scsi_target.c revision 109345
139215Sgibbs/*
2107178Snjl * SCSI Disk Emulator
339215Sgibbs *
4107178Snjl * Copyright (c) 2002 Nate Lawson.
539215Sgibbs * All rights reserved.
639215Sgibbs *
739215Sgibbs * Redistribution and use in source and binary forms, with or without
839215Sgibbs * modification, are permitted provided that the following conditions
939215Sgibbs * are met:
1039215Sgibbs * 1. Redistributions of source code must retain the above copyright
1139215Sgibbs *    notice, this list of conditions, and the following disclaimer,
1239215Sgibbs *    without modification, immediately at the beginning of the file.
1339215Sgibbs * 2. The name of the author may not be used to endorse or promote products
1439215Sgibbs *    derived from this software without specific prior written permission.
1539215Sgibbs *
1639215Sgibbs * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
1739215Sgibbs * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
1839215Sgibbs * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
1939215Sgibbs * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR
2039215Sgibbs * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
2139215Sgibbs * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
2239215Sgibbs * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
2339215Sgibbs * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
2439215Sgibbs * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
2539215Sgibbs * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
2639215Sgibbs * SUCH DAMAGE.
2739215Sgibbs *
2850476Speter * $FreeBSD: head/share/examples/scsi_target/scsi_target.c 109345 2003-01-16 00:24:29Z njl $
2939215Sgibbs */
3039215Sgibbs
3139215Sgibbs#include <sys/types.h>
3244498Sgibbs#include <errno.h>
33107178Snjl#include <err.h>
3439215Sgibbs#include <fcntl.h>
3544498Sgibbs#include <signal.h>
3639215Sgibbs#include <stddef.h>
3739215Sgibbs#include <stdio.h>
3839215Sgibbs#include <stdlib.h>
39107178Snjl#include <string.h>
4039215Sgibbs#include <sysexits.h>
4139215Sgibbs#include <unistd.h>
42107178Snjl#include <aio.h>
43109161Snjl#include <assert.h>
44107178Snjl#include <sys/stat.h>
45107178Snjl#include <sys/queue.h>
46107178Snjl#include <sys/event.h>
47107178Snjl#include <sys/param.h>
48107178Snjl#include <cam/cam_queue.h>
4939215Sgibbs#include <cam/scsi/scsi_all.h>
50107178Snjl#include <cam/scsi/scsi_targetio.h>
5139215Sgibbs#include <cam/scsi/scsi_message.h>
52107178Snjl#include "scsi_target.h"
5339215Sgibbs
54107178Snjl/* Maximum amount to transfer per CTIO */
55107178Snjl#define MAX_XFER	MAXPHYS
56107178Snjl/* Maximum number of allocated CTIOs */
57107178Snjl#define MAX_CTIOS	32
58107178Snjl/* Maximum sector size for emulated volume */
59107178Snjl#define MAX_SECTOR	32768
60107178Snjl
61107178Snjl/* Global variables */
62107178Snjlint		debug;
63107178Snjlu_int32_t	volume_size;
64107178Snjlsize_t		sector_size;
65107178Snjlsize_t		buf_size;
66107178Snjl
67107178Snjl/* Local variables */
68107178Snjlstatic int    targ_fd;
69107178Snjlstatic int    kq_fd;
70107178Snjlstatic int    file_fd;
71107178Snjlstatic int    num_ctios;
72107178Snjlstatic struct ccb_queue		pending_queue;
73107178Snjlstatic struct ccb_queue		work_queue;
74107178Snjlstatic struct ioc_enable_lun	ioc_enlun = {
7544498Sgibbs	CAM_BUS_WILDCARD,
7644498Sgibbs	CAM_TARGET_WILDCARD,
7744498Sgibbs	CAM_LUN_WILDCARD
7844498Sgibbs};
7939215Sgibbs
80107178Snjl/* Local functions */
81107178Snjlstatic void		cleanup(void);
82107178Snjlstatic int		init_ccbs(void);
83107178Snjlstatic void		request_loop(void);
84107178Snjlstatic void		handle_read(void);
85107178Snjl/* static int		work_atio(struct ccb_accept_tio *); */
86107178Snjlstatic void		queue_io(struct ccb_scsiio *);
87107178Snjlstatic void		run_queue(struct ccb_accept_tio *);
88107178Snjlstatic int		work_inot(struct ccb_immed_notify *);
89107178Snjlstatic struct ccb_scsiio *
90107178Snjl			get_ctio(void);
91107178Snjl/* static void		free_ccb(union ccb *); */
92107178Snjlstatic cam_status	get_sim_flags(u_int16_t *);
93107178Snjlstatic void		rel_simq(void);
94107178Snjlstatic void		abort_all_pending(void);
95107178Snjlstatic void		usage(void);
9639215Sgibbs
9739215Sgibbsint
9839215Sgibbsmain(int argc, char *argv[])
9939215Sgibbs{
100107178Snjl	int ch, unit;
101107178Snjl	char *file_name, targname[16];
102107178Snjl	u_int16_t req_flags, sim_flags;
103107178Snjl	off_t user_size;
10439215Sgibbs
105107178Snjl	/* Initialize */
106107178Snjl	debug = 0;
107107178Snjl	req_flags = sim_flags = 0;
