xref: /freebsd/sys/dev/isp/isp.c (revision 90d30dd1a9dc7f1dc7ef75e86a85f732754dd9d7)
1 /*-
2  *  Copyright (c) 1997-2009 by Matthew Jacob
3  *  All rights reserved.
4  *
5  *  Redistribution and use in source and binary forms, with or without
6  *  modification, are permitted provided that the following conditions
7  *  are met:
8  *
9  *  1. Redistributions of source code must retain the above copyright
10  *     notice, this list of conditions and the following disclaimer.
11  *  2. Redistributions in binary form must reproduce the above copyright
12  *     notice, this list of conditions and the following disclaimer in the
13  *     documentation and/or other materials provided with the distribution.
14  *
15  *  THIS SOFTWARE IS PROVIDED BY AUTHOR AND CONTRIBUTORS ``AS IS'' AND
16  *  ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17  *  IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18  *  ARE DISCLAIMED.  IN NO EVENT SHALL AUTHOR OR CONTRIBUTORS BE LIABLE
19  *  FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20  *  DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21  *  OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22  *  HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23  *  LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24  *  OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
25  *  SUCH DAMAGE.
26  *
27  */
28 
29 /*
30  * Machine and OS Independent (well, as best as possible)
31  * code for the Qlogic ISP SCSI and FC-SCSI adapters.
32  */
33 
34 /*
35  * Inspiration and ideas about this driver are from Erik Moe's Linux driver
36  * (qlogicisp.c) and Dave Miller's SBus version of same (qlogicisp.c). Some
37  * ideas dredged from the Solaris driver.
38  */
39 
40 /*
41  * Include header file appropriate for platform we're building on.
42  */
43 #ifdef	__NetBSD__
44 #include <sys/cdefs.h>
45 __KERNEL_RCSID(0, "$NetBSD$");
46 #include <dev/ic/isp_netbsd.h>
47 #endif
48 #ifdef	__FreeBSD__
49 #include <sys/cdefs.h>
50 __FBSDID("$FreeBSD$");
51 #include <dev/isp/isp_freebsd.h>
52 #endif
53 #ifdef	__OpenBSD__
54 #include <dev/ic/isp_openbsd.h>
55 #endif
56 #ifdef	__linux__
57 #include "isp_linux.h"
58 #endif
59 #ifdef	__svr4__
60 #include "isp_solaris.h"
61 #endif
62 
63 /*
64  * General defines
65  */
66 #define	MBOX_DELAY_COUNT	1000000 / 100
67 
68 /*
69  * Local static data
70  */
71 static const char notresp[] = "Not RESPONSE in RESPONSE Queue (type 0x%x) @ idx %d (next %d) nlooked %d";
72 static const char bun[] = "bad underrun (count %d, resid %d, status %s)";
73 static const char lipd[] = "Chan %d LIP destroyed %d active commands";
74 static const char sacq[] = "unable to acquire scratch area";
75 
76 static const uint8_t alpa_map[] = {
77 	0xef, 0xe8, 0xe4, 0xe2, 0xe1, 0xe0, 0xdc, 0xda,
78 	0xd9, 0xd6, 0xd5, 0xd4, 0xd3, 0xd2, 0xd1, 0xce,
79 	0xcd, 0xcc, 0xcb, 0xca, 0xc9, 0xc7, 0xc6, 0xc5,
80 	0xc3, 0xbc, 0xba, 0xb9, 0xb6, 0xb5, 0xb4, 0xb3,
81 	0xb2, 0xb1, 0xae, 0xad, 0xac, 0xab, 0xaa, 0xa9,
82 	0xa7, 0xa6, 0xa5, 0xa3, 0x9f, 0x9e, 0x9d, 0x9b,
83 	0x98, 0x97, 0x90, 0x8f, 0x88, 0x84, 0x82, 0x81,
84 	0x80, 0x7c, 0x7a, 0x79, 0x76, 0x75, 0x74, 0x73,
85 	0x72, 0x71, 0x6e, 0x6d, 0x6c, 0x6b, 0x6a, 0x69,
86 	0x67, 0x66, 0x65, 0x63, 0x5c, 0x5a, 0x59, 0x56,
87 	0x55, 0x54, 0x53, 0x52, 0x51, 0x4e, 0x4d, 0x4c,
88 	0x4b, 0x4a, 0x49, 0x47, 0x46, 0x45, 0x43, 0x3c,
89 	0x3a, 0x39, 0x36, 0x35, 0x34, 0x33, 0x32, 0x31,
90 	0x2e, 0x2d, 0x2c, 0x2b, 0x2a, 0x29, 0x27, 0x26,
91 	0x25, 0x23, 0x1f, 0x1e, 0x1d, 0x1b, 0x18, 0x17,
92 	0x10, 0x0f, 0x08, 0x04, 0x02, 0x01, 0x00
93 };
94 
95 /*
96  * Local function prototypes.
97  */
98 static int isp_parse_async(ispsoftc_t *, uint16_t);
99 static int isp_parse_async_fc(ispsoftc_t *, uint16_t);
100 static int isp_handle_other_response(ispsoftc_t *, int, isphdr_t *, uint32_t *);
101 static void isp_parse_status(ispsoftc_t *, ispstatusreq_t *, XS_T *, long *); static void
102 isp_parse_status_24xx(ispsoftc_t *, isp24xx_statusreq_t *, XS_T *, long *);
103 static void isp_fastpost_complete(ispsoftc_t *, uint32_t);
104 static int isp_mbox_continue(ispsoftc_t *);
105 static void isp_scsi_init(ispsoftc_t *);
106 static void isp_scsi_channel_init(ispsoftc_t *, int);
107 static void isp_fibre_init(ispsoftc_t *);
108 static void isp_fibre_init_2400(ispsoftc_t *);
109 static void isp_clear_portdb(ispsoftc_t *, int);
110 static void isp_mark_portdb(ispsoftc_t *, int);
111 static int isp_plogx(ispsoftc_t *, int, uint16_t, uint32_t, int);
112 static int isp_port_login(ispsoftc_t *, uint16_t, uint32_t);
113 static int isp_port_logout(ispsoftc_t *, uint16_t, uint32_t);
114 static int isp_getpdb(ispsoftc_t *, int, uint16_t, isp_pdb_t *);
115 static int isp_gethandles(ispsoftc_t *, int, uint16_t *, int *, int);
116 static void isp_dump_chip_portdb(ispsoftc_t *, int);
117 static uint64_t isp_get_wwn(ispsoftc_t *, int, int, int);
118 static int isp_fclink_test(ispsoftc_t *, int, int);
119 static int isp_pdb_sync(ispsoftc_t *, int);
120 static int isp_scan_loop(ispsoftc_t *, int);
121 static int isp_gid_ft_sns(ispsoftc_t *, int);
122 static int isp_gid_ft_ct_passthru(ispsoftc_t *, int);
123 static int isp_scan_fabric(ispsoftc_t *, int);
124 static int isp_login_device(ispsoftc_t *, int, uint32_t, isp_pdb_t *, uint16_t *);
125 static int isp_send_change_request(ispsoftc_t *, int);
126 static int isp_register_fc4_type(ispsoftc_t *, int);
127 static int isp_register_fc4_type_24xx(ispsoftc_t *, int);
128 static int isp_register_fc4_features_24xx(ispsoftc_t *, int);
129 static int isp_register_port_name_24xx(ispsoftc_t *, int);
130 static int isp_register_node_name_24xx(ispsoftc_t *, int);
131 static uint16_t isp_next_handle(ispsoftc_t *, uint16_t *);
132 static int isp_fw_state(ispsoftc_t *, int);
133 static void isp_mboxcmd_qnw(ispsoftc_t *, mbreg_t *, int);
134 static void isp_mboxcmd(ispsoftc_t *, mbreg_t *);
135 
136 static void isp_spi_update(ispsoftc_t *, int);
137 static void isp_setdfltsdparm(ispsoftc_t *);
138 static void isp_setdfltfcparm(ispsoftc_t *, int);
139 static int isp_read_nvram(ispsoftc_t *, int);
140 static int isp_read_nvram_2400(ispsoftc_t *, uint8_t *);
141 static void isp_rdnvram_word(ispsoftc_t *, int, uint16_t *);
142 static void isp_rd_2400_nvram(ispsoftc_t *, uint32_t, uint32_t *);
143 static void isp_parse_nvram_1020(ispsoftc_t *, uint8_t *);
144 static void isp_parse_nvram_1080(ispsoftc_t *, int, uint8_t *);
145 static void isp_parse_nvram_12160(ispsoftc_t *, int, uint8_t *);
146 static void isp_parse_nvram_2100(ispsoftc_t *, uint8_t *);
147 static void isp_parse_nvram_2400(ispsoftc_t *, uint8_t *);
148 
149 static void
150 isp_change_fw_state(ispsoftc_t *isp, int chan, int state)
151 {
152 	fcparam *fcp = FCPARAM(isp, chan);
153 
154 	if (fcp->isp_fwstate == state)
155 		return;
156 	isp_prt(isp, ISP_LOGCONFIG|ISP_LOG_SANCFG,
157 	    "Chan %d Firmware state <%s->%s>", chan,
158 	    isp_fc_fw_statename(fcp->isp_fwstate), isp_fc_fw_statename(state));
159 	fcp->isp_fwstate = state;
160 }
161 
162 /*
163  * Reset Hardware.
164  *
165  * Hit the chip over the head, download new f/w if available and set it running.
166  *
167  * Locking done elsewhere.
168  */
169 
170 void
171 isp_reset(ispsoftc_t *isp, int do_load_defaults)
172 {
173 	mbreg_t mbs;
174 	char *buf;
175 	uint64_t fwt;
176 	uint32_t code_org, val;
177 	int loops, i, dodnld = 1;
178 	const char *btype = "????";
179 	static const char dcrc[] = "Downloaded RISC Code Checksum Failure";
180 
181 	isp->isp_state = ISP_NILSTATE;
182 	if (isp->isp_dead) {
183 		isp_shutdown(isp);
184 		ISP_DISABLE_INTS(isp);
185 		return;
186 	}
187 
188 	/*
189 	 * Basic types (SCSI, FibreChannel and PCI or SBus)
190 	 * have been set in the MD code. We figure out more
191 	 * here. Possibly more refined types based upon PCI
192 	 * identification. Chip revision has been gathered.
193 	 *
194 	 * After we've fired this chip up, zero out the conf1 register
195 	 * for SCSI adapters and do other settings for the 2100.
196 	 */
197 
198 	ISP_DISABLE_INTS(isp);
199 
200 	/*
201 	 * Pick an initial maxcmds value which will be used
202 	 * to allocate xflist pointer space. It may be changed
203 	 * later by the firmware.
204 	 */
205 	if (IS_24XX(isp)) {
206 		isp->isp_maxcmds = 4096;
207 	} else if (IS_2322(isp)) {
208 		isp->isp_maxcmds = 2048;
209 	} else if (IS_23XX(isp) || IS_2200(isp)) {
210 		isp->isp_maxcmds = 1024;
211  	} else {
212 		isp->isp_maxcmds = 512;
213 	}
214 
215 	/*
216 	 * Set up DMA for the request and response queues.
217 	 *
218 	 * We do this now so we can use the request queue
219 	 * for dma to load firmware from.
220 	 */
221 	if (ISP_MBOXDMASETUP(isp) != 0) {
222 		isp_prt(isp, ISP_LOGERR, "Cannot setup DMA");
223 		return;
224 	}
225 
226 	/*
227 	 * Set up default request/response queue in-pointer/out-pointer
228 	 * register indices.
229 	 */
230 	if (IS_24XX(isp)) {
231 		isp->isp_rqstinrp = BIU2400_REQINP;
232 		isp->isp_rqstoutrp = BIU2400_REQOUTP;
233 		isp->isp_respinrp = BIU2400_RSPINP;
234 		isp->isp_respoutrp = BIU2400_RSPOUTP;
235 	} else if (IS_23XX(isp)) {
236 		isp->isp_rqstinrp = BIU_REQINP;
237 		isp->isp_rqstoutrp = BIU_REQOUTP;
238 		isp->isp_respinrp = BIU_RSPINP;
239 		isp->isp_respoutrp = BIU_RSPOUTP;
240 	} else {
241 		isp->isp_rqstinrp = INMAILBOX4;
242 		isp->isp_rqstoutrp = OUTMAILBOX4;
243 		isp->isp_respinrp = OUTMAILBOX5;
244 		isp->isp_respoutrp = INMAILBOX5;
245 	}
246 
247 	/*
248 	 * Put the board into PAUSE mode (so we can read the SXP registers
249 	 * or write FPM/FBM registers).
250 	 */
251 	if (IS_24XX(isp)) {
252 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_CLEAR_HOST_INT);
253 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_CLEAR_RISC_INT);
254 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_PAUSE);
255 	} else {
256 		ISP_WRITE(isp, HCCR, HCCR_CMD_PAUSE);
257 	}
258 
259 	if (IS_FC(isp)) {
260 		switch (isp->isp_type) {
261 		case ISP_HA_FC_2100:
262 			btype = "2100";
263 			break;
264 		case ISP_HA_FC_2200:
265 			btype = "2200";
266 			break;
267 		case ISP_HA_FC_2300:
268 			btype = "2300";
269 			break;
270 		case ISP_HA_FC_2312:
271 			btype = "2312";
272 			break;
273 		case ISP_HA_FC_2322:
274 			btype = "2322";
275 			break;
276 		case ISP_HA_FC_2400:
277 			btype = "2422";
278 			break;
279 		case ISP_HA_FC_2500:
280 			btype = "2532";
281 			break;
282 		case ISP_HA_FC_2600:
283 			btype = "2031";
284 			break;
285 		default:
286 			break;
287 		}
288 
289 		if (!IS_24XX(isp)) {
290 			/*
291 			 * While we're paused, reset the FPM module and FBM
292 			 * fifos.
293 			 */
294 			ISP_WRITE(isp, BIU2100_CSR, BIU2100_FPM0_REGS);
295 			ISP_WRITE(isp, FPM_DIAG_CONFIG, FPM_SOFT_RESET);
296 			ISP_WRITE(isp, BIU2100_CSR, BIU2100_FB_REGS);
297 			ISP_WRITE(isp, FBM_CMD, FBMCMD_FIFO_RESET_ALL);
298 			ISP_WRITE(isp, BIU2100_CSR, BIU2100_RISC_REGS);
299 		}
300 	} else if (IS_1240(isp)) {
301 		sdparam *sdp;
302 
303 		btype = "1240";
304 		isp->isp_clock = 60;
305 		sdp = SDPARAM(isp, 0);
306 		sdp->isp_ultramode = 1;
307 		sdp = SDPARAM(isp, 1);
308 		sdp->isp_ultramode = 1;
309 		/*
310 		 * XXX: Should probably do some bus sensing.
311 		 */
312 	} else if (IS_ULTRA3(isp)) {
313 		sdparam *sdp = isp->isp_param;
314 
315 		isp->isp_clock = 100;
316 
317 		if (IS_10160(isp))
318 			btype = "10160";
319 		else if (IS_12160(isp))
320 			btype = "12160";
321 		else
322 			btype = "<UNKLVD>";
323 		sdp->isp_lvdmode = 1;
324 
325 		if (IS_DUALBUS(isp)) {
326 			sdp++;
327 			sdp->isp_lvdmode = 1;
328 		}
329 	} else if (IS_ULTRA2(isp)) {
330 		static const char m[] = "bus %d is in %s Mode";
331 		uint16_t l;
332 		sdparam *sdp = SDPARAM(isp, 0);
333 
334 		isp->isp_clock = 100;
335 
336 		if (IS_1280(isp))
337 			btype = "1280";
338 		else if (IS_1080(isp))
339 			btype = "1080";
340 		else
341 			btype = "<UNKLVD>";
342 
343 		l = ISP_READ(isp, SXP_PINS_DIFF) & ISP1080_MODE_MASK;
344 		switch (l) {
345 		case ISP1080_LVD_MODE:
346 			sdp->isp_lvdmode = 1;
347 			isp_prt(isp, ISP_LOGCONFIG, m, 0, "LVD");
348 			break;
349 		case ISP1080_HVD_MODE:
350 			sdp->isp_diffmode = 1;
351 			isp_prt(isp, ISP_LOGCONFIG, m, 0, "Differential");
352 			break;
353 		case ISP1080_SE_MODE:
354 			sdp->isp_ultramode = 1;
355 			isp_prt(isp, ISP_LOGCONFIG, m, 0, "Single-Ended");
356 			break;
357 		default:
358 			isp_prt(isp, ISP_LOGERR,
359 			    "unknown mode on bus %d (0x%x)", 0, l);
360 			break;
361 		}
362 
363 		if (IS_DUALBUS(isp)) {
364 			sdp = SDPARAM(isp, 1);
365 			l = ISP_READ(isp, SXP_PINS_DIFF|SXP_BANK1_SELECT);
366 			l &= ISP1080_MODE_MASK;
367 			switch (l) {
368 			case ISP1080_LVD_MODE:
369 				sdp->isp_lvdmode = 1;
370 				isp_prt(isp, ISP_LOGCONFIG, m, 1, "LVD");
371 				break;
372 			case ISP1080_HVD_MODE:
373 				sdp->isp_diffmode = 1;
374 				isp_prt(isp, ISP_LOGCONFIG,
375 				    m, 1, "Differential");
376 				break;
377 			case ISP1080_SE_MODE:
378 				sdp->isp_ultramode = 1;
379 				isp_prt(isp, ISP_LOGCONFIG,
380 				    m, 1, "Single-Ended");
381 				break;
382 			default:
383 				isp_prt(isp, ISP_LOGERR,
384 				    "unknown mode on bus %d (0x%x)", 1, l);
385 				break;
386 			}
387 		}
388 	} else {
389 		sdparam *sdp = SDPARAM(isp, 0);
390 		i = ISP_READ(isp, BIU_CONF0) & BIU_CONF0_HW_MASK;
391 		switch (i) {
392 		default:
393 			isp_prt(isp, ISP_LOGALL, "Unknown Chip Type 0x%x", i);
394 			/* FALLTHROUGH */
395 		case 1:
396 			btype = "1020";
397 			isp->isp_type = ISP_HA_SCSI_1020;
398 			isp->isp_clock = 40;
399 			break;
400 		case 2:
401 			/*
402 			 * Some 1020A chips are Ultra Capable, but don't
403 			 * run the clock rate up for that unless told to
404 			 * do so by the Ultra Capable bits being set.
405 			 */
406 			btype = "1020A";
407 			isp->isp_type = ISP_HA_SCSI_1020A;
408 			isp->isp_clock = 40;
409 			break;
410 		case 3:
411 			btype = "1040";
412 			isp->isp_type = ISP_HA_SCSI_1040;
413 			isp->isp_clock = 60;
414 			break;
415 		case 4:
416 			btype = "1040A";
417 			isp->isp_type = ISP_HA_SCSI_1040A;
418 			isp->isp_clock = 60;
419 			break;
420 		case 5:
421 			btype = "1040B";
422 			isp->isp_type = ISP_HA_SCSI_1040B;
423 			isp->isp_clock = 60;
424 			break;
425 		case 6:
426 			btype = "1040C";
427 			isp->isp_type = ISP_HA_SCSI_1040C;
428 			isp->isp_clock = 60;
429                         break;
430 		}
431 		/*
432 		 * Now, while we're at it, gather info about ultra
433 		 * and/or differential mode.
434 		 */
435 		if (ISP_READ(isp, SXP_PINS_DIFF) & SXP_PINS_DIFF_MODE) {
436 			isp_prt(isp, ISP_LOGCONFIG, "Differential Mode");
437 			sdp->isp_diffmode = 1;
438 		} else {
439 			sdp->isp_diffmode = 0;
440 		}
441 		i = ISP_READ(isp, RISC_PSR);
442 		if (isp->isp_bustype == ISP_BT_SBUS) {
443 			i &= RISC_PSR_SBUS_ULTRA;
444 		} else {
445 			i &= RISC_PSR_PCI_ULTRA;
446 		}
447 		if (i != 0) {
448 			isp_prt(isp, ISP_LOGCONFIG, "Ultra Mode Capable");
449 			sdp->isp_ultramode = 1;
450 			/*
451 			 * If we're in Ultra Mode, we have to be 60MHz clock-
452 			 * even for the SBus version.
453 			 */
454 			isp->isp_clock = 60;
455 		} else {
456 			sdp->isp_ultramode = 0;
457 			/*
458 			 * Clock is known. Gronk.
459 			 */
460 		}
461 
462 		/*
463 		 * Machine dependent clock (if set) overrides
464 		 * our generic determinations.
465 		 */
466 		if (isp->isp_mdvec->dv_clock) {
467 			if (isp->isp_mdvec->dv_clock < isp->isp_clock) {
468 				isp->isp_clock = isp->isp_mdvec->dv_clock;
469 			}
470 		}
471 
472 	}
473 
474 	/*
475 	 * Clear instrumentation
476 	 */
477 	isp->isp_intcnt = isp->isp_intbogus = 0;
478 
479 	/*
480 	 * Do MD specific pre initialization
481 	 */
482 	ISP_RESET0(isp);
483 
484 	/*
485 	 * Hit the chip over the head with hammer,
486 	 * and give it a chance to recover.
487 	 */
488 
489 	if (IS_SCSI(isp)) {
490 		ISP_WRITE(isp, BIU_ICR, BIU_ICR_SOFT_RESET);
491 		/*
492 		 * A slight delay...
493 		 */
494 		ISP_DELAY(100);
495 
496 		/*
497 		 * Clear data && control DMA engines.
498 		 */
499 		ISP_WRITE(isp, CDMA_CONTROL, DMA_CNTRL_CLEAR_CHAN | DMA_CNTRL_RESET_INT);
500 		ISP_WRITE(isp, DDMA_CONTROL, DMA_CNTRL_CLEAR_CHAN | DMA_CNTRL_RESET_INT);
501 
502 
503 	} else if (IS_24XX(isp)) {
504 		/*
505 		 * Stop DMA and wait for it to stop.
506 		 */
507 		ISP_WRITE(isp, BIU2400_CSR, BIU2400_DMA_STOP|(3 << 4));
508 		for (val = loops = 0; loops < 30000; loops++) {
509 			ISP_DELAY(10);
510 			val = ISP_READ(isp, BIU2400_CSR);
511 			if ((val & BIU2400_DMA_ACTIVE) == 0) {
512 				break;
513 			}
514 		}
515 		if (val & BIU2400_DMA_ACTIVE) {
516 			ISP_RESET0(isp);
517 			isp_prt(isp, ISP_LOGERR, "DMA Failed to Stop on Reset");
518 			return;
519 		}
520 		/*
521 		 * Hold it in SOFT_RESET and STOP state for 100us.
522 		 */
523 		ISP_WRITE(isp, BIU2400_CSR, BIU2400_SOFT_RESET|BIU2400_DMA_STOP|(3 << 4));
524 		ISP_DELAY(100);
525 		for (loops = 0; loops < 10000; loops++) {
526 			ISP_DELAY(5);
527 			val = ISP_READ(isp, OUTMAILBOX0);
528 		}
529 		for (val = loops = 0; loops < 500000; loops ++) {
530 			val = ISP_READ(isp, BIU2400_CSR);
531 			if ((val & BIU2400_SOFT_RESET) == 0) {
532 				break;
533 			}
534 		}
535 		if (val & BIU2400_SOFT_RESET) {
536 			ISP_RESET0(isp);
537 			isp_prt(isp, ISP_LOGERR, "Failed to come out of reset");
538 			return;
539 		}
540 	} else {
541 		ISP_WRITE(isp, BIU2100_CSR, BIU2100_SOFT_RESET);
542 		/*
543 		 * A slight delay...
544 		 */
545 		ISP_DELAY(100);
546 
547 		/*
548 		 * Clear data && control DMA engines.
549 		 */
550 		ISP_WRITE(isp, CDMA2100_CONTROL, DMA_CNTRL2100_CLEAR_CHAN | DMA_CNTRL2100_RESET_INT);
551 		ISP_WRITE(isp, TDMA2100_CONTROL, DMA_CNTRL2100_CLEAR_CHAN | DMA_CNTRL2100_RESET_INT);
552 		ISP_WRITE(isp, RDMA2100_CONTROL, DMA_CNTRL2100_CLEAR_CHAN | DMA_CNTRL2100_RESET_INT);
553 	}
554 
555 	/*
556 	 * Wait for ISP to be ready to go...
557 	 */
558 	loops = MBOX_DELAY_COUNT;
559 	for (;;) {
560 		if (IS_SCSI(isp)) {
561 			if (!(ISP_READ(isp, BIU_ICR) & BIU_ICR_SOFT_RESET)) {
562 				break;
563 			}
564 		} else if (IS_24XX(isp)) {
565 			if (ISP_READ(isp, OUTMAILBOX0) == 0) {
566 				break;
567 			}
568 		} else {
569 			if (!(ISP_READ(isp, BIU2100_CSR) & BIU2100_SOFT_RESET))
570 				break;
571 		}
572 		ISP_DELAY(100);
573 		if (--loops < 0) {
574 			ISP_DUMPREGS(isp, "chip reset timed out");
575 			ISP_RESET0(isp);
576 			return;
577 		}
578 	}
579 
580 	/*
581 	 * After we've fired this chip up, zero out the conf1 register
582 	 * for SCSI adapters and other settings for the 2100.
583 	 */
584 
585 	if (IS_SCSI(isp)) {
586 		ISP_WRITE(isp, BIU_CONF1, 0);
587 	} else if (!IS_24XX(isp)) {
588 		ISP_WRITE(isp, BIU2100_CSR, 0);
589 	}
590 
591 	/*
592 	 * Reset RISC Processor
593 	 */
594 	if (IS_24XX(isp)) {
595 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_RESET);
596 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_RELEASE);
597 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_CLEAR_RESET);
598 	} else {
599 		ISP_WRITE(isp, HCCR, HCCR_CMD_RESET);
600 		ISP_DELAY(100);
601 		ISP_WRITE(isp, BIU_SEMA, 0);
602 	}
603 
604 	/*
605 	 * Post-RISC Reset stuff.
606 	 */
607 	if (IS_24XX(isp)) {
608 		for (val = loops = 0; loops < 5000000; loops++) {
609 			ISP_DELAY(5);
610 			val = ISP_READ(isp, OUTMAILBOX0);
611 			if (val == 0) {
612 				break;
613 			}
614 		}
615 		if (val != 0) {
616 			ISP_RESET0(isp);
617 			isp_prt(isp, ISP_LOGERR, "reset didn't clear");
618 			return;
619 		}
620 	} else if (IS_SCSI(isp)) {
621 		uint16_t tmp = isp->isp_mdvec->dv_conf1;
622 		/*
623 		 * Busted FIFO. Turn off all but burst enables.
624 		 */
625 		if (isp->isp_type == ISP_HA_SCSI_1040A) {
626 			tmp &= BIU_BURST_ENABLE;
627 		}
628 		ISP_SETBITS(isp, BIU_CONF1, tmp);
629 		if (tmp & BIU_BURST_ENABLE) {
630 			ISP_SETBITS(isp, CDMA_CONF, DMA_ENABLE_BURST);
631 			ISP_SETBITS(isp, DDMA_CONF, DMA_ENABLE_BURST);
632 		}
633 		if (SDPARAM(isp, 0)->isp_ptisp) {
634 			if (SDPARAM(isp, 0)->isp_ultramode) {
635 				while (ISP_READ(isp, RISC_MTR) != 0x1313) {
636 					ISP_WRITE(isp, RISC_MTR, 0x1313);
637 					ISP_WRITE(isp, HCCR, HCCR_CMD_STEP);
638 				}
639 			} else {
640 				ISP_WRITE(isp, RISC_MTR, 0x1212);
641 			}
642 			/*
643 			 * PTI specific register
644 			 */
645 			ISP_WRITE(isp, RISC_EMB, DUAL_BANK);
646 		} else {
647 			ISP_WRITE(isp, RISC_MTR, 0x1212);
648 		}
649 		ISP_WRITE(isp, HCCR, HCCR_CMD_RELEASE);
650 	} else {
651 		ISP_WRITE(isp, RISC_MTR2100, 0x1212);
652 		if (IS_2200(isp) || IS_23XX(isp)) {
653 			ISP_WRITE(isp, HCCR, HCCR_2X00_DISABLE_PARITY_PAUSE);
654 		}
655 		ISP_WRITE(isp, HCCR, HCCR_CMD_RELEASE);
656 	}
657 
658 	ISP_WRITE(isp, isp->isp_rqstinrp, 0);
659 	ISP_WRITE(isp, isp->isp_rqstoutrp, 0);
660 	ISP_WRITE(isp, isp->isp_respinrp, 0);
661 	ISP_WRITE(isp, isp->isp_respoutrp, 0);
662 	if (IS_24XX(isp)) {
663 		if (!IS_26XX(isp)) {
664 			ISP_WRITE(isp, BIU2400_PRI_REQINP, 0);
665 			ISP_WRITE(isp, BIU2400_PRI_REQOUTP, 0);
666 		}
667 		ISP_WRITE(isp, BIU2400_ATIO_RSPINP, 0);
668 		ISP_WRITE(isp, BIU2400_ATIO_RSPOUTP, 0);
669 	}
670 
671 	/*
672 	 * Do MD specific post initialization
673 	 */
674 	ISP_RESET1(isp);
675 
676 	/*
677 	 * Wait for everything to finish firing up.
678 	 *
679 	 * Avoid doing this on early 2312s because you can generate a PCI
680 	 * parity error (chip breakage).
681 	 */
682 	if (IS_2312(isp) && isp->isp_revision < 2) {
683 		ISP_DELAY(100);
684 	} else {
685 		loops = MBOX_DELAY_COUNT;
686 		while (ISP_READ(isp, OUTMAILBOX0) == MBOX_BUSY) {
687 			ISP_DELAY(100);
688 			if (--loops < 0) {
689 				ISP_RESET0(isp);
690 				isp_prt(isp, ISP_LOGERR, "MBOX_BUSY never cleared on reset");
691 				return;
692 			}
693 		}
694 	}
695 
696 	/*
697 	 * Up until this point we've done everything by just reading or
698 	 * setting registers. From this point on we rely on at least *some*
699 	 * kind of firmware running in the card.
700 	 */
701 
702 	/*
703 	 * Do some sanity checking by running a NOP command.
704 	 * If it succeeds, the ROM firmware is now running.
705 	 */
706 	MBSINIT(&mbs, MBOX_NO_OP, MBLOGALL, 0);
707 	isp_mboxcmd(isp, &mbs);
708 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
709 		isp_prt(isp, ISP_LOGERR, "NOP command failed (%x)", mbs.param[0]);
710 		ISP_RESET0(isp);
711 		return;
712 	}
713 
714 	/*
715 	 * Do some operational tests
716 	 */
717 
718 	if (IS_SCSI(isp) || IS_24XX(isp)) {
719 		static const uint16_t patterns[MAX_MAILBOX] = {
720 			0x0000, 0xdead, 0xbeef, 0xffff,
721 			0xa5a5, 0x5a5a, 0x7f7f, 0x7ff7,
722 			0x3421, 0xabcd, 0xdcba, 0xfeef,
723 			0xbead, 0xdebe, 0x2222, 0x3333,
724 			0x5555, 0x6666, 0x7777, 0xaaaa,
725 			0xffff, 0xdddd, 0x9999, 0x1fbc,
726 			0x6666, 0x6677, 0x1122, 0x33ff,
727 			0x0000, 0x0001, 0x1000, 0x1010,
728 		};
729 		int nmbox = ISP_NMBOX(isp);
730 		if (IS_SCSI(isp))
731 			nmbox = 6;
732 		MBSINIT(&mbs, MBOX_MAILBOX_REG_TEST, MBLOGALL, 0);
733 		for (i = 1; i < nmbox; i++) {
734 			mbs.param[i] = patterns[i];
735 		}
736 		isp_mboxcmd(isp, &mbs);
737 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
738 			ISP_RESET0(isp);
739 			return;
740 		}
741 		for (i = 1; i < nmbox; i++) {
742 			if (mbs.param[i] != patterns[i]) {
743 				ISP_RESET0(isp);
744 				isp_prt(isp, ISP_LOGERR, "Register Test Failed at Register %d: should have 0x%04x but got 0x%04x", i, patterns[i], mbs.param[i]);
745 				return;
746 			}
747 		}
748 	}
749 
750 	/*
751 	 * Download new Firmware, unless requested not to do so.
752 	 * This is made slightly trickier in some cases where the
753 	 * firmware of the ROM revision is newer than the revision
754 	 * compiled into the driver. So, where we used to compare
755 	 * versions of our f/w and the ROM f/w, now we just see
756 	 * whether we have f/w at all and whether a config flag
757 	 * has disabled our download.
758 	 */
759 	if ((isp->isp_mdvec->dv_ispfw == NULL) || (isp->isp_confopts & ISP_CFG_NORELOAD)) {
760 		dodnld = 0;
761 	}
762 
763 	if (IS_24XX(isp)) {
764 		code_org = ISP_CODE_ORG_2400;
765 	} else if (IS_23XX(isp)) {
766 		code_org = ISP_CODE_ORG_2300;
767 	} else {
768 		code_org = ISP_CODE_ORG;
769 	}
770 
771 	isp->isp_loaded_fw = 0;
772 	if (dodnld && IS_24XX(isp)) {
773 		const uint32_t *ptr = isp->isp_mdvec->dv_ispfw;
774 		int wordload;
775 
776 		/*
777 		 * Keep loading until we run out of f/w.
778 		 */
779 		code_org = ptr[2];	/* 1st load address is our start addr */
780 		wordload = 0;
781 
782 		for (;;) {
783 			uint32_t la, wi, wl;
784 
785 			isp_prt(isp, ISP_LOGDEBUG0, "load 0x%x words of code at load address 0x%x", ptr[3], ptr[2]);
786 
787 			wi = 0;
788 			la = ptr[2];
789 			wl = ptr[3];
790 
791 			while (wi < ptr[3]) {
792 				uint32_t *cp;
793 				uint32_t nw;
794 
795 				nw = ISP_QUEUE_SIZE(RQUEST_QUEUE_LEN(isp)) >> 2;
796 				if (nw > wl) {
797 					nw = wl;
798 				}
799 				cp = isp->isp_rquest;
800 				for (i = 0; i < nw; i++) {
801 					ISP_IOXPUT_32(isp,  ptr[wi++], &cp[i]);
802 					wl--;
803 				}
804 				MEMORYBARRIER(isp, SYNC_REQUEST, 0, ISP_QUEUE_SIZE(RQUEST_QUEUE_LEN(isp)), -1);
805 	again:
806 				MBSINIT(&mbs, 0, MBLOGALL, 0);
807 				if (la < 0x10000 && nw < 0x10000) {
808 					mbs.param[0] = MBOX_LOAD_RISC_RAM_2100;
809 					mbs.param[1] = la;
810 					mbs.param[2] = DMA_WD1(isp->isp_rquest_dma);
811 					mbs.param[3] = DMA_WD0(isp->isp_rquest_dma);
812 					mbs.param[4] = nw;
813 					mbs.param[6] = DMA_WD3(isp->isp_rquest_dma);
814 					mbs.param[7] = DMA_WD2(isp->isp_rquest_dma);
815 					isp_prt(isp, ISP_LOGDEBUG0, "LOAD RISC RAM 2100 %u words at load address 0x%x", nw, la);
816 				} else if (wordload) {
817 					union {
818 						const uint32_t *cp;
819 						uint32_t *np;
820 					} ucd;
821 					ucd.cp = (const uint32_t *)cp;
822 					mbs.param[0] = MBOX_WRITE_RAM_WORD_EXTENDED;
823 					mbs.param[1] = la;
824 					mbs.param[2] = (*ucd.np);
825 					mbs.param[3] = (*ucd.np) >> 16;
826 					mbs.param[8] = la >> 16;
827 					isp->isp_mbxwrk0 = nw - 1;
828 					isp->isp_mbxworkp = ucd.np+1;
829 					isp->isp_mbxwrk1 = (la + 1);
830 					isp->isp_mbxwrk8 = (la + 1) >> 16;
831 					isp_prt(isp, ISP_LOGDEBUG0, "WRITE RAM WORD EXTENDED %u words at load address 0x%x", nw, la);
832 				} else {
833 					mbs.param[0] = MBOX_LOAD_RISC_RAM;
834 					mbs.param[1] = la;
835 					mbs.param[2] = DMA_WD1(isp->isp_rquest_dma);
836 					mbs.param[3] = DMA_WD0(isp->isp_rquest_dma);
837 					mbs.param[4] = nw >> 16;
838 					mbs.param[5] = nw;
839 					mbs.param[6] = DMA_WD3(isp->isp_rquest_dma);
840 					mbs.param[7] = DMA_WD2(isp->isp_rquest_dma);
841 					mbs.param[8] = la >> 16;
842 					isp_prt(isp, ISP_LOGDEBUG0, "LOAD RISC RAM %u words at load address 0x%x", nw, la);
843 				}
844 				isp_mboxcmd(isp, &mbs);
845 				if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
846 					if (mbs.param[0] == MBOX_HOST_INTERFACE_ERROR) {
847 						isp_prt(isp, ISP_LOGERR, "switching to word load");
848 						wordload = 1;
849 						goto again;
850 					}
851 					isp_prt(isp, ISP_LOGERR, "F/W Risc Ram Load Failed");
852 					ISP_RESET0(isp);
853 					return;
854 				}
855 				la += nw;
856 			}
857 
858 			if (ptr[1] == 0) {
859 				break;
860 			}
861 			ptr += ptr[3];
862 		}
863 		isp->isp_loaded_fw = 1;
864 	} else if (dodnld && IS_23XX(isp)) {
865 		const uint16_t *ptr = isp->isp_mdvec->dv_ispfw;
866 		uint16_t wi, wl, segno;
867 		uint32_t la;
868 
869 		la = code_org;
870 		segno = 0;
871 
872 		for (;;) {
873 			uint32_t nxtaddr;
874 
875 			isp_prt(isp, ISP_LOGDEBUG0, "load 0x%x words of code at load address 0x%x", ptr[3], la);
876 
877 			wi = 0;
878 			wl = ptr[3];
879 
880 			while (wi < ptr[3]) {
881 				uint16_t *cp;
882 				uint16_t nw;
883 
884 				nw = ISP_QUEUE_SIZE(RQUEST_QUEUE_LEN(isp)) >> 1;
885 				if (nw > wl) {
886 					nw = wl;
887 				}
888 				if (nw > (1 << 15)) {
889 					nw = 1 << 15;
890 				}
891 				cp = isp->isp_rquest;
892 				for (i = 0; i < nw; i++) {
893 					ISP_IOXPUT_16(isp,  ptr[wi++], &cp[i]);
894 					wl--;
895 				}
896 				MEMORYBARRIER(isp, SYNC_REQUEST, 0, ISP_QUEUE_SIZE(RQUEST_QUEUE_LEN(isp)), -1);
897 				MBSINIT(&mbs, 0, MBLOGALL, 0);
898 				if (la < 0x10000) {
899 					mbs.param[0] = MBOX_LOAD_RISC_RAM_2100;
900 					mbs.param[1] = la;
901 					mbs.param[2] = DMA_WD1(isp->isp_rquest_dma);
902 					mbs.param[3] = DMA_WD0(isp->isp_rquest_dma);
903 					mbs.param[4] = nw;
904 					mbs.param[6] = DMA_WD3(isp->isp_rquest_dma);
905 					mbs.param[7] = DMA_WD2(isp->isp_rquest_dma);
906 					isp_prt(isp, ISP_LOGDEBUG1, "LOAD RISC RAM 2100 %u words at load address 0x%x\n", nw, la);
907 				} else {
908 					mbs.param[0] = MBOX_LOAD_RISC_RAM;
909 					mbs.param[1] = la;
910 					mbs.param[2] = DMA_WD1(isp->isp_rquest_dma);
911 					mbs.param[3] = DMA_WD0(isp->isp_rquest_dma);
912 					mbs.param[4] = nw;
913 					mbs.param[6] = DMA_WD3(isp->isp_rquest_dma);
914 					mbs.param[7] = DMA_WD2(isp->isp_rquest_dma);
915 					mbs.param[8] = la >> 16;
916 					isp_prt(isp, ISP_LOGDEBUG1, "LOAD RISC RAM %u words at load address 0x%x\n", nw, la);
917 				}
918 				isp_mboxcmd(isp, &mbs);
919 				if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
920 					isp_prt(isp, ISP_LOGERR, "F/W Risc Ram Load Failed");
921 					ISP_RESET0(isp);
922 					return;
923 				}
924 				la += nw;
925 			}
926 
927 			if (!IS_2322(isp)) {
928 				break;
929 			}
930 
931 			if (++segno == 3) {
932 				break;
933 			}
934 
935 			/*
936 			 * If we're a 2322, the firmware actually comes in
937 			 * three chunks. We loaded the first at the code_org
938 			 * address. The other two chunks, which follow right
939 			 * after each other in memory here, get loaded at
940 			 * addresses specfied at offset 0x9..0xB.
941 			 */
942 
943 			nxtaddr = ptr[3];
944 			ptr = &ptr[nxtaddr];
945 			la = ptr[5] | ((ptr[4] & 0x3f) << 16);
946 		}
947 		isp->isp_loaded_fw = 1;
948 	} else if (dodnld) {
949 		union {
950 			const uint16_t *cp;
951 			uint16_t *np;
952 		} ucd;
953 		ucd.cp = isp->isp_mdvec->dv_ispfw;
954 		isp->isp_mbxworkp = &ucd.np[1];
955 		isp->isp_mbxwrk0 = ucd.np[3] - 1;
956 		isp->isp_mbxwrk1 = code_org + 1;
957 		MBSINIT(&mbs, MBOX_WRITE_RAM_WORD, MBLOGNONE, 0);
958 		mbs.param[1] = code_org;
959 		mbs.param[2] = ucd.np[0];
960 		isp_prt(isp, ISP_LOGDEBUG1, "WRITE RAM %u words at load address 0x%x", ucd.np[3], code_org);
961 		isp_mboxcmd(isp, &mbs);
962 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
963 			isp_prt(isp, ISP_LOGERR, "F/W download failed at word %d", isp->isp_mbxwrk1 - code_org);
964 			ISP_RESET0(isp);
965 			return;
966 		}
967 	} else if (IS_26XX(isp)) {
968 		MBSINIT(&mbs, MBOX_LOAD_FLASH_FIRMWARE, MBLOGALL, 5000000);
969 		mbs.ibitm = 0x01;
970 		mbs.obitm = 0x07;
971 		isp_mboxcmd(isp, &mbs);
972 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
973 			isp_prt(isp, ISP_LOGERR, "Flash F/W load failed");
974 			ISP_RESET0(isp);
975 			return;
976 		}
977 	} else {
978 		isp_prt(isp, ISP_LOGDEBUG2, "skipping f/w download");
979 	}
980 
981 	/*
982 	 * If we loaded firmware, verify its checksum
983 	 */
984 	if (isp->isp_loaded_fw) {
985 		MBSINIT(&mbs, MBOX_VERIFY_CHECKSUM, MBLOGNONE, 0);
986 		if (IS_24XX(isp)) {
987 			mbs.param[1] = code_org >> 16;
988 			mbs.param[2] = code_org;
989 		} else {
990 			mbs.param[1] = code_org;
991 		}
992 		isp_mboxcmd(isp, &mbs);
993 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
994 			isp_prt(isp, ISP_LOGERR, dcrc);
995 			ISP_RESET0(isp);
996 			return;
997 		}
998 	}
999 
1000 	/*
1001 	 * Now start it rolling.
1002 	 *
1003 	 * If we didn't actually download f/w,
1004 	 * we still need to (re)start it.
1005 	 */
1006 
1007 
1008 	MBSINIT(&mbs, MBOX_EXEC_FIRMWARE, MBLOGALL, 5000000);
1009 	if (IS_24XX(isp)) {
1010 		mbs.param[1] = code_org >> 16;
1011 		mbs.param[2] = code_org;
1012 		if (isp->isp_loaded_fw) {
1013 			mbs.param[3] = 0;
1014 		} else {
1015 			mbs.param[3] = 1;
1016 		}
1017 	} else if (IS_2322(isp)) {
1018 		mbs.param[1] = code_org;
1019 		if (isp->isp_loaded_fw) {
1020 			mbs.param[2] = 0;
1021 		} else {
1022 			mbs.param[2] = 1;
1023 		}
1024 	} else {
1025 		mbs.param[1] = code_org;
1026 	}
1027 	isp_mboxcmd(isp, &mbs);
1028 	if (IS_2322(isp) || IS_24XX(isp)) {
1029 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1030 			ISP_RESET0(isp);
1031 			return;
1032 		}
1033 	}
1034 
1035 	if (IS_SCSI(isp)) {
1036 		/*
1037 		 * Set CLOCK RATE, but only if asked to.
1038 		 */
1039 		if (isp->isp_clock) {
1040 			MBSINIT(&mbs, MBOX_SET_CLOCK_RATE, MBLOGALL, 0);
1041 			mbs.param[1] = isp->isp_clock;
1042 			isp_mboxcmd(isp, &mbs);
1043 			/* we will try not to care if this fails */
1044 		}
1045 	}
1046 
1047 	/*
1048 	 * Ask the chip for the current firmware version.
1049 	 * This should prove that the new firmware is working.
1050 	 */
1051 	MBSINIT(&mbs, MBOX_ABOUT_FIRMWARE, MBLOGALL, 0);
1052 	isp_mboxcmd(isp, &mbs);
1053 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1054 		ISP_RESET0(isp);
1055 		return;
1056 	}
1057 
1058 	/*
1059 	 * The SBus firmware that we are using apparently does not return
1060 	 * major, minor, micro revisions in the mailbox registers, which
1061 	 * is really, really, annoying.
1062 	 */
1063 	if (ISP_SBUS_SUPPORTED && isp->isp_bustype == ISP_BT_SBUS) {
1064 		if (dodnld) {
1065 #ifdef	ISP_TARGET_MODE
1066 			isp->isp_fwrev[0] = 7;
1067 			isp->isp_fwrev[1] = 55;
1068 #else
1069 			isp->isp_fwrev[0] = 1;
1070 			isp->isp_fwrev[1] = 37;
1071 #endif
1072 			isp->isp_fwrev[2] = 0;
1073 		}
1074 	} else {
1075 		isp->isp_fwrev[0] = mbs.param[1];
1076 		isp->isp_fwrev[1] = mbs.param[2];
1077 		isp->isp_fwrev[2] = mbs.param[3];
1078 	}
1079 
1080 	if (IS_FC(isp)) {
1081 		/*
1082 		 * We do not believe firmware attributes for 2100 code less
1083 		 * than 1.17.0, unless it's the firmware we specifically
1084 		 * are loading.
1085 		 *
1086 		 * Note that all 22XX and later f/w is greater than 1.X.0.
1087 		 */
1088 		if ((ISP_FW_OLDER_THAN(isp, 1, 17, 1))) {
1089 #ifdef	USE_SMALLER_2100_FIRMWARE
1090 			isp->isp_fwattr = ISP_FW_ATTR_SCCLUN;
1091 #else
1092 			isp->isp_fwattr = 0;
1093 #endif
1094 		} else {
1095 			isp->isp_fwattr = mbs.param[6];
1096 		}
1097 		if (IS_24XX(isp)) {
1098 			isp->isp_fwattr |= ((uint64_t) mbs.param[15]) << 16;
1099 			if (isp->isp_fwattr & ISP2400_FW_ATTR_EXTNDED) {
1100 				isp->isp_fwattr |=
1101 				    (((uint64_t) mbs.param[16]) << 32) |
1102 				    (((uint64_t) mbs.param[17]) << 48);
1103 			}
1104 		}
1105 	} else {
1106 		isp->isp_fwattr = 0;
1107 	}
1108 
1109 	isp_prt(isp, ISP_LOGCONFIG, "Board Type %s, Chip Revision 0x%x, %s F/W Revision %d.%d.%d",
1110 	    btype, isp->isp_revision, dodnld? "loaded" : "resident", isp->isp_fwrev[0], isp->isp_fwrev[1], isp->isp_fwrev[2]);
1111 
1112 	fwt = isp->isp_fwattr;
1113 	if (IS_24XX(isp)) {
1114 		buf = FCPARAM(isp, 0)->isp_scratch;
1115 		ISP_SNPRINTF(buf, ISP_FC_SCRLEN, "Attributes:");
1116 		if (fwt & ISP2400_FW_ATTR_CLASS2) {
1117 			fwt ^=ISP2400_FW_ATTR_CLASS2;
1118 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s Class2", buf);
1119 		}
1120 		if (fwt & ISP2400_FW_ATTR_IP) {
1121 			fwt ^=ISP2400_FW_ATTR_IP;
1122 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s IP", buf);
1123 		}
1124 		if (fwt & ISP2400_FW_ATTR_MULTIID) {
1125 			fwt ^=ISP2400_FW_ATTR_MULTIID;
1126 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s MultiID", buf);
1127 		}
1128 		if (fwt & ISP2400_FW_ATTR_SB2) {
1129 			fwt ^=ISP2400_FW_ATTR_SB2;
1130 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s SB2", buf);
1131 		}
1132 		if (fwt & ISP2400_FW_ATTR_T10CRC) {
1133 			fwt ^=ISP2400_FW_ATTR_T10CRC;
1134 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s T10CRC", buf);
1135 		}
1136 		if (fwt & ISP2400_FW_ATTR_VI) {
1137 			fwt ^=ISP2400_FW_ATTR_VI;
1138 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s VI", buf);
1139 		}
1140 		if (fwt & ISP2400_FW_ATTR_MQ) {
1141 			fwt ^=ISP2400_FW_ATTR_MQ;
1142 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s MQ", buf);
1143 		}
1144 		if (fwt & ISP2400_FW_ATTR_MSIX) {
1145 			fwt ^=ISP2400_FW_ATTR_MSIX;
1146 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s MSIX", buf);
1147 		}
1148 		if (fwt & ISP2400_FW_ATTR_FCOE) {
1149 			fwt ^=ISP2400_FW_ATTR_FCOE;
1150 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s FCOE", buf);
1151 		}
1152 		if (fwt & ISP2400_FW_ATTR_VP0) {
1153 			fwt ^= ISP2400_FW_ATTR_VP0;
1154 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s VP0_Decoupling", buf);
1155 		}
1156 		if (fwt & ISP2400_FW_ATTR_EXPFW) {
1157 			fwt ^= ISP2400_FW_ATTR_EXPFW;
1158 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s (Experimental)", buf);
1159 		}
1160 		if (fwt & ISP2400_FW_ATTR_HOTFW) {
1161 			fwt ^= ISP2400_FW_ATTR_HOTFW;
1162 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s HotFW", buf);
1163 		}
1164 		fwt &= ~ISP2400_FW_ATTR_EXTNDED;
1165 		if (fwt & ISP2400_FW_ATTR_EXTVP) {
1166 			fwt ^= ISP2400_FW_ATTR_EXTVP;
1167 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s ExtVP", buf);
1168 		}
1169 		if (fwt & ISP2400_FW_ATTR_VN2VN) {
1170 			fwt ^= ISP2400_FW_ATTR_VN2VN;
1171 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s VN2VN", buf);
1172 		}
1173 		if (fwt & ISP2400_FW_ATTR_EXMOFF) {
1174 			fwt ^= ISP2400_FW_ATTR_EXMOFF;
1175 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s EXMOFF", buf);
1176 		}
1177 		if (fwt & ISP2400_FW_ATTR_NPMOFF) {
1178 			fwt ^= ISP2400_FW_ATTR_NPMOFF;
1179 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s NPMOFF", buf);
1180 		}
1181 		if (fwt & ISP2400_FW_ATTR_DIFCHOP) {
1182 			fwt ^= ISP2400_FW_ATTR_DIFCHOP;
1183 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s DIFCHOP", buf);
1184 		}
1185 		if (fwt & ISP2400_FW_ATTR_SRIOV) {
1186 			fwt ^= ISP2400_FW_ATTR_SRIOV;
1187 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s SRIOV", buf);
1188 		}
1189 		if (fwt & ISP2400_FW_ATTR_ASICTMP) {
1190 			fwt ^= ISP2400_FW_ATTR_ASICTMP;
1191 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s ASICTMP", buf);
1192 		}
1193 		if (fwt & ISP2400_FW_ATTR_ATIOMQ) {
1194 			fwt ^= ISP2400_FW_ATTR_ATIOMQ;
1195 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s ATIOMQ", buf);
1196 		}
1197 		if (fwt) {
1198 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s (unknown 0x%08x%08x)", buf,
1199 			    (uint32_t) (fwt >> 32), (uint32_t) fwt);
1200 		}
1201 		isp_prt(isp, ISP_LOGCONFIG, "%s", buf);
1202 	} else if (IS_FC(isp)) {
1203 		buf = FCPARAM(isp, 0)->isp_scratch;
1204 		ISP_SNPRINTF(buf, ISP_FC_SCRLEN, "Attributes:");
1205 		if (fwt & ISP_FW_ATTR_TMODE) {
1206 			fwt ^=ISP_FW_ATTR_TMODE;
1207 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s TargetMode", buf);
1208 		}
1209 		if (fwt & ISP_FW_ATTR_SCCLUN) {
1210 			fwt ^=ISP_FW_ATTR_SCCLUN;
1211 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s SCC-Lun", buf);
1212 		}
1213 		if (fwt & ISP_FW_ATTR_FABRIC) {
1214 			fwt ^=ISP_FW_ATTR_FABRIC;
1215 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s Fabric", buf);
1216 		}
1217 		if (fwt & ISP_FW_ATTR_CLASS2) {
1218 			fwt ^=ISP_FW_ATTR_CLASS2;
1219 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s Class2", buf);
1220 		}
1221 		if (fwt & ISP_FW_ATTR_FCTAPE) {
1222 			fwt ^=ISP_FW_ATTR_FCTAPE;
1223 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s FC-Tape", buf);
1224 		}
1225 		if (fwt & ISP_FW_ATTR_IP) {
1226 			fwt ^=ISP_FW_ATTR_IP;
1227 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s IP", buf);
1228 		}
1229 		if (fwt & ISP_FW_ATTR_VI) {
1230 			fwt ^=ISP_FW_ATTR_VI;
1231 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s VI", buf);
1232 		}
1233 		if (fwt & ISP_FW_ATTR_VI_SOLARIS) {
1234 			fwt ^=ISP_FW_ATTR_VI_SOLARIS;
1235 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s VI_SOLARIS", buf);
1236 		}
1237 		if (fwt & ISP_FW_ATTR_2KLOGINS) {
1238 			fwt ^=ISP_FW_ATTR_2KLOGINS;
1239 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s 2K-Login", buf);
1240 		}
1241 		if (fwt != 0) {
1242 			ISP_SNPRINTF(buf, ISP_FC_SCRLEN - strlen(buf), "%s (unknown 0x%08x%08x)", buf,
1243 			    (uint32_t) (fwt >> 32), (uint32_t) fwt);
1244 		}
1245 		isp_prt(isp, ISP_LOGCONFIG, "%s", buf);
1246 	}
1247 
1248 	if (IS_24XX(isp)) {
1249 		MBSINIT(&mbs, MBOX_GET_RESOURCE_COUNT, MBLOGALL, 0);
1250 		isp_mboxcmd(isp, &mbs);
1251 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1252 			ISP_RESET0(isp);
1253 			return;
1254 		}
1255 		if (isp->isp_maxcmds >= mbs.param[3]) {
1256 			isp->isp_maxcmds = mbs.param[3];
1257 		}
1258 	} else {
1259 		MBSINIT(&mbs, MBOX_GET_FIRMWARE_STATUS, MBLOGALL, 0);
1260 		isp_mboxcmd(isp, &mbs);
1261 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1262 			ISP_RESET0(isp);
1263 			return;
1264 		}
1265 		if (isp->isp_maxcmds >= mbs.param[2]) {
1266 			isp->isp_maxcmds = mbs.param[2];
1267 		}
1268 	}
1269 	isp_prt(isp, ISP_LOGCONFIG, "%d max I/O command limit set", isp->isp_maxcmds);
1270 
1271 	/*
1272 	 * If we don't have Multi-ID f/w loaded, we need to restrict channels to one.
