xref: /freebsd/sys/cam/scsi/scsi_sg.c (revision c552ebe12dd9f65e195a4b2835ec4b57e6bc79ba)
11eba4c79SScott Long /*-
21eba4c79SScott Long  * Copyright (c) 2007 Scott Long
31eba4c79SScott Long  * All rights reserved.
41eba4c79SScott Long  *
51eba4c79SScott Long  * Redistribution and use in source and binary forms, with or without
61eba4c79SScott Long  * modification, are permitted provided that the following conditions
71eba4c79SScott Long  * are met:
81eba4c79SScott Long  * 1. Redistributions of source code must retain the above copyright
91eba4c79SScott Long  *    notice, this list of conditions, and the following disclaimer,
101eba4c79SScott Long  *    without modification, immediately at the beginning of the file.
111eba4c79SScott Long  * 2. The name of the author may not be used to endorse or promote products
121eba4c79SScott Long  *    derived from this software without specific prior written permission.
131eba4c79SScott Long  *
141eba4c79SScott Long  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
151eba4c79SScott Long  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
161eba4c79SScott Long  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
171eba4c79SScott Long  * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR
181eba4c79SScott Long  * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
191eba4c79SScott Long  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
201eba4c79SScott Long  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
211eba4c79SScott Long  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
221eba4c79SScott Long  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
231eba4c79SScott Long  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
241eba4c79SScott Long  * SUCH DAMAGE.
251eba4c79SScott Long  */
261eba4c79SScott Long 
271eba4c79SScott Long /*
281eba4c79SScott Long  * scsi_sg peripheral driver.  This driver is meant to implement the Linux
291eba4c79SScott Long  * SG passthrough interface for SCSI.
301eba4c79SScott Long  */
311eba4c79SScott Long 
321eba4c79SScott Long #include <sys/cdefs.h>
331eba4c79SScott Long __FBSDID("$FreeBSD$");
341eba4c79SScott Long 
351eba4c79SScott Long #include <sys/param.h>
361eba4c79SScott Long #include <sys/systm.h>
371eba4c79SScott Long #include <sys/kernel.h>
381eba4c79SScott Long #include <sys/types.h>
391eba4c79SScott Long #include <sys/bio.h>
401eba4c79SScott Long #include <sys/malloc.h>
411eba4c79SScott Long #include <sys/fcntl.h>
421eba4c79SScott Long #include <sys/ioccom.h>
431eba4c79SScott Long #include <sys/conf.h>
441eba4c79SScott Long #include <sys/errno.h>
451eba4c79SScott Long #include <sys/devicestat.h>
461eba4c79SScott Long #include <sys/proc.h>
471eba4c79SScott Long #include <sys/uio.h>
481eba4c79SScott Long 
491eba4c79SScott Long #include <cam/cam.h>
501eba4c79SScott Long #include <cam/cam_ccb.h>
511eba4c79SScott Long #include <cam/cam_periph.h>
521eba4c79SScott Long #include <cam/cam_queue.h>
531eba4c79SScott Long #include <cam/cam_xpt_periph.h>
541eba4c79SScott Long #include <cam/cam_debug.h>
551eba4c79SScott Long #include <cam/cam_sim.h>
561eba4c79SScott Long 
571eba4c79SScott Long #include <cam/scsi/scsi_all.h>
581eba4c79SScott Long #include <cam/scsi/scsi_message.h>
591eba4c79SScott Long #include <cam/scsi/scsi_sg.h>
601eba4c79SScott Long 
611eba4c79SScott Long #include <compat/linux/linux_ioctl.h>
621eba4c79SScott Long 
631eba4c79SScott Long typedef enum {
64*c552ebe1SKenneth D. Merry 	SG_FLAG_LOCKED		= 0x01,
65*c552ebe1SKenneth D. Merry 	SG_FLAG_INVALID		= 0x02
661eba4c79SScott Long } sg_flags;
671eba4c79SScott Long 
681eba4c79SScott Long typedef enum {
691eba4c79SScott Long 	SG_STATE_NORMAL
701eba4c79SScott Long } sg_state;
711eba4c79SScott Long 
721eba4c79SScott Long typedef enum {
73472cdbefSScott Long 	SG_RDWR_FREE,
741eba4c79SScott Long 	SG_RDWR_INPROG,
751eba4c79SScott Long 	SG_RDWR_DONE
761eba4c79SScott Long } sg_rdwr_state;
771eba4c79SScott Long 
781eba4c79SScott Long typedef enum {
791eba4c79SScott Long 	SG_CCB_RDWR_IO,
801eba4c79SScott Long 	SG_CCB_WAITING
811eba4c79SScott Long } sg_ccb_types;
821eba4c79SScott Long 
831eba4c79SScott Long #define ccb_type	ppriv_field0
841eba4c79SScott Long #define ccb_rdwr	ppriv_ptr1
851eba4c79SScott Long 
861eba4c79SScott Long struct sg_rdwr {
871eba4c79SScott Long 	TAILQ_ENTRY(sg_rdwr)	rdwr_link;
881eba4c79SScott Long 	int			tag;
891eba4c79SScott Long 	int			state;
901eba4c79SScott Long 	int			buf_len;
911eba4c79SScott Long 	char			*buf;
921eba4c79SScott Long 	union ccb		*ccb;
931eba4c79SScott Long 	union {
941eba4c79SScott Long 		struct sg_header hdr;
951eba4c79SScott Long 		struct sg_io_hdr io_hdr;
961eba4c79SScott Long 	} hdr;
971eba4c79SScott Long };
981eba4c79SScott Long 
991eba4c79SScott Long struct sg_softc {
1001eba4c79SScott Long 	sg_state		state;
1011eba4c79SScott Long 	sg_flags		flags;
1021eba4c79SScott Long 	struct devstat		*device_stats;
1031eba4c79SScott Long 	TAILQ_HEAD(, sg_rdwr)	rdwr_done;
1041eba4c79SScott Long 	struct cdev		*dev;
105715ab212SScott Long 	int			sg_timeout;
106715ab212SScott Long 	int			sg_user_timeout;
107715ab212SScott Long 	uint8_t			pd_type;
1081eba4c79SScott Long 	union ccb		saved_ccb;
1091eba4c79SScott Long };
1101eba4c79SScott Long 
1111eba4c79SScott Long static d_open_t		sgopen;
1121eba4c79SScott Long static d_close_t	sgclose;
1131eba4c79SScott Long static d_ioctl_t	sgioctl;
1141eba4c79SScott Long static d_write_t	sgwrite;
1151eba4c79SScott Long static d_read_t		sgread;
1161eba4c79SScott Long 
1171eba4c79SScott Long static periph_init_t	sginit;
1181eba4c79SScott Long static periph_ctor_t	sgregister;
1191eba4c79SScott Long static periph_oninv_t	sgoninvalidate;
1201eba4c79SScott Long static periph_dtor_t	sgcleanup;
1211eba4c79SScott Long static periph_start_t	sgstart;
1221eba4c79SScott Long static void		sgasync(void *callback_arg, uint32_t code,
1231eba4c79SScott Long 				struct cam_path *path, void *arg);
1241eba4c79SScott Long static void		sgdone(struct cam_periph *periph, union ccb *done_ccb);
1251eba4c79SScott Long static int		sgsendccb(struct cam_periph *periph, union ccb *ccb);
1261eba4c79SScott Long static int		sgsendrdwr(struct cam_periph *periph, union ccb *ccb);
1271eba4c79SScott Long static int		sgerror(union ccb *ccb, uint32_t cam_flags,
1281eba4c79SScott Long 				uint32_t sense_flags);
1291eba4c79SScott Long static void		sg_scsiio_status(struct ccb_scsiio *csio,
1301eba4c79SScott Long 					 u_short *hoststat, u_short *drvstat);
1311eba4c79SScott Long 
1321eba4c79SScott Long static int		scsi_group_len(u_char cmd);
1331eba4c79SScott Long 
1341eba4c79SScott Long static struct periph_driver sgdriver =
1351eba4c79SScott Long {
1361eba4c79SScott Long 	sginit, "sg",
1371eba4c79SScott Long 	TAILQ_HEAD_INITIALIZER(sgdriver.units), /* gen */ 0
1381eba4c79SScott Long };
1391eba4c79SScott Long PERIPHDRIVER_DECLARE(sg, sgdriver);
1401eba4c79SScott Long 
1411eba4c79SScott Long static struct cdevsw sg_cdevsw = {
1421eba4c79SScott Long 	.d_version =	D_VERSION,
143*c552ebe1SKenneth D. Merry 	.d_flags =	D_NEEDGIANT | D_TRACKCLOSE,
1441eba4c79SScott Long 	.d_open =	sgopen,
1451eba4c79SScott Long 	.d_close =	sgclose,
1461eba4c79SScott Long 	.d_ioctl =	sgioctl,
1471eba4c79SScott Long 	.d_write =	sgwrite,
1481eba4c79SScott Long 	.d_read =	sgread,
1491eba4c79SScott Long 	.d_name =	"sg",
1501eba4c79SScott Long };
1511eba4c79SScott Long 
1521eba4c79SScott Long static int sg_version = 30125;
1531eba4c79SScott Long 
1541eba4c79SScott Long static void
1551eba4c79SScott Long sginit(void)
1561eba4c79SScott Long {
1571eba4c79SScott Long 	cam_status status;
1581eba4c79SScott Long 
1591eba4c79SScott Long 	/*
1601eba4c79SScott Long 	 * Install a global async callback.  This callback will receive aync
1611eba4c79SScott Long 	 * callbacks like "new device found".