108107178Snjl	user_size = 0;
109107178Snjl	targ_fd = file_fd = kq_fd = -1;
110107178Snjl	num_ctios = 0;
111107178Snjl	sector_size = SECTOR_SIZE;
112107178Snjl	buf_size = DFLTPHYS;
113107178Snjl
114107178Snjl	/* Prepare resource pools */
115107178Snjl	TAILQ_INIT(&pending_queue);
116107178Snjl	TAILQ_INIT(&work_queue);
117107178Snjl
118107178Snjl	while ((ch = getopt(argc, argv, "AdSTb:c:s:W:")) != -1) {
11939215Sgibbs		switch(ch) {
120107178Snjl		case 'A':
121107178Snjl			req_flags |= SID_Addr16;
12239215Sgibbs			break;
123107178Snjl		case 'd':
124107178Snjl			debug = 1;
12539215Sgibbs			break;
126107178Snjl		case 'S':
127107178Snjl			req_flags |= SID_Sync;
12844498Sgibbs			break;
129107178Snjl		case 'T':
130107178Snjl			req_flags |= SID_CmdQue;
13144498Sgibbs			break;
132107178Snjl		case 'b':
133107178Snjl			buf_size = atoi(optarg);
134107178Snjl			if (buf_size < 256 || buf_size > MAX_XFER)
135107178Snjl				errx(1, "Unreasonable buf size: %s", optarg);
13644498Sgibbs			break;
137107178Snjl		case 'c':
138107178Snjl			sector_size = atoi(optarg);
139107178Snjl			if (sector_size < 512 || sector_size > MAX_SECTOR)
140107178Snjl				errx(1, "Unreasonable sector size: %s", optarg);
14163185Smjacob			break;
142107178Snjl		case 's':
143107178Snjl			user_size = strtoll(optarg, (char **)NULL, /*base*/10);
144107178Snjl			if (user_size < 0)
145107178Snjl				errx(1, "Unreasonable volume size: %s", optarg);
146107178Snjl			break;
147107178Snjl		case 'W':
148107178Snjl			req_flags &= ~(SID_WBus16 | SID_WBus32);
149107178Snjl			switch (atoi(optarg)) {
150107178Snjl			case 8:
151107178Snjl				/* Leave req_flags zeroed */
152107178Snjl				break;
153107178Snjl			case 16:
154107178Snjl				req_flags |= SID_WBus16;
155107178Snjl				break;
156107178Snjl			case 32:
157107178Snjl				req_flags |= SID_WBus32;
158107178Snjl				break;
159107178Snjl			default:
160107178Snjl				warnx("Width %s not supported", optarg);
161107178Snjl				usage();
162107178Snjl				/* NOTREACHED */
163107178Snjl			}
164107178Snjl			break;
16539215Sgibbs		default:
16639215Sgibbs			usage();
16739215Sgibbs			/* NOTREACHED */
16839215Sgibbs		}
16939215Sgibbs	}
17039215Sgibbs	argc -= optind;
17139215Sgibbs	argv += optind;
172107178Snjl
173107178Snjl	if (argc != 2)
17439215Sgibbs		usage();
17539215Sgibbs
176107178Snjl	sscanf(argv[0], "%u:%u:%u", &ioc_enlun.path_id, &ioc_enlun.target_id,
177107178Snjl	       &ioc_enlun.lun_id);
178107178Snjl	file_name = argv[1];
179107178Snjl
180107178Snjl	if (ioc_enlun.path_id == CAM_BUS_WILDCARD ||
181107178Snjl	    ioc_enlun.target_id == CAM_TARGET_WILDCARD ||
182107178Snjl	    ioc_enlun.lun_id == CAM_LUN_WILDCARD) {
183107178Snjl		warnx("Incomplete target path specified");
18444498Sgibbs		usage();
18544498Sgibbs		/* NOTREACHED */
18644498Sgibbs	}
187107178Snjl	/* We don't support any vendor-specific commands */
188107178Snjl	ioc_enlun.grp6_len = 0;
189107178Snjl	ioc_enlun.grp7_len = 0;
19044498Sgibbs
191107178Snjl	/* Open backing store for IO */
192107178Snjl	file_fd = open(file_name, O_RDWR);
193107178Snjl	if (file_fd < 0)
194107178Snjl		err(1, "open backing store file");
19544498Sgibbs
196107178Snjl	/* Check backing store size or use the size user gave us */
197107178Snjl	if (user_size == 0) {
198107178Snjl		struct stat st;
199107178Snjl
200107178Snjl		if (fstat(file_fd, &st) < 0)
201107178Snjl			err(1, "fstat file");
202107178Snjl		volume_size = st.st_size / sector_size;
203107178Snjl	} else {
204107178Snjl		volume_size = user_size / sector_size;
20544498Sgibbs	}
206107178Snjl	if (volume_size <= 0)
207107178Snjl		errx(1, "volume must be larger than %d", sector_size);
20844498Sgibbs
209109161Snjl	{
210109161Snjl		struct aiocb aio, *aiop;
211109161Snjl
212109161Snjl		/* Make sure we have working AIO support */
213109161Snjl		memset(&aio, 0, sizeof(aio));
214109161Snjl		aio.aio_buf = malloc(sector_size);
215109161Snjl		if (aio.aio_buf == NULL)
216109161Snjl			err(1, "malloc");
217109161Snjl		aio.aio_fildes = file_fd;
218109161Snjl		aio.aio_offset = 0;
219109161Snjl		aio.aio_nbytes = sector_size;
220109161Snjl		signal(SIGSYS, SIG_IGN);
221109161Snjl		if (aio_read(&aio) != 0) {
222109161Snjl			printf("You must enable VFS_AIO in your kernel "
223109161Snjl			       "or load the aio(4) module.\n");
224109161Snjl			err(1, "aio_read");
225109161Snjl		}
226109161Snjl		if (aio_waitcomplete(&aiop, NULL) != sector_size)
227109161Snjl			err(1, "aio_waitcomplete");
228109161Snjl		assert(aiop == &aio);
229109161Snjl		signal(SIGSYS, SIG_DFL);
230109161Snjl		free((void *)aio.aio_buf);
