xref: /freebsd/sys/dev/isp/isp_target.c (revision 74d9553e43cfafc29448d0bb836916aa21dea0de)
1 /*-
2  *  Copyright (c) 1997-2009 by Matthew Jacob
3  *  All rights reserved.
4  *
5  *  Redistribution and use in source and binary forms, with or without
6  *  modification, are permitted provided that the following conditions
7  *  are met:
8  *
9  *  1. Redistributions of source code must retain the above copyright
10  *     notice, this list of conditions and the following disclaimer.
11  *  2. Redistributions in binary form must reproduce the above copyright
12  *     notice, this list of conditions and the following disclaimer in the
13  *     documentation and/or other materials provided with the distribution.
14  *
15  *  THIS SOFTWARE IS PROVIDED BY AUTHOR AND CONTRIBUTORS ``AS IS'' AND
16  *  ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17  *  IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18  *  ARE DISCLAIMED.  IN NO EVENT SHALL AUTHOR OR CONTRIBUTORS BE LIABLE
19  *  FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20  *  DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21  *  OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22  *  HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23  *  LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24  *  OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
25  *  SUCH DAMAGE.
26  *
27  */
28 /*
29  * Machine and OS Independent Target Mode Code for the Qlogic SCSI/FC adapters.
30  */
31 /*
32  * Bug fixes gratefully acknowledged from:
33  *	Oded Kedem <oded@kashya.com>
34  */
35 /*
36  * Include header file appropriate for platform we're building on.
37  */
38 
39 #ifdef	__NetBSD__
40 #include <dev/ic/isp_netbsd.h>
41 #endif
42 #ifdef	__FreeBSD__
43 #include <sys/cdefs.h>
44 __FBSDID("$FreeBSD$");
45 #include <dev/isp/isp_freebsd.h>
46 #endif
47 #ifdef	__OpenBSD__
48 #include <dev/ic/isp_openbsd.h>
49 #endif
50 #ifdef	__linux__
51 #include "isp_linux.h"
52 #endif
53 
54 #ifdef	ISP_TARGET_MODE
55 static const char atiocope[] = "ATIO returned for LUN %x because it was in the middle of Bus Device Reset on bus %d";
56 static const char atior[] = "ATIO returned for LUN %x from handle 0x%x because a Bus Reset occurred on bus %d";
57 static const char rqo[] = "%s: Request Queue Overflow";
58 
59 static void isp_got_msg_fc(ispsoftc_t *, in_fcentry_t *);
60 static void isp_got_tmf_24xx(ispsoftc_t *, at7_entry_t *);
61 static void isp_handle_atio2(ispsoftc_t *, at2_entry_t *);
62 static void isp_handle_ctio2(ispsoftc_t *, ct2_entry_t *);
63 static void isp_handle_ctio7(ispsoftc_t *, ct7_entry_t *);
64 static void isp_handle_24xx_inotify(ispsoftc_t *, in_fcentry_24xx_t *);
65 
66 /*
67  * The Qlogic driver gets an interrupt to look at response queue entries.
68  * Some of these are status completions for initiatior mode commands, but
69  * if target mode is enabled, we get a whole wad of response queue entries
70  * to be handled here.
71  *
72  * Basically the split into 3 main groups: Lun Enable/Modification responses,
73  * SCSI Command processing, and Immediate Notification events.
74  *
75  * You start by writing a request queue entry to enable target mode (and
76  * establish some resource limitations which you can modify later).
77  * The f/w responds with a LUN ENABLE or LUN MODIFY response with
78  * the status of this action. If the enable was successful, you can expect...
79  *
80  * Response queue entries with SCSI commands encapsulate show up in an ATIO
81  * (Accept Target IO) type- sometimes with enough info to stop the command at
82  * this level. Ultimately the driver has to feed back to the f/w's request
83  * queue a sequence of CTIOs (continue target I/O) that describe data to
84  * be moved and/or status to be sent) and finally finishing with sending
85  * to the f/w's response queue an ATIO which then completes the handshake
86  * with the f/w for that command. There's a lot of variations on this theme,
87  * including flags you can set in the CTIO for the Qlogic 2X00 fibre channel
88  * cards that 'auto-replenish' the f/w's ATIO count, but this is the basic
89  * gist of it.
90  *
91  * The third group that can show up in the response queue are Immediate
92  * Notification events. These include things like notifications of SCSI bus
93  * resets, or Bus Device Reset messages or other messages received. This
94  * a classic oddbins area. It can get  a little weird because you then turn
95  * around and acknowledge the Immediate Notify by writing an entry onto the
96  * request queue and then the f/w turns around and gives you an acknowledgement
97  * to *your* acknowledgement on the response queue (the idea being to let
98  * the f/w tell you when the event is *really* over I guess).
99  *
100  */
101 
102 
103 /*
104  * A new response queue entry has arrived. The interrupt service code
105  * has already swizzled it into the platform dependent from canonical form.
106  *
107  * Because of the way this driver is designed, unfortunately most of the
108  * actual synchronization work has to be done in the platform specific
109  * code- we have no synchroniation primitives in the common code.
110  */
111 
112 int
113 isp_target_notify(ispsoftc_t *isp, void *vptr, uint32_t *optrp)
114 {
115 	uint16_t status;
116 	uint32_t seqid;
117 	union {
118 		at2_entry_t	*at2iop;
119 		at2e_entry_t	*at2eiop;
120 		at7_entry_t	*at7iop;
121 		ct2_entry_t	*ct2iop;
122 		ct2e_entry_t	*ct2eiop;
123 		ct7_entry_t	*ct7iop;
124 		lun_entry_t	*lunenp;
125 		in_fcentry_t	*inot_fcp;
126 		in_fcentry_e_t	*inote_fcp;
127 		in_fcentry_24xx_t *inot_24xx;
128 		na_fcentry_t	*nack_fcp;
129 		na_fcentry_e_t	*nacke_fcp;
130 		na_fcentry_24xx_t *nack_24xx;
131 		isphdr_t	*hp;
132 		abts_t		*abts;
133 		abts_rsp_t	*abts_rsp;
134 		els_t		*els;
135 		void *		*vp;
136 #define	at2iop		unp.at2iop
137 #define	at2eiop		unp.at2eiop
138 #define	at7iop		unp.at7iop
139 #define	ct2iop		unp.ct2iop
140 #define	ct2eiop		unp.ct2eiop
141 #define	ct7iop		unp.ct7iop
142 #define	lunenp		unp.lunenp
143 #define	inot_fcp	unp.inot_fcp
144 #define	inote_fcp	unp.inote_fcp
145 #define	inot_24xx	unp.inot_24xx
146 #define	nack_fcp	unp.nack_fcp
147 #define	nacke_fcp	unp.nacke_fcp
148 #define	nack_24xx	unp.nack_24xx
149 #define	abts		unp.abts
150 #define	abts_rsp	unp.abts_rsp
151 #define els		unp.els
152 #define	hdrp		unp.hp
153 	} unp;
154 	uint8_t local[QENTRY_LEN];
155 	uint16_t iid;
156 	int bus, type, len, level, rval = 1;
157 	isp_notify_t notify;
158 
159 	type = isp_get_response_type(isp, (isphdr_t *)vptr);
160 	unp.vp = vptr;
161 
162 	ISP_TDQE(isp, "isp_target_notify", (int) *optrp, vptr);
163 
164 	switch (type) {
165 	case RQSTYPE_ATIO:
166 		isp_get_atio7(isp, at7iop, (at7_entry_t *) local);
167 		at7iop = (at7_entry_t *) local;
168 		/*
169 		 * Check for and do something with commands whose
170 		 * IULEN extends past a single queue entry.
171 		 */
172 		len = at7iop->at_ta_len & 0x0fff;
173 		if (len > (QENTRY_LEN - 8)) {
174 			len -= (QENTRY_LEN - 8);
175 			isp_prt(isp, ISP_LOGINFO, "long IU length (%d) ignored", len);
176 			while (len > 0) {
177 				*optrp =  ISP_NXT_QENTRY(*optrp, RESULT_QUEUE_LEN(isp));
178 				len -= QENTRY_LEN;
179 			}
180 		}
181 		/*
182 		 * Check for a task management function
183 		 */
184 		if (at7iop->at_cmnd.fcp_cmnd_task_management) {
185 			isp_got_tmf_24xx(isp, at7iop);
186 			break;
187 		}
188 		/*
189 		 * Just go straight to outer layer for this one.
