xref: /freebsd/sys/dev/mfi/mfi.c (revision 94942af266ac119ede0ca836f9aa5a5ac0582938)
1 /*-
2  * Copyright (c) 2006 IronPort Systems
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  *
14  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
15  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
18  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
24  * SUCH DAMAGE.
25  */
26 
27 #include <sys/cdefs.h>
28 __FBSDID("$FreeBSD$");
29 
30 #include "opt_mfi.h"
31 
32 #include <sys/param.h>
33 #include <sys/systm.h>
34 #include <sys/sysctl.h>
35 #include <sys/malloc.h>
36 #include <sys/kernel.h>
37 #include <sys/poll.h>
38 #include <sys/selinfo.h>
39 #include <sys/bus.h>
40 #include <sys/conf.h>
41 #include <sys/eventhandler.h>
42 #include <sys/rman.h>
43 #include <sys/bus_dma.h>
44 #include <sys/bio.h>
45 #include <sys/ioccom.h>
46 #include <sys/uio.h>
47 #include <sys/proc.h>
48 #include <sys/signalvar.h>
49 
50 #include <machine/bus.h>
51 #include <machine/resource.h>
52 
53 #include <dev/mfi/mfireg.h>
54 #include <dev/mfi/mfi_ioctl.h>
55 #include <dev/mfi/mfivar.h>
56 
57 static int	mfi_alloc_commands(struct mfi_softc *);
58 static int	mfi_comms_init(struct mfi_softc *);
59 static int	mfi_wait_command(struct mfi_softc *, struct mfi_command *);
60 static int	mfi_get_controller_info(struct mfi_softc *);
61 static int	mfi_get_log_state(struct mfi_softc *,
62 		    struct mfi_evt_log_state **);
63 static int	mfi_get_entry(struct mfi_softc *, int);
64 static int	mfi_dcmd_command(struct mfi_softc *, struct mfi_command **,
65 		    uint32_t, void **, size_t);
66 static void	mfi_data_cb(void *, bus_dma_segment_t *, int, int);
67 static void	mfi_startup(void *arg);
68 static void	mfi_intr(void *arg);
69 static void	mfi_enable_intr(struct mfi_softc *sc);
70 static void	mfi_ldprobe(struct mfi_softc *sc);
71 static int	mfi_aen_register(struct mfi_softc *sc, int seq, int locale);
72 static void	mfi_aen_complete(struct mfi_command *);
73 static int	mfi_aen_setup(struct mfi_softc *, uint32_t);
74 static int	mfi_add_ld(struct mfi_softc *sc, int);
75 static void	mfi_add_ld_complete(struct mfi_command *);
76 static struct mfi_command * mfi_bio_command(struct mfi_softc *);
77 static void	mfi_bio_complete(struct mfi_command *);
78 static int	mfi_mapcmd(struct mfi_softc *, struct mfi_command *);
79 static int	mfi_send_frame(struct mfi_softc *, struct mfi_command *);
80 static void	mfi_complete(struct mfi_softc *, struct mfi_command *);
81 static int	mfi_abort(struct mfi_softc *, struct mfi_command *);
82 static int	mfi_linux_ioctl_int(struct cdev *, u_long, caddr_t, int, d_thread_t *);
83 static void	mfi_timeout(void *);
84 
85 
86 SYSCTL_NODE(_hw, OID_AUTO, mfi, CTLFLAG_RD, 0, "MFI driver parameters");
87 static int	mfi_event_locale = MFI_EVT_LOCALE_ALL;
88 TUNABLE_INT("hw.mfi.event_locale", &mfi_event_locale);
89 SYSCTL_INT(_hw_mfi, OID_AUTO, event_locale, CTLFLAG_RW, &mfi_event_locale,
90             0, "event message locale");
91 
92 static int	mfi_event_class = MFI_EVT_CLASS_INFO;
93 TUNABLE_INT("hw.mfi.event_class", &mfi_event_class);
94 SYSCTL_INT(_hw_mfi, OID_AUTO, event_class, CTLFLAG_RW, &mfi_event_class,
95           0, "event message class");
96 
97 /* Management interface */
98 static d_open_t		mfi_open;
99 static d_close_t	mfi_close;
100 static d_ioctl_t	mfi_ioctl;
101 static d_poll_t		mfi_poll;
102 
103 static struct cdevsw mfi_cdevsw = {
104 	.d_version = 	D_VERSION,
105 	.d_flags =	0,
106 	.d_open = 	mfi_open,
107 	.d_close =	mfi_close,
108 	.d_ioctl =	mfi_ioctl,
109 	.d_poll =	mfi_poll,
110 	.d_name =	"mfi",
111 };
112 
113 MALLOC_DEFINE(M_MFIBUF, "mfibuf", "Buffers for the MFI driver");
114 
115 #define MFI_INQ_LENGTH SHORT_INQUIRY_LENGTH
116 
117 static int
118 mfi_transition_firmware(struct mfi_softc *sc)
119 {
120 	int32_t fw_state, cur_state;
121 	int max_wait, i;
122 
123 	fw_state = MFI_READ4(sc, MFI_OMSG0) & MFI_FWSTATE_MASK;
124 	while (fw_state != MFI_FWSTATE_READY) {
125 		if (bootverbose)
126 			device_printf(sc->mfi_dev, "Waiting for firmware to "
127 			    "become ready\n");
128 		cur_state = fw_state;
129 		switch (fw_state) {
130 		case MFI_FWSTATE_FAULT:
131 			device_printf(sc->mfi_dev, "Firmware fault\n");
132 			return (ENXIO);
133 		case MFI_FWSTATE_WAIT_HANDSHAKE:
134 			MFI_WRITE4(sc, MFI_IDB, MFI_FWINIT_CLEAR_HANDSHAKE);
135 			max_wait = 2;
136 			break;
137 		case MFI_FWSTATE_OPERATIONAL:
138 			MFI_WRITE4(sc, MFI_IDB, MFI_FWINIT_READY);
139 			max_wait = 10;
140 			break;
141 		case MFI_FWSTATE_UNDEFINED:
142 		case MFI_FWSTATE_BB_INIT:
143 			max_wait = 2;
144 			break;
145 		case MFI_FWSTATE_FW_INIT:
146 		case MFI_FWSTATE_DEVICE_SCAN:
147 		case MFI_FWSTATE_FLUSH_CACHE:
148 			max_wait = 20;
149 			break;
150 		default:
151 			device_printf(sc->mfi_dev,"Unknown firmware state %d\n",
152 			    fw_state);
153 			return (ENXIO);
154 		}
155 		for (i = 0; i < (max_wait * 10); i++) {
156 			fw_state = MFI_READ4(sc, MFI_OMSG0) & MFI_FWSTATE_MASK;
157 			if (fw_state == cur_state)
158 				DELAY(100000);
159 			else
160 				break;
161 		}
162 		if (fw_state == cur_state) {
163 			device_printf(sc->mfi_dev, "firmware stuck in state "
164 			    "%#x\n", fw_state);
165 			return (ENXIO);
166 		}
167 	}
168 	return (0);
169 }
170 
171 static void
172 mfi_addr32_cb(void *arg, bus_dma_segment_t *segs, int nsegs, int error)
173 {
174 	uint32_t *addr;
175 
176 	addr = arg;
177 	*addr = segs[0].ds_addr;
178 }
179 
180 int
181 mfi_attach(struct mfi_softc *sc)
182 {
183 	uint32_t status;
184 	int error, commsz, framessz, sensesz;
185 	int frames, unit, max_fw_sge;
186 
187 	mtx_init(&sc->mfi_io_lock, "MFI I/O lock", NULL, MTX_DEF);
188 	TAILQ_INIT(&sc->mfi_ld_tqh);
189 	TAILQ_INIT(&sc->mfi_aen_pids);
190 	TAILQ_INIT(&sc->mfi_cam_ccbq);
191 
192 	mfi_initq_free(sc);
193 	mfi_initq_ready(sc);
194 	mfi_initq_busy(sc);
195 	mfi_initq_bio(sc);
196 
197 	/* Before we get too far, see if the firmware is working */
198 	if ((error = mfi_transition_firmware(sc)) != 0) {
199 		device_printf(sc->mfi_dev, "Firmware not in READY state, "
200 		    "error %d\n", error);
201 		return (ENXIO);
202 	}
203 
204 	/*
205 	 * Get information needed for sizing the contiguous memory for the
206 	 * frame pool.  Size down the sgl parameter since we know that
207 	 * we will never need more than what's required for MAXPHYS.
208 	 * It would be nice if these constants were available at runtime
209 	 * instead of compile time.
210 	 */
211 	status = MFI_READ4(sc, MFI_OMSG0);
212 	sc->mfi_max_fw_cmds = status & MFI_FWSTATE_MAXCMD_MASK;
213 	max_fw_sge = (status & MFI_FWSTATE_MAXSGL_MASK) >> 16;
214 	sc->mfi_max_sge = min(max_fw_sge, ((MAXPHYS / PAGE_SIZE) + 1));
215 
216 	/*
217 	 * Create the dma tag for data buffers.  Used both for block I/O
218 	 * and for various internal data queries.
219 	 */
220 	if (bus_dma_tag_create( sc->mfi_parent_dmat,	/* parent */
221 				1, 0,			/* algnmnt, boundary */
222 				BUS_SPACE_MAXADDR,	/* lowaddr */
223 				BUS_SPACE_MAXADDR,	/* highaddr */
224 				NULL, NULL,		/* filter, filterarg */
225 				BUS_SPACE_MAXSIZE_32BIT,/* maxsize */
226 				sc->mfi_max_sge,	/* nsegments */
227 				BUS_SPACE_MAXSIZE_32BIT,/* maxsegsize */
228 				BUS_DMA_ALLOCNOW,	/* flags */
229 				busdma_lock_mutex,	/* lockfunc */
230 				&sc->mfi_io_lock,	/* lockfuncarg */
231 				&sc->mfi_buffer_dmat)) {
232 		device_printf(sc->mfi_dev, "Cannot allocate buffer DMA tag\n");
233 		return (ENOMEM);
234 	}
235 
236 	/*
237 	 * Allocate DMA memory for the comms queues.  Keep it under 4GB for
238 	 * efficiency.  The mfi_hwcomms struct includes space for 1 reply queue
239 	 * entry, so the calculated size here will be will be 1 more than
240 	 * mfi_max_fw_cmds.  This is apparently a requirement of the hardware.
241 	 */
242 	commsz = (sizeof(uint32_t) * sc->mfi_max_fw_cmds) +
243 	    sizeof(struct mfi_hwcomms);
244 	if (bus_dma_tag_create( sc->mfi_parent_dmat,	/* parent */
245 				1, 0,			/* algnmnt, boundary */
246 				BUS_SPACE_MAXADDR_32BIT,/* lowaddr */
247 				BUS_SPACE_MAXADDR,	/* highaddr */
248 				NULL, NULL,		/* filter, filterarg */
249 				commsz,			/* maxsize */
250 				1,			/* msegments */
251 				commsz,			/* maxsegsize */
252 				0,			/* flags */
253 				NULL, NULL,		/* lockfunc, lockarg */
254 				&sc->mfi_comms_dmat)) {
255 		device_printf(sc->mfi_dev, "Cannot allocate comms DMA tag\n");
256 		return (ENOMEM);
257 	}
258 	if (bus_dmamem_alloc(sc->mfi_comms_dmat, (void **)&sc->mfi_comms,
259 	    BUS_DMA_NOWAIT, &sc->mfi_comms_dmamap)) {
260 		device_printf(sc->mfi_dev, "Cannot allocate comms memory\n");
261 		return (ENOMEM);
262 	}
263 	bzero(sc->mfi_comms, commsz);
264 	bus_dmamap_load(sc->mfi_comms_dmat, sc->mfi_comms_dmamap,
265 	    sc->mfi_comms, commsz, mfi_addr32_cb, &sc->mfi_comms_busaddr, 0);
266 
267 	/*
268 	 * Allocate DMA memory for the command frames.  Keep them in the
269 	 * lower 4GB for efficiency.  Calculate the size of the commands at
270 	 * the same time; each command is one 64 byte frame plus a set of
271          * additional frames for holding sg lists or other data.