1621eba4c79SScott Long 	 */
16385d92640SScott Long 	status = xpt_register_async(AC_FOUND_DEVICE, sgasync, NULL, NULL);
1641eba4c79SScott Long 
1651eba4c79SScott Long 	if (status != CAM_REQ_CMP) {
1661eba4c79SScott Long 		printf("sg: Failed to attach master async callbac "
1671eba4c79SScott Long 			"due to status 0x%x!\n", status);
1681eba4c79SScott Long 	}
1691eba4c79SScott Long }
1701eba4c79SScott Long 
1711eba4c79SScott Long static void
1721eba4c79SScott Long sgoninvalidate(struct cam_periph *periph)
1731eba4c79SScott Long {
1741eba4c79SScott Long 	struct sg_softc *softc;
1751eba4c79SScott Long 
1761eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
1771eba4c79SScott Long 
1781eba4c79SScott Long 	/*
1791eba4c79SScott Long 	 * Deregister any async callbacks.
1801eba4c79SScott Long 	 */
18185d92640SScott Long 	xpt_register_async(0, sgasync, periph, periph->path);
1821eba4c79SScott Long 
1831eba4c79SScott Long 	softc->flags |= SG_FLAG_INVALID;
1841eba4c79SScott Long 
1851eba4c79SScott Long 	/*
1861eba4c79SScott Long 	 * XXX Return all queued I/O with ENXIO.
1871eba4c79SScott Long 	 * XXX Handle any transactions queued to the card
1881eba4c79SScott Long 	 *     with XPT_ABORT_CCB.
1891eba4c79SScott Long 	 */
1901eba4c79SScott Long 
1911eba4c79SScott Long 	if (bootverbose) {
1921eba4c79SScott Long 		xpt_print(periph->path, "lost device\n");
1931eba4c79SScott Long 	}
1941eba4c79SScott Long }
1951eba4c79SScott Long 
1961eba4c79SScott Long static void
1971eba4c79SScott Long sgcleanup(struct cam_periph *periph)
1981eba4c79SScott Long {
1991eba4c79SScott Long 	struct sg_softc *softc;
2001eba4c79SScott Long 
2011eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
2025f3fed85SEdward Tomasz Napierala 	if (bootverbose)
2031eba4c79SScott Long 		xpt_print(periph->path, "removing device entry\n");
2045f3fed85SEdward Tomasz Napierala 	devstat_remove_entry(softc->device_stats);
2055f3fed85SEdward Tomasz Napierala 	cam_periph_unlock(periph);
2065f3fed85SEdward Tomasz Napierala 	destroy_dev(softc->dev);
2075f3fed85SEdward Tomasz Napierala 	cam_periph_lock(periph);
2081eba4c79SScott Long 	free(softc, M_DEVBUF);
2091eba4c79SScott Long }
2101eba4c79SScott Long 
2111eba4c79SScott Long static void
2121eba4c79SScott Long sgasync(void *callback_arg, uint32_t code, struct cam_path *path, void *arg)
2131eba4c79SScott Long {
2141eba4c79SScott Long 	struct cam_periph *periph;
2151eba4c79SScott Long 
2161eba4c79SScott Long 	periph = (struct cam_periph *)callback_arg;
2171eba4c79SScott Long 
2181eba4c79SScott Long 	switch (code) {
2191eba4c79SScott Long 	case AC_FOUND_DEVICE:
2201eba4c79SScott Long 	{
2211eba4c79SScott Long 		struct ccb_getdev *cgd;
2221eba4c79SScott Long 		cam_status status;
2231eba4c79SScott Long 
2241eba4c79SScott Long 		cgd = (struct ccb_getdev *)arg;
2251eba4c79SScott Long 		if (cgd == NULL)
2261eba4c79SScott Long 			break;
2271eba4c79SScott Long 
22852c9ce25SScott Long 		if (cgd->protocol != PROTO_SCSI)
22952c9ce25SScott Long 			break;
23052c9ce25SScott Long 
2311eba4c79SScott Long 		/*
2321eba4c79SScott Long 		 * Allocate a peripheral instance for this device and
2331eba4c79SScott Long 		 * start the probe process.
2341eba4c79SScott Long 		 */
2351eba4c79SScott Long 		status = cam_periph_alloc(sgregister, sgoninvalidate,
2361eba4c79SScott Long 					  sgcleanup, sgstart, "sg",
2371eba4c79SScott Long 					  CAM_PERIPH_BIO, cgd->ccb_h.path,
2381eba4c79SScott Long 					  sgasync, AC_FOUND_DEVICE, cgd);
2391eba4c79SScott Long 		if ((status != CAM_REQ_CMP) && (status != CAM_REQ_INPROG)) {
2401eba4c79SScott Long 			const struct cam_status_entry *entry;
2411eba4c79SScott Long 
2421eba4c79SScott Long 			entry = cam_fetch_status_entry(status);
2431eba4c79SScott Long 			printf("sgasync: Unable to attach new device "
2441eba4c79SScott Long 				"due to status %#x: %s\n", status, entry ?
