xref: /freebsd/sys/cam/ctl/ctl_tpc.c (revision 243e928310d073338c5ec089f0dce238a80b9866)
1 /*-
2  * Copyright (c) 2014 Alexander Motin <mav@FreeBSD.org>
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer,
10  *    without modification, immediately at the beginning of the file.
11  * 2. Redistributions in binary form must reproduce the above copyright
12  *    notice, this list of conditions and the following disclaimer in the
13  *    documentation and/or other materials provided with the distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
16  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
17  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
18  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
19  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
20  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
21  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
22  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
24  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25  */
26 
27 #include <sys/cdefs.h>
28 __FBSDID("$FreeBSD$");
29 
30 #include <sys/param.h>
31 #include <sys/systm.h>
32 #include <sys/kernel.h>
33 #include <sys/types.h>
34 #include <sys/lock.h>
35 #include <sys/module.h>
36 #include <sys/mutex.h>
37 #include <sys/condvar.h>
38 #include <sys/malloc.h>
39 #include <sys/conf.h>
40 #include <sys/queue.h>
41 #include <sys/sysctl.h>
42 #include <machine/atomic.h>
43 
44 #include <cam/cam.h>
45 #include <cam/scsi/scsi_all.h>
46 #include <cam/scsi/scsi_da.h>
47 #include <cam/ctl/ctl_io.h>
48 #include <cam/ctl/ctl.h>
49 #include <cam/ctl/ctl_frontend.h>
50 #include <cam/ctl/ctl_util.h>
51 #include <cam/ctl/ctl_backend.h>
52 #include <cam/ctl/ctl_ioctl.h>
53 #include <cam/ctl/ctl_ha.h>
54 #include <cam/ctl/ctl_private.h>
55 #include <cam/ctl/ctl_debug.h>
56 #include <cam/ctl/ctl_scsi_all.h>
57 #include <cam/ctl/ctl_tpc.h>
58 #include <cam/ctl/ctl_error.h>
59 
60 #define	TPC_MAX_CSCDS	64
61 #define	TPC_MAX_SEGS	64
62 #define	TPC_MAX_SEG	0
63 #define	TPC_MAX_LIST	8192
64 #define	TPC_MAX_INLINE	0
65 #define	TPC_MAX_LISTS	255
66 #define	TPC_MAX_IO_SIZE	(1024 * 1024)
67 #define	TPC_MAX_IOCHUNK_SIZE	(TPC_MAX_IO_SIZE * 16)
68 #define	TPC_MIN_TOKEN_TIMEOUT	1
69 #define	TPC_DFL_TOKEN_TIMEOUT	60
70 #define	TPC_MAX_TOKEN_TIMEOUT	600
71 
72 MALLOC_DEFINE(M_CTL_TPC, "ctltpc", "CTL TPC");
73 
74 typedef enum {
75 	TPC_ERR_RETRY		= 0x000,
76 	TPC_ERR_FAIL		= 0x001,
77 	TPC_ERR_MASK		= 0x0ff,
78 	TPC_ERR_NO_DECREMENT	= 0x100
79 } tpc_error_action;
80 
81 struct tpc_list;
82 TAILQ_HEAD(runl, tpc_io);
83 struct tpc_io {
84 	union ctl_io		*io;
85 	uint64_t		 lun;
86 	struct tpc_list		*list;
87 	struct runl		 run;
88 	TAILQ_ENTRY(tpc_io)	 rlinks;
89 	TAILQ_ENTRY(tpc_io)	 links;
90 };
91 
92 struct tpc_token {
93 	uint8_t			 token[512];
94 	uint64_t		 lun;
95 	uint32_t		 blocksize;
96 	uint8_t			*params;
97 	struct scsi_range_desc	*range;
98 	int			 nrange;
99 	int			 active;
100 	time_t			 last_active;
101 	uint32_t		 timeout;
102 	TAILQ_ENTRY(tpc_token)	 links;
103 };
104 
105 struct tpc_list {
106 	uint8_t			 service_action;
107 	int			 init_port;
108 	uint32_t		 init_idx;
109 	uint32_t		 list_id;
110 	uint8_t			 flags;
111 	uint8_t			*params;
112 	struct scsi_ec_cscd	*cscd;
113 	struct scsi_ec_segment	*seg[TPC_MAX_SEGS];
114 	uint8_t			*inl;
115 	int			 ncscd;
116 	int			 nseg;
117 	int			 leninl;
118 	struct tpc_token	*token;
119 	struct scsi_range_desc	*range;
120 	int			 nrange;
121 	off_t			 offset_into_rod;
122 
123 	int			 curseg;
124 	off_t			 cursectors;
125 	off_t			 curbytes;
126 	int			 curops;
127 	int			 stage;
128 	uint8_t			*buf;
129 	off_t			 segsectors;
130 	off_t			 segbytes;
131 	int			 tbdio;
132 	int			 error;
133 	int			 abort;
134 	int			 completed;
135 	time_t			 last_active;
136 	TAILQ_HEAD(, tpc_io)	 allio;
137 	struct scsi_sense_data	 sense_data;
138 	uint8_t			 sense_len;
139 	uint8_t			 scsi_status;
140 	struct ctl_scsiio	*ctsio;
141 	struct ctl_lun		*lun;
142 	int			 res_token_valid;
143 	uint8_t			 res_token[512];
144 	TAILQ_ENTRY(tpc_list)	 links;
145 };
146 
147 static void
148 tpc_timeout(void *arg)
149 {
150 	struct ctl_softc *softc = arg;
151 	struct ctl_lun *lun;
152 	struct tpc_token *token, *ttoken;
153 	struct tpc_list *list, *tlist;
154 
155 	/* Free completed lists with expired timeout. */
156 	STAILQ_FOREACH(lun, &softc->lun_list, links) {
157 		mtx_lock(&lun->lun_lock);
158 		TAILQ_FOREACH_SAFE(list, &lun->tpc_lists, links, tlist) {
159 			if (!list->completed || time_uptime < list->last_active +
160 			    TPC_DFL_TOKEN_TIMEOUT)
161 				continue;
162 			TAILQ_REMOVE(&lun->tpc_lists, list, links);
163 			free(list, M_CTL);
164 		}
165 		mtx_unlock(&lun->lun_lock);
166 	}
167 
168 	/* Free inactive ROD tokens with expired timeout. */
169 	mtx_lock(&softc->tpc_lock);
170 	TAILQ_FOREACH_SAFE(token, &softc->tpc_tokens, links, ttoken) {
171 		if (token->active ||
172 		    time_uptime < token->last_active + token->timeout + 1)
173 			continue;
174 		TAILQ_REMOVE(&softc->tpc_tokens, token, links);
175 		free(token->params, M_CTL);
176 		free(token, M_CTL);
177 	}
178 	mtx_unlock(&softc->tpc_lock);
179 	callout_schedule(&softc->tpc_timeout, hz);
180 }
181 
182 void
183 ctl_tpc_init(struct ctl_softc *softc)
184 {
185 
186 	mtx_init(&softc->tpc_lock, "CTL TPC mutex", NULL, MTX_DEF);
187 	TAILQ_INIT(&softc->tpc_tokens);
188 	callout_init_mtx(&softc->tpc_timeout, &softc->ctl_lock, 0);
189 	callout_reset(&softc->tpc_timeout, hz, tpc_timeout, softc);
190 }
191 
192 void
193 ctl_tpc_shutdown(struct ctl_softc *softc)
194 {
195 	struct tpc_token *token;
196 
197 	callout_drain(&softc->tpc_timeout);
198 
199 	/* Free ROD tokens. */
200 	mtx_lock(&softc->tpc_lock);
201 	while ((token = TAILQ_FIRST(&softc->tpc_tokens)) != NULL) {
202 		TAILQ_REMOVE(&softc->tpc_tokens, token, links);
203 		free(token->params, M_CTL);
204 		free(token, M_CTL);
205 	}
206 	mtx_unlock(&softc->tpc_lock);
207 	mtx_destroy(&softc->tpc_lock);
208 }
209 
210 void
211 ctl_tpc_lun_init(struct ctl_lun *lun)
212 {
213 
214 	TAILQ_INIT(&lun->tpc_lists);
215 }
216 
217 void
218 ctl_tpc_lun_shutdown(struct ctl_lun *lun)
219 {
220 	struct ctl_softc *softc = lun->ctl_softc;
221 	struct tpc_list *list;
222 	struct tpc_token *token, *ttoken;
223 
224 	/* Free lists for this LUN. */
225 	while ((list = TAILQ_FIRST(&lun->tpc_lists)) != NULL) {
226 		TAILQ_REMOVE(&lun->tpc_lists, list, links);
227 		KASSERT(list->completed,
228 		    ("Not completed TPC (%p) on shutdown", list));
229 		free(list, M_CTL);
230 	}
231 
232 	/* Free ROD tokens for this LUN. */
233 	mtx_lock(&softc->tpc_lock);
234 	TAILQ_FOREACH_SAFE(token, &softc->tpc_tokens, links, ttoken) {
235 		if (token->lun != lun->lun || token->active)
236 			continue;
237 		TAILQ_REMOVE(&softc->tpc_tokens, token, links);
238 		free(token->params, M_CTL);
239 		free(token, M_CTL);
240 	}
241 	mtx_unlock(&softc->tpc_lock);
242 }
243 
244 int
245 ctl_inquiry_evpd_tpc(struct ctl_scsiio *ctsio, int alloc_len)
246 {
247 	struct scsi_vpd_tpc *tpc_ptr;
248 	struct scsi_vpd_tpc_descriptor *d_ptr;
249 	struct scsi_vpd_tpc_descriptor_bdrl *bdrl_ptr;
250 	struct scsi_vpd_tpc_descriptor_sc *sc_ptr;
251 	struct scsi_vpd_tpc_descriptor_sc_descr *scd_ptr;
252 	struct scsi_vpd_tpc_descriptor_pd *pd_ptr;
253 	struct scsi_vpd_tpc_descriptor_sd *sd_ptr;
254 	struct scsi_vpd_tpc_descriptor_sdid *sdid_ptr;
255 	struct scsi_vpd_tpc_descriptor_rtf *rtf_ptr;
256 	struct scsi_vpd_tpc_descriptor_rtf_block *rtfb_ptr;
257 	struct scsi_vpd_tpc_descriptor_srt *srt_ptr;
258 	struct scsi_vpd_tpc_descriptor_srtd *srtd_ptr;
259 	struct scsi_vpd_tpc_descriptor_gco *gco_ptr;
260 	struct ctl_lun *lun;
261 	int data_len;
262 
263 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
264 
265 	data_len = sizeof(struct scsi_vpd_tpc) +
266 	    sizeof(struct scsi_vpd_tpc_descriptor_bdrl) +
267 	    roundup2(sizeof(struct scsi_vpd_tpc_descriptor_sc) +
268 	     2 * sizeof(struct scsi_vpd_tpc_descriptor_sc_descr) + 11, 4) +
269 	    sizeof(struct scsi_vpd_tpc_descriptor_pd) +
270 	    roundup2(sizeof(struct scsi_vpd_tpc_descriptor_sd) + 4, 4) +
271 	    roundup2(sizeof(struct scsi_vpd_tpc_descriptor_sdid) + 2, 4) +
272 	    sizeof(struct scsi_vpd_tpc_descriptor_rtf) +
273 	     sizeof(struct scsi_vpd_tpc_descriptor_rtf_block) +
274 	    sizeof(struct scsi_vpd_tpc_descriptor_srt) +
275 	     2*sizeof(struct scsi_vpd_tpc_descriptor_srtd) +
276 	    sizeof(struct scsi_vpd_tpc_descriptor_gco);
277 
278 	ctsio->kern_data_ptr = malloc(data_len, M_CTL, M_WAITOK | M_ZERO);
279 	tpc_ptr = (struct scsi_vpd_tpc *)ctsio->kern_data_ptr;
280 	ctsio->kern_sg_entries = 0;
281 
282 	if (data_len < alloc_len) {
283 		ctsio->residual = alloc_len - data_len;
284 		ctsio->kern_data_len = data_len;
285 		ctsio->kern_total_len = data_len;
286 	} else {
287 		ctsio->residual = 0;
288 		ctsio->kern_data_len = alloc_len;
289 		ctsio->kern_total_len = alloc_len;
290 	}
291 	ctsio->kern_data_resid = 0;
292 	ctsio->kern_rel_offset = 0;
293 	ctsio->kern_sg_entries = 0;
294 
295 	/*
296 	 * The control device is always connected.  The disk device, on the
297 	 * other hand, may not be online all the time.
