xref: /linux/drivers/scsi/scsi_scan.c (revision 4c461ee2b2a5a7c327fe092b41de1fcc002adc01)
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3  * scsi_scan.c
4  *
5  * Copyright (C) 2000 Eric Youngdale,
6  * Copyright (C) 2002 Patrick Mansfield
7  *
8  * The general scanning/probing algorithm is as follows, exceptions are
9  * made to it depending on device specific flags, compilation options, and
10  * global variable (boot or module load time) settings.
11  *
12  * A specific LUN is scanned via an INQUIRY command; if the LUN has a
13  * device attached, a scsi_device is allocated and setup for it.
14  *
15  * For every id of every channel on the given host:
16  *
17  * 	Scan LUN 0; if the target responds to LUN 0 (even if there is no
18  * 	device or storage attached to LUN 0):
19  *
20  * 		If LUN 0 has a device attached, allocate and setup a
21  * 		scsi_device for it.
22  *
23  * 		If target is SCSI-3 or up, issue a REPORT LUN, and scan
24  * 		all of the LUNs returned by the REPORT LUN; else,
25  * 		sequentially scan LUNs up until some maximum is reached,
26  * 		or a LUN is seen that cannot have a device attached to it.
27  */
28 
29 #include <linux/module.h>
30 #include <linux/moduleparam.h>
31 #include <linux/init.h>
32 #include <linux/blkdev.h>
33 #include <linux/delay.h>
34 #include <linux/kthread.h>
35 #include <linux/spinlock.h>
36 #include <linux/async.h>
37 #include <linux/slab.h>
38 #include <linux/unaligned.h>
39 
40 #include <scsi/scsi.h>
41 #include <scsi/scsi_cmnd.h>
42 #include <scsi/scsi_device.h>
43 #include <scsi/scsi_driver.h>
44 #include <scsi/scsi_devinfo.h>
45 #include <scsi/scsi_host.h>
46 #include <scsi/scsi_transport.h>
47 #include <scsi/scsi_dh.h>
48 #include <scsi/scsi_eh.h>
49 
50 #include "scsi_priv.h"
51 #include "scsi_logging.h"
52 
53 #define ALLOC_FAILURE_MSG	KERN_ERR "%s: Allocation failure during" \
54 	" SCSI scanning, some SCSI devices might not be configured\n"
55 
56 /*
57  * Default timeout
58  */
59 #define SCSI_TIMEOUT (2*HZ)
60 #define SCSI_REPORT_LUNS_TIMEOUT (30*HZ)
61 
62 /*
63  * Prefix values for the SCSI id's (stored in sysfs name field)
64  */
65 #define SCSI_UID_SER_NUM 'S'
66 #define SCSI_UID_UNKNOWN 'Z'
67 
68 /*
69  * Return values of some of the scanning functions.
70  *
71  * SCSI_SCAN_NO_RESPONSE: no valid response received from the target, this
72  * includes allocation or general failures preventing IO from being sent.
73  *
74  * SCSI_SCAN_TARGET_PRESENT: target responded, but no device is available
75  * on the given LUN.
76  *
77  * SCSI_SCAN_LUN_PRESENT: target responded, and a device is available on a
78  * given LUN.
79  */
80 #define SCSI_SCAN_NO_RESPONSE		0
81 #define SCSI_SCAN_TARGET_PRESENT	1
82 #define SCSI_SCAN_LUN_PRESENT		2
83 
84 static const char *scsi_null_device_strs = "nullnullnullnull";
85 
86 #define MAX_SCSI_LUNS	512
87 
88 static u64 max_scsi_luns = MAX_SCSI_LUNS;
89 
90 module_param_named(max_luns, max_scsi_luns, ullong, S_IRUGO|S_IWUSR);
91 MODULE_PARM_DESC(max_luns,
92 		 "last scsi LUN (should be between 1 and 2^64-1)");
93 
94 #ifdef CONFIG_SCSI_SCAN_ASYNC
95 #define SCSI_SCAN_TYPE_DEFAULT "async"
96 #else
97 #define SCSI_SCAN_TYPE_DEFAULT "sync"
98 #endif
99 
100 static char scsi_scan_type[7] = SCSI_SCAN_TYPE_DEFAULT;
101 
102 module_param_string(scan, scsi_scan_type, sizeof(scsi_scan_type),
103 		    S_IRUGO|S_IWUSR);
104 MODULE_PARM_DESC(scan, "sync, async, manual, or none. "
105 		 "Setting to 'manual' disables automatic scanning, but allows "
106 		 "for manual device scan via the 'scan' sysfs attribute.");
107 
108 static unsigned int scsi_inq_timeout = SCSI_TIMEOUT/HZ + 18;
109 
110 module_param_named(inq_timeout, scsi_inq_timeout, uint, S_IRUGO|S_IWUSR);
111 MODULE_PARM_DESC(inq_timeout,
112 		 "Timeout (in seconds) waiting for devices to answer INQUIRY."
113 		 " Default is 20. Some devices may need more; most need less.");
114 
115 /* This lock protects only this list */
116 static DEFINE_SPINLOCK(async_scan_lock);
117 static LIST_HEAD(scanning_hosts);
118 
119 struct async_scan_data {
120 	struct list_head list;
121 	struct Scsi_Host *shost;
122 	struct completion prev_finished;
123 };
124 
125 /*
126  * scsi_enable_async_suspend - Enable async suspend and resume
127  */
128 void scsi_enable_async_suspend(struct device *dev)
129 {
130 	/*
131 	 * If a user has disabled async probing a likely reason is due to a
132 	 * storage enclosure that does not inject staggered spin-ups. For
133 	 * safety, make resume synchronous as well in that case.
134 	 */
135 	if (strncmp(scsi_scan_type, "async", 5) != 0)
136 		return;
137 	/* Enable asynchronous suspend and resume. */
138 	device_enable_async_suspend(dev);
139 }
140 
141 /**
142  * scsi_complete_async_scans - Wait for asynchronous scans to complete
143  *
144  * When this function returns, any host which started scanning before
145  * this function was called will have finished its scan.  Hosts which
146  * started scanning after this function was called may or may not have
147  * finished.
148  */
149 int scsi_complete_async_scans(void)
150 {
151 	struct async_scan_data *data;
152 
153 	do {
154 		scoped_guard(spinlock, &async_scan_lock)
155 			if (list_empty(&scanning_hosts))
156 				return 0;
157 		/* If we can't get memory immediately, that's OK.  Just
158 		 * sleep a little.  Even if we never get memory, the async
159 		 * scans will finish eventually.
160 		 */
161 		data = kmalloc(sizeof(*data), GFP_KERNEL);
162 		if (!data)
163 			msleep(1);
164 	} while (!data);
165 
166 	data->shost = NULL;
167 	init_completion(&data->prev_finished);
168 
169 	spin_lock(&async_scan_lock);
170 	/* Check that there's still somebody else on the list */
171 	if (list_empty(&scanning_hosts))
172 		goto done;
173 	list_add_tail(&data->list, &scanning_hosts);
174 	spin_unlock(&async_scan_lock);
175 
176 	printk(KERN_INFO "scsi: waiting for bus probes to complete ...\n");
177 	wait_for_completion(&data->prev_finished);
178 
179 	spin_lock(&async_scan_lock);
180 	list_del(&data->list);
181 	if (!list_empty(&scanning_hosts)) {
182 		struct async_scan_data *next = list_entry(scanning_hosts.next,
183 				struct async_scan_data, list);
184 		complete(&next->prev_finished);
185 	}
186  done:
187 	spin_unlock(&async_scan_lock);
188 
189 	kfree(data);
190 	return 0;
191 }
192 
193 /**
194  * scsi_unlock_floptical - unlock device via a special MODE SENSE command
195  * @sdev:	scsi device to send command to
196  * @result:	area to store the result of the MODE SENSE
197  *
198  * Description:
199  *     Send a vendor specific MODE SENSE (not a MODE SELECT) command.
200  *     Called for BLIST_KEY devices.
201  **/
202 static void scsi_unlock_floptical(struct scsi_device *sdev,
203 				  unsigned char *result)
204 {
205 	unsigned char scsi_cmd[MAX_COMMAND_SIZE];
206 
207 	sdev_printk(KERN_NOTICE, sdev, "unlocking floptical drive\n");
208 	scsi_cmd[0] = MODE_SENSE;
209 	scsi_cmd[1] = 0;
210 	scsi_cmd[2] = 0x2e;
211 	scsi_cmd[3] = 0;
212 	scsi_cmd[4] = 0x2a;     /* size */
213 	scsi_cmd[5] = 0;
214 	scsi_execute_cmd(sdev, scsi_cmd, REQ_OP_DRV_IN, result, 0x2a,
215 			 SCSI_TIMEOUT, 3, NULL);
216 }
217 
218 static int scsi_realloc_sdev_budget_map(struct scsi_device *sdev,
219 					unsigned int depth)
220 {
221 	int new_shift = sbitmap_calculate_shift(depth);
222 	bool need_alloc = !sdev->budget_map.map;
223 	bool need_free = false;
224 	unsigned int memflags;
225 	int ret;
226 	struct sbitmap sb_backup;
227 
228 	depth = min_t(unsigned int, depth, scsi_device_max_queue_depth(sdev));
229 
230 	/*
231 	 * realloc if new shift is calculated, which is caused by setting
232 	 * up one new default queue depth after calling ->sdev_configure
233 	 */
234 	if (!need_alloc && new_shift != sdev->budget_map.shift)
235 		need_alloc = need_free = true;
236 
237 	if (!need_alloc)
238 		return 0;
239 
240 	/*
241 	 * Request queue has to be frozen for reallocating budget map,
242 	 * and here disk isn't added yet, so freezing is pretty fast
243 	 */
244 	if (need_free) {
245 		memflags = blk_mq_freeze_queue(sdev->request_queue);
246 		sb_backup = sdev->budget_map;
247 	}
248 	ret = sbitmap_init_node(&sdev->budget_map,
249 				scsi_device_max_queue_depth(sdev),
250 				new_shift, GFP_NOIO,
251 				sdev->request_queue->node, false, true);
252 	if (!ret)
253 		sbitmap_resize(&sdev->budget_map, depth);
254 
255 	if (need_free) {
256 		if (ret)
257 			sdev->budget_map = sb_backup;
258 		else
259 			sbitmap_free(&sb_backup);
260 		ret = 0;
261 		blk_mq_unfreeze_queue(sdev->request_queue, memflags);
262 	}
263 	return ret;
264 }
265 
266 /**
267  * scsi_alloc_sdev - allocate and setup a scsi_Device
268  * @starget: which target to allocate a &scsi_device for
269  * @lun: which lun
270  * @hostdata: usually NULL and set by ->sdev_init instead
271  *
272  * Description:
273  *     Allocate, initialize for io, and return a pointer to a scsi_Device.
274  *     Stores the @shost, @channel, @id, and @lun in the scsi_Device, and
275  *     adds scsi_Device to the appropriate list.
276  *
277  * Return value:
278  *     scsi_Device pointer, or NULL on failure.
