ub.c 54 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215
  1. /*
  2. * The low performance USB storage driver (ub).
  3. *
  4. * Copyright (c) 1999, 2000 Matthew Dharm (mdharm-usb@one-eyed-alien.net)
  5. * Copyright (C) 2004 Pete Zaitcev (zaitcev@yahoo.com)
  6. *
  7. * This work is a part of Linux kernel, is derived from it,
  8. * and is not licensed separately. See file COPYING for details.
  9. *
  10. * TODO (sorted by decreasing priority)
  11. * -- Do resets with usb_device_reset (needs a thread context, use khubd)
  12. * -- set readonly flag for CDs, set removable flag for CF readers
  13. * -- do inquiry and verify we got a disk and not a tape (for LUN mismatch)
  14. * -- support pphaneuf's SDDR-75 with two LUNs (also broken capacity...)
  15. * -- special case some senses, e.g. 3a/0 -> no media present, reduce retries
  16. * -- verify the 13 conditions and do bulk resets
  17. * -- normal pool of commands instead of cmdv[]?
  18. * -- kill last_pipe and simply do two-state clearing on both pipes
  19. * -- verify protocol (bulk) from USB descriptors (maybe...)
  20. * -- highmem and sg
  21. * -- move top_sense and work_bcs into separate allocations (if they survive)
  22. * for cache purists and esoteric architectures.
  23. * -- prune comments, they are too volumnous
  24. * -- Exterminate P3 printks
  25. * -- Resove XXX's
  26. * -- Redo "benh's retries", perhaps have spin-up code to handle them. V:D=?
  27. */
  28. #include <linux/kernel.h>
  29. #include <linux/module.h>
  30. #include <linux/usb.h>
  31. #include <linux/blkdev.h>
  32. #include <linux/devfs_fs_kernel.h>
  33. #include <linux/timer.h>
  34. #include <scsi/scsi.h>
  35. #define DRV_NAME "ub"
  36. #define DEVFS_NAME DRV_NAME
  37. #define UB_MAJOR 180
  38. /*
  39. * Definitions which have to be scattered once we understand the layout better.
  40. */
  41. /* Transport (despite PR in the name) */
  42. #define US_PR_BULK 0x50 /* bulk only */
  43. /* Protocol */
  44. #define US_SC_SCSI 0x06 /* Transparent */
  45. /*
  46. */
  47. #define UB_MINORS_PER_MAJOR 8
  48. #define UB_MAX_CDB_SIZE 16 /* Corresponds to Bulk */
  49. #define UB_SENSE_SIZE 18
  50. /*
  51. */
  52. /* command block wrapper */
  53. struct bulk_cb_wrap {
  54. __le32 Signature; /* contains 'USBC' */
  55. u32 Tag; /* unique per command id */
  56. __le32 DataTransferLength; /* size of data */
  57. u8 Flags; /* direction in bit 0 */
  58. u8 Lun; /* LUN normally 0 */
  59. u8 Length; /* of of the CDB */
  60. u8 CDB[UB_MAX_CDB_SIZE]; /* max command */
  61. };
  62. #define US_BULK_CB_WRAP_LEN 31
  63. #define US_BULK_CB_SIGN 0x43425355 /*spells out USBC */
  64. #define US_BULK_FLAG_IN 1
  65. #define US_BULK_FLAG_OUT 0
  66. /* command status wrapper */
  67. struct bulk_cs_wrap {
  68. __le32 Signature; /* should = 'USBS' */
  69. u32 Tag; /* same as original command */
  70. __le32 Residue; /* amount not transferred */
  71. u8 Status; /* see below */
  72. };
  73. #define US_BULK_CS_WRAP_LEN 13
  74. #define US_BULK_CS_SIGN 0x53425355 /* spells out 'USBS' */
  75. /* This is for Olympus Camedia digital cameras */
  76. #define US_BULK_CS_OLYMPUS_SIGN 0x55425355 /* spells out 'USBU' */
  77. #define US_BULK_STAT_OK 0
  78. #define US_BULK_STAT_FAIL 1
  79. #define US_BULK_STAT_PHASE 2
  80. /* bulk-only class specific requests */
  81. #define US_BULK_RESET_REQUEST 0xff
  82. #define US_BULK_GET_MAX_LUN 0xfe
  83. /*
  84. */
  85. struct ub_dev;
  86. #define UB_MAX_REQ_SG 1
  87. #define UB_MAX_SECTORS 64
  88. /*
  89. * A second is more than enough for a 32K transfer (UB_MAX_SECTORS)
  90. * even if a webcam hogs the bus, but some devices need time to spin up.
  91. */
  92. #define UB_URB_TIMEOUT (HZ*2)
  93. #define UB_DATA_TIMEOUT (HZ*5) /* ZIP does spin-ups in the data phase */
  94. #define UB_STAT_TIMEOUT (HZ*5) /* Same spinups and eject for a dataless cmd. */
  95. #define UB_CTRL_TIMEOUT (HZ/2) /* 500ms ought to be enough to clear a stall */
  96. /*
  97. * An instance of a SCSI command in transit.
  98. */
  99. #define UB_DIR_NONE 0
  100. #define UB_DIR_READ 1
  101. #define UB_DIR_ILLEGAL2 2
  102. #define UB_DIR_WRITE 3
  103. #define UB_DIR_CHAR(c) (((c)==UB_DIR_WRITE)? 'w': \
  104. (((c)==UB_DIR_READ)? 'r': 'n'))
  105. enum ub_scsi_cmd_state {
  106. UB_CMDST_INIT, /* Initial state */
  107. UB_CMDST_CMD, /* Command submitted */
  108. UB_CMDST_DATA, /* Data phase */
  109. UB_CMDST_CLR2STS, /* Clearing before requesting status */
  110. UB_CMDST_STAT, /* Status phase */
  111. UB_CMDST_CLEAR, /* Clearing a stall (halt, actually) */
  112. UB_CMDST_SENSE, /* Sending Request Sense */
  113. UB_CMDST_DONE /* Final state */
  114. };
  115. static char *ub_scsi_cmd_stname[] = {
  116. ". ",
  117. "Cmd",
  118. "dat",
  119. "c2s",
  120. "sts",
  121. "clr",
  122. "Sen",
  123. "fin"
  124. };
  125. struct ub_scsi_cmd {
  126. unsigned char cdb[UB_MAX_CDB_SIZE];
  127. unsigned char cdb_len;
  128. unsigned char dir; /* 0 - none, 1 - read, 3 - write. */
  129. unsigned char trace_index;
  130. enum ub_scsi_cmd_state state;
  131. unsigned int tag;
  132. struct ub_scsi_cmd *next;
  133. int error; /* Return code - valid upon done */
  134. unsigned int act_len; /* Return size */
  135. unsigned char key, asc, ascq; /* May be valid if error==-EIO */
  136. int stat_count; /* Retries getting status. */
  137. /*
  138. * We do not support transfers from highmem pages
  139. * because the underlying USB framework does not do what we need.
  140. */
  141. char *data; /* Requested buffer */
  142. unsigned int len; /* Requested length */
  143. // struct scatterlist sgv[UB_MAX_REQ_SG];
  144. void (*done)(struct ub_dev *, struct ub_scsi_cmd *);
  145. void *back;
  146. };
  147. /*
  148. */
  149. struct ub_capacity {
  150. unsigned long nsec; /* Linux size - 512 byte sectors */
  151. unsigned int bsize; /* Linux hardsect_size */
  152. unsigned int bshift; /* Shift between 512 and hard sects */
  153. };
  154. /*
  155. * The SCSI command tracing structure.
  156. */
  157. #define SCMD_ST_HIST_SZ 8
  158. #define SCMD_TRACE_SZ 63 /* Less than 4KB of 61-byte lines */
  159. struct ub_scsi_cmd_trace {
  160. int hcur;
  161. unsigned int tag;
  162. unsigned int req_size, act_size;
  163. unsigned char op;
  164. unsigned char dir;
  165. unsigned char key, asc, ascq;
  166. char st_hst[SCMD_ST_HIST_SZ];
  167. };
  168. struct ub_scsi_trace {
  169. int cur;
  170. struct ub_scsi_cmd_trace vec[SCMD_TRACE_SZ];
  171. };
  172. /*
  173. * This is a direct take-off from linux/include/completion.h
  174. * The difference is that I do not wait on this thing, just poll.
  175. * When I want to wait (ub_probe), I just use the stock completion.
  176. *
  177. * Note that INIT_COMPLETION takes no lock. It is correct. But why
  178. * in the bloody hell that thing takes struct instead of pointer to struct
  179. * is quite beyond me. I just copied it from the stock completion.
  180. */
  181. struct ub_completion {
  182. unsigned int done;
  183. spinlock_t lock;
  184. };
  185. static inline void ub_init_completion(struct ub_completion *x)
  186. {
  187. x->done = 0;
  188. spin_lock_init(&x->lock);
  189. }
  190. #define UB_INIT_COMPLETION(x) ((x).done = 0)
  191. static void ub_complete(struct ub_completion *x)
  192. {
  193. unsigned long flags;
  194. spin_lock_irqsave(&x->lock, flags);
  195. x->done++;
  196. spin_unlock_irqrestore(&x->lock, flags);
  197. }
  198. static int ub_is_completed(struct ub_completion *x)
  199. {
  200. unsigned long flags;
  201. int ret;
  202. spin_lock_irqsave(&x->lock, flags);
  203. ret = x->done;
  204. spin_unlock_irqrestore(&x->lock, flags);
  205. return ret;
  206. }
  207. /*
  208. */
  209. struct ub_scsi_cmd_queue {
  210. int qlen, qmax;
  211. struct ub_scsi_cmd *head, *tail;
  212. };
  213. /*
  214. * The UB device instance.
