ctl_tpc.c revision 311417
1/*-
2 * Copyright (c) 2014 Alexander Motin <mav@FreeBSD.org>
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * 1. Redistributions of source code must retain the above copyright
9 *    notice, this list of conditions and the following disclaimer,
10 *    without modification, immediately at the beginning of the file.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 *    notice, this list of conditions and the following disclaimer in the
13 *    documentation and/or other materials provided with the distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
16 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
17 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
18 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
19 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
20 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
21 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
22 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
23 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
24 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
25 */
26
27#include <sys/cdefs.h>
28__FBSDID("$FreeBSD: stable/10/sys/cam/ctl/ctl_tpc.c 311417 2017-01-05 11:36:52Z mav $");
29
30#include <sys/param.h>
31#include <sys/systm.h>
32#include <sys/kernel.h>
33#include <sys/types.h>
34#include <sys/lock.h>
35#include <sys/module.h>
36#include <sys/mutex.h>
37#include <sys/condvar.h>
38#include <sys/malloc.h>
39#include <sys/conf.h>
40#include <sys/queue.h>
41#include <sys/sysctl.h>
42#include <machine/atomic.h>
43
44#include <cam/cam.h>
45#include <cam/scsi/scsi_all.h>
46#include <cam/scsi/scsi_da.h>
47#include <cam/ctl/ctl_io.h>
48#include <cam/ctl/ctl.h>
49#include <cam/ctl/ctl_frontend.h>
50#include <cam/ctl/ctl_util.h>
51#include <cam/ctl/ctl_backend.h>
52#include <cam/ctl/ctl_ioctl.h>
53#include <cam/ctl/ctl_ha.h>
54#include <cam/ctl/ctl_private.h>
55#include <cam/ctl/ctl_debug.h>
56#include <cam/ctl/ctl_scsi_all.h>
57#include <cam/ctl/ctl_tpc.h>
58#include <cam/ctl/ctl_error.h>
59
60#define	TPC_MAX_CSCDS	64
61#define	TPC_MAX_SEGS	64
62#define	TPC_MAX_SEG	0
63#define	TPC_MAX_LIST	8192
64#define	TPC_MAX_INLINE	0
65#define	TPC_MAX_LISTS	255
66#define	TPC_MAX_IO_SIZE	(1024 * 1024)
67#define	TPC_MAX_IOCHUNK_SIZE	(TPC_MAX_IO_SIZE * 16)
68#define	TPC_MIN_TOKEN_TIMEOUT	1
69#define	TPC_DFL_TOKEN_TIMEOUT	60
70#define	TPC_MAX_TOKEN_TIMEOUT	600
71
72MALLOC_DEFINE(M_CTL_TPC, "ctltpc", "CTL TPC");
73
74typedef enum {
75	TPC_ERR_RETRY		= 0x000,
76	TPC_ERR_FAIL		= 0x001,
77	TPC_ERR_MASK		= 0x0ff,
78	TPC_ERR_NO_DECREMENT	= 0x100
79} tpc_error_action;
80
81struct tpc_list;
82TAILQ_HEAD(runl, tpc_io);
83struct tpc_io {
84	union ctl_io		*io;
85	uint64_t		 lun;
86	struct tpc_list		*list;
87	struct runl		 run;
88	TAILQ_ENTRY(tpc_io)	 rlinks;
89	TAILQ_ENTRY(tpc_io)	 links;
90};
91
92struct tpc_token {
93	uint8_t			 token[512];
94	uint64_t		 lun;
95	uint32_t		 blocksize;
96	uint8_t			*params;
97	struct scsi_range_desc	*range;
98	int			 nrange;
99	int			 active;
100	time_t			 last_active;
101	uint32_t		 timeout;
102	TAILQ_ENTRY(tpc_token)	 links;
103};
104
105struct tpc_list {
106	uint8_t			 service_action;
107	int			 init_port;
108	uint32_t		 init_idx;
109	uint32_t		 list_id;
110	uint8_t			 flags;
111	uint8_t			*params;
112	struct scsi_ec_cscd	*cscd;
113	struct scsi_ec_segment	*seg[TPC_MAX_SEGS];
114	uint8_t			*inl;
115	int			 ncscd;
116	int			 nseg;
117	int			 leninl;
118	struct tpc_token	*token;
119	struct scsi_range_desc	*range;
120	int			 nrange;
121	off_t			 offset_into_rod;
122
123	int			 curseg;
124	off_t			 cursectors;
125	off_t			 curbytes;
126	int			 curops;
127	int			 stage;
128	uint8_t			*buf;
129	off_t			 segsectors;
130	off_t			 segbytes;
131	int			 tbdio;
132	int			 error;
133	int			 abort;
134	int			 completed;
135	time_t			 last_active;
136	TAILQ_HEAD(, tpc_io)	 allio;
137	struct scsi_sense_data	 sense_data;
138	uint8_t			 sense_len;
139	uint8_t			 scsi_status;
140	struct ctl_scsiio	*ctsio;
141	struct ctl_lun		*lun;
142	int			 res_token_valid;
143	uint8_t			 res_token[512];
144	TAILQ_ENTRY(tpc_list)	 links;
145};
146
147static void
148tpc_timeout(void *arg)
149{
150	struct ctl_softc *softc = arg;
151	struct ctl_lun *lun;
152	struct tpc_token *token, *ttoken;
153	struct tpc_list *list, *tlist;
154
155	/* Free completed lists with expired timeout. */
156	STAILQ_FOREACH(lun, &softc->lun_list, links) {
157		mtx_lock(&lun->lun_lock);
158		TAILQ_FOREACH_SAFE(list, &lun->tpc_lists, links, tlist) {
159			if (!list->completed || time_uptime < list->last_active +
160			    TPC_DFL_TOKEN_TIMEOUT)
161				continue;
162			TAILQ_REMOVE(&lun->tpc_lists, list, links);
163			free(list, M_CTL);
164		}
165		mtx_unlock(&lun->lun_lock);
166	}
167
168	/* Free inactive ROD tokens with expired timeout. */
169	mtx_lock(&softc->tpc_lock);
170	TAILQ_FOREACH_SAFE(token, &softc->tpc_tokens, links, ttoken) {
171		if (token->active ||
172		    time_uptime < token->last_active + token->timeout + 1)
173			continue;
174		TAILQ_REMOVE(&softc->tpc_tokens, token, links);
175		free(token->params, M_CTL);
176		free(token, M_CTL);
177	}
178	mtx_unlock(&softc->tpc_lock);
179	callout_schedule(&softc->tpc_timeout, hz);
180}
181
182void
183ctl_tpc_init(struct ctl_softc *softc)
184{
185
186	mtx_init(&softc->tpc_lock, "CTL TPC mutex", NULL, MTX_DEF);
187	TAILQ_INIT(&softc->tpc_tokens);
188	callout_init_mtx(&softc->tpc_timeout, &softc->ctl_lock, 0);
189	callout_reset(&softc->tpc_timeout, hz, tpc_timeout, softc);
190}
191
192void
193ctl_tpc_shutdown(struct ctl_softc *softc)
194{
195	struct tpc_token *token;
196
197	callout_drain(&softc->tpc_timeout);
198
199	/* Free ROD tokens. */
200	mtx_lock(&softc->tpc_lock);
201	while ((token = TAILQ_FIRST(&softc->tpc_tokens)) != NULL) {
202		TAILQ_REMOVE(&softc->tpc_tokens, token, links);
203		free(token->params, M_CTL);
204		free(token, M_CTL);
205	}
206	mtx_unlock(&softc->tpc_lock);
207	mtx_destroy(&softc->tpc_lock);
208}
209
210void
211ctl_tpc_lun_init(struct ctl_lun *lun)
212{
213
214	TAILQ_INIT(&lun->tpc_lists);
215}
216
217void
218ctl_tpc_lun_shutdown(struct ctl_lun *lun)
219{
220	struct ctl_softc *softc = lun->ctl_softc;
221	struct tpc_list *list;
222	struct tpc_token *token, *ttoken;
223
224	/* Free lists for this LUN. */
225	while ((list = TAILQ_FIRST(&lun->tpc_lists)) != NULL) {
226		TAILQ_REMOVE(&lun->tpc_lists, list, links);
227		KASSERT(list->completed,
228		    ("Not completed TPC (%p) on shutdown", list));
229		free(list, M_CTL);
230	}
231
232	/* Free ROD tokens for this LUN. */
233	mtx_lock(&softc->tpc_lock);
234	TAILQ_FOREACH_SAFE(token, &softc->tpc_tokens, links, ttoken) {
235		if (token->lun != lun->lun || token->active)
236			continue;
237		TAILQ_REMOVE(&softc->tpc_tokens, token, links);
238		free(token->params, M_CTL);
239		free(token, M_CTL);
240	}
241	mtx_unlock(&softc->tpc_lock);
242}
243
244int
245ctl_inquiry_evpd_tpc(struct ctl_scsiio *ctsio, int alloc_len)
246{
247	struct scsi_vpd_tpc *tpc_ptr;
248	struct scsi_vpd_tpc_descriptor *d_ptr;
249	struct scsi_vpd_tpc_descriptor_bdrl *bdrl_ptr;
250	struct scsi_vpd_tpc_descriptor_sc *sc_ptr;
251	struct scsi_vpd_tpc_descriptor_sc_descr *scd_ptr;
252	struct scsi_vpd_tpc_descriptor_pd *pd_ptr;
253	struct scsi_vpd_tpc_descriptor_sd *sd_ptr;
254	struct scsi_vpd_tpc_descriptor_sdid *sdid_ptr;
255	struct scsi_vpd_tpc_descriptor_rtf *rtf_ptr;
256	struct scsi_vpd_tpc_descriptor_rtf_block *rtfb_ptr;
257	struct scsi_vpd_tpc_descriptor_srt *srt_ptr;
258	struct scsi_vpd_tpc_descriptor_srtd *srtd_ptr;
259	struct scsi_vpd_tpc_descriptor_gco *gco_ptr;
260	struct ctl_lun *lun;
261	int data_len;
262
263	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
264
265	data_len = sizeof(struct scsi_vpd_tpc) +
266	    sizeof(struct scsi_vpd_tpc_descriptor_bdrl) +
267	    roundup2(sizeof(struct scsi_vpd_tpc_descriptor_sc) +
268	     2 * sizeof(struct scsi_vpd_tpc_descriptor_sc_descr) + 11, 4) +
269	    sizeof(struct scsi_vpd_tpc_descriptor_pd) +
270	    roundup2(sizeof(struct scsi_vpd_tpc_descriptor_sd) + 4, 4) +
271	    roundup2(sizeof(struct scsi_vpd_tpc_descriptor_sdid) + 2, 4) +
272	    sizeof(struct scsi_vpd_tpc_descriptor_rtf) +
273	     sizeof(struct scsi_vpd_tpc_descriptor_rtf_block) +
274	    sizeof(struct scsi_vpd_tpc_descriptor_srt) +
275	     2*sizeof(struct scsi_vpd_tpc_descriptor_srtd) +
276	    sizeof(struct scsi_vpd_tpc_descriptor_gco);
277
278	ctsio->kern_data_ptr = malloc(data_len, M_CTL, M_WAITOK | M_ZERO);
279	tpc_ptr = (struct scsi_vpd_tpc *)ctsio->kern_data_ptr;
280	ctsio->kern_sg_entries = 0;
281
282	if (data_len < alloc_len) {
283		ctsio->residual = alloc_len - data_len;
284		ctsio->kern_data_len = data_len;
285		ctsio->kern_total_len = data_len;
286	} else {
287		ctsio->residual = 0;
288		ctsio->kern_data_len = alloc_len;
289		ctsio->kern_total_len = alloc_len;
290	}
291	ctsio->kern_data_resid = 0;
292	ctsio->kern_rel_offset = 0;
293	ctsio->kern_sg_entries = 0;
294
295	/*
296	 * The control device is always connected.  The disk device, on the
297	 * other hand, may not be online all the time.
