vhost: use shadow used ring in dequeue path
[dpdk.git] / lib / librte_vhost / virtio_net.c
1 /* SPDX-License-Identifier: BSD-3-Clause
2  * Copyright(c) 2010-2016 Intel Corporation
3  */
4
5 #include <stdint.h>
6 #include <stdbool.h>
7 #include <linux/virtio_net.h>
8
9 #include <rte_mbuf.h>
10 #include <rte_memcpy.h>
11 #include <rte_ether.h>
12 #include <rte_ip.h>
13 #include <rte_vhost.h>
14 #include <rte_tcp.h>
15 #include <rte_udp.h>
16 #include <rte_sctp.h>
17 #include <rte_arp.h>
18 #include <rte_spinlock.h>
19 #include <rte_malloc.h>
20
21 #include "iotlb.h"
22 #include "vhost.h"
23
24 #define MAX_PKT_BURST 32
25
26 #define MAX_BATCH_LEN 256
27
28 static  __rte_always_inline bool
29 rxvq_is_mergeable(struct virtio_net *dev)
30 {
31         return dev->features & (1ULL << VIRTIO_NET_F_MRG_RXBUF);
32 }
33
34 static bool
35 is_valid_virt_queue_idx(uint32_t idx, int is_tx, uint32_t nr_vring)
36 {
37         return (is_tx ^ (idx & 1)) == 0 && idx < nr_vring;
38 }
39
40 static __rte_always_inline struct vring_desc *
41 alloc_copy_ind_table(struct virtio_net *dev, struct vhost_virtqueue *vq,
42                                          struct vring_desc *desc)
43 {
44         struct vring_desc *idesc;
45         uint64_t src, dst;
46         uint64_t len, remain = desc->len;
47         uint64_t desc_addr = desc->addr;
48
49         idesc = rte_malloc(__func__, desc->len, 0);
50         if (unlikely(!idesc))
51                 return 0;
52
53         dst = (uint64_t)(uintptr_t)idesc;
54
55         while (remain) {
56                 len = remain;
57                 src = vhost_iova_to_vva(dev, vq, desc_addr, &len,
58                                 VHOST_ACCESS_RO);
59                 if (unlikely(!src || !len)) {
60                         rte_free(idesc);
61                         return 0;
62                 }
63
64                 rte_memcpy((void *)(uintptr_t)dst, (void *)(uintptr_t)src, len);
65
66                 remain -= len;
67                 dst += len;
68                 desc_addr += len;
69         }
70
71         return idesc;
72 }
73
74 static __rte_always_inline void
75 free_ind_table(struct vring_desc *idesc)
76 {
77         rte_free(idesc);
78 }
79
80 static __rte_always_inline void
81 do_flush_shadow_used_ring(struct virtio_net *dev, struct vhost_virtqueue *vq,
82                           uint16_t to, uint16_t from, uint16_t size)
83 {
84         rte_memcpy(&vq->used->ring[to],
85                         &vq->shadow_used_ring[from],
86                         size * sizeof(struct vring_used_elem));
87         vhost_log_cache_used_vring(dev, vq,
88                         offsetof(struct vring_used, ring[to]),
89                         size * sizeof(struct vring_used_elem));
90 }
91
92 static __rte_always_inline void
93 flush_shadow_used_ring(struct virtio_net *dev, struct vhost_virtqueue *vq)
94 {
95         uint16_t used_idx = vq->last_used_idx & (vq->size - 1);
96
97         if (used_idx + vq->shadow_used_idx <= vq->size) {
98                 do_flush_shadow_used_ring(dev, vq, used_idx, 0,
99                                           vq->shadow_used_idx);
100         } else {
101                 uint16_t size;
102
103                 /* update used ring interval [used_idx, vq->size] */
104                 size = vq->size - used_idx;
105                 do_flush_shadow_used_ring(dev, vq, used_idx, 0, size);
106
107                 /* update the left half used ring interval [0, left_size] */
108                 do_flush_shadow_used_ring(dev, vq, 0, size,
109                                           vq->shadow_used_idx - size);
110         }
111         vq->last_used_idx += vq->shadow_used_idx;
112
113         rte_smp_wmb();
114
115         vhost_log_cache_sync(dev, vq);
116
117         *(volatile uint16_t *)&vq->used->idx += vq->shadow_used_idx;
118         vhost_log_used_vring(dev, vq, offsetof(struct vring_used, idx),
119                 sizeof(vq->used->idx));
120 }
121
122 static __rte_always_inline void
123 update_shadow_used_ring(struct vhost_virtqueue *vq,
124                          uint16_t desc_idx, uint16_t len)
125 {
126         uint16_t i = vq->shadow_used_idx++;
127
128         vq->shadow_used_ring[i].id  = desc_idx;
129         vq->shadow_used_ring[i].len = len;
130 }
131
132 static inline void
133 do_data_copy_enqueue(struct virtio_net *dev, struct vhost_virtqueue *vq)
134 {
135         struct batch_copy_elem *elem = vq->batch_copy_elems;
136         uint16_t count = vq->batch_copy_nb_elems;
137         int i;
138
139         for (i = 0; i < count; i++) {
140                 rte_memcpy(elem[i].dst, elem[i].src, elem[i].len);
141                 vhost_log_cache_write(dev, vq, elem[i].log_addr, elem[i].len);
142                 PRINT_PACKET(dev, (uintptr_t)elem[i].dst, elem[i].len, 0);
143         }
144 }
145
146 static inline void
147 do_data_copy_dequeue(struct vhost_virtqueue *vq)
148 {
149         struct batch_copy_elem *elem = vq->batch_copy_elems;
150         uint16_t count = vq->batch_copy_nb_elems;
151         int i;
152
153         for (i = 0; i < count; i++)
154                 rte_memcpy(elem[i].dst, elem[i].src, elem[i].len);
155 }
156
157 /* avoid write operation when necessary, to lessen cache issues */
158 #define ASSIGN_UNLESS_EQUAL(var, val) do {      \
159         if ((var) != (val))                     \
160                 (var) = (val);                  \
161 } while (0)
162
163 static __rte_always_inline void
164 virtio_enqueue_offload(struct rte_mbuf *m_buf, struct virtio_net_hdr *net_hdr)
165 {
166         uint64_t csum_l4 = m_buf->ol_flags & PKT_TX_L4_MASK;
167
168         if (m_buf->ol_flags & PKT_TX_TCP_SEG)
169                 csum_l4 |= PKT_TX_TCP_CKSUM;
170
171         if (csum_l4) {
172                 net_hdr->flags = VIRTIO_NET_HDR_F_NEEDS_CSUM;
173                 net_hdr->csum_start = m_buf->l2_len + m_buf->l3_len;
174
175                 switch (csum_l4) {
176                 case PKT_TX_TCP_CKSUM:
177                         net_hdr->csum_offset = (offsetof(struct tcp_hdr,
178                                                 cksum));