1273 	 * Only make this check for non-SCSI cards (I'm not sure firmware attributes
1274 	 * work for them).
1275 	 */
1276 	if (IS_FC(isp) && isp->isp_nchan > 1) {
1277 		if (!ISP_CAP_MULTI_ID(isp)) {
1278 			isp_prt(isp, ISP_LOGWARN, "non-MULTIID f/w loaded, "
1279 			    "only can enable 1 of %d channels", isp->isp_nchan);
1280 			isp->isp_nchan = 1;
1281 		} else if (!ISP_CAP_VP0(isp)) {
1282 			isp_prt(isp, ISP_LOGWARN, "We can not use MULTIID "
1283 			    "feature properly without VP0_Decoupling");
1284 			isp->isp_nchan = 1;
1285 		}
1286 	}
1287 	if (IS_FC(isp)) {
1288 		for (i = 0; i < isp->isp_nchan; i++)
1289 			isp_change_fw_state(isp, i, FW_CONFIG_WAIT);
1290 	}
1291 	if (isp->isp_dead) {
1292 		isp_shutdown(isp);
1293 		ISP_DISABLE_INTS(isp);
1294 		return;
1295 	}
1296 
1297 	isp->isp_state = ISP_RESETSTATE;
1298 
1299 	/*
1300 	 * Okay- now that we have new firmware running, we now (re)set our
1301 	 * notion of how many luns we support. This is somewhat tricky because
1302 	 * if we haven't loaded firmware, we sometimes do not have an easy way
1303 	 * of knowing how many luns we support.
1304 	 *
1305 	 * Expanded lun firmware gives you 32 luns for SCSI cards and
1306 	 * 16384 luns for Fibre Channel cards.
1307 	 *
1308 	 * It turns out that even for QLogic 2100s with ROM 1.10 and above
1309 	 * we do get a firmware attributes word returned in mailbox register 6.
1310 	 *
1311 	 * Because the lun is in a different position in the Request Queue
1312 	 * Entry structure for Fibre Channel with expanded lun firmware, we
1313 	 * can only support one lun (lun zero) when we don't know what kind
1314 	 * of firmware we're running.
1315 	 */
1316 	if (IS_SCSI(isp)) {
1317 		if (dodnld) {
1318 			if (IS_ULTRA2(isp) || IS_ULTRA3(isp)) {
1319 				isp->isp_maxluns = 32;
1320 			} else {
1321 				isp->isp_maxluns = 8;
1322 			}
1323 		} else {
1324 			isp->isp_maxluns = 8;
1325 		}
1326 	} else {
1327 		if (ISP_CAP_SCCFW(isp)) {
1328 			isp->isp_maxluns = 0;	/* No limit -- 2/8 bytes */
1329 		} else {
1330 			isp->isp_maxluns = 16;
1331 		}
1332 	}
1333 
1334 	/*
1335 	 * We get some default values established. As a side
1336 	 * effect, NVRAM is read here (unless overriden by
1337 	 * a configuration flag).
1338 	 */
1339 	if (do_load_defaults) {
1340 		if (IS_SCSI(isp)) {
1341 			isp_setdfltsdparm(isp);
1342 		} else {
1343 			for (i = 0; i < isp->isp_nchan; i++) {
1344 				isp_setdfltfcparm(isp, i);
1345 			}
1346 		}
1347 	}
1348 }
1349 
1350 /*
1351  * Clean firmware shutdown.
1352  */
1353 static int
1354 isp_deinit(ispsoftc_t *isp)
1355 {
1356 	mbreg_t mbs;
1357 
1358 	isp->isp_state = ISP_NILSTATE;
1359 	MBSINIT(&mbs, MBOX_STOP_FIRMWARE, MBLOGALL, 500000);
1360 	mbs.param[1] = 0;
1361 	mbs.param[2] = 0;
1362 	mbs.param[3] = 0;
1363 	mbs.param[4] = 0;
1364 	mbs.param[5] = 0;
1365 	mbs.param[6] = 0;
1366 	mbs.param[7] = 0;
1367 	mbs.param[8] = 0;
1368 	isp_mboxcmd(isp, &mbs);
1369 	return (mbs.param[0] == MBOX_COMMAND_COMPLETE ? 0 : mbs.param[0]);
1370 }
1371 
1372 /*
1373  * Initialize Parameters of Hardware to a known state.
1374  *
1375  * Locks are held before coming here.
1376  */
1377 void
1378 isp_init(ispsoftc_t *isp)
1379 {
1380 	if (IS_FC(isp)) {
1381 		if (IS_24XX(isp)) {
1382 			isp_fibre_init_2400(isp);
1383 		} else {
1384 			isp_fibre_init(isp);
1385 		}
1386 	} else {
1387 		isp_scsi_init(isp);
1388 	}
1389 	GET_NANOTIME(&isp->isp_init_time);
1390 }
1391 
1392 static void
1393 isp_scsi_init(ispsoftc_t *isp)
1394 {
1395 	sdparam *sdp_chan0, *sdp_chan1;
1396 	mbreg_t mbs;
1397 
1398 	isp->isp_state = ISP_INITSTATE;
1399 
1400 	sdp_chan0 = SDPARAM(isp, 0);
1401 	sdp_chan1 = sdp_chan0;
1402 	if (IS_DUALBUS(isp)) {
1403 		sdp_chan1 = SDPARAM(isp, 1);
1404 	}
1405 
1406 	/* First do overall per-card settings. */
1407 
1408 	/*
1409 	 * If we have fast memory timing enabled, turn it on.
1410 	 */
1411 	if (sdp_chan0->isp_fast_mttr) {
1412 		ISP_WRITE(isp, RISC_MTR, 0x1313);
1413 	}
1414 
1415 	/*
1416 	 * Set Retry Delay and Count.
1417 	 * You set both channels at the same time.
1418 	 */
1419 	MBSINIT(&mbs, MBOX_SET_RETRY_COUNT, MBLOGALL, 0);
1420 	mbs.param[1] = sdp_chan0->isp_retry_count;
1421 	mbs.param[2] = sdp_chan0->isp_retry_delay;
1422 	mbs.param[6] = sdp_chan1->isp_retry_count;
1423 	mbs.param[7] = sdp_chan1->isp_retry_delay;
1424 	isp_mboxcmd(isp, &mbs);
1425 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1426 		return;
1427 	}
1428 
1429 	/*
1430 	 * Set ASYNC DATA SETUP time. This is very important.
1431 	 */
1432 	MBSINIT(&mbs, MBOX_SET_ASYNC_DATA_SETUP_TIME, MBLOGALL, 0);
1433 	mbs.param[1] = sdp_chan0->isp_async_data_setup;
1434 	mbs.param[2] = sdp_chan1->isp_async_data_setup;
1435 	isp_mboxcmd(isp, &mbs);
1436 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1437 		return;
1438 	}
1439 
1440 	/*
1441 	 * Set ACTIVE Negation State.
1442 	 */
1443 	MBSINIT(&mbs, MBOX_SET_ACT_NEG_STATE, MBLOGNONE, 0);
1444 	mbs.param[1] =
1445 	    (sdp_chan0->isp_req_ack_active_neg << 4) |
1446 	    (sdp_chan0->isp_data_line_active_neg << 5);
1447 	mbs.param[2] =
1448 	    (sdp_chan1->isp_req_ack_active_neg << 4) |
1449 	    (sdp_chan1->isp_data_line_active_neg << 5);
1450 	isp_mboxcmd(isp, &mbs);
1451 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1452 		isp_prt(isp, ISP_LOGERR,
1453 		    "failed to set active negation state (%d,%d), (%d,%d)",
1454 		    sdp_chan0->isp_req_ack_active_neg,
1455 		    sdp_chan0->isp_data_line_active_neg,
1456 		    sdp_chan1->isp_req_ack_active_neg,
1457 		    sdp_chan1->isp_data_line_active_neg);
1458 		/*
1459 		 * But don't return.
1460 		 */
1461 	}
1462 
1463 	/*
1464 	 * Set the Tag Aging limit
1465 	 */
1466 	MBSINIT(&mbs, MBOX_SET_TAG_AGE_LIMIT, MBLOGALL, 0);
1467 	mbs.param[1] = sdp_chan0->isp_tag_aging;
1468 	mbs.param[2] = sdp_chan1->isp_tag_aging;
1469 	isp_mboxcmd(isp, &mbs);
1470 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1471 		isp_prt(isp, ISP_LOGERR, "failed to set tag age limit (%d,%d)",
1472 		    sdp_chan0->isp_tag_aging, sdp_chan1->isp_tag_aging);
1473 		return;
1474 	}
1475 
1476 	/*
1477 	 * Set selection timeout.
1478 	 */
1479 	MBSINIT(&mbs, MBOX_SET_SELECT_TIMEOUT, MBLOGALL, 0);
1480 	mbs.param[1] = sdp_chan0->isp_selection_timeout;
1481 	mbs.param[2] = sdp_chan1->isp_selection_timeout;
1482 	isp_mboxcmd(isp, &mbs);
1483 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1484 		return;
1485 	}
1486 
1487 	/* now do per-channel settings */
1488 	isp_scsi_channel_init(isp, 0);
1489 	if (IS_DUALBUS(isp))
1490 		isp_scsi_channel_init(isp, 1);
1491 
1492 	/*
1493 	 * Now enable request/response queues
1494 	 */
1495 
1496 	if (IS_ULTRA2(isp) || IS_1240(isp)) {
1497 		MBSINIT(&mbs, MBOX_INIT_RES_QUEUE_A64, MBLOGALL, 0);
1498 		mbs.param[1] = RESULT_QUEUE_LEN(isp);
1499 		mbs.param[2] = DMA_WD1(isp->isp_result_dma);
1500 		mbs.param[3] = DMA_WD0(isp->isp_result_dma);
1501 		mbs.param[4] = 0;
1502 		mbs.param[6] = DMA_WD3(isp->isp_result_dma);
1503 		mbs.param[7] = DMA_WD2(isp->isp_result_dma);
1504 		isp_mboxcmd(isp, &mbs);
1505 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1506 			return;
1507 		}
1508 		isp->isp_residx = isp->isp_resodx = mbs.param[5];
1509 
1510 		MBSINIT(&mbs, MBOX_INIT_REQ_QUEUE_A64, MBLOGALL, 0);
1511 		mbs.param[1] = RQUEST_QUEUE_LEN(isp);
1512 		mbs.param[2] = DMA_WD1(isp->isp_rquest_dma);
1513 		mbs.param[3] = DMA_WD0(isp->isp_rquest_dma);
1514 		mbs.param[5] = 0;
1515 		mbs.param[6] = DMA_WD3(isp->isp_result_dma);
1516 		mbs.param[7] = DMA_WD2(isp->isp_result_dma);
1517 		isp_mboxcmd(isp, &mbs);
1518 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1519 			return;
1520 		}
1521 		isp->isp_reqidx = isp->isp_reqodx = mbs.param[4];
1522 	} else {
1523 		MBSINIT(&mbs, MBOX_INIT_RES_QUEUE, MBLOGALL, 0);
1524 		mbs.param[1] = RESULT_QUEUE_LEN(isp);
1525 		mbs.param[2] = DMA_WD1(isp->isp_result_dma);
1526 		mbs.param[3] = DMA_WD0(isp->isp_result_dma);
1527 		mbs.param[4] = 0;
1528 		isp_mboxcmd(isp, &mbs);
1529 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1530 			return;
1531 		}
1532 		isp->isp_residx = isp->isp_resodx = mbs.param[5];
1533 
1534 		MBSINIT(&mbs, MBOX_INIT_REQ_QUEUE, MBLOGALL, 0);
1535 		mbs.param[1] = RQUEST_QUEUE_LEN(isp);
1536 		mbs.param[2] = DMA_WD1(isp->isp_rquest_dma);
1537 		mbs.param[3] = DMA_WD0(isp->isp_rquest_dma);
1538 		mbs.param[5] = 0;
1539 		isp_mboxcmd(isp, &mbs);
1540 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1541 			return;
1542 		}
1543 		isp->isp_reqidx = isp->isp_reqodx = mbs.param[4];
1544 	}
1545 
1546 	/*
1547 	 * Turn on LVD transitions for ULTRA2 or better and other features
1548 	 *
1549 	 * Now that we have 32 bit handles, don't do any fast posting
1550 	 * any more. For Ultra2/Ultra3 cards, we can turn on 32 bit RIO
1551 	 * operation or use fast posting. To be conservative, we'll only
1552 	 * do this for Ultra3 cards now because the other cards are so
1553 	 * rare for this author to find and test with.
1554 	 */
1555 
1556 	MBSINIT(&mbs, MBOX_SET_FW_FEATURES, MBLOGALL, 0);
1557 	if (IS_ULTRA2(isp))
1558 		mbs.param[1] |= FW_FEATURE_LVD_NOTIFY;
1559 #ifdef	ISP_NO_RIO
1560 	if (IS_ULTRA3(isp))
1561 		mbs.param[1] |= FW_FEATURE_FAST_POST;
1562 #else
1563 	if (IS_ULTRA3(isp))
1564 		mbs.param[1] |= FW_FEATURE_RIO_32BIT;
1565 #endif
1566 	if (mbs.param[1] != 0) {
1567 		uint16_t sfeat = mbs.param[1];
1568 		isp_mboxcmd(isp, &mbs);
1569 		if (mbs.param[0] == MBOX_COMMAND_COMPLETE) {
1570 			isp_prt(isp, ISP_LOGINFO,
1571 			    "Enabled FW features (0x%x)", sfeat);
1572 		}
1573 	}
1574 
1575 	isp->isp_state = ISP_RUNSTATE;
1576 }
1577 
1578 static void
1579 isp_scsi_channel_init(ispsoftc_t *isp, int chan)
1580 {
1581 	sdparam *sdp;
1582 	mbreg_t mbs;
1583 	int tgt;
1584 
1585 	sdp = SDPARAM(isp, chan);
1586 
1587 	/*
1588 	 * Set (possibly new) Initiator ID.
1589 	 */
1590 	MBSINIT(&mbs, MBOX_SET_INIT_SCSI_ID, MBLOGALL, 0);
1591 	mbs.param[1] = (chan << 7) | sdp->isp_initiator_id;
1592 	isp_mboxcmd(isp, &mbs);
1593 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1594 		return;
1595 	}
1596 	isp_prt(isp, ISP_LOGINFO, "Chan %d Initiator ID is %d",
1597 	    chan, sdp->isp_initiator_id);
1598 
1599 
1600 	/*
1601 	 * Set current per-target parameters to an initial safe minimum.
1602 	 */
1603 	for (tgt = 0; tgt < MAX_TARGETS; tgt++) {
1604 		int lun;
1605 		uint16_t sdf;
1606 
1607 		if (sdp->isp_devparam[tgt].dev_enable == 0) {
1608 			continue;
1609 		}
1610 #ifndef	ISP_TARGET_MODE
1611 		sdf = sdp->isp_devparam[tgt].goal_flags;
1612 		sdf &= DPARM_SAFE_DFLT;
1613 		/*
1614 		 * It is not quite clear when this changed over so that
1615 		 * we could force narrow and async for 1000/1020 cards,
1616 		 * but assume that this is only the case for loaded
1617 		 * firmware.
1618 		 */
1619 		if (isp->isp_loaded_fw) {
1620 			sdf |= DPARM_NARROW | DPARM_ASYNC;
1621 		}
1622 #else
1623 		/*
1624 		 * The !$*!)$!$)* f/w uses the same index into some
1625 		 * internal table to decide how to respond to negotiations,
1626 		 * so if we've said "let's be safe" for ID X, and ID X
1627 		 * selects *us*, the negotiations will back to 'safe'
1628 		 * (as in narrow/async). What the f/w *should* do is
1629 		 * use the initiator id settings to decide how to respond.
1630 		 */
1631 		sdp->isp_devparam[tgt].goal_flags = sdf = DPARM_DEFAULT;
1632 #endif
1633 		MBSINIT(&mbs, MBOX_SET_TARGET_PARAMS, MBLOGNONE, 0);
1634 		mbs.param[1] = (chan << 15) | (tgt << 8);
1635 		mbs.param[2] = sdf;
1636 		if ((sdf & DPARM_SYNC) == 0) {
1637 			mbs.param[3] = 0;
1638 		} else {
1639 			mbs.param[3] =
1640 			    (sdp->isp_devparam[tgt].goal_offset << 8) |
1641 			    (sdp->isp_devparam[tgt].goal_period);
1642 		}
1643 		isp_prt(isp, ISP_LOGDEBUG0, "Initial Settings bus%d tgt%d flags 0x%x off 0x%x per 0x%x",
1644 		    chan, tgt, mbs.param[2], mbs.param[3] >> 8, mbs.param[3] & 0xff);
1645 		isp_mboxcmd(isp, &mbs);
1646 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1647 			sdf = DPARM_SAFE_DFLT;
1648 			MBSINIT(&mbs, MBOX_SET_TARGET_PARAMS, MBLOGALL, 0);
1649 			mbs.param[1] = (tgt << 8) | (chan << 15);
1650 			mbs.param[2] = sdf;
1651 			mbs.param[3] = 0;
1652 			isp_mboxcmd(isp, &mbs);
1653 			if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1654 				continue;
1655 			}
1656 		}
1657 
1658 		/*
1659 		 * We don't update any information directly from the f/w
1660 		 * because we need to run at least one command to cause a
1661 		 * new state to be latched up. So, we just assume that we
1662 		 * converge to the values we just had set.
1663 		 *
1664 		 * Ensure that we don't believe tagged queuing is enabled yet.
1665 		 * It turns out that sometimes the ISP just ignores our
1666 		 * attempts to set parameters for devices that it hasn't
1667 		 * seen yet.
1668 		 */
1669 		sdp->isp_devparam[tgt].actv_flags = sdf & ~DPARM_TQING;
1670 		for (lun = 0; lun < (int) isp->isp_maxluns; lun++) {
1671 			MBSINIT(&mbs, MBOX_SET_DEV_QUEUE_PARAMS, MBLOGALL, 0);
1672 			mbs.param[1] = (chan << 15) | (tgt << 8) | lun;
1673 			mbs.param[2] = sdp->isp_max_queue_depth;
1674 			mbs.param[3] = sdp->isp_devparam[tgt].exc_throttle;
1675 			isp_mboxcmd(isp, &mbs);
1676 			if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1677 				break;
1678 			}
1679 		}
1680 	}
1681 	for (tgt = 0; tgt < MAX_TARGETS; tgt++) {
1682 		if (sdp->isp_devparam[tgt].dev_refresh) {
1683 			sdp->sendmarker = 1;
1684 			sdp->update = 1;
1685 			break;
1686 		}
1687 	}
1688 }
1689 
1690 /*
1691  * Fibre Channel specific initialization.
1692  */
1693 static void
1694 isp_fibre_init(ispsoftc_t *isp)
1695 {
1696 	fcparam *fcp;
1697 	isp_icb_t local, *icbp = &local;
1698 	mbreg_t mbs;
1699 
1700 	/*
1701 	 * We only support one channel on non-24XX cards
1702 	 */
1703 	fcp = FCPARAM(isp, 0);
1704 	if (fcp->role == ISP_ROLE_NONE)
1705 		return;
1706 
1707 	isp->isp_state = ISP_INITSTATE;
1708 	ISP_MEMZERO(icbp, sizeof (*icbp));
1709 	icbp->icb_version = ICB_VERSION1;
1710 	icbp->icb_fwoptions = fcp->isp_fwoptions;
1711 
1712 	/*
1713 	 * Firmware Options are either retrieved from NVRAM or
1714 	 * are patched elsewhere. We check them for sanity here
1715 	 * and make changes based on board revision, but otherwise
1716 	 * let others decide policy.
1717 	 */
1718 
1719 	/*
1720 	 * If this is a 2100 < revision 5, we have to turn off FAIRNESS.
1721 	 */
1722 	if (IS_2100(isp) && isp->isp_revision < 5) {
1723 		icbp->icb_fwoptions &= ~ICBOPT_FAIRNESS;
1724 	}
1725 
1726 	/*
1727 	 * We have to use FULL LOGIN even though it resets the loop too much
1728 	 * because otherwise port database entries don't get updated after
1729 	 * a LIP- this is a known f/w bug for 2100 f/w less than 1.17.0.
1730 	 */
1731 	if (!ISP_FW_NEWER_THAN(isp, 1, 17, 0)) {
1732 		icbp->icb_fwoptions |= ICBOPT_FULL_LOGIN;
1733 	}
1734 
1735 	/*
1736 	 * Insist on Port Database Update Async notifications
1737 	 */
1738 	icbp->icb_fwoptions |= ICBOPT_PDBCHANGE_AE;
1739 
1740 	/*
1741 	 * Make sure that target role reflects into fwoptions.
1742 	 */
1743 	if (fcp->role & ISP_ROLE_TARGET) {
1744 		icbp->icb_fwoptions |= ICBOPT_TGT_ENABLE;
1745 	} else {
1746 		icbp->icb_fwoptions &= ~ICBOPT_TGT_ENABLE;
1747 	}
1748 
1749 	/*
1750 	 * For some reason my 2200 does not generate ATIOs in target mode
1751 	 * if initiator is disabled.  Extra logins are better then target
1752 	 * not working at all.
1753 	 */
1754 	if ((fcp->role & ISP_ROLE_INITIATOR) || IS_2100(isp) || IS_2200(isp)) {
1755 		icbp->icb_fwoptions &= ~ICBOPT_INI_DISABLE;
1756 	} else {
1757 		icbp->icb_fwoptions |= ICBOPT_INI_DISABLE;
1758 	}
1759 
1760 	icbp->icb_maxfrmlen = DEFAULT_FRAMESIZE(isp);
1761 	if (icbp->icb_maxfrmlen < ICB_MIN_FRMLEN || icbp->icb_maxfrmlen > ICB_MAX_FRMLEN) {
1762 		isp_prt(isp, ISP_LOGERR, "bad frame length (%d) from NVRAM- using %d", DEFAULT_FRAMESIZE(isp), ICB_DFLT_FRMLEN);
1763 		icbp->icb_maxfrmlen = ICB_DFLT_FRMLEN;
1764 	}
1765 	icbp->icb_maxalloc = fcp->isp_maxalloc;
1766 	if (icbp->icb_maxalloc < 1) {
1767 		isp_prt(isp, ISP_LOGERR, "bad maximum allocation (%d)- using 16", fcp->isp_maxalloc);
1768 		icbp->icb_maxalloc = 16;
1769 	}
1770 	icbp->icb_execthrottle = DEFAULT_EXEC_THROTTLE(isp);
1771 	if (icbp->icb_execthrottle < 1) {
1772 		isp_prt(isp, ISP_LOGERR, "bad execution throttle of %d- using %d", DEFAULT_EXEC_THROTTLE(isp), ICB_DFLT_THROTTLE);
1773 		icbp->icb_execthrottle = ICB_DFLT_THROTTLE;
1774 	}
1775 	icbp->icb_retry_delay = fcp->isp_retry_delay;
1776 	icbp->icb_retry_count = fcp->isp_retry_count;
1777 	if (fcp->isp_loopid < LOCAL_LOOP_LIM) {
1778 		icbp->icb_hardaddr = fcp->isp_loopid;
1779 		if (isp->isp_confopts & ISP_CFG_OWNLOOPID)
1780 			icbp->icb_fwoptions |= ICBOPT_HARD_ADDRESS;
1781 		else
1782 			icbp->icb_fwoptions |= ICBOPT_PREV_ADDRESS;
1783 	}
1784 
1785 	/*
1786 	 * Right now we just set extended options to prefer point-to-point
1787 	 * over loop based upon some soft config options.
1788 	 *
1789 	 * NB: for the 2300, ICBOPT_EXTENDED is required.
1790 	 */
1791 	if (IS_2100(isp)) {
1792 		/*
1793 		 * We can't have Fast Posting any more- we now
1794 		 * have 32 bit handles.
1795 		 */
1796 		icbp->icb_fwoptions &= ~ICBOPT_FAST_POST;
1797 	} else if (IS_2200(isp) || IS_23XX(isp)) {
1798 		icbp->icb_fwoptions |= ICBOPT_EXTENDED;
1799 
1800 		icbp->icb_xfwoptions = fcp->isp_xfwoptions;
1801 
1802 		if (ISP_CAP_FCTAPE(isp)) {
1803 			if (isp->isp_confopts & ISP_CFG_NOFCTAPE)
1804 				icbp->icb_xfwoptions &= ~ICBXOPT_FCTAPE;
1805 
1806 			if (isp->isp_confopts & ISP_CFG_FCTAPE)
1807 				icbp->icb_xfwoptions |= ICBXOPT_FCTAPE;
1808 
1809 			if (icbp->icb_xfwoptions & ICBXOPT_FCTAPE) {
1810 				icbp->icb_fwoptions &= ~ICBOPT_FULL_LOGIN;	/* per documents */
1811 				icbp->icb_xfwoptions |= ICBXOPT_FCTAPE_CCQ|ICBXOPT_FCTAPE_CONFIRM;
1812 				FCPARAM(isp, 0)->fctape_enabled = 1;
1813 			} else {
1814 				FCPARAM(isp, 0)->fctape_enabled = 0;
1815 			}
1816 		} else {
1817 			icbp->icb_xfwoptions &= ~ICBXOPT_FCTAPE;
1818 			FCPARAM(isp, 0)->fctape_enabled = 0;
1819 		}
1820 
1821 		/*
1822 		 * Prefer or force Point-To-Point instead Loop?
1823 		 */
1824 		switch (isp->isp_confopts & ISP_CFG_PORT_PREF) {
1825 		case ISP_CFG_NPORT:
1826 			icbp->icb_xfwoptions &= ~ICBXOPT_TOPO_MASK;
1827 			icbp->icb_xfwoptions |= ICBXOPT_PTP_2_LOOP;
1828 			break;
1829 		case ISP_CFG_NPORT_ONLY:
1830 			icbp->icb_xfwoptions &= ~ICBXOPT_TOPO_MASK;
1831 			icbp->icb_xfwoptions |= ICBXOPT_PTP_ONLY;
1832 			break;
1833 		case ISP_CFG_LPORT_ONLY:
1834 			icbp->icb_xfwoptions &= ~ICBXOPT_TOPO_MASK;
1835 			icbp->icb_xfwoptions |= ICBXOPT_LOOP_ONLY;
1836 			break;
1837 		default:
1838 			/*
1839 			 * Let NVRAM settings define it if they are sane
1840 			 */
1841 			switch (icbp->icb_xfwoptions & ICBXOPT_TOPO_MASK) {
1842 			case ICBXOPT_PTP_2_LOOP:
1843 			case ICBXOPT_PTP_ONLY:
1844 			case ICBXOPT_LOOP_ONLY:
1845 			case ICBXOPT_LOOP_2_PTP:
1846 				break;
1847 			default:
1848 				icbp->icb_xfwoptions &= ~ICBXOPT_TOPO_MASK;
1849 				icbp->icb_xfwoptions |= ICBXOPT_LOOP_2_PTP;
1850 			}
1851 			break;
1852 		}
1853 		if (IS_2200(isp)) {
1854 			/*
1855 			 * We can't have Fast Posting any more- we now
1856 			 * have 32 bit handles.
1857 			 *
1858 			 * RIO seemed to have to much breakage.
1859 			 *
1860 			 * Just opt for safety.
1861 			 */
1862 			icbp->icb_xfwoptions &= ~ICBXOPT_RIO_16BIT;
1863 			icbp->icb_fwoptions &= ~ICBOPT_FAST_POST;
1864 		} else {
1865 			/*
1866 			 * QLogic recommends that FAST Posting be turned
1867 			 * off for 23XX cards and instead allow the HBA
1868 			 * to write response queue entries and interrupt
1869 			 * after a delay (ZIO).
1870 			 */
1871 			icbp->icb_fwoptions &= ~ICBOPT_FAST_POST;
1872 			if ((fcp->isp_xfwoptions & ICBXOPT_TIMER_MASK) == ICBXOPT_ZIO) {
1873 				icbp->icb_xfwoptions |= ICBXOPT_ZIO;
1874 				icbp->icb_idelaytimer = 10;
1875 			}
1876 			icbp->icb_zfwoptions = fcp->isp_zfwoptions;
1877 			if (isp->isp_confopts & ISP_CFG_1GB) {
1878 				icbp->icb_zfwoptions &= ~ICBZOPT_RATE_MASK;
1879 				icbp->icb_zfwoptions |= ICBZOPT_RATE_1GB;
1880 			} else if (isp->isp_confopts & ISP_CFG_2GB) {
1881 				icbp->icb_zfwoptions &= ~ICBZOPT_RATE_MASK;
1882 				icbp->icb_zfwoptions |= ICBZOPT_RATE_2GB;
1883 			} else {
1884 				switch (icbp->icb_zfwoptions & ICBZOPT_RATE_MASK) {
1885 				case ICBZOPT_RATE_1GB:
1886 				case ICBZOPT_RATE_2GB:
1887 				case ICBZOPT_RATE_AUTO:
1888 					break;
1889 				default:
1890 					icbp->icb_zfwoptions &= ~ICBZOPT_RATE_MASK;
1891 					icbp->icb_zfwoptions |= ICBZOPT_RATE_AUTO;
1892 					break;
1893 				}
1894 			}
1895 		}
1896 	}
1897 
1898 
1899 	/*
1900 	 * For 22XX > 2.1.26 && 23XX, set some options.
1901 	 */
1902 	if (ISP_FW_NEWER_THAN(isp, 2, 26, 0)) {
1903 		MBSINIT(&mbs, MBOX_SET_FIRMWARE_OPTIONS, MBLOGALL, 0);
1904 		mbs.param[1] = IFCOPT1_DISF7SWTCH|IFCOPT1_LIPASYNC|IFCOPT1_LIPF8;
1905 		mbs.param[2] = 0;
1906 		mbs.param[3] = 0;
1907 		if (ISP_FW_NEWER_THAN(isp, 3, 16, 0)) {
1908 			mbs.param[1] |= IFCOPT1_EQFQASYNC|IFCOPT1_CTIO_RETRY;
1909 			if (fcp->role & ISP_ROLE_TARGET) {
1910 				if (ISP_FW_NEWER_THAN(isp, 3, 25, 0)) {
1911 					mbs.param[1] |= IFCOPT1_ENAPURE;
1912 				}
1913 				mbs.param[3] = IFCOPT3_NOPRLI;
1914 			}
1915 		}
1916 		isp_mboxcmd(isp, &mbs);
1917 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
1918 			return;
1919 		}
1920 	}
1921 	icbp->icb_logintime = ICB_LOGIN_TOV;
1922 
1923 #ifdef	ISP_TARGET_MODE
1924 	if (icbp->icb_fwoptions & ICBOPT_TGT_ENABLE) {
1925 		icbp->icb_lunenables = 0xffff;
1926 		icbp->icb_ccnt = 0xff;
1927 		icbp->icb_icnt = 0xff;
1928 		icbp->icb_lunetimeout = ICB_LUN_ENABLE_TOV;
1929 	}
1930 #endif
1931 	if (fcp->isp_wwnn && fcp->isp_wwpn) {
1932 		icbp->icb_fwoptions |= ICBOPT_BOTH_WWNS;
1933 		MAKE_NODE_NAME_FROM_WWN(icbp->icb_nodename, fcp->isp_wwnn);
1934 		MAKE_NODE_NAME_FROM_WWN(icbp->icb_portname, fcp->isp_wwpn);
1935 		isp_prt(isp, ISP_LOGDEBUG1,
1936 		    "Setting ICB Node 0x%08x%08x Port 0x%08x%08x",
1937 		    ((uint32_t) (fcp->isp_wwnn >> 32)),
1938 		    ((uint32_t) (fcp->isp_wwnn)),
1939 		    ((uint32_t) (fcp->isp_wwpn >> 32)),
1940 		    ((uint32_t) (fcp->isp_wwpn)));
1941 	} else if (fcp->isp_wwpn) {
1942 		icbp->icb_fwoptions &= ~ICBOPT_BOTH_WWNS;
1943 		MAKE_NODE_NAME_FROM_WWN(icbp->icb_portname, fcp->isp_wwpn);
1944 		isp_prt(isp, ISP_LOGDEBUG1,
1945 		    "Setting ICB Port 0x%08x%08x",
1946 		    ((uint32_t) (fcp->isp_wwpn >> 32)),
1947 		    ((uint32_t) (fcp->isp_wwpn)));
1948 	} else {
1949 		isp_prt(isp, ISP_LOGERR, "No valid WWNs to use");
1950 		return;
1951 	}
1952 	icbp->icb_rqstqlen = RQUEST_QUEUE_LEN(isp);
1953 	if (icbp->icb_rqstqlen < 1) {
1954 		isp_prt(isp, ISP_LOGERR, "bad request queue length");
1955 	}
1956 	icbp->icb_rsltqlen = RESULT_QUEUE_LEN(isp);
1957 	if (icbp->icb_rsltqlen < 1) {
1958 		isp_prt(isp, ISP_LOGERR, "bad result queue length");
1959 	}
1960 	icbp->icb_rqstaddr[RQRSP_ADDR0015] = DMA_WD0(isp->isp_rquest_dma);
1961 	icbp->icb_rqstaddr[RQRSP_ADDR1631] = DMA_WD1(isp->isp_rquest_dma);
1962 	icbp->icb_rqstaddr[RQRSP_ADDR3247] = DMA_WD2(isp->isp_rquest_dma);
1963 	icbp->icb_rqstaddr[RQRSP_ADDR4863] = DMA_WD3(isp->isp_rquest_dma);
1964 	icbp->icb_respaddr[RQRSP_ADDR0015] = DMA_WD0(isp->isp_result_dma);
1965 	icbp->icb_respaddr[RQRSP_ADDR1631] = DMA_WD1(isp->isp_result_dma);
1966 	icbp->icb_respaddr[RQRSP_ADDR3247] = DMA_WD2(isp->isp_result_dma);
1967 	icbp->icb_respaddr[RQRSP_ADDR4863] = DMA_WD3(isp->isp_result_dma);
1968 
1969 	if (FC_SCRATCH_ACQUIRE(isp, 0)) {
1970 		isp_prt(isp, ISP_LOGERR, sacq);
1971 		return;
1972 	}
1973 	isp_prt(isp, ISP_LOGDEBUG0, "isp_fibre_init: fwopt 0x%x xfwopt 0x%x zfwopt 0x%x",
1974 	    icbp->icb_fwoptions, icbp->icb_xfwoptions, icbp->icb_zfwoptions);
1975 
1976 	isp_put_icb(isp, icbp, (isp_icb_t *)fcp->isp_scratch);
1977 	if (isp->isp_dblev & ISP_LOGDEBUG1) {
1978 		isp_print_bytes(isp, "isp_fibre_init",
1979 		    sizeof(*icbp), fcp->isp_scratch);
1980 	}
1981 
1982 	/*
1983 	 * Init the firmware
1984 	 */
1985 	MBSINIT(&mbs, MBOX_INIT_FIRMWARE, MBLOGALL, 30000000);
1986 	mbs.param[1] = 0;
1987 	mbs.param[2] = DMA_WD1(fcp->isp_scdma);
1988 	mbs.param[3] = DMA_WD0(fcp->isp_scdma);
1989 	mbs.param[6] = DMA_WD3(fcp->isp_scdma);
1990 	mbs.param[7] = DMA_WD2(fcp->isp_scdma);
1991 	isp_prt(isp, ISP_LOGDEBUG0, "INIT F/W from %p (%08x%08x)",
1992 	    fcp->isp_scratch, (uint32_t) ((uint64_t)fcp->isp_scdma >> 32),
1993 	    (uint32_t) fcp->isp_scdma);
1994 	MEMORYBARRIER(isp, SYNC_SFORDEV, 0, sizeof (*icbp), 0);
1995 	isp_mboxcmd(isp, &mbs);
1996 	FC_SCRATCH_RELEASE(isp, 0);
1997 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE)
1998 		return;
1999 	isp->isp_reqidx = 0;
2000 	isp->isp_reqodx = 0;
2001 	isp->isp_residx = 0;
2002 	isp->isp_resodx = 0;
2003 
2004 	/*
2005 	 * Whatever happens, we're now committed to being here.
2006 	 */
2007 	isp->isp_state = ISP_RUNSTATE;
2008 }
2009 
2010 static void
2011 isp_fibre_init_2400(ispsoftc_t *isp)
2012 {
2013 	fcparam *fcp;
2014 	isp_icb_2400_t local, *icbp = &local;
2015 	mbreg_t mbs;
2016 	int chan;
2017 
2018 	/*
2019 	 * Check to see whether all channels have *some* kind of role
2020 	 */
2021 	for (chan = 0; chan < isp->isp_nchan; chan++) {
2022 		fcp = FCPARAM(isp, chan);
2023 		if (fcp->role != ISP_ROLE_NONE) {
2024 			break;
2025 		}
2026 	}
2027 	if (chan == isp->isp_nchan) {
2028 		isp_prt(isp, ISP_LOG_WARN1, "all %d channels with role 'none'", chan);
2029 		return;
2030 	}
2031 
2032 	isp->isp_state = ISP_INITSTATE;
2033 
2034 	/*
2035 	 * Start with channel 0.
2036 	 */
2037 	fcp = FCPARAM(isp, 0);
2038 
2039 	/*
2040 	 * Turn on LIP F8 async event (1)
2041 	 */
2042 	MBSINIT(&mbs, MBOX_SET_FIRMWARE_OPTIONS, MBLOGALL, 0);
2043 	mbs.param[1] = 1;
2044 	isp_mboxcmd(isp, &mbs);
2045 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
2046 		return;
2047 	}
2048 
2049 	ISP_MEMZERO(icbp, sizeof (*icbp));
2050 	icbp->icb_fwoptions1 = fcp->isp_fwoptions;
2051 	icbp->icb_fwoptions2 = fcp->isp_xfwoptions;
2052 	icbp->icb_fwoptions3 = fcp->isp_zfwoptions;
2053 	if (isp->isp_nchan > 1 && ISP_CAP_VP0(isp)) {
2054 		icbp->icb_fwoptions1 &= ~ICB2400_OPT1_INI_DISABLE;
2055 		icbp->icb_fwoptions1 |= ICB2400_OPT1_TGT_ENABLE;
2056 	} else {
2057 		if (fcp->role & ISP_ROLE_TARGET)
2058 			icbp->icb_fwoptions1 |= ICB2400_OPT1_TGT_ENABLE;
2059 		else
2060 			icbp->icb_fwoptions1 &= ~ICB2400_OPT1_TGT_ENABLE;
2061 		if (fcp->role & ISP_ROLE_INITIATOR)
2062 			icbp->icb_fwoptions1 &= ~ICB2400_OPT1_INI_DISABLE;
2063 		else
2064 			icbp->icb_fwoptions1 |= ICB2400_OPT1_INI_DISABLE;
2065 	}
2066 
2067 	icbp->icb_version = ICB_VERSION1;
2068 	icbp->icb_maxfrmlen = DEFAULT_FRAMESIZE(isp);
2069 	if (icbp->icb_maxfrmlen < ICB_MIN_FRMLEN || icbp->icb_maxfrmlen > ICB_MAX_FRMLEN) {
2070 		isp_prt(isp, ISP_LOGERR, "bad frame length (%d) from NVRAM- using %d", DEFAULT_FRAMESIZE(isp), ICB_DFLT_FRMLEN);
2071 		icbp->icb_maxfrmlen = ICB_DFLT_FRMLEN;
2072 	}
2073 
2074 	icbp->icb_execthrottle = DEFAULT_EXEC_THROTTLE(isp);
2075 	if (icbp->icb_execthrottle < 1) {
2076 		isp_prt(isp, ISP_LOGERR, "bad execution throttle of %d- using %d", DEFAULT_EXEC_THROTTLE(isp), ICB_DFLT_THROTTLE);
2077 		icbp->icb_execthrottle = ICB_DFLT_THROTTLE;
2078 	}
2079 
2080 	/*
2081 	 * Set target exchange count. Take half if we are supporting both roles.
2082 	 */
2083 	if (icbp->icb_fwoptions1 & ICB2400_OPT1_TGT_ENABLE) {
2084 		icbp->icb_xchgcnt = isp->isp_maxcmds;
2085 		if ((icbp->icb_fwoptions1 & ICB2400_OPT1_INI_DISABLE) == 0)
2086 			icbp->icb_xchgcnt >>= 1;
2087 	}
2088 
2089 	if (fcp->isp_loopid < LOCAL_LOOP_LIM) {
2090 		icbp->icb_hardaddr = fcp->isp_loopid;
2091 		if (isp->isp_confopts & ISP_CFG_OWNLOOPID)
2092 			icbp->icb_fwoptions1 |= ICB2400_OPT1_HARD_ADDRESS;
2093 		else
2094 			icbp->icb_fwoptions1 |= ICB2400_OPT1_PREV_ADDRESS;
2095 	}
2096 
2097 	if (isp->isp_confopts & ISP_CFG_NOFCTAPE) {
2098 		icbp->icb_fwoptions2 &= ~ICB2400_OPT2_FCTAPE;
2099 	}
2100 	if (isp->isp_confopts & ISP_CFG_FCTAPE) {
2101 		icbp->icb_fwoptions2 |= ICB2400_OPT2_FCTAPE;
2102 	}
2103 
2104 	for (chan = 0; chan < isp->isp_nchan; chan++) {
2105 		if (icbp->icb_fwoptions2 & ICB2400_OPT2_FCTAPE)
2106 			FCPARAM(isp, chan)->fctape_enabled = 1;
2107 		else
2108 			FCPARAM(isp, chan)->fctape_enabled = 0;
2109 	}
2110 
2111 	switch (isp->isp_confopts & ISP_CFG_PORT_PREF) {
2112 	case ISP_CFG_NPORT_ONLY:
2113 		icbp->icb_fwoptions2 &= ~ICB2400_OPT2_TOPO_MASK;
2114 		icbp->icb_fwoptions2 |= ICB2400_OPT2_PTP_ONLY;
2115 		break;
2116 	case ISP_CFG_LPORT_ONLY:
2117 		icbp->icb_fwoptions2 &= ~ICB2400_OPT2_TOPO_MASK;
2118 		icbp->icb_fwoptions2 |= ICB2400_OPT2_LOOP_ONLY;
2119 		break;
2120 	default:
2121 		/* ISP_CFG_PTP_2_LOOP not available in 24XX/25XX */
2122 		icbp->icb_fwoptions2 &= ~ICB2400_OPT2_TOPO_MASK;
2123 		icbp->icb_fwoptions2 |= ICB2400_OPT2_LOOP_2_PTP;
2124 		break;
2125 	}
2126 
2127 	switch (icbp->icb_fwoptions2 & ICB2400_OPT2_TIMER_MASK) {
2128 	case ICB2400_OPT2_ZIO:
2129 	case ICB2400_OPT2_ZIO1:
2130 		icbp->icb_idelaytimer = 0;
2131 		break;
2132 	case 0:
2133 		break;
2134 	default:
2135 		isp_prt(isp, ISP_LOGWARN, "bad value %x in fwopt2 timer field", icbp->icb_fwoptions2 & ICB2400_OPT2_TIMER_MASK);
2136 		icbp->icb_fwoptions2 &= ~ICB2400_OPT2_TIMER_MASK;
2137 		break;
2138 	}
2139 
2140 	if (IS_26XX(isp)) {
2141 		/* We don't support MSI-X yet, so set this unconditionally. */
2142 		icbp->icb_fwoptions2 |= ICB2400_OPT2_ENA_IHR;
2143 		icbp->icb_fwoptions2 |= ICB2400_OPT2_ENA_IHA;
2144 	}
2145 
2146 	if ((icbp->icb_fwoptions3 & ICB2400_OPT3_RSPSZ_MASK) == 0) {
2147 		icbp->icb_fwoptions3 |= ICB2400_OPT3_RSPSZ_24;
2148 	}
2149 	if (isp->isp_confopts & ISP_CFG_1GB) {
2150 		icbp->icb_fwoptions3 &= ~ICB2400_OPT3_RATE_MASK;
2151 		icbp->icb_fwoptions3 |= ICB2400_OPT3_RATE_1GB;
2152 	} else if (isp->isp_confopts & ISP_CFG_2GB) {
2153 		icbp->icb_fwoptions3 &= ~ICB2400_OPT3_RATE_MASK;
2154 		icbp->icb_fwoptions3 |= ICB2400_OPT3_RATE_2GB;
2155 	} else if (isp->isp_confopts & ISP_CFG_4GB) {
2156 		icbp->icb_fwoptions3 &= ~ICB2400_OPT3_RATE_MASK;
2157 		icbp->icb_fwoptions3 |= ICB2400_OPT3_RATE_4GB;
2158 	} else if (isp->isp_confopts & ISP_CFG_8GB) {
2159 		icbp->icb_fwoptions3 &= ~ICB2400_OPT3_RATE_MASK;
2160 		icbp->icb_fwoptions3 |= ICB2400_OPT3_RATE_8GB;
2161 	} else if (isp->isp_confopts & ISP_CFG_16GB) {
2162 		icbp->icb_fwoptions3 &= ~ICB2400_OPT3_RATE_MASK;
2163 		icbp->icb_fwoptions3 |= ICB2400_OPT3_RATE_16GB;
2164 	} else {
2165 		switch (icbp->icb_fwoptions3 & ICB2400_OPT3_RATE_MASK) {
2166 		case ICB2400_OPT3_RATE_4GB:
2167 		case ICB2400_OPT3_RATE_8GB:
2168 		case ICB2400_OPT3_RATE_16GB:
2169 		case ICB2400_OPT3_RATE_AUTO:
2170 			break;
2171 		case ICB2400_OPT3_RATE_2GB:
2172 			if (isp->isp_type <= ISP_HA_FC_2500)
2173 				break;
2174 			/*FALLTHROUGH*/
2175 		case ICB2400_OPT3_RATE_1GB:
2176 			if (isp->isp_type <= ISP_HA_FC_2400)
2177 				break;
2178 			/*FALLTHROUGH*/
2179 		default:
2180 			icbp->icb_fwoptions3 &= ~ICB2400_OPT3_RATE_MASK;
2181 			icbp->icb_fwoptions3 |= ICB2400_OPT3_RATE_AUTO;
2182 			break;
2183 		}
2184 	}
2185 	icbp->icb_logintime = ICB_LOGIN_TOV;
2186 
2187 	if (fcp->isp_wwnn && fcp->isp_wwpn) {
2188 		icbp->icb_fwoptions1 |= ICB2400_OPT1_BOTH_WWNS;
2189 		MAKE_NODE_NAME_FROM_WWN(icbp->icb_portname, fcp->isp_wwpn);
2190 		MAKE_NODE_NAME_FROM_WWN(icbp->icb_nodename, fcp->isp_wwnn);
2191 		isp_prt(isp, ISP_LOGDEBUG1, "Setting ICB Node 0x%08x%08x Port 0x%08x%08x", ((uint32_t) (fcp->isp_wwnn >> 32)), ((uint32_t) (fcp->isp_wwnn)),
2192 		    ((uint32_t) (fcp->isp_wwpn >> 32)), ((uint32_t) (fcp->isp_wwpn)));
2193 	} else if (fcp->isp_wwpn) {
2194 		icbp->icb_fwoptions1 &= ~ICB2400_OPT1_BOTH_WWNS;
2195 		MAKE_NODE_NAME_FROM_WWN(icbp->icb_portname, fcp->isp_wwpn);
2196 		isp_prt(isp, ISP_LOGDEBUG1, "Setting ICB Node to be same as Port 0x%08x%08x", ((uint32_t) (fcp->isp_wwpn >> 32)), ((uint32_t) (fcp->isp_wwpn)));
2197 	} else {
2198 		isp_prt(isp, ISP_LOGERR, "No valid WWNs to use");
2199 		return;
2200 	}
2201 	icbp->icb_retry_count = fcp->isp_retry_count;
2202 
2203 	icbp->icb_rqstqlen = RQUEST_QUEUE_LEN(isp);
2204 	if (icbp->icb_rqstqlen < 8) {
2205 		isp_prt(isp, ISP_LOGERR, "bad request queue length %d", icbp->icb_rqstqlen);
2206 		return;
2207 	}
2208 	icbp->icb_rsltqlen = RESULT_QUEUE_LEN(isp);
2209 	if (icbp->icb_rsltqlen < 8) {
2210 		isp_prt(isp, ISP_LOGERR, "bad result queue length %d",
2211 		    icbp->icb_rsltqlen);
2212 		return;
2213 	}
2214 	icbp->icb_rqstaddr[RQRSP_ADDR0015] = DMA_WD0(isp->isp_rquest_dma);
2215 	icbp->icb_rqstaddr[RQRSP_ADDR1631] = DMA_WD1(isp->isp_rquest_dma);
2216 	icbp->icb_rqstaddr[RQRSP_ADDR3247] = DMA_WD2(isp->isp_rquest_dma);
2217 	icbp->icb_rqstaddr[RQRSP_ADDR4863] = DMA_WD3(isp->isp_rquest_dma);
2218 
2219 	icbp->icb_respaddr[RQRSP_ADDR0015] = DMA_WD0(isp->isp_result_dma);
2220 	icbp->icb_respaddr[RQRSP_ADDR1631] = DMA_WD1(isp->isp_result_dma);
2221 	icbp->icb_respaddr[RQRSP_ADDR3247] = DMA_WD2(isp->isp_result_dma);
2222 	icbp->icb_respaddr[RQRSP_ADDR4863] = DMA_WD3(isp->isp_result_dma);
2223 
2224 #ifdef	ISP_TARGET_MODE
2225 	/* unconditionally set up the ATIO queue if we support target mode */
2226 	icbp->icb_atioqlen = RESULT_QUEUE_LEN(isp);
2227 	if (icbp->icb_atioqlen < 8) {
2228 		isp_prt(isp, ISP_LOGERR, "bad ATIO queue length %d", icbp->icb_atioqlen);
2229 		return;
2230 	}
2231 	icbp->icb_atioqaddr[RQRSP_ADDR0015] = DMA_WD0(isp->isp_atioq_dma);
2232 	icbp->icb_atioqaddr[RQRSP_ADDR1631] = DMA_WD1(isp->isp_atioq_dma);
2233 	icbp->icb_atioqaddr[RQRSP_ADDR3247] = DMA_WD2(isp->isp_atioq_dma);
2234 	icbp->icb_atioqaddr[RQRSP_ADDR4863] = DMA_WD3(isp->isp_atioq_dma);
2235 	isp_prt(isp, ISP_LOGDEBUG0, "isp_fibre_init_2400: atioq %04x%04x%04x%04x", DMA_WD3(isp->isp_atioq_dma), DMA_WD2(isp->isp_atioq_dma),
2236 	    DMA_WD1(isp->isp_atioq_dma), DMA_WD0(isp->isp_atioq_dma));
2237 #endif
2238 
2239 	isp_prt(isp, ISP_LOGDEBUG0, "isp_fibre_init_2400: fwopt1 0x%x fwopt2 0x%x fwopt3 0x%x", icbp->icb_fwoptions1, icbp->icb_fwoptions2, icbp->icb_fwoptions3);
2240 
2241 	isp_prt(isp, ISP_LOGDEBUG0, "isp_fibre_init_2400: rqst %04x%04x%04x%04x rsp %04x%04x%04x%04x", DMA_WD3(isp->isp_rquest_dma), DMA_WD2(isp->isp_rquest_dma),
2242 	    DMA_WD1(isp->isp_rquest_dma), DMA_WD0(isp->isp_rquest_dma), DMA_WD3(isp->isp_result_dma), DMA_WD2(isp->isp_result_dma),
2243 	    DMA_WD1(isp->isp_result_dma), DMA_WD0(isp->isp_result_dma));
2244 
2245 	if (FC_SCRATCH_ACQUIRE(isp, 0)) {
2246 		isp_prt(isp, ISP_LOGERR, sacq);
2247 		return;
2248 	}
2249 	ISP_MEMZERO(fcp->isp_scratch, ISP_FC_SCRLEN);
2250 	isp_put_icb_2400(isp, icbp, fcp->isp_scratch);
2251 	if (isp->isp_dblev & ISP_LOGDEBUG1) {
2252 		isp_print_bytes(isp, "isp_fibre_init_2400",
2253 		    sizeof (*icbp), fcp->isp_scratch);
2254 	}
2255 
2256 	/*
2257 	 * Now fill in information about any additional channels
2258 	 */
2259 	if (isp->isp_nchan > 1) {
2260 		isp_icb_2400_vpinfo_t vpinfo, *vdst;
2261 		vp_port_info_t pi, *pdst;
2262 		size_t amt = 0;
2263 		uint8_t *off;
2264 
2265 		vpinfo.vp_global_options = ICB2400_VPGOPT_GEN_RIDA;
2266 		if (ISP_CAP_VP0(isp)) {
2267 			vpinfo.vp_global_options |= ICB2400_VPGOPT_VP0_DECOUPLE;
2268 			vpinfo.vp_count = isp->isp_nchan;
2269 			chan = 0;
2270 		} else {
2271 			vpinfo.vp_count = isp->isp_nchan - 1;
2272 			chan = 1;
2273 		}
2274 		off = fcp->isp_scratch;
2275 		off += ICB2400_VPINFO_OFF;
2276 		vdst = (isp_icb_2400_vpinfo_t *) off;
2277 		isp_put_icb_2400_vpinfo(isp, &vpinfo, vdst);
2278 		amt = ICB2400_VPINFO_OFF + sizeof (isp_icb_2400_vpinfo_t);
2279 		for (; chan < isp->isp_nchan; chan++) {
2280 			fcparam *fcp2;
2281 
2282 			ISP_MEMZERO(&pi, sizeof (pi));
2283 			fcp2 = FCPARAM(isp, chan);
2284 			if (fcp2->role != ISP_ROLE_NONE) {
2285 				pi.vp_port_options = ICB2400_VPOPT_ENABLED |
2286 				    ICB2400_VPOPT_ENA_SNSLOGIN;
2287 				if (fcp2->role & ISP_ROLE_INITIATOR)
2288 					pi.vp_port_options |= ICB2400_VPOPT_INI_ENABLE;
2289 				if ((fcp2->role & ISP_ROLE_TARGET) == 0)
2290 					pi.vp_port_options |= ICB2400_VPOPT_TGT_DISABLE;
2291 			}
2292 			if (fcp2->isp_loopid < LOCAL_LOOP_LIM) {
2293 				pi.vp_port_loopid = fcp2->isp_loopid;
2294 				if (isp->isp_confopts & ISP_CFG_OWNLOOPID)
2295 					pi.vp_port_options |= ICB2400_VPOPT_HARD_ADDRESS;
2296 				else
2297 					pi.vp_port_options |= ICB2400_VPOPT_PREV_ADDRESS;
2298 			}
2299 			MAKE_NODE_NAME_FROM_WWN(pi.vp_port_portname, fcp2->isp_wwpn);
2300 			MAKE_NODE_NAME_FROM_WWN(pi.vp_port_nodename, fcp2->isp_wwnn);
2301 			off = fcp->isp_scratch;
2302 			if (ISP_CAP_VP0(isp))
2303 				off += ICB2400_VPINFO_PORT_OFF(chan);
2304 			else
2305 				off += ICB2400_VPINFO_PORT_OFF(chan - 1);
2306 			pdst = (vp_port_info_t *) off;
2307 			isp_put_vp_port_info(isp, &pi, pdst);
2308 			amt += ICB2400_VPOPT_WRITE_SIZE;
2309 		}
2310 		if (isp->isp_dblev & ISP_LOGDEBUG1) {
2311 			isp_print_bytes(isp, "isp_fibre_init_2400",
2312 			    amt - ICB2400_VPINFO_OFF,
2313 			    (char *)fcp->isp_scratch + ICB2400_VPINFO_OFF);
2314 		}
2315 	}
2316 
2317 	/*
2318 	 * Init the firmware
2319 	 */
2320 	MBSINIT(&mbs, 0, MBLOGALL, 30000000);
2321 	if (isp->isp_nchan > 1) {
2322 		mbs.param[0] = MBOX_INIT_FIRMWARE_MULTI_ID;
2323 	} else {
2324 		mbs.param[0] = MBOX_INIT_FIRMWARE;
2325 	}
2326 	mbs.param[1] = 0;
2327 	mbs.param[2] = DMA_WD1(fcp->isp_scdma);
2328 	mbs.param[3] = DMA_WD0(fcp->isp_scdma);
2329 	mbs.param[6] = DMA_WD3(fcp->isp_scdma);
2330 	mbs.param[7] = DMA_WD2(fcp->isp_scdma);
2331 	isp_prt(isp, ISP_LOGDEBUG0, "INIT F/W from %04x%04x%04x%04x", DMA_WD3(fcp->isp_scdma), DMA_WD2(fcp->isp_scdma), DMA_WD1(fcp->isp_scdma), DMA_WD0(fcp->isp_scdma));
2332 	MEMORYBARRIER(isp, SYNC_SFORDEV, 0, sizeof (*icbp), 0);
2333 	isp_mboxcmd(isp, &mbs);
2334 	FC_SCRATCH_RELEASE(isp, 0);
2335 
2336 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
2337 		return;
2338 	}
2339 	isp->isp_reqidx = 0;
2340 	isp->isp_reqodx = 0;
2341 	isp->isp_residx = 0;
2342 	isp->isp_resodx = 0;
2343 	isp->isp_atioodx = 0;
2344 
2345 	/*
2346 	 * Whatever happens, we're now committed to being here.
