xref: /illumos-gate/usr/src/cmd/bhyve/pci_e82545.c (revision 4f3f3e9a1dee62c031fa67cfe64e11d6dd3fab1b)
1 /*
2  * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
3  *
4  * Copyright (c) 2016 Alexander Motin <mav@FreeBSD.org>
5  * Copyright (c) 2015 Peter Grehan <grehan@freebsd.org>
6  * Copyright (c) 2013 Jeremiah Lott, Avere Systems
7  * All rights reserved.
8  *
9  * Redistribution and use in source and binary forms, with or without
10  * modification, are permitted provided that the following conditions
11  * are met:
12  * 1. Redistributions of source code must retain the above copyright
13  *    notice, this list of conditions and the following disclaimer
14  *    in this position and unchanged.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  *
19  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
20  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
23  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29  * SUCH DAMAGE.
30  */
31 
32 #include <sys/cdefs.h>
33 __FBSDID("$FreeBSD$");
34 
35 #include <sys/types.h>
36 #ifndef WITHOUT_CAPSICUM
37 #include <sys/capsicum.h>
38 #endif
39 #include <sys/limits.h>
40 #include <sys/ioctl.h>
41 #include <sys/uio.h>
42 #include <net/ethernet.h>
43 #include <netinet/in.h>
44 #include <netinet/tcp.h>
45 
46 #ifndef WITHOUT_CAPSICUM
47 #include <capsicum_helpers.h>
48 #endif
49 
50 #include <err.h>
51 #include <errno.h>
52 #include <fcntl.h>
53 #include <md5.h>
54 #include <stdio.h>
55 #include <stdlib.h>
56 #include <string.h>
57 #include <sysexits.h>
58 #include <unistd.h>
59 #include <pthread.h>
60 #include <pthread_np.h>
61 
62 #include "e1000_regs.h"
63 #include "e1000_defines.h"
64 #include "mii.h"
65 
66 #include "bhyverun.h"
67 #include "config.h"
68 #include "debug.h"
69 #include "pci_emul.h"
70 #include "mevent.h"
71 #include "net_utils.h"
72 #include "net_backends.h"
73 
74 /* Hardware/register definitions XXX: move some to common code. */
75 #define E82545_VENDOR_ID_INTEL			0x8086
76 #define E82545_DEV_ID_82545EM_COPPER		0x100F
77 #define E82545_SUBDEV_ID			0x1008
78 
79 #define E82545_REVISION_4			4
80 
81 #define E82545_MDIC_DATA_MASK			0x0000FFFF
82 #define E82545_MDIC_OP_MASK			0x0c000000
83 #define E82545_MDIC_IE				0x20000000
84 
85 #define E82545_EECD_FWE_DIS	0x00000010 /* Flash writes disabled */
86 #define E82545_EECD_FWE_EN	0x00000020 /* Flash writes enabled */
87 #define E82545_EECD_FWE_MASK	0x00000030 /* Flash writes mask */
88 
89 #define E82545_BAR_REGISTER			0
90 #define E82545_BAR_REGISTER_LEN			(128*1024)
91 #define E82545_BAR_FLASH			1
92 #define E82545_BAR_FLASH_LEN			(64*1024)
93 #define E82545_BAR_IO				2
94 #define E82545_BAR_IO_LEN			8
95 
96 #define E82545_IOADDR				0x00000000
97 #define E82545_IODATA				0x00000004
98 #define E82545_IO_REGISTER_MAX			0x0001FFFF
99 #define E82545_IO_FLASH_BASE			0x00080000
100 #define E82545_IO_FLASH_MAX			0x000FFFFF
101 
102 #define E82545_ARRAY_ENTRY(reg, offset)		(reg + (offset<<2))
103 #define E82545_RAR_MAX				15
104 #define E82545_MTA_MAX				127
105 #define E82545_VFTA_MAX				127
106 
107 /* Slightly modified from the driver versions, hardcoded for 3 opcode bits,
108  * followed by 6 address bits.
109  * TODO: make opcode bits and addr bits configurable?
110  * NVM Commands - Microwire */
111 #define E82545_NVM_OPCODE_BITS	3
112 #define E82545_NVM_ADDR_BITS	6
113 #define E82545_NVM_DATA_BITS	16
114 #define E82545_NVM_OPADDR_BITS	(E82545_NVM_OPCODE_BITS + E82545_NVM_ADDR_BITS)
115 #define E82545_NVM_ADDR_MASK	((1 << E82545_NVM_ADDR_BITS)-1)
116 #define E82545_NVM_OPCODE_MASK	\
117     (((1 << E82545_NVM_OPCODE_BITS) - 1) << E82545_NVM_ADDR_BITS)
118 #define E82545_NVM_OPCODE_READ	(0x6 << E82545_NVM_ADDR_BITS)	/* read */
119 #define E82545_NVM_OPCODE_WRITE	(0x5 << E82545_NVM_ADDR_BITS)	/* write */
120 #define E82545_NVM_OPCODE_ERASE	(0x7 << E82545_NVM_ADDR_BITS)	/* erase */
121 #define	E82545_NVM_OPCODE_EWEN	(0x4 << E82545_NVM_ADDR_BITS)	/* wr-enable */
122 
123 #define	E82545_NVM_EEPROM_SIZE	64 /* 64 * 16-bit values == 128K */
124 
125 #define E1000_ICR_SRPD		0x00010000
126 
127 /* This is an arbitrary number.  There is no hard limit on the chip. */
128 #define I82545_MAX_TXSEGS	64
129 
130 /* Legacy receive descriptor */
131 struct e1000_rx_desc {
132 	uint64_t buffer_addr;	/* Address of the descriptor's data buffer */
133 	uint16_t length;	/* Length of data DMAed into data buffer */
134 	uint16_t csum;		/* Packet checksum */
135 	uint8_t	 status;       	/* Descriptor status */
136 	uint8_t  errors;	/* Descriptor Errors */
137 	uint16_t special;
138 };
139 
140 /* Transmit descriptor types */
141 #define	E1000_TXD_MASK		(E1000_TXD_CMD_DEXT | 0x00F00000)
142 #define E1000_TXD_TYP_L		(0)
143 #define E1000_TXD_TYP_C		(E1000_TXD_CMD_DEXT | E1000_TXD_DTYP_C)
144 #define E1000_TXD_TYP_D		(E1000_TXD_CMD_DEXT | E1000_TXD_DTYP_D)
145 
146 /* Legacy transmit descriptor */
147 struct e1000_tx_desc {
148 	uint64_t buffer_addr;   /* Address of the descriptor's data buffer */
149 	union {
150 		uint32_t data;
151 		struct {
152 			uint16_t length;  /* Data buffer length */
153 			uint8_t  cso;  /* Checksum offset */
154 			uint8_t  cmd;  /* Descriptor control */
155 		} flags;
156 	} lower;
157 	union {
158 		uint32_t data;
159 		struct {
160 			uint8_t status; /* Descriptor status */
161 			uint8_t css;  /* Checksum start */
162 			uint16_t special;
163 		} fields;
164 	} upper;
165 };
166 
167 /* Context descriptor */
168 struct e1000_context_desc {
169 	union {
170 		uint32_t ip_config;
171 		struct {
172 			uint8_t ipcss;  /* IP checksum start */
173 			uint8_t ipcso;  /* IP checksum offset */
174 			uint16_t ipcse;  /* IP checksum end */
175 		} ip_fields;
176 	} lower_setup;
177 	union {
178 		uint32_t tcp_config;
179 		struct {
180 			uint8_t tucss;  /* TCP checksum start */
181 			uint8_t tucso;  /* TCP checksum offset */
182 			uint16_t tucse;  /* TCP checksum end */
183 		} tcp_fields;
184 	} upper_setup;
185 	uint32_t cmd_and_length;
186 	union {
187 		uint32_t data;
188 		struct {
189 			uint8_t status;  /* Descriptor status */
190 			uint8_t hdr_len;  /* Header length */
191 			uint16_t mss;  /* Maximum segment size */
192 		} fields;
193 	} tcp_seg_setup;
194 };
195 
196 /* Data descriptor */
197 struct e1000_data_desc {
198 	uint64_t buffer_addr;  /* Address of the descriptor's buffer address */
199 	union {
200 		uint32_t data;
201 		struct {
202 			uint16_t length;  /* Data buffer length */
203 			uint8_t typ_len_ext;
204 			uint8_t cmd;
205 		} flags;
206 	} lower;
207 	union {
208 		uint32_t data;
209 		struct {
210 			uint8_t status;  /* Descriptor status */
211 			uint8_t popts;  /* Packet Options */
212 			uint16_t special;
213 		} fields;
214 	} upper;
215 };
216 
217 union e1000_tx_udesc {
218 	struct e1000_tx_desc td;
219 	struct e1000_context_desc cd;
220 	struct e1000_data_desc dd;
221 };
222 
223 /* Tx checksum info for a packet. */
224 struct ck_info {
225 	int	ck_valid;	/* ck_info is valid */
226 	uint8_t	ck_start;	/* start byte of cksum calcuation */
227 	uint8_t	ck_off;		/* offset of cksum insertion */
228 	uint16_t ck_len;	/* length of cksum calc: 0 is to packet-end */
229 };
230 
231 /*
232  * Debug printf
233  */
234 static int e82545_debug = 0;
235 #define WPRINTF(msg,params...) PRINTLN("e82545: " msg, ##params)
236 #define DPRINTF(msg,params...) if (e82545_debug) WPRINTF(msg, params)
237 
238 #define	MIN(a,b) (((a)<(b))?(a):(b))
239 #define	MAX(a,b) (((a)>(b))?(a):(b))
240 
241 /* s/w representation of the RAL/RAH regs */
242 struct  eth_uni {
243 	int		eu_valid;
244 	int		eu_addrsel;
245 	struct ether_addr eu_eth;
246 };
247 
248 
249 struct e82545_softc {
250 	struct pci_devinst *esc_pi;
251 	struct vmctx	*esc_ctx;
252 	struct mevent   *esc_mevpitr;
253 	pthread_mutex_t	esc_mtx;
254 	struct ether_addr esc_mac;
255 	net_backend_t	*esc_be;
256 
257 	/* General */
258 	uint32_t	esc_CTRL;	/* x0000 device ctl */
259 	uint32_t	esc_FCAL;	/* x0028 flow ctl addr lo */
260 	uint32_t	esc_FCAH;	/* x002C flow ctl addr hi */
261 	uint32_t	esc_FCT;	/* x0030 flow ctl type */
262 	uint32_t	esc_VET;	/* x0038 VLAN eth type */
263 	uint32_t	esc_FCTTV;	/* x0170 flow ctl tx timer */
264 	uint32_t	esc_LEDCTL;	/* x0E00 LED control */
265 	uint32_t	esc_PBA;	/* x1000 pkt buffer allocation */
266 
267 	/* Interrupt control */
268 	int		esc_irq_asserted;
269 	uint32_t	esc_ICR;	/* x00C0 cause read/clear */
270 	uint32_t	esc_ITR;	/* x00C4 intr throttling */
271 	uint32_t	esc_ICS;	/* x00C8 cause set */
272 	uint32_t	esc_IMS;	/* x00D0 mask set/read */
273 	uint32_t	esc_IMC;	/* x00D8 mask clear */
274 
275 	/* Transmit */
276 	union e1000_tx_udesc *esc_txdesc;
277 	struct e1000_context_desc esc_txctx;
278 	pthread_t	esc_tx_tid;
279 	pthread_cond_t	esc_tx_cond;
280 	int		esc_tx_enabled;
281 	int		esc_tx_active;
282 	uint32_t	esc_TXCW;	/* x0178 transmit config */
283 	uint32_t	esc_TCTL;	/* x0400 transmit ctl */
284 	uint32_t	esc_TIPG;	/* x0410 inter-packet gap */
285 	uint16_t	esc_AIT;	/* x0458 Adaptive Interframe Throttle */
286 	uint64_t	esc_tdba;      	/* verified 64-bit desc table addr */
287 	uint32_t	esc_TDBAL;	/* x3800 desc table addr, low bits */
288 	uint32_t	esc_TDBAH;	/* x3804 desc table addr, hi 32-bits */
289 	uint32_t	esc_TDLEN;	/* x3808 # descriptors in bytes */
290 	uint16_t	esc_TDH;	/* x3810 desc table head idx */
291 	uint16_t	esc_TDHr;	/* internal read version of TDH */
292 	uint16_t	esc_TDT;	/* x3818 desc table tail idx */
293 	uint32_t	esc_TIDV;	/* x3820 intr delay */
294 	uint32_t	esc_TXDCTL;	/* x3828 desc control */
295 	uint32_t	esc_TADV;	/* x382C intr absolute delay */
