xref: /openbsd-src/sys/dev/pv/hyperv.c (revision 1a8dbaac879b9f3335ad7fb25429ce63ac1d6bac)
1 /*-
2  * Copyright (c) 2009-2012 Microsoft Corp.
3  * Copyright (c) 2012 NetApp Inc.
4  * Copyright (c) 2012 Citrix Inc.
5  * Copyright (c) 2016 Mike Belopuhov <mike@esdenera.com>
6  * All rights reserved.
7  *
8  * Redistribution and use in source and binary forms, with or without
9  * modification, are permitted provided that the following conditions
10  * are met:
11  * 1. Redistributions of source code must retain the above copyright
12  *    notice unmodified, this list of conditions, and the following
13  *    disclaimer.
14  * 2. Redistributions in binary form must reproduce the above copyright
15  *    notice, this list of conditions and the following disclaimer in the
16  *    documentation and/or other materials provided with the distribution.
17  *
18  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
19  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
20  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
21  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
22  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
23  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
24  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
25  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
27  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28  */
29 
30 /*
31  * The OpenBSD port was done under funding by Esdenera Networks GmbH.
32  */
33 
34 #include <sys/param.h>
35 
36 /* Hyperv requires locked atomic operations */
37 #ifndef MULTIPROCESSOR
38 #define _HYPERVMPATOMICS
39 #define MULTIPROCESSOR
40 #endif
41 #include <sys/atomic.h>
42 #ifdef _HYPERVMPATOMICS
43 #undef MULTIPROCESSOR
44 #undef _HYPERVMPATOMICS
45 #endif
46 
47 #include <sys/systm.h>
48 #include <sys/proc.h>
49 #include <sys/signal.h>
50 #include <sys/signalvar.h>
51 #include <sys/malloc.h>
52 #include <sys/kernel.h>
53 #include <sys/device.h>
54 #include <sys/timetc.h>
55 #include <sys/task.h>
56 #include <sys/syslog.h>
57 
58 #include <machine/bus.h>
59 #include <machine/cpu.h>
60 #include <machine/cpufunc.h>
61 
62 #include <uvm/uvm_extern.h>
63 
64 #include <machine/i82489var.h>
65 
66 #include <dev/pv/pvvar.h>
67 #include <dev/pv/pvreg.h>
68 #include <dev/pv/hypervreg.h>
69 #include <dev/pv/hypervvar.h>
70 
71 /* Command submission flags */
72 #define HCF_SLEEPOK	0x0001	/* M_WAITOK */
73 #define HCF_NOSLEEP	0x0002	/* M_NOWAIT */
74 #define HCF_NOREPLY	0x0004
75 
76 struct hv_softc *hv_sc;
77 
78 int 	hv_match(struct device *, void *, void *);
79 void	hv_attach(struct device *, struct device *, void *);
80 void	hv_set_version(struct hv_softc *);
81 u_int	hv_gettime(struct timecounter *);
82 int	hv_init_hypercall(struct hv_softc *);
83 uint64_t hv_hypercall(struct hv_softc *, uint64_t, void *, void *);
84 int	hv_init_interrupts(struct hv_softc *);
85 int	hv_init_synic(struct hv_softc *);
86 int	hv_cmd(struct hv_softc *, void *, size_t, void *, size_t, int);
87 int	hv_start(struct hv_softc *, struct hv_msg *);
88 int	hv_reply(struct hv_softc *, struct hv_msg *);
89 void	hv_wait(struct hv_softc *, int (*done)(struct hv_softc *,
90 	    struct hv_msg *), struct hv_msg *, void *, const char *);
91 uint16_t hv_intr_signal(struct hv_softc *, void *);
92 void	hv_intr(void);
93 void	hv_event_intr(struct hv_softc *);
94 void	hv_message_intr(struct hv_softc *);
95 int	hv_vmbus_connect(struct hv_softc *);
96 void	hv_channel_response(struct hv_softc *, struct vmbus_chanmsg_hdr *);
97 void	hv_channel_offer(struct hv_softc *, struct vmbus_chanmsg_hdr *);
98 void	hv_channel_rescind(struct hv_softc *, struct vmbus_chanmsg_hdr *);
99 void	hv_channel_delivered(struct hv_softc *, struct vmbus_chanmsg_hdr *);
100 int	hv_channel_scan(struct hv_softc *);
101 void	hv_process_offer(struct hv_softc *, struct hv_offer *);
102 struct hv_channel *
103 	hv_channel_lookup(struct hv_softc *, uint32_t);
104 int	hv_channel_ring_create(struct hv_channel *, uint32_t);
105 void	hv_channel_ring_destroy(struct hv_channel *);
106 void	hv_channel_pause(struct hv_channel *);
107 uint	hv_channel_unpause(struct hv_channel *);
108 uint	hv_channel_ready(struct hv_channel *);
109 extern void hv_attach_icdevs(struct hv_softc *);
110 int	hv_attach_devices(struct hv_softc *);
111 
112 struct {
113 	int		  hmd_response;
114 	int		  hmd_request;
115 	void		(*hmd_handler)(struct hv_softc *,
116 			    struct vmbus_chanmsg_hdr *);
117 } hv_msg_dispatch[] = {
118 	{ 0,					0, NULL },
119 	{ VMBUS_CHANMSG_CHOFFER,		0, hv_channel_offer },
120 	{ VMBUS_CHANMSG_CHRESCIND,		0, hv_channel_rescind },
121 	{ VMBUS_CHANMSG_CHREQUEST,		VMBUS_CHANMSG_CHOFFER,
122 	  NULL },
123 	{ VMBUS_CHANMSG_CHOFFER_DONE,		0,
124 	  hv_channel_delivered },
125 	{ VMBUS_CHANMSG_CHOPEN,			0, NULL },
126 	{ VMBUS_CHANMSG_CHOPEN_RESP,		VMBUS_CHANMSG_CHOPEN,
127 	  hv_channel_response },
128 	{ VMBUS_CHANMSG_CHCLOSE,		0, NULL },
129 	{ VMBUS_CHANMSG_GPADL_CONN,		0, NULL },
130 	{ VMBUS_CHANMSG_GPADL_SUBCONN,		0, NULL },
131 	{ VMBUS_CHANMSG_GPADL_CONNRESP,		VMBUS_CHANMSG_GPADL_CONN,
132 	  hv_channel_response },
133 	{ VMBUS_CHANMSG_GPADL_DISCONN,		0, NULL },
134 	{ VMBUS_CHANMSG_GPADL_DISCONNRESP,	VMBUS_CHANMSG_GPADL_DISCONN,
135 	  hv_channel_response },
136 	{ VMBUS_CHANMSG_CHFREE,			0, NULL },
137 	{ VMBUS_CHANMSG_CONNECT,		0, NULL },
138 	{ VMBUS_CHANMSG_CONNECT_RESP,		VMBUS_CHANMSG_CONNECT,
139 	  hv_channel_response },
140 	{ VMBUS_CHANMSG_DISCONNECT,		0, NULL },
141 };
142 
143 struct timecounter hv_timecounter = {
144 	hv_gettime, 0, 0xffffffff, 10000000, "hyperv", 9001, NULL, 0
145 };
146 
147 struct cfdriver hyperv_cd = {
148 	NULL, "hyperv", DV_DULL
149 };
150 
151 const struct cfattach hyperv_ca = {
152 	sizeof(struct hv_softc), hv_match, hv_attach
153 };
154 
155 const struct hv_guid hv_guid_network = {
156 	{ 0x63, 0x51, 0x61, 0xf8, 0x3e, 0xdf, 0xc5, 0x46,
157 	  0x91, 0x3f, 0xf2, 0xd2, 0xf9, 0x65, 0xed, 0x0e }
158 };
159 
160 const struct hv_guid hv_guid_ide = {
161 	{ 0x32, 0x26, 0x41, 0x32, 0xcb, 0x86, 0xa2, 0x44,
162 	  0x9b, 0x5c, 0x50, 0xd1, 0x41, 0x73, 0x54, 0xf5 }
163 };
164 
165 const struct hv_guid hv_guid_scsi = {
166 	{ 0xd9, 0x63, 0x61, 0xba, 0xa1, 0x04, 0x29, 0x4d,
167 	  0xb6, 0x05, 0x72, 0xe2, 0xff, 0xb1, 0xdc, 0x7f }
168 };
169 
170 const struct hv_guid hv_guid_shutdown = {
171 	{ 0x31, 0x60, 0x0b, 0x0e, 0x13, 0x52, 0x34, 0x49,
172 	  0x81, 0x8b, 0x38, 0xd9, 0x0c, 0xed, 0x39, 0xdb }
173 };
174 
175 const struct hv_guid hv_guid_timesync = {
176 	{ 0x30, 0xe6, 0x27, 0x95, 0xae, 0xd0, 0x7b, 0x49,
177 	  0xad, 0xce, 0xe8, 0x0a, 0xb0, 0x17, 0x5c, 0xaf }
178 };
179 
180 const struct hv_guid hv_guid_heartbeat = {
181 	{ 0x39, 0x4f, 0x16, 0x57, 0x15, 0x91, 0x78, 0x4e,
182 	  0xab, 0x55, 0x38, 0x2f, 0x3b, 0xd5, 0x42, 0x2d }