298 	 */
299 	if (lun != NULL)
300 		tpc_ptr->device = (SID_QUAL_LU_CONNECTED << 5) |
301 				     lun->be_lun->lun_type;
302 	else
303 		tpc_ptr->device = (SID_QUAL_LU_OFFLINE << 5) | T_DIRECT;
304 	tpc_ptr->page_code = SVPD_SCSI_TPC;
305 	scsi_ulto2b(data_len - 4, tpc_ptr->page_length);
306 
307 	/* Block Device ROD Limits */
308 	d_ptr = (struct scsi_vpd_tpc_descriptor *)&tpc_ptr->descr[0];
309 	bdrl_ptr = (struct scsi_vpd_tpc_descriptor_bdrl *)d_ptr;
310 	scsi_ulto2b(SVPD_TPC_BDRL, bdrl_ptr->desc_type);
311 	scsi_ulto2b(sizeof(*bdrl_ptr) - 4, bdrl_ptr->desc_length);
312 	scsi_ulto2b(TPC_MAX_SEGS, bdrl_ptr->maximum_ranges);
313 	scsi_ulto4b(TPC_MAX_TOKEN_TIMEOUT,
314 	    bdrl_ptr->maximum_inactivity_timeout);
315 	scsi_ulto4b(TPC_DFL_TOKEN_TIMEOUT,
316 	    bdrl_ptr->default_inactivity_timeout);
317 	scsi_u64to8b(0, bdrl_ptr->maximum_token_transfer_size);
318 	scsi_u64to8b(0, bdrl_ptr->optimal_transfer_count);
319 
320 	/* Supported commands */
321 	d_ptr = (struct scsi_vpd_tpc_descriptor *)
322 	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
323 	sc_ptr = (struct scsi_vpd_tpc_descriptor_sc *)d_ptr;
324 	scsi_ulto2b(SVPD_TPC_SC, sc_ptr->desc_type);
325 	sc_ptr->list_length = 2 * sizeof(*scd_ptr) + 11;
326 	scsi_ulto2b(roundup2(1 + sc_ptr->list_length, 4), sc_ptr->desc_length);
327 	scd_ptr = &sc_ptr->descr[0];
328 	scd_ptr->opcode = EXTENDED_COPY;
329 	scd_ptr->sa_length = 5;
330 	scd_ptr->supported_service_actions[0] = EC_EC_LID1;
331 	scd_ptr->supported_service_actions[1] = EC_EC_LID4;
332 	scd_ptr->supported_service_actions[2] = EC_PT;
333 	scd_ptr->supported_service_actions[3] = EC_WUT;
334 	scd_ptr->supported_service_actions[4] = EC_COA;
335 	scd_ptr = (struct scsi_vpd_tpc_descriptor_sc_descr *)
336 	    &scd_ptr->supported_service_actions[scd_ptr->sa_length];
337 	scd_ptr->opcode = RECEIVE_COPY_STATUS;
338 	scd_ptr->sa_length = 6;
339 	scd_ptr->supported_service_actions[0] = RCS_RCS_LID1;
340 	scd_ptr->supported_service_actions[1] = RCS_RCFD;
341 	scd_ptr->supported_service_actions[2] = RCS_RCS_LID4;
342 	scd_ptr->supported_service_actions[3] = RCS_RCOP;
343 	scd_ptr->supported_service_actions[4] = RCS_RRTI;
344 	scd_ptr->supported_service_actions[5] = RCS_RART;
345 
346 	/* Parameter data. */
347 	d_ptr = (struct scsi_vpd_tpc_descriptor *)
348 	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
349 	pd_ptr = (struct scsi_vpd_tpc_descriptor_pd *)d_ptr;
350 	scsi_ulto2b(SVPD_TPC_PD, pd_ptr->desc_type);
351 	scsi_ulto2b(sizeof(*pd_ptr) - 4, pd_ptr->desc_length);
352 	scsi_ulto2b(TPC_MAX_CSCDS, pd_ptr->maximum_cscd_descriptor_count);
353 	scsi_ulto2b(TPC_MAX_SEGS, pd_ptr->maximum_segment_descriptor_count);
354 	scsi_ulto4b(TPC_MAX_LIST, pd_ptr->maximum_descriptor_list_length);
355 	scsi_ulto4b(TPC_MAX_INLINE, pd_ptr->maximum_inline_data_length);
356 
357 	/* Supported Descriptors */
358 	d_ptr = (struct scsi_vpd_tpc_descriptor *)
359 	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
360 	sd_ptr = (struct scsi_vpd_tpc_descriptor_sd *)d_ptr;
361 	scsi_ulto2b(SVPD_TPC_SD, sd_ptr->desc_type);
362 	scsi_ulto2b(roundup2(sizeof(*sd_ptr) - 4 + 4, 4), sd_ptr->desc_length);
363 	sd_ptr->list_length = 4;
364 	sd_ptr->supported_descriptor_codes[0] = EC_SEG_B2B;
365 	sd_ptr->supported_descriptor_codes[1] = EC_SEG_VERIFY;
366 	sd_ptr->supported_descriptor_codes[2] = EC_SEG_REGISTER_KEY;
367 	sd_ptr->supported_descriptor_codes[3] = EC_CSCD_ID;
368 
369 	/* Supported CSCD Descriptor IDs */
370 	d_ptr = (struct scsi_vpd_tpc_descriptor *)
371 	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
372 	sdid_ptr = (struct scsi_vpd_tpc_descriptor_sdid *)d_ptr;
373 	scsi_ulto2b(SVPD_TPC_SDID, sdid_ptr->desc_type);
374 	scsi_ulto2b(roundup2(sizeof(*sdid_ptr) - 4 + 2, 4), sdid_ptr->desc_length);
375 	scsi_ulto2b(2, sdid_ptr->list_length);
376 	scsi_ulto2b(0xffff, &sdid_ptr->supported_descriptor_ids[0]);
377 
378 	/* ROD Token Features */
379 	d_ptr = (struct scsi_vpd_tpc_descriptor *)
380 	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
381 	rtf_ptr = (struct scsi_vpd_tpc_descriptor_rtf *)d_ptr;
382 	scsi_ulto2b(SVPD_TPC_RTF, rtf_ptr->desc_type);
383 	scsi_ulto2b(sizeof(*rtf_ptr) - 4 + sizeof(*rtfb_ptr), rtf_ptr->desc_length);
384 	rtf_ptr->remote_tokens = 0;
385 	scsi_ulto4b(TPC_MIN_TOKEN_TIMEOUT, rtf_ptr->minimum_token_lifetime);
386 	scsi_ulto4b(UINT32_MAX, rtf_ptr->maximum_token_lifetime);
387 	scsi_ulto4b(TPC_MAX_TOKEN_TIMEOUT,
388 	    rtf_ptr->maximum_token_inactivity_timeout);
389 	scsi_ulto2b(sizeof(*rtfb_ptr), rtf_ptr->type_specific_features_length);
390 	rtfb_ptr = (struct scsi_vpd_tpc_descriptor_rtf_block *)
391 	    &rtf_ptr->type_specific_features;
392 	rtfb_ptr->type_format = SVPD_TPC_RTF_BLOCK;
393 	scsi_ulto2b(sizeof(*rtfb_ptr) - 4, rtfb_ptr->desc_length);
394 	scsi_ulto2b(0, rtfb_ptr->optimal_length_granularity);
395 	scsi_u64to8b(0, rtfb_ptr->maximum_bytes);
396 	scsi_u64to8b(0, rtfb_ptr->optimal_bytes);
397 	scsi_u64to8b(UINT64_MAX, rtfb_ptr->optimal_bytes_to_token_per_segment);
398 	scsi_u64to8b(TPC_MAX_IOCHUNK_SIZE,
399 	    rtfb_ptr->optimal_bytes_from_token_per_segment);
400 
401 	/* Supported ROD Tokens */
402 	d_ptr = (struct scsi_vpd_tpc_descriptor *)
403 	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
404 	srt_ptr = (struct scsi_vpd_tpc_descriptor_srt *)d_ptr;
405 	scsi_ulto2b(SVPD_TPC_SRT, srt_ptr->desc_type);
406 	scsi_ulto2b(sizeof(*srt_ptr) - 4 + 2*sizeof(*srtd_ptr), srt_ptr->desc_length);
407 	scsi_ulto2b(2*sizeof(*srtd_ptr), srt_ptr->rod_type_descriptors_length);
408 	srtd_ptr = (struct scsi_vpd_tpc_descriptor_srtd *)
409 	    &srt_ptr->rod_type_descriptors;
410 	scsi_ulto4b(ROD_TYPE_AUR, srtd_ptr->rod_type);
411 	srtd_ptr->flags = SVPD_TPC_SRTD_TIN | SVPD_TPC_SRTD_TOUT;
412 	scsi_ulto2b(0, srtd_ptr->preference_indicator);
413 	srtd_ptr++;
414 	scsi_ulto4b(ROD_TYPE_BLOCK_ZERO, srtd_ptr->rod_type);
415 	srtd_ptr->flags = SVPD_TPC_SRTD_TIN;
416 	scsi_ulto2b(0, srtd_ptr->preference_indicator);
417 
418 	/* General Copy Operations */
419 	d_ptr = (struct scsi_vpd_tpc_descriptor *)
420 	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
421 	gco_ptr = (struct scsi_vpd_tpc_descriptor_gco *)d_ptr;
422 	scsi_ulto2b(SVPD_TPC_GCO, gco_ptr->desc_type);
423 	scsi_ulto2b(sizeof(*gco_ptr) - 4, gco_ptr->desc_length);
424 	scsi_ulto4b(TPC_MAX_LISTS, gco_ptr->total_concurrent_copies);
425 	scsi_ulto4b(TPC_MAX_LISTS, gco_ptr->maximum_identified_concurrent_copies);
426 	scsi_ulto4b(TPC_MAX_SEG, gco_ptr->maximum_segment_length);
427 	gco_ptr->data_segment_granularity = 0;
428 	gco_ptr->inline_data_granularity = 0;
429 
430 	ctl_set_success(ctsio);
431 	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
432 	ctsio->be_move_done = ctl_config_move_done;
433 	ctl_datamove((union ctl_io *)ctsio);
434 
435 	return (CTL_RETVAL_COMPLETE);
436 }
437 
438 int
439 ctl_receive_copy_operating_parameters(struct ctl_scsiio *ctsio)
440 {
441 	struct scsi_receive_copy_operating_parameters *cdb;
442 	struct scsi_receive_copy_operating_parameters_data *data;
443 	int retval;
444 	int alloc_len, total_len;
445 
446 	CTL_DEBUG_PRINT(("ctl_report_supported_tmf\n"));
447 
448 	cdb = (struct scsi_receive_copy_operating_parameters *)ctsio->cdb;
449 
450 	retval = CTL_RETVAL_COMPLETE;
451 
452 	total_len = sizeof(*data) + 4;
453 	alloc_len = scsi_4btoul(cdb->length);
454 
455 	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
456 
457 	ctsio->kern_sg_entries = 0;
458 
459 	if (total_len < alloc_len) {
460 		ctsio->residual = alloc_len - total_len;
461 		ctsio->kern_data_len = total_len;
462 		ctsio->kern_total_len = total_len;
463 	} else {
464 		ctsio->residual = 0;
465 		ctsio->kern_data_len = alloc_len;
466 		ctsio->kern_total_len = alloc_len;
467 	}
468 	ctsio->kern_data_resid = 0;
469 	ctsio->kern_rel_offset = 0;
470 
471 	data = (struct scsi_receive_copy_operating_parameters_data *)ctsio->kern_data_ptr;
472 	scsi_ulto4b(sizeof(*data) - 4 + 4, data->length);
473 	data->snlid = RCOP_SNLID;
474 	scsi_ulto2b(TPC_MAX_CSCDS, data->maximum_cscd_descriptor_count);
475 	scsi_ulto2b(TPC_MAX_SEGS, data->maximum_segment_descriptor_count);
476 	scsi_ulto4b(TPC_MAX_LIST, data->maximum_descriptor_list_length);
477 	scsi_ulto4b(TPC_MAX_SEG, data->maximum_segment_length);
478 	scsi_ulto4b(TPC_MAX_INLINE, data->maximum_inline_data_length);
479 	scsi_ulto4b(0, data->held_data_limit);
480 	scsi_ulto4b(0, data->maximum_stream_device_transfer_size);
481 	scsi_ulto2b(TPC_MAX_LISTS, data->total_concurrent_copies);
482 	data->maximum_concurrent_copies = TPC_MAX_LISTS;
483 	data->data_segment_granularity = 0;
484 	data->inline_data_granularity = 0;
485 	data->held_data_granularity = 0;
486 	data->implemented_descriptor_list_length = 4;
487 	data->list_of_implemented_descriptor_type_codes[0] = EC_SEG_B2B;
488 	data->list_of_implemented_descriptor_type_codes[1] = EC_SEG_VERIFY;
489 	data->list_of_implemented_descriptor_type_codes[2] = EC_SEG_REGISTER_KEY;
490 	data->list_of_implemented_descriptor_type_codes[3] = EC_CSCD_ID;
491 
492 	ctl_set_success(ctsio);
493 	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
494 	ctsio->be_move_done = ctl_config_move_done;
495 	ctl_datamove((union ctl_io *)ctsio);
496 	return (retval);
497 }
498 
499 static struct tpc_list *
500 tpc_find_list(struct ctl_lun *lun, uint32_t list_id, uint32_t init_idx)
501 {
502 	struct tpc_list *list;
503 
504 	mtx_assert(&lun->lun_lock, MA_OWNED);
505 	TAILQ_FOREACH(list, &lun->tpc_lists, links) {
506 		if ((list->flags & EC_LIST_ID_USAGE_MASK) !=
507 		     EC_LIST_ID_USAGE_NONE && list->list_id == list_id &&
508 		    list->init_idx == init_idx)
509 			break;
510 	}
511 	return (list);
512 }
513 
514 int
515 ctl_receive_copy_status_lid1(struct ctl_scsiio *ctsio)
516 {
517 	struct ctl_lun *lun;
518 	struct scsi_receive_copy_status_lid1 *cdb;
519 	struct scsi_receive_copy_status_lid1_data *data;
520 	struct tpc_list *list;
521 	struct tpc_list list_copy;
522 	int retval;
523 	int alloc_len, total_len;
524 	uint32_t list_id;
525 
526 	CTL_DEBUG_PRINT(("ctl_receive_copy_status_lid1\n"));
527 
528 	cdb = (struct scsi_receive_copy_status_lid1 *)ctsio->cdb;
529 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
530 
531 	retval = CTL_RETVAL_COMPLETE;
532 
533 	list_id = cdb->list_identifier;
534 	mtx_lock(&lun->lun_lock);
535 	list = tpc_find_list(lun, list_id,
536 	    ctl_get_initindex(&ctsio->io_hdr.nexus));
537 	if (list == NULL) {
538 		mtx_unlock(&lun->lun_lock);
539 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