231109161Snjl		if (debug)
232109161Snjl			warnx("aio support tested ok");
233109161Snjl	}
234109161Snjl
235107178Snjl	/* Go through all the control devices and find one that isn't busy. */
236107178Snjl	unit = 0;
237107178Snjl	do {
238107178Snjl		snprintf(targname, sizeof(targname), "/dev/targ%d", unit++);
239107178Snjl    		targ_fd = open(targname, O_RDWR);
240107178Snjl	} while (targ_fd < 0 && errno == EBUSY);
24144498Sgibbs
242107178Snjl	if (targ_fd < 0)
243107178Snjl    	    err(1, "Tried to open %d devices, none available", unit);
24463185Smjacob
245107178Snjl	/* The first three are handled by kevent() later */
246107178Snjl	signal(SIGHUP, SIG_IGN);
247107178Snjl	signal(SIGINT, SIG_IGN);
248107178Snjl	signal(SIGTERM, SIG_IGN);
249107178Snjl	signal(SIGPROF, SIG_IGN);
250107178Snjl	signal(SIGALRM, SIG_IGN);
251107178Snjl	signal(SIGSTOP, SIG_IGN);
252107178Snjl	signal(SIGTSTP, SIG_IGN);
25339215Sgibbs
254107178Snjl	/* Register a cleanup handler to run when exiting */
255107178Snjl	atexit(cleanup);
256107178Snjl
257107178Snjl	/* Enable listening on the specified LUN */
258107178Snjl	if (ioctl(targ_fd, TARGIOCENABLE, &ioc_enlun) != 0)
259107178Snjl		err(1, "TARGIOCENABLE");
260107178Snjl
261107178Snjl	/* Enable debugging if requested */
262107178Snjl	if (debug) {
263107178Snjl		if (ioctl(targ_fd, TARGIOCDEBUG, &debug) != 0)
264107178Snjl			err(1, "TARGIOCDEBUG");
26539215Sgibbs	}
26639215Sgibbs
267107178Snjl	/* Set up inquiry data according to what SIM supports */
268107178Snjl	if (get_sim_flags(&sim_flags) != CAM_REQ_CMP)
269107178Snjl		errx(1, "get_sim_flags");
270107178Snjl	if (tcmd_init(req_flags, sim_flags) != 0)
271107178Snjl		errx(1, "Initializing tcmd subsystem failed");
27244498Sgibbs
273107178Snjl	/* Queue ATIOs and INOTs on descriptor */
274107178Snjl	if (init_ccbs() != 0)
275107178Snjl		errx(1, "init_ccbs failed");
27649935Sgibbs
277107178Snjl	if (debug)
278107178Snjl		warnx("main loop beginning");
279107178Snjl	request_loop();
28039215Sgibbs
281107178Snjl	exit(0);
28249935Sgibbs}
28349935Sgibbs
28449935Sgibbsstatic void
28549935Sgibbscleanup()
28649935Sgibbs{
287107178Snjl	struct ccb_hdr *ccb_h;
288107178Snjl
28963290Smjacob	if (debug) {
290107178Snjl		warnx("cleanup called");
29163290Smjacob		debug = 0;
292107178Snjl		ioctl(targ_fd, TARGIOCDEBUG, &debug);
29363290Smjacob	}
294107178Snjl	ioctl(targ_fd, TARGIOCDISABLE, NULL);
295107178Snjl	close(targ_fd);
296107178Snjl
297107178Snjl	while ((ccb_h = TAILQ_FIRST(&pending_queue)) != NULL) {
298107178Snjl		TAILQ_REMOVE(&pending_queue, ccb_h, periph_links.tqe);
299107178Snjl		free_ccb((union ccb *)ccb_h);
30044498Sgibbs	}
301107178Snjl	while ((ccb_h = TAILQ_FIRST(&work_queue)) != NULL) {
302107178Snjl		TAILQ_REMOVE(&work_queue, ccb_h, periph_links.tqe);
303107178Snjl		free_ccb((union ccb *)ccb_h);
304107178Snjl	}
305107178Snjl
306107178Snjl	if (kq_fd != -1)
307107178Snjl		close(kq_fd);
30839215Sgibbs}
30939215Sgibbs
310107178Snjl/* Allocate ATIOs/INOTs and queue on HBA */
311107178Snjlstatic int
312107178Snjlinit_ccbs()
313107178Snjl{
314107178Snjl	int i;
315107178Snjl
316107178Snjl	for (i = 0; i < MAX_INITIATORS; i++) {
317107178Snjl		struct ccb_accept_tio *atio;
318107178Snjl		struct atio_descr *a_descr;
319107178Snjl		struct ccb_immed_notify *inot;
320107178Snjl
321107178Snjl		atio = (struct ccb_accept_tio *)malloc(sizeof(*atio));
322107178Snjl		if (atio == NULL) {
323107178Snjl			warn("malloc ATIO");
324107178Snjl			return (-1);
325107178Snjl		}
326107178Snjl		a_descr = (struct atio_descr *)malloc(sizeof(*a_descr));
327107178Snjl		if (a_descr == NULL) {
328107178Snjl			free(atio);
329107178Snjl			warn("malloc atio_descr");
330107178Snjl			return (-1);
331107178Snjl		}
332107178Snjl		atio->ccb_h.func_code = XPT_ACCEPT_TARGET_IO;
333107178Snjl		atio->ccb_h.targ_descr = a_descr;
334107178Snjl		send_ccb((union ccb *)atio, /*priority*/1);
335107178Snjl
336107178Snjl		inot = (struct ccb_immed_notify *)malloc(sizeof(*inot));
337107178Snjl		if (inot == NULL) {
338107178Snjl			warn("malloc INOT");
339107178Snjl			return (-1);
340107178Snjl		}
341107178Snjl		inot->ccb_h.func_code = XPT_IMMED_NOTIFY;
342107178Snjl		send_ccb((union ccb *)inot, /*priority*/1);
343107178Snjl	}
344107178Snjl
345107178Snjl	return (0);
346107178Snjl}
347107178Snjl
34839215Sgibbsstatic void
349107178Snjlrequest_loop()
35039215Sgibbs{
351107178Snjl	struct kevent events[MAX_EVENTS];
352107178Snjl	struct timespec ts, *tptr;
353107178Snjl	int quit;
35439215Sgibbs
355107178Snjl	/* Register kqueue for event notification */
