scsi_debug.c 163.0 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8
/*
 * vvvvvvvvvvvvvvvvvvvvvvv Original vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
 *  Copyright (C) 1992  Eric Youngdale
 *  Simulate a host adapter with 2 disks attached.  Do a lot of checking
 *  to make sure that we are not getting blocks mixed up, and PANIC if
 *  anything out of the ordinary is seen.
 * ^^^^^^^^^^^^^^^^^^^^^^^ Original ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
 *
9
 * Copyright (C) 2001 - 2016 Douglas Gilbert
L
Linus Torvalds 已提交
10
 *
11 12 13 14
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2, or (at your option)
 * any later version.
L
Linus Torvalds 已提交
15
 *
16
 *  For documentation see http://sg.danny.cz/sg/sdebug26.html
L
Linus Torvalds 已提交
17 18 19
 *
 */

20 21 22

#define pr_fmt(fmt) KBUILD_MODNAME ":%s: " fmt, __func__

L
Linus Torvalds 已提交
23 24 25 26
#include <linux/module.h>

#include <linux/kernel.h>
#include <linux/errno.h>
27
#include <linux/jiffies.h>
28
#include <linux/slab.h>
L
Linus Torvalds 已提交
29 30 31 32 33 34 35 36
#include <linux/types.h>
#include <linux/string.h>
#include <linux/genhd.h>
#include <linux/fs.h>
#include <linux/init.h>
#include <linux/proc_fs.h>
#include <linux/vmalloc.h>
#include <linux/moduleparam.h>
J
Jens Axboe 已提交
37
#include <linux/scatterlist.h>
L
Linus Torvalds 已提交
38
#include <linux/blkdev.h>
39
#include <linux/crc-t10dif.h>
40 41 42 43
#include <linux/spinlock.h>
#include <linux/interrupt.h>
#include <linux/atomic.h>
#include <linux/hrtimer.h>
D
Douglas Gilbert 已提交
44
#include <linux/uuid.h>
45
#include <linux/t10-pi.h>
46 47

#include <net/checksum.h>
48

49 50
#include <asm/unaligned.h>

51 52 53
#include <scsi/scsi.h>
#include <scsi/scsi_cmnd.h>
#include <scsi/scsi_device.h>
L
Linus Torvalds 已提交
54 55
#include <scsi/scsi_host.h>
#include <scsi/scsicam.h>
56
#include <scsi/scsi_eh.h>
57
#include <scsi/scsi_tcq.h>
58
#include <scsi/scsi_dbg.h>
L
Linus Torvalds 已提交
59

60
#include "sd.h"
L
Linus Torvalds 已提交
61 62
#include "scsi_logging.h"

63
/* make sure inq_product_rev string corresponds to this version */
D
Douglas Gilbert 已提交
64 65
#define SDEBUG_VERSION "1.86"
static const char *sdebug_version_date = "20160430";
66 67

#define MY_NAME "scsi_debug"
L
Linus Torvalds 已提交
68

69
/* Additional Sense Code (ASC) */
D
Douglas Gilbert 已提交
70 71
#define NO_ADDITIONAL_SENSE 0x0
#define LOGICAL_UNIT_NOT_READY 0x4
72
#define LOGICAL_UNIT_COMMUNICATION_FAILURE 0x8
L
Linus Torvalds 已提交
73
#define UNRECOVERED_READ_ERR 0x11
D
Douglas Gilbert 已提交
74
#define PARAMETER_LIST_LENGTH_ERR 0x1a
L
Linus Torvalds 已提交
75
#define INVALID_OPCODE 0x20
76
#define LBA_OUT_OF_RANGE 0x21
L
Linus Torvalds 已提交
77
#define INVALID_FIELD_IN_CDB 0x24
D
Douglas Gilbert 已提交
78
#define INVALID_FIELD_IN_PARAM_LIST 0x26
79 80
#define UA_RESET_ASC 0x29
#define UA_CHANGED_ASC 0x2a
81 82
#define TARGET_CHANGED_ASC 0x3f
#define LUNS_CHANGED_ASCQ 0x0e
83 84
#define INSUFF_RES_ASC 0x55
#define INSUFF_RES_ASCQ 0x3
85 86 87
#define POWER_ON_RESET_ASCQ 0x0
#define BUS_RESET_ASCQ 0x2	/* scsi bus reset occurred */
#define MODE_CHANGED_ASCQ 0x1	/* mode parameters changed */
88
#define CAPACITY_CHANGED_ASCQ 0x9
L
Linus Torvalds 已提交
89
#define SAVING_PARAMS_UNSUP 0x39
90
#define TRANSPORT_PROBLEM 0x4b
D
Douglas Gilbert 已提交
91 92
#define THRESHOLD_EXCEEDED 0x5d
#define LOW_POWER_COND_ON 0x5e
93
#define MISCOMPARE_VERIFY_ASC 0x1d
94 95
#define MICROCODE_CHANGED_ASCQ 0x1	/* with TARGET_CHANGED_ASC */
#define MICROCODE_CHANGED_WO_RESET_ASCQ 0x16
L
Linus Torvalds 已提交
96

97 98 99
/* Additional Sense Code Qualifier (ASCQ) */
#define ACK_NAK_TO 0x3

L
Linus Torvalds 已提交
100 101 102 103 104 105 106
/* Default values for driver parameters */
#define DEF_NUM_HOST   1
#define DEF_NUM_TGTS   1
#define DEF_MAX_LUNS   1
/* With these defaults, this driver will make 1 host with 1 target
 * (id 0) containing 1 logical unit (lun 0). That is 1 device.
 */
107
#define DEF_ATO 1
108
#define DEF_JDELAY   1		/* if > 0 unit is a jiffy */
L
Linus Torvalds 已提交
109
#define DEF_DEV_SIZE_MB   8
110 111
#define DEF_DIF 0
#define DEF_DIX 0
L
Linus Torvalds 已提交
112
#define DEF_D_SENSE   0
113
#define DEF_EVERY_NTH   0
D
Douglas Gilbert 已提交
114
#define DEF_FAKE_RW	0
115
#define DEF_GUARD 0
116
#define DEF_HOST_LOCK 0
117 118 119
#define DEF_LBPU 0
#define DEF_LBPWS 0
#define DEF_LBPWS10 0
120
#define DEF_LBPRZ 1
121
#define DEF_LOWEST_ALIGNED 0
122
#define DEF_NDELAY   0		/* if > 0 unit is a nanosecond */
123 124 125
#define DEF_NO_LUN_0   0
#define DEF_NUM_PARTS   0
#define DEF_OPTS   0
126
#define DEF_OPT_BLKS 1024
127
#define DEF_PHYSBLK_EXP 0
128
#define DEF_OPT_XFERLEN_EXP 0
D
Douglas Gilbert 已提交
129
#define DEF_PTYPE   TYPE_DISK
130
#define DEF_REMOVABLE false
131
#define DEF_SCSI_LEVEL   7    /* INQUIRY, byte2 [6->SPC-4; 7->SPC-5] */
132 133 134
#define DEF_SECTOR_SIZE 512
#define DEF_UNMAP_ALIGNMENT 0
#define DEF_UNMAP_GRANULARITY 1
135 136
#define DEF_UNMAP_MAX_BLOCKS 0xFFFFFFFF
#define DEF_UNMAP_MAX_DESC 256
137 138 139
#define DEF_VIRTUAL_GB   0
#define DEF_VPD_USE_HOSTNO 1
#define DEF_WRITESAME_LENGTH 0xFFFF
140
#define DEF_STRICT 0
141 142
#define DEF_STATISTICS false
#define DEF_SUBMIT_QUEUES 1
D
Douglas Gilbert 已提交
143
#define DEF_UUID_CTL 0
144
#define JDELAY_OVERRIDDEN -9999
L
Linus Torvalds 已提交
145

D
Douglas Gilbert 已提交
146 147
#define SDEBUG_LUN_0_VAL 0

148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169
/* bit mask values for sdebug_opts */
#define SDEBUG_OPT_NOISE		1
#define SDEBUG_OPT_MEDIUM_ERR		2
#define SDEBUG_OPT_TIMEOUT		4
#define SDEBUG_OPT_RECOVERED_ERR	8
#define SDEBUG_OPT_TRANSPORT_ERR	16
#define SDEBUG_OPT_DIF_ERR		32
#define SDEBUG_OPT_DIX_ERR		64
#define SDEBUG_OPT_MAC_TIMEOUT		128
#define SDEBUG_OPT_SHORT_TRANSFER	0x100
#define SDEBUG_OPT_Q_NOISE		0x200
#define SDEBUG_OPT_ALL_TSF		0x400
#define SDEBUG_OPT_RARE_TSF		0x800
#define SDEBUG_OPT_N_WCE		0x1000
#define SDEBUG_OPT_RESET_NOISE		0x2000
#define SDEBUG_OPT_NO_CDB_NOISE		0x4000
#define SDEBUG_OPT_ALL_NOISE (SDEBUG_OPT_NOISE | SDEBUG_OPT_Q_NOISE | \
			      SDEBUG_OPT_RESET_NOISE)
#define SDEBUG_OPT_ALL_INJECTING (SDEBUG_OPT_RECOVERED_ERR | \
				  SDEBUG_OPT_TRANSPORT_ERR | \
				  SDEBUG_OPT_DIF_ERR | SDEBUG_OPT_DIX_ERR | \
				  SDEBUG_OPT_SHORT_TRANSFER)
L
Linus Torvalds 已提交
170
/* When "every_nth" > 0 then modulo "every_nth" commands:
171
 *   - a missing response is simulated if SDEBUG_OPT_TIMEOUT is set
L
Linus Torvalds 已提交
172
 *   - a RECOVERED_ERROR is simulated on successful read and write
173
 *     commands if SDEBUG_OPT_RECOVERED_ERR is set.
174
 *   - a TRANSPORT_ERROR is simulated on successful read and write
175
 *     commands if SDEBUG_OPT_TRANSPORT_ERR is set.
L
Linus Torvalds 已提交
176 177
 *
 * When "every_nth" < 0 then after "- every_nth" commands:
178
 *   - a missing response is simulated if SDEBUG_OPT_TIMEOUT is set
L
Linus Torvalds 已提交
179
 *   - a RECOVERED_ERROR is simulated on successful read and write
180
 *     commands if SDEBUG_OPT_RECOVERED_ERR is set.
181
 *   - a TRANSPORT_ERROR is simulated on successful read and write
182 183 184 185
 *     commands if _DEBUG_OPT_TRANSPORT_ERR is set.
 * This will continue on every subsequent command until some other action
 * occurs (e.g. the user * writing a new value (other than -1 or 1) to
 * every_nth via sysfs).
L
Linus Torvalds 已提交
186 187
 */

188
/* As indicated in SAM-5 and SPC-4 Unit Attentions (UAs) are returned in
189 190 191 192 193 194
 * priority order. In the subset implemented here lower numbers have higher
 * priority. The UA numbers should be a sequence starting from 0 with
 * SDEBUG_NUM_UAS being 1 higher than the highest numbered UA. */
#define SDEBUG_UA_POR 0		/* Power on, reset, or bus device reset */
#define SDEBUG_UA_BUS_RESET 1
#define SDEBUG_UA_MODE_CHANGED 2
195
#define SDEBUG_UA_CAPACITY_CHANGED 3
196
#define SDEBUG_UA_LUNS_CHANGED 4
197 198 199
#define SDEBUG_UA_MICROCODE_CHANGED 5	/* simulate firmware change */
#define SDEBUG_UA_MICROCODE_CHANGED_WO_RESET 6
#define SDEBUG_NUM_UAS 7
200

201
/* when 1==SDEBUG_OPT_MEDIUM_ERR, a medium error is simulated at this
L
Linus Torvalds 已提交
202 203
 * sector on read commands: */
#define OPT_MEDIUM_ERR_ADDR   0x1234 /* that's sector 4660 in decimal */
204
#define OPT_MEDIUM_ERR_NUM    10     /* number of consecutive medium errs */
L
Linus Torvalds 已提交
205 206 207 208 209

/* If REPORT LUNS has luns >= 256 it can choose "flat space" (value 1)
 * or "peripheral device" addressing (value 0) */
#define SAM2_LUN_ADDRESS_METHOD 0

210 211 212 213 214 215 216 217 218
/* SDEBUG_CANQUEUE is the maximum number of commands that can be queued
 * (for response) per submit queue at one time. Can be reduced by max_queue
 * option. Command responses are not queued when jdelay=0 and ndelay=0. The
 * per-device DEF_CMD_PER_LUN can be changed via sysfs:
 * /sys/class/scsi_device/<h:c:t:l>/device/queue_depth
 * but cannot exceed SDEBUG_CANQUEUE .
 */
#define SDEBUG_CANQUEUE_WORDS  3	/* a WORD is bits in a long */
#define SDEBUG_CANQUEUE  (SDEBUG_CANQUEUE_WORDS * BITS_PER_LONG)
219 220
#define DEF_CMD_PER_LUN  255

221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239
#define F_D_IN			1
#define F_D_OUT			2
#define F_D_OUT_MAYBE		4	/* WRITE SAME, NDOB bit */
#define F_D_UNKN		8
#define F_RL_WLUN_OK		0x10
#define F_SKIP_UA		0x20
#define F_DELAY_OVERR		0x40
#define F_SA_LOW		0x80	/* cdb byte 1, bits 4 to 0 */
#define F_SA_HIGH		0x100	/* as used by variable length cdbs */
#define F_INV_OP		0x200
#define F_FAKE_RW		0x400
#define F_M_ACCESS		0x800	/* media access */

#define FF_RESPOND (F_RL_WLUN_OK | F_SKIP_UA | F_DELAY_OVERR)
#define FF_DIRECT_IO (F_M_ACCESS | F_FAKE_RW)
#define FF_SA (F_SA_HIGH | F_SA_LOW)

#define SDEBUG_MAX_PARTS 4

D
Douglas Gilbert 已提交
240
#define SDEBUG_MAX_CMD_LEN 32
241 242 243 244 245 246 247


struct sdebug_dev_info {
	struct list_head dev_list;
	unsigned int channel;
	unsigned int target;
	u64 lun;
C
Christoph Hellwig 已提交
248
	uuid_t lu_name;
249 250 251
	struct sdebug_host_info *sdbg_host;
	unsigned long uas_bm[1];
	atomic_t num_in_q;
252
	atomic_t stopped;
253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268
	bool used;
};

struct sdebug_host_info {
	struct list_head host_list;
	struct Scsi_Host *shost;
	struct device dev;
	struct list_head dev_info_list;
};

#define to_sdebug_host(d)	\
	container_of(d, struct sdebug_host_info, dev)

struct sdebug_defer {
	struct hrtimer hrt;
	struct execute_work ew;
269 270 271
	int sqa_idx;	/* index of sdebug_queue array */
	int qc_idx;	/* index of sdebug_queued_cmd array within sqa_idx */
	int issuing_cpu;
272 273 274
};

struct sdebug_queued_cmd {
275 276 277
	/* corresponding bit set in in_use_bm[] in owning struct sdebug_queue
	 * instance indicates this slot is in use.
	 */
278 279
	struct sdebug_defer *sd_dp;
	struct scsi_cmnd *a_cmnd;
280 281 282 283 284
	unsigned int inj_recovered:1;
	unsigned int inj_transport:1;
	unsigned int inj_dif:1;
	unsigned int inj_dix:1;
	unsigned int inj_short:1;
285 286
};

287 288 289 290 291
struct sdebug_queue {
	struct sdebug_queued_cmd qc_arr[SDEBUG_CANQUEUE];
	unsigned long in_use_bm[SDEBUG_CANQUEUE_WORDS];
	spinlock_t qc_lock;
	atomic_t blocked;	/* to temporarily stop more being queued */
292 293
};

294 295 296 297 298
static atomic_t sdebug_cmnd_count;   /* number of incoming commands */
static atomic_t sdebug_completions;  /* count of deferred completions */
static atomic_t sdebug_miss_cpus;    /* submission + completion cpus differ */
static atomic_t sdebug_a_tsf;	     /* 'almost task set full' counter */

299
struct opcode_info_t {
D
Douglas Gilbert 已提交
300 301
	u8 num_attached;	/* 0 if this is it (i.e. a leaf); use 0xff */
				/* for terminating element */
302 303 304 305 306 307 308 309 310 311
	u8 opcode;		/* if num_attached > 0, preferred */
	u16 sa;			/* service action */
	u32 flags;		/* OR-ed set of SDEB_F_* */
	int (*pfp)(struct scsi_cmnd *, struct sdebug_dev_info *);
	const struct opcode_info_t *arrp;  /* num_attached elements or NULL */
	u8 len_mask[16];	/* len=len_mask[0], then mask for cdb[1]... */
				/* ignore cdb bytes after position 15 */
};

/* SCSI opcodes (first byte of cdb) of interest mapped onto these indexes */
312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345
enum sdeb_opcode_index {
	SDEB_I_INVALID_OPCODE =	0,
	SDEB_I_INQUIRY = 1,
	SDEB_I_REPORT_LUNS = 2,
	SDEB_I_REQUEST_SENSE = 3,
	SDEB_I_TEST_UNIT_READY = 4,
	SDEB_I_MODE_SENSE = 5,		/* 6, 10 */
	SDEB_I_MODE_SELECT = 6,		/* 6, 10 */
	SDEB_I_LOG_SENSE = 7,
	SDEB_I_READ_CAPACITY = 8,	/* 10; 16 is in SA_IN(16) */
	SDEB_I_READ = 9,		/* 6, 10, 12, 16 */
	SDEB_I_WRITE = 10,		/* 6, 10, 12, 16 */
	SDEB_I_START_STOP = 11,
	SDEB_I_SERV_ACT_IN = 12,	/* 12, 16 */
	SDEB_I_SERV_ACT_OUT = 13,	/* 12, 16 */
	SDEB_I_MAINT_IN = 14,
	SDEB_I_MAINT_OUT = 15,
	SDEB_I_VERIFY = 16,		/* 10 only */
	SDEB_I_VARIABLE_LEN = 17,
	SDEB_I_RESERVE = 18,		/* 6, 10 */
	SDEB_I_RELEASE = 19,		/* 6, 10 */
	SDEB_I_ALLOW_REMOVAL = 20,	/* PREVENT ALLOW MEDIUM REMOVAL */
	SDEB_I_REZERO_UNIT = 21,	/* REWIND in SSC */
	SDEB_I_ATA_PT = 22,		/* 12, 16 */
	SDEB_I_SEND_DIAG = 23,
	SDEB_I_UNMAP = 24,
	SDEB_I_XDWRITEREAD = 25,	/* 10 only */
	SDEB_I_WRITE_BUFFER = 26,
	SDEB_I_WRITE_SAME = 27,		/* 10, 16 */
	SDEB_I_SYNC_CACHE = 28,		/* 10 only */
	SDEB_I_COMP_WRITE = 29,
	SDEB_I_LAST_ELEMENT = 30,	/* keep this last */
};

346

347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366
static const unsigned char opcode_ind_arr[256] = {
/* 0x0; 0x0->0x1f: 6 byte cdbs */
	SDEB_I_TEST_UNIT_READY, SDEB_I_REZERO_UNIT, 0, SDEB_I_REQUEST_SENSE,
	    0, 0, 0, 0,
	SDEB_I_READ, 0, SDEB_I_WRITE, 0, 0, 0, 0, 0,
	0, 0, SDEB_I_INQUIRY, 0, 0, SDEB_I_MODE_SELECT, SDEB_I_RESERVE,
	    SDEB_I_RELEASE,
	0, 0, SDEB_I_MODE_SENSE, SDEB_I_START_STOP, 0, SDEB_I_SEND_DIAG,
	    SDEB_I_ALLOW_REMOVAL, 0,
/* 0x20; 0x20->0x3f: 10 byte cdbs */
	0, 0, 0, 0, 0, SDEB_I_READ_CAPACITY, 0, 0,
	SDEB_I_READ, 0, SDEB_I_WRITE, 0, 0, 0, 0, SDEB_I_VERIFY,
	0, 0, 0, 0, 0, SDEB_I_SYNC_CACHE, 0, 0,
	0, 0, 0, SDEB_I_WRITE_BUFFER, 0, 0, 0, 0,
/* 0x40; 0x40->0x5f: 10 byte cdbs */
	0, SDEB_I_WRITE_SAME, SDEB_I_UNMAP, 0, 0, 0, 0, 0,
	0, 0, 0, 0, 0, SDEB_I_LOG_SENSE, 0, 0,
	0, 0, 0, SDEB_I_XDWRITEREAD, 0, SDEB_I_MODE_SELECT, SDEB_I_RESERVE,
	    SDEB_I_RELEASE,
	0, 0, SDEB_I_MODE_SENSE, 0, 0, 0, 0, 0,
367
/* 0x60; 0x60->0x7d are reserved, 0x7e is "extended cdb" */
368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403
	0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
	0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
	0, SDEB_I_VARIABLE_LEN,
/* 0x80; 0x80->0x9f: 16 byte cdbs */
	0, 0, 0, 0, 0, SDEB_I_ATA_PT, 0, 0,
	SDEB_I_READ, SDEB_I_COMP_WRITE, SDEB_I_WRITE, 0, 0, 0, 0, 0,
	0, 0, 0, SDEB_I_WRITE_SAME, 0, 0, 0, 0,
	0, 0, 0, 0, 0, 0, SDEB_I_SERV_ACT_IN, SDEB_I_SERV_ACT_OUT,
/* 0xa0; 0xa0->0xbf: 12 byte cdbs */
	SDEB_I_REPORT_LUNS, SDEB_I_ATA_PT, 0, SDEB_I_MAINT_IN,
	     SDEB_I_MAINT_OUT, 0, 0, 0,
	SDEB_I_READ, SDEB_I_SERV_ACT_OUT, SDEB_I_WRITE, SDEB_I_SERV_ACT_IN,
	     0, 0, 0, 0,
	0, 0, 0, 0, 0, 0, 0, 0,
	0, 0, 0, 0, 0, 0, 0, 0,
/* 0xc0; 0xc0->0xff: vendor specific */
	0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
	0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
	0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
	0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
};

static int resp_inquiry(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_report_luns(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_requests(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_mode_sense(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_mode_select(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_log_sense(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_readcap(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_read_dt0(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_write_dt0(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_start_stop(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_readcap16(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_get_lba_status(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_report_tgtpgs(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_unmap(struct scsi_cmnd *, struct sdebug_dev_info *);
404 405
static int resp_rsup_opcodes(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_rsup_tmfs(struct scsi_cmnd *, struct sdebug_dev_info *);
406 407 408
static int resp_write_same_10(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_write_same_16(struct scsi_cmnd *, struct sdebug_dev_info *);
static int resp_xdwriteread_10(struct scsi_cmnd *, struct sdebug_dev_info *);
409
static int resp_comp_write(struct scsi_cmnd *, struct sdebug_dev_info *);
410
static int resp_write_buffer(struct scsi_cmnd *, struct sdebug_dev_info *);
411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456

static const struct opcode_info_t msense_iarr[1] = {
	{0, 0x1a, 0, F_D_IN, NULL, NULL,
	    {6,  0xe8, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
};

static const struct opcode_info_t mselect_iarr[1] = {
	{0, 0x15, 0, F_D_OUT, NULL, NULL,
	    {6,  0xf1, 0, 0, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
};

static const struct opcode_info_t read_iarr[3] = {
	{0, 0x28, 0, F_D_IN | FF_DIRECT_IO, resp_read_dt0, NULL,/* READ(10) */
	    {10,  0xff, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff, 0xff, 0xc7, 0, 0,
	     0, 0, 0, 0} },
	{0, 0x8, 0, F_D_IN | FF_DIRECT_IO, resp_read_dt0, NULL, /* READ(6) */
	    {6,  0xff, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{0, 0xa8, 0, F_D_IN | FF_DIRECT_IO, resp_read_dt0, NULL,/* READ(12) */
	    {12,  0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x9f,
	     0xc7, 0, 0, 0, 0} },
};

static const struct opcode_info_t write_iarr[3] = {
	{0, 0x2a, 0, F_D_OUT | FF_DIRECT_IO, resp_write_dt0, NULL,   /* 10 */
	    {10,  0xfb, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff, 0xff, 0xc7, 0, 0,
	     0, 0, 0, 0} },
	{0, 0xa, 0, F_D_OUT | FF_DIRECT_IO, resp_write_dt0, NULL,    /* 6 */
	    {6,  0xff, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{0, 0xaa, 0, F_D_OUT | FF_DIRECT_IO, resp_write_dt0, NULL,   /* 12 */
	    {12,  0xfb, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x9f,
	     0xc7, 0, 0, 0, 0} },
};

static const struct opcode_info_t sa_in_iarr[1] = {
	{0, 0x9e, 0x12, F_SA_LOW | F_D_IN, resp_get_lba_status, NULL,
	    {16,  0x12, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
	     0xff, 0xff, 0xff, 0, 0xc7} },
};

static const struct opcode_info_t vl_iarr[1] = {	/* VARIABLE LENGTH */
	{0, 0x7f, 0xb, F_SA_HIGH | F_D_OUT | FF_DIRECT_IO, resp_write_dt0,
	    NULL, {32,  0xc7, 0, 0, 0, 0, 0x1f, 0x18, 0x0, 0xb, 0xfa,
		   0, 0xff, 0xff, 0xff, 0xff} },	/* WRITE(32) */
};

static const struct opcode_info_t maint_in_iarr[2] = {
457
	{0, 0xa3, 0xc, F_SA_LOW | F_D_IN, resp_rsup_opcodes, NULL,
458 459
	    {12,  0xc, 0x87, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0,
	     0xc7, 0, 0, 0, 0} },
460
	{0, 0xa3, 0xd, F_SA_LOW | F_D_IN, resp_rsup_tmfs, NULL,
461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527
	    {12,  0xd, 0x80, 0, 0, 0, 0xff, 0xff, 0xff, 0xff, 0, 0xc7, 0, 0,
	     0, 0} },
};

static const struct opcode_info_t write_same_iarr[1] = {
	{0, 0x93, 0, F_D_OUT_MAYBE | FF_DIRECT_IO, resp_write_same_16, NULL,
	    {16,  0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
	     0xff, 0xff, 0xff, 0x1f, 0xc7} },
};

static const struct opcode_info_t reserve_iarr[1] = {
	{0, 0x16, 0, F_D_OUT, NULL, NULL,	/* RESERVE(6) */
	    {6,  0x1f, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
};

static const struct opcode_info_t release_iarr[1] = {
	{0, 0x17, 0, F_D_OUT, NULL, NULL,	/* RELEASE(6) */
	    {6,  0x1f, 0xff, 0, 0, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
};


/* This array is accessed via SDEB_I_* values. Make sure all are mapped,
 * plus the terminating elements for logic that scans this table such as
 * REPORT SUPPORTED OPERATION CODES. */
static const struct opcode_info_t opcode_info_arr[SDEB_I_LAST_ELEMENT + 1] = {
/* 0 */
	{0, 0, 0, F_INV_OP | FF_RESPOND, NULL, NULL,
	    {0,  0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{0, 0x12, 0, FF_RESPOND | F_D_IN, resp_inquiry, NULL,
	    {6,  0xe3, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{0, 0xa0, 0, FF_RESPOND | F_D_IN, resp_report_luns, NULL,
	    {12,  0xe3, 0xff, 0, 0, 0, 0xff, 0xff, 0xff, 0xff, 0, 0xc7, 0, 0,
	     0, 0} },
	{0, 0x3, 0, FF_RESPOND | F_D_IN, resp_requests, NULL,
	    {6,  0xe1, 0, 0, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{0, 0x0, 0, F_M_ACCESS | F_RL_WLUN_OK, NULL, NULL,/* TEST UNIT READY */
	    {6,  0, 0, 0, 0, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{1, 0x5a, 0, F_D_IN, resp_mode_sense, msense_iarr,
	    {10,  0xf8, 0xff, 0xff, 0, 0, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0,
	     0} },
	{1, 0x55, 0, F_D_OUT, resp_mode_select, mselect_iarr,
	    {10,  0xf1, 0, 0, 0, 0, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0} },
	{0, 0x4d, 0, F_D_IN, resp_log_sense, NULL,
	    {10,  0xe3, 0xff, 0xff, 0, 0xff, 0xff, 0xff, 0xff, 0xc7, 0, 0, 0,
	     0, 0, 0} },
	{0, 0x25, 0, F_D_IN, resp_readcap, NULL,
	    {10,  0xe1, 0xff, 0xff, 0xff, 0xff, 0, 0, 0x1, 0xc7, 0, 0, 0, 0,
	     0, 0} },
	{3, 0x88, 0, F_D_IN | FF_DIRECT_IO, resp_read_dt0, read_iarr,
	    {16,  0xfe, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
	     0xff, 0xff, 0xff, 0x9f, 0xc7} },		/* READ(16) */
/* 10 */
	{3, 0x8a, 0, F_D_OUT | FF_DIRECT_IO, resp_write_dt0, write_iarr,
	    {16,  0xfa, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
	     0xff, 0xff, 0xff, 0x9f, 0xc7} },		/* WRITE(16) */
	{0, 0x1b, 0, 0, resp_start_stop, NULL,		/* START STOP UNIT */
	    {6,  0x1, 0, 0xf, 0xf7, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{1, 0x9e, 0x10, F_SA_LOW | F_D_IN, resp_readcap16, sa_in_iarr,
	    {16,  0x10, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
	     0xff, 0xff, 0xff, 0x1, 0xc7} },	/* READ CAPACITY(16) */
	{0, 0, 0, F_INV_OP | FF_RESPOND, NULL, NULL, /* SA OUT */
	    {0,  0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{2, 0xa3, 0xa, F_SA_LOW | F_D_IN, resp_report_tgtpgs, maint_in_iarr,
	    {12,  0xea, 0, 0, 0, 0, 0xff, 0xff, 0xff, 0xff, 0, 0xc7, 0, 0, 0,
	     0} },
	{0, 0, 0, F_INV_OP | FF_RESPOND, NULL, NULL, /* MAINT OUT */
	    {0,  0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
528 529 530
	{0, 0x2f, 0, F_D_OUT_MAYBE | FF_DIRECT_IO, NULL, NULL, /* VERIFY(10) */
	    {10,  0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xc7,
	     0, 0, 0, 0, 0, 0} },
531 532 533 534 535 536 537 538 539 540
	{1, 0x7f, 0x9, F_SA_HIGH | F_D_IN | FF_DIRECT_IO, resp_read_dt0,
	    vl_iarr, {32,  0xc7, 0, 0, 0, 0, 0x1f, 0x18, 0x0, 0x9, 0xfe, 0,
		      0xff, 0xff, 0xff, 0xff} },/* VARIABLE LENGTH, READ(32) */
	{1, 0x56, 0, F_D_OUT, NULL, reserve_iarr, /* RESERVE(10) */
	    {10,  0xff, 0xff, 0xff, 0, 0, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0,
	     0} },
	{1, 0x57, 0, F_D_OUT, NULL, release_iarr, /* RELEASE(10) */
	    {10,  0x13, 0xff, 0xff, 0, 0, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0,
	     0} },
/* 20 */
541 542
	{0, 0x1e, 0, 0, NULL, NULL, /* ALLOW REMOVAL */
	    {6,  0, 0, 0, 0x3, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
543 544 545 546 547 548 549 550 551 552 553
	{0, 0x1, 0, 0, resp_start_stop, NULL, /* REWIND ?? */
	    {6,  0x1, 0, 0, 0, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{0, 0, 0, F_INV_OP | FF_RESPOND, NULL, NULL, /* ATA_PT */
	    {0,  0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{0, 0x1d, F_D_OUT, 0, NULL, NULL,	/* SEND DIAGNOSTIC */
	    {6,  0xf7, 0, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
	{0, 0x42, 0, F_D_OUT | FF_DIRECT_IO, resp_unmap, NULL, /* UNMAP */
	    {10,  0x1, 0, 0, 0, 0, 0x1f, 0xff, 0xff, 0xc7, 0, 0, 0, 0, 0, 0} },
	{0, 0x53, 0, F_D_IN | F_D_OUT | FF_DIRECT_IO, resp_xdwriteread_10,
	    NULL, {10,  0xff, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff, 0xff, 0xc7,
		   0, 0, 0, 0, 0, 0} },
554 555 556
	{0, 0x3b, 0, F_D_OUT_MAYBE, resp_write_buffer, NULL,
	    {10,  0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xc7, 0, 0,
	     0, 0, 0, 0} },			/* WRITE_BUFFER */
557 558 559 560 561 562
	{1, 0x41, 0, F_D_OUT_MAYBE | FF_DIRECT_IO, resp_write_same_10,
	    write_same_iarr, {10,  0xff, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff,
			      0xff, 0xc7, 0, 0, 0, 0, 0, 0} },
	{0, 0x35, 0, F_DELAY_OVERR | FF_DIRECT_IO, NULL, NULL, /* SYNC_CACHE */
	    {10,  0x7, 0xff, 0xff, 0xff, 0xff, 0x1f, 0xff, 0xff, 0xc7, 0, 0,
	     0, 0, 0, 0} },
563
	{0, 0x89, 0, F_D_OUT | FF_DIRECT_IO, resp_comp_write, NULL,
564 565 566 567 568 569 570 571
	    {16,  0xf8, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0, 0,
	     0, 0xff, 0x1f, 0xc7} },		/* COMPARE AND WRITE */

/* 30 */
	{0xff, 0, 0, 0, NULL, NULL,		/* terminating element */
	    {0,  0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0} },
};

