xref: /freebsd/sys/cam/scsi/scsi_sg.c (revision 227d67aa5469398eb77e5eca2e525e6aae7b3a61)
11eba4c79SScott Long /*-
21eba4c79SScott Long  * Copyright (c) 2007 Scott Long
31eba4c79SScott Long  * All rights reserved.
41eba4c79SScott Long  *
51eba4c79SScott Long  * Redistribution and use in source and binary forms, with or without
61eba4c79SScott Long  * modification, are permitted provided that the following conditions
71eba4c79SScott Long  * are met:
81eba4c79SScott Long  * 1. Redistributions of source code must retain the above copyright
91eba4c79SScott Long  *    notice, this list of conditions, and the following disclaimer,
101eba4c79SScott Long  *    without modification, immediately at the beginning of the file.
111eba4c79SScott Long  * 2. The name of the author may not be used to endorse or promote products
121eba4c79SScott Long  *    derived from this software without specific prior written permission.
131eba4c79SScott Long  *
141eba4c79SScott Long  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
151eba4c79SScott Long  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
161eba4c79SScott Long  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
171eba4c79SScott Long  * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR
181eba4c79SScott Long  * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
191eba4c79SScott Long  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
201eba4c79SScott Long  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
211eba4c79SScott Long  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
221eba4c79SScott Long  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
231eba4c79SScott Long  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
241eba4c79SScott Long  * SUCH DAMAGE.
251eba4c79SScott Long  */
261eba4c79SScott Long 
271eba4c79SScott Long /*
281eba4c79SScott Long  * scsi_sg peripheral driver.  This driver is meant to implement the Linux
291eba4c79SScott Long  * SG passthrough interface for SCSI.
301eba4c79SScott Long  */
311eba4c79SScott Long 
321eba4c79SScott Long #include <sys/cdefs.h>
331eba4c79SScott Long __FBSDID("$FreeBSD$");
341eba4c79SScott Long 
351eba4c79SScott Long #include <sys/param.h>
361eba4c79SScott Long #include <sys/systm.h>
371eba4c79SScott Long #include <sys/kernel.h>
381eba4c79SScott Long #include <sys/types.h>
391eba4c79SScott Long #include <sys/bio.h>
401eba4c79SScott Long #include <sys/malloc.h>
411eba4c79SScott Long #include <sys/fcntl.h>
421eba4c79SScott Long #include <sys/ioccom.h>
431eba4c79SScott Long #include <sys/conf.h>
441eba4c79SScott Long #include <sys/errno.h>
451eba4c79SScott Long #include <sys/devicestat.h>
461eba4c79SScott Long #include <sys/proc.h>
471eba4c79SScott Long #include <sys/uio.h>
481eba4c79SScott Long 
491eba4c79SScott Long #include <cam/cam.h>
501eba4c79SScott Long #include <cam/cam_ccb.h>
511eba4c79SScott Long #include <cam/cam_periph.h>
521eba4c79SScott Long #include <cam/cam_queue.h>
531eba4c79SScott Long #include <cam/cam_xpt_periph.h>
541eba4c79SScott Long #include <cam/cam_debug.h>
551eba4c79SScott Long #include <cam/cam_sim.h>
561eba4c79SScott Long 
571eba4c79SScott Long #include <cam/scsi/scsi_all.h>
581eba4c79SScott Long #include <cam/scsi/scsi_message.h>
591eba4c79SScott Long #include <cam/scsi/scsi_sg.h>
601eba4c79SScott Long 
611eba4c79SScott Long #include <compat/linux/linux_ioctl.h>
621eba4c79SScott Long 
631eba4c79SScott Long typedef enum {
64c552ebe1SKenneth D. Merry 	SG_FLAG_LOCKED		= 0x01,
65c552ebe1SKenneth D. Merry 	SG_FLAG_INVALID		= 0x02
661eba4c79SScott Long } sg_flags;
671eba4c79SScott Long 
681eba4c79SScott Long typedef enum {
691eba4c79SScott Long 	SG_STATE_NORMAL
701eba4c79SScott Long } sg_state;
711eba4c79SScott Long 
721eba4c79SScott Long typedef enum {
73472cdbefSScott Long 	SG_RDWR_FREE,
741eba4c79SScott Long 	SG_RDWR_INPROG,
751eba4c79SScott Long 	SG_RDWR_DONE
761eba4c79SScott Long } sg_rdwr_state;
771eba4c79SScott Long 
781eba4c79SScott Long typedef enum {
79*227d67aaSAlexander Motin 	SG_CCB_RDWR_IO
801eba4c79SScott Long } sg_ccb_types;
811eba4c79SScott Long 
821eba4c79SScott Long #define ccb_type	ppriv_field0
831eba4c79SScott Long #define ccb_rdwr	ppriv_ptr1
841eba4c79SScott Long 
851eba4c79SScott Long struct sg_rdwr {
861eba4c79SScott Long 	TAILQ_ENTRY(sg_rdwr)	rdwr_link;
871eba4c79SScott Long 	int			tag;
881eba4c79SScott Long 	int			state;
891eba4c79SScott Long 	int			buf_len;
901eba4c79SScott Long 	char			*buf;
911eba4c79SScott Long 	union ccb		*ccb;
921eba4c79SScott Long 	union {
931eba4c79SScott Long 		struct sg_header hdr;
941eba4c79SScott Long 		struct sg_io_hdr io_hdr;
951eba4c79SScott Long 	} hdr;
961eba4c79SScott Long };
971eba4c79SScott Long 
981eba4c79SScott Long struct sg_softc {
991eba4c79SScott Long 	sg_state		state;
1001eba4c79SScott Long 	sg_flags		flags;
10186d45c7fSKenneth D. Merry 	int			open_count;
1021eba4c79SScott Long 	struct devstat		*device_stats;
1031eba4c79SScott Long 	TAILQ_HEAD(, sg_rdwr)	rdwr_done;
1041eba4c79SScott Long 	struct cdev		*dev;
105715ab212SScott Long 	int			sg_timeout;
106715ab212SScott Long 	int			sg_user_timeout;
107715ab212SScott Long 	uint8_t			pd_type;
1081eba4c79SScott Long 	union ccb		saved_ccb;
1091eba4c79SScott Long };
1101eba4c79SScott Long 
1111eba4c79SScott Long static d_open_t		sgopen;
1121eba4c79SScott Long static d_close_t	sgclose;
1131eba4c79SScott Long static d_ioctl_t	sgioctl;
1141eba4c79SScott Long static d_write_t	sgwrite;
1151eba4c79SScott Long static d_read_t		sgread;
1161eba4c79SScott Long 
1171eba4c79SScott Long static periph_init_t	sginit;
1181eba4c79SScott Long static periph_ctor_t	sgregister;
1191eba4c79SScott Long static periph_oninv_t	sgoninvalidate;
1201eba4c79SScott Long static periph_dtor_t	sgcleanup;
1211eba4c79SScott Long static void		sgasync(void *callback_arg, uint32_t code,
1221eba4c79SScott Long 				struct cam_path *path, void *arg);
1231eba4c79SScott Long static void		sgdone(struct cam_periph *periph, union ccb *done_ccb);
1241eba4c79SScott Long static int		sgsendccb(struct cam_periph *periph, union ccb *ccb);
1251eba4c79SScott Long static int		sgsendrdwr(struct cam_periph *periph, union ccb *ccb);
1261eba4c79SScott Long static int		sgerror(union ccb *ccb, uint32_t cam_flags,
1271eba4c79SScott Long 				uint32_t sense_flags);
1281eba4c79SScott Long static void		sg_scsiio_status(struct ccb_scsiio *csio,
1291eba4c79SScott Long 					 u_short *hoststat, u_short *drvstat);
1301eba4c79SScott Long 
1311eba4c79SScott Long static int		scsi_group_len(u_char cmd);
1321eba4c79SScott Long 
1331eba4c79SScott Long static struct periph_driver sgdriver =
1341eba4c79SScott Long {
1351eba4c79SScott Long 	sginit, "sg",
1361eba4c79SScott Long 	TAILQ_HEAD_INITIALIZER(sgdriver.units), /* gen */ 0
1371eba4c79SScott Long };
1381eba4c79SScott Long PERIPHDRIVER_DECLARE(sg, sgdriver);
1391eba4c79SScott Long 
1401eba4c79SScott Long static struct cdevsw sg_cdevsw = {
1411eba4c79SScott Long 	.d_version =	D_VERSION,
142c552ebe1SKenneth D. Merry 	.d_flags =	D_NEEDGIANT | D_TRACKCLOSE,
1431eba4c79SScott Long 	.d_open =	sgopen,
1441eba4c79SScott Long 	.d_close =	sgclose,
1451eba4c79SScott Long 	.d_ioctl =	sgioctl,
1461eba4c79SScott Long 	.d_write =	sgwrite,
1471eba4c79SScott Long 	.d_read =	sgread,
1481eba4c79SScott Long 	.d_name =	"sg",
1491eba4c79SScott Long };
1501eba4c79SScott Long 
1511eba4c79SScott Long static int sg_version = 30125;
1521eba4c79SScott Long 
1531eba4c79SScott Long static void
1541eba4c79SScott Long sginit(void)
1551eba4c79SScott Long {
1561eba4c79SScott Long 	cam_status status;
1571eba4c79SScott Long 
1581eba4c79SScott Long 	/*
1591eba4c79SScott Long 	 * Install a global async callback.  This callback will receive aync
1601eba4c79SScott Long 	 * callbacks like "new device found".