279  **/
280 static struct scsi_device *scsi_alloc_sdev(struct scsi_target *starget,
281 					   u64 lun, void *hostdata)
282 {
283 	unsigned int depth;
284 	struct scsi_device *sdev;
285 	struct request_queue *q;
286 	int display_failure_msg = 1, ret;
287 	struct Scsi_Host *shost = dev_to_shost(starget->dev.parent);
288 	struct queue_limits lim;
289 
290 	sdev = kzalloc(sizeof(*sdev) + shost->transportt->device_size,
291 		       GFP_KERNEL);
292 	if (!sdev)
293 		goto out;
294 
295 	strscpy(sdev->vendor, scsi_null_device_strs);
296 	strscpy(sdev->model, scsi_null_device_strs);
297 	strscpy(sdev->rev, scsi_null_device_strs);
298 	sdev->host = shost;
299 	sdev->queue_ramp_up_period = SCSI_DEFAULT_RAMP_UP_PERIOD;
300 	sdev->id = starget->id;
301 	sdev->lun = lun;
302 	sdev->channel = starget->channel;
303 	mutex_init(&sdev->state_mutex);
304 	sdev->sdev_state = SDEV_CREATED;
305 	INIT_LIST_HEAD(&sdev->siblings);
306 	INIT_LIST_HEAD(&sdev->same_target_siblings);
307 	INIT_LIST_HEAD(&sdev->starved_entry);
308 	INIT_LIST_HEAD(&sdev->event_list);
309 	spin_lock_init(&sdev->list_lock);
310 	mutex_init(&sdev->inquiry_mutex);
311 	INIT_WORK(&sdev->event_work, scsi_evt_thread);
312 	INIT_WORK(&sdev->requeue_work, scsi_requeue_run_queue);
313 
314 	sdev->sdev_gendev.parent = get_device(&starget->dev);
315 	sdev->sdev_target = starget;
316 
317 	/* usually NULL and set by ->sdev_init instead */
318 	sdev->hostdata = hostdata;
319 
320 	/* if the device needs this changing, it may do so in the
321 	 * sdev_configure function */
322 	sdev->max_device_blocked = SCSI_DEFAULT_DEVICE_BLOCKED;
323 
324 	/*
325 	 * Some low level driver could use device->type
326 	 */
327 	sdev->type = -1;
328 
329 	/*
330 	 * Assume that the device will have handshaking problems,
331 	 * and then fix this field later if it turns out it
332 	 * doesn't
333 	 */
334 	sdev->borken = 1;
335 
336 	sdev->sg_reserved_size = INT_MAX;
337 
338 	scsi_init_limits(shost, &lim);
339 	q = blk_mq_alloc_queue(&sdev->host->tag_set, &lim, sdev);
340 	if (IS_ERR(q)) {
341 		/* release fn is set up in scsi_sysfs_device_initialise, so
342 		 * have to free and put manually here */
343 		put_device(&starget->dev);
344 		kfree(sdev);
345 		goto out;
346 	}
347 	kref_get(&sdev->host->tagset_refcnt);
348 	sdev->request_queue = q;
349 
350 	scsi_sysfs_device_initialize(sdev);
351 
352 	if (scsi_device_is_pseudo_dev(sdev))
353 		return sdev;
354 
355 	depth = sdev->host->cmd_per_lun ?: 1;
356 
357 	/*
358 	 * Use .can_queue as budget map's depth because we have to
359 	 * support adjusting queue depth from sysfs. Meantime use
360 	 * default device queue depth to figure out sbitmap shift
361 	 * since we use this queue depth most of times.
362 	 */
363 	if (scsi_realloc_sdev_budget_map(sdev, depth))
364 		goto out_device_destroy;
365 
366 	scsi_change_queue_depth(sdev, depth);
367 
368 	if (shost->hostt->sdev_init) {
369 		ret = shost->hostt->sdev_init(sdev);
370 		if (ret) {
371 			/*
372 			 * if LLDD reports slave not present, don't clutter
373 			 * console with alloc failure messages
374 			 */
375 			if (ret == -ENXIO)
376 				display_failure_msg = 0;
377 			goto out_device_destroy;
378 		}
379 	}
380 
381 	return sdev;
382 
383 out_device_destroy:
384 	__scsi_remove_device(sdev);
385 out:
386 	if (display_failure_msg)
387 		printk(ALLOC_FAILURE_MSG, __func__);
388 	return NULL;
389 }
390 
391 static void scsi_target_destroy(struct scsi_target *starget)
392 {
393 	struct device *dev = &starget->dev;
394 	struct Scsi_Host *shost = dev_to_shost(dev->parent);
395 	unsigned long flags;
396 
397 	BUG_ON(starget->state == STARGET_DEL);
398 	starget->state = STARGET_DEL;
399 	transport_destroy_device(dev);
400 	spin_lock_irqsave(shost->host_lock, flags);
401 	if (shost->hostt->target_destroy)
402 		shost->hostt->target_destroy(starget);
403 	list_del_init(&starget->siblings);
404 	spin_unlock_irqrestore(shost->host_lock, flags);
405 	put_device(dev);
406 }
407 
408 static void scsi_target_dev_release(struct device *dev)
409 {
410 	struct device *parent = dev->parent;
411 	struct scsi_target *starget = to_scsi_target(dev);
412 
413 	kfree(starget);
414 	put_device(parent);
415 }
416 
417 static const struct device_type scsi_target_type = {
418 	.name =		"scsi_target",
419 	.release =	scsi_target_dev_release,
420 };
421 
422 int scsi_is_target_device(const struct device *dev)
423 {
424 	return dev->type == &scsi_target_type;
425 }
426 EXPORT_SYMBOL(scsi_is_target_device);
427 
428 static struct scsi_target *__scsi_find_target(struct device *parent,
429 					      int channel, uint id)
430 {
431 	struct scsi_target *starget, *found_starget = NULL;
432 	struct Scsi_Host *shost = dev_to_shost(parent);
433 	/*
434 	 * Search for an existing target for this sdev.
435 	 */
436 	list_for_each_entry(starget, &shost->__targets, siblings) {
437 		if (starget->id == id &&
438 		    starget->channel == channel) {
439 			found_starget = starget;
440 			break;
441 		}
442 	}
443 	if (found_starget)
444 		get_device(&found_starget->dev);
445 
446 	return found_starget;
447 }
448 
449 /**
450  * scsi_target_reap_ref_release - remove target from visibility
451  * @kref: the reap_ref in the target being released
452  *
453  * Called on last put of reap_ref, which is the indication that no device
454  * under this target is visible anymore, so render the target invisible in
455  * sysfs.  Note: we have to be in user context here because the target reaps
456  * should be done in places where the scsi device visibility is being removed.
457  */
458 static void scsi_target_reap_ref_release(struct kref *kref)
459 {
460 	struct scsi_target *starget
461 		= container_of(kref, struct scsi_target, reap_ref);
462 
463 	/*
464 	 * if we get here and the target is still in a CREATED state that
465 	 * means it was allocated but never made visible (because a scan
466 	 * turned up no LUNs), so don't call device_del() on it.
467 	 */
468 	if ((starget->state != STARGET_CREATED) &&
469 	    (starget->state != STARGET_CREATED_REMOVE)) {
470 		transport_remove_device(&starget->dev);
471 		device_del(&starget->dev);
472 	}
473 	scsi_target_destroy(starget);
474 }
475 
476 static void scsi_target_reap_ref_put(struct scsi_target *starget)
477 {
478 	kref_put(&starget->reap_ref, scsi_target_reap_ref_release);
479 }
480 
481 /**
482  * scsi_alloc_target - allocate a new or find an existing target
483  * @parent:	parent of the target (need not be a scsi host)
484  * @channel:	target channel number (zero if no channels)
485  * @id:		target id number
486  *
487  * Return an existing target if one exists, provided it hasn't already
488  * gone into STARGET_DEL state, otherwise allocate a new target.
489  *
490  * The target is returned with an incremented reference, so the caller
491  * is responsible for both reaping and doing a last put
492  */
493 static struct scsi_target *scsi_alloc_target(struct device *parent,
494 					     int channel, uint id)
495 {
496 	struct Scsi_Host *shost = dev_to_shost(parent);
497 	struct device *dev = NULL;
498 	unsigned long flags;
499 	const int size = sizeof(struct scsi_target)
500 		+ shost->transportt->target_size;
501 	struct scsi_target *starget;
502 	struct scsi_target *found_target;
503 	int error, ref_got;
504 
505 	starget = kzalloc(size, GFP_KERNEL);
506 	if (!starget) {
507 		printk(KERN_ERR "%s: allocation failure\n", __func__);
508 		return NULL;
509 	}
510 	dev = &starget->dev;
511 	device_initialize(dev);
512 	kref_init(&starget->reap_ref);
513 	dev->parent = get_device(parent);
514 	dev_set_name(dev, "target%d:%d:%d", shost->host_no, channel, id);
515 	dev->bus = &scsi_bus_type;
516 	dev->type = &scsi_target_type;
517 	scsi_enable_async_suspend(dev);
518 	starget->id = id;
519 	starget->channel = channel;
520 	starget->can_queue = 0;
521 	INIT_LIST_HEAD(&starget->siblings);
522 	INIT_LIST_HEAD(&starget->devices);
523 	starget->state = STARGET_CREATED;
524 	starget->scsi_level = SCSI_2;
525 	starget->max_target_blocked = SCSI_DEFAULT_TARGET_BLOCKED;
526  retry:
527 	spin_lock_irqsave(shost->host_lock, flags);
528 
529 	found_target = __scsi_find_target(parent, channel, id);
530 	if (found_target)
531 		goto found;
532 
533 	list_add_tail(&starget->siblings, &shost->__targets);
534 	spin_unlock_irqrestore(shost->host_lock, flags);
535 	/* allocate and add */
536 	transport_setup_device(dev);
537 	if (shost->hostt->target_alloc) {
538 		error = shost->hostt->target_alloc(starget);
539 
540 		if(error) {
541 			if (error != -ENXIO)
542 				dev_err(dev, "target allocation failed, error %d\n", error);
543 			/* don't want scsi_target_reap to do the final
544 			 * put because it will be under the host lock */
545 			scsi_target_destroy(starget);
546 			return NULL;
547 		}
548 	}
549 	get_device(dev);
550 
551 	return starget;
552 
553  found:
554 	/*
555 	 * release routine already fired if kref is zero, so if we can still
556 	 * take the reference, the target must be alive.  If we can't, it must
557 	 * be dying and we need to wait for a new target
558 	 */
559 	ref_got = kref_get_unless_zero(&found_target->reap_ref);
560 
561 	spin_unlock_irqrestore(shost->host_lock, flags);
562 	if (ref_got) {
563 		put_device(dev);
564 		return found_target;
565 	}
566 	/*
567 	 * Unfortunately, we found a dying target; need to wait until it's
568 	 * dead before we can get a new one.  There is an anomaly here.  We
569 	 * *should* call scsi_target_reap() to balance the kref_get() of the
570 	 * reap_ref above.  However, since the target being released, it's
571 	 * already invisible and the reap_ref is irrelevant.  If we call
572 	 * scsi_target_reap() we might spuriously do another device_del() on
573 	 * an already invisible target.