540 		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
541 		    /*bit*/ 0);
542 		ctl_done((union ctl_io *)ctsio);
543 		return (retval);
544 	}
545 	list_copy = *list;
546 	if (list->completed) {
547 		TAILQ_REMOVE(&lun->tpc_lists, list, links);
548 		free(list, M_CTL);
549 	}
550 	mtx_unlock(&lun->lun_lock);
551 
552 	total_len = sizeof(*data);
553 	alloc_len = scsi_4btoul(cdb->length);
554 
555 	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
556 
557 	ctsio->kern_sg_entries = 0;
558 
559 	if (total_len < alloc_len) {
560 		ctsio->residual = alloc_len - total_len;
561 		ctsio->kern_data_len = total_len;
562 		ctsio->kern_total_len = total_len;
563 	} else {
564 		ctsio->residual = 0;
565 		ctsio->kern_data_len = alloc_len;
566 		ctsio->kern_total_len = alloc_len;
567 	}
568 	ctsio->kern_data_resid = 0;
569 	ctsio->kern_rel_offset = 0;
570 
571 	data = (struct scsi_receive_copy_status_lid1_data *)ctsio->kern_data_ptr;
572 	scsi_ulto4b(sizeof(*data) - 4, data->available_data);
573 	if (list_copy.completed) {
574 		if (list_copy.error || list_copy.abort)
575 			data->copy_command_status = RCS_CCS_ERROR;
576 		else
577 			data->copy_command_status = RCS_CCS_COMPLETED;
578 	} else
579 		data->copy_command_status = RCS_CCS_INPROG;
580 	scsi_ulto2b(list_copy.curseg, data->segments_processed);
581 	if (list_copy.curbytes <= UINT32_MAX) {
582 		data->transfer_count_units = RCS_TC_BYTES;
583 		scsi_ulto4b(list_copy.curbytes, data->transfer_count);
584 	} else {
585 		data->transfer_count_units = RCS_TC_MBYTES;
586 		scsi_ulto4b(list_copy.curbytes >> 20, data->transfer_count);
587 	}
588 
589 	ctl_set_success(ctsio);
590 	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
591 	ctsio->be_move_done = ctl_config_move_done;
592 	ctl_datamove((union ctl_io *)ctsio);
593 	return (retval);
594 }
595 
596 int
597 ctl_receive_copy_failure_details(struct ctl_scsiio *ctsio)
598 {
599 	struct ctl_lun *lun;
600 	struct scsi_receive_copy_failure_details *cdb;
601 	struct scsi_receive_copy_failure_details_data *data;
602 	struct tpc_list *list;
603 	struct tpc_list list_copy;
604 	int retval;
605 	int alloc_len, total_len;
606 	uint32_t list_id;
607 
608 	CTL_DEBUG_PRINT(("ctl_receive_copy_failure_details\n"));
609 
610 	cdb = (struct scsi_receive_copy_failure_details *)ctsio->cdb;
611 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
612 
613 	retval = CTL_RETVAL_COMPLETE;
614 
615 	list_id = cdb->list_identifier;
616 	mtx_lock(&lun->lun_lock);
617 	list = tpc_find_list(lun, list_id,
618 	    ctl_get_initindex(&ctsio->io_hdr.nexus));
619 	if (list == NULL || !list->completed) {
620 		mtx_unlock(&lun->lun_lock);
621 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
622 		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
623 		    /*bit*/ 0);
624 		ctl_done((union ctl_io *)ctsio);
625 		return (retval);
626 	}
627 	list_copy = *list;
628 	TAILQ_REMOVE(&lun->tpc_lists, list, links);
629 	free(list, M_CTL);
630 	mtx_unlock(&lun->lun_lock);
631 
632 	total_len = sizeof(*data) + list_copy.sense_len;
633 	alloc_len = scsi_4btoul(cdb->length);
634 
635 	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
636 
637 	ctsio->kern_sg_entries = 0;
638 
639 	if (total_len < alloc_len) {
640 		ctsio->residual = alloc_len - total_len;
641 		ctsio->kern_data_len = total_len;
642 		ctsio->kern_total_len = total_len;
643 	} else {
644 		ctsio->residual = 0;
645 		ctsio->kern_data_len = alloc_len;
646 		ctsio->kern_total_len = alloc_len;
647 	}
648 	ctsio->kern_data_resid = 0;
649 	ctsio->kern_rel_offset = 0;
650 
651 	data = (struct scsi_receive_copy_failure_details_data *)ctsio->kern_data_ptr;
652 	if (list_copy.completed && (list_copy.error || list_copy.abort)) {
653 		scsi_ulto4b(sizeof(*data) - 4 + list_copy.sense_len,
654 		    data->available_data);
655 		data->copy_command_status = RCS_CCS_ERROR;
656 	} else
657 		scsi_ulto4b(0, data->available_data);
658 	scsi_ulto2b(list_copy.sense_len, data->sense_data_length);
659 	memcpy(data->sense_data, &list_copy.sense_data, list_copy.sense_len);
660 
661 	ctl_set_success(ctsio);
662 	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
663 	ctsio->be_move_done = ctl_config_move_done;
664 	ctl_datamove((union ctl_io *)ctsio);
665 	return (retval);
666 }
667 
668 int
669 ctl_receive_copy_status_lid4(struct ctl_scsiio *ctsio)
670 {
671 	struct ctl_lun *lun;
672 	struct scsi_receive_copy_status_lid4 *cdb;
673 	struct scsi_receive_copy_status_lid4_data *data;
674 	struct tpc_list *list;
675 	struct tpc_list list_copy;
676 	int retval;
677 	int alloc_len, total_len;
678 	uint32_t list_id;
679 
680 	CTL_DEBUG_PRINT(("ctl_receive_copy_status_lid4\n"));
681 
682 	cdb = (struct scsi_receive_copy_status_lid4 *)ctsio->cdb;
683 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
684 
685 	retval = CTL_RETVAL_COMPLETE;
686 
687 	list_id = scsi_4btoul(cdb->list_identifier);
688 	mtx_lock(&lun->lun_lock);
689 	list = tpc_find_list(lun, list_id,
690 	    ctl_get_initindex(&ctsio->io_hdr.nexus));
691 	if (list == NULL) {
692 		mtx_unlock(&lun->lun_lock);
693 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
694 		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
695 		    /*bit*/ 0);
696 		ctl_done((union ctl_io *)ctsio);
697 		return (retval);
698 	}
699 	list_copy = *list;
700 	if (list->completed) {
701 		TAILQ_REMOVE(&lun->tpc_lists, list, links);
702 		free(list, M_CTL);
703 	}
704 	mtx_unlock(&lun->lun_lock);
705 
706 	total_len = sizeof(*data) + list_copy.sense_len;
707 	alloc_len = scsi_4btoul(cdb->length);
708 
709 	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
710 
711 	ctsio->kern_sg_entries = 0;
712 
713 	if (total_len < alloc_len) {
714 		ctsio->residual = alloc_len - total_len;
715 		ctsio->kern_data_len = total_len;
716 		ctsio->kern_total_len = total_len;
717 	} else {
718 		ctsio->residual = 0;
719 		ctsio->kern_data_len = alloc_len;
720 		ctsio->kern_total_len = alloc_len;
721 	}
722 	ctsio->kern_data_resid = 0;
723 	ctsio->kern_rel_offset = 0;
724 
725 	data = (struct scsi_receive_copy_status_lid4_data *)ctsio->kern_data_ptr;
726 	scsi_ulto4b(sizeof(*data) - 4 + list_copy.sense_len,
727 	    data->available_data);
728 	data->response_to_service_action = list_copy.service_action;
729 	if (list_copy.completed) {
730 		if (list_copy.error)
731 			data->copy_command_status = RCS_CCS_ERROR;
732 		else if (list_copy.abort)
733 			data->copy_command_status = RCS_CCS_ABORTED;
734 		else
735 			data->copy_command_status = RCS_CCS_COMPLETED;
736 	} else
737 		data->copy_command_status = RCS_CCS_INPROG_FG;
738 	scsi_ulto2b(list_copy.curops, data->operation_counter);
739 	scsi_ulto4b(UINT32_MAX, data->estimated_status_update_delay);
740 	data->transfer_count_units = RCS_TC_BYTES;
741 	scsi_u64to8b(list_copy.curbytes, data->transfer_count);
742 	scsi_ulto2b(list_copy.curseg, data->segments_processed);
743 	data->length_of_the_sense_data_field = list_copy.sense_len;
744 	data->sense_data_length = list_copy.sense_len;
745 	memcpy(data->sense_data, &list_copy.sense_data, list_copy.sense_len);
746 
747 	ctl_set_success(ctsio);
748 	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
749 	ctsio->be_move_done = ctl_config_move_done;
750 	ctl_datamove((union ctl_io *)ctsio);
751 	return (retval);
752 }
753 
754 int
755 ctl_copy_operation_abort(struct ctl_scsiio *ctsio)
756 {
757 	struct ctl_lun *lun;
758 	struct scsi_copy_operation_abort *cdb;
759 	struct tpc_list *list;
760 	int retval;
761 	uint32_t list_id;
762 
763 	CTL_DEBUG_PRINT(("ctl_copy_operation_abort\n"));
764 
765 	cdb = (struct scsi_copy_operation_abort *)ctsio->cdb;
766 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
767 
768 	retval = CTL_RETVAL_COMPLETE;
769 
770 	list_id = scsi_4btoul(cdb->list_identifier);
771 	mtx_lock(&lun->lun_lock);
772 	list = tpc_find_list(lun, list_id,
773 	    ctl_get_initindex(&ctsio->io_hdr.nexus));
774 	if (list == NULL) {
775 		mtx_unlock(&lun->lun_lock);
776 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
777 		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
778 		    /*bit*/ 0);
779 		ctl_done((union ctl_io *)ctsio);
780 		return (retval);
781 	}
782 	list->abort = 1;
783 	mtx_unlock(&lun->lun_lock);
784 
785 	ctl_set_success(ctsio);
786 	ctl_done((union ctl_io *)ctsio);
787 	return (retval);
788 }
789 
790 static uint64_t
791 tpc_resolve(struct tpc_list *list, uint16_t idx, uint32_t *ss,
792     uint32_t *pb, uint32_t *pbo)
793 {
794 
795 	if (idx == 0xffff) {
796 		if (ss && list->lun->be_lun)
797 			*ss = list->lun->be_lun->blocksize;
798 		if (pb && list->lun->be_lun)
799 			*pb = list->lun->be_lun->blocksize <<
800 			    list->lun->be_lun->pblockexp;
801 		if (pbo && list->lun->be_lun)
802 			*pbo = list->lun->be_lun->blocksize *
803 			    list->lun->be_lun->pblockoff;
804 		return (list->lun->lun);
805 	}
806 	if (idx >= list->ncscd)
807 		return (UINT64_MAX);
808 	return (tpcl_resolve(list->lun->ctl_softc,
809 	    list->init_port, &list->cscd[idx], ss, pb, pbo));
810 }
811 
812 static int
813 tpc_process_b2b(struct tpc_list *list)
814 {
815 	struct scsi_ec_segment_b2b *seg;
816 	struct scsi_ec_cscd_dtsp *sdstp, *ddstp;
817 	struct tpc_io *tior, *tiow;
818 	struct runl run;
819 	uint64_t sl, dl;
820 	off_t srclba, dstlba, numbytes, donebytes, roundbytes;
821 	int numlba;
822 	uint32_t srcblock, dstblock, pb, pbo, adj;
823 	uint8_t csi[4];
824 
825 	scsi_ulto4b(list->curseg, csi);
826 	if (list->stage == 1) {
827 		while ((tior = TAILQ_FIRST(&list->allio)) != NULL) {
828 			TAILQ_REMOVE(&list->allio, tior, links);
829 			ctl_free_io(tior->io);
830 			free(tior, M_CTL);
831 		}
832 		free(list->buf, M_CTL);
833 		if (list->abort) {
834 			ctl_set_task_aborted(list->ctsio);
835 			return (CTL_RETVAL_ERROR);
836 		} else if (list->error) {
837 			ctl_set_sense(list->ctsio, /*current_error*/ 1,
838 			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
839 			    /*asc*/ 0x0d, /*ascq*/ 0x01,
840 			    SSD_ELEM_COMMAND, sizeof(csi), csi,
841 			    SSD_ELEM_NONE);
842 			return (CTL_RETVAL_ERROR);
843 		}
844 		list->cursectors += list->segsectors;
845 		list->curbytes += list->segbytes;
846 		return (CTL_RETVAL_COMPLETE);
847 	}
848 
849 	TAILQ_INIT(&list->allio);
850 	seg = (struct scsi_ec_segment_b2b *)list->seg[list->curseg];
851 	sl = tpc_resolve(list, scsi_2btoul(seg->src_cscd), &srcblock, NULL, NULL);
852 	dl = tpc_resolve(list, scsi_2btoul(seg->dst_cscd), &dstblock, &pb, &pbo);
853 	if (sl >= CTL_MAX_LUNS || dl >= CTL_MAX_LUNS) {
