2 * High Precisition Event Timer emulation
4 * Copyright (c) 2007 Alexander Graf
5 * Copyright (c) 2008 IBM Corporation
7 * Authors: Beth Kon <bkon@us.ibm.com>
9 * This library is free software; you can redistribute it and/or
10 * modify it under the terms of the GNU Lesser General Public
11 * License as published by the Free Software Foundation; either
12 * version 2 of the License, or (at your option) any later version.
14 * This library is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
17 * Lesser General Public License for more details.
19 * You should have received a copy of the GNU Lesser General Public
20 * License along with this library; if not, write to the Free Software
21 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston MA 02110-1301 USA
23 * *****************************************************************
25 * This driver attempts to emulate an HPET device in software.
31 #include "qemu-timer.h"
32 #include "hpet_emul.h"
36 #define dprintf printf
41 static HPETState *hpet_statep;
43 uint32_t hpet_in_legacy_mode(void)
46 return hpet_statep->config & HPET_CFG_LEGACY;
51 static uint32_t timer_int_route(struct HPETTimer *timer)
54 route = (timer->config & HPET_TN_INT_ROUTE_MASK) >> HPET_TN_INT_ROUTE_SHIFT;
58 static uint32_t hpet_enabled(void)
60 return hpet_statep->config & HPET_CFG_ENABLE;
63 static uint32_t timer_is_periodic(HPETTimer *t)
65 return t->config & HPET_TN_PERIODIC;
68 static uint32_t timer_enabled(HPETTimer *t)
70 return t->config & HPET_TN_ENABLE;
73 static uint32_t hpet_time_after(uint64_t a, uint64_t b)
75 return ((int32_t)(b) - (int32_t)(a) < 0);
78 static uint32_t hpet_time_after64(uint64_t a, uint64_t b)
80 return ((int64_t)(b) - (int64_t)(a) < 0);
83 static uint64_t ticks_to_ns(uint64_t value)
85 return (muldiv64(value, HPET_CLK_PERIOD, FS_PER_NS));
88 static uint64_t ns_to_ticks(uint64_t value)
90 return (muldiv64(value, FS_PER_NS, HPET_CLK_PERIOD));
93 static uint64_t hpet_fixup_reg(uint64_t new, uint64_t old, uint64_t mask)
100 static int activating_bit(uint64_t old, uint64_t new, uint64_t mask)
102 return (!(old & mask) && (new & mask));
105 static int deactivating_bit(uint64_t old, uint64_t new, uint64_t mask)
107 return ((old & mask) && !(new & mask));
110 static uint64_t hpet_get_ticks(void)
113 ticks = ns_to_ticks(qemu_get_clock(vm_clock) + hpet_statep->hpet_offset);
118 * calculate diff between comparator value and current ticks
120 static inline uint64_t hpet_calculate_diff(HPETTimer *t, uint64_t current)
123 if (t->config & HPET_TN_32BIT) {
125 cmp = (uint32_t)t->cmp;
126 diff = cmp - (uint32_t)current;
127 diff = (int32_t)diff > 0 ? diff : (uint32_t)0;
128 return (uint64_t)diff;
132 diff = cmp - current;
133 diff = (int64_t)diff > 0 ? diff : (uint64_t)0;
138 static void update_irq(struct HPETTimer *timer)
143 if (timer->tn <= 1 && hpet_in_legacy_mode()) {
144 /* if LegacyReplacementRoute bit is set, HPET specification requires
145 * timer0 be routed to IRQ0 in NON-APIC or IRQ2 in the I/O APIC,
146 * timer1 be routed to IRQ8 in NON-APIC or IRQ8 in the I/O APIC.