190 		 */
191 		isp_async(isp, ISPASYNC_TARGET_ACTION, local);
192 		break;
193 
194 	case RQSTYPE_ATIO2:
195 		if (ISP_CAP_2KLOGIN(isp)) {
196 			isp_get_atio2e(isp, at2eiop, (at2e_entry_t *) local);
197 		} else {
198 			isp_get_atio2(isp, at2iop, (at2_entry_t *) local);
199 		}
200 		isp_handle_atio2(isp, (at2_entry_t *) local);
201 		break;
202 
203 	case RQSTYPE_CTIO3:
204 	case RQSTYPE_CTIO2:
205 		if (ISP_CAP_2KLOGIN(isp)) {
206 			isp_get_ctio2e(isp, ct2eiop, (ct2e_entry_t *) local);
207 		} else {
208 			isp_get_ctio2(isp, ct2iop, (ct2_entry_t *) local);
209 		}
210 		isp_handle_ctio2(isp, (ct2_entry_t *) local);
211 		break;
212 
213 	case RQSTYPE_CTIO7:
214 		isp_get_ctio7(isp, ct7iop, (ct7_entry_t *) local);
215 		isp_handle_ctio7(isp, (ct7_entry_t *) local);
216 		break;
217 
218 	case RQSTYPE_ENABLE_LUN:
219 	case RQSTYPE_MODIFY_LUN:
220 		isp_get_enable_lun(isp, lunenp, (lun_entry_t *) local);
221 		isp_async(isp, ISPASYNC_TARGET_ACTION, local);
222 		break;
223 
224 	case RQSTYPE_NOTIFY:
225 		bus = 0;
226 		if (IS_24XX(isp)) {
227 			isp_get_notify_24xx(isp, inot_24xx, (in_fcentry_24xx_t *)local);
228 			inot_24xx = (in_fcentry_24xx_t *) local;
229 			isp_handle_24xx_inotify(isp, inot_24xx);
230 			break;
231 		} else {
232 			if (ISP_CAP_2KLOGIN(isp)) {
233 				in_fcentry_e_t *ecp = (in_fcentry_e_t *)local;
234 				isp_get_notify_fc_e(isp, inote_fcp, ecp);
235 				iid = ecp->in_iid;
236 				status = ecp->in_status;
237 				seqid = ecp->in_seqid;
238 			} else {
239 				in_fcentry_t *fcp = (in_fcentry_t *)local;
240 				isp_get_notify_fc(isp, inot_fcp, fcp);
241 				iid = fcp->in_iid;
242 				status = fcp->in_status;
243 				seqid = fcp->in_seqid;
244 			}
245 		}
246 
247 		isp_prt(isp, ISP_LOGTDEBUG0, "Immediate Notify On Bus %d, status=0x%x seqid=0x%x", bus, status, seqid);
248 
249 		switch (status) {
250 		case IN_MSG_RECEIVED:
251 		case IN_IDE_RECEIVED:
252 			isp_got_msg_fc(isp, (in_fcentry_t *)local);
253 			break;
254 		case IN_RSRC_UNAVAIL:
255 			isp_prt(isp, ISP_LOGINFO, "Firmware out of ATIOs");
256 			isp_async(isp, ISPASYNC_TARGET_NOTIFY_ACK, local);
257 			break;
258 
259 		case IN_RESET:
260 			ISP_MEMZERO(&notify, sizeof (isp_notify_t));
261 			notify.nt_hba = isp;
262 			notify.nt_wwn = INI_ANY;
263 			notify.nt_tgt = TGT_ANY;
264 			notify.nt_nphdl = iid;
265 			notify.nt_sid = PORT_ANY;
266 			notify.nt_did = PORT_ANY;
267 			notify.nt_lun = LUN_ANY;
268 			notify.nt_tagval = TAG_ANY;
269 			notify.nt_tagval |= (((uint64_t)(isp->isp_serno++)) << 32);
270 			notify.nt_ncode = NT_BUS_RESET;
271 			notify.nt_need_ack = 1;
272 			notify.nt_lreserved = local;
273 			isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
274 			break;
275 
276 		case IN_PORT_LOGOUT:
277 			ISP_MEMZERO(&notify, sizeof (isp_notify_t));
278 			notify.nt_hba = isp;
279 			notify.nt_wwn = INI_ANY;
280 			notify.nt_nphdl = iid;
281 			notify.nt_sid = PORT_ANY;
282 			notify.nt_did = PORT_ANY;
283 			notify.nt_ncode = NT_LOGOUT;
284 			notify.nt_need_ack = 1;
285 			notify.nt_lreserved = local;
286 			isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
287 			break;
288 
289 		case IN_ABORT_TASK:
290 			ISP_MEMZERO(&notify, sizeof (isp_notify_t));
291 			notify.nt_hba = isp;
292 			notify.nt_wwn = INI_ANY;
293 			notify.nt_nphdl = iid;
294 			notify.nt_sid = PORT_ANY;
295 			notify.nt_did = PORT_ANY;
296 			notify.nt_ncode = NT_ABORT_TASK;
297 			notify.nt_need_ack = 1;
298 			notify.nt_lreserved = local;
299 			isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
300 			break;
301 
302 		case IN_GLOBAL_LOGO:
303 			isp_prt(isp, ISP_LOGTINFO, "%s: all ports logged out", __func__);
304 			ISP_MEMZERO(&notify, sizeof (isp_notify_t));
305 			notify.nt_hba = isp;
306 			notify.nt_wwn = INI_ANY;
307 			notify.nt_nphdl = NIL_HANDLE;
308 			notify.nt_sid = PORT_ANY;
309 			notify.nt_did = PORT_ANY;
310 			notify.nt_ncode = NT_GLOBAL_LOGOUT;
311 			notify.nt_need_ack = 1;
312 			notify.nt_lreserved = local;
313 			isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
314 			break;
315 
316 		case IN_PORT_CHANGED:
317 			isp_prt(isp, ISP_LOGTINFO, "%s: port changed", __func__);
318 			ISP_MEMZERO(&notify, sizeof (isp_notify_t));
319 			notify.nt_hba = isp;
320 			notify.nt_wwn = INI_ANY;
321 			notify.nt_nphdl = NIL_HANDLE;
322 			notify.nt_sid = PORT_ANY;
323 			notify.nt_did = PORT_ANY;
324 			notify.nt_ncode = NT_CHANGED;
325 			notify.nt_need_ack = 1;
326 			notify.nt_lreserved = local;
327 			isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
328 			break;
329 
330 		default:
331 			ISP_SNPRINTF(local, sizeof local, "%s: unknown status to RQSTYPE_NOTIFY (0x%x)", __func__, status);
332 			isp_print_bytes(isp, local, QENTRY_LEN, vptr);
333 			isp_async(isp, ISPASYNC_TARGET_NOTIFY_ACK, local);
334 			break;
335 		}
336 		break;
337 
338 	case RQSTYPE_NOTIFY_ACK:
339 		/*
340 		 * The ISP is acknowledging our acknowledgement of an
341 		 * Immediate Notify entry for some asynchronous event.