  215. */
  216. struct ub_dev {
  217. spinlock_t lock;
  218. int id; /* Number among ub's */
  219. atomic_t poison; /* The USB device is disconnected */
  220. int openc; /* protected by ub_lock! */
  221. /* kref is too implicit for our taste */
  222. unsigned int tagcnt;
  223. int changed; /* Media was changed */
  224. int removable;
  225. int readonly;
  226. int first_open; /* Kludge. See ub_bd_open. */
  227. char name[8];
  228. struct usb_device *dev;
  229. struct usb_interface *intf;
  230. struct ub_capacity capacity;
  231. struct gendisk *disk;
  232. unsigned int send_bulk_pipe; /* cached pipe values */
  233. unsigned int recv_bulk_pipe;
  234. unsigned int send_ctrl_pipe;
  235. unsigned int recv_ctrl_pipe;
  236. struct tasklet_struct tasklet;
  237. /* XXX Use Ingo's mempool (once we have more than one) */
  238. int cmda[1];
  239. struct ub_scsi_cmd cmdv[1];
  240. struct ub_scsi_cmd_queue cmd_queue;
  241. struct ub_scsi_cmd top_rqs_cmd; /* REQUEST SENSE */
  242. unsigned char top_sense[UB_SENSE_SIZE];
  243. struct ub_completion work_done;
  244. struct urb work_urb;
  245. struct timer_list work_timer;
  246. int last_pipe; /* What might need clearing */
  247. struct bulk_cb_wrap work_bcb;
  248. struct bulk_cs_wrap work_bcs;
  249. struct usb_ctrlrequest work_cr;
  250. struct ub_scsi_trace tr;
  251. };
  252. /*
  253. */
  254. static void ub_cleanup(struct ub_dev *sc);
  255. static int ub_bd_rq_fn_1(struct ub_dev *sc, struct request *rq);
  256. static int ub_cmd_build_block(struct ub_dev *sc, struct ub_scsi_cmd *cmd,
  257. struct request *rq);
  258. static int ub_cmd_build_packet(struct ub_dev *sc, struct ub_scsi_cmd *cmd,
  259. struct request *rq);
  260. static void ub_rw_cmd_done(struct ub_dev *sc, struct ub_scsi_cmd *cmd);
  261. static void ub_end_rq(struct request *rq, int uptodate);
  262. static int ub_submit_scsi(struct ub_dev *sc, struct ub_scsi_cmd *cmd);
  263. static void ub_urb_complete(struct urb *urb, struct pt_regs *pt);
  264. static void ub_scsi_action(unsigned long _dev);
  265. static void ub_scsi_dispatch(struct ub_dev *sc);
  266. static void ub_scsi_urb_compl(struct ub_dev *sc, struct ub_scsi_cmd *cmd);
  267. static void ub_state_done(struct ub_dev *sc, struct ub_scsi_cmd *cmd, int rc);
  268. static void __ub_state_stat(struct ub_dev *sc, struct ub_scsi_cmd *cmd);
  269. static void ub_state_stat(struct ub_dev *sc, struct ub_scsi_cmd *cmd);
  270. static void ub_state_sense(struct ub_dev *sc, struct ub_scsi_cmd *cmd);
  271. static int ub_submit_clear_stall(struct ub_dev *sc, struct ub_scsi_cmd *cmd,
  272. int stalled_pipe);
  273. static void ub_top_sense_done(struct ub_dev *sc, struct ub_scsi_cmd *scmd);
  274. static int ub_sync_tur(struct ub_dev *sc);
  275. static int ub_sync_read_cap(struct ub_dev *sc, struct ub_capacity *ret);
  276. /*
  277. */
  278. static struct usb_device_id ub_usb_ids[] = {
  279. // { USB_DEVICE_VER(0x0781, 0x0002, 0x0009, 0x0009) }, /* SDDR-31 */
  280. { USB_INTERFACE_INFO(USB_CLASS_MASS_STORAGE, US_SC_SCSI, US_PR_BULK) },
  281. { }
  282. };
  283. MODULE_DEVICE_TABLE(usb, ub_usb_ids);
  284. /*
  285. * Find me a way to identify "next free minor" for add_disk(),
  286. * and the array disappears the next day. However, the number of
  287. * hosts has something to do with the naming and /proc/partitions.
  288. * This has to be thought out in detail before changing.
  289. * If UB_MAX_HOST was 1000, we'd use a bitmap. Or a better data structure.
  290. */
  291. #define UB_MAX_HOSTS 26
  292. static char ub_hostv[UB_MAX_HOSTS];
  293. static DEFINE_SPINLOCK(ub_lock); /* Locks globals and ->openc */
  294. /*
  295. * The SCSI command tracing procedures.
  296. */
  297. static void ub_cmdtr_new(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  298. {
  299. int n;
  300. struct ub_scsi_cmd_trace *t;
  301. if ((n = sc->tr.cur + 1) == SCMD_TRACE_SZ) n = 0;
  302. t = &sc->tr.vec[n];
  303. memset(t, 0, sizeof(struct ub_scsi_cmd_trace));
  304. t->tag = cmd->tag;
  305. t->op = cmd->cdb[0];
  306. t->dir = cmd->dir;
  307. t->req_size = cmd->len;
  308. t->st_hst[0] = cmd->state;
  309. sc->tr.cur = n;
  310. cmd->trace_index = n;
  311. }
  312. static void ub_cmdtr_state(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  313. {
  314. int n;
  315. struct ub_scsi_cmd_trace *t;
  316. t = &sc->tr.vec[cmd->trace_index];
  317. if (t->tag == cmd->tag) {
  318. if ((n = t->hcur + 1) == SCMD_ST_HIST_SZ) n = 0;
  319. t->st_hst[n] = cmd->state;
  320. t->hcur = n;
  321. }
  322. }
  323. static void ub_cmdtr_act_len(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  324. {
  325. struct ub_scsi_cmd_trace *t;
  326. t = &sc->tr.vec[cmd->trace_index];
  327. if (t->tag == cmd->tag)
  328. t->act_size = cmd->act_len;
  329. }
  330. static void ub_cmdtr_sense(struct ub_dev *sc, struct ub_scsi_cmd *cmd,
  331. unsigned char *sense)
  332. {
  333. struct ub_scsi_cmd_trace *t;
  334. t = &sc->tr.vec[cmd->trace_index];
  335. if (t->tag == cmd->tag) {
  336. t->key = sense[2] & 0x0F;
  337. t->asc = sense[12];
  338. t->ascq = sense[13];
  339. }
  340. }
  341. static ssize_t ub_diag_show(struct device *dev, char *page)
  342. {
  343. struct usb_interface *intf;
  344. struct ub_dev *sc;
  345. int cnt;
  346. unsigned long flags;
  347. int nc, nh;
  348. int i, j;
  349. struct ub_scsi_cmd_trace *t;
  350. intf = to_usb_interface(dev);
  351. sc = usb_get_intfdata(intf);
  352. if (sc == NULL)
  353. return 0;
  354. cnt = 0;
  355. spin_lock_irqsave(&sc->lock, flags);
  356. cnt += sprintf(page + cnt,
  357. "qlen %d qmax %d changed %d removable %d readonly %d\n",
  358. sc->cmd_queue.qlen, sc->cmd_queue.qmax,
  359. sc->changed, sc->removable, sc->readonly);
  360. if ((nc = sc->tr.cur + 1) == SCMD_TRACE_SZ) nc = 0;
  361. for (j = 0; j < SCMD_TRACE_SZ; j++) {
  362. t = &sc->tr.vec[nc];
  363. cnt += sprintf(page + cnt, "%08x %02x", t->tag, t->op);
  364. if (t->op == REQUEST_SENSE) {
  365. cnt += sprintf(page + cnt, " [sense %x %02x %02x]",
  366. t->key, t->asc, t->ascq);
  367. } else {
  368. cnt += sprintf(page + cnt, " %c", UB_DIR_CHAR(t->dir));
  369. cnt += sprintf(page + cnt, " [%5d %5d]",
  370. t->req_size, t->act_size);
  371. }
  372. if ((nh = t->hcur + 1) == SCMD_ST_HIST_SZ) nh = 0;
  373. for (i = 0; i < SCMD_ST_HIST_SZ; i++) {
  374. cnt += sprintf(page + cnt, " %s",
  375. ub_scsi_cmd_stname[(int)t->st_hst[nh]]);
  376. if (++nh == SCMD_ST_HIST_SZ) nh = 0;
  377. }
  378. cnt += sprintf(page + cnt, "\n");
  379. if (++nc == SCMD_TRACE_SZ) nc = 0;
  380. }
  381. spin_unlock_irqrestore(&sc->lock, flags);
  382. return cnt;
  383. }
  384. static DEVICE_ATTR(diag, S_IRUGO, ub_diag_show, NULL); /* N.B. World readable */
  385. /*
  386. * The id allocator.
  387. *
  388. * This also stores the host for indexing by minor, which is somewhat dirty.
  389. */
  390. static int ub_id_get(void)
  391. {
  392. unsigned long flags;
  393. int i;
  394. spin_lock_irqsave(&ub_lock, flags);
  395. for (i = 0; i < UB_MAX_HOSTS; i++) {
  396. if (ub_hostv[i] == 0) {
  397. ub_hostv[i] = 1;
  398. spin_unlock_irqrestore(&ub_lock, flags);
  399. return i;
  400. }
  401. }
  402. spin_unlock_irqrestore(&ub_lock, flags);
  403. return -1;
  404. }
  405. static void ub_id_put(int id)
  406. {
  407. unsigned long flags;
  408. if (id < 0 || id >= UB_MAX_HOSTS) {
  409. printk(KERN_ERR DRV_NAME ": bad host ID %d\n", id);
  410. return;
  411. }
  412. spin_lock_irqsave(&ub_lock, flags);
  413. if (ub_hostv[id] == 0) {
  414. spin_unlock_irqrestore(&ub_lock, flags);
  415. printk(KERN_ERR DRV_NAME ": freeing free host ID %d\n", id);
  416. return;
  417. }
  418. ub_hostv[id] = 0;
  419. spin_unlock_irqrestore(&ub_lock, flags);
  420. }
  421. /*
  422. * Downcount for deallocation. This rides on two assumptions:
  423. * - once something is poisoned, its refcount cannot grow
  424. * - opens cannot happen at this time (del_gendisk was done)
  425. * If the above is true, we can drop the lock, which we need for
  426. * blk_cleanup_queue(): the silly thing may attempt to sleep.
  427. * [Actually, it never needs to sleep for us, but it calls might_sleep()]
  428. */
  429. static void ub_put(struct ub_dev *sc)
  430. {
  431. unsigned long flags;
  432. spin_lock_irqsave(&ub_lock, flags);
  433. --sc->openc;
  434. if (sc->openc == 0 && atomic_read(&sc->poison)) {
  435. spin_unlock_irqrestore(&ub_lock, flags);
  436. ub_cleanup(sc);
  437. } else {
  438. spin_unlock_irqrestore(&ub_lock, flags);
  439. }
  440. }
  441. /*
  442. * Final cleanup and deallocation.
  443. */
  444. static void ub_cleanup(struct ub_dev *sc)
  445. {
  446. request_queue_t *q;
  447. /* I don't think queue can be NULL. But... Stolen from sx8.c */
  448. if ((q = sc->disk->queue) != NULL)
  449. blk_cleanup_queue(q);
  450. /*
  451. * If we zero disk->private_data BEFORE put_disk, we have to check
  452. * for NULL all over the place in open, release, check_media and
  453. * revalidate, because the block level semaphore is well inside the
  454. * put_disk. But we cannot zero after the call, because *disk is gone.
