xref: /freebsd/sys/dev/usb/storage/umass.c (revision 10b59a9b4add0320d52c15ce057dd697261e7dfc)
1 #include <sys/cdefs.h>
2 __FBSDID("$FreeBSD$");
3 
4 /*-
5  * Copyright (c) 1999 MAEKAWA Masahide <bishop@rr.iij4u.or.jp>,
6  *		      Nick Hibma <n_hibma@FreeBSD.org>
7  * All rights reserved.
8  *
9  * Redistribution and use in source and binary forms, with or without
10  * modification, are permitted provided that the following conditions
11  * are met:
12  * 1. Redistributions of source code must retain the above copyright
13  *    notice, this list of conditions and the following disclaimer.
14  * 2. Redistributions in binary form must reproduce the above copyright
15  *    notice, this list of conditions and the following disclaimer in the
16  *    documentation and/or other materials provided with the distribution.
17  *
18  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
19  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
20  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
21  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
22  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
23  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
24  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
25  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
26  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
27  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
28  * SUCH DAMAGE.
29  *
30  *	$FreeBSD$
31  *	$NetBSD: umass.c,v 1.28 2000/04/02 23:46:53 augustss Exp $
32  */
33 
34 /* Also already merged from NetBSD:
35  *	$NetBSD: umass.c,v 1.67 2001/11/25 19:05:22 augustss Exp $
36  *	$NetBSD: umass.c,v 1.90 2002/11/04 19:17:33 pooka Exp $
37  *	$NetBSD: umass.c,v 1.108 2003/11/07 17:03:25 wiz Exp $
38  *	$NetBSD: umass.c,v 1.109 2003/12/04 13:57:31 keihan Exp $
39  */
40 
41 /*
42  * Universal Serial Bus Mass Storage Class specs:
43  * http://www.usb.org/developers/devclass_docs/usb_msc_overview_1.2.pdf
44  * http://www.usb.org/developers/devclass_docs/usbmassbulk_10.pdf
45  * http://www.usb.org/developers/devclass_docs/usb_msc_cbi_1.1.pdf
46  * http://www.usb.org/developers/devclass_docs/usbmass-ufi10.pdf
47  */
48 
49 /*
50  * Ported to NetBSD by Lennart Augustsson <augustss@NetBSD.org>.
51  * Parts of the code written by Jason R. Thorpe <thorpej@shagadelic.org>.
52  */
53 
54 /*
55  * The driver handles 3 Wire Protocols
56  * - Command/Bulk/Interrupt (CBI)
57  * - Command/Bulk/Interrupt with Command Completion Interrupt (CBI with CCI)
58  * - Mass Storage Bulk-Only (BBB)
59  *   (BBB refers Bulk/Bulk/Bulk for Command/Data/Status phases)
60  *
61  * Over these wire protocols it handles the following command protocols
62  * - SCSI
63  * - UFI (floppy command set)
64  * - 8070i (ATAPI)
65  *
66  * UFI and 8070i (ATAPI) are transformed versions of the SCSI command set. The
67  * sc->sc_transform method is used to convert the commands into the appropriate
68  * format (if at all necessary). For example, UFI requires all commands to be
69  * 12 bytes in length amongst other things.
70  *
71  * The source code below is marked and can be split into a number of pieces
72  * (in this order):
73  *
74  * - probe/attach/detach
75  * - generic transfer routines
76  * - BBB
77  * - CBI
78  * - CBI_I (in addition to functions from CBI)
79  * - CAM (Common Access Method)
80  * - SCSI
81  * - UFI
82  * - 8070i (ATAPI)
83  *
84  * The protocols are implemented using a state machine, for the transfers as
85  * well as for the resets. The state machine is contained in umass_t_*_callback.
86  * The state machine is started through either umass_command_start() or
87  * umass_reset().
88  *
89  * The reason for doing this is a) CAM performs a lot better this way and b) it
90  * avoids using tsleep from interrupt context (for example after a failed
91  * transfer).
92  */
93 
94 /*
95  * The SCSI related part of this driver has been derived from the
96  * dev/ppbus/vpo.c driver, by Nicolas Souchu (nsouch@FreeBSD.org).
97  *
98  * The CAM layer uses so called actions which are messages sent to the host
99  * adapter for completion. The actions come in through umass_cam_action. The
100  * appropriate block of routines is called depending on the transport protocol
101  * in use. When the transfer has finished, these routines call
102  * umass_cam_cb again to complete the CAM command.
103  */
104 
105 #include <sys/stdint.h>
106 #include <sys/stddef.h>
107 #include <sys/param.h>
108 #include <sys/queue.h>
109 #include <sys/types.h>
110 #include <sys/systm.h>
111 #include <sys/kernel.h>
112 #include <sys/bus.h>
113 #include <sys/module.h>
114 #include <sys/lock.h>
115 #include <sys/mutex.h>
116 #include <sys/condvar.h>
117 #include <sys/sysctl.h>
118 #include <sys/sx.h>
119 #include <sys/unistd.h>
120 #include <sys/callout.h>
121 #include <sys/malloc.h>
122 #include <sys/priv.h>
123 
124 #include <dev/usb/usb.h>
125 #include <dev/usb/usbdi.h>
126 #include <dev/usb/usbdi_util.h>
127 #include "usbdevs.h"
128 
129 #include <dev/usb/quirk/usb_quirk.h>
130 
131 #include <cam/cam.h>
132 #include <cam/cam_ccb.h>
133 #include <cam/cam_sim.h>
134 #include <cam/cam_xpt_sim.h>
135 #include <cam/scsi/scsi_all.h>
136 #include <cam/scsi/scsi_da.h>
137 
138 #include <cam/cam_periph.h>
139 
140 #define UMASS_EXT_BUFFER
141 #ifdef UMASS_EXT_BUFFER
142 /* this enables loading of virtual buffers into DMA */
143 #define	UMASS_USB_FLAGS .ext_buffer=1,
144 #else
145 #define	UMASS_USB_FLAGS
146 #endif
147 
148 #ifdef USB_DEBUG
149 #define	DIF(m, x)				\
150   do {						\
151     if (umass_debug & (m)) { x ; }		\
152   } while (0)
153 
154 #define	DPRINTF(sc, m, fmt, ...)			\
155   do {							\
156     if (umass_debug & (m)) {				\
157         printf("%s:%s: " fmt,				\
158 	       (sc) ? (const char *)(sc)->sc_name :	\
159 	       (const char *)"umassX",			\
160 		__FUNCTION__ ,## __VA_ARGS__);		\
161     }							\
162   } while (0)
163 
164 #define	UDMASS_GEN	0x00010000	/* general */
165 #define	UDMASS_SCSI	0x00020000	/* scsi */
166 #define	UDMASS_UFI	0x00040000	/* ufi command set */
167 #define	UDMASS_ATAPI	0x00080000	/* 8070i command set */
168 #define	UDMASS_CMD	(UDMASS_SCSI|UDMASS_UFI|UDMASS_ATAPI)
169 #define	UDMASS_USB	0x00100000	/* USB general */
170 #define	UDMASS_BBB	0x00200000	/* Bulk-Only transfers */
171 #define	UDMASS_CBI	0x00400000	/* CBI transfers */
172 #define	UDMASS_WIRE	(UDMASS_BBB|UDMASS_CBI)
173 #define	UDMASS_ALL	0xffff0000	/* all of the above */
174 static int umass_debug = 0;
175 
176 static SYSCTL_NODE(_hw_usb, OID_AUTO, umass, CTLFLAG_RW, 0, "USB umass");
177 SYSCTL_INT(_hw_usb_umass, OID_AUTO, debug, CTLFLAG_RW,
178     &umass_debug, 0, "umass debug level");
179 
180 TUNABLE_INT("hw.usb.umass.debug", &umass_debug);
181 #else
182 #define	DIF(...) do { } while (0)
183 #define	DPRINTF(...) do { } while (0)
184 #endif
185 
186 #define	UMASS_GONE ((struct umass_softc *)1)
187 
188 #define	UMASS_BULK_SIZE (1 << 17)
189 #define	UMASS_CBI_DIAGNOSTIC_CMDLEN 12	/* bytes */
190 #define	UMASS_MAX_CMDLEN MAX(12, CAM_MAX_CDBLEN)	/* bytes */
191 
192 /* USB transfer definitions */
193 
194 #define	UMASS_T_BBB_RESET1      0	/* Bulk-Only */
195 #define	UMASS_T_BBB_RESET2      1
196 #define	UMASS_T_BBB_RESET3      2
197 #define	UMASS_T_BBB_COMMAND     3
198 #define	UMASS_T_BBB_DATA_READ   4
199 #define	UMASS_T_BBB_DATA_RD_CS  5
200 #define	UMASS_T_BBB_DATA_WRITE  6
201 #define	UMASS_T_BBB_DATA_WR_CS  7
202 #define	UMASS_T_BBB_STATUS      8
203 #define	UMASS_T_BBB_MAX         9
204 
205 #define	UMASS_T_CBI_RESET1      0	/* CBI */
206 #define	UMASS_T_CBI_RESET2      1
207 #define	UMASS_T_CBI_RESET3      2
208 #define	UMASS_T_CBI_COMMAND     3
209 #define	UMASS_T_CBI_DATA_READ   4
210 #define	UMASS_T_CBI_DATA_RD_CS  5
211 #define	UMASS_T_CBI_DATA_WRITE  6
212 #define	UMASS_T_CBI_DATA_WR_CS  7
213 #define	UMASS_T_CBI_STATUS      8
214 #define	UMASS_T_CBI_RESET4      9
215 #define	UMASS_T_CBI_MAX        10
216 
217 #define	UMASS_T_MAX MAX(UMASS_T_CBI_MAX, UMASS_T_BBB_MAX)
218 
219 /* Generic definitions */
220 
221 /* Direction for transfer */
222 #define	DIR_NONE	0
223 #define	DIR_IN		1
224 #define	DIR_OUT		2
225 
226 /* device name */
227 #define	DEVNAME		"umass"
228 #define	DEVNAME_SIM	"umass-sim"
229 
230 /* Approximate maximum transfer speeds (assumes 33% overhead). */
231 #define	UMASS_FULL_TRANSFER_SPEED	1000
232 #define	UMASS_HIGH_TRANSFER_SPEED	40000
233 #define	UMASS_SUPER_TRANSFER_SPEED	400000
234 #define	UMASS_FLOPPY_TRANSFER_SPEED	20
235 
236 #define	UMASS_TIMEOUT			5000	/* ms */
237 
238 /* CAM specific definitions */
239 
240 #define	UMASS_SCSIID_MAX	1	/* maximum number of drives expected */
241 #define	UMASS_SCSIID_HOST	UMASS_SCSIID_MAX
242 
243 /* Bulk-Only features */
244 
245 #define	UR_BBB_RESET		0xff	/* Bulk-Only reset */
246 #define	UR_BBB_GET_MAX_LUN	0xfe	/* Get maximum lun */
247 
248 /* Command Block Wrapper */
249 typedef struct {
250 	uDWord	dCBWSignature;
251 #define	CBWSIGNATURE	0x43425355
252 	uDWord	dCBWTag;
253 	uDWord	dCBWDataTransferLength;
254 	uByte	bCBWFlags;
255 #define	CBWFLAGS_OUT	0x00
256 #define	CBWFLAGS_IN	0x80
257 	uByte	bCBWLUN;
258 	uByte	bCDBLength;
259 #define	CBWCDBLENGTH	16
260 	uByte	CBWCDB[CBWCDBLENGTH];
261 } __packed umass_bbb_cbw_t;
262 
263 #define	UMASS_BBB_CBW_SIZE	31
264 
265 /* Command Status Wrapper */
266 typedef struct {
267 	uDWord	dCSWSignature;
268 #define	CSWSIGNATURE	0x53425355
269 #define	CSWSIGNATURE_IMAGINATION_DBX1	0x43425355
270 #define	CSWSIGNATURE_OLYMPUS_C1	0x55425355
271 	uDWord	dCSWTag;
272 	uDWord	dCSWDataResidue;
273 	uByte	bCSWStatus;
274 #define	CSWSTATUS_GOOD	0x0
275 #define	CSWSTATUS_FAILED	0x1
276 #define	CSWSTATUS_PHASE	0x2
277 } __packed umass_bbb_csw_t;
278 
279 #define	UMASS_BBB_CSW_SIZE	13
280 
281 /* CBI features */
282 
283 #define	UR_CBI_ADSC	0x00
284 
285 typedef union {
286 	struct {
287 		uint8_t	type;
288 #define	IDB_TYPE_CCI		0x00
289 		uint8_t	value;
290 #define	IDB_VALUE_PASS		0x00
291 #define	IDB_VALUE_FAIL		0x01
292 #define	IDB_VALUE_PHASE		0x02
293 #define	IDB_VALUE_PERSISTENT	0x03
294 #define	IDB_VALUE_STATUS_MASK	0x03
295 	} __packed common;
296 
297 	struct {
298 		uint8_t	asc;
299 		uint8_t	ascq;
300 	} __packed ufi;
301 } __packed umass_cbi_sbl_t;
302 
303 struct umass_softc;			/* see below */
304 
305 typedef void (umass_callback_t)(struct umass_softc *sc, union ccb *ccb,
306     	uint32_t residue, uint8_t status);
307 
308 #define	STATUS_CMD_OK		0	/* everything ok */
309 #define	STATUS_CMD_UNKNOWN	1	/* will have to fetch sense */
310 #define	STATUS_CMD_FAILED	2	/* transfer was ok, command failed */
311 #define	STATUS_WIRE_FAILED	3	/* couldn't even get command across */
312 
313 typedef uint8_t (umass_transform_t)(struct umass_softc *sc, uint8_t *cmd_ptr,
314     	uint8_t cmd_len);
315 
316 /* Wire and command protocol */
317 #define	UMASS_PROTO_BBB		0x0001	/* USB wire protocol */
318 #define	UMASS_PROTO_CBI		0x0002
319 #define	UMASS_PROTO_CBI_I	0x0004
320 #define	UMASS_PROTO_WIRE	0x00ff	/* USB wire protocol mask */
321 #define	UMASS_PROTO_SCSI	0x0100	/* command protocol */
322 #define	UMASS_PROTO_ATAPI	0x0200
323 #define	UMASS_PROTO_UFI		0x0400
324 #define	UMASS_PROTO_RBC		0x0800
325 #define	UMASS_PROTO_COMMAND	0xff00	/* command protocol mask */
326 
327 /* Device specific quirks */
328 #define	NO_QUIRKS		0x0000
329 	/*
330 	 * The drive does not support Test Unit Ready. Convert to Start Unit
331 	 */
332 #define	NO_TEST_UNIT_READY	0x0001
333 	/*
334 	 * The drive does not reset the Unit Attention state after REQUEST
335 	 * SENSE has been sent. The INQUIRY command does not reset the UA
336 	 * either, and so CAM runs in circles trying to retrieve the initial
337 	 * INQUIRY data.
338 	 */
339 #define	RS_NO_CLEAR_UA		0x0002
340 	/* The drive does not support START STOP.  */
341 #define	NO_START_STOP		0x0004
342 	/* Don't ask for full inquiry data (255b).  */
343 #define	FORCE_SHORT_INQUIRY	0x0008
344 	/* Needs to be initialised the Shuttle way */
345 #define	SHUTTLE_INIT		0x0010
346 	/* Drive needs to be switched to alternate iface 1 */
347 #define	ALT_IFACE_1		0x0020
348 	/* Drive does not do 1Mb/s, but just floppy speeds (20kb/s) */
349 #define	FLOPPY_SPEED		0x0040
350 	/* The device can't count and gets the residue of transfers wrong */
351 #define	IGNORE_RESIDUE		0x0080
352 	/* No GetMaxLun call */
353 #define	NO_GETMAXLUN		0x0100
354 	/* The device uses a weird CSWSIGNATURE. */
355 #define	WRONG_CSWSIG		0x0200
356 	/* Device cannot handle INQUIRY so fake a generic response */
357 #define	NO_INQUIRY		0x0400
358 	/* Device cannot handle INQUIRY EVPD, return CHECK CONDITION */
359 #define	NO_INQUIRY_EVPD		0x0800
360 	/* Pad all RBC requests to 12 bytes. */
361 #define	RBC_PAD_TO_12		0x1000
362 	/*
363 	 * Device reports number of sectors from READ_CAPACITY, not max
364 	 * sector number.
365 	 */
366 #define	READ_CAPACITY_OFFBY1	0x2000
367 	/*
368 	 * Device cannot handle a SCSI synchronize cache command.  Normally
369 	 * this quirk would be handled in the cam layer, but for IDE bridges
370 	 * we need to associate the quirk with the bridge and not the
371 	 * underlying disk device.  This is handled by faking a success
372 	 * result.
