xref: /netbsd-src/sys/dev/usb/umass.c (revision a24efa7dea9f1f56c3bdb15a927d3516792ace1c)
1 /*	$NetBSD: umass.c,v 1.152 2016/04/29 07:11:32 skrll Exp $	*/
2 
3 /*
4  * Copyright (c) 2003 The NetBSD Foundation, Inc.
5  * All rights reserved.
6  *
7  * This code is derived from software contributed to The NetBSD Foundation
8  * by Charles M. Hannum.
9  *
10  * Redistribution and use in source and binary forms, with or without
11  * modification, are permitted provided that the following conditions
12  * are met:
13  * 1. Redistributions of source code must retain the above copyright
14  *    notice, this list of conditions and the following disclaimer.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  *
19  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29  * POSSIBILITY OF SUCH DAMAGE.
30  */
31 
32 /*-
33  * Copyright (c) 1999 MAEKAWA Masahide <bishop@rr.iij4u.or.jp>,
34  *		      Nick Hibma <n_hibma@freebsd.org>
35  * All rights reserved.
36  *
37  * Redistribution and use in source and binary forms, with or without
38  * modification, are permitted provided that the following conditions
39  * are met:
40  * 1. Redistributions of source code must retain the above copyright
41  *    notice, this list of conditions and the following disclaimer.
42  * 2. Redistributions in binary form must reproduce the above copyright
43  *    notice, this list of conditions and the following disclaimer in the
44  *    documentation and/or other materials provided with the distribution.
45  *
46  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
47  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
48  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
49  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
50  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
51  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
52  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
53  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
54  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
55  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
56  * SUCH DAMAGE.
57  *
58  *     $FreeBSD: src/sys/dev/usb/umass.c,v 1.13 2000/03/26 01:39:12 n_hibma Exp $
59  */
60 
61 /*
62  * Universal Serial Bus Mass Storage Class specs:
63  * http://www.usb.org/developers/docs/devclass_docs/Mass_Storage_Specification_Overview_v1.4_2-19-2010.pdf
64  * http://www.usb.org/developers/docs/devclass_docs/usbmassbulk_10.pdf
65  * http://www.usb.org/developers/docs/devclass_docs/usb_msc_cbi_1.1.pdf
66  * http://www.usb.org/developers/docs/devclass_docs/usbmass-ufi10.pdf
67  */
68 
69 /*
70  * Ported to NetBSD by Lennart Augustsson <augustss@NetBSD.org>.
71  * Parts of the code written by Jason R. Thorpe <thorpej@shagadelic.org>.
72  */
73 
74 /*
75  * The driver handles 3 Wire Protocols
76  * - Command/Bulk/Interrupt (CBI)
77  * - Command/Bulk/Interrupt with Command Completion Interrupt (CBI with CCI)
78  * - Mass Storage Bulk-Only (BBB)
79  *   (BBB refers Bulk/Bulk/Bulk for Command/Data/Status phases)
80  *
81  * Over these wire protocols it handles the following command protocols
82  * - SCSI
83  * - 8070 (ATA/ATAPI for rewritable removable media)
84  * - UFI (USB Floppy Interface)
85  *
86  * 8070i is a transformed version of the SCSI command set. UFI is a transformed
87  * version of the 8070i command set.  The sc->transform method is used to
88  * convert the commands into the appropriate format (if at all necessary).
89  * For example, ATAPI requires all commands to be 12 bytes in length amongst
90  * other things.
91  *
92  * The source code below is marked and can be split into a number of pieces
93  * (in this order):
94  *
95  * - probe/attach/detach
96  * - generic transfer routines
97  * - BBB
98  * - CBI
99  * - CBI_I (in addition to functions from CBI)
100  * - CAM (Common Access Method)
101  * - SCSI
102  * - UFI
103  * - 8070i
104  *
105  * The protocols are implemented using a state machine, for the transfers as
106  * well as for the resets. The state machine is contained in umass_*_state.
107  * The state machine is started through either umass_*_transfer or
108  * umass_*_reset.
109  *
110  * The reason for doing this is a) CAM performs a lot better this way and b) it
111  * avoids using tsleep from interrupt context (for example after a failed
112  * transfer).
113  */
114 
115 /*
116  * The SCSI related part of this driver has been derived from the
117  * dev/ppbus/vpo.c driver, by Nicolas Souchu (nsouch@freebsd.org).
118  *
119  * The CAM layer uses so called actions which are messages sent to the host
120  * adapter for completion. The actions come in through umass_cam_action. The
121  * appropriate block of routines is called depending on the transport protocol
122  * in use. When the transfer has finished, these routines call
123  * umass_cam_cb again to complete the CAM command.
124  */
125 
126 #include <sys/cdefs.h>
127 __KERNEL_RCSID(0, "$NetBSD: umass.c,v 1.152 2016/04/29 07:11:32 skrll Exp $");
128 
129 #ifdef _KERNEL_OPT
130 #include "opt_usb.h"
131 #endif
132 
133 #include "atapibus.h"
134 #include "scsibus.h"
135 #include "wd.h"
136 
137 #include <sys/param.h>
138 #include <sys/systm.h>
139 #include <sys/kernel.h>
140 #include <sys/conf.h>
141 #include <sys/buf.h>
142 #include <sys/device.h>
143 #include <sys/malloc.h>
144 #include <sys/sysctl.h>
145 
146 #include <dev/usb/usb.h>
147 #include <dev/usb/usbdi.h>
148 #include <dev/usb/usbdi_util.h>
149 #include <dev/usb/usbdevs.h>
150 #include <dev/usb/usbhist.h>
151 
152 #include <dev/usb/umassvar.h>
153 #include <dev/usb/umass_quirks.h>
154 #include <dev/usb/umass_scsipi.h>
155 #include <dev/usb/umass_isdata.h>
156 
157 #include <dev/scsipi/scsipi_all.h>
158 #include <dev/scsipi/scsipiconf.h>
159 
160 #ifdef USB_DEBUG
161 int umassdebug = 0;
162 
163 SYSCTL_SETUP(sysctl_hw_umass_setup, "sysctl hw.umass setup")
164 {
165 	int err;
166 	const struct sysctlnode *rnode;
167 	const struct sysctlnode *cnode;
168 
169 	err = sysctl_createv(clog, 0, NULL, &rnode,
170 	    CTLFLAG_PERMANENT, CTLTYPE_NODE, "umass",
171 	    SYSCTL_DESCR("umass global controls"),
172 	    NULL, 0, NULL, 0, CTL_HW, CTL_CREATE, CTL_EOL);
173 
174 	if (err)
175 		goto fail;
176 
177 	/* control debugging printfs */
178 	err = sysctl_createv(clog, 0, &rnode, &cnode,
179 	    CTLFLAG_PERMANENT|CTLFLAG_READWRITE, CTLTYPE_INT,
180 	    "debug", SYSCTL_DESCR("Enable debugging output"),
181 	    NULL, 0, &umassdebug, sizeof(umassdebug), CTL_CREATE, CTL_EOL);
182 	if (err)
183 		goto fail;
184 
185 	return;
186 fail:
187 	aprint_error("%s: sysctl_createv failed (err = %d)\n", __func__, err);
188 }
189 
190 const char *states[TSTATE_STATES+1] = {
191 	/* should be kept in sync with the list at transfer_state */
192 	"Idle",
193 	"BBB CBW",
194 	"BBB Data",
195 	"BBB Data bulk-in/-out clear stall",
196 	"BBB CSW, 1st attempt",
197 	"BBB CSW bulk-in clear stall",
198 	"BBB CSW, 2nd attempt",
199 	"BBB Reset",
200 	"BBB bulk-in clear stall",
201 	"BBB bulk-out clear stall",
202 	"CBI Command",
203 	"CBI Data",
204 	"CBI Status",
205 	"CBI Data bulk-in/-out clear stall",
206 	"CBI Status intr-in clear stall",
207 	"CBI Reset",
208 	"CBI bulk-in clear stall",
209 	"CBI bulk-out clear stall",
210 	NULL
211 };
212 #endif
213 
214 /* USB device probe/attach/detach functions */
215 int umass_match(device_t, cfdata_t, void *);
216 void umass_attach(device_t, device_t, void *);
217 int umass_detach(device_t, int);
218 static void umass_childdet(device_t, device_t);
219 int umass_activate(device_t, enum devact);
220 extern struct cfdriver umass_cd;
221 CFATTACH_DECL2_NEW(umass, sizeof(struct umass_softc), umass_match, umass_attach,
222     umass_detach, umass_activate, NULL, umass_childdet);
223 
224 Static void umass_disco(struct umass_softc *sc);
225 
226 /* generic transfer functions */
227 Static usbd_status umass_setup_transfer(struct umass_softc *,
228 				struct usbd_pipe *,
229 				void *, int, int,
230 				struct usbd_xfer *);
231 Static usbd_status umass_setup_ctrl_transfer(struct umass_softc *,
232 				usb_device_request_t *,
233 				void *, int, int,
234 				struct usbd_xfer *);
235 Static void umass_clear_endpoint_stall(struct umass_softc *, int,
236 				struct usbd_xfer *);
237 #if 0
238 Static void umass_reset(struct umass_softc *, transfer_cb_f, void *);
239 #endif
240 
241 /* Bulk-Only related functions */
242 Static void umass_bbb_transfer(struct umass_softc *, int, void *, int, void *,
243 			       int, int, u_int, int, umass_callback, void *);
244 Static void umass_bbb_reset(struct umass_softc *, int);
245 Static void umass_bbb_state(struct usbd_xfer *, void *, usbd_status);
246 
247 usbd_status umass_bbb_get_max_lun(struct umass_softc *, uint8_t *);
248 
249 /* CBI related functions */
250 Static void umass_cbi_transfer(struct umass_softc *, int, void *, int, void *,
251 			       int, int, u_int, int, umass_callback, void *);
252 Static void umass_cbi_reset(struct umass_softc *, int);
