vhost: support indirect descriptor in mergeable Rx
[dpdk.git] / lib / librte_vhost / virtio_net.c
1 /*-
2  *   BSD LICENSE
3  *
4  *   Copyright(c) 2010-2016 Intel Corporation. All rights reserved.
5  *   All rights reserved.
6  *
7  *   Redistribution and use in source and binary forms, with or without
8  *   modification, are permitted provided that the following conditions
9  *   are met:
10  *
11  *     * Redistributions of source code must retain the above copyright
12  *       notice, this list of conditions and the following disclaimer.
13  *     * Redistributions in binary form must reproduce the above copyright
14  *       notice, this list of conditions and the following disclaimer in
15  *       the documentation and/or other materials provided with the
16  *       distribution.
17  *     * Neither the name of Intel Corporation nor the names of its
18  *       contributors may be used to endorse or promote products derived
19  *       from this software without specific prior written permission.
20  *
21  *   THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
22  *   "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
23  *   LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
24  *   A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
25  *   OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
26  *   SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
27  *   LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
28  *   DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
29  *   THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
30  *   (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
31  *   OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32  */
33
34 #include <stdint.h>
35 #include <stdbool.h>
36 #include <linux/virtio_net.h>
37
38 #include <rte_mbuf.h>
39 #include <rte_memcpy.h>
40 #include <rte_ether.h>
41 #include <rte_ip.h>
42 #include <rte_virtio_net.h>
43 #include <rte_tcp.h>
44 #include <rte_udp.h>
45 #include <rte_sctp.h>
46 #include <rte_arp.h>
47
48 #include "vhost.h"
49
50 #define MAX_PKT_BURST 32
51 #define VHOST_LOG_PAGE  4096
52
53 static inline void __attribute__((always_inline))
54 vhost_log_page(uint8_t *log_base, uint64_t page)
55 {
56         log_base[page / 8] |= 1 << (page % 8);
57 }
58
59 static inline void __attribute__((always_inline))
60 vhost_log_write(struct virtio_net *dev, uint64_t addr, uint64_t len)
61 {
62         uint64_t page;
63
64         if (likely(((dev->features & (1ULL << VHOST_F_LOG_ALL)) == 0) ||
65                    !dev->log_base || !len))
66                 return;
67
68         if (unlikely(dev->log_size <= ((addr + len - 1) / VHOST_LOG_PAGE / 8)))
69                 return;
70
71         /* To make sure guest memory updates are committed before logging */
72         rte_smp_wmb();
73
74         page = addr / VHOST_LOG_PAGE;
75         while (page * VHOST_LOG_PAGE < addr + len) {
76                 vhost_log_page((uint8_t *)(uintptr_t)dev->log_base, page);
77                 page += 1;
78         }
79 }
80
81 static inline void __attribute__((always_inline))
82 vhost_log_used_vring(struct virtio_net *dev, struct vhost_virtqueue *vq,
83                      uint64_t offset, uint64_t len)
84 {
85         vhost_log_write(dev, vq->log_guest_addr + offset, len);
86 }
87
88 static bool
89 is_valid_virt_queue_idx(uint32_t idx, int is_tx, uint32_t qp_nb)
90 {
91         return (is_tx ^ (idx & 1)) == 0 && idx < qp_nb * VIRTIO_QNUM;
92 }
93
94 static inline void __attribute__((always_inline))
95 do_flush_shadow_used_ring(struct virtio_net *dev, struct vhost_virtqueue *vq,
96                           uint16_t to, uint16_t from, uint16_t size)
97 {
98         rte_memcpy(&vq->used->ring[to],
99                         &vq->shadow_used_ring[from],
100                         size * sizeof(struct vring_used_elem));
101         vhost_log_used_vring(dev, vq,
102                         offsetof(struct vring_used, ring[to]),
103                         size * sizeof(struct vring_used_elem));
104 }
105
106 static inline void __attribute__((always_inline))
107 flush_shadow_used_ring(struct virtio_net *dev, struct vhost_virtqueue *vq)
108 {
109         uint16_t used_idx = vq->last_used_idx & (vq->size - 1);
110
111         if (used_idx + vq->shadow_used_idx <= vq->size) {
112                 do_flush_shadow_used_ring(dev, vq, used_idx, 0,
113                                           vq->shadow_used_idx);
114         } else {
115                 uint16_t size;
116
117                 /* update used ring interval [used_idx, vq->size] */
118                 size = vq->size - used_idx;
119                 do_flush_shadow_used_ring(dev, vq, used_idx, 0, size);
120
121                 /* update the left half used ring interval [0, left_size] */
122                 do_flush_shadow_used_ring(dev, vq, 0, size,
123                                           vq->shadow_used_idx - size);
124         }
125         vq->last_used_idx += vq->shadow_used_idx;
126
127         rte_smp_wmb();
128
129         *(volatile uint16_t *)&vq->used->idx += vq->shadow_used_idx;
130         vhost_log_used_vring(dev, vq, offsetof(struct vring_used, idx),
131                 sizeof(vq->used->idx));
132 }
133
134 static inline void __attribute__((always_inline))
135 update_shadow_used_ring(struct vhost_virtqueue *vq,
136                          uint16_t desc_idx, uint16_t len)
137 {
138         uint16_t i = vq->shadow_used_idx++;
139
140         vq->shadow_used_ring[i].id  = desc_idx;
141         vq->shadow_used_ring[i].len = len;
142 }
143
144 static void
