]> git.proxmox.com Git - mirror_ubuntu-jammy-kernel.git/blame - drivers/scsi/scsi_debug.c
scsi: core: Introduce scsi_devinfo_key enumeration type
[mirror_ubuntu-jammy-kernel.git] / drivers / scsi / scsi_debug.c
CommitLineData
1da177e4 1/*
1da177e4
LT
2 * vvvvvvvvvvvvvvvvvvvvvvv Original vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
3 * Copyright (C) 1992 Eric Youngdale
4 * Simulate a host adapter with 2 disks attached. Do a lot of checking
5 * to make sure that we are not getting blocks mixed up, and PANIC if
6 * anything out of the ordinary is seen.
7 * ^^^^^^^^^^^^^^^^^^^^^^^ Original ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
8 *
773642d9 9 * Copyright (C) 2001 - 2016 Douglas Gilbert
1da177e4 10 *
773642d9
DG
11 * This program is free software; you can redistribute it and/or modify
12 * it under the terms of the GNU General Public License as published by
13 * the Free Software Foundation; either version 2, or (at your option)
14 * any later version.
1da177e4 15 *
78d4e5a0 16 * For documentation see http://sg.danny.cz/sg/sdebug26.html
1da177e4 17 *
1da177e4
LT
18 */
19
c1287970
TW
20
21#define pr_fmt(fmt) KBUILD_MODNAME ":%s: " fmt, __func__
22
1da177e4
LT
23#include <linux/module.h>
24
25#include <linux/kernel.h>
1da177e4 26#include <linux/errno.h>
b333a819 27#include <linux/jiffies.h>
5a0e3ad6 28#include <linux/slab.h>
1da177e4
LT
29#include <linux/types.h>
30#include <linux/string.h>
31#include <linux/genhd.h>
32#include <linux/fs.h>
33#include <linux/init.h>
34#include <linux/proc_fs.h>
1da177e4
LT
35#include <linux/vmalloc.h>
36#include <linux/moduleparam.h>
852e034d 37#include <linux/scatterlist.h>
1da177e4 38#include <linux/blkdev.h>
c6a44287 39#include <linux/crc-t10dif.h>
cbf67842
DG
40#include <linux/spinlock.h>
41#include <linux/interrupt.h>
42#include <linux/atomic.h>
43#include <linux/hrtimer.h>
09ba24c1 44#include <linux/uuid.h>
6ebf105c 45#include <linux/t10-pi.h>
c6a44287
MP
46
47#include <net/checksum.h>
9ff26eef 48
44d92694
MP
49#include <asm/unaligned.h>
50
9ff26eef
FT
51#include <scsi/scsi.h>
52#include <scsi/scsi_cmnd.h>
53#include <scsi/scsi_device.h>
1da177e4
LT
54#include <scsi/scsi_host.h>
55#include <scsi/scsicam.h>
a34c4e98 56#include <scsi/scsi_eh.h>
cbf67842 57#include <scsi/scsi_tcq.h>
395cef03 58#include <scsi/scsi_dbg.h>
1da177e4 59
c6a44287 60#include "sd.h"
1da177e4 61#include "scsi_logging.h"
1da177e4 62
773642d9 63/* make sure inq_product_rev string corresponds to this version */
b01f6f83
DG
64#define SDEBUG_VERSION "1.86"
65static const char *sdebug_version_date = "20160430";
cbf67842
DG
66
67#define MY_NAME "scsi_debug"
1da177e4 68
6f3cbf55 69/* Additional Sense Code (ASC) */
c65b1445
DG
70#define NO_ADDITIONAL_SENSE 0x0
71#define LOGICAL_UNIT_NOT_READY 0x4
c2248fc9 72#define LOGICAL_UNIT_COMMUNICATION_FAILURE 0x8
1da177e4 73#define UNRECOVERED_READ_ERR 0x11
c65b1445 74#define PARAMETER_LIST_LENGTH_ERR 0x1a
1da177e4 75#define INVALID_OPCODE 0x20
22017ed2 76#define LBA_OUT_OF_RANGE 0x21
1da177e4 77#define INVALID_FIELD_IN_CDB 0x24
c65b1445 78#define INVALID_FIELD_IN_PARAM_LIST 0x26
cbf67842
DG
79#define UA_RESET_ASC 0x29
80#define UA_CHANGED_ASC 0x2a
19c8ead7
EM
81#define TARGET_CHANGED_ASC 0x3f
82#define LUNS_CHANGED_ASCQ 0x0e
22017ed2
DG
83#define INSUFF_RES_ASC 0x55
84#define INSUFF_RES_ASCQ 0x3
cbf67842
DG
85#define POWER_ON_RESET_ASCQ 0x0
86#define BUS_RESET_ASCQ 0x2 /* scsi bus reset occurred */
87#define MODE_CHANGED_ASCQ 0x1 /* mode parameters changed */
22017ed2 88#define CAPACITY_CHANGED_ASCQ 0x9
1da177e4 89#define SAVING_PARAMS_UNSUP 0x39
6f3cbf55 90#define TRANSPORT_PROBLEM 0x4b
c65b1445
DG
91#define THRESHOLD_EXCEEDED 0x5d
92#define LOW_POWER_COND_ON 0x5e
22017ed2 93#define MISCOMPARE_VERIFY_ASC 0x1d
acafd0b9
EM
94#define MICROCODE_CHANGED_ASCQ 0x1 /* with TARGET_CHANGED_ASC */
95#define MICROCODE_CHANGED_WO_RESET_ASCQ 0x16
1da177e4 96
6f3cbf55
DG
97/* Additional Sense Code Qualifier (ASCQ) */
98#define ACK_NAK_TO 0x3
99
1da177e4
LT
100/* Default values for driver parameters */
101#define DEF_NUM_HOST 1
102#define DEF_NUM_TGTS 1
103#define DEF_MAX_LUNS 1
104/* With these defaults, this driver will make 1 host with 1 target
105 * (id 0) containing 1 logical unit (lun 0). That is 1 device.
106 */
5b94e232 107#define DEF_ATO 1
c2206098 108#define DEF_JDELAY 1 /* if > 0 unit is a jiffy */
1da177e4 109#define DEF_DEV_SIZE_MB 8
5b94e232
MP
110#define DEF_DIF 0
111#define DEF_DIX 0
1da177e4 112#define DEF_D_SENSE 0
5b94e232 113#define DEF_EVERY_NTH 0
23183910 114#define DEF_FAKE_RW 0
c6a44287 115#define DEF_GUARD 0
cbf67842 116#define DEF_HOST_LOCK 0
5b94e232
MP
117#define DEF_LBPU 0
118#define DEF_LBPWS 0
119#define DEF_LBPWS10 0
be1dd78d 120#define DEF_LBPRZ 1
ea61fca5 121#define DEF_LOWEST_ALIGNED 0
cbf67842 122#define DEF_NDELAY 0 /* if > 0 unit is a nanosecond */
5b94e232
MP
123#define DEF_NO_LUN_0 0
124#define DEF_NUM_PARTS 0
125#define DEF_OPTS 0
32c5844a 126#define DEF_OPT_BLKS 1024
5b94e232 127#define DEF_PHYSBLK_EXP 0
86e6828a 128#define DEF_OPT_XFERLEN_EXP 0
b01f6f83 129#define DEF_PTYPE TYPE_DISK
d986788b 130#define DEF_REMOVABLE false
760f3b03 131#define DEF_SCSI_LEVEL 7 /* INQUIRY, byte2 [6->SPC-4; 7->SPC-5] */
5b94e232
MP
132#define DEF_SECTOR_SIZE 512
133#define DEF_UNMAP_ALIGNMENT 0
134#define DEF_UNMAP_GRANULARITY 1
6014759c
MP
135#define DEF_UNMAP_MAX_BLOCKS 0xFFFFFFFF
136#define DEF_UNMAP_MAX_DESC 256
5b94e232
MP
137#define DEF_VIRTUAL_GB 0
138#define DEF_VPD_USE_HOSTNO 1
139#define DEF_WRITESAME_LENGTH 0xFFFF
c2248fc9 140#define DEF_STRICT 0
c4837394
DG
141#define DEF_STATISTICS false
142#define DEF_SUBMIT_QUEUES 1
09ba24c1 143#define DEF_UUID_CTL 0
c2206098 144#define JDELAY_OVERRIDDEN -9999
1da177e4 145
b01f6f83
DG
146#define SDEBUG_LUN_0_VAL 0
147
773642d9
DG
148/* bit mask values for sdebug_opts */
149#define SDEBUG_OPT_NOISE 1
150#define SDEBUG_OPT_MEDIUM_ERR 2
151#define SDEBUG_OPT_TIMEOUT 4
152#define SDEBUG_OPT_RECOVERED_ERR 8
153#define SDEBUG_OPT_TRANSPORT_ERR 16
154#define SDEBUG_OPT_DIF_ERR 32
155#define SDEBUG_OPT_DIX_ERR 64
156#define SDEBUG_OPT_MAC_TIMEOUT 128
157#define SDEBUG_OPT_SHORT_TRANSFER 0x100
158#define SDEBUG_OPT_Q_NOISE 0x200
159#define SDEBUG_OPT_ALL_TSF 0x400
160#define SDEBUG_OPT_RARE_TSF 0x800
161#define SDEBUG_OPT_N_WCE 0x1000
162#define SDEBUG_OPT_RESET_NOISE 0x2000
163#define SDEBUG_OPT_NO_CDB_NOISE 0x4000
164#define SDEBUG_OPT_ALL_NOISE (SDEBUG_OPT_NOISE | SDEBUG_OPT_Q_NOISE | \
165 SDEBUG_OPT_RESET_NOISE)
166#define SDEBUG_OPT_ALL_INJECTING (SDEBUG_OPT_RECOVERED_ERR | \
167 SDEBUG_OPT_TRANSPORT_ERR | \
168 SDEBUG_OPT_DIF_ERR | SDEBUG_OPT_DIX_ERR | \
169 SDEBUG_OPT_SHORT_TRANSFER)
1da177e4 170/* When "every_nth" > 0 then modulo "every_nth" commands:
fd32119b 171 * - a missing response is simulated if SDEBUG_OPT_TIMEOUT is set
1da177e4 172 * - a RECOVERED_ERROR is simulated on successful read and write
773642d9 173 * commands if SDEBUG_OPT_RECOVERED_ERR is set.
6f3cbf55 174 * - a TRANSPORT_ERROR is simulated on successful read and write
773642d9 175 * commands if SDEBUG_OPT_TRANSPORT_ERR is set.
1da177e4
LT
176 *
177 * When "every_nth" < 0 then after "- every_nth" commands:
fd32119b 178 * - a missing response is simulated if SDEBUG_OPT_TIMEOUT is set
1da177e4 179 * - a RECOVERED_ERROR is simulated on successful read and write
773642d9 180 * commands if SDEBUG_OPT_RECOVERED_ERR is set.
6f3cbf55 181 * - a TRANSPORT_ERROR is simulated on successful read and write
773642d9
DG
182 * commands if _DEBUG_OPT_TRANSPORT_ERR is set.
183 * This will continue on every subsequent command until some other action
184 * occurs (e.g. the user * writing a new value (other than -1 or 1) to
185 * every_nth via sysfs).
1da177e4
LT
186 */
187
fd32119b 188/* As indicated in SAM-5 and SPC-4 Unit Attentions (UAs) are returned in
cbf67842
DG
189 * priority order. In the subset implemented here lower numbers have higher
190 * priority. The UA numbers should be a sequence starting from 0 with
191 * SDEBUG_NUM_UAS being 1 higher than the highest numbered UA. */
192#define SDEBUG_UA_POR 0 /* Power on, reset, or bus device reset */
193#define SDEBUG_UA_BUS_RESET 1
194#define SDEBUG_UA_MODE_CHANGED 2
0d01c5df 195#define SDEBUG_UA_CAPACITY_CHANGED 3
19c8ead7 196#define SDEBUG_UA_LUNS_CHANGED 4
acafd0b9
EM
197#define SDEBUG_UA_MICROCODE_CHANGED 5 /* simulate firmware change */
198#define SDEBUG_UA_MICROCODE_CHANGED_WO_RESET 6
199#define SDEBUG_NUM_UAS 7
cbf67842 200
773642d9 201/* when 1==SDEBUG_OPT_MEDIUM_ERR, a medium error is simulated at this
1da177e4
LT
202 * sector on read commands: */
203#define OPT_MEDIUM_ERR_ADDR 0x1234 /* that's sector 4660 in decimal */
32f7ef73 204#define OPT_MEDIUM_ERR_NUM 10 /* number of consecutive medium errs */
1da177e4
LT
205
206/* If REPORT LUNS has luns >= 256 it can choose "flat space" (value 1)
207 * or "peripheral device" addressing (value 0) */
208#define SAM2_LUN_ADDRESS_METHOD 0
209
c4837394
DG
210/* SDEBUG_CANQUEUE is the maximum number of commands that can be queued
211 * (for response) per submit queue at one time. Can be reduced by max_queue
212 * option. Command responses are not queued when jdelay=0 and ndelay=0. The
213 * per-device DEF_CMD_PER_LUN can be changed via sysfs:
214 * /sys/class/scsi_device/<h:c:t:l>/device/queue_depth
215 * but cannot exceed SDEBUG_CANQUEUE .
216 */
217#define SDEBUG_CANQUEUE_WORDS 3 /* a WORD is bits in a long */
218#define SDEBUG_CANQUEUE (SDEBUG_CANQUEUE_WORDS * BITS_PER_LONG)
cbf67842
DG
219#define DEF_CMD_PER_LUN 255
220
fd32119b
DG
221#define F_D_IN 1
222#define F_D_OUT 2
223#define F_D_OUT_MAYBE 4 /* WRITE SAME, NDOB bit */
224#define F_D_UNKN 8
225#define F_RL_WLUN_OK 0x10
226#define F_SKIP_UA 0x20
227#define F_DELAY_OVERR 0x40
228#define F_SA_LOW 0x80 /* cdb byte 1, bits 4 to 0 */
229#define F_SA_HIGH 0x100 /* as used by variable length cdbs */
230#define F_INV_OP 0x200
231#define F_FAKE_RW 0x400
232#define F_M_ACCESS 0x800 /* media access */
233
234#define FF_RESPOND (F_RL_WLUN_OK | F_SKIP_UA | F_DELAY_OVERR)
235#define FF_DIRECT_IO (F_M_ACCESS | F_FAKE_RW)
236#define FF_SA (F_SA_HIGH | F_SA_LOW)
237
238#define SDEBUG_MAX_PARTS 4
239
b01f6f83 240#define SDEBUG_MAX_CMD_LEN 32
fd32119b
DG
241
242
243struct sdebug_dev_info {
244 struct list_head dev_list;
245 unsigned int channel;
246 unsigned int target;
247 u64 lun;
bf476433 248 uuid_t lu_name;
fd32119b
DG
249 struct sdebug_host_info *sdbg_host;
250 unsigned long uas_bm[1];
251 atomic_t num_in_q;
c4837394 252 atomic_t stopped;
fd32119b
DG
253 bool used;
254};
255
256struct sdebug_host_info {
257 struct list_head host_list;
258 struct Scsi_Host *shost;
259 struct device dev;
260 struct list_head dev_info_list;
261};
262
263#define to_sdebug_host(d) \
264 container_of(d, struct sdebug_host_info, dev)
265
266struct sdebug_defer {
267 struct hrtimer hrt;
268 struct execute_work ew;
c4837394
DG
269 int sqa_idx; /* index of sdebug_queue array */
270 int qc_idx; /* index of sdebug_queued_cmd array within sqa_idx */
271 int issuing_cpu;
fd32119b
DG
272};
273
274struct sdebug_queued_cmd {
c4837394
DG
275 /* corresponding bit set in in_use_bm[] in owning struct sdebug_queue
276 * instance indicates this slot is in use.
277 */
fd32119b
DG
278 struct sdebug_defer *sd_dp;
279 struct scsi_cmnd *a_cmnd;
c4837394
DG
280 unsigned int inj_recovered:1;
281 unsigned int inj_transport:1;
282 unsigned int inj_dif:1;
283 unsigned int inj_dix:1;
284 unsigned int inj_short:1;
fd32119b
DG
285};
286
c4837394
DG
287struct sdebug_queue {
288 struct sdebug_queued_cmd qc_arr[SDEBUG_CANQUEUE];
289 unsigned long in_use_bm[SDEBUG_CANQUEUE_WORDS];
290 spinlock_t qc_lock;
291 atomic_t blocked; /* to temporarily stop more being queued */
fd32119b
DG
292};
293
c4837394
DG
294static atomic_t sdebug_cmnd_count; /* number of incoming commands */
295static atomic_t sdebug_completions; /* count of deferred completions */
296static atomic_t sdebug_miss_cpus; /* submission + completion cpus differ */
297static atomic_t sdebug_a_tsf; /* 'almost task set full' counter */
298
fd32119b 299struct opcode_info_t {
b01f6f83
DG
300 u8 num_attached; /* 0 if this is it (i.e. a leaf); use 0xff */
301 /* for terminating element */
fd32119b
DG
302 u8 opcode; /* if num_attached > 0, preferred */
303 u16 sa; /* service action */
304 u32 flags; /* OR-ed set of SDEB_F_* */
305 int (*pfp)(struct scsi_cmnd *, struct sdebug_dev_info *);
306 const struct opcode_info_t *arrp; /* num_attached elements or NULL */
307 u8 len_mask[16]; /* len=len_mask[0], then mask for cdb[1]... */
308 /* ignore cdb bytes after position 15 */
309};
310
311/* SCSI opcodes (first byte of cdb) of interest mapped onto these indexes */
c2248fc9
DG
312enum sdeb_opcode_index {
313 SDEB_I_INVALID_OPCODE = 0,
314 SDEB_I_INQUIRY = 1,
315 SDEB_I_REPORT_LUNS = 2,
316 SDEB_I_REQUEST_SENSE = 3,
317 SDEB_I_TEST_UNIT_READY = 4,
318 SDEB_I_MODE_SENSE = 5, /* 6, 10 */
319 SDEB_I_MODE_SELECT = 6, /* 6, 10 */
320 SDEB_I_LOG_SENSE = 7,
321 SDEB_I_READ_CAPACITY = 8, /* 10; 16 is in SA_IN(16) */
322 SDEB_I_READ = 9, /* 6, 10, 12, 16 */
323 SDEB_I_WRITE = 10, /* 6, 10, 12, 16 */
324 SDEB_I_START_STOP = 11,
325 SDEB_I_SERV_ACT_IN = 12, /* 12, 16 */
326 SDEB_I_SERV_ACT_OUT = 13, /* 12, 16 */
327 SDEB_I_MAINT_IN = 14,
328 SDEB_I_MAINT_OUT = 15,
329 SDEB_I_VERIFY = 16, /* 10 only */
330 SDEB_I_VARIABLE_LEN = 17,
331 SDEB_I_RESERVE = 18, /* 6, 10 */
332 SDEB_I_RELEASE = 19, /* 6, 10 */
333 SDEB_I_ALLOW_REMOVAL = 20, /* PREVENT ALLOW MEDIUM REMOVAL */
334 SDEB_I_REZERO_UNIT = 21, /* REWIND in SSC */
335 SDEB_I_ATA_PT = 22, /* 12, 16 */
336 SDEB_I_SEND_DIAG = 23,
337 SDEB_I_UNMAP = 24,
338 SDEB_I_XDWRITEREAD = 25, /* 10 only */
339 SDEB_I_WRITE_BUFFER = 26,
340 SDEB_I_WRITE_SAME = 27, /* 10, 16 */
341 SDEB_I_SYNC_CACHE = 28, /* 10 only */
342 SDEB_I_COMP_WRITE = 29,
343 SDEB_I_LAST_ELEMENT = 30, /* keep this last */
344};
345
c4837394 346
c2248fc9
DG
347static const unsigned char opcode_ind_arr[256] = {
348/* 0x0; 0x0->0x1f: 6 byte cdbs */
349 SDEB_I_TEST_UNIT_READY, SDEB_I_REZERO_UNIT, 0, SDEB_I_REQUEST_SENSE,
350 0, 0, 0, 0,
351 SDEB_I_READ, 0, SDEB_I_WRITE, 0, 0, 0, 0, 0,
352 0, 0, SDEB_I_INQUIRY, 0, 0, SDEB_I_MODE_SELECT, SDEB_I_RESERVE,
353 SDEB_I_RELEASE,
354 0, 0, SDEB_I_MODE_SENSE, SDEB_I_START_STOP, 0, SDEB_I_SEND_DIAG,
355 SDEB_I_ALLOW_REMOVAL, 0,
356/* 0x20; 0x20->0x3f: 10 byte cdbs */
357 0, 0, 0, 0, 0, SDEB_I_READ_CAPACITY, 0, 0,
358 SDEB_I_READ, 0, SDEB_I_WRITE, 0, 0, 0, 0, SDEB_I_VERIFY,
359 0, 0, 0, 0, 0, SDEB_I_SYNC_CACHE, 0, 0,
360 0, 0, 0, SDEB_I_WRITE_BUFFER, 0, 0, 0, 0,
361/* 0x40; 0x40->0x5f: 10 byte cdbs */
362 0, SDEB_I_WRITE_SAME, SDEB_I_UNMAP, 0, 0, 0, 0, 0,
363 0, 0, 0, 0, 0, SDEB_I_LOG_SENSE, 0, 0,
364 0, 0, 0, SDEB_I_XDWRITEREAD, 0, SDEB_I_MODE_SELECT, SDEB_I_RESERVE,
365 SDEB_I_RELEASE,
366 0, 0, SDEB_I_MODE_SENSE, 0, 0, 0, 0, 0,
fd32119b 367/* 0x60; 0x60->0x7d are reserved, 0x7e is "extended cdb" */
c2248fc9
DG
368 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
369 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
370 0, SDEB_I_VARIABLE_LEN,
371/* 0x80; 0x80->0x9f: 16 byte cdbs */
372 0, 0, 0, 0, 0, SDEB_I_ATA_PT, 0, 0,
373 SDEB_I_READ, SDEB_I_COMP_WRITE, SDEB_I_WRITE, 0, 0, 0, 0, 0,
374 0, 0, 0, SDEB_I_WRITE_SAME, 0, 0, 0, 0,
375 0, 0, 0, 0, 0, 0, SDEB_I_SERV_ACT_IN, SDEB_I_SERV_ACT_OUT,
376/* 0xa0; 0xa0->0xbf: 12 byte cdbs */
377 SDEB_I_REPORT_LUNS, SDEB_I_ATA_PT, 0, SDEB_I_MAINT_IN,
378 SDEB_I_MAINT_OUT, 0, 0, 0,
379 SDEB_I_READ, SDEB_I_SERV_ACT_OUT, SDEB_I_WRITE, SDEB_I_SERV_ACT_IN,
380 0, 0, 0, 0,
381 0, 0, 0, 0, 0, 0, 0, 0,
382 0, 0, 0, 0, 0, 0, 0, 0,
383/* 0xc0; 0xc0->0xff: vendor specific */
384 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
385 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
386 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
387 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
388};
389
c2248fc9
DG
390static int resp_inquiry(struct scsi_cmnd *, struct sdebug_dev_info *);
391static int resp_report_luns(struct scsi_cmnd *, struct sdebug_dev_info *);
392static int resp_requests(struct scsi_cmnd *, struct sdebug_dev_info *);
393static int resp_mode_sense(struct scsi_cmnd *, struct sdebug_dev_info *);
394static int resp_mode_select(struct scsi_cmnd *, struct sdebug_dev_info *);
395static int resp_log_sense(struct scsi_cmnd *, struct sdebug_dev_info *);
396static int resp_readcap(struct scsi_cmnd *, struct sdebug_dev_info *);
397static int resp_read_dt0(struct scsi_cmnd *, struct sdebug_dev_info *);
398static int resp_write_dt0(struct scsi_cmnd *, struct sdebug_dev_info *);
399static int resp_start_stop(struct scsi_cmnd *, struct sdebug_dev_info *);
400static int resp_readcap16(struct scsi_cmnd *, struct sdebug_dev_info *);
401static int resp_get_lba_status(struct scsi_cmnd *, struct sdebug_dev_info *);
402static int resp_report_tgtpgs(struct scsi_cmnd *, struct sdebug_dev_info *);
403static int resp_unmap(struct scsi_cmnd *, struct sdebug_dev_info *);
38d5c833
DG
404static int resp_rsup_opcodes(struct scsi_cmnd *, struct sdebug_dev_info *);
405static int resp_rsup_tmfs(struct scsi_cmnd *, struct sdebug_dev_info *);
c2248fc9
DG
406static int resp_write_same_10(struct scsi_cmnd *, struct sdebug_dev_info *);
407static int resp_write_same_16(struct scsi_cmnd *, struct sdebug_dev_info *);
408static int resp_xdwriteread_10(struct scsi_cmnd *, struct sdebug_dev_info *);
38d5c833 409static int resp_comp_write(struct scsi_cmnd *, struct sdebug_dev_info *);
acafd0b9 410static int resp_write_buffer(struct scsi_cmnd *, struct sdebug_dev_info *);
c2248fc9 411
c2248fc9
DG
412static const struct opcode_info_t msense_iarr[1] = {
413 {0, 0x1a, 0, F_D_IN, NULL, NULL,
414 {6, 0xe8, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
415};
416
417static const struct opcode_info_t mselect_iarr[1] = {
418 {0, 0x15, 0, F_D_OUT, NULL, NULL,
419 {6, 0xf1, 0, 0, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
420};
421
422static const struct opcode_info_t read_iarr[3] = {
423 {0, 0x28, 0, F_D_IN | FF_DIRECT_IO, resp_read_dt0, NULL,/* READ(10) */
424 {10, 0xff, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff, 0xff, 0xc7, 0, 0,
425 0, 0, 0, 0} },
426 {0, 0x8, 0, F_D_IN | FF_DIRECT_IO, resp_read_dt0, NULL, /* READ(6) */
427 {6, 0xff, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
428 {0, 0xa8, 0, F_D_IN | FF_DIRECT_IO, resp_read_dt0, NULL,/* READ(12) */
429 {12, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x9f,
430 0xc7, 0, 0, 0, 0} },
431};
432
433static const struct opcode_info_t write_iarr[3] = {
434 {0, 0x2a, 0, F_D_OUT | FF_DIRECT_IO, resp_write_dt0, NULL, /* 10 */
435 {10, 0xfb, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff, 0xff, 0xc7, 0, 0,
436 0, 0, 0, 0} },
437 {0, 0xa, 0, F_D_OUT | FF_DIRECT_IO, resp_write_dt0, NULL, /* 6 */
438 {6, 0xff, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
439 {0, 0xaa, 0, F_D_OUT | FF_DIRECT_IO, resp_write_dt0, NULL, /* 12 */
440 {12, 0xfb, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x9f,
441 0xc7, 0, 0, 0, 0} },
442};
443
444static const struct opcode_info_t sa_in_iarr[1] = {
445 {0, 0x9e, 0x12, F_SA_LOW | F_D_IN, resp_get_lba_status, NULL,
446 {16, 0x12, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
447 0xff, 0xff, 0xff, 0, 0xc7} },
448};
449
450static const struct opcode_info_t vl_iarr[1] = { /* VARIABLE LENGTH */
451 {0, 0x7f, 0xb, F_SA_HIGH | F_D_OUT | FF_DIRECT_IO, resp_write_dt0,
452 NULL, {32, 0xc7, 0, 0, 0, 0, 0x1f, 0x18, 0x0, 0xb, 0xfa,
453 0, 0xff, 0xff, 0xff, 0xff} }, /* WRITE(32) */
454};
455
456static const struct opcode_info_t maint_in_iarr[2] = {
38d5c833 457 {0, 0xa3, 0xc, F_SA_LOW | F_D_IN, resp_rsup_opcodes, NULL,
c2248fc9
DG
458 {12, 0xc, 0x87, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0,
459 0xc7, 0, 0, 0, 0} },
38d5c833 460 {0, 0xa3, 0xd, F_SA_LOW | F_D_IN, resp_rsup_tmfs, NULL,
c2248fc9
DG
461 {12, 0xd, 0x80, 0, 0, 0, 0xff, 0xff, 0xff, 0xff, 0, 0xc7, 0, 0,
462 0, 0} },
463};
464
465static const struct opcode_info_t write_same_iarr[1] = {
466 {0, 0x93, 0, F_D_OUT_MAYBE | FF_DIRECT_IO, resp_write_same_16, NULL,
467 {16, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
468 0xff, 0xff, 0xff, 0x1f, 0xc7} },
469};
470
471static const struct opcode_info_t reserve_iarr[1] = {
472 {0, 0x16, 0, F_D_OUT, NULL, NULL, /* RESERVE(6) */
473 {6, 0x1f, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
474};
475
476static const struct opcode_info_t release_iarr[1] = {
477 {0, 0x17, 0, F_D_OUT, NULL, NULL, /* RELEASE(6) */
478 {6, 0x1f, 0xff, 0, 0, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
479};
480
481
482/* This array is accessed via SDEB_I_* values. Make sure all are mapped,
483 * plus the terminating elements for logic that scans this table such as
484 * REPORT SUPPORTED OPERATION CODES. */
485static const struct opcode_info_t opcode_info_arr[SDEB_I_LAST_ELEMENT + 1] = {
486/* 0 */
487 {0, 0, 0, F_INV_OP | FF_RESPOND, NULL, NULL,
488 {0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
489 {0, 0x12, 0, FF_RESPOND | F_D_IN, resp_inquiry, NULL,
490 {6, 0xe3, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
491 {0, 0xa0, 0, FF_RESPOND | F_D_IN, resp_report_luns, NULL,
492 {12, 0xe3, 0xff, 0, 0, 0, 0xff, 0xff, 0xff, 0xff, 0, 0xc7, 0, 0,
493 0, 0} },
494 {0, 0x3, 0, FF_RESPOND | F_D_IN, resp_requests, NULL,
495 {6, 0xe1, 0, 0, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
496 {0, 0x0, 0, F_M_ACCESS | F_RL_WLUN_OK, NULL, NULL,/* TEST UNIT READY */
497 {6, 0, 0, 0, 0, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
498 {1, 0x5a, 0, F_D_IN, resp_mode_sense, msense_iarr,
499 {10, 0xf8, 0xff, 0xff, 0, 0, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0,
500 0} },
501 {1, 0x55, 0, F_D_OUT, resp_mode_select, mselect_iarr,
502 {10, 0xf1, 0, 0, 0, 0, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0} },
503 {0, 0x4d, 0, F_D_IN, resp_log_sense, NULL,
504 {10, 0xe3, 0xff, 0xff, 0, 0xff, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0,
505 0, 0, 0} },
506 {0, 0x25, 0, F_D_IN, resp_readcap, NULL,
507 {10, 0xe1, 0xff, 0xff, 0xff, 0xff, 0, 0, 0x1, 0xc7, 0, 0, 0, 0,
508 0, 0} },
509 {3, 0x88, 0, F_D_IN | FF_DIRECT_IO, resp_read_dt0, read_iarr,
510 {16, 0xfe, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
511 0xff, 0xff, 0xff, 0x9f, 0xc7} }, /* READ(16) */
512/* 10 */
513 {3, 0x8a, 0, F_D_OUT | FF_DIRECT_IO, resp_write_dt0, write_iarr,
514 {16, 0xfa, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
515 0xff, 0xff, 0xff, 0x9f, 0xc7} }, /* WRITE(16) */
516 {0, 0x1b, 0, 0, resp_start_stop, NULL, /* START STOP UNIT */
517 {6, 0x1, 0, 0xf, 0xf7, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
518 {1, 0x9e, 0x10, F_SA_LOW | F_D_IN, resp_readcap16, sa_in_iarr,
519 {16, 0x10, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
520 0xff, 0xff, 0xff, 0x1, 0xc7} }, /* READ CAPACITY(16) */
521 {0, 0, 0, F_INV_OP | FF_RESPOND, NULL, NULL, /* SA OUT */
522 {0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
523 {2, 0xa3, 0xa, F_SA_LOW | F_D_IN, resp_report_tgtpgs, maint_in_iarr,
524 {12, 0xea, 0, 0, 0, 0, 0xff, 0xff, 0xff, 0xff, 0, 0xc7, 0, 0, 0,
525 0} },
526 {0, 0, 0, F_INV_OP | FF_RESPOND, NULL, NULL, /* MAINT OUT */
527 {0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
f7f9f26b
DG
528 {0, 0x2f, 0, F_D_OUT_MAYBE | FF_DIRECT_IO, NULL, NULL, /* VERIFY(10) */
529 {10, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xc7,
530 0, 0, 0, 0, 0, 0} },
c2248fc9
DG
531 {1, 0x7f, 0x9, F_SA_HIGH | F_D_IN | FF_DIRECT_IO, resp_read_dt0,
532 vl_iarr, {32, 0xc7, 0, 0, 0, 0, 0x1f, 0x18, 0x0, 0x9, 0xfe, 0,
533 0xff, 0xff, 0xff, 0xff} },/* VARIABLE LENGTH, READ(32) */
534 {1, 0x56, 0, F_D_OUT, NULL, reserve_iarr, /* RESERVE(10) */
535 {10, 0xff, 0xff, 0xff, 0, 0, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0,
536 0} },
537 {1, 0x57, 0, F_D_OUT, NULL, release_iarr, /* RELEASE(10) */
538 {10, 0x13, 0xff, 0xff, 0, 0, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0,
539 0} },
540/* 20 */
f7f9f26b
DG
541 {0, 0x1e, 0, 0, NULL, NULL, /* ALLOW REMOVAL */
542 {6, 0, 0, 0, 0x3, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
c2248fc9
DG
543 {0, 0x1, 0, 0, resp_start_stop, NULL, /* REWIND ?? */
544 {6, 0x1, 0, 0, 0, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
545 {0, 0, 0, F_INV_OP | FF_RESPOND, NULL, NULL, /* ATA_PT */
546 {0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
547 {0, 0x1d, F_D_OUT, 0, NULL, NULL, /* SEND DIAGNOSTIC */
548 {6, 0xf7, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
549 {0, 0x42, 0, F_D_OUT | FF_DIRECT_IO, resp_unmap, NULL, /* UNMAP */
550 {10, 0x1, 0, 0, 0, 0, 0x1f, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0} },
551 {0, 0x53, 0, F_D_IN | F_D_OUT | FF_DIRECT_IO, resp_xdwriteread_10,
552 NULL, {10, 0xff, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff, 0xff, 0xc7,
553 0, 0, 0, 0, 0, 0} },
acafd0b9
EM
554 {0, 0x3b, 0, F_D_OUT_MAYBE, resp_write_buffer, NULL,
555 {10, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xc7, 0, 0,
556 0, 0, 0, 0} }, /* WRITE_BUFFER */
c2248fc9
DG
557 {1, 0x41, 0, F_D_OUT_MAYBE | FF_DIRECT_IO, resp_write_same_10,
558 write_same_iarr, {10, 0xff, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff,
559 0xff, 0xc7, 0, 0, 0, 0, 0, 0} },
560 {0, 0x35, 0, F_DELAY_OVERR | FF_DIRECT_IO, NULL, NULL, /* SYNC_CACHE */
561 {10, 0x7, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff, 0xff, 0xc7, 0, 0,
562 0, 0, 0, 0} },
38d5c833 563 {0, 0x89, 0, F_D_OUT | FF_DIRECT_IO, resp_comp_write, NULL,
c2248fc9
DG
564 {16, 0xf8, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0, 0,
565 0, 0xff, 0x1f, 0xc7} }, /* COMPARE AND WRITE */
566
567/* 30 */
568 {0xff, 0, 0, 0, NULL, NULL, /* terminating element */
569 {0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
570};
571
773642d9
DG
572static int sdebug_add_host = DEF_NUM_HOST;
573static int sdebug_ato = DEF_ATO;
c2206098 574static int sdebug_jdelay = DEF_JDELAY; /* if > 0 then unit is jiffies */
773642d9
DG
575static int sdebug_dev_size_mb = DEF_DEV_SIZE_MB;
576static int sdebug_dif = DEF_DIF;
577static int sdebug_dix = DEF_DIX;
578static int sdebug_dsense = DEF_D_SENSE;
579static int sdebug_every_nth = DEF_EVERY_NTH;
580static int sdebug_fake_rw = DEF_FAKE_RW;
581static unsigned int sdebug_guard = DEF_GUARD;
582static int sdebug_lowest_aligned = DEF_LOWEST_ALIGNED;
583static int sdebug_max_luns = DEF_MAX_LUNS;
c4837394 584static int sdebug_max_queue = SDEBUG_CANQUEUE; /* per submit queue */
cbf67842 585static atomic_t retired_max_queue; /* if > 0 then was prior max_queue */
c2206098 586static int sdebug_ndelay = DEF_NDELAY; /* if > 0 then unit is nanoseconds */
773642d9
DG
587static int sdebug_no_lun_0 = DEF_NO_LUN_0;
588static int sdebug_no_uld;
589static int sdebug_num_parts = DEF_NUM_PARTS;
590static int sdebug_num_tgts = DEF_NUM_TGTS; /* targets per host */
591static int sdebug_opt_blks = DEF_OPT_BLKS;
592static int sdebug_opts = DEF_OPTS;
593static int sdebug_physblk_exp = DEF_PHYSBLK_EXP;
86e6828a 594static int sdebug_opt_xferlen_exp = DEF_OPT_XFERLEN_EXP;
b01f6f83 595static int sdebug_ptype = DEF_PTYPE; /* SCSI peripheral device type */
773642d9
DG
596static int sdebug_scsi_level = DEF_SCSI_LEVEL;
597static int sdebug_sector_size = DEF_SECTOR_SIZE;
598static int sdebug_virtual_gb = DEF_VIRTUAL_GB;
599static int sdebug_vpd_use_hostno = DEF_VPD_USE_HOSTNO;
600static unsigned int sdebug_lbpu = DEF_LBPU;
601static unsigned int sdebug_lbpws = DEF_LBPWS;
602static unsigned int sdebug_lbpws10 = DEF_LBPWS10;
603static unsigned int sdebug_lbprz = DEF_LBPRZ;
604static unsigned int sdebug_unmap_alignment = DEF_UNMAP_ALIGNMENT;
605static unsigned int sdebug_unmap_granularity = DEF_UNMAP_GRANULARITY;
606static unsigned int sdebug_unmap_max_blocks = DEF_UNMAP_MAX_BLOCKS;
607static unsigned int sdebug_unmap_max_desc = DEF_UNMAP_MAX_DESC;
608static unsigned int sdebug_write_same_length = DEF_WRITESAME_LENGTH;
09ba24c1 609static int sdebug_uuid_ctl = DEF_UUID_CTL;
773642d9
DG
610static bool sdebug_removable = DEF_REMOVABLE;
611static bool sdebug_clustering;
612static bool sdebug_host_lock = DEF_HOST_LOCK;
613static bool sdebug_strict = DEF_STRICT;
817fd66b 614static bool sdebug_any_injecting_opt;
773642d9 615static bool sdebug_verbose;
f46eb0e9 616static bool have_dif_prot;
c4837394
DG
617static bool sdebug_statistics = DEF_STATISTICS;
618static bool sdebug_mq_active;
1da177e4 619
c65b1445 620static unsigned int sdebug_store_sectors;
1da177e4
LT
621static sector_t sdebug_capacity; /* in sectors */
622
623/* old BIOS stuff, kernel may get rid of them but some mode sense pages
624 may still need them */
625static int sdebug_heads; /* heads per disk */
626static int sdebug_cylinders_per; /* cylinders per surface */
627static int sdebug_sectors_per; /* sectors per cylinder */
628
1da177e4
LT
629static LIST_HEAD(sdebug_host_list);
630static DEFINE_SPINLOCK(sdebug_host_list_lock);
631
fd32119b 632static unsigned char *fake_storep; /* ramdisk storage */
6ebf105c 633static struct t10_pi_tuple *dif_storep; /* protection info */
44d92694 634static void *map_storep; /* provisioning map */
1da177e4 635
44d92694 636static unsigned long map_size;
cbf67842
DG
637static int num_aborts;
638static int num_dev_resets;
639static int num_target_resets;
640static int num_bus_resets;
641static int num_host_resets;
c6a44287
MP
642static int dix_writes;
643static int dix_reads;
644static int dif_errors;
1da177e4 645
c4837394
DG
646static int submit_queues = DEF_SUBMIT_QUEUES; /* > 1 for multi-queue (mq) */
647static struct sdebug_queue *sdebug_q_arr; /* ptr to array of submit queues */
fd32119b 648
1da177e4
LT
649static DEFINE_RWLOCK(atomic_rw);
650
cbf67842
DG
651static char sdebug_proc_name[] = MY_NAME;
652static const char *my_name = MY_NAME;
1da177e4 653
1da177e4
LT
654static struct bus_type pseudo_lld_bus;
655
656static struct device_driver sdebug_driverfs_driver = {
657 .name = sdebug_proc_name,
658 .bus = &pseudo_lld_bus,
1da177e4
LT
659};
660
661static const int check_condition_result =
662 (DRIVER_SENSE << 24) | SAM_STAT_CHECK_CONDITION;
663
c6a44287
MP
664static const int illegal_condition_result =
665 (DRIVER_SENSE << 24) | (DID_ABORT << 16) | SAM_STAT_CHECK_CONDITION;
666
cbf67842
DG
667static const int device_qfull_result =
668 (DID_OK << 16) | (COMMAND_COMPLETE << 8) | SAM_STAT_TASK_SET_FULL;
669
fd32119b 670
760f3b03
DG
671/* Only do the extra work involved in logical block provisioning if one or
672 * more of the lbpu, lbpws or lbpws10 parameters are given and we are doing
673 * real reads and writes (i.e. not skipping them for speed).