2347 	 */
2348 	isp->isp_state = ISP_RUNSTATE;
2349 }
2350 
2351 static int
2352 isp_fc_enable_vp(ispsoftc_t *isp, int chan)
2353 {
2354 	fcparam *fcp = FCPARAM(isp, chan);
2355 	vp_modify_t vp;
2356 	void *reqp;
2357 	uint8_t resp[QENTRY_LEN];
2358 
2359 	/* Build a VP MODIFY command in memory */
2360 	ISP_MEMZERO(&vp, sizeof(vp));
2361 	vp.vp_mod_hdr.rqs_entry_type = RQSTYPE_VP_MODIFY;
2362 	vp.vp_mod_hdr.rqs_entry_count = 1;
2363 	vp.vp_mod_cnt = 1;
2364 	vp.vp_mod_idx0 = chan;
2365 	vp.vp_mod_cmd = VP_MODIFY_ENA;
2366 	vp.vp_mod_ports[0].options = ICB2400_VPOPT_ENABLED |
2367 	    ICB2400_VPOPT_ENA_SNSLOGIN;
2368 	if (fcp->role & ISP_ROLE_INITIATOR)
2369 		vp.vp_mod_ports[0].options |= ICB2400_VPOPT_INI_ENABLE;
2370 	if ((fcp->role & ISP_ROLE_TARGET) == 0)
2371 		vp.vp_mod_ports[0].options |= ICB2400_VPOPT_TGT_DISABLE;
2372 	if (fcp->isp_loopid < LOCAL_LOOP_LIM) {
2373 		vp.vp_mod_ports[0].loopid = fcp->isp_loopid;
2374 		if (isp->isp_confopts & ISP_CFG_OWNLOOPID)
2375 			vp.vp_mod_ports[0].options |= ICB2400_VPOPT_HARD_ADDRESS;
2376 		else
2377 			vp.vp_mod_ports[0].options |= ICB2400_VPOPT_PREV_ADDRESS;
2378 	}
2379 	MAKE_NODE_NAME_FROM_WWN(vp.vp_mod_ports[0].wwpn, fcp->isp_wwpn);
2380 	MAKE_NODE_NAME_FROM_WWN(vp.vp_mod_ports[0].wwnn, fcp->isp_wwnn);
2381 
2382 	/* Prepare space for response in memory */
2383 	memset(resp, 0xff, sizeof(resp));
2384 	vp.vp_mod_hdl = isp_allocate_handle(isp, resp, ISP_HANDLE_CTRL);
2385 	if (vp.vp_mod_hdl == 0) {
2386 		isp_prt(isp, ISP_LOGERR,
2387 		    "%s: VP_MODIFY of Chan %d out of handles", __func__, chan);
2388 		return (EIO);
2389 	}
2390 
2391 	/* Send request and wait for response. */
2392 	reqp = isp_getrqentry(isp);
2393 	if (reqp == NULL) {
2394 		isp_prt(isp, ISP_LOGERR,
2395 		    "%s: VP_MODIFY of Chan %d out of rqent", __func__, chan);
2396 		isp_destroy_handle(isp, vp.vp_mod_hdl);
2397 		return (EIO);
2398 	}
2399 	isp_put_vp_modify(isp, &vp, (vp_modify_t *)reqp);
2400 	if (isp->isp_dblev & ISP_LOGDEBUG1)
2401 		isp_print_bytes(isp, "IOCB VP_MODIFY", QENTRY_LEN, reqp);
2402 	ISP_SYNC_REQUEST(isp);
2403 	if (msleep(resp, &isp->isp_lock, 0, "VP_MODIFY", 5*hz) == EWOULDBLOCK) {
2404 		isp_prt(isp, ISP_LOGERR,
2405 		    "%s: VP_MODIFY of Chan %d timed out", __func__, chan);
2406 		isp_destroy_handle(isp, vp.vp_mod_hdl);
2407 		return (EIO);
2408 	}
2409 	if (isp->isp_dblev & ISP_LOGDEBUG1)
2410 		isp_print_bytes(isp, "IOCB VP_MODIFY response", QENTRY_LEN, resp);
2411 	isp_get_vp_modify(isp, (vp_modify_t *)resp, &vp);
2412 
2413 	if (vp.vp_mod_hdr.rqs_flags != 0 || vp.vp_mod_status != VP_STS_OK) {
2414 		isp_prt(isp, ISP_LOGERR,
2415 		    "%s: VP_MODIFY of Chan %d failed with flags %x status %d",
2416 		    __func__, chan, vp.vp_mod_hdr.rqs_flags, vp.vp_mod_status);
2417 		return (EIO);
2418 	}
2419 	return (0);
2420 }
2421 
2422 static int
2423 isp_fc_disable_vp(ispsoftc_t *isp, int chan)
2424 {
2425 	vp_ctrl_info_t vp;
2426 	void *reqp;
2427 	uint8_t resp[QENTRY_LEN];
2428 
2429 	/* Build a VP CTRL command in memory */
2430 	ISP_MEMZERO(&vp, sizeof(vp));
2431 	vp.vp_ctrl_hdr.rqs_entry_type = RQSTYPE_VP_CTRL;
2432 	vp.vp_ctrl_hdr.rqs_entry_count = 1;
2433 	if (ISP_CAP_VP0(isp)) {
2434 		vp.vp_ctrl_status = 1;
2435 	} else {
2436 		vp.vp_ctrl_status = 0;
2437 		chan--;	/* VP0 can not be controlled in this case. */
2438 	}
2439 	vp.vp_ctrl_command = VP_CTRL_CMD_DISABLE_VP_LOGO_ALL;
2440 	vp.vp_ctrl_vp_count = 1;
2441 	vp.vp_ctrl_idmap[chan / 16] |= (1 << chan % 16);
2442 
2443 	/* Prepare space for response in memory */
2444 	memset(resp, 0xff, sizeof(resp));
2445 	vp.vp_ctrl_handle = isp_allocate_handle(isp, resp, ISP_HANDLE_CTRL);
2446 	if (vp.vp_ctrl_handle == 0) {
2447 		isp_prt(isp, ISP_LOGERR,
2448 		    "%s: VP_CTRL of Chan %d out of handles", __func__, chan);
2449 		return (EIO);
2450 	}
2451 
2452 	/* Send request and wait for response. */
2453 	reqp = isp_getrqentry(isp);
2454 	if (reqp == NULL) {
2455 		isp_prt(isp, ISP_LOGERR,
2456 		    "%s: VP_CTRL of Chan %d out of rqent", __func__, chan);
2457 		isp_destroy_handle(isp, vp.vp_ctrl_handle);
2458 		return (EIO);
2459 	}
2460 	isp_put_vp_ctrl_info(isp, &vp, (vp_ctrl_info_t *)reqp);
2461 	if (isp->isp_dblev & ISP_LOGDEBUG1)
2462 		isp_print_bytes(isp, "IOCB VP_CTRL", QENTRY_LEN, reqp);
2463 	ISP_SYNC_REQUEST(isp);
2464 	if (msleep(resp, &isp->isp_lock, 0, "VP_CTRL", 5*hz) == EWOULDBLOCK) {
2465 		isp_prt(isp, ISP_LOGERR,
2466 		    "%s: VP_CTRL of Chan %d timed out", __func__, chan);
2467 		isp_destroy_handle(isp, vp.vp_ctrl_handle);
2468 		return (EIO);
2469 	}
2470 	if (isp->isp_dblev & ISP_LOGDEBUG1)
2471 		isp_print_bytes(isp, "IOCB VP_CTRL response", QENTRY_LEN, resp);
2472 	isp_get_vp_ctrl_info(isp, (vp_ctrl_info_t *)resp, &vp);
2473 
2474 	if (vp.vp_ctrl_hdr.rqs_flags != 0 || vp.vp_ctrl_status != 0) {
2475 		isp_prt(isp, ISP_LOGERR,
2476 		    "%s: VP_CTRL of Chan %d failed with flags %x status %d %d",
2477 		    __func__, chan, vp.vp_ctrl_hdr.rqs_flags,
2478 		    vp.vp_ctrl_status, vp.vp_ctrl_index_fail);
2479 		return (EIO);
2480 	}
2481 	return (0);
2482 }
2483 
2484 static int
2485 isp_fc_change_role(ispsoftc_t *isp, int chan, int new_role)
2486 {
2487 	fcparam *fcp = FCPARAM(isp, chan);
2488 	int i, was, res = 0;
2489 
2490 	if (chan >= isp->isp_nchan) {
2491 		isp_prt(isp, ISP_LOGWARN, "%s: bad channel %d", __func__, chan);
2492 		return (ENXIO);
2493 	}
2494 	if (fcp->role == new_role)
2495 		return (0);
2496 	for (was = 0, i = 0; i < isp->isp_nchan; i++) {
2497 		if (FCPARAM(isp, i)->role != ISP_ROLE_NONE)
2498 			was++;
2499 	}
2500 	if (was == 0 || (was == 1 && fcp->role != ISP_ROLE_NONE)) {
2501 		fcp->role = new_role;
2502 		return (isp_reinit(isp, 0));
2503 	}
2504 	if (fcp->role != ISP_ROLE_NONE) {
2505 		res = isp_fc_disable_vp(isp, chan);
2506 		isp_clear_portdb(isp, chan);
2507 	}
2508 	fcp->role = new_role;
2509 	if (fcp->role != ISP_ROLE_NONE)
2510 		res = isp_fc_enable_vp(isp, chan);
2511 	return (res);
2512 }
2513 
2514 static void
2515 isp_clear_portdb(ispsoftc_t *isp, int chan)
2516 {
2517 	fcparam *fcp = FCPARAM(isp, chan);
2518 	fcportdb_t *lp;
2519 	int i;
2520 
2521 	for (i = 0; i < MAX_FC_TARG; i++) {
2522 		lp = &fcp->portdb[i];
2523 		switch (lp->state) {
2524 		case FC_PORTDB_STATE_DEAD:
2525 		case FC_PORTDB_STATE_CHANGED:
2526 		case FC_PORTDB_STATE_VALID:
2527 			lp->state = FC_PORTDB_STATE_NIL;
2528 			isp_async(isp, ISPASYNC_DEV_GONE, chan, lp);
2529 			break;
2530 		case FC_PORTDB_STATE_NIL:
2531 		case FC_PORTDB_STATE_NEW:
2532 			lp->state = FC_PORTDB_STATE_NIL;
2533 			break;
2534 		case FC_PORTDB_STATE_ZOMBIE:
2535 			break;
2536 		default:
2537 			panic("Don't know how to clear state %d\n", lp->state);
2538 		}
2539 	}
2540 }
2541 
2542 static void
2543 isp_mark_portdb(ispsoftc_t *isp, int chan)
2544 {
2545 	fcparam *fcp = FCPARAM(isp, chan);
2546 	fcportdb_t *lp;
2547 	int i;
2548 
2549 	for (i = 0; i < MAX_FC_TARG; i++) {
2550 		lp = &fcp->portdb[i];
2551 		if (lp->state == FC_PORTDB_STATE_NIL)
2552 			continue;
2553 		if (lp->portid >= DOMAIN_CONTROLLER_BASE &&
2554 		    lp->portid <= DOMAIN_CONTROLLER_END)
2555 			continue;
2556 		fcp->portdb[i].probational = 1;
2557 	}
2558 }
2559 
2560 /*
2561  * Perform an IOCB PLOGI or LOGO via EXECUTE IOCB A64 for 24XX cards
2562  * or via FABRIC LOGIN/FABRIC LOGOUT for other cards.
2563  */
2564 static int
2565 isp_plogx(ispsoftc_t *isp, int chan, uint16_t handle, uint32_t portid, int flags)
2566 {
2567 	isp_plogx_t pl;
2568 	void *reqp;
2569 	uint8_t resp[QENTRY_LEN];
2570 	uint32_t sst, parm1;
2571 	int rval, lev;
2572 	const char *msg;
2573 	char buf[64];
2574 
2575 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d PLOGX %s PortID 0x%06x nphdl 0x%x",
2576 	    chan, (flags & PLOGX_FLG_CMD_MASK) == PLOGX_FLG_CMD_PLOGI ?
2577 	    "Login":"Logout", portid, handle);
2578 	if (!IS_24XX(isp)) {
2579 		int action = flags & PLOGX_FLG_CMD_MASK;
2580 		if (action == PLOGX_FLG_CMD_PLOGI) {
2581 			return (isp_port_login(isp, handle, portid));
2582 		} else if (action == PLOGX_FLG_CMD_LOGO) {
2583 			return (isp_port_logout(isp, handle, portid));
2584 		} else {
2585 			return (MBOX_INVALID_COMMAND);
2586 		}
2587 	}
2588 
2589 	ISP_MEMZERO(&pl, sizeof(pl));
2590 	pl.plogx_header.rqs_entry_count = 1;
2591 	pl.plogx_header.rqs_entry_type = RQSTYPE_LOGIN;
2592 	pl.plogx_nphdl = handle;
2593 	pl.plogx_vphdl = chan;
2594 	pl.plogx_portlo = portid;
2595 	pl.plogx_rspsz_porthi = (portid >> 16) & 0xff;
2596 	pl.plogx_flags = flags;
2597 
2598 	/* Prepare space for response in memory */
2599 	memset(resp, 0xff, sizeof(resp));
2600 	pl.plogx_handle = isp_allocate_handle(isp, resp, ISP_HANDLE_CTRL);
2601 	if (pl.plogx_handle == 0) {
2602 		isp_prt(isp, ISP_LOGERR,
2603 		    "%s: PLOGX of Chan %d out of handles", __func__, chan);
2604 		return (-1);
2605 	}
2606 
2607 	/* Send request and wait for response. */
2608 	reqp = isp_getrqentry(isp);
2609 	if (reqp == NULL) {
2610 		isp_prt(isp, ISP_LOGERR,
2611 		    "%s: PLOGX of Chan %d out of rqent", __func__, chan);
2612 		isp_destroy_handle(isp, pl.plogx_handle);
2613 		return (-1);
2614 	}
2615 	isp_put_plogx(isp, &pl, (isp_plogx_t *)reqp);
2616 	if (isp->isp_dblev & ISP_LOGDEBUG1)
2617 		isp_print_bytes(isp, "IOCB LOGX", QENTRY_LEN, reqp);
2618 	ISP_SYNC_REQUEST(isp);
2619 	if (msleep(resp, &isp->isp_lock, 0, "PLOGX", 3 * ICB_LOGIN_TOV * hz)
2620 	    == EWOULDBLOCK) {
2621 		isp_prt(isp, ISP_LOGERR,
2622 		    "%s: PLOGX of Chan %d timed out", __func__, chan);
2623 		isp_destroy_handle(isp, pl.plogx_handle);
2624 		return (-1);
2625 	}
2626 	if (isp->isp_dblev & ISP_LOGDEBUG1)
2627 		isp_print_bytes(isp, "IOCB LOGX response", QENTRY_LEN, resp);
2628 	isp_get_plogx(isp, (isp_plogx_t *)resp, &pl);
2629 
2630 	if (pl.plogx_status == PLOGX_STATUS_OK) {
2631 		return (0);
2632 	} else if (pl.plogx_status != PLOGX_STATUS_IOCBERR) {
2633 		isp_prt(isp, ISP_LOGWARN,
2634 		    "status 0x%x on port login IOCB channel %d",
2635 		    pl.plogx_status, chan);
2636 		return (-1);
2637 	}
2638 
2639 	sst = pl.plogx_ioparm[0].lo16 | (pl.plogx_ioparm[0].hi16 << 16);
2640 	parm1 = pl.plogx_ioparm[1].lo16 | (pl.plogx_ioparm[1].hi16 << 16);
2641 
2642 	rval = -1;
2643 	lev = ISP_LOGERR;
2644 	msg = NULL;
2645 
2646 	switch (sst) {
2647 	case PLOGX_IOCBERR_NOLINK:
2648 		msg = "no link";
2649 		break;
2650 	case PLOGX_IOCBERR_NOIOCB:
2651 		msg = "no IOCB buffer";
2652 		break;
2653 	case PLOGX_IOCBERR_NOXGHG:
2654 		msg = "no Exchange Control Block";
2655 		break;
2656 	case PLOGX_IOCBERR_FAILED:
2657 		ISP_SNPRINTF(buf, sizeof (buf), "reason 0x%x (last LOGIN state 0x%x)", parm1 & 0xff, (parm1 >> 8) & 0xff);
2658 		msg = buf;
2659 		break;
2660 	case PLOGX_IOCBERR_NOFABRIC:
2661 		msg = "no fabric";
2662 		break;
2663 	case PLOGX_IOCBERR_NOTREADY:
2664 		msg = "firmware not ready";
2665 		break;
2666 	case PLOGX_IOCBERR_NOLOGIN:
2667 		ISP_SNPRINTF(buf, sizeof (buf), "not logged in (last state 0x%x)", parm1);
2668 		msg = buf;
2669 		rval = MBOX_NOT_LOGGED_IN;
2670 		break;
2671 	case PLOGX_IOCBERR_REJECT:
2672 		ISP_SNPRINTF(buf, sizeof (buf), "LS_RJT = 0x%x", parm1);
2673 		msg = buf;
2674 		break;
2675 	case PLOGX_IOCBERR_NOPCB:
2676 		msg = "no PCB allocated";
2677 		break;
2678 	case PLOGX_IOCBERR_EINVAL:
2679 		ISP_SNPRINTF(buf, sizeof (buf), "invalid parameter at offset 0x%x", parm1);
2680 		msg = buf;
2681 		break;
2682 	case PLOGX_IOCBERR_PORTUSED:
2683 		lev = ISP_LOG_SANCFG|ISP_LOG_WARN1;
2684 		ISP_SNPRINTF(buf, sizeof (buf), "already logged in with N-Port handle 0x%x", parm1);
2685 		msg = buf;
2686 		rval = MBOX_PORT_ID_USED | (parm1 << 16);
2687 		break;
2688 	case PLOGX_IOCBERR_HNDLUSED:
2689 		lev = ISP_LOG_SANCFG|ISP_LOG_WARN1;
2690 		ISP_SNPRINTF(buf, sizeof (buf), "handle already used for PortID 0x%06x", parm1);
2691 		msg = buf;
2692 		rval = MBOX_LOOP_ID_USED;
2693 		break;
2694 	case PLOGX_IOCBERR_NOHANDLE:
2695 		msg = "no handle allocated";
2696 		break;
2697 	case PLOGX_IOCBERR_NOFLOGI:
2698 		msg = "no FLOGI_ACC";
2699 		break;
2700 	default:
2701 		ISP_SNPRINTF(buf, sizeof (buf), "status %x from %x", pl.plogx_status, flags);
2702 		msg = buf;
2703 		break;
2704 	}
2705 	if (msg) {
2706 		isp_prt(isp, ISP_LOGERR, "Chan %d PLOGX PortID 0x%06x to N-Port handle 0x%x: %s", chan, portid, handle, msg);
2707 	}
2708 	return (rval);
2709 }
2710 
2711 static int
2712 isp_port_login(ispsoftc_t *isp, uint16_t handle, uint32_t portid)
2713 {
2714 	mbreg_t mbs;
2715 
2716 	MBSINIT(&mbs, MBOX_FABRIC_LOGIN, MBLOGNONE, 500000);
2717 	if (ISP_CAP_2KLOGIN(isp)) {
2718 		mbs.param[1] = handle;
2719 		mbs.ibits = (1 << 10);
2720 	} else {
2721 		mbs.param[1] = handle << 8;
2722 	}
2723 	mbs.param[2] = portid >> 16;
2724 	mbs.param[3] = portid;
2725 	mbs.logval = MBLOGNONE;
2726 	mbs.timeout = 500000;
2727 	isp_mboxcmd(isp, &mbs);
2728 
2729 	switch (mbs.param[0]) {
2730 	case MBOX_PORT_ID_USED:
2731 		isp_prt(isp, ISP_LOG_SANCFG|ISP_LOG_WARN1, "isp_port_login: portid 0x%06x already logged in as 0x%x", portid, mbs.param[1]);
2732 		return (MBOX_PORT_ID_USED | (mbs.param[1] << 16));
2733 
2734 	case MBOX_LOOP_ID_USED:
2735 		isp_prt(isp, ISP_LOG_SANCFG|ISP_LOG_WARN1, "isp_port_login: handle 0x%x in use for port id 0x%02xXXXX", handle, mbs.param[1] & 0xff);
2736 		return (MBOX_LOOP_ID_USED);
2737 
2738 	case MBOX_COMMAND_COMPLETE:
2739 		return (0);
2740 
2741 	case MBOX_COMMAND_ERROR:
2742 		isp_prt(isp, ISP_LOG_SANCFG|ISP_LOG_WARN1, "isp_port_login: error 0x%x in PLOGI to port 0x%06x", mbs.param[1], portid);
2743 		return (MBOX_COMMAND_ERROR);
2744 
2745 	case MBOX_ALL_IDS_USED:
2746 		isp_prt(isp, ISP_LOG_SANCFG|ISP_LOG_WARN1, "isp_port_login: all IDs used for fabric login");
2747 		return (MBOX_ALL_IDS_USED);
2748 
2749 	default:
2750 		isp_prt(isp, ISP_LOG_SANCFG, "isp_port_login: error 0x%x on port login of 0x%06x@0x%0x", mbs.param[0], portid, handle);
2751 		return (mbs.param[0]);
2752 	}
2753 }
2754 
2755 /*
2756  * Pre-24XX fabric port logout
2757  *
2758  * Note that portid is not used
2759  */
2760 static int
2761 isp_port_logout(ispsoftc_t *isp, uint16_t handle, uint32_t portid)
2762 {
2763 	mbreg_t mbs;
2764 
2765 	MBSINIT(&mbs, MBOX_FABRIC_LOGOUT, MBLOGNONE, 500000);
2766 	if (ISP_CAP_2KLOGIN(isp)) {
2767 		mbs.param[1] = handle;
2768 		mbs.ibits = (1 << 10);
2769 	} else {
2770 		mbs.param[1] = handle << 8;
2771 	}
2772 	isp_mboxcmd(isp, &mbs);
2773 	return (mbs.param[0] == MBOX_COMMAND_COMPLETE? 0 : mbs.param[0]);
2774 }
2775 
2776 static int
2777 isp_getpdb(ispsoftc_t *isp, int chan, uint16_t id, isp_pdb_t *pdb)
2778 {
2779 	mbreg_t mbs;
2780 	union {
2781 		isp_pdb_21xx_t fred;
2782 		isp_pdb_24xx_t bill;
2783 	} un;
2784 
2785 	MBSINIT(&mbs, MBOX_GET_PORT_DB,
2786 	    MBLOGALL & ~MBLOGMASK(MBOX_COMMAND_PARAM_ERROR), 250000);
2787 	if (IS_24XX(isp)) {
2788 		mbs.ibits = (1 << 9)|(1 << 10);
2789 		mbs.param[1] = id;
2790 		mbs.param[9] = chan;
2791 	} else if (ISP_CAP_2KLOGIN(isp)) {
2792 		mbs.param[1] = id;
2793 	} else {
2794 		mbs.param[1] = id << 8;
2795 	}
2796 	mbs.param[2] = DMA_WD1(isp->isp_iocb_dma);
2797 	mbs.param[3] = DMA_WD0(isp->isp_iocb_dma);
2798 	mbs.param[6] = DMA_WD3(isp->isp_iocb_dma);
2799 	mbs.param[7] = DMA_WD2(isp->isp_iocb_dma);
2800 	MEMORYBARRIER(isp, SYNC_IFORDEV, 0, sizeof(un), chan);
2801 
2802 	isp_mboxcmd(isp, &mbs);
2803 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE)
2804 		return (mbs.param[0] | (mbs.param[1] << 16));
2805 
2806 	MEMORYBARRIER(isp, SYNC_IFORCPU, 0, sizeof(un), chan);
2807 	if (IS_24XX(isp)) {
2808 		isp_get_pdb_24xx(isp, isp->isp_iocb, &un.bill);
2809 		pdb->handle = un.bill.pdb_handle;
2810 		pdb->prli_word3 = un.bill.pdb_prli_svc3;
2811 		pdb->portid = BITS2WORD_24XX(un.bill.pdb_portid_bits);
2812 		ISP_MEMCPY(pdb->portname, un.bill.pdb_portname, 8);
2813 		ISP_MEMCPY(pdb->nodename, un.bill.pdb_nodename, 8);
2814 		isp_prt(isp, ISP_LOGDEBUG1,
2815 		    "Chan %d handle 0x%x Port 0x%06x flags 0x%x curstate %x",
2816 		    chan, id, pdb->portid, un.bill.pdb_flags,
2817 		    un.bill.pdb_curstate);
2818 		if (un.bill.pdb_curstate < PDB2400_STATE_PLOGI_DONE || un.bill.pdb_curstate > PDB2400_STATE_LOGGED_IN) {
2819 			mbs.param[0] = MBOX_NOT_LOGGED_IN;
2820 			return (mbs.param[0]);
2821 		}
2822 	} else {
2823 		isp_get_pdb_21xx(isp, isp->isp_iocb, &un.fred);
2824 		pdb->handle = un.fred.pdb_loopid;
2825 		pdb->prli_word3 = un.fred.pdb_prli_svc3;
2826 		pdb->portid = BITS2WORD(un.fred.pdb_portid_bits);
2827 		ISP_MEMCPY(pdb->portname, un.fred.pdb_portname, 8);
2828 		ISP_MEMCPY(pdb->nodename, un.fred.pdb_nodename, 8);
2829 		isp_prt(isp, ISP_LOGDEBUG1,
2830 		    "Chan %d handle 0x%x Port 0x%06x", chan, id, pdb->portid);
2831 	}
2832 	return (0);
2833 }
2834 
2835 static int
2836 isp_gethandles(ispsoftc_t *isp, int chan, uint16_t *handles, int *num, int loop)
2837 {
2838 	fcparam *fcp = FCPARAM(isp, chan);
2839 	mbreg_t mbs;
2840 	isp_pnhle_21xx_t el1, *elp1;
2841 	isp_pnhle_23xx_t el3, *elp3;
2842 	isp_pnhle_24xx_t el4, *elp4;
2843 	int i, j;
2844 	uint32_t p;
2845 	uint16_t h;
2846 
2847 	MBSINIT(&mbs, MBOX_GET_ID_LIST, MBLOGALL, 250000);
2848 	if (IS_24XX(isp)) {
2849 		mbs.param[2] = DMA_WD1(fcp->isp_scdma);
2850 		mbs.param[3] = DMA_WD0(fcp->isp_scdma);
2851 		mbs.param[6] = DMA_WD3(fcp->isp_scdma);
2852 		mbs.param[7] = DMA_WD2(fcp->isp_scdma);
2853 		mbs.param[8] = ISP_FC_SCRLEN;
2854 		mbs.param[9] = chan;
2855 	} else {
2856 		mbs.ibits = (1 << 1)|(1 << 2)|(1 << 3)|(1 << 6);
2857 		mbs.param[1] = DMA_WD1(fcp->isp_scdma);
2858 		mbs.param[2] = DMA_WD0(fcp->isp_scdma);
2859 		mbs.param[3] = DMA_WD3(fcp->isp_scdma);
2860 		mbs.param[6] = DMA_WD2(fcp->isp_scdma);
2861 	}
2862 	if (FC_SCRATCH_ACQUIRE(isp, chan)) {
2863 		isp_prt(isp, ISP_LOGERR, sacq);
2864 		return (-1);
2865 	}
2866 	MEMORYBARRIER(isp, SYNC_SFORDEV, 0, ISP_FC_SCRLEN, chan);
2867 	isp_mboxcmd(isp, &mbs);
2868 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
2869 		FC_SCRATCH_RELEASE(isp, chan);
2870 		return (mbs.param[0] | (mbs.param[1] << 16));
2871 	}
2872 	MEMORYBARRIER(isp, SYNC_SFORCPU, 0, ISP_FC_SCRLEN, chan);
2873 	elp1 = fcp->isp_scratch;
2874 	elp3 = fcp->isp_scratch;
2875 	elp4 = fcp->isp_scratch;
2876 	for (i = 0, j = 0; i < mbs.param[1] && j < *num; i++) {
2877 		if (IS_24XX(isp)) {
2878 			isp_get_pnhle_24xx(isp, &elp4[i], &el4);
2879 			p = el4.pnhle_port_id_lo |
2880 			    (el4.pnhle_port_id_hi << 16);
2881 			h = el4.pnhle_handle;
2882 		} else if (IS_23XX(isp)) {
2883 			isp_get_pnhle_23xx(isp, &elp3[i], &el3);
2884 			p = el3.pnhle_port_id_lo |
2885 			    (el3.pnhle_port_id_hi << 16);
2886 			h = el3.pnhle_handle;
2887 		} else { /* 21xx */
2888 			isp_get_pnhle_21xx(isp, &elp1[i], &el1);
2889 			p = el1.pnhle_port_id_lo |
2890 			    ((el1.pnhle_port_id_hi_handle & 0xff) << 16);
2891 			h = el1.pnhle_port_id_hi_handle >> 8;
2892 		}
2893 		if (loop && (p >> 8) != (fcp->isp_portid >> 8))
2894 			continue;
2895 		handles[j++] = h;
2896 	}
2897 	*num = j;
2898 	FC_SCRATCH_RELEASE(isp, chan);
2899 	return (0);
2900 }
2901 
2902 static void
2903 isp_dump_chip_portdb(ispsoftc_t *isp, int chan)
2904 {
2905 	isp_pdb_t pdb;
2906 	uint16_t lim, nphdl;
2907 
2908 	isp_prt(isp, ISP_LOG_SANCFG|ISP_LOGINFO, "Chan %d chip port dump", chan);
2909 	if (ISP_CAP_2KLOGIN(isp)) {
2910 		lim = NPH_MAX_2K;
2911 	} else {
2912 		lim = NPH_MAX;
2913 	}
2914 	for (nphdl = 0; nphdl != lim; nphdl++) {
2915 		if (isp_getpdb(isp, chan, nphdl, &pdb)) {
2916 			continue;
2917 		}
2918 		isp_prt(isp, ISP_LOG_SANCFG|ISP_LOGINFO, "Chan %d Handle 0x%04x "
2919 		    "PortID 0x%06x WWPN 0x%02x%02x%02x%02x%02x%02x%02x%02x",
2920 		    chan, nphdl, pdb.portid, pdb.portname[0], pdb.portname[1],
2921 		    pdb.portname[2], pdb.portname[3], pdb.portname[4],
2922 		    pdb.portname[5], pdb.portname[6], pdb.portname[7]);
2923 	}
2924 }
2925 
2926 static uint64_t
2927 isp_get_wwn(ispsoftc_t *isp, int chan, int nphdl, int nodename)
2928 {
2929 	uint64_t wwn = INI_NONE;
2930 	mbreg_t mbs;
2931 
2932 	MBSINIT(&mbs, MBOX_GET_PORT_NAME,
2933 	    MBLOGALL & ~MBLOGMASK(MBOX_COMMAND_PARAM_ERROR), 500000);
2934 	if (ISP_CAP_2KLOGIN(isp)) {
2935 		mbs.param[1] = nphdl;
2936 		if (nodename) {
2937 			mbs.param[10] = 1;
2938 		}
2939 		mbs.param[9] = chan;
2940 	} else {
2941 		mbs.ibitm = 3;
2942 		mbs.param[1] = nphdl << 8;
2943 		if (nodename) {
2944 			mbs.param[1] |= 1;
2945 		}
2946 	}
2947 	isp_mboxcmd(isp, &mbs);
2948 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
2949 		return (wwn);
2950 	}
2951 	if (IS_24XX(isp)) {
2952 		wwn =
2953 		    (((uint64_t)(mbs.param[2] >> 8))	<< 56) |
2954 		    (((uint64_t)(mbs.param[2] & 0xff))	<< 48) |
2955 		    (((uint64_t)(mbs.param[3] >> 8))	<< 40) |
2956 		    (((uint64_t)(mbs.param[3] & 0xff))	<< 32) |
2957 		    (((uint64_t)(mbs.param[6] >> 8))	<< 24) |
2958 		    (((uint64_t)(mbs.param[6] & 0xff))	<< 16) |
2959 		    (((uint64_t)(mbs.param[7] >> 8))	<<  8) |
2960 		    (((uint64_t)(mbs.param[7] & 0xff)));
2961 	} else {
2962 		wwn =
2963 		    (((uint64_t)(mbs.param[2] & 0xff))  << 56) |
2964 		    (((uint64_t)(mbs.param[2] >> 8))	<< 48) |
2965 		    (((uint64_t)(mbs.param[3] & 0xff))	<< 40) |
2966 		    (((uint64_t)(mbs.param[3] >> 8))	<< 32) |
2967 		    (((uint64_t)(mbs.param[6] & 0xff))	<< 24) |
2968 		    (((uint64_t)(mbs.param[6] >> 8))	<< 16) |
2969 		    (((uint64_t)(mbs.param[7] & 0xff))	<<  8) |
2970 		    (((uint64_t)(mbs.param[7] >> 8)));
2971 	}
2972 	return (wwn);
2973 }
2974 
2975 /*
2976  * Make sure we have good FC link.
2977  */
2978 
2979 static int
2980 isp_fclink_test(ispsoftc_t *isp, int chan, int usdelay)
2981 {
2982 	mbreg_t mbs;
2983 	int i, r;
2984 	uint16_t nphdl;
2985 	fcparam *fcp;
2986 	isp_pdb_t pdb;
2987 	NANOTIME_T hra, hrb;
2988 
2989 	fcp = FCPARAM(isp, chan);
2990 
2991 	if (fcp->isp_loopstate < LOOP_HAVE_LINK)
2992 		return (-1);
2993 	if (fcp->isp_loopstate >= LOOP_LTEST_DONE)
2994 		return (0);
2995 
2996 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d FC link test", chan);
2997 	fcp->isp_loopstate = LOOP_TESTING_LINK;
2998 
2999 	/*
3000 	 * Wait up to N microseconds for F/W to go to a ready state.
3001 	 */
3002 	GET_NANOTIME(&hra);
3003 	while (1) {
3004 		isp_change_fw_state(isp, chan, isp_fw_state(isp, chan));
3005 		if (fcp->isp_fwstate == FW_READY) {
3006 			break;
3007 		}
3008 		if (fcp->isp_loopstate < LOOP_TESTING_LINK)
3009 			goto abort;
3010 		GET_NANOTIME(&hrb);
3011 		if ((NANOTIME_SUB(&hrb, &hra) / 1000 + 1000 >= usdelay))
3012 			break;
3013 		ISP_SLEEP(isp, 1000);
3014 	}
3015 	if (fcp->isp_fwstate != FW_READY) {
3016 		isp_prt(isp, ISP_LOG_SANCFG,
3017 		    "Chan %d Firmware is not ready (%s)",
3018 		    chan, isp_fc_fw_statename(fcp->isp_fwstate));
3019 		return (-1);
3020 	}
3021 
3022 	/*
3023 	 * Get our Loop ID and Port ID.
3024 	 */
3025 	MBSINIT(&mbs, MBOX_GET_LOOP_ID, MBLOGALL, 0);
3026 	mbs.param[9] = chan;
3027 	isp_mboxcmd(isp, &mbs);
3028 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
3029 		return (-1);
3030 	}
3031 
3032 	if (IS_2100(isp)) {
3033 		/*
3034 		 * Don't bother with fabric if we are using really old
3035 		 * 2100 firmware. It's just not worth it.
3036 		 */
3037 		if (ISP_FW_NEWER_THAN(isp, 1, 15, 37))
3038 			fcp->isp_topo = TOPO_FL_PORT;
3039 		else
3040 			fcp->isp_topo = TOPO_NL_PORT;
3041 	} else {
3042 		int topo = (int) mbs.param[6];
3043 		if (topo < TOPO_NL_PORT || topo > TOPO_PTP_STUB) {
3044 			topo = TOPO_PTP_STUB;
3045 		}
3046 		fcp->isp_topo = topo;
3047 	}
3048 	fcp->isp_portid = mbs.param[2] | (mbs.param[3] << 16);
3049 
3050 	if (!TOPO_IS_FABRIC(fcp->isp_topo)) {
3051 		fcp->isp_loopid = mbs.param[1] & 0xff;
3052 	} else if (fcp->isp_topo != TOPO_F_PORT) {
3053 		uint8_t alpa = fcp->isp_portid;
3054 
3055 		for (i = 0; alpa_map[i]; i++) {
3056 			if (alpa_map[i] == alpa)
3057 				break;
3058 		}
3059 		if (alpa_map[i])
3060 			fcp->isp_loopid = i;
3061 	}
3062 
3063 	if (fcp->isp_topo == TOPO_F_PORT || fcp->isp_topo == TOPO_FL_PORT) {
3064 		nphdl = IS_24XX(isp) ? NPH_FL_ID : FL_ID;
3065 		r = isp_getpdb(isp, chan, nphdl, &pdb);
3066 		if (r != 0 || pdb.portid == 0) {
3067 			if (IS_2100(isp)) {
3068 				fcp->isp_topo = TOPO_NL_PORT;
3069 			} else {
3070 				isp_prt(isp, ISP_LOGWARN,
3071 				    "fabric topology, but cannot get info about fabric controller (0x%x)", r);
3072 				fcp->isp_topo = TOPO_PTP_STUB;
3073 			}
3074 			goto not_on_fabric;
3075 		}
3076 
3077 		if (IS_24XX(isp)) {
3078 			fcp->isp_fabric_params = mbs.param[7];
3079 			fcp->isp_sns_hdl = NPH_SNS_ID;
3080 			r = isp_register_fc4_type_24xx(isp, chan);
3081 			if (fcp->isp_loopstate < LOOP_TESTING_LINK)
3082 				goto abort;
3083 			if (r != 0)
3084 				goto not_on_fabric;
3085 			r = isp_register_fc4_features_24xx(isp, chan);
3086 			if (fcp->isp_loopstate < LOOP_TESTING_LINK)
3087 				goto abort;
3088 			if (r != 0)
3089 				goto not_on_fabric;
3090 			r = isp_register_port_name_24xx(isp, chan);
3091 			if (fcp->isp_loopstate < LOOP_TESTING_LINK)
3092 				goto abort;
3093 			if (r != 0)
3094 				goto not_on_fabric;
3095 			isp_register_node_name_24xx(isp, chan);
3096 			if (fcp->isp_loopstate < LOOP_TESTING_LINK)
3097 				goto abort;
3098 		} else {
3099 			fcp->isp_sns_hdl = SNS_ID;
3100 			r = isp_register_fc4_type(isp, chan);
3101 			if (r != 0)
3102 				goto not_on_fabric;
3103 			if (fcp->role == ISP_ROLE_TARGET)
3104 				isp_send_change_request(isp, chan);
3105 		}
3106 	}
3107 
3108 not_on_fabric:
3109 	/* Get link speed. */
3110 	fcp->isp_gbspeed = 1;
3111 	if (IS_23XX(isp) || IS_24XX(isp)) {
3112 		MBSINIT(&mbs, MBOX_GET_SET_DATA_RATE, MBLOGALL, 3000000);
3113 		mbs.param[1] = MBGSD_GET_RATE;
3114 		/* mbs.param[2] undefined if we're just getting rate */
3115 		isp_mboxcmd(isp, &mbs);
3116 		if (mbs.param[0] == MBOX_COMMAND_COMPLETE) {
3117 			if (mbs.param[1] == MBGSD_10GB)
3118 				fcp->isp_gbspeed = 10;
3119 			else if (mbs.param[1] == MBGSD_16GB)
3120 				fcp->isp_gbspeed = 16;
3121 			else if (mbs.param[1] == MBGSD_8GB)
3122 				fcp->isp_gbspeed = 8;
3123 			else if (mbs.param[1] == MBGSD_4GB)
3124 				fcp->isp_gbspeed = 4;
3125 			else if (mbs.param[1] == MBGSD_2GB)
3126 				fcp->isp_gbspeed = 2;
3127 			else if (mbs.param[1] == MBGSD_1GB)
3128 				fcp->isp_gbspeed = 1;
3129 		}
3130 	}
3131 
3132 	if (fcp->isp_loopstate < LOOP_TESTING_LINK) {
3133 abort:
3134 		isp_prt(isp, ISP_LOG_SANCFG,
3135 		    "Chan %d FC link test aborted", chan);
3136 		return (1);
3137 	}
3138 	fcp->isp_loopstate = LOOP_LTEST_DONE;
3139 	isp_prt(isp, ISP_LOG_SANCFG|ISP_LOGCONFIG,
3140 	    "Chan %d WWPN %016jx WWNN %016jx",
3141 	    chan, (uintmax_t)fcp->isp_wwpn, (uintmax_t)fcp->isp_wwnn);
3142 	isp_prt(isp, ISP_LOG_SANCFG|ISP_LOGCONFIG,
3143 	    "Chan %d %dGb %s PortID 0x%06x LoopID 0x%02x",
3144 	    chan, fcp->isp_gbspeed, isp_fc_toponame(fcp), fcp->isp_portid,
3145 	    fcp->isp_loopid);
3146 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d FC link test done", chan);
3147 	return (0);
3148 }
3149 
3150 /*
3151  * Complete the synchronization of our Port Database.
3152  *
3153  * At this point, we've scanned the local loop (if any) and the fabric
3154  * and performed fabric logins on all new devices.
3155  *
3156  * Our task here is to go through our port database removing any entities
3157  * that are still marked probational (issuing PLOGO for ones which we had
3158  * PLOGI'd into) or are dead, and notifying upper layers about new/changed
3159  * devices.
3160  */
3161 static int
3162 isp_pdb_sync(ispsoftc_t *isp, int chan)
3163 {
3164 	fcparam *fcp = FCPARAM(isp, chan);
3165 	fcportdb_t *lp;
3166 	uint16_t dbidx;
3167 
3168 	if (fcp->isp_loopstate < LOOP_FSCAN_DONE)
3169 		return (-1);
3170 	if (fcp->isp_loopstate >= LOOP_READY)
3171 		return (0);
3172 
3173 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d FC PDB sync", chan);
3174 
3175 	fcp->isp_loopstate = LOOP_SYNCING_PDB;
3176 
3177 	for (dbidx = 0; dbidx < MAX_FC_TARG; dbidx++) {
3178 		lp = &fcp->portdb[dbidx];
3179 
3180 		if (lp->state == FC_PORTDB_STATE_NIL)
3181 			continue;
3182 		if (lp->probational && lp->state != FC_PORTDB_STATE_ZOMBIE)
3183 			lp->state = FC_PORTDB_STATE_DEAD;
3184 		switch (lp->state) {
3185 		case FC_PORTDB_STATE_DEAD:
3186 			lp->state = FC_PORTDB_STATE_NIL;
3187 			isp_async(isp, ISPASYNC_DEV_GONE, chan, lp);
3188 			if (lp->autologin == 0) {
3189 				(void) isp_plogx(isp, chan, lp->handle,
3190 				    lp->portid,
3191 				    PLOGX_FLG_CMD_LOGO |
3192 				    PLOGX_FLG_IMPLICIT |
3193 				    PLOGX_FLG_FREE_NPHDL);
3194 			}
3195 			/*
3196 			 * Note that we might come out of this with our state
3197 			 * set to FC_PORTDB_STATE_ZOMBIE.