854 		ctl_set_sense(list->ctsio, /*current_error*/ 1,
855 		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
856 		    /*asc*/ 0x08, /*ascq*/ 0x04,
857 		    SSD_ELEM_COMMAND, sizeof(csi), csi,
858 		    SSD_ELEM_NONE);
859 		return (CTL_RETVAL_ERROR);
860 	}
861 	if (pbo > 0)
862 		pbo = pb - pbo;
863 	sdstp = &list->cscd[scsi_2btoul(seg->src_cscd)].dtsp;
864 	if (scsi_3btoul(sdstp->block_length) != 0)
865 		srcblock = scsi_3btoul(sdstp->block_length);
866 	ddstp = &list->cscd[scsi_2btoul(seg->dst_cscd)].dtsp;
867 	if (scsi_3btoul(ddstp->block_length) != 0)
868 		dstblock = scsi_3btoul(ddstp->block_length);
869 	numlba = scsi_2btoul(seg->number_of_blocks);
870 	if (seg->flags & EC_SEG_DC)
871 		numbytes = (off_t)numlba * dstblock;
872 	else
873 		numbytes = (off_t)numlba * srcblock;
874 	srclba = scsi_8btou64(seg->src_lba);
875 	dstlba = scsi_8btou64(seg->dst_lba);
876 
877 //	printf("Copy %ju bytes from %ju @ %ju to %ju @ %ju\n",
878 //	    (uintmax_t)numbytes, sl, scsi_8btou64(seg->src_lba),
879 //	    dl, scsi_8btou64(seg->dst_lba));
880 
881 	if (numbytes == 0)
882 		return (CTL_RETVAL_COMPLETE);
883 
884 	if (numbytes % srcblock != 0 || numbytes % dstblock != 0) {
885 		ctl_set_sense(list->ctsio, /*current_error*/ 1,
886 		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
887 		    /*asc*/ 0x26, /*ascq*/ 0x0A,
888 		    SSD_ELEM_COMMAND, sizeof(csi), csi,
889 		    SSD_ELEM_NONE);
890 		return (CTL_RETVAL_ERROR);
891 	}
892 
893 	list->buf = malloc(numbytes, M_CTL, M_WAITOK);
894 	list->segbytes = numbytes;
895 	list->segsectors = numbytes / dstblock;
896 	donebytes = 0;
897 	TAILQ_INIT(&run);
898 	list->tbdio = 0;
899 	while (donebytes < numbytes) {
900 		roundbytes = numbytes - donebytes;
901 		if (roundbytes > TPC_MAX_IO_SIZE) {
902 			roundbytes = TPC_MAX_IO_SIZE;
903 			roundbytes -= roundbytes % dstblock;
904 			if (pb > dstblock) {
905 				adj = (dstlba * dstblock + roundbytes - pbo) % pb;
906 				if (roundbytes > adj)
907 					roundbytes -= adj;
908 			}
909 		}
910 
911 		tior = malloc(sizeof(*tior), M_CTL, M_WAITOK | M_ZERO);
912 		TAILQ_INIT(&tior->run);
913 		tior->list = list;
914 		TAILQ_INSERT_TAIL(&list->allio, tior, links);
915 		tior->io = tpcl_alloc_io();
916 		ctl_scsi_read_write(tior->io,
917 				    /*data_ptr*/ &list->buf[donebytes],
918 				    /*data_len*/ roundbytes,
919 				    /*read_op*/ 1,
920 				    /*byte2*/ 0,
921 				    /*minimum_cdb_size*/ 0,
922 				    /*lba*/ srclba,
923 				    /*num_blocks*/ roundbytes / srcblock,
924 				    /*tag_type*/ CTL_TAG_SIMPLE,
925 				    /*control*/ 0);
926 		tior->io->io_hdr.retries = 3;
927 		tior->lun = sl;
928 		tior->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tior;
929 
930 		tiow = malloc(sizeof(*tior), M_CTL, M_WAITOK | M_ZERO);
931 		TAILQ_INIT(&tiow->run);
932 		tiow->list = list;
933 		TAILQ_INSERT_TAIL(&list->allio, tiow, links);
934 		tiow->io = tpcl_alloc_io();
935 		ctl_scsi_read_write(tiow->io,
936 				    /*data_ptr*/ &list->buf[donebytes],
937 				    /*data_len*/ roundbytes,
938 				    /*read_op*/ 0,
939 				    /*byte2*/ 0,
940 				    /*minimum_cdb_size*/ 0,
941 				    /*lba*/ dstlba,
942 				    /*num_blocks*/ roundbytes / dstblock,
943 				    /*tag_type*/ CTL_TAG_SIMPLE,
944 				    /*control*/ 0);
945 		tiow->io->io_hdr.retries = 3;
946 		tiow->lun = dl;
947 		tiow->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tiow;
948 
949 		TAILQ_INSERT_TAIL(&tior->run, tiow, rlinks);
950 		TAILQ_INSERT_TAIL(&run, tior, rlinks);
951 		list->tbdio++;
952 		donebytes += roundbytes;
953 		srclba += roundbytes / srcblock;
954 		dstlba += roundbytes / dstblock;
955 	}
956 
957 	while ((tior = TAILQ_FIRST(&run)) != NULL) {
958 		TAILQ_REMOVE(&run, tior, rlinks);
959 		if (tpcl_queue(tior->io, tior->lun) != CTL_RETVAL_COMPLETE)
960 			panic("tpcl_queue() error");
961 	}
962 
963 	list->stage++;
964 	return (CTL_RETVAL_QUEUED);
965 }
966 
967 static int
968 tpc_process_verify(struct tpc_list *list)
969 {
970 	struct scsi_ec_segment_verify *seg;
971 	struct tpc_io *tio;
972 	uint64_t sl;
973 	uint8_t csi[4];
974 
975 	scsi_ulto4b(list->curseg, csi);
976 	if (list->stage == 1) {
977 		while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
978 			TAILQ_REMOVE(&list->allio, tio, links);
979 			ctl_free_io(tio->io);
980 			free(tio, M_CTL);
981 		}
982 		if (list->abort) {
983 			ctl_set_task_aborted(list->ctsio);
984 			return (CTL_RETVAL_ERROR);
985 		} else if (list->error) {
986 			ctl_set_sense(list->ctsio, /*current_error*/ 1,
987 			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
988 			    /*asc*/ 0x0d, /*ascq*/ 0x01,
989 			    SSD_ELEM_COMMAND, sizeof(csi), csi,
990 			    SSD_ELEM_NONE);
991 			return (CTL_RETVAL_ERROR);
992 		} else
993 			return (CTL_RETVAL_COMPLETE);
994 	}
995 
996 	TAILQ_INIT(&list->allio);
997 	seg = (struct scsi_ec_segment_verify *)list->seg[list->curseg];
998 	sl = tpc_resolve(list, scsi_2btoul(seg->src_cscd), NULL, NULL, NULL);
999 	if (sl >= CTL_MAX_LUNS) {
1000 		ctl_set_sense(list->ctsio, /*current_error*/ 1,
1001 		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1002 		    /*asc*/ 0x08, /*ascq*/ 0x04,
1003 		    SSD_ELEM_COMMAND, sizeof(csi), csi,
1004 		    SSD_ELEM_NONE);
1005 		return (CTL_RETVAL_ERROR);
1006 	}
1007 
1008 //	printf("Verify %ju\n", sl);
1009 
1010 	if ((seg->tur & 0x01) == 0)
1011 		return (CTL_RETVAL_COMPLETE);
1012 
1013 	list->tbdio = 1;
1014 	tio = malloc(sizeof(*tio), M_CTL, M_WAITOK | M_ZERO);
1015 	TAILQ_INIT(&tio->run);
1016 	tio->list = list;
1017 	TAILQ_INSERT_TAIL(&list->allio, tio, links);
1018 	tio->io = tpcl_alloc_io();
1019 	ctl_scsi_tur(tio->io, /*tag_type*/ CTL_TAG_SIMPLE, /*control*/ 0);
1020 	tio->io->io_hdr.retries = 3;
1021 	tio->lun = sl;
1022 	tio->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tio;
1023 	list->stage++;
1024 	if (tpcl_queue(tio->io, tio->lun) != CTL_RETVAL_COMPLETE)
1025 		panic("tpcl_queue() error");
1026 	return (CTL_RETVAL_QUEUED);
1027 }
1028 
1029 static int
1030 tpc_process_register_key(struct tpc_list *list)
1031 {
1032 	struct scsi_ec_segment_register_key *seg;
1033 	struct tpc_io *tio;
1034 	uint64_t dl;
1035 	int datalen;
1036 	uint8_t csi[4];
1037 
1038 	scsi_ulto4b(list->curseg, csi);
1039 	if (list->stage == 1) {
1040 		while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
1041 			TAILQ_REMOVE(&list->allio, tio, links);
1042 			ctl_free_io(tio->io);
1043 			free(tio, M_CTL);
1044 		}
1045 		free(list->buf, M_CTL);
1046 		if (list->abort) {
1047 			ctl_set_task_aborted(list->ctsio);
1048 			return (CTL_RETVAL_ERROR);
1049 		} else if (list->error) {
1050 			ctl_set_sense(list->ctsio, /*current_error*/ 1,
1051 			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1052 			    /*asc*/ 0x0d, /*ascq*/ 0x01,
1053 			    SSD_ELEM_COMMAND, sizeof(csi), csi,
1054 			    SSD_ELEM_NONE);
1055 			return (CTL_RETVAL_ERROR);
1056 		} else
1057 			return (CTL_RETVAL_COMPLETE);
1058 	}
1059 
1060 	TAILQ_INIT(&list->allio);
1061 	seg = (struct scsi_ec_segment_register_key *)list->seg[list->curseg];
1062 	dl = tpc_resolve(list, scsi_2btoul(seg->dst_cscd), NULL, NULL, NULL);
1063 	if (dl >= CTL_MAX_LUNS) {
1064 		ctl_set_sense(list->ctsio, /*current_error*/ 1,
1065 		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1066 		    /*asc*/ 0x08, /*ascq*/ 0x04,
1067 		    SSD_ELEM_COMMAND, sizeof(csi), csi,
1068 		    SSD_ELEM_NONE);
1069 		return (CTL_RETVAL_ERROR);
1070 	}
1071 
1072 //	printf("Register Key %ju\n", dl);
1073 
1074 	list->tbdio = 1;
1075 	tio = malloc(sizeof(*tio), M_CTL, M_WAITOK | M_ZERO);
1076 	TAILQ_INIT(&tio->run);
1077 	tio->list = list;
1078 	TAILQ_INSERT_TAIL(&list->allio, tio, links);
1079 	tio->io = tpcl_alloc_io();
1080 	datalen = sizeof(struct scsi_per_res_out_parms);
1081 	list->buf = malloc(datalen, M_CTL, M_WAITOK);
1082 	ctl_scsi_persistent_res_out(tio->io,
1083 	    list->buf, datalen, SPRO_REGISTER, -1,
1084 	    scsi_8btou64(seg->res_key), scsi_8btou64(seg->sa_res_key),
1085 	    /*tag_type*/ CTL_TAG_SIMPLE, /*control*/ 0);
1086 	tio->io->io_hdr.retries = 3;
1087 	tio->lun = dl;
1088 	tio->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tio;
1089 	list->stage++;
1090 	if (tpcl_queue(tio->io, tio->lun) != CTL_RETVAL_COMPLETE)
1091 		panic("tpcl_queue() error");
1092 	return (CTL_RETVAL_QUEUED);
1093 }
1094 
1095 static off_t
1096 tpc_ranges_length(struct scsi_range_desc *range, int nrange)
1097 {
1098 	off_t length = 0;
1099 	int r;
1100 
1101 	for (r = 0; r < nrange; r++)
1102 		length += scsi_4btoul(range[r].length);
1103 	return (length);
1104 }
1105 
1106 static int
1107 tpc_check_ranges_l(struct scsi_range_desc *range, int nrange, uint64_t maxlba)
1108 {
1109 	uint64_t b1;
1110 	uint32_t l1;
1111 	int i;
1112 
1113 	for (i = 0; i < nrange; i++) {
1114 		b1 = scsi_8btou64(range[i].lba);
1115 		l1 = scsi_4btoul(range[i].length);
1116 		if (b1 + l1 < b1 || b1 + l1 > maxlba + 1)
1117 			return (-1);
1118 	}
1119 	return (0);
1120 }
1121 
1122 static int
1123 tpc_check_ranges_x(struct scsi_range_desc *range, int nrange)
1124 {
1125 	uint64_t b1, b2;
1126 	uint32_t l1, l2;
1127 	int i, j;
1128 
1129 	for (i = 0; i < nrange - 1; i++) {
1130 		b1 = scsi_8btou64(range[i].lba);
1131 		l1 = scsi_4btoul(range[i].length);
1132 		for (j = i + 1; j < nrange; j++) {
1133 			b2 = scsi_8btou64(range[j].lba);
1134 			l2 = scsi_4btoul(range[j].length);
1135 			if (b1 + l1 > b2 && b2 + l2 > b1)
1136 				return (-1);
1137 		}
1138 	}
1139 	return (0);
1140 }
1141 
1142 static int
1143 tpc_skip_ranges(struct scsi_range_desc *range, int nrange, off_t skip,
1144     int *srange, off_t *soffset)
1145 {
1146 	off_t off;
1147 	int r;
1148 
1149 	r = 0;
1150 	off = 0;
1151 	while (r < nrange) {
1152 		if (skip - off < scsi_4btoul(range[r].length)) {
1153 			*srange = r;
1154 			*soffset = skip - off;
1155 			return (0);
1156 		}
1157 		off += scsi_4btoul(range[r].length);
1158 		r++;
1159 	}
1160 	return (-1);
1161 }
1162 
1163 static int
1164 tpc_process_wut(struct tpc_list *list)
1165 {
1166 	struct tpc_io *tio, *tior, *tiow;
1167 	struct runl run;
1168 	int drange, srange;
1169 	off_t doffset, soffset;
1170 	off_t srclba, dstlba, numbytes, donebytes, roundbytes;
1171 	uint32_t srcblock, dstblock, pb, pbo, adj;
1172 
1173 	if (list->stage > 0) {
1174 		/* Cleanup after previous rounds. */
1175 		while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
1176 			TAILQ_REMOVE(&list->allio, tio, links);
1177 			ctl_free_io(tio->io);
1178 			free(tio, M_CTL);
1179 		}
