xref: /qemu/block/block-backend.c (revision 86d063fa)
1 /*
2  * QEMU Block backends
3  *
4  * Copyright (C) 2014-2016 Red Hat, Inc.
5  *
6  * Authors:
7  *  Markus Armbruster <armbru@redhat.com>,
8  *
9  * This work is licensed under the terms of the GNU LGPL, version 2.1
10  * or later.  See the COPYING.LIB file in the top-level directory.
11  */
12 
13 #include "qemu/osdep.h"
14 #include "sysemu/block-backend.h"
15 #include "block/block_int.h"
16 #include "block/blockjob.h"
17 #include "block/coroutines.h"
18 #include "block/throttle-groups.h"
19 #include "hw/qdev-core.h"
20 #include "sysemu/blockdev.h"
21 #include "sysemu/runstate.h"
22 #include "sysemu/replay.h"
23 #include "qapi/error.h"
24 #include "qapi/qapi-events-block.h"
25 #include "qemu/id.h"
26 #include "qemu/main-loop.h"
27 #include "qemu/option.h"
28 #include "trace.h"
29 #include "migration/misc.h"
30 
31 /* Number of coroutines to reserve per attached device model */
32 #define COROUTINE_POOL_RESERVATION 64
33 
34 #define NOT_DONE 0x7fffffff /* used while emulated sync operation in progress */
35 
36 static AioContext *blk_aiocb_get_aio_context(BlockAIOCB *acb);
37 
38 typedef struct BlockBackendAioNotifier {
39     void (*attached_aio_context)(AioContext *new_context, void *opaque);
40     void (*detach_aio_context)(void *opaque);
41     void *opaque;
42     QLIST_ENTRY(BlockBackendAioNotifier) list;
43 } BlockBackendAioNotifier;
44 
45 struct BlockBackend {
46     char *name;
47     int refcnt;
48     BdrvChild *root;
49     AioContext *ctx;
50     DriveInfo *legacy_dinfo;    /* null unless created by drive_new() */
51     QTAILQ_ENTRY(BlockBackend) link;         /* for block_backends */
52     QTAILQ_ENTRY(BlockBackend) monitor_link; /* for monitor_block_backends */
53     BlockBackendPublic public;
54 
55     DeviceState *dev;           /* attached device model, if any */
56     const BlockDevOps *dev_ops;
57     void *dev_opaque;
58 
59     /* If the BDS tree is removed, some of its options are stored here (which
60      * can be used to restore those options in the new BDS on insert) */
61     BlockBackendRootState root_state;
62 
63     bool enable_write_cache;
64 
65     /* I/O stats (display with "info blockstats"). */
66     BlockAcctStats stats;
67 
68     BlockdevOnError on_read_error, on_write_error;
69     bool iostatus_enabled;
70     BlockDeviceIoStatus iostatus;
71 
72     uint64_t perm;
73     uint64_t shared_perm;
74     bool disable_perm;
75 
76     bool allow_aio_context_change;
77     bool allow_write_beyond_eof;
78 
79     /* Protected by BQL */
80     NotifierList remove_bs_notifiers, insert_bs_notifiers;
81     QLIST_HEAD(, BlockBackendAioNotifier) aio_notifiers;
82 
83     int quiesce_counter;
84     CoQueue queued_requests;
85     bool disable_request_queuing;
86 
87     VMChangeStateEntry *vmsh;
88     bool force_allow_inactivate;
89 
90     /* Number of in-flight aio requests.  BlockDriverState also counts
91      * in-flight requests but aio requests can exist even when blk->root is
92      * NULL, so we cannot rely on its counter for that case.
93      * Accessed with atomic ops.
94      */
95     unsigned int in_flight;
96 };
97 
98 typedef struct BlockBackendAIOCB {
99     BlockAIOCB common;
100     BlockBackend *blk;
101     int ret;
102 } BlockBackendAIOCB;
103 
104 static const AIOCBInfo block_backend_aiocb_info = {
105     .get_aio_context = blk_aiocb_get_aio_context,
106     .aiocb_size = sizeof(BlockBackendAIOCB),
107 };
108 
109 static void drive_info_del(DriveInfo *dinfo);
110 static BlockBackend *bdrv_first_blk(BlockDriverState *bs);
111 
112 /* All BlockBackends. Protected by BQL. */
113 static QTAILQ_HEAD(, BlockBackend) block_backends =
114     QTAILQ_HEAD_INITIALIZER(block_backends);
115 
116 /*
117  * All BlockBackends referenced by the monitor and which are iterated through by
118  * blk_next(). Protected by BQL.
119  */
120 static QTAILQ_HEAD(, BlockBackend) monitor_block_backends =
121     QTAILQ_HEAD_INITIALIZER(monitor_block_backends);
122 
123 static void blk_root_inherit_options(BdrvChildRole role, bool parent_is_format,
124                                      int *child_flags, QDict *child_options,
125                                      int parent_flags, QDict *parent_options)
126 {
127     /* We're not supposed to call this function for root nodes */
128     abort();
129 }
130 static void blk_root_drained_begin(BdrvChild *child);
131 static bool blk_root_drained_poll(BdrvChild *child);
132 static void blk_root_drained_end(BdrvChild *child);
133 
134 static void blk_root_change_media(BdrvChild *child, bool load);
135 static void blk_root_resize(BdrvChild *child);
136 
137 static bool blk_root_change_aio_ctx(BdrvChild *child, AioContext *ctx,
138                                     GHashTable *visited, Transaction *tran,
139                                     Error **errp);
140 
141 static char *blk_root_get_parent_desc(BdrvChild *child)
142 {
143     BlockBackend *blk = child->opaque;
144     g_autofree char *dev_id = NULL;
145 
146     if (blk->name) {
147         return g_strdup_printf("block device '%s'", blk->name);
148     }
149 
150     dev_id = blk_get_attached_dev_id(blk);
151     if (*dev_id) {
152         return g_strdup_printf("block device '%s'", dev_id);
153     } else {
154         /* TODO Callback into the BB owner for something more detailed */
155         return g_strdup("an unnamed block device");
156     }
157 }
158 
159 static const char *blk_root_get_name(BdrvChild *child)
160 {
161     return blk_name(child->opaque);
162 }
163 
164 static void blk_vm_state_changed(void *opaque, bool running, RunState state)
165 {
166     Error *local_err = NULL;
167     BlockBackend *blk = opaque;
168 
169     if (state == RUN_STATE_INMIGRATE) {
170         return;
171     }
172 
173     qemu_del_vm_change_state_handler(blk->vmsh);
174     blk->vmsh = NULL;
175     blk_set_perm(blk, blk->perm, blk->shared_perm, &local_err);
176     if (local_err) {
177         error_report_err(local_err);
178     }
179 }
180 
181 /*
182  * Notifies the user of the BlockBackend that migration has completed. qdev
183  * devices can tighten their permissions in response (specifically revoke
184  * shared write permissions that we needed for storage migration).
185  *
186  * If an error is returned, the VM cannot be allowed to be resumed.
187  */
188 static void blk_root_activate(BdrvChild *child, Error **errp)
189 {
190     BlockBackend *blk = child->opaque;
191     Error *local_err = NULL;
192     uint64_t saved_shared_perm;
193 
194     if (!blk->disable_perm) {
195         return;
196     }
197 
198     blk->disable_perm = false;
199 
200     /*
201      * blk->shared_perm contains the permissions we want to share once
202      * migration is really completely done.  For now, we need to share
203      * all; but we also need to retain blk->shared_perm, which is
204      * overwritten by a successful blk_set_perm() call.  Save it and
205      * restore it below.
206      */
207     saved_shared_perm = blk->shared_perm;
208 
209     blk_set_perm(blk, blk->perm, BLK_PERM_ALL, &local_err);
210     if (local_err) {
211         error_propagate(errp, local_err);
212         blk->disable_perm = true;
213         return;
214     }
215     blk->shared_perm = saved_shared_perm;
216 
217     if (runstate_check(RUN_STATE_INMIGRATE)) {
218         /* Activation can happen when migration process is still active, for
219          * example when nbd_server_add is called during non-shared storage
220          * migration. Defer the shared_perm update to migration completion. */
221         if (!blk->vmsh) {
222             blk->vmsh = qemu_add_vm_change_state_handler(blk_vm_state_changed,
223                                                          blk);
224         }
225         return;
226     }
227 
228     blk_set_perm(blk, blk->perm, blk->shared_perm, &local_err);
229     if (local_err) {
230         error_propagate(errp, local_err);
231         blk->disable_perm = true;
232         return;
233     }
234 }
235 
236 void blk_set_force_allow_inactivate(BlockBackend *blk)
237 {
238     GLOBAL_STATE_CODE();
239     blk->force_allow_inactivate = true;
240 }
241 
242 static bool blk_can_inactivate(BlockBackend *blk)
243 {
244     /* If it is a guest device, inactivate is ok. */
245     if (blk->dev || blk_name(blk)[0]) {
246         return true;
247     }
248 
249     /* Inactivating means no more writes to the image can be done,
250      * even if those writes would be changes invisible to the
251      * guest.  For block job BBs that satisfy this, we can just allow
252      * it.  This is the case for mirror job source, which is required
253      * by libvirt non-shared block migration. */
254     if (!(blk->perm & (BLK_PERM_WRITE | BLK_PERM_WRITE_UNCHANGED))) {
255         return true;
256     }
257 
258     return blk->force_allow_inactivate;
259 }
260 
261 static int blk_root_inactivate(BdrvChild *child)
262 {
263     BlockBackend *blk = child->opaque;
264 
265     if (blk->disable_perm) {
266         return 0;
267     }
268 
269     if (!blk_can_inactivate(blk)) {
270         return -EPERM;
271     }
272 
273     blk->disable_perm = true;
274     if (blk->root) {
275         bdrv_child_try_set_perm(blk->root, 0, BLK_PERM_ALL, &error_abort);
276     }
277 
278     return 0;
279 }
280 
281 static void blk_root_attach(BdrvChild *child)
282 {
283     BlockBackend *blk = child->opaque;
284     BlockBackendAioNotifier *notifier;
285 
286     trace_blk_root_attach(child, blk, child->bs);
287 
288     QLIST_FOREACH(notifier, &blk->aio_notifiers, list) {
289         bdrv_add_aio_context_notifier(child->bs,
290                 notifier->attached_aio_context,
291                 notifier->detach_aio_context,
292                 notifier->opaque);
293     }
294 }
295 
296 static void blk_root_detach(BdrvChild *child)
297 {
298     BlockBackend *blk = child->opaque;
299     BlockBackendAioNotifier *notifier;
300 
301     trace_blk_root_detach(child, blk, child->bs);
302 
303     QLIST_FOREACH(notifier, &blk->aio_notifiers, list) {
304         bdrv_remove_aio_context_notifier(child->bs,
305                 notifier->attached_aio_context,
306                 notifier->detach_aio_context,
307                 notifier->opaque);
308     }
309 }
310 
311 static AioContext *blk_root_get_parent_aio_context(BdrvChild *c)
312 {
313     BlockBackend *blk = c->opaque;
314     IO_CODE();
315 
316     return blk_get_aio_context(blk);
317 }
318 
319 static const BdrvChildClass child_root = {
320     .inherit_options    = blk_root_inherit_options,
321 
322     .change_media       = blk_root_change_media,
323     .resize             = blk_root_resize,
324     .get_name           = blk_root_get_name,
325     .get_parent_desc    = blk_root_get_parent_desc,
326 
327     .drained_begin      = blk_root_drained_begin,
328     .drained_poll       = blk_root_drained_poll,
329     .drained_end        = blk_root_drained_end,
330 
331     .activate           = blk_root_activate,
332     .inactivate         = blk_root_inactivate,
333 
334     .attach             = blk_root_attach,
335     .detach             = blk_root_detach,
336 
337     .change_aio_ctx     = blk_root_change_aio_ctx,
338 
339     .get_parent_aio_context = blk_root_get_parent_aio_context,
340 };
341 
342 /*
343  * Create a new BlockBackend with a reference count of one.
344  *
345  * @perm is a bitmasks of BLK_PERM_* constants which describes the permissions
346  * to request for a block driver node that is attached to this BlockBackend.