179                         break;
180                 case PKT_TX_UDP_CKSUM:
181                         net_hdr->csum_offset = (offsetof(struct udp_hdr,
182                                                 dgram_cksum));
183                         break;
184                 case PKT_TX_SCTP_CKSUM:
185                         net_hdr->csum_offset = (offsetof(struct sctp_hdr,
186                                                 cksum));
187                         break;
188                 }
189         } else {
190                 ASSIGN_UNLESS_EQUAL(net_hdr->csum_start, 0);
191                 ASSIGN_UNLESS_EQUAL(net_hdr->csum_offset, 0);
192                 ASSIGN_UNLESS_EQUAL(net_hdr->flags, 0);
193         }
194
195         /* IP cksum verification cannot be bypassed, then calculate here */
196         if (m_buf->ol_flags & PKT_TX_IP_CKSUM) {
197                 struct ipv4_hdr *ipv4_hdr;
198
199                 ipv4_hdr = rte_pktmbuf_mtod_offset(m_buf, struct ipv4_hdr *,
200                                                    m_buf->l2_len);
201                 ipv4_hdr->hdr_checksum = rte_ipv4_cksum(ipv4_hdr);
202         }
203
204         if (m_buf->ol_flags & PKT_TX_TCP_SEG) {
205                 if (m_buf->ol_flags & PKT_TX_IPV4)
206                         net_hdr->gso_type = VIRTIO_NET_HDR_GSO_TCPV4;
207                 else
208                         net_hdr->gso_type = VIRTIO_NET_HDR_GSO_TCPV6;
209                 net_hdr->gso_size = m_buf->tso_segsz;
210                 net_hdr->hdr_len = m_buf->l2_len + m_buf->l3_len
211                                         + m_buf->l4_len;
212         } else if (m_buf->ol_flags & PKT_TX_UDP_SEG) {
213                 net_hdr->gso_type = VIRTIO_NET_HDR_GSO_UDP;
214                 net_hdr->gso_size = m_buf->tso_segsz;
215                 net_hdr->hdr_len = m_buf->l2_len + m_buf->l3_len +
216                         m_buf->l4_len;
217         } else {
218                 ASSIGN_UNLESS_EQUAL(net_hdr->gso_type, 0);
219                 ASSIGN_UNLESS_EQUAL(net_hdr->gso_size, 0);
220                 ASSIGN_UNLESS_EQUAL(net_hdr->hdr_len, 0);
221         }
222 }
223
224 static __rte_always_inline int
225 fill_vec_buf(struct virtio_net *dev, struct vhost_virtqueue *vq,
226                          uint32_t avail_idx, uint32_t *vec_idx,
227                          struct buf_vector *buf_vec, uint16_t *desc_chain_head,
228                          uint16_t *desc_chain_len)
229 {
230         uint16_t idx = vq->avail->ring[avail_idx & (vq->size - 1)];
231         uint32_t vec_id = *vec_idx;
232         uint32_t len    = 0;
233         uint64_t dlen;
234         struct vring_desc *descs = vq->desc;
235         struct vring_desc *idesc = NULL;
236
237         *desc_chain_head = idx;
238
239         if (vq->desc[idx].flags & VRING_DESC_F_INDIRECT) {
240                 dlen = vq->desc[idx].len;
241                 descs = (struct vring_desc *)(uintptr_t)
242                         vhost_iova_to_vva(dev, vq, vq->desc[idx].addr,
243                                                 &dlen,
244                                                 VHOST_ACCESS_RO);
245                 if (unlikely(!descs))
246                         return -1;
247
248                 if (unlikely(dlen < vq->desc[idx].len)) {
249                         /*
250                          * The indirect desc table is not contiguous
251                          * in process VA space, we have to copy it.
252                          */
253                         idesc = alloc_copy_ind_table(dev, vq, &vq->desc[idx]);
254                         if (unlikely(!idesc))
255                                 return -1;
256
257                         descs = idesc;
258                 }
259
260                 idx = 0;
261         }
262
263         while (1) {
264                 if (unlikely(vec_id >= BUF_VECTOR_MAX || idx >= vq->size)) {
265                         free_ind_table(idesc);
266                         return -1;
267                 }
268
269                 len += descs[idx].len;
270                 buf_vec[vec_id].buf_addr = descs[idx].addr;
271                 buf_vec[vec_id].buf_len  = descs[idx].len;
272                 buf_vec[vec_id].desc_idx = idx;
273                 vec_id++;
274
275                 if ((descs[idx].flags & VRING_DESC_F_NEXT) == 0)
276                         break;
277
278                 idx = descs[idx].next;
279         }
280
281         *desc_chain_len = len;
282         *vec_idx = vec_id;
283
284         if (unlikely(!!idesc))
285                 free_ind_table(idesc);
286
287         return 0;
288 }
289
290 /*
291  * Returns -1 on fail, 0 on success
292  */
293 static inline int
294 reserve_avail_buf(struct virtio_net *dev, struct vhost_virtqueue *vq,
295                                 uint32_t size, struct buf_vector *buf_vec,
296                                 uint16_t *num_buffers, uint16_t avail_head)
297 {
298         uint16_t cur_idx;
299         uint32_t vec_idx = 0;
300         uint16_t max_tries, tries = 0;
301
302         uint16_t head_idx = 0;
303         uint16_t len = 0;
304
305         *num_buffers = 0;
306         cur_idx  = vq->last_avail_idx;
307
308         if (rxvq_is_mergeable(dev))
309                 max_tries = vq->size;
310         else
311                 max_tries = 1;
312
313         while (size > 0) {
314                 if (unlikely(cur_idx == avail_head))
315                         return -1;
316
317                 if (unlikely(fill_vec_buf(dev, vq, cur_idx, &vec_idx, buf_vec,
318                                                 &head_idx, &len) < 0))
319                         return -1;
320                 len = RTE_MIN(len, size);
321                 update_shadow_used_ring(vq, head_idx, len);
322                 size -= len;
323
324                 cur_idx++;
325                 tries++;
326                 *num_buffers += 1;
327
328                 /*
329                  * if we tried all available ring items, and still
330                  * can't get enough buf, it means something abnormal
331                  * happened.