574 	 */
575 	put_device(&found_target->dev);
576 	/*
577 	 * length of time is irrelevant here, we just want to yield the CPU
578 	 * for a tick to avoid busy waiting for the target to die.
579 	 */
580 	msleep(1);
581 	goto retry;
582 }
583 
584 /**
585  * scsi_target_reap - check to see if target is in use and destroy if not
586  * @starget: target to be checked
587  *
588  * This is used after removing a LUN or doing a last put of the target
589  * it checks atomically that nothing is using the target and removes
590  * it if so.
591  */
592 void scsi_target_reap(struct scsi_target *starget)
593 {
594 	/*
595 	 * serious problem if this triggers: STARGET_DEL is only set in the if
596 	 * the reap_ref drops to zero, so we're trying to do another final put
597 	 * on an already released kref
598 	 */
599 	BUG_ON(starget->state == STARGET_DEL);
600 	scsi_target_reap_ref_put(starget);
601 }
602 
603 /**
604  * scsi_sanitize_inquiry_string - remove non-graphical chars from an
605  *                                INQUIRY result string
606  * @s: INQUIRY result string to sanitize
607  * @len: length of the string
608  *
609  * Description:
610  *	The SCSI spec says that INQUIRY vendor, product, and revision
611  *	strings must consist entirely of graphic ASCII characters,
612  *	padded on the right with spaces.  Since not all devices obey
613  *	this rule, we will replace non-graphic or non-ASCII characters
614  *	with spaces.  Exception: a NUL character is interpreted as a
615  *	string terminator, so all the following characters are set to
616  *	spaces.
617  **/
618 void scsi_sanitize_inquiry_string(unsigned char *s, int len)
619 {
620 	int terminated = 0;
621 
622 	for (; len > 0; (--len, ++s)) {
623 		if (*s == 0)
624 			terminated = 1;
625 		if (terminated || *s < 0x20 || *s > 0x7e)
626 			*s = ' ';
627 	}
628 }
629 EXPORT_SYMBOL(scsi_sanitize_inquiry_string);
630 
631 
632 /**
633  * scsi_probe_lun - probe a single LUN using a SCSI INQUIRY
634  * @sdev:	scsi_device to probe
635  * @inq_result:	area to store the INQUIRY result
636  * @result_len: len of inq_result
637  * @bflags:	store any bflags found here
638  *
639  * Description:
640  *     Probe the lun associated with @req using a standard SCSI INQUIRY;
641  *
642  *     If the INQUIRY is successful, zero is returned and the
643  *     INQUIRY data is in @inq_result; the scsi_level and INQUIRY length
644  *     are copied to the scsi_device any flags value is stored in *@bflags.
645  **/
646 static int scsi_probe_lun(struct scsi_device *sdev, unsigned char *inq_result,
647 			  int result_len, blist_flags_t *bflags)
648 {
649 	unsigned char scsi_cmd[MAX_COMMAND_SIZE];
650 	int first_inquiry_len, try_inquiry_len, next_inquiry_len;
651 	int response_len = 0;
652 	int pass, count, result, resid;
653 	struct scsi_failure failure_defs[] = {
654 		/*
655 		 * not-ready to ready transition [asc/ascq=0x28/0x0] or
656 		 * power-on, reset [asc/ascq=0x29/0x0], continue. INQUIRY
657 		 * should not yield UNIT_ATTENTION but many buggy devices do
658 		 * so anyway.
659 		 */
660 		{
661 			.sense = UNIT_ATTENTION,
662 			.asc = 0x28,
663 			.result = SAM_STAT_CHECK_CONDITION,
664 		},
665 		{
666 			.sense = UNIT_ATTENTION,
667 			.asc = 0x29,
668 			.result = SAM_STAT_CHECK_CONDITION,
669 		},
670 		{
671 			.allowed = 1,
672 			.result = DID_TIME_OUT << 16,
673 		},
674 		{}
675 	};
676 	struct scsi_failures failures = {
677 		.total_allowed = 3,
678 		.failure_definitions = failure_defs,
679 	};
680 	const struct scsi_exec_args exec_args = {
681 		.resid = &resid,
682 		.failures = &failures,
683 	};
684 
685 	*bflags = 0;
686 
687 	/* Perform up to 3 passes.  The first pass uses a conservative
688 	 * transfer length of 36 unless sdev->inquiry_len specifies a
689 	 * different value. */
690 	first_inquiry_len = sdev->inquiry_len ? sdev->inquiry_len : 36;
691 	try_inquiry_len = first_inquiry_len;
692 	pass = 1;
693 
694  next_pass:
695 	SCSI_LOG_SCAN_BUS(3, sdev_printk(KERN_INFO, sdev,
696 				"scsi scan: INQUIRY pass %d length %d\n",
697 				pass, try_inquiry_len));
698 
699 	/* Each pass gets up to three chances to ignore Unit Attention */
700 	scsi_failures_reset_retries(&failures);
701 
702 	for (count = 0; count < 3; ++count) {
703 		memset(scsi_cmd, 0, 6);
704 		scsi_cmd[0] = INQUIRY;
705 		scsi_cmd[4] = (unsigned char) try_inquiry_len;
706 
707 		memset(inq_result, 0, try_inquiry_len);
708 
709 		result = scsi_execute_cmd(sdev,  scsi_cmd, REQ_OP_DRV_IN,
710 					  inq_result, try_inquiry_len,
711 					  HZ / 2 + HZ * scsi_inq_timeout, 3,
712 					  &exec_args);
713 
714 		SCSI_LOG_SCAN_BUS(3, sdev_printk(KERN_INFO, sdev,
715 				"scsi scan: INQUIRY %s with code 0x%x\n",
716 				result ? "failed" : "successful", result));
717 
718 		if (result == 0) {
719 			/*
720 			 * if nothing was transferred, we try
721 			 * again. It's a workaround for some USB
722 			 * devices.
723 			 */
724 			if (resid == try_inquiry_len)
725 				continue;
726 		}
727 		break;
728 	}
729 
730 	if (result == 0) {
731 		scsi_sanitize_inquiry_string(&inq_result[INQUIRY_VENDOR_OFFSET],
732 					     INQUIRY_VENDOR_LEN);
733 		scsi_sanitize_inquiry_string(&inq_result[INQUIRY_MODEL_OFFSET],
734 					     INQUIRY_MODEL_LEN);
735 		scsi_sanitize_inquiry_string(
736 			&inq_result[INQUIRY_REVISION_OFFSET],
737 			INQUIRY_REVISION_LEN);
738 
739 		response_len = inq_result[4] + 5;
740 		if (response_len > 255)
741 			response_len = first_inquiry_len;	/* sanity */
742 
743 		/*
744 		 * Get any flags for this device.
745 		 *
746 		 * XXX add a bflags to scsi_device, and replace the
747 		 * corresponding bit fields in scsi_device, so bflags
748 		 * need not be passed as an argument.
749 		 */
750 		*bflags = scsi_get_device_flags(sdev,
751 				&inq_result[INQUIRY_VENDOR_OFFSET],
752 				&inq_result[INQUIRY_MODEL_OFFSET]);
753 
754 		/* When the first pass succeeds we gain information about
755 		 * what larger transfer lengths might work. */
756 		if (pass == 1) {
757 			if (BLIST_INQUIRY_36 & *bflags)
758 				next_inquiry_len = 36;
759 			/*
760 			 * LLD specified a maximum sdev->inquiry_len
761 			 * but device claims it has more data. Capping
762 			 * the length only makes sense for legacy
763 			 * devices. If a device supports SPC-4 (2014)
764 			 * or newer, assume that it is safe to ask for
765 			 * as much as the device says it supports.
766 			 */
767 			else if (sdev->inquiry_len &&
768 				 response_len > sdev->inquiry_len &&
769 				 (inq_result[2] & 0x7) < 6) /* SPC-4 */
770 				next_inquiry_len = sdev->inquiry_len;
771 			else
772 				next_inquiry_len = response_len;
773 
774 			/* If more data is available perform the second pass */
775 			if (next_inquiry_len > try_inquiry_len) {
776 				try_inquiry_len = next_inquiry_len;
777 				pass = 2;
778 				goto next_pass;
779 			}
780 		}
781 
782 	} else if (pass == 2) {
783 		sdev_printk(KERN_INFO, sdev,
784 			    "scsi scan: %d byte inquiry failed.  "
785 			    "Consider BLIST_INQUIRY_36 for this device\n",
786 			    try_inquiry_len);
787 
788 		/* If this pass failed, the third pass goes back and transfers
789 		 * the same amount as we successfully got in the first pass. */
790 		try_inquiry_len = first_inquiry_len;
791 		pass = 3;
792 		goto next_pass;
793 	}
794 
795 	/* If the last transfer attempt got an error, assume the
796 	 * peripheral doesn't exist or is dead. */
797 	if (result)
798 		return -EIO;
799 
800 	/* Don't report any more data than the device says is valid */
801 	sdev->inquiry_len = min(try_inquiry_len, response_len);
802 
803 	/*
804 	 * XXX Abort if the response length is less than 36? If less than
805 	 * 32, the lookup of the device flags (above) could be invalid,
806 	 * and it would be possible to take an incorrect action - we do
807 	 * not want to hang because of a short INQUIRY. On the flip side,
808 	 * if the device is spun down or becoming ready (and so it gives a
809 	 * short INQUIRY), an abort here prevents any further use of the
810 	 * device, including spin up.
811 	 *
812 	 * On the whole, the best approach seems to be to assume the first
813 	 * 36 bytes are valid no matter what the device says.  That's
814 	 * better than copying < 36 bytes to the inquiry-result buffer
815 	 * and displaying garbage for the Vendor, Product, or Revision
816 	 * strings.
817 	 */
818 	if (sdev->inquiry_len < 36) {
819 		if (!sdev->host->short_inquiry) {
820 			shost_printk(KERN_INFO, sdev->host,
821 				    "scsi scan: INQUIRY result too short (%d),"
822 				    " using 36\n", sdev->inquiry_len);
823 			sdev->host->short_inquiry = 1;
824 		}
825 		sdev->inquiry_len = 36;
826 	}
827 
828 	/*
829 	 * Related to the above issue:
830 	 *
831 	 * XXX Devices (disk or all?) should be sent a TEST UNIT READY,
832 	 * and if not ready, sent a START_STOP to start (maybe spin up) and
833 	 * then send the INQUIRY again, since the INQUIRY can change after
834 	 * a device is initialized.
835 	 *
836 	 * Ideally, start a device if explicitly asked to do so.  This
837 	 * assumes that a device is spun up on power on, spun down on
838 	 * request, and then spun up on request.
839 	 */
840 
841 	/*
842 	 * The scanning code needs to know the scsi_level, even if no
843 	 * device is attached at LUN 0 (SCSI_SCAN_TARGET_PRESENT) so
844 	 * non-zero LUNs can be scanned.
845 	 */
846 	sdev->scsi_level = inq_result[2] & 0x0f;
847 	if (sdev->scsi_level >= 2 ||
848 	    (sdev->scsi_level == 1 && (inq_result[3] & 0x0f) == 1))
849 		sdev->scsi_level++;
850 	sdev->sdev_target->scsi_level = sdev->scsi_level;
851 
852 	/*
853 	 * If SCSI-2 or lower, and if the transport requires it,
854 	 * store the LUN value in CDB[1].