347  * @shared_perm is a bitmask which describes which permissions may be granted
348  * to other users of the attached node.
349  * Both sets of permissions can be changed later using blk_set_perm().
350  *
351  * Return the new BlockBackend on success, null on failure.
352  */
353 BlockBackend *blk_new(AioContext *ctx, uint64_t perm, uint64_t shared_perm)
354 {
355     BlockBackend *blk;
356 
357     GLOBAL_STATE_CODE();
358 
359     blk = g_new0(BlockBackend, 1);
360     blk->refcnt = 1;
361     blk->ctx = ctx;
362     blk->perm = perm;
363     blk->shared_perm = shared_perm;
364     blk_set_enable_write_cache(blk, true);
365 
366     blk->on_read_error = BLOCKDEV_ON_ERROR_REPORT;
367     blk->on_write_error = BLOCKDEV_ON_ERROR_ENOSPC;
368 
369     block_acct_init(&blk->stats);
370 
371     qemu_co_queue_init(&blk->queued_requests);
372     notifier_list_init(&blk->remove_bs_notifiers);
373     notifier_list_init(&blk->insert_bs_notifiers);
374     QLIST_INIT(&blk->aio_notifiers);
375 
376     QTAILQ_INSERT_TAIL(&block_backends, blk, link);
377     return blk;
378 }
379 
380 /*
381  * Create a new BlockBackend connected to an existing BlockDriverState.
382  *
383  * @perm is a bitmasks of BLK_PERM_* constants which describes the
384  * permissions to request for @bs that is attached to this
385  * BlockBackend.  @shared_perm is a bitmask which describes which
386  * permissions may be granted to other users of the attached node.
387  * Both sets of permissions can be changed later using blk_set_perm().
388  *
389  * Return the new BlockBackend on success, null on failure.
390  */
391 BlockBackend *blk_new_with_bs(BlockDriverState *bs, uint64_t perm,
392                               uint64_t shared_perm, Error **errp)
393 {
394     BlockBackend *blk = blk_new(bdrv_get_aio_context(bs), perm, shared_perm);
395 
396     GLOBAL_STATE_CODE();
397 
398     if (blk_insert_bs(blk, bs, errp) < 0) {
399         blk_unref(blk);
400         return NULL;
401     }
402     return blk;
403 }
404 
405 /*
406  * Creates a new BlockBackend, opens a new BlockDriverState, and connects both.
407  * The new BlockBackend is in the main AioContext.
408  *
409  * Just as with bdrv_open(), after having called this function the reference to
410  * @options belongs to the block layer (even on failure).
411  *
412  * TODO: Remove @filename and @flags; it should be possible to specify a whole
413  * BDS tree just by specifying the @options QDict (or @reference,
414  * alternatively). At the time of adding this function, this is not possible,
415  * though, so callers of this function have to be able to specify @filename and
416  * @flags.
417  */
418 BlockBackend *blk_new_open(const char *filename, const char *reference,
419                            QDict *options, int flags, Error **errp)
420 {
421     BlockBackend *blk;
422     BlockDriverState *bs;
423     uint64_t perm = 0;
424     uint64_t shared = BLK_PERM_ALL;
425 
426     GLOBAL_STATE_CODE();
427 
428     /*
429      * blk_new_open() is mainly used in .bdrv_create implementations and the
430      * tools where sharing isn't a major concern because the BDS stays private
431      * and the file is generally not supposed to be used by a second process,
432      * so we just request permission according to the flags.
433      *
434      * The exceptions are xen_disk and blockdev_init(); in these cases, the
435      * caller of blk_new_open() doesn't make use of the permissions, but they
436      * shouldn't hurt either. We can still share everything here because the
437      * guest devices will add their own blockers if they can't share.
438      */
439     if ((flags & BDRV_O_NO_IO) == 0) {
440         perm |= BLK_PERM_CONSISTENT_READ;
441         if (flags & BDRV_O_RDWR) {
442             perm |= BLK_PERM_WRITE;
443         }
444     }
445     if (flags & BDRV_O_RESIZE) {
446         perm |= BLK_PERM_RESIZE;
447     }
448     if (flags & BDRV_O_NO_SHARE) {
449         shared = BLK_PERM_CONSISTENT_READ | BLK_PERM_WRITE_UNCHANGED;
450     }
451 
452     blk = blk_new(qemu_get_aio_context(), perm, shared);
453     bs = bdrv_open(filename, reference, options, flags, errp);
454     if (!bs) {
455         blk_unref(blk);
456         return NULL;
457     }
458 
459     blk->root = bdrv_root_attach_child(bs, "root", &child_root,
460                                        BDRV_CHILD_FILTERED | BDRV_CHILD_PRIMARY,
461                                        perm, shared, blk, errp);
462     if (!blk->root) {
463         blk_unref(blk);
464         return NULL;
465     }
466 
467     return blk;
468 }
469 
470 static void blk_delete(BlockBackend *blk)
471 {
472     assert(!blk->refcnt);
473     assert(!blk->name);
474     assert(!blk->dev);
475     if (blk->public.throttle_group_member.throttle_state) {
476         blk_io_limits_disable(blk);
477     }
478     if (blk->root) {
479         blk_remove_bs(blk);
480     }
481     if (blk->vmsh) {
482         qemu_del_vm_change_state_handler(blk->vmsh);
483         blk->vmsh = NULL;
484     }
485     assert(QLIST_EMPTY(&blk->remove_bs_notifiers.notifiers));
486     assert(QLIST_EMPTY(&blk->insert_bs_notifiers.notifiers));
487     assert(QLIST_EMPTY(&blk->aio_notifiers));
488     QTAILQ_REMOVE(&block_backends, blk, link);
489     drive_info_del(blk->legacy_dinfo);
490     block_acct_cleanup(&blk->stats);
491     g_free(blk);
492 }
493 
494 static void drive_info_del(DriveInfo *dinfo)
495 {
496     if (!dinfo) {
497         return;
498     }
499     qemu_opts_del(dinfo->opts);
500     g_free(dinfo);
501 }
502 
503 int blk_get_refcnt(BlockBackend *blk)
504 {
505     GLOBAL_STATE_CODE();
506     return blk ? blk->refcnt : 0;
507 }
508 
509 /*
510  * Increment @blk's reference count.
511  * @blk must not be null.
512  */
513 void blk_ref(BlockBackend *blk)
514 {
515     assert(blk->refcnt > 0);
516     GLOBAL_STATE_CODE();
517     blk->refcnt++;
518 }
519 
520 /*
521  * Decrement @blk's reference count.
522  * If this drops it to zero, destroy @blk.
523  * For convenience, do nothing if @blk is null.
524  */
525 void blk_unref(BlockBackend *blk)
526 {
527     GLOBAL_STATE_CODE();
528     if (blk) {
529         assert(blk->refcnt > 0);
530         if (blk->refcnt > 1) {
531             blk->refcnt--;
532         } else {
533             blk_drain(blk);
534             /* blk_drain() cannot resurrect blk, nobody held a reference */
535             assert(blk->refcnt == 1);
536             blk->refcnt = 0;
537             blk_delete(blk);
538         }
539     }
540 }
541 
542 /*
543  * Behaves similarly to blk_next() but iterates over all BlockBackends, even the
544  * ones which are hidden (i.e. are not referenced by the monitor).
545  */
546 BlockBackend *blk_all_next(BlockBackend *blk)
547 {
548     GLOBAL_STATE_CODE();
549     return blk ? QTAILQ_NEXT(blk, link)
550                : QTAILQ_FIRST(&block_backends);
551 }
552 
553 void blk_remove_all_bs(void)
554 {
555     BlockBackend *blk = NULL;
556 
557     GLOBAL_STATE_CODE();
558 
559     while ((blk = blk_all_next(blk)) != NULL) {
560         AioContext *ctx = blk_get_aio_context(blk);
561 
562         aio_context_acquire(ctx);
563         if (blk->root) {
564             blk_remove_bs(blk);
565         }
566         aio_context_release(ctx);
567     }
568 }
569 
570 /*
571  * Return the monitor-owned BlockBackend after @blk.
572  * If @blk is null, return the first one.
573  * Else, return @blk's next sibling, which may be null.
574  *
575  * To iterate over all BlockBackends, do
576  * for (blk = blk_next(NULL); blk; blk = blk_next(blk)) {
577  *     ...
578  * }
579  */
580 BlockBackend *blk_next(BlockBackend *blk)
581 {
582     GLOBAL_STATE_CODE();
583     return blk ? QTAILQ_NEXT(blk, monitor_link)
584                : QTAILQ_FIRST(&monitor_block_backends);
585 }
586 
587 /* Iterates over all top-level BlockDriverStates, i.e. BDSs that are owned by
588  * the monitor or attached to a BlockBackend */
589 BlockDriverState *bdrv_next(BdrvNextIterator *it)
590 {
591     BlockDriverState *bs, *old_bs;
592 
593     /* Must be called from the main loop */
594     assert(qemu_get_current_aio_context() == qemu_get_aio_context());
595 
596     /* First, return all root nodes of BlockBackends. In order to avoid
597      * returning a BDS twice when multiple BBs refer to it, we only return it
598      * if the BB is the first one in the parent list of the BDS. */
599     if (it->phase == BDRV_NEXT_BACKEND_ROOTS) {
600         BlockBackend *old_blk = it->blk;
601 
602         old_bs = old_blk ? blk_bs(old_blk) : NULL;
603 
604         do {
605             it->blk = blk_all_next(it->blk);
606             bs = it->blk ? blk_bs(it->blk) : NULL;
607         } while (it->blk && (bs == NULL || bdrv_first_blk(bs) != it->blk));
608 
609         if (it->blk) {
610             blk_ref(it->blk);
611         }
612         blk_unref(old_blk);
613 
614         if (bs) {
615             bdrv_ref(bs);
616             bdrv_unref(old_bs);
617             return bs;
618         }
619         it->phase = BDRV_NEXT_MONITOR_OWNED;
620     } else {
621         old_bs = it->bs;
622     }
623 
624     /* Then return the monitor-owned BDSes without a BB attached. Ignore all
625      * BDSes that are attached to a BlockBackend here; they have been handled
626      * by the above block already */
627     do {
628         it->bs = bdrv_next_monitor_owned(it->bs);
629         bs = it->bs;
630     } while (bs && bdrv_has_blk(bs));
631 
632     if (bs) {
633         bdrv_ref(bs);
634     }
635     bdrv_unref(old_bs);
636 
637     return bs;
638 }
639 
640 static void bdrv_next_reset(BdrvNextIterator *it)
641 {
642     *it = (BdrvNextIterator) {
643         .phase = BDRV_NEXT_BACKEND_ROOTS,
644     };
645 }
646 
647 BlockDriverState *bdrv_first(BdrvNextIterator *it)
648 {
649     GLOBAL_STATE_CODE();
650     bdrv_next_reset(it);
651     return bdrv_next(it);
652 }
653 
654 /* Must be called when aborting a bdrv_next() iteration before
655  * bdrv_next() returns NULL */
656 void bdrv_next_cleanup(BdrvNextIterator *it)
657 {
658     /* Must be called from the main loop */
659     assert(qemu_get_current_aio_context() == qemu_get_aio_context());
660 
661     if (it->phase == BDRV_NEXT_BACKEND_ROOTS) {
662         if (it->blk) {
663             bdrv_unref(blk_bs(it->blk));
664             blk_unref(it->blk);
665         }
666     } else {
667         bdrv_unref(it->bs);
668     }
669 
670     bdrv_next_reset(it);
671 }
672 
673 /*
674  * Add a BlockBackend into the list of backends referenced by the monitor, with
675  * the given @name acting as the handle for the monitor.
676  * Strictly for use by blockdev.c.
677  *
678  * @name must not be null or empty.
679  *
680  * Returns true on success and false on failure. In the latter case, an Error
681  * object is returned through @errp.