1611eba4c79SScott Long 	 */
16285d92640SScott Long 	status = xpt_register_async(AC_FOUND_DEVICE, sgasync, NULL, NULL);
1631eba4c79SScott Long 
1641eba4c79SScott Long 	if (status != CAM_REQ_CMP) {
1651eba4c79SScott Long 		printf("sg: Failed to attach master async callbac "
1661eba4c79SScott Long 			"due to status 0x%x!\n", status);
1671eba4c79SScott Long 	}
1681eba4c79SScott Long }
1691eba4c79SScott Long 
1701eba4c79SScott Long static void
17186d45c7fSKenneth D. Merry sgdevgonecb(void *arg)
17286d45c7fSKenneth D. Merry {
17386d45c7fSKenneth D. Merry 	struct cam_periph *periph;
17486d45c7fSKenneth D. Merry 	struct sg_softc *softc;
175*227d67aaSAlexander Motin 	struct mtx *mtx;
17686d45c7fSKenneth D. Merry 	int i;
17786d45c7fSKenneth D. Merry 
17886d45c7fSKenneth D. Merry 	periph = (struct cam_periph *)arg;
179*227d67aaSAlexander Motin 	mtx = cam_periph_mtx(periph);
180*227d67aaSAlexander Motin 	mtx_lock(mtx);
18186d45c7fSKenneth D. Merry 
182*227d67aaSAlexander Motin 	softc = (struct sg_softc *)periph->softc;
18386d45c7fSKenneth D. Merry 	KASSERT(softc->open_count >= 0, ("Negative open count %d",
18486d45c7fSKenneth D. Merry 		softc->open_count));
18586d45c7fSKenneth D. Merry 
18686d45c7fSKenneth D. Merry 	/*
18786d45c7fSKenneth D. Merry 	 * When we get this callback, we will get no more close calls from
18886d45c7fSKenneth D. Merry 	 * devfs.  So if we have any dangling opens, we need to release the
18986d45c7fSKenneth D. Merry 	 * reference held for that particular context.
19086d45c7fSKenneth D. Merry 	 */
19186d45c7fSKenneth D. Merry 	for (i = 0; i < softc->open_count; i++)
19286d45c7fSKenneth D. Merry 		cam_periph_release_locked(periph);
19386d45c7fSKenneth D. Merry 
19486d45c7fSKenneth D. Merry 	softc->open_count = 0;
19586d45c7fSKenneth D. Merry 
19686d45c7fSKenneth D. Merry 	/*
19786d45c7fSKenneth D. Merry 	 * Release the reference held for the device node, it is gone now.
19886d45c7fSKenneth D. Merry 	 */
19986d45c7fSKenneth D. Merry 	cam_periph_release_locked(periph);
20086d45c7fSKenneth D. Merry 
20186d45c7fSKenneth D. Merry 	/*
202*227d67aaSAlexander Motin 	 * We reference the lock directly here, instead of using
20386d45c7fSKenneth D. Merry 	 * cam_periph_unlock().  The reason is that the final call to
20486d45c7fSKenneth D. Merry 	 * cam_periph_release_locked() above could result in the periph
20586d45c7fSKenneth D. Merry 	 * getting freed.  If that is the case, dereferencing the periph
20686d45c7fSKenneth D. Merry 	 * with a cam_periph_unlock() call would cause a page fault.
20786d45c7fSKenneth D. Merry 	 */
208*227d67aaSAlexander Motin 	mtx_unlock(mtx);
20986d45c7fSKenneth D. Merry }
21086d45c7fSKenneth D. Merry 
21186d45c7fSKenneth D. Merry 
21286d45c7fSKenneth D. Merry static void
2131eba4c79SScott Long sgoninvalidate(struct cam_periph *periph)
2141eba4c79SScott Long {
2151eba4c79SScott Long 	struct sg_softc *softc;
2161eba4c79SScott Long 
2171eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
2181eba4c79SScott Long 
2191eba4c79SScott Long 	/*
2201eba4c79SScott Long 	 * Deregister any async callbacks.
2211eba4c79SScott Long 	 */
22285d92640SScott Long 	xpt_register_async(0, sgasync, periph, periph->path);
2231eba4c79SScott Long 
2241eba4c79SScott Long 	softc->flags |= SG_FLAG_INVALID;
2251eba4c79SScott Long 
2261eba4c79SScott Long 	/*
22786d45c7fSKenneth D. Merry 	 * Tell devfs this device has gone away, and ask for a callback
22886d45c7fSKenneth D. Merry 	 * when it has cleaned up its state.
22986d45c7fSKenneth D. Merry 	 */
23086d45c7fSKenneth D. Merry 	destroy_dev_sched_cb(softc->dev, sgdevgonecb, periph);
23186d45c7fSKenneth D. Merry 
23286d45c7fSKenneth D. Merry 	/*
2331eba4c79SScott Long 	 * XXX Return all queued I/O with ENXIO.
2341eba4c79SScott Long 	 * XXX Handle any transactions queued to the card
2351eba4c79SScott Long 	 *     with XPT_ABORT_CCB.
2361eba4c79SScott Long 	 */
2371eba4c79SScott Long 
2381eba4c79SScott Long }
2391eba4c79SScott Long 
2401eba4c79SScott Long static void
2411eba4c79SScott Long sgcleanup(struct cam_periph *periph)
2421eba4c79SScott Long {
2431eba4c79SScott Long 	struct sg_softc *softc;
2441eba4c79SScott Long 
2451eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
24686d45c7fSKenneth D. Merry 
2475f3fed85SEdward Tomasz Napierala 	devstat_remove_entry(softc->device_stats);
24886d45c7fSKenneth D. Merry 
2491eba4c79SScott Long 	free(softc, M_DEVBUF);
2501eba4c79SScott Long }
2511eba4c79SScott Long 
2521eba4c79SScott Long static void
2531eba4c79SScott Long sgasync(void *callback_arg, uint32_t code, struct cam_path *path, void *arg)
2541eba4c79SScott Long {
2551eba4c79SScott Long 	struct cam_periph *periph;
2561eba4c79SScott Long 
2571eba4c79SScott Long 	periph = (struct cam_periph *)callback_arg;
2581eba4c79SScott Long 
2591eba4c79SScott Long 	switch (code) {
2601eba4c79SScott Long 	case AC_FOUND_DEVICE:
2611eba4c79SScott Long 	{
2621eba4c79SScott Long 		struct ccb_getdev *cgd;
2631eba4c79SScott Long 		cam_status status;
2641eba4c79SScott Long 
2651eba4c79SScott Long 		cgd = (struct ccb_getdev *)arg;
2661eba4c79SScott Long 		if (cgd == NULL)
2671eba4c79SScott Long 			break;
2681eba4c79SScott Long 
26952c9ce25SScott Long 		if (cgd->protocol != PROTO_SCSI)
27052c9ce25SScott Long 			break;
27152c9ce25SScott Long 
2721eba4c79SScott Long 		/*
2731eba4c79SScott Long 		 * Allocate a peripheral instance for this device and
2741eba4c79SScott Long 		 * start the probe process.