253 Static void umass_cbi_state(struct usbd_xfer *, void *, usbd_status);
254 
255 Static int umass_cbi_adsc(struct umass_softc *, char *, int, int, struct usbd_xfer *);
256 
257 const struct umass_wire_methods umass_bbb_methods = {
258 	.wire_xfer = umass_bbb_transfer,
259 	.wire_reset = umass_bbb_reset,
260 	.wire_state = umass_bbb_state
261 };
262 
263 const struct umass_wire_methods umass_cbi_methods = {
264 	.wire_xfer = umass_cbi_transfer,
265 	.wire_reset = umass_cbi_reset,
266 	.wire_state = umass_cbi_state
267 };
268 
269 #ifdef UMASS_DEBUG
270 /* General debugging functions */
271 Static void umass_bbb_dump_cbw(struct umass_softc *sc,
272 				umass_bbb_cbw_t *cbw);
273 Static void umass_bbb_dump_csw(struct umass_softc *sc,
274 				umass_bbb_csw_t *csw);
275 Static void umass_dump_buffer(struct umass_softc *sc, uint8_t *buffer,
276 				int buflen, int printlen);
277 #endif
278 
279 
280 /*
281  * USB device probe/attach/detach
282  */
283 
284 int
285 umass_match(device_t parent, cfdata_t match, void *aux)
286 {
287 	struct usbif_attach_arg *uiaa = aux;
288 	const struct umass_quirk *quirk;
289 
290 	quirk = umass_lookup(uiaa->uiaa_vendor, uiaa->uiaa_product);
291 	if (quirk != NULL && quirk->uq_match != UMASS_QUIRK_USE_DEFAULTMATCH)
292 		return quirk->uq_match;
293 
294 	if (uiaa->uiaa_class != UICLASS_MASS)
295 		return UMATCH_NONE;
296 
297 	switch (uiaa->uiaa_subclass) {
298 	case UISUBCLASS_RBC:
299 	case UISUBCLASS_SFF8020I:
300 	case UISUBCLASS_QIC157:
301 	case UISUBCLASS_UFI:
302 	case UISUBCLASS_SFF8070I:
303 	case UISUBCLASS_SCSI:
304 		break;
305 	default:
306 		return UMATCH_IFACECLASS;
307 	}
308 
309 	switch (uiaa->uiaa_proto) {
310 	case UIPROTO_MASS_CBI_I:
311 	case UIPROTO_MASS_CBI:
312 	case UIPROTO_MASS_BBB_OLD:
313 	case UIPROTO_MASS_BBB:
314 		break;
315 	default:
316 		return UMATCH_IFACECLASS_IFACESUBCLASS;
317 	}
318 
319 	return UMATCH_IFACECLASS_IFACESUBCLASS_IFACEPROTO;
320 }
321 
322 void
323 umass_attach(device_t parent, device_t self, void *aux)
324 {
325 	struct umass_softc *sc = device_private(self);
326 	struct usbif_attach_arg *uiaa = aux;
327 	const struct umass_quirk *quirk;
328 	usb_interface_descriptor_t *id;
329 	usb_endpoint_descriptor_t *ed;
330 	const char *sWire, *sCommand;
331 	char *devinfop;
332 	usbd_status err;
333 	int i, error;
334 
335 	sc->sc_dev = self;
336 
337 	aprint_naive("\n");
338 	aprint_normal("\n");
339 
340 	mutex_init(&sc->sc_lock, MUTEX_DEFAULT, IPL_SOFTUSB);
341 	cv_init(&sc->sc_detach_cv, "umassdet");
342 
343 	devinfop = usbd_devinfo_alloc(uiaa->uiaa_device, 0);
344 	aprint_normal_dev(self, "%s\n", devinfop);
345 	usbd_devinfo_free(devinfop);
346 
347 	sc->sc_udev = uiaa->uiaa_device;
348 	sc->sc_iface = uiaa->uiaa_iface;
349 	sc->sc_ifaceno = uiaa->uiaa_ifaceno;
350 
351 	quirk = umass_lookup(uiaa->uiaa_vendor, uiaa->uiaa_product);
352 	if (quirk != NULL) {
353 		sc->sc_wire = quirk->uq_wire;
354 		sc->sc_cmd = quirk->uq_cmd;
355 		sc->sc_quirks = quirk->uq_flags;
356 		sc->sc_busquirks = quirk->uq_busquirks;
357 
358 		if (quirk->uq_fixup != NULL)
359 			(*quirk->uq_fixup)(sc);
360 	} else {
361 		sc->sc_wire = UMASS_WPROTO_UNSPEC;
362 		sc->sc_cmd = UMASS_CPROTO_UNSPEC;
363 		sc->sc_quirks = 0;
364 		sc->sc_busquirks = 0;
365 	}
366 
367 	if (sc->sc_wire == UMASS_WPROTO_UNSPEC) {
368 		switch (uiaa->uiaa_proto) {
369 		case UIPROTO_MASS_CBI:
370 			sc->sc_wire = UMASS_WPROTO_CBI;
371 			break;
372 		case UIPROTO_MASS_CBI_I:
373 			sc->sc_wire = UMASS_WPROTO_CBI_I;
374 			break;
375 		case UIPROTO_MASS_BBB:
376 		case UIPROTO_MASS_BBB_OLD:
377 			sc->sc_wire = UMASS_WPROTO_BBB;
378 			break;
379 		default:
380 			DPRINTF(UDMASS_GEN,
381 				("%s: Unsupported wire protocol %u\n",
382 				device_xname(sc->sc_dev),
383 				uiaa->uiaa_proto));
384 			return;
385 		}
386 	}
387 
388 	if (sc->sc_cmd == UMASS_CPROTO_UNSPEC) {
389 		switch (uiaa->uiaa_subclass) {
390 		case UISUBCLASS_SCSI:
391 			sc->sc_cmd = UMASS_CPROTO_SCSI;
392 			break;
393 		case UISUBCLASS_UFI:
394 			sc->sc_cmd = UMASS_CPROTO_UFI;
395 			break;
396 		case UISUBCLASS_SFF8020I:
397 		case UISUBCLASS_SFF8070I:
398 		case UISUBCLASS_QIC157:
399 			sc->sc_cmd = UMASS_CPROTO_ATAPI;
400 			break;
401 		case UISUBCLASS_RBC:
402 			sc->sc_cmd = UMASS_CPROTO_RBC;
403 			break;
404 		default:
405 			DPRINTF(UDMASS_GEN,
406 				("%s: Unsupported command protocol %u\n",
407 				device_xname(sc->sc_dev),
408 				uiaa->uiaa_subclass));
409 			return;
410 		}
411 	}
412 
413 	switch (sc->sc_wire) {
414 	case UMASS_WPROTO_CBI:
415 		sWire = "CBI";
416 		break;
417 	case UMASS_WPROTO_CBI_I:
418 		sWire = "CBI with CCI";
419 		break;
420 	case UMASS_WPROTO_BBB:
421 		sWire = "Bulk-Only";
422 		break;
423 	default:
424 		sWire = "unknown";
425 		break;
426 	}
427 
428 	switch (sc->sc_cmd) {
429 	case UMASS_CPROTO_RBC:
430 		sCommand = "RBC";
431 		break;
432 	case UMASS_CPROTO_SCSI:
433 		sCommand = "SCSI";
434 		break;
435 	case UMASS_CPROTO_UFI:
436 		sCommand = "UFI";
437 		break;
438 	case UMASS_CPROTO_ATAPI:
439 		sCommand = "ATAPI";
440 		break;
441 	case UMASS_CPROTO_ISD_ATA:
442 		sCommand = "ISD-ATA";
443 		break;
444 	default:
445 		sCommand = "unknown";
446 		break;
447 	}
448 
449 	aprint_verbose_dev(self, "using %s over %s\n", sCommand, sWire);
450 
451 	if (quirk != NULL && quirk->uq_init != NULL) {
452 		err = (*quirk->uq_init)(sc);
453 		if (err) {
454 			aprint_error_dev(self, "quirk init failed\n");
455 			umass_disco(sc);
456 			return;
457 		}
458 	}
459 
460 	/*
461 	 * In addition to the Control endpoint the following endpoints
462 	 * are required:
463 	 * a) bulk-in endpoint.
464 	 * b) bulk-out endpoint.
465 	 * and for Control/Bulk/Interrupt with CCI (CBI_I)
466 	 * c) intr-in
467 	 *
468 	 * The endpoint addresses are not fixed, so we have to read them
469 	 * from the device descriptors of the current interface.
470 	 */
471 	id = usbd_get_interface_descriptor(sc->sc_iface);
472 	for (i = 0 ; i < id->bNumEndpoints ; i++) {
473 		ed = usbd_interface2endpoint_descriptor(sc->sc_iface, i);
474 		if (ed == NULL) {
475 			aprint_error_dev(self,
476 			    "could not read endpoint descriptor\n");
477 			return;
478 		}
479 		if (UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_IN
480 		    && (ed->bmAttributes & UE_XFERTYPE) == UE_BULK) {
481 			sc->sc_epaddr[UMASS_BULKIN] = ed->bEndpointAddress;
482 		} else if (UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_OUT
483 		    && (ed->bmAttributes & UE_XFERTYPE) == UE_BULK) {
484 			sc->sc_epaddr[UMASS_BULKOUT] = ed->bEndpointAddress;
485 		} else if (sc->sc_wire == UMASS_WPROTO_CBI_I
486 		    && UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_IN
487 		    && (ed->bmAttributes & UE_XFERTYPE) == UE_INTERRUPT) {
488 			sc->sc_epaddr[UMASS_INTRIN] = ed->bEndpointAddress;
489 #ifdef UMASS_DEBUG
490 			if (UGETW(ed->wMaxPacketSize) > 2) {
491 				DPRINTF(UDMASS_CBI, ("%s: intr size is %d\n",
492 					device_xname(sc->sc_dev),
493 					UGETW(ed->wMaxPacketSize)));
494 			}
495 #endif
496 		}
497 	}
498 
499 	/* check whether we found all the endpoints we need */
500 	if (!sc->sc_epaddr[UMASS_BULKIN] || !sc->sc_epaddr[UMASS_BULKOUT] ||
501 	    (sc->sc_wire == UMASS_WPROTO_CBI_I &&
502 	     !sc->sc_epaddr[UMASS_INTRIN])) {
503 		aprint_error_dev(self, "endpoint not found %u/%u/%u\n",
504 		       sc->sc_epaddr[UMASS_BULKIN],
505 		       sc->sc_epaddr[UMASS_BULKOUT],
506 		       sc->sc_epaddr[UMASS_INTRIN]);
507 		return;
508 	}
509 
510 	/*
511 	 * Get the maximum LUN supported by the device.
512 	 */
513 	if (sc->sc_wire == UMASS_WPROTO_BBB &&
514 	    (sc->sc_quirks & UMASS_QUIRK_NOGETMAXLUN) == 0) {
515 		err = umass_bbb_get_max_lun(sc, &sc->maxlun);
516 		if (err) {
517 			aprint_error_dev(self, "unable to get Max Lun: %s\n",
518 			    usbd_errstr(err));
519 			return;
520 		}
521 		if (sc->maxlun > 0)
522 			sc->sc_busquirks |= PQUIRK_FORCELUNS;
523 	} else {
524 		sc->maxlun = 0;
525 	}
526 
527 	/* Open the bulk-in and -out pipe */
528 	DPRINTF(UDMASS_USB, ("%s: opening iface %p epaddr %d for BULKOUT\n",
529 		device_xname(sc->sc_dev), sc->sc_iface,
530 		sc->sc_epaddr[UMASS_BULKOUT]));
531 	err = usbd_open_pipe(sc->sc_iface, sc->sc_epaddr[UMASS_BULKOUT],
532 				USBD_EXCLUSIVE_USE,
533 				&sc->sc_pipe[UMASS_BULKOUT]);
534 	if (err) {
535 		aprint_error_dev(self, "cannot open %u-out pipe (bulk)\n",
536 		    sc->sc_epaddr[UMASS_BULKOUT]);
537 		umass_disco(sc);
538 		return;
539 	}
540 	DPRINTF(UDMASS_USB, ("%s: opening iface %p epaddr %d for BULKIN\n",
541 		device_xname(sc->sc_dev), sc->sc_iface,
542 		sc->sc_epaddr[UMASS_BULKIN]));
543 	err = usbd_open_pipe(sc->sc_iface, sc->sc_epaddr[UMASS_BULKIN],
544 				USBD_EXCLUSIVE_USE, &sc->sc_pipe[UMASS_BULKIN]);
545 	if (err) {
546 		aprint_error_dev(self, "could not open %u-in pipe (bulk)\n",
547 		    sc->sc_epaddr[UMASS_BULKIN]);
548 		umass_disco(sc);
549 		return;
550 	}
551 	/*
552 	 * Open the intr-in pipe if the protocol is CBI with CCI.