682  */
683 bool monitor_add_blk(BlockBackend *blk, const char *name, Error **errp)
684 {
685     assert(!blk->name);
686     assert(name && name[0]);
687     GLOBAL_STATE_CODE();
688 
689     if (!id_wellformed(name)) {
690         error_setg(errp, "Invalid device name");
691         return false;
692     }
693     if (blk_by_name(name)) {
694         error_setg(errp, "Device with id '%s' already exists", name);
695         return false;
696     }
697     if (bdrv_find_node(name)) {
698         error_setg(errp,
699                    "Device name '%s' conflicts with an existing node name",
700                    name);
701         return false;
702     }
703 
704     blk->name = g_strdup(name);
705     QTAILQ_INSERT_TAIL(&monitor_block_backends, blk, monitor_link);
706     return true;
707 }
708 
709 /*
710  * Remove a BlockBackend from the list of backends referenced by the monitor.
711  * Strictly for use by blockdev.c.
712  */
713 void monitor_remove_blk(BlockBackend *blk)
714 {
715     GLOBAL_STATE_CODE();
716 
717     if (!blk->name) {
718         return;
719     }
720 
721     QTAILQ_REMOVE(&monitor_block_backends, blk, monitor_link);
722     g_free(blk->name);
723     blk->name = NULL;
724 }
725 
726 /*
727  * Return @blk's name, a non-null string.
728  * Returns an empty string iff @blk is not referenced by the monitor.
729  */
730 const char *blk_name(const BlockBackend *blk)
731 {
732     IO_CODE();
733     return blk->name ?: "";
734 }
735 
736 /*
737  * Return the BlockBackend with name @name if it exists, else null.
738  * @name must not be null.
739  */
740 BlockBackend *blk_by_name(const char *name)
741 {
742     BlockBackend *blk = NULL;
743 
744     GLOBAL_STATE_CODE();
745     assert(name);
746     while ((blk = blk_next(blk)) != NULL) {
747         if (!strcmp(name, blk->name)) {
748             return blk;
749         }
750     }
751     return NULL;
752 }
753 
754 /*
755  * Return the BlockDriverState attached to @blk if any, else null.
756  */
757 BlockDriverState *blk_bs(BlockBackend *blk)
758 {
759     IO_CODE();
760     return blk->root ? blk->root->bs : NULL;
761 }
762 
763 static BlockBackend *bdrv_first_blk(BlockDriverState *bs)
764 {
765     BdrvChild *child;
766 
767     GLOBAL_STATE_CODE();
768 
769     QLIST_FOREACH(child, &bs->parents, next_parent) {
770         if (child->klass == &child_root) {
771             return child->opaque;
772         }
773     }
774 
775     return NULL;
776 }
777 
778 /*
779  * Returns true if @bs has an associated BlockBackend.
780  */
781 bool bdrv_has_blk(BlockDriverState *bs)
782 {
783     GLOBAL_STATE_CODE();
784     return bdrv_first_blk(bs) != NULL;
785 }
786 
787 /*
788  * Returns true if @bs has only BlockBackends as parents.
789  */
790 bool bdrv_is_root_node(BlockDriverState *bs)
791 {
792     BdrvChild *c;
793 
794     GLOBAL_STATE_CODE();
795     QLIST_FOREACH(c, &bs->parents, next_parent) {
796         if (c->klass != &child_root) {
797             return false;
798         }
799     }
800 
801     return true;
802 }
803 
804 /*
805  * Return @blk's DriveInfo if any, else null.
806  */
807 DriveInfo *blk_legacy_dinfo(BlockBackend *blk)
808 {
809     GLOBAL_STATE_CODE();
810     return blk->legacy_dinfo;
811 }
812 
813 /*
814  * Set @blk's DriveInfo to @dinfo, and return it.
815  * @blk must not have a DriveInfo set already.
816  * No other BlockBackend may have the same DriveInfo set.
817  */
818 DriveInfo *blk_set_legacy_dinfo(BlockBackend *blk, DriveInfo *dinfo)
819 {
820     assert(!blk->legacy_dinfo);
821     GLOBAL_STATE_CODE();
822     return blk->legacy_dinfo = dinfo;
823 }
824 
825 /*
826  * Return the BlockBackend with DriveInfo @dinfo.
827  * It must exist.
828  */
829 BlockBackend *blk_by_legacy_dinfo(DriveInfo *dinfo)
830 {
831     BlockBackend *blk = NULL;
832     GLOBAL_STATE_CODE();
833 
834     while ((blk = blk_next(blk)) != NULL) {
835         if (blk->legacy_dinfo == dinfo) {
836             return blk;
837         }
838     }
839     abort();
840 }
841 
842 /*
843  * Returns a pointer to the publicly accessible fields of @blk.
844  */
845 BlockBackendPublic *blk_get_public(BlockBackend *blk)
846 {
847     GLOBAL_STATE_CODE();
848     return &blk->public;
849 }
850 
851 /*
852  * Returns a BlockBackend given the associated @public fields.
853  */
854 BlockBackend *blk_by_public(BlockBackendPublic *public)
855 {
856     GLOBAL_STATE_CODE();
857     return container_of(public, BlockBackend, public);
858 }
859 
860 /*
861  * Disassociates the currently associated BlockDriverState from @blk.
862  */
863 void blk_remove_bs(BlockBackend *blk)
864 {
865     ThrottleGroupMember *tgm = &blk->public.throttle_group_member;
866     BdrvChild *root;
867 
868     GLOBAL_STATE_CODE();
869 
870     notifier_list_notify(&blk->remove_bs_notifiers, blk);
871     if (tgm->throttle_state) {
872         BlockDriverState *bs = blk_bs(blk);
873 
874         /*
875          * Take a ref in case blk_bs() changes across bdrv_drained_begin(), for
876          * example, if a temporary filter node is removed by a blockjob.
877          */
878         bdrv_ref(bs);
879         bdrv_drained_begin(bs);
880         throttle_group_detach_aio_context(tgm);
881         throttle_group_attach_aio_context(tgm, qemu_get_aio_context());
882         bdrv_drained_end(bs);
883         bdrv_unref(bs);
884     }
885 
886     blk_update_root_state(blk);
887 
888     /* bdrv_root_unref_child() will cause blk->root to become stale and may
889      * switch to a completion coroutine later on. Let's drain all I/O here
890      * to avoid that and a potential QEMU crash.
891      */
892     blk_drain(blk);
893     root = blk->root;
894     blk->root = NULL;
895     bdrv_root_unref_child(root);
896 }
897 
898 /*
899  * Associates a new BlockDriverState with @blk.
900  */
901 int blk_insert_bs(BlockBackend *blk, BlockDriverState *bs, Error **errp)
902 {
903     ThrottleGroupMember *tgm = &blk->public.throttle_group_member;
904     GLOBAL_STATE_CODE();
905     bdrv_ref(bs);
906     blk->root = bdrv_root_attach_child(bs, "root", &child_root,
907                                        BDRV_CHILD_FILTERED | BDRV_CHILD_PRIMARY,
908                                        blk->perm, blk->shared_perm,
909                                        blk, errp);
910     if (blk->root == NULL) {
911         return -EPERM;
912     }
913 
914     notifier_list_notify(&blk->insert_bs_notifiers, blk);
915     if (tgm->throttle_state) {
916         throttle_group_detach_aio_context(tgm);
917         throttle_group_attach_aio_context(tgm, bdrv_get_aio_context(bs));
918     }
919 
920     return 0;
921 }
922 
923 /*
924  * Change BlockDriverState associated with @blk.
925  */
926 int blk_replace_bs(BlockBackend *blk, BlockDriverState *new_bs, Error **errp)
927 {
928     GLOBAL_STATE_CODE();
929     return bdrv_replace_child_bs(blk->root, new_bs, errp);
930 }
931 
932 /*
933  * Sets the permission bitmasks that the user of the BlockBackend needs.
934  */
935 int blk_set_perm(BlockBackend *blk, uint64_t perm, uint64_t shared_perm,
936                  Error **errp)
937 {
938     int ret;
939     GLOBAL_STATE_CODE();
940 
941     if (blk->root && !blk->disable_perm) {
942         ret = bdrv_child_try_set_perm(blk->root, perm, shared_perm, errp);
943         if (ret < 0) {
944             return ret;
945         }
946     }
947 
948     blk->perm = perm;
949     blk->shared_perm = shared_perm;
950 
951     return 0;
952 }
953 
954 void blk_get_perm(BlockBackend *blk, uint64_t *perm, uint64_t *shared_perm)
955 {
956     GLOBAL_STATE_CODE();
957     *perm = blk->perm;
958     *shared_perm = blk->shared_perm;
959 }
960 
961 /*
962  * Attach device model @dev to @blk.
963  * Return 0 on success, -EBUSY when a device model is attached already.
964  */
965 int blk_attach_dev(BlockBackend *blk, DeviceState *dev)
966 {
967     GLOBAL_STATE_CODE();
968     if (blk->dev) {
969         return -EBUSY;
970     }
971 
972     /* While migration is still incoming, we don't need to apply the
973      * permissions of guest device BlockBackends. We might still have a block
974      * job or NBD server writing to the image for storage migration. */
975     if (runstate_check(RUN_STATE_INMIGRATE)) {
976         blk->disable_perm = true;
977     }
978 
979     blk_ref(blk);
980     blk->dev = dev;
981     blk_iostatus_reset(blk);
982 
983     return 0;
984 }
985 
986 /*
987  * Detach device model @dev from @blk.
988  * @dev must be currently attached to @blk.
989  */
990 void blk_detach_dev(BlockBackend *blk, DeviceState *dev)
991 {
992     assert(blk->dev == dev);
993     GLOBAL_STATE_CODE();
994     blk->dev = NULL;
995     blk->dev_ops = NULL;
996     blk->dev_opaque = NULL;
997     blk_set_perm(blk, 0, BLK_PERM_ALL, &error_abort);
998     blk_unref(blk);
999 }
1000 
1001 /*
1002  * Return the device model attached to @blk if any, else null.
1003  */
1004 DeviceState *blk_get_attached_dev(BlockBackend *blk)
1005 {
1006     GLOBAL_STATE_CODE();
1007     return blk->dev;
1008 }
1009 
1010 /* Return the qdev ID, or if no ID is assigned the QOM path, of the block
1011  * device attached to the BlockBackend. */
1012 char *blk_get_attached_dev_id(BlockBackend *blk)
1013 {
1014     DeviceState *dev = blk->dev;
1015     IO_CODE();
1016 
1017     if (!dev) {
1018         return g_strdup("");
1019     } else if (dev->id) {
1020         return g_strdup(dev->id);
1021     }
1022 
1023     return object_get_canonical_path(OBJECT(dev)) ?: g_strdup("");
1024 }
1025 
1026 /*
1027  * Return the BlockBackend which has the device model @dev attached if it
1028  * exists, else null.
1029  *
1030  * @dev must not be null.
1031  */
1032 BlockBackend *blk_by_dev(void *dev)
1033 {
1034     BlockBackend *blk = NULL;
1035 
1036     GLOBAL_STATE_CODE();
1037 
1038     assert(dev != NULL);
1039     while ((blk = blk_all_next(blk)) != NULL) {
1040         if (blk->dev == dev) {
1041             return blk;
1042         }
1043     }
1044     return NULL;
1045 }
1046 
1047 /*
1048  * Set @blk's device model callbacks to @ops.
1049  * @opaque is the opaque argument to pass to the callbacks.
1050  * This is for use by device models.
1051  */
1052 void blk_set_dev_ops(BlockBackend *blk, const BlockDevOps *ops,
1053                      void *opaque)
1054 {
1055     GLOBAL_STATE_CODE();
1056     blk->dev_ops = ops;
1057     blk->dev_opaque = opaque;
1058 
1059     /* Are we currently quiesced? Should we enforce this right now? */
1060     if (blk->quiesce_counter && ops && ops->drained_begin) {
1061         ops->drained_begin(opaque);
1062     }
1063 }
1064 
1065 /*
1066  * Notify @blk's attached device model of media change.
1067  *
1068  * If @load is true, notify of media load. This action can fail, meaning that
1069  * the medium cannot be loaded. @errp is set then.
1070  *
1071  * If @load is false, notify of media eject. This can never fail.
1072  *
1073  * Also send DEVICE_TRAY_MOVED events as appropriate.