1180 		free(list->buf, M_CTL);
1181 		if (list->abort) {
1182 			ctl_set_task_aborted(list->ctsio);
1183 			return (CTL_RETVAL_ERROR);
1184 		} else if (list->error) {
1185 			ctl_set_sense(list->ctsio, /*current_error*/ 1,
1186 			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1187 			    /*asc*/ 0x0d, /*ascq*/ 0x01, SSD_ELEM_NONE);
1188 			return (CTL_RETVAL_ERROR);
1189 		}
1190 		list->cursectors += list->segsectors;
1191 		list->curbytes += list->segbytes;
1192 	}
1193 
1194 	/* Check where we are on destination ranges list. */
1195 	if (tpc_skip_ranges(list->range, list->nrange, list->cursectors,
1196 	    &drange, &doffset) != 0)
1197 		return (CTL_RETVAL_COMPLETE);
1198 	dstblock = list->lun->be_lun->blocksize;
1199 	pb = dstblock << list->lun->be_lun->pblockexp;
1200 	if (list->lun->be_lun->pblockoff > 0)
1201 		pbo = pb - dstblock * list->lun->be_lun->pblockoff;
1202 	else
1203 		pbo = 0;
1204 
1205 	/* Check where we are on source ranges list. */
1206 	srcblock = list->token->blocksize;
1207 	if (tpc_skip_ranges(list->token->range, list->token->nrange,
1208 	    list->offset_into_rod + list->cursectors * dstblock / srcblock,
1209 	    &srange, &soffset) != 0) {
1210 		ctl_set_sense(list->ctsio, /*current_error*/ 1,
1211 		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1212 		    /*asc*/ 0x0d, /*ascq*/ 0x04, SSD_ELEM_NONE);
1213 		return (CTL_RETVAL_ERROR);
1214 	}
1215 
1216 	srclba = scsi_8btou64(list->token->range[srange].lba) + soffset;
1217 	dstlba = scsi_8btou64(list->range[drange].lba) + doffset;
1218 	numbytes = srcblock *
1219 	    (scsi_4btoul(list->token->range[srange].length) - soffset);
1220 	numbytes = omin(numbytes, dstblock *
1221 	    (scsi_4btoul(list->range[drange].length) - doffset));
1222 	if (numbytes > TPC_MAX_IOCHUNK_SIZE) {
1223 		numbytes = TPC_MAX_IOCHUNK_SIZE;
1224 		numbytes -= numbytes % dstblock;
1225 		if (pb > dstblock) {
1226 			adj = (dstlba * dstblock + numbytes - pbo) % pb;
1227 			if (numbytes > adj)
1228 				numbytes -= adj;
1229 		}
1230 	}
1231 
1232 	if (numbytes % srcblock != 0 || numbytes % dstblock != 0) {
1233 		ctl_set_sense(list->ctsio, /*current_error*/ 1,
1234 		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1235 		    /*asc*/ 0x26, /*ascq*/ 0x0A, SSD_ELEM_NONE);
1236 		return (CTL_RETVAL_ERROR);
1237 	}
1238 
1239 	list->buf = malloc(numbytes, M_CTL, M_WAITOK |
1240 	    (list->token == NULL ? M_ZERO : 0));
1241 	list->segbytes = numbytes;
1242 	list->segsectors = numbytes / dstblock;
1243 //printf("Copy chunk of %ju sectors from %ju to %ju\n", list->segsectors,
1244 //    srclba, dstlba);
1245 	donebytes = 0;
1246 	TAILQ_INIT(&run);
1247 	list->tbdio = 0;
1248 	TAILQ_INIT(&list->allio);
1249 	while (donebytes < numbytes) {
1250 		roundbytes = numbytes - donebytes;
1251 		if (roundbytes > TPC_MAX_IO_SIZE) {
1252 			roundbytes = TPC_MAX_IO_SIZE;
1253 			roundbytes -= roundbytes % dstblock;
1254 			if (pb > dstblock) {
1255 				adj = (dstlba * dstblock + roundbytes - pbo) % pb;
1256 				if (roundbytes > adj)
1257 					roundbytes -= adj;
1258 			}
1259 		}
1260 
1261 		tior = malloc(sizeof(*tior), M_CTL, M_WAITOK | M_ZERO);
1262 		TAILQ_INIT(&tior->run);
1263 		tior->list = list;
1264 		TAILQ_INSERT_TAIL(&list->allio, tior, links);
1265 		tior->io = tpcl_alloc_io();
1266 		ctl_scsi_read_write(tior->io,
1267 				    /*data_ptr*/ &list->buf[donebytes],
1268 				    /*data_len*/ roundbytes,
1269 				    /*read_op*/ 1,
1270 				    /*byte2*/ 0,
1271 				    /*minimum_cdb_size*/ 0,
1272 				    /*lba*/ srclba,
1273 				    /*num_blocks*/ roundbytes / srcblock,
1274 				    /*tag_type*/ CTL_TAG_SIMPLE,
1275 				    /*control*/ 0);
1276 		tior->io->io_hdr.retries = 3;
1277 		tior->lun = list->token->lun;
1278 		tior->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tior;
1279 
1280 		tiow = malloc(sizeof(*tiow), M_CTL, M_WAITOK | M_ZERO);
1281 		TAILQ_INIT(&tiow->run);
1282 		tiow->list = list;
1283 		TAILQ_INSERT_TAIL(&list->allio, tiow, links);
1284 		tiow->io = tpcl_alloc_io();
1285 		ctl_scsi_read_write(tiow->io,
1286 				    /*data_ptr*/ &list->buf[donebytes],
1287 				    /*data_len*/ roundbytes,
1288 				    /*read_op*/ 0,
1289 				    /*byte2*/ 0,
1290 				    /*minimum_cdb_size*/ 0,
1291 				    /*lba*/ dstlba,
1292 				    /*num_blocks*/ roundbytes / dstblock,
1293 				    /*tag_type*/ CTL_TAG_SIMPLE,
1294 				    /*control*/ 0);
1295 		tiow->io->io_hdr.retries = 3;
1296 		tiow->lun = list->lun->lun;
1297 		tiow->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tiow;
1298 
1299 		TAILQ_INSERT_TAIL(&tior->run, tiow, rlinks);
1300 		TAILQ_INSERT_TAIL(&run, tior, rlinks);
1301 		list->tbdio++;
1302 		donebytes += roundbytes;
1303 		srclba += roundbytes / srcblock;
1304 		dstlba += roundbytes / dstblock;
1305 	}
1306 
1307 	while ((tior = TAILQ_FIRST(&run)) != NULL) {
1308 		TAILQ_REMOVE(&run, tior, rlinks);
1309 		if (tpcl_queue(tior->io, tior->lun) != CTL_RETVAL_COMPLETE)
1310 			panic("tpcl_queue() error");
1311 	}
1312 
1313 	list->stage++;
1314 	return (CTL_RETVAL_QUEUED);
1315 }
1316 
1317 static int
1318 tpc_process_zero_wut(struct tpc_list *list)
1319 {
1320 	struct tpc_io *tio, *tiow;
1321 	struct runl run, *prun;
1322 	int r;
1323 	uint32_t dstblock, len;
1324 
1325 	if (list->stage > 0) {
1326 complete:
1327 		/* Cleanup after previous rounds. */
1328 		while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
1329 			TAILQ_REMOVE(&list->allio, tio, links);
1330 			ctl_free_io(tio->io);
1331 			free(tio, M_CTL);
1332 		}
1333 		if (list->abort) {
1334 			ctl_set_task_aborted(list->ctsio);
1335 			return (CTL_RETVAL_ERROR);
1336 		} else if (list->error) {
1337 			ctl_set_sense(list->ctsio, /*current_error*/ 1,
1338 			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1339 			    /*asc*/ 0x0d, /*ascq*/ 0x01, SSD_ELEM_NONE);
1340 			return (CTL_RETVAL_ERROR);
1341 		}
1342 		list->cursectors += list->segsectors;
1343 		list->curbytes += list->segbytes;
1344 		return (CTL_RETVAL_COMPLETE);
1345 	}
1346 
1347 	dstblock = list->lun->be_lun->blocksize;
1348 	TAILQ_INIT(&run);
1349 	prun = &run;
1350 	list->tbdio = 1;
1351 	TAILQ_INIT(&list->allio);
1352 	list->segsectors = 0;
1353 	for (r = 0; r < list->nrange; r++) {
1354 		len = scsi_4btoul(list->range[r].length);
1355 		if (len == 0)
1356 			continue;
1357 
1358 		tiow = malloc(sizeof(*tiow), M_CTL, M_WAITOK | M_ZERO);
1359 		TAILQ_INIT(&tiow->run);
1360 		tiow->list = list;
1361 		TAILQ_INSERT_TAIL(&list->allio, tiow, links);
1362 		tiow->io = tpcl_alloc_io();
1363 		ctl_scsi_write_same(tiow->io,
1364 				    /*data_ptr*/ NULL,
1365 				    /*data_len*/ 0,
1366 				    /*byte2*/ SWS_NDOB,
1367 				    /*lba*/ scsi_8btou64(list->range[r].lba),
1368 				    /*num_blocks*/ len,
1369 				    /*tag_type*/ CTL_TAG_SIMPLE,
1370 				    /*control*/ 0);
1371 		tiow->io->io_hdr.retries = 3;
1372 		tiow->lun = list->lun->lun;
1373 		tiow->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tiow;
1374 
1375 		TAILQ_INSERT_TAIL(prun, tiow, rlinks);
1376 		prun = &tiow->run;
1377 		list->segsectors += len;
1378 	}
1379 	list->segbytes = list->segsectors * dstblock;
1380 
1381 	if (TAILQ_EMPTY(&run))
1382 		goto complete;
1383 
1384 	while ((tiow = TAILQ_FIRST(&run)) != NULL) {
1385 		TAILQ_REMOVE(&run, tiow, rlinks);
1386 		if (tpcl_queue(tiow->io, tiow->lun) != CTL_RETVAL_COMPLETE)
1387 			panic("tpcl_queue() error");
1388 	}
1389 
1390 	list->stage++;
1391 	return (CTL_RETVAL_QUEUED);
1392 }
1393 
1394 static void
1395 tpc_process(struct tpc_list *list)
1396 {
1397 	struct ctl_lun *lun = list->lun;
1398 	struct ctl_softc *softc = lun->ctl_softc;
1399 	struct scsi_ec_segment *seg;
1400 	struct ctl_scsiio *ctsio = list->ctsio;
1401 	int retval = CTL_RETVAL_COMPLETE;
1402 	uint8_t csi[4];
1403 
1404 	if (list->service_action == EC_WUT) {
1405 		if (list->token != NULL)
1406 			retval = tpc_process_wut(list);
1407 		else
1408 			retval = tpc_process_zero_wut(list);
1409 		if (retval == CTL_RETVAL_QUEUED)
1410 			return;
1411 		if (retval == CTL_RETVAL_ERROR) {
1412 			list->error = 1;
1413 			goto done;
1414 		}
1415 	} else {
1416 //printf("ZZZ %d cscd, %d segs\n", list->ncscd, list->nseg);
1417 		while (list->curseg < list->nseg) {
1418 			seg = list->seg[list->curseg];
1419 			switch (seg->type_code) {
1420 			case EC_SEG_B2B:
1421 				retval = tpc_process_b2b(list);
1422 				break;
1423 			case EC_SEG_VERIFY:
1424 				retval = tpc_process_verify(list);
1425 				break;
1426 			case EC_SEG_REGISTER_KEY:
1427 				retval = tpc_process_register_key(list);
1428 				break;
1429 			default:
1430 				scsi_ulto4b(list->curseg, csi);
1431 				ctl_set_sense(ctsio, /*current_error*/ 1,
1432 				    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1433 				    /*asc*/ 0x26, /*ascq*/ 0x09,
1434 				    SSD_ELEM_COMMAND, sizeof(csi), csi,
1435 				    SSD_ELEM_NONE);
1436 				goto done;
1437 			}
1438 			if (retval == CTL_RETVAL_QUEUED)
1439 				return;
1440 			if (retval == CTL_RETVAL_ERROR) {
1441 				list->error = 1;
1442 				goto done;
1443 			}
1444 			list->curseg++;
1445 			list->stage = 0;
1446 		}
1447 	}
1448 
1449 	ctl_set_success(ctsio);
1450 
1451 done:
1452 //printf("ZZZ done\n");
1453 	free(list->params, M_CTL);
1454 	list->params = NULL;
1455 	if (list->token) {
1456 		mtx_lock(&softc->tpc_lock);
1457 		if (--list->token->active == 0)
1458 			list->token->last_active = time_uptime;
1459 		mtx_unlock(&softc->tpc_lock);
1460 		list->token = NULL;
1461 	}
1462 	mtx_lock(&lun->lun_lock);
1463 	if ((list->flags & EC_LIST_ID_USAGE_MASK) == EC_LIST_ID_USAGE_NONE) {
1464 		TAILQ_REMOVE(&lun->tpc_lists, list, links);
1465 		free(list, M_CTL);
1466 	} else {
1467 		list->completed = 1;
1468 		list->last_active = time_uptime;
1469 		list->sense_data = ctsio->sense_data;
1470 		list->sense_len = ctsio->sense_len;
1471 		list->scsi_status = ctsio->scsi_status;
1472 	}
1473 	mtx_unlock(&lun->lun_lock);
1474 
1475 	ctl_done((union ctl_io *)ctsio);
1476 }
1477 
1478 /*
1479  * For any sort of check condition, busy, etc., we just retry.  We do not
1480  * decrement the retry count for unit attention type errors.  These are
1481  * normal, and we want to save the retry count for "real" errors.  Otherwise,
1482  * we could end up with situations where a command will succeed in some
1483  * situations and fail in others, depending on whether a unit attention is
1484  * pending.  Also, some of our error recovery actions, most notably the
1485  * LUN reset action, will cause a unit attention.