  455. * The sd.c is blatantly racy in this area.
  456. */
  457. /* disk->private_data = NULL; */
  458. put_disk(sc->disk);
  459. sc->disk = NULL;
  460. ub_id_put(sc->id);
  461. kfree(sc);
  462. }
  463. /*
  464. * The "command allocator".
  465. */
  466. static struct ub_scsi_cmd *ub_get_cmd(struct ub_dev *sc)
  467. {
  468. struct ub_scsi_cmd *ret;
  469. if (sc->cmda[0])
  470. return NULL;
  471. ret = &sc->cmdv[0];
  472. sc->cmda[0] = 1;
  473. return ret;
  474. }
  475. static void ub_put_cmd(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  476. {
  477. if (cmd != &sc->cmdv[0]) {
  478. printk(KERN_WARNING "%s: releasing a foreign cmd %p\n",
  479. sc->name, cmd);
  480. return;
  481. }
  482. if (!sc->cmda[0]) {
  483. printk(KERN_WARNING "%s: releasing a free cmd\n", sc->name);
  484. return;
  485. }
  486. sc->cmda[0] = 0;
  487. }
  488. /*
  489. * The command queue.
  490. */
  491. static void ub_cmdq_add(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  492. {
  493. struct ub_scsi_cmd_queue *t = &sc->cmd_queue;
  494. if (t->qlen++ == 0) {
  495. t->head = cmd;
  496. t->tail = cmd;
  497. } else {
  498. t->tail->next = cmd;
  499. t->tail = cmd;
  500. }
  501. if (t->qlen > t->qmax)
  502. t->qmax = t->qlen;
  503. }
  504. static void ub_cmdq_insert(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  505. {
  506. struct ub_scsi_cmd_queue *t = &sc->cmd_queue;
  507. if (t->qlen++ == 0) {
  508. t->head = cmd;
  509. t->tail = cmd;
  510. } else {
  511. cmd->next = t->head;
  512. t->head = cmd;
  513. }
  514. if (t->qlen > t->qmax)
  515. t->qmax = t->qlen;
  516. }
  517. static struct ub_scsi_cmd *ub_cmdq_pop(struct ub_dev *sc)
  518. {
  519. struct ub_scsi_cmd_queue *t = &sc->cmd_queue;
  520. struct ub_scsi_cmd *cmd;
  521. if (t->qlen == 0)
  522. return NULL;
  523. if (--t->qlen == 0)
  524. t->tail = NULL;
  525. cmd = t->head;
  526. t->head = cmd->next;
  527. cmd->next = NULL;
  528. return cmd;
  529. }
  530. #define ub_cmdq_peek(sc) ((sc)->cmd_queue.head)
  531. /*
  532. * The request function is our main entry point
  533. */
  534. static void ub_bd_rq_fn(request_queue_t *q)
  535. {
  536. struct ub_dev *sc = q->queuedata;
  537. struct request *rq;
  538. while ((rq = elv_next_request(q)) != NULL) {
  539. if (ub_bd_rq_fn_1(sc, rq) != 0) {
  540. blk_stop_queue(q);
  541. break;
  542. }
  543. }
  544. }
  545. static int ub_bd_rq_fn_1(struct ub_dev *sc, struct request *rq)
  546. {
  547. struct ub_scsi_cmd *cmd;
  548. int rc;
  549. if (atomic_read(&sc->poison) || sc->changed) {
  550. blkdev_dequeue_request(rq);
  551. ub_end_rq(rq, 0);
  552. return 0;
  553. }
  554. if ((cmd = ub_get_cmd(sc)) == NULL)
  555. return -1;
  556. memset(cmd, 0, sizeof(struct ub_scsi_cmd));
  557. blkdev_dequeue_request(rq);
  558. if (blk_pc_request(rq)) {
  559. rc = ub_cmd_build_packet(sc, cmd, rq);
  560. } else {
  561. rc = ub_cmd_build_block(sc, cmd, rq);
  562. }
  563. if (rc != 0) {
  564. ub_put_cmd(sc, cmd);
  565. ub_end_rq(rq, 0);
  566. blk_start_queue(sc->disk->queue);
  567. return 0;
  568. }
  569. cmd->state = UB_CMDST_INIT;
  570. cmd->done = ub_rw_cmd_done;
  571. cmd->back = rq;
  572. cmd->tag = sc->tagcnt++;
  573. if ((rc = ub_submit_scsi(sc, cmd)) != 0) {
  574. ub_put_cmd(sc, cmd);
  575. ub_end_rq(rq, 0);
  576. blk_start_queue(sc->disk->queue);
  577. return 0;
  578. }
  579. return 0;
  580. }
  581. static int ub_cmd_build_block(struct ub_dev *sc, struct ub_scsi_cmd *cmd,
  582. struct request *rq)
  583. {
  584. int ub_dir;
  585. #if 0 /* We use rq->buffer for now */
  586. struct scatterlist *sg;
  587. int n_elem;
  588. #endif
  589. unsigned int block, nblks;
  590. if (rq_data_dir(rq) == WRITE)
  591. ub_dir = UB_DIR_WRITE;
  592. else
  593. ub_dir = UB_DIR_READ;
  594. /*
  595. * get scatterlist from block layer
  596. */
  597. #if 0 /* We use rq->buffer for now */
  598. sg = &cmd->sgv[0];
  599. n_elem = blk_rq_map_sg(q, rq, sg);
  600. if (n_elem <= 0) {
  601. ub_put_cmd(sc, cmd);
  602. ub_end_rq(rq, 0);
  603. blk_start_queue(q);
  604. return 0; /* request with no s/g entries? */
  605. }
  606. if (n_elem != 1) { /* Paranoia */
  607. printk(KERN_WARNING "%s: request with %d segments\n",
  608. sc->name, n_elem);
  609. ub_put_cmd(sc, cmd);
  610. ub_end_rq(rq, 0);
  611. blk_start_queue(q);
  612. return 0;
  613. }
  614. #endif
  615. /*
  616. * XXX Unfortunately, this check does not work. It is quite possible
  617. * to get bogus non-null rq->buffer if you allow sg by mistake.
  618. */
  619. if (rq->buffer == NULL) {
  620. /*
  621. * This must not happen if we set the queue right.
  622. * The block level must create bounce buffers for us.
  623. */
  624. static int do_print = 1;
  625. if (do_print) {
  626. printk(KERN_WARNING "%s: unmapped block request"
  627. " flags 0x%lx sectors %lu\n",
  628. sc->name, rq->flags, rq->nr_sectors);
  629. do_print = 0;
  630. }
  631. return -1;
  632. }
  633. /*
  634. * build the command
  635. *
  636. * The call to blk_queue_hardsect_size() guarantees that request
  637. * is aligned, but it is given in terms of 512 byte units, always.
  638. */
  639. block = rq->sector >> sc->capacity.bshift;
  640. nblks = rq->nr_sectors >> sc->capacity.bshift;
  641. cmd->cdb[0] = (ub_dir == UB_DIR_READ)? READ_10: WRITE_10;
  642. /* 10-byte uses 4 bytes of LBA: 2147483648KB, 2097152MB, 2048GB */
  643. cmd->cdb[2] = block >> 24;
  644. cmd->cdb[3] = block >> 16;
  645. cmd->cdb[4] = block >> 8;
  646. cmd->cdb[5] = block;
  647. cmd->cdb[7] = nblks >> 8;
  648. cmd->cdb[8] = nblks;
  649. cmd->cdb_len = 10;
  650. cmd->dir = ub_dir;
  651. cmd->data = rq->buffer;
  652. cmd->len = rq->nr_sectors * 512;
  653. return 0;
  654. }
  655. static int ub_cmd_build_packet(struct ub_dev *sc, struct ub_scsi_cmd *cmd,
  656. struct request *rq)
  657. {
  658. if (rq->data_len != 0 && rq->data == NULL) {
  659. static int do_print = 1;
  660. if (do_print) {
  661. printk(KERN_WARNING "%s: unmapped packet request"
  662. " flags 0x%lx length %d\n",
  663. sc->name, rq->flags, rq->data_len);
  664. do_print = 0;
  665. }
  666. return -1;
  667. }
  668. memcpy(&cmd->cdb, rq->cmd, rq->cmd_len);
  669. cmd->cdb_len = rq->cmd_len;
  670. if (rq->data_len == 0) {
  671. cmd->dir = UB_DIR_NONE;
  672. } else {
  673. if (rq_data_dir(rq) == WRITE)
  674. cmd->dir = UB_DIR_WRITE;
  675. else
  676. cmd->dir = UB_DIR_READ;
  677. }
  678. cmd->data = rq->data;
  679. cmd->len = rq->data_len;
  680. return 0;
  681. }
  682. static void ub_rw_cmd_done(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  683. {
  684. struct request *rq = cmd->back;
  685. struct gendisk *disk = sc->disk;
  686. request_queue_t *q = disk->queue;
  687. int uptodate;
  688. if (blk_pc_request(rq)) {
  689. /* UB_SENSE_SIZE is smaller than SCSI_SENSE_BUFFERSIZE */
  690. memcpy(rq->sense, sc->top_sense, UB_SENSE_SIZE);
  691. rq->sense_len = UB_SENSE_SIZE;
  692. }
  693. if (cmd->error == 0)
  694. uptodate = 1;
  695. else
  696. uptodate = 0;
  697. ub_put_cmd(sc, cmd);
  698. ub_end_rq(rq, uptodate);
  699. blk_start_queue(q);
  700. }
  701. static void ub_end_rq(struct request *rq, int uptodate)
  702. {
  703. int rc;
  704. rc = end_that_request_first(rq, uptodate, rq->hard_nr_sectors);
  705. // assert(rc == 0);
  706. end_that_request_last(rq);
  707. }
  708. /*
  709. * Submit a regular SCSI operation (not an auto-sense).
  710. *
  711. * The Iron Law of Good Submit Routine is:
  712. * Zero return - callback is done, Nonzero return - callback is not done.
  713. * No exceptions.
  714. *
  715. * Host is assumed locked.
  716. *
  717. * XXX We only support Bulk for the moment.