296 
297 	/* L2 frame acceptance */
298 	struct eth_uni	esc_uni[16];	/* 16 x unicast MAC addresses */
299 	uint32_t	esc_fmcast[128]; /* Multicast filter bit-match */
300 	uint32_t	esc_fvlan[128]; /* VLAN 4096-bit filter */
301 
302 	/* Receive */
303 	struct e1000_rx_desc *esc_rxdesc;
304 	pthread_cond_t	esc_rx_cond;
305 	int		esc_rx_enabled;
306 	int		esc_rx_active;
307 	int		esc_rx_loopback;
308 	uint32_t	esc_RCTL;	/* x0100 receive ctl */
309 	uint32_t	esc_FCRTL;	/* x2160 flow cntl thresh, low */
310 	uint32_t	esc_FCRTH;	/* x2168 flow cntl thresh, hi */
311 	uint64_t	esc_rdba;	/* verified 64-bit desc table addr */
312 	uint32_t	esc_RDBAL;	/* x2800 desc table addr, low bits */
313 	uint32_t	esc_RDBAH;	/* x2804 desc table addr, hi 32-bits*/
314 	uint32_t	esc_RDLEN;	/* x2808 #descriptors */
315 	uint16_t	esc_RDH;	/* x2810 desc table head idx */
316 	uint16_t	esc_RDT;	/* x2818 desc table tail idx */
317 	uint32_t	esc_RDTR;	/* x2820 intr delay */
318 	uint32_t	esc_RXDCTL;	/* x2828 desc control */
319 	uint32_t	esc_RADV;	/* x282C intr absolute delay */
320 	uint32_t	esc_RSRPD;	/* x2C00 recv small packet detect */
321 	uint32_t	esc_RXCSUM;     /* x5000 receive cksum ctl */
322 
323 	/* IO Port register access */
324 	uint32_t io_addr;
325 
326 	/* Shadow copy of MDIC */
327 	uint32_t mdi_control;
328 	/* Shadow copy of EECD */
329 	uint32_t eeprom_control;
330 	/* Latest NVM in/out */
331 	uint16_t nvm_data;
332 	uint16_t nvm_opaddr;
333 	/* stats */
334 	uint32_t missed_pkt_count; /* dropped for no room in rx queue */
335 	uint32_t pkt_rx_by_size[6];
336 	uint32_t pkt_tx_by_size[6];
337 	uint32_t good_pkt_rx_count;
338 	uint32_t bcast_pkt_rx_count;
339 	uint32_t mcast_pkt_rx_count;
340 	uint32_t good_pkt_tx_count;
341 	uint32_t bcast_pkt_tx_count;
342 	uint32_t mcast_pkt_tx_count;
343 	uint32_t oversize_rx_count;
344 	uint32_t tso_tx_count;
345 	uint64_t good_octets_rx;
346 	uint64_t good_octets_tx;
347 	uint64_t missed_octets; /* counts missed and oversized */
348 
349 	uint8_t nvm_bits:6; /* number of bits remaining in/out */
350 	uint8_t nvm_mode:2;
351 #define E82545_NVM_MODE_OPADDR  0x0
352 #define E82545_NVM_MODE_DATAIN  0x1
353 #define E82545_NVM_MODE_DATAOUT 0x2
354 	/* EEPROM data */
355 	uint16_t eeprom_data[E82545_NVM_EEPROM_SIZE];
356 };
357 
358 static void e82545_reset(struct e82545_softc *sc, int dev);
359 static void e82545_rx_enable(struct e82545_softc *sc);
360 static void e82545_rx_disable(struct e82545_softc *sc);
361 static void e82545_rx_callback(int fd, enum ev_type type, void *param);
362 static void e82545_tx_start(struct e82545_softc *sc);
363 static void e82545_tx_enable(struct e82545_softc *sc);
364 static void e82545_tx_disable(struct e82545_softc *sc);
365 
366 static inline int
367 e82545_size_stat_index(uint32_t size)
368 {
369 	if (size <= 64) {
370 		return 0;
371 	} else if (size >= 1024) {
372 		return 5;
373 	} else {
374 		/* should be 1-4 */
375 		return (ffs(size) - 6);
376 	}
377 }
378 
379 static void
380 e82545_init_eeprom(struct e82545_softc *sc)
381 {
382 	uint16_t checksum, i;
383 
384         /* mac addr */
385 	sc->eeprom_data[NVM_MAC_ADDR] = ((uint16_t)sc->esc_mac.octet[0]) |
386 		(((uint16_t)sc->esc_mac.octet[1]) << 8);
387 	sc->eeprom_data[NVM_MAC_ADDR+1] = ((uint16_t)sc->esc_mac.octet[2]) |
388 		(((uint16_t)sc->esc_mac.octet[3]) << 8);
389 	sc->eeprom_data[NVM_MAC_ADDR+2] = ((uint16_t)sc->esc_mac.octet[4]) |
390 		(((uint16_t)sc->esc_mac.octet[5]) << 8);
391 
392 	/* pci ids */
393 	sc->eeprom_data[NVM_SUB_DEV_ID] = E82545_SUBDEV_ID;
394 	sc->eeprom_data[NVM_SUB_VEN_ID] = E82545_VENDOR_ID_INTEL;
395 	sc->eeprom_data[NVM_DEV_ID] = E82545_DEV_ID_82545EM_COPPER;
396 	sc->eeprom_data[NVM_VEN_ID] = E82545_VENDOR_ID_INTEL;
397 
398 	/* fill in the checksum */
399         checksum = 0;
400 	for (i = 0; i < NVM_CHECKSUM_REG; i++) {
401 		checksum += sc->eeprom_data[i];
402 	}
403 	checksum = NVM_SUM - checksum;
404 	sc->eeprom_data[NVM_CHECKSUM_REG] = checksum;
405 	DPRINTF("eeprom checksum: 0x%x", checksum);
406 }
407 
408 static void
409 e82545_write_mdi(struct e82545_softc *sc, uint8_t reg_addr,
410 			uint8_t phy_addr, uint32_t data)
411 {
412 	DPRINTF("Write mdi reg:0x%x phy:0x%x data: 0x%x", reg_addr, phy_addr, data);
413 }
414 
415 static uint32_t
416 e82545_read_mdi(struct e82545_softc *sc, uint8_t reg_addr,
417 			uint8_t phy_addr)
418 {
419 	//DPRINTF("Read mdi reg:0x%x phy:0x%x", reg_addr, phy_addr);
420 	switch (reg_addr) {
421 	case PHY_STATUS:
422 		return (MII_SR_LINK_STATUS | MII_SR_AUTONEG_CAPS |
423 			MII_SR_AUTONEG_COMPLETE);
424 	case PHY_AUTONEG_ADV:
425 		return NWAY_AR_SELECTOR_FIELD;
426 	case PHY_LP_ABILITY:
427 		return 0;
428 	case PHY_1000T_STATUS:
429 		return (SR_1000T_LP_FD_CAPS | SR_1000T_REMOTE_RX_STATUS |
430 			SR_1000T_LOCAL_RX_STATUS);
431 	case PHY_ID1:
432 		return (M88E1011_I_PHY_ID >> 16) & 0xFFFF;
433 	case PHY_ID2:
434 		return (M88E1011_I_PHY_ID | E82545_REVISION_4) & 0xFFFF;
435 	default:
436 		DPRINTF("Unknown mdi read reg:0x%x phy:0x%x", reg_addr, phy_addr);
437 		return 0;
438 	}
439 	/* not reached */
440 }
441 
442 static void
443 e82545_eecd_strobe(struct e82545_softc *sc)
444 {
445 	/* Microwire state machine */
446 	/*
447 	DPRINTF("eeprom state machine srtobe "
448 		"0x%x 0x%x 0x%x 0x%x",
449 		sc->nvm_mode, sc->nvm_bits,
450 		sc->nvm_opaddr, sc->nvm_data);*/
451 
452 	if (sc->nvm_bits == 0) {
453 		DPRINTF("eeprom state machine not expecting data! "
454 			"0x%x 0x%x 0x%x 0x%x",
455 			sc->nvm_mode, sc->nvm_bits,
456 			sc->nvm_opaddr, sc->nvm_data);
457 		return;
458 	}
459 	sc->nvm_bits--;
460 	if (sc->nvm_mode == E82545_NVM_MODE_DATAOUT) {
461 		/* shifting out */
462 		if (sc->nvm_data & 0x8000) {
463 			sc->eeprom_control |= E1000_EECD_DO;
464 		} else {
465 			sc->eeprom_control &= ~E1000_EECD_DO;
466 		}
467 		sc->nvm_data <<= 1;
468 		if (sc->nvm_bits == 0) {
469 			/* read done, back to opcode mode. */
470 			sc->nvm_opaddr = 0;
471 			sc->nvm_mode = E82545_NVM_MODE_OPADDR;
472 			sc->nvm_bits = E82545_NVM_OPADDR_BITS;
473 		}
474 	} else if (sc->nvm_mode == E82545_NVM_MODE_DATAIN) {
475 		/* shifting in */
476 		sc->nvm_data <<= 1;
477 		if (sc->eeprom_control & E1000_EECD_DI) {
478 			sc->nvm_data |= 1;
479 		}
480 		if (sc->nvm_bits == 0) {
481 			/* eeprom write */
482 			uint16_t op = sc->nvm_opaddr & E82545_NVM_OPCODE_MASK;
483 			uint16_t addr = sc->nvm_opaddr & E82545_NVM_ADDR_MASK;
484 			if (op != E82545_NVM_OPCODE_WRITE) {
485 				DPRINTF("Illegal eeprom write op 0x%x",
486 					sc->nvm_opaddr);
487 			} else if (addr >= E82545_NVM_EEPROM_SIZE) {
488 				DPRINTF("Illegal eeprom write addr 0x%x",
489 					sc->nvm_opaddr);
490 			} else {
491 				DPRINTF("eeprom write eeprom[0x%x] = 0x%x",
492 				addr, sc->nvm_data);
493 				sc->eeprom_data[addr] = sc->nvm_data;
494 			}
495 			/* back to opcode mode */
496 			sc->nvm_opaddr = 0;
497 			sc->nvm_mode = E82545_NVM_MODE_OPADDR;
498 			sc->nvm_bits = E82545_NVM_OPADDR_BITS;
499 		}
500 	} else if (sc->nvm_mode == E82545_NVM_MODE_OPADDR) {
501 		sc->nvm_opaddr <<= 1;
502 		if (sc->eeprom_control & E1000_EECD_DI) {
503 			sc->nvm_opaddr |= 1;
504 		}
505 		if (sc->nvm_bits == 0) {
506 			uint16_t op = sc->nvm_opaddr & E82545_NVM_OPCODE_MASK;
507 			switch (op) {
508 			case E82545_NVM_OPCODE_EWEN:
509 				DPRINTF("eeprom write enable: 0x%x",
510 					sc->nvm_opaddr);
511 				/* back to opcode mode */
512 				sc->nvm_opaddr = 0;
513 				sc->nvm_mode = E82545_NVM_MODE_OPADDR;
514 				sc->nvm_bits = E82545_NVM_OPADDR_BITS;
515 				break;
516 			case E82545_NVM_OPCODE_READ:
517 			{
518 				uint16_t addr = sc->nvm_opaddr &
519 					E82545_NVM_ADDR_MASK;
520 				sc->nvm_mode = E82545_NVM_MODE_DATAOUT;
521 				sc->nvm_bits = E82545_NVM_DATA_BITS;
522 				if (addr < E82545_NVM_EEPROM_SIZE) {
523 					sc->nvm_data = sc->eeprom_data[addr];
524 					DPRINTF("eeprom read: eeprom[0x%x] = 0x%x",
525 						addr, sc->nvm_data);
526 				} else {
527 					DPRINTF("eeprom illegal read: 0x%x",
528 						sc->nvm_opaddr);
529 					sc->nvm_data = 0;
530 				}
531 				break;
532 			}
533 			case E82545_NVM_OPCODE_WRITE:
534 				sc->nvm_mode = E82545_NVM_MODE_DATAIN;
535 				sc->nvm_bits = E82545_NVM_DATA_BITS;
536 				sc->nvm_data = 0;
537 				break;
538 			default:
539 				DPRINTF("eeprom unknown op: 0x%x",
540 					sc->nvm_opaddr);
541 				/* back to opcode mode */
542 				sc->nvm_opaddr = 0;
543 				sc->nvm_mode = E82545_NVM_MODE_OPADDR;
544 				sc->nvm_bits = E82545_NVM_OPADDR_BITS;
545 			}
546 		}
547 	} else {
548 		DPRINTF("eeprom state machine wrong state! "
549 			"0x%x 0x%x 0x%x 0x%x",
550 			sc->nvm_mode, sc->nvm_bits,
551 			sc->nvm_opaddr, sc->nvm_data);
552 	}
553 }
554 
555 static void
556 e82545_itr_callback(int fd, enum ev_type type, void *param)
557 {
558 	uint32_t new;
559 	struct e82545_softc *sc = param;
560 
561 	pthread_mutex_lock(&sc->esc_mtx);
562 	new = sc->esc_ICR & sc->esc_IMS;
563 	if (new && !sc->esc_irq_asserted) {
564 		DPRINTF("itr callback: lintr assert %x", new);
565 		sc->esc_irq_asserted = 1;
566 		pci_lintr_assert(sc->esc_pi);
567 	} else {
568 		mevent_delete(sc->esc_mevpitr);
569 		sc->esc_mevpitr = NULL;
570 	}
571 	pthread_mutex_unlock(&sc->esc_mtx);
572 }
573 
574 static void
575 e82545_icr_assert(struct e82545_softc *sc, uint32_t bits)
576 {
577 	uint32_t new;
578 
579 	DPRINTF("icr assert: 0x%x", bits);
580 
581 	/*
582 	 * An interrupt is only generated if bits are set that
583 	 * aren't already in the ICR, these bits are unmasked,
584 	 * and there isn't an interrupt already pending.