553 	 * Note: early versions of the Zip drive do have an interrupt pipe, but
554 	 * this pipe is unused
555 	 *
556 	 * We do not open the interrupt pipe as an interrupt pipe, but as a
557 	 * normal bulk endpoint. We send an IN transfer down the wire at the
558 	 * appropriate time, because we know exactly when to expect data on
559 	 * that endpoint. This saves bandwidth, but more important, makes the
560 	 * code for handling the data on that endpoint simpler. No data
561 	 * arriving concurrently.
562 	 */
563 	if (sc->sc_wire == UMASS_WPROTO_CBI_I) {
564 		DPRINTF(UDMASS_USB, ("%s: opening iface %p epaddr %d for INTRIN\n",
565 			device_xname(sc->sc_dev), sc->sc_iface,
566 			sc->sc_epaddr[UMASS_INTRIN]));
567 		err = usbd_open_pipe(sc->sc_iface, sc->sc_epaddr[UMASS_INTRIN],
568 				USBD_EXCLUSIVE_USE, &sc->sc_pipe[UMASS_INTRIN]);
569 		if (err) {
570 			aprint_error_dev(self, "couldn't open %u-in (intr)\n",
571 			    sc->sc_epaddr[UMASS_INTRIN]);
572 			umass_disco(sc);
573 			return;
574 		}
575 	}
576 
577 	/* initialisation of generic part */
578 	sc->transfer_state = TSTATE_IDLE;
579 
580 	for (i = 0; i < XFER_NR; i++) {
581 		sc->transfer_xfer[i] = NULL;
582 	}
583 
584 	/*
585 	 * Create the transfers
586 	 */
587 	struct usbd_pipe *pipe0 = usbd_get_pipe0(sc->sc_udev);
588 	switch (sc->sc_wire) {
589 	case UMASS_WPROTO_BBB:
590 		err = usbd_create_xfer(sc->sc_pipe[UMASS_BULKIN],
591 		    UMASS_MAX_TRANSFER_SIZE, USBD_SHORT_XFER_OK, 0,
592 		    &sc->transfer_xfer[XFER_BBB_DATAIN]);
593 		if (err)
594 			goto fail_create;
595 		err = usbd_create_xfer(sc->sc_pipe[UMASS_BULKOUT],
596 		    UMASS_MAX_TRANSFER_SIZE, USBD_SHORT_XFER_OK, 0,
597 		    &sc->transfer_xfer[XFER_BBB_DATAOUT]);
598 		if (err)
599 			goto fail_create;
600 		err = usbd_create_xfer(sc->sc_pipe[UMASS_BULKOUT],
601 		    UMASS_BBB_CBW_SIZE, USBD_SHORT_XFER_OK, 0,
602 		    &sc->transfer_xfer[XFER_BBB_CBW]);
603 		if (err)
604 			goto fail_create;
605 		err = usbd_create_xfer(sc->sc_pipe[UMASS_BULKIN],
606 		    UMASS_BBB_CSW_SIZE, USBD_SHORT_XFER_OK, 0,
607 		    &sc->transfer_xfer[XFER_BBB_CSW1]);
608 		if (err)
609 			goto fail_create;
610 		err = usbd_create_xfer(sc->sc_pipe[UMASS_BULKIN],
611 		    UMASS_BBB_CSW_SIZE, USBD_SHORT_XFER_OK, 0,
612 		    &sc->transfer_xfer[XFER_BBB_CSW2]);
613 		if (err)
614 			goto fail_create;
615 		err = usbd_create_xfer(pipe0, 0, 0, 0,
616 		    &sc->transfer_xfer[XFER_BBB_SCLEAR]);
617 		if (err)
618 			goto fail_create;
619 		err = usbd_create_xfer(pipe0, 0, 0, 0,
620 		    &sc->transfer_xfer[XFER_BBB_DCLEAR]);
621 		if (err)
622 			goto fail_create;
623 		err = usbd_create_xfer(pipe0, 0, 0, 0,
624 		    &sc->transfer_xfer[XFER_BBB_RESET1]);
625 		if (err)
626 			goto fail_create;
627 		err = usbd_create_xfer(pipe0, 0, 0, 0,
628 		    &sc->transfer_xfer[XFER_BBB_RESET2]);
629 		if (err)
630 			goto fail_create;
631 		err = usbd_create_xfer(pipe0, 0, 0, 0,
632 		    &sc->transfer_xfer[XFER_BBB_RESET3]);
633 		if (err)
634 			goto fail_create;
635 		break;
636 	case UMASS_WPROTO_CBI:
637 	case UMASS_WPROTO_CBI_I:
638 		err = usbd_create_xfer(pipe0, sizeof(sc->cbl), 0, 0,
639 		    &sc->transfer_xfer[XFER_CBI_CB]);
640 		if (err)
641 			goto fail_create;
642 		err = usbd_create_xfer(sc->sc_pipe[UMASS_BULKIN],
643 		    UMASS_MAX_TRANSFER_SIZE, USBD_SHORT_XFER_OK, 0,
644 		    &sc->transfer_xfer[XFER_CBI_DATAIN]);
645 		if (err)
646 			goto fail_create;
647 		err = usbd_create_xfer(sc->sc_pipe[UMASS_BULKOUT],
648 		    UMASS_MAX_TRANSFER_SIZE, 0, 0,
649 		    &sc->transfer_xfer[XFER_CBI_DATAOUT]);
650 		if (err)
651 			goto fail_create;
652 		err = usbd_create_xfer(sc->sc_pipe[UMASS_INTRIN],
653 		    sizeof(sc->sbl), 0, 0,
654 		    &sc->transfer_xfer[XFER_CBI_STATUS]);
655 		if (err)
656 			goto fail_create;
657 		err = usbd_create_xfer(pipe0, 0, 0, 0,
658 		    &sc->transfer_xfer[XFER_CBI_DCLEAR]);
659 		if (err)
660 			goto fail_create;
661 		err = usbd_create_xfer(pipe0, 0, 0, 0,
662 		    &sc->transfer_xfer[XFER_CBI_SCLEAR]);
663 		if (err)
664 			goto fail_create;
665 		err = usbd_create_xfer(pipe0, sizeof(sc->cbl), 0, 0,
666 		    &sc->transfer_xfer[XFER_CBI_RESET1]);
667 		if (err)
668 			goto fail_create;
669 		err = usbd_create_xfer(pipe0, sizeof(sc->cbl), 0, 0,
670 		    &sc->transfer_xfer[XFER_CBI_RESET2]);
671 		if (err)
672 			goto fail_create;
673 		err = usbd_create_xfer(pipe0, sizeof(sc->cbl), 0, 0,
674 		    &sc->transfer_xfer[XFER_CBI_RESET3]);
675 		if (err)
676 			goto fail_create;
677 		break;
678 	default:
679 	fail_create:
680 		aprint_error_dev(self, "failed to create xfers\n");
681 		umass_disco(sc);
682 		return;
683 	}
684 
685 	/*
686 	 * Record buffer pinters for data transfer (it's huge), command and
687 	 * status data here
688 	 */
689 	switch (sc->sc_wire) {
690 	case UMASS_WPROTO_BBB:
691 		sc->datain_buffer =
692 		    usbd_get_buffer(sc->transfer_xfer[XFER_BBB_DATAIN]);
693 		sc->dataout_buffer =
694 		    usbd_get_buffer(sc->transfer_xfer[XFER_BBB_DATAOUT]);
695 		sc->cmd_buffer =
696 		    usbd_get_buffer(sc->transfer_xfer[XFER_BBB_CBW]);
697 		sc->s1_buffer =
698 		    usbd_get_buffer(sc->transfer_xfer[XFER_BBB_CSW1]);
699 		sc->s2_buffer =
700 		    usbd_get_buffer(sc->transfer_xfer[XFER_BBB_CSW2]);
701 		break;
702 	case UMASS_WPROTO_CBI:
703 	case UMASS_WPROTO_CBI_I:
704 		sc->datain_buffer =
705 		    usbd_get_buffer(sc->transfer_xfer[XFER_CBI_DATAIN]);
706 		sc->dataout_buffer =
707 		    usbd_get_buffer(sc->transfer_xfer[XFER_CBI_DATAOUT]);
708 		sc->cmd_buffer =
709 		    usbd_get_buffer(sc->transfer_xfer[XFER_CBI_CB]);
710 		sc->s1_buffer =
711 		    usbd_get_buffer(sc->transfer_xfer[XFER_CBI_STATUS]);
712 		sc->s2_buffer =
713 		    usbd_get_buffer(sc->transfer_xfer[XFER_CBI_RESET1]);
714 		break;
715 	default:
716 		break;
717 	}
718 
719 	/* Initialise the wire protocol specific methods */
720 	switch (sc->sc_wire) {
721 	case UMASS_WPROTO_BBB:
722 		sc->sc_methods = &umass_bbb_methods;
723 		break;
724 	case UMASS_WPROTO_CBI:
725 	case UMASS_WPROTO_CBI_I:
726 		sc->sc_methods = &umass_cbi_methods;
727 		break;
728 	default:
729 		umass_disco(sc);
730 		return;
731 	}
732 
733 	error = 0;
734 	switch (sc->sc_cmd) {
735 	case UMASS_CPROTO_RBC:
736 	case UMASS_CPROTO_SCSI:
737 #if NSCSIBUS > 0
738 		error = umass_scsi_attach(sc);
739 #else
740 		aprint_error_dev(self, "scsibus not configured\n");
741 #endif
742 		break;
743 
744 	case UMASS_CPROTO_UFI:
745 	case UMASS_CPROTO_ATAPI:
746 #if NATAPIBUS > 0
747 		error = umass_atapi_attach(sc);
748 #else
749 		aprint_error_dev(self, "atapibus not configured\n");
750 #endif
751 		break;
752 
753 	case UMASS_CPROTO_ISD_ATA:
754 #if NWD > 0
755 		error = umass_isdata_attach(sc);
756 #else
757 		aprint_error_dev(self, "isdata not configured\n");
758 #endif
759 		break;
760 
761 	default:
762 		aprint_error_dev(self, "command protocol=0x%x not supported\n",
763 		    sc->sc_cmd);
764 		umass_disco(sc);
765 		return;
766 	}
767 	if (error) {
768 		aprint_error_dev(self, "bus attach failed\n");
769 		umass_disco(sc);
770 		return;
771 	}
772 
773 	usbd_add_drv_event(USB_EVENT_DRIVER_ATTACH, sc->sc_udev,
774 			   sc->sc_dev);
775 
776 	if (!pmf_device_register(self, NULL, NULL))
777 		aprint_error_dev(self, "couldn't establish power handler\n");
778 
779 	DPRINTF(UDMASS_GEN, ("%s: Attach finished\n", device_xname(sc->sc_dev)));
780 
781 	return;
782 }
783 
784 static void
785 umass_childdet(device_t self, device_t child)
786 {
787 	struct umass_softc *sc = device_private(self);
788 
789 	KASSERTMSG(child == sc->bus->sc_child,
790 		   "assertion child == sc->bus->sc_child failed\n");
791 	sc->bus->sc_child = NULL;
792 }
793 
794 int
795 umass_detach(device_t self, int flags)
796 {
797 	struct umass_softc *sc = device_private(self);
798 	struct umassbus_softc *scbus;
799 	int rv = 0, i;
800 
801 	DPRINTF(UDMASS_USB, ("%s: detached\n", device_xname(sc->sc_dev)));