572 573
static int sdebug_add_host = DEF_NUM_HOST;
static int sdebug_ato = DEF_ATO;
574
static int sdebug_jdelay = DEF_JDELAY;	/* if > 0 then unit is jiffies */
575 576 577 578 579 580 581 582 583
static int sdebug_dev_size_mb = DEF_DEV_SIZE_MB;
static int sdebug_dif = DEF_DIF;
static int sdebug_dix = DEF_DIX;
static int sdebug_dsense = DEF_D_SENSE;
static int sdebug_every_nth = DEF_EVERY_NTH;
static int sdebug_fake_rw = DEF_FAKE_RW;
static unsigned int sdebug_guard = DEF_GUARD;
static int sdebug_lowest_aligned = DEF_LOWEST_ALIGNED;
static int sdebug_max_luns = DEF_MAX_LUNS;
584
static int sdebug_max_queue = SDEBUG_CANQUEUE;	/* per submit queue */
585
static atomic_t retired_max_queue;	/* if > 0 then was prior max_queue */
586
static int sdebug_ndelay = DEF_NDELAY;	/* if > 0 then unit is nanoseconds */
587 588 589 590 591 592 593
static int sdebug_no_lun_0 = DEF_NO_LUN_0;
static int sdebug_no_uld;
static int sdebug_num_parts = DEF_NUM_PARTS;
static int sdebug_num_tgts = DEF_NUM_TGTS; /* targets per host */
static int sdebug_opt_blks = DEF_OPT_BLKS;
static int sdebug_opts = DEF_OPTS;
static int sdebug_physblk_exp = DEF_PHYSBLK_EXP;
594
static int sdebug_opt_xferlen_exp = DEF_OPT_XFERLEN_EXP;
D
Douglas Gilbert 已提交
595
static int sdebug_ptype = DEF_PTYPE; /* SCSI peripheral device type */
596 597 598 599 600 601 602 603 604 605 606 607 608
static int sdebug_scsi_level = DEF_SCSI_LEVEL;
static int sdebug_sector_size = DEF_SECTOR_SIZE;
static int sdebug_virtual_gb = DEF_VIRTUAL_GB;
static int sdebug_vpd_use_hostno = DEF_VPD_USE_HOSTNO;
static unsigned int sdebug_lbpu = DEF_LBPU;
static unsigned int sdebug_lbpws = DEF_LBPWS;
static unsigned int sdebug_lbpws10 = DEF_LBPWS10;
static unsigned int sdebug_lbprz = DEF_LBPRZ;
static unsigned int sdebug_unmap_alignment = DEF_UNMAP_ALIGNMENT;
static unsigned int sdebug_unmap_granularity = DEF_UNMAP_GRANULARITY;
static unsigned int sdebug_unmap_max_blocks = DEF_UNMAP_MAX_BLOCKS;
static unsigned int sdebug_unmap_max_desc = DEF_UNMAP_MAX_DESC;
static unsigned int sdebug_write_same_length = DEF_WRITESAME_LENGTH;
D
Douglas Gilbert 已提交
609
static int sdebug_uuid_ctl = DEF_UUID_CTL;
610 611 612 613
static bool sdebug_removable = DEF_REMOVABLE;
static bool sdebug_clustering;
static bool sdebug_host_lock = DEF_HOST_LOCK;
static bool sdebug_strict = DEF_STRICT;
614
static bool sdebug_any_injecting_opt;
615
static bool sdebug_verbose;
616
static bool have_dif_prot;
617 618
static bool sdebug_statistics = DEF_STATISTICS;
static bool sdebug_mq_active;
L
Linus Torvalds 已提交
619

D
Douglas Gilbert 已提交
620
static unsigned int sdebug_store_sectors;
L
Linus Torvalds 已提交
621 622 623 624 625 626 627 628 629 630 631
static sector_t sdebug_capacity;	/* in sectors */

/* old BIOS stuff, kernel may get rid of them but some mode sense pages
   may still need them */
static int sdebug_heads;		/* heads per disk */
static int sdebug_cylinders_per;	/* cylinders per surface */
static int sdebug_sectors_per;		/* sectors per cylinder */

static LIST_HEAD(sdebug_host_list);
static DEFINE_SPINLOCK(sdebug_host_list_lock);

632
static unsigned char *fake_storep;	/* ramdisk storage */
633
static struct t10_pi_tuple *dif_storep;	/* protection info */
634
static void *map_storep;		/* provisioning map */
L
Linus Torvalds 已提交
635

636
static unsigned long map_size;
637 638 639 640 641
static int num_aborts;
static int num_dev_resets;
static int num_target_resets;
static int num_bus_resets;
static int num_host_resets;
642 643 644
static int dix_writes;
static int dix_reads;
static int dif_errors;
L
Linus Torvalds 已提交
645

646 647
static int submit_queues = DEF_SUBMIT_QUEUES;  /* > 1 for multi-queue (mq) */
static struct sdebug_queue *sdebug_q_arr;  /* ptr to array of submit queues */
648

L
Linus Torvalds 已提交
649 650
static DEFINE_RWLOCK(atomic_rw);

651 652
static char sdebug_proc_name[] = MY_NAME;
static const char *my_name = MY_NAME;
L
Linus Torvalds 已提交
653 654 655 656 657 658 659 660 661 662 663

static struct bus_type pseudo_lld_bus;

static struct device_driver sdebug_driverfs_driver = {
	.name 		= sdebug_proc_name,
	.bus		= &pseudo_lld_bus,
};

static const int check_condition_result =
		(DRIVER_SENSE << 24) | SAM_STAT_CHECK_CONDITION;

664 665 666
static const int illegal_condition_result =
	(DRIVER_SENSE << 24) | (DID_ABORT << 16) | SAM_STAT_CHECK_CONDITION;

667 668 669
static const int device_qfull_result =
	(DID_OK << 16) | (COMMAND_COMPLETE << 8) | SAM_STAT_TASK_SET_FULL;

670

671 672 673 674 675
/* Only do the extra work involved in logical block provisioning if one or
 * more of the lbpu, lbpws or lbpws10 parameters are given and we are doing
 * real reads and writes (i.e. not skipping them for speed).
 */
static inline bool scsi_debug_lbp(void)
676 677 678 679
{
	return 0 == sdebug_fake_rw &&
		(sdebug_lbpu || sdebug_lbpws || sdebug_lbpws10);
}
D
Douglas Gilbert 已提交
680

681 682 683 684
static void *fake_store(unsigned long long lba)
{
	lba = do_div(lba, sdebug_store_sectors);

685
	return fake_storep + lba * sdebug_sector_size;
686 687
}

688
static struct t10_pi_tuple *dif_store(sector_t sector)
689
{
690
	sector = sector_div(sector, sdebug_store_sectors);
691 692 693 694

	return dif_storep + sector;
}

695 696 697 698 699 700 701 702 703
static void sdebug_max_tgts_luns(void)
{
	struct sdebug_host_info *sdbg_host;
	struct Scsi_Host *hpnt;

	spin_lock(&sdebug_host_list_lock);
	list_for_each_entry(sdbg_host, &sdebug_host_list, host_list) {
		hpnt = sdbg_host->shost;
		if ((hpnt->this_id >= 0) &&
704 705
		    (sdebug_num_tgts > hpnt->this_id))
			hpnt->max_id = sdebug_num_tgts + 1;
706
		else
707 708
			hpnt->max_id = sdebug_num_tgts;
		/* sdebug_max_luns; */
709
		hpnt->max_lun = SCSI_W_LUN_REPORT_LUNS + 1;
710 711 712 713
	}
	spin_unlock(&sdebug_host_list_lock);
}

714 715 716
enum sdeb_cmd_data {SDEB_IN_DATA = 0, SDEB_IN_CDB = 1};

/* Set in_bit to -1 to indicate no bit position of invalid field */
717 718 719
static void mk_sense_invalid_fld(struct scsi_cmnd *scp,
				 enum sdeb_cmd_data c_d,
				 int in_byte, int in_bit)
720 721 722 723 724 725 726 727 728 729 730 731 732
{
	unsigned char *sbuff;
	u8 sks[4];
	int sl, asc;

	sbuff = scp->sense_buffer;
	if (!sbuff) {
		sdev_printk(KERN_ERR, scp->device,
			    "%s: sense_buffer is NULL\n", __func__);
		return;
	}
	asc = c_d ? INVALID_FIELD_IN_CDB : INVALID_FIELD_IN_PARAM_LIST;
	memset(sbuff, 0, SCSI_SENSE_BUFFERSIZE);
733
	scsi_build_sense_buffer(sdebug_dsense, sbuff, ILLEGAL_REQUEST, asc, 0);
734 735 736 737 738 739 740 741 742
	memset(sks, 0, sizeof(sks));
	sks[0] = 0x80;
	if (c_d)
		sks[0] |= 0x40;
	if (in_bit >= 0) {
		sks[0] |= 0x8;
		sks[0] |= 0x7 & in_bit;
	}
	put_unaligned_be16(in_byte, sks + 1);
743
	if (sdebug_dsense) {
744 745 746 747 748 749 750
		sl = sbuff[7] + 8;
		sbuff[7] = sl;
		sbuff[sl] = 0x2;
		sbuff[sl + 1] = 0x6;
		memcpy(sbuff + sl + 4, sks, 3);
	} else
		memcpy(sbuff + 15, sks, 3);
751
	if (sdebug_verbose)
752 753 754 755 756
		sdev_printk(KERN_INFO, scp->device, "%s:  [sense_key,asc,ascq"
			    "]: [0x5,0x%x,0x0] %c byte=%d, bit=%d\n",
			    my_name, asc, c_d ? 'C' : 'D', in_byte, in_bit);
}

757
static void mk_sense_buffer(struct scsi_cmnd *scp, int key, int asc, int asq)
758 759 760
{
	unsigned char *sbuff;

761 762 763 764 765 766 767
	sbuff = scp->sense_buffer;
	if (!sbuff) {
		sdev_printk(KERN_ERR, scp->device,
			    "%s: sense_buffer is NULL\n", __func__);
		return;
	}
	memset(sbuff, 0, SCSI_SENSE_BUFFERSIZE);
768

769
	scsi_build_sense_buffer(sdebug_dsense, sbuff, key, asc, asq);
770

771
	if (sdebug_verbose)
772 773 774
		sdev_printk(KERN_INFO, scp->device,
			    "%s:  [sense_key,asc,ascq]: [0x%x,0x%x,0x%x]\n",
			    my_name, key, asc, asq);
775
}
L
Linus Torvalds 已提交
776

777
static void mk_sense_invalid_opcode(struct scsi_cmnd *scp)
778 779 780 781
{
	mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_OPCODE, 0);
}

L
Linus Torvalds 已提交
782 783
static int scsi_debug_ioctl(struct scsi_device *dev, int cmd, void __user *arg)
{
784
	if (sdebug_verbose) {
785 786 787 788 789 790 791 792 793 794
		if (0x1261 == cmd)
			sdev_printk(KERN_INFO, dev,
				    "%s: BLKFLSBUF [0x1261]\n", __func__);
		else if (0x5331 == cmd)
			sdev_printk(KERN_INFO, dev,
				    "%s: CDROM_GET_CAPABILITY [0x5331]\n",
				    __func__);
		else
			sdev_printk(KERN_INFO, dev, "%s: cmd=0x%x\n",
				    __func__, cmd);
L
Linus Torvalds 已提交
795 796 797 798 799
	}
	return -EINVAL;
	/* return -ENOTTY; // correct return but upsets fdisk */
}

800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815
static void clear_luns_changed_on_target(struct sdebug_dev_info *devip)
{
	struct sdebug_host_info *sdhp;
	struct sdebug_dev_info *dp;

	spin_lock(&sdebug_host_list_lock);
	list_for_each_entry(sdhp, &sdebug_host_list, host_list) {
		list_for_each_entry(dp, &sdhp->dev_info_list, dev_list) {
			if ((devip->sdbg_host == dp->sdbg_host) &&
			    (devip->target == dp->target))
				clear_bit(SDEBUG_UA_LUNS_CHANGED, dp->uas_bm);
		}
	}
	spin_unlock(&sdebug_host_list_lock);
}

816
static int make_ua(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
L
Linus Torvalds 已提交
817
{
818 819 820 821 822 823 824 825
	int k;

	k = find_first_bit(devip->uas_bm, SDEBUG_NUM_UAS);
	if (k != SDEBUG_NUM_UAS) {
		const char *cp = NULL;

		switch (k) {
		case SDEBUG_UA_POR:
826 827
			mk_sense_buffer(scp, UNIT_ATTENTION, UA_RESET_ASC,
					POWER_ON_RESET_ASCQ);
828
			if (sdebug_verbose)
829 830 831
				cp = "power on reset";
			break;
		case SDEBUG_UA_BUS_RESET:
832 833
			mk_sense_buffer(scp, UNIT_ATTENTION, UA_RESET_ASC,
					BUS_RESET_ASCQ);
834
			if (sdebug_verbose)
835 836 837
				cp = "bus reset";
			break;
		case SDEBUG_UA_MODE_CHANGED:
838 839
			mk_sense_buffer(scp, UNIT_ATTENTION, UA_CHANGED_ASC,
					MODE_CHANGED_ASCQ);
840
			if (sdebug_verbose)
841 842
				cp = "mode parameters changed";
			break;
843
		case SDEBUG_UA_CAPACITY_CHANGED:
844 845
			mk_sense_buffer(scp, UNIT_ATTENTION, UA_CHANGED_ASC,
					CAPACITY_CHANGED_ASCQ);
846
			if (sdebug_verbose)
847
				cp = "capacity data changed";
848
			break;
849
		case SDEBUG_UA_MICROCODE_CHANGED:
850
			mk_sense_buffer(scp, UNIT_ATTENTION,
D
Douglas Gilbert 已提交
851 852
					TARGET_CHANGED_ASC,
					MICROCODE_CHANGED_ASCQ);
853
			if (sdebug_verbose)
854 855 856
				cp = "microcode has been changed";
			break;
		case SDEBUG_UA_MICROCODE_CHANGED_WO_RESET:
857
			mk_sense_buffer(scp, UNIT_ATTENTION,
858 859
					TARGET_CHANGED_ASC,
					MICROCODE_CHANGED_WO_RESET_ASCQ);
860
			if (sdebug_verbose)
861 862
				cp = "microcode has been changed without reset";
			break;
863 864 865 866 867 868
		case SDEBUG_UA_LUNS_CHANGED:
			/*
			 * SPC-3 behavior is to report a UNIT ATTENTION with
			 * ASC/ASCQ REPORTED LUNS DATA HAS CHANGED on every LUN
			 * on the target, until a REPORT LUNS command is
			 * received.  SPC-4 behavior is to report it only once.
869
			 * NOTE:  sdebug_scsi_level does not use the same
870 871
			 * values as struct scsi_device->scsi_level.
			 */
872
			if (sdebug_scsi_level >= 6)	/* SPC-4 and above */
873
				clear_luns_changed_on_target(devip);
874
			mk_sense_buffer(scp, UNIT_ATTENTION,
875 876
					TARGET_CHANGED_ASC,
					LUNS_CHANGED_ASCQ);
877
			if (sdebug_verbose)
878 879
				cp = "reported luns data has changed";
			break;
880
		default:
881 882
			pr_warn("unexpected unit attention code=%d\n", k);
			if (sdebug_verbose)
883 884 885 886
				cp = "unknown";
			break;
		}
		clear_bit(k, devip->uas_bm);
887
		if (sdebug_verbose)
888
			sdev_printk(KERN_INFO, scp->device,
889 890
				   "%s reports: Unit attention: %s\n",
				   my_name, cp);
L
Linus Torvalds 已提交
891 892 893 894 895
		return check_condition_result;
	}
	return 0;
}

896
/* Build SCSI "data-in" buffer. Returns 0 if ok else (DID_ERROR << 16). */
897
static int fill_from_dev_buffer(struct scsi_cmnd *scp, unsigned char *arr,
L
Linus Torvalds 已提交
898 899
				int arr_len)
{
900
	int act_len;
901
	struct scsi_data_buffer *sdb = scsi_in(scp);
L
Linus Torvalds 已提交
902

903
	if (!sdb->length)
L
Linus Torvalds 已提交
904
		return 0;
905
	if (!(scsi_bidi_cmnd(scp) || scp->sc_data_direction == DMA_FROM_DEVICE))
906
		return DID_ERROR << 16;
907 908 909

	act_len = sg_copy_from_buffer(sdb->table.sgl, sdb->table.nents,
				      arr, arr_len);
910
	sdb->resid = scsi_bufflen(scp) - act_len;
911

L
Linus Torvalds 已提交
912 913 914
	return 0;
}

915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943
/* Partial build of SCSI "data-in" buffer. Returns 0 if ok else
 * (DID_ERROR << 16). Can write to offset in data-in buffer. If multiple
 * calls, not required to write in ascending offset order. Assumes resid
 * set to scsi_bufflen() prior to any calls.
 */
static int p_fill_from_dev_buffer(struct scsi_cmnd *scp, const void *arr,
				  int arr_len, unsigned int off_dst)
{
	int act_len, n;
	struct scsi_data_buffer *sdb = scsi_in(scp);
	off_t skip = off_dst;

	if (sdb->length <= off_dst)
		return 0;
	if (!(scsi_bidi_cmnd(scp) || scp->sc_data_direction == DMA_FROM_DEVICE))
		return DID_ERROR << 16;

	act_len = sg_pcopy_from_buffer(sdb->table.sgl, sdb->table.nents,
				       arr, arr_len, skip);
	pr_debug("%s: off_dst=%u, scsi_bufflen=%u, act_len=%u, resid=%d\n",
		 __func__, off_dst, scsi_bufflen(scp), act_len, sdb->resid);
	n = (int)scsi_bufflen(scp) - ((int)off_dst + act_len);
	sdb->resid = min(sdb->resid, n);
	return 0;
}

/* Fetches from SCSI "data-out" buffer. Returns number of bytes fetched into
 * 'arr' or -1 if error.
 */
944 945
static int fetch_to_dev_buffer(struct scsi_cmnd *scp, unsigned char *arr,
			       int arr_len)
L
Linus Torvalds 已提交
946
{
947
	if (!scsi_bufflen(scp))
L
Linus Torvalds 已提交
948
		return 0;
949
	if (!(scsi_bidi_cmnd(scp) || scp->sc_data_direction == DMA_TO_DEVICE))
L
Linus Torvalds 已提交
950
		return -1;
951 952

	return scsi_sg_copy_to_buffer(scp, arr, arr_len);
L
Linus Torvalds 已提交
953 954 955
}


956 957 958
static char sdebug_inq_vendor_id[9] = "Linux   ";
static char sdebug_inq_product_id[17] = "scsi_debug      ";
static char sdebug_inq_product_rev[5] = "0186";	/* version less '.' */
959 960 961 962
/* Use some locally assigned NAAs for SAS addresses. */
static const u64 naa3_comp_a = 0x3222222000000000ULL;
static const u64 naa3_comp_b = 0x3333333000000000ULL;
static const u64 naa3_comp_c = 0x3111111000000000ULL;
L
Linus Torvalds 已提交
963

964
/* Device identification VPD page. Returns number of bytes placed in arr */
965 966
static int inquiry_vpd_83(unsigned char *arr, int port_group_id,
			  int target_dev_id, int dev_id_num,
D
Douglas Gilbert 已提交
967
			  const char *dev_id_str, int dev_id_str_len,
C
Christoph Hellwig 已提交
968
			  const uuid_t *lu_name)
L
Linus Torvalds 已提交
969
{
D
Douglas Gilbert 已提交
970 971
	int num, port_a;
	char b[32];
L
Linus Torvalds 已提交
972

D
Douglas Gilbert 已提交
973
	port_a = target_dev_id + 1;
L
Linus Torvalds 已提交
974 975 976 977
	/* T10 vendor identifier field format (faked) */
	arr[0] = 0x2;	/* ASCII */
	arr[1] = 0x1;
	arr[2] = 0x0;
978 979
	memcpy(&arr[4], sdebug_inq_vendor_id, 8);
	memcpy(&arr[12], sdebug_inq_product_id, 16);
L
Linus Torvalds 已提交
980 981 982 983
	memcpy(&arr[28], dev_id_str, dev_id_str_len);
	num = 8 + 16 + dev_id_str_len;
	arr[3] = num;
	num += 4;
D
Douglas Gilbert 已提交
984
	if (dev_id_num >= 0) {
D
Douglas Gilbert 已提交
985 986 987 988 989 990 991 992 993 994 995
		if (sdebug_uuid_ctl) {
			/* Locally assigned UUID */
			arr[num++] = 0x1;  /* binary (not necessarily sas) */
			arr[num++] = 0xa;  /* PIV=0, lu, naa */
			arr[num++] = 0x0;
			arr[num++] = 0x12;
			arr[num++] = 0x10; /* uuid type=1, locally assigned */
			arr[num++] = 0x0;
			memcpy(arr + num, lu_name, 16);
			num += 16;
		} else {
996
			/* NAA-3, Logical unit identifier (binary) */
D
Douglas Gilbert 已提交
997 998 999 1000
			arr[num++] = 0x1;  /* binary (not necessarily sas) */
			arr[num++] = 0x3;  /* PIV=0, lu, naa */
			arr[num++] = 0x0;
			arr[num++] = 0x8;
1001
			put_unaligned_be64(naa3_comp_b + dev_id_num, arr + num);
D
Douglas Gilbert 已提交
1002 1003
			num += 8;
		}
D
Douglas Gilbert 已提交
1004 1005 1006 1007 1008 1009 1010 1011 1012 1013
		/* Target relative port number */
		arr[num++] = 0x61;	/* proto=sas, binary */
		arr[num++] = 0x94;	/* PIV=1, target port, rel port */
		arr[num++] = 0x0;	/* reserved */
		arr[num++] = 0x4;	/* length */
		arr[num++] = 0x0;	/* reserved */
		arr[num++] = 0x0;	/* reserved */
		arr[num++] = 0x0;
		arr[num++] = 0x1;	/* relative port A */
	}
1014
	/* NAA-3, Target port identifier */
D
Douglas Gilbert 已提交
1015 1016 1017 1018
	arr[num++] = 0x61;	/* proto=sas, binary */
	arr[num++] = 0x93;	/* piv=1, target port, naa */
	arr[num++] = 0x0;
	arr[num++] = 0x8;
1019
	put_unaligned_be64(naa3_comp_a + port_a, arr + num);
1020
	num += 8;
1021
	/* NAA-3, Target port group identifier */
1022 1023 1024 1025 1026 1027
	arr[num++] = 0x61;	/* proto=sas, binary */
	arr[num++] = 0x95;	/* piv=1, target port group id */
	arr[num++] = 0x0;
	arr[num++] = 0x4;
	arr[num++] = 0;
	arr[num++] = 0;
1028 1029
	put_unaligned_be16(port_group_id, arr + num);
	num += 2;
1030
	/* NAA-3, Target device identifier */
D
Douglas Gilbert 已提交
1031 1032 1033 1034
	arr[num++] = 0x61;	/* proto=sas, binary */
	arr[num++] = 0xa3;	/* piv=1, target device, naa */
	arr[num++] = 0x0;
	arr[num++] = 0x8;
1035
	put_unaligned_be64(naa3_comp_a + target_dev_id, arr + num);
1036
	num += 8;
D
Douglas Gilbert 已提交
1037 1038 1039 1040 1041
	/* SCSI name string: Target device identifier */
	arr[num++] = 0x63;	/* proto=sas, UTF-8 */
	arr[num++] = 0xa8;	/* piv=1, target device, SCSI name string */
	arr[num++] = 0x0;
	arr[num++] = 24;
1042
	memcpy(arr + num, "naa.32222220", 12);
D
Douglas Gilbert 已提交
1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057
	num += 12;
	snprintf(b, sizeof(b), "%08X", target_dev_id);
	memcpy(arr + num, b, 8);
	num += 8;
	memset(arr + num, 0, 4);
	num += 4;
	return num;
}

static unsigned char vpd84_data[] = {
/* from 4th byte */ 0x22,0x22,0x22,0x0,0xbb,0x0,
    0x22,0x22,0x22,0x0,0xbb,0x1,
    0x22,0x22,0x22,0x0,0xbb,0x2,
};

1058
/*  Software interface identification VPD page */
1059
static int inquiry_vpd_84(unsigned char *arr)
D
Douglas Gilbert 已提交
1060 1061 1062 1063 1064
{
	memcpy(arr, vpd84_data, sizeof(vpd84_data));
	return sizeof(vpd84_data);
}

1065
/* Management network addresses VPD page */
1066
static int inquiry_vpd_85(unsigned char *arr)
D
Douglas Gilbert 已提交
1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100
{
	int num = 0;
	const char * na1 = "https://www.kernel.org/config";
	const char * na2 = "http://www.kernel.org/log";
	int plen, olen;

	arr[num++] = 0x1;	/* lu, storage config */
	arr[num++] = 0x0;	/* reserved */
	arr[num++] = 0x0;
	olen = strlen(na1);
	plen = olen + 1;
	if (plen % 4)
		plen = ((plen / 4) + 1) * 4;
	arr[num++] = plen;	/* length, null termianted, padded */
	memcpy(arr + num, na1, olen);
	memset(arr + num + olen, 0, plen - olen);
	num += plen;

	arr[num++] = 0x4;	/* lu, logging */
	arr[num++] = 0x0;	/* reserved */
	arr[num++] = 0x0;
	olen = strlen(na2);
	plen = olen + 1;
	if (plen % 4)
		plen = ((plen / 4) + 1) * 4;
	arr[num++] = plen;	/* length, null terminated, padded */
	memcpy(arr + num, na2, olen);
	memset(arr + num + olen, 0, plen - olen);
	num += plen;

	return num;
}

/* SCSI ports VPD page */
1101
static int inquiry_vpd_88(unsigned char *arr, int target_dev_id)
D
Douglas Gilbert 已提交
1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120
{
	int num = 0;
	int port_a, port_b;

	port_a = target_dev_id + 1;
	port_b = port_a + 1;
	arr[num++] = 0x0;	/* reserved */
	arr[num++] = 0x0;	/* reserved */
	arr[num++] = 0x0;
	arr[num++] = 0x1;	/* relative port 1 (primary) */
	memset(arr + num, 0, 6);
	num += 6;
	arr[num++] = 0x0;
	arr[num++] = 12;	/* length tp descriptor */
	/* naa-5 target port identifier (A) */
	arr[num++] = 0x61;	/* proto=sas, binary */
	arr[num++] = 0x93;	/* PIV=1, target port, NAA */
	arr[num++] = 0x0;	/* reserved */
	arr[num++] = 0x8;	/* length */
1121
	put_unaligned_be64(naa3_comp_a + port_a, arr + num);
1122
	num += 8;
D
Douglas Gilbert 已提交
1123 1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135
	arr[num++] = 0x0;	/* reserved */
	arr[num++] = 0x0;	/* reserved */
	arr[num++] = 0x0;
	arr[num++] = 0x2;	/* relative port 2 (secondary) */
	memset(arr + num, 0, 6);
	num += 6;
	arr[num++] = 0x0;
	arr[num++] = 12;	/* length tp descriptor */
	/* naa-5 target port identifier (B) */
	arr[num++] = 0x61;	/* proto=sas, binary */
	arr[num++] = 0x93;	/* PIV=1, target port, NAA */
	arr[num++] = 0x0;	/* reserved */
	arr[num++] = 0x8;	/* length */
1136
	put_unaligned_be64(naa3_comp_a + port_b, arr + num);
1137
	num += 8;
D
Douglas Gilbert 已提交
1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186

	return num;
}


static unsigned char vpd89_data[] = {
/* from 4th byte */ 0,0,0,0,
'l','i','n','u','x',' ',' ',' ',
'S','A','T',' ','s','c','s','i','_','d','e','b','u','g',' ',' ',
'1','2','3','4',
0x34,0,0,0,1,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,
0xec,0,0,0,
0x5a,0xc,0xff,0x3f,0x37,0xc8,0x10,0,0,0,0,0,0x3f,0,0,0,
0,0,0,0,0x58,0x58,0x58,0x58,0x58,0x58,0x58,0x58,0x20,0x20,0x20,0x20,
0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0,0,0,0x40,0x4,0,0x2e,0x33,
0x38,0x31,0x20,0x20,0x20,0x20,0x54,0x53,0x38,0x33,0x30,0x30,0x33,0x31,
0x53,0x41,
0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,
0x20,0x20,
0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,0x20,
0x10,0x80,
0,0,0,0x2f,0,0,0,0x2,0,0x2,0x7,0,0xff,0xff,0x1,0,
0x3f,0,0xc1,0xff,0x3e,0,0x10,0x1,0xb0,0xf8,0x50,0x9,0,0,0x7,0,
0x3,0,0x78,0,0x78,0,0xf0,0,0x78,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0x2,0,0,0,0,0,0,0,
0x7e,0,0x1b,0,0x6b,0x34,0x1,0x7d,0x3,0x40,0x69,0x34,0x1,0x3c,0x3,0x40,
0x7f,0x40,0,0,0,0,0xfe,0xfe,0,0,0,0,0,0xfe,0,0,
0,0,0,0,0,0,0,0,0xb0,0xf8,0x50,0x9,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0x1,0,0xb0,0xf8,0x50,0x9,0xb0,0xf8,0x50,0x9,0x20,0x20,0x2,0,0xb6,0x42,
0,0x80,0x8a,0,0x6,0x3c,0xa,0x3c,0xff,0xff,0xc6,0x7,0,0x1,0,0x8,
0xf0,0xf,0,0x10,0x2,0,0x30,0,0,0,0,0,0,0,0x6,0xfe,
0,0,0x2,0,0x50,0,0x8a,0,0x4f,0x95,0,0,0x21,0,0xb,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0xa5,0x51,
};

1187
/* ATA Information VPD page */
1188
static int inquiry_vpd_89(unsigned char *arr)
D
Douglas Gilbert 已提交
1189 1190 1191 1192 1193 1194 1195
{
	memcpy(arr, vpd89_data, sizeof(vpd89_data));
	return sizeof(vpd89_data);
}


static unsigned char vpdb0_data[] = {
1196 1197 1198 1199
	/* from 4th byte */ 0,0,0,4, 0,0,0x4,0, 0,0,0,64,
	0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
	0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
	0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
D
Douglas Gilbert 已提交
1200 1201
};

1202
/* Block limits VPD page (SBC-3) */
1203
static int inquiry_vpd_b0(unsigned char *arr)
D
Douglas Gilbert 已提交
1204
{
1205 1206
	unsigned int gran;

D
Douglas Gilbert 已提交
1207
	memcpy(arr, vpdb0_data, sizeof(vpdb0_data));
1208 1209

	/* Optimal transfer length granularity */
1210 1211 1212 1213 1214
	if (sdebug_opt_xferlen_exp != 0 &&
	    sdebug_physblk_exp < sdebug_opt_xferlen_exp)
		gran = 1 << sdebug_opt_xferlen_exp;
	else
		gran = 1 << sdebug_physblk_exp;
1215
	put_unaligned_be16(gran, arr + 2);
1216 1217

	/* Maximum Transfer Length */
1218 1219
	if (sdebug_store_sectors > 0x400)
		put_unaligned_be32(sdebug_store_sectors, arr + 4);
1220

1221
	/* Optimal Transfer Length */
1222
	put_unaligned_be32(sdebug_opt_blks, &arr[8]);
1223

1224
	if (sdebug_lbpu) {
1225
		/* Maximum Unmap LBA Count */
1226
		put_unaligned_be32(sdebug_unmap_max_blocks, &arr[16]);
1227 1228

		/* Maximum Unmap Block Descriptor Count */
1229
		put_unaligned_be32(sdebug_unmap_max_desc, &arr[20]);
1230 1231
	}

1232
	/* Unmap Granularity Alignment */
1233 1234
	if (sdebug_unmap_alignment) {
		put_unaligned_be32(sdebug_unmap_alignment, &arr[28]);
1235 1236 1237
		arr[28] |= 0x80; /* UGAVALID */
	}

1238
	/* Optimal Unmap Granularity */
1239
	put_unaligned_be32(sdebug_unmap_granularity, &arr[24]);
1240

1241
	/* Maximum WRITE SAME Length */
1242
	put_unaligned_be64(sdebug_write_same_length, &arr[32]);
1243 1244

	return 0x3c; /* Mandatory page length for Logical Block Provisioning */
1245

D
Douglas Gilbert 已提交
1246
	return sizeof(vpdb0_data);
L
Linus Torvalds 已提交
1247 1248
}

1249
/* Block device characteristics VPD page (SBC-3) */
1250
static int inquiry_vpd_b1(unsigned char *arr)
1251 1252 1253
{
	memset(arr, 0, 0x3c);
	arr[0] = 0;
1254 1255 1256
	arr[1] = 1;	/* non rotating medium (e.g. solid state) */
	arr[2] = 0;
	arr[3] = 5;	/* less than 1.8" */
1257 1258 1259

	return 0x3c;
}
L
Linus Torvalds 已提交
1260

1261 1262
/* Logical block provisioning VPD page (SBC-4) */
static int inquiry_vpd_b2(unsigned char *arr)
1263
{
1264
	memset(arr, 0, 0x4);
1265
	arr[0] = 0;			/* threshold exponent */
1266
	if (sdebug_lbpu)
1267
		arr[1] = 1 << 7;
1268
	if (sdebug_lbpws)
1269
		arr[1] |= 1 << 6;
1270
	if (sdebug_lbpws10)
1271
		arr[1] |= 1 << 5;
1272 1273 1274 1275 1276
	if (sdebug_lbprz && scsi_debug_lbp())
		arr[1] |= (sdebug_lbprz & 0x7) << 2;  /* sbc4r07 and later */
	/* anc_sup=0; dp=0 (no provisioning group descriptor) */
	/* minimum_percentage=0; provisioning_type=0 (unknown) */
	/* threshold_percentage=0 */
1277
	return 0x4;
1278 1279
}

L
Linus Torvalds 已提交
1280
#define SDEBUG_LONG_INQ_SZ 96
D
Douglas Gilbert 已提交
1281
#define SDEBUG_MAX_INQ_ARR_SZ 584
L
Linus Torvalds 已提交
1282

1283
static int resp_inquiry(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
L
Linus Torvalds 已提交
1284 1285
{
	unsigned char pq_pdt;
1286
	unsigned char * arr;
1287
	unsigned char *cmd = scp->cmnd;
1288
	int alloc_len, n, ret;
1289
	bool have_wlun, is_disk;
L
Linus Torvalds 已提交
1290