585 	 */
586 	new = bits & ~sc->esc_ICR & sc->esc_IMS;
587 	sc->esc_ICR |= bits;
588 
589 	if (new == 0) {
590 		DPRINTF("icr assert: masked %x, ims %x", new, sc->esc_IMS);
591 	} else if (sc->esc_mevpitr != NULL) {
592 		DPRINTF("icr assert: throttled %x, ims %x", new, sc->esc_IMS);
593 	} else if (!sc->esc_irq_asserted) {
594 		DPRINTF("icr assert: lintr assert %x", new);
595 		sc->esc_irq_asserted = 1;
596 		pci_lintr_assert(sc->esc_pi);
597 		if (sc->esc_ITR != 0) {
598 			sc->esc_mevpitr = mevent_add(
599 			    (sc->esc_ITR + 3905) / 3906,  /* 256ns -> 1ms */
600 			    EVF_TIMER, e82545_itr_callback, sc);
601 		}
602 	}
603 }
604 
605 static void
606 e82545_ims_change(struct e82545_softc *sc, uint32_t bits)
607 {
608 	uint32_t new;
609 
610 	/*
611 	 * Changing the mask may allow previously asserted
612 	 * but masked interrupt requests to generate an interrupt.
613 	 */
614 	new = bits & sc->esc_ICR & ~sc->esc_IMS;
615 	sc->esc_IMS |= bits;
616 
617 	if (new == 0) {
618 		DPRINTF("ims change: masked %x, ims %x", new, sc->esc_IMS);
619 	} else if (sc->esc_mevpitr != NULL) {
620 		DPRINTF("ims change: throttled %x, ims %x", new, sc->esc_IMS);
621 	} else if (!sc->esc_irq_asserted) {
622 		DPRINTF("ims change: lintr assert %x", new);
623 		sc->esc_irq_asserted = 1;
624 		pci_lintr_assert(sc->esc_pi);
625 		if (sc->esc_ITR != 0) {
626 			sc->esc_mevpitr = mevent_add(
627 			    (sc->esc_ITR + 3905) / 3906,  /* 256ns -> 1ms */
628 			    EVF_TIMER, e82545_itr_callback, sc);
629 		}
630 	}
631 }
632 
633 static void
634 e82545_icr_deassert(struct e82545_softc *sc, uint32_t bits)
635 {
636 
637 	DPRINTF("icr deassert: 0x%x", bits);
638 	sc->esc_ICR &= ~bits;
639 
640 	/*
641 	 * If there are no longer any interrupt sources and there
642 	 * was an asserted interrupt, clear it
643 	 */
644 	if (sc->esc_irq_asserted && !(sc->esc_ICR & sc->esc_IMS)) {
645 		DPRINTF("icr deassert: lintr deassert %x", bits);
646 		pci_lintr_deassert(sc->esc_pi);
647 		sc->esc_irq_asserted = 0;
648 	}
649 }
650 
651 static void
652 e82545_intr_write(struct e82545_softc *sc, uint32_t offset, uint32_t value)
653 {
654 
655 	DPRINTF("intr_write: off %x, val %x", offset, value);
656 
657 	switch (offset) {
658 	case E1000_ICR:
659 		e82545_icr_deassert(sc, value);
660 		break;
661 	case E1000_ITR:
662 		sc->esc_ITR = value;
663 		break;
664 	case E1000_ICS:
665 		sc->esc_ICS = value;	/* not used: store for debug */
666 		e82545_icr_assert(sc, value);
667 		break;
668 	case E1000_IMS:
669 		e82545_ims_change(sc, value);
670 		break;
671 	case E1000_IMC:
672 		sc->esc_IMC = value;	/* for debug */
673 		sc->esc_IMS &= ~value;
674 		// XXX clear interrupts if all ICR bits now masked
675 		// and interrupt was pending ?
676 		break;
677 	default:
678 		break;
679 	}
680 }
681 
682 static uint32_t
683 e82545_intr_read(struct e82545_softc *sc, uint32_t offset)
684 {
685 	uint32_t retval;
686 
687 	retval = 0;
688 
689 	DPRINTF("intr_read: off %x", offset);
690 
691 	switch (offset) {
692 	case E1000_ICR:
693 		retval = sc->esc_ICR;
694 		sc->esc_ICR = 0;
695 		e82545_icr_deassert(sc, ~0);
696 		break;
697 	case E1000_ITR:
698 		retval = sc->esc_ITR;
699 		break;
700 	case E1000_ICS:
701 		/* write-only register */
702 		break;
703 	case E1000_IMS:
704 		retval = sc->esc_IMS;
705 		break;
706 	case E1000_IMC:
707 		/* write-only register */
708 		break;
709 	default:
710 		break;
711 	}
712 
713 	return (retval);
714 }
715 
716 static void
717 e82545_devctl(struct e82545_softc *sc, uint32_t val)
718 {
719 
720 	sc->esc_CTRL = val & ~E1000_CTRL_RST;
721 
722 	if (val & E1000_CTRL_RST) {
723 		DPRINTF("e1k: s/w reset, ctl %x", val);
724 		e82545_reset(sc, 1);
725 	}
726 	/* XXX check for phy reset ? */
727 }
728 
729 static void
730 e82545_rx_update_rdba(struct e82545_softc *sc)
731 {
732 
733 	/* XXX verify desc base/len within phys mem range */
734 	sc->esc_rdba = (uint64_t)sc->esc_RDBAH << 32 |
735 	    sc->esc_RDBAL;
736 
737 	/* Cache host mapping of guest descriptor array */
738 	sc->esc_rxdesc = paddr_guest2host(sc->esc_ctx,
739 	    sc->esc_rdba, sc->esc_RDLEN);
740 }
741 
742 static void
743 e82545_rx_ctl(struct e82545_softc *sc, uint32_t val)
744 {
745 	int on;
746 
747 	on = ((val & E1000_RCTL_EN) == E1000_RCTL_EN);
748 
749 	/* Save RCTL after stripping reserved bits 31:27,24,21,14,11:10,0 */
750 	sc->esc_RCTL = val & ~0xF9204c01;
751 
752 	DPRINTF("rx_ctl - %s RCTL %x, val %x",
753 		on ? "on" : "off", sc->esc_RCTL, val);
754 
755 	/* state change requested */
756 	if (on != sc->esc_rx_enabled) {
757 		if (on) {
758 			/* Catch disallowed/unimplemented settings */
759 			//assert(!(val & E1000_RCTL_LBM_TCVR));
760 
761 			if (sc->esc_RCTL & E1000_RCTL_LBM_TCVR) {
762 				sc->esc_rx_loopback = 1;
763 			} else {
764 				sc->esc_rx_loopback = 0;
765 			}
766 
767 			e82545_rx_update_rdba(sc);
768 			e82545_rx_enable(sc);
769 		} else {
770 			e82545_rx_disable(sc);
771 			sc->esc_rx_loopback = 0;
772 			sc->esc_rdba = 0;
773 			sc->esc_rxdesc = NULL;
774 		}
775 	}
776 }
777 
778 static void
779 e82545_tx_update_tdba(struct e82545_softc *sc)
780 {
781 
782 	/* XXX verify desc base/len within phys mem range */
783 	sc->esc_tdba = (uint64_t)sc->esc_TDBAH << 32 | sc->esc_TDBAL;
784 
785 	/* Cache host mapping of guest descriptor array */
786 	sc->esc_txdesc = paddr_guest2host(sc->esc_ctx, sc->esc_tdba,
787             sc->esc_TDLEN);
788 }
789 
790 static void
791 e82545_tx_ctl(struct e82545_softc *sc, uint32_t val)
792 {
793 	int on;
794 
795 	on = ((val & E1000_TCTL_EN) == E1000_TCTL_EN);
796 
797 	/* ignore TCTL_EN settings that don't change state */
798 	if (on == sc->esc_tx_enabled)
799 		return;
800 
801 	if (on) {
802 		e82545_tx_update_tdba(sc);
803 		e82545_tx_enable(sc);
804 	} else {
805 		e82545_tx_disable(sc);
806 		sc->esc_tdba = 0;
807 		sc->esc_txdesc = NULL;
808 	}
809 
810 	/* Save TCTL value after stripping reserved bits 31:25,23,2,0 */
811 	sc->esc_TCTL = val & ~0xFE800005;
812 }
813 
814 static int
815 e82545_bufsz(uint32_t rctl)
816 {
817 
818 	switch (rctl & (E1000_RCTL_BSEX | E1000_RCTL_SZ_256)) {
819 	case (E1000_RCTL_SZ_2048): return (2048);
820 	case (E1000_RCTL_SZ_1024): return (1024);
821 	case (E1000_RCTL_SZ_512): return (512);
822 	case (E1000_RCTL_SZ_256): return (256);
823 	case (E1000_RCTL_BSEX|E1000_RCTL_SZ_16384): return (16384);
824 	case (E1000_RCTL_BSEX|E1000_RCTL_SZ_8192): return (8192);
825 	case (E1000_RCTL_BSEX|E1000_RCTL_SZ_4096): return (4096);
826 	}
827 	return (256);	/* Forbidden value. */
828 }
829 
830 /* XXX one packet at a time until this is debugged */
831 static void
832 e82545_rx_callback(int fd, enum ev_type type, void *param)
833 {
834 	struct e82545_softc *sc = param;
835 	struct e1000_rx_desc *rxd;
836 	struct iovec vec[64];
837 	int left, len, lim, maxpktsz, maxpktdesc, bufsz, i, n, size;
838 	uint32_t cause = 0;
839 	uint16_t *tp, tag, head;
840 
841 	pthread_mutex_lock(&sc->esc_mtx);
842 	DPRINTF("rx_run: head %x, tail %x", sc->esc_RDH, sc->esc_RDT);
843 
844 	if (!sc->esc_rx_enabled || sc->esc_rx_loopback) {
845 		DPRINTF("rx disabled (!%d || %d) -- packet(s) dropped",
846 		    sc->esc_rx_enabled, sc->esc_rx_loopback);
847 		while (netbe_rx_discard(sc->esc_be) > 0) {
848 		}
849 		goto done1;
850 	}
851 	bufsz = e82545_bufsz(sc->esc_RCTL);
852 	maxpktsz = (sc->esc_RCTL & E1000_RCTL_LPE) ? 16384 : 1522;
853 	maxpktdesc = (maxpktsz + bufsz - 1) / bufsz;
854 	size = sc->esc_RDLEN / 16;
855 	head = sc->esc_RDH;
856 	left = (size + sc->esc_RDT - head) % size;
857 	if (left < maxpktdesc) {
858 		DPRINTF("rx overflow (%d < %d) -- packet(s) dropped",
859 		    left, maxpktdesc);
860 		while (netbe_rx_discard(sc->esc_be) > 0) {
861 		}
862 		goto done1;
863 	}
864 
865 	sc->esc_rx_active = 1;
866 	pthread_mutex_unlock(&sc->esc_mtx);
867 
868 	for (lim = size / 4; lim > 0 && left >= maxpktdesc; lim -= n) {
869 
870 		/* Grab rx descriptor pointed to by the head pointer */
871 		for (i = 0; i < maxpktdesc; i++) {
872 			rxd = &sc->esc_rxdesc[(head + i) % size];
873 			vec[i].iov_base = paddr_guest2host(sc->esc_ctx,
874 			    rxd->buffer_addr, bufsz);
875 			vec[i].iov_len = bufsz;
876 		}
877 		len = netbe_recv(sc->esc_be, vec, maxpktdesc);
878 		if (len <= 0) {
879 			DPRINTF("netbe_recv() returned %d", len);
880 			goto done;
881 		}
882 
883 		/*
884 		 * Adjust the packet length based on whether the CRC needs
885 		 * to be stripped or if the packet is less than the minimum
886 		 * eth packet size.
