xref: /dragonfly/sys/dev/raid/mlx/mlx.c (revision 6fb88001)
1 /*-
2  * Copyright (c) 1999 Michael Smith
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  *
14  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
15  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
18  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
24  * SUCH DAMAGE.
25  *
26  *	$FreeBSD: src/sys/dev/mlx/mlx.c,v 1.14.2.5 2001/09/11 09:49:53 kris Exp $
27  *	$DragonFly: src/sys/dev/raid/mlx/mlx.c,v 1.14 2005/10/12 17:35:54 dillon Exp $
28  */
29 
30 /*
31  * Driver for the Mylex DAC960 family of RAID controllers.
32  */
33 
34 #include <sys/param.h>
35 #include <sys/systm.h>
36 #include <sys/malloc.h>
37 #include <sys/kernel.h>
38 
39 #include <sys/bus.h>
40 #include <sys/conf.h>
41 #include <sys/devicestat.h>
42 #include <sys/disk.h>
43 #include <sys/stat.h>
44 #include <sys/thread2.h>
45 
46 #include <machine/resource.h>
47 #include <machine/bus_memio.h>
48 #include <machine/bus_pio.h>
49 #include <machine/bus.h>
50 #include <machine/clock.h>
51 #include <sys/rman.h>
52 
53 #include "mlx_compat.h"
54 #include "mlxio.h"
55 #include "mlxvar.h"
56 #include "mlxreg.h"
57 
58 #define MLX_CDEV_MAJOR	130
59 
60 static struct cdevsw mlx_cdevsw = {
61 		/* name */ 	"mlx",
62 		/* maj */	MLX_CDEV_MAJOR,
63 		/* flags */	0,
64 		/* port */	NULL,
65 		/* clone */	NULL,
66 
67 		/* open */	mlx_open,
68 		/* close */	mlx_close,
69 		/* read */	noread,
70 		/* write */	nowrite,
71 		/* ioctl */	mlx_ioctl,
72 		/* poll */	nopoll,
73 		/* mmap */	nommap,
74 		/* strategy */	nostrategy,
75 		/* dump */	nodump,
76 		/* psize */ 	nopsize
77 };
78 
79 devclass_t	mlx_devclass;
80 
81 /*
82  * Per-interface accessor methods
83  */
84 static int			mlx_v3_tryqueue(struct mlx_softc *sc, struct mlx_command *mc);
85 static int			mlx_v3_findcomplete(struct mlx_softc *sc, u_int8_t *slot, u_int16_t *status);
86 static void			mlx_v3_intaction(struct mlx_softc *sc, int action);
87 static int			mlx_v3_fw_handshake(struct mlx_softc *sc, int *error, int *param1, int *param2);
88 
89 static int			mlx_v4_tryqueue(struct mlx_softc *sc, struct mlx_command *mc);
90 static int			mlx_v4_findcomplete(struct mlx_softc *sc, u_int8_t *slot, u_int16_t *status);
91 static void			mlx_v4_intaction(struct mlx_softc *sc, int action);
92 static int			mlx_v4_fw_handshake(struct mlx_softc *sc, int *error, int *param1, int *param2);
93 
94 static int			mlx_v5_tryqueue(struct mlx_softc *sc, struct mlx_command *mc);
95 static int			mlx_v5_findcomplete(struct mlx_softc *sc, u_int8_t *slot, u_int16_t *status);
96 static void			mlx_v5_intaction(struct mlx_softc *sc, int action);
97 static int			mlx_v5_fw_handshake(struct mlx_softc *sc, int *error, int *param1, int *param2);
98 
99 /*
100  * Status monitoring
101  */
102 static void			mlx_periodic(void *data);
103 static void			mlx_periodic_enquiry(struct mlx_command *mc);
104 static void			mlx_periodic_eventlog_poll(struct mlx_softc *sc);
105 static void			mlx_periodic_eventlog_respond(struct mlx_command *mc);
106 static void			mlx_periodic_rebuild(struct mlx_command *mc);
107 
108 /*
109  * Channel Pause
110  */
111 static void			mlx_pause_action(struct mlx_softc *sc);
112 static void			mlx_pause_done(struct mlx_command *mc);
113 
114 /*
115  * Command submission.
116  */
117 static void			*mlx_enquire(struct mlx_softc *sc, int command, size_t bufsize,
118 					     void (*complete)(struct mlx_command *mc));
119 static int			mlx_flush(struct mlx_softc *sc);
120 static int			mlx_check(struct mlx_softc *sc, int drive);
121 static int			mlx_rebuild(struct mlx_softc *sc, int channel, int target);
122 static int			mlx_wait_command(struct mlx_command *mc);
123 static int			mlx_poll_command(struct mlx_command *mc);
124 static void			mlx_startio(struct mlx_softc *sc);
125 static void			mlx_completeio(struct mlx_command *mc);
126 static int			mlx_user_command(struct mlx_softc *sc, struct mlx_usercommand *mu);
127 
128 /*
129  * Command buffer allocation.
130  */
131 static struct mlx_command	*mlx_alloccmd(struct mlx_softc *sc);
132 static void			mlx_releasecmd(struct mlx_command *mc);
133 static void			mlx_freecmd(struct mlx_command *mc);
134 
135 /*
136  * Command management.
137  */
138 static int			mlx_getslot(struct mlx_command *mc);
139 static void			mlx_mapcmd(struct mlx_command *mc);
140 static void			mlx_unmapcmd(struct mlx_command *mc);
141 static int			mlx_start(struct mlx_command *mc);
142 static int			mlx_done(struct mlx_softc *sc);
143 static void			mlx_complete(struct mlx_softc *sc);
144 
145 /*
146  * Debugging.
147  */
148 static char			*mlx_diagnose_command(struct mlx_command *mc);
149 static void			mlx_describe_controller(struct mlx_softc *sc);
150 static int			mlx_fw_message(struct mlx_softc *sc, int status, int param1, int param2);
151 
152 /*
153  * Utility functions.
154  */
155 static struct mlx_sysdrive	*mlx_findunit(struct mlx_softc *sc, int unit);
156 
157 /********************************************************************************
158  ********************************************************************************
159                                                                 Public Interfaces
160  ********************************************************************************
161  ********************************************************************************/
162 
163 /********************************************************************************
164  * Free all of the resources associated with (sc)
165  *
166  * Should not be called if the controller is active.
167  */
168 void
169 mlx_free(struct mlx_softc *sc)
170 {
171     struct mlx_command	*mc;
172 
173     debug_called(1);
174 
175     /* cancel status timeout */
176     callout_stop(&sc->mlx_timeout);
177 
178     /* throw away any command buffers */
179     while ((mc = TAILQ_FIRST(&sc->mlx_freecmds)) != NULL) {
180 	TAILQ_REMOVE(&sc->mlx_freecmds, mc, mc_link);
181 	mlx_freecmd(mc);
182     }
183 
184     /* destroy data-transfer DMA tag */
185     if (sc->mlx_buffer_dmat)
186 	bus_dma_tag_destroy(sc->mlx_buffer_dmat);
187 
188     /* free and destroy DMA memory and tag for s/g lists */
189     if (sc->mlx_sgtable)
190 	bus_dmamem_free(sc->mlx_sg_dmat, sc->mlx_sgtable, sc->mlx_sg_dmamap);
191     if (sc->mlx_sg_dmat)
192 	bus_dma_tag_destroy(sc->mlx_sg_dmat);
193 
194     /* disconnect the interrupt handler */
195     if (sc->mlx_intr)
196 	bus_teardown_intr(sc->mlx_dev, sc->mlx_irq, sc->mlx_intr);
197     if (sc->mlx_irq != NULL)
198 	bus_release_resource(sc->mlx_dev, SYS_RES_IRQ, 0, sc->mlx_irq);
199 
200     /* destroy the parent DMA tag */
201     if (sc->mlx_parent_dmat)
202 	bus_dma_tag_destroy(sc->mlx_parent_dmat);
203 
204     /* release the register window mapping */
205     if (sc->mlx_mem != NULL)
206 	bus_release_resource(sc->mlx_dev, sc->mlx_mem_type, sc->mlx_mem_rid, sc->mlx_mem);
207 
208     /* free controller enquiry data */
209     if (sc->mlx_enq2 != NULL)
210 	free(sc->mlx_enq2, M_DEVBUF);
211 
212     cdevsw_remove(&mlx_cdevsw, -1, device_get_unit(sc->mlx_dev));
213 }
214 
215 /********************************************************************************
216  * Map the scatter/gather table into bus space
217  */
218 static void
219 mlx_dma_map_sg(void *arg, bus_dma_segment_t *segs, int nseg, int error)
220 {
221     struct mlx_softc	*sc = (struct mlx_softc *)arg;
222 
223     debug_called(1);
224 
225     /* save base of s/g table's address in bus space */
226     sc->mlx_sgbusaddr = segs->ds_addr;
227 }
228 
229 static int
230 mlx_sglist_map(struct mlx_softc *sc)
231 {
232     size_t	segsize;
233     int		error, ncmd;
234 
235     debug_called(1);
236 
237     /* destroy any existing mappings */
238     if (sc->mlx_sgtable)
239 	bus_dmamem_free(sc->mlx_sg_dmat, sc->mlx_sgtable, sc->mlx_sg_dmamap);
240     if (sc->mlx_sg_dmat)
241 	bus_dma_tag_destroy(sc->mlx_sg_dmat);
242 
243     /*
244      * Create a single tag describing a region large enough to hold all of
245      * the s/g lists we will need.  If we're called early on, we don't know how
246      * many commands we're going to be asked to support, so only allocate enough
247      * for a couple.
248      */
249     if (sc->mlx_enq2 == NULL) {
250 	ncmd = 2;
251     } else {
252 	ncmd = sc->mlx_enq2->me_max_commands;
253     }
254     segsize = sizeof(struct mlx_sgentry) * MLX_NSEG * ncmd;
255     error = bus_dma_tag_create(sc->mlx_parent_dmat, 	/* parent */
256 			       1, 0, 			/* alignment, boundary */
257 			       BUS_SPACE_MAXADDR,	/* lowaddr */
258 			       BUS_SPACE_MAXADDR, 	/* highaddr */
259 			       NULL, NULL, 		/* filter, filterarg */
260 			       segsize, 1,		/* maxsize, nsegments */
261 			       BUS_SPACE_MAXSIZE_32BIT,	/* maxsegsize */
262 			       0,			/* flags */
263 			       &sc->mlx_sg_dmat);
264     if (error != 0) {
265 	device_printf(sc->mlx_dev, "can't allocate scatter/gather DMA tag\n");
266 	return(ENOMEM);
267     }
268 
269     /*
270      * Allocate enough s/g maps for all commands and permanently map them into
271      * controller-visible space.
272      *
273      * XXX this assumes we can get enough space for all the s/g maps in one
274      * contiguous slab.  We may need to switch to a more complex arrangement where
275      * we allocate in smaller chunks and keep a lookup table from slot to bus address.
276      */
277     error = bus_dmamem_alloc(sc->mlx_sg_dmat, (void **)&sc->mlx_sgtable, BUS_DMA_NOWAIT, &sc->mlx_sg_dmamap);
278     if (error) {
279 	device_printf(sc->mlx_dev, "can't allocate s/g table\n");
280 	return(ENOMEM);
281     }
282     bus_dmamap_load(sc->mlx_sg_dmat, sc->mlx_sg_dmamap, sc->mlx_sgtable, segsize, mlx_dma_map_sg, sc, 0);
283     return(0);
284 }
285 
286 /********************************************************************************
287  * Initialise the controller and softc
288  */
289 int
290 mlx_attach(struct mlx_softc *sc)
291 {
292     struct mlx_enquiry_old	*meo;
293     int				rid, error, fwminor, hscode, hserror, hsparam1, hsparam2, hsmsg;
294 
295     debug_called(1);
296     callout_init(&sc->mlx_timeout);
297 
298     /*
299      * Initialise per-controller queues.
300      */
301     TAILQ_INIT(&sc->mlx_work);
302     TAILQ_INIT(&sc->mlx_freecmds);
303     MLX_BIO_QINIT(sc->mlx_bioq);
304 
305     /*
306      * Select accessor methods based on controller interface type.
307      */
308     switch(sc->mlx_iftype) {
309     case MLX_IFTYPE_2:
310     case MLX_IFTYPE_3:
311 	sc->mlx_tryqueue	= mlx_v3_tryqueue;
312 	sc->mlx_findcomplete	= mlx_v3_findcomplete;
313 	sc->mlx_intaction	= mlx_v3_intaction;
314 	sc->mlx_fw_handshake	= mlx_v3_fw_handshake;
315 	break;
316     case MLX_IFTYPE_4:
317 	sc->mlx_tryqueue	= mlx_v4_tryqueue;
318 	sc->mlx_findcomplete	= mlx_v4_findcomplete;
319 	sc->mlx_intaction	= mlx_v4_intaction;
320 	sc->mlx_fw_handshake	= mlx_v4_fw_handshake;
321 	break;
322     case MLX_IFTYPE_5:
323 	sc->mlx_tryqueue	= mlx_v5_tryqueue;
324 	sc->mlx_findcomplete	= mlx_v5_findcomplete;
325 	sc->mlx_intaction	= mlx_v5_intaction;
326 	sc->mlx_fw_handshake	= mlx_v5_fw_handshake;
327 	break;
328     default:
329 	mlx_free(sc);
330 	return(ENXIO);		/* should never happen */
331     }
332 
333     /* disable interrupts before we start talking to the controller */
334     sc->mlx_intaction(sc, MLX_INTACTION_DISABLE);
335 
336     /*
337      * Wait for the controller to come ready, handshake with the firmware if required.
338      * This is typically only necessary on platforms where the controller BIOS does not
339      * run.
340      */
341     hsmsg = 0;
342     DELAY(1000);
343     while ((hscode = sc->mlx_fw_handshake(sc, &hserror, &hsparam1, &hsparam2)) != 0) {
344 	/* report first time around... */
345 	if (hsmsg == 0) {
346 	    device_printf(sc->mlx_dev, "controller initialisation in progress...\n");
347 	    hsmsg = 1;
348 	}
349 	/* did we get a real message? */
350 	if (hscode == 2) {
351 	    hscode = mlx_fw_message(sc, hserror, hsparam1, hsparam2);
352 	    /* fatal initialisation error? */
353 	    if (hscode != 0) {
354 		mlx_free(sc);
355 		return(ENXIO);
356 	    }
357 	}
358     }
359     if (hsmsg == 1)
360 	device_printf(sc->mlx_dev, "initialisation complete.\n");
361 
362     /*
363      * Allocate and connect our interrupt.