802 
803 	pmf_device_deregister(self);
804 
805 	/* Abort the pipes to wake up any waiting processes. */
806 	for (i = 0 ; i < UMASS_NEP ; i++) {
807 		if (sc->sc_pipe[i] != NULL)
808 			usbd_abort_pipe(sc->sc_pipe[i]);
809 	}
810 
811 	/* Do we really need reference counting?  Perhaps in ioctl() */
812 	mutex_enter(&sc->sc_lock);
813 	if (--sc->sc_refcnt >= 0) {
814 #ifdef DIAGNOSTIC
815 		aprint_normal_dev(self, "waiting for refcnt\n");
816 #endif
817 		/* Wait for processes to go away. */
818 		usb_detach_wait(sc->sc_dev, &sc->sc_detach_cv, &sc->sc_lock);
819 	}
820 	mutex_exit(&sc->sc_lock);
821 
822 	scbus = sc->bus;
823 	if (scbus != NULL) {
824 		if (scbus->sc_child != NULL)
825 			rv = config_detach(scbus->sc_child, flags);
826 		free(scbus, M_DEVBUF);
827 		sc->bus = NULL;
828 	}
829 
830 	if (rv != 0)
831 		return rv;
832 
833 	umass_disco(sc);
834 
835 	usbd_add_drv_event(USB_EVENT_DRIVER_DETACH, sc->sc_udev,
836 			   sc->sc_dev);
837 
838 	mutex_destroy(&sc->sc_lock);
839 	cv_destroy(&sc->sc_detach_cv);
840 
841 	return rv;
842 }
843 
844 int
845 umass_activate(device_t dev, enum devact act)
846 {
847 	struct umass_softc *sc = device_private(dev);
848 
849 	DPRINTF(UDMASS_USB, ("%s: umass_activate: %d\n",
850 	    device_xname(dev), act));
851 
852 	switch (act) {
853 	case DVACT_DEACTIVATE:
854 		sc->sc_dying = 1;
855 		return 0;
856 	default:
857 		return EOPNOTSUPP;
858 	}
859 }
860 
861 Static void
862 umass_disco(struct umass_softc *sc)
863 {
864 	int i;
865 
866 	DPRINTF(UDMASS_GEN, ("umass_disco\n"));
867 
868 	/* Remove all the pipes. */
869 	for (i = 0 ; i < UMASS_NEP ; i++) {
870 		if (sc->sc_pipe[i] != NULL) {
871 			usbd_abort_pipe(sc->sc_pipe[i]);
872 		}
873 	}
874 
875 	/* Some xfers may be queued in the default pipe */
876 	usbd_abort_default_pipe(sc->sc_udev);
877 
878 	/* Free the xfers. */
879 	for (i = 0; i < XFER_NR; i++) {
880 		if (sc->transfer_xfer[i] != NULL) {
881 			usbd_destroy_xfer(sc->transfer_xfer[i]);
882 			sc->transfer_xfer[i] = NULL;
883 		}
884 	}
885 
886 	for (i = 0 ; i < UMASS_NEP ; i++) {
887 		if (sc->sc_pipe[i] != NULL) {
888 			usbd_close_pipe(sc->sc_pipe[i]);
889 			sc->sc_pipe[i] = NULL;
890 		}
891 	}
892 
893 }
894 
895 /*
896  * Generic functions to handle transfers
897  */
898 
899 Static usbd_status
900 umass_setup_transfer(struct umass_softc *sc, struct usbd_pipe *pipe,
901 			void *buffer, int buflen, int flags,
902 			struct usbd_xfer *xfer)
903 {
904 	usbd_status err;
905 
906 	USBHIST_FUNC(); USBHIST_CALLED(umassdebug);
907 
908 	if (sc->sc_dying)
909 		return USBD_IOERROR;
910 
911 	/* Initialiase a USB transfer and then schedule it */
912 
913 	usbd_setup_xfer(xfer, sc, buffer, buflen, flags, sc->timeout,
914 	    sc->sc_methods->wire_state);
915 
916 	USBHIST_LOG(umassdebug, "xfer %p, flags %d", xfer, flags, 0, 0);
917 
918 	err = usbd_transfer(xfer);
919 	DPRINTF(UDMASS_XFER,("%s: start xfer buffer=%p buflen=%d flags=0x%x "
920 	    "timeout=%d\n", device_xname(sc->sc_dev),
921 	    buffer, buflen, flags, sc->timeout));
922 	if (err && err != USBD_IN_PROGRESS) {
923 		DPRINTF(UDMASS_BBB, ("%s: failed to setup transfer, %s\n",
924 			device_xname(sc->sc_dev), usbd_errstr(err)));
925 		return err;
926 	}
927 
928 	return USBD_NORMAL_COMPLETION;
929 }
930 
931 
932 Static usbd_status
933 umass_setup_ctrl_transfer(struct umass_softc *sc, usb_device_request_t *req,
934 	 void *buffer, int buflen, int flags, struct usbd_xfer *xfer)
935 {
936 	usbd_status err;
937 
938 	if (sc->sc_dying)
939 		return USBD_IOERROR;
940 
941 	/* Initialiase a USB control transfer and then schedule it */
942 
943 	usbd_setup_default_xfer(xfer, sc->sc_udev, (void *) sc, sc->timeout,
944 		req, buffer, buflen, flags, sc->sc_methods->wire_state);
945 
946 	err = usbd_transfer(xfer);
947 	if (err && err != USBD_IN_PROGRESS) {
948 		DPRINTF(UDMASS_BBB, ("%s: failed to setup ctrl transfer, %s\n",
949 			 device_xname(sc->sc_dev), usbd_errstr(err)));
950 
951 		/* do not reset, as this would make us loop */
952 		return err;
953 	}
954 
955 	return USBD_NORMAL_COMPLETION;
956 }
957 
958 Static void
959 umass_clear_endpoint_stall(struct umass_softc *sc, int endpt,
960 	struct usbd_xfer *xfer)
961 {
962 	if (sc->sc_dying)
963 		return;
964 
965 	DPRINTF(UDMASS_BBB, ("%s: Clear endpoint 0x%02x stall\n",
966 		device_xname(sc->sc_dev), sc->sc_epaddr[endpt]));
967 
968 	usbd_clear_endpoint_toggle(sc->sc_pipe[endpt]);
969 
970 	sc->sc_req.bmRequestType = UT_WRITE_ENDPOINT;
971 	sc->sc_req.bRequest = UR_CLEAR_FEATURE;
972 	USETW(sc->sc_req.wValue, UF_ENDPOINT_HALT);
973 	USETW(sc->sc_req.wIndex, sc->sc_epaddr[endpt]);
974 	USETW(sc->sc_req.wLength, 0);
975 	umass_setup_ctrl_transfer(sc, &sc->sc_req, NULL, 0, 0, xfer);
976 }
977 
978 #if 0
979 Static void
980 umass_reset(struct umass_softc *sc, transfer_cb_f cb, void *priv)
981 {
982 	sc->transfer_cb = cb;
983 	sc->transfer_priv = priv;
984 
985 	/* The reset is a forced reset, so no error (yet) */
986 	sc->reset(sc, STATUS_CMD_OK);
987 }
988 #endif
989 
990 /*
991  * Bulk protocol specific functions
992  */
993 
994 Static void
995 umass_bbb_reset(struct umass_softc *sc, int status)
996 {
997 	KASSERTMSG(sc->sc_wire & UMASS_WPROTO_BBB,
998 		   "sc->sc_wire == 0x%02x wrong for umass_bbb_reset\n",
999 		   sc->sc_wire);
1000 
1001 	if (sc->sc_dying)
1002 		return;
1003 
1004 	/*
1005 	 * Reset recovery (5.3.4 in Universal Serial Bus Mass Storage Class)
1006 	 *
1007 	 * For Reset Recovery the host shall issue in the following order:
1008 	 * a) a Bulk-Only Mass Storage Reset
1009 	 * b) a Clear Feature HALT to the Bulk-In endpoint
1010 	 * c) a Clear Feature HALT to the Bulk-Out endpoint
1011 	 *
1012 	 * This is done in 3 steps, states:
1013 	 * TSTATE_BBB_RESET1
1014 	 * TSTATE_BBB_RESET2
1015 	 * TSTATE_BBB_RESET3
1016 	 *
1017 	 * If the reset doesn't succeed, the device should be port reset.
1018 	 */
1019 
1020 	DPRINTF(UDMASS_BBB, ("%s: Bulk Reset\n",
1021 		device_xname(sc->sc_dev)));
1022 
1023 	sc->transfer_state = TSTATE_BBB_RESET1;
1024 	sc->transfer_status = status;
1025 
1026 	/* reset is a class specific interface write */
1027 	sc->sc_req.bmRequestType = UT_WRITE_CLASS_INTERFACE;
1028 	sc->sc_req.bRequest = UR_BBB_RESET;
1029 	USETW(sc->sc_req.wValue, 0);
1030 	USETW(sc->sc_req.wIndex, sc->sc_ifaceno);
1031 	USETW(sc->sc_req.wLength, 0);
1032 	umass_setup_ctrl_transfer(sc, &sc->sc_req, NULL, 0, 0,
1033 				  sc->transfer_xfer[XFER_BBB_RESET1]);
1034 }
1035 
1036 Static void
1037 umass_bbb_transfer(struct umass_softc *sc, int lun, void *cmd, int cmdlen,
1038 		   void *data, int datalen, int dir, u_int timeout,
1039 		   int flags, umass_callback cb, void *priv)
1040 {
1041 	static int dCBWtag = 42;	/* unique for CBW of transfer */
1042 
1043 	DPRINTF(UDMASS_BBB,("%s: umass_bbb_transfer cmd=0x%02x\n",
1044 		device_xname(sc->sc_dev), *(u_char *)cmd));
1045 
1046 	KASSERTMSG(sc->sc_wire & UMASS_WPROTO_BBB,
1047 		   "sc->sc_wire == 0x%02x wrong for umass_bbb_transfer\n",
1048 		   sc->sc_wire);
1049 
1050 	if (sc->sc_dying)
1051 		return;
1052 
1053 	/* Be a little generous. */
1054 	sc->timeout = timeout + USBD_DEFAULT_TIMEOUT;
1055 
1056 	/*
1057 	 * Do a Bulk-Only transfer with cmdlen bytes from cmd, possibly
1058 	 * a data phase of datalen bytes from/to the device and finally a
1059 	 * csw read phase.
1060 	 * If the data direction was inbound a maximum of datalen bytes
1061 	 * is stored in the buffer pointed to by data.
1062 	 *
1063 	 * umass_bbb_transfer initialises the transfer and lets the state
1064 	 * machine in umass_bbb_state handle the completion. It uses the
1065 	 * following states:
1066 	 * TSTATE_BBB_COMMAND
1067 	 *   -> TSTATE_BBB_DATA
1068 	 *   -> TSTATE_BBB_STATUS
1069 	 *   -> TSTATE_BBB_STATUS2
1070 	 *   -> TSTATE_BBB_IDLE
1071 	 *
1072 	 * An error in any of those states will invoke
1073 	 * umass_bbb_reset.