855 	 */
856 	sdev->lun_in_cdb = 0;
857 	if (sdev->scsi_level <= SCSI_2 &&
858 	    sdev->scsi_level != SCSI_UNKNOWN &&
859 	    !sdev->host->no_scsi2_lun_in_cdb)
860 		sdev->lun_in_cdb = 1;
861 
862 	return 0;
863 }
864 
865 /**
866  * scsi_add_lun - allocate and fully initialize a scsi_device
867  * @sdev:	holds information to be stored in the new scsi_device
868  * @inq_result:	holds the result of a previous INQUIRY to the LUN
869  * @bflags:	black/white list flag
870  * @async:	1 if this device is being scanned asynchronously
871  *
872  * Description:
873  *     Initialize the scsi_device @sdev.  Optionally set fields based
874  *     on values in *@bflags.
875  *
876  * Return:
877  *     SCSI_SCAN_NO_RESPONSE: could not allocate or setup a scsi_device
878  *     SCSI_SCAN_LUN_PRESENT: a new scsi_device was allocated and initialized
879  **/
880 static int scsi_add_lun(struct scsi_device *sdev, unsigned char *inq_result,
881 		blist_flags_t *bflags, int async)
882 {
883 	const struct scsi_host_template *hostt = sdev->host->hostt;
884 	struct queue_limits lim;
885 	int ret;
886 
887 	/*
888 	 * XXX do not save the inquiry, since it can change underneath us,
889 	 * save just vendor/model/rev.
890 	 *
891 	 * Rather than save it and have an ioctl that retrieves the saved
892 	 * value, have an ioctl that executes the same INQUIRY code used
893 	 * in scsi_probe_lun, let user level programs doing INQUIRY
894 	 * scanning run at their own risk, or supply a user level program
895 	 * that can correctly scan.
896 	 */
897 
898 	/*
899 	 * Copy at least 36 bytes of INQUIRY data, so that we don't
900 	 * dereference unallocated memory when accessing the Vendor,
901 	 * Product, and Revision strings.  Badly behaved devices may set
902 	 * the INQUIRY Additional Length byte to a small value, indicating
903 	 * these strings are invalid, but often they contain plausible data
904 	 * nonetheless.  It doesn't matter if the device sent < 36 bytes
905 	 * total, since scsi_probe_lun() initializes inq_result with 0s.
906 	 */
907 	sdev->inquiry = kmemdup(inq_result,
908 				max_t(size_t, sdev->inquiry_len, 36),
909 				GFP_KERNEL);
910 	if (sdev->inquiry == NULL)
911 		return SCSI_SCAN_NO_RESPONSE;
912 
913 	strscpy(sdev->vendor, sdev->inquiry + INQUIRY_VENDOR_OFFSET);
914 	strscpy(sdev->model, sdev->inquiry + INQUIRY_MODEL_OFFSET);
915 	/*
916 	 * memcpy() instead of strscpy() because strscpy() would read past
917 	 * the end of sdev->inquiry if its length is exactly 36 bytes.
918 	 */
919 	memcpy(sdev->rev, sdev->inquiry + INQUIRY_REVISION_OFFSET,
920 	       INQUIRY_REVISION_LEN);
921 	sdev->rev[INQUIRY_REVISION_LEN] = '\0';
922 
923 	sdev->is_ata = strncmp(sdev->vendor, "ATA     ", 8) == 0;
924 	if (sdev->is_ata) {
925 		/*
926 		 * sata emulation layer device.  This is a hack to work around
927 		 * the SATL power management specifications which state that
928 		 * when the SATL detects the device has gone into standby
929 		 * mode, it shall respond with NOT READY.
930 		 */
931 		sdev->allow_restart = 1;
932 	}
933 
934 	if (*bflags & BLIST_ISROM) {
935 		sdev->type = TYPE_ROM;
936 		sdev->removable = 1;
937 	} else {
938 		sdev->type = (inq_result[0] & 0x1f);
939 		sdev->removable = (inq_result[1] & 0x80) >> 7;
940 
941 		/*
942 		 * some devices may respond with wrong type for
943 		 * well-known logical units. Force well-known type
944 		 * to enumerate them correctly.
945 		 */
946 		if (scsi_is_wlun(sdev->lun) && sdev->type != TYPE_WLUN) {
947 			sdev_printk(KERN_WARNING, sdev,
948 				"%s: correcting incorrect peripheral device type 0x%x for W-LUN 0x%16xhN\n",
949 				__func__, sdev->type, (unsigned int)sdev->lun);
950 			sdev->type = TYPE_WLUN;
951 		}
952 
953 	}
954 
955 	if (sdev->type == TYPE_RBC || sdev->type == TYPE_ROM) {
956 		/* RBC and MMC devices can return SCSI-3 compliance and yet
957 		 * still not support REPORT LUNS, so make them act as
958 		 * BLIST_NOREPORTLUN unless BLIST_REPORTLUN2 is
959 		 * specifically set */
960 		if ((*bflags & BLIST_REPORTLUN2) == 0)
961 			*bflags |= BLIST_NOREPORTLUN;
962 	}
963 
964 	/*
965 	 * For a peripheral qualifier (PQ) value of 1 (001b), the SCSI
966 	 * spec says: The device server is capable of supporting the
967 	 * specified peripheral device type on this logical unit. However,
968 	 * the physical device is not currently connected to this logical
969 	 * unit.
970 	 *
971 	 * The above is vague, as it implies that we could treat 001 and
972 	 * 011 the same. Stay compatible with previous code, and create a
973 	 * scsi_device for a PQ of 1
974 	 *
975 	 * Don't set the device offline here; rather let the upper
976 	 * level drivers eval the PQ to decide whether they should
977 	 * attach. So remove ((inq_result[0] >> 5) & 7) == 1 check.
978 	 */
979 
980 	sdev->inq_periph_qual = (inq_result[0] >> 5) & 7;
981 	sdev->lockable = sdev->removable;
982 	sdev->soft_reset = (inq_result[7] & 1) && ((inq_result[3] & 7) == 2);
983 
984 	if (sdev->scsi_level >= SCSI_3 ||
985 			(sdev->inquiry_len > 56 && inq_result[56] & 0x04))
986 		sdev->ppr = 1;
987 	if (inq_result[7] & 0x60)
988 		sdev->wdtr = 1;
989 	if (inq_result[7] & 0x10)
990 		sdev->sdtr = 1;
991 
992 	sdev_printk(KERN_NOTICE, sdev, "%s %.8s %.16s %.4s PQ: %d "
993 			"ANSI: %d%s\n", scsi_device_type(sdev->type),
994 			sdev->vendor, sdev->model, sdev->rev,
995 			sdev->inq_periph_qual, inq_result[2] & 0x07,
996 			(inq_result[3] & 0x0f) == 1 ? " CCS" : "");
997 
998 	if ((sdev->scsi_level >= SCSI_2) && (inq_result[7] & 2) &&
999 	    !(*bflags & BLIST_NOTQ)) {
1000 		sdev->tagged_supported = 1;
1001 		sdev->simple_tags = 1;
1002 	}
1003 
1004 	/*
1005 	 * Some devices (Texel CD ROM drives) have handshaking problems
1006 	 * when used with the Seagate controllers. borken is initialized
1007 	 * to 1, and then set it to 0 here.
1008 	 */
1009 	if ((*bflags & BLIST_BORKEN) == 0)
1010 		sdev->borken = 0;
1011 
1012 	if (*bflags & BLIST_NO_ULD_ATTACH)
1013 		sdev->no_uld_attach = 1;
1014 
1015 	/*
1016 	 * Apparently some really broken devices (contrary to the SCSI
1017 	 * standards) need to be selected without asserting ATN
1018 	 */
1019 	if (*bflags & BLIST_SELECT_NO_ATN)
1020 		sdev->select_no_atn = 1;
1021 
1022 	/*
1023 	 * Some devices may not want to have a start command automatically
1024 	 * issued when a device is added.
1025 	 */
1026 	if (*bflags & BLIST_NOSTARTONADD)
1027 		sdev->no_start_on_add = 1;
1028 
1029 	if (*bflags & BLIST_SINGLELUN)
1030 		scsi_target(sdev)->single_lun = 1;
1031 
1032 	sdev->use_10_for_rw = 1;
1033 
1034 	/* some devices don't like REPORT SUPPORTED OPERATION CODES
1035 	 * and will simply timeout causing sd_mod init to take a very
1036 	 * very long time */
1037 	if (*bflags & BLIST_NO_RSOC)
1038 		sdev->no_report_opcodes = 1;
1039 
1040 	/* set the device running here so that slave configure
1041 	 * may do I/O */
1042 	mutex_lock(&sdev->state_mutex);
1043 	ret = scsi_device_set_state(sdev, SDEV_RUNNING);
1044 	if (ret)
1045 		ret = scsi_device_set_state(sdev, SDEV_BLOCK);
1046 	mutex_unlock(&sdev->state_mutex);
1047 
1048 	if (ret) {
1049 		sdev_printk(KERN_ERR, sdev,
1050 			    "in wrong state %s to complete scan\n",
1051 			    scsi_device_state_name(sdev->sdev_state));
1052 		return SCSI_SCAN_NO_RESPONSE;
1053 	}
1054 
1055 	if (*bflags & BLIST_NOT_LOCKABLE)
1056 		sdev->lockable = 0;
1057 
1058 	if (*bflags & BLIST_RETRY_HWERROR)
1059 		sdev->retry_hwerror = 1;
1060 
1061 	if (*bflags & BLIST_NO_DIF)
1062 		sdev->no_dif = 1;
1063 
1064 	if (*bflags & BLIST_UNMAP_LIMIT_WS)
1065 		sdev->unmap_limit_for_ws = 1;
1066 
1067 	if (*bflags & BLIST_IGN_MEDIA_CHANGE)
1068 		sdev->ignore_media_change = 1;
1069 
1070 	sdev->eh_timeout = SCSI_DEFAULT_EH_TIMEOUT;
1071 
1072 	if (*bflags & BLIST_TRY_VPD_PAGES)
1073 		sdev->try_vpd_pages = 1;
1074 	else if (*bflags & BLIST_SKIP_VPD_PAGES)
1075 		sdev->skip_vpd_pages = 1;
1076 
1077 	if (*bflags & BLIST_NO_VPD_SIZE)
1078 		sdev->no_vpd_size = 1;
1079 
1080 	transport_configure_device(&sdev->sdev_gendev);
1081 
1082 	sdev->sdev_bflags = *bflags;
1083 
1084 	if (scsi_device_is_pseudo_dev(sdev))
1085 		return SCSI_SCAN_LUN_PRESENT;
1086 
1087 	/*
1088 	 * No need to freeze the queue as it isn't reachable to anyone else yet.