332                  */
333                 if (unlikely(tries > max_tries))
334                         return -1;
335         }
336
337         return 0;
338 }
339
340 static __rte_always_inline int
341 copy_mbuf_to_desc(struct virtio_net *dev, struct vhost_virtqueue *vq,
342                             struct rte_mbuf *m, struct buf_vector *buf_vec,
343                             uint16_t num_buffers)
344 {
345         uint32_t vec_idx = 0;
346         uint64_t desc_addr, desc_gaddr;
347         uint32_t mbuf_offset, mbuf_avail;
348         uint32_t desc_offset, desc_avail;
349         uint32_t cpy_len;
350         uint64_t desc_chunck_len;
351         uint64_t hdr_addr, hdr_phys_addr;
352         struct rte_mbuf *hdr_mbuf;
353         struct batch_copy_elem *batch_copy = vq->batch_copy_elems;
354         struct virtio_net_hdr_mrg_rxbuf tmp_hdr, *hdr = NULL;
355         int error = 0;
356
357         if (unlikely(m == NULL)) {
358                 error = -1;
359                 goto out;
360         }
361
362         desc_chunck_len = buf_vec[vec_idx].buf_len;
363         desc_gaddr = buf_vec[vec_idx].buf_addr;
364         desc_addr = vhost_iova_to_vva(dev, vq,
365                                         desc_gaddr,
366                                         &desc_chunck_len,
367                                         VHOST_ACCESS_RW);
368         if (buf_vec[vec_idx].buf_len < dev->vhost_hlen || !desc_addr) {
369                 error = -1;
370                 goto out;
371         }
372
373         hdr_mbuf = m;
374         hdr_addr = desc_addr;
375         if (unlikely(desc_chunck_len < dev->vhost_hlen))
376                 hdr = &tmp_hdr;
377         else
378                 hdr = (struct virtio_net_hdr_mrg_rxbuf *)(uintptr_t)hdr_addr;
379         hdr_phys_addr = desc_gaddr;
380         rte_prefetch0((void *)(uintptr_t)hdr_addr);
381
382         VHOST_LOG_DEBUG(VHOST_DATA, "(%d) RX: num merge buffers %d\n",
383                 dev->vid, num_buffers);
384
385         desc_avail  = buf_vec[vec_idx].buf_len - dev->vhost_hlen;
386         if (unlikely(desc_chunck_len < dev->vhost_hlen)) {
387                 desc_chunck_len = desc_avail;
388                 desc_gaddr += dev->vhost_hlen;
389                 desc_addr = vhost_iova_to_vva(dev, vq,
390                                 desc_gaddr,
391                                 &desc_chunck_len,
392                                 VHOST_ACCESS_RW);
393                 if (unlikely(!desc_addr)) {
394                         error = -1;
395                         goto out;
396                 }
397
398                 desc_offset = 0;
399         } else {
400                 desc_offset = dev->vhost_hlen;
401                 desc_chunck_len -= dev->vhost_hlen;
402         }
403
404
405         mbuf_avail  = rte_pktmbuf_data_len(m);
406         mbuf_offset = 0;
407         while (mbuf_avail != 0 || m->next != NULL) {
408                 /* done with current desc buf, get the next one */
409                 if (desc_avail == 0) {
410                         vec_idx++;
411                         desc_chunck_len = buf_vec[vec_idx].buf_len;
412                         desc_gaddr = buf_vec[vec_idx].buf_addr;
413                         desc_addr =
414                                 vhost_iova_to_vva(dev, vq,
415                                         desc_gaddr,
416                                         &desc_chunck_len,
417                                         VHOST_ACCESS_RW);
418                         if (unlikely(!desc_addr)) {
419                                 error = -1;
420                                 goto out;
421                         }
422
423                         /* Prefetch buffer address. */
424                         rte_prefetch0((void *)(uintptr_t)desc_addr);
425                         desc_offset = 0;
426                         desc_avail  = buf_vec[vec_idx].buf_len;
427                 } else if (unlikely(desc_chunck_len == 0)) {
428                         desc_chunck_len = desc_avail;
429                         desc_gaddr += desc_offset;
430                         desc_addr = vhost_iova_to_vva(dev, vq,
431                                         desc_gaddr,
432                                         &desc_chunck_len, VHOST_ACCESS_RW);
433                         if (unlikely(!desc_addr)) {
434                                 error = -1;
435                                 goto out;
436                         }
437                         desc_offset = 0;
438                 }
439
440                 /* done with current mbuf, get the next one */
441                 if (mbuf_avail == 0) {
442                         m = m->next;
443
444                         mbuf_offset = 0;
445                         mbuf_avail  = rte_pktmbuf_data_len(m);
446                 }
447
448                 if (hdr_addr) {
449                         virtio_enqueue_offload(hdr_mbuf, &hdr->hdr);
450                         if (rxvq_is_mergeable(dev))
451                                 ASSIGN_UNLESS_EQUAL(hdr->num_buffers,
452                                                 num_buffers);
453
454                         if (unlikely(hdr == &tmp_hdr)) {
455                                 uint64_t len;
456                                 uint64_t remain = dev->vhost_hlen;
457                                 uint64_t src = (uint64_t)(uintptr_t)hdr, dst;
458                                 uint64_t guest_addr = hdr_phys_addr;
459
460                                 while (remain) {
461                                         len = remain;
462                                         dst = vhost_iova_to_vva(dev, vq,
463                                                         guest_addr, &len,
464                                                         VHOST_ACCESS_RW);
465                                         if (unlikely(!dst || !len)) {
466                                                 error = -1;
467                                                 goto out;
468                                         }
469
470                                         rte_memcpy((void *)(uintptr_t)dst,
471                                                         (void *)(uintptr_t)src,
472                                                         len);
473
474                                         PRINT_PACKET(dev, (uintptr_t)dst,
475                                                         (uint32_t)len, 0);
476                                         vhost_log_cache_write(dev, vq,
477                                                         guest_addr, len);
478
479                                         remain -= len;
480                                         guest_addr += len;
481                                         src += len;
482                                 }
483                         } else {
484                                 PRINT_PACKET(dev, (uintptr_t)hdr_addr,
485                                                 dev->vhost_hlen, 0);
