]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/blob - sys/dev/usb/umass.c
reclaim node reference when ieee80211_encap fails
[FreeBSD/FreeBSD.git] / sys / dev / usb / umass.c
1 /*-
2  * Copyright (c) 1999 MAEKAWA Masahide <bishop@rr.iij4u.or.jp>,
3  *                    Nick Hibma <n_hibma@freebsd.org>
4  * All rights reserved.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions
8  * are met:
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice, this list of conditions and the following disclaimer.
11  * 2. Redistributions in binary form must reproduce the above copyright
12  *    notice, this list of conditions and the following disclaimer in the
13  *    documentation and/or other materials provided with the distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
16  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
19  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
25  * SUCH DAMAGE.
26  *
27  *      $FreeBSD$
28  *      $NetBSD: umass.c,v 1.28 2000/04/02 23:46:53 augustss Exp $
29  */
30
31 /* Also already merged from NetBSD:
32  *      $NetBSD: umass.c,v 1.67 2001/11/25 19:05:22 augustss Exp $
33  *      $NetBSD: umass.c,v 1.90 2002/11/04 19:17:33 pooka Exp $
34  *      $NetBSD: umass.c,v 1.108 2003/11/07 17:03:25 wiz Exp $
35  *      $NetBSD: umass.c,v 1.109 2003/12/04 13:57:31 keihan Exp $
36  */
37
38 /*
39  * Universal Serial Bus Mass Storage Class specs:
40  * http://www.usb.org/developers/devclass_docs/usb_msc_overview_1.2.pdf
41  * http://www.usb.org/developers/devclass_docs/usbmassbulk_10.pdf
42  * http://www.usb.org/developers/devclass_docs/usb_msc_cbi_1.1.pdf
43  * http://www.usb.org/developers/devclass_docs/usbmass-ufi10.pdf
44  */
45
46 /*
47  * Ported to NetBSD by Lennart Augustsson <augustss@NetBSD.org>.
48  * Parts of the code written by Jason R. Thorpe <thorpej@shagadelic.org>.
49  */
50
51 /*
52  * The driver handles 3 Wire Protocols
53  * - Command/Bulk/Interrupt (CBI)
54  * - Command/Bulk/Interrupt with Command Completion Interrupt (CBI with CCI)
55  * - Mass Storage Bulk-Only (BBB)
56  *   (BBB refers Bulk/Bulk/Bulk for Command/Data/Status phases)
57  *
58  * Over these wire protocols it handles the following command protocols
59  * - SCSI
60  * - UFI (floppy command set)
61  * - 8070i (ATAPI)
62  *
63  * UFI and 8070i (ATAPI) are transformed versions of the SCSI command set. The
64  * sc->transform method is used to convert the commands into the appropriate
65  * format (if at all necessary). For example, UFI requires all commands to be
66  * 12 bytes in length amongst other things.
67  *
68  * The source code below is marked and can be split into a number of pieces
69  * (in this order):
70  *
71  * - probe/attach/detach
72  * - generic transfer routines
73  * - BBB
74  * - CBI
75  * - CBI_I (in addition to functions from CBI)
76  * - CAM (Common Access Method)
77  * - SCSI
78  * - UFI
79  * - 8070i (ATAPI)
80  *
81  * The protocols are implemented using a state machine, for the transfers as
82  * well as for the resets. The state machine is contained in umass_*_state.
83  * The state machine is started through either umass_*_transfer or
84  * umass_*_reset.
85  *
86  * The reason for doing this is a) CAM performs a lot better this way and b) it
87  * avoids using tsleep from interrupt context (for example after a failed
88  * transfer).
89  */
90
91 /*
92  * The SCSI related part of this driver has been derived from the
93  * dev/ppbus/vpo.c driver, by Nicolas Souchu (nsouch@freebsd.org).
94  *
95  * The CAM layer uses so called actions which are messages sent to the host
96  * adapter for completion. The actions come in through umass_cam_action. The
97  * appropriate block of routines is called depending on the transport protocol
98  * in use. When the transfer has finished, these routines call
99  * umass_cam_cb again to complete the CAM command.
100  */
101
102 /*
103  * XXX Currently CBI with CCI is not supported because it bombs the system
104  *     when the device is detached (low frequency interrupts are detached
105  *     too late.
106  */
107 #undef CBI_I
108
109 #include <sys/param.h>
110 #include <sys/systm.h>
111 #include <sys/kernel.h>
112 #include <sys/module.h>
113 #include <sys/bus.h>
114 #include <sys/sysctl.h>
115
116 #include <dev/usb/usb.h>
117 #include <dev/usb/usbdi.h>
118 #include <dev/usb/usbdi_util.h>
119 #include "usbdevs.h"
120
121 #include <cam/cam.h>
122 #include <cam/cam_ccb.h>
123 #include <cam/cam_sim.h>
124 #include <cam/cam_xpt_sim.h>
125 #include <cam/scsi/scsi_all.h>
126 #include <cam/scsi/scsi_da.h>
127
128 #include <cam/cam_periph.h>
129
130 #ifdef USB_DEBUG
131 #define DIF(m, x)       if (umassdebug & (m)) do { x ; } while (0)
132 #define DPRINTF(m, x)   if (umassdebug & (m)) logprintf x
133 #define UDMASS_GEN      0x00010000      /* general */
134 #define UDMASS_SCSI     0x00020000      /* scsi */
135 #define UDMASS_UFI      0x00040000      /* ufi command set */
136 #define UDMASS_ATAPI    0x00080000      /* 8070i command set */
137 #define UDMASS_CMD      (UDMASS_SCSI|UDMASS_UFI|UDMASS_ATAPI)
138 #define UDMASS_USB      0x00100000      /* USB general */
139 #define UDMASS_BBB      0x00200000      /* Bulk-Only transfers */
140 #define UDMASS_CBI      0x00400000      /* CBI transfers */
141 #define UDMASS_WIRE     (UDMASS_BBB|UDMASS_CBI)
142 #define UDMASS_ALL      0xffff0000      /* all of the above */
143 int umassdebug = 0;
144 SYSCTL_NODE(_hw_usb, OID_AUTO, umass, CTLFLAG_RW, 0, "USB umass");
145 SYSCTL_INT(_hw_usb_umass, OID_AUTO, debug, CTLFLAG_RW,
146            &umassdebug, 0, "umass debug level");
147 #else
148 #define DIF(m, x)       /* nop */
149 #define DPRINTF(m, x)   /* nop */
150 #endif
151
152
153 /* Generic definitions */
154
155 /* Direction for umass_*_transfer */
156 #define DIR_NONE        0
157 #define DIR_IN          1
158 #define DIR_OUT         2
159
160 /* device name */
161 #define DEVNAME         "umass"
162 #define DEVNAME_SIM     "umass-sim"
163
164 #define UMASS_MAX_TRANSFER_SIZE         65536
165 /* Approximate maximum transfer speeds (assumes 33% overhead). */
166 #define UMASS_FULL_TRANSFER_SPEED       1000
167 #define UMASS_HIGH_TRANSFER_SPEED       40000
168 #define UMASS_FLOPPY_TRANSFER_SPEED     20
169
170 #define UMASS_TIMEOUT                   5000 /* msecs */
171
172 /* CAM specific definitions */
173
174 #define UMASS_SCSIID_MAX        1       /* maximum number of drives expected */
175 #define UMASS_SCSIID_HOST       UMASS_SCSIID_MAX
176
177 #define MS_TO_TICKS(ms) ((ms) * hz / 1000)
178
179
180 /* Bulk-Only features */
181
182 #define UR_BBB_RESET            0xff            /* Bulk-Only reset */
183 #define UR_BBB_GET_MAX_LUN      0xfe            /* Get maximum lun */
184
185 /* Command Block Wrapper */
186 typedef struct {
187         uDWord          dCBWSignature;
188 #       define CBWSIGNATURE     0x43425355
189         uDWord          dCBWTag;
190         uDWord          dCBWDataTransferLength;
191         uByte           bCBWFlags;
192 #       define CBWFLAGS_OUT     0x00
193 #       define CBWFLAGS_IN      0x80
194         uByte           bCBWLUN;
195         uByte           bCDBLength;
196 #       define CBWCDBLENGTH     16
197         uByte           CBWCDB[CBWCDBLENGTH];
198 } umass_bbb_cbw_t;
199 #define UMASS_BBB_CBW_SIZE      31
200
201 /* Command Status Wrapper */
202 typedef struct {
203         uDWord          dCSWSignature;
204 #       define CSWSIGNATURE     0x53425355
205 #       define CSWSIGNATURE_OLYMPUS_C1  0x55425355
206         uDWord          dCSWTag;
207         uDWord          dCSWDataResidue;
208         uByte           bCSWStatus;
209 #       define CSWSTATUS_GOOD   0x0
210 #       define CSWSTATUS_FAILED 0x1
211 #       define CSWSTATUS_PHASE  0x2
212 } umass_bbb_csw_t;
213 #define UMASS_BBB_CSW_SIZE      13
214
215 /* CBI features */
216
217 #define UR_CBI_ADSC     0x00
218
219 typedef unsigned char umass_cbi_cbl_t[16];      /* Command block */
220
221 typedef union {
222         struct {
223                 unsigned char   type;
224                 #define IDB_TYPE_CCI            0x00
225                 unsigned char   value;
226                 #define IDB_VALUE_PASS          0x00
227                 #define IDB_VALUE_FAIL          0x01
228                 #define IDB_VALUE_PHASE         0x02
229                 #define IDB_VALUE_PERSISTENT    0x03
230                 #define IDB_VALUE_STATUS_MASK   0x03
231         } common;
232
233         struct {
234                 unsigned char   asc;
235                 unsigned char   ascq;
236         } ufi;
237 } umass_cbi_sbl_t;
238
239
240
241 struct umass_softc;             /* see below */
242
243 typedef void (*transfer_cb_f)   (struct umass_softc *sc, void *priv,
244                                 int residue, int status);
245 #define STATUS_CMD_OK           0       /* everything ok */
246 #define STATUS_CMD_UNKNOWN      1       /* will have to fetch sense */
247 #define STATUS_CMD_FAILED       2       /* transfer was ok, command failed */
248 #define STATUS_WIRE_FAILED      3       /* couldn't even get command across */
249
250 typedef void (*wire_reset_f)    (struct umass_softc *sc, int status);
251 typedef void (*wire_transfer_f) (struct umass_softc *sc, int lun,
252                                 void *cmd, int cmdlen, void *data, int datalen,
253                                 int dir, u_int timeout, transfer_cb_f cb, void *priv);
254 typedef void (*wire_state_f)    (usbd_xfer_handle xfer,
255                                 usbd_private_handle priv, usbd_status err);
256
257 typedef int (*command_transform_f)      (struct umass_softc *sc,
258                                 unsigned char *cmd, int cmdlen,
259                                 unsigned char **rcmd, int *rcmdlen);
260
261
262 struct umass_devdescr_t {
263         u_int32_t       vid;
264 #       define VID_WILDCARD     0xffffffff
265 #       define VID_EOT          0xfffffffe
266         u_int32_t       pid;
267 #       define PID_WILDCARD     0xffffffff
268 #       define PID_EOT          0xfffffffe
269         u_int32_t       rid;
270 #       define RID_WILDCARD     0xffffffff
271 #       define RID_EOT          0xfffffffe
272
273         /* wire and command protocol */
274         u_int16_t       proto;
275 #       define UMASS_PROTO_BBB          0x0001  /* USB wire protocol */
276 #       define UMASS_PROTO_CBI          0x0002
277 #       define UMASS_PROTO_CBI_I        0x0004
278 #       define UMASS_PROTO_WIRE         0x00ff  /* USB wire protocol mask */
279 #       define UMASS_PROTO_SCSI         0x0100  /* command protocol */
280 #       define UMASS_PROTO_ATAPI        0x0200
281 #       define UMASS_PROTO_UFI          0x0400
282 #       define UMASS_PROTO_RBC          0x0800
283 #       define UMASS_PROTO_COMMAND      0xff00  /* command protocol mask */
284
285         /* Device specific quirks */
286         u_int16_t       quirks;
287 #       define NO_QUIRKS                0x0000
288         /* The drive does not support Test Unit Ready. Convert to Start Unit
289          */
290 #       define NO_TEST_UNIT_READY       0x0001
291         /* The drive does not reset the Unit Attention state after REQUEST
292          * SENSE has been sent. The INQUIRY command does not reset the UA
293          * either, and so CAM runs in circles trying to retrieve the initial
294          * INQUIRY data.
295          */
296 #       define RS_NO_CLEAR_UA           0x0002
297         /* The drive does not support START STOP.  */
298 #       define NO_START_STOP            0x0004
299         /* Don't ask for full inquiry data (255b).  */
300 #       define FORCE_SHORT_INQUIRY      0x0008
301         /* Needs to be initialised the Shuttle way */
302 #       define SHUTTLE_INIT             0x0010
303         /* Drive needs to be switched to alternate iface 1 */
304 #       define ALT_IFACE_1              0x0020
305         /* Drive does not do 1Mb/s, but just floppy speeds (20kb/s) */
306 #       define FLOPPY_SPEED             0x0040
307         /* The device can't count and gets the residue of transfers wrong */
308 #       define IGNORE_RESIDUE           0x0080
309         /* No GetMaxLun call */
310 #       define NO_GETMAXLUN             0x0100
311         /* The device uses a weird CSWSIGNATURE. */
312 #       define WRONG_CSWSIG             0x0200
313         /* Device cannot handle INQUIRY so fake a generic response */
314 #       define NO_INQUIRY               0x0400
315         /* Device cannot handle INQUIRY EVPD, return CHECK CONDITION */
316 #       define NO_INQUIRY_EVPD          0x0800
317 };
318
319 Static struct umass_devdescr_t umass_devdescrs[] = {
320         { USB_VENDOR_ASAHIOPTICAL, PID_WILDCARD, RID_WILDCARD,
321           UMASS_PROTO_ATAPI | UMASS_PROTO_CBI_I,
322           RS_NO_CLEAR_UA
323         },
324         { USB_VENDOR_FUJIPHOTO, USB_PRODUCT_FUJIPHOTO_MASS0100, RID_WILDCARD,
325           UMASS_PROTO_ATAPI | UMASS_PROTO_CBI_I,
326           RS_NO_CLEAR_UA
327         },
328         { USB_VENDOR_GENESYS,  USB_PRODUCT_GENESYS_GL641USB2IDE, RID_WILDCARD,
329           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
330           FORCE_SHORT_INQUIRY | NO_START_STOP | IGNORE_RESIDUE
331         },
332         { USB_VENDOR_GENESYS,  USB_PRODUCT_GENESYS_GL641USB2IDE_2, RID_WILDCARD,
333           UMASS_PROTO_ATAPI | UMASS_PROTO_BBB,
334           FORCE_SHORT_INQUIRY | NO_START_STOP | IGNORE_RESIDUE
335         },
336         { USB_VENDOR_GENESYS,  USB_PRODUCT_GENESYS_GL641USB, RID_WILDCARD,
337           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
338           FORCE_SHORT_INQUIRY | NO_START_STOP | IGNORE_RESIDUE
339         },
340         { USB_VENDOR_HITACHI, USB_PRODUCT_HITACHI_DVDCAM_USB, RID_WILDCARD,
341           UMASS_PROTO_ATAPI | UMASS_PROTO_CBI_I,
342           NO_INQUIRY
343         },
344         { USB_VENDOR_HP, USB_PRODUCT_HP_CDW8200, RID_WILDCARD,
345           UMASS_PROTO_ATAPI | UMASS_PROTO_CBI_I,
346           NO_TEST_UNIT_READY | NO_START_STOP
347         },
348         { USB_VENDOR_INSYSTEM, USB_PRODUCT_INSYSTEM_USBCABLE, RID_WILDCARD,
349           UMASS_PROTO_ATAPI | UMASS_PROTO_CBI,
350           NO_TEST_UNIT_READY | NO_START_STOP | ALT_IFACE_1
351         },
352         { USB_VENDOR_IODATA, USB_PRODUCT_IODATA_IU_CD2, RID_WILDCARD,
353           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
354           NO_QUIRKS
355         },
356         { USB_VENDOR_IODATA, USB_PRODUCT_IODATA_DVR_UEH8, RID_WILDCARD,
357           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
358           NO_QUIRKS
359         },
360         { USB_VENDOR_IOMEGA, USB_PRODUCT_IOMEGA_ZIP100, RID_WILDCARD,
361           /* XXX This is not correct as there are Zip drives that use ATAPI.