  718. */
  719. static int ub_submit_scsi(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  720. {
  721. if (cmd->state != UB_CMDST_INIT ||
  722. (cmd->dir != UB_DIR_NONE && cmd->len == 0)) {
  723. return -EINVAL;
  724. }
  725. ub_cmdq_add(sc, cmd);
  726. /*
  727. * We can call ub_scsi_dispatch(sc) right away here, but it's a little
  728. * safer to jump to a tasklet, in case upper layers do something silly.
  729. */
  730. tasklet_schedule(&sc->tasklet);
  731. return 0;
  732. }
  733. /*
  734. * Submit the first URB for the queued command.
  735. * This function does not deal with queueing in any way.
  736. */
  737. static int ub_scsi_cmd_start(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  738. {
  739. struct bulk_cb_wrap *bcb;
  740. int rc;
  741. bcb = &sc->work_bcb;
  742. /*
  743. * ``If the allocation length is eighteen or greater, and a device
  744. * server returns less than eithteen bytes of data, the application
  745. * client should assume that the bytes not transferred would have been
  746. * zeroes had the device server returned those bytes.''
  747. *
  748. * We zero sense for all commands so that when a packet request
  749. * fails it does not return a stale sense.
  750. */
  751. memset(&sc->top_sense, 0, UB_SENSE_SIZE);
  752. /* set up the command wrapper */
  753. bcb->Signature = cpu_to_le32(US_BULK_CB_SIGN);
  754. bcb->Tag = cmd->tag; /* Endianness is not important */
  755. bcb->DataTransferLength = cpu_to_le32(cmd->len);
  756. bcb->Flags = (cmd->dir == UB_DIR_READ) ? 0x80 : 0;
  757. bcb->Lun = 0; /* No multi-LUN yet */
  758. bcb->Length = cmd->cdb_len;
  759. /* copy the command payload */
  760. memcpy(bcb->CDB, cmd->cdb, UB_MAX_CDB_SIZE);
  761. UB_INIT_COMPLETION(sc->work_done);
  762. sc->last_pipe = sc->send_bulk_pipe;
  763. usb_fill_bulk_urb(&sc->work_urb, sc->dev, sc->send_bulk_pipe,
  764. bcb, US_BULK_CB_WRAP_LEN, ub_urb_complete, sc);
  765. sc->work_urb.transfer_flags = URB_ASYNC_UNLINK;
  766. /* Fill what we shouldn't be filling, because usb-storage did so. */
  767. sc->work_urb.actual_length = 0;
  768. sc->work_urb.error_count = 0;
  769. sc->work_urb.status = 0;
  770. if ((rc = usb_submit_urb(&sc->work_urb, GFP_ATOMIC)) != 0) {
  771. /* XXX Clear stalls */
  772. printk("ub: cmd #%d start failed (%d)\n", cmd->tag, rc); /* P3 */
  773. ub_complete(&sc->work_done);
  774. return rc;
  775. }
  776. sc->work_timer.expires = jiffies + UB_URB_TIMEOUT;
  777. add_timer(&sc->work_timer);
  778. cmd->state = UB_CMDST_CMD;
  779. ub_cmdtr_state(sc, cmd);
  780. return 0;
  781. }
  782. /*
  783. * Timeout handler.
  784. */
  785. static void ub_urb_timeout(unsigned long arg)
  786. {
  787. struct ub_dev *sc = (struct ub_dev *) arg;
  788. unsigned long flags;
  789. spin_lock_irqsave(&sc->lock, flags);
  790. usb_unlink_urb(&sc->work_urb);
  791. spin_unlock_irqrestore(&sc->lock, flags);
  792. }
  793. /*
  794. * Completion routine for the work URB.
  795. *
  796. * This can be called directly from usb_submit_urb (while we have
  797. * the sc->lock taken) and from an interrupt (while we do NOT have
  798. * the sc->lock taken). Therefore, bounce this off to a tasklet.
  799. */
  800. static void ub_urb_complete(struct urb *urb, struct pt_regs *pt)
  801. {
  802. struct ub_dev *sc = urb->context;
  803. ub_complete(&sc->work_done);
  804. tasklet_schedule(&sc->tasklet);
  805. }
  806. static void ub_scsi_action(unsigned long _dev)
  807. {
  808. struct ub_dev *sc = (struct ub_dev *) _dev;
  809. unsigned long flags;
  810. spin_lock_irqsave(&sc->lock, flags);
  811. del_timer(&sc->work_timer);
  812. ub_scsi_dispatch(sc);
  813. spin_unlock_irqrestore(&sc->lock, flags);
  814. }
  815. static void ub_scsi_dispatch(struct ub_dev *sc)
  816. {
  817. struct ub_scsi_cmd *cmd;
  818. int rc;
  819. while ((cmd = ub_cmdq_peek(sc)) != NULL) {
  820. if (cmd->state == UB_CMDST_DONE) {
  821. ub_cmdq_pop(sc);
  822. (*cmd->done)(sc, cmd);
  823. } else if (cmd->state == UB_CMDST_INIT) {
  824. ub_cmdtr_new(sc, cmd);
  825. if ((rc = ub_scsi_cmd_start(sc, cmd)) == 0)
  826. break;
  827. cmd->error = rc;
  828. cmd->state = UB_CMDST_DONE;
  829. ub_cmdtr_state(sc, cmd);
  830. } else {
  831. if (!ub_is_completed(&sc->work_done))
  832. break;
  833. ub_scsi_urb_compl(sc, cmd);
  834. }
  835. }
  836. }
  837. static void ub_scsi_urb_compl(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  838. {
  839. struct urb *urb = &sc->work_urb;
  840. struct bulk_cs_wrap *bcs;
  841. int pipe;
  842. int rc;
  843. if (atomic_read(&sc->poison)) {
  844. /* A little too simplistic, I feel... */
  845. goto Bad_End;
  846. }
  847. if (cmd->state == UB_CMDST_CLEAR) {
  848. if (urb->status == -EPIPE) {
  849. /*
  850. * STALL while clearning STALL.
  851. * The control pipe clears itself - nothing to do.
  852. * XXX Might try to reset the device here and retry.
  853. */
  854. printk(KERN_NOTICE "%s: "
  855. "stall on control pipe for device %u\n",
  856. sc->name, sc->dev->devnum);
  857. goto Bad_End;
  858. }
  859. /*
  860. * We ignore the result for the halt clear.
  861. */
  862. /* reset the endpoint toggle */
  863. usb_settoggle(sc->dev, usb_pipeendpoint(sc->last_pipe),
  864. usb_pipeout(sc->last_pipe), 0);
  865. ub_state_sense(sc, cmd);
  866. } else if (cmd->state == UB_CMDST_CLR2STS) {
  867. if (urb->status == -EPIPE) {
  868. /*
  869. * STALL while clearning STALL.
  870. * The control pipe clears itself - nothing to do.
  871. * XXX Might try to reset the device here and retry.
  872. */
  873. printk(KERN_NOTICE "%s: "
  874. "stall on control pipe for device %u\n",
  875. sc->name, sc->dev->devnum);
  876. goto Bad_End;
  877. }
  878. /*
  879. * We ignore the result for the halt clear.
  880. */
  881. /* reset the endpoint toggle */
  882. usb_settoggle(sc->dev, usb_pipeendpoint(sc->last_pipe),
  883. usb_pipeout(sc->last_pipe), 0);
  884. ub_state_stat(sc, cmd);
  885. } else if (cmd->state == UB_CMDST_CMD) {
  886. if (urb->status == -EPIPE) {
  887. rc = ub_submit_clear_stall(sc, cmd, sc->last_pipe);
  888. if (rc != 0) {
  889. printk(KERN_NOTICE "%s: "
  890. "unable to submit clear for device %u"
  891. " (code %d)\n",
  892. sc->name, sc->dev->devnum, rc);
  893. /*
  894. * This is typically ENOMEM or some other such shit.
  895. * Retrying is pointless. Just do Bad End on it...
  896. */
  897. goto Bad_End;
  898. }
  899. cmd->state = UB_CMDST_CLEAR;
  900. ub_cmdtr_state(sc, cmd);
  901. return;
  902. }
  903. if (urb->status != 0) {
  904. printk("ub: cmd #%d cmd status (%d)\n", cmd->tag, urb->status); /* P3 */
  905. goto Bad_End;
  906. }
  907. if (urb->actual_length != US_BULK_CB_WRAP_LEN) {
  908. printk("ub: cmd #%d xferred %d\n", cmd->tag, urb->actual_length); /* P3 */
  909. /* XXX Must do reset here to unconfuse the device */
  910. goto Bad_End;
  911. }
  912. if (cmd->dir == UB_DIR_NONE) {
  913. ub_state_stat(sc, cmd);
  914. return;
  915. }
  916. UB_INIT_COMPLETION(sc->work_done);
  917. if (cmd->dir == UB_DIR_READ)
  918. pipe = sc->recv_bulk_pipe;
  919. else
  920. pipe = sc->send_bulk_pipe;
  921. sc->last_pipe = pipe;
  922. usb_fill_bulk_urb(&sc->work_urb, sc->dev, pipe,
  923. cmd->data, cmd->len, ub_urb_complete, sc);
  924. sc->work_urb.transfer_flags = URB_ASYNC_UNLINK;
  925. sc->work_urb.actual_length = 0;
  926. sc->work_urb.error_count = 0;
  927. sc->work_urb.status = 0;
  928. if ((rc = usb_submit_urb(&sc->work_urb, GFP_ATOMIC)) != 0) {
  929. /* XXX Clear stalls */
  930. printk("ub: data #%d submit failed (%d)\n", cmd->tag, rc); /* P3 */
  931. ub_complete(&sc->work_done);
  932. ub_state_done(sc, cmd, rc);
  933. return;
  934. }
  935. sc->work_timer.expires = jiffies + UB_DATA_TIMEOUT;
  936. add_timer(&sc->work_timer);
  937. cmd->state = UB_CMDST_DATA;
  938. ub_cmdtr_state(sc, cmd);
  939. } else if (cmd->state == UB_CMDST_DATA) {
  940. if (urb->status == -EPIPE) {
  941. rc = ub_submit_clear_stall(sc, cmd, sc->last_pipe);
  942. if (rc != 0) {
  943. printk(KERN_NOTICE "%s: "
  944. "unable to submit clear for device %u"
  945. " (code %d)\n",
  946. sc->name, sc->dev->devnum, rc);
  947. /*
  948. * This is typically ENOMEM or some other such shit.
  949. * Retrying is pointless. Just do Bad End on it...
  950. */
  951. goto Bad_End;
  952. }
  953. cmd->state = UB_CMDST_CLR2STS;
  954. ub_cmdtr_state(sc, cmd);
  955. return;
  956. }
  957. if (urb->status == -EOVERFLOW) {
  958. /*
  959. * A babble? Failure, but we must transfer CSW now.