486                                 vhost_log_cache_write(dev, vq, hdr_phys_addr,
487                                                 dev->vhost_hlen);
488                         }
489
490                         hdr_addr = 0;
491                 }
492
493                 cpy_len = RTE_MIN(desc_chunck_len, mbuf_avail);
494
495                 if (likely(cpy_len > MAX_BATCH_LEN ||
496                                         vq->batch_copy_nb_elems >= vq->size)) {
497                         rte_memcpy((void *)((uintptr_t)(desc_addr +
498                                                         desc_offset)),
499                                 rte_pktmbuf_mtod_offset(m, void *, mbuf_offset),
500                                 cpy_len);
501                         vhost_log_cache_write(dev, vq, desc_gaddr + desc_offset,
502                                         cpy_len);
503                         PRINT_PACKET(dev, (uintptr_t)(desc_addr + desc_offset),
504                                 cpy_len, 0);
505                 } else {
506                         batch_copy[vq->batch_copy_nb_elems].dst =
507                                 (void *)((uintptr_t)(desc_addr + desc_offset));
508                         batch_copy[vq->batch_copy_nb_elems].src =
509                                 rte_pktmbuf_mtod_offset(m, void *, mbuf_offset);
510                         batch_copy[vq->batch_copy_nb_elems].log_addr =
511                                 desc_gaddr + desc_offset;
512                         batch_copy[vq->batch_copy_nb_elems].len = cpy_len;
513                         vq->batch_copy_nb_elems++;
514                 }
515
516                 mbuf_avail  -= cpy_len;
517                 mbuf_offset += cpy_len;
518                 desc_avail  -= cpy_len;
519                 desc_offset += cpy_len;
520                 desc_chunck_len -= cpy_len;
521         }
522
523 out:
524
525         return error;
526 }
527
528 static __rte_always_inline uint32_t
529 virtio_dev_rx(struct virtio_net *dev, uint16_t queue_id,
530         struct rte_mbuf **pkts, uint32_t count)
531 {
532         struct vhost_virtqueue *vq;
533         uint32_t pkt_idx = 0;
534         uint16_t num_buffers;
535         struct buf_vector buf_vec[BUF_VECTOR_MAX];
536         uint16_t avail_head;
537
538         VHOST_LOG_DEBUG(VHOST_DATA, "(%d) %s\n", dev->vid, __func__);
539         if (unlikely(!is_valid_virt_queue_idx(queue_id, 0, dev->nr_vring))) {
540                 RTE_LOG(ERR, VHOST_DATA, "(%d) %s: invalid virtqueue idx %d.\n",
541                         dev->vid, __func__, queue_id);
542                 return 0;
543         }
544
545         vq = dev->virtqueue[queue_id];
546
547         rte_spinlock_lock(&vq->access_lock);
548
549         if (unlikely(vq->enabled == 0))
550                 goto out_access_unlock;
551
552         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
553                 vhost_user_iotlb_rd_lock(vq);
554
555         if (unlikely(vq->access_ok == 0))
556                 if (unlikely(vring_translate(dev, vq) < 0))
557                         goto out;
558
559         count = RTE_MIN((uint32_t)MAX_PKT_BURST, count);
560         if (count == 0)
561                 goto out;
562
563         vq->batch_copy_nb_elems = 0;
564
565         rte_prefetch0(&vq->avail->ring[vq->last_avail_idx & (vq->size - 1)]);
566
567         vq->shadow_used_idx = 0;
568         avail_head = *((volatile uint16_t *)&vq->avail->idx);
569         for (pkt_idx = 0; pkt_idx < count; pkt_idx++) {
570                 uint32_t pkt_len = pkts[pkt_idx]->pkt_len + dev->vhost_hlen;
571
572                 if (unlikely(reserve_avail_buf(dev, vq,
573                                                 pkt_len, buf_vec, &num_buffers,
574                                                 avail_head) < 0)) {
575                         VHOST_LOG_DEBUG(VHOST_DATA,
576                                 "(%d) failed to get enough desc from vring\n",
577                                 dev->vid);
578                         vq->shadow_used_idx -= num_buffers;
579                         break;
580                 }
581
582                 VHOST_LOG_DEBUG(VHOST_DATA, "(%d) current index %d | end index %d\n",
583                         dev->vid, vq->last_avail_idx,
584                         vq->last_avail_idx + num_buffers);
585
586                 if (copy_mbuf_to_desc(dev, vq, pkts[pkt_idx],
587                                                 buf_vec, num_buffers) < 0) {
588                         vq->shadow_used_idx -= num_buffers;
589                         break;
590                 }
591
592                 vq->last_avail_idx += num_buffers;
593         }
594
595         do_data_copy_enqueue(dev, vq);
596
597         if (likely(vq->shadow_used_idx)) {
598                 flush_shadow_used_ring(dev, vq);
599                 vhost_vring_call(dev, vq);
600         }
601
602 out:
603         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
604                 vhost_user_iotlb_rd_unlock(vq);
605
606 out_access_unlock:
607         rte_spinlock_unlock(&vq->access_lock);
608
609         return pkt_idx;
610 }
611
612 uint16_t
613 rte_vhost_enqueue_burst(int vid, uint16_t queue_id,
614         struct rte_mbuf **pkts, uint16_t count)
615 {
616         struct virtio_net *dev = get_device(vid);
617
618         if (!dev)
619                 return 0;
620
621         if (unlikely(!(dev->flags & VIRTIO_DEV_BUILTIN_VIRTIO_NET))) {
622                 RTE_LOG(ERR, VHOST_DATA,
623                         "(%d) %s: built-in vhost net backend is disabled.\n",
624                         dev->vid, __func__);
625                 return 0;
626         }
627
628         return virtio_dev_rx(dev, queue_id, pkts, count);
629 }
630
631 static inline bool
632 virtio_net_with_host_offload(struct virtio_net *dev)
633 {
634         if (dev->features &
635                         ((1ULL << VIRTIO_NET_F_CSUM) |
636                          (1ULL << VIRTIO_NET_F_HOST_ECN) |
637                          (1ULL << VIRTIO_NET_F_HOST_TSO4) |
638                          (1ULL << VIRTIO_NET_F_HOST_TSO6) |
639                          (1ULL << VIRTIO_NET_F_HOST_UFO)))
640                 return true;
641
642         return false;
643 }
644
645 static void
646 parse_ethernet(struct rte_mbuf *m, uint16_t *l4_proto, void **l4_hdr)
647 {
648         struct ipv4_hdr *ipv4_hdr;
649         struct ipv6_hdr *ipv6_hdr;
650         void *l3_hdr = NULL;
651         struct ether_hdr *eth_hdr;
652         uint16_t ethertype;
653
654         eth_hdr = rte_pktmbuf_mtod(m, struct ether_hdr *);
655
656         m->l2_len = sizeof(struct ether_hdr);
657         ethertype = rte_be_to_cpu_16(eth_hdr->ether_type);
658
659         if (ethertype == ETHER_TYPE_VLAN) {
660                 struct vlan_hdr *vlan_hdr = (struct vlan_hdr *)(eth_hdr + 1);
661
662                 m->l2_len += sizeof(struct vlan_hdr);
663                 ethertype = rte_be_to_cpu_16(vlan_hdr->eth_proto);
664         }
665