2751eba4c79SScott Long 		 */
2761eba4c79SScott Long 		status = cam_periph_alloc(sgregister, sgoninvalidate,
277*227d67aaSAlexander Motin 					  sgcleanup, NULL, "sg",
278*227d67aaSAlexander Motin 					  CAM_PERIPH_BIO, path,
2791eba4c79SScott Long 					  sgasync, AC_FOUND_DEVICE, cgd);
2801eba4c79SScott Long 		if ((status != CAM_REQ_CMP) && (status != CAM_REQ_INPROG)) {
2811eba4c79SScott Long 			const struct cam_status_entry *entry;
2821eba4c79SScott Long 
2831eba4c79SScott Long 			entry = cam_fetch_status_entry(status);
2841eba4c79SScott Long 			printf("sgasync: Unable to attach new device "
2851eba4c79SScott Long 				"due to status %#x: %s\n", status, entry ?
2861eba4c79SScott Long 				entry->status_text : "Unknown");
2871eba4c79SScott Long 		}
2881eba4c79SScott Long 		break;
2891eba4c79SScott Long 	}
2901eba4c79SScott Long 	default:
2911eba4c79SScott Long 		cam_periph_async(periph, code, path, arg);
2921eba4c79SScott Long 		break;
2931eba4c79SScott Long 	}
2941eba4c79SScott Long }
2951eba4c79SScott Long 
2961eba4c79SScott Long static cam_status
2971eba4c79SScott Long sgregister(struct cam_periph *periph, void *arg)
2981eba4c79SScott Long {
2991eba4c79SScott Long 	struct sg_softc *softc;
3001eba4c79SScott Long 	struct ccb_getdev *cgd;
301b8b6b5d3SAlexander Motin 	struct ccb_pathinq cpi;
3021eba4c79SScott Long 	int no_tags;
3031eba4c79SScott Long 
3041eba4c79SScott Long 	cgd = (struct ccb_getdev *)arg;
3051eba4c79SScott Long 	if (cgd == NULL) {
3061eba4c79SScott Long 		printf("sgregister: no getdev CCB, can't register device\n");
3071eba4c79SScott Long 		return (CAM_REQ_CMP_ERR);
3081eba4c79SScott Long 	}
3091eba4c79SScott Long 
3104400b36dSScott Long 	softc = malloc(sizeof(*softc), M_DEVBUF, M_ZERO | M_NOWAIT);
3111eba4c79SScott Long 	if (softc == NULL) {
3121eba4c79SScott Long 		printf("sgregister: Unable to allocate softc\n");
3131eba4c79SScott Long 		return (CAM_REQ_CMP_ERR);
3141eba4c79SScott Long 	}
3151eba4c79SScott Long 
3161eba4c79SScott Long 	softc->state = SG_STATE_NORMAL;
3171eba4c79SScott Long 	softc->pd_type = SID_TYPE(&cgd->inq_data);
318715ab212SScott Long 	softc->sg_timeout = SG_DEFAULT_TIMEOUT / SG_DEFAULT_HZ * hz;
319715ab212SScott Long 	softc->sg_user_timeout = SG_DEFAULT_TIMEOUT;
3201eba4c79SScott Long 	TAILQ_INIT(&softc->rdwr_done);
3211eba4c79SScott Long 	periph->softc = softc;
3221eba4c79SScott Long 
323b8b6b5d3SAlexander Motin 	bzero(&cpi, sizeof(cpi));
324b8b6b5d3SAlexander Motin 	xpt_setup_ccb(&cpi.ccb_h, periph->path, CAM_PRIORITY_NORMAL);
325b8b6b5d3SAlexander Motin 	cpi.ccb_h.func_code = XPT_PATH_INQ;
326b8b6b5d3SAlexander Motin 	xpt_action((union ccb *)&cpi);
327b8b6b5d3SAlexander Motin 
3281eba4c79SScott Long 	/*
3291eba4c79SScott Long 	 * We pass in 0 for all blocksize, since we don't know what the
3301eba4c79SScott Long 	 * blocksize of the device is, if it even has a blocksize.
3311eba4c79SScott Long 	 */
33285d92640SScott Long 	cam_periph_unlock(periph);
3331eba4c79SScott Long 	no_tags = (cgd->inq_data.flags & SID_CmdQue) == 0;
3341eba4c79SScott Long 	softc->device_stats = devstat_new_entry("sg",
335d3ce8327SEd Schouten 			periph->unit_number, 0,
3361eba4c79SScott Long 			DEVSTAT_NO_BLOCKSIZE
3371eba4c79SScott Long 			| (no_tags ? DEVSTAT_NO_ORDERED_TAGS : 0),
3381eba4c79SScott Long 			softc->pd_type |
339b8b6b5d3SAlexander Motin 			XPORT_DEVSTAT_TYPE(cpi.transport) |
3401eba4c79SScott Long 			DEVSTAT_TYPE_PASS,
3411eba4c79SScott Long 			DEVSTAT_PRIORITY_PASS);
3421eba4c79SScott Long 
34386d45c7fSKenneth D. Merry 	/*
34486d45c7fSKenneth D. Merry 	 * Acquire a reference to the periph before we create the devfs
34586d45c7fSKenneth D. Merry 	 * instance for it.  We'll release this reference once the devfs
34686d45c7fSKenneth D. Merry 	 * instance has been freed.
34786d45c7fSKenneth D. Merry 	 */
34886d45c7fSKenneth D. Merry 	if (cam_periph_acquire(periph) != CAM_REQ_CMP) {
34986d45c7fSKenneth D. Merry 		xpt_print(periph->path, "%s: lost periph during "
35086d45c7fSKenneth D. Merry 			  "registration!\n", __func__);
35186d45c7fSKenneth D. Merry 		cam_periph_lock(periph);
35286d45c7fSKenneth D. Merry 		return (CAM_REQ_CMP_ERR);
35386d45c7fSKenneth D. Merry 	}
35486d45c7fSKenneth D. Merry 
3551eba4c79SScott Long 	/* Register the device */
356d3ce8327SEd Schouten 	softc->dev = make_dev(&sg_cdevsw, periph->unit_number,
3571eba4c79SScott Long 			      UID_ROOT, GID_OPERATOR, 0600, "%s%d",
3581eba4c79SScott Long 			      periph->periph_name, periph->unit_number);
359cf454e30SMatt Jacob 	if (periph->unit_number < 26) {
360c59b4dcdSMatt Jacob 		(void)make_dev_alias(softc->dev, "sg%c",
361c59b4dcdSMatt Jacob 		    periph->unit_number + 'a');
362cf454e30SMatt Jacob 	} else {
363cf454e30SMatt Jacob 		(void)make_dev_alias(softc->dev, "sg%c%c",
364c59b4dcdSMatt Jacob 		    ((periph->unit_number / 26) - 1) + 'a',
365c59b4dcdSMatt Jacob 		    (periph->unit_number % 26) + 'a');
366cf454e30SMatt Jacob 	}
3672b83592fSScott Long 	cam_periph_lock(periph);
3681eba4c79SScott Long 	softc->dev->si_drv1 = periph;
3691eba4c79SScott Long 
3701eba4c79SScott Long 	/*
3711eba4c79SScott Long 	 * Add as async callback so that we get
3721eba4c79SScott Long 	 * notified if this device goes away.
3731eba4c79SScott Long 	 */
37485d92640SScott Long 	xpt_register_async(AC_LOST_DEVICE, sgasync, periph, periph->path);
3751eba4c79SScott Long 
3761eba4c79SScott Long 	if (bootverbose)
3771eba4c79SScott Long 		xpt_announce_periph(periph, NULL);
3781eba4c79SScott Long 
3791eba4c79SScott Long 	return (CAM_REQ_CMP);
3801eba4c79SScott Long }
3811eba4c79SScott Long 
3821eba4c79SScott Long static void
3831eba4c79SScott Long sgdone(struct cam_periph *periph, union ccb *done_ccb)
3841eba4c79SScott Long {
3851eba4c79SScott Long 	struct sg_softc *softc;
3861eba4c79SScott Long 	struct ccb_scsiio *csio;
3871eba4c79SScott Long 
3881eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
3891eba4c79SScott Long 	csio = &done_ccb->csio;
3901eba4c79SScott Long 	switch (csio->ccb_h.ccb_type) {
3911eba4c79SScott Long 	case SG_CCB_RDWR_IO:
3921eba4c79SScott Long 	{
3931eba4c79SScott Long 		struct sg_rdwr *rdwr;
3941eba4c79SScott Long 		int state;
3951eba4c79SScott Long 
3961eba4c79SScott Long 		devstat_end_transaction(softc->device_stats,
3971eba4c79SScott Long 					csio->dxfer_len,
3981eba4c79SScott Long 					csio->tag_action & 0xf,
3991eba4c79SScott Long 					((csio->ccb_h.flags & CAM_DIR_MASK) ==
4001eba4c79SScott Long 					CAM_DIR_NONE) ? DEVSTAT_NO_DATA :
4011eba4c79SScott Long 					(csio->ccb_h.flags & CAM_DIR_OUT) ?
