qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Michael Walle <michael@walle.cc>
To: qemu-devel@nongnu.org
Cc: Peter Maydell <peter.maydell@linaro.org>,
	Paul Brook <paul@codesourcery.com>,
	Anthony Liguori <anthony@codemonkey.ws>
Subject: Re: [Qemu-devel] [PATCH 28/28] hw/sd.c: add SD card save/load support
Date: Wed, 6 Mar 2013 19:31:55 +0100	[thread overview]
Message-ID: <201303061931.55967.michael@walle.cc> (raw)
In-Reply-To: <1351586664-20525-29-git-send-email-peter.maydell@linaro.org>


Hi all,

Sorry for digging out such an old thread :) but this patch introduced a memory 
corruption, see below.

Am Dienstag 30 Oktober 2012, 09:44:24 schrieb Peter Maydell:
> From: Igor Mitsyanko <i.mitsyanko@gmail.com>
> 
> This patch updates SD card model to support save/load of card's state.
> 
> Signed-off-by: Igor Mitsyanko <i.mitsyanko@samsung.com>
> Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
> Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
> ---
>  hw/sd.c |   89
> +++++++++++++++++++++++++++++++++++++++++++++------------------ 1 file
> changed, 64 insertions(+), 25 deletions(-)
> 
> diff --git a/hw/sd.c b/hw/sd.c
> index b2f211c..3c34d43 100644
> --- a/hw/sd.c
> +++ b/hw/sd.c
> @@ -55,24 +55,28 @@ typedef enum {
>      sd_illegal = -2,
>  } sd_rsp_type_t;
> 
> +enum SDCardModes {
> +    sd_inactive,
> +    sd_card_identification_mode,
> +    sd_data_transfer_mode,
> +};
> +
> +enum SDCardStates {
> +    sd_inactive_state = -1,
> +    sd_idle_state = 0,
> +    sd_ready_state,
> +    sd_identification_state,
> +    sd_standby_state,
> +    sd_transfer_state,
> +    sd_sendingdata_state,
> +    sd_receivingdata_state,
> +    sd_programming_state,
> +    sd_disconnect_state,
> +};
> +
>  struct SDState {
> -    enum {
> -        sd_inactive,
> -        sd_card_identification_mode,
> -        sd_data_transfer_mode,
> -    } mode;
> -    enum {
> -        sd_inactive_state = -1,
> -        sd_idle_state = 0,
> -        sd_ready_state,
> -        sd_identification_state,
> -        sd_standby_state,
> -        sd_transfer_state,
> -        sd_sendingdata_state,
> -        sd_receivingdata_state,
> -        sd_programming_state,
> -        sd_disconnect_state,
> -    } state;
> +    uint32_t mode;    /* current card mode, one of SDCardModes */
> +    int32_t state;    /* current card state, one of SDCardStates */
>      uint32_t ocr;
>      uint8_t scr[8];
>      uint8_t cid[16];
> @@ -83,21 +87,22 @@ struct SDState {
>      uint32_t vhs;
>      bool wp_switch;
>      unsigned long *wp_groups;
> +    int32_t wpgrps_size;
>      uint64_t size;
> -    int blk_len;
> +    uint32_t blk_len;
>      uint32_t erase_start;
>      uint32_t erase_end;
>      uint8_t pwd[16];
> -    int pwd_len;
> -    int function_group[6];
> +    uint32_t pwd_len;
> +    uint8_t function_group[6];
> 
>      bool spi;
> -    int current_cmd;
> +    uint8_t current_cmd;
>      /* True if we will handle the next command as an ACMD. Note that this
> does * *not* track the APP_CMD status bit!
>       */
>      bool expecting_acmd;
> -    int blk_written;
> +    uint32_t blk_written;
>      uint64_t data_start;
>      uint32_t data_offset;
>      uint8_t data[512];
> @@ -421,8 +426,9 @@ static void sd_reset(SDState *sd, BlockDriverState
> *bdrv) if (sd->wp_groups)
>          g_free(sd->wp_groups);
>      sd->wp_switch = bdrv ? bdrv_is_read_only(bdrv) : false;
> -    sd->wp_groups = bitmap_new(sect);
> -    memset(sd->function_group, 0, sizeof(int) * 6);
> +    sd->wpgrps_size = sect;
> +    sd->wp_groups = bitmap_new(sd->wpgrps_size);
> +    memset(sd->function_group, 0, sizeof(sd->function_group));
>      sd->erase_start = 0;
>      sd->erase_end = 0;
>      sd->size = size;
> @@ -446,6 +452,38 @@ static const BlockDevOps sd_block_ops = {
>      .change_media_cb = sd_cardchange,
>  };
> 
> +static const VMStateDescription sd_vmstate = {
> +    .name = "sd-card",
> +    .version_id = 1,
> +    .minimum_version_id = 1,
> +    .fields = (VMStateField[]) {
> +        VMSTATE_UINT32(mode, SDState),
> +        VMSTATE_INT32(state, SDState),
> +        VMSTATE_UINT8_ARRAY(cid, SDState, 16),
> +        VMSTATE_UINT8_ARRAY(csd, SDState, 16),
> +        VMSTATE_UINT16(rca, SDState),
> +        VMSTATE_UINT32(card_status, SDState),
> +        VMSTATE_PARTIAL_BUFFER(sd_status, SDState, 1),
> +        VMSTATE_UINT32(vhs, SDState),
> +        VMSTATE_BITMAP(wp_groups, SDState, 0, wpgrps_size),
> +        VMSTATE_UINT32(blk_len, SDState),
> +        VMSTATE_UINT32(erase_start, SDState),
> +        VMSTATE_UINT32(erase_end, SDState),
> +        VMSTATE_UINT8_ARRAY(pwd, SDState, 16),
> +        VMSTATE_UINT32(pwd_len, SDState),
> +        VMSTATE_UINT8_ARRAY(function_group, SDState, 6),
> +        VMSTATE_UINT8(current_cmd, SDState),
> +        VMSTATE_BOOL(expecting_acmd, SDState),
> +        VMSTATE_UINT32(blk_written, SDState),
> +        VMSTATE_UINT64(data_start, SDState),
> +        VMSTATE_UINT32(data_offset, SDState),
> +        VMSTATE_UINT8_ARRAY(data, SDState, 512),
> +        VMSTATE_BUFFER_UNSAFE(buf, SDState, 1, 512),