  960. */
  961. cmd->error = -EOVERFLOW; /* A cheap trick... */
  962. } else {
  963. if (urb->status != 0)
  964. goto Bad_End;
  965. }
  966. cmd->act_len = urb->actual_length;
  967. ub_cmdtr_act_len(sc, cmd);
  968. ub_state_stat(sc, cmd);
  969. } else if (cmd->state == UB_CMDST_STAT) {
  970. if (urb->status == -EPIPE) {
  971. rc = ub_submit_clear_stall(sc, cmd, sc->last_pipe);
  972. if (rc != 0) {
  973. printk(KERN_NOTICE "%s: "
  974. "unable to submit clear for device %u"
  975. " (code %d)\n",
  976. sc->name, sc->dev->devnum, rc);
  977. /*
  978. * This is typically ENOMEM or some other such shit.
  979. * Retrying is pointless. Just do Bad End on it...
  980. */
  981. goto Bad_End;
  982. }
  983. cmd->state = UB_CMDST_CLEAR;
  984. ub_cmdtr_state(sc, cmd);
  985. return;
  986. }
  987. if (urb->status != 0)
  988. goto Bad_End;
  989. if (urb->actual_length == 0) {
  990. /*
  991. * Some broken devices add unnecessary zero-length
  992. * packets to the end of their data transfers.
  993. * Such packets show up as 0-length CSWs. If we
  994. * encounter such a thing, try to read the CSW again.
  995. */
  996. if (++cmd->stat_count >= 4) {
  997. printk(KERN_NOTICE "%s: "
  998. "unable to get CSW on device %u\n",
  999. sc->name, sc->dev->devnum);
  1000. goto Bad_End;
  1001. }
  1002. __ub_state_stat(sc, cmd);
  1003. return;
  1004. }
  1005. /*
  1006. * Check the returned Bulk protocol status.
  1007. */
  1008. bcs = &sc->work_bcs;
  1009. rc = le32_to_cpu(bcs->Residue);
  1010. if (rc != cmd->len - cmd->act_len) {
  1011. /*
  1012. * It is all right to transfer less, the caller has
  1013. * to check. But it's not all right if the device
  1014. * counts disagree with our counts.
  1015. */
  1016. /* P3 */ printk("%s: resid %d len %d act %d\n",
  1017. sc->name, rc, cmd->len, cmd->act_len);
  1018. goto Bad_End;
  1019. }
  1020. #if 0
  1021. if (bcs->Signature != cpu_to_le32(US_BULK_CS_SIGN) &&
  1022. bcs->Signature != cpu_to_le32(US_BULK_CS_OLYMPUS_SIGN)) {
  1023. /* Windows ignores signatures, so do we. */
  1024. }
  1025. #endif
  1026. if (bcs->Tag != cmd->tag) {
  1027. /*
  1028. * This usually happens when we disagree with the
  1029. * device's microcode about something. For instance,
  1030. * a few of them throw this after timeouts. They buffer
  1031. * commands and reply at commands we timed out before.
  1032. * Without flushing these replies we loop forever.
  1033. */
  1034. if (++cmd->stat_count >= 4) {
  1035. printk(KERN_NOTICE "%s: "
  1036. "tag mismatch orig 0x%x reply 0x%x "
  1037. "on device %u\n",
  1038. sc->name, cmd->tag, bcs->Tag,
  1039. sc->dev->devnum);
  1040. goto Bad_End;
  1041. }
  1042. __ub_state_stat(sc, cmd);
  1043. return;
  1044. }
  1045. switch (bcs->Status) {
  1046. case US_BULK_STAT_OK:
  1047. break;
  1048. case US_BULK_STAT_FAIL:
  1049. ub_state_sense(sc, cmd);
  1050. return;
  1051. case US_BULK_STAT_PHASE:
  1052. /* XXX We must reset the transport here */
  1053. /* P3 */ printk("%s: status PHASE\n", sc->name);
  1054. goto Bad_End;
  1055. default:
  1056. printk(KERN_INFO "%s: unknown CSW status 0x%x\n",
  1057. sc->name, bcs->Status);
  1058. goto Bad_End;
  1059. }
  1060. /* Not zeroing error to preserve a babble indicator */
  1061. cmd->state = UB_CMDST_DONE;
  1062. ub_cmdtr_state(sc, cmd);
  1063. ub_cmdq_pop(sc);
  1064. (*cmd->done)(sc, cmd);
  1065. } else if (cmd->state == UB_CMDST_SENSE) {
  1066. ub_state_done(sc, cmd, -EIO);
  1067. } else {
  1068. printk(KERN_WARNING "%s: "
  1069. "wrong command state %d on device %u\n",
  1070. sc->name, cmd->state, sc->dev->devnum);
  1071. goto Bad_End;
  1072. }
  1073. return;
  1074. Bad_End: /* Little Excel is dead */
  1075. ub_state_done(sc, cmd, -EIO);
  1076. }
  1077. /*
  1078. * Factorization helper for the command state machine:
  1079. * Finish the command.
  1080. */
  1081. static void ub_state_done(struct ub_dev *sc, struct ub_scsi_cmd *cmd, int rc)
  1082. {
  1083. cmd->error = rc;
  1084. cmd->state = UB_CMDST_DONE;
  1085. ub_cmdtr_state(sc, cmd);
  1086. ub_cmdq_pop(sc);
  1087. (*cmd->done)(sc, cmd);
  1088. }
  1089. /*
  1090. * Factorization helper for the command state machine:
  1091. * Submit a CSW read.
  1092. */
  1093. static void __ub_state_stat(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  1094. {
  1095. int rc;
  1096. UB_INIT_COMPLETION(sc->work_done);
  1097. sc->last_pipe = sc->recv_bulk_pipe;
  1098. usb_fill_bulk_urb(&sc->work_urb, sc->dev, sc->recv_bulk_pipe,
  1099. &sc->work_bcs, US_BULK_CS_WRAP_LEN, ub_urb_complete, sc);
  1100. sc->work_urb.transfer_flags = URB_ASYNC_UNLINK;
  1101. sc->work_urb.actual_length = 0;
  1102. sc->work_urb.error_count = 0;
  1103. sc->work_urb.status = 0;
  1104. if ((rc = usb_submit_urb(&sc->work_urb, GFP_ATOMIC)) != 0) {
  1105. /* XXX Clear stalls */
  1106. printk("%s: CSW #%d submit failed (%d)\n", sc->name, cmd->tag, rc); /* P3 */
  1107. ub_complete(&sc->work_done);
  1108. ub_state_done(sc, cmd, rc);
  1109. return;
  1110. }
  1111. sc->work_timer.expires = jiffies + UB_STAT_TIMEOUT;
  1112. add_timer(&sc->work_timer);
  1113. }
  1114. /*
  1115. * Factorization helper for the command state machine:
  1116. * Submit a CSW read and go to STAT state.
  1117. */
  1118. static void ub_state_stat(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  1119. {
  1120. __ub_state_stat(sc, cmd);
  1121. cmd->stat_count = 0;
  1122. cmd->state = UB_CMDST_STAT;
  1123. ub_cmdtr_state(sc, cmd);
  1124. }
  1125. /*
  1126. * Factorization helper for the command state machine:
  1127. * Submit a REQUEST SENSE and go to SENSE state.
  1128. */
  1129. static void ub_state_sense(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  1130. {
  1131. struct ub_scsi_cmd *scmd;
  1132. int rc;
  1133. if (cmd->cdb[0] == REQUEST_SENSE) {
  1134. rc = -EPIPE;
  1135. goto error;
  1136. }
  1137. scmd = &sc->top_rqs_cmd;
  1138. scmd->cdb[0] = REQUEST_SENSE;
  1139. scmd->cdb[4] = UB_SENSE_SIZE;
  1140. scmd->cdb_len = 6;
  1141. scmd->dir = UB_DIR_READ;
  1142. scmd->state = UB_CMDST_INIT;
  1143. scmd->data = sc->top_sense;
  1144. scmd->len = UB_SENSE_SIZE;
  1145. scmd->done = ub_top_sense_done;
  1146. scmd->back = cmd;
  1147. scmd->tag = sc->tagcnt++;
  1148. cmd->state = UB_CMDST_SENSE;
  1149. ub_cmdtr_state(sc, cmd);
  1150. ub_cmdq_insert(sc, scmd);
  1151. return;
  1152. error:
  1153. ub_state_done(sc, cmd, rc);
  1154. }
  1155. /*
  1156. * A helper for the command's state machine:
  1157. * Submit a stall clear.
  1158. */
  1159. static int ub_submit_clear_stall(struct ub_dev *sc, struct ub_scsi_cmd *cmd,
  1160. int stalled_pipe)
  1161. {
  1162. int endp;
  1163. struct usb_ctrlrequest *cr;
  1164. int rc;
  1165. endp = usb_pipeendpoint(stalled_pipe);
  1166. if (usb_pipein (stalled_pipe))
  1167. endp |= USB_DIR_IN;
  1168. cr = &sc->work_cr;
  1169. cr->bRequestType = USB_RECIP_ENDPOINT;
  1170. cr->bRequest = USB_REQ_CLEAR_FEATURE;
  1171. cr->wValue = cpu_to_le16(USB_ENDPOINT_HALT);
  1172. cr->wIndex = cpu_to_le16(endp);
  1173. cr->wLength = cpu_to_le16(0);
  1174. UB_INIT_COMPLETION(sc->work_done);
  1175. usb_fill_control_urb(&sc->work_urb, sc->dev, sc->send_ctrl_pipe,
  1176. (unsigned char*) cr, NULL, 0, ub_urb_complete, sc);
  1177. sc->work_urb.transfer_flags = URB_ASYNC_UNLINK;
  1178. sc->work_urb.actual_length = 0;
  1179. sc->work_urb.error_count = 0;
  1180. sc->work_urb.status = 0;
  1181. if ((rc = usb_submit_urb(&sc->work_urb, GFP_ATOMIC)) != 0) {
  1182. ub_complete(&sc->work_done);
  1183. return rc;
  1184. }
  1185. sc->work_timer.expires = jiffies + UB_CTRL_TIMEOUT;
  1186. add_timer(&sc->work_timer);
  1187. return 0;
  1188. }
  1189. /*
  1190. */
  1191. static void ub_top_sense_done(struct ub_dev *sc, struct ub_scsi_cmd *scmd)
  1192. {
  1193. unsigned char *sense = scmd->data;
  1194. struct ub_scsi_cmd *cmd;
  1195. /*
  1196. * Ignoring scmd->act_len, because the buffer was pre-zeroed.