183 };
184 
185 const struct hv_guid hv_guid_kvp = {
186 	{ 0xe7, 0xf4, 0xa0, 0xa9, 0x45, 0x5a, 0x96, 0x4d,
187 	  0xb8, 0x27, 0x8a, 0x84, 0x1e, 0x8c, 0x03, 0xe6 }
188 };
189 
190 #ifdef HYPERV_DEBUG
191 const struct hv_guid hv_guid_vss = {
192 	{ 0x29, 0x2e, 0xfa, 0x35, 0x23, 0xea, 0x36, 0x42,
193 	  0x96, 0xae, 0x3a, 0x6e, 0xba, 0xcb, 0xa4, 0x40 }
194 };
195 
196 const struct hv_guid hv_guid_dynmem = {
197 	{ 0xdc, 0x74, 0x50, 0x52, 0x85, 0x89, 0xe2, 0x46,
198 	  0x80, 0x57, 0xa3, 0x07, 0xdc, 0x18, 0xa5, 0x02 }
199 };
200 
201 const struct hv_guid hv_guid_mouse = {
202 	{ 0x9e, 0xb6, 0xa8, 0xcf, 0x4a, 0x5b, 0xc0, 0x4c,
203 	  0xb9, 0x8b, 0x8b, 0xa1, 0xa1, 0xf3, 0xf9, 0x5a }
204 };
205 
206 const struct hv_guid hv_guid_kbd = {
207 	{ 0x6d, 0xad, 0x12, 0xf9, 0x17, 0x2b, 0xea, 0x48,
208 	  0xbd, 0x65, 0xf9, 0x27, 0xa6, 0x1c, 0x76, 0x84 }
209 };
210 
211 const struct hv_guid hv_guid_video = {
212 	{ 0x02, 0x78, 0x0a, 0xda, 0x77, 0xe3, 0xac, 0x4a,
213 	  0x8e, 0x77, 0x05, 0x58, 0xeb, 0x10, 0x73, 0xf8 }
214 };
215 
216 const struct hv_guid hv_guid_fc = {
217 	{ 0x4a, 0xcc, 0x9b, 0x2f, 0x69, 0x00, 0xf3, 0x4a,
218 	  0xb7, 0x6b, 0x6f, 0xd0, 0xbe, 0x52, 0x8c, 0xda }
219 };
220 
221 const struct hv_guid hv_guid_fcopy = {
222 	{ 0xe3, 0x4b, 0xd1, 0x34, 0xe4, 0xde, 0xc8, 0x41,
223 	  0x9a, 0xe7, 0x6b, 0x17, 0x49, 0x77, 0xc1, 0x92 }
224 };
225 
226 const struct hv_guid hv_guid_pcie = {
227 	{ 0x1d, 0xf6, 0xc4, 0x44, 0x44, 0x44, 0x00, 0x44,
228 	  0x9d, 0x52, 0x80, 0x2e, 0x27, 0xed, 0xe1, 0x9f }
229 };
230 
231 const struct hv_guid hv_guid_netdir = {
232 	{ 0x3d, 0xaf, 0x2e, 0x8c, 0xa7, 0x32, 0x09, 0x4b,
233 	  0xab, 0x99, 0xbd, 0x1f, 0x1c, 0x86, 0xb5, 0x01 }
234 };
235 
236 const struct hv_guid hv_guid_rdesktop = {
237 	{ 0xf4, 0xac, 0x6a, 0x27, 0x15, 0xac, 0x6c, 0x42,
238 	  0x98, 0xdd, 0x75, 0x21, 0xad, 0x3f, 0x01, 0xfe }
239 };
240 
241 /* Automatic Virtual Machine Activation (AVMA) Services */
242 const struct hv_guid hv_guid_avma1 = {
243 	{ 0x55, 0xb2, 0x87, 0x44, 0x8c, 0xb8, 0x3f, 0x40,
244 	  0xbb, 0x51, 0xd1, 0xf6, 0x9c, 0xf1, 0x7f, 0x87 }
245 };
246 
247 const struct hv_guid hv_guid_avma2 = {
248 	{ 0xf4, 0xba, 0x75, 0x33, 0x15, 0x9e, 0x30, 0x4b,
249 	  0xb7, 0x65, 0x67, 0xac, 0xb1, 0x0d, 0x60, 0x7b }
250 };
251 
252 const struct hv_guid hv_guid_avma3 = {
253 	{ 0xa0, 0x1f, 0x22, 0x99, 0xad, 0x24, 0xe2, 0x11,
254 	  0xbe, 0x98, 0x00, 0x1a, 0xa0, 0x1b, 0xbf, 0x6e }
255 };
256 
257 const struct hv_guid hv_guid_avma4 = {
258 	{ 0x16, 0x57, 0xe6, 0xf8, 0xb3, 0x3c, 0x06, 0x4a,
259 	  0x9a, 0x60, 0x18, 0x89, 0xc5, 0xcc, 0xca, 0xb5 }
260 };
261 #endif	/* HYPERV_DEBUG */
262 
263 int
264 hv_match(struct device *parent, void *match, void *aux)
265 {
266 	struct pv_attach_args *pva = aux;
267 	struct pvbus_hv *hv = &pva->pva_hv[PVBUS_HYPERV];
268 
269 	if ((hv->hv_major == 0 && hv->hv_minor == 0) || hv->hv_base == 0)
270 		return (0);
271 
272 	return (1);
273 }
274 
275 void
276 hv_attach(struct device *parent, struct device *self, void *aux)
277 {
278 	struct hv_softc *sc = (struct hv_softc *)self;
279 	struct pv_attach_args *pva = aux;
280 	struct pvbus_hv *hv = &pva->pva_hv[PVBUS_HYPERV];
281 
282 	sc->sc_pvbus = hv;
283 	sc->sc_dmat = pva->pva_dmat;
284 
285 	if (!(hv->hv_features & CPUID_HV_MSR_HYPERCALL) ||
286 	    !(hv->hv_features & CPUID_HV_MSR_SYNIC)) {
287 		printf(": not functional\n");
288 		return;
289 	}
290 
291 	DPRINTF("\n");
292 
293 	hv_set_version(sc);
294 
295 	if (hv->hv_features & CPUID_HV_MSR_TIME_REFCNT)
296 		tc_init(&hv_timecounter);
297 
298 	if (hv_init_hypercall(sc))
299 		return;
300 
301 	/* Wire it up to the global */
302 	hv_sc = sc;
303 
304 	if (hv_init_interrupts(sc))
305 		return;
306 
307 	if (hv_vmbus_connect(sc))
308 		return;
309 
310 	DPRINTF("%s", sc->sc_dev.dv_xname);
311 	printf(": protocol %d.%d, features %#x\n",
312 	    VMBUS_VERSION_MAJOR(sc->sc_proto),
313 	    VMBUS_VERSION_MINOR(sc->sc_proto),
314 	    hv->hv_features);
315 
316 	if (hv_channel_scan(sc))
317 		return;
318 
319 	/* Attach heartbeat, KVP and other "internal" services */
320 	hv_attach_icdevs(sc);
321 
322 	/* Attach devices with external drivers */
323 	hv_attach_devices(sc);
324 }
325 
326 void
327 hv_set_version(struct hv_softc *sc)
328 {
329 	uint64_t ver;
330 
331 	/* OpenBSD build date */
332 	ver = MSR_HV_GUESTID_OSTYPE_OPENBSD;
333 	ver |= (uint64_t)OpenBSD << MSR_HV_GUESTID_VERSION_SHIFT;
334 	wrmsr(MSR_HV_GUEST_OS_ID, ver);
335 }
336 
337 u_int
338 hv_gettime(struct timecounter *tc)
339 {
340 	u_int now = rdmsr(MSR_HV_TIME_REF_COUNT);
341 
342 	return (now);
343 }
344 
345 int
346 hv_init_hypercall(struct hv_softc *sc)
347 {
348 	extern void *hv_hypercall_page;
349 	uint64_t msr;
350 	paddr_t pa;
351 
352 	sc->sc_hc = &hv_hypercall_page;
353 
354 	if (!pmap_extract(pmap_kernel(), (vaddr_t)sc->sc_hc, &pa)) {
355 		printf(": hypercall page PA extraction failed\n");
356 		return (-1);
357 	}
358 
359 	msr = (atop(pa) << MSR_HV_HYPERCALL_PGSHIFT) | MSR_HV_HYPERCALL_ENABLE;
360 	wrmsr(MSR_HV_HYPERCALL, msr);
361 
362 	if (!(rdmsr(MSR_HV_HYPERCALL) & MSR_HV_HYPERCALL_ENABLE)) {
363 		printf(": failed to set up a hypercall page\n");
364 		return (-1);
365 	}
366 
367 	return (0);
368 }
369 
370 uint64_t
371 hv_hypercall(struct hv_softc *sc, uint64_t control, void *input,
372     void *output)
373 {
374 	paddr_t input_pa = 0, output_pa = 0;
375 	uint64_t status = 0;
376 
377 	if (input != NULL &&
378 	    pmap_extract(pmap_kernel(), (vaddr_t)input, &input_pa) == 0) {
379 		printf("%s: hypercall input PA extraction failed\n",
380 		    sc->sc_dev.dv_xname);
381 		return (~HYPERCALL_STATUS_SUCCESS);
382 	}
383 
384 	if (output != NULL &&
385 	    pmap_extract(pmap_kernel(), (vaddr_t)output, &output_pa) == 0) {
386 		printf("%s: hypercall output PA extraction failed\n",
387 		    sc->sc_dev.dv_xname);
388 		return (~HYPERCALL_STATUS_SUCCESS);
389 	}
390 
391 #ifdef __amd64__
392 	__asm__ __volatile__ ("mov %0, %%r8" : : "r" (output_pa) : "r8");
393 	__asm__ __volatile__ ("call *%3" : "=a" (status) : "c" (control),
394 	    "d" (input_pa), "m" (sc->sc_hc));
395 #else  /* __i386__ */
396 	{
397 		uint32_t control_hi = control >> 32;
398 		uint32_t control_lo = control & 0xfffffffff;
399 		uint32_t status_hi = 1;
400 		uint32_t status_lo = 1;
401 
402 		__asm__ __volatile__ ("call *%8" :
403 		    "=d" (status_hi), "=a"(status_lo) :
404 		    "d" (control_hi), "a" (control_lo),
405 		    "b" (0), "c" (input_pa), "D" (0), "S" (output_pa),
406 		    "m" (sc->sc_hc));
407 
408 		status = status_lo | ((uint64_t)status_hi << 32);
409 	}
410 #endif	/* __amd64__ */
411 
412 	return (status);
413 }
414 
415 int
416 hv_init_interrupts(struct hv_softc *sc)
417 {
418 	struct cpu_info *ci = curcpu();
419 	int cpu = CPU_INFO_UNIT(ci);