3198 			 */
3199 			break;
3200 		case FC_PORTDB_STATE_NEW:
3201 			lp->state = FC_PORTDB_STATE_VALID;
3202 			isp_async(isp, ISPASYNC_DEV_ARRIVED, chan, lp);
3203 			break;
3204 		case FC_PORTDB_STATE_CHANGED:
3205 			lp->state = FC_PORTDB_STATE_VALID;
3206 			isp_async(isp, ISPASYNC_DEV_CHANGED, chan, lp);
3207 			lp->portid = lp->new_portid;
3208 			lp->prli_word3 = lp->new_prli_word3;
3209 			break;
3210 		case FC_PORTDB_STATE_VALID:
3211 			isp_async(isp, ISPASYNC_DEV_STAYED, chan, lp);
3212 			break;
3213 		case FC_PORTDB_STATE_ZOMBIE:
3214 			break;
3215 		default:
3216 			isp_prt(isp, ISP_LOGWARN,
3217 			    "isp_pdb_sync: state %d for idx %d",
3218 			    lp->state, dbidx);
3219 			isp_dump_portdb(isp, chan);
3220 		}
3221 	}
3222 
3223 	if (fcp->isp_loopstate < LOOP_SYNCING_PDB) {
3224 		isp_prt(isp, ISP_LOG_SANCFG,
3225 		    "Chan %d FC PDB sync aborted", chan);
3226 		return (1);
3227 	}
3228 
3229 	fcp->isp_loopstate = LOOP_READY;
3230 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d FC PDB sync done", chan);
3231 	return (0);
3232 }
3233 
3234 static void
3235 isp_pdb_add_update(ispsoftc_t *isp, int chan, isp_pdb_t *pdb)
3236 {
3237 	fcportdb_t *lp;
3238 	uint64_t wwnn, wwpn;
3239 
3240 	MAKE_WWN_FROM_NODE_NAME(wwnn, pdb->nodename);
3241 	MAKE_WWN_FROM_NODE_NAME(wwpn, pdb->portname);
3242 
3243 	/* Search port database for the same WWPN. */
3244 	if (isp_find_pdb_by_wwpn(isp, chan, wwpn, &lp)) {
3245 		if (!lp->probational) {
3246 			isp_prt(isp, ISP_LOGERR,
3247 			    "Chan %d Port 0x%06x@0x%04x [%d] is not probational (0x%x)",
3248 			    chan, lp->portid, lp->handle,
3249 			    FC_PORTDB_TGT(isp, chan, lp), lp->state);
3250 			isp_dump_portdb(isp, chan);
3251 			return;
3252 		}
3253 		lp->probational = 0;
3254 		lp->node_wwn = wwnn;
3255 
3256 		/* Old device, nothing new. */
3257 		if (lp->portid == pdb->portid &&
3258 		    lp->handle == pdb->handle &&
3259 		    lp->prli_word3 == pdb->prli_word3) {
3260 			if (lp->state != FC_PORTDB_STATE_NEW)
3261 				lp->state = FC_PORTDB_STATE_VALID;
3262 			isp_prt(isp, ISP_LOG_SANCFG,
3263 			    "Chan %d Port 0x%06x@0x%04x is valid",
3264 			    chan, pdb->portid, pdb->handle);
3265 			return;
3266 		}
3267 
3268 		/* Something has changed. */
3269 		lp->state = FC_PORTDB_STATE_CHANGED;
3270 		lp->handle = pdb->handle;
3271 		lp->new_portid = pdb->portid;
3272 		lp->new_prli_word3 = pdb->prli_word3;
3273 		isp_prt(isp, ISP_LOG_SANCFG,
3274 		    "Chan %d Port 0x%06x@0x%04x is changed",
3275 		    chan, pdb->portid, pdb->handle);
3276 		return;
3277 	}
3278 
3279 	/* It seems like a new port. Find an empty slot for it. */
3280 	if (!isp_find_pdb_empty(isp, chan, &lp)) {
3281 		isp_prt(isp, ISP_LOGERR, "Chan %d out of portdb entries", chan);
3282 		return;
3283 	}
3284 
3285 	ISP_MEMZERO(lp, sizeof (fcportdb_t));
3286 	lp->autologin = 1;
3287 	lp->probational = 0;
3288 	lp->state = FC_PORTDB_STATE_NEW;
3289 	lp->portid = lp->new_portid = pdb->portid;
3290 	lp->prli_word3 = lp->new_prli_word3 = pdb->prli_word3;
3291 	lp->handle = pdb->handle;
3292 	lp->port_wwn = wwpn;
3293 	lp->node_wwn = wwnn;
3294 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d Port 0x%06x@0x%04x is new",
3295 	    chan, pdb->portid, pdb->handle);
3296 }
3297 
3298 /*
3299  * Fix port IDs for logged-in initiators on pre-2400 chips.
3300  * For those chips we are not receiving login events, adding initiators
3301  * based on ATIO requests, but there is no port ID in that structure.
3302  */
3303 static void
3304 isp_fix_portids(ispsoftc_t *isp, int chan)
3305 {
3306 	fcparam *fcp = FCPARAM(isp, chan);
3307 	isp_pdb_t pdb;
3308 	uint64_t wwpn;
3309 	int i, r;
3310 
3311 	for (i = 0; i < MAX_FC_TARG; i++) {
3312 		fcportdb_t *lp = &fcp->portdb[i];
3313 
3314 		if (lp->state == FC_PORTDB_STATE_NIL ||
3315 		    lp->state == FC_PORTDB_STATE_ZOMBIE)
3316 			continue;
3317 		if (VALID_PORT(lp->portid))
3318 			continue;
3319 
3320 		r = isp_getpdb(isp, chan, lp->handle, &pdb);
3321 		if (fcp->isp_loopstate < LOOP_SCANNING_LOOP)
3322 			return;
3323 		if (r != 0) {
3324 			isp_prt(isp, ISP_LOGDEBUG1,
3325 			    "Chan %d FC Scan Loop handle %d returned %x",
3326 			    chan, lp->handle, r);
3327 			continue;
3328 		}
3329 
3330 		MAKE_WWN_FROM_NODE_NAME(wwpn, pdb.portname);
3331 		if (lp->port_wwn != wwpn)
3332 			continue;
3333 		lp->portid = lp->new_portid = pdb.portid;
3334 		isp_prt(isp, ISP_LOG_SANCFG,
3335 		    "Chan %d Port 0x%06x@0x%04x is fixed",
3336 		    chan, pdb.portid, pdb.handle);
3337 	}
3338 }
3339 
3340 /*
3341  * Scan local loop for devices.
3342  */
3343 static int
3344 isp_scan_loop(ispsoftc_t *isp, int chan)
3345 {
3346 	fcparam *fcp = FCPARAM(isp, chan);
3347 	int idx, lim, r;
3348 	isp_pdb_t pdb;
3349 	uint16_t *handles;
3350 	uint16_t handle;
3351 
3352 	if (fcp->isp_loopstate < LOOP_LTEST_DONE)
3353 		return (-1);
3354 	if (fcp->isp_loopstate >= LOOP_LSCAN_DONE)
3355 		return (0);
3356 
3357 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d FC loop scan", chan);
3358 	fcp->isp_loopstate = LOOP_SCANNING_LOOP;
3359 	if (TOPO_IS_FABRIC(fcp->isp_topo)) {
3360 		if (!IS_24XX(isp)) {
3361 			isp_fix_portids(isp, chan);
3362 			if (fcp->isp_loopstate < LOOP_SCANNING_LOOP)
3363 				goto abort;
3364 		}
3365 		isp_prt(isp, ISP_LOG_SANCFG,
3366 		    "Chan %d FC loop scan done (no loop)", chan);
3367 		fcp->isp_loopstate = LOOP_LSCAN_DONE;
3368 		return (0);
3369 	}
3370 
3371 	handles = (uint16_t *)fcp->isp_scanscratch;
3372 	lim = ISP_FC_SCRLEN / 2;
3373 	r = isp_gethandles(isp, chan, handles, &lim, 1);
3374 	if (r != 0) {
3375 		isp_prt(isp, ISP_LOG_SANCFG,
3376 		    "Chan %d Getting list of handles failed with %x", chan, r);
3377 		isp_prt(isp, ISP_LOG_SANCFG,
3378 		    "Chan %d FC loop scan done (bad)", chan);
3379 		return (-1);
3380 	}
3381 
3382 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d Got %d handles",
3383 	    chan, lim);
3384 
3385 	/*
3386 	 * Run through the list and get the port database info for each one.
3387 	 */
3388 	isp_mark_portdb(isp, chan);
3389 	for (idx = 0; idx < lim; idx++) {
3390 		handle = handles[idx];
3391 
3392 		/*
3393 		 * Don't scan "special" ids.
3394 		 */
3395 		if (ISP_CAP_2KLOGIN(isp)) {
3396 			if (handle >= NPH_RESERVED)
3397 				continue;
3398 		} else {
3399 			if (handle >= FL_ID && handle <= SNS_ID)
3400 				continue;
3401 		}
3402 
3403 		/*
3404 		 * In older cards with older f/w GET_PORT_DATABASE has been
3405 		 * known to hang. This trick gets around that problem.
3406 		 */
3407 		if (IS_2100(isp) || IS_2200(isp)) {
3408 			uint64_t node_wwn = isp_get_wwn(isp, chan, handle, 1);
3409 			if (fcp->isp_loopstate < LOOP_SCANNING_LOOP) {
3410 abort:
3411 				isp_prt(isp, ISP_LOG_SANCFG,
3412 				    "Chan %d FC loop scan aborted", chan);
3413 				return (1);
3414 			}
3415 			if (node_wwn == INI_NONE) {
3416 				continue;
3417 			}
3418 		}
3419 
3420 		/*
3421 		 * Get the port database entity for this index.
3422 		 */
3423 		r = isp_getpdb(isp, chan, handle, &pdb);
3424 		if (fcp->isp_loopstate < LOOP_SCANNING_LOOP)
3425 			goto abort;
3426 		if (r != 0) {
3427 			isp_prt(isp, ISP_LOGDEBUG1,
3428 			    "Chan %d FC Scan Loop handle %d returned %x",
3429 			    chan, handle, r);
3430 			continue;
3431 		}
3432 
3433 		isp_pdb_add_update(isp, chan, &pdb);
3434 	}
3435 	if (fcp->isp_loopstate < LOOP_SCANNING_LOOP)
3436 		goto abort;
3437 	fcp->isp_loopstate = LOOP_LSCAN_DONE;
3438 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d FC loop scan done", chan);
3439 	return (0);
3440 }
3441 
3442 /*
3443  * Scan the fabric for devices and add them to our port database.
3444  *
3445  * Use the GID_FT command to get all Port IDs for FC4 SCSI devices it knows.
3446  *
3447  * For 2100-23XX cards, we can use the SNS mailbox command to pass simple
3448  * name server commands to the switch management server via the QLogic f/w.
3449  *
3450  * For the 24XX card, we have to use CT-Pass through run via the Execute IOCB
3451  * mailbox command.
3452  */
3453 #define	GIDLEN	(ISP_FC_SCRLEN - (3 * QENTRY_LEN))
3454 #define	NGENT	((GIDLEN - 16) >> 2)
3455 
3456 #define	XTXOFF	(ISP_FC_SCRLEN - (3 * QENTRY_LEN))	/* CT request */
3457 #define	CTXOFF	(ISP_FC_SCRLEN - (2 * QENTRY_LEN))	/* Request IOCB */
3458 #define	ZTXOFF	(ISP_FC_SCRLEN - (1 * QENTRY_LEN))	/* Response IOCB */
3459 
3460 static int
3461 isp_gid_ft_sns(ispsoftc_t *isp, int chan)
3462 {
3463 	union {
3464 		sns_gid_ft_req_t _x;
3465 		uint8_t _y[SNS_GID_FT_REQ_SIZE];
3466 	} un;
3467 	fcparam *fcp = FCPARAM(isp, chan);
3468 	sns_gid_ft_req_t *rq = &un._x;
3469 	uint8_t *scp = fcp->isp_scratch;
3470 	mbreg_t mbs;
3471 
3472 	isp_prt(isp, ISP_LOGDEBUG0, "Chan %d requesting GID_FT via SNS", chan);
3473 	if (FC_SCRATCH_ACQUIRE(isp, chan)) {
3474 		isp_prt(isp, ISP_LOGERR, sacq);
3475 		return (-1);
3476 	}
3477 
3478 	ISP_MEMZERO(rq, SNS_GID_FT_REQ_SIZE);
3479 	rq->snscb_rblen = GIDLEN >> 1;
3480 	rq->snscb_addr[RQRSP_ADDR0015] = DMA_WD0(fcp->isp_scdma);
3481 	rq->snscb_addr[RQRSP_ADDR1631] = DMA_WD1(fcp->isp_scdma);
3482 	rq->snscb_addr[RQRSP_ADDR3247] = DMA_WD2(fcp->isp_scdma);
3483 	rq->snscb_addr[RQRSP_ADDR4863] = DMA_WD3(fcp->isp_scdma);
3484 	rq->snscb_sblen = 6;
3485 	rq->snscb_cmd = SNS_GID_FT;
3486 	rq->snscb_mword_div_2 = NGENT;
3487 	rq->snscb_fc4_type = FC4_SCSI;
3488 
3489 	isp_put_gid_ft_request(isp, rq, (sns_gid_ft_req_t *)&scp[CTXOFF]);
3490 	MEMORYBARRIER(isp, SYNC_SFORDEV, CTXOFF, SNS_GID_FT_REQ_SIZE, chan);
3491 
3492 	MBSINIT(&mbs, MBOX_SEND_SNS, MBLOGALL, 10000000);
3493 	mbs.param[0] = MBOX_SEND_SNS;
3494 	mbs.param[1] = SNS_GID_FT_REQ_SIZE >> 1;
3495 	mbs.param[2] = DMA_WD1(fcp->isp_scdma + CTXOFF);
3496 	mbs.param[3] = DMA_WD0(fcp->isp_scdma + CTXOFF);
3497 	mbs.param[6] = DMA_WD3(fcp->isp_scdma + CTXOFF);
3498 	mbs.param[7] = DMA_WD2(fcp->isp_scdma + CTXOFF);
3499 	isp_mboxcmd(isp, &mbs);
3500 	if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
3501 		if (mbs.param[0] == MBOX_INVALID_COMMAND) {
3502 			return (1);
3503 		} else {
3504 			return (-1);
3505 		}
3506 	}
3507 	MEMORYBARRIER(isp, SYNC_SFORCPU, 0, GIDLEN, chan);
3508 	if (isp->isp_dblev & ISP_LOGDEBUG1)
3509 		isp_print_bytes(isp, "CT response", GIDLEN, scp);
3510 	isp_get_gid_ft_response(isp, (sns_gid_ft_rsp_t *)scp,
3511 	    (sns_gid_ft_rsp_t *)fcp->isp_scanscratch, NGENT);
3512 	FC_SCRATCH_RELEASE(isp, chan);
3513 	return (0);
3514 }
3515 
3516 static int
3517 isp_ct_passthru(ispsoftc_t *isp, int chan, uint32_t cmd_bcnt, uint32_t rsp_bcnt)
3518 {
3519 	fcparam *fcp = FCPARAM(isp, chan);
3520 	isp_ct_pt_t pt;
3521 	void *reqp;
3522 	uint8_t resp[QENTRY_LEN];
3523 
3524 	/*
3525 	 * Build a Passthrough IOCB in memory.
3526 	 */
3527 	ISP_MEMZERO(&pt, sizeof(pt));
3528 	pt.ctp_header.rqs_entry_count = 1;
3529 	pt.ctp_header.rqs_entry_type = RQSTYPE_CT_PASSTHRU;
3530 	pt.ctp_nphdl = fcp->isp_sns_hdl;
3531 	pt.ctp_cmd_cnt = 1;
3532 	pt.ctp_vpidx = ISP_GET_VPIDX(isp, chan);
3533 	pt.ctp_time = 10;
3534 	pt.ctp_rsp_cnt = 1;
3535 	pt.ctp_rsp_bcnt = rsp_bcnt;
3536 	pt.ctp_cmd_bcnt = cmd_bcnt;
3537 	pt.ctp_dataseg[0].ds_base = DMA_LO32(fcp->isp_scdma+XTXOFF);
3538 	pt.ctp_dataseg[0].ds_basehi = DMA_HI32(fcp->isp_scdma+XTXOFF);
3539 	pt.ctp_dataseg[0].ds_count = cmd_bcnt;
3540 	pt.ctp_dataseg[1].ds_base = DMA_LO32(fcp->isp_scdma);
3541 	pt.ctp_dataseg[1].ds_basehi = DMA_HI32(fcp->isp_scdma);
3542 	pt.ctp_dataseg[1].ds_count = rsp_bcnt;
3543 
3544 	/* Prepare space for response in memory */
3545 	memset(resp, 0xff, sizeof(resp));
3546 	pt.ctp_handle = isp_allocate_handle(isp, resp, ISP_HANDLE_CTRL);
3547 	if (pt.ctp_handle == 0) {
3548 		isp_prt(isp, ISP_LOGERR,
3549 		    "%s: CTP of Chan %d out of handles", __func__, chan);
3550 		return (-1);
3551 	}
3552 
3553 	/* Send request and wait for response. */
3554 	reqp = isp_getrqentry(isp);
3555 	if (reqp == NULL) {
3556 		isp_prt(isp, ISP_LOGERR,
3557 		    "%s: CTP of Chan %d out of rqent", __func__, chan);
3558 		isp_destroy_handle(isp, pt.ctp_handle);
3559 		return (-1);
3560 	}
3561 	isp_put_ct_pt(isp, &pt, (isp_ct_pt_t *)reqp);
3562 	if (isp->isp_dblev & ISP_LOGDEBUG1)
3563 		isp_print_bytes(isp, "CT IOCB request", QENTRY_LEN, reqp);
3564 	ISP_SYNC_REQUEST(isp);
3565 	if (msleep(resp, &isp->isp_lock, 0, "CTP", pt.ctp_time*hz) == EWOULDBLOCK) {
3566 		isp_prt(isp, ISP_LOGERR,
3567 		    "%s: CTP of Chan %d timed out", __func__, chan);
3568 		isp_destroy_handle(isp, pt.ctp_handle);
3569 		return (-1);
3570 	}
3571 	if (isp->isp_dblev & ISP_LOGDEBUG1)
3572 		isp_print_bytes(isp, "CT IOCB response", QENTRY_LEN, resp);
3573 
3574 	isp_get_ct_pt(isp, (isp_ct_pt_t *)resp, &pt);
3575 	if (pt.ctp_status && pt.ctp_status != RQCS_DATA_UNDERRUN) {
3576 		isp_prt(isp, ISP_LOGWARN,
3577 		    "Chan %d GID_FT CT Passthrough returned 0x%x",
3578 		    chan, pt.ctp_status);
3579 		return (-1);
3580 	}
3581 
3582 	return (0);
3583 }
3584 
3585 static int
3586 isp_gid_ft_ct_passthru(ispsoftc_t *isp, int chan)
3587 {
3588 	fcparam *fcp = FCPARAM(isp, chan);
3589 	ct_hdr_t ct;
3590 	uint32_t *rp;
3591 	uint8_t *scp = fcp->isp_scratch;
3592 
3593 	isp_prt(isp, ISP_LOGDEBUG0, "Chan %d requesting GID_FT via CT", chan);
3594 	if (FC_SCRATCH_ACQUIRE(isp, chan)) {
3595 		isp_prt(isp, ISP_LOGERR, sacq);
3596 		return (-1);
3597 	}
3598 
3599 	/*
3600 	 * Build the CT header and command in memory.
3601 	 */
3602 	ISP_MEMZERO(&ct, sizeof (ct));
3603 	ct.ct_revision = CT_REVISION;
3604 	ct.ct_fcs_type = CT_FC_TYPE_FC;
3605 	ct.ct_fcs_subtype = CT_FC_SUBTYPE_NS;
3606 	ct.ct_cmd_resp = SNS_GID_FT;
3607 	ct.ct_bcnt_resid = (GIDLEN - 16) >> 2;
3608 	isp_put_ct_hdr(isp, &ct, (ct_hdr_t *) &scp[XTXOFF]);
3609 	rp = (uint32_t *) &scp[XTXOFF + sizeof(ct)];
3610 	ISP_IOZPUT_32(isp, FC4_SCSI, rp);
3611 	if (isp->isp_dblev & ISP_LOGDEBUG1) {
3612 		isp_print_bytes(isp, "CT request",
3613 		    sizeof(ct) + sizeof(uint32_t), &scp[XTXOFF]);
3614 	}
3615 
3616 	if (isp_ct_passthru(isp, chan, sizeof(ct) + sizeof(uint32_t), GIDLEN)) {
3617 		FC_SCRATCH_RELEASE(isp, chan);
3618 		return (-1);
3619 	}
3620 
3621 	if (isp->isp_dblev & ISP_LOGDEBUG1)
3622 		isp_print_bytes(isp, "CT response", GIDLEN, scp);
3623 	isp_get_gid_ft_response(isp, (sns_gid_ft_rsp_t *)scp,
3624 	    (sns_gid_ft_rsp_t *)fcp->isp_scanscratch, NGENT);
3625 	FC_SCRATCH_RELEASE(isp, chan);
3626 	return (0);
3627 }
3628 
3629 static int
3630 isp_scan_fabric(ispsoftc_t *isp, int chan)
3631 {
3632 	fcparam *fcp = FCPARAM(isp, chan);
3633 	fcportdb_t *lp;
3634 	uint32_t portid;
3635 	uint16_t nphdl;
3636 	isp_pdb_t pdb;
3637 	int portidx, portlim, r;
3638 	sns_gid_ft_rsp_t *rs;
3639 
3640 	if (fcp->isp_loopstate < LOOP_LSCAN_DONE)
3641 		return (-1);
3642 	if (fcp->isp_loopstate >= LOOP_FSCAN_DONE)
3643 		return (0);
3644 
3645 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d FC fabric scan", chan);
3646 	fcp->isp_loopstate = LOOP_SCANNING_FABRIC;
3647 	if (!TOPO_IS_FABRIC(fcp->isp_topo)) {
3648 		fcp->isp_loopstate = LOOP_FSCAN_DONE;
3649 		isp_prt(isp, ISP_LOG_SANCFG,
3650 		    "Chan %d FC fabric scan done (no fabric)", chan);
3651 		return (0);
3652 	}
3653 
3654 	if (fcp->isp_loopstate < LOOP_SCANNING_FABRIC) {
3655 abort:
3656 		FC_SCRATCH_RELEASE(isp, chan);
3657 		isp_prt(isp, ISP_LOG_SANCFG,
3658 		    "Chan %d FC fabric scan aborted", chan);
3659 		return (1);
3660 	}
3661 
3662 	/*
3663 	 * Make sure we still are logged into the fabric controller.
3664 	 */
3665 	nphdl = IS_24XX(isp) ? NPH_FL_ID : FL_ID;
3666 	r = isp_getpdb(isp, chan, nphdl, &pdb);
3667 	if ((r & 0xffff) == MBOX_NOT_LOGGED_IN) {
3668 		isp_dump_chip_portdb(isp, chan);
3669 	}
3670 	if (r) {
3671 		fcp->isp_loopstate = LOOP_LTEST_DONE;
3672 fail:
3673 		isp_prt(isp, ISP_LOG_SANCFG,
3674 		    "Chan %d FC fabric scan done (bad)", chan);
3675 		return (-1);
3676 	}
3677 
3678 	/* Get list of port IDs from SNS. */
3679 	if (IS_24XX(isp))
3680 		r = isp_gid_ft_ct_passthru(isp, chan);
3681 	else
3682 		r = isp_gid_ft_sns(isp, chan);
3683 	if (fcp->isp_loopstate < LOOP_SCANNING_FABRIC)
3684 		goto abort;
3685 	if (r > 0) {
3686 		fcp->isp_loopstate = LOOP_FSCAN_DONE;
3687 		return (-1);
3688 	} else if (r < 0) {
3689 		fcp->isp_loopstate = LOOP_LTEST_DONE;	/* try again */
3690 		return (-1);
3691 	}
3692 
3693 	rs = (sns_gid_ft_rsp_t *) fcp->isp_scanscratch;
3694 	if (fcp->isp_loopstate < LOOP_SCANNING_FABRIC)
3695 		goto abort;
3696 	if (rs->snscb_cthdr.ct_cmd_resp != LS_ACC) {
3697 		int level;
3698 		if (rs->snscb_cthdr.ct_reason == 9 && rs->snscb_cthdr.ct_explanation == 7) {
3699 			level = ISP_LOG_SANCFG;
3700 		} else {
3701 			level = ISP_LOGWARN;
3702 		}
3703 		isp_prt(isp, level, "Chan %d Fabric Nameserver rejected GID_FT"
3704 		    " (Reason=0x%x Expl=0x%x)", chan,
3705 		    rs->snscb_cthdr.ct_reason,
3706 		    rs->snscb_cthdr.ct_explanation);
3707 		fcp->isp_loopstate = LOOP_FSCAN_DONE;
3708 		return (-1);
3709 	}
3710 
3711 	/* Check our buffer was big enough to get the full list. */
3712 	for (portidx = 0; portidx < NGENT-1; portidx++) {
3713 		if (rs->snscb_ports[portidx].control & 0x80)
3714 			break;
3715 	}
3716 	if ((rs->snscb_ports[portidx].control & 0x80) == 0) {
3717 		isp_prt(isp, ISP_LOGWARN,
3718 		    "fabric too big for scratch area: increase ISP_FC_SCRLEN");
3719 	}
3720 	portlim = portidx + 1;
3721 	isp_prt(isp, ISP_LOG_SANCFG,
3722 	    "Chan %d Got %d ports back from name server", chan, portlim);
3723 
3724 	/* Go through the list and remove duplicate port ids. */
3725 	for (portidx = 0; portidx < portlim; portidx++) {
3726 		int npidx;
3727 
3728 		portid =
3729 		    ((rs->snscb_ports[portidx].portid[0]) << 16) |
3730 		    ((rs->snscb_ports[portidx].portid[1]) << 8) |
3731 		    ((rs->snscb_ports[portidx].portid[2]));
3732 
3733 		for (npidx = portidx + 1; npidx < portlim; npidx++) {
3734 			uint32_t new_portid =
3735 			    ((rs->snscb_ports[npidx].portid[0]) << 16) |
3736 			    ((rs->snscb_ports[npidx].portid[1]) << 8) |
3737 			    ((rs->snscb_ports[npidx].portid[2]));
3738 			if (new_portid == portid) {
3739 				break;
3740 			}
3741 		}
3742 
3743 		if (npidx < portlim) {
3744 			rs->snscb_ports[npidx].portid[0] = 0;
3745 			rs->snscb_ports[npidx].portid[1] = 0;
3746 			rs->snscb_ports[npidx].portid[2] = 0;
3747 			isp_prt(isp, ISP_LOG_SANCFG, "Chan %d removing duplicate PortID 0x%06x entry from list", chan, portid);
3748 		}
3749 	}
3750 
3751 	/*
3752 	 * We now have a list of Port IDs for all FC4 SCSI devices
3753 	 * that the Fabric Name server knows about.
3754 	 *
3755 	 * For each entry on this list go through our port database looking
3756 	 * for probational entries- if we find one, then an old entry is
3757 	 * maybe still this one. We get some information to find out.
3758 	 *
3759 	 * Otherwise, it's a new fabric device, and we log into it
3760 	 * (unconditionally). After searching the entire database
3761 	 * again to make sure that we never ever ever ever have more
3762 	 * than one entry that has the same PortID or the same
3763 	 * WWNN/WWPN duple, we enter the device into our database.
3764 	 */
3765 	isp_mark_portdb(isp, chan);
3766 	for (portidx = 0; portidx < portlim; portidx++) {
3767 		portid = ((rs->snscb_ports[portidx].portid[0]) << 16) |
3768 			 ((rs->snscb_ports[portidx].portid[1]) << 8) |
3769 			 ((rs->snscb_ports[portidx].portid[2]));
3770 		isp_prt(isp, ISP_LOG_SANCFG,
3771 		    "Chan %d Checking fabric port 0x%06x", chan, portid);
3772 		if (portid == 0) {
3773 			isp_prt(isp, ISP_LOG_SANCFG,
3774 			    "Chan %d Port at idx %d is zero",
3775 			    chan, portidx);
3776 			continue;
3777 		}
3778 		if (portid == fcp->isp_portid) {
3779 			isp_prt(isp, ISP_LOG_SANCFG,
3780 			    "Chan %d Port 0x%06x is our", chan, portid);
3781 			continue;
3782 		}
3783 
3784 		/* Now search the entire port database for the same portid. */
3785 		if (isp_find_pdb_by_portid(isp, chan, portid, &lp)) {
3786 			if (!lp->probational) {
3787 				isp_prt(isp, ISP_LOGERR,
3788 				    "Chan %d Port 0x%06x@0x%04x [%d] is not probational (0x%x)",
3789 				    chan, lp->portid, lp->handle,
3790 				    FC_PORTDB_TGT(isp, chan, lp), lp->state);
3791 				isp_dump_portdb(isp, chan);
3792 				goto fail;
3793 			}
3794 
3795 			/*
3796 			 * See if we're still logged into it.
3797 			 *
3798 			 * If we aren't, mark it as a dead device and
3799 			 * leave the new portid in the database entry
3800 			 * for somebody further along to decide what to
3801 			 * do (policy choice).
3802 			 *
3803 			 * If we are, check to see if it's the same
3804 			 * device still (it should be). If for some
3805 			 * reason it isn't, mark it as a changed device
3806 			 * and leave the new portid and role in the
3807 			 * database entry for somebody further along to
3808 			 * decide what to do (policy choice).
3809 			 */
3810 			r = isp_getpdb(isp, chan, lp->handle, &pdb);
3811 			if (fcp->isp_loopstate < LOOP_SCANNING_FABRIC)
3812 				goto abort;
3813 			if (r != 0) {
3814 				lp->state = FC_PORTDB_STATE_DEAD;
3815 				isp_prt(isp, ISP_LOG_SANCFG,
3816 				    "Chan %d Port 0x%06x handle 0x%x is dead (%d)",
3817 				    chan, portid, lp->handle, r);
3818 				goto relogin;
3819 			}
3820 
3821 			isp_pdb_add_update(isp, chan, &pdb);
3822 			continue;
3823 		}
3824 
3825 relogin:
3826 		if ((fcp->role & ISP_ROLE_INITIATOR) == 0) {
3827 			isp_prt(isp, ISP_LOG_SANCFG,
3828 			    "Chan %d Port 0x%06x is not logged in", chan, portid);
3829 			continue;
3830 		}
3831 
3832 		if (isp_login_device(isp, chan, portid, &pdb,
3833 		    &FCPARAM(isp, 0)->isp_lasthdl)) {
3834 			if (fcp->isp_loopstate < LOOP_SCANNING_FABRIC)
3835 				goto abort;
3836 			continue;
3837 		}
3838 
3839 		isp_pdb_add_update(isp, chan, &pdb);
3840 	}
3841 
3842 	if (fcp->isp_loopstate < LOOP_SCANNING_FABRIC)
3843 		goto abort;
3844 	fcp->isp_loopstate = LOOP_FSCAN_DONE;
3845 	isp_prt(isp, ISP_LOG_SANCFG, "Chan %d FC fabric scan done", chan);
3846 	return (0);
3847 }
3848 
3849 /*
3850  * Find an unused handle and try and use to login to a port.
3851  */
3852 static int
3853 isp_login_device(ispsoftc_t *isp, int chan, uint32_t portid, isp_pdb_t *p, uint16_t *ohp)
3854 {
3855 	int lim, i, r;
3856 	uint16_t handle;
3857 
3858 	if (ISP_CAP_2KLOGIN(isp)) {
3859 		lim = NPH_MAX_2K;
3860 	} else {
3861 		lim = NPH_MAX;
3862 	}
3863 
3864 	handle = isp_next_handle(isp, ohp);
3865 	for (i = 0; i < lim; i++) {
3866 		if (FCPARAM(isp, chan)->isp_loopstate != LOOP_SCANNING_FABRIC)
3867 			return (-1);
3868 
3869 		/* Check if this handle is free. */
3870 		r = isp_getpdb(isp, chan, handle, p);
3871 		if (r == 0) {
3872 			if (p->portid != portid) {
3873 				/* This handle is busy, try next one. */
3874 				handle = isp_next_handle(isp, ohp);
3875 				continue;
3876 			}
3877 			break;
3878 		}
3879 		if (FCPARAM(isp, chan)->isp_loopstate != LOOP_SCANNING_FABRIC)
3880 			return (-1);
3881 
3882 		/*
3883 		 * Now try and log into the device
3884 		 */
3885 		r = isp_plogx(isp, chan, handle, portid, PLOGX_FLG_CMD_PLOGI);
3886 		if (r == 0) {
3887 			break;
3888 		} else if ((r & 0xffff) == MBOX_PORT_ID_USED) {
3889 			/*
3890 			 * If we get here, then the firmwware still thinks we're logged into this device, but with a different
3891 			 * handle. We need to break that association. We used to try and just substitute the handle, but then
3892 			 * failed to get any data via isp_getpdb (below).
3893 			 */
3894 			if (isp_plogx(isp, chan, r >> 16, portid, PLOGX_FLG_CMD_LOGO | PLOGX_FLG_IMPLICIT | PLOGX_FLG_FREE_NPHDL)) {
3895 				isp_prt(isp, ISP_LOGERR, "baw... logout of %x failed", r >> 16);
3896 			}
3897 			if (FCPARAM(isp, chan)->isp_loopstate != LOOP_SCANNING_FABRIC)
3898 				return (-1);
3899 			r = isp_plogx(isp, chan, handle, portid, PLOGX_FLG_CMD_PLOGI);
3900 			if (r != 0)
3901 				i = lim;
3902 			break;
3903 		} else if ((r & 0xffff) == MBOX_LOOP_ID_USED) {
3904 			/* Try the next handle. */
3905 			handle = isp_next_handle(isp, ohp);
3906 		} else {
3907 			/* Give up. */
3908 			i = lim;
3909 			break;
3910 		}
3911 	}
3912 
3913 	if (i == lim) {
3914 		isp_prt(isp, ISP_LOGWARN, "Chan %d PLOGI 0x%06x failed", chan, portid);
3915 		return (-1);
3916 	}
3917 
3918 	/*
3919 	 * If we successfully logged into it, get the PDB for it
3920 	 * so we can crosscheck that it is still what we think it
3921 	 * is and that we also have the role it plays
3922 	 */
3923 	r = isp_getpdb(isp, chan, handle, p);
3924 	if (r != 0) {
3925 		isp_prt(isp, ISP_LOGERR, "Chan %d new device 0x%06x@0x%x disappeared", chan, portid, handle);
3926 		return (-1);
3927 	}
3928 
3929 	if (p->handle != handle || p->portid != portid) {
3930 		isp_prt(isp, ISP_LOGERR, "Chan %d new device 0x%06x@0x%x changed (0x%06x@0x%0x)",
3931 		    chan, portid, handle, p->portid, p->handle);
3932 		return (-1);
3933 	}
3934 	return (0);
3935 }
3936 
3937 static int
3938 isp_send_change_request(ispsoftc_t *isp, int chan)
3939 {
3940 	mbreg_t mbs;
3941 
3942 	MBSINIT(&mbs, MBOX_SEND_CHANGE_REQUEST, MBLOGALL, 500000);
3943 	mbs.param[1] = 0x03;
3944 	mbs.param[9] = chan;
3945 	isp_mboxcmd(isp, &mbs);
3946 	if (mbs.param[0] == MBOX_COMMAND_COMPLETE) {
3947 		return (0);
3948 	} else {
3949 		isp_prt(isp, ISP_LOGWARN, "Chan %d Send Change Request: 0x%x",
3950 		    chan, mbs.param[0]);
3951 		return (-1);
3952 	}
3953 }
3954 
3955 static int
3956 isp_register_fc4_type(ispsoftc_t *isp, int chan)
3957 {
3958 	fcparam *fcp = FCPARAM(isp, chan);
3959 	uint8_t local[SNS_RFT_ID_REQ_SIZE];
3960 	sns_screq_t *reqp = (sns_screq_t *) local;
3961 	mbreg_t mbs;
3962 
3963 	ISP_MEMZERO((void *) reqp, SNS_RFT_ID_REQ_SIZE);
3964 	reqp->snscb_rblen = SNS_RFT_ID_RESP_SIZE >> 1;
3965 	reqp->snscb_addr[RQRSP_ADDR0015] = DMA_WD0(fcp->isp_scdma + 0x100);
3966 	reqp->snscb_addr[RQRSP_ADDR1631] = DMA_WD1(fcp->isp_scdma + 0x100);
3967 	reqp->snscb_addr[RQRSP_ADDR3247] = DMA_WD2(fcp->isp_scdma + 0x100);
3968 	reqp->snscb_addr[RQRSP_ADDR4863] = DMA_WD3(fcp->isp_scdma + 0x100);
3969 	reqp->snscb_sblen = 22;
3970 	reqp->snscb_data[0] = SNS_RFT_ID;
3971 	reqp->snscb_data[4] = fcp->isp_portid & 0xffff;
3972 	reqp->snscb_data[5] = (fcp->isp_portid >> 16) & 0xff;
3973 	reqp->snscb_data[6] = (1 << FC4_SCSI);
3974 	if (FC_SCRATCH_ACQUIRE(isp, chan)) {
3975 		isp_prt(isp, ISP_LOGERR, sacq);
3976 		return (-1);
3977 	}
3978 	isp_put_sns_request(isp, reqp, (sns_screq_t *) fcp->isp_scratch);
3979 	MBSINIT(&mbs, MBOX_SEND_SNS, MBLOGALL, 1000000);
3980 	mbs.param[1] = SNS_RFT_ID_REQ_SIZE >> 1;
3981 	mbs.param[2] = DMA_WD1(fcp->isp_scdma);
3982 	mbs.param[3] = DMA_WD0(fcp->isp_scdma);
3983 	mbs.param[6] = DMA_WD3(fcp->isp_scdma);
3984 	mbs.param[7] = DMA_WD2(fcp->isp_scdma);
3985 	MEMORYBARRIER(isp, SYNC_SFORDEV, 0, SNS_RFT_ID_REQ_SIZE, chan);
3986 	isp_mboxcmd(isp, &mbs);
3987 	FC_SCRATCH_RELEASE(isp, chan);
3988 	if (mbs.param[0] == MBOX_COMMAND_COMPLETE) {
3989 		return (0);
3990 	} else {
3991 		isp_prt(isp, ISP_LOGWARN, "Chan %d Register FC4 Type: 0x%x",
3992 		    chan, mbs.param[0]);
3993 		return (-1);
3994 	}
3995 }
3996 
3997 static int
3998 isp_register_fc4_type_24xx(ispsoftc_t *isp, int chan)
3999 {
4000 	fcparam *fcp = FCPARAM(isp, chan);
4001 	ct_hdr_t *ct;
4002 	rft_id_t rp;
4003 	uint8_t *scp = fcp->isp_scratch;
4004 
4005 	if (FC_SCRATCH_ACQUIRE(isp, chan)) {
4006 		isp_prt(isp, ISP_LOGERR, sacq);
4007 		return (-1);
4008 	}
4009 
4010 	/*
4011 	 * Build the CT header and command in memory.
4012 	 */
4013 	ISP_MEMZERO(&rp, sizeof(rp));
4014 	ct = &rp.rftid_hdr;
4015 	ct->ct_revision = CT_REVISION;
4016 	ct->ct_fcs_type = CT_FC_TYPE_FC;
4017 	ct->ct_fcs_subtype = CT_FC_SUBTYPE_NS;
4018 	ct->ct_cmd_resp = SNS_RFT_ID;
4019 	ct->ct_bcnt_resid = (sizeof (rft_id_t) - sizeof (ct_hdr_t)) >> 2;
4020 	rp.rftid_portid[0] = fcp->isp_portid >> 16;
4021 	rp.rftid_portid[1] = fcp->isp_portid >> 8;
4022 	rp.rftid_portid[2] = fcp->isp_portid;
4023 	rp.rftid_fc4types[FC4_SCSI >> 5] = 1 << (FC4_SCSI & 0x1f);
4024 	isp_put_rft_id(isp, &rp, (rft_id_t *)&scp[XTXOFF]);
4025 	if (isp->isp_dblev & ISP_LOGDEBUG1)
4026 		isp_print_bytes(isp, "CT request", sizeof(rft_id_t), &scp[XTXOFF]);
4027 
4028 	if (isp_ct_passthru(isp, chan, sizeof(rft_id_t), sizeof(ct_hdr_t))) {
4029 		FC_SCRATCH_RELEASE(isp, chan);
4030 		return (-1);
4031 	}
4032 
4033 	isp_get_ct_hdr(isp, (ct_hdr_t *) scp, ct);
4034 	FC_SCRATCH_RELEASE(isp, chan);
4035 	if (ct->ct_cmd_resp == LS_RJT) {
4036 		isp_prt(isp, ISP_LOG_SANCFG|ISP_LOG_WARN1, "Chan %d Register FC4 Type rejected", chan);
4037 		return (-1);
4038 	} else if (ct->ct_cmd_resp == LS_ACC) {
4039 		isp_prt(isp, ISP_LOG_SANCFG, "Chan %d Register FC4 Type accepted", chan);
4040 	} else {
4041 		isp_prt(isp, ISP_LOGWARN, "Chan %d Register FC4 Type: 0x%x", chan, ct->ct_cmd_resp);
4042 		return (-1);
4043 	}
4044 	return (0);
4045 }
4046 
4047 static int
4048 isp_register_fc4_features_24xx(ispsoftc_t *isp, int chan)
4049 {
4050 	fcparam *fcp = FCPARAM(isp, chan);
4051 	ct_hdr_t *ct;
4052 	rff_id_t rp;
4053 	uint8_t *scp = fcp->isp_scratch;
4054 
4055 	if (FC_SCRATCH_ACQUIRE(isp, chan)) {
4056 		isp_prt(isp, ISP_LOGERR, sacq);
4057 		return (-1);
4058 	}
4059 
4060 	/*
4061 	 * Build the CT header and command in memory.
4062 	 */
4063 	ISP_MEMZERO(&rp, sizeof(rp));
4064 	ct = &rp.rffid_hdr;
4065 	ct->ct_revision = CT_REVISION;
4066 	ct->ct_fcs_type = CT_FC_TYPE_FC;
4067 	ct->ct_fcs_subtype = CT_FC_SUBTYPE_NS;
4068 	ct->ct_cmd_resp = SNS_RFF_ID;
4069 	ct->ct_bcnt_resid = (sizeof (rff_id_t) - sizeof (ct_hdr_t)) >> 2;
4070 	rp.rffid_portid[0] = fcp->isp_portid >> 16;
4071 	rp.rffid_portid[1] = fcp->isp_portid >> 8;
4072 	rp.rffid_portid[2] = fcp->isp_portid;
4073 	rp.rffid_fc4features = 0;
4074 	if (fcp->role & ISP_ROLE_TARGET)
4075 		rp.rffid_fc4features |= 1;
4076 	if (fcp->role & ISP_ROLE_INITIATOR)
4077 		rp.rffid_fc4features |= 2;
4078 	rp.rffid_fc4type = FC4_SCSI;
4079 	isp_put_rff_id(isp, &rp, (rff_id_t *)&scp[XTXOFF]);
4080 	if (isp->isp_dblev & ISP_LOGDEBUG1)
4081 		isp_print_bytes(isp, "CT request", sizeof(rft_id_t), &scp[XTXOFF]);
4082 
4083 	if (isp_ct_passthru(isp, chan, sizeof(rft_id_t), sizeof(ct_hdr_t))) {
4084 		FC_SCRATCH_RELEASE(isp, chan);
4085 		return (-1);
4086 	}
4087 
4088 	isp_get_ct_hdr(isp, (ct_hdr_t *) scp, ct);
4089 	FC_SCRATCH_RELEASE(isp, chan);
4090 	if (ct->ct_cmd_resp == LS_RJT) {
4091 		isp_prt(isp, ISP_LOG_SANCFG|ISP_LOG_WARN1,
4092 		    "Chan %d Register FC4 Features rejected", chan);
4093 		return (-1);
4094 	} else if (ct->ct_cmd_resp == LS_ACC) {
4095 		isp_prt(isp, ISP_LOG_SANCFG,
4096 		    "Chan %d Register FC4 Features accepted", chan);
4097 	} else {
4098 		isp_prt(isp, ISP_LOGWARN,
4099 		    "Chan %d Register FC4 Features: 0x%x", chan, ct->ct_cmd_resp);
4100 		return (-1);
4101 	}
4102 	return (0);
4103 }
4104 
4105 static int
4106 isp_register_port_name_24xx(ispsoftc_t *isp, int chan)
4107 {
4108 	fcparam *fcp = FCPARAM(isp, chan);
4109 	ct_hdr_t *ct;
4110 	rspn_id_t rp;
4111 	uint8_t *scp = fcp->isp_scratch;
4112 	int len;
4113 
4114 	if (FC_SCRATCH_ACQUIRE(isp, chan)) {
4115 		isp_prt(isp, ISP_LOGERR, sacq);
4116 		return (-1);
4117 	}
4118 
4119 	/*
4120 	 * Build the CT header and command in memory.
4121 	 */
4122 	ISP_MEMZERO(&rp, sizeof(rp));
4123 	ct = &rp.rspnid_hdr;
4124 	ct->ct_revision = CT_REVISION;
4125 	ct->ct_fcs_type = CT_FC_TYPE_FC;
4126 	ct->ct_fcs_subtype = CT_FC_SUBTYPE_NS;
4127 	ct->ct_cmd_resp = SNS_RSPN_ID;
4128 	rp.rspnid_portid[0] = fcp->isp_portid >> 16;
4129 	rp.rspnid_portid[1] = fcp->isp_portid >> 8;
4130 	rp.rspnid_portid[2] = fcp->isp_portid;
4131 	rp.rspnid_length = 0;
4132 	len = offsetof(rspn_id_t, rspnid_name);
4133 	mtx_lock(&prison0.pr_mtx);
4134 	rp.rspnid_length += sprintf(&scp[XTXOFF + len + rp.rspnid_length],
4135 	    "%s", prison0.pr_hostname[0] ? prison0.pr_hostname : "FreeBSD");
4136 	mtx_unlock(&prison0.pr_mtx);
4137 	rp.rspnid_length += sprintf(&scp[XTXOFF + len + rp.rspnid_length],
4138 	    ":%s", device_get_nameunit(isp->isp_dev));
4139 	if (chan != 0) {
4140 		rp.rspnid_length += sprintf(&scp[XTXOFF + len +
4141 		    rp.rspnid_length], "/%d", chan);
4142 	}
4143 	len += rp.rspnid_length;
4144 	ct->ct_bcnt_resid = (len - sizeof(ct_hdr_t)) >> 2;
4145 	isp_put_rspn_id(isp, &rp, (rspn_id_t *)&scp[XTXOFF]);
4146 	if (isp->isp_dblev & ISP_LOGDEBUG1)
4147 		isp_print_bytes(isp, "CT request", len, &scp[XTXOFF]);
4148 
4149 	if (isp_ct_passthru(isp, chan, len, sizeof(ct_hdr_t))) {
4150 		FC_SCRATCH_RELEASE(isp, chan);
4151 		return (-1);
4152 	}
4153 
4154 	isp_get_ct_hdr(isp, (ct_hdr_t *) scp, ct);
4155 	FC_SCRATCH_RELEASE(isp, chan);
4156 	if (ct->ct_cmd_resp == LS_RJT) {
4157 		isp_prt(isp, ISP_LOG_SANCFG|ISP_LOG_WARN1,
4158 		    "Chan %d Register Symbolic Port Name rejected", chan);
4159 		return (-1);
4160 	} else if (ct->ct_cmd_resp == LS_ACC) {
4161 		isp_prt(isp, ISP_LOG_SANCFG,
4162 		    "Chan %d Register Symbolic Port Name accepted", chan);
4163 	} else {
4164 		isp_prt(isp, ISP_LOGWARN,
4165 		    "Chan %d Register Symbolic Port Name: 0x%x", chan, ct->ct_cmd_resp);
4166 		return (-1);
4167 	}
4168 	return (0);
4169 }
4170 
4171 static int
4172 isp_register_node_name_24xx(ispsoftc_t *isp, int chan)
4173 {
4174 	fcparam *fcp = FCPARAM(isp, chan);
4175 	ct_hdr_t *ct;
4176 	rsnn_nn_t rp;
4177 	uint8_t *scp = fcp->isp_scratch;
4178 	int len;
4179 
4180 	if (FC_SCRATCH_ACQUIRE(isp, chan)) {
4181 		isp_prt(isp, ISP_LOGERR, sacq);
4182 		return (-1);
4183 	}
4184 
4185 	/*
4186 	 * Build the CT header and command in memory.
4187 	 */
4188 	ISP_MEMZERO(&rp, sizeof(rp));
4189 	ct = &rp.rsnnnn_hdr;
4190 	ct->ct_revision = CT_REVISION;
4191 	ct->ct_fcs_type = CT_FC_TYPE_FC;
4192 	ct->ct_fcs_subtype = CT_FC_SUBTYPE_NS;
4193 	ct->ct_cmd_resp = SNS_RSNN_NN;
4194 	MAKE_NODE_NAME_FROM_WWN(rp.rsnnnn_nodename, fcp->isp_wwnn);
4195 	rp.rsnnnn_length = 0;
4196 	len = offsetof(rsnn_nn_t, rsnnnn_name);
4197 	mtx_lock(&prison0.pr_mtx);
4198 	rp.rsnnnn_length += sprintf(&scp[XTXOFF + len + rp.rsnnnn_length],
4199 	    "%s", prison0.pr_hostname[0] ? prison0.pr_hostname : "FreeBSD");
4200 	mtx_unlock(&prison0.pr_mtx);
4201 	len += rp.rsnnnn_length;
4202 	ct->ct_bcnt_resid = (len - sizeof(ct_hdr_t)) >> 2;
4203 	isp_put_rsnn_nn(isp, &rp, (rsnn_nn_t *)&scp[XTXOFF]);
4204 	if (isp->isp_dblev & ISP_LOGDEBUG1)
4205 		isp_print_bytes(isp, "CT request", len, &scp[XTXOFF]);
4206 
4207 	if (isp_ct_passthru(isp, chan, len, sizeof(ct_hdr_t))) {
4208 		FC_SCRATCH_RELEASE(isp, chan);
4209 		return (-1);
4210 	}
4211 
4212 	isp_get_ct_hdr(isp, (ct_hdr_t *) scp, ct);
4213 	FC_SCRATCH_RELEASE(isp, chan);
4214 	if (ct->ct_cmd_resp == LS_RJT) {
4215 		isp_prt(isp, ISP_LOG_SANCFG|ISP_LOG_WARN1,
4216 		    "Chan %d Register Symbolic Node Name rejected", chan);
4217 		return (-1);
4218 	} else if (ct->ct_cmd_resp == LS_ACC) {
4219 		isp_prt(isp, ISP_LOG_SANCFG,
4220 		    "Chan %d Register Symbolic Node Name accepted", chan);
4221 	} else {
4222 		isp_prt(isp, ISP_LOGWARN,
4223 		    "Chan %d Register Symbolic Node Name: 0x%x", chan, ct->ct_cmd_resp);
4224 		return (-1);
4225 	}
4226 	return (0);
4227 }
4228 
4229 static uint16_t
4230 isp_next_handle(ispsoftc_t *isp, uint16_t *ohp)
4231 {
4232 	fcparam *fcp;
4233 	int i, chan, wrap;
4234 	uint16_t handle, minh, maxh;
4235 
4236 	handle = *ohp;
4237 	if (ISP_CAP_2KLOGIN(isp)) {
4238 		minh = 0;
4239 		maxh = NPH_RESERVED - 1;
4240 	} else {
4241 		minh = SNS_ID + 1;
4242 		maxh = NPH_MAX - 1;
4243 	}
4244 	wrap = 0;
4245 
4246 next:
4247 	if (handle == NIL_HANDLE) {
4248 		handle = minh;
4249 	} else {
4250 		handle++;
4251 		if (handle > maxh) {
4252 			if (++wrap >= 2) {
4253 				isp_prt(isp, ISP_LOGERR, "Out of port handles!");
4254 				return (NIL_HANDLE);
4255 			}
4256 			handle = minh;
4257 		}
4258 	}
4259 	for (chan = 0; chan < isp->isp_nchan; chan++) {
4260 		fcp = FCPARAM(isp, chan);
4261 		if (fcp->role == ISP_ROLE_NONE)
4262 			continue;
4263 		for (i = 0; i < MAX_FC_TARG; i++) {
4264 			if (fcp->portdb[i].state != FC_PORTDB_STATE_NIL &&
4265 			    fcp->portdb[i].handle == handle)
4266 				goto next;
4267 		}
4268 	}
4269 	*ohp = handle;
4270 	return (handle);
4271 }
4272 
4273 /*
4274  * Start a command. Locking is assumed done in the caller.