373 	 */
374 #define	NO_SYNCHRONIZE_CACHE	0x4000
375 
376 struct umass_softc {
377 
378 	struct scsi_sense cam_scsi_sense;
379 	struct scsi_test_unit_ready cam_scsi_test_unit_ready;
380 	struct mtx sc_mtx;
381 	struct {
382 		uint8_t *data_ptr;
383 		union ccb *ccb;
384 		umass_callback_t *callback;
385 
386 		uint32_t data_len;	/* bytes */
387 		uint32_t data_rem;	/* bytes */
388 		uint32_t data_timeout;	/* ms */
389 		uint32_t actlen;	/* bytes */
390 
391 		uint8_t	cmd_data[UMASS_MAX_CMDLEN];
392 		uint8_t	cmd_len;	/* bytes */
393 		uint8_t	dir;
394 		uint8_t	lun;
395 	}	sc_transfer;
396 
397 	/* Bulk specific variables for transfers in progress */
398 	umass_bbb_cbw_t cbw;		/* command block wrapper */
399 	umass_bbb_csw_t csw;		/* command status wrapper */
400 
401 	/* CBI specific variables for transfers in progress */
402 	umass_cbi_sbl_t sbl;		/* status block */
403 
404 	device_t sc_dev;
405 	struct usb_device *sc_udev;
406 	struct cam_sim *sc_sim;		/* SCSI Interface Module */
407 	struct usb_xfer *sc_xfer[UMASS_T_MAX];
408 
409 	/*
410 	 * The command transform function is used to convert the SCSI
411 	 * commands into their derivatives, like UFI, ATAPI, and friends.
412 	 */
413 	umass_transform_t *sc_transform;
414 
415 	uint32_t sc_unit;
416 	uint32_t sc_quirks;		/* they got it almost right */
417 	uint32_t sc_proto;		/* wire and cmd protocol */
418 
419 	uint8_t	sc_name[16];
420 	uint8_t	sc_iface_no;		/* interface number */
421 	uint8_t	sc_maxlun;		/* maximum LUN number, inclusive */
422 	uint8_t	sc_last_xfer_index;
423 	uint8_t	sc_status_try;
424 };
425 
426 struct umass_probe_proto {
427 	uint32_t quirks;
428 	uint32_t proto;
429 
430 	int	error;
431 };
432 
433 /* prototypes */
434 
435 static device_probe_t umass_probe;
436 static device_attach_t umass_attach;
437 static device_detach_t umass_detach;
438 
439 static usb_callback_t umass_tr_error;
440 static usb_callback_t umass_t_bbb_reset1_callback;
441 static usb_callback_t umass_t_bbb_reset2_callback;
442 static usb_callback_t umass_t_bbb_reset3_callback;
443 static usb_callback_t umass_t_bbb_command_callback;
444 static usb_callback_t umass_t_bbb_data_read_callback;
445 static usb_callback_t umass_t_bbb_data_rd_cs_callback;
446 static usb_callback_t umass_t_bbb_data_write_callback;
447 static usb_callback_t umass_t_bbb_data_wr_cs_callback;
448 static usb_callback_t umass_t_bbb_status_callback;
449 static usb_callback_t umass_t_cbi_reset1_callback;
450 static usb_callback_t umass_t_cbi_reset2_callback;
451 static usb_callback_t umass_t_cbi_reset3_callback;
452 static usb_callback_t umass_t_cbi_reset4_callback;
453 static usb_callback_t umass_t_cbi_command_callback;
454 static usb_callback_t umass_t_cbi_data_read_callback;
455 static usb_callback_t umass_t_cbi_data_rd_cs_callback;
456 static usb_callback_t umass_t_cbi_data_write_callback;
457 static usb_callback_t umass_t_cbi_data_wr_cs_callback;
458 static usb_callback_t umass_t_cbi_status_callback;
459 
460 static void	umass_cancel_ccb(struct umass_softc *);
461 static void	umass_init_shuttle(struct umass_softc *);
462 static void	umass_reset(struct umass_softc *);
463 static void	umass_t_bbb_data_clear_stall_callback(struct usb_xfer *,
464 		    uint8_t, uint8_t, usb_error_t);
465 static void	umass_command_start(struct umass_softc *, uint8_t, void *,
466 		    uint32_t, uint32_t, umass_callback_t *, union ccb *);
467 static uint8_t	umass_bbb_get_max_lun(struct umass_softc *);
468 static void	umass_cbi_start_status(struct umass_softc *);
469 static void	umass_t_cbi_data_clear_stall_callback(struct usb_xfer *,
470 		    uint8_t, uint8_t, usb_error_t);
471 static int	umass_cam_attach_sim(struct umass_softc *);
472 static void	umass_cam_attach(struct umass_softc *);
473 static void	umass_cam_detach_sim(struct umass_softc *);
474 static void	umass_cam_action(struct cam_sim *, union ccb *);
475 static void	umass_cam_poll(struct cam_sim *);
476 static void	umass_cam_cb(struct umass_softc *, union ccb *, uint32_t,
477 		    uint8_t);
478 static void	umass_cam_sense_cb(struct umass_softc *, union ccb *, uint32_t,
479 		    uint8_t);
480 static void	umass_cam_quirk_cb(struct umass_softc *, union ccb *, uint32_t,
481 		    uint8_t);
482 static uint8_t	umass_scsi_transform(struct umass_softc *, uint8_t *, uint8_t);
483 static uint8_t	umass_rbc_transform(struct umass_softc *, uint8_t *, uint8_t);
484 static uint8_t	umass_ufi_transform(struct umass_softc *, uint8_t *, uint8_t);
485 static uint8_t	umass_atapi_transform(struct umass_softc *, uint8_t *,
486 		    uint8_t);
487 static uint8_t	umass_no_transform(struct umass_softc *, uint8_t *, uint8_t);
488 static uint8_t	umass_std_transform(struct umass_softc *, union ccb *, uint8_t
489 		    *, uint8_t);
490 
491 #ifdef USB_DEBUG
492 static void	umass_bbb_dump_cbw(struct umass_softc *, umass_bbb_cbw_t *);
493 static void	umass_bbb_dump_csw(struct umass_softc *, umass_bbb_csw_t *);
494 static void	umass_cbi_dump_cmd(struct umass_softc *, void *, uint8_t);
495 static void	umass_dump_buffer(struct umass_softc *, uint8_t *, uint32_t,
496 		    uint32_t);
497 #endif
498 
499 static struct usb_config umass_bbb_config[UMASS_T_BBB_MAX] = {
500 
501 	[UMASS_T_BBB_RESET1] = {
502 		.type = UE_CONTROL,
503 		.endpoint = 0x00,	/* Control pipe */
504 		.direction = UE_DIR_ANY,
505 		.bufsize = sizeof(struct usb_device_request),
506 		.callback = &umass_t_bbb_reset1_callback,
507 		.timeout = 5000,	/* 5 seconds */
508 		.interval = 500,	/* 500 milliseconds */
509 	},
510 
511 	[UMASS_T_BBB_RESET2] = {
512 		.type = UE_CONTROL,
513 		.endpoint = 0x00,	/* Control pipe */
514 		.direction = UE_DIR_ANY,
515 		.bufsize = sizeof(struct usb_device_request),
516 		.callback = &umass_t_bbb_reset2_callback,
517 		.timeout = 5000,	/* 5 seconds */
518 		.interval = 50,	/* 50 milliseconds */
519 	},
520 
521 	[UMASS_T_BBB_RESET3] = {
522 		.type = UE_CONTROL,
523 		.endpoint = 0x00,	/* Control pipe */
524 		.direction = UE_DIR_ANY,
525 		.bufsize = sizeof(struct usb_device_request),
526 		.callback = &umass_t_bbb_reset3_callback,
527 		.timeout = 5000,	/* 5 seconds */
528 		.interval = 50,	/* 50 milliseconds */
529 	},
530 
531 	[UMASS_T_BBB_COMMAND] = {
532 		.type = UE_BULK,
533 		.endpoint = UE_ADDR_ANY,
534 		.direction = UE_DIR_OUT,
535 		.bufsize = sizeof(umass_bbb_cbw_t),
536 		.callback = &umass_t_bbb_command_callback,
537 		.timeout = 5000,	/* 5 seconds */
538 	},
539 
540 	[UMASS_T_BBB_DATA_READ] = {
541 		.type = UE_BULK,
542 		.endpoint = UE_ADDR_ANY,
543 		.direction = UE_DIR_IN,
544 		.bufsize = UMASS_BULK_SIZE,
545 		.flags = {.proxy_buffer = 1,.short_xfer_ok = 1, UMASS_USB_FLAGS},
546 		.callback = &umass_t_bbb_data_read_callback,
547 		.timeout = 0,	/* overwritten later */
548 	},
549 
550 	[UMASS_T_BBB_DATA_RD_CS] = {
551 		.type = UE_CONTROL,
552 		.endpoint = 0x00,	/* Control pipe */
553 		.direction = UE_DIR_ANY,
554 		.bufsize = sizeof(struct usb_device_request),
555 		.callback = &umass_t_bbb_data_rd_cs_callback,
556 		.timeout = 5000,	/* 5 seconds */
557 	},
558 
559 	[UMASS_T_BBB_DATA_WRITE] = {
560 		.type = UE_BULK,
561 		.endpoint = UE_ADDR_ANY,
562 		.direction = UE_DIR_OUT,
563 		.bufsize = UMASS_BULK_SIZE,
564 		.flags = {.proxy_buffer = 1,.short_xfer_ok = 1, UMASS_USB_FLAGS},
565 		.callback = &umass_t_bbb_data_write_callback,
566 		.timeout = 0,	/* overwritten later */
567 	},
568 
569 	[UMASS_T_BBB_DATA_WR_CS] = {
570 		.type = UE_CONTROL,
571 		.endpoint = 0x00,	/* Control pipe */
572 		.direction = UE_DIR_ANY,
573 		.bufsize = sizeof(struct usb_device_request),
574 		.callback = &umass_t_bbb_data_wr_cs_callback,
575 		.timeout = 5000,	/* 5 seconds */
576 	},
577 
578 	[UMASS_T_BBB_STATUS] = {
579 		.type = UE_BULK,
580 		.endpoint = UE_ADDR_ANY,
581 		.direction = UE_DIR_IN,
582 		.bufsize = sizeof(umass_bbb_csw_t),
583 		.flags = {.short_xfer_ok = 1,},
584 		.callback = &umass_t_bbb_status_callback,
585 		.timeout = 5000,	/* ms */
586 	},
587 };
588 
589 static struct usb_config umass_cbi_config[UMASS_T_CBI_MAX] = {
590 
591 	[UMASS_T_CBI_RESET1] = {
592 		.type = UE_CONTROL,
593 		.endpoint = 0x00,	/* Control pipe */
594 		.direction = UE_DIR_ANY,
595 		.bufsize = (sizeof(struct usb_device_request) +
596 		    UMASS_CBI_DIAGNOSTIC_CMDLEN),
597 		.callback = &umass_t_cbi_reset1_callback,
598 		.timeout = 5000,	/* 5 seconds */
599 		.interval = 500,	/* 500 milliseconds */
600 	},
601 
602 	[UMASS_T_CBI_RESET2] = {
603 		.type = UE_CONTROL,
604 		.endpoint = 0x00,	/* Control pipe */
605 		.direction = UE_DIR_ANY,
606 		.bufsize = sizeof(struct usb_device_request),
607 		.callback = &umass_t_cbi_reset2_callback,
608 		.timeout = 5000,	/* 5 seconds */
609 		.interval = 50,	/* 50 milliseconds */
610 	},
611 
612 	[UMASS_T_CBI_RESET3] = {
613 		.type = UE_CONTROL,
614 		.endpoint = 0x00,	/* Control pipe */
615 		.direction = UE_DIR_ANY,
616 		.bufsize = sizeof(struct usb_device_request),
617 		.callback = &umass_t_cbi_reset3_callback,
618 		.timeout = 5000,	/* 5 seconds */
619 		.interval = 50,	/* 50 milliseconds */
620 	},
621 
622 	[UMASS_T_CBI_COMMAND] = {
623 		.type = UE_CONTROL,
624 		.endpoint = 0x00,	/* Control pipe */
625 		.direction = UE_DIR_ANY,
626 		.bufsize = (sizeof(struct usb_device_request) +
627 		    UMASS_MAX_CMDLEN),
628 		.callback = &umass_t_cbi_command_callback,
629 		.timeout = 5000,	/* 5 seconds */
630 	},
631 
632 	[UMASS_T_CBI_DATA_READ] = {
633 		.type = UE_BULK,
634 		.endpoint = UE_ADDR_ANY,
635 		.direction = UE_DIR_IN,
636 		.bufsize = UMASS_BULK_SIZE,
637 		.flags = {.proxy_buffer = 1,.short_xfer_ok = 1, UMASS_USB_FLAGS},
638 		.callback = &umass_t_cbi_data_read_callback,
639 		.timeout = 0,	/* overwritten later */
640 	},
641 
642 	[UMASS_T_CBI_DATA_RD_CS] = {
643 		.type = UE_CONTROL,
644 		.endpoint = 0x00,	/* Control pipe */
645 		.direction = UE_DIR_ANY,
646 		.bufsize = sizeof(struct usb_device_request),
647 		.callback = &umass_t_cbi_data_rd_cs_callback,
648 		.timeout = 5000,	/* 5 seconds */
649 	},
650 
651 	[UMASS_T_CBI_DATA_WRITE] = {
652 		.type = UE_BULK,
653 		.endpoint = UE_ADDR_ANY,
654 		.direction = UE_DIR_OUT,
655 		.bufsize = UMASS_BULK_SIZE,
656 		.flags = {.proxy_buffer = 1,.short_xfer_ok = 1, UMASS_USB_FLAGS},
657 		.callback = &umass_t_cbi_data_write_callback,
658 		.timeout = 0,	/* overwritten later */
659 	},
660 
661 	[UMASS_T_CBI_DATA_WR_CS] = {
662 		.type = UE_CONTROL,
663 		.endpoint = 0x00,	/* Control pipe */
664 		.direction = UE_DIR_ANY,
665 		.bufsize = sizeof(struct usb_device_request),
666 		.callback = &umass_t_cbi_data_wr_cs_callback,
667 		.timeout = 5000,	/* 5 seconds */
668 	},
669 
670 	[UMASS_T_CBI_STATUS] = {
671 		.type = UE_INTERRUPT,
672 		.endpoint = UE_ADDR_ANY,
673 		.direction = UE_DIR_IN,
674 		.flags = {.short_xfer_ok = 1,.no_pipe_ok = 1,},
675 		.bufsize = sizeof(umass_cbi_sbl_t),
676 		.callback = &umass_t_cbi_status_callback,
677 		.timeout = 5000,	/* ms */
678 	},
679 
680 	[UMASS_T_CBI_RESET4] = {
681 		.type = UE_CONTROL,
682 		.endpoint = 0x00,	/* Control pipe */
683 		.direction = UE_DIR_ANY,
684 		.bufsize = sizeof(struct usb_device_request),
685 		.callback = &umass_t_cbi_reset4_callback,
686 		.timeout = 5000,	/* ms */
687 	},
688 };
689 
690 /* If device cannot return valid inquiry data, fake it */
691 static const uint8_t fake_inq_data[SHORT_INQUIRY_LENGTH] = {
692 	0, /* removable */ 0x80, SCSI_REV_2, SCSI_REV_2,
693 	 /* additional_length */ 31, 0, 0, 0
694 };
695 
696 #define	UFI_COMMAND_LENGTH	12	/* UFI commands are always 12 bytes */
697 #define	ATAPI_COMMAND_LENGTH	12	/* ATAPI commands are always 12 bytes */
698 
699 static devclass_t umass_devclass;
700 
701 static device_method_t umass_methods[] = {
702 	/* Device interface */
703 	DEVMETHOD(device_probe, umass_probe),
704 	DEVMETHOD(device_attach, umass_attach),
705 	DEVMETHOD(device_detach, umass_detach),
706 	{0, 0}
707 };
708 
709 static driver_t umass_driver = {
710 	.name = "umass",
711 	.methods = umass_methods,
712 	.size = sizeof(struct umass_softc),
713 };
714 
715 DRIVER_MODULE(umass, uhub, umass_driver, umass_devclass, NULL, 0);
716 MODULE_DEPEND(umass, usb, 1, 1, 1);
717 MODULE_DEPEND(umass, cam, 1, 1, 1);
718 MODULE_VERSION(umass, 1);
719 
720 /*
721  * USB device probe/attach/detach
722  */
723 
724 static const STRUCT_USB_HOST_ID __used umass_devs[] = {
725 	/* generic mass storage class */
726 	{USB_IFACE_CLASS(UICLASS_MASS),},
727 };
728 
729 static uint16_t
730 umass_get_proto(struct usb_interface *iface)
731 {
732 	struct usb_interface_descriptor *id;
733 	uint16_t retval;
734 
735 	retval = 0;
736 
737 	/* Check for a standards compliant device */
738 	id = usbd_get_interface_descriptor(iface);
739 	if ((id == NULL) ||
740 	    (id->bInterfaceClass != UICLASS_MASS)) {
741 		goto done;
742 	}
743 	switch (id->bInterfaceSubClass) {
744 	case UISUBCLASS_SCSI:
745 		retval |= UMASS_PROTO_SCSI;
746 		break;
747 	case UISUBCLASS_UFI:
748 		retval |= UMASS_PROTO_UFI;
749 		break;
750 	case UISUBCLASS_RBC:
751 		retval |= UMASS_PROTO_RBC;
752 		break;
753 	case UISUBCLASS_SFF8020I:
754 	case UISUBCLASS_SFF8070I:
755 		retval |= UMASS_PROTO_ATAPI;
756 		break;
757 	default:
758 		goto done;
759 	}
760 
761 	switch (id->bInterfaceProtocol) {
762 	case UIPROTO_MASS_CBI:
763 		retval |= UMASS_PROTO_CBI;
764 		break;
765 	case UIPROTO_MASS_CBI_I:
766 		retval |= UMASS_PROTO_CBI_I;
767 		break;
768 	case UIPROTO_MASS_BBB_OLD:
769 	case UIPROTO_MASS_BBB:
770 		retval |= UMASS_PROTO_BBB;
771 		break;
772 	default:
773 		goto done;
774 	}
775 done:
776 	return (retval);
777 }
778 
779 /*
780  * Match the device we are seeing with the devices supported.