674 */
675static inline bool scsi_debug_lbp(void)
fd32119b
DG
676{
677 return 0 == sdebug_fake_rw &&
678 (sdebug_lbpu || sdebug_lbpws || sdebug_lbpws10);
679}
c65b1445 680
14faa944
AM
681static void *fake_store(unsigned long long lba)
682{
683 lba = do_div(lba, sdebug_store_sectors);
684
773642d9 685 return fake_storep + lba * sdebug_sector_size;
14faa944
AM
686}
687
6ebf105c 688static struct t10_pi_tuple *dif_store(sector_t sector)
14faa944 689{
49413112 690 sector = sector_div(sector, sdebug_store_sectors);
14faa944
AM
691
692 return dif_storep + sector;
693}
694
8dea0d02
FT
695static void sdebug_max_tgts_luns(void)
696{
697 struct sdebug_host_info *sdbg_host;
698 struct Scsi_Host *hpnt;
699
700 spin_lock(&sdebug_host_list_lock);
701 list_for_each_entry(sdbg_host, &sdebug_host_list, host_list) {
702 hpnt = sdbg_host->shost;
703 if ((hpnt->this_id >= 0) &&
773642d9
DG
704 (sdebug_num_tgts > hpnt->this_id))
705 hpnt->max_id = sdebug_num_tgts + 1;
8dea0d02 706 else
773642d9
DG
707 hpnt->max_id = sdebug_num_tgts;
708 /* sdebug_max_luns; */
f2d3fd29 709 hpnt->max_lun = SCSI_W_LUN_REPORT_LUNS + 1;
8dea0d02
FT
710 }
711 spin_unlock(&sdebug_host_list_lock);
712}
713
22017ed2
DG
714enum sdeb_cmd_data {SDEB_IN_DATA = 0, SDEB_IN_CDB = 1};
715
716/* Set in_bit to -1 to indicate no bit position of invalid field */
fd32119b
DG
717static void mk_sense_invalid_fld(struct scsi_cmnd *scp,
718 enum sdeb_cmd_data c_d,
719 int in_byte, int in_bit)
22017ed2
DG
720{
721 unsigned char *sbuff;
722 u8 sks[4];
723 int sl, asc;
724
725 sbuff = scp->sense_buffer;
726 if (!sbuff) {
727 sdev_printk(KERN_ERR, scp->device,
728 "%s: sense_buffer is NULL\n", __func__);
729 return;
730 }
731 asc = c_d ? INVALID_FIELD_IN_CDB : INVALID_FIELD_IN_PARAM_LIST;
732 memset(sbuff, 0, SCSI_SENSE_BUFFERSIZE);
773642d9 733 scsi_build_sense_buffer(sdebug_dsense, sbuff, ILLEGAL_REQUEST, asc, 0);
22017ed2
DG
734 memset(sks, 0, sizeof(sks));
735 sks[0] = 0x80;
736 if (c_d)
737 sks[0] |= 0x40;
738 if (in_bit >= 0) {
739 sks[0] |= 0x8;
740 sks[0] |= 0x7 & in_bit;
741 }
742 put_unaligned_be16(in_byte, sks + 1);
773642d9 743 if (sdebug_dsense) {
22017ed2
DG
744 sl = sbuff[7] + 8;
745 sbuff[7] = sl;
746 sbuff[sl] = 0x2;
747 sbuff[sl + 1] = 0x6;
748 memcpy(sbuff + sl + 4, sks, 3);
749 } else
750 memcpy(sbuff + 15, sks, 3);
773642d9 751 if (sdebug_verbose)
22017ed2
DG
752 sdev_printk(KERN_INFO, scp->device, "%s: [sense_key,asc,ascq"
753 "]: [0x5,0x%x,0x0] %c byte=%d, bit=%d\n",
754 my_name, asc, c_d ? 'C' : 'D', in_byte, in_bit);
755}
756
cbf67842 757static void mk_sense_buffer(struct scsi_cmnd *scp, int key, int asc, int asq)
8dea0d02
FT
758{
759 unsigned char *sbuff;
760
cbf67842
DG
761 sbuff = scp->sense_buffer;
762 if (!sbuff) {
763 sdev_printk(KERN_ERR, scp->device,
764 "%s: sense_buffer is NULL\n", __func__);
765 return;
766 }
767 memset(sbuff, 0, SCSI_SENSE_BUFFERSIZE);
8dea0d02 768
773642d9 769 scsi_build_sense_buffer(sdebug_dsense, sbuff, key, asc, asq);
8dea0d02 770
773642d9 771 if (sdebug_verbose)
cbf67842
DG
772 sdev_printk(KERN_INFO, scp->device,
773 "%s: [sense_key,asc,ascq]: [0x%x,0x%x,0x%x]\n",
774 my_name, key, asc, asq);
8dea0d02 775}
1da177e4 776
fd32119b 777static void mk_sense_invalid_opcode(struct scsi_cmnd *scp)
22017ed2
DG
778{
779 mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_OPCODE, 0);
780}
781
1da177e4
LT
782static int scsi_debug_ioctl(struct scsi_device *dev, int cmd, void __user *arg)
783{
773642d9 784 if (sdebug_verbose) {
cbf67842
DG
785 if (0x1261 == cmd)
786 sdev_printk(KERN_INFO, dev,
787 "%s: BLKFLSBUF [0x1261]\n", __func__);
788 else if (0x5331 == cmd)
789 sdev_printk(KERN_INFO, dev,
790 "%s: CDROM_GET_CAPABILITY [0x5331]\n",
791 __func__);
792 else
793 sdev_printk(KERN_INFO, dev, "%s: cmd=0x%x\n",
794 __func__, cmd);
1da177e4
LT
795 }
796 return -EINVAL;
797 /* return -ENOTTY; // correct return but upsets fdisk */
798}
799
19c8ead7
EM
800static void clear_luns_changed_on_target(struct sdebug_dev_info *devip)
801{
802 struct sdebug_host_info *sdhp;
803 struct sdebug_dev_info *dp;
804
805 spin_lock(&sdebug_host_list_lock);
806 list_for_each_entry(sdhp, &sdebug_host_list, host_list) {
807 list_for_each_entry(dp, &sdhp->dev_info_list, dev_list) {
808 if ((devip->sdbg_host == dp->sdbg_host) &&
809 (devip->target == dp->target))
810 clear_bit(SDEBUG_UA_LUNS_CHANGED, dp->uas_bm);
811 }
812 }
813 spin_unlock(&sdebug_host_list_lock);
814}
815
f46eb0e9 816static int make_ua(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
1da177e4 817{
cbf67842 818 int k;
cbf67842
DG
819
820 k = find_first_bit(devip->uas_bm, SDEBUG_NUM_UAS);
821 if (k != SDEBUG_NUM_UAS) {
822 const char *cp = NULL;
823
824 switch (k) {
825 case SDEBUG_UA_POR:
f46eb0e9
DG
826 mk_sense_buffer(scp, UNIT_ATTENTION, UA_RESET_ASC,
827 POWER_ON_RESET_ASCQ);
773642d9 828 if (sdebug_verbose)
cbf67842
DG
829 cp = "power on reset";
830 break;
831 case SDEBUG_UA_BUS_RESET:
f46eb0e9
DG
832 mk_sense_buffer(scp, UNIT_ATTENTION, UA_RESET_ASC,
833 BUS_RESET_ASCQ);
773642d9 834 if (sdebug_verbose)
cbf67842
DG
835 cp = "bus reset";
836 break;
837 case SDEBUG_UA_MODE_CHANGED:
f46eb0e9
DG
838 mk_sense_buffer(scp, UNIT_ATTENTION, UA_CHANGED_ASC,
839 MODE_CHANGED_ASCQ);
773642d9 840 if (sdebug_verbose)
cbf67842
DG
841 cp = "mode parameters changed";
842 break;
0d01c5df 843 case SDEBUG_UA_CAPACITY_CHANGED:
f46eb0e9
DG
844 mk_sense_buffer(scp, UNIT_ATTENTION, UA_CHANGED_ASC,
845 CAPACITY_CHANGED_ASCQ);
773642d9 846 if (sdebug_verbose)
0d01c5df 847 cp = "capacity data changed";
f49accf1 848 break;
acafd0b9 849 case SDEBUG_UA_MICROCODE_CHANGED:
f46eb0e9 850 mk_sense_buffer(scp, UNIT_ATTENTION,
b01f6f83
DG
851 TARGET_CHANGED_ASC,
852 MICROCODE_CHANGED_ASCQ);
773642d9 853 if (sdebug_verbose)
acafd0b9
EM
854 cp = "microcode has been changed";
855 break;
856 case SDEBUG_UA_MICROCODE_CHANGED_WO_RESET:
f46eb0e9 857 mk_sense_buffer(scp, UNIT_ATTENTION,
acafd0b9
EM
858 TARGET_CHANGED_ASC,
859 MICROCODE_CHANGED_WO_RESET_ASCQ);
773642d9 860 if (sdebug_verbose)
acafd0b9
EM
861 cp = "microcode has been changed without reset";
862 break;
19c8ead7
EM
863 case SDEBUG_UA_LUNS_CHANGED:
864 /*
865 * SPC-3 behavior is to report a UNIT ATTENTION with
866 * ASC/ASCQ REPORTED LUNS DATA HAS CHANGED on every LUN
867 * on the target, until a REPORT LUNS command is
868 * received. SPC-4 behavior is to report it only once.
773642d9 869 * NOTE: sdebug_scsi_level does not use the same
19c8ead7
EM
870 * values as struct scsi_device->scsi_level.
871 */
773642d9 872 if (sdebug_scsi_level >= 6) /* SPC-4 and above */
19c8ead7 873 clear_luns_changed_on_target(devip);
f46eb0e9 874 mk_sense_buffer(scp, UNIT_ATTENTION,
19c8ead7
EM
875 TARGET_CHANGED_ASC,
876 LUNS_CHANGED_ASCQ);
773642d9 877 if (sdebug_verbose)
19c8ead7
EM
878 cp = "reported luns data has changed";
879 break;
cbf67842 880 default:
773642d9
DG
881 pr_warn("unexpected unit attention code=%d\n", k);
882 if (sdebug_verbose)
cbf67842
DG
883 cp = "unknown";
884 break;
885 }
886 clear_bit(k, devip->uas_bm);
773642d9 887 if (sdebug_verbose)
f46eb0e9 888 sdev_printk(KERN_INFO, scp->device,
cbf67842
DG
889 "%s reports: Unit attention: %s\n",
890 my_name, cp);
1da177e4
LT
891 return check_condition_result;
892 }
893 return 0;
894}
895
fb0cc8d1 896/* Build SCSI "data-in" buffer. Returns 0 if ok else (DID_ERROR << 16). */
21a61829 897static int fill_from_dev_buffer(struct scsi_cmnd *scp, unsigned char *arr,
1da177e4
LT
898 int arr_len)
899{
21a61829 900 int act_len;
072d0bb3 901 struct scsi_data_buffer *sdb = scsi_in(scp);
1da177e4 902
072d0bb3 903 if (!sdb->length)
1da177e4 904 return 0;
072d0bb3 905 if (!(scsi_bidi_cmnd(scp) || scp->sc_data_direction == DMA_FROM_DEVICE))
773642d9 906 return DID_ERROR << 16;
21a61829
FT
907
908 act_len = sg_copy_from_buffer(sdb->table.sgl, sdb->table.nents,
909 arr, arr_len);
a4517511 910 sdb->resid = scsi_bufflen(scp) - act_len;
21a61829 911
1da177e4
LT
912 return 0;
913}
914
fb0cc8d1
DG
915/* Partial build of SCSI "data-in" buffer. Returns 0 if ok else
916 * (DID_ERROR << 16). Can write to offset in data-in buffer. If multiple
917 * calls, not required to write in ascending offset order. Assumes resid
918 * set to scsi_bufflen() prior to any calls.
919 */
920static int p_fill_from_dev_buffer(struct scsi_cmnd *scp, const void *arr,
921 int arr_len, unsigned int off_dst)
922{
923 int act_len, n;
924 struct scsi_data_buffer *sdb = scsi_in(scp);
925 off_t skip = off_dst;
926
927 if (sdb->length <= off_dst)
928 return 0;
929 if (!(scsi_bidi_cmnd(scp) || scp->sc_data_direction == DMA_FROM_DEVICE))
930 return DID_ERROR << 16;
931
932 act_len = sg_pcopy_from_buffer(sdb->table.sgl, sdb->table.nents,
933 arr, arr_len, skip);
934 pr_debug("%s: off_dst=%u, scsi_bufflen=%u, act_len=%u, resid=%d\n",
935 __func__, off_dst, scsi_bufflen(scp), act_len, sdb->resid);
936 n = (int)scsi_bufflen(scp) - ((int)off_dst + act_len);
937 sdb->resid = min(sdb->resid, n);
938 return 0;
939}
940
941/* Fetches from SCSI "data-out" buffer. Returns number of bytes fetched into
942 * 'arr' or -1 if error.
943 */
21a61829
FT
944static int fetch_to_dev_buffer(struct scsi_cmnd *scp, unsigned char *arr,
945 int arr_len)
1da177e4 946{
21a61829 947 if (!scsi_bufflen(scp))
1da177e4 948 return 0;
072d0bb3 949 if (!(scsi_bidi_cmnd(scp) || scp->sc_data_direction == DMA_TO_DEVICE))
1da177e4 950 return -1;
21a61829
FT
951
952 return scsi_sg_copy_to_buffer(scp, arr, arr_len);
1da177e4
LT
953}
954
955
e5203cf0
HR
956static char sdebug_inq_vendor_id[9] = "Linux ";
957static char sdebug_inq_product_id[17] = "scsi_debug ";
958static char sdebug_inq_product_rev[5] = "0186"; /* version less '.' */
1b37bd60
DG
959/* Use some locally assigned NAAs for SAS addresses. */
960static const u64 naa3_comp_a = 0x3222222000000000ULL;
961static const u64 naa3_comp_b = 0x3333333000000000ULL;
962static const u64 naa3_comp_c = 0x3111111000000000ULL;
1da177e4 963
cbf67842 964/* Device identification VPD page. Returns number of bytes placed in arr */
760f3b03
DG
965static int inquiry_vpd_83(unsigned char *arr, int port_group_id,
966 int target_dev_id, int dev_id_num,
09ba24c1 967 const char *dev_id_str, int dev_id_str_len,
bf476433 968 const uuid_t *lu_name)
1da177e4 969{
c65b1445
DG
970 int num, port_a;
971 char b[32];
1da177e4 972
c65b1445 973 port_a = target_dev_id + 1;
1da177e4
LT
974 /* T10 vendor identifier field format (faked) */
975 arr[0] = 0x2; /* ASCII */
976 arr[1] = 0x1;
977 arr[2] = 0x0;
e5203cf0
HR
978 memcpy(&arr[4], sdebug_inq_vendor_id, 8);
979 memcpy(&arr[12], sdebug_inq_product_id, 16);
1da177e4
LT
980 memcpy(&arr[28], dev_id_str, dev_id_str_len);
981 num = 8 + 16 + dev_id_str_len;
982 arr[3] = num;
983 num += 4;
c65b1445 984 if (dev_id_num >= 0) {
09ba24c1
DG
985 if (sdebug_uuid_ctl) {
986 /* Locally assigned UUID */
987 arr[num++] = 0x1; /* binary (not necessarily sas) */
988 arr[num++] = 0xa; /* PIV=0, lu, naa */
989 arr[num++] = 0x0;
990 arr[num++] = 0x12;
991 arr[num++] = 0x10; /* uuid type=1, locally assigned */
992 arr[num++] = 0x0;
993 memcpy(arr + num, lu_name, 16);
994 num += 16;
995 } else {
1b37bd60 996 /* NAA-3, Logical unit identifier (binary) */
09ba24c1
DG
997 arr[num++] = 0x1; /* binary (not necessarily sas) */
998 arr[num++] = 0x3; /* PIV=0, lu, naa */
999 arr[num++] = 0x0;
1000 arr[num++] = 0x8;
1b37bd60 1001 put_unaligned_be64(naa3_comp_b + dev_id_num, arr + num);
09ba24c1
DG
1002 num += 8;
1003 }
c65b1445
DG
1004 /* Target relative port number */
1005 arr[num++] = 0x61; /* proto=sas, binary */
1006 arr[num++] = 0x94; /* PIV=1, target port, rel port */
1007 arr[num++] = 0x0; /* reserved */
1008 arr[num++] = 0x4; /* length */
1009 arr[num++] = 0x0; /* reserved */
1010 arr[num++] = 0x0; /* reserved */
1011 arr[num++] = 0x0;
1012 arr[num++] = 0x1; /* relative port A */
1013 }
1b37bd60 1014 /* NAA-3, Target port identifier */
c65b1445
DG
1015 arr[num++] = 0x61; /* proto=sas, binary */
1016 arr[num++] = 0x93; /* piv=1, target port, naa */
1017 arr[num++] = 0x0;
1018 arr[num++] = 0x8;
1b37bd60 1019 put_unaligned_be64(naa3_comp_a + port_a, arr + num);
773642d9 1020 num += 8;
1b37bd60 1021 /* NAA-3, Target port group identifier */
5a09e398
HR
1022 arr[num++] = 0x61; /* proto=sas, binary */
1023 arr[num++] = 0x95; /* piv=1, target port group id */
1024 arr[num++] = 0x0;
1025 arr[num++] = 0x4;
1026 arr[num++] = 0;
1027 arr[num++] = 0;
773642d9
DG
1028 put_unaligned_be16(port_group_id, arr + num);
1029 num += 2;
1b37bd60 1030 /* NAA-3, Target device identifier */
c65b1445
DG
1031 arr[num++] = 0x61; /* proto=sas, binary */
1032 arr[num++] = 0xa3; /* piv=1, target device, naa */
1033 arr[num++] = 0x0;
1034 arr[num++] = 0x8;
1b37bd60 1035 put_unaligned_be64(naa3_comp_a + target_dev_id, arr + num);
773642d9 1036 num += 8;
c65b1445
DG
1037 /* SCSI name string: Target device identifier */
1038 arr[num++] = 0x63; /* proto=sas, UTF-8 */
1039 arr[num++] = 0xa8; /* piv=1, target device, SCSI name string */
1040 arr[num++] = 0x0;
1041 arr[num++] = 24;
1b37bd60 1042 memcpy(arr + num, "naa.32222220", 12);
c65b1445
DG
1043 num += 12;
1044 snprintf(b, sizeof(b), "%08X", target_dev_id);
1045 memcpy(arr + num, b, 8);
1046 num += 8;
1047 memset(arr + num, 0, 4);
1048 num += 4;
1049 return num;
1050}
1051
c65b1445
DG
1052static unsigned char vpd84_data[] = {
1053/* from 4th byte */ 0x22,0x22,0x22,0x0,0xbb,0x0,
1054 0x22,0x22,0x22,0x0,0xbb,0x1,
1055 0x22,0x22,0x22,0x0,0xbb,0x2,
1056};
1057
cbf67842 1058/* Software interface identification VPD page */
760f3b03 1059static int inquiry_vpd_84(unsigned char *arr)
c65b1445
DG
1060{
1061 memcpy(arr, vpd84_data, sizeof(vpd84_data));
1062 return sizeof(vpd84_data);
1063}
1064
cbf67842 1065/* Management network addresses VPD page */
760f3b03 1066static int inquiry_vpd_85(unsigned char *arr)
c65b1445
DG
1067{
1068 int num = 0;
1069 const char * na1 = "https://www.kernel.org/config";
1070 const char * na2 = "http://www.kernel.org/log";
1071 int plen, olen;
1072
1073 arr[num++] = 0x1; /* lu, storage config */
1074 arr[num++] = 0x0; /* reserved */
1075 arr[num++] = 0x0;
1076 olen = strlen(na1);
1077 plen = olen + 1;
1078 if (plen % 4)
1079 plen = ((plen / 4) + 1) * 4;
1080 arr[num++] = plen; /* length, null termianted, padded */
1081 memcpy(arr + num, na1, olen);
1082 memset(arr + num + olen, 0, plen - olen);
1083 num += plen;
1084
1085 arr[num++] = 0x4; /* lu, logging */
1086 arr[num++] = 0x0; /* reserved */
1087 arr[num++] = 0x0;
1088 olen = strlen(na2);
1089 plen = olen + 1;
1090 if (plen % 4)
1091 plen = ((plen / 4) + 1) * 4;
1092 arr[num++] = plen; /* length, null terminated, padded */
1093 memcpy(arr + num, na2, olen);
1094 memset(arr + num + olen, 0, plen - olen);
1095 num += plen;
1096
1097 return num;
1098}
1099
1100/* SCSI ports VPD page */
760f3b03 1101static int inquiry_vpd_88(unsigned char *arr, int target_dev_id)
c65b1445
DG
1102{
1103 int num = 0;
1104 int port_a, port_b;
1105
1106 port_a = target_dev_id + 1;
1107 port_b = port_a + 1;
1108 arr[num++] = 0x0; /* reserved */
1109 arr[num++] = 0x0; /* reserved */
1110 arr[num++] = 0x0;
1111 arr[num++] = 0x1; /* relative port 1 (primary) */
1112 memset(arr + num, 0, 6);
1113 num += 6;
1114 arr[num++] = 0x0;
1115 arr[num++] = 12; /* length tp descriptor */
1116 /* naa-5 target port identifier (A) */
1117 arr[num++] = 0x61; /* proto=sas, binary */
1118 arr[num++] = 0x93; /* PIV=1, target port, NAA */
1119 arr[num++] = 0x0; /* reserved */
1120 arr[num++] = 0x8; /* length */
1b37bd60 1121 put_unaligned_be64(naa3_comp_a + port_a, arr + num);
773642d9 1122 num += 8;
c65b1445
DG
1123 arr[num++] = 0x0; /* reserved */
1124 arr[num++] = 0x0; /* reserved */
1125 arr[num++] = 0x0;
1126 arr[num++] = 0x2; /* relative port 2 (secondary) */
1127 memset(arr + num, 0, 6);
1128 num += 6;
1129 arr[num++] = 0x0;
1130 arr[num++] = 12; /* length tp descriptor */
1131 /* naa-5 target port identifier (B) */
1132 arr[num++] = 0x61; /* proto=sas, binary */
1133 arr[num++] = 0x93; /* PIV=1, target port, NAA */
1134 arr[num++] = 0x0; /* reserved */
1135 arr[num++] = 0x8; /* length */
1b37bd60 1136 put_unaligned_be64(naa3_comp_a + port_b, arr + num);
773642d9 1137 num += 8;
c65b1445
DG
1138
1139 return num;
1140}
1141
1142
1143static unsigned char vpd89_data[] = {
1144/* from 4th byte */ 0,0,0,0,
1145'l','i','n','u','x',' ',' ',' ',
1146'S','A','T',' ','s','c','s','i','_','d','e','b','u','g',' ',' ',
1147'1','2','3','4',
11480x34,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,
11490xec,0,0,0,
11500x5a,0xc,0xff,0x3f,0x37,0xc8,0x10,0,0,0,0,0,0x3f,0,0,0,
11510,0,0,0,0x58,0x58,0x58,0x58,0x58,0x58,0x58,0x58,0x20,0x20,0x20,0x20,
11520x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0,0,0,0x40,0x4,0,0x2e,0x33,
11530x38,0x31,0x20,0x20,0x20,0x20,0x54,0x53,0x38,0x33,0x30,0x30,0x33,0x31,
11540x53,0x41,
11550x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,
11560x20,0x20,
11570x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,
11580x10,0x80,
11590,0,0,0x2f,0,0,0,0x2,0,0x2,0x7,0,0xff,0xff,0x1,0,
11600x3f,0,0xc1,0xff,0x3e,0,0x10,0x1,0xb0,0xf8,0x50,0x9,0,0,0x7,0,
11610x3,0,0x78,0,0x78,0,0xf0,0,0x78,0,0,0,0,0,0,0,
11620,0,0,0,0,0,0,0,0x2,0,0,0,0,0,0,0,
11630x7e,0,0x1b,0,0x6b,0x34,0x1,0x7d,0x3,0x40,0x69,0x34,0x1,0x3c,0x3,0x40,
11640x7f,0x40,0,0,0,0,0xfe,0xfe,0,0,0,0,0,0xfe,0,0,
11650,0,0,0,0,0,0,0,0xb0,0xf8,0x50,0x9,0,0,0,0,
11660,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11670,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11680,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11690x1,0,0xb0,0xf8,0x50,0x9,0xb0,0xf8,0x50,0x9,0x20,0x20,0x2,0,0xb6,0x42,
11700,0x80,0x8a,0,0x6,0x3c,0xa,0x3c,0xff,0xff,0xc6,0x7,0,0x1,0,0x8,
11710xf0,0xf,0,0x10,0x2,0,0x30,0,0,0,0,0,0,0,0x6,0xfe,
11720,0,0x2,0,0x50,0,0x8a,0,0x4f,0x95,0,0,0x21,0,0xb,0,
11730,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11740,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11750,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11760,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11770,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11780,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11790,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11800,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11810,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11820,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11830,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
11840,0,0,0,0,0,0,0,0,0,0,0,0,0,0xa5,0x51,
1185};
1186
cbf67842 1187/* ATA Information VPD page */
760f3b03 1188static int inquiry_vpd_89(unsigned char *arr)
c65b1445
DG
1189{
1190 memcpy(arr, vpd89_data, sizeof(vpd89_data));
1191 return sizeof(vpd89_data);
1192}
1193
1194
1195static unsigned char vpdb0_data[] = {
1e49f785
DG
1196 /* from 4th byte */ 0,0,0,4, 0,0,0x4,0, 0,0,0,64,
1197 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
1198 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
1199 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
c65b1445
DG
1200};
1201
cbf67842 1202/* Block limits VPD page (SBC-3) */
760f3b03 1203static int inquiry_vpd_b0(unsigned char *arr)
c65b1445 1204{
ea61fca5
MP
1205 unsigned int gran;
1206
c65b1445 1207 memcpy(arr, vpdb0_data, sizeof(vpdb0_data));
e308b3d1
MP
1208
1209 /* Optimal transfer length granularity */
86e6828a
LH
1210 if (sdebug_opt_xferlen_exp != 0 &&
1211 sdebug_physblk_exp < sdebug_opt_xferlen_exp)
1212 gran = 1 << sdebug_opt_xferlen_exp;
1213 else
1214 gran = 1 << sdebug_physblk_exp;
773642d9 1215 put_unaligned_be16(gran, arr + 2);
e308b3d1
MP
1216
1217 /* Maximum Transfer Length */
773642d9
DG
1218 if (sdebug_store_sectors > 0x400)
1219 put_unaligned_be32(sdebug_store_sectors, arr + 4);
44d92694 1220
e308b3d1 1221 /* Optimal Transfer Length */
773642d9 1222 put_unaligned_be32(sdebug_opt_blks, &arr[8]);
e308b3d1 1223
773642d9 1224 if (sdebug_lbpu) {
e308b3d1 1225 /* Maximum Unmap LBA Count */
773642d9 1226 put_unaligned_be32(sdebug_unmap_max_blocks, &arr[16]);
e308b3d1
MP
1227
1228 /* Maximum Unmap Block Descriptor Count */
773642d9 1229 put_unaligned_be32(sdebug_unmap_max_desc, &arr[20]);
44d92694
MP
1230 }
1231
e308b3d1 1232 /* Unmap Granularity Alignment */
773642d9
DG
1233 if (sdebug_unmap_alignment) {
1234 put_unaligned_be32(sdebug_unmap_alignment, &arr[28]);
44d92694
MP
1235 arr[28] |= 0x80; /* UGAVALID */
1236 }
1237
e308b3d1 1238 /* Optimal Unmap Granularity */