666         l3_hdr = (char *)eth_hdr + m->l2_len;
667
668         switch (ethertype) {
669         case ETHER_TYPE_IPv4:
670                 ipv4_hdr = l3_hdr;
671                 *l4_proto = ipv4_hdr->next_proto_id;
672                 m->l3_len = (ipv4_hdr->version_ihl & 0x0f) * 4;
673                 *l4_hdr = (char *)l3_hdr + m->l3_len;
674                 m->ol_flags |= PKT_TX_IPV4;
675                 break;
676         case ETHER_TYPE_IPv6:
677                 ipv6_hdr = l3_hdr;
678                 *l4_proto = ipv6_hdr->proto;
679                 m->l3_len = sizeof(struct ipv6_hdr);
680                 *l4_hdr = (char *)l3_hdr + m->l3_len;
681                 m->ol_flags |= PKT_TX_IPV6;
682                 break;
683         default:
684                 m->l3_len = 0;
685                 *l4_proto = 0;
686                 *l4_hdr = NULL;
687                 break;
688         }
689 }
690
691 static __rte_always_inline void
692 vhost_dequeue_offload(struct virtio_net_hdr *hdr, struct rte_mbuf *m)
693 {
694         uint16_t l4_proto = 0;
695         void *l4_hdr = NULL;
696         struct tcp_hdr *tcp_hdr = NULL;
697
698         if (hdr->flags == 0 && hdr->gso_type == VIRTIO_NET_HDR_GSO_NONE)
699                 return;
700
701         parse_ethernet(m, &l4_proto, &l4_hdr);
702         if (hdr->flags == VIRTIO_NET_HDR_F_NEEDS_CSUM) {
703                 if (hdr->csum_start == (m->l2_len + m->l3_len)) {
704                         switch (hdr->csum_offset) {
705                         case (offsetof(struct tcp_hdr, cksum)):
706                                 if (l4_proto == IPPROTO_TCP)
707                                         m->ol_flags |= PKT_TX_TCP_CKSUM;
708                                 break;
709                         case (offsetof(struct udp_hdr, dgram_cksum)):
710                                 if (l4_proto == IPPROTO_UDP)
711                                         m->ol_flags |= PKT_TX_UDP_CKSUM;
712                                 break;
713                         case (offsetof(struct sctp_hdr, cksum)):
714                                 if (l4_proto == IPPROTO_SCTP)
715                                         m->ol_flags |= PKT_TX_SCTP_CKSUM;
716                                 break;
717                         default:
718                                 break;
719                         }
720                 }
721         }
722
723         if (l4_hdr && hdr->gso_type != VIRTIO_NET_HDR_GSO_NONE) {
724                 switch (hdr->gso_type & ~VIRTIO_NET_HDR_GSO_ECN) {
725                 case VIRTIO_NET_HDR_GSO_TCPV4:
726                 case VIRTIO_NET_HDR_GSO_TCPV6:
727                         tcp_hdr = l4_hdr;
728                         m->ol_flags |= PKT_TX_TCP_SEG;
729                         m->tso_segsz = hdr->gso_size;
730                         m->l4_len = (tcp_hdr->data_off & 0xf0) >> 2;
731                         break;
732                 case VIRTIO_NET_HDR_GSO_UDP:
733                         m->ol_flags |= PKT_TX_UDP_SEG;
734                         m->tso_segsz = hdr->gso_size;
735                         m->l4_len = sizeof(struct udp_hdr);
736                         break;
737                 default:
738                         RTE_LOG(WARNING, VHOST_DATA,
739                                 "unsupported gso type %u.\n", hdr->gso_type);
740                         break;
741                 }
742         }
743 }
744
745 static __rte_always_inline void
746 put_zmbuf(struct zcopy_mbuf *zmbuf)
747 {
748         zmbuf->in_use = 0;
749 }
750
751 static __rte_always_inline int
752 copy_desc_to_mbuf(struct virtio_net *dev, struct vhost_virtqueue *vq,
753                   struct vring_desc *descs, uint16_t max_desc,
754                   struct rte_mbuf *m, uint16_t desc_idx,
755                   struct rte_mempool *mbuf_pool)
756 {
757         struct vring_desc *desc;
758         uint64_t desc_addr, desc_gaddr;
759         uint32_t desc_avail, desc_offset;
760         uint32_t mbuf_avail, mbuf_offset;
761         uint32_t cpy_len;
762         uint64_t desc_chunck_len;
763         struct rte_mbuf *cur = m, *prev = m;
764         struct virtio_net_hdr tmp_hdr;
765         struct virtio_net_hdr *hdr = NULL;
766         /* A counter to avoid desc dead loop chain */
767         uint32_t nr_desc = 1;
768         struct batch_copy_elem *batch_copy = vq->batch_copy_elems;
769         int error = 0;
770
771         desc = &descs[desc_idx];
772         if (unlikely((desc->len < dev->vhost_hlen)) ||
773                         (desc->flags & VRING_DESC_F_INDIRECT)) {
774                 error = -1;
775                 goto out;
776         }
777
778         desc_chunck_len = desc->len;
779         desc_gaddr = desc->addr;
780         desc_addr = vhost_iova_to_vva(dev,
781                                         vq, desc_gaddr,
782                                         &desc_chunck_len,
783                                         VHOST_ACCESS_RO);
784         if (unlikely(!desc_addr)) {
785                 error = -1;
786                 goto out;
787         }
788
789         if (virtio_net_with_host_offload(dev)) {
790                 if (unlikely(desc_chunck_len < sizeof(struct virtio_net_hdr))) {
791                         uint64_t len = desc_chunck_len;
792                         uint64_t remain = sizeof(struct virtio_net_hdr);
793                         uint64_t src = desc_addr;
794                         uint64_t dst = (uint64_t)(uintptr_t)&tmp_hdr;
795                         uint64_t guest_addr = desc_gaddr;
796
797                         /*
798                          * No luck, the virtio-net header doesn't fit
799                          * in a contiguous virtual area.
800                          */
801                         while (remain) {
802                                 len = remain;
803                                 src = vhost_iova_to_vva(dev, vq,
804                                                 guest_addr, &len,
805                                                 VHOST_ACCESS_RO);
806                                 if (unlikely(!src || !len)) {
807                                         error = -1;
808                                         goto out;
809                                 }
810
811                                 rte_memcpy((void *)(uintptr_t)dst,
812                                                    (void *)(uintptr_t)src, len);
813
814                                 guest_addr += len;
815                                 remain -= len;
816                                 dst += len;
817                         }
818
819                         hdr = &tmp_hdr;
820                 } else {
821                         hdr = (struct virtio_net_hdr *)((uintptr_t)desc_addr);
822                         rte_prefetch0(hdr);
823                 }
824         }
825
826         /*
827          * A virtio driver normally uses at least 2 desc buffers
828          * for Tx: the first for storing the header, and others
829          * for storing the data.
