset);
1285                                 batch_copy[copy_nb].src =
1286                                         (void *)((uintptr_t)(desc_addr +
1287                                                              desc_offset));
1288                                 batch_copy[copy_nb].len = cpy_len;
1289                                 copy_nb++;
1290                         }
1291                 }
1292
1293                 mbuf_avail  -= cpy_len;
1294                 mbuf_offset += cpy_len;
1295                 desc_avail  -= cpy_len;
1296                 desc_chunck_len -= cpy_len;
1297                 desc_offset += cpy_len;
1298
1299                 /* This desc reaches to its end, get the next one */
1300                 if (desc_avail == 0) {
1301                         if ((desc->flags & VRING_DESC_F_NEXT) == 0)
1302                                 break;
1303
1304                         if (unlikely(desc->next >= max_desc ||
1305                                      ++nr_desc > max_desc)) {
1306                                 error = -1;
1307                                 goto out;
1308                         }
1309                         desc = &descs[desc->next];
1310                         if (unlikely(desc->flags & VRING_DESC_F_INDIRECT)) {
1311                                 error = -1;
1312                                 goto out;
1313                         }
1314
1315                         desc_chunck_len = desc->len;
1316                         desc_gaddr = desc->addr;
1317                         desc_addr = vhost_iova_to_vva(dev,
1318                                                         vq, desc_gaddr,
1319                                                         &desc_chunck_len,
1320                                                         VHOST_ACCESS_RO);
1321                         if (unlikely(!desc_addr)) {
1322                                 error = -1;
1323                                 goto out;
1324                         }
1325
1326                         rte_prefetch0((void *)(uintptr_t)desc_addr);
1327
1328                         desc_offset = 0;
1329                         desc_avail  = desc->len;
1330
1331                         PRINT_PACKET(dev, (uintptr_t)desc_addr,
1332                                         (uint32_t)desc_chunck_len, 0);
1333                 } else if (unlikely(desc_chunck_len == 0)) {
1334                         desc_chunck_len = desc_avail;
1335                         desc_gaddr += desc_offset;
1336                         desc_addr = vhost_iova_to_vva(dev, vq,
1337                                         desc_gaddr,
1338                                         &desc_chunck_len,
1339                                         VHOST_ACCESS_RO);
1340                         if (unlikely(!desc_addr)) {
1341                                 error = -1;
1342                                 goto out;
1343                         }
1344                         desc_offset = 0;
1345
1346                         PRINT_PACKET(dev, (uintptr_t)desc_addr,
1347                                         (uint32_t)desc_chunck_len, 0);
1348                 }
1349
1350                 /*
1351                  * This mbuf reaches to its end, get a new one
1352                  * to hold more data.
1353                  */
1354                 if (mbuf_avail == 0) {
1355                         cur = rte_pktmbuf_alloc(mbuf_pool);
1356                         if (unlikely(cur == NULL)) {
1357                                 RTE_LOG(ERR, VHOST_DATA, "Failed to "
1358                                         "allocate memory for mbuf.\n");
1359                                 error = -1;
1360                                 goto out;
1361                         }
1362                         if (unlikely(dev->dequeue_zero_copy))
1363                                 rte_mbuf_refcnt_update(cur, 1);
1364
1365                         prev->next = cur;
1366                         prev->data_len = mbuf_offset;
1367                         m->nb_segs += 1;
1368                         m->pkt_len += mbuf_offset;
1369                         prev = cur;
1370
1371                         mbuf_offset = 0;
1372                         mbuf_avail  = cur->buf_len - RTE_PKTMBUF_HEADROOM;
1373                 }
1374         }
1375
1376         prev->data_len = mbuf_offset;
1377         m->pkt_len    += mbuf_offset;
1378
1379         if (hdr)
1380                 vhost_dequeue_offload(hdr, m);
1381
1382 out:
1383         vq->batch_copy_nb_elems = copy_nb;
1384
1385         return error;
1386 }
1387
1388 static __rte_always_inline void
1389 update_used_ring(struct virtio_net *dev, struct vhost_virtqueue *vq,
1390                  uint32_t used_idx, uint32_t desc_idx)
1391 {