272 	 * The assumption here is that the SG list will start at the second
273 	 * frame and not use the unused bytes in the first frame.  While this
274 	 * isn't technically correct, it simplifies the calculation and allows
275 	 * for command frames that might be larger than an mfi_io_frame.
276 	 */
277 	if (sizeof(bus_addr_t) == 8) {
278 		sc->mfi_sge_size = sizeof(struct mfi_sg64);
279 		sc->mfi_flags |= MFI_FLAGS_SG64;
280 	} else {
281 		sc->mfi_sge_size = sizeof(struct mfi_sg32);
282 	}
283 	frames = (sc->mfi_sge_size * sc->mfi_max_sge - 1) / MFI_FRAME_SIZE + 2;
284 	sc->mfi_cmd_size = frames * MFI_FRAME_SIZE;
285 	framessz = sc->mfi_cmd_size * sc->mfi_max_fw_cmds;
286 	if (bus_dma_tag_create( sc->mfi_parent_dmat,	/* parent */
287 				64, 0,			/* algnmnt, boundary */
288 				BUS_SPACE_MAXADDR_32BIT,/* lowaddr */
289 				BUS_SPACE_MAXADDR,	/* highaddr */
290 				NULL, NULL,		/* filter, filterarg */
291 				framessz,		/* maxsize */
292 				1,			/* nsegments */
293 				framessz,		/* maxsegsize */
294 				0,			/* flags */
295 				NULL, NULL,		/* lockfunc, lockarg */
296 				&sc->mfi_frames_dmat)) {
297 		device_printf(sc->mfi_dev, "Cannot allocate frame DMA tag\n");
298 		return (ENOMEM);
299 	}
300 	if (bus_dmamem_alloc(sc->mfi_frames_dmat, (void **)&sc->mfi_frames,
301 	    BUS_DMA_NOWAIT, &sc->mfi_frames_dmamap)) {
302 		device_printf(sc->mfi_dev, "Cannot allocate frames memory\n");
303 		return (ENOMEM);
304 	}
305 	bzero(sc->mfi_frames, framessz);
306 	bus_dmamap_load(sc->mfi_frames_dmat, sc->mfi_frames_dmamap,
307 	    sc->mfi_frames, framessz, mfi_addr32_cb, &sc->mfi_frames_busaddr,0);
308 
309 	/*
310 	 * Allocate DMA memory for the frame sense data.  Keep them in the
311 	 * lower 4GB for efficiency
312 	 */
313 	sensesz = sc->mfi_max_fw_cmds * MFI_SENSE_LEN;
314 	if (bus_dma_tag_create( sc->mfi_parent_dmat,	/* parent */
315 				4, 0,			/* algnmnt, boundary */
316 				BUS_SPACE_MAXADDR_32BIT,/* lowaddr */
317 				BUS_SPACE_MAXADDR,	/* highaddr */
318 				NULL, NULL,		/* filter, filterarg */
319 				sensesz,		/* maxsize */
320 				1,			/* nsegments */
321 				sensesz,		/* maxsegsize */
322 				0,			/* flags */
323 				NULL, NULL,		/* lockfunc, lockarg */
324 				&sc->mfi_sense_dmat)) {
325 		device_printf(sc->mfi_dev, "Cannot allocate sense DMA tag\n");
326 		return (ENOMEM);
327 	}
328 	if (bus_dmamem_alloc(sc->mfi_sense_dmat, (void **)&sc->mfi_sense,
329 	    BUS_DMA_NOWAIT, &sc->mfi_sense_dmamap)) {
330 		device_printf(sc->mfi_dev, "Cannot allocate sense memory\n");
331 		return (ENOMEM);
332 	}
333 	bus_dmamap_load(sc->mfi_sense_dmat, sc->mfi_sense_dmamap,
334 	    sc->mfi_sense, sensesz, mfi_addr32_cb, &sc->mfi_sense_busaddr, 0);
335 
336 	if ((error = mfi_alloc_commands(sc)) != 0)
337 		return (error);
338 
339 	if ((error = mfi_comms_init(sc)) != 0)
340 		return (error);
341 
342 	if ((error = mfi_get_controller_info(sc)) != 0)
343 		return (error);
344 
345 	mtx_lock(&sc->mfi_io_lock);
346 	if ((error = mfi_aen_setup(sc, 0), 0) != 0) {
347 		mtx_unlock(&sc->mfi_io_lock);
348 		return (error);
349 	}
350 	mtx_unlock(&sc->mfi_io_lock);
351 
352 	/*
353 	 * Set up the interrupt handler.  XXX This should happen in
354 	 * mfi_pci.c
355 	 */
356 	sc->mfi_irq_rid = 0;
357 	if ((sc->mfi_irq = bus_alloc_resource_any(sc->mfi_dev, SYS_RES_IRQ,
358 	    &sc->mfi_irq_rid, RF_SHAREABLE | RF_ACTIVE)) == NULL) {
359 		device_printf(sc->mfi_dev, "Cannot allocate interrupt\n");
360 		return (EINVAL);
361 	}
362 	if (bus_setup_intr(sc->mfi_dev, sc->mfi_irq, INTR_MPSAFE|INTR_TYPE_BIO,
363 	    NULL, mfi_intr, sc, &sc->mfi_intr)) {
364 		device_printf(sc->mfi_dev, "Cannot set up interrupt\n");
365 		return (EINVAL);
366 	}
367 
368 	/* Register a config hook to probe the bus for arrays */
369 	sc->mfi_ich.ich_func = mfi_startup;
370 	sc->mfi_ich.ich_arg = sc;
371 	if (config_intrhook_establish(&sc->mfi_ich) != 0) {
372 		device_printf(sc->mfi_dev, "Cannot establish configuration "
373 		    "hook\n");
374 		return (EINVAL);
375 	}
376 
377 	/*
378 	 * Register a shutdown handler.
379 	 */
380 	if ((sc->mfi_eh = EVENTHANDLER_REGISTER(shutdown_final, mfi_shutdown,
381 	    sc, SHUTDOWN_PRI_DEFAULT)) == NULL) {
382 		device_printf(sc->mfi_dev, "Warning: shutdown event "
383 		    "registration failed\n");
384 	}
385 
386 	/*
387 	 * Create the control device for doing management
388 	 */
389 	unit = device_get_unit(sc->mfi_dev);
390 	sc->mfi_cdev = make_dev(&mfi_cdevsw, unit, UID_ROOT, GID_OPERATOR,
391 	    0640, "mfi%d", unit);
392 	if (unit == 0)
393 		make_dev_alias(sc->mfi_cdev, "megaraid_sas_ioctl_node");
394 	if (sc->mfi_cdev != NULL)
395 		sc->mfi_cdev->si_drv1 = sc;
396 
397 	device_add_child(sc->mfi_dev, "mfip", -1);
398 	bus_generic_attach(sc->mfi_dev);
399 
400 	/* Start the timeout watchdog */
401 	callout_init(&sc->mfi_watchdog_callout, 1);
402 	callout_reset(&sc->mfi_watchdog_callout, MFI_CMD_TIMEOUT * hz,
403 	    mfi_timeout, sc);
404 
405 	return (0);
406 }
407 
408 static int
409 mfi_alloc_commands(struct mfi_softc *sc)
410 {
411 	struct mfi_command *cm;
412 	int i, ncmds;
413 
414 	/*
415 	 * XXX Should we allocate all the commands up front, or allocate on
416 	 * demand later like 'aac' does?
417 	 */
418 	ncmds = sc->mfi_max_fw_cmds;
419 	sc->mfi_commands = malloc(sizeof(struct mfi_command) * ncmds, M_MFIBUF,
420 	    M_WAITOK | M_ZERO);
421 
422 	for (i = 0; i < ncmds; i++) {
423 		cm = &sc->mfi_commands[i];
424 		cm->cm_frame = (union mfi_frame *)((uintptr_t)sc->mfi_frames +
425 		    sc->mfi_cmd_size * i);
426 		cm->cm_frame_busaddr = sc->mfi_frames_busaddr +
427 		    sc->mfi_cmd_size * i;
428 		cm->cm_frame->header.context = i;
429 		cm->cm_sense = &sc->mfi_sense[i];
430 		cm->cm_sense_busaddr= sc->mfi_sense_busaddr + MFI_SENSE_LEN * i;
431 		cm->cm_sc = sc;
432 		cm->cm_index = i;
433 		if (bus_dmamap_create(sc->mfi_buffer_dmat, 0,
434 		    &cm->cm_dmamap) == 0)
435 			mfi_release_command(cm);
436 		else
437 			break;
438 		sc->mfi_total_cmds++;
439 	}
440 
441 	return (0);
442 }
443 
444 void
445 mfi_release_command(struct mfi_command *cm)
446 {
447 	struct mfi_frame_header *hdr;
448 	uint32_t *hdr_data;
449 
450 	/*
451 	 * Zero out the important fields of the frame, but make sure the
452 	 * context field is preserved.  For efficiency, handle the fields
453 	 * as 32 bit words.  Clear out the first S/G entry too for safety.