1291
	alloc_len = get_unaligned_be16(cmd + 3);
1292 1293 1294
	arr = kzalloc(SDEBUG_MAX_INQ_ARR_SZ, GFP_ATOMIC);
	if (! arr)
		return DID_REQUEUE << 16;
1295
	is_disk = (sdebug_ptype == TYPE_DISK);
D
Douglas Gilbert 已提交
1296
	have_wlun = scsi_is_wlun(scp->device->lun);
1297
	if (have_wlun)
D
Douglas Gilbert 已提交
1298 1299 1300
		pq_pdt = TYPE_WLUN;	/* present, wlun */
	else if (sdebug_no_lun_0 && (devip->lun == SDEBUG_LUN_0_VAL))
		pq_pdt = 0x7f;	/* not present, PQ=3, PDT=0x1f */
D
Douglas Gilbert 已提交
1301
	else
1302
		pq_pdt = (sdebug_ptype & 0x1f);
L
Linus Torvalds 已提交
1303 1304
	arr[0] = pq_pdt;
	if (0x2 & cmd[1]) {  /* CMDDT bit set */
1305
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, 1);
1306
		kfree(arr);
L
Linus Torvalds 已提交
1307 1308
		return check_condition_result;
	} else if (0x1 & cmd[1]) {  /* EVPD bit set */
1309
		int lu_id_num, port_group_id, target_dev_id, len;
D
Douglas Gilbert 已提交
1310 1311
		char lu_id_str[6];
		int host_no = devip->sdbg_host->shost->host_no;
L
Linus Torvalds 已提交
1312
		
1313 1314
		port_group_id = (((host_no + 1) & 0x7f) << 8) +
		    (devip->channel & 0x7f);
D
Douglas Gilbert 已提交
1315
		if (sdebug_vpd_use_hostno == 0)
D
Douglas Gilbert 已提交
1316
			host_no = 0;
1317
		lu_id_num = have_wlun ? -1 : (((host_no + 1) * 2000) +
D
Douglas Gilbert 已提交
1318 1319 1320 1321
			    (devip->target * 1000) + devip->lun);
		target_dev_id = ((host_no + 1) * 2000) +
				 (devip->target * 1000) - 3;
		len = scnprintf(lu_id_str, 6, "%d", lu_id_num);
L
Linus Torvalds 已提交
1322
		if (0 == cmd[2]) { /* supported vital product data pages */
D
Douglas Gilbert 已提交
1323 1324 1325 1326 1327 1328 1329 1330 1331 1332
			arr[1] = cmd[2];	/*sanity */
			n = 4;
			arr[n++] = 0x0;   /* this page */
			arr[n++] = 0x80;  /* unit serial number */
			arr[n++] = 0x83;  /* device identification */
			arr[n++] = 0x84;  /* software interface ident. */
			arr[n++] = 0x85;  /* management network addresses */
			arr[n++] = 0x86;  /* extended inquiry */
			arr[n++] = 0x87;  /* mode page policy */
			arr[n++] = 0x88;  /* SCSI ports */
1333 1334 1335 1336 1337 1338
			if (is_disk) {	  /* SBC only */
				arr[n++] = 0x89;  /* ATA information */
				arr[n++] = 0xb0;  /* Block limits */
				arr[n++] = 0xb1;  /* Block characteristics */
				arr[n++] = 0xb2;  /* Logical Block Prov */
			}
D
Douglas Gilbert 已提交
1339
			arr[3] = n - 4;	  /* number of supported VPD pages */
L
Linus Torvalds 已提交
1340
		} else if (0x80 == cmd[2]) { /* unit serial number */
D
Douglas Gilbert 已提交
1341
			arr[1] = cmd[2];	/*sanity */
L
Linus Torvalds 已提交
1342
			arr[3] = len;
D
Douglas Gilbert 已提交
1343
			memcpy(&arr[4], lu_id_str, len);
L
Linus Torvalds 已提交
1344
		} else if (0x83 == cmd[2]) { /* device identification */
D
Douglas Gilbert 已提交
1345
			arr[1] = cmd[2];	/*sanity */
1346 1347
			arr[3] = inquiry_vpd_83(&arr[4], port_group_id,
						target_dev_id, lu_id_num,
D
Douglas Gilbert 已提交
1348 1349
						lu_id_str, len,
						&devip->lu_name);
D
Douglas Gilbert 已提交
1350 1351
		} else if (0x84 == cmd[2]) { /* Software interface ident. */
			arr[1] = cmd[2];	/*sanity */
1352
			arr[3] = inquiry_vpd_84(&arr[4]);
D
Douglas Gilbert 已提交
1353 1354
		} else if (0x85 == cmd[2]) { /* Management network addresses */
			arr[1] = cmd[2];	/*sanity */
1355
			arr[3] = inquiry_vpd_85(&arr[4]);
D
Douglas Gilbert 已提交
1356 1357 1358
		} else if (0x86 == cmd[2]) { /* extended inquiry */
			arr[1] = cmd[2];	/*sanity */
			arr[3] = 0x3c;	/* number of following entries */
1359
			if (sdebug_dif == T10_PI_TYPE3_PROTECTION)
1360
				arr[4] = 0x4;	/* SPT: GRD_CHK:1 */
1361
			else if (have_dif_prot)
1362 1363 1364
				arr[4] = 0x5;   /* SPT: GRD_CHK:1, REF_CHK:1 */
			else
				arr[4] = 0x0;   /* no protection stuff */
D
Douglas Gilbert 已提交
1365 1366 1367 1368 1369 1370 1371 1372 1373 1374
			arr[5] = 0x7;   /* head of q, ordered + simple q's */
		} else if (0x87 == cmd[2]) { /* mode page policy */
			arr[1] = cmd[2];	/*sanity */
			arr[3] = 0x8;	/* number of following entries */
			arr[4] = 0x2;	/* disconnect-reconnect mp */
			arr[6] = 0x80;	/* mlus, shared */
			arr[8] = 0x18;	 /* protocol specific lu */
			arr[10] = 0x82;	 /* mlus, per initiator port */
		} else if (0x88 == cmd[2]) { /* SCSI Ports */
			arr[1] = cmd[2];	/*sanity */
1375 1376
			arr[3] = inquiry_vpd_88(&arr[4], target_dev_id);
		} else if (is_disk && 0x89 == cmd[2]) { /* ATA information */
D
Douglas Gilbert 已提交
1377
			arr[1] = cmd[2];        /*sanity */
1378
			n = inquiry_vpd_89(&arr[4]);
1379
			put_unaligned_be16(n, arr + 2);
1380
		} else if (is_disk && 0xb0 == cmd[2]) { /* Block limits */
D
Douglas Gilbert 已提交
1381
			arr[1] = cmd[2];        /*sanity */
1382 1383
			arr[3] = inquiry_vpd_b0(&arr[4]);
		} else if (is_disk && 0xb1 == cmd[2]) { /* Block char. */
1384
			arr[1] = cmd[2];        /*sanity */
1385 1386
			arr[3] = inquiry_vpd_b1(&arr[4]);
		} else if (is_disk && 0xb2 == cmd[2]) { /* LB Prov. */
1387
			arr[1] = cmd[2];        /*sanity */
1388
			arr[3] = inquiry_vpd_b2(&arr[4]);
L
Linus Torvalds 已提交
1389
		} else {
1390
			mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, -1);
1391
			kfree(arr);
L
Linus Torvalds 已提交
1392 1393
			return check_condition_result;
		}
1394
		len = min(get_unaligned_be16(arr + 2) + 4, alloc_len);
1395
		ret = fill_from_dev_buffer(scp, arr,
D
Douglas Gilbert 已提交
1396
			    min(len, SDEBUG_MAX_INQ_ARR_SZ));
1397 1398
		kfree(arr);
		return ret;
L
Linus Torvalds 已提交
1399 1400
	}
	/* drops through here for a standard inquiry */
1401 1402
	arr[1] = sdebug_removable ? 0x80 : 0;	/* Removable disk */
	arr[2] = sdebug_scsi_level;
L
Linus Torvalds 已提交
1403 1404
	arr[3] = 2;    /* response_data_format==2 */
	arr[4] = SDEBUG_LONG_INQ_SZ - 5;
1405
	arr[5] = (int)have_dif_prot;	/* PROTECT bit */
D
Douglas Gilbert 已提交
1406
	if (sdebug_vpd_use_hostno == 0)
1407
		arr[5] |= 0x10; /* claim: implicit TPGS */
D
Douglas Gilbert 已提交
1408
	arr[6] = 0x10; /* claim: MultiP */
L
Linus Torvalds 已提交
1409
	/* arr[6] |= 0x40; ... claim: EncServ (enclosure services) */
D
Douglas Gilbert 已提交
1410
	arr[7] = 0xa; /* claim: LINKED + CMDQUE */
1411 1412 1413
	memcpy(&arr[8], sdebug_inq_vendor_id, 8);
	memcpy(&arr[16], sdebug_inq_product_id, 16);
	memcpy(&arr[32], sdebug_inq_product_rev, 4);
L
Linus Torvalds 已提交
1414
	/* version descriptors (2 bytes each) follow */
1415 1416
	put_unaligned_be16(0xc0, arr + 58);   /* SAM-6 no version claimed */
	put_unaligned_be16(0x5c0, arr + 60);  /* SPC-5 no version claimed */
D
Douglas Gilbert 已提交
1417
	n = 62;
1418 1419 1420 1421 1422 1423
	if (is_disk) {		/* SBC-4 no version claimed */
		put_unaligned_be16(0x600, arr + n);
		n += 2;
	} else if (sdebug_ptype == TYPE_TAPE) {	/* SSC-4 rev 3 */
		put_unaligned_be16(0x525, arr + n);
		n += 2;
L
Linus Torvalds 已提交
1424
	}
1425
	put_unaligned_be16(0x2100, arr + n);	/* SPL-4 no version claimed */
1426
	ret = fill_from_dev_buffer(scp, arr,
L
Linus Torvalds 已提交
1427
			    min(alloc_len, SDEBUG_LONG_INQ_SZ));
1428 1429
	kfree(arr);
	return ret;
L
Linus Torvalds 已提交
1430 1431
}

1432 1433 1434
static unsigned char iec_m_pg[] = {0x1c, 0xa, 0x08, 0, 0, 0, 0, 0,
				   0, 0, 0x0, 0x0};

L
Linus Torvalds 已提交
1435 1436 1437 1438
static int resp_requests(struct scsi_cmnd * scp,
			 struct sdebug_dev_info * devip)
{
	unsigned char * sbuff;
1439
	unsigned char *cmd = scp->cmnd;
1440
	unsigned char arr[SCSI_SENSE_BUFFERSIZE];
1441
	bool dsense;
L
Linus Torvalds 已提交
1442 1443
	int len = 18;

D
Douglas Gilbert 已提交
1444
	memset(arr, 0, sizeof(arr));
1445
	dsense = !!(cmd[1] & 1);
1446
	sbuff = scp->sense_buffer;
D
Douglas Gilbert 已提交
1447
	if ((iec_m_pg[2] & 0x4) && (6 == (iec_m_pg[3] & 0xf))) {
1448
		if (dsense) {
D
Douglas Gilbert 已提交
1449 1450 1451 1452
			arr[0] = 0x72;
			arr[1] = 0x0;		/* NO_SENSE in sense_key */
			arr[2] = THRESHOLD_EXCEEDED;
			arr[3] = 0xff;		/* TEST set and MRIE==6 */
1453
			len = 8;
D
Douglas Gilbert 已提交
1454 1455 1456 1457 1458 1459 1460 1461
		} else {
			arr[0] = 0x70;
			arr[2] = 0x0;		/* NO_SENSE in sense_key */
			arr[7] = 0xa;   	/* 18 byte sense buffer */
			arr[12] = THRESHOLD_EXCEEDED;
			arr[13] = 0xff;		/* TEST set and MRIE==6 */
		}
	} else {
1462
		memcpy(arr, sbuff, SCSI_SENSE_BUFFERSIZE);
1463
		if (arr[0] >= 0x70 && dsense == sdebug_dsense)
1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476
			;	/* have sense and formats match */
		else if (arr[0] <= 0x70) {
			if (dsense) {
				memset(arr, 0, 8);
				arr[0] = 0x72;
				len = 8;
			} else {
				memset(arr, 0, 18);
				arr[0] = 0x70;
				arr[7] = 0xa;
			}
		} else if (dsense) {
			memset(arr, 0, 8);
D
Douglas Gilbert 已提交
1477 1478 1479 1480 1481
			arr[0] = 0x72;
			arr[1] = sbuff[2];     /* sense key */
			arr[2] = sbuff[12];    /* asc */
			arr[3] = sbuff[13];    /* ascq */
			len = 8;
1482 1483 1484 1485 1486 1487 1488
		} else {
			memset(arr, 0, 18);
			arr[0] = 0x70;
			arr[2] = sbuff[1];
			arr[7] = 0xa;
			arr[12] = sbuff[1];
			arr[13] = sbuff[3];
D
Douglas Gilbert 已提交
1489
		}
1490

D
Douglas Gilbert 已提交
1491
	}
1492
	mk_sense_buffer(scp, 0, NO_ADDITIONAL_SENSE, 0);
L
Linus Torvalds 已提交
1493 1494 1495
	return fill_from_dev_buffer(scp, arr, len);
}

D
Douglas Gilbert 已提交
1496 1497 1498
static int resp_start_stop(struct scsi_cmnd * scp,
			   struct sdebug_dev_info * devip)
{
1499
	unsigned char *cmd = scp->cmnd;
1500
	int power_cond, stop;
D
Douglas Gilbert 已提交
1501 1502 1503

	power_cond = (cmd[4] & 0xf0) >> 4;
	if (power_cond) {
1504
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 4, 7);
D
Douglas Gilbert 已提交
1505 1506
		return check_condition_result;
	}
1507 1508
	stop = !(cmd[4] & 1);
	atomic_xchg(&devip->stopped, stop);
D
Douglas Gilbert 已提交
1509 1510 1511
	return 0;
}

1512 1513
static sector_t get_sdebug_capacity(void)
{
1514 1515 1516 1517 1518
	static const unsigned int gibibyte = 1073741824;

	if (sdebug_virtual_gb > 0)
		return (sector_t)sdebug_virtual_gb *
			(gibibyte / sdebug_sector_size);
1519 1520 1521 1522
	else
		return sdebug_store_sectors;
}

L
Linus Torvalds 已提交
1523 1524 1525 1526 1527
#define SDEBUG_READCAP_ARR_SZ 8
static int resp_readcap(struct scsi_cmnd * scp,
			struct sdebug_dev_info * devip)
{
	unsigned char arr[SDEBUG_READCAP_ARR_SZ];
D
Douglas Gilbert 已提交
1528
	unsigned int capac;
L
Linus Torvalds 已提交
1529

D
Douglas Gilbert 已提交
1530
	/* following just in case virtual_gb changed */
1531
	sdebug_capacity = get_sdebug_capacity();
L
Linus Torvalds 已提交
1532
	memset(arr, 0, SDEBUG_READCAP_ARR_SZ);
D
Douglas Gilbert 已提交
1533 1534
	if (sdebug_capacity < 0xffffffff) {
		capac = (unsigned int)sdebug_capacity - 1;
1535 1536 1537 1538
		put_unaligned_be32(capac, arr + 0);
	} else
		put_unaligned_be32(0xffffffff, arr + 0);
	put_unaligned_be16(sdebug_sector_size, arr + 6);
L
Linus Torvalds 已提交
1539 1540 1541
	return fill_from_dev_buffer(scp, arr, SDEBUG_READCAP_ARR_SZ);
}

D
Douglas Gilbert 已提交
1542 1543 1544 1545
#define SDEBUG_READCAP16_ARR_SZ 32
static int resp_readcap16(struct scsi_cmnd * scp,
			  struct sdebug_dev_info * devip)
{
1546
	unsigned char *cmd = scp->cmnd;
D
Douglas Gilbert 已提交
1547
	unsigned char arr[SDEBUG_READCAP16_ARR_SZ];
1548
	int alloc_len;
D
Douglas Gilbert 已提交
1549

1550
	alloc_len = get_unaligned_be32(cmd + 10);
D
Douglas Gilbert 已提交
1551
	/* following just in case virtual_gb changed */
1552
	sdebug_capacity = get_sdebug_capacity();
D
Douglas Gilbert 已提交
1553
	memset(arr, 0, SDEBUG_READCAP16_ARR_SZ);
1554 1555 1556 1557
	put_unaligned_be64((u64)(sdebug_capacity - 1), arr + 0);
	put_unaligned_be32(sdebug_sector_size, arr + 8);
	arr[13] = sdebug_physblk_exp & 0xf;
	arr[14] = (sdebug_lowest_aligned >> 8) & 0x3f;
1558

1559
	if (scsi_debug_lbp()) {
1560
		arr[14] |= 0x80; /* LBPME */
1561 1562 1563 1564 1565 1566
		/* from sbc4r07, this LBPRZ field is 1 bit, but the LBPRZ in
		 * the LB Provisioning VPD page is 3 bits. Note that lbprz=2
		 * in the wider field maps to 0 in this field.
		 */
		if (sdebug_lbprz & 1)	/* precisely what the draft requires */
			arr[14] |= 0x40;
1567
	}
1568

1569
	arr[15] = sdebug_lowest_aligned & 0xff;
1570

1571
	if (have_dif_prot) {
1572
		arr[12] = (sdebug_dif - 1) << 1; /* P_TYPE */
1573 1574 1575
		arr[12] |= 1; /* PROT_EN */
	}

D
Douglas Gilbert 已提交
1576 1577 1578 1579
	return fill_from_dev_buffer(scp, arr,
				    min(alloc_len, SDEBUG_READCAP16_ARR_SZ));
}

1580 1581 1582 1583 1584
#define SDEBUG_MAX_TGTPGS_ARR_SZ 1412

static int resp_report_tgtpgs(struct scsi_cmnd * scp,
			      struct sdebug_dev_info * devip)
{
1585
	unsigned char *cmd = scp->cmnd;
1586 1587 1588 1589 1590
	unsigned char * arr;
	int host_no = devip->sdbg_host->shost->host_no;
	int n, ret, alen, rlen;
	int port_group_a, port_group_b, port_a, port_b;

1591
	alen = get_unaligned_be32(cmd + 6);
1592 1593 1594
	arr = kzalloc(SDEBUG_MAX_TGTPGS_ARR_SZ, GFP_ATOMIC);
	if (! arr)
		return DID_REQUEUE << 16;
1595 1596 1597 1598 1599 1600 1601 1602 1603
	/*
	 * EVPD page 0x88 states we have two ports, one
	 * real and a fake port with no device connected.
	 * So we create two port groups with one port each
	 * and set the group with port B to unavailable.
	 */
	port_a = 0x1; /* relative port A */
	port_b = 0x2; /* relative port B */
	port_group_a = (((host_no + 1) & 0x7f) << 8) +
1604
			(devip->channel & 0x7f);
1605
	port_group_b = (((host_no + 1) & 0x7f) << 8) +
1606
			(devip->channel & 0x7f) + 0x80;
1607 1608 1609 1610 1611

	/*
	 * The asymmetric access state is cycled according to the host_id.
	 */
	n = 4;
D
Douglas Gilbert 已提交
1612
	if (sdebug_vpd_use_hostno == 0) {
1613 1614
		arr[n++] = host_no % 3; /* Asymm access state */
		arr[n++] = 0x0F; /* claim: all states are supported */
1615
	} else {
1616 1617
		arr[n++] = 0x0; /* Active/Optimized path */
		arr[n++] = 0x01; /* only support active/optimized paths */
1618
	}
1619 1620
	put_unaligned_be16(port_group_a, arr + n);
	n += 2;
1621 1622 1623 1624 1625 1626
	arr[n++] = 0;    /* Reserved */
	arr[n++] = 0;    /* Status code */
	arr[n++] = 0;    /* Vendor unique */
	arr[n++] = 0x1;  /* One port per group */
	arr[n++] = 0;    /* Reserved */
	arr[n++] = 0;    /* Reserved */
1627 1628
	put_unaligned_be16(port_a, arr + n);
	n += 2;
1629 1630
	arr[n++] = 3;    /* Port unavailable */
	arr[n++] = 0x08; /* claim: only unavailalbe paths are supported */
1631 1632
	put_unaligned_be16(port_group_b, arr + n);
	n += 2;
1633 1634 1635 1636 1637 1638
	arr[n++] = 0;    /* Reserved */
	arr[n++] = 0;    /* Status code */
	arr[n++] = 0;    /* Vendor unique */
	arr[n++] = 0x1;  /* One port per group */
	arr[n++] = 0;    /* Reserved */
	arr[n++] = 0;    /* Reserved */
1639 1640
	put_unaligned_be16(port_b, arr + n);
	n += 2;
1641 1642

	rlen = n - 4;
1643
	put_unaligned_be32(rlen, arr + 0);
1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657

	/*
	 * Return the smallest value of either
	 * - The allocated length
	 * - The constructed command length
	 * - The maximum array size
	 */
	rlen = min(alen,n);
	ret = fill_from_dev_buffer(scp, arr,
				   min(rlen, SDEBUG_MAX_TGTPGS_ARR_SZ));
	kfree(arr);
	return ret;
}

1658 1659
static int resp_rsup_opcodes(struct scsi_cmnd *scp,
			     struct sdebug_dev_info *devip)
1660 1661 1662 1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673 1674 1675
{
	bool rctd;
	u8 reporting_opts, req_opcode, sdeb_i, supp;
	u16 req_sa, u;
	u32 alloc_len, a_len;
	int k, offset, len, errsts, count, bump, na;
	const struct opcode_info_t *oip;
	const struct opcode_info_t *r_oip;
	u8 *arr;
	u8 *cmd = scp->cmnd;

	rctd = !!(cmd[2] & 0x80);
	reporting_opts = cmd[2] & 0x7;
	req_opcode = cmd[3];
	req_sa = get_unaligned_be16(cmd + 4);
	alloc_len = get_unaligned_be32(cmd + 6);
1676
	if (alloc_len < 4 || alloc_len > 0xffff) {
1677 1678 1679 1680 1681 1682 1683
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 6, -1);
		return check_condition_result;
	}
	if (alloc_len > 8192)
		a_len = 8192;
	else
		a_len = alloc_len;
1684
	arr = kzalloc((a_len < 256) ? 320 : a_len + 64, GFP_ATOMIC);
1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706 1707 1708 1709 1710 1711 1712 1713 1714 1715 1716 1717 1718 1719 1720 1721 1722 1723 1724 1725 1726 1727 1728 1729 1730 1731 1732 1733 1734 1735 1736 1737 1738 1739 1740 1741 1742 1743 1744 1745 1746 1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787 1788 1789 1790 1791 1792 1793 1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804 1805 1806 1807 1808
	if (NULL == arr) {
		mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
				INSUFF_RES_ASCQ);
		return check_condition_result;
	}
	switch (reporting_opts) {
	case 0:	/* all commands */
		/* count number of commands */
		for (count = 0, oip = opcode_info_arr;
		     oip->num_attached != 0xff; ++oip) {
			if (F_INV_OP & oip->flags)
				continue;
			count += (oip->num_attached + 1);
		}
		bump = rctd ? 20 : 8;
		put_unaligned_be32(count * bump, arr);
		for (offset = 4, oip = opcode_info_arr;
		     oip->num_attached != 0xff && offset < a_len; ++oip) {
			if (F_INV_OP & oip->flags)
				continue;
			na = oip->num_attached;
			arr[offset] = oip->opcode;
			put_unaligned_be16(oip->sa, arr + offset + 2);
			if (rctd)
				arr[offset + 5] |= 0x2;
			if (FF_SA & oip->flags)
				arr[offset + 5] |= 0x1;
			put_unaligned_be16(oip->len_mask[0], arr + offset + 6);
			if (rctd)
				put_unaligned_be16(0xa, arr + offset + 8);
			r_oip = oip;
			for (k = 0, oip = oip->arrp; k < na; ++k, ++oip) {
				if (F_INV_OP & oip->flags)
					continue;
				offset += bump;
				arr[offset] = oip->opcode;
				put_unaligned_be16(oip->sa, arr + offset + 2);
				if (rctd)
					arr[offset + 5] |= 0x2;
				if (FF_SA & oip->flags)
					arr[offset + 5] |= 0x1;
				put_unaligned_be16(oip->len_mask[0],
						   arr + offset + 6);
				if (rctd)
					put_unaligned_be16(0xa,
							   arr + offset + 8);
			}
			oip = r_oip;
			offset += bump;
		}
		break;
	case 1:	/* one command: opcode only */
	case 2:	/* one command: opcode plus service action */
	case 3:	/* one command: if sa==0 then opcode only else opcode+sa */
		sdeb_i = opcode_ind_arr[req_opcode];
		oip = &opcode_info_arr[sdeb_i];
		if (F_INV_OP & oip->flags) {
			supp = 1;
			offset = 4;
		} else {
			if (1 == reporting_opts) {
				if (FF_SA & oip->flags) {
					mk_sense_invalid_fld(scp, SDEB_IN_CDB,
							     2, 2);
					kfree(arr);
					return check_condition_result;
				}
				req_sa = 0;
			} else if (2 == reporting_opts &&
				   0 == (FF_SA & oip->flags)) {
				mk_sense_invalid_fld(scp, SDEB_IN_CDB, 4, -1);
				kfree(arr);	/* point at requested sa */
				return check_condition_result;
			}
			if (0 == (FF_SA & oip->flags) &&
			    req_opcode == oip->opcode)
				supp = 3;
			else if (0 == (FF_SA & oip->flags)) {
				na = oip->num_attached;
				for (k = 0, oip = oip->arrp; k < na;
				     ++k, ++oip) {
					if (req_opcode == oip->opcode)
						break;
				}
				supp = (k >= na) ? 1 : 3;
			} else if (req_sa != oip->sa) {
				na = oip->num_attached;
				for (k = 0, oip = oip->arrp; k < na;
				     ++k, ++oip) {
					if (req_sa == oip->sa)
						break;
				}
				supp = (k >= na) ? 1 : 3;
			} else
				supp = 3;
			if (3 == supp) {
				u = oip->len_mask[0];
				put_unaligned_be16(u, arr + 2);
				arr[4] = oip->opcode;
				for (k = 1; k < u; ++k)
					arr[4 + k] = (k < 16) ?
						 oip->len_mask[k] : 0xff;
				offset = 4 + u;
			} else
				offset = 4;
		}
		arr[1] = (rctd ? 0x80 : 0) | supp;
		if (rctd) {
			put_unaligned_be16(0xa, arr + offset);
			offset += 12;
		}
		break;
	default:
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, 2);
		kfree(arr);
		return check_condition_result;
	}
	offset = (offset < a_len) ? offset : a_len;
	len = (offset < alloc_len) ? offset : alloc_len;
	errsts = fill_from_dev_buffer(scp, arr, len);
	kfree(arr);
	return errsts;
}

1809 1810
static int resp_rsup_tmfs(struct scsi_cmnd *scp,
			  struct sdebug_dev_info *devip)
1811 1812 1813 1814 1815 1816 1817 1818 1819 1820 1821 1822 1823 1824 1825 1826 1827 1828 1829 1830 1831 1832 1833 1834 1835
{
	bool repd;
	u32 alloc_len, len;
	u8 arr[16];
	u8 *cmd = scp->cmnd;

	memset(arr, 0, sizeof(arr));
	repd = !!(cmd[2] & 0x80);
	alloc_len = get_unaligned_be32(cmd + 6);
	if (alloc_len < 4) {
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 6, -1);
		return check_condition_result;
	}
	arr[0] = 0xc8;		/* ATS | ATSS | LURS */
	arr[1] = 0x1;		/* ITNRS */
	if (repd) {
		arr[3] = 0xc;
		len = 16;
	} else
		len = 4;

	len = (len < alloc_len) ? len : alloc_len;
	return fill_from_dev_buffer(scp, arr, len);
}

L
Linus Torvalds 已提交
1836 1837 1838 1839 1840 1841 1842 1843 1844 1845 1846 1847 1848 1849 1850 1851 1852 1853 1854 1855 1856 1857 1858 1859 1860 1861
/* <<Following mode page info copied from ST318451LW>> */

static int resp_err_recov_pg(unsigned char * p, int pcontrol, int target)
{	/* Read-Write Error Recovery page for mode_sense */
	unsigned char err_recov_pg[] = {0x1, 0xa, 0xc0, 11, 240, 0, 0, 0,
					5, 0, 0xff, 0xff};

	memcpy(p, err_recov_pg, sizeof(err_recov_pg));
	if (1 == pcontrol)
		memset(p + 2, 0, sizeof(err_recov_pg) - 2);
	return sizeof(err_recov_pg);
}

static int resp_disconnect_pg(unsigned char * p, int pcontrol, int target)
{ 	/* Disconnect-Reconnect page for mode_sense */
	unsigned char disconnect_pg[] = {0x2, 0xe, 128, 128, 0, 10, 0, 0,
					 0, 0, 0, 0, 0, 0, 0, 0};

	memcpy(p, disconnect_pg, sizeof(disconnect_pg));
	if (1 == pcontrol)
		memset(p + 2, 0, sizeof(disconnect_pg) - 2);
	return sizeof(disconnect_pg);
}

static int resp_format_pg(unsigned char * p, int pcontrol, int target)
{       /* Format device page for mode_sense */
1862 1863 1864 1865 1866
	unsigned char format_pg[] = {0x3, 0x16, 0, 0, 0, 0, 0, 0,
				     0, 0, 0, 0, 0, 0, 0, 0,
				     0, 0, 0, 0, 0x40, 0, 0, 0};

	memcpy(p, format_pg, sizeof(format_pg));
1867 1868 1869
	put_unaligned_be16(sdebug_sectors_per, p + 10);
	put_unaligned_be16(sdebug_sector_size, p + 12);
	if (sdebug_removable)
1870 1871 1872 1873
		p[20] |= 0x20; /* should agree with INQUIRY */
	if (1 == pcontrol)
		memset(p + 2, 0, sizeof(format_pg) - 2);
	return sizeof(format_pg);
L
Linus Torvalds 已提交
1874 1875
}

1876 1877 1878 1879
static unsigned char caching_pg[] = {0x8, 18, 0x14, 0, 0xff, 0xff, 0, 0,
				     0xff, 0xff, 0xff, 0xff, 0x80, 0x14, 0, 0,
				     0, 0, 0, 0};

L
Linus Torvalds 已提交
1880 1881
static int resp_caching_pg(unsigned char * p, int pcontrol, int target)
{ 	/* Caching page for mode_sense */
1882 1883 1884
	unsigned char ch_caching_pg[] = {/* 0x8, 18, */ 0x4, 0, 0, 0, 0, 0,
		0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0};
	unsigned char d_caching_pg[] = {0x8, 18, 0x14, 0, 0xff, 0xff, 0, 0,
L
Linus Torvalds 已提交
1885 1886
		0xff, 0xff, 0xff, 0xff, 0x80, 0x14, 0, 0,     0, 0, 0, 0};

1887
	if (SDEBUG_OPT_N_WCE & sdebug_opts)
1888
		caching_pg[2] &= ~0x4;	/* set WCE=0 (default WCE=1) */
L
Linus Torvalds 已提交
1889 1890
	memcpy(p, caching_pg, sizeof(caching_pg));
	if (1 == pcontrol)
1891 1892 1893
		memcpy(p + 2, ch_caching_pg, sizeof(ch_caching_pg));
	else if (2 == pcontrol)
		memcpy(p, d_caching_pg, sizeof(d_caching_pg));
L
Linus Torvalds 已提交
1894 1895 1896
	return sizeof(caching_pg);
}

1897 1898 1899
static unsigned char ctrl_m_pg[] = {0xa, 10, 2, 0, 0, 0, 0, 0,
				    0, 0, 0x2, 0x4b};

L
Linus Torvalds 已提交
1900 1901
static int resp_ctrl_m_pg(unsigned char * p, int pcontrol, int target)
{ 	/* Control mode page for mode_sense */
D
Douglas Gilbert 已提交
1902 1903 1904
	unsigned char ch_ctrl_m_pg[] = {/* 0xa, 10, */ 0x6, 0, 0, 0, 0, 0,
				        0, 0, 0, 0};
	unsigned char d_ctrl_m_pg[] = {0xa, 10, 2, 0, 0, 0, 0, 0,
L
Linus Torvalds 已提交
1905 1906
				     0, 0, 0x2, 0x4b};

1907
	if (sdebug_dsense)
L
Linus Torvalds 已提交
1908
		ctrl_m_pg[2] |= 0x4;
D
Douglas Gilbert 已提交
1909 1910
	else
		ctrl_m_pg[2] &= ~0x4;
1911

1912
	if (sdebug_ato)
1913 1914
		ctrl_m_pg[5] |= 0x80; /* ATO=1 */

L
Linus Torvalds 已提交
1915 1916
	memcpy(p, ctrl_m_pg, sizeof(ctrl_m_pg));
	if (1 == pcontrol)
D
Douglas Gilbert 已提交
1917 1918 1919
		memcpy(p + 2, ch_ctrl_m_pg, sizeof(ch_ctrl_m_pg));
	else if (2 == pcontrol)
		memcpy(p, d_ctrl_m_pg, sizeof(d_ctrl_m_pg));
L
Linus Torvalds 已提交
1920 1921 1922
	return sizeof(ctrl_m_pg);
}

D
Douglas Gilbert 已提交
1923

L
Linus Torvalds 已提交
1924 1925
static int resp_iec_m_pg(unsigned char * p, int pcontrol, int target)
{	/* Informational Exceptions control mode page for mode_sense */
D
Douglas Gilbert 已提交
1926 1927 1928 1929 1930
	unsigned char ch_iec_m_pg[] = {/* 0x1c, 0xa, */ 0x4, 0xf, 0, 0, 0, 0,
				       0, 0, 0x0, 0x0};
	unsigned char d_iec_m_pg[] = {0x1c, 0xa, 0x08, 0, 0, 0, 0, 0,
				      0, 0, 0x0, 0x0};

L
Linus Torvalds 已提交
1931 1932
	memcpy(p, iec_m_pg, sizeof(iec_m_pg));
	if (1 == pcontrol)
D
Douglas Gilbert 已提交
1933 1934 1935
		memcpy(p + 2, ch_iec_m_pg, sizeof(ch_iec_m_pg));
	else if (2 == pcontrol)
		memcpy(p, d_iec_m_pg, sizeof(d_iec_m_pg));
L
Linus Torvalds 已提交
1936 1937 1938
	return sizeof(iec_m_pg);
}