364      */
365     rid = 0;
366     sc->mlx_irq = bus_alloc_resource(sc->mlx_dev, SYS_RES_IRQ, &rid, 0, ~0, 1, RF_SHAREABLE | RF_ACTIVE);
367     if (sc->mlx_irq == NULL) {
368 	device_printf(sc->mlx_dev, "can't allocate interrupt\n");
369 	mlx_free(sc);
370 	return(ENXIO);
371     }
372     error = bus_setup_intr(sc->mlx_dev, sc->mlx_irq,
373 			   INTR_ENTROPY, mlx_intr, sc,
374 			   &sc->mlx_intr, NULL);
375     if (error) {
376 	device_printf(sc->mlx_dev, "can't set up interrupt\n");
377 	mlx_free(sc);
378 	return(ENXIO);
379     }
380 
381     /*
382      * Create DMA tag for mapping buffers into controller-addressable space.
383      */
384     error = bus_dma_tag_create(sc->mlx_parent_dmat, 		/* parent */
385 			       1, 0, 				/* alignment, boundary */
386 			       BUS_SPACE_MAXADDR,		/* lowaddr */
387 			       BUS_SPACE_MAXADDR, 		/* highaddr */
388 			       NULL, NULL, 			/* filter, filterarg */
389 			       MAXBSIZE, MLX_NSEG,		/* maxsize, nsegments */
390 			       BUS_SPACE_MAXSIZE_32BIT,		/* maxsegsize */
391 			       0,				/* flags */
392 			       &sc->mlx_buffer_dmat);
393     if (error != 0) {
394 	device_printf(sc->mlx_dev, "can't allocate buffer DMA tag\n");
395 	mlx_free(sc);
396 	return(ENOMEM);
397     }
398 
399     /*
400      * Create some initial scatter/gather mappings so we can run the probe commands.
401      */
402     error = mlx_sglist_map(sc);
403     if (error != 0) {
404 	device_printf(sc->mlx_dev, "can't make initial s/g list mapping\n");
405 	mlx_free(sc);
406 	return(error);
407     }
408 
409     /*
410      * We don't (yet) know where the event log is up to.
411      */
412     sc->mlx_currevent = -1;
413 
414     /*
415      * Obtain controller feature information
416      */
417     if ((sc->mlx_enq2 = mlx_enquire(sc, MLX_CMD_ENQUIRY2, sizeof(struct mlx_enquiry2), NULL)) == NULL) {
418 	device_printf(sc->mlx_dev, "ENQUIRY2 failed\n");
419 	mlx_free(sc);
420 	return(ENXIO);
421     }
422 
423     /*
424      * Do quirk/feature related things.
425      */
426     fwminor = (sc->mlx_enq2->me_firmware_id >> 8) & 0xff;
427     switch(sc->mlx_iftype) {
428     case MLX_IFTYPE_2:
429 	/* These controllers don't report the firmware version in the ENQUIRY2 response */
430 	if ((meo = mlx_enquire(sc, MLX_CMD_ENQUIRY_OLD, sizeof(struct mlx_enquiry_old), NULL)) == NULL) {
431 	    device_printf(sc->mlx_dev, "ENQUIRY_OLD failed\n");
432 	    mlx_free(sc);
433 	    return(ENXIO);
434 	}
435 	sc->mlx_enq2->me_firmware_id = ('0' << 24) | (0 << 16) | (meo->me_fwminor << 8) | meo->me_fwmajor;
436 	free(meo, M_DEVBUF);
437 
438 	/* XXX require 2.42 or better (PCI) or 2.14 or better (EISA) */
439 	if (meo->me_fwminor < 42) {
440 	    device_printf(sc->mlx_dev, " *** WARNING *** This firmware revision is not recommended\n");
441 	    device_printf(sc->mlx_dev, " *** WARNING *** Use revision 2.42 or later\n");
442 	}
443 	break;
444     case MLX_IFTYPE_3:
445 	/* XXX certify 3.52? */
446 	if (fwminor < 51) {
447 	    device_printf(sc->mlx_dev, " *** WARNING *** This firmware revision is not recommended\n");
448 	    device_printf(sc->mlx_dev, " *** WARNING *** Use revision 3.51 or later\n");
449 	}
450 	break;
451     case MLX_IFTYPE_4:
452 	/* XXX certify firmware versions? */
453 	if (fwminor < 6) {
454 	    device_printf(sc->mlx_dev, " *** WARNING *** This firmware revision is not recommended\n");
455 	    device_printf(sc->mlx_dev, " *** WARNING *** Use revision 4.06 or later\n");
456 	}
457 	break;
458     case MLX_IFTYPE_5:
459 	if (fwminor < 7) {
460 	    device_printf(sc->mlx_dev, " *** WARNING *** This firmware revision is not recommended\n");
461 	    device_printf(sc->mlx_dev, " *** WARNING *** Use revision 5.07 or later\n");
462 	}
463 	break;
464     default:
465 	mlx_free(sc);
466 	return(ENXIO);		/* should never happen */
467     }
468 
469     /*
470      * Create the final scatter/gather mappings now that we have characterised the controller.
471      */
472     error = mlx_sglist_map(sc);
473     if (error != 0) {
474 	device_printf(sc->mlx_dev, "can't make final s/g list mapping\n");
475 	mlx_free(sc);
476 	return(error);
477     }
478 
479     /*
480      * No user-requested background operation is in progress.
481      */
482     sc->mlx_background = 0;
483     sc->mlx_rebuildstat.rs_code = MLX_REBUILDSTAT_IDLE;
484 
485     /*
486      * Create the control device.
487      */
488     cdevsw_add(&mlx_cdevsw, -1, device_get_unit(sc->mlx_dev));
489     make_dev(&mlx_cdevsw, device_get_unit(sc->mlx_dev),
490 	    UID_ROOT, GID_OPERATOR, S_IRUSR | S_IWUSR,
491 	    "mlx%d", device_get_unit(sc->mlx_dev));
492 
493     /*
494      * Start the timeout routine.
495      */
496     callout_reset(&sc->mlx_timeout, hz, mlx_periodic, sc);
497 
498     /* print a little information about the controller */
499     mlx_describe_controller(sc);
500 
501     return(0);
502 }
503 
504 /********************************************************************************
505  * Locate disk resources and attach children to them.
506  */
507 void
508 mlx_startup(struct mlx_softc *sc)
509 {
510     struct mlx_enq_sys_drive	*mes;
511     struct mlx_sysdrive		*dr;
512     int				i, error;
513 
514     debug_called(1);
515 
516     /*
517      * Scan all the system drives and attach children for those that
518      * don't currently have them.
519      */
520     mes = mlx_enquire(sc, MLX_CMD_ENQSYSDRIVE, sizeof(*mes) * MLX_MAXDRIVES, NULL);
521     if (mes == NULL) {
522 	device_printf(sc->mlx_dev, "error fetching drive status\n");
523 	return;
524     }
525 
526     /* iterate over drives returned */
527     for (i = 0, dr = &sc->mlx_sysdrive[0];
528 	 (i < MLX_MAXDRIVES) && (mes[i].sd_size != 0xffffffff);
529 	 i++, dr++) {
530 	/* are we already attached to this drive? */
531     	if (dr->ms_disk == 0) {
532 	    /* pick up drive information */
533 	    dr->ms_size = mes[i].sd_size;
534 	    dr->ms_raidlevel = mes[i].sd_raidlevel & 0xf;
535 	    dr->ms_state = mes[i].sd_state;
536 
537 	    /* generate geometry information */
538 	    if (sc->mlx_geom == MLX_GEOM_128_32) {
539 		dr->ms_heads = 128;
540 		dr->ms_sectors = 32;
541 		dr->ms_cylinders = dr->ms_size / (128 * 32);
542 	    } else {        /* MLX_GEOM_255/63 */
543 		dr->ms_heads = 255;
544 		dr->ms_sectors = 63;
545 		dr->ms_cylinders = dr->ms_size / (255 * 63);
546 	    }
547 	    dr->ms_disk =  device_add_child(sc->mlx_dev, /*"mlxd"*/NULL, -1);
548 	    if (dr->ms_disk == 0)
549 		device_printf(sc->mlx_dev, "device_add_child failed\n");
550 	    device_set_ivars(dr->ms_disk, dr);
551 	}
552     }
553     free(mes, M_DEVBUF);
554     if ((error = bus_generic_attach(sc->mlx_dev)) != 0)
555 	device_printf(sc->mlx_dev, "bus_generic_attach returned %d", error);
556 
557     /* mark controller back up */
558     sc->mlx_state &= ~MLX_STATE_SHUTDOWN;
559 
560     /* enable interrupts */
561     sc->mlx_intaction(sc, MLX_INTACTION_ENABLE);
562 }
563 
564 /********************************************************************************
565  * Disconnect from the controller completely, in preparation for unload.
566  */
567 int
568 mlx_detach(device_t dev)
569 {
570     struct mlx_softc	*sc = device_get_softc(dev);
571     struct mlxd_softc	*mlxd;
572     int			i, error;
573 
574     debug_called(1);
575 
576     error = EBUSY;
577     crit_enter();
578     if (sc->mlx_state & MLX_STATE_OPEN)
579 	goto out;
580 
581     for (i = 0; i < MLX_MAXDRIVES; i++) {
582 	if (sc->mlx_sysdrive[i].ms_disk != 0) {
583 	    mlxd = device_get_softc(sc->mlx_sysdrive[i].ms_disk);
584 	    if (mlxd->mlxd_flags & MLXD_OPEN) {		/* drive is mounted, abort detach */
585 		device_printf(sc->mlx_sysdrive[i].ms_disk, "still open, can't detach\n");
586 		goto out;
587 	    }
588 	}
589     }
590     if ((error = mlx_shutdown(dev)))
591 	goto out;
592 
593     mlx_free(sc);
594 
595     error = 0;
596  out:
597     crit_exit();
598     return(error);
599 }
600 
601 /********************************************************************************
602  * Bring the controller down to a dormant state and detach all child devices.
603  *
604  * This function is called before detach, system shutdown, or before performing
605  * an operation which may add or delete system disks.  (Call mlx_startup to
606  * resume normal operation.)
607  *
608  * Note that we can assume that the bioq on the controller is empty, as we won't
609  * allow shutdown if any device is open.
610  */
611 int
612 mlx_shutdown(device_t dev)
613 {
614     struct mlx_softc	*sc = device_get_softc(dev);
615     int			i, error;
616 
617     debug_called(1);
618 
619     crit_enter();
620     error = 0;
621 
622     sc->mlx_state |= MLX_STATE_SHUTDOWN;
623     sc->mlx_intaction(sc, MLX_INTACTION_DISABLE);
624 
625     /* flush controller */
626     device_printf(sc->mlx_dev, "flushing cache...");
627     if (mlx_flush(sc)) {
628 	printf("failed\n");
629     } else {
630 	printf("done\n");
631     }
632 
633     /* delete all our child devices */
634     for (i = 0; i < MLX_MAXDRIVES; i++) {
635 	if (sc->mlx_sysdrive[i].ms_disk != 0) {
636 	    if ((error = device_delete_child(sc->mlx_dev, sc->mlx_sysdrive[i].ms_disk)) != 0)
637 		goto out;
638 	    sc->mlx_sysdrive[i].ms_disk = 0;
639 	}
640     }
641 
642  out:
643     crit_exit();
644     return(error);
645 }
646 
647 /********************************************************************************
648  * Bring the controller to a quiescent state, ready for system suspend.
649  */
650 int
651 mlx_suspend(device_t dev)
652 {
653     struct mlx_softc	*sc = device_get_softc(dev);
654 
655     debug_called(1);
656 
657     crit_enter();
658     sc->mlx_state |= MLX_STATE_SUSPEND;
659 
660     /* flush controller */
661     device_printf(sc->mlx_dev, "flushing cache...");
662     printf("%s\n", mlx_flush(sc) ? "failed" : "done");
663 
664     sc->mlx_intaction(sc, MLX_INTACTION_DISABLE);
665     crit_exit();
666 
667     return(0);
668 }
669 
670 /********************************************************************************
671  * Bring the controller back to a state ready for operation.
672  */
673 int
674 mlx_resume(device_t dev)
675 {
676     struct mlx_softc	*sc = device_get_softc(dev);
677 
678     debug_called(1);
679 
680     sc->mlx_state &= ~MLX_STATE_SUSPEND;
681     sc->mlx_intaction(sc, MLX_INTACTION_ENABLE);
682 
683     return(0);
684 }
685 
686 /*******************************************************************************
687  * Take an interrupt, or be poked by other code to look for interrupt-worthy
688  * status.
689  */
690 void
691 mlx_intr(void *arg)
692 {
693     struct mlx_softc	*sc = (struct mlx_softc *)arg;
694 
695     debug_called(1);
696 
697     /* collect finished commands, queue anything waiting */
698     mlx_done(sc);
699 };
700 
701 /*******************************************************************************
702  * Receive a buf structure from a child device and queue it on a particular
703  * disk resource, then poke the disk resource to start as much work as it can.
704  */
705 int
706 mlx_submit_buf(struct mlx_softc *sc, mlx_bio *bp)
707 {
708     debug_called(1);
709 
710     crit_enter();
711     MLX_BIO_QINSERT(sc->mlx_bioq, bp);
712     sc->mlx_waitbufs++;
713     crit_exit();
714     mlx_startio(sc);
715     return(0);
716 }
717 
718 /********************************************************************************
719  * Accept an open operation on the control device.
720  */
721 int
722 mlx_open(dev_t dev, int flags, int fmt, d_thread_t *td)
723 {
724     int			unit = minor(dev);
725     struct mlx_softc	*sc = devclass_get_softc(mlx_devclass, unit);
726 
727     sc->mlx_state |= MLX_STATE_OPEN;
728     return(0);
729 }
730 
731 /********************************************************************************
732  * Accept the last close on the control device.
733  */
734 int
735 mlx_close(dev_t dev, int flags, int fmt, d_thread_t *td)
736 {
737     int			unit = minor(dev);
738     struct mlx_softc	*sc = devclass_get_softc(mlx_devclass, unit);
739 
740     sc->mlx_state &= ~MLX_STATE_OPEN;
741     return (0);
742 }
743 
744 /********************************************************************************
745  * Handle controller-specific control operations.
746  */
747 int
748 mlx_ioctl(dev_t dev, u_long cmd, caddr_t addr, int32_t flag, d_thread_t *td)
749 {
750     int				unit = minor(dev);
751     struct mlx_softc		*sc = devclass_get_softc(mlx_devclass, unit);
752     struct mlx_rebuild_request	*rb = (struct mlx_rebuild_request *)addr;
753     struct mlx_rebuild_status	*rs = (struct mlx_rebuild_status *)addr;
754     int				*arg = (int *)addr;
755     struct mlx_pause		*mp;
756     struct mlx_sysdrive		*dr;
757     struct mlxd_softc		*mlxd;
758     int				i, error;
759 
760     switch(cmd) {
761 	/*
762 	 * Enumerate connected system drives; returns the first system drive's
763 	 * unit number if *arg is -1, or the next unit after *arg if it's
764 	 * a valid unit on this controller.
