]> CyberLeo.Net >> Repos - FreeBSD/stable/10.git/blob - sys/cam/ctl/ctl_tpc.c
MFC r310285:
[FreeBSD/stable/10.git] / sys / cam / ctl / ctl_tpc.c
1 /*-
2  * Copyright (c) 2014 Alexander Motin <mav@FreeBSD.org>
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer,
10  *    without modification, immediately at the beginning of the file.
11  * 2. Redistributions in binary form must reproduce the above copyright
12  *    notice, this list of conditions and the following disclaimer in the
13  *    documentation and/or other materials provided with the distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
16  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
17  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
18  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
19  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
20  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
21  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
22  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
24  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25  */
26
27 #include <sys/cdefs.h>
28 __FBSDID("$FreeBSD$");
29
30 #include <sys/param.h>
31 #include <sys/systm.h>
32 #include <sys/kernel.h>
33 #include <sys/types.h>
34 #include <sys/lock.h>
35 #include <sys/module.h>
36 #include <sys/mutex.h>
37 #include <sys/condvar.h>
38 #include <sys/malloc.h>
39 #include <sys/conf.h>
40 #include <sys/queue.h>
41 #include <sys/sysctl.h>
42 #include <machine/atomic.h>
43
44 #include <cam/cam.h>
45 #include <cam/scsi/scsi_all.h>
46 #include <cam/scsi/scsi_da.h>
47 #include <cam/ctl/ctl_io.h>
48 #include <cam/ctl/ctl.h>
49 #include <cam/ctl/ctl_frontend.h>
50 #include <cam/ctl/ctl_util.h>
51 #include <cam/ctl/ctl_backend.h>
52 #include <cam/ctl/ctl_ioctl.h>
53 #include <cam/ctl/ctl_ha.h>
54 #include <cam/ctl/ctl_private.h>
55 #include <cam/ctl/ctl_debug.h>
56 #include <cam/ctl/ctl_scsi_all.h>
57 #include <cam/ctl/ctl_tpc.h>
58 #include <cam/ctl/ctl_error.h>
59
60 #define TPC_MAX_CSCDS   64
61 #define TPC_MAX_SEGS    64
62 #define TPC_MAX_SEG     0
63 #define TPC_MAX_LIST    8192
64 #define TPC_MAX_INLINE  0
65 #define TPC_MAX_LISTS   255
66 #define TPC_MAX_IO_SIZE (1024 * 1024)
67 #define TPC_MAX_IOCHUNK_SIZE    (TPC_MAX_IO_SIZE * 16)
68 #define TPC_MIN_TOKEN_TIMEOUT   1
69 #define TPC_DFL_TOKEN_TIMEOUT   60
70 #define TPC_MAX_TOKEN_TIMEOUT   600
71
72 MALLOC_DEFINE(M_CTL_TPC, "ctltpc", "CTL TPC");
73
74 typedef enum {
75         TPC_ERR_RETRY           = 0x000,
76         TPC_ERR_FAIL            = 0x001,
77         TPC_ERR_MASK            = 0x0ff,
78         TPC_ERR_NO_DECREMENT    = 0x100
79 } tpc_error_action;
80
81 struct tpc_list;
82 TAILQ_HEAD(runl, tpc_io);
83 struct tpc_io {
84         union ctl_io            *io;
85         uint64_t                 lun;
86         struct tpc_list         *list;
87         struct runl              run;
88         TAILQ_ENTRY(tpc_io)      rlinks;
89         TAILQ_ENTRY(tpc_io)      links;
90 };
91
92 struct tpc_token {
93         uint8_t                  token[512];
94         uint64_t                 lun;
95         uint32_t                 blocksize;
96         uint8_t                 *params;
97         struct scsi_range_desc  *range;
98         int                      nrange;
99         int                      active;
100         time_t                   last_active;
101         uint32_t                 timeout;
102         TAILQ_ENTRY(tpc_token)   links;
103 };
104
105 struct tpc_list {
106         uint8_t                  service_action;
107         int                      init_port;
108         uint32_t                 init_idx;
109         uint32_t                 list_id;
110         uint8_t                  flags;
111         uint8_t                 *params;
112         struct scsi_ec_cscd     *cscd;
113         struct scsi_ec_segment  *seg[TPC_MAX_SEGS];
114         uint8_t                 *inl;
115         int                      ncscd;
116         int                      nseg;
117         int                      leninl;
118         struct tpc_token        *token;
119         struct scsi_range_desc  *range;
120         int                      nrange;
121         off_t                    offset_into_rod;
122
123         int                      curseg;
124         off_t                    cursectors;
125         off_t                    curbytes;
126         int                      curops;
127         int                      stage;
128         uint8_t                 *buf;
129         off_t                    segsectors;
130         off_t                    segbytes;
131         int                      tbdio;
132         int                      error;
133         int                      abort;
134         int                      completed;
135         time_t                   last_active;
136         TAILQ_HEAD(, tpc_io)     allio;
137         struct scsi_sense_data   sense_data;
138         uint8_t                  sense_len;
139         uint8_t                  scsi_status;
140         struct ctl_scsiio       *ctsio;
141         struct ctl_lun          *lun;
142         int                      res_token_valid;
143         uint8_t                  res_token[512];
144         TAILQ_ENTRY(tpc_list)    links;
145 };
146
147 static void
148 tpc_timeout(void *arg)
149 {
150         struct ctl_softc *softc = arg;
151         struct ctl_lun *lun;
152         struct tpc_token *token, *ttoken;
153         struct tpc_list *list, *tlist;
154
155         /* Free completed lists with expired timeout. */
156         STAILQ_FOREACH(lun, &softc->lun_list, links) {
157                 mtx_lock(&lun->lun_lock);
158                 TAILQ_FOREACH_SAFE(list, &lun->tpc_lists, links, tlist) {
159                         if (!list->completed || time_uptime < list->last_active +
160                             TPC_DFL_TOKEN_TIMEOUT)
161                                 continue;
162                         TAILQ_REMOVE(&lun->tpc_lists, list, links);
163                         free(list, M_CTL);
164                 }
165                 mtx_unlock(&lun->lun_lock);
166         }
167
168         /* Free inactive ROD tokens with expired timeout. */
169         mtx_lock(&softc->tpc_lock);
170         TAILQ_FOREACH_SAFE(token, &softc->tpc_tokens, links, ttoken) {
171                 if (token->active ||
172                     time_uptime < token->last_active + token->timeout + 1)
173                         continue;
174                 TAILQ_REMOVE(&softc->tpc_tokens, token, links);
175                 free(token->params, M_CTL);
176                 free(token, M_CTL);
177         }
178         mtx_unlock(&softc->tpc_lock);
179         callout_schedule(&softc->tpc_timeout, hz);
180 }
181
182 void
183 ctl_tpc_init(struct ctl_softc *softc)
184 {
185
186         mtx_init(&softc->tpc_lock, "CTL TPC mutex", NULL, MTX_DEF);
187         TAILQ_INIT(&softc->tpc_tokens);
188         callout_init_mtx(&softc->tpc_timeout, &softc->ctl_lock, 0);
189         callout_reset(&softc->tpc_timeout, hz, tpc_timeout, softc);
190 }
191
192 void
193 ctl_tpc_shutdown(struct ctl_softc *softc)
194 {
195         struct tpc_token *token;
196
197         callout_drain(&softc->tpc_timeout);
198
199         /* Free ROD tokens. */
200         mtx_lock(&softc->tpc_lock);
201         while ((token = TAILQ_FIRST(&softc->tpc_tokens)) != NULL) {
202                 TAILQ_REMOVE(&softc->tpc_tokens, token, links);
203                 free(token->params, M_CTL);
204                 free(token, M_CTL);
205         }
206         mtx_unlock(&softc->tpc_lock);
207         mtx_destroy(&softc->tpc_lock);
208 }
209
210 void
211 ctl_tpc_lun_init(struct ctl_lun *lun)
212 {
213
214         TAILQ_INIT(&lun->tpc_lists);
215 }
216
217 void
218 ctl_tpc_lun_shutdown(struct ctl_lun *lun)
219 {
220         struct ctl_softc *softc = lun->ctl_softc;
221         struct tpc_list *list;
222         struct tpc_token *token, *ttoken;
223
224         /* Free lists for this LUN. */
225         while ((list = TAILQ_FIRST(&lun->tpc_lists)) != NULL) {
226                 TAILQ_REMOVE(&lun->tpc_lists, list, links);
227                 KASSERT(list->completed,
228                     ("Not completed TPC (%p) on shutdown", list));
229                 free(list, M_CTL);
230         }
231
232         /* Free ROD tokens for this LUN. */
233         mtx_lock(&softc->tpc_lock);
234         TAILQ_FOREACH_SAFE(token, &softc->tpc_tokens, links, ttoken) {
235                 if (token->lun != lun->lun || token->active)
236                         continue;
237                 TAILQ_REMOVE(&softc->tpc_tokens, token, links);
238                 free(token->params, M_CTL);
239                 free(token, M_CTL);
240         }
241         mtx_unlock(&softc->tpc_lock);
242 }
243
244 int
245 ctl_inquiry_evpd_tpc(struct ctl_scsiio *ctsio, int alloc_len)
246 {
247         struct scsi_vpd_tpc *tpc_ptr;
248         struct scsi_vpd_tpc_descriptor *d_ptr;
249         struct scsi_vpd_tpc_descriptor_bdrl *bdrl_ptr;
250         struct scsi_vpd_tpc_descriptor_sc *sc_ptr;
251         struct scsi_vpd_tpc_descriptor_sc_descr *scd_ptr;
252         struct scsi_vpd_tpc_descriptor_pd *pd_ptr;
253         struct scsi_vpd_tpc_descriptor_sd *sd_ptr;
254         struct scsi_vpd_tpc_descriptor_sdid *sdid_ptr;
255         struct scsi_vpd_tpc_descriptor_rtf *rtf_ptr;
256         struct scsi_vpd_tpc_descriptor_rtf_block *rtfb_ptr;
257         struct scsi_vpd_tpc_descriptor_srt *srt_ptr;
258         struct scsi_vpd_tpc_descriptor_srtd *srtd_ptr;
259         struct scsi_vpd_tpc_descriptor_gco *gco_ptr;
260         struct ctl_lun *lun;
261         int data_len;
262
263         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
264
265         data_len = sizeof(struct scsi_vpd_tpc) +
266             sizeof(struct scsi_vpd_tpc_descriptor_bdrl) +
267             roundup2(sizeof(struct scsi_vpd_tpc_descriptor_sc) +
268              2 * sizeof(struct scsi_vpd_tpc_descriptor_sc_descr) + 11, 4) +
269             sizeof(struct scsi_vpd_tpc_descriptor_pd) +
270             roundup2(sizeof(struct scsi_vpd_tpc_descriptor_sd) + 4, 4) +
271             roundup2(sizeof(struct scsi_vpd_tpc_descriptor_sdid) + 2, 4) +
272             sizeof(struct scsi_vpd_tpc_descriptor_rtf) +
273              sizeof(struct scsi_vpd_tpc_descriptor_rtf_block) +
274             sizeof(struct scsi_vpd_tpc_descriptor_srt) +
275              2*sizeof(struct scsi_vpd_tpc_descriptor_srtd) +
276             sizeof(struct scsi_vpd_tpc_descriptor_gco);
277
278         ctsio->kern_data_ptr = malloc(data_len, M_CTL, M_WAITOK | M_ZERO);
279         tpc_ptr = (struct scsi_vpd_tpc *)ctsio->kern_data_ptr;
280         ctsio->kern_sg_entries = 0;
281
282         if (data_len < alloc_len) {
283                 ctsio->residual = alloc_len - data_len;
284                 ctsio->kern_data_len = data_len;
285                 ctsio->kern_total_len = data_len;
286         } else {
287                 ctsio->residual = 0;
288                 ctsio->kern_data_len = alloc_len;
289                 ctsio->kern_total_len = alloc_len;
290         }
291         ctsio->kern_data_resid = 0;
292         ctsio->kern_rel_offset = 0;
293         ctsio->kern_sg_entries = 0;
294
295         /*
296          * The control device is always connected.  The disk device, on the
297          * other hand, may not be online all the time.