773642d9 1239 put_unaligned_be32(sdebug_unmap_granularity, &arr[24]);
6014759c 1240
5b94e232 1241 /* Maximum WRITE SAME Length */
773642d9 1242 put_unaligned_be64(sdebug_write_same_length, &arr[32]);
5b94e232
MP
1243
1244 return 0x3c; /* Mandatory page length for Logical Block Provisioning */
44d92694 1245
c65b1445 1246 return sizeof(vpdb0_data);
1da177e4
LT
1247}
1248
1e49f785 1249/* Block device characteristics VPD page (SBC-3) */
760f3b03 1250static int inquiry_vpd_b1(unsigned char *arr)
eac6e8e4
MW
1251{
1252 memset(arr, 0, 0x3c);
1253 arr[0] = 0;
1e49f785
DG
1254 arr[1] = 1; /* non rotating medium (e.g. solid state) */
1255 arr[2] = 0;
1256 arr[3] = 5; /* less than 1.8" */
eac6e8e4
MW
1257
1258 return 0x3c;
1259}
1da177e4 1260
760f3b03
DG
1261/* Logical block provisioning VPD page (SBC-4) */
1262static int inquiry_vpd_b2(unsigned char *arr)
6014759c 1263{
3f0bc3b3 1264 memset(arr, 0, 0x4);
6014759c 1265 arr[0] = 0; /* threshold exponent */
773642d9 1266 if (sdebug_lbpu)
6014759c 1267 arr[1] = 1 << 7;
773642d9 1268 if (sdebug_lbpws)
6014759c 1269 arr[1] |= 1 << 6;
773642d9 1270 if (sdebug_lbpws10)
5b94e232 1271 arr[1] |= 1 << 5;
760f3b03
DG
1272 if (sdebug_lbprz && scsi_debug_lbp())
1273 arr[1] |= (sdebug_lbprz & 0x7) << 2; /* sbc4r07 and later */
1274 /* anc_sup=0; dp=0 (no provisioning group descriptor) */
1275 /* minimum_percentage=0; provisioning_type=0 (unknown) */
1276 /* threshold_percentage=0 */
3f0bc3b3 1277 return 0x4;
6014759c
MP
1278}
1279
1da177e4 1280#define SDEBUG_LONG_INQ_SZ 96
c65b1445 1281#define SDEBUG_MAX_INQ_ARR_SZ 584
1da177e4 1282
c2248fc9 1283static int resp_inquiry(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
1da177e4
LT
1284{
1285 unsigned char pq_pdt;
5a09e398 1286 unsigned char * arr;
01123ef4 1287 unsigned char *cmd = scp->cmnd;
5a09e398 1288 int alloc_len, n, ret;
760f3b03 1289 bool have_wlun, is_disk;
1da177e4 1290
773642d9 1291 alloc_len = get_unaligned_be16(cmd + 3);
6f3cbf55
DG
1292 arr = kzalloc(SDEBUG_MAX_INQ_ARR_SZ, GFP_ATOMIC);
1293 if (! arr)
1294 return DID_REQUEUE << 16;
760f3b03 1295 is_disk = (sdebug_ptype == TYPE_DISK);
b01f6f83 1296 have_wlun = scsi_is_wlun(scp->device->lun);
c2248fc9 1297 if (have_wlun)
b01f6f83
DG
1298 pq_pdt = TYPE_WLUN; /* present, wlun */
1299 else if (sdebug_no_lun_0 && (devip->lun == SDEBUG_LUN_0_VAL))
1300 pq_pdt = 0x7f; /* not present, PQ=3, PDT=0x1f */
c65b1445 1301 else
773642d9 1302 pq_pdt = (sdebug_ptype & 0x1f);
1da177e4
LT
1303 arr[0] = pq_pdt;
1304 if (0x2 & cmd[1]) { /* CMDDT bit set */
22017ed2 1305 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, 1);
5a09e398 1306 kfree(arr);
1da177e4
LT
1307 return check_condition_result;
1308 } else if (0x1 & cmd[1]) { /* EVPD bit set */
5a09e398 1309 int lu_id_num, port_group_id, target_dev_id, len;
c65b1445
DG
1310 char lu_id_str[6];
1311 int host_no = devip->sdbg_host->shost->host_no;
1da177e4 1312
5a09e398
HR
1313 port_group_id = (((host_no + 1) & 0x7f) << 8) +
1314 (devip->channel & 0x7f);
b01f6f83 1315 if (sdebug_vpd_use_hostno == 0)
23183910 1316 host_no = 0;
c2248fc9 1317 lu_id_num = have_wlun ? -1 : (((host_no + 1) * 2000) +
c65b1445
DG
1318 (devip->target * 1000) + devip->lun);
1319 target_dev_id = ((host_no + 1) * 2000) +
1320 (devip->target * 1000) - 3;
1321 len = scnprintf(lu_id_str, 6, "%d", lu_id_num);
1da177e4 1322 if (0 == cmd[2]) { /* supported vital product data pages */
c65b1445
DG
1323 arr[1] = cmd[2]; /*sanity */
1324 n = 4;
1325 arr[n++] = 0x0; /* this page */
1326 arr[n++] = 0x80; /* unit serial number */
1327 arr[n++] = 0x83; /* device identification */
1328 arr[n++] = 0x84; /* software interface ident. */
1329 arr[n++] = 0x85; /* management network addresses */
1330 arr[n++] = 0x86; /* extended inquiry */
1331 arr[n++] = 0x87; /* mode page policy */
1332 arr[n++] = 0x88; /* SCSI ports */
760f3b03
DG
1333 if (is_disk) { /* SBC only */
1334 arr[n++] = 0x89; /* ATA information */
1335 arr[n++] = 0xb0; /* Block limits */
1336 arr[n++] = 0xb1; /* Block characteristics */
1337 arr[n++] = 0xb2; /* Logical Block Prov */
1338 }
c65b1445 1339 arr[3] = n - 4; /* number of supported VPD pages */
1da177e4 1340 } else if (0x80 == cmd[2]) { /* unit serial number */
c65b1445 1341 arr[1] = cmd[2]; /*sanity */
1da177e4 1342 arr[3] = len;
c65b1445 1343 memcpy(&arr[4], lu_id_str, len);
1da177e4 1344 } else if (0x83 == cmd[2]) { /* device identification */
c65b1445 1345 arr[1] = cmd[2]; /*sanity */
760f3b03
DG
1346 arr[3] = inquiry_vpd_83(&arr[4], port_group_id,
1347 target_dev_id, lu_id_num,
09ba24c1
DG
1348 lu_id_str, len,
1349 &devip->lu_name);
c65b1445
DG
1350 } else if (0x84 == cmd[2]) { /* Software interface ident. */
1351 arr[1] = cmd[2]; /*sanity */
760f3b03 1352 arr[3] = inquiry_vpd_84(&arr[4]);
c65b1445
DG
1353 } else if (0x85 == cmd[2]) { /* Management network addresses */
1354 arr[1] = cmd[2]; /*sanity */
760f3b03 1355 arr[3] = inquiry_vpd_85(&arr[4]);
c65b1445
DG
1356 } else if (0x86 == cmd[2]) { /* extended inquiry */
1357 arr[1] = cmd[2]; /*sanity */
1358 arr[3] = 0x3c; /* number of following entries */
8475c811 1359 if (sdebug_dif == T10_PI_TYPE3_PROTECTION)
c6a44287 1360 arr[4] = 0x4; /* SPT: GRD_CHK:1 */
760f3b03 1361 else if (have_dif_prot)
c6a44287
MP
1362 arr[4] = 0x5; /* SPT: GRD_CHK:1, REF_CHK:1 */
1363 else
1364 arr[4] = 0x0; /* no protection stuff */
c65b1445
DG
1365 arr[5] = 0x7; /* head of q, ordered + simple q's */
1366 } else if (0x87 == cmd[2]) { /* mode page policy */
1367 arr[1] = cmd[2]; /*sanity */
1368 arr[3] = 0x8; /* number of following entries */
1369 arr[4] = 0x2; /* disconnect-reconnect mp */
1370 arr[6] = 0x80; /* mlus, shared */
1371 arr[8] = 0x18; /* protocol specific lu */
1372 arr[10] = 0x82; /* mlus, per initiator port */
1373 } else if (0x88 == cmd[2]) { /* SCSI Ports */
1374 arr[1] = cmd[2]; /*sanity */
760f3b03
DG
1375 arr[3] = inquiry_vpd_88(&arr[4], target_dev_id);
1376 } else if (is_disk && 0x89 == cmd[2]) { /* ATA information */
c65b1445 1377 arr[1] = cmd[2]; /*sanity */
760f3b03 1378 n = inquiry_vpd_89(&arr[4]);
773642d9 1379 put_unaligned_be16(n, arr + 2);
760f3b03 1380 } else if (is_disk && 0xb0 == cmd[2]) { /* Block limits */
c65b1445 1381 arr[1] = cmd[2]; /*sanity */
760f3b03
DG
1382 arr[3] = inquiry_vpd_b0(&arr[4]);
1383 } else if (is_disk && 0xb1 == cmd[2]) { /* Block char. */
eac6e8e4 1384 arr[1] = cmd[2]; /*sanity */
760f3b03
DG
1385 arr[3] = inquiry_vpd_b1(&arr[4]);
1386 } else if (is_disk && 0xb2 == cmd[2]) { /* LB Prov. */
6014759c 1387 arr[1] = cmd[2]; /*sanity */
760f3b03 1388 arr[3] = inquiry_vpd_b2(&arr[4]);
1da177e4 1389 } else {
22017ed2 1390 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, -1);
5a09e398 1391 kfree(arr);
1da177e4
LT
1392 return check_condition_result;
1393 }
773642d9 1394 len = min(get_unaligned_be16(arr + 2) + 4, alloc_len);
5a09e398 1395 ret = fill_from_dev_buffer(scp, arr,
c65b1445 1396 min(len, SDEBUG_MAX_INQ_ARR_SZ));
5a09e398
HR
1397 kfree(arr);
1398 return ret;
1da177e4
LT
1399 }
1400 /* drops through here for a standard inquiry */
773642d9
DG
1401 arr[1] = sdebug_removable ? 0x80 : 0; /* Removable disk */
1402 arr[2] = sdebug_scsi_level;
1da177e4
LT
1403 arr[3] = 2; /* response_data_format==2 */
1404 arr[4] = SDEBUG_LONG_INQ_SZ - 5;
f46eb0e9 1405 arr[5] = (int)have_dif_prot; /* PROTECT bit */
b01f6f83 1406 if (sdebug_vpd_use_hostno == 0)
70bdf202 1407 arr[5] |= 0x10; /* claim: implicit TPGS */
c65b1445 1408 arr[6] = 0x10; /* claim: MultiP */
1da177e4 1409 /* arr[6] |= 0x40; ... claim: EncServ (enclosure services) */
c65b1445 1410 arr[7] = 0xa; /* claim: LINKED + CMDQUE */
e5203cf0
HR
1411 memcpy(&arr[8], sdebug_inq_vendor_id, 8);
1412 memcpy(&arr[16], sdebug_inq_product_id, 16);
1413 memcpy(&arr[32], sdebug_inq_product_rev, 4);
1da177e4 1414 /* version descriptors (2 bytes each) follow */
760f3b03
DG
1415 put_unaligned_be16(0xc0, arr + 58); /* SAM-6 no version claimed */
1416 put_unaligned_be16(0x5c0, arr + 60); /* SPC-5 no version claimed */
c65b1445 1417 n = 62;
760f3b03
DG
1418 if (is_disk) { /* SBC-4 no version claimed */
1419 put_unaligned_be16(0x600, arr + n);
1420 n += 2;
1421 } else if (sdebug_ptype == TYPE_TAPE) { /* SSC-4 rev 3 */
1422 put_unaligned_be16(0x525, arr + n);
1423 n += 2;
1da177e4 1424 }
760f3b03 1425 put_unaligned_be16(0x2100, arr + n); /* SPL-4 no version claimed */
5a09e398 1426 ret = fill_from_dev_buffer(scp, arr,
1da177e4 1427 min(alloc_len, SDEBUG_LONG_INQ_SZ));
5a09e398
HR
1428 kfree(arr);
1429 return ret;
1da177e4
LT
1430}
1431
fd32119b
DG
1432static unsigned char iec_m_pg[] = {0x1c, 0xa, 0x08, 0, 0, 0, 0, 0,
1433 0, 0, 0x0, 0x0};
1434
1da177e4
LT
1435static int resp_requests(struct scsi_cmnd * scp,
1436 struct sdebug_dev_info * devip)
1437{
1438 unsigned char * sbuff;
01123ef4 1439 unsigned char *cmd = scp->cmnd;
cbf67842 1440 unsigned char arr[SCSI_SENSE_BUFFERSIZE];
2492fc09 1441 bool dsense;
1da177e4
LT
1442 int len = 18;
1443
c65b1445 1444 memset(arr, 0, sizeof(arr));
c2248fc9 1445 dsense = !!(cmd[1] & 1);
cbf67842 1446 sbuff = scp->sense_buffer;
c65b1445 1447 if ((iec_m_pg[2] & 0x4) && (6 == (iec_m_pg[3] & 0xf))) {
c2248fc9 1448 if (dsense) {
c65b1445
DG
1449 arr[0] = 0x72;
1450 arr[1] = 0x0; /* NO_SENSE in sense_key */
1451 arr[2] = THRESHOLD_EXCEEDED;
1452 arr[3] = 0xff; /* TEST set and MRIE==6 */
c2248fc9 1453 len = 8;
c65b1445
DG
1454 } else {
1455 arr[0] = 0x70;
1456 arr[2] = 0x0; /* NO_SENSE in sense_key */
1457 arr[7] = 0xa; /* 18 byte sense buffer */
1458 arr[12] = THRESHOLD_EXCEEDED;
1459 arr[13] = 0xff; /* TEST set and MRIE==6 */
1460 }
c65b1445 1461 } else {
cbf67842 1462 memcpy(arr, sbuff, SCSI_SENSE_BUFFERSIZE);
773642d9 1463 if (arr[0] >= 0x70 && dsense == sdebug_dsense)
c2248fc9
DG
1464 ; /* have sense and formats match */
1465 else if (arr[0] <= 0x70) {
1466 if (dsense) {
1467 memset(arr, 0, 8);
1468 arr[0] = 0x72;
1469 len = 8;
1470 } else {
1471 memset(arr, 0, 18);
1472 arr[0] = 0x70;
1473 arr[7] = 0xa;
1474 }
1475 } else if (dsense) {
1476 memset(arr, 0, 8);
c65b1445
DG
1477 arr[0] = 0x72;
1478 arr[1] = sbuff[2]; /* sense key */
1479 arr[2] = sbuff[12]; /* asc */
1480 arr[3] = sbuff[13]; /* ascq */
1481 len = 8;
c2248fc9
DG
1482 } else {
1483 memset(arr, 0, 18);
1484 arr[0] = 0x70;
1485 arr[2] = sbuff[1];
1486 arr[7] = 0xa;
1487 arr[12] = sbuff[1];
1488 arr[13] = sbuff[3];
c65b1445 1489 }
c2248fc9 1490
c65b1445 1491 }
cbf67842 1492 mk_sense_buffer(scp, 0, NO_ADDITIONAL_SENSE, 0);
1da177e4
LT
1493 return fill_from_dev_buffer(scp, arr, len);
1494}
1495
c65b1445
DG
1496static int resp_start_stop(struct scsi_cmnd * scp,
1497 struct sdebug_dev_info * devip)
1498{
01123ef4 1499 unsigned char *cmd = scp->cmnd;
c4837394 1500 int power_cond, stop;
c65b1445 1501
c65b1445
DG
1502 power_cond = (cmd[4] & 0xf0) >> 4;
1503 if (power_cond) {
22017ed2 1504 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 4, 7);
c65b1445
DG
1505 return check_condition_result;
1506 }
c4837394
DG
1507 stop = !(cmd[4] & 1);
1508 atomic_xchg(&devip->stopped, stop);
c65b1445
DG
1509 return 0;
1510}
1511
28898873
FT
1512static sector_t get_sdebug_capacity(void)
1513{
773642d9
DG
1514 static const unsigned int gibibyte = 1073741824;
1515
1516 if (sdebug_virtual_gb > 0)
1517 return (sector_t)sdebug_virtual_gb *
1518 (gibibyte / sdebug_sector_size);
28898873
FT
1519 else
1520 return sdebug_store_sectors;
1521}
1522
1da177e4
LT
1523#define SDEBUG_READCAP_ARR_SZ 8
1524static int resp_readcap(struct scsi_cmnd * scp,
1525 struct sdebug_dev_info * devip)
1526{
1527 unsigned char arr[SDEBUG_READCAP_ARR_SZ];
c65b1445 1528 unsigned int capac;
1da177e4 1529
c65b1445 1530 /* following just in case virtual_gb changed */
28898873 1531 sdebug_capacity = get_sdebug_capacity();
1da177e4 1532 memset(arr, 0, SDEBUG_READCAP_ARR_SZ);
c65b1445
DG
1533 if (sdebug_capacity < 0xffffffff) {
1534 capac = (unsigned int)sdebug_capacity - 1;
773642d9
DG
1535 put_unaligned_be32(capac, arr + 0);
1536 } else
1537 put_unaligned_be32(0xffffffff, arr + 0);
1538 put_unaligned_be16(sdebug_sector_size, arr + 6);
1da177e4
LT
1539 return fill_from_dev_buffer(scp, arr, SDEBUG_READCAP_ARR_SZ);
1540}
1541
c65b1445
DG
1542#define SDEBUG_READCAP16_ARR_SZ 32
1543static int resp_readcap16(struct scsi_cmnd * scp,
1544 struct sdebug_dev_info * devip)
1545{
01123ef4 1546 unsigned char *cmd = scp->cmnd;
c65b1445 1547 unsigned char arr[SDEBUG_READCAP16_ARR_SZ];
773642d9 1548 int alloc_len;
c65b1445 1549
773642d9 1550 alloc_len = get_unaligned_be32(cmd + 10);
c65b1445 1551 /* following just in case virtual_gb changed */
28898873 1552 sdebug_capacity = get_sdebug_capacity();
c65b1445 1553 memset(arr, 0, SDEBUG_READCAP16_ARR_SZ);
773642d9
DG
1554 put_unaligned_be64((u64)(sdebug_capacity - 1), arr + 0);
1555 put_unaligned_be32(sdebug_sector_size, arr + 8);
1556 arr[13] = sdebug_physblk_exp & 0xf;
1557 arr[14] = (sdebug_lowest_aligned >> 8) & 0x3f;
44d92694 1558
be1dd78d 1559 if (scsi_debug_lbp()) {
5b94e232 1560 arr[14] |= 0x80; /* LBPME */
760f3b03
DG
1561 /* from sbc4r07, this LBPRZ field is 1 bit, but the LBPRZ in
1562 * the LB Provisioning VPD page is 3 bits. Note that lbprz=2
1563 * in the wider field maps to 0 in this field.
1564 */
1565 if (sdebug_lbprz & 1) /* precisely what the draft requires */
1566 arr[14] |= 0x40;
be1dd78d 1567 }
44d92694 1568
773642d9 1569 arr[15] = sdebug_lowest_aligned & 0xff;
c6a44287 1570
760f3b03 1571 if (have_dif_prot) {
773642d9 1572 arr[12] = (sdebug_dif - 1) << 1; /* P_TYPE */
c6a44287
MP
1573 arr[12] |= 1; /* PROT_EN */
1574 }
1575
c65b1445
DG
1576 return fill_from_dev_buffer(scp, arr,
1577 min(alloc_len, SDEBUG_READCAP16_ARR_SZ));
1578}
1579
5a09e398
HR
1580#define SDEBUG_MAX_TGTPGS_ARR_SZ 1412
1581
1582static int resp_report_tgtpgs(struct scsi_cmnd * scp,
1583 struct sdebug_dev_info * devip)
1584{
01123ef4 1585 unsigned char *cmd = scp->cmnd;
5a09e398
HR
1586 unsigned char * arr;
1587 int host_no = devip->sdbg_host->shost->host_no;
1588 int n, ret, alen, rlen;
1589 int port_group_a, port_group_b, port_a, port_b;
1590
773642d9 1591 alen = get_unaligned_be32(cmd + 6);
6f3cbf55
DG
1592 arr = kzalloc(SDEBUG_MAX_TGTPGS_ARR_SZ, GFP_ATOMIC);
1593 if (! arr)
1594 return DID_REQUEUE << 16;
5a09e398
HR
1595 /*
1596 * EVPD page 0x88 states we have two ports, one
1597 * real and a fake port with no device connected.
1598 * So we create two port groups with one port each
1599 * and set the group with port B to unavailable.
1600 */
1601 port_a = 0x1; /* relative port A */
1602 port_b = 0x2; /* relative port B */
1603 port_group_a = (((host_no + 1) & 0x7f) << 8) +
773642d9 1604 (devip->channel & 0x7f);
5a09e398 1605 port_group_b = (((host_no + 1) & 0x7f) << 8) +
773642d9 1606 (devip->channel & 0x7f) + 0x80;
5a09e398
HR
1607
1608 /*
1609 * The asymmetric access state is cycled according to the host_id.
1610 */
1611 n = 4;
b01f6f83 1612 if (sdebug_vpd_use_hostno == 0) {
773642d9
DG
1613 arr[n++] = host_no % 3; /* Asymm access state */
1614 arr[n++] = 0x0F; /* claim: all states are supported */
5a09e398 1615 } else {
773642d9
DG
1616 arr[n++] = 0x0; /* Active/Optimized path */
1617 arr[n++] = 0x01; /* only support active/optimized paths */
5a09e398 1618 }
773642d9
DG
1619 put_unaligned_be16(port_group_a, arr + n);
1620 n += 2;
5a09e398
HR
1621 arr[n++] = 0; /* Reserved */
1622 arr[n++] = 0; /* Status code */
1623 arr[n++] = 0; /* Vendor unique */
1624 arr[n++] = 0x1; /* One port per group */
1625 arr[n++] = 0; /* Reserved */
1626 arr[n++] = 0; /* Reserved */
773642d9
DG
1627 put_unaligned_be16(port_a, arr + n);
1628 n += 2;
5a09e398
HR
1629 arr[n++] = 3; /* Port unavailable */
1630 arr[n++] = 0x08; /* claim: only unavailalbe paths are supported */
773642d9
DG
1631 put_unaligned_be16(port_group_b, arr + n);
1632 n += 2;
5a09e398
HR
1633 arr[n++] = 0; /* Reserved */
1634 arr[n++] = 0; /* Status code */
1635 arr[n++] = 0; /* Vendor unique */
1636 arr[n++] = 0x1; /* One port per group */
1637 arr[n++] = 0; /* Reserved */
1638 arr[n++] = 0; /* Reserved */
773642d9
DG
1639 put_unaligned_be16(port_b, arr + n);
1640 n += 2;
5a09e398
HR
1641
1642 rlen = n - 4;
773642d9 1643 put_unaligned_be32(rlen, arr + 0);
5a09e398
HR
1644
1645 /*
1646 * Return the smallest value of either
1647 * - The allocated length
1648 * - The constructed command length
1649 * - The maximum array size
1650 */
1651 rlen = min(alen,n);
1652 ret = fill_from_dev_buffer(scp, arr,
1653 min(rlen, SDEBUG_MAX_TGTPGS_ARR_SZ));
1654 kfree(arr);
1655 return ret;
1656}
1657
fd32119b
DG
1658static int resp_rsup_opcodes(struct scsi_cmnd *scp,
1659 struct sdebug_dev_info *devip)
38d5c833
DG
1660{
1661 bool rctd;
1662 u8 reporting_opts, req_opcode, sdeb_i, supp;
1663 u16 req_sa, u;
1664 u32 alloc_len, a_len;
1665 int k, offset, len, errsts, count, bump, na;
1666 const struct opcode_info_t *oip;
1667 const struct opcode_info_t *r_oip;
1668 u8 *arr;
1669 u8 *cmd = scp->cmnd;
1670
1671 rctd = !!(cmd[2] & 0x80);
1672 reporting_opts = cmd[2] & 0x7;
1673 req_opcode = cmd[3];
1674 req_sa = get_unaligned_be16(cmd + 4);
1675 alloc_len = get_unaligned_be32(cmd + 6);
6d310dfb 1676 if (alloc_len < 4 || alloc_len > 0xffff) {
38d5c833
DG
1677 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 6, -1);
1678 return check_condition_result;
1679 }
1680 if (alloc_len > 8192)
1681 a_len = 8192;
1682 else
1683 a_len = alloc_len;
99531e60 1684 arr = kzalloc((a_len < 256) ? 320 : a_len + 64, GFP_ATOMIC);
38d5c833
DG
1685 if (NULL == arr) {
1686 mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
1687 INSUFF_RES_ASCQ);
1688 return check_condition_result;
1689 }
1690 switch (reporting_opts) {
1691 case 0: /* all commands */
1692 /* count number of commands */
1693 for (count = 0, oip = opcode_info_arr;
1694 oip->num_attached != 0xff; ++oip) {
1695 if (F_INV_OP & oip->flags)
1696 continue;
1697 count += (oip->num_attached + 1);
1698 }
1699 bump = rctd ? 20 : 8;
1700 put_unaligned_be32(count * bump, arr);
1701 for (offset = 4, oip = opcode_info_arr;
1702 oip->num_attached != 0xff && offset < a_len; ++oip) {
1703 if (F_INV_OP & oip->flags)
1704 continue;
1705 na = oip->num_attached;
1706 arr[offset] = oip->opcode;
1707 put_unaligned_be16(oip->sa, arr + offset + 2);
1708 if (rctd)
1709 arr[offset + 5] |= 0x2;
1710 if (FF_SA & oip->flags)
1711 arr[offset + 5] |= 0x1;
1712 put_unaligned_be16(oip->len_mask[0], arr + offset + 6);
1713 if (rctd)
1714 put_unaligned_be16(0xa, arr + offset + 8);
1715 r_oip = oip;
1716 for (k = 0, oip = oip->arrp; k < na; ++k, ++oip) {
1717 if (F_INV_OP & oip->flags)
1718 continue;
1719 offset += bump;
1720 arr[offset] = oip->opcode;
1721 put_unaligned_be16(oip->sa, arr + offset + 2);
1722 if (rctd)
1723 arr[offset + 5] |= 0x2;
1724 if (FF_SA & oip->flags)
1725 arr[offset + 5] |= 0x1;
1726 put_unaligned_be16(oip->len_mask[0],
1727 arr + offset + 6);
1728 if (rctd)
1729 put_unaligned_be16(0xa,
1730 arr + offset + 8);
1731 }
1732 oip = r_oip;
1733 offset += bump;
1734 }
1735 break;
1736 case 1: /* one command: opcode only */
1737 case 2: /* one command: opcode plus service action */
1738 case 3: /* one command: if sa==0 then opcode only else opcode+sa */
1739 sdeb_i = opcode_ind_arr[req_opcode];
1740 oip = &opcode_info_arr[sdeb_i];
1741 if (F_INV_OP & oip->flags) {
1742 supp = 1;
1743 offset = 4;
1744 } else {
1745 if (1 == reporting_opts) {
1746 if (FF_SA & oip->flags) {
1747 mk_sense_invalid_fld(scp, SDEB_IN_CDB,
1748 2, 2);
1749 kfree(arr);
1750 return check_condition_result;
1751 }
1752 req_sa = 0;
1753 } else if (2 == reporting_opts &&
1754 0 == (FF_SA & oip->flags)) {
1755 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 4, -1);
1756 kfree(arr); /* point at requested sa */
1757 return check_condition_result;
1758 }
1759 if (0 == (FF_SA & oip->flags) &&
1760 req_opcode == oip->opcode)
1761 supp = 3;
1762 else if (0 == (FF_SA & oip->flags)) {
1763 na = oip->num_attached;
1764 for (k = 0, oip = oip->arrp; k < na;
1765 ++k, ++oip) {
1766 if (req_opcode == oip->opcode)
1767 break;
1768 }
1769 supp = (k >= na) ? 1 : 3;
1770 } else if (req_sa != oip->sa) {
1771 na = oip->num_attached;
1772 for (k = 0, oip = oip->arrp; k < na;
1773 ++k, ++oip) {
1774 if (req_sa == oip->sa)
1775 break;
1776 }
1777 supp = (k >= na) ? 1 : 3;
1778 } else
1779 supp = 3;
1780 if (3 == supp) {
1781 u = oip->len_mask[0];
1782 put_unaligned_be16(u, arr + 2);
1783 arr[4] = oip->opcode;
1784 for (k = 1; k < u; ++k)
1785 arr[4 + k] = (k < 16) ?