765 	 */
766     case MLX_NEXT_CHILD:
767 	/* search system drives */
768 	for (i = 0; i < MLX_MAXDRIVES; i++) {
769 	    /* is this one attached? */
770 	    if (sc->mlx_sysdrive[i].ms_disk != 0) {
771 		/* looking for the next one we come across? */
772 		if (*arg == -1) {
773 		    *arg = device_get_unit(sc->mlx_sysdrive[0].ms_disk);
774 		    return(0);
775 		}
776 		/* we want the one after this one */
777 		if (*arg == device_get_unit(sc->mlx_sysdrive[i].ms_disk))
778 		    *arg = -1;
779 	    }
780 	}
781 	return(ENOENT);
782 
783 	/*
784 	 * Scan the controller to see whether new drives have appeared.
785 	 */
786     case MLX_RESCAN_DRIVES:
787 	mlx_startup(sc);
788 	return(0);
789 
790 	/*
791 	 * Disconnect from the specified drive; it may be about to go
792 	 * away.
793 	 */
794     case MLX_DETACH_DRIVE:			/* detach one drive */
795 
796 	if (((dr = mlx_findunit(sc, *arg)) == NULL) ||
797 	    ((mlxd = device_get_softc(dr->ms_disk)) == NULL))
798 	    return(ENOENT);
799 
800 	device_printf(dr->ms_disk, "detaching...");
801 	error = 0;
802 	if (mlxd->mlxd_flags & MLXD_OPEN) {
803 	    error = EBUSY;
804 	    goto detach_out;
805 	}
806 
807 	/* flush controller */
808 	if (mlx_flush(sc)) {
809 	    error = EBUSY;
810 	    goto detach_out;
811 	}
812 
813 	/* nuke drive */
814 	if ((error = device_delete_child(sc->mlx_dev, dr->ms_disk)) != 0)
815 	    goto detach_out;
816 	dr->ms_disk = 0;
817 
818     detach_out:
819 	if (error) {
820 	    printf("failed\n");
821 	} else {
822 	    printf("done\n");
823 	}
824 	return(error);
825 
826 	/*
827 	 * Pause one or more SCSI channels for a period of time, to assist
828 	 * in the process of hot-swapping devices.
829 	 *
830 	 * Note that at least the 3.51 firmware on the DAC960PL doesn't seem
831 	 * to do this right.
832 	 */
833     case MLX_PAUSE_CHANNEL:			/* schedule a channel pause */
834 	/* Does this command work on this firmware? */
835 	if (!(sc->mlx_feature & MLX_FEAT_PAUSEWORKS))
836 	    return(EOPNOTSUPP);
837 
838 	mp = (struct mlx_pause *)addr;
839 	if ((mp->mp_which == MLX_PAUSE_CANCEL) && (sc->mlx_pause.mp_when != 0)) {
840 	    /* cancel a pending pause operation */
841 	    sc->mlx_pause.mp_which = 0;
842 	} else {
843 	    /* fix for legal channels */
844 	    mp->mp_which &= ((1 << sc->mlx_enq2->me_actual_channels) -1);
845 	    /* check time values */
846 	    if ((mp->mp_when < 0) || (mp->mp_when > 3600))
847 		return(EINVAL);
848 	    if ((mp->mp_howlong < 1) || (mp->mp_howlong > (0xf * 30)))
849 		return(EINVAL);
850 
851 	    /* check for a pause currently running */
852 	    if ((sc->mlx_pause.mp_which != 0) && (sc->mlx_pause.mp_when == 0))
853 		return(EBUSY);
854 
855 	    /* looks ok, go with it */
856 	    sc->mlx_pause.mp_which = mp->mp_which;
857 	    sc->mlx_pause.mp_when = time_second + mp->mp_when;
858 	    sc->mlx_pause.mp_howlong = sc->mlx_pause.mp_when + mp->mp_howlong;
859 	}
860 	return(0);
861 
862 	/*
863 	 * Accept a command passthrough-style.
864 	 */
865     case MLX_COMMAND:
866 	return(mlx_user_command(sc, (struct mlx_usercommand *)addr));
867 
868 	/*
869 	 * Start a rebuild on a given SCSI disk
870 	 */
871     case MLX_REBUILDASYNC:
872 	if (sc->mlx_background != 0) {
873 	    rb->rr_status = 0x0106;
874 	    return(EBUSY);
875 	}
876 	rb->rr_status = mlx_rebuild(sc, rb->rr_channel, rb->rr_target);
877 	switch (rb->rr_status) {
878 	case 0:
879 	    error = 0;
880 	    break;
881 	case 0x10000:
882 	    error = ENOMEM;		/* couldn't set up the command */
883 	    break;
884 	case 0x0002:
885 	    error = EBUSY;
886 	    break;
887 	case 0x0104:
888 	    error = EIO;
889 	    break;
890 	case 0x0105:
891 	    error = ERANGE;
892 	    break;
893 	case 0x0106:
894 	    error = EBUSY;
895 	    break;
896 	default:
897 	    error = EINVAL;
898 	    break;
899 	}
900 	if (error == 0)
901 	    sc->mlx_background = MLX_BACKGROUND_REBUILD;
902 	return(error);
903 
904 	/*
905 	 * Get the status of the current rebuild or consistency check.
906 	 */
907     case MLX_REBUILDSTAT:
908 	*rs = sc->mlx_rebuildstat;
909 	return(0);
910 
911 	/*
912 	 * Return the per-controller system drive number matching the
913 	 * disk device number in (arg), if it happens to belong to us.
914 	 */
915     case MLX_GET_SYSDRIVE:
916 	error = ENOENT;
917 	mlxd = (struct mlxd_softc *)devclass_get_softc(mlxd_devclass, *arg);
918 	if ((mlxd != NULL) && (mlxd->mlxd_drive >= sc->mlx_sysdrive) &&
919 	    (mlxd->mlxd_drive < (sc->mlx_sysdrive + MLX_MAXDRIVES))) {
920 	    error = 0;
921 	    *arg = mlxd->mlxd_drive - sc->mlx_sysdrive;
922 	}
923 	return(error);
924 
925     default:
926 	return(ENOTTY);
927     }
928 }
929 
930 /********************************************************************************
931  * Handle operations requested by a System Drive connected to this controller.
932  */
933 int
934 mlx_submit_ioctl(struct mlx_softc *sc, struct mlx_sysdrive *drive, u_long cmd,
935 		caddr_t addr, int32_t flag, d_thread_t *td)
936 {
937     int				*arg = (int *)addr;
938     int				error, result;
939 
940     switch(cmd) {
941 	/*
942 	 * Return the current status of this drive.
943 	 */
944     case MLXD_STATUS:
945 	*arg = drive->ms_state;
946 	return(0);
947 
948 	/*
949 	 * Start a background consistency check on this drive.
950 	 */
951     case MLXD_CHECKASYNC:		/* start a background consistency check */
952 	if (sc->mlx_background != 0) {
953 	    *arg = 0x0106;
954 	    return(EBUSY);
955 	}
956 	result = mlx_check(sc, drive - &sc->mlx_sysdrive[0]);
957 	switch (result) {
958 	case 0:
959 	    error = 0;
960 	    break;
961 	case 0x10000:
962 	    error = ENOMEM;		/* couldn't set up the command */
963 	    break;
964 	case 0x0002:
965 	    error = EIO;
966 	    break;
967 	case 0x0105:
968 	    error = ERANGE;
969 	    break;
970 	case 0x0106:
971 	    error = EBUSY;
972 	    break;
973 	default:
974 	    error = EINVAL;
975 	    break;
976 	}
977 	if (error == 0)
978 	    sc->mlx_background = MLX_BACKGROUND_CHECK;
979 	*arg = result;
980 	return(error);
981 
982     }
983     return(ENOIOCTL);
984 }
985 
986 
987 /********************************************************************************
988  ********************************************************************************
989                                                                 Status Monitoring
990  ********************************************************************************
991  ********************************************************************************/
992 
993 /********************************************************************************
994  * Fire off commands to periodically check the status of connected drives.
995  */
996 static void
997 mlx_periodic(void *data)
998 {
999     struct mlx_softc *sc = (struct mlx_softc *)data;
1000 
1001     debug_called(1);
1002 
1003     /*
1004      * Run a bus pause?
1005      */
1006     if ((sc->mlx_pause.mp_which != 0) &&
1007 	(sc->mlx_pause.mp_when > 0) &&
1008 	(time_second >= sc->mlx_pause.mp_when)){
1009 
1010 	mlx_pause_action(sc);		/* pause is running */
1011 	sc->mlx_pause.mp_when = 0;
1012 	sysbeep(500, hz);
1013 
1014 	/*
1015 	 * Bus pause still running?
1016 	 */
1017     } else if ((sc->mlx_pause.mp_which != 0) &&
1018 	       (sc->mlx_pause.mp_when == 0)) {
1019 
1020 	/* time to stop bus pause? */
1021 	if (time_second >= sc->mlx_pause.mp_howlong) {
1022 	    mlx_pause_action(sc);
1023 	    sc->mlx_pause.mp_which = 0;	/* pause is complete */
1024 	    sysbeep(500, hz);
1025 	} else {
1026 	    sysbeep((time_second % 5) * 100 + 500, hz/8);
1027 	}
1028 
1029 	/*
1030 	 * Run normal periodic activities?
1031 	 */
1032     } else if (time_second > (sc->mlx_lastpoll + 10)) {
1033 	sc->mlx_lastpoll = time_second;
1034 
1035 	/*
1036 	 * Check controller status.
1037 	 *
1038 	 * XXX Note that this may not actually launch a command in situations of high load.
1039 	 */
1040 	mlx_enquire(sc, (sc->mlx_iftype == MLX_IFTYPE_2) ? MLX_CMD_ENQUIRY_OLD : MLX_CMD_ENQUIRY,
1041 		    imax(sizeof(struct mlx_enquiry), sizeof(struct mlx_enquiry_old)), mlx_periodic_enquiry);
1042 
1043 	/*
1044 	 * Check system drive status.
1045 	 *
1046 	 * XXX This might be better left to event-driven detection, eg. I/O to an offline
1047 	 *     drive will detect it's offline, rebuilds etc. should detect the drive is back
1048 	 *     online.
1049 	 */
1050 	mlx_enquire(sc, MLX_CMD_ENQSYSDRIVE, sizeof(struct mlx_enq_sys_drive) * MLX_MAXDRIVES,
1051 			mlx_periodic_enquiry);
1052 
1053     }
1054 
1055     /* get drive rebuild/check status */
1056     /* XXX should check sc->mlx_background if this is only valid while in progress */
1057     mlx_enquire(sc, MLX_CMD_REBUILDSTAT, sizeof(struct mlx_rebuild_stat), mlx_periodic_rebuild);
1058 
1059     /* deal with possibly-missed interrupts and timed-out commands */
1060     mlx_done(sc);
1061 
1062     /* reschedule another poll next second or so */
1063     callout_reset(&sc->mlx_timeout, hz, mlx_periodic, sc);
1064 }
1065 
1066 /********************************************************************************
1067  * Handle the result of an ENQUIRY command instigated by periodic status polling.
1068  */
1069 static void
1070 mlx_periodic_enquiry(struct mlx_command *mc)
1071 {
1072     struct mlx_softc		*sc = mc->mc_sc;
1073 
1074     debug_called(1);
1075 
1076     /* Command completed OK? */
1077     if (mc->mc_status != 0) {
1078 	device_printf(sc->mlx_dev, "periodic enquiry failed - %s\n", mlx_diagnose_command(mc));
1079 	goto out;
1080     }
1081 
1082     /* respond to command */
1083     switch(mc->mc_mailbox[0]) {
1084 	/*
1085 	 * This is currently a bit fruitless, as we don't know how to extract the eventlog
1086 	 * pointer yet.
1087 	 */
1088     case MLX_CMD_ENQUIRY_OLD:
1089     {
1090 	struct mlx_enquiry		*me = (struct mlx_enquiry *)mc->mc_data;
1091 	struct mlx_enquiry_old		*meo = (struct mlx_enquiry_old *)mc->mc_data;
1092 	int				i;
1093 
1094 	/* convert data in-place to new format */
1095 	for (i = (sizeof(me->me_dead) / sizeof(me->me_dead[0])) - 1; i >= 0; i--) {
1096 	    me->me_dead[i].dd_chan = meo->me_dead[i].dd_chan;
1097 	    me->me_dead[i].dd_targ = meo->me_dead[i].dd_targ;
1098 	}
1099 	me->me_misc_flags        = 0;
1100 	me->me_rebuild_count     = meo->me_rebuild_count;
1101 	me->me_dead_count        = meo->me_dead_count;
1102 	me->me_critical_sd_count = meo->me_critical_sd_count;
1103 	me->me_event_log_seq_num = 0;
1104 	me->me_offline_sd_count  = meo->me_offline_sd_count;
1105 	me->me_max_commands      = meo->me_max_commands;
1106 	me->me_rebuild_flag      = meo->me_rebuild_flag;
1107 	me->me_fwmajor           = meo->me_fwmajor;
1108 	me->me_fwminor           = meo->me_fwminor;
1109 	me->me_status_flags      = meo->me_status_flags;
1110 	me->me_flash_age         = meo->me_flash_age;
1111 	for (i = (sizeof(me->me_drvsize) / sizeof(me->me_drvsize[0])) - 1; i >= 0; i--) {
1112 	    if (i > ((sizeof(meo->me_drvsize) / sizeof(meo->me_drvsize[0])) - 1)) {
1113 		me->me_drvsize[i] = 0;		/* drive beyond supported range */
1114 	    } else {
1115 		me->me_drvsize[i] = meo->me_drvsize[i];
1116 	    }
1117 	}
1118 	me->me_num_sys_drvs = meo->me_num_sys_drvs;
1119     }
1120     /* FALLTHROUGH */
1121 
1122 	/*
1123 	 * Generic controller status update.  We could do more with this than just
1124 	 * checking the event log.