342 		 */
343 		if (IS_24XX(isp)) {
344 			isp_get_notify_ack_24xx(isp, nack_24xx, (na_fcentry_24xx_t *) local);
345 			nack_24xx = (na_fcentry_24xx_t *) local;
346 			if (nack_24xx->na_status != NA_OK) {
347 				level = ISP_LOGINFO;
348 			} else {
349 				level = ISP_LOGTDEBUG1;
350 			}
351 			isp_prt(isp, level, "Notify Ack Status=0x%x; Subcode 0x%x seqid=0x%x", nack_24xx->na_status, nack_24xx->na_status_subcode, nack_24xx->na_rxid);
352 		} else {
353 			if (ISP_CAP_2KLOGIN(isp)) {
354 				isp_get_notify_ack_fc_e(isp, nacke_fcp, (na_fcentry_e_t *)local);
355 			} else {
356 				isp_get_notify_ack_fc(isp, nack_fcp, (na_fcentry_t *)local);
357 			}
358 			nack_fcp = (na_fcentry_t *)local;
359 			if (nack_fcp->na_status != NA_OK) {
360 				level = ISP_LOGINFO;
361 			} else {
362 				level = ISP_LOGTDEBUG1;
363 			}
364 			isp_prt(isp, level, "Notify Ack Status=0x%x seqid 0x%x", nack_fcp->na_status, nack_fcp->na_seqid);
365 		}
366 		break;
367 
368 	case RQSTYPE_ABTS_RCVD:
369 		isp_get_abts(isp, abts, (abts_t *)local);
370 		isp_async(isp, ISPASYNC_TARGET_ACTION, &local);
371 		break;
372 	case RQSTYPE_ABTS_RSP:
373 		isp_get_abts_rsp(isp, abts_rsp, (abts_rsp_t *)local);
374 		abts_rsp = (abts_rsp_t *) local;
375 		if (abts_rsp->abts_rsp_status) {
376 			level = ISP_LOGINFO;
377 		} else {
378 			level = ISP_LOGTDEBUG0;
379 		}
380 		isp_prt(isp, level, "ABTS RSP response[0x%x]: status=0x%x sub=(0x%x 0x%x)", abts_rsp->abts_rsp_rxid_task, abts_rsp->abts_rsp_status,
381 		    abts_rsp->abts_rsp_payload.rsp.subcode1, abts_rsp->abts_rsp_payload.rsp.subcode2);
382 		break;
383 	default:
384 		isp_prt(isp, ISP_LOGERR, "%s: unknown entry type 0x%x", __func__, type);
385 		rval = 0;
386 		break;
387 	}
388 #undef	atiop
389 #undef	at2iop
390 #undef	at2eiop
391 #undef	at7iop
392 #undef	ctiop
393 #undef	ct2iop
394 #undef	ct2eiop
395 #undef	ct7iop
396 #undef	lunenp
397 #undef	inotp
398 #undef	inot_fcp
399 #undef	inote_fcp
400 #undef	inot_24xx
401 #undef	nackp
402 #undef	nack_fcp
403 #undef	nacke_fcp
404 #undef	hack_24xx
405 #undef	abts
406 #undef	abts_rsp
407 #undef	els
408 #undef	hdrp
409 	return (rval);
410 }
411 
412 int
413 isp_target_put_entry(ispsoftc_t *isp, void *ap)
414 {
415 	void *outp;
416 	uint8_t etype = ((isphdr_t *) ap)->rqs_entry_type;
417 
418 	outp = isp_getrqentry(isp);
419 	if (outp == NULL) {
420 		isp_prt(isp, ISP_LOGWARN, rqo, __func__);
421 		return (-1);
422 	}
423 	switch (etype) {
424 	case RQSTYPE_ATIO2:
425 		if (ISP_CAP_2KLOGIN(isp)) {
426 			isp_put_atio2e(isp, (at2e_entry_t *) ap, (at2e_entry_t *) outp);
427 		} else {
428 			isp_put_atio2(isp, (at2_entry_t *) ap, (at2_entry_t *) outp);
429 		}
430 		break;
431 	case RQSTYPE_CTIO2:
432 		if (ISP_CAP_2KLOGIN(isp)) {
433 			isp_put_ctio2e(isp, (ct2e_entry_t *) ap, (ct2e_entry_t *) outp);
434 		} else {
435 			isp_put_ctio2(isp, (ct2_entry_t *) ap, (ct2_entry_t *) outp);
436 		}
437 		break;
438 	case RQSTYPE_CTIO7:
439 		isp_put_ctio7(isp, (ct7_entry_t *) ap, (ct7_entry_t *) outp);
440 		break;
441 	default:
442 		isp_prt(isp, ISP_LOGERR, "%s: Unknown type 0x%x", __func__, etype);
443 		return (-1);
444 	}
445 	ISP_TDQE(isp, __func__, isp->isp_reqidx, ap);
446 	ISP_SYNC_REQUEST(isp);
447 	return (0);
448 }
449 
450 int
451 isp_target_put_atio(ispsoftc_t *isp, void *arg)
452 {
453 	at2_entry_t *aep = arg;
454 	union {
455 		at2_entry_t _atio2;
456 		at2e_entry_t _atio2e;
457 	} atun;
458 
459 	ISP_MEMZERO(&atun, sizeof atun);
460 	atun._atio2.at_header.rqs_entry_type = RQSTYPE_ATIO2;
461 	atun._atio2.at_header.rqs_entry_count = 1;
462 	if (ISP_CAP_SCCFW(isp)) {
463 		atun._atio2.at_scclun = aep->at_scclun;
464 	} else {
465 		atun._atio2.at_lun = (uint8_t) aep->at_lun;
466 	}
467 	if (ISP_CAP_2KLOGIN(isp)) {
468 		atun._atio2e.at_iid = ((at2e_entry_t *)aep)->at_iid;
469 	} else {
470 		atun._atio2.at_iid = aep->at_iid;
471 	}
472 	atun._atio2.at_rxid = aep->at_rxid;
473 	atun._atio2.at_status = CT_OK;
474 	return (isp_target_put_entry(isp, &atun));
475 }
476 
477 /*
478  * Command completion- both for handling cases of no resources or
479  * no blackhole driver, or other cases where we have to, inline,
480  * finish the command sanely, or for normal command completion.
481  *
482  * The 'completion' code value has the scsi status byte in the low 8 bits.
483  * If status is a CHECK CONDITION and bit 8 is nonzero, then bits 12..15 have
484  * the sense key and  bits 16..23 have the ASCQ and bits 24..31 have the ASC
485  * values.
486  *
487  * NB: the key, asc, ascq, cannot be used for parallel SCSI as it doesn't
488  * NB: inline SCSI sense reporting. As such, we lose this information. XXX.
489  *
490  * For both parallel && fibre channel, we use the feature that does
491  * an automatic resource autoreplenish so we don't have then later do
492  * put of an atio to replenish the f/w's resource count.
493  */
494 
495 int
496 isp_endcmd(ispsoftc_t *isp, ...)
497 {
498 	uint32_t code, hdl;
499 	uint8_t sts;
500 	union {
501 		ct2_entry_t _ctio2;
502 		ct2e_entry_t _ctio2e;
503 		ct7_entry_t _ctio7;
504 	} un;
505 	va_list ap;
506 	int vpidx, nphdl;
507 
508 	ISP_MEMZERO(&un, sizeof un);
509 
510 	if (IS_24XX(isp)) {
511 		at7_entry_t *aep;
512 		ct7_entry_t *cto = &un._ctio7;
513 
514 		va_start(ap, isp);
515 		aep = va_arg(ap, at7_entry_t *);
516 		nphdl = va_arg(ap, int);
517 		/*
518 		 * Note that vpidx may equal 0xff (unknown) here
519 		 */
520 		vpidx = va_arg(ap, int);
521 		code = va_arg(ap, uint32_t);
522 		hdl = va_arg(ap, uint32_t);
523 		va_end(ap);
524 		isp_prt(isp, ISP_LOGTDEBUG0, "%s: [RX_ID 0x%x] chan %d code %x", __func__, aep->at_rxid, vpidx, code);
525 
526 		sts = code & 0xff;
527 		cto->ct_header.rqs_entry_type = RQSTYPE_CTIO7;
528 		cto->ct_header.rqs_entry_count = 1;
529 		cto->ct_nphdl = nphdl;
530 		cto->ct_rxid = aep->at_rxid;
531 		cto->ct_iid_lo = (aep->at_hdr.s_id[1] << 8) | aep->at_hdr.s_id[2];
532 		cto->ct_iid_hi = aep->at_hdr.s_id[0];
533 		cto->ct_oxid = aep->at_hdr.ox_id;
534 		cto->ct_scsi_status = sts;
535 		cto->ct_vpidx = vpidx;