356107178Snjl	if ((kq_fd = kqueue()) < 0)
357107178Snjl		err(1, "init kqueue");
35839215Sgibbs
359107178Snjl	/* Set up some default events */
360107178Snjl	EV_SET(&events[0], SIGHUP, EVFILT_SIGNAL, EV_ADD|EV_ENABLE, 0, 0, 0);
361107178Snjl	EV_SET(&events[1], SIGINT, EVFILT_SIGNAL, EV_ADD|EV_ENABLE, 0, 0, 0);
362107178Snjl	EV_SET(&events[2], SIGTERM, EVFILT_SIGNAL, EV_ADD|EV_ENABLE, 0, 0, 0);
363107178Snjl	EV_SET(&events[3], targ_fd, EVFILT_READ, EV_ADD|EV_ENABLE, 0, 0, 0);
364107178Snjl	if (kevent(kq_fd, events, 4, NULL, 0, NULL) < 0)
365107178Snjl		err(1, "kevent signal registration");
366107178Snjl
367107178Snjl	ts.tv_sec = 0;
368107178Snjl	ts.tv_nsec = 0;
369107178Snjl	tptr = NULL;
370107178Snjl	quit = 0;
371107178Snjl
372107178Snjl	/* Loop until user signal */
37344498Sgibbs	while (quit == 0) {
374107178Snjl		int retval, i;
375107178Snjl		struct ccb_hdr *ccb_h;
37639215Sgibbs
377107178Snjl		/* Check for the next signal, read ready, or AIO completion */
378107178Snjl		retval = kevent(kq_fd, NULL, 0, events, MAX_EVENTS, tptr);
379107178Snjl		if (retval < 0) {
380107178Snjl			if (errno == EINTR) {
381107178Snjl				if (debug)
382107178Snjl					warnx("EINTR, looping");
38344498Sgibbs				continue;
384107178Snjl            		}
385107178Snjl			else {
386107178Snjl				err(1, "kevent failed");
387107178Snjl			}
388107178Snjl		} else if (retval > MAX_EVENTS) {
389107178Snjl			errx(1, "kevent returned more events than allocated?");
39039215Sgibbs		}
39139215Sgibbs
392107178Snjl		/* Process all received events. */
393107178Snjl		for (i = 0; i < retval; i++) {
394107178Snjl			if ((events[i].flags & EV_ERROR) != 0)
395107178Snjl				errx(1, "kevent registration failed");
39639215Sgibbs
397107178Snjl			switch (events[i].filter) {
398107178Snjl			case EVFILT_READ:
399107178Snjl				if (debug)
400107178Snjl					warnx("read ready");
401107178Snjl				handle_read();
402107178Snjl				break;
403107178Snjl			case EVFILT_AIO:
404107178Snjl			{
405107178Snjl				struct ccb_scsiio *ctio;
406107178Snjl				struct ctio_descr *c_descr;
407107178Snjl				if (debug)
408107178Snjl					warnx("aio ready");
40939215Sgibbs
410107178Snjl				ctio = (struct ccb_scsiio *)events[i].udata;
411107178Snjl				c_descr = (struct ctio_descr *)
412107178Snjl					  ctio->ccb_h.targ_descr;
413107178Snjl				c_descr->event = AIO_DONE;
414107178Snjl				/* Queue on the appropriate ATIO */
415107178Snjl				queue_io(ctio);
416107178Snjl				/* Process any queued completions. */
417107178Snjl				run_queue(c_descr->atio);
418107178Snjl				break;
419107178Snjl			}
420107178Snjl			case EVFILT_SIGNAL:
421107178Snjl				if (debug)
422107178Snjl					warnx("signal ready, setting quit");
423107178Snjl				quit = 1;
424107178Snjl				break;
425107178Snjl			default:
426107178Snjl				warnx("unknown event %#x", events[i].filter);
427107178Snjl				break;
428107178Snjl			}
429107178Snjl
430107178Snjl			if (debug)
431107178Snjl				warnx("event done");
43239215Sgibbs		}
43339215Sgibbs
434107178Snjl		/* Grab the first CCB and perform one work unit. */
435107178Snjl		if ((ccb_h = TAILQ_FIRST(&work_queue)) != NULL) {
436107178Snjl			union ccb *ccb;
43739215Sgibbs
438107178Snjl			ccb = (union ccb *)ccb_h;
439107178Snjl			switch (ccb_h->func_code) {
440107178Snjl			case XPT_ACCEPT_TARGET_IO:
441107178Snjl				/* Start one more transfer. */
442107178Snjl				retval = work_atio(&ccb->atio);
443107178Snjl				break;
444107178Snjl			case XPT_IMMED_NOTIFY:
445107178Snjl				retval = work_inot(&ccb->cin);
446107178Snjl				break;
447107178Snjl			default:
448107178Snjl				warnx("Unhandled ccb type %#x on workq",
449107178Snjl				      ccb_h->func_code);
450107178Snjl				abort();
451107178Snjl				/* NOTREACHED */
45239215Sgibbs			}
45339215Sgibbs
454107178Snjl			/* Assume work function handled the exception */
455107178Snjl			if ((ccb_h->status & CAM_DEV_QFRZN) != 0) {
456109345Snjl				if (debug) {
457109345Snjl					warnx("Queue frozen receiving CCB, "
458109345Snjl					      "releasing");
459109345Snjl				}
460107178Snjl				rel_simq();
46139215Sgibbs			}
46239215Sgibbs
463107178Snjl			/* No more work needed for this command. */
464107178Snjl			if (retval == 0) {
465107178Snjl				TAILQ_REMOVE(&work_queue, ccb_h,
466107178Snjl					     periph_links.tqe);
46739215Sgibbs			}
468107178Snjl		}
46939215Sgibbs
470107178Snjl		/*
471107178Snjl		 * Poll for new events (i.e. completions) while we
472107178Snjl		 * are processing CCBs on the work_queue. Once it's
473107178Snjl		 * empty, use an infinite wait.