1125 	 */
1126     case MLX_CMD_ENQUIRY:
1127     {
1128 	struct mlx_enquiry		*me = (struct mlx_enquiry *)mc->mc_data;
1129 
1130 	if (sc->mlx_currevent == -1) {
1131 	    /* initialise our view of the event log */
1132 	    sc->mlx_currevent = sc->mlx_lastevent = me->me_event_log_seq_num;
1133 	} else if ((me->me_event_log_seq_num != sc->mlx_lastevent) && !(sc->mlx_flags & MLX_EVENTLOG_BUSY)) {
1134 	    /* record where current events are up to */
1135 	    sc->mlx_currevent = me->me_event_log_seq_num;
1136 	    debug(1, "event log pointer was %d, now %d\n", sc->mlx_lastevent, sc->mlx_currevent);
1137 
1138 	    /* mark the event log as busy */
1139 	    atomic_set_int(&sc->mlx_flags, MLX_EVENTLOG_BUSY);
1140 
1141 	    /* drain new eventlog entries */
1142 	    mlx_periodic_eventlog_poll(sc);
1143 	}
1144 	break;
1145     }
1146     case MLX_CMD_ENQSYSDRIVE:
1147     {
1148 	struct mlx_enq_sys_drive	*mes = (struct mlx_enq_sys_drive *)mc->mc_data;
1149 	struct mlx_sysdrive		*dr;
1150 	int				i;
1151 
1152 	for (i = 0, dr = &sc->mlx_sysdrive[0];
1153 	     (i < MLX_MAXDRIVES) && (mes[i].sd_size != 0xffffffff);
1154 	     i++) {
1155 
1156 	    /* has state been changed by controller? */
1157 	    if (dr->ms_state != mes[i].sd_state) {
1158 		switch(mes[i].sd_state) {
1159 		case MLX_SYSD_OFFLINE:
1160 		    device_printf(dr->ms_disk, "drive offline\n");
1161 		    break;
1162 		case MLX_SYSD_ONLINE:
1163 		    device_printf(dr->ms_disk, "drive online\n");
1164 		    break;
1165 		case MLX_SYSD_CRITICAL:
1166 		    device_printf(dr->ms_disk, "drive critical\n");
1167 		    break;
1168 		}
1169 		/* save new state */
1170 		dr->ms_state = mes[i].sd_state;
1171 	    }
1172 	}
1173 	break;
1174     }
1175     default:
1176 	device_printf(sc->mlx_dev, "%s: unknown command 0x%x", __func__, mc->mc_mailbox[0]);
1177 	break;
1178     }
1179 
1180  out:
1181     free(mc->mc_data, M_DEVBUF);
1182     mlx_releasecmd(mc);
1183 }
1184 
1185 /********************************************************************************
1186  * Instigate a poll for one event log message on (sc).
1187  * We only poll for one message at a time, to keep our command usage down.
1188  */
1189 static void
1190 mlx_periodic_eventlog_poll(struct mlx_softc *sc)
1191 {
1192     struct mlx_command	*mc;
1193     void		*result = NULL;
1194     int			error;
1195 
1196     debug_called(1);
1197 
1198     /* get ourselves a command buffer */
1199     error = 1;
1200     if ((mc = mlx_alloccmd(sc)) == NULL)
1201 	goto out;
1202     /*
1203      * allocate the response structure - sizeof(struct mlx_eventlog_entry)?
1204      * Called from timeout - use M_NOWAIT (repoll later on failure?)
1205      */
1206     if ((result = malloc(1024, M_DEVBUF, M_NOWAIT)) == NULL)
1207 	goto out;
1208     /* get a command slot */
1209     if (mlx_getslot(mc))
1210 	goto out;
1211 
1212     /* map the command so the controller can see it */
1213     mc->mc_data = result;
1214     mc->mc_length = /*sizeof(struct mlx_eventlog_entry)*/1024;
1215     mlx_mapcmd(mc);
1216 
1217     /* build the command to get one entry */
1218     mlx_make_type3(mc, MLX_CMD_LOGOP, MLX_LOGOP_GET, 1, sc->mlx_lastevent, 0, 0, mc->mc_dataphys, 0);
1219     mc->mc_complete = mlx_periodic_eventlog_respond;
1220     mc->mc_private = mc;
1221 
1222     /* start the command */
1223     if ((error = mlx_start(mc)) != 0)
1224 	goto out;
1225 
1226     error = 0;			/* success */
1227  out:
1228     if (error != 0) {
1229 	if (mc != NULL)
1230 	    mlx_releasecmd(mc);
1231 	if (result != NULL)
1232 	    free(result, M_DEVBUF);
1233     }
1234 }
1235 
1236 /********************************************************************************
1237  * Handle the result of polling for a log message, generate diagnostic output.
1238  * If this wasn't the last message waiting for us, we'll go collect another.
1239  */
1240 static char *mlx_sense_messages[] = {
1241     "because write recovery failed",
1242     "because of SCSI bus reset failure",
1243     "because of double check condition",
1244     "because it was removed",
1245     "because of gross error on SCSI chip",
1246     "because of bad tag returned from drive",
1247     "because of timeout on SCSI command",
1248     "because of reset SCSI command issued from system",
1249     "because busy or parity error count exceeded limit",
1250     "because of 'kill drive' command from system",
1251     "because of selection timeout",
1252     "due to SCSI phase sequence error",
1253     "due to unknown status"
1254 };
1255 
1256 static void
1257 mlx_periodic_eventlog_respond(struct mlx_command *mc)
1258 {
1259     struct mlx_softc		*sc = mc->mc_sc;
1260     struct mlx_eventlog_entry	*el = (struct mlx_eventlog_entry *)mc->mc_data;
1261     char			*reason;
1262 
1263     debug_called(1);
1264 
1265     sc->mlx_lastevent++;		/* next message... */
1266     if (mc->mc_status == 0) {
1267 
1268 	/* handle event log message */
1269 	switch(el->el_type) {
1270 	    /*
1271 	     * This is the only sort of message we understand at the moment.
1272 	     * The tests here are probably incomplete.
1273 	     */
1274 	case MLX_LOGMSG_SENSE:	/* sense data */
1275 	    /* Mylex vendor-specific message indicating a drive was killed? */
1276 	    if ((el->el_sensekey == 9) &&
1277 		(el->el_asc == 0x80)) {
1278 		if (el->el_asq < (sizeof(mlx_sense_messages) / sizeof(mlx_sense_messages[0]))) {
1279 		    reason = mlx_sense_messages[el->el_asq];
1280 		} else {
1281 		    reason = "for unknown reason";
1282 		}
1283 		device_printf(sc->mlx_dev, "physical drive %d:%d killed %s\n",
1284 			      el->el_channel, el->el_target, reason);
1285 	    }
1286 	    /* SCSI drive was reset? */
1287 	    if ((el->el_sensekey == 6) && (el->el_asc == 0x29)) {
1288 		device_printf(sc->mlx_dev, "physical drive %d:%d reset\n",
1289 			      el->el_channel, el->el_target);
1290 	    }
1291 	    /* SCSI drive error? */
1292 	    if (!((el->el_sensekey == 0) ||
1293 		  ((el->el_sensekey == 2) &&
1294 		   (el->el_asc == 0x04) &&
1295 		   ((el->el_asq == 0x01) ||
1296 		    (el->el_asq == 0x02))))) {
1297 		device_printf(sc->mlx_dev, "physical drive %d:%d error log: sense = %d asc = %x asq = %x\n",
1298 			      el->el_channel, el->el_target, el->el_sensekey, el->el_asc, el->el_asq);
1299 		device_printf(sc->mlx_dev, "  info %4D csi %4D\n", el->el_information, ":", el->el_csi, ":");
1300 	    }
1301 	    break;
1302 
1303 	default:
1304 	    device_printf(sc->mlx_dev, "unknown log message type 0x%x\n", el->el_type);
1305 	    break;
1306 	}
1307     } else {
1308 	device_printf(sc->mlx_dev, "error reading message log - %s\n", mlx_diagnose_command(mc));
1309 	/* give up on all the outstanding messages, as we may have come unsynched */
1310 	sc->mlx_lastevent = sc->mlx_currevent;
1311     }
1312 
1313     /* dispose of command and data */
1314     free(mc->mc_data, M_DEVBUF);
1315     mlx_releasecmd(mc);
1316 
1317     /* is there another message to obtain? */
1318     if (sc->mlx_lastevent != sc->mlx_currevent) {
1319 	mlx_periodic_eventlog_poll(sc);
1320     } else {
1321 	/* clear log-busy status */
1322 	atomic_clear_int(&sc->mlx_flags, MLX_EVENTLOG_BUSY);
1323     }
1324 }
1325 
1326 /********************************************************************************
1327  * Handle check/rebuild operations in progress.
1328  */
1329 static void
1330 mlx_periodic_rebuild(struct mlx_command *mc)
1331 {
1332     struct mlx_softc		*sc = mc->mc_sc;
1333     struct mlx_rebuild_status	*mr = (struct mlx_rebuild_status *)mc->mc_data;
1334 
1335     switch(mc->mc_status) {
1336     case 0:				/* operation running, update stats */
1337 	sc->mlx_rebuildstat = *mr;
1338 
1339 	/* spontaneous rebuild/check? */
1340 	if (sc->mlx_background == 0) {
1341 	    sc->mlx_background = MLX_BACKGROUND_SPONTANEOUS;
1342 	    device_printf(sc->mlx_dev, "background check/rebuild operation started\n");
1343 	}
1344 	break;
1345 
1346     case 0x0105:			/* nothing running, finalise stats and report */
1347 	switch(sc->mlx_background) {
1348 	case MLX_BACKGROUND_CHECK:
1349 	    device_printf(sc->mlx_dev, "consistency check completed\n");	/* XXX print drive? */
1350 	    break;
1351 	case MLX_BACKGROUND_REBUILD:
1352 	    device_printf(sc->mlx_dev, "drive rebuild completed\n");	/* XXX print channel/target? */
1353 	    break;
1354 	case MLX_BACKGROUND_SPONTANEOUS:
1355 	default:
1356 	    /* if we have previously been non-idle, report the transition */
1357 	    if (sc->mlx_rebuildstat.rs_code != MLX_REBUILDSTAT_IDLE) {
1358 		device_printf(sc->mlx_dev, "background check/rebuild operation completed\n");
1359 	    }
1360 	}
1361 	sc->mlx_background = 0;
1362 	sc->mlx_rebuildstat.rs_code = MLX_REBUILDSTAT_IDLE;
1363 	break;
1364     }
1365     free(mc->mc_data, M_DEVBUF);
1366     mlx_releasecmd(mc);
1367 }
1368 
1369 /********************************************************************************
1370  ********************************************************************************
1371                                                                     Channel Pause
1372  ********************************************************************************
1373  ********************************************************************************/
1374 
1375 /********************************************************************************
1376  * It's time to perform a channel pause action for (sc), either start or stop
1377  * the pause.
1378  */
1379 static void
1380 mlx_pause_action(struct mlx_softc *sc)
1381 {
1382     struct mlx_command	*mc;
1383     int			failsafe, i, command;
1384 
1385     /* What are we doing here? */
1386     if (sc->mlx_pause.mp_when == 0) {
1387 	command = MLX_CMD_STARTCHANNEL;
1388 	failsafe = 0;
1389 
1390     } else {
1391 	command = MLX_CMD_STOPCHANNEL;
1392 
1393 	/*
1394 	 * Channels will always start again after the failsafe period,
1395 	 * which is specified in multiples of 30 seconds.
1396 	 * This constrains us to a maximum pause of 450 seconds.
1397 	 */
1398 	failsafe = ((sc->mlx_pause.mp_howlong - time_second) + 5) / 30;
1399 	if (failsafe > 0xf) {
1400 	    failsafe = 0xf;
1401 	    sc->mlx_pause.mp_howlong = time_second + (0xf * 30) - 5;
1402 	}
1403     }
1404 
1405     /* build commands for every channel requested */
1406     for (i = 0; i < sc->mlx_enq2->me_actual_channels; i++) {
1407 	if ((1 << i) & sc->mlx_pause.mp_which) {
1408 
1409 	    /* get ourselves a command buffer */
1410 	    if ((mc = mlx_alloccmd(sc)) == NULL)
1411 		goto fail;
1412 	    /* get a command slot */
1413 	    mc->mc_flags |= MLX_CMD_PRIORITY;
1414 	    if (mlx_getslot(mc))
1415 		goto fail;
1416 
1417 	    /* build the command */
1418 	    mlx_make_type2(mc, command, (failsafe << 4) | i, 0, 0, 0, 0, 0, 0, 0);
1419 	    mc->mc_complete = mlx_pause_done;
1420 	    mc->mc_private = sc;		/* XXX not needed */
1421 	    if (mlx_start(mc))
1422 		goto fail;
1423 	    /* command submitted OK */
1424 	    return;
1425 
1426 	fail:
1427 	    device_printf(sc->mlx_dev, "%s failed for channel %d\n",
1428 			  command == MLX_CMD_STOPCHANNEL ? "pause" : "resume", i);
1429 	    if (mc != NULL)
1430 		mlx_releasecmd(mc);
1431 	}
1432     }
1433 }
1434 
1435 static void
1436 mlx_pause_done(struct mlx_command *mc)
1437 {
1438     struct mlx_softc	*sc = mc->mc_sc;
1439     int			command = mc->mc_mailbox[0];
1440     int			channel = mc->mc_mailbox[2] & 0xf;
1441 
1442     if (mc->mc_status != 0) {
1443 	device_printf(sc->mlx_dev, "%s command failed - %s\n",
1444 		      command == MLX_CMD_STOPCHANNEL ? "pause" : "resume", mlx_diagnose_command(mc));
1445     } else if (command == MLX_CMD_STOPCHANNEL) {
1446 	device_printf(sc->mlx_dev, "channel %d pausing for %ld seconds\n",
1447 		      channel, (long)(sc->mlx_pause.mp_howlong - time_second));
1448     } else {
1449 	device_printf(sc->mlx_dev, "channel %d resuming\n", channel);
1450     }
1451     mlx_releasecmd(mc);
1452 }
1453 
1454 /********************************************************************************
1455  ********************************************************************************
1456                                                                Command Submission
1457  ********************************************************************************
1458  ********************************************************************************/
1459 
1460 /********************************************************************************
1461  * Perform an Enquiry command using a type-3 command buffer and a return a single
1462  * linear result buffer.  If the completion function is specified, it will
1463  * be called with the completed command (and the result response will not be
1464  * valid until that point).  Otherwise, the command will either be busy-waited
1465  * for (interrupts not enabled), or slept for.
1466  */
1467 static void *
1468 mlx_enquire(struct mlx_softc *sc, int command, size_t bufsize, void (* complete)(struct mlx_command *mc))
1469 {
1470     struct mlx_command	*mc;
1471     void		*result;
1472     int			error;
1473 
1474     debug_called(1);
1475 
1476     /* get ourselves a command buffer */
1477     error = 1;
1478     result = NULL;
1479     if ((mc = mlx_alloccmd(sc)) == NULL)
1480 	goto out;
1481     /* allocate the response structure */
1482     result = malloc(bufsize, M_DEVBUF, M_INTWAIT);
1483     /* get a command slot */
1484     mc->mc_flags |= MLX_CMD_PRIORITY | MLX_CMD_DATAOUT;
1485     if (mlx_getslot(mc))
1486 	goto out;
1487 
1488     /* map the command so the controller can see it */
1489     mc->mc_data = result;
1490     mc->mc_length = bufsize;
1491     mlx_mapcmd(mc);
1492 
1493     /* build an enquiry command */
1494     mlx_make_type2(mc, command, 0, 0, 0, 0, 0, 0, mc->mc_dataphys, 0);
1495 
1496     /* do we want a completion callback? */
1497     if (complete != NULL) {
1498 	mc->mc_complete = complete;
1499 	mc->mc_private = mc;
1500 	if ((error = mlx_start(mc)) != 0)
1501 	    goto out;
1502     } else {
1503 	/* run the command in either polled or wait mode */
1504 	if ((sc->mlx_state & MLX_STATE_INTEN) ? mlx_wait_command(mc) : mlx_poll_command(mc))
1505 	    goto out;
1506 
1507 	/* command completed OK? */
1508 	if (mc->mc_status != 0) {
1509 	    device_printf(sc->mlx_dev, "ENQUIRY failed - %s\n", mlx_diagnose_command(mc));
1510 	    goto out;
1511 	}
1512     }
1513     error = 0;			/* success */
1514  out:
1515     /* we got a command, but nobody else will free it */
1516     if ((complete == NULL) && (mc != NULL))
1517 	mlx_releasecmd(mc);
1518     /* we got an error, and we allocated a result */
1519     if ((error != 0) && (result != NULL)) {
1520 	free(result, M_DEVBUF);
1521 	result = NULL;
1522     }
1523     return(result);
1524 }
1525 
1526 
1527 /********************************************************************************
1528  * Perform a Flush command on the nominated controller.
