xref: /OK3568_Linux_fs/kernel/drivers/scsi/esas2r/esas2r_ioctl.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun /*
2*4882a593Smuzhiyun  *  linux/drivers/scsi/esas2r/esas2r_ioctl.c
3*4882a593Smuzhiyun  *      For use with ATTO ExpressSAS R6xx SAS/SATA RAID controllers
4*4882a593Smuzhiyun  *
5*4882a593Smuzhiyun  *  Copyright (c) 2001-2013 ATTO Technology, Inc.
6*4882a593Smuzhiyun  *  (mailto:linuxdrivers@attotech.com)
7*4882a593Smuzhiyun  *
8*4882a593Smuzhiyun  * This program is free software; you can redistribute it and/or
9*4882a593Smuzhiyun  * modify it under the terms of the GNU General Public License
10*4882a593Smuzhiyun  * as published by the Free Software Foundation; either version 2
11*4882a593Smuzhiyun  * of the License, or (at your option) any later version.
12*4882a593Smuzhiyun  *
13*4882a593Smuzhiyun  * This program is distributed in the hope that it will be useful,
14*4882a593Smuzhiyun  * but WITHOUT ANY WARRANTY; without even the implied warranty of
15*4882a593Smuzhiyun  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16*4882a593Smuzhiyun  * GNU General Public License for more details.
17*4882a593Smuzhiyun  *
18*4882a593Smuzhiyun  * NO WARRANTY
19*4882a593Smuzhiyun  * THE PROGRAM IS PROVIDED ON AN "AS IS" BASIS, WITHOUT WARRANTIES OR
20*4882a593Smuzhiyun  * CONDITIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED INCLUDING, WITHOUT
21*4882a593Smuzhiyun  * LIMITATION, ANY WARRANTIES OR CONDITIONS OF TITLE, NON-INFRINGEMENT,
22*4882a593Smuzhiyun  * MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Each Recipient is
23*4882a593Smuzhiyun  * solely responsible for determining the appropriateness of using and
24*4882a593Smuzhiyun  * distributing the Program and assumes all risks associated with its
25*4882a593Smuzhiyun  * exercise of rights under this Agreement, including but not limited to
26*4882a593Smuzhiyun  * the risks and costs of program errors, damage to or loss of data,
27*4882a593Smuzhiyun  * programs or equipment, and unavailability or interruption of operations.
28*4882a593Smuzhiyun  *
29*4882a593Smuzhiyun  * DISCLAIMER OF LIABILITY
30*4882a593Smuzhiyun  * NEITHER RECIPIENT NOR ANY CONTRIBUTORS SHALL HAVE ANY LIABILITY FOR ANY
31*4882a593Smuzhiyun  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
32*4882a593Smuzhiyun  * DAMAGES (INCLUDING WITHOUT LIMITATION LOST PROFITS), HOWEVER CAUSED AND
33*4882a593Smuzhiyun  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR
34*4882a593Smuzhiyun  * TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
35*4882a593Smuzhiyun  * USE OR DISTRIBUTION OF THE PROGRAM OR THE EXERCISE OF ANY RIGHTS GRANTED
36*4882a593Smuzhiyun  * HEREUNDER, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES
37*4882a593Smuzhiyun  *
38*4882a593Smuzhiyun  * You should have received a copy of the GNU General Public License
39*4882a593Smuzhiyun  * along with this program; if not, write to the Free Software
40*4882a593Smuzhiyun  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301,
41*4882a593Smuzhiyun  * USA.
42*4882a593Smuzhiyun  */
43*4882a593Smuzhiyun 
44*4882a593Smuzhiyun #include "esas2r.h"
45*4882a593Smuzhiyun 
46*4882a593Smuzhiyun /*
47*4882a593Smuzhiyun  * Buffered ioctl handlers.  A buffered ioctl is one which requires that we
48*4882a593Smuzhiyun  * allocate a DMA-able memory area to communicate with the firmware.  In
49*4882a593Smuzhiyun  * order to prevent continually allocating and freeing consistent memory,
50*4882a593Smuzhiyun  * we will allocate a global buffer the first time we need it and re-use
51*4882a593Smuzhiyun  * it for subsequent ioctl calls that require it.