420 
421 	sc->sc_idtvec = LAPIC_HYPERV_VECTOR;
422 
423 	TAILQ_INIT(&sc->sc_reqs);
424 	mtx_init(&sc->sc_reqlck, IPL_NET);
425 
426 	TAILQ_INIT(&sc->sc_rsps);
427 	mtx_init(&sc->sc_rsplck, IPL_NET);
428 
429 	sc->sc_simp[cpu] = km_alloc(PAGE_SIZE, &kv_any, &kp_zero, &kd_nowait);
430 	if (sc->sc_simp[cpu] == NULL) {
431 		printf(": failed to allocate SIMP\n");
432 		return (-1);
433 	}
434 
435 	sc->sc_siep[cpu] = km_alloc(PAGE_SIZE, &kv_any, &kp_zero, &kd_nowait);
436 	if (sc->sc_siep[cpu] == NULL) {
437 		printf(": failed to allocate SIEP\n");
438 		km_free(sc->sc_simp[cpu], PAGE_SIZE, &kv_any, &kp_zero);
439 		return (-1);
440 	}
441 
442 	sc->sc_proto = VMBUS_VERSION_WS2008;
443 
444 	return (hv_init_synic(sc));
445 }
446 
447 int
448 hv_init_synic(struct hv_softc *sc)
449 {
450 	struct cpu_info *ci = curcpu();
451 	int cpu = CPU_INFO_UNIT(ci);
452 	uint64_t simp, siefp, sctrl, sint;
453 	paddr_t pa;
454 
455 	/*
456 	 * Setup the Synic's message page
457 	 */
458 	if (!pmap_extract(pmap_kernel(), (vaddr_t)sc->sc_simp[cpu], &pa)) {
459 		printf(": SIMP PA extraction failed\n");
460 		return (-1);
461 	}
462 	simp = rdmsr(MSR_HV_SIMP);
463 	simp &= (1 << MSR_HV_SIMP_PGSHIFT) - 1;
464 	simp |= (atop(pa) << MSR_HV_SIMP_PGSHIFT);
465 	simp |= MSR_HV_SIMP_ENABLE;
466 	wrmsr(MSR_HV_SIMP, simp);
467 
468 	/*
469 	 * Setup the Synic's event page
470 	 */
471 	if (!pmap_extract(pmap_kernel(), (vaddr_t)sc->sc_siep[cpu], &pa)) {
472 		printf(": SIEP PA extraction failed\n");
473 		return (-1);
474 	}
475 	siefp = rdmsr(MSR_HV_SIEFP);
476 	siefp &= (1<<MSR_HV_SIEFP_PGSHIFT) - 1;
477 	siefp |= (atop(pa) << MSR_HV_SIEFP_PGSHIFT);
478 	siefp |= MSR_HV_SIEFP_ENABLE;
479 	wrmsr(MSR_HV_SIEFP, siefp);
480 
481 	/*
482 	 * Configure and unmask SINT for message and event flags
483 	 */
484 	sint = rdmsr(MSR_HV_SINT0 + VMBUS_SINT_MESSAGE);
485 	sint = sc->sc_idtvec | MSR_HV_SINT_AUTOEOI |
486 	    (sint & MSR_HV_SINT_RSVD_MASK);
487 	wrmsr(MSR_HV_SINT0 + VMBUS_SINT_MESSAGE, sint);
488 
489 	/* Enable the global synic bit */
490 	sctrl = rdmsr(MSR_HV_SCONTROL);
491 	sctrl |= MSR_HV_SCTRL_ENABLE;
492 	wrmsr(MSR_HV_SCONTROL, sctrl);
493 
494 	sc->sc_vcpus[cpu] = rdmsr(MSR_HV_VP_INDEX);
495 
496 	DPRINTF("vcpu%u: SIMP %#llx SIEFP %#llx SCTRL %#llx\n",
497 	    sc->sc_vcpus[cpu], simp, siefp, sctrl);
498 
499 	return (0);
500 }
501 
502 int
503 hv_cmd(struct hv_softc *sc, void *cmd, size_t cmdlen, void *rsp,
504     size_t rsplen, int flags)
505 {
506 	struct hv_msg msg;
507 	int rv;
508 
509 	if (cmdlen > VMBUS_MSG_DSIZE_MAX) {
510 		printf("%s: payload too large (%lu)\n", sc->sc_dev.dv_xname,
511 		    cmdlen);
512 		return (EMSGSIZE);
513 	}
514 
515 	memset(&msg, 0, sizeof(msg));
516 
517 	msg.msg_req.hc_dsize = cmdlen;
518 	memcpy(msg.msg_req.hc_data, cmd, cmdlen);
519 
520 	if (!(flags & HCF_NOREPLY)) {
521 		msg.msg_rsp = rsp;
522 		msg.msg_rsplen = rsplen;
523 	} else
524 		msg.msg_flags |= MSGF_NOQUEUE;
525 
526 	if (flags & HCF_NOSLEEP)
527 		msg.msg_flags |= MSGF_NOSLEEP;
528 
529 	if ((rv = hv_start(sc, &msg)) != 0)
530 		return (rv);
531 	return (hv_reply(sc, &msg));
532 }
533 
534 int
535 hv_start(struct hv_softc *sc, struct hv_msg *msg)
536 {
537 	const int delays[] = { 100, 100, 100, 500, 500, 5000, 5000, 5000 };
538 	const char *wchan = "hvstart";
539 	uint16_t status;
540 	int i, s;
541 
542 	msg->msg_req.hc_connid = VMBUS_CONNID_MESSAGE;
543 	msg->msg_req.hc_msgtype = 1;
544 
545 	if (!(msg->msg_flags & MSGF_NOQUEUE)) {
546 		mtx_enter(&sc->sc_reqlck);
547 		TAILQ_INSERT_TAIL(&sc->sc_reqs, msg, msg_entry);
548 		mtx_leave(&sc->sc_reqlck);
549 	}
550 
551 	for (i = 0; i < nitems(delays); i++) {
552 		status = hv_hypercall(sc, HYPERCALL_POST_MESSAGE,
553 		    &msg->msg_req, NULL);
554 		if (status == HYPERCALL_STATUS_SUCCESS)
555 			break;
556 		if (msg->msg_flags & MSGF_NOSLEEP) {
557 			delay(delays[i]);
558 			s = splnet();
559 			hv_intr();
560 			splx(s);
561 		} else
562 			tsleep(wchan, PRIBIO, wchan, 1);
563 	}
564 	if (status != 0) {
565 		printf("%s: posting vmbus message failed with %d\n",
566 		    sc->sc_dev.dv_xname, status);
567 		if (!(msg->msg_flags & MSGF_NOQUEUE)) {
568 			mtx_enter(&sc->sc_reqlck);
569 			TAILQ_REMOVE(&sc->sc_reqs, msg, msg_entry);
570 			mtx_leave(&sc->sc_reqlck);
571 		}
572 		return (EIO);
573 	}
574 
575 	return (0);
576 }
577 
578 static int
579 hv_reply_done(struct hv_softc *sc, struct hv_msg *msg)
580 {
581 	struct hv_msg *m;
582 
583 	mtx_enter(&sc->sc_rsplck);
584 	TAILQ_FOREACH(m, &sc->sc_rsps, msg_entry) {
585 		if (m == msg) {
586 			mtx_leave(&sc->sc_rsplck);
587 			return (1);
588 		}
589 	}
590 	mtx_leave(&sc->sc_rsplck);
591 	return (0);
592 }
593 
594 int
595 hv_reply(struct hv_softc *sc, struct hv_msg *msg)
596 {
597 	if (msg->msg_flags & MSGF_NOQUEUE)
598 		return (0);
599 
600 	hv_wait(sc, hv_reply_done, msg, msg, "hvreply");
601 
602 	mtx_enter(&sc->sc_rsplck);
603 	TAILQ_REMOVE(&sc->sc_rsps, msg, msg_entry);
604 	mtx_leave(&sc->sc_rsplck);
605 
606 	return (0);
607 }
608 
609 void
610 hv_wait(struct hv_softc *sc, int (*cond)(struct hv_softc *, struct hv_msg *),
611     struct hv_msg *msg, void *wchan, const char *wmsg)
612 {
613 	int s;
614 
615 	KASSERT(cold ? msg->msg_flags & MSGF_NOSLEEP : 1);
616 
617 	while (!cond(sc, msg)) {
618 		if (msg->msg_flags & MSGF_NOSLEEP) {
619 			delay(1000);
620 			s = splnet();
621 			hv_intr();
622 			splx(s);
623 		} else
624 			tsleep(wchan, PRIBIO, wmsg ? wmsg : "hvwait", 1);
625 	}
626 }
627 
628 uint16_t
629 hv_intr_signal(struct hv_softc *sc, void *con)
630 {
631 	uint64_t status;
632 
633 	status = hv_hypercall(sc, HYPERCALL_SIGNAL_EVENT, con, NULL);
634 	return ((uint16_t)status);
635 }
636 
637 void
638 hv_intr(void)
639 {
640 	struct hv_softc *sc = hv_sc;
641 
642 	hv_event_intr(sc);
643 	hv_message_intr(sc);
644 }
645 
646 void
647 hv_event_intr(struct hv_softc *sc)
648 {
649 	struct vmbus_evtflags *evt;
650 	struct cpu_info *ci = curcpu();
651 	int cpu = CPU_INFO_UNIT(ci);
652 	int bit, row, maxrow, chanid;
653 	struct hv_channel *ch;
654 	u_long *revents, pending;
655 
656 	evt = (struct vmbus_evtflags *)sc->sc_siep[cpu] +
657 	    VMBUS_SINT_MESSAGE;
658 	if ((sc->sc_proto == VMBUS_VERSION_WS2008) ||
659 	    (sc->sc_proto == VMBUS_VERSION_WIN7)) {
660 		if (!test_bit(0, &evt->evt_flags[0]))
661 			return;
662 		clear_bit(0, &evt->evt_flags[0]);
663 		maxrow = VMBUS_CHAN_MAX_COMPAT / VMBUS_EVTFLAG_LEN;
664 		/*
665 		 * receive size is 1/2 page and divide that by 4 bytes
666 		 */
667 		revents = sc->sc_revents;
668 	} else {
669 		maxrow = nitems(evt->evt_flags);
670 		/*
671 		 * On Host with Win8 or above, the event page can be
672 		 * checked directly to get the id of the channel
673 		 * that has the pending interrupt.