145 virtio_enqueue_offload(struct rte_mbuf *m_buf, struct virtio_net_hdr *net_hdr)
146 {
147         if (m_buf->ol_flags & PKT_TX_L4_MASK) {
148                 net_hdr->flags = VIRTIO_NET_HDR_F_NEEDS_CSUM;
149                 net_hdr->csum_start = m_buf->l2_len + m_buf->l3_len;
150
151                 switch (m_buf->ol_flags & PKT_TX_L4_MASK) {
152                 case PKT_TX_TCP_CKSUM:
153                         net_hdr->csum_offset = (offsetof(struct tcp_hdr,
154                                                 cksum));
155                         break;
156                 case PKT_TX_UDP_CKSUM:
157                         net_hdr->csum_offset = (offsetof(struct udp_hdr,
158                                                 dgram_cksum));
159                         break;
160                 case PKT_TX_SCTP_CKSUM:
161                         net_hdr->csum_offset = (offsetof(struct sctp_hdr,
162                                                 cksum));
163                         break;
164                 }
165         }
166
167         if (m_buf->ol_flags & PKT_TX_TCP_SEG) {
168                 if (m_buf->ol_flags & PKT_TX_IPV4)
169                         net_hdr->gso_type = VIRTIO_NET_HDR_GSO_TCPV4;
170                 else
171                         net_hdr->gso_type = VIRTIO_NET_HDR_GSO_TCPV6;
172                 net_hdr->gso_size = m_buf->tso_segsz;
173                 net_hdr->hdr_len = m_buf->l2_len + m_buf->l3_len
174                                         + m_buf->l4_len;
175         }
176 }
177
178 static inline void
179 copy_virtio_net_hdr(struct virtio_net *dev, uint64_t desc_addr,
180                     struct virtio_net_hdr_mrg_rxbuf hdr)
181 {
182         if (dev->vhost_hlen == sizeof(struct virtio_net_hdr_mrg_rxbuf))
183                 *(struct virtio_net_hdr_mrg_rxbuf *)(uintptr_t)desc_addr = hdr;
184         else
185                 *(struct virtio_net_hdr *)(uintptr_t)desc_addr = hdr.hdr;
186 }
187
188 static inline int __attribute__((always_inline))
189 copy_mbuf_to_desc(struct virtio_net *dev, struct vhost_virtqueue *vq,
190                   struct rte_mbuf *m, uint16_t desc_idx)
191 {
192         uint32_t desc_avail, desc_offset;
193         uint32_t mbuf_avail, mbuf_offset;
194         uint32_t cpy_len;
195         struct vring_desc *desc;
196         uint64_t desc_addr;
197         struct virtio_net_hdr_mrg_rxbuf virtio_hdr = {{0, 0, 0, 0, 0, 0}, 0};
198
199         desc = &vq->desc[desc_idx];
200         desc_addr = gpa_to_vva(dev, desc->addr);
201         /*
202          * Checking of 'desc_addr' placed outside of 'unlikely' macro to avoid
203          * performance issue with some versions of gcc (4.8.4 and 5.3.0) which
204          * otherwise stores offset on the stack instead of in a register.
205          */
206         if (unlikely(desc->len < dev->vhost_hlen) || !desc_addr)
207                 return -1;
208
209         rte_prefetch0((void *)(uintptr_t)desc_addr);
210
211         virtio_enqueue_offload(m, &virtio_hdr.hdr);
212         copy_virtio_net_hdr(dev, desc_addr, virtio_hdr);
213         vhost_log_write(dev, desc->addr, dev->vhost_hlen);
214         PRINT_PACKET(dev, (uintptr_t)desc_addr, dev->vhost_hlen, 0);
215
216         desc_offset = dev->vhost_hlen;
217         desc_avail  = desc->len - dev->vhost_hlen;
218
219         mbuf_avail  = rte_pktmbuf_data_len(m);
220         mbuf_offset = 0;
221         while (mbuf_avail != 0 || m->next != NULL) {
222                 /* done with current mbuf, fetch next */
223                 if (mbuf_avail == 0) {
224                         m = m->next;
225
226                         mbuf_offset = 0;
227                         mbuf_avail  = rte_pktmbuf_data_len(m);
228                 }
229
230                 /* done with current desc buf, fetch next */
231                 if (desc_avail == 0) {
232                         if ((desc->flags & VRING_DESC_F_NEXT) == 0) {
233                                 /* Room in vring buffer is not enough */
234                                 return -1;
235                         }
236                         if (unlikely(desc->next >= vq->size))
237                                 return -1;
238
239                         desc = &vq->desc[desc->next];
240                         desc_addr = gpa_to_vva(dev, desc->addr);
241                         if (unlikely(!desc_addr))
242                                 return -1;
243
244                         desc_offset = 0;
245                         desc_avail  = desc->len;
246                 }
247
248                 cpy_len = RTE_MIN(desc_avail, mbuf_avail);
249                 rte_memcpy((void *)((uintptr_t)(desc_addr + desc_offset)),
250                         rte_pktmbuf_mtod_offset(m, void *, mbuf_offset),
251                         cpy_len);
252                 vhost_log_write(dev, desc->addr + desc_offset, cpy_len);
253                 PRINT_PACKET(dev, (uintptr_t)(desc_addr + desc_offset),
254                              cpy_len, 0);
255
256                 mbuf_avail  -= cpy_len;
257                 mbuf_offset += cpy_len;
258                 desc_avail  -= cpy_len;
259                 desc_offset += cpy_len;
260         }
261
262         return 0;
263 }
264
265 /**
266  * This function adds buffers to the virtio devices RX virtqueue. Buffers can
267  * be received from the physical port or from another virtio device. A packet
268  * count is returned to indicate the number of packets that are succesfully
269  * added to the RX queue. This function works when the mbuf is scattered, but
270  * it doesn't support the mergeable feature.