1486  *
1487  * We can add more detail here later if necessary.
1488  */
1489 static tpc_error_action
1490 tpc_checkcond_parse(union ctl_io *io)
1491 {
1492 	tpc_error_action error_action;
1493 	int error_code, sense_key, asc, ascq;
1494 
1495 	/*
1496 	 * Default to retrying the command.
1497 	 */
1498 	error_action = TPC_ERR_RETRY;
1499 
1500 	scsi_extract_sense_len(&io->scsiio.sense_data,
1501 			       io->scsiio.sense_len,
1502 			       &error_code,
1503 			       &sense_key,
1504 			       &asc,
1505 			       &ascq,
1506 			       /*show_errors*/ 1);
1507 
1508 	switch (error_code) {
1509 	case SSD_DEFERRED_ERROR:
1510 	case SSD_DESC_DEFERRED_ERROR:
1511 		error_action |= TPC_ERR_NO_DECREMENT;
1512 		break;
1513 	case SSD_CURRENT_ERROR:
1514 	case SSD_DESC_CURRENT_ERROR:
1515 	default:
1516 		switch (sense_key) {
1517 		case SSD_KEY_UNIT_ATTENTION:
1518 			error_action |= TPC_ERR_NO_DECREMENT;
1519 			break;
1520 		case SSD_KEY_HARDWARE_ERROR:
1521 			/*
1522 			 * This is our generic "something bad happened"
1523 			 * error code.  It often isn't recoverable.
1524 			 */
1525 			if ((asc == 0x44) && (ascq == 0x00))
1526 				error_action = TPC_ERR_FAIL;
1527 			break;
1528 		case SSD_KEY_NOT_READY:
1529 			/*
1530 			 * If the LUN is powered down, there likely isn't
1531 			 * much point in retrying right now.
1532 			 */
1533 			if ((asc == 0x04) && (ascq == 0x02))
1534 				error_action = TPC_ERR_FAIL;
1535 			/*
1536 			 * If the LUN is offline, there probably isn't much
1537 			 * point in retrying, either.
1538 			 */
1539 			if ((asc == 0x04) && (ascq == 0x03))
1540 				error_action = TPC_ERR_FAIL;
1541 			break;
1542 		}
1543 	}
1544 	return (error_action);
1545 }
1546 
1547 static tpc_error_action
1548 tpc_error_parse(union ctl_io *io)
1549 {
1550 	tpc_error_action error_action = TPC_ERR_RETRY;
1551 
1552 	switch (io->io_hdr.io_type) {
1553 	case CTL_IO_SCSI:
1554 		switch (io->io_hdr.status & CTL_STATUS_MASK) {
1555 		case CTL_SCSI_ERROR:
1556 			switch (io->scsiio.scsi_status) {
1557 			case SCSI_STATUS_CHECK_COND:
1558 				error_action = tpc_checkcond_parse(io);
1559 				break;
1560 			default:
1561 				break;
1562 			}
1563 			break;
1564 		default:
1565 			break;
1566 		}
1567 		break;
1568 	case CTL_IO_TASK:
1569 		break;
1570 	default:
1571 		panic("%s: invalid ctl_io type %d\n", __func__,
1572 		      io->io_hdr.io_type);
1573 		break;
1574 	}
1575 	return (error_action);
1576 }
1577 
1578 void
1579 tpc_done(union ctl_io *io)
1580 {
1581 	struct tpc_io *tio, *tior;
1582 
1583 	/*
1584 	 * Very minimal retry logic.  We basically retry if we got an error
1585 	 * back, and the retry count is greater than 0.  If we ever want
1586 	 * more sophisticated initiator type behavior, the CAM error
1587 	 * recovery code in ../common might be helpful.
1588 	 */
1589 	tio = io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr;
1590 	if (((io->io_hdr.status & CTL_STATUS_MASK) != CTL_SUCCESS)
1591 	 && (io->io_hdr.retries > 0)) {
1592 		ctl_io_status old_status;
1593 		tpc_error_action error_action;
1594 
1595 		error_action = tpc_error_parse(io);
1596 		switch (error_action & TPC_ERR_MASK) {
1597 		case TPC_ERR_FAIL:
1598 			break;
1599 		case TPC_ERR_RETRY:
1600 		default:
1601 			if ((error_action & TPC_ERR_NO_DECREMENT) == 0)
1602 				io->io_hdr.retries--;
1603 			old_status = io->io_hdr.status;
1604 			io->io_hdr.status = CTL_STATUS_NONE;
1605 			io->io_hdr.flags &= ~CTL_FLAG_ABORT;
1606 			io->io_hdr.flags &= ~CTL_FLAG_SENT_2OTHER_SC;
1607 			if (tpcl_queue(io, tio->lun) != CTL_RETVAL_COMPLETE) {
1608 				printf("%s: error returned from ctl_queue()!\n",
1609 				       __func__);
1610 				io->io_hdr.status = old_status;
1611 			} else
1612 				return;
1613 		}
1614 	}
1615 
1616 	if ((io->io_hdr.status & CTL_STATUS_MASK) != CTL_SUCCESS)
1617 		tio->list->error = 1;
1618 	else
1619 		atomic_add_int(&tio->list->curops, 1);
1620 	if (!tio->list->error && !tio->list->abort) {
1621 		while ((tior = TAILQ_FIRST(&tio->run)) != NULL) {
1622 			TAILQ_REMOVE(&tio->run, tior, rlinks);
1623 			atomic_add_int(&tio->list->tbdio, 1);
1624 			if (tpcl_queue(tior->io, tior->lun) != CTL_RETVAL_COMPLETE)
1625 				panic("tpcl_queue() error");
1626 		}
1627 	}
1628 	if (atomic_fetchadd_int(&tio->list->tbdio, -1) == 1)
1629 		tpc_process(tio->list);
1630 }
1631 
1632 int
1633 ctl_extended_copy_lid1(struct ctl_scsiio *ctsio)
1634 {
1635 	struct scsi_extended_copy *cdb;
1636 	struct scsi_extended_copy_lid1_data *data;
1637 	struct ctl_lun *lun;
1638 	struct tpc_list *list, *tlist;
1639 	uint8_t *ptr;
1640 	char *value;
1641 	int len, off, lencscd, lenseg, leninl, nseg;
1642 
1643 	CTL_DEBUG_PRINT(("ctl_extended_copy_lid1\n"));
1644 
1645 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
1646 	cdb = (struct scsi_extended_copy *)ctsio->cdb;
1647 	len = scsi_4btoul(cdb->length);
1648 
1649 	if (len == 0) {
1650 		ctl_set_success(ctsio);
1651 		goto done;
1652 	}
1653 	if (len < sizeof(struct scsi_extended_copy_lid1_data) ||
1654 	    len > sizeof(struct scsi_extended_copy_lid1_data) +
1655 	    TPC_MAX_LIST + TPC_MAX_INLINE) {
1656 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
1657 		    /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
1658 		goto done;
1659 	}
1660 
1661 	/*
1662 	 * If we've got a kernel request that hasn't been malloced yet,
1663 	 * malloc it and tell the caller the data buffer is here.
1664 	 */
1665 	if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
1666 		ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
1667 		ctsio->kern_data_len = len;
1668 		ctsio->kern_total_len = len;
1669 		ctsio->kern_data_resid = 0;
1670 		ctsio->kern_rel_offset = 0;
1671 		ctsio->kern_sg_entries = 0;
1672 		ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
1673 		ctsio->be_move_done = ctl_config_move_done;
1674 		ctl_datamove((union ctl_io *)ctsio);
1675 
1676 		return (CTL_RETVAL_COMPLETE);
1677 	}
1678 
1679 	data = (struct scsi_extended_copy_lid1_data *)ctsio->kern_data_ptr;
1680 	lencscd = scsi_2btoul(data->cscd_list_length);
1681 	lenseg = scsi_4btoul(data->segment_list_length);
1682 	leninl = scsi_4btoul(data->inline_data_length);
1683 	if (lencscd > TPC_MAX_CSCDS * sizeof(struct scsi_ec_cscd)) {
1684 		ctl_set_sense(ctsio, /*current_error*/ 1,
1685 		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1686 		    /*asc*/ 0x26, /*ascq*/ 0x06, SSD_ELEM_NONE);
1687 		goto done;
1688 	}
1689 	if (lenseg > TPC_MAX_SEGS * sizeof(struct scsi_ec_segment)) {
1690 		ctl_set_sense(ctsio, /*current_error*/ 1,
1691 		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1692 		    /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1693 		goto done;
1694 	}
1695 	if (lencscd + lenseg > TPC_MAX_LIST ||
1696 	    leninl > TPC_MAX_INLINE ||
1697 	    len < sizeof(struct scsi_extended_copy_lid1_data) +
1698 	     lencscd + lenseg + leninl) {
1699 		ctl_set_param_len_error(ctsio);
1700 		goto done;
1701 	}
1702 
1703 	list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
1704 	list->service_action = cdb->service_action;
1705 	value = ctl_get_opt(&lun->be_lun->options, "insecure_tpc");
1706 	if (value != NULL && strcmp(value, "on") == 0)
1707 		list->init_port = -1;
1708 	else
1709 		list->init_port = ctsio->io_hdr.nexus.targ_port;
1710 	list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
1711 	list->list_id = data->list_identifier;
1712 	list->flags = data->flags;
1713 	list->params = ctsio->kern_data_ptr;
1714 	list->cscd = (struct scsi_ec_cscd *)&data->data[0];
1715 	ptr = &data->data[lencscd];
1716 	for (nseg = 0, off = 0; off < lenseg; nseg++) {
1717 		if (nseg >= TPC_MAX_SEGS) {
1718 			free(list, M_CTL);
1719 			ctl_set_sense(ctsio, /*current_error*/ 1,
1720 			    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1721 			    /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1722 			goto done;
1723 		}
1724 		list->seg[nseg] = (struct scsi_ec_segment *)(ptr + off);
1725 		off += sizeof(struct scsi_ec_segment) +
1726 		    scsi_2btoul(list->seg[nseg]->descr_length);
1727 	}
1728 	list->inl = &data->data[lencscd + lenseg];
1729 	list->ncscd = lencscd / sizeof(struct scsi_ec_cscd);
1730 	list->nseg = nseg;
1731 	list->leninl = leninl;
1732 	list->ctsio = ctsio;
1733 	list->lun = lun;
1734 	mtx_lock(&lun->lun_lock);
1735 	if ((list->flags & EC_LIST_ID_USAGE_MASK) != EC_LIST_ID_USAGE_NONE) {
1736 		tlist = tpc_find_list(lun, list->list_id, list->init_idx);
1737 		if (tlist != NULL && !tlist->completed) {
1738 			mtx_unlock(&lun->lun_lock);
1739 			free(list, M_CTL);
1740 			ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
1741 			    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
1742 			    /*bit*/ 0);
1743 			goto done;
1744 		}
1745 		if (tlist != NULL) {
1746 			TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
1747 			free(tlist, M_CTL);
1748 		}
1749 	}
1750 	TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
1751 	mtx_unlock(&lun->lun_lock);
1752 
1753 	tpc_process(list);
1754 	return (CTL_RETVAL_COMPLETE);
1755 
1756 done:
1757 	if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
1758 		free(ctsio->kern_data_ptr, M_CTL);
1759 		ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
1760 	}
1761 	ctl_done((union ctl_io *)ctsio);
1762 	return (CTL_RETVAL_COMPLETE);
1763 }
1764 
1765 int
1766 ctl_extended_copy_lid4(struct ctl_scsiio *ctsio)
1767 {
1768 	struct scsi_extended_copy *cdb;
1769 	struct scsi_extended_copy_lid4_data *data;
1770 	struct ctl_lun *lun;
1771 	struct tpc_list *list, *tlist;
1772 	uint8_t *ptr;
1773 	char *value;
1774 	int len, off, lencscd, lenseg, leninl, nseg;
1775 
1776 	CTL_DEBUG_PRINT(("ctl_extended_copy_lid4\n"));
1777 
1778 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
1779 	cdb = (struct scsi_extended_copy *)ctsio->cdb;
1780 	len = scsi_4btoul(cdb->length);
1781 
1782 	if (len == 0) {
1783 		ctl_set_success(ctsio);
1784 		goto done;
1785 	}
1786 	if (len < sizeof(struct scsi_extended_copy_lid4_data) ||
1787 	    len > sizeof(struct scsi_extended_copy_lid4_data) +
1788 	    TPC_MAX_LIST + TPC_MAX_INLINE) {
1789 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
1790 		    /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
1791 		goto done;
1792 	}
1793 
1794 	/*
1795 	 * If we've got a kernel request that hasn't been malloced yet,
1796 	 * malloc it and tell the caller the data buffer is here.