474107178Snjl		 */
475107178Snjl		if (!TAILQ_EMPTY(&work_queue))
476107178Snjl			tptr = &ts;
477107178Snjl		else
478107178Snjl			tptr = NULL;
47939215Sgibbs	}
48039215Sgibbs}
48139215Sgibbs
482107178Snjl/* CCBs are ready from the kernel */
48339215Sgibbsstatic void
484107178Snjlhandle_read()
48539215Sgibbs{
486107178Snjl	union ccb *ccb_array[MAX_INITIATORS], *ccb;
487107178Snjl	int ccb_count, i;
48839215Sgibbs
489107178Snjl	ccb_count = read(targ_fd, ccb_array, sizeof(ccb_array));
490107178Snjl	if (ccb_count <= 0) {
491107178Snjl		warn("read ccb ptrs");
492107178Snjl		return;
49339215Sgibbs	}
494107178Snjl	ccb_count /= sizeof(union ccb *);
495107178Snjl	if (ccb_count < 1) {
496107178Snjl		warnx("truncated read ccb ptr?");
497107178Snjl		return;
498107178Snjl	}
49939215Sgibbs
500107178Snjl	for (i = 0; i < ccb_count; i++) {
501107178Snjl		ccb = ccb_array[i];
502107178Snjl		TAILQ_REMOVE(&pending_queue, &ccb->ccb_h, periph_links.tqe);
503107178Snjl
504107178Snjl		switch (ccb->ccb_h.func_code) {
505107178Snjl		case XPT_ACCEPT_TARGET_IO:
506107178Snjl		{
507107178Snjl			struct ccb_accept_tio *atio;
508107178Snjl			struct atio_descr *a_descr;
509107178Snjl
510107178Snjl			/* Initialize ATIO descr for this transaction */
511107178Snjl			atio = &ccb->atio;
512107178Snjl			a_descr = (struct atio_descr *)atio->ccb_h.targ_descr;
513107178Snjl			bzero(a_descr, sizeof(*a_descr));
514107178Snjl			TAILQ_INIT(&a_descr->cmplt_io);
515107178Snjl			a_descr->flags = atio->ccb_h.flags &
516107178Snjl				(CAM_DIS_DISCONNECT | CAM_TAG_ACTION_VALID);
517107178Snjl			/* XXX add a_descr->priority */
518107178Snjl			if ((atio->ccb_h.flags & CAM_CDB_POINTER) == 0)
519107178Snjl				a_descr->cdb = atio->cdb_io.cdb_bytes;
520107178Snjl			else
521107178Snjl				a_descr->cdb = atio->cdb_io.cdb_ptr;
522107178Snjl
523107178Snjl			/* ATIOs are processed in FIFO order */
524107178Snjl			TAILQ_INSERT_TAIL(&work_queue, &ccb->ccb_h,
525107178Snjl					  periph_links.tqe);
526107178Snjl			break;
527107178Snjl		}
528107178Snjl		case XPT_CONT_TARGET_IO:
529107178Snjl		{
530107178Snjl			struct ccb_scsiio *ctio;
531107178Snjl			struct ctio_descr *c_descr;
532107178Snjl
533107178Snjl			ctio = &ccb->ctio;
534107178Snjl			c_descr = (struct ctio_descr *)ctio->ccb_h.targ_descr;
535107178Snjl			c_descr->event = CTIO_DONE;
536107178Snjl			/* Queue on the appropriate ATIO */
537107178Snjl			queue_io(ctio);
538107178Snjl			/* Process any queued completions. */
539107178Snjl			run_queue(c_descr->atio);
540107178Snjl			break;
541107178Snjl		}
542107178Snjl		case XPT_IMMED_NOTIFY:
543107178Snjl			/* INOTs are handled with priority */
544107178Snjl			TAILQ_INSERT_HEAD(&work_queue, &ccb->ccb_h,
545107178Snjl					  periph_links.tqe);
546107178Snjl			break;
547107178Snjl		default:
548107178Snjl			warnx("Unhandled ccb type %#x in handle_read",
549107178Snjl			      ccb->ccb_h.func_code);
550107178Snjl			break;
551107178Snjl		}
55239215Sgibbs	}
553107178Snjl}
55439215Sgibbs
555107178Snjl/* Process an ATIO CCB from the kernel */
556107178Snjlint
557107178Snjlwork_atio(struct ccb_accept_tio *atio)
558107178Snjl{
559107178Snjl	struct ccb_scsiio *ctio;
560107178Snjl	struct atio_descr *a_descr;
561107178Snjl	struct ctio_descr *c_descr;
562107178Snjl	cam_status status;
563107178Snjl	int ret;
564107178Snjl
565107178Snjl	if (debug)
566107178Snjl		warnx("Working on ATIO %p", atio);
567107178Snjl
568107178Snjl	a_descr = (struct atio_descr *)atio->ccb_h.targ_descr;
569107178Snjl
570107178Snjl	/* Get a CTIO and initialize it according to our known parameters */
571107178Snjl	ctio = get_ctio();
572107178Snjl	if (ctio == NULL)
573107178Snjl		return (1);
574107178Snjl	ret = 0;
575107178Snjl	ctio->ccb_h.flags = a_descr->flags;
576107178Snjl	ctio->tag_id = atio->tag_id;
577107178Snjl	ctio->init_id = atio->init_id;
578107178Snjl	/* XXX priority needs to be added to a_descr */
579107178Snjl	c_descr = (struct ctio_descr *)ctio->ccb_h.targ_descr;
580107178Snjl	c_descr->atio = atio;
581107178Snjl	if ((a_descr->flags & CAM_DIR_IN) != 0)
582107178Snjl		c_descr->offset = a_descr->base_off + a_descr->targ_req;
583107178Snjl	else if ((a_descr->flags & CAM_DIR_MASK) == CAM_DIR_OUT)
584107178Snjl		c_descr->offset = a_descr->base_off + a_descr->init_req;
585107178Snjl
586107178Snjl	/*
587107178Snjl	 * Return a check condition if there was an error while
588107178Snjl	 * receiving this ATIO.