271  */
272 static inline uint32_t __attribute__((always_inline))
273 virtio_dev_rx(struct virtio_net *dev, uint16_t queue_id,
274               struct rte_mbuf **pkts, uint32_t count)
275 {
276         struct vhost_virtqueue *vq;
277         uint16_t avail_idx, free_entries, start_idx;
278         uint16_t desc_indexes[MAX_PKT_BURST];
279         uint16_t used_idx;
280         uint32_t i;
281
282         LOG_DEBUG(VHOST_DATA, "(%d) %s\n", dev->vid, __func__);
283         if (unlikely(!is_valid_virt_queue_idx(queue_id, 0, dev->virt_qp_nb))) {
284                 RTE_LOG(ERR, VHOST_DATA, "(%d) %s: invalid virtqueue idx %d.\n",
285                         dev->vid, __func__, queue_id);
286                 return 0;
287         }
288
289         vq = dev->virtqueue[queue_id];
290         if (unlikely(vq->enabled == 0))
291                 return 0;
292
293         avail_idx = *((volatile uint16_t *)&vq->avail->idx);
294         start_idx = vq->last_used_idx;
295         free_entries = avail_idx - start_idx;
296         count = RTE_MIN(count, free_entries);
297         count = RTE_MIN(count, (uint32_t)MAX_PKT_BURST);
298         if (count == 0)
299                 return 0;
300
301         LOG_DEBUG(VHOST_DATA, "(%d) start_idx %d | end_idx %d\n",
302                 dev->vid, start_idx, start_idx + count);
303
304         /* Retrieve all of the desc indexes first to avoid caching issues. */
305         rte_prefetch0(&vq->avail->ring[start_idx & (vq->size - 1)]);
306         for (i = 0; i < count; i++) {
307                 used_idx = (start_idx + i) & (vq->size - 1);
308                 desc_indexes[i] = vq->avail->ring[used_idx];
309                 vq->used->ring[used_idx].id = desc_indexes[i];
310                 vq->used->ring[used_idx].len = pkts[i]->pkt_len +
311                                                dev->vhost_hlen;
312                 vhost_log_used_vring(dev, vq,
313                         offsetof(struct vring_used, ring[used_idx]),
314                         sizeof(vq->used->ring[used_idx]));
315         }
316
317         rte_prefetch0(&vq->desc[desc_indexes[0]]);
318         for (i = 0; i < count; i++) {
319                 uint16_t desc_idx = desc_indexes[i];
320                 int err;
321
322                 err = copy_mbuf_to_desc(dev, vq, pkts[i], desc_idx);
323                 if (unlikely(err)) {
324                         used_idx = (start_idx + i) & (vq->size - 1);
325                         vq->used->ring[used_idx].len = dev->vhost_hlen;
326                         vhost_log_used_vring(dev, vq,
327                                 offsetof(struct vring_used, ring[used_idx]),
328                                 sizeof(vq->used->ring[used_idx]));
329                 }
330
331                 if (i + 1 < count)
332                         rte_prefetch0(&vq->desc[desc_indexes[i+1]]);
333         }
334
335         rte_smp_wmb();
336
337         *(volatile uint16_t *)&vq->used->idx += count;
338         vq->last_used_idx += count;
339         vhost_log_used_vring(dev, vq,
340                 offsetof(struct vring_used, idx),
341                 sizeof(vq->used->idx));
342
343         /* flush used->idx update before we read avail->flags. */
344         rte_mb();
345
346         /* Kick the guest if necessary. */
347         if (!(vq->avail->flags & VRING_AVAIL_F_NO_INTERRUPT)
348                         && (vq->callfd >= 0))
349                 eventfd_write(vq->callfd, (eventfd_t)1);
350         return count;
351 }
352
353 static inline int __attribute__((always_inline))
354 fill_vec_buf(struct virtio_net *dev, struct vhost_virtqueue *vq,
355                          uint32_t avail_idx, uint32_t *vec_idx,
356                          struct buf_vector *buf_vec, uint16_t *desc_chain_head,
357                          uint16_t *desc_chain_len)
358 {
359         uint16_t idx = vq->avail->ring[avail_idx & (vq->size - 1)];
360         uint32_t vec_id = *vec_idx;
361         uint32_t len    = 0;
362         struct vring_desc *descs = vq->desc;
363
364         *desc_chain_head = idx;
365
366         if (vq->desc[idx].flags & VRING_DESC_F_INDIRECT) {
367                 descs = (struct vring_desc *)(uintptr_t)
368                                         gpa_to_vva(dev, vq->desc[idx].addr);
369                 if (unlikely(!descs))
370                         return -1;
371
372                 idx = 0;
373         }
374
375         while (1) {
376                 if (unlikely(vec_id >= BUF_VECTOR_MAX || idx >= vq->size))
377                         return -1;
378
379                 len += descs[idx].len;
380                 buf_vec[vec_id].buf_addr = descs[idx].addr;
381                 buf_vec[vec_id].buf_len  = descs[idx].len;
382                 buf_vec[vec_id].desc_idx = idx;
383                 vec_id++;
384
385                 if ((descs[idx].flags & VRING_DESC_F_NEXT) == 0)
386                         break;
387
388                 idx = descs[idx].next;
389         }
390
391         *desc_chain_len = len;
392         *vec_idx = vec_id;
393
394         return 0;
395 }
396
397 /*
398  * Returns -1 on fail, 0 on success
399  */
400 static inline int
401 reserve_avail_buf_mergeable(struct virtio_net *dev, struct vhost_virtqueue *vq,
402                                 uint32_t size, struct buf_vector *buf_vec,
403                                 uint16_t *num_buffers, uint16_t avail_head)
404 {
405         uint16_t cur_idx;
406         uint32_t vec_idx = 0;
407         uint16_t tries = 0;
408
409         uint16_t head_idx = 0;
410         uint16_t len = 0;
411
412         *num_buffers = 0;
413         cur_idx  = vq->last_avail_idx;
414
415         while (size > 0) {
416                 if (unlikely(cur_idx == avail_head))
417                         return -1;
418
419                 if (unlikely(fill_vec_buf(dev, vq, cur_idx, &vec_idx, buf_vec,
420                                                 &head_idx, &len) < 0))
421                         return -1;
422                 len = RTE_MIN(len, size);
423                 update_shadow_used_ring(vq, head_idx, len);
424                 size -= len;
425
426                 cur_idx++;
427                 tries++;
428                 *num_buffers += 1;
429
430                 /*
431                  * if we tried all available ring items, and still
432                  * can't get enough buf, it means something abnormal
433                  * happened.