887 		 */
888 		if (len < ETHER_MIN_LEN - ETHER_CRC_LEN)
889 			len = ETHER_MIN_LEN - ETHER_CRC_LEN;
890 		if (!(sc->esc_RCTL & E1000_RCTL_SECRC))
891 			len += ETHER_CRC_LEN;
892 		n = (len + bufsz - 1) / bufsz;
893 
894 		DPRINTF("packet read %d bytes, %d segs, head %d",
895 		    len, n, head);
896 
897 		/* Apply VLAN filter. */
898 		tp = (uint16_t *)vec[0].iov_base + 6;
899 		if ((sc->esc_RCTL & E1000_RCTL_VFE) &&
900 		    (ntohs(tp[0]) == sc->esc_VET)) {
901 			tag = ntohs(tp[1]) & 0x0fff;
902 			if ((sc->esc_fvlan[tag >> 5] &
903 			    (1 << (tag & 0x1f))) != 0) {
904 				DPRINTF("known VLAN %d", tag);
905 			} else {
906 				DPRINTF("unknown VLAN %d", tag);
907 				n = 0;
908 				continue;
909 			}
910 		}
911 
912 		/* Update all consumed descriptors. */
913 		for (i = 0; i < n - 1; i++) {
914 			rxd = &sc->esc_rxdesc[(head + i) % size];
915 			rxd->length = bufsz;
916 			rxd->csum = 0;
917 			rxd->errors = 0;
918 			rxd->special = 0;
919 			rxd->status = E1000_RXD_STAT_DD;
920 		}
921 		rxd = &sc->esc_rxdesc[(head + i) % size];
922 		rxd->length = len % bufsz;
923 		rxd->csum = 0;
924 		rxd->errors = 0;
925 		rxd->special = 0;
926 		/* XXX signal no checksum for now */
927 		rxd->status = E1000_RXD_STAT_PIF | E1000_RXD_STAT_IXSM |
928 		    E1000_RXD_STAT_EOP | E1000_RXD_STAT_DD;
929 
930 		/* Schedule receive interrupts. */
931 		if (len <= sc->esc_RSRPD) {
932 			cause |= E1000_ICR_SRPD | E1000_ICR_RXT0;
933 		} else {
934 			/* XXX: RDRT and RADV timers should be here. */
935 			cause |= E1000_ICR_RXT0;
936 		}
937 
938 		head = (head + n) % size;
939 		left -= n;
940 	}
941 
942 done:
943 	pthread_mutex_lock(&sc->esc_mtx);
944 	sc->esc_rx_active = 0;
945 	if (sc->esc_rx_enabled == 0)
946 		pthread_cond_signal(&sc->esc_rx_cond);
947 
948 	sc->esc_RDH = head;
949 	/* Respect E1000_RCTL_RDMTS */
950 	left = (size + sc->esc_RDT - head) % size;
951 	if (left < (size >> (((sc->esc_RCTL >> 8) & 3) + 1)))
952 		cause |= E1000_ICR_RXDMT0;
953 	/* Assert all accumulated interrupts. */
954 	if (cause != 0)
955 		e82545_icr_assert(sc, cause);
956 done1:
957 	DPRINTF("rx_run done: head %x, tail %x", sc->esc_RDH, sc->esc_RDT);
958 	pthread_mutex_unlock(&sc->esc_mtx);
959 }
960 
961 static uint16_t
962 e82545_carry(uint32_t sum)
963 {
964 
965 	sum = (sum & 0xFFFF) + (sum >> 16);
966 	if (sum > 0xFFFF)
967 		sum -= 0xFFFF;
968 	return (sum);
969 }
970 
971 static uint16_t
972 e82545_buf_checksum(uint8_t *buf, int len)
973 {
974 	int i;
975 	uint32_t sum = 0;
976 
977 	/* Checksum all the pairs of bytes first... */
978 	for (i = 0; i < (len & ~1U); i += 2)
979 		sum += *((u_int16_t *)(buf + i));
980 
981 	/*
982 	 * If there's a single byte left over, checksum it, too.
983 	 * Network byte order is big-endian, so the remaining byte is
984 	 * the high byte.
985 	 */
986 	if (i < len)
987 		sum += htons(buf[i] << 8);
988 
989 	return (e82545_carry(sum));
990 }
991 
992 static uint16_t
993 e82545_iov_checksum(struct iovec *iov, int iovcnt, int off, int len)
994 {
995 	int now, odd;
996 	uint32_t sum = 0, s;
997 
998 	/* Skip completely unneeded vectors. */
999 	while (iovcnt > 0 && iov->iov_len <= off && off > 0) {
1000 		off -= iov->iov_len;
1001 		iov++;
1002 		iovcnt--;
1003 	}
1004 
1005 	/* Calculate checksum of requested range. */
1006 	odd = 0;
1007 	while (len > 0 && iovcnt > 0) {
1008 		now = MIN(len, iov->iov_len - off);
1009 #ifdef __FreeBSD__
1010 		s = e82545_buf_checksum(iov->iov_base + off, now);
1011 #else
1012 		s = e82545_buf_checksum((uint8_t *)iov->iov_base + off, now);
1013 #endif
1014 		sum += odd ? (s << 8) : s;
1015 		odd ^= (now & 1);
1016 		len -= now;
1017 		off = 0;
1018 		iov++;
1019 		iovcnt--;
1020 	}
1021 
1022 	return (e82545_carry(sum));
1023 }
1024 
1025 /*
1026  * Return the transmit descriptor type.
1027  */
1028 static int
1029 e82545_txdesc_type(uint32_t lower)
1030 {
1031 	int type;
1032 
1033 	type = 0;
1034 
1035 	if (lower & E1000_TXD_CMD_DEXT)
1036 		type = lower & E1000_TXD_MASK;
1037 
1038 	return (type);
1039 }
1040 
1041 static void
1042 e82545_transmit_checksum(struct iovec *iov, int iovcnt, struct ck_info *ck)
1043 {
1044 	uint16_t cksum;
1045 	int cklen;
1046 
1047 	DPRINTF("tx cksum: iovcnt/s/off/len %d/%d/%d/%d",
1048 	    iovcnt, ck->ck_start, ck->ck_off, ck->ck_len);
1049 	cklen = ck->ck_len ? ck->ck_len - ck->ck_start + 1 : INT_MAX;
1050 	cksum = e82545_iov_checksum(iov, iovcnt, ck->ck_start, cklen);
1051 	*(uint16_t *)((uint8_t *)iov[0].iov_base + ck->ck_off) = ~cksum;
1052 }
1053 
1054 static void
1055 e82545_transmit_backend(struct e82545_softc *sc, struct iovec *iov, int iovcnt)
1056 {
1057 
1058 	if (sc->esc_be == NULL)
1059 		return;
1060 
1061 	(void) netbe_send(sc->esc_be, iov, iovcnt);
1062 }
1063 
1064 static void
1065 e82545_transmit_done(struct e82545_softc *sc, uint16_t head, uint16_t tail,
1066     uint16_t dsize, int *tdwb)
1067 {
1068 	union e1000_tx_udesc *dsc;
1069 
1070 	for ( ; head != tail; head = (head + 1) % dsize) {
1071 		dsc = &sc->esc_txdesc[head];
1072 		if (dsc->td.lower.data & E1000_TXD_CMD_RS) {
1073 			dsc->td.upper.data |= E1000_TXD_STAT_DD;
1074 			*tdwb = 1;
1075 		}
1076 	}
1077 }
1078 
1079 static int
1080 e82545_transmit(struct e82545_softc *sc, uint16_t head, uint16_t tail,
1081     uint16_t dsize, uint16_t *rhead, int *tdwb)
1082 {
1083 	uint8_t *hdr, *hdrp;
1084 	struct iovec iovb[I82545_MAX_TXSEGS + 2];
1085 	struct iovec tiov[I82545_MAX_TXSEGS + 2];
1086 	struct e1000_context_desc *cd;
1087 	struct ck_info ckinfo[2];
1088 	struct iovec *iov;
1089 	union  e1000_tx_udesc *dsc;
1090 	int desc, dtype, len, ntype, iovcnt, tcp, tso;
1091 	int mss, paylen, seg, tiovcnt, left, now, nleft, nnow, pv, pvoff;
1092 	unsigned hdrlen, vlen, pktlen;
1093 	uint32_t tcpsum, tcpseq;
1094 	uint16_t ipcs, tcpcs, ipid, ohead;
1095 	bool invalid;
1096 
1097 	ckinfo[0].ck_valid = ckinfo[1].ck_valid = 0;
1098 	iovcnt = 0;
1099 	ntype = 0;
1100 	tso = 0;
1101 	pktlen = 0;
1102 	ohead = head;
1103 	invalid = false;
1104 
1105 	/* iovb[0/1] may be used for writable copy of headers. */
1106 	iov = &iovb[2];
1107 
1108 	for (desc = 0; ; desc++, head = (head + 1) % dsize) {
1109 		if (head == tail) {
1110 			*rhead = head;
1111 			return (0);
1112 		}
1113 		dsc = &sc->esc_txdesc[head];
1114 		dtype = e82545_txdesc_type(dsc->td.lower.data);
1115 
1116 		if (desc == 0) {
1117 			switch (dtype) {
1118 			case E1000_TXD_TYP_C:
1119 				DPRINTF("tx ctxt desc idx %d: %016jx "
1120 				    "%08x%08x",
1121 				    head, dsc->td.buffer_addr,
1122 				    dsc->td.upper.data, dsc->td.lower.data);
1123 				/* Save context and return */
1124 				sc->esc_txctx = dsc->cd;
1125 				goto done;
1126 			case E1000_TXD_TYP_L:
1127 				DPRINTF("tx legacy desc idx %d: %08x%08x",
1128 				    head, dsc->td.upper.data, dsc->td.lower.data);
1129 				/*
1130 				 * legacy cksum start valid in first descriptor
1131 				 */
1132 				ntype = dtype;
1133 				ckinfo[0].ck_start = dsc->td.upper.fields.css;
1134 				break;
1135 			case E1000_TXD_TYP_D:
1136 				DPRINTF("tx data desc idx %d: %08x%08x",
1137 				    head, dsc->td.upper.data, dsc->td.lower.data);
1138 				ntype = dtype;
1139 				break;
1140 			default:
1141 				break;
1142 			}
1143 		} else {
1144 			/* Descriptor type must be consistent */
1145 			assert(dtype == ntype);
1146 			DPRINTF("tx next desc idx %d: %08x%08x",
1147 			    head, dsc->td.upper.data, dsc->td.lower.data);
1148 		}
1149 
1150 		len = (dtype == E1000_TXD_TYP_L) ? dsc->td.lower.flags.length :
1151 		    dsc->dd.lower.data & 0xFFFFF;
1152 
1153 		/* Strip checksum supplied by guest. */
1154 		if ((dsc->td.lower.data & E1000_TXD_CMD_EOP) != 0 &&
1155 		    (dsc->td.lower.data & E1000_TXD_CMD_IFCS) == 0) {
1156 			if (len <= 2) {
1157 				WPRINTF("final descriptor too short (%d) -- dropped",
1158 				    len);
1159 				invalid = true;
1160 			} else
1161 				len -= 2;
1162 		}
1163 
1164 		if (len > 0 && iovcnt < I82545_MAX_TXSEGS) {
1165 			iov[iovcnt].iov_base = paddr_guest2host(sc->esc_ctx,
1166 			    dsc->td.buffer_addr, len);
1167 			iov[iovcnt].iov_len = len;
1168 			iovcnt++;
1169 			pktlen += len;
1170 		}
1171 
1172 		/*
1173 		 * Pull out info that is valid in the final descriptor
1174 		 * and exit descriptor loop.