298          */
299         if (lun != NULL)
300                 tpc_ptr->device = (SID_QUAL_LU_CONNECTED << 5) |
301                                      lun->be_lun->lun_type;
302         else
303                 tpc_ptr->device = (SID_QUAL_LU_OFFLINE << 5) | T_DIRECT;
304         tpc_ptr->page_code = SVPD_SCSI_TPC;
305         scsi_ulto2b(data_len - 4, tpc_ptr->page_length);
306
307         /* Block Device ROD Limits */
308         d_ptr = (struct scsi_vpd_tpc_descriptor *)&tpc_ptr->descr[0];
309         bdrl_ptr = (struct scsi_vpd_tpc_descriptor_bdrl *)d_ptr;
310         scsi_ulto2b(SVPD_TPC_BDRL, bdrl_ptr->desc_type);
311         scsi_ulto2b(sizeof(*bdrl_ptr) - 4, bdrl_ptr->desc_length);
312         scsi_ulto2b(TPC_MAX_SEGS, bdrl_ptr->maximum_ranges);
313         scsi_ulto4b(TPC_MAX_TOKEN_TIMEOUT,
314             bdrl_ptr->maximum_inactivity_timeout);
315         scsi_ulto4b(TPC_DFL_TOKEN_TIMEOUT,
316             bdrl_ptr->default_inactivity_timeout);
317         scsi_u64to8b(0, bdrl_ptr->maximum_token_transfer_size);
318         scsi_u64to8b(0, bdrl_ptr->optimal_transfer_count);
319
320         /* Supported commands */
321         d_ptr = (struct scsi_vpd_tpc_descriptor *)
322             (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
323         sc_ptr = (struct scsi_vpd_tpc_descriptor_sc *)d_ptr;
324         scsi_ulto2b(SVPD_TPC_SC, sc_ptr->desc_type);
325         sc_ptr->list_length = 2 * sizeof(*scd_ptr) + 11;
326         scsi_ulto2b(roundup2(1 + sc_ptr->list_length, 4), sc_ptr->desc_length);
327         scd_ptr = &sc_ptr->descr[0];
328         scd_ptr->opcode = EXTENDED_COPY;
329         scd_ptr->sa_length = 5;
330         scd_ptr->supported_service_actions[0] = EC_EC_LID1;
331         scd_ptr->supported_service_actions[1] = EC_EC_LID4;
332         scd_ptr->supported_service_actions[2] = EC_PT;
333         scd_ptr->supported_service_actions[3] = EC_WUT;
334         scd_ptr->supported_service_actions[4] = EC_COA;
335         scd_ptr = (struct scsi_vpd_tpc_descriptor_sc_descr *)
336             &scd_ptr->supported_service_actions[scd_ptr->sa_length];
337         scd_ptr->opcode = RECEIVE_COPY_STATUS;
338         scd_ptr->sa_length = 6;
339         scd_ptr->supported_service_actions[0] = RCS_RCS_LID1;
340         scd_ptr->supported_service_actions[1] = RCS_RCFD;
341         scd_ptr->supported_service_actions[2] = RCS_RCS_LID4;
342         scd_ptr->supported_service_actions[3] = RCS_RCOP;
343         scd_ptr->supported_service_actions[4] = RCS_RRTI;
344         scd_ptr->supported_service_actions[5] = RCS_RART;
345
346         /* Parameter data. */
347         d_ptr = (struct scsi_vpd_tpc_descriptor *)
348             (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
349         pd_ptr = (struct scsi_vpd_tpc_descriptor_pd *)d_ptr;
350         scsi_ulto2b(SVPD_TPC_PD, pd_ptr->desc_type);
351         scsi_ulto2b(sizeof(*pd_ptr) - 4, pd_ptr->desc_length);
352         scsi_ulto2b(TPC_MAX_CSCDS, pd_ptr->maximum_cscd_descriptor_count);
353         scsi_ulto2b(TPC_MAX_SEGS, pd_ptr->maximum_segment_descriptor_count);
354         scsi_ulto4b(TPC_MAX_LIST, pd_ptr->maximum_descriptor_list_length);
355         scsi_ulto4b(TPC_MAX_INLINE, pd_ptr->maximum_inline_data_length);
356
357         /* Supported Descriptors */
358         d_ptr = (struct scsi_vpd_tpc_descriptor *)
359             (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
360         sd_ptr = (struct scsi_vpd_tpc_descriptor_sd *)d_ptr;
361         scsi_ulto2b(SVPD_TPC_SD, sd_ptr->desc_type);
362         scsi_ulto2b(roundup2(sizeof(*sd_ptr) - 4 + 4, 4), sd_ptr->desc_length);
363         sd_ptr->list_length = 4;
364         sd_ptr->supported_descriptor_codes[0] = EC_SEG_B2B;
365         sd_ptr->supported_descriptor_codes[1] = EC_SEG_VERIFY;
366         sd_ptr->supported_descriptor_codes[2] = EC_SEG_REGISTER_KEY;
367         sd_ptr->supported_descriptor_codes[3] = EC_CSCD_ID;
368
369         /* Supported CSCD Descriptor IDs */
370         d_ptr = (struct scsi_vpd_tpc_descriptor *)
371             (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
372         sdid_ptr = (struct scsi_vpd_tpc_descriptor_sdid *)d_ptr;
373         scsi_ulto2b(SVPD_TPC_SDID, sdid_ptr->desc_type);
374         scsi_ulto2b(roundup2(sizeof(*sdid_ptr) - 4 + 2, 4), sdid_ptr->desc_length);
375         scsi_ulto2b(2, sdid_ptr->list_length);
376         scsi_ulto2b(0xffff, &sdid_ptr->supported_descriptor_ids[0]);
377
378         /* ROD Token Features */
379         d_ptr = (struct scsi_vpd_tpc_descriptor *)
380             (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
381         rtf_ptr = (struct scsi_vpd_tpc_descriptor_rtf *)d_ptr;
382         scsi_ulto2b(SVPD_TPC_RTF, rtf_ptr->desc_type);
383         scsi_ulto2b(sizeof(*rtf_ptr) - 4 + sizeof(*rtfb_ptr), rtf_ptr->desc_length);
384         rtf_ptr->remote_tokens = 0;
385         scsi_ulto4b(TPC_MIN_TOKEN_TIMEOUT, rtf_ptr->minimum_token_lifetime);
386         scsi_ulto4b(UINT32_MAX, rtf_ptr->maximum_token_lifetime);
387         scsi_ulto4b(TPC_MAX_TOKEN_TIMEOUT,
388             rtf_ptr->maximum_token_inactivity_timeout);
389         scsi_ulto2b(sizeof(*rtfb_ptr), rtf_ptr->type_specific_features_length);
390         rtfb_ptr = (struct scsi_vpd_tpc_descriptor_rtf_block *)
391             &rtf_ptr->type_specific_features;
392         rtfb_ptr->type_format = SVPD_TPC_RTF_BLOCK;
393         scsi_ulto2b(sizeof(*rtfb_ptr) - 4, rtfb_ptr->desc_length);
394         scsi_ulto2b(0, rtfb_ptr->optimal_length_granularity);
395         scsi_u64to8b(0, rtfb_ptr->maximum_bytes);
396         scsi_u64to8b(0, rtfb_ptr->optimal_bytes);
397         scsi_u64to8b(UINT64_MAX, rtfb_ptr->optimal_bytes_to_token_per_segment);
398         scsi_u64to8b(TPC_MAX_IOCHUNK_SIZE,
399             rtfb_ptr->optimal_bytes_from_token_per_segment);
400
401         /* Supported ROD Tokens */
402         d_ptr = (struct scsi_vpd_tpc_descriptor *)
403             (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
404         srt_ptr = (struct scsi_vpd_tpc_descriptor_srt *)d_ptr;
405         scsi_ulto2b(SVPD_TPC_SRT, srt_ptr->desc_type);
406         scsi_ulto2b(sizeof(*srt_ptr) - 4 + 2*sizeof(*srtd_ptr), srt_ptr->desc_length);
407         scsi_ulto2b(2*sizeof(*srtd_ptr), srt_ptr->rod_type_descriptors_length);
408         srtd_ptr = (struct scsi_vpd_tpc_descriptor_srtd *)
409             &srt_ptr->rod_type_descriptors;
410         scsi_ulto4b(ROD_TYPE_AUR, srtd_ptr->rod_type);
411         srtd_ptr->flags = SVPD_TPC_SRTD_TIN | SVPD_TPC_SRTD_TOUT;
412         scsi_ulto2b(0, srtd_ptr->preference_indicator);
413         srtd_ptr++;
414         scsi_ulto4b(ROD_TYPE_BLOCK_ZERO, srtd_ptr->rod_type);
415         srtd_ptr->flags = SVPD_TPC_SRTD_TIN;
416         scsi_ulto2b(0, srtd_ptr->preference_indicator);
417
418         /* General Copy Operations */
419         d_ptr = (struct scsi_vpd_tpc_descriptor *)
420             (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
421         gco_ptr = (struct scsi_vpd_tpc_descriptor_gco *)d_ptr;
422         scsi_ulto2b(SVPD_TPC_GCO, gco_ptr->desc_type);
423         scsi_ulto2b(sizeof(*gco_ptr) - 4, gco_ptr->desc_length);
424         scsi_ulto4b(TPC_MAX_LISTS, gco_ptr->total_concurrent_copies);
425         scsi_ulto4b(TPC_MAX_LISTS, gco_ptr->maximum_identified_concurrent_copies);
426         scsi_ulto4b(TPC_MAX_SEG, gco_ptr->maximum_segment_length);
427         gco_ptr->data_segment_granularity = 0;
428         gco_ptr->inline_data_granularity = 0;
429
430         ctl_set_success(ctsio);
431         ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
432         ctsio->be_move_done = ctl_config_move_done;
433         ctl_datamove((union ctl_io *)ctsio);
434
435         return (CTL_RETVAL_COMPLETE);
436 }
437
438 int
439 ctl_receive_copy_operating_parameters(struct ctl_scsiio *ctsio)
440 {
441         struct scsi_receive_copy_operating_parameters *cdb;
442         struct scsi_receive_copy_operating_parameters_data *data;
443         int retval;
444         int alloc_len, total_len;
445
446         CTL_DEBUG_PRINT(("ctl_report_supported_tmf\n"));
447
448         cdb = (struct scsi_receive_copy_operating_parameters *)ctsio->cdb;
449
450         retval = CTL_RETVAL_COMPLETE;
451
452         total_len = sizeof(*data) + 4;
453         alloc_len = scsi_4btoul(cdb->length);
454
455         ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
456
457         ctsio->kern_sg_entries = 0;
458
459         if (total_len < alloc_len) {
460                 ctsio->residual = alloc_len - total_len;
461                 ctsio->kern_data_len = total_len;
462                 ctsio->kern_total_len = total_len;
463         } else {
464                 ctsio->residual = 0;
465                 ctsio->kern_data_len = alloc_len;
466                 ctsio->kern_total_len = alloc_len;
467         }
468         ctsio->kern_data_resid = 0;
469         ctsio->kern_rel_offset = 0;
470
471         data = (struct scsi_receive_copy_operating_parameters_data *)ctsio->kern_data_ptr;
472         scsi_ulto4b(sizeof(*data) - 4 + 4, data->length);
473         data->snlid = RCOP_SNLID;
474         scsi_ulto2b(TPC_MAX_CSCDS, data->maximum_cscd_descriptor_count);
475         scsi_ulto2b(TPC_MAX_SEGS, data->maximum_segment_descriptor_count);
476         scsi_ulto4b(TPC_MAX_LIST, data->maximum_descriptor_list_length);
477         scsi_ulto4b(TPC_MAX_SEG, data->maximum_segment_length);
478         scsi_ulto4b(TPC_MAX_INLINE, data->maximum_inline_data_length);
479         scsi_ulto4b(0, data->held_data_limit);
480         scsi_ulto4b(0, data->maximum_stream_device_transfer_size);
481         scsi_ulto2b(TPC_MAX_LISTS, data->total_concurrent_copies);
482         data->maximum_concurrent_copies = TPC_MAX_LISTS;
483         data->data_segment_granularity = 0;
484         data->inline_data_granularity = 0;
485         data->held_data_granularity = 0;
486         data->implemented_descriptor_list_length = 4;
487         data->list_of_implemented_descriptor_type_codes[0] = EC_SEG_B2B;
488         data->list_of_implemented_descriptor_type_codes[1] = EC_SEG_VERIFY;
489         data->list_of_implemented_descriptor_type_codes[2] = EC_SEG_REGISTER_KEY;
490         data->list_of_implemented_descriptor_type_codes[3] = EC_CSCD_ID;
491
492         ctl_set_success(ctsio);
493         ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
494         ctsio->be_move_done = ctl_config_move_done;
495         ctl_datamove((union ctl_io *)ctsio);
496         return (retval);
497 }
498
499 static struct tpc_list *
500 tpc_find_list(struct ctl_lun *lun, uint32_t list_id, uint32_t init_idx)
501 {
502         struct tpc_list *list;
503
504         mtx_assert(&lun->lun_lock, MA_OWNED);
505         TAILQ_FOREACH(list, &lun->tpc_lists, links) {
506                 if ((list->flags & EC_LIST_ID_USAGE_MASK) !=
507                      EC_LIST_ID_USAGE_NONE && list->list_id == list_id &&
508                     list->init_idx == init_idx)
509                         break;
510         }
511         return (list);
512 }
513
514 int
515 ctl_receive_copy_status_lid1(struct ctl_scsiio *ctsio)
516 {
517         struct ctl_lun *lun;
518         struct scsi_receive_copy_status_lid1 *cdb;
519         struct scsi_receive_copy_status_lid1_data *data;
520         struct tpc_list *list;
521         struct tpc_list list_copy;
522         int retval;
523         int alloc_len, total_len;
524         uint32_t list_id;
525
526         CTL_DEBUG_PRINT(("ctl_receive_copy_status_lid1\n"));
527
528         cdb = (struct scsi_receive_copy_status_lid1 *)ctsio->cdb;
529         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
530
531         retval = CTL_RETVAL_COMPLETE;
532
533         list_id = cdb->list_identifier;
534         mtx_lock(&lun->lun_lock);
535         list = tpc_find_list(lun, list_id,
536             ctl_get_initindex(&ctsio->io_hdr.nexus));
537         if (list == NULL) {
538                 mtx_unlock(&lun->lun_lock);
539                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
540                     /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
541                     /*bit*/ 0);
542                 ctl_done((union ctl_io *)ctsio);
543                 return (retval);
544         }
545         list_copy = *list;
546         if (list->completed) {
547                 TAILQ_REMOVE(&lun->tpc_lists, list, links);
548                 free(list, M_CTL);
549         }
550         mtx_unlock(&lun->lun_lock);
551
552         total_len = sizeof(*data);
553         alloc_len = scsi_4btoul(cdb->length);
554
555         ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
556
557         ctsio->kern_sg_entries = 0;
558
559         if (total_len < alloc_len) {
560                 ctsio->residual = alloc_len - total_len;
561                 ctsio->kern_data_len = total_len;
562                 ctsio->kern_total_len = total_len;
563         } else {
564                 ctsio->residual = 0;
565                 ctsio->kern_data_len = alloc_len;
566                 ctsio->kern_total_len = alloc_len;
567         }
568         ctsio->kern_data_resid = 0;
569         ctsio->kern_rel_offset = 0;
570
571         data = (struct scsi_receive_copy_status_lid1_data *)ctsio->kern_data_ptr;
572         scsi_ulto4b(sizeof(*data) - 4, data->available_data);
573         if (list_copy.completed) {