362            */
363           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
364           NO_TEST_UNIT_READY
365         },
366         { USB_VENDOR_LOGITEC, USB_PRODUCT_LOGITEC_LDR_H443SU2, RID_WILDCARD,
367           UMASS_PROTO_SCSI,
368           NO_QUIRKS
369         },
370         { USB_VENDOR_LOGITEC, USB_PRODUCT_LOGITEC_LDR_H443U2, RID_WILDCARD,
371           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
372           NO_QUIRKS
373         },
374         { USB_VENDOR_MELCO,  USB_PRODUCT_MELCO_DUBPXXG, RID_WILDCARD,
375           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
376           FORCE_SHORT_INQUIRY | NO_START_STOP | IGNORE_RESIDUE
377         },
378         { USB_VENDOR_MICROTECH, USB_PRODUCT_MICROTECH_DPCM, RID_WILDCARD,
379           UMASS_PROTO_SCSI | UMASS_PROTO_CBI,
380           NO_TEST_UNIT_READY | NO_START_STOP
381         },
382         { USB_VENDOR_MSYSTEMS, USB_PRODUCT_MSYSTEMS_DISKONKEY, RID_WILDCARD,
383           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
384           IGNORE_RESIDUE | NO_GETMAXLUN | RS_NO_CLEAR_UA
385         },
386         { USB_VENDOR_MSYSTEMS, USB_PRODUCT_MSYSTEMS_DISKONKEY2, RID_WILDCARD,
387           UMASS_PROTO_ATAPI | UMASS_PROTO_BBB,
388           NO_QUIRKS
389         },
390         { USB_VENDOR_NEODIO, USB_PRODUCT_NEODIO_ND3260, RID_WILDCARD,
391           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
392           FORCE_SHORT_INQUIRY
393         },
394         { USB_VENDOR_OLYMPUS, USB_PRODUCT_OLYMPUS_C1, RID_WILDCARD,
395           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
396           WRONG_CSWSIG
397         },
398         { USB_VENDOR_ONSPEC, USB_PRODUCT_ONSPEC_UCF100, RID_WILDCARD,
399           UMASS_PROTO_ATAPI | UMASS_PROTO_BBB,
400           NO_INQUIRY | NO_GETMAXLUN
401         },
402         { USB_VENDOR_PANASONIC, USB_PRODUCT_PANASONIC_KXLCB20AN, RID_WILDCARD,
403           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
404           NO_QUIRKS
405         },
406         { USB_VENDOR_PANASONIC, USB_PRODUCT_PANASONIC_KXLCB35AN, RID_WILDCARD,
407           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
408           NO_QUIRKS
409         },
410         { USB_VENDOR_PLEXTOR, USB_PRODUCT_PLEXTOR_40_12_40U, RID_WILDCARD,
411           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
412           NO_TEST_UNIT_READY
413         },
414         { USB_VENDOR_PNY, USB_PRODUCT_PNY_ATTACHE, RID_WILDCARD,
415           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
416           IGNORE_RESIDUE
417         },
418         { USB_VENDOR_SANDISK, USB_PRODUCT_SANDISK_SDCZ2_256, RID_WILDCARD,
419           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
420           IGNORE_RESIDUE
421         },
422         { USB_VENDOR_SCANLOGIC, USB_PRODUCT_SCANLOGIC_SL11R, RID_WILDCARD,
423           UMASS_PROTO_ATAPI | UMASS_PROTO_BBB,
424           NO_INQUIRY
425         },
426         { USB_VENDOR_SHUTTLE, USB_PRODUCT_SHUTTLE_EUSB, RID_WILDCARD,
427           UMASS_PROTO_ATAPI | UMASS_PROTO_CBI_I,
428           NO_TEST_UNIT_READY | NO_START_STOP | SHUTTLE_INIT
429         },
430         { USB_VENDOR_SIGMATEL, USB_PRODUCT_SIGMATEL_I_BEAD100, RID_WILDCARD,
431           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
432           SHUTTLE_INIT
433         },
434         { USB_VENDOR_SIIG, USB_PRODUCT_SIIG_WINTERREADER, RID_WILDCARD,
435           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
436           IGNORE_RESIDUE
437         },
438         { USB_VENDOR_SONY, USB_PRODUCT_SONY_DSC, RID_WILDCARD,
439           UMASS_PROTO_RBC | UMASS_PROTO_CBI,
440           NO_QUIRKS
441         },
442         { USB_VENDOR_SONY, USB_PRODUCT_SONY_HANDYCAM, RID_WILDCARD,
443           UMASS_PROTO_RBC | UMASS_PROTO_CBI,
444           NO_QUIRKS
445         },
446         { USB_VENDOR_SONY, USB_PRODUCT_SONY_MSC, RID_WILDCARD,
447           UMASS_PROTO_RBC | UMASS_PROTO_CBI,
448           NO_QUIRKS
449         },
450         { USB_VENDOR_TREK, USB_PRODUCT_TREK_THUMBDRIVE_8MB, RID_WILDCARD,
451           UMASS_PROTO_ATAPI | UMASS_PROTO_BBB,
452           IGNORE_RESIDUE
453         },
454         { USB_VENDOR_TRUMPION, USB_PRODUCT_TRUMPION_C3310, RID_WILDCARD,
455           UMASS_PROTO_UFI | UMASS_PROTO_CBI,
456           NO_QUIRKS
457         },
458         { USB_VENDOR_TWINMOS, USB_PRODUCT_TWINMOS_MDIV, RID_WILDCARD,
459           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
460           NO_QUIRKS
461         },
462         { USB_VENDOR_WESTERN,  USB_PRODUCT_WESTERN_EXTHDD, RID_WILDCARD,
463           UMASS_PROTO_SCSI | UMASS_PROTO_BBB,
464           FORCE_SHORT_INQUIRY | NO_START_STOP | IGNORE_RESIDUE
465         },
466         { USB_VENDOR_YANO,  USB_PRODUCT_YANO_U640MO, RID_WILDCARD,
467           UMASS_PROTO_ATAPI | UMASS_PROTO_CBI_I,
468           FORCE_SHORT_INQUIRY
469         },
470         { VID_EOT, PID_EOT, RID_EOT, 0, 0 }
471 };
472
473
474 /* the per device structure */
475 struct umass_softc {
476         USBBASEDEVICE           sc_dev;         /* base device */
477         usbd_device_handle      sc_udev;        /* USB device */
478
479         struct cam_sim          *umass_sim;     /* SCSI Interface Module */
480
481         unsigned char           flags;          /* various device flags */
482 #       define UMASS_FLAGS_GONE         0x01    /* devices is no more */
483
484         u_int16_t               proto;          /* wire and cmd protocol */
485         u_int16_t               quirks;         /* they got it almost right */
486
487         usbd_interface_handle   iface;          /* Mass Storage interface */
488         int                     ifaceno;        /* MS iface number */
489
490         u_int8_t                bulkin;         /* bulk-in Endpoint Address */
491         u_int8_t                bulkout;        /* bulk-out Endpoint Address */
492         u_int8_t                intrin;         /* intr-in Endp. (CBI) */
493         usbd_pipe_handle        bulkin_pipe;
494         usbd_pipe_handle        bulkout_pipe;
495         usbd_pipe_handle        intrin_pipe;
496
497         /* Reset the device in a wire protocol specific way */
498         wire_reset_f            reset;
499
500         /* The start of a wire transfer. It prepares the whole transfer (cmd,
501          * data, and status stage) and initiates it. It is up to the state
502          * machine (below) to handle the various stages and errors in these
503          */
504         wire_transfer_f         transfer;
505
506         /* The state machine, handling the various states during a transfer */
507         wire_state_f            state;
508
509         /* The command transform function is used to conver the SCSI commands
510          * into their derivatives, like UFI, ATAPI, and friends.
511          */
512         command_transform_f     transform;      /* command transform */
513
514         /* Bulk specific variables for transfers in progress */
515         umass_bbb_cbw_t         cbw;    /* command block wrapper */
516         umass_bbb_csw_t         csw;    /* command status wrapper*/
517         /* CBI specific variables for transfers in progress */
518         umass_cbi_cbl_t         cbl;    /* command block */
519         umass_cbi_sbl_t         sbl;    /* status block */
520
521         /* generic variables for transfers in progress */
522         /* ctrl transfer requests */
523         usb_device_request_t    request;
524
525         /* xfer handles
526          * Most of our operations are initiated from interrupt context, so
527          * we need to avoid using the one that is in use. We want to avoid
528          * allocating them in the interrupt context as well.
529          */
530         /* indices into array below */
531 #       define XFER_BBB_CBW             0       /* Bulk-Only */
532 #       define XFER_BBB_DATA            1
533 #       define XFER_BBB_DCLEAR          2
534 #       define XFER_BBB_CSW1            3
535 #       define XFER_BBB_CSW2            4
536 #       define XFER_BBB_SCLEAR          5
537 #       define XFER_BBB_RESET1          6
538 #       define XFER_BBB_RESET2          7
539 #       define XFER_BBB_RESET3          8
540
541 #       define XFER_CBI_CB              0       /* CBI */
542 #       define XFER_CBI_DATA            1
543 #       define XFER_CBI_STATUS          2
544 #       define XFER_CBI_DCLEAR          3
545 #       define XFER_CBI_SCLEAR          4
546 #       define XFER_CBI_RESET1          5
547 #       define XFER_CBI_RESET2          6
548 #       define XFER_CBI_RESET3          7
549
550 #       define XFER_NR                  9       /* maximum number */
551
552         usbd_xfer_handle        transfer_xfer[XFER_NR]; /* for ctrl xfers */
553
554         int                     transfer_dir;           /* data direction */
555         void                    *transfer_data;         /* data buffer */
556         int                     transfer_datalen;       /* (maximum) length */
557         int                     transfer_actlen;        /* actual length */
558         transfer_cb_f           transfer_cb;            /* callback */
559         void                    *transfer_priv;         /* for callback */
560         int                     transfer_status;
561
562         int                     transfer_state;
563 #       define TSTATE_ATTACH                    0       /* in attach */
564 #       define TSTATE_IDLE                      1
565 #       define TSTATE_BBB_COMMAND               2       /* CBW transfer */
566 #       define TSTATE_BBB_DATA                  3       /* Data transfer */
567 #       define TSTATE_BBB_DCLEAR                4       /* clear endpt stall */
568 #       define TSTATE_BBB_STATUS1               5       /* clear endpt stall */
569 #       define TSTATE_BBB_SCLEAR                6       /* clear endpt stall */
570 #       define TSTATE_BBB_STATUS2               7       /* CSW transfer */
571 #       define TSTATE_BBB_RESET1                8       /* reset command */
572 #       define TSTATE_BBB_RESET2                9       /* in clear stall */
573 #       define TSTATE_BBB_RESET3                10      /* out clear stall */
574 #       define TSTATE_CBI_COMMAND               11      /* command transfer */
575 #       define TSTATE_CBI_DATA                  12      /* data transfer */
576 #       define TSTATE_CBI_STATUS                13      /* status transfer */
577 #       define TSTATE_CBI_DCLEAR                14      /* clear ep stall */
578 #       define TSTATE_CBI_SCLEAR                15      /* clear ep stall */
579 #       define TSTATE_CBI_RESET1                16      /* reset command */
580 #       define TSTATE_CBI_RESET2                17      /* in clear stall */
581 #       define TSTATE_CBI_RESET3                18      /* out clear stall */
582 #       define TSTATE_STATES                    19      /* # of states above */
583
584
585         /* SCSI/CAM specific variables */
586         unsigned char           cam_scsi_command[CAM_MAX_CDBLEN];
587         unsigned char           cam_scsi_command2[CAM_MAX_CDBLEN];
588         struct scsi_sense       cam_scsi_sense;
589         struct scsi_sense       cam_scsi_test_unit_ready;
590         usb_callout_t           cam_scsi_rescan_ch;
591
592         int                     timeout;                /* in msecs */
593
594         int                     maxlun;                 /* maximum LUN number */
595 };
596
597 #ifdef USB_DEBUG
598 char *states[TSTATE_STATES+1] = {
599         /* should be kept in sync with the list at transfer_state */
600         "Attach",
601         "Idle",
602         "BBB CBW",
603         "BBB Data",
604         "BBB Data bulk-in/-out clear stall",
605         "BBB CSW, 1st attempt",
606         "BBB CSW bulk-in clear stall",
607         "BBB CSW, 2nd attempt",
608         "BBB Reset",
609         "BBB bulk-in clear stall",
610         "BBB bulk-out clear stall",
611         "CBI Command",
612         "CBI Data",
613         "CBI Status",
614         "CBI Data bulk-in/-out clear stall",
615         "CBI Status intr-in clear stall",
616         "CBI Reset",
617         "CBI bulk-in clear stall",
618         "CBI bulk-out clear stall",
619         NULL
620 };
621 #endif
622
623 /* If device cannot return valid inquiry data, fake it */
624 Static uint8_t fake_inq_data[SHORT_INQUIRY_LENGTH] = {
625         0, /*removable*/ 0x80, SCSI_REV_2, SCSI_REV_2,
626         /*additional_length*/ 31, 0, 0, 0
627 };
628
629 /* USB device probe/attach/detach functions */
630 USB_DECLARE_DRIVER(umass);
631 Static int umass_match_proto    (struct umass_softc *sc,
632                                 usbd_interface_handle iface,
633                                 usbd_device_handle udev);
634
635 /* quirk functions */
636 Static void umass_init_shuttle  (struct umass_softc *sc);
637
638 /* generic transfer functions */
639 Static usbd_status umass_setup_transfer (struct umass_softc *sc,
640                                 usbd_pipe_handle pipe,
641                                 void *buffer, int buflen, int flags,
642                                 usbd_xfer_handle xfer);
643 Static usbd_status umass_setup_ctrl_transfer    (struct umass_softc *sc,
644                                 usbd_device_handle udev,
645                                 usb_device_request_t *req,
646                                 void *buffer, int buflen, int flags,
647                                 usbd_xfer_handle xfer);
648 Static void umass_clear_endpoint_stall  (struct umass_softc *sc,
649                                 u_int8_t endpt, usbd_pipe_handle pipe,
650                                 int state, usbd_xfer_handle xfer);
651 Static void umass_reset         (struct umass_softc *sc,
652                                 transfer_cb_f cb, void *priv);
653
654 /* Bulk-Only related functions */
655 Static void umass_bbb_reset     (struct umass_softc *sc, int status);
656 Static void umass_bbb_transfer  (struct umass_softc *sc, int lun,
657                                 void *cmd, int cmdlen,
658                                 void *data, int datalen, int dir, u_int timeout,
659                                 transfer_cb_f cb, void *priv);
660 Static void umass_bbb_state     (usbd_xfer_handle xfer,
661                                 usbd_private_handle priv,
662                                 usbd_status err);
663 Static int umass_bbb_get_max_lun
664                                 (struct umass_softc *sc);
665
666 /* CBI related functions */
667 Static int umass_cbi_adsc       (struct umass_softc *sc,
668                                 char *buffer, int buflen,
669                                 usbd_xfer_handle xfer);
670 Static void umass_cbi_reset     (struct umass_softc *sc, int status);
671 Static void umass_cbi_transfer  (struct umass_softc *sc, int lun,
672                                 void *cmd, int cmdlen,
673                                 void *data, int datalen, int dir, u_int timeout,
674                                 transfer_cb_f cb, void *priv);
675 Static void umass_cbi_state     (usbd_xfer_handle xfer,
676                                 usbd_private_handle priv, usbd_status err);
677
678 /* CAM related functions */
679 Static void umass_cam_action    (struct cam_sim *sim, union ccb *ccb);
680 Static void umass_cam_poll      (struct cam_sim *sim);
681
682 Static void umass_cam_cb        (struct umass_softc *sc, void *priv,
683                                 int residue, int status);
684 Static void umass_cam_sense_cb  (struct umass_softc *sc, void *priv,
685                                 int residue, int status);
686 Static void umass_cam_quirk_cb  (struct umass_softc *sc, void *priv,
687                                 int residue, int status);
688
689 Static void umass_cam_rescan_callback
690                                 (struct cam_periph *periph,union ccb *ccb);
691 Static void umass_cam_rescan    (void *addr);
692
693 Static int umass_cam_attach_sim (struct umass_softc *sc);
694 Static int umass_cam_attach     (struct umass_softc *sc);
695 Static int umass_cam_detach_sim (struct umass_softc *sc);
696
697
698 /* SCSI specific functions */
699 Static int umass_scsi_transform (struct umass_softc *sc,
700                                 unsigned char *cmd, int cmdlen,
701                                 unsigned char **rcmd, int *rcmdlen);
702
703 /* UFI specific functions */
704 #define UFI_COMMAND_LENGTH      12      /* UFI commands are always 12 bytes */
705 Static int umass_ufi_transform  (struct umass_softc *sc,
706                                 unsigned char *cmd, int cmdlen,
707                                 unsigned char **rcmd, int *rcmdlen);
708
709 /* ATAPI (8070i) specific functions */
710 #define ATAPI_COMMAND_LENGTH    12      /* ATAPI commands are always 12 bytes */
711 Static int umass_atapi_transform        (struct umass_softc *sc,
712                                 unsigned char *cmd, int cmdlen,
713                                 unsigned char **rcmd, int *rcmdlen);
714
715 /* RBC specific functions */
716 Static int umass_rbc_transform  (struct umass_softc *sc,
717                                 unsigned char *cmd, int cmdlen,
718                                 unsigned char **rcmd, int *rcmdlen);
719
720 #ifdef USB_DEBUG
721 /* General debugging functions */
722 Static void umass_bbb_dump_cbw  (struct umass_softc *sc, umass_bbb_cbw_t *cbw);
723 Static void umass_bbb_dump_csw  (struct umass_softc *sc, umass_bbb_csw_t *csw);
724 Static void umass_cbi_dump_cmd  (struct umass_softc *sc, void *cmd, int cmdlen);
725 Static void umass_dump_buffer   (struct umass_softc *sc, u_int8_t *buffer,
726                                 int buflen, int printlen);
727 #endif
728
729 #if defined(__FreeBSD__)
730 MODULE_DEPEND(umass, cam, 1,1,1);
731 #endif
732
733 /*
734  * USB device probe/attach/detach
735  */
736
737 /*
738  * Match the device we are seeing with the devices supported. Fill in the
739  * description in the softc accordingly. This function is called from both
740  * probe and attach.
741  */
742
743 Static int
744 umass_match_proto(struct umass_softc *sc, usbd_interface_handle iface,
745                   usbd_device_handle udev)
746 {
747         usb_device_descriptor_t *dd;
748         usb_interface_descriptor_t *id;
749         int i;
750         int found = 0;
751
752         sc->sc_udev = udev;
753         sc->proto = 0;
754         sc->quirks = 0;
755
756         dd = usbd_get_device_descriptor(udev);
757
758         /* An entry specifically for Y-E Data devices as they don't fit in the
759          * device description table.