536 		cto->ct_flags = CT7_NOACK;
537 		if (code & ECMD_TERMINATE) {
538 			cto->ct_flags |= CT7_TERMINATE;
539 		} else if (code & ECMD_SVALID) {
540 			cto->ct_flags |= CT7_FLAG_MODE1 | CT7_SENDSTATUS;
541 			cto->ct_scsi_status |= (FCP_SNSLEN_VALID << 8);
542 			cto->ct_senselen = min(16, MAXRESPLEN_24XX);
543 			ISP_MEMZERO(cto->rsp.m1.ct_resp, sizeof (cto->rsp.m1.ct_resp));
544 			cto->rsp.m1.ct_resp[0] = 0xf0;
545 			cto->rsp.m1.ct_resp[2] = (code >> 12) & 0xf;
546 			cto->rsp.m1.ct_resp[7] = 8;
547 			cto->rsp.m1.ct_resp[12] = (code >> 16) & 0xff;
548 			cto->rsp.m1.ct_resp[13] = (code >> 24) & 0xff;
549 		} else if (code & ECMD_RVALID) {
550 			cto->ct_flags |= CT7_FLAG_MODE1 | CT7_SENDSTATUS;
551 			cto->ct_scsi_status |= (FCP_RSPLEN_VALID << 8);
552 			cto->rsp.m1.ct_resplen = 4;
553 			ISP_MEMZERO(cto->rsp.m1.ct_resp, sizeof (cto->rsp.m1.ct_resp));
554 			cto->rsp.m1.ct_resp[0] = (code >> 12) & 0xf;
555 			cto->rsp.m1.ct_resp[1] = (code >> 16) & 0xff;
556 			cto->rsp.m1.ct_resp[2] = (code >> 24) & 0xff;
557 			cto->rsp.m1.ct_resp[3] = 0;
558 		} else {
559 			cto->ct_flags |= CT7_FLAG_MODE1 | CT7_SENDSTATUS;
560 		}
561 		if (aep->at_cmnd.cdb_dl.sf.fcp_cmnd_dl) {
562 			cto->ct_resid = aep->at_cmnd.cdb_dl.sf.fcp_cmnd_dl;
563 			if (cto->ct_resid < 0) {
564 				 cto->ct_scsi_status |= (FCP_RESID_OVERFLOW << 8);
565 			} else if (cto->ct_resid > 0) {
566 				 cto->ct_scsi_status |= (FCP_RESID_UNDERFLOW << 8);
567 			}
568 		}
569 		cto->ct_syshandle = hdl;
570 	} else {
571 		at2_entry_t *aep;
572 		ct2_entry_t *cto = &un._ctio2;
573 
574 		va_start(ap, isp);
575 		aep = va_arg(ap, at2_entry_t *);
576 		/* nphdl and vpidx are unused here. */
577 		nphdl = va_arg(ap, int);
578 		vpidx = va_arg(ap, int);
579 		code = va_arg(ap, uint32_t);
580 		hdl = va_arg(ap, uint32_t);
581 		va_end(ap);
582 
583 		isp_prt(isp, ISP_LOGTDEBUG0, "%s: [RX_ID 0x%x] code %x", __func__, aep->at_rxid, code);
584 
585 		sts = code & 0xff;
586 		cto->ct_header.rqs_entry_type = RQSTYPE_CTIO2;
587 		cto->ct_header.rqs_entry_count = 1;
588 		if (ISP_CAP_SCCFW(isp) == 0) {
589 			cto->ct_lun = aep->at_lun;
590 		}
591 		if (ISP_CAP_2KLOGIN(isp)) {
592 			un._ctio2e.ct_iid = ((at2e_entry_t *)aep)->at_iid;
593 		} else {
594 			cto->ct_iid = aep->at_iid;
595 		}
596 		cto->ct_rxid = aep->at_rxid;
597 		cto->rsp.m1.ct_scsi_status = sts;
598 		cto->ct_flags = CT2_SENDSTATUS | CT2_NO_DATA | CT2_FLAG_MODE1;
599 		if (hdl == 0) {
600 			cto->ct_flags |= CT2_CCINCR;
601 		}
602 		if (aep->at_datalen) {
603 			cto->ct_resid = aep->at_datalen;
604 			cto->rsp.m1.ct_scsi_status |= CT2_DATA_UNDER;
605 		}
606 		if (sts == SCSI_CHECK && (code & ECMD_SVALID)) {
607 			cto->rsp.m1.ct_resp[0] = 0xf0;
608 			cto->rsp.m1.ct_resp[2] = (code >> 12) & 0xf;
609 			cto->rsp.m1.ct_resp[7] = 8;
610 			cto->rsp.m1.ct_resp[12] = (code >> 24) & 0xff;
611 			cto->rsp.m1.ct_resp[13] = (code >> 16) & 0xff;
612 			cto->rsp.m1.ct_senselen = 16;
613 			cto->rsp.m1.ct_scsi_status |= CT2_SNSLEN_VALID;
614 		}
615 		cto->ct_syshandle = hdl;
616 	}
617 	return (isp_target_put_entry(isp, &un));
618 }
619 
620 /*
621  * These are either broadcast events or specifically CTIO fast completion
622  */
623 
624 int
625 isp_target_async(ispsoftc_t *isp, int bus, int event)
626 {
627 	isp_notify_t notify;
628 
629 	ISP_MEMZERO(&notify, sizeof (isp_notify_t));
630 	notify.nt_hba = isp;
631 	notify.nt_wwn = INI_ANY;
632 	notify.nt_nphdl = NIL_HANDLE;
633 	notify.nt_sid = PORT_ANY;
634 	notify.nt_did = PORT_ANY;
635 	notify.nt_tgt = TGT_ANY;
636 	notify.nt_channel = bus;
637 	notify.nt_lun = LUN_ANY;
638 	notify.nt_tagval = TAG_ANY;
639 	notify.nt_tagval |= (((uint64_t)(isp->isp_serno++)) << 32);
640 
641 	switch (event) {
642 	case ASYNC_LOOP_UP:
643 	case ASYNC_PTPMODE:
644 		isp_prt(isp, ISP_LOGTDEBUG0, "%s: LOOP UP", __func__);
645 		notify.nt_ncode = NT_LINK_UP;
646 		isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
647 		break;
648 	case ASYNC_LOOP_DOWN:
649 		isp_prt(isp, ISP_LOGTDEBUG0, "%s: LOOP DOWN", __func__);
650 		notify.nt_ncode = NT_LINK_DOWN;
651 		isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
652 		break;
653 	case ASYNC_LIP_ERROR:
654 	case ASYNC_LIP_NOS_OLS_RECV:
655 	case ASYNC_LIP_OCCURRED:
656 	case ASYNC_LOOP_RESET:
657 		isp_prt(isp, ISP_LOGTDEBUG0, "%s: LIP RESET", __func__);
658 		notify.nt_ncode = NT_LIP_RESET;
659 		isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
660 		break;
661 	case ASYNC_BUS_RESET:
662 	case ASYNC_TIMEOUT_RESET:	/* XXX: where does this come from ? */
663 		isp_prt(isp, ISP_LOGTDEBUG0, "%s: BUS RESET", __func__);
664 		notify.nt_ncode = NT_BUS_RESET;
665 		isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
666 		break;
667 	case ASYNC_DEVICE_RESET:
668 		isp_prt(isp, ISP_LOGTDEBUG0, "%s: DEVICE RESET", __func__);
669 		notify.nt_ncode = NT_TARGET_RESET;
670 		isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
671 		break;
672 	case ASYNC_CTIO_DONE:
673 	{
674 		uint8_t storage[QENTRY_LEN];
675 		isp_prt(isp, ISP_LOGTDEBUG0, "%s: CTIO DONE", __func__);
676 		memset(storage, 0, QENTRY_LEN);
677 		if (IS_24XX(isp)) {
678 			ct7_entry_t *ct = (ct7_entry_t *) storage;
679 			ct->ct_header.rqs_entry_type = RQSTYPE_CTIO7;
680 			ct->ct_nphdl = CT7_OK;
681 			ct->ct_syshandle = bus;
682 			ct->ct_flags = CT7_SENDSTATUS;
683 		} else {
684             		/* This should also suffice for 2K login code */
685 			ct2_entry_t *ct = (ct2_entry_t *) storage;
686 			ct->ct_header.rqs_entry_type = RQSTYPE_CTIO2;
687 			ct->ct_status = CT_OK;
688 			ct->ct_syshandle = bus;
689 			ct->ct_flags = CT2_SENDSTATUS|CT2_FASTPOST;
690 		}
691 		isp_async(isp, ISPASYNC_TARGET_ACTION, storage);
692 		break;
693 	}
694 	default:
695 		isp_prt(isp, ISP_LOGERR, "%s: unknown event 0x%x", __func__, event);
696 		if (isp->isp_state == ISP_RUNSTATE) {
697 			isp_async(isp, ISPASYNC_TARGET_NOTIFY_ACK, NULL);
698 		}
699 		break;
700 	}
701 	return (0);
702 }
703 
704 /*
705  * Synthesize a message from the task management flags in a FCP_CMND_IU.