1089 	 */
1090 	lim = queue_limits_start_update(sdev->request_queue);
1091 	if (*bflags & BLIST_MAX_512)
1092 		lim.max_hw_sectors = 512;
1093 	else if (*bflags & BLIST_MAX_1024)
1094 		lim.max_hw_sectors = 1024;
1095 
1096 	if (hostt->sdev_configure)
1097 		ret = hostt->sdev_configure(sdev, &lim);
1098 	if (ret) {
1099 		queue_limits_cancel_update(sdev->request_queue);
1100 		/*
1101 		 * If the LLDD reports device not present, don't clutter the
1102 		 * console with failure messages.
1103 		 */
1104 		if (ret != -ENXIO)
1105 			sdev_printk(KERN_ERR, sdev,
1106 				"failed to configure device\n");
1107 		return SCSI_SCAN_NO_RESPONSE;
1108 	}
1109 
1110 	ret = queue_limits_commit_update(sdev->request_queue, &lim);
1111 	if (ret) {
1112 		sdev_printk(KERN_ERR, sdev, "failed to apply queue limits.\n");
1113 		return SCSI_SCAN_NO_RESPONSE;
1114 	}
1115 
1116 	/*
1117 	 * The queue_depth is often changed in ->sdev_configure.
1118 	 *
1119 	 * Set up budget map again since memory consumption of the map depends
1120 	 * on actual queue depth.
1121 	 */
1122 	if (hostt->sdev_configure)
1123 		scsi_realloc_sdev_budget_map(sdev, sdev->queue_depth);
1124 
1125 	if (sdev->scsi_level >= SCSI_3)
1126 		scsi_attach_vpd(sdev);
1127 
1128 	scsi_cdl_check(sdev);
1129 
1130 	sdev->max_queue_depth = sdev->queue_depth;
1131 	WARN_ON_ONCE(sdev->max_queue_depth > sdev->budget_map.depth);
1132 
1133 	/*
1134 	 * Ok, the device is now all set up, we can
1135 	 * register it and tell the rest of the kernel
1136 	 * about it.
1137 	 */
1138 	if (!async && scsi_sysfs_add_sdev(sdev) != 0)
1139 		return SCSI_SCAN_NO_RESPONSE;
1140 
1141 	return SCSI_SCAN_LUN_PRESENT;
1142 }
1143 
1144 #ifdef CONFIG_SCSI_LOGGING
1145 /**
1146  * scsi_inq_str - print INQUIRY data from min to max index, strip trailing whitespace
1147  * @buf:   Output buffer with at least end-first+1 bytes of space
1148  * @inq:   Inquiry buffer (input)
1149  * @first: Offset of string into inq
1150  * @end:   Index after last character in inq
1151  */
1152 static unsigned char *scsi_inq_str(unsigned char *buf, unsigned char *inq,
1153 				   unsigned first, unsigned end)
1154 {
1155 	unsigned term = 0, idx;
1156 
1157 	for (idx = 0; idx + first < end && idx + first < inq[4] + 5; idx++) {
1158 		if (inq[idx+first] > ' ') {
1159 			buf[idx] = inq[idx+first];
1160 			term = idx+1;
1161 		} else {
1162 			buf[idx] = ' ';
1163 		}
1164 	}
1165 	buf[term] = 0;
1166 	return buf;
1167 }
1168 #endif
1169 
1170 /**
1171  * scsi_probe_and_add_lun - probe a LUN, if a LUN is found add it
1172  * @shost:      SCSI host pointer
1173  * @starget:	pointer to target device structure
1174  * @lun:	LUN of target device
1175  * @bflagsp:	store bflags here if not NULL
1176  * @sdevp:	probe the LUN corresponding to this scsi_device
1177  * @rescan:     if not equal to SCSI_SCAN_INITIAL skip some code only
1178  *              needed on first scan
1179  * @hostdata:	passed to scsi_alloc_sdev()
1180  *
1181  * Description:
1182  *     Call scsi_probe_lun, if a LUN with an attached device is found,
1183  *     allocate and set it up by calling scsi_add_lun.
1184  *
1185  * Return:
1186  *
1187  *   - SCSI_SCAN_NO_RESPONSE: could not allocate or setup a scsi_device
1188  *   - SCSI_SCAN_TARGET_PRESENT: target responded, but no device is
1189  *         attached at the LUN
1190  *   - SCSI_SCAN_LUN_PRESENT: a new scsi_device was allocated and initialized
1191  **/
1192 static int scsi_probe_and_add_lun(struct Scsi_Host *shost,
1193 				  struct scsi_target *starget,
1194 				  u64 lun, blist_flags_t *bflagsp,
1195 				  struct scsi_device **sdevp,
1196 				  enum scsi_scan_mode rescan,
1197 				  void *hostdata)
1198 	__must_hold(&shost->scan_mutex)
1199 {
1200 	struct scsi_device *sdev;
1201 	unsigned char *result;
1202 	blist_flags_t bflags;
1203 	int res = SCSI_SCAN_NO_RESPONSE, result_len = 256;
1204 
1205 	/*
1206 	 * The rescan flag is used as an optimization, the first scan of a
1207 	 * host adapter calls into here with rescan == 0.
1208 	 */
1209 	sdev = scsi_device_lookup_by_target(starget, lun);
1210 	if (sdev) {
1211 		if (rescan != SCSI_SCAN_INITIAL || !scsi_device_created(sdev)) {
1212 			SCSI_LOG_SCAN_BUS(3, sdev_printk(KERN_INFO, sdev,
1213 				"scsi scan: device exists on %s\n",
1214 				dev_name(&sdev->sdev_gendev)));
1215 			if (sdevp)
1216 				*sdevp = sdev;
1217 			else
1218 				scsi_device_put(sdev);
1219 
1220 			if (bflagsp)
1221 				*bflagsp = scsi_get_device_flags(sdev,
1222 								 sdev->vendor,
1223 								 sdev->model);
1224 			return SCSI_SCAN_LUN_PRESENT;
1225 		}
1226 		scsi_device_put(sdev);
1227 	} else
1228 		sdev = scsi_alloc_sdev(starget, lun, hostdata);
1229 	if (!sdev)
1230 		goto out;
1231 
1232 	if (scsi_device_is_pseudo_dev(sdev)) {
1233 		if (bflagsp)
1234 			*bflagsp = BLIST_NOLUN;
1235 		return SCSI_SCAN_LUN_PRESENT;
1236 	}
1237 
1238 	result = kmalloc(result_len, GFP_KERNEL);
1239 	if (!result)
1240 		goto out_free_sdev;
1241 
1242 	if (scsi_probe_lun(sdev, result, result_len, &bflags))
1243 		goto out_free_result;
1244 
1245 	if (bflagsp)
1246 		*bflagsp = bflags;
1247 	/*
1248 	 * result contains valid SCSI INQUIRY data.
1249 	 */
1250 	if ((result[0] >> 5) == 3) {
1251 		/*
1252 		 * For a Peripheral qualifier 3 (011b), the SCSI
1253 		 * spec says: The device server is not capable of
1254 		 * supporting a physical device on this logical
1255 		 * unit.
1256 		 *
1257 		 * For disks, this implies that there is no
1258 		 * logical disk configured at sdev->lun, but there
1259 		 * is a target id responding.
1260 		 */
1261 		SCSI_LOG_SCAN_BUS(2, sdev_printk(KERN_INFO, sdev, "scsi scan:"
1262 				   " peripheral qualifier of 3, device not"
1263 				   " added\n"))
1264 		if (lun == 0) {
1265 			SCSI_LOG_SCAN_BUS(1, {
1266 				unsigned char vend[9];
1267 				unsigned char mod[17];
1268 
1269 				sdev_printk(KERN_INFO, sdev,
1270 					"scsi scan: consider passing scsi_mod."
1271 					"dev_flags=%s:%s:0x240 or 0x1000240\n",
1272 					scsi_inq_str(vend, result, 8, 16),
1273 					scsi_inq_str(mod, result, 16, 32));
1274 			});
1275 
1276 		}
1277 
1278 		res = SCSI_SCAN_TARGET_PRESENT;
1279 		goto out_free_result;
1280 	}
1281 
1282 	/*
1283 	 * Some targets may set slight variations of PQ and PDT to signal
1284 	 * that no LUN is present, so don't add sdev in these cases.
1285 	 * Two specific examples are:
1286 	 * 1) NetApp targets: return PQ=1, PDT=0x1f
1287 	 * 2) USB UFI: returns PDT=0x1f, with the PQ bits being "reserved"
1288 	 *    in the UFI 1.0 spec (we cannot rely on reserved bits).
1289 	 *
1290 	 * References:
1291 	 * 1) SCSI SPC-3, pp. 145-146
1292 	 * PQ=1: "A peripheral device having the specified peripheral
1293 	 * device type is not connected to this logical unit. However, the
1294 	 * device server is capable of supporting the specified peripheral
1295 	 * device type on this logical unit."
1296 	 * PDT=0x1f: "Unknown or no device type"
1297 	 * 2) USB UFI 1.0, p. 20
1298 	 * PDT=00h Direct-access device (floppy)
1299 	 * PDT=1Fh none (no FDD connected to the requested logical unit)
1300 	 */
1301 	if (((result[0] >> 5) == 1 || starget->pdt_1f_for_no_lun) &&
1302 	    (result[0] & 0x1f) == 0x1f &&
1303 	    !scsi_is_wlun(lun)) {
1304 		SCSI_LOG_SCAN_BUS(3, sdev_printk(KERN_INFO, sdev,
1305 					"scsi scan: peripheral device type"
1306 					" of 31, no device added\n"));
1307 		res = SCSI_SCAN_TARGET_PRESENT;
1308 		goto out_free_result;
1309 	}
1310 
1311 	res = scsi_add_lun(sdev, result, &bflags, shost->async_scan);
1312 	if (res == SCSI_SCAN_LUN_PRESENT) {
1313 		if (bflags & BLIST_KEY) {
1314 			sdev->lockable = 0;
1315 			scsi_unlock_floptical(sdev, result);
1316 		}
1317 	}
1318 
1319  out_free_result:
1320 	kfree(result);
1321  out_free_sdev:
1322 	if (res == SCSI_SCAN_LUN_PRESENT) {
1323 		if (sdevp) {
1324 			if (scsi_device_get(sdev) == 0) {
1325 				*sdevp = sdev;
1326 			} else {
1327 				__scsi_remove_device(sdev);
1328 				res = SCSI_SCAN_NO_RESPONSE;
1329 			}
1330 		}
1331 	} else
1332 		__scsi_remove_device(sdev);
1333  out:
1334 	return res;
1335 }
1336 
1337 /**
1338  * scsi_sequential_lun_scan - sequentially scan a SCSI target
1339  * @shost:      SCSI host pointer
1340  * @starget:	pointer to target structure to scan
1341  * @bflags:	black/white list flag for LUN 0
1342  * @scsi_level: Which version of the standard does this device adhere to
1343  * @rescan:     passed to scsi_probe_add_lun()
1344  *
1345  * Description:
1346  *     Generally, scan from LUN 1 (LUN 0 is assumed to already have been
1347  *     scanned) to some maximum lun until a LUN is found with no device
1348  *     attached. Use the bflags to figure out any oddities.
1349  *
1350  *     Modifies sdevscan->lun.