589107178Snjl	 */
590107178Snjl	if (atio->sense_len != 0) {
59139215Sgibbs		struct scsi_sense_data *sense;
59239215Sgibbs
593107178Snjl		if (debug) {
594107178Snjl			warnx("ATIO with %u bytes sense received",
595107178Snjl			      atio->sense_len);
59639215Sgibbs		}
597107178Snjl		sense = &atio->sense_data;
598107178Snjl		tcmd_sense(ctio->init_id, ctio, sense->flags,
599107178Snjl			   sense->add_sense_code, sense->add_sense_code_qual);
600107178Snjl		send_ccb((union ccb *)ctio, /*priority*/1);
601107178Snjl		return (0);
602107178Snjl	}
60339215Sgibbs
604107178Snjl	status = atio->ccb_h.status & CAM_STATUS_MASK;
605107178Snjl	switch (status) {
606107178Snjl	case CAM_CDB_RECVD:
607107178Snjl		ret = tcmd_handle(atio, ctio, ATIO_WORK);
608107178Snjl		break;
609107178Snjl	case CAM_REQ_ABORTED:
610107178Snjl		/* Requeue on HBA */
611107178Snjl		TAILQ_REMOVE(&work_queue, &atio->ccb_h, periph_links.tqe);
612107178Snjl		send_ccb((union ccb *)atio, /*priority*/1);
613107178Snjl		ret = 1;
614107178Snjl		break;
615107178Snjl	default:
616107178Snjl		warnx("ATIO completed with unhandled status %#x", status);
617107178Snjl		abort();
618107178Snjl		/* NOTREACHED */
619107178Snjl		break;
620107178Snjl	}
62139215Sgibbs
622107178Snjl	return (ret);
623107178Snjl}
62439215Sgibbs
625107178Snjlstatic void
626107178Snjlqueue_io(struct ccb_scsiio *ctio)
627107178Snjl{
628107178Snjl	struct ccb_hdr *ccb_h;
629107178Snjl	struct io_queue *ioq;
630107178Snjl	struct ctio_descr *c_descr, *curr_descr;
631107178Snjl
632107178Snjl	c_descr = (struct ctio_descr *)ctio->ccb_h.targ_descr;
633107178Snjl	/* If the completion is for a specific ATIO, queue in order */
634107178Snjl	if (c_descr->atio != NULL) {
635107178Snjl		struct atio_descr *a_descr;
63639215Sgibbs
637107178Snjl		a_descr = (struct atio_descr *)c_descr->atio->ccb_h.targ_descr;
638107178Snjl		ioq = &a_descr->cmplt_io;
639107178Snjl	} else {
640107178Snjl		errx(1, "CTIO %p has NULL ATIO", ctio);
641107178Snjl	}
642107178Snjl
643107178Snjl	/* Insert in order, sorted by offset */
644107178Snjl	if (!TAILQ_EMPTY(ioq)) {
645107178Snjl		TAILQ_FOREACH_REVERSE(ccb_h, ioq, io_queue, periph_links.tqe) {
646107178Snjl			curr_descr = (struct ctio_descr *)ccb_h->targ_descr;
647107178Snjl			if (curr_descr->offset <= c_descr->offset) {
648107178Snjl				TAILQ_INSERT_AFTER(ioq, ccb_h, &ctio->ccb_h,
649107178Snjl						   periph_links.tqe);
650107178Snjl				break;
651107178Snjl			}
652107178Snjl			if (TAILQ_PREV(ccb_h, io_queue, periph_links.tqe)
653107178Snjl			    == NULL) {
654107178Snjl				TAILQ_INSERT_BEFORE(ccb_h, &ctio->ccb_h,
655107178Snjl						    periph_links.tqe);
656107178Snjl				break;
657107178Snjl			}
65839215Sgibbs		}
659107178Snjl	} else {
660107178Snjl		TAILQ_INSERT_HEAD(ioq, &ctio->ccb_h, periph_links.tqe);
661107178Snjl	}
662107178Snjl}
66339215Sgibbs
664107178Snjl/*
665107178Snjl * Go through all completed AIO/CTIOs for a given ATIO and advance data
666107178Snjl * counts, start continuation IO, etc.
667107178Snjl */
668107178Snjlstatic void
669107178Snjlrun_queue(struct ccb_accept_tio *atio)
670107178Snjl{
671107178Snjl	struct atio_descr *a_descr;
672107178Snjl	struct ccb_hdr *ccb_h;
673107178Snjl	int sent_status, event;
674107178Snjl
675107178Snjl	if (atio == NULL)
676107178Snjl		return;
677107178Snjl
678107178Snjl	a_descr = (struct atio_descr *)atio->ccb_h.targ_descr;
679107178Snjl
680107178Snjl	while ((ccb_h = TAILQ_FIRST(&a_descr->cmplt_io)) != NULL) {
681107178Snjl		struct ccb_scsiio *ctio;
682107178Snjl		struct ctio_descr *c_descr;
683107178Snjl
684107178Snjl		ctio = (struct ccb_scsiio *)ccb_h;
685107178Snjl		c_descr = (struct ctio_descr *)ctio->ccb_h.targ_descr;
686107178Snjl
687107178Snjl		/* If completed item is in range, call handler */
688107178Snjl		if ((c_descr->event == AIO_DONE &&
689107178Snjl		    c_descr->offset == a_descr->base_off + a_descr->targ_ack)
690107178Snjl		 || (c_descr->event == CTIO_DONE &&
691107178Snjl		    c_descr->offset == a_descr->base_off + a_descr->init_ack)) {
692107178Snjl			sent_status = (ccb_h->flags & CAM_SEND_STATUS) != 0;
693107178Snjl			event = c_descr->event;
694107178Snjl
695107178Snjl			TAILQ_REMOVE(&a_descr->cmplt_io, ccb_h,
696107178Snjl				     periph_links.tqe);