4275  */
4276 
4277 int
4278 isp_start(XS_T *xs)
4279 {
4280 	ispsoftc_t *isp;
4281 	uint32_t cdblen;
4282 	uint8_t local[QENTRY_LEN];
4283 	ispreq_t *reqp;
4284 	void *cdbp, *qep;
4285 	uint16_t *tptr;
4286 	fcportdb_t *lp;
4287 	int target, dmaresult;
4288 
4289 	XS_INITERR(xs);
4290 	isp = XS_ISP(xs);
4291 
4292 	/*
4293 	 * Check command CDB length, etc.. We really are limited to 16 bytes
4294 	 * for Fibre Channel, but can do up to 44 bytes in parallel SCSI,
4295 	 * but probably only if we're running fairly new firmware (we'll
4296 	 * let the old f/w choke on an extended command queue entry).
4297 	 */
4298 
4299 	if (XS_CDBLEN(xs) > (IS_FC(isp)? 16 : 44) || XS_CDBLEN(xs) == 0) {
4300 		isp_prt(isp, ISP_LOGERR, "unsupported cdb length (%d, CDB[0]=0x%x)", XS_CDBLEN(xs), XS_CDBP(xs)[0] & 0xff);
4301 		XS_SETERR(xs, HBA_BOTCH);
4302 		return (CMD_COMPLETE);
4303 	}
4304 
4305 	/*
4306 	 * Translate the target to device handle as appropriate, checking
4307 	 * for correct device state as well.
4308 	 */
4309 	target = XS_TGT(xs);
4310 	if (IS_FC(isp)) {
4311 		fcparam *fcp = FCPARAM(isp, XS_CHANNEL(xs));
4312 
4313 		if ((fcp->role & ISP_ROLE_INITIATOR) == 0) {
4314 			isp_prt(isp, ISP_LOG_WARN1,
4315 			    "%d.%d.%jx I am not an initiator",
4316 			    XS_CHANNEL(xs), target, (uintmax_t)XS_LUN(xs));
4317 			XS_SETERR(xs, HBA_SELTIMEOUT);
4318 			return (CMD_COMPLETE);
4319 		}
4320 
4321 		if (isp->isp_state != ISP_RUNSTATE) {
4322 			isp_prt(isp, ISP_LOGERR, "Adapter not at RUNSTATE");
4323 			XS_SETERR(xs, HBA_BOTCH);
4324 			return (CMD_COMPLETE);
4325 		}
4326 
4327 		/*
4328 		 * Try again later.
4329 		 */
4330 		if (fcp->isp_loopstate != LOOP_READY) {
4331 			return (CMD_RQLATER);
4332 		}
4333 
4334 		isp_prt(isp, ISP_LOGDEBUG2, "XS_TGT(xs)=%d", target);
4335 		lp = &fcp->portdb[target];
4336 		if (target < 0 || target >= MAX_FC_TARG ||
4337 		    lp->is_target == 0) {
4338 			XS_SETERR(xs, HBA_SELTIMEOUT);
4339 			return (CMD_COMPLETE);
4340 		}
4341 		if (lp->state == FC_PORTDB_STATE_ZOMBIE) {
4342 			isp_prt(isp, ISP_LOGDEBUG1,
4343 			    "%d.%d.%jx target zombie",
4344 			    XS_CHANNEL(xs), target, (uintmax_t)XS_LUN(xs));
4345 			return (CMD_RQLATER);
4346 		}
4347 		if (lp->state != FC_PORTDB_STATE_VALID) {
4348 			isp_prt(isp, ISP_LOGDEBUG1,
4349 			    "%d.%d.%jx bad db port state 0x%x",
4350 			    XS_CHANNEL(xs), target, (uintmax_t)XS_LUN(xs), lp->state);
4351 			XS_SETERR(xs, HBA_SELTIMEOUT);
4352 			return (CMD_COMPLETE);
4353 		}
4354 	} else {
4355 		sdparam *sdp = SDPARAM(isp, XS_CHANNEL(xs));
4356 		if (isp->isp_state != ISP_RUNSTATE) {
4357 			isp_prt(isp, ISP_LOGERR, "Adapter not at RUNSTATE");
4358 			XS_SETERR(xs, HBA_BOTCH);
4359 			return (CMD_COMPLETE);
4360 		}
4361 
4362 		if (sdp->update) {
4363 			isp_spi_update(isp, XS_CHANNEL(xs));
4364 		}
4365 		lp = NULL;
4366 	}
4367 
4368  start_again:
4369 
4370 	qep = isp_getrqentry(isp);
4371 	if (qep == NULL) {
4372 		isp_prt(isp, ISP_LOG_WARN1, "Request Queue Overflow");
4373 		XS_SETERR(xs, HBA_BOTCH);
4374 		return (CMD_EAGAIN);
4375 	}
4376 	XS_SETERR(xs, HBA_NOERROR);
4377 
4378 	/*
4379 	 * Now see if we need to synchronize the ISP with respect to anything.
4380 	 * We do dual duty here (cough) for synchronizing for busses other
4381 	 * than which we got here to send a command to.
4382 	 */
4383 	reqp = (ispreq_t *) local;
4384 	ISP_MEMZERO(local, QENTRY_LEN);
4385 	if (ISP_TST_SENDMARKER(isp, XS_CHANNEL(xs))) {
4386 		if (IS_24XX(isp)) {
4387 			isp_marker_24xx_t *m = (isp_marker_24xx_t *) reqp;
4388 			m->mrk_header.rqs_entry_count = 1;
4389 			m->mrk_header.rqs_entry_type = RQSTYPE_MARKER;
4390 			m->mrk_modifier = SYNC_ALL;
4391 			m->mrk_vphdl = XS_CHANNEL(xs);
4392 			isp_put_marker_24xx(isp, m, qep);
4393 		} else {
4394 			isp_marker_t *m = (isp_marker_t *) reqp;
4395 			m->mrk_header.rqs_entry_count = 1;
4396 			m->mrk_header.rqs_entry_type = RQSTYPE_MARKER;
4397 			m->mrk_target = (XS_CHANNEL(xs) << 7);	/* bus # */
4398 			m->mrk_modifier = SYNC_ALL;
4399 			isp_put_marker(isp, m, qep);
4400 		}
4401 		ISP_SYNC_REQUEST(isp);
4402 		ISP_SET_SENDMARKER(isp, XS_CHANNEL(xs), 0);
4403 		goto start_again;
4404 	}
4405 
4406 	reqp->req_header.rqs_entry_count = 1;
4407 
4408 	/*
4409 	 * Select and install Header Code.
4410 	 * Note that it might be overridden before going out
4411 	 * if we're on a 64 bit platform. The lower level
4412 	 * code (isp_send_cmd) will select the appropriate
4413 	 * 64 bit variant if it needs to.
4414 	 */
4415 	if (IS_24XX(isp)) {
4416 		reqp->req_header.rqs_entry_type = RQSTYPE_T7RQS;
4417 	} else if (IS_FC(isp)) {
4418 		reqp->req_header.rqs_entry_type = RQSTYPE_T2RQS;
4419 	} else {
4420 		if (XS_CDBLEN(xs) > 12) {
4421 			reqp->req_header.rqs_entry_type = RQSTYPE_CMDONLY;
4422 		} else {
4423 			reqp->req_header.rqs_entry_type = RQSTYPE_REQUEST;
4424 		}
4425 	}
4426 
4427 	/*
4428 	 * Set task attributes
4429 	 */
4430 	if (IS_24XX(isp)) {
4431 		int ttype;
4432 		if (XS_TAG_P(xs)) {
4433 			ttype = XS_TAG_TYPE(xs);
4434 		} else {
4435 			if (XS_CDBP(xs)[0] == 0x3) {
4436 				ttype = REQFLAG_HTAG;
4437 			} else {
4438 				ttype = REQFLAG_STAG;
4439 			}
4440 		}
4441 		if (ttype == REQFLAG_OTAG) {
4442 			ttype = FCP_CMND_TASK_ATTR_ORDERED;
4443 		} else if (ttype == REQFLAG_HTAG) {
4444 			ttype = FCP_CMND_TASK_ATTR_HEAD;
4445 		} else {
4446 			ttype = FCP_CMND_TASK_ATTR_SIMPLE;
4447 		}
4448 		((ispreqt7_t *)reqp)->req_task_attribute = ttype;
4449 	} else if (IS_FC(isp)) {
4450 		/*
4451 		 * See comment in isp_intr
4452 		 */
4453 		/* XS_SET_RESID(xs, 0); */
4454 
4455 		/*
4456 		 * Fibre Channel always requires some kind of tag.
4457 		 * The Qlogic drivers seem be happy not to use a tag,
4458 		 * but this breaks for some devices (IBM drives).
4459 		 */
4460 		if (XS_TAG_P(xs)) {
4461 			((ispreqt2_t *)reqp)->req_flags = XS_TAG_TYPE(xs);
4462 		} else {
4463 			/*
4464 			 * If we don't know what tag to use, use HEAD OF QUEUE
4465 			 * for Request Sense or Simple.
4466 			 */
4467 			if (XS_CDBP(xs)[0] == 0x3)	/* REQUEST SENSE */
4468 				((ispreqt2_t *)reqp)->req_flags = REQFLAG_HTAG;
4469 			else
4470 				((ispreqt2_t *)reqp)->req_flags = REQFLAG_STAG;
4471 		}
4472 	} else {
4473 		sdparam *sdp = SDPARAM(isp, XS_CHANNEL(xs));
4474 		if ((sdp->isp_devparam[target].actv_flags & DPARM_TQING) && XS_TAG_P(xs)) {
4475 			reqp->req_flags = XS_TAG_TYPE(xs);
4476 		}
4477 	}
4478 
4479 	tptr = &reqp->req_time;
4480 
4481 	/*
4482 	 * NB: we do not support long CDBs (yet)
4483 	 */
4484 	cdblen = XS_CDBLEN(xs);
4485 
4486 	if (IS_SCSI(isp)) {
4487 		if (cdblen > sizeof (reqp->req_cdb)) {
4488 			isp_prt(isp, ISP_LOGERR, "Command Length %u too long for this chip", cdblen);
4489 			XS_SETERR(xs, HBA_BOTCH);
4490 			return (CMD_COMPLETE);
4491 		}
4492 		reqp->req_target = target | (XS_CHANNEL(xs) << 7);
4493 		reqp->req_lun_trn = XS_LUN(xs);
4494 		cdbp = reqp->req_cdb;
4495 		reqp->req_cdblen = cdblen;
4496 	} else if (IS_24XX(isp)) {
4497 		ispreqt7_t *t7 = (ispreqt7_t *)local;
4498 
4499 		if (cdblen > sizeof (t7->req_cdb)) {
4500 			isp_prt(isp, ISP_LOGERR, "Command Length %u too long for this chip", cdblen);
4501 			XS_SETERR(xs, HBA_BOTCH);
4502 			return (CMD_COMPLETE);
4503 		}
4504 
4505 		t7->req_nphdl = lp->handle;
4506 		t7->req_tidlo = lp->portid;
4507 		t7->req_tidhi = lp->portid >> 16;
4508 		t7->req_vpidx = ISP_GET_VPIDX(isp, XS_CHANNEL(xs));
4509 #if __FreeBSD_version >= 1000700
4510 		be64enc(t7->req_lun, CAM_EXTLUN_BYTE_SWIZZLE(XS_LUN(xs)));
4511 #else
4512 		if (XS_LUN(xs) >= 256) {
4513 			t7->req_lun[0] = XS_LUN(xs) >> 8;
4514 			t7->req_lun[0] |= 0x40;
4515 		}
4516 		t7->req_lun[1] = XS_LUN(xs);
4517 #endif
4518 		if (FCPARAM(isp, XS_CHANNEL(xs))->fctape_enabled && (lp->prli_word3 & PRLI_WD3_RETRY)) {
4519 			if (FCP_NEXT_CRN(isp, &t7->req_crn, xs)) {
4520 				isp_prt(isp, ISP_LOG_WARN1,
4521 				    "%d.%d.%jx cannot generate next CRN",
4522 				    XS_CHANNEL(xs), target, (uintmax_t)XS_LUN(xs));
4523 				XS_SETERR(xs, HBA_BOTCH);
4524 				return (CMD_EAGAIN);
4525 			}
4526 		}
4527 		tptr = &t7->req_time;
4528 		cdbp = t7->req_cdb;
4529 	} else {
4530 		ispreqt2_t *t2 = (ispreqt2_t *)local;
4531 
4532 		if (cdblen > sizeof t2->req_cdb) {
4533 			isp_prt(isp, ISP_LOGERR, "Command Length %u too long for this chip", cdblen);
4534 			XS_SETERR(xs, HBA_BOTCH);
4535 			return (CMD_COMPLETE);
4536 		}
4537 		if (FCPARAM(isp, XS_CHANNEL(xs))->fctape_enabled && (lp->prli_word3 & PRLI_WD3_RETRY)) {
4538 			if (FCP_NEXT_CRN(isp, &t2->req_crn, xs)) {
4539 				isp_prt(isp, ISP_LOG_WARN1,
4540 				    "%d.%d.%jx cannot generate next CRN",
4541 				    XS_CHANNEL(xs), target, (uintmax_t)XS_LUN(xs));
4542 				XS_SETERR(xs, HBA_BOTCH);
4543 				return (CMD_EAGAIN);
4544 			}
4545 		}
4546 		if (ISP_CAP_2KLOGIN(isp)) {
4547 			ispreqt2e_t *t2e = (ispreqt2e_t *)local;
4548 			t2e->req_target = lp->handle;
4549 			t2e->req_scclun = XS_LUN(xs);
4550 #if __FreeBSD_version < 1000700
4551 			if (XS_LUN(xs) >= 256)
4552 				t2e->req_scclun |= 0x4000;
4553 #endif
4554 			cdbp = t2e->req_cdb;
4555 		} else if (ISP_CAP_SCCFW(isp)) {
4556 			ispreqt2_t *t2 = (ispreqt2_t *)local;
4557 			t2->req_target = lp->handle;
4558 			t2->req_scclun = XS_LUN(xs);
4559 #if __FreeBSD_version < 1000700
4560 			if (XS_LUN(xs) >= 256)
4561 				t2->req_scclun |= 0x4000;
4562 #endif
4563 			cdbp = t2->req_cdb;
4564 		} else {
4565 			t2->req_target = lp->handle;
4566 			t2->req_lun_trn = XS_LUN(xs);
4567 			cdbp = t2->req_cdb;
4568 		}
4569 	}
4570 	ISP_MEMCPY(cdbp, XS_CDBP(xs), cdblen);
4571 
4572 	*tptr = (XS_TIME(xs) + 999) / 1000;
4573 	if (IS_24XX(isp) && *tptr > 0x1999) {
4574 		*tptr = 0x1999;
4575 	}
4576 
4577 	/* Whew. Thankfully the same for type 7 requests */
4578 	reqp->req_handle = isp_allocate_handle(isp, xs, ISP_HANDLE_INITIATOR);
4579 	if (reqp->req_handle == 0) {
4580 		isp_prt(isp, ISP_LOG_WARN1, "out of xflist pointers");
4581 		XS_SETERR(xs, HBA_BOTCH);
4582 		return (CMD_EAGAIN);
4583 	}
4584 
4585 	/*
4586 	 * Set up DMA and/or do any platform dependent swizzling of the request entry
4587 	 * so that the Qlogic F/W understands what is being asked of it.
4588 	 *
4589 	 * The callee is responsible for adding all requests at this point.
4590 	 */
4591 	dmaresult = ISP_DMASETUP(isp, xs, reqp);
4592 	if (dmaresult != CMD_QUEUED) {
4593 		isp_destroy_handle(isp, reqp->req_handle);
4594 		/*
4595 		 * dmasetup sets actual error in packet, and
4596 		 * return what we were given to return.
4597 		 */
4598 		return (dmaresult);
4599 	}
4600 	isp_xs_prt(isp, xs, ISP_LOGDEBUG0, "START cmd cdb[0]=0x%x datalen %ld", XS_CDBP(xs)[0], (long) XS_XFRLEN(xs));
4601 	isp->isp_nactive++;
4602 	return (CMD_QUEUED);
4603 }
4604 
4605 /*
4606  * isp control
4607  * Locks (ints blocked) assumed held.
4608  */
4609 
4610 int
4611 isp_control(ispsoftc_t *isp, ispctl_t ctl, ...)
4612 {
4613 	XS_T *xs;
4614 	mbreg_t *mbr, mbs;
4615 	int chan, tgt;
4616 	uint32_t handle;
4617 	va_list ap;
4618 
4619 	switch (ctl) {
4620 	case ISPCTL_RESET_BUS:
4621 		/*
4622 		 * Issue a bus reset.
4623 		 */
4624 		if (IS_24XX(isp)) {
4625 			isp_prt(isp, ISP_LOGERR, "BUS RESET NOT IMPLEMENTED");
4626 			break;
4627 		} else if (IS_FC(isp)) {
4628 			mbs.param[1] = 10;
4629 			chan = 0;
4630 		} else {
4631 			va_start(ap, ctl);
4632 			chan = va_arg(ap, int);
4633 			va_end(ap);
4634 			mbs.param[1] = SDPARAM(isp, chan)->isp_bus_reset_delay;
4635 			if (mbs.param[1] < 2) {
4636 				mbs.param[1] = 2;
4637 			}
4638 			mbs.param[2] = chan;
4639 		}
4640 		MBSINIT(&mbs, MBOX_BUS_RESET, MBLOGALL, 0);
4641 		ISP_SET_SENDMARKER(isp, chan, 1);
4642 		isp_mboxcmd(isp, &mbs);
4643 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
4644 			break;
4645 		}
4646 		isp_prt(isp, ISP_LOGINFO, "driver initiated bus reset of bus %d", chan);
4647 		return (0);
4648 
4649 	case ISPCTL_RESET_DEV:
4650 		va_start(ap, ctl);
4651 		chan = va_arg(ap, int);
4652 		tgt = va_arg(ap, int);
4653 		va_end(ap);
4654 		if (IS_24XX(isp)) {
4655 			uint8_t local[QENTRY_LEN];
4656 			isp24xx_tmf_t *tmf;
4657 			isp24xx_statusreq_t *sp;
4658 			fcparam *fcp = FCPARAM(isp, chan);
4659 			fcportdb_t *lp;
4660 
4661 			if (tgt < 0 || tgt >= MAX_FC_TARG) {
4662 				isp_prt(isp, ISP_LOGWARN, "Chan %d trying to reset bad target %d", chan, tgt);
4663 				break;
4664 			}
4665 			lp = &fcp->portdb[tgt];
4666 			if (lp->is_target == 0 ||
4667 			    lp->state != FC_PORTDB_STATE_VALID) {
4668 				isp_prt(isp, ISP_LOGWARN, "Chan %d abort of no longer valid target %d", chan, tgt);
4669 				break;
4670 			}
4671 
4672 			tmf = (isp24xx_tmf_t *) local;
4673 			ISP_MEMZERO(tmf, QENTRY_LEN);
4674 			tmf->tmf_header.rqs_entry_type = RQSTYPE_TSK_MGMT;
4675 			tmf->tmf_header.rqs_entry_count = 1;
4676 			tmf->tmf_nphdl = lp->handle;
4677 			tmf->tmf_delay = 2;
4678 			tmf->tmf_timeout = 4;
4679 			tmf->tmf_flags = ISP24XX_TMF_TARGET_RESET;
4680 			tmf->tmf_tidlo = lp->portid;
4681 			tmf->tmf_tidhi = lp->portid >> 16;
4682 			tmf->tmf_vpidx = ISP_GET_VPIDX(isp, chan);
4683 			isp_put_24xx_tmf(isp, tmf, isp->isp_iocb);
4684 			MEMORYBARRIER(isp, SYNC_IFORDEV, 0, QENTRY_LEN, chan);
4685 			fcp->sendmarker = 1;
4686 
4687 			isp_prt(isp, ISP_LOGALL, "Chan %d Reset N-Port Handle 0x%04x @ Port 0x%06x", chan, lp->handle, lp->portid);
4688 			MBSINIT(&mbs, MBOX_EXEC_COMMAND_IOCB_A64, MBLOGALL,
4689 			    MBCMD_DEFAULT_TIMEOUT + tmf->tmf_timeout * 1000000);
4690 			mbs.param[1] = QENTRY_LEN;
4691 			mbs.param[2] = DMA_WD1(isp->isp_iocb_dma);
4692 			mbs.param[3] = DMA_WD0(isp->isp_iocb_dma);
4693 			mbs.param[6] = DMA_WD3(isp->isp_iocb_dma);
4694 			mbs.param[7] = DMA_WD2(isp->isp_iocb_dma);
4695 			isp_mboxcmd(isp, &mbs);
4696 			if (mbs.param[0] != MBOX_COMMAND_COMPLETE)
4697 				break;
4698 
4699 			MEMORYBARRIER(isp, SYNC_IFORCPU, QENTRY_LEN, QENTRY_LEN, chan);
4700 			sp = (isp24xx_statusreq_t *) local;
4701 			isp_get_24xx_response(isp, &((isp24xx_statusreq_t *)isp->isp_iocb)[1], sp);
4702 			if (sp->req_completion_status == 0) {
4703 				return (0);
4704 			}
4705 			isp_prt(isp, ISP_LOGWARN, "Chan %d reset of target %d returned 0x%x", chan, tgt, sp->req_completion_status);
4706 			break;
4707 		} else if (IS_FC(isp)) {
4708 			if (ISP_CAP_2KLOGIN(isp)) {
4709 				mbs.param[1] = tgt;
4710 				mbs.ibits = (1 << 10);
4711 			} else {
4712 				mbs.param[1] = (tgt << 8);
4713 			}
4714 		} else {
4715 			mbs.param[1] = (chan << 15) | (tgt << 8);
4716 		}
4717 		MBSINIT(&mbs, MBOX_ABORT_TARGET, MBLOGALL, 0);
4718 		mbs.param[2] = 3;	/* 'delay', in seconds */
4719 		isp_mboxcmd(isp, &mbs);
4720 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
4721 			break;
4722 		}
4723 		isp_prt(isp, ISP_LOGINFO, "Target %d on Bus %d Reset Succeeded", tgt, chan);
4724 		ISP_SET_SENDMARKER(isp, chan, 1);
4725 		return (0);
4726 
4727 	case ISPCTL_ABORT_CMD:
4728 		va_start(ap, ctl);
4729 		xs = va_arg(ap, XS_T *);
4730 		va_end(ap);
4731 
4732 		tgt = XS_TGT(xs);
4733 		chan = XS_CHANNEL(xs);
4734 
4735 		handle = isp_find_handle(isp, xs);
4736 		if (handle == 0) {
4737 			isp_prt(isp, ISP_LOGWARN, "cannot find handle for command to abort");
4738 			break;
4739 		}
4740 		if (IS_24XX(isp)) {
4741 			isp24xx_abrt_t local, *ab = &local;
4742 			fcparam *fcp;
4743 			fcportdb_t *lp;
4744 
4745 			fcp = FCPARAM(isp, chan);
4746 			if (tgt < 0 || tgt >= MAX_FC_TARG) {
4747 				isp_prt(isp, ISP_LOGWARN, "Chan %d trying to abort bad target %d", chan, tgt);
4748 				break;
4749 			}
4750 			lp = &fcp->portdb[tgt];
4751 			if (lp->is_target == 0 ||
4752 			    lp->state != FC_PORTDB_STATE_VALID) {
4753 				isp_prt(isp, ISP_LOGWARN, "Chan %d abort of no longer valid target %d", chan, tgt);
4754 				break;
4755 			}
4756 			isp_prt(isp, ISP_LOGALL, "Chan %d Abort Cmd for N-Port 0x%04x @ Port 0x%06x", chan, lp->handle, lp->portid);
4757 			ISP_MEMZERO(ab, QENTRY_LEN);
4758 			ab->abrt_header.rqs_entry_type = RQSTYPE_ABORT_IO;
4759 			ab->abrt_header.rqs_entry_count = 1;
4760 			ab->abrt_handle = lp->handle;
4761 			ab->abrt_cmd_handle = handle;
4762 			ab->abrt_tidlo = lp->portid;
4763 			ab->abrt_tidhi = lp->portid >> 16;
4764 			ab->abrt_vpidx = ISP_GET_VPIDX(isp, chan);
4765 			isp_put_24xx_abrt(isp, ab, isp->isp_iocb);
4766 			MEMORYBARRIER(isp, SYNC_IFORDEV, 0, 2 * QENTRY_LEN, chan);
4767 
4768 			ISP_MEMZERO(&mbs, sizeof (mbs));
4769 			MBSINIT(&mbs, MBOX_EXEC_COMMAND_IOCB_A64, MBLOGALL, 5000000);
4770 			mbs.param[1] = QENTRY_LEN;
4771 			mbs.param[2] = DMA_WD1(isp->isp_iocb_dma);
4772 			mbs.param[3] = DMA_WD0(isp->isp_iocb_dma);
4773 			mbs.param[6] = DMA_WD3(isp->isp_iocb_dma);
4774 			mbs.param[7] = DMA_WD2(isp->isp_iocb_dma);
4775 
4776 			isp_mboxcmd(isp, &mbs);
4777 			if (mbs.param[0] != MBOX_COMMAND_COMPLETE)
4778 				break;
4779 
4780 			MEMORYBARRIER(isp, SYNC_IFORCPU, QENTRY_LEN, QENTRY_LEN, chan);
4781 			isp_get_24xx_abrt(isp, &((isp24xx_abrt_t *)isp->isp_iocb)[1], ab);
4782 			if (ab->abrt_nphdl == ISP24XX_ABRT_OKAY) {
4783 				return (0);
4784 			}
4785 			isp_prt(isp, ISP_LOGWARN, "Chan %d handle %d abort returned 0x%x", chan, tgt, ab->abrt_nphdl);
4786 			break;
4787 		} else if (IS_FC(isp)) {
4788 			if (ISP_CAP_SCCFW(isp)) {
4789 				if (ISP_CAP_2KLOGIN(isp)) {
4790 					mbs.param[1] = tgt;
4791 				} else {
4792 					mbs.param[1] = tgt << 8;
4793 				}
4794 				mbs.param[6] = XS_LUN(xs);
4795 			} else {
4796 				mbs.param[1] = tgt << 8 | XS_LUN(xs);
4797 			}
4798 		} else {
4799 			mbs.param[1] = (chan << 15) | (tgt << 8) | XS_LUN(xs);
4800 		}
4801 		MBSINIT(&mbs, MBOX_ABORT,
4802 		    MBLOGALL & ~MBLOGMASK(MBOX_COMMAND_ERROR), 0);
4803 		mbs.param[2] = handle;
4804 		isp_mboxcmd(isp, &mbs);
4805 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
4806 			break;
4807 		}
4808 		return (0);
4809 
4810 	case ISPCTL_UPDATE_PARAMS:
4811 
4812 		va_start(ap, ctl);
4813 		chan = va_arg(ap, int);
4814 		va_end(ap);
4815 		isp_spi_update(isp, chan);
4816 		return (0);
4817 
4818 	case ISPCTL_FCLINK_TEST:
4819 
4820 		if (IS_FC(isp)) {
4821 			int usdelay;
4822 			va_start(ap, ctl);
4823 			chan = va_arg(ap, int);
4824 			usdelay = va_arg(ap, int);
4825 			va_end(ap);
4826 			if (usdelay == 0) {
4827 				usdelay =  250000;
4828 			}
4829 			return (isp_fclink_test(isp, chan, usdelay));
4830 		}
4831 		break;
4832 
4833 	case ISPCTL_SCAN_FABRIC:
4834 
4835 		if (IS_FC(isp)) {
4836 			va_start(ap, ctl);
4837 			chan = va_arg(ap, int);
4838 			va_end(ap);
4839 			return (isp_scan_fabric(isp, chan));
4840 		}
4841 		break;
4842 
4843 	case ISPCTL_SCAN_LOOP:
4844 
4845 		if (IS_FC(isp)) {
4846 			va_start(ap, ctl);
4847 			chan = va_arg(ap, int);
4848 			va_end(ap);
4849 			return (isp_scan_loop(isp, chan));
4850 		}
4851 		break;
4852 
4853 	case ISPCTL_PDB_SYNC:
4854 
4855 		if (IS_FC(isp)) {
4856 			va_start(ap, ctl);
4857 			chan = va_arg(ap, int);
4858 			va_end(ap);
4859 			return (isp_pdb_sync(isp, chan));
4860 		}
4861 		break;
4862 
4863 	case ISPCTL_SEND_LIP:
4864 
4865 		if (IS_FC(isp) && !IS_24XX(isp)) {
4866 			MBSINIT(&mbs, MBOX_INIT_LIP, MBLOGALL, 0);
4867 			if (ISP_CAP_2KLOGIN(isp)) {
4868 				mbs.ibits = (1 << 10);
4869 			}
4870 			isp_mboxcmd(isp, &mbs);
4871 			if (mbs.param[0] == MBOX_COMMAND_COMPLETE) {
4872 				return (0);
4873 			}
4874 		}
4875 		break;
4876 
4877 	case ISPCTL_GET_PDB:
4878 		if (IS_FC(isp)) {
4879 			isp_pdb_t *pdb;
4880 			va_start(ap, ctl);
4881 			chan = va_arg(ap, int);
4882 			tgt = va_arg(ap, int);
4883 			pdb = va_arg(ap, isp_pdb_t *);
4884 			va_end(ap);
4885 			return (isp_getpdb(isp, chan, tgt, pdb));
4886 		}
4887 		break;
4888 
4889 	case ISPCTL_GET_NAMES:
4890 	{
4891 		uint64_t *wwnn, *wwnp;
4892 		va_start(ap, ctl);
4893 		chan = va_arg(ap, int);
4894 		tgt = va_arg(ap, int);
4895 		wwnn = va_arg(ap, uint64_t *);
4896 		wwnp = va_arg(ap, uint64_t *);
4897 		va_end(ap);
4898 		if (wwnn == NULL && wwnp == NULL) {
4899 			break;
4900 		}
4901 		if (wwnn) {
4902 			*wwnn = isp_get_wwn(isp, chan, tgt, 1);
4903 			if (*wwnn == INI_NONE) {
4904 				break;
4905 			}
4906 		}
4907 		if (wwnp) {
4908 			*wwnp = isp_get_wwn(isp, chan, tgt, 0);
4909 			if (*wwnp == INI_NONE) {
4910 				break;
4911 			}
4912 		}
4913 		return (0);
4914 	}
4915 	case ISPCTL_RUN_MBOXCMD:
4916 	{
4917 		va_start(ap, ctl);
4918 		mbr = va_arg(ap, mbreg_t *);
4919 		va_end(ap);
4920 		isp_mboxcmd(isp, mbr);
4921 		return (0);
4922 	}
4923 	case ISPCTL_PLOGX:
4924 	{
4925 		isp_plcmd_t *p;
4926 		int r;
4927 
4928 		va_start(ap, ctl);
4929 		p = va_arg(ap, isp_plcmd_t *);
4930 		va_end(ap);
4931 
4932 		if ((p->flags & PLOGX_FLG_CMD_MASK) != PLOGX_FLG_CMD_PLOGI || (p->handle != NIL_HANDLE)) {
4933 			return (isp_plogx(isp, p->channel, p->handle, p->portid, p->flags));
4934 		}
4935 		do {
4936 			isp_next_handle(isp, &p->handle);
4937 			r = isp_plogx(isp, p->channel, p->handle, p->portid, p->flags);
4938 			if ((r & 0xffff) == MBOX_PORT_ID_USED) {
4939 				p->handle = r >> 16;
4940 				r = 0;
4941 				break;
4942 			}
4943 		} while ((r & 0xffff) == MBOX_LOOP_ID_USED);
4944 		return (r);
4945 	}
4946 	case ISPCTL_CHANGE_ROLE:
4947 		if (IS_FC(isp)) {
4948 			int role, r;
4949 
4950 			va_start(ap, ctl);
4951 			chan = va_arg(ap, int);
4952 			role = va_arg(ap, int);
4953 			va_end(ap);
4954 			r = isp_fc_change_role(isp, chan, role);
4955 			return (r);
4956 		}
4957 		break;
4958 	default:
4959 		isp_prt(isp, ISP_LOGERR, "Unknown Control Opcode 0x%x", ctl);
4960 		break;
4961 
4962 	}
4963 	return (-1);
4964 }
4965 
4966 /*
4967  * Interrupt Service Routine(s).
4968  *
4969  * External (OS) framework has done the appropriate locking,
4970  * and the locking will be held throughout this function.
4971  */
4972 
4973 /*
4974  * Limit our stack depth by sticking with the max likely number
4975  * of completions on a request queue at any one time.
4976  */
4977 #ifndef	MAX_REQUESTQ_COMPLETIONS
4978 #define	MAX_REQUESTQ_COMPLETIONS	32
4979 #endif
4980 
4981 void
4982 isp_intr(ispsoftc_t *isp, uint16_t isr, uint16_t sema, uint16_t info)
4983 {
4984 	XS_T *complist[MAX_REQUESTQ_COMPLETIONS], *xs;
4985 	uint32_t iptr, optr, junk;
4986 	int i, nlooked = 0, ndone = 0, continuations_expected = 0;
4987 	int etype, last_etype = 0;
4988 
4989 again:
4990 	/*
4991 	 * Is this a mailbox related interrupt?
4992 	 * The mailbox semaphore will be nonzero if so.
4993 	 */
4994 	if (sema) {
4995  fmbox:
4996 		if (info & MBOX_COMMAND_COMPLETE) {
4997 			isp->isp_intmboxc++;
4998 			if (isp->isp_mboxbsy) {
4999 				int obits = isp->isp_obits;
5000 				isp->isp_mboxtmp[0] = info;
5001 				for (i = 1; i < ISP_NMBOX(isp); i++) {
5002 					if ((obits & (1 << i)) == 0) {
5003 						continue;
5004 					}
5005 					isp->isp_mboxtmp[i] = ISP_READ(isp, MBOX_OFF(i));
5006 				}
5007 				if (isp->isp_mbxwrk0) {
5008 					if (isp_mbox_continue(isp) == 0) {
5009 						return;
5010 					}
5011 				}
5012 				MBOX_NOTIFY_COMPLETE(isp);
5013 			} else {
5014 				isp_prt(isp, ISP_LOGWARN, "mailbox cmd (0x%x) with no waiters", info);
5015 			}
5016 		} else {
5017 			i = IS_FC(isp)? isp_parse_async_fc(isp, info) : isp_parse_async(isp, info);
5018 			if (i < 0) {
5019 				return;
5020 			}
5021 		}
5022 		if ((IS_FC(isp) && info != ASYNC_RIOZIO_STALL) || isp->isp_state != ISP_RUNSTATE) {
5023 			goto out;
5024 		}
5025 	}
5026 
5027 	/*
5028 	 * We can't be getting this now.
5029 	 */
5030 	if (isp->isp_state != ISP_RUNSTATE) {
5031 		/*
5032 		 * This seems to happen to 23XX and 24XX cards- don't know why.
5033 		 */
5034 		 if (isp->isp_mboxbsy && isp->isp_lastmbxcmd == MBOX_ABOUT_FIRMWARE) {
5035 			goto fmbox;
5036 		}
5037 		isp_prt(isp, ISP_LOGINFO, "interrupt (ISR=%x SEMA=%x INFO=%x) "
5038 		    "when not ready", isr, sema, info);
5039 		/*
5040 		 * Thank you very much!  *Burrrp*!
5041 		 */
5042 		isp->isp_residx = ISP_READ(isp, isp->isp_respinrp);
5043 		isp->isp_resodx = isp->isp_residx;
5044 		ISP_WRITE(isp, isp->isp_respoutrp, isp->isp_resodx);
5045 		if (IS_24XX(isp)) {
5046 			ISP_DISABLE_INTS(isp);
5047 		}
5048 		goto out;
5049 	}
5050 
5051 #ifdef	ISP_TARGET_MODE
5052 	/*
5053 	 * Check for ATIO Queue entries.
5054 	 */
5055 	if (IS_24XX(isp) &&
5056 	    (isr == ISPR2HST_ATIO_UPDATE || isr == ISPR2HST_ATIO_RSPQ_UPDATE ||
5057 	     isr == ISPR2HST_ATIO_UPDATE2)) {
5058 		iptr = ISP_READ(isp, BIU2400_ATIO_RSPINP);
5059 		optr = isp->isp_atioodx;
5060 
5061 		while (optr != iptr) {
5062 			uint8_t qe[QENTRY_LEN];
5063 			isphdr_t *hp;
5064 			uint32_t oop;
5065 			void *addr;
5066 
5067 			oop = optr;
5068 			MEMORYBARRIER(isp, SYNC_ATIOQ, oop, QENTRY_LEN, -1);
5069 			addr = ISP_QUEUE_ENTRY(isp->isp_atioq, oop);
5070 			isp_get_hdr(isp, addr, (isphdr_t *)qe);
5071 			hp = (isphdr_t *)qe;
5072 			switch (hp->rqs_entry_type) {
5073 			case RQSTYPE_NOTIFY:
5074 			case RQSTYPE_ATIO:
5075 				(void) isp_target_notify(isp, addr, &oop);
5076 				break;
5077 			default:
5078 				isp_print_qentry(isp, "?ATIOQ entry?", oop, addr);
5079 				break;
5080 			}
5081 			optr = ISP_NXT_QENTRY(oop, RESULT_QUEUE_LEN(isp));
5082 		}
5083 		if (isp->isp_atioodx != optr) {
5084 			ISP_WRITE(isp, BIU2400_ATIO_RSPOUTP, optr);
5085 			isp->isp_atioodx = optr;
5086 		}
5087 	}
5088 #endif
5089 
5090 	/*
5091 	 * You *must* read the Response Queue In Pointer
5092 	 * prior to clearing the RISC interrupt.
5093 	 *
5094 	 * Debounce the 2300 if revision less than 2.
5095 	 */
5096 	if (IS_2100(isp) || (IS_2300(isp) && isp->isp_revision < 2)) {
5097 		i = 0;
5098 		do {
5099 			iptr = ISP_READ(isp, isp->isp_respinrp);
5100 			junk = ISP_READ(isp, isp->isp_respinrp);
5101 		} while (junk != iptr && ++i < 1000);
5102 
5103 		if (iptr != junk) {
5104 			isp_prt(isp, ISP_LOGWARN, "Response Queue Out Pointer Unstable (%x, %x)", iptr, junk);
5105 			goto out;
5106 		}
5107 	} else {
5108 		iptr = ISP_READ(isp, isp->isp_respinrp);
5109 	}
5110 
5111 	optr = isp->isp_resodx;
5112 	if (optr == iptr && sema == 0) {
5113 		/*
5114 		 * There are a lot of these- reasons unknown- mostly on
5115 		 * faster Alpha machines.
5116 		 *
5117 		 * I tried delaying after writing HCCR_CMD_CLEAR_RISC_INT to
5118 		 * make sure the old interrupt went away (to avoid 'ringing'
5119 		 * effects), but that didn't stop this from occurring.
5120 		 */
5121 		if (IS_24XX(isp)) {
5122 			junk = 0;
5123 		} else if (IS_23XX(isp)) {
5124 			ISP_DELAY(100);
5125 			iptr = ISP_READ(isp, isp->isp_respinrp);
5126 			junk = ISP_READ(isp, BIU_R2HSTSLO);
5127 		} else {
5128 			junk = ISP_READ(isp, BIU_ISR);
5129 		}
5130 		if (optr == iptr) {
5131 			if (IS_23XX(isp) || IS_24XX(isp)) {
5132 				;
5133 			} else {
5134 				sema = ISP_READ(isp, BIU_SEMA);
5135 				info = ISP_READ(isp, OUTMAILBOX0);
5136 				if ((sema & 0x3) && (info & 0x8000)) {
5137 					goto again;
5138 				}
5139 			}
5140 			isp->isp_intbogus++;
5141 			isp_prt(isp, ISP_LOGDEBUG1, "bogus intr- isr %x (%x) iptr %x optr %x", isr, junk, iptr, optr);
5142 		}
5143 	}
5144 	isp->isp_residx = iptr;
5145 
5146 	while (optr != iptr) {
5147 		uint8_t qe[QENTRY_LEN];
5148 		ispstatusreq_t *sp = (ispstatusreq_t *) qe;
5149 		isphdr_t *hp;
5150 		int buddaboom, scsi_status, completion_status;
5151 		int req_status_flags, req_state_flags;
5152 		uint8_t *snsp, *resp;
5153 		uint32_t rlen, slen, totslen;
5154 		long resid;
5155 		uint16_t oop;
5156 
5157 		hp = (isphdr_t *) ISP_QUEUE_ENTRY(isp->isp_result, optr);
5158 		oop = optr;
5159 		optr = ISP_NXT_QENTRY(optr, RESULT_QUEUE_LEN(isp));
5160 		nlooked++;
5161  read_again:
5162 		buddaboom = req_status_flags = req_state_flags = 0;
5163 		resid = 0L;
5164 
5165 		/*
5166 		 * Synchronize our view of this response queue entry.
5167 		 */
5168 		MEMORYBARRIER(isp, SYNC_RESULT, oop, QENTRY_LEN, -1);
5169 		if (isp->isp_dblev & ISP_LOGDEBUG1)
5170 			isp_print_qentry(isp, "Response Queue Entry", oop, hp);
5171 		isp_get_hdr(isp, hp, &sp->req_header);
5172 		etype = sp->req_header.rqs_entry_type;
5173 
5174 		if (IS_24XX(isp) && etype == RQSTYPE_RESPONSE) {
5175 			isp24xx_statusreq_t *sp2 = (isp24xx_statusreq_t *)qe;
5176 			isp_get_24xx_response(isp, (isp24xx_statusreq_t *)hp, sp2);
5177 			scsi_status = sp2->req_scsi_status;
5178 			completion_status = sp2->req_completion_status;
5179 			if ((scsi_status & 0xff) != 0)
5180 				req_state_flags = RQSF_GOT_STATUS;
5181 			else
5182 				req_state_flags = 0;
5183 			resid = sp2->req_resid;
5184 		} else if (etype == RQSTYPE_RESPONSE) {
5185 			isp_get_response(isp, (ispstatusreq_t *) hp, sp);
5186 			scsi_status = sp->req_scsi_status;
5187 			completion_status = sp->req_completion_status;
5188 			req_status_flags = sp->req_status_flags;
5189 			req_state_flags = sp->req_state_flags;
5190 			resid = sp->req_resid;
5191 		} else if (etype == RQSTYPE_RIO1) {
5192 			isp_rio1_t *rio = (isp_rio1_t *) qe;
5193 			isp_get_rio1(isp, (isp_rio1_t *) hp, rio);
5194 			for (i = 0; i < rio->req_header.rqs_seqno; i++) {
5195 				isp_fastpost_complete(isp, rio->req_handles[i]);
5196 			}
5197 			if (isp->isp_fpcchiwater < rio->req_header.rqs_seqno) {
5198 				isp->isp_fpcchiwater = rio->req_header.rqs_seqno;
5199 			}
5200 			ISP_MEMZERO(hp, QENTRY_LEN);	/* PERF */
5201 			last_etype = etype;
5202 			continue;
5203 		} else if (etype == RQSTYPE_RIO2) {
5204 			isp_prt(isp, ISP_LOGERR, "dropping RIO2 response");
5205 			ISP_MEMZERO(hp, QENTRY_LEN);	/* PERF */
5206 			last_etype = etype;
5207 			continue;
5208 		} else if (etype == RQSTYPE_STATUS_CONT) {
5209 			isp_get_cont_response(isp, (ispstatus_cont_t *) hp, (ispstatus_cont_t *) sp);
5210 			if (last_etype == RQSTYPE_RESPONSE && continuations_expected && ndone > 0 && (xs = complist[ndone-1]) != NULL) {
5211 				ispstatus_cont_t *scp = (ispstatus_cont_t *) sp;
5212 				XS_SENSE_APPEND(xs, scp->req_sense_data, sizeof (scp->req_sense_data));
5213 				isp_prt(isp, ISP_LOGDEBUG0|ISP_LOG_CWARN, "%d more Status Continuations expected", --continuations_expected);
5214 			} else {
5215 				isp_prt(isp, ISP_LOG_WARN1, "Ignored Continuation Response");
5216 			}
5217 			ISP_MEMZERO(hp, QENTRY_LEN);	/* PERF */
5218 			continue;
5219 		} else {
5220 			/*
5221 			 * Somebody reachable via isp_handle_other_response
5222 			 * may have updated the response queue pointers for
5223 			 * us, so we reload our goal index.
5224 			 */
5225 			int r;
5226 			uint32_t tsto = oop;
5227 			r = isp_handle_other_response(isp, etype, hp, &tsto);
5228 			if (r < 0) {
5229 				goto read_again;
5230 			}
5231 			/*
5232 			 * If somebody updated the output pointer, then reset
5233 			 * optr to be one more than the updated amount.
5234 			 */
5235 			while (tsto != oop) {
5236 				optr = ISP_NXT_QENTRY(tsto, RESULT_QUEUE_LEN(isp));
5237 			}
5238 			if (r > 0) {
5239 				ISP_MEMZERO(hp, QENTRY_LEN);	/* PERF */
5240 				last_etype = etype;
5241 				continue;
5242 			}
5243 
5244 			/*
5245 			 * After this point, we'll just look at the header as
5246 			 * we don't know how to deal with the rest of the
5247 			 * response.
5248 			 */
5249 
5250 			/*
5251 			 * It really has to be a bounced request just copied
5252 			 * from the request queue to the response queue. If
5253 			 * not, something bad has happened.
5254 			 */
5255 			if (etype != RQSTYPE_REQUEST) {
5256 				isp_prt(isp, ISP_LOGERR, notresp, etype, oop, optr, nlooked);
5257 				ISP_MEMZERO(hp, QENTRY_LEN);	/* PERF */
5258 				last_etype = etype;
5259 				continue;
5260 			}
5261 			buddaboom = 1;
5262 			scsi_status = sp->req_scsi_status;
5263 			completion_status = sp->req_completion_status;
5264 			req_status_flags = sp->req_status_flags;
5265 			req_state_flags = sp->req_state_flags;
5266 			resid = sp->req_resid;
5267 		}
5268 
5269 		if (sp->req_header.rqs_flags & RQSFLAG_MASK) {
5270 			if (sp->req_header.rqs_flags & RQSFLAG_CONTINUATION) {
5271 				isp_print_qentry(isp, "unexpected continuation segment",
5272 				    oop, hp);
5273 				last_etype = etype;
5274 				continue;
5275 			}
5276 			if (sp->req_header.rqs_flags & RQSFLAG_FULL) {
5277 				isp_prt(isp, ISP_LOG_WARN1, "internal queues full");
5278 				/*
5279 				 * We'll synthesize a QUEUE FULL message below.
5280 				 */
5281 			}
5282 			if (sp->req_header.rqs_flags & RQSFLAG_BADHEADER) {
5283 				isp_print_qentry(isp, "bad header flag",
5284 				    oop, hp);
5285 				buddaboom++;
5286 			}
5287 			if (sp->req_header.rqs_flags & RQSFLAG_BADPACKET) {
5288 				isp_print_qentry(isp, "bad request packet",
5289 				    oop, hp);
5290 				buddaboom++;
5291 			}
5292 			if (sp->req_header.rqs_flags & RQSFLAG_BADCOUNT) {
5293 				isp_print_qentry(isp, "invalid entry count",
5294 				    oop, hp);
5295 				buddaboom++;
5296 			}
5297 			if (sp->req_header.rqs_flags & RQSFLAG_BADORDER) {
5298 				isp_print_qentry(isp, "invalid IOCB ordering",
5299 				    oop, hp);
5300 				last_etype = etype;
5301 				continue;
5302 			}
5303 		}
5304 
5305 		xs = isp_find_xs(isp, sp->req_handle);
5306 		if (xs == NULL) {
5307 			uint8_t ts = completion_status & 0xff;
5308 			/*
5309 			 * Only whine if this isn't the expected fallout of
5310 			 * aborting the command or resetting the target.
5311 			 */
5312 			if (etype != RQSTYPE_RESPONSE) {
5313 				isp_prt(isp, ISP_LOGERR, "cannot find handle 0x%x (type 0x%x)", sp->req_handle, etype);
5314 			} else if (ts != RQCS_ABORTED && ts != RQCS_RESET_OCCURRED) {
5315 				isp_prt(isp, ISP_LOGERR, "cannot find handle 0x%x (status 0x%x)", sp->req_handle, ts);
5316 			}
5317 			ISP_MEMZERO(hp, QENTRY_LEN);	/* PERF */
5318 			last_etype = etype;
5319 			continue;
5320 		}
5321 		if (req_status_flags & RQSTF_BUS_RESET) {
5322 			isp_prt(isp, ISP_LOG_WARN1, "%d.%d.%jx bus was reset",
5323 			    XS_CHANNEL(xs), XS_TGT(xs), (uintmax_t)XS_LUN(xs));
5324 			XS_SETERR(xs, HBA_BUSRESET);
5325 			ISP_SET_SENDMARKER(isp, XS_CHANNEL(xs), 1);
5326 		}
5327 		if (buddaboom) {
5328 			isp_prt(isp, ISP_LOG_WARN1, "%d.%d.%jx buddaboom",
5329 			    XS_CHANNEL(xs), XS_TGT(xs), (uintmax_t)XS_LUN(xs));
5330 			XS_SETERR(xs, HBA_BOTCH);
5331 		}
5332 
5333 		resp = NULL;
5334 		rlen = 0;
5335 		snsp = NULL;
5336 		totslen = slen = 0;
5337 		if (IS_24XX(isp) && (scsi_status & (RQCS_RV|RQCS_SV)) != 0) {
5338 			resp = ((isp24xx_statusreq_t *)sp)->req_rsp_sense;
5339 			rlen = ((isp24xx_statusreq_t *)sp)->req_response_len;
5340 		} else if (IS_FC(isp) && (scsi_status & RQCS_RV) != 0) {
5341 			resp = sp->req_response;
5342 			rlen = sp->req_response_len;
5343 		}
5344 		if (IS_FC(isp) && (scsi_status & RQCS_SV) != 0) {
5345 			/*
5346 			 * Fibre Channel F/W doesn't say we got status
5347 			 * if there's Sense Data instead. I guess they
5348 			 * think it goes w/o saying.
5349 			 */
5350 			req_state_flags |= RQSF_GOT_STATUS|RQSF_GOT_SENSE;
5351 			if (IS_24XX(isp)) {
5352 				snsp = ((isp24xx_statusreq_t *)sp)->req_rsp_sense;
5353 				snsp += rlen;
5354 				totslen = ((isp24xx_statusreq_t *)sp)->req_sense_len;
5355 				slen = (sizeof (((isp24xx_statusreq_t *)sp)->req_rsp_sense)) - rlen;
5356 				if (totslen < slen)
5357 					slen = totslen;
5358 			} else {
5359 				snsp = sp->req_sense_data;
5360 				totslen = sp->req_sense_len;
5361 				slen = sizeof (sp->req_sense_data);
5362 				if (totslen < slen)
5363 					slen = totslen;
5364 			}
5365 		} else if (IS_SCSI(isp) && (req_state_flags & RQSF_GOT_SENSE)) {
5366 			snsp = sp->req_sense_data;
5367 			totslen = sp->req_sense_len;
5368 			slen = sizeof (sp->req_sense_data);
5369 			if (totslen < slen)
5370 				slen = totslen;
5371 		}
5372 		if (req_state_flags & RQSF_GOT_STATUS) {
5373 			*XS_STSP(xs) = scsi_status & 0xff;
5374 		}
5375 
5376 		switch (etype) {
5377 		case RQSTYPE_RESPONSE:
5378 			if (resp && rlen >= 4 && resp[FCP_RSPNS_CODE_OFFSET] != 0) {
5379 				const char *ptr;
5380 				char lb[64];
5381 				const char *rnames[10] = {
5382 				    "Task Management function complete",
5383 				    "FCP_DATA length different than FCP_BURST_LEN",
5384 				    "FCP_CMND fields invalid",
5385 				    "FCP_DATA parameter mismatch with FCP_DATA_RO",
5386 				    "Task Management function rejected",
5387 				    "Task Management function failed",
5388 				    NULL,
5389 				    NULL,
5390 				    "Task Management function succeeded",
5391 				    "Task Management function incorrect logical unit number",
5392 				};
5393 				uint8_t code = resp[FCP_RSPNS_CODE_OFFSET];
5394 				if (code >= 10 || rnames[code] == NULL) {
5395 					ISP_SNPRINTF(lb, sizeof(lb),
5396 					    "Unknown FCP Response Code 0x%x",
5397 					    code);
5398 					ptr = lb;
5399 				} else {
5400 					ptr = rnames[code];
5401 				}
5402 				isp_xs_prt(isp, xs, ISP_LOGWARN,
5403 				    "FCP RESPONSE, LENGTH %u: %s CDB0=0x%02x",
5404 				    rlen, ptr, XS_CDBP(xs)[0] & 0xff);
5405 				if (code != 0 && code != 8)
5406 					XS_SETERR(xs, HBA_BOTCH);
5407 			}
5408 			if (IS_24XX(isp)) {
5409 				isp_parse_status_24xx(isp, (isp24xx_statusreq_t *)sp, xs, &resid);
5410 			} else {
5411 				isp_parse_status(isp, (void *)sp, xs, &resid);
5412 			}
5413 			if ((XS_NOERR(xs) || XS_ERR(xs) == HBA_NOERROR) && (*XS_STSP(xs) == SCSI_BUSY)) {
5414 				XS_SETERR(xs, HBA_TGTBSY);
5415 			}
5416 			if (IS_SCSI(isp)) {
5417 				XS_SET_RESID(xs, resid);
5418 				/*
5419 				 * A new synchronous rate was negotiated for
5420 				 * this target. Mark state such that we'll go
5421 				 * look up that which has changed later.