1074  */
1075 void blk_dev_change_media_cb(BlockBackend *blk, bool load, Error **errp)
1076 {
1077     GLOBAL_STATE_CODE();
1078     if (blk->dev_ops && blk->dev_ops->change_media_cb) {
1079         bool tray_was_open, tray_is_open;
1080         Error *local_err = NULL;
1081 
1082         tray_was_open = blk_dev_is_tray_open(blk);
1083         blk->dev_ops->change_media_cb(blk->dev_opaque, load, &local_err);
1084         if (local_err) {
1085             assert(load == true);
1086             error_propagate(errp, local_err);
1087             return;
1088         }
1089         tray_is_open = blk_dev_is_tray_open(blk);
1090 
1091         if (tray_was_open != tray_is_open) {
1092             char *id = blk_get_attached_dev_id(blk);
1093             qapi_event_send_device_tray_moved(blk_name(blk), id, tray_is_open);
1094             g_free(id);
1095         }
1096     }
1097 }
1098 
1099 static void blk_root_change_media(BdrvChild *child, bool load)
1100 {
1101     blk_dev_change_media_cb(child->opaque, load, NULL);
1102 }
1103 
1104 /*
1105  * Does @blk's attached device model have removable media?
1106  * %true if no device model is attached.
1107  */
1108 bool blk_dev_has_removable_media(BlockBackend *blk)
1109 {
1110     GLOBAL_STATE_CODE();
1111     return !blk->dev || (blk->dev_ops && blk->dev_ops->change_media_cb);
1112 }
1113 
1114 /*
1115  * Does @blk's attached device model have a tray?
1116  */
1117 bool blk_dev_has_tray(BlockBackend *blk)
1118 {
1119     IO_CODE();
1120     return blk->dev_ops && blk->dev_ops->is_tray_open;
1121 }
1122 
1123 /*
1124  * Notify @blk's attached device model of a media eject request.
1125  * If @force is true, the medium is about to be yanked out forcefully.
1126  */
1127 void blk_dev_eject_request(BlockBackend *blk, bool force)
1128 {
1129     GLOBAL_STATE_CODE();
1130     if (blk->dev_ops && blk->dev_ops->eject_request_cb) {
1131         blk->dev_ops->eject_request_cb(blk->dev_opaque, force);
1132     }
1133 }
1134 
1135 /*
1136  * Does @blk's attached device model have a tray, and is it open?
1137  */
1138 bool blk_dev_is_tray_open(BlockBackend *blk)
1139 {
1140     IO_CODE();
1141     if (blk_dev_has_tray(blk)) {
1142         return blk->dev_ops->is_tray_open(blk->dev_opaque);
1143     }
1144     return false;
1145 }
1146 
1147 /*
1148  * Does @blk's attached device model have the medium locked?
1149  * %false if the device model has no such lock.
1150  */
1151 bool blk_dev_is_medium_locked(BlockBackend *blk)
1152 {
1153     GLOBAL_STATE_CODE();
1154     if (blk->dev_ops && blk->dev_ops->is_medium_locked) {
1155         return blk->dev_ops->is_medium_locked(blk->dev_opaque);
1156     }
1157     return false;
1158 }
1159 
1160 /*
1161  * Notify @blk's attached device model of a backend size change.
1162  */
1163 static void blk_root_resize(BdrvChild *child)
1164 {
1165     BlockBackend *blk = child->opaque;
1166 
1167     if (blk->dev_ops && blk->dev_ops->resize_cb) {
1168         blk->dev_ops->resize_cb(blk->dev_opaque);
1169     }
1170 }
1171 
1172 void blk_iostatus_enable(BlockBackend *blk)
1173 {
1174     GLOBAL_STATE_CODE();
1175     blk->iostatus_enabled = true;
1176     blk->iostatus = BLOCK_DEVICE_IO_STATUS_OK;
1177 }
1178 
1179 /* The I/O status is only enabled if the drive explicitly
1180  * enables it _and_ the VM is configured to stop on errors */
1181 bool blk_iostatus_is_enabled(const BlockBackend *blk)
1182 {
1183     IO_CODE();
1184     return (blk->iostatus_enabled &&
1185            (blk->on_write_error == BLOCKDEV_ON_ERROR_ENOSPC ||
1186             blk->on_write_error == BLOCKDEV_ON_ERROR_STOP   ||
1187             blk->on_read_error == BLOCKDEV_ON_ERROR_STOP));
1188 }
1189 
1190 BlockDeviceIoStatus blk_iostatus(const BlockBackend *blk)
1191 {
1192     GLOBAL_STATE_CODE();
1193     return blk->iostatus;
1194 }
1195 
1196 void blk_iostatus_disable(BlockBackend *blk)
1197 {
1198     GLOBAL_STATE_CODE();
1199     blk->iostatus_enabled = false;
1200 }
1201 
1202 void blk_iostatus_reset(BlockBackend *blk)
1203 {
1204     GLOBAL_STATE_CODE();
1205     if (blk_iostatus_is_enabled(blk)) {
1206         blk->iostatus = BLOCK_DEVICE_IO_STATUS_OK;
1207     }
1208 }
1209 
1210 void blk_iostatus_set_err(BlockBackend *blk, int error)
1211 {
1212     IO_CODE();
1213     assert(blk_iostatus_is_enabled(blk));
1214     if (blk->iostatus == BLOCK_DEVICE_IO_STATUS_OK) {
1215         blk->iostatus = error == ENOSPC ? BLOCK_DEVICE_IO_STATUS_NOSPACE :
1216                                           BLOCK_DEVICE_IO_STATUS_FAILED;
1217     }
1218 }
1219 
1220 void blk_set_allow_write_beyond_eof(BlockBackend *blk, bool allow)
1221 {
1222     IO_CODE();
1223     blk->allow_write_beyond_eof = allow;
1224 }
1225 
1226 void blk_set_allow_aio_context_change(BlockBackend *blk, bool allow)
1227 {
1228     IO_CODE();
1229     blk->allow_aio_context_change = allow;
1230 }
1231 
1232 void blk_set_disable_request_queuing(BlockBackend *blk, bool disable)
1233 {
1234     IO_CODE();
1235     blk->disable_request_queuing = disable;
1236 }
1237 
1238 static int coroutine_fn GRAPH_RDLOCK
1239 blk_check_byte_request(BlockBackend *blk, int64_t offset, int64_t bytes)
1240 {
1241     int64_t len;
1242 
1243     if (bytes < 0) {
1244         return -EIO;
1245     }
1246 
1247     if (!blk_co_is_available(blk)) {
1248         return -ENOMEDIUM;
1249     }
1250 
1251     if (offset < 0) {
1252         return -EIO;
1253     }
1254 
1255     if (!blk->allow_write_beyond_eof) {
1256         len = bdrv_co_getlength(blk_bs(blk));
1257         if (len < 0) {
1258             return len;
1259         }
1260 
1261         if (offset > len || len - offset < bytes) {
1262             return -EIO;
1263         }
1264     }
1265 
1266     return 0;
1267 }
1268 
1269 /* To be called between exactly one pair of blk_inc/dec_in_flight() */
1270 static void coroutine_fn blk_wait_while_drained(BlockBackend *blk)
1271 {
1272     assert(blk->in_flight > 0);
1273 
1274     if (blk->quiesce_counter && !blk->disable_request_queuing) {
1275         blk_dec_in_flight(blk);
1276         qemu_co_queue_wait(&blk->queued_requests, NULL);
1277         blk_inc_in_flight(blk);
1278     }
1279 }
1280 
1281 /* To be called between exactly one pair of blk_inc/dec_in_flight() */
1282 static int coroutine_fn
1283 blk_co_do_preadv_part(BlockBackend *blk, int64_t offset, int64_t bytes,
1284                       QEMUIOVector *qiov, size_t qiov_offset,
1285                       BdrvRequestFlags flags)
1286 {
1287     int ret;
1288     BlockDriverState *bs;
1289     IO_CODE();
1290 
1291     blk_wait_while_drained(blk);
1292     GRAPH_RDLOCK_GUARD();
1293 
1294     /* Call blk_bs() only after waiting, the graph may have changed */
1295     bs = blk_bs(blk);
1296     trace_blk_co_preadv(blk, bs, offset, bytes, flags);
1297 
1298     ret = blk_check_byte_request(blk, offset, bytes);
1299     if (ret < 0) {
1300         return ret;
1301     }
1302 
1303     bdrv_inc_in_flight(bs);
1304 
1305     /* throttling disk I/O */
1306     if (blk->public.throttle_group_member.throttle_state) {
1307         throttle_group_co_io_limits_intercept(&blk->public.throttle_group_member,
1308                 bytes, false);
1309     }
1310 
1311     ret = bdrv_co_preadv_part(blk->root, offset, bytes, qiov, qiov_offset,
1312                               flags);
1313     bdrv_dec_in_flight(bs);
1314     return ret;
1315 }
1316 
1317 int coroutine_fn blk_co_pread(BlockBackend *blk, int64_t offset, int64_t bytes,
1318                               void *buf, BdrvRequestFlags flags)
1319 {
1320     QEMUIOVector qiov = QEMU_IOVEC_INIT_BUF(qiov, buf, bytes);
1321     IO_OR_GS_CODE();
1322 
1323     assert(bytes <= SIZE_MAX);
1324 
1325     return blk_co_preadv(blk, offset, bytes, &qiov, flags);
1326 }
1327 
1328 int coroutine_fn blk_co_preadv(BlockBackend *blk, int64_t offset,
1329                                int64_t bytes, QEMUIOVector *qiov,
1330                                BdrvRequestFlags flags)
1331 {
1332     int ret;
1333     IO_OR_GS_CODE();
1334 
1335     blk_inc_in_flight(blk);
1336     ret = blk_co_do_preadv_part(blk, offset, bytes, qiov, 0, flags);
1337     blk_dec_in_flight(blk);
1338 
1339     return ret;
1340 }
1341 
1342 int coroutine_fn blk_co_preadv_part(BlockBackend *blk, int64_t offset,
1343                                     int64_t bytes, QEMUIOVector *qiov,
1344                                     size_t qiov_offset, BdrvRequestFlags flags)
1345 {
1346     int ret;
1347     IO_OR_GS_CODE();
1348 
1349     blk_inc_in_flight(blk);
1350     ret = blk_co_do_preadv_part(blk, offset, bytes, qiov, qiov_offset, flags);
1351     blk_dec_in_flight(blk);
1352 
1353     return ret;
1354 }
1355 
1356 /* To be called between exactly one pair of blk_inc/dec_in_flight() */
1357 static int coroutine_fn
1358 blk_co_do_pwritev_part(BlockBackend *blk, int64_t offset, int64_t bytes,
1359                        QEMUIOVector *qiov, size_t qiov_offset,
1360                        BdrvRequestFlags flags)
1361 {
1362     int ret;
1363     BlockDriverState *bs;
1364     IO_CODE();
1365 
1366     blk_wait_while_drained(blk);
1367     GRAPH_RDLOCK_GUARD();
1368 
1369     /* Call blk_bs() only after waiting, the graph may have changed */
1370     bs = blk_bs(blk);
1371     trace_blk_co_pwritev(blk, bs, offset, bytes, flags);
1372 