1074 	 */
1075 
1076 	/* check the given arguments */
1077 	KASSERTMSG(datalen == 0 || data != NULL,
1078 		   "%s: datalen > 0, but no buffer",device_xname(sc->sc_dev));
1079 	KASSERTMSG(cmdlen <= CBWCDBLENGTH,
1080 		   "%s: cmdlen exceeds CDB length in CBW (%d > %d)",
1081 			device_xname(sc->sc_dev), cmdlen, CBWCDBLENGTH);
1082 	KASSERTMSG(dir == DIR_NONE || datalen > 0,
1083 		   "%s: datalen == 0 while direction is not NONE\n",
1084 			device_xname(sc->sc_dev));
1085 	KASSERTMSG(datalen == 0 || dir != DIR_NONE,
1086 		   "%s: direction is NONE while datalen is not zero\n",
1087 			device_xname(sc->sc_dev));
1088 	/* CTASSERT */
1089 	KASSERTMSG(sizeof(umass_bbb_cbw_t) == UMASS_BBB_CBW_SIZE,
1090 		   "%s: CBW struct does not have the right size (%zu vs. %u)\n",
1091 			device_xname(sc->sc_dev),
1092 			sizeof(umass_bbb_cbw_t), UMASS_BBB_CBW_SIZE);
1093 	/* CTASSERT */
1094 	KASSERTMSG(sizeof(umass_bbb_csw_t) == UMASS_BBB_CSW_SIZE,
1095 		   "%s: CSW struct does not have the right size (%zu vs. %u)\n",
1096 			device_xname(sc->sc_dev),
1097 			sizeof(umass_bbb_csw_t), UMASS_BBB_CSW_SIZE);
1098 
1099 	/*
1100 	 * Determine the direction of the data transfer and the length.
1101 	 *
1102 	 * dCBWDataTransferLength (datalen) :
1103 	 *   This field indicates the number of bytes of data that the host
1104 	 *   intends to transfer on the IN or OUT Bulk endpoint(as indicated by
1105 	 *   the Direction bit) during the execution of this command. If this
1106 	 *   field is set to 0, the device will expect that no data will be
1107 	 *   transferred IN or OUT during this command, regardless of the value
1108 	 *   of the Direction bit defined in dCBWFlags.
1109 	 *
1110 	 * dCBWFlags (dir) :
1111 	 *   The bits of the Flags field are defined as follows:
1112 	 *     Bits 0-6	 reserved
1113 	 *     Bit  7	 Direction - this bit shall be ignored if the
1114 	 *			     dCBWDataTransferLength field is zero.
1115 	 *		 0 = data Out from host to device
1116 	 *		 1 = data In from device to host
1117 	 */
1118 
1119 	/* Fill in the Command Block Wrapper */
1120 	USETDW(sc->cbw.dCBWSignature, CBWSIGNATURE);
1121 	USETDW(sc->cbw.dCBWTag, dCBWtag);
1122 	dCBWtag++;	/* cannot be done in macro (it will be done 4 times) */
1123 	USETDW(sc->cbw.dCBWDataTransferLength, datalen);
1124 	/* DIR_NONE is treated as DIR_OUT (0x00) */
1125 	sc->cbw.bCBWFlags = (dir == DIR_IN? CBWFLAGS_IN:CBWFLAGS_OUT);
1126 	sc->cbw.bCBWLUN = lun;
1127 	sc->cbw.bCDBLength = cmdlen;
1128 	memcpy(sc->cbw.CBWCDB, cmd, cmdlen);
1129 
1130 	DIF(UDMASS_BBB, umass_bbb_dump_cbw(sc, &sc->cbw));
1131 
1132 	/* store the details for the data transfer phase */
1133 	sc->transfer_dir = dir;
1134 	sc->transfer_data = data;
1135 	sc->transfer_datalen = datalen;
1136 	sc->transfer_actlen = 0;
1137 	sc->transfer_cb = cb;
1138 	sc->transfer_priv = priv;
1139 	sc->transfer_status = STATUS_CMD_OK;
1140 
1141 	/* move from idle to the command state */
1142 	sc->transfer_state = TSTATE_BBB_COMMAND;
1143 
1144 	/* Send the CBW from host to device via bulk-out endpoint. */
1145 	if (umass_setup_transfer(sc, sc->sc_pipe[UMASS_BULKOUT],
1146 			&sc->cbw, UMASS_BBB_CBW_SIZE, flags,
1147 			sc->transfer_xfer[XFER_BBB_CBW])) {
1148 		umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1149 	}
1150 }
1151 
1152 
1153 Static void
1154 umass_bbb_state(struct usbd_xfer *xfer, void *priv,
1155 		usbd_status err)
1156 {
1157 	struct umass_softc *sc = (struct umass_softc *) priv;
1158 	struct usbd_xfer *next_xfer;
1159 	int residue;
1160 
1161 	USBHIST_FUNC(); USBHIST_CALLED(umassdebug);
1162 
1163 	KASSERTMSG(sc->sc_wire & UMASS_WPROTO_BBB,
1164 		   "sc->sc_wire == 0x%02x wrong for umass_bbb_state\n",
1165 		   sc->sc_wire);
1166 
1167 	if (sc->sc_dying)
1168 		return;
1169 
1170 	/*
1171 	 * State handling for BBB transfers.
1172 	 *
1173 	 * The subroutine is rather long. It steps through the states given in
1174 	 * Annex A of the Bulk-Only specification.
1175 	 * Each state first does the error handling of the previous transfer
1176 	 * and then prepares the next transfer.
1177 	 * Each transfer is done asynchroneously so after the request/transfer
1178 	 * has been submitted you will find a 'return;'.
1179 	 */
1180 
1181 	DPRINTF(UDMASS_BBB, ("%s: Handling BBB state %d (%s), xfer=%p, %s\n",
1182 		device_xname(sc->sc_dev), sc->transfer_state,
1183 		states[sc->transfer_state], xfer, usbd_errstr(err)));
1184 
1185 	USBHIST_LOG(umassdebug, "xfer %p, transfer_state %d dir %d", xfer,
1186 	    sc->transfer_state, sc->transfer_dir, 0);
1187 
1188 	switch (sc->transfer_state) {
1189 
1190 	/***** Bulk Transfer *****/
1191 	case TSTATE_BBB_COMMAND:
1192 		/* Command transport phase, error handling */
1193 		if (err) {
1194 			DPRINTF(UDMASS_BBB, ("%s: failed to send CBW\n",
1195 				device_xname(sc->sc_dev)));
1196 			/* If the device detects that the CBW is invalid, then
1197 			 * the device may STALL both bulk endpoints and require
1198 			 * a Bulk-Reset
1199 			 */
1200 			umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1201 			return;
1202 		}
1203 
1204 		/* Data transport phase, setup transfer */
1205 		sc->transfer_state = TSTATE_BBB_DATA;
1206 		if (sc->transfer_dir == DIR_IN) {
1207 			if (umass_setup_transfer(sc, sc->sc_pipe[UMASS_BULKIN],
1208 					sc->datain_buffer, sc->transfer_datalen,
1209 					USBD_SHORT_XFER_OK,
1210 					sc->transfer_xfer[XFER_BBB_DATAIN]))
1211 				umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1212 
1213 			return;
1214 		} else if (sc->transfer_dir == DIR_OUT) {
1215 			memcpy(sc->dataout_buffer, sc->transfer_data,
1216 			       sc->transfer_datalen);
1217 			if (umass_setup_transfer(sc, sc->sc_pipe[UMASS_BULKOUT],
1218 					sc->dataout_buffer, sc->transfer_datalen,
1219 					0,/* fixed length transfer */
1220 					sc->transfer_xfer[XFER_BBB_DATAOUT]))
1221 				umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1222 
1223 			return;
1224 		} else {
1225 			DPRINTF(UDMASS_BBB, ("%s: no data phase\n",
1226 				device_xname(sc->sc_dev)));
1227 		}
1228 
1229 		/* FALLTHROUGH if no data phase, err == 0 */
1230 	case TSTATE_BBB_DATA:
1231 		/* Command transport phase error handling (ignored if no data
1232 		 * phase (fallthrough from previous state)) */
1233 		if (sc->transfer_dir != DIR_NONE) {
1234 			/* retrieve the length of the transfer that was done */
1235 			usbd_get_xfer_status(xfer, NULL, NULL,
1236 			     &sc->transfer_actlen, NULL);
1237 			DPRINTF(UDMASS_BBB, ("%s: BBB_DATA actlen=%d\n",
1238 				device_xname(sc->sc_dev), sc->transfer_actlen));
1239 
1240 			if (err) {
1241 				DPRINTF(UDMASS_BBB, ("%s: Data-%s %d failed, "
1242 					"%s\n", device_xname(sc->sc_dev),
1243 					(sc->transfer_dir == DIR_IN?"in":"out"),
1244 					sc->transfer_datalen,usbd_errstr(err)));
1245 
1246 				if (err == USBD_STALLED) {
1247 					sc->transfer_state = TSTATE_BBB_DCLEAR;
1248 					umass_clear_endpoint_stall(sc,
1249 					  (sc->transfer_dir == DIR_IN?
1250 					    UMASS_BULKIN:UMASS_BULKOUT),
1251 					  sc->transfer_xfer[XFER_BBB_DCLEAR]);
1252 				} else {
1253 					/* Unless the error is a pipe stall the
1254 					 * error is fatal.
1255 					 */
1256 					umass_bbb_reset(sc,STATUS_WIRE_FAILED);
1257 				}
1258 				return;
1259 			}
1260 		}
1261 
1262 		/* FALLTHROUGH, err == 0 (no data phase or successful) */
1263 	case TSTATE_BBB_DCLEAR: /* stall clear after data phase */
1264 		if (sc->transfer_dir == DIR_IN)
1265 			memcpy(sc->transfer_data, sc->datain_buffer,
1266 			       sc->transfer_actlen);
1267 
1268 		DIF(UDMASS_BBB, if (sc->transfer_dir == DIR_IN)
1269 					umass_dump_buffer(sc, sc->transfer_data,
1270 						sc->transfer_datalen, 48));
1271 
1272 		/* FALLTHROUGH, err == 0 (no data phase or successful) */
1273 	case TSTATE_BBB_SCLEAR: /* stall clear after status phase */
1274 		/* Reading of CSW after bulk stall condition in data phase
1275 		 * (TSTATE_BBB_DATA2) or bulk-in stall condition after
1276 		 * reading CSW (TSTATE_BBB_SCLEAR).
1277 		 * In the case of no data phase or successful data phase,
1278 		 * err == 0 and the following if block is passed.