  1197. */
  1198. ub_cmdtr_sense(sc, scmd, sense);
  1199. /*
  1200. * Find the command which triggered the unit attention or a check,
  1201. * save the sense into it, and advance its state machine.
  1202. */
  1203. if ((cmd = ub_cmdq_peek(sc)) == NULL) {
  1204. printk(KERN_WARNING "%s: sense done while idle\n", sc->name);
  1205. return;
  1206. }
  1207. if (cmd != scmd->back) {
  1208. printk(KERN_WARNING "%s: "
  1209. "sense done for wrong command 0x%x on device %u\n",
  1210. sc->name, cmd->tag, sc->dev->devnum);
  1211. return;
  1212. }
  1213. if (cmd->state != UB_CMDST_SENSE) {
  1214. printk(KERN_WARNING "%s: "
  1215. "sense done with bad cmd state %d on device %u\n",
  1216. sc->name, cmd->state, sc->dev->devnum);
  1217. return;
  1218. }
  1219. cmd->key = sense[2] & 0x0F;
  1220. cmd->asc = sense[12];
  1221. cmd->ascq = sense[13];
  1222. ub_scsi_urb_compl(sc, cmd);
  1223. }
  1224. #if 0
  1225. /* Determine what the maximum LUN supported is */
  1226. int usb_stor_Bulk_max_lun(struct us_data *us)
  1227. {
  1228. int result;
  1229. /* issue the command */
  1230. result = usb_stor_control_msg(us, us->recv_ctrl_pipe,
  1231. US_BULK_GET_MAX_LUN,
  1232. USB_DIR_IN | USB_TYPE_CLASS |
  1233. USB_RECIP_INTERFACE,
  1234. 0, us->ifnum, us->iobuf, 1, HZ);
  1235. /*
  1236. * Some devices (i.e. Iomega Zip100) need this -- apparently
  1237. * the bulk pipes get STALLed when the GetMaxLUN request is
  1238. * processed. This is, in theory, harmless to all other devices
  1239. * (regardless of if they stall or not).
  1240. */
  1241. if (result < 0) {
  1242. usb_stor_clear_halt(us, us->recv_bulk_pipe);
  1243. usb_stor_clear_halt(us, us->send_bulk_pipe);
  1244. }
  1245. US_DEBUGP("GetMaxLUN command result is %d, data is %d\n",
  1246. result, us->iobuf[0]);
  1247. /* if we have a successful request, return the result */
  1248. if (result == 1)
  1249. return us->iobuf[0];
  1250. /* return the default -- no LUNs */
  1251. return 0;
  1252. }
  1253. #endif
  1254. /*
  1255. * This is called from a process context.
  1256. */
  1257. static void ub_revalidate(struct ub_dev *sc)
  1258. {
  1259. sc->readonly = 0; /* XXX Query this from the device */
  1260. sc->capacity.nsec = 0;
  1261. sc->capacity.bsize = 512;
  1262. sc->capacity.bshift = 0;
  1263. if (ub_sync_tur(sc) != 0)
  1264. return; /* Not ready */
  1265. sc->changed = 0;
  1266. if (ub_sync_read_cap(sc, &sc->capacity) != 0) {
  1267. /*
  1268. * The retry here means something is wrong, either with the
  1269. * device, with the transport, or with our code.
  1270. * We keep this because sd.c has retries for capacity.
  1271. */
  1272. if (ub_sync_read_cap(sc, &sc->capacity) != 0) {
  1273. sc->capacity.nsec = 0;
  1274. sc->capacity.bsize = 512;
  1275. sc->capacity.bshift = 0;
  1276. }
  1277. }
  1278. }
  1279. /*
  1280. * The open funcion.
  1281. * This is mostly needed to keep refcounting, but also to support
  1282. * media checks on removable media drives.
  1283. */
  1284. static int ub_bd_open(struct inode *inode, struct file *filp)
  1285. {
  1286. struct gendisk *disk = inode->i_bdev->bd_disk;
  1287. struct ub_dev *sc;
  1288. unsigned long flags;
  1289. int rc;
  1290. if ((sc = disk->private_data) == NULL)
  1291. return -ENXIO;
  1292. spin_lock_irqsave(&ub_lock, flags);
  1293. if (atomic_read(&sc->poison)) {
  1294. spin_unlock_irqrestore(&ub_lock, flags);
  1295. return -ENXIO;
  1296. }
  1297. sc->openc++;
  1298. spin_unlock_irqrestore(&ub_lock, flags);
  1299. /*
  1300. * This is a workaround for a specific problem in our block layer.
  1301. * In 2.6.9, register_disk duplicates the code from rescan_partitions.
  1302. * However, if we do add_disk with a device which persistently reports
  1303. * a changed media, add_disk calls register_disk, which does do_open,
  1304. * which will call rescan_paritions for changed media. After that,
  1305. * register_disk attempts to do it all again and causes double kobject
  1306. * registration and a eventually an oops on module removal.
  1307. *
  1308. * The bottom line is, Al Viro says that we should not allow
  1309. * bdev->bd_invalidated to be set when doing add_disk no matter what.
  1310. */
  1311. if (sc->first_open) {
  1312. if (sc->changed) {
  1313. sc->first_open = 0;
  1314. rc = -ENOMEDIUM;
  1315. goto err_open;
  1316. }
  1317. }
  1318. if (sc->removable || sc->readonly)
  1319. check_disk_change(inode->i_bdev);
  1320. /*
  1321. * The sd.c considers ->media_present and ->changed not equivalent,
  1322. * under some pretty murky conditions (a failure of READ CAPACITY).
  1323. * We may need it one day.
  1324. */
  1325. if (sc->removable && sc->changed && !(filp->f_flags & O_NDELAY)) {
  1326. rc = -ENOMEDIUM;
  1327. goto err_open;
  1328. }
  1329. if (sc->readonly && (filp->f_mode & FMODE_WRITE)) {
  1330. rc = -EROFS;
  1331. goto err_open;
  1332. }
  1333. return 0;
  1334. err_open:
  1335. ub_put(sc);
  1336. return rc;
  1337. }
  1338. /*
  1339. */
  1340. static int ub_bd_release(struct inode *inode, struct file *filp)
  1341. {
  1342. struct gendisk *disk = inode->i_bdev->bd_disk;
  1343. struct ub_dev *sc = disk->private_data;
  1344. ub_put(sc);
  1345. return 0;
  1346. }
  1347. /*
  1348. * The ioctl interface.
  1349. */
  1350. static int ub_bd_ioctl(struct inode *inode, struct file *filp,
  1351. unsigned int cmd, unsigned long arg)
  1352. {
  1353. struct gendisk *disk = inode->i_bdev->bd_disk;
  1354. void __user *usermem = (void __user *) arg;
  1355. return scsi_cmd_ioctl(filp, disk, cmd, usermem);
  1356. }
  1357. /*
  1358. * This is called once a new disk was seen by the block layer or by ub_probe().
  1359. * The main onjective here is to discover the features of the media such as
  1360. * the capacity, read-only status, etc. USB storage generally does not
  1361. * need to be spun up, but if we needed it, this would be the place.
  1362. *
  1363. * This call can sleep.
  1364. *
  1365. * The return code is not used.
  1366. */
  1367. static int ub_bd_revalidate(struct gendisk *disk)
  1368. {
  1369. struct ub_dev *sc = disk->private_data;
  1370. ub_revalidate(sc);
  1371. /* This is pretty much a long term P3 */
  1372. if (!atomic_read(&sc->poison)) { /* Cover sc->dev */
  1373. printk(KERN_INFO "%s: device %u capacity nsec %ld bsize %u\n",
  1374. sc->name, sc->dev->devnum,
  1375. sc->capacity.nsec, sc->capacity.bsize);
  1376. }
  1377. /* XXX Support sector size switching like in sr.c */
  1378. blk_queue_hardsect_size(disk->queue, sc->capacity.bsize);
  1379. set_capacity(disk, sc->capacity.nsec);
  1380. // set_disk_ro(sdkp->disk, sc->readonly);
  1381. return 0;
  1382. }
  1383. /*
  1384. * The check is called by the block layer to verify if the media
  1385. * is still available. It is supposed to be harmless, lightweight and
  1386. * non-intrusive in case the media was not changed.
  1387. *
  1388. * This call can sleep.
  1389. *
  1390. * The return code is bool!
  1391. */
  1392. static int ub_bd_media_changed(struct gendisk *disk)
  1393. {
  1394. struct ub_dev *sc = disk->private_data;
  1395. if (!sc->removable)
  1396. return 0;
  1397. /*
  1398. * We clean checks always after every command, so this is not
  1399. * as dangerous as it looks. If the TEST_UNIT_READY fails here,
  1400. * the device is actually not ready with operator or software
  1401. * intervention required. One dangerous item might be a drive which
  1402. * spins itself down, and come the time to write dirty pages, this
  1403. * will fail, then block layer discards the data. Since we never
  1404. * spin drives up, such devices simply cannot be used with ub anyway.
  1405. */
  1406. if (ub_sync_tur(sc) != 0) {
  1407. sc->changed = 1;
  1408. return 1;
  1409. }
  1410. return sc->changed;
  1411. }
  1412. static struct block_device_operations ub_bd_fops = {
  1413. .owner = THIS_MODULE,
  1414. .open = ub_bd_open,
  1415. .release = ub_bd_release,
  1416. .ioctl = ub_bd_ioctl,
  1417. .media_changed = ub_bd_media_changed,
  1418. .revalidate_disk = ub_bd_revalidate,
  1419. };
  1420. /*
  1421. * Common ->done routine for commands executed synchronously.
  1422. */
  1423. static void ub_probe_done(struct ub_dev *sc, struct ub_scsi_cmd *cmd)
  1424. {
  1425. struct completion *cop = cmd->back;
  1426. complete(cop);
  1427. }
  1428. /*
  1429. * Test if the device has a check condition on it, synchronously.