1797 	 */
1798 	if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
1799 		ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
1800 		ctsio->kern_data_len = len;
1801 		ctsio->kern_total_len = len;
1802 		ctsio->kern_data_resid = 0;
1803 		ctsio->kern_rel_offset = 0;
1804 		ctsio->kern_sg_entries = 0;
1805 		ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
1806 		ctsio->be_move_done = ctl_config_move_done;
1807 		ctl_datamove((union ctl_io *)ctsio);
1808 
1809 		return (CTL_RETVAL_COMPLETE);
1810 	}
1811 
1812 	data = (struct scsi_extended_copy_lid4_data *)ctsio->kern_data_ptr;
1813 	lencscd = scsi_2btoul(data->cscd_list_length);
1814 	lenseg = scsi_2btoul(data->segment_list_length);
1815 	leninl = scsi_2btoul(data->inline_data_length);
1816 	if (lencscd > TPC_MAX_CSCDS * sizeof(struct scsi_ec_cscd)) {
1817 		ctl_set_sense(ctsio, /*current_error*/ 1,
1818 		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1819 		    /*asc*/ 0x26, /*ascq*/ 0x06, SSD_ELEM_NONE);
1820 		goto done;
1821 	}
1822 	if (lenseg > TPC_MAX_SEGS * sizeof(struct scsi_ec_segment)) {
1823 		ctl_set_sense(ctsio, /*current_error*/ 1,
1824 		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1825 		    /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1826 		goto done;
1827 	}
1828 	if (lencscd + lenseg > TPC_MAX_LIST ||
1829 	    leninl > TPC_MAX_INLINE ||
1830 	    len < sizeof(struct scsi_extended_copy_lid1_data) +
1831 	     lencscd + lenseg + leninl) {
1832 		ctl_set_param_len_error(ctsio);
1833 		goto done;
1834 	}
1835 
1836 	list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
1837 	list->service_action = cdb->service_action;
1838 	value = ctl_get_opt(&lun->be_lun->options, "insecure_tpc");
1839 	if (value != NULL && strcmp(value, "on") == 0)
1840 		list->init_port = -1;
1841 	else
1842 		list->init_port = ctsio->io_hdr.nexus.targ_port;
1843 	list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
1844 	list->list_id = scsi_4btoul(data->list_identifier);
1845 	list->flags = data->flags;
1846 	list->params = ctsio->kern_data_ptr;
1847 	list->cscd = (struct scsi_ec_cscd *)&data->data[0];
1848 	ptr = &data->data[lencscd];
1849 	for (nseg = 0, off = 0; off < lenseg; nseg++) {
1850 		if (nseg >= TPC_MAX_SEGS) {
1851 			free(list, M_CTL);
1852 			ctl_set_sense(ctsio, /*current_error*/ 1,
1853 			    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1854 			    /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1855 			goto done;
1856 		}
1857 		list->seg[nseg] = (struct scsi_ec_segment *)(ptr + off);
1858 		off += sizeof(struct scsi_ec_segment) +
1859 		    scsi_2btoul(list->seg[nseg]->descr_length);
1860 	}
1861 	list->inl = &data->data[lencscd + lenseg];
1862 	list->ncscd = lencscd / sizeof(struct scsi_ec_cscd);
1863 	list->nseg = nseg;
1864 	list->leninl = leninl;
1865 	list->ctsio = ctsio;
1866 	list->lun = lun;
1867 	mtx_lock(&lun->lun_lock);
1868 	if ((list->flags & EC_LIST_ID_USAGE_MASK) != EC_LIST_ID_USAGE_NONE) {
1869 		tlist = tpc_find_list(lun, list->list_id, list->init_idx);
1870 		if (tlist != NULL && !tlist->completed) {
1871 			mtx_unlock(&lun->lun_lock);
1872 			free(list, M_CTL);
1873 			ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
1874 			    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
1875 			    /*bit*/ 0);
1876 			goto done;
1877 		}
1878 		if (tlist != NULL) {
1879 			TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
1880 			free(tlist, M_CTL);
1881 		}
1882 	}
1883 	TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
1884 	mtx_unlock(&lun->lun_lock);
1885 
1886 	tpc_process(list);
1887 	return (CTL_RETVAL_COMPLETE);
1888 
1889 done:
1890 	if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
1891 		free(ctsio->kern_data_ptr, M_CTL);
1892 		ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
1893 	}
1894 	ctl_done((union ctl_io *)ctsio);
1895 	return (CTL_RETVAL_COMPLETE);
1896 }
1897 
1898 static void
1899 tpc_create_token(struct ctl_lun *lun, struct ctl_port *port, off_t len,
1900     struct scsi_token *token)
1901 {
1902 	static int id = 0;
1903 	struct scsi_vpd_id_descriptor *idd = NULL;
1904 	struct scsi_ec_cscd_id *cscd;
1905 	struct scsi_read_capacity_data_long *dtsd;
1906 	int targid_len;
1907 
1908 	scsi_ulto4b(ROD_TYPE_AUR, token->type);
1909 	scsi_ulto2b(0x01f8, token->length);
1910 	scsi_u64to8b(atomic_fetchadd_int(&id, 1), &token->body[0]);
1911 	if (lun->lun_devid)
1912 		idd = scsi_get_devid_desc((struct scsi_vpd_id_descriptor *)
1913 		    lun->lun_devid->data, lun->lun_devid->len,
1914 		    scsi_devid_is_lun_naa);
1915 	if (idd == NULL && lun->lun_devid)
1916 		idd = scsi_get_devid_desc((struct scsi_vpd_id_descriptor *)
1917 		    lun->lun_devid->data, lun->lun_devid->len,
1918 		    scsi_devid_is_lun_eui64);
1919 	if (idd != NULL) {
1920 		cscd = (struct scsi_ec_cscd_id *)&token->body[8];
1921 		cscd->type_code = EC_CSCD_ID;
1922 		cscd->luidt_pdt = T_DIRECT;
1923 		memcpy(&cscd->codeset, idd, 4 + idd->length);
1924 		scsi_ulto3b(lun->be_lun->blocksize, cscd->dtsp.block_length);
1925 	}
1926 	scsi_u64to8b(0, &token->body[40]); /* XXX: Should be 128bit value. */
1927 	scsi_u64to8b(len, &token->body[48]);
1928 
1929 	/* ROD token device type specific data (RC16 without first field) */
1930 	dtsd = (struct scsi_read_capacity_data_long *)&token->body[88 - 8];
1931 	scsi_ulto4b(lun->be_lun->blocksize, dtsd->length);
1932 	dtsd->prot_lbppbe = lun->be_lun->pblockexp & SRC16_LBPPBE;
1933 	scsi_ulto2b(lun->be_lun->pblockoff & SRC16_LALBA_A, dtsd->lalba_lbp);
1934 	if (lun->be_lun->flags & CTL_LUN_FLAG_UNMAP)
1935 		dtsd->lalba_lbp[0] |= SRC16_LBPME | SRC16_LBPRZ;
1936 
1937 	if (port->target_devid) {
1938 		targid_len = port->target_devid->len;
1939 		memcpy(&token->body[120], port->target_devid->data, targid_len);
1940 	} else
1941 		targid_len = 32;
1942 	arc4rand(&token->body[120 + targid_len], 384 - targid_len, 0);
1943 };
1944 
1945 int
1946 ctl_populate_token(struct ctl_scsiio *ctsio)
1947 {
1948 	struct scsi_populate_token *cdb;
1949 	struct scsi_populate_token_data *data;
1950 	struct ctl_softc *softc;
1951 	struct ctl_lun *lun;
1952 	struct ctl_port *port;
1953 	struct tpc_list *list, *tlist;
1954 	struct tpc_token *token;
1955 	int len, lendata, lendesc;
1956 
1957 	CTL_DEBUG_PRINT(("ctl_populate_token\n"));
1958 
1959 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
1960 	softc = lun->ctl_softc;
1961 	port = softc->ctl_ports[ctsio->io_hdr.nexus.targ_port];
1962 	cdb = (struct scsi_populate_token *)ctsio->cdb;
1963 	len = scsi_4btoul(cdb->length);
1964 
1965 	if (len < sizeof(struct scsi_populate_token_data) ||
1966 	    len > sizeof(struct scsi_populate_token_data) +
1967 	     TPC_MAX_SEGS * sizeof(struct scsi_range_desc)) {
1968 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
1969 		    /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
1970 		goto done;
1971 	}
1972 
1973 	/*
1974 	 * If we've got a kernel request that hasn't been malloced yet,
1975 	 * malloc it and tell the caller the data buffer is here.
1976 	 */
1977 	if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
1978 		ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
1979 		ctsio->kern_data_len = len;
1980 		ctsio->kern_total_len = len;
1981 		ctsio->kern_data_resid = 0;
1982 		ctsio->kern_rel_offset = 0;
1983 		ctsio->kern_sg_entries = 0;
1984 		ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
1985 		ctsio->be_move_done = ctl_config_move_done;
1986 		ctl_datamove((union ctl_io *)ctsio);
1987 
1988 		return (CTL_RETVAL_COMPLETE);
1989 	}
1990 
1991 	data = (struct scsi_populate_token_data *)ctsio->kern_data_ptr;
1992 	lendata = scsi_2btoul(data->length);
1993 	if (lendata < sizeof(struct scsi_populate_token_data) - 2 +
1994 	    sizeof(struct scsi_range_desc)) {
1995 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
1996 		    /*field*/ 0, /*bit_valid*/ 0, /*bit*/ 0);
1997 		goto done;
1998 	}
1999 	lendesc = scsi_2btoul(data->range_descriptor_length);
2000 	if (lendesc < sizeof(struct scsi_range_desc) ||
2001 	    len < sizeof(struct scsi_populate_token_data) + lendesc ||
2002 	    lendata < sizeof(struct scsi_populate_token_data) - 2 + lendesc) {
2003 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2004 		    /*field*/ 14, /*bit_valid*/ 0, /*bit*/ 0);
2005 		goto done;
2006 	}
2007 /*
2008 	printf("PT(list=%u) flags=%x to=%d rt=%x len=%x\n",
2009 	    scsi_4btoul(cdb->list_identifier),
2010 	    data->flags, scsi_4btoul(data->inactivity_timeout),
2011 	    scsi_4btoul(data->rod_type),
2012 	    scsi_2btoul(data->range_descriptor_length));
2013 */
2014 
2015 	/* Validate INACTIVITY TIMEOUT field */
2016 	if (scsi_4btoul(data->inactivity_timeout) > TPC_MAX_TOKEN_TIMEOUT) {
2017 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2018 		    /*command*/ 0, /*field*/ 4, /*bit_valid*/ 0,
2019 		    /*bit*/ 0);
2020 		goto done;
2021 	}
2022 
2023 	/* Validate ROD TYPE field */
2024 	if ((data->flags & EC_PT_RTV) &&
2025 	    scsi_4btoul(data->rod_type) != ROD_TYPE_AUR) {
2026 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2027 		    /*field*/ 8, /*bit_valid*/ 0, /*bit*/ 0);
2028 		goto done;
2029 	}
2030 
2031 	/* Validate list of ranges */
2032 	if (tpc_check_ranges_l(&data->desc[0],
2033 	    scsi_2btoul(data->range_descriptor_length) /
2034 	    sizeof(struct scsi_range_desc),
2035 	    lun->be_lun->maxlba) != 0) {
2036 		ctl_set_lba_out_of_range(ctsio);
2037 		goto done;
2038 	}
2039 	if (tpc_check_ranges_x(&data->desc[0],
2040 	    scsi_2btoul(data->range_descriptor_length) /
2041 	    sizeof(struct scsi_range_desc)) != 0) {
2042 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 0,
2043 		    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2044 		    /*bit*/ 0);
2045 		goto done;
2046 	}
2047 
2048 	list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
2049 	list->service_action = cdb->service_action;
2050 	list->init_port = ctsio->io_hdr.nexus.targ_port;
2051 	list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
2052 	list->list_id = scsi_4btoul(cdb->list_identifier);
2053 	list->flags = data->flags;
2054 	list->ctsio = ctsio;
2055 	list->lun = lun;
2056 	mtx_lock(&lun->lun_lock);
2057 	tlist = tpc_find_list(lun, list->list_id, list->init_idx);
2058 	if (tlist != NULL && !tlist->completed) {
2059 		mtx_unlock(&lun->lun_lock);
2060 		free(list, M_CTL);
2061 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2062 		    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2063 		    /*bit*/ 0);
2064 		goto done;
2065 	}
2066 	if (tlist != NULL) {
2067 		TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
2068 		free(tlist, M_CTL);
2069 	}
2070 	TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
2071 	mtx_unlock(&lun->lun_lock);
2072 
2073 	token = malloc(sizeof(*token), M_CTL, M_WAITOK | M_ZERO);
2074 	token->lun = lun->lun;
2075 	token->blocksize = lun->be_lun->blocksize;
2076 	token->params = ctsio->kern_data_ptr;
2077 	token->range = &data->desc[0];
2078 	token->nrange = scsi_2btoul(data->range_descriptor_length) /
2079 	    sizeof(struct scsi_range_desc);
2080 	list->cursectors = tpc_ranges_length(token->range, token->nrange);
2081 	list->curbytes = (off_t)list->cursectors * lun->be_lun->blocksize;
2082 	tpc_create_token(lun, port, list->curbytes,
2083 	    (struct scsi_token *)token->token);
2084 	token->active = 0;
2085 	token->last_active = time_uptime;
2086 	token->timeout = scsi_4btoul(data->inactivity_timeout);
2087 	if (token->timeout == 0)
2088 		token->timeout = TPC_DFL_TOKEN_TIMEOUT;
2089 	else if (token->timeout < TPC_MIN_TOKEN_TIMEOUT)
2090 		token->timeout = TPC_MIN_TOKEN_TIMEOUT;
2091 	memcpy(list->res_token, token->token, sizeof(list->res_token));
2092 	list->res_token_valid = 1;
2093 	list->curseg = 0;
2094 	list->completed = 1;
2095 	list->last_active = time_uptime;
2096 	mtx_lock(&softc->tpc_lock);
2097 	TAILQ_INSERT_TAIL(&softc->tpc_tokens, token, links);
2098 	mtx_unlock(&softc->tpc_lock);
2099 	ctl_set_success(ctsio);
2100 	ctl_done((union ctl_io *)ctsio);
2101 	return (CTL_RETVAL_COMPLETE);
2102 
2103 done:
2104 	if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
2105 		free(ctsio->kern_data_ptr, M_CTL);
2106 		ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
2107 	}
2108 	ctl_done((union ctl_io *)ctsio);
2109 	return (CTL_RETVAL_COMPLETE);
2110 }
2111 
2112 int
2113 ctl_write_using_token(struct ctl_scsiio *ctsio)
2114 {
2115 	struct scsi_write_using_token *cdb;
2116 	struct scsi_write_using_token_data *data;
2117 	struct ctl_softc *softc;
2118 	struct ctl_lun *lun;
2119 	struct tpc_list *list, *tlist;
2120 	struct tpc_token *token;
2121 	int len, lendata, lendesc;
2122 
2123 	CTL_DEBUG_PRINT(("ctl_write_using_token\n"));
2124 
2125 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
2126 	softc = lun->ctl_softc;
2127 	cdb = (struct scsi_write_using_token *)ctsio->cdb;
2128 	len = scsi_4btoul(cdb->length);
2129 
2130 	if (len < sizeof(struct scsi_write_using_token_data) ||
2131 	    len > sizeof(struct scsi_write_using_token_data) +
2132 	     TPC_MAX_SEGS * sizeof(struct scsi_range_desc)) {
2133 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
2134 		    /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
2135 		goto done;
2136 	}
2137 
2138 	/*
2139 	 * If we've got a kernel request that hasn't been malloced yet,
2140 	 * malloc it and tell the caller the data buffer is here.