148 if (timer->tn == 0) {
149 irq=timer->state->irqs[0];
151 irq=timer->state->irqs[8];
153 route=timer_int_route(timer);
154 irq=timer->state->irqs[route];
156 if (timer_enabled(timer) && hpet_enabled()) {
161 static void hpet_save(QEMUFile *f, void *opaque)
163 HPETState *s = opaque;
165 qemu_put_be64s(f, &s->config);
166 qemu_put_be64s(f, &s->isr);
167 /* save current counter value */
168 s->hpet_counter = hpet_get_ticks();
169 qemu_put_be64s(f, &s->hpet_counter);
171 for (i = 0; i < HPET_NUM_TIMERS; i++) {
172 qemu_put_8s(f, &s->timer[i].tn);
173 qemu_put_be64s(f, &s->timer[i].config);
174 qemu_put_be64s(f, &s->timer[i].cmp);
175 qemu_put_be64s(f, &s->timer[i].fsb);
176 qemu_put_be64s(f, &s->timer[i].period);
177 qemu_put_8s(f, &s->timer[i].wrap_flag);
178 if (s->timer[i].qemu_timer) {
179 qemu_put_timer(f, s->timer[i].qemu_timer);
184 static int hpet_load(QEMUFile *f, void *opaque, int version_id)
186 HPETState *s = opaque;
192 qemu_get_be64s(f, &s->config);
193 qemu_get_be64s(f, &s->isr);
194 qemu_get_be64s(f, &s->hpet_counter);
195 /* Recalculate the offset between the main counter and guest time */
196 s->hpet_offset = ticks_to_ns(s->hpet_counter) - qemu_get_clock(vm_clock);
198 for (i = 0; i < HPET_NUM_TIMERS; i++) {
199 qemu_get_8s(f, &s->timer[i].tn);
200 qemu_get_be64s(f, &s->timer[i].config);
201 qemu_get_be64s(f, &s->timer[i].cmp);
202 qemu_get_be64s(f, &s->timer[i].fsb);
203 qemu_get_be64s(f, &s->timer[i].period);
204 qemu_get_8s(f, &s->timer[i].wrap_flag);
205 if (s->timer[i].qemu_timer) {
206 qemu_get_timer(f, s->timer[i].qemu_timer);
213 * timer expiration callback
215 static void hpet_timer(void *opaque)
217 HPETTimer *t = (HPETTimer*)opaque;
220 uint64_t period = t->period;
221 uint64_t cur_tick = hpet_get_ticks();
223 if (timer_is_periodic(t) && period != 0) {
224 if (t->config & HPET_TN_32BIT) {
225 while (hpet_time_after(cur_tick, t->cmp))
226 t->cmp = (uint32_t)(t->cmp + t->period);
228 while (hpet_time_after64(cur_tick, t->cmp))
231 diff = hpet_calculate_diff(t, cur_tick);
232 qemu_mod_timer(t->qemu_timer, qemu_get_clock(vm_clock)
233 + (int64_t)ticks_to_ns(diff));
234 } else if (t->config & HPET_TN_32BIT && !timer_is_periodic(t)) {
236 diff = hpet_calculate_diff(t, cur_tick);
237 qemu_mod_timer(t->qemu_timer, qemu_get_clock(vm_clock)
238 + (int64_t)ticks_to_ns(diff));
245 static void hpet_set_timer(HPETTimer *t)
248 uint32_t wrap_diff; /* how many ticks until we wrap? */
249 uint64_t cur_tick = hpet_get_ticks();
251 /* whenever new timer is being set up, make sure wrap_flag is 0 */
253 diff = hpet_calculate_diff(t, cur_tick);
255 /* hpet spec says in one-shot 32-bit mode, generate an interrupt when
256 * counter wraps in addition to an interrupt with comparator match.