760          */
761         if (UGETW(dd->idVendor) == USB_VENDOR_YEDATA
762             && UGETW(dd->idProduct) == USB_PRODUCT_YEDATA_FLASHBUSTERU) {
763
764                 /* Revisions < 1.28 do not handle the interrupt endpoint
765                  * very well.
766                  */
767                 if (UGETW(dd->bcdDevice) < 0x128) {
768                         sc->proto = UMASS_PROTO_UFI | UMASS_PROTO_CBI;
769                 } else {
770                         sc->proto = UMASS_PROTO_UFI | UMASS_PROTO_CBI_I;
771                 }
772
773                 /*
774                  * Revisions < 1.28 do not have the TEST UNIT READY command
775                  * Revisions == 1.28 have a broken TEST UNIT READY
776                  */
777                 if (UGETW(dd->bcdDevice) <= 0x128)
778                         sc->quirks |= NO_TEST_UNIT_READY;
779
780                 sc->quirks |= RS_NO_CLEAR_UA | FLOPPY_SPEED;
781                 return(UMATCH_VENDOR_PRODUCT);
782         }
783
784         /* Check the list of supported devices for a match. While looking,
785          * check for wildcarded and fully matched. First match wins.
786          */
787         for (i = 0; umass_devdescrs[i].vid != VID_EOT && !found; i++) {
788                 if (umass_devdescrs[i].vid == VID_WILDCARD &&
789                     umass_devdescrs[i].pid == PID_WILDCARD &&
790                     umass_devdescrs[i].rid == RID_WILDCARD) {
791                         printf("umass: ignoring invalid wildcard quirk\n");
792                         continue;
793                 }
794                 if ((umass_devdescrs[i].vid == UGETW(dd->idVendor) ||
795                      umass_devdescrs[i].vid == VID_WILDCARD)
796                  && (umass_devdescrs[i].pid == UGETW(dd->idProduct) ||
797                      umass_devdescrs[i].pid == PID_WILDCARD)) {
798                         if (umass_devdescrs[i].rid == RID_WILDCARD) {
799                                 sc->proto = umass_devdescrs[i].proto;
800                                 sc->quirks = umass_devdescrs[i].quirks;
801                                 return (UMATCH_VENDOR_PRODUCT);
802                         } else if (umass_devdescrs[i].rid ==
803                             UGETW(dd->bcdDevice)) {
804                                 sc->proto = umass_devdescrs[i].proto;
805                                 sc->quirks = umass_devdescrs[i].quirks;
806                                 return (UMATCH_VENDOR_PRODUCT_REV);
807                         } /* else RID does not match */
808                 }
809         }
810
811         /* Check for a standards compliant device */
812         id = usbd_get_interface_descriptor(iface);
813         if (id == NULL || id->bInterfaceClass != UICLASS_MASS)
814                 return(UMATCH_NONE);
815
816         switch (id->bInterfaceSubClass) {
817         case UISUBCLASS_SCSI:
818                 sc->proto |= UMASS_PROTO_SCSI;
819                 break;
820         case UISUBCLASS_UFI:
821                 sc->proto |= UMASS_PROTO_UFI;
822                 break;
823         case UISUBCLASS_RBC:
824                 sc->proto |= UMASS_PROTO_RBC;
825                 break;
826         case UISUBCLASS_SFF8020I:
827         case UISUBCLASS_SFF8070I:
828                 sc->proto |= UMASS_PROTO_ATAPI;
829                 break;
830         default:
831                 DPRINTF(UDMASS_GEN, ("%s: Unsupported command protocol %d\n",
832                         USBDEVNAME(sc->sc_dev), id->bInterfaceSubClass));
833                 return(UMATCH_NONE);
834         }
835
836         switch (id->bInterfaceProtocol) {
837         case UIPROTO_MASS_CBI:
838                 sc->proto |= UMASS_PROTO_CBI;
839                 break;
840         case UIPROTO_MASS_CBI_I:
841                 sc->proto |= UMASS_PROTO_CBI_I;
842                 break;
843         case UIPROTO_MASS_BBB_OLD:
844         case UIPROTO_MASS_BBB:
845                 sc->proto |= UMASS_PROTO_BBB;
846                 break;
847         default:
848                 DPRINTF(UDMASS_GEN, ("%s: Unsupported wire protocol %d\n",
849                         USBDEVNAME(sc->sc_dev), id->bInterfaceProtocol));
850                 return(UMATCH_NONE);
851         }
852
853         return(UMATCH_DEVCLASS_DEVSUBCLASS_DEVPROTO);
854 }
855
856 USB_MATCH(umass)
857 {
858         USB_MATCH_START(umass, uaa);
859         struct umass_softc *sc = device_get_softc(self);
860
861         USB_MATCH_SETUP;
862
863         if (uaa->iface == NULL)
864                 return(UMATCH_NONE);
865
866         return(umass_match_proto(sc, uaa->iface, uaa->device));
867 }
868
869 USB_ATTACH(umass)
870 {
871         USB_ATTACH_START(umass, sc, uaa);
872         usb_interface_descriptor_t *id;
873         usb_endpoint_descriptor_t *ed;
874         char devinfo[1024];
875         int i;
876         int err;
877
878         /*
879          * the softc struct is bzero-ed in device_set_driver. We can safely
880          * call umass_detach without specifically initialising the struct.
881          */
882
883         usbd_devinfo(uaa->device, 0, devinfo);
884         USB_ATTACH_SETUP;
885
886         sc->iface = uaa->iface;
887         sc->ifaceno = uaa->ifaceno;
888         usb_callout_init(sc->cam_scsi_rescan_ch);
889
890         /* initialise the proto and drive values in the umass_softc (again) */
891         (void) umass_match_proto(sc, sc->iface, uaa->device);
892
893         id = usbd_get_interface_descriptor(sc->iface);
894 #ifdef USB_DEBUG
895         printf("%s: ", USBDEVNAME(sc->sc_dev));
896         switch (sc->proto&UMASS_PROTO_COMMAND) {
897         case UMASS_PROTO_SCSI:
898                 printf("SCSI");
899                 break;
900         case UMASS_PROTO_ATAPI:
901                 printf("8070i (ATAPI)");
902                 break;
903         case UMASS_PROTO_UFI:
904                 printf("UFI");
905                 break;
906         case UMASS_PROTO_RBC:
907                 printf("RBC");
908                 break;
909         default:
910                 printf("(unknown 0x%02x)", sc->proto&UMASS_PROTO_COMMAND);
911                 break;
912         }
913         printf(" over ");
914         switch (sc->proto&UMASS_PROTO_WIRE) {
915         case UMASS_PROTO_BBB:
916                 printf("Bulk-Only");
917                 break;
918         case UMASS_PROTO_CBI:                   /* uses Comand/Bulk pipes */
919                 printf("CBI");
920                 break;
921         case UMASS_PROTO_CBI_I:         /* uses Comand/Bulk/Interrupt pipes */
922                 printf("CBI with CCI");
923 #ifndef CBI_I
924                 printf(" (using CBI)");
925 #endif
926                 break;
927         default:
928                 printf("(unknown 0x%02x)", sc->proto&UMASS_PROTO_WIRE);
929         }
930         printf("; quirks = 0x%04x\n", sc->quirks);
931 #endif
932
933 #ifndef CBI_I
934         if (sc->proto & UMASS_PROTO_CBI_I) {
935                 /* See beginning of file for comment on the use of CBI with CCI */
936                 sc->proto = (sc->proto & ~UMASS_PROTO_CBI_I) | UMASS_PROTO_CBI;
937         }
938 #endif
939
940         if (sc->quirks & ALT_IFACE_1) {
941                 err = usbd_set_interface(uaa->iface, 1);
942                 if (err) {
943                         DPRINTF(UDMASS_USB, ("%s: could not switch to "
944                                 "Alt Interface %d\n",
945                                 USBDEVNAME(sc->sc_dev), 1));
946                         umass_detach(self);
947                         USB_ATTACH_ERROR_RETURN;
948                 }
949         }
950
951         /*
952          * In addition to the Control endpoint the following endpoints
953          * are required:
954          * a) bulk-in endpoint.
955          * b) bulk-out endpoint.
956          * and for Control/Bulk/Interrupt with CCI (CBI_I)
957          * c) intr-in
958          *
959          * The endpoint addresses are not fixed, so we have to read them
960          * from the device descriptors of the current interface.
961          */
962         for (i = 0 ; i < id->bNumEndpoints ; i++) {
963                 ed = usbd_interface2endpoint_descriptor(sc->iface, i);
964                 if (!ed) {
965                         printf("%s: could not read endpoint descriptor\n",
966                                USBDEVNAME(sc->sc_dev));
967                         USB_ATTACH_ERROR_RETURN;
968                 }
969                 if (UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_IN
970                     && (ed->bmAttributes & UE_XFERTYPE) == UE_BULK) {
971                         sc->bulkin = ed->bEndpointAddress;
972                 } else if (UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_OUT
973                     && (ed->bmAttributes & UE_XFERTYPE) == UE_BULK) {
974                         sc->bulkout = ed->bEndpointAddress;
975                 } else if (sc->proto & UMASS_PROTO_CBI_I
976                     && UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_IN
977                     && (ed->bmAttributes & UE_XFERTYPE) == UE_INTERRUPT) {
978                         sc->intrin = ed->bEndpointAddress;
979 #ifdef USB_DEBUG
980                         if (UGETW(ed->wMaxPacketSize) > 2) {
981                                 DPRINTF(UDMASS_CBI, ("%s: intr size is %d\n",
982                                         USBDEVNAME(sc->sc_dev),
983                                         UGETW(ed->wMaxPacketSize)));
984                         }
985 #endif
986                 }
987         }
988
989         /* check whether we found all the endpoints we need */
990         if (!sc->bulkin || !sc->bulkout
991             || (sc->proto & UMASS_PROTO_CBI_I && !sc->intrin) ) {
992                 DPRINTF(UDMASS_USB, ("%s: endpoint not found %d/%d/%d\n",
993                         USBDEVNAME(sc->sc_dev),
994                         sc->bulkin, sc->bulkout, sc->intrin));
995                 umass_detach(self);
996                 USB_ATTACH_ERROR_RETURN;
997         }
998
999         /* Open the bulk-in and -out pipe */
1000         err = usbd_open_pipe(sc->iface, sc->bulkout,
1001                                 USBD_EXCLUSIVE_USE, &sc->bulkout_pipe);
1002         if (err) {
1003                 DPRINTF(UDMASS_USB, ("%s: cannot open %d-out pipe (bulk)\n",
1004                         USBDEVNAME(sc->sc_dev), sc->bulkout));
1005                 umass_detach(self);
1006                 USB_ATTACH_ERROR_RETURN;
1007         }
1008         err = usbd_open_pipe(sc->iface, sc->bulkin,
1009                                 USBD_EXCLUSIVE_USE, &sc->bulkin_pipe);
1010         if (err) {
1011                 DPRINTF(UDMASS_USB, ("%s: could not open %d-in pipe (bulk)\n",
1012                         USBDEVNAME(sc->sc_dev), sc->bulkin));
1013                 umass_detach(self);
1014                 USB_ATTACH_ERROR_RETURN;
1015         }
1016         /* Open the intr-in pipe if the protocol is CBI with CCI.
1017          * Note: early versions of the Zip drive do have an interrupt pipe, but
1018          * this pipe is unused.
1019          *
1020          * We do not open the interrupt pipe as an interrupt pipe, but as a
1021          * normal bulk endpoint. We send an IN transfer down the wire at the
1022          * appropriate time, because we know exactly when to expect data on
1023          * that endpoint. This saves bandwidth, but more important, makes the
1024          * code for handling the data on that endpoint simpler. No data
1025          * arriving concurrently.
1026          */
1027         if (sc->proto & UMASS_PROTO_CBI_I) {
1028                 err = usbd_open_pipe(sc->iface, sc->intrin,
1029                                 USBD_EXCLUSIVE_USE, &sc->intrin_pipe);
1030                 if (err) {
1031                         DPRINTF(UDMASS_USB, ("%s: couldn't open %d-in (intr)\n",
1032                                 USBDEVNAME(sc->sc_dev), sc->intrin));
1033                         umass_detach(self);
1034                         USB_ATTACH_ERROR_RETURN;
1035                 }
1036         }
1037
1038         /* initialisation of generic part */
1039         sc->transfer_state = TSTATE_ATTACH;
1040
1041         /* request a sufficient number of xfer handles */
1042         for (i = 0; i < XFER_NR; i++) {
1043                 sc->transfer_xfer[i] = usbd_alloc_xfer(uaa->device);
1044                 if (!sc->transfer_xfer[i]) {
1045                         DPRINTF(UDMASS_USB, ("%s: Out of memory\n",
1046                                 USBDEVNAME(sc->sc_dev)));
1047                         umass_detach(self);
1048                         USB_ATTACH_ERROR_RETURN;
1049                 }
1050         }
1051
1052         /* Initialise the wire protocol specific methods */
1053         if (sc->proto & UMASS_PROTO_BBB) {
1054                 sc->reset = umass_bbb_reset;
1055                 sc->transfer = umass_bbb_transfer;
1056                 sc->state = umass_bbb_state;
1057         } else if (sc->proto & (UMASS_PROTO_CBI|UMASS_PROTO_CBI_I)) {
1058                 sc->reset = umass_cbi_reset;
1059                 sc->transfer = umass_cbi_transfer;
1060                 sc->state = umass_cbi_state;
1061 #ifdef USB_DEBUG
1062         } else {
1063                 panic("%s:%d: Unknown proto 0x%02x",
1064                       __FILE__, __LINE__, sc->proto);
1065 #endif
1066         }
1067
1068         if (sc->proto & UMASS_PROTO_SCSI)
1069                 sc->transform = umass_scsi_transform;
1070         else if (sc->proto & UMASS_PROTO_UFI)
1071                 sc->transform = umass_ufi_transform;
1072         else if (sc->proto & UMASS_PROTO_ATAPI)
1073                 sc->transform = umass_atapi_transform;
1074         else if (sc->proto & UMASS_PROTO_RBC)
1075                 sc->transform = umass_rbc_transform;
1076 #ifdef USB_DEBUG
1077         else
1078                 panic("No transformation defined for command proto 0x%02x",
1079                       sc->proto & UMASS_PROTO_COMMAND);
1080 #endif
1081
1082         /* From here onwards the device can be used. */
1083
1084         if (sc->quirks & SHUTTLE_INIT)
1085                 umass_init_shuttle(sc);
1086
1087         /* Get the maximum LUN supported by the device.
1088          */
1089         if ((sc->proto & UMASS_PROTO_WIRE) == UMASS_PROTO_BBB)
1090                 sc->maxlun = umass_bbb_get_max_lun(sc);
1091         else
1092                 sc->maxlun = 0;
1093
1094         if ((sc->proto & UMASS_PROTO_SCSI) ||
1095             (sc->proto & UMASS_PROTO_ATAPI) ||
1096             (sc->proto & UMASS_PROTO_UFI) ||
1097             (sc->proto & UMASS_PROTO_RBC)) {
1098                 /* Prepare the SCSI command block */
1099                 sc->cam_scsi_sense.opcode = REQUEST_SENSE;
1100                 sc->cam_scsi_test_unit_ready.opcode = TEST_UNIT_READY;
1101
1102                 /* register the SIM */
1103                 err = umass_cam_attach_sim(sc);
1104                 if (err) {
1105                         umass_detach(self);
1106                         USB_ATTACH_ERROR_RETURN;
1107                 }
1108                 /* scan the new sim */
1109                 err = umass_cam_attach(sc);
1110                 if (err) {
1111                         umass_cam_detach_sim(sc);
1112                         umass_detach(self);
1113                         USB_ATTACH_ERROR_RETURN;
1114                 }
1115         } else {
1116                 panic("%s:%d: Unknown proto 0x%02x",
1117                       __FILE__, __LINE__, sc->proto);
1118         }
1119
1120         sc->transfer_state = TSTATE_IDLE;
1121         DPRINTF(UDMASS_GEN, ("%s: Attach finished\n", USBDEVNAME(sc->sc_dev)));
1122
1123         USB_ATTACH_SUCCESS_RETURN;
1124 }
1125
1126 USB_DETACH(umass)
1127 {
1128         USB_DETACH_START(umass, sc);
1129         int err = 0;
1130         int i;
1131
1132         DPRINTF(UDMASS_USB, ("%s: detached\n", USBDEVNAME(sc->sc_dev)));
1133
1134         sc->flags |= UMASS_FLAGS_GONE;
1135
1136         /* abort all the pipes in case there are transfers active. */
1137         usbd_abort_default_pipe(sc->sc_udev);
1138         if (sc->bulkout_pipe)
1139                 usbd_abort_pipe(sc->bulkout_pipe);
1140         if (sc->bulkin_pipe)
1141                 usbd_abort_pipe(sc->bulkin_pipe);
1142         if (sc->intrin_pipe)
1143                 usbd_abort_pipe(sc->intrin_pipe);
1144
1145         usb_uncallout_drain(sc->cam_scsi_rescan_ch, umass_cam_rescan, sc);
1146         if ((sc->proto & UMASS_PROTO_SCSI) ||
1147             (sc->proto & UMASS_PROTO_ATAPI) ||
1148             (sc->proto & UMASS_PROTO_UFI) ||
1149             (sc->proto & UMASS_PROTO_RBC))
1150                 /* detach the SCSI host controller (SIM) */
1151                 err = umass_cam_detach_sim(sc);
1152
1153         for (i = 0; i < XFER_NR; i++)
1154                 if (sc->transfer_xfer[i])
1155                         usbd_free_xfer(sc->transfer_xfer[i]);
1156
1157         /* remove all the pipes */
1158         if (sc->bulkout_pipe)
1159                 usbd_close_pipe(sc->bulkout_pipe);
1160         if (sc->bulkin_pipe)
1161                 usbd_close_pipe(sc->bulkin_pipe);
1162         if (sc->intrin_pipe)
1163                 usbd_close_pipe(sc->intrin_pipe);
1164
1165         return(err);
1166 }
1167
1168 Static void
1169 umass_init_shuttle(struct umass_softc *sc)
1170 {
1171         usb_device_request_t req;
1172         u_char status[2];
1173
1174         /* The Linux driver does this, but no one can tell us what the
1175          * command does.