1786 oip->len_mask[k] : 0xff;
1787 offset = 4 + u;
1788 } else
1789 offset = 4;
1790 }
1791 arr[1] = (rctd ? 0x80 : 0) | supp;
1792 if (rctd) {
1793 put_unaligned_be16(0xa, arr + offset);
1794 offset += 12;
1795 }
1796 break;
1797 default:
1798 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, 2);
1799 kfree(arr);
1800 return check_condition_result;
1801 }
1802 offset = (offset < a_len) ? offset : a_len;
1803 len = (offset < alloc_len) ? offset : alloc_len;
1804 errsts = fill_from_dev_buffer(scp, arr, len);
1805 kfree(arr);
1806 return errsts;
1807}
1808
fd32119b
DG
1809static int resp_rsup_tmfs(struct scsi_cmnd *scp,
1810 struct sdebug_dev_info *devip)
38d5c833
DG
1811{
1812 bool repd;
1813 u32 alloc_len, len;
1814 u8 arr[16];
1815 u8 *cmd = scp->cmnd;
1816
1817 memset(arr, 0, sizeof(arr));
1818 repd = !!(cmd[2] & 0x80);
1819 alloc_len = get_unaligned_be32(cmd + 6);
1820 if (alloc_len < 4) {
1821 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 6, -1);
1822 return check_condition_result;
1823 }
1824 arr[0] = 0xc8; /* ATS | ATSS | LURS */
1825 arr[1] = 0x1; /* ITNRS */
1826 if (repd) {
1827 arr[3] = 0xc;
1828 len = 16;
1829 } else
1830 len = 4;
1831
1832 len = (len < alloc_len) ? len : alloc_len;
1833 return fill_from_dev_buffer(scp, arr, len);
1834}
1835
1da177e4
LT
1836/* <<Following mode page info copied from ST318451LW>> */
1837
1838static int resp_err_recov_pg(unsigned char * p, int pcontrol, int target)
1839{ /* Read-Write Error Recovery page for mode_sense */
1840 unsigned char err_recov_pg[] = {0x1, 0xa, 0xc0, 11, 240, 0, 0, 0,
1841 5, 0, 0xff, 0xff};
1842
1843 memcpy(p, err_recov_pg, sizeof(err_recov_pg));
1844 if (1 == pcontrol)
1845 memset(p + 2, 0, sizeof(err_recov_pg) - 2);
1846 return sizeof(err_recov_pg);
1847}
1848
1849static int resp_disconnect_pg(unsigned char * p, int pcontrol, int target)
1850{ /* Disconnect-Reconnect page for mode_sense */
1851 unsigned char disconnect_pg[] = {0x2, 0xe, 128, 128, 0, 10, 0, 0,
1852 0, 0, 0, 0, 0, 0, 0, 0};
1853
1854 memcpy(p, disconnect_pg, sizeof(disconnect_pg));
1855 if (1 == pcontrol)
1856 memset(p + 2, 0, sizeof(disconnect_pg) - 2);
1857 return sizeof(disconnect_pg);
1858}
1859
1860static int resp_format_pg(unsigned char * p, int pcontrol, int target)
1861{ /* Format device page for mode_sense */
597136ab
MP
1862 unsigned char format_pg[] = {0x3, 0x16, 0, 0, 0, 0, 0, 0,
1863 0, 0, 0, 0, 0, 0, 0, 0,
1864 0, 0, 0, 0, 0x40, 0, 0, 0};
1865
1866 memcpy(p, format_pg, sizeof(format_pg));
773642d9
DG
1867 put_unaligned_be16(sdebug_sectors_per, p + 10);
1868 put_unaligned_be16(sdebug_sector_size, p + 12);
1869 if (sdebug_removable)
597136ab
MP
1870 p[20] |= 0x20; /* should agree with INQUIRY */
1871 if (1 == pcontrol)
1872 memset(p + 2, 0, sizeof(format_pg) - 2);
1873 return sizeof(format_pg);
1da177e4
LT
1874}
1875
fd32119b
DG
1876static unsigned char caching_pg[] = {0x8, 18, 0x14, 0, 0xff, 0xff, 0, 0,
1877 0xff, 0xff, 0xff, 0xff, 0x80, 0x14, 0, 0,
1878 0, 0, 0, 0};
1879
1da177e4
LT
1880static int resp_caching_pg(unsigned char * p, int pcontrol, int target)
1881{ /* Caching page for mode_sense */
cbf67842
DG
1882 unsigned char ch_caching_pg[] = {/* 0x8, 18, */ 0x4, 0, 0, 0, 0, 0,
1883 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0};
1884 unsigned char d_caching_pg[] = {0x8, 18, 0x14, 0, 0xff, 0xff, 0, 0,
1da177e4
LT
1885 0xff, 0xff, 0xff, 0xff, 0x80, 0x14, 0, 0, 0, 0, 0, 0};
1886
773642d9 1887 if (SDEBUG_OPT_N_WCE & sdebug_opts)
cbf67842 1888 caching_pg[2] &= ~0x4; /* set WCE=0 (default WCE=1) */
1da177e4
LT
1889 memcpy(p, caching_pg, sizeof(caching_pg));
1890 if (1 == pcontrol)
cbf67842
DG
1891 memcpy(p + 2, ch_caching_pg, sizeof(ch_caching_pg));
1892 else if (2 == pcontrol)
1893 memcpy(p, d_caching_pg, sizeof(d_caching_pg));
1da177e4
LT
1894 return sizeof(caching_pg);
1895}
1896
fd32119b
DG
1897static unsigned char ctrl_m_pg[] = {0xa, 10, 2, 0, 0, 0, 0, 0,
1898 0, 0, 0x2, 0x4b};
1899
1da177e4
LT
1900static int resp_ctrl_m_pg(unsigned char * p, int pcontrol, int target)
1901{ /* Control mode page for mode_sense */
c65b1445
DG
1902 unsigned char ch_ctrl_m_pg[] = {/* 0xa, 10, */ 0x6, 0, 0, 0, 0, 0,
1903 0, 0, 0, 0};
1904 unsigned char d_ctrl_m_pg[] = {0xa, 10, 2, 0, 0, 0, 0, 0,
1da177e4
LT
1905 0, 0, 0x2, 0x4b};
1906
773642d9 1907 if (sdebug_dsense)
1da177e4 1908 ctrl_m_pg[2] |= 0x4;
c65b1445
DG
1909 else
1910 ctrl_m_pg[2] &= ~0x4;
c6a44287 1911
773642d9 1912 if (sdebug_ato)
c6a44287
MP
1913 ctrl_m_pg[5] |= 0x80; /* ATO=1 */
1914
1da177e4
LT
1915 memcpy(p, ctrl_m_pg, sizeof(ctrl_m_pg));
1916 if (1 == pcontrol)
c65b1445
DG
1917 memcpy(p + 2, ch_ctrl_m_pg, sizeof(ch_ctrl_m_pg));
1918 else if (2 == pcontrol)
1919 memcpy(p, d_ctrl_m_pg, sizeof(d_ctrl_m_pg));
1da177e4
LT
1920 return sizeof(ctrl_m_pg);
1921}
1922
c65b1445 1923
1da177e4
LT
1924static int resp_iec_m_pg(unsigned char * p, int pcontrol, int target)
1925{ /* Informational Exceptions control mode page for mode_sense */
c65b1445
DG
1926 unsigned char ch_iec_m_pg[] = {/* 0x1c, 0xa, */ 0x4, 0xf, 0, 0, 0, 0,
1927 0, 0, 0x0, 0x0};
1928 unsigned char d_iec_m_pg[] = {0x1c, 0xa, 0x08, 0, 0, 0, 0, 0,
1929 0, 0, 0x0, 0x0};
1930
1da177e4
LT
1931 memcpy(p, iec_m_pg, sizeof(iec_m_pg));
1932 if (1 == pcontrol)
c65b1445
DG
1933 memcpy(p + 2, ch_iec_m_pg, sizeof(ch_iec_m_pg));
1934 else if (2 == pcontrol)
1935 memcpy(p, d_iec_m_pg, sizeof(d_iec_m_pg));
1da177e4
LT
1936 return sizeof(iec_m_pg);
1937}
1938
c65b1445
DG
1939static int resp_sas_sf_m_pg(unsigned char * p, int pcontrol, int target)
1940{ /* SAS SSP mode page - short format for mode_sense */
1941 unsigned char sas_sf_m_pg[] = {0x19, 0x6,
1942 0x6, 0x0, 0x7, 0xd0, 0x0, 0x0};
1943
1944 memcpy(p, sas_sf_m_pg, sizeof(sas_sf_m_pg));
1945 if (1 == pcontrol)
1946 memset(p + 2, 0, sizeof(sas_sf_m_pg) - 2);
1947 return sizeof(sas_sf_m_pg);
1948}
1949
1950
1951static int resp_sas_pcd_m_spg(unsigned char * p, int pcontrol, int target,
1952 int target_dev_id)
1953{ /* SAS phy control and discover mode page for mode_sense */
1954 unsigned char sas_pcd_m_pg[] = {0x59, 0x1, 0, 0x64, 0, 0x6, 0, 2,
1955 0, 0, 0, 0, 0x10, 0x9, 0x8, 0x0,
773642d9
DG
1956 0, 0, 0, 0, 0, 0, 0, 0, /* insert SAS addr */
1957 0, 0, 0, 0, 0, 0, 0, 0, /* insert SAS addr */
c65b1445
DG
1958 0x2, 0, 0, 0, 0, 0, 0, 0,
1959 0x88, 0x99, 0, 0, 0, 0, 0, 0,
1960 0, 0, 0, 0, 0, 0, 0, 0,
1961 0, 1, 0, 0, 0x10, 0x9, 0x8, 0x0,
773642d9
DG
1962 0, 0, 0, 0, 0, 0, 0, 0, /* insert SAS addr */
1963 0, 0, 0, 0, 0, 0, 0, 0, /* insert SAS addr */
c65b1445
DG
1964 0x3, 0, 0, 0, 0, 0, 0, 0,
1965 0x88, 0x99, 0, 0, 0, 0, 0, 0,
1966 0, 0, 0, 0, 0, 0, 0, 0,
1967 };
1968 int port_a, port_b;
1969
1b37bd60
DG
1970 put_unaligned_be64(naa3_comp_a, sas_pcd_m_pg + 16);
1971 put_unaligned_be64(naa3_comp_c + 1, sas_pcd_m_pg + 24);
1972 put_unaligned_be64(naa3_comp_a, sas_pcd_m_pg + 64);
1973 put_unaligned_be64(naa3_comp_c + 1, sas_pcd_m_pg + 72);
c65b1445
DG
1974 port_a = target_dev_id + 1;
1975 port_b = port_a + 1;
1976 memcpy(p, sas_pcd_m_pg, sizeof(sas_pcd_m_pg));
773642d9
DG
1977 put_unaligned_be32(port_a, p + 20);
1978 put_unaligned_be32(port_b, p + 48 + 20);
c65b1445
DG
1979 if (1 == pcontrol)
1980 memset(p + 4, 0, sizeof(sas_pcd_m_pg) - 4);
1981 return sizeof(sas_pcd_m_pg);
1982}
1983
1984static int resp_sas_sha_m_spg(unsigned char * p, int pcontrol)
1985{ /* SAS SSP shared protocol specific port mode subpage */
1986 unsigned char sas_sha_m_pg[] = {0x59, 0x2, 0, 0xc, 0, 0x6, 0x10, 0,
1987 0, 0, 0, 0, 0, 0, 0, 0,
1988 };
1989
1990 memcpy(p, sas_sha_m_pg, sizeof(sas_sha_m_pg));
1991 if (1 == pcontrol)
1992 memset(p + 4, 0, sizeof(sas_sha_m_pg) - 4);
1993 return sizeof(sas_sha_m_pg);
1994}
1995
1da177e4
LT
1996#define SDEBUG_MAX_MSENSE_SZ 256
1997
fd32119b
DG
1998static int resp_mode_sense(struct scsi_cmnd *scp,
1999 struct sdebug_dev_info *devip)
1da177e4 2000{
23183910 2001 int pcontrol, pcode, subpcode, bd_len;
1da177e4 2002 unsigned char dev_spec;
760f3b03 2003 int alloc_len, offset, len, target_dev_id;
c2248fc9 2004 int target = scp->device->id;
1da177e4
LT
2005 unsigned char * ap;
2006 unsigned char arr[SDEBUG_MAX_MSENSE_SZ];
01123ef4 2007 unsigned char *cmd = scp->cmnd;
760f3b03 2008 bool dbd, llbaa, msense_6, is_disk, bad_pcode;
1da177e4 2009
760f3b03 2010 dbd = !!(cmd[1] & 0x8); /* disable block descriptors */
1da177e4
LT
2011 pcontrol = (cmd[2] & 0xc0) >> 6;
2012 pcode = cmd[2] & 0x3f;
2013 subpcode = cmd[3];
2014 msense_6 = (MODE_SENSE == cmd[0]);
760f3b03
DG
2015 llbaa = msense_6 ? false : !!(cmd[1] & 0x10);
2016 is_disk = (sdebug_ptype == TYPE_DISK);
2017 if (is_disk && !dbd)
23183910
DG
2018 bd_len = llbaa ? 16 : 8;
2019 else
2020 bd_len = 0;
773642d9 2021 alloc_len = msense_6 ? cmd[4] : get_unaligned_be16(cmd + 7);
1da177e4
LT
2022 memset(arr, 0, SDEBUG_MAX_MSENSE_SZ);
2023 if (0x3 == pcontrol) { /* Saving values not supported */
cbf67842 2024 mk_sense_buffer(scp, ILLEGAL_REQUEST, SAVING_PARAMS_UNSUP, 0);
1da177e4
LT
2025 return check_condition_result;
2026 }
c65b1445
DG
2027 target_dev_id = ((devip->sdbg_host->shost->host_no + 1) * 2000) +
2028 (devip->target * 1000) - 3;
b01f6f83 2029 /* for disks set DPOFUA bit and clear write protect (WP) bit */
760f3b03 2030 if (is_disk)
b01f6f83 2031 dev_spec = 0x10; /* =0x90 if WP=1 implies read-only */
23183910
DG
2032 else
2033 dev_spec = 0x0;
1da177e4
LT
2034 if (msense_6) {
2035 arr[2] = dev_spec;
23183910 2036 arr[3] = bd_len;
1da177e4
LT
2037 offset = 4;
2038 } else {
2039 arr[3] = dev_spec;
23183910
DG
2040 if (16 == bd_len)
2041 arr[4] = 0x1; /* set LONGLBA bit */
2042 arr[7] = bd_len; /* assume 255 or less */
1da177e4
LT
2043 offset = 8;
2044 }
2045 ap = arr + offset;
28898873
FT
2046 if ((bd_len > 0) && (!sdebug_capacity))
2047 sdebug_capacity = get_sdebug_capacity();
2048
23183910 2049 if (8 == bd_len) {
773642d9
DG
2050 if (sdebug_capacity > 0xfffffffe)
2051 put_unaligned_be32(0xffffffff, ap + 0);
2052 else
2053 put_unaligned_be32(sdebug_capacity, ap + 0);
2054 put_unaligned_be16(sdebug_sector_size, ap + 6);
23183910
DG
2055 offset += bd_len;
2056 ap = arr + offset;
2057 } else if (16 == bd_len) {
773642d9
DG
2058 put_unaligned_be64((u64)sdebug_capacity, ap + 0);
2059 put_unaligned_be32(sdebug_sector_size, ap + 12);
23183910
DG
2060 offset += bd_len;
2061 ap = arr + offset;
2062 }
1da177e4 2063
c65b1445
DG
2064 if ((subpcode > 0x0) && (subpcode < 0xff) && (0x19 != pcode)) {
2065 /* TODO: Control Extension page */
22017ed2 2066 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 3, -1);
1da177e4
LT
2067 return check_condition_result;
2068 }
760f3b03
DG
2069 bad_pcode = false;
2070
1da177e4
LT
2071 switch (pcode) {
2072 case 0x1: /* Read-Write error recovery page, direct access */
2073 len = resp_err_recov_pg(ap, pcontrol, target);
2074 offset += len;
2075 break;
2076 case 0x2: /* Disconnect-Reconnect page, all devices */
2077 len = resp_disconnect_pg(ap, pcontrol, target);
2078 offset += len;
2079 break;
2080 case 0x3: /* Format device page, direct access */
760f3b03
DG
2081 if (is_disk) {
2082 len = resp_format_pg(ap, pcontrol, target);
2083 offset += len;
2084 } else
2085 bad_pcode = true;
1da177e4
LT
2086 break;
2087 case 0x8: /* Caching page, direct access */
760f3b03
DG
2088 if (is_disk) {
2089 len = resp_caching_pg(ap, pcontrol, target);
2090 offset += len;
2091 } else
2092 bad_pcode = true;
1da177e4
LT
2093 break;
2094 case 0xa: /* Control Mode page, all devices */
2095 len = resp_ctrl_m_pg(ap, pcontrol, target);
2096 offset += len;
2097 break;
c65b1445
DG
2098 case 0x19: /* if spc==1 then sas phy, control+discover */
2099 if ((subpcode > 0x2) && (subpcode < 0xff)) {
22017ed2 2100 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 3, -1);
c65b1445
DG
2101 return check_condition_result;
2102 }
2103 len = 0;
2104 if ((0x0 == subpcode) || (0xff == subpcode))
2105 len += resp_sas_sf_m_pg(ap + len, pcontrol, target);
2106 if ((0x1 == subpcode) || (0xff == subpcode))
2107 len += resp_sas_pcd_m_spg(ap + len, pcontrol, target,
2108 target_dev_id);
2109 if ((0x2 == subpcode) || (0xff == subpcode))
2110 len += resp_sas_sha_m_spg(ap + len, pcontrol);
2111 offset += len;
2112 break;
1da177e4
LT
2113 case 0x1c: /* Informational Exceptions Mode page, all devices */
2114 len = resp_iec_m_pg(ap, pcontrol, target);
2115 offset += len;
2116 break;
2117 case 0x3f: /* Read all Mode pages */
c65b1445
DG
2118 if ((0 == subpcode) || (0xff == subpcode)) {
2119 len = resp_err_recov_pg(ap, pcontrol, target);
2120 len += resp_disconnect_pg(ap + len, pcontrol, target);
760f3b03
DG
2121 if (is_disk) {
2122 len += resp_format_pg(ap + len, pcontrol,
2123 target);
2124 len += resp_caching_pg(ap + len, pcontrol,
2125 target);
2126 }
c65b1445
DG
2127 len += resp_ctrl_m_pg(ap + len, pcontrol, target);
2128 len += resp_sas_sf_m_pg(ap + len, pcontrol, target);
2129 if (0xff == subpcode) {
2130 len += resp_sas_pcd_m_spg(ap + len, pcontrol,
2131 target, target_dev_id);
2132 len += resp_sas_sha_m_spg(ap + len, pcontrol);
2133 }
2134 len += resp_iec_m_pg(ap + len, pcontrol, target);
760f3b03 2135 offset += len;
c65b1445 2136 } else {
22017ed2 2137 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 3, -1);
c65b1445
DG
2138 return check_condition_result;
2139 }
1da177e4
LT
2140 break;
2141 default:
760f3b03
DG
2142 bad_pcode = true;
2143 break;
2144 }
2145 if (bad_pcode) {
22017ed2 2146 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, 5);
1da177e4
LT
2147 return check_condition_result;
2148 }
2149 if (msense_6)
2150 arr[0] = offset - 1;
773642d9
DG
2151 else
2152 put_unaligned_be16((offset - 2), arr + 0);
1da177e4
LT
2153 return fill_from_dev_buffer(scp, arr, min(alloc_len, offset));
2154}
2155
c65b1445
DG
2156#define SDEBUG_MAX_MSELECT_SZ 512
2157
fd32119b
DG
2158static int resp_mode_select(struct scsi_cmnd *scp,
2159 struct sdebug_dev_info *devip)
c65b1445
DG
2160{
2161 int pf, sp, ps, md_len, bd_len, off, spf, pg_len;
c2248fc9 2162 int param_len, res, mpage;
c65b1445 2163 unsigned char arr[SDEBUG_MAX_MSELECT_SZ];
01123ef4 2164 unsigned char *cmd = scp->cmnd;
c2248fc9 2165 int mselect6 = (MODE_SELECT == cmd[0]);
c65b1445 2166
c65b1445
DG
2167 memset(arr, 0, sizeof(arr));
2168 pf = cmd[1] & 0x10;
2169 sp = cmd[1] & 0x1;
773642d9 2170 param_len = mselect6 ? cmd[4] : get_unaligned_be16(cmd + 7);
c65b1445 2171 if ((0 == pf) || sp || (param_len > SDEBUG_MAX_MSELECT_SZ)) {
22017ed2 2172 mk_sense_invalid_fld(scp, SDEB_IN_CDB, mselect6 ? 4 : 7, -1);
c65b1445
DG
2173 return check_condition_result;
2174 }
2175 res = fetch_to_dev_buffer(scp, arr, param_len);
2176 if (-1 == res)
773642d9
DG
2177 return DID_ERROR << 16;
2178 else if (sdebug_verbose && (res < param_len))
cbf67842
DG
2179 sdev_printk(KERN_INFO, scp->device,
2180 "%s: cdb indicated=%d, IO sent=%d bytes\n",
2181 __func__, param_len, res);
773642d9
DG
2182 md_len = mselect6 ? (arr[0] + 1) : (get_unaligned_be16(arr + 0) + 2);
2183 bd_len = mselect6 ? arr[3] : get_unaligned_be16(arr + 6);
23183910 2184 if (md_len > 2) {
22017ed2 2185 mk_sense_invalid_fld(scp, SDEB_IN_DATA, 0, -1);
c65b1445
DG
2186 return check_condition_result;
2187 }
2188 off = bd_len + (mselect6 ? 4 : 8);
2189 mpage = arr[off] & 0x3f;
2190 ps = !!(arr[off] & 0x80);
2191 if (ps) {
22017ed2 2192 mk_sense_invalid_fld(scp, SDEB_IN_DATA, off, 7);
c65b1445
DG
2193 return check_condition_result;
2194 }
2195 spf = !!(arr[off] & 0x40);
773642d9 2196 pg_len = spf ? (get_unaligned_be16(arr + off + 2) + 4) :
c65b1445
DG
2197 (arr[off + 1] + 2);
2198 if ((pg_len + off) > param_len) {
cbf67842 2199 mk_sense_buffer(scp, ILLEGAL_REQUEST,
c65b1445
DG
2200 PARAMETER_LIST_LENGTH_ERR, 0);
2201 return check_condition_result;
2202 }
2203 switch (mpage) {
cbf67842
DG
2204 case 0x8: /* Caching Mode page */
2205 if (caching_pg[1] == arr[off + 1]) {
2206 memcpy(caching_pg + 2, arr + off + 2,
2207 sizeof(caching_pg) - 2);
2208 goto set_mode_changed_ua;
2209 }
2210 break;
c65b1445
DG
2211 case 0xa: /* Control Mode page */
2212 if (ctrl_m_pg[1] == arr[off + 1]) {
2213 memcpy(ctrl_m_pg + 2, arr + off + 2,
2214 sizeof(ctrl_m_pg) - 2);
773642d9 2215 sdebug_dsense = !!(ctrl_m_pg[2] & 0x4);
cbf67842 2216 goto set_mode_changed_ua;
c65b1445
DG
2217 }
2218 break;
2219 case 0x1c: /* Informational Exceptions Mode page */
2220 if (iec_m_pg[1] == arr[off + 1]) {
2221 memcpy(iec_m_pg + 2, arr + off + 2,
2222 sizeof(iec_m_pg) - 2);
cbf67842 2223 goto set_mode_changed_ua;
c65b1445
DG
2224 }
2225 break;
2226 default:
2227 break;
2228 }
22017ed2 2229 mk_sense_invalid_fld(scp, SDEB_IN_DATA, off, 5);
c65b1445 2230 return check_condition_result;
cbf67842
DG
2231set_mode_changed_ua:
2232 set_bit(SDEBUG_UA_MODE_CHANGED, devip->uas_bm);
2233 return 0;
c65b1445
DG
2234}
2235
2236static int resp_temp_l_pg(unsigned char * arr)
2237{
2238 unsigned char temp_l_pg[] = {0x0, 0x0, 0x3, 0x2, 0x0, 38,
2239 0x0, 0x1, 0x3, 0x2, 0x0, 65,
2240 };
2241
2242 memcpy(arr, temp_l_pg, sizeof(temp_l_pg));
2243 return sizeof(temp_l_pg);
2244}
2245
2246static int resp_ie_l_pg(unsigned char * arr)
2247{
2248 unsigned char ie_l_pg[] = {0x0, 0x0, 0x3, 0x3, 0x0, 0x0, 38,
2249 };
2250
2251 memcpy(arr, ie_l_pg, sizeof(ie_l_pg));
2252 if (iec_m_pg[2] & 0x4) { /* TEST bit set */
2253 arr[4] = THRESHOLD_EXCEEDED;
2254 arr[5] = 0xff;
2255 }
2256 return sizeof(ie_l_pg);
2257}
2258
2259#define SDEBUG_MAX_LSENSE_SZ 512
2260
2261static int resp_log_sense(struct scsi_cmnd * scp,
2262 struct sdebug_dev_info * devip)
2263{
ab17241c 2264 int ppc, sp, pcode, subpcode, alloc_len, len, n;
c65b1445 2265 unsigned char arr[SDEBUG_MAX_LSENSE_SZ];
01123ef4 2266 unsigned char *cmd = scp->cmnd;
c65b1445 2267
c65b1445
DG
2268 memset(arr, 0, sizeof(arr));
2269 ppc = cmd[1] & 0x2;
2270 sp = cmd[1] & 0x1;
2271 if (ppc || sp) {
22017ed2 2272 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, ppc ? 1 : 0);
c65b1445
DG
2273 return check_condition_result;
2274 }
c65b1445 2275 pcode = cmd[2] & 0x3f;
23183910 2276 subpcode = cmd[3] & 0xff;
773642d9 2277 alloc_len = get_unaligned_be16(cmd + 7);
c65b1445 2278 arr[0] = pcode;
23183910
DG
2279 if (0 == subpcode) {
2280 switch (pcode) {
2281 case 0x0: /* Supported log pages log page */
2282 n = 4;
2283 arr[n++] = 0x0; /* this page */
2284 arr[n++] = 0xd; /* Temperature */
2285 arr[n++] = 0x2f; /* Informational exceptions */
2286 arr[3] = n - 4;
2287 break;
2288 case 0xd: /* Temperature log page */
2289 arr[3] = resp_temp_l_pg(arr + 4);
2290 break;
2291 case 0x2f: /* Informational exceptions log page */
2292 arr[3] = resp_ie_l_pg(arr + 4);
2293 break;
2294 default:
22017ed2 2295 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, 5);
23183910
DG
2296 return check_condition_result;
2297 }
2298 } else if (0xff == subpcode) {
2299 arr[0] |= 0x40;
2300 arr[1] = subpcode;
2301 switch (pcode) {
2302 case 0x0: /* Supported log pages and subpages log page */
2303 n = 4;
2304 arr[n++] = 0x0;
2305 arr[n++] = 0x0; /* 0,0 page */
2306 arr[n++] = 0x0;
2307 arr[n++] = 0xff; /* this page */
2308 arr[n++] = 0xd;
2309 arr[n++] = 0x0; /* Temperature */
2310 arr[n++] = 0x2f;
2311 arr[n++] = 0x0; /* Informational exceptions */
2312 arr[3] = n - 4;
2313 break;
2314 case 0xd: /* Temperature subpages */
2315 n = 4;
2316 arr[n++] = 0xd;
2317 arr[n++] = 0x0; /* Temperature */
2318 arr[3] = n - 4;
2319 break;
2320 case 0x2f: /* Informational exceptions subpages */
2321 n = 4;
2322 arr[n++] = 0x2f;
2323 arr[n++] = 0x0; /* Informational exceptions */
2324 arr[3] = n - 4;
2325 break;
2326 default:
22017ed2 2327 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, 5);
23183910
DG
2328 return check_condition_result;
2329 }
2330 } else {
22017ed2 2331 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 3, -1);
c65b1445
DG
2332 return check_condition_result;
2333 }
773642d9 2334 len = min(get_unaligned_be16(arr + 2) + 4, alloc_len);
c65b1445
DG
2335 return fill_from_dev_buffer(scp, arr,
2336 min(len, SDEBUG_MAX_INQ_ARR_SZ));
2337}
2338
cbf67842 2339static int check_device_access_params(struct scsi_cmnd *scp,
19789100 2340 unsigned long long lba, unsigned int num)
1da177e4 2341{
c65b1445 2342 if (lba + num > sdebug_capacity) {
22017ed2 2343 mk_sense_buffer(scp, ILLEGAL_REQUEST, LBA_OUT_OF_RANGE, 0);
1da177e4
LT
2344 return check_condition_result;
2345 }
c65b1445
DG
2346 /* transfer length excessive (tie in to block limits VPD page) */
2347 if (num > sdebug_store_sectors) {
22017ed2 2348 /* needs work to find which cdb byte 'num' comes from */
cbf67842 2349 mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_FIELD_IN_CDB, 0);
c65b1445
DG
2350 return check_condition_result;
2351 }
19789100
FT
2352 return 0;
2353}
2354
a4517511 2355/* Returns number of bytes copied or -1 if error. */
fd32119b
DG
2356static int do_device_access(struct scsi_cmnd *scmd, u64 lba, u32 num,
2357 bool do_write)
19789100
FT
2358{
2359 int ret;
c2248fc9 2360 u64 block, rest = 0;
a4517511
AM
2361 struct scsi_data_buffer *sdb;
2362 enum dma_data_direction dir;
a4517511 2363
c2248fc9 2364 if (do_write) {
a4517511
AM
2365 sdb = scsi_out(scmd);
2366 dir = DMA_TO_DEVICE;
a4517511
AM
2367 } else {
2368 sdb = scsi_in(scmd);
2369 dir = DMA_FROM_DEVICE;
a4517511 2370 }
19789100 2371
a4517511
AM
2372 if (!sdb->length)
2373 return 0;
2374 if (!(scsi_bidi_cmnd(scmd) || scmd->sc_data_direction == dir))
2375 return -1;
19789100
FT
2376
2377 block = do_div(lba, sdebug_store_sectors);
2378 if (block + num > sdebug_store_sectors)
2379 rest = block + num - sdebug_store_sectors;
2380
386ecb12 2381 ret = sg_copy_buffer(sdb->table.sgl, sdb->table.nents,
773642d9
DG
2382 fake_storep + (block * sdebug_sector_size),
2383 (num - rest) * sdebug_sector_size, 0, do_write);
2384 if (ret != (num - rest) * sdebug_sector_size)
a4517511
AM
2385 return ret;
2386
2387 if (rest) {
386ecb12 2388 ret += sg_copy_buffer(sdb->table.sgl, sdb->table.nents,
773642d9
DG
2389 fake_storep, rest * sdebug_sector_size,
2390 (num - rest) * sdebug_sector_size, do_write);
a4517511 2391 }
19789100
FT
2392
2393 return ret;
2394}
2395
38d5c833
DG
2396/* If fake_store(lba,num) compares equal to arr(num), then copy top half of
2397 * arr into fake_store(lba,num) and return true. If comparison fails then
2398 * return false. */
fd32119b 2399static bool comp_write_worker(u64 lba, u32 num, const u8 *arr)
38d5c833
DG
2400{
2401 bool res;
2402 u64 block, rest = 0;
2403 u32 store_blks = sdebug_store_sectors;
773642d9 2404 u32 lb_size = sdebug_sector_size;
38d5c833
DG
2405
2406 block = do_div(lba, store_blks);
2407 if (block + num > store_blks)
2408 rest = block + num - store_blks;
2409
2410 res = !memcmp(fake_storep + (block * lb_size), arr,
2411 (num - rest) * lb_size);
2412 if (!res)
2413 return res;
2414 if (rest)
2415 res = memcmp(fake_storep, arr + ((num - rest) * lb_size),
2416 rest * lb_size);
2417 if (!res)
2418 return res;
2419 arr += num * lb_size;
2420 memcpy(fake_storep + (block * lb_size), arr, (num - rest) * lb_size);
2421 if (rest)
2422 memcpy(fake_storep, arr + ((num - rest) * lb_size),
2423 rest * lb_size);
2424 return res;
2425}
2426
51d648af 2427static __be16 dif_compute_csum(const void *buf, int len)
beb40ea4 2428{
51d648af 2429 __be16 csum;
beb40ea4 2430
773642d9 2431 if (sdebug_guard)
51d648af
AM
2432 csum = (__force __be16)ip_compute_csum(buf, len);
2433 else
beb40ea4 2434 csum = cpu_to_be16(crc_t10dif(buf, len));
51d648af 2435
beb40ea4
AM
2436 return csum;
2437}
2438
6ebf105c 2439static int dif_verify(struct t10_pi_tuple *sdt, const void *data,
beb40ea4
AM
2440 sector_t sector, u32 ei_lba)
2441{
773642d9 2442 __be16 csum = dif_compute_csum(data, sdebug_sector_size);
beb40ea4
AM
2443
2444 if (sdt->guard_tag != csum) {
c1287970 2445 pr_err("GUARD check failed on sector %lu rcvd 0x%04x, data 0x%04x\n",
beb40ea4
AM
2446 (unsigned long)sector,
2447 be16_to_cpu(sdt->guard_tag),
2448 be16_to_cpu(csum));
2449 return 0x01;
2450 }
8475c811 2451 if (sdebug_dif == T10_PI_TYPE1_PROTECTION &&
beb40ea4 2452 be32_to_cpu(sdt->ref_tag) != (sector & 0xffffffff)) {
c1287970
TW
2453 pr_err("REF check failed on sector %lu\n",
2454 (unsigned long)sector);
beb40ea4
AM
2455 return 0x03;
2456 }
8475c811 2457 if (sdebug_dif == T10_PI_TYPE2_PROTECTION &&
beb40ea4 2458 be32_to_cpu(sdt->ref_tag) != ei_lba) {
c1287970
TW
2459 pr_err("REF check failed on sector %lu\n",
2460 (unsigned long)sector);
beb40ea4
AM
2461 return 0x03;
2462 }
2463 return 0;
2464}
2465
bb8c063c 2466static void dif_copy_prot(struct scsi_cmnd *SCpnt, sector_t sector,
65f72f2a 2467 unsigned int sectors, bool read)
c6a44287 2468{
be4e11be 2469 size_t resid;
c6a44287 2470 void *paddr;
14faa944 2471 const void *dif_store_end = dif_storep + sdebug_store_sectors;
be4e11be 2472 struct sg_mapping_iter miter;
c6a44287 2473
e18d8bea
AM
2474 /* Bytes of protection data to copy into sgl */
2475 resid = sectors * sizeof(*dif_storep);
c6a44287 2476
be4e11be
AM
2477 sg_miter_start(&miter, scsi_prot_sglist(SCpnt),
2478 scsi_prot_sg_count(SCpnt), SG_MITER_ATOMIC |
2479 (read ? SG_MITER_TO_SG : SG_MITER_FROM_SG));
2480
2481 while (sg_miter_next(&miter) && resid > 0) {
2482 size_t len = min(miter.length, resid);
14faa944 2483 void *start = dif_store(sector);
be4e11be 2484 size_t rest = 0;
14faa944
AM
2485
2486 if (dif_store_end < start + len)
2487 rest = start + len - dif_store_end;
c6a44287 2488
be4e11be 2489 paddr = miter.addr;
14faa944 2490
65f72f2a
AM
2491 if (read)
2492 memcpy(paddr, start, len - rest);
2493 else
2494 memcpy(start, paddr, len - rest);
2495
2496 if (rest) {
2497 if (read)
2498 memcpy(paddr + len - rest, dif_storep, rest);
2499 else
2500 memcpy(dif_storep, paddr + len - rest, rest);
2501 }
c6a44287 2502
e18d8bea 2503 sector += len / sizeof(*dif_storep);
c6a44287 2504 resid -= len;
c6a44287 2505 }
be4e11be 2506 sg_miter_stop(&miter);
bb8c063c
AM
2507}
2508
2509static int prot_verify_read(struct scsi_cmnd *SCpnt, sector_t start_sec,
2510 unsigned int sectors, u32 ei_lba)
2511{
2512 unsigned int i;
6ebf105c 2513 struct t10_pi_tuple *sdt;
bb8c063c
AM
2514 sector_t sector;
2515
c45eabec 2516 for (i = 0; i < sectors; i++, ei_lba++) {
bb8c063c
AM
2517 int ret;
2518
2519 sector = start_sec + i;
2520 sdt = dif_store(sector);
2521
51d648af 2522 if (sdt->app_tag == cpu_to_be16(0xffff))
bb8c063c
AM
2523 continue;
2524
2525 ret = dif_verify(sdt, fake_store(sector), sector, ei_lba);
2526 if (ret) {
2527 dif_errors++;
2528 return ret;
2529 }
bb8c063c 2530 }
c6a44287 2531
65f72f2a 2532 dif_copy_prot(SCpnt, start_sec, sectors, true);