1529  *
1530  * May be called with interrupts enabled or disabled; will not return until
1531  * the flush operation completes or fails.
1532  */
1533 static int
1534 mlx_flush(struct mlx_softc *sc)
1535 {
1536     struct mlx_command	*mc;
1537     int			error;
1538 
1539     debug_called(1);
1540 
1541     /* get ourselves a command buffer */
1542     error = 1;
1543     if ((mc = mlx_alloccmd(sc)) == NULL)
1544 	goto out;
1545     /* get a command slot */
1546     if (mlx_getslot(mc))
1547 	goto out;
1548 
1549     /* build a flush command */
1550     mlx_make_type2(mc, MLX_CMD_FLUSH, 0, 0, 0, 0, 0, 0, 0, 0);
1551 
1552     /* can't assume that interrupts are going to work here, so play it safe */
1553     if (mlx_poll_command(mc))
1554 	goto out;
1555 
1556     /* command completed OK? */
1557     if (mc->mc_status != 0) {
1558 	device_printf(sc->mlx_dev, "FLUSH failed - %s\n", mlx_diagnose_command(mc));
1559 	goto out;
1560     }
1561 
1562     error = 0;			/* success */
1563  out:
1564     if (mc != NULL)
1565 	mlx_releasecmd(mc);
1566     return(error);
1567 }
1568 
1569 /********************************************************************************
1570  * Start a background consistency check on (drive).
1571  *
1572  * May be called with interrupts enabled or disabled; will return as soon as the
1573  * operation has started or been refused.
1574  */
1575 static int
1576 mlx_check(struct mlx_softc *sc, int drive)
1577 {
1578     struct mlx_command	*mc;
1579     int			error;
1580 
1581     debug_called(1);
1582 
1583     /* get ourselves a command buffer */
1584     error = 0x10000;
1585     if ((mc = mlx_alloccmd(sc)) == NULL)
1586 	goto out;
1587     /* get a command slot */
1588     if (mlx_getslot(mc))
1589 	goto out;
1590 
1591     /* build a checkasync command, set the "fix it" flag */
1592     mlx_make_type2(mc, MLX_CMD_CHECKASYNC, 0, 0, 0, 0, 0, drive | 0x80, 0, 0);
1593 
1594     /* start the command and wait for it to be returned */
1595     if (mlx_wait_command(mc))
1596 	goto out;
1597 
1598     /* command completed OK? */
1599     if (mc->mc_status != 0) {
1600 	device_printf(sc->mlx_dev, "CHECK ASYNC failed - %s\n", mlx_diagnose_command(mc));
1601     } else {
1602 	device_printf(sc->mlx_sysdrive[drive].ms_disk, "consistency check started");
1603     }
1604     error = mc->mc_status;
1605 
1606  out:
1607     if (mc != NULL)
1608 	mlx_releasecmd(mc);
1609     return(error);
1610 }
1611 
1612 /********************************************************************************
1613  * Start a background rebuild of the physical drive at (channel),(target).
1614  *
1615  * May be called with interrupts enabled or disabled; will return as soon as the
1616  * operation has started or been refused.
1617  */
1618 static int
1619 mlx_rebuild(struct mlx_softc *sc, int channel, int target)
1620 {
1621     struct mlx_command	*mc;
1622     int			error;
1623 
1624     debug_called(1);
1625 
1626     /* get ourselves a command buffer */
1627     error = 0x10000;
1628     if ((mc = mlx_alloccmd(sc)) == NULL)
1629 	goto out;
1630     /* get a command slot */
1631     if (mlx_getslot(mc))
1632 	goto out;
1633 
1634     /* build a checkasync command, set the "fix it" flag */
1635     mlx_make_type2(mc, MLX_CMD_REBUILDASYNC, channel, target, 0, 0, 0, 0, 0, 0);
1636 
1637     /* start the command and wait for it to be returned */
1638     if (mlx_wait_command(mc))
1639 	goto out;
1640 
1641     /* command completed OK? */
1642     if (mc->mc_status != 0) {
1643 	device_printf(sc->mlx_dev, "REBUILD ASYNC failed - %s\n", mlx_diagnose_command(mc));
1644     } else {
1645 	device_printf(sc->mlx_dev, "drive rebuild started for %d:%d\n", channel, target);
1646     }
1647     error = mc->mc_status;
1648 
1649  out:
1650     if (mc != NULL)
1651 	mlx_releasecmd(mc);
1652     return(error);
1653 }
1654 
1655 /********************************************************************************
1656  * Run the command (mc) and return when it completes.
1657  *
1658  * Interrupts need to be enabled; returns nonzero on error.
1659  */
1660 static int
1661 mlx_wait_command(struct mlx_command *mc)
1662 {
1663     struct mlx_softc	*sc = mc->mc_sc;
1664     int			error, count;
1665 
1666     debug_called(1);
1667 
1668     mc->mc_complete = NULL;
1669     mc->mc_private = mc;		/* wake us when you're done */
1670     if ((error = mlx_start(mc)) != 0)
1671 	return(error);
1672 
1673     count = 0;
1674     /* XXX better timeout? */
1675     while ((mc->mc_status == MLX_STATUS_BUSY) && (count < 30)) {
1676 	tsleep(mc->mc_private, PCATCH, "mlxwcmd", hz);
1677     }
1678 
1679     if (mc->mc_status != 0) {
1680 	device_printf(sc->mlx_dev, "command failed - %s\n", mlx_diagnose_command(mc));
1681 	return(EIO);
1682     }
1683     return(0);
1684 }
1685 
1686 
1687 /********************************************************************************
1688  * Start the command (mc) and busy-wait for it to complete.
1689  *
1690  * Should only be used when interrupts can't be relied upon. Returns 0 on
1691  * success, nonzero on error.
1692  * Successfully completed commands are dequeued.
1693  */
1694 static int
1695 mlx_poll_command(struct mlx_command *mc)
1696 {
1697     struct mlx_softc	*sc = mc->mc_sc;
1698     int			error, count;
1699 
1700     debug_called(1);
1701 
1702     mc->mc_complete = NULL;
1703     mc->mc_private = NULL;	/* we will poll for it */
1704     if ((error = mlx_start(mc)) != 0)
1705 	return(error);
1706 
1707     count = 0;
1708     do {
1709 	/* poll for completion */
1710 	mlx_done(mc->mc_sc);
1711 
1712     } while ((mc->mc_status == MLX_STATUS_BUSY) && (count++ < 15000000));
1713     if (mc->mc_status != MLX_STATUS_BUSY) {
1714 	crit_enter();
1715 	TAILQ_REMOVE(&sc->mlx_work, mc, mc_link);
1716 	crit_exit();
1717 	return(0);
1718     }
1719     device_printf(sc->mlx_dev, "command failed - %s\n", mlx_diagnose_command(mc));
1720     return(EIO);
1721 }
1722 
1723 /********************************************************************************
1724  * Pull as much work off the softc's work queue as possible and give it to the
1725  * controller.  Leave a couple of slots free for emergencies.
1726  *
1727  * Must be called at splbio or in an equivalent fashion that prevents
1728  * reentry or activity on the bioq.
1729  */
1730 static void
1731 mlx_startio(struct mlx_softc *sc)
1732 {
1733     struct mlx_command	*mc;
1734     struct mlxd_softc	*mlxd;
1735     mlx_bio		*bp;
1736     int			blkcount;
1737     int			driveno;
1738     int			cmd;
1739 
1740     /* avoid reentrancy */
1741     if (mlx_lock_tas(sc, MLX_LOCK_STARTING))
1742 	return;
1743 
1744     /* spin until something prevents us from doing any work */
1745     crit_enter();
1746     for (;;) {
1747 
1748 	/* see if there's work to be done */
1749 	if ((bp = MLX_BIO_QFIRST(sc->mlx_bioq)) == NULL)
1750 	    break;
1751 	/* get a command */
1752 	if ((mc = mlx_alloccmd(sc)) == NULL)
1753 	    break;
1754 	/* get a slot for the command */
1755 	if (mlx_getslot(mc) != 0) {
1756 	    mlx_releasecmd(mc);
1757 	    break;
1758 	}
1759 	/* get the buf containing our work */
1760 	MLX_BIO_QREMOVE(sc->mlx_bioq, bp);
1761 	sc->mlx_waitbufs--;
1762 	crit_exit();
1763 
1764 	/* connect the buf to the command */
1765 	mc->mc_complete = mlx_completeio;
1766 	mc->mc_private = bp;
1767 	mc->mc_data = MLX_BIO_DATA(bp);
1768 	mc->mc_length = MLX_BIO_LENGTH(bp);
1769 	if (MLX_BIO_IS_READ(bp)) {
1770 	    mc->mc_flags |= MLX_CMD_DATAIN;
1771 	    cmd = MLX_CMD_READSG;
1772 	} else {
1773 	    mc->mc_flags |= MLX_CMD_DATAOUT;
1774 	    cmd = MLX_CMD_WRITESG;
1775 	}
1776 
1777 	/* map the command so the controller can work with it */
1778 	mlx_mapcmd(mc);
1779 
1780 	/* build a suitable I/O command (assumes 512-byte rounded transfers) */
1781 	mlxd = (struct mlxd_softc *)MLX_BIO_SOFTC(bp);
1782 	driveno = mlxd->mlxd_drive - sc->mlx_sysdrive;
1783 	blkcount = (MLX_BIO_LENGTH(bp) + MLX_BLKSIZE - 1) / MLX_BLKSIZE;
1784 
1785 	if ((MLX_BIO_LBA(bp) + blkcount) > sc->mlx_sysdrive[driveno].ms_size)
1786 	    device_printf(sc->mlx_dev, "I/O beyond end of unit (%u,%d > %u)\n",
1787 			  MLX_BIO_LBA(bp), blkcount, sc->mlx_sysdrive[driveno].ms_size);
1788 
1789 	/*
1790 	 * Build the I/O command.  Note that the SG list type bits are set to zero,
1791 	 * denoting the format of SG list that we are using.
1792 	 */
1793 	if (sc->mlx_iftype == MLX_IFTYPE_2) {
1794 	    mlx_make_type1(mc, (cmd == MLX_CMD_WRITESG) ? MLX_CMD_WRITESG_OLD : MLX_CMD_READSG_OLD,
1795 			   blkcount & 0xff, 				/* xfer length low byte */
1796 			   MLX_BIO_LBA(bp),				/* physical block number */
1797 			   driveno,					/* target drive number */
1798 			   mc->mc_sgphys,				/* location of SG list */
1799 			   mc->mc_nsgent & 0x3f);			/* size of SG list (top 3 bits clear) */
1800 	} else {
1801 	    mlx_make_type5(mc, cmd,
1802 			   blkcount & 0xff, 				/* xfer length low byte */
1803 			   (driveno << 3) | ((blkcount >> 8) & 0x07),	/* target and length high 3 bits */
1804 			   MLX_BIO_LBA(bp),				/* physical block number */
1805 			   mc->mc_sgphys,				/* location of SG list */
1806 			   mc->mc_nsgent & 0x3f);			/* size of SG list (top 3 bits clear) */
1807 	}
1808 
1809 	/* try to give command to controller */
1810 	if (mlx_start(mc) != 0) {
1811 	    /* fail the command */
1812 	    mc->mc_status = MLX_STATUS_WEDGED;
1813 	    mlx_completeio(mc);
1814 	}
1815 	crit_enter();
1816     }
1817     crit_exit();
1818     mlx_lock_clr(sc, MLX_LOCK_STARTING);
1819 }
1820 
1821 /********************************************************************************
1822  * Handle completion of an I/O command.
1823  */
1824 static void
1825 mlx_completeio(struct mlx_command *mc)
1826 {
1827     struct mlx_softc	*sc = mc->mc_sc;
1828     mlx_bio		*bp = (mlx_bio *)mc->mc_private;
1829     struct mlxd_softc	*mlxd = (struct mlxd_softc *)MLX_BIO_SOFTC(bp);
1830 
1831     if (mc->mc_status != MLX_STATUS_OK) {	/* could be more verbose here? */
1832 	MLX_BIO_SET_ERROR(bp, EIO);
1833 
1834 	switch(mc->mc_status) {
1835 	case MLX_STATUS_RDWROFFLINE:		/* system drive has gone offline */
1836 	    device_printf(mlxd->mlxd_dev, "drive offline\n");
1837 	    /* should signal this with a return code */
1838 	    mlxd->mlxd_drive->ms_state = MLX_SYSD_OFFLINE;
1839 	    break;
1840 
1841 	default:				/* other I/O error */
1842 	    device_printf(sc->mlx_dev, "I/O error - %s\n", mlx_diagnose_command(mc));
1843 #if 0
1844 	    device_printf(sc->mlx_dev, "  b_bcount %ld  blkcount %ld  b_pblkno %d\n",
1845 			  MLX_BIO_LENGTH(bp), MLX_BIO_LENGTH(bp) / MLX_BLKSIZE, MLX_BIO_LBA(bp));
1846 	    device_printf(sc->mlx_dev, "  %13D\n", mc->mc_mailbox, " ");
1847 #endif
1848 	    break;
1849 	}
1850     }
1851     mlx_releasecmd(mc);
1852     mlxd_intr(bp);
1853 }
1854 
1855 /********************************************************************************
1856  * Take a command from user-space and try to run it.
1857  *
1858  * XXX Note that this can't perform very much in the way of error checking, and
1859  *     as such, applications _must_ be considered trustworthy.
1860  * XXX Commands using S/G for data are not supported.