1176          */
1177         req.bmRequestType = UT_READ_VENDOR_DEVICE;
1178         req.bRequest = 1;       /* XXX unknown command */
1179         USETW(req.wValue, 0);
1180         USETW(req.wIndex, sc->ifaceno);
1181         USETW(req.wLength, sizeof status);
1182         (void) usbd_do_request(sc->sc_udev, &req, &status);
1183
1184         DPRINTF(UDMASS_GEN, ("%s: Shuttle init returned 0x%02x%02x\n",
1185                 USBDEVNAME(sc->sc_dev), status[0], status[1]));
1186 }
1187
1188  /*
1189  * Generic functions to handle transfers
1190  */
1191
1192 Static usbd_status
1193 umass_setup_transfer(struct umass_softc *sc, usbd_pipe_handle pipe,
1194                         void *buffer, int buflen, int flags,
1195                         usbd_xfer_handle xfer)
1196 {
1197         usbd_status err;
1198
1199         /* Initialise a USB transfer and then schedule it */
1200
1201         (void) usbd_setup_xfer(xfer, pipe, (void *) sc, buffer, buflen, flags,
1202                         sc->timeout, sc->state);
1203
1204         err = usbd_transfer(xfer);
1205         if (err && err != USBD_IN_PROGRESS) {
1206                 DPRINTF(UDMASS_BBB, ("%s: failed to setup transfer, %s\n",
1207                         USBDEVNAME(sc->sc_dev), usbd_errstr(err)));
1208                 return(err);
1209         }
1210
1211         return (USBD_NORMAL_COMPLETION);
1212 }
1213
1214
1215 Static usbd_status
1216 umass_setup_ctrl_transfer(struct umass_softc *sc, usbd_device_handle udev,
1217          usb_device_request_t *req,
1218          void *buffer, int buflen, int flags,
1219          usbd_xfer_handle xfer)
1220 {
1221         usbd_status err;
1222
1223         /* Initialise a USB control transfer and then schedule it */
1224
1225         (void) usbd_setup_default_xfer(xfer, udev, (void *) sc,
1226                         sc->timeout, req, buffer, buflen, flags, sc->state);
1227
1228         err = usbd_transfer(xfer);
1229         if (err && err != USBD_IN_PROGRESS) {
1230                 DPRINTF(UDMASS_BBB, ("%s: failed to setup ctrl transfer, %s\n",
1231                          USBDEVNAME(sc->sc_dev), usbd_errstr(err)));
1232
1233                 /* do not reset, as this would make us loop */
1234                 return(err);
1235         }
1236
1237         return (USBD_NORMAL_COMPLETION);
1238 }
1239
1240 Static void
1241 umass_clear_endpoint_stall(struct umass_softc *sc,
1242                                 u_int8_t endpt, usbd_pipe_handle pipe,
1243                                 int state, usbd_xfer_handle xfer)
1244 {
1245         usbd_device_handle udev;
1246
1247         DPRINTF(UDMASS_BBB, ("%s: Clear endpoint 0x%02x stall\n",
1248                 USBDEVNAME(sc->sc_dev), endpt));
1249
1250         usbd_interface2device_handle(sc->iface, &udev);
1251
1252         sc->transfer_state = state;
1253
1254         usbd_clear_endpoint_toggle(pipe);
1255
1256         sc->request.bmRequestType = UT_WRITE_ENDPOINT;
1257         sc->request.bRequest = UR_CLEAR_FEATURE;
1258         USETW(sc->request.wValue, UF_ENDPOINT_HALT);
1259         USETW(sc->request.wIndex, endpt);
1260         USETW(sc->request.wLength, 0);
1261         umass_setup_ctrl_transfer(sc, udev, &sc->request, NULL, 0, 0, xfer);
1262 }
1263
1264 Static void
1265 umass_reset(struct umass_softc *sc, transfer_cb_f cb, void *priv)
1266 {
1267         sc->transfer_cb = cb;
1268         sc->transfer_priv = priv;
1269
1270         /* The reset is a forced reset, so no error (yet) */
1271         sc->reset(sc, STATUS_CMD_OK);
1272 }
1273
1274 /*
1275  * Bulk protocol specific functions
1276  */
1277
1278 Static void
1279 umass_bbb_reset(struct umass_softc *sc, int status)
1280 {
1281         usbd_device_handle udev;
1282
1283         KASSERT(sc->proto & UMASS_PROTO_BBB,
1284                 ("%s: umass_bbb_reset: wrong sc->proto 0x%02x\n",
1285                         USBDEVNAME(sc->sc_dev), sc->proto));
1286
1287         /*
1288          * Reset recovery (5.3.4 in Universal Serial Bus Mass Storage Class)
1289          *
1290          * For Reset Recovery the host shall issue in the following order:
1291          * a) a Bulk-Only Mass Storage Reset
1292          * b) a Clear Feature HALT to the Bulk-In endpoint
1293          * c) a Clear Feature HALT to the Bulk-Out endpoint
1294          *
1295          * This is done in 3 steps, states:
1296          * TSTATE_BBB_RESET1
1297          * TSTATE_BBB_RESET2
1298          * TSTATE_BBB_RESET3
1299          *
1300          * If the reset doesn't succeed, the device should be port reset.
1301          */
1302
1303         DPRINTF(UDMASS_BBB, ("%s: Bulk Reset\n",
1304                 USBDEVNAME(sc->sc_dev)));
1305
1306         sc->transfer_state = TSTATE_BBB_RESET1;
1307         sc->transfer_status = status;
1308
1309         usbd_interface2device_handle(sc->iface, &udev);
1310
1311         /* reset is a class specific interface write */
1312         sc->request.bmRequestType = UT_WRITE_CLASS_INTERFACE;
1313         sc->request.bRequest = UR_BBB_RESET;
1314         USETW(sc->request.wValue, 0);
1315         USETW(sc->request.wIndex, sc->ifaceno);
1316         USETW(sc->request.wLength, 0);
1317         umass_setup_ctrl_transfer(sc, udev, &sc->request, NULL, 0, 0,
1318                                   sc->transfer_xfer[XFER_BBB_RESET1]);
1319 }
1320
1321 Static void
1322 umass_bbb_transfer(struct umass_softc *sc, int lun, void *cmd, int cmdlen,
1323                     void *data, int datalen, int dir, u_int timeout,
1324                     transfer_cb_f cb, void *priv)
1325 {
1326         KASSERT(sc->proto & UMASS_PROTO_BBB,
1327                 ("%s: umass_bbb_transfer: wrong sc->proto 0x%02x\n",
1328                         USBDEVNAME(sc->sc_dev), sc->proto));
1329
1330         /* Be a little generous. */
1331         sc->timeout = timeout + UMASS_TIMEOUT;
1332
1333         /*
1334          * Do a Bulk-Only transfer with cmdlen bytes from cmd, possibly
1335          * a data phase of datalen bytes from/to the device and finally a
1336          * csw read phase.
1337          * If the data direction was inbound a maximum of datalen bytes
1338          * is stored in the buffer pointed to by data.
1339          *
1340          * umass_bbb_transfer initialises the transfer and lets the state
1341          * machine in umass_bbb_state handle the completion. It uses the
1342          * following states:
1343          * TSTATE_BBB_COMMAND
1344          *   -> TSTATE_BBB_DATA
1345          *   -> TSTATE_BBB_STATUS
1346          *   -> TSTATE_BBB_STATUS2
1347          *   -> TSTATE_BBB_IDLE
1348          *
1349          * An error in any of those states will invoke
1350          * umass_bbb_reset.
1351          */
1352
1353         /* check the given arguments */
1354         KASSERT(datalen == 0 || data != NULL,
1355                 ("%s: datalen > 0, but no buffer",USBDEVNAME(sc->sc_dev)));
1356         KASSERT(cmdlen <= CBWCDBLENGTH,
1357                 ("%s: cmdlen exceeds CDB length in CBW (%d > %d)",
1358                         USBDEVNAME(sc->sc_dev), cmdlen, CBWCDBLENGTH));
1359         KASSERT(dir == DIR_NONE || datalen > 0,
1360                 ("%s: datalen == 0 while direction is not NONE\n",
1361                         USBDEVNAME(sc->sc_dev)));
1362         KASSERT(datalen == 0 || dir != DIR_NONE,
1363                 ("%s: direction is NONE while datalen is not zero\n",
1364                         USBDEVNAME(sc->sc_dev)));
1365         KASSERT(sizeof(umass_bbb_cbw_t) == UMASS_BBB_CBW_SIZE,
1366                 ("%s: CBW struct does not have the right size (%ld vs. %d)\n",
1367                         USBDEVNAME(sc->sc_dev),
1368                         (long)sizeof(umass_bbb_cbw_t), UMASS_BBB_CBW_SIZE));
1369         KASSERT(sizeof(umass_bbb_csw_t) == UMASS_BBB_CSW_SIZE,
1370                 ("%s: CSW struct does not have the right size (%ld vs. %d)\n",
1371                         USBDEVNAME(sc->sc_dev),
1372                         (long)sizeof(umass_bbb_csw_t), UMASS_BBB_CSW_SIZE));
1373
1374         /*
1375          * Determine the direction of the data transfer and the length.
1376          *
1377          * dCBWDataTransferLength (datalen) :
1378          *   This field indicates the number of bytes of data that the host
1379          *   intends to transfer on the IN or OUT Bulk endpoint(as indicated by
1380          *   the Direction bit) during the execution of this command. If this
1381          *   field is set to 0, the device will expect that no data will be
1382          *   transferred IN or OUT during this command, regardless of the value
1383          *   of the Direction bit defined in dCBWFlags.
1384          *
1385          * dCBWFlags (dir) :
1386          *   The bits of the Flags field are defined as follows:
1387          *     Bits 0-6  reserved
1388          *     Bit  7    Direction - this bit shall be ignored if the
1389          *                           dCBWDataTransferLength field is zero.
1390          *               0 = data Out from host to device
1391          *               1 = data In from device to host
1392          */
1393
1394         /* Fill in the Command Block Wrapper
1395          * We fill in all the fields, so there is no need to bzero it first.
1396          */
1397         USETDW(sc->cbw.dCBWSignature, CBWSIGNATURE);
1398         /* We don't care about the initial value, as long as the values are unique */
1399         USETDW(sc->cbw.dCBWTag, UGETDW(sc->cbw.dCBWTag) + 1);
1400         USETDW(sc->cbw.dCBWDataTransferLength, datalen);
1401         /* DIR_NONE is treated as DIR_OUT (0x00) */
1402         sc->cbw.bCBWFlags = (dir == DIR_IN? CBWFLAGS_IN:CBWFLAGS_OUT);
1403         sc->cbw.bCBWLUN = lun;
1404         sc->cbw.bCDBLength = cmdlen;
1405         bcopy(cmd, sc->cbw.CBWCDB, cmdlen);
1406
1407         DIF(UDMASS_BBB, umass_bbb_dump_cbw(sc, &sc->cbw));
1408
1409         /* store the details for the data transfer phase */
1410         sc->transfer_dir = dir;
1411         sc->transfer_data = data;
1412         sc->transfer_datalen = datalen;
1413         sc->transfer_actlen = 0;
1414         sc->transfer_cb = cb;
1415         sc->transfer_priv = priv;
1416         sc->transfer_status = STATUS_CMD_OK;
1417
1418         /* move from idle to the command state */
1419         sc->transfer_state = TSTATE_BBB_COMMAND;
1420
1421         /* Send the CBW from host to device via bulk-out endpoint. */
1422         if (umass_setup_transfer(sc, sc->bulkout_pipe,
1423                         &sc->cbw, UMASS_BBB_CBW_SIZE, 0,
1424                         sc->transfer_xfer[XFER_BBB_CBW])) {
1425                 umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1426         }
1427 }
1428
1429
1430 Static void
1431 umass_bbb_state(usbd_xfer_handle xfer, usbd_private_handle priv,
1432                 usbd_status err)
1433 {
1434         struct umass_softc *sc = (struct umass_softc *) priv;
1435         usbd_xfer_handle next_xfer;
1436
1437         KASSERT(sc->proto & UMASS_PROTO_BBB,
1438                 ("%s: umass_bbb_state: wrong sc->proto 0x%02x\n",
1439                         USBDEVNAME(sc->sc_dev), sc->proto));
1440
1441         /*
1442          * State handling for BBB transfers.
1443          *
1444          * The subroutine is rather long. It steps through the states given in
1445          * Annex A of the Bulk-Only specification.
1446          * Each state first does the error handling of the previous transfer
1447          * and then prepares the next transfer.
1448          * Each transfer is done asynchronously so after the request/transfer
1449          * has been submitted you will find a 'return;'.
1450          */
1451
1452         DPRINTF(UDMASS_BBB, ("%s: Handling BBB state %d (%s), xfer=%p, %s\n",
1453                 USBDEVNAME(sc->sc_dev), sc->transfer_state,
1454                 states[sc->transfer_state], xfer, usbd_errstr(err)));
1455
1456         /* Give up if the device has detached. */
1457         if (sc->flags & UMASS_FLAGS_GONE) {
1458                 sc->transfer_state = TSTATE_IDLE;
1459                 sc->transfer_cb(sc, sc->transfer_priv, sc->transfer_datalen,
1460                     STATUS_CMD_FAILED);
1461                 return;
1462         }
1463
1464         switch (sc->transfer_state) {
1465
1466         /***** Bulk Transfer *****/
1467         case TSTATE_BBB_COMMAND:
1468                 /* Command transport phase, error handling */
1469                 if (err) {
1470                         DPRINTF(UDMASS_BBB, ("%s: failed to send CBW\n",
1471                                 USBDEVNAME(sc->sc_dev)));
1472                         /* If the device detects that the CBW is invalid, then
1473                          * the device may STALL both bulk endpoints and require
1474                          * a Bulk-Reset
1475                          */
1476                         umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1477                         return;
1478                 }
1479
1480                 /* Data transport phase, setup transfer */
1481                 sc->transfer_state = TSTATE_BBB_DATA;
1482                 if (sc->transfer_dir == DIR_IN) {
1483                         if (umass_setup_transfer(sc, sc->bulkin_pipe,
1484                                         sc->transfer_data, sc->transfer_datalen,
1485                                         USBD_SHORT_XFER_OK,
1486                                         sc->transfer_xfer[XFER_BBB_DATA]))
1487                                 umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1488
1489                         return;
1490                 } else if (sc->transfer_dir == DIR_OUT) {
1491                         if (umass_setup_transfer(sc, sc->bulkout_pipe,
1492                                         sc->transfer_data, sc->transfer_datalen,
1493                                         0,      /* fixed length transfer */
1494                                         sc->transfer_xfer[XFER_BBB_DATA]))
1495                                 umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1496
1497                         return;
1498                 } else {
1499                         DPRINTF(UDMASS_BBB, ("%s: no data phase\n",
1500                                 USBDEVNAME(sc->sc_dev)));
1501                 }
1502
1503                 /* FALLTHROUGH if no data phase, err == 0 */
1504         case TSTATE_BBB_DATA:
1505                 /* Command transport phase, error handling (ignored if no data
1506                  * phase (fallthrough from previous state)) */
1507                 if (sc->transfer_dir != DIR_NONE) {
1508                         /* retrieve the length of the transfer that was done */
1509                         usbd_get_xfer_status(xfer, NULL, NULL,
1510                                                 &sc->transfer_actlen, NULL);
1511
1512                         if (err) {
1513                                 DPRINTF(UDMASS_BBB, ("%s: Data-%s %db failed, "
1514                                         "%s\n", USBDEVNAME(sc->sc_dev),
1515                                         (sc->transfer_dir == DIR_IN?"in":"out"),
1516                                         sc->transfer_datalen,usbd_errstr(err)));
1517
1518                                 if (err == USBD_STALLED) {
1519                                         umass_clear_endpoint_stall(sc,
1520                                           (sc->transfer_dir == DIR_IN?
1521                                             sc->bulkin:sc->bulkout),
1522                                           (sc->transfer_dir == DIR_IN?
1523                                             sc->bulkin_pipe:sc->bulkout_pipe),
1524                                           TSTATE_BBB_DCLEAR,
1525                                           sc->transfer_xfer[XFER_BBB_DCLEAR]);
1526                                         return;
1527                                 } else {
1528                                         /* Unless the error is a pipe stall the
1529                                          * error is fatal.
1530                                          */
1531                                         umass_bbb_reset(sc,STATUS_WIRE_FAILED);
1532                                         return;
1533                                 }
1534                         }
1535                 }
1536
1537                 DIF(UDMASS_BBB, if (sc->transfer_dir == DIR_IN)
1538                                         umass_dump_buffer(sc, sc->transfer_data,
1539                                                 sc->transfer_datalen, 48));
1540
1541
1542
1543                 /* FALLTHROUGH, err == 0 (no data phase or successfull) */
1544         case TSTATE_BBB_DCLEAR: /* stall clear after data phase */
1545         case TSTATE_BBB_SCLEAR: /* stall clear after status phase */
1546                 /* Reading of CSW after bulk stall condition in data phase
1547                  * (TSTATE_BBB_DATA2) or bulk-in stall condition after
1548                  * reading CSW (TSTATE_BBB_SCLEAR).
1549                  * In the case of no data phase or successfull data phase,
1550                  * err == 0 and the following if block is passed.