830          */
831         if (likely((desc->len == dev->vhost_hlen) &&
832                    (desc->flags & VRING_DESC_F_NEXT) != 0)) {
833                 desc = &descs[desc->next];
834                 if (unlikely(desc->flags & VRING_DESC_F_INDIRECT)) {
835                         error = -1;
836                         goto out;
837                 }
838
839                 desc_chunck_len = desc->len;
840                 desc_gaddr = desc->addr;
841                 desc_addr = vhost_iova_to_vva(dev,
842                                                         vq, desc_gaddr,
843                                                         &desc_chunck_len,
844                                                         VHOST_ACCESS_RO);
845                 if (unlikely(!desc_addr)) {
846                         error = -1;
847                         goto out;
848                 }
849
850                 desc_offset = 0;
851                 desc_avail  = desc->len;
852                 nr_desc    += 1;
853         } else {
854                 desc_avail  = desc->len - dev->vhost_hlen;
855
856                 if (unlikely(desc_chunck_len < dev->vhost_hlen)) {
857                         desc_chunck_len = desc_avail;
858                         desc_gaddr += dev->vhost_hlen;
859                         desc_addr = vhost_iova_to_vva(dev,
860                                         vq, desc_gaddr,
861                                         &desc_chunck_len,
862                                         VHOST_ACCESS_RO);
863                         if (unlikely(!desc_addr)) {
864                                 error = -1;
865                                 goto out;
866                         }
867
868                         desc_offset = 0;
869                 } else {
870                         desc_offset = dev->vhost_hlen;
871                         desc_chunck_len -= dev->vhost_hlen;
872                 }
873         }
874
875         rte_prefetch0((void *)(uintptr_t)(desc_addr + desc_offset));
876
877         PRINT_PACKET(dev, (uintptr_t)(desc_addr + desc_offset),
878                         (uint32_t)desc_chunck_len, 0);
879
880         mbuf_offset = 0;
881         mbuf_avail  = m->buf_len - RTE_PKTMBUF_HEADROOM;
882         while (1) {
883                 uint64_t hpa;
884
885                 cpy_len = RTE_MIN(desc_chunck_len, mbuf_avail);
886
887                 /*
888                  * A desc buf might across two host physical pages that are
889                  * not continuous. In such case (gpa_to_hpa returns 0), data
890                  * will be copied even though zero copy is enabled.
891                  */
892                 if (unlikely(dev->dequeue_zero_copy && (hpa = gpa_to_hpa(dev,
893                                         desc_gaddr + desc_offset, cpy_len)))) {
894                         cur->data_len = cpy_len;
895                         cur->data_off = 0;
896                         cur->buf_addr = (void *)(uintptr_t)(desc_addr
897                                 + desc_offset);
898                         cur->buf_iova = hpa;
899
900                         /*
901                          * In zero copy mode, one mbuf can only reference data
902                          * for one or partial of one desc buff.
903                          */
904                         mbuf_avail = cpy_len;
905                 } else {
906                         if (likely(cpy_len > MAX_BATCH_LEN ||
907                                    vq->batch_copy_nb_elems >= vq->size ||
908                                    (hdr && cur == m) ||
909                                    desc->len != desc_chunck_len)) {
910                                 rte_memcpy(rte_pktmbuf_mtod_offset(cur, void *,
911                                                                    mbuf_offset),
912                                            (void *)((uintptr_t)(desc_addr +
913                                                                 desc_offset)),
914                                            cpy_len);
915                         } else {
916                                 batch_copy[vq->batch_copy_nb_elems].dst =
917                                         rte_pktmbuf_mtod_offset(cur, void *,
918                                                                 mbuf_offset);
919                                 batch_copy[vq->batch_copy_nb_elems].src =
920                                         (void *)((uintptr_t)(desc_addr +
921                                                              desc_offset));
922                                 batch_copy[vq->batch_copy_nb_elems].len =
923                                         cpy_len;
924                                 vq->batch_copy_nb_elems++;
925                         }
926                 }
927
928                 mbuf_avail  -= cpy_len;
929                 mbuf_offset += cpy_len;
930                 desc_avail  -= cpy_len;
931                 desc_chunck_len -= cpy_len;
932                 desc_offset += cpy_len;
933
934                 /* This desc reaches to its end, get the next one */
935                 if (desc_avail == 0) {
936                         if ((desc->flags & VRING_DESC_F_NEXT) == 0)
937                                 break;
938
939                         if (unlikely(desc->next >= max_desc ||
940                                      ++nr_desc > max_desc)) {
941                                 error = -1;
942                                 goto out;
943                         }
944                         desc = &descs[desc->next];
945                         if (unlikely(desc->flags & VRING_DESC_F_INDIRECT)) {
946                                 error = -1;
947                                 goto out;
948                         }
949
950                         desc_chunck_len = desc->len;
951                         desc_gaddr = desc->addr;
952                         desc_addr = vhost_iova_to_vva(dev,
953                                                         vq, desc_gaddr,
954                                                         &desc_chunck_len,
955                                                         VHOST_ACCESS_RO);
956                         if (unlikely(!desc_addr)) {
957                                 error = -1;
958                                 goto out;
959                         }
960
961                         rte_prefetch0((void *)(uintptr_t)desc_addr);
962
963                         desc_offset = 0;
964                         desc_avail  = desc->len;
965
966                         PRINT_PACKET(dev, (uintptr_t)desc_addr,
967                                         (uint32_t)desc_chunck_len, 0);
968                 } else if (unlikely(desc_chunck_len == 0)) {
969                         desc_chunck_len = desc_avail;
970                         desc_gaddr += desc_offset;
971                         desc_addr = vhost_iova_to_vva(dev, vq,
972                                         desc_gaddr,
973                                         &desc_chunck_len,
974                                         VHOST_ACCESS_RO);
975                         if (unlikely(!desc_addr)) {
976                                 error = -1;
977                                 goto out;
978                         }
979                         desc_offset = 0;
980
981                         PRINT_PACKET(dev, (uintptr_t)desc_addr,
982                                         (uint32_t)desc_chunck_len, 0);
983                 }
984
985                 /*
986                  * This mbuf reaches to its end, get a new one
987                  * to hold more data.