1175 		 */
1176 		if (dsc->td.lower.data & E1000_TXD_CMD_EOP) {
1177 			if (dtype == E1000_TXD_TYP_L) {
1178 				if (dsc->td.lower.data & E1000_TXD_CMD_IC) {
1179 					ckinfo[0].ck_valid = 1;
1180 					ckinfo[0].ck_off =
1181 					    dsc->td.lower.flags.cso;
1182 					ckinfo[0].ck_len = 0;
1183 				}
1184 			} else {
1185 				cd = &sc->esc_txctx;
1186 				if (dsc->dd.lower.data & E1000_TXD_CMD_TSE)
1187 					tso = 1;
1188 				if (dsc->dd.upper.fields.popts &
1189 				    E1000_TXD_POPTS_IXSM)
1190 					ckinfo[0].ck_valid = 1;
1191 				if (dsc->dd.upper.fields.popts &
1192 				    E1000_TXD_POPTS_IXSM || tso) {
1193 					ckinfo[0].ck_start =
1194 					    cd->lower_setup.ip_fields.ipcss;
1195 					ckinfo[0].ck_off =
1196 					    cd->lower_setup.ip_fields.ipcso;
1197 					ckinfo[0].ck_len =
1198 					    cd->lower_setup.ip_fields.ipcse;
1199 				}
1200 				if (dsc->dd.upper.fields.popts &
1201 				    E1000_TXD_POPTS_TXSM)
1202 					ckinfo[1].ck_valid = 1;
1203 				if (dsc->dd.upper.fields.popts &
1204 				    E1000_TXD_POPTS_TXSM || tso) {
1205 					ckinfo[1].ck_start =
1206 					    cd->upper_setup.tcp_fields.tucss;
1207 					ckinfo[1].ck_off =
1208 					    cd->upper_setup.tcp_fields.tucso;
1209 					ckinfo[1].ck_len =
1210 					    cd->upper_setup.tcp_fields.tucse;
1211 				}
1212 			}
1213 			break;
1214 		}
1215 	}
1216 
1217 	if (invalid)
1218 		goto done;
1219 
1220 	if (iovcnt > I82545_MAX_TXSEGS) {
1221 		WPRINTF("tx too many descriptors (%d > %d) -- dropped",
1222 		    iovcnt, I82545_MAX_TXSEGS);
1223 		goto done;
1224 	}
1225 
1226 	hdrlen = vlen = 0;
1227 	/* Estimate writable space for VLAN header insertion. */
1228 	if ((sc->esc_CTRL & E1000_CTRL_VME) &&
1229 	    (dsc->td.lower.data & E1000_TXD_CMD_VLE)) {
1230 		hdrlen = ETHER_ADDR_LEN*2;
1231 		vlen = ETHER_VLAN_ENCAP_LEN;
1232 	}
1233 	if (!tso) {
1234 		/* Estimate required writable space for checksums. */
1235 		if (ckinfo[0].ck_valid)
1236 			hdrlen = MAX(hdrlen, ckinfo[0].ck_off + 2);
1237 		if (ckinfo[1].ck_valid)
1238 			hdrlen = MAX(hdrlen, ckinfo[1].ck_off + 2);
1239 		/* Round up writable space to the first vector. */
1240 		if (hdrlen != 0 && iov[0].iov_len > hdrlen &&
1241 		    iov[0].iov_len < hdrlen + 100)
1242 			hdrlen = iov[0].iov_len;
1243 	} else {
1244 		/* In case of TSO header length provided by software. */
1245 		hdrlen = sc->esc_txctx.tcp_seg_setup.fields.hdr_len;
1246 
1247 		/*
1248 		 * Cap the header length at 240 based on 7.2.4.5 of
1249 		 * the Intel 82576EB (Rev 2.63) datasheet.
1250 		 */
1251 		if (hdrlen > 240) {
1252 			WPRINTF("TSO hdrlen too large: %d", hdrlen);
1253 			goto done;
1254 		}
1255 
1256 		/*
1257 		 * If VLAN insertion is requested, ensure the header
1258 		 * at least holds the amount of data copied during
1259 		 * VLAN insertion below.
1260 		 *
1261 		 * XXX: Realistic packets will include a full Ethernet
1262 		 * header before the IP header at ckinfo[0].ck_start,
1263 		 * but this check is sufficient to prevent
1264 		 * out-of-bounds access below.
1265 		 */
1266 		if (vlen != 0 && hdrlen < ETHER_ADDR_LEN*2) {
1267 			WPRINTF("TSO hdrlen too small for vlan insertion "
1268 			    "(%d vs %d) -- dropped", hdrlen,
1269 			    ETHER_ADDR_LEN*2);
1270 			goto done;
1271 		}
1272 
1273 		/*
1274 		 * Ensure that the header length covers the used fields
1275 		 * in the IP and TCP headers as well as the IP and TCP
1276 		 * checksums.  The following fields are accessed below:
1277 		 *
1278 		 * Header | Field | Offset | Length
1279 		 * -------+-------+--------+-------
1280 		 * IPv4   | len   | 2      | 2
1281 		 * IPv4   | ID    | 4      | 2
1282 		 * IPv6   | len   | 4      | 2
1283 		 * TCP    | seq # | 4      | 4
1284 		 * TCP    | flags | 13     | 1
1285 		 * UDP    | len   | 4      | 4
1286 		 */
1287 		if (hdrlen < ckinfo[0].ck_start + 6 ||
1288 		    hdrlen < ckinfo[0].ck_off + 2) {
1289 			WPRINTF("TSO hdrlen too small for IP fields (%d) "
1290 			    "-- dropped", hdrlen);
1291 			goto done;
1292 		}
1293 		if (sc->esc_txctx.cmd_and_length & E1000_TXD_CMD_TCP) {
1294 			if (hdrlen < ckinfo[1].ck_start + 14) {
1295 				WPRINTF("TSO hdrlen too small for TCP fields "
1296 				    "(%d) -- dropped", hdrlen);
1297 				goto done;
1298 			}
1299 		} else {
1300 			if (hdrlen < ckinfo[1].ck_start + 8) {
1301 				WPRINTF("TSO hdrlen too small for UDP fields "
1302 				    "(%d) -- dropped", hdrlen);
1303 				goto done;
1304 			}
1305 		}
1306 		if (ckinfo[1].ck_valid && hdrlen < ckinfo[1].ck_off + 2) {
1307 			WPRINTF("TSO hdrlen too small for TCP/UDP fields "
1308 			    "(%d) -- dropped", hdrlen);
1309 			goto done;
1310 		}
1311 		if (ckinfo[1].ck_valid && hdrlen < ckinfo[1].ck_off + 2) {
1312 			WPRINTF("TSO hdrlen too small for TCP/UDP fields "
1313 			    "(%d) -- dropped", hdrlen);
1314 			goto done;
1315 		}
1316 	}
1317 
1318 	if (pktlen < hdrlen + vlen) {
1319 		WPRINTF("packet too small for writable header");
1320 		goto done;
1321 	}
1322 
1323 	/* Allocate, fill and prepend writable header vector. */
1324 	if (hdrlen + vlen != 0) {
1325 		hdr = __builtin_alloca(hdrlen + vlen);
1326 		hdr += vlen;
1327 		for (left = hdrlen, hdrp = hdr; left > 0;
1328 		    left -= now, hdrp += now) {
1329 			now = MIN(left, iov->iov_len);
1330 			memcpy(hdrp, iov->iov_base, now);
1331 			iov->iov_base += now;
1332 			iov->iov_len -= now;
1333 			if (iov->iov_len == 0) {
1334 				iov++;
1335 				iovcnt--;
1336 			}
1337 		}
1338 		iov--;
1339 		iovcnt++;
1340 #ifdef __FreeBSD__
1341 		iov->iov_base = hdr;
1342 #else
1343 		iov->iov_base = (caddr_t)hdr;
1344 #endif
1345 		iov->iov_len = hdrlen;
1346 	} else
1347 		hdr = NULL;
1348 
1349 	/* Insert VLAN tag. */
1350 	if (vlen != 0) {
1351 		hdr -= ETHER_VLAN_ENCAP_LEN;
1352 		memmove(hdr, hdr + ETHER_VLAN_ENCAP_LEN, ETHER_ADDR_LEN*2);
1353 		hdrlen += ETHER_VLAN_ENCAP_LEN;
1354 		hdr[ETHER_ADDR_LEN*2 + 0] = sc->esc_VET >> 8;
1355 		hdr[ETHER_ADDR_LEN*2 + 1] = sc->esc_VET & 0xff;
1356 		hdr[ETHER_ADDR_LEN*2 + 2] = dsc->td.upper.fields.special >> 8;
1357 		hdr[ETHER_ADDR_LEN*2 + 3] = dsc->td.upper.fields.special & 0xff;
1358 #ifdef __FreeBSD__
1359 		iov->iov_base = hdr;
1360 #else
1361 		iov->iov_base = (caddr_t)hdr;
1362 #endif
1363 		iov->iov_len += ETHER_VLAN_ENCAP_LEN;
1364 		/* Correct checksum offsets after VLAN tag insertion. */
1365 		ckinfo[0].ck_start += ETHER_VLAN_ENCAP_LEN;
1366 		ckinfo[0].ck_off += ETHER_VLAN_ENCAP_LEN;
1367 		if (ckinfo[0].ck_len != 0)
1368 			ckinfo[0].ck_len += ETHER_VLAN_ENCAP_LEN;
1369 		ckinfo[1].ck_start += ETHER_VLAN_ENCAP_LEN;
1370 		ckinfo[1].ck_off += ETHER_VLAN_ENCAP_LEN;
1371 		if (ckinfo[1].ck_len != 0)
1372 			ckinfo[1].ck_len += ETHER_VLAN_ENCAP_LEN;
1373 	}
1374 
1375 	/* Simple non-TSO case. */
1376 	if (!tso) {
1377 		/* Calculate checksums and transmit. */
1378 		if (ckinfo[0].ck_valid)
1379 			e82545_transmit_checksum(iov, iovcnt, &ckinfo[0]);
1380 		if (ckinfo[1].ck_valid)
1381 			e82545_transmit_checksum(iov, iovcnt, &ckinfo[1]);
1382 		e82545_transmit_backend(sc, iov, iovcnt);
1383 		goto done;
1384 	}
1385 
1386 	/* Doing TSO. */
1387 	tcp = (sc->esc_txctx.cmd_and_length & E1000_TXD_CMD_TCP) != 0;
1388 	mss = sc->esc_txctx.tcp_seg_setup.fields.mss;
1389 	paylen = (sc->esc_txctx.cmd_and_length & 0x000fffff);
1390 	DPRINTF("tx %s segmentation offload %d+%d/%d bytes %d iovs",
1391 	    tcp ? "TCP" : "UDP", hdrlen, paylen, mss, iovcnt);
1392 	ipid = ntohs(*(uint16_t *)&hdr[ckinfo[0].ck_start + 4]);
1393 	tcpseq = 0;
1394 	if (tcp)
1395 		tcpseq = ntohl(*(uint32_t *)&hdr[ckinfo[1].ck_start + 4]);
1396 	ipcs = *(uint16_t *)&hdr[ckinfo[0].ck_off];
1397 	tcpcs = 0;
1398 	if (ckinfo[1].ck_valid)	/* Save partial pseudo-header checksum. */
1399 		tcpcs = *(uint16_t *)&hdr[ckinfo[1].ck_off];
1400 	pv = 1;
1401 	pvoff = 0;
1402 	for (seg = 0, left = paylen; left > 0; seg++, left -= now) {
1403 		now = MIN(left, mss);
1404 
1405 		/* Construct IOVs for the segment. */
1406 		/* Include whole original header. */
1407 #ifdef __FreeBSD__
1408 		tiov[0].iov_base = hdr;
1409 #else
1410 		tiov[0].iov_base = (caddr_t)hdr;
1411 #endif
1412 		tiov[0].iov_len = hdrlen;
1413 		tiovcnt = 1;
1414 		/* Include respective part of payload IOV. */
1415 		for (nleft = now; pv < iovcnt && nleft > 0; nleft -= nnow) {
1416 			nnow = MIN(nleft, iov[pv].iov_len - pvoff);
1417 			tiov[tiovcnt].iov_base = iov[pv].iov_base + pvoff;
1418 			tiov[tiovcnt++].iov_len = nnow;
1419 			if (pvoff + nnow == iov[pv].iov_len) {
1420 				pv++;
1421 				pvoff = 0;
1422 			} else
1423 				pvoff += nnow;
1424 		}
1425 		DPRINTF("tx segment %d %d+%d bytes %d iovs",
1426 		    seg, hdrlen, now, tiovcnt);
1427 
1428 		/* Update IP header. */
1429 		if (sc->esc_txctx.cmd_and_length & E1000_TXD_CMD_IP) {
1430 			/* IPv4 -- set length and ID */
1431 			*(uint16_t *)&hdr[ckinfo[0].ck_start + 2] =
1432 			    htons(hdrlen - ckinfo[0].ck_start + now);
1433 			*(uint16_t *)&hdr[ckinfo[0].ck_start + 4] =
1434 			    htons(ipid + seg);
1435 		} else {
1436 			/* IPv6 -- set length */
1437 			*(uint16_t *)&hdr[ckinfo[0].ck_start + 4] =
1438 			    htons(hdrlen - ckinfo[0].ck_start - 40 +
1439 				  now);
1440 		}
1441 
1442 		/* Update pseudo-header checksum. */
1443 		tcpsum = tcpcs;
1444 		tcpsum += htons(hdrlen - ckinfo[1].ck_start + now);
1445 
1446 		/* Update TCP/UDP headers. */
1447 		if (tcp) {
1448 			/* Update sequence number and FIN/PUSH flags. */