2451eba4c79SScott Long 				entry->status_text : "Unknown");
2461eba4c79SScott Long 		}
2471eba4c79SScott Long 		break;
2481eba4c79SScott Long 	}
2491eba4c79SScott Long 	default:
2501eba4c79SScott Long 		cam_periph_async(periph, code, path, arg);
2511eba4c79SScott Long 		break;
2521eba4c79SScott Long 	}
2531eba4c79SScott Long }
2541eba4c79SScott Long 
2551eba4c79SScott Long static cam_status
2561eba4c79SScott Long sgregister(struct cam_periph *periph, void *arg)
2571eba4c79SScott Long {
2581eba4c79SScott Long 	struct sg_softc *softc;
2591eba4c79SScott Long 	struct ccb_getdev *cgd;
260b8b6b5d3SAlexander Motin 	struct ccb_pathinq cpi;
2611eba4c79SScott Long 	int no_tags;
2621eba4c79SScott Long 
2631eba4c79SScott Long 	cgd = (struct ccb_getdev *)arg;
2641eba4c79SScott Long 	if (periph == NULL) {
2651eba4c79SScott Long 		printf("sgregister: periph was NULL!!\n");
2661eba4c79SScott Long 		return (CAM_REQ_CMP_ERR);
2671eba4c79SScott Long 	}
2681eba4c79SScott Long 
2691eba4c79SScott Long 	if (cgd == NULL) {
2701eba4c79SScott Long 		printf("sgregister: no getdev CCB, can't register device\n");
2711eba4c79SScott Long 		return (CAM_REQ_CMP_ERR);
2721eba4c79SScott Long 	}
2731eba4c79SScott Long 
2744400b36dSScott Long 	softc = malloc(sizeof(*softc), M_DEVBUF, M_ZERO | M_NOWAIT);
2751eba4c79SScott Long 	if (softc == NULL) {
2761eba4c79SScott Long 		printf("sgregister: Unable to allocate softc\n");
2771eba4c79SScott Long 		return (CAM_REQ_CMP_ERR);
2781eba4c79SScott Long 	}
2791eba4c79SScott Long 
2801eba4c79SScott Long 	softc->state = SG_STATE_NORMAL;
2811eba4c79SScott Long 	softc->pd_type = SID_TYPE(&cgd->inq_data);
282715ab212SScott Long 	softc->sg_timeout = SG_DEFAULT_TIMEOUT / SG_DEFAULT_HZ * hz;
283715ab212SScott Long 	softc->sg_user_timeout = SG_DEFAULT_TIMEOUT;
2841eba4c79SScott Long 	TAILQ_INIT(&softc->rdwr_done);
2851eba4c79SScott Long 	periph->softc = softc;
2861eba4c79SScott Long 
287b8b6b5d3SAlexander Motin 	bzero(&cpi, sizeof(cpi));
288b8b6b5d3SAlexander Motin 	xpt_setup_ccb(&cpi.ccb_h, periph->path, CAM_PRIORITY_NORMAL);
289b8b6b5d3SAlexander Motin 	cpi.ccb_h.func_code = XPT_PATH_INQ;
290b8b6b5d3SAlexander Motin 	xpt_action((union ccb *)&cpi);
291b8b6b5d3SAlexander Motin 
2921eba4c79SScott Long 	/*
2931eba4c79SScott Long 	 * We pass in 0 for all blocksize, since we don't know what the
2941eba4c79SScott Long 	 * blocksize of the device is, if it even has a blocksize.
2951eba4c79SScott Long 	 */
29685d92640SScott Long 	cam_periph_unlock(periph);
2971eba4c79SScott Long 	no_tags = (cgd->inq_data.flags & SID_CmdQue) == 0;
2981eba4c79SScott Long 	softc->device_stats = devstat_new_entry("sg",
299d3ce8327SEd Schouten 			periph->unit_number, 0,
3001eba4c79SScott Long 			DEVSTAT_NO_BLOCKSIZE
3011eba4c79SScott Long 			| (no_tags ? DEVSTAT_NO_ORDERED_TAGS : 0),
3021eba4c79SScott Long 			softc->pd_type |
303b8b6b5d3SAlexander Motin 			XPORT_DEVSTAT_TYPE(cpi.transport) |
3041eba4c79SScott Long 			DEVSTAT_TYPE_PASS,
3051eba4c79SScott Long 			DEVSTAT_PRIORITY_PASS);
3061eba4c79SScott Long 
3071eba4c79SScott Long 	/* Register the device */
308d3ce8327SEd Schouten 	softc->dev = make_dev(&sg_cdevsw, periph->unit_number,
3091eba4c79SScott Long 			      UID_ROOT, GID_OPERATOR, 0600, "%s%d",
3101eba4c79SScott Long 			      periph->periph_name, periph->unit_number);
311cf454e30SMatt Jacob 	if (periph->unit_number < 26) {
312c59b4dcdSMatt Jacob 		(void)make_dev_alias(softc->dev, "sg%c",
313c59b4dcdSMatt Jacob 		    periph->unit_number + 'a');
314cf454e30SMatt Jacob 	} else {
315cf454e30SMatt Jacob 		(void)make_dev_alias(softc->dev, "sg%c%c",
316c59b4dcdSMatt Jacob 		    ((periph->unit_number / 26) - 1) + 'a',
317c59b4dcdSMatt Jacob 		    (periph->unit_number % 26) + 'a');
318cf454e30SMatt Jacob 	}
3192b83592fSScott Long 	cam_periph_lock(periph);
3201eba4c79SScott Long 	softc->dev->si_drv1 = periph;
3211eba4c79SScott Long 
3221eba4c79SScott Long 	/*
3231eba4c79SScott Long 	 * Add as async callback so that we get
3241eba4c79SScott Long 	 * notified if this device goes away.
3251eba4c79SScott Long 	 */
32685d92640SScott Long 	xpt_register_async(AC_LOST_DEVICE, sgasync, periph, periph->path);
3271eba4c79SScott Long 
3281eba4c79SScott Long 	if (bootverbose)
3291eba4c79SScott Long 		xpt_announce_periph(periph, NULL);
3301eba4c79SScott Long 
3311eba4c79SScott Long 	return (CAM_REQ_CMP);
3321eba4c79SScott Long }
3331eba4c79SScott Long 
3341eba4c79SScott Long static void
3351eba4c79SScott Long sgstart(struct cam_periph *periph, union ccb *start_ccb)
3361eba4c79SScott Long {
3371eba4c79SScott Long 	struct sg_softc *softc;
3381eba4c79SScott Long 
3391eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
3401eba4c79SScott Long 
3411eba4c79SScott Long 	switch (softc->state) {
3421eba4c79SScott Long 	case SG_STATE_NORMAL:
3431eba4c79SScott Long 		start_ccb->ccb_h.ccb_type = SG_CCB_WAITING;
3441eba4c79SScott Long 		SLIST_INSERT_HEAD(&periph->ccb_list, &start_ccb->ccb_h,
3451eba4c79SScott Long 				  periph_links.sle);
3461eba4c79SScott Long 		periph->immediate_priority = CAM_PRIORITY_NONE;
3471eba4c79SScott Long 		wakeup(&periph->ccb_list);
3481eba4c79SScott Long 		break;
3491eba4c79SScott Long 	}
3501eba4c79SScott Long }
3511eba4c79SScott Long 
3521eba4c79SScott Long static void
3531eba4c79SScott Long sgdone(struct cam_periph *periph, union ccb *done_ccb)
3541eba4c79SScott Long {
3551eba4c79SScott Long 	struct sg_softc *softc;
3561eba4c79SScott Long 	struct ccb_scsiio *csio;
3571eba4c79SScott Long 
3581eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
3591eba4c79SScott Long 	csio = &done_ccb->csio;
3601eba4c79SScott Long 	switch (csio->ccb_h.ccb_type) {
3611eba4c79SScott Long 	case SG_CCB_WAITING:
3621eba4c79SScott Long 		/* Caller will release the CCB */
3631eba4c79SScott Long 		wakeup(&done_ccb->ccb_h.cbfcnp);
3641eba4c79SScott Long 		return;
3651eba4c79SScott Long 	case SG_CCB_RDWR_IO:
3661eba4c79SScott Long 	{
3671eba4c79SScott Long 		struct sg_rdwr *rdwr;
3681eba4c79SScott Long 		int state;
3691eba4c79SScott Long 
3701eba4c79SScott Long 		devstat_end_transaction(softc->device_stats,
3711eba4c79SScott Long 					csio->dxfer_len,
3721eba4c79SScott Long 					csio->tag_action & 0xf,
3731eba4c79SScott Long 					((csio->ccb_h.flags & CAM_DIR_MASK) ==
3741eba4c79SScott Long 					CAM_DIR_NONE) ? DEVSTAT_NO_DATA :
3751eba4c79SScott Long 					(csio->ccb_h.flags & CAM_DIR_OUT) ?