988                  */
989                 if (mbuf_avail == 0) {
990                         cur = rte_pktmbuf_alloc(mbuf_pool);
991                         if (unlikely(cur == NULL)) {
992                                 RTE_LOG(ERR, VHOST_DATA, "Failed to "
993                                         "allocate memory for mbuf.\n");
994                                 error = -1;
995                                 goto out;
996                         }
997                         if (unlikely(dev->dequeue_zero_copy))
998                                 rte_mbuf_refcnt_update(cur, 1);
999
1000                         prev->next = cur;
1001                         prev->data_len = mbuf_offset;
1002                         m->nb_segs += 1;
1003                         m->pkt_len += mbuf_offset;
1004                         prev = cur;
1005
1006                         mbuf_offset = 0;
1007                         mbuf_avail  = cur->buf_len - RTE_PKTMBUF_HEADROOM;
1008                 }
1009         }
1010
1011         prev->data_len = mbuf_offset;
1012         m->pkt_len    += mbuf_offset;
1013
1014         if (hdr)
1015                 vhost_dequeue_offload(hdr, m);
1016
1017 out:
1018
1019         return error;
1020 }
1021
1022 static __rte_always_inline struct zcopy_mbuf *
1023 get_zmbuf(struct vhost_virtqueue *vq)
1024 {
1025         uint16_t i;
1026         uint16_t last;
1027         int tries = 0;
1028
1029         /* search [last_zmbuf_idx, zmbuf_size) */
1030         i = vq->last_zmbuf_idx;
1031         last = vq->zmbuf_size;
1032
1033 again:
1034         for (; i < last; i++) {
1035                 if (vq->zmbufs[i].in_use == 0) {
1036                         vq->last_zmbuf_idx = i + 1;
1037                         vq->zmbufs[i].in_use = 1;
1038                         return &vq->zmbufs[i];
1039                 }
1040         }
1041
1042         tries++;
1043         if (tries == 1) {
1044                 /* search [0, last_zmbuf_idx) */
1045                 i = 0;
1046                 last = vq->last_zmbuf_idx;
1047                 goto again;
1048         }
1049
1050         return NULL;
1051 }
1052
1053 static __rte_always_inline bool
1054 mbuf_is_consumed(struct rte_mbuf *m)
1055 {
1056         while (m) {
1057                 if (rte_mbuf_refcnt_read(m) > 1)
1058                         return false;
1059                 m = m->next;
1060         }
1061
1062         return true;
1063 }
1064
1065 static __rte_always_inline void
1066 restore_mbuf(struct rte_mbuf *m)
1067 {
1068         uint32_t mbuf_size, priv_size;
1069
1070         while (m) {
1071                 priv_size = rte_pktmbuf_priv_size(m->pool);
1072                 mbuf_size = sizeof(struct rte_mbuf) + priv_size;
1073                 /* start of buffer is after mbuf structure and priv data */
1074
1075                 m->buf_addr = (char *)m + mbuf_size;
1076                 m->buf_iova = rte_mempool_virt2iova(m) + mbuf_size;
1077                 m = m->next;
1078         }
1079 }
1080
1081 uint16_t
1082 rte_vhost_dequeue_burst(int vid, uint16_t queue_id,
1083         struct rte_mempool *mbuf_pool, struct rte_mbuf **pkts, uint16_t count)
1084 {
1085         struct virtio_net *dev;
1086         struct rte_mbuf *rarp_mbuf = NULL;
1087         struct vhost_virtqueue *vq;
1088         uint32_t desc_indexes[MAX_PKT_BURST];
1089         uint32_t i = 0;
1090         uint16_t free_entries;
1091         uint16_t avail_idx;
1092
1093         dev = get_device(vid);
1094         if (!dev)
1095                 return 0;
1096
1097         if (unlikely(!(dev->flags & VIRTIO_DEV_BUILTIN_VIRTIO_NET))) {
1098                 RTE_LOG(ERR, VHOST_DATA,
1099                         "(%d) %s: built-in vhost net backend is disabled.\n",
1100                         dev->vid, __func__);
1101                 return 0;
1102         }
1103
1104         if (unlikely(!is_valid_virt_queue_idx(queue_id, 1, dev->nr_vring))) {
1105                 RTE_LOG(ERR, VHOST_DATA, "(%d) %s: invalid virtqueue idx %d.\n",
1106                         dev->vid, __func__, queue_id);
1107                 return 0;
1108         }
1109
1110         vq = dev->virtqueue[queue_id];
1111
1112         if (unlikely(rte_spinlock_trylock(&vq->access_lock) == 0))
1113                 return 0;
1114
1115         if (unlikely(vq->enabled == 0))
1116                 goto out_access_unlock;
1117
1118         vq->batch_copy_nb_elems = 0;
1119         vq->shadow_used_idx = 0;
1120
1121         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
1122                 vhost_user_iotlb_rd_lock(vq);
1123
1124         if (unlikely(vq->access_ok == 0))
1125                 if (unlikely(vring_translate(dev, vq) < 0))
1126                         goto out;
1127
1128         if (unlikely(dev->dequeue_zero_copy)) {
1129                 struct zcopy_mbuf *zmbuf, *next;
1130                 int nr_updated = 0;
1131
1132                 for (zmbuf = TAILQ_FIRST(&vq->zmbuf_list);
1133                      zmbuf != NULL; zmbuf = next) {
1134                         next = TAILQ_NEXT(zmbuf, next);
1135
1136                         if (mbuf_is_consumed(zmbuf->mbuf)) {
1137                                 update_shadow_used_ring(vq, zmbuf->desc_idx, 0);
1138                                 nr_updated += 1;
1139
1140                                 TAILQ_REMOVE(&vq->zmbuf_list, zmbuf, next);
1141                                 restore_mbuf(zmbuf->mbuf);
1142                                 rte_pktmbuf_free(zmbuf->mbuf);
1143                                 put_zmbuf(zmbuf);
1144                                 vq->nr_zmbuf -= 1;
1145                         }
1146                 }
1147
1148                 flush_shadow_used_ring(dev, vq);
1149                 vhost_vring_call(dev, vq);
1150                 vq->shadow_used_idx = 0;
1151         }
1152
1153         /*
1154          * Construct a RARP broadcast packet, and inject it to the "pkts"
1155          * array, to looks like that guest actually send such packet.
1156          *
1157          * Check user_send_rarp() for more information.
1158          *
1159          * broadcast_rarp shares a cacheline in the virtio_net structure
1160          * with some fields that are accessed during enqueue and
1161          * rte_atomic16_cmpset() causes a write if using cmpxchg. This could
1162          * result in false sharing between enqueue and dequeue.