5422 				 */
5423 				if (req_status_flags & RQSTF_NEGOTIATION) {
5424 					int t = XS_TGT(xs);
5425 					sdparam *sdp = SDPARAM(isp, XS_CHANNEL(xs));
5426 					sdp->isp_devparam[t].dev_refresh = 1;
5427 					sdp->update = 1;
5428 				}
5429 			} else {
5430 				if (req_status_flags & RQSF_XFER_COMPLETE) {
5431 					XS_SET_RESID(xs, 0);
5432 				} else if (scsi_status & RQCS_RESID) {
5433 					XS_SET_RESID(xs, resid);
5434 				} else {
5435 					XS_SET_RESID(xs, 0);
5436 				}
5437 			}
5438 			if (snsp && slen) {
5439 				if (totslen > slen) {
5440 					continuations_expected += ((totslen - slen + QENTRY_LEN - 5) / (QENTRY_LEN - 4));
5441 					if (ndone > (MAX_REQUESTQ_COMPLETIONS - continuations_expected - 1)) {
5442 						/* we'll lose some stats, but that's a small price to pay */
5443 						for (i = 0; i < ndone; i++) {
5444 							if (complist[i]) {
5445 								isp->isp_rsltccmplt++;
5446 								isp_done(complist[i]);
5447 							}
5448 						}
5449 						ndone = 0;
5450 					}
5451 					isp_prt(isp, ISP_LOGDEBUG0|ISP_LOG_CWARN, "Expecting %d more Status Continuations for total sense length of %u",
5452 					    continuations_expected, totslen);
5453 				}
5454 				XS_SAVE_SENSE(xs, snsp, totslen, slen);
5455 			} else if ((req_status_flags & RQSF_GOT_STATUS) && (scsi_status & 0xff) == SCSI_CHECK && IS_FC(isp)) {
5456 				isp_prt(isp, ISP_LOGWARN, "CHECK CONDITION w/o sense data for CDB=0x%x", XS_CDBP(xs)[0] & 0xff);
5457 				isp_print_qentry(isp, "CC with no Sense",
5458 				    oop, hp);
5459 			}
5460 			isp_prt(isp, ISP_LOGDEBUG2, "asked for %ld got raw resid %ld settled for %ld", (long) XS_XFRLEN(xs), resid, (long) XS_GET_RESID(xs));
5461 			break;
5462 		case RQSTYPE_REQUEST:
5463 		case RQSTYPE_A64:
5464 		case RQSTYPE_T2RQS:
5465 		case RQSTYPE_T3RQS:
5466 		case RQSTYPE_T7RQS:
5467 			if (!IS_24XX(isp) && (sp->req_header.rqs_flags & RQSFLAG_FULL)) {
5468 				/*
5469 				 * Force Queue Full status.
5470 				 */
5471 				*XS_STSP(xs) = SCSI_QFULL;
5472 				XS_SETERR(xs, HBA_NOERROR);
5473 			} else if (XS_NOERR(xs)) {
5474 				isp_prt(isp, ISP_LOG_WARN1,
5475 				    "%d.%d.%jx badness at %s:%u",
5476 				    XS_CHANNEL(xs), XS_TGT(xs),
5477 				    (uintmax_t)XS_LUN(xs),
5478 				    __func__, __LINE__);
5479 				XS_SETERR(xs, HBA_BOTCH);
5480 			}
5481 			XS_SET_RESID(xs, XS_XFRLEN(xs));
5482 			break;
5483 		default:
5484 			isp_print_qentry(isp, "Unhandled Response Type",
5485 			    oop, hp);
5486 			if (XS_NOERR(xs)) {
5487 				XS_SETERR(xs, HBA_BOTCH);
5488 			}
5489 			break;
5490 		}
5491 
5492 		/*
5493 		 * Free any DMA resources. As a side effect, this may
5494 		 * also do any cache flushing necessary for data coherence.
5495 		 */
5496 		if (XS_XFRLEN(xs)) {
5497 			ISP_DMAFREE(isp, xs, sp->req_handle);
5498 		}
5499 		isp_destroy_handle(isp, sp->req_handle);
5500 
5501 		if (isp->isp_nactive > 0) {
5502 		    isp->isp_nactive--;
5503 		}
5504 		complist[ndone++] = xs;	/* defer completion call until later */
5505 		ISP_MEMZERO(hp, QENTRY_LEN);	/* PERF */
5506 		last_etype = etype;
5507 		if (ndone == MAX_REQUESTQ_COMPLETIONS) {
5508 			break;
5509 		}
5510 	}
5511 
5512 	/*
5513 	 * If we looked at any commands, then it's valid to find out
5514 	 * what the outpointer is. It also is a trigger to update the
5515 	 * ISP's notion of what we've seen so far.
5516 	 */
5517 	if (nlooked) {
5518 		ISP_WRITE(isp, isp->isp_respoutrp, optr);
5519 		isp->isp_resodx = optr;
5520 		if (isp->isp_rscchiwater < ndone)
5521 			isp->isp_rscchiwater = ndone;
5522 	}
5523 
5524 out:
5525 
5526 	if (IS_24XX(isp)) {
5527 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_CLEAR_RISC_INT);
5528 	} else {
5529 		ISP_WRITE(isp, HCCR, HCCR_CMD_CLEAR_RISC_INT);
5530 		ISP_WRITE(isp, BIU_SEMA, 0);
5531 	}
5532 
5533 	for (i = 0; i < ndone; i++) {
5534 		xs = complist[i];
5535 		if (xs) {
5536 			if (((isp->isp_dblev & (ISP_LOGDEBUG1|ISP_LOGDEBUG2|ISP_LOGDEBUG3))) ||
5537 			    ((isp->isp_dblev & (ISP_LOGDEBUG0|ISP_LOG_CWARN) && ((!XS_NOERR(xs)) || (*XS_STSP(xs) != SCSI_GOOD))))) {
5538 				isp_prt_endcmd(isp, xs);
5539 			}
5540 			isp->isp_rsltccmplt++;
5541 			isp_done(xs);
5542 		}
5543 	}
5544 }
5545 
5546 /*
5547  * Support routines.
5548  */
5549 
5550 void
5551 isp_prt_endcmd(ispsoftc_t *isp, XS_T *xs)
5552 {
5553 	char cdbstr[16 * 5 + 1];
5554 	int i, lim;
5555 
5556 	lim = XS_CDBLEN(xs) > 16? 16 : XS_CDBLEN(xs);
5557 	ISP_SNPRINTF(cdbstr, sizeof (cdbstr), "0x%02x ", XS_CDBP(xs)[0]);
5558 	for (i = 1; i < lim; i++) {
5559 		ISP_SNPRINTF(cdbstr, sizeof (cdbstr), "%s0x%02x ", cdbstr, XS_CDBP(xs)[i]);
5560 	}
5561 	if (XS_SENSE_VALID(xs)) {
5562 		isp_xs_prt(isp, xs, ISP_LOGALL, "FIN dl%d resid %ld CDB=%s SenseLength=%u/%u KEY/ASC/ASCQ=0x%02x/0x%02x/0x%02x",
5563 		    XS_XFRLEN(xs), (long) XS_GET_RESID(xs), cdbstr, XS_CUR_SNSLEN(xs), XS_TOT_SNSLEN(xs), XS_SNSKEY(xs), XS_SNSASC(xs), XS_SNSASCQ(xs));
5564 	} else {
5565 		isp_xs_prt(isp, xs, ISP_LOGALL, "FIN dl%d resid %ld CDB=%s STS 0x%x XS_ERR=0x%x", XS_XFRLEN(xs), (long) XS_GET_RESID(xs), cdbstr, *XS_STSP(xs), XS_ERR(xs));
5566 	}
5567 }
5568 
5569 /*
5570  * Parse an ASYNC mailbox complete
5571  *
5572  * Return non-zero if the event has been acknowledged.
5573  */
5574 static int
5575 isp_parse_async(ispsoftc_t *isp, uint16_t mbox)
5576 {
5577 	int acked = 0;
5578 	uint32_t h1 = 0, h2 = 0;
5579 	uint16_t chan = 0;
5580 
5581 	/*
5582 	 * Pick up the channel, but not if this is a ASYNC_RIO32_2,
5583 	 * where Mailboxes 6/7 have the second handle.
5584 	 */
5585 	if (mbox != ASYNC_RIO32_2) {
5586 		if (IS_DUALBUS(isp)) {
5587 			chan = ISP_READ(isp, OUTMAILBOX6);
5588 		}
5589 	}
5590 	isp_prt(isp, ISP_LOGDEBUG2, "Async Mbox 0x%x", mbox);
5591 
5592 	switch (mbox) {
5593 	case ASYNC_BUS_RESET:
5594 		ISP_SET_SENDMARKER(isp, chan, 1);
5595 #ifdef	ISP_TARGET_MODE
5596 		if (isp_target_async(isp, chan, mbox)) {
5597 			acked = 1;
5598 		}
5599 #endif
5600 		isp_async(isp, ISPASYNC_BUS_RESET, chan);
5601 		break;
5602 	case ASYNC_SYSTEM_ERROR:
5603 		isp->isp_dead = 1;
5604 		isp->isp_state = ISP_CRASHED;
5605 		/*
5606 		 * Were we waiting for a mailbox command to complete?
5607 		 * If so, it's dead, so wake up the waiter.
5608 		 */
5609 		if (isp->isp_mboxbsy) {
5610 			isp->isp_obits = 1;
5611 			isp->isp_mboxtmp[0] = MBOX_HOST_INTERFACE_ERROR;
5612 			MBOX_NOTIFY_COMPLETE(isp);
5613 		}
5614 		/*
5615 		 * It's up to the handler for isp_async to reinit stuff and
5616 		 * restart the firmware
5617 		 */
5618 		isp_async(isp, ISPASYNC_FW_CRASH);
5619 		acked = 1;
5620 		break;
5621 
5622 	case ASYNC_RQS_XFER_ERR:
5623 		isp_prt(isp, ISP_LOGERR, "Request Queue Transfer Error");
5624 		break;
5625 
5626 	case ASYNC_RSP_XFER_ERR:
5627 		isp_prt(isp, ISP_LOGERR, "Response Queue Transfer Error");
5628 		break;
5629 
5630 	case ASYNC_QWAKEUP:
5631 		/*
5632 		 * We've just been notified that the Queue has woken up.
5633 		 * We don't need to be chatty about this- just unlatch things
5634 		 * and move on.
5635 		 */
5636 		mbox = ISP_READ(isp, isp->isp_rqstoutrp);
5637 		break;
5638 
5639 	case ASYNC_TIMEOUT_RESET:
5640 		isp_prt(isp, ISP_LOGWARN, "timeout initiated SCSI bus reset of chan %d", chan);
5641 		ISP_SET_SENDMARKER(isp, chan, 1);
5642 #ifdef	ISP_TARGET_MODE
5643 		if (isp_target_async(isp, chan, mbox)) {
5644 			acked = 1;
5645 		}
5646 #endif
5647 		break;
5648 
5649 	case ASYNC_DEVICE_RESET:
5650 		isp_prt(isp, ISP_LOGINFO, "device reset on chan %d", chan);
5651 		ISP_SET_SENDMARKER(isp, chan, 1);
5652 #ifdef	ISP_TARGET_MODE
5653 		if (isp_target_async(isp, chan, mbox)) {
5654 			acked = 1;
5655 		}
5656 #endif
5657 		break;
5658 
5659 	case ASYNC_EXTMSG_UNDERRUN:
5660 		isp_prt(isp, ISP_LOGWARN, "extended message underrun");
5661 		break;
5662 
5663 	case ASYNC_SCAM_INT:
5664 		isp_prt(isp, ISP_LOGINFO, "SCAM interrupt");
5665 		break;
5666 
5667 	case ASYNC_HUNG_SCSI:
5668 		isp_prt(isp, ISP_LOGERR, "stalled SCSI Bus after DATA Overrun");
5669 		/* XXX: Need to issue SCSI reset at this point */
5670 		break;
5671 
5672 	case ASYNC_KILLED_BUS:
5673 		isp_prt(isp, ISP_LOGERR, "SCSI Bus reset after DATA Overrun");
5674 		break;
5675 
5676 	case ASYNC_BUS_TRANSIT:
5677 		mbox = ISP_READ(isp, OUTMAILBOX2);
5678 		switch (mbox & SXP_PINS_MODE_MASK) {
5679 		case SXP_PINS_LVD_MODE:
5680 			isp_prt(isp, ISP_LOGINFO, "Transition to LVD mode");
5681 			SDPARAM(isp, chan)->isp_diffmode = 0;
5682 			SDPARAM(isp, chan)->isp_ultramode = 0;
5683 			SDPARAM(isp, chan)->isp_lvdmode = 1;
5684 			break;
5685 		case SXP_PINS_HVD_MODE:
5686 			isp_prt(isp, ISP_LOGINFO,
5687 			    "Transition to Differential mode");
5688 			SDPARAM(isp, chan)->isp_diffmode = 1;
5689 			SDPARAM(isp, chan)->isp_ultramode = 0;
5690 			SDPARAM(isp, chan)->isp_lvdmode = 0;
5691 			break;
5692 		case SXP_PINS_SE_MODE:
5693 			isp_prt(isp, ISP_LOGINFO,
5694 			    "Transition to Single Ended mode");
5695 			SDPARAM(isp, chan)->isp_diffmode = 0;
5696 			SDPARAM(isp, chan)->isp_ultramode = 1;
5697 			SDPARAM(isp, chan)->isp_lvdmode = 0;
5698 			break;
5699 		default:
5700 			isp_prt(isp, ISP_LOGWARN,
5701 			    "Transition to Unknown Mode 0x%x", mbox);
5702 			break;
5703 		}
5704 		/*
5705 		 * XXX: Set up to renegotiate again!
5706 		 */
5707 		/* Can only be for a 1080... */
5708 		ISP_SET_SENDMARKER(isp, chan, 1);
5709 		break;
5710 
5711 	case ASYNC_CMD_CMPLT:
5712 	case ASYNC_RIO32_1:
5713 		if (!IS_ULTRA3(isp)) {
5714 			isp_prt(isp, ISP_LOGERR, "unexpected fast posting completion");
5715 			break;
5716 		}
5717 		/* FALLTHROUGH */
5718 		h1 = (ISP_READ(isp, OUTMAILBOX2) << 16) | ISP_READ(isp, OUTMAILBOX1);
5719 		break;
5720 
5721 	case ASYNC_RIO32_2:
5722 		h1 = (ISP_READ(isp, OUTMAILBOX2) << 16) | ISP_READ(isp, OUTMAILBOX1);
5723 		h2 = (ISP_READ(isp, OUTMAILBOX7) << 16) | ISP_READ(isp, OUTMAILBOX6);
5724 		break;
5725 
5726 	case ASYNC_RIO16_5:
5727 	case ASYNC_RIO16_4:
5728 	case ASYNC_RIO16_3:
5729 	case ASYNC_RIO16_2:
5730 	case ASYNC_RIO16_1:
5731 		isp_prt(isp, ISP_LOGERR, "unexpected 16 bit RIO handle");
5732 		break;
5733 	default:
5734 		isp_prt(isp, ISP_LOGWARN, "%s: unhandled async code 0x%x", __func__, mbox);
5735 		break;
5736 	}
5737 
5738 	if (h1 || h2) {
5739 		isp_prt(isp, ISP_LOGDEBUG3, "fast post/rio completion of 0x%08x", h1);
5740 		isp_fastpost_complete(isp, h1);
5741 		if (h2) {
5742 			isp_prt(isp, ISP_LOGDEBUG3, "fast post/rio completion of 0x%08x", h2);
5743 			isp_fastpost_complete(isp, h2);
5744 			if (isp->isp_fpcchiwater < 2) {
5745 				isp->isp_fpcchiwater = 2;
5746 			}
5747 		} else {
5748 			if (isp->isp_fpcchiwater < 1) {
5749 				isp->isp_fpcchiwater = 1;
5750 			}
5751 		}
5752 	} else {
5753 		isp->isp_intoasync++;
5754 	}
5755 	return (acked);
5756 }
5757 
5758 static int
5759 isp_parse_async_fc(ispsoftc_t *isp, uint16_t mbox)
5760 {
5761 	fcparam *fcp;
5762 	int acked = 0;
5763 	uint16_t chan;
5764 
5765 	if (IS_DUALBUS(isp)) {
5766 		chan = ISP_READ(isp, OUTMAILBOX6);
5767 	} else {
5768 		chan = 0;
5769 	}
5770 	isp_prt(isp, ISP_LOGDEBUG2, "Async Mbox 0x%x", mbox);
5771 
5772 	switch (mbox) {
5773 	case ASYNC_SYSTEM_ERROR:
5774 		isp->isp_dead = 1;
5775 		isp->isp_state = ISP_CRASHED;
5776 		FCPARAM(isp, chan)->isp_loopstate = LOOP_NIL;
5777 		isp_change_fw_state(isp, chan, FW_CONFIG_WAIT);
5778 		/*
5779 		 * Were we waiting for a mailbox command to complete?
5780 		 * If so, it's dead, so wake up the waiter.
5781 		 */
5782 		if (isp->isp_mboxbsy) {
5783 			isp->isp_obits = 1;
5784 			isp->isp_mboxtmp[0] = MBOX_HOST_INTERFACE_ERROR;
5785 			MBOX_NOTIFY_COMPLETE(isp);
5786 		}
5787 		/*
5788 		 * It's up to the handler for isp_async to reinit stuff and
5789 		 * restart the firmware
5790 		 */
5791 		isp_async(isp, ISPASYNC_FW_CRASH);
5792 		acked = 1;
5793 		break;
5794 
5795 	case ASYNC_RQS_XFER_ERR:
5796 		isp_prt(isp, ISP_LOGERR, "Request Queue Transfer Error");
5797 		break;
5798 
5799 	case ASYNC_RSP_XFER_ERR:
5800 		isp_prt(isp, ISP_LOGERR, "Response Queue Transfer Error");
5801 		break;
5802 
5803 	case ASYNC_QWAKEUP:
5804 #ifdef	ISP_TARGET_MODE
5805 		if (IS_24XX(isp)) {
5806 			isp_prt(isp, ISP_LOGERR, "ATIO Queue Transfer Error");
5807 			break;
5808 		}
5809 #endif
5810 		isp_prt(isp, ISP_LOGERR, "%s: unexpected ASYNC_QWAKEUP code", __func__);
5811 		break;
5812 
5813 	case ASYNC_CMD_CMPLT:
5814 		isp_fastpost_complete(isp, (ISP_READ(isp, OUTMAILBOX2) << 16) | ISP_READ(isp, OUTMAILBOX1));
5815 		if (isp->isp_fpcchiwater < 1) {
5816 			isp->isp_fpcchiwater = 1;
5817 		}
5818 		break;
5819 
5820 	case ASYNC_RIOZIO_STALL:
5821 		break;
5822 
5823 	case ASYNC_CTIO_DONE:
5824 #ifdef	ISP_TARGET_MODE
5825 		if (isp_target_async(isp, (ISP_READ(isp, OUTMAILBOX2) << 16) | ISP_READ(isp, OUTMAILBOX1), mbox)) {
5826 			acked = 1;
5827 		} else {
5828 			isp->isp_fphccmplt++;
5829 		}
5830 #else
5831 		isp_prt(isp, ISP_LOGWARN, "unexpected ASYNC CTIO done");
5832 #endif
5833 		break;
5834 	case ASYNC_LIP_ERROR:
5835 	case ASYNC_LIP_NOS_OLS_RECV:
5836 	case ASYNC_LIP_OCCURRED:
5837 	case ASYNC_PTPMODE:
5838 		/*
5839 		 * These are broadcast events that have to be sent across
5840 		 * all active channels.
5841 		 */
5842 		for (chan = 0; chan < isp->isp_nchan; chan++) {
5843 			fcp = FCPARAM(isp, chan);
5844 			int topo = fcp->isp_topo;
5845 
5846 			if (fcp->role == ISP_ROLE_NONE)
5847 				continue;
5848 			if (fcp->isp_loopstate > LOOP_HAVE_LINK)
5849 				fcp->isp_loopstate = LOOP_HAVE_LINK;
5850 			ISP_SET_SENDMARKER(isp, chan, 1);
5851 			isp_async(isp, ISPASYNC_LIP, chan);
5852 #ifdef	ISP_TARGET_MODE
5853 			if (isp_target_async(isp, chan, mbox)) {
5854 				acked = 1;
5855 			}
5856 #endif
5857 			/*
5858 			 * We've had problems with data corruption occuring on
5859 			 * commands that complete (with no apparent error) after
5860 			 * we receive a LIP. This has been observed mostly on
5861 			 * Local Loop topologies. To be safe, let's just mark
5862 			 * all active initiator commands as dead.
5863 			 */
5864 			if (topo == TOPO_NL_PORT || topo == TOPO_FL_PORT) {
5865 				int i, j;
5866 				for (i = j = 0; i < isp->isp_maxcmds; i++) {
5867 					XS_T *xs;
5868 					isp_hdl_t *hdp;
5869 
5870 					hdp = &isp->isp_xflist[i];
5871 					if (ISP_H2HT(hdp->handle) != ISP_HANDLE_INITIATOR) {
5872 						continue;
5873 					}
5874 					xs = hdp->cmd;
5875 					if (XS_CHANNEL(xs) != chan) {
5876 						continue;
5877 					}
5878 					j++;
5879 					isp_prt(isp, ISP_LOG_WARN1,
5880 					    "%d.%d.%jx bus reset set at %s:%u",
5881 					    XS_CHANNEL(xs), XS_TGT(xs),
5882 					    (uintmax_t)XS_LUN(xs),
5883 					    __func__, __LINE__);
5884 					XS_SETERR(xs, HBA_BUSRESET);
5885 				}
5886 				if (j) {
5887 					isp_prt(isp, ISP_LOGERR, lipd, chan, j);
5888 				}
5889 			}
5890 		}
5891 		break;
5892 
5893 	case ASYNC_LOOP_UP:
5894 		/*
5895 		 * This is a broadcast event that has to be sent across
5896 		 * all active channels.
5897 		 */
5898 		for (chan = 0; chan < isp->isp_nchan; chan++) {
5899 			fcp = FCPARAM(isp, chan);
5900 			if (fcp->role == ISP_ROLE_NONE)
5901 				continue;
5902 			fcp->isp_linkstate = 1;
5903 			if (fcp->isp_loopstate < LOOP_HAVE_LINK)
5904 				fcp->isp_loopstate = LOOP_HAVE_LINK;
5905 			ISP_SET_SENDMARKER(isp, chan, 1);
5906 			isp_async(isp, ISPASYNC_LOOP_UP, chan);
5907 #ifdef	ISP_TARGET_MODE
5908 			if (isp_target_async(isp, chan, mbox)) {
5909 				acked = 1;
5910 			}
5911 #endif
5912 		}
5913 		break;
5914 
5915 	case ASYNC_LOOP_DOWN:
5916 		/*
5917 		 * This is a broadcast event that has to be sent across
5918 		 * all active channels.
5919 		 */
5920 		for (chan = 0; chan < isp->isp_nchan; chan++) {
5921 			fcp = FCPARAM(isp, chan);
5922 			if (fcp->role == ISP_ROLE_NONE)
5923 				continue;
5924 			ISP_SET_SENDMARKER(isp, chan, 1);
5925 			fcp->isp_linkstate = 0;
5926 			fcp->isp_loopstate = LOOP_NIL;
5927 			isp_async(isp, ISPASYNC_LOOP_DOWN, chan);
5928 #ifdef	ISP_TARGET_MODE
5929 			if (isp_target_async(isp, chan, mbox)) {
5930 				acked = 1;
5931 			}
5932 #endif
5933 		}
5934 		break;
5935 
5936 	case ASYNC_LOOP_RESET:
5937 		/*
5938 		 * This is a broadcast event that has to be sent across
5939 		 * all active channels.
5940 		 */
5941 		for (chan = 0; chan < isp->isp_nchan; chan++) {
5942 			fcp = FCPARAM(isp, chan);
5943 			if (fcp->role == ISP_ROLE_NONE)
5944 				continue;
5945 			ISP_SET_SENDMARKER(isp, chan, 1);
5946 			if (fcp->isp_loopstate > LOOP_HAVE_LINK)
5947 				fcp->isp_loopstate = LOOP_HAVE_LINK;
5948 			isp_async(isp, ISPASYNC_LOOP_RESET, chan);
5949 #ifdef	ISP_TARGET_MODE
5950 			if (isp_target_async(isp, chan, mbox)) {
5951 				acked = 1;
5952 			}
5953 #endif
5954 		}
5955 		break;
5956 
5957 	case ASYNC_PDB_CHANGED:
5958 	{
5959 		int echan, nphdl, nlstate, reason;
5960 
5961 		if (IS_23XX(isp) || IS_24XX(isp)) {
5962 			nphdl = ISP_READ(isp, OUTMAILBOX1);
5963 			nlstate = ISP_READ(isp, OUTMAILBOX2);
5964 		} else {
5965 			nphdl = nlstate = 0xffff;
5966 		}
5967 		if (IS_24XX(isp))
5968 			reason = ISP_READ(isp, OUTMAILBOX3) >> 8;
5969 		else
5970 			reason = 0xff;
5971 		if (ISP_CAP_MULTI_ID(isp)) {
5972 			chan = ISP_READ(isp, OUTMAILBOX3) & 0xff;
5973 			if (chan == 0xff || nphdl == NIL_HANDLE) {
5974 				chan = 0;
5975 				echan = isp->isp_nchan - 1;
5976 			} else if (chan >= isp->isp_nchan) {
5977 				break;
5978 			} else {
5979 				echan = chan;
5980 			}
5981 		} else {
5982 			chan = echan = 0;
5983 		}
5984 		for (; chan <= echan; chan++) {
5985 			fcp = FCPARAM(isp, chan);
5986 			if (fcp->role == ISP_ROLE_NONE)
5987 				continue;
5988 			if (fcp->isp_loopstate > LOOP_LTEST_DONE)
5989 				fcp->isp_loopstate = LOOP_LTEST_DONE;
5990 			else if (fcp->isp_loopstate < LOOP_HAVE_LINK)
5991 				fcp->isp_loopstate = LOOP_HAVE_LINK;
5992 			isp_async(isp, ISPASYNC_CHANGE_NOTIFY, chan,
5993 			    ISPASYNC_CHANGE_PDB, nphdl, nlstate, reason);
5994 		}
5995 		break;
5996 	}
5997 	case ASYNC_CHANGE_NOTIFY:
5998 	{
5999 		int portid;
6000 
6001 		portid = ((ISP_READ(isp, OUTMAILBOX1) & 0xff) << 16) |
6002 		    ISP_READ(isp, OUTMAILBOX2);
6003 		if (ISP_CAP_MULTI_ID(isp)) {
6004 			chan = ISP_READ(isp, OUTMAILBOX3) & 0xff;
6005 			if (chan >= isp->isp_nchan)
6006 				break;
6007 		} else {
6008 			chan = 0;
6009 		}
6010 		fcp = FCPARAM(isp, chan);
6011 		if (fcp->role == ISP_ROLE_NONE)
6012 			break;
6013 		if (fcp->isp_loopstate > LOOP_LTEST_DONE)
6014 			fcp->isp_loopstate = LOOP_LTEST_DONE;
6015 		else if (fcp->isp_loopstate < LOOP_HAVE_LINK)
6016 			fcp->isp_loopstate = LOOP_HAVE_LINK;
6017 		isp_async(isp, ISPASYNC_CHANGE_NOTIFY, chan,
6018 		    ISPASYNC_CHANGE_SNS, portid);
6019 		break;
6020 	}
6021 	case ASYNC_ERR_LOGGING_DISABLED:
6022 		isp_prt(isp, ISP_LOGWARN, "Error logging disabled (reason 0x%x)",
6023 		    ISP_READ(isp, OUTMAILBOX1));
6024 		break;
6025 	case ASYNC_CONNMODE:
6026 		/*
6027 		 * This only applies to 2100 amd 2200 cards
6028 		 */
6029 		if (!IS_2200(isp) && !IS_2100(isp)) {
6030 			isp_prt(isp, ISP_LOGWARN, "bad card for ASYNC_CONNMODE event");
6031 			break;
6032 		}
6033 		chan = 0;
6034 		mbox = ISP_READ(isp, OUTMAILBOX1);
6035 		switch (mbox) {
6036 		case ISP_CONN_LOOP:
6037 			isp_prt(isp, ISP_LOGINFO,
6038 			    "Point-to-Point -> Loop mode");
6039 			break;
6040 		case ISP_CONN_PTP:
6041 			isp_prt(isp, ISP_LOGINFO,
6042 			    "Loop -> Point-to-Point mode");
6043 			break;
6044 		case ISP_CONN_BADLIP:
6045 			isp_prt(isp, ISP_LOGWARN,
6046 			    "Point-to-Point -> Loop mode (BAD LIP)");
6047 			break;
6048 		case ISP_CONN_FATAL:
6049 			isp->isp_dead = 1;
6050 			isp->isp_state = ISP_CRASHED;
6051 			isp_prt(isp, ISP_LOGERR, "FATAL CONNECTION ERROR");
6052 			isp_async(isp, ISPASYNC_FW_CRASH);
6053 			return (-1);
6054 		case ISP_CONN_LOOPBACK:
6055 			isp_prt(isp, ISP_LOGWARN,
6056 			    "Looped Back in Point-to-Point mode");
6057 			break;
6058 		default:
6059 			isp_prt(isp, ISP_LOGWARN,
6060 			    "Unknown connection mode (0x%x)", mbox);
6061 			break;
6062 		}
6063 		ISP_SET_SENDMARKER(isp, chan, 1);
6064 		FCPARAM(isp, chan)->isp_loopstate = LOOP_HAVE_LINK;
6065 		isp_async(isp, ISPASYNC_CHANGE_NOTIFY, chan, ISPASYNC_CHANGE_OTHER);
6066 		break;
6067 	case ASYNC_P2P_INIT_ERR:
6068 		isp_prt(isp, ISP_LOGWARN, "P2P init error (reason 0x%x)",
6069 		    ISP_READ(isp, OUTMAILBOX1));
6070 		break;
6071 	case ASYNC_RCV_ERR:
6072 		if (IS_24XX(isp)) {
6073 			isp_prt(isp, ISP_LOGWARN, "Receive Error");
6074 		} else {
6075 			isp_prt(isp, ISP_LOGWARN, "unexpected ASYNC_RCV_ERR");
6076 		}
6077 		break;
6078 	case ASYNC_RJT_SENT:	/* same as ASYNC_QFULL_SENT */
6079 		if (IS_24XX(isp)) {
6080 			isp_prt(isp, ISP_LOGTDEBUG0, "LS_RJT sent");
6081 			break;
6082 		} else {
6083 			isp_prt(isp, ISP_LOGTDEBUG0, "QFULL sent");
6084 			break;
6085 		}
6086 	case ASYNC_FW_RESTART_COMPLETE:
6087 		isp_prt(isp, ISP_LOGDEBUG0, "FW restart complete");
6088 		break;
6089 	case ASYNC_TEMPERATURE_ALERT:
6090 		isp_prt(isp, ISP_LOGERR, "Temperature alert (subcode 0x%x)",
6091 		    ISP_READ(isp, OUTMAILBOX1));
6092 		break;
6093 	case ASYNC_AUTOLOAD_FW_COMPLETE:
6094 		isp_prt(isp, ISP_LOGDEBUG0, "Autoload FW init complete");
6095 		break;
6096 	case ASYNC_AUTOLOAD_FW_FAILURE:
6097 		isp_prt(isp, ISP_LOGERR, "Autoload FW init failure");
6098 		break;
6099 	default:
6100 		isp_prt(isp, ISP_LOGWARN, "Unknown Async Code 0x%x", mbox);
6101 		break;
6102 	}
6103 	if (mbox != ASYNC_CTIO_DONE && mbox != ASYNC_CMD_CMPLT) {
6104 		isp->isp_intoasync++;
6105 	}
6106 	return (acked);
6107 }
6108 
6109 /*
6110  * Handle other response entries. A pointer to the request queue output
6111  * index is here in case we want to eat several entries at once, although
6112  * this is not used currently.
6113  */
6114 
6115 static int
6116 isp_handle_other_response(ispsoftc_t *isp, int type, isphdr_t *hp, uint32_t *optrp)
6117 {
6118 	isp_ridacq_t rid;
6119 	int chan, c;
6120 	uint32_t hdl;
6121 	void *ptr;
6122 
6123 	switch (type) {
6124 	case RQSTYPE_STATUS_CONT:
6125 		isp_prt(isp, ISP_LOG_WARN1, "Ignored Continuation Response");
6126 		return (1);
6127 	case RQSTYPE_MARKER:
6128 		isp_prt(isp, ISP_LOG_WARN1, "Marker Response");
6129 		return (1);
6130 	case RQSTYPE_RPT_ID_ACQ:
6131 		isp_get_ridacq(isp, (isp_ridacq_t *)hp, &rid);
6132 		if (rid.ridacq_format == 0) {
6133 			for (chan = 0; chan < isp->isp_nchan; chan++) {
6134 				fcparam *fcp = FCPARAM(isp, chan);
6135 				if (fcp->role == ISP_ROLE_NONE)
6136 					continue;
6137 				c = (chan == 0) ? 127 : (chan - 1);
6138 				if (rid.ridacq_map[c / 16] & (1 << (c % 16)) ||
6139 				    chan == 0) {
6140 					fcp->isp_loopstate = LOOP_HAVE_LINK;
6141 					isp_async(isp, ISPASYNC_CHANGE_NOTIFY,
6142 					    chan, ISPASYNC_CHANGE_OTHER);
6143 				} else {
6144 					fcp->isp_loopstate = LOOP_NIL;
6145 					isp_async(isp, ISPASYNC_LOOP_DOWN,
6146 					    chan);
6147 				}
6148 			}
6149 		} else {
6150 			fcparam *fcp = FCPARAM(isp, rid.ridacq_vp_index);
6151 			if (rid.ridacq_vp_status == RIDACQ_STS_COMPLETE ||
6152 			    rid.ridacq_vp_status == RIDACQ_STS_CHANGED) {
6153 				fcp->isp_loopstate = LOOP_HAVE_LINK;
6154 				isp_async(isp, ISPASYNC_CHANGE_NOTIFY,
6155 				    rid.ridacq_vp_index, ISPASYNC_CHANGE_OTHER);
6156 			} else {
6157 				fcp->isp_loopstate = LOOP_NIL;
6158 				isp_async(isp, ISPASYNC_LOOP_DOWN,
6159 				    rid.ridacq_vp_index);
6160 			}
6161 		}
6162 		return (1);
6163 	case RQSTYPE_CT_PASSTHRU:
6164 	case RQSTYPE_VP_MODIFY:
6165 	case RQSTYPE_VP_CTRL:
6166 	case RQSTYPE_LOGIN:
6167 		ISP_IOXGET_32(isp, (uint32_t *)(hp + 1), hdl);
6168 		ptr = isp_find_xs(isp, hdl);
6169 		if (ptr != NULL) {
6170 			isp_destroy_handle(isp, hdl);
6171 			memcpy(ptr, hp, QENTRY_LEN);
6172 			wakeup(ptr);
6173 		}
6174 		return (1);
6175 	case RQSTYPE_ATIO:
6176 	case RQSTYPE_CTIO:
6177 	case RQSTYPE_ENABLE_LUN:
6178 	case RQSTYPE_MODIFY_LUN:
6179 	case RQSTYPE_NOTIFY:
6180 	case RQSTYPE_NOTIFY_ACK:
6181 	case RQSTYPE_CTIO1:
6182 	case RQSTYPE_ATIO2:
6183 	case RQSTYPE_CTIO2:
6184 	case RQSTYPE_CTIO3:
6185 	case RQSTYPE_CTIO7:
6186 	case RQSTYPE_ABTS_RCVD:
6187 	case RQSTYPE_ABTS_RSP:
6188 		isp->isp_rsltccmplt++;	/* count as a response completion */
6189 #ifdef	ISP_TARGET_MODE
6190 		if (isp_target_notify(isp, (ispstatusreq_t *) hp, optrp)) {
6191 			return (1);
6192 		}
6193 #endif
6194 		/* FALLTHROUGH */
6195 	case RQSTYPE_REQUEST:
6196 	default:
6197 		ISP_DELAY(100);
6198 		if (type != isp_get_response_type(isp, hp)) {
6199 			/*
6200 			 * This is questionable- we're just papering over
6201 			 * something we've seen on SMP linux in target
6202 			 * mode- we don't really know what's happening
6203 			 * here that causes us to think we've gotten
6204 			 * an entry, but that either the entry isn't
6205 			 * filled out yet or our CPU read data is stale.
6206 			 */
6207 			isp_prt(isp, ISP_LOGINFO,
6208 				"unstable type in response queue");
6209 			return (-1);
6210 		}
6211 		isp_prt(isp, ISP_LOGWARN, "Unhandled Response Type 0x%x",
6212 		    isp_get_response_type(isp, hp));
6213 		return (0);
6214 	}
6215 }
6216 
6217 static void
6218 isp_parse_status(ispsoftc_t *isp, ispstatusreq_t *sp, XS_T *xs, long *rp)
6219 {
6220 	switch (sp->req_completion_status & 0xff) {
6221 	case RQCS_COMPLETE:
6222 		if (XS_NOERR(xs)) {
6223 			XS_SETERR(xs, HBA_NOERROR);
6224 		}
6225 		return;
6226 
6227 	case RQCS_INCOMPLETE:
6228 		if ((sp->req_state_flags & RQSF_GOT_TARGET) == 0) {
6229 			isp_xs_prt(isp, xs, ISP_LOG_WARN1, "Selection Timeout @ %s:%d", __func__, __LINE__);
6230 			if (XS_NOERR(xs)) {
6231 				XS_SETERR(xs, HBA_SELTIMEOUT);
6232 				*rp = XS_XFRLEN(xs);
6233 			}
6234 			return;
6235 		}
6236 		isp_xs_prt(isp, xs, ISP_LOGERR, "Command Incomplete, state 0x%x", sp->req_state_flags);
6237 		break;
6238 
6239 	case RQCS_DMA_ERROR:
6240 		isp_xs_prt(isp, xs, ISP_LOGERR, "DMA Error");
6241 		*rp = XS_XFRLEN(xs);
6242 		break;
6243 
6244 	case RQCS_TRANSPORT_ERROR:
6245 	{
6246 		char buf[172];
6247 		ISP_SNPRINTF(buf, sizeof (buf), "states=>");
6248 		if (sp->req_state_flags & RQSF_GOT_BUS) {
6249 			ISP_SNPRINTF(buf, sizeof (buf), "%s GOT_BUS", buf);
6250 		}
6251 		if (sp->req_state_flags & RQSF_GOT_TARGET) {
6252 			ISP_SNPRINTF(buf, sizeof (buf), "%s GOT_TGT", buf);
6253 		}
6254 		if (sp->req_state_flags & RQSF_SENT_CDB) {
6255 			ISP_SNPRINTF(buf, sizeof (buf), "%s SENT_CDB", buf);
6256 		}
6257 		if (sp->req_state_flags & RQSF_XFRD_DATA) {
6258 			ISP_SNPRINTF(buf, sizeof (buf), "%s XFRD_DATA", buf);
6259 		}
6260 		if (sp->req_state_flags & RQSF_GOT_STATUS) {
6261 			ISP_SNPRINTF(buf, sizeof (buf), "%s GOT_STS", buf);
6262 		}
6263 		if (sp->req_state_flags & RQSF_GOT_SENSE) {
6264 			ISP_SNPRINTF(buf, sizeof (buf), "%s GOT_SNS", buf);
6265 		}
6266 		if (sp->req_state_flags & RQSF_XFER_COMPLETE) {
6267 			ISP_SNPRINTF(buf, sizeof (buf), "%s XFR_CMPLT", buf);
6268 		}
6269 		ISP_SNPRINTF(buf, sizeof (buf), "%s\nstatus=>", buf);
6270 		if (sp->req_status_flags & RQSTF_DISCONNECT) {
6271 			ISP_SNPRINTF(buf, sizeof (buf), "%s Disconnect", buf);
6272 		}
6273 		if (sp->req_status_flags & RQSTF_SYNCHRONOUS) {
6274 			ISP_SNPRINTF(buf, sizeof (buf), "%s Sync_xfr", buf);
6275 		}
6276 		if (sp->req_status_flags & RQSTF_PARITY_ERROR) {
6277 			ISP_SNPRINTF(buf, sizeof (buf), "%s Parity", buf);
6278 		}
6279 		if (sp->req_status_flags & RQSTF_BUS_RESET) {
6280 			ISP_SNPRINTF(buf, sizeof (buf), "%s Bus_Reset", buf);
6281 		}
6282 		if (sp->req_status_flags & RQSTF_DEVICE_RESET) {
6283 			ISP_SNPRINTF(buf, sizeof (buf), "%s Device_Reset", buf);
6284 		}
6285 		if (sp->req_status_flags & RQSTF_ABORTED) {
6286 			ISP_SNPRINTF(buf, sizeof (buf), "%s Aborted", buf);
6287 		}
6288 		if (sp->req_status_flags & RQSTF_TIMEOUT) {
6289 			ISP_SNPRINTF(buf, sizeof (buf), "%s Timeout", buf);
6290 		}
6291 		if (sp->req_status_flags & RQSTF_NEGOTIATION) {
6292 			ISP_SNPRINTF(buf, sizeof (buf), "%s Negotiation", buf);
6293 		}
6294 		isp_xs_prt(isp, xs,  ISP_LOGERR, "Transport Error: %s", buf);
6295 		*rp = XS_XFRLEN(xs);
6296 		break;
6297 	}
6298 	case RQCS_RESET_OCCURRED:
6299 	{
6300 		int chan;
6301 		isp_xs_prt(isp, xs, ISP_LOGWARN, "Bus Reset destroyed command");
6302 		for (chan = 0; chan < isp->isp_nchan; chan++) {
6303 			FCPARAM(isp, chan)->sendmarker = 1;
6304 		}
6305 		if (XS_NOERR(xs)) {
6306 			XS_SETERR(xs, HBA_BUSRESET);
6307 		}
6308 		*rp = XS_XFRLEN(xs);
6309 		return;
6310 	}
6311 	case RQCS_ABORTED:
6312 		isp_xs_prt(isp, xs, ISP_LOGERR, "Command Aborted");
6313 		ISP_SET_SENDMARKER(isp, XS_CHANNEL(xs), 1);
6314 		if (XS_NOERR(xs)) {
6315 			XS_SETERR(xs, HBA_ABORTED);
6316 		}
6317 		return;
6318 
6319 	case RQCS_TIMEOUT:
6320 		isp_xs_prt(isp, xs, ISP_LOGWARN, "Command timed out");
6321 		/*
6322 	 	 * XXX: Check to see if we logged out of the device.
6323 		 */
6324 		if (XS_NOERR(xs)) {
6325 			XS_SETERR(xs, HBA_CMDTIMEOUT);
6326 		}
6327 		return;
6328 
6329 	case RQCS_DATA_OVERRUN:
6330 		XS_SET_RESID(xs, sp->req_resid);
6331 		isp_xs_prt(isp, xs, ISP_LOGERR, "data overrun (%ld)", (long) XS_GET_RESID(xs));
6332 		if (XS_NOERR(xs)) {
6333 			XS_SETERR(xs, HBA_DATAOVR);
6334 		}
6335 		return;
6336 
6337 	case RQCS_COMMAND_OVERRUN:
6338 		isp_xs_prt(isp, xs, ISP_LOGERR, "command overrun");
6339 		break;
6340 
6341 	case RQCS_STATUS_OVERRUN:
6342 		isp_xs_prt(isp, xs, ISP_LOGERR, "status overrun");
6343 		break;
6344 
6345 	case RQCS_BAD_MESSAGE:
6346 		isp_xs_prt(isp, xs, ISP_LOGERR, "msg not COMMAND COMPLETE after status");
6347 		break;
6348 
6349 	case RQCS_NO_MESSAGE_OUT:
6350 		isp_xs_prt(isp, xs, ISP_LOGERR, "No MESSAGE OUT phase after selection");
6351 		break;
6352 
6353 	case RQCS_EXT_ID_FAILED:
6354 		isp_xs_prt(isp, xs, ISP_LOGERR, "EXTENDED IDENTIFY failed");
6355 		break;
6356 
6357 	case RQCS_IDE_MSG_FAILED:
6358 		isp_xs_prt(isp, xs, ISP_LOGERR, "INITIATOR DETECTED ERROR rejected");
6359 		break;
6360 
6361 	case RQCS_ABORT_MSG_FAILED:
6362 		isp_xs_prt(isp, xs, ISP_LOGERR, "ABORT OPERATION rejected");
6363 		break;
6364 
6365 	case RQCS_REJECT_MSG_FAILED:
6366 		isp_xs_prt(isp, xs, ISP_LOGERR, "MESSAGE REJECT rejected");
6367 		break;
6368 
6369 	case RQCS_NOP_MSG_FAILED:
6370 		isp_xs_prt(isp, xs, ISP_LOGERR, "NOP rejected");
6371 		break;
6372 
6373 	case RQCS_PARITY_ERROR_MSG_FAILED:
6374 		isp_xs_prt(isp, xs, ISP_LOGERR, "MESSAGE PARITY ERROR rejected");
6375 		break;
6376 
6377 	case RQCS_DEVICE_RESET_MSG_FAILED:
6378 		isp_xs_prt(isp, xs, ISP_LOGWARN, "BUS DEVICE RESET rejected");
6379 		break;
6380 
6381 	case RQCS_ID_MSG_FAILED:
6382 		isp_xs_prt(isp, xs, ISP_LOGERR, "IDENTIFY rejected");
6383 		break;
6384 
6385 	case RQCS_UNEXP_BUS_FREE:
6386 		isp_xs_prt(isp, xs, ISP_LOGERR, "Unexpected Bus Free");
6387 		break;
6388 
6389 	case RQCS_DATA_UNDERRUN:
6390 	{
6391 		if (IS_FC(isp)) {
6392 			int ru_marked = (sp->req_scsi_status & RQCS_RU) != 0;
6393 			if (!ru_marked || sp->req_resid > XS_XFRLEN(xs)) {
6394 				isp_xs_prt(isp, xs, ISP_LOGWARN, bun, XS_XFRLEN(xs), sp->req_resid, (ru_marked)? "marked" : "not marked");
6395 				if (XS_NOERR(xs)) {
6396 					XS_SETERR(xs, HBA_BOTCH);
6397 				}
6398 				return;
6399 			}
6400 		}
6401 		XS_SET_RESID(xs, sp->req_resid);
6402 		if (XS_NOERR(xs)) {
6403 			XS_SETERR(xs, HBA_NOERROR);
6404 		}
6405 		return;
6406 	}
6407 
6408 	case RQCS_XACT_ERR1:
6409 		isp_xs_prt(isp, xs, ISP_LOGERR, "HBA attempted queued transaction with disconnect not set");
6410 		break;
6411 
6412 	case RQCS_XACT_ERR2:
6413 		isp_xs_prt(isp, xs, ISP_LOGERR,
6414 		    "HBA attempted queued transaction to target routine %jx",
6415 		    (uintmax_t)XS_LUN(xs));
6416 		break;
6417 
6418 	case RQCS_XACT_ERR3:
6419 		isp_xs_prt(isp, xs, ISP_LOGERR, "HBA attempted queued cmd when queueing disabled");
6420 		break;
6421 
6422 	case RQCS_BAD_ENTRY:
6423 		isp_prt(isp, ISP_LOGERR, "Invalid IOCB entry type detected");
6424 		break;
6425 
6426 	case RQCS_QUEUE_FULL:
6427 		isp_xs_prt(isp, xs, ISP_LOG_WARN1, "internal queues full status 0x%x", *XS_STSP(xs));
6428 
6429 		/*
6430 		 * If QFULL or some other status byte is set, then this
6431 		 * isn't an error, per se.
6432 		 *
6433 		 * Unfortunately, some QLogic f/w writers have, in
6434 		 * some cases, ommitted to *set* status to QFULL.
6435 		 */
6436 #if	0
6437 		if (*XS_STSP(xs) != SCSI_GOOD && XS_NOERR(xs)) {
6438 			XS_SETERR(xs, HBA_NOERROR);
6439 			return;
6440 		}
6441 
6442 #endif
6443 		*XS_STSP(xs) = SCSI_QFULL;
6444 		XS_SETERR(xs, HBA_NOERROR);
6445 		return;
6446 
6447 	case RQCS_PHASE_SKIPPED:
6448 		isp_xs_prt(isp, xs, ISP_LOGERR, "SCSI phase skipped");
6449 		break;
6450 
6451 	case RQCS_ARQS_FAILED:
6452 		isp_xs_prt(isp, xs, ISP_LOGERR, "Auto Request Sense Failed");
6453 		if (XS_NOERR(xs)) {
6454 			XS_SETERR(xs, HBA_ARQFAIL);
6455 		}
6456 		return;
6457 
6458 	case RQCS_WIDE_FAILED:
6459 		isp_xs_prt(isp, xs, ISP_LOGERR, "Wide Negotiation Failed");
6460 		if (IS_SCSI(isp)) {
6461 			sdparam *sdp = SDPARAM(isp, XS_CHANNEL(xs));
6462 			sdp->isp_devparam[XS_TGT(xs)].goal_flags &= ~DPARM_WIDE;
6463 			sdp->isp_devparam[XS_TGT(xs)].dev_update = 1;
6464 			sdp->update = 1;
6465 		}
6466 		if (XS_NOERR(xs)) {
6467 			XS_SETERR(xs, HBA_NOERROR);
6468 		}
6469 		return;
6470 
6471 	case RQCS_SYNCXFER_FAILED:
6472 		isp_xs_prt(isp, xs, ISP_LOGERR, "SDTR Message Failed");
6473 		if (IS_SCSI(isp)) {
6474 			sdparam *sdp = SDPARAM(isp, XS_CHANNEL(xs));
6475 			sdp += XS_CHANNEL(xs);
6476 			sdp->isp_devparam[XS_TGT(xs)].goal_flags &= ~DPARM_SYNC;
6477 			sdp->isp_devparam[XS_TGT(xs)].dev_update = 1;
6478 			sdp->update = 1;
6479 		}
6480 		break;
6481 
6482 	case RQCS_LVD_BUSERR:
6483 		isp_xs_prt(isp, xs, ISP_LOGERR, "Bad LVD condition");
6484 		break;
6485 
6486 	case RQCS_PORT_UNAVAILABLE:
6487 		/*
6488 		 * No such port on the loop. Moral equivalent of SELTIMEO
6489 		 */
6490 	case RQCS_PORT_LOGGED_OUT:
6491 	{
6492 		const char *reason;
6493 		uint8_t sts = sp->req_completion_status & 0xff;
6494 
6495 		/*
6496 		 * It was there (maybe)- treat as a selection timeout.
6497 		 */
6498 		if (sts == RQCS_PORT_UNAVAILABLE) {
6499 			reason = "unavailable";
6500 		} else {
6501 			reason = "logout";
6502 		}
6503 
6504 		isp_prt(isp, ISP_LOGINFO, "port %s for target %d", reason, XS_TGT(xs));
6505 
6506 		/*
6507 		 * If we're on a local loop, force a LIP (which is overkill)
6508 		 * to force a re-login of this unit. If we're on fabric,
6509 		 * then we'll have to log in again as a matter of course.