3761eba4c79SScott Long 					DEVSTAT_WRITE : DEVSTAT_READ,
3771eba4c79SScott Long 					NULL, NULL);
3781eba4c79SScott Long 
3791eba4c79SScott Long 		rdwr = done_ccb->ccb_h.ccb_rdwr;
3801eba4c79SScott Long 		state = rdwr->state;
3811eba4c79SScott Long 		rdwr->state = SG_RDWR_DONE;
3821eba4c79SScott Long 		wakeup(rdwr);
3831eba4c79SScott Long 		break;
3841eba4c79SScott Long 	}
3851eba4c79SScott Long 	default:
3861eba4c79SScott Long 		panic("unknown sg CCB type");
3871eba4c79SScott Long 	}
3881eba4c79SScott Long }
3891eba4c79SScott Long 
3901eba4c79SScott Long static int
3911eba4c79SScott Long sgopen(struct cdev *dev, int flags, int fmt, struct thread *td)
3921eba4c79SScott Long {
3931eba4c79SScott Long 	struct cam_periph *periph;
3941eba4c79SScott Long 	struct sg_softc *softc;
3951eba4c79SScott Long 	int error = 0;
3961eba4c79SScott Long 
3971eba4c79SScott Long 	periph = (struct cam_periph *)dev->si_drv1;
3981eba4c79SScott Long 	if (periph == NULL)
3991eba4c79SScott Long 		return (ENXIO);
4001eba4c79SScott Long 
4018900f4b8SKenneth D. Merry 	if (cam_periph_acquire(periph) != CAM_REQ_CMP)
4028900f4b8SKenneth D. Merry 		return (ENXIO);
4038900f4b8SKenneth D. Merry 
4041eba4c79SScott Long 	/*
4051eba4c79SScott Long 	 * Don't allow access when we're running at a high securelevel.
4061eba4c79SScott Long 	 */
4071eba4c79SScott Long 	error = securelevel_gt(td->td_ucred, 1);
4088900f4b8SKenneth D. Merry 	if (error) {
4098900f4b8SKenneth D. Merry 		cam_periph_release(periph);
4101eba4c79SScott Long 		return (error);
4118900f4b8SKenneth D. Merry 	}
4121eba4c79SScott Long 
4132b83592fSScott Long 	cam_periph_lock(periph);
4142b83592fSScott Long 
4152b83592fSScott Long 	softc = (struct sg_softc *)periph->softc;
4162b83592fSScott Long 	if (softc->flags & SG_FLAG_INVALID) {
417*c552ebe1SKenneth D. Merry 		cam_periph_release_locked(periph);
4182b83592fSScott Long 		cam_periph_unlock(periph);
4192b83592fSScott Long 		return (ENXIO);
4202b83592fSScott Long 	}
4211eba4c79SScott Long 
422835187bfSScott Long 	cam_periph_unlock(periph);
4231eba4c79SScott Long 
4241eba4c79SScott Long 	return (error);
4251eba4c79SScott Long }
4261eba4c79SScott Long 
4271eba4c79SScott Long static int
4281eba4c79SScott Long sgclose(struct cdev *dev, int flag, int fmt, struct thread *td)
4291eba4c79SScott Long {
4301eba4c79SScott Long 	struct cam_periph *periph;
4311eba4c79SScott Long 
4321eba4c79SScott Long 	periph = (struct cam_periph *)dev->si_drv1;
4331eba4c79SScott Long 	if (periph == NULL)
4341eba4c79SScott Long 		return (ENXIO);
4351eba4c79SScott Long 
4361eba4c79SScott Long 	cam_periph_release(periph);
4371eba4c79SScott Long 
4381eba4c79SScott Long 	return (0);
4391eba4c79SScott Long }
4401eba4c79SScott Long 
4411eba4c79SScott Long static int
4421eba4c79SScott Long sgioctl(struct cdev *dev, u_long cmd, caddr_t arg, int flag, struct thread *td)
4431eba4c79SScott Long {
4441eba4c79SScott Long 	union ccb *ccb;
4451eba4c79SScott Long 	struct ccb_scsiio *csio;
4461eba4c79SScott Long 	struct cam_periph *periph;
4471eba4c79SScott Long 	struct sg_softc *softc;
4481eba4c79SScott Long 	struct sg_io_hdr req;
4491eba4c79SScott Long 	int dir, error;
4501eba4c79SScott Long 
4511eba4c79SScott Long 	periph = (struct cam_periph *)dev->si_drv1;
4521eba4c79SScott Long 	if (periph == NULL)
4531eba4c79SScott Long 		return (ENXIO);
4541eba4c79SScott Long 
4552b83592fSScott Long 	cam_periph_lock(periph);
4562b83592fSScott Long 
4571eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
4581eba4c79SScott Long 	error = 0;
4591eba4c79SScott Long 
4601eba4c79SScott Long 	switch (cmd) {
4611eba4c79SScott Long 	case LINUX_SCSI_GET_BUS_NUMBER: {
4621eba4c79SScott Long 		int busno;
4631eba4c79SScott Long 
4641eba4c79SScott Long 		busno = xpt_path_path_id(periph->path);
4651eba4c79SScott Long 		error = copyout(&busno, arg, sizeof(busno));
4661eba4c79SScott Long 		break;
4671eba4c79SScott Long 	}
4681eba4c79SScott Long 	case LINUX_SCSI_GET_IDLUN: {
4691eba4c79SScott Long 		struct scsi_idlun idlun;
4701eba4c79SScott Long 		struct cam_sim *sim;
4711eba4c79SScott Long 
4721eba4c79SScott Long 		idlun.dev_id = xpt_path_target_id(periph->path);
4731eba4c79SScott Long 		sim = xpt_path_sim(periph->path);
4741eba4c79SScott Long 		idlun.host_unique_id = sim->unit_number;
4751eba4c79SScott Long 		error = copyout(&idlun, arg, sizeof(idlun));
4761eba4c79SScott Long 		break;
4771eba4c79SScott Long 	}
4781eba4c79SScott Long 	case SG_GET_VERSION_NUM:
4791eba4c79SScott Long 	case LINUX_SG_GET_VERSION_NUM:
4801eba4c79SScott Long 		error = copyout(&sg_version, arg, sizeof(sg_version));
4811eba4c79SScott Long 		break;
4821eba4c79SScott Long 	case SG_SET_TIMEOUT:
483715ab212SScott Long 	case LINUX_SG_SET_TIMEOUT: {
484715ab212SScott Long 		u_int user_timeout;
485715ab212SScott Long 
486715ab212SScott Long 		error = copyin(arg, &user_timeout, sizeof(u_int));
487715ab212SScott Long 		if (error == 0) {
488715ab212SScott Long 			softc->sg_user_timeout = user_timeout;
489715ab212SScott Long 			softc->sg_timeout = user_timeout / SG_DEFAULT_HZ * hz;
490715ab212SScott Long 		}
4911eba4c79SScott Long 		break;
492715ab212SScott Long 	}
4931eba4c79SScott Long 	case SG_GET_TIMEOUT:
4941eba4c79SScott Long 	case LINUX_SG_GET_TIMEOUT:
4951eba4c79SScott Long 		/*
496715ab212SScott Long 		 * The value is returned directly to the syscall.