674 		 */
675 		revents = &evt->evt_flags[0];
676 	}
677 
678 	for (row = 0; row < maxrow; row++) {
679 		if (revents[row] == 0)
680 			continue;
681 		pending = atomic_swap_ulong(&revents[row], 0);
682 		for (bit = 0; pending > 0; pending >>= 1, bit++) {
683 			if ((pending & 1) == 0)
684 				continue;
685 			chanid = (row * LONG_BIT) + bit;
686 			/* vmbus channel protocol message */
687 			if (chanid == 0)
688 				continue;
689 			ch = hv_channel_lookup(sc, chanid);
690 			if (ch == NULL) {
691 				printf("%s: unhandled event on %d\n",
692 				    sc->sc_dev.dv_xname, chanid);
693 				continue;
694 			}
695 			if (ch->ch_state != HV_CHANSTATE_OPENED) {
696 				printf("%s: channel %d is not active\n",
697 				    sc->sc_dev.dv_xname, chanid);
698 				continue;
699 			}
700 			ch->ch_evcnt.ec_count++;
701 			hv_channel_schedule(ch);
702 		}
703 	}
704 }
705 
706 void
707 hv_message_intr(struct hv_softc *sc)
708 {
709 	struct vmbus_message *msg;
710 	struct vmbus_chanmsg_hdr *hdr;
711 	struct cpu_info *ci = curcpu();
712 	int cpu = CPU_INFO_UNIT(ci);
713 
714 	for (;;) {
715 		msg = (struct vmbus_message *)sc->sc_simp[cpu] +
716 		    VMBUS_SINT_MESSAGE;
717 		if (msg->msg_type == VMBUS_MSGTYPE_NONE)
718 			break;
719 
720 		hdr = (struct vmbus_chanmsg_hdr *)msg->msg_data;
721 		if (hdr->chm_type >= VMBUS_CHANMSG_COUNT) {
722 			printf("%s: unhandled message type %u flags %#x\n",
723 			    sc->sc_dev.dv_xname, hdr->chm_type,
724 			    msg->msg_flags);
725 			goto skip;
726 		}
727 		if (hv_msg_dispatch[hdr->chm_type].hmd_handler)
728 			hv_msg_dispatch[hdr->chm_type].hmd_handler(sc, hdr);
729 		else
730 			printf("%s: unhandled message type %u\n",
731 			    sc->sc_dev.dv_xname, hdr->chm_type);
732  skip:
733 		msg->msg_type = VMBUS_MSGTYPE_NONE;
734 		virtio_membar_sync();
735 		if (msg->msg_flags & VMBUS_MSGFLAG_PENDING)
736 			wrmsr(MSR_HV_EOM, 0);
737 	}
738 }
739 
740 void
741 hv_channel_response(struct hv_softc *sc, struct vmbus_chanmsg_hdr *rsphdr)
742 {
743 	struct hv_msg *msg;
744 	struct vmbus_chanmsg_hdr *reqhdr;
745 	int req;
746 
747 	req = hv_msg_dispatch[rsphdr->chm_type].hmd_request;
748 	mtx_enter(&sc->sc_reqlck);
749 	TAILQ_FOREACH(msg, &sc->sc_reqs, msg_entry) {
750 		reqhdr = (struct vmbus_chanmsg_hdr *)&msg->msg_req.hc_data;
751 		if (reqhdr->chm_type == req) {
752 			TAILQ_REMOVE(&sc->sc_reqs, msg, msg_entry);
753 			break;
754 		}
755 	}
756 	mtx_leave(&sc->sc_reqlck);
757 	if (msg != NULL) {
758 		memcpy(msg->msg_rsp, rsphdr, msg->msg_rsplen);
759 		mtx_enter(&sc->sc_rsplck);
760 		TAILQ_INSERT_TAIL(&sc->sc_rsps, msg, msg_entry);
761 		mtx_leave(&sc->sc_rsplck);
762 		wakeup(msg);
763 	}
764 }
765 
766 void
767 hv_channel_offer(struct hv_softc *sc, struct vmbus_chanmsg_hdr *hdr)
768 {
769 	struct hv_offer *co;
770 
771 	co = malloc(sizeof(*co), M_DEVBUF, M_NOWAIT | M_ZERO);
772 	if (co == NULL) {
773 		printf("%s: failed to allocate an offer object\n",
774 		    sc->sc_dev.dv_xname);
775 		return;
776 	}
777 
778 	memcpy(&co->co_chan, hdr, sizeof(co->co_chan));
779 
780 	mtx_enter(&sc->sc_offerlck);
781 	SIMPLEQ_INSERT_TAIL(&sc->sc_offers, co, co_entry);
782 	mtx_leave(&sc->sc_offerlck);
783 }
784 
785 void
786 hv_channel_rescind(struct hv_softc *sc, struct vmbus_chanmsg_hdr *hdr)
787 {
788 	const struct vmbus_chanmsg_chrescind *cmd;
789 
790 	cmd = (const struct vmbus_chanmsg_chrescind *)hdr;
791 	printf("%s: revoking channel %u\n", sc->sc_dev.dv_xname,
792 	    cmd->chm_chanid);
793 }
794 
795 void
796 hv_channel_delivered(struct hv_softc *sc, struct vmbus_chanmsg_hdr *hdr)
797 {
798 	atomic_setbits_int(&sc->sc_flags, HSF_OFFERS_DELIVERED);
799 	wakeup(&sc->sc_offers);
800 }
801 
802 int
803 hv_vmbus_connect(struct hv_softc *sc)
804 {
805 	const uint32_t versions[] = {
806 		VMBUS_VERSION_WIN10,
807 		VMBUS_VERSION_WIN8_1, VMBUS_VERSION_WIN8,
808 		VMBUS_VERSION_WIN7, VMBUS_VERSION_WS2008
809 	};
810 	struct vmbus_chanmsg_connect cmd;
811 	struct vmbus_chanmsg_connect_resp rsp;
812 	paddr_t epa, mpa1, mpa2;
813 	int i;
814 
815 	sc->sc_events = km_alloc(PAGE_SIZE, &kv_any, &kp_zero, &kd_nowait);
816 	if (sc->sc_events == NULL) {
817 		printf(": failed to allocate channel port events page\n");
818 		goto errout;
819 	}
820 	if (!pmap_extract(pmap_kernel(), (vaddr_t)sc->sc_events, &epa)) {
821 		printf(": channel port events page PA extraction failed\n");
822 		goto errout;
823 	}
824 
825 	sc->sc_wevents = (u_long *)sc->sc_events;
826 	sc->sc_revents = (u_long *)((caddr_t)sc->sc_events + (PAGE_SIZE >> 1));
827 
828 	sc->sc_monitor[0] = km_alloc(PAGE_SIZE, &kv_any, &kp_zero, &kd_nowait);
829 	if (sc->sc_monitor[0] == NULL) {
830 		printf(": failed to allocate monitor page 1\n");
831 		goto errout;
832 	}
833 	if (!pmap_extract(pmap_kernel(), (vaddr_t)sc->sc_monitor[0], &mpa1)) {
834 		printf(": monitor page 1 PA extraction failed\n");
835 		goto errout;
836 	}
837 
838 	sc->sc_monitor[1] = km_alloc(PAGE_SIZE, &kv_any, &kp_zero, &kd_nowait);
839 	if (sc->sc_monitor[1] == NULL) {
840 		printf(": failed to allocate monitor page 2\n");
841 		goto errout;
842 	}
843 	if (!pmap_extract(pmap_kernel(), (vaddr_t)sc->sc_monitor[1], &mpa2)) {
844 		printf(": monitor page 2 PA extraction failed\n");
845 		goto errout;
846 	}
847 
848 	memset(&cmd, 0, sizeof(cmd));
849 	cmd.chm_hdr.chm_type = VMBUS_CHANMSG_CONNECT;
850 	cmd.chm_evtflags = (uint64_t)epa;
851 	cmd.chm_mnf1 = (uint64_t)mpa1;
852 	cmd.chm_mnf2 = (uint64_t)mpa2;
853 
854 	memset(&rsp, 0, sizeof(rsp));
855 
856 	for (i = 0; i < nitems(versions); i++) {
857 		cmd.chm_ver = versions[i];
858 		if (hv_cmd(sc, &cmd, sizeof(cmd), &rsp, sizeof(rsp),
859 		    HCF_NOSLEEP)) {
860 			DPRINTF("%s: CONNECT failed\n",
861 			    sc->sc_dev.dv_xname);
862 			goto errout;
863 		}
864 		if (rsp.chm_done) {
865 			sc->sc_flags |= HSF_CONNECTED;
866 			sc->sc_proto = versions[i];
867 			sc->sc_handle = VMBUS_GPADL_START;
868 			break;
869 		}
870 	}
871 	if (i == nitems(versions)) {
872 		printf("%s: failed to negotiate protocol version\n",
873 		    sc->sc_dev.dv_xname);
874 		goto errout;
875 	}
876 
877 	return (0);
878 
879  errout:
880 	if (sc->sc_events) {
881 		km_free(sc->sc_events, PAGE_SIZE, &kv_any, &kp_zero);
882 		sc->sc_events = NULL;
883 		sc->sc_wevents = NULL;
884 		sc->sc_revents = NULL;
885 	}
886 	if (sc->sc_monitor[0]) {
887 		km_free(sc->sc_monitor[0], PAGE_SIZE, &kv_any, &kp_zero);
888 		sc->sc_monitor[0] = NULL;
889 	}
890 	if (sc->sc_monitor[1]) {
891 		km_free(sc->sc_monitor[1], PAGE_SIZE, &kv_any, &kp_zero);
892 		sc->sc_monitor[1] = NULL;
893 	}
894 	return (-1);
895 }
896 
897 #ifdef HYPERV_DEBUG