434                  */
435                 if (unlikely(tries >= vq->size))
436                         return -1;
437         }
438
439         return 0;
440 }
441
442 static inline int __attribute__((always_inline))
443 copy_mbuf_to_desc_mergeable(struct virtio_net *dev, struct rte_mbuf *m,
444                             struct buf_vector *buf_vec, uint16_t num_buffers)
445 {
446         struct virtio_net_hdr_mrg_rxbuf virtio_hdr = {{0, 0, 0, 0, 0, 0}, 0};
447         uint32_t vec_idx = 0;
448         uint64_t desc_addr;
449         uint32_t mbuf_offset, mbuf_avail;
450         uint32_t desc_offset, desc_avail;
451         uint32_t cpy_len;
452         uint64_t hdr_addr, hdr_phys_addr;
453         struct rte_mbuf *hdr_mbuf;
454
455         if (unlikely(m == NULL))
456                 return -1;
457
458         desc_addr = gpa_to_vva(dev, buf_vec[vec_idx].buf_addr);
459         if (buf_vec[vec_idx].buf_len < dev->vhost_hlen || !desc_addr)
460                 return -1;
461
462         hdr_mbuf = m;
463         hdr_addr = desc_addr;
464         hdr_phys_addr = buf_vec[vec_idx].buf_addr;
465         rte_prefetch0((void *)(uintptr_t)hdr_addr);
466
467         virtio_hdr.num_buffers = num_buffers;
468         LOG_DEBUG(VHOST_DATA, "(%d) RX: num merge buffers %d\n",
469                 dev->vid, num_buffers);
470
471         desc_avail  = buf_vec[vec_idx].buf_len - dev->vhost_hlen;
472         desc_offset = dev->vhost_hlen;
473
474         mbuf_avail  = rte_pktmbuf_data_len(m);
475         mbuf_offset = 0;
476         while (mbuf_avail != 0 || m->next != NULL) {
477                 /* done with current desc buf, get the next one */
478                 if (desc_avail == 0) {
479                         vec_idx++;
480                         desc_addr = gpa_to_vva(dev, buf_vec[vec_idx].buf_addr);
481                         if (unlikely(!desc_addr))
482                                 return -1;
483
484                         /* Prefetch buffer address. */
485                         rte_prefetch0((void *)(uintptr_t)desc_addr);
486                         desc_offset = 0;
487                         desc_avail  = buf_vec[vec_idx].buf_len;
488                 }
489
490                 /* done with current mbuf, get the next one */
491                 if (mbuf_avail == 0) {
492                         m = m->next;
493
494                         mbuf_offset = 0;
495                         mbuf_avail  = rte_pktmbuf_data_len(m);
496                 }
497
498                 if (hdr_addr) {
499                         virtio_enqueue_offload(hdr_mbuf, &virtio_hdr.hdr);
500                         copy_virtio_net_hdr(dev, hdr_addr, virtio_hdr);
501                         vhost_log_write(dev, hdr_phys_addr, dev->vhost_hlen);
502                         PRINT_PACKET(dev, (uintptr_t)hdr_addr,
503                                      dev->vhost_hlen, 0);
504
505                         hdr_addr = 0;
506                 }
507
508                 cpy_len = RTE_MIN(desc_avail, mbuf_avail);
509                 rte_memcpy((void *)((uintptr_t)(desc_addr + desc_offset)),
510                         rte_pktmbuf_mtod_offset(m, void *, mbuf_offset),
511                         cpy_len);
512                 vhost_log_write(dev, buf_vec[vec_idx].buf_addr + desc_offset,
513                         cpy_len);
514                 PRINT_PACKET(dev, (uintptr_t)(desc_addr + desc_offset),
515                         cpy_len, 0);
516
517                 mbuf_avail  -= cpy_len;
518                 mbuf_offset += cpy_len;
519                 desc_avail  -= cpy_len;
520                 desc_offset += cpy_len;
521         }
522
523         return 0;
524 }
525
526 static inline uint32_t __attribute__((always_inline))
527 virtio_dev_merge_rx(struct virtio_net *dev, uint16_t queue_id,
528         struct rte_mbuf **pkts, uint32_t count)
529 {
530         struct vhost_virtqueue *vq;
531         uint32_t pkt_idx = 0;
532         uint16_t num_buffers;
533         struct buf_vector buf_vec[BUF_VECTOR_MAX];
534         uint16_t avail_head;
535
536         LOG_DEBUG(VHOST_DATA, "(%d) %s\n", dev->vid, __func__);
537         if (unlikely(!is_valid_virt_queue_idx(queue_id, 0, dev->virt_qp_nb))) {
538                 RTE_LOG(ERR, VHOST_DATA, "(%d) %s: invalid virtqueue idx %d.\n",
539                         dev->vid, __func__, queue_id);
540                 return 0;
541         }
542
543         vq = dev->virtqueue[queue_id];
544         if (unlikely(vq->enabled == 0))
545                 return 0;
546
547         count = RTE_MIN((uint32_t)MAX_PKT_BURST, count);
548         if (count == 0)
549                 return 0;
550
551         rte_prefetch0(&vq->avail->ring[vq->last_avail_idx & (vq->size - 1)]);
552
553         vq->shadow_used_idx = 0;
554         avail_head = *((volatile uint16_t *)&vq->avail->idx);
555         for (pkt_idx = 0; pkt_idx < count; pkt_idx++) {
556                 uint32_t pkt_len = pkts[pkt_idx]->pkt_len + dev->vhost_hlen;
557
558                 if (unlikely(reserve_avail_buf_mergeable(dev, vq,
559                                                 pkt_len, buf_vec, &num_buffers,
560                                                 avail_head) < 0)) {
561                         LOG_DEBUG(VHOST_DATA,
562                                 "(%d) failed to get enough desc from vring\n",
563                                 dev->vid);
564                         vq->shadow_used_idx -= num_buffers;