298	 */
299	if (lun != NULL)
300		tpc_ptr->device = (SID_QUAL_LU_CONNECTED << 5) |
301				     lun->be_lun->lun_type;
302	else
303		tpc_ptr->device = (SID_QUAL_LU_OFFLINE << 5) | T_DIRECT;
304	tpc_ptr->page_code = SVPD_SCSI_TPC;
305	scsi_ulto2b(data_len - 4, tpc_ptr->page_length);
306
307	/* Block Device ROD Limits */
308	d_ptr = (struct scsi_vpd_tpc_descriptor *)&tpc_ptr->descr[0];
309	bdrl_ptr = (struct scsi_vpd_tpc_descriptor_bdrl *)d_ptr;
310	scsi_ulto2b(SVPD_TPC_BDRL, bdrl_ptr->desc_type);
311	scsi_ulto2b(sizeof(*bdrl_ptr) - 4, bdrl_ptr->desc_length);
312	scsi_ulto2b(TPC_MAX_SEGS, bdrl_ptr->maximum_ranges);
313	scsi_ulto4b(TPC_MAX_TOKEN_TIMEOUT,
314	    bdrl_ptr->maximum_inactivity_timeout);
315	scsi_ulto4b(TPC_DFL_TOKEN_TIMEOUT,
316	    bdrl_ptr->default_inactivity_timeout);
317	scsi_u64to8b(0, bdrl_ptr->maximum_token_transfer_size);
318	scsi_u64to8b(0, bdrl_ptr->optimal_transfer_count);
319
320	/* Supported commands */
321	d_ptr = (struct scsi_vpd_tpc_descriptor *)
322	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
323	sc_ptr = (struct scsi_vpd_tpc_descriptor_sc *)d_ptr;
324	scsi_ulto2b(SVPD_TPC_SC, sc_ptr->desc_type);
325	sc_ptr->list_length = 2 * sizeof(*scd_ptr) + 11;
326	scsi_ulto2b(roundup2(1 + sc_ptr->list_length, 4), sc_ptr->desc_length);
327	scd_ptr = &sc_ptr->descr[0];
328	scd_ptr->opcode = EXTENDED_COPY;
329	scd_ptr->sa_length = 5;
330	scd_ptr->supported_service_actions[0] = EC_EC_LID1;
331	scd_ptr->supported_service_actions[1] = EC_EC_LID4;
332	scd_ptr->supported_service_actions[2] = EC_PT;
333	scd_ptr->supported_service_actions[3] = EC_WUT;
334	scd_ptr->supported_service_actions[4] = EC_COA;
335	scd_ptr = (struct scsi_vpd_tpc_descriptor_sc_descr *)
336	    &scd_ptr->supported_service_actions[scd_ptr->sa_length];
337	scd_ptr->opcode = RECEIVE_COPY_STATUS;
338	scd_ptr->sa_length = 6;
339	scd_ptr->supported_service_actions[0] = RCS_RCS_LID1;
340	scd_ptr->supported_service_actions[1] = RCS_RCFD;
341	scd_ptr->supported_service_actions[2] = RCS_RCS_LID4;
342	scd_ptr->supported_service_actions[3] = RCS_RCOP;
343	scd_ptr->supported_service_actions[4] = RCS_RRTI;
344	scd_ptr->supported_service_actions[5] = RCS_RART;
345
346	/* Parameter data. */
347	d_ptr = (struct scsi_vpd_tpc_descriptor *)
348	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
349	pd_ptr = (struct scsi_vpd_tpc_descriptor_pd *)d_ptr;
350	scsi_ulto2b(SVPD_TPC_PD, pd_ptr->desc_type);
351	scsi_ulto2b(sizeof(*pd_ptr) - 4, pd_ptr->desc_length);
352	scsi_ulto2b(TPC_MAX_CSCDS, pd_ptr->maximum_cscd_descriptor_count);
353	scsi_ulto2b(TPC_MAX_SEGS, pd_ptr->maximum_segment_descriptor_count);
354	scsi_ulto4b(TPC_MAX_LIST, pd_ptr->maximum_descriptor_list_length);
355	scsi_ulto4b(TPC_MAX_INLINE, pd_ptr->maximum_inline_data_length);
356
357	/* Supported Descriptors */
358	d_ptr = (struct scsi_vpd_tpc_descriptor *)
359	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
360	sd_ptr = (struct scsi_vpd_tpc_descriptor_sd *)d_ptr;
361	scsi_ulto2b(SVPD_TPC_SD, sd_ptr->desc_type);
362	scsi_ulto2b(roundup2(sizeof(*sd_ptr) - 4 + 4, 4), sd_ptr->desc_length);
363	sd_ptr->list_length = 4;
364	sd_ptr->supported_descriptor_codes[0] = EC_SEG_B2B;
365	sd_ptr->supported_descriptor_codes[1] = EC_SEG_VERIFY;
366	sd_ptr->supported_descriptor_codes[2] = EC_SEG_REGISTER_KEY;
367	sd_ptr->supported_descriptor_codes[3] = EC_CSCD_ID;
368
369	/* Supported CSCD Descriptor IDs */
370	d_ptr = (struct scsi_vpd_tpc_descriptor *)
371	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
372	sdid_ptr = (struct scsi_vpd_tpc_descriptor_sdid *)d_ptr;
373	scsi_ulto2b(SVPD_TPC_SDID, sdid_ptr->desc_type);
374	scsi_ulto2b(roundup2(sizeof(*sdid_ptr) - 4 + 2, 4), sdid_ptr->desc_length);
375	scsi_ulto2b(2, sdid_ptr->list_length);
376	scsi_ulto2b(0xffff, &sdid_ptr->supported_descriptor_ids[0]);
377
378	/* ROD Token Features */
379	d_ptr = (struct scsi_vpd_tpc_descriptor *)
380	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
381	rtf_ptr = (struct scsi_vpd_tpc_descriptor_rtf *)d_ptr;
382	scsi_ulto2b(SVPD_TPC_RTF, rtf_ptr->desc_type);
383	scsi_ulto2b(sizeof(*rtf_ptr) - 4 + sizeof(*rtfb_ptr), rtf_ptr->desc_length);
384	rtf_ptr->remote_tokens = 0;
385	scsi_ulto4b(TPC_MIN_TOKEN_TIMEOUT, rtf_ptr->minimum_token_lifetime);
386	scsi_ulto4b(UINT32_MAX, rtf_ptr->maximum_token_lifetime);
387	scsi_ulto4b(TPC_MAX_TOKEN_TIMEOUT,
388	    rtf_ptr->maximum_token_inactivity_timeout);
389	scsi_ulto2b(sizeof(*rtfb_ptr), rtf_ptr->type_specific_features_length);
390	rtfb_ptr = (struct scsi_vpd_tpc_descriptor_rtf_block *)
391	    &rtf_ptr->type_specific_features;
392	rtfb_ptr->type_format = SVPD_TPC_RTF_BLOCK;
393	scsi_ulto2b(sizeof(*rtfb_ptr) - 4, rtfb_ptr->desc_length);
394	scsi_ulto2b(0, rtfb_ptr->optimal_length_granularity);
395	scsi_u64to8b(0, rtfb_ptr->maximum_bytes);
396	scsi_u64to8b(0, rtfb_ptr->optimal_bytes);
397	scsi_u64to8b(UINT64_MAX, rtfb_ptr->optimal_bytes_to_token_per_segment);
398	scsi_u64to8b(TPC_MAX_IOCHUNK_SIZE,
399	    rtfb_ptr->optimal_bytes_from_token_per_segment);
400
401	/* Supported ROD Tokens */
402	d_ptr = (struct scsi_vpd_tpc_descriptor *)
403	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
404	srt_ptr = (struct scsi_vpd_tpc_descriptor_srt *)d_ptr;
405	scsi_ulto2b(SVPD_TPC_SRT, srt_ptr->desc_type);
406	scsi_ulto2b(sizeof(*srt_ptr) - 4 + 2*sizeof(*srtd_ptr), srt_ptr->desc_length);
407	scsi_ulto2b(2*sizeof(*srtd_ptr), srt_ptr->rod_type_descriptors_length);
408	srtd_ptr = (struct scsi_vpd_tpc_descriptor_srtd *)
409	    &srt_ptr->rod_type_descriptors;
410	scsi_ulto4b(ROD_TYPE_AUR, srtd_ptr->rod_type);
411	srtd_ptr->flags = SVPD_TPC_SRTD_TIN | SVPD_TPC_SRTD_TOUT;
412	scsi_ulto2b(0, srtd_ptr->preference_indicator);
413	srtd_ptr++;
414	scsi_ulto4b(ROD_TYPE_BLOCK_ZERO, srtd_ptr->rod_type);
415	srtd_ptr->flags = SVPD_TPC_SRTD_TIN;
416	scsi_ulto2b(0, srtd_ptr->preference_indicator);
417
418	/* General Copy Operations */
419	d_ptr = (struct scsi_vpd_tpc_descriptor *)
420	    (&d_ptr->parameters[0] + scsi_2btoul(d_ptr->desc_length));
421	gco_ptr = (struct scsi_vpd_tpc_descriptor_gco *)d_ptr;
422	scsi_ulto2b(SVPD_TPC_GCO, gco_ptr->desc_type);
423	scsi_ulto2b(sizeof(*gco_ptr) - 4, gco_ptr->desc_length);
424	scsi_ulto4b(TPC_MAX_LISTS, gco_ptr->total_concurrent_copies);
425	scsi_ulto4b(TPC_MAX_LISTS, gco_ptr->maximum_identified_concurrent_copies);
426	scsi_ulto4b(TPC_MAX_SEG, gco_ptr->maximum_segment_length);
427	gco_ptr->data_segment_granularity = 0;
428	gco_ptr->inline_data_granularity = 0;
429
430	ctl_set_success(ctsio);
431	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
432	ctsio->be_move_done = ctl_config_move_done;
433	ctl_datamove((union ctl_io *)ctsio);
434
435	return (CTL_RETVAL_COMPLETE);
436}
437
438int
439ctl_receive_copy_operating_parameters(struct ctl_scsiio *ctsio)
440{
441	struct scsi_receive_copy_operating_parameters *cdb;
442	struct scsi_receive_copy_operating_parameters_data *data;
443	int retval;
444	int alloc_len, total_len;
445
446	CTL_DEBUG_PRINT(("ctl_report_supported_tmf\n"));
447
448	cdb = (struct scsi_receive_copy_operating_parameters *)ctsio->cdb;
449
450	retval = CTL_RETVAL_COMPLETE;
451
452	total_len = sizeof(*data) + 4;
453	alloc_len = scsi_4btoul(cdb->length);
454
455	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
456
457	ctsio->kern_sg_entries = 0;
458
459	if (total_len < alloc_len) {
460		ctsio->residual = alloc_len - total_len;
461		ctsio->kern_data_len = total_len;
462		ctsio->kern_total_len = total_len;
463	} else {
464		ctsio->residual = 0;
465		ctsio->kern_data_len = alloc_len;
466		ctsio->kern_total_len = alloc_len;
467	}
468	ctsio->kern_data_resid = 0;
469	ctsio->kern_rel_offset = 0;
470
471	data = (struct scsi_receive_copy_operating_parameters_data *)ctsio->kern_data_ptr;
472	scsi_ulto4b(sizeof(*data) - 4 + 4, data->length);
473	data->snlid = RCOP_SNLID;
474	scsi_ulto2b(TPC_MAX_CSCDS, data->maximum_cscd_descriptor_count);
475	scsi_ulto2b(TPC_MAX_SEGS, data->maximum_segment_descriptor_count);
476	scsi_ulto4b(TPC_MAX_LIST, data->maximum_descriptor_list_length);
477	scsi_ulto4b(TPC_MAX_SEG, data->maximum_segment_length);
478	scsi_ulto4b(TPC_MAX_INLINE, data->maximum_inline_data_length);
479	scsi_ulto4b(0, data->held_data_limit);
480	scsi_ulto4b(0, data->maximum_stream_device_transfer_size);
481	scsi_ulto2b(TPC_MAX_LISTS, data->total_concurrent_copies);
482	data->maximum_concurrent_copies = TPC_MAX_LISTS;
483	data->data_segment_granularity = 0;
484	data->inline_data_granularity = 0;
485	data->held_data_granularity = 0;
486	data->implemented_descriptor_list_length = 4;
487	data->list_of_implemented_descriptor_type_codes[0] = EC_SEG_B2B;
488	data->list_of_implemented_descriptor_type_codes[1] = EC_SEG_VERIFY;
489	data->list_of_implemented_descriptor_type_codes[2] = EC_SEG_REGISTER_KEY;
490	data->list_of_implemented_descriptor_type_codes[3] = EC_CSCD_ID;
491
492	ctl_set_success(ctsio);
493	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
494	ctsio->be_move_done = ctl_config_move_done;
495	ctl_datamove((union ctl_io *)ctsio);
496	return (retval);
497}
498
499static struct tpc_list *
500tpc_find_list(struct ctl_lun *lun, uint32_t list_id, uint32_t init_idx)
501{
502	struct tpc_list *list;
503
504	mtx_assert(&lun->lun_lock, MA_OWNED);
505	TAILQ_FOREACH(list, &lun->tpc_lists, links) {
506		if ((list->flags & EC_LIST_ID_USAGE_MASK) !=
507		     EC_LIST_ID_USAGE_NONE && list->list_id == list_id &&
508		    list->init_idx == init_idx)
509			break;
510	}
511	return (list);
512}
513
514int
515ctl_receive_copy_status_lid1(struct ctl_scsiio *ctsio)
516{
517	struct ctl_lun *lun;
518	struct scsi_receive_copy_status_lid1 *cdb;
519	struct scsi_receive_copy_status_lid1_data *data;
520	struct tpc_list *list;
521	struct tpc_list list_copy;
522	int retval;
523	int alloc_len, total_len;
524	uint32_t list_id;
525
526	CTL_DEBUG_PRINT(("ctl_receive_copy_status_lid1\n"));
527
528	cdb = (struct scsi_receive_copy_status_lid1 *)ctsio->cdb;
529	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
530
531	retval = CTL_RETVAL_COMPLETE;
532
533	list_id = cdb->list_identifier;
534	mtx_lock(&lun->lun_lock);
535	list = tpc_find_list(lun, list_id,
536	    ctl_get_initindex(&ctsio->io_hdr.nexus));
537	if (list == NULL) {
538		mtx_unlock(&lun->lun_lock);
539		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
540		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