574                 if (list_copy.error || list_copy.abort)
575                         data->copy_command_status = RCS_CCS_ERROR;
576                 else
577                         data->copy_command_status = RCS_CCS_COMPLETED;
578         } else
579                 data->copy_command_status = RCS_CCS_INPROG;
580         scsi_ulto2b(list_copy.curseg, data->segments_processed);
581         if (list_copy.curbytes <= UINT32_MAX) {
582                 data->transfer_count_units = RCS_TC_BYTES;
583                 scsi_ulto4b(list_copy.curbytes, data->transfer_count);
584         } else {
585                 data->transfer_count_units = RCS_TC_MBYTES;
586                 scsi_ulto4b(list_copy.curbytes >> 20, data->transfer_count);
587         }
588
589         ctl_set_success(ctsio);
590         ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
591         ctsio->be_move_done = ctl_config_move_done;
592         ctl_datamove((union ctl_io *)ctsio);
593         return (retval);
594 }
595
596 int
597 ctl_receive_copy_failure_details(struct ctl_scsiio *ctsio)
598 {
599         struct ctl_lun *lun;
600         struct scsi_receive_copy_failure_details *cdb;
601         struct scsi_receive_copy_failure_details_data *data;
602         struct tpc_list *list;
603         struct tpc_list list_copy;
604         int retval;
605         int alloc_len, total_len;
606         uint32_t list_id;
607
608         CTL_DEBUG_PRINT(("ctl_receive_copy_failure_details\n"));
609
610         cdb = (struct scsi_receive_copy_failure_details *)ctsio->cdb;
611         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
612
613         retval = CTL_RETVAL_COMPLETE;
614
615         list_id = cdb->list_identifier;
616         mtx_lock(&lun->lun_lock);
617         list = tpc_find_list(lun, list_id,
618             ctl_get_initindex(&ctsio->io_hdr.nexus));
619         if (list == NULL || !list->completed) {
620                 mtx_unlock(&lun->lun_lock);
621                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
622                     /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
623                     /*bit*/ 0);
624                 ctl_done((union ctl_io *)ctsio);
625                 return (retval);
626         }
627         list_copy = *list;
628         TAILQ_REMOVE(&lun->tpc_lists, list, links);
629         free(list, M_CTL);
630         mtx_unlock(&lun->lun_lock);
631
632         total_len = sizeof(*data) + list_copy.sense_len;
633         alloc_len = scsi_4btoul(cdb->length);
634
635         ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
636
637         ctsio->kern_sg_entries = 0;
638
639         if (total_len < alloc_len) {
640                 ctsio->residual = alloc_len - total_len;
641                 ctsio->kern_data_len = total_len;
642                 ctsio->kern_total_len = total_len;
643         } else {
644                 ctsio->residual = 0;
645                 ctsio->kern_data_len = alloc_len;
646                 ctsio->kern_total_len = alloc_len;
647         }
648         ctsio->kern_data_resid = 0;
649         ctsio->kern_rel_offset = 0;
650
651         data = (struct scsi_receive_copy_failure_details_data *)ctsio->kern_data_ptr;
652         if (list_copy.completed && (list_copy.error || list_copy.abort)) {
653                 scsi_ulto4b(sizeof(*data) - 4 + list_copy.sense_len,
654                     data->available_data);
655                 data->copy_command_status = RCS_CCS_ERROR;
656         } else
657                 scsi_ulto4b(0, data->available_data);
658         scsi_ulto2b(list_copy.sense_len, data->sense_data_length);
659         memcpy(data->sense_data, &list_copy.sense_data, list_copy.sense_len);
660
661         ctl_set_success(ctsio);
662         ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
663         ctsio->be_move_done = ctl_config_move_done;
664         ctl_datamove((union ctl_io *)ctsio);
665         return (retval);
666 }
667
668 int
669 ctl_receive_copy_status_lid4(struct ctl_scsiio *ctsio)
670 {
671         struct ctl_lun *lun;
672         struct scsi_receive_copy_status_lid4 *cdb;
673         struct scsi_receive_copy_status_lid4_data *data;
674         struct tpc_list *list;
675         struct tpc_list list_copy;
676         int retval;
677         int alloc_len, total_len;
678         uint32_t list_id;
679
680         CTL_DEBUG_PRINT(("ctl_receive_copy_status_lid4\n"));
681
682         cdb = (struct scsi_receive_copy_status_lid4 *)ctsio->cdb;
683         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
684
685         retval = CTL_RETVAL_COMPLETE;
686
687         list_id = scsi_4btoul(cdb->list_identifier);
688         mtx_lock(&lun->lun_lock);
689         list = tpc_find_list(lun, list_id,
690             ctl_get_initindex(&ctsio->io_hdr.nexus));
691         if (list == NULL) {
692                 mtx_unlock(&lun->lun_lock);
693                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
694                     /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
695                     /*bit*/ 0);
696                 ctl_done((union ctl_io *)ctsio);
697                 return (retval);
698         }
699         list_copy = *list;
700         if (list->completed) {
701                 TAILQ_REMOVE(&lun->tpc_lists, list, links);
702                 free(list, M_CTL);
703         }
704         mtx_unlock(&lun->lun_lock);
705
706         total_len = sizeof(*data) + list_copy.sense_len;
707         alloc_len = scsi_4btoul(cdb->length);
708
709         ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
710
711         ctsio->kern_sg_entries = 0;
712
713         if (total_len < alloc_len) {
714                 ctsio->residual = alloc_len - total_len;
715                 ctsio->kern_data_len = total_len;
716                 ctsio->kern_total_len = total_len;
717         } else {
718                 ctsio->residual = 0;
719                 ctsio->kern_data_len = alloc_len;
720                 ctsio->kern_total_len = alloc_len;
721         }
722         ctsio->kern_data_resid = 0;
723         ctsio->kern_rel_offset = 0;
724
725         data = (struct scsi_receive_copy_status_lid4_data *)ctsio->kern_data_ptr;
726         scsi_ulto4b(sizeof(*data) - 4 + list_copy.sense_len,
727             data->available_data);
728         data->response_to_service_action = list_copy.service_action;
729         if (list_copy.completed) {
730                 if (list_copy.error)
731                         data->copy_command_status = RCS_CCS_ERROR;
732                 else if (list_copy.abort)
733                         data->copy_command_status = RCS_CCS_ABORTED;
734                 else
735                         data->copy_command_status = RCS_CCS_COMPLETED;
736         } else
737                 data->copy_command_status = RCS_CCS_INPROG_FG;
738         scsi_ulto2b(list_copy.curops, data->operation_counter);
739         scsi_ulto4b(UINT32_MAX, data->estimated_status_update_delay);
740         data->transfer_count_units = RCS_TC_BYTES;
741         scsi_u64to8b(list_copy.curbytes, data->transfer_count);
742         scsi_ulto2b(list_copy.curseg, data->segments_processed);
743         data->length_of_the_sense_data_field = list_copy.sense_len;
744         data->sense_data_length = list_copy.sense_len;
745         memcpy(data->sense_data, &list_copy.sense_data, list_copy.sense_len);
746
747         ctl_set_success(ctsio);
748         ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
749         ctsio->be_move_done = ctl_config_move_done;
750         ctl_datamove((union ctl_io *)ctsio);
751         return (retval);
752 }
753
754 int
755 ctl_copy_operation_abort(struct ctl_scsiio *ctsio)
756 {
757         struct ctl_lun *lun;
758         struct scsi_copy_operation_abort *cdb;
759         struct tpc_list *list;
760         int retval;
761         uint32_t list_id;
762
763         CTL_DEBUG_PRINT(("ctl_copy_operation_abort\n"));
764
765         cdb = (struct scsi_copy_operation_abort *)ctsio->cdb;
766         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
767
768         retval = CTL_RETVAL_COMPLETE;
769
770         list_id = scsi_4btoul(cdb->list_identifier);
771         mtx_lock(&lun->lun_lock);
772         list = tpc_find_list(lun, list_id,
773             ctl_get_initindex(&ctsio->io_hdr.nexus));
774         if (list == NULL) {
775                 mtx_unlock(&lun->lun_lock);
776                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
777                     /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
778                     /*bit*/ 0);
779                 ctl_done((union ctl_io *)ctsio);
780                 return (retval);
781         }
782         list->abort = 1;
783         mtx_unlock(&lun->lun_lock);
784
785         ctl_set_success(ctsio);
786         ctl_done((union ctl_io *)ctsio);
787         return (retval);
788 }
789
790 static uint64_t
791 tpc_resolve(struct tpc_list *list, uint16_t idx, uint32_t *ss,
792     uint32_t *pb, uint32_t *pbo)
793 {
794
795         if (idx == 0xffff) {
796                 if (ss && list->lun->be_lun)
797                         *ss = list->lun->be_lun->blocksize;
798                 if (pb && list->lun->be_lun)
799                         *pb = list->lun->be_lun->blocksize <<
800                             list->lun->be_lun->pblockexp;
801                 if (pbo && list->lun->be_lun)
802                         *pbo = list->lun->be_lun->blocksize *
803                             list->lun->be_lun->pblockoff;
804                 return (list->lun->lun);
805         }
806         if (idx >= list->ncscd)
807                 return (UINT64_MAX);
808         return (tpcl_resolve(list->lun->ctl_softc,
809             list->init_port, &list->cscd[idx], ss, pb, pbo));
810 }
811
812 static int
813 tpc_process_b2b(struct tpc_list *list)
814 {
815         struct scsi_ec_segment_b2b *seg;
816         struct scsi_ec_cscd_dtsp *sdstp, *ddstp;
817         struct tpc_io *tior, *tiow;
818         struct runl run;
819         uint64_t sl, dl;
820         off_t srclba, dstlba, numbytes, donebytes, roundbytes;
821         int numlba;
822         uint32_t srcblock, dstblock, pb, pbo, adj;
823         uint8_t csi[4];
824
825         scsi_ulto4b(list->curseg, csi);
826         if (list->stage == 1) {
827                 while ((tior = TAILQ_FIRST(&list->allio)) != NULL) {
828                         TAILQ_REMOVE(&list->allio, tior, links);
829                         ctl_free_io(tior->io);
830                         free(tior, M_CTL);
831                 }
832                 free(list->buf, M_CTL);
833                 if (list->abort) {
834                         ctl_set_task_aborted(list->ctsio);
835                         return (CTL_RETVAL_ERROR);
836                 } else if (list->error) {
837                         ctl_set_sense(list->ctsio, /*current_error*/ 1,
838                             /*sense_key*/ SSD_KEY_COPY_ABORTED,
839                             /*asc*/ 0x0d, /*ascq*/ 0x01,
840                             SSD_ELEM_COMMAND, sizeof(csi), csi,
841                             SSD_ELEM_NONE);
842                         return (CTL_RETVAL_ERROR);
843                 }
844                 list->cursectors += list->segsectors;
845                 list->curbytes += list->segbytes;
846                 return (CTL_RETVAL_COMPLETE);
847         }
848
849         TAILQ_INIT(&list->allio);
850         seg = (struct scsi_ec_segment_b2b *)list->seg[list->curseg];
851         sl = tpc_resolve(list, scsi_2btoul(seg->src_cscd), &srcblock, NULL, NULL);
852         dl = tpc_resolve(list, scsi_2btoul(seg->dst_cscd), &dstblock, &pb, &pbo);
853         if (sl >= CTL_MAX_LUNS || dl >= CTL_MAX_LUNS) {
854                 ctl_set_sense(list->ctsio, /*current_error*/ 1,
855                     /*sense_key*/ SSD_KEY_COPY_ABORTED,
856                     /*asc*/ 0x08, /*ascq*/ 0x04,
857                     SSD_ELEM_COMMAND, sizeof(csi), csi,
858                     SSD_ELEM_NONE);
859                 return (CTL_RETVAL_ERROR);
860         }
861         if (pbo > 0)
862                 pbo = pb - pbo;
863         sdstp = &list->cscd[scsi_2btoul(seg->src_cscd)].dtsp;
864         if (scsi_3btoul(sdstp->block_length) != 0)
865                 srcblock = scsi_3btoul(sdstp->block_length);
866         ddstp = &list->cscd[scsi_2btoul(seg->dst_cscd)].dtsp;
867         if (scsi_3btoul(ddstp->block_length) != 0)
868                 dstblock = scsi_3btoul(ddstp->block_length);
869         numlba = scsi_2btoul(seg->number_of_blocks);
870         if (seg->flags & EC_SEG_DC)
871                 numbytes = (off_t)numlba * dstblock;
872         else
873                 numbytes = (off_t)numlba * srcblock;
874         srclba = scsi_8btou64(seg->src_lba);
875         dstlba = scsi_8btou64(seg->dst_lba);
876
877 //      printf("Copy %ju bytes from %ju @ %ju to %ju @ %ju\n",
878 //          (uintmax_t)numbytes, sl, scsi_8btou64(seg->src_lba),
879 //          dl, scsi_8btou64(seg->dst_lba));
880
881         if (numbytes == 0)
882                 return (CTL_RETVAL_COMPLETE);
883
884         if (numbytes % srcblock != 0 || numbytes % dstblock != 0) {
885                 ctl_set_sense(list->ctsio, /*current_error*/ 1,
886                     /*sense_key*/ SSD_KEY_COPY_ABORTED,
887                     /*asc*/ 0x26, /*ascq*/ 0x0A,