52*4882a593Smuzhiyun  */
53*4882a593Smuzhiyun 
54*4882a593Smuzhiyun u8 *esas2r_buffered_ioctl;
55*4882a593Smuzhiyun dma_addr_t esas2r_buffered_ioctl_addr;
56*4882a593Smuzhiyun u32 esas2r_buffered_ioctl_size;
57*4882a593Smuzhiyun struct pci_dev *esas2r_buffered_ioctl_pcid;
58*4882a593Smuzhiyun 
59*4882a593Smuzhiyun static DEFINE_SEMAPHORE(buffered_ioctl_semaphore);
60*4882a593Smuzhiyun typedef int (*BUFFERED_IOCTL_CALLBACK)(struct esas2r_adapter *,
61*4882a593Smuzhiyun 				       struct esas2r_request *,
62*4882a593Smuzhiyun 				       struct esas2r_sg_context *,
63*4882a593Smuzhiyun 				       void *);
64*4882a593Smuzhiyun typedef void (*BUFFERED_IOCTL_DONE_CALLBACK)(struct esas2r_adapter *,
65*4882a593Smuzhiyun 					     struct esas2r_request *, void *);
66*4882a593Smuzhiyun 
67*4882a593Smuzhiyun struct esas2r_buffered_ioctl {
68*4882a593Smuzhiyun 	struct esas2r_adapter *a;
69*4882a593Smuzhiyun 	void *ioctl;
70*4882a593Smuzhiyun 	u32 length;
71*4882a593Smuzhiyun 	u32 control_code;
72*4882a593Smuzhiyun 	u32 offset;
73*4882a593Smuzhiyun 	BUFFERED_IOCTL_CALLBACK
74*4882a593Smuzhiyun 		callback;
75*4882a593Smuzhiyun 	void *context;
76*4882a593Smuzhiyun 	BUFFERED_IOCTL_DONE_CALLBACK
77*4882a593Smuzhiyun 		done_callback;
78*4882a593Smuzhiyun 	void *done_context;
79*4882a593Smuzhiyun 
80*4882a593Smuzhiyun };
81*4882a593Smuzhiyun 
complete_fm_api_req(struct esas2r_adapter * a,struct esas2r_request * rq)82*4882a593Smuzhiyun static void complete_fm_api_req(struct esas2r_adapter *a,
83*4882a593Smuzhiyun 				struct esas2r_request *rq)
84*4882a593Smuzhiyun {
85*4882a593Smuzhiyun 	a->fm_api_command_done = 1;
86*4882a593Smuzhiyun 	wake_up_interruptible(&a->fm_api_waiter);
87*4882a593Smuzhiyun }
88*4882a593Smuzhiyun 
89*4882a593Smuzhiyun /* Callbacks for building scatter/gather lists for FM API requests */
get_physaddr_fm_api(struct esas2r_sg_context * sgc,u64 * addr)90*4882a593Smuzhiyun static u32 get_physaddr_fm_api(struct esas2r_sg_context *sgc, u64 *addr)
91*4882a593Smuzhiyun {
92*4882a593Smuzhiyun 	struct esas2r_adapter *a = (struct esas2r_adapter *)sgc->adapter;
93*4882a593Smuzhiyun 	int offset = sgc->cur_offset - a->save_offset;
94*4882a593Smuzhiyun 
95*4882a593Smuzhiyun 	(*addr) = a->firmware.phys + offset;
96*4882a593Smuzhiyun 	return a->firmware.orig_len - offset;
97*4882a593Smuzhiyun }
98*4882a593Smuzhiyun 
get_physaddr_fm_api_header(struct esas2r_sg_context * sgc,u64 * addr)99*4882a593Smuzhiyun static u32 get_physaddr_fm_api_header(struct esas2r_sg_context *sgc, u64 *addr)
100*4882a593Smuzhiyun {
101*4882a593Smuzhiyun 	struct esas2r_adapter *a = (struct esas2r_adapter *)sgc->adapter;
102*4882a593Smuzhiyun 	int offset = sgc->cur_offset - a->save_offset;
103*4882a593Smuzhiyun 
104*4882a593Smuzhiyun 	(*addr) = a->firmware.header_buff_phys + offset;
105*4882a593Smuzhiyun 	return sizeof(struct esas2r_flash_img) - offset;
106*4882a593Smuzhiyun }
107*4882a593Smuzhiyun 
108*4882a593Smuzhiyun /* Handle EXPRESS_IOCTL_RW_FIRMWARE ioctl with img_type = FW_IMG_FM_API. */