4021eba4c79SScott Long 					DEVSTAT_WRITE : DEVSTAT_READ,
4031eba4c79SScott Long 					NULL, NULL);
4041eba4c79SScott Long 
4051eba4c79SScott Long 		rdwr = done_ccb->ccb_h.ccb_rdwr;
4061eba4c79SScott Long 		state = rdwr->state;
4071eba4c79SScott Long 		rdwr->state = SG_RDWR_DONE;
4081eba4c79SScott Long 		wakeup(rdwr);
4091eba4c79SScott Long 		break;
4101eba4c79SScott Long 	}
4111eba4c79SScott Long 	default:
4121eba4c79SScott Long 		panic("unknown sg CCB type");
4131eba4c79SScott Long 	}
4141eba4c79SScott Long }
4151eba4c79SScott Long 
4161eba4c79SScott Long static int
4171eba4c79SScott Long sgopen(struct cdev *dev, int flags, int fmt, struct thread *td)
4181eba4c79SScott Long {
4191eba4c79SScott Long 	struct cam_periph *periph;
4201eba4c79SScott Long 	struct sg_softc *softc;
4211eba4c79SScott Long 	int error = 0;
4221eba4c79SScott Long 
4231eba4c79SScott Long 	periph = (struct cam_periph *)dev->si_drv1;
4241eba4c79SScott Long 	if (periph == NULL)
4251eba4c79SScott Long 		return (ENXIO);
4261eba4c79SScott Long 
4278900f4b8SKenneth D. Merry 	if (cam_periph_acquire(periph) != CAM_REQ_CMP)
4288900f4b8SKenneth D. Merry 		return (ENXIO);
4298900f4b8SKenneth D. Merry 
4301eba4c79SScott Long 	/*
4311eba4c79SScott Long 	 * Don't allow access when we're running at a high securelevel.
4321eba4c79SScott Long 	 */
4331eba4c79SScott Long 	error = securelevel_gt(td->td_ucred, 1);
4348900f4b8SKenneth D. Merry 	if (error) {
4358900f4b8SKenneth D. Merry 		cam_periph_release(periph);
4361eba4c79SScott Long 		return (error);
4378900f4b8SKenneth D. Merry 	}
4381eba4c79SScott Long 
4392b83592fSScott Long 	cam_periph_lock(periph);
4402b83592fSScott Long 
4412b83592fSScott Long 	softc = (struct sg_softc *)periph->softc;
4422b83592fSScott Long 	if (softc->flags & SG_FLAG_INVALID) {
443c552ebe1SKenneth D. Merry 		cam_periph_release_locked(periph);
4442b83592fSScott Long 		cam_periph_unlock(periph);
4452b83592fSScott Long 		return (ENXIO);
4462b83592fSScott Long 	}
4471eba4c79SScott Long 
44886d45c7fSKenneth D. Merry 	softc->open_count++;
44986d45c7fSKenneth D. Merry 
450835187bfSScott Long 	cam_periph_unlock(periph);
4511eba4c79SScott Long 
4521eba4c79SScott Long 	return (error);
4531eba4c79SScott Long }
4541eba4c79SScott Long 
4551eba4c79SScott Long static int
4561eba4c79SScott Long sgclose(struct cdev *dev, int flag, int fmt, struct thread *td)
4571eba4c79SScott Long {
4581eba4c79SScott Long 	struct cam_periph *periph;
45986d45c7fSKenneth D. Merry 	struct sg_softc   *softc;
460*227d67aaSAlexander Motin 	struct mtx *mtx;
4611eba4c79SScott Long 
4621eba4c79SScott Long 	periph = (struct cam_periph *)dev->si_drv1;
4631eba4c79SScott Long 	if (periph == NULL)
4641eba4c79SScott Long 		return (ENXIO);
465*227d67aaSAlexander Motin 	mtx = cam_periph_mtx(periph);
466*227d67aaSAlexander Motin 	mtx_lock(mtx);
4671eba4c79SScott Long 
46886d45c7fSKenneth D. Merry 	softc = periph->softc;
46986d45c7fSKenneth D. Merry 	softc->open_count--;
47086d45c7fSKenneth D. Merry 
47186d45c7fSKenneth D. Merry 	cam_periph_release_locked(periph);
47286d45c7fSKenneth D. Merry 
47386d45c7fSKenneth D. Merry 	/*
474*227d67aaSAlexander Motin 	 * We reference the lock directly here, instead of using
47586d45c7fSKenneth D. Merry 	 * cam_periph_unlock().  The reason is that the call to
47686d45c7fSKenneth D. Merry 	 * cam_periph_release_locked() above could result in the periph
47786d45c7fSKenneth D. Merry 	 * getting freed.  If that is the case, dereferencing the periph
47886d45c7fSKenneth D. Merry 	 * with a cam_periph_unlock() call would cause a page fault.
47986d45c7fSKenneth D. Merry 	 *
48086d45c7fSKenneth D. Merry 	 * cam_periph_release() avoids this problem using the same method,
48186d45c7fSKenneth D. Merry 	 * but we're manually acquiring and dropping the lock here to
48286d45c7fSKenneth D. Merry 	 * protect the open count and avoid another lock acquisition and
48386d45c7fSKenneth D. Merry 	 * release.
48486d45c7fSKenneth D. Merry 	 */
485*227d67aaSAlexander Motin 	mtx_unlock(mtx);
4861eba4c79SScott Long 
4871eba4c79SScott Long 	return (0);
4881eba4c79SScott Long }
4891eba4c79SScott Long 
4901eba4c79SScott Long static int
4911eba4c79SScott Long sgioctl(struct cdev *dev, u_long cmd, caddr_t arg, int flag, struct thread *td)
4921eba4c79SScott Long {
4931eba4c79SScott Long 	union ccb *ccb;
4941eba4c79SScott Long 	struct ccb_scsiio *csio;
4951eba4c79SScott Long 	struct cam_periph *periph;
4961eba4c79SScott Long 	struct sg_softc *softc;
4971eba4c79SScott Long 	struct sg_io_hdr req;
4981eba4c79SScott Long 	int dir, error;
4991eba4c79SScott Long 
5001eba4c79SScott Long 	periph = (struct cam_periph *)dev->si_drv1;
5011eba4c79SScott Long 	if (periph == NULL)
5021eba4c79SScott Long 		return (ENXIO);
5031eba4c79SScott Long 
5042b83592fSScott Long 	cam_periph_lock(periph);
5052b83592fSScott Long 
5061eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
5071eba4c79SScott Long 	error = 0;
5081eba4c79SScott Long 
5091eba4c79SScott Long 	switch (cmd) {
5101eba4c79SScott Long 	case LINUX_SCSI_GET_BUS_NUMBER: {
5111eba4c79SScott Long 		int busno;
5121eba4c79SScott Long 
5131eba4c79SScott Long 		busno = xpt_path_path_id(periph->path);
5141eba4c79SScott Long 		error = copyout(&busno, arg, sizeof(busno));
5151eba4c79SScott Long 		break;
5161eba4c79SScott Long 	}
5171eba4c79SScott Long 	case LINUX_SCSI_GET_IDLUN: {
5181eba4c79SScott Long 		struct scsi_idlun idlun;
5191eba4c79SScott Long 		struct cam_sim *sim;
5201eba4c79SScott Long 
5211eba4c79SScott Long 		idlun.dev_id = xpt_path_target_id(periph->path);
5221eba4c79SScott Long 		sim = xpt_path_sim(periph->path);
5231eba4c79SScott Long 		idlun.host_unique_id = sim->unit_number;
5241eba4c79SScott Long 		error = copyout(&idlun, arg, sizeof(idlun));
5251eba4c79SScott Long 		break;
5261eba4c79SScott Long 	}
5271eba4c79SScott Long 	case SG_GET_VERSION_NUM:
5281eba4c79SScott Long 	case LINUX_SG_GET_VERSION_NUM:
5291eba4c79SScott Long 		error = copyout(&sg_version, arg, sizeof(sg_version));
5301eba4c79SScott Long 		break;
5311eba4c79SScott Long 	case SG_SET_TIMEOUT:
532715ab212SScott Long 	case LINUX_SG_SET_TIMEOUT: {
533715ab212SScott Long 		u_int user_timeout;
534715ab212SScott Long 
535715ab212SScott Long 		error = copyin(arg, &user_timeout, sizeof(u_int));
536715ab212SScott Long 		if (error == 0) {
537715ab212SScott Long 			softc->sg_user_timeout = user_timeout;
538715ab212SScott Long 			softc->sg_timeout = user_timeout / SG_DEFAULT_HZ * hz;
539715ab212SScott Long 		}
5401eba4c79SScott Long 		break;
541715ab212SScott Long 	}
5421eba4c79SScott Long 	case SG_GET_TIMEOUT:
5431eba4c79SScott Long 	case LINUX_SG_GET_TIMEOUT:
5441eba4c79SScott Long 		/*
545715ab212SScott Long 		 * The value is returned directly to the syscall.