888                     SSD_ELEM_COMMAND, sizeof(csi), csi,
889                     SSD_ELEM_NONE);
890                 return (CTL_RETVAL_ERROR);
891         }
892
893         list->buf = malloc(numbytes, M_CTL, M_WAITOK);
894         list->segbytes = numbytes;
895         list->segsectors = numbytes / dstblock;
896         donebytes = 0;
897         TAILQ_INIT(&run);
898         list->tbdio = 0;
899         while (donebytes < numbytes) {
900                 roundbytes = numbytes - donebytes;
901                 if (roundbytes > TPC_MAX_IO_SIZE) {
902                         roundbytes = TPC_MAX_IO_SIZE;
903                         roundbytes -= roundbytes % dstblock;
904                         if (pb > dstblock) {
905                                 adj = (dstlba * dstblock + roundbytes - pbo) % pb;
906                                 if (roundbytes > adj)
907                                         roundbytes -= adj;
908                         }
909                 }
910
911                 tior = malloc(sizeof(*tior), M_CTL, M_WAITOK | M_ZERO);
912                 TAILQ_INIT(&tior->run);
913                 tior->list = list;
914                 TAILQ_INSERT_TAIL(&list->allio, tior, links);
915                 tior->io = tpcl_alloc_io();
916                 ctl_scsi_read_write(tior->io,
917                                     /*data_ptr*/ &list->buf[donebytes],
918                                     /*data_len*/ roundbytes,
919                                     /*read_op*/ 1,
920                                     /*byte2*/ 0,
921                                     /*minimum_cdb_size*/ 0,
922                                     /*lba*/ srclba,
923                                     /*num_blocks*/ roundbytes / srcblock,
924                                     /*tag_type*/ CTL_TAG_SIMPLE,
925                                     /*control*/ 0);
926                 tior->io->io_hdr.retries = 3;
927                 tior->lun = sl;
928                 tior->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tior;
929
930                 tiow = malloc(sizeof(*tior), M_CTL, M_WAITOK | M_ZERO);
931                 TAILQ_INIT(&tiow->run);
932                 tiow->list = list;
933                 TAILQ_INSERT_TAIL(&list->allio, tiow, links);
934                 tiow->io = tpcl_alloc_io();
935                 ctl_scsi_read_write(tiow->io,
936                                     /*data_ptr*/ &list->buf[donebytes],
937                                     /*data_len*/ roundbytes,
938                                     /*read_op*/ 0,
939                                     /*byte2*/ 0,
940                                     /*minimum_cdb_size*/ 0,
941                                     /*lba*/ dstlba,
942                                     /*num_blocks*/ roundbytes / dstblock,
943                                     /*tag_type*/ CTL_TAG_SIMPLE,
944                                     /*control*/ 0);
945                 tiow->io->io_hdr.retries = 3;
946                 tiow->lun = dl;
947                 tiow->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tiow;
948
949                 TAILQ_INSERT_TAIL(&tior->run, tiow, rlinks);
950                 TAILQ_INSERT_TAIL(&run, tior, rlinks);
951                 list->tbdio++;
952                 donebytes += roundbytes;
953                 srclba += roundbytes / srcblock;
954                 dstlba += roundbytes / dstblock;
955         }
956
957         while ((tior = TAILQ_FIRST(&run)) != NULL) {
958                 TAILQ_REMOVE(&run, tior, rlinks);
959                 if (tpcl_queue(tior->io, tior->lun) != CTL_RETVAL_COMPLETE)
960                         panic("tpcl_queue() error");
961         }
962
963         list->stage++;
964         return (CTL_RETVAL_QUEUED);
965 }
966
967 static int
968 tpc_process_verify(struct tpc_list *list)
969 {
970         struct scsi_ec_segment_verify *seg;
971         struct tpc_io *tio;
972         uint64_t sl;
973         uint8_t csi[4];
974
975         scsi_ulto4b(list->curseg, csi);
976         if (list->stage == 1) {
977                 while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
978                         TAILQ_REMOVE(&list->allio, tio, links);
979                         ctl_free_io(tio->io);
980                         free(tio, M_CTL);
981                 }
982                 if (list->abort) {
983                         ctl_set_task_aborted(list->ctsio);
984                         return (CTL_RETVAL_ERROR);
985                 } else if (list->error) {
986                         ctl_set_sense(list->ctsio, /*current_error*/ 1,
987                             /*sense_key*/ SSD_KEY_COPY_ABORTED,
988                             /*asc*/ 0x0d, /*ascq*/ 0x01,
989                             SSD_ELEM_COMMAND, sizeof(csi), csi,
990                             SSD_ELEM_NONE);
991                         return (CTL_RETVAL_ERROR);
992                 } else
993                         return (CTL_RETVAL_COMPLETE);
994         }
995
996         TAILQ_INIT(&list->allio);
997         seg = (struct scsi_ec_segment_verify *)list->seg[list->curseg];
998         sl = tpc_resolve(list, scsi_2btoul(seg->src_cscd), NULL, NULL, NULL);
999         if (sl >= CTL_MAX_LUNS) {
1000                 ctl_set_sense(list->ctsio, /*current_error*/ 1,
1001                     /*sense_key*/ SSD_KEY_COPY_ABORTED,
1002                     /*asc*/ 0x08, /*ascq*/ 0x04,
1003                     SSD_ELEM_COMMAND, sizeof(csi), csi,
1004                     SSD_ELEM_NONE);
1005                 return (CTL_RETVAL_ERROR);
1006         }
1007
1008 //      printf("Verify %ju\n", sl);
1009
1010         if ((seg->tur & 0x01) == 0)
1011                 return (CTL_RETVAL_COMPLETE);
1012
1013         list->tbdio = 1;
1014         tio = malloc(sizeof(*tio), M_CTL, M_WAITOK | M_ZERO);
1015         TAILQ_INIT(&tio->run);
1016         tio->list = list;
1017         TAILQ_INSERT_TAIL(&list->allio, tio, links);
1018         tio->io = tpcl_alloc_io();
1019         ctl_scsi_tur(tio->io, /*tag_type*/ CTL_TAG_SIMPLE, /*control*/ 0);
1020         tio->io->io_hdr.retries = 3;
1021         tio->lun = sl;
1022         tio->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tio;
1023         list->stage++;
1024         if (tpcl_queue(tio->io, tio->lun) != CTL_RETVAL_COMPLETE)
1025                 panic("tpcl_queue() error");
1026         return (CTL_RETVAL_QUEUED);
1027 }
1028
1029 static int
1030 tpc_process_register_key(struct tpc_list *list)
1031 {
1032         struct scsi_ec_segment_register_key *seg;
1033         struct tpc_io *tio;
1034         uint64_t dl;
1035         int datalen;
1036         uint8_t csi[4];
1037
1038         scsi_ulto4b(list->curseg, csi);
1039         if (list->stage == 1) {
1040                 while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
1041                         TAILQ_REMOVE(&list->allio, tio, links);
1042                         ctl_free_io(tio->io);
1043                         free(tio, M_CTL);
1044                 }
1045                 free(list->buf, M_CTL);
1046                 if (list->abort) {
1047                         ctl_set_task_aborted(list->ctsio);
1048                         return (CTL_RETVAL_ERROR);
1049                 } else if (list->error) {
1050                         ctl_set_sense(list->ctsio, /*current_error*/ 1,
1051                             /*sense_key*/ SSD_KEY_COPY_ABORTED,
1052                             /*asc*/ 0x0d, /*ascq*/ 0x01,
1053                             SSD_ELEM_COMMAND, sizeof(csi), csi,
1054                             SSD_ELEM_NONE);
1055                         return (CTL_RETVAL_ERROR);
1056                 } else
1057                         return (CTL_RETVAL_COMPLETE);
1058         }
1059
1060         TAILQ_INIT(&list->allio);
1061         seg = (struct scsi_ec_segment_register_key *)list->seg[list->curseg];
1062         dl = tpc_resolve(list, scsi_2btoul(seg->dst_cscd), NULL, NULL, NULL);
1063         if (dl >= CTL_MAX_LUNS) {
1064                 ctl_set_sense(list->ctsio, /*current_error*/ 1,
1065                     /*sense_key*/ SSD_KEY_COPY_ABORTED,
1066                     /*asc*/ 0x08, /*ascq*/ 0x04,
1067                     SSD_ELEM_COMMAND, sizeof(csi), csi,
1068                     SSD_ELEM_NONE);
1069                 return (CTL_RETVAL_ERROR);
1070         }
1071
1072 //      printf("Register Key %ju\n", dl);
1073
1074         list->tbdio = 1;
1075         tio = malloc(sizeof(*tio), M_CTL, M_WAITOK | M_ZERO);
1076         TAILQ_INIT(&tio->run);
1077         tio->list = list;
1078         TAILQ_INSERT_TAIL(&list->allio, tio, links);
1079         tio->io = tpcl_alloc_io();
1080         datalen = sizeof(struct scsi_per_res_out_parms);
1081         list->buf = malloc(datalen, M_CTL, M_WAITOK);
1082         ctl_scsi_persistent_res_out(tio->io,
1083             list->buf, datalen, SPRO_REGISTER, -1,
1084             scsi_8btou64(seg->res_key), scsi_8btou64(seg->sa_res_key),
1085             /*tag_type*/ CTL_TAG_SIMPLE, /*control*/ 0);
1086         tio->io->io_hdr.retries = 3;
1087         tio->lun = dl;
1088         tio->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tio;
1089         list->stage++;
1090         if (tpcl_queue(tio->io, tio->lun) != CTL_RETVAL_COMPLETE)
1091                 panic("tpcl_queue() error");
1092         return (CTL_RETVAL_QUEUED);
1093 }
1094
1095 static off_t
1096 tpc_ranges_length(struct scsi_range_desc *range, int nrange)
1097 {
1098         off_t length = 0;
1099         int r;
1100
1101         for (r = 0; r < nrange; r++)
1102                 length += scsi_4btoul(range[r].length);
1103         return (length);
1104 }
1105
1106 static int
1107 tpc_check_ranges_l(struct scsi_range_desc *range, int nrange, uint64_t maxlba,
1108     uint64_t *lba)
1109 {
1110         uint64_t b1;
1111         uint32_t l1;
1112         int i;
1113
1114         for (i = 0; i < nrange; i++) {
1115                 b1 = scsi_8btou64(range[i].lba);
1116                 l1 = scsi_4btoul(range[i].length);
1117                 if (b1 + l1 < b1 || b1 + l1 > maxlba + 1) {
1118                         *lba = MAX(b1, maxlba + 1);
1119                         return (-1);
1120                 }
1121         }
1122         return (0);
1123 }
1124
1125 static int
1126 tpc_check_ranges_x(struct scsi_range_desc *range, int nrange)
1127 {
1128         uint64_t b1, b2;
1129         uint32_t l1, l2;
1130         int i, j;
1131
1132         for (i = 0; i < nrange - 1; i++) {
1133                 b1 = scsi_8btou64(range[i].lba);
1134                 l1 = scsi_4btoul(range[i].length);
1135                 for (j = i + 1; j < nrange; j++) {
1136                         b2 = scsi_8btou64(range[j].lba);
1137                         l2 = scsi_4btoul(range[j].length);
1138                         if (b1 + l1 > b2 && b2 + l2 > b1)
1139                                 return (-1);
1140                 }
1141         }
1142         return (0);
1143 }
1144
1145 static int
1146 tpc_skip_ranges(struct scsi_range_desc *range, int nrange, off_t skip,
1147     int *srange, off_t *soffset)
1148 {
1149         off_t off;
1150         int r;
1151
1152         r = 0;
1153         off = 0;
1154         while (r < nrange) {
1155                 if (skip - off < scsi_4btoul(range[r].length)) {
1156                         *srange = r;
1157                         *soffset = skip - off;
1158                         return (0);
1159                 }
1160                 off += scsi_4btoul(range[r].length);
1161                 r++;
1162         }
1163         return (-1);
1164 }
1165
1166 static int
1167 tpc_process_wut(struct tpc_list *list)
1168 {
1169         struct tpc_io *tio, *tior, *tiow;
1170         struct runl run;
1171         int drange, srange;
1172         off_t doffset, soffset;
1173         off_t srclba, dstlba, numbytes, donebytes, roundbytes;
1174         uint32_t srcblock, dstblock, pb, pbo, adj;
1175
1176         if (list->stage > 0) {
1177                 /* Cleanup after previous rounds. */
1178                 while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
1179                         TAILQ_REMOVE(&list->allio, tio, links);
1180                         ctl_free_io(tio->io);
1181                         free(tio, M_CTL);
1182                 }
1183                 free(list->buf, M_CTL);
1184                 if (list->abort) {
1185                         ctl_set_task_aborted(list->ctsio);
1186                         return (CTL_RETVAL_ERROR);
1187                 } else if (list->error) {
1188                         ctl_set_sense(list->ctsio, /*current_error*/ 1,
1189                             /*sense_key*/ SSD_KEY_COPY_ABORTED,
1190                             /*asc*/ 0x0d, /*ascq*/ 0x01, SSD_ELEM_NONE);
1191                         return (CTL_RETVAL_ERROR);
1192                 }
1193                 list->cursectors += list->segsectors;
1194                 list->curbytes += list->segbytes;
1195         }
1196
1197         /* Check where we are on destination ranges list. */
1198         if (tpc_skip_ranges(list->range, list->nrange, list->cursectors,
1199             &drange, &doffset) != 0)
1200                 return (CTL_RETVAL_COMPLETE);
1201         dstblock = list->lun->be_lun->blocksize;
1202         pb = dstblock << list->lun->be_lun->pblockexp;