do_fm_api(struct esas2r_adapter * a,struct esas2r_flash_img * fi)109*4882a593Smuzhiyun static void do_fm_api(struct esas2r_adapter *a, struct esas2r_flash_img *fi)
110*4882a593Smuzhiyun {
111*4882a593Smuzhiyun 	struct esas2r_request *rq;
112*4882a593Smuzhiyun 
113*4882a593Smuzhiyun 	if (mutex_lock_interruptible(&a->fm_api_mutex)) {
114*4882a593Smuzhiyun 		fi->status = FI_STAT_BUSY;
115*4882a593Smuzhiyun 		return;
116*4882a593Smuzhiyun 	}
117*4882a593Smuzhiyun 
118*4882a593Smuzhiyun 	rq = esas2r_alloc_request(a);
119*4882a593Smuzhiyun 	if (rq == NULL) {
120*4882a593Smuzhiyun 		fi->status = FI_STAT_BUSY;
121*4882a593Smuzhiyun 		goto free_sem;
122*4882a593Smuzhiyun 	}
123*4882a593Smuzhiyun 
124*4882a593Smuzhiyun 	if (fi == &a->firmware.header) {
125*4882a593Smuzhiyun 		a->firmware.header_buff = dma_alloc_coherent(&a->pcid->dev,
126*4882a593Smuzhiyun 							     (size_t)sizeof(
127*4882a593Smuzhiyun 								     struct
128*4882a593Smuzhiyun 								     esas2r_flash_img),
129*4882a593Smuzhiyun 							     (dma_addr_t *)&a->
130*4882a593Smuzhiyun 							     firmware.
131*4882a593Smuzhiyun 							     header_buff_phys,
132*4882a593Smuzhiyun 							     GFP_KERNEL);
133*4882a593Smuzhiyun 
134*4882a593Smuzhiyun 		if (a->firmware.header_buff == NULL) {
135*4882a593Smuzhiyun 			esas2r_debug("failed to allocate header buffer!");
136*4882a593Smuzhiyun 			fi->status = FI_STAT_BUSY;
137*4882a593Smuzhiyun 			goto free_req;
138*4882a593Smuzhiyun 		}
139*4882a593Smuzhiyun 
140*4882a593Smuzhiyun 		memcpy(a->firmware.header_buff, fi,
141*4882a593Smuzhiyun 		       sizeof(struct esas2r_flash_img));
142*4882a593Smuzhiyun 		a->save_offset = a->firmware.header_buff;
143*4882a593Smuzhiyun 		a->fm_api_sgc.get_phys_addr =
144*4882a593Smuzhiyun 			(PGETPHYSADDR)get_physaddr_fm_api_header;
145*4882a593Smuzhiyun 	} else {
146*4882a593Smuzhiyun 		a->save_offset = (u8 *)fi;
147*4882a593Smuzhiyun 		a->fm_api_sgc.get_phys_addr =
148*4882a593Smuzhiyun 			(PGETPHYSADDR)get_physaddr_fm_api;
149*4882a593Smuzhiyun 	}
150*4882a593Smuzhiyun 
151*4882a593Smuzhiyun 	rq->comp_cb = complete_fm_api_req;
152*4882a593Smuzhiyun 	a->fm_api_command_done = 0;
153*4882a593Smuzhiyun 	a->fm_api_sgc.cur_offset = a->save_offset;
154*4882a593Smuzhiyun 
155*4882a593Smuzhiyun 	if (!esas2r_fm_api(a, (struct esas2r_flash_img *)a->save_offset, rq,
156*4882a593Smuzhiyun 			   &a->fm_api_sgc))
157*4882a593Smuzhiyun 		goto all_done;
158*4882a593Smuzhiyun 
159*4882a593Smuzhiyun 	/* Now wait around for it to complete. */
160*4882a593Smuzhiyun 	while (!a->fm_api_command_done)
161*4882a593Smuzhiyun 		wait_event_interruptible(a->fm_api_waiter,
162*4882a593Smuzhiyun 					 a->fm_api_command_done);
163*4882a593Smuzhiyun all_done:
164*4882a593Smuzhiyun 	if (fi == &a->firmware.header) {
165*4882a593Smuzhiyun 		memcpy(fi, a->firmware.header_buff,
166*4882a593Smuzhiyun 		       sizeof(struct esas2r_flash_img));
167*4882a593Smuzhiyun 
168*4882a593Smuzhiyun 		dma_free_coherent(&a->pcid->dev,