706  */
707 static void
708 isp_got_msg_fc(ispsoftc_t *isp, in_fcentry_t *inp)
709 {
710 	isp_notify_t notify;
711 	static const char f1[] = "%s from N-port handle 0x%x lun %x seq 0x%x";
712 	static const char f2[] = "unknown %s 0x%x lun %x N-Port handle 0x%x task flags 0x%x seq 0x%x\n";
713 	uint16_t seqid, nphdl;
714 
715 	ISP_MEMZERO(&notify, sizeof (isp_notify_t));
716 	notify.nt_hba = isp;
717 	notify.nt_wwn = INI_ANY;
718 	if (ISP_CAP_2KLOGIN(isp)) {
719 		notify.nt_nphdl = ((in_fcentry_e_t *)inp)->in_iid;
720 		nphdl = ((in_fcentry_e_t *)inp)->in_iid;
721 		seqid = ((in_fcentry_e_t *)inp)->in_seqid;
722 	} else {
723 		notify.nt_nphdl = inp->in_iid;
724 		nphdl = inp->in_iid;
725 		seqid = inp->in_seqid;
726 	}
727 	notify.nt_sid = PORT_ANY;
728 	notify.nt_did = PORT_ANY;
729 
730 	/* nt_tgt set in outer layers */
731 	if (ISP_CAP_SCCFW(isp)) {
732 		notify.nt_lun = inp->in_scclun;
733 #if __FreeBSD_version < 1000700
734 		notify.nt_lun &= 0x3fff;
735 #endif
736 	} else {
737 		notify.nt_lun = inp->in_lun;
738 	}
739 	notify.nt_tagval = seqid;
740 	notify.nt_tagval |= (((uint64_t)(isp->isp_serno++)) << 32);
741 	notify.nt_need_ack = 1;
742 	notify.nt_lreserved = inp;
743 
744 	if (inp->in_status != IN_MSG_RECEIVED) {
745 		isp_prt(isp, ISP_LOGINFO, f2, "immediate notify status", inp->in_status, notify.nt_lun, nphdl, inp->in_task_flags, inp->in_seqid);
746 		isp_async(isp, ISPASYNC_TARGET_NOTIFY_ACK, inp);
747 		return;
748 	}
749 
750 	if (inp->in_task_flags & TASK_FLAGS_ABORT_TASK_SET) {
751 		isp_prt(isp, ISP_LOGINFO, f1, "ABORT TASK SET", nphdl, notify.nt_lun, inp->in_seqid);
752 		notify.nt_ncode = NT_ABORT_TASK_SET;
753 	} else if (inp->in_task_flags & TASK_FLAGS_CLEAR_TASK_SET) {
754 		isp_prt(isp, ISP_LOGINFO, f1, "CLEAR TASK SET", nphdl, notify.nt_lun, inp->in_seqid);
755 		notify.nt_ncode = NT_CLEAR_TASK_SET;
756 	} else if (inp->in_task_flags & TASK_FLAGS_LUN_RESET) {
757 		isp_prt(isp, ISP_LOGINFO, f1, "LUN RESET", nphdl, notify.nt_lun, inp->in_seqid);
758 		notify.nt_ncode = NT_LUN_RESET;
759 	} else if (inp->in_task_flags & TASK_FLAGS_TARGET_RESET) {
760 		isp_prt(isp, ISP_LOGINFO, f1, "TARGET RESET", nphdl, notify.nt_lun, inp->in_seqid);
761 		notify.nt_ncode = NT_TARGET_RESET;
762 	} else if (inp->in_task_flags & TASK_FLAGS_CLEAR_ACA) {
763 		isp_prt(isp, ISP_LOGINFO, f1, "CLEAR ACA", nphdl, notify.nt_lun, inp->in_seqid);
764 		notify.nt_ncode = NT_CLEAR_ACA;
765 	} else {
766 		isp_prt(isp, ISP_LOGWARN, f2, "task flag", inp->in_status, notify.nt_lun, nphdl, inp->in_task_flags,  inp->in_seqid);
767 		isp_async(isp, ISPASYNC_TARGET_NOTIFY_ACK, inp);
768 		return;
769 	}
770 	isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
771 }
772 
773 static void
774 isp_got_tmf_24xx(ispsoftc_t *isp, at7_entry_t *aep)
775 {
776 	isp_notify_t notify;
777 	static const char f1[] = "%s from PortID 0x%06x lun %x seq 0x%08x";
778 	static const char f2[] = "unknown Task Flag 0x%x lun %x PortID 0x%x tag 0x%08x";
779 	fcportdb_t *lp;
780 	uint16_t chan;
781 	uint32_t sid, did;
782 
783 	ISP_MEMZERO(&notify, sizeof (isp_notify_t));
784 	notify.nt_hba = isp;
785 	notify.nt_wwn = INI_ANY;
786 	notify.nt_lun = (aep->at_cmnd.fcp_cmnd_lun[0] << 8) | (aep->at_cmnd.fcp_cmnd_lun[1]);
787 	notify.nt_tagval = aep->at_rxid;
788 	notify.nt_tagval |= (((uint64_t)(isp->isp_serno++)) << 32);
789 	notify.nt_lreserved = aep;
790 	sid = (aep->at_hdr.s_id[0] << 16) | (aep->at_hdr.s_id[1] << 8) | aep->at_hdr.s_id[2];
791 	did = (aep->at_hdr.d_id[0] << 16) | (aep->at_hdr.d_id[1] << 8) | aep->at_hdr.d_id[2];
792 	if (ISP_CAP_MULTI_ID(isp) && isp->isp_nchan > 1) {
793 		/* Channel has to be derived from D_ID */
794 		isp_find_chan_by_did(isp, did, &chan);
795 		if (chan == ISP_NOCHAN) {
796 			isp_prt(isp, ISP_LOGWARN, "%s: D_ID 0x%x not found on any channel", __func__, did);
797 			isp_endcmd(isp, aep, NIL_HANDLE, ISP_NOCHAN, ECMD_TERMINATE, 0);
798 			return;
799 		}
800 	} else {
801 		chan = 0;
802 	}
803 	if (isp_find_pdb_by_portid(isp, chan, sid, &lp))
804 		notify.nt_nphdl = lp->handle;
805 	else
806 		notify.nt_nphdl = NIL_HANDLE;
807 	notify.nt_sid = sid;
808 	notify.nt_did = did;
809 	notify.nt_channel = chan;
810 	if (aep->at_cmnd.fcp_cmnd_task_management & FCP_CMND_TMF_QUERY_TASK_SET) {
811 		isp_prt(isp, ISP_LOGINFO, f1, "QUERY TASK SET", sid, notify.nt_lun, aep->at_rxid);
812 		notify.nt_ncode = NT_QUERY_TASK_SET;
813 	} else if (aep->at_cmnd.fcp_cmnd_task_management & FCP_CMND_TMF_ABORT_TASK_SET) {
814 		isp_prt(isp, ISP_LOGINFO, f1, "ABORT TASK SET", sid, notify.nt_lun, aep->at_rxid);
815 		notify.nt_ncode = NT_ABORT_TASK_SET;
816 	} else if (aep->at_cmnd.fcp_cmnd_task_management & FCP_CMND_TMF_CLEAR_TASK_SET) {
817 		isp_prt(isp, ISP_LOGINFO, f1, "CLEAR TASK SET", sid, notify.nt_lun, aep->at_rxid);
818 		notify.nt_ncode = NT_CLEAR_TASK_SET;
819 	} else if (aep->at_cmnd.fcp_cmnd_task_management & FCP_CMND_TMF_QUERY_ASYNC_EVENT) {
820 		isp_prt(isp, ISP_LOGINFO, f1, "QUERY ASYNC EVENT", sid, notify.nt_lun, aep->at_rxid);
821 		notify.nt_ncode = NT_QUERY_ASYNC_EVENT;
822 	} else if (aep->at_cmnd.fcp_cmnd_task_management & FCP_CMND_TMF_LUN_RESET) {
823 		isp_prt(isp, ISP_LOGINFO, f1, "LUN RESET", sid, notify.nt_lun, aep->at_rxid);
824 		notify.nt_ncode = NT_LUN_RESET;
825 	} else if (aep->at_cmnd.fcp_cmnd_task_management & FCP_CMND_TMF_TGT_RESET) {
826 		isp_prt(isp, ISP_LOGINFO, f1, "TARGET RESET", sid, notify.nt_lun, aep->at_rxid);
827 		notify.nt_ncode = NT_TARGET_RESET;
828 	} else if (aep->at_cmnd.fcp_cmnd_task_management & FCP_CMND_TMF_CLEAR_ACA) {
829 		isp_prt(isp, ISP_LOGINFO, f1, "CLEAR ACA", sid, notify.nt_lun, aep->at_rxid);
830 		notify.nt_ncode = NT_CLEAR_ACA;
831 	} else {
832 		isp_prt(isp, ISP_LOGWARN, f2, aep->at_cmnd.fcp_cmnd_task_management, notify.nt_lun, sid, aep->at_rxid);
833 		notify.nt_ncode = NT_UNKNOWN;
834 		isp_endcmd(isp, aep, notify.nt_nphdl, chan, ECMD_RVALID | (0x4 << 12), 0);
835 		return;
836 	}
837 	isp_async(isp, ISPASYNC_TARGET_NOTIFY, &notify);
838 }
839 
840 int
841 isp_notify_ack(ispsoftc_t *isp, void *arg)
842 {
843 	char storage[QENTRY_LEN];
844 	void *outp;
845 
846 	/*
847 	 * This is in case a Task Management Function ends up here.