1279 		 */
1280 		if (err) {	/* should not occur */
1281 			printf("%s: BBB bulk-%s stall clear failed, %s\n",
1282 			    device_xname(sc->sc_dev),
1283 			    (sc->transfer_dir == DIR_IN? "in":"out"),
1284 			    usbd_errstr(err));
1285 			umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1286 			return;
1287 		}
1288 
1289 		/* Status transport phase, setup transfer */
1290 		if (sc->transfer_state == TSTATE_BBB_COMMAND ||
1291 		    sc->transfer_state == TSTATE_BBB_DATA ||
1292 		    sc->transfer_state == TSTATE_BBB_DCLEAR) {
1293 			/* After no data phase, successful data phase and
1294 			 * after clearing bulk-in/-out stall condition
1295 			 */
1296 			sc->transfer_state = TSTATE_BBB_STATUS1;
1297 			next_xfer = sc->transfer_xfer[XFER_BBB_CSW1];
1298 		} else {
1299 			/* After first attempt of fetching CSW */
1300 			sc->transfer_state = TSTATE_BBB_STATUS2;
1301 			next_xfer = sc->transfer_xfer[XFER_BBB_CSW2];
1302 		}
1303 
1304 		/* Read the Command Status Wrapper via bulk-in endpoint. */
1305 		if (umass_setup_transfer(sc, sc->sc_pipe[UMASS_BULKIN],
1306 			&sc->csw, UMASS_BBB_CSW_SIZE, 0, next_xfer)) {
1307 			umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1308 			return;
1309 		}
1310 
1311 		return;
1312 	case TSTATE_BBB_STATUS1:	/* first attempt */
1313 	case TSTATE_BBB_STATUS2:	/* second attempt */
1314 		/* Status transfer, error handling */
1315 		if (err) {
1316 			DPRINTF(UDMASS_BBB, ("%s: Failed to read CSW, %s%s\n",
1317 				device_xname(sc->sc_dev), usbd_errstr(err),
1318 				(sc->transfer_state == TSTATE_BBB_STATUS1?
1319 					", retrying":"")));
1320 
1321 			/* If this was the first attempt at fetching the CSW
1322 			 * retry it, otherwise fail.
1323 			 */
1324 			if (sc->transfer_state == TSTATE_BBB_STATUS1) {
1325 				sc->transfer_state = TSTATE_BBB_SCLEAR;
1326 				umass_clear_endpoint_stall(sc, UMASS_BULKIN,
1327 				    sc->transfer_xfer[XFER_BBB_SCLEAR]);
1328 				return;
1329 			} else {
1330 				umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1331 				return;
1332 			}
1333 		}
1334 
1335 		DIF(UDMASS_BBB, umass_bbb_dump_csw(sc, &sc->csw));
1336 
1337 #ifdef UMASS_DEBUG
1338 		residue = UGETDW(sc->csw.dCSWDataResidue);
1339 		if (residue != sc->transfer_datalen - sc->transfer_actlen)
1340 			printf("%s: dCSWDataResidue=%d req=%d act=%d\n",
1341 			       device_xname(sc->sc_dev), residue,
1342 			       sc->transfer_datalen, sc->transfer_actlen);
1343 #endif
1344 		residue = sc->transfer_datalen - sc->transfer_actlen;
1345 
1346 		/* Translate weird command-status signatures. */
1347 		if ((sc->sc_quirks & UMASS_QUIRK_WRONG_CSWSIG) &&
1348 		    UGETDW(sc->csw.dCSWSignature) == CSWSIGNATURE_OLYMPUS_C1)
1349 			USETDW(sc->csw.dCSWSignature, CSWSIGNATURE);
1350 
1351 		/* Translate invalid command-status tags */
1352 		if (sc->sc_quirks & UMASS_QUIRK_WRONG_CSWTAG)
1353 			USETDW(sc->csw.dCSWTag, UGETDW(sc->cbw.dCBWTag));
1354 
1355 		/* Check CSW and handle any error */
1356 		if (UGETDW(sc->csw.dCSWSignature) != CSWSIGNATURE) {
1357 			/* Invalid CSW: Wrong signature or wrong tag might
1358 			 * indicate that the device is confused -> reset it.
1359 			 */
1360 			printf("%s: Invalid CSW: sig 0x%08x should be 0x%08x\n",
1361 				device_xname(sc->sc_dev),
1362 				UGETDW(sc->csw.dCSWSignature),
1363 				CSWSIGNATURE);
1364 
1365 			umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1366 			return;
1367 		} else if (UGETDW(sc->csw.dCSWTag)
1368 				!= UGETDW(sc->cbw.dCBWTag)) {
1369 			printf("%s: Invalid CSW: tag %d should be %d\n",
1370 				device_xname(sc->sc_dev),
1371 				UGETDW(sc->csw.dCSWTag),
1372 				UGETDW(sc->cbw.dCBWTag));
1373 
1374 			umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1375 			return;
1376 
1377 		/* CSW is valid here */
1378 		} else if (sc->csw.bCSWStatus > CSWSTATUS_PHASE) {
1379 			printf("%s: Invalid CSW: status %d > %d\n",
1380 				device_xname(sc->sc_dev),
1381 				sc->csw.bCSWStatus,
1382 				CSWSTATUS_PHASE);
1383 
1384 			umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1385 			return;
1386 		} else if (sc->csw.bCSWStatus == CSWSTATUS_PHASE) {
1387 			printf("%s: Phase Error, residue = %d\n",
1388 				device_xname(sc->sc_dev), residue);
1389 
1390 			umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1391 			return;
1392 
1393 		} else if (sc->transfer_actlen > sc->transfer_datalen) {
1394 			/* Buffer overrun! Don't let this go by unnoticed */
1395 			panic("%s: transferred %s %d bytes instead of %d bytes",
1396 			    device_xname(sc->sc_dev),
1397 			    sc->transfer_dir == DIR_IN ? "IN" : "OUT",
1398 			    sc->transfer_actlen, sc->transfer_datalen);
1399 #if 0
1400 		} else if (sc->transfer_datalen - sc->transfer_actlen
1401 			   != residue) {
1402 			DPRINTF(UDMASS_BBB, ("%s: actlen=%d != residue=%d\n",
1403 				device_xname(sc->sc_dev),
1404 				sc->transfer_datalen - sc->transfer_actlen,
1405 				residue));
1406 
1407 			umass_bbb_reset(sc, STATUS_WIRE_FAILED);
1408 			return;
1409 #endif
1410 		} else if (sc->csw.bCSWStatus == CSWSTATUS_FAILED) {
1411 			DPRINTF(UDMASS_BBB, ("%s: Command Failed, res = %d\n",
1412 				device_xname(sc->sc_dev), residue));
1413 
1414 			/* SCSI command failed but transfer was succesful */
1415 			sc->transfer_state = TSTATE_IDLE;
1416 			sc->transfer_cb(sc, sc->transfer_priv, residue,
1417 					STATUS_CMD_FAILED);
1418 
1419 			return;
1420 
1421 		} else {	/* success */
1422 			sc->transfer_state = TSTATE_IDLE;
1423 			sc->transfer_cb(sc, sc->transfer_priv, residue,
1424 					STATUS_CMD_OK);
1425 
1426 			return;
1427 		}
1428 
1429 	/***** Bulk Reset *****/
1430 	case TSTATE_BBB_RESET1:
1431 		if (err)
1432 			printf("%s: BBB reset failed, %s\n",
1433 				device_xname(sc->sc_dev), usbd_errstr(err));
1434 
1435 		sc->transfer_state = TSTATE_BBB_RESET2;
1436 		umass_clear_endpoint_stall(sc, UMASS_BULKIN,
1437 			sc->transfer_xfer[XFER_BBB_RESET2]);
1438 
1439 		return;
1440 	case TSTATE_BBB_RESET2:
1441 		if (err)	/* should not occur */
1442 			printf("%s: BBB bulk-in clear stall failed, %s\n",
1443 			       device_xname(sc->sc_dev), usbd_errstr(err));
1444 			/* no error recovery, otherwise we end up in a loop */
1445 
1446 		sc->transfer_state = TSTATE_BBB_RESET3;
1447 		umass_clear_endpoint_stall(sc, UMASS_BULKOUT,
1448 			sc->transfer_xfer[XFER_BBB_RESET3]);
1449 
1450 		return;
1451 	case TSTATE_BBB_RESET3:
1452 		if (err)	/* should not occur */
1453 			printf("%s: BBB bulk-out clear stall failed, %s\n",
1454 			       device_xname(sc->sc_dev), usbd_errstr(err));
1455 			/* no error recovery, otherwise we end up in a loop */
1456 
1457 		sc->transfer_state = TSTATE_IDLE;
1458 		if (sc->transfer_priv) {
1459 			sc->transfer_cb(sc, sc->transfer_priv,
1460 					sc->transfer_datalen,
1461 					sc->transfer_status);
1462 		}
1463 
1464 		return;
1465 
1466 	/***** Default *****/
1467 	default:
1468 		panic("%s: Unknown state %d",
1469 		      device_xname(sc->sc_dev), sc->transfer_state);
1470 	}
1471 }
1472 
1473 /*
1474  * Command/Bulk/Interrupt (CBI) specific functions
1475  */
1476 
1477 Static int
1478 umass_cbi_adsc(struct umass_softc *sc, char *buffer, int buflen, int flags,
1479 	       struct usbd_xfer *xfer)
1480 {
1481 	KASSERTMSG(sc->sc_wire & (UMASS_WPROTO_CBI|UMASS_WPROTO_CBI_I),
1482 		   "sc->sc_wire == 0x%02x wrong for umass_cbi_adsc\n",
1483 		   sc->sc_wire);
1484 
1485 	if ((sc->sc_cmd == UMASS_CPROTO_RBC) &&
1486 	    (sc->sc_quirks & UMASS_QUIRK_RBC_PAD_TO_12) != 0 && buflen < 12) {
1487 		(void)memset(buffer + buflen, 0, 12 - buflen);
1488 		buflen = 12;
1489 	}
1490 
1491 	sc->sc_req.bmRequestType = UT_WRITE_CLASS_INTERFACE;
1492 	sc->sc_req.bRequest = UR_CBI_ADSC;
1493 	USETW(sc->sc_req.wValue, 0);
1494 	USETW(sc->sc_req.wIndex, sc->sc_ifaceno);
1495 	USETW(sc->sc_req.wLength, buflen);
1496 	return umass_setup_ctrl_transfer(sc, &sc->sc_req, buffer,
1497 					 buflen, flags, xfer);
1498 }
1499 
1500 
1501 Static void
1502 umass_cbi_reset(struct umass_softc *sc, int status)
1503 {
1504 	int i;
1505 #	define SEND_DIAGNOSTIC_CMDLEN	12
1506 
1507 	KASSERTMSG(sc->sc_wire & (UMASS_WPROTO_CBI|UMASS_WPROTO_CBI_I),
1508 		   "sc->sc_wire == 0x%02x wrong for umass_cbi_reset\n",
1509 		   sc->sc_wire);
1510 
1511 	if (sc->sc_dying)
1512 		return;
1513 
1514 	/*
1515 	 * Command Block Reset Protocol
1516 	 *
1517 	 * First send a reset request to the device. Then clear
1518 	 * any possibly stalled bulk endpoints.
1519 
1520 	 * This is done in 3 steps, states:
1521 	 * TSTATE_CBI_RESET1
1522 	 * TSTATE_CBI_RESET2
1523 	 * TSTATE_CBI_RESET3
1524 	 *
1525 	 * If the reset doesn't succeed, the device should be port reset.