c6a44287
MP
2533 dix_reads++;
2534
2535 return 0;
2536}
2537
fd32119b 2538static int resp_read_dt0(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
19789100 2539{
c2248fc9 2540 u8 *cmd = scp->cmnd;
c4837394 2541 struct sdebug_queued_cmd *sqcp;
c2248fc9
DG
2542 u64 lba;
2543 u32 num;
2544 u32 ei_lba;
19789100
FT
2545 unsigned long iflags;
2546 int ret;
c2248fc9 2547 bool check_prot;
19789100 2548
c2248fc9
DG
2549 switch (cmd[0]) {
2550 case READ_16:
2551 ei_lba = 0;
2552 lba = get_unaligned_be64(cmd + 2);
2553 num = get_unaligned_be32(cmd + 10);
2554 check_prot = true;
2555 break;
2556 case READ_10:
2557 ei_lba = 0;
2558 lba = get_unaligned_be32(cmd + 2);
2559 num = get_unaligned_be16(cmd + 7);
2560 check_prot = true;
2561 break;
2562 case READ_6:
2563 ei_lba = 0;
2564 lba = (u32)cmd[3] | (u32)cmd[2] << 8 |
2565 (u32)(cmd[1] & 0x1f) << 16;
2566 num = (0 == cmd[4]) ? 256 : cmd[4];
2567 check_prot = true;
2568 break;
2569 case READ_12:
2570 ei_lba = 0;
2571 lba = get_unaligned_be32(cmd + 2);
2572 num = get_unaligned_be32(cmd + 6);
2573 check_prot = true;
2574 break;
2575 case XDWRITEREAD_10:
2576 ei_lba = 0;
2577 lba = get_unaligned_be32(cmd + 2);
2578 num = get_unaligned_be16(cmd + 7);
2579 check_prot = false;
2580 break;
2581 default: /* assume READ(32) */
2582 lba = get_unaligned_be64(cmd + 12);
2583 ei_lba = get_unaligned_be32(cmd + 20);
2584 num = get_unaligned_be32(cmd + 28);
2585 check_prot = false;
2586 break;
2587 }
f46eb0e9 2588 if (unlikely(have_dif_prot && check_prot)) {
8475c811 2589 if (sdebug_dif == T10_PI_TYPE2_PROTECTION &&
c2248fc9
DG
2590 (cmd[1] & 0xe0)) {
2591 mk_sense_invalid_opcode(scp);
2592 return check_condition_result;
2593 }
8475c811
CH
2594 if ((sdebug_dif == T10_PI_TYPE1_PROTECTION ||
2595 sdebug_dif == T10_PI_TYPE3_PROTECTION) &&
c2248fc9
DG
2596 (cmd[1] & 0xe0) == 0)
2597 sdev_printk(KERN_ERR, scp->device, "Unprotected RD "
2598 "to DIF device\n");
2599 }
f46eb0e9 2600 if (unlikely(sdebug_any_injecting_opt)) {
c4837394 2601 sqcp = (struct sdebug_queued_cmd *)scp->host_scribble;
c2248fc9 2602
c4837394
DG
2603 if (sqcp) {
2604 if (sqcp->inj_short)
2605 num /= 2;
2606 }
2607 } else
2608 sqcp = NULL;
c2248fc9
DG
2609
2610 /* inline check_device_access_params() */
f46eb0e9 2611 if (unlikely(lba + num > sdebug_capacity)) {
c2248fc9
DG
2612 mk_sense_buffer(scp, ILLEGAL_REQUEST, LBA_OUT_OF_RANGE, 0);
2613 return check_condition_result;
2614 }
2615 /* transfer length excessive (tie in to block limits VPD page) */
f46eb0e9 2616 if (unlikely(num > sdebug_store_sectors)) {
c2248fc9
DG
2617 /* needs work to find which cdb byte 'num' comes from */
2618 mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_FIELD_IN_CDB, 0);
2619 return check_condition_result;
2620 }
19789100 2621
f46eb0e9
DG
2622 if (unlikely((SDEBUG_OPT_MEDIUM_ERR & sdebug_opts) &&
2623 (lba <= (OPT_MEDIUM_ERR_ADDR + OPT_MEDIUM_ERR_NUM - 1)) &&
2624 ((lba + num) > OPT_MEDIUM_ERR_ADDR))) {
c65b1445 2625 /* claim unrecoverable read error */
c2248fc9 2626 mk_sense_buffer(scp, MEDIUM_ERROR, UNRECOVERED_READ_ERR, 0);
c65b1445 2627 /* set info field and valid bit for fixed descriptor */
c2248fc9
DG
2628 if (0x70 == (scp->sense_buffer[0] & 0x7f)) {
2629 scp->sense_buffer[0] |= 0x80; /* Valid bit */
32f7ef73
DG
2630 ret = (lba < OPT_MEDIUM_ERR_ADDR)
2631 ? OPT_MEDIUM_ERR_ADDR : (int)lba;
c2248fc9 2632 put_unaligned_be32(ret, scp->sense_buffer + 3);
c65b1445 2633 }
c2248fc9 2634 scsi_set_resid(scp, scsi_bufflen(scp));
1da177e4
LT
2635 return check_condition_result;
2636 }
c6a44287 2637
6c78cc06
AM
2638 read_lock_irqsave(&atomic_rw, iflags);
2639
c6a44287 2640 /* DIX + T10 DIF */
f46eb0e9 2641 if (unlikely(sdebug_dix && scsi_prot_sg_count(scp))) {
c2248fc9 2642 int prot_ret = prot_verify_read(scp, lba, num, ei_lba);
c6a44287
MP
2643
2644 if (prot_ret) {
6c78cc06 2645 read_unlock_irqrestore(&atomic_rw, iflags);
c2248fc9 2646 mk_sense_buffer(scp, ABORTED_COMMAND, 0x10, prot_ret);
c6a44287
MP
2647 return illegal_condition_result;
2648 }
2649 }
2650
c2248fc9 2651 ret = do_device_access(scp, lba, num, false);
1da177e4 2652 read_unlock_irqrestore(&atomic_rw, iflags);
f46eb0e9 2653 if (unlikely(ret == -1))
a4517511
AM
2654 return DID_ERROR << 16;
2655
c2248fc9 2656 scsi_in(scp)->resid = scsi_bufflen(scp) - ret;
a4517511 2657
c4837394
DG
2658 if (unlikely(sqcp)) {
2659 if (sqcp->inj_recovered) {
c2248fc9
DG
2660 mk_sense_buffer(scp, RECOVERED_ERROR,
2661 THRESHOLD_EXCEEDED, 0);
2662 return check_condition_result;
c4837394 2663 } else if (sqcp->inj_transport) {
c2248fc9
DG
2664 mk_sense_buffer(scp, ABORTED_COMMAND,
2665 TRANSPORT_PROBLEM, ACK_NAK_TO);
2666 return check_condition_result;
c4837394 2667 } else if (sqcp->inj_dif) {
c2248fc9
DG
2668 /* Logical block guard check failed */
2669 mk_sense_buffer(scp, ABORTED_COMMAND, 0x10, 1);
2670 return illegal_condition_result;
c4837394 2671 } else if (sqcp->inj_dix) {
c2248fc9
DG
2672 mk_sense_buffer(scp, ILLEGAL_REQUEST, 0x10, 1);
2673 return illegal_condition_result;
2674 }
2675 }
a4517511 2676 return 0;
1da177e4
LT
2677}
2678
58a8635d 2679static void dump_sector(unsigned char *buf, int len)
c6a44287 2680{
cbf67842 2681 int i, j, n;
c6a44287 2682
cbf67842 2683 pr_err(">>> Sector Dump <<<\n");
c6a44287 2684 for (i = 0 ; i < len ; i += 16) {
cbf67842 2685 char b[128];
c6a44287 2686
cbf67842 2687 for (j = 0, n = 0; j < 16; j++) {
c6a44287 2688 unsigned char c = buf[i+j];
cbf67842 2689
c6a44287 2690 if (c >= 0x20 && c < 0x7e)
cbf67842
DG
2691 n += scnprintf(b + n, sizeof(b) - n,
2692 " %c ", buf[i+j]);
c6a44287 2693 else
cbf67842
DG
2694 n += scnprintf(b + n, sizeof(b) - n,
2695 "%02x ", buf[i+j]);
c6a44287 2696 }
cbf67842 2697 pr_err("%04d: %s\n", i, b);
c6a44287
MP
2698 }
2699}
2700
2701static int prot_verify_write(struct scsi_cmnd *SCpnt, sector_t start_sec,
395cef03 2702 unsigned int sectors, u32 ei_lba)
c6a44287 2703{
be4e11be 2704 int ret;
6ebf105c 2705 struct t10_pi_tuple *sdt;
be4e11be 2706 void *daddr;
65f72f2a 2707 sector_t sector = start_sec;
c6a44287 2708 int ppage_offset;
be4e11be
AM
2709 int dpage_offset;
2710 struct sg_mapping_iter diter;
2711 struct sg_mapping_iter piter;
c6a44287 2712
c6a44287
MP
2713 BUG_ON(scsi_sg_count(SCpnt) == 0);
2714 BUG_ON(scsi_prot_sg_count(SCpnt) == 0);
2715
be4e11be
AM
2716 sg_miter_start(&piter, scsi_prot_sglist(SCpnt),
2717 scsi_prot_sg_count(SCpnt),
2718 SG_MITER_ATOMIC | SG_MITER_FROM_SG);
2719 sg_miter_start(&diter, scsi_sglist(SCpnt), scsi_sg_count(SCpnt),
2720 SG_MITER_ATOMIC | SG_MITER_FROM_SG);
2721
2722 /* For each protection page */
2723 while (sg_miter_next(&piter)) {
2724 dpage_offset = 0;
2725 if (WARN_ON(!sg_miter_next(&diter))) {
2726 ret = 0x01;
2727 goto out;
2728 }
c6a44287 2729
be4e11be 2730 for (ppage_offset = 0; ppage_offset < piter.length;
6ebf105c 2731 ppage_offset += sizeof(struct t10_pi_tuple)) {
c6a44287 2732 /* If we're at the end of the current
be4e11be 2733 * data page advance to the next one
c6a44287 2734 */
be4e11be
AM
2735 if (dpage_offset >= diter.length) {
2736 if (WARN_ON(!sg_miter_next(&diter))) {
2737 ret = 0x01;
2738 goto out;
2739 }
2740 dpage_offset = 0;
c6a44287
MP
2741 }
2742
be4e11be
AM
2743 sdt = piter.addr + ppage_offset;
2744 daddr = diter.addr + dpage_offset;
c6a44287 2745
be4e11be 2746 ret = dif_verify(sdt, daddr, sector, ei_lba);
beb40ea4 2747 if (ret) {
773642d9 2748 dump_sector(daddr, sdebug_sector_size);
395cef03
MP
2749 goto out;
2750 }
2751
c6a44287 2752 sector++;
395cef03 2753 ei_lba++;
773642d9 2754 dpage_offset += sdebug_sector_size;
c6a44287 2755 }
be4e11be
AM
2756 diter.consumed = dpage_offset;
2757 sg_miter_stop(&diter);
c6a44287 2758 }
be4e11be 2759 sg_miter_stop(&piter);
c6a44287 2760
65f72f2a 2761 dif_copy_prot(SCpnt, start_sec, sectors, false);
c6a44287
MP
2762 dix_writes++;
2763
2764 return 0;
2765
2766out:
2767 dif_errors++;
be4e11be
AM
2768 sg_miter_stop(&diter);
2769 sg_miter_stop(&piter);
c6a44287
MP
2770 return ret;
2771}
2772
b90ebc3d
AM
2773static unsigned long lba_to_map_index(sector_t lba)
2774{
773642d9
DG
2775 if (sdebug_unmap_alignment)
2776 lba += sdebug_unmap_granularity - sdebug_unmap_alignment;
2777 sector_div(lba, sdebug_unmap_granularity);
b90ebc3d
AM
2778 return lba;
2779}
2780
2781static sector_t map_index_to_lba(unsigned long index)
44d92694 2782{
773642d9 2783 sector_t lba = index * sdebug_unmap_granularity;
a027b5b9 2784
773642d9
DG
2785 if (sdebug_unmap_alignment)
2786 lba -= sdebug_unmap_granularity - sdebug_unmap_alignment;
a027b5b9 2787 return lba;
b90ebc3d 2788}
44d92694 2789
b90ebc3d
AM
2790static unsigned int map_state(sector_t lba, unsigned int *num)
2791{
2792 sector_t end;
2793 unsigned int mapped;
2794 unsigned long index;
2795 unsigned long next;
44d92694 2796
b90ebc3d
AM
2797 index = lba_to_map_index(lba);
2798 mapped = test_bit(index, map_storep);
44d92694
MP
2799
2800 if (mapped)
b90ebc3d 2801 next = find_next_zero_bit(map_storep, map_size, index);
44d92694 2802 else
b90ebc3d 2803 next = find_next_bit(map_storep, map_size, index);
44d92694 2804
b90ebc3d 2805 end = min_t(sector_t, sdebug_store_sectors, map_index_to_lba(next));
44d92694 2806 *num = end - lba;
44d92694
MP
2807 return mapped;
2808}
2809
2810static void map_region(sector_t lba, unsigned int len)
2811{
44d92694
MP
2812 sector_t end = lba + len;
2813
44d92694 2814 while (lba < end) {
b90ebc3d 2815 unsigned long index = lba_to_map_index(lba);
44d92694 2816
b90ebc3d
AM
2817 if (index < map_size)
2818 set_bit(index, map_storep);
44d92694 2819
b90ebc3d 2820 lba = map_index_to_lba(index + 1);
44d92694
MP
2821 }
2822}
2823
2824static void unmap_region(sector_t lba, unsigned int len)
2825{
44d92694
MP
2826 sector_t end = lba + len;
2827
44d92694 2828 while (lba < end) {
b90ebc3d 2829 unsigned long index = lba_to_map_index(lba);
44d92694 2830
b90ebc3d 2831 if (lba == map_index_to_lba(index) &&
773642d9 2832 lba + sdebug_unmap_granularity <= end &&
b90ebc3d
AM
2833 index < map_size) {
2834 clear_bit(index, map_storep);
760f3b03 2835 if (sdebug_lbprz) { /* for LBPRZ=2 return 0xff_s */
be1dd78d 2836 memset(fake_storep +
760f3b03
DG
2837 lba * sdebug_sector_size,
2838 (sdebug_lbprz & 1) ? 0 : 0xff,
773642d9
DG
2839 sdebug_sector_size *
2840 sdebug_unmap_granularity);
b90ebc3d 2841 }
e9926b43
AM
2842 if (dif_storep) {
2843 memset(dif_storep + lba, 0xff,
2844 sizeof(*dif_storep) *
773642d9 2845 sdebug_unmap_granularity);
e9926b43 2846 }
be1dd78d 2847 }
b90ebc3d 2848 lba = map_index_to_lba(index + 1);
44d92694
MP
2849 }
2850}
2851
fd32119b 2852static int resp_write_dt0(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
1da177e4 2853{
c2248fc9
DG
2854 u8 *cmd = scp->cmnd;
2855 u64 lba;
2856 u32 num;
2857 u32 ei_lba;
1da177e4 2858 unsigned long iflags;
19789100 2859 int ret;
c2248fc9 2860 bool check_prot;
1da177e4 2861
c2248fc9
DG
2862 switch (cmd[0]) {
2863 case WRITE_16:
2864 ei_lba = 0;
2865 lba = get_unaligned_be64(cmd + 2);
2866 num = get_unaligned_be32(cmd + 10);
2867 check_prot = true;
2868 break;
2869 case WRITE_10:
2870 ei_lba = 0;
2871 lba = get_unaligned_be32(cmd + 2);
2872 num = get_unaligned_be16(cmd + 7);
2873 check_prot = true;
2874 break;
2875 case WRITE_6:
2876 ei_lba = 0;
2877 lba = (u32)cmd[3] | (u32)cmd[2] << 8 |
2878 (u32)(cmd[1] & 0x1f) << 16;
2879 num = (0 == cmd[4]) ? 256 : cmd[4];
2880 check_prot = true;
2881 break;
2882 case WRITE_12:
2883 ei_lba = 0;
2884 lba = get_unaligned_be32(cmd + 2);
2885 num = get_unaligned_be32(cmd + 6);
2886 check_prot = true;
2887 break;
2888 case 0x53: /* XDWRITEREAD(10) */
2889 ei_lba = 0;
2890 lba = get_unaligned_be32(cmd + 2);
2891 num = get_unaligned_be16(cmd + 7);
2892 check_prot = false;
2893 break;
2894 default: /* assume WRITE(32) */
2895 lba = get_unaligned_be64(cmd + 12);
2896 ei_lba = get_unaligned_be32(cmd + 20);
2897 num = get_unaligned_be32(cmd + 28);
2898 check_prot = false;
2899 break;
2900 }
f46eb0e9 2901 if (unlikely(have_dif_prot && check_prot)) {
8475c811 2902 if (sdebug_dif == T10_PI_TYPE2_PROTECTION &&
c2248fc9
DG
2903 (cmd[1] & 0xe0)) {
2904 mk_sense_invalid_opcode(scp);
2905 return check_condition_result;
2906 }
8475c811
CH
2907 if ((sdebug_dif == T10_PI_TYPE1_PROTECTION ||
2908 sdebug_dif == T10_PI_TYPE3_PROTECTION) &&
c2248fc9
DG
2909 (cmd[1] & 0xe0) == 0)
2910 sdev_printk(KERN_ERR, scp->device, "Unprotected WR "
2911 "to DIF device\n");
2912 }
2913
2914 /* inline check_device_access_params() */
f46eb0e9 2915 if (unlikely(lba + num > sdebug_capacity)) {
c2248fc9
DG
2916 mk_sense_buffer(scp, ILLEGAL_REQUEST, LBA_OUT_OF_RANGE, 0);
2917 return check_condition_result;
2918 }
2919 /* transfer length excessive (tie in to block limits VPD page) */
f46eb0e9 2920 if (unlikely(num > sdebug_store_sectors)) {
c2248fc9
DG
2921 /* needs work to find which cdb byte 'num' comes from */
2922 mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_FIELD_IN_CDB, 0);
2923 return check_condition_result;
2924 }
1da177e4 2925
6c78cc06
AM
2926 write_lock_irqsave(&atomic_rw, iflags);
2927
c6a44287 2928 /* DIX + T10 DIF */
f46eb0e9 2929 if (unlikely(sdebug_dix && scsi_prot_sg_count(scp))) {
c2248fc9 2930 int prot_ret = prot_verify_write(scp, lba, num, ei_lba);
c6a44287
MP
2931
2932 if (prot_ret) {
6c78cc06 2933 write_unlock_irqrestore(&atomic_rw, iflags);
c2248fc9 2934 mk_sense_buffer(scp, ILLEGAL_REQUEST, 0x10, prot_ret);
c6a44287
MP
2935 return illegal_condition_result;
2936 }
2937 }
2938
c2248fc9 2939 ret = do_device_access(scp, lba, num, true);
f46eb0e9 2940 if (unlikely(scsi_debug_lbp()))
44d92694 2941 map_region(lba, num);
1da177e4 2942 write_unlock_irqrestore(&atomic_rw, iflags);
f46eb0e9 2943 if (unlikely(-1 == ret))
773642d9 2944 return DID_ERROR << 16;
c4837394
DG
2945 else if (unlikely(sdebug_verbose &&
2946 (ret < (num * sdebug_sector_size))))
c2248fc9 2947 sdev_printk(KERN_INFO, scp->device,
cbf67842 2948 "%s: write: cdb indicated=%u, IO sent=%d bytes\n",
773642d9 2949 my_name, num * sdebug_sector_size, ret);
44d92694 2950
f46eb0e9 2951 if (unlikely(sdebug_any_injecting_opt)) {
c4837394
DG
2952 struct sdebug_queued_cmd *sqcp =
2953 (struct sdebug_queued_cmd *)scp->host_scribble;
c2248fc9 2954
c4837394
DG
2955 if (sqcp) {
2956 if (sqcp->inj_recovered) {
2957 mk_sense_buffer(scp, RECOVERED_ERROR,
2958 THRESHOLD_EXCEEDED, 0);
2959 return check_condition_result;
2960 } else if (sqcp->inj_dif) {
2961 /* Logical block guard check failed */
2962 mk_sense_buffer(scp, ABORTED_COMMAND, 0x10, 1);
2963 return illegal_condition_result;
2964 } else if (sqcp->inj_dix) {
2965 mk_sense_buffer(scp, ILLEGAL_REQUEST, 0x10, 1);
2966 return illegal_condition_result;
2967 }
c2248fc9
DG
2968 }
2969 }
44d92694
MP
2970 return 0;
2971}
2972
fd32119b
DG
2973static int resp_write_same(struct scsi_cmnd *scp, u64 lba, u32 num,
2974 u32 ei_lba, bool unmap, bool ndob)
44d92694
MP
2975{
2976 unsigned long iflags;
2977 unsigned long long i;
2978 int ret;
773642d9 2979 u64 lba_off;
44d92694 2980
c2248fc9 2981 ret = check_device_access_params(scp, lba, num);
44d92694
MP
2982 if (ret)
2983 return ret;
2984
2985 write_lock_irqsave(&atomic_rw, iflags);
2986
9ed8d3dc 2987 if (unmap && scsi_debug_lbp()) {
44d92694
MP
2988 unmap_region(lba, num);
2989 goto out;
2990 }
2991
773642d9 2992 lba_off = lba * sdebug_sector_size;
c2248fc9
DG
2993 /* if ndob then zero 1 logical block, else fetch 1 logical block */
2994 if (ndob) {
773642d9 2995 memset(fake_storep + lba_off, 0, sdebug_sector_size);
c2248fc9
DG
2996 ret = 0;
2997 } else
773642d9
DG
2998 ret = fetch_to_dev_buffer(scp, fake_storep + lba_off,
2999 sdebug_sector_size);
44d92694
MP
3000
3001 if (-1 == ret) {
3002 write_unlock_irqrestore(&atomic_rw, iflags);
773642d9 3003 return DID_ERROR << 16;
e33d7c56 3004 } else if (sdebug_verbose && !ndob && (ret < sdebug_sector_size))
c2248fc9 3005 sdev_printk(KERN_INFO, scp->device,
e33d7c56 3006 "%s: %s: lb size=%u, IO sent=%d bytes\n",
cbf67842 3007 my_name, "write same",
e33d7c56 3008 sdebug_sector_size, ret);
44d92694
MP
3009
3010 /* Copy first sector to remaining blocks */
3011 for (i = 1 ; i < num ; i++)
773642d9
DG
3012 memcpy(fake_storep + ((lba + i) * sdebug_sector_size),
3013 fake_storep + lba_off,
3014 sdebug_sector_size);
44d92694 3015
9ed8d3dc 3016 if (scsi_debug_lbp())
44d92694
MP
3017 map_region(lba, num);
3018out:
3019 write_unlock_irqrestore(&atomic_rw, iflags);
3020
1da177e4
LT
3021 return 0;
3022}
3023
fd32119b
DG
3024static int resp_write_same_10(struct scsi_cmnd *scp,
3025 struct sdebug_dev_info *devip)
c2248fc9
DG
3026{
3027 u8 *cmd = scp->cmnd;
3028 u32 lba;
3029 u16 num;
3030 u32 ei_lba = 0;
3031 bool unmap = false;
3032
3033 if (cmd[1] & 0x8) {
773642d9 3034 if (sdebug_lbpws10 == 0) {
c2248fc9
DG
3035 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, 3);
3036 return check_condition_result;
3037 } else
3038 unmap = true;
3039 }
3040 lba = get_unaligned_be32(cmd + 2);
3041 num = get_unaligned_be16(cmd + 7);
773642d9 3042 if (num > sdebug_write_same_length) {
c2248fc9
DG
3043 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 7, -1);
3044 return check_condition_result;
3045 }
3046 return resp_write_same(scp, lba, num, ei_lba, unmap, false);
3047}
3048
fd32119b
DG
3049static int resp_write_same_16(struct scsi_cmnd *scp,
3050 struct sdebug_dev_info *devip)
c2248fc9
DG
3051{
3052 u8 *cmd = scp->cmnd;
3053 u64 lba;
3054 u32 num;
3055 u32 ei_lba = 0;
3056 bool unmap = false;
3057 bool ndob = false;
3058
3059 if (cmd[1] & 0x8) { /* UNMAP */
773642d9 3060 if (sdebug_lbpws == 0) {
c2248fc9
DG
3061 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, 3);
3062 return check_condition_result;
3063 } else
3064 unmap = true;
3065 }
3066 if (cmd[1] & 0x1) /* NDOB (no data-out buffer, assumes zeroes) */
3067 ndob = true;
3068 lba = get_unaligned_be64(cmd + 2);
3069 num = get_unaligned_be32(cmd + 10);
773642d9 3070 if (num > sdebug_write_same_length) {
c2248fc9
DG
3071 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 10, -1);
3072 return check_condition_result;
3073 }
3074 return resp_write_same(scp, lba, num, ei_lba, unmap, ndob);
3075}
3076
acafd0b9
EM
3077/* Note the mode field is in the same position as the (lower) service action
3078 * field. For the Report supported operation codes command, SPC-4 suggests
3079 * each mode of this command should be reported separately; for future. */
fd32119b
DG
3080static int resp_write_buffer(struct scsi_cmnd *scp,
3081 struct sdebug_dev_info *devip)
acafd0b9
EM
3082{
3083 u8 *cmd = scp->cmnd;
3084 struct scsi_device *sdp = scp->device;
3085 struct sdebug_dev_info *dp;
3086 u8 mode;
3087
3088 mode = cmd[1] & 0x1f;
3089 switch (mode) {
3090 case 0x4: /* download microcode (MC) and activate (ACT) */
3091 /* set UAs on this device only */
3092 set_bit(SDEBUG_UA_BUS_RESET, devip->uas_bm);
3093 set_bit(SDEBUG_UA_MICROCODE_CHANGED, devip->uas_bm);
3094 break;
3095 case 0x5: /* download MC, save and ACT */
3096 set_bit(SDEBUG_UA_MICROCODE_CHANGED_WO_RESET, devip->uas_bm);
3097 break;
3098 case 0x6: /* download MC with offsets and ACT */
3099 /* set UAs on most devices (LUs) in this target */
3100 list_for_each_entry(dp,
3101 &devip->sdbg_host->dev_info_list,
3102 dev_list)
3103 if (dp->target == sdp->id) {
3104 set_bit(SDEBUG_UA_BUS_RESET, dp->uas_bm);
3105 if (devip != dp)
3106 set_bit(SDEBUG_UA_MICROCODE_CHANGED,
3107 dp->uas_bm);
3108 }
3109 break;
3110 case 0x7: /* download MC with offsets, save, and ACT */
3111 /* set UA on all devices (LUs) in this target */
3112 list_for_each_entry(dp,
3113 &devip->sdbg_host->dev_info_list,
3114 dev_list)
3115 if (dp->target == sdp->id)
3116 set_bit(SDEBUG_UA_MICROCODE_CHANGED_WO_RESET,
3117 dp->uas_bm);
3118 break;
3119 default:
3120 /* do nothing for this command for other mode values */
3121 break;
3122 }
3123 return 0;
3124}
3125
fd32119b
DG
3126static int resp_comp_write(struct scsi_cmnd *scp,
3127 struct sdebug_dev_info *devip)
38d5c833
DG
3128{
3129 u8 *cmd = scp->cmnd;
3130 u8 *arr;
3131 u8 *fake_storep_hold;
3132 u64 lba;
3133 u32 dnum;
773642d9 3134 u32 lb_size = sdebug_sector_size;
38d5c833
DG
3135 u8 num;
3136 unsigned long iflags;
3137 int ret;
d467d31f 3138 int retval = 0;
38d5c833 3139
d467d31f 3140 lba = get_unaligned_be64(cmd + 2);
38d5c833
DG
3141 num = cmd[13]; /* 1 to a maximum of 255 logical blocks */
3142 if (0 == num)
3143 return 0; /* degenerate case, not an error */
8475c811 3144 if (sdebug_dif == T10_PI_TYPE2_PROTECTION &&
38d5c833
DG
3145 (cmd[1] & 0xe0)) {
3146 mk_sense_invalid_opcode(scp);
3147 return check_condition_result;
3148 }
8475c811
CH
3149 if ((sdebug_dif == T10_PI_TYPE1_PROTECTION ||
3150 sdebug_dif == T10_PI_TYPE3_PROTECTION) &&
38d5c833
DG
3151 (cmd[1] & 0xe0) == 0)
3152 sdev_printk(KERN_ERR, scp->device, "Unprotected WR "
3153 "to DIF device\n");
3154
3155 /* inline check_device_access_params() */
3156 if (lba + num > sdebug_capacity) {
3157 mk_sense_buffer(scp, ILLEGAL_REQUEST, LBA_OUT_OF_RANGE, 0);
3158 return check_condition_result;
3159 }
3160 /* transfer length excessive (tie in to block limits VPD page) */
3161 if (num > sdebug_store_sectors) {
3162 /* needs work to find which cdb byte 'num' comes from */
3163 mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_FIELD_IN_CDB, 0);
3164 return check_condition_result;
3165 }
d467d31f
DG
3166 dnum = 2 * num;
3167 arr = kzalloc(dnum * lb_size, GFP_ATOMIC);
3168 if (NULL == arr) {
3169 mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
3170 INSUFF_RES_ASCQ);
3171 return check_condition_result;
3172 }
38d5c833
DG
3173
3174 write_lock_irqsave(&atomic_rw, iflags);
3175
3176 /* trick do_device_access() to fetch both compare and write buffers
3177 * from data-in into arr. Safe (atomic) since write_lock held. */
3178 fake_storep_hold = fake_storep;
3179 fake_storep = arr;
3180 ret = do_device_access(scp, 0, dnum, true);
3181 fake_storep = fake_storep_hold;
3182 if (ret == -1) {
d467d31f
DG
3183 retval = DID_ERROR << 16;
3184 goto cleanup;
773642d9 3185 } else if (sdebug_verbose && (ret < (dnum * lb_size)))
38d5c833
DG
3186 sdev_printk(KERN_INFO, scp->device, "%s: compare_write: cdb "
3187 "indicated=%u, IO sent=%d bytes\n", my_name,
3188 dnum * lb_size, ret);
3189 if (!comp_write_worker(lba, num, arr)) {
38d5c833 3190 mk_sense_buffer(scp, MISCOMPARE, MISCOMPARE_VERIFY_ASC, 0);
d467d31f
DG
3191 retval = check_condition_result;
3192 goto cleanup;
38d5c833
DG
3193 }
3194 if (scsi_debug_lbp())
3195 map_region(lba, num);
d467d31f 3196cleanup:
38d5c833 3197 write_unlock_irqrestore(&atomic_rw, iflags);
d467d31f
DG
3198 kfree(arr);
3199 return retval;
38d5c833
DG
3200}
3201
44d92694
MP
3202struct unmap_block_desc {
3203 __be64 lba;
3204 __be32 blocks;
3205 __be32 __reserved;
3206};
3207
fd32119b 3208static int resp_unmap(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
44d92694
MP
3209{
3210 unsigned char *buf;
3211 struct unmap_block_desc *desc;
3212 unsigned int i, payload_len, descriptors;
3213 int ret;
6c78cc06 3214 unsigned long iflags;
44d92694 3215
44d92694 3216
c2248fc9
DG
3217 if (!scsi_debug_lbp())
3218 return 0; /* fib and say its done */
3219 payload_len = get_unaligned_be16(scp->cmnd + 7);
3220 BUG_ON(scsi_bufflen(scp) != payload_len);
44d92694
MP
3221
3222 descriptors = (payload_len - 8) / 16;
773642d9 3223 if (descriptors > sdebug_unmap_max_desc) {
c2248fc9
DG
3224 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 7, -1);
3225 return check_condition_result;
3226 }
44d92694 3227
b333a819 3228 buf = kzalloc(scsi_bufflen(scp), GFP_ATOMIC);
c2248fc9
DG
3229 if (!buf) {
3230 mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
3231 INSUFF_RES_ASCQ);
44d92694 3232 return check_condition_result;
c2248fc9 3233 }
44d92694 3234
c2248fc9 3235 scsi_sg_copy_to_buffer(scp, buf, scsi_bufflen(scp));
44d92694
MP
3236
3237 BUG_ON(get_unaligned_be16(&buf[0]) != payload_len - 2);
3238 BUG_ON(get_unaligned_be16(&buf[2]) != descriptors * 16);
3239
3240 desc = (void *)&buf[8];
3241
6c78cc06
AM
3242 write_lock_irqsave(&atomic_rw, iflags);
3243
44d92694
MP
3244 for (i = 0 ; i < descriptors ; i++) {
3245 unsigned long long lba = get_unaligned_be64(&desc[i].lba);
3246 unsigned int num = get_unaligned_be32(&desc[i].blocks);
3247
c2248fc9 3248 ret = check_device_access_params(scp, lba, num);
44d92694
MP
3249 if (ret)
3250 goto out;
3251
3252 unmap_region(lba, num);
3253 }
3254
3255 ret = 0;
3256
3257out:
6c78cc06 3258 write_unlock_irqrestore(&atomic_rw, iflags);
44d92694
MP
3259 kfree(buf);
3260
3261 return ret;
3262}
3263
3264#define SDEBUG_GET_LBA_STATUS_LEN 32
3265
fd32119b
DG
3266static int resp_get_lba_status(struct scsi_cmnd *scp,
3267 struct sdebug_dev_info *devip)
44d92694 3268{
c2248fc9
DG
3269 u8 *cmd = scp->cmnd;
3270 u64 lba;
3271 u32 alloc_len, mapped, num;
3272 u8 arr[SDEBUG_GET_LBA_STATUS_LEN];
44d92694
MP
3273 int ret;
3274
c2248fc9
DG
3275 lba = get_unaligned_be64(cmd + 2);
3276 alloc_len = get_unaligned_be32(cmd + 10);
44d92694
MP
3277
3278 if (alloc_len < 24)
3279 return 0;
3280
c2248fc9 3281 ret = check_device_access_params(scp, lba, 1);
44d92694
MP
3282 if (ret)
3283 return ret;
3284
c2248fc9
DG
3285 if (scsi_debug_lbp())
3286 mapped = map_state(lba, &num);
3287 else {
3288 mapped = 1;
3289 /* following just in case virtual_gb changed */
3290 sdebug_capacity = get_sdebug_capacity();
3291 if (sdebug_capacity - lba <= 0xffffffff)
3292 num = sdebug_capacity - lba;
3293 else
3294 num = 0xffffffff;
3295 }
44d92694
MP
3296
3297 memset(arr, 0, SDEBUG_GET_LBA_STATUS_LEN);
c2248fc9
DG
3298 put_unaligned_be32(20, arr); /* Parameter Data Length */
3299 put_unaligned_be64(lba, arr + 8); /* LBA */
3300 put_unaligned_be32(num, arr + 16); /* Number of blocks */
3301 arr[20] = !mapped; /* prov_stat=0: mapped; 1: dealloc */
44d92694 3302
c2248fc9 3303 return fill_from_dev_buffer(scp, arr, SDEBUG_GET_LBA_STATUS_LEN);
44d92694
MP
3304}
3305
fb0cc8d1
DG
3306#define RL_BUCKET_ELEMS 8
3307
8d039e22
DG
3308/* Even though each pseudo target has a REPORT LUNS "well known logical unit"
3309 * (W-LUN), the normal Linux scanning logic does not associate it with a
3310 * device (e.g. /dev/sg7). The following magic will make that association:
3311 * "cd /sys/class/scsi_host/host<n> ; echo '- - 49409' > scan"
3312 * where <n> is a host number. If there are multiple targets in a host then
3313 * the above will associate a W-LUN to each target. To only get a W-LUN
3314 * for target 2, then use "echo '- 2 49409' > scan" .