258 if (t->config & HPET_TN_32BIT && !timer_is_periodic(t)) {
259 wrap_diff = 0xffffffff - (uint32_t)cur_tick;
260 if (wrap_diff < (uint32_t)diff) {
265 qemu_mod_timer(t->qemu_timer, qemu_get_clock(vm_clock)
266 + (int64_t)ticks_to_ns(diff));
269 static void hpet_del_timer(HPETTimer *t)
271 qemu_del_timer(t->qemu_timer);
275 static uint32_t hpet_ram_readb(void *opaque, target_phys_addr_t addr)
277 printf("qemu: hpet_read b at %" PRIx64 "\n", addr);
281 static uint32_t hpet_ram_readw(void *opaque, target_phys_addr_t addr)
283 printf("qemu: hpet_read w at %" PRIx64 "\n", addr);
288 static uint32_t hpet_ram_readl(void *opaque, target_phys_addr_t addr)
290 HPETState *s = (HPETState *)opaque;
291 uint64_t cur_tick, index;
293 dprintf("qemu: Enter hpet_ram_readl at %" PRIx64 "\n", addr);
295 /*address range of all TN regs*/
296 if (index >= 0x100 && index <= 0x3ff) {
297 uint8_t timer_id = (addr - 0x100) / 0x20;
298 if (timer_id > HPET_NUM_TIMERS - 1) {
299 printf("qemu: timer id out of range\n");
302 HPETTimer *timer = &s->timer[timer_id];
304 switch ((addr - 0x100) % 0x20) {
306 return timer->config;
307 case HPET_TN_CFG + 4: // Interrupt capabilities
308 return timer->config >> 32;
309 case HPET_TN_CMP: // comparator register
311 case HPET_TN_CMP + 4:
312 return timer->cmp >> 32;
314 return timer->fsb >> 32;
316 dprintf("qemu: invalid hpet_ram_readl\n");
322 return s->capability;
324 return s->capability >> 32;
328 dprintf("qemu: invalid HPET_CFG + 4 hpet_ram_readl \n");
332 cur_tick = hpet_get_ticks();
334 cur_tick = s->hpet_counter;
335 dprintf("qemu: reading counter = %" PRIx64 "\n", cur_tick);
337 case HPET_COUNTER + 4:
339 cur_tick = hpet_get_ticks();
341 cur_tick = s->hpet_counter;
342 dprintf("qemu: reading counter + 4 = %" PRIx64 "\n", cur_tick);
343 return cur_tick >> 32;
347 dprintf("qemu: invalid hpet_ram_readl\n");
355 static void hpet_ram_writeb(void *opaque, target_phys_addr_t addr,
358 printf("qemu: invalid hpet_write b at %" PRIx64 " = %#x\n",
362 static void hpet_ram_writew(void *opaque, target_phys_addr_t addr,
365 printf("qemu: invalid hpet_write w at %" PRIx64 " = %#x\n",
370 static void hpet_ram_writel(void *opaque, target_phys_addr_t addr,
374 HPETState *s = (HPETState *)opaque;
375 uint64_t old_val, new_val, index;
377 dprintf("qemu: Enter hpet_ram_writel at %" PRIx64 " = %#x\n", addr, value);
379 old_val = hpet_ram_readl(opaque, addr);
382 /*address range of all TN regs*/
383 if (index >= 0x100 && index <= 0x3ff) {
384 uint8_t timer_id = (addr - 0x100) / 0x20;
385 dprintf("qemu: hpet_ram_writel timer_id = %#x \n", timer_id);
386 HPETTimer *timer = &s->timer[timer_id];
388 switch ((addr - 0x100) % 0x20) {
390 dprintf("qemu: hpet_ram_writel HPET_TN_CFG\n");
391 timer->config = hpet_fixup_reg(new_val, old_val, 0x3e4e);
392 if (new_val & HPET_TN_32BIT) {
393 timer->cmp = (uint32_t)timer->cmp;
394 timer->period = (uint32_t)timer->period;
396 if (new_val & HPET_TIMER_TYPE_LEVEL) {
397 printf("qemu: level-triggered hpet not supported\n");
402 case HPET_TN_CFG + 4: // Interrupt capabilities
403 dprintf("qemu: invalid HPET_TN_CFG+4 write\n");
405 case HPET_TN_CMP: // comparator register
406 dprintf("qemu: hpet_ram_writel HPET_TN_CMP \n");
407 if (timer->config & HPET_TN_32BIT)
408 new_val = (uint32_t)new_val;
409 if (!timer_is_periodic(timer) ||
410 (timer->config & HPET_TN_SETVAL))
411 timer->cmp = (timer->cmp & 0xffffffff00000000ULL)
415 * FIXME: Clamp period to reasonable min value?
416 * Clamp period to reasonable max value
418 new_val &= (timer->config & HPET_TN_32BIT ? ~0u : ~0ull) >> 1;
419 timer->period = (timer->period & 0xffffffff00000000ULL)
422 timer->config &= ~HPET_TN_SETVAL;
424 hpet_set_timer(timer);
426 case HPET_TN_CMP + 4: // comparator register high order
427 dprintf("qemu: hpet_ram_writel HPET_TN_CMP + 4\n");
428 if (!timer_is_periodic(timer) ||
429 (timer->config & HPET_TN_SETVAL))
430 timer->cmp = (timer->cmp & 0xffffffffULL)
434 * FIXME: Clamp period to reasonable min value?