454 	 */
455 	hdr = &cm->cm_frame->header;
456 	if (hdr->sg_count) {
457 		cm->cm_sg->sg32[0].len = 0;
458 		cm->cm_sg->sg32[0].addr = 0;
459 	}
460 
461 	hdr_data = (uint32_t *)cm->cm_frame;
462 	hdr_data[0] = 0;	/* cmd, sense_len, cmd_status, scsi_status */
463 	hdr_data[1] = 0;	/* target_id, lun_id, cdb_len, sg_count */
464 	hdr_data[4] = 0;	/* flags, timeout */
465 	hdr_data[5] = 0;	/* data_len */
466 
467 	cm->cm_extra_frames = 0;
468 	cm->cm_flags = 0;
469 	cm->cm_complete = NULL;
470 	cm->cm_private = NULL;
471 	cm->cm_data = NULL;
472 	cm->cm_sg = 0;
473 	cm->cm_total_frame_size = 0;
474 
475 	mfi_enqueue_free(cm);
476 }
477 
478 static int
479 mfi_dcmd_command(struct mfi_softc *sc, struct mfi_command **cmp, uint32_t opcode,
480     void **bufp, size_t bufsize)
481 {
482 	struct mfi_command *cm;
483 	struct mfi_dcmd_frame *dcmd;
484 	void *buf = NULL;
485 
486 	mtx_assert(&sc->mfi_io_lock, MA_OWNED);
487 
488 	cm = mfi_dequeue_free(sc);
489 	if (cm == NULL)
490 		return (EBUSY);
491 
492 	if ((bufsize > 0) && (bufp != NULL)) {
493 		if (*bufp == NULL) {
494 			buf = malloc(bufsize, M_MFIBUF, M_NOWAIT|M_ZERO);
495 			if (buf == NULL) {
496 				mfi_release_command(cm);
497 				return (ENOMEM);
498 			}
499 			*bufp = buf;
500 		} else {
501 			buf = *bufp;
502 		}
503 	}
504 
505 	dcmd =  &cm->cm_frame->dcmd;
506 	bzero(dcmd->mbox, MFI_MBOX_SIZE);
507 	dcmd->header.cmd = MFI_CMD_DCMD;
508 	dcmd->header.timeout = 0;
509 	dcmd->header.flags = 0;
510 	dcmd->header.data_len = bufsize;
511 	dcmd->opcode = opcode;
512 	cm->cm_sg = &dcmd->sgl;
513 	cm->cm_total_frame_size = MFI_DCMD_FRAME_SIZE;
514 	cm->cm_flags = 0;
515 	cm->cm_data = buf;
516 	cm->cm_private = buf;
517 	cm->cm_len = bufsize;
518 
519 	*cmp = cm;
520 	if ((bufp != NULL) && (*bufp == NULL) && (buf != NULL))
521 		*bufp = buf;
522 	return (0);
523 }
524 
525 static int
526 mfi_comms_init(struct mfi_softc *sc)
527 {
528 	struct mfi_command *cm;
529 	struct mfi_init_frame *init;
530 	struct mfi_init_qinfo *qinfo;
531 	int error;
532 
533 	mtx_lock(&sc->mfi_io_lock);
534 	if ((cm = mfi_dequeue_free(sc)) == NULL)
535 		return (EBUSY);
536 
537 	/*
538 	 * Abuse the SG list area of the frame to hold the init_qinfo
539 	 * object;
540 	 */
541 	init = &cm->cm_frame->init;
542 	qinfo = (struct mfi_init_qinfo *)((uintptr_t)init + MFI_FRAME_SIZE);
543 
544 	bzero(qinfo, sizeof(struct mfi_init_qinfo));
545 	qinfo->rq_entries = sc->mfi_max_fw_cmds + 1;
546 	qinfo->rq_addr_lo = sc->mfi_comms_busaddr +
547 	    offsetof(struct mfi_hwcomms, hw_reply_q);
548 	qinfo->pi_addr_lo = sc->mfi_comms_busaddr +
549 	    offsetof(struct mfi_hwcomms, hw_pi);
550 	qinfo->ci_addr_lo = sc->mfi_comms_busaddr +
551 	    offsetof(struct mfi_hwcomms, hw_ci);
552 
553 	init->header.cmd = MFI_CMD_INIT;
554 	init->header.data_len = sizeof(struct mfi_init_qinfo);
555 	init->qinfo_new_addr_lo = cm->cm_frame_busaddr + MFI_FRAME_SIZE;
556 	cm->cm_data = NULL;
557 	cm->cm_flags = MFI_CMD_POLLED;
558 
559 	if ((error = mfi_mapcmd(sc, cm)) != 0) {
560 		device_printf(sc->mfi_dev, "failed to send init command\n");
561 		mtx_unlock(&sc->mfi_io_lock);
562 		return (error);
563 	}
564 	mfi_release_command(cm);
565 	mtx_unlock(&sc->mfi_io_lock);
566 
567 	return (0);
568 }
569 
570 static int
571 mfi_get_controller_info(struct mfi_softc *sc)
572 {
573 	struct mfi_command *cm = NULL;
574 	struct mfi_ctrl_info *ci = NULL;
575 	uint32_t max_sectors_1, max_sectors_2;
576 	int error;
577 
578 	mtx_lock(&sc->mfi_io_lock);
579 	error = mfi_dcmd_command(sc, &cm, MFI_DCMD_CTRL_GETINFO,
580 	    (void **)&ci, sizeof(*ci));
581 	if (error)
582 		goto out;
583 	cm->cm_flags = MFI_CMD_DATAIN | MFI_CMD_POLLED;
584 
585 	if ((error = mfi_mapcmd(sc, cm)) != 0) {
586 		device_printf(sc->mfi_dev, "Failed to get controller info\n");
587 		sc->mfi_max_io = (sc->mfi_max_sge - 1) * PAGE_SIZE /
588 		    MFI_SECTOR_LEN;
589 		error = 0;
590 		goto out;
591 	}
592 
593 	bus_dmamap_sync(sc->mfi_buffer_dmat, cm->cm_dmamap,
594 	    BUS_DMASYNC_POSTREAD);
595 	bus_dmamap_unload(sc->mfi_buffer_dmat, cm->cm_dmamap);
596 
597 	max_sectors_1 = (1 << ci->stripe_sz_ops.min) * ci->max_strips_per_io;
598 	max_sectors_2 = ci->max_request_size;
599 	sc->mfi_max_io = min(max_sectors_1, max_sectors_2);
600 
601 out:
602 	if (ci)
603 		free(ci, M_MFIBUF);
604 	if (cm)
605 		mfi_release_command(cm);
606 	mtx_unlock(&sc->mfi_io_lock);
607 	return (error);
608 }
609 
610 static int
611 mfi_get_log_state(struct mfi_softc *sc, struct mfi_evt_log_state **log_state)
612 {
613 	struct mfi_command *cm = NULL;
614 	int error;
615 
616 	error = mfi_dcmd_command(sc, &cm, MFI_DCMD_CTRL_EVENT_GETINFO,
617 	    (void **)log_state, sizeof(**log_state));
618 	if (error)
619 		goto out;
620 	cm->cm_flags = MFI_CMD_DATAIN | MFI_CMD_POLLED;
621 
622 	if ((error = mfi_mapcmd(sc, cm)) != 0) {
623 		device_printf(sc->mfi_dev, "Failed to get log state\n");
624 		goto out;
625 	}
626 
627 	bus_dmamap_sync(sc->mfi_buffer_dmat, cm->cm_dmamap,
628 	    BUS_DMASYNC_POSTREAD);
629 	bus_dmamap_unload(sc->mfi_buffer_dmat, cm->cm_dmamap);
630 
631 out:
632 	if (cm)
633 		mfi_release_command(cm);
634 
635 	return (error);
636 }
637 
638 static int
639 mfi_aen_setup(struct mfi_softc *sc, uint32_t seq_start)
640 {
641 	struct mfi_evt_log_state *log_state = NULL;
642 	union mfi_evt class_locale;
643 	int error = 0;
644 	uint32_t seq;
645 
646 	class_locale.members.reserved = 0;
647 	class_locale.members.locale = mfi_event_locale;
648 	class_locale.members.class  = mfi_event_class;
649 
650 	if (seq_start == 0) {
651 		error = mfi_get_log_state(sc, &log_state);
652 		if (error) {
653 			if (log_state)
654 				free(log_state, M_MFIBUF);
655 			return (error);
656 		}
657 		/*
658 		 * Don't run them yet since we can't parse them.
659 		 * We can indirectly get the contents from
660 		 * the AEN mechanism via setting it lower then
661 		 * current.  The firmware will iterate through them.
662 		 */
663 		for (seq = log_state->shutdown_seq_num;
664 		     seq <= log_state->newest_seq_num; seq++) {
665 			mfi_get_entry(sc, seq);
666 		}
667 	} else
668 		seq = seq_start;
669 	mfi_aen_register(sc, seq, class_locale.word);
670 	free(log_state, M_MFIBUF);
671 
672 	return 0;
673 }
674 
675 static int
676 mfi_wait_command(struct mfi_softc *sc, struct mfi_command *cm)
677 {
678 
679 	mtx_assert(&sc->mfi_io_lock, MA_OWNED);
680 	cm->cm_complete = NULL;
681 
682 	mfi_enqueue_ready(cm);
683 	mfi_startio(sc);
684 	return (msleep(cm, &sc->mfi_io_lock, PRIBIO, "mfiwait", 0));
685 }
686 
687 void
688 mfi_free(struct mfi_softc *sc)
689 {
690 	struct mfi_command *cm;
691 	int i;
692 
693 	callout_drain(&sc->mfi_watchdog_callout);
694 
695 	if (sc->mfi_cdev != NULL)
696 		destroy_dev(sc->mfi_cdev);
697 
698 	if (sc->mfi_total_cmds != 0) {
699 		for (i = 0; i < sc->mfi_total_cmds; i++) {
700 			cm = &sc->mfi_commands[i];
701 			bus_dmamap_destroy(sc->mfi_buffer_dmat, cm->cm_dmamap);
702 		}
703 		free(sc->mfi_commands, M_MFIBUF);
704 	}
705 
706 	if (sc->mfi_intr)
707 		bus_teardown_intr(sc->mfi_dev, sc->mfi_irq, sc->mfi_intr);
708 	if (sc->mfi_irq != NULL)
709 		bus_release_resource(sc->mfi_dev, SYS_RES_IRQ, sc->mfi_irq_rid,
710 		    sc->mfi_irq);
711 
712 	if (sc->mfi_sense_busaddr != 0)
713 		bus_dmamap_unload(sc->mfi_sense_dmat, sc->mfi_sense_dmamap);
714 	if (sc->mfi_sense != NULL)
715 		bus_dmamem_free(sc->mfi_sense_dmat, sc->mfi_sense,
716 		    sc->mfi_sense_dmamap);
717 	if (sc->mfi_sense_dmat != NULL)
718 		bus_dma_tag_destroy(sc->mfi_sense_dmat);
719 
720 	if (sc->mfi_frames_busaddr != 0)
721 		bus_dmamap_unload(sc->mfi_frames_dmat, sc->mfi_frames_dmamap);
722 	if (sc->mfi_frames != NULL)
723 		bus_dmamem_free(sc->mfi_frames_dmat, sc->mfi_frames,
724 		    sc->mfi_frames_dmamap);
725 	if (sc->mfi_frames_dmat != NULL)
726 		bus_dma_tag_destroy(sc->mfi_frames_dmat);
727 
728 	if (sc->mfi_comms_busaddr != 0)
729 		bus_dmamap_unload(sc->mfi_comms_dmat, sc->mfi_comms_dmamap);
730 	if (sc->mfi_comms != NULL)
731 		bus_dmamem_free(sc->mfi_comms_dmat, sc->mfi_comms,
732 		    sc->mfi_comms_dmamap);
733 	if (sc->mfi_comms_dmat != NULL)
734 		bus_dma_tag_destroy(sc->mfi_comms_dmat);
735 
736 	if (sc->mfi_buffer_dmat != NULL)
737 		bus_dma_tag_destroy(sc->mfi_buffer_dmat);
738 	if (sc->mfi_parent_dmat != NULL)
739 		bus_dma_tag_destroy(sc->mfi_parent_dmat);
740 
741 	if (mtx_initialized(&sc->mfi_io_lock))
742 		mtx_destroy(&sc->mfi_io_lock);
743 
744 	return;
745 }
746 
747 static void
748 mfi_startup(void *arg)
749 {
750 	struct mfi_softc *sc;
751 
752 	sc = (struct mfi_softc *)arg;
753 
754 	config_intrhook_disestablish(&sc->mfi_ich);
755 
756 	mfi_enable_intr(sc);
757 	mtx_lock(&sc->mfi_io_lock);
758 	mfi_ldprobe(sc);
759 	mtx_unlock(&sc->mfi_io_lock);
760 }
761 
762 static void
763 mfi_intr(void *arg)
764 {