1351  **/
1352 static void scsi_sequential_lun_scan(struct Scsi_Host *shost,
1353 				     struct scsi_target *starget,
1354 				     blist_flags_t bflags, int scsi_level,
1355 				     enum scsi_scan_mode rescan)
1356 	__must_hold(&shost->scan_mutex)
1357 {
1358 	uint max_dev_lun;
1359 	u64 sparse_lun, lun;
1360 
1361 	SCSI_LOG_SCAN_BUS(3, starget_printk(KERN_INFO, starget,
1362 		"scsi scan: Sequential scan\n"));
1363 
1364 	max_dev_lun = min(max_scsi_luns, shost->max_lun);
1365 	/*
1366 	 * If this device is known to support sparse multiple units,
1367 	 * override the other settings, and scan all of them. Normally,
1368 	 * SCSI-3 devices should be scanned via the REPORT LUNS.
1369 	 */
1370 	if (bflags & BLIST_SPARSELUN) {
1371 		max_dev_lun = shost->max_lun;
1372 		sparse_lun = 1;
1373 	} else
1374 		sparse_lun = 0;
1375 
1376 	/*
1377 	 * If less than SCSI_1_CCS, and no special lun scanning, stop
1378 	 * scanning; this matches 2.4 behaviour, but could just be a bug
1379 	 * (to continue scanning a SCSI_1_CCS device).
1380 	 *
1381 	 * This test is broken.  We might not have any device on lun0 for
1382 	 * a sparselun device, and if that's the case then how would we
1383 	 * know the real scsi_level, eh?  It might make sense to just not
1384 	 * scan any SCSI_1 device for non-0 luns, but that check would best
1385 	 * go into scsi_alloc_sdev() and just have it return null when asked
1386 	 * to alloc an sdev for lun > 0 on an already found SCSI_1 device.
1387 	 *
1388 	if ((sdevscan->scsi_level < SCSI_1_CCS) &&
1389 	    ((bflags & (BLIST_FORCELUN | BLIST_SPARSELUN | BLIST_MAX5LUN))
1390 	     == 0))
1391 		return;
1392 	 */
1393 	/*
1394 	 * If this device is known to support multiple units, override
1395 	 * the other settings, and scan all of them.
1396 	 */
1397 	if (bflags & BLIST_FORCELUN)
1398 		max_dev_lun = shost->max_lun;
1399 	/*
1400 	 * REGAL CDC-4X: avoid hang after LUN 4
1401 	 */
1402 	if (bflags & BLIST_MAX5LUN)
1403 		max_dev_lun = min(5U, max_dev_lun);
1404 	/*
1405 	 * Do not scan SCSI-2 or lower device past LUN 7, unless
1406 	 * BLIST_LARGELUN.
1407 	 */
1408 	if (scsi_level < SCSI_3 && !(bflags & BLIST_LARGELUN))
1409 		max_dev_lun = min(8U, max_dev_lun);
1410 	else
1411 		max_dev_lun = min(256U, max_dev_lun);
1412 
1413 	/*
1414 	 * We have already scanned LUN 0, so start at LUN 1. Keep scanning
1415 	 * until we reach the max, or no LUN is found and we are not
1416 	 * sparse_lun.
1417 	 */
1418 	for (lun = 1; lun < max_dev_lun; ++lun)
1419 		if (scsi_probe_and_add_lun(shost, starget, lun, NULL, NULL,
1420 				rescan, NULL) != SCSI_SCAN_LUN_PRESENT &&
1421 		    !sparse_lun)
1422 			return;
1423 }
1424 
1425 /**
1426  * scsi_report_lun_scan - Scan using SCSI REPORT LUN results
1427  * @shost: SCSI host pointer
1428  * @starget: which target
1429  * @bflags: Zero or a mix of BLIST_NOLUN, BLIST_REPORTLUN2, or BLIST_NOREPORTLUN
1430  * @rescan: nonzero if we can skip code only needed on first scan
1431  *
1432  * Description:
1433  *   Fast scanning for modern (SCSI-3) devices by sending a REPORT LUN command.
1434  *   Scan the resulting list of LUNs by calling scsi_probe_and_add_lun.
1435  *
1436  *   If BLINK_REPORTLUN2 is set, scan a target that supports more than 8
1437  *   LUNs even if it's older than SCSI-3.
1438  *   If BLIST_NOREPORTLUN is set, return 1 always.
1439  *   If BLIST_NOLUN is set, return 0 always.
1440  *   If starget->no_report_luns is set, return 1 always.
1441  *
1442  * Return:
1443  *     0: scan completed (or no memory, so further scanning is futile)
1444  *     1: could not scan with REPORT LUN
1445  **/
1446 static int scsi_report_lun_scan(struct Scsi_Host *shost,
1447 			struct scsi_target *starget, blist_flags_t bflags,
1448 			enum scsi_scan_mode rescan)
1449 	__must_hold(&shost->scan_mutex)
1450 {
1451 	unsigned char scsi_cmd[MAX_COMMAND_SIZE];
1452 	unsigned int length;
1453 	u64 lun;
1454 	unsigned int num_luns;
1455 	int result;
1456 	struct scsi_lun *lunp, *lun_data;
1457 	struct scsi_device *sdev;
1458 	struct scsi_failure failure_defs[] = {
1459 		{
1460 			.sense = UNIT_ATTENTION,
1461 			.asc = SCMD_FAILURE_ASC_ANY,
1462 			.ascq = SCMD_FAILURE_ASCQ_ANY,
1463 			.result = SAM_STAT_CHECK_CONDITION,
1464 		},
1465 		/* Fail all CCs except the UA above */
1466 		{
1467 			.sense = SCMD_FAILURE_SENSE_ANY,
1468 			.result = SAM_STAT_CHECK_CONDITION,
1469 		},
1470 		/* Retry any other errors not listed above */
1471 		{
1472 			.result = SCMD_FAILURE_RESULT_ANY,
1473 		},
1474 		{}
1475 	};
1476 	struct scsi_failures failures = {
1477 		.total_allowed = 3,
1478 		.failure_definitions = failure_defs,
1479 	};
1480 	const struct scsi_exec_args exec_args = {
1481 		.failures = &failures,
1482 	};
1483 	int ret = 0;
1484 
1485 	/*
1486 	 * Only support SCSI-3 and up devices if BLIST_NOREPORTLUN is not set.
1487 	 * Also allow SCSI-2 if BLIST_REPORTLUN2 is set and host adapter does
1488 	 * support more than 8 LUNs.
1489 	 * Don't attempt if the target doesn't support REPORT LUNS.
1490 	 */
1491 	if (bflags & BLIST_NOREPORTLUN)
1492 		return 1;
1493 	if (starget->scsi_level < SCSI_2 &&
1494 	    starget->scsi_level != SCSI_UNKNOWN)
1495 		return 1;
1496 	if (starget->scsi_level < SCSI_3 &&
1497 	    (!(bflags & BLIST_REPORTLUN2) || shost->max_lun <= 8))
1498 		return 1;
1499 	if (bflags & BLIST_NOLUN)
1500 		return 0;
1501 	if (starget->no_report_luns)
1502 		return 1;
1503 
1504 	if (!(sdev = scsi_device_lookup_by_target(starget, 0))) {
1505 		sdev = scsi_alloc_sdev(starget, 0, NULL);
1506 		if (!sdev)
1507 			return 0;
1508 		if (scsi_device_get(sdev)) {
1509 			__scsi_remove_device(sdev);
1510 			return 0;
1511 		}
1512 	}
1513 
1514 	/*
1515 	 * Allocate enough to hold the header (the same size as one scsi_lun)
1516 	 * plus the number of luns we are requesting.  511 was the default
1517 	 * value of the now removed max_report_luns parameter.
1518 	 */
1519 	length = (511 + 1) * sizeof(struct scsi_lun);
1520 retry:
1521 	lun_data = kmalloc(length, GFP_KERNEL);
1522 	if (!lun_data) {
1523 		printk(ALLOC_FAILURE_MSG, __func__);
1524 		goto out;
1525 	}
1526 
1527 	scsi_cmd[0] = REPORT_LUNS;
1528 
1529 	/*
1530 	 * bytes 1 - 5: reserved, set to zero.
1531 	 */
1532 	memset(&scsi_cmd[1], 0, 5);
1533 
1534 	/*
1535 	 * bytes 6 - 9: length of the command.
1536 	 */
1537 	put_unaligned_be32(length, &scsi_cmd[6]);
1538 
1539 	scsi_cmd[10] = 0;	/* reserved */
1540 	scsi_cmd[11] = 0;	/* control */
1541 
1542 	/*
1543 	 * We can get a UNIT ATTENTION, for example a power on/reset, so
1544 	 * retry a few times (like sd.c does for TEST UNIT READY).
1545 	 * Experience shows some combinations of adapter/devices get at
1546 	 * least two power on/resets.
1547 	 *
1548 	 * Illegal requests (for devices that do not support REPORT LUNS)
1549 	 * should come through as a check condition, and will not generate
1550 	 * a retry.
1551 	 */
1552 	scsi_failures_reset_retries(&failures);
1553 
1554 	SCSI_LOG_SCAN_BUS(3, sdev_printk (KERN_INFO, sdev,
1555 			  "scsi scan: Sending REPORT LUNS\n"));
1556 
1557 	result = scsi_execute_cmd(sdev, scsi_cmd, REQ_OP_DRV_IN, lun_data,
1558 				  length, SCSI_REPORT_LUNS_TIMEOUT, 3,
1559 				  &exec_args);
1560 
1561 	SCSI_LOG_SCAN_BUS(3, sdev_printk (KERN_INFO, sdev,
1562 			  "scsi scan: REPORT LUNS  %s result 0x%x\n",
1563 			  result ?  "failed" : "successful", result));
1564 	if (result) {
1565 		/*
1566 		 * The device probably does not support a REPORT LUN command
1567 		 */
1568 		ret = 1;
1569 		goto out_err;
1570 	}
1571 
1572 	/*
1573 	 * Get the length from the first four bytes of lun_data.
1574 	 */
1575 	if (get_unaligned_be32(lun_data->scsi_lun) +
1576 	    sizeof(struct scsi_lun) > length) {
1577 		length = get_unaligned_be32(lun_data->scsi_lun) +
1578 			 sizeof(struct scsi_lun);
1579 		kfree(lun_data);
1580 		goto retry;
1581 	}
1582 	length = get_unaligned_be32(lun_data->scsi_lun);
1583 
1584 	num_luns = (length / sizeof(struct scsi_lun));
1585 
1586 	SCSI_LOG_SCAN_BUS(3, sdev_printk (KERN_INFO, sdev,
1587 		"scsi scan: REPORT LUN scan\n"));
1588 
1589 	/*
1590 	 * Scan the luns in lun_data. The entry at offset 0 is really
1591 	 * the header, so start at 1 and go up to and including num_luns.
1592 	 */
1593 	for (lunp = &lun_data[1]; lunp <= &lun_data[num_luns]; lunp++) {
1594 		lun = scsilun_to_int(lunp);
1595 
1596 		if (lun > sdev->host->max_lun) {
1597 			sdev_printk(KERN_WARNING, sdev,
1598 				    "lun%llu has a LUN larger than"
1599 				    " allowed by the host adapter\n", lun);
1600 		} else {
1601 			int res;
1602 
1603 			res = scsi_probe_and_add_lun(shost, starget,
1604 				lun, NULL, NULL, rescan, NULL);
1605 			if (res == SCSI_SCAN_NO_RESPONSE) {
1606 				/*
1607 				 * Got some results, but now none, abort.