1373     ret = blk_check_byte_request(blk, offset, bytes);
1374     if (ret < 0) {
1375         return ret;
1376     }
1377 
1378     bdrv_inc_in_flight(bs);
1379     /* throttling disk I/O */
1380     if (blk->public.throttle_group_member.throttle_state) {
1381         throttle_group_co_io_limits_intercept(&blk->public.throttle_group_member,
1382                 bytes, true);
1383     }
1384 
1385     if (!blk->enable_write_cache) {
1386         flags |= BDRV_REQ_FUA;
1387     }
1388 
1389     ret = bdrv_co_pwritev_part(blk->root, offset, bytes, qiov, qiov_offset,
1390                                flags);
1391     bdrv_dec_in_flight(bs);
1392     return ret;
1393 }
1394 
1395 int coroutine_fn blk_co_pwritev_part(BlockBackend *blk, int64_t offset,
1396                                      int64_t bytes,
1397                                      QEMUIOVector *qiov, size_t qiov_offset,
1398                                      BdrvRequestFlags flags)
1399 {
1400     int ret;
1401     IO_OR_GS_CODE();
1402 
1403     blk_inc_in_flight(blk);
1404     ret = blk_co_do_pwritev_part(blk, offset, bytes, qiov, qiov_offset, flags);
1405     blk_dec_in_flight(blk);
1406 
1407     return ret;
1408 }
1409 
1410 int coroutine_fn blk_co_pwrite(BlockBackend *blk, int64_t offset, int64_t bytes,
1411                                const void *buf, BdrvRequestFlags flags)
1412 {
1413     QEMUIOVector qiov = QEMU_IOVEC_INIT_BUF(qiov, buf, bytes);
1414     IO_OR_GS_CODE();
1415 
1416     assert(bytes <= SIZE_MAX);
1417 
1418     return blk_co_pwritev(blk, offset, bytes, &qiov, flags);
1419 }
1420 
1421 int coroutine_fn blk_co_pwritev(BlockBackend *blk, int64_t offset,
1422                                 int64_t bytes, QEMUIOVector *qiov,
1423                                 BdrvRequestFlags flags)
1424 {
1425     IO_OR_GS_CODE();
1426     return blk_co_pwritev_part(blk, offset, bytes, qiov, 0, flags);
1427 }
1428 
1429 int coroutine_fn blk_co_block_status_above(BlockBackend *blk,
1430                                            BlockDriverState *base,
1431                                            int64_t offset, int64_t bytes,
1432                                            int64_t *pnum, int64_t *map,
1433                                            BlockDriverState **file)
1434 {
1435     IO_CODE();
1436     GRAPH_RDLOCK_GUARD();
1437     return bdrv_co_block_status_above(blk_bs(blk), base, offset, bytes, pnum,
1438                                       map, file);
1439 }
1440 
1441 int coroutine_fn blk_co_is_allocated_above(BlockBackend *blk,
1442                                            BlockDriverState *base,
1443                                            bool include_base, int64_t offset,
1444                                            int64_t bytes, int64_t *pnum)
1445 {
1446     IO_CODE();
1447     GRAPH_RDLOCK_GUARD();
1448     return bdrv_co_is_allocated_above(blk_bs(blk), base, include_base, offset,
1449                                       bytes, pnum);
1450 }
1451 
1452 typedef struct BlkRwCo {
1453     BlockBackend *blk;
1454     int64_t offset;
1455     void *iobuf;
1456     int ret;
1457     BdrvRequestFlags flags;
1458 } BlkRwCo;
1459 
1460 int blk_make_zero(BlockBackend *blk, BdrvRequestFlags flags)
1461 {
1462     GLOBAL_STATE_CODE();
1463     return bdrv_make_zero(blk->root, flags);
1464 }
1465 
1466 void blk_inc_in_flight(BlockBackend *blk)
1467 {
1468     IO_CODE();
1469     qatomic_inc(&blk->in_flight);
1470 }
1471 
1472 void blk_dec_in_flight(BlockBackend *blk)
1473 {
1474     IO_CODE();
1475     qatomic_dec(&blk->in_flight);
1476     aio_wait_kick();
1477 }
1478 
1479 static void error_callback_bh(void *opaque)
1480 {
1481     struct BlockBackendAIOCB *acb = opaque;
1482 
1483     blk_dec_in_flight(acb->blk);
1484     acb->common.cb(acb->common.opaque, acb->ret);
1485     qemu_aio_unref(acb);
1486 }
1487 
1488 BlockAIOCB *blk_abort_aio_request(BlockBackend *blk,
1489                                   BlockCompletionFunc *cb,
1490                                   void *opaque, int ret)
1491 {
1492     struct BlockBackendAIOCB *acb;
1493     IO_CODE();
1494 
1495     blk_inc_in_flight(blk);
1496     acb = blk_aio_get(&block_backend_aiocb_info, blk, cb, opaque);
1497     acb->blk = blk;
1498     acb->ret = ret;
1499 
1500     replay_bh_schedule_oneshot_event(blk_get_aio_context(blk),
1501                                      error_callback_bh, acb);
1502     return &acb->common;
1503 }
1504 
1505 typedef struct BlkAioEmAIOCB {
1506     BlockAIOCB common;
1507     BlkRwCo rwco;
1508     int64_t bytes;
1509     bool has_returned;
1510 } BlkAioEmAIOCB;
1511 
1512 static AioContext *blk_aio_em_aiocb_get_aio_context(BlockAIOCB *acb_)
1513 {
1514     BlkAioEmAIOCB *acb = container_of(acb_, BlkAioEmAIOCB, common);
1515 
1516     return blk_get_aio_context(acb->rwco.blk);
1517 }
1518 
1519 static const AIOCBInfo blk_aio_em_aiocb_info = {
1520     .aiocb_size         = sizeof(BlkAioEmAIOCB),
1521     .get_aio_context    = blk_aio_em_aiocb_get_aio_context,
1522 };
1523 
1524 static void blk_aio_complete(BlkAioEmAIOCB *acb)
1525 {
1526     if (acb->has_returned) {
1527         acb->common.cb(acb->common.opaque, acb->rwco.ret);
1528         blk_dec_in_flight(acb->rwco.blk);
1529         qemu_aio_unref(acb);
1530     }
1531 }
1532 
1533 static void blk_aio_complete_bh(void *opaque)
1534 {
1535     BlkAioEmAIOCB *acb = opaque;
1536     assert(acb->has_returned);
1537     blk_aio_complete(acb);
1538 }
1539 
1540 static BlockAIOCB *blk_aio_prwv(BlockBackend *blk, int64_t offset,
1541                                 int64_t bytes,
1542                                 void *iobuf, CoroutineEntry co_entry,
1543                                 BdrvRequestFlags flags,
1544                                 BlockCompletionFunc *cb, void *opaque)
1545 {
1546     BlkAioEmAIOCB *acb;
1547     Coroutine *co;
1548 
1549     blk_inc_in_flight(blk);
1550     acb = blk_aio_get(&blk_aio_em_aiocb_info, blk, cb, opaque);
1551     acb->rwco = (BlkRwCo) {
1552         .blk    = blk,
1553         .offset = offset,
1554         .iobuf  = iobuf,
1555         .flags  = flags,
1556         .ret    = NOT_DONE,
1557     };
1558     acb->bytes = bytes;
1559     acb->has_returned = false;
1560 
1561     co = qemu_coroutine_create(co_entry, acb);
1562     aio_co_enter(blk_get_aio_context(blk), co);
1563 
1564     acb->has_returned = true;
1565     if (acb->rwco.ret != NOT_DONE) {
1566         replay_bh_schedule_oneshot_event(blk_get_aio_context(blk),
1567                                          blk_aio_complete_bh, acb);
1568     }
1569 
1570     return &acb->common;
1571 }
1572 
1573 static void coroutine_fn blk_aio_read_entry(void *opaque)
1574 {
1575     BlkAioEmAIOCB *acb = opaque;
1576     BlkRwCo *rwco = &acb->rwco;
1577     QEMUIOVector *qiov = rwco->iobuf;
1578 
1579     assert(qiov->size == acb->bytes);
1580     rwco->ret = blk_co_do_preadv_part(rwco->blk, rwco->offset, acb->bytes, qiov,
1581                                       0, rwco->flags);
1582     blk_aio_complete(acb);
1583 }
1584 
1585 static void coroutine_fn blk_aio_write_entry(void *opaque)
1586 {
1587     BlkAioEmAIOCB *acb = opaque;
1588     BlkRwCo *rwco = &acb->rwco;
1589     QEMUIOVector *qiov = rwco->iobuf;
1590 
1591     assert(!qiov || qiov->size == acb->bytes);
1592     rwco->ret = blk_co_do_pwritev_part(rwco->blk, rwco->offset, acb->bytes,
1593                                        qiov, 0, rwco->flags);
1594     blk_aio_complete(acb);
1595 }
1596 
1597 BlockAIOCB *blk_aio_pwrite_zeroes(BlockBackend *blk, int64_t offset,
1598                                   int64_t bytes, BdrvRequestFlags flags,
1599                                   BlockCompletionFunc *cb, void *opaque)
1600 {
1601     IO_CODE();
1602     return blk_aio_prwv(blk, offset, bytes, NULL, blk_aio_write_entry,
1603                         flags | BDRV_REQ_ZERO_WRITE, cb, opaque);
1604 }
1605 
1606 int64_t coroutine_fn blk_co_getlength(BlockBackend *blk)
1607 {
1608     IO_CODE();
1609     GRAPH_RDLOCK_GUARD();
1610 
1611     if (!blk_co_is_available(blk)) {
1612         return -ENOMEDIUM;
1613     }
1614 
1615     return bdrv_co_getlength(blk_bs(blk));
1616 }
1617 
1618 int64_t coroutine_fn blk_co_nb_sectors(BlockBackend *blk)
1619 {
1620     BlockDriverState *bs = blk_bs(blk);
1621 
1622     IO_CODE();
1623     GRAPH_RDLOCK_GUARD();
1624 
1625     if (!bs) {
1626         return -ENOMEDIUM;
1627     } else {
1628         return bdrv_co_nb_sectors(bs);
1629     }
1630 }
1631 
1632 /*
1633  * This wrapper is written by hand because this function is in the hot I/O path,
1634  * via blk_get_geometry.
1635  */
1636 int64_t coroutine_mixed_fn blk_nb_sectors(BlockBackend *blk)
1637 {
1638     BlockDriverState *bs = blk_bs(blk);
1639 
1640     IO_CODE();
1641 
1642     if (!bs) {
1643         return -ENOMEDIUM;
1644     } else {
1645         return bdrv_nb_sectors(bs);
1646     }
1647 }
1648 
1649 /* return 0 as number of sectors if no device present or error */
1650 void coroutine_fn blk_co_get_geometry(BlockBackend *blk,
1651                                       uint64_t *nb_sectors_ptr)
1652 {
1653     int64_t ret = blk_co_nb_sectors(blk);
1654     *nb_sectors_ptr = ret < 0 ? 0 : ret;
1655 }
1656 
1657 /*
1658  * This wrapper is written by hand because this function is in the hot I/O path.