765 	struct mfi_softc *sc;
766 	struct mfi_command *cm;
767 	uint32_t status, pi, ci, context;
768 
769 	sc = (struct mfi_softc *)arg;
770 
771 	status = MFI_READ4(sc, MFI_OSTS);
772 	if ((status & MFI_OSTS_INTR_VALID) == 0)
773 		return;
774 
775 	MFI_WRITE4(sc, MFI_OSTS, status);
776 
777 	pi = sc->mfi_comms->hw_pi;
778 	ci = sc->mfi_comms->hw_ci;
779 	mtx_lock(&sc->mfi_io_lock);
780 	while (ci != pi) {
781 		context = sc->mfi_comms->hw_reply_q[ci];
782 		cm = &sc->mfi_commands[context];
783 		mfi_remove_busy(cm);
784 		mfi_complete(sc, cm);
785 		if (++ci == (sc->mfi_max_fw_cmds + 1)) {
786 			ci = 0;
787 		}
788 	}
789 
790 	sc->mfi_comms->hw_ci = ci;
791 
792 	/* Give defered I/O a chance to run */
793 	if (sc->mfi_flags & MFI_FLAGS_QFRZN)
794 		sc->mfi_flags &= ~MFI_FLAGS_QFRZN;
795 	mfi_startio(sc);
796 	mtx_unlock(&sc->mfi_io_lock);
797 
798 	return;
799 }
800 
801 int
802 mfi_shutdown(struct mfi_softc *sc)
803 {
804 	struct mfi_dcmd_frame *dcmd;
805 	struct mfi_command *cm;
806 	int error;
807 
808 	mtx_lock(&sc->mfi_io_lock);
809 	error = mfi_dcmd_command(sc, &cm, MFI_DCMD_CTRL_SHUTDOWN, NULL, 0);
810 	if (error) {
811 		mtx_unlock(&sc->mfi_io_lock);
812 		return (error);
813 	}
814 
815 	if (sc->mfi_aen_cm != NULL)
816 		mfi_abort(sc, sc->mfi_aen_cm);
817 
818 	dcmd = &cm->cm_frame->dcmd;
819 	dcmd->header.flags = MFI_FRAME_DIR_NONE;
820 	cm->cm_flags = MFI_CMD_POLLED;
821 	cm->cm_data = NULL;
822 
823 	if ((error = mfi_mapcmd(sc, cm)) != 0) {
824 		device_printf(sc->mfi_dev, "Failed to shutdown controller\n");
825 	}
826 
827 	mfi_release_command(cm);
828 	mtx_unlock(&sc->mfi_io_lock);
829 	return (error);
830 }
831 
832 static void
833 mfi_enable_intr(struct mfi_softc *sc)
834 {
835 
836 	MFI_WRITE4(sc, MFI_OMSK, 0x01);
837 }
838 
839 static void
840 mfi_ldprobe(struct mfi_softc *sc)
841 {
842 	struct mfi_frame_header *hdr;
843 	struct mfi_command *cm = NULL;
844 	struct mfi_ld_list *list = NULL;
845 	int error, i;
846 
847 	mtx_assert(&sc->mfi_io_lock, MA_OWNED);
848 
849 	error = mfi_dcmd_command(sc, &cm, MFI_DCMD_LD_GET_LIST,
850 	    (void **)&list, sizeof(*list));
851 	if (error)
852 		goto out;
853 
854 	cm->cm_flags = MFI_CMD_DATAIN;
855 	if (mfi_wait_command(sc, cm) != 0) {
856 		device_printf(sc->mfi_dev, "Failed to get device listing\n");
857 		goto out;
858 	}
859 
860 	hdr = &cm->cm_frame->header;
861 	if (hdr->cmd_status != MFI_STAT_OK) {
862 		device_printf(sc->mfi_dev, "MFI_DCMD_LD_GET_LIST failed %x\n",
863 		    hdr->cmd_status);
864 		goto out;
865 	}
866 
867 	for (i = 0; i < list->ld_count; i++)
868 		mfi_add_ld(sc, list->ld_list[i].ld.v.target_id);
869 out:
870 	if (list)
871 		free(list, M_MFIBUF);
872 	if (cm)
873 		mfi_release_command(cm);
874 
875 	return;
876 }
877 
878 static void
879 mfi_decode_evt(struct mfi_softc *sc, struct mfi_evt_detail *detail)
880 {
881 	switch (detail->arg_type) {
882 	case MR_EVT_ARGS_NONE:
883 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - %s\n",
884 		    detail->seq,
885 		    detail->time,
886 		    detail->class.members.locale,
887 		    detail->class.members.class,
888 		    detail->description
889 		    );
890 		break;
891 	case MR_EVT_ARGS_CDB_SENSE:
892 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - PD %02d(e%d/s%d) CDB %*D"
893 		    "Sense %*D\n: %s\n",
894 		    detail->seq,
895 		    detail->time,
896 		    detail->class.members.locale,
897 		    detail->class.members.class,
898 		    detail->args.cdb_sense.pd.device_id,
899 		    detail->args.cdb_sense.pd.enclosure_index,
900 		    detail->args.cdb_sense.pd.slot_number,
901 		    detail->args.cdb_sense.cdb_len,
902 		    detail->args.cdb_sense.cdb,
903 		    ":",
904 		    detail->args.cdb_sense.sense_len,
905 		    detail->args.cdb_sense.sense,
906 		    ":",
907 		    detail->description
908 		    );
909 		break;
910 	case MR_EVT_ARGS_LD:
911 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - VD %02d/%d "
912 		    "event: %s\n",
913 		    detail->seq,
914 		    detail->time,
915 		    detail->class.members.locale,
916 		    detail->class.members.class,
917 		    detail->args.ld.ld_index,
918 		    detail->args.ld.target_id,
919 		    detail->description
920 		    );
921 		break;
922 	case MR_EVT_ARGS_LD_COUNT:
923 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - VD %02d/%d "
924 		    "count %lld: %s\n",
925 		    detail->seq,
926 		    detail->time,
927 		    detail->class.members.locale,
928 		    detail->class.members.class,
929 		    detail->args.ld_count.ld.ld_index,
930 		    detail->args.ld_count.ld.target_id,
931 		    (long long)detail->args.ld_count.count,
932 		    detail->description
933 		    );
934 		break;
935 	case MR_EVT_ARGS_LD_LBA:
936 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - VD %02d/%d "
937 		    "lba %lld: %s\n",
938 		    detail->seq,
939 		    detail->time,
940 		    detail->class.members.locale,
941 		    detail->class.members.class,
942 		    detail->args.ld_lba.ld.ld_index,
943 		    detail->args.ld_lba.ld.target_id,
944 		    (long long)detail->args.ld_lba.lba,
945 		    detail->description
946 		    );
947 		break;
948 	case MR_EVT_ARGS_LD_OWNER:
949 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - VD %02d/%d "
950 		    "owner changed: prior %d, new %d: %s\n",
951 		    detail->seq,
952 		    detail->time,
953 		    detail->class.members.locale,
954 		    detail->class.members.class,
955 		    detail->args.ld_owner.ld.ld_index,
956 		    detail->args.ld_owner.ld.target_id,
957 		    detail->args.ld_owner.pre_owner,
958 		    detail->args.ld_owner.new_owner,
959 		    detail->description
960 		    );
961 		break;
962 	case MR_EVT_ARGS_LD_LBA_PD_LBA:
963 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - VD %02d/%d "
964 		    "lba %lld, physical drive PD %02d(e%d/s%d) lba %lld: %s\n",
965 		    detail->seq,
966 		    detail->time,
967 		    detail->class.members.locale,
968 		    detail->class.members.class,
969 		    detail->args.ld_lba_pd_lba.ld.ld_index,
970 		    detail->args.ld_lba_pd_lba.ld.target_id,
971 		    (long long)detail->args.ld_lba_pd_lba.ld_lba,
972 		    detail->args.ld_lba_pd_lba.pd.device_id,
973 		    detail->args.ld_lba_pd_lba.pd.enclosure_index,
974 		    detail->args.ld_lba_pd_lba.pd.slot_number,
975 		    (long long)detail->args.ld_lba_pd_lba.pd_lba,
976 		    detail->description
977 		    );
978 		break;
979 	case MR_EVT_ARGS_LD_PROG:
980 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - VD %02d/%d "
981 		    "progress %d%% in %ds: %s\n",
982 		    detail->seq,
983 		    detail->time,
984 		    detail->class.members.locale,
985 		    detail->class.members.class,
986 		    detail->args.ld_prog.ld.ld_index,
987 		    detail->args.ld_prog.ld.target_id,
988 		    detail->args.ld_prog.prog.progress/655,
989 		    detail->args.ld_prog.prog.elapsed_seconds,
990 		    detail->description
991 		    );
992 		break;
993 	case MR_EVT_ARGS_LD_STATE:
994 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - VD %02d/%d "
995 		    "state prior %d new %d: %s\n",
996 		    detail->seq,
997 		    detail->time,
998 		    detail->class.members.locale,
999 		    detail->class.members.class,
1000 		    detail->args.ld_state.ld.ld_index,
1001 		    detail->args.ld_state.ld.target_id,
1002 		    detail->args.ld_state.prev_state,
1003 		    detail->args.ld_state.new_state,
1004 		    detail->description
1005 		    );
1006 		break;
1007 	case MR_EVT_ARGS_LD_STRIP:
1008 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - VD %02d/%d "
1009 		    "strip %lld: %s\n",
1010 		    detail->seq,
1011 		    detail->time,
1012 		    detail->class.members.locale,
1013 		    detail->class.members.class,
1014 		    detail->args.ld_strip.ld.ld_index,
1015 		    detail->args.ld_strip.ld.target_id,
1016 		    (long long)detail->args.ld_strip.strip,
1017 		    detail->description
1018 		    );
1019 		break;
1020 	case MR_EVT_ARGS_PD:
1021 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - PD %02d(e%d/s%d) "
1022 		    "event: %s\n",
1023 		    detail->seq,
1024 		    detail->time,
1025 		    detail->class.members.locale,
1026 		    detail->class.members.class,
1027 		    detail->args.pd.device_id,
1028 		    detail->args.pd.enclosure_index,
1029 		    detail->args.pd.slot_number,
1030 		    detail->description
1031 		    );
1032 		break;
1033 	case MR_EVT_ARGS_PD_ERR:
1034 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - PD %02d(e%d/s%d) "
1035 		    "err %d: %s\n",
1036 		    detail->seq,
1037 		    detail->time,
1038 		    detail->class.members.locale,
1039 		    detail->class.members.class,
1040 		    detail->args.pd_err.pd.device_id,
1041 		    detail->args.pd_err.pd.enclosure_index,
1042 		    detail->args.pd_err.pd.slot_number,
1043 		    detail->args.pd_err.err,
1044 		    detail->description
1045 		    );
1046 		break;