  1430. */
  1431. static int ub_sync_tur(struct ub_dev *sc)
  1432. {
  1433. struct ub_scsi_cmd *cmd;
  1434. enum { ALLOC_SIZE = sizeof(struct ub_scsi_cmd) };
  1435. unsigned long flags;
  1436. struct completion compl;
  1437. int rc;
  1438. init_completion(&compl);
  1439. rc = -ENOMEM;
  1440. if ((cmd = kmalloc(ALLOC_SIZE, GFP_KERNEL)) == NULL)
  1441. goto err_alloc;
  1442. memset(cmd, 0, ALLOC_SIZE);
  1443. cmd->cdb[0] = TEST_UNIT_READY;
  1444. cmd->cdb_len = 6;
  1445. cmd->dir = UB_DIR_NONE;
  1446. cmd->state = UB_CMDST_INIT;
  1447. cmd->done = ub_probe_done;
  1448. cmd->back = &compl;
  1449. spin_lock_irqsave(&sc->lock, flags);
  1450. cmd->tag = sc->tagcnt++;
  1451. rc = ub_submit_scsi(sc, cmd);
  1452. spin_unlock_irqrestore(&sc->lock, flags);
  1453. if (rc != 0) {
  1454. printk("ub: testing ready: submit error (%d)\n", rc); /* P3 */
  1455. goto err_submit;
  1456. }
  1457. wait_for_completion(&compl);
  1458. rc = cmd->error;
  1459. if (rc == -EIO && cmd->key != 0) /* Retries for benh's key */
  1460. rc = cmd->key;
  1461. err_submit:
  1462. kfree(cmd);
  1463. err_alloc:
  1464. return rc;
  1465. }
  1466. /*
  1467. * Read the SCSI capacity synchronously (for probing).
  1468. */
  1469. static int ub_sync_read_cap(struct ub_dev *sc, struct ub_capacity *ret)
  1470. {
  1471. struct ub_scsi_cmd *cmd;
  1472. char *p;
  1473. enum { ALLOC_SIZE = sizeof(struct ub_scsi_cmd) + 8 };
  1474. unsigned long flags;
  1475. unsigned int bsize, shift;
  1476. unsigned long nsec;
  1477. struct completion compl;
  1478. int rc;
  1479. init_completion(&compl);
  1480. rc = -ENOMEM;
  1481. if ((cmd = kmalloc(ALLOC_SIZE, GFP_KERNEL)) == NULL)
  1482. goto err_alloc;
  1483. memset(cmd, 0, ALLOC_SIZE);
  1484. p = (char *)cmd + sizeof(struct ub_scsi_cmd);
  1485. cmd->cdb[0] = 0x25;
  1486. cmd->cdb_len = 10;
  1487. cmd->dir = UB_DIR_READ;
  1488. cmd->state = UB_CMDST_INIT;
  1489. cmd->data = p;
  1490. cmd->len = 8;
  1491. cmd->done = ub_probe_done;
  1492. cmd->back = &compl;
  1493. spin_lock_irqsave(&sc->lock, flags);
  1494. cmd->tag = sc->tagcnt++;
  1495. rc = ub_submit_scsi(sc, cmd);
  1496. spin_unlock_irqrestore(&sc->lock, flags);
  1497. if (rc != 0) {
  1498. printk("ub: reading capacity: submit error (%d)\n", rc); /* P3 */
  1499. goto err_submit;
  1500. }
  1501. wait_for_completion(&compl);
  1502. if (cmd->error != 0) {
  1503. printk("ub: reading capacity: error %d\n", cmd->error); /* P3 */
  1504. rc = -EIO;
  1505. goto err_read;
  1506. }
  1507. if (cmd->act_len != 8) {
  1508. printk("ub: reading capacity: size %d\n", cmd->act_len); /* P3 */
  1509. rc = -EIO;
  1510. goto err_read;
  1511. }
  1512. /* sd.c special-cases sector size of 0 to mean 512. Needed? Safe? */
  1513. nsec = be32_to_cpu(*(__be32 *)p) + 1;
  1514. bsize = be32_to_cpu(*(__be32 *)(p + 4));
  1515. switch (bsize) {
  1516. case 512: shift = 0; break;
  1517. case 1024: shift = 1; break;
  1518. case 2048: shift = 2; break;
  1519. case 4096: shift = 3; break;
  1520. default:
  1521. printk("ub: Bad sector size %u\n", bsize); /* P3 */
  1522. rc = -EDOM;
  1523. goto err_inv_bsize;
  1524. }
  1525. ret->bsize = bsize;
  1526. ret->bshift = shift;
  1527. ret->nsec = nsec << shift;
  1528. rc = 0;
  1529. err_inv_bsize:
  1530. err_read:
  1531. err_submit:
  1532. kfree(cmd);
  1533. err_alloc:
  1534. return rc;
  1535. }
  1536. /*
  1537. */
  1538. static void ub_probe_urb_complete(struct urb *urb, struct pt_regs *pt)
  1539. {
  1540. struct completion *cop = urb->context;
  1541. complete(cop);
  1542. }
  1543. static void ub_probe_timeout(unsigned long arg)
  1544. {
  1545. struct completion *cop = (struct completion *) arg;
  1546. complete(cop);
  1547. }
  1548. /*
  1549. * Clear initial stalls.
  1550. */
  1551. static int ub_probe_clear_stall(struct ub_dev *sc, int stalled_pipe)
  1552. {
  1553. int endp;
  1554. struct usb_ctrlrequest *cr;
  1555. struct completion compl;
  1556. struct timer_list timer;
  1557. int rc;
  1558. init_completion(&compl);
  1559. endp = usb_pipeendpoint(stalled_pipe);
  1560. if (usb_pipein (stalled_pipe))
  1561. endp |= USB_DIR_IN;
  1562. cr = &sc->work_cr;
  1563. cr->bRequestType = USB_RECIP_ENDPOINT;
  1564. cr->bRequest = USB_REQ_CLEAR_FEATURE;
  1565. cr->wValue = cpu_to_le16(USB_ENDPOINT_HALT);
  1566. cr->wIndex = cpu_to_le16(endp);
  1567. cr->wLength = cpu_to_le16(0);
  1568. usb_fill_control_urb(&sc->work_urb, sc->dev, sc->send_ctrl_pipe,
  1569. (unsigned char*) cr, NULL, 0, ub_probe_urb_complete, &compl);
  1570. sc->work_urb.transfer_flags = 0;
  1571. sc->work_urb.actual_length = 0;
  1572. sc->work_urb.error_count = 0;
  1573. sc->work_urb.status = 0;
  1574. if ((rc = usb_submit_urb(&sc->work_urb, GFP_KERNEL)) != 0) {
  1575. printk(KERN_WARNING
  1576. "%s: Unable to submit a probe clear (%d)\n", sc->name, rc);
  1577. return rc;
  1578. }
  1579. init_timer(&timer);
  1580. timer.function = ub_probe_timeout;
  1581. timer.data = (unsigned long) &compl;
  1582. timer.expires = jiffies + UB_CTRL_TIMEOUT;
  1583. add_timer(&timer);
  1584. wait_for_completion(&compl);
  1585. del_timer_sync(&timer);
  1586. usb_kill_urb(&sc->work_urb);
  1587. /* reset the endpoint toggle */
  1588. usb_settoggle(sc->dev, endp, usb_pipeout(sc->last_pipe), 0);
  1589. return 0;
  1590. }
  1591. /*
  1592. * Get the pipe settings.
  1593. */
  1594. static int ub_get_pipes(struct ub_dev *sc, struct usb_device *dev,
  1595. struct usb_interface *intf)
  1596. {
  1597. struct usb_host_interface *altsetting = intf->cur_altsetting;
  1598. struct usb_endpoint_descriptor *ep_in = NULL;
  1599. struct usb_endpoint_descriptor *ep_out = NULL;
  1600. struct usb_endpoint_descriptor *ep;
  1601. int i;
  1602. /*
  1603. * Find the endpoints we need.
  1604. * We are expecting a minimum of 2 endpoints - in and out (bulk).
  1605. * We will ignore any others.
  1606. */
  1607. for (i = 0; i < altsetting->desc.bNumEndpoints; i++) {
  1608. ep = &altsetting->endpoint[i].desc;
  1609. /* Is it a BULK endpoint? */
  1610. if ((ep->bmAttributes & USB_ENDPOINT_XFERTYPE_MASK)
  1611. == USB_ENDPOINT_XFER_BULK) {
  1612. /* BULK in or out? */
  1613. if (ep->bEndpointAddress & USB_DIR_IN)
  1614. ep_in = ep;
  1615. else
  1616. ep_out = ep;
  1617. }
  1618. }
  1619. if (ep_in == NULL || ep_out == NULL) {
  1620. printk(KERN_NOTICE "%s: device %u failed endpoint check\n",
  1621. sc->name, sc->dev->devnum);
  1622. return -EIO;
  1623. }
  1624. /* Calculate and store the pipe values */
  1625. sc->send_ctrl_pipe = usb_sndctrlpipe(dev, 0);
  1626. sc->recv_ctrl_pipe = usb_rcvctrlpipe(dev, 0);
  1627. sc->send_bulk_pipe = usb_sndbulkpipe(dev,
  1628. ep_out->bEndpointAddress & USB_ENDPOINT_NUMBER_MASK);
  1629. sc->recv_bulk_pipe = usb_rcvbulkpipe(dev,
  1630. ep_in->bEndpointAddress & USB_ENDPOINT_NUMBER_MASK);
  1631. return 0;
  1632. }
  1633. /*
  1634. * Probing is done in the process context, which allows us to cheat
  1635. * and not to build a state machine for the discovery.
  1636. */
  1637. static int ub_probe(struct usb_interface *intf,
  1638. const struct usb_device_id *dev_id)
  1639. {
  1640. struct ub_dev *sc;
  1641. request_queue_t *q;
  1642. struct gendisk *disk;
  1643. int rc;
  1644. int i;
  1645. rc = -ENOMEM;
  1646. if ((sc = kmalloc(sizeof(struct ub_dev), GFP_KERNEL)) == NULL)
  1647. goto err_core;
  1648. memset(sc, 0, sizeof(struct ub_dev));
  1649. spin_lock_init(&sc->lock);
  1650. usb_init_urb(&sc->work_urb);
  1651. tasklet_init(&sc->tasklet, ub_scsi_action, (unsigned long)sc);
  1652. atomic_set(&sc->poison, 0);
  1653. init_timer(&sc->work_timer);
  1654. sc->work_timer.data = (unsigned long) sc;
  1655. sc->work_timer.function = ub_urb_timeout;
  1656. ub_init_completion(&sc->work_done);
  1657. sc->work_done.done = 1; /* A little yuk, but oh well... */
  1658. rc = -ENOSR;
  1659. if ((sc->id = ub_id_get()) == -1)
  1660. goto err_id;
  1661. snprintf(sc->name, 8, DRV_NAME "%c", sc->id + 'a');
  1662. sc->dev = interface_to_usbdev(intf);
  1663. sc->intf = intf;
  1664. // sc->ifnum = intf->cur_altsetting->desc.bInterfaceNumber;
  1665. usb_set_intfdata(intf, sc);
  1666. usb_get_dev(sc->dev);
  1667. // usb_get_intf(sc->intf); /* Do we need this? */
  1668. /* XXX Verify that we can handle the device (from descriptors) */
  1669. ub_get_pipes(sc, sc->dev, intf);
  1670. if (device_create_file(&sc->intf->dev, &dev_attr_diag) != 0)
  1671. goto err_diag;
  1672. /*
  1673. * At this point, all USB initialization is done, do upper layer.