781  */
782 static struct umass_probe_proto
783 umass_probe_proto(device_t dev, struct usb_attach_arg *uaa)
784 {
785 	struct umass_probe_proto ret;
786 	uint32_t quirks = NO_QUIRKS;
787 	uint32_t proto = umass_get_proto(uaa->iface);
788 
789 	memset(&ret, 0, sizeof(ret));
790 	ret.error = BUS_PROBE_GENERIC;
791 
792 	/* Search for protocol enforcement */
793 
794 	if (usb_test_quirk(uaa, UQ_MSC_FORCE_WIRE_BBB)) {
795 		proto &= ~UMASS_PROTO_WIRE;
796 		proto |= UMASS_PROTO_BBB;
797 	} else if (usb_test_quirk(uaa, UQ_MSC_FORCE_WIRE_CBI)) {
798 		proto &= ~UMASS_PROTO_WIRE;
799 		proto |= UMASS_PROTO_CBI;
800 	} else if (usb_test_quirk(uaa, UQ_MSC_FORCE_WIRE_CBI_I)) {
801 		proto &= ~UMASS_PROTO_WIRE;
802 		proto |= UMASS_PROTO_CBI_I;
803 	}
804 
805 	if (usb_test_quirk(uaa, UQ_MSC_FORCE_PROTO_SCSI)) {
806 		proto &= ~UMASS_PROTO_COMMAND;
807 		proto |= UMASS_PROTO_SCSI;
808 	} else if (usb_test_quirk(uaa, UQ_MSC_FORCE_PROTO_ATAPI)) {
809 		proto &= ~UMASS_PROTO_COMMAND;
810 		proto |= UMASS_PROTO_ATAPI;
811 	} else if (usb_test_quirk(uaa, UQ_MSC_FORCE_PROTO_UFI)) {
812 		proto &= ~UMASS_PROTO_COMMAND;
813 		proto |= UMASS_PROTO_UFI;
814 	} else if (usb_test_quirk(uaa, UQ_MSC_FORCE_PROTO_RBC)) {
815 		proto &= ~UMASS_PROTO_COMMAND;
816 		proto |= UMASS_PROTO_RBC;
817 	}
818 
819 	/* Check if the protocol is invalid */
820 
821 	if ((proto & UMASS_PROTO_COMMAND) == 0) {
822 		ret.error = ENXIO;
823 		goto done;
824 	}
825 
826 	if ((proto & UMASS_PROTO_WIRE) == 0) {
827 		ret.error = ENXIO;
828 		goto done;
829 	}
830 
831 	/* Search for quirks */
832 
833 	if (usb_test_quirk(uaa, UQ_MSC_NO_TEST_UNIT_READY))
834 		quirks |= NO_TEST_UNIT_READY;
835 	if (usb_test_quirk(uaa, UQ_MSC_NO_RS_CLEAR_UA))
836 		quirks |= RS_NO_CLEAR_UA;
837 	if (usb_test_quirk(uaa, UQ_MSC_NO_START_STOP))
838 		quirks |= NO_START_STOP;
839 	if (usb_test_quirk(uaa, UQ_MSC_NO_GETMAXLUN))
840 		quirks |= NO_GETMAXLUN;
841 	if (usb_test_quirk(uaa, UQ_MSC_NO_INQUIRY))
842 		quirks |= NO_INQUIRY;
843 	if (usb_test_quirk(uaa, UQ_MSC_NO_INQUIRY_EVPD))
844 		quirks |= NO_INQUIRY_EVPD;
845 	if (usb_test_quirk(uaa, UQ_MSC_NO_SYNC_CACHE))
846 		quirks |= NO_SYNCHRONIZE_CACHE;
847 	if (usb_test_quirk(uaa, UQ_MSC_SHUTTLE_INIT))
848 		quirks |= SHUTTLE_INIT;
849 	if (usb_test_quirk(uaa, UQ_MSC_ALT_IFACE_1))
850 		quirks |= ALT_IFACE_1;
851 	if (usb_test_quirk(uaa, UQ_MSC_FLOPPY_SPEED))
852 		quirks |= FLOPPY_SPEED;
853 	if (usb_test_quirk(uaa, UQ_MSC_IGNORE_RESIDUE))
854 		quirks |= IGNORE_RESIDUE;
855 	if (usb_test_quirk(uaa, UQ_MSC_WRONG_CSWSIG))
856 		quirks |= WRONG_CSWSIG;
857 	if (usb_test_quirk(uaa, UQ_MSC_RBC_PAD_TO_12))
858 		quirks |= RBC_PAD_TO_12;
859 	if (usb_test_quirk(uaa, UQ_MSC_READ_CAP_OFFBY1))
860 		quirks |= READ_CAPACITY_OFFBY1;
861 	if (usb_test_quirk(uaa, UQ_MSC_FORCE_SHORT_INQ))
862 		quirks |= FORCE_SHORT_INQUIRY;
863 
864 done:
865 	ret.quirks = quirks;
866 	ret.proto = proto;
867 	return (ret);
868 }
869 
870 static int
871 umass_probe(device_t dev)
872 {
873 	struct usb_attach_arg *uaa = device_get_ivars(dev);
874 	struct umass_probe_proto temp;
875 
876 	if (uaa->usb_mode != USB_MODE_HOST) {
877 		return (ENXIO);
878 	}
879 	temp = umass_probe_proto(dev, uaa);
880 
881 	return (temp.error);
882 }
883 
884 static int
885 umass_attach(device_t dev)
886 {
887 	struct umass_softc *sc = device_get_softc(dev);
888 	struct usb_attach_arg *uaa = device_get_ivars(dev);
889 	struct umass_probe_proto temp = umass_probe_proto(dev, uaa);
890 	struct usb_interface_descriptor *id;
891 	int32_t err;
892 
893 	/*
894 	 * NOTE: the softc struct is cleared in device_set_driver.
895 	 * We can safely call umass_detach without specifically
896 	 * initializing the struct.
897 	 */
898 
899 	sc->sc_dev = dev;
900 	sc->sc_udev = uaa->device;
901 	sc->sc_proto = temp.proto;
902 	sc->sc_quirks = temp.quirks;
903 	sc->sc_unit = device_get_unit(dev);
904 
905 	snprintf(sc->sc_name, sizeof(sc->sc_name),
906 	    "%s", device_get_nameunit(dev));
907 
908 	device_set_usb_desc(dev);
909 
910         mtx_init(&sc->sc_mtx, device_get_nameunit(dev),
911 	    NULL, MTX_DEF | MTX_RECURSE);
912 
913 	/* get interface index */
914 
915 	id = usbd_get_interface_descriptor(uaa->iface);
916 	if (id == NULL) {
917 		device_printf(dev, "failed to get "
918 		    "interface number\n");
919 		goto detach;
920 	}
921 	sc->sc_iface_no = id->bInterfaceNumber;
922 
923 #ifdef USB_DEBUG
924 	device_printf(dev, " ");
925 
926 	switch (sc->sc_proto & UMASS_PROTO_COMMAND) {
927 	case UMASS_PROTO_SCSI:
928 		printf("SCSI");
929 		break;
930 	case UMASS_PROTO_ATAPI:
931 		printf("8070i (ATAPI)");
932 		break;
933 	case UMASS_PROTO_UFI:
934 		printf("UFI");
935 		break;
936 	case UMASS_PROTO_RBC:
937 		printf("RBC");
938 		break;
939 	default:
940 		printf("(unknown 0x%02x)",
941 		    sc->sc_proto & UMASS_PROTO_COMMAND);
942 		break;
943 	}
944 
945 	printf(" over ");
946 
947 	switch (sc->sc_proto & UMASS_PROTO_WIRE) {
948 	case UMASS_PROTO_BBB:
949 		printf("Bulk-Only");
950 		break;
951 	case UMASS_PROTO_CBI:		/* uses Comand/Bulk pipes */
952 		printf("CBI");
953 		break;
954 	case UMASS_PROTO_CBI_I:	/* uses Comand/Bulk/Interrupt pipes */
955 		printf("CBI with CCI");
956 		break;
957 	default:
958 		printf("(unknown 0x%02x)",
959 		    sc->sc_proto & UMASS_PROTO_WIRE);
960 	}
961 
962 	printf("; quirks = 0x%04x\n", sc->sc_quirks);
963 #endif
964 
965 	if (sc->sc_quirks & ALT_IFACE_1) {
966 		err = usbd_set_alt_interface_index
967 		    (uaa->device, uaa->info.bIfaceIndex, 1);
968 
969 		if (err) {
970 			DPRINTF(sc, UDMASS_USB, "could not switch to "
971 			    "Alt Interface 1\n");
972 			goto detach;
973 		}
974 	}
975 	/* allocate all required USB transfers */
976 
977 	if (sc->sc_proto & UMASS_PROTO_BBB) {
978 
979 		err = usbd_transfer_setup(uaa->device,
980 		    &uaa->info.bIfaceIndex, sc->sc_xfer, umass_bbb_config,
981 		    UMASS_T_BBB_MAX, sc, &sc->sc_mtx);
982 
983 		/* skip reset first time */
984 		sc->sc_last_xfer_index = UMASS_T_BBB_COMMAND;
985 
986 	} else if (sc->sc_proto & (UMASS_PROTO_CBI | UMASS_PROTO_CBI_I)) {
987 
988 		err = usbd_transfer_setup(uaa->device,
989 		    &uaa->info.bIfaceIndex, sc->sc_xfer, umass_cbi_config,
990 		    UMASS_T_CBI_MAX, sc, &sc->sc_mtx);
991 
992 		/* skip reset first time */
993 		sc->sc_last_xfer_index = UMASS_T_CBI_COMMAND;
994 
995 	} else {
996 		err = USB_ERR_INVAL;
997 	}
998 
999 	if (err) {
1000 		device_printf(dev, "could not setup required "
1001 		    "transfers, %s\n", usbd_errstr(err));
1002 		goto detach;
1003 	}
1004 	sc->sc_transform =
1005 	    (sc->sc_proto & UMASS_PROTO_SCSI) ? &umass_scsi_transform :
1006 	    (sc->sc_proto & UMASS_PROTO_UFI) ? &umass_ufi_transform :
1007 	    (sc->sc_proto & UMASS_PROTO_ATAPI) ? &umass_atapi_transform :
1008 	    (sc->sc_proto & UMASS_PROTO_RBC) ? &umass_rbc_transform :
1009 	    &umass_no_transform;
1010 
1011 	/* from here onwards the device can be used. */
1012 
1013 	if (sc->sc_quirks & SHUTTLE_INIT) {
1014 		umass_init_shuttle(sc);
1015 	}
1016 	/* get the maximum LUN supported by the device */
1017 
1018 	if (((sc->sc_proto & UMASS_PROTO_WIRE) == UMASS_PROTO_BBB) &&
1019 	    !(sc->sc_quirks & NO_GETMAXLUN))
1020 		sc->sc_maxlun = umass_bbb_get_max_lun(sc);
1021 	else
1022 		sc->sc_maxlun = 0;
1023 
1024 	/* Prepare the SCSI command block */
1025 	sc->cam_scsi_sense.opcode = REQUEST_SENSE;
1026 	sc->cam_scsi_test_unit_ready.opcode = TEST_UNIT_READY;
1027 
1028 	/* register the SIM */
1029 	err = umass_cam_attach_sim(sc);
1030 	if (err) {
1031 		goto detach;
1032 	}
1033 	/* scan the SIM */
1034 	umass_cam_attach(sc);
1035 
1036 	DPRINTF(sc, UDMASS_GEN, "Attach finished\n");
1037 
1038 	return (0);			/* success */
1039 
1040 detach:
1041 	umass_detach(dev);
1042 	return (ENXIO);			/* failure */
1043 }
1044 
1045 static int
1046 umass_detach(device_t dev)
1047 {
1048 	struct umass_softc *sc = device_get_softc(dev);
1049 
1050 	DPRINTF(sc, UDMASS_USB, "\n");
1051 
1052 	/* teardown our statemachine */
1053 
1054 	usbd_transfer_unsetup(sc->sc_xfer, UMASS_T_MAX);
1055 
1056 #if (__FreeBSD_version >= 700037)
1057 	mtx_lock(&sc->sc_mtx);
1058 #endif
1059 	umass_cam_detach_sim(sc);
1060 
1061 #if (__FreeBSD_version >= 700037)
1062 	mtx_unlock(&sc->sc_mtx);
1063 #endif
1064 	mtx_destroy(&sc->sc_mtx);
1065 
1066 	return (0);			/* success */
1067 }
1068 
1069 static void
1070 umass_init_shuttle(struct umass_softc *sc)
1071 {
1072 	struct usb_device_request req;
1073 	usb_error_t err;
1074 	uint8_t status[2] = {0, 0};
1075 
1076 	/*
1077 	 * The Linux driver does this, but no one can tell us what the
1078 	 * command does.