1203         if (list->lun->be_lun->pblockoff > 0)
1204                 pbo = pb - dstblock * list->lun->be_lun->pblockoff;
1205         else
1206                 pbo = 0;
1207
1208         /* Check where we are on source ranges list. */
1209         srcblock = list->token->blocksize;
1210         if (tpc_skip_ranges(list->token->range, list->token->nrange,
1211             list->offset_into_rod + list->cursectors * dstblock / srcblock,
1212             &srange, &soffset) != 0) {
1213                 ctl_set_sense(list->ctsio, /*current_error*/ 1,
1214                     /*sense_key*/ SSD_KEY_COPY_ABORTED,
1215                     /*asc*/ 0x0d, /*ascq*/ 0x04, SSD_ELEM_NONE);
1216                 return (CTL_RETVAL_ERROR);
1217         }
1218
1219         srclba = scsi_8btou64(list->token->range[srange].lba) + soffset;
1220         dstlba = scsi_8btou64(list->range[drange].lba) + doffset;
1221         numbytes = srcblock *
1222             (scsi_4btoul(list->token->range[srange].length) - soffset);
1223         numbytes = omin(numbytes, dstblock *
1224             (scsi_4btoul(list->range[drange].length) - doffset));
1225         if (numbytes > TPC_MAX_IOCHUNK_SIZE) {
1226                 numbytes = TPC_MAX_IOCHUNK_SIZE;
1227                 numbytes -= numbytes % dstblock;
1228                 if (pb > dstblock) {
1229                         adj = (dstlba * dstblock + numbytes - pbo) % pb;
1230                         if (numbytes > adj)
1231                                 numbytes -= adj;
1232                 }
1233         }
1234
1235         if (numbytes % srcblock != 0 || numbytes % dstblock != 0) {
1236                 ctl_set_sense(list->ctsio, /*current_error*/ 1,
1237                     /*sense_key*/ SSD_KEY_COPY_ABORTED,
1238                     /*asc*/ 0x26, /*ascq*/ 0x0A, SSD_ELEM_NONE);
1239                 return (CTL_RETVAL_ERROR);
1240         }
1241
1242         list->buf = malloc(numbytes, M_CTL, M_WAITOK |
1243             (list->token == NULL ? M_ZERO : 0));
1244         list->segbytes = numbytes;
1245         list->segsectors = numbytes / dstblock;
1246 //printf("Copy chunk of %ju sectors from %ju to %ju\n", list->segsectors,
1247 //    srclba, dstlba);
1248         donebytes = 0;
1249         TAILQ_INIT(&run);
1250         list->tbdio = 0;
1251         TAILQ_INIT(&list->allio);
1252         while (donebytes < numbytes) {
1253                 roundbytes = numbytes - donebytes;
1254                 if (roundbytes > TPC_MAX_IO_SIZE) {
1255                         roundbytes = TPC_MAX_IO_SIZE;
1256                         roundbytes -= roundbytes % dstblock;
1257                         if (pb > dstblock) {
1258                                 adj = (dstlba * dstblock + roundbytes - pbo) % pb;
1259                                 if (roundbytes > adj)
1260                                         roundbytes -= adj;
1261                         }
1262                 }
1263
1264                 tior = malloc(sizeof(*tior), M_CTL, M_WAITOK | M_ZERO);
1265                 TAILQ_INIT(&tior->run);
1266                 tior->list = list;
1267                 TAILQ_INSERT_TAIL(&list->allio, tior, links);
1268                 tior->io = tpcl_alloc_io();
1269                 ctl_scsi_read_write(tior->io,
1270                                     /*data_ptr*/ &list->buf[donebytes],
1271                                     /*data_len*/ roundbytes,
1272                                     /*read_op*/ 1,
1273                                     /*byte2*/ 0,
1274                                     /*minimum_cdb_size*/ 0,
1275                                     /*lba*/ srclba,
1276                                     /*num_blocks*/ roundbytes / srcblock,
1277                                     /*tag_type*/ CTL_TAG_SIMPLE,
1278                                     /*control*/ 0);
1279                 tior->io->io_hdr.retries = 3;
1280                 tior->lun = list->token->lun;
1281                 tior->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tior;
1282
1283                 tiow = malloc(sizeof(*tiow), M_CTL, M_WAITOK | M_ZERO);
1284                 TAILQ_INIT(&tiow->run);
1285                 tiow->list = list;
1286                 TAILQ_INSERT_TAIL(&list->allio, tiow, links);
1287                 tiow->io = tpcl_alloc_io();
1288                 ctl_scsi_read_write(tiow->io,
1289                                     /*data_ptr*/ &list->buf[donebytes],
1290                                     /*data_len*/ roundbytes,
1291                                     /*read_op*/ 0,
1292                                     /*byte2*/ 0,
1293                                     /*minimum_cdb_size*/ 0,
1294                                     /*lba*/ dstlba,
1295                                     /*num_blocks*/ roundbytes / dstblock,
1296                                     /*tag_type*/ CTL_TAG_SIMPLE,
1297                                     /*control*/ 0);
1298                 tiow->io->io_hdr.retries = 3;
1299                 tiow->lun = list->lun->lun;
1300                 tiow->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tiow;
1301
1302                 TAILQ_INSERT_TAIL(&tior->run, tiow, rlinks);
1303                 TAILQ_INSERT_TAIL(&run, tior, rlinks);
1304                 list->tbdio++;
1305                 donebytes += roundbytes;
1306                 srclba += roundbytes / srcblock;
1307                 dstlba += roundbytes / dstblock;
1308         }
1309
1310         while ((tior = TAILQ_FIRST(&run)) != NULL) {
1311                 TAILQ_REMOVE(&run, tior, rlinks);
1312                 if (tpcl_queue(tior->io, tior->lun) != CTL_RETVAL_COMPLETE)
1313                         panic("tpcl_queue() error");
1314         }
1315
1316         list->stage++;
1317         return (CTL_RETVAL_QUEUED);
1318 }
1319
1320 static int
1321 tpc_process_zero_wut(struct tpc_list *list)
1322 {
1323         struct tpc_io *tio, *tiow;
1324         struct runl run, *prun;
1325         int r;
1326         uint32_t dstblock, len;
1327
1328         if (list->stage > 0) {
1329 complete:
1330                 /* Cleanup after previous rounds. */
1331                 while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
1332                         TAILQ_REMOVE(&list->allio, tio, links);
1333                         ctl_free_io(tio->io);
1334                         free(tio, M_CTL);
1335                 }
1336                 if (list->abort) {
1337                         ctl_set_task_aborted(list->ctsio);
1338                         return (CTL_RETVAL_ERROR);
1339                 } else if (list->error) {
1340                         ctl_set_sense(list->ctsio, /*current_error*/ 1,
1341                             /*sense_key*/ SSD_KEY_COPY_ABORTED,
1342                             /*asc*/ 0x0d, /*ascq*/ 0x01, SSD_ELEM_NONE);
1343                         return (CTL_RETVAL_ERROR);
1344                 }
1345                 list->cursectors += list->segsectors;
1346                 list->curbytes += list->segbytes;
1347                 return (CTL_RETVAL_COMPLETE);
1348         }
1349
1350         dstblock = list->lun->be_lun->blocksize;
1351         TAILQ_INIT(&run);
1352         prun = &run;
1353         list->tbdio = 1;
1354         TAILQ_INIT(&list->allio);
1355         list->segsectors = 0;
1356         for (r = 0; r < list->nrange; r++) {
1357                 len = scsi_4btoul(list->range[r].length);
1358                 if (len == 0)
1359                         continue;
1360
1361                 tiow = malloc(sizeof(*tiow), M_CTL, M_WAITOK | M_ZERO);
1362                 TAILQ_INIT(&tiow->run);
1363                 tiow->list = list;
1364                 TAILQ_INSERT_TAIL(&list->allio, tiow, links);
1365                 tiow->io = tpcl_alloc_io();
1366                 ctl_scsi_write_same(tiow->io,
1367                                     /*data_ptr*/ NULL,
1368                                     /*data_len*/ 0,
1369                                     /*byte2*/ SWS_NDOB,
1370                                     /*lba*/ scsi_8btou64(list->range[r].lba),
1371                                     /*num_blocks*/ len,
1372                                     /*tag_type*/ CTL_TAG_SIMPLE,
1373                                     /*control*/ 0);
1374                 tiow->io->io_hdr.retries = 3;
1375                 tiow->lun = list->lun->lun;
1376                 tiow->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tiow;
1377
1378                 TAILQ_INSERT_TAIL(prun, tiow, rlinks);
1379                 prun = &tiow->run;
1380                 list->segsectors += len;
1381         }
1382         list->segbytes = list->segsectors * dstblock;
1383
1384         if (TAILQ_EMPTY(&run))
1385                 goto complete;
1386
1387         while ((tiow = TAILQ_FIRST(&run)) != NULL) {
1388                 TAILQ_REMOVE(&run, tiow, rlinks);
1389                 if (tpcl_queue(tiow->io, tiow->lun) != CTL_RETVAL_COMPLETE)
1390                         panic("tpcl_queue() error");
1391         }
1392
1393         list->stage++;
1394         return (CTL_RETVAL_QUEUED);
1395 }
1396
1397 static void
1398 tpc_process(struct tpc_list *list)
1399 {
1400         struct ctl_lun *lun = list->lun;
1401         struct ctl_softc *softc = lun->ctl_softc;
1402         struct scsi_ec_segment *seg;
1403         struct ctl_scsiio *ctsio = list->ctsio;
1404         int retval = CTL_RETVAL_COMPLETE;
1405         uint8_t csi[4];
1406
1407         if (list->service_action == EC_WUT) {
1408                 if (list->token != NULL)
1409                         retval = tpc_process_wut(list);
1410                 else
1411                         retval = tpc_process_zero_wut(list);
1412                 if (retval == CTL_RETVAL_QUEUED)
1413                         return;
1414                 if (retval == CTL_RETVAL_ERROR) {
1415                         list->error = 1;
1416                         goto done;
1417                 }
1418         } else {
1419 //printf("ZZZ %d cscd, %d segs\n", list->ncscd, list->nseg);
1420                 while (list->curseg < list->nseg) {
1421                         seg = list->seg[list->curseg];
1422                         switch (seg->type_code) {
1423                         case EC_SEG_B2B:
1424                                 retval = tpc_process_b2b(list);
1425                                 break;
1426                         case EC_SEG_VERIFY:
1427                                 retval = tpc_process_verify(list);
1428                                 break;
1429                         case EC_SEG_REGISTER_KEY:
1430                                 retval = tpc_process_register_key(list);
1431                                 break;
1432                         default:
1433                                 scsi_ulto4b(list->curseg, csi);
1434                                 ctl_set_sense(ctsio, /*current_error*/ 1,
1435                                     /*sense_key*/ SSD_KEY_COPY_ABORTED,
1436                                     /*asc*/ 0x26, /*ascq*/ 0x09,
1437                                     SSD_ELEM_COMMAND, sizeof(csi), csi,
1438                                     SSD_ELEM_NONE);
1439                                 goto done;
1440                         }
1441                         if (retval == CTL_RETVAL_QUEUED)
1442                                 return;
1443                         if (retval == CTL_RETVAL_ERROR) {
1444                                 list->error = 1;
1445                                 goto done;
1446                         }
1447                         list->curseg++;
1448                         list->stage = 0;
1449                 }
1450         }
1451
1452         ctl_set_success(ctsio);
1453
1454 done:
1455 //printf("ZZZ done\n");
1456         free(list->params, M_CTL);
1457         list->params = NULL;
1458         if (list->token) {
1459                 mtx_lock(&softc->tpc_lock);
1460                 if (--list->token->active == 0)
1461                         list->token->last_active = time_uptime;
1462                 mtx_unlock(&softc->tpc_lock);
1463                 list->token = NULL;
1464         }
1465         mtx_lock(&lun->lun_lock);
1466         if ((list->flags & EC_LIST_ID_USAGE_MASK) == EC_LIST_ID_USAGE_NONE) {
1467                 TAILQ_REMOVE(&lun->tpc_lists, list, links);
1468                 free(list, M_CTL);
1469         } else {
1470                 list->completed = 1;
1471                 list->last_active = time_uptime;
1472                 list->sense_data = ctsio->sense_data;
1473                 list->sense_len = ctsio->sense_len;
1474                 list->scsi_status = ctsio->scsi_status;
1475         }
1476         mtx_unlock(&lun->lun_lock);
1477
1478         ctl_done((union ctl_io *)ctsio);
1479 }
1480
1481 /*
1482  * For any sort of check condition, busy, etc., we just retry.  We do not
1483  * decrement the retry count for unit attention type errors.  These are
1484  * normal, and we want to save the retry count for "real" errors.  Otherwise,
1485  * we could end up with situations where a command will succeed in some
1486  * situations and fail in others, depending on whether a unit attention is
1487  * pending.  Also, some of our error recovery actions, most notably the
1488  * LUN reset action, will cause a unit attention.