898 static inline char *
899 guidprint(struct hv_guid *a)
900 {
901 	/* 3     0  5  4 7 6  8 9  10        15 */
902 	/* 33221100-5544-7766-9988-FFEEDDCCBBAA */
903 	static char buf[16 * 2 + 4 + 1];
904 	int i, j = 0;
905 
906 	for (i = 3; i != -1; i -= 1, j += 2)
907 		snprintf(&buf[j], 3, "%02x", (uint8_t)a->data[i]);
908 	buf[j++] = '-';
909 	for (i = 5; i != 3; i -= 1, j += 2)
910 		snprintf(&buf[j], 3, "%02x", (uint8_t)a->data[i]);
911 	buf[j++] = '-';
912 	for (i = 7; i != 5; i -= 1, j += 2)
913 		snprintf(&buf[j], 3, "%02x", (uint8_t)a->data[i]);
914 	buf[j++] = '-';
915 	for (i = 8; i < 10; i += 1, j += 2)
916 		snprintf(&buf[j], 3, "%02x", (uint8_t)a->data[i]);
917 	buf[j++] = '-';
918 	for (i = 10; i < 16; i += 1, j += 2)
919 		snprintf(&buf[j], 3, "%02x", (uint8_t)a->data[i]);
920 	return (&buf[0]);
921 }
922 #endif	/* HYPERV_DEBUG */
923 
924 void
925 hv_guid_sprint(struct hv_guid *guid, char *str, size_t size)
926 {
927 	const struct {
928 		const struct hv_guid	*guid;
929 		const char		*ident;
930 	} map[] = {
931 		{ &hv_guid_network,	"network" },
932 		{ &hv_guid_ide,		"ide" },
933 		{ &hv_guid_scsi,	"scsi" },
934 		{ &hv_guid_shutdown,	"shutdown" },
935 		{ &hv_guid_timesync,	"timesync" },
936 		{ &hv_guid_heartbeat,	"heartbeat" },
937 		{ &hv_guid_kvp,		"kvp" },
938 #ifdef HYPERV_DEBUG
939 		{ &hv_guid_vss,		"vss" },
940 		{ &hv_guid_dynmem,	"dynamic-memory" },
941 		{ &hv_guid_mouse,	"mouse" },
942 		{ &hv_guid_kbd,		"keyboard" },
943 		{ &hv_guid_video,	"video" },
944 		{ &hv_guid_fc,		"fiber-channel" },
945 		{ &hv_guid_fcopy,	"file-copy" },
946 		{ &hv_guid_pcie,	"pcie-passthrough" },
947 		{ &hv_guid_netdir,	"network-direct" },
948 		{ &hv_guid_rdesktop,	"remote-desktop" },
949 		{ &hv_guid_avma1,	"avma-1" },
950 		{ &hv_guid_avma2,	"avma-2" },
951 		{ &hv_guid_avma3,	"avma-3" },
952 		{ &hv_guid_avma4,	"avma-4" },
953 #endif
954 	};
955 	int i;
956 
957 	for (i = 0; i < nitems(map); i++) {
958 		if (memcmp(guid, map[i].guid, sizeof(*guid)) == 0) {
959 			strlcpy(str, map[i].ident, size);
960 			return;
961 		}
962 	}
963 #ifdef HYPERV_DEBUG
964 	strlcpy(str, guidprint(guid), size);
965 #endif
966 }
967 
968 static int
969 hv_channel_scan_done(struct hv_softc *sc, struct hv_msg *msg __unused)
970 {
971 	return (sc->sc_flags & HSF_OFFERS_DELIVERED);
972 }
973 
974 int
975 hv_channel_scan(struct hv_softc *sc)
976 {
977 	struct vmbus_chanmsg_hdr hdr;
978 	struct vmbus_chanmsg_choffer rsp;
979 	struct hv_offer *co;
980 
981 	SIMPLEQ_INIT(&sc->sc_offers);
982 	mtx_init(&sc->sc_offerlck, IPL_NET);
983 
984 	memset(&hdr, 0, sizeof(hdr));
985 	hdr.chm_type = VMBUS_CHANMSG_CHREQUEST;
986 
987 	if (hv_cmd(sc, &hdr, sizeof(hdr), &rsp, sizeof(rsp),
988 	    HCF_NOSLEEP | HCF_NOREPLY)) {
989 		DPRINTF("%s: CHREQUEST failed\n", sc->sc_dev.dv_xname);
990 		return (-1);
991 	}
992 
993 	hv_wait(sc, hv_channel_scan_done, (struct hv_msg *)&hdr,
994 	    &sc->sc_offers, "hvscan");
995 
996 	TAILQ_INIT(&sc->sc_channels);
997 	mtx_init(&sc->sc_channelck, IPL_NET);
998 
999 	mtx_enter(&sc->sc_offerlck);
1000 	while (!SIMPLEQ_EMPTY(&sc->sc_offers)) {
1001 		co = SIMPLEQ_FIRST(&sc->sc_offers);
1002 		SIMPLEQ_REMOVE_HEAD(&sc->sc_offers, co_entry);
1003 		mtx_leave(&sc->sc_offerlck);
1004 
1005 		hv_process_offer(sc, co);
1006 		free(co, M_DEVBUF, sizeof(*co));
1007 
1008 		mtx_enter(&sc->sc_offerlck);
1009 	}
1010 	mtx_leave(&sc->sc_offerlck);
1011 
1012 	return (0);
1013 }
1014 
1015 void
1016 hv_process_offer(struct hv_softc *sc, struct hv_offer *co)
1017 {
1018 	struct hv_channel *ch, *nch;
1019 
1020 	nch = malloc(sizeof(*nch), M_DEVBUF, M_ZERO | M_NOWAIT);
1021 	if (nch == NULL) {
1022 		printf("%s: failed to allocate memory for the channel\n",
1023 		    sc->sc_dev.dv_xname);
1024 		return;
1025 	}
1026 	nch->ch_sc = sc;
1027 	hv_guid_sprint(&co->co_chan.chm_chtype, nch->ch_ident,
1028 	    sizeof(nch->ch_ident));
1029 
1030 	/*
1031 	 * By default we setup state to enable batched reading.
1032 	 * A specific service can choose to disable this prior
1033 	 * to opening the channel.
1034 	 */
1035 	nch->ch_flags |= CHF_BATCHED;
1036 
1037 	KASSERT((((vaddr_t)&nch->ch_monprm) & 0x7) == 0);
1038 	memset(&nch->ch_monprm, 0, sizeof(nch->ch_monprm));
1039 	nch->ch_monprm.mp_connid = VMBUS_CONNID_EVENT;
1040 
1041 	if (sc->sc_proto != VMBUS_VERSION_WS2008)
1042 		nch->ch_monprm.mp_connid = co->co_chan.chm_connid;
1043 
1044 	if (co->co_chan.chm_flags1 & VMBUS_CHOFFER_FLAG1_HASMNF) {
1045 		nch->ch_mgroup = co->co_chan.chm_montrig / VMBUS_MONTRIG_LEN;
1046 		nch->ch_mindex = co->co_chan.chm_montrig % VMBUS_MONTRIG_LEN;
1047 		nch->ch_flags |= CHF_MONITOR;
1048 	}
1049 
1050 	nch->ch_id = co->co_chan.chm_chanid;
1051 
1052 	memcpy(&nch->ch_type, &co->co_chan.chm_chtype, sizeof(ch->ch_type));
1053 	memcpy(&nch->ch_inst, &co->co_chan.chm_chinst, sizeof(ch->ch_inst));
1054 
1055 	mtx_enter(&sc->sc_channelck);
1056 	TAILQ_FOREACH(ch, &sc->sc_channels, ch_entry) {
1057 		if (!memcmp(&ch->ch_type, &nch->ch_type, sizeof(ch->ch_type)) &&
1058 		    !memcmp(&ch->ch_inst, &nch->ch_inst, sizeof(ch->ch_inst)))
1059 			break;
1060 	}
1061 	if (ch != NULL) {
1062 		if (co->co_chan.chm_subidx == 0) {
1063 			printf("%s: unknown offer \"%s\"\n",
1064 			    sc->sc_dev.dv_xname, nch->ch_ident);
1065 			mtx_leave(&sc->sc_channelck);
1066 			free(nch, M_DEVBUF, sizeof(*nch));
1067 			return;
1068 		}
1069 #ifdef HYPERV_DEBUG
1070 		printf("%s: subchannel %u for \"%s\"\n", sc->sc_dev.dv_xname,
1071 		    co->co_chan.chm_subidx, ch->ch_ident);
1072 #endif
1073 		mtx_leave(&sc->sc_channelck);
1074 		free(nch, M_DEVBUF, sizeof(*nch));
1075 		return;
1076 	}
1077 
1078 	nch->ch_state = HV_CHANSTATE_OFFERED;
1079 
1080 	TAILQ_INSERT_TAIL(&sc->sc_channels, nch, ch_entry);
1081 	mtx_leave(&sc->sc_channelck);
1082 
1083 #ifdef HYPERV_DEBUG
1084 	printf("%s: channel %u: \"%s\"", sc->sc_dev.dv_xname, nch->ch_id,
1085 	    nch->ch_ident);
1086 	if (nch->ch_flags & CHF_MONITOR)
1087 		printf(", monitor %u\n", co->co_chan.chm_montrig);
1088 	else
1089 		printf("\n");
1090 #endif
1091 }
1092 
1093 struct hv_channel *
1094 hv_channel_lookup(struct hv_softc *sc, uint32_t relid)
1095 {
1096 	struct hv_channel *ch;
1097 
1098 	TAILQ_FOREACH(ch, &sc->sc_channels, ch_entry) {
1099 		if (ch->ch_id == relid)
1100 			return (ch);
1101 	}
1102 	return (NULL);
1103 }
1104 
1105 int
1106 hv_channel_ring_create(struct hv_channel *ch, uint32_t buflen)
1107 {
1108 	struct hv_softc *sc = ch->ch_sc;
1109 
1110 	buflen = roundup(buflen, PAGE_SIZE) + sizeof(struct vmbus_bufring);
1111 	ch->ch_ring = km_alloc(2 * buflen, &kv_any, &kp_zero, cold ?