D
Douglas Gilbert 已提交
1939 1940 1941 1942 1943 1944 1945 1946 1947 1948 1949 1950 1951 1952 1953 1954 1955
static int resp_sas_sf_m_pg(unsigned char * p, int pcontrol, int target)
{	/* SAS SSP mode page - short format for mode_sense */
	unsigned char sas_sf_m_pg[] = {0x19, 0x6,
		0x6, 0x0, 0x7, 0xd0, 0x0, 0x0};

	memcpy(p, sas_sf_m_pg, sizeof(sas_sf_m_pg));
	if (1 == pcontrol)
		memset(p + 2, 0, sizeof(sas_sf_m_pg) - 2);
	return sizeof(sas_sf_m_pg);
}


static int resp_sas_pcd_m_spg(unsigned char * p, int pcontrol, int target,
			      int target_dev_id)
{	/* SAS phy control and discover mode page for mode_sense */
	unsigned char sas_pcd_m_pg[] = {0x59, 0x1, 0, 0x64, 0, 0x6, 0, 2,
		    0, 0, 0, 0, 0x10, 0x9, 0x8, 0x0,
1956 1957
		    0, 0, 0, 0, 0, 0, 0, 0,	/* insert SAS addr */
		    0, 0, 0, 0, 0, 0, 0, 0,	/* insert SAS addr */
D
Douglas Gilbert 已提交
1958 1959 1960 1961
		    0x2, 0, 0, 0, 0, 0, 0, 0,
		    0x88, 0x99, 0, 0, 0, 0, 0, 0,
		    0, 0, 0, 0, 0, 0, 0, 0,
		    0, 1, 0, 0, 0x10, 0x9, 0x8, 0x0,
1962 1963
		    0, 0, 0, 0, 0, 0, 0, 0,	/* insert SAS addr */
		    0, 0, 0, 0, 0, 0, 0, 0,	/* insert SAS addr */
D
Douglas Gilbert 已提交
1964 1965 1966 1967 1968 1969
		    0x3, 0, 0, 0, 0, 0, 0, 0,
		    0x88, 0x99, 0, 0, 0, 0, 0, 0,
		    0, 0, 0, 0, 0, 0, 0, 0,
		};
	int port_a, port_b;

1970 1971 1972 1973
	put_unaligned_be64(naa3_comp_a, sas_pcd_m_pg + 16);
	put_unaligned_be64(naa3_comp_c + 1, sas_pcd_m_pg + 24);
	put_unaligned_be64(naa3_comp_a, sas_pcd_m_pg + 64);
	put_unaligned_be64(naa3_comp_c + 1, sas_pcd_m_pg + 72);
D
Douglas Gilbert 已提交
1974 1975 1976
	port_a = target_dev_id + 1;
	port_b = port_a + 1;
	memcpy(p, sas_pcd_m_pg, sizeof(sas_pcd_m_pg));
1977 1978
	put_unaligned_be32(port_a, p + 20);
	put_unaligned_be32(port_b, p + 48 + 20);
D
Douglas Gilbert 已提交
1979 1980 1981 1982 1983 1984 1985 1986 1987 1988 1989 1990 1991 1992 1993 1994 1995
	if (1 == pcontrol)
		memset(p + 4, 0, sizeof(sas_pcd_m_pg) - 4);
	return sizeof(sas_pcd_m_pg);
}

static int resp_sas_sha_m_spg(unsigned char * p, int pcontrol)
{	/* SAS SSP shared protocol specific port mode subpage */
	unsigned char sas_sha_m_pg[] = {0x59, 0x2, 0, 0xc, 0, 0x6, 0x10, 0,
		    0, 0, 0, 0, 0, 0, 0, 0,
		};

	memcpy(p, sas_sha_m_pg, sizeof(sas_sha_m_pg));
	if (1 == pcontrol)
		memset(p + 4, 0, sizeof(sas_sha_m_pg) - 4);
	return sizeof(sas_sha_m_pg);
}

L
Linus Torvalds 已提交
1996 1997
#define SDEBUG_MAX_MSENSE_SZ 256

1998 1999
static int resp_mode_sense(struct scsi_cmnd *scp,
			   struct sdebug_dev_info *devip)
L
Linus Torvalds 已提交
2000
{
D
Douglas Gilbert 已提交
2001
	int pcontrol, pcode, subpcode, bd_len;
L
Linus Torvalds 已提交
2002
	unsigned char dev_spec;
2003
	int alloc_len, offset, len, target_dev_id;
2004
	int target = scp->device->id;
L
Linus Torvalds 已提交
2005 2006
	unsigned char * ap;
	unsigned char arr[SDEBUG_MAX_MSENSE_SZ];
2007
	unsigned char *cmd = scp->cmnd;
2008
	bool dbd, llbaa, msense_6, is_disk, bad_pcode;
L
Linus Torvalds 已提交
2009

2010
	dbd = !!(cmd[1] & 0x8);		/* disable block descriptors */
L
Linus Torvalds 已提交
2011 2012 2013 2014
	pcontrol = (cmd[2] & 0xc0) >> 6;
	pcode = cmd[2] & 0x3f;
	subpcode = cmd[3];
	msense_6 = (MODE_SENSE == cmd[0]);
2015 2016 2017
	llbaa = msense_6 ? false : !!(cmd[1] & 0x10);
	is_disk = (sdebug_ptype == TYPE_DISK);
	if (is_disk && !dbd)
D
Douglas Gilbert 已提交
2018 2019 2020
		bd_len = llbaa ? 16 : 8;
	else
		bd_len = 0;
2021
	alloc_len = msense_6 ? cmd[4] : get_unaligned_be16(cmd + 7);
L
Linus Torvalds 已提交
2022 2023
	memset(arr, 0, SDEBUG_MAX_MSENSE_SZ);
	if (0x3 == pcontrol) {  /* Saving values not supported */
2024
		mk_sense_buffer(scp, ILLEGAL_REQUEST, SAVING_PARAMS_UNSUP, 0);
L
Linus Torvalds 已提交
2025 2026
		return check_condition_result;
	}
D
Douglas Gilbert 已提交
2027 2028
	target_dev_id = ((devip->sdbg_host->shost->host_no + 1) * 2000) +
			(devip->target * 1000) - 3;
D
Douglas Gilbert 已提交
2029
	/* for disks set DPOFUA bit and clear write protect (WP) bit */
2030
	if (is_disk)
D
Douglas Gilbert 已提交
2031
		dev_spec = 0x10;	/* =0x90 if WP=1 implies read-only */
D
Douglas Gilbert 已提交
2032 2033
	else
		dev_spec = 0x0;
L
Linus Torvalds 已提交
2034 2035
	if (msense_6) {
		arr[2] = dev_spec;
D
Douglas Gilbert 已提交
2036
		arr[3] = bd_len;
L
Linus Torvalds 已提交
2037 2038 2039
		offset = 4;
	} else {
		arr[3] = dev_spec;
D
Douglas Gilbert 已提交
2040 2041 2042
		if (16 == bd_len)
			arr[4] = 0x1;	/* set LONGLBA bit */
		arr[7] = bd_len;	/* assume 255 or less */
L
Linus Torvalds 已提交
2043 2044 2045
		offset = 8;
	}
	ap = arr + offset;
2046 2047 2048
	if ((bd_len > 0) && (!sdebug_capacity))
		sdebug_capacity = get_sdebug_capacity();

D
Douglas Gilbert 已提交
2049
	if (8 == bd_len) {
2050 2051 2052 2053 2054
		if (sdebug_capacity > 0xfffffffe)
			put_unaligned_be32(0xffffffff, ap + 0);
		else
			put_unaligned_be32(sdebug_capacity, ap + 0);
		put_unaligned_be16(sdebug_sector_size, ap + 6);
D
Douglas Gilbert 已提交
2055 2056 2057
		offset += bd_len;
		ap = arr + offset;
	} else if (16 == bd_len) {
2058 2059
		put_unaligned_be64((u64)sdebug_capacity, ap + 0);
		put_unaligned_be32(sdebug_sector_size, ap + 12);
D
Douglas Gilbert 已提交
2060 2061 2062
		offset += bd_len;
		ap = arr + offset;
	}
L
Linus Torvalds 已提交
2063

D
Douglas Gilbert 已提交
2064 2065
	if ((subpcode > 0x0) && (subpcode < 0xff) && (0x19 != pcode)) {
		/* TODO: Control Extension page */
2066
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 3, -1);
L
Linus Torvalds 已提交
2067 2068
		return check_condition_result;
	}
2069 2070
	bad_pcode = false;

L
Linus Torvalds 已提交
2071 2072 2073 2074 2075 2076 2077 2078 2079 2080
	switch (pcode) {
	case 0x1:	/* Read-Write error recovery page, direct access */
		len = resp_err_recov_pg(ap, pcontrol, target);
		offset += len;
		break;
	case 0x2:	/* Disconnect-Reconnect page, all devices */
		len = resp_disconnect_pg(ap, pcontrol, target);
		offset += len;
		break;
        case 0x3:       /* Format device page, direct access */
2081 2082 2083 2084 2085
		if (is_disk) {
			len = resp_format_pg(ap, pcontrol, target);
			offset += len;
		} else
			bad_pcode = true;
L
Linus Torvalds 已提交
2086 2087
                break;
	case 0x8:	/* Caching page, direct access */
2088 2089 2090 2091 2092
		if (is_disk) {
			len = resp_caching_pg(ap, pcontrol, target);
			offset += len;
		} else
			bad_pcode = true;
L
Linus Torvalds 已提交
2093 2094 2095 2096 2097
		break;
	case 0xa:	/* Control Mode page, all devices */
		len = resp_ctrl_m_pg(ap, pcontrol, target);
		offset += len;
		break;
D
Douglas Gilbert 已提交
2098 2099
	case 0x19:	/* if spc==1 then sas phy, control+discover */
		if ((subpcode > 0x2) && (subpcode < 0xff)) {
2100
			mk_sense_invalid_fld(scp, SDEB_IN_CDB, 3, -1);
D
Douglas Gilbert 已提交
2101 2102 2103 2104 2105 2106 2107 2108 2109 2110 2111 2112
			return check_condition_result;
	        }
		len = 0;
		if ((0x0 == subpcode) || (0xff == subpcode))
			len += resp_sas_sf_m_pg(ap + len, pcontrol, target);
		if ((0x1 == subpcode) || (0xff == subpcode))
			len += resp_sas_pcd_m_spg(ap + len, pcontrol, target,
						  target_dev_id);
		if ((0x2 == subpcode) || (0xff == subpcode))
			len += resp_sas_sha_m_spg(ap + len, pcontrol);
		offset += len;
		break;
L
Linus Torvalds 已提交
2113 2114 2115 2116 2117
	case 0x1c:	/* Informational Exceptions Mode page, all devices */
		len = resp_iec_m_pg(ap, pcontrol, target);
		offset += len;
		break;
	case 0x3f:	/* Read all Mode pages */
D
Douglas Gilbert 已提交
2118 2119 2120
		if ((0 == subpcode) || (0xff == subpcode)) {
			len = resp_err_recov_pg(ap, pcontrol, target);
			len += resp_disconnect_pg(ap + len, pcontrol, target);
2121 2122 2123 2124 2125 2126
			if (is_disk) {
				len += resp_format_pg(ap + len, pcontrol,
						      target);
				len += resp_caching_pg(ap + len, pcontrol,
						       target);
			}
D
Douglas Gilbert 已提交
2127 2128 2129 2130 2131 2132 2133 2134
			len += resp_ctrl_m_pg(ap + len, pcontrol, target);
			len += resp_sas_sf_m_pg(ap + len, pcontrol, target);
			if (0xff == subpcode) {
				len += resp_sas_pcd_m_spg(ap + len, pcontrol,
						  target, target_dev_id);
				len += resp_sas_sha_m_spg(ap + len, pcontrol);
			}
			len += resp_iec_m_pg(ap + len, pcontrol, target);
2135
			offset += len;
D
Douglas Gilbert 已提交
2136
		} else {
2137
			mk_sense_invalid_fld(scp, SDEB_IN_CDB, 3, -1);
D
Douglas Gilbert 已提交
2138 2139
			return check_condition_result;
                }
L
Linus Torvalds 已提交
2140 2141
		break;
	default:
2142 2143 2144 2145
		bad_pcode = true;
		break;
	}
	if (bad_pcode) {
2146
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, 5);
L
Linus Torvalds 已提交
2147 2148 2149 2150
		return check_condition_result;
	}
	if (msense_6)
		arr[0] = offset - 1;
2151 2152
	else
		put_unaligned_be16((offset - 2), arr + 0);
L
Linus Torvalds 已提交
2153 2154 2155
	return fill_from_dev_buffer(scp, arr, min(alloc_len, offset));
}

D
Douglas Gilbert 已提交
2156 2157
#define SDEBUG_MAX_MSELECT_SZ 512

2158 2159
static int resp_mode_select(struct scsi_cmnd *scp,
			    struct sdebug_dev_info *devip)
D
Douglas Gilbert 已提交
2160 2161
{
	int pf, sp, ps, md_len, bd_len, off, spf, pg_len;
2162
	int param_len, res, mpage;
D
Douglas Gilbert 已提交
2163
	unsigned char arr[SDEBUG_MAX_MSELECT_SZ];
2164
	unsigned char *cmd = scp->cmnd;
2165
	int mselect6 = (MODE_SELECT == cmd[0]);
D
Douglas Gilbert 已提交
2166 2167 2168 2169

	memset(arr, 0, sizeof(arr));
	pf = cmd[1] & 0x10;
	sp = cmd[1] & 0x1;
2170
	param_len = mselect6 ? cmd[4] : get_unaligned_be16(cmd + 7);
D
Douglas Gilbert 已提交
2171
	if ((0 == pf) || sp || (param_len > SDEBUG_MAX_MSELECT_SZ)) {
2172
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, mselect6 ? 4 : 7, -1);
D
Douglas Gilbert 已提交
2173 2174 2175 2176
		return check_condition_result;
	}
        res = fetch_to_dev_buffer(scp, arr, param_len);
        if (-1 == res)
2177 2178
		return DID_ERROR << 16;
	else if (sdebug_verbose && (res < param_len))
2179 2180 2181
		sdev_printk(KERN_INFO, scp->device,
			    "%s: cdb indicated=%d, IO sent=%d bytes\n",
			    __func__, param_len, res);
2182 2183
	md_len = mselect6 ? (arr[0] + 1) : (get_unaligned_be16(arr + 0) + 2);
	bd_len = mselect6 ? arr[3] : get_unaligned_be16(arr + 6);
D
Douglas Gilbert 已提交
2184
	if (md_len > 2) {
2185
		mk_sense_invalid_fld(scp, SDEB_IN_DATA, 0, -1);
D
Douglas Gilbert 已提交
2186 2187 2188 2189 2190 2191
		return check_condition_result;
	}
	off = bd_len + (mselect6 ? 4 : 8);
	mpage = arr[off] & 0x3f;
	ps = !!(arr[off] & 0x80);
	if (ps) {
2192
		mk_sense_invalid_fld(scp, SDEB_IN_DATA, off, 7);
D
Douglas Gilbert 已提交
2193 2194 2195
		return check_condition_result;
	}
	spf = !!(arr[off] & 0x40);
2196
	pg_len = spf ? (get_unaligned_be16(arr + off + 2) + 4) :
D
Douglas Gilbert 已提交
2197 2198
		       (arr[off + 1] + 2);
	if ((pg_len + off) > param_len) {
2199
		mk_sense_buffer(scp, ILLEGAL_REQUEST,
D
Douglas Gilbert 已提交
2200 2201 2202 2203
				PARAMETER_LIST_LENGTH_ERR, 0);
		return check_condition_result;
	}
	switch (mpage) {
2204 2205 2206 2207 2208 2209 2210
	case 0x8:      /* Caching Mode page */
		if (caching_pg[1] == arr[off + 1]) {
			memcpy(caching_pg + 2, arr + off + 2,
			       sizeof(caching_pg) - 2);
			goto set_mode_changed_ua;
		}
		break;
D
Douglas Gilbert 已提交
2211 2212 2213 2214
	case 0xa:      /* Control Mode page */
		if (ctrl_m_pg[1] == arr[off + 1]) {
			memcpy(ctrl_m_pg + 2, arr + off + 2,
			       sizeof(ctrl_m_pg) - 2);
2215
			sdebug_dsense = !!(ctrl_m_pg[2] & 0x4);
2216
			goto set_mode_changed_ua;
D
Douglas Gilbert 已提交
2217 2218 2219 2220 2221 2222
		}
		break;
	case 0x1c:      /* Informational Exceptions Mode page */
		if (iec_m_pg[1] == arr[off + 1]) {
			memcpy(iec_m_pg + 2, arr + off + 2,
			       sizeof(iec_m_pg) - 2);
2223
			goto set_mode_changed_ua;
D
Douglas Gilbert 已提交
2224 2225 2226 2227 2228
		}
		break;
	default:
		break;
	}
2229
	mk_sense_invalid_fld(scp, SDEB_IN_DATA, off, 5);
D
Douglas Gilbert 已提交
2230
	return check_condition_result;
2231 2232 2233
set_mode_changed_ua:
	set_bit(SDEBUG_UA_MODE_CHANGED, devip->uas_bm);
	return 0;
D
Douglas Gilbert 已提交
2234 2235 2236 2237 2238 2239 2240 2241 2242 2243 2244 2245 2246 2247 2248 2249 2250 2251 2252 2253 2254 2255 2256 2257 2258 2259 2260 2261 2262 2263
}

static int resp_temp_l_pg(unsigned char * arr)
{
	unsigned char temp_l_pg[] = {0x0, 0x0, 0x3, 0x2, 0x0, 38,
				     0x0, 0x1, 0x3, 0x2, 0x0, 65,
		};

        memcpy(arr, temp_l_pg, sizeof(temp_l_pg));
        return sizeof(temp_l_pg);
}

static int resp_ie_l_pg(unsigned char * arr)
{
	unsigned char ie_l_pg[] = {0x0, 0x0, 0x3, 0x3, 0x0, 0x0, 38,
		};

        memcpy(arr, ie_l_pg, sizeof(ie_l_pg));
	if (iec_m_pg[2] & 0x4) {	/* TEST bit set */
		arr[4] = THRESHOLD_EXCEEDED;
		arr[5] = 0xff;
	}
        return sizeof(ie_l_pg);
}

#define SDEBUG_MAX_LSENSE_SZ 512

static int resp_log_sense(struct scsi_cmnd * scp,
                          struct sdebug_dev_info * devip)
{
2264
	int ppc, sp, pcode, subpcode, alloc_len, len, n;
D
Douglas Gilbert 已提交
2265
	unsigned char arr[SDEBUG_MAX_LSENSE_SZ];
2266
	unsigned char *cmd = scp->cmnd;
D
Douglas Gilbert 已提交
2267 2268 2269 2270 2271

	memset(arr, 0, sizeof(arr));
	ppc = cmd[1] & 0x2;
	sp = cmd[1] & 0x1;
	if (ppc || sp) {
2272
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, ppc ? 1 : 0);
D
Douglas Gilbert 已提交
2273 2274 2275
		return check_condition_result;
	}
	pcode = cmd[2] & 0x3f;
D
Douglas Gilbert 已提交
2276
	subpcode = cmd[3] & 0xff;
2277
	alloc_len = get_unaligned_be16(cmd + 7);
D
Douglas Gilbert 已提交
2278
	arr[0] = pcode;
D
Douglas Gilbert 已提交
2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291 2292 2293 2294
	if (0 == subpcode) {
		switch (pcode) {
		case 0x0:	/* Supported log pages log page */
			n = 4;
			arr[n++] = 0x0;		/* this page */
			arr[n++] = 0xd;		/* Temperature */
			arr[n++] = 0x2f;	/* Informational exceptions */
			arr[3] = n - 4;
			break;
		case 0xd:	/* Temperature log page */
			arr[3] = resp_temp_l_pg(arr + 4);
			break;
		case 0x2f:	/* Informational exceptions log page */
			arr[3] = resp_ie_l_pg(arr + 4);
			break;
		default:
2295
			mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, 5);
D
Douglas Gilbert 已提交
2296 2297 2298 2299 2300 2301 2302 2303 2304 2305 2306 2307 2308 2309 2310 2311 2312 2313 2314 2315 2316 2317 2318 2319 2320 2321 2322 2323 2324 2325 2326
			return check_condition_result;
		}
	} else if (0xff == subpcode) {
		arr[0] |= 0x40;
		arr[1] = subpcode;
		switch (pcode) {
		case 0x0:	/* Supported log pages and subpages log page */
			n = 4;
			arr[n++] = 0x0;
			arr[n++] = 0x0;		/* 0,0 page */
			arr[n++] = 0x0;
			arr[n++] = 0xff;	/* this page */
			arr[n++] = 0xd;
			arr[n++] = 0x0;		/* Temperature */
			arr[n++] = 0x2f;
			arr[n++] = 0x0;	/* Informational exceptions */
			arr[3] = n - 4;
			break;
		case 0xd:	/* Temperature subpages */
			n = 4;
			arr[n++] = 0xd;
			arr[n++] = 0x0;		/* Temperature */
			arr[3] = n - 4;
			break;
		case 0x2f:	/* Informational exceptions subpages */
			n = 4;
			arr[n++] = 0x2f;
			arr[n++] = 0x0;		/* Informational exceptions */
			arr[3] = n - 4;
			break;
		default:
2327
			mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, 5);
D
Douglas Gilbert 已提交
2328 2329 2330
			return check_condition_result;
		}
	} else {
2331
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 3, -1);
D
Douglas Gilbert 已提交
2332 2333
		return check_condition_result;
	}
2334
	len = min(get_unaligned_be16(arr + 2) + 4, alloc_len);
D
Douglas Gilbert 已提交
2335 2336 2337 2338
	return fill_from_dev_buffer(scp, arr,
		    min(len, SDEBUG_MAX_INQ_ARR_SZ));
}

2339
static int check_device_access_params(struct scsi_cmnd *scp,
2340
				      unsigned long long lba, unsigned int num)
L
Linus Torvalds 已提交
2341
{
D
Douglas Gilbert 已提交
2342
	if (lba + num > sdebug_capacity) {
2343
		mk_sense_buffer(scp, ILLEGAL_REQUEST, LBA_OUT_OF_RANGE, 0);
L
Linus Torvalds 已提交
2344 2345
		return check_condition_result;
	}
D
Douglas Gilbert 已提交
2346 2347
	/* transfer length excessive (tie in to block limits VPD page) */
	if (num > sdebug_store_sectors) {
2348
		/* needs work to find which cdb byte 'num' comes from */
2349
		mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_FIELD_IN_CDB, 0);
D
Douglas Gilbert 已提交
2350 2351
		return check_condition_result;
	}
2352 2353 2354
	return 0;
}

2355
/* Returns number of bytes copied or -1 if error. */
2356 2357
static int do_device_access(struct scsi_cmnd *scmd, u64 lba, u32 num,
			    bool do_write)
2358 2359
{
	int ret;
2360
	u64 block, rest = 0;
2361 2362 2363
	struct scsi_data_buffer *sdb;
	enum dma_data_direction dir;

2364
	if (do_write) {
2365 2366 2367 2368 2369 2370
		sdb = scsi_out(scmd);
		dir = DMA_TO_DEVICE;
	} else {
		sdb = scsi_in(scmd);
		dir = DMA_FROM_DEVICE;
	}
2371

2372 2373 2374 2375
	if (!sdb->length)
		return 0;
	if (!(scsi_bidi_cmnd(scmd) || scmd->sc_data_direction == dir))
		return -1;
2376 2377 2378 2379 2380

	block = do_div(lba, sdebug_store_sectors);
	if (block + num > sdebug_store_sectors)
		rest = block + num - sdebug_store_sectors;

2381
	ret = sg_copy_buffer(sdb->table.sgl, sdb->table.nents,
2382 2383 2384
		   fake_storep + (block * sdebug_sector_size),
		   (num - rest) * sdebug_sector_size, 0, do_write);
	if (ret != (num - rest) * sdebug_sector_size)
2385 2386 2387
		return ret;

	if (rest) {
2388
		ret += sg_copy_buffer(sdb->table.sgl, sdb->table.nents,
2389 2390
			    fake_storep, rest * sdebug_sector_size,
			    (num - rest) * sdebug_sector_size, do_write);
2391
	}
2392 2393 2394 2395

	return ret;
}

2396 2397 2398
/* If fake_store(lba,num) compares equal to arr(num), then copy top half of
 * arr into fake_store(lba,num) and return true. If comparison fails then
 * return false. */
2399
static bool comp_write_worker(u64 lba, u32 num, const u8 *arr)
2400 2401 2402 2403
{
	bool res;
	u64 block, rest = 0;
	u32 store_blks = sdebug_store_sectors;
2404
	u32 lb_size = sdebug_sector_size;
2405 2406 2407 2408 2409 2410 2411 2412 2413 2414 2415 2416 2417 2418 2419 2420 2421 2422 2423 2424 2425 2426

	block = do_div(lba, store_blks);
	if (block + num > store_blks)
		rest = block + num - store_blks;

	res = !memcmp(fake_storep + (block * lb_size), arr,
		      (num - rest) * lb_size);
	if (!res)
		return res;
	if (rest)
		res = memcmp(fake_storep, arr + ((num - rest) * lb_size),
			     rest * lb_size);
	if (!res)
		return res;
	arr += num * lb_size;
	memcpy(fake_storep + (block * lb_size), arr, (num - rest) * lb_size);
	if (rest)
		memcpy(fake_storep, arr + ((num - rest) * lb_size),
		       rest * lb_size);
	return res;
}

2427
static __be16 dif_compute_csum(const void *buf, int len)
2428
{
2429
	__be16 csum;
2430

2431
	if (sdebug_guard)
2432 2433
		csum = (__force __be16)ip_compute_csum(buf, len);
	else
2434
		csum = cpu_to_be16(crc_t10dif(buf, len));
2435

2436 2437 2438
	return csum;
}

2439
static int dif_verify(struct t10_pi_tuple *sdt, const void *data,
2440 2441
		      sector_t sector, u32 ei_lba)
{
2442
	__be16 csum = dif_compute_csum(data, sdebug_sector_size);
2443 2444

	if (sdt->guard_tag != csum) {
2445
		pr_err("GUARD check failed on sector %lu rcvd 0x%04x, data 0x%04x\n",
2446 2447 2448 2449 2450
			(unsigned long)sector,
			be16_to_cpu(sdt->guard_tag),
			be16_to_cpu(csum));
		return 0x01;
	}
2451
	if (sdebug_dif == T10_PI_TYPE1_PROTECTION &&
2452
	    be32_to_cpu(sdt->ref_tag) != (sector & 0xffffffff)) {
2453 2454
		pr_err("REF check failed on sector %lu\n",
			(unsigned long)sector);
2455 2456
		return 0x03;
	}
2457
	if (sdebug_dif == T10_PI_TYPE2_PROTECTION &&
2458
	    be32_to_cpu(sdt->ref_tag) != ei_lba) {
2459 2460
		pr_err("REF check failed on sector %lu\n",
			(unsigned long)sector);
2461 2462 2463 2464 2465
		return 0x03;
	}
	return 0;
}

2466
static void dif_copy_prot(struct scsi_cmnd *SCpnt, sector_t sector,
2467
			  unsigned int sectors, bool read)
2468
{
2469
	size_t resid;
2470
	void *paddr;
2471
	const void *dif_store_end = dif_storep + sdebug_store_sectors;
2472
	struct sg_mapping_iter miter;
2473

2474 2475
	/* Bytes of protection data to copy into sgl */
	resid = sectors * sizeof(*dif_storep);
2476

2477 2478 2479 2480 2481 2482
	sg_miter_start(&miter, scsi_prot_sglist(SCpnt),
			scsi_prot_sg_count(SCpnt), SG_MITER_ATOMIC |
			(read ? SG_MITER_TO_SG : SG_MITER_FROM_SG));

	while (sg_miter_next(&miter) && resid > 0) {
		size_t len = min(miter.length, resid);
2483
		void *start = dif_store(sector);
2484
		size_t rest = 0;
2485 2486 2487

		if (dif_store_end < start + len)
			rest = start + len - dif_store_end;
2488

2489
		paddr = miter.addr;
2490

2491 2492 2493 2494 2495 2496 2497 2498 2499 2500 2501
		if (read)
			memcpy(paddr, start, len - rest);
		else
			memcpy(start, paddr, len - rest);

		if (rest) {
			if (read)
				memcpy(paddr + len - rest, dif_storep, rest);
			else
				memcpy(dif_storep, paddr + len - rest, rest);
		}
2502

2503
		sector += len / sizeof(*dif_storep);
2504 2505
		resid -= len;
	}
2506
	sg_miter_stop(&miter);
2507 2508 2509 2510 2511 2512
}

static int prot_verify_read(struct scsi_cmnd *SCpnt, sector_t start_sec,
			    unsigned int sectors, u32 ei_lba)
{
	unsigned int i;
2513
	struct t10_pi_tuple *sdt;
2514 2515
	sector_t sector;

2516
	for (i = 0; i < sectors; i++, ei_lba++) {
2517 2518 2519 2520 2521
		int ret;

		sector = start_sec + i;
		sdt = dif_store(sector);

2522
		if (sdt->app_tag == cpu_to_be16(0xffff))
2523 2524 2525 2526 2527 2528 2529 2530
			continue;

		ret = dif_verify(sdt, fake_store(sector), sector, ei_lba);
		if (ret) {
			dif_errors++;
			return ret;
		}
	}
2531

2532
	dif_copy_prot(SCpnt, start_sec, sectors, true);
2533 2534 2535 2536 2537
	dix_reads++;

	return 0;
}

2538
static int resp_read_dt0(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
2539
{
2540
	u8 *cmd = scp->cmnd;
2541
	struct sdebug_queued_cmd *sqcp;
2542 2543 2544
	u64 lba;
	u32 num;
	u32 ei_lba;
2545 2546
	unsigned long iflags;
	int ret;
2547
	bool check_prot;
2548

2549 2550 2551 2552 2553 2554 2555 2556 2557 2558 2559 2560 2561 2562 2563 2564 2565 2566 2567 2568 2569 2570 2571 2572 2573 2574 2575 2576 2577 2578 2579 2580 2581 2582 2583 2584 2585 2586 2587
	switch (cmd[0]) {
	case READ_16:
		ei_lba = 0;
		lba = get_unaligned_be64(cmd + 2);
		num = get_unaligned_be32(cmd + 10);
		check_prot = true;
		break;
	case READ_10:
		ei_lba = 0;
		lba = get_unaligned_be32(cmd + 2);
		num = get_unaligned_be16(cmd + 7);
		check_prot = true;
		break;
	case READ_6:
		ei_lba = 0;
		lba = (u32)cmd[3] | (u32)cmd[2] << 8 |
		      (u32)(cmd[1] & 0x1f) << 16;
		num = (0 == cmd[4]) ? 256 : cmd[4];
		check_prot = true;
		break;
	case READ_12:
		ei_lba = 0;
		lba = get_unaligned_be32(cmd + 2);
		num = get_unaligned_be32(cmd + 6);
		check_prot = true;
		break;
	case XDWRITEREAD_10:
		ei_lba = 0;
		lba = get_unaligned_be32(cmd + 2);
		num = get_unaligned_be16(cmd + 7);
		check_prot = false;
		break;
	default:	/* assume READ(32) */
		lba = get_unaligned_be64(cmd + 12);
		ei_lba = get_unaligned_be32(cmd + 20);
		num = get_unaligned_be32(cmd + 28);
		check_prot = false;
		break;
	}
2588
	if (unlikely(have_dif_prot && check_prot)) {
2589
		if (sdebug_dif == T10_PI_TYPE2_PROTECTION &&
2590 2591 2592 2593
		    (cmd[1] & 0xe0)) {
			mk_sense_invalid_opcode(scp);
			return check_condition_result;
		}
2594 2595
		if ((sdebug_dif == T10_PI_TYPE1_PROTECTION ||
		     sdebug_dif == T10_PI_TYPE3_PROTECTION) &&
2596 2597 2598 2599
		    (cmd[1] & 0xe0) == 0)
			sdev_printk(KERN_ERR, scp->device, "Unprotected RD "
				    "to DIF device\n");
	}
2600
	if (unlikely(sdebug_any_injecting_opt)) {
2601
		sqcp = (struct sdebug_queued_cmd *)scp->host_scribble;
2602

2603 2604 2605 2606 2607 2608
		if (sqcp) {
			if (sqcp->inj_short)
				num /= 2;
		}
	} else
		sqcp = NULL;
2609 2610

	/* inline check_device_access_params() */
2611
	if (unlikely(lba + num > sdebug_capacity)) {
2612 2613 2614 2615
		mk_sense_buffer(scp, ILLEGAL_REQUEST, LBA_OUT_OF_RANGE, 0);
		return check_condition_result;
	}
	/* transfer length excessive (tie in to block limits VPD page) */
2616
	if (unlikely(num > sdebug_store_sectors)) {
2617 2618 2619 2620
		/* needs work to find which cdb byte 'num' comes from */
		mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_FIELD_IN_CDB, 0);
		return check_condition_result;
	}
2621

2622 2623 2624
	if (unlikely((SDEBUG_OPT_MEDIUM_ERR & sdebug_opts) &&
		     (lba <= (OPT_MEDIUM_ERR_ADDR + OPT_MEDIUM_ERR_NUM - 1)) &&
		     ((lba + num) > OPT_MEDIUM_ERR_ADDR))) {
D
Douglas Gilbert 已提交
2625
		/* claim unrecoverable read error */
2626
		mk_sense_buffer(scp, MEDIUM_ERROR, UNRECOVERED_READ_ERR, 0);
D
Douglas Gilbert 已提交
2627
		/* set info field and valid bit for fixed descriptor */
2628 2629
		if (0x70 == (scp->sense_buffer[0] & 0x7f)) {
			scp->sense_buffer[0] |= 0x80;	/* Valid bit */
2630 2631
			ret = (lba < OPT_MEDIUM_ERR_ADDR)
			      ? OPT_MEDIUM_ERR_ADDR : (int)lba;
2632
			put_unaligned_be32(ret, scp->sense_buffer + 3);
D
Douglas Gilbert 已提交
2633
		}
2634
		scsi_set_resid(scp, scsi_bufflen(scp));
L
Linus Torvalds 已提交
2635 2636
		return check_condition_result;
	}
2637