1551                  */
1552                 if (err) {      /* should not occur */
1553                         /* try the transfer below, even if clear stall failed */
1554                         DPRINTF(UDMASS_BBB, ("%s: bulk-%s stall clear failed"
1555                                 ", %s\n", USBDEVNAME(sc->sc_dev),
1556                                 (sc->transfer_dir == DIR_IN? "in":"out"),
1557                                 usbd_errstr(err)));
1558                         umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1559                         return;
1560                 }
1561
1562                 /* Status transport phase, setup transfer */
1563                 if (sc->transfer_state == TSTATE_BBB_COMMAND ||
1564                     sc->transfer_state == TSTATE_BBB_DATA ||
1565                     sc->transfer_state == TSTATE_BBB_DCLEAR) {
1566                         /* After no data phase, successfull data phase and
1567                          * after clearing bulk-in/-out stall condition
1568                          */
1569                         sc->transfer_state = TSTATE_BBB_STATUS1;
1570                         next_xfer = sc->transfer_xfer[XFER_BBB_CSW1];
1571                 } else {
1572                         /* After first attempt of fetching CSW */
1573                         sc->transfer_state = TSTATE_BBB_STATUS2;
1574                         next_xfer = sc->transfer_xfer[XFER_BBB_CSW2];
1575                 }
1576
1577                 /* Read the Command Status Wrapper via bulk-in endpoint. */
1578                 if (umass_setup_transfer(sc, sc->bulkin_pipe,
1579                                 &sc->csw, UMASS_BBB_CSW_SIZE, 0,
1580                                 next_xfer)) {
1581                         umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1582                         return;
1583                 }
1584
1585                 return;
1586         case TSTATE_BBB_STATUS1:        /* first attempt */
1587         case TSTATE_BBB_STATUS2:        /* second attempt */
1588                 /* Status transfer, error handling */
1589                 if (err) {
1590                         DPRINTF(UDMASS_BBB, ("%s: Failed to read CSW, %s%s\n",
1591                                 USBDEVNAME(sc->sc_dev), usbd_errstr(err),
1592                                 (sc->transfer_state == TSTATE_BBB_STATUS1?
1593                                         ", retrying":"")));
1594
1595                         /* If this was the first attempt at fetching the CSW
1596                          * retry it, otherwise fail.
1597                          */
1598                         if (sc->transfer_state == TSTATE_BBB_STATUS1) {
1599                                 umass_clear_endpoint_stall(sc,
1600                                             sc->bulkin, sc->bulkin_pipe,
1601                                             TSTATE_BBB_SCLEAR,
1602                                             sc->transfer_xfer[XFER_BBB_SCLEAR]);
1603                                 return;
1604                         } else {
1605                                 umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1606                                 return;
1607                         }
1608                 }
1609
1610                 DIF(UDMASS_BBB, umass_bbb_dump_csw(sc, &sc->csw));
1611
1612                 /* Translate weird command-status signatures. */
1613                 if ((sc->quirks & WRONG_CSWSIG) &&
1614                     UGETDW(sc->csw.dCSWSignature) == CSWSIGNATURE_OLYMPUS_C1)
1615                         USETDW(sc->csw.dCSWSignature, CSWSIGNATURE);
1616
1617                 int Residue;
1618                 Residue = UGETDW(sc->csw.dCSWDataResidue);
1619                 if (Residue == 0 &&
1620                     sc->transfer_datalen - sc->transfer_actlen != 0)
1621                         Residue = sc->transfer_datalen - sc->transfer_actlen;
1622
1623                 /* Check CSW and handle any error */
1624                 if (UGETDW(sc->csw.dCSWSignature) != CSWSIGNATURE) {
1625                         /* Invalid CSW: Wrong signature or wrong tag might
1626                          * indicate that the device is confused -> reset it.
1627                          */
1628                         printf("%s: Invalid CSW: sig 0x%08x should be 0x%08x\n",
1629                                 USBDEVNAME(sc->sc_dev),
1630                                 UGETDW(sc->csw.dCSWSignature),
1631                                 CSWSIGNATURE);
1632
1633                         umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1634                         return;
1635                 } else if (UGETDW(sc->csw.dCSWTag)
1636                                 != UGETDW(sc->cbw.dCBWTag)) {
1637                         printf("%s: Invalid CSW: tag %d should be %d\n",
1638                                 USBDEVNAME(sc->sc_dev),
1639                                 UGETDW(sc->csw.dCSWTag),
1640                                 UGETDW(sc->cbw.dCBWTag));
1641
1642                         umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1643                         return;
1644
1645                 /* CSW is valid here */
1646                 } else if (sc->csw.bCSWStatus > CSWSTATUS_PHASE) {
1647                         printf("%s: Invalid CSW: status %d > %d\n",
1648                                 USBDEVNAME(sc->sc_dev),
1649                                 sc->csw.bCSWStatus,
1650                                 CSWSTATUS_PHASE);
1651
1652                         umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1653                         return;
1654                 } else if (sc->csw.bCSWStatus == CSWSTATUS_PHASE) {
1655                         printf("%s: Phase Error, residue = %d\n",
1656                                 USBDEVNAME(sc->sc_dev), Residue);
1657
1658                         umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1659                         return;
1660
1661                 } else if (sc->transfer_actlen > sc->transfer_datalen) {
1662                         /* Buffer overrun! Don't let this go by unnoticed */
1663                         panic("%s: transferred %db instead of %db",
1664                                 USBDEVNAME(sc->sc_dev),
1665                                 sc->transfer_actlen, sc->transfer_datalen);
1666
1667                 } else if (sc->csw.bCSWStatus == CSWSTATUS_FAILED) {
1668                         DPRINTF(UDMASS_BBB, ("%s: Command Failed, res = %d\n",
1669                                 USBDEVNAME(sc->sc_dev), Residue));
1670
1671                         /* SCSI command failed but transfer was succesful */
1672                         sc->transfer_state = TSTATE_IDLE;
1673                         sc->transfer_cb(sc, sc->transfer_priv, Residue,
1674                                         STATUS_CMD_FAILED);
1675                         return;
1676
1677                 } else {        /* success */
1678                         sc->transfer_state = TSTATE_IDLE;
1679                         sc->transfer_cb(sc, sc->transfer_priv, Residue,
1680                                         STATUS_CMD_OK);
1681
1682                         return;
1683                 }
1684
1685         /***** Bulk Reset *****/
1686         case TSTATE_BBB_RESET1:
1687                 if (err)
1688                         printf("%s: BBB reset failed, %s\n",
1689                                 USBDEVNAME(sc->sc_dev), usbd_errstr(err));
1690
1691                 umass_clear_endpoint_stall(sc,
1692                         sc->bulkin, sc->bulkin_pipe, TSTATE_BBB_RESET2,
1693                         sc->transfer_xfer[XFER_BBB_RESET2]);
1694
1695                 return;
1696         case TSTATE_BBB_RESET2:
1697                 if (err)        /* should not occur */
1698                         printf("%s: BBB bulk-in clear stall failed, %s\n",
1699                                USBDEVNAME(sc->sc_dev), usbd_errstr(err));
1700                         /* no error recovery, otherwise we end up in a loop */
1701
1702                 umass_clear_endpoint_stall(sc,
1703                         sc->bulkout, sc->bulkout_pipe, TSTATE_BBB_RESET3,
1704                         sc->transfer_xfer[XFER_BBB_RESET3]);
1705
1706                 return;
1707         case TSTATE_BBB_RESET3:
1708                 if (err)        /* should not occur */
1709                         printf("%s: BBB bulk-out clear stall failed, %s\n",
1710                                USBDEVNAME(sc->sc_dev), usbd_errstr(err));
1711                         /* no error recovery, otherwise we end up in a loop */
1712
1713                 sc->transfer_state = TSTATE_IDLE;
1714                 if (sc->transfer_priv) {
1715                         sc->transfer_cb(sc, sc->transfer_priv,
1716                                         sc->transfer_datalen,
1717                                         sc->transfer_status);
1718                 }
1719
1720                 return;
1721
1722         /***** Default *****/
1723         default:
1724                 panic("%s: Unknown state %d",
1725                       USBDEVNAME(sc->sc_dev), sc->transfer_state);
1726         }
1727 }
1728
1729 Static int
1730 umass_bbb_get_max_lun(struct umass_softc *sc)
1731 {
1732         usbd_device_handle udev;
1733         usb_device_request_t req;
1734         usbd_status err;
1735         usb_interface_descriptor_t *id;
1736         int maxlun = 0;
1737         u_int8_t buf = 0;
1738
1739         usbd_interface2device_handle(sc->iface, &udev);
1740         id = usbd_get_interface_descriptor(sc->iface);
1741
1742         /* The Get Max Lun command is a class-specific request. */
1743         req.bmRequestType = UT_READ_CLASS_INTERFACE;
1744         req.bRequest = UR_BBB_GET_MAX_LUN;
1745         USETW(req.wValue, 0);
1746         USETW(req.wIndex, id->bInterfaceNumber);
1747         USETW(req.wLength, 1);
1748
1749         err = usbd_do_request(udev, &req, &buf);
1750         switch (err) {
1751         case USBD_NORMAL_COMPLETION:
1752                 maxlun = buf;
1753                 DPRINTF(UDMASS_BBB, ("%s: Max Lun is %d\n",
1754                     USBDEVNAME(sc->sc_dev), maxlun));
1755                 break;
1756         case USBD_STALLED:
1757         case USBD_SHORT_XFER:
1758         default:
1759                 /* Device doesn't support Get Max Lun request. */
1760                 printf("%s: Get Max Lun not supported (%s)\n",
1761                     USBDEVNAME(sc->sc_dev), usbd_errstr(err));
1762                 /* XXX Should we port_reset the device? */
1763                 break;
1764         }
1765
1766         return(maxlun);
1767 }
1768
1769 /*
1770  * Command/Bulk/Interrupt (CBI) specific functions
1771  */
1772
1773 Static int
1774 umass_cbi_adsc(struct umass_softc *sc, char *buffer, int buflen,
1775                usbd_xfer_handle xfer)
1776 {
1777         usbd_device_handle udev;
1778
1779         KASSERT(sc->proto & (UMASS_PROTO_CBI|UMASS_PROTO_CBI_I),
1780                 ("%s: umass_cbi_adsc: wrong sc->proto 0x%02x\n",
1781                         USBDEVNAME(sc->sc_dev), sc->proto));
1782
1783         usbd_interface2device_handle(sc->iface, &udev);
1784
1785         sc->request.bmRequestType = UT_WRITE_CLASS_INTERFACE;
1786         sc->request.bRequest = UR_CBI_ADSC;
1787         USETW(sc->request.wValue, 0);
1788         USETW(sc->request.wIndex, sc->ifaceno);
1789         USETW(sc->request.wLength, buflen);
1790         return umass_setup_ctrl_transfer(sc, udev, &sc->request, buffer,
1791                                          buflen, 0, xfer);
1792 }
1793
1794
1795 Static void
1796 umass_cbi_reset(struct umass_softc *sc, int status)
1797 {
1798         int i;
1799 #       define SEND_DIAGNOSTIC_CMDLEN   12
1800
1801         KASSERT(sc->proto & (UMASS_PROTO_CBI|UMASS_PROTO_CBI_I),
1802                 ("%s: umass_cbi_reset: wrong sc->proto 0x%02x\n",
1803                         USBDEVNAME(sc->sc_dev), sc->proto));
1804
1805         /*
1806          * Command Block Reset Protocol
1807          *
1808          * First send a reset request to the device. Then clear
1809          * any possibly stalled bulk endpoints.
1810          *
1811          * This is done in 3 steps, states:
1812          * TSTATE_CBI_RESET1
1813          * TSTATE_CBI_RESET2
1814          * TSTATE_CBI_RESET3
1815          *
1816          * If the reset doesn't succeed, the device should be port reset.
1817          */
1818
1819         DPRINTF(UDMASS_CBI, ("%s: CBI Reset\n",
1820                 USBDEVNAME(sc->sc_dev)));
1821
1822         KASSERT(sizeof(sc->cbl) >= SEND_DIAGNOSTIC_CMDLEN,
1823                 ("%s: CBL struct is too small (%ld < %d)\n",
1824                         USBDEVNAME(sc->sc_dev),
1825                         (long)sizeof(sc->cbl), SEND_DIAGNOSTIC_CMDLEN));
1826
1827         sc->transfer_state = TSTATE_CBI_RESET1;
1828         sc->transfer_status = status;
1829
1830         /* The 0x1d code is the SEND DIAGNOSTIC command. To distinguish between
1831          * the two the last 10 bytes of the cbl is filled with 0xff (section
1832          * 2.2 of the CBI spec).
1833          */
1834         sc->cbl[0] = 0x1d;      /* Command Block Reset */
1835         sc->cbl[1] = 0x04;
1836         for (i = 2; i < SEND_DIAGNOSTIC_CMDLEN; i++)
1837                 sc->cbl[i] = 0xff;
1838
1839         umass_cbi_adsc(sc, sc->cbl, SEND_DIAGNOSTIC_CMDLEN,
1840                        sc->transfer_xfer[XFER_CBI_RESET1]);
1841         /* XXX if the command fails we should reset the port on the hub */
1842 }
1843
1844 Static void
1845 umass_cbi_transfer(struct umass_softc *sc, int lun,
1846                 void *cmd, int cmdlen, void *data, int datalen, int dir,
1847                 u_int timeout, transfer_cb_f cb, void *priv)
1848 {
1849         KASSERT(sc->proto & (UMASS_PROTO_CBI|UMASS_PROTO_CBI_I),
1850                 ("%s: umass_cbi_transfer: wrong sc->proto 0x%02x\n",
1851                         USBDEVNAME(sc->sc_dev), sc->proto));
1852
1853         /* Be a little generous. */
1854         sc->timeout = timeout + UMASS_TIMEOUT;
1855
1856         /*
1857          * Do a CBI transfer with cmdlen bytes from cmd, possibly
1858          * a data phase of datalen bytes from/to the device and finally a
1859          * csw read phase.
1860          * If the data direction was inbound a maximum of datalen bytes
1861          * is stored in the buffer pointed to by data.
1862          *
1863          * umass_cbi_transfer initialises the transfer and lets the state
1864          * machine in umass_cbi_state handle the completion. It uses the
1865          * following states:
1866          * TSTATE_CBI_COMMAND
1867          *   -> XXX fill in
1868          *
1869          * An error in any of those states will invoke
1870          * umass_cbi_reset.
1871          */
1872
1873         /* check the given arguments */
1874         KASSERT(datalen == 0 || data != NULL,
1875                 ("%s: datalen > 0, but no buffer",USBDEVNAME(sc->sc_dev)));
1876         KASSERT(datalen == 0 || dir != DIR_NONE,
1877                 ("%s: direction is NONE while datalen is not zero\n",
1878                         USBDEVNAME(sc->sc_dev)));
1879
1880         /* store the details for the data transfer phase */
1881         sc->transfer_dir = dir;
1882         sc->transfer_data = data;
1883         sc->transfer_datalen = datalen;
1884         sc->transfer_actlen = 0;
1885         sc->transfer_cb = cb;
1886         sc->transfer_priv = priv;
1887         sc->transfer_status = STATUS_CMD_OK;
1888
1889         /* move from idle to the command state */
1890         sc->transfer_state = TSTATE_CBI_COMMAND;
1891
1892         DIF(UDMASS_CBI, umass_cbi_dump_cmd(sc, cmd, cmdlen));
1893
1894         /* Send the Command Block from host to device via control endpoint. */
1895         if (umass_cbi_adsc(sc, cmd, cmdlen, sc->transfer_xfer[XFER_CBI_CB]))
1896                 umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1897 }
1898
1899 Static void
1900 umass_cbi_state(usbd_xfer_handle xfer, usbd_private_handle priv,
1901                 usbd_status err)
1902 {
1903         struct umass_softc *sc = (struct umass_softc *) priv;
1904
1905         KASSERT(sc->proto & (UMASS_PROTO_CBI|UMASS_PROTO_CBI_I),
1906                 ("%s: umass_cbi_state: wrong sc->proto 0x%02x\n",
1907                         USBDEVNAME(sc->sc_dev), sc->proto));
1908
1909         /*
1910          * State handling for CBI transfers.
1911          */
1912
1913         DPRINTF(UDMASS_CBI, ("%s: Handling CBI state %d (%s), xfer=%p, %s\n",
1914                 USBDEVNAME(sc->sc_dev), sc->transfer_state,
1915                 states[sc->transfer_state], xfer, usbd_errstr(err)));
1916
1917         /* Give up if the device has detached. */
1918         if (sc->flags & UMASS_FLAGS_GONE) {
1919                 sc->transfer_state = TSTATE_IDLE;
1920                 sc->transfer_cb(sc, sc->transfer_priv, sc->transfer_datalen,
1921                     STATUS_CMD_FAILED);
1922                 return;
1923         }
1924
1925         switch (sc->transfer_state) {
1926
1927         /***** CBI Transfer *****/
1928         case TSTATE_CBI_COMMAND:
1929                 if (err == USBD_STALLED) {
1930                         DPRINTF(UDMASS_CBI, ("%s: Command Transport failed\n",
1931                                 USBDEVNAME(sc->sc_dev)));
1932                         /* Status transport by control pipe (section 2.3.2.1).
1933                          * The command contained in the command block failed.
1934                          *
1935                          * The control pipe has already been unstalled by the
1936                          * USB stack.
1937                          * Section 2.4.3.1.1 states that the bulk in endpoints
1938                          * should not be stalled at this point.