565                         break;
566                 }
567
568                 LOG_DEBUG(VHOST_DATA, "(%d) current index %d | end index %d\n",
569                         dev->vid, vq->last_avail_idx,
570                         vq->last_avail_idx + num_buffers);
571
572                 if (copy_mbuf_to_desc_mergeable(dev, pkts[pkt_idx],
573                                                 buf_vec, num_buffers) < 0) {
574                         vq->shadow_used_idx -= num_buffers;
575                         break;
576                 }
577
578                 vq->last_avail_idx += num_buffers;
579         }
580
581         if (likely(vq->shadow_used_idx)) {
582                 flush_shadow_used_ring(dev, vq);
583
584                 /* flush used->idx update before we read avail->flags. */
585                 rte_mb();
586
587                 /* Kick the guest if necessary. */
588                 if (!(vq->avail->flags & VRING_AVAIL_F_NO_INTERRUPT)
589                                 && (vq->callfd >= 0))
590                         eventfd_write(vq->callfd, (eventfd_t)1);
591         }
592
593         return pkt_idx;
594 }
595
596 uint16_t
597 rte_vhost_enqueue_burst(int vid, uint16_t queue_id,
598         struct rte_mbuf **pkts, uint16_t count)
599 {
600         struct virtio_net *dev = get_device(vid);
601
602         if (!dev)
603                 return 0;
604
605         if (dev->features & (1 << VIRTIO_NET_F_MRG_RXBUF))
606                 return virtio_dev_merge_rx(dev, queue_id, pkts, count);
607         else
608                 return virtio_dev_rx(dev, queue_id, pkts, count);
609 }
610
611 static inline bool
612 virtio_net_with_host_offload(struct virtio_net *dev)
613 {
614         if (dev->features &
615                         (VIRTIO_NET_F_CSUM | VIRTIO_NET_F_HOST_ECN |
616                          VIRTIO_NET_F_HOST_TSO4 | VIRTIO_NET_F_HOST_TSO6 |
617                          VIRTIO_NET_F_HOST_UFO))
618                 return true;
619
620         return false;
621 }
622
623 static void
624 parse_ethernet(struct rte_mbuf *m, uint16_t *l4_proto, void **l4_hdr)
625 {
626         struct ipv4_hdr *ipv4_hdr;
627         struct ipv6_hdr *ipv6_hdr;
628         void *l3_hdr = NULL;
629         struct ether_hdr *eth_hdr;
630         uint16_t ethertype;
631
632         eth_hdr = rte_pktmbuf_mtod(m, struct ether_hdr *);
633
634         m->l2_len = sizeof(struct ether_hdr);
635         ethertype = rte_be_to_cpu_16(eth_hdr->ether_type);
636
637         if (ethertype == ETHER_TYPE_VLAN) {
638                 struct vlan_hdr *vlan_hdr = (struct vlan_hdr *)(eth_hdr + 1);
639
640                 m->l2_len += sizeof(struct vlan_hdr);
641                 ethertype = rte_be_to_cpu_16(vlan_hdr->eth_proto);
642         }
643
644         l3_hdr = (char *)eth_hdr + m->l2_len;
645
646         switch (ethertype) {
647         case ETHER_TYPE_IPv4:
648                 ipv4_hdr = (struct ipv4_hdr *)l3_hdr;
649                 *l4_proto = ipv4_hdr->next_proto_id;
650                 m->l3_len = (ipv4_hdr->version_ihl & 0x0f) * 4;
651                 *l4_hdr = (char *)l3_hdr + m->l3_len;
652                 m->ol_flags |= PKT_TX_IPV4;
653                 break;
654         case ETHER_TYPE_IPv6:
655                 ipv6_hdr = (struct ipv6_hdr *)l3_hdr;
656                 *l4_proto = ipv6_hdr->proto;
657                 m->l3_len = sizeof(struct ipv6_hdr);
658                 *l4_hdr = (char *)l3_hdr + m->l3_len;
659                 m->ol_flags |= PKT_TX_IPV6;
660                 break;
661         default:
662                 m->l3_len = 0;
663                 *l4_proto = 0;
664                 break;
665         }
666 }
667
668 static inline void __attribute__((always_inline))
669 vhost_dequeue_offload(struct virtio_net_hdr *hdr, struct rte_mbuf *m)
670 {
671         uint16_t l4_proto = 0;
672         void *l4_hdr = NULL;
673         struct tcp_hdr *tcp_hdr = NULL;
674
675         if (hdr->flags == 0 && hdr->gso_type == VIRTIO_NET_HDR_GSO_NONE)
676                 return;
677
678         parse_ethernet(m, &l4_proto, &l4_hdr);
679         if (hdr->flags == VIRTIO_NET_HDR_F_NEEDS_CSUM) {
680                 if (hdr->csum_start == (m->l2_len + m->l3_len)) {
681                         switch (hdr->csum_offset) {
682                         case (offsetof(struct tcp_hdr, cksum)):
683                                 if (l4_proto == IPPROTO_TCP)
684                                         m->ol_flags |= PKT_TX_TCP_CKSUM;
685                                 break;
686                         case (offsetof(struct udp_hdr, dgram_cksum)):
687                                 if (l4_proto == IPPROTO_UDP)
688                                         m->ol_flags |= PKT_TX_UDP_CKSUM;
689                                 break;
690                         case (offsetof(struct sctp_hdr, cksum)):
691                                 if (l4_proto == IPPROTO_SCTP)
692                                         m->ol_flags |= PKT_TX_SCTP_CKSUM;
693                                 break;
694                         default:
695                                 break;
696                         }
697                 }
698         }
699
700         if (hdr->gso_type != VIRTIO_NET_HDR_GSO_NONE) {
701                 switch (hdr->gso_type & ~VIRTIO_NET_HDR_GSO_ECN) {
702                 case VIRTIO_NET_HDR_GSO_TCPV4:
703                 case VIRTIO_NET_HDR_GSO_TCPV6:
704                         tcp_hdr = (struct tcp_hdr *)l4_hdr;
705                         m->ol_flags |= PKT_TX_TCP_SEG;
706                         m->tso_segsz = hdr->gso_size;
707                         m->l4_len = (tcp_hdr->data_off & 0xf0) >> 2;
708                         break;
709                 default:
710                         RTE_LOG(WARNING, VHOST_DATA,
711                                 "unsupported gso type %u.\n", hdr->gso_type);
712                         break;
713                 }
714         }
715 }
716
717 #define RARP_PKT_SIZE   64
718
719 static int
720 make_rarp_packet(struct rte_mbuf *rarp_mbuf, const struct ether_addr *mac)
721 {
722         struct ether_hdr *eth_hdr;
723         struct arp_hdr  *rarp;
724
725         if (rarp_mbuf->buf_len < 64) {
726                 RTE_LOG(WARNING, VHOST_DATA,
727                         "failed to make RARP; mbuf size too small %u (< %d)\n",
728                         rarp_mbuf->buf_len, RARP_PKT_SIZE);
729                 return -1;
730         }
731
732         /* Ethernet header. */
733         eth_hdr = rte_pktmbuf_mtod_offset(rarp_mbuf, struct ether_hdr *, 0);
734         memset(eth_hdr->d_addr.addr_bytes, 0xff, ETHER_ADDR_LEN);
735         ether_addr_copy(mac, &eth_hdr->s_addr);
736         eth_hdr->ether_type = htons(ETHER_TYPE_RARP);
737
738         /* RARP header. */
739         rarp = (struct arp_hdr *)(eth_hdr + 1);
740         rarp->arp_hrd = htons(ARP_HRD_ETHER);
741         rarp->arp_pro = htons(ETHER_TYPE_IPv4);
742         rarp->arp_hln = ETHER_ADDR_LEN;
743         rarp->arp_pln = 4;
744         rarp->arp_op  = htons(ARP_OP_REVREQUEST);
745
746         ether_addr_copy(mac, &rarp->arp_data.arp_sha);
747         ether_addr_copy(mac, &rarp->arp_data.arp_tha);
748         memset(&rarp->arp_data.arp_sip, 0x00, 4);
749         memset(&rarp->arp_data.arp_tip, 0x00, 4);
750
751         rarp_mbuf->pkt_len  = rarp_mbuf->data_len = RARP_PKT_SIZE;
752
753         return 0;
754 }
755
756 static inline void __attribute__((always_inline))
757 put_zmbuf(struct zcopy_mbuf *zmbuf)
758 {
759         zmbuf->in_use = 0;
760 }
761
762 static inline int __attribute__((always_inline))
763 copy_desc_to_mbuf(struct virtio_net *dev, struct vring_desc *descs,
764                   uint16_t max_desc, struct rte_mbuf *m, uint16_t desc_idx,
765                   struct rte_mempool *mbuf_pool)
766 {
767         struct vring_desc *desc;
768         uint64_t desc_addr;
769         uint32_t desc_avail, desc_offset;
770         uint32_t mbuf_avail, mbuf_offset;
771         uint32_t cpy_len;
772         struct rte_mbuf *cur = m, *prev = m;
773         struct virtio_net_hdr *hdr = NULL;
774         /* A counter to avoid desc dead loop chain */
775         uint32_t nr_desc = 1;
776
777         desc = &descs[desc_idx];
778         if (unlikely((desc->len < dev->vhost_hlen)) ||
779                         (desc->flags & VRING_DESC_F_INDIRECT))
780                 return -1;
781
782         desc_addr = gpa_to_vva(dev, desc->addr);
783         if (unlikely(!desc_addr))
784                 return -1;
785
786         if (virtio_net_with_host_offload(dev)) {
787                 hdr = (struct virtio_net_hdr *)((uintptr_t)desc_addr);
788                 rte_prefetch0(hdr);
789         }
790
791         /*
792          * A virtio driver normally uses at least 2 desc buffers
793          * for Tx: the first for storing the header, and others
794          * for storing the data.
795          */
796         if (likely((desc->len == dev->vhost_hlen) &&
797                    (desc->flags & VRING_DESC_F_NEXT) != 0)) {
798                 desc = &descs[desc->next];
799                 if (unlikely(desc->flags & VRING_DESC_F_INDIRECT))
800                         return -1;
801
802                 desc_addr = gpa_to_vva(dev, desc->addr);
803                 if (unlikely(!desc_addr))
804                         return -1;
805
806                 desc_offset = 0;
807                 desc_avail  = desc->len;
808                 nr_desc    += 1;
809         } else {
810                 desc_avail  = desc->len - dev->vhost_hlen;
811                 desc_offset = dev->vhost_hlen;
812         }
813
814         rte_prefetch0((void *)(uintptr_t)(desc_addr + desc_offset));
815
816         PRINT_PACKET(dev, (uintptr_t)(desc_addr + desc_offset), desc_avail, 0);
817
818         mbuf_offset = 0;
819         mbuf_avail  = m->buf_len - RTE_PKTMBUF_HEADROOM;
820         while (1) {
821                 uint64_t hpa;
822
823                 cpy_len = RTE_MIN(desc_avail, mbuf_avail);
824
825                 /*
826                  * A desc buf might across two host physical pages that are
827                  * not continuous. In such case (gpa_to_hpa returns 0), data
828                  * will be copied even though zero copy is enabled.
829                  */
830                 if (unlikely(dev->dequeue_zero_copy && (hpa = gpa_to_hpa(dev,
831                                         desc->addr + desc_offset, cpy_len)))) {
832                         cur->data_len = cpy_len;
833                         cur->data_off = 0;
834                         cur->buf_addr = (void *)(uintptr_t)desc_addr;
835                         cur->buf_physaddr = hpa;
836
837                         /*
838                          * In zero copy mode, one mbuf can only reference data
839                          * for one or partial of one desc buff.