buf is dynamically allocated in the sd_init(), see also the SDState:

struct SDState {
[...]
    uint8_t *buf;

    bool enable;
};


> +        VMSTATE_BOOL(enable, SDState),
> +        VMSTATE_END_OF_LIST()
> +    }
> +};
> +
>  /* We do not model the chip select pin, so allow the board to select
>     whether card should be in SSI or MMC/SD mode.  It is also up to the
>     board to ensure that ssi transfers only occur when the chip select
> @@ -463,6 +501,7 @@ SDState *sd_init(BlockDriverState *bs, bool is_spi)
>          bdrv_attach_dev_nofail(sd->bdrv, sd);
>          bdrv_set_dev_ops(sd->bdrv, &sd_block_ops, sd);
>      }
> +    vmstate_register(NULL, -1, &sd_vmstate, sd);
>      return sd;
>  }
> 
> @@ -576,7 +615,7 @@ static void sd_lock_command(SDState *sd)
>              sd->card_status |= LOCK_UNLOCK_FAILED;
>              return;
>          }
> -        bitmap_zero(sd->wp_groups, sd_addr_to_wpnum(sd->size) + 1);
> +        bitmap_zero(sd->wp_groups, sd->wpgrps_size);
>          sd->csd[14] &= ~0x10;
>          sd->card_status &= ~CARD_IS_LOCKED;
>          sd->pwd_len = 0;


-- 
Michael

  reply	other threads:[~2013-03-06 18:32 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-10-30  8:43 [Qemu-devel] [PULL 00/28] arm-devs queue Peter Maydell
2012-10-30  8:43 ` [Qemu-devel] [PATCH 01/28] hw/armv7m_nvic: Implement byte/halfword access for NVIC SCB_SHPRx registers Peter Maydell
2012-10-30  8:43 ` [Qemu-devel] [PATCH 02/28] hw/vexpress.c: Don't prematurely explode QEMUMachineInitArgs Peter Maydell
2012-10-30  8:43 ` [Qemu-devel] [PATCH 03/28] hw/realview.c: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 04/28] hw/versatilepb: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 05/28] hw/spitz: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 06/28] hw/omap_sx1: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 07/28] hw/nseries: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 08/28] hw/mainstone: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 09/28] hw/exynos4_boards: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 10/28] hw/pl050: Use LOG_GUEST_ERROR Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 11/28] hw/pl061: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 12/28] hw/pl080: Use LOG_GUEST_ERROR and LOG_UNIMP Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 13/28] hw/pl110: Use LOG_GUEST_ERROR rather than hw_error() Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 14/28] hw/pl190: Use LOG_UNIMP " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 15/28] hw/arm11mpcore: Use LOG_GUEST_ERROR " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 16/28] hw/arm_gic: Use LOG_GUEST_ERROR Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 17/28] hw/arm_timer: Use LOG_GUEST_ERROR and LOG_UNIMP Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 18/28] hw/armv7m_nvic: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 19/28] hw/arm_sysctl: Use LOG_GUEST_ERROR Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 20/28] hw/arm_l2x0: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 21/28] hw/versatile_i2c: " Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 22/28] pflash_cfi0x: remove unused base field Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 23/28] pflash_cfi01: remove unused total_len field Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 24/28] pflash_cfi0x: QOMified Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 25/28] pflash_cfi01: Fix debug mode printfery Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 26/28] hw/sd.c: Fix erase for high capacity cards Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 27/28] vmstate: Add support for saving/loading bitmaps Peter Maydell
2012-10-30  8:44 ` [Qemu-devel] [PATCH 28/28] hw/sd.c: add SD card save/load support Peter Maydell
2013-03-06 18:31   ` Michael Walle [this message]
2013-03-06 18:52     ` Peter Maydell
2013-03-07 12:35       ` Igor Mitsyanko
2012-11-01 16:02 ` [Qemu-devel] [PULL 00/28] arm-devs queue Aurelien Jarno

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=201303061931.55967.michael@walle.cc \
    --to=michael@walle.cc \
    --cc=anthony@codemonkey.ws \
    --cc=paul@codesourcery.com \
    --cc=peter.maydell@linaro.org \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).