1047 	case MR_EVT_ARGS_PD_LBA:
1048 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - PD %02d(e%d/s%d) "
1049 		    "lba %lld: %s\n",
1050 		    detail->seq,
1051 		    detail->time,
1052 		    detail->class.members.locale,
1053 		    detail->class.members.class,
1054 		    detail->args.pd_lba.pd.device_id,
1055 		    detail->args.pd_lba.pd.enclosure_index,
1056 		    detail->args.pd_lba.pd.slot_number,
1057 		    (long long)detail->args.pd_lba.lba,
1058 		    detail->description
1059 		    );
1060 		break;
1061 	case MR_EVT_ARGS_PD_LBA_LD:
1062 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - PD %02d(e%d/s%d) "
1063 		    "lba %lld VD %02d/%d: %s\n",
1064 		    detail->seq,
1065 		    detail->time,
1066 		    detail->class.members.locale,
1067 		    detail->class.members.class,
1068 		    detail->args.pd_lba_ld.pd.device_id,
1069 		    detail->args.pd_lba_ld.pd.enclosure_index,
1070 		    detail->args.pd_lba_ld.pd.slot_number,
1071 		    (long long)detail->args.pd_lba.lba,
1072 		    detail->args.pd_lba_ld.ld.ld_index,
1073 		    detail->args.pd_lba_ld.ld.target_id,
1074 		    detail->description
1075 		    );
1076 		break;
1077 	case MR_EVT_ARGS_PD_PROG:
1078 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - PD %02d(e%d/s%d) "
1079 		    "progress %d%% seconds %ds: %s\n",
1080 		    detail->seq,
1081 		    detail->time,
1082 		    detail->class.members.locale,
1083 		    detail->class.members.class,
1084 		    detail->args.pd_prog.pd.device_id,
1085 		    detail->args.pd_prog.pd.enclosure_index,
1086 		    detail->args.pd_prog.pd.slot_number,
1087 		    detail->args.pd_prog.prog.progress/655,
1088 		    detail->args.pd_prog.prog.elapsed_seconds,
1089 		    detail->description
1090 		    );
1091 		break;
1092 	case MR_EVT_ARGS_PD_STATE:
1093 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - PD %02d(e%d/s%d) "
1094 		    "state prior %d new %d: %s\n",
1095 		    detail->seq,
1096 		    detail->time,
1097 		    detail->class.members.locale,
1098 		    detail->class.members.class,
1099 		    detail->args.pd_prog.pd.device_id,
1100 		    detail->args.pd_prog.pd.enclosure_index,
1101 		    detail->args.pd_prog.pd.slot_number,
1102 		    detail->args.pd_state.prev_state,
1103 		    detail->args.pd_state.new_state,
1104 		    detail->description
1105 		    );
1106 		break;
1107 	case MR_EVT_ARGS_PCI:
1108 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - PCI 0x04%x 0x04%x "
1109 		    "0x04%x 0x04%x: %s\n",
1110 		    detail->seq,
1111 		    detail->time,
1112 		    detail->class.members.locale,
1113 		    detail->class.members.class,
1114 		    detail->args.pci.venderId,
1115 		    detail->args.pci.deviceId,
1116 		    detail->args.pci.subVenderId,
1117 		    detail->args.pci.subDeviceId,
1118 		    detail->description
1119 		    );
1120 		break;
1121 	case MR_EVT_ARGS_RATE:
1122 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - Rebuild rate %d: %s\n",
1123 		    detail->seq,
1124 		    detail->time,
1125 		    detail->class.members.locale,
1126 		    detail->class.members.class,
1127 		    detail->args.rate,
1128 		    detail->description
1129 		    );
1130 		break;
1131 	case MR_EVT_ARGS_TIME:
1132 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - Adapter ticks %d "
1133 		    "elapsed %ds: %s\n",
1134 		    detail->seq,
1135 		    detail->time,
1136 		    detail->class.members.locale,
1137 		    detail->class.members.class,
1138 		    detail->args.time.rtc,
1139 		    detail->args.time.elapsedSeconds,
1140 		    detail->description
1141 		    );
1142 		break;
1143 	case MR_EVT_ARGS_ECC:
1144 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - Adapter ECC %x,%x: %s: %s\n",
1145 		    detail->seq,
1146 		    detail->time,
1147 		    detail->class.members.locale,
1148 		    detail->class.members.class,
1149 		    detail->args.ecc.ecar,
1150 		    detail->args.ecc.elog,
1151 		    detail->args.ecc.str,
1152 		    detail->description
1153 		    );
1154 		break;
1155 	default:
1156 		device_printf(sc->mfi_dev, "%d (%us/0x%04x/%d) - Type %d: %s\n",
1157 		    detail->seq,
1158 		    detail->time,
1159 		    detail->class.members.locale,
1160 		    detail->class.members.class,
1161 		    detail->arg_type, detail->description
1162 		    );
1163 	}
1164 }
1165 
1166 static int
1167 mfi_aen_register(struct mfi_softc *sc, int seq, int locale)
1168 {
1169 	struct mfi_command *cm;
1170 	struct mfi_dcmd_frame *dcmd;
1171 	union mfi_evt current_aen, prior_aen;
1172 	struct mfi_evt_detail *ed = NULL;
1173 	int error = 0;
1174 
1175 	current_aen.word = locale;
1176 	if (sc->mfi_aen_cm != NULL) {
1177 		prior_aen.word =
1178 		    ((uint32_t *)&sc->mfi_aen_cm->cm_frame->dcmd.mbox)[1];
1179 		if (prior_aen.members.class <= current_aen.members.class &&
1180 		    !((prior_aen.members.locale & current_aen.members.locale)
1181 		    ^current_aen.members.locale)) {
1182 			return (0);
1183 		} else {
1184 			prior_aen.members.locale |= current_aen.members.locale;
1185 			if (prior_aen.members.class
1186 			    < current_aen.members.class)
1187 				current_aen.members.class =
1188 				    prior_aen.members.class;
1189 			mfi_abort(sc, sc->mfi_aen_cm);
1190 		}
1191 	}
1192 
1193 	error = mfi_dcmd_command(sc, &cm, MFI_DCMD_CTRL_EVENT_WAIT,
1194 	    (void **)&ed, sizeof(*ed));
1195 	if (error) {
1196 		goto out;
1197 	}
1198 
1199 	dcmd = &cm->cm_frame->dcmd;
1200 	((uint32_t *)&dcmd->mbox)[0] = seq;
1201 	((uint32_t *)&dcmd->mbox)[1] = locale;
1202 	cm->cm_flags = MFI_CMD_DATAIN;
1203 	cm->cm_complete = mfi_aen_complete;
1204 
1205 	sc->mfi_aen_cm = cm;
1206 
1207 	mfi_enqueue_ready(cm);
1208 	mfi_startio(sc);
1209 
1210 out:
1211 	return (error);
1212 }
1213 
1214 static void
1215 mfi_aen_complete(struct mfi_command *cm)
1216 {
1217 	struct mfi_frame_header *hdr;
1218 	struct mfi_softc *sc;
1219 	struct mfi_evt_detail *detail;
1220 	struct mfi_aen *mfi_aen_entry, *tmp;
1221 	int seq = 0, aborted = 0;
1222 
1223 	sc = cm->cm_sc;
1224 	hdr = &cm->cm_frame->header;
1225 
1226 	if (sc->mfi_aen_cm == NULL)
1227 		return;
1228 
1229 	if (sc->mfi_aen_cm->cm_aen_abort || hdr->cmd_status == 0xff) {
1230 		sc->mfi_aen_cm->cm_aen_abort = 0;
1231 		aborted = 1;
1232 	} else {
1233 		sc->mfi_aen_triggered = 1;
1234 		if (sc->mfi_poll_waiting) {
1235 			sc->mfi_poll_waiting = 0;
1236 			selwakeup(&sc->mfi_select);
1237 		}
1238 		detail = cm->cm_data;
1239 		/*
1240 		 * XXX If this function is too expensive or is recursive, then
1241 		 * events should be put onto a queue and processed later.
1242 		 */
1243 		mtx_unlock(&sc->mfi_io_lock);
1244 		mfi_decode_evt(sc, detail);
1245 		mtx_lock(&sc->mfi_io_lock);
1246 		seq = detail->seq + 1;
1247 		TAILQ_FOREACH_SAFE(mfi_aen_entry, &sc->mfi_aen_pids, aen_link, tmp) {
1248 			TAILQ_REMOVE(&sc->mfi_aen_pids, mfi_aen_entry,
1249 			    aen_link);
1250 			PROC_LOCK(mfi_aen_entry->p);
1251 			psignal(mfi_aen_entry->p, SIGIO);
1252 			PROC_UNLOCK(mfi_aen_entry->p);
1253 			free(mfi_aen_entry, M_MFIBUF);
1254 		}
1255 	}
1256 
1257 	free(cm->cm_data, M_MFIBUF);
1258 	sc->mfi_aen_cm = NULL;
1259 	wakeup(&sc->mfi_aen_cm);
1260 	mfi_release_command(cm);
1261 
1262 	/* set it up again so the driver can catch more events */
1263 	if (!aborted) {
1264 		mfi_aen_setup(sc, seq);
1265 	}
1266 }
1267 
1268 /* Only do one event for now so we can easily iterate through them */
1269 #define MAX_EVENTS 1
1270 static int
1271 mfi_get_entry(struct mfi_softc *sc, int seq)
1272 {
1273 	struct mfi_command *cm;
1274 	struct mfi_dcmd_frame *dcmd;
1275 	struct mfi_evt_list *el;
1276 	int error;
1277 	int i;
1278 	int size;
1279 
1280 	if ((cm = mfi_dequeue_free(sc)) == NULL) {
1281 		return (EBUSY);
1282 	}
1283 
1284 	size = sizeof(struct mfi_evt_list) + sizeof(struct mfi_evt_detail)
1285 		* (MAX_EVENTS - 1);
1286 	el = malloc(size, M_MFIBUF, M_NOWAIT | M_ZERO);
1287 	if (el == NULL) {
1288 		mfi_release_command(cm);
1289 		return (ENOMEM);
1290 	}
1291 
1292 	dcmd = &cm->cm_frame->dcmd;
1293 	bzero(dcmd->mbox, MFI_MBOX_SIZE);
1294 	dcmd->header.cmd = MFI_CMD_DCMD;
1295 	dcmd->header.timeout = 0;
1296 	dcmd->header.data_len = size;
1297 	dcmd->opcode = MFI_DCMD_CTRL_EVENT_GET;
1298 	((uint32_t *)&dcmd->mbox)[0] = seq;
1299 	((uint32_t *)&dcmd->mbox)[1] = MFI_EVT_LOCALE_ALL;
1300 	cm->cm_sg = &dcmd->sgl;
1301 	cm->cm_total_frame_size = MFI_DCMD_FRAME_SIZE;
1302 	cm->cm_flags = MFI_CMD_DATAIN | MFI_CMD_POLLED;
1303 	cm->cm_data = el;
1304 	cm->cm_len = size;
1305 
1306 	if ((error = mfi_mapcmd(sc, cm)) != 0) {
1307 		device_printf(sc->mfi_dev, "Failed to get controller entry\n");
1308 		sc->mfi_max_io = (sc->mfi_max_sge - 1) * PAGE_SIZE /
1309 		    MFI_SECTOR_LEN;
1310 		free(el, M_MFIBUF);
1311 		mfi_release_command(cm);
1312 		return (0);
1313 	}
1314 
1315 	bus_dmamap_sync(sc->mfi_buffer_dmat, cm->cm_dmamap,