2638 2639
	read_lock_irqsave(&atomic_rw, iflags);

2640
	/* DIX + T10 DIF */
2641
	if (unlikely(sdebug_dix && scsi_prot_sg_count(scp))) {
2642
		int prot_ret = prot_verify_read(scp, lba, num, ei_lba);
2643 2644

		if (prot_ret) {
2645
			read_unlock_irqrestore(&atomic_rw, iflags);
2646
			mk_sense_buffer(scp, ABORTED_COMMAND, 0x10, prot_ret);
2647 2648 2649 2650
			return illegal_condition_result;
		}
	}

2651
	ret = do_device_access(scp, lba, num, false);
L
Linus Torvalds 已提交
2652
	read_unlock_irqrestore(&atomic_rw, iflags);
2653
	if (unlikely(ret == -1))
2654 2655
		return DID_ERROR << 16;

2656
	scsi_in(scp)->resid = scsi_bufflen(scp) - ret;
2657

2658 2659
	if (unlikely(sqcp)) {
		if (sqcp->inj_recovered) {
2660 2661 2662
			mk_sense_buffer(scp, RECOVERED_ERROR,
					THRESHOLD_EXCEEDED, 0);
			return check_condition_result;
2663
		} else if (sqcp->inj_transport) {
2664 2665 2666
			mk_sense_buffer(scp, ABORTED_COMMAND,
					TRANSPORT_PROBLEM, ACK_NAK_TO);
			return check_condition_result;
2667
		} else if (sqcp->inj_dif) {
2668 2669 2670
			/* Logical block guard check failed */
			mk_sense_buffer(scp, ABORTED_COMMAND, 0x10, 1);
			return illegal_condition_result;
2671
		} else if (sqcp->inj_dix) {
2672 2673 2674 2675
			mk_sense_buffer(scp, ILLEGAL_REQUEST, 0x10, 1);
			return illegal_condition_result;
		}
	}
2676
	return 0;
L
Linus Torvalds 已提交
2677 2678
}

2679
static void dump_sector(unsigned char *buf, int len)
2680
{
2681
	int i, j, n;
2682

2683
	pr_err(">>> Sector Dump <<<\n");
2684
	for (i = 0 ; i < len ; i += 16) {
2685
		char b[128];
2686

2687
		for (j = 0, n = 0; j < 16; j++) {
2688
			unsigned char c = buf[i+j];
2689

2690
			if (c >= 0x20 && c < 0x7e)
2691 2692
				n += scnprintf(b + n, sizeof(b) - n,
					       " %c ", buf[i+j]);
2693
			else
2694 2695
				n += scnprintf(b + n, sizeof(b) - n,
					       "%02x ", buf[i+j]);
2696
		}
2697
		pr_err("%04d: %s\n", i, b);
2698 2699 2700 2701
	}
}

static int prot_verify_write(struct scsi_cmnd *SCpnt, sector_t start_sec,
2702
			     unsigned int sectors, u32 ei_lba)
2703
{
2704
	int ret;
2705
	struct t10_pi_tuple *sdt;
2706
	void *daddr;
2707
	sector_t sector = start_sec;
2708
	int ppage_offset;
2709 2710 2711
	int dpage_offset;
	struct sg_mapping_iter diter;
	struct sg_mapping_iter piter;
2712 2713 2714 2715

	BUG_ON(scsi_sg_count(SCpnt) == 0);
	BUG_ON(scsi_prot_sg_count(SCpnt) == 0);

2716 2717 2718 2719 2720 2721 2722 2723 2724 2725 2726 2727 2728
	sg_miter_start(&piter, scsi_prot_sglist(SCpnt),
			scsi_prot_sg_count(SCpnt),
			SG_MITER_ATOMIC | SG_MITER_FROM_SG);
	sg_miter_start(&diter, scsi_sglist(SCpnt), scsi_sg_count(SCpnt),
			SG_MITER_ATOMIC | SG_MITER_FROM_SG);

	/* For each protection page */
	while (sg_miter_next(&piter)) {
		dpage_offset = 0;
		if (WARN_ON(!sg_miter_next(&diter))) {
			ret = 0x01;
			goto out;
		}
2729

2730
		for (ppage_offset = 0; ppage_offset < piter.length;
2731
		     ppage_offset += sizeof(struct t10_pi_tuple)) {
2732
			/* If we're at the end of the current
2733
			 * data page advance to the next one
2734
			 */
2735 2736 2737 2738 2739 2740
			if (dpage_offset >= diter.length) {
				if (WARN_ON(!sg_miter_next(&diter))) {
					ret = 0x01;
					goto out;
				}
				dpage_offset = 0;
2741 2742
			}

2743 2744
			sdt = piter.addr + ppage_offset;
			daddr = diter.addr + dpage_offset;
2745

2746
			ret = dif_verify(sdt, daddr, sector, ei_lba);
2747
			if (ret) {
2748
				dump_sector(daddr, sdebug_sector_size);
2749 2750 2751
				goto out;
			}

2752
			sector++;
2753
			ei_lba++;
2754
			dpage_offset += sdebug_sector_size;
2755
		}
2756 2757
		diter.consumed = dpage_offset;
		sg_miter_stop(&diter);
2758
	}
2759
	sg_miter_stop(&piter);
2760

2761
	dif_copy_prot(SCpnt, start_sec, sectors, false);
2762 2763 2764 2765 2766 2767
	dix_writes++;

	return 0;

out:
	dif_errors++;
2768 2769
	sg_miter_stop(&diter);
	sg_miter_stop(&piter);
2770 2771 2772
	return ret;
}

2773 2774
static unsigned long lba_to_map_index(sector_t lba)
{
2775 2776 2777
	if (sdebug_unmap_alignment)
		lba += sdebug_unmap_granularity - sdebug_unmap_alignment;
	sector_div(lba, sdebug_unmap_granularity);
2778 2779 2780 2781
	return lba;
}

static sector_t map_index_to_lba(unsigned long index)
2782
{
2783
	sector_t lba = index * sdebug_unmap_granularity;
2784

2785 2786
	if (sdebug_unmap_alignment)
		lba -= sdebug_unmap_granularity - sdebug_unmap_alignment;
2787
	return lba;
2788
}
2789

2790 2791 2792 2793 2794 2795
static unsigned int map_state(sector_t lba, unsigned int *num)
{
	sector_t end;
	unsigned int mapped;
	unsigned long index;
	unsigned long next;
2796

2797 2798
	index = lba_to_map_index(lba);
	mapped = test_bit(index, map_storep);
2799 2800

	if (mapped)
2801
		next = find_next_zero_bit(map_storep, map_size, index);
2802
	else
2803
		next = find_next_bit(map_storep, map_size, index);
2804

2805
	end = min_t(sector_t, sdebug_store_sectors,  map_index_to_lba(next));
2806 2807 2808 2809 2810 2811 2812 2813 2814
	*num = end - lba;
	return mapped;
}

static void map_region(sector_t lba, unsigned int len)
{
	sector_t end = lba + len;

	while (lba < end) {
2815
		unsigned long index = lba_to_map_index(lba);
2816

2817 2818
		if (index < map_size)
			set_bit(index, map_storep);
2819

2820
		lba = map_index_to_lba(index + 1);
2821 2822 2823 2824 2825 2826 2827 2828
	}
}

static void unmap_region(sector_t lba, unsigned int len)
{
	sector_t end = lba + len;

	while (lba < end) {
2829
		unsigned long index = lba_to_map_index(lba);
2830

2831
		if (lba == map_index_to_lba(index) &&
2832
		    lba + sdebug_unmap_granularity <= end &&
2833 2834
		    index < map_size) {
			clear_bit(index, map_storep);
2835
			if (sdebug_lbprz) {  /* for LBPRZ=2 return 0xff_s */
2836
				memset(fake_storep +
2837 2838
				       lba * sdebug_sector_size,
				       (sdebug_lbprz & 1) ? 0 : 0xff,
2839 2840
				       sdebug_sector_size *
				       sdebug_unmap_granularity);
2841
			}
2842 2843 2844
			if (dif_storep) {
				memset(dif_storep + lba, 0xff,
				       sizeof(*dif_storep) *
2845
				       sdebug_unmap_granularity);
2846
			}
2847
		}
2848
		lba = map_index_to_lba(index + 1);
2849 2850 2851
	}
}

2852
static int resp_write_dt0(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
L
Linus Torvalds 已提交
2853
{
2854 2855 2856 2857
	u8 *cmd = scp->cmnd;
	u64 lba;
	u32 num;
	u32 ei_lba;
L
Linus Torvalds 已提交
2858
	unsigned long iflags;
2859
	int ret;
2860
	bool check_prot;
L
Linus Torvalds 已提交
2861

2862 2863 2864 2865 2866 2867 2868 2869 2870 2871 2872 2873 2874 2875 2876 2877 2878 2879 2880 2881 2882 2883 2884 2885 2886 2887 2888 2889 2890 2891 2892 2893 2894 2895 2896 2897 2898 2899 2900
	switch (cmd[0]) {
	case WRITE_16:
		ei_lba = 0;
		lba = get_unaligned_be64(cmd + 2);
		num = get_unaligned_be32(cmd + 10);
		check_prot = true;
		break;
	case WRITE_10:
		ei_lba = 0;
		lba = get_unaligned_be32(cmd + 2);
		num = get_unaligned_be16(cmd + 7);
		check_prot = true;
		break;
	case WRITE_6:
		ei_lba = 0;
		lba = (u32)cmd[3] | (u32)cmd[2] << 8 |
		      (u32)(cmd[1] & 0x1f) << 16;
		num = (0 == cmd[4]) ? 256 : cmd[4];
		check_prot = true;
		break;
	case WRITE_12:
		ei_lba = 0;
		lba = get_unaligned_be32(cmd + 2);
		num = get_unaligned_be32(cmd + 6);
		check_prot = true;
		break;
	case 0x53:	/* XDWRITEREAD(10) */
		ei_lba = 0;
		lba = get_unaligned_be32(cmd + 2);
		num = get_unaligned_be16(cmd + 7);
		check_prot = false;
		break;
	default:	/* assume WRITE(32) */
		lba = get_unaligned_be64(cmd + 12);
		ei_lba = get_unaligned_be32(cmd + 20);
		num = get_unaligned_be32(cmd + 28);
		check_prot = false;
		break;
	}
2901
	if (unlikely(have_dif_prot && check_prot)) {
2902
		if (sdebug_dif == T10_PI_TYPE2_PROTECTION &&
2903 2904 2905 2906
		    (cmd[1] & 0xe0)) {
			mk_sense_invalid_opcode(scp);
			return check_condition_result;
		}
2907 2908
		if ((sdebug_dif == T10_PI_TYPE1_PROTECTION ||
		     sdebug_dif == T10_PI_TYPE3_PROTECTION) &&
2909 2910 2911 2912 2913 2914
		    (cmd[1] & 0xe0) == 0)
			sdev_printk(KERN_ERR, scp->device, "Unprotected WR "
				    "to DIF device\n");
	}

	/* inline check_device_access_params() */
2915
	if (unlikely(lba + num > sdebug_capacity)) {
2916 2917 2918 2919
		mk_sense_buffer(scp, ILLEGAL_REQUEST, LBA_OUT_OF_RANGE, 0);
		return check_condition_result;
	}
	/* transfer length excessive (tie in to block limits VPD page) */
2920
	if (unlikely(num > sdebug_store_sectors)) {
2921 2922 2923 2924
		/* needs work to find which cdb byte 'num' comes from */
		mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_FIELD_IN_CDB, 0);
		return check_condition_result;
	}
L
Linus Torvalds 已提交
2925

2926 2927
	write_lock_irqsave(&atomic_rw, iflags);

2928
	/* DIX + T10 DIF */
2929
	if (unlikely(sdebug_dix && scsi_prot_sg_count(scp))) {
2930
		int prot_ret = prot_verify_write(scp, lba, num, ei_lba);
2931 2932

		if (prot_ret) {
2933
			write_unlock_irqrestore(&atomic_rw, iflags);
2934
			mk_sense_buffer(scp, ILLEGAL_REQUEST, 0x10, prot_ret);
2935 2936 2937 2938
			return illegal_condition_result;
		}
	}

2939
	ret = do_device_access(scp, lba, num, true);
2940
	if (unlikely(scsi_debug_lbp()))
2941
		map_region(lba, num);
L
Linus Torvalds 已提交
2942
	write_unlock_irqrestore(&atomic_rw, iflags);
2943
	if (unlikely(-1 == ret))
2944
		return DID_ERROR << 16;
2945 2946
	else if (unlikely(sdebug_verbose &&
			  (ret < (num * sdebug_sector_size))))
2947
		sdev_printk(KERN_INFO, scp->device,
2948
			    "%s: write: cdb indicated=%u, IO sent=%d bytes\n",
2949
			    my_name, num * sdebug_sector_size, ret);
2950

2951
	if (unlikely(sdebug_any_injecting_opt)) {
2952 2953
		struct sdebug_queued_cmd *sqcp =
				(struct sdebug_queued_cmd *)scp->host_scribble;
2954

2955 2956 2957 2958 2959 2960 2961 2962 2963 2964 2965 2966 2967
		if (sqcp) {
			if (sqcp->inj_recovered) {
				mk_sense_buffer(scp, RECOVERED_ERROR,
						THRESHOLD_EXCEEDED, 0);
				return check_condition_result;
			} else if (sqcp->inj_dif) {
				/* Logical block guard check failed */
				mk_sense_buffer(scp, ABORTED_COMMAND, 0x10, 1);
				return illegal_condition_result;
			} else if (sqcp->inj_dix) {
				mk_sense_buffer(scp, ILLEGAL_REQUEST, 0x10, 1);
				return illegal_condition_result;
			}
2968 2969
		}
	}
2970 2971 2972
	return 0;
}

2973 2974
static int resp_write_same(struct scsi_cmnd *scp, u64 lba, u32 num,
			   u32 ei_lba, bool unmap, bool ndob)
2975 2976 2977 2978
{
	unsigned long iflags;
	unsigned long long i;
	int ret;
2979
	u64 lba_off;
2980

2981
	ret = check_device_access_params(scp, lba, num);
2982 2983 2984 2985 2986
	if (ret)
		return ret;

	write_lock_irqsave(&atomic_rw, iflags);

2987
	if (unmap && scsi_debug_lbp()) {
2988 2989 2990 2991
		unmap_region(lba, num);
		goto out;
	}

2992
	lba_off = lba * sdebug_sector_size;
2993 2994
	/* if ndob then zero 1 logical block, else fetch 1 logical block */
	if (ndob) {
2995
		memset(fake_storep + lba_off, 0, sdebug_sector_size);
2996 2997
		ret = 0;
	} else
2998 2999
		ret = fetch_to_dev_buffer(scp, fake_storep + lba_off,
					  sdebug_sector_size);
3000 3001 3002

	if (-1 == ret) {
		write_unlock_irqrestore(&atomic_rw, iflags);
3003
		return DID_ERROR << 16;
3004
	} else if (sdebug_verbose && !ndob && (ret < sdebug_sector_size))
3005
		sdev_printk(KERN_INFO, scp->device,
3006
			    "%s: %s: lb size=%u, IO sent=%d bytes\n",
3007
			    my_name, "write same",
3008
			    sdebug_sector_size, ret);
3009 3010 3011

	/* Copy first sector to remaining blocks */
	for (i = 1 ; i < num ; i++)
3012 3013 3014
		memcpy(fake_storep + ((lba + i) * sdebug_sector_size),
		       fake_storep + lba_off,
		       sdebug_sector_size);
3015

3016
	if (scsi_debug_lbp())
3017 3018 3019 3020
		map_region(lba, num);
out:
	write_unlock_irqrestore(&atomic_rw, iflags);

L
Linus Torvalds 已提交
3021 3022 3023
	return 0;
}

3024 3025
static int resp_write_same_10(struct scsi_cmnd *scp,
			      struct sdebug_dev_info *devip)
3026 3027 3028 3029 3030 3031 3032 3033
{
	u8 *cmd = scp->cmnd;
	u32 lba;
	u16 num;
	u32 ei_lba = 0;
	bool unmap = false;

	if (cmd[1] & 0x8) {
3034
		if (sdebug_lbpws10 == 0) {
3035 3036 3037 3038 3039 3040 3041
			mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, 3);
			return check_condition_result;
		} else
			unmap = true;
	}
	lba = get_unaligned_be32(cmd + 2);
	num = get_unaligned_be16(cmd + 7);
3042
	if (num > sdebug_write_same_length) {
3043 3044 3045 3046 3047 3048
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 7, -1);
		return check_condition_result;
	}
	return resp_write_same(scp, lba, num, ei_lba, unmap, false);
}

3049 3050
static int resp_write_same_16(struct scsi_cmnd *scp,
			      struct sdebug_dev_info *devip)
3051 3052 3053 3054 3055 3056 3057 3058 3059
{
	u8 *cmd = scp->cmnd;
	u64 lba;
	u32 num;
	u32 ei_lba = 0;
	bool unmap = false;
	bool ndob = false;

	if (cmd[1] & 0x8) {	/* UNMAP */
3060
		if (sdebug_lbpws == 0) {
3061 3062 3063 3064 3065 3066 3067 3068 3069
			mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, 3);
			return check_condition_result;
		} else
			unmap = true;
	}
	if (cmd[1] & 0x1)  /* NDOB (no data-out buffer, assumes zeroes) */
		ndob = true;
	lba = get_unaligned_be64(cmd + 2);
	num = get_unaligned_be32(cmd + 10);
3070
	if (num > sdebug_write_same_length) {
3071 3072 3073 3074 3075 3076
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 10, -1);
		return check_condition_result;
	}
	return resp_write_same(scp, lba, num, ei_lba, unmap, ndob);
}

3077 3078 3079
/* Note the mode field is in the same position as the (lower) service action
 * field. For the Report supported operation codes command, SPC-4 suggests
 * each mode of this command should be reported separately; for future. */
3080 3081
static int resp_write_buffer(struct scsi_cmnd *scp,
			     struct sdebug_dev_info *devip)
3082 3083 3084 3085 3086 3087 3088 3089 3090 3091 3092 3093 3094 3095 3096 3097 3098 3099 3100 3101 3102 3103 3104 3105 3106 3107 3108 3109 3110 3111 3112 3113 3114 3115 3116 3117 3118 3119 3120 3121 3122 3123 3124 3125
{
	u8 *cmd = scp->cmnd;
	struct scsi_device *sdp = scp->device;
	struct sdebug_dev_info *dp;
	u8 mode;

	mode = cmd[1] & 0x1f;
	switch (mode) {
	case 0x4:	/* download microcode (MC) and activate (ACT) */
		/* set UAs on this device only */
		set_bit(SDEBUG_UA_BUS_RESET, devip->uas_bm);
		set_bit(SDEBUG_UA_MICROCODE_CHANGED, devip->uas_bm);
		break;
	case 0x5:	/* download MC, save and ACT */
		set_bit(SDEBUG_UA_MICROCODE_CHANGED_WO_RESET, devip->uas_bm);
		break;
	case 0x6:	/* download MC with offsets and ACT */
		/* set UAs on most devices (LUs) in this target */
		list_for_each_entry(dp,
				    &devip->sdbg_host->dev_info_list,
				    dev_list)
			if (dp->target == sdp->id) {
				set_bit(SDEBUG_UA_BUS_RESET, dp->uas_bm);
				if (devip != dp)
					set_bit(SDEBUG_UA_MICROCODE_CHANGED,
						dp->uas_bm);
			}
		break;
	case 0x7:	/* download MC with offsets, save, and ACT */
		/* set UA on all devices (LUs) in this target */
		list_for_each_entry(dp,
				    &devip->sdbg_host->dev_info_list,
				    dev_list)
			if (dp->target == sdp->id)
				set_bit(SDEBUG_UA_MICROCODE_CHANGED_WO_RESET,
					dp->uas_bm);
		break;
	default:
		/* do nothing for this command for other mode values */
		break;
	}
	return 0;
}

3126 3127
static int resp_comp_write(struct scsi_cmnd *scp,
			   struct sdebug_dev_info *devip)
3128 3129 3130 3131 3132 3133
{
	u8 *cmd = scp->cmnd;
	u8 *arr;
	u8 *fake_storep_hold;
	u64 lba;
	u32 dnum;
3134
	u32 lb_size = sdebug_sector_size;
3135 3136 3137
	u8 num;
	unsigned long iflags;
	int ret;
3138
	int retval = 0;
3139

3140
	lba = get_unaligned_be64(cmd + 2);
3141 3142 3143
	num = cmd[13];		/* 1 to a maximum of 255 logical blocks */
	if (0 == num)
		return 0;	/* degenerate case, not an error */
3144
	if (sdebug_dif == T10_PI_TYPE2_PROTECTION &&
3145 3146 3147 3148
	    (cmd[1] & 0xe0)) {
		mk_sense_invalid_opcode(scp);
		return check_condition_result;
	}
3149 3150
	if ((sdebug_dif == T10_PI_TYPE1_PROTECTION ||
	     sdebug_dif == T10_PI_TYPE3_PROTECTION) &&
3151 3152 3153 3154 3155 3156 3157 3158 3159 3160 3161 3162 3163 3164 3165
	    (cmd[1] & 0xe0) == 0)
		sdev_printk(KERN_ERR, scp->device, "Unprotected WR "
			    "to DIF device\n");

	/* inline check_device_access_params() */
	if (lba + num > sdebug_capacity) {
		mk_sense_buffer(scp, ILLEGAL_REQUEST, LBA_OUT_OF_RANGE, 0);
		return check_condition_result;
	}
	/* transfer length excessive (tie in to block limits VPD page) */
	if (num > sdebug_store_sectors) {
		/* needs work to find which cdb byte 'num' comes from */
		mk_sense_buffer(scp, ILLEGAL_REQUEST, INVALID_FIELD_IN_CDB, 0);
		return check_condition_result;
	}
3166 3167 3168 3169 3170 3171 3172
	dnum = 2 * num;
	arr = kzalloc(dnum * lb_size, GFP_ATOMIC);
	if (NULL == arr) {
		mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
				INSUFF_RES_ASCQ);
		return check_condition_result;
	}
3173 3174 3175 3176 3177 3178 3179 3180 3181 3182

	write_lock_irqsave(&atomic_rw, iflags);

	/* trick do_device_access() to fetch both compare and write buffers
	 * from data-in into arr. Safe (atomic) since write_lock held. */
	fake_storep_hold = fake_storep;
	fake_storep = arr;
	ret = do_device_access(scp, 0, dnum, true);
	fake_storep = fake_storep_hold;
	if (ret == -1) {
3183 3184
		retval = DID_ERROR << 16;
		goto cleanup;
3185
	} else if (sdebug_verbose && (ret < (dnum * lb_size)))
3186 3187 3188 3189 3190
		sdev_printk(KERN_INFO, scp->device, "%s: compare_write: cdb "
			    "indicated=%u, IO sent=%d bytes\n", my_name,
			    dnum * lb_size, ret);
	if (!comp_write_worker(lba, num, arr)) {
		mk_sense_buffer(scp, MISCOMPARE, MISCOMPARE_VERIFY_ASC, 0);
3191 3192
		retval = check_condition_result;
		goto cleanup;
3193 3194 3195
	}
	if (scsi_debug_lbp())
		map_region(lba, num);
3196
cleanup:
3197
	write_unlock_irqrestore(&atomic_rw, iflags);
3198 3199
	kfree(arr);
	return retval;
3200 3201
}

3202 3203 3204 3205 3206 3207
struct unmap_block_desc {
	__be64	lba;
	__be32	blocks;
	__be32	__reserved;
};

3208
static int resp_unmap(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
3209 3210 3211 3212 3213
{
	unsigned char *buf;
	struct unmap_block_desc *desc;
	unsigned int i, payload_len, descriptors;
	int ret;
3214
	unsigned long iflags;
3215 3216


3217 3218 3219 3220
	if (!scsi_debug_lbp())
		return 0;	/* fib and say its done */
	payload_len = get_unaligned_be16(scp->cmnd + 7);
	BUG_ON(scsi_bufflen(scp) != payload_len);
3221 3222

	descriptors = (payload_len - 8) / 16;
3223
	if (descriptors > sdebug_unmap_max_desc) {
3224 3225 3226
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 7, -1);
		return check_condition_result;
	}
3227

3228
	buf = kzalloc(scsi_bufflen(scp), GFP_ATOMIC);
3229 3230 3231
	if (!buf) {
		mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
				INSUFF_RES_ASCQ);
3232
		return check_condition_result;
3233
	}
3234

3235
	scsi_sg_copy_to_buffer(scp, buf, scsi_bufflen(scp));
3236 3237 3238 3239 3240 3241

	BUG_ON(get_unaligned_be16(&buf[0]) != payload_len - 2);
	BUG_ON(get_unaligned_be16(&buf[2]) != descriptors * 16);

	desc = (void *)&buf[8];

3242 3243
	write_lock_irqsave(&atomic_rw, iflags);

3244 3245 3246 3247
	for (i = 0 ; i < descriptors ; i++) {
		unsigned long long lba = get_unaligned_be64(&desc[i].lba);
		unsigned int num = get_unaligned_be32(&desc[i].blocks);

3248
		ret = check_device_access_params(scp, lba, num);
3249 3250 3251 3252 3253 3254 3255 3256 3257
		if (ret)
			goto out;

		unmap_region(lba, num);
	}

	ret = 0;

out:
3258
	write_unlock_irqrestore(&atomic_rw, iflags);
3259 3260 3261 3262 3263 3264 3265
	kfree(buf);

	return ret;
}

#define SDEBUG_GET_LBA_STATUS_LEN 32

3266 3267
static int resp_get_lba_status(struct scsi_cmnd *scp,
			       struct sdebug_dev_info *devip)
3268
{
3269 3270 3271 3272
	u8 *cmd = scp->cmnd;
	u64 lba;
	u32 alloc_len, mapped, num;
	u8 arr[SDEBUG_GET_LBA_STATUS_LEN];
3273 3274
	int ret;

3275 3276
	lba = get_unaligned_be64(cmd + 2);
	alloc_len = get_unaligned_be32(cmd + 10);
3277 3278 3279 3280

	if (alloc_len < 24)
		return 0;

3281
	ret = check_device_access_params(scp, lba, 1);
3282 3283 3284
	if (ret)
		return ret;

3285 3286 3287 3288 3289 3290 3291 3292 3293 3294 3295
	if (scsi_debug_lbp())
		mapped = map_state(lba, &num);
	else {
		mapped = 1;
		/* following just in case virtual_gb changed */
		sdebug_capacity = get_sdebug_capacity();
		if (sdebug_capacity - lba <= 0xffffffff)
			num = sdebug_capacity - lba;
		else
			num = 0xffffffff;
	}
3296 3297

	memset(arr, 0, SDEBUG_GET_LBA_STATUS_LEN);
3298 3299 3300 3301
	put_unaligned_be32(20, arr);		/* Parameter Data Length */
	put_unaligned_be64(lba, arr + 8);	/* LBA */
	put_unaligned_be32(num, arr + 16);	/* Number of blocks */
	arr[20] = !mapped;		/* prov_stat=0: mapped; 1: dealloc */
3302

3303
	return fill_from_dev_buffer(scp, arr, SDEBUG_GET_LBA_STATUS_LEN);
3304 3305
}

3306 3307
#define RL_BUCKET_ELEMS 8

3308 3309 3310 3311 3312 3313 3314 3315 3316 3317
/* Even though each pseudo target has a REPORT LUNS "well known logical unit"
 * (W-LUN), the normal Linux scanning logic does not associate it with a
 * device (e.g. /dev/sg7). The following magic will make that association:
 *   "cd /sys/class/scsi_host/host<n> ; echo '- - 49409' > scan"
 * where <n> is a host number. If there are multiple targets in a host then
 * the above will associate a W-LUN to each target. To only get a W-LUN
 * for target 2, then use "echo '- 2 49409' > scan" .
 */
static int resp_report_luns(struct scsi_cmnd *scp,
			    struct sdebug_dev_info *devip)
L
Linus Torvalds 已提交
3318
{
3319
	unsigned char *cmd = scp->cmnd;
L
Linus Torvalds 已提交
3320
	unsigned int alloc_len;
3321
	unsigned char select_report;
3322
	u64 lun;
3323
	struct scsi_lun *lun_p;
3324
	u8 arr[RL_BUCKET_ELEMS * sizeof(struct scsi_lun)];
3325 3326 3327 3328
	unsigned int lun_cnt;	/* normal LUN count (max: 256) */
	unsigned int wlun_cnt;	/* report luns W-LUN count */
	unsigned int tlun_cnt;	/* total LUN count */
	unsigned int rlen;	/* response length (in bytes) */
3329 3330 3331
	int k, j, n, res;
	unsigned int off_rsp = 0;
	const int sz_lun = sizeof(struct scsi_lun);
L
Linus Torvalds 已提交
3332

3333
	clear_luns_changed_on_target(devip);
3334 3335 3336 3337 3338 3339 3340

	select_report = cmd[2];
	alloc_len = get_unaligned_be32(cmd + 6);

	if (alloc_len < 4) {
		pr_err("alloc len too small %d\n", alloc_len);
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 6, -1);
L
Linus Torvalds 已提交
3341 3342
		return check_condition_result;
	}
3343 3344 3345 3346 3347 3348 3349

	switch (select_report) {
	case 0:		/* all LUNs apart from W-LUNs */
		lun_cnt = sdebug_max_luns;
		wlun_cnt = 0;
		break;
	case 1:		/* only W-LUNs */
D
Douglas Gilbert 已提交
3350
		lun_cnt = 0;
3351 3352 3353 3354 3355 3356 3357 3358 3359 3360 3361 3362 3363 3364 3365 3366
		wlun_cnt = 1;
		break;
	case 2:		/* all LUNs */
		lun_cnt = sdebug_max_luns;
		wlun_cnt = 1;
		break;
	case 0x10:	/* only administrative LUs */
	case 0x11:	/* see SPC-5 */
	case 0x12:	/* only subsiduary LUs owned by referenced LU */
	default:
		pr_debug("select report invalid %d\n", select_report);
		mk_sense_invalid_fld(scp, SDEB_IN_CDB, 2, -1);
		return check_condition_result;
	}

	if (sdebug_no_lun_0 && (lun_cnt > 0))
D
Douglas Gilbert 已提交
3367
		--lun_cnt;
3368 3369

	tlun_cnt = lun_cnt + wlun_cnt;
3370 3371
	rlen = tlun_cnt * sz_lun;	/* excluding 8 byte header */
	scsi_set_resid(scp, scsi_bufflen(scp));
3372 3373 3374
	pr_debug("select_report %d luns = %d wluns = %d no_lun0 %d\n",
		 select_report, lun_cnt, wlun_cnt, sdebug_no_lun_0);

3375
	/* loops rely on sizeof response header same as sizeof lun (both 8) */
3376
	lun = sdebug_no_lun_0 ? 1 : 0;
3377 3378 3379 3380 3381 3382 3383 3384 3385 3386 3387 3388 3389 3390 3391 3392 3393 3394 3395 3396 3397 3398 3399 3400 3401 3402 3403
	for (k = 0, j = 0, res = 0; true; ++k, j = 0) {
		memset(arr, 0, sizeof(arr));
		lun_p = (struct scsi_lun *)&arr[0];
		if (k == 0) {
			put_unaligned_be32(rlen, &arr[0]);
			++lun_p;
			j = 1;
		}
		for ( ; j < RL_BUCKET_ELEMS; ++j, ++lun_p) {
			if ((k * RL_BUCKET_ELEMS) + j > lun_cnt)
				break;
			int_to_scsilun(lun++, lun_p);
		}
		if (j < RL_BUCKET_ELEMS)
			break;
		n = j * sz_lun;
		res = p_fill_from_dev_buffer(scp, arr, n, off_rsp);
		if (res)
			return res;
		off_rsp += n;
	}
	if (wlun_cnt) {
		int_to_scsilun(SCSI_W_LUN_REPORT_LUNS, lun_p);
		++j;
	}
	if (j > 0)
		res = p_fill_from_dev_buffer(scp, arr, j * sz_lun, off_rsp);
3404
	return res;
L
Linus Torvalds 已提交
3405 3406
}

3407 3408 3409
static int resp_xdwriteread(struct scsi_cmnd *scp, unsigned long long lba,
			    unsigned int num, struct sdebug_dev_info *devip)
{
3410
	int j;
3411 3412 3413
	unsigned char *kaddr, *buf;
	unsigned int offset;
	struct scsi_data_buffer *sdb = scsi_in(scp);
3414
	struct sg_mapping_iter miter;
3415 3416

	/* better not to use temporary buffer. */
3417
	buf = kzalloc(scsi_bufflen(scp), GFP_ATOMIC);
3418
	if (!buf) {
3419 3420
		mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
				INSUFF_RES_ASCQ);
3421 3422
		return check_condition_result;
	}
3423

3424
	scsi_sg_copy_to_buffer(scp, buf, scsi_bufflen(scp));
3425 3426

	offset = 0;
3427 3428
	sg_miter_start(&miter, sdb->table.sgl, sdb->table.nents,
			SG_MITER_ATOMIC | SG_MITER_TO_SG);
3429

3430 3431 3432 3433
	while (sg_miter_next(&miter)) {
		kaddr = miter.addr;
		for (j = 0; j < miter.length; j++)
			*(kaddr + j) ^= *(buf + offset + j);
3434

3435
		offset += miter.length;
3436
	}
3437
	sg_miter_stop(&miter);
3438 3439
	kfree(buf);

3440
	return 0;
3441 3442
}

3443 3444
static int resp_xdwriteread_10(struct scsi_cmnd *scp,
			       struct sdebug_dev_info *devip)
3445 3446 3447 3448 3449 3450 3451 3452 3453 3454 3455 3456 3457 3458 3459 3460 3461 3462 3463 3464 3465 3466 3467 3468
{
	u8 *cmd = scp->cmnd;
	u64 lba;
	u32 num;
	int errsts;

	if (!scsi_bidi_cmnd(scp)) {
		mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
				INSUFF_RES_ASCQ);
		return check_condition_result;
	}
	errsts = resp_read_dt0(scp, devip);
	if (errsts)
		return errsts;
	if (!(cmd[1] & 0x4)) {		/* DISABLE_WRITE is not set */
		errsts = resp_write_dt0(scp, devip);
		if (errsts)
			return errsts;
	}
	lba = get_unaligned_be32(cmd + 2);
	num = get_unaligned_be16(cmd + 7);
	return resp_xdwriteread(scp, lba, num, devip);
}