840                          */
841                         mbuf_avail = cpy_len;
842                 } else {
843                         rte_memcpy(rte_pktmbuf_mtod_offset(cur, void *,
844                                                            mbuf_offset),
845                                 (void *)((uintptr_t)(desc_addr + desc_offset)),
846                                 cpy_len);
847                 }
848
849                 mbuf_avail  -= cpy_len;
850                 mbuf_offset += cpy_len;
851                 desc_avail  -= cpy_len;
852                 desc_offset += cpy_len;
853
854                 /* This desc reaches to its end, get the next one */
855                 if (desc_avail == 0) {
856                         if ((desc->flags & VRING_DESC_F_NEXT) == 0)
857                                 break;
858
859                         if (unlikely(desc->next >= max_desc ||
860                                      ++nr_desc > max_desc))
861                                 return -1;
862                         desc = &descs[desc->next];
863                         if (unlikely(desc->flags & VRING_DESC_F_INDIRECT))
864                                 return -1;
865
866                         desc_addr = gpa_to_vva(dev, desc->addr);
867                         if (unlikely(!desc_addr))
868                                 return -1;
869
870                         rte_prefetch0((void *)(uintptr_t)desc_addr);
871
872                         desc_offset = 0;
873                         desc_avail  = desc->len;
874
875                         PRINT_PACKET(dev, (uintptr_t)desc_addr, desc->len, 0);
876                 }
877
878                 /*
879                  * This mbuf reaches to its end, get a new one
880                  * to hold more data.
881                  */
882                 if (mbuf_avail == 0) {
883                         cur = rte_pktmbuf_alloc(mbuf_pool);
884                         if (unlikely(cur == NULL)) {
885                                 RTE_LOG(ERR, VHOST_DATA, "Failed to "
886                                         "allocate memory for mbuf.\n");
887                                 return -1;
888                         }
889
890                         prev->next = cur;
891                         prev->data_len = mbuf_offset;
892                         m->nb_segs += 1;
893                         m->pkt_len += mbuf_offset;
894                         prev = cur;
895
896                         mbuf_offset = 0;
897                         mbuf_avail  = cur->buf_len - RTE_PKTMBUF_HEADROOM;
898                 }
899         }
900
901         prev->data_len = mbuf_offset;
902         m->pkt_len    += mbuf_offset;
903
904         if (hdr)
905                 vhost_dequeue_offload(hdr, m);
906
907         return 0;
908 }
909
910 static inline void __attribute__((always_inline))
911 update_used_ring(struct virtio_net *dev, struct vhost_virtqueue *vq,
912                  uint32_t used_idx, uint32_t desc_idx)
913 {
914         vq->used->ring[used_idx].id  = desc_idx;
915         vq->used->ring[used_idx].len = 0;
916         vhost_log_used_vring(dev, vq,
917                         offsetof(struct vring_used, ring[used_idx]),
918                         sizeof(vq->used->ring[used_idx]));
919 }
920
921 static inline void __attribute__((always_inline))
922 update_used_idx(struct virtio_net *dev, struct vhost_virtqueue *vq,
923                 uint32_t count)
924 {
925         if (unlikely(count == 0))
926                 return;
927
928         rte_smp_wmb();
929         rte_smp_rmb();
930
931         vq->used->idx += count;
932         vhost_log_used_vring(dev, vq, offsetof(struct vring_used, idx),
933                         sizeof(vq->used->idx));
934
935         /* Kick guest if required. */
936         if (!(vq->avail->flags & VRING_AVAIL_F_NO_INTERRUPT)
937                         && (vq->callfd >= 0))
938                 eventfd_write(vq->callfd, (eventfd_t)1);
939 }
940
941 static inline struct zcopy_mbuf *__attribute__((always_inline))
942 get_zmbuf(struct vhost_virtqueue *vq)
943 {
944         uint16_t i;
945         uint16_t last;
946         int tries = 0;
947
948         /* search [last_zmbuf_idx, zmbuf_size) */
949         i = vq->last_zmbuf_idx;
950         last = vq->zmbuf_size;
951
952 again:
953         for (; i < last; i++) {
954                 if (vq->zmbufs[i].in_use == 0) {
955                         vq->last_zmbuf_idx = i + 1;
956                         vq->zmbufs[i].in_use = 1;
957                         return &vq->zmbufs[i];
958                 }
959         }
960
961         tries++;
962         if (tries == 1) {
963                 /* search [0, last_zmbuf_idx) */
964                 i = 0;
965                 last = vq->last_zmbuf_idx;
966                 goto again;
967         }
968
969         return NULL;
970 }
971
972 static inline bool __attribute__((always_inline))
973 mbuf_is_consumed(struct rte_mbuf *m)
974 {
975         while (m) {
976                 if (rte_mbuf_refcnt_read(m) > 1)
977                         return false;
978                 m = m->next;
979         }
980
981         return true;
982 }
983
984 uint16_t
985 rte_vhost_dequeue_burst(int vid, uint16_t queue_id,
986         struct rte_mempool *mbuf_pool, struct rte_mbuf **pkts, uint16_t count)
987 {
988         struct virtio_net *dev;
989         struct rte_mbuf *rarp_mbuf = NULL;
990         struct vhost_virtqueue *vq;
991         uint32_t desc_indexes[MAX_PKT_BURST];
992         uint32_t used_idx;
993         uint32_t i = 0;
994         uint16_t free_entries;
995         uint16_t avail_idx;
996
997         dev = get_device(vid);
998         if (!dev)
999                 return 0;
1000
1001         if (unlikely(!is_valid_virt_queue_idx(queue_id, 1, dev->virt_qp_nb))) {
1002                 RTE_LOG(ERR, VHOST_DATA, "(%d) %s: invalid virtqueue idx %d.\n",
1003                         dev->vid, __func__, queue_id);
1004                 return 0;
1005         }
1006
1007         vq = dev->virtqueue[queue_id];
1008         if (unlikely(vq->enabled == 0))
1009                 return 0;
1010
1011         if (unlikely(dev->dequeue_zero_copy)) {
1012                 struct zcopy_mbuf *zmbuf, *next;
1013                 int nr_updated = 0;
1014
1015                 for (zmbuf = TAILQ_FIRST(&vq->zmbuf_list);
1016                      zmbuf != NULL; zmbuf = next) {
1017                         next = TAILQ_NEXT(zmbuf, next);
1018
1019                         if (mbuf_is_consumed(zmbuf->mbuf)) {
1020                                 used_idx = vq->last_used_idx++ & (vq->size - 1);
1021                                 update_used_ring(dev, vq, used_idx,
1022                                                  zmbuf->desc_idx);
1023                                 nr_updated += 1;
1024
1025                                 TAILQ_REMOVE(&vq->zmbuf_list, zmbuf, next);
1026                                 rte_pktmbuf_free(zmbuf->mbuf);
1027                                 put_zmbuf(zmbuf);
1028                                 vq->nr_zmbuf -= 1;
1029                         }
1030                 }
1031
1032                 update_used_idx(dev, vq, nr_updated);
1033         }
1034
1035         /*
1036          * Construct a RARP broadcast packet, and inject it to the "pkts"
1037          * array, to looks like that guest actually send such packet.