1079 	 */
1080 	req.bmRequestType = UT_READ_VENDOR_DEVICE;
1081 	req.bRequest = 1;		/* XXX unknown command */
1082 	USETW(req.wValue, 0);
1083 	req.wIndex[0] = sc->sc_iface_no;
1084 	req.wIndex[1] = 0;
1085 	USETW(req.wLength, sizeof(status));
1086 	err = usbd_do_request(sc->sc_udev, NULL, &req, &status);
1087 
1088 	DPRINTF(sc, UDMASS_GEN, "Shuttle init returned 0x%02x%02x\n",
1089 	    status[0], status[1]);
1090 }
1091 
1092 /*
1093  * Generic functions to handle transfers
1094  */
1095 
1096 static void
1097 umass_transfer_start(struct umass_softc *sc, uint8_t xfer_index)
1098 {
1099 	DPRINTF(sc, UDMASS_GEN, "transfer index = "
1100 	    "%d\n", xfer_index);
1101 
1102 	if (sc->sc_xfer[xfer_index]) {
1103 		sc->sc_last_xfer_index = xfer_index;
1104 		usbd_transfer_start(sc->sc_xfer[xfer_index]);
1105 	} else {
1106 		umass_cancel_ccb(sc);
1107 	}
1108 }
1109 
1110 static void
1111 umass_reset(struct umass_softc *sc)
1112 {
1113 	DPRINTF(sc, UDMASS_GEN, "resetting device\n");
1114 
1115 	/*
1116 	 * stop the last transfer, if not already stopped:
1117 	 */
1118 	usbd_transfer_stop(sc->sc_xfer[sc->sc_last_xfer_index]);
1119 	umass_transfer_start(sc, 0);
1120 }
1121 
1122 static void
1123 umass_cancel_ccb(struct umass_softc *sc)
1124 {
1125 	union ccb *ccb;
1126 
1127 	mtx_assert(&sc->sc_mtx, MA_OWNED);
1128 
1129 	ccb = sc->sc_transfer.ccb;
1130 	sc->sc_transfer.ccb = NULL;
1131 	sc->sc_last_xfer_index = 0;
1132 
1133 	if (ccb) {
1134 		(sc->sc_transfer.callback)
1135 		    (sc, ccb, (sc->sc_transfer.data_len -
1136 		    sc->sc_transfer.actlen), STATUS_WIRE_FAILED);
1137 	}
1138 }
1139 
1140 static void
1141 umass_tr_error(struct usb_xfer *xfer, usb_error_t error)
1142 {
1143 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1144 
1145 	if (error != USB_ERR_CANCELLED) {
1146 
1147 		DPRINTF(sc, UDMASS_GEN, "transfer error, %s -> "
1148 		    "reset\n", usbd_errstr(error));
1149 	}
1150 	umass_cancel_ccb(sc);
1151 }
1152 
1153 /*
1154  * BBB protocol specific functions
1155  */
1156 
1157 static void
1158 umass_t_bbb_reset1_callback(struct usb_xfer *xfer, usb_error_t error)
1159 {
1160 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1161 	struct usb_device_request req;
1162 	struct usb_page_cache *pc;
1163 
1164 	switch (USB_GET_STATE(xfer)) {
1165 	case USB_ST_TRANSFERRED:
1166 		umass_transfer_start(sc, UMASS_T_BBB_RESET2);
1167 		return;
1168 
1169 	case USB_ST_SETUP:
1170 		/*
1171 		 * Reset recovery (5.3.4 in Universal Serial Bus Mass Storage Class)
1172 		 *
1173 		 * For Reset Recovery the host shall issue in the following order:
1174 		 * a) a Bulk-Only Mass Storage Reset
1175 		 * b) a Clear Feature HALT to the Bulk-In endpoint
1176 		 * c) a Clear Feature HALT to the Bulk-Out endpoint
1177 		 *
1178 		 * This is done in 3 steps, using 3 transfers:
1179 		 * UMASS_T_BBB_RESET1
1180 		 * UMASS_T_BBB_RESET2
1181 		 * UMASS_T_BBB_RESET3
1182 		 */
1183 
1184 		DPRINTF(sc, UDMASS_BBB, "BBB reset!\n");
1185 
1186 		req.bmRequestType = UT_WRITE_CLASS_INTERFACE;
1187 		req.bRequest = UR_BBB_RESET;	/* bulk only reset */
1188 		USETW(req.wValue, 0);
1189 		req.wIndex[0] = sc->sc_iface_no;
1190 		req.wIndex[1] = 0;
1191 		USETW(req.wLength, 0);
1192 
1193 		pc = usbd_xfer_get_frame(xfer, 0);
1194 		usbd_copy_in(pc, 0, &req, sizeof(req));
1195 
1196 		usbd_xfer_set_frame_len(xfer, 0, sizeof(req));
1197 		usbd_xfer_set_frames(xfer, 1);
1198 		usbd_transfer_submit(xfer);
1199 		return;
1200 
1201 	default:			/* Error */
1202 		umass_tr_error(xfer, error);
1203 		return;
1204 
1205 	}
1206 }
1207 
1208 static void
1209 umass_t_bbb_reset2_callback(struct usb_xfer *xfer, usb_error_t error)
1210 {
1211 	umass_t_bbb_data_clear_stall_callback(xfer, UMASS_T_BBB_RESET3,
1212 	    UMASS_T_BBB_DATA_READ, error);
1213 }
1214 
1215 static void
1216 umass_t_bbb_reset3_callback(struct usb_xfer *xfer, usb_error_t error)
1217 {
1218 	umass_t_bbb_data_clear_stall_callback(xfer, UMASS_T_BBB_COMMAND,
1219 	    UMASS_T_BBB_DATA_WRITE, error);
1220 }
1221 
1222 static void
1223 umass_t_bbb_data_clear_stall_callback(struct usb_xfer *xfer,
1224     uint8_t next_xfer, uint8_t stall_xfer, usb_error_t error)
1225 {
1226 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1227 
1228 	switch (USB_GET_STATE(xfer)) {
1229 	case USB_ST_TRANSFERRED:
1230 tr_transferred:
1231 		umass_transfer_start(sc, next_xfer);
1232 		return;
1233 
1234 	case USB_ST_SETUP:
1235 		if (usbd_clear_stall_callback(xfer, sc->sc_xfer[stall_xfer])) {
1236 			goto tr_transferred;
1237 		}
1238 		return;
1239 
1240 	default:			/* Error */
1241 		umass_tr_error(xfer, error);
1242 		return;
1243 
1244 	}
1245 }
1246 
1247 static void
1248 umass_t_bbb_command_callback(struct usb_xfer *xfer, usb_error_t error)
1249 {
1250 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1251 	union ccb *ccb = sc->sc_transfer.ccb;
1252 	struct usb_page_cache *pc;
1253 	uint32_t tag;
1254 
1255 	switch (USB_GET_STATE(xfer)) {
1256 	case USB_ST_TRANSFERRED:
1257 		umass_transfer_start
1258 		    (sc, ((sc->sc_transfer.dir == DIR_IN) ? UMASS_T_BBB_DATA_READ :
1259 		    (sc->sc_transfer.dir == DIR_OUT) ? UMASS_T_BBB_DATA_WRITE :
1260 		    UMASS_T_BBB_STATUS));
1261 		return;
1262 
1263 	case USB_ST_SETUP:
1264 
1265 		sc->sc_status_try = 0;
1266 
1267 		if (ccb) {
1268 
1269 			/*
1270 		         * the initial value is not important,
1271 		         * as long as the values are unique:
1272 		         */
1273 			tag = UGETDW(sc->cbw.dCBWTag) + 1;
1274 
1275 			USETDW(sc->cbw.dCBWSignature, CBWSIGNATURE);
1276 			USETDW(sc->cbw.dCBWTag, tag);
1277 
1278 			/*
1279 		         * dCBWDataTransferLength:
1280 		         *   This field indicates the number of bytes of data that the host
1281 		         *   intends to transfer on the IN or OUT Bulk endpoint(as indicated by
1282 		         *   the Direction bit) during the execution of this command. If this
1283 		         *   field is set to 0, the device will expect that no data will be
1284 		         *   transferred IN or OUT during this command, regardless of the value
1285 		         *   of the Direction bit defined in dCBWFlags.
1286 		         */
1287 			USETDW(sc->cbw.dCBWDataTransferLength, sc->sc_transfer.data_len);
1288 
1289 			/*
1290 		         * dCBWFlags:
1291 		         *   The bits of the Flags field are defined as follows:
1292 		         *     Bits 0-6  reserved
1293 		         *     Bit  7    Direction - this bit shall be ignored if the
1294 		         *                           dCBWDataTransferLength field is zero.
1295 		         *               0 = data Out from host to device
1296 		         *               1 = data In from device to host
1297 		         */
1298 			sc->cbw.bCBWFlags = ((sc->sc_transfer.dir == DIR_IN) ?
1299 			    CBWFLAGS_IN : CBWFLAGS_OUT);
1300 			sc->cbw.bCBWLUN = sc->sc_transfer.lun;
1301 
1302 			if (sc->sc_transfer.cmd_len > sizeof(sc->cbw.CBWCDB)) {
1303 				sc->sc_transfer.cmd_len = sizeof(sc->cbw.CBWCDB);
1304 				DPRINTF(sc, UDMASS_BBB, "Truncating long command!\n");
1305 			}
1306 			sc->cbw.bCDBLength = sc->sc_transfer.cmd_len;
1307 
1308 			memcpy(sc->cbw.CBWCDB, sc->sc_transfer.cmd_data,
1309 			    sc->sc_transfer.cmd_len);
1310 
1311 			memset(sc->sc_transfer.cmd_data +
1312 			    sc->sc_transfer.cmd_len, 0,
1313 			    sizeof(sc->cbw.CBWCDB) -
1314 			    sc->sc_transfer.cmd_len);
1315 
1316 			DIF(UDMASS_BBB, umass_bbb_dump_cbw(sc, &sc->cbw));
1317 
1318 			pc = usbd_xfer_get_frame(xfer, 0);
1319 			usbd_copy_in(pc, 0, &sc->cbw, sizeof(sc->cbw));
1320 			usbd_xfer_set_frame_len(xfer, 0, sizeof(sc->cbw));
1321 
1322 			usbd_transfer_submit(xfer);
1323 		}
1324 		return;
1325 
1326 	default:			/* Error */
1327 		umass_tr_error(xfer, error);
1328 		return;
1329 
1330 	}
1331 }
1332 
1333 static void
1334 umass_t_bbb_data_read_callback(struct usb_xfer *xfer, usb_error_t error)
1335 {
1336 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1337 	uint32_t max_bulk = usbd_xfer_max_len(xfer);
1338 #ifndef UMASS_EXT_BUFFER
1339 	struct usb_page_cache *pc;
1340 #endif
1341 	int actlen, sumlen;
1342 
1343 	usbd_xfer_status(xfer, &actlen, &sumlen, NULL, NULL);
1344 
1345 	switch (USB_GET_STATE(xfer)) {
1346 	case USB_ST_TRANSFERRED:
1347 #ifndef UMASS_EXT_BUFFER
1348 		pc = usbd_xfer_get_frame(xfer, 0);
1349 		usbd_copy_out(pc, 0, sc->sc_transfer.data_ptr, actlen);
1350 #endif
1351 		sc->sc_transfer.data_rem -= actlen;
1352 		sc->sc_transfer.data_ptr += actlen;
1353 		sc->sc_transfer.actlen += actlen;
1354 
1355 		if (actlen < sumlen) {
1356 			/* short transfer */
1357 			sc->sc_transfer.data_rem = 0;
1358 		}
1359 	case USB_ST_SETUP:
1360 		DPRINTF(sc, UDMASS_BBB, "max_bulk=%d, data_rem=%d\n",
1361 		    max_bulk, sc->sc_transfer.data_rem);
1362 
1363 		if (sc->sc_transfer.data_rem == 0) {
1364 			umass_transfer_start(sc, UMASS_T_BBB_STATUS);
1365 			return;
1366 		}
1367 		if (max_bulk > sc->sc_transfer.data_rem) {
1368 			max_bulk = sc->sc_transfer.data_rem;
1369 		}
1370 		usbd_xfer_set_timeout(xfer, sc->sc_transfer.data_timeout);
1371 
1372 #ifdef UMASS_EXT_BUFFER
1373 		usbd_xfer_set_frame_data(xfer, 0, sc->sc_transfer.data_ptr,
1374 		    max_bulk);
1375 #else
1376 		usbd_xfer_set_frame_len(xfer, 0, max_bulk);
1377 #endif
1378 		usbd_transfer_submit(xfer);
1379 		return;
1380 
1381 	default:			/* Error */
1382 		if (error == USB_ERR_CANCELLED) {
1383 			umass_tr_error(xfer, error);
1384 		} else {
1385 			umass_transfer_start(sc, UMASS_T_BBB_DATA_RD_CS);
1386 		}
1387 		return;
1388 
1389 	}
1390 }
1391 
1392 static void
1393 umass_t_bbb_data_rd_cs_callback(struct usb_xfer *xfer, usb_error_t error)
1394 {
1395 	umass_t_bbb_data_clear_stall_callback(xfer, UMASS_T_BBB_STATUS,
1396 	    UMASS_T_BBB_DATA_READ, error);
1397 }
1398 
1399 static void
1400 umass_t_bbb_data_write_callback(struct usb_xfer *xfer, usb_error_t error)
1401 {
1402 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1403 	uint32_t max_bulk = usbd_xfer_max_len(xfer);
1404 #ifndef UMASS_EXT_BUFFER
1405 	struct usb_page_cache *pc;
1406 #endif
1407 	int actlen, sumlen;
1408 
1409 	usbd_xfer_status(xfer, &actlen, &sumlen, NULL, NULL);
1410 
1411 	switch (USB_GET_STATE(xfer)) {
1412 	case USB_ST_TRANSFERRED:
1413 		sc->sc_transfer.data_rem -= actlen;
1414 		sc->sc_transfer.data_ptr += actlen;
1415 		sc->sc_transfer.actlen += actlen;
1416 
1417 		if (actlen < sumlen) {
1418 			/* short transfer */
1419 			sc->sc_transfer.data_rem = 0;
1420 		}
1421 	case USB_ST_SETUP:
1422 		DPRINTF(sc, UDMASS_BBB, "max_bulk=%d, data_rem=%d\n",
1423 		    max_bulk, sc->sc_transfer.data_rem);
1424 
1425 		if (sc->sc_transfer.data_rem == 0) {
1426 			umass_transfer_start(sc, UMASS_T_BBB_STATUS);
1427 			return;
1428 		}
1429 		if (max_bulk > sc->sc_transfer.data_rem) {
1430 			max_bulk = sc->sc_transfer.data_rem;
1431 		}
1432 		usbd_xfer_set_timeout(xfer, sc->sc_transfer.data_timeout);
1433 
1434 #ifdef UMASS_EXT_BUFFER
1435 		usbd_xfer_set_frame_data(xfer, 0, sc->sc_transfer.data_ptr,
1436 		    max_bulk);
1437 #else
1438 		pc = usbd_xfer_get_frame(xfer, 0);
1439 		usbd_copy_in(pc, 0, sc->sc_transfer.data_ptr, max_bulk);
1440 		usbd_xfer_set_frame_len(xfer, 0, max_bulk);
1441 #endif
1442 
1443 		usbd_transfer_submit(xfer);
1444 		return;
1445 
1446 	default:			/* Error */
1447 		if (error == USB_ERR_CANCELLED) {
1448 			umass_tr_error(xfer, error);
1449 		} else {
1450 			umass_transfer_start(sc, UMASS_T_BBB_DATA_WR_CS);
1451 		}
1452 		return;
1453 
1454 	}
1455 }
1456 
1457 static void
1458 umass_t_bbb_data_wr_cs_callback(struct usb_xfer *xfer, usb_error_t error)
1459 {
1460 	umass_t_bbb_data_clear_stall_callback(xfer, UMASS_T_BBB_STATUS,
1461 	    UMASS_T_BBB_DATA_WRITE, error);
1462 }
1463 
1464 static void
1465 umass_t_bbb_status_callback(struct usb_xfer *xfer, usb_error_t error)
1466 {
1467 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1468 	union ccb *ccb = sc->sc_transfer.ccb;
1469 	struct usb_page_cache *pc;
1470 	uint32_t residue;
1471 	int actlen;
1472 
1473 	usbd_xfer_status(xfer, &actlen, NULL, NULL, NULL);
1474 
1475 	switch (USB_GET_STATE(xfer)) {
1476 	case USB_ST_TRANSFERRED:
1477 
1478 		/*
1479 		 * Do a full reset if there is something wrong with the CSW:
1480 		 */
1481 		sc->sc_status_try = 1;
1482 
1483 		/* Zero missing parts of the CSW: */
1484 
1485 		if (actlen < sizeof(sc->csw))
1486 			memset(&sc->csw, 0, sizeof(sc->csw));
1487 
1488 		pc = usbd_xfer_get_frame(xfer, 0);
1489 		usbd_copy_out(pc, 0, &sc->csw, actlen);
1490 
1491 		DIF(UDMASS_BBB, umass_bbb_dump_csw(sc, &sc->csw));
1492 
1493 		residue = UGETDW(sc->csw.dCSWDataResidue);
1494 
1495 		if ((!residue) || (sc->sc_quirks & IGNORE_RESIDUE)) {
1496 			residue = (sc->sc_transfer.data_len -
1497 			    sc->sc_transfer.actlen);
1498 		}
1499 		if (residue > sc->sc_transfer.data_len) {
1500 			DPRINTF(sc, UDMASS_BBB, "truncating residue from %d "
1501 			    "to %d bytes\n", residue, sc->sc_transfer.data_len);
1502 			residue = sc->sc_transfer.data_len;
1503 		}
1504 		/* translate weird command-status signatures: */
1505 		if (sc->sc_quirks & WRONG_CSWSIG) {
1506 
1507 			uint32_t temp = UGETDW(sc->csw.dCSWSignature);
1508 
1509 			if ((temp == CSWSIGNATURE_OLYMPUS_C1) ||
1510 			    (temp == CSWSIGNATURE_IMAGINATION_DBX1)) {
1511 				USETDW(sc->csw.dCSWSignature, CSWSIGNATURE);
1512 			}
1513 		}
1514 		/* check CSW and handle eventual error */
1515 		if (UGETDW(sc->csw.dCSWSignature) != CSWSIGNATURE) {
1516 			DPRINTF(sc, UDMASS_BBB, "bad CSW signature 0x%08x != 0x%08x\n",
1517 			    UGETDW(sc->csw.dCSWSignature), CSWSIGNATURE);
1518 			/*
1519 			 * Invalid CSW: Wrong signature or wrong tag might
1520 			 * indicate that we lost synchronization. Reset the
1521 			 * device.