1112 	    &kd_nowait : &kd_waitok);
1113 	if (ch->ch_ring == NULL) {
1114 		printf("%s: failed to allocate channel ring\n",
1115 		    sc->sc_dev.dv_xname);
1116 		return (-1);
1117 	}
1118 	ch->ch_ring_size = 2 * buflen;
1119 
1120 	memset(&ch->ch_wrd, 0, sizeof(ch->ch_wrd));
1121 	ch->ch_wrd.rd_ring = (struct vmbus_bufring *)ch->ch_ring;
1122 	ch->ch_wrd.rd_size = buflen;
1123 	ch->ch_wrd.rd_dsize = buflen - sizeof(struct vmbus_bufring);
1124 	mtx_init(&ch->ch_wrd.rd_lock, IPL_NET);
1125 
1126 	memset(&ch->ch_rrd, 0, sizeof(ch->ch_rrd));
1127 	ch->ch_rrd.rd_ring = (struct vmbus_bufring *)((uint8_t *)ch->ch_ring +
1128 	    buflen);
1129 	ch->ch_rrd.rd_size = buflen;
1130 	ch->ch_rrd.rd_dsize = buflen - sizeof(struct vmbus_bufring);
1131 	mtx_init(&ch->ch_rrd.rd_lock, IPL_NET);
1132 
1133 	if (hv_handle_alloc(ch, ch->ch_ring, 2 * buflen, &ch->ch_ring_gpadl)) {
1134 		printf("%s: failed to obtain a PA handle for the ring\n",
1135 		    sc->sc_dev.dv_xname);
1136 		hv_channel_ring_destroy(ch);
1137 		return (-1);
1138 	}
1139 
1140 	return (0);
1141 }
1142 
1143 void
1144 hv_channel_ring_destroy(struct hv_channel *ch)
1145 {
1146 	km_free(ch->ch_ring, ch->ch_ring_size, &kv_any, &kp_zero);
1147 	ch->ch_ring = NULL;
1148 	hv_handle_free(ch, ch->ch_ring_gpadl);
1149 
1150 	memset(&ch->ch_wrd, 0, sizeof(ch->ch_wrd));
1151 	memset(&ch->ch_rrd, 0, sizeof(ch->ch_rrd));
1152 }
1153 
1154 int
1155 hv_channel_open(struct hv_channel *ch, size_t buflen, void *udata,
1156     size_t udatalen, void (*handler)(void *), void *arg)
1157 {
1158 	struct hv_softc *sc = ch->ch_sc;
1159 	struct vmbus_chanmsg_chopen cmd;
1160 	struct vmbus_chanmsg_chopen_resp rsp;
1161 	int rv;
1162 
1163 	if (ch->ch_ring == NULL &&
1164 	    hv_channel_ring_create(ch, buflen)) {
1165 		DPRINTF("%s: failed to create channel ring\n",
1166 		    sc->sc_dev.dv_xname);
1167 		return (-1);
1168 	}
1169 
1170 	memset(&cmd, 0, sizeof(cmd));
1171 	cmd.chm_hdr.chm_type = VMBUS_CHANMSG_CHOPEN;
1172 	cmd.chm_openid = ch->ch_id;
1173 	cmd.chm_chanid = ch->ch_id;
1174 	cmd.chm_gpadl = ch->ch_ring_gpadl;
1175 	cmd.chm_txbr_pgcnt = ch->ch_wrd.rd_size >> PAGE_SHIFT;
1176 	cmd.chm_vcpuid = ch->ch_vcpu;
1177 
1178 	if (udata && udatalen > 0)
1179 		memcpy(cmd.chm_udata, udata, udatalen);
1180 
1181 	memset(&rsp, 0, sizeof(rsp));
1182 
1183 	ch->ch_handler = handler;
1184 	ch->ch_ctx = arg;
1185 
1186 	ch->ch_state = HV_CHANSTATE_OPENED;
1187 
1188 	rv = hv_cmd(sc, &cmd, sizeof(cmd), &rsp, sizeof(rsp),
1189 	    cold ? HCF_NOSLEEP : HCF_SLEEPOK);
1190 	if (rv) {
1191 		hv_channel_ring_destroy(ch);
1192 		DPRINTF("%s: CHOPEN failed with %d\n",
1193 		    sc->sc_dev.dv_xname, rv);
1194 		ch->ch_handler = NULL;
1195 		ch->ch_ctx = NULL;
1196 		ch->ch_state = HV_CHANSTATE_OFFERED;
1197 		return (-1);
1198 	}
1199 
1200 	return (0);
1201 }
1202 
1203 int
1204 hv_channel_close(struct hv_channel *ch)
1205 {
1206 	struct hv_softc *sc = ch->ch_sc;
1207 	struct vmbus_chanmsg_chclose cmd;
1208 	int rv;
1209 
1210 	memset(&cmd, 0, sizeof(cmd));
1211 	cmd.chm_hdr.chm_type = VMBUS_CHANMSG_CHCLOSE;
1212 	cmd.chm_chanid = ch->ch_id;
1213 
1214 	ch->ch_state = HV_CHANSTATE_CLOSING;
1215 	rv = hv_cmd(sc, &cmd, sizeof(cmd), NULL, 0, HCF_NOREPLY);
1216 	if (rv) {
1217 		DPRINTF("%s: CHCLOSE failed with %d\n",
1218 		    sc->sc_dev.dv_xname, rv);
1219 		return (-1);
1220 	}
1221 	ch->ch_state = HV_CHANSTATE_CLOSED;
1222 	hv_channel_ring_destroy(ch);
1223 	return (0);
1224 }
1225 
1226 static inline void
1227 hv_channel_setevent(struct hv_softc *sc, struct hv_channel *ch)
1228 {
1229 	struct vmbus_mon_trig *mtg;
1230 
1231 	/* Each uint32_t represents 32 channels */
1232 	set_bit(ch->ch_id, sc->sc_wevents);
1233 	if (ch->ch_flags & CHF_MONITOR) {
1234 		mtg = &sc->sc_monitor[1]->mnf_trigs[ch->ch_mgroup];
1235 		set_bit(ch->ch_mindex, &mtg->mt_pending);
1236 	} else
1237 		hv_intr_signal(sc, &ch->ch_monprm);
1238 }
1239 
1240 void
1241 hv_channel_intr(void *arg)
1242 {
1243 	struct hv_channel *ch = arg;
1244 
1245 	if (hv_channel_ready(ch))
1246 		ch->ch_handler(ch->ch_ctx);
1247 
1248 	if (hv_channel_unpause(ch) == 0)
1249 		return;
1250 
1251 	hv_channel_pause(ch);
1252 	hv_channel_schedule(ch);
1253 }
1254 
1255 int
1256 hv_channel_setdeferred(struct hv_channel *ch, const char *name)
1257 {
1258 	ch->ch_taskq = taskq_create(name, 1, IPL_NET, TASKQ_MPSAFE);
1259 	if (ch->ch_taskq == NULL)
1260 		return (-1);
1261 	task_set(&ch->ch_task, hv_channel_intr, ch);
1262 	return (0);
1263 }
1264 
1265 void
1266 hv_channel_schedule(struct hv_channel *ch)
1267 {
1268 	if (ch->ch_handler) {
1269 		if (!cold && (ch->ch_flags & CHF_BATCHED)) {
1270 			hv_channel_pause(ch);
1271 			task_add(ch->ch_taskq, &ch->ch_task);
1272 		} else
1273 			ch->ch_handler(ch->ch_ctx);
1274 	}
1275 }
1276 
1277 static inline void
1278 hv_ring_put(struct hv_ring_data *wrd, uint8_t *data, uint32_t datalen)
1279 {
1280 	int left = MIN(datalen, wrd->rd_dsize - wrd->rd_prod);
1281 
1282 	memcpy(&wrd->rd_ring->br_data[wrd->rd_prod], data, left);
1283 	memcpy(&wrd->rd_ring->br_data[0], data + left, datalen - left);
1284 	wrd->rd_prod += datalen;
1285 	if (wrd->rd_prod >= wrd->rd_dsize)
1286 		wrd->rd_prod -= wrd->rd_dsize;
1287 }
1288 
1289 static inline void
1290 hv_ring_get(struct hv_ring_data *rrd, uint8_t *data, uint32_t datalen,
1291     int peek)
1292 {
1293 	int left = MIN(datalen, rrd->rd_dsize - rrd->rd_cons);
1294 
1295 	memcpy(data, &rrd->rd_ring->br_data[rrd->rd_cons], left);
1296 	memcpy(data + left, &rrd->rd_ring->br_data[0], datalen - left);
1297 	if (!peek) {
1298 		rrd->rd_cons += datalen;
1299 		if (rrd->rd_cons >= rrd->rd_dsize)
1300 			rrd->rd_cons -= rrd->rd_dsize;
1301 	}
1302 }
1303 
1304 static inline void
1305 hv_ring_avail(struct hv_ring_data *rd, uint32_t *towrite, uint32_t *toread)
1306 {
1307 	uint32_t ridx = rd->rd_ring->br_rindex;
1308 	uint32_t widx = rd->rd_ring->br_windex;
1309 	uint32_t r, w;
1310 
1311 	if (widx >= ridx)
1312 		w = rd->rd_dsize - (widx - ridx);
1313 	else
1314 		w = ridx - widx;
1315 	r = rd->rd_dsize - w;
1316 	if (towrite)
1317 		*towrite = w;
1318 	if (toread)
1319 		*toread = r;
1320 }
1321 
1322 int
1323 hv_ring_write(struct hv_ring_data *wrd, struct iovec *iov, int iov_cnt,
1324     int *needsig)
1325 {
1326 	uint64_t indices = 0;
1327 	uint32_t avail, oprod, datalen = sizeof(indices);
1328 	int i;
1329 
1330 	for (i = 0; i < iov_cnt; i++)
1331 		datalen += iov[i].iov_len;
1332 
1333 	KASSERT(datalen <= wrd->rd_dsize);
1334 
1335 	hv_ring_avail(wrd, &avail, NULL);
1336 	if (avail <= datalen) {
1337 		DPRINTF("%s: avail %u datalen %u\n", __func__, avail, datalen);
1338 		return (EAGAIN);
1339 	}
1340 
1341 	oprod = wrd->rd_prod;
1342 
1343 	for (i = 0; i < iov_cnt; i++)
1344 		hv_ring_put(wrd, iov[i].iov_base, iov[i].iov_len);
1345 
1346 	indices = (uint64_t)oprod << 32;
1347 	hv_ring_put(wrd, (uint8_t *)&indices, sizeof(indices));
1348 
1349 	virtio_membar_sync();