541		    /*bit*/ 0);
542		ctl_done((union ctl_io *)ctsio);
543		return (retval);
544	}
545	list_copy = *list;
546	if (list->completed) {
547		TAILQ_REMOVE(&lun->tpc_lists, list, links);
548		free(list, M_CTL);
549	}
550	mtx_unlock(&lun->lun_lock);
551
552	total_len = sizeof(*data);
553	alloc_len = scsi_4btoul(cdb->length);
554
555	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
556
557	ctsio->kern_sg_entries = 0;
558
559	if (total_len < alloc_len) {
560		ctsio->residual = alloc_len - total_len;
561		ctsio->kern_data_len = total_len;
562		ctsio->kern_total_len = total_len;
563	} else {
564		ctsio->residual = 0;
565		ctsio->kern_data_len = alloc_len;
566		ctsio->kern_total_len = alloc_len;
567	}
568	ctsio->kern_data_resid = 0;
569	ctsio->kern_rel_offset = 0;
570
571	data = (struct scsi_receive_copy_status_lid1_data *)ctsio->kern_data_ptr;
572	scsi_ulto4b(sizeof(*data) - 4, data->available_data);
573	if (list_copy.completed) {
574		if (list_copy.error || list_copy.abort)
575			data->copy_command_status = RCS_CCS_ERROR;
576		else
577			data->copy_command_status = RCS_CCS_COMPLETED;
578	} else
579		data->copy_command_status = RCS_CCS_INPROG;
580	scsi_ulto2b(list_copy.curseg, data->segments_processed);
581	if (list_copy.curbytes <= UINT32_MAX) {
582		data->transfer_count_units = RCS_TC_BYTES;
583		scsi_ulto4b(list_copy.curbytes, data->transfer_count);
584	} else {
585		data->transfer_count_units = RCS_TC_MBYTES;
586		scsi_ulto4b(list_copy.curbytes >> 20, data->transfer_count);
587	}
588
589	ctl_set_success(ctsio);
590	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
591	ctsio->be_move_done = ctl_config_move_done;
592	ctl_datamove((union ctl_io *)ctsio);
593	return (retval);
594}
595
596int
597ctl_receive_copy_failure_details(struct ctl_scsiio *ctsio)
598{
599	struct ctl_lun *lun;
600	struct scsi_receive_copy_failure_details *cdb;
601	struct scsi_receive_copy_failure_details_data *data;
602	struct tpc_list *list;
603	struct tpc_list list_copy;
604	int retval;
605	int alloc_len, total_len;
606	uint32_t list_id;
607
608	CTL_DEBUG_PRINT(("ctl_receive_copy_failure_details\n"));
609
610	cdb = (struct scsi_receive_copy_failure_details *)ctsio->cdb;
611	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
612
613	retval = CTL_RETVAL_COMPLETE;
614
615	list_id = cdb->list_identifier;
616	mtx_lock(&lun->lun_lock);
617	list = tpc_find_list(lun, list_id,
618	    ctl_get_initindex(&ctsio->io_hdr.nexus));
619	if (list == NULL || !list->completed) {
620		mtx_unlock(&lun->lun_lock);
621		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
622		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
623		    /*bit*/ 0);
624		ctl_done((union ctl_io *)ctsio);
625		return (retval);
626	}
627	list_copy = *list;
628	TAILQ_REMOVE(&lun->tpc_lists, list, links);
629	free(list, M_CTL);
630	mtx_unlock(&lun->lun_lock);
631
632	total_len = sizeof(*data) + list_copy.sense_len;
633	alloc_len = scsi_4btoul(cdb->length);
634
635	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
636
637	ctsio->kern_sg_entries = 0;
638
639	if (total_len < alloc_len) {
640		ctsio->residual = alloc_len - total_len;
641		ctsio->kern_data_len = total_len;
642		ctsio->kern_total_len = total_len;
643	} else {
644		ctsio->residual = 0;
645		ctsio->kern_data_len = alloc_len;
646		ctsio->kern_total_len = alloc_len;
647	}
648	ctsio->kern_data_resid = 0;
649	ctsio->kern_rel_offset = 0;
650
651	data = (struct scsi_receive_copy_failure_details_data *)ctsio->kern_data_ptr;
652	if (list_copy.completed && (list_copy.error || list_copy.abort)) {
653		scsi_ulto4b(sizeof(*data) - 4 + list_copy.sense_len,
654		    data->available_data);
655		data->copy_command_status = RCS_CCS_ERROR;
656	} else
657		scsi_ulto4b(0, data->available_data);
658	scsi_ulto2b(list_copy.sense_len, data->sense_data_length);
659	memcpy(data->sense_data, &list_copy.sense_data, list_copy.sense_len);
660
661	ctl_set_success(ctsio);
662	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
663	ctsio->be_move_done = ctl_config_move_done;
664	ctl_datamove((union ctl_io *)ctsio);
665	return (retval);
666}
667
668int
669ctl_receive_copy_status_lid4(struct ctl_scsiio *ctsio)
670{
671	struct ctl_lun *lun;
672	struct scsi_receive_copy_status_lid4 *cdb;
673	struct scsi_receive_copy_status_lid4_data *data;
674	struct tpc_list *list;
675	struct tpc_list list_copy;
676	int retval;
677	int alloc_len, total_len;
678	uint32_t list_id;
679
680	CTL_DEBUG_PRINT(("ctl_receive_copy_status_lid4\n"));
681
682	cdb = (struct scsi_receive_copy_status_lid4 *)ctsio->cdb;
683	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
684
685	retval = CTL_RETVAL_COMPLETE;
686
687	list_id = scsi_4btoul(cdb->list_identifier);
688	mtx_lock(&lun->lun_lock);
689	list = tpc_find_list(lun, list_id,
690	    ctl_get_initindex(&ctsio->io_hdr.nexus));
691	if (list == NULL) {
692		mtx_unlock(&lun->lun_lock);
693		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
694		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
695		    /*bit*/ 0);
696		ctl_done((union ctl_io *)ctsio);
697		return (retval);
698	}
699	list_copy = *list;
700	if (list->completed) {
701		TAILQ_REMOVE(&lun->tpc_lists, list, links);
702		free(list, M_CTL);
703	}
704	mtx_unlock(&lun->lun_lock);
705
706	total_len = sizeof(*data) + list_copy.sense_len;
707	alloc_len = scsi_4btoul(cdb->length);
708
709	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
710
711	ctsio->kern_sg_entries = 0;
712
713	if (total_len < alloc_len) {
714		ctsio->residual = alloc_len - total_len;
715		ctsio->kern_data_len = total_len;
716		ctsio->kern_total_len = total_len;
717	} else {
718		ctsio->residual = 0;
719		ctsio->kern_data_len = alloc_len;
720		ctsio->kern_total_len = alloc_len;
721	}
722	ctsio->kern_data_resid = 0;
723	ctsio->kern_rel_offset = 0;
724
725	data = (struct scsi_receive_copy_status_lid4_data *)ctsio->kern_data_ptr;
726	scsi_ulto4b(sizeof(*data) - 4 + list_copy.sense_len,
727	    data->available_data);
728	data->response_to_service_action = list_copy.service_action;
729	if (list_copy.completed) {
730		if (list_copy.error)
731			data->copy_command_status = RCS_CCS_ERROR;
732		else if (list_copy.abort)
733			data->copy_command_status = RCS_CCS_ABORTED;
734		else
735			data->copy_command_status = RCS_CCS_COMPLETED;
736	} else
737		data->copy_command_status = RCS_CCS_INPROG_FG;
738	scsi_ulto2b(list_copy.curops, data->operation_counter);
739	scsi_ulto4b(UINT32_MAX, data->estimated_status_update_delay);
740	data->transfer_count_units = RCS_TC_BYTES;
741	scsi_u64to8b(list_copy.curbytes, data->transfer_count);
742	scsi_ulto2b(list_copy.curseg, data->segments_processed);
743	data->length_of_the_sense_data_field = list_copy.sense_len;
744	data->sense_data_length = list_copy.sense_len;
745	memcpy(data->sense_data, &list_copy.sense_data, list_copy.sense_len);
746
747	ctl_set_success(ctsio);
748	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
749	ctsio->be_move_done = ctl_config_move_done;
750	ctl_datamove((union ctl_io *)ctsio);
751	return (retval);
752}
753
754int
755ctl_copy_operation_abort(struct ctl_scsiio *ctsio)
756{
757	struct ctl_lun *lun;
758	struct scsi_copy_operation_abort *cdb;
759	struct tpc_list *list;
760	int retval;
761	uint32_t list_id;
762
763	CTL_DEBUG_PRINT(("ctl_copy_operation_abort\n"));
764
765	cdb = (struct scsi_copy_operation_abort *)ctsio->cdb;
766	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
767
768	retval = CTL_RETVAL_COMPLETE;
769
770	list_id = scsi_4btoul(cdb->list_identifier);
771	mtx_lock(&lun->lun_lock);
772	list = tpc_find_list(lun, list_id,
773	    ctl_get_initindex(&ctsio->io_hdr.nexus));
774	if (list == NULL) {
775		mtx_unlock(&lun->lun_lock);
776		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
777		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
778		    /*bit*/ 0);
779		ctl_done((union ctl_io *)ctsio);
780		return (retval);
781	}
782	list->abort = 1;
783	mtx_unlock(&lun->lun_lock);
784
785	ctl_set_success(ctsio);
786	ctl_done((union ctl_io *)ctsio);
787	return (retval);
788}
789
790static uint64_t
791tpc_resolve(struct tpc_list *list, uint16_t idx, uint32_t *ss,
792    uint32_t *pb, uint32_t *pbo)
793{
794
795	if (idx == 0xffff) {
796		if (ss && list->lun->be_lun)
797			*ss = list->lun->be_lun->blocksize;
798		if (pb && list->lun->be_lun)
799			*pb = list->lun->be_lun->blocksize <<
800			    list->lun->be_lun->pblockexp;
801		if (pbo && list->lun->be_lun)
802			*pbo = list->lun->be_lun->blocksize *
803			    list->lun->be_lun->pblockoff;
804		return (list->lun->lun);
805	}
806	if (idx >= list->ncscd)
807		return (UINT64_MAX);
808	return (tpcl_resolve(list->lun->ctl_softc,
809	    list->init_port, &list->cscd[idx], ss, pb, pbo));
810}
811
812static int
813tpc_process_b2b(struct tpc_list *list)
814{
815	struct scsi_ec_segment_b2b *seg;
816	struct scsi_ec_cscd_dtsp *sdstp, *ddstp;
817	struct tpc_io *tior, *tiow;
818	struct runl run;
819	uint64_t sl, dl;
820	off_t srclba, dstlba, numbytes, donebytes, roundbytes;
821	int numlba;
822	uint32_t srcblock, dstblock, pb, pbo, adj;
823	uint8_t csi[4];
824
825	scsi_ulto4b(list->curseg, csi);
826	if (list->stage == 1) {
827		while ((tior = TAILQ_FIRST(&list->allio)) != NULL) {
828			TAILQ_REMOVE(&list->allio, tior, links);
829			ctl_free_io(tior->io);
830			free(tior, M_CTL);
831		}
832		free(list->buf, M_CTL);
833		if (list->abort) {
834			ctl_set_task_aborted(list->ctsio);
835			return (CTL_RETVAL_ERROR);
836		} else if (list->error) {
837			ctl_set_sense(list->ctsio, /*current_error*/ 1,
838			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
839			    /*asc*/ 0x0d, /*ascq*/ 0x01,
840			    SSD_ELEM_COMMAND, sizeof(csi), csi,
841			    SSD_ELEM_NONE);
842			return (CTL_RETVAL_ERROR);
843		}
844		list->cursectors += list->segsectors;
845		list->curbytes += list->segbytes;
846		return (CTL_RETVAL_COMPLETE);
847	}
848
849	TAILQ_INIT(&list->allio);
850	seg = (struct scsi_ec_segment_b2b *)list->seg[list->curseg];
851	sl = tpc_resolve(list, scsi_2btoul(seg->src_cscd), &srcblock, NULL, NULL);
852	dl = tpc_resolve(list, scsi_2btoul(seg->dst_cscd), &dstblock, &pb, &pbo);
853	if (sl >= CTL_MAX_LUNS || dl >= CTL_MAX_LUNS) {
854		ctl_set_sense(list->ctsio, /*current_error*/ 1,
855		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
856		    /*asc*/ 0x08, /*ascq*/ 0x04,