848 	 */
849 	if (IS_24XX(isp) && arg != NULL && (((isphdr_t *)arg)->rqs_entry_type == RQSTYPE_ATIO)) {
850 		at7_entry_t *aep = arg;
851 		return (isp_endcmd(isp, aep, NIL_HANDLE, 0, 0, 0));
852 	}
853 
854 	outp = isp_getrqentry(isp);
855 	if (outp == NULL) {
856 		isp_prt(isp, ISP_LOGWARN, rqo, __func__);
857 		return (1);
858 	}
859 
860 	ISP_MEMZERO(storage, QENTRY_LEN);
861 
862 	if (IS_24XX(isp)) {
863 		na_fcentry_24xx_t *na = (na_fcentry_24xx_t *) storage;
864 		na->na_header.rqs_entry_type = RQSTYPE_NOTIFY_ACK;
865 		na->na_header.rqs_entry_count = 1;
866 		if (arg) {
867 			in_fcentry_24xx_t *in = arg;
868 			na->na_nphdl = in->in_nphdl;
869 			na->na_flags = in->in_flags;
870 			na->na_status = in->in_status;
871 			na->na_status_subcode = in->in_status_subcode;
872 			na->na_fwhandle = in->in_fwhandle;
873 			na->na_rxid = in->in_rxid;
874 			na->na_oxid = in->in_oxid;
875 			na->na_vpidx = in->in_vpidx;
876 			if (in->in_status == IN24XX_SRR_RCVD) {
877 				na->na_srr_rxid = in->in_srr_rxid;
878 				na->na_srr_reloff_hi = in->in_srr_reloff_hi;
879 				na->na_srr_reloff_lo = in->in_srr_reloff_lo;
880 				na->na_srr_iu = in->in_srr_iu;
881 				/*
882 				 * Whether we're accepting the SRR or rejecting
883 				 * it is determined by looking at the in_reserved
884 				 * field in the original notify structure.
885 				 */
886 				if (in->in_reserved) {
887 					na->na_srr_flags = 1;
888 					na->na_srr_reject_vunique = 0;
889 					na->na_srr_reject_code = 9;		/* unable to perform this command at this time */
890 					na->na_srr_reject_explanation = 0x2a;	/* unable to supply the requested data */
891 				}
892 			}
893 		}
894 		isp_put_notify_24xx_ack(isp, na, (na_fcentry_24xx_t *)outp);
895 	} else {
896 		na_fcentry_t *na = (na_fcentry_t *) storage;
897 		int iid = 0;
898 
899 		if (arg) {
900 			in_fcentry_t *inp = arg;
901 			ISP_MEMCPY(storage, arg, sizeof (isphdr_t));
902 			if (ISP_CAP_2KLOGIN(isp)) {
903 				((na_fcentry_e_t *)na)->na_iid = ((in_fcentry_e_t *)inp)->in_iid;
904 				iid = ((na_fcentry_e_t *)na)->na_iid;
905 			} else {
906 				na->na_iid = inp->in_iid;
907 				iid = na->na_iid;
908 			}
909 			na->na_task_flags = inp->in_task_flags & TASK_FLAGS_RESERVED_MASK;
910 			na->na_seqid = inp->in_seqid;
911 			na->na_status = inp->in_status;
912 			na->na_flags = NAFC_RCOUNT;
913 			if (inp->in_status == IN_RESET) {
914 				na->na_flags = NAFC_RST_CLRD;	/* We do not modify resource counts for LIP resets */
915 			}
916 			if (inp->in_status == IN_MSG_RECEIVED) {
917 				na->na_flags |= NAFC_TVALID;
918 				na->na_response = 0;	/* XXX SUCCEEDED XXX */
919 			}
920 		} else {
921 			na->na_flags = NAFC_RST_CLRD;
922 		}
923 		na->na_header.rqs_entry_type = RQSTYPE_NOTIFY_ACK;
924 		na->na_header.rqs_entry_count = 1;
925 		if (ISP_CAP_2KLOGIN(isp)) {
926 			isp_put_notify_ack_fc_e(isp, (na_fcentry_e_t *) na, (na_fcentry_e_t *)outp);
927 		} else {
928 			isp_put_notify_ack_fc(isp, na, (na_fcentry_t *)outp);
929 		}
930 		isp_prt(isp, ISP_LOGTDEBUG0, "notify ack handle %x seqid %x flags %x tflags %x response %x", iid, na->na_seqid,
931 		    na->na_flags, na->na_task_flags, na->na_response);
932 	}
933 	ISP_TDQE(isp, "isp_notify_ack", isp->isp_reqidx, storage);
934 	ISP_SYNC_REQUEST(isp);
935 	return (0);
936 }
937 
938 int
939 isp_acknak_abts(ispsoftc_t *isp, void *arg, int errno)
940 {
941 	char storage[QENTRY_LEN];
942 	uint16_t tmpw;
943 	uint8_t tmpb;
944 	abts_t *abts = arg;
945 	abts_rsp_t *rsp = (abts_rsp_t *) storage;
946 	void *outp;
947 
948 	if (!IS_24XX(isp)) {
949 		isp_prt(isp, ISP_LOGERR, "%s: called for non-24XX card", __func__);
950 		return (0);
951 	}
952 
953 	if (abts->abts_header.rqs_entry_type != RQSTYPE_ABTS_RCVD) {
954 		isp_prt(isp, ISP_LOGERR, "%s: called for non-ABTS entry (0x%x)", __func__, abts->abts_header.rqs_entry_type);
955 		return (0);
956 	}
957 
958 	outp = isp_getrqentry(isp);
959 	if (outp == NULL) {
960 		isp_prt(isp, ISP_LOGWARN, rqo, __func__);
961 		return (1);
962 	}
963 
964 	ISP_MEMCPY(rsp, abts, QENTRY_LEN);
965 	rsp->abts_rsp_header.rqs_entry_type = RQSTYPE_ABTS_RSP;
966 
967 	/*
968 	 * Swap destination and source for response.
969 	 */
970 	rsp->abts_rsp_r_ctl = BA_ACC;
971 	tmpw = rsp->abts_rsp_did_lo;
972 	tmpb = rsp->abts_rsp_did_hi;
973 	rsp->abts_rsp_did_lo = rsp->abts_rsp_sid_lo;
974 	rsp->abts_rsp_did_hi = rsp->abts_rsp_sid_hi;
975 	rsp->abts_rsp_sid_lo = tmpw;
976 	rsp->abts_rsp_sid_hi = tmpb;
977 
978 	rsp->abts_rsp_f_ctl_hi ^= 0x80; 	/* invert Exchange Context */
979 	rsp->abts_rsp_f_ctl_hi &= ~0x7f;	/* clear Sequence Initiator and other bits */
980 	rsp->abts_rsp_f_ctl_hi |= 0x10;		/* abort the whole exchange */
981 	rsp->abts_rsp_f_ctl_hi |= 0x8;		/* last data frame of sequence */
982 	rsp->abts_rsp_f_ctl_hi |= 0x1;		/* transfer Sequence Initiative */
983 	rsp->abts_rsp_f_ctl_lo = 0;
984 
985 	if (errno == 0) {
986 		uint16_t rx_id, ox_id;
987 
988 		rx_id = rsp->abts_rsp_rx_id;
989 		ox_id = rsp->abts_rsp_ox_id;
990 		ISP_MEMZERO(&rsp->abts_rsp_payload.ba_acc, sizeof (rsp->abts_rsp_payload.ba_acc));
991                 isp_prt(isp, ISP_LOGTINFO, "[0x%x] ABTS of 0x%x being BA_ACC'd", rsp->abts_rsp_rxid_abts, rsp->abts_rsp_rxid_task);
992                 rsp->abts_rsp_payload.ba_acc.aborted_rx_id = rx_id;
993                 rsp->abts_rsp_payload.ba_acc.aborted_ox_id = ox_id;
994                 rsp->abts_rsp_payload.ba_acc.high_seq_cnt = 0xffff;
995 	} else {
996 		ISP_MEMZERO(&rsp->abts_rsp_payload.ba_rjt, sizeof (rsp->abts_rsp_payload.ba_acc));
997 		switch (errno) {
998 		case ENOMEM:
999 			rsp->abts_rsp_payload.ba_rjt.reason = 5;	/* Logical Unit Busy */
1000 			break;
1001 		default:
1002 			rsp->abts_rsp_payload.ba_rjt.reason = 9;	/* Unable to perform command request */
1003 			break;
1004 		}
1005 	}
1006 
1007 	/*
1008 	 * The caller will have set response values as appropriate
1009 	 * in the ABTS structure just before calling us.
1010 	 */
1011 	isp_put_abts_rsp(isp, rsp, (abts_rsp_t *)outp);
1012 	ISP_TDQE(isp, "isp_acknak_abts", isp->isp_reqidx, storage);
1013 	ISP_SYNC_REQUEST(isp);
1014 	return (0);
1015 }
1016 
1017 static void
1018 isp_handle_atio2(ispsoftc_t *isp, at2_entry_t *aep)
1019 {
1020 	int lun, iid;
1021 
1022 	if (ISP_CAP_SCCFW(isp)) {
1023 		lun = aep->at_scclun;
1024 #if __FreeBSD_version < 1000700
1025 		lun &= 0x3fff;
1026 #endif
1027 	} else {
1028 		lun = aep->at_lun;
1029 	}
1030 
1031 	if (ISP_CAP_2KLOGIN(isp)) {
1032 		iid = ((at2e_entry_t *)aep)->at_iid;
1033 	} else {
1034 		iid = aep->at_iid;
1035 	}
1036 
1037 	/*
1038 	 * The firmware status (except for the QLTM_SVALID bit) indicates
1039 	 * why this ATIO was sent to us.