1350 	wrd->rd_ring->br_windex = wrd->rd_prod;
1351 	virtio_membar_sync();
1352 
1353 	/* Signal when the ring transitions from being empty to non-empty */
1354 	if (wrd->rd_ring->br_imask == 0 &&
1355 	    wrd->rd_ring->br_rindex == oprod)
1356 		*needsig = 1;
1357 	else
1358 		*needsig = 0;
1359 
1360 	return (0);
1361 }
1362 
1363 int
1364 hv_channel_send(struct hv_channel *ch, void *data, uint32_t datalen,
1365     uint64_t rid, int type, uint32_t flags)
1366 {
1367 	struct hv_softc *sc = ch->ch_sc;
1368 	struct vmbus_chanpkt cp;
1369 	struct iovec iov[3];
1370 	uint32_t pktlen, pktlen_aligned;
1371 	uint64_t zeropad = 0;
1372 	int rv, needsig = 0;
1373 
1374 	pktlen = sizeof(cp) + datalen;
1375 	pktlen_aligned = roundup(pktlen, sizeof(uint64_t));
1376 
1377 	cp.cp_hdr.cph_type = type;
1378 	cp.cp_hdr.cph_flags = flags;
1379 	VMBUS_CHANPKT_SETLEN(cp.cp_hdr.cph_hlen, sizeof(cp));
1380 	VMBUS_CHANPKT_SETLEN(cp.cp_hdr.cph_tlen, pktlen_aligned);
1381 	cp.cp_hdr.cph_tid = rid;
1382 
1383 	iov[0].iov_base = &cp;
1384 	iov[0].iov_len = sizeof(cp);
1385 
1386 	iov[1].iov_base = data;
1387 	iov[1].iov_len = datalen;
1388 
1389 	iov[2].iov_base = &zeropad;
1390 	iov[2].iov_len = pktlen_aligned - pktlen;
1391 
1392 	mtx_enter(&ch->ch_wrd.rd_lock);
1393 	rv = hv_ring_write(&ch->ch_wrd, iov, 3, &needsig);
1394 	mtx_leave(&ch->ch_wrd.rd_lock);
1395 	if (rv == 0 && needsig)
1396 		hv_channel_setevent(sc, ch);
1397 
1398 	return (rv);
1399 }
1400 
1401 int
1402 hv_channel_send_sgl(struct hv_channel *ch, struct vmbus_gpa *sgl,
1403     uint32_t nsge, void *data, uint32_t datalen, uint64_t rid)
1404 {
1405 	struct hv_softc *sc = ch->ch_sc;
1406 	struct vmbus_chanpkt_sglist cp;
1407 	struct iovec iov[4];
1408 	uint32_t buflen, pktlen, pktlen_aligned;
1409 	uint64_t zeropad = 0;
1410 	int rv, needsig = 0;
1411 
1412 	buflen = sizeof(struct vmbus_gpa) * nsge;
1413 	pktlen = sizeof(cp) + datalen + buflen;
1414 	pktlen_aligned = roundup(pktlen, sizeof(uint64_t));
1415 
1416 	cp.cp_hdr.cph_type = VMBUS_CHANPKT_TYPE_GPA;
1417 	cp.cp_hdr.cph_flags = VMBUS_CHANPKT_FLAG_RC;
1418 	VMBUS_CHANPKT_SETLEN(cp.cp_hdr.cph_hlen, sizeof(cp) + buflen);
1419 	VMBUS_CHANPKT_SETLEN(cp.cp_hdr.cph_tlen, pktlen_aligned);
1420 	cp.cp_hdr.cph_tid = rid;
1421 	cp.cp_gpa_cnt = nsge;
1422 	cp.cp_rsvd = 0;
1423 
1424 	iov[0].iov_base = &cp;
1425 	iov[0].iov_len = sizeof(cp);
1426 
1427 	iov[1].iov_base = sgl;
1428 	iov[1].iov_len = buflen;
1429 
1430 	iov[2].iov_base = data;
1431 	iov[2].iov_len = datalen;
1432 
1433 	iov[3].iov_base = &zeropad;
1434 	iov[3].iov_len = pktlen_aligned - pktlen;
1435 
1436 	mtx_enter(&ch->ch_wrd.rd_lock);
1437 	rv = hv_ring_write(&ch->ch_wrd, iov, 4, &needsig);
1438 	mtx_leave(&ch->ch_wrd.rd_lock);
1439 	if (rv == 0 && needsig)
1440 		hv_channel_setevent(sc, ch);
1441 
1442 	return (rv);
1443 }
1444 
1445 int
1446 hv_channel_send_prpl(struct hv_channel *ch, struct vmbus_gpa_range *prpl,
1447     uint32_t nprp, void *data, uint32_t datalen, uint64_t rid)
1448 {
1449 	struct hv_softc *sc = ch->ch_sc;
1450 	struct vmbus_chanpkt_prplist cp;
1451 	struct iovec iov[4];
1452 	uint32_t buflen, pktlen, pktlen_aligned;
1453 	uint64_t zeropad = 0;
1454 	int rv, needsig = 0;
1455 
1456 	buflen = sizeof(struct vmbus_gpa_range) * (nprp + 1);
1457 	pktlen = sizeof(cp) + datalen + buflen;
1458 	pktlen_aligned = roundup(pktlen, sizeof(uint64_t));
1459 
1460 	cp.cp_hdr.cph_type = VMBUS_CHANPKT_TYPE_GPA;
1461 	cp.cp_hdr.cph_flags = VMBUS_CHANPKT_FLAG_RC;
1462 	VMBUS_CHANPKT_SETLEN(cp.cp_hdr.cph_hlen, sizeof(cp) + buflen);
1463 	VMBUS_CHANPKT_SETLEN(cp.cp_hdr.cph_tlen, pktlen_aligned);
1464 	cp.cp_hdr.cph_tid = rid;
1465 	cp.cp_range_cnt = 1;
1466 	cp.cp_rsvd = 0;
1467 
1468 	iov[0].iov_base = &cp;
1469 	iov[0].iov_len = sizeof(cp);
1470 
1471 	iov[1].iov_base = prpl;
1472 	iov[1].iov_len = buflen;
1473 
1474 	iov[2].iov_base = data;
1475 	iov[2].iov_len = datalen;
1476 
1477 	iov[3].iov_base = &zeropad;
1478 	iov[3].iov_len = pktlen_aligned - pktlen;
1479 
1480 	mtx_enter(&ch->ch_wrd.rd_lock);
1481 	rv = hv_ring_write(&ch->ch_wrd, iov, 4, &needsig);
1482 	mtx_leave(&ch->ch_wrd.rd_lock);
1483 	if (rv == 0 && needsig)
1484 		hv_channel_setevent(sc, ch);
1485 
1486 	return (rv);
1487 }
1488 
1489 int
1490 hv_ring_peek(struct hv_ring_data *rrd, void *data, uint32_t datalen)
1491 {
1492 	uint32_t avail;
1493 
1494 	KASSERT(datalen <= rrd->rd_dsize);
1495 
1496 	hv_ring_avail(rrd, NULL, &avail);
1497 	if (avail < datalen)
1498 		return (EAGAIN);
1499 
1500 	hv_ring_get(rrd, (uint8_t *)data, datalen, 1);
1501 	return (0);
1502 }
1503 
1504 int
1505 hv_ring_read(struct hv_ring_data *rrd, void *data, uint32_t datalen,
1506     uint32_t offset)
1507 {
1508 	uint64_t indices;
1509 	uint32_t avail;
1510 
1511 	KASSERT(datalen <= rrd->rd_dsize);
1512 
1513 	hv_ring_avail(rrd, NULL, &avail);
1514 	if (avail < datalen) {
1515 		DPRINTF("%s: avail %u datalen %u\n", __func__, avail, datalen);
1516 		return (EAGAIN);
1517 	}
1518 
1519 	if (offset) {
1520 		rrd->rd_cons += offset;
1521 		if (rrd->rd_cons >= rrd->rd_dsize)
1522 			rrd->rd_cons -= rrd->rd_dsize;
1523 	}
1524 
1525 	hv_ring_get(rrd, (uint8_t *)data, datalen, 0);
1526 	hv_ring_get(rrd, (uint8_t *)&indices, sizeof(indices), 0);
1527 
1528 	virtio_membar_sync();
1529 	rrd->rd_ring->br_rindex = rrd->rd_cons;
1530 
1531 	return (0);
1532 }
1533 
1534 int
1535 hv_channel_recv(struct hv_channel *ch, void *data, uint32_t datalen,
1536     uint32_t *rlen, uint64_t *rid, int raw)
1537 {
1538 	struct vmbus_chanpkt_hdr cph;
1539 	uint32_t offset, pktlen;
1540 	int rv;
1541 
1542 	*rlen = 0;
1543 
1544 	mtx_enter(&ch->ch_rrd.rd_lock);
1545 
1546 	if ((rv = hv_ring_peek(&ch->ch_rrd, &cph, sizeof(cph))) != 0) {
1547 		mtx_leave(&ch->ch_rrd.rd_lock);
1548 		return (rv);
1549 	}
1550 
1551 	offset = raw ? 0 : VMBUS_CHANPKT_GETLEN(cph.cph_hlen);
1552 	pktlen = VMBUS_CHANPKT_GETLEN(cph.cph_tlen) - offset;
1553 	if (pktlen > datalen) {
1554 		mtx_leave(&ch->ch_rrd.rd_lock);
1555 		printf("%s: pktlen %u datalen %u\n", __func__, pktlen, datalen);
1556 		return (EINVAL);
1557 	}
1558 
1559 	rv = hv_ring_read(&ch->ch_rrd, data, pktlen, offset);
1560 	if (rv == 0) {
1561 		*rlen = pktlen;
1562 		*rid = cph.cph_tid;
1563 	}
1564 
1565 	mtx_leave(&ch->ch_rrd.rd_lock);
1566 
1567 	return (rv);
1568 }
1569 
1570 static inline void
1571 hv_ring_mask(struct hv_ring_data *rd)
1572 {
1573 	virtio_membar_sync();
1574 	rd->rd_ring->br_imask = 1;
1575 	virtio_membar_sync();
1576 }
1577 
1578 static inline void
1579 hv_ring_unmask(struct hv_ring_data *rd)
1580 {
1581 	virtio_membar_sync();
1582 	rd->rd_ring->br_imask = 0;
1583 	virtio_membar_sync();
1584 }
1585 
1586 void
1587 hv_channel_pause(struct hv_channel *ch)
1588 {
1589 	hv_ring_mask(&ch->ch_rrd);
1590 }
1591 
1592 uint
1593 hv_channel_unpause(struct hv_channel *ch)
1594 {
1595 	uint32_t avail;
1596 
1597 	hv_ring_unmask(&ch->ch_rrd);
1598 	hv_ring_avail(&ch->ch_rrd, NULL, &avail);
1599 