697107178Snjl			tcmd_handle(atio, ctio, c_descr->event);
698107178Snjl
699107178Snjl			/* If entire transfer complete, send back ATIO */
700107178Snjl			if (sent_status != 0 && event == CTIO_DONE)
701107178Snjl				send_ccb((union ccb *)atio, /*priority*/1);
702107178Snjl		} else {
703107178Snjl			/* Gap in offsets so wait until later callback */
704107178Snjl			if (debug)
705107178Snjl				warnx("IO %p out of order", ccb_h);
706107178Snjl			break;
70763185Smjacob		}
708107178Snjl	}
709107178Snjl}
71063185Smjacob
711107178Snjlstatic int
712107178Snjlwork_inot(struct ccb_immed_notify *inot)
713107178Snjl{
714107178Snjl	cam_status status;
715107178Snjl	int sense;
71663185Smjacob
717107178Snjl	if (debug)
718107178Snjl		warnx("Working on INOT %p", inot);
719107178Snjl
720107178Snjl	status = inot->ccb_h.status;
721107178Snjl	sense = (status & CAM_AUTOSNS_VALID) != 0;
722107178Snjl	status &= CAM_STATUS_MASK;
723107178Snjl
724107178Snjl	switch (status) {
725107178Snjl	case CAM_SCSI_BUS_RESET:
726107178Snjl		tcmd_ua(CAM_TARGET_WILDCARD, UA_BUS_RESET);
727107178Snjl		abort_all_pending();
728107178Snjl		break;
729107178Snjl	case CAM_BDR_SENT:
730107178Snjl		tcmd_ua(CAM_TARGET_WILDCARD, UA_BDR);
731107178Snjl		abort_all_pending();
732107178Snjl		break;
733107178Snjl	case CAM_MESSAGE_RECV:
734107178Snjl		switch (inot->message_args[0]) {
735107178Snjl		case MSG_TASK_COMPLETE:
736107178Snjl		case MSG_INITIATOR_DET_ERR:
737107178Snjl		case MSG_ABORT_TASK_SET:
738107178Snjl		case MSG_MESSAGE_REJECT:
739107178Snjl		case MSG_NOOP:
740107178Snjl		case MSG_PARITY_ERROR:
741107178Snjl		case MSG_TARGET_RESET:
742107178Snjl		case MSG_ABORT_TASK:
743107178Snjl		case MSG_CLEAR_TASK_SET:
744107178Snjl		default:
745107178Snjl			warnx("INOT message %#x", inot->message_args[0]);
746107178Snjl			break;
74739215Sgibbs		}
748107178Snjl		break;
749107178Snjl	case CAM_REQ_ABORTED:
750107178Snjl		warnx("INOT %p aborted", inot);
751107178Snjl		break;
752107178Snjl	default:
753107178Snjl		warnx("Unhandled INOT status %#x", status);
754107178Snjl		break;
75539215Sgibbs	}
75639215Sgibbs
757107178Snjl	/* If there is sense data, use it */
758107178Snjl	if (sense != 0) {
759107178Snjl		struct scsi_sense_data *sense;
760107178Snjl
761107178Snjl		sense = &inot->sense_data;
762107178Snjl		tcmd_sense(inot->initiator_id, NULL, sense->flags,
763107178Snjl			   sense->add_sense_code, sense->add_sense_code_qual);
764107178Snjl		if (debug)
765107178Snjl			warnx("INOT has sense: %#x", sense->flags);
766107178Snjl	}
767107178Snjl
768107178Snjl	/* Requeue on SIM */
769107178Snjl	TAILQ_REMOVE(&work_queue, &inot->ccb_h, periph_links.tqe);
770107178Snjl	send_ccb((union ccb *)inot, /*priority*/1);
771107178Snjl
772107178Snjl	return (1);
77339215Sgibbs}
77439215Sgibbs
775107178Snjlvoid
776107178Snjlsend_ccb(union ccb *ccb, int priority)
777107178Snjl{
778107178Snjl	if (debug)
779107178Snjl		warnx("sending ccb (%#x)", ccb->ccb_h.func_code);
780107178Snjl	ccb->ccb_h.pinfo.priority = priority;
781107178Snjl	if (XPT_FC_IS_QUEUED(ccb)) {
782107178Snjl		TAILQ_INSERT_TAIL(&pending_queue, &ccb->ccb_h,
783107178Snjl				  periph_links.tqe);
784107178Snjl	}
785107178Snjl	if (write(targ_fd, &ccb, sizeof(ccb)) != sizeof(ccb)) {
786107178Snjl		warn("write ccb");
787107178Snjl		ccb->ccb_h.status = CAM_PROVIDE_FAIL;
788107178Snjl	}
789107178Snjl}
790107178Snjl
791107178Snjl/* Return a CTIO/descr/buf combo from the freelist or malloc one */
792107178Snjlstatic struct ccb_scsiio *
793107178Snjlget_ctio()
794107178Snjl{
795107178Snjl	struct ccb_scsiio *ctio;
796107178Snjl	struct ctio_descr *c_descr;
797107178Snjl	struct sigevent *se;
798107178Snjl
799107178Snjl	if (num_ctios == MAX_CTIOS)
800107178Snjl		return (NULL);
801107178Snjl
802107178Snjl	ctio = (struct ccb_scsiio *)malloc(sizeof(*ctio));
803107178Snjl	if (ctio == NULL) {
804107178Snjl		warn("malloc CTIO");
805107178Snjl		return (NULL);
806107178Snjl	}
807107178Snjl	c_descr = (struct ctio_descr *)malloc(sizeof(*c_descr));
808107178Snjl	if (c_descr == NULL) {
809107178Snjl		free(ctio);
810107178Snjl		warn("malloc ctio_descr");
811107178Snjl		return (NULL);
812107178Snjl	}
813107178Snjl	c_descr->buf = malloc(buf_size);
814107178Snjl	if (c_descr->buf == NULL) {