857		    SSD_ELEM_COMMAND, sizeof(csi), csi,
858		    SSD_ELEM_NONE);
859		return (CTL_RETVAL_ERROR);
860	}
861	if (pbo > 0)
862		pbo = pb - pbo;
863	sdstp = &list->cscd[scsi_2btoul(seg->src_cscd)].dtsp;
864	if (scsi_3btoul(sdstp->block_length) != 0)
865		srcblock = scsi_3btoul(sdstp->block_length);
866	ddstp = &list->cscd[scsi_2btoul(seg->dst_cscd)].dtsp;
867	if (scsi_3btoul(ddstp->block_length) != 0)
868		dstblock = scsi_3btoul(ddstp->block_length);
869	numlba = scsi_2btoul(seg->number_of_blocks);
870	if (seg->flags & EC_SEG_DC)
871		numbytes = (off_t)numlba * dstblock;
872	else
873		numbytes = (off_t)numlba * srcblock;
874	srclba = scsi_8btou64(seg->src_lba);
875	dstlba = scsi_8btou64(seg->dst_lba);
876
877//	printf("Copy %ju bytes from %ju @ %ju to %ju @ %ju\n",
878//	    (uintmax_t)numbytes, sl, scsi_8btou64(seg->src_lba),
879//	    dl, scsi_8btou64(seg->dst_lba));
880
881	if (numbytes == 0)
882		return (CTL_RETVAL_COMPLETE);
883
884	if (numbytes % srcblock != 0 || numbytes % dstblock != 0) {
885		ctl_set_sense(list->ctsio, /*current_error*/ 1,
886		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
887		    /*asc*/ 0x26, /*ascq*/ 0x0A,
888		    SSD_ELEM_COMMAND, sizeof(csi), csi,
889		    SSD_ELEM_NONE);
890		return (CTL_RETVAL_ERROR);
891	}
892
893	list->buf = malloc(numbytes, M_CTL, M_WAITOK);
894	list->segbytes = numbytes;
895	list->segsectors = numbytes / dstblock;
896	donebytes = 0;
897	TAILQ_INIT(&run);
898	list->tbdio = 0;
899	while (donebytes < numbytes) {
900		roundbytes = numbytes - donebytes;
901		if (roundbytes > TPC_MAX_IO_SIZE) {
902			roundbytes = TPC_MAX_IO_SIZE;
903			roundbytes -= roundbytes % dstblock;
904			if (pb > dstblock) {
905				adj = (dstlba * dstblock + roundbytes - pbo) % pb;
906				if (roundbytes > adj)
907					roundbytes -= adj;
908			}
909		}
910
911		tior = malloc(sizeof(*tior), M_CTL, M_WAITOK | M_ZERO);
912		TAILQ_INIT(&tior->run);
913		tior->list = list;
914		TAILQ_INSERT_TAIL(&list->allio, tior, links);
915		tior->io = tpcl_alloc_io();
916		ctl_scsi_read_write(tior->io,
917				    /*data_ptr*/ &list->buf[donebytes],
918				    /*data_len*/ roundbytes,
919				    /*read_op*/ 1,
920				    /*byte2*/ 0,
921				    /*minimum_cdb_size*/ 0,
922				    /*lba*/ srclba,
923				    /*num_blocks*/ roundbytes / srcblock,
924				    /*tag_type*/ CTL_TAG_SIMPLE,
925				    /*control*/ 0);
926		tior->io->io_hdr.retries = 3;
927		tior->lun = sl;
928		tior->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tior;
929
930		tiow = malloc(sizeof(*tior), M_CTL, M_WAITOK | M_ZERO);
931		TAILQ_INIT(&tiow->run);
932		tiow->list = list;
933		TAILQ_INSERT_TAIL(&list->allio, tiow, links);
934		tiow->io = tpcl_alloc_io();
935		ctl_scsi_read_write(tiow->io,
936				    /*data_ptr*/ &list->buf[donebytes],
937				    /*data_len*/ roundbytes,
938				    /*read_op*/ 0,
939				    /*byte2*/ 0,
940				    /*minimum_cdb_size*/ 0,
941				    /*lba*/ dstlba,
942				    /*num_blocks*/ roundbytes / dstblock,
943				    /*tag_type*/ CTL_TAG_SIMPLE,
944				    /*control*/ 0);
945		tiow->io->io_hdr.retries = 3;
946		tiow->lun = dl;
947		tiow->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tiow;
948
949		TAILQ_INSERT_TAIL(&tior->run, tiow, rlinks);
950		TAILQ_INSERT_TAIL(&run, tior, rlinks);
951		list->tbdio++;
952		donebytes += roundbytes;
953		srclba += roundbytes / srcblock;
954		dstlba += roundbytes / dstblock;
955	}
956
957	while ((tior = TAILQ_FIRST(&run)) != NULL) {
958		TAILQ_REMOVE(&run, tior, rlinks);
959		if (tpcl_queue(tior->io, tior->lun) != CTL_RETVAL_COMPLETE)
960			panic("tpcl_queue() error");
961	}
962
963	list->stage++;
964	return (CTL_RETVAL_QUEUED);
965}
966
967static int
968tpc_process_verify(struct tpc_list *list)
969{
970	struct scsi_ec_segment_verify *seg;
971	struct tpc_io *tio;
972	uint64_t sl;
973	uint8_t csi[4];
974
975	scsi_ulto4b(list->curseg, csi);
976	if (list->stage == 1) {
977		while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
978			TAILQ_REMOVE(&list->allio, tio, links);
979			ctl_free_io(tio->io);
980			free(tio, M_CTL);
981		}
982		if (list->abort) {
983			ctl_set_task_aborted(list->ctsio);
984			return (CTL_RETVAL_ERROR);
985		} else if (list->error) {
986			ctl_set_sense(list->ctsio, /*current_error*/ 1,
987			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
988			    /*asc*/ 0x0d, /*ascq*/ 0x01,
989			    SSD_ELEM_COMMAND, sizeof(csi), csi,
990			    SSD_ELEM_NONE);
991			return (CTL_RETVAL_ERROR);
992		} else
993			return (CTL_RETVAL_COMPLETE);
994	}
995
996	TAILQ_INIT(&list->allio);
997	seg = (struct scsi_ec_segment_verify *)list->seg[list->curseg];
998	sl = tpc_resolve(list, scsi_2btoul(seg->src_cscd), NULL, NULL, NULL);
999	if (sl >= CTL_MAX_LUNS) {
1000		ctl_set_sense(list->ctsio, /*current_error*/ 1,
1001		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1002		    /*asc*/ 0x08, /*ascq*/ 0x04,
1003		    SSD_ELEM_COMMAND, sizeof(csi), csi,
1004		    SSD_ELEM_NONE);
1005		return (CTL_RETVAL_ERROR);
1006	}
1007
1008//	printf("Verify %ju\n", sl);
1009
1010	if ((seg->tur & 0x01) == 0)
1011		return (CTL_RETVAL_COMPLETE);
1012
1013	list->tbdio = 1;
1014	tio = malloc(sizeof(*tio), M_CTL, M_WAITOK | M_ZERO);
1015	TAILQ_INIT(&tio->run);
1016	tio->list = list;
1017	TAILQ_INSERT_TAIL(&list->allio, tio, links);
1018	tio->io = tpcl_alloc_io();
1019	ctl_scsi_tur(tio->io, /*tag_type*/ CTL_TAG_SIMPLE, /*control*/ 0);
1020	tio->io->io_hdr.retries = 3;
1021	tio->lun = sl;
1022	tio->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tio;
1023	list->stage++;
1024	if (tpcl_queue(tio->io, tio->lun) != CTL_RETVAL_COMPLETE)
1025		panic("tpcl_queue() error");
1026	return (CTL_RETVAL_QUEUED);
1027}
1028
1029static int
1030tpc_process_register_key(struct tpc_list *list)
1031{
1032	struct scsi_ec_segment_register_key *seg;
1033	struct tpc_io *tio;
1034	uint64_t dl;
1035	int datalen;
1036	uint8_t csi[4];
1037
1038	scsi_ulto4b(list->curseg, csi);
1039	if (list->stage == 1) {
1040		while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
1041			TAILQ_REMOVE(&list->allio, tio, links);
1042			ctl_free_io(tio->io);
1043			free(tio, M_CTL);
1044		}
1045		free(list->buf, M_CTL);
1046		if (list->abort) {
1047			ctl_set_task_aborted(list->ctsio);
1048			return (CTL_RETVAL_ERROR);
1049		} else if (list->error) {
1050			ctl_set_sense(list->ctsio, /*current_error*/ 1,
1051			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1052			    /*asc*/ 0x0d, /*ascq*/ 0x01,
1053			    SSD_ELEM_COMMAND, sizeof(csi), csi,
1054			    SSD_ELEM_NONE);
1055			return (CTL_RETVAL_ERROR);
1056		} else
1057			return (CTL_RETVAL_COMPLETE);
1058	}
1059
1060	TAILQ_INIT(&list->allio);
1061	seg = (struct scsi_ec_segment_register_key *)list->seg[list->curseg];
1062	dl = tpc_resolve(list, scsi_2btoul(seg->dst_cscd), NULL, NULL, NULL);
1063	if (dl >= CTL_MAX_LUNS) {
1064		ctl_set_sense(list->ctsio, /*current_error*/ 1,
1065		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1066		    /*asc*/ 0x08, /*ascq*/ 0x04,
1067		    SSD_ELEM_COMMAND, sizeof(csi), csi,
1068		    SSD_ELEM_NONE);
1069		return (CTL_RETVAL_ERROR);
1070	}
1071
1072//	printf("Register Key %ju\n", dl);
1073
1074	list->tbdio = 1;
1075	tio = malloc(sizeof(*tio), M_CTL, M_WAITOK | M_ZERO);
1076	TAILQ_INIT(&tio->run);
1077	tio->list = list;
1078	TAILQ_INSERT_TAIL(&list->allio, tio, links);
1079	tio->io = tpcl_alloc_io();
1080	datalen = sizeof(struct scsi_per_res_out_parms);
1081	list->buf = malloc(datalen, M_CTL, M_WAITOK);
1082	ctl_scsi_persistent_res_out(tio->io,
1083	    list->buf, datalen, SPRO_REGISTER, -1,
1084	    scsi_8btou64(seg->res_key), scsi_8btou64(seg->sa_res_key),
1085	    /*tag_type*/ CTL_TAG_SIMPLE, /*control*/ 0);
1086	tio->io->io_hdr.retries = 3;
1087	tio->lun = dl;
1088	tio->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tio;
1089	list->stage++;
1090	if (tpcl_queue(tio->io, tio->lun) != CTL_RETVAL_COMPLETE)
1091		panic("tpcl_queue() error");
1092	return (CTL_RETVAL_QUEUED);
1093}
1094
1095static off_t
1096tpc_ranges_length(struct scsi_range_desc *range, int nrange)
1097{
1098	off_t length = 0;
1099	int r;
1100
1101	for (r = 0; r < nrange; r++)
1102		length += scsi_4btoul(range[r].length);
1103	return (length);
1104}
1105
1106static int
1107tpc_check_ranges_l(struct scsi_range_desc *range, int nrange, uint64_t maxlba,
1108    uint64_t *lba)
1109{
1110	uint64_t b1;
1111	uint32_t l1;
1112	int i;
1113
1114	for (i = 0; i < nrange; i++) {
1115		b1 = scsi_8btou64(range[i].lba);
1116		l1 = scsi_4btoul(range[i].length);
1117		if (b1 + l1 < b1 || b1 + l1 > maxlba + 1) {
1118			*lba = MAX(b1, maxlba + 1);
1119			return (-1);
1120		}
1121	}
1122	return (0);
1123}
1124
1125static int
1126tpc_check_ranges_x(struct scsi_range_desc *range, int nrange)
1127{
1128	uint64_t b1, b2;
1129	uint32_t l1, l2;
1130	int i, j;
1131
1132	for (i = 0; i < nrange - 1; i++) {
1133		b1 = scsi_8btou64(range[i].lba);
1134		l1 = scsi_4btoul(range[i].length);
1135		for (j = i + 1; j < nrange; j++) {
1136			b2 = scsi_8btou64(range[j].lba);
1137			l2 = scsi_4btoul(range[j].length);
1138			if (b1 + l1 > b2 && b2 + l2 > b1)
1139				return (-1);
1140		}
1141	}
1142	return (0);
1143}
1144
1145static int
1146tpc_skip_ranges(struct scsi_range_desc *range, int nrange, off_t skip,
1147    int *srange, off_t *soffset)
1148{
1149	off_t off;
1150	int r;
1151
1152	r = 0;
1153	off = 0;
1154	while (r < nrange) {
1155		if (skip - off < scsi_4btoul(range[r].length)) {
1156			*srange = r;
1157			*soffset = skip - off;
1158			return (0);
1159		}
1160		off += scsi_4btoul(range[r].length);
1161		r++;
1162	}
1163	return (-1);
1164}
1165
1166static int
1167tpc_process_wut(struct tpc_list *list)
1168{
1169	struct tpc_io *tio, *tior, *tiow;
1170	struct runl run;
1171	int drange, srange;
1172	off_t doffset, soffset;
1173	off_t srclba, dstlba, numbytes, donebytes, roundbytes;
1174	uint32_t srcblock, dstblock, pb, pbo, adj;
1175
1176	if (list->stage > 0) {
1177		/* Cleanup after previous rounds. */
1178		while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
1179			TAILQ_REMOVE(&list->allio, tio, links);
1180			ctl_free_io(tio->io);
1181			free(tio, M_CTL);
1182		}
1183		free(list->buf, M_CTL);
1184		if (list->abort) {
1185			ctl_set_task_aborted(list->ctsio);
1186			return (CTL_RETVAL_ERROR);
1187		} else if (list->error) {