1659  */
1660 void coroutine_mixed_fn blk_get_geometry(BlockBackend *blk,
1661                                          uint64_t *nb_sectors_ptr)
1662 {
1663     int64_t ret = blk_nb_sectors(blk);
1664     *nb_sectors_ptr = ret < 0 ? 0 : ret;
1665 }
1666 
1667 BlockAIOCB *blk_aio_preadv(BlockBackend *blk, int64_t offset,
1668                            QEMUIOVector *qiov, BdrvRequestFlags flags,
1669                            BlockCompletionFunc *cb, void *opaque)
1670 {
1671     IO_CODE();
1672     assert((uint64_t)qiov->size <= INT64_MAX);
1673     return blk_aio_prwv(blk, offset, qiov->size, qiov,
1674                         blk_aio_read_entry, flags, cb, opaque);
1675 }
1676 
1677 BlockAIOCB *blk_aio_pwritev(BlockBackend *blk, int64_t offset,
1678                             QEMUIOVector *qiov, BdrvRequestFlags flags,
1679                             BlockCompletionFunc *cb, void *opaque)
1680 {
1681     IO_CODE();
1682     assert((uint64_t)qiov->size <= INT64_MAX);
1683     return blk_aio_prwv(blk, offset, qiov->size, qiov,
1684                         blk_aio_write_entry, flags, cb, opaque);
1685 }
1686 
1687 void blk_aio_cancel(BlockAIOCB *acb)
1688 {
1689     GLOBAL_STATE_CODE();
1690     bdrv_aio_cancel(acb);
1691 }
1692 
1693 void blk_aio_cancel_async(BlockAIOCB *acb)
1694 {
1695     IO_CODE();
1696     bdrv_aio_cancel_async(acb);
1697 }
1698 
1699 /* To be called between exactly one pair of blk_inc/dec_in_flight() */
1700 static int coroutine_fn
1701 blk_co_do_ioctl(BlockBackend *blk, unsigned long int req, void *buf)
1702 {
1703     IO_CODE();
1704 
1705     blk_wait_while_drained(blk);
1706     GRAPH_RDLOCK_GUARD();
1707 
1708     if (!blk_co_is_available(blk)) {
1709         return -ENOMEDIUM;
1710     }
1711 
1712     return bdrv_co_ioctl(blk_bs(blk), req, buf);
1713 }
1714 
1715 int coroutine_fn blk_co_ioctl(BlockBackend *blk, unsigned long int req,
1716                               void *buf)
1717 {
1718     int ret;
1719     IO_OR_GS_CODE();
1720 
1721     blk_inc_in_flight(blk);
1722     ret = blk_co_do_ioctl(blk, req, buf);
1723     blk_dec_in_flight(blk);
1724 
1725     return ret;
1726 }
1727 
1728 static void coroutine_fn blk_aio_ioctl_entry(void *opaque)
1729 {
1730     BlkAioEmAIOCB *acb = opaque;
1731     BlkRwCo *rwco = &acb->rwco;
1732 
1733     rwco->ret = blk_co_do_ioctl(rwco->blk, rwco->offset, rwco->iobuf);
1734 
1735     blk_aio_complete(acb);
1736 }
1737 
1738 BlockAIOCB *blk_aio_ioctl(BlockBackend *blk, unsigned long int req, void *buf,
1739                           BlockCompletionFunc *cb, void *opaque)
1740 {
1741     IO_CODE();
1742     return blk_aio_prwv(blk, req, 0, buf, blk_aio_ioctl_entry, 0, cb, opaque);
1743 }
1744 
1745 /* To be called between exactly one pair of blk_inc/dec_in_flight() */
1746 static int coroutine_fn
1747 blk_co_do_pdiscard(BlockBackend *blk, int64_t offset, int64_t bytes)
1748 {
1749     int ret;
1750     IO_CODE();
1751 
1752     blk_wait_while_drained(blk);
1753     GRAPH_RDLOCK_GUARD();
1754 
1755     ret = blk_check_byte_request(blk, offset, bytes);
1756     if (ret < 0) {
1757         return ret;
1758     }
1759 
1760     return bdrv_co_pdiscard(blk->root, offset, bytes);
1761 }
1762 
1763 static void coroutine_fn blk_aio_pdiscard_entry(void *opaque)
1764 {
1765     BlkAioEmAIOCB *acb = opaque;
1766     BlkRwCo *rwco = &acb->rwco;
1767 
1768     rwco->ret = blk_co_do_pdiscard(rwco->blk, rwco->offset, acb->bytes);
1769     blk_aio_complete(acb);
1770 }
1771 
1772 BlockAIOCB *blk_aio_pdiscard(BlockBackend *blk,
1773                              int64_t offset, int64_t bytes,
1774                              BlockCompletionFunc *cb, void *opaque)
1775 {
1776     IO_CODE();
1777     return blk_aio_prwv(blk, offset, bytes, NULL, blk_aio_pdiscard_entry, 0,
1778                         cb, opaque);
1779 }
1780 
1781 int coroutine_fn blk_co_pdiscard(BlockBackend *blk, int64_t offset,
1782                                  int64_t bytes)
1783 {
1784     int ret;
1785     IO_OR_GS_CODE();
1786 
1787     blk_inc_in_flight(blk);
1788     ret = blk_co_do_pdiscard(blk, offset, bytes);
1789     blk_dec_in_flight(blk);
1790 
1791     return ret;
1792 }
1793 
1794 /* To be called between exactly one pair of blk_inc/dec_in_flight() */
1795 static int coroutine_fn blk_co_do_flush(BlockBackend *blk)
1796 {
1797     IO_CODE();
1798     blk_wait_while_drained(blk);
1799     GRAPH_RDLOCK_GUARD();
1800 
1801     if (!blk_co_is_available(blk)) {
1802         return -ENOMEDIUM;
1803     }
1804 
1805     return bdrv_co_flush(blk_bs(blk));
1806 }
1807 
1808 static void coroutine_fn blk_aio_flush_entry(void *opaque)
1809 {
1810     BlkAioEmAIOCB *acb = opaque;
1811     BlkRwCo *rwco = &acb->rwco;
1812 
1813     rwco->ret = blk_co_do_flush(rwco->blk);
1814     blk_aio_complete(acb);
1815 }
1816 
1817 BlockAIOCB *blk_aio_flush(BlockBackend *blk,
1818                           BlockCompletionFunc *cb, void *opaque)
1819 {
1820     IO_CODE();
1821     return blk_aio_prwv(blk, 0, 0, NULL, blk_aio_flush_entry, 0, cb, opaque);
1822 }
1823 
1824 int coroutine_fn blk_co_flush(BlockBackend *blk)
1825 {
1826     int ret;
1827     IO_OR_GS_CODE();
1828 
1829     blk_inc_in_flight(blk);
1830     ret = blk_co_do_flush(blk);
1831     blk_dec_in_flight(blk);
1832 
1833     return ret;
1834 }
1835 
1836 void blk_drain(BlockBackend *blk)
1837 {
1838     BlockDriverState *bs = blk_bs(blk);
1839     GLOBAL_STATE_CODE();
1840 
1841     if (bs) {
1842         bdrv_ref(bs);
1843         bdrv_drained_begin(bs);
1844     }
1845 
1846     /* We may have -ENOMEDIUM completions in flight */
1847     AIO_WAIT_WHILE(blk_get_aio_context(blk),
1848                    qatomic_mb_read(&blk->in_flight) > 0);
1849 
1850     if (bs) {
1851         bdrv_drained_end(bs);
1852         bdrv_unref(bs);
1853     }
1854 }
1855 
1856 void blk_drain_all(void)
1857 {
1858     BlockBackend *blk = NULL;
1859 
1860     GLOBAL_STATE_CODE();
1861 
1862     bdrv_drain_all_begin();
1863 
1864     while ((blk = blk_all_next(blk)) != NULL) {
1865         AioContext *ctx = blk_get_aio_context(blk);
1866 
1867         aio_context_acquire(ctx);
1868 
1869         /* We may have -ENOMEDIUM completions in flight */
1870         AIO_WAIT_WHILE(ctx, qatomic_mb_read(&blk->in_flight) > 0);
1871 
1872         aio_context_release(ctx);
1873     }
1874 
1875     bdrv_drain_all_end();
1876 }
1877 
1878 void blk_set_on_error(BlockBackend *blk, BlockdevOnError on_read_error,
1879                       BlockdevOnError on_write_error)
1880 {
1881     GLOBAL_STATE_CODE();
1882     blk->on_read_error = on_read_error;
1883     blk->on_write_error = on_write_error;
1884 }
1885 
1886 BlockdevOnError blk_get_on_error(BlockBackend *blk, bool is_read)
1887 {
1888     IO_CODE();
1889     return is_read ? blk->on_read_error : blk->on_write_error;
1890 }
1891 
1892 BlockErrorAction blk_get_error_action(BlockBackend *blk, bool is_read,
1893                                       int error)
1894 {
1895     BlockdevOnError on_err = blk_get_on_error(blk, is_read);
1896     IO_CODE();
1897 
1898     switch (on_err) {
1899     case BLOCKDEV_ON_ERROR_ENOSPC:
1900         return (error == ENOSPC) ?
1901                BLOCK_ERROR_ACTION_STOP : BLOCK_ERROR_ACTION_REPORT;
1902     case BLOCKDEV_ON_ERROR_STOP:
1903         return BLOCK_ERROR_ACTION_STOP;
1904     case BLOCKDEV_ON_ERROR_REPORT:
1905         return BLOCK_ERROR_ACTION_REPORT;
1906     case BLOCKDEV_ON_ERROR_IGNORE:
1907         return BLOCK_ERROR_ACTION_IGNORE;
1908     case BLOCKDEV_ON_ERROR_AUTO:
1909     default:
1910         abort();
1911     }
1912 }
1913 
1914 static void send_qmp_error_event(BlockBackend *blk,
1915                                  BlockErrorAction action,
1916                                  bool is_read, int error)
1917 {
1918     IoOperationType optype;
1919     BlockDriverState *bs = blk_bs(blk);
1920 
1921     optype = is_read ? IO_OPERATION_TYPE_READ : IO_OPERATION_TYPE_WRITE;
1922     qapi_event_send_block_io_error(blk_name(blk),
1923                                    bs ? bdrv_get_node_name(bs) : NULL, optype,
1924                                    action, blk_iostatus_is_enabled(blk),
1925                                    error == ENOSPC, strerror(error));
1926 }
1927 
1928 /* This is done by device models because, while the block layer knows
1929  * about the error, it does not know whether an operation comes from
1930  * the device or the block layer (from a job, for example).
1931  */
1932 void blk_error_action(BlockBackend *blk, BlockErrorAction action,
1933                       bool is_read, int error)
1934 {
1935     assert(error >= 0);
1936     IO_CODE();
1937 
1938     if (action == BLOCK_ERROR_ACTION_STOP) {
1939         /* First set the iostatus, so that "info block" returns an iostatus
1940          * that matches the events raised so far (an additional error iostatus
1941          * is fine, but not a lost one).
1942          */
1943         blk_iostatus_set_err(blk, error);
1944 
1945         /* Then raise the request to stop the VM and the event.
1946          * qemu_system_vmstop_request_prepare has two effects.  First,
1947          * it ensures that the STOP event always comes after the
1948          * BLOCK_IO_ERROR event.  Second, it ensures that even if management
1949          * can observe the STOP event and do a "cont" before the STOP
1950          * event is issued, the VM will not stop.  In this case, vm_start()
1951          * also ensures that the STOP/RESUME pair of events is emitted.
1952          */
1953         qemu_system_vmstop_request_prepare();
1954         send_qmp_error_event(blk, action, is_read, error);
1955         qemu_system_vmstop_request(RUN_STATE_IO_ERROR);
1956     } else {
1957         send_qmp_error_event(blk, action, is_read, error);
1958     }
1959 }
1960 
1961 /*
1962  * Returns true if the BlockBackend can support taking write permissions
1963  * (because its root node is not read-only).