1316 	    BUS_DMASYNC_POSTREAD);
1317 	bus_dmamap_unload(sc->mfi_buffer_dmat, cm->cm_dmamap);
1318 
1319 	if (dcmd->header.cmd_status != MFI_STAT_NOT_FOUND) {
1320 		for (i = 0; i < el->count; i++) {
1321 			if (seq + i == el->event[i].seq)
1322 				mfi_decode_evt(sc, &el->event[i]);
1323 		}
1324 	}
1325 
1326 	free(cm->cm_data, M_MFIBUF);
1327 	mfi_release_command(cm);
1328 	return (0);
1329 }
1330 
1331 static int
1332 mfi_add_ld(struct mfi_softc *sc, int id)
1333 {
1334 	struct mfi_command *cm;
1335 	struct mfi_dcmd_frame *dcmd = NULL;
1336 	struct mfi_ld_info *ld_info = NULL;
1337 	int error;
1338 
1339 	mtx_assert(&sc->mfi_io_lock, MA_OWNED);
1340 
1341 	error = mfi_dcmd_command(sc, &cm, MFI_DCMD_LD_GET_INFO,
1342 	    (void **)&ld_info, sizeof(*ld_info));
1343 	if (error) {
1344 		device_printf(sc->mfi_dev,
1345 		    "Failed to allocate for MFI_DCMD_LD_GET_INFO %d\n", error);
1346 		if (ld_info)
1347 			free(ld_info, M_MFIBUF);
1348 		return (error);
1349 	}
1350 	cm->cm_flags = MFI_CMD_DATAIN;
1351 	dcmd = &cm->cm_frame->dcmd;
1352 	dcmd->mbox[0] = id;
1353 	if (mfi_wait_command(sc, cm) != 0) {
1354 		device_printf(sc->mfi_dev,
1355 		    "Failed to get logical drive: %d\n", id);
1356 		free(ld_info, M_MFIBUF);
1357 		return (0);
1358 	}
1359 
1360 	mfi_add_ld_complete(cm);
1361 	return (0);
1362 }
1363 
1364 static void
1365 mfi_add_ld_complete(struct mfi_command *cm)
1366 {
1367 	struct mfi_frame_header *hdr;
1368 	struct mfi_ld_info *ld_info;
1369 	struct mfi_softc *sc;
1370 	device_t child;
1371 
1372 	sc = cm->cm_sc;
1373 	hdr = &cm->cm_frame->header;
1374 	ld_info = cm->cm_private;
1375 
1376 	if (hdr->cmd_status != MFI_STAT_OK) {
1377 		free(ld_info, M_MFIBUF);
1378 		mfi_release_command(cm);
1379 		return;
1380 	}
1381 	mfi_release_command(cm);
1382 
1383 	mtx_unlock(&sc->mfi_io_lock);
1384 	mtx_lock(&Giant);
1385 	if ((child = device_add_child(sc->mfi_dev, "mfid", -1)) == NULL) {
1386 		device_printf(sc->mfi_dev, "Failed to add logical disk\n");
1387 		free(ld_info, M_MFIBUF);
1388 		mtx_unlock(&Giant);
1389 		mtx_lock(&sc->mfi_io_lock);
1390 		return;
1391 	}
1392 
1393 	device_set_ivars(child, ld_info);
1394 	device_set_desc(child, "MFI Logical Disk");
1395 	bus_generic_attach(sc->mfi_dev);
1396 	mtx_unlock(&Giant);
1397 	mtx_lock(&sc->mfi_io_lock);
1398 }
1399 
1400 static struct mfi_command *
1401 mfi_bio_command(struct mfi_softc *sc)
1402 {
1403 	struct mfi_io_frame *io;
1404 	struct mfi_command *cm;
1405 	struct bio *bio;
1406 	int flags, blkcount;
1407 
1408 	if ((cm = mfi_dequeue_free(sc)) == NULL)
1409 		return (NULL);
1410 
1411 	if ((bio = mfi_dequeue_bio(sc)) == NULL) {
1412 		mfi_release_command(cm);
1413 		return (NULL);
1414 	}
1415 
1416 	io = &cm->cm_frame->io;
1417 	switch (bio->bio_cmd & 0x03) {
1418 	case BIO_READ:
1419 		io->header.cmd = MFI_CMD_LD_READ;
1420 		flags = MFI_CMD_DATAIN;
1421 		break;
1422 	case BIO_WRITE:
1423 		io->header.cmd = MFI_CMD_LD_WRITE;
1424 		flags = MFI_CMD_DATAOUT;
1425 		break;
1426 	default:
1427 		panic("Invalid bio command");
1428 	}
1429 
1430 	/* Cheat with the sector length to avoid a non-constant division */
1431 	blkcount = (bio->bio_bcount + MFI_SECTOR_LEN - 1) / MFI_SECTOR_LEN;
1432 	io->header.target_id = (uintptr_t)bio->bio_driver1;
1433 	io->header.timeout = 0;
1434 	io->header.flags = 0;
1435 	io->header.sense_len = MFI_SENSE_LEN;
1436 	io->header.data_len = blkcount;
1437 	io->sense_addr_lo = cm->cm_sense_busaddr;
1438 	io->sense_addr_hi = 0;
1439 	io->lba_hi = (bio->bio_pblkno & 0xffffffff00000000) >> 32;
1440 	io->lba_lo = bio->bio_pblkno & 0xffffffff;
1441 	cm->cm_complete = mfi_bio_complete;
1442 	cm->cm_private = bio;
1443 	cm->cm_data = bio->bio_data;
1444 	cm->cm_len = bio->bio_bcount;
1445 	cm->cm_sg = &io->sgl;
1446 	cm->cm_total_frame_size = MFI_IO_FRAME_SIZE;
1447 	cm->cm_flags = flags;
1448 	return (cm);
1449 }
1450 
1451 static void
1452 mfi_bio_complete(struct mfi_command *cm)
1453 {
1454 	struct bio *bio;
1455 	struct mfi_frame_header *hdr;
1456 	struct mfi_softc *sc;
1457 
1458 	bio = cm->cm_private;
1459 	hdr = &cm->cm_frame->header;
1460 	sc = cm->cm_sc;
1461 
1462 	if ((hdr->cmd_status != 0) || (hdr->scsi_status != 0)) {
1463 		bio->bio_flags |= BIO_ERROR;
1464 		bio->bio_error = EIO;
1465 		device_printf(sc->mfi_dev, "I/O error, status= %d "
1466 		    "scsi_status= %d\n", hdr->cmd_status, hdr->scsi_status);
1467 		mfi_print_sense(cm->cm_sc, cm->cm_sense);
1468 	}
1469 
1470 	mfi_release_command(cm);
1471 	mfi_disk_complete(bio);
1472 }
1473 
1474 void
1475 mfi_startio(struct mfi_softc *sc)
1476 {
1477 	struct mfi_command *cm;
1478 	struct ccb_hdr *ccbh;
1479 
1480 	for (;;) {
1481 		/* Don't bother if we're short on resources */
1482 		if (sc->mfi_flags & MFI_FLAGS_QFRZN)
1483 			break;
1484 
1485 		/* Try a command that has already been prepared */
1486 		cm = mfi_dequeue_ready(sc);
1487 
1488 		if (cm == NULL) {
1489 			if ((ccbh = TAILQ_FIRST(&sc->mfi_cam_ccbq)) != NULL)
1490 				cm = sc->mfi_cam_start(ccbh);
1491 		}
1492 
1493 		/* Nope, so look for work on the bioq */
1494 		if (cm == NULL)
1495 			cm = mfi_bio_command(sc);
1496 
1497 		/* No work available, so exit */
1498 		if (cm == NULL)
1499 			break;
1500 
1501 		/* Send the command to the controller */
1502 		if (mfi_mapcmd(sc, cm) != 0) {
1503 			mfi_requeue_ready(cm);
1504 			break;
1505 		}
1506 	}
1507 }
1508 
1509 static int
1510 mfi_mapcmd(struct mfi_softc *sc, struct mfi_command *cm)
1511 {
1512 	int error, polled;
1513 
1514 	mtx_assert(&sc->mfi_io_lock, MA_OWNED);
1515 
1516 	if (cm->cm_data != NULL) {
1517 		polled = (cm->cm_flags & MFI_CMD_POLLED) ? BUS_DMA_NOWAIT : 0;
1518 		error = bus_dmamap_load(sc->mfi_buffer_dmat, cm->cm_dmamap,
1519 		    cm->cm_data, cm->cm_len, mfi_data_cb, cm, polled);
1520 		if (error == EINPROGRESS) {
1521 			sc->mfi_flags |= MFI_FLAGS_QFRZN;
1522 			return (0);
1523 		}
1524 	} else {
1525 		error = mfi_send_frame(sc, cm);
1526 	}
1527 
1528 	return (error);
1529 }
1530 
1531 static void
1532 mfi_data_cb(void *arg, bus_dma_segment_t *segs, int nsegs, int error)
1533 {
1534 	struct mfi_frame_header *hdr;
1535 	struct mfi_command *cm;
1536 	union mfi_sgl *sgl;
1537 	struct mfi_softc *sc;
1538 	int i, dir;
1539 
1540 	if (error)
1541 		return;
1542 
1543 	cm = (struct mfi_command *)arg;
1544 	sc = cm->cm_sc;
1545 	hdr = &cm->cm_frame->header;
1546 	sgl = cm->cm_sg;
1547 
1548 	if ((sc->mfi_flags & MFI_FLAGS_SG64) == 0) {
1549 		for (i = 0; i < nsegs; i++) {
1550 			sgl->sg32[i].addr = segs[i].ds_addr;
1551 			sgl->sg32[i].len = segs[i].ds_len;
1552 		}
1553 	} else {
1554 		for (i = 0; i < nsegs; i++) {
1555 			sgl->sg64[i].addr = segs[i].ds_addr;
1556 			sgl->sg64[i].len = segs[i].ds_len;
1557 		}
1558 		hdr->flags |= MFI_FRAME_SGL64;
1559 	}
1560 	hdr->sg_count = nsegs;
1561 
1562 	dir = 0;
1563 	if (cm->cm_flags & MFI_CMD_DATAIN) {
1564 		dir |= BUS_DMASYNC_PREREAD;
1565 		hdr->flags |= MFI_FRAME_DIR_READ;
1566 	}
1567 	if (cm->cm_flags & MFI_CMD_DATAOUT) {
1568 		dir |= BUS_DMASYNC_PREWRITE;
1569 		hdr->flags |= MFI_FRAME_DIR_WRITE;
1570 	}
1571 	bus_dmamap_sync(sc->mfi_buffer_dmat, cm->cm_dmamap, dir);
1572 	cm->cm_flags |= MFI_CMD_MAPPED;
1573 
1574 	/*
1575 	 * Instead of calculating the total number of frames in the
1576 	 * compound frame, it's already assumed that there will be at
1577 	 * least 1 frame, so don't compensate for the modulo of the
1578 	 * following division.
1579 	 */
1580 	cm->cm_total_frame_size += (sc->mfi_sge_size * nsegs);
1581 	cm->cm_extra_frames = (cm->cm_total_frame_size - 1) / MFI_FRAME_SIZE;
1582 
1583 	mfi_send_frame(sc, cm);
1584 
1585 	return;
1586 }
1587 
1588 static int
1589 mfi_send_frame(struct mfi_softc *sc, struct mfi_command *cm)
1590 {
1591 	struct mfi_frame_header *hdr;
1592 	int tm = MFI_POLL_TIMEOUT_SECS * 1000;
1593 
1594 	hdr = &cm->cm_frame->header;
1595 
1596 	if ((cm->cm_flags & MFI_CMD_POLLED) == 0) {
1597 		cm->cm_timestamp = time_uptime;
1598 		mfi_enqueue_busy(cm);
1599 	} else {
1600 		hdr->cmd_status = 0xff;
1601 		hdr->flags |= MFI_FRAME_DONT_POST_IN_REPLY_QUEUE;
1602 	}
1603 
1604 	/*
1605 	 * The bus address of the command is aligned on a 64 byte boundary,
1606 	 * leaving the least 6 bits as zero.  For whatever reason, the
1607 	 * hardware wants the address shifted right by three, leaving just
1608 	 * 3 zero bits.  These three bits are then used as a prefetching
1609 	 * hint for the hardware to predict how many frames need to be
1610 	 * fetched across the bus.  If a command has more than 8 frames
1611 	 * then the 3 bits are set to 0x7 and the firmware uses other
1612 	 * information in the command to determine the total amount to fetch.
1613 	 * However, FreeBSD doesn't support I/O larger than 128K, so 8 frames
1614 	 * is enough for both 32bit and 64bit systems.