1188			ctl_set_sense(list->ctsio, /*current_error*/ 1,
1189			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1190			    /*asc*/ 0x0d, /*ascq*/ 0x01, SSD_ELEM_NONE);
1191			return (CTL_RETVAL_ERROR);
1192		}
1193		list->cursectors += list->segsectors;
1194		list->curbytes += list->segbytes;
1195	}
1196
1197	/* Check where we are on destination ranges list. */
1198	if (tpc_skip_ranges(list->range, list->nrange, list->cursectors,
1199	    &drange, &doffset) != 0)
1200		return (CTL_RETVAL_COMPLETE);
1201	dstblock = list->lun->be_lun->blocksize;
1202	pb = dstblock << list->lun->be_lun->pblockexp;
1203	if (list->lun->be_lun->pblockoff > 0)
1204		pbo = pb - dstblock * list->lun->be_lun->pblockoff;
1205	else
1206		pbo = 0;
1207
1208	/* Check where we are on source ranges list. */
1209	srcblock = list->token->blocksize;
1210	if (tpc_skip_ranges(list->token->range, list->token->nrange,
1211	    list->offset_into_rod + list->cursectors * dstblock / srcblock,
1212	    &srange, &soffset) != 0) {
1213		ctl_set_sense(list->ctsio, /*current_error*/ 1,
1214		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1215		    /*asc*/ 0x0d, /*ascq*/ 0x04, SSD_ELEM_NONE);
1216		return (CTL_RETVAL_ERROR);
1217	}
1218
1219	srclba = scsi_8btou64(list->token->range[srange].lba) + soffset;
1220	dstlba = scsi_8btou64(list->range[drange].lba) + doffset;
1221	numbytes = srcblock *
1222	    (scsi_4btoul(list->token->range[srange].length) - soffset);
1223	numbytes = omin(numbytes, dstblock *
1224	    (scsi_4btoul(list->range[drange].length) - doffset));
1225	if (numbytes > TPC_MAX_IOCHUNK_SIZE) {
1226		numbytes = TPC_MAX_IOCHUNK_SIZE;
1227		numbytes -= numbytes % dstblock;
1228		if (pb > dstblock) {
1229			adj = (dstlba * dstblock + numbytes - pbo) % pb;
1230			if (numbytes > adj)
1231				numbytes -= adj;
1232		}
1233	}
1234
1235	if (numbytes % srcblock != 0 || numbytes % dstblock != 0) {
1236		ctl_set_sense(list->ctsio, /*current_error*/ 1,
1237		    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1238		    /*asc*/ 0x26, /*ascq*/ 0x0A, SSD_ELEM_NONE);
1239		return (CTL_RETVAL_ERROR);
1240	}
1241
1242	list->buf = malloc(numbytes, M_CTL, M_WAITOK |
1243	    (list->token == NULL ? M_ZERO : 0));
1244	list->segbytes = numbytes;
1245	list->segsectors = numbytes / dstblock;
1246//printf("Copy chunk of %ju sectors from %ju to %ju\n", list->segsectors,
1247//    srclba, dstlba);
1248	donebytes = 0;
1249	TAILQ_INIT(&run);
1250	list->tbdio = 0;
1251	TAILQ_INIT(&list->allio);
1252	while (donebytes < numbytes) {
1253		roundbytes = numbytes - donebytes;
1254		if (roundbytes > TPC_MAX_IO_SIZE) {
1255			roundbytes = TPC_MAX_IO_SIZE;
1256			roundbytes -= roundbytes % dstblock;
1257			if (pb > dstblock) {
1258				adj = (dstlba * dstblock + roundbytes - pbo) % pb;
1259				if (roundbytes > adj)
1260					roundbytes -= adj;
1261			}
1262		}
1263
1264		tior = malloc(sizeof(*tior), M_CTL, M_WAITOK | M_ZERO);
1265		TAILQ_INIT(&tior->run);
1266		tior->list = list;
1267		TAILQ_INSERT_TAIL(&list->allio, tior, links);
1268		tior->io = tpcl_alloc_io();
1269		ctl_scsi_read_write(tior->io,
1270				    /*data_ptr*/ &list->buf[donebytes],
1271				    /*data_len*/ roundbytes,
1272				    /*read_op*/ 1,
1273				    /*byte2*/ 0,
1274				    /*minimum_cdb_size*/ 0,
1275				    /*lba*/ srclba,
1276				    /*num_blocks*/ roundbytes / srcblock,
1277				    /*tag_type*/ CTL_TAG_SIMPLE,
1278				    /*control*/ 0);
1279		tior->io->io_hdr.retries = 3;
1280		tior->lun = list->token->lun;
1281		tior->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tior;
1282
1283		tiow = malloc(sizeof(*tiow), M_CTL, M_WAITOK | M_ZERO);
1284		TAILQ_INIT(&tiow->run);
1285		tiow->list = list;
1286		TAILQ_INSERT_TAIL(&list->allio, tiow, links);
1287		tiow->io = tpcl_alloc_io();
1288		ctl_scsi_read_write(tiow->io,
1289				    /*data_ptr*/ &list->buf[donebytes],
1290				    /*data_len*/ roundbytes,
1291				    /*read_op*/ 0,
1292				    /*byte2*/ 0,
1293				    /*minimum_cdb_size*/ 0,
1294				    /*lba*/ dstlba,
1295				    /*num_blocks*/ roundbytes / dstblock,
1296				    /*tag_type*/ CTL_TAG_SIMPLE,
1297				    /*control*/ 0);
1298		tiow->io->io_hdr.retries = 3;
1299		tiow->lun = list->lun->lun;
1300		tiow->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tiow;
1301
1302		TAILQ_INSERT_TAIL(&tior->run, tiow, rlinks);
1303		TAILQ_INSERT_TAIL(&run, tior, rlinks);
1304		list->tbdio++;
1305		donebytes += roundbytes;
1306		srclba += roundbytes / srcblock;
1307		dstlba += roundbytes / dstblock;
1308	}
1309
1310	while ((tior = TAILQ_FIRST(&run)) != NULL) {
1311		TAILQ_REMOVE(&run, tior, rlinks);
1312		if (tpcl_queue(tior->io, tior->lun) != CTL_RETVAL_COMPLETE)
1313			panic("tpcl_queue() error");
1314	}
1315
1316	list->stage++;
1317	return (CTL_RETVAL_QUEUED);
1318}
1319
1320static int
1321tpc_process_zero_wut(struct tpc_list *list)
1322{
1323	struct tpc_io *tio, *tiow;
1324	struct runl run, *prun;
1325	int r;
1326	uint32_t dstblock, len;
1327
1328	if (list->stage > 0) {
1329complete:
1330		/* Cleanup after previous rounds. */
1331		while ((tio = TAILQ_FIRST(&list->allio)) != NULL) {
1332			TAILQ_REMOVE(&list->allio, tio, links);
1333			ctl_free_io(tio->io);
1334			free(tio, M_CTL);
1335		}
1336		if (list->abort) {
1337			ctl_set_task_aborted(list->ctsio);
1338			return (CTL_RETVAL_ERROR);
1339		} else if (list->error) {
1340			ctl_set_sense(list->ctsio, /*current_error*/ 1,
1341			    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1342			    /*asc*/ 0x0d, /*ascq*/ 0x01, SSD_ELEM_NONE);
1343			return (CTL_RETVAL_ERROR);
1344		}
1345		list->cursectors += list->segsectors;
1346		list->curbytes += list->segbytes;
1347		return (CTL_RETVAL_COMPLETE);
1348	}
1349
1350	dstblock = list->lun->be_lun->blocksize;
1351	TAILQ_INIT(&run);
1352	prun = &run;
1353	list->tbdio = 1;
1354	TAILQ_INIT(&list->allio);
1355	list->segsectors = 0;
1356	for (r = 0; r < list->nrange; r++) {
1357		len = scsi_4btoul(list->range[r].length);
1358		if (len == 0)
1359			continue;
1360
1361		tiow = malloc(sizeof(*tiow), M_CTL, M_WAITOK | M_ZERO);
1362		TAILQ_INIT(&tiow->run);
1363		tiow->list = list;
1364		TAILQ_INSERT_TAIL(&list->allio, tiow, links);
1365		tiow->io = tpcl_alloc_io();
1366		ctl_scsi_write_same(tiow->io,
1367				    /*data_ptr*/ NULL,
1368				    /*data_len*/ 0,
1369				    /*byte2*/ SWS_NDOB,
1370				    /*lba*/ scsi_8btou64(list->range[r].lba),
1371				    /*num_blocks*/ len,
1372				    /*tag_type*/ CTL_TAG_SIMPLE,
1373				    /*control*/ 0);
1374		tiow->io->io_hdr.retries = 3;
1375		tiow->lun = list->lun->lun;
1376		tiow->io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr = tiow;
1377
1378		TAILQ_INSERT_TAIL(prun, tiow, rlinks);
1379		prun = &tiow->run;
1380		list->segsectors += len;
1381	}
1382	list->segbytes = list->segsectors * dstblock;
1383
1384	if (TAILQ_EMPTY(&run))
1385		goto complete;
1386
1387	while ((tiow = TAILQ_FIRST(&run)) != NULL) {
1388		TAILQ_REMOVE(&run, tiow, rlinks);
1389		if (tpcl_queue(tiow->io, tiow->lun) != CTL_RETVAL_COMPLETE)
1390			panic("tpcl_queue() error");
1391	}
1392
1393	list->stage++;
1394	return (CTL_RETVAL_QUEUED);
1395}
1396
1397static void
1398tpc_process(struct tpc_list *list)
1399{
1400	struct ctl_lun *lun = list->lun;
1401	struct ctl_softc *softc = lun->ctl_softc;
1402	struct scsi_ec_segment *seg;
1403	struct ctl_scsiio *ctsio = list->ctsio;
1404	int retval = CTL_RETVAL_COMPLETE;
1405	uint8_t csi[4];
1406
1407	if (list->service_action == EC_WUT) {
1408		if (list->token != NULL)
1409			retval = tpc_process_wut(list);
1410		else
1411			retval = tpc_process_zero_wut(list);
1412		if (retval == CTL_RETVAL_QUEUED)
1413			return;
1414		if (retval == CTL_RETVAL_ERROR) {
1415			list->error = 1;
1416			goto done;
1417		}
1418	} else {
1419//printf("ZZZ %d cscd, %d segs\n", list->ncscd, list->nseg);
1420		while (list->curseg < list->nseg) {
1421			seg = list->seg[list->curseg];
1422			switch (seg->type_code) {
1423			case EC_SEG_B2B:
1424				retval = tpc_process_b2b(list);
1425				break;
1426			case EC_SEG_VERIFY:
1427				retval = tpc_process_verify(list);
1428				break;
1429			case EC_SEG_REGISTER_KEY:
1430				retval = tpc_process_register_key(list);
1431				break;
1432			default:
1433				scsi_ulto4b(list->curseg, csi);
1434				ctl_set_sense(ctsio, /*current_error*/ 1,
1435				    /*sense_key*/ SSD_KEY_COPY_ABORTED,
1436				    /*asc*/ 0x26, /*ascq*/ 0x09,
1437				    SSD_ELEM_COMMAND, sizeof(csi), csi,
1438				    SSD_ELEM_NONE);
1439				goto done;
1440			}
1441			if (retval == CTL_RETVAL_QUEUED)
1442				return;
1443			if (retval == CTL_RETVAL_ERROR) {
1444				list->error = 1;
1445				goto done;
1446			}
1447			list->curseg++;
1448			list->stage = 0;
1449		}
1450	}
1451
1452	ctl_set_success(ctsio);
1453
1454done:
1455//printf("ZZZ done\n");
1456	free(list->params, M_CTL);
1457	list->params = NULL;
1458	if (list->token) {
1459		mtx_lock(&softc->tpc_lock);
1460		if (--list->token->active == 0)
1461			list->token->last_active = time_uptime;
1462		mtx_unlock(&softc->tpc_lock);
1463		list->token = NULL;
1464	}
1465	mtx_lock(&lun->lun_lock);
1466	if ((list->flags & EC_LIST_ID_USAGE_MASK) == EC_LIST_ID_USAGE_NONE) {
1467		TAILQ_REMOVE(&lun->tpc_lists, list, links);
1468		free(list, M_CTL);
1469	} else {
1470		list->completed = 1;
1471		list->last_active = time_uptime;
1472		list->sense_data = ctsio->sense_data;
1473		list->sense_len = ctsio->sense_len;
1474		list->scsi_status = ctsio->scsi_status;
1475	}
1476	mtx_unlock(&lun->lun_lock);
1477
1478	ctl_done((union ctl_io *)ctsio);
1479}
1480
1481/*
1482 * For any sort of check condition, busy, etc., we just retry.  We do not
1483 * decrement the retry count for unit attention type errors.  These are
1484 * normal, and we want to save the retry count for "real" errors.  Otherwise,
1485 * we could end up with situations where a command will succeed in some
1486 * situations and fail in others, depending on whether a unit attention is
1487 * pending.  Also, some of our error recovery actions, most notably the
1488 * LUN reset action, will cause a unit attention.
1489 *
1490 * We can add more detail here later if necessary.
1491 */
1492static tpc_error_action
1493tpc_checkcond_parse(union ctl_io *io)
1494{
1495	tpc_error_action error_action;
1496	int error_code, sense_key, asc, ascq;
1497
1498	/*
1499	 * Default to retrying the command.