  1674. * We really hate halfway initialized structures, so from the
  1675. * invariants perspective, this ub_dev is fully constructed at
  1676. * this point.
  1677. */
  1678. /*
  1679. * This is needed to clear toggles. It is a problem only if we do
  1680. * `rmmod ub && modprobe ub` without disconnects, but we like that.
  1681. */
  1682. ub_probe_clear_stall(sc, sc->recv_bulk_pipe);
  1683. ub_probe_clear_stall(sc, sc->send_bulk_pipe);
  1684. /*
  1685. * The way this is used by the startup code is a little specific.
  1686. * A SCSI check causes a USB stall. Our common case code sees it
  1687. * and clears the check, after which the device is ready for use.
  1688. * But if a check was not present, any command other than
  1689. * TEST_UNIT_READY ends with a lockup (including REQUEST_SENSE).
  1690. *
  1691. * If we neglect to clear the SCSI check, the first real command fails
  1692. * (which is the capacity readout). We clear that and retry, but why
  1693. * causing spurious retries for no reason.
  1694. *
  1695. * Revalidation may start with its own TEST_UNIT_READY, but that one
  1696. * has to succeed, so we clear checks with an additional one here.
  1697. * In any case it's not our business how revaliadation is implemented.
  1698. */
  1699. for (i = 0; i < 3; i++) { /* Retries for benh's key */
  1700. if ((rc = ub_sync_tur(sc)) <= 0) break;
  1701. if (rc != 0x6) break;
  1702. msleep(10);
  1703. }
  1704. sc->removable = 1; /* XXX Query this from the device */
  1705. sc->changed = 1; /* ub_revalidate clears only */
  1706. sc->first_open = 1;
  1707. ub_revalidate(sc);
  1708. /* This is pretty much a long term P3 */
  1709. printk(KERN_INFO "%s: device %u capacity nsec %ld bsize %u\n",
  1710. sc->name, sc->dev->devnum, sc->capacity.nsec, sc->capacity.bsize);
  1711. /*
  1712. * Just one disk per sc currently, but maybe more.
  1713. */
  1714. rc = -ENOMEM;
  1715. if ((disk = alloc_disk(UB_MINORS_PER_MAJOR)) == NULL)
  1716. goto err_diskalloc;
  1717. sc->disk = disk;
  1718. sprintf(disk->disk_name, DRV_NAME "%c", sc->id + 'a');
  1719. sprintf(disk->devfs_name, DEVFS_NAME "/%c", sc->id + 'a');
  1720. disk->major = UB_MAJOR;
  1721. disk->first_minor = sc->id * UB_MINORS_PER_MAJOR;
  1722. disk->fops = &ub_bd_fops;
  1723. disk->private_data = sc;
  1724. disk->driverfs_dev = &intf->dev;
  1725. rc = -ENOMEM;
  1726. if ((q = blk_init_queue(ub_bd_rq_fn, &sc->lock)) == NULL)
  1727. goto err_blkqinit;
  1728. disk->queue = q;
  1729. // blk_queue_bounce_limit(q, hba[i]->pdev->dma_mask);
  1730. blk_queue_max_hw_segments(q, UB_MAX_REQ_SG);
  1731. blk_queue_max_phys_segments(q, UB_MAX_REQ_SG);
  1732. // blk_queue_segment_boundary(q, CARM_SG_BOUNDARY);
  1733. blk_queue_max_sectors(q, UB_MAX_SECTORS);
  1734. blk_queue_hardsect_size(q, sc->capacity.bsize);
  1735. /*
  1736. * This is a serious infraction, caused by a deficiency in the
  1737. * USB sg interface (usb_sg_wait()). We plan to remove this once
  1738. * we get mileage on the driver and can justify a change to USB API.
  1739. * See blk_queue_bounce_limit() to understand this part.
  1740. *
  1741. * XXX And I still need to be aware of the DMA mask in the HC.
  1742. */
  1743. q->bounce_pfn = blk_max_low_pfn;
  1744. q->bounce_gfp = GFP_NOIO;
  1745. q->queuedata = sc;
  1746. set_capacity(disk, sc->capacity.nsec);
  1747. if (sc->removable)
  1748. disk->flags |= GENHD_FL_REMOVABLE;
  1749. add_disk(disk);
  1750. return 0;
  1751. err_blkqinit:
  1752. put_disk(disk);
  1753. err_diskalloc:
  1754. device_remove_file(&sc->intf->dev, &dev_attr_diag);
  1755. err_diag:
  1756. usb_set_intfdata(intf, NULL);
  1757. // usb_put_intf(sc->intf);
  1758. usb_put_dev(sc->dev);
  1759. ub_id_put(sc->id);
  1760. err_id:
  1761. kfree(sc);
  1762. err_core:
  1763. return rc;
  1764. }
  1765. static void ub_disconnect(struct usb_interface *intf)
  1766. {
  1767. struct ub_dev *sc = usb_get_intfdata(intf);
  1768. struct gendisk *disk = sc->disk;
  1769. unsigned long flags;
  1770. /*
  1771. * Prevent ub_bd_release from pulling the rug from under us.
  1772. * XXX This is starting to look like a kref.
  1773. * XXX Why not to take this ref at probe time?
  1774. */
  1775. spin_lock_irqsave(&ub_lock, flags);
  1776. sc->openc++;
  1777. spin_unlock_irqrestore(&ub_lock, flags);
  1778. /*
  1779. * Fence stall clearnings, operations triggered by unlinkings and so on.
  1780. * We do not attempt to unlink any URBs, because we do not trust the
  1781. * unlink paths in HC drivers. Also, we get -84 upon disconnect anyway.
  1782. */
  1783. atomic_set(&sc->poison, 1);
  1784. /*
  1785. * Blow away queued commands.
  1786. *
  1787. * Actually, this never works, because before we get here
  1788. * the HCD terminates outstanding URB(s). It causes our
  1789. * SCSI command queue to advance, commands fail to submit,
  1790. * and the whole queue drains. So, we just use this code to
  1791. * print warnings.
  1792. */
  1793. spin_lock_irqsave(&sc->lock, flags);
  1794. {
  1795. struct ub_scsi_cmd *cmd;
  1796. int cnt = 0;
  1797. while ((cmd = ub_cmdq_pop(sc)) != NULL) {
  1798. cmd->error = -ENOTCONN;
  1799. cmd->state = UB_CMDST_DONE;
  1800. ub_cmdtr_state(sc, cmd);
  1801. ub_cmdq_pop(sc);
  1802. (*cmd->done)(sc, cmd);
  1803. cnt++;
  1804. }
  1805. if (cnt != 0) {
  1806. printk(KERN_WARNING "%s: "
  1807. "%d was queued after shutdown\n", sc->name, cnt);
  1808. }
  1809. }
  1810. spin_unlock_irqrestore(&sc->lock, flags);
  1811. /*
  1812. * Unregister the upper layer.
  1813. */
  1814. if (disk->flags & GENHD_FL_UP)
  1815. del_gendisk(disk);
  1816. /*
  1817. * I wish I could do:
  1818. * set_bit(QUEUE_FLAG_DEAD, &q->queue_flags);
  1819. * As it is, we rely on our internal poisoning and let
  1820. * the upper levels to spin furiously failing all the I/O.
  1821. */
  1822. /*
  1823. * Taking a lock on a structure which is about to be freed
  1824. * is very nonsensual. Here it is largely a way to do a debug freeze,
  1825. * and a bracket which shows where the nonsensual code segment ends.
  1826. *
  1827. * Testing for -EINPROGRESS is always a bug, so we are bending
  1828. * the rules a little.
  1829. */
  1830. spin_lock_irqsave(&sc->lock, flags);
  1831. if (sc->work_urb.status == -EINPROGRESS) { /* janitors: ignore */
  1832. printk(KERN_WARNING "%s: "
  1833. "URB is active after disconnect\n", sc->name);
  1834. }
  1835. spin_unlock_irqrestore(&sc->lock, flags);
  1836. /*
  1837. * There is virtually no chance that other CPU runs times so long
  1838. * after ub_urb_complete should have called del_timer, but only if HCD
  1839. * didn't forget to deliver a callback on unlink.
  1840. */
  1841. del_timer_sync(&sc->work_timer);
  1842. /*
  1843. * At this point there must be no commands coming from anyone
  1844. * and no URBs left in transit.
  1845. */
  1846. device_remove_file(&sc->intf->dev, &dev_attr_diag);
  1847. usb_set_intfdata(intf, NULL);
  1848. // usb_put_intf(sc->intf);
  1849. sc->intf = NULL;
  1850. usb_put_dev(sc->dev);
  1851. sc->dev = NULL;
  1852. ub_put(sc);
  1853. }
  1854. static struct usb_driver ub_driver = {
  1855. .owner = THIS_MODULE,
  1856. .name = "ub",
  1857. .probe = ub_probe,
  1858. .disconnect = ub_disconnect,
  1859. .id_table = ub_usb_ids,
  1860. };
  1861. static int __init ub_init(void)
  1862. {
  1863. int rc;
  1864. /* P3 */ printk("ub: sizeof ub_scsi_cmd %zu ub_dev %zu\n",
  1865. sizeof(struct ub_scsi_cmd), sizeof(struct ub_dev));
  1866. if ((rc = register_blkdev(UB_MAJOR, DRV_NAME)) != 0)
  1867. goto err_regblkdev;
  1868. devfs_mk_dir(DEVFS_NAME);
  1869. if ((rc = usb_register(&ub_driver)) != 0)
  1870. goto err_register;
  1871. return 0;
  1872. err_register:
  1873. devfs_remove(DEVFS_NAME);
  1874. unregister_blkdev(UB_MAJOR, DRV_NAME);
  1875. err_regblkdev:
  1876. return rc;
  1877. }
  1878. static void __exit ub_exit(void)
  1879. {
  1880. usb_deregister(&ub_driver);
  1881. devfs_remove(DEVFS_NAME);
  1882. unregister_blkdev(UB_MAJOR, DRV_NAME);
  1883. }
  1884. module_init(ub_init);
  1885. module_exit(ub_exit);
  1886. MODULE_LICENSE("GPL");