1522 			 */
1523 			goto tr_error;
1524 		} else if (UGETDW(sc->csw.dCSWTag) != UGETDW(sc->cbw.dCBWTag)) {
1525 			DPRINTF(sc, UDMASS_BBB, "Invalid CSW: tag 0x%08x should be "
1526 			    "0x%08x\n", UGETDW(sc->csw.dCSWTag),
1527 			    UGETDW(sc->cbw.dCBWTag));
1528 			goto tr_error;
1529 		} else if (sc->csw.bCSWStatus > CSWSTATUS_PHASE) {
1530 			DPRINTF(sc, UDMASS_BBB, "Invalid CSW: status %d > %d\n",
1531 			    sc->csw.bCSWStatus, CSWSTATUS_PHASE);
1532 			goto tr_error;
1533 		} else if (sc->csw.bCSWStatus == CSWSTATUS_PHASE) {
1534 			DPRINTF(sc, UDMASS_BBB, "Phase error, residue = "
1535 			    "%d\n", residue);
1536 			goto tr_error;
1537 		} else if (sc->sc_transfer.actlen > sc->sc_transfer.data_len) {
1538 			DPRINTF(sc, UDMASS_BBB, "Buffer overrun %d > %d\n",
1539 			    sc->sc_transfer.actlen, sc->sc_transfer.data_len);
1540 			goto tr_error;
1541 		} else if (sc->csw.bCSWStatus == CSWSTATUS_FAILED) {
1542 			DPRINTF(sc, UDMASS_BBB, "Command failed, residue = "
1543 			    "%d\n", residue);
1544 
1545 			sc->sc_transfer.ccb = NULL;
1546 
1547 			sc->sc_last_xfer_index = UMASS_T_BBB_COMMAND;
1548 
1549 			(sc->sc_transfer.callback)
1550 			    (sc, ccb, residue, STATUS_CMD_FAILED);
1551 		} else {
1552 			sc->sc_transfer.ccb = NULL;
1553 
1554 			sc->sc_last_xfer_index = UMASS_T_BBB_COMMAND;
1555 
1556 			(sc->sc_transfer.callback)
1557 			    (sc, ccb, residue, STATUS_CMD_OK);
1558 		}
1559 		return;
1560 
1561 	case USB_ST_SETUP:
1562 		usbd_xfer_set_frame_len(xfer, 0, usbd_xfer_max_len(xfer));
1563 		usbd_transfer_submit(xfer);
1564 		return;
1565 
1566 	default:
1567 tr_error:
1568 		DPRINTF(sc, UDMASS_BBB, "Failed to read CSW: %s, try %d\n",
1569 		    usbd_errstr(error), sc->sc_status_try);
1570 
1571 		if ((error == USB_ERR_CANCELLED) ||
1572 		    (sc->sc_status_try)) {
1573 			umass_tr_error(xfer, error);
1574 		} else {
1575 			sc->sc_status_try = 1;
1576 			umass_transfer_start(sc, UMASS_T_BBB_DATA_RD_CS);
1577 		}
1578 		return;
1579 
1580 	}
1581 }
1582 
1583 static void
1584 umass_command_start(struct umass_softc *sc, uint8_t dir,
1585     void *data_ptr, uint32_t data_len,
1586     uint32_t data_timeout, umass_callback_t *callback,
1587     union ccb *ccb)
1588 {
1589 	sc->sc_transfer.lun = ccb->ccb_h.target_lun;
1590 
1591 	/*
1592 	 * NOTE: assumes that "sc->sc_transfer.cmd_data" and
1593 	 * "sc->sc_transfer.cmd_len" has been properly
1594 	 * initialized.
1595 	 */
1596 
1597 	sc->sc_transfer.dir = data_len ? dir : DIR_NONE;
1598 	sc->sc_transfer.data_ptr = data_ptr;
1599 	sc->sc_transfer.data_len = data_len;
1600 	sc->sc_transfer.data_rem = data_len;
1601 	sc->sc_transfer.data_timeout = (data_timeout + UMASS_TIMEOUT);
1602 
1603 	sc->sc_transfer.actlen = 0;
1604 	sc->sc_transfer.callback = callback;
1605 	sc->sc_transfer.ccb = ccb;
1606 
1607 	if (sc->sc_xfer[sc->sc_last_xfer_index]) {
1608 		usbd_transfer_start(sc->sc_xfer[sc->sc_last_xfer_index]);
1609 	} else {
1610 		ccb->ccb_h.status = CAM_TID_INVALID;
1611 		xpt_done(ccb);
1612 	}
1613 }
1614 
1615 static uint8_t
1616 umass_bbb_get_max_lun(struct umass_softc *sc)
1617 {
1618 	struct usb_device_request req;
1619 	usb_error_t err;
1620 	uint8_t buf = 0;
1621 
1622 	/* The Get Max Lun command is a class-specific request. */
1623 	req.bmRequestType = UT_READ_CLASS_INTERFACE;
1624 	req.bRequest = UR_BBB_GET_MAX_LUN;
1625 	USETW(req.wValue, 0);
1626 	req.wIndex[0] = sc->sc_iface_no;
1627 	req.wIndex[1] = 0;
1628 	USETW(req.wLength, 1);
1629 
1630 	err = usbd_do_request(sc->sc_udev, NULL, &req, &buf);
1631 	if (err) {
1632 		buf = 0;
1633 
1634 		/* Device doesn't support Get Max Lun request. */
1635 		printf("%s: Get Max Lun not supported (%s)\n",
1636 		    sc->sc_name, usbd_errstr(err));
1637 	}
1638 	return (buf);
1639 }
1640 
1641 /*
1642  * Command/Bulk/Interrupt (CBI) specific functions
1643  */
1644 
1645 static void
1646 umass_cbi_start_status(struct umass_softc *sc)
1647 {
1648 	if (sc->sc_xfer[UMASS_T_CBI_STATUS]) {
1649 		umass_transfer_start(sc, UMASS_T_CBI_STATUS);
1650 	} else {
1651 		union ccb *ccb = sc->sc_transfer.ccb;
1652 
1653 		sc->sc_transfer.ccb = NULL;
1654 
1655 		sc->sc_last_xfer_index = UMASS_T_CBI_COMMAND;
1656 
1657 		(sc->sc_transfer.callback)
1658 		    (sc, ccb, (sc->sc_transfer.data_len -
1659 		    sc->sc_transfer.actlen), STATUS_CMD_UNKNOWN);
1660 	}
1661 }
1662 
1663 static void
1664 umass_t_cbi_reset1_callback(struct usb_xfer *xfer, usb_error_t error)
1665 {
1666 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1667 	struct usb_device_request req;
1668 	struct usb_page_cache *pc;
1669 	uint8_t buf[UMASS_CBI_DIAGNOSTIC_CMDLEN];
1670 
1671 	uint8_t i;
1672 
1673 	switch (USB_GET_STATE(xfer)) {
1674 	case USB_ST_TRANSFERRED:
1675 		umass_transfer_start(sc, UMASS_T_CBI_RESET2);
1676 		break;
1677 
1678 	case USB_ST_SETUP:
1679 		/*
1680 		 * Command Block Reset Protocol
1681 		 *
1682 		 * First send a reset request to the device. Then clear
1683 		 * any possibly stalled bulk endpoints.
1684 		 *
1685 		 * This is done in 3 steps, using 3 transfers:
1686 		 * UMASS_T_CBI_RESET1
1687 		 * UMASS_T_CBI_RESET2
1688 		 * UMASS_T_CBI_RESET3
1689 		 * UMASS_T_CBI_RESET4 (only if there is an interrupt endpoint)
1690 		 */
1691 
1692 		DPRINTF(sc, UDMASS_CBI, "CBI reset!\n");
1693 
1694 		req.bmRequestType = UT_WRITE_CLASS_INTERFACE;
1695 		req.bRequest = UR_CBI_ADSC;
1696 		USETW(req.wValue, 0);
1697 		req.wIndex[0] = sc->sc_iface_no;
1698 		req.wIndex[1] = 0;
1699 		USETW(req.wLength, UMASS_CBI_DIAGNOSTIC_CMDLEN);
1700 
1701 		/*
1702 		 * The 0x1d code is the SEND DIAGNOSTIC command. To
1703 		 * distinguish between the two, the last 10 bytes of the CBL
1704 		 * is filled with 0xff (section 2.2 of the CBI
1705 		 * specification)
1706 		 */
1707 		buf[0] = 0x1d;		/* Command Block Reset */
1708 		buf[1] = 0x04;
1709 
1710 		for (i = 2; i < UMASS_CBI_DIAGNOSTIC_CMDLEN; i++) {
1711 			buf[i] = 0xff;
1712 		}
1713 
1714 		pc = usbd_xfer_get_frame(xfer, 0);
1715 		usbd_copy_in(pc, 0, &req, sizeof(req));
1716 		pc = usbd_xfer_get_frame(xfer, 1);
1717 		usbd_copy_in(pc, 0, buf, sizeof(buf));
1718 
1719 		usbd_xfer_set_frame_len(xfer, 0, sizeof(req));
1720 		usbd_xfer_set_frame_len(xfer, 1, sizeof(buf));
1721 		usbd_xfer_set_frames(xfer, 2);
1722 		usbd_transfer_submit(xfer);
1723 		break;
1724 
1725 	default:			/* Error */
1726 		if (error == USB_ERR_CANCELLED)
1727 			umass_tr_error(xfer, error);
1728 		else
1729 			umass_transfer_start(sc, UMASS_T_CBI_RESET2);
1730 		break;
1731 
1732 	}
1733 }
1734 
1735 static void
1736 umass_t_cbi_reset2_callback(struct usb_xfer *xfer, usb_error_t error)
1737 {
1738 	umass_t_cbi_data_clear_stall_callback(xfer, UMASS_T_CBI_RESET3,
1739 	    UMASS_T_CBI_DATA_READ, error);
1740 }
1741 
1742 static void
1743 umass_t_cbi_reset3_callback(struct usb_xfer *xfer, usb_error_t error)
1744 {
1745 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1746 
1747 	umass_t_cbi_data_clear_stall_callback
1748 	    (xfer, (sc->sc_xfer[UMASS_T_CBI_RESET4] &&
1749 	    sc->sc_xfer[UMASS_T_CBI_STATUS]) ?
1750 	    UMASS_T_CBI_RESET4 : UMASS_T_CBI_COMMAND,
1751 	    UMASS_T_CBI_DATA_WRITE, error);
1752 }
1753 
1754 static void
1755 umass_t_cbi_reset4_callback(struct usb_xfer *xfer, usb_error_t error)
1756 {
1757 	umass_t_cbi_data_clear_stall_callback(xfer, UMASS_T_CBI_COMMAND,
1758 	    UMASS_T_CBI_STATUS, error);
1759 }
1760 
1761 static void
1762 umass_t_cbi_data_clear_stall_callback(struct usb_xfer *xfer,
1763     uint8_t next_xfer, uint8_t stall_xfer, usb_error_t error)
1764 {
1765 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1766 
1767 	switch (USB_GET_STATE(xfer)) {
1768 	case USB_ST_TRANSFERRED:
1769 tr_transferred:
1770 		if (next_xfer == UMASS_T_CBI_STATUS) {
1771 			umass_cbi_start_status(sc);
1772 		} else {
1773 			umass_transfer_start(sc, next_xfer);
1774 		}
1775 		break;
1776 
1777 	case USB_ST_SETUP:
1778 		if (usbd_clear_stall_callback(xfer, sc->sc_xfer[stall_xfer])) {
1779 			goto tr_transferred;	/* should not happen */
1780 		}
1781 		break;
1782 
1783 	default:			/* Error */
1784 		umass_tr_error(xfer, error);
1785 		break;
1786 
1787 	}
1788 }
1789 
1790 static void
1791 umass_t_cbi_command_callback(struct usb_xfer *xfer, usb_error_t error)
1792 {
1793 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1794 	union ccb *ccb = sc->sc_transfer.ccb;
1795 	struct usb_device_request req;
1796 	struct usb_page_cache *pc;
1797 
1798 	switch (USB_GET_STATE(xfer)) {
1799 	case USB_ST_TRANSFERRED:
1800 
1801 		if (sc->sc_transfer.dir == DIR_NONE) {
1802 			umass_cbi_start_status(sc);
1803 		} else {
1804 			umass_transfer_start
1805 			    (sc, (sc->sc_transfer.dir == DIR_IN) ?
1806 			    UMASS_T_CBI_DATA_READ : UMASS_T_CBI_DATA_WRITE);
1807 		}
1808 		break;
1809 
1810 	case USB_ST_SETUP:
1811 
1812 		if (ccb) {
1813 
1814 			/*
1815 		         * do a CBI transfer with cmd_len bytes from
1816 		         * cmd_data, possibly a data phase of data_len
1817 		         * bytes from/to the device and finally a status
1818 		         * read phase.
1819 		         */
1820 
1821 			req.bmRequestType = UT_WRITE_CLASS_INTERFACE;
1822 			req.bRequest = UR_CBI_ADSC;
1823 			USETW(req.wValue, 0);
1824 			req.wIndex[0] = sc->sc_iface_no;
1825 			req.wIndex[1] = 0;
1826 			req.wLength[0] = sc->sc_transfer.cmd_len;
1827 			req.wLength[1] = 0;
1828 
1829 			pc = usbd_xfer_get_frame(xfer, 0);
1830 			usbd_copy_in(pc, 0, &req, sizeof(req));
1831 			pc = usbd_xfer_get_frame(xfer, 1);
1832 			usbd_copy_in(pc, 0, sc->sc_transfer.cmd_data,
1833 			    sc->sc_transfer.cmd_len);
1834 
1835 			usbd_xfer_set_frame_len(xfer, 0, sizeof(req));
1836 			usbd_xfer_set_frame_len(xfer, 1, sc->sc_transfer.cmd_len);
1837 			usbd_xfer_set_frames(xfer,
1838 			    sc->sc_transfer.cmd_len ? 2 : 1);
1839 
1840 			DIF(UDMASS_CBI,
1841 			    umass_cbi_dump_cmd(sc,
1842 			    sc->sc_transfer.cmd_data,
1843 			    sc->sc_transfer.cmd_len));
1844 
1845 			usbd_transfer_submit(xfer);
1846 		}
1847 		break;
1848 
1849 	default:			/* Error */
1850 		/*
1851 		 * STALL on the control pipe can be result of the command error.
1852 		 * Attempt to clear this STALL same as for bulk pipe also
1853 		 * results in command completion interrupt, but ASC/ASCQ there
1854 		 * look like not always valid, so don't bother about it.
1855 		 */
1856 		if ((error == USB_ERR_STALLED) ||
1857 		    (sc->sc_transfer.callback == &umass_cam_cb)) {
1858 			sc->sc_transfer.ccb = NULL;
1859 			(sc->sc_transfer.callback)
1860 			    (sc, ccb, sc->sc_transfer.data_len,
1861 			    STATUS_CMD_UNKNOWN);
1862 		} else {
1863 			umass_tr_error(xfer, error);
1864 			/* skip reset */
1865 			sc->sc_last_xfer_index = UMASS_T_CBI_COMMAND;
1866 		}
1867 		break;
1868 	}
1869 }
1870 
1871 static void
1872 umass_t_cbi_data_read_callback(struct usb_xfer *xfer, usb_error_t error)
1873 {
1874 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1875 	uint32_t max_bulk = usbd_xfer_max_len(xfer);
1876 #ifndef UMASS_EXT_BUFFER
1877 	struct usb_page_cache *pc;
1878 #endif
1879 	int actlen, sumlen;
1880 
1881 	usbd_xfer_status(xfer, &actlen, &sumlen, NULL, NULL);
1882 
1883 	switch (USB_GET_STATE(xfer)) {
1884 	case USB_ST_TRANSFERRED:
1885 #ifndef UMASS_EXT_BUFFER
1886 		pc = usbd_xfer_get_frame(xfer, 0);
1887 		usbd_copy_out(pc, 0, sc->sc_transfer.data_ptr, actlen);
1888 #endif
1889 		sc->sc_transfer.data_rem -= actlen;
1890 		sc->sc_transfer.data_ptr += actlen;
1891 		sc->sc_transfer.actlen += actlen;
1892 
1893 		if (actlen < sumlen) {
1894 			/* short transfer */
1895 			sc->sc_transfer.data_rem = 0;
1896 		}
1897 	case USB_ST_SETUP:
1898 		DPRINTF(sc, UDMASS_CBI, "max_bulk=%d, data_rem=%d\n",
1899 		    max_bulk, sc->sc_transfer.data_rem);
1900 
1901 		if (sc->sc_transfer.data_rem == 0) {
1902 			umass_cbi_start_status(sc);
1903 			break;
1904 		}
1905 		if (max_bulk > sc->sc_transfer.data_rem) {
1906 			max_bulk = sc->sc_transfer.data_rem;
1907 		}
1908 		usbd_xfer_set_timeout(xfer, sc->sc_transfer.data_timeout);
1909 
1910 #ifdef UMASS_EXT_BUFFER
1911 		usbd_xfer_set_frame_data(xfer, 0, sc->sc_transfer.data_ptr,
1912 		    max_bulk);
1913 #else
1914 		usbd_xfer_set_frame_len(xfer, 0, max_bulk);
1915 #endif
1916 		usbd_transfer_submit(xfer);
1917 		break;
1918 
1919 	default:			/* Error */
1920 		if ((error == USB_ERR_CANCELLED) ||
1921 		    (sc->sc_transfer.callback != &umass_cam_cb)) {
1922 			umass_tr_error(xfer, error);
1923 		} else {
1924 			umass_transfer_start(sc, UMASS_T_CBI_DATA_RD_CS);
1925 		}
1926 		break;
1927 
1928 	}
1929 }
1930 
1931 static void
1932 umass_t_cbi_data_rd_cs_callback(struct usb_xfer *xfer, usb_error_t error)
1933 {
1934 	umass_t_cbi_data_clear_stall_callback(xfer, UMASS_T_CBI_STATUS,
1935 	    UMASS_T_CBI_DATA_READ, error);
1936 }
1937 
1938 static void
1939 umass_t_cbi_data_write_callback(struct usb_xfer *xfer, usb_error_t error)
1940 {
1941 	struct umass_softc *sc = usbd_xfer_softc(xfer);
1942 	uint32_t max_bulk = usbd_xfer_max_len(xfer);
1943 #ifndef UMASS_EXT_BUFFER
1944 	struct usb_page_cache *pc;
1945 #endif
1946 	int actlen, sumlen;
1947 
1948 	usbd_xfer_status(xfer, &actlen, &sumlen, NULL, NULL);
1949 
1950 	switch (USB_GET_STATE(xfer)) {
1951 	case USB_ST_TRANSFERRED:
1952 		sc->sc_transfer.data_rem -= actlen;
1953 		sc->sc_transfer.data_ptr += actlen;
1954 		sc->sc_transfer.actlen += actlen;
1955 
1956 		if (actlen < sumlen) {
1957 			/* short transfer */
1958 			sc->sc_transfer.data_rem = 0;
1959 		}
1960 	case USB_ST_SETUP:
1961 		DPRINTF(sc, UDMASS_CBI, "max_bulk=%d, data_rem=%d\n",
1962 		    max_bulk, sc->sc_transfer.data_rem);
1963 
1964 		if (sc->sc_transfer.data_rem == 0) {
1965 			umass_cbi_start_status(sc);
1966 			break;
1967 		}
1968 		if (max_bulk > sc->sc_transfer.data_rem) {
1969 			max_bulk = sc->sc_transfer.data_rem;
1970 		}
1971 		usbd_xfer_set_timeout(xfer, sc->sc_transfer.data_timeout);
1972 
1973 #ifdef UMASS_EXT_BUFFER
1974 		usbd_xfer_set_frame_data(xfer, 0, sc->sc_transfer.data_ptr,
1975 		    max_bulk);
1976 #else
1977 		pc = usbd_xfer_get_frame(xfer, 0);
1978 		usbd_copy_in(pc, 0, sc->sc_transfer.data_ptr, max_bulk);
1979 		usbd_xfer_set_frame_len(xfer, 0, max_bulk);
1980 #endif
1981 
1982 		usbd_transfer_submit(xfer);
1983 		break;
1984 
1985 	default:			/* Error */
1986 		if ((error == USB_ERR_CANCELLED) ||
1987 		    (sc->sc_transfer.callback != &umass_cam_cb)) {
1988 			umass_tr_error(xfer, error);
1989 		} else {
1990 			umass_transfer_start(sc, UMASS_T_CBI_DATA_WR_CS);
1991 		}
1992 		break;
1993 
1994 	}
1995 }
1996 
1997 static void
1998 umass_t_cbi_data_wr_cs_callback(struct usb_xfer *xfer, usb_error_t error)
1999 {
2000 	umass_t_cbi_data_clear_stall_callback(xfer, UMASS_T_CBI_STATUS,
2001 	    UMASS_T_CBI_DATA_WRITE, error);
2002 }
2003 
2004 static void
2005 umass_t_cbi_status_callback(struct usb_xfer *xfer, usb_error_t error)
2006 {
2007 	struct umass_softc *sc = usbd_xfer_softc(xfer);
2008 	union ccb *ccb = sc->sc_transfer.ccb;
2009 	struct usb_page_cache *pc;
2010 	uint32_t residue;
2011 	uint8_t status;
2012 	int actlen;
2013 
2014 	usbd_xfer_status(xfer, &actlen, NULL, NULL, NULL);
2015 
2016 	switch (USB_GET_STATE(xfer)) {
2017 	case USB_ST_TRANSFERRED:
2018 
2019 		if (actlen < sizeof(sc->sbl)) {
2020 			goto tr_setup;
2021 		}
2022 		pc = usbd_xfer_get_frame(xfer, 0);
2023 		usbd_copy_out(pc, 0, &sc->sbl, sizeof(sc->sbl));
2024 
2025 		residue = (sc->sc_transfer.data_len -
2026 		    sc->sc_transfer.actlen);
2027 
2028 		/* dissect the information in the buffer */
2029 
2030 		if (sc->sc_proto & UMASS_PROTO_UFI) {
2031 
2032 			/*
2033 			 * Section 3.4.3.1.3 specifies that the UFI command
2034 			 * protocol returns an ASC and ASCQ in the interrupt
2035 			 * data block.