5461eba4c79SScott Long 		 */
547715ab212SScott Long 		td->td_retval[0] = softc->sg_user_timeout;
5481eba4c79SScott Long 		error = 0;
5491eba4c79SScott Long 		break;
5501eba4c79SScott Long 	case SG_IO:
5511eba4c79SScott Long 	case LINUX_SG_IO:
5521eba4c79SScott Long 		error = copyin(arg, &req, sizeof(req));
5531eba4c79SScott Long 		if (error)
5541eba4c79SScott Long 			break;
5551eba4c79SScott Long 
5561eba4c79SScott Long 		if (req.cmd_len > IOCDBLEN) {
5571eba4c79SScott Long 			error = EINVAL;
5581eba4c79SScott Long 			break;
5591eba4c79SScott Long 		}
5601eba4c79SScott Long 
5611eba4c79SScott Long 		if (req.iovec_count != 0) {
5621eba4c79SScott Long 			error = EOPNOTSUPP;
5631eba4c79SScott Long 			break;
5641eba4c79SScott Long 		}
5651eba4c79SScott Long 
5661e637ba6SAlexander Motin 		ccb = cam_periph_getccb(periph, CAM_PRIORITY_NORMAL);
5671eba4c79SScott Long 		csio = &ccb->csio;
5681eba4c79SScott Long 
5691eba4c79SScott Long 		error = copyin(req.cmdp, &csio->cdb_io.cdb_bytes,
5701eba4c79SScott Long 		    req.cmd_len);
5711eba4c79SScott Long 		if (error) {
5721eba4c79SScott Long 			xpt_release_ccb(ccb);
5731eba4c79SScott Long 			break;
5741eba4c79SScott Long 		}
5751eba4c79SScott Long 
5761eba4c79SScott Long 		switch(req.dxfer_direction) {
5771eba4c79SScott Long 		case SG_DXFER_TO_DEV:
5781eba4c79SScott Long 			dir = CAM_DIR_OUT;
5791eba4c79SScott Long 			break;
5801eba4c79SScott Long 		case SG_DXFER_FROM_DEV:
5811eba4c79SScott Long 			dir = CAM_DIR_IN;
5821eba4c79SScott Long 			break;
5831eba4c79SScott Long 		case SG_DXFER_TO_FROM_DEV:
5841eba4c79SScott Long 			dir = CAM_DIR_IN | CAM_DIR_OUT;
5851eba4c79SScott Long 			break;
5861eba4c79SScott Long 		case SG_DXFER_NONE:
5871eba4c79SScott Long 		default:
5881eba4c79SScott Long 			dir = CAM_DIR_NONE;
5891eba4c79SScott Long 			break;
5901eba4c79SScott Long 		}
5911eba4c79SScott Long 
5921eba4c79SScott Long 		cam_fill_csio(csio,
5931eba4c79SScott Long 			      /*retries*/1,
5941eba4c79SScott Long 			      sgdone,
5951eba4c79SScott Long 			      dir|CAM_DEV_QFRZDIS,
5961eba4c79SScott Long 			      MSG_SIMPLE_Q_TAG,
5971eba4c79SScott Long 			      req.dxferp,
5981eba4c79SScott Long 			      req.dxfer_len,
5991eba4c79SScott Long 			      req.mx_sb_len,
6001eba4c79SScott Long 			      req.cmd_len,
6011eba4c79SScott Long 			      req.timeout);
6021eba4c79SScott Long 
6031eba4c79SScott Long 		error = sgsendccb(periph, ccb);
6041eba4c79SScott Long 		if (error) {
6051eba4c79SScott Long 			req.host_status = DID_ERROR;
6061eba4c79SScott Long 			req.driver_status = DRIVER_INVALID;
6071eba4c79SScott Long 			xpt_release_ccb(ccb);
6081eba4c79SScott Long 			break;
6091eba4c79SScott Long 		}
6101eba4c79SScott Long 
6111eba4c79SScott Long 		req.status = csio->scsi_status;
6121eba4c79SScott Long 		req.masked_status = (csio->scsi_status >> 1) & 0x7f;
6131eba4c79SScott Long 		sg_scsiio_status(csio, &req.host_status, &req.driver_status);
6141eba4c79SScott Long 		req.resid = csio->resid;
6151eba4c79SScott Long 		req.duration = csio->ccb_h.timeout;
6161eba4c79SScott Long 		req.info = 0;
6171eba4c79SScott Long 
6181eba4c79SScott Long 		error = copyout(&req, arg, sizeof(req));
6191eba4c79SScott Long 		if ((error == 0) && (csio->ccb_h.status & CAM_AUTOSNS_VALID)
6201eba4c79SScott Long 		    && (req.sbp != NULL)) {
6211eba4c79SScott Long 			req.sb_len_wr = req.mx_sb_len - csio->sense_resid;
6221eba4c79SScott Long 			error = copyout(&csio->sense_data, req.sbp,
6231eba4c79SScott Long 					req.sb_len_wr);
6241eba4c79SScott Long 		}
6251eba4c79SScott Long 
6261eba4c79SScott Long 		xpt_release_ccb(ccb);
6271eba4c79SScott Long 		break;
6281eba4c79SScott Long 
6291eba4c79SScott Long 	case SG_GET_RESERVED_SIZE:
6301eba4c79SScott Long 	case LINUX_SG_GET_RESERVED_SIZE: {
6311eba4c79SScott Long 		int size = 32768;
6321eba4c79SScott Long 
6331eba4c79SScott Long 		error = copyout(&size, arg, sizeof(size));
6341eba4c79SScott Long 		break;
6351eba4c79SScott Long 	}
6361eba4c79SScott Long 
6371eba4c79SScott Long 	case SG_GET_SCSI_ID:
6381eba4c79SScott Long 	case LINUX_SG_GET_SCSI_ID:
6391eba4c79SScott Long 	{
6401eba4c79SScott Long 		struct sg_scsi_id id;
6411eba4c79SScott Long 
64275b06c87SMatt Jacob 		id.host_no = cam_sim_path(xpt_path_sim(periph->path));
6431eba4c79SScott Long 		id.channel = xpt_path_path_id(periph->path);
6441eba4c79SScott Long 		id.scsi_id = xpt_path_target_id(periph->path);
6451eba4c79SScott Long 		id.lun = xpt_path_lun_id(periph->path);
6461eba4c79SScott Long 		id.scsi_type = softc->pd_type;
6471eba4c79SScott Long 		id.h_cmd_per_lun = 1;
6481eba4c79SScott Long 		id.d_queue_depth = 1;
6491eba4c79SScott Long 		id.unused[0] = 0;
6501eba4c79SScott Long 		id.unused[1] = 0;
6511eba4c79SScott Long 
6521eba4c79SScott Long 		error = copyout(&id, arg, sizeof(id));
6531eba4c79SScott Long 		break;
6541eba4c79SScott Long 	}
6551eba4c79SScott Long 
6561eba4c79SScott Long 	case SG_EMULATED_HOST:
6571eba4c79SScott Long 	case SG_SET_TRANSFORM:
6581eba4c79SScott Long 	case SG_GET_TRANSFORM:
6591eba4c79SScott Long 	case SG_GET_NUM_WAITING:
6601eba4c79SScott Long 	case SG_SCSI_RESET:
6611eba4c79SScott Long 	case SG_GET_REQUEST_TABLE:
6621eba4c79SScott Long 	case SG_SET_KEEP_ORPHAN:
6631eba4c79SScott Long 	case SG_GET_KEEP_ORPHAN:
6641eba4c79SScott Long 	case SG_GET_ACCESS_COUNT:
6651eba4c79SScott Long 	case SG_SET_FORCE_LOW_DMA:
6661eba4c79SScott Long 	case SG_GET_LOW_DMA:
6671eba4c79SScott Long 	case SG_GET_SG_TABLESIZE:
6681eba4c79SScott Long 	case SG_SET_FORCE_PACK_ID:
6691eba4c79SScott Long 	case SG_GET_PACK_ID:
6701eba4c79SScott Long 	case SG_SET_RESERVED_SIZE:
6711eba4c79SScott Long 	case SG_GET_COMMAND_Q:
6721eba4c79SScott Long 	case SG_SET_COMMAND_Q:
6731eba4c79SScott Long 	case SG_SET_DEBUG:
6741eba4c79SScott Long 	case SG_NEXT_CMD_LEN:
6751eba4c79SScott Long 	case LINUX_SG_EMULATED_HOST:
6761eba4c79SScott Long 	case LINUX_SG_SET_TRANSFORM:
6771eba4c79SScott Long 	case LINUX_SG_GET_TRANSFORM:
6781eba4c79SScott Long 	case LINUX_SG_GET_NUM_WAITING:
6791eba4c79SScott Long 	case LINUX_SG_SCSI_RESET:
6801eba4c79SScott Long 	case LINUX_SG_GET_REQUEST_TABLE:
6811eba4c79SScott Long 	case LINUX_SG_SET_KEEP_ORPHAN:
6821eba4c79SScott Long 	case LINUX_SG_GET_KEEP_ORPHAN:
6831eba4c79SScott Long 	case LINUX_SG_GET_ACCESS_COUNT:
6841eba4c79SScott Long 	case LINUX_SG_SET_FORCE_LOW_DMA:
6851eba4c79SScott Long 	case LINUX_SG_GET_LOW_DMA:
6861eba4c79SScott Long 	case LINUX_SG_GET_SG_TABLESIZE:
6871eba4c79SScott Long 	case LINUX_SG_SET_FORCE_PACK_ID:
6881eba4c79SScott Long 	case LINUX_SG_GET_PACK_ID:
6891eba4c79SScott Long 	case LINUX_SG_SET_RESERVED_SIZE:
6901eba4c79SScott Long 	case LINUX_SG_GET_COMMAND_Q:
6911eba4c79SScott Long 	case LINUX_SG_SET_COMMAND_Q:
6921eba4c79SScott Long 	case LINUX_SG_SET_DEBUG:
6931eba4c79SScott Long 	case LINUX_SG_NEXT_CMD_LEN:
6941eba4c79SScott Long 	default:
6951eba4c79SScott Long #ifdef CAMDEBUG
6961eba4c79SScott Long 		printf("sgioctl: rejecting cmd 0x%lx\n", cmd);
6971eba4c79SScott Long #endif
6981eba4c79SScott Long 		error = ENODEV;
6991eba4c79SScott Long 		break;
7001eba4c79SScott Long 	}
7011eba4c79SScott Long 
7022b83592fSScott Long 	cam_periph_unlock(periph);
7031eba4c79SScott Long 	return (error);
7041eba4c79SScott Long }
7051eba4c79SScott Long 
7061eba4c79SScott Long static int
7071eba4c79SScott Long sgwrite(struct cdev *dev, struct uio *uio, int ioflag)
7081eba4c79SScott Long {
7091eba4c79SScott Long 	union ccb *ccb;
7101eba4c79SScott Long 	struct cam_periph *periph;
7111eba4c79SScott Long 	struct ccb_scsiio *csio;
7121eba4c79SScott Long 	struct sg_softc *sc;
7131eba4c79SScott Long 	struct sg_header *hdr;
7141eba4c79SScott Long 	struct sg_rdwr *rdwr;
7151eba4c79SScott Long 	u_char cdb_cmd;
7161eba4c79SScott Long 	char *buf;
7171eba4c79SScott Long 	int error = 0, cdb_len, buf_len, dir;
7181eba4c79SScott Long 
7191eba4c79SScott Long 	periph = dev->si_drv1;
7204400b36dSScott Long 	rdwr = malloc(sizeof(*rdwr), M_DEVBUF, M_WAITOK | M_ZERO);
7211eba4c79SScott Long 	hdr = &rdwr->hdr.hdr;
7221eba4c79SScott Long 
7231eba4c79SScott Long 	/* Copy in the header block and sanity check it */
7241eba4c79SScott Long 	if (uio->uio_resid < sizeof(*hdr)) {
7251eba4c79SScott Long 		error = EINVAL;
7261eba4c79SScott Long 		goto out_hdr;
7271eba4c79SScott Long 	}
7281eba4c79SScott Long 	error = uiomove(hdr, sizeof(*hdr), uio);
7291eba4c79SScott Long 	if (error)
7301eba4c79SScott Long 		goto out_hdr;
7311eba4c79SScott Long 
7328008a935SScott Long 	ccb = xpt_alloc_ccb();
7331eba4c79SScott Long 	if (ccb == NULL) {
7341eba4c79SScott Long 		error = ENOMEM;
7351eba4c79SScott Long 		goto out_hdr;
7361eba4c79SScott Long 	}
7371eba4c79SScott Long 	csio = &ccb->csio;
7381eba4c79SScott Long 
7391eba4c79SScott Long 	/*
7401eba4c79SScott Long 	 * Copy in the CDB block.  The designers of the interface didn't
7411eba4c79SScott Long 	 * bother to provide a size for this in the header, so we have to
7421eba4c79SScott Long 	 * figure it out ourselves.
7431eba4c79SScott Long 	 */
7441eba4c79SScott Long 	if (uio->uio_resid < 1)
7451eba4c79SScott Long 		goto out_ccb;
7461eba4c79SScott Long 	error = uiomove(&cdb_cmd, 1, uio);
7471eba4c79SScott Long 	if (error)
7481eba4c79SScott Long 		goto out_ccb;
7491eba4c79SScott Long 	if (hdr->twelve_byte)
7501eba4c79SScott Long 		cdb_len = 12;
7511eba4c79SScott Long 	else
7521eba4c79SScott Long 		cdb_len = scsi_group_len(cdb_cmd);
7531eba4c79SScott Long 	/*
7541eba4c79SScott Long 	 * We've already read the first byte of the CDB and advanced the uio
7551eba4c79SScott Long 	 * pointer.  Just read the rest.
7561eba4c79SScott Long 	 */
7571eba4c79SScott Long 	csio->cdb_io.cdb_bytes[0] = cdb_cmd;
7581eba4c79SScott Long 	error = uiomove(&csio->cdb_io.cdb_bytes[1], cdb_len - 1, uio);
7591eba4c79SScott Long 	if (error)
7601eba4c79SScott Long 		goto out_ccb;
7611eba4c79SScott Long 
7621eba4c79SScott Long 	/*
7631eba4c79SScott Long 	 * Now set up the data block.  Again, the designers didn't bother
7641eba4c79SScott Long 	 * to make this reliable.