1392         vq->used->ring[used_idx].id  = desc_idx;
1393         vq->used->ring[used_idx].len = 0;
1394         vhost_log_cache_used_vring(dev, vq,
1395                         offsetof(struct vring_used, ring[used_idx]),
1396                         sizeof(vq->used->ring[used_idx]));
1397 }
1398
1399 static __rte_always_inline void
1400 update_used_idx(struct virtio_net *dev, struct vhost_virtqueue *vq,
1401                 uint32_t count)
1402 {
1403         if (unlikely(count == 0))
1404                 return;
1405
1406         rte_smp_wmb();
1407         rte_smp_rmb();
1408
1409         vhost_log_cache_sync(dev, vq);
1410
1411         vq->used->idx += count;
1412         vhost_log_used_vring(dev, vq, offsetof(struct vring_used, idx),
1413                         sizeof(vq->used->idx));
1414
1415         /* Kick guest if required. */
1416         if (!(vq->avail->flags & VRING_AVAIL_F_NO_INTERRUPT)
1417                         && (vq->callfd >= 0))
1418                 eventfd_write(vq->callfd, (eventfd_t)1);
1419 }
1420
1421 static __rte_always_inline struct zcopy_mbuf *
1422 get_zmbuf(struct vhost_virtqueue *vq)
1423 {
1424         uint16_t i;
1425         uint16_t last;
1426         int tries = 0;
1427
1428         /* search [last_zmbuf_idx, zmbuf_size) */
1429         i = vq->last_zmbuf_idx;
1430         last = vq->zmbuf_size;
1431
1432 again:
1433         for (; i < last; i++) {
1434                 if (vq->zmbufs[i].in_use == 0) {
1435                         vq->last_zmbuf_idx = i + 1;
1436                         vq->zmbufs[i].in_use = 1;
1437                         return &vq->zmbufs[i];
1438                 }
1439         }
1440
1441         tries++;
1442         if (tries == 1) {
1443                 /* search [0, last_zmbuf_idx) */
1444                 i = 0;
1445                 last = vq->last_zmbuf_idx;
1446                 goto again;
1447         }
1448
1449         return NULL;
1450 }
1451
1452 static __rte_always_inline bool
1453 mbuf_is_consumed(struct rte_mbuf *m)
1454 {
1455         while (m) {
1456                 if (rte_mbuf_refcnt_read(m) > 1)
1457                         return false;
1458                 m = m->next;
1459         }
1460
1461         return true;
1462 }
1463
1464 static __rte_always_inline void
1465 restore_mbuf(struct rte_mbuf *m)
1466 {
1467         uint32_t mbuf_size, priv_size;
1468
1469         while (m) {
1470                 priv_size = rte_pktmbuf_priv_size(m->pool);
1471                 mbuf_size = sizeof(struct rte_mbuf) + priv_size;
1472                 /* start of buffer is after mbuf structure and priv data */
1473
1474                 m->buf_addr = (char *)m + mbuf_size;
1475                 m->buf_iova = rte_mempool_virt2iova(m) + mbuf_size;
1476                 m = m->next;
1477         }
1478 }
1479
1480 uint16_t
1481 rte_vhost_dequeue_burst(int vid, uint16_t queue_id,
1482         struct rte_mempool *mbuf_pool, struct rte_mbuf **pkts, uint16_t count)
1483 {
1484         struct virtio_net *dev;
1485         struct rte_mbuf *rarp_mbuf = NULL;
1486         struct vhost_virtqueue *vq;
1487         uint32_t desc_indexes[MAX_PKT_BURST];
1488         uint32_t used_idx;
1489         uint32_t i = 0;
1490         uint16_t free_entries;
1491         uint16_t avail_idx;
1492
1493         dev = get_device(vid);
1494         if (!dev)
1495                 return 0;
1496
1497         if (unlikely(!is_valid_virt_queue_idx(queue_id, 1, dev->nr_vring))) {
1498                 RTE_LOG(ERR, VHOST_DATA, "(%d) %s: invalid virtqueue idx %d.\n",
1499                         dev->vid, __func__, queue_id);
1500                 return 0;
1501         }
1502
1503         vq = dev->virtqueue[queue_id];
1504
1505         if (unlikely(rte_spinlock_trylock(&vq->access_lock) == 0))
1506                 return 0;
1507
1508         if (unlikely(vq->enabled == 0))
1509                 goto out_access_unlock;
1510
1511         vq->batch_copy_nb_elems = 0;
1512
1513         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
1514                 vhost_user_iotlb_rd_lock(vq);
1515
1516         if (unlikely(vq->access_ok == 0))
1517                 if (unlikely(vring_translate(dev, vq) < 0))
1518                         goto out;
1519
1520         if (unlikely(dev->dequeue_zero_copy)) {
1521                 struct zcopy_mbuf *zmbuf, *next;
1522                 int nr_updated = 0;
1523
1524                 for (zmbuf = TAILQ_FIRST(&vq->zmbuf_list);
1525                      zmbuf != NULL; zmbuf = next) {
1526                         next = TAILQ_NEXT(zmbuf, next);
1527
1528                         if (mbuf_is_consumed(zmbuf->mbuf)) {
1529                                 used_idx = vq->last_used_idx++ & (vq->size - 1);
1530                                 update_used_ring(dev, vq, used_idx,