435 * Clamp period to reasonable max value
437 new_val &= (timer->config
438 & HPET_TN_32BIT ? ~0u : ~0ull) >> 1;
439 timer->period = (timer->period & 0xffffffffULL)
442 timer->config &= ~HPET_TN_SETVAL;
444 hpet_set_timer(timer);
446 case HPET_TN_ROUTE + 4:
447 dprintf("qemu: hpet_ram_writel HPET_TN_ROUTE + 4\n");
450 dprintf("qemu: invalid hpet_ram_writel\n");
459 s->config = hpet_fixup_reg(new_val, old_val, 0x3);
460 if (activating_bit(old_val, new_val, HPET_CFG_ENABLE)) {
461 /* Enable main counter and interrupt generation. */
462 s->hpet_offset = ticks_to_ns(s->hpet_counter)
463 - qemu_get_clock(vm_clock);
464 for (i = 0; i < HPET_NUM_TIMERS; i++)
465 if ((&s->timer[i])->cmp != ~0ULL)
466 hpet_set_timer(&s->timer[i]);
468 else if (deactivating_bit(old_val, new_val, HPET_CFG_ENABLE)) {
469 /* Halt main counter and disable interrupt generation. */
470 s->hpet_counter = hpet_get_ticks();
471 for (i = 0; i < HPET_NUM_TIMERS; i++)
472 hpet_del_timer(&s->timer[i]);
474 /* i8254 and RTC are disabled when HPET is in legacy mode */
475 if (activating_bit(old_val, new_val, HPET_CFG_LEGACY)) {
477 } else if (deactivating_bit(old_val, new_val, HPET_CFG_LEGACY)) {
482 dprintf("qemu: invalid HPET_CFG+4 write \n");
485 /* FIXME: need to handle level-triggered interrupts */
489 printf("qemu: Writing counter while HPET enabled!\n");
490 s->hpet_counter = (s->hpet_counter & 0xffffffff00000000ULL)
492 dprintf("qemu: HPET counter written. ctr = %#x -> %" PRIx64 "\n",
493 value, s->hpet_counter);
495 case HPET_COUNTER + 4:
497 printf("qemu: Writing counter while HPET enabled!\n");
498 s->hpet_counter = (s->hpet_counter & 0xffffffffULL)
499 | (((uint64_t)value) << 32);
500 dprintf("qemu: HPET counter + 4 written. ctr = %#x -> %" PRIx64 "\n",
501 value, s->hpet_counter);
504 dprintf("qemu: invalid hpet_ram_writel\n");
510 static CPUReadMemoryFunc *hpet_ram_read[] = {
521 static CPUWriteMemoryFunc *hpet_ram_write[] = {
532 static void hpet_reset(void *opaque) {
533 HPETState *s = opaque;
535 static int count = 0;
537 for (i=0; i<HPET_NUM_TIMERS; i++) {
538 HPETTimer *timer = &s->timer[i];
539 hpet_del_timer(timer);
542 timer->config = HPET_TN_PERIODIC_CAP | HPET_TN_SIZE_CAP;
543 /* advertise availability of irqs 5,10,11 */
544 timer->config |= 0x00000c20ULL << 32;
546 timer->period = 0ULL;
547 timer->wrap_flag = 0;
550 s->hpet_counter = 0ULL;
551 s->hpet_offset = 0ULL;
552 /* 64-bit main counter; 3 timers supported; LegacyReplacementRoute. */
553 s->capability = 0x8086a201ULL;
554 s->capability |= ((HPET_CLK_PERIOD) << 32);
556 /* we don't enable pit when hpet_reset is first called (by hpet_init)
557 * because hpet is taking over for pit here. On subsequent invocations,
558 * hpet_reset is called due to system reset. At this point control must
559 * be returned to pit until SW reenables hpet.
566 void hpet_init(qemu_irq *irq) {
570 dprintf ("hpet_init\n");
572 s = qemu_mallocz(sizeof(HPETState));
575 for (i=0; i<HPET_NUM_TIMERS; i++) {
576 HPETTimer *timer = &s->timer[i];
577 timer->qemu_timer = qemu_new_timer(vm_clock, hpet_timer, timer);
580 register_savevm("hpet", -1, 1, hpet_save, hpet_load, s);
581 qemu_register_reset(hpet_reset, s);
583 iomemtype = cpu_register_io_memory(0, hpet_ram_read,
585 cpu_register_physical_memory(HPET_BASE, 0x400, iomemtype);