7651eba4c79SScott Long 	 */
7661eba4c79SScott Long 	buf_len = uio->uio_resid;
7671eba4c79SScott Long 	if (buf_len != 0) {
7684400b36dSScott Long 		buf = malloc(buf_len, M_DEVBUF, M_WAITOK | M_ZERO);
7691eba4c79SScott Long 		error = uiomove(buf, buf_len, uio);
7701eba4c79SScott Long 		if (error)
7711eba4c79SScott Long 			goto out_buf;
7721eba4c79SScott Long 		dir = CAM_DIR_OUT;
7731eba4c79SScott Long 	} else if (hdr->reply_len != 0) {
7744400b36dSScott Long 		buf = malloc(hdr->reply_len, M_DEVBUF, M_WAITOK | M_ZERO);
7751eba4c79SScott Long 		buf_len = hdr->reply_len;
7761eba4c79SScott Long 		dir = CAM_DIR_IN;
7771eba4c79SScott Long 	} else {
7781eba4c79SScott Long 		buf = NULL;
7791eba4c79SScott Long 		buf_len = 0;
7801eba4c79SScott Long 		dir = CAM_DIR_NONE;
7811eba4c79SScott Long 	}
7821eba4c79SScott Long 
7832b83592fSScott Long 	cam_periph_lock(periph);
7842b83592fSScott Long 	sc = periph->softc;
7851e637ba6SAlexander Motin 	xpt_setup_ccb(&ccb->ccb_h, periph->path, CAM_PRIORITY_NORMAL);
7861eba4c79SScott Long 	cam_fill_csio(csio,
7871eba4c79SScott Long 		      /*retries*/1,
7881eba4c79SScott Long 		      sgdone,
7891eba4c79SScott Long 		      dir|CAM_DEV_QFRZDIS,
7901eba4c79SScott Long 		      MSG_SIMPLE_Q_TAG,
7911eba4c79SScott Long 		      buf,
7921eba4c79SScott Long 		      buf_len,
7931eba4c79SScott Long 		      SG_MAX_SENSE,
7941eba4c79SScott Long 		      cdb_len,
795715ab212SScott Long 		      sc->sg_timeout);
7961eba4c79SScott Long 
7971eba4c79SScott Long 	/*
7981eba4c79SScott Long 	 * Send off the command and hope that it works. This path does not
7991eba4c79SScott Long 	 * go through sgstart because the I/O is supposed to be asynchronous.
8001eba4c79SScott Long 	 */
8011eba4c79SScott Long 	rdwr->buf = buf;
8021eba4c79SScott Long 	rdwr->buf_len = buf_len;
8031eba4c79SScott Long 	rdwr->tag = hdr->pack_id;
8041eba4c79SScott Long 	rdwr->ccb = ccb;
8051eba4c79SScott Long 	rdwr->state = SG_RDWR_INPROG;
8061eba4c79SScott Long 	ccb->ccb_h.ccb_rdwr = rdwr;
8071eba4c79SScott Long 	ccb->ccb_h.ccb_type = SG_CCB_RDWR_IO;
8081eba4c79SScott Long 	TAILQ_INSERT_TAIL(&sc->rdwr_done, rdwr, rdwr_link);
8092b83592fSScott Long 	error = sgsendrdwr(periph, ccb);
8102b83592fSScott Long 	cam_periph_unlock(periph);
8112b83592fSScott Long 	return (error);
8121eba4c79SScott Long 
8131eba4c79SScott Long out_buf:
8141eba4c79SScott Long 	free(buf, M_DEVBUF);
8151eba4c79SScott Long out_ccb:
8161eba4c79SScott Long 	xpt_free_ccb(ccb);
8171eba4c79SScott Long out_hdr:
8181eba4c79SScott Long 	free(rdwr, M_DEVBUF);
8191eba4c79SScott Long 	return (error);
8201eba4c79SScott Long }
8211eba4c79SScott Long 
8221eba4c79SScott Long static int
8231eba4c79SScott Long sgread(struct cdev *dev, struct uio *uio, int ioflag)
8241eba4c79SScott Long {
8251eba4c79SScott Long 	struct ccb_scsiio *csio;
8261eba4c79SScott Long 	struct cam_periph *periph;
8271eba4c79SScott Long 	struct sg_softc *sc;
8281eba4c79SScott Long 	struct sg_header *hdr;
8291eba4c79SScott Long 	struct sg_rdwr *rdwr;
8301eba4c79SScott Long 	u_short hstat, dstat;
8311eba4c79SScott Long 	int error, pack_len, reply_len, pack_id;
8321eba4c79SScott Long 
8331eba4c79SScott Long 	periph = dev->si_drv1;
8341eba4c79SScott Long 
8351eba4c79SScott Long 	/* XXX The pack len field needs to be updated and written out instead
8361eba4c79SScott Long 	 * of discarded.  Not sure how to do that.
8371eba4c79SScott Long 	 */
8381eba4c79SScott Long 	uio->uio_rw = UIO_WRITE;
8391eba4c79SScott Long 	if ((error = uiomove(&pack_len, 4, uio)) != 0)
8401eba4c79SScott Long 		return (error);
8411eba4c79SScott Long 	if ((error = uiomove(&reply_len, 4, uio)) != 0)
8421eba4c79SScott Long 		return (error);
8431eba4c79SScott Long 	if ((error = uiomove(&pack_id, 4, uio)) != 0)
8441eba4c79SScott Long 		return (error);
8451eba4c79SScott Long 	uio->uio_rw = UIO_READ;
8461eba4c79SScott Long 
8472b83592fSScott Long 	cam_periph_lock(periph);
8482b83592fSScott Long 	sc = periph->softc;
8491eba4c79SScott Long search:
8501eba4c79SScott Long 	TAILQ_FOREACH(rdwr, &sc->rdwr_done, rdwr_link) {
8511eba4c79SScott Long 		if (rdwr->tag == pack_id)
8521eba4c79SScott Long 			break;
8531eba4c79SScott Long 	}
8541eba4c79SScott Long 	if ((rdwr == NULL) || (rdwr->state != SG_RDWR_DONE)) {
855*227d67aaSAlexander Motin 		if (cam_periph_sleep(periph, rdwr, PCATCH, "sgread", 0) == ERESTART)
8561eba4c79SScott Long 			return (EAGAIN);
8571eba4c79SScott Long 		goto search;
8581eba4c79SScott Long 	}
8591eba4c79SScott Long 	TAILQ_REMOVE(&sc->rdwr_done, rdwr, rdwr_link);
8602b83592fSScott Long 	cam_periph_unlock(periph);
8611eba4c79SScott Long 
8621eba4c79SScott Long 	hdr = &rdwr->hdr.hdr;
8631eba4c79SScott Long 	csio = &rdwr->ccb->csio;
8641eba4c79SScott Long 	sg_scsiio_status(csio, &hstat, &dstat);
8651eba4c79SScott Long 	hdr->host_status = hstat;
8661eba4c79SScott Long 	hdr->driver_status = dstat;
8671eba4c79SScott Long 	hdr->target_status = csio->scsi_status >> 1;
8681eba4c79SScott Long 
8691eba4c79SScott Long 	switch (hstat) {
8701eba4c79SScott Long 	case DID_OK:
8711eba4c79SScott Long 	case DID_PASSTHROUGH:
8721eba4c79SScott Long 	case DID_SOFT_ERROR:
8731eba4c79SScott Long 		hdr->result = 0;
8741eba4c79SScott Long 		break;
8751eba4c79SScott Long 	case DID_NO_CONNECT:
8761eba4c79SScott Long 	case DID_BUS_BUSY:
8771eba4c79SScott Long 	case DID_TIME_OUT:
8781eba4c79SScott Long 		hdr->result = EBUSY;
8791eba4c79SScott Long 		break;
8801eba4c79SScott Long 	case DID_BAD_TARGET:
8811eba4c79SScott Long 	case DID_ABORT:
8821eba4c79SScott Long 	case DID_PARITY:
8831eba4c79SScott Long 	case DID_RESET:
8841eba4c79SScott Long 	case DID_BAD_INTR:
8851eba4c79SScott Long 	case DID_ERROR:
8861eba4c79SScott Long 	default:
8871eba4c79SScott Long 		hdr->result = EIO;
8881eba4c79SScott Long 		break;
8891eba4c79SScott Long 	}
8901eba4c79SScott Long 
8911eba4c79SScott Long 	if (dstat == DRIVER_SENSE) {
8921eba4c79SScott Long 		bcopy(&csio->sense_data, hdr->sense_buffer,
8931eba4c79SScott Long 		      min(csio->sense_len, SG_MAX_SENSE));
8941eba4c79SScott Long #ifdef CAMDEBUG
8951eba4c79SScott Long 		scsi_sense_print(csio);
8961eba4c79SScott Long #endif
8971eba4c79SScott Long 	}
8981eba4c79SScott Long 
8991eba4c79SScott Long 	error = uiomove(&hdr->result, sizeof(*hdr) -
9001eba4c79SScott Long 			offsetof(struct sg_header, result), uio);
9011eba4c79SScott Long 	if ((error == 0) && (hdr->result == 0))
9021eba4c79SScott Long 		error = uiomove(rdwr->buf, rdwr->buf_len, uio);
9031eba4c79SScott Long 
9042b83592fSScott Long 	cam_periph_lock(periph);
9051eba4c79SScott Long 	xpt_free_ccb(rdwr->ccb);
9062b83592fSScott Long 	cam_periph_unlock(periph);
9071eba4c79SScott Long 	free(rdwr->buf, M_DEVBUF);
9081eba4c79SScott Long 	free(rdwr, M_DEVBUF);
9091eba4c79SScott Long 	return (error);
9101eba4c79SScott Long }
9111eba4c79SScott Long 
9121eba4c79SScott Long static int
9131eba4c79SScott Long sgsendccb(struct cam_periph *periph, union ccb *ccb)
9141eba4c79SScott Long {
9151eba4c79SScott Long 	struct sg_softc *softc;
9161eba4c79SScott Long 	struct cam_periph_map_info mapinfo;
91795fbded6SScott Long 	int error;
9181eba4c79SScott Long 
9191eba4c79SScott Long 	softc = periph->softc;
9201eba4c79SScott Long 	bzero(&mapinfo, sizeof(mapinfo));
9212b83592fSScott Long 
9222b83592fSScott Long 	/*
9232b83592fSScott Long 	 * cam_periph_mapmem calls into proc and vm functions that can
9242b83592fSScott Long 	 * sleep as well as trigger I/O, so we can't hold the lock.