1964  */
1965 bool blk_supports_write_perm(BlockBackend *blk)
1966 {
1967     BlockDriverState *bs = blk_bs(blk);
1968     GLOBAL_STATE_CODE();
1969 
1970     if (bs) {
1971         return !bdrv_is_read_only(bs);
1972     } else {
1973         return blk->root_state.open_flags & BDRV_O_RDWR;
1974     }
1975 }
1976 
1977 /*
1978  * Returns true if the BlockBackend can be written to in its current
1979  * configuration (i.e. if write permission have been requested)
1980  */
1981 bool blk_is_writable(BlockBackend *blk)
1982 {
1983     IO_CODE();
1984     return blk->perm & BLK_PERM_WRITE;
1985 }
1986 
1987 bool blk_is_sg(BlockBackend *blk)
1988 {
1989     BlockDriverState *bs = blk_bs(blk);
1990     GLOBAL_STATE_CODE();
1991 
1992     if (!bs) {
1993         return false;
1994     }
1995 
1996     return bdrv_is_sg(bs);
1997 }
1998 
1999 bool blk_enable_write_cache(BlockBackend *blk)
2000 {
2001     IO_CODE();
2002     return blk->enable_write_cache;
2003 }
2004 
2005 void blk_set_enable_write_cache(BlockBackend *blk, bool wce)
2006 {
2007     IO_CODE();
2008     blk->enable_write_cache = wce;
2009 }
2010 
2011 void blk_activate(BlockBackend *blk, Error **errp)
2012 {
2013     BlockDriverState *bs = blk_bs(blk);
2014     GLOBAL_STATE_CODE();
2015 
2016     if (!bs) {
2017         error_setg(errp, "Device '%s' has no medium", blk->name);
2018         return;
2019     }
2020 
2021     bdrv_activate(bs, errp);
2022 }
2023 
2024 bool coroutine_fn blk_co_is_inserted(BlockBackend *blk)
2025 {
2026     BlockDriverState *bs = blk_bs(blk);
2027     IO_CODE();
2028     assert_bdrv_graph_readable();
2029 
2030     return bs && bdrv_co_is_inserted(bs);
2031 }
2032 
2033 bool coroutine_fn blk_co_is_available(BlockBackend *blk)
2034 {
2035     IO_CODE();
2036     return blk_co_is_inserted(blk) && !blk_dev_is_tray_open(blk);
2037 }
2038 
2039 void coroutine_fn blk_co_lock_medium(BlockBackend *blk, bool locked)
2040 {
2041     BlockDriverState *bs = blk_bs(blk);
2042     IO_CODE();
2043     GRAPH_RDLOCK_GUARD();
2044 
2045     if (bs) {
2046         bdrv_co_lock_medium(bs, locked);
2047     }
2048 }
2049 
2050 void coroutine_fn blk_co_eject(BlockBackend *blk, bool eject_flag)
2051 {
2052     BlockDriverState *bs = blk_bs(blk);
2053     char *id;
2054     IO_CODE();
2055     GRAPH_RDLOCK_GUARD();
2056 
2057     if (bs) {
2058         bdrv_co_eject(bs, eject_flag);
2059     }
2060 
2061     /* Whether or not we ejected on the backend,
2062      * the frontend experienced a tray event. */
2063     id = blk_get_attached_dev_id(blk);
2064     qapi_event_send_device_tray_moved(blk_name(blk), id,
2065                                       eject_flag);
2066     g_free(id);
2067 }
2068 
2069 int blk_get_flags(BlockBackend *blk)
2070 {
2071     BlockDriverState *bs = blk_bs(blk);
2072     GLOBAL_STATE_CODE();
2073 
2074     if (bs) {
2075         return bdrv_get_flags(bs);
2076     } else {
2077         return blk->root_state.open_flags;
2078     }
2079 }
2080 
2081 /* Returns the minimum request alignment, in bytes; guaranteed nonzero */
2082 uint32_t blk_get_request_alignment(BlockBackend *blk)
2083 {
2084     BlockDriverState *bs = blk_bs(blk);
2085     IO_CODE();
2086     return bs ? bs->bl.request_alignment : BDRV_SECTOR_SIZE;
2087 }
2088 
2089 /* Returns the maximum hardware transfer length, in bytes; guaranteed nonzero */
2090 uint64_t blk_get_max_hw_transfer(BlockBackend *blk)
2091 {
2092     BlockDriverState *bs = blk_bs(blk);
2093     uint64_t max = INT_MAX;
2094     IO_CODE();
2095 
2096     if (bs) {
2097         max = MIN_NON_ZERO(max, bs->bl.max_hw_transfer);
2098         max = MIN_NON_ZERO(max, bs->bl.max_transfer);
2099     }
2100     return ROUND_DOWN(max, blk_get_request_alignment(blk));
2101 }
2102 
2103 /* Returns the maximum transfer length, in bytes; guaranteed nonzero */
2104 uint32_t blk_get_max_transfer(BlockBackend *blk)
2105 {
2106     BlockDriverState *bs = blk_bs(blk);
2107     uint32_t max = INT_MAX;
2108     IO_CODE();
2109 
2110     if (bs) {
2111         max = MIN_NON_ZERO(max, bs->bl.max_transfer);
2112     }
2113     return ROUND_DOWN(max, blk_get_request_alignment(blk));
2114 }
2115 
2116 int blk_get_max_hw_iov(BlockBackend *blk)
2117 {
2118     IO_CODE();
2119     return MIN_NON_ZERO(blk->root->bs->bl.max_hw_iov,
2120                         blk->root->bs->bl.max_iov);
2121 }
2122 
2123 int blk_get_max_iov(BlockBackend *blk)
2124 {
2125     IO_CODE();
2126     return blk->root->bs->bl.max_iov;
2127 }
2128 
2129 void *blk_try_blockalign(BlockBackend *blk, size_t size)
2130 {
2131     IO_CODE();
2132     return qemu_try_blockalign(blk ? blk_bs(blk) : NULL, size);
2133 }
2134 
2135 void *blk_blockalign(BlockBackend *blk, size_t size)
2136 {
2137     IO_CODE();
2138     return qemu_blockalign(blk ? blk_bs(blk) : NULL, size);
2139 }
2140 
2141 bool blk_op_is_blocked(BlockBackend *blk, BlockOpType op, Error **errp)
2142 {
2143     BlockDriverState *bs = blk_bs(blk);
2144     GLOBAL_STATE_CODE();
2145 
2146     if (!bs) {
2147         return false;
2148     }
2149 
2150     return bdrv_op_is_blocked(bs, op, errp);
2151 }
2152 
2153 void blk_op_unblock(BlockBackend *blk, BlockOpType op, Error *reason)
2154 {
2155     BlockDriverState *bs = blk_bs(blk);
2156     GLOBAL_STATE_CODE();
2157 
2158     if (bs) {
2159         bdrv_op_unblock(bs, op, reason);
2160     }
2161 }
2162 
2163 void blk_op_block_all(BlockBackend *blk, Error *reason)
2164 {
2165     BlockDriverState *bs = blk_bs(blk);
2166     GLOBAL_STATE_CODE();
2167 
2168     if (bs) {
2169         bdrv_op_block_all(bs, reason);
2170     }
2171 }
2172 
2173 void blk_op_unblock_all(BlockBackend *blk, Error *reason)
2174 {
2175     BlockDriverState *bs = blk_bs(blk);
2176     GLOBAL_STATE_CODE();
2177 
2178     if (bs) {
2179         bdrv_op_unblock_all(bs, reason);
2180     }
2181 }
2182 
2183 AioContext *blk_get_aio_context(BlockBackend *blk)
2184 {
2185     BlockDriverState *bs = blk_bs(blk);
2186     IO_CODE();
2187 
2188     if (bs) {
2189         AioContext *ctx = bdrv_get_aio_context(blk_bs(blk));
2190         assert(ctx == blk->ctx);
2191     }
2192 
2193     return blk->ctx;
2194 }
2195 
2196 static AioContext *blk_aiocb_get_aio_context(BlockAIOCB *acb)
2197 {
2198     BlockBackendAIOCB *blk_acb = DO_UPCAST(BlockBackendAIOCB, common, acb);
2199     return blk_get_aio_context(blk_acb->blk);
2200 }
2201 
2202 static int blk_do_set_aio_context(BlockBackend *blk, AioContext *new_context,
2203                                   bool update_root_node, Error **errp)
2204 {
2205     BlockDriverState *bs = blk_bs(blk);
2206     ThrottleGroupMember *tgm = &blk->public.throttle_group_member;
2207     int ret;
2208 
2209     if (bs) {
2210         bdrv_ref(bs);
2211 
2212         if (update_root_node) {
2213             /*
2214              * update_root_node MUST be false for blk_root_set_aio_ctx_commit(),
2215              * as we are already in the commit function of a transaction.
2216              */
2217             ret = bdrv_try_change_aio_context(bs, new_context, blk->root, errp);
2218             if (ret < 0) {
2219                 bdrv_unref(bs);
2220                 return ret;
2221             }
2222         }
2223         /*
2224          * Make blk->ctx consistent with the root node before we invoke any
2225          * other operations like drain that might inquire blk->ctx
2226          */
2227         blk->ctx = new_context;
2228         if (tgm->throttle_state) {
2229             bdrv_drained_begin(bs);
2230             throttle_group_detach_aio_context(tgm);
2231             throttle_group_attach_aio_context(tgm, new_context);
2232             bdrv_drained_end(bs);
2233         }
2234 
2235         bdrv_unref(bs);
2236     } else {
2237         blk->ctx = new_context;
2238     }
2239 
2240     return 0;
2241 }
2242 
2243 int blk_set_aio_context(BlockBackend *blk, AioContext *new_context,
2244                         Error **errp)
2245 {
2246     GLOBAL_STATE_CODE();
2247     return blk_do_set_aio_context(blk, new_context, true, errp);
2248 }
2249 
2250 typedef struct BdrvStateBlkRootContext {
2251     AioContext *new_ctx;
2252     BlockBackend *blk;
2253 } BdrvStateBlkRootContext;
2254 
2255 static void blk_root_set_aio_ctx_commit(void *opaque)
2256 {
2257     BdrvStateBlkRootContext *s = opaque;
2258     BlockBackend *blk = s->blk;
2259 
2260     blk_do_set_aio_context(blk, s->new_ctx, false, &error_abort);
2261 }
2262 
2263 static TransactionActionDrv set_blk_root_context = {
2264     .commit = blk_root_set_aio_ctx_commit,
2265     .clean = g_free,
2266 };
2267 
2268 static bool blk_root_change_aio_ctx(BdrvChild *child, AioContext *ctx,
2269                                     GHashTable *visited, Transaction *tran,
2270                                     Error **errp)
2271 {
2272     BlockBackend *blk = child->opaque;
2273     BdrvStateBlkRootContext *s;
2274 
2275     if (!blk->allow_aio_context_change) {
2276         /*
2277          * Manually created BlockBackends (those with a name) that are not
2278          * attached to anything can change their AioContext without updating
2279          * their user; return an error for others.