1608 				 */
1609 				sdev_printk(KERN_ERR, sdev,
1610 					"Unexpected response"
1611 					" from lun %llu while scanning, scan"
1612 					" aborted\n", (unsigned long long)lun);
1613 				break;
1614 			}
1615 		}
1616 	}
1617 
1618  out_err:
1619 	kfree(lun_data);
1620  out:
1621 	if (scsi_device_created(sdev))
1622 		/*
1623 		 * the sdev we used didn't appear in the report luns scan
1624 		 */
1625 		__scsi_remove_device(sdev);
1626 	scsi_device_put(sdev);
1627 	return ret;
1628 }
1629 
1630 struct scsi_device *__scsi_add_device(struct Scsi_Host *shost, uint channel,
1631 				      uint id, u64 lun, void *hostdata)
1632 {
1633 	struct scsi_device *sdev = ERR_PTR(-ENODEV);
1634 	struct device *parent = &shost->shost_gendev;
1635 	struct scsi_target *starget;
1636 
1637 	if (strncmp(scsi_scan_type, "none", 4) == 0)
1638 		return ERR_PTR(-ENODEV);
1639 
1640 	starget = scsi_alloc_target(parent, channel, id);
1641 	if (!starget)
1642 		return ERR_PTR(-ENOMEM);
1643 	scsi_autopm_get_target(starget);
1644 
1645 	mutex_lock(&shost->scan_mutex);
1646 	if (!shost->async_scan)
1647 		scsi_complete_async_scans();
1648 
1649 	if (scsi_host_scan_allowed(shost) && scsi_autopm_get_host(shost) == 0) {
1650 		scsi_probe_and_add_lun(shost, starget, lun, NULL, &sdev,
1651 				       SCSI_SCAN_RESCAN, hostdata);
1652 		scsi_autopm_put_host(shost);
1653 	}
1654 	mutex_unlock(&shost->scan_mutex);
1655 	scsi_autopm_put_target(starget);
1656 	/*
1657 	 * paired with scsi_alloc_target().  Target will be destroyed unless
1658 	 * scsi_probe_and_add_lun made an underlying device visible
1659 	 */
1660 	scsi_target_reap(starget);
1661 	put_device(&starget->dev);
1662 
1663 	return sdev;
1664 }
1665 EXPORT_SYMBOL(__scsi_add_device);
1666 
1667 /**
1668  * scsi_add_device - creates a new SCSI (LU) instance
1669  * @host: the &Scsi_Host instance where the device is located
1670  * @channel: target channel number (rarely other than %0)
1671  * @target: target id number
1672  * @lun: LUN of target device
1673  *
1674  * Probe for a specific LUN and add it if found.
1675  *
1676  * Notes: This call is usually performed internally during a SCSI
1677  * bus scan when an HBA is added (i.e. scsi_scan_host()). So it
1678  * should only be called if the HBA becomes aware of a new SCSI
1679  * device (LU) after scsi_scan_host() has completed. If successful
1680  * this call can lead to sdev_init() and sdev_configure() callbacks
1681  * into the LLD.
1682  *
1683  * Return: %0 on success or negative error code on failure
1684  */
1685 int scsi_add_device(struct Scsi_Host *host, uint channel,
1686 		    uint target, u64 lun)
1687 {
1688 	struct scsi_device *sdev =
1689 		__scsi_add_device(host, channel, target, lun, NULL);
1690 	if (IS_ERR(sdev))
1691 		return PTR_ERR(sdev);
1692 
1693 	scsi_device_put(sdev);
1694 	return 0;
1695 }
1696 EXPORT_SYMBOL(scsi_add_device);
1697 
1698 int scsi_resume_device(struct scsi_device *sdev)
1699 {
1700 	struct device *dev = &sdev->sdev_gendev;
1701 	int ret = 0;
1702 
1703 	device_lock(dev);
1704 
1705 	/*
1706 	 * Bail out if the device or its queue are not running. Otherwise,
1707 	 * the rescan may block waiting for commands to be executed, with us
1708 	 * holding the device lock. This can result in a potential deadlock
1709 	 * in the power management core code when system resume is on-going.
1710 	 */
1711 	if (sdev->sdev_state != SDEV_RUNNING ||
1712 	    blk_queue_pm_only(sdev->request_queue)) {
1713 		ret = -EWOULDBLOCK;
1714 		goto unlock;
1715 	}
1716 
1717 	if (dev->driver && try_module_get(dev->driver->owner)) {
1718 		struct scsi_driver *drv = to_scsi_driver(dev->driver);
1719 
1720 		if (drv->resume)
1721 			ret = drv->resume(dev);
1722 		module_put(dev->driver->owner);
1723 	}
1724 
1725 unlock:
1726 	device_unlock(dev);
1727 
1728 	return ret;
1729 }
1730 EXPORT_SYMBOL(scsi_resume_device);
1731 
1732 int scsi_rescan_device(struct scsi_device *sdev)
1733 {
1734 	struct device *dev = &sdev->sdev_gendev;
1735 	int ret = 0;
1736 
1737 	device_lock(dev);
1738 
1739 	/*
1740 	 * Bail out if the device or its queue are not running. Otherwise,
1741 	 * the rescan may block waiting for commands to be executed, with us
1742 	 * holding the device lock. This can result in a potential deadlock
1743 	 * in the power management core code when system resume is on-going.
1744 	 */
1745 	if (sdev->sdev_state != SDEV_RUNNING ||
1746 	    blk_queue_pm_only(sdev->request_queue)) {
1747 		ret = -EWOULDBLOCK;
1748 		goto unlock;
1749 	}
1750 
1751 	scsi_attach_vpd(sdev);
1752 	scsi_cdl_check(sdev);
1753 
1754 	if (sdev->handler && sdev->handler->rescan)
1755 		sdev->handler->rescan(sdev);
1756 
1757 	if (dev->driver && try_module_get(dev->driver->owner)) {
1758 		struct scsi_driver *drv = to_scsi_driver(dev->driver);
1759 
1760 		if (drv->rescan)
1761 			drv->rescan(dev);
1762 		module_put(dev->driver->owner);
1763 	}
1764 
1765 unlock:
1766 	device_unlock(dev);
1767 
1768 	return ret;
1769 }
1770 EXPORT_SYMBOL(scsi_rescan_device);
1771 
1772 static void __scsi_scan_target(struct Scsi_Host *shost, struct device *parent,
1773 			       unsigned int channel, unsigned int id, u64 lun,
1774 			       enum scsi_scan_mode rescan)
1775 	__must_hold(&shost->scan_mutex)
1776 {
1777 	blist_flags_t bflags = 0;
1778 	int res;
1779 	struct scsi_target *starget;
1780 
1781 	if (shost->this_id == id)
1782 		/*
1783 		 * Don't scan the host adapter
1784 		 */
1785 		return;
1786 
1787 	starget = scsi_alloc_target(parent, channel, id);
1788 	if (!starget)
1789 		return;
1790 	scsi_autopm_get_target(starget);
1791 
1792 	if (lun != SCAN_WILD_CARD) {
1793 		/*
1794 		 * Scan for a specific host/chan/id/lun.
1795 		 */
1796 		scsi_probe_and_add_lun(shost, starget, lun, NULL, NULL, rescan,
1797 				       NULL);
1798 		goto out_reap;
1799 	}
1800 
1801 	/*
1802 	 * Scan LUN 0, if there is some response, scan further. Ideally, we
1803 	 * would not configure LUN 0 until all LUNs are scanned.
1804 	 */
1805 	res = scsi_probe_and_add_lun(shost, starget, 0, &bflags, NULL, rescan,
1806 				     NULL);
1807 	if (res == SCSI_SCAN_LUN_PRESENT || res == SCSI_SCAN_TARGET_PRESENT) {
1808 		if (scsi_report_lun_scan(shost, starget, bflags, rescan) != 0)
1809 			/*
1810 			 * The REPORT LUN did not scan the target,
1811 			 * do a sequential scan.
1812 			 */
1813 			scsi_sequential_lun_scan(shost, starget, bflags,
1814 						 starget->scsi_level, rescan);
1815 	}
1816 
1817  out_reap:
1818 	scsi_autopm_put_target(starget);
1819 	/*
1820 	 * paired with scsi_alloc_target(): determine if the target has
1821 	 * any children at all and if not, nuke it
1822 	 */
1823 	scsi_target_reap(starget);
1824 
1825 	put_device(&starget->dev);
1826 }
1827 
1828 /**
1829  * scsi_scan_target - scan a target id, possibly including all LUNs on the target.
1830  * @parent:	host to scan
1831  * @channel:	channel to scan
1832  * @id:		target id to scan
1833  * @lun:	Specific LUN to scan or SCAN_WILD_CARD
1834  * @rescan:	passed to LUN scanning routines; SCSI_SCAN_INITIAL for
1835  *              no rescan, SCSI_SCAN_RESCAN to rescan existing LUNs,
1836  *              and SCSI_SCAN_MANUAL to force scanning even if
1837  *              'scan=manual' is set.
1838  *
1839  * Description:
1840  *     Scan the target id on @parent, @channel, and @id. Scan at least LUN 0,
1841  *     and possibly all LUNs on the target id.
1842  *
1843  *     First try a REPORT LUN scan, if that does not scan the target, do a
1844  *     sequential scan of LUNs on the target id.
1845  **/
1846 void scsi_scan_target(struct device *parent, unsigned int channel,
1847 		      unsigned int id, u64 lun, enum scsi_scan_mode rescan)
1848 {
1849 	struct Scsi_Host *shost = dev_to_shost(parent);
1850 
1851 	if (strncmp(scsi_scan_type, "none", 4) == 0)
1852 		return;
1853 
1854 	if (rescan != SCSI_SCAN_MANUAL &&
1855 	    strncmp(scsi_scan_type, "manual", 6) == 0)
1856 		return;
1857 
1858 	mutex_lock(&shost->scan_mutex);
1859 	if (!shost->async_scan)
1860 		scsi_complete_async_scans();
1861 
1862 	if (scsi_host_scan_allowed(shost) && scsi_autopm_get_host(shost) == 0) {
1863 		__scsi_scan_target(shost, parent, channel, id, lun, rescan);
1864 		scsi_autopm_put_host(shost);
1865 	}
1866 	mutex_unlock(&shost->scan_mutex);
1867 }
1868 EXPORT_SYMBOL(scsi_scan_target);
1869 
1870 static void scsi_scan_channel(struct Scsi_Host *shost, unsigned int channel,
1871 			      unsigned int id, u64 lun,
1872 			      enum scsi_scan_mode rescan)
1873 	__must_hold(&shost->scan_mutex)
1874 {
1875 	uint order_id;
1876 
1877 	if (id == SCAN_WILD_CARD)
1878 		for (id = 0; id < shost->max_id; ++id) {
1879 			/*
1880 			 * XXX adapter drivers when possible (FCP, iSCSI)
1881 			 * could modify max_id to match the current max,
1882 			 * not the absolute max.