9252b83592fSScott Long 	 * Dropping it here is reasonably safe.
92695fbded6SScott Long 	 * The only CCB opcode that is possible here is XPT_SCSI_IO, no
92795fbded6SScott Long 	 * need for additional checks.
9282b83592fSScott Long 	 */
9292b83592fSScott Long 	cam_periph_unlock(periph);
9301eba4c79SScott Long 	error = cam_periph_mapmem(ccb, &mapinfo);
9312b83592fSScott Long 	cam_periph_lock(periph);
9321eba4c79SScott Long 	if (error)
9331eba4c79SScott Long 		return (error);
9341eba4c79SScott Long 
9351eba4c79SScott Long 	error = cam_periph_runccb(ccb,
9361eba4c79SScott Long 				  sgerror,
9371eba4c79SScott Long 				  CAM_RETRY_SELTO,
9381eba4c79SScott Long 				  SF_RETRY_UA,
9391eba4c79SScott Long 				  softc->device_stats);
9401eba4c79SScott Long 
9411eba4c79SScott Long 	cam_periph_unmapmem(ccb, &mapinfo);
9421eba4c79SScott Long 
9431eba4c79SScott Long 	return (error);
9441eba4c79SScott Long }
9451eba4c79SScott Long 
9461eba4c79SScott Long static int
9471eba4c79SScott Long sgsendrdwr(struct cam_periph *periph, union ccb *ccb)
9481eba4c79SScott Long {
9491eba4c79SScott Long 	struct sg_softc *softc;
9501eba4c79SScott Long 
9511eba4c79SScott Long 	softc = periph->softc;
9521eba4c79SScott Long 	devstat_start_transaction(softc->device_stats, NULL);
9531eba4c79SScott Long 	xpt_action(ccb);
9541eba4c79SScott Long 	return (0);
9551eba4c79SScott Long }
9561eba4c79SScott Long 
9571eba4c79SScott Long static int
9581eba4c79SScott Long sgerror(union ccb *ccb, uint32_t cam_flags, uint32_t sense_flags)
9591eba4c79SScott Long {
9601eba4c79SScott Long 	struct cam_periph *periph;
9611eba4c79SScott Long 	struct sg_softc *softc;
9621eba4c79SScott Long 
9631eba4c79SScott Long 	periph = xpt_path_periph(ccb->ccb_h.path);
9641eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
9651eba4c79SScott Long 
9661eba4c79SScott Long 	return (cam_periph_error(ccb, cam_flags, sense_flags,
9671eba4c79SScott Long 				 &softc->saved_ccb));
9681eba4c79SScott Long }
9691eba4c79SScott Long 
9701eba4c79SScott Long static void
9711eba4c79SScott Long sg_scsiio_status(struct ccb_scsiio *csio, u_short *hoststat, u_short *drvstat)
9721eba4c79SScott Long {
9731eba4c79SScott Long 	int status;
9741eba4c79SScott Long 
9751eba4c79SScott Long 	status = csio->ccb_h.status;
9761eba4c79SScott Long 
9771eba4c79SScott Long 	switch (status & CAM_STATUS_MASK) {
9781eba4c79SScott Long 	case CAM_REQ_CMP:
9791eba4c79SScott Long 		*hoststat = DID_OK;
9801eba4c79SScott Long 		*drvstat = 0;
9811eba4c79SScott Long 		break;
9821eba4c79SScott Long 	case CAM_REQ_CMP_ERR:
9831eba4c79SScott Long 		*hoststat = DID_ERROR;
9841eba4c79SScott Long 		*drvstat = 0;
9851eba4c79SScott Long 		break;
9861eba4c79SScott Long 	case CAM_REQ_ABORTED:
9871eba4c79SScott Long 		*hoststat = DID_ABORT;
9881eba4c79SScott Long 		*drvstat = 0;
9891eba4c79SScott Long 		break;
9901eba4c79SScott Long 	case CAM_REQ_INVALID:
9911eba4c79SScott Long 		*hoststat = DID_ERROR;
9921eba4c79SScott Long 		*drvstat = DRIVER_INVALID;
9931eba4c79SScott Long 		break;
9941eba4c79SScott Long 	case CAM_DEV_NOT_THERE:
9951eba4c79SScott Long 		*hoststat = DID_BAD_TARGET;
9961eba4c79SScott Long 		*drvstat = 0;
9974fee613eSEdward Tomasz Napierala 		break;
9981eba4c79SScott Long 	case CAM_SEL_TIMEOUT:
9991eba4c79SScott Long 		*hoststat = DID_NO_CONNECT;
10001eba4c79SScott Long 		*drvstat = 0;
10011eba4c79SScott Long 		break;
10021eba4c79SScott Long 	case CAM_CMD_TIMEOUT:
10031eba4c79SScott Long 		*hoststat = DID_TIME_OUT;
10041eba4c79SScott Long 		*drvstat = 0;
10051eba4c79SScott Long 		break;
10061eba4c79SScott Long 	case CAM_SCSI_STATUS_ERROR:
10071eba4c79SScott Long 		*hoststat = DID_ERROR;
10081eba4c79SScott Long 		*drvstat = 0;
10090c70e307SEdward Tomasz Napierala 		break;
10101eba4c79SScott Long 	case CAM_SCSI_BUS_RESET:
10111eba4c79SScott Long 		*hoststat = DID_RESET;
10121eba4c79SScott Long 		*drvstat = 0;
10131eba4c79SScott Long 		break;
10141eba4c79SScott Long 	case CAM_UNCOR_PARITY:
10151eba4c79SScott Long 		*hoststat = DID_PARITY;
10161eba4c79SScott Long 		*drvstat = 0;
10171eba4c79SScott Long 		break;
10181eba4c79SScott Long 	case CAM_SCSI_BUSY:
10191eba4c79SScott Long 		*hoststat = DID_BUS_BUSY;
10201eba4c79SScott Long 		*drvstat = 0;
10210c70e307SEdward Tomasz Napierala 		break;
10221eba4c79SScott Long 	default:
10231eba4c79SScott Long 		*hoststat = DID_ERROR;
10241eba4c79SScott Long 		*drvstat = DRIVER_ERROR;
10251eba4c79SScott Long 	}
10261eba4c79SScott Long 
10271eba4c79SScott Long 	if (status & CAM_AUTOSNS_VALID)
10281eba4c79SScott Long 		*drvstat = DRIVER_SENSE;
10291eba4c79SScott Long }
10301eba4c79SScott Long 
10311eba4c79SScott Long static int
10321eba4c79SScott Long scsi_group_len(u_char cmd)
10331eba4c79SScott Long {
10341eba4c79SScott Long 	int len[] = {6, 10, 10, 12, 12, 12, 10, 10};
10351eba4c79SScott Long 	int group;
10361eba4c79SScott Long 
10371eba4c79SScott Long 	group = (cmd >> 5) & 0x7;
10381eba4c79SScott Long 	return (len[group]);
10391eba4c79SScott Long }
10401eba4c79SScott Long 
1041