1040 	 *
1041 	 * If QLTM_SVALID is set, the firware has recommended Sense Data.
1042 	 *
1043 	 * If the DISCONNECTS DISABLED bit is set in the flags field,
1044 	 * we're still connected on the SCSI bus - i.e. the initiator
1045 	 * did not set DiscPriv in the identify message. We don't care
1046 	 * about this so it's ignored.
1047 	 */
1048 
1049 	switch (aep->at_status & ~QLTM_SVALID) {
1050 	case AT_PATH_INVALID:
1051 		/*
1052 		 * ATIO rejected by the firmware due to disabled lun.
1053 		 */
1054 		isp_prt(isp, ISP_LOGERR, "rejected ATIO2 for disabled lun %x", lun);
1055 		break;
1056 	case AT_NOCAP:
1057 		/*
1058 		 * Requested Capability not available
1059 		 * We sent an ATIO that overflowed the firmware's
1060 		 * command resource count.
1061 		 */
1062 		isp_prt(isp, ISP_LOGERR, "rejected ATIO2 for lun %x- command count overflow", lun);
1063 		break;
1064 
1065 	case AT_BDR_MSG:
1066 		/*
1067 		 * If we send an ATIO to the firmware to increment
1068 		 * its command resource count, and the firmware is
1069 		 * recovering from a Bus Device Reset, it returns
1070 		 * the ATIO with this status. We set the command
1071 		 * resource count in the Enable Lun entry and no
1072 		 * not increment it. Therefore we should never get
1073 		 * this status here.
1074 		 */
1075 		isp_prt(isp, ISP_LOGERR, atiocope, lun, 0);
1076 		break;
1077 
1078 	case AT_CDB:		/* Got a CDB */
1079 		/*
1080 		 * Punt to platform specific layer.
1081 		 */
1082 		isp_async(isp, ISPASYNC_TARGET_ACTION, aep);
1083 		break;
1084 
1085 	case AT_RESET:
1086 		/*
1087 		 * A bus reset came along an blew away this command. Why
1088 		 * they do this in addition the async event code stuff,
1089 		 * I dunno.
1090 		 *
1091 		 * Ignore it because the async event will clear things
1092 		 * up for us.
1093 		 */
1094 		isp_prt(isp, ISP_LOGERR, atior, lun, iid, 0);
1095 		break;
1096 
1097 
1098 	default:
1099 		isp_prt(isp, ISP_LOGERR, "Unknown ATIO2 status 0x%x from handle %d for lun %x", aep->at_status, iid, lun);
1100 		(void) isp_target_put_atio(isp, aep);
1101 		break;
1102 	}
1103 }
1104 
1105 static void
1106 isp_handle_ctio2(ispsoftc_t *isp, ct2_entry_t *ct)
1107 {
1108 	void *xs;
1109 	int pl = ISP_LOGTDEBUG2;
1110 	char *fmsg = NULL;
1111 
1112 	if (ct->ct_syshandle) {
1113 		xs = isp_find_xs(isp, ct->ct_syshandle);
1114 		if (xs == NULL) {
1115 			pl = ISP_LOGALL;
1116 		}
1117 	} else {
1118 		xs = NULL;
1119 	}
1120 
1121 	switch (ct->ct_status & ~QLTM_SVALID) {
1122 	case CT_BUS_ERROR:
1123 		isp_prt(isp, ISP_LOGERR, "PCI DMA Bus Error");
1124 		/* FALL Through */
1125 	case CT_DATA_OVER:
1126 	case CT_DATA_UNDER:
1127 	case CT_OK:
1128 		/*
1129 		 * There are generally 2 possibilities as to why we'd get
1130 		 * this condition:
1131 		 * 	We sent or received data.
1132 		 * 	We sent status & command complete.
1133 		 */
1134 
1135 		break;
1136 
1137 	case CT_BDR_MSG:
1138 		/*
1139 		 * Target Reset function received.
1140 		 *
1141 		 * The firmware generates an async mailbox interrupt to
1142 		 * notify us of this and returns outstanding CTIOs with this
1143 		 * status. These CTIOs are handled in that same way as
1144 		 * CT_ABORTED ones, so just fall through here.
1145 		 */
1146 		fmsg = "TARGET RESET";
1147 		/*FALLTHROUGH*/
1148 	case CT_RESET:
1149 		if (fmsg == NULL)
1150 			fmsg = "LIP Reset";
1151 		/*FALLTHROUGH*/
1152 	case CT_ABORTED:
1153 		/*
1154 		 * When an Abort message is received the firmware goes to
1155 		 * Bus Free and returns all outstanding CTIOs with the status
1156 		 * set, then sends us an Immediate Notify entry.
1157 		 */
1158 		if (fmsg == NULL) {
1159 			fmsg = "ABORT";
1160 		}
1161 
1162 		isp_prt(isp, ISP_LOGTDEBUG0, "CTIO2 destroyed by %s: RX_ID=0x%x", fmsg, ct->ct_rxid);
1163 		break;
1164 
1165 	case CT_INVAL:
1166 		/*
1167 		 * CTIO rejected by the firmware - invalid data direction.
1168 		 */
1169 		isp_prt(isp, ISP_LOGERR, "CTIO2 had wrong data direction");
1170 		break;
1171 
1172 	case CT_RSELTMO:
1173 		fmsg = "failure to reconnect to initiator";
1174 		/*FALLTHROUGH*/
1175 	case CT_TIMEOUT:
1176 		if (fmsg == NULL)
1177 			fmsg = "command";
1178 		isp_prt(isp, ISP_LOGWARN, "Firmware timed out on %s", fmsg);
1179 		break;
1180 
1181 	case CT_ERR:
1182 		fmsg = "Completed with Error";
1183 		/*FALLTHROUGH*/
1184 	case CT_LOGOUT:
1185 		if (fmsg == NULL)
1186 			fmsg = "Port Logout";
1187 		/*FALLTHROUGH*/
1188 	case CT_PORTUNAVAIL:
1189 		if (fmsg == NULL)
1190 			fmsg = "Port not available";
1191 		/*FALLTHROUGH*/
1192 	case CT_PORTCHANGED:
1193 		if (fmsg == NULL)
1194 			fmsg = "Port Changed";
1195 		/*FALLTHROUGH*/
1196 	case CT_NOACK:
1197 		if (fmsg == NULL)
1198 			fmsg = "unacknowledged Immediate Notify pending";
1199 		isp_prt(isp, ISP_LOGWARN, "CTIO returned by f/w- %s", fmsg);
1200 		break;
1201 
1202 	case CT_INVRXID:
1203 		/*
1204 		 * CTIO rejected by the firmware because an invalid RX_ID.
1205 		 * Just print a message.
1206 		 */
1207 		isp_prt(isp, ISP_LOGWARN, "CTIO2 completed with Invalid RX_ID 0x%x", ct->ct_rxid);
1208 		break;
1209 
1210 	default:
1211 		isp_prt(isp, ISP_LOGERR, "Unknown CTIO2 status 0x%x", ct->ct_status & ~QLTM_SVALID);
1212 		break;
1213 	}
1214 
1215 	if (xs == NULL) {
1216 		/*
1217 		 * There may be more than one CTIO for a data transfer,
1218 		 * or this may be a status CTIO we're not monitoring.
1219 		 *
1220 		 * The assumption is that they'll all be returned in the
1221 		 * order we got them.
1222 		 */
1223 		if (ct->ct_syshandle == 0) {
1224 			if ((ct->ct_flags & CT2_SENDSTATUS) == 0) {
1225 				isp_prt(isp, pl, "intermediate CTIO completed ok");
1226 			} else {
1227 				isp_prt(isp, pl, "unmonitored CTIO completed ok");
1228 			}
1229 		} else {
1230 			isp_prt(isp, pl, "NO xs for CTIO (handle 0x%x) status 0x%x", ct->ct_syshandle, ct->ct_status & ~QLTM_SVALID);
1231 		}
1232 	} else {
1233 		if ((ct->ct_flags & CT2_DATAMASK) != CT2_NO_DATA) {
1234 			ISP_DMAFREE(isp, xs, ct->ct_syshandle);
1235 		}
1236 		if (ct->ct_flags & CT2_SENDSTATUS) {
1237 			/*
1238 			 * Sent status and command complete.
1239 			 *
1240 			 * We're now really done with this command, so we
1241 			 * punt to the platform dependent layers because
1242 			 * only there can we do the appropriate command
1243 			 * complete thread synchronization.
1244 			 */
1245 			isp_prt(isp, pl, "status CTIO complete");
1246 		} else {
1247 			/*
1248 			 * Final CTIO completed. Release DMA resources and
1249 			 * notify platform dependent layers.