1449 			*(uint32_t *)&hdr[ckinfo[1].ck_start + 4] =
1450 			    htonl(tcpseq + paylen - left);
1451 			if (now < left) {
1452 				hdr[ckinfo[1].ck_start + 13] &=
1453 				    ~(TH_FIN | TH_PUSH);
1454 			}
1455 		} else {
1456 			/* Update payload length. */
1457 			*(uint32_t *)&hdr[ckinfo[1].ck_start + 4] =
1458 			    hdrlen - ckinfo[1].ck_start + now;
1459 		}
1460 
1461 		/* Calculate checksums and transmit. */
1462 		if (ckinfo[0].ck_valid) {
1463 			*(uint16_t *)&hdr[ckinfo[0].ck_off] = ipcs;
1464 			e82545_transmit_checksum(tiov, tiovcnt, &ckinfo[0]);
1465 		}
1466 		if (ckinfo[1].ck_valid) {
1467 			*(uint16_t *)&hdr[ckinfo[1].ck_off] =
1468 			    e82545_carry(tcpsum);
1469 			e82545_transmit_checksum(tiov, tiovcnt, &ckinfo[1]);
1470 		}
1471 		e82545_transmit_backend(sc, tiov, tiovcnt);
1472 	}
1473 
1474 done:
1475 	head = (head + 1) % dsize;
1476 	e82545_transmit_done(sc, ohead, head, dsize, tdwb);
1477 
1478 	*rhead = head;
1479 	return (desc + 1);
1480 }
1481 
1482 static void
1483 e82545_tx_run(struct e82545_softc *sc)
1484 {
1485 	uint32_t cause;
1486 	uint16_t head, rhead, tail, size;
1487 	int lim, tdwb, sent;
1488 
1489 	head = sc->esc_TDH;
1490 	tail = sc->esc_TDT;
1491 	size = sc->esc_TDLEN / 16;
1492 	DPRINTF("tx_run: head %x, rhead %x, tail %x",
1493 	    sc->esc_TDH, sc->esc_TDHr, sc->esc_TDT);
1494 
1495 	pthread_mutex_unlock(&sc->esc_mtx);
1496 	rhead = head;
1497 	tdwb = 0;
1498 	for (lim = size / 4; sc->esc_tx_enabled && lim > 0; lim -= sent) {
1499 		sent = e82545_transmit(sc, head, tail, size, &rhead, &tdwb);
1500 		if (sent == 0)
1501 			break;
1502 		head = rhead;
1503 	}
1504 	pthread_mutex_lock(&sc->esc_mtx);
1505 
1506 	sc->esc_TDH = head;
1507 	sc->esc_TDHr = rhead;
1508 	cause = 0;
1509 	if (tdwb)
1510 		cause |= E1000_ICR_TXDW;
1511 	if (lim != size / 4 && sc->esc_TDH == sc->esc_TDT)
1512 		cause |= E1000_ICR_TXQE;
1513 	if (cause)
1514 		e82545_icr_assert(sc, cause);
1515 
1516 	DPRINTF("tx_run done: head %x, rhead %x, tail %x",
1517 	    sc->esc_TDH, sc->esc_TDHr, sc->esc_TDT);
1518 }
1519 
1520 static _Noreturn void *
1521 e82545_tx_thread(void *param)
1522 {
1523 	struct e82545_softc *sc = param;
1524 
1525 	pthread_mutex_lock(&sc->esc_mtx);
1526 	for (;;) {
1527 		while (!sc->esc_tx_enabled || sc->esc_TDHr == sc->esc_TDT) {
1528 			if (sc->esc_tx_enabled && sc->esc_TDHr != sc->esc_TDT)
1529 				break;
1530 			sc->esc_tx_active = 0;
1531 			if (sc->esc_tx_enabled == 0)
1532 				pthread_cond_signal(&sc->esc_tx_cond);
1533 			pthread_cond_wait(&sc->esc_tx_cond, &sc->esc_mtx);
1534 		}
1535 		sc->esc_tx_active = 1;
1536 
1537 		/* Process some tx descriptors.  Lock dropped inside. */
1538 		e82545_tx_run(sc);
1539 	}
1540 }
1541 
1542 static void
1543 e82545_tx_start(struct e82545_softc *sc)
1544 {
1545 
1546 	if (sc->esc_tx_active == 0)
1547 		pthread_cond_signal(&sc->esc_tx_cond);
1548 }
1549 
1550 static void
1551 e82545_tx_enable(struct e82545_softc *sc)
1552 {
1553 
1554 	sc->esc_tx_enabled = 1;
1555 }
1556 
1557 static void
1558 e82545_tx_disable(struct e82545_softc *sc)
1559 {
1560 
1561 	sc->esc_tx_enabled = 0;
1562 	while (sc->esc_tx_active)
1563 		pthread_cond_wait(&sc->esc_tx_cond, &sc->esc_mtx);
1564 }
1565 
1566 static void
1567 e82545_rx_enable(struct e82545_softc *sc)
1568 {
1569 
1570 	sc->esc_rx_enabled = 1;
1571 }
1572 
1573 static void
1574 e82545_rx_disable(struct e82545_softc *sc)
1575 {
1576 
1577 	sc->esc_rx_enabled = 0;
1578 	while (sc->esc_rx_active)
1579 		pthread_cond_wait(&sc->esc_rx_cond, &sc->esc_mtx);
1580 }
1581 
1582 static void
1583 e82545_write_ra(struct e82545_softc *sc, int reg, uint32_t wval)
1584 {
1585 	struct eth_uni *eu;
1586 	int idx;
1587 
1588 	idx = reg >> 1;
1589 	assert(idx < 15);
1590 
1591 	eu = &sc->esc_uni[idx];
1592 
1593 	if (reg & 0x1) {
1594 		/* RAH */
1595 		eu->eu_valid = ((wval & E1000_RAH_AV) == E1000_RAH_AV);
1596 		eu->eu_addrsel = (wval >> 16) & 0x3;
1597 		eu->eu_eth.octet[5] = wval >> 8;
1598 		eu->eu_eth.octet[4] = wval;
1599 	} else {
1600 		/* RAL */
1601 		eu->eu_eth.octet[3] = wval >> 24;
1602 		eu->eu_eth.octet[2] = wval >> 16;
1603 		eu->eu_eth.octet[1] = wval >> 8;
1604 		eu->eu_eth.octet[0] = wval;
1605 	}
1606 }
1607 
1608 static uint32_t
1609 e82545_read_ra(struct e82545_softc *sc, int reg)
1610 {
1611 	struct eth_uni *eu;
1612 	uint32_t retval;
1613 	int idx;
1614 
1615 	idx = reg >> 1;
1616 	assert(idx < 15);
1617 
1618 	eu = &sc->esc_uni[idx];
1619 
1620 	if (reg & 0x1) {
1621 		/* RAH */
1622 		retval = (eu->eu_valid << 31) |
1623 			 (eu->eu_addrsel << 16) |
1624 			 (eu->eu_eth.octet[5] << 8) |
1625 			 eu->eu_eth.octet[4];
1626 	} else {
1627 		/* RAL */
1628 		retval = (eu->eu_eth.octet[3] << 24) |
1629 			 (eu->eu_eth.octet[2] << 16) |
1630 			 (eu->eu_eth.octet[1] << 8) |
1631 			 eu->eu_eth.octet[0];
1632 	}
1633 
1634 	return (retval);
1635 }
1636 
1637 static void
1638 e82545_write_register(struct e82545_softc *sc, uint32_t offset, uint32_t value)
1639 {
1640 	int ridx;
1641 
1642 	if (offset & 0x3) {
1643 		DPRINTF("Unaligned register write offset:0x%x value:0x%x", offset, value);
1644 		return;
1645 	}
1646 	DPRINTF("Register write: 0x%x value: 0x%x", offset, value);
1647 
1648 	switch (offset) {
1649 	case E1000_CTRL:
1650 	case E1000_CTRL_DUP:
1651 		e82545_devctl(sc, value);
1652 		break;
1653 	case E1000_FCAL:
1654 		sc->esc_FCAL = value;
1655 		break;
1656 	case E1000_FCAH:
1657 		sc->esc_FCAH = value & ~0xFFFF0000;
1658 		break;
1659 	case E1000_FCT:
1660 		sc->esc_FCT = value & ~0xFFFF0000;
1661 		break;
1662 	case E1000_VET:
1663 		sc->esc_VET = value & ~0xFFFF0000;
1664 		break;
1665 	case E1000_FCTTV:
1666 		sc->esc_FCTTV = value & ~0xFFFF0000;
1667 		break;
1668 	case E1000_LEDCTL:
1669 		sc->esc_LEDCTL = value & ~0x30303000;
1670 		break;
1671 	case E1000_PBA:
1672 		sc->esc_PBA = value & 0x0000FF80;
1673 		break;
1674 	case E1000_ICR:
1675 	case E1000_ITR:
1676 	case E1000_ICS:
1677 	case E1000_IMS:
1678 	case E1000_IMC:
1679 		e82545_intr_write(sc, offset, value);
1680 		break;
1681 	case E1000_RCTL:
1682 		e82545_rx_ctl(sc, value);
1683 		break;
1684 	case E1000_FCRTL:
1685 		sc->esc_FCRTL = value & ~0xFFFF0007;
1686 		break;
1687 	case E1000_FCRTH:
1688 		sc->esc_FCRTH = value & ~0xFFFF0007;
1689 		break;
1690 	case E1000_RDBAL(0):
1691 		sc->esc_RDBAL = value & ~0xF;
1692 		if (sc->esc_rx_enabled) {
1693 			/* Apparently legal: update cached address */
1694 			e82545_rx_update_rdba(sc);
1695 		}
1696 		break;
1697 	case E1000_RDBAH(0):
1698 		assert(!sc->esc_rx_enabled);
1699 		sc->esc_RDBAH = value;
1700 		break;
1701 	case E1000_RDLEN(0):
1702 		assert(!sc->esc_rx_enabled);
1703 		sc->esc_RDLEN = value & ~0xFFF0007F;
1704 		break;
1705 	case E1000_RDH(0):
1706 		/* XXX should only ever be zero ? Range check ? */
1707 		sc->esc_RDH = value;
1708 		break;
1709 	case E1000_RDT(0):
1710 		/* XXX if this opens up the rx ring, do something ? */
1711 		sc->esc_RDT = value;
1712 		break;
1713 	case E1000_RDTR:
1714 		/* ignore FPD bit 31 */
1715 		sc->esc_RDTR = value & ~0xFFFF0000;
1716 		break;
1717 	case E1000_RXDCTL(0):
1718 		sc->esc_RXDCTL = value & ~0xFEC0C0C0;
1719 		break;
1720 	case E1000_RADV:
1721 		sc->esc_RADV = value & ~0xFFFF0000;
1722 		break;
1723 	case E1000_RSRPD:
1724 		sc->esc_RSRPD = value & ~0xFFFFF000;
1725 		break;
1726 	case E1000_RXCSUM:
1727 		sc->esc_RXCSUM = value & ~0xFFFFF800;
1728 		break;
1729 	case E1000_TXCW:
1730 		sc->esc_TXCW = value & ~0x3FFF0000;
1731 		break;
1732 	case E1000_TCTL:
1733 		e82545_tx_ctl(sc, value);
1734 		break;
1735 	case E1000_TIPG:
1736 		sc->esc_TIPG = value;
1737 		break;
1738 	case E1000_AIT:
1739 		sc->esc_AIT = value;
1740 		break;
1741 	case E1000_TDBAL(0):
1742 		sc->esc_TDBAL = value & ~0xF;
1743 		if (sc->esc_tx_enabled)
1744 			e82545_tx_update_tdba(sc);
1745 		break;
1746 	case E1000_TDBAH(0):
1747 		sc->esc_TDBAH = value;
1748 		if (sc->esc_tx_enabled)
1749 			e82545_tx_update_tdba(sc);
1750 		break;
1751 	case E1000_TDLEN(0):
1752 		sc->esc_TDLEN = value & ~0xFFF0007F;
1753 		if (sc->esc_tx_enabled)
1754 			e82545_tx_update_tdba(sc);
1755 		break;
1756 	case E1000_TDH(0):
1757 		//assert(!sc->esc_tx_enabled);
1758 		/* XXX should only ever be zero ? Range check ? */
1759 		sc->esc_TDHr = sc->esc_TDH = value;
1760 		break;
1761 	case E1000_TDT(0):
1762 		/* XXX range check ? */
1763 		sc->esc_TDT = value;
1764 		if (sc->esc_tx_enabled)
1765 			e82545_tx_start(sc);
1766 		break;
1767 	case E1000_TIDV:
1768 		sc->esc_TIDV = value & ~0xFFFF0000;
1769 		break;
1770 	case E1000_TXDCTL(0):
1771 		//assert(!sc->esc_tx_enabled);
1772 		sc->esc_TXDCTL = value & ~0xC0C0C0;
1773 		break;
1774 	case E1000_TADV:
1775 		sc->esc_TADV = value & ~0xFFFF0000;
1776 		break;
1777 	case E1000_RAL(0) ... E1000_RAH(15):
1778 		/* convert to u32 offset */
1779 		ridx = (offset - E1000_RAL(0)) >> 2;
1780 		e82545_write_ra(sc, ridx, value);
1781 		break;
1782 	case E1000_MTA ... (E1000_MTA + (127*4)):
1783 		sc->esc_fmcast[(offset - E1000_MTA) >> 2] = value;
1784 		break;
1785 	case E1000_VFTA ... (E1000_VFTA + (127*4)):
1786 		sc->esc_fvlan[(offset - E1000_VFTA) >> 2] = value;
1787 		break;
1788 	case E1000_EECD:
1789 	{
1790 		//DPRINTF("EECD write 0x%x -> 0x%x", sc->eeprom_control, value);
1791 		/* edge triggered low->high */
1792 		uint32_t eecd_strobe = ((sc->eeprom_control & E1000_EECD_SK) ?