1939                          */
1940
1941                         sc->transfer_state = TSTATE_IDLE;
1942                         sc->transfer_cb(sc, sc->transfer_priv,
1943                                         sc->transfer_datalen,
1944                                         STATUS_CMD_FAILED);
1945
1946                         return;
1947                 } else if (err) {
1948                         DPRINTF(UDMASS_CBI, ("%s: failed to send ADSC\n",
1949                                 USBDEVNAME(sc->sc_dev)));
1950                         umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1951
1952                         return;
1953                 }
1954
1955                 sc->transfer_state = TSTATE_CBI_DATA;
1956                 if (sc->transfer_dir == DIR_IN) {
1957                         if (umass_setup_transfer(sc, sc->bulkin_pipe,
1958                                         sc->transfer_data, sc->transfer_datalen,
1959                                         USBD_SHORT_XFER_OK,
1960                                         sc->transfer_xfer[XFER_CBI_DATA]))
1961                                 umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1962
1963                 } else if (sc->transfer_dir == DIR_OUT) {
1964                         if (umass_setup_transfer(sc, sc->bulkout_pipe,
1965                                         sc->transfer_data, sc->transfer_datalen,
1966                                         0,      /* fixed length transfer */
1967                                         sc->transfer_xfer[XFER_CBI_DATA]))
1968                                 umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1969
1970                 } else if (sc->proto & UMASS_PROTO_CBI_I) {
1971                         DPRINTF(UDMASS_CBI, ("%s: no data phase\n",
1972                                 USBDEVNAME(sc->sc_dev)));
1973                         sc->transfer_state = TSTATE_CBI_STATUS;
1974                         if (umass_setup_transfer(sc, sc->intrin_pipe,
1975                                         &sc->sbl, sizeof(sc->sbl),
1976                                         0,      /* fixed length transfer */
1977                                         sc->transfer_xfer[XFER_CBI_STATUS])){
1978                                 umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1979                         }
1980                 } else {
1981                         DPRINTF(UDMASS_CBI, ("%s: no data phase\n",
1982                                 USBDEVNAME(sc->sc_dev)));
1983                         /* No command completion interrupt. Request
1984                          * sense data.
1985                          */
1986                         sc->transfer_state = TSTATE_IDLE;
1987                         sc->transfer_cb(sc, sc->transfer_priv,
1988                                0, STATUS_CMD_UNKNOWN);
1989                 }
1990
1991                 return;
1992
1993         case TSTATE_CBI_DATA:
1994                 /* retrieve the length of the transfer that was done */
1995                 usbd_get_xfer_status(xfer,NULL,NULL,&sc->transfer_actlen,NULL);
1996
1997                 if (err) {
1998                         DPRINTF(UDMASS_CBI, ("%s: Data-%s %db failed, "
1999                                 "%s\n", USBDEVNAME(sc->sc_dev),
2000                                 (sc->transfer_dir == DIR_IN?"in":"out"),
2001                                 sc->transfer_datalen,usbd_errstr(err)));
2002
2003                         if (err == USBD_STALLED) {
2004                                 umass_clear_endpoint_stall(sc,
2005                                         sc->bulkin, sc->bulkin_pipe,
2006                                         TSTATE_CBI_DCLEAR,
2007                                         sc->transfer_xfer[XFER_CBI_DCLEAR]);
2008                         } else {
2009                                 umass_cbi_reset(sc, STATUS_WIRE_FAILED);
2010                         }
2011                         return;
2012                 }
2013
2014                 DIF(UDMASS_CBI, if (sc->transfer_dir == DIR_IN)
2015                                         umass_dump_buffer(sc, sc->transfer_data,
2016                                                 sc->transfer_actlen, 48));
2017
2018                 if (sc->proto & UMASS_PROTO_CBI_I) {
2019                         sc->transfer_state = TSTATE_CBI_STATUS;
2020                         if (umass_setup_transfer(sc, sc->intrin_pipe,
2021                                     &sc->sbl, sizeof(sc->sbl),
2022                                     0,  /* fixed length transfer */
2023                                     sc->transfer_xfer[XFER_CBI_STATUS])){
2024                                 umass_cbi_reset(sc, STATUS_WIRE_FAILED);
2025                         }
2026                 } else {
2027                         /* No command completion interrupt. Request
2028                          * sense to get status of command.
2029                          */
2030                         sc->transfer_state = TSTATE_IDLE;
2031                         sc->transfer_cb(sc, sc->transfer_priv,
2032                                 sc->transfer_datalen - sc->transfer_actlen,
2033                                 STATUS_CMD_UNKNOWN);
2034                 }
2035                 return;
2036
2037         case TSTATE_CBI_STATUS:
2038                 if (err) {
2039                         DPRINTF(UDMASS_CBI, ("%s: Status Transport failed\n",
2040                                 USBDEVNAME(sc->sc_dev)));
2041                         /* Status transport by interrupt pipe (section 2.3.2.2).
2042                          */
2043
2044                         if (err == USBD_STALLED) {
2045                                 umass_clear_endpoint_stall(sc,
2046                                         sc->intrin, sc->intrin_pipe,
2047                                         TSTATE_CBI_SCLEAR,
2048                                         sc->transfer_xfer[XFER_CBI_SCLEAR]);
2049                         } else {
2050                                 umass_cbi_reset(sc, STATUS_WIRE_FAILED);
2051                         }
2052                         return;
2053                 }
2054
2055                 /* Dissect the information in the buffer */
2056
2057                 if (sc->proto & UMASS_PROTO_UFI) {
2058                         int status;
2059
2060                         /* Section 3.4.3.1.3 specifies that the UFI command
2061                          * protocol returns an ASC and ASCQ in the interrupt
2062                          * data block.
2063                          */
2064
2065                         DPRINTF(UDMASS_CBI, ("%s: UFI CCI, ASC = 0x%02x, "
2066                                 "ASCQ = 0x%02x\n",
2067                                 USBDEVNAME(sc->sc_dev),
2068                                 sc->sbl.ufi.asc, sc->sbl.ufi.ascq));
2069
2070                         if (sc->sbl.ufi.asc == 0 && sc->sbl.ufi.ascq == 0)
2071                                 status = STATUS_CMD_OK;
2072                         else
2073                                 status = STATUS_CMD_FAILED;
2074
2075                         sc->transfer_state = TSTATE_IDLE;
2076                         sc->transfer_cb(sc, sc->transfer_priv,
2077                                 sc->transfer_datalen - sc->transfer_actlen,
2078                                 status);
2079                 } else {
2080                         /* Command Interrupt Data Block */
2081                         DPRINTF(UDMASS_CBI, ("%s: type=0x%02x, value=0x%02x\n",
2082                                 USBDEVNAME(sc->sc_dev),
2083                                 sc->sbl.common.type, sc->sbl.common.value));
2084
2085                         if (sc->sbl.common.type == IDB_TYPE_CCI) {
2086                                 int err;
2087
2088                                 if ((sc->sbl.common.value&IDB_VALUE_STATUS_MASK)
2089                                                         == IDB_VALUE_PASS) {
2090                                         err = STATUS_CMD_OK;
2091                                 } else if ((sc->sbl.common.value & IDB_VALUE_STATUS_MASK)
2092                                                         == IDB_VALUE_FAIL ||
2093                                            (sc->sbl.common.value & IDB_VALUE_STATUS_MASK)
2094                                                 == IDB_VALUE_PERSISTENT) {
2095                                         err = STATUS_CMD_FAILED;
2096                                 } else {
2097                                         err = STATUS_WIRE_FAILED;
2098                                 }
2099
2100                                 sc->transfer_state = TSTATE_IDLE;
2101                                 sc->transfer_cb(sc, sc->transfer_priv,
2102                                        sc->transfer_datalen-sc->transfer_actlen,
2103                                        err);
2104                         }
2105                 }
2106                 return;
2107
2108         case TSTATE_CBI_DCLEAR:
2109                 if (err) {      /* should not occur */
2110                         printf("%s: CBI bulk-in/out stall clear failed, %s\n",
2111                                USBDEVNAME(sc->sc_dev), usbd_errstr(err));
2112                         umass_cbi_reset(sc, STATUS_WIRE_FAILED);
2113                 }
2114
2115                 sc->transfer_state = TSTATE_IDLE;
2116                 sc->transfer_cb(sc, sc->transfer_priv,
2117                                 sc->transfer_datalen,
2118                                 STATUS_CMD_FAILED);
2119                 return;
2120
2121         case TSTATE_CBI_SCLEAR:
2122                 if (err)        /* should not occur */
2123                         printf("%s: CBI intr-in stall clear failed, %s\n",
2124                                USBDEVNAME(sc->sc_dev), usbd_errstr(err));
2125
2126                 /* Something really bad is going on. Reset the device */
2127                 umass_cbi_reset(sc, STATUS_CMD_FAILED);
2128                 return;
2129
2130         /***** CBI Reset *****/
2131         case TSTATE_CBI_RESET1:
2132                 if (err)
2133                         printf("%s: CBI reset failed, %s\n",
2134                                 USBDEVNAME(sc->sc_dev), usbd_errstr(err));
2135
2136                 umass_clear_endpoint_stall(sc,
2137                         sc->bulkin, sc->bulkin_pipe, TSTATE_CBI_RESET2,
2138                         sc->transfer_xfer[XFER_CBI_RESET2]);
2139
2140                 return;
2141         case TSTATE_CBI_RESET2:
2142                 if (err)        /* should not occur */
2143                         printf("%s: CBI bulk-in stall clear failed, %s\n",
2144                                USBDEVNAME(sc->sc_dev), usbd_errstr(err));
2145                         /* no error recovery, otherwise we end up in a loop */
2146
2147                 umass_clear_endpoint_stall(sc,
2148                         sc->bulkout, sc->bulkout_pipe, TSTATE_CBI_RESET3,
2149                         sc->transfer_xfer[XFER_CBI_RESET3]);
2150
2151                 return;
2152         case TSTATE_CBI_RESET3:
2153                 if (err)        /* should not occur */
2154                         printf("%s: CBI bulk-out stall clear failed, %s\n",
2155                                USBDEVNAME(sc->sc_dev), usbd_errstr(err));
2156                         /* no error recovery, otherwise we end up in a loop */
2157
2158                 sc->transfer_state = TSTATE_IDLE;
2159                 if (sc->transfer_priv) {
2160                         sc->transfer_cb(sc, sc->transfer_priv,
2161                                         sc->transfer_datalen,
2162                                         sc->transfer_status);
2163                 }
2164
2165                 return;
2166
2167
2168         /***** Default *****/
2169         default:
2170                 panic("%s: Unknown state %d",
2171                       USBDEVNAME(sc->sc_dev), sc->transfer_state);
2172         }
2173 }
2174
2175
2176
2177
2178 /*
2179  * CAM specific functions (used by SCSI, UFI, 8070i (ATAPI))
2180  */
2181
2182 Static int
2183 umass_cam_attach_sim(struct umass_softc *sc)
2184 {
2185         struct cam_devq *devq;          /* Per device Queue */
2186
2187         /* A HBA is attached to the CAM layer.
2188          *
2189          * The CAM layer will then after a while start probing for
2190          * devices on the bus. The number of SIMs is limited to one.
2191          */
2192
2193         devq = cam_simq_alloc(1 /*maximum openings*/);
2194         if (devq == NULL)
2195                 return(ENOMEM);
2196
2197         sc->umass_sim = cam_sim_alloc(umass_cam_action, umass_cam_poll,
2198                                 DEVNAME_SIM,
2199                                 sc /*priv*/,
2200                                 USBDEVUNIT(sc->sc_dev) /*unit number*/,
2201                                 1 /*maximum device openings*/,
2202                                 0 /*maximum tagged device openings*/,
2203                                 devq);
2204         if (sc->umass_sim == NULL) {
2205                 cam_simq_free(devq);
2206                 return(ENOMEM);
2207         }
2208
2209         if(xpt_bus_register(sc->umass_sim, USBDEVUNIT(sc->sc_dev)) !=
2210             CAM_SUCCESS)
2211                 return(ENOMEM);
2212
2213         return(0);
2214 }
2215
2216 Static void
2217 umass_cam_rescan_callback(struct cam_periph *periph, union ccb *ccb)
2218 {
2219 #ifdef USB_DEBUG
2220         if (ccb->ccb_h.status != CAM_REQ_CMP) {
2221                 DPRINTF(UDMASS_SCSI, ("%s:%d Rescan failed, 0x%04x\n",
2222                         periph->periph_name, periph->unit_number,
2223                         ccb->ccb_h.status));
2224         } else {
2225                 DPRINTF(UDMASS_SCSI, ("%s%d: Rescan succeeded\n",
2226                         periph->periph_name, periph->unit_number));
2227         }
2228 #endif
2229
2230         xpt_free_path(ccb->ccb_h.path);
2231         free(ccb, M_USBDEV);
2232 }
2233
2234 Static void
2235 umass_cam_rescan(void *addr)
2236 {
2237         struct umass_softc *sc = (struct umass_softc *) addr;
2238         struct cam_path *path;
2239         union ccb *ccb;
2240
2241         DPRINTF(UDMASS_SCSI, ("scbus%d: scanning for %s:%d:%d:%d\n",
2242                 cam_sim_path(sc->umass_sim),
2243                 USBDEVNAME(sc->sc_dev), cam_sim_path(sc->umass_sim),
2244                 USBDEVUNIT(sc->sc_dev), CAM_LUN_WILDCARD));
2245
2246         ccb = malloc(sizeof(union ccb), M_USBDEV, M_NOWAIT | M_ZERO);
2247         if (ccb == NULL)
2248                 return;
2249         if (xpt_create_path(&path, xpt_periph, cam_sim_path(sc->umass_sim),
2250                             CAM_TARGET_WILDCARD, CAM_LUN_WILDCARD)
2251             != CAM_REQ_CMP) {
2252                 free(ccb, M_USBDEV);
2253                 return;
2254         }
2255
2256         xpt_setup_ccb(&ccb->ccb_h, path, 5/*priority (low)*/);
2257         ccb->ccb_h.func_code = XPT_SCAN_BUS;
2258         ccb->ccb_h.cbfcnp = umass_cam_rescan_callback;
2259         ccb->crcn.flags = CAM_FLAG_NONE;
2260         xpt_action(ccb);
2261
2262         /* The scan is in progress now. */
2263 }
2264
2265 Static int
2266 umass_cam_attach(struct umass_softc *sc)
2267 {
2268 #ifndef USB_DEBUG
2269         if (bootverbose)
2270 #endif
2271                 printf("%s:%d:%d:%d: Attached to scbus%d\n",
2272                         USBDEVNAME(sc->sc_dev), cam_sim_path(sc->umass_sim),
2273                         USBDEVUNIT(sc->sc_dev), CAM_LUN_WILDCARD,
2274                         cam_sim_path(sc->umass_sim));
2275
2276         if (!cold) {
2277                 /* Notify CAM of the new device after a short delay. Any
2278                  * failure is benign, as the user can still do it by hand
2279                  * (camcontrol rescan <busno>). Only do this if we are not
2280                  * booting, because CAM does a scan after booting has
2281                  * completed, when interrupts have been enabled.
2282                  */
2283
2284                 usb_callout(sc->cam_scsi_rescan_ch, MS_TO_TICKS(200),
2285                     umass_cam_rescan, sc);
2286         }
2287
2288         return(0);      /* always succesfull */
2289 }
2290
2291 /* umass_cam_detach
2292  *      detach from the CAM layer
2293  */
2294
2295 Static int
2296 umass_cam_detach_sim(struct umass_softc *sc)
2297 {
2298         if (sc->umass_sim) {
2299                 if (xpt_bus_deregister(cam_sim_path(sc->umass_sim)))
2300                         cam_sim_free(sc->umass_sim, /*free_devq*/TRUE);
2301                 else
2302                         return(EBUSY);
2303
2304                 sc->umass_sim = NULL;
2305         }
2306
2307         return(0);
2308 }
2309
2310 /* umass_cam_action
2311  *      CAM requests for action come through here
2312  */
2313
2314 Static void
2315 umass_cam_action(struct cam_sim *sim, union ccb *ccb)
2316 {
2317         struct umass_softc *sc = (struct umass_softc *)sim->softc;
2318
2319         /* The softc is still there, but marked as going away. umass_cam_detach
2320          * has not yet notified CAM of the lost device however.
2321          */
2322         if (sc && (sc->flags & UMASS_FLAGS_GONE)) {
2323                 DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:func_code 0x%04x: "
2324                         "Invalid target (gone)\n",
2325                         USBDEVNAME(sc->sc_dev), cam_sim_path(sc->umass_sim),
2326                         ccb->ccb_h.target_id, ccb->ccb_h.target_lun,
2327                         ccb->ccb_h.func_code));
2328                 ccb->ccb_h.status = CAM_TID_INVALID;
2329                 xpt_done(ccb);
2330                 return;
2331         }
2332
2333         /* Verify, depending on the operation to perform, that we either got a
2334          * valid sc, because an existing target was referenced, or otherwise
2335          * the SIM is addressed.
2336          *
2337          * This avoids bombing out at a printf and does give the CAM layer some
2338          * sensible feedback on errors.