2036 			 */
2037 
2038 			DPRINTF(sc, UDMASS_CBI, "UFI CCI, ASC = 0x%02x, "
2039 			    "ASCQ = 0x%02x\n", sc->sbl.ufi.asc,
2040 			    sc->sbl.ufi.ascq);
2041 
2042 			status = (((sc->sbl.ufi.asc == 0) &&
2043 			    (sc->sbl.ufi.ascq == 0)) ?
2044 			    STATUS_CMD_OK : STATUS_CMD_FAILED);
2045 
2046 			sc->sc_transfer.ccb = NULL;
2047 
2048 			sc->sc_last_xfer_index = UMASS_T_CBI_COMMAND;
2049 
2050 			(sc->sc_transfer.callback)
2051 			    (sc, ccb, residue, status);
2052 
2053 			break;
2054 
2055 		} else {
2056 
2057 			/* Command Interrupt Data Block */
2058 
2059 			DPRINTF(sc, UDMASS_CBI, "type=0x%02x, value=0x%02x\n",
2060 			    sc->sbl.common.type, sc->sbl.common.value);
2061 
2062 			if (sc->sbl.common.type == IDB_TYPE_CCI) {
2063 
2064 				status = (sc->sbl.common.value & IDB_VALUE_STATUS_MASK);
2065 
2066 				status = ((status == IDB_VALUE_PASS) ? STATUS_CMD_OK :
2067 				    (status == IDB_VALUE_FAIL) ? STATUS_CMD_FAILED :
2068 				    (status == IDB_VALUE_PERSISTENT) ? STATUS_CMD_FAILED :
2069 				    STATUS_WIRE_FAILED);
2070 
2071 				sc->sc_transfer.ccb = NULL;
2072 
2073 				sc->sc_last_xfer_index = UMASS_T_CBI_COMMAND;
2074 
2075 				(sc->sc_transfer.callback)
2076 				    (sc, ccb, residue, status);
2077 
2078 				break;
2079 			}
2080 		}
2081 
2082 		/* fallthrough */
2083 
2084 	case USB_ST_SETUP:
2085 tr_setup:
2086 		usbd_xfer_set_frame_len(xfer, 0, usbd_xfer_max_len(xfer));
2087 		usbd_transfer_submit(xfer);
2088 		break;
2089 
2090 	default:			/* Error */
2091 		DPRINTF(sc, UDMASS_CBI, "Failed to read CSW: %s\n",
2092 		    usbd_errstr(error));
2093 		umass_tr_error(xfer, error);
2094 		break;
2095 
2096 	}
2097 }
2098 
2099 /*
2100  * CAM specific functions (used by SCSI, UFI, 8070i (ATAPI))
2101  */
2102 
2103 static int
2104 umass_cam_attach_sim(struct umass_softc *sc)
2105 {
2106 	struct cam_devq *devq;		/* Per device Queue */
2107 
2108 	/*
2109 	 * A HBA is attached to the CAM layer.
2110 	 *
2111 	 * The CAM layer will then after a while start probing for devices on
2112 	 * the bus. The number of SIMs is limited to one.
2113 	 */
2114 
2115 	devq = cam_simq_alloc(1 /* maximum openings */ );
2116 	if (devq == NULL) {
2117 		return (ENOMEM);
2118 	}
2119 	sc->sc_sim = cam_sim_alloc
2120 	    (&umass_cam_action, &umass_cam_poll,
2121 	    DEVNAME_SIM,
2122 	    sc /* priv */ ,
2123 	    sc->sc_unit /* unit number */ ,
2124 #if (__FreeBSD_version >= 700037)
2125 	    &sc->sc_mtx /* mutex */ ,
2126 #endif
2127 	    1 /* maximum device openings */ ,
2128 	    0 /* maximum tagged device openings */ ,
2129 	    devq);
2130 
2131 	if (sc->sc_sim == NULL) {
2132 		cam_simq_free(devq);
2133 		return (ENOMEM);
2134 	}
2135 
2136 #if (__FreeBSD_version >= 700037)
2137 	mtx_lock(&sc->sc_mtx);
2138 #endif
2139 
2140 #if (__FreeBSD_version >= 700048)
2141 	if (xpt_bus_register(sc->sc_sim, sc->sc_dev, sc->sc_unit) != CAM_SUCCESS) {
2142 		mtx_unlock(&sc->sc_mtx);
2143 		return (ENOMEM);
2144 	}
2145 #else
2146 	if (xpt_bus_register(sc->sc_sim, sc->sc_unit) != CAM_SUCCESS) {
2147 #if (__FreeBSD_version >= 700037)
2148 		mtx_unlock(&sc->sc_mtx);
2149 #endif
2150 		return (ENOMEM);
2151 	}
2152 #endif
2153 
2154 #if (__FreeBSD_version >= 700037)
2155 	mtx_unlock(&sc->sc_mtx);
2156 #endif
2157 	return (0);
2158 }
2159 
2160 static void
2161 umass_cam_attach(struct umass_softc *sc)
2162 {
2163 #ifndef USB_DEBUG
2164 	if (bootverbose)
2165 #endif
2166 		printf("%s:%d:%d:%d: Attached to scbus%d\n",
2167 		    sc->sc_name, cam_sim_path(sc->sc_sim),
2168 		    sc->sc_unit, CAM_LUN_WILDCARD,
2169 		    cam_sim_path(sc->sc_sim));
2170 }
2171 
2172 /* umass_cam_detach
2173  *	detach from the CAM layer
2174  */
2175 
2176 static void
2177 umass_cam_detach_sim(struct umass_softc *sc)
2178 {
2179 	if (sc->sc_sim != NULL) {
2180 		if (xpt_bus_deregister(cam_sim_path(sc->sc_sim))) {
2181 			/* accessing the softc is not possible after this */
2182 			sc->sc_sim->softc = UMASS_GONE;
2183 			cam_sim_free(sc->sc_sim, /* free_devq */ TRUE);
2184 		} else {
2185 			panic("%s: CAM layer is busy\n",
2186 			    sc->sc_name);
2187 		}
2188 		sc->sc_sim = NULL;
2189 	}
2190 }
2191 
2192 /* umass_cam_action
2193  * 	CAM requests for action come through here
2194  */
2195 
2196 static void
2197 umass_cam_action(struct cam_sim *sim, union ccb *ccb)
2198 {
2199 	struct umass_softc *sc = (struct umass_softc *)sim->softc;
2200 
2201 	if (sc == UMASS_GONE ||
2202 	    (sc != NULL && !usbd_device_attached(sc->sc_udev))) {
2203 		ccb->ccb_h.status = CAM_SEL_TIMEOUT;
2204 		xpt_done(ccb);
2205 		return;
2206 	}
2207 	if (sc) {
2208 #if (__FreeBSD_version < 700037)
2209 		mtx_lock(&sc->sc_mtx);
2210 #endif
2211 	}
2212 	/*
2213 	 * Verify, depending on the operation to perform, that we either got
2214 	 * a valid sc, because an existing target was referenced, or
2215 	 * otherwise the SIM is addressed.
2216 	 *
2217 	 * This avoids bombing out at a printf and does give the CAM layer some
2218 	 * sensible feedback on errors.
2219 	 */
2220 	switch (ccb->ccb_h.func_code) {
2221 	case XPT_SCSI_IO:
2222 	case XPT_RESET_DEV:
2223 	case XPT_GET_TRAN_SETTINGS:
2224 	case XPT_SET_TRAN_SETTINGS:
2225 	case XPT_CALC_GEOMETRY:
2226 		/* the opcodes requiring a target. These should never occur. */
2227 		if (sc == NULL) {
2228 			DPRINTF(sc, UDMASS_GEN, "%s:%d:%d:%d:func_code 0x%04x: "
2229 			    "Invalid target (target needed)\n",
2230 			    DEVNAME_SIM, cam_sim_path(sc->sc_sim),
2231 			    ccb->ccb_h.target_id, ccb->ccb_h.target_lun,
2232 			    ccb->ccb_h.func_code);
2233 
2234 			ccb->ccb_h.status = CAM_TID_INVALID;
2235 			xpt_done(ccb);
2236 			goto done;
2237 		}
2238 		break;
2239 	case XPT_PATH_INQ:
2240 	case XPT_NOOP:
2241 		/*
2242 		 * The opcodes sometimes aimed at a target (sc is valid),
2243 		 * sometimes aimed at the SIM (sc is invalid and target is
2244 		 * CAM_TARGET_WILDCARD)
2245 		 */
2246 		if ((sc == NULL) &&
2247 		    (ccb->ccb_h.target_id != CAM_TARGET_WILDCARD)) {
2248 			DPRINTF(sc, UDMASS_SCSI, "%s:%d:%d:%d:func_code 0x%04x: "
2249 			    "Invalid target (no wildcard)\n",
2250 			    DEVNAME_SIM, cam_sim_path(sc->sc_sim),
2251 			    ccb->ccb_h.target_id, ccb->ccb_h.target_lun,
2252 			    ccb->ccb_h.func_code);
2253 
2254 			ccb->ccb_h.status = CAM_TID_INVALID;
2255 			xpt_done(ccb);
2256 			goto done;
2257 		}
2258 		break;
2259 	default:
2260 		/* XXX Hm, we should check the input parameters */
2261 		break;
2262 	}
2263 
2264 	/* Perform the requested action */
2265 	switch (ccb->ccb_h.func_code) {
2266 	case XPT_SCSI_IO:
2267 		{
2268 			uint8_t *cmd;
2269 			uint8_t dir;
2270 
2271 			if (ccb->csio.ccb_h.flags & CAM_CDB_POINTER) {
2272 				cmd = (uint8_t *)(ccb->csio.cdb_io.cdb_ptr);
2273 			} else {
2274 				cmd = (uint8_t *)(ccb->csio.cdb_io.cdb_bytes);
2275 			}
2276 
2277 			DPRINTF(sc, UDMASS_SCSI, "%d:%d:%d:XPT_SCSI_IO: "
2278 			    "cmd: 0x%02x, flags: 0x%02x, "
2279 			    "%db cmd/%db data/%db sense\n",
2280 			    cam_sim_path(sc->sc_sim), ccb->ccb_h.target_id,
2281 			    ccb->ccb_h.target_lun, cmd[0],
2282 			    ccb->ccb_h.flags & CAM_DIR_MASK, ccb->csio.cdb_len,
2283 			    ccb->csio.dxfer_len, ccb->csio.sense_len);
2284 
2285 			if (sc->sc_transfer.ccb) {
2286 				DPRINTF(sc, UDMASS_SCSI, "%d:%d:%d:XPT_SCSI_IO: "
2287 				    "I/O in progress, deferring\n",
2288 				    cam_sim_path(sc->sc_sim), ccb->ccb_h.target_id,
2289 				    ccb->ccb_h.target_lun);
2290 				ccb->ccb_h.status = CAM_SCSI_BUSY;
2291 				xpt_done(ccb);
2292 				goto done;
2293 			}
2294 			switch (ccb->ccb_h.flags & CAM_DIR_MASK) {
2295 			case CAM_DIR_IN:
2296 				dir = DIR_IN;
2297 				break;
2298 			case CAM_DIR_OUT:
2299 				dir = DIR_OUT;
2300 				DIF(UDMASS_SCSI,
2301 				    umass_dump_buffer(sc, ccb->csio.data_ptr,
2302 				    ccb->csio.dxfer_len, 48));
2303 				break;
2304 			default:
2305 				dir = DIR_NONE;
2306 			}
2307 
2308 			ccb->ccb_h.status = CAM_REQ_INPROG | CAM_SIM_QUEUED;
2309 
2310 			/*
2311 			 * sc->sc_transform will convert the command to the
2312 			 * command format needed by the specific command set
2313 			 * and return the converted command in
2314 			 * "sc->sc_transfer.cmd_data"
2315 			 */
2316 			if (umass_std_transform(sc, ccb, cmd, ccb->csio.cdb_len)) {
2317 
2318 				if (sc->sc_transfer.cmd_data[0] == INQUIRY) {
2319 					const char *pserial;
2320 
2321 					pserial = usb_get_serial(sc->sc_udev);
2322 
2323 					/*
2324 					 * Umass devices don't generally report their serial numbers
2325 					 * in the usual SCSI way.  Emulate it here.