1531                                                  zmbuf->desc_idx);
1532                                 nr_updated += 1;
1533
1534                                 TAILQ_REMOVE(&vq->zmbuf_list, zmbuf, next);
1535                                 restore_mbuf(zmbuf->mbuf);
1536                                 rte_pktmbuf_free(zmbuf->mbuf);
1537                                 put_zmbuf(zmbuf);
1538                                 vq->nr_zmbuf -= 1;
1539                         }
1540                 }
1541
1542                 update_used_idx(dev, vq, nr_updated);
1543         }
1544
1545         /*
1546          * Construct a RARP broadcast packet, and inject it to the "pkts"
1547          * array, to looks like that guest actually send such packet.
1548          *
1549          * Check user_send_rarp() for more information.
1550          *
1551          * broadcast_rarp shares a cacheline in the virtio_net structure
1552          * with some fields that are accessed during enqueue and
1553          * rte_atomic16_cmpset() causes a write if using cmpxchg. This could
1554          * result in false sharing between enqueue and dequeue.
1555          *
1556          * Prevent unnecessary false sharing by reading broadcast_rarp first
1557          * and only performing cmpset if the read indicates it is likely to
1558          * be set.
1559          */
1560
1561         if (unlikely(rte_atomic16_read(&dev->broadcast_rarp) &&
1562                         rte_atomic16_cmpset((volatile uint16_t *)
1563                                 &dev->broadcast_rarp.cnt, 1, 0))) {
1564
1565                 rarp_mbuf = rte_pktmbuf_alloc(mbuf_pool);
1566                 if (rarp_mbuf == NULL) {
1567                         RTE_LOG(ERR, VHOST_DATA,
1568                                 "Failed to allocate memory for mbuf.\n");
1569                         goto out;
1570                 }
1571
1572                 if (make_rarp_packet(rarp_mbuf, &dev->mac)) {
1573                         rte_pktmbuf_free(rarp_mbuf);
1574                         rarp_mbuf = NULL;
1575                 } else {
1576                         count -= 1;
1577                 }
1578         }
1579
1580         free_entries = *((volatile uint16_t *)&vq->avail->idx) -
1581                         vq->last_avail_idx;
1582         if (free_entries == 0)
1583                 goto out;
1584
1585         LOG_DEBUG(VHOST_DATA, "(%d) %s\n", dev->vid, __func__);
1586
1587         /* Prefetch available and used ring */
1588         avail_idx = vq->last_avail_idx & (vq->size - 1);
1589         used_idx  = vq->last_used_idx  & (vq->size - 1);
1590         rte_prefetch0(&vq->avail->ring[avail_idx]);
1591         rte_prefetch0(&vq->used->ring[used_idx]);
1592
1593         count = RTE_MIN(count, MAX_PKT_BURST);
1594         count = RTE_MIN(count, free_entries);
1595         LOG_DEBUG(VHOST_DATA, "(%d) about to dequeue %u buffers\n",
1596                         dev->vid, count);
1597
1598         /* Retrieve all of the head indexes first to avoid caching issues. */
1599         for (i = 0; i < count; i++) {
1600                 avail_idx = (vq->last_avail_idx + i) & (vq->size - 1);
1601                 used_idx  = (vq->last_used_idx  + i) & (vq->size - 1);
1602                 desc_indexes[i] = vq->avail->ring[avail_idx];
1603
1604                 if (likely(dev->dequeue_zero_copy == 0))
1605                         update_used_ring(dev, vq, used_idx, desc_indexes[i]);
1606         }
1607
1608         /* Prefetch descriptor index. */
1609         rte_prefetch0(&vq->desc[desc_indexes[0]]);
1610         for (i = 0; i < count; i++) {
1611                 struct vring_desc *desc, *idesc = NULL;
1612                 uint16_t sz, idx;
1613                 uint64_t dlen;
1614                 int err;
1615
1616                 if (likely(i + 1 < count))
1617                         rte_prefetch0(&vq->desc[desc_indexes[i + 1]]);
1618
1619                 if (vq->desc[desc_indexes[i]].flags & VRING_DESC_F_INDIRECT) {
1620                         dlen = vq->desc[desc_indexes[i]].len;
1621                         desc = (struct vring_desc *)(uintptr_t)
1622                                 vhost_iova_to_vva(dev, vq,
1623                                                 vq->desc[desc_indexes[i]].addr,
1624                                                 &dlen,
1625                                                 VHOST_ACCESS_RO);
1626                         if (unlikely(!desc))
1627                                 break;
1628
1629                         if (unlikely(dlen < vq->desc[desc_indexes[i]].len)) {
1630                                 /*
1631                                  * The indirect desc table is not contiguous
1632                                  * in process VA space, we have to copy it.