2141 	 */
2142 	if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
2143 		ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
2144 		ctsio->kern_data_len = len;
2145 		ctsio->kern_total_len = len;
2146 		ctsio->kern_data_resid = 0;
2147 		ctsio->kern_rel_offset = 0;
2148 		ctsio->kern_sg_entries = 0;
2149 		ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
2150 		ctsio->be_move_done = ctl_config_move_done;
2151 		ctl_datamove((union ctl_io *)ctsio);
2152 
2153 		return (CTL_RETVAL_COMPLETE);
2154 	}
2155 
2156 	data = (struct scsi_write_using_token_data *)ctsio->kern_data_ptr;
2157 	lendata = scsi_2btoul(data->length);
2158 	if (lendata < sizeof(struct scsi_write_using_token_data) - 2 +
2159 	    sizeof(struct scsi_range_desc)) {
2160 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2161 		    /*field*/ 0, /*bit_valid*/ 0, /*bit*/ 0);
2162 		goto done;
2163 	}
2164 	lendesc = scsi_2btoul(data->range_descriptor_length);
2165 	if (lendesc < sizeof(struct scsi_range_desc) ||
2166 	    len < sizeof(struct scsi_write_using_token_data) + lendesc ||
2167 	    lendata < sizeof(struct scsi_write_using_token_data) - 2 + lendesc) {
2168 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2169 		    /*field*/ 534, /*bit_valid*/ 0, /*bit*/ 0);
2170 		goto done;
2171 	}
2172 /*
2173 	printf("WUT(list=%u) flags=%x off=%ju len=%x\n",
2174 	    scsi_4btoul(cdb->list_identifier),
2175 	    data->flags, scsi_8btou64(data->offset_into_rod),
2176 	    scsi_2btoul(data->range_descriptor_length));
2177 */
2178 
2179 	/* Validate list of ranges */
2180 	if (tpc_check_ranges_l(&data->desc[0],
2181 	    scsi_2btoul(data->range_descriptor_length) /
2182 	    sizeof(struct scsi_range_desc),
2183 	    lun->be_lun->maxlba) != 0) {
2184 		ctl_set_lba_out_of_range(ctsio);
2185 		goto done;
2186 	}
2187 	if (tpc_check_ranges_x(&data->desc[0],
2188 	    scsi_2btoul(data->range_descriptor_length) /
2189 	    sizeof(struct scsi_range_desc)) != 0) {
2190 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 0,
2191 		    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2192 		    /*bit*/ 0);
2193 		goto done;
2194 	}
2195 
2196 	list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
2197 	list->service_action = cdb->service_action;
2198 	list->init_port = ctsio->io_hdr.nexus.targ_port;
2199 	list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
2200 	list->list_id = scsi_4btoul(cdb->list_identifier);
2201 	list->flags = data->flags;
2202 	list->params = ctsio->kern_data_ptr;
2203 	list->range = &data->desc[0];
2204 	list->nrange = scsi_2btoul(data->range_descriptor_length) /
2205 	    sizeof(struct scsi_range_desc);
2206 	list->offset_into_rod = scsi_8btou64(data->offset_into_rod);
2207 	list->ctsio = ctsio;
2208 	list->lun = lun;
2209 	mtx_lock(&lun->lun_lock);
2210 	tlist = tpc_find_list(lun, list->list_id, list->init_idx);
2211 	if (tlist != NULL && !tlist->completed) {
2212 		mtx_unlock(&lun->lun_lock);
2213 		free(list, M_CTL);
2214 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2215 		    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2216 		    /*bit*/ 0);
2217 		goto done;
2218 	}
2219 	if (tlist != NULL) {
2220 		TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
2221 		free(tlist, M_CTL);
2222 	}
2223 	TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
2224 	mtx_unlock(&lun->lun_lock);
2225 
2226 	/* Block device zero ROD token -> no token. */
2227 	if (scsi_4btoul(data->rod_token) == ROD_TYPE_BLOCK_ZERO) {
2228 		tpc_process(list);
2229 		return (CTL_RETVAL_COMPLETE);
2230 	}
2231 
2232 	mtx_lock(&softc->tpc_lock);
2233 	TAILQ_FOREACH(token, &softc->tpc_tokens, links) {
2234 		if (memcmp(token->token, data->rod_token,
2235 		    sizeof(data->rod_token)) == 0)
2236 			break;
2237 	}
2238 	if (token != NULL) {
2239 		token->active++;
2240 		list->token = token;
2241 		if (data->flags & EC_WUT_DEL_TKN)
2242 			token->timeout = 0;
2243 	}
2244 	mtx_unlock(&softc->tpc_lock);
2245 	if (token == NULL) {
2246 		mtx_lock(&lun->lun_lock);
2247 		TAILQ_REMOVE(&lun->tpc_lists, list, links);
2248 		mtx_unlock(&lun->lun_lock);
2249 		free(list, M_CTL);
2250 		ctl_set_sense(ctsio, /*current_error*/ 1,
2251 		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
2252 		    /*asc*/ 0x23, /*ascq*/ 0x04, SSD_ELEM_NONE);
2253 		goto done;
2254 	}
2255 
2256 	tpc_process(list);
2257 	return (CTL_RETVAL_COMPLETE);
2258 
2259 done:
2260 	if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
2261 		free(ctsio->kern_data_ptr, M_CTL);
2262 		ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
2263 	}
2264 	ctl_done((union ctl_io *)ctsio);
2265 	return (CTL_RETVAL_COMPLETE);
2266 }
2267 
2268 int
2269 ctl_receive_rod_token_information(struct ctl_scsiio *ctsio)
2270 {
2271 	struct ctl_lun *lun;
2272 	struct scsi_receive_rod_token_information *cdb;
2273 	struct scsi_receive_copy_status_lid4_data *data;
2274 	struct tpc_list *list;
2275 	struct tpc_list list_copy;
2276 	uint8_t *ptr;
2277 	int retval;
2278 	int alloc_len, total_len, token_len;
2279 	uint32_t list_id;
2280 
2281 	CTL_DEBUG_PRINT(("ctl_receive_rod_token_information\n"));
2282 
2283 	cdb = (struct scsi_receive_rod_token_information *)ctsio->cdb;
2284 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
2285 
2286 	retval = CTL_RETVAL_COMPLETE;
2287 
2288 	list_id = scsi_4btoul(cdb->list_identifier);
2289 	mtx_lock(&lun->lun_lock);
2290 	list = tpc_find_list(lun, list_id,
2291 	    ctl_get_initindex(&ctsio->io_hdr.nexus));
2292 	if (list == NULL) {
2293 		mtx_unlock(&lun->lun_lock);
2294 		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2295 		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
2296 		    /*bit*/ 0);
2297 		ctl_done((union ctl_io *)ctsio);
2298 		return (retval);
2299 	}
2300 	list_copy = *list;
2301 	if (list->completed) {
2302 		TAILQ_REMOVE(&lun->tpc_lists, list, links);
2303 		free(list, M_CTL);
2304 	}
2305 	mtx_unlock(&lun->lun_lock);
2306 
2307 	token_len = list_copy.res_token_valid ? 2 + sizeof(list_copy.res_token) : 0;
2308 	total_len = sizeof(*data) + list_copy.sense_len + 4 + token_len;
2309 	alloc_len = scsi_4btoul(cdb->length);
2310 
2311 	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
2312 
2313 	ctsio->kern_sg_entries = 0;
2314 
2315 	if (total_len < alloc_len) {
2316 		ctsio->residual = alloc_len - total_len;
2317 		ctsio->kern_data_len = total_len;
2318 		ctsio->kern_total_len = total_len;
2319 	} else {
2320 		ctsio->residual = 0;
2321 		ctsio->kern_data_len = alloc_len;
2322 		ctsio->kern_total_len = alloc_len;
2323 	}
2324 	ctsio->kern_data_resid = 0;
2325 	ctsio->kern_rel_offset = 0;
2326 
2327 	data = (struct scsi_receive_copy_status_lid4_data *)ctsio->kern_data_ptr;
2328 	scsi_ulto4b(sizeof(*data) - 4 + list_copy.sense_len +
2329 	    4 + token_len, data->available_data);
2330 	data->response_to_service_action = list_copy.service_action;
2331 	if (list_copy.completed) {
2332 		if (list_copy.error)
2333 			data->copy_command_status = RCS_CCS_ERROR;
2334 		else if (list_copy.abort)
2335 			data->copy_command_status = RCS_CCS_ABORTED;
2336 		else
2337 			data->copy_command_status = RCS_CCS_COMPLETED;
2338 	} else
2339 		data->copy_command_status = RCS_CCS_INPROG_FG;
2340 	scsi_ulto2b(list_copy.curops, data->operation_counter);
2341 	scsi_ulto4b(UINT32_MAX, data->estimated_status_update_delay);
2342 	data->transfer_count_units = RCS_TC_LBAS;
2343 	scsi_u64to8b(list_copy.cursectors, data->transfer_count);
2344 	scsi_ulto2b(list_copy.curseg, data->segments_processed);
2345 	data->length_of_the_sense_data_field = list_copy.sense_len;
2346 	data->sense_data_length = list_copy.sense_len;
2347 	memcpy(data->sense_data, &list_copy.sense_data, list_copy.sense_len);
2348 
2349 	ptr = &data->sense_data[data->length_of_the_sense_data_field];
2350 	scsi_ulto4b(token_len, &ptr[0]);
2351 	if (list_copy.res_token_valid) {
2352 		scsi_ulto2b(0, &ptr[4]);
2353 		memcpy(&ptr[6], list_copy.res_token, sizeof(list_copy.res_token));
2354 	}
2355 /*
2356 	printf("RRTI(list=%u) valid=%d\n",
2357 	    scsi_4btoul(cdb->list_identifier), list_copy.res_token_valid);
2358 */
2359 	ctl_set_success(ctsio);
2360 	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
2361 	ctsio->be_move_done = ctl_config_move_done;
2362 	ctl_datamove((union ctl_io *)ctsio);
2363 	return (retval);
2364 }
2365 
2366 int
2367 ctl_report_all_rod_tokens(struct ctl_scsiio *ctsio)
2368 {
2369 	struct ctl_softc *softc;
2370 	struct ctl_lun *lun;
2371 	struct scsi_report_all_rod_tokens *cdb;
2372 	struct scsi_report_all_rod_tokens_data *data;
2373 	struct tpc_token *token;
2374 	int retval;
2375 	int alloc_len, total_len, tokens, i;
2376 
2377 	CTL_DEBUG_PRINT(("ctl_receive_rod_token_information\n"));
2378 
2379 	cdb = (struct scsi_report_all_rod_tokens *)ctsio->cdb;
2380 	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
2381 	softc = lun->ctl_softc;
2382 
2383 	retval = CTL_RETVAL_COMPLETE;
2384 
2385 	tokens = 0;
2386 	mtx_lock(&softc->tpc_lock);
2387 	TAILQ_FOREACH(token, &softc->tpc_tokens, links)
2388 		tokens++;
2389 	mtx_unlock(&softc->tpc_lock);
2390 	if (tokens > 512)
2391 		tokens = 512;
2392 
2393 	total_len = sizeof(*data) + tokens * 96;
2394 	alloc_len = scsi_4btoul(cdb->length);
2395 
2396 	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
2397 
2398 	ctsio->kern_sg_entries = 0;
2399 
2400 	if (total_len < alloc_len) {
2401 		ctsio->residual = alloc_len - total_len;
2402 		ctsio->kern_data_len = total_len;
2403 		ctsio->kern_total_len = total_len;
2404 	} else {
2405 		ctsio->residual = 0;
2406 		ctsio->kern_data_len = alloc_len;
2407 		ctsio->kern_total_len = alloc_len;
2408 	}
2409 	ctsio->kern_data_resid = 0;
2410 	ctsio->kern_rel_offset = 0;
2411 
2412 	data = (struct scsi_report_all_rod_tokens_data *)ctsio->kern_data_ptr;
2413 	i = 0;
2414 	mtx_lock(&softc->tpc_lock);
2415 	TAILQ_FOREACH(token, &softc->tpc_tokens, links) {
2416 		if (i >= tokens)
2417 			break;
2418 		memcpy(&data->rod_management_token_list[i * 96],
2419 		    token->token, 96);
2420 		i++;
2421 	}
2422 	mtx_unlock(&softc->tpc_lock);
2423 	scsi_ulto4b(sizeof(*data) - 4 + i * 96, data->available_data);
2424 /*
2425 	printf("RART tokens=%d\n", i);
2426 */
2427 	ctl_set_success(ctsio);
2428 	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
2429 	ctsio->be_move_done = ctl_config_move_done;
2430 	ctl_datamove((union ctl_io *)ctsio);
2431 	return (retval);
2432 }
2433 
2434