2339          */
2340         switch (ccb->ccb_h.func_code) {
2341         case XPT_SCSI_IO:
2342         case XPT_RESET_DEV:
2343         case XPT_GET_TRAN_SETTINGS:
2344         case XPT_SET_TRAN_SETTINGS:
2345         case XPT_CALC_GEOMETRY:
2346                 /* the opcodes requiring a target. These should never occur. */
2347                 if (sc == NULL) {
2348                         printf("%s:%d:%d:%d:func_code 0x%04x: "
2349                                 "Invalid target (target needed)\n",
2350                                 DEVNAME_SIM, cam_sim_path(sc->umass_sim),
2351                                 ccb->ccb_h.target_id, ccb->ccb_h.target_lun,
2352                                 ccb->ccb_h.func_code);
2353
2354                         ccb->ccb_h.status = CAM_TID_INVALID;
2355                         xpt_done(ccb);
2356                         return;
2357                 }
2358                 break;
2359         case XPT_PATH_INQ:
2360         case XPT_NOOP:
2361                 /* The opcodes sometimes aimed at a target (sc is valid),
2362                  * sometimes aimed at the SIM (sc is invalid and target is
2363                  * CAM_TARGET_WILDCARD)
2364                  */
2365                 if (sc == NULL && ccb->ccb_h.target_id != CAM_TARGET_WILDCARD) {
2366                         DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:func_code 0x%04x: "
2367                                 "Invalid target (no wildcard)\n",
2368                                 DEVNAME_SIM, cam_sim_path(sc->umass_sim),
2369                                 ccb->ccb_h.target_id, ccb->ccb_h.target_lun,
2370                                 ccb->ccb_h.func_code));
2371
2372                         ccb->ccb_h.status = CAM_TID_INVALID;
2373                         xpt_done(ccb);
2374                         return;
2375                 }
2376                 break;
2377         default:
2378                 /* XXX Hm, we should check the input parameters */
2379                 break;
2380         }
2381
2382         /* Perform the requested action */
2383         switch (ccb->ccb_h.func_code) {
2384         case XPT_SCSI_IO:
2385         {
2386                 struct ccb_scsiio *csio = &ccb->csio;   /* deref union */
2387                 int dir;
2388                 unsigned char *cmd;
2389                 int cmdlen;
2390                 unsigned char *rcmd;
2391                 int rcmdlen;
2392
2393                 DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:XPT_SCSI_IO: "
2394                         "cmd: 0x%02x, flags: 0x%02x, "
2395                         "%db cmd/%db data/%db sense\n",
2396                         USBDEVNAME(sc->sc_dev), cam_sim_path(sc->umass_sim),
2397                         ccb->ccb_h.target_id, ccb->ccb_h.target_lun,
2398                         csio->cdb_io.cdb_bytes[0],
2399                         ccb->ccb_h.flags & CAM_DIR_MASK,
2400                         csio->cdb_len, csio->dxfer_len,
2401                         csio->sense_len));
2402
2403                 /* clear the end of the buffer to make sure we don't send out
2404                  * garbage.
2405                  */
2406                 DIF(UDMASS_SCSI, if ((ccb->ccb_h.flags & CAM_DIR_MASK)
2407                                      == CAM_DIR_OUT)
2408                                         umass_dump_buffer(sc, csio->data_ptr,
2409                                                 csio->dxfer_len, 48));
2410
2411                 if (sc->transfer_state != TSTATE_IDLE) {
2412                         DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:XPT_SCSI_IO: "
2413                                 "I/O in progress, deferring (state %d, %s)\n",
2414                                 USBDEVNAME(sc->sc_dev), cam_sim_path(sc->umass_sim),
2415                                 ccb->ccb_h.target_id, ccb->ccb_h.target_lun,
2416                                 sc->transfer_state,states[sc->transfer_state]));
2417                         ccb->ccb_h.status = CAM_SCSI_BUSY;
2418                         xpt_done(ccb);
2419                         return;
2420                 }
2421
2422                 switch(ccb->ccb_h.flags&CAM_DIR_MASK) {
2423                 case CAM_DIR_IN:
2424                         dir = DIR_IN;
2425                         break;
2426                 case CAM_DIR_OUT:
2427                         dir = DIR_OUT;
2428                         break;
2429                 default:
2430                         dir = DIR_NONE;
2431                 }
2432
2433                 ccb->ccb_h.status = CAM_REQ_INPROG | CAM_SIM_QUEUED;
2434
2435
2436                 if (csio->ccb_h.flags & CAM_CDB_POINTER) {
2437                         cmd = (unsigned char *) csio->cdb_io.cdb_ptr;
2438                 } else {
2439                         cmd = (unsigned char *) &csio->cdb_io.cdb_bytes;
2440                 }
2441                 cmdlen = csio->cdb_len;
2442                 rcmd = (unsigned char *) &sc->cam_scsi_command;
2443                 rcmdlen = sizeof(sc->cam_scsi_command);
2444
2445                 /* sc->transform will convert the command to the command
2446                  * (format) needed by the specific command set and return
2447                  * the converted command in a buffer pointed to be rcmd.
2448                  * We pass in a buffer, but if the command does not
2449                  * have to be transformed it returns a ptr to the original
2450                  * buffer (see umass_scsi_transform).
2451                  */
2452
2453                 if (sc->transform(sc, cmd, cmdlen, &rcmd, &rcmdlen)) {
2454                         /*
2455                          * Handle EVPD inquiry for broken devices first
2456                          * NO_INQUIRY also implies NO_INQUIRY_EVPD
2457                          */
2458                         if ((sc->quirks & (NO_INQUIRY_EVPD | NO_INQUIRY)) &&
2459                             rcmd[0] == INQUIRY && (rcmd[1] & SI_EVPD)) {
2460                                 struct scsi_sense_data *sense;
2461
2462                                 sense = &ccb->csio.sense_data;
2463                                 bzero(sense, sizeof(*sense));
2464                                 sense->error_code = SSD_CURRENT_ERROR;
2465                                 sense->flags = SSD_KEY_ILLEGAL_REQUEST;
2466                                 sense->add_sense_code = 0x24;
2467                                 sense->extra_len = 10;
2468                                 ccb->csio.scsi_status = SCSI_STATUS_CHECK_COND;
2469                                 ccb->ccb_h.status = CAM_SCSI_STATUS_ERROR |
2470                                     CAM_AUTOSNS_VALID;
2471                                 xpt_done(ccb);
2472                                 return;
2473                         }
2474                         /* Return fake inquiry data for broken devices */
2475                         if ((sc->quirks & NO_INQUIRY) && rcmd[0] == INQUIRY) {
2476                                 struct ccb_scsiio *csio = &ccb->csio;
2477
2478                                 memcpy(csio->data_ptr, &fake_inq_data,
2479                                     sizeof(fake_inq_data));
2480                                 csio->scsi_status = SCSI_STATUS_OK;
2481                                 ccb->ccb_h.status = CAM_REQ_CMP;
2482                                 xpt_done(ccb);
2483                                 return;
2484                         }
2485                         if ((sc->quirks & FORCE_SHORT_INQUIRY) &&
2486                             rcmd[0] == INQUIRY) {
2487                                 csio->dxfer_len = SHORT_INQUIRY_LENGTH;
2488                         }
2489                         sc->transfer(sc, ccb->ccb_h.target_lun, rcmd, rcmdlen,
2490                                      csio->data_ptr,
2491                                      csio->dxfer_len, dir, ccb->ccb_h.timeout,
2492                                      umass_cam_cb, (void *) ccb);
2493                 } else {
2494                         ccb->ccb_h.status = CAM_REQ_INVALID;
2495                         xpt_done(ccb);
2496                 }
2497
2498                 break;
2499         }
2500         case XPT_PATH_INQ:
2501         {
2502                 struct ccb_pathinq *cpi = &ccb->cpi;
2503
2504                 DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:XPT_PATH_INQ:.\n",
2505                         (sc == NULL? DEVNAME_SIM:USBDEVNAME(sc->sc_dev)),
2506                         cam_sim_path(sc->umass_sim),
2507                         ccb->ccb_h.target_id, ccb->ccb_h.target_lun));
2508
2509                 /* host specific information */
2510                 cpi->version_num = 1;
2511                 cpi->hba_inquiry = 0;
2512                 cpi->target_sprt = 0;
2513                 cpi->hba_misc = PIM_NO_6_BYTE;
2514                 cpi->hba_eng_cnt = 0;
2515                 cpi->max_target = UMASS_SCSIID_MAX;     /* one target */
2516                 cpi->initiator_id = UMASS_SCSIID_HOST;
2517                 strncpy(cpi->sim_vid, "FreeBSD", SIM_IDLEN);
2518                 strncpy(cpi->hba_vid, "USB SCSI", HBA_IDLEN);
2519                 strncpy(cpi->dev_name, cam_sim_name(sim), DEV_IDLEN);
2520                 cpi->unit_number = cam_sim_unit(sim);
2521                 cpi->bus_id = USBDEVUNIT(sc->sc_dev);
2522
2523                 if (sc == NULL) {
2524                         cpi->base_transfer_speed = 0;
2525                         cpi->max_lun = 0;
2526                 } else {
2527                         if (sc->quirks & FLOPPY_SPEED) {
2528                                 cpi->base_transfer_speed =
2529                                     UMASS_FLOPPY_TRANSFER_SPEED;
2530                         } else if (usbd_get_speed(sc->sc_udev) ==
2531                             USB_SPEED_HIGH) {
2532                                 cpi->base_transfer_speed =
2533                                     UMASS_HIGH_TRANSFER_SPEED;
2534                         } else {
2535                                 cpi->base_transfer_speed =
2536                                     UMASS_FULL_TRANSFER_SPEED;
2537                         }
2538                         cpi->max_lun = sc->maxlun;
2539                 }
2540
2541                 cpi->ccb_h.status = CAM_REQ_CMP;
2542                 xpt_done(ccb);
2543                 break;
2544         }
2545         case XPT_RESET_DEV:
2546         {
2547                 DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:XPT_RESET_DEV:.\n",
2548                         USBDEVNAME(sc->sc_dev), cam_sim_path(sc->umass_sim),
2549                         ccb->ccb_h.target_id, ccb->ccb_h.target_lun));
2550
2551                 ccb->ccb_h.status = CAM_REQ_INPROG;
2552                 umass_reset(sc, umass_cam_cb, (void *) ccb);
2553                 break;
2554         }
2555         case XPT_GET_TRAN_SETTINGS:
2556         {
2557                 struct ccb_trans_settings *cts = &ccb->cts;
2558
2559                 DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:XPT_GET_TRAN_SETTINGS:.\n",
2560                         USBDEVNAME(sc->sc_dev), cam_sim_path(sc->umass_sim),
2561                         ccb->ccb_h.target_id, ccb->ccb_h.target_lun));
2562
2563                 cts->valid = 0;
2564                 cts->flags = 0;         /* no disconnection, tagging */
2565
2566                 ccb->ccb_h.status = CAM_REQ_CMP;
2567                 xpt_done(ccb);
2568                 break;
2569         }
2570         case XPT_SET_TRAN_SETTINGS:
2571         {
2572                 DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:XPT_SET_TRAN_SETTINGS:.\n",
2573                         USBDEVNAME(sc->sc_dev), cam_sim_path(sc->umass_sim),
2574                         ccb->ccb_h.target_id, ccb->ccb_h.target_lun));
2575
2576                 ccb->ccb_h.status = CAM_FUNC_NOTAVAIL;
2577                 xpt_done(ccb);
2578                 break;
2579         }
2580         case XPT_CALC_GEOMETRY:
2581         {
2582                 cam_calc_geometry(&ccb->ccg, /*extended*/1);
2583                 xpt_done(ccb);
2584                 break;
2585         }
2586         case XPT_NOOP:
2587         {
2588                 DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:XPT_NOOP:.\n",
2589                         (sc == NULL? DEVNAME_SIM:USBDEVNAME(sc->sc_dev)),
2590                         cam_sim_path(sc->umass_sim),
2591                         ccb->ccb_h.target_id, ccb->ccb_h.target_lun));
2592
2593                 ccb->ccb_h.status = CAM_REQ_CMP;
2594                 xpt_done(ccb);
2595                 break;
2596         }
2597         default:
2598                 DPRINTF(UDMASS_SCSI, ("%s:%d:%d:%d:func_code 0x%04x: "
2599                         "Not implemented\n",
2600                         (sc == NULL? DEVNAME_SIM:USBDEVNAME(sc->sc_dev)),
2601                         cam_sim_path(sc->umass_sim),
2602                         ccb->ccb_h.target_id, ccb->ccb_h.target_lun,
2603                         ccb->ccb_h.func_code));
2604
2605                 ccb->ccb_h.status = CAM_FUNC_NOTAVAIL;
2606                 xpt_done(ccb);
2607                 break;
2608         }
2609 }
2610
2611 /* umass_cam_poll
2612  *      all requests are handled through umass_cam_action, requests
2613  *      are never pending. So, nothing to do here.
2614  */
2615 Static void
2616 umass_cam_poll(struct cam_sim *sim)
2617 {
2618 #ifdef USB_DEBUG
2619         struct umass_softc *sc = (struct umass_softc *) sim->softc;
2620
2621         DPRINTF(UDMASS_SCSI, ("%s: CAM poll\n",
2622                 USBDEVNAME(sc->sc_dev)));
2623 #endif
2624
2625         /* nop */
2626 }
2627
2628
2629 /* umass_cam_cb
2630  *      finalise a completed CAM command
2631  */
2632
2633 Static void
2634 umass_cam_cb(struct umass_softc *sc, void *priv, int residue, int status)
2635 {
2636         union ccb *ccb = (union ccb *) priv;
2637         struct ccb_scsiio *csio = &ccb->csio;           /* deref union */
2638
2639         /* If the device is gone, just fail the request. */
2640         if (sc->flags & UMASS_FLAGS_GONE) {
2641                 ccb->ccb_h.status = CAM_TID_INVALID;
2642                 xpt_done(ccb);
2643                 return;
2644         }
2645
2646         csio->resid = residue;
2647
2648         switch (status) {
2649         case STATUS_CMD_OK:
2650                 ccb->ccb_h.status = CAM_REQ_CMP;
2651                 xpt_done(ccb);
2652                 break;
2653
2654         case STATUS_CMD_UNKNOWN:
2655         case STATUS_CMD_FAILED:
2656                 switch (ccb->ccb_h.func_code) {
2657                 case XPT_SCSI_IO:
2658                 {
2659                         unsigned char *rcmd;
2660                         int rcmdlen;
2661
2662                         /* fetch sense data */
2663                         /* the rest of the command was filled in at attach */
2664                         sc->cam_scsi_sense.length = csio->sense_len;
2665
2666                         DPRINTF(UDMASS_SCSI,("%s: Fetching %db sense data\n",
2667                                 USBDEVNAME(sc->sc_dev), csio->sense_len));
2668
2669                         rcmd = (unsigned char *) &sc->cam_scsi_command;
2670                         rcmdlen = sizeof(sc->cam_scsi_command);
2671
2672                         if (sc->transform(sc,
2673                                     (unsigned char *) &sc->cam_scsi_sense,
2674                                     sizeof(sc->cam_scsi_sense),
2675                                     &rcmd, &rcmdlen)) {
2676                                 if ((sc->quirks & FORCE_SHORT_INQUIRY) && (rcmd[0] == INQUIRY)) {
2677                                         csio->sense_len = SHORT_INQUIRY_LENGTH;
2678                                 }
2679                                 sc->transfer(sc, ccb->ccb_h.target_lun,
2680                                              rcmd, rcmdlen,
2681                                              &csio->sense_data,
2682                                              csio->sense_len, DIR_IN, ccb->ccb_h.timeout,
2683                                              umass_cam_sense_cb, (void *) ccb);
2684                         } else {
2685                                 panic("transform(REQUEST_SENSE) failed");
2686                         }
2687                         break;
2688                 }
2689                 case XPT_RESET_DEV: /* Reset failed */
2690                         ccb->ccb_h.status = CAM_REQ_CMP_ERR;
2691                         xpt_done(ccb);
2692                         break;
2693                 default:
2694                         panic("umass_cam_cb called for func_code %d",
2695                               ccb->ccb_h.func_code);
2696                 }
2697                 break;
2698
2699         case STATUS_WIRE_FAILED:
2700                 /* the wire protocol failed and will have recovered
2701                  * (hopefully).  We return an error to CAM and let CAM retry
2702                  * the command if necessary.
2703                  */
2704                 ccb->ccb_h.status = CAM_REQ_CMP_ERR;
2705                 xpt_done(ccb);
2706                 break;
2707         default:
2708                 panic("%s: Unknown status %d in umass_cam_cb",
2709                         USBDEVNAME(sc->sc_dev), status);
2710         }
2711 }
2712
2713 /* Finalise a completed autosense operation
2714  */
2715 Static void
2716 umass_cam_sense_cb(struct umass_softc *sc, void *priv, int residue, int status)
2717 {
2718         union ccb *ccb = (union ccb *) priv;
2719         struct ccb_scsiio *csio = &ccb->csio;           /* deref union */
2720         unsigned char *rcmd;
2721         int rcmdlen;
2722
2723         if (sc->flags & UMASS_FLAGS_GONE) {
2724                 ccb->ccb_h.status = CAM_AUTOSENSE_FAIL;
2725                 xpt_done(ccb);
2726                 return;
2727         }
2728
2729         switch (status) {
2730         case STATUS_CMD_OK:
2731         case STATUS_CMD_UNKNOWN:
2732         case STATUS_CMD_FAILED:
2733                 /* Getting sense data always succeeds (apart from wire
2734                  * failures).
2735                  */
2736                 if ((sc->quirks & RS_NO_CLEAR_UA)
2737                     && csio->cdb_io.cdb_bytes[0] == INQUIRY
2738                     && (csio->sense_data.flags & SSD_KEY)
2739                                                 == SSD_KEY_UNIT_ATTENTION) {
2740                         /* Ignore unit attention errors in the case where
2741                          * the Unit Attention state is not cleared on
2742                          * REQUEST SENSE. They will appear again at the next
2743                          * command.