1633                                  */
1634                                 idesc = alloc_copy_ind_table(dev, vq,
1635                                                 &vq->desc[desc_indexes[i]]);
1636                                 if (unlikely(!idesc))
1637                                         break;
1638
1639                                 desc = idesc;
1640                         }
1641
1642                         rte_prefetch0(desc);
1643                         sz = vq->desc[desc_indexes[i]].len / sizeof(*desc);
1644                         idx = 0;
1645                 } else {
1646                         desc = vq->desc;
1647                         sz = vq->size;
1648                         idx = desc_indexes[i];
1649                 }
1650
1651                 pkts[i] = rte_pktmbuf_alloc(mbuf_pool);
1652                 if (unlikely(pkts[i] == NULL)) {
1653                         RTE_LOG(ERR, VHOST_DATA,
1654                                 "Failed to allocate memory for mbuf.\n");
1655                         free_ind_table(idesc);
1656                         break;
1657                 }
1658
1659                 err = copy_desc_to_mbuf(dev, vq, desc, sz, pkts[i], idx,
1660                                         mbuf_pool);
1661                 if (unlikely(err)) {
1662                         rte_pktmbuf_free(pkts[i]);
1663                         free_ind_table(idesc);
1664                         break;
1665                 }
1666
1667                 if (unlikely(dev->dequeue_zero_copy)) {
1668                         struct zcopy_mbuf *zmbuf;
1669
1670                         zmbuf = get_zmbuf(vq);
1671                         if (!zmbuf) {
1672                                 rte_pktmbuf_free(pkts[i]);
1673                                 free_ind_table(idesc);
1674                                 break;
1675                         }
1676                         zmbuf->mbuf = pkts[i];
1677                         zmbuf->desc_idx = desc_indexes[i];
1678
1679                         /*
1680                          * Pin lock the mbuf; we will check later to see
1681                          * whether the mbuf is freed (when we are the last
1682                          * user) or not. If that's the case, we then could
1683                          * update the used ring safely.
1684                          */
1685                         rte_mbuf_refcnt_update(pkts[i], 1);
1686
1687                         vq->nr_zmbuf += 1;
1688                         TAILQ_INSERT_TAIL(&vq->zmbuf_list, zmbuf, next);
1689                 }
1690
1691                 if (unlikely(!!idesc))
1692                         free_ind_table(idesc);
1693         }
1694         vq->last_avail_idx += i;
1695
1696         if (likely(dev->dequeue_zero_copy == 0)) {
1697                 do_data_copy_dequeue(vq);
1698                 vq->last_used_idx += i;
1699                 update_used_idx(dev, vq, i);
1700         }
1701
1702 out:
1703         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
1704                 vhost_user_iotlb_rd_unlock(vq);
1705
1706 out_access_unlock:
1707         rte_spinlock_unlock(&vq->access_lock);
1708
1709         if (unlikely(rarp_mbuf != NULL)) {
1710                 /*
1711                  * Inject it to the head of "pkts" array, so that switch's mac
1712                  * learning table will get updated first.
1713                  */
1714                 memmove(&pkts[1], pkts, i * sizeof(struct rte_mbuf *));
1715                 pkts[0] = rarp_mbuf;
1716                 i += 1;
1717         }
1718
1719         return i;
1720 }