3469 3470 3471 3472 3473 3474 3475 3476 3477 3478 3479 3480 3481 3482 3483 3484 3485 3486 3487
static struct sdebug_queue *get_queue(struct scsi_cmnd *cmnd)
{
	struct sdebug_queue *sqp = sdebug_q_arr;

	if (sdebug_mq_active) {
		u32 tag = blk_mq_unique_tag(cmnd->request);
		u16 hwq = blk_mq_unique_tag_to_hwq(tag);

		if (unlikely(hwq >= submit_queues)) {
			pr_warn("Unexpected hwq=%d, apply modulo\n", hwq);
			hwq %= submit_queues;
		}
		pr_debug("tag=%u, hwq=%d\n", tag, hwq);
		return sqp + hwq;
	} else
		return sqp;
}

/* Queued (deferred) command completions converge here. */
3488
static void sdebug_q_cmd_complete(struct sdebug_defer *sd_dp)
L
Linus Torvalds 已提交
3489
{
3490
	int qc_idx;
3491
	int retiring = 0;
L
Linus Torvalds 已提交
3492
	unsigned long iflags;
3493
	struct sdebug_queue *sqp;
3494 3495 3496
	struct sdebug_queued_cmd *sqcp;
	struct scsi_cmnd *scp;
	struct sdebug_dev_info *devip;
L
Linus Torvalds 已提交
3497

3498 3499 3500 3501 3502 3503 3504 3505 3506
	qc_idx = sd_dp->qc_idx;
	sqp = sdebug_q_arr + sd_dp->sqa_idx;
	if (sdebug_statistics) {
		atomic_inc(&sdebug_completions);
		if (raw_smp_processor_id() != sd_dp->issuing_cpu)
			atomic_inc(&sdebug_miss_cpus);
	}
	if (unlikely((qc_idx < 0) || (qc_idx >= SDEBUG_CANQUEUE))) {
		pr_err("wild qc_idx=%d\n", qc_idx);
L
Linus Torvalds 已提交
3507 3508
		return;
	}
3509 3510
	spin_lock_irqsave(&sqp->qc_lock, iflags);
	sqcp = &sqp->qc_arr[qc_idx];
3511
	scp = sqcp->a_cmnd;
D
Douglas Gilbert 已提交
3512
	if (unlikely(scp == NULL)) {
3513 3514 3515
		spin_unlock_irqrestore(&sqp->qc_lock, iflags);
		pr_err("scp is NULL, sqa_idx=%d, qc_idx=%d\n",
		       sd_dp->sqa_idx, qc_idx);
3516 3517 3518
		return;
	}
	devip = (struct sdebug_dev_info *)scp->device->hostdata;
3519
	if (likely(devip))
3520 3521
		atomic_dec(&devip->num_in_q);
	else
3522
		pr_err("devip=NULL\n");
3523
	if (unlikely(atomic_read(&retired_max_queue) > 0))
3524 3525 3526
		retiring = 1;

	sqcp->a_cmnd = NULL;
3527 3528
	if (unlikely(!test_and_clear_bit(qc_idx, sqp->in_use_bm))) {
		spin_unlock_irqrestore(&sqp->qc_lock, iflags);
3529
		pr_err("Unexpected completion\n");
L
Linus Torvalds 已提交
3530 3531
		return;
	}
3532 3533 3534 3535 3536

	if (unlikely(retiring)) {	/* user has reduced max_queue */
		int k, retval;

		retval = atomic_read(&retired_max_queue);
3537 3538
		if (qc_idx >= retval) {
			spin_unlock_irqrestore(&sqp->qc_lock, iflags);
3539
			pr_err("index %d too large\n", retval);
3540 3541
			return;
		}
3542
		k = find_last_bit(sqp->in_use_bm, retval);
3543
		if ((k < sdebug_max_queue) || (k == retval))
3544 3545 3546
			atomic_set(&retired_max_queue, 0);
		else
			atomic_set(&retired_max_queue, k + 1);
L
Linus Torvalds 已提交
3547
	}
3548
	spin_unlock_irqrestore(&sqp->qc_lock, iflags);
3549
	scp->scsi_done(scp); /* callback to mid level */
L
Linus Torvalds 已提交
3550 3551
}

3552
/* When high resolution timer goes off this function is called. */
3553
static enum hrtimer_restart sdebug_q_cmd_hrt_complete(struct hrtimer *timer)
3554
{
3555 3556 3557
	struct sdebug_defer *sd_dp = container_of(timer, struct sdebug_defer,
						  hrt);
	sdebug_q_cmd_complete(sd_dp);
3558 3559
	return HRTIMER_NORESTART;
}
L
Linus Torvalds 已提交
3560

3561
/* When work queue schedules work, it calls this function. */
3562
static void sdebug_q_cmd_wq_complete(struct work_struct *work)
3563 3564 3565 3566 3567 3568
{
	struct sdebug_defer *sd_dp = container_of(work, struct sdebug_defer,
						  ew.work);
	sdebug_q_cmd_complete(sd_dp);
}

D
Douglas Gilbert 已提交
3569
static bool got_shared_uuid;
C
Christoph Hellwig 已提交
3570
static uuid_t shared_uuid;
D
Douglas Gilbert 已提交
3571

3572 3573
static struct sdebug_dev_info *sdebug_device_create(
			struct sdebug_host_info *sdbg_host, gfp_t flags)
3574 3575 3576 3577 3578
{
	struct sdebug_dev_info *devip;

	devip = kzalloc(sizeof(*devip), flags);
	if (devip) {
D
Douglas Gilbert 已提交
3579
		if (sdebug_uuid_ctl == 1)
C
Christoph Hellwig 已提交
3580
			uuid_gen(&devip->lu_name);
D
Douglas Gilbert 已提交
3581 3582 3583 3584
		else if (sdebug_uuid_ctl == 2) {
			if (got_shared_uuid)
				devip->lu_name = shared_uuid;
			else {
C
Christoph Hellwig 已提交
3585
				uuid_gen(&shared_uuid);
D
Douglas Gilbert 已提交
3586 3587 3588 3589
				got_shared_uuid = true;
				devip->lu_name = shared_uuid;
			}
		}
3590 3591 3592 3593 3594 3595
		devip->sdbg_host = sdbg_host;
		list_add_tail(&devip->dev_list, &sdbg_host->dev_info_list);
	}
	return devip;
}

3596
static struct sdebug_dev_info *find_build_dev_info(struct scsi_device *sdev)
L
Linus Torvalds 已提交
3597
{
3598 3599 3600
	struct sdebug_host_info *sdbg_host;
	struct sdebug_dev_info *open_devip = NULL;
	struct sdebug_dev_info *devip;
L
Linus Torvalds 已提交
3601

3602 3603
	sdbg_host = *(struct sdebug_host_info **)shost_priv(sdev->host);
	if (!sdbg_host) {
3604
		pr_err("Host info NULL\n");
L
Linus Torvalds 已提交
3605 3606 3607 3608 3609 3610 3611 3612 3613 3614 3615 3616
		return NULL;
        }
	list_for_each_entry(devip, &sdbg_host->dev_info_list, dev_list) {
		if ((devip->used) && (devip->channel == sdev->channel) &&
                    (devip->target == sdev->id) &&
                    (devip->lun == sdev->lun))
                        return devip;
		else {
			if ((!devip->used) && (!open_devip))
				open_devip = devip;
		}
	}
3617 3618 3619
	if (!open_devip) { /* try and make a new one */
		open_devip = sdebug_device_create(sdbg_host, GFP_ATOMIC);
		if (!open_devip) {
3620
			pr_err("out of memory at line %d\n", __LINE__);
L
Linus Torvalds 已提交
3621 3622 3623
			return NULL;
		}
	}
3624 3625 3626 3627 3628

	open_devip->channel = sdev->channel;
	open_devip->target = sdev->id;
	open_devip->lun = sdev->lun;
	open_devip->sdbg_host = sdbg_host;
3629 3630
	atomic_set(&open_devip->num_in_q, 0);
	set_bit(SDEBUG_UA_POR, open_devip->uas_bm);
3631
	open_devip->used = true;
3632
	return open_devip;
L
Linus Torvalds 已提交
3633 3634
}

3635
static int scsi_debug_slave_alloc(struct scsi_device *sdp)
L
Linus Torvalds 已提交
3636
{
3637
	if (sdebug_verbose)
3638
		pr_info("slave_alloc <%u %u %u %llu>\n",
3639
		       sdp->host->host_no, sdp->channel, sdp->id, sdp->lun);
N
Nick Piggin 已提交
3640
	queue_flag_set_unlocked(QUEUE_FLAG_BIDI, sdp->request_queue);
3641 3642
	return 0;
}
L
Linus Torvalds 已提交
3643

3644 3645
static int scsi_debug_slave_configure(struct scsi_device *sdp)
{
3646 3647
	struct sdebug_dev_info *devip =
			(struct sdebug_dev_info *)sdp->hostdata;
3648

3649
	if (sdebug_verbose)
3650
		pr_info("slave_configure <%u %u %u %llu>\n",
3651
		       sdp->host->host_no, sdp->channel, sdp->id, sdp->lun);
D
Douglas Gilbert 已提交
3652 3653 3654
	if (sdp->host->max_cmd_len != SDEBUG_MAX_CMD_LEN)
		sdp->host->max_cmd_len = SDEBUG_MAX_CMD_LEN;
	if (devip == NULL) {
3655
		devip = find_build_dev_info(sdp);
D
Douglas Gilbert 已提交
3656
		if (devip == NULL)
3657 3658
			return 1;  /* no resources, will be marked offline */
	}
3659
	sdp->hostdata = devip;
3660
	blk_queue_max_segment_size(sdp->request_queue, -1U);
3661
	if (sdebug_no_uld)
3662
		sdp->no_uld_attach = 1;
3663 3664 3665 3666 3667 3668 3669
	return 0;
}

static void scsi_debug_slave_destroy(struct scsi_device *sdp)
{
	struct sdebug_dev_info *devip =
		(struct sdebug_dev_info *)sdp->hostdata;
3670

3671
	if (sdebug_verbose)
3672
		pr_info("slave_destroy <%u %u %u %llu>\n",
3673 3674
		       sdp->host->host_no, sdp->channel, sdp->id, sdp->lun);
	if (devip) {
L
Lucas De Marchi 已提交
3675
		/* make this slot available for re-use */
3676
		devip->used = false;
3677 3678 3679 3680
		sdp->hostdata = NULL;
	}
}

3681 3682 3683 3684 3685 3686 3687 3688 3689 3690
static void stop_qc_helper(struct sdebug_defer *sd_dp)
{
	if (!sd_dp)
		return;
	if ((sdebug_jdelay > 0) || (sdebug_ndelay > 0))
		hrtimer_cancel(&sd_dp->hrt);
	else if (sdebug_jdelay < 0)
		cancel_work_sync(&sd_dp->ew.work);
}

3691 3692 3693
/* If @cmnd found deletes its timer or work queue and returns true; else
   returns false */
static bool stop_queued_cmnd(struct scsi_cmnd *cmnd)
3694 3695
{
	unsigned long iflags;
3696 3697
	int j, k, qmax, r_qmax;
	struct sdebug_queue *sqp;
3698
	struct sdebug_queued_cmd *sqcp;
3699
	struct sdebug_dev_info *devip;
3700
	struct sdebug_defer *sd_dp;
3701

3702 3703 3704 3705 3706 3707 3708 3709 3710 3711 3712 3713 3714 3715 3716 3717 3718 3719 3720 3721 3722 3723
	for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp) {
		spin_lock_irqsave(&sqp->qc_lock, iflags);
		qmax = sdebug_max_queue;
		r_qmax = atomic_read(&retired_max_queue);
		if (r_qmax > qmax)
			qmax = r_qmax;
		for (k = 0; k < qmax; ++k) {
			if (test_bit(k, sqp->in_use_bm)) {
				sqcp = &sqp->qc_arr[k];
				if (cmnd != sqcp->a_cmnd)
					continue;
				/* found */
				devip = (struct sdebug_dev_info *)
						cmnd->device->hostdata;
				if (devip)
					atomic_dec(&devip->num_in_q);
				sqcp->a_cmnd = NULL;
				sd_dp = sqcp->sd_dp;
				spin_unlock_irqrestore(&sqp->qc_lock, iflags);
				stop_qc_helper(sd_dp);
				clear_bit(k, sqp->in_use_bm);
				return true;
3724
			}
3725
		}
3726
		spin_unlock_irqrestore(&sqp->qc_lock, iflags);
3727
	}
3728
	return false;
3729 3730
}

3731
/* Deletes (stops) timers or work queues of all queued commands */
3732 3733 3734
static void stop_all_queued(void)
{
	unsigned long iflags;
3735 3736
	int j, k;
	struct sdebug_queue *sqp;
3737
	struct sdebug_queued_cmd *sqcp;
3738
	struct sdebug_dev_info *devip;
3739
	struct sdebug_defer *sd_dp;
3740

3741 3742 3743 3744 3745 3746 3747 3748 3749 3750 3751 3752 3753 3754 3755 3756 3757
	for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp) {
		spin_lock_irqsave(&sqp->qc_lock, iflags);
		for (k = 0; k < SDEBUG_CANQUEUE; ++k) {
			if (test_bit(k, sqp->in_use_bm)) {
				sqcp = &sqp->qc_arr[k];
				if (sqcp->a_cmnd == NULL)
					continue;
				devip = (struct sdebug_dev_info *)
					sqcp->a_cmnd->device->hostdata;
				if (devip)
					atomic_dec(&devip->num_in_q);
				sqcp->a_cmnd = NULL;
				sd_dp = sqcp->sd_dp;
				spin_unlock_irqrestore(&sqp->qc_lock, iflags);
				stop_qc_helper(sd_dp);
				clear_bit(k, sqp->in_use_bm);
				spin_lock_irqsave(&sqp->qc_lock, iflags);
3758
			}
3759
		}
3760
		spin_unlock_irqrestore(&sqp->qc_lock, iflags);
3761
	}
L
Linus Torvalds 已提交
3762 3763
}

3764 3765
/* Free queued command memory on heap */
static void free_all_queued(void)
L
Linus Torvalds 已提交
3766
{
3767 3768
	int j, k;
	struct sdebug_queue *sqp;
3769 3770
	struct sdebug_queued_cmd *sqcp;

3771 3772 3773 3774 3775 3776
	for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp) {
		for (k = 0; k < SDEBUG_CANQUEUE; ++k) {
			sqcp = &sqp->qc_arr[k];
			kfree(sqcp->sd_dp);
			sqcp->sd_dp = NULL;
		}
3777
	}
L
Linus Torvalds 已提交
3778 3779
}

3780
static int scsi_debug_abort(struct scsi_cmnd *SCpnt)
L
Linus Torvalds 已提交
3781
{
3782 3783
	bool ok;

3784 3785
	++num_aborts;
	if (SCpnt) {
3786 3787 3788 3789 3790
		ok = stop_queued_cmnd(SCpnt);
		if (SCpnt->device && (SDEBUG_OPT_ALL_NOISE & sdebug_opts))
			sdev_printk(KERN_INFO, SCpnt->device,
				    "%s: command%s found\n", __func__,
				    ok ? "" : " not");
3791 3792
	}
	return SUCCESS;
L
Linus Torvalds 已提交
3793 3794 3795 3796 3797
}

static int scsi_debug_device_reset(struct scsi_cmnd * SCpnt)
{
	++num_dev_resets;
3798 3799
	if (SCpnt && SCpnt->device) {
		struct scsi_device *sdp = SCpnt->device;
3800 3801
		struct sdebug_dev_info *devip =
				(struct sdebug_dev_info *)sdp->hostdata;
3802

3803
		if (SDEBUG_OPT_ALL_NOISE & sdebug_opts)
3804
			sdev_printk(KERN_INFO, sdp, "%s\n", __func__);
L
Linus Torvalds 已提交
3805
		if (devip)
3806 3807 3808 3809 3810 3811 3812 3813 3814 3815 3816 3817 3818 3819 3820 3821 3822 3823 3824
			set_bit(SDEBUG_UA_POR, devip->uas_bm);
	}
	return SUCCESS;
}

static int scsi_debug_target_reset(struct scsi_cmnd *SCpnt)
{
	struct sdebug_host_info *sdbg_host;
	struct sdebug_dev_info *devip;
	struct scsi_device *sdp;
	struct Scsi_Host *hp;
	int k = 0;

	++num_target_resets;
	if (!SCpnt)
		goto lie;
	sdp = SCpnt->device;
	if (!sdp)
		goto lie;
3825
	if (SDEBUG_OPT_ALL_NOISE & sdebug_opts)
3826 3827 3828 3829 3830 3831 3832 3833 3834 3835 3836 3837 3838
		sdev_printk(KERN_INFO, sdp, "%s\n", __func__);
	hp = sdp->host;
	if (!hp)
		goto lie;
	sdbg_host = *(struct sdebug_host_info **)shost_priv(hp);
	if (sdbg_host) {
		list_for_each_entry(devip,
				    &sdbg_host->dev_info_list,
				    dev_list)
			if (devip->target == sdp->id) {
				set_bit(SDEBUG_UA_BUS_RESET, devip->uas_bm);
				++k;
			}
L
Linus Torvalds 已提交
3839
	}
3840
	if (SDEBUG_OPT_RESET_NOISE & sdebug_opts)
3841 3842 3843
		sdev_printk(KERN_INFO, sdp,
			    "%s: %d device(s) found in target\n", __func__, k);
lie:
L
Linus Torvalds 已提交
3844 3845 3846 3847 3848 3849
	return SUCCESS;
}

static int scsi_debug_bus_reset(struct scsi_cmnd * SCpnt)
{
	struct sdebug_host_info *sdbg_host;
3850
	struct sdebug_dev_info *devip;
L
Linus Torvalds 已提交
3851 3852
        struct scsi_device * sdp;
        struct Scsi_Host * hp;
3853
	int k = 0;
L
Linus Torvalds 已提交
3854 3855

	++num_bus_resets;
3856 3857 3858
	if (!(SCpnt && SCpnt->device))
		goto lie;
	sdp = SCpnt->device;
3859
	if (SDEBUG_OPT_ALL_NOISE & sdebug_opts)
3860 3861 3862
		sdev_printk(KERN_INFO, sdp, "%s\n", __func__);
	hp = sdp->host;
	if (hp) {
3863
		sdbg_host = *(struct sdebug_host_info **)shost_priv(hp);
L
Linus Torvalds 已提交
3864
		if (sdbg_host) {
3865
			list_for_each_entry(devip,
L
Linus Torvalds 已提交
3866
                                            &sdbg_host->dev_info_list,
3867 3868 3869 3870
					    dev_list) {
				set_bit(SDEBUG_UA_BUS_RESET, devip->uas_bm);
				++k;
			}
L
Linus Torvalds 已提交
3871 3872
		}
	}
3873
	if (SDEBUG_OPT_RESET_NOISE & sdebug_opts)
3874 3875 3876
		sdev_printk(KERN_INFO, sdp,
			    "%s: %d device(s) found in host\n", __func__, k);
lie:
L
Linus Torvalds 已提交
3877 3878 3879 3880 3881 3882
	return SUCCESS;
}

static int scsi_debug_host_reset(struct scsi_cmnd * SCpnt)
{
	struct sdebug_host_info * sdbg_host;
3883 3884
	struct sdebug_dev_info *devip;
	int k = 0;
L
Linus Torvalds 已提交
3885 3886

	++num_host_resets;
3887
	if ((SCpnt->device) && (SDEBUG_OPT_ALL_NOISE & sdebug_opts))
3888
		sdev_printk(KERN_INFO, SCpnt->device, "%s\n", __func__);
L
Linus Torvalds 已提交
3889 3890
        spin_lock(&sdebug_host_list_lock);
        list_for_each_entry(sdbg_host, &sdebug_host_list, host_list) {
3891 3892 3893 3894 3895
		list_for_each_entry(devip, &sdbg_host->dev_info_list,
				    dev_list) {
			set_bit(SDEBUG_UA_BUS_RESET, devip->uas_bm);
			++k;
		}
L
Linus Torvalds 已提交
3896 3897 3898
        }
        spin_unlock(&sdebug_host_list_lock);
	stop_all_queued();
3899
	if (SDEBUG_OPT_RESET_NOISE & sdebug_opts)
3900 3901
		sdev_printk(KERN_INFO, SCpnt->device,
			    "%s: %d device(s) found\n", __func__, k);
L
Linus Torvalds 已提交
3902 3903 3904
	return SUCCESS;
}

3905
static void __init sdebug_build_parts(unsigned char *ramp,
3906
				      unsigned long store_size)
L
Linus Torvalds 已提交
3907 3908 3909 3910 3911 3912 3913
{
	struct partition * pp;
	int starts[SDEBUG_MAX_PARTS + 2];
	int sectors_per_part, num_sectors, k;
	int heads_by_sects, start_sec, end_sec;

	/* assume partition table already zeroed */
3914
	if ((sdebug_num_parts < 1) || (store_size < 1048576))
L
Linus Torvalds 已提交
3915
		return;
3916 3917
	if (sdebug_num_parts > SDEBUG_MAX_PARTS) {
		sdebug_num_parts = SDEBUG_MAX_PARTS;
3918
		pr_warn("reducing partitions to %d\n", SDEBUG_MAX_PARTS);
L
Linus Torvalds 已提交
3919
	}
D
Douglas Gilbert 已提交
3920
	num_sectors = (int)sdebug_store_sectors;
L
Linus Torvalds 已提交
3921
	sectors_per_part = (num_sectors - sdebug_sectors_per)
3922
			   / sdebug_num_parts;
L
Linus Torvalds 已提交
3923 3924
	heads_by_sects = sdebug_heads * sdebug_sectors_per;
        starts[0] = sdebug_sectors_per;
3925
	for (k = 1; k < sdebug_num_parts; ++k)
L
Linus Torvalds 已提交
3926 3927
		starts[k] = ((k * sectors_per_part) / heads_by_sects)
			    * heads_by_sects;
3928 3929
	starts[sdebug_num_parts] = num_sectors;
	starts[sdebug_num_parts + 1] = 0;
L
Linus Torvalds 已提交
3930 3931 3932 3933 3934 3935 3936 3937 3938 3939 3940 3941 3942 3943 3944 3945 3946 3947 3948

	ramp[510] = 0x55;	/* magic partition markings */
	ramp[511] = 0xAA;
	pp = (struct partition *)(ramp + 0x1be);
	for (k = 0; starts[k + 1]; ++k, ++pp) {
		start_sec = starts[k];
		end_sec = starts[k + 1] - 1;
		pp->boot_ind = 0;

		pp->cyl = start_sec / heads_by_sects;
		pp->head = (start_sec - (pp->cyl * heads_by_sects))
			   / sdebug_sectors_per;
		pp->sector = (start_sec % sdebug_sectors_per) + 1;

		pp->end_cyl = end_sec / heads_by_sects;
		pp->end_head = (end_sec - (pp->end_cyl * heads_by_sects))
			       / sdebug_sectors_per;
		pp->end_sector = (end_sec % sdebug_sectors_per) + 1;

3949 3950
		pp->start_sect = cpu_to_le32(start_sec);
		pp->nr_sects = cpu_to_le32(end_sec - start_sec + 1);
L
Linus Torvalds 已提交
3951 3952 3953 3954
		pp->sys_ind = 0x83;	/* plain Linux partition */
	}
}

3955 3956 3957 3958 3959 3960 3961 3962 3963 3964 3965 3966 3967 3968 3969 3970 3971 3972 3973 3974 3975 3976 3977 3978 3979 3980 3981 3982 3983 3984 3985 3986 3987 3988 3989 3990 3991 3992 3993 3994 3995 3996 3997 3998 3999 4000 4001 4002 4003 4004
static void block_unblock_all_queues(bool block)
{
	int j;
	struct sdebug_queue *sqp;

	for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp)
		atomic_set(&sqp->blocked, (int)block);
}

/* Adjust (by rounding down) the sdebug_cmnd_count so abs(every_nth)-1
 * commands will be processed normally before triggers occur.
 */
static void tweak_cmnd_count(void)
{
	int count, modulo;

	modulo = abs(sdebug_every_nth);
	if (modulo < 2)
		return;
	block_unblock_all_queues(true);
	count = atomic_read(&sdebug_cmnd_count);
	atomic_set(&sdebug_cmnd_count, (count / modulo) * modulo);
	block_unblock_all_queues(false);
}

static void clear_queue_stats(void)
{
	atomic_set(&sdebug_cmnd_count, 0);
	atomic_set(&sdebug_completions, 0);
	atomic_set(&sdebug_miss_cpus, 0);
	atomic_set(&sdebug_a_tsf, 0);
}

static void setup_inject(struct sdebug_queue *sqp,
			 struct sdebug_queued_cmd *sqcp)
{
	if ((atomic_read(&sdebug_cmnd_count) % abs(sdebug_every_nth)) > 0)
		return;
	sqcp->inj_recovered = !!(SDEBUG_OPT_RECOVERED_ERR & sdebug_opts);
	sqcp->inj_transport = !!(SDEBUG_OPT_TRANSPORT_ERR & sdebug_opts);
	sqcp->inj_dif = !!(SDEBUG_OPT_DIF_ERR & sdebug_opts);
	sqcp->inj_dix = !!(SDEBUG_OPT_DIX_ERR & sdebug_opts);
	sqcp->inj_short = !!(SDEBUG_OPT_SHORT_TRANSFER & sdebug_opts);
}

/* Complete the processing of the thread that queued a SCSI command to this
 * driver. It either completes the command by calling cmnd_done() or
 * schedules a hr timer or work queue then returns 0. Returns
 * SCSI_MLQUEUE_HOST_BUSY if temporarily out of resources.
 */
4005 4006
static int schedule_resp(struct scsi_cmnd *cmnd, struct sdebug_dev_info *devip,
			 int scsi_result, int delta_jiff)
L
Linus Torvalds 已提交
4007
{
4008
	unsigned long iflags;
4009
	int k, num_in_q, qdepth, inject;
4010 4011
	struct sdebug_queue *sqp;
	struct sdebug_queued_cmd *sqcp;
4012
	struct scsi_device *sdp;
4013
	struct sdebug_defer *sd_dp;
4014

D
Douglas Gilbert 已提交
4015 4016
	if (unlikely(devip == NULL)) {
		if (scsi_result == 0)
4017 4018
			scsi_result = DID_NO_CONNECT << 16;
		goto respond_in_thread;
4019
	}
4020 4021
	sdp = cmnd->device;

4022
	if (unlikely(sdebug_verbose && scsi_result))
4023 4024
		sdev_printk(KERN_INFO, sdp, "%s: non-zero result=0x%x\n",
			    __func__, scsi_result);
4025 4026
	if (delta_jiff == 0)
		goto respond_in_thread;
L
Linus Torvalds 已提交
4027

4028
	/* schedule the response at a later time if resources permit */
4029 4030 4031 4032 4033 4034
	sqp = get_queue(cmnd);
	spin_lock_irqsave(&sqp->qc_lock, iflags);
	if (unlikely(atomic_read(&sqp->blocked))) {
		spin_unlock_irqrestore(&sqp->qc_lock, iflags);
		return SCSI_MLQUEUE_HOST_BUSY;
	}
4035 4036 4037
	num_in_q = atomic_read(&devip->num_in_q);
	qdepth = cmnd->device->queue_depth;
	inject = 0;
4038
	if (unlikely((qdepth > 0) && (num_in_q >= qdepth))) {
4039
		if (scsi_result) {
4040
			spin_unlock_irqrestore(&sqp->qc_lock, iflags);
4041 4042 4043
			goto respond_in_thread;
		} else
			scsi_result = device_qfull_result;
4044
	} else if (unlikely(sdebug_every_nth &&
4045 4046
			    (SDEBUG_OPT_RARE_TSF & sdebug_opts) &&
			    (scsi_result == 0))) {
4047 4048
		if ((num_in_q == (qdepth - 1)) &&
		    (atomic_inc_return(&sdebug_a_tsf) >=
4049
		     abs(sdebug_every_nth))) {
4050 4051
			atomic_set(&sdebug_a_tsf, 0);
			inject = 1;
4052
			scsi_result = device_qfull_result;
L
Linus Torvalds 已提交
4053 4054 4055
		}
	}

4056
	k = find_first_zero_bit(sqp->in_use_bm, sdebug_max_queue);
4057
	if (unlikely(k >= sdebug_max_queue)) {
4058
		spin_unlock_irqrestore(&sqp->qc_lock, iflags);
4059 4060
		if (scsi_result)
			goto respond_in_thread;
4061
		else if (SDEBUG_OPT_ALL_TSF & sdebug_opts)
4062
			scsi_result = device_qfull_result;
4063
		if (SDEBUG_OPT_Q_NOISE & sdebug_opts)
4064
			sdev_printk(KERN_INFO, sdp,
4065
				    "%s: max_queue=%d exceeded, %s\n",
4066
				    __func__, sdebug_max_queue,
4067 4068 4069 4070 4071
				    (scsi_result ?  "status: TASK SET FULL" :
						    "report: host busy"));
		if (scsi_result)
			goto respond_in_thread;
		else
4072 4073
			return SCSI_MLQUEUE_HOST_BUSY;
	}
4074
	__set_bit(k, sqp->in_use_bm);
4075
	atomic_inc(&devip->num_in_q);
4076
	sqcp = &sqp->qc_arr[k];
4077
	sqcp->a_cmnd = cmnd;
4078
	cmnd->host_scribble = (unsigned char *)sqcp;
4079
	cmnd->result = scsi_result;
4080
	sd_dp = sqcp->sd_dp;
4081 4082 4083
	spin_unlock_irqrestore(&sqp->qc_lock, iflags);
	if (unlikely(sdebug_every_nth && sdebug_any_injecting_opt))
		setup_inject(sqp, sqcp);
D
Douglas Gilbert 已提交
4084
	if (delta_jiff > 0 || sdebug_ndelay > 0) {
4085
		ktime_t kt;
4086

4087 4088 4089 4090 4091 4092
		if (delta_jiff > 0) {
			struct timespec ts;

			jiffies_to_timespec(delta_jiff, &ts);
			kt = ktime_set(ts.tv_sec, ts.tv_nsec);
		} else
T
Thomas Gleixner 已提交
4093
			kt = sdebug_ndelay;
4094 4095 4096
		if (NULL == sd_dp) {
			sd_dp = kzalloc(sizeof(*sd_dp), GFP_ATOMIC);
			if (NULL == sd_dp)
4097
				return SCSI_MLQUEUE_HOST_BUSY;
4098 4099
			sqcp->sd_dp = sd_dp;
			hrtimer_init(&sd_dp->hrt, CLOCK_MONOTONIC,
4100
				     HRTIMER_MODE_REL_PINNED);
4101
			sd_dp->hrt.function = sdebug_q_cmd_hrt_complete;
4102 4103
			sd_dp->sqa_idx = sqp - sdebug_q_arr;
			sd_dp->qc_idx = k;
L
Linus Torvalds 已提交
4104
		}
4105 4106 4107 4108
		if (sdebug_statistics)
			sd_dp->issuing_cpu = raw_smp_processor_id();
		hrtimer_start(&sd_dp->hrt, kt, HRTIMER_MODE_REL_PINNED);
	} else {	/* jdelay < 0, use work queue */
4109 4110 4111
		if (NULL == sd_dp) {
			sd_dp = kzalloc(sizeof(*sqcp->sd_dp), GFP_ATOMIC);
			if (NULL == sd_dp)
4112
				return SCSI_MLQUEUE_HOST_BUSY;
4113
			sqcp->sd_dp = sd_dp;
4114 4115
			sd_dp->sqa_idx = sqp - sdebug_q_arr;
			sd_dp->qc_idx = k;
4116
			INIT_WORK(&sd_dp->ew.work, sdebug_q_cmd_wq_complete);
4117
		}
4118 4119
		if (sdebug_statistics)
			sd_dp->issuing_cpu = raw_smp_processor_id();
4120
		schedule_work(&sd_dp->ew.work);
L
Linus Torvalds 已提交
4121
	}
4122 4123
	if (unlikely((SDEBUG_OPT_Q_NOISE & sdebug_opts) &&
		     (scsi_result == device_qfull_result)))
4124 4125 4126 4127 4128
		sdev_printk(KERN_INFO, sdp,
			    "%s: num_in_q=%d +1, %s%s\n", __func__,
			    num_in_q, (inject ? "<inject> " : ""),
			    "status: TASK SET FULL");
	return 0;
4129 4130 4131 4132 4133

respond_in_thread:	/* call back to mid-layer using invocation thread */
	cmnd->result = scsi_result;
	cmnd->scsi_done(cmnd);
	return 0;
L
Linus Torvalds 已提交
4134
}
4135