1793 			0 : (value & E1000_EECD_SK));
1794 		uint32_t eecd_mask = (E1000_EECD_SK|E1000_EECD_CS|
1795 					E1000_EECD_DI|E1000_EECD_REQ);
1796 		sc->eeprom_control &= ~eecd_mask;
1797 		sc->eeprom_control |= (value & eecd_mask);
1798 		/* grant/revoke immediately */
1799 		if (value & E1000_EECD_REQ) {
1800 			sc->eeprom_control |= E1000_EECD_GNT;
1801 		} else {
1802                         sc->eeprom_control &= ~E1000_EECD_GNT;
1803 		}
1804 		if (eecd_strobe && (sc->eeprom_control & E1000_EECD_CS)) {
1805 			e82545_eecd_strobe(sc);
1806 		}
1807 		return;
1808 	}
1809 	case E1000_MDIC:
1810 	{
1811 		uint8_t reg_addr = (uint8_t)((value & E1000_MDIC_REG_MASK) >>
1812 						E1000_MDIC_REG_SHIFT);
1813 		uint8_t phy_addr = (uint8_t)((value & E1000_MDIC_PHY_MASK) >>
1814 						E1000_MDIC_PHY_SHIFT);
1815 		sc->mdi_control =
1816 			(value & ~(E1000_MDIC_ERROR|E1000_MDIC_DEST));
1817 		if ((value & E1000_MDIC_READY) != 0) {
1818 			DPRINTF("Incorrect MDIC ready bit: 0x%x", value);
1819 			return;
1820 		}
1821 		switch (value & E82545_MDIC_OP_MASK) {
1822 		case E1000_MDIC_OP_READ:
1823 			sc->mdi_control &= ~E82545_MDIC_DATA_MASK;
1824 			sc->mdi_control |= e82545_read_mdi(sc, reg_addr, phy_addr);
1825 			break;
1826 		case E1000_MDIC_OP_WRITE:
1827 			e82545_write_mdi(sc, reg_addr, phy_addr,
1828 				value & E82545_MDIC_DATA_MASK);
1829 			break;
1830 		default:
1831 			DPRINTF("Unknown MDIC op: 0x%x", value);
1832 			return;
1833 		}
1834 		/* TODO: barrier? */
1835 		sc->mdi_control |= E1000_MDIC_READY;
1836 		if (value & E82545_MDIC_IE) {
1837 			// TODO: generate interrupt
1838 		}
1839 		return;
1840 	}
1841 	case E1000_MANC:
1842 	case E1000_STATUS:
1843 		return;
1844 	default:
1845 		DPRINTF("Unknown write register: 0x%x value:%x", offset, value);
1846 		return;
1847 	}
1848 }
1849 
1850 static uint32_t
1851 e82545_read_register(struct e82545_softc *sc, uint32_t offset)
1852 {
1853 	uint32_t retval;
1854 	int ridx;
1855 
1856 	if (offset & 0x3) {
1857 		DPRINTF("Unaligned register read offset:0x%x", offset);
1858 		return 0;
1859 	}
1860 
1861 	DPRINTF("Register read: 0x%x", offset);
1862 
1863 	switch (offset) {
1864 	case E1000_CTRL:
1865 		retval = sc->esc_CTRL;
1866 		break;
1867 	case E1000_STATUS:
1868 		retval = E1000_STATUS_FD | E1000_STATUS_LU |
1869 		    E1000_STATUS_SPEED_1000;
1870 		break;
1871 	case E1000_FCAL:
1872 		retval = sc->esc_FCAL;
1873 		break;
1874 	case E1000_FCAH:
1875 		retval = sc->esc_FCAH;
1876 		break;
1877 	case E1000_FCT:
1878 		retval = sc->esc_FCT;
1879 		break;
1880 	case E1000_VET:
1881 		retval = sc->esc_VET;
1882 		break;
1883 	case E1000_FCTTV:
1884 		retval = sc->esc_FCTTV;
1885 		break;
1886 	case E1000_LEDCTL:
1887 		retval = sc->esc_LEDCTL;
1888 		break;
1889 	case E1000_PBA:
1890 		retval = sc->esc_PBA;
1891 		break;
1892 	case E1000_ICR:
1893 	case E1000_ITR:
1894 	case E1000_ICS:
1895 	case E1000_IMS:
1896 	case E1000_IMC:
1897 		retval = e82545_intr_read(sc, offset);
1898 		break;
1899 	case E1000_RCTL:
1900 		retval = sc->esc_RCTL;
1901 		break;
1902 	case E1000_FCRTL:
1903 		retval = sc->esc_FCRTL;
1904 		break;
1905 	case E1000_FCRTH:
1906 		retval = sc->esc_FCRTH;
1907 		break;
1908 	case E1000_RDBAL(0):
1909 		retval = sc->esc_RDBAL;
1910 		break;
1911 	case E1000_RDBAH(0):
1912 		retval = sc->esc_RDBAH;
1913 		break;
1914 	case E1000_RDLEN(0):
1915 		retval = sc->esc_RDLEN;
1916 		break;
1917 	case E1000_RDH(0):
1918 		retval = sc->esc_RDH;
1919 		break;
1920 	case E1000_RDT(0):
1921 		retval = sc->esc_RDT;
1922 		break;
1923 	case E1000_RDTR:
1924 		retval = sc->esc_RDTR;
1925 		break;
1926 	case E1000_RXDCTL(0):
1927 		retval = sc->esc_RXDCTL;
1928 		break;
1929 	case E1000_RADV:
1930 		retval = sc->esc_RADV;
1931 		break;
1932 	case E1000_RSRPD:
1933 		retval = sc->esc_RSRPD;
1934 		break;
1935 	case E1000_RXCSUM:
1936 		retval = sc->esc_RXCSUM;
1937 		break;
1938 	case E1000_TXCW:
1939 		retval = sc->esc_TXCW;
1940 		break;
1941 	case E1000_TCTL:
1942 		retval = sc->esc_TCTL;
1943 		break;
1944 	case E1000_TIPG:
1945 		retval = sc->esc_TIPG;
1946 		break;
1947 	case E1000_AIT:
1948 		retval = sc->esc_AIT;
1949 		break;
1950 	case E1000_TDBAL(0):
1951 		retval = sc->esc_TDBAL;
1952 		break;
1953 	case E1000_TDBAH(0):
1954 		retval = sc->esc_TDBAH;
1955 		break;
1956 	case E1000_TDLEN(0):
1957 		retval = sc->esc_TDLEN;
1958 		break;
1959 	case E1000_TDH(0):
1960 		retval = sc->esc_TDH;
1961 		break;
1962 	case E1000_TDT(0):
1963 		retval = sc->esc_TDT;
1964 		break;
1965 	case E1000_TIDV:
1966 		retval = sc->esc_TIDV;
1967 		break;
1968 	case E1000_TXDCTL(0):
1969 		retval = sc->esc_TXDCTL;
1970 		break;
1971 	case E1000_TADV:
1972 		retval = sc->esc_TADV;
1973 		break;
1974 	case E1000_RAL(0) ... E1000_RAH(15):
1975 		/* convert to u32 offset */
1976 		ridx = (offset - E1000_RAL(0)) >> 2;
1977 		retval = e82545_read_ra(sc, ridx);
1978 		break;
1979 	case E1000_MTA ... (E1000_MTA + (127*4)):
1980 		retval = sc->esc_fmcast[(offset - E1000_MTA) >> 2];
1981 		break;
1982 	case E1000_VFTA ... (E1000_VFTA + (127*4)):
1983 		retval = sc->esc_fvlan[(offset - E1000_VFTA) >> 2];
1984 		break;
1985 	case E1000_EECD:
1986 		//DPRINTF("EECD read %x", sc->eeprom_control);
1987 		retval = sc->eeprom_control;
1988 		break;
1989 	case E1000_MDIC:
1990 		retval = sc->mdi_control;
1991 		break;
1992 	case E1000_MANC:
1993 		retval = 0;
1994 		break;
1995 	/* stats that we emulate. */
1996 	case E1000_MPC:
1997 		retval = sc->missed_pkt_count;
1998 		break;
1999 	case E1000_PRC64:
2000 		retval = sc->pkt_rx_by_size[0];
2001 		break;
2002 	case E1000_PRC127:
2003 		retval = sc->pkt_rx_by_size[1];
2004 		break;
2005 	case E1000_PRC255:
2006 		retval = sc->pkt_rx_by_size[2];
2007 		break;
2008 	case E1000_PRC511:
2009 		retval = sc->pkt_rx_by_size[3];
2010 		break;
2011 	case E1000_PRC1023:
2012 		retval = sc->pkt_rx_by_size[4];
2013 		break;
2014 	case E1000_PRC1522:
2015 		retval = sc->pkt_rx_by_size[5];
2016 		break;
2017 	case E1000_GPRC:
2018 		retval = sc->good_pkt_rx_count;
2019 		break;
2020 	case E1000_BPRC:
2021 		retval = sc->bcast_pkt_rx_count;
2022 		break;
2023 	case E1000_MPRC:
2024 		retval = sc->mcast_pkt_rx_count;
2025 		break;
2026 	case E1000_GPTC:
2027 	case E1000_TPT:
2028 		retval = sc->good_pkt_tx_count;
2029 		break;
2030 	case E1000_GORCL:
2031 		retval = (uint32_t)sc->good_octets_rx;
2032 		break;
2033 	case E1000_GORCH:
2034 		retval = (uint32_t)(sc->good_octets_rx >> 32);
2035 		break;
2036 	case E1000_TOTL:
2037 	case E1000_GOTCL:
2038 		retval = (uint32_t)sc->good_octets_tx;
2039 		break;
2040 	case E1000_TOTH:
2041 	case E1000_GOTCH:
2042 		retval = (uint32_t)(sc->good_octets_tx >> 32);
2043 		break;
2044 	case E1000_ROC:
2045 		retval = sc->oversize_rx_count;
2046 		break;
2047 	case E1000_TORL:
2048 		retval = (uint32_t)(sc->good_octets_rx + sc->missed_octets);
2049 		break;
2050 	case E1000_TORH:
2051 		retval = (uint32_t)((sc->good_octets_rx +
2052 		    sc->missed_octets) >> 32);
2053 		break;
2054 	case E1000_TPR:
2055 		retval = sc->good_pkt_rx_count + sc->missed_pkt_count +
2056 		    sc->oversize_rx_count;
2057 		break;
2058 	case E1000_PTC64:
2059 		retval = sc->pkt_tx_by_size[0];
2060 		break;
2061 	case E1000_PTC127:
2062 		retval = sc->pkt_tx_by_size[1];
2063 		break;
2064 	case E1000_PTC255:
2065 		retval = sc->pkt_tx_by_size[2];
2066 		break;
2067 	case E1000_PTC511:
2068 		retval = sc->pkt_tx_by_size[3];
2069 		break;
2070 	case E1000_PTC1023:
2071 		retval = sc->pkt_tx_by_size[4];
2072 		break;
2073 	case E1000_PTC1522:
2074 		retval = sc->pkt_tx_by_size[5];
2075 		break;
2076 	case E1000_MPTC:
2077 		retval = sc->mcast_pkt_tx_count;
2078 		break;
2079 	case E1000_BPTC:
2080 		retval = sc->bcast_pkt_tx_count;
2081 		break;
2082 	case E1000_TSCTC:
2083 		retval = sc->tso_tx_count;
2084 		break;
2085 	/* stats that are always 0. */
2086 	case E1000_CRCERRS:
2087 	case E1000_ALGNERRC:
2088 	case E1000_SYMERRS:
2089 	case E1000_RXERRC:
2090 	case E1000_SCC:
2091 	case E1000_ECOL:
2092 	case E1000_MCC:
2093 	case E1000_LATECOL:
2094 	case E1000_COLC:
2095 	case E1000_DC:
2096 	case E1000_TNCRS:
2097 	case E1000_SEC:
2098 	case E1000_CEXTERR:
2099 	case E1000_RLEC:
2100 	case E1000_XONRXC:
2101 	case E1000_XONTXC:
2102 	case E1000_XOFFRXC:
2103 	case E1000_XOFFTXC:
2104 	case E1000_FCRUC:
2105 	case E1000_RNBC:
2106 	case E1000_RUC:
2107 	case E1000_RFC:
2108 	case E1000_RJC:
2109 	case E1000_MGTPRC:
2110 	case E1000_MGTPDC:
2111 	case E1000_MGTPTC:
2112 	case E1000_TSCTFC:
2113 		retval = 0;
2114 		break;
2115 	default:
2116 		DPRINTF("Unknown read register: 0x%x", offset);
2117 		retval = 0;
2118 		break;
2119 	}
2120 
2121 	return (retval);
2122 }
2123 
2124 static void
2125 e82545_write(struct vmctx *ctx, int vcpu, struct pci_devinst *pi, int baridx,
2126 	     uint64_t offset, int size, uint64_t value)
2127 {
2128 	struct e82545_softc *sc;
2129 
2130 	//DPRINTF("Write bar:%d offset:0x%lx value:0x%lx size:%d", baridx, offset, value, size);
2131 
2132 	sc = pi->pi_arg;
2133 
2134 	pthread_mutex_lock(&sc->esc_mtx);
2135 
2136 	switch (baridx) {
2137 	case E82545_BAR_IO:
2138 		switch (offset) {
2139 		case E82545_IOADDR:
2140 			if (size != 4) {
2141 				DPRINTF("Wrong io addr write sz:%d value:0x%lx", size, value);
2142 			} else
2143 				sc->io_addr = (uint32_t)value;
2144 			break;
2145 		case E82545_IODATA:
2146 			if (size != 4) {
2147 				DPRINTF("Wrong io data write size:%d value:0x%lx", size, value);
2148 			} else if (sc->io_addr > E82545_IO_REGISTER_MAX) {
2149 				DPRINTF("Non-register io write addr:0x%x value:0x%lx", sc->io_addr, value);
2150 			} else
2151 				e82545_write_register(sc, sc->io_addr,
2152 						      (uint32_t)value);
2153 			break;
2154 		default:
2155 			DPRINTF("Unknown io bar write offset:0x%lx value:0x%lx size:%d", offset, value, size);
2156 			break;
2157 		}
2158 		break;
2159 	case E82545_BAR_REGISTER:
2160 		if (size != 4) {
2161 			DPRINTF("Wrong register write size:%d offset:0x%lx value:0x%lx", size, offset, value);
2162 		} else
2163 			e82545_write_register(sc, (uint32_t)offset,
2164 					      (uint32_t)value);
2165 		break;
2166 	default:
2167 		DPRINTF("Unknown write bar:%d off:0x%lx val:0x%lx size:%d",
2168 			baridx, offset, value, size);
2169 	}
2170 
2171 	pthread_mutex_unlock(&sc->esc_mtx);
2172 }
2173 
2174 static uint64_t
2175 e82545_read(struct vmctx *ctx, int vcpu, struct pci_devinst *pi, int baridx,
2176 	    uint64_t offset, int size)
2177 {
2178 	struct e82545_softc *sc;
2179 	uint64_t retval;
2180 
2181 	//DPRINTF("Read  bar:%d offset:0x%lx size:%d", baridx, offset, size);
2182 	sc = pi->pi_arg;
2183 	retval = 0;
2184 
2185 	pthread_mutex_lock(&sc->esc_mtx);
2186 
2187 	switch (baridx) {
2188 	case E82545_BAR_IO:
2189 		switch (offset) {
2190 		case E82545_IOADDR:
2191 			if (size != 4) {
2192 				DPRINTF("Wrong io addr read sz:%d", size);
2193 			} else
2194 				retval = sc->io_addr;
2195 			break;
2196 		case E82545_IODATA:
2197 			if (size != 4) {
2198 				DPRINTF("Wrong io data read sz:%d", size);
2199 			}
2200 			if (sc->io_addr > E82545_IO_REGISTER_MAX) {
2201 				DPRINTF("Non-register io read addr:0x%x",
2202 					sc->io_addr);
2203 			} else
2204 				retval = e82545_read_register(sc, sc->io_addr);
2205 			break;
2206 		default:
2207 			DPRINTF("Unknown io bar read offset:0x%lx size:%d",
2208 				offset, size);
2209 			break;
2210 		}
2211 		break;
2212 	case E82545_BAR_REGISTER:
2213 		if (size != 4) {
2214 			DPRINTF("Wrong register read size:%d offset:0x%lx",
2215 				size, offset);
2216 		} else
2217 			retval = e82545_read_register(sc, (uint32_t)offset);
2218 		break;
2219 	default:
2220 		DPRINTF("Unknown read bar:%d offset:0x%lx size:%d",
2221 			baridx, offset, size);
2222 		break;
2223 	}
2224 
2225 	pthread_mutex_unlock(&sc->esc_mtx);
2226 
2227 	return (retval);
2228 }
2229 
2230 static void
2231 e82545_reset(struct e82545_softc *sc, int drvr)
2232 {
2233 	int i;
2234 
2235 	e82545_rx_disable(sc);
2236 	e82545_tx_disable(sc);
2237 
2238 	/* clear outstanding interrupts */
2239 	if (sc->esc_irq_asserted)
2240 		pci_lintr_deassert(sc->esc_pi);
2241 
2242 	/* misc */
2243 	if (!drvr) {
2244 		sc->esc_FCAL = 0;
2245 		sc->esc_FCAH = 0;
2246 		sc->esc_FCT = 0;
2247 		sc->esc_VET = 0;
2248 		sc->esc_FCTTV = 0;
2249 	}
2250 	sc->esc_LEDCTL = 0x07061302;
2251 	sc->esc_PBA = 0x00100030;
2252 
2253 	/* start nvm in opcode mode. */
2254 	sc->nvm_opaddr = 0;
2255 	sc->nvm_mode = E82545_NVM_MODE_OPADDR;
2256 	sc->nvm_bits = E82545_NVM_OPADDR_BITS;
2257 	sc->eeprom_control = E1000_EECD_PRES | E82545_EECD_FWE_EN;
2258 	e82545_init_eeprom(sc);
2259 
2260 	/* interrupt */
2261 	sc->esc_ICR = 0;
2262 	sc->esc_ITR = 250;
2263 	sc->esc_ICS = 0;
2264 	sc->esc_IMS = 0;
2265 	sc->esc_IMC = 0;
2266 
2267 	/* L2 filters */
2268 	if (!drvr) {
2269 		memset(sc->esc_fvlan, 0, sizeof(sc->esc_fvlan));
2270 		memset(sc->esc_fmcast, 0, sizeof(sc->esc_fmcast));
2271 		memset(sc->esc_uni, 0, sizeof(sc->esc_uni));
2272 
2273 		/* XXX not necessary on 82545 ?? */
2274 		sc->esc_uni[0].eu_valid = 1;
2275 		memcpy(sc->esc_uni[0].eu_eth.octet, sc->esc_mac.octet,
2276 		    ETHER_ADDR_LEN);
2277 	} else {
2278 		/* Clear RAH valid bits */
2279 		for (i = 0; i < 16; i++)
2280 			sc->esc_uni[i].eu_valid = 0;
2281 	}
2282 
2283 	/* receive */
2284 	if (!drvr) {
2285 		sc->esc_RDBAL = 0;
2286 		sc->esc_RDBAH = 0;
2287 	}
2288 	sc->esc_RCTL = 0;
2289 	sc->esc_FCRTL = 0;
2290 	sc->esc_FCRTH = 0;
2291 	sc->esc_RDLEN = 0;
2292 	sc->esc_RDH = 0;
2293 	sc->esc_RDT = 0;
2294 	sc->esc_RDTR = 0;
2295 	sc->esc_RXDCTL = (1 << 24) | (1 << 16); /* default GRAN/WTHRESH */
2296 	sc->esc_RADV = 0;
2297 	sc->esc_RXCSUM = 0;
2298 
2299 	/* transmit */
2300 	if (!drvr) {
2301 		sc->esc_TDBAL = 0;
2302 		sc->esc_TDBAH = 0;
2303 		sc->esc_TIPG = 0;
2304 		sc->esc_AIT = 0;
2305 		sc->esc_TIDV = 0;
2306 		sc->esc_TADV = 0;
2307 	}
2308 	sc->esc_tdba = 0;
2309 	sc->esc_txdesc = NULL;
2310 	sc->esc_TXCW = 0;
2311 	sc->esc_TCTL = 0;
2312 	sc->esc_TDLEN = 0;
2313 	sc->esc_TDT = 0;
2314 	sc->esc_TDHr = sc->esc_TDH = 0;
2315 	sc->esc_TXDCTL = 0;
2316 }
2317 
2318 static int
2319 e82545_init(struct vmctx *ctx, struct pci_devinst *pi, nvlist_t *nvl)
2320 {
2321 	char nstr[80];
2322 	struct e82545_softc *sc;
2323 	const char *mac;
2324 	int err;
2325 
2326 	/* Setup our softc */
2327 	sc = calloc(1, sizeof(*sc));
2328 
2329 	pi->pi_arg = sc;
2330 	sc->esc_pi = pi;
2331 	sc->esc_ctx = ctx;
2332 
2333 	pthread_mutex_init(&sc->esc_mtx, NULL);
2334 	pthread_cond_init(&sc->esc_rx_cond, NULL);
2335 	pthread_cond_init(&sc->esc_tx_cond, NULL);
2336 	pthread_create(&sc->esc_tx_tid, NULL, e82545_tx_thread, sc);
2337 	snprintf(nstr, sizeof(nstr), "e82545-%d:%d tx", pi->pi_slot,
2338 	    pi->pi_func);
2339         pthread_set_name_np(sc->esc_tx_tid, nstr);
2340 
2341 	pci_set_cfgdata16(pi, PCIR_DEVICE, E82545_DEV_ID_82545EM_COPPER);
2342 	pci_set_cfgdata16(pi, PCIR_VENDOR, E82545_VENDOR_ID_INTEL);
2343 	pci_set_cfgdata8(pi,  PCIR_CLASS, PCIC_NETWORK);
2344 	pci_set_cfgdata8(pi, PCIR_SUBCLASS, PCIS_NETWORK_ETHERNET);
2345 	pci_set_cfgdata16(pi, PCIR_SUBDEV_0, E82545_SUBDEV_ID);
2346 	pci_set_cfgdata16(pi, PCIR_SUBVEND_0, E82545_VENDOR_ID_INTEL);
2347 
2348 	pci_set_cfgdata8(pi,  PCIR_HDRTYPE, PCIM_HDRTYPE_NORMAL);
2349 	pci_set_cfgdata8(pi,  PCIR_INTPIN, 0x1);
2350 
2351 	/* TODO: this card also supports msi, but the freebsd driver for it
2352 	 * does not, so I have not implemented it. */
2353 	pci_lintr_request(pi);
2354 
2355 	pci_emul_alloc_bar(pi, E82545_BAR_REGISTER, PCIBAR_MEM32,
2356 		E82545_BAR_REGISTER_LEN);
2357 	pci_emul_alloc_bar(pi, E82545_BAR_FLASH, PCIBAR_MEM32,
2358 		E82545_BAR_FLASH_LEN);
2359 	pci_emul_alloc_bar(pi, E82545_BAR_IO, PCIBAR_IO,
2360 		E82545_BAR_IO_LEN);
2361 
2362 	mac = get_config_value_node(nvl, "mac");
2363 	if (mac != NULL) {
2364 		err = net_parsemac(mac, sc->esc_mac.octet);
2365 		if (err) {
2366 			free(sc);
2367 			return (err);
2368 		}
2369 	} else
2370 		net_genmac(pi, sc->esc_mac.octet);
2371 
2372 	err = netbe_init(&sc->esc_be, nvl, e82545_rx_callback, sc);
2373 	if (err) {
2374 		free(sc);
2375 		return (err);
2376 	}
2377 
2378 #ifndef __FreeBSD__
2379 	size_t buflen = sizeof (sc->esc_mac.octet);
2380 
2381 	err = netbe_get_mac(sc->esc_be, sc->esc_mac.octet, &buflen);
2382 	if (err != 0) {
2383 		free(sc);
2384 		return (err);
2385 	}
2386 #endif
2387 
2388 	netbe_rx_enable(sc->esc_be);
2389 
2390 	/* H/w initiated reset */
2391 	e82545_reset(sc, 0);
2392 
2393 	return (0);
2394 }
2395 
2396 static const struct pci_devemu pci_de_e82545 = {
2397 	.pe_emu = 	"e1000",
2398 	.pe_init =	e82545_init,
2399 	.pe_legacy_config = netbe_legacy_config,
2400 	.pe_barwrite =	e82545_write,
2401 	.pe_barread =	e82545_read,
2402 };
2403 PCI_EMUL_SET(pci_de_e82545);
2404