4971eba4c79SScott Long 		 */
498715ab212SScott Long 		td->td_retval[0] = softc->sg_user_timeout;
4991eba4c79SScott Long 		error = 0;
5001eba4c79SScott Long 		break;
5011eba4c79SScott Long 	case SG_IO:
5021eba4c79SScott Long 	case LINUX_SG_IO:
5031eba4c79SScott Long 		error = copyin(arg, &req, sizeof(req));
5041eba4c79SScott Long 		if (error)
5051eba4c79SScott Long 			break;
5061eba4c79SScott Long 
5071eba4c79SScott Long 		if (req.cmd_len > IOCDBLEN) {
5081eba4c79SScott Long 			error = EINVAL;
5091eba4c79SScott Long 			break;
5101eba4c79SScott Long 		}
5111eba4c79SScott Long 
5121eba4c79SScott Long 		if (req.iovec_count != 0) {
5131eba4c79SScott Long 			error = EOPNOTSUPP;
5141eba4c79SScott Long 			break;
5151eba4c79SScott Long 		}
5161eba4c79SScott Long 
5171e637ba6SAlexander Motin 		ccb = cam_periph_getccb(periph, CAM_PRIORITY_NORMAL);
5181eba4c79SScott Long 		csio = &ccb->csio;
5191eba4c79SScott Long 
5201eba4c79SScott Long 		error = copyin(req.cmdp, &csio->cdb_io.cdb_bytes,
5211eba4c79SScott Long 		    req.cmd_len);
5221eba4c79SScott Long 		if (error) {
5231eba4c79SScott Long 			xpt_release_ccb(ccb);
5241eba4c79SScott Long 			break;
5251eba4c79SScott Long 		}
5261eba4c79SScott Long 
5271eba4c79SScott Long 		switch(req.dxfer_direction) {
5281eba4c79SScott Long 		case SG_DXFER_TO_DEV:
5291eba4c79SScott Long 			dir = CAM_DIR_OUT;
5301eba4c79SScott Long 			break;
5311eba4c79SScott Long 		case SG_DXFER_FROM_DEV:
5321eba4c79SScott Long 			dir = CAM_DIR_IN;
5331eba4c79SScott Long 			break;
5341eba4c79SScott Long 		case SG_DXFER_TO_FROM_DEV:
5351eba4c79SScott Long 			dir = CAM_DIR_IN | CAM_DIR_OUT;
5361eba4c79SScott Long 			break;
5371eba4c79SScott Long 		case SG_DXFER_NONE:
5381eba4c79SScott Long 		default:
5391eba4c79SScott Long 			dir = CAM_DIR_NONE;
5401eba4c79SScott Long 			break;
5411eba4c79SScott Long 		}
5421eba4c79SScott Long 
5431eba4c79SScott Long 		cam_fill_csio(csio,
5441eba4c79SScott Long 			      /*retries*/1,
5451eba4c79SScott Long 			      sgdone,
5461eba4c79SScott Long 			      dir|CAM_DEV_QFRZDIS,
5471eba4c79SScott Long 			      MSG_SIMPLE_Q_TAG,
5481eba4c79SScott Long 			      req.dxferp,
5491eba4c79SScott Long 			      req.dxfer_len,
5501eba4c79SScott Long 			      req.mx_sb_len,
5511eba4c79SScott Long 			      req.cmd_len,
5521eba4c79SScott Long 			      req.timeout);
5531eba4c79SScott Long 
5541eba4c79SScott Long 		error = sgsendccb(periph, ccb);
5551eba4c79SScott Long 		if (error) {
5561eba4c79SScott Long 			req.host_status = DID_ERROR;
5571eba4c79SScott Long 			req.driver_status = DRIVER_INVALID;
5581eba4c79SScott Long 			xpt_release_ccb(ccb);
5591eba4c79SScott Long 			break;
5601eba4c79SScott Long 		}
5611eba4c79SScott Long 
5621eba4c79SScott Long 		req.status = csio->scsi_status;
5631eba4c79SScott Long 		req.masked_status = (csio->scsi_status >> 1) & 0x7f;
5641eba4c79SScott Long 		sg_scsiio_status(csio, &req.host_status, &req.driver_status);
5651eba4c79SScott Long 		req.resid = csio->resid;
5661eba4c79SScott Long 		req.duration = csio->ccb_h.timeout;
5671eba4c79SScott Long 		req.info = 0;
5681eba4c79SScott Long 
5691eba4c79SScott Long 		error = copyout(&req, arg, sizeof(req));
5701eba4c79SScott Long 		if ((error == 0) && (csio->ccb_h.status & CAM_AUTOSNS_VALID)
5711eba4c79SScott Long 		    && (req.sbp != NULL)) {
5721eba4c79SScott Long 			req.sb_len_wr = req.mx_sb_len - csio->sense_resid;
5731eba4c79SScott Long 			error = copyout(&csio->sense_data, req.sbp,
5741eba4c79SScott Long 					req.sb_len_wr);
5751eba4c79SScott Long 		}
5761eba4c79SScott Long 
5771eba4c79SScott Long 		xpt_release_ccb(ccb);
5781eba4c79SScott Long 		break;
5791eba4c79SScott Long 
5801eba4c79SScott Long 	case SG_GET_RESERVED_SIZE:
5811eba4c79SScott Long 	case LINUX_SG_GET_RESERVED_SIZE: {
5821eba4c79SScott Long 		int size = 32768;
5831eba4c79SScott Long 
5841eba4c79SScott Long 		error = copyout(&size, arg, sizeof(size));
5851eba4c79SScott Long 		break;
5861eba4c79SScott Long 	}
5871eba4c79SScott Long 
5881eba4c79SScott Long 	case SG_GET_SCSI_ID:
5891eba4c79SScott Long 	case LINUX_SG_GET_SCSI_ID:
5901eba4c79SScott Long 	{
5911eba4c79SScott Long 		struct sg_scsi_id id;
5921eba4c79SScott Long 
59375b06c87SMatt Jacob 		id.host_no = cam_sim_path(xpt_path_sim(periph->path));
5941eba4c79SScott Long 		id.channel = xpt_path_path_id(periph->path);
5951eba4c79SScott Long 		id.scsi_id = xpt_path_target_id(periph->path);
5961eba4c79SScott Long 		id.lun = xpt_path_lun_id(periph->path);
5971eba4c79SScott Long 		id.scsi_type = softc->pd_type;
5981eba4c79SScott Long 		id.h_cmd_per_lun = 1;
5991eba4c79SScott Long 		id.d_queue_depth = 1;
6001eba4c79SScott Long 		id.unused[0] = 0;
6011eba4c79SScott Long 		id.unused[1] = 0;
6021eba4c79SScott Long 
6031eba4c79SScott Long 		error = copyout(&id, arg, sizeof(id));
6041eba4c79SScott Long 		break;
6051eba4c79SScott Long 	}
6061eba4c79SScott Long 
6071eba4c79SScott Long 	case SG_EMULATED_HOST:
6081eba4c79SScott Long 	case SG_SET_TRANSFORM:
6091eba4c79SScott Long 	case SG_GET_TRANSFORM:
6101eba4c79SScott Long 	case SG_GET_NUM_WAITING:
6111eba4c79SScott Long 	case SG_SCSI_RESET:
6121eba4c79SScott Long 	case SG_GET_REQUEST_TABLE:
6131eba4c79SScott Long 	case SG_SET_KEEP_ORPHAN:
6141eba4c79SScott Long 	case SG_GET_KEEP_ORPHAN:
6151eba4c79SScott Long 	case SG_GET_ACCESS_COUNT:
6161eba4c79SScott Long 	case SG_SET_FORCE_LOW_DMA:
6171eba4c79SScott Long 	case SG_GET_LOW_DMA:
6181eba4c79SScott Long 	case SG_GET_SG_TABLESIZE:
6191eba4c79SScott Long 	case SG_SET_FORCE_PACK_ID:
6201eba4c79SScott Long 	case SG_GET_PACK_ID:
6211eba4c79SScott Long 	case SG_SET_RESERVED_SIZE:
6221eba4c79SScott Long 	case SG_GET_COMMAND_Q:
6231eba4c79SScott Long 	case SG_SET_COMMAND_Q:
6241eba4c79SScott Long 	case SG_SET_DEBUG:
6251eba4c79SScott Long 	case SG_NEXT_CMD_LEN:
6261eba4c79SScott Long 	case LINUX_SG_EMULATED_HOST:
6271eba4c79SScott Long 	case LINUX_SG_SET_TRANSFORM:
6281eba4c79SScott Long 	case LINUX_SG_GET_TRANSFORM:
6291eba4c79SScott Long 	case LINUX_SG_GET_NUM_WAITING:
6301eba4c79SScott Long 	case LINUX_SG_SCSI_RESET:
6311eba4c79SScott Long 	case LINUX_SG_GET_REQUEST_TABLE:
6321eba4c79SScott Long 	case LINUX_SG_SET_KEEP_ORPHAN:
6331eba4c79SScott Long 	case LINUX_SG_GET_KEEP_ORPHAN:
6341eba4c79SScott Long 	case LINUX_SG_GET_ACCESS_COUNT:
6351eba4c79SScott Long 	case LINUX_SG_SET_FORCE_LOW_DMA:
6361eba4c79SScott Long 	case LINUX_SG_GET_LOW_DMA:
6371eba4c79SScott Long 	case LINUX_SG_GET_SG_TABLESIZE:
6381eba4c79SScott Long 	case LINUX_SG_SET_FORCE_PACK_ID:
6391eba4c79SScott Long 	case LINUX_SG_GET_PACK_ID:
6401eba4c79SScott Long 	case LINUX_SG_SET_RESERVED_SIZE:
6411eba4c79SScott Long 	case LINUX_SG_GET_COMMAND_Q:
6421eba4c79SScott Long 	case LINUX_SG_SET_COMMAND_Q:
6431eba4c79SScott Long 	case LINUX_SG_SET_DEBUG:
6441eba4c79SScott Long 	case LINUX_SG_NEXT_CMD_LEN:
6451eba4c79SScott Long 	default:
6461eba4c79SScott Long #ifdef CAMDEBUG
6471eba4c79SScott Long 		printf("sgioctl: rejecting cmd 0x%lx\n", cmd);
6481eba4c79SScott Long #endif
6491eba4c79SScott Long 		error = ENODEV;
6501eba4c79SScott Long 		break;
6511eba4c79SScott Long 	}
6521eba4c79SScott Long 
6532b83592fSScott Long 	cam_periph_unlock(periph);
6541eba4c79SScott Long 	return (error);
6551eba4c79SScott Long }
6561eba4c79SScott Long 
6571eba4c79SScott Long static int
6581eba4c79SScott Long sgwrite(struct cdev *dev, struct uio *uio, int ioflag)
6591eba4c79SScott Long {
6601eba4c79SScott Long 	union ccb *ccb;
6611eba4c79SScott Long 	struct cam_periph *periph;
6621eba4c79SScott Long 	struct ccb_scsiio *csio;
6631eba4c79SScott Long 	struct sg_softc *sc;
6641eba4c79SScott Long 	struct sg_header *hdr;
6651eba4c79SScott Long 	struct sg_rdwr *rdwr;
6661eba4c79SScott Long 	u_char cdb_cmd;
6671eba4c79SScott Long 	char *buf;
6681eba4c79SScott Long 	int error = 0, cdb_len, buf_len, dir;
6691eba4c79SScott Long 
6701eba4c79SScott Long 	periph = dev->si_drv1;
6714400b36dSScott Long 	rdwr = malloc(sizeof(*rdwr), M_DEVBUF, M_WAITOK | M_ZERO);
6721eba4c79SScott Long 	hdr = &rdwr->hdr.hdr;
6731eba4c79SScott Long 
6741eba4c79SScott Long 	/* Copy in the header block and sanity check it */
6751eba4c79SScott Long 	if (uio->uio_resid < sizeof(*hdr)) {
6761eba4c79SScott Long 		error = EINVAL;
6771eba4c79SScott Long 		goto out_hdr;
6781eba4c79SScott Long 	}
6791eba4c79SScott Long 	error = uiomove(hdr, sizeof(*hdr), uio);
6801eba4c79SScott Long 	if (error)
6811eba4c79SScott Long 		goto out_hdr;
6821eba4c79SScott Long 
6838008a935SScott Long 	ccb = xpt_alloc_ccb();
6841eba4c79SScott Long 	if (ccb == NULL) {
6851eba4c79SScott Long 		error = ENOMEM;
6861eba4c79SScott Long 		goto out_hdr;
6871eba4c79SScott Long 	}
6881eba4c79SScott Long 	csio = &ccb->csio;
6891eba4c79SScott Long 
6901eba4c79SScott Long 	/*
6911eba4c79SScott Long 	 * Copy in the CDB block.  The designers of the interface didn't
6921eba4c79SScott Long 	 * bother to provide a size for this in the header, so we have to
6931eba4c79SScott Long 	 * figure it out ourselves.
6941eba4c79SScott Long 	 */
6951eba4c79SScott Long 	if (uio->uio_resid < 1)
6961eba4c79SScott Long 		goto out_ccb;
6971eba4c79SScott Long 	error = uiomove(&cdb_cmd, 1, uio);
6981eba4c79SScott Long 	if (error)
6991eba4c79SScott Long 		goto out_ccb;
7001eba4c79SScott Long 	if (hdr->twelve_byte)
7011eba4c79SScott Long 		cdb_len = 12;
7021eba4c79SScott Long 	else
7031eba4c79SScott Long 		cdb_len = scsi_group_len(cdb_cmd);
7041eba4c79SScott Long 	/*
7051eba4c79SScott Long 	 * We've already read the first byte of the CDB and advanced the uio
7061eba4c79SScott Long 	 * pointer.  Just read the rest.
7071eba4c79SScott Long 	 */
7081eba4c79SScott Long 	csio->cdb_io.cdb_bytes[0] = cdb_cmd;
7091eba4c79SScott Long 	error = uiomove(&csio->cdb_io.cdb_bytes[1], cdb_len - 1, uio);
7101eba4c79SScott Long 	if (error)
7111eba4c79SScott Long 		goto out_ccb;
7121eba4c79SScott Long 
7131eba4c79SScott Long 	/*
7141eba4c79SScott Long 	 * Now set up the data block.  Again, the designers didn't bother
7151eba4c79SScott Long 	 * to make this reliable.
7161eba4c79SScott Long 	 */
7171eba4c79SScott Long 	buf_len = uio->uio_resid;
7181eba4c79SScott Long 	if (buf_len != 0) {
7194400b36dSScott Long 		buf = malloc(buf_len, M_DEVBUF, M_WAITOK | M_ZERO);
7201eba4c79SScott Long 		error = uiomove(buf, buf_len, uio);
7211eba4c79SScott Long 		if (error)
7221eba4c79SScott Long 			goto out_buf;
7231eba4c79SScott Long 		dir = CAM_DIR_OUT;
7241eba4c79SScott Long 	} else if (hdr->reply_len != 0) {
7254400b36dSScott Long 		buf = malloc(hdr->reply_len, M_DEVBUF, M_WAITOK | M_ZERO);
7261eba4c79SScott Long 		buf_len = hdr->reply_len;
7271eba4c79SScott Long 		dir = CAM_DIR_IN;
7281eba4c79SScott Long 	} else {
7291eba4c79SScott Long 		buf = NULL;
7301eba4c79SScott Long 		buf_len = 0;
7311eba4c79SScott Long 		dir = CAM_DIR_NONE;
7321eba4c79SScott Long 	}
7331eba4c79SScott Long 
7342b83592fSScott Long 	cam_periph_lock(periph);
7352b83592fSScott Long 	sc = periph->softc;
7361e637ba6SAlexander Motin 	xpt_setup_ccb(&ccb->ccb_h, periph->path, CAM_PRIORITY_NORMAL);
7371eba4c79SScott Long 	cam_fill_csio(csio,
7381eba4c79SScott Long 		      /*retries*/1,
7391eba4c79SScott Long 		      sgdone,
7401eba4c79SScott Long 		      dir|CAM_DEV_QFRZDIS,
7411eba4c79SScott Long 		      MSG_SIMPLE_Q_TAG,
7421eba4c79SScott Long 		      buf,
7431eba4c79SScott Long 		      buf_len,
7441eba4c79SScott Long 		      SG_MAX_SENSE,
7451eba4c79SScott Long 		      cdb_len,
746715ab212SScott Long 		      sc->sg_timeout);
7471eba4c79SScott Long 
7481eba4c79SScott Long 	/*
7491eba4c79SScott Long 	 * Send off the command and hope that it works. This path does not
7501eba4c79SScott Long 	 * go through sgstart because the I/O is supposed to be asynchronous.