D
Douglas Gilbert 已提交
4136 4137 4138 4139 4140 4141
/* Note: The following macros create attribute files in the
   /sys/module/scsi_debug/parameters directory. Unfortunately this
   driver is unaware of a change and cannot trigger auxiliary actions
   as it can when the corresponding attribute in the
   /sys/bus/pseudo/drivers/scsi_debug directory is changed.
 */
4142 4143 4144
module_param_named(add_host, sdebug_add_host, int, S_IRUGO | S_IWUSR);
module_param_named(ato, sdebug_ato, int, S_IRUGO);
module_param_named(clustering, sdebug_clustering, bool, S_IRUGO | S_IWUSR);
4145
module_param_named(delay, sdebug_jdelay, int, S_IRUGO | S_IWUSR);
4146 4147 4148 4149 4150 4151 4152 4153
module_param_named(dev_size_mb, sdebug_dev_size_mb, int, S_IRUGO);
module_param_named(dif, sdebug_dif, int, S_IRUGO);
module_param_named(dix, sdebug_dix, int, S_IRUGO);
module_param_named(dsense, sdebug_dsense, int, S_IRUGO | S_IWUSR);
module_param_named(every_nth, sdebug_every_nth, int, S_IRUGO | S_IWUSR);
module_param_named(fake_rw, sdebug_fake_rw, int, S_IRUGO | S_IWUSR);
module_param_named(guard, sdebug_guard, uint, S_IRUGO);
module_param_named(host_lock, sdebug_host_lock, bool, S_IRUGO | S_IWUSR);
4154 4155 4156 4157 4158 4159
module_param_string(inq_vendor, sdebug_inq_vendor_id,
		    sizeof(sdebug_inq_vendor_id), S_IRUGO|S_IWUSR);
module_param_string(inq_product, sdebug_inq_product_id,
		    sizeof(sdebug_inq_product_id), S_IRUGO|S_IWUSR);
module_param_string(inq_rev, sdebug_inq_product_rev,
		    sizeof(sdebug_inq_product_rev), S_IRUGO|S_IWUSR);
4160 4161 4162 4163 4164 4165 4166 4167 4168 4169 4170 4171 4172 4173 4174
module_param_named(lbpu, sdebug_lbpu, int, S_IRUGO);
module_param_named(lbpws, sdebug_lbpws, int, S_IRUGO);
module_param_named(lbpws10, sdebug_lbpws10, int, S_IRUGO);
module_param_named(lbprz, sdebug_lbprz, int, S_IRUGO);
module_param_named(lowest_aligned, sdebug_lowest_aligned, int, S_IRUGO);
module_param_named(max_luns, sdebug_max_luns, int, S_IRUGO | S_IWUSR);
module_param_named(max_queue, sdebug_max_queue, int, S_IRUGO | S_IWUSR);
module_param_named(ndelay, sdebug_ndelay, int, S_IRUGO | S_IWUSR);
module_param_named(no_lun_0, sdebug_no_lun_0, int, S_IRUGO | S_IWUSR);
module_param_named(no_uld, sdebug_no_uld, int, S_IRUGO);
module_param_named(num_parts, sdebug_num_parts, int, S_IRUGO);
module_param_named(num_tgts, sdebug_num_tgts, int, S_IRUGO | S_IWUSR);
module_param_named(opt_blks, sdebug_opt_blks, int, S_IRUGO);
module_param_named(opts, sdebug_opts, int, S_IRUGO | S_IWUSR);
module_param_named(physblk_exp, sdebug_physblk_exp, int, S_IRUGO);
4175
module_param_named(opt_xferlen_exp, sdebug_opt_xferlen_exp, int, S_IRUGO);
4176 4177 4178 4179
module_param_named(ptype, sdebug_ptype, int, S_IRUGO | S_IWUSR);
module_param_named(removable, sdebug_removable, bool, S_IRUGO | S_IWUSR);
module_param_named(scsi_level, sdebug_scsi_level, int, S_IRUGO);
module_param_named(sector_size, sdebug_sector_size, int, S_IRUGO);
4180
module_param_named(statistics, sdebug_statistics, bool, S_IRUGO | S_IWUSR);
4181
module_param_named(strict, sdebug_strict, bool, S_IRUGO | S_IWUSR);
4182
module_param_named(submit_queues, submit_queues, int, S_IRUGO);
4183 4184 4185 4186 4187
module_param_named(unmap_alignment, sdebug_unmap_alignment, int, S_IRUGO);
module_param_named(unmap_granularity, sdebug_unmap_granularity, int, S_IRUGO);
module_param_named(unmap_max_blocks, sdebug_unmap_max_blocks, int, S_IRUGO);
module_param_named(unmap_max_desc, sdebug_unmap_max_desc, int, S_IRUGO);
module_param_named(virtual_gb, sdebug_virtual_gb, int, S_IRUGO | S_IWUSR);
D
Douglas Gilbert 已提交
4188
module_param_named(uuid_ctl, sdebug_uuid_ctl, int, S_IRUGO);
4189
module_param_named(vpd_use_hostno, sdebug_vpd_use_hostno, int,
4190
		   S_IRUGO | S_IWUSR);
4191
module_param_named(write_same_length, sdebug_write_same_length, int,
4192
		   S_IRUGO | S_IWUSR);
L
Linus Torvalds 已提交
4193 4194 4195 4196

MODULE_AUTHOR("Eric Youngdale + Douglas Gilbert");
MODULE_DESCRIPTION("SCSI debug adapter driver");
MODULE_LICENSE("GPL");
D
Douglas Gilbert 已提交
4197
MODULE_VERSION(SDEBUG_VERSION);
L
Linus Torvalds 已提交
4198 4199

MODULE_PARM_DESC(add_host, "0..127 hosts allowed(def=1)");
4200
MODULE_PARM_DESC(ato, "application tag ownership: 0=disk 1=host (def=1)");
4201
MODULE_PARM_DESC(clustering, "when set enables larger transfers (def=0)");
4202
MODULE_PARM_DESC(delay, "response delay (def=1 jiffy); 0:imm, -1,-2:tiny");
4203
MODULE_PARM_DESC(dev_size_mb, "size in MiB of ram shared by devs(def=8)");
4204 4205
MODULE_PARM_DESC(dif, "data integrity field type: 0-3 (def=0)");
MODULE_PARM_DESC(dix, "data integrity extensions mask (def=0)");
D
Douglas Gilbert 已提交
4206
MODULE_PARM_DESC(dsense, "use descriptor sense format(def=0 -> fixed)");
4207
MODULE_PARM_DESC(every_nth, "timeout every nth command(def=0)");
D
Douglas Gilbert 已提交
4208
MODULE_PARM_DESC(fake_rw, "fake reads/writes instead of copying (def=0)");
4209
MODULE_PARM_DESC(guard, "protection checksum: 0=crc, 1=ip (def=0)");
4210
MODULE_PARM_DESC(host_lock, "host_lock is ignored (def=0)");
4211 4212 4213
MODULE_PARM_DESC(inq_vendor, "SCSI INQUIRY vendor string (def=\"Linux\")");
MODULE_PARM_DESC(inq_product, "SCSI INQUIRY product string (def=\"scsi_debug\")");
MODULE_PARM_DESC(inq_rev, "SCSI INQUIRY revision string (def=\"0186\")");
4214 4215 4216
MODULE_PARM_DESC(lbpu, "enable LBP, support UNMAP command (def=0)");
MODULE_PARM_DESC(lbpws, "enable LBP, support WRITE SAME(16) with UNMAP bit (def=0)");
MODULE_PARM_DESC(lbpws10, "enable LBP, support WRITE SAME(10) with UNMAP bit (def=0)");
4217 4218
MODULE_PARM_DESC(lbprz,
	"on read unmapped LBs return 0 when 1 (def), return 0xff when 2");
4219
MODULE_PARM_DESC(lowest_aligned, "lowest aligned lba (def=0)");
D
Douglas Gilbert 已提交
4220
MODULE_PARM_DESC(max_luns, "number of LUNs per target to simulate(def=1)");
4221 4222
MODULE_PARM_DESC(max_queue, "max number of queued commands (1 to max(def))");
MODULE_PARM_DESC(ndelay, "response delay in nanoseconds (def=0 -> ignore)");
D
Douglas Gilbert 已提交
4223
MODULE_PARM_DESC(no_lun_0, "no LU number 0 (def=0 -> have lun 0)");
4224
MODULE_PARM_DESC(no_uld, "stop ULD (e.g. sd driver) attaching (def=0))");
L
Linus Torvalds 已提交
4225
MODULE_PARM_DESC(num_parts, "number of partitions(def=0)");
D
Douglas Gilbert 已提交
4226
MODULE_PARM_DESC(num_tgts, "number of targets per host to simulate(def=1)");
4227
MODULE_PARM_DESC(opt_blks, "optimal transfer length in blocks (def=1024)");
4228
MODULE_PARM_DESC(opts, "1->noise, 2->medium_err, 4->timeout, 8->recovered_err... (def=0)");
4229
MODULE_PARM_DESC(physblk_exp, "physical block exponent (def=0)");
4230
MODULE_PARM_DESC(opt_xferlen_exp, "optimal transfer length granularity exponent (def=physblk_exp)");
L
Linus Torvalds 已提交
4231
MODULE_PARM_DESC(ptype, "SCSI peripheral type(def=0[disk])");
4232
MODULE_PARM_DESC(removable, "claim to have removable media (def=0)");
4233
MODULE_PARM_DESC(scsi_level, "SCSI level to simulate(def=7[SPC-5])");
4234
MODULE_PARM_DESC(sector_size, "logical block size in bytes (def=512)");
4235
MODULE_PARM_DESC(statistics, "collect statistics on commands, queues (def=0)");
4236
MODULE_PARM_DESC(strict, "stricter checks: reserved field in cdb (def=0)");
4237
MODULE_PARM_DESC(submit_queues, "support for block multi-queue (def=1)");
4238 4239
MODULE_PARM_DESC(unmap_alignment, "lowest aligned thin provisioning lba (def=0)");
MODULE_PARM_DESC(unmap_granularity, "thin provisioning granularity in blocks (def=1)");
4240 4241
MODULE_PARM_DESC(unmap_max_blocks, "max # of blocks can be unmapped in one cmd (def=0xffffffff)");
MODULE_PARM_DESC(unmap_max_desc, "max # of ranges that can be unmapped in one cmd (def=256)");
D
Douglas Gilbert 已提交
4242 4243
MODULE_PARM_DESC(uuid_ctl,
		 "1->use uuid for lu name, 0->don't, 2->all use same (def=0)");
4244
MODULE_PARM_DESC(virtual_gb, "virtual gigabyte (GiB) size (def=0 -> use dev_size_mb)");
4245 4246
MODULE_PARM_DESC(vpd_use_hostno, "0 -> dev ids ignore hostno (def=1 -> unique dev ids)");
MODULE_PARM_DESC(write_same_length, "Maximum blocks per WRITE SAME cmd (def=0xffff)");
L
Linus Torvalds 已提交
4247

4248 4249
#define SDEBUG_INFO_LEN 256
static char sdebug_info[SDEBUG_INFO_LEN];
L
Linus Torvalds 已提交
4250 4251 4252

static const char * scsi_debug_info(struct Scsi_Host * shp)
{
4253 4254
	int k;

4255 4256 4257
	k = scnprintf(sdebug_info, SDEBUG_INFO_LEN, "%s: version %s [%s]\n",
		      my_name, SDEBUG_VERSION, sdebug_version_date);
	if (k >= (SDEBUG_INFO_LEN - 1))
4258
		return sdebug_info;
4259 4260 4261 4262
	scnprintf(sdebug_info + k, SDEBUG_INFO_LEN - k,
		  "  dev_size_mb=%d, opts=0x%x, submit_queues=%d, %s=%d",
		  sdebug_dev_size_mb, sdebug_opts, submit_queues,
		  "statistics", (int)sdebug_statistics);
L
Linus Torvalds 已提交
4263 4264 4265
	return sdebug_info;
}

4266
/* 'echo <val> > /proc/scsi/scsi_debug/<host_id>' writes to opts */
4267 4268
static int scsi_debug_write_info(struct Scsi_Host *host, char *buffer,
				 int length)
L
Linus Torvalds 已提交
4269
{
A
Al Viro 已提交
4270 4271 4272
	char arr[16];
	int opts;
	int minLen = length > 15 ? 15 : length;
L
Linus Torvalds 已提交
4273

A
Al Viro 已提交
4274 4275 4276 4277 4278 4279
	if (!capable(CAP_SYS_ADMIN) || !capable(CAP_SYS_RAWIO))
		return -EACCES;
	memcpy(arr, buffer, minLen);
	arr[minLen] = '\0';
	if (1 != sscanf(arr, "%d", &opts))
		return -EINVAL;
4280 4281 4282 4283
	sdebug_opts = opts;
	sdebug_verbose = !!(SDEBUG_OPT_NOISE & opts);
	sdebug_any_injecting_opt = !!(SDEBUG_OPT_ALL_INJECTING & opts);
	if (sdebug_every_nth != 0)
4284
		tweak_cmnd_count();
A
Al Viro 已提交
4285 4286
	return length;
}
L
Linus Torvalds 已提交
4287

4288 4289 4290
/* Output seen with 'cat /proc/scsi/scsi_debug/<host_id>'. It will be the
 * same for each scsi_debug host (if more than one). Some of the counters
 * output are not atomics so might be inaccurate in a busy system. */
A
Al Viro 已提交
4291 4292
static int scsi_debug_show_info(struct seq_file *m, struct Scsi_Host *host)
{
4293 4294 4295 4296 4297 4298 4299 4300 4301 4302 4303 4304 4305 4306 4307 4308 4309 4310 4311 4312 4313 4314 4315 4316 4317 4318 4319 4320 4321 4322 4323 4324 4325 4326 4327 4328 4329
	int f, j, l;
	struct sdebug_queue *sqp;

	seq_printf(m, "scsi_debug adapter driver, version %s [%s]\n",
		   SDEBUG_VERSION, sdebug_version_date);
	seq_printf(m, "num_tgts=%d, %ssize=%d MB, opts=0x%x, every_nth=%d\n",
		   sdebug_num_tgts, "shared (ram) ", sdebug_dev_size_mb,
		   sdebug_opts, sdebug_every_nth);
	seq_printf(m, "delay=%d, ndelay=%d, max_luns=%d, sector_size=%d %s\n",
		   sdebug_jdelay, sdebug_ndelay, sdebug_max_luns,
		   sdebug_sector_size, "bytes");
	seq_printf(m, "cylinders=%d, heads=%d, sectors=%d, command aborts=%d\n",
		   sdebug_cylinders_per, sdebug_heads, sdebug_sectors_per,
		   num_aborts);
	seq_printf(m, "RESETs: device=%d, target=%d, bus=%d, host=%d\n",
		   num_dev_resets, num_target_resets, num_bus_resets,
		   num_host_resets);
	seq_printf(m, "dix_reads=%d, dix_writes=%d, dif_errors=%d\n",
		   dix_reads, dix_writes, dif_errors);
	seq_printf(m, "usec_in_jiffy=%lu, %s=%d, mq_active=%d\n",
		   TICK_NSEC / 1000, "statistics", sdebug_statistics,
		   sdebug_mq_active);
	seq_printf(m, "cmnd_count=%d, completions=%d, %s=%d, a_tsf=%d\n",
		   atomic_read(&sdebug_cmnd_count),
		   atomic_read(&sdebug_completions),
		   "miss_cpus", atomic_read(&sdebug_miss_cpus),
		   atomic_read(&sdebug_a_tsf));

	seq_printf(m, "submit_queues=%d\n", submit_queues);
	for (j = 0, sqp = sdebug_q_arr; j < submit_queues; ++j, ++sqp) {
		seq_printf(m, "  queue %d:\n", j);
		f = find_first_bit(sqp->in_use_bm, sdebug_max_queue);
		if (f != sdebug_max_queue) {
			l = find_last_bit(sqp->in_use_bm, sdebug_max_queue);
			seq_printf(m, "    in_use_bm BUSY: %s: %d,%d\n",
				   "first,last bits", f, l);
		}
4330
	}
A
Al Viro 已提交
4331
	return 0;
L
Linus Torvalds 已提交
4332 4333
}

4334
static ssize_t delay_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4335
{
4336
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_jdelay);
L
Linus Torvalds 已提交
4337
}
4338 4339 4340
/* Returns -EBUSY if jdelay is being changed and commands are queued. The unit
 * of delay is jiffies.
 */
4341 4342
static ssize_t delay_store(struct device_driver *ddp, const char *buf,
			   size_t count)
L
Linus Torvalds 已提交
4343
{
4344
	int jdelay, res;
4345

D
Douglas Gilbert 已提交
4346
	if (count > 0 && sscanf(buf, "%d", &jdelay) == 1) {
4347
		res = count;
4348
		if (sdebug_jdelay != jdelay) {
4349 4350 4351 4352 4353 4354 4355 4356 4357 4358 4359 4360 4361 4362
			int j, k;
			struct sdebug_queue *sqp;

			block_unblock_all_queues(true);
			for (j = 0, sqp = sdebug_q_arr; j < submit_queues;
			     ++j, ++sqp) {
				k = find_first_bit(sqp->in_use_bm,
						   sdebug_max_queue);
				if (k != sdebug_max_queue) {
					res = -EBUSY;   /* queued commands */
					break;
				}
			}
			if (res > 0) {
4363 4364 4365
				/* make sure sdebug_defer instances get
				 * re-allocated for new delay variant */
				free_all_queued();
4366
				sdebug_jdelay = jdelay;
4367
				sdebug_ndelay = 0;
4368
			}
4369
			block_unblock_all_queues(false);
L
Linus Torvalds 已提交
4370
		}
4371
		return res;
L
Linus Torvalds 已提交
4372 4373 4374
	}
	return -EINVAL;
}
4375
static DRIVER_ATTR_RW(delay);
L
Linus Torvalds 已提交
4376

4377 4378
static ssize_t ndelay_show(struct device_driver *ddp, char *buf)
{
4379
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_ndelay);
4380 4381
}
/* Returns -EBUSY if ndelay is being changed and commands are queued */
4382
/* If > 0 and accepted then sdebug_jdelay is set to JDELAY_OVERRIDDEN */
4383
static ssize_t ndelay_store(struct device_driver *ddp, const char *buf,
4384
			    size_t count)
4385
{
4386
	int ndelay, res;
4387 4388

	if ((count > 0) && (1 == sscanf(buf, "%d", &ndelay)) &&
4389
	    (ndelay >= 0) && (ndelay < (1000 * 1000 * 1000))) {
4390
		res = count;
4391
		if (sdebug_ndelay != ndelay) {
4392 4393 4394 4395 4396 4397 4398 4399 4400 4401 4402 4403 4404 4405
			int j, k;
			struct sdebug_queue *sqp;

			block_unblock_all_queues(true);
			for (j = 0, sqp = sdebug_q_arr; j < submit_queues;
			     ++j, ++sqp) {
				k = find_first_bit(sqp->in_use_bm,
						   sdebug_max_queue);
				if (k != sdebug_max_queue) {
					res = -EBUSY;   /* queued commands */
					break;
				}
			}
			if (res > 0) {
4406 4407 4408
				/* make sure sdebug_defer instances get
				 * re-allocated for new delay variant */
				free_all_queued();
4409
				sdebug_ndelay = ndelay;
4410 4411
				sdebug_jdelay = ndelay  ? JDELAY_OVERRIDDEN
							: DEF_JDELAY;
4412
			}
4413
			block_unblock_all_queues(false);
4414 4415 4416 4417 4418 4419 4420
		}
		return res;
	}
	return -EINVAL;
}
static DRIVER_ATTR_RW(ndelay);

4421
static ssize_t opts_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4422
{
4423
	return scnprintf(buf, PAGE_SIZE, "0x%x\n", sdebug_opts);
L
Linus Torvalds 已提交
4424 4425
}

4426 4427
static ssize_t opts_store(struct device_driver *ddp, const char *buf,
			  size_t count)
L
Linus Torvalds 已提交
4428 4429 4430 4431 4432
{
        int opts;
	char work[20];

        if (1 == sscanf(buf, "%10s", work)) {
4433
		if (0 == strncasecmp(work,"0x", 2)) {
L
Linus Torvalds 已提交
4434 4435 4436 4437 4438 4439 4440 4441 4442
			if (1 == sscanf(&work[2], "%x", &opts))
				goto opts_done;
		} else {
			if (1 == sscanf(work, "%d", &opts))
				goto opts_done;
		}
	}
	return -EINVAL;
opts_done:
4443 4444 4445
	sdebug_opts = opts;
	sdebug_verbose = !!(SDEBUG_OPT_NOISE & opts);
	sdebug_any_injecting_opt = !!(SDEBUG_OPT_ALL_INJECTING & opts);
4446
	tweak_cmnd_count();
L
Linus Torvalds 已提交
4447 4448
	return count;
}
4449
static DRIVER_ATTR_RW(opts);
L
Linus Torvalds 已提交
4450

4451
static ssize_t ptype_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4452
{
4453
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_ptype);
L
Linus Torvalds 已提交
4454
}
4455 4456
static ssize_t ptype_store(struct device_driver *ddp, const char *buf,
			   size_t count)
L
Linus Torvalds 已提交
4457 4458 4459 4460
{
        int n;

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4461
		sdebug_ptype = n;
L
Linus Torvalds 已提交
4462 4463 4464 4465
		return count;
	}
	return -EINVAL;
}
4466
static DRIVER_ATTR_RW(ptype);
L
Linus Torvalds 已提交
4467

4468
static ssize_t dsense_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4469
{
4470
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_dsense);
L
Linus Torvalds 已提交
4471
}
4472 4473
static ssize_t dsense_store(struct device_driver *ddp, const char *buf,
			    size_t count)
L
Linus Torvalds 已提交
4474 4475 4476 4477
{
        int n;

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4478
		sdebug_dsense = n;
L
Linus Torvalds 已提交
4479 4480 4481 4482
		return count;
	}
	return -EINVAL;
}
4483
static DRIVER_ATTR_RW(dsense);
L
Linus Torvalds 已提交
4484

4485
static ssize_t fake_rw_show(struct device_driver *ddp, char *buf)
D
Douglas Gilbert 已提交
4486
{
4487
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_fake_rw);
D
Douglas Gilbert 已提交
4488
}
4489 4490
static ssize_t fake_rw_store(struct device_driver *ddp, const char *buf,
			     size_t count)
D
Douglas Gilbert 已提交
4491 4492 4493 4494
{
        int n;

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4495
		n = (n > 0);
4496 4497
		sdebug_fake_rw = (sdebug_fake_rw > 0);
		if (sdebug_fake_rw != n) {
4498 4499
			if ((0 == n) && (NULL == fake_storep)) {
				unsigned long sz =
4500
					(unsigned long)sdebug_dev_size_mb *
4501 4502 4503 4504
					1048576;

				fake_storep = vmalloc(sz);
				if (NULL == fake_storep) {
4505
					pr_err("out of memory, 9\n");
4506 4507 4508 4509
					return -ENOMEM;
				}
				memset(fake_storep, 0, sz);
			}
4510
			sdebug_fake_rw = n;
4511
		}
D
Douglas Gilbert 已提交
4512 4513 4514 4515
		return count;
	}
	return -EINVAL;
}
4516
static DRIVER_ATTR_RW(fake_rw);
D
Douglas Gilbert 已提交
4517

4518
static ssize_t no_lun_0_show(struct device_driver *ddp, char *buf)
D
Douglas Gilbert 已提交
4519
{
4520
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_no_lun_0);
D
Douglas Gilbert 已提交
4521
}
4522 4523
static ssize_t no_lun_0_store(struct device_driver *ddp, const char *buf,
			      size_t count)
D
Douglas Gilbert 已提交
4524 4525 4526 4527
{
        int n;

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4528
		sdebug_no_lun_0 = n;
D
Douglas Gilbert 已提交
4529 4530 4531 4532
		return count;
	}
	return -EINVAL;
}
4533
static DRIVER_ATTR_RW(no_lun_0);
D
Douglas Gilbert 已提交
4534

4535
static ssize_t num_tgts_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4536
{
4537
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_num_tgts);
L
Linus Torvalds 已提交
4538
}
4539 4540
static ssize_t num_tgts_store(struct device_driver *ddp, const char *buf,
			      size_t count)
L
Linus Torvalds 已提交
4541 4542 4543 4544
{
        int n;

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4545
		sdebug_num_tgts = n;
L
Linus Torvalds 已提交
4546 4547 4548 4549 4550
		sdebug_max_tgts_luns();
		return count;
	}
	return -EINVAL;
}
4551
static DRIVER_ATTR_RW(num_tgts);
L
Linus Torvalds 已提交
4552

4553
static ssize_t dev_size_mb_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4554
{
4555
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_dev_size_mb);
L
Linus Torvalds 已提交
4556
}
4557
static DRIVER_ATTR_RO(dev_size_mb);
L
Linus Torvalds 已提交
4558

4559
static ssize_t num_parts_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4560
{
4561
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_num_parts);
L
Linus Torvalds 已提交
4562
}
4563
static DRIVER_ATTR_RO(num_parts);
L
Linus Torvalds 已提交
4564

4565
static ssize_t every_nth_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4566
{
4567
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_every_nth);
L
Linus Torvalds 已提交
4568
}
4569 4570
static ssize_t every_nth_store(struct device_driver *ddp, const char *buf,
			       size_t count)
L
Linus Torvalds 已提交
4571 4572 4573 4574
{
        int nth;

	if ((count > 0) && (1 == sscanf(buf, "%d", &nth))) {
4575
		sdebug_every_nth = nth;
4576 4577 4578 4579 4580
		if (nth && !sdebug_statistics) {
			pr_info("every_nth needs statistics=1, set it\n");
			sdebug_statistics = true;
		}
		tweak_cmnd_count();
L
Linus Torvalds 已提交
4581 4582 4583 4584
		return count;
	}
	return -EINVAL;
}
4585
static DRIVER_ATTR_RW(every_nth);
L
Linus Torvalds 已提交
4586

4587
static ssize_t max_luns_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4588
{
4589
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_max_luns);
L
Linus Torvalds 已提交
4590
}
4591 4592
static ssize_t max_luns_store(struct device_driver *ddp, const char *buf,
			      size_t count)
L
Linus Torvalds 已提交
4593 4594
{
        int n;
4595
	bool changed;
L
Linus Torvalds 已提交
4596 4597

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4598 4599 4600 4601
		if (n > 256) {
			pr_warn("max_luns can be no more than 256\n");
			return -EINVAL;
		}
4602 4603
		changed = (sdebug_max_luns != n);
		sdebug_max_luns = n;
L
Linus Torvalds 已提交
4604
		sdebug_max_tgts_luns();
4605
		if (changed && (sdebug_scsi_level >= 5)) {	/* >= SPC-3 */
4606 4607 4608 4609 4610 4611 4612 4613 4614 4615 4616 4617 4618 4619
			struct sdebug_host_info *sdhp;
			struct sdebug_dev_info *dp;

			spin_lock(&sdebug_host_list_lock);
			list_for_each_entry(sdhp, &sdebug_host_list,
					    host_list) {
				list_for_each_entry(dp, &sdhp->dev_info_list,
						    dev_list) {
					set_bit(SDEBUG_UA_LUNS_CHANGED,
						dp->uas_bm);
				}
			}
			spin_unlock(&sdebug_host_list_lock);
		}
L
Linus Torvalds 已提交
4620 4621 4622 4623
		return count;
	}
	return -EINVAL;
}
4624
static DRIVER_ATTR_RW(max_luns);
L
Linus Torvalds 已提交
4625

4626
static ssize_t max_queue_show(struct device_driver *ddp, char *buf)
4627
{
4628
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_max_queue);
4629
}
4630 4631
/* N.B. max_queue can be changed while there are queued commands. In flight
 * commands beyond the new max_queue will be completed. */
4632 4633
static ssize_t max_queue_store(struct device_driver *ddp, const char *buf,
			       size_t count)
4634
{
4635 4636
	int j, n, k, a;
	struct sdebug_queue *sqp;
4637 4638

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n > 0) &&
4639 4640 4641 4642 4643 4644 4645 4646 4647
	    (n <= SDEBUG_CANQUEUE)) {
		block_unblock_all_queues(true);
		k = 0;
		for (j = 0, sqp = sdebug_q_arr; j < submit_queues;
		     ++j, ++sqp) {
			a = find_last_bit(sqp->in_use_bm, SDEBUG_CANQUEUE);
			if (a > k)
				k = a;
		}
4648
		sdebug_max_queue = n;
4649
		if (k == SDEBUG_CANQUEUE)
4650 4651 4652 4653 4654
			atomic_set(&retired_max_queue, 0);
		else if (k >= n)
			atomic_set(&retired_max_queue, k + 1);
		else
			atomic_set(&retired_max_queue, 0);
4655
		block_unblock_all_queues(false);
4656 4657 4658 4659
		return count;
	}
	return -EINVAL;
}
4660
static DRIVER_ATTR_RW(max_queue);
4661

4662
static ssize_t no_uld_show(struct device_driver *ddp, char *buf)
4663
{
4664
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_no_uld);
4665
}
4666
static DRIVER_ATTR_RO(no_uld);
4667

4668
static ssize_t scsi_level_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4669
{
4670
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_scsi_level);
L
Linus Torvalds 已提交
4671
}
4672
static DRIVER_ATTR_RO(scsi_level);
L
Linus Torvalds 已提交
4673

4674
static ssize_t virtual_gb_show(struct device_driver *ddp, char *buf)
D
Douglas Gilbert 已提交
4675
{
4676
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_virtual_gb);
D
Douglas Gilbert 已提交
4677
}
4678 4679
static ssize_t virtual_gb_store(struct device_driver *ddp, const char *buf,
				size_t count)
D
Douglas Gilbert 已提交
4680
{
4681
        int n;
4682
	bool changed;
D
Douglas Gilbert 已提交
4683 4684

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4685 4686
		changed = (sdebug_virtual_gb != n);
		sdebug_virtual_gb = n;
4687
		sdebug_capacity = get_sdebug_capacity();
4688 4689 4690 4691
		if (changed) {
			struct sdebug_host_info *sdhp;
			struct sdebug_dev_info *dp;

4692
			spin_lock(&sdebug_host_list_lock);
4693 4694 4695 4696 4697 4698 4699 4700
			list_for_each_entry(sdhp, &sdebug_host_list,
					    host_list) {
				list_for_each_entry(dp, &sdhp->dev_info_list,
						    dev_list) {
					set_bit(SDEBUG_UA_CAPACITY_CHANGED,
						dp->uas_bm);
				}
			}
4701
			spin_unlock(&sdebug_host_list_lock);
4702
		}
D
Douglas Gilbert 已提交
4703 4704 4705 4706
		return count;
	}
	return -EINVAL;
}
4707
static DRIVER_ATTR_RW(virtual_gb);
D
Douglas Gilbert 已提交
4708

4709
static ssize_t add_host_show(struct device_driver *ddp, char *buf)
L
Linus Torvalds 已提交
4710
{
4711
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_add_host);
L
Linus Torvalds 已提交
4712 4713
}

4714 4715 4716
static int sdebug_add_adapter(void);
static void sdebug_remove_adapter(void);

4717 4718
static ssize_t add_host_store(struct device_driver *ddp, const char *buf,
			      size_t count)
L
Linus Torvalds 已提交
4719
{
4720
	int delta_hosts;
L
Linus Torvalds 已提交
4721

4722
	if (sscanf(buf, "%d", &delta_hosts) != 1)
L
Linus Torvalds 已提交
4723 4724 4725 4726 4727 4728 4729 4730 4731 4732 4733 4734
		return -EINVAL;
	if (delta_hosts > 0) {
		do {
			sdebug_add_adapter();
		} while (--delta_hosts);
	} else if (delta_hosts < 0) {
		do {
			sdebug_remove_adapter();
		} while (++delta_hosts);
	}
	return count;
}
4735
static DRIVER_ATTR_RW(add_host);
L
Linus Torvalds 已提交
4736

4737
static ssize_t vpd_use_hostno_show(struct device_driver *ddp, char *buf)
D
Douglas Gilbert 已提交
4738
{
4739
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_vpd_use_hostno);
D
Douglas Gilbert 已提交
4740
}
4741 4742
static ssize_t vpd_use_hostno_store(struct device_driver *ddp, const char *buf,
				    size_t count)
D
Douglas Gilbert 已提交
4743 4744 4745 4746
{
	int n;

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4747
		sdebug_vpd_use_hostno = n;
D
Douglas Gilbert 已提交
4748 4749 4750 4751
		return count;
	}
	return -EINVAL;
}
4752
static DRIVER_ATTR_RW(vpd_use_hostno);
D
Douglas Gilbert 已提交
4753

4754 4755 4756 4757 4758 4759 4760 4761 4762 4763 4764 4765 4766 4767 4768 4769 4770 4771 4772 4773 4774 4775
static ssize_t statistics_show(struct device_driver *ddp, char *buf)
{
	return scnprintf(buf, PAGE_SIZE, "%d\n", (int)sdebug_statistics);
}
static ssize_t statistics_store(struct device_driver *ddp, const char *buf,
				size_t count)
{
	int n;

	if ((count > 0) && (sscanf(buf, "%d", &n) == 1) && (n >= 0)) {
		if (n > 0)
			sdebug_statistics = true;
		else {
			clear_queue_stats();
			sdebug_statistics = false;
		}
		return count;
	}
	return -EINVAL;
}
static DRIVER_ATTR_RW(statistics);

4776
static ssize_t sector_size_show(struct device_driver *ddp, char *buf)
4777
{
4778
	return scnprintf(buf, PAGE_SIZE, "%u\n", sdebug_sector_size);
4779
}
4780
static DRIVER_ATTR_RO(sector_size);
4781

4782 4783 4784 4785 4786 4787
static ssize_t submit_queues_show(struct device_driver *ddp, char *buf)
{
	return scnprintf(buf, PAGE_SIZE, "%d\n", submit_queues);
}
static DRIVER_ATTR_RO(submit_queues);

4788
static ssize_t dix_show(struct device_driver *ddp, char *buf)
4789
{
4790
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_dix);
4791
}
4792
static DRIVER_ATTR_RO(dix);
4793

4794
static ssize_t dif_show(struct device_driver *ddp, char *buf)
4795
{
4796
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_dif);
4797
}
4798
static DRIVER_ATTR_RO(dif);
4799

4800
static ssize_t guard_show(struct device_driver *ddp, char *buf)
4801
{
4802
	return scnprintf(buf, PAGE_SIZE, "%u\n", sdebug_guard);
4803
}
4804
static DRIVER_ATTR_RO(guard);
4805

4806
static ssize_t ato_show(struct device_driver *ddp, char *buf)
4807
{
4808
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_ato);
4809
}
4810
static DRIVER_ATTR_RO(ato);
4811

4812
static ssize_t map_show(struct device_driver *ddp, char *buf)
4813 4814 4815
{
	ssize_t count;

4816
	if (!scsi_debug_lbp())
4817 4818 4819
		return scnprintf(buf, PAGE_SIZE, "0-%u\n",
				 sdebug_store_sectors);