1500	 */
1501	error_action = TPC_ERR_RETRY;
1502
1503	scsi_extract_sense_len(&io->scsiio.sense_data,
1504			       io->scsiio.sense_len,
1505			       &error_code,
1506			       &sense_key,
1507			       &asc,
1508			       &ascq,
1509			       /*show_errors*/ 1);
1510
1511	switch (error_code) {
1512	case SSD_DEFERRED_ERROR:
1513	case SSD_DESC_DEFERRED_ERROR:
1514		error_action |= TPC_ERR_NO_DECREMENT;
1515		break;
1516	case SSD_CURRENT_ERROR:
1517	case SSD_DESC_CURRENT_ERROR:
1518	default:
1519		switch (sense_key) {
1520		case SSD_KEY_UNIT_ATTENTION:
1521			error_action |= TPC_ERR_NO_DECREMENT;
1522			break;
1523		case SSD_KEY_HARDWARE_ERROR:
1524			/*
1525			 * This is our generic "something bad happened"
1526			 * error code.  It often isn't recoverable.
1527			 */
1528			if ((asc == 0x44) && (ascq == 0x00))
1529				error_action = TPC_ERR_FAIL;
1530			break;
1531		case SSD_KEY_NOT_READY:
1532			/*
1533			 * If the LUN is powered down, there likely isn't
1534			 * much point in retrying right now.
1535			 */
1536			if ((asc == 0x04) && (ascq == 0x02))
1537				error_action = TPC_ERR_FAIL;
1538			/*
1539			 * If the LUN is offline, there probably isn't much
1540			 * point in retrying, either.
1541			 */
1542			if ((asc == 0x04) && (ascq == 0x03))
1543				error_action = TPC_ERR_FAIL;
1544			break;
1545		}
1546	}
1547	return (error_action);
1548}
1549
1550static tpc_error_action
1551tpc_error_parse(union ctl_io *io)
1552{
1553	tpc_error_action error_action = TPC_ERR_RETRY;
1554
1555	switch (io->io_hdr.io_type) {
1556	case CTL_IO_SCSI:
1557		switch (io->io_hdr.status & CTL_STATUS_MASK) {
1558		case CTL_SCSI_ERROR:
1559			switch (io->scsiio.scsi_status) {
1560			case SCSI_STATUS_CHECK_COND:
1561				error_action = tpc_checkcond_parse(io);
1562				break;
1563			default:
1564				break;
1565			}
1566			break;
1567		default:
1568			break;
1569		}
1570		break;
1571	case CTL_IO_TASK:
1572		break;
1573	default:
1574		panic("%s: invalid ctl_io type %d\n", __func__,
1575		      io->io_hdr.io_type);
1576		break;
1577	}
1578	return (error_action);
1579}
1580
1581void
1582tpc_done(union ctl_io *io)
1583{
1584	struct tpc_io *tio, *tior;
1585
1586	/*
1587	 * Very minimal retry logic.  We basically retry if we got an error
1588	 * back, and the retry count is greater than 0.  If we ever want
1589	 * more sophisticated initiator type behavior, the CAM error
1590	 * recovery code in ../common might be helpful.
1591	 */
1592	tio = io->io_hdr.ctl_private[CTL_PRIV_FRONTEND].ptr;
1593	if (((io->io_hdr.status & CTL_STATUS_MASK) != CTL_SUCCESS)
1594	 && (io->io_hdr.retries > 0)) {
1595		ctl_io_status old_status;
1596		tpc_error_action error_action;
1597
1598		error_action = tpc_error_parse(io);
1599		switch (error_action & TPC_ERR_MASK) {
1600		case TPC_ERR_FAIL:
1601			break;
1602		case TPC_ERR_RETRY:
1603		default:
1604			if ((error_action & TPC_ERR_NO_DECREMENT) == 0)
1605				io->io_hdr.retries--;
1606			old_status = io->io_hdr.status;
1607			io->io_hdr.status = CTL_STATUS_NONE;
1608			io->io_hdr.flags &= ~CTL_FLAG_ABORT;
1609			io->io_hdr.flags &= ~CTL_FLAG_SENT_2OTHER_SC;
1610			if (tpcl_queue(io, tio->lun) != CTL_RETVAL_COMPLETE) {
1611				printf("%s: error returned from ctl_queue()!\n",
1612				       __func__);
1613				io->io_hdr.status = old_status;
1614			} else
1615				return;
1616		}
1617	}
1618
1619	if ((io->io_hdr.status & CTL_STATUS_MASK) != CTL_SUCCESS)
1620		tio->list->error = 1;
1621	else
1622		atomic_add_int(&tio->list->curops, 1);
1623	if (!tio->list->error && !tio->list->abort) {
1624		while ((tior = TAILQ_FIRST(&tio->run)) != NULL) {
1625			TAILQ_REMOVE(&tio->run, tior, rlinks);
1626			atomic_add_int(&tio->list->tbdio, 1);
1627			if (tpcl_queue(tior->io, tior->lun) != CTL_RETVAL_COMPLETE)
1628				panic("tpcl_queue() error");
1629		}
1630	}
1631	if (atomic_fetchadd_int(&tio->list->tbdio, -1) == 1)
1632		tpc_process(tio->list);
1633}
1634
1635int
1636ctl_extended_copy_lid1(struct ctl_scsiio *ctsio)
1637{
1638	struct scsi_extended_copy *cdb;
1639	struct scsi_extended_copy_lid1_data *data;
1640	struct ctl_lun *lun;
1641	struct tpc_list *list, *tlist;
1642	uint8_t *ptr;
1643	char *value;
1644	int len, off, lencscd, lenseg, leninl, nseg;
1645
1646	CTL_DEBUG_PRINT(("ctl_extended_copy_lid1\n"));
1647
1648	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
1649	cdb = (struct scsi_extended_copy *)ctsio->cdb;
1650	len = scsi_4btoul(cdb->length);
1651
1652	if (len == 0) {
1653		ctl_set_success(ctsio);
1654		goto done;
1655	}
1656	if (len < sizeof(struct scsi_extended_copy_lid1_data) ||
1657	    len > sizeof(struct scsi_extended_copy_lid1_data) +
1658	    TPC_MAX_LIST + TPC_MAX_INLINE) {
1659		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
1660		    /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
1661		goto done;
1662	}
1663
1664	/*
1665	 * If we've got a kernel request that hasn't been malloced yet,
1666	 * malloc it and tell the caller the data buffer is here.
1667	 */
1668	if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
1669		ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
1670		ctsio->kern_data_len = len;
1671		ctsio->kern_total_len = len;
1672		ctsio->kern_data_resid = 0;
1673		ctsio->kern_rel_offset = 0;
1674		ctsio->kern_sg_entries = 0;
1675		ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
1676		ctsio->be_move_done = ctl_config_move_done;
1677		ctl_datamove((union ctl_io *)ctsio);
1678
1679		return (CTL_RETVAL_COMPLETE);
1680	}
1681
1682	data = (struct scsi_extended_copy_lid1_data *)ctsio->kern_data_ptr;
1683	lencscd = scsi_2btoul(data->cscd_list_length);
1684	lenseg = scsi_4btoul(data->segment_list_length);
1685	leninl = scsi_4btoul(data->inline_data_length);
1686	if (lencscd > TPC_MAX_CSCDS * sizeof(struct scsi_ec_cscd)) {
1687		ctl_set_sense(ctsio, /*current_error*/ 1,
1688		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1689		    /*asc*/ 0x26, /*ascq*/ 0x06, SSD_ELEM_NONE);
1690		goto done;
1691	}
1692	if (lenseg > TPC_MAX_SEGS * sizeof(struct scsi_ec_segment)) {
1693		ctl_set_sense(ctsio, /*current_error*/ 1,
1694		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1695		    /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1696		goto done;
1697	}
1698	if (lencscd + lenseg > TPC_MAX_LIST ||
1699	    leninl > TPC_MAX_INLINE ||
1700	    len < sizeof(struct scsi_extended_copy_lid1_data) +
1701	     lencscd + lenseg + leninl) {
1702		ctl_set_param_len_error(ctsio);
1703		goto done;
1704	}
1705
1706	list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
1707	list->service_action = cdb->service_action;
1708	value = ctl_get_opt(&lun->be_lun->options, "insecure_tpc");
1709	if (value != NULL && strcmp(value, "on") == 0)
1710		list->init_port = -1;
1711	else
1712		list->init_port = ctsio->io_hdr.nexus.targ_port;
1713	list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
1714	list->list_id = data->list_identifier;
1715	list->flags = data->flags;
1716	list->params = ctsio->kern_data_ptr;
1717	list->cscd = (struct scsi_ec_cscd *)&data->data[0];
1718	ptr = &data->data[lencscd];
1719	for (nseg = 0, off = 0; off < lenseg; nseg++) {
1720		if (nseg >= TPC_MAX_SEGS) {
1721			free(list, M_CTL);
1722			ctl_set_sense(ctsio, /*current_error*/ 1,
1723			    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1724			    /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1725			goto done;
1726		}
1727		list->seg[nseg] = (struct scsi_ec_segment *)(ptr + off);
1728		off += sizeof(struct scsi_ec_segment) +
1729		    scsi_2btoul(list->seg[nseg]->descr_length);
1730	}
1731	list->inl = &data->data[lencscd + lenseg];
1732	list->ncscd = lencscd / sizeof(struct scsi_ec_cscd);
1733	list->nseg = nseg;
1734	list->leninl = leninl;
1735	list->ctsio = ctsio;
1736	list->lun = lun;
1737	mtx_lock(&lun->lun_lock);
1738	if ((list->flags & EC_LIST_ID_USAGE_MASK) != EC_LIST_ID_USAGE_NONE) {
1739		tlist = tpc_find_list(lun, list->list_id, list->init_idx);
1740		if (tlist != NULL && !tlist->completed) {
1741			mtx_unlock(&lun->lun_lock);
1742			free(list, M_CTL);
1743			ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
1744			    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
1745			    /*bit*/ 0);
1746			goto done;
1747		}
1748		if (tlist != NULL) {
1749			TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
1750			free(tlist, M_CTL);
1751		}
1752	}
1753	TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
1754	mtx_unlock(&lun->lun_lock);
1755
1756	tpc_process(list);
1757	return (CTL_RETVAL_COMPLETE);
1758
1759done:
1760	if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
1761		free(ctsio->kern_data_ptr, M_CTL);
1762		ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
1763	}
1764	ctl_done((union ctl_io *)ctsio);
1765	return (CTL_RETVAL_COMPLETE);
1766}
1767
1768int
1769ctl_extended_copy_lid4(struct ctl_scsiio *ctsio)
1770{
1771	struct scsi_extended_copy *cdb;
1772	struct scsi_extended_copy_lid4_data *data;
1773	struct ctl_lun *lun;
1774	struct tpc_list *list, *tlist;
1775	uint8_t *ptr;
1776	char *value;
1777	int len, off, lencscd, lenseg, leninl, nseg;
1778
1779	CTL_DEBUG_PRINT(("ctl_extended_copy_lid4\n"));
1780
1781	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
1782	cdb = (struct scsi_extended_copy *)ctsio->cdb;
1783	len = scsi_4btoul(cdb->length);
1784
1785	if (len == 0) {
1786		ctl_set_success(ctsio);
1787		goto done;
1788	}
1789	if (len < sizeof(struct scsi_extended_copy_lid4_data) ||
1790	    len > sizeof(struct scsi_extended_copy_lid4_data) +
1791	    TPC_MAX_LIST + TPC_MAX_INLINE) {
1792		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
1793		    /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
1794		goto done;
1795	}
1796
1797	/*
1798	 * If we've got a kernel request that hasn't been malloced yet,
1799	 * malloc it and tell the caller the data buffer is here.