1883 			 *
1884 			 * XXX add a shost id iterator, so for example,
1885 			 * the FC ID can be the same as a target id
1886 			 * without a huge overhead of sparse id's.
1887 			 */
1888 			if (shost->reverse_ordering)
1889 				/*
1890 				 * Scan from high to low id.
1891 				 */
1892 				order_id = shost->max_id - id - 1;
1893 			else
1894 				order_id = id;
1895 			__scsi_scan_target(shost, &shost->shost_gendev, channel,
1896 					order_id, lun, rescan);
1897 		}
1898 	else
1899 		__scsi_scan_target(shost, &shost->shost_gendev, channel,
1900 				id, lun, rescan);
1901 }
1902 
1903 int scsi_scan_host_selected(struct Scsi_Host *shost, unsigned int channel,
1904 			    unsigned int id, u64 lun,
1905 			    enum scsi_scan_mode rescan)
1906 {
1907 	SCSI_LOG_SCAN_BUS(3, shost_printk (KERN_INFO, shost,
1908 		"%s: <%u:%u:%llu>\n",
1909 		__func__, channel, id, lun));
1910 
1911 	if (((channel != SCAN_WILD_CARD) && (channel > shost->max_channel)) ||
1912 	    ((id != SCAN_WILD_CARD) && (id >= shost->max_id)) ||
1913 	    ((lun != SCAN_WILD_CARD) && (lun >= shost->max_lun)))
1914 		return -EINVAL;
1915 
1916 	mutex_lock(&shost->scan_mutex);
1917 	if (!shost->async_scan)
1918 		scsi_complete_async_scans();
1919 
1920 	if (scsi_host_scan_allowed(shost) && scsi_autopm_get_host(shost) == 0) {
1921 		if (channel == SCAN_WILD_CARD)
1922 			for (channel = 0; channel <= shost->max_channel;
1923 			     channel++)
1924 				scsi_scan_channel(shost, channel, id, lun,
1925 						  rescan);
1926 		else
1927 			scsi_scan_channel(shost, channel, id, lun, rescan);
1928 		scsi_autopm_put_host(shost);
1929 	}
1930 	mutex_unlock(&shost->scan_mutex);
1931 
1932 	return 0;
1933 }
1934 
1935 static void scsi_sysfs_add_devices(struct Scsi_Host *shost)
1936 {
1937 	struct scsi_device *sdev;
1938 	shost_for_each_device(sdev, shost) {
1939 		/* target removed before the device could be added */
1940 		if (sdev->sdev_state == SDEV_DEL)
1941 			continue;
1942 		/* If device is already visible, skip adding it to sysfs */
1943 		if (sdev->is_visible)
1944 			continue;
1945 		if (!scsi_host_scan_allowed(shost) ||
1946 		    scsi_sysfs_add_sdev(sdev) != 0)
1947 			__scsi_remove_device(sdev);
1948 	}
1949 }
1950 
1951 /**
1952  * scsi_prep_async_scan - prepare for an async scan
1953  * @shost: the host which will be scanned
1954  * Returns: a cookie to be passed to scsi_finish_async_scan()
1955  *
1956  * Tells the midlayer this host is going to do an asynchronous scan.
1957  * It reserves the host's position in the scanning list and ensures
1958  * that other asynchronous scans started after this one won't affect the
1959  * ordering of the discovered devices.
1960  */
1961 static struct async_scan_data *scsi_prep_async_scan(struct Scsi_Host *shost)
1962 {
1963 	struct async_scan_data *data = NULL;
1964 
1965 	if (strncmp(scsi_scan_type, "sync", 4) == 0)
1966 		return NULL;
1967 
1968 	mutex_lock(&shost->scan_mutex);
1969 	if (shost->async_scan) {
1970 		shost_printk(KERN_DEBUG, shost, "%s called twice\n", __func__);
1971 		goto err;
1972 	}
1973 
1974 	data = kmalloc_obj(*data);
1975 	if (!data)
1976 		goto err;
1977 	data->shost = scsi_host_get(shost);
1978 	if (!data->shost)
1979 		goto err;
1980 	init_completion(&data->prev_finished);
1981 
1982 	shost->async_scan = true;
1983 	mutex_unlock(&shost->scan_mutex);
1984 
1985 	spin_lock(&async_scan_lock);
1986 	if (list_empty(&scanning_hosts))
1987 		complete(&data->prev_finished);
1988 	list_add_tail(&data->list, &scanning_hosts);
1989 	spin_unlock(&async_scan_lock);
1990 
1991 	return data;
1992 
1993  err:
1994 	mutex_unlock(&shost->scan_mutex);
1995 	kfree(data);
1996 	return NULL;
1997 }
1998 
1999 /**
2000  * scsi_finish_async_scan - asynchronous scan has finished
2001  * @data: cookie returned from earlier call to scsi_prep_async_scan()
2002  *
2003  * All the devices currently attached to this host have been found.
2004  * This function announces all the devices it has found to the rest
2005  * of the system.
2006  */
2007 static void scsi_finish_async_scan(struct async_scan_data *data)
2008 {
2009 	struct Scsi_Host *shost;
2010 
2011 	if (!data)
2012 		return;
2013 
2014 	shost = data->shost;
2015 
2016 	mutex_lock(&shost->scan_mutex);
2017 
2018 	if (!shost->async_scan) {
2019 		shost_printk(KERN_INFO, shost, "%s called twice\n", __func__);
2020 		dump_stack();
2021 		mutex_unlock(&shost->scan_mutex);
2022 		return;
2023 	}
2024 
2025 	wait_for_completion(&data->prev_finished);
2026 
2027 	scsi_sysfs_add_devices(shost);
2028 
2029 	shost->async_scan = false;
2030 
2031 	mutex_unlock(&shost->scan_mutex);
2032 
2033 	spin_lock(&async_scan_lock);
2034 	list_del(&data->list);
2035 	if (!list_empty(&scanning_hosts)) {
2036 		struct async_scan_data *next = list_entry(scanning_hosts.next,
2037 				struct async_scan_data, list);
2038 		complete(&next->prev_finished);
2039 	}
2040 	spin_unlock(&async_scan_lock);
2041 
2042 	scsi_autopm_put_host(shost);
2043 	scsi_host_put(shost);
2044 	kfree(data);
2045 }
2046 
2047 static void do_scsi_scan_host(struct Scsi_Host *shost)
2048 {
2049 	if (shost->hostt->scan_finished) {
2050 		unsigned long start = jiffies;
2051 		if (shost->hostt->scan_start)
2052 			shost->hostt->scan_start(shost);
2053 
2054 		while (!shost->hostt->scan_finished(shost, jiffies - start))
2055 			msleep(10);
2056 	} else {
2057 		scsi_scan_host_selected(shost, SCAN_WILD_CARD, SCAN_WILD_CARD,
2058 				SCAN_WILD_CARD, SCSI_SCAN_INITIAL);
2059 	}
2060 }
2061 
2062 static void do_scan_async(void *_data, async_cookie_t c)
2063 {
2064 	struct async_scan_data *data = _data;
2065 	struct Scsi_Host *shost = data->shost;
2066 
2067 	do_scsi_scan_host(shost);
2068 	scsi_finish_async_scan(data);
2069 }
2070 
2071 /**
2072  * scsi_scan_host - scan the given adapter
2073  * @shost:	adapter to scan
2074  *
2075  * Notes: Should be called after scsi_add_host()
2076  **/
2077 void scsi_scan_host(struct Scsi_Host *shost)
2078 {
2079 	struct async_scan_data *data;
2080 
2081 	if (strncmp(scsi_scan_type, "none", 4) == 0 ||
2082 	    strncmp(scsi_scan_type, "manual", 6) == 0)
2083 		return;
2084 	if (scsi_autopm_get_host(shost) < 0)
2085 		return;
2086 
2087 	data = scsi_prep_async_scan(shost);
2088 	if (!data) {
2089 		do_scsi_scan_host(shost);
2090 		scsi_autopm_put_host(shost);
2091 		return;
2092 	}
2093 
2094 	/* register with the async subsystem so wait_for_device_probe()
2095 	 * will flush this work
2096 	 */
2097 	async_schedule(do_scan_async, data);
2098 
2099 	/* scsi_autopm_put_host(shost) is called in scsi_finish_async_scan() */
2100 }
2101 EXPORT_SYMBOL(scsi_scan_host);
2102 
2103 void scsi_forget_host(struct Scsi_Host *shost)
2104 {
2105 	struct scsi_device *sdev;
2106 	unsigned long flags;
2107 
2108  restart:
2109 	spin_lock_irqsave(shost->host_lock, flags);
2110 	list_for_each_entry(sdev, &shost->__devices, siblings) {
2111 		if (scsi_device_is_pseudo_dev(sdev) ||
2112 		    sdev->sdev_state == SDEV_DEL)
2113 			continue;
2114 		spin_unlock_irqrestore(shost->host_lock, flags);
2115 		__scsi_remove_device(sdev);
2116 		goto restart;
2117 	}
2118 	spin_unlock_irqrestore(shost->host_lock, flags);
2119 
2120 	/*
2121 	 * Remove the pseudo device last since it may be needed during removal
2122 	 * of other SCSI devices.
2123 	 */
2124 	if (shost->pseudo_sdev)
2125 		__scsi_remove_device(shost->pseudo_sdev);
2126 }
2127 
2128 /**
2129  * scsi_get_pseudo_sdev() - Attach a pseudo SCSI device to a SCSI host
2130  * @shost: Host that needs a pseudo SCSI device
2131  *
2132  * Lock status: None assumed.
2133  *
2134  * Returns:     The scsi_device or NULL
2135  *
2136  * Notes:
2137  *	Attach a single scsi_device to the Scsi_Host. The primary aim for this
2138  *	device is to serve as a container from which SCSI commands can be
2139  *	allocated. Each SCSI command will carry a command tag allocated by the
2140  *	block layer. These SCSI commands can be used by the LLDD to send
2141  *	internal or passthrough commands without having to manage tag allocation
2142  *	inside the LLDD.
2143  */
2144 struct scsi_device *scsi_get_pseudo_sdev(struct Scsi_Host *shost)
2145 {
2146 	struct scsi_device *sdev = NULL;
2147 	struct scsi_target *starget;
2148 
2149 	guard(mutex)(&shost->scan_mutex);
2150 
2151 	if (!scsi_host_scan_allowed(shost))
2152 		goto out;
2153 
2154 	starget = scsi_alloc_target(&shost->shost_gendev, 0, shost->max_id);
2155 	if (!starget)
2156 		goto out;
2157 
2158 	sdev = scsi_alloc_sdev(starget, U64_MAX, NULL);
2159 	if (!sdev) {
2160 		scsi_target_reap(starget);
2161 		goto put_target;
2162 	}
2163 
2164 	sdev->borken = 0;
2165 
2166 put_target:
2167 	/* See also the get_device(dev) call in scsi_alloc_target(). */
2168 	put_device(&starget->dev);
2169 
2170 out:
2171 	return sdev;
2172 }
2173