1163          *
1164          * Prevent unnecessary false sharing by reading broadcast_rarp first
1165          * and only performing cmpset if the read indicates it is likely to
1166          * be set.
1167          */
1168
1169         if (unlikely(rte_atomic16_read(&dev->broadcast_rarp) &&
1170                         rte_atomic16_cmpset((volatile uint16_t *)
1171                                 &dev->broadcast_rarp.cnt, 1, 0))) {
1172
1173                 rarp_mbuf = rte_net_make_rarp_packet(mbuf_pool, &dev->mac);
1174                 if (rarp_mbuf == NULL) {
1175                         RTE_LOG(ERR, VHOST_DATA,
1176                                 "Failed to make RARP packet.\n");
1177                         return 0;
1178                 }
1179                 count -= 1;
1180         }
1181
1182         free_entries = *((volatile uint16_t *)&vq->avail->idx) -
1183                         vq->last_avail_idx;
1184         if (free_entries == 0)
1185                 goto out;
1186
1187         VHOST_LOG_DEBUG(VHOST_DATA, "(%d) %s\n", dev->vid, __func__);
1188
1189         /* Prefetch available and used ring */
1190         avail_idx = vq->last_avail_idx & (vq->size - 1);
1191         rte_prefetch0(&vq->avail->ring[avail_idx]);
1192
1193         count = RTE_MIN(count, MAX_PKT_BURST);
1194         count = RTE_MIN(count, free_entries);
1195         VHOST_LOG_DEBUG(VHOST_DATA, "(%d) about to dequeue %u buffers\n",
1196                         dev->vid, count);
1197
1198         /* Retrieve all of the head indexes first to avoid caching issues. */
1199         for (i = 0; i < count; i++) {
1200                 avail_idx = (vq->last_avail_idx + i) & (vq->size - 1);
1201                 desc_indexes[i] = vq->avail->ring[avail_idx];
1202
1203                 if (likely(dev->dequeue_zero_copy == 0))
1204                         update_shadow_used_ring(vq, desc_indexes[i], 0);
1205         }
1206
1207         /* Prefetch descriptor index. */
1208         rte_prefetch0(&vq->desc[desc_indexes[0]]);
1209         for (i = 0; i < count; i++) {
1210                 struct vring_desc *desc, *idesc = NULL;
1211                 uint16_t sz, idx;
1212                 uint64_t dlen;
1213                 int err;
1214
1215                 if (likely(i + 1 < count))
1216                         rte_prefetch0(&vq->desc[desc_indexes[i + 1]]);
1217
1218                 if (vq->desc[desc_indexes[i]].flags & VRING_DESC_F_INDIRECT) {
1219                         dlen = vq->desc[desc_indexes[i]].len;
1220                         desc = (struct vring_desc *)(uintptr_t)
1221                                 vhost_iova_to_vva(dev, vq,
1222                                                 vq->desc[desc_indexes[i]].addr,
1223                                                 &dlen,
1224                                                 VHOST_ACCESS_RO);
1225                         if (unlikely(!desc))
1226                                 break;
1227
1228                         if (unlikely(dlen < vq->desc[desc_indexes[i]].len)) {
1229                                 /*
1230                                  * The indirect desc table is not contiguous
1231                                  * in process VA space, we have to copy it.
1232                                  */
1233                                 idesc = alloc_copy_ind_table(dev, vq,
1234                                                 &vq->desc[desc_indexes[i]]);
1235                                 if (unlikely(!idesc))
1236                                         break;
1237
1238                                 desc = idesc;
1239                         }
1240
1241                         rte_prefetch0(desc);
1242                         sz = vq->desc[desc_indexes[i]].len / sizeof(*desc);
1243                         idx = 0;
1244                 } else {
1245                         desc = vq->desc;
1246                         sz = vq->size;
1247                         idx = desc_indexes[i];
1248                 }
1249
1250                 pkts[i] = rte_pktmbuf_alloc(mbuf_pool);
1251                 if (unlikely(pkts[i] == NULL)) {
1252                         RTE_LOG(ERR, VHOST_DATA,
1253                                 "Failed to allocate memory for mbuf.\n");
1254                         free_ind_table(idesc);
1255                         break;
1256                 }
1257
1258                 err = copy_desc_to_mbuf(dev, vq, desc, sz, pkts[i], idx,
1259                                         mbuf_pool);
1260                 if (unlikely(err)) {
1261                         rte_pktmbuf_free(pkts[i]);
1262                         free_ind_table(idesc);
1263                         break;
1264                 }
1265
1266                 if (unlikely(dev->dequeue_zero_copy)) {
1267                         struct zcopy_mbuf *zmbuf;
1268
1269                         zmbuf = get_zmbuf(vq);
1270                         if (!zmbuf) {
1271                                 rte_pktmbuf_free(pkts[i]);
1272                                 free_ind_table(idesc);
1273                                 break;
1274                         }
1275                         zmbuf->mbuf = pkts[i];
1276                         zmbuf->desc_idx = desc_indexes[i];
1277
1278                         /*
1279                          * Pin lock the mbuf; we will check later to see
1280                          * whether the mbuf is freed (when we are the last
1281                          * user) or not. If that's the case, we then could
1282                          * update the used ring safely.
1283                          */
1284                         rte_mbuf_refcnt_update(pkts[i], 1);
1285
1286                         vq->nr_zmbuf += 1;
1287                         TAILQ_INSERT_TAIL(&vq->zmbuf_list, zmbuf, next);
1288                 }
1289
1290                 if (unlikely(!!idesc))
1291                         free_ind_table(idesc);
1292         }
1293         vq->last_avail_idx += i;
1294
1295         if (likely(dev->dequeue_zero_copy == 0)) {
1296                 do_data_copy_dequeue(vq);
1297                 if (unlikely(i < count))
1298                         vq->shadow_used_idx = i;
1299                 flush_shadow_used_ring(dev, vq);
1300                 vhost_vring_call(dev, vq);
1301         }
1302
1303 out:
1304         if (dev->features & (1ULL << VIRTIO_F_IOMMU_PLATFORM))
1305                 vhost_user_iotlb_rd_unlock(vq);
1306
1307 out_access_unlock:
1308         rte_spinlock_unlock(&vq->access_lock);
1309
1310         if (unlikely(rarp_mbuf != NULL)) {
1311                 /*
1312                  * Inject it to the head of "pkts" array, so that switch's mac
1313                  * learning table will get updated first.
1314                  */
1315                 memmove(&pkts[1], pkts, i * sizeof(struct rte_mbuf *));
1316                 pkts[0] = rarp_mbuf;
1317                 i += 1;
1318         }
1319
1320         return i;
1321 }