7511eba4c79SScott Long 	 */
7521eba4c79SScott Long 	rdwr->buf = buf;
7531eba4c79SScott Long 	rdwr->buf_len = buf_len;
7541eba4c79SScott Long 	rdwr->tag = hdr->pack_id;
7551eba4c79SScott Long 	rdwr->ccb = ccb;
7561eba4c79SScott Long 	rdwr->state = SG_RDWR_INPROG;
7571eba4c79SScott Long 	ccb->ccb_h.ccb_rdwr = rdwr;
7581eba4c79SScott Long 	ccb->ccb_h.ccb_type = SG_CCB_RDWR_IO;
7591eba4c79SScott Long 	TAILQ_INSERT_TAIL(&sc->rdwr_done, rdwr, rdwr_link);
7602b83592fSScott Long 	error = sgsendrdwr(periph, ccb);
7612b83592fSScott Long 	cam_periph_unlock(periph);
7622b83592fSScott Long 	return (error);
7631eba4c79SScott Long 
7641eba4c79SScott Long out_buf:
7651eba4c79SScott Long 	free(buf, M_DEVBUF);
7661eba4c79SScott Long out_ccb:
7671eba4c79SScott Long 	xpt_free_ccb(ccb);
7681eba4c79SScott Long out_hdr:
7691eba4c79SScott Long 	free(rdwr, M_DEVBUF);
7701eba4c79SScott Long 	return (error);
7711eba4c79SScott Long }
7721eba4c79SScott Long 
7731eba4c79SScott Long static int
7741eba4c79SScott Long sgread(struct cdev *dev, struct uio *uio, int ioflag)
7751eba4c79SScott Long {
7761eba4c79SScott Long 	struct ccb_scsiio *csio;
7771eba4c79SScott Long 	struct cam_periph *periph;
7781eba4c79SScott Long 	struct sg_softc *sc;
7791eba4c79SScott Long 	struct sg_header *hdr;
7801eba4c79SScott Long 	struct sg_rdwr *rdwr;
7811eba4c79SScott Long 	u_short hstat, dstat;
7821eba4c79SScott Long 	int error, pack_len, reply_len, pack_id;
7831eba4c79SScott Long 
7841eba4c79SScott Long 	periph = dev->si_drv1;
7851eba4c79SScott Long 
7861eba4c79SScott Long 	/* XXX The pack len field needs to be updated and written out instead
7871eba4c79SScott Long 	 * of discarded.  Not sure how to do that.
7881eba4c79SScott Long 	 */
7891eba4c79SScott Long 	uio->uio_rw = UIO_WRITE;
7901eba4c79SScott Long 	if ((error = uiomove(&pack_len, 4, uio)) != 0)
7911eba4c79SScott Long 		return (error);
7921eba4c79SScott Long 	if ((error = uiomove(&reply_len, 4, uio)) != 0)
7931eba4c79SScott Long 		return (error);
7941eba4c79SScott Long 	if ((error = uiomove(&pack_id, 4, uio)) != 0)
7951eba4c79SScott Long 		return (error);
7961eba4c79SScott Long 	uio->uio_rw = UIO_READ;
7971eba4c79SScott Long 
7982b83592fSScott Long 	cam_periph_lock(periph);
7992b83592fSScott Long 	sc = periph->softc;
8001eba4c79SScott Long search:
8011eba4c79SScott Long 	TAILQ_FOREACH(rdwr, &sc->rdwr_done, rdwr_link) {
8021eba4c79SScott Long 		if (rdwr->tag == pack_id)
8031eba4c79SScott Long 			break;
8041eba4c79SScott Long 	}
8051eba4c79SScott Long 	if ((rdwr == NULL) || (rdwr->state != SG_RDWR_DONE)) {
8062b83592fSScott Long 		if (msleep(rdwr, periph->sim->mtx, PCATCH, "sgread", 0) == ERESTART)
8071eba4c79SScott Long 			return (EAGAIN);
8081eba4c79SScott Long 		goto search;
8091eba4c79SScott Long 	}
8101eba4c79SScott Long 	TAILQ_REMOVE(&sc->rdwr_done, rdwr, rdwr_link);
8112b83592fSScott Long 	cam_periph_unlock(periph);
8121eba4c79SScott Long 
8131eba4c79SScott Long 	hdr = &rdwr->hdr.hdr;
8141eba4c79SScott Long 	csio = &rdwr->ccb->csio;
8151eba4c79SScott Long 	sg_scsiio_status(csio, &hstat, &dstat);
8161eba4c79SScott Long 	hdr->host_status = hstat;
8171eba4c79SScott Long 	hdr->driver_status = dstat;
8181eba4c79SScott Long 	hdr->target_status = csio->scsi_status >> 1;
8191eba4c79SScott Long 
8201eba4c79SScott Long 	switch (hstat) {
8211eba4c79SScott Long 	case DID_OK:
8221eba4c79SScott Long 	case DID_PASSTHROUGH:
8231eba4c79SScott Long 	case DID_SOFT_ERROR:
8241eba4c79SScott Long 		hdr->result = 0;
8251eba4c79SScott Long 		break;
8261eba4c79SScott Long 	case DID_NO_CONNECT:
8271eba4c79SScott Long 	case DID_BUS_BUSY:
8281eba4c79SScott Long 	case DID_TIME_OUT:
8291eba4c79SScott Long 		hdr->result = EBUSY;
8301eba4c79SScott Long 		break;
8311eba4c79SScott Long 	case DID_BAD_TARGET:
8321eba4c79SScott Long 	case DID_ABORT:
8331eba4c79SScott Long 	case DID_PARITY:
8341eba4c79SScott Long 	case DID_RESET:
8351eba4c79SScott Long 	case DID_BAD_INTR:
8361eba4c79SScott Long 	case DID_ERROR:
8371eba4c79SScott Long 	default:
8381eba4c79SScott Long 		hdr->result = EIO;
8391eba4c79SScott Long 		break;
8401eba4c79SScott Long 	}
8411eba4c79SScott Long 
8421eba4c79SScott Long 	if (dstat == DRIVER_SENSE) {
8431eba4c79SScott Long 		bcopy(&csio->sense_data, hdr->sense_buffer,
8441eba4c79SScott Long 		      min(csio->sense_len, SG_MAX_SENSE));
8451eba4c79SScott Long #ifdef CAMDEBUG
8461eba4c79SScott Long 		scsi_sense_print(csio);
8471eba4c79SScott Long #endif
8481eba4c79SScott Long 	}
8491eba4c79SScott Long 
8501eba4c79SScott Long 	error = uiomove(&hdr->result, sizeof(*hdr) -
8511eba4c79SScott Long 			offsetof(struct sg_header, result), uio);
8521eba4c79SScott Long 	if ((error == 0) && (hdr->result == 0))
8531eba4c79SScott Long 		error = uiomove(rdwr->buf, rdwr->buf_len, uio);
8541eba4c79SScott Long 
8552b83592fSScott Long 	cam_periph_lock(periph);
8561eba4c79SScott Long 	xpt_free_ccb(rdwr->ccb);
8572b83592fSScott Long 	cam_periph_unlock(periph);
8581eba4c79SScott Long 	free(rdwr->buf, M_DEVBUF);
8591eba4c79SScott Long 	free(rdwr, M_DEVBUF);
8601eba4c79SScott Long 	return (error);
8611eba4c79SScott Long }
8621eba4c79SScott Long 
8631eba4c79SScott Long static int
8641eba4c79SScott Long sgsendccb(struct cam_periph *periph, union ccb *ccb)
8651eba4c79SScott Long {
8661eba4c79SScott Long 	struct sg_softc *softc;
8671eba4c79SScott Long 	struct cam_periph_map_info mapinfo;
8681eba4c79SScott Long 	int error, need_unmap = 0;
8691eba4c79SScott Long 
8701eba4c79SScott Long 	softc = periph->softc;
8711eba4c79SScott Long 	if (((ccb->ccb_h.flags & CAM_DIR_MASK) != CAM_DIR_NONE)
8721eba4c79SScott Long 	    && (ccb->csio.data_ptr != NULL)) {
8731eba4c79SScott Long 		bzero(&mapinfo, sizeof(mapinfo));
8742b83592fSScott Long 
8752b83592fSScott Long 		/*
8762b83592fSScott Long 		 * cam_periph_mapmem calls into proc and vm functions that can
8772b83592fSScott Long 		 * sleep as well as trigger I/O, so we can't hold the lock.