1250 			 */
1251 			isp_prt(isp, pl, "data CTIO complete");
1252 		}
1253 		isp_async(isp, ISPASYNC_TARGET_ACTION, ct);
1254 		/*
1255 		 * The platform layer will destroy the handle if appropriate.
1256 		 */
1257 	}
1258 }
1259 
1260 static void
1261 isp_handle_ctio7(ispsoftc_t *isp, ct7_entry_t *ct)
1262 {
1263 	void *xs;
1264 	int pl = ISP_LOGTDEBUG2;
1265 	char *fmsg = NULL;
1266 
1267 	if (ct->ct_syshandle) {
1268 		xs = isp_find_xs(isp, ct->ct_syshandle);
1269 		if (xs == NULL) {
1270 			pl = ISP_LOGALL;
1271 		}
1272 	} else {
1273 		xs = NULL;
1274 	}
1275 
1276 	switch (ct->ct_nphdl) {
1277 	case CT7_BUS_ERROR:
1278 		isp_prt(isp, ISP_LOGERR, "PCI DMA Bus Error");
1279 		/* FALL Through */
1280 	case CT7_DATA_OVER:
1281 	case CT7_DATA_UNDER:
1282 	case CT7_OK:
1283 		/*
1284 		 * There are generally 2 possibilities as to why we'd get
1285 		 * this condition:
1286 		 * 	We sent or received data.
1287 		 * 	We sent status & command complete.
1288 		 */
1289 
1290 		break;
1291 
1292 	case CT7_RESET:
1293 		if (fmsg == NULL) {
1294 			fmsg = "LIP Reset";
1295 		}
1296 		/*FALLTHROUGH*/
1297 	case CT7_ABORTED:
1298 		/*
1299 		 * When an Abort message is received the firmware goes to
1300 		 * Bus Free and returns all outstanding CTIOs with the status
1301 		 * set, then sends us an Immediate Notify entry.
1302 		 */
1303 		if (fmsg == NULL) {
1304 			fmsg = "ABORT";
1305 		}
1306 		isp_prt(isp, ISP_LOGTDEBUG0, "CTIO7 destroyed by %s: RX_ID=0x%x", fmsg, ct->ct_rxid);
1307 		break;
1308 
1309 	case CT7_TIMEOUT:
1310 		if (fmsg == NULL) {
1311 			fmsg = "command";
1312 		}
1313 		isp_prt(isp, ISP_LOGWARN, "Firmware timed out on %s", fmsg);
1314 		break;
1315 
1316 	case CT7_ERR:
1317 		fmsg = "Completed with Error";
1318 		/*FALLTHROUGH*/
1319 	case CT7_LOGOUT:
1320 		if (fmsg == NULL) {
1321 			fmsg = "Port Logout";
1322 		}
1323 		/*FALLTHROUGH*/
1324 	case CT7_PORTUNAVAIL:
1325 		if (fmsg == NULL) {
1326 			fmsg = "Port not available";
1327 		}
1328 		/*FALLTHROUGH*/
1329 	case CT7_PORTCHANGED:
1330 		if (fmsg == NULL) {
1331 			fmsg = "Port Changed";
1332 		}
1333 		isp_prt(isp, ISP_LOGWARN, "CTIO returned by f/w- %s", fmsg);
1334 		break;
1335 
1336 	case CT7_INVRXID:
1337 		/*
1338 		 * CTIO rejected by the firmware because an invalid RX_ID.
1339 		 * Just print a message.
1340 		 */
1341 		isp_prt(isp, ISP_LOGWARN, "CTIO7 completed with Invalid RX_ID 0x%x", ct->ct_rxid);
1342 		break;
1343 
1344 	case CT7_REASSY_ERR:
1345 		isp_prt(isp, ISP_LOGWARN, "reassembly error");
1346 		break;
1347 
1348 	case CT7_SRR:
1349 		isp_prt(isp, ISP_LOGTDEBUG0, "SRR received");
1350 		break;
1351 
1352 	default:
1353 		isp_prt(isp, ISP_LOGERR, "Unknown CTIO7 status 0x%x", ct->ct_nphdl);
1354 		break;
1355 	}
1356 
1357 	if (xs == NULL) {
1358 		/*
1359 		 * There may be more than one CTIO for a data transfer,
1360 		 * or this may be a status CTIO we're not monitoring.
1361 		 *
1362 		 * The assumption is that they'll all be returned in the
1363 		 * order we got them.
1364 		 */
1365 		if (ct->ct_syshandle == 0) {
1366 			if (ct->ct_flags & CT7_TERMINATE) {
1367 				isp_prt(isp, ISP_LOGINFO, "termination of [RX_ID 0x%x] complete", ct->ct_rxid);
1368 			} else if ((ct->ct_flags & CT7_SENDSTATUS) == 0) {
1369 				isp_prt(isp, pl, "intermediate CTIO completed ok");
1370 			} else {
1371 				isp_prt(isp, pl, "unmonitored CTIO completed ok");
1372 			}
1373 		} else {
1374 			isp_prt(isp, pl, "NO xs for CTIO (handle 0x%x) status 0x%x", ct->ct_syshandle, ct->ct_nphdl);
1375 		}
1376 	} else {
1377 		if ((ct->ct_flags & CT7_DATAMASK) != CT7_NO_DATA) {
1378 			ISP_DMAFREE(isp, xs, ct->ct_syshandle);
1379 		}
1380 		if (ct->ct_flags & CT7_SENDSTATUS) {
1381 			/*
1382 			 * Sent status and command complete.
1383 			 *
1384 			 * We're now really done with this command, so we
1385 			 * punt to the platform dependent layers because
1386 			 * only there can we do the appropriate command
1387 			 * complete thread synchronization.
1388 			 */
1389 			isp_prt(isp, pl, "status CTIO complete");
1390 		} else {
1391 			/*
1392 			 * Final CTIO completed. Release DMA resources and
1393 			 * notify platform dependent layers.
1394 			 */
1395 			isp_prt(isp, pl, "data CTIO complete");
1396 		}
1397 		isp_async(isp, ISPASYNC_TARGET_ACTION, ct);
1398 		/*
1399 		 * The platform layer will destroy the handle if appropriate.
1400 		 */
1401 	}
1402 }
1403 
1404 static void
1405 isp_handle_24xx_inotify(ispsoftc_t *isp, in_fcentry_24xx_t *inot_24xx)
1406 {
1407 	uint8_t ochan, chan, lochan, hichan;
1408 
1409 	/*
1410 	 * Check to see whether we got a wildcard channel.
1411 	 * If so, we have to iterate over all channels.
1412 	 */
1413 	ochan = chan = ISP_GET_VPIDX(isp, inot_24xx->in_vpidx);
1414 	if (chan == 0xff) {
1415 		lochan = 0;
1416 		hichan = isp->isp_nchan;
1417 	} else {
1418 		if (chan >= isp->isp_nchan) {
1419 			char buf[64];
1420 			ISP_SNPRINTF(buf, sizeof buf, "%s: bad channel %d for status 0x%x", __func__, chan, inot_24xx->in_status);
1421 			isp_print_bytes(isp, buf, QENTRY_LEN, inot_24xx);
1422 			isp_async(isp, ISPASYNC_TARGET_NOTIFY_ACK, inot_24xx);
1423 			return;
1424 		}
1425 		lochan = chan;
1426 		hichan = chan + 1;
1427 	}
1428 	isp_prt(isp, ISP_LOGTDEBUG1, "%s: Immediate Notify Channels %d..%d status=0x%x seqid=0x%x", __func__, lochan, hichan-1, inot_24xx->in_status, inot_24xx->in_rxid);
1429 	for (chan = lochan; chan < hichan; chan++) {
1430 		if (FCPARAM(isp, chan)->role == ISP_ROLE_NONE)
1431 			continue;
1432 		switch (inot_24xx->in_status) {
1433 		case IN24XX_LIP_RESET:
1434 		case IN24XX_LINK_RESET:
1435 		case IN24XX_PORT_LOGOUT:
1436 		case IN24XX_PORT_CHANGED:
1437 		case IN24XX_LINK_FAILED:
1438 		case IN24XX_SRR_RCVD:
1439 		case IN24XX_ELS_RCVD:
1440 			inot_24xx->in_reserved = 0;	/* clear this for later usage */
1441 			inot_24xx->in_vpidx = chan;
1442 			isp_async(isp, ISPASYNC_TARGET_ACTION, inot_24xx);
1443 			break;
1444 		default:
1445 			isp_prt(isp, ISP_LOGINFO, "%s: unhandled status (0x%x) for chan %d", __func__, inot_24xx->in_status, chan);
1446 			isp_async(isp, ISPASYNC_TARGET_NOTIFY_ACK, inot_24xx);
1447 			break;
1448 		}
1449 	}
1450 	inot_24xx->in_vpidx = ochan;
1451 }
1452 #endif
1453