1600 	return (avail);
1601 }
1602 
1603 uint
1604 hv_channel_ready(struct hv_channel *ch)
1605 {
1606 	uint32_t avail;
1607 
1608 	hv_ring_avail(&ch->ch_rrd, NULL, &avail);
1609 
1610 	return (avail);
1611 }
1612 
1613 /* How many PFNs can be referenced by the header */
1614 #define HV_NPFNHDR	((VMBUS_MSG_DSIZE_MAX -	\
1615 	  sizeof(struct vmbus_chanmsg_gpadl_conn)) / sizeof(uint64_t))
1616 
1617 /* How many PFNs can be referenced by the body */
1618 #define HV_NPFNBODY	((VMBUS_MSG_DSIZE_MAX -	\
1619 	  sizeof(struct vmbus_chanmsg_gpadl_subconn)) / sizeof(uint64_t))
1620 
1621 int
1622 hv_handle_alloc(struct hv_channel *ch, void *buffer, uint32_t buflen,
1623     uint32_t *handle)
1624 {
1625 	struct hv_softc *sc = ch->ch_sc;
1626 	struct vmbus_chanmsg_gpadl_conn *hdr;
1627 	struct vmbus_chanmsg_gpadl_subconn *cmd;
1628 	struct vmbus_chanmsg_gpadl_connresp rsp;
1629 	struct hv_msg *msg;
1630 	int i, j, last, left, rv;
1631 	int bodylen = 0, ncmds = 0, pfn = 0;
1632 	int waitflag = cold ? M_NOWAIT : M_WAITOK;
1633 	uint64_t *frames;
1634 	paddr_t pa;
1635 	caddr_t body;
1636 	/* Total number of pages to reference */
1637 	int total = atop(buflen);
1638 	/* Number of pages that will fit the header */
1639 	int inhdr = MIN(total, HV_NPFNHDR);
1640 
1641 	KASSERT((buflen & (PAGE_SIZE - 1)) == 0);
1642 
1643 	if ((msg = malloc(sizeof(*msg), M_DEVBUF, M_ZERO | waitflag)) == NULL)
1644 		return (ENOMEM);
1645 
1646 	/* Prepare array of frame addresses */
1647 	if ((frames = mallocarray(total, sizeof(*frames), M_DEVBUF, M_ZERO |
1648 	    waitflag)) == NULL) {
1649 		free(msg, M_DEVBUF, sizeof(*msg));
1650 		return (ENOMEM);
1651 	}
1652 	for (i = 0; i < total; i++) {
1653 		if (!pmap_extract(pmap_kernel(), (vaddr_t)buffer +
1654 		    PAGE_SIZE * i, &pa)) {
1655 			free(msg, M_DEVBUF, sizeof(*msg));
1656 			free(frames, M_DEVBUF, total * sizeof(*frames));
1657 			return (EFAULT);
1658 		}
1659 		frames[i] = atop(pa);
1660 	}
1661 
1662 	msg->msg_req.hc_dsize = sizeof(struct vmbus_chanmsg_gpadl_conn) +
1663 	    inhdr * sizeof(uint64_t);
1664 	hdr = (struct vmbus_chanmsg_gpadl_conn *)msg->msg_req.hc_data;
1665 	msg->msg_rsp = &rsp;
1666 	msg->msg_rsplen = sizeof(rsp);
1667 	if (waitflag == M_NOWAIT)
1668 		msg->msg_flags = MSGF_NOSLEEP;
1669 
1670 	left = total - inhdr;
1671 
1672 	/* Allocate additional gpadl_body structures if required */
1673 	if (left > 0) {
1674 		ncmds = MAX(1, left / HV_NPFNBODY + left % HV_NPFNBODY);
1675 		bodylen = ncmds * VMBUS_MSG_DSIZE_MAX;
1676 		body = malloc(bodylen, M_DEVBUF, M_ZERO | waitflag);
1677 		if (body == NULL) {
1678 			free(msg, M_DEVBUF, sizeof(*msg));
1679 			free(frames, M_DEVBUF, atop(buflen) * sizeof(*frames));
1680 			return (ENOMEM);
1681 		}
1682 	}
1683 
1684 	*handle = atomic_inc_int_nv(&sc->sc_handle);
1685 
1686 	hdr->chm_hdr.chm_type = VMBUS_CHANMSG_GPADL_CONN;
1687 	hdr->chm_chanid = ch->ch_id;
1688 	hdr->chm_gpadl = *handle;
1689 
1690 	/* Single range for a contiguous buffer */
1691 	hdr->chm_range_cnt = 1;
1692 	hdr->chm_range_len = sizeof(struct vmbus_gpa_range) + total *
1693 	    sizeof(uint64_t);
1694 	hdr->chm_range.gpa_ofs = 0;
1695 	hdr->chm_range.gpa_len = buflen;
1696 
1697 	/* Fit as many pages as possible into the header */
1698 	for (i = 0; i < inhdr; i++)
1699 		hdr->chm_range.gpa_page[i] = frames[pfn++];
1700 
1701 	for (i = 0; i < ncmds; i++) {
1702 		cmd = (struct vmbus_chanmsg_gpadl_subconn *)(body +
1703 		    VMBUS_MSG_DSIZE_MAX * i);
1704 		cmd->chm_hdr.chm_type = VMBUS_CHANMSG_GPADL_SUBCONN;
1705 		cmd->chm_gpadl = *handle;
1706 		last = MIN(left, HV_NPFNBODY);
1707 		for (j = 0; j < last; j++)
1708 			cmd->chm_gpa_page[j] = frames[pfn++];
1709 		left -= last;
1710 	}
1711 
1712 	rv = hv_start(sc, msg);
1713 	if (rv != 0) {
1714 		DPRINTF("%s: GPADL_CONN failed\n", sc->sc_dev.dv_xname);
1715 		goto out;
1716 	}
1717 	for (i = 0; i < ncmds; i++) {
1718 		int cmdlen = sizeof(*cmd);
1719 		cmd = (struct vmbus_chanmsg_gpadl_subconn *)(body +
1720 		    VMBUS_MSG_DSIZE_MAX * i);
1721 		/* Last element can be short */
1722 		if (i == ncmds - 1)
1723 			cmdlen += last * sizeof(uint64_t);
1724 		else
1725 			cmdlen += HV_NPFNBODY * sizeof(uint64_t);
1726 		rv = hv_cmd(sc, cmd, cmdlen, NULL, 0, waitflag | HCF_NOREPLY);
1727 		if (rv != 0) {
1728 			DPRINTF("%s: GPADL_SUBCONN (iteration %d/%d) failed "
1729 			    "with %d\n", sc->sc_dev.dv_xname, i, ncmds, rv);
1730 			goto out;
1731 		}
1732 	}
1733 	rv = hv_reply(sc, msg);
1734 	if (rv != 0)
1735 		DPRINTF("%s: GPADL allocation failed with %d\n",
1736 		    sc->sc_dev.dv_xname, rv);
1737 
1738  out:
1739 	free(msg, M_DEVBUF, sizeof(*msg));
1740 	free(frames, M_DEVBUF, total * sizeof(*frames));
1741 	if (bodylen > 0)
1742 		free(body, M_DEVBUF, bodylen);
1743 	if (rv != 0)
1744 		return (rv);
1745 
1746 	KASSERT(*handle == rsp.chm_gpadl);
1747 
1748 	return (0);
1749 }
1750 
1751 void
1752 hv_handle_free(struct hv_channel *ch, uint32_t handle)
1753 {
1754 	struct hv_softc *sc = ch->ch_sc;
1755 	struct vmbus_chanmsg_gpadl_disconn cmd;
1756 	struct vmbus_chanmsg_gpadl_disconn rsp;
1757 	int rv;
1758 
1759 	memset(&cmd, 0, sizeof(cmd));
1760 	cmd.chm_hdr.chm_type = VMBUS_CHANMSG_GPADL_DISCONN;
1761 	cmd.chm_chanid = ch->ch_id;
1762 	cmd.chm_gpadl = handle;
1763 
1764 	rv = hv_cmd(sc, &cmd, sizeof(cmd), &rsp, sizeof(rsp), cold ?
1765 	    HCF_NOSLEEP : 0);
1766 	if (rv)
1767 		DPRINTF("%s: GPADL_DISCONN failed with %d\n",
1768 		    sc->sc_dev.dv_xname, rv);
1769 }
1770 
1771 static int
1772 hv_attach_print(void *aux, const char *name)
1773 {
1774 	struct hv_attach_args *aa = aux;
1775 
1776 	if (name)
1777 		printf("\"%s\" at %s", aa->aa_ident, name);
1778 
1779 	return (UNCONF);
1780 }
1781 
1782 int
1783 hv_attach_devices(struct hv_softc *sc)
1784 {
1785 	struct hv_dev *dv;
1786 	struct hv_channel *ch;
1787 
1788 	SLIST_INIT(&sc->sc_devs);
1789 	mtx_init(&sc->sc_devlck, IPL_NET);
1790 
1791 	TAILQ_FOREACH(ch, &sc->sc_channels, ch_entry) {
1792 		if (ch->ch_state != HV_CHANSTATE_OFFERED)
1793 			continue;
1794 		if (!(ch->ch_flags & CHF_MONITOR))
1795 			continue;
1796 		dv = malloc(sizeof(*dv), M_DEVBUF, M_ZERO | M_NOWAIT);
1797 		if (dv == NULL) {
1798 			printf("%s: failed to allocate device object\n",
1799 			    sc->sc_dev.dv_xname);
1800 			return (-1);
1801 		}
1802 		dv->dv_aa.aa_parent = sc;
1803 		dv->dv_aa.aa_type = &ch->ch_type;
1804 		dv->dv_aa.aa_inst = &ch->ch_inst;
1805 		dv->dv_aa.aa_ident = ch->ch_ident;
1806 		dv->dv_aa.aa_chan = ch;
1807 		dv->dv_aa.aa_dmat = sc->sc_dmat;
1808 		mtx_enter(&sc->sc_devlck);
1809 		SLIST_INSERT_HEAD(&sc->sc_devs, dv, dv_entry);
1810 		mtx_leave(&sc->sc_devlck);
1811 		config_found((struct device *)sc, &dv->dv_aa, hv_attach_print);
1812 	}
1813 	return (0);
1814 }
1815 
1816 void
1817 hv_evcount_attach(struct hv_channel *ch, const char *name)
1818 {
1819 	struct hv_softc *sc = ch->ch_sc;
1820 
1821 	evcount_attach(&ch->ch_evcnt, name, &sc->sc_idtvec);
1822 }
1823