2280          */
2281         if (!blk->name || blk->dev) {
2282             /* TODO Add BB name/QOM path */
2283             error_setg(errp, "Cannot change iothread of active block backend");
2284             return false;
2285         }
2286     }
2287 
2288     s = g_new(BdrvStateBlkRootContext, 1);
2289     *s = (BdrvStateBlkRootContext) {
2290         .new_ctx = ctx,
2291         .blk = blk,
2292     };
2293 
2294     tran_add(tran, &set_blk_root_context, s);
2295     return true;
2296 }
2297 
2298 void blk_add_aio_context_notifier(BlockBackend *blk,
2299         void (*attached_aio_context)(AioContext *new_context, void *opaque),
2300         void (*detach_aio_context)(void *opaque), void *opaque)
2301 {
2302     BlockBackendAioNotifier *notifier;
2303     BlockDriverState *bs = blk_bs(blk);
2304     GLOBAL_STATE_CODE();
2305 
2306     notifier = g_new(BlockBackendAioNotifier, 1);
2307     notifier->attached_aio_context = attached_aio_context;
2308     notifier->detach_aio_context = detach_aio_context;
2309     notifier->opaque = opaque;
2310     QLIST_INSERT_HEAD(&blk->aio_notifiers, notifier, list);
2311 
2312     if (bs) {
2313         bdrv_add_aio_context_notifier(bs, attached_aio_context,
2314                                       detach_aio_context, opaque);
2315     }
2316 }
2317 
2318 void blk_remove_aio_context_notifier(BlockBackend *blk,
2319                                      void (*attached_aio_context)(AioContext *,
2320                                                                   void *),
2321                                      void (*detach_aio_context)(void *),
2322                                      void *opaque)
2323 {
2324     BlockBackendAioNotifier *notifier;
2325     BlockDriverState *bs = blk_bs(blk);
2326 
2327     GLOBAL_STATE_CODE();
2328 
2329     if (bs) {
2330         bdrv_remove_aio_context_notifier(bs, attached_aio_context,
2331                                          detach_aio_context, opaque);
2332     }
2333 
2334     QLIST_FOREACH(notifier, &blk->aio_notifiers, list) {
2335         if (notifier->attached_aio_context == attached_aio_context &&
2336             notifier->detach_aio_context == detach_aio_context &&
2337             notifier->opaque == opaque) {
2338             QLIST_REMOVE(notifier, list);
2339             g_free(notifier);
2340             return;
2341         }
2342     }
2343 
2344     abort();
2345 }
2346 
2347 void blk_add_remove_bs_notifier(BlockBackend *blk, Notifier *notify)
2348 {
2349     GLOBAL_STATE_CODE();
2350     notifier_list_add(&blk->remove_bs_notifiers, notify);
2351 }
2352 
2353 void blk_add_insert_bs_notifier(BlockBackend *blk, Notifier *notify)
2354 {
2355     GLOBAL_STATE_CODE();
2356     notifier_list_add(&blk->insert_bs_notifiers, notify);
2357 }
2358 
2359 void coroutine_fn blk_co_io_plug(BlockBackend *blk)
2360 {
2361     BlockDriverState *bs = blk_bs(blk);
2362     IO_CODE();
2363     GRAPH_RDLOCK_GUARD();
2364 
2365     if (bs) {
2366         bdrv_co_io_plug(bs);
2367     }
2368 }
2369 
2370 void coroutine_fn blk_co_io_unplug(BlockBackend *blk)
2371 {
2372     BlockDriverState *bs = blk_bs(blk);
2373     IO_CODE();
2374     GRAPH_RDLOCK_GUARD();
2375 
2376     if (bs) {
2377         bdrv_co_io_unplug(bs);
2378     }
2379 }
2380 
2381 BlockAcctStats *blk_get_stats(BlockBackend *blk)
2382 {
2383     IO_CODE();
2384     return &blk->stats;
2385 }
2386 
2387 void *blk_aio_get(const AIOCBInfo *aiocb_info, BlockBackend *blk,
2388                   BlockCompletionFunc *cb, void *opaque)
2389 {
2390     IO_CODE();
2391     return qemu_aio_get(aiocb_info, blk_bs(blk), cb, opaque);
2392 }
2393 
2394 int coroutine_fn blk_co_pwrite_zeroes(BlockBackend *blk, int64_t offset,
2395                                       int64_t bytes, BdrvRequestFlags flags)
2396 {
2397     IO_OR_GS_CODE();
2398     return blk_co_pwritev(blk, offset, bytes, NULL,
2399                           flags | BDRV_REQ_ZERO_WRITE);
2400 }
2401 
2402 int coroutine_fn blk_co_pwrite_compressed(BlockBackend *blk, int64_t offset,
2403                                           int64_t bytes, const void *buf)
2404 {
2405     QEMUIOVector qiov = QEMU_IOVEC_INIT_BUF(qiov, buf, bytes);
2406     IO_OR_GS_CODE();
2407     return blk_co_pwritev_part(blk, offset, bytes, &qiov, 0,
2408                                BDRV_REQ_WRITE_COMPRESSED);
2409 }
2410 
2411 int coroutine_fn blk_co_truncate(BlockBackend *blk, int64_t offset, bool exact,
2412                                  PreallocMode prealloc, BdrvRequestFlags flags,
2413                                  Error **errp)
2414 {
2415     IO_OR_GS_CODE();
2416     GRAPH_RDLOCK_GUARD();
2417     if (!blk_co_is_available(blk)) {
2418         error_setg(errp, "No medium inserted");
2419         return -ENOMEDIUM;
2420     }
2421 
2422     return bdrv_co_truncate(blk->root, offset, exact, prealloc, flags, errp);
2423 }
2424 
2425 int blk_save_vmstate(BlockBackend *blk, const uint8_t *buf,
2426                      int64_t pos, int size)
2427 {
2428     int ret;
2429     GLOBAL_STATE_CODE();
2430 
2431     if (!blk_is_available(blk)) {
2432         return -ENOMEDIUM;
2433     }
2434 
2435     ret = bdrv_save_vmstate(blk_bs(blk), buf, pos, size);
2436     if (ret < 0) {
2437         return ret;
2438     }
2439 
2440     if (ret == size && !blk->enable_write_cache) {
2441         ret = bdrv_flush(blk_bs(blk));
2442     }
2443 
2444     return ret < 0 ? ret : size;
2445 }
2446 
2447 int blk_load_vmstate(BlockBackend *blk, uint8_t *buf, int64_t pos, int size)
2448 {
2449     GLOBAL_STATE_CODE();
2450     if (!blk_is_available(blk)) {
2451         return -ENOMEDIUM;
2452     }
2453 
2454     return bdrv_load_vmstate(blk_bs(blk), buf, pos, size);
2455 }
2456 
2457 int blk_probe_blocksizes(BlockBackend *blk, BlockSizes *bsz)
2458 {
2459     GLOBAL_STATE_CODE();
2460     if (!blk_is_available(blk)) {
2461         return -ENOMEDIUM;
2462     }
2463 
2464     return bdrv_probe_blocksizes(blk_bs(blk), bsz);
2465 }
2466 
2467 int blk_probe_geometry(BlockBackend *blk, HDGeometry *geo)
2468 {
2469     GLOBAL_STATE_CODE();
2470     if (!blk_is_available(blk)) {
2471         return -ENOMEDIUM;
2472     }
2473 
2474     return bdrv_probe_geometry(blk_bs(blk), geo);
2475 }
2476 
2477 /*
2478  * Updates the BlockBackendRootState object with data from the currently
2479  * attached BlockDriverState.
2480  */
2481 void blk_update_root_state(BlockBackend *blk)
2482 {
2483     GLOBAL_STATE_CODE();
2484     assert(blk->root);
2485 
2486     blk->root_state.open_flags    = blk->root->bs->open_flags;
2487     blk->root_state.detect_zeroes = blk->root->bs->detect_zeroes;
2488 }
2489 
2490 /*
2491  * Returns the detect-zeroes setting to be used for bdrv_open() of a
2492  * BlockDriverState which is supposed to inherit the root state.
2493  */
2494 bool blk_get_detect_zeroes_from_root_state(BlockBackend *blk)
2495 {
2496     GLOBAL_STATE_CODE();
2497     return blk->root_state.detect_zeroes;
2498 }
2499 
2500 /*
2501  * Returns the flags to be used for bdrv_open() of a BlockDriverState which is
2502  * supposed to inherit the root state.
2503  */
2504 int blk_get_open_flags_from_root_state(BlockBackend *blk)
2505 {
2506     GLOBAL_STATE_CODE();
2507     return blk->root_state.open_flags;
2508 }
2509 
2510 BlockBackendRootState *blk_get_root_state(BlockBackend *blk)
2511 {
2512     GLOBAL_STATE_CODE();
2513     return &blk->root_state;
2514 }
2515 
2516 int blk_commit_all(void)
2517 {
2518     BlockBackend *blk = NULL;
2519     GLOBAL_STATE_CODE();
2520 
2521     while ((blk = blk_all_next(blk)) != NULL) {
2522         AioContext *aio_context = blk_get_aio_context(blk);
2523         BlockDriverState *unfiltered_bs = bdrv_skip_filters(blk_bs(blk));
2524 
2525         aio_context_acquire(aio_context);
2526         if (blk_is_inserted(blk) && bdrv_cow_child(unfiltered_bs)) {
2527             int ret;
2528 
2529             ret = bdrv_commit(unfiltered_bs);
2530             if (ret < 0) {
2531                 aio_context_release(aio_context);
2532                 return ret;
2533             }
2534         }
2535         aio_context_release(aio_context);
2536     }
2537     return 0;
2538 }
2539 
2540 
2541 /* throttling disk I/O limits */
2542 void blk_set_io_limits(BlockBackend *blk, ThrottleConfig *cfg)
2543 {
2544     GLOBAL_STATE_CODE();
2545     throttle_group_config(&blk->public.throttle_group_member, cfg);
2546 }
2547 
2548 void blk_io_limits_disable(BlockBackend *blk)
2549 {
2550     BlockDriverState *bs = blk_bs(blk);
2551     ThrottleGroupMember *tgm = &blk->public.throttle_group_member;
2552     assert(tgm->throttle_state);
2553     GLOBAL_STATE_CODE();
2554     if (bs) {
2555         bdrv_ref(bs);
2556         bdrv_drained_begin(bs);
2557     }
2558     throttle_group_unregister_tgm(tgm);
2559     if (bs) {
2560         bdrv_drained_end(bs);
2561         bdrv_unref(bs);
2562     }
2563 }
2564 
2565 /* should be called before blk_set_io_limits if a limit is set */
2566 void blk_io_limits_enable(BlockBackend *blk, const char *group)
2567 {
2568     assert(!blk->public.throttle_group_member.throttle_state);
2569     GLOBAL_STATE_CODE();
2570     throttle_group_register_tgm(&blk->public.throttle_group_member,
2571                                 group, blk_get_aio_context(blk));
2572 }
2573 
2574 void blk_io_limits_update_group(BlockBackend *blk, const char *group)
2575 {
2576     GLOBAL_STATE_CODE();
2577     /* this BB is not part of any group */
2578     if (!blk->public.throttle_group_member.throttle_state) {
2579         return;
2580     }
2581 
2582     /* this BB is a part of the same group than the one we want */
2583     if (!g_strcmp0(throttle_group_get_name(&blk->public.throttle_group_member),
2584                 group)) {
2585         return;
2586     }
2587 
2588     /* need to change the group this bs belong to */
2589     blk_io_limits_disable(blk);
2590     blk_io_limits_enable(blk, group);
2591 }
2592 
2593 static void blk_root_drained_begin(BdrvChild *child)
2594 {
2595     BlockBackend *blk = child->opaque;
2596     ThrottleGroupMember *tgm = &blk->public.throttle_group_member;
2597 
2598     if (++blk->quiesce_counter == 1) {
2599         if (blk->dev_ops && blk->dev_ops->drained_begin) {
2600             blk->dev_ops->drained_begin(blk->dev_opaque);
2601         }
2602     }
2603 
2604     /* Note that blk->root may not be accessible here yet if we are just
2605      * attaching to a BlockDriverState that is drained. Use child instead. */
2606 
2607     if (qatomic_fetch_inc(&tgm->io_limits_disabled) == 0) {
2608         throttle_group_restart_tgm(tgm);
2609     }
2610 }
2611 
2612 static bool blk_root_drained_poll(BdrvChild *child)
2613 {
2614     BlockBackend *blk = child->opaque;
2615     bool busy = false;
2616     assert(blk->quiesce_counter);
2617 
2618     if (blk->dev_ops && blk->dev_ops->drained_poll) {
2619         busy = blk->dev_ops->drained_poll(blk->dev_opaque);
2620     }
2621     return busy || !!blk->in_flight;
2622 }
2623 
2624 static void blk_root_drained_end(BdrvChild *child)
2625 {
2626     BlockBackend *blk = child->opaque;
2627     assert(blk->quiesce_counter);
2628 
2629     assert(blk->public.throttle_group_member.io_limits_disabled);
2630     qatomic_dec(&blk->public.throttle_group_member.io_limits_disabled);
2631 
2632     if (--blk->quiesce_counter == 0) {
2633         if (blk->dev_ops && blk->dev_ops->drained_end) {
2634             blk->dev_ops->drained_end(blk->dev_opaque);
2635         }
2636         while (qemu_co_enter_next(&blk->queued_requests, NULL)) {
2637             /* Resume all queued requests */
2638         }
2639     }
2640 }
2641 
2642 bool blk_register_buf(BlockBackend *blk, void *host, size_t size, Error **errp)
2643 {
2644     BlockDriverState *bs = blk_bs(blk);
2645 
2646     GLOBAL_STATE_CODE();
2647 
2648     if (bs) {
2649         return bdrv_register_buf(bs, host, size, errp);
2650     }
2651     return true;
2652 }
2653 
2654 void blk_unregister_buf(BlockBackend *blk, void *host, size_t size)
2655 {
2656     BlockDriverState *bs = blk_bs(blk);
2657 
2658     GLOBAL_STATE_CODE();
2659 
2660     if (bs) {
2661         bdrv_unregister_buf(bs, host, size);
2662     }
2663 }
2664 
2665 int coroutine_fn blk_co_copy_range(BlockBackend *blk_in, int64_t off_in,
2666                                    BlockBackend *blk_out, int64_t off_out,
2667                                    int64_t bytes, BdrvRequestFlags read_flags,
2668                                    BdrvRequestFlags write_flags)
2669 {
2670     int r;
2671     IO_CODE();
2672     GRAPH_RDLOCK_GUARD();
2673 
2674     r = blk_check_byte_request(blk_in, off_in, bytes);
2675     if (r) {
2676         return r;
2677     }
2678     r = blk_check_byte_request(blk_out, off_out, bytes);
2679     if (r) {
2680         return r;
2681     }
2682 
2683     return bdrv_co_copy_range(blk_in->root, off_in,
2684                               blk_out->root, off_out,
2685                               bytes, read_flags, write_flags);
2686 }
2687 
2688 const BdrvChild *blk_root(BlockBackend *blk)
2689 {
2690     GLOBAL_STATE_CODE();
2691     return blk->root;
2692 }
2693 
2694 int blk_make_empty(BlockBackend *blk, Error **errp)
2695 {
2696     GLOBAL_STATE_CODE();
2697     if (!blk_is_available(blk)) {
2698         error_setg(errp, "No medium inserted");
2699         return -ENOMEDIUM;
2700     }
2701 
2702     return bdrv_make_empty(blk->root, errp);
2703 }
2704