3315 */
3316static int resp_report_luns(struct scsi_cmnd *scp,
3317 struct sdebug_dev_info *devip)
1da177e4 3318{
8d039e22 3319 unsigned char *cmd = scp->cmnd;
1da177e4 3320 unsigned int alloc_len;
8d039e22 3321 unsigned char select_report;
22017ed2 3322 u64 lun;
8d039e22 3323 struct scsi_lun *lun_p;
fb0cc8d1 3324 u8 arr[RL_BUCKET_ELEMS * sizeof(struct scsi_lun)];
8d039e22
DG
3325 unsigned int lun_cnt; /* normal LUN count (max: 256) */
3326 unsigned int wlun_cnt; /* report luns W-LUN count */
3327 unsigned int tlun_cnt; /* total LUN count */
3328 unsigned int rlen; /* response length (in bytes) */
fb0cc8d1
DG
3329 int k, j, n, res;
3330 unsigned int off_rsp = 0;
3331 const int sz_lun = sizeof(struct scsi_lun);
1da177e4 3332
19c8ead7 3333 clear_luns_changed_on_target(devip);
8d039e22
DG
3334
3335 select_report = cmd[2];
3336 alloc_len = get_unaligned_be32(cmd + 6);
3337
3338 if (alloc_len < 4) {
3339 pr_err("alloc len too small %d\n", alloc_len);
3340 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 6, -1);
1da177e4
LT
3341 return check_condition_result;
3342 }
8d039e22
DG
3343
3344 switch (select_report) {
3345 case 0: /* all LUNs apart from W-LUNs */
3346 lun_cnt = sdebug_max_luns;
3347 wlun_cnt = 0;
3348 break;
3349 case 1: /* only W-LUNs */
c65b1445 3350 lun_cnt = 0;
8d039e22
DG
3351 wlun_cnt = 1;
3352 break;
3353 case 2: /* all LUNs */
3354 lun_cnt = sdebug_max_luns;
3355 wlun_cnt = 1;
3356 break;
3357 case 0x10: /* only administrative LUs */
3358 case 0x11: /* see SPC-5 */
3359 case 0x12: /* only subsiduary LUs owned by referenced LU */
3360 default:
3361 pr_debug("select report invalid %d\n", select_report);
3362 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, -1);
3363 return check_condition_result;
3364 }
3365
3366 if (sdebug_no_lun_0 && (lun_cnt > 0))
c65b1445 3367 --lun_cnt;
8d039e22
DG
3368
3369 tlun_cnt = lun_cnt + wlun_cnt;
fb0cc8d1
DG
3370 rlen = tlun_cnt * sz_lun; /* excluding 8 byte header */
3371 scsi_set_resid(scp, scsi_bufflen(scp));
8d039e22
DG
3372 pr_debug("select_report %d luns = %d wluns = %d no_lun0 %d\n",
3373 select_report, lun_cnt, wlun_cnt, sdebug_no_lun_0);
3374
fb0cc8d1 3375 /* loops rely on sizeof response header same as sizeof lun (both 8) */
8d039e22 3376 lun = sdebug_no_lun_0 ? 1 : 0;
fb0cc8d1
DG
3377 for (k = 0, j = 0, res = 0; true; ++k, j = 0) {
3378 memset(arr, 0, sizeof(arr));
3379 lun_p = (struct scsi_lun *)&arr[0];
3380 if (k == 0) {
3381 put_unaligned_be32(rlen, &arr[0]);
3382 ++lun_p;
3383 j = 1;
3384 }
3385 for ( ; j < RL_BUCKET_ELEMS; ++j, ++lun_p) {
3386 if ((k * RL_BUCKET_ELEMS) + j > lun_cnt)
3387 break;
3388 int_to_scsilun(lun++, lun_p);
3389 }
3390 if (j < RL_BUCKET_ELEMS)
3391 break;
3392 n = j * sz_lun;
3393 res = p_fill_from_dev_buffer(scp, arr, n, off_rsp);
3394 if (res)
3395 return res;
3396 off_rsp += n;
3397 }
3398 if (wlun_cnt) {
3399 int_to_scsilun(SCSI_W_LUN_REPORT_LUNS, lun_p);
3400 ++j;
3401 }
3402 if (j > 0)
3403 res = p_fill_from_dev_buffer(scp, arr, j * sz_lun, off_rsp);
8d039e22 3404 return res;
1da177e4
LT
3405}
3406
c639d14e
FT
3407static int resp_xdwriteread(struct scsi_cmnd *scp, unsigned long long lba,
3408 unsigned int num, struct sdebug_dev_info *devip)
3409{
be4e11be 3410 int j;
c639d14e
FT
3411 unsigned char *kaddr, *buf;
3412 unsigned int offset;
c639d14e 3413 struct scsi_data_buffer *sdb = scsi_in(scp);
be4e11be 3414 struct sg_mapping_iter miter;
c639d14e
FT
3415
3416 /* better not to use temporary buffer. */
b333a819 3417 buf = kzalloc(scsi_bufflen(scp), GFP_ATOMIC);
c5af0db9 3418 if (!buf) {
22017ed2
DG
3419 mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
3420 INSUFF_RES_ASCQ);
c5af0db9
AM
3421 return check_condition_result;
3422 }
c639d14e 3423
21a61829 3424 scsi_sg_copy_to_buffer(scp, buf, scsi_bufflen(scp));
c639d14e
FT
3425
3426 offset = 0;
be4e11be
AM
3427 sg_miter_start(&miter, sdb->table.sgl, sdb->table.nents,
3428 SG_MITER_ATOMIC | SG_MITER_TO_SG);
c639d14e 3429
be4e11be
AM
3430 while (sg_miter_next(&miter)) {
3431 kaddr = miter.addr;
3432 for (j = 0; j < miter.length; j++)
3433 *(kaddr + j) ^= *(buf + offset + j);
c639d14e 3434
be4e11be 3435 offset += miter.length;
c639d14e 3436 }
be4e11be 3437 sg_miter_stop(&miter);
c639d14e
FT
3438 kfree(buf);
3439
be4e11be 3440 return 0;
c639d14e
FT
3441}
3442
fd32119b
DG
3443static int resp_xdwriteread_10(struct scsi_cmnd *scp,
3444 struct sdebug_dev_info *devip)
c2248fc9
DG
3445{
3446 u8 *cmd = scp->cmnd;
3447 u64 lba;
3448 u32 num;
3449 int errsts;
3450
3451 if (!scsi_bidi_cmnd(scp)) {
3452 mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
3453 INSUFF_RES_ASCQ);
3454 return check_condition_result;
3455 }
3456 errsts = resp_read_dt0(scp, devip);
3457 if (errsts)
3458 return errsts;
3459 if (!(cmd[1] & 0x4)) { /* DISABLE_WRITE is not set */
3460 errsts = resp_write_dt0(scp, devip);
3461 if (errsts)
3462 return errsts;
3463 }
3464 lba = get_unaligned_be32(cmd + 2);
3465 num = get_unaligned_be16(cmd + 7);
3466 return resp_xdwriteread(scp, lba, num, devip);
3467}
3468
c4837394
DG
3469static struct sdebug_queue *get_queue(struct scsi_cmnd *cmnd)
3470{
3471 struct sdebug_queue *sqp = sdebug_q_arr;
3472
3473 if (sdebug_mq_active) {
3474 u32 tag = blk_mq_unique_tag(cmnd->request);
3475 u16 hwq = blk_mq_unique_tag_to_hwq(tag);
3476
3477 if (unlikely(hwq >= submit_queues)) {
3478 pr_warn("Unexpected hwq=%d, apply modulo\n", hwq);
3479 hwq %= submit_queues;
3480 }
3481 pr_debug("tag=%u, hwq=%d\n", tag, hwq);
3482 return sqp + hwq;
3483 } else
3484 return sqp;
3485}
3486
3487/* Queued (deferred) command completions converge here. */
fd32119b 3488static void sdebug_q_cmd_complete(struct sdebug_defer *sd_dp)
1da177e4 3489{
c4837394 3490 int qc_idx;
cbf67842 3491 int retiring = 0;
1da177e4 3492 unsigned long iflags;
c4837394 3493 struct sdebug_queue *sqp;
cbf67842
DG
3494 struct sdebug_queued_cmd *sqcp;
3495 struct scsi_cmnd *scp;
3496 struct sdebug_dev_info *devip;
1da177e4 3497
c4837394
DG
3498 qc_idx = sd_dp->qc_idx;
3499 sqp = sdebug_q_arr + sd_dp->sqa_idx;
3500 if (sdebug_statistics) {
3501 atomic_inc(&sdebug_completions);
3502 if (raw_smp_processor_id() != sd_dp->issuing_cpu)
3503 atomic_inc(&sdebug_miss_cpus);
3504 }
3505 if (unlikely((qc_idx < 0) || (qc_idx >= SDEBUG_CANQUEUE))) {
3506 pr_err("wild qc_idx=%d\n", qc_idx);
1da177e4
LT
3507 return;
3508 }
c4837394
DG
3509 spin_lock_irqsave(&sqp->qc_lock, iflags);
3510 sqcp = &sqp->qc_arr[qc_idx];
cbf67842 3511 scp = sqcp->a_cmnd;
b01f6f83 3512 if (unlikely(scp == NULL)) {
c4837394
DG
3513 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
3514 pr_err("scp is NULL, sqa_idx=%d, qc_idx=%d\n",
3515 sd_dp->sqa_idx, qc_idx);
cbf67842
DG
3516 return;
3517 }
3518 devip = (struct sdebug_dev_info *)scp->device->hostdata;
f46eb0e9 3519 if (likely(devip))
cbf67842
DG
3520 atomic_dec(&devip->num_in_q);
3521 else
c1287970 3522 pr_err("devip=NULL\n");
f46eb0e9 3523 if (unlikely(atomic_read(&retired_max_queue) > 0))
cbf67842
DG
3524 retiring = 1;
3525
3526 sqcp->a_cmnd = NULL;
c4837394
DG
3527 if (unlikely(!test_and_clear_bit(qc_idx, sqp->in_use_bm))) {
3528 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
c1287970 3529 pr_err("Unexpected completion\n");
1da177e4
LT
3530 return;
3531 }
cbf67842
DG
3532
3533 if (unlikely(retiring)) { /* user has reduced max_queue */
3534 int k, retval;
3535
3536 retval = atomic_read(&retired_max_queue);
c4837394
DG
3537 if (qc_idx >= retval) {
3538 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
c1287970 3539 pr_err("index %d too large\n", retval);
cbf67842
DG
3540 return;
3541 }
c4837394 3542 k = find_last_bit(sqp->in_use_bm, retval);
773642d9 3543 if ((k < sdebug_max_queue) || (k == retval))
cbf67842
DG
3544 atomic_set(&retired_max_queue, 0);
3545 else
3546 atomic_set(&retired_max_queue, k + 1);
1da177e4 3547 }
c4837394 3548 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
cbf67842 3549 scp->scsi_done(scp); /* callback to mid level */
1da177e4
LT
3550}
3551
cbf67842 3552/* When high resolution timer goes off this function is called. */
fd32119b 3553static enum hrtimer_restart sdebug_q_cmd_hrt_complete(struct hrtimer *timer)
cbf67842 3554{
a10bc12a
DG
3555 struct sdebug_defer *sd_dp = container_of(timer, struct sdebug_defer,
3556 hrt);
3557 sdebug_q_cmd_complete(sd_dp);
cbf67842
DG
3558 return HRTIMER_NORESTART;
3559}
1da177e4 3560
a10bc12a 3561/* When work queue schedules work, it calls this function. */
fd32119b 3562static void sdebug_q_cmd_wq_complete(struct work_struct *work)
a10bc12a
DG
3563{
3564 struct sdebug_defer *sd_dp = container_of(work, struct sdebug_defer,
3565 ew.work);
3566 sdebug_q_cmd_complete(sd_dp);
3567}
3568
09ba24c1 3569static bool got_shared_uuid;
bf476433 3570static uuid_t shared_uuid;
09ba24c1 3571
fd32119b
DG
3572static struct sdebug_dev_info *sdebug_device_create(
3573 struct sdebug_host_info *sdbg_host, gfp_t flags)
5cb2fc06
FT
3574{
3575 struct sdebug_dev_info *devip;
3576
3577 devip = kzalloc(sizeof(*devip), flags);
3578 if (devip) {
09ba24c1 3579 if (sdebug_uuid_ctl == 1)
bf476433 3580 uuid_gen(&devip->lu_name);
09ba24c1
DG
3581 else if (sdebug_uuid_ctl == 2) {
3582 if (got_shared_uuid)
3583 devip->lu_name = shared_uuid;
3584 else {
bf476433 3585 uuid_gen(&shared_uuid);
09ba24c1
DG
3586 got_shared_uuid = true;
3587 devip->lu_name = shared_uuid;
3588 }
3589 }
5cb2fc06
FT
3590 devip->sdbg_host = sdbg_host;
3591 list_add_tail(&devip->dev_list, &sdbg_host->dev_info_list);
3592 }
3593 return devip;
3594}
3595
f46eb0e9 3596static struct sdebug_dev_info *find_build_dev_info(struct scsi_device *sdev)
1da177e4 3597{
f46eb0e9
DG
3598 struct sdebug_host_info *sdbg_host;
3599 struct sdebug_dev_info *open_devip = NULL;
3600 struct sdebug_dev_info *devip;
1da177e4 3601
d1e4c9c5
FT
3602 sdbg_host = *(struct sdebug_host_info **)shost_priv(sdev->host);
3603 if (!sdbg_host) {
c1287970 3604 pr_err("Host info NULL\n");
1da177e4
LT
3605 return NULL;
3606 }
3607 list_for_each_entry(devip, &sdbg_host->dev_info_list, dev_list) {
3608 if ((devip->used) && (devip->channel == sdev->channel) &&
3609 (devip->target == sdev->id) &&
3610 (devip->lun == sdev->lun))
3611 return devip;
3612 else {
3613 if ((!devip->used) && (!open_devip))
3614 open_devip = devip;
3615 }
3616 }
5cb2fc06
FT
3617 if (!open_devip) { /* try and make a new one */
3618 open_devip = sdebug_device_create(sdbg_host, GFP_ATOMIC);
3619 if (!open_devip) {
c1287970 3620 pr_err("out of memory at line %d\n", __LINE__);
1da177e4
LT
3621 return NULL;
3622 }
1da177e4 3623 }
a75869d1
FT
3624
3625 open_devip->channel = sdev->channel;
3626 open_devip->target = sdev->id;
3627 open_devip->lun = sdev->lun;
3628 open_devip->sdbg_host = sdbg_host;
cbf67842
DG
3629 atomic_set(&open_devip->num_in_q, 0);
3630 set_bit(SDEBUG_UA_POR, open_devip->uas_bm);
c2248fc9 3631 open_devip->used = true;
a75869d1 3632 return open_devip;
1da177e4
LT
3633}
3634
8dea0d02 3635static int scsi_debug_slave_alloc(struct scsi_device *sdp)
1da177e4 3636{
773642d9 3637 if (sdebug_verbose)
c1287970 3638 pr_info("slave_alloc <%u %u %u %llu>\n",
8dea0d02 3639 sdp->host->host_no, sdp->channel, sdp->id, sdp->lun);
75ad23bc 3640 queue_flag_set_unlocked(QUEUE_FLAG_BIDI, sdp->request_queue);
8dea0d02
FT
3641 return 0;
3642}
1da177e4 3643
8dea0d02
FT
3644static int scsi_debug_slave_configure(struct scsi_device *sdp)
3645{
f46eb0e9
DG
3646 struct sdebug_dev_info *devip =
3647 (struct sdebug_dev_info *)sdp->hostdata;
a34c4e98 3648
773642d9 3649 if (sdebug_verbose)
c1287970 3650 pr_info("slave_configure <%u %u %u %llu>\n",
8dea0d02 3651 sdp->host->host_no, sdp->channel, sdp->id, sdp->lun);
b01f6f83
DG
3652 if (sdp->host->max_cmd_len != SDEBUG_MAX_CMD_LEN)
3653 sdp->host->max_cmd_len = SDEBUG_MAX_CMD_LEN;
3654 if (devip == NULL) {
f46eb0e9 3655 devip = find_build_dev_info(sdp);
b01f6f83 3656 if (devip == NULL)
f46eb0e9
DG
3657 return 1; /* no resources, will be marked offline */
3658 }
c8b09f6f 3659 sdp->hostdata = devip;
6bb5e6e7 3660 blk_queue_max_segment_size(sdp->request_queue, -1U);
773642d9 3661 if (sdebug_no_uld)
78d4e5a0 3662 sdp->no_uld_attach = 1;
8dea0d02
FT
3663 return 0;
3664}
3665
3666static void scsi_debug_slave_destroy(struct scsi_device *sdp)
3667{
3668 struct sdebug_dev_info *devip =
3669 (struct sdebug_dev_info *)sdp->hostdata;
a34c4e98 3670
773642d9 3671 if (sdebug_verbose)
c1287970 3672 pr_info("slave_destroy <%u %u %u %llu>\n",
8dea0d02
FT
3673 sdp->host->host_no, sdp->channel, sdp->id, sdp->lun);
3674 if (devip) {
25985edc 3675 /* make this slot available for re-use */
c2248fc9 3676 devip->used = false;
8dea0d02
FT
3677 sdp->hostdata = NULL;
3678 }
3679}
3680
c4837394
DG
3681static void stop_qc_helper(struct sdebug_defer *sd_dp)
3682{
3683 if (!sd_dp)
3684 return;
3685 if ((sdebug_jdelay > 0) || (sdebug_ndelay > 0))
3686 hrtimer_cancel(&sd_dp->hrt);
3687 else if (sdebug_jdelay < 0)
3688 cancel_work_sync(&sd_dp->ew.work);
3689}
3690
a10bc12a
DG
3691/* If @cmnd found deletes its timer or work queue and returns true; else
3692 returns false */
3693static bool stop_queued_cmnd(struct scsi_cmnd *cmnd)
8dea0d02
FT
3694{
3695 unsigned long iflags;
c4837394
DG
3696 int j, k, qmax, r_qmax;
3697 struct sdebug_queue *sqp;
8dea0d02 3698 struct sdebug_queued_cmd *sqcp;
cbf67842 3699 struct sdebug_dev_info *devip;
a10bc12a 3700 struct sdebug_defer *sd_dp;
8dea0d02 3701
c4837394
DG
3702 for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp) {
3703 spin_lock_irqsave(&sqp->qc_lock, iflags);
3704 qmax = sdebug_max_queue;
3705 r_qmax = atomic_read(&retired_max_queue);
3706 if (r_qmax > qmax)
3707 qmax = r_qmax;
3708 for (k = 0; k < qmax; ++k) {
3709 if (test_bit(k, sqp->in_use_bm)) {
3710 sqcp = &sqp->qc_arr[k];
3711 if (cmnd != sqcp->a_cmnd)
3712 continue;
3713 /* found */
3714 devip = (struct sdebug_dev_info *)
3715 cmnd->device->hostdata;
3716 if (devip)
3717 atomic_dec(&devip->num_in_q);
3718 sqcp->a_cmnd = NULL;
3719 sd_dp = sqcp->sd_dp;
3720 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
3721 stop_qc_helper(sd_dp);
3722 clear_bit(k, sqp->in_use_bm);
3723 return true;
cbf67842 3724 }
8dea0d02 3725 }
c4837394 3726 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
8dea0d02 3727 }
a10bc12a 3728 return false;
8dea0d02
FT
3729}
3730
a10bc12a 3731/* Deletes (stops) timers or work queues of all queued commands */
8dea0d02
FT
3732static void stop_all_queued(void)
3733{
3734 unsigned long iflags;
c4837394
DG
3735 int j, k;
3736 struct sdebug_queue *sqp;
8dea0d02 3737 struct sdebug_queued_cmd *sqcp;
cbf67842 3738 struct sdebug_dev_info *devip;
a10bc12a 3739 struct sdebug_defer *sd_dp;
8dea0d02 3740
c4837394
DG
3741 for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp) {
3742 spin_lock_irqsave(&sqp->qc_lock, iflags);
3743 for (k = 0; k < SDEBUG_CANQUEUE; ++k) {
3744 if (test_bit(k, sqp->in_use_bm)) {
3745 sqcp = &sqp->qc_arr[k];
3746 if (sqcp->a_cmnd == NULL)
3747 continue;
3748 devip = (struct sdebug_dev_info *)
3749 sqcp->a_cmnd->device->hostdata;
3750 if (devip)
3751 atomic_dec(&devip->num_in_q);
3752 sqcp->a_cmnd = NULL;
3753 sd_dp = sqcp->sd_dp;
3754 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
3755 stop_qc_helper(sd_dp);
3756 clear_bit(k, sqp->in_use_bm);
3757 spin_lock_irqsave(&sqp->qc_lock, iflags);
cbf67842 3758 }
8dea0d02 3759 }
c4837394 3760 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
8dea0d02 3761 }
1da177e4
LT
3762}
3763
cbf67842
DG
3764/* Free queued command memory on heap */
3765static void free_all_queued(void)
1da177e4 3766{
c4837394
DG
3767 int j, k;
3768 struct sdebug_queue *sqp;
cbf67842
DG
3769 struct sdebug_queued_cmd *sqcp;
3770
c4837394
DG
3771 for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp) {
3772 for (k = 0; k < SDEBUG_CANQUEUE; ++k) {
3773 sqcp = &sqp->qc_arr[k];
3774 kfree(sqcp->sd_dp);
3775 sqcp->sd_dp = NULL;
3776 }
cbf67842 3777 }
1da177e4
LT
3778}
3779
cbf67842 3780static int scsi_debug_abort(struct scsi_cmnd *SCpnt)
1da177e4 3781{
a10bc12a
DG
3782 bool ok;
3783
cbf67842
DG
3784 ++num_aborts;
3785 if (SCpnt) {
a10bc12a
DG
3786 ok = stop_queued_cmnd(SCpnt);
3787 if (SCpnt->device && (SDEBUG_OPT_ALL_NOISE & sdebug_opts))
3788 sdev_printk(KERN_INFO, SCpnt->device,
3789 "%s: command%s found\n", __func__,
3790 ok ? "" : " not");
cbf67842
DG
3791 }
3792 return SUCCESS;
1da177e4
LT
3793}
3794
3795static int scsi_debug_device_reset(struct scsi_cmnd * SCpnt)
3796{
1da177e4 3797 ++num_dev_resets;
cbf67842
DG
3798 if (SCpnt && SCpnt->device) {
3799 struct scsi_device *sdp = SCpnt->device;
f46eb0e9
DG
3800 struct sdebug_dev_info *devip =
3801 (struct sdebug_dev_info *)sdp->hostdata;
cbf67842 3802
773642d9 3803 if (SDEBUG_OPT_ALL_NOISE & sdebug_opts)
cbf67842 3804 sdev_printk(KERN_INFO, sdp, "%s\n", __func__);
1da177e4 3805 if (devip)
cbf67842
DG
3806 set_bit(SDEBUG_UA_POR, devip->uas_bm);
3807 }
3808 return SUCCESS;
3809}
3810
3811static int scsi_debug_target_reset(struct scsi_cmnd *SCpnt)
3812{
3813 struct sdebug_host_info *sdbg_host;
3814 struct sdebug_dev_info *devip;
3815 struct scsi_device *sdp;
3816 struct Scsi_Host *hp;
3817 int k = 0;
3818
3819 ++num_target_resets;
3820 if (!SCpnt)
3821 goto lie;
3822 sdp = SCpnt->device;
3823 if (!sdp)
3824 goto lie;
773642d9 3825 if (SDEBUG_OPT_ALL_NOISE & sdebug_opts)
cbf67842
DG
3826 sdev_printk(KERN_INFO, sdp, "%s\n", __func__);
3827 hp = sdp->host;
3828 if (!hp)
3829 goto lie;
3830 sdbg_host = *(struct sdebug_host_info **)shost_priv(hp);
3831 if (sdbg_host) {
3832 list_for_each_entry(devip,
3833 &sdbg_host->dev_info_list,
3834 dev_list)
3835 if (devip->target == sdp->id) {
3836 set_bit(SDEBUG_UA_BUS_RESET, devip->uas_bm);
3837 ++k;
3838 }
1da177e4 3839 }
773642d9 3840 if (SDEBUG_OPT_RESET_NOISE & sdebug_opts)
cbf67842
DG
3841 sdev_printk(KERN_INFO, sdp,
3842 "%s: %d device(s) found in target\n", __func__, k);
3843lie:
1da177e4
LT
3844 return SUCCESS;
3845}
3846
3847static int scsi_debug_bus_reset(struct scsi_cmnd * SCpnt)
3848{
3849 struct sdebug_host_info *sdbg_host;
cbf67842 3850 struct sdebug_dev_info *devip;
1da177e4
LT
3851 struct scsi_device * sdp;
3852 struct Scsi_Host * hp;
cbf67842 3853 int k = 0;
1da177e4 3854
1da177e4 3855 ++num_bus_resets;
cbf67842
DG
3856 if (!(SCpnt && SCpnt->device))
3857 goto lie;
3858 sdp = SCpnt->device;
773642d9 3859 if (SDEBUG_OPT_ALL_NOISE & sdebug_opts)
cbf67842
DG
3860 sdev_printk(KERN_INFO, sdp, "%s\n", __func__);
3861 hp = sdp->host;
3862 if (hp) {
d1e4c9c5 3863 sdbg_host = *(struct sdebug_host_info **)shost_priv(hp);
1da177e4 3864 if (sdbg_host) {
cbf67842 3865 list_for_each_entry(devip,
1da177e4 3866 &sdbg_host->dev_info_list,
cbf67842
DG
3867 dev_list) {
3868 set_bit(SDEBUG_UA_BUS_RESET, devip->uas_bm);
3869 ++k;
3870 }
1da177e4
LT
3871 }
3872 }
773642d9 3873 if (SDEBUG_OPT_RESET_NOISE & sdebug_opts)
cbf67842
DG
3874 sdev_printk(KERN_INFO, sdp,
3875 "%s: %d device(s) found in host\n", __func__, k);
3876lie:
1da177e4
LT
3877 return SUCCESS;
3878}
3879
3880static int scsi_debug_host_reset(struct scsi_cmnd * SCpnt)
3881{
3882 struct sdebug_host_info * sdbg_host;
cbf67842
DG
3883 struct sdebug_dev_info *devip;
3884 int k = 0;
1da177e4 3885
1da177e4 3886 ++num_host_resets;
773642d9 3887 if ((SCpnt->device) && (SDEBUG_OPT_ALL_NOISE & sdebug_opts))
cbf67842 3888 sdev_printk(KERN_INFO, SCpnt->device, "%s\n", __func__);
1da177e4
LT
3889 spin_lock(&sdebug_host_list_lock);
3890 list_for_each_entry(sdbg_host, &sdebug_host_list, host_list) {
cbf67842
DG
3891 list_for_each_entry(devip, &sdbg_host->dev_info_list,
3892 dev_list) {
3893 set_bit(SDEBUG_UA_BUS_RESET, devip->uas_bm);
3894 ++k;
3895 }
1da177e4
LT
3896 }
3897 spin_unlock(&sdebug_host_list_lock);
3898 stop_all_queued();
773642d9 3899 if (SDEBUG_OPT_RESET_NOISE & sdebug_opts)
cbf67842
DG
3900 sdev_printk(KERN_INFO, SCpnt->device,
3901 "%s: %d device(s) found\n", __func__, k);
1da177e4
LT
3902 return SUCCESS;
3903}
3904
f58b0efb 3905static void __init sdebug_build_parts(unsigned char *ramp,
5f2578e5 3906 unsigned long store_size)
1da177e4
LT
3907{
3908 struct partition * pp;
3909 int starts[SDEBUG_MAX_PARTS + 2];
3910 int sectors_per_part, num_sectors, k;
3911 int heads_by_sects, start_sec, end_sec;
3912
3913 /* assume partition table already zeroed */
773642d9 3914 if ((sdebug_num_parts < 1) || (store_size < 1048576))
1da177e4 3915 return;
773642d9
DG
3916 if (sdebug_num_parts > SDEBUG_MAX_PARTS) {
3917 sdebug_num_parts = SDEBUG_MAX_PARTS;
c1287970 3918 pr_warn("reducing partitions to %d\n", SDEBUG_MAX_PARTS);
1da177e4 3919 }
c65b1445 3920 num_sectors = (int)sdebug_store_sectors;
1da177e4 3921 sectors_per_part = (num_sectors - sdebug_sectors_per)
773642d9 3922 / sdebug_num_parts;
1da177e4
LT
3923 heads_by_sects = sdebug_heads * sdebug_sectors_per;
3924 starts[0] = sdebug_sectors_per;
773642d9 3925 for (k = 1; k < sdebug_num_parts; ++k)
1da177e4
LT
3926 starts[k] = ((k * sectors_per_part) / heads_by_sects)
3927 * heads_by_sects;
773642d9
DG
3928 starts[sdebug_num_parts] = num_sectors;
3929 starts[sdebug_num_parts + 1] = 0;
1da177e4
LT
3930
3931 ramp[510] = 0x55; /* magic partition markings */
3932 ramp[511] = 0xAA;
3933 pp = (struct partition *)(ramp + 0x1be);
3934 for (k = 0; starts[k + 1]; ++k, ++pp) {
3935 start_sec = starts[k];
3936 end_sec = starts[k + 1] - 1;
3937 pp->boot_ind = 0;
3938
3939 pp->cyl = start_sec / heads_by_sects;
3940 pp->head = (start_sec - (pp->cyl * heads_by_sects))
3941 / sdebug_sectors_per;
3942 pp->sector = (start_sec % sdebug_sectors_per) + 1;
3943
3944 pp->end_cyl = end_sec / heads_by_sects;
3945 pp->end_head = (end_sec - (pp->end_cyl * heads_by_sects))
3946 / sdebug_sectors_per;
3947 pp->end_sector = (end_sec % sdebug_sectors_per) + 1;
3948
150c3544
AM
3949 pp->start_sect = cpu_to_le32(start_sec);
3950 pp->nr_sects = cpu_to_le32(end_sec - start_sec + 1);
1da177e4
LT
3951 pp->sys_ind = 0x83; /* plain Linux partition */
3952 }
3953}
3954
c4837394
DG
3955static void block_unblock_all_queues(bool block)
3956{
3957 int j;
3958 struct sdebug_queue *sqp;
3959
3960 for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp)
3961 atomic_set(&sqp->blocked, (int)block);
3962}
3963
3964/* Adjust (by rounding down) the sdebug_cmnd_count so abs(every_nth)-1
3965 * commands will be processed normally before triggers occur.
3966 */
3967static void tweak_cmnd_count(void)
3968{
3969 int count, modulo;
3970
3971 modulo = abs(sdebug_every_nth);
3972 if (modulo < 2)
3973 return;
3974 block_unblock_all_queues(true);
3975 count = atomic_read(&sdebug_cmnd_count);
3976 atomic_set(&sdebug_cmnd_count, (count / modulo) * modulo);
3977 block_unblock_all_queues(false);
3978}
3979
3980static void clear_queue_stats(void)
3981{
3982 atomic_set(&sdebug_cmnd_count, 0);
3983 atomic_set(&sdebug_completions, 0);
3984 atomic_set(&sdebug_miss_cpus, 0);
3985 atomic_set(&sdebug_a_tsf, 0);
3986}
3987
3988static void setup_inject(struct sdebug_queue *sqp,
3989 struct sdebug_queued_cmd *sqcp)
3990{
3991 if ((atomic_read(&sdebug_cmnd_count) % abs(sdebug_every_nth)) > 0)
3992 return;
3993 sqcp->inj_recovered = !!(SDEBUG_OPT_RECOVERED_ERR & sdebug_opts);
3994 sqcp->inj_transport = !!(SDEBUG_OPT_TRANSPORT_ERR & sdebug_opts);
3995 sqcp->inj_dif = !!(SDEBUG_OPT_DIF_ERR & sdebug_opts);
3996 sqcp->inj_dix = !!(SDEBUG_OPT_DIX_ERR & sdebug_opts);
3997 sqcp->inj_short = !!(SDEBUG_OPT_SHORT_TRANSFER & sdebug_opts);
3998}
3999
4000/* Complete the processing of the thread that queued a SCSI command to this
4001 * driver. It either completes the command by calling cmnd_done() or
4002 * schedules a hr timer or work queue then returns 0. Returns
4003 * SCSI_MLQUEUE_HOST_BUSY if temporarily out of resources.
4004 */
fd32119b
DG
4005static int schedule_resp(struct scsi_cmnd *cmnd, struct sdebug_dev_info *devip,
4006 int scsi_result, int delta_jiff)
1da177e4 4007{
cbf67842 4008 unsigned long iflags;
cd62b7da 4009 int k, num_in_q, qdepth, inject;
c4837394
DG
4010 struct sdebug_queue *sqp;
4011 struct sdebug_queued_cmd *sqcp;
299b6c07 4012 struct scsi_device *sdp;
a10bc12a 4013 struct sdebug_defer *sd_dp;
299b6c07 4014
b01f6f83
DG
4015 if (unlikely(devip == NULL)) {
4016 if (scsi_result == 0)
f46eb0e9
DG
4017 scsi_result = DID_NO_CONNECT << 16;
4018 goto respond_in_thread;
cbf67842 4019 }
299b6c07
TW
4020 sdp = cmnd->device;
4021
f46eb0e9 4022 if (unlikely(sdebug_verbose && scsi_result))
cbf67842
DG
4023 sdev_printk(KERN_INFO, sdp, "%s: non-zero result=0x%x\n",
4024 __func__, scsi_result);
cd62b7da
DG
4025 if (delta_jiff == 0)
4026 goto respond_in_thread;
1da177e4 4027
cd62b7da 4028 /* schedule the response at a later time if resources permit */
c4837394
DG
4029 sqp = get_queue(cmnd);
4030 spin_lock_irqsave(&sqp->qc_lock, iflags);
4031 if (unlikely(atomic_read(&sqp->blocked))) {
4032 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
4033 return SCSI_MLQUEUE_HOST_BUSY;
4034 }
cbf67842
DG
4035 num_in_q = atomic_read(&devip->num_in_q);
4036 qdepth = cmnd->device->queue_depth;
cbf67842 4037 inject = 0;
f46eb0e9 4038 if (unlikely((qdepth > 0) && (num_in_q >= qdepth))) {
cd62b7da 4039 if (scsi_result) {
c4837394 4040 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
cd62b7da
DG
4041 goto respond_in_thread;
4042 } else
4043 scsi_result = device_qfull_result;
c4837394 4044 } else if (unlikely(sdebug_every_nth &&
f46eb0e9
DG
4045 (SDEBUG_OPT_RARE_TSF & sdebug_opts) &&
4046 (scsi_result == 0))) {
cbf67842
DG
4047 if ((num_in_q == (qdepth - 1)) &&
4048 (atomic_inc_return(&sdebug_a_tsf) >=
773642d9 4049 abs(sdebug_every_nth))) {
cbf67842
DG
4050 atomic_set(&sdebug_a_tsf, 0);
4051 inject = 1;
cd62b7da 4052 scsi_result = device_qfull_result;
1da177e4
LT
4053 }
4054 }
1da177e4 4055
c4837394 4056 k = find_first_zero_bit(sqp->in_use_bm, sdebug_max_queue);
f46eb0e9 4057 if (unlikely(k >= sdebug_max_queue)) {
c4837394 4058 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
cd62b7da
DG
4059 if (scsi_result)
4060 goto respond_in_thread;
773642d9 4061 else if (SDEBUG_OPT_ALL_TSF & sdebug_opts)
cd62b7da 4062 scsi_result = device_qfull_result;
773642d9 4063 if (SDEBUG_OPT_Q_NOISE & sdebug_opts)
cbf67842 4064 sdev_printk(KERN_INFO, sdp,
cd62b7da 4065 "%s: max_queue=%d exceeded, %s\n",
773642d9 4066 __func__, sdebug_max_queue,
cd62b7da
DG
4067 (scsi_result ? "status: TASK SET FULL" :
4068 "report: host busy"));
4069 if (scsi_result)
4070 goto respond_in_thread;
4071 else
cbf67842
DG
4072 return SCSI_MLQUEUE_HOST_BUSY;
4073 }
c4837394 4074 __set_bit(k, sqp->in_use_bm);
cbf67842 4075 atomic_inc(&devip->num_in_q);
c4837394 4076 sqcp = &sqp->qc_arr[k];
cbf67842 4077 sqcp->a_cmnd = cmnd;
c4837394 4078 cmnd->host_scribble = (unsigned char *)sqcp;
cbf67842 4079 cmnd->result = scsi_result;
a10bc12a 4080 sd_dp = sqcp->sd_dp;
c4837394
DG
4081 spin_unlock_irqrestore(&sqp->qc_lock, iflags);
4082 if (unlikely(sdebug_every_nth && sdebug_any_injecting_opt))
4083 setup_inject(sqp, sqcp);
b01f6f83 4084 if (delta_jiff > 0 || sdebug_ndelay > 0) {
b333a819 4085 ktime_t kt;
cbf67842 4086
b333a819 4087 if (delta_jiff > 0) {
13f6b610 4088 kt = ns_to_ktime((u64)delta_jiff * (NSEC_PER_SEC / HZ));
b333a819 4089 } else
8b0e1953 4090 kt = sdebug_ndelay;
a10bc12a
DG
4091 if (NULL == sd_dp) {
4092 sd_dp = kzalloc(sizeof(*sd_dp), GFP_ATOMIC);
4093 if (NULL == sd_dp)
cbf67842 4094 return SCSI_MLQUEUE_HOST_BUSY;
a10bc12a
DG
4095 sqcp->sd_dp = sd_dp;
4096 hrtimer_init(&sd_dp->hrt, CLOCK_MONOTONIC,
c4837394 4097 HRTIMER_MODE_REL_PINNED);
a10bc12a 4098 sd_dp->hrt.function = sdebug_q_cmd_hrt_complete;
c4837394
DG
4099 sd_dp->sqa_idx = sqp - sdebug_q_arr;
4100 sd_dp->qc_idx = k;
1da177e4 4101 }
c4837394
DG
4102 if (sdebug_statistics)
4103 sd_dp->issuing_cpu = raw_smp_processor_id();
4104 hrtimer_start(&sd_dp->hrt, kt, HRTIMER_MODE_REL_PINNED);
4105 } else { /* jdelay < 0, use work queue */
a10bc12a
DG
4106 if (NULL == sd_dp) {
4107 sd_dp = kzalloc(sizeof(*sqcp->sd_dp), GFP_ATOMIC);
4108 if (NULL == sd_dp)
cbf67842 4109 return SCSI_MLQUEUE_HOST_BUSY;
a10bc12a 4110 sqcp->sd_dp = sd_dp;
c4837394
DG
4111 sd_dp->sqa_idx = sqp - sdebug_q_arr;
4112 sd_dp->qc_idx = k;
a10bc12a 4113 INIT_WORK(&sd_dp->ew.work, sdebug_q_cmd_wq_complete);
cbf67842 4114 }
c4837394
DG
4115 if (sdebug_statistics)
4116 sd_dp->issuing_cpu = raw_smp_processor_id();
a10bc12a 4117 schedule_work(&sd_dp->ew.work);
1da177e4 4118 }
f46eb0e9
DG
4119 if (unlikely((SDEBUG_OPT_Q_NOISE & sdebug_opts) &&
4120 (scsi_result == device_qfull_result)))
cbf67842
DG
4121 sdev_printk(KERN_INFO, sdp,
4122 "%s: num_in_q=%d +1, %s%s\n", __func__,
4123 num_in_q, (inject ? "<inject> " : ""),
4124 "status: TASK SET FULL");
4125 return 0;
cd62b7da
DG
4126
4127respond_in_thread: /* call back to mid-layer using invocation thread */
4128 cmnd->result = scsi_result;
4129 cmnd->scsi_done(cmnd);
4130 return 0;
1da177e4 4131}
cbf67842 4132
23183910
DG
4133/* Note: The following macros create attribute files in the
4134 /sys/module/scsi_debug/parameters directory. Unfortunately this
4135 driver is unaware of a change and cannot trigger auxiliary actions
4136 as it can when the corresponding attribute in the
4137 /sys/bus/pseudo/drivers/scsi_debug directory is changed.