6510 		 */
6511 		if (FCPARAM(isp, 0)->isp_topo == TOPO_NL_PORT ||
6512 		    FCPARAM(isp, 0)->isp_topo == TOPO_FL_PORT) {
6513 			mbreg_t mbs;
6514 			MBSINIT(&mbs, MBOX_INIT_LIP, MBLOGALL, 0);
6515 			if (ISP_CAP_2KLOGIN(isp)) {
6516 				mbs.ibits = (1 << 10);
6517 			}
6518 			isp_mboxcmd_qnw(isp, &mbs, 1);
6519 		}
6520 		if (XS_NOERR(xs)) {
6521 			XS_SETERR(xs, HBA_SELTIMEOUT);
6522 		}
6523 		return;
6524 	}
6525 	case RQCS_PORT_CHANGED:
6526 		isp_prt(isp, ISP_LOGWARN, "port changed for target %d", XS_TGT(xs));
6527 		if (XS_NOERR(xs)) {
6528 			XS_SETERR(xs, HBA_SELTIMEOUT);
6529 		}
6530 		return;
6531 
6532 	case RQCS_PORT_BUSY:
6533 		isp_prt(isp, ISP_LOGWARN, "port busy for target %d", XS_TGT(xs));
6534 		if (XS_NOERR(xs)) {
6535 			XS_SETERR(xs, HBA_TGTBSY);
6536 		}
6537 		return;
6538 
6539 	default:
6540 		isp_prt(isp, ISP_LOGERR, "Unknown Completion Status 0x%x", sp->req_completion_status);
6541 		break;
6542 	}
6543 	if (XS_NOERR(xs)) {
6544 		XS_SETERR(xs, HBA_BOTCH);
6545 	}
6546 }
6547 
6548 static void
6549 isp_parse_status_24xx(ispsoftc_t *isp, isp24xx_statusreq_t *sp, XS_T *xs, long *rp)
6550 {
6551 	int ru_marked, sv_marked;
6552 	int chan = XS_CHANNEL(xs);
6553 
6554 	switch (sp->req_completion_status) {
6555 	case RQCS_COMPLETE:
6556 		if (XS_NOERR(xs)) {
6557 			XS_SETERR(xs, HBA_NOERROR);
6558 		}
6559 		return;
6560 
6561 	case RQCS_DMA_ERROR:
6562 		isp_xs_prt(isp, xs, ISP_LOGERR, "DMA error");
6563 		break;
6564 
6565 	case RQCS_TRANSPORT_ERROR:
6566 		isp_xs_prt(isp, xs,  ISP_LOGERR, "Transport Error");
6567 		break;
6568 
6569 	case RQCS_RESET_OCCURRED:
6570 		isp_xs_prt(isp, xs, ISP_LOGWARN, "reset destroyed command");
6571 		FCPARAM(isp, chan)->sendmarker = 1;
6572 		if (XS_NOERR(xs)) {
6573 			XS_SETERR(xs, HBA_BUSRESET);
6574 		}
6575 		return;
6576 
6577 	case RQCS_ABORTED:
6578 		isp_xs_prt(isp, xs, ISP_LOGERR, "Command Aborted");
6579 		FCPARAM(isp, chan)->sendmarker = 1;
6580 		if (XS_NOERR(xs)) {
6581 			XS_SETERR(xs, HBA_ABORTED);
6582 		}
6583 		return;
6584 
6585 	case RQCS_TIMEOUT:
6586 		isp_xs_prt(isp, xs, ISP_LOGWARN, "Command Timed Out");
6587 		if (XS_NOERR(xs)) {
6588 			XS_SETERR(xs, HBA_CMDTIMEOUT);
6589 		}
6590 		return;
6591 
6592 	case RQCS_DATA_OVERRUN:
6593 		XS_SET_RESID(xs, sp->req_resid);
6594 		isp_xs_prt(isp, xs, ISP_LOGERR, "Data Overrun");
6595 		if (XS_NOERR(xs)) {
6596 			XS_SETERR(xs, HBA_DATAOVR);
6597 		}
6598 		return;
6599 
6600 	case RQCS_24XX_DRE:	/* data reassembly error */
6601 		isp_prt(isp, ISP_LOGERR, "Chan %d data reassembly error for target %d", chan, XS_TGT(xs));
6602 		if (XS_NOERR(xs)) {
6603 			XS_SETERR(xs, HBA_ABORTED);
6604 		}
6605 		*rp = XS_XFRLEN(xs);
6606 		return;
6607 
6608 	case RQCS_24XX_TABORT:	/* aborted by target */
6609 		isp_prt(isp, ISP_LOGERR, "Chan %d target %d sent ABTS", chan, XS_TGT(xs));
6610 		if (XS_NOERR(xs)) {
6611 			XS_SETERR(xs, HBA_ABORTED);
6612 		}
6613 		return;
6614 
6615 	case RQCS_DATA_UNDERRUN:
6616 		ru_marked = (sp->req_scsi_status & RQCS_RU) != 0;
6617 		/*
6618 		 * We can get an underrun w/o things being marked
6619 		 * if we got a non-zero status.
6620 		 */
6621 		sv_marked = (sp->req_scsi_status & (RQCS_SV|RQCS_RV)) != 0;
6622 		if ((ru_marked == 0 && sv_marked == 0) ||
6623 		    (sp->req_resid > XS_XFRLEN(xs))) {
6624 			isp_xs_prt(isp, xs, ISP_LOGWARN, bun, XS_XFRLEN(xs), sp->req_resid, (ru_marked)? "marked" : "not marked");
6625 			if (XS_NOERR(xs)) {
6626 				XS_SETERR(xs, HBA_BOTCH);
6627 			}
6628 			return;
6629 		}
6630 		XS_SET_RESID(xs, sp->req_resid);
6631 		isp_xs_prt(isp, xs, ISP_LOG_WARN1, "Data Underrun (%d) for command 0x%x", sp->req_resid, XS_CDBP(xs)[0] & 0xff);
6632 		if (XS_NOERR(xs)) {
6633 			XS_SETERR(xs, HBA_NOERROR);
6634 		}
6635 		return;
6636 
6637 	case RQCS_PORT_UNAVAILABLE:
6638 		/*
6639 		 * No such port on the loop. Moral equivalent of SELTIMEO
6640 		 */
6641 	case RQCS_PORT_LOGGED_OUT:
6642 	{
6643 		const char *reason;
6644 		uint8_t sts = sp->req_completion_status & 0xff;
6645 
6646 		/*
6647 		 * It was there (maybe)- treat as a selection timeout.
6648 		 */
6649 		if (sts == RQCS_PORT_UNAVAILABLE) {
6650 			reason = "unavailable";
6651 		} else {
6652 			reason = "logout";
6653 		}
6654 
6655 		isp_prt(isp, ISP_LOGINFO, "Chan %d port %s for target %d",
6656 		    chan, reason, XS_TGT(xs));
6657 
6658 		/*
6659 		 * There is no MBOX_INIT_LIP for the 24XX.
6660 		 */
6661 		if (XS_NOERR(xs)) {
6662 			XS_SETERR(xs, HBA_SELTIMEOUT);
6663 		}
6664 		return;
6665 	}
6666 	case RQCS_PORT_CHANGED:
6667 		isp_prt(isp, ISP_LOGWARN, "port changed for target %d chan %d", XS_TGT(xs), chan);
6668 		if (XS_NOERR(xs)) {
6669 			XS_SETERR(xs, HBA_SELTIMEOUT);
6670 		}
6671 		return;
6672 
6673 
6674 	case RQCS_24XX_ENOMEM:	/* f/w resource unavailable */
6675 		isp_prt(isp, ISP_LOGWARN, "f/w resource unavailable for target %d chan %d", XS_TGT(xs), chan);
6676 		if (XS_NOERR(xs)) {
6677 			*XS_STSP(xs) = SCSI_BUSY;
6678 			XS_SETERR(xs, HBA_TGTBSY);
6679 		}
6680 		return;
6681 
6682 	case RQCS_24XX_TMO:	/* task management overrun */
6683 		isp_prt(isp, ISP_LOGWARN, "command for target %d overlapped task management for chan %d", XS_TGT(xs), chan);
6684 		if (XS_NOERR(xs)) {
6685 			*XS_STSP(xs) = SCSI_BUSY;
6686 			XS_SETERR(xs, HBA_TGTBSY);
6687 		}
6688 		return;
6689 
6690 	default:
6691 		isp_prt(isp, ISP_LOGERR, "Unknown Completion Status 0x%x on chan %d", sp->req_completion_status, chan);
6692 		break;
6693 	}
6694 	if (XS_NOERR(xs)) {
6695 		XS_SETERR(xs, HBA_BOTCH);
6696 	}
6697 }
6698 
6699 static void
6700 isp_fastpost_complete(ispsoftc_t *isp, uint32_t fph)
6701 {
6702 	XS_T *xs;
6703 
6704 	if (fph == 0) {
6705 		return;
6706 	}
6707 	xs = isp_find_xs(isp, fph);
6708 	if (xs == NULL) {
6709 		isp_prt(isp, ISP_LOGWARN,
6710 		    "Command for fast post handle 0x%x not found", fph);
6711 		return;
6712 	}
6713 	isp_destroy_handle(isp, fph);
6714 
6715 	/*
6716 	 * Since we don't have a result queue entry item,
6717 	 * we must believe that SCSI status is zero and
6718 	 * that all data transferred.
6719 	 */
6720 	XS_SET_RESID(xs, 0);
6721 	*XS_STSP(xs) = SCSI_GOOD;
6722 	if (XS_XFRLEN(xs)) {
6723 		ISP_DMAFREE(isp, xs, fph);
6724 	}
6725 	if (isp->isp_nactive) {
6726 		isp->isp_nactive--;
6727 	}
6728 	isp->isp_fphccmplt++;
6729 	isp_done(xs);
6730 }
6731 
6732 static int
6733 isp_mbox_continue(ispsoftc_t *isp)
6734 {
6735 	mbreg_t mbs;
6736 	uint16_t *ptr;
6737 	uint32_t offset;
6738 
6739 	switch (isp->isp_lastmbxcmd) {
6740 	case MBOX_WRITE_RAM_WORD:
6741 	case MBOX_READ_RAM_WORD:
6742 	case MBOX_WRITE_RAM_WORD_EXTENDED:
6743 	case MBOX_READ_RAM_WORD_EXTENDED:
6744 		break;
6745 	default:
6746 		return (1);
6747 	}
6748 	if (isp->isp_mboxtmp[0] != MBOX_COMMAND_COMPLETE) {
6749 		isp->isp_mbxwrk0 = 0;
6750 		return (-1);
6751 	}
6752 
6753 	/*
6754 	 * Clear the previous interrupt.
6755 	 */
6756 	if (IS_24XX(isp)) {
6757 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_CLEAR_RISC_INT);
6758 	} else {
6759 		ISP_WRITE(isp, HCCR, HCCR_CMD_CLEAR_RISC_INT);
6760 		ISP_WRITE(isp, BIU_SEMA, 0);
6761 	}
6762 
6763 	/*
6764 	 * Continue with next word.
6765 	 */
6766 	ISP_MEMZERO(&mbs, sizeof (mbs));
6767 	ptr = isp->isp_mbxworkp;
6768 	switch (isp->isp_lastmbxcmd) {
6769 	case MBOX_WRITE_RAM_WORD:
6770 		mbs.param[1] = isp->isp_mbxwrk1++;
6771 		mbs.param[2] = *ptr++;
6772 		break;
6773 	case MBOX_READ_RAM_WORD:
6774 		*ptr++ = isp->isp_mboxtmp[2];
6775 		mbs.param[1] = isp->isp_mbxwrk1++;
6776 		break;
6777 	case MBOX_WRITE_RAM_WORD_EXTENDED:
6778 		if (IS_24XX(isp)) {
6779 			uint32_t *lptr = (uint32_t *)ptr;
6780 			mbs.param[2] = lptr[0];
6781 			mbs.param[3] = lptr[0] >> 16;
6782 			lptr++;
6783 			ptr = (uint16_t *)lptr;
6784 		} else {
6785 			mbs.param[2] = *ptr++;
6786 		}
6787 		offset = isp->isp_mbxwrk1;
6788 		offset |= isp->isp_mbxwrk8 << 16;
6789 		mbs.param[1] = offset;
6790 		mbs.param[8] = offset >> 16;
6791 		offset++;
6792 		isp->isp_mbxwrk1 = offset;
6793 		isp->isp_mbxwrk8 = offset >> 16;
6794 		break;
6795 	case MBOX_READ_RAM_WORD_EXTENDED:
6796 		if (IS_24XX(isp)) {
6797 			uint32_t *lptr = (uint32_t *)ptr;
6798 			uint32_t val = isp->isp_mboxtmp[2];
6799 			val |= (isp->isp_mboxtmp[3]) << 16;
6800 			*lptr++ = val;
6801 			ptr = (uint16_t *)lptr;
6802 		} else {
6803 			*ptr++ = isp->isp_mboxtmp[2];
6804 		}
6805 		offset = isp->isp_mbxwrk1;
6806 		offset |= isp->isp_mbxwrk8 << 16;
6807 		mbs.param[1] = offset;
6808 		mbs.param[8] = offset >> 16;
6809 		offset++;
6810 		isp->isp_mbxwrk1 = offset;
6811 		isp->isp_mbxwrk8 = offset >> 16;
6812 		break;
6813 	}
6814 	isp->isp_mbxworkp = ptr;
6815 	isp->isp_mbxwrk0--;
6816 	mbs.param[0] = isp->isp_lastmbxcmd;
6817 	mbs.logval = MBLOGALL;
6818 	isp_mboxcmd_qnw(isp, &mbs, 0);
6819 	return (0);
6820 }
6821 
6822 #define	ISP_SCSI_IBITS(op)		(mbpscsi[((op)<<1)])
6823 #define	ISP_SCSI_OBITS(op)		(mbpscsi[((op)<<1) + 1])
6824 #define	ISP_SCSI_OPMAP(in, out)		in, out
6825 static const uint8_t mbpscsi[] = {
6826 	ISP_SCSI_OPMAP(0x01, 0x01),	/* 0x00: MBOX_NO_OP */
6827 	ISP_SCSI_OPMAP(0x1f, 0x01),	/* 0x01: MBOX_LOAD_RAM */
6828 	ISP_SCSI_OPMAP(0x03, 0x01),	/* 0x02: MBOX_EXEC_FIRMWARE */
6829 	ISP_SCSI_OPMAP(0x1f, 0x01),	/* 0x03: MBOX_DUMP_RAM */
6830 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x04: MBOX_WRITE_RAM_WORD */
6831 	ISP_SCSI_OPMAP(0x03, 0x07),	/* 0x05: MBOX_READ_RAM_WORD */
6832 	ISP_SCSI_OPMAP(0x3f, 0x3f),	/* 0x06: MBOX_MAILBOX_REG_TEST */
6833 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x07: MBOX_VERIFY_CHECKSUM	*/
6834 	ISP_SCSI_OPMAP(0x01, 0x0f),	/* 0x08: MBOX_ABOUT_FIRMWARE */
6835 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x09: */
6836 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x0a: */
6837 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x0b: */
6838 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x0c: */
6839 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x0d: */
6840 	ISP_SCSI_OPMAP(0x01, 0x05),	/* 0x0e: MBOX_CHECK_FIRMWARE */
6841 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x0f: */
6842 	ISP_SCSI_OPMAP(0x1f, 0x1f),	/* 0x10: MBOX_INIT_REQ_QUEUE */
6843 	ISP_SCSI_OPMAP(0x3f, 0x3f),	/* 0x11: MBOX_INIT_RES_QUEUE */
6844 	ISP_SCSI_OPMAP(0x0f, 0x0f),	/* 0x12: MBOX_EXECUTE_IOCB */
6845 	ISP_SCSI_OPMAP(0x03, 0x03),	/* 0x13: MBOX_WAKE_UP	*/
6846 	ISP_SCSI_OPMAP(0x01, 0x3f),	/* 0x14: MBOX_STOP_FIRMWARE */
6847 	ISP_SCSI_OPMAP(0x0f, 0x0f),	/* 0x15: MBOX_ABORT */
6848 	ISP_SCSI_OPMAP(0x03, 0x03),	/* 0x16: MBOX_ABORT_DEVICE */
6849 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x17: MBOX_ABORT_TARGET */
6850 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x18: MBOX_BUS_RESET */
6851 	ISP_SCSI_OPMAP(0x03, 0x07),	/* 0x19: MBOX_STOP_QUEUE */
6852 	ISP_SCSI_OPMAP(0x03, 0x07),	/* 0x1a: MBOX_START_QUEUE */
6853 	ISP_SCSI_OPMAP(0x03, 0x07),	/* 0x1b: MBOX_SINGLE_STEP_QUEUE */
6854 	ISP_SCSI_OPMAP(0x03, 0x07),	/* 0x1c: MBOX_ABORT_QUEUE */
6855 	ISP_SCSI_OPMAP(0x03, 0x4f),	/* 0x1d: MBOX_GET_DEV_QUEUE_STATUS */
6856 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x1e: */
6857 	ISP_SCSI_OPMAP(0x01, 0x07),	/* 0x1f: MBOX_GET_FIRMWARE_STATUS */
6858 	ISP_SCSI_OPMAP(0x01, 0x07),	/* 0x20: MBOX_GET_INIT_SCSI_ID */
6859 	ISP_SCSI_OPMAP(0x01, 0x07),	/* 0x21: MBOX_GET_SELECT_TIMEOUT */
6860 	ISP_SCSI_OPMAP(0x01, 0xc7),	/* 0x22: MBOX_GET_RETRY_COUNT	*/
6861 	ISP_SCSI_OPMAP(0x01, 0x07),	/* 0x23: MBOX_GET_TAG_AGE_LIMIT */
6862 	ISP_SCSI_OPMAP(0x01, 0x03),	/* 0x24: MBOX_GET_CLOCK_RATE */
6863 	ISP_SCSI_OPMAP(0x01, 0x07),	/* 0x25: MBOX_GET_ACT_NEG_STATE */
6864 	ISP_SCSI_OPMAP(0x01, 0x07),	/* 0x26: MBOX_GET_ASYNC_DATA_SETUP_TIME */
6865 	ISP_SCSI_OPMAP(0x01, 0x07),	/* 0x27: MBOX_GET_PCI_PARAMS */
6866 	ISP_SCSI_OPMAP(0x03, 0x4f),	/* 0x28: MBOX_GET_TARGET_PARAMS */
6867 	ISP_SCSI_OPMAP(0x03, 0x0f),	/* 0x29: MBOX_GET_DEV_QUEUE_PARAMS */
6868 	ISP_SCSI_OPMAP(0x01, 0x07),	/* 0x2a: MBOX_GET_RESET_DELAY_PARAMS */
6869 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x2b: */
6870 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x2c: */
6871 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x2d: */
6872 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x2e: */
6873 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x2f: */
6874 	ISP_SCSI_OPMAP(0x03, 0x03),	/* 0x30: MBOX_SET_INIT_SCSI_ID */
6875 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x31: MBOX_SET_SELECT_TIMEOUT */
6876 	ISP_SCSI_OPMAP(0xc7, 0xc7),	/* 0x32: MBOX_SET_RETRY_COUNT	*/
6877 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x33: MBOX_SET_TAG_AGE_LIMIT */
6878 	ISP_SCSI_OPMAP(0x03, 0x03),	/* 0x34: MBOX_SET_CLOCK_RATE */
6879 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x35: MBOX_SET_ACT_NEG_STATE */
6880 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x36: MBOX_SET_ASYNC_DATA_SETUP_TIME */
6881 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x37: MBOX_SET_PCI_CONTROL_PARAMS */
6882 	ISP_SCSI_OPMAP(0x4f, 0x4f),	/* 0x38: MBOX_SET_TARGET_PARAMS */
6883 	ISP_SCSI_OPMAP(0x0f, 0x0f),	/* 0x39: MBOX_SET_DEV_QUEUE_PARAMS */
6884 	ISP_SCSI_OPMAP(0x07, 0x07),	/* 0x3a: MBOX_SET_RESET_DELAY_PARAMS */
6885 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x3b: */
6886 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x3c: */
6887 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x3d: */
6888 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x3e: */
6889 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x3f: */
6890 	ISP_SCSI_OPMAP(0x01, 0x03),	/* 0x40: MBOX_RETURN_BIOS_BLOCK_ADDR */
6891 	ISP_SCSI_OPMAP(0x3f, 0x01),	/* 0x41: MBOX_WRITE_FOUR_RAM_WORDS */
6892 	ISP_SCSI_OPMAP(0x03, 0x07),	/* 0x42: MBOX_EXEC_BIOS_IOCB */
6893 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x43: */
6894 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x44: */
6895 	ISP_SCSI_OPMAP(0x03, 0x03),	/* 0x45: SET SYSTEM PARAMETER */
6896 	ISP_SCSI_OPMAP(0x01, 0x03),	/* 0x46: GET SYSTEM PARAMETER */
6897 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x47: */
6898 	ISP_SCSI_OPMAP(0x01, 0xcf),	/* 0x48: GET SCAM CONFIGURATION */
6899 	ISP_SCSI_OPMAP(0xcf, 0xcf),	/* 0x49: SET SCAM CONFIGURATION */
6900 	ISP_SCSI_OPMAP(0x03, 0x03),	/* 0x4a: MBOX_SET_FIRMWARE_FEATURES */
6901 	ISP_SCSI_OPMAP(0x01, 0x03),	/* 0x4b: MBOX_GET_FIRMWARE_FEATURES */
6902 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x4c: */
6903 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x4d: */
6904 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x4e: */
6905 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x4f: */
6906 	ISP_SCSI_OPMAP(0xdf, 0xdf),	/* 0x50: LOAD RAM A64 */
6907 	ISP_SCSI_OPMAP(0xdf, 0xdf),	/* 0x51: DUMP RAM A64 */
6908 	ISP_SCSI_OPMAP(0xdf, 0xff),	/* 0x52: INITIALIZE REQUEST QUEUE A64 */
6909 	ISP_SCSI_OPMAP(0xef, 0xff),	/* 0x53: INITIALIZE RESPONSE QUEUE A64 */
6910 	ISP_SCSI_OPMAP(0xcf, 0x01),	/* 0x54: EXECUCUTE COMMAND IOCB A64 */
6911 	ISP_SCSI_OPMAP(0x07, 0x01),	/* 0x55: ENABLE TARGET MODE */
6912 	ISP_SCSI_OPMAP(0x03, 0x0f),	/* 0x56: GET TARGET STATUS */
6913 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x57: */
6914 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x58: */
6915 	ISP_SCSI_OPMAP(0x00, 0x00),	/* 0x59: */
6916 	ISP_SCSI_OPMAP(0x03, 0x03),	/* 0x5a: SET DATA OVERRUN RECOVERY MODE */
6917 	ISP_SCSI_OPMAP(0x01, 0x03),	/* 0x5b: GET DATA OVERRUN RECOVERY MODE */
6918 	ISP_SCSI_OPMAP(0x0f, 0x0f),	/* 0x5c: SET HOST DATA */
6919 	ISP_SCSI_OPMAP(0x01, 0x01)	/* 0x5d: GET NOST DATA */
6920 };
6921 #define	MAX_SCSI_OPCODE	0x5d
6922 
6923 static const char *scsi_mbcmd_names[] = {
6924 	"NO-OP",
6925 	"LOAD RAM",
6926 	"EXEC FIRMWARE",
6927 	"DUMP RAM",
6928 	"WRITE RAM WORD",
6929 	"READ RAM WORD",
6930 	"MAILBOX REG TEST",
6931 	"VERIFY CHECKSUM",
6932 	"ABOUT FIRMWARE",
6933 	NULL,
6934 	NULL,
6935 	NULL,
6936 	NULL,
6937 	NULL,
6938 	"CHECK FIRMWARE",
6939 	NULL,
6940 	"INIT REQUEST QUEUE",
6941 	"INIT RESULT QUEUE",
6942 	"EXECUTE IOCB",
6943 	"WAKE UP",
6944 	"STOP FIRMWARE",
6945 	"ABORT",
6946 	"ABORT DEVICE",
6947 	"ABORT TARGET",
6948 	"BUS RESET",
6949 	"STOP QUEUE",
6950 	"START QUEUE",
6951 	"SINGLE STEP QUEUE",
6952 	"ABORT QUEUE",
6953 	"GET DEV QUEUE STATUS",
6954 	NULL,
6955 	"GET FIRMWARE STATUS",
6956 	"GET INIT SCSI ID",
6957 	"GET SELECT TIMEOUT",
6958 	"GET RETRY COUNT",
6959 	"GET TAG AGE LIMIT",
6960 	"GET CLOCK RATE",
6961 	"GET ACT NEG STATE",
6962 	"GET ASYNC DATA SETUP TIME",
6963 	"GET PCI PARAMS",
6964 	"GET TARGET PARAMS",
6965 	"GET DEV QUEUE PARAMS",
6966 	"GET RESET DELAY PARAMS",
6967 	NULL,
6968 	NULL,
6969 	NULL,
6970 	NULL,
6971 	NULL,
6972 	"SET INIT SCSI ID",
6973 	"SET SELECT TIMEOUT",
6974 	"SET RETRY COUNT",
6975 	"SET TAG AGE LIMIT",
6976 	"SET CLOCK RATE",
6977 	"SET ACT NEG STATE",
6978 	"SET ASYNC DATA SETUP TIME",
6979 	"SET PCI CONTROL PARAMS",
6980 	"SET TARGET PARAMS",
6981 	"SET DEV QUEUE PARAMS",
6982 	"SET RESET DELAY PARAMS",
6983 	NULL,
6984 	NULL,
6985 	NULL,
6986 	NULL,
6987 	NULL,
6988 	"RETURN BIOS BLOCK ADDR",
6989 	"WRITE FOUR RAM WORDS",
6990 	"EXEC BIOS IOCB",
6991 	NULL,
6992 	NULL,
6993 	"SET SYSTEM PARAMETER",
6994 	"GET SYSTEM PARAMETER",
6995 	NULL,
6996 	"GET SCAM CONFIGURATION",
6997 	"SET SCAM CONFIGURATION",
6998 	"SET FIRMWARE FEATURES",
6999 	"GET FIRMWARE FEATURES",
7000 	NULL,
7001 	NULL,
7002 	NULL,
7003 	NULL,
7004 	"LOAD RAM A64",
7005 	"DUMP RAM A64",
7006 	"INITIALIZE REQUEST QUEUE A64",
7007 	"INITIALIZE RESPONSE QUEUE A64",
7008 	"EXECUTE IOCB A64",
7009 	"ENABLE TARGET MODE",
7010 	"GET TARGET MODE STATE",
7011 	NULL,
7012 	NULL,
7013 	NULL,
7014 	"SET DATA OVERRUN RECOVERY MODE",
7015 	"GET DATA OVERRUN RECOVERY MODE",
7016 	"SET HOST DATA",
7017 	"GET NOST DATA",
7018 };
7019 
7020 #define	ISP_FC_IBITS(op)	((mbpfc[((op)<<3) + 0] << 24) | (mbpfc[((op)<<3) + 1] << 16) | (mbpfc[((op)<<3) + 2] << 8) | (mbpfc[((op)<<3) + 3]))
7021 #define	ISP_FC_OBITS(op)	((mbpfc[((op)<<3) + 4] << 24) | (mbpfc[((op)<<3) + 5] << 16) | (mbpfc[((op)<<3) + 6] << 8) | (mbpfc[((op)<<3) + 7]))
7022 
7023 #define	ISP_FC_OPMAP(in0, out0)							  0,   0,   0, in0,    0,    0,    0, out0
7024 #define	ISP_FC_OPMAP_HALF(in1, in0, out1, out0)					  0,   0, in1, in0,    0,    0, out1, out0
7025 #define	ISP_FC_OPMAP_FULL(in3, in2, in1, in0, out3, out2, out1, out0)		in3, in2, in1, in0, out3, out2, out1, out0
7026 static const uint32_t mbpfc[] = {
7027 	ISP_FC_OPMAP(0x01, 0x01),	/* 0x00: MBOX_NO_OP */
7028 	ISP_FC_OPMAP(0x1f, 0x01),	/* 0x01: MBOX_LOAD_RAM */
7029 	ISP_FC_OPMAP_HALF(0x07, 0xff, 0x00, 0x03),	/* 0x02: MBOX_EXEC_FIRMWARE */
7030 	ISP_FC_OPMAP(0xdf, 0x01),	/* 0x03: MBOX_DUMP_RAM */
7031 	ISP_FC_OPMAP(0x07, 0x07),	/* 0x04: MBOX_WRITE_RAM_WORD */
7032 	ISP_FC_OPMAP(0x03, 0x07),	/* 0x05: MBOX_READ_RAM_WORD */
7033 	ISP_FC_OPMAP_FULL(0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff),	/* 0x06: MBOX_MAILBOX_REG_TEST */
7034 	ISP_FC_OPMAP(0x07, 0x07),	/* 0x07: MBOX_VERIFY_CHECKSUM	*/
7035 	ISP_FC_OPMAP_FULL(0x0, 0x0, 0x0, 0x01, 0x0, 0x3, 0x80, 0x7f),	/* 0x08: MBOX_ABOUT_FIRMWARE */
7036 	ISP_FC_OPMAP(0xdf, 0x01),	/* 0x09: MBOX_LOAD_RISC_RAM_2100 */
7037 	ISP_FC_OPMAP(0xdf, 0x01),	/* 0x0a: DUMP RAM */
7038 	ISP_FC_OPMAP_HALF(0x1, 0xff, 0x0, 0x01),	/* 0x0b: MBOX_LOAD_RISC_RAM */
7039 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x0c: */
7040 	ISP_FC_OPMAP_HALF(0x1, 0x0f, 0x0, 0x01),	/* 0x0d: MBOX_WRITE_RAM_WORD_EXTENDED */
7041 	ISP_FC_OPMAP(0x01, 0x05),	/* 0x0e: MBOX_CHECK_FIRMWARE */
7042 	ISP_FC_OPMAP_HALF(0x1, 0x03, 0x0, 0x0d),	/* 0x0f: MBOX_READ_RAM_WORD_EXTENDED */
7043 	ISP_FC_OPMAP(0x1f, 0x11),	/* 0x10: MBOX_INIT_REQ_QUEUE */
7044 	ISP_FC_OPMAP(0x2f, 0x21),	/* 0x11: MBOX_INIT_RES_QUEUE */
7045 	ISP_FC_OPMAP(0x0f, 0x01),	/* 0x12: MBOX_EXECUTE_IOCB */
7046 	ISP_FC_OPMAP(0x03, 0x03),	/* 0x13: MBOX_WAKE_UP	*/
7047 	ISP_FC_OPMAP_HALF(0x1, 0xff, 0x0, 0x03),	/* 0x14: MBOX_STOP_FIRMWARE */
7048 	ISP_FC_OPMAP(0x4f, 0x01),	/* 0x15: MBOX_ABORT */
7049 	ISP_FC_OPMAP(0x07, 0x01),	/* 0x16: MBOX_ABORT_DEVICE */
7050 	ISP_FC_OPMAP(0x07, 0x01),	/* 0x17: MBOX_ABORT_TARGET */
7051 	ISP_FC_OPMAP(0x03, 0x03),	/* 0x18: MBOX_BUS_RESET */
7052 	ISP_FC_OPMAP(0x07, 0x05),	/* 0x19: MBOX_STOP_QUEUE */
7053 	ISP_FC_OPMAP(0x07, 0x05),	/* 0x1a: MBOX_START_QUEUE */
7054 	ISP_FC_OPMAP(0x07, 0x05),	/* 0x1b: MBOX_SINGLE_STEP_QUEUE */
7055 	ISP_FC_OPMAP(0x07, 0x05),	/* 0x1c: MBOX_ABORT_QUEUE */
7056 	ISP_FC_OPMAP(0x07, 0x03),	/* 0x1d: MBOX_GET_DEV_QUEUE_STATUS */
7057 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x1e: */
7058 	ISP_FC_OPMAP(0x01, 0x07),	/* 0x1f: MBOX_GET_FIRMWARE_STATUS */
7059 	ISP_FC_OPMAP_HALF(0x2, 0x01, 0x7e, 0xcf),	/* 0x20: MBOX_GET_LOOP_ID */
7060 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x21: */
7061 	ISP_FC_OPMAP(0x03, 0x4b),	/* 0x22: MBOX_GET_TIMEOUT_PARAMS */
7062 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x23: */
7063 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x24: */
7064 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x25: */
7065 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x26: */
7066 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x27: */
7067 	ISP_FC_OPMAP(0x01, 0x03),	/* 0x28: MBOX_GET_FIRMWARE_OPTIONS */
7068 	ISP_FC_OPMAP(0x03, 0x07),	/* 0x29: MBOX_GET_PORT_QUEUE_PARAMS */
7069 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x2a: */
7070 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x2b: */
7071 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x2c: */
7072 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x2d: */
7073 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x2e: */
7074 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x2f: */
7075 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x30: */
7076 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x31: */
7077 	ISP_FC_OPMAP(0x4b, 0x4b),	/* 0x32: MBOX_SET_TIMEOUT_PARAMS */
7078 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x33: */
7079 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x34: */
7080 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x35: */
7081 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x36: */
7082 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x37: */
7083 	ISP_FC_OPMAP(0x0f, 0x01),	/* 0x38: MBOX_SET_FIRMWARE_OPTIONS */
7084 	ISP_FC_OPMAP(0x0f, 0x07),	/* 0x39: MBOX_SET_PORT_QUEUE_PARAMS */
7085 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x3a: */
7086 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x3b: */
7087 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x3c: */
7088 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x3d: */
7089 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x3e: */
7090 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x3f: */
7091 	ISP_FC_OPMAP(0x03, 0x01),	/* 0x40: MBOX_LOOP_PORT_BYPASS */
7092 	ISP_FC_OPMAP(0x03, 0x01),	/* 0x41: MBOX_LOOP_PORT_ENABLE */
7093 	ISP_FC_OPMAP_HALF(0x0, 0x01, 0x3, 0xcf),	/* 0x42: MBOX_GET_RESOURCE_COUNT */
7094 	ISP_FC_OPMAP(0x01, 0x01),	/* 0x43: MBOX_REQUEST_OFFLINE_MODE */
7095 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x44: */
7096 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x45: */
7097 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x46: */
7098 	ISP_FC_OPMAP(0xcf, 0x03),	/* 0x47: GET PORT_DATABASE ENHANCED */
7099 	ISP_FC_OPMAP(0xcf, 0x0f),	/* 0x48: MBOX_INIT_FIRMWARE_MULTI_ID */
7100 	ISP_FC_OPMAP(0xcd, 0x01),	/* 0x49: MBOX_GET_VP_DATABASE */
7101 	ISP_FC_OPMAP_HALF(0x2, 0xcd, 0x0, 0x01),	/* 0x4a: MBOX_GET_VP_DATABASE_ENTRY */
7102 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x4b: */
7103 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x4c: */
7104 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x4d: */
7105 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x4e: */
7106 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x4f: */
7107 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x50: */
7108 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x51: */
7109 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x52: */
7110 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x53: */
7111 	ISP_FC_OPMAP(0xcf, 0x01),	/* 0x54: EXECUTE IOCB A64 */
7112 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x55: */
7113 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x56: */
7114 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x57: */
7115 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x58: */
7116 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x59: */
7117 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x5a: */
7118 	ISP_FC_OPMAP(0x03, 0x01),	/* 0x5b: MBOX_DRIVER_HEARTBEAT */
7119 	ISP_FC_OPMAP(0xcf, 0x01),	/* 0x5c: MBOX_FW_HEARTBEAT */
7120 	ISP_FC_OPMAP(0x07, 0x1f),	/* 0x5d: MBOX_GET_SET_DATA_RATE */
7121 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x5e: */
7122 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x5f: */
7123 	ISP_FC_OPMAP(0xcf, 0x0f),	/* 0x60: MBOX_INIT_FIRMWARE */
7124 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x61: */
7125 	ISP_FC_OPMAP(0x01, 0x01),	/* 0x62: MBOX_INIT_LIP */
7126 	ISP_FC_OPMAP(0xcd, 0x03),	/* 0x63: MBOX_GET_FC_AL_POSITION_MAP */
7127 	ISP_FC_OPMAP(0xcf, 0x01),	/* 0x64: MBOX_GET_PORT_DB */
7128 	ISP_FC_OPMAP(0x07, 0x01),	/* 0x65: MBOX_CLEAR_ACA */
7129 	ISP_FC_OPMAP(0x07, 0x01),	/* 0x66: MBOX_TARGET_RESET */
7130 	ISP_FC_OPMAP(0x07, 0x01),	/* 0x67: MBOX_CLEAR_TASK_SET */
7131 	ISP_FC_OPMAP(0x07, 0x01),	/* 0x68: MBOX_ABORT_TASK_SET */
7132 	ISP_FC_OPMAP(0x01, 0x07),	/* 0x69: MBOX_GET_FW_STATE */
7133 	ISP_FC_OPMAP_HALF(0x6, 0x03, 0x0, 0xcf),	/* 0x6a: MBOX_GET_PORT_NAME */
7134 	ISP_FC_OPMAP(0xcf, 0x01),	/* 0x6b: MBOX_GET_LINK_STATUS */
7135 	ISP_FC_OPMAP(0x0f, 0x01),	/* 0x6c: MBOX_INIT_LIP_RESET */
7136 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x6d: */
7137 	ISP_FC_OPMAP(0xcf, 0x03),	/* 0x6e: MBOX_SEND_SNS */
7138 	ISP_FC_OPMAP(0x0f, 0x07),	/* 0x6f: MBOX_FABRIC_LOGIN */
7139 	ISP_FC_OPMAP_HALF(0x02, 0x03, 0x00, 0x03),	/* 0x70: MBOX_SEND_CHANGE_REQUEST */
7140 	ISP_FC_OPMAP(0x03, 0x03),	/* 0x71: MBOX_FABRIC_LOGOUT */
7141 	ISP_FC_OPMAP(0x0f, 0x0f),	/* 0x72: MBOX_INIT_LIP_LOGIN */
7142 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x73: */
7143 	ISP_FC_OPMAP(0x07, 0x01),	/* 0x74: LOGIN LOOP PORT */
7144 	ISP_FC_OPMAP_HALF(0x03, 0xcf, 0x00, 0x07),	/* 0x75: GET PORT/NODE NAME LIST */
7145 	ISP_FC_OPMAP(0x4f, 0x01),	/* 0x76: SET VENDOR ID */
7146 	ISP_FC_OPMAP(0xcd, 0x01),	/* 0x77: INITIALIZE IP MAILBOX */
7147 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x78: */
7148 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x79: */
7149 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x7a: */
7150 	ISP_FC_OPMAP(0x00, 0x00),	/* 0x7b: */
7151 	ISP_FC_OPMAP_HALF(0x03, 0x4f, 0x00, 0x07),	/* 0x7c: Get ID List */
7152 	ISP_FC_OPMAP(0xcf, 0x01),	/* 0x7d: SEND LFA */
7153 	ISP_FC_OPMAP(0x0f, 0x01)	/* 0x7e: LUN RESET */
7154 };
7155 #define	MAX_FC_OPCODE	0x7e
7156 /*
7157  * Footnotes
7158  *
7159  * (1): this sets bits 21..16 in mailbox register #8, which we nominally
7160  *	do not access at this time in the core driver. The caller is
7161  *	responsible for setting this register first (Gross!). The assumption
7162  *	is that we won't overflow.
7163  */
7164 
7165 static const char *fc_mbcmd_names[] = {
7166 	"NO-OP",			/* 00h */
7167 	"LOAD RAM",
7168 	"EXEC FIRMWARE",
7169 	"DUMP RAM",
7170 	"WRITE RAM WORD",
7171 	"READ RAM WORD",
7172 	"MAILBOX REG TEST",
7173 	"VERIFY CHECKSUM",
7174 	"ABOUT FIRMWARE",
7175 	"LOAD RAM (2100)",
7176 	"DUMP RAM",
7177 	"LOAD RISC RAM",
7178 	"DUMP RISC RAM",
7179 	"WRITE RAM WORD EXTENDED",
7180 	"CHECK FIRMWARE",
7181 	"READ RAM WORD EXTENDED",
7182 	"INIT REQUEST QUEUE",		/* 10h */
7183 	"INIT RESULT QUEUE",
7184 	"EXECUTE IOCB",
7185 	"WAKE UP",
7186 	"STOP FIRMWARE",
7187 	"ABORT",
7188 	"ABORT DEVICE",
7189 	"ABORT TARGET",
7190 	"BUS RESET",
7191 	"STOP QUEUE",
7192 	"START QUEUE",
7193 	"SINGLE STEP QUEUE",
7194 	"ABORT QUEUE",
7195 	"GET DEV QUEUE STATUS",
7196 	NULL,
7197 	"GET FIRMWARE STATUS",
7198 	"GET LOOP ID",			/* 20h */
7199 	NULL,
7200 	"GET TIMEOUT PARAMS",
7201 	NULL,
7202 	NULL,
7203 	NULL,
7204 	NULL,
7205 	NULL,
7206 	"GET FIRMWARE OPTIONS",
7207 	"GET PORT QUEUE PARAMS",
7208 	"GENERATE SYSTEM ERROR",
7209 	NULL,
7210 	NULL,
7211 	NULL,
7212 	NULL,
7213 	NULL,
7214 	"WRITE SFP",			/* 30h */
7215 	"READ SFP",
7216 	"SET TIMEOUT PARAMS",
7217 	NULL,
7218 	NULL,
7219 	NULL,
7220 	NULL,
7221 	NULL,
7222 	"SET FIRMWARE OPTIONS",
7223 	"SET PORT QUEUE PARAMS",
7224 	NULL,
7225 	"SET FC LED CONF",
7226 	NULL,
7227 	"RESTART NIC FIRMWARE",
7228 	"ACCESS CONTROL",
7229 	NULL,
7230 	"LOOP PORT BYPASS",		/* 40h */
7231 	"LOOP PORT ENABLE",
7232 	"GET RESOURCE COUNT",
7233 	"REQUEST NON PARTICIPATING MODE",
7234 	"DIAGNOSTIC ECHO TEST",
7235 	"DIAGNOSTIC LOOPBACK",
7236 	NULL,
7237 	"GET PORT DATABASE ENHANCED",
7238 	"INIT FIRMWARE MULTI ID",
7239 	"GET VP DATABASE",
7240 	"GET VP DATABASE ENTRY",
7241 	NULL,
7242 	NULL,
7243 	NULL,
7244 	NULL,
7245 	NULL,
7246 	"GET FCF LIST",			/* 50h */
7247 	"GET DCBX PARAMETERS",
7248 	NULL,
7249 	"HOST MEMORY COPY",
7250 	"EXECUTE IOCB A64",
7251 	NULL,
7252 	NULL,
7253 	"SEND RNID",
7254 	NULL,
7255 	"SET PARAMETERS",
7256 	"GET PARAMETERS",
7257 	"DRIVER HEARTBEAT",
7258 	"FIRMWARE HEARTBEAT",
7259 	"GET/SET DATA RATE",
7260 	"SEND RNFT",
7261 	NULL,
7262 	"INIT FIRMWARE",		/* 60h */
7263 	"GET INIT CONTROL BLOCK",
7264 	"INIT LIP",
7265 	"GET FC-AL POSITION MAP",
7266 	"GET PORT DATABASE",
7267 	"CLEAR ACA",
7268 	"TARGET RESET",
7269 	"CLEAR TASK SET",
7270 	"ABORT TASK SET",
7271 	"GET FW STATE",
7272 	"GET PORT NAME",
7273 	"GET LINK STATUS",
7274 	"INIT LIP RESET",
7275 	"GET LINK STATS & PRIVATE DATA CNTS",
7276 	"SEND SNS",
7277 	"FABRIC LOGIN",
7278 	"SEND CHANGE REQUEST",		/* 70h */
7279 	"FABRIC LOGOUT",
7280 	"INIT LIP LOGIN",
7281 	NULL,
7282 	"LOGIN LOOP PORT",
7283 	"GET PORT/NODE NAME LIST",
7284 	"SET VENDOR ID",
7285 	"INITIALIZE IP MAILBOX",
7286 	NULL,
7287 	NULL,
7288 	"GET XGMAC STATS",
7289 	NULL,
7290 	"GET ID LIST",
7291 	"SEND LFA",
7292 	"LUN RESET"
7293 };
7294 
7295 static void
7296 isp_mboxcmd_qnw(ispsoftc_t *isp, mbreg_t *mbp, int nodelay)
7297 {
7298 	unsigned int ibits, obits, box, opcode;
7299 
7300 	opcode = mbp->param[0];
7301 	if (IS_FC(isp)) {
7302 		ibits = ISP_FC_IBITS(opcode);
7303 		obits = ISP_FC_OBITS(opcode);
7304 	} else {
7305 		ibits = ISP_SCSI_IBITS(opcode);
7306 		obits = ISP_SCSI_OBITS(opcode);
7307 	}
7308 	ibits |= mbp->ibits;
7309 	obits |= mbp->obits;
7310 	for (box = 0; box < ISP_NMBOX(isp); box++) {
7311 		if (ibits & (1 << box)) {
7312 			ISP_WRITE(isp, MBOX_OFF(box), mbp->param[box]);
7313 		}
7314 		if (nodelay == 0) {
7315 			isp->isp_mboxtmp[box] = mbp->param[box] = 0;
7316 		}
7317 	}
7318 	if (nodelay == 0) {
7319 		isp->isp_lastmbxcmd = opcode;
7320 		isp->isp_obits = obits;
7321 		isp->isp_mboxbsy = 1;
7322 	}
7323 	if (IS_24XX(isp)) {
7324 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_SET_HOST_INT);
7325 	} else {
7326 		ISP_WRITE(isp, HCCR, HCCR_CMD_SET_HOST_INT);
7327 	}
7328 	/*
7329 	 * Oddly enough, if we're not delaying for an answer,
7330 	 * delay a bit to give the f/w a chance to pick up the
7331 	 * command.
7332 	 */
7333 	if (nodelay) {
7334 		ISP_DELAY(1000);
7335 	}
7336 }
7337 
7338 static void
7339 isp_mboxcmd(ispsoftc_t *isp, mbreg_t *mbp)
7340 {
7341 	const char *cname, *xname, *sname;
7342 	char tname[16], mname[16];
7343 	unsigned int ibits, obits, box, opcode;
7344 
7345 	opcode = mbp->param[0];
7346 	if (IS_FC(isp)) {
7347 		if (opcode > MAX_FC_OPCODE) {
7348 			mbp->param[0] = MBOX_INVALID_COMMAND;
7349 			isp_prt(isp, ISP_LOGERR, "Unknown Command 0x%x", opcode);
7350 			return;
7351 		}
7352 		cname = fc_mbcmd_names[opcode];
7353 		ibits = ISP_FC_IBITS(opcode);
7354 		obits = ISP_FC_OBITS(opcode);
7355 	} else {
7356 		if (opcode > MAX_SCSI_OPCODE) {
7357 			mbp->param[0] = MBOX_INVALID_COMMAND;
7358 			isp_prt(isp, ISP_LOGERR, "Unknown Command 0x%x", opcode);
7359 			return;
7360 		}
7361 		cname = scsi_mbcmd_names[opcode];
7362 		ibits = ISP_SCSI_IBITS(opcode);
7363 		obits = ISP_SCSI_OBITS(opcode);
7364 	}
7365 	if (cname == NULL) {
7366 		cname = tname;
7367 		ISP_SNPRINTF(tname, sizeof tname, "opcode %x", opcode);
7368 	}
7369 	isp_prt(isp, ISP_LOGDEBUG3, "Mailbox Command '%s'", cname);
7370 
7371 	/*
7372 	 * Pick up any additional bits that the caller might have set.
7373 	 */
7374 	ibits |= mbp->ibits;
7375 	obits |= mbp->obits;
7376 
7377 	/*
7378 	 * Mask any bits that the caller wants us to mask
7379 	 */
7380 	ibits &= mbp->ibitm;
7381 	obits &= mbp->obitm;
7382 
7383 
7384 	if (ibits == 0 && obits == 0) {
7385 		mbp->param[0] = MBOX_COMMAND_PARAM_ERROR;
7386 		isp_prt(isp, ISP_LOGERR, "no parameters for 0x%x", opcode);
7387 		return;
7388 	}
7389 
7390 	/*
7391 	 * Get exclusive usage of mailbox registers.
7392 	 */
7393 	if (MBOX_ACQUIRE(isp)) {
7394 		mbp->param[0] = MBOX_REGS_BUSY;
7395 		goto out;
7396 	}
7397 
7398 	for (box = 0; box < ISP_NMBOX(isp); box++) {
7399 		if (ibits & (1 << box)) {
7400 			isp_prt(isp, ISP_LOGDEBUG3, "IN mbox %d = 0x%04x", box,
7401 			    mbp->param[box]);
7402 			ISP_WRITE(isp, MBOX_OFF(box), mbp->param[box]);
7403 		}
7404 		isp->isp_mboxtmp[box] = mbp->param[box] = 0;
7405 	}
7406 
7407 	isp->isp_lastmbxcmd = opcode;
7408 
7409 	/*
7410 	 * We assume that we can't overwrite a previous command.
7411 	 */
7412 	isp->isp_obits = obits;
7413 	isp->isp_mboxbsy = 1;
7414 
7415 	/*
7416 	 * Set Host Interrupt condition so that RISC will pick up mailbox regs.
7417 	 */
7418 	if (IS_24XX(isp)) {
7419 		ISP_WRITE(isp, BIU2400_HCCR, HCCR_2400_CMD_SET_HOST_INT);
7420 	} else {
7421 		ISP_WRITE(isp, HCCR, HCCR_CMD_SET_HOST_INT);
7422 	}
7423 
7424 	/*
7425 	 * While we haven't finished the command, spin our wheels here.
7426 	 */
7427 	MBOX_WAIT_COMPLETE(isp, mbp);
7428 
7429 	/*
7430 	 * Did the command time out?
7431 	 */
7432 	if (mbp->param[0] == MBOX_TIMEOUT) {
7433 		isp->isp_mboxbsy = 0;
7434 		MBOX_RELEASE(isp);
7435 		goto out;
7436 	}
7437 
7438 	/*
7439 	 * Copy back output registers.
7440 	 */
7441 	for (box = 0; box < ISP_NMBOX(isp); box++) {
7442 		if (obits & (1 << box)) {
7443 			mbp->param[box] = isp->isp_mboxtmp[box];
7444 			isp_prt(isp, ISP_LOGDEBUG3, "OUT mbox %d = 0x%04x", box,
7445 			    mbp->param[box]);
7446 		}
7447 	}
7448 
7449 	isp->isp_mboxbsy = 0;
7450 	MBOX_RELEASE(isp);
7451 out:
7452 	if (mbp->logval == 0 || mbp->param[0] == MBOX_COMMAND_COMPLETE)
7453 		return;
7454 
7455 	if ((mbp->param[0] & 0xbfe0) == 0 &&
7456 	    (mbp->logval & MBLOGMASK(mbp->param[0])) == 0)
7457 		return;
7458 
7459 	xname = NULL;
7460 	sname = "";
7461 	switch (mbp->param[0]) {
7462 	case MBOX_INVALID_COMMAND:
7463 		xname = "INVALID COMMAND";
7464 		break;
7465 	case MBOX_HOST_INTERFACE_ERROR:
7466 		xname = "HOST INTERFACE ERROR";
7467 		break;
7468 	case MBOX_TEST_FAILED:
7469 		xname = "TEST FAILED";
7470 		break;
7471 	case MBOX_COMMAND_ERROR:
7472 		xname = "COMMAND ERROR";
7473 		ISP_SNPRINTF(mname, sizeof(mname), " subcode 0x%x",
7474 		    mbp->param[1]);
7475 		sname = mname;
7476 		break;
7477 	case MBOX_COMMAND_PARAM_ERROR:
7478 		xname = "COMMAND PARAMETER ERROR";
7479 		break;
7480 	case MBOX_PORT_ID_USED:
7481 		xname = "PORT ID ALREADY IN USE";
7482 		break;
7483 	case MBOX_LOOP_ID_USED:
7484 		xname = "LOOP ID ALREADY IN USE";
7485 		break;
7486 	case MBOX_ALL_IDS_USED:
7487 		xname = "ALL LOOP IDS IN USE";
7488 		break;
7489 	case MBOX_NOT_LOGGED_IN:
7490 		xname = "NOT LOGGED IN";
7491 		break;
7492 	case MBOX_LINK_DOWN_ERROR:
7493 		xname = "LINK DOWN ERROR";
7494 		break;
7495 	case MBOX_LOOPBACK_ERROR:
7496 		xname = "LOOPBACK ERROR";
7497 		break;
7498 	case MBOX_CHECKSUM_ERROR:
7499 		xname = "CHECKSUM ERROR";
7500 		break;
7501 	case MBOX_INVALID_PRODUCT_KEY:
7502 		xname = "INVALID PRODUCT KEY";
7503 		break;
7504 	case MBOX_REGS_BUSY:
7505 		xname = "REGISTERS BUSY";
7506 		break;
7507 	case MBOX_TIMEOUT:
7508 		xname = "TIMEOUT";
7509 		break;
7510 	default:
7511 		ISP_SNPRINTF(mname, sizeof mname, "error 0x%x", mbp->param[0]);
7512 		xname = mname;
7513 		break;
7514 	}
7515 	if (xname) {
7516 		isp_prt(isp, ISP_LOGALL, "Mailbox Command '%s' failed (%s%s)",
7517 		    cname, xname, sname);
7518 	}
7519 }
7520 
7521 static int
7522 isp_fw_state(ispsoftc_t *isp, int chan)
7523 {
7524 	if (IS_FC(isp)) {
7525 		mbreg_t mbs;
7526 
7527 		MBSINIT(&mbs, MBOX_GET_FW_STATE, MBLOGALL, 0);
7528 		isp_mboxcmd(isp, &mbs);
7529 		if (mbs.param[0] == MBOX_COMMAND_COMPLETE) {
7530 			return (mbs.param[1]);
7531 		}
7532 	}
7533 	return (FW_ERROR);
7534 }
7535 
7536 static void
7537 isp_spi_update(ispsoftc_t *isp, int chan)
7538 {
7539 	int tgt;
7540 	mbreg_t mbs;
7541 	sdparam *sdp;
7542 
7543 	if (IS_FC(isp)) {
7544 		/*
7545 		 * There are no 'per-bus' settings for Fibre Channel.