8782b83592fSScott Long 		 * Dropping it here is reasonably safe.
8792b83592fSScott Long 		 */
8802b83592fSScott Long 		cam_periph_unlock(periph);
8811eba4c79SScott Long 		error = cam_periph_mapmem(ccb, &mapinfo);
8822b83592fSScott Long 		cam_periph_lock(periph);
8831eba4c79SScott Long 		if (error)
8841eba4c79SScott Long 			return (error);
8851eba4c79SScott Long 		need_unmap = 1;
8861eba4c79SScott Long 	}
8871eba4c79SScott Long 
8881eba4c79SScott Long 	error = cam_periph_runccb(ccb,
8891eba4c79SScott Long 				  sgerror,
8901eba4c79SScott Long 				  CAM_RETRY_SELTO,
8911eba4c79SScott Long 				  SF_RETRY_UA,
8921eba4c79SScott Long 				  softc->device_stats);
8931eba4c79SScott Long 
8941eba4c79SScott Long 	if (need_unmap)
8951eba4c79SScott Long 		cam_periph_unmapmem(ccb, &mapinfo);
8961eba4c79SScott Long 
8971eba4c79SScott Long 	return (error);
8981eba4c79SScott Long }
8991eba4c79SScott Long 
9001eba4c79SScott Long static int
9011eba4c79SScott Long sgsendrdwr(struct cam_periph *periph, union ccb *ccb)
9021eba4c79SScott Long {
9031eba4c79SScott Long 	struct sg_softc *softc;
9041eba4c79SScott Long 
9051eba4c79SScott Long 	softc = periph->softc;
9061eba4c79SScott Long 	devstat_start_transaction(softc->device_stats, NULL);
9071eba4c79SScott Long 	xpt_action(ccb);
9081eba4c79SScott Long 	return (0);
9091eba4c79SScott Long }
9101eba4c79SScott Long 
9111eba4c79SScott Long static int
9121eba4c79SScott Long sgerror(union ccb *ccb, uint32_t cam_flags, uint32_t sense_flags)
9131eba4c79SScott Long {
9141eba4c79SScott Long 	struct cam_periph *periph;
9151eba4c79SScott Long 	struct sg_softc *softc;
9161eba4c79SScott Long 
9171eba4c79SScott Long 	periph = xpt_path_periph(ccb->ccb_h.path);
9181eba4c79SScott Long 	softc = (struct sg_softc *)periph->softc;
9191eba4c79SScott Long 
9201eba4c79SScott Long 	return (cam_periph_error(ccb, cam_flags, sense_flags,
9211eba4c79SScott Long 				 &softc->saved_ccb));
9221eba4c79SScott Long }
9231eba4c79SScott Long 
9241eba4c79SScott Long static void
9251eba4c79SScott Long sg_scsiio_status(struct ccb_scsiio *csio, u_short *hoststat, u_short *drvstat)
9261eba4c79SScott Long {
9271eba4c79SScott Long 	int status;
9281eba4c79SScott Long 
9291eba4c79SScott Long 	status = csio->ccb_h.status;
9301eba4c79SScott Long 
9311eba4c79SScott Long 	switch (status & CAM_STATUS_MASK) {
9321eba4c79SScott Long 	case CAM_REQ_CMP:
9331eba4c79SScott Long 		*hoststat = DID_OK;
9341eba4c79SScott Long 		*drvstat = 0;
9351eba4c79SScott Long 		break;
9361eba4c79SScott Long 	case CAM_REQ_CMP_ERR:
9371eba4c79SScott Long 		*hoststat = DID_ERROR;
9381eba4c79SScott Long 		*drvstat = 0;
9391eba4c79SScott Long 		break;
9401eba4c79SScott Long 	case CAM_REQ_ABORTED:
9411eba4c79SScott Long 		*hoststat = DID_ABORT;
9421eba4c79SScott Long 		*drvstat = 0;
9431eba4c79SScott Long 		break;
9441eba4c79SScott Long 	case CAM_REQ_INVALID:
9451eba4c79SScott Long 		*hoststat = DID_ERROR;
9461eba4c79SScott Long 		*drvstat = DRIVER_INVALID;
9471eba4c79SScott Long 		break;
9481eba4c79SScott Long 	case CAM_DEV_NOT_THERE:
9491eba4c79SScott Long 		*hoststat = DID_BAD_TARGET;
9501eba4c79SScott Long 		*drvstat = 0;
9514fee613eSEdward Tomasz Napierala 		break;
9521eba4c79SScott Long 	case CAM_SEL_TIMEOUT:
9531eba4c79SScott Long 		*hoststat = DID_NO_CONNECT;
9541eba4c79SScott Long 		*drvstat = 0;
9551eba4c79SScott Long 		break;
9561eba4c79SScott Long 	case CAM_CMD_TIMEOUT:
9571eba4c79SScott Long 		*hoststat = DID_TIME_OUT;
9581eba4c79SScott Long 		*drvstat = 0;
9591eba4c79SScott Long 		break;
9601eba4c79SScott Long 	case CAM_SCSI_STATUS_ERROR:
9611eba4c79SScott Long 		*hoststat = DID_ERROR;
9621eba4c79SScott Long 		*drvstat = 0;
9630c70e307SEdward Tomasz Napierala 		break;
9641eba4c79SScott Long 	case CAM_SCSI_BUS_RESET:
9651eba4c79SScott Long 		*hoststat = DID_RESET;
9661eba4c79SScott Long 		*drvstat = 0;
9671eba4c79SScott Long 		break;
9681eba4c79SScott Long 	case CAM_UNCOR_PARITY:
9691eba4c79SScott Long 		*hoststat = DID_PARITY;
9701eba4c79SScott Long 		*drvstat = 0;
9711eba4c79SScott Long 		break;
9721eba4c79SScott Long 	case CAM_SCSI_BUSY:
9731eba4c79SScott Long 		*hoststat = DID_BUS_BUSY;
9741eba4c79SScott Long 		*drvstat = 0;
9750c70e307SEdward Tomasz Napierala 		break;
9761eba4c79SScott Long 	default:
9771eba4c79SScott Long 		*hoststat = DID_ERROR;
9781eba4c79SScott Long 		*drvstat = DRIVER_ERROR;
9791eba4c79SScott Long 	}
9801eba4c79SScott Long 
9811eba4c79SScott Long 	if (status & CAM_AUTOSNS_VALID)
9821eba4c79SScott Long 		*drvstat = DRIVER_SENSE;
9831eba4c79SScott Long }
9841eba4c79SScott Long 
9851eba4c79SScott Long static int
9861eba4c79SScott Long scsi_group_len(u_char cmd)
9871eba4c79SScott Long {
9881eba4c79SScott Long 	int len[] = {6, 10, 10, 12, 12, 12, 10, 10};
9891eba4c79SScott Long 	int group;
9901eba4c79SScott Long 
9911eba4c79SScott Long 	group = (cmd >> 5) & 0x7;
9921eba4c79SScott Long 	return (len[group]);
9931eba4c79SScott Long }
9941eba4c79SScott Long 
995