2326 					 */
2327 					if ((sc->sc_transfer.cmd_data[1] & SI_EVPD) &&
2328 					    (sc->sc_transfer.cmd_data[2] == SVPD_UNIT_SERIAL_NUMBER) &&
2329 					    (pserial[0] != '\0')) {
2330 						struct scsi_vpd_unit_serial_number *vpd_serial;
2331 
2332 						vpd_serial = (struct scsi_vpd_unit_serial_number *)ccb->csio.data_ptr;
2333 						vpd_serial->length = strlen(pserial);
2334 						if (vpd_serial->length > sizeof(vpd_serial->serial_num))
2335 							vpd_serial->length = sizeof(vpd_serial->serial_num);
2336 						memcpy(vpd_serial->serial_num, pserial, vpd_serial->length);
2337 						ccb->csio.scsi_status = SCSI_STATUS_OK;
2338 						ccb->ccb_h.status = CAM_REQ_CMP;
2339 						xpt_done(ccb);
2340 						goto done;
2341 					}
2342 
2343 					/*
2344 					 * Handle EVPD inquiry for broken devices first
2345 					 * NO_INQUIRY also implies NO_INQUIRY_EVPD
2346 					 */
2347 					if ((sc->sc_quirks & (NO_INQUIRY_EVPD | NO_INQUIRY)) &&
2348 					    (sc->sc_transfer.cmd_data[1] & SI_EVPD)) {
2349 
2350 						scsi_set_sense_data(&ccb->csio.sense_data,
2351 							/*sense_format*/ SSD_TYPE_NONE,
2352 							/*current_error*/ 1,
2353 							/*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
2354 							/*asc*/ 0x24,
2355 							/*ascq*/ 0x00,
2356 							/*extra args*/ SSD_ELEM_NONE);
2357 						ccb->csio.scsi_status = SCSI_STATUS_CHECK_COND;
2358 						ccb->ccb_h.status = CAM_SCSI_STATUS_ERROR |
2359 						    CAM_AUTOSNS_VALID;
2360 						xpt_done(ccb);
2361 						goto done;
2362 					}
2363 					/*
2364 					 * Return fake inquiry data for
2365 					 * broken devices
2366 					 */
2367 					if (sc->sc_quirks & NO_INQUIRY) {
2368 						memcpy(ccb->csio.data_ptr, &fake_inq_data,
2369 						    sizeof(fake_inq_data));
2370 						ccb->csio.scsi_status = SCSI_STATUS_OK;
2371 						ccb->ccb_h.status = CAM_REQ_CMP;
2372 						xpt_done(ccb);
2373 						goto done;
2374 					}
2375 					if (sc->sc_quirks & FORCE_SHORT_INQUIRY) {
2376 						ccb->csio.dxfer_len = SHORT_INQUIRY_LENGTH;
2377 					}
2378 				} else if (sc->sc_transfer.cmd_data[0] == SYNCHRONIZE_CACHE) {
2379 					if (sc->sc_quirks & NO_SYNCHRONIZE_CACHE) {
2380 						ccb->csio.scsi_status = SCSI_STATUS_OK;
2381 						ccb->ccb_h.status = CAM_REQ_CMP;
2382 						xpt_done(ccb);
2383 						goto done;
2384 					}
2385 				}
2386 				umass_command_start(sc, dir, ccb->csio.data_ptr,
2387 				    ccb->csio.dxfer_len,
2388 				    ccb->ccb_h.timeout,
2389 				    &umass_cam_cb, ccb);
2390 			}
2391 			break;
2392 		}
2393 	case XPT_PATH_INQ:
2394 		{
2395 			struct ccb_pathinq *cpi = &ccb->cpi;
2396 
2397 			DPRINTF(sc, UDMASS_SCSI, "%d:%d:%d:XPT_PATH_INQ:.\n",
2398 			    sc ? cam_sim_path(sc->sc_sim) : -1, ccb->ccb_h.target_id,
2399 			    ccb->ccb_h.target_lun);
2400 
2401 			/* host specific information */
2402 			cpi->version_num = 1;
2403 			cpi->hba_inquiry = 0;
2404 			cpi->target_sprt = 0;
2405 			cpi->hba_misc = PIM_NO_6_BYTE;
2406 			cpi->hba_eng_cnt = 0;
2407 			cpi->max_target = UMASS_SCSIID_MAX;	/* one target */
2408 			cpi->initiator_id = UMASS_SCSIID_HOST;
2409 			strlcpy(cpi->sim_vid, "FreeBSD", SIM_IDLEN);
2410 			strlcpy(cpi->hba_vid, "USB SCSI", HBA_IDLEN);
2411 			strlcpy(cpi->dev_name, cam_sim_name(sim), DEV_IDLEN);
2412 			cpi->unit_number = cam_sim_unit(sim);
2413 			cpi->bus_id = sc->sc_unit;
2414 #if (__FreeBSD_version >= 700025)
2415 			cpi->protocol = PROTO_SCSI;
2416 			cpi->protocol_version = SCSI_REV_2;
2417 			cpi->transport = XPORT_USB;
2418 			cpi->transport_version = 0;
2419 #endif
2420 			if (sc == NULL) {
2421 				cpi->base_transfer_speed = 0;
2422 				cpi->max_lun = 0;
2423 			} else {
2424 				if (sc->sc_quirks & FLOPPY_SPEED) {
2425 					cpi->base_transfer_speed =
2426 					    UMASS_FLOPPY_TRANSFER_SPEED;
2427 				} else {
2428 					switch (usbd_get_speed(sc->sc_udev)) {
2429 					case USB_SPEED_SUPER:
2430 						cpi->base_transfer_speed =
2431 						    UMASS_SUPER_TRANSFER_SPEED;
2432 						cpi->maxio = MAXPHYS;
2433 						break;
2434 					case USB_SPEED_HIGH:
2435 						cpi->base_transfer_speed =
2436 						    UMASS_HIGH_TRANSFER_SPEED;
2437 						break;
2438 					default:
2439 						cpi->base_transfer_speed =
2440 						    UMASS_FULL_TRANSFER_SPEED;
2441 						break;
2442 					}
2443 				}
2444 				cpi->max_lun = sc->sc_maxlun;
2445 			}
2446 
2447 			cpi->ccb_h.status = CAM_REQ_CMP;
2448 			xpt_done(ccb);
2449 			break;
2450 		}
2451 	case XPT_RESET_DEV:
2452 		{
2453 			DPRINTF(sc, UDMASS_SCSI, "%d:%d:%d:XPT_RESET_DEV:.\n",
2454 			    cam_sim_path(sc->sc_sim), ccb->ccb_h.target_id,
2455 			    ccb->ccb_h.target_lun);
2456 
2457 			umass_reset(sc);
2458 
2459 			ccb->ccb_h.status = CAM_REQ_CMP;
2460 			xpt_done(ccb);
2461 			break;
2462 		}
2463 	case XPT_GET_TRAN_SETTINGS:
2464 		{
2465 			struct ccb_trans_settings *cts = &ccb->cts;
2466 
2467 			DPRINTF(sc, UDMASS_SCSI, "%d:%d:%d:XPT_GET_TRAN_SETTINGS:.\n",
2468 			    cam_sim_path(sc->sc_sim), ccb->ccb_h.target_id,
2469 			    ccb->ccb_h.target_lun);
2470 
2471 #if (__FreeBSD_version >= 700025)
2472 			cts->protocol = PROTO_SCSI;
2473 			cts->protocol_version = SCSI_REV_2;
2474 			cts->transport = XPORT_USB;
2475 			cts->transport_version = 0;
2476 			cts->xport_specific.valid = 0;
2477 #else
2478 			cts->valid = 0;
2479 			cts->flags = 0;	/* no disconnection, tagging */
2480 #endif
2481 			ccb->ccb_h.status = CAM_REQ_CMP;
2482 			xpt_done(ccb);
2483 			break;
2484 		}
2485 	case XPT_SET_TRAN_SETTINGS:
2486 		{
2487 			DPRINTF(sc, UDMASS_SCSI, "%d:%d:%d:XPT_SET_TRAN_SETTINGS:.\n",
2488 			    cam_sim_path(sc->sc_sim), ccb->ccb_h.target_id,
2489 			    ccb->ccb_h.target_lun);
2490 
2491 			ccb->ccb_h.status = CAM_FUNC_NOTAVAIL;
2492 			xpt_done(ccb);
2493 			break;
2494 		}
2495 	case XPT_CALC_GEOMETRY:
2496 		{
2497 			cam_calc_geometry(&ccb->ccg, /* extended */ 1);
2498 			xpt_done(ccb);
2499 			break;
2500 		}
2501 	case XPT_NOOP:
2502 		{
2503 			DPRINTF(sc, UDMASS_SCSI, "%d:%d:%d:XPT_NOOP:.\n",
2504 			    sc ? cam_sim_path(sc->sc_sim) : -1, ccb->ccb_h.target_id,
2505 			    ccb->ccb_h.target_lun);
2506 
2507 			ccb->ccb_h.status = CAM_REQ_CMP;
2508 			xpt_done(ccb);
2509 			break;
2510 		}
2511 	default:
2512 		DPRINTF(sc, UDMASS_SCSI, "%d:%d:%d:func_code 0x%04x: "
2513 		    "Not implemented\n",
2514 		    sc ? cam_sim_path(sc->sc_sim) : -1, ccb->ccb_h.target_id,
2515 		    ccb->ccb_h.target_lun, ccb->ccb_h.func_code);
2516 
2517 		ccb->ccb_h.status = CAM_FUNC_NOTAVAIL;
2518 		xpt_done(ccb);
2519 		break;
2520 	}
2521 
2522 done:
2523 #if (__FreeBSD_version < 700037)
2524 	if (sc) {
2525 		mtx_unlock(&sc->sc_mtx);
2526 	}
2527 #endif
2528 	return;
2529 }
2530 
2531 static void
2532 umass_cam_poll(struct cam_sim *sim)
2533 {
2534 	struct umass_softc *sc = (struct umass_softc *)sim->softc;
2535 
2536 	if (sc == UMASS_GONE)
2537 		return;
2538 
2539 	DPRINTF(sc, UDMASS_SCSI, "CAM poll\n");
2540 
2541 	usbd_transfer_poll(sc->sc_xfer, UMASS_T_MAX);
2542 }
2543 
2544 
2545 /* umass_cam_cb
2546  *	finalise a completed CAM command
2547  */
2548 
2549 static void
2550 umass_cam_cb(struct umass_softc *sc, union ccb *ccb, uint32_t residue,
2551     uint8_t status)
2552 {
2553 	ccb->csio.resid = residue;
2554 
2555 	switch (status) {
2556 	case STATUS_CMD_OK:
2557 		ccb->ccb_h.status = CAM_REQ_CMP;
2558 		if ((sc->sc_quirks & READ_CAPACITY_OFFBY1) &&
2559 		    (ccb->ccb_h.func_code == XPT_SCSI_IO) &&
2560 		    (ccb->csio.cdb_io.cdb_bytes[0] == READ_CAPACITY)) {
2561 			struct scsi_read_capacity_data *rcap;
2562 			uint32_t maxsector;
2563 
2564 			rcap = (void *)(ccb->csio.data_ptr);
2565 			maxsector = scsi_4btoul(rcap->addr) - 1;
2566 			scsi_ulto4b(maxsector, rcap->addr);
2567 		}
2568 		/*
2569 		 * We have to add SVPD_UNIT_SERIAL_NUMBER to the list
2570 		 * of pages supported by the device - otherwise, CAM
2571 		 * will never ask us for the serial number if the
2572 		 * device cannot handle that by itself.
2573 		 */
2574 		if (ccb->ccb_h.func_code == XPT_SCSI_IO &&
2575 		    sc->sc_transfer.cmd_data[0] == INQUIRY &&
2576 		    (sc->sc_transfer.cmd_data[1] & SI_EVPD) &&
2577 		    sc->sc_transfer.cmd_data[2] == SVPD_SUPPORTED_PAGE_LIST &&
2578 		    (usb_get_serial(sc->sc_udev)[0] != '\0')) {
2579 			struct ccb_scsiio *csio;
2580 			struct scsi_vpd_supported_page_list *page_list;
2581 
2582 			csio = &ccb->csio;
2583 			page_list = (struct scsi_vpd_supported_page_list *)csio->data_ptr;
2584 			if (page_list->length + 1 < SVPD_SUPPORTED_PAGES_SIZE) {
2585 				page_list->list[page_list->length] = SVPD_UNIT_SERIAL_NUMBER;
2586 				page_list->length++;
2587 			}
2588 		}
2589 		xpt_done(ccb);
2590 		break;
2591 
2592 	case STATUS_CMD_UNKNOWN:
2593 	case STATUS_CMD_FAILED:
2594 
2595 		/* fetch sense data */
2596 
2597 		/* the rest of the command was filled in at attach */
2598 		sc->cam_scsi_sense.length = ccb->csio.sense_len;
2599 
2600 		DPRINTF(sc, UDMASS_SCSI, "Fetching %d bytes of "
2601 		    "sense data\n", ccb->csio.sense_len);
2602 
2603 		if (umass_std_transform(sc, ccb, &sc->cam_scsi_sense.opcode,
2604 		    sizeof(sc->cam_scsi_sense))) {
2605 
2606 			if ((sc->sc_quirks & FORCE_SHORT_INQUIRY) &&
2607 			    (sc->sc_transfer.cmd_data[0] == INQUIRY)) {
2608 				ccb->csio.sense_len = SHORT_INQUIRY_LENGTH;
2609 			}
2610 			umass_command_start(sc, DIR_IN, &ccb->csio.sense_data.error_code,
2611 			    ccb->csio.sense_len, ccb->ccb_h.timeout,
2612 			    &umass_cam_sense_cb, ccb);
2613 		}
2614 		break;
2615 
2616 	default:
2617 		/*
2618 		 * The wire protocol failed and will hopefully have
2619 		 * recovered. We return an error to CAM and let CAM
2620 		 * retry the command if necessary.
2621 		 */
2622 		ccb->ccb_h.status = CAM_REQ_CMP_ERR;
2623 		xpt_done(ccb);
2624 		break;
2625 	}
2626 }
2627 
2628 /*
2629  * Finalise a completed autosense operation
2630  */
2631 static void
2632 umass_cam_sense_cb(struct umass_softc *sc, union ccb *ccb, uint32_t residue,
2633     uint8_t status)
2634 {
2635 	uint8_t *cmd;
2636 
2637 	switch (status) {
2638 	case STATUS_CMD_OK:
2639 	case STATUS_CMD_UNKNOWN:
2640 	case STATUS_CMD_FAILED: {
2641 		int key, sense_len;
2642 
2643 		ccb->csio.sense_resid = residue;
2644 		sense_len = ccb->csio.sense_len - ccb->csio.sense_resid;
2645 		key = scsi_get_sense_key(&ccb->csio.sense_data, sense_len,
2646 					 /*show_errors*/ 1);
2647 
2648 		if (ccb->csio.ccb_h.flags & CAM_CDB_POINTER) {
2649 			cmd = (uint8_t *)(ccb->csio.cdb_io.cdb_ptr);
2650 		} else {
2651 			cmd = (uint8_t *)(ccb->csio.cdb_io.cdb_bytes);
2652 		}
2653 
2654 		/*
2655 		 * Getting sense data always succeeds (apart from wire
2656 		 * failures):
2657 		 */
2658 		if ((sc->sc_quirks & RS_NO_CLEAR_UA) &&
2659 		    (cmd[0] == INQUIRY) &&
2660 		    (key == SSD_KEY_UNIT_ATTENTION)) {
2661 			/*
2662 			 * Ignore unit attention errors in the case where
2663 			 * the Unit Attention state is not cleared on
2664 			 * REQUEST SENSE. They will appear again at the next
2665 			 * command.
2666 			 */
2667 			ccb->ccb_h.status = CAM_REQ_CMP;
2668 		} else if (key == SSD_KEY_NO_SENSE) {
2669 			/*
2670 			 * No problem after all (in the case of CBI without
2671 			 * CCI)
2672 			 */
2673 			ccb->ccb_h.status = CAM_REQ_CMP;
2674 		} else if ((sc->sc_quirks & RS_NO_CLEAR_UA) &&
2675 			    (cmd[0] == READ_CAPACITY) &&
2676 		    (key == SSD_KEY_UNIT_ATTENTION)) {
2677 			/*
2678 			 * Some devices do not clear the unit attention error
2679 			 * on request sense. We insert a test unit ready
2680 			 * command to make sure we clear the unit attention
2681 			 * condition, then allow the retry to proceed as
2682 			 * usual.
2683 			 */
2684 
2685 			ccb->ccb_h.status = CAM_SCSI_STATUS_ERROR
2686 			    | CAM_AUTOSNS_VALID;
2687 			ccb->csio.scsi_status = SCSI_STATUS_CHECK_COND;
2688 
2689 #if 0
2690 			DELAY(300000);
2691 #endif
2692 			DPRINTF(sc, UDMASS_SCSI, "Doing a sneaky"
2693 			    "TEST_UNIT_READY\n");
2694 
2695 			/* the rest of the command was filled in at attach */
2696 
2697 			if (umass_std_transform(sc, ccb,
2698 			    &sc->cam_scsi_test_unit_ready.opcode,
2699 			    sizeof(sc->cam_scsi_test_unit_ready))) {
2700 				umass_command_start(sc, DIR_NONE, NULL, 0,
2701 				    ccb->ccb_h.timeout,
2702 				    &umass_cam_quirk_cb, ccb);
2703 			}
2704 			break;
2705 		} else {
2706 			ccb->ccb_h.status = CAM_SCSI_STATUS_ERROR
2707 			    | CAM_AUTOSNS_VALID;
2708 			ccb->csio.scsi_status = SCSI_STATUS_CHECK_COND;
2709 		}
2710 		xpt_done(ccb);
2711 		break;
2712 	}
2713 	default:
2714 		DPRINTF(sc, UDMASS_SCSI, "Autosense failed, "
2715 		    "status %d\n", status);
2716 		ccb->ccb_h.status = CAM_AUTOSENSE_FAIL;
2717 		xpt_done(ccb);
2718 	}
2719 }
2720 
2721 /*
2722  * This completion code just handles the fact that we sent a test-unit-ready
2723  * after having previously failed a READ CAPACITY with CHECK_COND.  Even
2724  * though this command succeeded, we have to tell CAM to retry.