4138 */
773642d9
DG
4139module_param_named(add_host, sdebug_add_host, int, S_IRUGO | S_IWUSR);
4140module_param_named(ato, sdebug_ato, int, S_IRUGO);
4141module_param_named(clustering, sdebug_clustering, bool, S_IRUGO | S_IWUSR);
c2206098 4142module_param_named(delay, sdebug_jdelay, int, S_IRUGO | S_IWUSR);
773642d9
DG
4143module_param_named(dev_size_mb, sdebug_dev_size_mb, int, S_IRUGO);
4144module_param_named(dif, sdebug_dif, int, S_IRUGO);
4145module_param_named(dix, sdebug_dix, int, S_IRUGO);
4146module_param_named(dsense, sdebug_dsense, int, S_IRUGO | S_IWUSR);
4147module_param_named(every_nth, sdebug_every_nth, int, S_IRUGO | S_IWUSR);
4148module_param_named(fake_rw, sdebug_fake_rw, int, S_IRUGO | S_IWUSR);
4149module_param_named(guard, sdebug_guard, uint, S_IRUGO);
4150module_param_named(host_lock, sdebug_host_lock, bool, S_IRUGO | S_IWUSR);
e5203cf0
HR
4151module_param_string(inq_vendor, sdebug_inq_vendor_id,
4152 sizeof(sdebug_inq_vendor_id), S_IRUGO|S_IWUSR);
4153module_param_string(inq_product, sdebug_inq_product_id,
4154 sizeof(sdebug_inq_product_id), S_IRUGO|S_IWUSR);
4155module_param_string(inq_rev, sdebug_inq_product_rev,
4156 sizeof(sdebug_inq_product_rev), S_IRUGO|S_IWUSR);
773642d9
DG
4157module_param_named(lbpu, sdebug_lbpu, int, S_IRUGO);
4158module_param_named(lbpws, sdebug_lbpws, int, S_IRUGO);
4159module_param_named(lbpws10, sdebug_lbpws10, int, S_IRUGO);
4160module_param_named(lbprz, sdebug_lbprz, int, S_IRUGO);
4161module_param_named(lowest_aligned, sdebug_lowest_aligned, int, S_IRUGO);
4162module_param_named(max_luns, sdebug_max_luns, int, S_IRUGO | S_IWUSR);
4163module_param_named(max_queue, sdebug_max_queue, int, S_IRUGO | S_IWUSR);
4164module_param_named(ndelay, sdebug_ndelay, int, S_IRUGO | S_IWUSR);
4165module_param_named(no_lun_0, sdebug_no_lun_0, int, S_IRUGO | S_IWUSR);
4166module_param_named(no_uld, sdebug_no_uld, int, S_IRUGO);
4167module_param_named(num_parts, sdebug_num_parts, int, S_IRUGO);
4168module_param_named(num_tgts, sdebug_num_tgts, int, S_IRUGO | S_IWUSR);
4169module_param_named(opt_blks, sdebug_opt_blks, int, S_IRUGO);
4170module_param_named(opts, sdebug_opts, int, S_IRUGO | S_IWUSR);
4171module_param_named(physblk_exp, sdebug_physblk_exp, int, S_IRUGO);
86e6828a 4172module_param_named(opt_xferlen_exp, sdebug_opt_xferlen_exp, int, S_IRUGO);
773642d9
DG
4173module_param_named(ptype, sdebug_ptype, int, S_IRUGO | S_IWUSR);
4174module_param_named(removable, sdebug_removable, bool, S_IRUGO | S_IWUSR);
4175module_param_named(scsi_level, sdebug_scsi_level, int, S_IRUGO);
4176module_param_named(sector_size, sdebug_sector_size, int, S_IRUGO);
c4837394 4177module_param_named(statistics, sdebug_statistics, bool, S_IRUGO | S_IWUSR);
773642d9 4178module_param_named(strict, sdebug_strict, bool, S_IRUGO | S_IWUSR);
c4837394 4179module_param_named(submit_queues, submit_queues, int, S_IRUGO);
773642d9
DG
4180module_param_named(unmap_alignment, sdebug_unmap_alignment, int, S_IRUGO);
4181module_param_named(unmap_granularity, sdebug_unmap_granularity, int, S_IRUGO);
4182module_param_named(unmap_max_blocks, sdebug_unmap_max_blocks, int, S_IRUGO);
4183module_param_named(unmap_max_desc, sdebug_unmap_max_desc, int, S_IRUGO);
4184module_param_named(virtual_gb, sdebug_virtual_gb, int, S_IRUGO | S_IWUSR);
09ba24c1 4185module_param_named(uuid_ctl, sdebug_uuid_ctl, int, S_IRUGO);
773642d9 4186module_param_named(vpd_use_hostno, sdebug_vpd_use_hostno, int,
5b94e232 4187 S_IRUGO | S_IWUSR);
773642d9 4188module_param_named(write_same_length, sdebug_write_same_length, int,
5b94e232 4189 S_IRUGO | S_IWUSR);
1da177e4
LT
4190
4191MODULE_AUTHOR("Eric Youngdale + Douglas Gilbert");
4192MODULE_DESCRIPTION("SCSI debug adapter driver");
4193MODULE_LICENSE("GPL");
b01f6f83 4194MODULE_VERSION(SDEBUG_VERSION);
1da177e4
LT
4195
4196MODULE_PARM_DESC(add_host, "0..127 hosts allowed(def=1)");
5b94e232 4197MODULE_PARM_DESC(ato, "application tag ownership: 0=disk 1=host (def=1)");
0759c666 4198MODULE_PARM_DESC(clustering, "when set enables larger transfers (def=0)");
cbf67842 4199MODULE_PARM_DESC(delay, "response delay (def=1 jiffy); 0:imm, -1,-2:tiny");
c2248fc9 4200MODULE_PARM_DESC(dev_size_mb, "size in MiB of ram shared by devs(def=8)");
5b94e232
MP
4201MODULE_PARM_DESC(dif, "data integrity field type: 0-3 (def=0)");
4202MODULE_PARM_DESC(dix, "data integrity extensions mask (def=0)");
c65b1445 4203MODULE_PARM_DESC(dsense, "use descriptor sense format(def=0 -> fixed)");
beb87c33 4204MODULE_PARM_DESC(every_nth, "timeout every nth command(def=0)");
23183910 4205MODULE_PARM_DESC(fake_rw, "fake reads/writes instead of copying (def=0)");
5b94e232 4206MODULE_PARM_DESC(guard, "protection checksum: 0=crc, 1=ip (def=0)");
185dd232 4207MODULE_PARM_DESC(host_lock, "host_lock is ignored (def=0)");
e5203cf0
HR
4208MODULE_PARM_DESC(inq_vendor, "SCSI INQUIRY vendor string (def=\"Linux\")");
4209MODULE_PARM_DESC(inq_product, "SCSI INQUIRY product string (def=\"scsi_debug\")");
4210MODULE_PARM_DESC(inq_rev, "SCSI INQUIRY revision string (def=\"0186\")");
5b94e232
MP
4211MODULE_PARM_DESC(lbpu, "enable LBP, support UNMAP command (def=0)");
4212MODULE_PARM_DESC(lbpws, "enable LBP, support WRITE SAME(16) with UNMAP bit (def=0)");
4213MODULE_PARM_DESC(lbpws10, "enable LBP, support WRITE SAME(10) with UNMAP bit (def=0)");
760f3b03
DG
4214MODULE_PARM_DESC(lbprz,
4215 "on read unmapped LBs return 0 when 1 (def), return 0xff when 2");
5b94e232 4216MODULE_PARM_DESC(lowest_aligned, "lowest aligned lba (def=0)");
c65b1445 4217MODULE_PARM_DESC(max_luns, "number of LUNs per target to simulate(def=1)");
cbf67842
DG
4218MODULE_PARM_DESC(max_queue, "max number of queued commands (1 to max(def))");
4219MODULE_PARM_DESC(ndelay, "response delay in nanoseconds (def=0 -> ignore)");
c65b1445 4220MODULE_PARM_DESC(no_lun_0, "no LU number 0 (def=0 -> have lun 0)");
78d4e5a0 4221MODULE_PARM_DESC(no_uld, "stop ULD (e.g. sd driver) attaching (def=0))");
1da177e4 4222MODULE_PARM_DESC(num_parts, "number of partitions(def=0)");
c65b1445 4223MODULE_PARM_DESC(num_tgts, "number of targets per host to simulate(def=1)");
32c5844a 4224MODULE_PARM_DESC(opt_blks, "optimal transfer length in blocks (def=1024)");
6f3cbf55 4225MODULE_PARM_DESC(opts, "1->noise, 2->medium_err, 4->timeout, 8->recovered_err... (def=0)");
5b94e232 4226MODULE_PARM_DESC(physblk_exp, "physical block exponent (def=0)");
86e6828a 4227MODULE_PARM_DESC(opt_xferlen_exp, "optimal transfer length granularity exponent (def=physblk_exp)");
1da177e4 4228MODULE_PARM_DESC(ptype, "SCSI peripheral type(def=0[disk])");
d986788b 4229MODULE_PARM_DESC(removable, "claim to have removable media (def=0)");
760f3b03 4230MODULE_PARM_DESC(scsi_level, "SCSI level to simulate(def=7[SPC-5])");
ea61fca5 4231MODULE_PARM_DESC(sector_size, "logical block size in bytes (def=512)");
c4837394 4232MODULE_PARM_DESC(statistics, "collect statistics on commands, queues (def=0)");
c2248fc9 4233MODULE_PARM_DESC(strict, "stricter checks: reserved field in cdb (def=0)");
c4837394 4234MODULE_PARM_DESC(submit_queues, "support for block multi-queue (def=1)");
5b94e232
MP
4235MODULE_PARM_DESC(unmap_alignment, "lowest aligned thin provisioning lba (def=0)");
4236MODULE_PARM_DESC(unmap_granularity, "thin provisioning granularity in blocks (def=1)");
6014759c
MP
4237MODULE_PARM_DESC(unmap_max_blocks, "max # of blocks can be unmapped in one cmd (def=0xffffffff)");
4238MODULE_PARM_DESC(unmap_max_desc, "max # of ranges that can be unmapped in one cmd (def=256)");
09ba24c1
DG
4239MODULE_PARM_DESC(uuid_ctl,
4240 "1->use uuid for lu name, 0->don't, 2->all use same (def=0)");
c2248fc9 4241MODULE_PARM_DESC(virtual_gb, "virtual gigabyte (GiB) size (def=0 -> use dev_size_mb)");
5b94e232
MP
4242MODULE_PARM_DESC(vpd_use_hostno, "0 -> dev ids ignore hostno (def=1 -> unique dev ids)");
4243MODULE_PARM_DESC(write_same_length, "Maximum blocks per WRITE SAME cmd (def=0xffff)");
1da177e4 4244
760f3b03
DG
4245#define SDEBUG_INFO_LEN 256
4246static char sdebug_info[SDEBUG_INFO_LEN];
1da177e4
LT
4247
4248static const char * scsi_debug_info(struct Scsi_Host * shp)
4249{
c4837394
DG
4250 int k;
4251
760f3b03
DG
4252 k = scnprintf(sdebug_info, SDEBUG_INFO_LEN, "%s: version %s [%s]\n",
4253 my_name, SDEBUG_VERSION, sdebug_version_date);
4254 if (k >= (SDEBUG_INFO_LEN - 1))
c4837394 4255 return sdebug_info;
760f3b03
DG
4256 scnprintf(sdebug_info + k, SDEBUG_INFO_LEN - k,
4257 " dev_size_mb=%d, opts=0x%x, submit_queues=%d, %s=%d",
4258 sdebug_dev_size_mb, sdebug_opts, submit_queues,
4259 "statistics", (int)sdebug_statistics);
1da177e4
LT
4260 return sdebug_info;
4261}
4262
cbf67842 4263/* 'echo <val> > /proc/scsi/scsi_debug/<host_id>' writes to opts */
fd32119b
DG
4264static int scsi_debug_write_info(struct Scsi_Host *host, char *buffer,
4265 int length)
1da177e4 4266{
c8ed555a
AV
4267 char arr[16];
4268 int opts;
4269 int minLen = length > 15 ? 15 : length;
1da177e4 4270
c8ed555a
AV
4271 if (!capable(CAP_SYS_ADMIN) || !capable(CAP_SYS_RAWIO))
4272 return -EACCES;
4273 memcpy(arr, buffer, minLen);
4274 arr[minLen] = '\0';
4275 if (1 != sscanf(arr, "%d", &opts))
4276 return -EINVAL;
773642d9
DG
4277 sdebug_opts = opts;
4278 sdebug_verbose = !!(SDEBUG_OPT_NOISE & opts);
4279 sdebug_any_injecting_opt = !!(SDEBUG_OPT_ALL_INJECTING & opts);
4280 if (sdebug_every_nth != 0)
c4837394 4281 tweak_cmnd_count();
c8ed555a
AV
4282 return length;
4283}
1da177e4 4284
cbf67842
DG
4285/* Output seen with 'cat /proc/scsi/scsi_debug/<host_id>'. It will be the
4286 * same for each scsi_debug host (if more than one). Some of the counters
4287 * output are not atomics so might be inaccurate in a busy system. */
c8ed555a
AV
4288static int scsi_debug_show_info(struct seq_file *m, struct Scsi_Host *host)
4289{
c4837394
DG
4290 int f, j, l;
4291 struct sdebug_queue *sqp;
4292
4293 seq_printf(m, "scsi_debug adapter driver, version %s [%s]\n",
4294 SDEBUG_VERSION, sdebug_version_date);
4295 seq_printf(m, "num_tgts=%d, %ssize=%d MB, opts=0x%x, every_nth=%d\n",
4296 sdebug_num_tgts, "shared (ram) ", sdebug_dev_size_mb,
4297 sdebug_opts, sdebug_every_nth);
4298 seq_printf(m, "delay=%d, ndelay=%d, max_luns=%d, sector_size=%d %s\n",
4299 sdebug_jdelay, sdebug_ndelay, sdebug_max_luns,
4300 sdebug_sector_size, "bytes");
4301 seq_printf(m, "cylinders=%d, heads=%d, sectors=%d, command aborts=%d\n",
4302 sdebug_cylinders_per, sdebug_heads, sdebug_sectors_per,
4303 num_aborts);
4304 seq_printf(m, "RESETs: device=%d, target=%d, bus=%d, host=%d\n",
4305 num_dev_resets, num_target_resets, num_bus_resets,
4306 num_host_resets);
4307 seq_printf(m, "dix_reads=%d, dix_writes=%d, dif_errors=%d\n",
4308 dix_reads, dix_writes, dif_errors);
4309 seq_printf(m, "usec_in_jiffy=%lu, %s=%d, mq_active=%d\n",
4310 TICK_NSEC / 1000, "statistics", sdebug_statistics,
4311 sdebug_mq_active);
4312 seq_printf(m, "cmnd_count=%d, completions=%d, %s=%d, a_tsf=%d\n",
4313 atomic_read(&sdebug_cmnd_count),
4314 atomic_read(&sdebug_completions),
4315 "miss_cpus", atomic_read(&sdebug_miss_cpus),
4316 atomic_read(&sdebug_a_tsf));
4317
4318 seq_printf(m, "submit_queues=%d\n", submit_queues);
4319 for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp) {
4320 seq_printf(m, " queue %d:\n", j);
4321 f = find_first_bit(sqp->in_use_bm, sdebug_max_queue);
4322 if (f != sdebug_max_queue) {
4323 l = find_last_bit(sqp->in_use_bm, sdebug_max_queue);
4324 seq_printf(m, " in_use_bm BUSY: %s: %d,%d\n",
4325 "first,last bits", f, l);
4326 }
cbf67842 4327 }
c8ed555a 4328 return 0;
1da177e4
LT
4329}
4330
82069379 4331static ssize_t delay_show(struct device_driver *ddp, char *buf)
1da177e4 4332{
c2206098 4333 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_jdelay);
1da177e4 4334}
c4837394
DG
4335/* Returns -EBUSY if jdelay is being changed and commands are queued. The unit
4336 * of delay is jiffies.
4337 */
82069379
AM
4338static ssize_t delay_store(struct device_driver *ddp, const char *buf,
4339 size_t count)
1da177e4 4340{
c2206098 4341 int jdelay, res;
cbf67842 4342
b01f6f83 4343 if (count > 0 && sscanf(buf, "%d", &jdelay) == 1) {
cbf67842 4344 res = count;
c2206098 4345 if (sdebug_jdelay != jdelay) {
c4837394
DG
4346 int j, k;
4347 struct sdebug_queue *sqp;
4348
4349 block_unblock_all_queues(true);
4350 for (j = 0, sqp = sdebug_q_arr; j < submit_queues;
4351 ++j, ++sqp) {
4352 k = find_first_bit(sqp->in_use_bm,
4353 sdebug_max_queue);
4354 if (k != sdebug_max_queue) {
4355 res = -EBUSY; /* queued commands */
4356 break;
4357 }
4358 }
4359 if (res > 0) {
a10bc12a
DG
4360 /* make sure sdebug_defer instances get
4361 * re-allocated for new delay variant */
4362 free_all_queued();
c2206098 4363 sdebug_jdelay = jdelay;
773642d9 4364 sdebug_ndelay = 0;
cbf67842 4365 }
c4837394 4366 block_unblock_all_queues(false);
1da177e4 4367 }
cbf67842 4368 return res;
1da177e4
LT
4369 }
4370 return -EINVAL;
4371}
82069379 4372static DRIVER_ATTR_RW(delay);
1da177e4 4373
cbf67842
DG
4374static ssize_t ndelay_show(struct device_driver *ddp, char *buf)
4375{
773642d9 4376 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_ndelay);
cbf67842
DG
4377}
4378/* Returns -EBUSY if ndelay is being changed and commands are queued */
c2206098 4379/* If > 0 and accepted then sdebug_jdelay is set to JDELAY_OVERRIDDEN */
cbf67842 4380static ssize_t ndelay_store(struct device_driver *ddp, const char *buf,
fd32119b 4381 size_t count)
cbf67842 4382{
c4837394 4383 int ndelay, res;
cbf67842
DG
4384
4385 if ((count > 0) && (1 == sscanf(buf, "%d", &ndelay)) &&
c4837394 4386 (ndelay >= 0) && (ndelay < (1000 * 1000 * 1000))) {
cbf67842 4387 res = count;
773642d9 4388 if (sdebug_ndelay != ndelay) {
c4837394
DG
4389 int j, k;
4390 struct sdebug_queue *sqp;
4391
4392 block_unblock_all_queues(true);
4393 for (j = 0, sqp = sdebug_q_arr; j < submit_queues;
4394 ++j, ++sqp) {
4395 k = find_first_bit(sqp->in_use_bm,
4396 sdebug_max_queue);
4397 if (k != sdebug_max_queue) {
4398 res = -EBUSY; /* queued commands */
4399 break;
4400 }
4401 }
4402 if (res > 0) {
a10bc12a
DG
4403 /* make sure sdebug_defer instances get
4404 * re-allocated for new delay variant */
4405 free_all_queued();
773642d9 4406 sdebug_ndelay = ndelay;
c2206098
DG
4407 sdebug_jdelay = ndelay ? JDELAY_OVERRIDDEN
4408 : DEF_JDELAY;
cbf67842 4409 }
c4837394 4410 block_unblock_all_queues(false);
cbf67842
DG
4411 }
4412 return res;
4413 }
4414 return -EINVAL;
4415}
4416static DRIVER_ATTR_RW(ndelay);
4417
82069379 4418static ssize_t opts_show(struct device_driver *ddp, char *buf)
1da177e4 4419{
773642d9 4420 return scnprintf(buf, PAGE_SIZE, "0x%x\n", sdebug_opts);
1da177e4
LT
4421}
4422
82069379
AM
4423static ssize_t opts_store(struct device_driver *ddp, const char *buf,
4424 size_t count)
1da177e4
LT
4425{
4426 int opts;
4427 char work[20];
4428
4429 if (1 == sscanf(buf, "%10s", work)) {
48a96876 4430 if (0 == strncasecmp(work,"0x", 2)) {
1da177e4
LT
4431 if (1 == sscanf(&work[2], "%x", &opts))
4432 goto opts_done;
4433 } else {
4434 if (1 == sscanf(work, "%d", &opts))
4435 goto opts_done;
4436 }
4437 }
4438 return -EINVAL;
4439opts_done:
773642d9
DG
4440 sdebug_opts = opts;
4441 sdebug_verbose = !!(SDEBUG_OPT_NOISE & opts);
4442 sdebug_any_injecting_opt = !!(SDEBUG_OPT_ALL_INJECTING & opts);
c4837394 4443 tweak_cmnd_count();
1da177e4
LT
4444 return count;
4445}
82069379 4446static DRIVER_ATTR_RW(opts);
1da177e4 4447
82069379 4448static ssize_t ptype_show(struct device_driver *ddp, char *buf)
1da177e4 4449{
773642d9 4450 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_ptype);
1da177e4 4451}
82069379
AM
4452static ssize_t ptype_store(struct device_driver *ddp, const char *buf,
4453 size_t count)
1da177e4
LT
4454{
4455 int n;
4456
4457 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
773642d9 4458 sdebug_ptype = n;
1da177e4
LT
4459 return count;
4460 }
4461 return -EINVAL;
4462}
82069379 4463static DRIVER_ATTR_RW(ptype);
1da177e4 4464
82069379 4465static ssize_t dsense_show(struct device_driver *ddp, char *buf)
1da177e4 4466{
773642d9 4467 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_dsense);
1da177e4 4468}
82069379
AM
4469static ssize_t dsense_store(struct device_driver *ddp, const char *buf,
4470 size_t count)
1da177e4
LT
4471{
4472 int n;
4473
4474 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
773642d9 4475 sdebug_dsense = n;
1da177e4
LT
4476 return count;
4477 }
4478 return -EINVAL;
4479}
82069379 4480static DRIVER_ATTR_RW(dsense);
1da177e4 4481
82069379 4482static ssize_t fake_rw_show(struct device_driver *ddp, char *buf)
23183910 4483{
773642d9 4484 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_fake_rw);
23183910 4485}
82069379
AM
4486static ssize_t fake_rw_store(struct device_driver *ddp, const char *buf,
4487 size_t count)
23183910
DG
4488{
4489 int n;
4490
4491 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
cbf67842 4492 n = (n > 0);
773642d9
DG
4493 sdebug_fake_rw = (sdebug_fake_rw > 0);
4494 if (sdebug_fake_rw != n) {
cbf67842
DG
4495 if ((0 == n) && (NULL == fake_storep)) {
4496 unsigned long sz =
773642d9 4497 (unsigned long)sdebug_dev_size_mb *
cbf67842
DG
4498 1048576;
4499
4500 fake_storep = vmalloc(sz);
4501 if (NULL == fake_storep) {
c1287970 4502 pr_err("out of memory, 9\n");
cbf67842
DG
4503 return -ENOMEM;
4504 }
4505 memset(fake_storep, 0, sz);
4506 }
773642d9 4507 sdebug_fake_rw = n;
cbf67842 4508 }
23183910
DG
4509 return count;
4510 }
4511 return -EINVAL;
4512}
82069379 4513static DRIVER_ATTR_RW(fake_rw);
23183910 4514
82069379 4515static ssize_t no_lun_0_show(struct device_driver *ddp, char *buf)
c65b1445 4516{
773642d9 4517 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_no_lun_0);
c65b1445 4518}
82069379
AM
4519static ssize_t no_lun_0_store(struct device_driver *ddp, const char *buf,
4520 size_t count)
c65b1445
DG
4521{
4522 int n;
4523
4524 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
773642d9 4525 sdebug_no_lun_0 = n;
c65b1445
DG
4526 return count;
4527 }
4528 return -EINVAL;
4529}
82069379 4530static DRIVER_ATTR_RW(no_lun_0);
c65b1445 4531
82069379 4532static ssize_t num_tgts_show(struct device_driver *ddp, char *buf)
1da177e4 4533{
773642d9 4534 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_num_tgts);
1da177e4 4535}
82069379
AM
4536static ssize_t num_tgts_store(struct device_driver *ddp, const char *buf,
4537 size_t count)
1da177e4
LT
4538{
4539 int n;
4540
4541 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
773642d9 4542 sdebug_num_tgts = n;
1da177e4
LT
4543 sdebug_max_tgts_luns();
4544 return count;
4545 }
4546 return -EINVAL;
4547}
82069379 4548static DRIVER_ATTR_RW(num_tgts);
1da177e4 4549
82069379 4550static ssize_t dev_size_mb_show(struct device_driver *ddp, char *buf)
1da177e4 4551{
773642d9 4552 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_dev_size_mb);
1da177e4 4553}
82069379 4554static DRIVER_ATTR_RO(dev_size_mb);
1da177e4 4555
82069379 4556static ssize_t num_parts_show(struct device_driver *ddp, char *buf)
1da177e4 4557{
773642d9 4558 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_num_parts);
1da177e4 4559}
82069379 4560static DRIVER_ATTR_RO(num_parts);
1da177e4 4561
82069379 4562static ssize_t every_nth_show(struct device_driver *ddp, char *buf)
1da177e4 4563{
773642d9 4564 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_every_nth);
1da177e4 4565}
82069379
AM
4566static ssize_t every_nth_store(struct device_driver *ddp, const char *buf,
4567 size_t count)
1da177e4
LT
4568{
4569 int nth;
4570
4571 if ((count > 0) && (1 == sscanf(buf, "%d", &nth))) {
773642d9 4572 sdebug_every_nth = nth;
c4837394
DG
4573 if (nth && !sdebug_statistics) {
4574 pr_info("every_nth needs statistics=1, set it\n");
4575 sdebug_statistics = true;
4576 }
4577 tweak_cmnd_count();
1da177e4
LT
4578 return count;
4579 }
4580 return -EINVAL;
4581}
82069379 4582static DRIVER_ATTR_RW(every_nth);
1da177e4 4583
82069379 4584static ssize_t max_luns_show(struct device_driver *ddp, char *buf)
1da177e4 4585{
773642d9 4586 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_max_luns);
1da177e4 4587}
82069379
AM
4588static ssize_t max_luns_store(struct device_driver *ddp, const char *buf,
4589 size_t count)
1da177e4
LT
4590{
4591 int n;
19c8ead7 4592 bool changed;
1da177e4
LT
4593
4594 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
8d039e22
DG
4595 if (n > 256) {
4596 pr_warn("max_luns can be no more than 256\n");
4597 return -EINVAL;
4598 }
773642d9
DG
4599 changed = (sdebug_max_luns != n);
4600 sdebug_max_luns = n;
1da177e4 4601 sdebug_max_tgts_luns();
773642d9 4602 if (changed && (sdebug_scsi_level >= 5)) { /* >= SPC-3 */
19c8ead7
EM
4603 struct sdebug_host_info *sdhp;
4604 struct sdebug_dev_info *dp;
4605
4606 spin_lock(&sdebug_host_list_lock);
4607 list_for_each_entry(sdhp, &sdebug_host_list,
4608 host_list) {
4609 list_for_each_entry(dp, &sdhp->dev_info_list,
4610 dev_list) {
4611 set_bit(SDEBUG_UA_LUNS_CHANGED,
4612 dp->uas_bm);
4613 }
4614 }
4615 spin_unlock(&sdebug_host_list_lock);
4616 }
1da177e4
LT
4617 return count;
4618 }
4619 return -EINVAL;
4620}
82069379 4621static DRIVER_ATTR_RW(max_luns);
1da177e4 4622
82069379 4623static ssize_t max_queue_show(struct device_driver *ddp, char *buf)
78d4e5a0 4624{
773642d9 4625 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_max_queue);
78d4e5a0 4626}
cbf67842
DG
4627/* N.B. max_queue can be changed while there are queued commands. In flight
4628 * commands beyond the new max_queue will be completed. */
82069379
AM
4629static ssize_t max_queue_store(struct device_driver *ddp, const char *buf,
4630 size_t count)
78d4e5a0 4631{
c4837394
DG
4632 int j, n, k, a;
4633 struct sdebug_queue *sqp;
78d4e5a0
DG
4634
4635 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n > 0) &&
c4837394
DG
4636 (n <= SDEBUG_CANQUEUE)) {
4637 block_unblock_all_queues(true);
4638 k = 0;
4639 for (j = 0, sqp = sdebug_q_arr; j < submit_queues;
4640 ++j, ++sqp) {
4641 a = find_last_bit(sqp->in_use_bm, SDEBUG_CANQUEUE);
4642 if (a > k)
4643 k = a;
4644 }
773642d9 4645 sdebug_max_queue = n;
c4837394 4646 if (k == SDEBUG_CANQUEUE)
cbf67842
DG
4647 atomic_set(&retired_max_queue, 0);
4648 else if (k >= n)
4649 atomic_set(&retired_max_queue, k + 1);
4650 else
4651 atomic_set(&retired_max_queue, 0);
c4837394 4652 block_unblock_all_queues(false);
78d4e5a0
DG
4653 return count;
4654 }
4655 return -EINVAL;
4656}
82069379 4657static DRIVER_ATTR_RW(max_queue);
78d4e5a0 4658
82069379 4659static ssize_t no_uld_show(struct device_driver *ddp, char *buf)
78d4e5a0 4660{
773642d9 4661 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_no_uld);
78d4e5a0 4662}
82069379 4663static DRIVER_ATTR_RO(no_uld);
78d4e5a0 4664
82069379 4665static ssize_t scsi_level_show(struct device_driver *ddp, char *buf)
1da177e4 4666{
773642d9 4667 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_scsi_level);
1da177e4 4668}
82069379 4669static DRIVER_ATTR_RO(scsi_level);
1da177e4 4670
82069379 4671static ssize_t virtual_gb_show(struct device_driver *ddp, char *buf)
c65b1445 4672{
773642d9 4673 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_virtual_gb);
c65b1445 4674}
82069379
AM
4675static ssize_t virtual_gb_store(struct device_driver *ddp, const char *buf,
4676 size_t count)
c65b1445 4677{
c2248fc9 4678 int n;
0d01c5df 4679 bool changed;
c65b1445
DG
4680
4681 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
773642d9
DG
4682 changed = (sdebug_virtual_gb != n);
4683 sdebug_virtual_gb = n;
28898873 4684 sdebug_capacity = get_sdebug_capacity();
0d01c5df
DG
4685 if (changed) {
4686 struct sdebug_host_info *sdhp;
4687 struct sdebug_dev_info *dp;
4688
4bc6b634 4689 spin_lock(&sdebug_host_list_lock);
0d01c5df
DG
4690 list_for_each_entry(sdhp, &sdebug_host_list,
4691 host_list) {
4692 list_for_each_entry(dp, &sdhp->dev_info_list,
4693 dev_list) {
4694 set_bit(SDEBUG_UA_CAPACITY_CHANGED,
4695 dp->uas_bm);
4696 }
4697 }
4bc6b634 4698 spin_unlock(&sdebug_host_list_lock);
0d01c5df 4699 }
c65b1445
DG
4700 return count;
4701 }
4702 return -EINVAL;
4703}
82069379 4704static DRIVER_ATTR_RW(virtual_gb);
c65b1445 4705
82069379 4706static ssize_t add_host_show(struct device_driver *ddp, char *buf)
1da177e4 4707{
773642d9 4708 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_add_host);
1da177e4
LT
4709}
4710
fd32119b
DG
4711static int sdebug_add_adapter(void);
4712static void sdebug_remove_adapter(void);
4713
82069379
AM
4714static ssize_t add_host_store(struct device_driver *ddp, const char *buf,
4715 size_t count)
1da177e4 4716{
f3df41cf 4717 int delta_hosts;
1da177e4 4718
f3df41cf 4719 if (sscanf(buf, "%d", &delta_hosts) != 1)
1da177e4 4720 return -EINVAL;
1da177e4
LT
4721 if (delta_hosts > 0) {
4722 do {
4723 sdebug_add_adapter();
4724 } while (--delta_hosts);
4725 } else if (delta_hosts < 0) {
4726 do {
4727 sdebug_remove_adapter();
4728 } while (++delta_hosts);
4729 }
4730 return count;
4731}
82069379 4732static DRIVER_ATTR_RW(add_host);
1da177e4 4733
82069379 4734static ssize_t vpd_use_hostno_show(struct device_driver *ddp, char *buf)
23183910 4735{
773642d9 4736 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_vpd_use_hostno);
23183910 4737}
82069379
AM
4738static ssize_t vpd_use_hostno_store(struct device_driver *ddp, const char *buf,
4739 size_t count)
23183910
DG
4740{
4741 int n;
4742
4743 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
773642d9 4744 sdebug_vpd_use_hostno = n;
23183910
DG
4745 return count;
4746 }
4747 return -EINVAL;
4748}
82069379 4749static DRIVER_ATTR_RW(vpd_use_hostno);
23183910 4750
c4837394
DG
4751static ssize_t statistics_show(struct device_driver *ddp, char *buf)
4752{
4753 return scnprintf(buf, PAGE_SIZE, "%d\n", (int)sdebug_statistics);
4754}
4755static ssize_t statistics_store(struct device_driver *ddp, const char *buf,
4756 size_t count)
4757{
4758 int n;
4759
4760 if ((count > 0) && (sscanf(buf, "%d", &n) == 1) && (n >= 0)) {
4761 if (n > 0)
4762 sdebug_statistics = true;
4763 else {
4764 clear_queue_stats();
4765 sdebug_statistics = false;
4766 }
4767 return count;
4768 }
4769 return -EINVAL;
4770}
4771static DRIVER_ATTR_RW(statistics);
4772
82069379 4773static ssize_t sector_size_show(struct device_driver *ddp, char *buf)
597136ab 4774{
773642d9 4775 return scnprintf(buf, PAGE_SIZE, "%u\n", sdebug_sector_size);
597136ab 4776}
82069379 4777static DRIVER_ATTR_RO(sector_size);
597136ab 4778
c4837394
DG
4779static ssize_t submit_queues_show(struct device_driver *ddp, char *buf)
4780{
4781 return scnprintf(buf, PAGE_SIZE, "%d\n", submit_queues);
4782}
4783static DRIVER_ATTR_RO(submit_queues);
4784
82069379 4785static ssize_t dix_show(struct device_driver *ddp, char *buf)
c6a44287 4786{
773642d9 4787 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_dix);
c6a44287 4788}
82069379 4789static DRIVER_ATTR_RO(dix);
c6a44287 4790
82069379 4791static ssize_t dif_show(struct device_driver *ddp, char *buf)
c6a44287 4792{
773642d9 4793 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_dif);
c6a44287 4794}
82069379 4795static DRIVER_ATTR_RO(dif);
c6a44287 4796
82069379 4797static ssize_t guard_show(struct device_driver *ddp, char *buf)
c6a44287 4798{
773642d9 4799 return scnprintf(buf, PAGE_SIZE, "%u\n", sdebug_guard);
c6a44287 4800}
82069379 4801static DRIVER_ATTR_RO(guard);
c6a44287 4802
82069379 4803static ssize_t ato_show(struct device_driver *ddp, char *buf)
c6a44287 4804{
773642d9 4805 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_ato);
c6a44287 4806}
82069379 4807static DRIVER_ATTR_RO(ato);
c6a44287 4808
82069379 4809static ssize_t map_show(struct device_driver *ddp, char *buf)
44d92694
MP
4810{
4811 ssize_t count;
4812
5b94e232 4813 if (!scsi_debug_lbp())
44d92694
MP
4814 return scnprintf(buf, PAGE_SIZE, "0-%u\n",
4815 sdebug_store_sectors);
4816
c7badc90
TH
4817 count = scnprintf(buf, PAGE_SIZE - 1, "%*pbl",
4818 (int)map_size, map_storep);
44d92694 4819 buf[count++] = '\n';
c7badc90 4820 buf[count] = '\0';
44d92694
MP
4821
4822 return count;
4823}
82069379 4824static DRIVER_ATTR_RO(map);
44d92694 4825
82069379 4826static ssize_t removable_show(struct device_driver *ddp, char *buf)
d986788b 4827{
773642d9 4828 return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_removable ? 1 : 0);
d986788b 4829}
82069379
AM
4830static ssize_t removable_store(struct device_driver *ddp, const char *buf,
4831 size_t count)
d986788b
MP
4832{
4833 int n;
4834
4835 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
773642d9 4836 sdebug_removable = (n > 0);
d986788b
MP
4837 return count;
4838 }
4839 return -EINVAL;
4840}
82069379 4841static DRIVER_ATTR_RW(removable);
d986788b 4842
cbf67842
DG
4843static ssize_t host_lock_show(struct device_driver *ddp, char *buf)
4844{
773642d9 4845 return scnprintf(buf, PAGE_SIZE, "%d\n", !!sdebug_host_lock);
cbf67842 4846}
185dd232 4847/* N.B. sdebug_host_lock does nothing, kept for backward compatibility */
cbf67842
DG
4848static ssize_t host_lock_store(struct device_driver *ddp, const char *buf,
4849 size_t count)
4850{
185dd232 4851 int n;
cbf67842
DG
4852
4853 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
185dd232
DG
4854 sdebug_host_lock = (n > 0);
4855 return count;
cbf67842
DG
4856 }
4857 return -EINVAL;
4858}
4859static DRIVER_ATTR_RW(host_lock);
4860
c2248fc9
DG
4861static ssize_t strict_show(struct device_driver *ddp, char *buf)
4862{
773642d9 4863 return scnprintf(buf, PAGE_SIZE, "%d\n", !!sdebug_strict);
c2248fc9
DG
4864}
4865static ssize_t strict_store(struct device_driver *ddp, const char *buf,
4866 size_t count)
4867{
4868 int n;
4869
4870 if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
773642d9 4871 sdebug_strict = (n > 0);
c2248fc9
DG
4872 return count;
4873 }
4874 return -EINVAL;
4875}
4876static DRIVER_ATTR_RW(strict);
4877
09ba24c1
DG
4878static ssize_t uuid_ctl_show(struct device_driver *ddp, char *buf)
4879{
4880 return scnprintf(buf, PAGE_SIZE, "%d\n", !!sdebug_uuid_ctl);
4881}
4882static DRIVER_ATTR_RO(uuid_ctl);
4883
cbf67842 4884
82069379 4885/* Note: The following array creates attribute files in the
23183910
DG
4886 /sys/bus/pseudo/drivers/scsi_debug directory. The advantage of these
4887 files (over those found in the /sys/module/scsi_debug/parameters
4888 directory) is that auxiliary actions can be triggered when an attribute
4889 is changed. For example see: sdebug_add_host_store() above.