1526 	 */
1527 
1528 	DPRINTF(UDMASS_CBI, ("%s: CBI Reset\n",
1529 		device_xname(sc->sc_dev)));
1530 
1531 	/* CTASSERT */
1532 	KASSERTMSG(sizeof(sc->cbl) >= SEND_DIAGNOSTIC_CMDLEN,
1533 		   "%s: CBL struct is too small (%zu < %u)\n",
1534 			device_xname(sc->sc_dev),
1535 			sizeof(sc->cbl), SEND_DIAGNOSTIC_CMDLEN);
1536 
1537 	sc->transfer_state = TSTATE_CBI_RESET1;
1538 	sc->transfer_status = status;
1539 
1540 	/* The 0x1d code is the SEND DIAGNOSTIC command. To distingiush between
1541 	 * the two the last 10 bytes of the cbl is filled with 0xff (section
1542 	 * 2.2 of the CBI spec).
1543 	 */
1544 	sc->cbl[0] = 0x1d;	/* Command Block Reset */
1545 	sc->cbl[1] = 0x04;
1546 	for (i = 2; i < SEND_DIAGNOSTIC_CMDLEN; i++)
1547 		sc->cbl[i] = 0xff;
1548 
1549 	umass_cbi_adsc(sc, sc->cbl, SEND_DIAGNOSTIC_CMDLEN, 0,
1550 		       sc->transfer_xfer[XFER_CBI_RESET1]);
1551 	/* XXX if the command fails we should reset the port on the bub */
1552 }
1553 
1554 Static void
1555 umass_cbi_transfer(struct umass_softc *sc, int lun,
1556 		   void *cmd, int cmdlen, void *data, int datalen, int dir,
1557 		   u_int timeout, int flags, umass_callback cb, void *priv)
1558 {
1559 	DPRINTF(UDMASS_CBI,("%s: umass_cbi_transfer cmd=0x%02x, len=%d\n",
1560 		device_xname(sc->sc_dev), *(u_char *)cmd, datalen));
1561 
1562 	KASSERTMSG(sc->sc_wire & (UMASS_WPROTO_CBI|UMASS_WPROTO_CBI_I),
1563 		   "sc->sc_wire == 0x%02x wrong for umass_cbi_transfer\n",
1564 		   sc->sc_wire);
1565 
1566 	if (sc->sc_dying)
1567 		return;
1568 
1569 	/* Be a little generous. */
1570 	sc->timeout = timeout + USBD_DEFAULT_TIMEOUT;
1571 
1572 	/*
1573 	 * Do a CBI transfer with cmdlen bytes from cmd, possibly
1574 	 * a data phase of datalen bytes from/to the device and finally a
1575 	 * csw read phase.
1576 	 * If the data direction was inbound a maximum of datalen bytes
1577 	 * is stored in the buffer pointed to by data.
1578 	 *
1579 	 * umass_cbi_transfer initialises the transfer and lets the state
1580 	 * machine in umass_cbi_state handle the completion. It uses the
1581 	 * following states:
1582 	 * TSTATE_CBI_COMMAND
1583 	 *   -> XXX fill in
1584 	 *
1585 	 * An error in any of those states will invoke
1586 	 * umass_cbi_reset.
1587 	 */
1588 
1589 	/* check the given arguments */
1590 	KASSERTMSG(datalen == 0 || data != NULL,
1591 		   "%s: datalen > 0, but no buffer",device_xname(sc->sc_dev));
1592 	KASSERTMSG(datalen == 0 || dir != DIR_NONE,
1593 		   "%s: direction is NONE while datalen is not zero\n",
1594 			device_xname(sc->sc_dev));
1595 
1596 	/* store the details for the data transfer phase */
1597 	sc->transfer_dir = dir;
1598 	sc->transfer_data = data;
1599 	sc->transfer_datalen = datalen;
1600 	sc->transfer_actlen = 0;
1601 	sc->transfer_cb = cb;
1602 	sc->transfer_priv = priv;
1603 	sc->transfer_status = STATUS_CMD_OK;
1604 
1605 	/* move from idle to the command state */
1606 	sc->transfer_state = TSTATE_CBI_COMMAND;
1607 
1608 	/* Send the Command Block from host to device via control endpoint. */
1609 	if (umass_cbi_adsc(sc, cmd, cmdlen, flags, sc->transfer_xfer[XFER_CBI_CB]))
1610 		umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1611 }
1612 
1613 Static void
1614 umass_cbi_state(struct usbd_xfer *xfer, void *priv,
1615 		usbd_status err)
1616 {
1617 	struct umass_softc *sc = (struct umass_softc *) priv;
1618 
1619 	KASSERTMSG(sc->sc_wire & (UMASS_WPROTO_CBI|UMASS_WPROTO_CBI_I),
1620 		   "sc->sc_wire == 0x%02x wrong for umass_cbi_state\n",
1621 		   sc->sc_wire);
1622 
1623 	if (sc->sc_dying)
1624 		return;
1625 
1626 	/*
1627 	 * State handling for CBI transfers.
1628 	 */
1629 
1630 	DPRINTF(UDMASS_CBI, ("%s: Handling CBI state %d (%s), xfer=%p, %s\n",
1631 		device_xname(sc->sc_dev), sc->transfer_state,
1632 		states[sc->transfer_state], xfer, usbd_errstr(err)));
1633 
1634 	switch (sc->transfer_state) {
1635 
1636 	/***** CBI Transfer *****/
1637 	case TSTATE_CBI_COMMAND:
1638 		if (err == USBD_STALLED) {
1639 			DPRINTF(UDMASS_CBI, ("%s: Command Transport failed\n",
1640 				device_xname(sc->sc_dev)));
1641 			/* Status transport by control pipe (section 2.3.2.1).
1642 			 * The command contained in the command block failed.
1643 			 *
1644 			 * The control pipe has already been unstalled by the
1645 			 * USB stack.
1646 			 * Section 2.4.3.1.1 states that the bulk in endpoints
1647 			 * should not stalled at this point.
1648 			 */
1649 
1650 			sc->transfer_state = TSTATE_IDLE;
1651 			sc->transfer_cb(sc, sc->transfer_priv,
1652 					sc->transfer_datalen,
1653 					STATUS_CMD_FAILED);
1654 
1655 			return;
1656 		} else if (err) {
1657 			DPRINTF(UDMASS_CBI, ("%s: failed to send ADSC\n",
1658 				device_xname(sc->sc_dev)));
1659 			umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1660 			return;
1661 		}
1662 
1663 		/* Data transport phase, setup transfer */
1664 		sc->transfer_state = TSTATE_CBI_DATA;
1665 		if (sc->transfer_dir == DIR_IN) {
1666 			if (umass_setup_transfer(sc, sc->sc_pipe[UMASS_BULKIN],
1667 			    sc->datain_buffer, sc->transfer_datalen,
1668 			    USBD_SHORT_XFER_OK,
1669 			    sc->transfer_xfer[XFER_CBI_DATAIN]))
1670 				umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1671 
1672 			return;
1673 		} else if (sc->transfer_dir == DIR_OUT) {
1674 			memcpy(sc->dataout_buffer, sc->transfer_data,
1675 			       sc->transfer_datalen);
1676 			if (umass_setup_transfer(sc, sc->sc_pipe[UMASS_BULKOUT],
1677 			    sc->dataout_buffer, sc->transfer_datalen,
1678 			    0, /* fixed length transfer */
1679 			    sc->transfer_xfer[XFER_CBI_DATAOUT]))
1680 				umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1681 
1682 			return;
1683 		} else {
1684 			DPRINTF(UDMASS_CBI, ("%s: no data phase\n",
1685 				device_xname(sc->sc_dev)));
1686 		}
1687 
1688 		/* FALLTHROUGH if no data phase, err == 0 */
1689 	case TSTATE_CBI_DATA:
1690 		/* Command transport phase error handling (ignored if no data
1691 		 * phase (fallthrough from previous state)) */
1692 		if (sc->transfer_dir != DIR_NONE) {
1693 			/* retrieve the length of the transfer that was done */
1694 			usbd_get_xfer_status(xfer, NULL, NULL,
1695 			    &sc->transfer_actlen, NULL);
1696 			DPRINTF(UDMASS_CBI, ("%s: CBI_DATA actlen=%d\n",
1697 				device_xname(sc->sc_dev), sc->transfer_actlen));
1698 
1699 			if (err) {
1700 				DPRINTF(UDMASS_CBI, ("%s: Data-%s %d failed, "
1701 					"%s\n", device_xname(sc->sc_dev),
1702 					(sc->transfer_dir == DIR_IN?"in":"out"),
1703 					sc->transfer_datalen,usbd_errstr(err)));
1704 
1705 				if (err == USBD_STALLED) {
1706 					sc->transfer_state = TSTATE_CBI_DCLEAR;
1707 					umass_clear_endpoint_stall(sc,
1708 					  (sc->transfer_dir == DIR_IN?
1709 					    UMASS_BULKIN:UMASS_BULKOUT),
1710 					sc->transfer_xfer[XFER_CBI_DCLEAR]);
1711 				} else {
1712 					/* Unless the error is a pipe stall the
1713 					 * error is fatal.
1714 					 */
1715 					umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1716 				}
1717 				return;
1718 			}
1719 		}
1720 
1721 		if (sc->transfer_dir == DIR_IN)
1722 			memcpy(sc->transfer_data, sc->datain_buffer,
1723 			       sc->transfer_actlen);
1724 
1725 		DIF(UDMASS_CBI, if (sc->transfer_dir == DIR_IN)
1726 					umass_dump_buffer(sc, sc->transfer_data,
1727 						sc->transfer_actlen, 48));
1728 
1729 		/* Status phase */
1730 		if (sc->sc_wire == UMASS_WPROTO_CBI_I) {
1731 			sc->transfer_state = TSTATE_CBI_STATUS;
1732 			memset(&sc->sbl, 0, sizeof(sc->sbl));
1733 			if (umass_setup_transfer(sc, sc->sc_pipe[UMASS_INTRIN],
1734 				    &sc->sbl, sizeof(sc->sbl),
1735 				    0,	/* fixed length transfer */
1736 				    sc->transfer_xfer[XFER_CBI_STATUS]))
1737 				umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1738 		} else {
1739 			/* No command completion interrupt. Request
1740 			 * sense to get status of command.
1741 			 */
1742 			sc->transfer_state = TSTATE_IDLE;
1743 			sc->transfer_cb(sc, sc->transfer_priv,
1744 				sc->transfer_datalen - sc->transfer_actlen,
1745 				STATUS_CMD_UNKNOWN);
1746 		}
1747 		return;
1748 
1749 	case TSTATE_CBI_STATUS:
1750 		if (err) {
1751 			DPRINTF(UDMASS_CBI, ("%s: Status Transport failed\n",
1752 				device_xname(sc->sc_dev)));
1753 			/* Status transport by interrupt pipe (section 2.3.2.2).
1754 			 */
1755 
1756 			if (err == USBD_STALLED) {
1757 				sc->transfer_state = TSTATE_CBI_SCLEAR;
1758 				umass_clear_endpoint_stall(sc, UMASS_INTRIN,
1759 					sc->transfer_xfer[XFER_CBI_SCLEAR]);
1760 			} else {
1761 				umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1762 			}
1763 			return;
1764 		}
1765 
1766 		/* Dissect the information in the buffer */
1767 
1768 		{
1769 			uint32_t actlen;
1770 			usbd_get_xfer_status(xfer,NULL,NULL,&actlen,NULL);
1771 			DPRINTF(UDMASS_CBI, ("%s: CBI_STATUS actlen=%d\n",
1772 				device_xname(sc->sc_dev), actlen));
1773 			if (actlen != 2)
1774 				break;
1775 		}
1776 
1777 		if (sc->sc_cmd == UMASS_CPROTO_UFI) {
1778 			int status;
1779 
1780 			/* Section 3.4.3.1.3 specifies that the UFI command
1781 			 * protocol returns an ASC and ASCQ in the interrupt
1782 			 * data block.