1861  */
1862 static int
1863 mlx_user_command(struct mlx_softc *sc, struct mlx_usercommand *mu)
1864 {
1865     struct mlx_command	*mc;
1866     struct mlx_dcdb	*dcdb;
1867     void		*kbuf;
1868     int			error;
1869 
1870     debug_called(0);
1871 
1872     kbuf = NULL;
1873     mc = NULL;
1874     dcdb = NULL;
1875     error = ENOMEM;
1876 
1877     /* get ourselves a command and copy in from user space */
1878     if ((mc = mlx_alloccmd(sc)) == NULL)
1879 	goto out;
1880     bcopy(mu->mu_command, mc->mc_mailbox, sizeof(mc->mc_mailbox));
1881     debug(0, "got command buffer");
1882 
1883     /* if we need a buffer for data transfer, allocate one and copy in its initial contents */
1884     if (mu->mu_datasize > 0) {
1885 	if (mu->mu_datasize > MAXPHYS)
1886 	    return (EINVAL);
1887 	if (((kbuf = malloc(mu->mu_datasize, M_DEVBUF, M_WAITOK)) == NULL) ||
1888 	    (error = copyin(mu->mu_buf, kbuf, mu->mu_datasize)))
1889 	    goto out;
1890 	debug(0, "got kernel buffer");
1891     }
1892 
1893     /* get a command slot */
1894     if (mlx_getslot(mc))
1895 	goto out;
1896     debug(0, "got a slot");
1897 
1898     /* map the command so the controller can see it */
1899     mc->mc_data = kbuf;
1900     mc->mc_length = mu->mu_datasize;
1901     mlx_mapcmd(mc);
1902     debug(0, "mapped");
1903 
1904     /*
1905      * If this is a passthrough SCSI command, the DCDB is packed at the
1906      * beginning of the data area.  Fix up the DCDB to point to the correct physical
1907      * address and override any bufptr supplied by the caller since we know
1908      * what it's meant to be.
1909      */
1910     if (mc->mc_mailbox[0] == MLX_CMD_DIRECT_CDB) {
1911 	dcdb = (struct mlx_dcdb *)kbuf;
1912 	dcdb->dcdb_physaddr = mc->mc_dataphys + sizeof(*dcdb);
1913 	mu->mu_bufptr = 8;
1914     }
1915 
1916     /*
1917      * If there's a data buffer, fix up the command's buffer pointer.
1918      */
1919     if (mu->mu_datasize > 0) {
1920 
1921 	/* range check the pointer to physical buffer address */
1922 	if ((mu->mu_bufptr < 0) || (mu->mu_bufptr > (sizeof(mu->mu_command) - sizeof(u_int32_t)))) {
1923 	    error = EINVAL;
1924 	    goto out;
1925 	}
1926 	mc->mc_mailbox[mu->mu_bufptr    ] =  mc->mc_dataphys        & 0xff;
1927 	mc->mc_mailbox[mu->mu_bufptr + 1] = (mc->mc_dataphys >> 8)  & 0xff;
1928 	mc->mc_mailbox[mu->mu_bufptr + 2] = (mc->mc_dataphys >> 16) & 0xff;
1929 	mc->mc_mailbox[mu->mu_bufptr + 3] = (mc->mc_dataphys >> 24) & 0xff;
1930     }
1931     debug(0, "command fixup");
1932 
1933     /* submit the command and wait */
1934     if ((error = mlx_wait_command(mc)) != 0)
1935 	goto out;
1936 
1937     /* copy out status and data */
1938     mu->mu_status = mc->mc_status;
1939     if ((mu->mu_datasize > 0) && ((error = copyout(kbuf, mu->mu_buf, mu->mu_datasize))))
1940 	goto out;
1941     error = 0;
1942 
1943  out:
1944     mlx_releasecmd(mc);
1945     if (kbuf != NULL)
1946 	free(kbuf, M_DEVBUF);
1947     return(error);
1948 }
1949 
1950 /********************************************************************************
1951  ********************************************************************************
1952                                                         Command I/O to Controller
1953  ********************************************************************************
1954  ********************************************************************************/
1955 
1956 /********************************************************************************
1957  * Find a free command slot for (mc).
1958  *
1959  * Don't hand out a slot to a normal-priority command unless there are at least
1960  * 4 slots free for priority commands.
1961  */
1962 static int
1963 mlx_getslot(struct mlx_command *mc)
1964 {
1965     struct mlx_softc	*sc = mc->mc_sc;
1966     int			slot, limit;
1967 
1968     debug_called(1);
1969 
1970     /*
1971      * Enforce slot-usage limit, if we have the required information.
1972      */
1973     if (sc->mlx_enq2 != NULL) {
1974 	limit = sc->mlx_enq2->me_max_commands;
1975     } else {
1976 	limit = 2;
1977     }
1978     if (sc->mlx_busycmds >= ((mc->mc_flags & MLX_CMD_PRIORITY) ? limit : limit - 4))
1979 	return(EBUSY);
1980 
1981     /*
1982      * Allocate an outstanding command slot
1983      *
1984      * XXX linear search is slow
1985      */
1986     crit_enter();
1987     for (slot = 0; slot < limit; slot++) {
1988 	debug(2, "try slot %d", slot);
1989 	if (sc->mlx_busycmd[slot] == NULL)
1990 	    break;
1991     }
1992     if (slot < limit) {
1993 	sc->mlx_busycmd[slot] = mc;
1994 	sc->mlx_busycmds++;
1995     }
1996     crit_exit();
1997 
1998     /* out of slots? */
1999     if (slot >= limit)
2000 	return(EBUSY);
2001 
2002     debug(2, "got slot %d", slot);
2003     mc->mc_slot = slot;
2004     return(0);
2005 }
2006 
2007 /********************************************************************************
2008  * Map/unmap (mc)'s data in the controller's addressable space.
2009  */
2010 static void
2011 mlx_setup_dmamap(void *arg, bus_dma_segment_t *segs, int nsegments, int error)
2012 {
2013     struct mlx_command	*mc = (struct mlx_command *)arg;
2014     struct mlx_softc	*sc = mc->mc_sc;
2015     struct mlx_sgentry	*sg;
2016     int			i;
2017 
2018     debug_called(1);
2019 
2020     /* XXX should be unnecessary */
2021     if (sc->mlx_enq2 && (nsegments > sc->mlx_enq2->me_max_sg))
2022 	panic("MLX: too many s/g segments (%d, max %d)", nsegments, sc->mlx_enq2->me_max_sg);
2023 
2024     /* get base address of s/g table */
2025     sg = sc->mlx_sgtable + (mc->mc_slot * MLX_NSEG);
2026 
2027     /* save s/g table information in command */
2028     mc->mc_nsgent = nsegments;
2029     mc->mc_sgphys = sc->mlx_sgbusaddr + (mc->mc_slot * MLX_NSEG * sizeof(struct mlx_sgentry));
2030     mc->mc_dataphys = segs[0].ds_addr;
2031 
2032     /* populate s/g table */
2033     for (i = 0; i < nsegments; i++, sg++) {
2034 	sg->sg_addr = segs[i].ds_addr;
2035 	sg->sg_count = segs[i].ds_len;
2036     }
2037 }
2038 
2039 static void
2040 mlx_mapcmd(struct mlx_command *mc)
2041 {
2042     struct mlx_softc	*sc = mc->mc_sc;
2043 
2044     debug_called(1);
2045 
2046     /* if the command involves data at all */
2047     if (mc->mc_data != NULL) {
2048 
2049 	/* map the data buffer into bus space and build the s/g list */
2050 	bus_dmamap_load(sc->mlx_buffer_dmat, mc->mc_dmamap, mc->mc_data, mc->mc_length,
2051 			mlx_setup_dmamap, mc, 0);
2052 	if (mc->mc_flags & MLX_CMD_DATAIN)
2053 	    bus_dmamap_sync(sc->mlx_buffer_dmat, mc->mc_dmamap, BUS_DMASYNC_PREREAD);
2054 	if (mc->mc_flags & MLX_CMD_DATAOUT)
2055 	    bus_dmamap_sync(sc->mlx_buffer_dmat, mc->mc_dmamap, BUS_DMASYNC_PREWRITE);
2056     }
2057 }
2058 
2059 static void
2060 mlx_unmapcmd(struct mlx_command *mc)
2061 {
2062     struct mlx_softc	*sc = mc->mc_sc;
2063 
2064     debug_called(1);
2065 
2066     /* if the command involved data at all */
2067     if (mc->mc_data != NULL) {
2068 
2069 	if (mc->mc_flags & MLX_CMD_DATAIN)
2070 	    bus_dmamap_sync(sc->mlx_buffer_dmat, mc->mc_dmamap, BUS_DMASYNC_POSTREAD);
2071 	if (mc->mc_flags & MLX_CMD_DATAOUT)
2072 	    bus_dmamap_sync(sc->mlx_buffer_dmat, mc->mc_dmamap, BUS_DMASYNC_POSTWRITE);
2073 
2074 	bus_dmamap_unload(sc->mlx_buffer_dmat, mc->mc_dmamap);
2075     }
2076 }
2077 
2078 /********************************************************************************
2079  * Try to deliver (mc) to the controller.
2080  *
2081  * Can be called at any interrupt level, with or without interrupts enabled.
2082  */
2083 static int
2084 mlx_start(struct mlx_command *mc)
2085 {
2086     struct mlx_softc	*sc = mc->mc_sc;
2087     int			i, done;
2088 
2089     debug_called(1);
2090 
2091     /* save the slot number as ident so we can handle this command when complete */
2092     mc->mc_mailbox[0x1] = mc->mc_slot;
2093 
2094     /* mark the command as currently being processed */
2095     mc->mc_status = MLX_STATUS_BUSY;
2096 
2097     /* set a default 60-second timeout  XXX tunable?  XXX not currently used */
2098     mc->mc_timeout = time_second + 60;
2099 
2100     /* spin waiting for the mailbox */
2101     for (i = 100000, done = 0; (i > 0) && !done; i--) {
2102 	crit_enter();
2103 	if (sc->mlx_tryqueue(sc, mc)) {
2104 	    done = 1;
2105 	    /* move command to work queue */
2106 	    TAILQ_INSERT_TAIL(&sc->mlx_work, mc, mc_link);
2107 	}
2108 	crit_exit();	/* drop spl to allow completion interrupts */
2109     }
2110 
2111     /* command is enqueued */
2112     if (done)
2113 	return(0);
2114 
2115     /*
2116      * We couldn't get the controller to take the command.  Revoke the slot
2117      * that the command was given and return it with a bad status.
2118      */
2119     sc->mlx_busycmd[mc->mc_slot] = NULL;
2120     device_printf(sc->mlx_dev, "controller wedged (not taking commands)\n");
2121     mc->mc_status = MLX_STATUS_WEDGED;
2122     mlx_complete(sc);
2123     return(EIO);
2124 }
2125 
2126 /********************************************************************************
2127  * Poll the controller (sc) for completed commands.
2128  * Update command status and free slots for reuse.  If any slots were freed,
2129  * new commands may be posted.
2130  *
2131  * Returns nonzero if one or more commands were completed.
2132  */
2133 static int
2134 mlx_done(struct mlx_softc *sc)
2135 {
2136     struct mlx_command	*mc;
2137     int			result;
2138     u_int8_t		slot;
2139     u_int16_t		status;
2140 
2141     debug_called(2);
2142 
2143     result = 0;
2144 
2145     /* loop collecting completed commands */
2146     crit_enter();
2147     for (;;) {
2148 	/* poll for a completed command's identifier and status */
2149 	if (sc->mlx_findcomplete(sc, &slot, &status)) {
2150 	    result = 1;
2151 	    mc = sc->mlx_busycmd[slot];			/* find command */
2152 	    if (mc != NULL) {				/* paranoia */
2153 		if (mc->mc_status == MLX_STATUS_BUSY) {
2154 		    mc->mc_status = status;		/* save status */
2155 
2156 		    /* free slot for reuse */
2157 		    sc->mlx_busycmd[slot] = NULL;
2158 		    sc->mlx_busycmds--;
2159 		} else {
2160 		    device_printf(sc->mlx_dev, "duplicate done event for slot %d\n", slot);
2161 		}
2162 	    } else {
2163 		device_printf(sc->mlx_dev, "done event for nonbusy slot %d\n", slot);
2164 	    }
2165 	} else {
2166 	    break;
2167 	}
2168     }
2169     crit_exit();
2170 
2171     /* if we've completed any commands, try posting some more */
2172     if (result)
2173 	mlx_startio(sc);
2174 
2175     /* handle completion and timeouts */
2176     mlx_complete(sc);
2177 
2178     return(result);
2179 }
2180 
2181 /********************************************************************************
2182  * Perform post-completion processing for commands on (sc).
2183  */
2184 static void
2185 mlx_complete(struct mlx_softc *sc)
2186 {
2187     struct mlx_command	*mc, *nc;
2188     int			count;
2189 
2190     debug_called(2);
2191 
2192     /* avoid reentrancy  XXX might want to signal and request a restart */
2193     if (mlx_lock_tas(sc, MLX_LOCK_COMPLETING))
2194 	return;
2195 
2196     crit_enter();
2197     count = 0;
2198 
2199     /* scan the list of busy/done commands */
2200     mc = TAILQ_FIRST(&sc->mlx_work);
2201     while (mc != NULL) {
2202 	nc = TAILQ_NEXT(mc, mc_link);
2203 
2204 	/* Command has been completed in some fashion */
2205 	if (mc->mc_status != MLX_STATUS_BUSY) {
2206 
2207 	    /* unmap the command's data buffer */
2208 	    mlx_unmapcmd(mc);
2209 	    /*
2210 	     * Does the command have a completion handler?
2211 	     */
2212 	    if (mc->mc_complete != NULL) {
2213 		/* remove from list and give to handler */
2214 		TAILQ_REMOVE(&sc->mlx_work, mc, mc_link);
2215 		mc->mc_complete(mc);
2216 
2217 		/*
2218 		 * Is there a sleeper waiting on this command?
2219 		 */
2220 	    } else if (mc->mc_private != NULL) {	/* sleeping caller wants to know about it */
2221 
2222 		/* remove from list and wake up sleeper */
2223 		TAILQ_REMOVE(&sc->mlx_work, mc, mc_link);
2224 		wakeup_one(mc->mc_private);
2225 
2226 		/*
2227 		 * Leave the command for a caller that's polling for it.
2228 		 */
2229 	    } else {
2230 	    }
2231 	}
2232 	mc = nc;
2233     }
2234     crit_exit();
2235 
2236     mlx_lock_clr(sc, MLX_LOCK_COMPLETING);
2237 }
2238 
2239 /********************************************************************************
2240  ********************************************************************************
2241                                                         Command Buffer Management
2242  ********************************************************************************
2243  ********************************************************************************/
2244 
2245 /********************************************************************************
2246  * Get a new command buffer.
2247  *
2248  * This may return NULL in low-memory cases.
2249  *
2250  * Note that using malloc() is expensive (the command buffer is << 1 page) but
2251  * necessary if we are to be a loadable module before the zone allocator is fixed.
2252  *
2253  * If possible, we recycle a command buffer that's been used before.
2254  *
2255  * XXX Note that command buffers are not cleaned out - it is the caller's
2256  *     responsibility to ensure that all required fields are filled in before
2257  *     using a buffer.