1615 	 */
1616 	if (cm->cm_extra_frames > 7)
1617 		cm->cm_extra_frames = 7;
1618 
1619 	MFI_WRITE4(sc, MFI_IQP, (cm->cm_frame_busaddr >> 3) |
1620 	    cm->cm_extra_frames);
1621 
1622 	if ((cm->cm_flags & MFI_CMD_POLLED) == 0)
1623 		return (0);
1624 
1625 	/* This is a polled command, so busy-wait for it to complete. */
1626 	while (hdr->cmd_status == 0xff) {
1627 		DELAY(1000);
1628 		tm -= 1;
1629 		if (tm <= 0)
1630 			break;
1631 	}
1632 
1633 	if (hdr->cmd_status == 0xff) {
1634 		device_printf(sc->mfi_dev, "Frame %p timed out "
1635 			      "command 0x%X\n", hdr, cm->cm_frame->dcmd.opcode);
1636 		return (ETIMEDOUT);
1637 	}
1638 
1639 	return (0);
1640 }
1641 
1642 static void
1643 mfi_complete(struct mfi_softc *sc, struct mfi_command *cm)
1644 {
1645 	int dir;
1646 
1647 	if ((cm->cm_flags & MFI_CMD_MAPPED) != 0) {
1648 		dir = 0;
1649 		if (cm->cm_flags & MFI_CMD_DATAIN)
1650 			dir |= BUS_DMASYNC_POSTREAD;
1651 		if (cm->cm_flags & MFI_CMD_DATAOUT)
1652 			dir |= BUS_DMASYNC_POSTWRITE;
1653 
1654 		bus_dmamap_sync(sc->mfi_buffer_dmat, cm->cm_dmamap, dir);
1655 		bus_dmamap_unload(sc->mfi_buffer_dmat, cm->cm_dmamap);
1656 		cm->cm_flags &= ~MFI_CMD_MAPPED;
1657 	}
1658 
1659 	if (cm->cm_complete != NULL)
1660 		cm->cm_complete(cm);
1661 	else
1662 		wakeup(cm);
1663 }
1664 
1665 static int
1666 mfi_abort(struct mfi_softc *sc, struct mfi_command *cm_abort)
1667 {
1668 	struct mfi_command *cm;
1669 	struct mfi_abort_frame *abort;
1670 	int i = 0;
1671 
1672 	mtx_assert(&sc->mfi_io_lock, MA_OWNED);
1673 
1674 	if ((cm = mfi_dequeue_free(sc)) == NULL) {
1675 		return (EBUSY);
1676 	}
1677 
1678 	abort = &cm->cm_frame->abort;
1679 	abort->header.cmd = MFI_CMD_ABORT;
1680 	abort->header.flags = 0;
1681 	abort->abort_context = cm_abort->cm_frame->header.context;
1682 	abort->abort_mfi_addr_lo = cm_abort->cm_frame_busaddr;
1683 	abort->abort_mfi_addr_hi = 0;
1684 	cm->cm_data = NULL;
1685 	cm->cm_flags = MFI_CMD_POLLED;
1686 
1687 	sc->mfi_aen_cm->cm_aen_abort = 1;
1688 	mfi_mapcmd(sc, cm);
1689 	mfi_release_command(cm);
1690 
1691 	while (i < 5 && sc->mfi_aen_cm != NULL) {
1692 		msleep(&sc->mfi_aen_cm, &sc->mfi_io_lock, 0, "mfiabort", 5 * hz);
1693 		i++;
1694 	}
1695 
1696 	return (0);
1697 }
1698 
1699 int
1700 mfi_dump_blocks(struct mfi_softc *sc, int id, uint64_t lba, void *virt, int len)
1701 {
1702 	struct mfi_command *cm;
1703 	struct mfi_io_frame *io;
1704 	int error;
1705 
1706 	if ((cm = mfi_dequeue_free(sc)) == NULL)
1707 		return (EBUSY);
1708 
1709 	io = &cm->cm_frame->io;
1710 	io->header.cmd = MFI_CMD_LD_WRITE;
1711 	io->header.target_id = id;
1712 	io->header.timeout = 0;
1713 	io->header.flags = 0;
1714 	io->header.sense_len = MFI_SENSE_LEN;
1715 	io->header.data_len = (len + MFI_SECTOR_LEN - 1) / MFI_SECTOR_LEN;
1716 	io->sense_addr_lo = cm->cm_sense_busaddr;
1717 	io->sense_addr_hi = 0;
1718 	io->lba_hi = (lba & 0xffffffff00000000) >> 32;
1719 	io->lba_lo = lba & 0xffffffff;
1720 	cm->cm_data = virt;
1721 	cm->cm_len = len;
1722 	cm->cm_sg = &io->sgl;
1723 	cm->cm_total_frame_size = MFI_IO_FRAME_SIZE;
1724 	cm->cm_flags = MFI_CMD_POLLED | MFI_CMD_DATAOUT;
1725 
1726 	error = mfi_mapcmd(sc, cm);
1727 	bus_dmamap_sync(sc->mfi_buffer_dmat, cm->cm_dmamap,
1728 	    BUS_DMASYNC_POSTWRITE);
1729 	bus_dmamap_unload(sc->mfi_buffer_dmat, cm->cm_dmamap);
1730 	mfi_release_command(cm);
1731 
1732 	return (error);
1733 }
1734 
1735 static int
1736 mfi_open(struct cdev *dev, int flags, int fmt, d_thread_t *td)
1737 {
1738 	struct mfi_softc *sc;
1739 
1740 	sc = dev->si_drv1;
1741 
1742 	mtx_lock(&sc->mfi_io_lock);
1743 	sc->mfi_flags |= MFI_FLAGS_OPEN;
1744 	mtx_unlock(&sc->mfi_io_lock);
1745 
1746 	return (0);
1747 }
1748 
1749 static int
1750 mfi_close(struct cdev *dev, int flags, int fmt, d_thread_t *td)
1751 {
1752 	struct mfi_softc *sc;
1753 	struct mfi_aen *mfi_aen_entry, *tmp;
1754 
1755 	sc = dev->si_drv1;
1756 
1757 	mtx_lock(&sc->mfi_io_lock);
1758 	sc->mfi_flags &= ~MFI_FLAGS_OPEN;
1759 
1760 	TAILQ_FOREACH_SAFE(mfi_aen_entry, &sc->mfi_aen_pids, aen_link, tmp) {
1761 		if (mfi_aen_entry->p == curproc) {
1762 			TAILQ_REMOVE(&sc->mfi_aen_pids, mfi_aen_entry,
1763 			    aen_link);
1764 			free(mfi_aen_entry, M_MFIBUF);
1765 		}
1766 	}
1767 	mtx_unlock(&sc->mfi_io_lock);
1768 	return (0);
1769 }
1770 
1771 static int
1772 mfi_ioctl(struct cdev *dev, u_long cmd, caddr_t arg, int flag, d_thread_t *td)
1773 {
1774 	struct mfi_softc *sc;
1775 	union mfi_statrequest *ms;
1776 	struct mfi_ioc_packet *ioc;
1777 	struct mfi_ioc_aen *aen;
1778 	struct mfi_command *cm = NULL;
1779 	uint32_t context;
1780 	uint8_t *sense_ptr;
1781 	uint8_t *data = NULL, *temp;
1782 	int i;
1783 	int error;
1784 
1785 	sc = dev->si_drv1;
1786 	error = 0;
1787 
1788 	switch (cmd) {
1789 	case MFIIO_STATS:
1790 		ms = (union mfi_statrequest *)arg;
1791 		switch (ms->ms_item) {
1792 		case MFIQ_FREE:
1793 		case MFIQ_BIO:
1794 		case MFIQ_READY:
1795 		case MFIQ_BUSY:
1796 			bcopy(&sc->mfi_qstat[ms->ms_item], &ms->ms_qstat,
1797 			    sizeof(struct mfi_qstat));
1798 			break;
1799 		default:
1800 			error = ENOIOCTL;
1801 			break;
1802 		}
1803 		break;
1804 	case MFIIO_QUERY_DISK:
1805 	{
1806 		struct mfi_query_disk *qd;
1807 		struct mfi_disk *ld;
1808 
1809 		qd = (struct mfi_query_disk *)arg;
1810 		mtx_lock(&sc->mfi_io_lock);
1811 		TAILQ_FOREACH(ld, &sc->mfi_ld_tqh, ld_link) {
1812 			if (ld->ld_id == qd->array_id)
1813 				break;
1814 		}
1815 		if (ld == NULL) {
1816 			qd->present = 0;
1817 			mtx_unlock(&sc->mfi_io_lock);
1818 			return (0);
1819 		}
1820 		qd->present = 1;
1821 		if (ld->ld_flags & MFI_DISK_FLAGS_OPEN)
1822 			qd->open = 1;
1823 		bzero(qd->devname, SPECNAMELEN + 1);
1824 		snprintf(qd->devname, SPECNAMELEN, "mfid%d", ld->ld_unit);
1825 		mtx_unlock(&sc->mfi_io_lock);
1826 		break;
1827 	}
1828 	case MFI_CMD:
1829 		ioc = (struct mfi_ioc_packet *)arg;
1830 
1831 		mtx_lock(&sc->mfi_io_lock);
1832 		if ((cm = mfi_dequeue_free(sc)) == NULL) {
1833 			mtx_unlock(&sc->mfi_io_lock);
1834 			return (EBUSY);
1835 		}
1836 		mtx_unlock(&sc->mfi_io_lock);
1837 
1838 		/*
1839 		 * save off original context since copying from user
1840 		 * will clobber some data
1841 		 */
1842 		context = cm->cm_frame->header.context;
1843 
1844 		bcopy(ioc->mfi_frame.raw, cm->cm_frame,
1845 		      ioc->mfi_sgl_off); /* Linux can do 2 frames ? */
1846 		cm->cm_total_frame_size = ioc->mfi_sgl_off;
1847 		cm->cm_sg =
1848 		    (union mfi_sgl *)&cm->cm_frame->bytes[ioc->mfi_sgl_off];
1849 		cm->cm_flags = MFI_CMD_DATAIN | MFI_CMD_DATAOUT
1850 			| MFI_CMD_POLLED;
1851 		cm->cm_len = cm->cm_frame->header.data_len;
1852 		cm->cm_data = data = malloc(cm->cm_len, M_MFIBUF,
1853 					    M_WAITOK | M_ZERO);
1854 		if (cm->cm_data == NULL) {
1855 			device_printf(sc->mfi_dev, "Malloc failed\n");
1856 			goto out;
1857 		}
1858 
1859 		/* restore header context */
1860 		cm->cm_frame->header.context = context;
1861 
1862 		temp = data;
1863 		for (i = 0; i < ioc->mfi_sge_count; i++) {
1864 			error = copyin(ioc->mfi_sgl[i].iov_base,
1865 			       temp,
1866 			       ioc->mfi_sgl[i].iov_len);
1867 			if (error != 0) {
1868 				device_printf(sc->mfi_dev,
1869 				    "Copy in failed\n");
1870 				goto out;
1871 			}
1872 			temp = &temp[ioc->mfi_sgl[i].iov_len];
1873 		}
1874 
1875 		mtx_lock(&sc->mfi_io_lock);
1876 		if ((error = mfi_mapcmd(sc, cm)) != 0) {
1877 			device_printf(sc->mfi_dev,
1878 			    "Controller polled failed\n");
1879 			mtx_unlock(&sc->mfi_io_lock);
1880 			goto out;
1881 		}
1882 
1883 		bus_dmamap_sync(sc->mfi_buffer_dmat, cm->cm_dmamap,
1884 				BUS_DMASYNC_POSTREAD);
1885 		bus_dmamap_unload(sc->mfi_buffer_dmat, cm->cm_dmamap);
1886 		mtx_unlock(&sc->mfi_io_lock);
1887 
1888 		temp = data;
1889 		for (i = 0; i < ioc->mfi_sge_count; i++) {
1890 			error = copyout(temp,
1891 				ioc->mfi_sgl[i].iov_base,
1892 				ioc->mfi_sgl[i].iov_len);
1893 			if (error != 0) {
1894 				device_printf(sc->mfi_dev,
1895 				    "Copy out failed\n");
1896 				goto out;
1897 			}
1898 			temp = &temp[ioc->mfi_sgl[i].iov_len];
1899 		}
1900 
1901 		if (ioc->mfi_sense_len) {
1902 			/* copy out sense */
1903 			sense_ptr = &((struct mfi_ioc_packet*)arg)
1904 			    ->mfi_frame.raw[0];
1905 			error = copyout(cm->cm_sense, sense_ptr,
1906 			    ioc->mfi_sense_len);
1907 			if (error != 0) {
1908 				device_printf(sc->mfi_dev,
1909 				    "Copy out failed\n");
1910 				goto out;
1911 			}
1912 		}
1913 
1914 		ioc->mfi_frame.hdr.cmd_status = cm->cm_frame->header.cmd_status;
1915 		if (cm->cm_frame->header.cmd_status == MFI_STAT_OK) {
1916 			switch (cm->cm_frame->dcmd.opcode) {
1917 			case MFI_DCMD_CFG_CLEAR:
1918 			case MFI_DCMD_CFG_ADD:
1919 /*
1920 				mfi_ldrescan(sc);
1921 */
1922 				break;
1923 			}
1924 		}
1925 out:
1926 		if (data)
1927 			free(data, M_MFIBUF);
1928 		if (cm) {
1929 			mtx_lock(&sc->mfi_io_lock);
1930 			mfi_release_command(cm);
1931 			mtx_unlock(&sc->mfi_io_lock);
1932 		}
1933 
1934 		break;
1935 	case MFI_SET_AEN:
1936 		aen = (struct mfi_ioc_aen *)arg;
1937 		error = mfi_aen_register(sc, aen->aen_seq_num,
1938 		    aen->aen_class_locale);
1939 
1940 		break;
1941 	case MFI_LINUX_CMD_2: /* Firmware Linux ioctl shim */