815107178Snjl		free(c_descr);
816107178Snjl		free(ctio);
817107178Snjl		warn("malloc backing store");
818107178Snjl		return (NULL);
819107178Snjl	}
820107178Snjl	num_ctios++;
821107178Snjl
822107178Snjl	/* Initialize CTIO, CTIO descr, and AIO */
823107178Snjl	ctio->ccb_h.func_code = XPT_CONT_TARGET_IO;
824107178Snjl	ctio->ccb_h.retry_count = 2;
825109345Snjl	ctio->ccb_h.timeout = CAM_TIME_INFINITY;
826107178Snjl	ctio->data_ptr = c_descr->buf;
827107178Snjl	ctio->ccb_h.targ_descr = c_descr;
828107178Snjl	c_descr->aiocb.aio_buf = c_descr->buf;
829107178Snjl	c_descr->aiocb.aio_fildes = file_fd;
830107178Snjl	se = &c_descr->aiocb.aio_sigevent;
831107178Snjl	se->sigev_notify = SIGEV_KEVENT;
832107178Snjl	se->sigev_notify_kqueue = kq_fd;
833107178Snjl	se->sigev_value.sigval_ptr = ctio;
834107178Snjl
835107178Snjl	return (ctio);
836107178Snjl}
837107178Snjl
838107178Snjlvoid
839107178Snjlfree_ccb(union ccb *ccb)
840107178Snjl{
841107178Snjl	switch (ccb->ccb_h.func_code) {
842107178Snjl	case XPT_CONT_TARGET_IO:
843107178Snjl	{
844107178Snjl		struct ctio_descr *c_descr;
845107178Snjl
846107178Snjl		c_descr = (struct ctio_descr *)ccb->ccb_h.targ_descr;
847107178Snjl		free(c_descr->buf);
848107178Snjl		num_ctios--;
849107178Snjl		/* FALLTHROUGH */
850107178Snjl	}
851107178Snjl	case XPT_ACCEPT_TARGET_IO:
852107178Snjl		free(ccb->ccb_h.targ_descr);
853107178Snjl		/* FALLTHROUGH */
854107178Snjl	case XPT_IMMED_NOTIFY:
855107178Snjl	default:
856107178Snjl		free(ccb);
857107178Snjl		break;
858107178Snjl	}
859107178Snjl}
860107178Snjl
861107178Snjlstatic cam_status
862107178Snjlget_sim_flags(u_int16_t *flags)
863107178Snjl{
864107178Snjl	struct ccb_pathinq cpi;
865107178Snjl	cam_status status;
866107178Snjl
867107178Snjl	/* Find SIM capabilities */
868107178Snjl	bzero(&cpi, sizeof(cpi));
869107178Snjl	cpi.ccb_h.func_code = XPT_PATH_INQ;
870107178Snjl	send_ccb((union ccb *)&cpi, /*priority*/1);
871107178Snjl	status = cpi.ccb_h.status & CAM_STATUS_MASK;
872107178Snjl	if (status != CAM_REQ_CMP) {
873107178Snjl		fprintf(stderr, "CPI failed, status %#x\n", status);
874107178Snjl		return (status);
875107178Snjl	}
876107178Snjl
877107178Snjl	/* Can only enable on controllers that support target mode */
878107178Snjl	if ((cpi.target_sprt & PIT_PROCESSOR) == 0) {
879107178Snjl		fprintf(stderr, "HBA does not support target mode\n");
880107178Snjl		status = CAM_PATH_INVALID;
881107178Snjl		return (status);
882107178Snjl	}
883107178Snjl
884107178Snjl	*flags = cpi.hba_inquiry;
885107178Snjl	return (status);
886107178Snjl}
887107178Snjl
88839215Sgibbsstatic void
889107178Snjlrel_simq()
89044498Sgibbs{
891107178Snjl	struct ccb_relsim crs;
892107178Snjl
893107178Snjl	bzero(&crs, sizeof(crs));
894107178Snjl	crs.ccb_h.func_code = XPT_REL_SIMQ;
895107178Snjl	crs.release_flags = RELSIM_RELEASE_AFTER_QEMPTY;
896107178Snjl	crs.openings = 0;
897107178Snjl	crs.release_timeout = 0;
898107178Snjl	crs.qfrozen_cnt = 0;
899107178Snjl	send_ccb((union ccb *)&crs, /*priority*/0);
90044498Sgibbs}
90144498Sgibbs
902107178Snjl/* Cancel all pending CCBs. */
90344498Sgibbsstatic void
904107178Snjlabort_all_pending()
90539215Sgibbs{
906107178Snjl	struct ccb_abort	 cab;
907107178Snjl	struct ccb_hdr		*ccb_h;
90839215Sgibbs
909107178Snjl	if (debug)
910107178Snjl		  warnx("abort_all_pending");
91139215Sgibbs
912107178Snjl	bzero(&cab, sizeof(cab));
913107178Snjl	cab.ccb_h.func_code = XPT_ABORT;
914107178Snjl	TAILQ_FOREACH(ccb_h, &pending_queue, periph_links.tqe) {
915107178Snjl		if (debug)
916107178Snjl			  warnx("Aborting pending CCB %p\n", ccb_h);
917107178Snjl		cab.abort_ccb = (union ccb *)ccb_h;
918107178Snjl		send_ccb((union ccb *)&cab, /*priority*/1);
919107178Snjl		if (cab.ccb_h.status != CAM_REQ_CMP) {
920107178Snjl			warnx("Unable to abort CCB, status %#x\n",
921107178Snjl			       cab.ccb_h.status);
922107178Snjl		}
923107178Snjl	}
92439215Sgibbs}
92539215Sgibbs
926107178Snjlstatic void
927107178Snjlusage()
928107178Snjl{
929107178Snjl	fprintf(stderr,
930107178Snjl		"Usage: scsi_target [-AdST] [-b bufsize] [-c sectorsize]\n"
931107178Snjl		"\t\t[-r numbufs] [-s volsize] [-W 8,16,32]\n"
932107178Snjl		"\t\tbus:target:lun filename\n");
933107178Snjl	exit(1);
934107178Snjl}
935