1489  *
1490  * We can add more detail here later if necessary.
1491  */
1492 static tpc_error_action
1493 tpc_checkcond_parse(union ctl_io *io)
1494 {
1495         tpc_error_action error_action;
1496         int error_code, sense_key, asc, ascq;
1497
1498         /*
1499          * Default to retrying the command.
1500          */
1501         error_action = TPC_ERR_RETRY;
1502
1503         scsi_extract_sense_len(&io->scsiio.sense_data,
1504                                io->scsiio.sense_len,
1505                                &error_code,
1506                                &sense_key,
1507                                &asc,
1508                                &ascq,
1509                                /*show_errors*/ 1);
1510
1511         switch (error_code) {
1512         case SSD_DEFERRED_ERROR:
1513         case SSD_DESC_DEFERRED_ERROR:
1514                 error_action |= TPC_ERR_NO_DECREMENT;
1515                 break;
1516         case SSD_CURRENT_ERROR:
1517         case SSD_DESC_CURRENT_ERROR:
1518         default:
1519                 switch (sense_key) {
1520                 case SSD_KEY_UNIT_ATTENTION:
1521                         error_action |= TPC_ERR_NO_DECREMENT;
1522                         break;
1523                 case SSD_KEY_HARDWARE_ERROR:
1524                         /*
1525                          * This is our generic "something bad happened"
1526                          * error code.  It often isn't recoverable.
1527                          */
1528                         if ((asc == 0x44) && (ascq == 0x00))
1529                                 error_action = TPC_ERR_FAIL;
1530                         break;
1531                 case SSD_KEY_NOT_READY:
1532                         /*
1533                          * If the LUN is powered down, there likely isn't
1534                          * much point in retrying right now.
1535                          */
1536                         if ((asc == 0x04) && (ascq == 0x02))
1537                                 error_action = TPC_ERR_FAIL;
1538                         /*
1539                          * If the LUN is offline, there probably isn't much
1540                          * point in retrying, either.
1541                          */
1542                         if ((asc == 0x04) && (ascq == 0x03))
1543                                 error_action = TPC_ERR_FAIL;
1544                         break;
1545                 }
1546         }
1547         return (error_action);
1548 }
1549
1550 static tpc_error_action
1551 tpc_error_parse(union ctl_io *io)
1552 {
1553         tpc_error_action error_action = TPC_ERR_RETRY;
1554
1555         switch (io->io_hdr.io_type) {
1556         case CTL_IO_SCSI:
1557                 switch (io->io_hdr.status & CTL_STATUS_MASK) {
1558                 case CTL_SCSI_ERROR:
1559                         switch (io->scsiio.scsi_status) {
1560                         case SCSI_STATUS_CHECK_COND:
1561                                 error_action = tpc_checkcond_parse(io);
1562                                 break;
1563                         default:
1564                                 break;
1565                         }
1566                         break;
1567                 default:
1568                         break;
1569                 }
1570                 break;
1571         case CTL_IO_TASK:
1572                 break;
1573         default:
1574                 panic("%s: invalid ctl_io type %d\n", __func__,
1575                       io->io_hdr.io_type);
1576                 break;
1577         }
1578         return (error_action);
1579 }
1580
1581 void
1582 tpc_done(union ctl_io *io)
1583 {
1584         struct tpc_io *tio, *tior;
1585
1586         /*
1587          * Very minimal retry logic.  We basically retry if we got an error
1588          * back, and the retry count is greater than 0.  If we ever want
1589          * more sophisticated initiator type behavior, the CAM error
1590          * recovery code in ../common might be helpful.
1591          */
1592         tio = io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr;
1593         if (((io->io_hdr.status & CTL_STATUS_MASK) != CTL_SUCCESS)
1594          && (io->io_hdr.retries > 0)) {
1595                 ctl_io_status old_status;
1596                 tpc_error_action error_action;
1597
1598                 error_action = tpc_error_parse(io);
1599                 switch (error_action & TPC_ERR_MASK) {
1600                 case TPC_ERR_FAIL:
1601                         break;
1602                 case TPC_ERR_RETRY:
1603                 default:
1604                         if ((error_action & TPC_ERR_NO_DECREMENT) == 0)
1605                                 io->io_hdr.retries--;
1606                         old_status = io->io_hdr.status;
1607                         io->io_hdr.status = CTL_STATUS_NONE;
1608                         io->io_hdr.flags &= ~CTL_FLAG_ABORT;
1609                         io->io_hdr.flags &= ~CTL_FLAG_SENT_2OTHER_SC;
1610                         if (tpcl_queue(io, tio->lun) != CTL_RETVAL_COMPLETE) {
1611                                 printf("%s: error returned from ctl_queue()!\n",
1612                                        __func__);
1613                                 io->io_hdr.status = old_status;
1614                         } else
1615                                 return;
1616                 }
1617         }
1618
1619         if ((io->io_hdr.status & CTL_STATUS_MASK) != CTL_SUCCESS)
1620                 tio->list->error = 1;
1621         else
1622                 atomic_add_int(&tio->list->curops, 1);
1623         if (!tio->list->error && !tio->list->abort) {
1624                 while ((tior = TAILQ_FIRST(&tio->run)) != NULL) {
1625                         TAILQ_REMOVE(&tio->run, tior, rlinks);
1626                         atomic_add_int(&tio->list->tbdio, 1);
1627                         if (tpcl_queue(tior->io, tior->lun) != CTL_RETVAL_COMPLETE)
1628                                 panic("tpcl_queue() error");
1629                 }
1630         }
1631         if (atomic_fetchadd_int(&tio->list->tbdio, -1) == 1)
1632                 tpc_process(tio->list);
1633 }
1634
1635 int
1636 ctl_extended_copy_lid1(struct ctl_scsiio *ctsio)
1637 {
1638         struct scsi_extended_copy *cdb;
1639         struct scsi_extended_copy_lid1_data *data;
1640         struct ctl_lun *lun;
1641         struct tpc_list *list, *tlist;
1642         uint8_t *ptr;
1643         char *value;
1644         int len, off, lencscd, lenseg, leninl, nseg;
1645
1646         CTL_DEBUG_PRINT(("ctl_extended_copy_lid1\n"));
1647
1648         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
1649         cdb = (struct scsi_extended_copy *)ctsio->cdb;
1650         len = scsi_4btoul(cdb->length);
1651
1652         if (len == 0) {
1653                 ctl_set_success(ctsio);
1654                 goto done;
1655         }
1656         if (len < sizeof(struct scsi_extended_copy_lid1_data) ||
1657             len > sizeof(struct scsi_extended_copy_lid1_data) +
1658             TPC_MAX_LIST + TPC_MAX_INLINE) {
1659                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
1660                     /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
1661                 goto done;
1662         }
1663
1664         /*
1665          * If we've got a kernel request that hasn't been malloced yet,
1666          * malloc it and tell the caller the data buffer is here.
1667          */
1668         if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
1669                 ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
1670                 ctsio->kern_data_len = len;
1671                 ctsio->kern_total_len = len;
1672                 ctsio->kern_data_resid = 0;
1673                 ctsio->kern_rel_offset = 0;
1674                 ctsio->kern_sg_entries = 0;
1675                 ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
1676                 ctsio->be_move_done = ctl_config_move_done;
1677                 ctl_datamove((union ctl_io *)ctsio);
1678
1679                 return (CTL_RETVAL_COMPLETE);
1680         }
1681
1682         data = (struct scsi_extended_copy_lid1_data *)ctsio->kern_data_ptr;
1683         lencscd = scsi_2btoul(data->cscd_list_length);
1684         lenseg = scsi_4btoul(data->segment_list_length);
1685         leninl = scsi_4btoul(data->inline_data_length);
1686         if (lencscd > TPC_MAX_CSCDS * sizeof(struct scsi_ec_cscd)) {
1687                 ctl_set_sense(ctsio, /*current_error*/ 1,
1688                     /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1689                     /*asc*/ 0x26, /*ascq*/ 0x06, SSD_ELEM_NONE);
1690                 goto done;
1691         }
1692         if (lenseg > TPC_MAX_SEGS * sizeof(struct scsi_ec_segment)) {
1693                 ctl_set_sense(ctsio, /*current_error*/ 1,
1694                     /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1695                     /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1696                 goto done;
1697         }
1698         if (lencscd + lenseg > TPC_MAX_LIST ||
1699             leninl > TPC_MAX_INLINE ||
1700             len < sizeof(struct scsi_extended_copy_lid1_data) +
1701              lencscd + lenseg + leninl) {
1702                 ctl_set_param_len_error(ctsio);
1703                 goto done;
1704         }
1705
1706         list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
1707         list->service_action = cdb->service_action;
1708         value = ctl_get_opt(&lun->be_lun->options, "insecure_tpc");
1709         if (value != NULL && strcmp(value, "on") == 0)
1710                 list->init_port = -1;
1711         else
1712                 list->init_port = ctsio->io_hdr.nexus.targ_port;
1713         list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
1714         list->list_id = data->list_identifier;
1715         list->flags = data->flags;
1716         list->params = ctsio->kern_data_ptr;
1717         list->cscd = (struct scsi_ec_cscd *)&data->data[0];
1718         ptr = &data->data[lencscd];
1719         for (nseg = 0, off = 0; off < lenseg; nseg++) {
1720                 if (nseg >= TPC_MAX_SEGS) {
1721                         free(list, M_CTL);
1722                         ctl_set_sense(ctsio, /*current_error*/ 1,
1723                             /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1724                             /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1725                         goto done;
1726                 }
1727                 list->seg[nseg] = (struct scsi_ec_segment *)(ptr + off);
1728                 off += sizeof(struct scsi_ec_segment) +
1729                     scsi_2btoul(list->seg[nseg]->descr_length);
1730         }
1731         list->inl = &data->data[lencscd + lenseg];
1732         list->ncscd = lencscd / sizeof(struct scsi_ec_cscd);
1733         list->nseg = nseg;
1734         list->leninl = leninl;
1735         list->ctsio = ctsio;
1736         list->lun = lun;
1737         mtx_lock(&lun->lun_lock);
1738         if ((list->flags & EC_LIST_ID_USAGE_MASK) != EC_LIST_ID_USAGE_NONE) {
1739                 tlist = tpc_find_list(lun, list->list_id, list->init_idx);
1740                 if (tlist != NULL && !tlist->completed) {
1741                         mtx_unlock(&lun->lun_lock);
1742                         free(list, M_CTL);
1743                         ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
1744                             /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
1745                             /*bit*/ 0);
1746                         goto done;
1747                 }
1748                 if (tlist != NULL) {
1749                         TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
1750                         free(tlist, M_CTL);
1751                 }
1752         }
1753         TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
1754         mtx_unlock(&lun->lun_lock);
1755
1756         tpc_process(list);
1757         return (CTL_RETVAL_COMPLETE);
1758
1759 done:
1760         if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
1761                 free(ctsio->kern_data_ptr, M_CTL);
1762                 ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
1763         }
1764         ctl_done((union ctl_io *)ctsio);
1765         return (CTL_RETVAL_COMPLETE);
1766 }
1767
1768 int
1769 ctl_extended_copy_lid4(struct ctl_scsiio *ctsio)
1770 {
1771         struct scsi_extended_copy *cdb;
1772         struct scsi_extended_copy_lid4_data *data;
1773         struct ctl_lun *lun;
1774         struct tpc_list *list, *tlist;
1775         uint8_t *ptr;
1776         char *value;
1777         int len, off, lencscd, lenseg, leninl, nseg;
1778
1779         CTL_DEBUG_PRINT(("ctl_extended_copy_lid4\n"));
1780
1781         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
1782         cdb = (struct scsi_extended_copy *)ctsio->cdb;
1783         len = scsi_4btoul(cdb->length);
1784
1785         if (len == 0) {
1786                 ctl_set_success(ctsio);
1787                 goto done;
1788         }
1789         if (len < sizeof(struct scsi_extended_copy_lid4_data) ||
1790             len > sizeof(struct scsi_extended_copy_lid4_data) +
1791             TPC_MAX_LIST + TPC_MAX_INLINE) {
1792                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
1793                     /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
1794                 goto done;
1795         }
1796
1797         /*
1798          * If we've got a kernel request that hasn't been malloced yet,
1799          * malloc it and tell the caller the data buffer is here.