4890 */
6ecaff7f 4891
82069379
AM
4892static struct attribute *sdebug_drv_attrs[] = {
4893 &driver_attr_delay.attr,
4894 &driver_attr_opts.attr,
4895 &driver_attr_ptype.attr,
4896 &driver_attr_dsense.attr,
4897 &driver_attr_fake_rw.attr,
4898 &driver_attr_no_lun_0.attr,
4899 &driver_attr_num_tgts.attr,
4900 &driver_attr_dev_size_mb.attr,
4901 &driver_attr_num_parts.attr,
4902 &driver_attr_every_nth.attr,
4903 &driver_attr_max_luns.attr,
4904 &driver_attr_max_queue.attr,
4905 &driver_attr_no_uld.attr,
4906 &driver_attr_scsi_level.attr,
4907 &driver_attr_virtual_gb.attr,
4908 &driver_attr_add_host.attr,
4909 &driver_attr_vpd_use_hostno.attr,
4910 &driver_attr_sector_size.attr,
c4837394
DG
4911 &driver_attr_statistics.attr,
4912 &driver_attr_submit_queues.attr,
82069379
AM
4913 &driver_attr_dix.attr,
4914 &driver_attr_dif.attr,
4915 &driver_attr_guard.attr,
4916 &driver_attr_ato.attr,
4917 &driver_attr_map.attr,
4918 &driver_attr_removable.attr,
cbf67842
DG
4919 &driver_attr_host_lock.attr,
4920 &driver_attr_ndelay.attr,
c2248fc9 4921 &driver_attr_strict.attr,
09ba24c1 4922 &driver_attr_uuid_ctl.attr,
82069379
AM
4923 NULL,
4924};
4925ATTRIBUTE_GROUPS(sdebug_drv);
1da177e4 4926
11ddceca 4927static struct device *pseudo_primary;
8dea0d02 4928
1da177e4
LT
4929static int __init scsi_debug_init(void)
4930{
5f2578e5 4931 unsigned long sz;
1da177e4
LT
4932 int host_to_add;
4933 int k;
6ecaff7f 4934 int ret;
1da177e4 4935
cbf67842
DG
4936 atomic_set(&retired_max_queue, 0);
4937
773642d9 4938 if (sdebug_ndelay >= 1000 * 1000 * 1000) {
c1287970 4939 pr_warn("ndelay must be less than 1 second, ignored\n");
773642d9
DG
4940 sdebug_ndelay = 0;
4941 } else if (sdebug_ndelay > 0)
c2206098 4942 sdebug_jdelay = JDELAY_OVERRIDDEN;
cbf67842 4943
773642d9 4944 switch (sdebug_sector_size) {
597136ab
MP
4945 case 512:
4946 case 1024:
4947 case 2048:
4948 case 4096:
4949 break;
4950 default:
773642d9 4951 pr_err("invalid sector_size %d\n", sdebug_sector_size);
597136ab
MP
4952 return -EINVAL;
4953 }
4954
773642d9 4955 switch (sdebug_dif) {
8475c811 4956 case T10_PI_TYPE0_PROTECTION:
f46eb0e9 4957 break;
8475c811
CH
4958 case T10_PI_TYPE1_PROTECTION:
4959 case T10_PI_TYPE2_PROTECTION:
4960 case T10_PI_TYPE3_PROTECTION:
f46eb0e9 4961 have_dif_prot = true;
c6a44287
MP
4962 break;
4963
4964 default:
c1287970 4965 pr_err("dif must be 0, 1, 2 or 3\n");
c6a44287
MP
4966 return -EINVAL;
4967 }
4968
773642d9 4969 if (sdebug_guard > 1) {
c1287970 4970 pr_err("guard must be 0 or 1\n");
c6a44287
MP
4971 return -EINVAL;
4972 }
4973
773642d9 4974 if (sdebug_ato > 1) {
c1287970 4975 pr_err("ato must be 0 or 1\n");
c6a44287
MP
4976 return -EINVAL;
4977 }
4978
773642d9
DG
4979 if (sdebug_physblk_exp > 15) {
4980 pr_err("invalid physblk_exp %u\n", sdebug_physblk_exp);
ea61fca5
MP
4981 return -EINVAL;
4982 }
8d039e22
DG
4983 if (sdebug_max_luns > 256) {
4984 pr_warn("max_luns can be no more than 256, use default\n");
4985 sdebug_max_luns = DEF_MAX_LUNS;
4986 }
ea61fca5 4987
773642d9
DG
4988 if (sdebug_lowest_aligned > 0x3fff) {
4989 pr_err("lowest_aligned too big: %u\n", sdebug_lowest_aligned);
ea61fca5
MP
4990 return -EINVAL;
4991 }
4992
c4837394
DG
4993 if (submit_queues < 1) {
4994 pr_err("submit_queues must be 1 or more\n");
4995 return -EINVAL;
4996 }
4997 sdebug_q_arr = kcalloc(submit_queues, sizeof(struct sdebug_queue),
4998 GFP_KERNEL);
4999 if (sdebug_q_arr == NULL)
5000 return -ENOMEM;
5001 for (k = 0; k < submit_queues; ++k)
5002 spin_lock_init(&sdebug_q_arr[k].qc_lock);
5003
773642d9
DG
5004 if (sdebug_dev_size_mb < 1)
5005 sdebug_dev_size_mb = 1; /* force minimum 1 MB ramdisk */
5006 sz = (unsigned long)sdebug_dev_size_mb * 1048576;
5007 sdebug_store_sectors = sz / sdebug_sector_size;
28898873 5008 sdebug_capacity = get_sdebug_capacity();
1da177e4
LT
5009
5010 /* play around with geometry, don't waste too much on track 0 */
5011 sdebug_heads = 8;
5012 sdebug_sectors_per = 32;
773642d9 5013 if (sdebug_dev_size_mb >= 256)
1da177e4 5014 sdebug_heads = 64;
773642d9 5015 else if (sdebug_dev_size_mb >= 16)
fa785f0a 5016 sdebug_heads = 32;
1da177e4
LT
5017 sdebug_cylinders_per = (unsigned long)sdebug_capacity /
5018 (sdebug_sectors_per * sdebug_heads);
5019 if (sdebug_cylinders_per >= 1024) {
5020 /* other LLDs do this; implies >= 1GB ram disk ... */
5021 sdebug_heads = 255;
5022 sdebug_sectors_per = 63;
5023 sdebug_cylinders_per = (unsigned long)sdebug_capacity /
5024 (sdebug_sectors_per * sdebug_heads);
5025 }
5026
b01f6f83 5027 if (sdebug_fake_rw == 0) {
cbf67842
DG
5028 fake_storep = vmalloc(sz);
5029 if (NULL == fake_storep) {
c1287970 5030 pr_err("out of memory, 1\n");
c4837394
DG
5031 ret = -ENOMEM;
5032 goto free_q_arr;
cbf67842
DG
5033 }
5034 memset(fake_storep, 0, sz);
773642d9 5035 if (sdebug_num_parts > 0)
cbf67842 5036 sdebug_build_parts(fake_storep, sz);
1da177e4 5037 }
1da177e4 5038
773642d9 5039 if (sdebug_dix) {
c6a44287
MP
5040 int dif_size;
5041
6ebf105c 5042 dif_size = sdebug_store_sectors * sizeof(struct t10_pi_tuple);
c6a44287
MP
5043 dif_storep = vmalloc(dif_size);
5044
c1287970 5045 pr_err("dif_storep %u bytes @ %p\n", dif_size, dif_storep);
c6a44287
MP
5046
5047 if (dif_storep == NULL) {
c1287970 5048 pr_err("out of mem. (DIX)\n");
c6a44287
MP
5049 ret = -ENOMEM;
5050 goto free_vm;
5051 }
5052
5053 memset(dif_storep, 0xff, dif_size);
5054 }
5055
5b94e232
MP
5056 /* Logical Block Provisioning */
5057 if (scsi_debug_lbp()) {
773642d9
DG
5058 sdebug_unmap_max_blocks =
5059 clamp(sdebug_unmap_max_blocks, 0U, 0xffffffffU);
6014759c 5060
773642d9
DG
5061 sdebug_unmap_max_desc =
5062 clamp(sdebug_unmap_max_desc, 0U, 256U);
6014759c 5063
773642d9
DG
5064 sdebug_unmap_granularity =
5065 clamp(sdebug_unmap_granularity, 1U, 0xffffffffU);
6014759c 5066
773642d9
DG
5067 if (sdebug_unmap_alignment &&
5068 sdebug_unmap_granularity <=
5069 sdebug_unmap_alignment) {
c1287970 5070 pr_err("ERR: unmap_granularity <= unmap_alignment\n");
c4837394
DG
5071 ret = -EINVAL;
5072 goto free_vm;
44d92694
MP
5073 }
5074
b90ebc3d
AM
5075 map_size = lba_to_map_index(sdebug_store_sectors - 1) + 1;
5076 map_storep = vmalloc(BITS_TO_LONGS(map_size) * sizeof(long));
44d92694 5077
c1287970 5078 pr_info("%lu provisioning blocks\n", map_size);
44d92694
MP
5079
5080 if (map_storep == NULL) {
c1287970 5081 pr_err("out of mem. (MAP)\n");
44d92694
MP
5082 ret = -ENOMEM;
5083 goto free_vm;
5084 }
5085
b90ebc3d 5086 bitmap_zero(map_storep, map_size);
44d92694
MP
5087
5088 /* Map first 1KB for partition table */
773642d9 5089 if (sdebug_num_parts)
44d92694
MP
5090 map_region(0, 2);
5091 }
5092
9b906779
NB
5093 pseudo_primary = root_device_register("pseudo_0");
5094 if (IS_ERR(pseudo_primary)) {
c1287970 5095 pr_warn("root_device_register() error\n");
9b906779 5096 ret = PTR_ERR(pseudo_primary);
6ecaff7f
RD
5097 goto free_vm;
5098 }
5099 ret = bus_register(&pseudo_lld_bus);
5100 if (ret < 0) {
c1287970 5101 pr_warn("bus_register error: %d\n", ret);
6ecaff7f
RD
5102 goto dev_unreg;
5103 }
5104 ret = driver_register(&sdebug_driverfs_driver);
5105 if (ret < 0) {
c1287970 5106 pr_warn("driver_register error: %d\n", ret);
6ecaff7f
RD
5107 goto bus_unreg;
5108 }
1da177e4 5109
773642d9
DG
5110 host_to_add = sdebug_add_host;
5111 sdebug_add_host = 0;
1da177e4
LT
5112
5113 for (k = 0; k < host_to_add; k++) {
5114 if (sdebug_add_adapter()) {
c1287970 5115 pr_err("sdebug_add_adapter failed k=%d\n", k);
1da177e4
LT
5116 break;
5117 }
5118 }
5119
773642d9
DG
5120 if (sdebug_verbose)
5121 pr_info("built %d host(s)\n", sdebug_add_host);
c1287970 5122
1da177e4 5123 return 0;
6ecaff7f 5124
6ecaff7f
RD
5125bus_unreg:
5126 bus_unregister(&pseudo_lld_bus);
5127dev_unreg:
9b906779 5128 root_device_unregister(pseudo_primary);
6ecaff7f 5129free_vm:
de232af6
TW
5130 vfree(map_storep);
5131 vfree(dif_storep);
6ecaff7f 5132 vfree(fake_storep);
c4837394
DG
5133free_q_arr:
5134 kfree(sdebug_q_arr);
6ecaff7f 5135 return ret;
1da177e4
LT
5136}
5137
5138static void __exit scsi_debug_exit(void)
5139{
773642d9 5140 int k = sdebug_add_host;
1da177e4
LT
5141
5142 stop_all_queued();
cbf67842 5143 free_all_queued();
1da177e4
LT
5144 for (; k; k--)
5145 sdebug_remove_adapter();
1da177e4
LT
5146 driver_unregister(&sdebug_driverfs_driver);
5147 bus_unregister(&pseudo_lld_bus);
9b906779 5148 root_device_unregister(pseudo_primary);
1da177e4 5149
4d2b496f 5150 vfree(map_storep);
de232af6 5151 vfree(dif_storep);
1da177e4 5152 vfree(fake_storep);
c4837394 5153 kfree(sdebug_q_arr);
1da177e4
LT
5154}
5155
5156device_initcall(scsi_debug_init);
5157module_exit(scsi_debug_exit);
5158
1da177e4
LT
5159static void sdebug_release_adapter(struct device * dev)
5160{
5161 struct sdebug_host_info *sdbg_host;
5162
5163 sdbg_host = to_sdebug_host(dev);
5164 kfree(sdbg_host);
5165}
5166
5167static int sdebug_add_adapter(void)
5168{
5169 int k, devs_per_host;
5170 int error = 0;
5171 struct sdebug_host_info *sdbg_host;
8b40228f 5172 struct sdebug_dev_info *sdbg_devinfo, *tmp;
1da177e4 5173
c65b1445 5174 sdbg_host = kzalloc(sizeof(*sdbg_host),GFP_KERNEL);
1da177e4 5175 if (NULL == sdbg_host) {
c1287970 5176 pr_err("out of memory at line %d\n", __LINE__);
1da177e4
LT
5177 return -ENOMEM;
5178 }
5179
1da177e4
LT
5180 INIT_LIST_HEAD(&sdbg_host->dev_info_list);
5181
773642d9 5182 devs_per_host = sdebug_num_tgts * sdebug_max_luns;
1da177e4 5183 for (k = 0; k < devs_per_host; k++) {
5cb2fc06
FT
5184 sdbg_devinfo = sdebug_device_create(sdbg_host, GFP_KERNEL);
5185 if (!sdbg_devinfo) {
c1287970 5186 pr_err("out of memory at line %d\n", __LINE__);
1da177e4
LT
5187 error = -ENOMEM;
5188 goto clean;
5189 }
1da177e4
LT
5190 }
5191
5192 spin_lock(&sdebug_host_list_lock);
5193 list_add_tail(&sdbg_host->host_list, &sdebug_host_list);
5194 spin_unlock(&sdebug_host_list_lock);
5195
5196 sdbg_host->dev.bus = &pseudo_lld_bus;
9b906779 5197 sdbg_host->dev.parent = pseudo_primary;
1da177e4 5198 sdbg_host->dev.release = &sdebug_release_adapter;
773642d9 5199 dev_set_name(&sdbg_host->dev, "adapter%d", sdebug_add_host);
1da177e4
LT
5200
5201 error = device_register(&sdbg_host->dev);
5202
5203 if (error)
5204 goto clean;
5205
773642d9 5206 ++sdebug_add_host;
1da177e4
LT
5207 return error;
5208
5209clean:
8b40228f
FT
5210 list_for_each_entry_safe(sdbg_devinfo, tmp, &sdbg_host->dev_info_list,
5211 dev_list) {
1da177e4
LT
5212 list_del(&sdbg_devinfo->dev_list);
5213 kfree(sdbg_devinfo);
5214 }
5215
5216 kfree(sdbg_host);
5217 return error;
5218}
5219
5220static void sdebug_remove_adapter(void)
5221{
5222 struct sdebug_host_info * sdbg_host = NULL;
5223
5224 spin_lock(&sdebug_host_list_lock);
5225 if (!list_empty(&sdebug_host_list)) {
5226 sdbg_host = list_entry(sdebug_host_list.prev,
5227 struct sdebug_host_info, host_list);
5228 list_del(&sdbg_host->host_list);
5229 }
5230 spin_unlock(&sdebug_host_list_lock);
5231
5232 if (!sdbg_host)
5233 return;
5234
773642d9
DG
5235 device_unregister(&sdbg_host->dev);
5236 --sdebug_add_host;
1da177e4
LT
5237}
5238
fd32119b 5239static int sdebug_change_qdepth(struct scsi_device *sdev, int qdepth)
cbf67842
DG
5240{
5241 int num_in_q = 0;
cbf67842
DG
5242 struct sdebug_dev_info *devip;
5243
c4837394 5244 block_unblock_all_queues(true);
cbf67842
DG
5245 devip = (struct sdebug_dev_info *)sdev->hostdata;
5246 if (NULL == devip) {
c4837394 5247 block_unblock_all_queues(false);
cbf67842
DG
5248 return -ENODEV;
5249 }
5250 num_in_q = atomic_read(&devip->num_in_q);
c40ecc12
CH
5251
5252 if (qdepth < 1)
5253 qdepth = 1;
c4837394
DG
5254 /* allow to exceed max host qc_arr elements for testing */
5255 if (qdepth > SDEBUG_CANQUEUE + 10)
5256 qdepth = SDEBUG_CANQUEUE + 10;
db5ed4df 5257 scsi_change_queue_depth(sdev, qdepth);
c40ecc12 5258
773642d9 5259 if (SDEBUG_OPT_Q_NOISE & sdebug_opts) {
c4837394 5260 sdev_printk(KERN_INFO, sdev, "%s: qdepth=%d, num_in_q=%d\n",
c40ecc12 5261 __func__, qdepth, num_in_q);
cbf67842 5262 }
c4837394 5263 block_unblock_all_queues(false);
cbf67842
DG
5264 return sdev->queue_depth;
5265}
5266
c4837394 5267static bool fake_timeout(struct scsi_cmnd *scp)
817fd66b 5268{
c4837394 5269 if (0 == (atomic_read(&sdebug_cmnd_count) % abs(sdebug_every_nth))) {
773642d9
DG
5270 if (sdebug_every_nth < -1)
5271 sdebug_every_nth = -1;
5272 if (SDEBUG_OPT_TIMEOUT & sdebug_opts)
c4837394 5273 return true; /* ignore command causing timeout */
773642d9 5274 else if (SDEBUG_OPT_MAC_TIMEOUT & sdebug_opts &&
817fd66b 5275 scsi_medium_access_command(scp))
c4837394 5276 return true; /* time out reads and writes */
817fd66b 5277 }
c4837394 5278 return false;
817fd66b
DG
5279}
5280
fd32119b
DG
5281static int scsi_debug_queuecommand(struct Scsi_Host *shost,
5282 struct scsi_cmnd *scp)
c2248fc9
DG
5283{
5284 u8 sdeb_i;
5285 struct scsi_device *sdp = scp->device;
5286 const struct opcode_info_t *oip;
5287 const struct opcode_info_t *r_oip;
5288 struct sdebug_dev_info *devip;
5289 u8 *cmd = scp->cmnd;
5290 int (*r_pfp)(struct scsi_cmnd *, struct sdebug_dev_info *);
5291 int k, na;
5292 int errsts = 0;
c2248fc9
DG
5293 u32 flags;
5294 u16 sa;
5295 u8 opcode = cmd[0];
5296 bool has_wlun_rl;
c2248fc9
DG
5297
5298 scsi_set_resid(scp, 0);
c4837394
DG
5299 if (sdebug_statistics)
5300 atomic_inc(&sdebug_cmnd_count);
f46eb0e9
DG
5301 if (unlikely(sdebug_verbose &&
5302 !(SDEBUG_OPT_NO_CDB_NOISE & sdebug_opts))) {
c2248fc9
DG
5303 char b[120];
5304 int n, len, sb;
5305
5306 len = scp->cmd_len;
5307 sb = (int)sizeof(b);
5308 if (len > 32)
5309 strcpy(b, "too long, over 32 bytes");
5310 else {
5311 for (k = 0, n = 0; k < len && n < sb; ++k)
5312 n += scnprintf(b + n, sb - n, "%02x ",
5313 (u32)cmd[k]);
5314 }
c4837394
DG
5315 if (sdebug_mq_active)
5316 sdev_printk(KERN_INFO, sdp, "%s: tag=%u, cmd %s\n",
5317 my_name, blk_mq_unique_tag(scp->request),
5318 b);
5319 else
5320 sdev_printk(KERN_INFO, sdp, "%s: cmd %s\n", my_name,
5321 b);
c2248fc9 5322 }
34d55434 5323 has_wlun_rl = (sdp->lun == SCSI_W_LUN_REPORT_LUNS);
f46eb0e9
DG
5324 if (unlikely((sdp->lun >= sdebug_max_luns) && !has_wlun_rl))
5325 goto err_out;
c2248fc9
DG
5326
5327 sdeb_i = opcode_ind_arr[opcode]; /* fully mapped */
5328 oip = &opcode_info_arr[sdeb_i]; /* safe if table consistent */
5329 devip = (struct sdebug_dev_info *)sdp->hostdata;
f46eb0e9
DG
5330 if (unlikely(!devip)) {
5331 devip = find_build_dev_info(sdp);
c2248fc9 5332 if (NULL == devip)
f46eb0e9 5333 goto err_out;
c2248fc9
DG
5334 }
5335 na = oip->num_attached;
5336 r_pfp = oip->pfp;
5337 if (na) { /* multiple commands with this opcode */
5338 r_oip = oip;
5339 if (FF_SA & r_oip->flags) {
5340 if (F_SA_LOW & oip->flags)
5341 sa = 0x1f & cmd[1];
5342 else
5343 sa = get_unaligned_be16(cmd + 8);
5344 for (k = 0; k <= na; oip = r_oip->arrp + k++) {
5345 if (opcode == oip->opcode && sa == oip->sa)
5346 break;
5347 }
5348 } else { /* since no service action only check opcode */
5349 for (k = 0; k <= na; oip = r_oip->arrp + k++) {
5350 if (opcode == oip->opcode)
5351 break;
5352 }
5353 }
5354 if (k > na) {
5355 if (F_SA_LOW & r_oip->flags)
5356 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, 4);
5357 else if (F_SA_HIGH & r_oip->flags)
5358 mk_sense_invalid_fld(scp, SDEB_IN_CDB, 8, 7);
5359 else
5360 mk_sense_invalid_opcode(scp);
5361 goto check_cond;
5362 }
5363 } /* else (when na==0) we assume the oip is a match */
5364 flags = oip->flags;
f46eb0e9 5365 if (unlikely(F_INV_OP & flags)) {
c2248fc9
DG
5366 mk_sense_invalid_opcode(scp);
5367 goto check_cond;
5368 }
f46eb0e9 5369 if (unlikely(has_wlun_rl && !(F_RL_WLUN_OK & flags))) {
773642d9
DG
5370 if (sdebug_verbose)
5371 sdev_printk(KERN_INFO, sdp, "%s: Opcode 0x%x not%s\n",
5372 my_name, opcode, " supported for wlun");
c2248fc9
DG
5373 mk_sense_invalid_opcode(scp);
5374 goto check_cond;
5375 }
f46eb0e9 5376 if (unlikely(sdebug_strict)) { /* check cdb against mask */
c2248fc9
DG
5377 u8 rem;
5378 int j;
5379
5380 for (k = 1; k < oip->len_mask[0] && k < 16; ++k) {
5381 rem = ~oip->len_mask[k] & cmd[k];
5382 if (rem) {
5383 for (j = 7; j >= 0; --j, rem <<= 1) {
5384 if (0x80 & rem)
5385 break;
5386 }
5387 mk_sense_invalid_fld(scp, SDEB_IN_CDB, k, j);
5388 goto check_cond;
5389 }
5390 }
5391 }
f46eb0e9 5392 if (unlikely(!(F_SKIP_UA & flags) &&
b01f6f83
DG
5393 find_first_bit(devip->uas_bm,
5394 SDEBUG_NUM_UAS) != SDEBUG_NUM_UAS)) {
f46eb0e9 5395 errsts = make_ua(scp, devip);
c2248fc9
DG
5396 if (errsts)
5397 goto check_cond;
5398 }
c4837394 5399 if (unlikely((F_M_ACCESS & flags) && atomic_read(&devip->stopped))) {
c2248fc9 5400 mk_sense_buffer(scp, NOT_READY, LOGICAL_UNIT_NOT_READY, 0x2);
773642d9 5401 if (sdebug_verbose)
c2248fc9
DG
5402 sdev_printk(KERN_INFO, sdp, "%s reports: Not ready: "
5403 "%s\n", my_name, "initializing command "
5404 "required");
5405 errsts = check_condition_result;
5406 goto fini;
5407 }
773642d9 5408 if (sdebug_fake_rw && (F_FAKE_RW & flags))
c2248fc9 5409 goto fini;
f46eb0e9 5410 if (unlikely(sdebug_every_nth)) {
c4837394 5411 if (fake_timeout(scp))
c2248fc9
DG
5412 return 0; /* ignore command: make trouble */
5413 }
f46eb0e9
DG
5414 if (likely(oip->pfp))
5415 errsts = oip->pfp(scp, devip); /* calls a resp_* function */
c2248fc9
DG
5416 else if (r_pfp) /* if leaf function ptr NULL, try the root's */
5417 errsts = r_pfp(scp, devip);
5418
5419fini:
5420 return schedule_resp(scp, devip, errsts,
c2206098 5421 ((F_DELAY_OVERR & flags) ? 0 : sdebug_jdelay));
c2248fc9
DG
5422check_cond:
5423 return schedule_resp(scp, devip, check_condition_result, 0);
f46eb0e9
DG
5424err_out:
5425 return schedule_resp(scp, NULL, DID_NO_CONNECT << 16, 0);
c2248fc9
DG
5426}
5427
9e603ca0 5428static struct scsi_host_template sdebug_driver_template = {
c8ed555a
AV
5429 .show_info = scsi_debug_show_info,
5430 .write_info = scsi_debug_write_info,
9e603ca0
FT
5431 .proc_name = sdebug_proc_name,
5432 .name = "SCSI DEBUG",
5433 .info = scsi_debug_info,
5434 .slave_alloc = scsi_debug_slave_alloc,
5435 .slave_configure = scsi_debug_slave_configure,
5436 .slave_destroy = scsi_debug_slave_destroy,
5437 .ioctl = scsi_debug_ioctl,
185dd232 5438 .queuecommand = scsi_debug_queuecommand,
cbf67842 5439 .change_queue_depth = sdebug_change_qdepth,
9e603ca0 5440 .eh_abort_handler = scsi_debug_abort,
9e603ca0 5441 .eh_device_reset_handler = scsi_debug_device_reset,
cbf67842
DG
5442 .eh_target_reset_handler = scsi_debug_target_reset,
5443 .eh_bus_reset_handler = scsi_debug_bus_reset,
9e603ca0 5444 .eh_host_reset_handler = scsi_debug_host_reset,
c4837394 5445 .can_queue = SDEBUG_CANQUEUE,
9e603ca0 5446 .this_id = 7,
65e8617f 5447 .sg_tablesize = SG_MAX_SEGMENTS,
cbf67842 5448 .cmd_per_lun = DEF_CMD_PER_LUN,
6bb5e6e7 5449 .max_sectors = -1U,
9e603ca0
FT
5450 .use_clustering = DISABLE_CLUSTERING,
5451 .module = THIS_MODULE,
c40ecc12 5452 .track_queue_depth = 1,
9e603ca0
FT
5453};
5454
1da177e4
LT
5455static int sdebug_driver_probe(struct device * dev)
5456{
22017ed2
DG
5457 int error = 0;
5458 struct sdebug_host_info *sdbg_host;
5459 struct Scsi_Host *hpnt;
f46eb0e9 5460 int hprot;
1da177e4
LT
5461
5462 sdbg_host = to_sdebug_host(dev);
5463
773642d9
DG
5464 sdebug_driver_template.can_queue = sdebug_max_queue;
5465 if (sdebug_clustering)
0759c666 5466 sdebug_driver_template.use_clustering = ENABLE_CLUSTERING;
78d4e5a0
DG
5467 hpnt = scsi_host_alloc(&sdebug_driver_template, sizeof(sdbg_host));
5468 if (NULL == hpnt) {
c1287970 5469 pr_err("scsi_host_alloc failed\n");
78d4e5a0 5470 error = -ENODEV;
1da177e4 5471 return error;
78d4e5a0 5472 }
c4837394 5473 if (submit_queues > nr_cpu_ids) {
9b130ad5 5474 pr_warn("%s: trim submit_queues (was %d) to nr_cpu_ids=%u\n",
c4837394
DG
5475 my_name, submit_queues, nr_cpu_ids);
5476 submit_queues = nr_cpu_ids;
5477 }
5478 /* Decide whether to tell scsi subsystem that we want mq */
5479 /* Following should give the same answer for each host */
5480 sdebug_mq_active = shost_use_blk_mq(hpnt) && (submit_queues > 1);
5481 if (sdebug_mq_active)
5482 hpnt->nr_hw_queues = submit_queues;
1da177e4
LT
5483
5484 sdbg_host->shost = hpnt;
5485 *((struct sdebug_host_info **)hpnt->hostdata) = sdbg_host;
773642d9
DG
5486 if ((hpnt->this_id >= 0) && (sdebug_num_tgts > hpnt->this_id))
5487 hpnt->max_id = sdebug_num_tgts + 1;
1da177e4 5488 else
773642d9
DG
5489 hpnt->max_id = sdebug_num_tgts;
5490 /* = sdebug_max_luns; */
f2d3fd29 5491 hpnt->max_lun = SCSI_W_LUN_REPORT_LUNS + 1;
1da177e4 5492
f46eb0e9 5493 hprot = 0;
c6a44287 5494
773642d9 5495 switch (sdebug_dif) {
c6a44287 5496
8475c811 5497 case T10_PI_TYPE1_PROTECTION:
f46eb0e9 5498 hprot = SHOST_DIF_TYPE1_PROTECTION;
773642d9 5499 if (sdebug_dix)
f46eb0e9 5500 hprot |= SHOST_DIX_TYPE1_PROTECTION;
c6a44287
MP
5501 break;
5502
8475c811 5503 case T10_PI_TYPE2_PROTECTION:
f46eb0e9 5504 hprot = SHOST_DIF_TYPE2_PROTECTION;
773642d9 5505 if (sdebug_dix)
f46eb0e9 5506 hprot |= SHOST_DIX_TYPE2_PROTECTION;
c6a44287
MP
5507 break;
5508
8475c811 5509 case T10_PI_TYPE3_PROTECTION:
f46eb0e9 5510 hprot = SHOST_DIF_TYPE3_PROTECTION;
773642d9 5511 if (sdebug_dix)
f46eb0e9 5512 hprot |= SHOST_DIX_TYPE3_PROTECTION;
c6a44287
MP
5513 break;
5514
5515 default:
773642d9 5516 if (sdebug_dix)
f46eb0e9 5517 hprot |= SHOST_DIX_TYPE0_PROTECTION;
c6a44287
MP
5518 break;
5519 }
5520
f46eb0e9 5521 scsi_host_set_prot(hpnt, hprot);
c6a44287 5522
f46eb0e9
DG
5523 if (have_dif_prot || sdebug_dix)
5524 pr_info("host protection%s%s%s%s%s%s%s\n",
5525 (hprot & SHOST_DIF_TYPE1_PROTECTION) ? " DIF1" : "",
5526 (hprot & SHOST_DIF_TYPE2_PROTECTION) ? " DIF2" : "",
5527 (hprot & SHOST_DIF_TYPE3_PROTECTION) ? " DIF3" : "",
5528 (hprot & SHOST_DIX_TYPE0_PROTECTION) ? " DIX0" : "",
5529 (hprot & SHOST_DIX_TYPE1_PROTECTION) ? " DIX1" : "",
5530 (hprot & SHOST_DIX_TYPE2_PROTECTION) ? " DIX2" : "",
5531 (hprot & SHOST_DIX_TYPE3_PROTECTION) ? " DIX3" : "");
c6a44287 5532
773642d9 5533 if (sdebug_guard == 1)
c6a44287
MP
5534 scsi_host_set_guard(hpnt, SHOST_DIX_GUARD_IP);
5535 else
5536 scsi_host_set_guard(hpnt, SHOST_DIX_GUARD_CRC);
5537
773642d9
DG
5538 sdebug_verbose = !!(SDEBUG_OPT_NOISE & sdebug_opts);
5539 sdebug_any_injecting_opt = !!(SDEBUG_OPT_ALL_INJECTING & sdebug_opts);
c4837394
DG
5540 if (sdebug_every_nth) /* need stats counters for every_nth */
5541 sdebug_statistics = true;
1da177e4
LT
5542 error = scsi_add_host(hpnt, &sdbg_host->dev);
5543 if (error) {
c1287970 5544 pr_err("scsi_add_host failed\n");
1da177e4
LT
5545 error = -ENODEV;
5546 scsi_host_put(hpnt);
5547 } else
5548 scsi_scan_host(hpnt);
5549
cbf67842 5550 return error;
1da177e4
LT
5551}
5552
5553static int sdebug_driver_remove(struct device * dev)
5554{
1da177e4 5555 struct sdebug_host_info *sdbg_host;
8b40228f 5556 struct sdebug_dev_info *sdbg_devinfo, *tmp;
1da177e4
LT
5557
5558 sdbg_host = to_sdebug_host(dev);
5559
5560 if (!sdbg_host) {
c1287970 5561 pr_err("Unable to locate host info\n");
1da177e4
LT
5562 return -ENODEV;
5563 }
5564
5565 scsi_remove_host(sdbg_host->shost);
5566
8b40228f
FT
5567 list_for_each_entry_safe(sdbg_devinfo, tmp, &sdbg_host->dev_info_list,
5568 dev_list) {
1da177e4
LT
5569 list_del(&sdbg_devinfo->dev_list);
5570 kfree(sdbg_devinfo);
5571 }
5572
5573 scsi_host_put(sdbg_host->shost);
5574 return 0;
5575}
5576
8dea0d02
FT
5577static int pseudo_lld_bus_match(struct device *dev,
5578 struct device_driver *dev_driver)
1da177e4 5579{
8dea0d02 5580 return 1;
1da177e4 5581}
8dea0d02
FT
5582
5583static struct bus_type pseudo_lld_bus = {
5584 .name = "pseudo",
5585 .match = pseudo_lld_bus_match,
5586 .probe = sdebug_driver_probe,
5587 .remove = sdebug_driver_remove,
82069379 5588 .drv_groups = sdebug_drv_groups,
8dea0d02 5589};