7546 		 */
7547 		return;
7548 	}
7549 	sdp = SDPARAM(isp, chan);
7550 	sdp->update = 0;
7551 
7552 	for (tgt = 0; tgt < MAX_TARGETS; tgt++) {
7553 		uint16_t flags, period, offset;
7554 		int get;
7555 
7556 		if (sdp->isp_devparam[tgt].dev_enable == 0) {
7557 			sdp->isp_devparam[tgt].dev_update = 0;
7558 			sdp->isp_devparam[tgt].dev_refresh = 0;
7559 			isp_prt(isp, ISP_LOGDEBUG0, "skipping target %d bus %d update", tgt, chan);
7560 			continue;
7561 		}
7562 		/*
7563 		 * If the goal is to update the status of the device,
7564 		 * take what's in goal_flags and try and set the device
7565 		 * toward that. Otherwise, if we're just refreshing the
7566 		 * current device state, get the current parameters.
7567 		 */
7568 
7569 		MBSINIT(&mbs, 0, MBLOGALL, 0);
7570 
7571 		/*
7572 		 * Refresh overrides set
7573 		 */
7574 		if (sdp->isp_devparam[tgt].dev_refresh) {
7575 			mbs.param[0] = MBOX_GET_TARGET_PARAMS;
7576 			get = 1;
7577 		} else if (sdp->isp_devparam[tgt].dev_update) {
7578 			mbs.param[0] = MBOX_SET_TARGET_PARAMS;
7579 
7580 			/*
7581 			 * Make sure goal_flags has "Renegotiate on Error"
7582 			 * on and "Freeze Queue on Error" off.
7583 			 */
7584 			sdp->isp_devparam[tgt].goal_flags |= DPARM_RENEG;
7585 			sdp->isp_devparam[tgt].goal_flags &= ~DPARM_QFRZ;
7586 			mbs.param[2] = sdp->isp_devparam[tgt].goal_flags;
7587 
7588 			/*
7589 			 * Insist that PARITY must be enabled
7590 			 * if SYNC or WIDE is enabled.
7591 			 */
7592 			if ((mbs.param[2] & (DPARM_SYNC|DPARM_WIDE)) != 0) {
7593 				mbs.param[2] |= DPARM_PARITY;
7594 			}
7595 
7596 			if (mbs.param[2] & DPARM_SYNC) {
7597 				mbs.param[3] =
7598 				    (sdp->isp_devparam[tgt].goal_offset << 8) |
7599 				    (sdp->isp_devparam[tgt].goal_period);
7600 			}
7601 			/*
7602 			 * A command completion later that has
7603 			 * RQSTF_NEGOTIATION set can cause
7604 			 * the dev_refresh/announce cycle also.
7605 			 *
7606 			 * Note: It is really important to update our current
7607 			 * flags with at least the state of TAG capabilities-
7608 			 * otherwise we might try and send a tagged command
7609 			 * when we have it all turned off. So change it here
7610 			 * to say that current already matches goal.
7611 			 */
7612 			sdp->isp_devparam[tgt].actv_flags &= ~DPARM_TQING;
7613 			sdp->isp_devparam[tgt].actv_flags |=
7614 			    (sdp->isp_devparam[tgt].goal_flags & DPARM_TQING);
7615 			isp_prt(isp, ISP_LOGDEBUG0, "bus %d set tgt %d flags 0x%x off 0x%x period 0x%x",
7616 			    chan, tgt, mbs.param[2], mbs.param[3] >> 8, mbs.param[3] & 0xff);
7617 			get = 0;
7618 		} else {
7619 			continue;
7620 		}
7621 		mbs.param[1] = (chan << 15) | (tgt << 8);
7622 		isp_mboxcmd(isp, &mbs);
7623 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
7624 			continue;
7625 		}
7626 		if (get == 0) {
7627 			sdp->sendmarker = 1;
7628 			sdp->isp_devparam[tgt].dev_update = 0;
7629 			sdp->isp_devparam[tgt].dev_refresh = 1;
7630 		} else {
7631 			sdp->isp_devparam[tgt].dev_refresh = 0;
7632 			flags = mbs.param[2];
7633 			period = mbs.param[3] & 0xff;
7634 			offset = mbs.param[3] >> 8;
7635 			sdp->isp_devparam[tgt].actv_flags = flags;
7636 			sdp->isp_devparam[tgt].actv_period = period;
7637 			sdp->isp_devparam[tgt].actv_offset = offset;
7638 			isp_async(isp, ISPASYNC_NEW_TGT_PARAMS, chan, tgt);
7639 		}
7640 	}
7641 
7642 	for (tgt = 0; tgt < MAX_TARGETS; tgt++) {
7643 		if (sdp->isp_devparam[tgt].dev_update ||
7644 		    sdp->isp_devparam[tgt].dev_refresh) {
7645 			sdp->update = 1;
7646 			break;
7647 		}
7648 	}
7649 }
7650 
7651 static void
7652 isp_setdfltsdparm(ispsoftc_t *isp)
7653 {
7654 	int tgt;
7655 	sdparam *sdp, *sdp1;
7656 
7657 	sdp = SDPARAM(isp, 0);
7658 	if (IS_DUALBUS(isp))
7659 		sdp1 = sdp + 1;
7660 	else
7661 		sdp1 = NULL;
7662 
7663 	/*
7664 	 * Establish some default parameters.
7665 	 */
7666 	sdp->isp_cmd_dma_burst_enable = 0;
7667 	sdp->isp_data_dma_burst_enabl = 1;
7668 	sdp->isp_fifo_threshold = 0;
7669 	sdp->isp_initiator_id = DEFAULT_IID(isp, 0);
7670 	if (isp->isp_type >= ISP_HA_SCSI_1040) {
7671 		sdp->isp_async_data_setup = 9;
7672 	} else {
7673 		sdp->isp_async_data_setup = 6;
7674 	}
7675 	sdp->isp_selection_timeout = 250;
7676 	sdp->isp_max_queue_depth = MAXISPREQUEST(isp);
7677 	sdp->isp_tag_aging = 8;
7678 	sdp->isp_bus_reset_delay = 5;
7679 	/*
7680 	 * Don't retry selection, busy or queue full automatically- reflect
7681 	 * these back to us.
7682 	 */
7683 	sdp->isp_retry_count = 0;
7684 	sdp->isp_retry_delay = 0;
7685 
7686 	for (tgt = 0; tgt < MAX_TARGETS; tgt++) {
7687 		sdp->isp_devparam[tgt].exc_throttle = ISP_EXEC_THROTTLE;
7688 		sdp->isp_devparam[tgt].dev_enable = 1;
7689 	}
7690 
7691 	/*
7692 	 * The trick here is to establish a default for the default (honk!)
7693 	 * state (goal_flags). Then try and get the current status from
7694 	 * the card to fill in the current state. We don't, in fact, set
7695 	 * the default to the SAFE default state- that's not the goal state.
7696 	 */
7697 	for (tgt = 0; tgt < MAX_TARGETS; tgt++) {
7698 		uint8_t off, per;
7699 		sdp->isp_devparam[tgt].actv_offset = 0;
7700 		sdp->isp_devparam[tgt].actv_period = 0;
7701 		sdp->isp_devparam[tgt].actv_flags = 0;
7702 
7703 		sdp->isp_devparam[tgt].goal_flags =
7704 		    sdp->isp_devparam[tgt].nvrm_flags = DPARM_DEFAULT;
7705 
7706 		/*
7707 		 * We default to Wide/Fast for versions less than a 1040
7708 		 * (unless it's SBus).
7709 		 */
7710 		if (IS_ULTRA3(isp)) {
7711 			off = ISP_80M_SYNCPARMS >> 8;
7712 			per = ISP_80M_SYNCPARMS & 0xff;
7713 		} else if (IS_ULTRA2(isp)) {
7714 			off = ISP_40M_SYNCPARMS >> 8;
7715 			per = ISP_40M_SYNCPARMS & 0xff;
7716 		} else if (IS_1240(isp)) {
7717 			off = ISP_20M_SYNCPARMS >> 8;
7718 			per = ISP_20M_SYNCPARMS & 0xff;
7719 		} else if ((isp->isp_bustype == ISP_BT_SBUS &&
7720 		    isp->isp_type < ISP_HA_SCSI_1020A) ||
7721 		    (isp->isp_bustype == ISP_BT_PCI &&
7722 		    isp->isp_type < ISP_HA_SCSI_1040) ||
7723 		    (isp->isp_clock && isp->isp_clock < 60) ||
7724 		    (sdp->isp_ultramode == 0)) {
7725 			off = ISP_10M_SYNCPARMS >> 8;
7726 			per = ISP_10M_SYNCPARMS & 0xff;
7727 		} else {
7728 			off = ISP_20M_SYNCPARMS_1040 >> 8;
7729 			per = ISP_20M_SYNCPARMS_1040 & 0xff;
7730 		}
7731 		sdp->isp_devparam[tgt].goal_offset =
7732 		    sdp->isp_devparam[tgt].nvrm_offset = off;
7733 		sdp->isp_devparam[tgt].goal_period =
7734 		    sdp->isp_devparam[tgt].nvrm_period = per;
7735 
7736 	}
7737 
7738 	/*
7739 	 * If we're a dual bus card, just copy the data over
7740 	 */
7741 	if (sdp1) {
7742 		*sdp1 = *sdp;
7743 		sdp1->isp_initiator_id = DEFAULT_IID(isp, 1);
7744 	}
7745 
7746 	/*
7747 	 * If we've not been told to avoid reading NVRAM, try and read it.
7748 	 * If we're successful reading it, we can then return because NVRAM
7749 	 * will tell us what the desired settings are. Otherwise, we establish
7750 	 * some reasonable 'fake' nvram and goal defaults.
7751 	 */
7752 	if ((isp->isp_confopts & ISP_CFG_NONVRAM) == 0) {
7753 		mbreg_t mbs;
7754 
7755 		if (isp_read_nvram(isp, 0) == 0) {
7756 			if (IS_DUALBUS(isp)) {
7757 				if (isp_read_nvram(isp, 1) == 0) {
7758 					return;
7759 				}
7760 			}
7761 		}
7762 		MBSINIT(&mbs, MBOX_GET_ACT_NEG_STATE, MBLOGNONE, 0);
7763 		isp_mboxcmd(isp, &mbs);
7764 		if (mbs.param[0] != MBOX_COMMAND_COMPLETE) {
7765 			sdp->isp_req_ack_active_neg = 1;
7766 			sdp->isp_data_line_active_neg = 1;
7767 			if (sdp1) {
7768 				sdp1->isp_req_ack_active_neg = 1;
7769 				sdp1->isp_data_line_active_neg = 1;
7770 			}
7771 		} else {
7772 			sdp->isp_req_ack_active_neg =
7773 			    (mbs.param[1] >> 4) & 0x1;
7774 			sdp->isp_data_line_active_neg =
7775 			    (mbs.param[1] >> 5) & 0x1;
7776 			if (sdp1) {
7777 				sdp1->isp_req_ack_active_neg =
7778 				    (mbs.param[2] >> 4) & 0x1;
7779 				sdp1->isp_data_line_active_neg =
7780 				    (mbs.param[2] >> 5) & 0x1;
7781 			}
7782 		}
7783 	}
7784 
7785 }
7786 
7787 static void
7788 isp_setdfltfcparm(ispsoftc_t *isp, int chan)
7789 {
7790 	fcparam *fcp = FCPARAM(isp, chan);
7791 
7792 	/*
7793 	 * Establish some default parameters.
7794 	 */
7795 	fcp->role = DEFAULT_ROLE(isp, chan);
7796 	fcp->isp_maxalloc = ICB_DFLT_ALLOC;
7797 	fcp->isp_retry_delay = ICB_DFLT_RDELAY;
7798 	fcp->isp_retry_count = ICB_DFLT_RCOUNT;
7799 	fcp->isp_loopid = DEFAULT_LOOPID(isp, chan);
7800 	fcp->isp_wwnn_nvram = DEFAULT_NODEWWN(isp, chan);
7801 	fcp->isp_wwpn_nvram = DEFAULT_PORTWWN(isp, chan);
7802 	fcp->isp_fwoptions = 0;
7803 	fcp->isp_xfwoptions = 0;
7804 	fcp->isp_zfwoptions = 0;
7805 	fcp->isp_lasthdl = NIL_HANDLE;
7806 
7807 	if (IS_24XX(isp)) {
7808 		fcp->isp_fwoptions |= ICB2400_OPT1_FAIRNESS;
7809 		fcp->isp_fwoptions |= ICB2400_OPT1_HARD_ADDRESS;
7810 		if (isp->isp_confopts & ISP_CFG_FULL_DUPLEX) {
7811 			fcp->isp_fwoptions |= ICB2400_OPT1_FULL_DUPLEX;
7812 		}
7813 		fcp->isp_fwoptions |= ICB2400_OPT1_BOTH_WWNS;
7814 		fcp->isp_zfwoptions |= ICB2400_OPT3_RATE_AUTO;
7815 	} else {
7816 		fcp->isp_fwoptions |= ICBOPT_FAIRNESS;
7817 		fcp->isp_fwoptions |= ICBOPT_PDBCHANGE_AE;
7818 		fcp->isp_fwoptions |= ICBOPT_HARD_ADDRESS;
7819 		if (isp->isp_confopts & ISP_CFG_FULL_DUPLEX) {
7820 			fcp->isp_fwoptions |= ICBOPT_FULL_DUPLEX;
7821 		}
7822 		/*
7823 		 * Make sure this is turned off now until we get
7824 		 * extended options from NVRAM
7825 		 */
7826 		fcp->isp_fwoptions &= ~ICBOPT_EXTENDED;
7827 		fcp->isp_zfwoptions |= ICBZOPT_RATE_AUTO;
7828 	}
7829 
7830 
7831 	/*
7832 	 * Now try and read NVRAM unless told to not do so.
7833 	 * This will set fcparam's isp_wwnn_nvram && isp_wwpn_nvram.
7834 	 */
7835 	if ((isp->isp_confopts & ISP_CFG_NONVRAM) == 0) {
7836 		int i, j = 0;
7837 		/*
7838 		 * Give a couple of tries at reading NVRAM.
7839 		 */
7840 		for (i = 0; i < 2; i++) {
7841 			j = isp_read_nvram(isp, chan);
7842 			if (j == 0) {
7843 				break;
7844 			}
7845 		}
7846 		if (j) {
7847 			isp->isp_confopts |= ISP_CFG_NONVRAM;
7848 		}
7849 	}
7850 
7851 	fcp->isp_wwnn = ACTIVE_NODEWWN(isp, chan);
7852 	fcp->isp_wwpn = ACTIVE_PORTWWN(isp, chan);
7853 	isp_prt(isp, ISP_LOGCONFIG, "Chan %d 0x%08x%08x/0x%08x%08x Role %s",
7854 	    chan, (uint32_t) (fcp->isp_wwnn >> 32), (uint32_t) (fcp->isp_wwnn),
7855 	    (uint32_t) (fcp->isp_wwpn >> 32), (uint32_t) (fcp->isp_wwpn),
7856 	    isp_class3_roles[fcp->role]);
7857 }
7858 
7859 /*
7860  * Re-initialize the ISP and complete all orphaned commands
7861  * with a 'botched' notice. The reset/init routines should
7862  * not disturb an already active list of commands.
7863  */
7864 
7865 int
7866 isp_reinit(ispsoftc_t *isp, int do_load_defaults)
7867 {
7868 	int i, res = 0;
7869 
7870 	if (isp->isp_state == ISP_RUNSTATE)
7871 		isp_deinit(isp);
7872 	if (isp->isp_state != ISP_RESETSTATE)
7873 		isp_reset(isp, do_load_defaults);
7874 	if (isp->isp_state != ISP_RESETSTATE) {
7875 		res = EIO;
7876 		isp_prt(isp, ISP_LOGERR, "%s: cannot reset card", __func__);
7877 		ISP_DISABLE_INTS(isp);
7878 		goto cleanup;
7879 	}
7880 
7881 	isp_init(isp);
7882 	if (isp->isp_state > ISP_RESETSTATE &&
7883 	    isp->isp_state != ISP_RUNSTATE) {
7884 		res = EIO;
7885 		isp_prt(isp, ISP_LOGERR, "%s: cannot init card", __func__);
7886 		ISP_DISABLE_INTS(isp);
7887 		if (IS_FC(isp)) {
7888 			/*
7889 			 * If we're in ISP_ROLE_NONE, turn off the lasers.
7890 			 */
7891 			if (!IS_24XX(isp)) {
7892 				ISP_WRITE(isp, BIU2100_CSR, BIU2100_FPM0_REGS);
7893 				ISP_WRITE(isp, FPM_DIAG_CONFIG, FPM_SOFT_RESET);
7894 				ISP_WRITE(isp, BIU2100_CSR, BIU2100_FB_REGS);
7895 				ISP_WRITE(isp, FBM_CMD, FBMCMD_FIFO_RESET_ALL);
7896 				ISP_WRITE(isp, BIU2100_CSR, BIU2100_RISC_REGS);
7897 			}
7898 		}
7899 	}
7900 
7901 cleanup:
7902 	isp->isp_nactive = 0;
7903 	isp_clear_commands(isp);
7904 	if (IS_FC(isp)) {
7905 		for (i = 0; i < isp->isp_nchan; i++)
7906 			isp_clear_portdb(isp, i);
7907 	}
7908 	return (res);
7909 }
7910 
7911 /*
7912  * NVRAM Routines
7913  */
7914 static int
7915 isp_read_nvram(ispsoftc_t *isp, int bus)
7916 {
7917 	int i, amt, retval;
7918 	uint8_t csum, minversion;
7919 	union {
7920 		uint8_t _x[ISP2400_NVRAM_SIZE];
7921 		uint16_t _s[ISP2400_NVRAM_SIZE>>1];
7922 	} _n;
7923 #define	nvram_data	_n._x
7924 #define	nvram_words	_n._s
7925 
7926 	if (IS_24XX(isp)) {
7927 		return (isp_read_nvram_2400(isp, nvram_data));
7928 	} else if (IS_FC(isp)) {
7929 		amt = ISP2100_NVRAM_SIZE;
7930 		minversion = 1;
7931 	} else if (IS_ULTRA2(isp)) {
7932 		amt = ISP1080_NVRAM_SIZE;
7933 		minversion = 0;
7934 	} else {
7935 		amt = ISP_NVRAM_SIZE;
7936 		minversion = 2;
7937 	}
7938 
7939 	for (i = 0; i < amt>>1; i++) {
7940 		isp_rdnvram_word(isp, i, &nvram_words[i]);
7941 	}
7942 
7943 	if (nvram_data[0] != 'I' || nvram_data[1] != 'S' ||
7944 	    nvram_data[2] != 'P') {
7945 		if (isp->isp_bustype != ISP_BT_SBUS) {
7946 			isp_prt(isp, ISP_LOGWARN, "invalid NVRAM header");
7947 			isp_prt(isp, ISP_LOGDEBUG0, "%x %x %x", nvram_data[0], nvram_data[1], nvram_data[2]);
7948 		}
7949 		retval = -1;
7950 		goto out;
7951 	}
7952 
7953 	for (csum = 0, i = 0; i < amt; i++) {
7954 		csum += nvram_data[i];
7955 	}
7956 	if (csum != 0) {
7957 		isp_prt(isp, ISP_LOGWARN, "invalid NVRAM checksum");
7958 		retval = -1;
7959 		goto out;
7960 	}
7961 
7962 	if (ISP_NVRAM_VERSION(nvram_data) < minversion) {
7963 		isp_prt(isp, ISP_LOGWARN, "version %d NVRAM not understood",
7964 		    ISP_NVRAM_VERSION(nvram_data));
7965 		retval = -1;
7966 		goto out;
7967 	}
7968 
7969 	if (IS_ULTRA3(isp)) {
7970 		isp_parse_nvram_12160(isp, bus, nvram_data);
7971 	} else if (IS_1080(isp)) {
7972 		isp_parse_nvram_1080(isp, bus, nvram_data);
7973 	} else if (IS_1280(isp) || IS_1240(isp)) {
7974 		isp_parse_nvram_1080(isp, bus, nvram_data);
7975 	} else if (IS_SCSI(isp)) {
7976 		isp_parse_nvram_1020(isp, nvram_data);
7977 	} else {
7978 		isp_parse_nvram_2100(isp, nvram_data);
7979 	}
7980 	retval = 0;
7981 out:
7982 	return (retval);
7983 #undef	nvram_data
7984 #undef	nvram_words
7985 }
7986 
7987 static int
7988 isp_read_nvram_2400(ispsoftc_t *isp, uint8_t *nvram_data)
7989 {
7990 	int retval = 0;
7991 	uint32_t addr, csum, lwrds, *dptr;
7992 
7993 	if (isp->isp_port) {
7994 		addr = ISP2400_NVRAM_PORT1_ADDR;
7995 	} else {
7996 		addr = ISP2400_NVRAM_PORT0_ADDR;
7997 	}
7998 
7999 	dptr = (uint32_t *) nvram_data;
8000 	for (lwrds = 0; lwrds < ISP2400_NVRAM_SIZE >> 2; lwrds++) {
8001 		isp_rd_2400_nvram(isp, addr++, dptr++);
8002 	}
8003 	if (nvram_data[0] != 'I' || nvram_data[1] != 'S' ||
8004 	    nvram_data[2] != 'P') {
8005 		isp_prt(isp, ISP_LOGWARN, "invalid NVRAM header (%x %x %x)",
8006 		    nvram_data[0], nvram_data[1], nvram_data[2]);
8007 		retval = -1;
8008 		goto out;
8009 	}
8010 	dptr = (uint32_t *) nvram_data;
8011 	for (csum = 0, lwrds = 0; lwrds < ISP2400_NVRAM_SIZE >> 2; lwrds++) {
8012 		uint32_t tmp;
8013 		ISP_IOXGET_32(isp, &dptr[lwrds], tmp);
8014 		csum += tmp;
8015 	}
8016 	if (csum != 0) {
8017 		isp_prt(isp, ISP_LOGWARN, "invalid NVRAM checksum");
8018 		retval = -1;
8019 		goto out;
8020 	}
8021 	isp_parse_nvram_2400(isp, nvram_data);
8022 out:
8023 	return (retval);
8024 }
8025 
8026 static void
8027 isp_rdnvram_word(ispsoftc_t *isp, int wo, uint16_t *rp)
8028 {
8029 	int i, cbits;
8030 	uint16_t bit, rqst, junk;
8031 
8032 	ISP_WRITE(isp, BIU_NVRAM, BIU_NVRAM_SELECT);
8033 	ISP_DELAY(10);
8034 	ISP_WRITE(isp, BIU_NVRAM, BIU_NVRAM_SELECT|BIU_NVRAM_CLOCK);
8035 	ISP_DELAY(10);
8036 
8037 	if (IS_FC(isp)) {
8038 		wo &= ((ISP2100_NVRAM_SIZE >> 1) - 1);
8039 		if (IS_2312(isp) && isp->isp_port) {
8040 			wo += 128;
8041 		}
8042 		rqst = (ISP_NVRAM_READ << 8) | wo;
8043 		cbits = 10;
8044 	} else if (IS_ULTRA2(isp)) {
8045 		wo &= ((ISP1080_NVRAM_SIZE >> 1) - 1);
8046 		rqst = (ISP_NVRAM_READ << 8) | wo;
8047 		cbits = 10;
8048 	} else {
8049 		wo &= ((ISP_NVRAM_SIZE >> 1) - 1);
8050 		rqst = (ISP_NVRAM_READ << 6) | wo;
8051 		cbits = 8;
8052 	}
8053 
8054 	/*
8055 	 * Clock the word select request out...
8056 	 */
8057 	for (i = cbits; i >= 0; i--) {
8058 		if ((rqst >> i) & 1) {
8059 			bit = BIU_NVRAM_SELECT | BIU_NVRAM_DATAOUT;
8060 		} else {
8061 			bit = BIU_NVRAM_SELECT;
8062 		}
8063 		ISP_WRITE(isp, BIU_NVRAM, bit);
8064 		ISP_DELAY(10);
8065 		junk = ISP_READ(isp, BIU_NVRAM);	/* force PCI flush */
8066 		ISP_WRITE(isp, BIU_NVRAM, bit | BIU_NVRAM_CLOCK);
8067 		ISP_DELAY(10);
8068 		junk = ISP_READ(isp, BIU_NVRAM);	/* force PCI flush */
8069 		ISP_WRITE(isp, BIU_NVRAM, bit);
8070 		ISP_DELAY(10);
8071 		junk = ISP_READ(isp, BIU_NVRAM);	/* force PCI flush */
8072 	}
8073 	/*
8074 	 * Now read the result back in (bits come back in MSB format).
8075 	 */
8076 	*rp = 0;
8077 	for (i = 0; i < 16; i++) {
8078 		uint16_t rv;
8079 		*rp <<= 1;
8080 		ISP_WRITE(isp, BIU_NVRAM, BIU_NVRAM_SELECT|BIU_NVRAM_CLOCK);
8081 		ISP_DELAY(10);
8082 		rv = ISP_READ(isp, BIU_NVRAM);
8083 		if (rv & BIU_NVRAM_DATAIN) {
8084 			*rp |= 1;
8085 		}
8086 		ISP_DELAY(10);
8087 		ISP_WRITE(isp, BIU_NVRAM, BIU_NVRAM_SELECT);
8088 		ISP_DELAY(10);
8089 		junk = ISP_READ(isp, BIU_NVRAM);	/* force PCI flush */
8090 	}
8091 	ISP_WRITE(isp, BIU_NVRAM, 0);
8092 	ISP_DELAY(10);
8093 	junk = ISP_READ(isp, BIU_NVRAM);	/* force PCI flush */
8094 	ISP_SWIZZLE_NVRAM_WORD(isp, rp);
8095 }
8096 
8097 static void
8098 isp_rd_2400_nvram(ispsoftc_t *isp, uint32_t addr, uint32_t *rp)
8099 {
8100 	int loops = 0;
8101 	uint32_t base = 0x7ffe0000;
8102 	uint32_t tmp = 0;
8103 
8104 	if (IS_26XX(isp)) {
8105 		base = 0x7fe7c000;	/* XXX: Observation, may be wrong. */
8106 	} else if (IS_25XX(isp)) {
8107 		base = 0x7ff00000 | 0x48000;
8108 	}
8109 	ISP_WRITE(isp, BIU2400_FLASH_ADDR, base | addr);
8110 	for (loops = 0; loops < 5000; loops++) {
8111 		ISP_DELAY(10);
8112 		tmp = ISP_READ(isp, BIU2400_FLASH_ADDR);
8113 		if ((tmp & (1U << 31)) != 0) {
8114 			break;
8115 		}
8116 	}
8117 	if (tmp & (1U << 31)) {
8118 		*rp = ISP_READ(isp, BIU2400_FLASH_DATA);
8119 		ISP_SWIZZLE_NVRAM_LONG(isp, rp);
8120 	} else {
8121 		*rp = 0xffffffff;
8122 	}
8123 }
8124 
8125 static void
8126 isp_parse_nvram_1020(ispsoftc_t *isp, uint8_t *nvram_data)
8127 {
8128 	sdparam *sdp = SDPARAM(isp, 0);
8129 	int tgt;
8130 
8131 	sdp->isp_fifo_threshold =
8132 		ISP_NVRAM_FIFO_THRESHOLD(nvram_data) |
8133 		(ISP_NVRAM_FIFO_THRESHOLD_128(nvram_data) << 2);
8134 
8135 	if ((isp->isp_confopts & ISP_CFG_OWNLOOPID) == 0)
8136 		sdp->isp_initiator_id = ISP_NVRAM_INITIATOR_ID(nvram_data);
8137 
8138 	sdp->isp_bus_reset_delay =
8139 		ISP_NVRAM_BUS_RESET_DELAY(nvram_data);
8140 
8141 	sdp->isp_retry_count =
8142 		ISP_NVRAM_BUS_RETRY_COUNT(nvram_data);
8143 
8144 	sdp->isp_retry_delay =
8145 		ISP_NVRAM_BUS_RETRY_DELAY(nvram_data);
8146 
8147 	sdp->isp_async_data_setup =
8148 		ISP_NVRAM_ASYNC_DATA_SETUP_TIME(nvram_data);
8149 
8150 	if (isp->isp_type >= ISP_HA_SCSI_1040) {
8151 		if (sdp->isp_async_data_setup < 9) {
8152 			sdp->isp_async_data_setup = 9;
8153 		}
8154 	} else {
8155 		if (sdp->isp_async_data_setup != 6) {
8156 			sdp->isp_async_data_setup = 6;
8157 		}
8158 	}
8159 
8160 	sdp->isp_req_ack_active_neg =
8161 		ISP_NVRAM_REQ_ACK_ACTIVE_NEGATION(nvram_data);
8162 
8163 	sdp->isp_data_line_active_neg =
8164 		ISP_NVRAM_DATA_LINE_ACTIVE_NEGATION(nvram_data);
8165 
8166 	sdp->isp_data_dma_burst_enabl =
8167 		ISP_NVRAM_DATA_DMA_BURST_ENABLE(nvram_data);
8168 
8169 	sdp->isp_cmd_dma_burst_enable =
8170 		ISP_NVRAM_CMD_DMA_BURST_ENABLE(nvram_data);
8171 
8172 	sdp->isp_tag_aging =
8173 		ISP_NVRAM_TAG_AGE_LIMIT(nvram_data);
8174 
8175 	sdp->isp_selection_timeout =
8176 		ISP_NVRAM_SELECTION_TIMEOUT(nvram_data);
8177 
8178 	sdp->isp_max_queue_depth =
8179 		ISP_NVRAM_MAX_QUEUE_DEPTH(nvram_data);
8180 
8181 	sdp->isp_fast_mttr = ISP_NVRAM_FAST_MTTR_ENABLE(nvram_data);
8182 
8183 	for (tgt = 0; tgt < MAX_TARGETS; tgt++) {
8184 		sdp->isp_devparam[tgt].dev_enable =
8185 			ISP_NVRAM_TGT_DEVICE_ENABLE(nvram_data, tgt);
8186 		sdp->isp_devparam[tgt].exc_throttle =
8187 			ISP_NVRAM_TGT_EXEC_THROTTLE(nvram_data, tgt);
8188 		sdp->isp_devparam[tgt].nvrm_offset =
8189 			ISP_NVRAM_TGT_SYNC_OFFSET(nvram_data, tgt);
8190 		sdp->isp_devparam[tgt].nvrm_period =
8191 			ISP_NVRAM_TGT_SYNC_PERIOD(nvram_data, tgt);
8192 		/*
8193 		 * We probably shouldn't lie about this, but it
8194 		 * it makes it much safer if we limit NVRAM values
8195 		 * to sanity.
8196 		 */
8197 		if (isp->isp_type < ISP_HA_SCSI_1040) {
8198 			/*
8199 			 * If we're not ultra, we can't possibly
8200 			 * be a shorter period than this.
8201 			 */
8202 			if (sdp->isp_devparam[tgt].nvrm_period < 0x19) {
8203 				sdp->isp_devparam[tgt].nvrm_period = 0x19;
8204 			}
8205 			if (sdp->isp_devparam[tgt].nvrm_offset > 0xc) {
8206 				sdp->isp_devparam[tgt].nvrm_offset = 0x0c;
8207 			}
8208 		} else {
8209 			if (sdp->isp_devparam[tgt].nvrm_offset > 0x8) {
8210 				sdp->isp_devparam[tgt].nvrm_offset = 0x8;
8211 			}
8212 		}
8213 		sdp->isp_devparam[tgt].nvrm_flags = 0;
8214 		if (ISP_NVRAM_TGT_RENEG(nvram_data, tgt))
8215 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_RENEG;
8216 		sdp->isp_devparam[tgt].nvrm_flags |= DPARM_ARQ;
8217 		if (ISP_NVRAM_TGT_TQING(nvram_data, tgt))
8218 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_TQING;
8219 		if (ISP_NVRAM_TGT_SYNC(nvram_data, tgt))
8220 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_SYNC;
8221 		if (ISP_NVRAM_TGT_WIDE(nvram_data, tgt))
8222 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_WIDE;
8223 		if (ISP_NVRAM_TGT_PARITY(nvram_data, tgt))
8224 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_PARITY;
8225 		if (ISP_NVRAM_TGT_DISC(nvram_data, tgt))
8226 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_DISC;
8227 		sdp->isp_devparam[tgt].actv_flags = 0; /* we don't know */
8228 		sdp->isp_devparam[tgt].goal_offset =
8229 		    sdp->isp_devparam[tgt].nvrm_offset;
8230 		sdp->isp_devparam[tgt].goal_period =
8231 		    sdp->isp_devparam[tgt].nvrm_period;
8232 		sdp->isp_devparam[tgt].goal_flags =
8233 		    sdp->isp_devparam[tgt].nvrm_flags;
8234 	}
8235 }
8236 
8237 static void
8238 isp_parse_nvram_1080(ispsoftc_t *isp, int bus, uint8_t *nvram_data)
8239 {
8240 	sdparam *sdp = SDPARAM(isp, bus);
8241 	int tgt;
8242 
8243 	sdp->isp_fifo_threshold =
8244 	    ISP1080_NVRAM_FIFO_THRESHOLD(nvram_data);
8245 
8246 	if ((isp->isp_confopts & ISP_CFG_OWNLOOPID) == 0)
8247 		sdp->isp_initiator_id = ISP1080_NVRAM_INITIATOR_ID(nvram_data, bus);
8248 
8249 	sdp->isp_bus_reset_delay =
8250 	    ISP1080_NVRAM_BUS_RESET_DELAY(nvram_data, bus);
8251 
8252 	sdp->isp_retry_count =
8253 	    ISP1080_NVRAM_BUS_RETRY_COUNT(nvram_data, bus);
8254 
8255 	sdp->isp_retry_delay =
8256 	    ISP1080_NVRAM_BUS_RETRY_DELAY(nvram_data, bus);
8257 
8258 	sdp->isp_async_data_setup =
8259 	    ISP1080_NVRAM_ASYNC_DATA_SETUP_TIME(nvram_data, bus);
8260 
8261 	sdp->isp_req_ack_active_neg =
8262 	    ISP1080_NVRAM_REQ_ACK_ACTIVE_NEGATION(nvram_data, bus);
8263 
8264 	sdp->isp_data_line_active_neg =
8265 	    ISP1080_NVRAM_DATA_LINE_ACTIVE_NEGATION(nvram_data, bus);
8266 
8267 	sdp->isp_data_dma_burst_enabl =
8268 	    ISP1080_NVRAM_BURST_ENABLE(nvram_data);
8269 
8270 	sdp->isp_cmd_dma_burst_enable =
8271 	    ISP1080_NVRAM_BURST_ENABLE(nvram_data);
8272 
8273 	sdp->isp_selection_timeout =
8274 	    ISP1080_NVRAM_SELECTION_TIMEOUT(nvram_data, bus);
8275 
8276 	sdp->isp_max_queue_depth =
8277 	     ISP1080_NVRAM_MAX_QUEUE_DEPTH(nvram_data, bus);
8278 
8279 	for (tgt = 0; tgt < MAX_TARGETS; tgt++) {
8280 		sdp->isp_devparam[tgt].dev_enable =
8281 		    ISP1080_NVRAM_TGT_DEVICE_ENABLE(nvram_data, tgt, bus);
8282 		sdp->isp_devparam[tgt].exc_throttle =
8283 			ISP1080_NVRAM_TGT_EXEC_THROTTLE(nvram_data, tgt, bus);
8284 		sdp->isp_devparam[tgt].nvrm_offset =
8285 			ISP1080_NVRAM_TGT_SYNC_OFFSET(nvram_data, tgt, bus);
8286 		sdp->isp_devparam[tgt].nvrm_period =
8287 			ISP1080_NVRAM_TGT_SYNC_PERIOD(nvram_data, tgt, bus);
8288 		sdp->isp_devparam[tgt].nvrm_flags = 0;
8289 		if (ISP1080_NVRAM_TGT_RENEG(nvram_data, tgt, bus))
8290 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_RENEG;
8291 		sdp->isp_devparam[tgt].nvrm_flags |= DPARM_ARQ;
8292 		if (ISP1080_NVRAM_TGT_TQING(nvram_data, tgt, bus))
8293 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_TQING;
8294 		if (ISP1080_NVRAM_TGT_SYNC(nvram_data, tgt, bus))
8295 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_SYNC;
8296 		if (ISP1080_NVRAM_TGT_WIDE(nvram_data, tgt, bus))
8297 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_WIDE;
8298 		if (ISP1080_NVRAM_TGT_PARITY(nvram_data, tgt, bus))
8299 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_PARITY;
8300 		if (ISP1080_NVRAM_TGT_DISC(nvram_data, tgt, bus))
8301 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_DISC;
8302 		sdp->isp_devparam[tgt].actv_flags = 0;
8303 		sdp->isp_devparam[tgt].goal_offset =
8304 		    sdp->isp_devparam[tgt].nvrm_offset;
8305 		sdp->isp_devparam[tgt].goal_period =
8306 		    sdp->isp_devparam[tgt].nvrm_period;
8307 		sdp->isp_devparam[tgt].goal_flags =
8308 		    sdp->isp_devparam[tgt].nvrm_flags;
8309 	}
8310 }
8311 
8312 static void
8313 isp_parse_nvram_12160(ispsoftc_t *isp, int bus, uint8_t *nvram_data)
8314 {
8315 	sdparam *sdp = SDPARAM(isp, bus);
8316 	int tgt;
8317 
8318 	sdp->isp_fifo_threshold =
8319 	    ISP12160_NVRAM_FIFO_THRESHOLD(nvram_data);
8320 
8321 	if ((isp->isp_confopts & ISP_CFG_OWNLOOPID) == 0)
8322 		sdp->isp_initiator_id = ISP12160_NVRAM_INITIATOR_ID(nvram_data, bus);
8323 
8324 	sdp->isp_bus_reset_delay =
8325 	    ISP12160_NVRAM_BUS_RESET_DELAY(nvram_data, bus);
8326 
8327 	sdp->isp_retry_count =
8328 	    ISP12160_NVRAM_BUS_RETRY_COUNT(nvram_data, bus);
8329 
8330 	sdp->isp_retry_delay =
8331 	    ISP12160_NVRAM_BUS_RETRY_DELAY(nvram_data, bus);
8332 
8333 	sdp->isp_async_data_setup =
8334 	    ISP12160_NVRAM_ASYNC_DATA_SETUP_TIME(nvram_data, bus);
8335 
8336 	sdp->isp_req_ack_active_neg =
8337 	    ISP12160_NVRAM_REQ_ACK_ACTIVE_NEGATION(nvram_data, bus);
8338 
8339 	sdp->isp_data_line_active_neg =
8340 	    ISP12160_NVRAM_DATA_LINE_ACTIVE_NEGATION(nvram_data, bus);
8341 
8342 	sdp->isp_data_dma_burst_enabl =
8343 	    ISP12160_NVRAM_BURST_ENABLE(nvram_data);
8344 
8345 	sdp->isp_cmd_dma_burst_enable =
8346 	    ISP12160_NVRAM_BURST_ENABLE(nvram_data);
8347 
8348 	sdp->isp_selection_timeout =
8349 	    ISP12160_NVRAM_SELECTION_TIMEOUT(nvram_data, bus);
8350 
8351 	sdp->isp_max_queue_depth =
8352 	     ISP12160_NVRAM_MAX_QUEUE_DEPTH(nvram_data, bus);
8353 
8354 	for (tgt = 0; tgt < MAX_TARGETS; tgt++) {
8355 		sdp->isp_devparam[tgt].dev_enable =
8356 		    ISP12160_NVRAM_TGT_DEVICE_ENABLE(nvram_data, tgt, bus);
8357 		sdp->isp_devparam[tgt].exc_throttle =
8358 			ISP12160_NVRAM_TGT_EXEC_THROTTLE(nvram_data, tgt, bus);
8359 		sdp->isp_devparam[tgt].nvrm_offset =
8360 			ISP12160_NVRAM_TGT_SYNC_OFFSET(nvram_data, tgt, bus);
8361 		sdp->isp_devparam[tgt].nvrm_period =
8362 			ISP12160_NVRAM_TGT_SYNC_PERIOD(nvram_data, tgt, bus);
8363 		sdp->isp_devparam[tgt].nvrm_flags = 0;
8364 		if (ISP12160_NVRAM_TGT_RENEG(nvram_data, tgt, bus))
8365 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_RENEG;
8366 		sdp->isp_devparam[tgt].nvrm_flags |= DPARM_ARQ;
8367 		if (ISP12160_NVRAM_TGT_TQING(nvram_data, tgt, bus))
8368 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_TQING;
8369 		if (ISP12160_NVRAM_TGT_SYNC(nvram_data, tgt, bus))
8370 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_SYNC;
8371 		if (ISP12160_NVRAM_TGT_WIDE(nvram_data, tgt, bus))
8372 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_WIDE;
8373 		if (ISP12160_NVRAM_TGT_PARITY(nvram_data, tgt, bus))
8374 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_PARITY;
8375 		if (ISP12160_NVRAM_TGT_DISC(nvram_data, tgt, bus))
8376 			sdp->isp_devparam[tgt].nvrm_flags |= DPARM_DISC;
8377 		sdp->isp_devparam[tgt].actv_flags = 0;
8378 		sdp->isp_devparam[tgt].goal_offset =
8379 		    sdp->isp_devparam[tgt].nvrm_offset;
8380 		sdp->isp_devparam[tgt].goal_period =
8381 		    sdp->isp_devparam[tgt].nvrm_period;
8382 		sdp->isp_devparam[tgt].goal_flags =
8383 		    sdp->isp_devparam[tgt].nvrm_flags;
8384 	}
8385 }
8386 
8387 static void
8388 isp_parse_nvram_2100(ispsoftc_t *isp, uint8_t *nvram_data)
8389 {
8390 	fcparam *fcp = FCPARAM(isp, 0);
8391 	uint64_t wwn;
8392 
8393 	/*
8394 	 * There is NVRAM storage for both Port and Node entities-
8395 	 * but the Node entity appears to be unused on all the cards
8396 	 * I can find. However, we should account for this being set
8397 	 * at some point in the future.
8398 	 *
8399 	 * Qlogic WWNs have an NAA of 2, but usually nothing shows up in
8400 	 * bits 48..60. In the case of the 2202, it appears that they do
8401 	 * use bit 48 to distinguish between the two instances on the card.
8402 	 * The 2204, which I've never seen, *probably* extends this method.
8403 	 */
8404 	wwn = ISP2100_NVRAM_PORT_NAME(nvram_data);
8405 	if (wwn) {
8406 		isp_prt(isp, ISP_LOGCONFIG, "NVRAM Port WWN 0x%08x%08x",
8407 		    (uint32_t) (wwn >> 32), (uint32_t) (wwn));
8408 		if ((wwn >> 60) == 0) {
8409 			wwn |= (((uint64_t) 2)<< 60);
8410 		}
8411 	}
8412 	fcp->isp_wwpn_nvram = wwn;
8413 	if (IS_2200(isp) || IS_23XX(isp)) {
8414 		wwn = ISP2100_NVRAM_NODE_NAME(nvram_data);
8415 		if (wwn) {
8416 			isp_prt(isp, ISP_LOGCONFIG, "NVRAM Node WWN 0x%08x%08x",
8417 			    (uint32_t) (wwn >> 32),
8418 			    (uint32_t) (wwn));
8419 			if ((wwn >> 60) == 0) {
8420 				wwn |= (((uint64_t) 2)<< 60);
8421 			}
8422 		} else {
8423 			wwn = fcp->isp_wwpn_nvram & ~((uint64_t) 0xfff << 48);
8424 		}
8425 	} else {
8426 		wwn &= ~((uint64_t) 0xfff << 48);
8427 	}
8428 	fcp->isp_wwnn_nvram = wwn;
8429 
8430 	fcp->isp_maxalloc = ISP2100_NVRAM_MAXIOCBALLOCATION(nvram_data);
8431 	if ((isp->isp_confopts & ISP_CFG_OWNFSZ) == 0) {
8432 		DEFAULT_FRAMESIZE(isp) =
8433 		    ISP2100_NVRAM_MAXFRAMELENGTH(nvram_data);
8434 	}
8435 	fcp->isp_retry_delay = ISP2100_NVRAM_RETRY_DELAY(nvram_data);
8436 	fcp->isp_retry_count = ISP2100_NVRAM_RETRY_COUNT(nvram_data);
8437 	if ((isp->isp_confopts & ISP_CFG_OWNLOOPID) == 0) {
8438 		fcp->isp_loopid = ISP2100_NVRAM_HARDLOOPID(nvram_data);
8439 	}
8440 	if ((isp->isp_confopts & ISP_CFG_OWNEXCTHROTTLE) == 0) {
8441 		DEFAULT_EXEC_THROTTLE(isp) =
8442 			ISP2100_NVRAM_EXECUTION_THROTTLE(nvram_data);
8443 	}
8444 	fcp->isp_fwoptions = ISP2100_NVRAM_OPTIONS(nvram_data);
8445 	isp_prt(isp, ISP_LOGDEBUG0,
8446 	    "NVRAM 0x%08x%08x 0x%08x%08x maxalloc %d maxframelen %d",
8447 	    (uint32_t) (fcp->isp_wwnn_nvram >> 32),
8448 	    (uint32_t) fcp->isp_wwnn_nvram,
8449 	    (uint32_t) (fcp->isp_wwpn_nvram >> 32),
8450 	    (uint32_t) fcp->isp_wwpn_nvram,
8451 	    ISP2100_NVRAM_MAXIOCBALLOCATION(nvram_data),
8452 	    ISP2100_NVRAM_MAXFRAMELENGTH(nvram_data));
8453 	isp_prt(isp, ISP_LOGDEBUG0,
8454 	    "execthrottle %d fwoptions 0x%x hardloop %d tov %d",
8455 	    ISP2100_NVRAM_EXECUTION_THROTTLE(nvram_data),
8456 	    ISP2100_NVRAM_OPTIONS(nvram_data),
8457 	    ISP2100_NVRAM_HARDLOOPID(nvram_data),
8458 	    ISP2100_NVRAM_TOV(nvram_data));
8459 	fcp->isp_xfwoptions = ISP2100_XFW_OPTIONS(nvram_data);
8460 	fcp->isp_zfwoptions = ISP2100_ZFW_OPTIONS(nvram_data);
8461 	isp_prt(isp, ISP_LOGDEBUG0, "xfwoptions 0x%x zfw options 0x%x",
8462 	    ISP2100_XFW_OPTIONS(nvram_data), ISP2100_ZFW_OPTIONS(nvram_data));
8463 }
8464 
8465 static void
8466 isp_parse_nvram_2400(ispsoftc_t *isp, uint8_t *nvram_data)
8467 {
8468 	fcparam *fcp = FCPARAM(isp, 0);
8469 	uint64_t wwn;
8470 
8471 	isp_prt(isp, ISP_LOGDEBUG0,
8472 	    "NVRAM 0x%08x%08x 0x%08x%08x exchg_cnt %d maxframelen %d",
8473 	    (uint32_t) (ISP2400_NVRAM_NODE_NAME(nvram_data) >> 32),
8474 	    (uint32_t) (ISP2400_NVRAM_NODE_NAME(nvram_data)),
8475 	    (uint32_t) (ISP2400_NVRAM_PORT_NAME(nvram_data) >> 32),
8476 	    (uint32_t) (ISP2400_NVRAM_PORT_NAME(nvram_data)),
8477 	    ISP2400_NVRAM_EXCHANGE_COUNT(nvram_data),
8478 	    ISP2400_NVRAM_MAXFRAMELENGTH(nvram_data));
8479 	isp_prt(isp, ISP_LOGDEBUG0,
8480 	    "NVRAM execthr %d loopid %d fwopt1 0x%x fwopt2 0x%x fwopt3 0x%x",
8481 	    ISP2400_NVRAM_EXECUTION_THROTTLE(nvram_data),
8482 	    ISP2400_NVRAM_HARDLOOPID(nvram_data),
8483 	    ISP2400_NVRAM_FIRMWARE_OPTIONS1(nvram_data),
8484 	    ISP2400_NVRAM_FIRMWARE_OPTIONS2(nvram_data),
8485 	    ISP2400_NVRAM_FIRMWARE_OPTIONS3(nvram_data));
8486 
8487 	wwn = ISP2400_NVRAM_PORT_NAME(nvram_data);
8488 	fcp->isp_wwpn_nvram = wwn;
8489 
8490 	wwn = ISP2400_NVRAM_NODE_NAME(nvram_data);
8491 	if (wwn) {
8492 		if ((wwn >> 60) != 2 && (wwn >> 60) != 5) {
8493 			wwn = 0;
8494 		}
8495 	}
8496 	if (wwn == 0 && (fcp->isp_wwpn_nvram >> 60) == 2) {
8497 		wwn = fcp->isp_wwpn_nvram;
8498 		wwn &= ~((uint64_t) 0xfff << 48);
8499 	}
8500 	fcp->isp_wwnn_nvram = wwn;
8501 
8502 	if (ISP2400_NVRAM_EXCHANGE_COUNT(nvram_data)) {
8503 		fcp->isp_maxalloc = ISP2400_NVRAM_EXCHANGE_COUNT(nvram_data);
8504 	}
8505 	if ((isp->isp_confopts & ISP_CFG_OWNFSZ) == 0) {
8506 		DEFAULT_FRAMESIZE(isp) =
8507 		    ISP2400_NVRAM_MAXFRAMELENGTH(nvram_data);
8508 	}
8509 	if ((isp->isp_confopts & ISP_CFG_OWNLOOPID) == 0) {
8510 		fcp->isp_loopid = ISP2400_NVRAM_HARDLOOPID(nvram_data);
8511 	}
8512 	if ((isp->isp_confopts & ISP_CFG_OWNEXCTHROTTLE) == 0) {
8513 		DEFAULT_EXEC_THROTTLE(isp) =
8514 			ISP2400_NVRAM_EXECUTION_THROTTLE(nvram_data);
8515 	}
8516 	fcp->isp_fwoptions = ISP2400_NVRAM_FIRMWARE_OPTIONS1(nvram_data);
8517 	fcp->isp_xfwoptions = ISP2400_NVRAM_FIRMWARE_OPTIONS2(nvram_data);
8518 	fcp->isp_zfwoptions = ISP2400_NVRAM_FIRMWARE_OPTIONS3(nvram_data);
8519 }
8520