1800          */
1801         if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
1802                 ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
1803                 ctsio->kern_data_len = len;
1804                 ctsio->kern_total_len = len;
1805                 ctsio->kern_data_resid = 0;
1806                 ctsio->kern_rel_offset = 0;
1807                 ctsio->kern_sg_entries = 0;
1808                 ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
1809                 ctsio->be_move_done = ctl_config_move_done;
1810                 ctl_datamove((union ctl_io *)ctsio);
1811
1812                 return (CTL_RETVAL_COMPLETE);
1813         }
1814
1815         data = (struct scsi_extended_copy_lid4_data *)ctsio->kern_data_ptr;
1816         lencscd = scsi_2btoul(data->cscd_list_length);
1817         lenseg = scsi_2btoul(data->segment_list_length);
1818         leninl = scsi_2btoul(data->inline_data_length);
1819         if (lencscd > TPC_MAX_CSCDS * sizeof(struct scsi_ec_cscd)) {
1820                 ctl_set_sense(ctsio, /*current_error*/ 1,
1821                     /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1822                     /*asc*/ 0x26, /*ascq*/ 0x06, SSD_ELEM_NONE);
1823                 goto done;
1824         }
1825         if (lenseg > TPC_MAX_SEGS * sizeof(struct scsi_ec_segment)) {
1826                 ctl_set_sense(ctsio, /*current_error*/ 1,
1827                     /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1828                     /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1829                 goto done;
1830         }
1831         if (lencscd + lenseg > TPC_MAX_LIST ||
1832             leninl > TPC_MAX_INLINE ||
1833             len < sizeof(struct scsi_extended_copy_lid1_data) +
1834              lencscd + lenseg + leninl) {
1835                 ctl_set_param_len_error(ctsio);
1836                 goto done;
1837         }
1838
1839         list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
1840         list->service_action = cdb->service_action;
1841         value = ctl_get_opt(&lun->be_lun->options, "insecure_tpc");
1842         if (value != NULL && strcmp(value, "on") == 0)
1843                 list->init_port = -1;
1844         else
1845                 list->init_port = ctsio->io_hdr.nexus.targ_port;
1846         list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
1847         list->list_id = scsi_4btoul(data->list_identifier);
1848         list->flags = data->flags;
1849         list->params = ctsio->kern_data_ptr;
1850         list->cscd = (struct scsi_ec_cscd *)&data->data[0];
1851         ptr = &data->data[lencscd];
1852         for (nseg = 0, off = 0; off < lenseg; nseg++) {
1853                 if (nseg >= TPC_MAX_SEGS) {
1854                         free(list, M_CTL);
1855                         ctl_set_sense(ctsio, /*current_error*/ 1,
1856                             /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1857                             /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1858                         goto done;
1859                 }
1860                 list->seg[nseg] = (struct scsi_ec_segment *)(ptr + off);
1861                 off += sizeof(struct scsi_ec_segment) +
1862                     scsi_2btoul(list->seg[nseg]->descr_length);
1863         }
1864         list->inl = &data->data[lencscd + lenseg];
1865         list->ncscd = lencscd / sizeof(struct scsi_ec_cscd);
1866         list->nseg = nseg;
1867         list->leninl = leninl;
1868         list->ctsio = ctsio;
1869         list->lun = lun;
1870         mtx_lock(&lun->lun_lock);
1871         if ((list->flags & EC_LIST_ID_USAGE_MASK) != EC_LIST_ID_USAGE_NONE) {
1872                 tlist = tpc_find_list(lun, list->list_id, list->init_idx);
1873                 if (tlist != NULL && !tlist->completed) {
1874                         mtx_unlock(&lun->lun_lock);
1875                         free(list, M_CTL);
1876                         ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
1877                             /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
1878                             /*bit*/ 0);
1879                         goto done;
1880                 }
1881                 if (tlist != NULL) {
1882                         TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
1883                         free(tlist, M_CTL);
1884                 }
1885         }
1886         TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
1887         mtx_unlock(&lun->lun_lock);
1888
1889         tpc_process(list);
1890         return (CTL_RETVAL_COMPLETE);
1891
1892 done:
1893         if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
1894                 free(ctsio->kern_data_ptr, M_CTL);
1895                 ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
1896         }
1897         ctl_done((union ctl_io *)ctsio);
1898         return (CTL_RETVAL_COMPLETE);
1899 }
1900
1901 static void
1902 tpc_create_token(struct ctl_lun *lun, struct ctl_port *port, off_t len,
1903     struct scsi_token *token)
1904 {
1905         static int id = 0;
1906         struct scsi_vpd_id_descriptor *idd = NULL;
1907         struct scsi_ec_cscd_id *cscd;
1908         struct scsi_read_capacity_data_long *dtsd;
1909         int targid_len;
1910
1911         scsi_ulto4b(ROD_TYPE_AUR, token->type);
1912         scsi_ulto2b(0x01f8, token->length);
1913         scsi_u64to8b(atomic_fetchadd_int(&id, 1), &token->body[0]);
1914         if (lun->lun_devid)
1915                 idd = scsi_get_devid_desc((struct scsi_vpd_id_descriptor *)
1916                     lun->lun_devid->data, lun->lun_devid->len,
1917                     scsi_devid_is_lun_naa);
1918         if (idd == NULL && lun->lun_devid)
1919                 idd = scsi_get_devid_desc((struct scsi_vpd_id_descriptor *)
1920                     lun->lun_devid->data, lun->lun_devid->len,
1921                     scsi_devid_is_lun_eui64);
1922         if (idd != NULL) {
1923                 cscd = (struct scsi_ec_cscd_id *)&token->body[8];
1924                 cscd->type_code = EC_CSCD_ID;
1925                 cscd->luidt_pdt = T_DIRECT;
1926                 memcpy(&cscd->codeset, idd, 4 + idd->length);
1927                 scsi_ulto3b(lun->be_lun->blocksize, cscd->dtsp.block_length);
1928         }
1929         scsi_u64to8b(0, &token->body[40]); /* XXX: Should be 128bit value. */
1930         scsi_u64to8b(len, &token->body[48]);
1931
1932         /* ROD token device type specific data (RC16 without first field) */
1933         dtsd = (struct scsi_read_capacity_data_long *)&token->body[88 - 8];
1934         scsi_ulto4b(lun->be_lun->blocksize, dtsd->length);
1935         dtsd->prot_lbppbe = lun->be_lun->pblockexp & SRC16_LBPPBE;
1936         scsi_ulto2b(lun->be_lun->pblockoff & SRC16_LALBA_A, dtsd->lalba_lbp);
1937         if (lun->be_lun->flags & CTL_LUN_FLAG_UNMAP)
1938                 dtsd->lalba_lbp[0] |= SRC16_LBPME | SRC16_LBPRZ;
1939
1940         if (port->target_devid) {
1941                 targid_len = port->target_devid->len;
1942                 memcpy(&token->body[120], port->target_devid->data, targid_len);
1943         } else
1944                 targid_len = 32;
1945         arc4rand(&token->body[120 + targid_len], 384 - targid_len, 0);
1946 };
1947
1948 int
1949 ctl_populate_token(struct ctl_scsiio *ctsio)
1950 {
1951         struct scsi_populate_token *cdb;
1952         struct scsi_populate_token_data *data;
1953         struct ctl_softc *softc;
1954         struct ctl_lun *lun;
1955         struct ctl_port *port;
1956         struct tpc_list *list, *tlist;
1957         struct tpc_token *token;
1958         uint64_t lba;
1959         int len, lendata, lendesc;
1960
1961         CTL_DEBUG_PRINT(("ctl_populate_token\n"));
1962
1963         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
1964         softc = lun->ctl_softc;
1965         port = softc->ctl_ports[ctsio->io_hdr.nexus.targ_port];
1966         cdb = (struct scsi_populate_token *)ctsio->cdb;
1967         len = scsi_4btoul(cdb->length);
1968
1969         if (len < sizeof(struct scsi_populate_token_data) ||
1970             len > sizeof(struct scsi_populate_token_data) +
1971              TPC_MAX_SEGS * sizeof(struct scsi_range_desc)) {
1972                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
1973                     /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
1974                 goto done;
1975         }
1976
1977         /*
1978          * If we've got a kernel request that hasn't been malloced yet,
1979          * malloc it and tell the caller the data buffer is here.
1980          */
1981         if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
1982                 ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
1983                 ctsio->kern_data_len = len;
1984                 ctsio->kern_total_len = len;
1985                 ctsio->kern_data_resid = 0;
1986                 ctsio->kern_rel_offset = 0;
1987                 ctsio->kern_sg_entries = 0;
1988                 ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
1989                 ctsio->be_move_done = ctl_config_move_done;
1990                 ctl_datamove((union ctl_io *)ctsio);
1991
1992                 return (CTL_RETVAL_COMPLETE);
1993         }
1994
1995         data = (struct scsi_populate_token_data *)ctsio->kern_data_ptr;
1996         lendata = scsi_2btoul(data->length);
1997         if (lendata < sizeof(struct scsi_populate_token_data) - 2 +
1998             sizeof(struct scsi_range_desc)) {
1999                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2000                     /*field*/ 0, /*bit_valid*/ 0, /*bit*/ 0);
2001                 goto done;
2002         }
2003         lendesc = scsi_2btoul(data->range_descriptor_length);
2004         if (lendesc < sizeof(struct scsi_range_desc) ||
2005             len < sizeof(struct scsi_populate_token_data) + lendesc ||
2006             lendata < sizeof(struct scsi_populate_token_data) - 2 + lendesc) {
2007                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2008                     /*field*/ 14, /*bit_valid*/ 0, /*bit*/ 0);
2009                 goto done;
2010         }
2011 /*
2012         printf("PT(list=%u) flags=%x to=%d rt=%x len=%x\n",
2013             scsi_4btoul(cdb->list_identifier),
2014             data->flags, scsi_4btoul(data->inactivity_timeout),
2015             scsi_4btoul(data->rod_type),
2016             scsi_2btoul(data->range_descriptor_length));
2017 */
2018
2019         /* Validate INACTIVITY TIMEOUT field */
2020         if (scsi_4btoul(data->inactivity_timeout) > TPC_MAX_TOKEN_TIMEOUT) {
2021                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2022                     /*command*/ 0, /*field*/ 4, /*bit_valid*/ 0,
2023                     /*bit*/ 0);
2024                 goto done;
2025         }
2026
2027         /* Validate ROD TYPE field */
2028         if ((data->flags & EC_PT_RTV) &&
2029             scsi_4btoul(data->rod_type) != ROD_TYPE_AUR) {
2030                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2031                     /*field*/ 8, /*bit_valid*/ 0, /*bit*/ 0);
2032                 goto done;
2033         }
2034
2035         /* Validate list of ranges */
2036         if (tpc_check_ranges_l(&data->desc[0],
2037             scsi_2btoul(data->range_descriptor_length) /
2038             sizeof(struct scsi_range_desc),
2039             lun->be_lun->maxlba, &lba) != 0) {
2040                 ctl_set_lba_out_of_range(ctsio, lba);
2041                 goto done;
2042         }
2043         if (tpc_check_ranges_x(&data->desc[0],
2044             scsi_2btoul(data->range_descriptor_length) /
2045             sizeof(struct scsi_range_desc)) != 0) {
2046                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 0,
2047                     /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2048                     /*bit*/ 0);
2049                 goto done;
2050         }
2051
2052         list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
2053         list->service_action = cdb->service_action;
2054         list->init_port = ctsio->io_hdr.nexus.targ_port;
2055         list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
2056         list->list_id = scsi_4btoul(cdb->list_identifier);
2057         list->flags = data->flags;
2058         list->ctsio = ctsio;
2059         list->lun = lun;
2060         mtx_lock(&lun->lun_lock);
2061         tlist = tpc_find_list(lun, list->list_id, list->init_idx);
2062         if (tlist != NULL && !tlist->completed) {
2063                 mtx_unlock(&lun->lun_lock);
2064                 free(list, M_CTL);
2065                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2066                     /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2067                     /*bit*/ 0);
2068                 goto done;
2069         }
2070         if (tlist != NULL) {
2071                 TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
2072                 free(tlist, M_CTL);
2073         }
2074         TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
2075         mtx_unlock(&lun->lun_lock);
2076
2077         token = malloc(sizeof(*token), M_CTL, M_WAITOK | M_ZERO);
2078         token->lun = lun->lun;
2079         token->blocksize = lun->be_lun->blocksize;
2080         token->params = ctsio->kern_data_ptr;
2081         token->range = &data->desc[0];
2082         token->nrange = scsi_2btoul(data->range_descriptor_length) /
2083             sizeof(struct scsi_range_desc);
2084         list->cursectors = tpc_ranges_length(token->range, token->nrange);
2085         list->curbytes = (off_t)list->cursectors * lun->be_lun->blocksize;
2086         tpc_create_token(lun, port, list->curbytes,
2087             (struct scsi_token *)token->token);
2088         token->active = 0;
2089         token->last_active = time_uptime;
2090         token->timeout = scsi_4btoul(data->inactivity_timeout);
2091         if (token->timeout == 0)
2092                 token->timeout = TPC_DFL_TOKEN_TIMEOUT;
2093         else if (token->timeout < TPC_MIN_TOKEN_TIMEOUT)
2094                 token->timeout = TPC_MIN_TOKEN_TIMEOUT;
2095         memcpy(list->res_token, token->token, sizeof(list->res_token));
2096         list->res_token_valid = 1;
2097         list->curseg = 0;
2098         list->completed = 1;
2099         list->last_active = time_uptime;
2100         mtx_lock(&softc->tpc_lock);
2101         TAILQ_INSERT_TAIL(&softc->tpc_tokens, token, links);
2102         mtx_unlock(&softc->tpc_lock);
2103         ctl_set_success(ctsio);
2104         ctl_done((union ctl_io *)ctsio);
2105         return (CTL_RETVAL_COMPLETE);
2106
2107 done:
2108         if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
2109                 free(ctsio->kern_data_ptr, M_CTL);
2110                 ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
2111         }
2112         ctl_done((union ctl_io *)ctsio);
2113         return (CTL_RETVAL_COMPLETE);
2114 }
2115
2116 int
2117 ctl_write_using_token(struct ctl_scsiio *ctsio)
2118 {
2119         struct scsi_write_using_token *cdb;
2120         struct scsi_write_using_token_data *data;
2121         struct ctl_softc *softc;
2122         struct ctl_lun *lun;
2123         struct tpc_list *list, *tlist;
2124         struct tpc_token *token;
2125         uint64_t lba;
2126         int len, lendata, lendesc;
2127
2128         CTL_DEBUG_PRINT(("ctl_write_using_token\n"));
2129
2130         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
2131         softc = lun->ctl_softc;
2132         cdb = (struct scsi_write_using_token *)ctsio->cdb;
2133         len = scsi_4btoul(cdb->length);
2134
2135         if (len < sizeof(struct scsi_write_using_token_data) ||
2136             len > sizeof(struct scsi_write_using_token_data) +
2137              TPC_MAX_SEGS * sizeof(struct scsi_range_desc)) {
2138                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
2139                     /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
2140                 goto done;
2141         }
2142
2143         /*
2144          * If we've got a kernel request that hasn't been malloced yet,
2145          * malloc it and tell the caller the data buffer is here.