1800	 */
1801	if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
1802		ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
1803		ctsio->kern_data_len = len;
1804		ctsio->kern_total_len = len;
1805		ctsio->kern_data_resid = 0;
1806		ctsio->kern_rel_offset = 0;
1807		ctsio->kern_sg_entries = 0;
1808		ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
1809		ctsio->be_move_done = ctl_config_move_done;
1810		ctl_datamove((union ctl_io *)ctsio);
1811
1812		return (CTL_RETVAL_COMPLETE);
1813	}
1814
1815	data = (struct scsi_extended_copy_lid4_data *)ctsio->kern_data_ptr;
1816	lencscd = scsi_2btoul(data->cscd_list_length);
1817	lenseg = scsi_2btoul(data->segment_list_length);
1818	leninl = scsi_2btoul(data->inline_data_length);
1819	if (lencscd > TPC_MAX_CSCDS * sizeof(struct scsi_ec_cscd)) {
1820		ctl_set_sense(ctsio, /*current_error*/ 1,
1821		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1822		    /*asc*/ 0x26, /*ascq*/ 0x06, SSD_ELEM_NONE);
1823		goto done;
1824	}
1825	if (lenseg > TPC_MAX_SEGS * sizeof(struct scsi_ec_segment)) {
1826		ctl_set_sense(ctsio, /*current_error*/ 1,
1827		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1828		    /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1829		goto done;
1830	}
1831	if (lencscd + lenseg > TPC_MAX_LIST ||
1832	    leninl > TPC_MAX_INLINE ||
1833	    len < sizeof(struct scsi_extended_copy_lid1_data) +
1834	     lencscd + lenseg + leninl) {
1835		ctl_set_param_len_error(ctsio);
1836		goto done;
1837	}
1838
1839	list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
1840	list->service_action = cdb->service_action;
1841	value = ctl_get_opt(&lun->be_lun->options, "insecure_tpc");
1842	if (value != NULL && strcmp(value, "on") == 0)
1843		list->init_port = -1;
1844	else
1845		list->init_port = ctsio->io_hdr.nexus.targ_port;
1846	list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
1847	list->list_id = scsi_4btoul(data->list_identifier);
1848	list->flags = data->flags;
1849	list->params = ctsio->kern_data_ptr;
1850	list->cscd = (struct scsi_ec_cscd *)&data->data[0];
1851	ptr = &data->data[lencscd];
1852	for (nseg = 0, off = 0; off < lenseg; nseg++) {
1853		if (nseg >= TPC_MAX_SEGS) {
1854			free(list, M_CTL);
1855			ctl_set_sense(ctsio, /*current_error*/ 1,
1856			    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
1857			    /*asc*/ 0x26, /*ascq*/ 0x08, SSD_ELEM_NONE);
1858			goto done;
1859		}
1860		list->seg[nseg] = (struct scsi_ec_segment *)(ptr + off);
1861		off += sizeof(struct scsi_ec_segment) +
1862		    scsi_2btoul(list->seg[nseg]->descr_length);
1863	}
1864	list->inl = &data->data[lencscd + lenseg];
1865	list->ncscd = lencscd / sizeof(struct scsi_ec_cscd);
1866	list->nseg = nseg;
1867	list->leninl = leninl;
1868	list->ctsio = ctsio;
1869	list->lun = lun;
1870	mtx_lock(&lun->lun_lock);
1871	if ((list->flags & EC_LIST_ID_USAGE_MASK) != EC_LIST_ID_USAGE_NONE) {
1872		tlist = tpc_find_list(lun, list->list_id, list->init_idx);
1873		if (tlist != NULL && !tlist->completed) {
1874			mtx_unlock(&lun->lun_lock);
1875			free(list, M_CTL);
1876			ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
1877			    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
1878			    /*bit*/ 0);
1879			goto done;
1880		}
1881		if (tlist != NULL) {
1882			TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
1883			free(tlist, M_CTL);
1884		}
1885	}
1886	TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
1887	mtx_unlock(&lun->lun_lock);
1888
1889	tpc_process(list);
1890	return (CTL_RETVAL_COMPLETE);
1891
1892done:
1893	if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
1894		free(ctsio->kern_data_ptr, M_CTL);
1895		ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
1896	}
1897	ctl_done((union ctl_io *)ctsio);
1898	return (CTL_RETVAL_COMPLETE);
1899}
1900
1901static void
1902tpc_create_token(struct ctl_lun *lun, struct ctl_port *port, off_t len,
1903    struct scsi_token *token)
1904{
1905	static int id = 0;
1906	struct scsi_vpd_id_descriptor *idd = NULL;
1907	struct scsi_ec_cscd_id *cscd;
1908	struct scsi_read_capacity_data_long *dtsd;
1909	int targid_len;
1910
1911	scsi_ulto4b(ROD_TYPE_AUR, token->type);
1912	scsi_ulto2b(0x01f8, token->length);
1913	scsi_u64to8b(atomic_fetchadd_int(&id, 1), &token->body[0]);
1914	if (lun->lun_devid)
1915		idd = scsi_get_devid_desc((struct scsi_vpd_id_descriptor *)
1916		    lun->lun_devid->data, lun->lun_devid->len,
1917		    scsi_devid_is_lun_naa);
1918	if (idd == NULL && lun->lun_devid)
1919		idd = scsi_get_devid_desc((struct scsi_vpd_id_descriptor *)
1920		    lun->lun_devid->data, lun->lun_devid->len,
1921		    scsi_devid_is_lun_eui64);
1922	if (idd != NULL) {
1923		cscd = (struct scsi_ec_cscd_id *)&token->body[8];
1924		cscd->type_code = EC_CSCD_ID;
1925		cscd->luidt_pdt = T_DIRECT;
1926		memcpy(&cscd->codeset, idd, 4 + idd->length);
1927		scsi_ulto3b(lun->be_lun->blocksize, cscd->dtsp.block_length);
1928	}
1929	scsi_u64to8b(0, &token->body[40]); /* XXX: Should be 128bit value. */
1930	scsi_u64to8b(len, &token->body[48]);
1931
1932	/* ROD token device type specific data (RC16 without first field) */
1933	dtsd = (struct scsi_read_capacity_data_long *)&token->body[88 - 8];
1934	scsi_ulto4b(lun->be_lun->blocksize, dtsd->length);
1935	dtsd->prot_lbppbe = lun->be_lun->pblockexp & SRC16_LBPPBE;
1936	scsi_ulto2b(lun->be_lun->pblockoff & SRC16_LALBA_A, dtsd->lalba_lbp);
1937	if (lun->be_lun->flags & CTL_LUN_FLAG_UNMAP)
1938		dtsd->lalba_lbp[0] |= SRC16_LBPME | SRC16_LBPRZ;
1939
1940	if (port->target_devid) {
1941		targid_len = port->target_devid->len;
1942		memcpy(&token->body[120], port->target_devid->data, targid_len);
1943	} else
1944		targid_len = 32;
1945	arc4rand(&token->body[120 + targid_len], 384 - targid_len, 0);
1946};
1947
1948int
1949ctl_populate_token(struct ctl_scsiio *ctsio)
1950{
1951	struct scsi_populate_token *cdb;
1952	struct scsi_populate_token_data *data;
1953	struct ctl_softc *softc;
1954	struct ctl_lun *lun;
1955	struct ctl_port *port;
1956	struct tpc_list *list, *tlist;
1957	struct tpc_token *token;
1958	uint64_t lba;
1959	int len, lendata, lendesc;
1960
1961	CTL_DEBUG_PRINT(("ctl_populate_token\n"));
1962
1963	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
1964	softc = lun->ctl_softc;
1965	port = softc->ctl_ports[ctsio->io_hdr.nexus.targ_port];
1966	cdb = (struct scsi_populate_token *)ctsio->cdb;
1967	len = scsi_4btoul(cdb->length);
1968
1969	if (len < sizeof(struct scsi_populate_token_data) ||
1970	    len > sizeof(struct scsi_populate_token_data) +
1971	     TPC_MAX_SEGS * sizeof(struct scsi_range_desc)) {
1972		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
1973		    /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
1974		goto done;
1975	}
1976
1977	/*
1978	 * If we've got a kernel request that hasn't been malloced yet,
1979	 * malloc it and tell the caller the data buffer is here.
1980	 */
1981	if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
1982		ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
1983		ctsio->kern_data_len = len;
1984		ctsio->kern_total_len = len;
1985		ctsio->kern_data_resid = 0;
1986		ctsio->kern_rel_offset = 0;
1987		ctsio->kern_sg_entries = 0;
1988		ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
1989		ctsio->be_move_done = ctl_config_move_done;
1990		ctl_datamove((union ctl_io *)ctsio);
1991
1992		return (CTL_RETVAL_COMPLETE);
1993	}
1994
1995	data = (struct scsi_populate_token_data *)ctsio->kern_data_ptr;
1996	lendata = scsi_2btoul(data->length);
1997	if (lendata < sizeof(struct scsi_populate_token_data) - 2 +
1998	    sizeof(struct scsi_range_desc)) {
1999		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2000		    /*field*/ 0, /*bit_valid*/ 0, /*bit*/ 0);
2001		goto done;
2002	}
2003	lendesc = scsi_2btoul(data->range_descriptor_length);
2004	if (lendesc < sizeof(struct scsi_range_desc) ||
2005	    len < sizeof(struct scsi_populate_token_data) + lendesc ||
2006	    lendata < sizeof(struct scsi_populate_token_data) - 2 + lendesc) {
2007		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2008		    /*field*/ 14, /*bit_valid*/ 0, /*bit*/ 0);
2009		goto done;
2010	}
2011/*
2012	printf("PT(list=%u) flags=%x to=%d rt=%x len=%x\n",
2013	    scsi_4btoul(cdb->list_identifier),
2014	    data->flags, scsi_4btoul(data->inactivity_timeout),
2015	    scsi_4btoul(data->rod_type),
2016	    scsi_2btoul(data->range_descriptor_length));
2017*/
2018
2019	/* Validate INACTIVITY TIMEOUT field */
2020	if (scsi_4btoul(data->inactivity_timeout) > TPC_MAX_TOKEN_TIMEOUT) {
2021		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2022		    /*command*/ 0, /*field*/ 4, /*bit_valid*/ 0,
2023		    /*bit*/ 0);
2024		goto done;
2025	}
2026
2027	/* Validate ROD TYPE field */
2028	if ((data->flags & EC_PT_RTV) &&
2029	    scsi_4btoul(data->rod_type) != ROD_TYPE_AUR) {
2030		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2031		    /*field*/ 8, /*bit_valid*/ 0, /*bit*/ 0);
2032		goto done;
2033	}
2034
2035	/* Validate list of ranges */
2036	if (tpc_check_ranges_l(&data->desc[0],
2037	    scsi_2btoul(data->range_descriptor_length) /
2038	    sizeof(struct scsi_range_desc),
2039	    lun->be_lun->maxlba, &lba) != 0) {
2040		ctl_set_lba_out_of_range(ctsio, lba);
2041		goto done;
2042	}
2043	if (tpc_check_ranges_x(&data->desc[0],
2044	    scsi_2btoul(data->range_descriptor_length) /
2045	    sizeof(struct scsi_range_desc)) != 0) {
2046		ctl_set_invalid_field(ctsio, /*sks_valid*/ 0,
2047		    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2048		    /*bit*/ 0);
2049		goto done;
2050	}
2051
2052	list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
2053	list->service_action = cdb->service_action;
2054	list->init_port = ctsio->io_hdr.nexus.targ_port;
2055	list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
2056	list->list_id = scsi_4btoul(cdb->list_identifier);
2057	list->flags = data->flags;
2058	list->ctsio = ctsio;
2059	list->lun = lun;
2060	mtx_lock(&lun->lun_lock);
2061	tlist = tpc_find_list(lun, list->list_id, list->init_idx);
2062	if (tlist != NULL && !tlist->completed) {
2063		mtx_unlock(&lun->lun_lock);
2064		free(list, M_CTL);
2065		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2066		    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2067		    /*bit*/ 0);
2068		goto done;
2069	}
2070	if (tlist != NULL) {
2071		TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
2072		free(tlist, M_CTL);
2073	}
2074	TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
2075	mtx_unlock(&lun->lun_lock);
2076
2077	token = malloc(sizeof(*token), M_CTL, M_WAITOK | M_ZERO);
2078	token->lun = lun->lun;
2079	token->blocksize = lun->be_lun->blocksize;
2080	token->params = ctsio->kern_data_ptr;
2081	token->range = &data->desc[0];
2082	token->nrange = scsi_2btoul(data->range_descriptor_length) /
2083	    sizeof(struct scsi_range_desc);
2084	list->cursectors = tpc_ranges_length(token->range, token->nrange);
2085	list->curbytes = (off_t)list->cursectors * lun->be_lun->blocksize;
2086	tpc_create_token(lun, port, list->curbytes,
2087	    (struct scsi_token *)token->token);
2088	token->active = 0;
2089	token->last_active = time_uptime;
2090	token->timeout = scsi_4btoul(data->inactivity_timeout);
2091	if (token->timeout == 0)
2092		token->timeout = TPC_DFL_TOKEN_TIMEOUT;
2093	else if (token->timeout < TPC_MIN_TOKEN_TIMEOUT)
2094		token->timeout = TPC_MIN_TOKEN_TIMEOUT;
2095	memcpy(list->res_token, token->token, sizeof(list->res_token));
2096	list->res_token_valid = 1;
2097	list->curseg = 0;
2098	list->completed = 1;
2099	list->last_active = time_uptime;
2100	mtx_lock(&softc->tpc_lock);
2101	TAILQ_INSERT_TAIL(&softc->tpc_tokens, token, links);
2102	mtx_unlock(&softc->tpc_lock);
2103	ctl_set_success(ctsio);
2104	ctl_done((union ctl_io *)ctsio);
2105	return (CTL_RETVAL_COMPLETE);
2106
2107done:
2108	if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
2109		free(ctsio->kern_data_ptr, M_CTL);
2110		ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
2111	}
2112	ctl_done((union ctl_io *)ctsio);
2113	return (CTL_RETVAL_COMPLETE);
2114}
2115
2116int
2117ctl_write_using_token(struct ctl_scsiio *ctsio)
2118{
2119	struct scsi_write_using_token *cdb;
2120	struct scsi_write_using_token_data *data;
2121	struct ctl_softc *softc;
2122	struct ctl_lun *lun;
2123	struct tpc_list *list, *tlist;
2124	struct tpc_token *token;
2125	uint64_t lba;
2126	int len, lendata, lendesc;
2127
2128	CTL_DEBUG_PRINT(("ctl_write_using_token\n"));
2129
2130	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
2131	softc = lun->ctl_softc;
2132	cdb = (struct scsi_write_using_token *)ctsio->cdb;
2133	len = scsi_4btoul(cdb->length);
2134
2135	if (len < sizeof(struct scsi_write_using_token_data) ||
2136	    len > sizeof(struct scsi_write_using_token_data) +
2137	     TPC_MAX_SEGS * sizeof(struct scsi_range_desc)) {
2138		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 1,
2139		    /*field*/ 9, /*bit_valid*/ 0, /*bit*/ 0);
2140		goto done;
2141	}
2142
2143	/*
2144	 * If we've got a kernel request that hasn't been malloced yet,
2145	 * malloc it and tell the caller the data buffer is here.