1783 			 */
1784 
1785 			DPRINTF(UDMASS_CBI, ("%s: UFI CCI, ASC = 0x%02x, "
1786 				"ASCQ = 0x%02x\n",
1787 				device_xname(sc->sc_dev),
1788 				sc->sbl.ufi.asc, sc->sbl.ufi.ascq));
1789 
1790 			if ((sc->sbl.ufi.asc == 0 && sc->sbl.ufi.ascq == 0) ||
1791 			    sc->sc_sense)
1792 				status = STATUS_CMD_OK;
1793 			else
1794 				status = STATUS_CMD_FAILED;
1795 
1796 			/* No autosense, command successful */
1797 			sc->transfer_state = TSTATE_IDLE;
1798 			sc->transfer_cb(sc, sc->transfer_priv,
1799 			    sc->transfer_datalen - sc->transfer_actlen, status);
1800 		} else {
1801 			int status;
1802 
1803 			/* Command Interrupt Data Block */
1804 
1805 			DPRINTF(UDMASS_CBI, ("%s: type=0x%02x, value=0x%02x\n",
1806 				device_xname(sc->sc_dev),
1807 				sc->sbl.common.type, sc->sbl.common.value));
1808 
1809 			if (sc->sbl.common.type == IDB_TYPE_CCI) {
1810 				switch (sc->sbl.common.value & IDB_VALUE_STATUS_MASK) {
1811 				case IDB_VALUE_PASS:
1812 					status = STATUS_CMD_OK;
1813 					break;
1814 				case IDB_VALUE_FAIL:
1815 				case IDB_VALUE_PERSISTENT:
1816 					status = STATUS_CMD_FAILED;
1817 					break;
1818 				case IDB_VALUE_PHASE:
1819 				default: /* XXX: gcc */
1820 					status = STATUS_WIRE_FAILED;
1821 					break;
1822 				}
1823 
1824 				sc->transfer_state = TSTATE_IDLE;
1825 				sc->transfer_cb(sc, sc->transfer_priv,
1826 				    sc->transfer_datalen - sc->transfer_actlen, status);
1827 			}
1828 		}
1829 		return;
1830 
1831 	case TSTATE_CBI_DCLEAR:
1832 		if (err) {	/* should not occur */
1833 			printf("%s: CBI bulk-%s stall clear failed, %s\n",
1834 			    device_xname(sc->sc_dev),
1835 			    (sc->transfer_dir == DIR_IN? "in":"out"),
1836 			    usbd_errstr(err));
1837 			umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1838 		} else {
1839 			sc->transfer_state = TSTATE_IDLE;
1840 			sc->transfer_cb(sc, sc->transfer_priv,
1841 			    sc->transfer_datalen, STATUS_CMD_FAILED);
1842 		}
1843 		return;
1844 
1845 	case TSTATE_CBI_SCLEAR:
1846 		if (err) {	/* should not occur */
1847 			printf("%s: CBI intr-in stall clear failed, %s\n",
1848 			       device_xname(sc->sc_dev), usbd_errstr(err));
1849 			umass_cbi_reset(sc, STATUS_WIRE_FAILED);
1850 		} else {
1851 			sc->transfer_state = TSTATE_IDLE;
1852 			sc->transfer_cb(sc, sc->transfer_priv,
1853 			    sc->transfer_datalen, STATUS_CMD_FAILED);
1854 		}
1855 		return;
1856 
1857 	/***** CBI Reset *****/
1858 	case TSTATE_CBI_RESET1:
1859 		if (err)
1860 			printf("%s: CBI reset failed, %s\n",
1861 				device_xname(sc->sc_dev), usbd_errstr(err));
1862 
1863 		sc->transfer_state = TSTATE_CBI_RESET2;
1864 		umass_clear_endpoint_stall(sc, UMASS_BULKIN,
1865 			sc->transfer_xfer[XFER_CBI_RESET2]);
1866 
1867 		return;
1868 	case TSTATE_CBI_RESET2:
1869 		if (err)	/* should not occur */
1870 			printf("%s: CBI bulk-in stall clear failed, %s\n",
1871 			       device_xname(sc->sc_dev), usbd_errstr(err));
1872 			/* no error recovery, otherwise we end up in a loop */
1873 
1874 		sc->transfer_state = TSTATE_CBI_RESET3;
1875 		umass_clear_endpoint_stall(sc, UMASS_BULKOUT,
1876 			sc->transfer_xfer[XFER_CBI_RESET3]);
1877 
1878 		return;
1879 	case TSTATE_CBI_RESET3:
1880 		if (err)	/* should not occur */
1881 			printf("%s: CBI bulk-out stall clear failed, %s\n",
1882 			       device_xname(sc->sc_dev), usbd_errstr(err));
1883 			/* no error recovery, otherwise we end up in a loop */
1884 
1885 		sc->transfer_state = TSTATE_IDLE;
1886 		if (sc->transfer_priv) {
1887 			sc->transfer_cb(sc, sc->transfer_priv,
1888 					sc->transfer_datalen,
1889 					sc->transfer_status);
1890 		}
1891 
1892 		return;
1893 
1894 
1895 	/***** Default *****/
1896 	default:
1897 		panic("%s: Unknown state %d",
1898 		      device_xname(sc->sc_dev), sc->transfer_state);
1899 	}
1900 }
1901 
1902 usbd_status
1903 umass_bbb_get_max_lun(struct umass_softc *sc, uint8_t *maxlun)
1904 {
1905 	usb_device_request_t req;
1906 	usbd_status err;
1907 
1908 	*maxlun = 0;		/* Default to 0. */
1909 
1910 	DPRINTF(UDMASS_BBB, ("%s: Get Max Lun\n", device_xname(sc->sc_dev)));
1911 
1912 	/* The Get Max Lun command is a class-specific request. */
1913 	req.bmRequestType = UT_READ_CLASS_INTERFACE;
1914 	req.bRequest = UR_BBB_GET_MAX_LUN;
1915 	USETW(req.wValue, 0);
1916 	USETW(req.wIndex, sc->sc_ifaceno);
1917 	USETW(req.wLength, 1);
1918 
1919 	err = usbd_do_request_flags(sc->sc_udev, &req, maxlun,
1920 	    USBD_SHORT_XFER_OK, 0, USBD_DEFAULT_TIMEOUT);
1921 	switch (err) {
1922 	case USBD_NORMAL_COMPLETION:
1923 		DPRINTF(UDMASS_BBB, ("%s: Max Lun %d\n",
1924 		    device_xname(sc->sc_dev), *maxlun));
1925 		break;
1926 
1927 	case USBD_STALLED:
1928 		/*
1929 		 * Device doesn't support Get Max Lun request.
1930 		 */
1931 		err = USBD_NORMAL_COMPLETION;
1932 		DPRINTF(UDMASS_BBB, ("%s: Get Max Lun not supported\n",
1933 		    device_xname(sc->sc_dev)));
1934 		break;
1935 
1936 	case USBD_SHORT_XFER:
1937 		/*
1938 		 * XXX This must mean Get Max Lun is not supported, too!
1939 		 */
1940 		err = USBD_NORMAL_COMPLETION;
1941 		DPRINTF(UDMASS_BBB, ("%s: Get Max Lun SHORT_XFER\n",
1942 		    device_xname(sc->sc_dev)));
1943 		break;
1944 
1945 	default:
1946 		printf("%s: Get Max Lun failed: %s\n",
1947 		    device_xname(sc->sc_dev), usbd_errstr(err));
1948 		/* XXX Should we port_reset the device? */
1949 		break;
1950 	}
1951 
1952 	return err;
1953 }
1954 
1955 
1956 
1957 
1958 #ifdef UMASS_DEBUG
1959 Static void
1960 umass_bbb_dump_cbw(struct umass_softc *sc, umass_bbb_cbw_t *cbw)
1961 {
1962 	int clen = cbw->bCDBLength;
1963 	int dlen = UGETDW(cbw->dCBWDataTransferLength);
1964 	uint8_t *c = cbw->CBWCDB;
1965 	int tag = UGETDW(cbw->dCBWTag);
1966 	int flags = cbw->bCBWFlags;
1967 
1968 	DPRINTF(UDMASS_BBB, ("%s: CBW %d: cmdlen=%d "
1969 		"(0x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%s), "
1970 		"data = %d bytes, dir = %s\n",
1971 		device_xname(sc->sc_dev), tag, clen,
1972 		c[0], c[1], c[2], c[3], c[4], c[5],
1973 		c[6], c[7], c[8], c[9],
1974 		(clen > 10? "...":""),
1975 		dlen, (flags == CBWFLAGS_IN? "in":
1976 		       (flags == CBWFLAGS_OUT? "out":"<invalid>"))));
1977 }
1978 
1979 Static void
1980 umass_bbb_dump_csw(struct umass_softc *sc, umass_bbb_csw_t *csw)
1981 {
1982 	int sig = UGETDW(csw->dCSWSignature);
1983 	int tag = UGETDW(csw->dCSWTag);
1984 	int res = UGETDW(csw->dCSWDataResidue);
1985 	int status = csw->bCSWStatus;
1986 
1987 	DPRINTF(UDMASS_BBB, ("%s: CSW %d: sig = 0x%08x (%s), tag = %d, "
1988 		"res = %d, status = 0x%02x (%s)\n", device_xname(sc->sc_dev),
1989 		tag, sig, (sig == CSWSIGNATURE?	 "valid":"invalid"),
1990 		tag, res,
1991 		status, (status == CSWSTATUS_GOOD? "good":
1992 			 (status == CSWSTATUS_FAILED? "failed":
1993 			  (status == CSWSTATUS_PHASE? "phase":"<invalid>")))));
1994 }
1995 
1996 Static void
1997 umass_dump_buffer(struct umass_softc *sc, uint8_t *buffer, int buflen,
1998 		  int printlen)
1999 {
2000 	int i, j;
2001 	char s1[40];
2002 	char s2[40];
2003 	char s3[5];
2004 
2005 	s1[0] = '\0';
2006 	s3[0] = '\0';
2007 
2008 	snprintf(s2, sizeof(s2), " buffer=%p, buflen=%d", buffer, buflen);
2009 	for (i = 0; i < buflen && i < printlen; i++) {
2010 		j = i % 16;
2011 		if (j == 0 && i != 0) {
2012 			DPRINTF(UDMASS_GEN, ("%s: 0x %s%s\n",
2013 				device_xname(sc->sc_dev), s1, s2));
2014 			s2[0] = '\0';
2015 		}
2016 		snprintf(&s1[j * 2], sizeof(s1) - j * 2, "%02x",
2017 		    buffer[i] & 0xff);
2018 	}
2019 	if (buflen > printlen)
2020 		snprintf(s3, sizeof(s3), " ...");
2021 	DPRINTF(UDMASS_GEN, ("%s: 0x %s%s%s\n",
2022 		device_xname(sc->sc_dev), s1, s2, s3));
2023 }
2024 #endif
2025