2258  */
2259 static struct mlx_command *
2260 mlx_alloccmd(struct mlx_softc *sc)
2261 {
2262     struct mlx_command	*mc;
2263     int			error;
2264 
2265     debug_called(1);
2266 
2267     crit_enter();
2268     if ((mc = TAILQ_FIRST(&sc->mlx_freecmds)) != NULL)
2269 	TAILQ_REMOVE(&sc->mlx_freecmds, mc, mc_link);
2270     crit_exit();
2271 
2272     /* allocate a new command buffer? */
2273     if (mc == NULL) {
2274 	mc = malloc(sizeof(*mc), M_DEVBUF, M_INTWAIT | M_ZERO);
2275 	mc->mc_sc = sc;
2276 	error = bus_dmamap_create(sc->mlx_buffer_dmat, 0, &mc->mc_dmamap);
2277 	if (error) {
2278 	    free(mc, M_DEVBUF);
2279 	    return(NULL);
2280 	}
2281     }
2282     return(mc);
2283 }
2284 
2285 /********************************************************************************
2286  * Release a command buffer for recycling.
2287  *
2288  * XXX It might be a good idea to limit the number of commands we save for reuse
2289  *     if it's shown that this list bloats out massively.
2290  */
2291 static void
2292 mlx_releasecmd(struct mlx_command *mc)
2293 {
2294     debug_called(1);
2295 
2296     crit_enter();
2297     TAILQ_INSERT_HEAD(&mc->mc_sc->mlx_freecmds, mc, mc_link);
2298     crit_exit();
2299 }
2300 
2301 /********************************************************************************
2302  * Permanently discard a command buffer.
2303  */
2304 static void
2305 mlx_freecmd(struct mlx_command *mc)
2306 {
2307     struct mlx_softc	*sc = mc->mc_sc;
2308 
2309     debug_called(1);
2310     bus_dmamap_destroy(sc->mlx_buffer_dmat, mc->mc_dmamap);
2311     free(mc, M_DEVBUF);
2312 }
2313 
2314 
2315 /********************************************************************************
2316  ********************************************************************************
2317                                                 Type 3 interface accessor methods
2318  ********************************************************************************
2319  ********************************************************************************/
2320 
2321 /********************************************************************************
2322  * Try to give (mc) to the controller.  Returns 1 if successful, 0 on failure
2323  * (the controller is not ready to take a command).
2324  *
2325  * Must be called at splbio or in a fashion that prevents reentry.
2326  */
2327 static int
2328 mlx_v3_tryqueue(struct mlx_softc *sc, struct mlx_command *mc)
2329 {
2330     int		i;
2331 
2332     debug_called(2);
2333 
2334     /* ready for our command? */
2335     if (!(MLX_V3_GET_IDBR(sc) & MLX_V3_IDB_FULL)) {
2336 	/* copy mailbox data to window */
2337 	for (i = 0; i < 13; i++)
2338 	    MLX_V3_PUT_MAILBOX(sc, i, mc->mc_mailbox[i]);
2339 
2340 	/* post command */
2341 	MLX_V3_PUT_IDBR(sc, MLX_V3_IDB_FULL);
2342 	return(1);
2343     }
2344     return(0);
2345 }
2346 
2347 /********************************************************************************
2348  * See if a command has been completed, if so acknowledge its completion
2349  * and recover the slot number and status code.
2350  *
2351  * Must be called at splbio or in a fashion that prevents reentry.
2352  */
2353 static int
2354 mlx_v3_findcomplete(struct mlx_softc *sc, u_int8_t *slot, u_int16_t *status)
2355 {
2356 
2357     debug_called(2);
2358 
2359     /* status available? */
2360     if (MLX_V3_GET_ODBR(sc) & MLX_V3_ODB_SAVAIL) {
2361 	*slot = MLX_V3_GET_STATUS_IDENT(sc);		/* get command identifier */
2362 	*status = MLX_V3_GET_STATUS(sc);		/* get status */
2363 
2364 	/* acknowledge completion */
2365 	MLX_V3_PUT_ODBR(sc, MLX_V3_ODB_SAVAIL);
2366 	MLX_V3_PUT_IDBR(sc, MLX_V3_IDB_SACK);
2367 	return(1);
2368     }
2369     return(0);
2370 }
2371 
2372 /********************************************************************************
2373  * Enable/disable interrupts as requested. (No acknowledge required)
2374  *
2375  * Must be called at splbio or in a fashion that prevents reentry.
2376  */
2377 static void
2378 mlx_v3_intaction(struct mlx_softc *sc, int action)
2379 {
2380     debug_called(1);
2381 
2382     switch(action) {
2383     case MLX_INTACTION_DISABLE:
2384 	MLX_V3_PUT_IER(sc, 0);
2385 	sc->mlx_state &= ~MLX_STATE_INTEN;
2386 	break;
2387     case MLX_INTACTION_ENABLE:
2388 	MLX_V3_PUT_IER(sc, 1);
2389 	sc->mlx_state |= MLX_STATE_INTEN;
2390 	break;
2391     }
2392 }
2393 
2394 /********************************************************************************
2395  * Poll for firmware error codes during controller initialisation.
2396  * Returns 0 if initialisation is complete, 1 if still in progress but no
2397  * error has been fetched, 2 if an error has been retrieved.
2398  */
2399 static int
2400 mlx_v3_fw_handshake(struct mlx_softc *sc, int *error, int *param1, int *param2)
2401 {
2402     u_int8_t	fwerror;
2403     static int	initted = 0;
2404 
2405     debug_called(2);
2406 
2407     /* first time around, clear any hardware completion status */
2408     if (!initted) {
2409 	MLX_V3_PUT_IDBR(sc, MLX_V3_IDB_SACK);
2410 	DELAY(1000);
2411 	initted = 1;
2412     }
2413 
2414     /* init in progress? */
2415     if (!(MLX_V3_GET_IDBR(sc) & MLX_V3_IDB_INIT_BUSY))
2416 	return(0);
2417 
2418     /* test error value */
2419     fwerror = MLX_V3_GET_FWERROR(sc);
2420     if (!(fwerror & MLX_V3_FWERROR_PEND))
2421 	return(1);
2422 
2423     /* mask status pending bit, fetch status */
2424     *error = fwerror & ~MLX_V3_FWERROR_PEND;
2425     *param1 = MLX_V3_GET_FWERROR_PARAM1(sc);
2426     *param2 = MLX_V3_GET_FWERROR_PARAM2(sc);
2427 
2428     /* acknowledge */
2429     MLX_V3_PUT_FWERROR(sc, 0);
2430 
2431     return(2);
2432 }
2433 
2434 /********************************************************************************
2435  ********************************************************************************
2436                                                 Type 4 interface accessor methods
2437  ********************************************************************************
2438  ********************************************************************************/
2439 
2440 /********************************************************************************
2441  * Try to give (mc) to the controller.  Returns 1 if successful, 0 on failure
2442  * (the controller is not ready to take a command).
2443  *
2444  * Must be called at splbio or in a fashion that prevents reentry.
2445  */
2446 static int
2447 mlx_v4_tryqueue(struct mlx_softc *sc, struct mlx_command *mc)
2448 {
2449     int		i;
2450 
2451     debug_called(2);
2452 
2453     /* ready for our command? */
2454     if (!(MLX_V4_GET_IDBR(sc) & MLX_V4_IDB_FULL)) {
2455 	/* copy mailbox data to window */
2456 	for (i = 0; i < 13; i++)
2457 	    MLX_V4_PUT_MAILBOX(sc, i, mc->mc_mailbox[i]);
2458 
2459 	/* memory-mapped controller, so issue a write barrier to ensure the mailbox is filled */
2460 	bus_space_barrier(sc->mlx_btag, sc->mlx_bhandle, MLX_V4_MAILBOX, MLX_V4_MAILBOX_LENGTH,
2461 			  BUS_SPACE_BARRIER_WRITE);
2462 
2463 	/* post command */
2464 	MLX_V4_PUT_IDBR(sc, MLX_V4_IDB_HWMBOX_CMD);
2465 	return(1);
2466     }
2467     return(0);
2468 }
2469 
2470 /********************************************************************************
2471  * See if a command has been completed, if so acknowledge its completion
2472  * and recover the slot number and status code.
2473  *
2474  * Must be called at splbio or in a fashion that prevents reentry.
2475  */
2476 static int
2477 mlx_v4_findcomplete(struct mlx_softc *sc, u_int8_t *slot, u_int16_t *status)
2478 {
2479 
2480     debug_called(2);
2481 
2482     /* status available? */
2483     if (MLX_V4_GET_ODBR(sc) & MLX_V4_ODB_HWSAVAIL) {
2484 	*slot = MLX_V4_GET_STATUS_IDENT(sc);		/* get command identifier */
2485 	*status = MLX_V4_GET_STATUS(sc);		/* get status */
2486 
2487 	/* acknowledge completion */
2488 	MLX_V4_PUT_ODBR(sc, MLX_V4_ODB_HWMBOX_ACK);
2489 	MLX_V4_PUT_IDBR(sc, MLX_V4_IDB_SACK);
2490 	return(1);
2491     }
2492     return(0);
2493 }
2494 
2495 /********************************************************************************
2496  * Enable/disable interrupts as requested.
2497  *
2498  * Must be called at splbio or in a fashion that prevents reentry.
2499  */
2500 static void
2501 mlx_v4_intaction(struct mlx_softc *sc, int action)
2502 {
2503     debug_called(1);
2504 
2505     switch(action) {
2506     case MLX_INTACTION_DISABLE:
2507 	MLX_V4_PUT_IER(sc, MLX_V4_IER_MASK | MLX_V4_IER_DISINT);
2508 	sc->mlx_state &= ~MLX_STATE_INTEN;
2509 	break;
2510     case MLX_INTACTION_ENABLE:
2511 	MLX_V4_PUT_IER(sc, MLX_V4_IER_MASK & ~MLX_V4_IER_DISINT);
2512 	sc->mlx_state |= MLX_STATE_INTEN;
2513 	break;
2514     }
2515 }
2516 
2517 /********************************************************************************
2518  * Poll for firmware error codes during controller initialisation.
2519  * Returns 0 if initialisation is complete, 1 if still in progress but no
2520  * error has been fetched, 2 if an error has been retrieved.
2521  */
2522 static int
2523 mlx_v4_fw_handshake(struct mlx_softc *sc, int *error, int *param1, int *param2)
2524 {
2525     u_int8_t	fwerror;
2526     static int	initted = 0;
2527 
2528     debug_called(2);
2529 
2530     /* first time around, clear any hardware completion status */
2531     if (!initted) {
2532 	MLX_V4_PUT_IDBR(sc, MLX_V4_IDB_SACK);
2533 	DELAY(1000);
2534 	initted = 1;
2535     }
2536 
2537     /* init in progress? */
2538     if (!(MLX_V4_GET_IDBR(sc) & MLX_V4_IDB_INIT_BUSY))
2539 	return(0);
2540 
2541     /* test error value */
2542     fwerror = MLX_V4_GET_FWERROR(sc);
2543     if (!(fwerror & MLX_V4_FWERROR_PEND))
2544 	return(1);
2545 
2546     /* mask status pending bit, fetch status */
2547     *error = fwerror & ~MLX_V4_FWERROR_PEND;
2548     *param1 = MLX_V4_GET_FWERROR_PARAM1(sc);
2549     *param2 = MLX_V4_GET_FWERROR_PARAM2(sc);
2550 
2551     /* acknowledge */
2552     MLX_V4_PUT_FWERROR(sc, 0);
2553 
2554     return(2);
2555 }
2556 
2557 /********************************************************************************
2558  ********************************************************************************
2559                                                 Type 5 interface accessor methods
2560  ********************************************************************************
2561  ********************************************************************************/
2562 
2563 /********************************************************************************
2564  * Try to give (mc) to the controller.  Returns 1 if successful, 0 on failure
2565  * (the controller is not ready to take a command).
2566  *
2567  * Must be called at splbio or in a fashion that prevents reentry.
2568  */
2569 static int
2570 mlx_v5_tryqueue(struct mlx_softc *sc, struct mlx_command *mc)
2571 {
2572     int		i;
2573 
2574     debug_called(2);
2575 
2576     /* ready for our command? */
2577     if (MLX_V5_GET_IDBR(sc) & MLX_V5_IDB_EMPTY) {
2578 	/* copy mailbox data to window */
2579 	for (i = 0; i < 13; i++)
2580 	    MLX_V5_PUT_MAILBOX(sc, i, mc->mc_mailbox[i]);
2581 
2582 	/* post command */
2583 	MLX_V5_PUT_IDBR(sc, MLX_V5_IDB_HWMBOX_CMD);
2584 	return(1);
2585     }
2586     return(0);
2587 }
2588 
2589 /********************************************************************************
2590  * See if a command has been completed, if so acknowledge its completion
2591  * and recover the slot number and status code.
2592  *
2593  * Must be called at splbio or in a fashion that prevents reentry.
2594  */
2595 static int
2596 mlx_v5_findcomplete(struct mlx_softc *sc, u_int8_t *slot, u_int16_t *status)
2597 {
2598 
2599     debug_called(2);
2600 
2601     /* status available? */
2602     if (MLX_V5_GET_ODBR(sc) & MLX_V5_ODB_HWSAVAIL) {
2603 	*slot = MLX_V5_GET_STATUS_IDENT(sc);		/* get command identifier */
2604 	*status = MLX_V5_GET_STATUS(sc);		/* get status */
2605 
2606 	/* acknowledge completion */
2607 	MLX_V5_PUT_ODBR(sc, MLX_V5_ODB_HWMBOX_ACK);
2608 	MLX_V5_PUT_IDBR(sc, MLX_V5_IDB_SACK);
2609 	return(1);
2610     }
2611     return(0);
2612 }
2613 
2614 /********************************************************************************
2615  * Enable/disable interrupts as requested.
2616  *
2617  * Must be called at splbio or in a fashion that prevents reentry.
2618  */
2619 static void
2620 mlx_v5_intaction(struct mlx_softc *sc, int action)
2621 {
2622     debug_called(1);
2623 
2624     switch(action) {
2625     case MLX_INTACTION_DISABLE:
2626 	MLX_V5_PUT_IER(sc, 0xff & MLX_V5_IER_DISINT);
2627 	sc->mlx_state &= ~MLX_STATE_INTEN;
2628 	break;
2629     case MLX_INTACTION_ENABLE:
2630 	MLX_V5_PUT_IER(sc, 0xff & ~MLX_V5_IER_DISINT);
2631 	sc->mlx_state |= MLX_STATE_INTEN;
2632 	break;
2633     }
2634 }
2635 
2636 /********************************************************************************
2637  * Poll for firmware error codes during controller initialisation.
2638  * Returns 0 if initialisation is complete, 1 if still in progress but no
2639  * error has been fetched, 2 if an error has been retrieved.