2146          */
2147         if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
2148                 ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
2149                 ctsio->kern_data_len = len;
2150                 ctsio->kern_total_len = len;
2151                 ctsio->kern_data_resid = 0;
2152                 ctsio->kern_rel_offset = 0;
2153                 ctsio->kern_sg_entries = 0;
2154                 ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
2155                 ctsio->be_move_done = ctl_config_move_done;
2156                 ctl_datamove((union ctl_io *)ctsio);
2157
2158                 return (CTL_RETVAL_COMPLETE);
2159         }
2160
2161         data = (struct scsi_write_using_token_data *)ctsio->kern_data_ptr;
2162         lendata = scsi_2btoul(data->length);
2163         if (lendata < sizeof(struct scsi_write_using_token_data) - 2 +
2164             sizeof(struct scsi_range_desc)) {
2165                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2166                     /*field*/ 0, /*bit_valid*/ 0, /*bit*/ 0);
2167                 goto done;
2168         }
2169         lendesc = scsi_2btoul(data->range_descriptor_length);
2170         if (lendesc < sizeof(struct scsi_range_desc) ||
2171             len < sizeof(struct scsi_write_using_token_data) + lendesc ||
2172             lendata < sizeof(struct scsi_write_using_token_data) - 2 + lendesc) {
2173                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2174                     /*field*/ 534, /*bit_valid*/ 0, /*bit*/ 0);
2175                 goto done;
2176         }
2177 /*
2178         printf("WUT(list=%u) flags=%x off=%ju len=%x\n",
2179             scsi_4btoul(cdb->list_identifier),
2180             data->flags, scsi_8btou64(data->offset_into_rod),
2181             scsi_2btoul(data->range_descriptor_length));
2182 */
2183
2184         /* Validate list of ranges */
2185         if (tpc_check_ranges_l(&data->desc[0],
2186             scsi_2btoul(data->range_descriptor_length) /
2187             sizeof(struct scsi_range_desc),
2188             lun->be_lun->maxlba, &lba) != 0) {
2189                 ctl_set_lba_out_of_range(ctsio, lba);
2190                 goto done;
2191         }
2192         if (tpc_check_ranges_x(&data->desc[0],
2193             scsi_2btoul(data->range_descriptor_length) /
2194             sizeof(struct scsi_range_desc)) != 0) {
2195                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 0,
2196                     /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2197                     /*bit*/ 0);
2198                 goto done;
2199         }
2200
2201         list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
2202         list->service_action = cdb->service_action;
2203         list->init_port = ctsio->io_hdr.nexus.targ_port;
2204         list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
2205         list->list_id = scsi_4btoul(cdb->list_identifier);
2206         list->flags = data->flags;
2207         list->params = ctsio->kern_data_ptr;
2208         list->range = &data->desc[0];
2209         list->nrange = scsi_2btoul(data->range_descriptor_length) /
2210             sizeof(struct scsi_range_desc);
2211         list->offset_into_rod = scsi_8btou64(data->offset_into_rod);
2212         list->ctsio = ctsio;
2213         list->lun = lun;
2214         mtx_lock(&lun->lun_lock);
2215         tlist = tpc_find_list(lun, list->list_id, list->init_idx);
2216         if (tlist != NULL && !tlist->completed) {
2217                 mtx_unlock(&lun->lun_lock);
2218                 free(list, M_CTL);
2219                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2220                     /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2221                     /*bit*/ 0);
2222                 goto done;
2223         }
2224         if (tlist != NULL) {
2225                 TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
2226                 free(tlist, M_CTL);
2227         }
2228         TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
2229         mtx_unlock(&lun->lun_lock);
2230
2231         /* Block device zero ROD token -> no token. */
2232         if (scsi_4btoul(data->rod_token) == ROD_TYPE_BLOCK_ZERO) {
2233                 tpc_process(list);
2234                 return (CTL_RETVAL_COMPLETE);
2235         }
2236
2237         mtx_lock(&softc->tpc_lock);
2238         TAILQ_FOREACH(token, &softc->tpc_tokens, links) {
2239                 if (memcmp(token->token, data->rod_token,
2240                     sizeof(data->rod_token)) == 0)
2241                         break;
2242         }
2243         if (token != NULL) {
2244                 token->active++;
2245                 list->token = token;
2246                 if (data->flags & EC_WUT_DEL_TKN)
2247                         token->timeout = 0;
2248         }
2249         mtx_unlock(&softc->tpc_lock);
2250         if (token == NULL) {
2251                 mtx_lock(&lun->lun_lock);
2252                 TAILQ_REMOVE(&lun->tpc_lists, list, links);
2253                 mtx_unlock(&lun->lun_lock);
2254                 free(list, M_CTL);
2255                 ctl_set_sense(ctsio, /*current_error*/ 1,
2256                     /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
2257                     /*asc*/ 0x23, /*ascq*/ 0x04, SSD_ELEM_NONE);
2258                 goto done;
2259         }
2260
2261         tpc_process(list);
2262         return (CTL_RETVAL_COMPLETE);
2263
2264 done:
2265         if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
2266                 free(ctsio->kern_data_ptr, M_CTL);
2267                 ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
2268         }
2269         ctl_done((union ctl_io *)ctsio);
2270         return (CTL_RETVAL_COMPLETE);
2271 }
2272
2273 int
2274 ctl_receive_rod_token_information(struct ctl_scsiio *ctsio)
2275 {
2276         struct ctl_lun *lun;
2277         struct scsi_receive_rod_token_information *cdb;
2278         struct scsi_receive_copy_status_lid4_data *data;
2279         struct tpc_list *list;
2280         struct tpc_list list_copy;
2281         uint8_t *ptr;
2282         int retval;
2283         int alloc_len, total_len, token_len;
2284         uint32_t list_id;
2285
2286         CTL_DEBUG_PRINT(("ctl_receive_rod_token_information\n"));
2287
2288         cdb = (struct scsi_receive_rod_token_information *)ctsio->cdb;
2289         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
2290
2291         retval = CTL_RETVAL_COMPLETE;
2292
2293         list_id = scsi_4btoul(cdb->list_identifier);
2294         mtx_lock(&lun->lun_lock);
2295         list = tpc_find_list(lun, list_id,
2296             ctl_get_initindex(&ctsio->io_hdr.nexus));
2297         if (list == NULL) {
2298                 mtx_unlock(&lun->lun_lock);
2299                 ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2300                     /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
2301                     /*bit*/ 0);
2302                 ctl_done((union ctl_io *)ctsio);
2303                 return (retval);
2304         }
2305         list_copy = *list;
2306         if (list->completed) {
2307                 TAILQ_REMOVE(&lun->tpc_lists, list, links);
2308                 free(list, M_CTL);
2309         }
2310         mtx_unlock(&lun->lun_lock);
2311
2312         token_len = list_copy.res_token_valid ? 2 + sizeof(list_copy.res_token) : 0;
2313         total_len = sizeof(*data) + list_copy.sense_len + 4 + token_len;
2314         alloc_len = scsi_4btoul(cdb->length);
2315
2316         ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
2317
2318         ctsio->kern_sg_entries = 0;
2319
2320         if (total_len < alloc_len) {
2321                 ctsio->residual = alloc_len - total_len;
2322                 ctsio->kern_data_len = total_len;
2323                 ctsio->kern_total_len = total_len;
2324         } else {
2325                 ctsio->residual = 0;
2326                 ctsio->kern_data_len = alloc_len;
2327                 ctsio->kern_total_len = alloc_len;
2328         }
2329         ctsio->kern_data_resid = 0;
2330         ctsio->kern_rel_offset = 0;
2331
2332         data = (struct scsi_receive_copy_status_lid4_data *)ctsio->kern_data_ptr;
2333         scsi_ulto4b(sizeof(*data) - 4 + list_copy.sense_len +
2334             4 + token_len, data->available_data);
2335         data->response_to_service_action = list_copy.service_action;
2336         if (list_copy.completed) {
2337                 if (list_copy.error)
2338                         data->copy_command_status = RCS_CCS_ERROR;
2339                 else if (list_copy.abort)
2340                         data->copy_command_status = RCS_CCS_ABORTED;
2341                 else
2342                         data->copy_command_status = RCS_CCS_COMPLETED;
2343         } else
2344                 data->copy_command_status = RCS_CCS_INPROG_FG;
2345         scsi_ulto2b(list_copy.curops, data->operation_counter);
2346         scsi_ulto4b(UINT32_MAX, data->estimated_status_update_delay);
2347         data->transfer_count_units = RCS_TC_LBAS;
2348         scsi_u64to8b(list_copy.cursectors, data->transfer_count);
2349         scsi_ulto2b(list_copy.curseg, data->segments_processed);
2350         data->length_of_the_sense_data_field = list_copy.sense_len;
2351         data->sense_data_length = list_copy.sense_len;
2352         memcpy(data->sense_data, &list_copy.sense_data, list_copy.sense_len);
2353
2354         ptr = &data->sense_data[data->length_of_the_sense_data_field];
2355         scsi_ulto4b(token_len, &ptr[0]);
2356         if (list_copy.res_token_valid) {
2357                 scsi_ulto2b(0, &ptr[4]);
2358                 memcpy(&ptr[6], list_copy.res_token, sizeof(list_copy.res_token));
2359         }
2360 /*
2361         printf("RRTI(list=%u) valid=%d\n",
2362             scsi_4btoul(cdb->list_identifier), list_copy.res_token_valid);
2363 */
2364         ctl_set_success(ctsio);
2365         ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
2366         ctsio->be_move_done = ctl_config_move_done;
2367         ctl_datamove((union ctl_io *)ctsio);
2368         return (retval);
2369 }
2370
2371 int
2372 ctl_report_all_rod_tokens(struct ctl_scsiio *ctsio)
2373 {
2374         struct ctl_softc *softc;
2375         struct ctl_lun *lun;
2376         struct scsi_report_all_rod_tokens *cdb;
2377         struct scsi_report_all_rod_tokens_data *data;
2378         struct tpc_token *token;
2379         int retval;
2380         int alloc_len, total_len, tokens, i;
2381
2382         CTL_DEBUG_PRINT(("ctl_receive_rod_token_information\n"));
2383
2384         cdb = (struct scsi_report_all_rod_tokens *)ctsio->cdb;
2385         lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
2386         softc = lun->ctl_softc;
2387
2388         retval = CTL_RETVAL_COMPLETE;
2389
2390         tokens = 0;
2391         mtx_lock(&softc->tpc_lock);
2392         TAILQ_FOREACH(token, &softc->tpc_tokens, links)
2393                 tokens++;
2394         mtx_unlock(&softc->tpc_lock);
2395         if (tokens > 512)
2396                 tokens = 512;
2397
2398         total_len = sizeof(*data) + tokens * 96;
2399         alloc_len = scsi_4btoul(cdb->length);
2400
2401         ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
2402
2403         ctsio->kern_sg_entries = 0;
2404
2405         if (total_len < alloc_len) {
2406                 ctsio->residual = alloc_len - total_len;
2407                 ctsio->kern_data_len = total_len;
2408                 ctsio->kern_total_len = total_len;
2409         } else {
2410                 ctsio->residual = 0;
2411                 ctsio->kern_data_len = alloc_len;
2412                 ctsio->kern_total_len = alloc_len;
2413         }
2414         ctsio->kern_data_resid = 0;
2415         ctsio->kern_rel_offset = 0;
2416
2417         data = (struct scsi_report_all_rod_tokens_data *)ctsio->kern_data_ptr;
2418         i = 0;
2419         mtx_lock(&softc->tpc_lock);
2420         TAILQ_FOREACH(token, &softc->tpc_tokens, links) {
2421                 if (i >= tokens)
2422                         break;
2423                 memcpy(&data->rod_management_token_list[i * 96],
2424                     token->token, 96);
2425                 i++;
2426         }
2427         mtx_unlock(&softc->tpc_lock);
2428         scsi_ulto4b(sizeof(*data) - 4 + i * 96, data->available_data);
2429 /*
2430         printf("RART tokens=%d\n", i);
2431 */
2432         ctl_set_success(ctsio);
2433         ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
2434         ctsio->be_move_done = ctl_config_move_done;
2435         ctl_datamove((union ctl_io *)ctsio);
2436         return (retval);
2437 }
2438