1942 		{
1943 			devclass_t devclass;
1944 			struct mfi_linux_ioc_packet l_ioc;
1945 			int adapter;
1946 
1947 			devclass = devclass_find("mfi");
1948 			if (devclass == NULL)
1949 				return (ENOENT);
1950 
1951 			error = copyin(arg, &l_ioc, sizeof(l_ioc));
1952 			if (error)
1953 				return (error);
1954 			adapter = l_ioc.lioc_adapter_no;
1955 			sc = devclass_get_softc(devclass, adapter);
1956 			if (sc == NULL)
1957 				return (ENOENT);
1958 			return (mfi_linux_ioctl_int(sc->mfi_cdev,
1959 			    cmd, arg, flag, td));
1960 			break;
1961 		}
1962 	case MFI_LINUX_SET_AEN_2: /* AEN Linux ioctl shim */
1963 		{
1964 			devclass_t devclass;
1965 			struct mfi_linux_ioc_aen l_aen;
1966 			int adapter;
1967 
1968 			devclass = devclass_find("mfi");
1969 			if (devclass == NULL)
1970 				return (ENOENT);
1971 
1972 			error = copyin(arg, &l_aen, sizeof(l_aen));
1973 			if (error)
1974 				return (error);
1975 			adapter = l_aen.laen_adapter_no;
1976 			sc = devclass_get_softc(devclass, adapter);
1977 			if (sc == NULL)
1978 				return (ENOENT);
1979 			return (mfi_linux_ioctl_int(sc->mfi_cdev,
1980 			    cmd, arg, flag, td));
1981 			break;
1982 		}
1983 	default:
1984 		device_printf(sc->mfi_dev, "IOCTL 0x%lx not handled\n", cmd);
1985 		error = ENOENT;
1986 		break;
1987 	}
1988 
1989 	return (error);
1990 }
1991 
1992 static int
1993 mfi_linux_ioctl_int(struct cdev *dev, u_long cmd, caddr_t arg, int flag, d_thread_t *td)
1994 {
1995 	struct mfi_softc *sc;
1996 	struct mfi_linux_ioc_packet l_ioc;
1997 	struct mfi_linux_ioc_aen l_aen;
1998 	struct mfi_command *cm = NULL;
1999 	struct mfi_aen *mfi_aen_entry;
2000 	uint8_t *sense_ptr;
2001 	uint32_t context;
2002 	uint8_t *data = NULL, *temp;
2003 	void *temp_convert;
2004 	int i;
2005 	int error;
2006 
2007 	sc = dev->si_drv1;
2008 	error = 0;
2009 	switch (cmd) {
2010 	case MFI_LINUX_CMD_2: /* Firmware Linux ioctl shim */
2011 		error = copyin(arg, &l_ioc, sizeof(l_ioc));
2012 		if (error != 0)
2013 			return (error);
2014 
2015 		if (l_ioc.lioc_sge_count > MAX_LINUX_IOCTL_SGE) {
2016 			return (EINVAL);
2017 		}
2018 
2019 		mtx_lock(&sc->mfi_io_lock);
2020 		if ((cm = mfi_dequeue_free(sc)) == NULL) {
2021 			mtx_unlock(&sc->mfi_io_lock);
2022 			return (EBUSY);
2023 		}
2024 		mtx_unlock(&sc->mfi_io_lock);
2025 
2026 		/*
2027 		 * save off original context since copying from user
2028 		 * will clobber some data
2029 		 */
2030 		context = cm->cm_frame->header.context;
2031 
2032 		bcopy(l_ioc.lioc_frame.raw, cm->cm_frame,
2033 		      l_ioc.lioc_sgl_off); /* Linux can do 2 frames ? */
2034 		cm->cm_total_frame_size = l_ioc.lioc_sgl_off;
2035 		cm->cm_sg =
2036 		    (union mfi_sgl *)&cm->cm_frame->bytes[l_ioc.lioc_sgl_off];
2037 		cm->cm_flags = MFI_CMD_DATAIN | MFI_CMD_DATAOUT
2038 			| MFI_CMD_POLLED;
2039 		cm->cm_len = cm->cm_frame->header.data_len;
2040 		cm->cm_data = data = malloc(cm->cm_len, M_MFIBUF,
2041 					    M_WAITOK | M_ZERO);
2042 
2043 		/* restore header context */
2044 		cm->cm_frame->header.context = context;
2045 
2046 		temp = data;
2047 		for (i = 0; i < l_ioc.lioc_sge_count; i++) {
2048 			temp_convert =
2049 			    (void *)(uintptr_t)l_ioc.lioc_sgl[i].iov_base;
2050 			error = copyin(temp_convert,
2051 			       temp,
2052 			       l_ioc.lioc_sgl[i].iov_len);
2053 			if (error != 0) {
2054 				device_printf(sc->mfi_dev,
2055 				    "Copy in failed\n");
2056 				goto out;
2057 			}
2058 			temp = &temp[l_ioc.lioc_sgl[i].iov_len];
2059 		}
2060 
2061 		mtx_lock(&sc->mfi_io_lock);
2062 		if ((error = mfi_mapcmd(sc, cm)) != 0) {
2063 			device_printf(sc->mfi_dev,
2064 			    "Controller polled failed\n");
2065 			mtx_unlock(&sc->mfi_io_lock);
2066 			goto out;
2067 		}
2068 
2069 		bus_dmamap_sync(sc->mfi_buffer_dmat, cm->cm_dmamap,
2070 				BUS_DMASYNC_POSTREAD);
2071 		bus_dmamap_unload(sc->mfi_buffer_dmat, cm->cm_dmamap);
2072 		mtx_unlock(&sc->mfi_io_lock);
2073 
2074 		temp = data;
2075 		for (i = 0; i < l_ioc.lioc_sge_count; i++) {
2076 			temp_convert =
2077 			    (void *)(uintptr_t)l_ioc.lioc_sgl[i].iov_base;
2078 			error = copyout(temp,
2079 				temp_convert,
2080 				l_ioc.lioc_sgl[i].iov_len);
2081 			if (error != 0) {
2082 				device_printf(sc->mfi_dev,
2083 				    "Copy out failed\n");
2084 				goto out;
2085 			}
2086 			temp = &temp[l_ioc.lioc_sgl[i].iov_len];
2087 		}
2088 
2089 		if (l_ioc.lioc_sense_len) {
2090 			/* copy out sense */
2091 			sense_ptr = &((struct mfi_linux_ioc_packet*)arg)
2092 			    ->lioc_frame.raw[0];
2093 			error = copyout(cm->cm_sense, sense_ptr,
2094 			    l_ioc.lioc_sense_len);
2095 			if (error != 0) {
2096 				device_printf(sc->mfi_dev,
2097 				    "Copy out failed\n");
2098 				goto out;
2099 			}
2100 		}
2101 
2102 		error = copyout(&cm->cm_frame->header.cmd_status,
2103 			&((struct mfi_linux_ioc_packet*)arg)
2104 			->lioc_frame.hdr.cmd_status,
2105 			1);
2106 		if (error != 0) {
2107 			device_printf(sc->mfi_dev,
2108 				      "Copy out failed\n");
2109 			goto out;
2110 		}
2111 
2112 		if (cm->cm_frame->header.cmd_status == MFI_STAT_OK) {
2113 			switch (cm->cm_frame->dcmd.opcode) {
2114 			case MFI_DCMD_CFG_CLEAR:
2115 			case MFI_DCMD_CFG_ADD:
2116 				/* mfi_ldrescan(sc); */
2117 				break;
2118 			}
2119 		}
2120 out:
2121 		if (data)
2122 			free(data, M_MFIBUF);
2123 		if (cm) {
2124 			mtx_lock(&sc->mfi_io_lock);
2125 			mfi_release_command(cm);
2126 			mtx_unlock(&sc->mfi_io_lock);
2127 		}
2128 
2129 		return (error);
2130 	case MFI_LINUX_SET_AEN_2: /* AEN Linux ioctl shim */
2131 		error = copyin(arg, &l_aen, sizeof(l_aen));
2132 		if (error != 0)
2133 			return (error);
2134 		printf("AEN IMPLEMENTED for pid %d\n", curproc->p_pid);
2135 		mfi_aen_entry = malloc(sizeof(struct mfi_aen), M_MFIBUF,
2136 		    M_WAITOK);
2137 		mtx_lock(&sc->mfi_io_lock);
2138 		if (mfi_aen_entry != NULL) {
2139 			mfi_aen_entry->p = curproc;
2140 			TAILQ_INSERT_TAIL(&sc->mfi_aen_pids, mfi_aen_entry,
2141 			    aen_link);
2142 		}
2143 		error = mfi_aen_register(sc, l_aen.laen_seq_num,
2144 		    l_aen.laen_class_locale);
2145 
2146 		if (error != 0) {
2147 			TAILQ_REMOVE(&sc->mfi_aen_pids, mfi_aen_entry,
2148 			    aen_link);
2149 			free(mfi_aen_entry, M_MFIBUF);
2150 		}
2151 		mtx_unlock(&sc->mfi_io_lock);
2152 
2153 		return (error);
2154 	default:
2155 		device_printf(sc->mfi_dev, "IOCTL 0x%lx not handled\n", cmd);
2156 		error = ENOENT;
2157 		break;
2158 	}
2159 
2160 	return (error);
2161 }
2162 
2163 static int
2164 mfi_poll(struct cdev *dev, int poll_events, struct thread *td)
2165 {
2166 	struct mfi_softc *sc;
2167 	int revents = 0;
2168 
2169 	sc = dev->si_drv1;
2170 
2171 	if (poll_events & (POLLIN | POLLRDNORM)) {
2172 		if (sc->mfi_aen_triggered != 0) {
2173 			revents |= poll_events & (POLLIN | POLLRDNORM);
2174 			sc->mfi_aen_triggered = 0;
2175 		}
2176 		if (sc->mfi_aen_triggered == 0 && sc->mfi_aen_cm == NULL) {
2177 			revents |= POLLERR;
2178 		}
2179 	}
2180 
2181 	if (revents == 0) {
2182 		if (poll_events & (POLLIN | POLLRDNORM)) {
2183 			sc->mfi_poll_waiting = 1;
2184 			selrecord(td, &sc->mfi_select);
2185 		}
2186 	}
2187 
2188 	return revents;
2189 }
2190 
2191 
2192 static void
2193 mfi_dump_all(void)
2194 {
2195 	struct mfi_softc *sc;
2196 	struct mfi_command *cm;
2197 	devclass_t dc;
2198 	time_t deadline;
2199 	int timedout;
2200 	int i;
2201 
2202 	dc = devclass_find("mfi");
2203 	if (dc == NULL) {
2204 		printf("No mfi dev class\n");
2205 		return;
2206 	}
2207 
2208 	for (i = 0; ; i++) {
2209 		sc = devclass_get_softc(dc, i);
2210 		if (sc == NULL)
2211 			break;
2212 		device_printf(sc->mfi_dev, "Dumping\n\n");
2213 		timedout = 0;
2214 		deadline = time_uptime - MFI_CMD_TIMEOUT;
2215 		mtx_lock(&sc->mfi_io_lock);
2216 		TAILQ_FOREACH(cm, &sc->mfi_busy, cm_link) {
2217 			if (cm->cm_timestamp < deadline) {
2218 				device_printf(sc->mfi_dev,
2219 				    "COMMAND %p TIMEOUT AFTER %d SECONDS\n", cm,
2220 				    (int)(time_uptime - cm->cm_timestamp));
2221 				MFI_PRINT_CMD(cm);
2222 				timedout++;
2223 			}
2224 		}
2225 
2226 #if 0
2227 		if (timedout)
2228 			MFI_DUMP_CMDS(SC);
2229 #endif
2230 
2231 		mtx_unlock(&sc->mfi_io_lock);
2232 	}
2233 
2234 	return;
2235 }
2236 
2237 static void
2238 mfi_timeout(void *data)
2239 {
2240 	struct mfi_softc *sc = (struct mfi_softc *)data;
2241 	struct mfi_command *cm;
2242 	time_t deadline;
2243 	int timedout = 0;
2244 
2245 	deadline = time_uptime - MFI_CMD_TIMEOUT;
2246 	mtx_lock(&sc->mfi_io_lock);
2247 	TAILQ_FOREACH(cm, &sc->mfi_busy, cm_link) {
2248 		if (sc->mfi_aen_cm == cm)
2249 			continue;
2250 		if ((sc->mfi_aen_cm != cm) && (cm->cm_timestamp < deadline)) {
2251 			device_printf(sc->mfi_dev,
2252 			    "COMMAND %p TIMEOUT AFTER %d SECONDS\n", cm,
2253 			    (int)(time_uptime - cm->cm_timestamp));
2254 			MFI_PRINT_CMD(cm);
2255 			MFI_VALIDATE_CMD(sc, cm);
2256 			timedout++;
2257 		}
2258 	}
2259 
2260 #if 0
2261 	if (timedout)
2262 		MFI_DUMP_CMDS(SC);
2263 #endif
2264 
2265 	mtx_unlock(&sc->mfi_io_lock);
2266 
2267 	callout_reset(&sc->mfi_watchdog_callout, MFI_CMD_TIMEOUT * hz,
2268 	    mfi_timeout, sc);
2269 
2270 	if (0)
2271 		mfi_dump_all();
2272 	return;
2273 }
2274