2640  */
2641 static int
2642 mlx_v5_fw_handshake(struct mlx_softc *sc, int *error, int *param1, int *param2)
2643 {
2644     u_int8_t	fwerror;
2645     static int	initted = 0;
2646 
2647     debug_called(2);
2648 
2649     /* first time around, clear any hardware completion status */
2650     if (!initted) {
2651 	MLX_V5_PUT_IDBR(sc, MLX_V5_IDB_SACK);
2652 	DELAY(1000);
2653 	initted = 1;
2654     }
2655 
2656     /* init in progress? */
2657     if (MLX_V5_GET_IDBR(sc) & MLX_V5_IDB_INIT_DONE)
2658 	return(0);
2659 
2660     /* test for error value */
2661     fwerror = MLX_V5_GET_FWERROR(sc);
2662     if (!(fwerror & MLX_V5_FWERROR_PEND))
2663 	return(1);
2664 
2665     /* mask status pending bit, fetch status */
2666     *error = fwerror & ~MLX_V5_FWERROR_PEND;
2667     *param1 = MLX_V5_GET_FWERROR_PARAM1(sc);
2668     *param2 = MLX_V5_GET_FWERROR_PARAM2(sc);
2669 
2670     /* acknowledge */
2671     MLX_V5_PUT_FWERROR(sc, 0xff);
2672 
2673     return(2);
2674 }
2675 
2676 /********************************************************************************
2677  ********************************************************************************
2678                                                                         Debugging
2679  ********************************************************************************
2680  ********************************************************************************/
2681 
2682 /********************************************************************************
2683  * Return a status message describing (mc)
2684  */
2685 static char *mlx_status_messages[] = {
2686     "normal completion",			/* 00 */
2687     "irrecoverable data error",			/* 01 */
2688     "drive does not exist, or is offline",	/* 02 */
2689     "attempt to write beyond end of drive",	/* 03 */
2690     "bad data encountered",			/* 04 */
2691     "invalid log entry request",		/* 05 */
2692     "attempt to rebuild online drive",		/* 06 */
2693     "new disk failed during rebuild",		/* 07 */
2694     "invalid channel/target",			/* 08 */
2695     "rebuild/check already in progress",	/* 09 */
2696     "one or more disks are dead",		/* 10 */
2697     "invalid or non-redundant drive",		/* 11 */
2698     "channel is busy",				/* 12 */
2699     "channel is not stopped",			/* 13 */
2700     "rebuild successfully terminated",		/* 14 */
2701     "unsupported command",			/* 15 */
2702     "check condition received",			/* 16 */
2703     "device is busy",				/* 17 */
2704     "selection or command timeout",		/* 18 */
2705     "command terminated abnormally",		/* 19 */
2706     ""
2707 };
2708 
2709 static struct
2710 {
2711     int		command;
2712     u_int16_t	status;
2713     int		msg;
2714 } mlx_messages[] = {
2715     {MLX_CMD_READSG,		0x0001,	 1},
2716     {MLX_CMD_READSG,		0x0002,	 1},
2717     {MLX_CMD_READSG,		0x0105,	 3},
2718     {MLX_CMD_READSG,		0x010c,	 4},
2719     {MLX_CMD_WRITESG,		0x0001,	 1},
2720     {MLX_CMD_WRITESG,		0x0002,	 1},
2721     {MLX_CMD_WRITESG,		0x0105,	 3},
2722     {MLX_CMD_READSG_OLD,	0x0001,	 1},
2723     {MLX_CMD_READSG_OLD,	0x0002,	 1},
2724     {MLX_CMD_READSG_OLD,	0x0105,	 3},
2725     {MLX_CMD_WRITESG_OLD,	0x0001,	 1},
2726     {MLX_CMD_WRITESG_OLD,	0x0002,	 1},
2727     {MLX_CMD_WRITESG_OLD,	0x0105,	 3},
2728     {MLX_CMD_LOGOP,		0x0105,	 5},
2729     {MLX_CMD_REBUILDASYNC,	0x0002,  6},
2730     {MLX_CMD_REBUILDASYNC,	0x0004,  7},
2731     {MLX_CMD_REBUILDASYNC,	0x0105,  8},
2732     {MLX_CMD_REBUILDASYNC,	0x0106,  9},
2733     {MLX_CMD_REBUILDASYNC,	0x0107, 14},
2734     {MLX_CMD_CHECKASYNC,	0x0002, 10},
2735     {MLX_CMD_CHECKASYNC,	0x0105, 11},
2736     {MLX_CMD_CHECKASYNC,	0x0106,  9},
2737     {MLX_CMD_STOPCHANNEL,	0x0106, 12},
2738     {MLX_CMD_STOPCHANNEL,	0x0105,  8},
2739     {MLX_CMD_STARTCHANNEL,	0x0005, 13},
2740     {MLX_CMD_STARTCHANNEL,	0x0105,  8},
2741     {MLX_CMD_DIRECT_CDB,	0x0002, 16},
2742     {MLX_CMD_DIRECT_CDB,	0x0008, 17},
2743     {MLX_CMD_DIRECT_CDB,	0x000e, 18},
2744     {MLX_CMD_DIRECT_CDB,	0x000f, 19},
2745     {MLX_CMD_DIRECT_CDB,	0x0105,  8},
2746 
2747     {0,				0x0104, 14},
2748     {-1, 0, 0}
2749 };
2750 
2751 static char *
2752 mlx_diagnose_command(struct mlx_command *mc)
2753 {
2754     static char	unkmsg[80];
2755     int		i;
2756 
2757     /* look up message in table */
2758     for (i = 0; mlx_messages[i].command != -1; i++)
2759 	if (((mc->mc_mailbox[0] == mlx_messages[i].command) || (mlx_messages[i].command == 0)) &&
2760 	    (mc->mc_status == mlx_messages[i].status))
2761 	    return(mlx_status_messages[mlx_messages[i].msg]);
2762 
2763     sprintf(unkmsg, "unknown response 0x%x for command 0x%x", (int)mc->mc_status, (int)mc->mc_mailbox[0]);
2764     return(unkmsg);
2765 }
2766 
2767 /*******************************************************************************
2768  * Print a string describing the controller (sc)
2769  */
2770 static struct
2771 {
2772     int		hwid;
2773     char	*name;
2774 } mlx_controller_names[] = {
2775     {0x01,	"960P/PD"},
2776     {0x02,	"960PL"},
2777     {0x10,	"960PG"},
2778     {0x11,	"960PJ"},
2779     {0x12,	"960PR"},
2780     {0x13,	"960PT"},
2781     {0x14,	"960PTL0"},
2782     {0x15,	"960PRL"},
2783     {0x16,	"960PTL1"},
2784     {0x20,	"1164PVX"},
2785     {-1, NULL}
2786 };
2787 
2788 static void
2789 mlx_describe_controller(struct mlx_softc *sc)
2790 {
2791     static char		buf[80];
2792     char		*model;
2793     int			i;
2794 
2795     for (i = 0, model = NULL; mlx_controller_names[i].name != NULL; i++) {
2796 	if ((sc->mlx_enq2->me_hardware_id & 0xff) == mlx_controller_names[i].hwid) {
2797 	    model = mlx_controller_names[i].name;
2798 	    break;
2799 	}
2800     }
2801     if (model == NULL) {
2802 	sprintf(buf, " model 0x%x", sc->mlx_enq2->me_hardware_id & 0xff);
2803 	model = buf;
2804     }
2805     device_printf(sc->mlx_dev, "DAC%s, %d channel%s, firmware %d.%02d-%c-%02d, %dMB RAM\n",
2806 		  model,
2807 		  sc->mlx_enq2->me_actual_channels,
2808 		  sc->mlx_enq2->me_actual_channels > 1 ? "s" : "",
2809 		  sc->mlx_enq2->me_firmware_id & 0xff,
2810 		  (sc->mlx_enq2->me_firmware_id >> 8) & 0xff,
2811 		  (sc->mlx_enq2->me_firmware_id >> 24) & 0xff,
2812 		  (sc->mlx_enq2->me_firmware_id >> 16) & 0xff,
2813 		  sc->mlx_enq2->me_mem_size / (1024 * 1024));
2814 
2815     if (bootverbose) {
2816 	device_printf(sc->mlx_dev, "  Hardware ID                 0x%08x\n", sc->mlx_enq2->me_hardware_id);
2817 	device_printf(sc->mlx_dev, "  Firmware ID                 0x%08x\n", sc->mlx_enq2->me_firmware_id);
2818 	device_printf(sc->mlx_dev, "  Configured/Actual channels  %d/%d\n", sc->mlx_enq2->me_configured_channels,
2819 		      sc->mlx_enq2->me_actual_channels);
2820 	device_printf(sc->mlx_dev, "  Max Targets                 %d\n", sc->mlx_enq2->me_max_targets);
2821 	device_printf(sc->mlx_dev, "  Max Tags                    %d\n", sc->mlx_enq2->me_max_tags);
2822 	device_printf(sc->mlx_dev, "  Max System Drives           %d\n", sc->mlx_enq2->me_max_sys_drives);
2823 	device_printf(sc->mlx_dev, "  Max Arms                    %d\n", sc->mlx_enq2->me_max_arms);
2824 	device_printf(sc->mlx_dev, "  Max Spans                   %d\n", sc->mlx_enq2->me_max_spans);
2825 	device_printf(sc->mlx_dev, "  DRAM/cache/flash/NVRAM size %d/%d/%d/%d\n", sc->mlx_enq2->me_mem_size,
2826 		      sc->mlx_enq2->me_cache_size, sc->mlx_enq2->me_flash_size, sc->mlx_enq2->me_nvram_size);
2827 	device_printf(sc->mlx_dev, "  DRAM type                   %d\n", sc->mlx_enq2->me_mem_type);
2828 	device_printf(sc->mlx_dev, "  Clock Speed                 %dns\n", sc->mlx_enq2->me_clock_speed);
2829 	device_printf(sc->mlx_dev, "  Hardware Speed              %dns\n", sc->mlx_enq2->me_hardware_speed);
2830 	device_printf(sc->mlx_dev, "  Max Commands                %d\n", sc->mlx_enq2->me_max_commands);
2831 	device_printf(sc->mlx_dev, "  Max SG Entries              %d\n", sc->mlx_enq2->me_max_sg);
2832 	device_printf(sc->mlx_dev, "  Max DP                      %d\n", sc->mlx_enq2->me_max_dp);
2833 	device_printf(sc->mlx_dev, "  Max IOD                     %d\n", sc->mlx_enq2->me_max_iod);
2834 	device_printf(sc->mlx_dev, "  Max Comb                    %d\n", sc->mlx_enq2->me_max_comb);
2835 	device_printf(sc->mlx_dev, "  Latency                     %ds\n", sc->mlx_enq2->me_latency);
2836 	device_printf(sc->mlx_dev, "  SCSI Timeout                %ds\n", sc->mlx_enq2->me_scsi_timeout);
2837 	device_printf(sc->mlx_dev, "  Min Free Lines              %d\n", sc->mlx_enq2->me_min_freelines);
2838 	device_printf(sc->mlx_dev, "  Rate Constant               %d\n", sc->mlx_enq2->me_rate_const);
2839 	device_printf(sc->mlx_dev, "  MAXBLK                      %d\n", sc->mlx_enq2->me_maxblk);
2840 	device_printf(sc->mlx_dev, "  Blocking Factor             %d sectors\n", sc->mlx_enq2->me_blocking_factor);
2841 	device_printf(sc->mlx_dev, "  Cache Line Size             %d blocks\n", sc->mlx_enq2->me_cacheline);
2842 	device_printf(sc->mlx_dev, "  SCSI Capability             %s%dMHz, %d bit\n",
2843 		      sc->mlx_enq2->me_scsi_cap & (1<<4) ? "differential " : "",
2844 		      (1 << ((sc->mlx_enq2->me_scsi_cap >> 2) & 3)) * 10,
2845 		      8 << (sc->mlx_enq2->me_scsi_cap & 0x3));
2846 	device_printf(sc->mlx_dev, "  Firmware Build Number       %d\n", sc->mlx_enq2->me_firmware_build);
2847 	device_printf(sc->mlx_dev, "  Fault Management Type       %d\n", sc->mlx_enq2->me_fault_mgmt_type);
2848 	device_printf(sc->mlx_dev, "  Features                    %b\n", sc->mlx_enq2->me_firmware_features,
2849 		      "\20\4Background Init\3Read Ahead\2MORE\1Cluster\n");
2850 
2851     }
2852 }
2853 
2854 /*******************************************************************************
2855  * Emit a string describing the firmware handshake status code, and return a flag
2856  * indicating whether the code represents a fatal error.
2857  *
2858  * Error code interpretations are from the Linux driver, and don't directly match
2859  * the messages printed by Mylex's BIOS.  This may change if documentation on the
2860  * codes is forthcoming.
2861  */
2862 static int
2863 mlx_fw_message(struct mlx_softc *sc, int error, int param1, int param2)
2864 {
2865     switch(error) {
2866     case 0x00:
2867 	device_printf(sc->mlx_dev, "physical drive %d:%d not responding\n", param2, param1);
2868 	break;
2869     case 0x08:
2870 	/* we could be neater about this and give some indication when we receive more of them */
2871 	if (!(sc->mlx_flags & MLX_SPINUP_REPORTED)) {
2872 	    device_printf(sc->mlx_dev, "spinning up drives...\n");
2873 	    sc->mlx_flags |= MLX_SPINUP_REPORTED;
2874 	}
2875 	break;
2876     case 0x30:
2877 	device_printf(sc->mlx_dev, "configuration checksum error\n");
2878 	break;
2879     case 0x60:
2880 	device_printf(sc->mlx_dev, "mirror race recovery failed\n");
2881 	break;
2882     case 0x70:
2883 	device_printf(sc->mlx_dev, "mirror race recovery in progress\n");
2884 	break;
2885     case 0x90:
2886 	device_printf(sc->mlx_dev, "physical drive %d:%d COD mismatch\n", param2, param1);
2887 	break;
2888     case 0xa0:
2889 	device_printf(sc->mlx_dev, "logical drive installation aborted\n");
2890 	break;
2891     case 0xb0:
2892 	device_printf(sc->mlx_dev, "mirror race on a critical system drive\n");
2893 	break;
2894     case 0xd0:
2895 	device_printf(sc->mlx_dev, "new controller configuration found\n");
2896 	break;
2897     case 0xf0:
2898 	device_printf(sc->mlx_dev, "FATAL MEMORY PARITY ERROR\n");
2899 	return(1);
2900     default:
2901 	device_printf(sc->mlx_dev, "unknown firmware initialisation error %02x:%02x:%02x\n", error, param1, param2);
2902 	break;
2903     }
2904     return(0);
2905 }
2906 
2907 /********************************************************************************
2908  ********************************************************************************
2909                                                                 Utility Functions
2910  ********************************************************************************
2911  ********************************************************************************/
2912 
2913 /********************************************************************************
2914  * Find the disk whose unit number is (unit) on this controller
2915  */
2916 static struct mlx_sysdrive *
2917 mlx_findunit(struct mlx_softc *sc, int unit)
2918 {
2919     int		i;
2920 
2921     /* search system drives */
2922     for (i = 0; i < MLX_MAXDRIVES; i++) {
2923 	/* is this one attached? */
2924 	if (sc->mlx_sysdrive[i].ms_disk != 0) {
2925 	    /* is this the one? */
2926 	    if (unit == device_get_unit(sc->mlx_sysdrive[i].ms_disk))
2927 		return(&sc->mlx_sysdrive[i]);
2928 	}
2929     }
2930     return(NULL);
2931 }
2932