4820 4821
	count = scnprintf(buf, PAGE_SIZE - 1, "%*pbl",
			  (int)map_size, map_storep);
4822
	buf[count++] = '\n';
4823
	buf[count] = '\0';
4824 4825 4826

	return count;
}
4827
static DRIVER_ATTR_RO(map);
4828

4829
static ssize_t removable_show(struct device_driver *ddp, char *buf)
4830
{
4831
	return scnprintf(buf, PAGE_SIZE, "%d\n", sdebug_removable ? 1 : 0);
4832
}
4833 4834
static ssize_t removable_store(struct device_driver *ddp, const char *buf,
			       size_t count)
4835 4836 4837 4838
{
	int n;

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4839
		sdebug_removable = (n > 0);
4840 4841 4842 4843
		return count;
	}
	return -EINVAL;
}
4844
static DRIVER_ATTR_RW(removable);
4845

4846 4847
static ssize_t host_lock_show(struct device_driver *ddp, char *buf)
{
4848
	return scnprintf(buf, PAGE_SIZE, "%d\n", !!sdebug_host_lock);
4849
}
4850
/* N.B. sdebug_host_lock does nothing, kept for backward compatibility */
4851 4852 4853
static ssize_t host_lock_store(struct device_driver *ddp, const char *buf,
			       size_t count)
{
4854
	int n;
4855 4856

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4857 4858
		sdebug_host_lock = (n > 0);
		return count;
4859 4860 4861 4862 4863
	}
	return -EINVAL;
}
static DRIVER_ATTR_RW(host_lock);

4864 4865
static ssize_t strict_show(struct device_driver *ddp, char *buf)
{
4866
	return scnprintf(buf, PAGE_SIZE, "%d\n", !!sdebug_strict);
4867 4868 4869 4870 4871 4872 4873
}
static ssize_t strict_store(struct device_driver *ddp, const char *buf,
			    size_t count)
{
	int n;

	if ((count > 0) && (1 == sscanf(buf, "%d", &n)) && (n >= 0)) {
4874
		sdebug_strict = (n > 0);
4875 4876 4877 4878 4879 4880
		return count;
	}
	return -EINVAL;
}
static DRIVER_ATTR_RW(strict);

D
Douglas Gilbert 已提交
4881 4882 4883 4884 4885 4886
static ssize_t uuid_ctl_show(struct device_driver *ddp, char *buf)
{
	return scnprintf(buf, PAGE_SIZE, "%d\n", !!sdebug_uuid_ctl);
}
static DRIVER_ATTR_RO(uuid_ctl);

4887

4888
/* Note: The following array creates attribute files in the
D
Douglas Gilbert 已提交
4889 4890 4891 4892 4893
   /sys/bus/pseudo/drivers/scsi_debug directory. The advantage of these
   files (over those found in the /sys/module/scsi_debug/parameters
   directory) is that auxiliary actions can be triggered when an attribute
   is changed. For example see: sdebug_add_host_store() above.
 */
4894

4895 4896 4897 4898 4899 4900 4901 4902 4903 4904 4905 4906 4907 4908 4909 4910 4911 4912 4913
static struct attribute *sdebug_drv_attrs[] = {
	&driver_attr_delay.attr,
	&driver_attr_opts.attr,
	&driver_attr_ptype.attr,
	&driver_attr_dsense.attr,
	&driver_attr_fake_rw.attr,
	&driver_attr_no_lun_0.attr,
	&driver_attr_num_tgts.attr,
	&driver_attr_dev_size_mb.attr,
	&driver_attr_num_parts.attr,
	&driver_attr_every_nth.attr,
	&driver_attr_max_luns.attr,
	&driver_attr_max_queue.attr,
	&driver_attr_no_uld.attr,
	&driver_attr_scsi_level.attr,
	&driver_attr_virtual_gb.attr,
	&driver_attr_add_host.attr,
	&driver_attr_vpd_use_hostno.attr,
	&driver_attr_sector_size.attr,
4914 4915
	&driver_attr_statistics.attr,
	&driver_attr_submit_queues.attr,
4916 4917 4918 4919 4920 4921
	&driver_attr_dix.attr,
	&driver_attr_dif.attr,
	&driver_attr_guard.attr,
	&driver_attr_ato.attr,
	&driver_attr_map.attr,
	&driver_attr_removable.attr,
4922 4923
	&driver_attr_host_lock.attr,
	&driver_attr_ndelay.attr,
4924
	&driver_attr_strict.attr,
D
Douglas Gilbert 已提交
4925
	&driver_attr_uuid_ctl.attr,
4926 4927 4928
	NULL,
};
ATTRIBUTE_GROUPS(sdebug_drv);
L
Linus Torvalds 已提交
4929

4930
static struct device *pseudo_primary;
4931

L
Linus Torvalds 已提交
4932 4933
static int __init scsi_debug_init(void)
{
4934
	unsigned long sz;
L
Linus Torvalds 已提交
4935 4936
	int host_to_add;
	int k;
4937
	int ret;
L
Linus Torvalds 已提交
4938

4939 4940
	atomic_set(&retired_max_queue, 0);

4941
	if (sdebug_ndelay >= 1000 * 1000 * 1000) {
4942
		pr_warn("ndelay must be less than 1 second, ignored\n");
4943 4944
		sdebug_ndelay = 0;
	} else if (sdebug_ndelay > 0)
4945
		sdebug_jdelay = JDELAY_OVERRIDDEN;
4946

4947
	switch (sdebug_sector_size) {
4948 4949 4950 4951 4952 4953
	case  512:
	case 1024:
	case 2048:
	case 4096:
		break;
	default:
4954
		pr_err("invalid sector_size %d\n", sdebug_sector_size);
4955 4956 4957
		return -EINVAL;
	}

4958
	switch (sdebug_dif) {
4959
	case T10_PI_TYPE0_PROTECTION:
4960
		break;
4961 4962 4963
	case T10_PI_TYPE1_PROTECTION:
	case T10_PI_TYPE2_PROTECTION:
	case T10_PI_TYPE3_PROTECTION:
4964
		have_dif_prot = true;
4965 4966 4967
		break;

	default:
4968
		pr_err("dif must be 0, 1, 2 or 3\n");
4969 4970 4971
		return -EINVAL;
	}

4972
	if (sdebug_guard > 1) {
4973
		pr_err("guard must be 0 or 1\n");
4974 4975 4976
		return -EINVAL;
	}

4977
	if (sdebug_ato > 1) {
4978
		pr_err("ato must be 0 or 1\n");
4979 4980 4981
		return -EINVAL;
	}

4982 4983
	if (sdebug_physblk_exp > 15) {
		pr_err("invalid physblk_exp %u\n", sdebug_physblk_exp);
4984 4985
		return -EINVAL;
	}
4986 4987 4988 4989
	if (sdebug_max_luns > 256) {
		pr_warn("max_luns can be no more than 256, use default\n");
		sdebug_max_luns = DEF_MAX_LUNS;
	}
4990

4991 4992
	if (sdebug_lowest_aligned > 0x3fff) {
		pr_err("lowest_aligned too big: %u\n", sdebug_lowest_aligned);
4993 4994 4995
		return -EINVAL;
	}

4996 4997 4998 4999 5000 5001 5002 5003 5004 5005 5006
	if (submit_queues < 1) {
		pr_err("submit_queues must be 1 or more\n");
		return -EINVAL;
	}
	sdebug_q_arr = kcalloc(submit_queues, sizeof(struct sdebug_queue),
			       GFP_KERNEL);
	if (sdebug_q_arr == NULL)
		return -ENOMEM;
	for (k = 0; k < submit_queues; ++k)
		spin_lock_init(&sdebug_q_arr[k].qc_lock);

5007 5008 5009 5010
	if (sdebug_dev_size_mb < 1)
		sdebug_dev_size_mb = 1;  /* force minimum 1 MB ramdisk */
	sz = (unsigned long)sdebug_dev_size_mb * 1048576;
	sdebug_store_sectors = sz / sdebug_sector_size;
5011
	sdebug_capacity = get_sdebug_capacity();
L
Linus Torvalds 已提交
5012 5013 5014 5015

	/* play around with geometry, don't waste too much on track 0 */
	sdebug_heads = 8;
	sdebug_sectors_per = 32;
5016
	if (sdebug_dev_size_mb >= 256)
L
Linus Torvalds 已提交
5017
		sdebug_heads = 64;
5018
	else if (sdebug_dev_size_mb >= 16)
5019
		sdebug_heads = 32;
L
Linus Torvalds 已提交
5020 5021 5022 5023 5024 5025 5026 5027 5028 5029
	sdebug_cylinders_per = (unsigned long)sdebug_capacity /
			       (sdebug_sectors_per * sdebug_heads);
	if (sdebug_cylinders_per >= 1024) {
		/* other LLDs do this; implies >= 1GB ram disk ... */
		sdebug_heads = 255;
		sdebug_sectors_per = 63;
		sdebug_cylinders_per = (unsigned long)sdebug_capacity /
			       (sdebug_sectors_per * sdebug_heads);
	}

D
Douglas Gilbert 已提交
5030
	if (sdebug_fake_rw == 0) {
5031 5032
		fake_storep = vmalloc(sz);
		if (NULL == fake_storep) {
5033
			pr_err("out of memory, 1\n");
5034 5035
			ret = -ENOMEM;
			goto free_q_arr;
5036 5037
		}
		memset(fake_storep, 0, sz);
5038
		if (sdebug_num_parts > 0)
5039
			sdebug_build_parts(fake_storep, sz);
L
Linus Torvalds 已提交
5040 5041
	}

5042
	if (sdebug_dix) {
5043 5044
		int dif_size;

5045
		dif_size = sdebug_store_sectors * sizeof(struct t10_pi_tuple);
5046 5047
		dif_storep = vmalloc(dif_size);

5048
		pr_err("dif_storep %u bytes @ %p\n", dif_size, dif_storep);
5049 5050

		if (dif_storep == NULL) {
5051
			pr_err("out of mem. (DIX)\n");
5052 5053 5054 5055 5056 5057 5058
			ret = -ENOMEM;
			goto free_vm;
		}

		memset(dif_storep, 0xff, dif_size);
	}

5059 5060
	/* Logical Block Provisioning */
	if (scsi_debug_lbp()) {
5061 5062
		sdebug_unmap_max_blocks =
			clamp(sdebug_unmap_max_blocks, 0U, 0xffffffffU);
5063

5064 5065
		sdebug_unmap_max_desc =
			clamp(sdebug_unmap_max_desc, 0U, 256U);
5066

5067 5068
		sdebug_unmap_granularity =
			clamp(sdebug_unmap_granularity, 1U, 0xffffffffU);
5069

5070 5071 5072
		if (sdebug_unmap_alignment &&
		    sdebug_unmap_granularity <=
		    sdebug_unmap_alignment) {
5073
			pr_err("ERR: unmap_granularity <= unmap_alignment\n");
5074 5075
			ret = -EINVAL;
			goto free_vm;
5076 5077
		}

5078 5079
		map_size = lba_to_map_index(sdebug_store_sectors - 1) + 1;
		map_storep = vmalloc(BITS_TO_LONGS(map_size) * sizeof(long));
5080

5081
		pr_info("%lu provisioning blocks\n", map_size);
5082 5083

		if (map_storep == NULL) {
5084
			pr_err("out of mem. (MAP)\n");
5085 5086 5087 5088
			ret = -ENOMEM;
			goto free_vm;
		}

5089
		bitmap_zero(map_storep, map_size);
5090 5091

		/* Map first 1KB for partition table */
5092
		if (sdebug_num_parts)
5093 5094 5095
			map_region(0, 2);
	}

5096 5097
	pseudo_primary = root_device_register("pseudo_0");
	if (IS_ERR(pseudo_primary)) {
5098
		pr_warn("root_device_register() error\n");
5099
		ret = PTR_ERR(pseudo_primary);
5100 5101 5102 5103
		goto free_vm;
	}
	ret = bus_register(&pseudo_lld_bus);
	if (ret < 0) {
5104
		pr_warn("bus_register error: %d\n", ret);
5105 5106 5107 5108
		goto dev_unreg;
	}
	ret = driver_register(&sdebug_driverfs_driver);
	if (ret < 0) {
5109
		pr_warn("driver_register error: %d\n", ret);
5110 5111
		goto bus_unreg;
	}
L
Linus Torvalds 已提交
5112

5113 5114
	host_to_add = sdebug_add_host;
	sdebug_add_host = 0;
L
Linus Torvalds 已提交
5115 5116 5117

        for (k = 0; k < host_to_add; k++) {
                if (sdebug_add_adapter()) {
5118
			pr_err("sdebug_add_adapter failed k=%d\n", k);
L
Linus Torvalds 已提交
5119 5120 5121 5122
                        break;
                }
        }

5123 5124
	if (sdebug_verbose)
		pr_info("built %d host(s)\n", sdebug_add_host);
5125

L
Linus Torvalds 已提交
5126
	return 0;
5127 5128 5129 5130

bus_unreg:
	bus_unregister(&pseudo_lld_bus);
dev_unreg:
5131
	root_device_unregister(pseudo_primary);
5132
free_vm:
5133 5134
	vfree(map_storep);
	vfree(dif_storep);
5135
	vfree(fake_storep);
5136 5137
free_q_arr:
	kfree(sdebug_q_arr);
5138
	return ret;
L
Linus Torvalds 已提交
5139 5140 5141 5142
}

static void __exit scsi_debug_exit(void)
{
5143
	int k = sdebug_add_host;
L
Linus Torvalds 已提交
5144 5145

	stop_all_queued();
5146
	free_all_queued();
L
Linus Torvalds 已提交
5147 5148 5149 5150
	for (; k; k--)
		sdebug_remove_adapter();
	driver_unregister(&sdebug_driverfs_driver);
	bus_unregister(&pseudo_lld_bus);
5151
	root_device_unregister(pseudo_primary);
L
Linus Torvalds 已提交
5152

5153
	vfree(map_storep);
5154
	vfree(dif_storep);
L
Linus Torvalds 已提交
5155
	vfree(fake_storep);
5156
	kfree(sdebug_q_arr);
L
Linus Torvalds 已提交
5157 5158 5159 5160 5161 5162 5163 5164 5165 5166 5167 5168 5169 5170 5171 5172 5173 5174
}

device_initcall(scsi_debug_init);
module_exit(scsi_debug_exit);

static void sdebug_release_adapter(struct device * dev)
{
        struct sdebug_host_info *sdbg_host;

	sdbg_host = to_sdebug_host(dev);
        kfree(sdbg_host);
}

static int sdebug_add_adapter(void)
{
	int k, devs_per_host;
        int error = 0;
        struct sdebug_host_info *sdbg_host;
5175
	struct sdebug_dev_info *sdbg_devinfo, *tmp;
L
Linus Torvalds 已提交
5176

D
Douglas Gilbert 已提交
5177
        sdbg_host = kzalloc(sizeof(*sdbg_host),GFP_KERNEL);
L
Linus Torvalds 已提交
5178
        if (NULL == sdbg_host) {
5179
		pr_err("out of memory at line %d\n", __LINE__);
L
Linus Torvalds 已提交
5180 5181 5182 5183 5184
                return -ENOMEM;
        }

        INIT_LIST_HEAD(&sdbg_host->dev_info_list);

5185
	devs_per_host = sdebug_num_tgts * sdebug_max_luns;
L
Linus Torvalds 已提交
5186
        for (k = 0; k < devs_per_host; k++) {
5187 5188
		sdbg_devinfo = sdebug_device_create(sdbg_host, GFP_KERNEL);
		if (!sdbg_devinfo) {
5189
			pr_err("out of memory at line %d\n", __LINE__);
L
Linus Torvalds 已提交
5190 5191 5192 5193 5194 5195 5196 5197 5198 5199
                        error = -ENOMEM;
			goto clean;
                }
        }

        spin_lock(&sdebug_host_list_lock);
        list_add_tail(&sdbg_host->host_list, &sdebug_host_list);
        spin_unlock(&sdebug_host_list_lock);

        sdbg_host->dev.bus = &pseudo_lld_bus;
5200
        sdbg_host->dev.parent = pseudo_primary;
L
Linus Torvalds 已提交
5201
        sdbg_host->dev.release = &sdebug_release_adapter;
5202
	dev_set_name(&sdbg_host->dev, "adapter%d", sdebug_add_host);
L
Linus Torvalds 已提交
5203 5204 5205 5206 5207 5208

        error = device_register(&sdbg_host->dev);

        if (error)
		goto clean;

5209
	++sdebug_add_host;
L
Linus Torvalds 已提交
5210 5211 5212
        return error;

clean:
5213 5214
	list_for_each_entry_safe(sdbg_devinfo, tmp, &sdbg_host->dev_info_list,
				 dev_list) {
L
Linus Torvalds 已提交
5215 5216 5217 5218 5219 5220 5221 5222 5223 5224 5225 5226 5227 5228 5229 5230 5231 5232 5233 5234 5235 5236 5237
		list_del(&sdbg_devinfo->dev_list);
		kfree(sdbg_devinfo);
	}

	kfree(sdbg_host);
        return error;
}

static void sdebug_remove_adapter(void)
{
        struct sdebug_host_info * sdbg_host = NULL;

        spin_lock(&sdebug_host_list_lock);
        if (!list_empty(&sdebug_host_list)) {
                sdbg_host = list_entry(sdebug_host_list.prev,
                                       struct sdebug_host_info, host_list);
		list_del(&sdbg_host->host_list);
	}
        spin_unlock(&sdebug_host_list_lock);

	if (!sdbg_host)
		return;

5238 5239
	device_unregister(&sdbg_host->dev);
	--sdebug_add_host;
L
Linus Torvalds 已提交
5240 5241
}

5242
static int sdebug_change_qdepth(struct scsi_device *sdev, int qdepth)
5243 5244 5245 5246
{
	int num_in_q = 0;
	struct sdebug_dev_info *devip;

5247
	block_unblock_all_queues(true);
5248 5249
	devip = (struct sdebug_dev_info *)sdev->hostdata;
	if (NULL == devip) {
5250
		block_unblock_all_queues(false);
5251 5252 5253
		return	-ENODEV;
	}
	num_in_q = atomic_read(&devip->num_in_q);
5254 5255 5256

	if (qdepth < 1)
		qdepth = 1;
5257 5258 5259
	/* allow to exceed max host qc_arr elements for testing */
	if (qdepth > SDEBUG_CANQUEUE + 10)
		qdepth = SDEBUG_CANQUEUE + 10;
5260
	scsi_change_queue_depth(sdev, qdepth);
5261

5262
	if (SDEBUG_OPT_Q_NOISE & sdebug_opts) {
5263
		sdev_printk(KERN_INFO, sdev, "%s: qdepth=%d, num_in_q=%d\n",
5264
			    __func__, qdepth, num_in_q);
5265
	}
5266
	block_unblock_all_queues(false);
5267 5268 5269
	return sdev->queue_depth;
}

5270
static bool fake_timeout(struct scsi_cmnd *scp)
5271
{
5272
	if (0 == (atomic_read(&sdebug_cmnd_count) % abs(sdebug_every_nth))) {
5273 5274 5275
		if (sdebug_every_nth < -1)
			sdebug_every_nth = -1;
		if (SDEBUG_OPT_TIMEOUT & sdebug_opts)
5276
			return true; /* ignore command causing timeout */
5277
		else if (SDEBUG_OPT_MAC_TIMEOUT & sdebug_opts &&
5278
			 scsi_medium_access_command(scp))
5279
			return true; /* time out reads and writes */
5280
	}
5281
	return false;
5282 5283
}

5284 5285
static int scsi_debug_queuecommand(struct Scsi_Host *shost,
				   struct scsi_cmnd *scp)
5286 5287 5288 5289 5290 5291 5292 5293 5294 5295 5296 5297 5298 5299 5300 5301
{
	u8 sdeb_i;
	struct scsi_device *sdp = scp->device;
	const struct opcode_info_t *oip;
	const struct opcode_info_t *r_oip;
	struct sdebug_dev_info *devip;
	u8 *cmd = scp->cmnd;
	int (*r_pfp)(struct scsi_cmnd *, struct sdebug_dev_info *);
	int k, na;
	int errsts = 0;
	u32 flags;
	u16 sa;
	u8 opcode = cmd[0];
	bool has_wlun_rl;

	scsi_set_resid(scp, 0);
5302 5303
	if (sdebug_statistics)
		atomic_inc(&sdebug_cmnd_count);
5304 5305
	if (unlikely(sdebug_verbose &&
		     !(SDEBUG_OPT_NO_CDB_NOISE & sdebug_opts))) {
5306 5307 5308 5309 5310 5311 5312 5313 5314 5315 5316 5317
		char b[120];
		int n, len, sb;

		len = scp->cmd_len;
		sb = (int)sizeof(b);
		if (len > 32)
			strcpy(b, "too long, over 32 bytes");
		else {
			for (k = 0, n = 0; k < len && n < sb; ++k)
				n += scnprintf(b + n, sb - n, "%02x ",
					       (u32)cmd[k]);
		}
5318 5319 5320 5321 5322 5323 5324
		if (sdebug_mq_active)
			sdev_printk(KERN_INFO, sdp, "%s: tag=%u, cmd %s\n",
				    my_name, blk_mq_unique_tag(scp->request),
				    b);
		else
			sdev_printk(KERN_INFO, sdp, "%s: cmd %s\n", my_name,
				    b);
5325
	}
5326
	has_wlun_rl = (sdp->lun == SCSI_W_LUN_REPORT_LUNS);
5327 5328
	if (unlikely((sdp->lun >= sdebug_max_luns) && !has_wlun_rl))
		goto err_out;
5329 5330 5331 5332

	sdeb_i = opcode_ind_arr[opcode];	/* fully mapped */
	oip = &opcode_info_arr[sdeb_i];		/* safe if table consistent */
	devip = (struct sdebug_dev_info *)sdp->hostdata;
5333 5334
	if (unlikely(!devip)) {
		devip = find_build_dev_info(sdp);
5335
		if (NULL == devip)
5336
			goto err_out;
5337 5338 5339 5340 5341 5342 5343 5344 5345 5346 5347 5348 5349 5350 5351 5352 5353 5354 5355 5356 5357 5358 5359 5360 5361 5362 5363 5364 5365 5366 5367
	}
	na = oip->num_attached;
	r_pfp = oip->pfp;
	if (na) {	/* multiple commands with this opcode */
		r_oip = oip;
		if (FF_SA & r_oip->flags) {
			if (F_SA_LOW & oip->flags)
				sa = 0x1f & cmd[1];
			else
				sa = get_unaligned_be16(cmd + 8);
			for (k = 0; k <= na; oip = r_oip->arrp + k++) {
				if (opcode == oip->opcode && sa == oip->sa)
					break;
			}
		} else {   /* since no service action only check opcode */
			for (k = 0; k <= na; oip = r_oip->arrp + k++) {
				if (opcode == oip->opcode)
					break;
			}
		}
		if (k > na) {
			if (F_SA_LOW & r_oip->flags)
				mk_sense_invalid_fld(scp, SDEB_IN_CDB, 1, 4);
			else if (F_SA_HIGH & r_oip->flags)
				mk_sense_invalid_fld(scp, SDEB_IN_CDB, 8, 7);
			else
				mk_sense_invalid_opcode(scp);
			goto check_cond;
		}
	}	/* else (when na==0) we assume the oip is a match */
	flags = oip->flags;
5368
	if (unlikely(F_INV_OP & flags)) {
5369 5370 5371
		mk_sense_invalid_opcode(scp);
		goto check_cond;
	}
5372
	if (unlikely(has_wlun_rl && !(F_RL_WLUN_OK & flags))) {
5373 5374 5375
		if (sdebug_verbose)
			sdev_printk(KERN_INFO, sdp, "%s: Opcode 0x%x not%s\n",
				    my_name, opcode, " supported for wlun");
5376 5377 5378
		mk_sense_invalid_opcode(scp);
		goto check_cond;
	}
5379
	if (unlikely(sdebug_strict)) {	/* check cdb against mask */
5380 5381 5382 5383 5384 5385 5386 5387 5388 5389 5390 5391 5392 5393 5394
		u8 rem;
		int j;

		for (k = 1; k < oip->len_mask[0] && k < 16; ++k) {
			rem = ~oip->len_mask[k] & cmd[k];
			if (rem) {
				for (j = 7; j >= 0; --j, rem <<= 1) {
					if (0x80 & rem)
						break;
				}
				mk_sense_invalid_fld(scp, SDEB_IN_CDB, k, j);
				goto check_cond;
			}
		}
	}
5395
	if (unlikely(!(F_SKIP_UA & flags) &&
D
Douglas Gilbert 已提交
5396 5397
		     find_first_bit(devip->uas_bm,
				    SDEBUG_NUM_UAS) != SDEBUG_NUM_UAS)) {
5398
		errsts = make_ua(scp, devip);
5399 5400 5401
		if (errsts)
			goto check_cond;
	}
5402
	if (unlikely((F_M_ACCESS & flags) && atomic_read(&devip->stopped))) {
5403
		mk_sense_buffer(scp, NOT_READY, LOGICAL_UNIT_NOT_READY, 0x2);
5404
		if (sdebug_verbose)
5405 5406 5407 5408 5409 5410
			sdev_printk(KERN_INFO, sdp, "%s reports: Not ready: "
				    "%s\n", my_name, "initializing command "
				    "required");
		errsts = check_condition_result;
		goto fini;
	}
5411
	if (sdebug_fake_rw && (F_FAKE_RW & flags))
5412
		goto fini;
5413
	if (unlikely(sdebug_every_nth)) {
5414
		if (fake_timeout(scp))
5415 5416
			return 0;	/* ignore command: make trouble */
	}
5417 5418
	if (likely(oip->pfp))
		errsts = oip->pfp(scp, devip);	/* calls a resp_* function */
5419 5420 5421 5422 5423
	else if (r_pfp)	/* if leaf function ptr NULL, try the root's */
		errsts = r_pfp(scp, devip);

fini:
	return schedule_resp(scp, devip, errsts,
5424
			     ((F_DELAY_OVERR & flags) ? 0 : sdebug_jdelay));
5425 5426
check_cond:
	return schedule_resp(scp, devip, check_condition_result, 0);
5427 5428
err_out:
	return schedule_resp(scp, NULL, DID_NO_CONNECT << 16, 0);
5429 5430
}

5431
static struct scsi_host_template sdebug_driver_template = {
A
Al Viro 已提交
5432 5433
	.show_info =		scsi_debug_show_info,
	.write_info =		scsi_debug_write_info,
5434 5435 5436 5437 5438 5439 5440
	.proc_name =		sdebug_proc_name,
	.name =			"SCSI DEBUG",
	.info =			scsi_debug_info,
	.slave_alloc =		scsi_debug_slave_alloc,
	.slave_configure =	scsi_debug_slave_configure,
	.slave_destroy =	scsi_debug_slave_destroy,
	.ioctl =		scsi_debug_ioctl,
5441
	.queuecommand =		scsi_debug_queuecommand,
5442
	.change_queue_depth =	sdebug_change_qdepth,
5443 5444
	.eh_abort_handler =	scsi_debug_abort,
	.eh_device_reset_handler = scsi_debug_device_reset,
5445 5446
	.eh_target_reset_handler = scsi_debug_target_reset,
	.eh_bus_reset_handler = scsi_debug_bus_reset,
5447
	.eh_host_reset_handler = scsi_debug_host_reset,
5448
	.can_queue =		SDEBUG_CANQUEUE,
5449
	.this_id =		7,
5450
	.sg_tablesize =		SG_MAX_SEGMENTS,
5451
	.cmd_per_lun =		DEF_CMD_PER_LUN,
5452
	.max_sectors =		-1U,
5453 5454
	.use_clustering = 	DISABLE_CLUSTERING,
	.module =		THIS_MODULE,
5455
	.track_queue_depth =	1,
5456 5457
};

L
Linus Torvalds 已提交
5458 5459
static int sdebug_driver_probe(struct device * dev)
{
5460 5461 5462
	int error = 0;
	struct sdebug_host_info *sdbg_host;
	struct Scsi_Host *hpnt;
5463
	int hprot;
L
Linus Torvalds 已提交
5464 5465 5466

	sdbg_host = to_sdebug_host(dev);

5467 5468
	sdebug_driver_template.can_queue = sdebug_max_queue;
	if (sdebug_clustering)
5469
		sdebug_driver_template.use_clustering = ENABLE_CLUSTERING;
5470 5471
	hpnt = scsi_host_alloc(&sdebug_driver_template, sizeof(sdbg_host));
	if (NULL == hpnt) {
5472
		pr_err("scsi_host_alloc failed\n");
5473
		error = -ENODEV;
L
Linus Torvalds 已提交
5474
		return error;
5475
	}
5476
	if (submit_queues > nr_cpu_ids) {
5477
		pr_warn("%s: trim submit_queues (was %d) to nr_cpu_ids=%u\n",
5478 5479 5480 5481 5482 5483 5484 5485
			my_name, submit_queues, nr_cpu_ids);
		submit_queues = nr_cpu_ids;
	}
	/* Decide whether to tell scsi subsystem that we want mq */
	/* Following should give the same answer for each host */
	sdebug_mq_active = shost_use_blk_mq(hpnt) && (submit_queues > 1);
	if (sdebug_mq_active)
		hpnt->nr_hw_queues = submit_queues;
L
Linus Torvalds 已提交
5486 5487 5488

        sdbg_host->shost = hpnt;
	*((struct sdebug_host_info **)hpnt->hostdata) = sdbg_host;
5489 5490
	if ((hpnt->this_id >= 0) && (sdebug_num_tgts > hpnt->this_id))
		hpnt->max_id = sdebug_num_tgts + 1;
L
Linus Torvalds 已提交
5491
	else
5492 5493
		hpnt->max_id = sdebug_num_tgts;
	/* = sdebug_max_luns; */
5494
	hpnt->max_lun = SCSI_W_LUN_REPORT_LUNS + 1;
L
Linus Torvalds 已提交
5495

5496
	hprot = 0;
5497

5498
	switch (sdebug_dif) {
5499

5500
	case T10_PI_TYPE1_PROTECTION:
5501
		hprot = SHOST_DIF_TYPE1_PROTECTION;
5502
		if (sdebug_dix)
5503
			hprot |= SHOST_DIX_TYPE1_PROTECTION;
5504 5505
		break;

5506
	case T10_PI_TYPE2_PROTECTION:
5507
		hprot = SHOST_DIF_TYPE2_PROTECTION;
5508
		if (sdebug_dix)
5509
			hprot |= SHOST_DIX_TYPE2_PROTECTION;
5510 5511
		break;

5512
	case T10_PI_TYPE3_PROTECTION:
5513
		hprot = SHOST_DIF_TYPE3_PROTECTION;
5514
		if (sdebug_dix)
5515
			hprot |= SHOST_DIX_TYPE3_PROTECTION;
5516 5517 5518
		break;

	default:
5519
		if (sdebug_dix)
5520
			hprot |= SHOST_DIX_TYPE0_PROTECTION;
5521 5522 5523
		break;
	}

5524
	scsi_host_set_prot(hpnt, hprot);
5525

5526 5527 5528 5529 5530 5531 5532 5533 5534
	if (have_dif_prot || sdebug_dix)
		pr_info("host protection%s%s%s%s%s%s%s\n",
			(hprot & SHOST_DIF_TYPE1_PROTECTION) ? " DIF1" : "",
			(hprot & SHOST_DIF_TYPE2_PROTECTION) ? " DIF2" : "",
			(hprot & SHOST_DIF_TYPE3_PROTECTION) ? " DIF3" : "",
			(hprot & SHOST_DIX_TYPE0_PROTECTION) ? " DIX0" : "",
			(hprot & SHOST_DIX_TYPE1_PROTECTION) ? " DIX1" : "",
			(hprot & SHOST_DIX_TYPE2_PROTECTION) ? " DIX2" : "",
			(hprot & SHOST_DIX_TYPE3_PROTECTION) ? " DIX3" : "");
5535

5536
	if (sdebug_guard == 1)
5537 5538 5539 5540
		scsi_host_set_guard(hpnt, SHOST_DIX_GUARD_IP);
	else
		scsi_host_set_guard(hpnt, SHOST_DIX_GUARD_CRC);

5541 5542
	sdebug_verbose = !!(SDEBUG_OPT_NOISE & sdebug_opts);
	sdebug_any_injecting_opt = !!(SDEBUG_OPT_ALL_INJECTING & sdebug_opts);
5543 5544
	if (sdebug_every_nth)	/* need stats counters for every_nth */
		sdebug_statistics = true;
L
Linus Torvalds 已提交
5545 5546
        error = scsi_add_host(hpnt, &sdbg_host->dev);
        if (error) {
5547
		pr_err("scsi_add_host failed\n");
L
Linus Torvalds 已提交
5548 5549 5550 5551 5552
                error = -ENODEV;
		scsi_host_put(hpnt);
        } else
		scsi_scan_host(hpnt);

5553
	return error;
L
Linus Torvalds 已提交
5554 5555 5556 5557 5558
}

static int sdebug_driver_remove(struct device * dev)
{
        struct sdebug_host_info *sdbg_host;
5559
	struct sdebug_dev_info *sdbg_devinfo, *tmp;
L
Linus Torvalds 已提交
5560 5561 5562 5563

	sdbg_host = to_sdebug_host(dev);

	if (!sdbg_host) {
5564
		pr_err("Unable to locate host info\n");
L
Linus Torvalds 已提交
5565 5566 5567 5568 5569
		return -ENODEV;
	}

        scsi_remove_host(sdbg_host->shost);

5570 5571
	list_for_each_entry_safe(sdbg_devinfo, tmp, &sdbg_host->dev_info_list,
				 dev_list) {
L
Linus Torvalds 已提交
5572 5573 5574 5575 5576 5577 5578 5579
                list_del(&sdbg_devinfo->dev_list);
                kfree(sdbg_devinfo);
        }

        scsi_host_put(sdbg_host->shost);
        return 0;
}

5580 5581
static int pseudo_lld_bus_match(struct device *dev,
				struct device_driver *dev_driver)
L
Linus Torvalds 已提交
5582
{
5583
	return 1;
L
Linus Torvalds 已提交
5584
}
5585 5586 5587 5588 5589 5590

static struct bus_type pseudo_lld_bus = {
	.name = "pseudo",
	.match = pseudo_lld_bus_match,
	.probe = sdebug_driver_probe,
	.remove = sdebug_driver_remove,
5591
	.drv_groups = sdebug_drv_groups,
5592
};