2725  */
2726 static void
2727 umass_cam_quirk_cb(struct umass_softc *sc, union ccb *ccb, uint32_t residue,
2728     uint8_t status)
2729 {
2730 	DPRINTF(sc, UDMASS_SCSI, "Test unit ready "
2731 	    "returned status %d\n", status);
2732 
2733 	ccb->ccb_h.status = CAM_SCSI_STATUS_ERROR
2734 	    | CAM_AUTOSNS_VALID;
2735 	ccb->csio.scsi_status = SCSI_STATUS_CHECK_COND;
2736 	xpt_done(ccb);
2737 }
2738 
2739 /*
2740  * SCSI specific functions
2741  */
2742 
2743 static uint8_t
2744 umass_scsi_transform(struct umass_softc *sc, uint8_t *cmd_ptr,
2745     uint8_t cmd_len)
2746 {
2747 	if ((cmd_len == 0) ||
2748 	    (cmd_len > sizeof(sc->sc_transfer.cmd_data))) {
2749 		DPRINTF(sc, UDMASS_SCSI, "Invalid command "
2750 		    "length: %d bytes\n", cmd_len);
2751 		return (0);		/* failure */
2752 	}
2753 	sc->sc_transfer.cmd_len = cmd_len;
2754 
2755 	switch (cmd_ptr[0]) {
2756 	case TEST_UNIT_READY:
2757 		if (sc->sc_quirks & NO_TEST_UNIT_READY) {
2758 			DPRINTF(sc, UDMASS_SCSI, "Converted TEST_UNIT_READY "
2759 			    "to START_UNIT\n");
2760 			memset(sc->sc_transfer.cmd_data, 0, cmd_len);
2761 			sc->sc_transfer.cmd_data[0] = START_STOP_UNIT;
2762 			sc->sc_transfer.cmd_data[4] = SSS_START;
2763 			return (1);
2764 		}
2765 		break;
2766 
2767 	case INQUIRY:
2768 		/*
2769 		 * some drives wedge when asked for full inquiry
2770 		 * information.
2771 		 */
2772 		if (sc->sc_quirks & FORCE_SHORT_INQUIRY) {
2773 			memcpy(sc->sc_transfer.cmd_data, cmd_ptr, cmd_len);
2774 			sc->sc_transfer.cmd_data[4] = SHORT_INQUIRY_LENGTH;
2775 			return (1);
2776 		}
2777 		break;
2778 	}
2779 
2780 	memcpy(sc->sc_transfer.cmd_data, cmd_ptr, cmd_len);
2781 	return (1);
2782 }
2783 
2784 static uint8_t
2785 umass_rbc_transform(struct umass_softc *sc, uint8_t *cmd_ptr, uint8_t cmd_len)
2786 {
2787 	if ((cmd_len == 0) ||
2788 	    (cmd_len > sizeof(sc->sc_transfer.cmd_data))) {
2789 		DPRINTF(sc, UDMASS_SCSI, "Invalid command "
2790 		    "length: %d bytes\n", cmd_len);
2791 		return (0);		/* failure */
2792 	}
2793 	switch (cmd_ptr[0]) {
2794 		/* these commands are defined in RBC: */
2795 	case READ_10:
2796 	case READ_CAPACITY:
2797 	case START_STOP_UNIT:
2798 	case SYNCHRONIZE_CACHE:
2799 	case WRITE_10:
2800 	case 0x2f:			/* VERIFY_10 is absent from
2801 					 * scsi_all.h??? */
2802 	case INQUIRY:
2803 	case MODE_SELECT_10:
2804 	case MODE_SENSE_10:
2805 	case TEST_UNIT_READY:
2806 	case WRITE_BUFFER:
2807 		/*
2808 		 * The following commands are not listed in my copy of the
2809 		 * RBC specs. CAM however seems to want those, and at least
2810 		 * the Sony DSC device appears to support those as well
2811 		 */
2812 	case REQUEST_SENSE:
2813 	case PREVENT_ALLOW:
2814 
2815 		memcpy(sc->sc_transfer.cmd_data, cmd_ptr, cmd_len);
2816 
2817 		if ((sc->sc_quirks & RBC_PAD_TO_12) && (cmd_len < 12)) {
2818 			memset(sc->sc_transfer.cmd_data + cmd_len,
2819 			    0, 12 - cmd_len);
2820 			cmd_len = 12;
2821 		}
2822 		sc->sc_transfer.cmd_len = cmd_len;
2823 		return (1);		/* sucess */
2824 
2825 		/* All other commands are not legal in RBC */
2826 	default:
2827 		DPRINTF(sc, UDMASS_SCSI, "Unsupported RBC "
2828 		    "command 0x%02x\n", cmd_ptr[0]);
2829 		return (0);		/* failure */
2830 	}
2831 }
2832 
2833 static uint8_t
2834 umass_ufi_transform(struct umass_softc *sc, uint8_t *cmd_ptr,
2835     uint8_t cmd_len)
2836 {
2837 	if ((cmd_len == 0) ||
2838 	    (cmd_len > sizeof(sc->sc_transfer.cmd_data))) {
2839 		DPRINTF(sc, UDMASS_SCSI, "Invalid command "
2840 		    "length: %d bytes\n", cmd_len);
2841 		return (0);		/* failure */
2842 	}
2843 	/* An UFI command is always 12 bytes in length */
2844 	sc->sc_transfer.cmd_len = UFI_COMMAND_LENGTH;
2845 
2846 	/* Zero the command data */
2847 	memset(sc->sc_transfer.cmd_data, 0, UFI_COMMAND_LENGTH);
2848 
2849 	switch (cmd_ptr[0]) {
2850 		/*
2851 		 * Commands of which the format has been verified. They
2852 		 * should work. Copy the command into the (zeroed out)
2853 		 * destination buffer.
2854 		 */
2855 	case TEST_UNIT_READY:
2856 		if (sc->sc_quirks & NO_TEST_UNIT_READY) {
2857 			/*
2858 			 * Some devices do not support this command. Start
2859 			 * Stop Unit should give the same results
2860 			 */
2861 			DPRINTF(sc, UDMASS_UFI, "Converted TEST_UNIT_READY "
2862 			    "to START_UNIT\n");
2863 
2864 			sc->sc_transfer.cmd_data[0] = START_STOP_UNIT;
2865 			sc->sc_transfer.cmd_data[4] = SSS_START;
2866 			return (1);
2867 		}
2868 		break;
2869 
2870 	case REZERO_UNIT:
2871 	case REQUEST_SENSE:
2872 	case FORMAT_UNIT:
2873 	case INQUIRY:
2874 	case START_STOP_UNIT:
2875 	case SEND_DIAGNOSTIC:
2876 	case PREVENT_ALLOW:
2877 	case READ_CAPACITY:
2878 	case READ_10:
2879 	case WRITE_10:
2880 	case POSITION_TO_ELEMENT:	/* SEEK_10 */
2881 	case WRITE_AND_VERIFY:
2882 	case VERIFY:
2883 	case MODE_SELECT_10:
2884 	case MODE_SENSE_10:
2885 	case READ_12:
2886 	case WRITE_12:
2887 	case READ_FORMAT_CAPACITIES:
2888 		break;
2889 
2890 		/*
2891 		 * SYNCHRONIZE_CACHE isn't supported by UFI, nor should it be
2892 		 * required for UFI devices, so it is appropriate to fake
2893 		 * success.
2894 		 */
2895 	case SYNCHRONIZE_CACHE:
2896 		return (2);
2897 
2898 	default:
2899 		DPRINTF(sc, UDMASS_SCSI, "Unsupported UFI "
2900 		    "command 0x%02x\n", cmd_ptr[0]);
2901 		return (0);		/* failure */
2902 	}
2903 
2904 	memcpy(sc->sc_transfer.cmd_data, cmd_ptr, cmd_len);
2905 	return (1);			/* success */
2906 }
2907 
2908 /*
2909  * 8070i (ATAPI) specific functions
2910  */
2911 static uint8_t
2912 umass_atapi_transform(struct umass_softc *sc, uint8_t *cmd_ptr,
2913     uint8_t cmd_len)
2914 {
2915 	if ((cmd_len == 0) ||
2916 	    (cmd_len > sizeof(sc->sc_transfer.cmd_data))) {
2917 		DPRINTF(sc, UDMASS_SCSI, "Invalid command "
2918 		    "length: %d bytes\n", cmd_len);
2919 		return (0);		/* failure */
2920 	}
2921 	/* An ATAPI command is always 12 bytes in length. */
2922 	sc->sc_transfer.cmd_len = ATAPI_COMMAND_LENGTH;
2923 
2924 	/* Zero the command data */
2925 	memset(sc->sc_transfer.cmd_data, 0, ATAPI_COMMAND_LENGTH);
2926 
2927 	switch (cmd_ptr[0]) {
2928 		/*
2929 		 * Commands of which the format has been verified. They
2930 		 * should work. Copy the command into the destination
2931 		 * buffer.
2932 		 */
2933 	case INQUIRY:
2934 		/*
2935 		 * some drives wedge when asked for full inquiry
2936 		 * information.
2937 		 */
2938 		if (sc->sc_quirks & FORCE_SHORT_INQUIRY) {
2939 			memcpy(sc->sc_transfer.cmd_data, cmd_ptr, cmd_len);
2940 
2941 			sc->sc_transfer.cmd_data[4] = SHORT_INQUIRY_LENGTH;
2942 			return (1);
2943 		}
2944 		break;
2945 
2946 	case TEST_UNIT_READY:
2947 		if (sc->sc_quirks & NO_TEST_UNIT_READY) {
2948 			DPRINTF(sc, UDMASS_SCSI, "Converted TEST_UNIT_READY "
2949 			    "to START_UNIT\n");
2950 			sc->sc_transfer.cmd_data[0] = START_STOP_UNIT;
2951 			sc->sc_transfer.cmd_data[4] = SSS_START;
2952 			return (1);
2953 		}
2954 		break;
2955 
2956 	case REZERO_UNIT:
2957 	case REQUEST_SENSE:
2958 	case START_STOP_UNIT:
2959 	case SEND_DIAGNOSTIC:
2960 	case PREVENT_ALLOW:
2961 	case READ_CAPACITY:
2962 	case READ_10:
2963 	case WRITE_10:
2964 	case POSITION_TO_ELEMENT:	/* SEEK_10 */
2965 	case SYNCHRONIZE_CACHE:
2966 	case MODE_SELECT_10:
2967 	case MODE_SENSE_10:
2968 	case READ_BUFFER:
2969 	case 0x42:			/* READ_SUBCHANNEL */
2970 	case 0x43:			/* READ_TOC */
2971 	case 0x44:			/* READ_HEADER */
2972 	case 0x47:			/* PLAY_MSF (Play Minute/Second/Frame) */
2973 	case 0x48:			/* PLAY_TRACK */
2974 	case 0x49:			/* PLAY_TRACK_REL */
2975 	case 0x4b:			/* PAUSE */
2976 	case 0x51:			/* READ_DISK_INFO */
2977 	case 0x52:			/* READ_TRACK_INFO */
2978 	case 0x54:			/* SEND_OPC */
2979 	case 0x59:			/* READ_MASTER_CUE */
2980 	case 0x5b:			/* CLOSE_TR_SESSION */
2981 	case 0x5c:			/* READ_BUFFER_CAP */
2982 	case 0x5d:			/* SEND_CUE_SHEET */
2983 	case 0xa1:			/* BLANK */
2984 	case 0xa5:			/* PLAY_12 */
2985 	case 0xa6:			/* EXCHANGE_MEDIUM */
2986 	case 0xad:			/* READ_DVD_STRUCTURE */
2987 	case 0xbb:			/* SET_CD_SPEED */
2988 	case 0xe5:			/* READ_TRACK_INFO_PHILIPS */
2989 		break;
2990 
2991 	case READ_12:
2992 	case WRITE_12:
2993 	default:
2994 		DPRINTF(sc, UDMASS_SCSI, "Unsupported ATAPI "
2995 		    "command 0x%02x - trying anyway\n",
2996 		    cmd_ptr[0]);
2997 		break;
2998 	}
2999 
3000 	memcpy(sc->sc_transfer.cmd_data, cmd_ptr, cmd_len);
3001 	return (1);			/* success */
3002 }
3003 
3004 static uint8_t
3005 umass_no_transform(struct umass_softc *sc, uint8_t *cmd,
3006     uint8_t cmdlen)
3007 {
3008 	return (0);			/* failure */
3009 }
3010 
3011 static uint8_t
3012 umass_std_transform(struct umass_softc *sc, union ccb *ccb,
3013     uint8_t *cmd, uint8_t cmdlen)
3014 {
3015 	uint8_t retval;
3016 
3017 	retval = (sc->sc_transform) (sc, cmd, cmdlen);
3018 
3019 	if (retval == 2) {
3020 		ccb->ccb_h.status = CAM_REQ_CMP;
3021 		xpt_done(ccb);
3022 		return (0);
3023 	} else if (retval == 0) {
3024 		ccb->ccb_h.status = CAM_REQ_INVALID;
3025 		xpt_done(ccb);
3026 		return (0);
3027 	}
3028 	/* Command should be executed */
3029 	return (1);
3030 }
3031 
3032 #ifdef USB_DEBUG
3033 static void
3034 umass_bbb_dump_cbw(struct umass_softc *sc, umass_bbb_cbw_t *cbw)
3035 {
3036 	uint8_t *c = cbw->CBWCDB;
3037 
3038 	uint32_t dlen = UGETDW(cbw->dCBWDataTransferLength);
3039 	uint32_t tag = UGETDW(cbw->dCBWTag);
3040 
3041 	uint8_t clen = cbw->bCDBLength;
3042 	uint8_t flags = cbw->bCBWFlags;
3043 	uint8_t lun = cbw->bCBWLUN;
3044 
3045 	DPRINTF(sc, UDMASS_BBB, "CBW %d: cmd = %db "
3046 	    "(0x%02x%02x%02x%02x%02x%02x%s), "
3047 	    "data = %db, lun = %d, dir = %s\n",
3048 	    tag, clen,
3049 	    c[0], c[1], c[2], c[3], c[4], c[5], (clen > 6 ? "..." : ""),
3050 	    dlen, lun, (flags == CBWFLAGS_IN ? "in" :
3051 	    (flags == CBWFLAGS_OUT ? "out" : "<invalid>")));
3052 }
3053 
3054 static void
3055 umass_bbb_dump_csw(struct umass_softc *sc, umass_bbb_csw_t *csw)
3056 {
3057 	uint32_t sig = UGETDW(csw->dCSWSignature);
3058 	uint32_t tag = UGETDW(csw->dCSWTag);
3059 	uint32_t res = UGETDW(csw->dCSWDataResidue);
3060 	uint8_t status = csw->bCSWStatus;
3061 
3062 	DPRINTF(sc, UDMASS_BBB, "CSW %d: sig = 0x%08x (%s), tag = 0x%08x, "
3063 	    "res = %d, status = 0x%02x (%s)\n",
3064 	    tag, sig, (sig == CSWSIGNATURE ? "valid" : "invalid"),
3065 	    tag, res,
3066 	    status, (status == CSWSTATUS_GOOD ? "good" :
3067 	    (status == CSWSTATUS_FAILED ? "failed" :
3068 	    (status == CSWSTATUS_PHASE ? "phase" : "<invalid>"))));
3069 }
3070 
3071 static void
3072 umass_cbi_dump_cmd(struct umass_softc *sc, void *cmd, uint8_t cmdlen)
3073 {
3074 	uint8_t *c = cmd;
3075 	uint8_t dir = sc->sc_transfer.dir;
3076 
3077 	DPRINTF(sc, UDMASS_BBB, "cmd = %db "
3078 	    "(0x%02x%02x%02x%02x%02x%02x%s), "
3079 	    "data = %db, dir = %s\n",
3080 	    cmdlen,
3081 	    c[0], c[1], c[2], c[3], c[4], c[5], (cmdlen > 6 ? "..." : ""),
3082 	    sc->sc_transfer.data_len,
3083 	    (dir == DIR_IN ? "in" :
3084 	    (dir == DIR_OUT ? "out" :
3085 	    (dir == DIR_NONE ? "no data phase" : "<invalid>"))));
3086 }
3087 
3088 static void
3089 umass_dump_buffer(struct umass_softc *sc, uint8_t *buffer, uint32_t buflen,
3090     uint32_t printlen)
3091 {
3092 	uint32_t i, j;
3093 	char s1[40];
3094 	char s2[40];
3095 	char s3[5];
3096 
3097 	s1[0] = '\0';
3098 	s3[0] = '\0';
3099 
3100 	sprintf(s2, " buffer=%p, buflen=%d", buffer, buflen);
3101 	for (i = 0; (i < buflen) && (i < printlen); i++) {
3102 		j = i % 16;
3103 		if (j == 0 && i != 0) {
3104 			DPRINTF(sc, UDMASS_GEN, "0x %s%s\n",
3105 			    s1, s2);
3106 			s2[0] = '\0';
3107 		}
3108 		sprintf(&s1[j * 2], "%02x", buffer[i] & 0xff);
3109 	}
3110 	if (buflen > printlen)
3111 		sprintf(s3, " ...");
3112 	DPRINTF(sc, UDMASS_GEN, "0x %s%s%s\n",
3113 	    s1, s2, s3);
3114 }
3115 
3116 #endif
3117