2744                          */
2745                         ccb->ccb_h.status = CAM_REQ_CMP;
2746                 } else if ((csio->sense_data.flags & SSD_KEY)
2747                                                 == SSD_KEY_NO_SENSE) {
2748                         /* No problem after all (in the case of CBI without
2749                          * CCI)
2750                          */
2751                         ccb->ccb_h.status = CAM_REQ_CMP;
2752                 } else if ((sc->quirks & RS_NO_CLEAR_UA) &&
2753                            (csio->cdb_io.cdb_bytes[0] == READ_CAPACITY) &&
2754                            ((csio->sense_data.flags & SSD_KEY)
2755                             == SSD_KEY_UNIT_ATTENTION)) {
2756                         /*
2757                          * Some devices do not clear the unit attention error
2758                          * on request sense. We insert a test unit ready
2759                          * command to make sure we clear the unit attention
2760                          * condition, then allow the retry to proceed as
2761                          * usual.
2762                          */
2763
2764                         ccb->ccb_h.status = CAM_SCSI_STATUS_ERROR
2765                                             | CAM_AUTOSNS_VALID;
2766                         csio->scsi_status = SCSI_STATUS_CHECK_COND;
2767
2768 #if 0
2769                         DELAY(300000);
2770 #endif
2771
2772                         DPRINTF(UDMASS_SCSI,("%s: Doing a sneaky"
2773                                              "TEST_UNIT_READY\n",
2774                                 USBDEVNAME(sc->sc_dev)));
2775
2776                         /* the rest of the command was filled in at attach */
2777
2778                         rcmd = (unsigned char *) &sc->cam_scsi_command2;
2779                         rcmdlen = sizeof(sc->cam_scsi_command2);
2780
2781                         if (sc->transform(sc,
2782                                         (unsigned char *)
2783                                         &sc->cam_scsi_test_unit_ready,
2784                                         sizeof(sc->cam_scsi_test_unit_ready),
2785                                         &rcmd, &rcmdlen)) {
2786                                 sc->transfer(sc, ccb->ccb_h.target_lun,
2787                                              rcmd, rcmdlen,
2788                                              NULL, 0, DIR_NONE, ccb->ccb_h.timeout,
2789                                              umass_cam_quirk_cb, (void *) ccb);
2790                         } else {
2791                                 panic("transform(TEST_UNIT_READY) failed");
2792                         }
2793                         break;
2794                 } else {
2795                         ccb->ccb_h.status = CAM_SCSI_STATUS_ERROR
2796                                             | CAM_AUTOSNS_VALID;
2797                         csio->scsi_status = SCSI_STATUS_CHECK_COND;
2798                 }
2799                 xpt_done(ccb);
2800                 break;
2801
2802         default:
2803                 DPRINTF(UDMASS_SCSI, ("%s: Autosense failed, status %d\n",
2804                         USBDEVNAME(sc->sc_dev), status));
2805                 ccb->ccb_h.status = CAM_AUTOSENSE_FAIL;
2806                 xpt_done(ccb);
2807         }
2808 }
2809
2810 /*
2811  * This completion code just handles the fact that we sent a test-unit-ready
2812  * after having previously failed a READ CAPACITY with CHECK_COND.  Even
2813  * though this command succeeded, we have to tell CAM to retry.
2814  */
2815 Static void
2816 umass_cam_quirk_cb(struct umass_softc *sc, void *priv, int residue, int status)
2817 {
2818         union ccb *ccb = (union ccb *) priv;
2819
2820         DPRINTF(UDMASS_SCSI, ("%s: Test unit ready returned status %d\n",
2821         USBDEVNAME(sc->sc_dev), status));
2822
2823         if (sc->flags & UMASS_FLAGS_GONE) {
2824                 ccb->ccb_h.status = CAM_TID_INVALID;
2825                 xpt_done(ccb);
2826                 return;
2827         }
2828 #if 0
2829         ccb->ccb_h.status = CAM_REQ_CMP;
2830 #endif
2831         ccb->ccb_h.status = CAM_SCSI_STATUS_ERROR
2832                             | CAM_AUTOSNS_VALID;
2833         ccb->csio.scsi_status = SCSI_STATUS_CHECK_COND;
2834         xpt_done(ccb);
2835 }
2836
2837 Static int
2838 umass_driver_load(module_t mod, int what, void *arg)
2839 {
2840         switch (what) {
2841         case MOD_UNLOAD:
2842         case MOD_LOAD:
2843         default:
2844                 return(usbd_driver_load(mod, what, arg));
2845         }
2846 }
2847
2848 /*
2849  * SCSI specific functions
2850  */
2851
2852 Static int
2853 umass_scsi_transform(struct umass_softc *sc, unsigned char *cmd, int cmdlen,
2854                      unsigned char **rcmd, int *rcmdlen)
2855 {
2856         switch (cmd[0]) {
2857         case TEST_UNIT_READY:
2858                 if (sc->quirks & NO_TEST_UNIT_READY) {
2859                         KASSERT(*rcmdlen >= sizeof(struct scsi_start_stop_unit),
2860                                 ("rcmdlen = %d < %ld, buffer too small",
2861                                  *rcmdlen,
2862                                  (long)sizeof(struct scsi_start_stop_unit)));
2863                         DPRINTF(UDMASS_SCSI, ("%s: Converted TEST_UNIT_READY "
2864                                 "to START_UNIT\n", USBDEVNAME(sc->sc_dev)));
2865                         memset(*rcmd, 0, *rcmdlen);
2866                         (*rcmd)[0] = START_STOP_UNIT;
2867                         (*rcmd)[4] = SSS_START;
2868                         return 1;
2869                 }
2870                 /* fallthrough */
2871         case INQUIRY:
2872                 /* some drives wedge when asked for full inquiry information. */
2873                 if (sc->quirks & FORCE_SHORT_INQUIRY) {
2874                         memcpy(*rcmd, cmd, cmdlen);
2875                         *rcmdlen = cmdlen;
2876                         (*rcmd)[4] = SHORT_INQUIRY_LENGTH;
2877                         return 1;
2878                 }
2879                 /* fallthrough */
2880         default:
2881                 *rcmd = cmd;            /* We don't need to copy it */
2882                 *rcmdlen = cmdlen;
2883         }
2884
2885         return 1;
2886 }
2887 /* RBC specific functions */
2888 Static int
2889 umass_rbc_transform(struct umass_softc *sc, unsigned char *cmd, int cmdlen,
2890                      unsigned char **rcmd, int *rcmdlen)
2891 {
2892         switch (cmd[0]) {
2893         /* these commands are defined in RBC: */
2894         case READ_10:
2895         case READ_CAPACITY:
2896         case START_STOP_UNIT:
2897         case SYNCHRONIZE_CACHE:
2898         case WRITE_10:
2899         case 0x2f: /* VERIFY_10 is absent from scsi_all.h??? */
2900         case INQUIRY:
2901         case MODE_SELECT_10:
2902         case MODE_SENSE_10:
2903         case TEST_UNIT_READY:
2904         case WRITE_BUFFER:
2905          /* The following commands are not listed in my copy of the RBC specs.
2906           * CAM however seems to want those, and at least the Sony DSC device
2907           * appears to support those as well */
2908         case REQUEST_SENSE:
2909         case PREVENT_ALLOW:
2910                 *rcmd = cmd;            /* We don't need to copy it */
2911                 *rcmdlen = cmdlen;
2912                 return 1;
2913         /* All other commands are not legal in RBC */
2914         default:
2915                 printf("%s: Unsupported RBC command 0x%02x",
2916                         USBDEVNAME(sc->sc_dev), cmd[0]);
2917                 printf("\n");
2918                 return 0;       /* failure */
2919         }
2920 }
2921
2922 /*
2923  * UFI specific functions
2924  */
2925 Static int
2926 umass_ufi_transform(struct umass_softc *sc, unsigned char *cmd, int cmdlen,
2927                     unsigned char **rcmd, int *rcmdlen)
2928 {
2929         /* A UFI command is always 12 bytes in length */
2930         KASSERT(*rcmdlen >= UFI_COMMAND_LENGTH,
2931                 ("rcmdlen = %d < %d, buffer too small",
2932                  *rcmdlen, UFI_COMMAND_LENGTH));
2933
2934         *rcmdlen = UFI_COMMAND_LENGTH;
2935         memset(*rcmd, 0, UFI_COMMAND_LENGTH);
2936
2937         switch (cmd[0]) {
2938         /* Commands of which the format has been verified. They should work.
2939          * Copy the command into the (zeroed out) destination buffer.
2940          */
2941         case TEST_UNIT_READY:
2942                 if (sc->quirks &  NO_TEST_UNIT_READY) {
2943                         /* Some devices do not support this command.
2944                          * Start Stop Unit should give the same results
2945                          */
2946                         DPRINTF(UDMASS_UFI, ("%s: Converted TEST_UNIT_READY "
2947                                 "to START_UNIT\n", USBDEVNAME(sc->sc_dev)));
2948                         (*rcmd)[0] = START_STOP_UNIT;
2949                         (*rcmd)[4] = SSS_START;
2950                 } else {
2951                         memcpy(*rcmd, cmd, cmdlen);
2952                 }
2953                 return 1;
2954
2955         case REZERO_UNIT:
2956         case REQUEST_SENSE:
2957         case FORMAT_UNIT:
2958         case INQUIRY:
2959         case START_STOP_UNIT:
2960         case SEND_DIAGNOSTIC:
2961         case PREVENT_ALLOW:
2962         case READ_CAPACITY:
2963         case READ_10:
2964         case WRITE_10:
2965         case POSITION_TO_ELEMENT:       /* SEEK_10 */
2966         case WRITE_AND_VERIFY:
2967         case VERIFY:
2968         case MODE_SELECT_10:
2969         case MODE_SENSE_10:
2970         case READ_12:
2971         case WRITE_12:
2972         case READ_FORMAT_CAPACITIES:
2973                 memcpy(*rcmd, cmd, cmdlen);
2974                 return 1;
2975
2976         default:
2977                 printf("%s: Unsupported UFI command 0x%02x\n",
2978                         USBDEVNAME(sc->sc_dev), cmd[0]);
2979                 return 0;       /* failure */
2980         }
2981 }
2982
2983 /*
2984  * 8070i (ATAPI) specific functions
2985  */
2986 Static int
2987 umass_atapi_transform(struct umass_softc *sc, unsigned char *cmd, int cmdlen,
2988                       unsigned char **rcmd, int *rcmdlen)
2989 {
2990         /* An ATAPI command is always 12 bytes in length. */
2991         KASSERT(*rcmdlen >= ATAPI_COMMAND_LENGTH,
2992                 ("rcmdlen = %d < %d, buffer too small",
2993                  *rcmdlen, ATAPI_COMMAND_LENGTH));
2994
2995         *rcmdlen = ATAPI_COMMAND_LENGTH;
2996         memset(*rcmd, 0, ATAPI_COMMAND_LENGTH);
2997
2998         switch (cmd[0]) {
2999         /* Commands of which the format has been verified. They should work.
3000          * Copy the command into the (zeroed out) destination buffer.
3001          */
3002         case INQUIRY:
3003                 memcpy(*rcmd, cmd, cmdlen);
3004                 /* some drives wedge when asked for full inquiry information. */
3005                 if (sc->quirks & FORCE_SHORT_INQUIRY)
3006                         (*rcmd)[4] = SHORT_INQUIRY_LENGTH;
3007                 return 1;
3008
3009         case TEST_UNIT_READY:
3010                 if (sc->quirks & NO_TEST_UNIT_READY) {
3011                         KASSERT(*rcmdlen >= sizeof(struct scsi_start_stop_unit),
3012                                 ("rcmdlen = %d < %ld, buffer too small",
3013                                  *rcmdlen,
3014                                  (long)sizeof(struct scsi_start_stop_unit)));
3015                         DPRINTF(UDMASS_SCSI, ("%s: Converted TEST_UNIT_READY "
3016                                 "to START_UNIT\n", USBDEVNAME(sc->sc_dev)));
3017                         memset(*rcmd, 0, *rcmdlen);
3018                         (*rcmd)[0] = START_STOP_UNIT;
3019                         (*rcmd)[4] = SSS_START;
3020                         return 1;
3021                 }
3022                 /* fallthrough */
3023         case REZERO_UNIT:
3024         case REQUEST_SENSE:
3025         case START_STOP_UNIT:
3026         case SEND_DIAGNOSTIC:
3027         case PREVENT_ALLOW:
3028         case READ_CAPACITY:
3029         case READ_10:
3030         case WRITE_10:
3031         case POSITION_TO_ELEMENT:       /* SEEK_10 */
3032         case SYNCHRONIZE_CACHE:
3033         case MODE_SELECT_10:
3034         case MODE_SENSE_10:
3035         case READ_BUFFER:
3036         case 0x42: /* READ_SUBCHANNEL */
3037         case 0x43: /* READ_TOC */
3038         case 0x44: /* READ_HEADER */
3039         case 0x51: /* READ_DISK_INFO */
3040         case 0x52: /* READ_TRACK_INFO */
3041         case 0x54: /* SEND_OPC */
3042         case 0x59: /* READ_MASTER_CUE */
3043         case 0x5b: /* CLOSE_TR_SESSION */
3044         case 0x5c: /* READ_BUFFER_CAP */
3045         case 0x5d: /* SEND_CUE_SHEET */
3046         case 0xa1: /* BLANK */
3047         case 0xa6: /* EXCHANGE_MEDIUM */
3048         case 0xad: /* READ_DVD_STRUCTURE */
3049         case 0xbb: /* SET_CD_SPEED */
3050         case 0xe5: /* READ_TRACK_INFO_PHILIPS */
3051                 memcpy(*rcmd, cmd, cmdlen);
3052                 return 1;
3053
3054         case READ_12:
3055         case WRITE_12:
3056         default:
3057                 printf("%s: Unsupported ATAPI command 0x%02x\n",
3058                         USBDEVNAME(sc->sc_dev), cmd[0]);
3059                 return 0;       /* failure */
3060         }
3061 }
3062
3063
3064 /* (even the comment is missing) */
3065
3066 DRIVER_MODULE(umass, uhub, umass_driver, umass_devclass, umass_driver_load, 0);
3067
3068
3069
3070 #ifdef USB_DEBUG
3071 Static void
3072 umass_bbb_dump_cbw(struct umass_softc *sc, umass_bbb_cbw_t *cbw)
3073 {
3074         int clen = cbw->bCDBLength;
3075         int dlen = UGETDW(cbw->dCBWDataTransferLength);
3076         u_int8_t *c = cbw->CBWCDB;
3077         int tag = UGETDW(cbw->dCBWTag);
3078         int flags = cbw->bCBWFlags;
3079
3080         DPRINTF(UDMASS_BBB, ("%s: CBW %d: cmd = %db "
3081                 "(0x%02x%02x%02x%02x%02x%02x%s), "
3082                 "data = %db, dir = %s\n",
3083                 USBDEVNAME(sc->sc_dev), tag, clen,
3084                 c[0], c[1], c[2], c[3], c[4], c[5], (clen > 6? "...":""),
3085                 dlen, (flags == CBWFLAGS_IN? "in":
3086                        (flags == CBWFLAGS_OUT? "out":"<invalid>"))));
3087 }
3088
3089 Static void
3090 umass_bbb_dump_csw(struct umass_softc *sc, umass_bbb_csw_t *csw)
3091 {
3092         int sig = UGETDW(csw->dCSWSignature);
3093         int tag = UGETW(csw->dCSWTag);
3094         int res = UGETDW(csw->dCSWDataResidue);
3095         int status = csw->bCSWStatus;
3096
3097         DPRINTF(UDMASS_BBB, ("%s: CSW %d: sig = 0x%08x (%s), tag = %d, "
3098                 "res = %d, status = 0x%02x (%s)\n", USBDEVNAME(sc->sc_dev),
3099                 tag, sig, (sig == CSWSIGNATURE?  "valid":"invalid"),
3100                 tag, res,
3101                 status, (status == CSWSTATUS_GOOD? "good":
3102                          (status == CSWSTATUS_FAILED? "failed":
3103                           (status == CSWSTATUS_PHASE? "phase":"<invalid>")))));
3104 }
3105
3106 Static void
3107 umass_cbi_dump_cmd(struct umass_softc *sc, void *cmd, int cmdlen)
3108 {
3109         u_int8_t *c = cmd;
3110         int dir = sc->transfer_dir;
3111
3112         DPRINTF(UDMASS_BBB, ("%s: cmd = %db "
3113                 "(0x%02x%02x%02x%02x%02x%02x%s), "
3114                 "data = %db, dir = %s\n",
3115                 USBDEVNAME(sc->sc_dev), cmdlen,
3116                 c[0], c[1], c[2], c[3], c[4], c[5], (cmdlen > 6? "...":""),
3117                 sc->transfer_datalen,
3118                 (dir == DIR_IN? "in":
3119                  (dir == DIR_OUT? "out":
3120                   (dir == DIR_NONE? "no data phase": "<invalid>")))));
3121 }
3122
3123 Static void
3124 umass_dump_buffer(struct umass_softc *sc, u_int8_t *buffer, int buflen,
3125                   int printlen)
3126 {
3127         int i, j;
3128         char s1[40];
3129         char s2[40];
3130         char s3[5];
3131
3132         s1[0] = '\0';
3133         s3[0] = '\0';
3134
3135         sprintf(s2, " buffer=%p, buflen=%d", buffer, buflen);
3136         for (i = 0; i < buflen && i < printlen; i++) {
3137                 j = i % 16;
3138                 if (j == 0 && i != 0) {
3139                         DPRINTF(UDMASS_GEN, ("%s: 0x %s%s\n",
3140                                 USBDEVNAME(sc->sc_dev), s1, s2));
3141                         s2[0] = '\0';
3142                 }
3143                 sprintf(&s1[j*2], "%02x", buffer[i] & 0xff);
3144         }
3145         if (buflen > printlen)
3146                 sprintf(s3, " ...");
3147         DPRINTF(UDMASS_GEN, ("%s: 0x %s%s%s\n",
3148                 USBDEVNAME(sc->sc_dev), s1, s2, s3));
3149 }
3150 #endif