1038          *
1039          * Check user_send_rarp() for more information.
1040          */
1041         if (unlikely(rte_atomic16_cmpset((volatile uint16_t *)
1042                                          &dev->broadcast_rarp.cnt, 1, 0))) {
1043                 rarp_mbuf = rte_pktmbuf_alloc(mbuf_pool);
1044                 if (rarp_mbuf == NULL) {
1045                         RTE_LOG(ERR, VHOST_DATA,
1046                                 "Failed to allocate memory for mbuf.\n");
1047                         return 0;
1048                 }
1049
1050                 if (make_rarp_packet(rarp_mbuf, &dev->mac)) {
1051                         rte_pktmbuf_free(rarp_mbuf);
1052                         rarp_mbuf = NULL;
1053                 } else {
1054                         count -= 1;
1055                 }
1056         }
1057
1058         free_entries = *((volatile uint16_t *)&vq->avail->idx) -
1059                         vq->last_avail_idx;
1060         if (free_entries == 0)
1061                 goto out;
1062
1063         LOG_DEBUG(VHOST_DATA, "(%d) %s\n", dev->vid, __func__);
1064
1065         /* Prefetch available and used ring */
1066         avail_idx = vq->last_avail_idx & (vq->size - 1);
1067         used_idx  = vq->last_used_idx  & (vq->size - 1);
1068         rte_prefetch0(&vq->avail->ring[avail_idx]);
1069         rte_prefetch0(&vq->used->ring[used_idx]);
1070
1071         count = RTE_MIN(count, MAX_PKT_BURST);
1072         count = RTE_MIN(count, free_entries);
1073         LOG_DEBUG(VHOST_DATA, "(%d) about to dequeue %u buffers\n",
1074                         dev->vid, count);
1075
1076         /* Retrieve all of the head indexes first to avoid caching issues. */
1077         for (i = 0; i < count; i++) {
1078                 avail_idx = (vq->last_avail_idx + i) & (vq->size - 1);
1079                 used_idx  = (vq->last_used_idx  + i) & (vq->size - 1);
1080                 desc_indexes[i] = vq->avail->ring[avail_idx];
1081
1082                 if (likely(dev->dequeue_zero_copy == 0))
1083                         update_used_ring(dev, vq, used_idx, desc_indexes[i]);
1084         }
1085
1086         /* Prefetch descriptor index. */
1087         rte_prefetch0(&vq->desc[desc_indexes[0]]);
1088         for (i = 0; i < count; i++) {
1089                 struct vring_desc *desc;
1090                 uint16_t sz, idx;
1091                 int err;
1092
1093                 if (likely(i + 1 < count))
1094                         rte_prefetch0(&vq->desc[desc_indexes[i + 1]]);
1095
1096                 if (vq->desc[desc_indexes[i]].flags & VRING_DESC_F_INDIRECT) {
1097                         desc = (struct vring_desc *)(uintptr_t)gpa_to_vva(dev,
1098                                         vq->desc[desc_indexes[i]].addr);
1099                         if (unlikely(!desc))
1100                                 break;
1101
1102                         rte_prefetch0(desc);
1103                         sz = vq->desc[desc_indexes[i]].len / sizeof(*desc);
1104                         idx = 0;
1105                 } else {
1106                         desc = vq->desc;
1107                         sz = vq->size;
1108                         idx = desc_indexes[i];
1109                 }
1110
1111                 pkts[i] = rte_pktmbuf_alloc(mbuf_pool);
1112                 if (unlikely(pkts[i] == NULL)) {
1113                         RTE_LOG(ERR, VHOST_DATA,
1114                                 "Failed to allocate memory for mbuf.\n");
1115                         break;
1116                 }
1117
1118                 err = copy_desc_to_mbuf(dev, desc, sz, pkts[i], idx, mbuf_pool);
1119                 if (unlikely(err)) {
1120                         rte_pktmbuf_free(pkts[i]);
1121                         break;
1122                 }
1123
1124                 if (unlikely(dev->dequeue_zero_copy)) {
1125                         struct zcopy_mbuf *zmbuf;
1126
1127                         zmbuf = get_zmbuf(vq);
1128                         if (!zmbuf) {
1129                                 rte_pktmbuf_free(pkts[i]);
1130                                 break;
1131                         }
1132                         zmbuf->mbuf = pkts[i];
1133                         zmbuf->desc_idx = desc_indexes[i];
1134
1135                         /*
1136                          * Pin lock the mbuf; we will check later to see
1137                          * whether the mbuf is freed (when we are the last
1138                          * user) or not. If that's the case, we then could
1139                          * update the used ring safely.
1140                          */
1141                         rte_mbuf_refcnt_update(pkts[i], 1);
1142
1143                         vq->nr_zmbuf += 1;
1144                         TAILQ_INSERT_TAIL(&vq->zmbuf_list, zmbuf, next);
1145                 }
1146         }
1147         vq->last_avail_idx += i;
1148
1149         if (likely(dev->dequeue_zero_copy == 0)) {
1150                 vq->last_used_idx += i;
1151                 update_used_idx(dev, vq, i);
1152         }
1153
1154 out:
1155         if (unlikely(rarp_mbuf != NULL)) {
1156                 /*
1157                  * Inject it to the head of "pkts" array, so that switch's mac
1158                  * learning table will get updated first.
1159                  */
1160                 memmove(&pkts[1], pkts, i * sizeof(struct rte_mbuf *));
1161                 pkts[0] = rarp_mbuf;
1162                 i += 1;
1163         }
1164
1165         return i;
1166 }