2146	 */
2147	if ((ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) == 0) {
2148		ctsio->kern_data_ptr = malloc(len, M_CTL, M_WAITOK);
2149		ctsio->kern_data_len = len;
2150		ctsio->kern_total_len = len;
2151		ctsio->kern_data_resid = 0;
2152		ctsio->kern_rel_offset = 0;
2153		ctsio->kern_sg_entries = 0;
2154		ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
2155		ctsio->be_move_done = ctl_config_move_done;
2156		ctl_datamove((union ctl_io *)ctsio);
2157
2158		return (CTL_RETVAL_COMPLETE);
2159	}
2160
2161	data = (struct scsi_write_using_token_data *)ctsio->kern_data_ptr;
2162	lendata = scsi_2btoul(data->length);
2163	if (lendata < sizeof(struct scsi_write_using_token_data) - 2 +
2164	    sizeof(struct scsi_range_desc)) {
2165		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2166		    /*field*/ 0, /*bit_valid*/ 0, /*bit*/ 0);
2167		goto done;
2168	}
2169	lendesc = scsi_2btoul(data->range_descriptor_length);
2170	if (lendesc < sizeof(struct scsi_range_desc) ||
2171	    len < sizeof(struct scsi_write_using_token_data) + lendesc ||
2172	    lendata < sizeof(struct scsi_write_using_token_data) - 2 + lendesc) {
2173		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1, /*command*/ 0,
2174		    /*field*/ 534, /*bit_valid*/ 0, /*bit*/ 0);
2175		goto done;
2176	}
2177/*
2178	printf("WUT(list=%u) flags=%x off=%ju len=%x\n",
2179	    scsi_4btoul(cdb->list_identifier),
2180	    data->flags, scsi_8btou64(data->offset_into_rod),
2181	    scsi_2btoul(data->range_descriptor_length));
2182*/
2183
2184	/* Validate list of ranges */
2185	if (tpc_check_ranges_l(&data->desc[0],
2186	    scsi_2btoul(data->range_descriptor_length) /
2187	    sizeof(struct scsi_range_desc),
2188	    lun->be_lun->maxlba, &lba) != 0) {
2189		ctl_set_lba_out_of_range(ctsio, lba);
2190		goto done;
2191	}
2192	if (tpc_check_ranges_x(&data->desc[0],
2193	    scsi_2btoul(data->range_descriptor_length) /
2194	    sizeof(struct scsi_range_desc)) != 0) {
2195		ctl_set_invalid_field(ctsio, /*sks_valid*/ 0,
2196		    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2197		    /*bit*/ 0);
2198		goto done;
2199	}
2200
2201	list = malloc(sizeof(struct tpc_list), M_CTL, M_WAITOK | M_ZERO);
2202	list->service_action = cdb->service_action;
2203	list->init_port = ctsio->io_hdr.nexus.targ_port;
2204	list->init_idx = ctl_get_initindex(&ctsio->io_hdr.nexus);
2205	list->list_id = scsi_4btoul(cdb->list_identifier);
2206	list->flags = data->flags;
2207	list->params = ctsio->kern_data_ptr;
2208	list->range = &data->desc[0];
2209	list->nrange = scsi_2btoul(data->range_descriptor_length) /
2210	    sizeof(struct scsi_range_desc);
2211	list->offset_into_rod = scsi_8btou64(data->offset_into_rod);
2212	list->ctsio = ctsio;
2213	list->lun = lun;
2214	mtx_lock(&lun->lun_lock);
2215	tlist = tpc_find_list(lun, list->list_id, list->init_idx);
2216	if (tlist != NULL && !tlist->completed) {
2217		mtx_unlock(&lun->lun_lock);
2218		free(list, M_CTL);
2219		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2220		    /*command*/ 0, /*field*/ 0, /*bit_valid*/ 0,
2221		    /*bit*/ 0);
2222		goto done;
2223	}
2224	if (tlist != NULL) {
2225		TAILQ_REMOVE(&lun->tpc_lists, tlist, links);
2226		free(tlist, M_CTL);
2227	}
2228	TAILQ_INSERT_TAIL(&lun->tpc_lists, list, links);
2229	mtx_unlock(&lun->lun_lock);
2230
2231	/* Block device zero ROD token -> no token. */
2232	if (scsi_4btoul(data->rod_token) == ROD_TYPE_BLOCK_ZERO) {
2233		tpc_process(list);
2234		return (CTL_RETVAL_COMPLETE);
2235	}
2236
2237	mtx_lock(&softc->tpc_lock);
2238	TAILQ_FOREACH(token, &softc->tpc_tokens, links) {
2239		if (memcmp(token->token, data->rod_token,
2240		    sizeof(data->rod_token)) == 0)
2241			break;
2242	}
2243	if (token != NULL) {
2244		token->active++;
2245		list->token = token;
2246		if (data->flags & EC_WUT_DEL_TKN)
2247			token->timeout = 0;
2248	}
2249	mtx_unlock(&softc->tpc_lock);
2250	if (token == NULL) {
2251		mtx_lock(&lun->lun_lock);
2252		TAILQ_REMOVE(&lun->tpc_lists, list, links);
2253		mtx_unlock(&lun->lun_lock);
2254		free(list, M_CTL);
2255		ctl_set_sense(ctsio, /*current_error*/ 1,
2256		    /*sense_key*/ SSD_KEY_ILLEGAL_REQUEST,
2257		    /*asc*/ 0x23, /*ascq*/ 0x04, SSD_ELEM_NONE);
2258		goto done;
2259	}
2260
2261	tpc_process(list);
2262	return (CTL_RETVAL_COMPLETE);
2263
2264done:
2265	if (ctsio->io_hdr.flags & CTL_FLAG_ALLOCATED) {
2266		free(ctsio->kern_data_ptr, M_CTL);
2267		ctsio->io_hdr.flags &= ~CTL_FLAG_ALLOCATED;
2268	}
2269	ctl_done((union ctl_io *)ctsio);
2270	return (CTL_RETVAL_COMPLETE);
2271}
2272
2273int
2274ctl_receive_rod_token_information(struct ctl_scsiio *ctsio)
2275{
2276	struct ctl_lun *lun;
2277	struct scsi_receive_rod_token_information *cdb;
2278	struct scsi_receive_copy_status_lid4_data *data;
2279	struct tpc_list *list;
2280	struct tpc_list list_copy;
2281	uint8_t *ptr;
2282	int retval;
2283	int alloc_len, total_len, token_len;
2284	uint32_t list_id;
2285
2286	CTL_DEBUG_PRINT(("ctl_receive_rod_token_information\n"));
2287
2288	cdb = (struct scsi_receive_rod_token_information *)ctsio->cdb;
2289	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
2290
2291	retval = CTL_RETVAL_COMPLETE;
2292
2293	list_id = scsi_4btoul(cdb->list_identifier);
2294	mtx_lock(&lun->lun_lock);
2295	list = tpc_find_list(lun, list_id,
2296	    ctl_get_initindex(&ctsio->io_hdr.nexus));
2297	if (list == NULL) {
2298		mtx_unlock(&lun->lun_lock);
2299		ctl_set_invalid_field(ctsio, /*sks_valid*/ 1,
2300		    /*command*/ 1, /*field*/ 2, /*bit_valid*/ 0,
2301		    /*bit*/ 0);
2302		ctl_done((union ctl_io *)ctsio);
2303		return (retval);
2304	}
2305	list_copy = *list;
2306	if (list->completed) {
2307		TAILQ_REMOVE(&lun->tpc_lists, list, links);
2308		free(list, M_CTL);
2309	}
2310	mtx_unlock(&lun->lun_lock);
2311
2312	token_len = list_copy.res_token_valid ? 2 + sizeof(list_copy.res_token) : 0;
2313	total_len = sizeof(*data) + list_copy.sense_len + 4 + token_len;
2314	alloc_len = scsi_4btoul(cdb->length);
2315
2316	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
2317
2318	ctsio->kern_sg_entries = 0;
2319
2320	if (total_len < alloc_len) {
2321		ctsio->residual = alloc_len - total_len;
2322		ctsio->kern_data_len = total_len;
2323		ctsio->kern_total_len = total_len;
2324	} else {
2325		ctsio->residual = 0;
2326		ctsio->kern_data_len = alloc_len;
2327		ctsio->kern_total_len = alloc_len;
2328	}
2329	ctsio->kern_data_resid = 0;
2330	ctsio->kern_rel_offset = 0;
2331
2332	data = (struct scsi_receive_copy_status_lid4_data *)ctsio->kern_data_ptr;
2333	scsi_ulto4b(sizeof(*data) - 4 + list_copy.sense_len +
2334	    4 + token_len, data->available_data);
2335	data->response_to_service_action = list_copy.service_action;
2336	if (list_copy.completed) {
2337		if (list_copy.error)
2338			data->copy_command_status = RCS_CCS_ERROR;
2339		else if (list_copy.abort)
2340			data->copy_command_status = RCS_CCS_ABORTED;
2341		else
2342			data->copy_command_status = RCS_CCS_COMPLETED;
2343	} else
2344		data->copy_command_status = RCS_CCS_INPROG_FG;
2345	scsi_ulto2b(list_copy.curops, data->operation_counter);
2346	scsi_ulto4b(UINT32_MAX, data->estimated_status_update_delay);
2347	data->transfer_count_units = RCS_TC_LBAS;
2348	scsi_u64to8b(list_copy.cursectors, data->transfer_count);
2349	scsi_ulto2b(list_copy.curseg, data->segments_processed);
2350	data->length_of_the_sense_data_field = list_copy.sense_len;
2351	data->sense_data_length = list_copy.sense_len;
2352	memcpy(data->sense_data, &list_copy.sense_data, list_copy.sense_len);
2353
2354	ptr = &data->sense_data[data->length_of_the_sense_data_field];
2355	scsi_ulto4b(token_len, &ptr[0]);
2356	if (list_copy.res_token_valid) {
2357		scsi_ulto2b(0, &ptr[4]);
2358		memcpy(&ptr[6], list_copy.res_token, sizeof(list_copy.res_token));
2359	}
2360/*
2361	printf("RRTI(list=%u) valid=%d\n",
2362	    scsi_4btoul(cdb->list_identifier), list_copy.res_token_valid);
2363*/
2364	ctl_set_success(ctsio);
2365	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
2366	ctsio->be_move_done = ctl_config_move_done;
2367	ctl_datamove((union ctl_io *)ctsio);
2368	return (retval);
2369}
2370
2371int
2372ctl_report_all_rod_tokens(struct ctl_scsiio *ctsio)
2373{
2374	struct ctl_softc *softc;
2375	struct ctl_lun *lun;
2376	struct scsi_report_all_rod_tokens *cdb;
2377	struct scsi_report_all_rod_tokens_data *data;
2378	struct tpc_token *token;
2379	int retval;
2380	int alloc_len, total_len, tokens, i;
2381
2382	CTL_DEBUG_PRINT(("ctl_receive_rod_token_information\n"));
2383
2384	cdb = (struct scsi_report_all_rod_tokens *)ctsio->cdb;
2385	lun = (struct ctl_lun *)ctsio->io_hdr.ctl_private[CTL_PRIV_LUN].ptr;
2386	softc = lun->ctl_softc;
2387
2388	retval = CTL_RETVAL_COMPLETE;
2389
2390	tokens = 0;
2391	mtx_lock(&softc->tpc_lock);
2392	TAILQ_FOREACH(token, &softc->tpc_tokens, links)
2393		tokens++;
2394	mtx_unlock(&softc->tpc_lock);
2395	if (tokens > 512)
2396		tokens = 512;
2397
2398	total_len = sizeof(*data) + tokens * 96;
2399	alloc_len = scsi_4btoul(cdb->length);
2400
2401	ctsio->kern_data_ptr = malloc(total_len, M_CTL, M_WAITOK | M_ZERO);
2402
2403	ctsio->kern_sg_entries = 0;
2404
2405	if (total_len < alloc_len) {
2406		ctsio->residual = alloc_len - total_len;
2407		ctsio->kern_data_len = total_len;
2408		ctsio->kern_total_len = total_len;
2409	} else {
2410		ctsio->residual = 0;
2411		ctsio->kern_data_len = alloc_len;
2412		ctsio->kern_total_len = alloc_len;
2413	}
2414	ctsio->kern_data_resid = 0;
2415	ctsio->kern_rel_offset = 0;
2416
2417	data = (struct scsi_report_all_rod_tokens_data *)ctsio->kern_data_ptr;
2418	i = 0;
2419	mtx_lock(&softc->tpc_lock);
2420	TAILQ_FOREACH(token, &softc->tpc_tokens, links) {
2421		if (i >= tokens)
2422			break;
2423		memcpy(&data->rod_management_token_list[i * 96],
2424		    token->token, 96);
2425		i++;
2426	}
2427	mtx_unlock(&softc->tpc_lock);
2428	scsi_ulto4b(sizeof(*data) - 4 + i * 96, data->available_data);
2429/*
2430	printf("RART tokens=%d\n", i);
2431*/
2432	ctl_set_success(ctsio);
2433	ctsio->io_hdr.flags |= CTL_FLAG_ALLOCATED;
2434	ctsio->be_move_done = ctl_config_move_done;
2435	ctl_datamove((union ctl_io *)ctsio);
2436	return (retval);
2437}
2438
2439