169*4882a593Smuzhiyun 				  (size_t)sizeof(struct esas2r_flash_img),
170*4882a593Smuzhiyun 				  a->firmware.header_buff,
171*4882a593Smuzhiyun 				  (dma_addr_t)a->firmware.header_buff_phys);
172*4882a593Smuzhiyun 	}
173*4882a593Smuzhiyun free_req:
174*4882a593Smuzhiyun 	esas2r_free_request(a, (struct esas2r_request *)rq);
175*4882a593Smuzhiyun free_sem:
176*4882a593Smuzhiyun 	mutex_unlock(&a->fm_api_mutex);
177*4882a593Smuzhiyun 	return;
178*4882a593Smuzhiyun 
179*4882a593Smuzhiyun }
180*4882a593Smuzhiyun 
complete_nvr_req(struct esas2r_adapter * a,struct esas2r_request * rq)181*4882a593Smuzhiyun static void complete_nvr_req(struct esas2r_adapter *a,
182*4882a593Smuzhiyun 			     struct esas2r_request *rq)
183*4882a593Smuzhiyun {
184*4882a593Smuzhiyun 	a->nvram_command_done = 1;
185*4882a593Smuzhiyun 	wake_up_interruptible(&a->nvram_waiter);
186*4882a593Smuzhiyun }
187*4882a593Smuzhiyun 
188*4882a593Smuzhiyun /* Callback for building scatter/gather lists for buffered ioctls */
get_physaddr_buffered_ioctl(struct esas2r_sg_context * sgc,u64 * addr)189*4882a593Smuzhiyun static u32 get_physaddr_buffered_ioctl(struct esas2r_sg_context *sgc,
190*4882a593Smuzhiyun 				       u64 *addr)
191*4882a593Smuzhiyun {
192*4882a593Smuzhiyun 	int offset = (u8 *)sgc->cur_offset - esas2r_buffered_ioctl;
193*4882a593Smuzhiyun 
194*4882a593Smuzhiyun 	(*addr) = esas2r_buffered_ioctl_addr + offset;
195*4882a593Smuzhiyun 	return esas2r_buffered_ioctl_size - offset;
196*4882a593Smuzhiyun }
197*4882a593Smuzhiyun 
complete_buffered_ioctl_req(struct esas2r_adapter * a,struct esas2r_request * rq)198*4882a593Smuzhiyun static void complete_buffered_ioctl_req(struct esas2r_adapter *a,
199*4882a593Smuzhiyun 					struct esas2r_request *rq)
200*4882a593Smuzhiyun {
201*4882a593Smuzhiyun 	a->buffered_ioctl_done = 1;
202*4882a593Smuzhiyun 	wake_up_interruptible(&a->buffered_ioctl_waiter);
203*4882a593Smuzhiyun }
204*4882a593Smuzhiyun 
handle_buffered_ioctl(struct esas2r_buffered_ioctl * bi)205*4882a593Smuzhiyun static u8 handle_buffered_ioctl(struct esas2r_buffered_ioctl *bi)
206*4882a593Smuzhiyun {
207*4882a593Smuzhiyun 	struct esas2r_adapter *a = bi->a;
208*4882a593Smuzhiyun 	struct esas2r_request *rq;
209*4882a593Smuzhiyun 	struct esas2r_sg_context sgc;
210*4882a593Smuzhiyun 	u8 result = IOCTL_SUCCESS;
211*4882a593Smuzhiyun 
212*4882a593Smuzhiyun 	if (down_interruptible(&buffered_ioctl_semaphore))
213*4882a593Smuzhiyun 		return IOCTL_OUT_OF_RESOURCES;
214*4882a593Smuzhiyun 
215*4882a593Smuzhiyun 	/* allocate a buffer or use the existing buffer. */
216*4882a593Smuzhiyun 	if (esas2r_buffered_ioctl) {
217*4882a593Smuzhiyun 		if (esas2r_buffered_ioctl_size < bi->length) {
218*4882a593Smuzhiyun 			/* free the too-small buffer and get a new one */
219*4882a593Smuzhiyun 			dma_free_coherent(&a->pcid->dev,
220*4882a593Smuzhiyun 					  (size_t)esas2r_buffered_ioctl_size,
221*4882a593Smuzhiyun 					  esas2r_buffered_ioctl,
222*4882a593Smuzhiyun 					  esas2r_buffered_ioctl_addr);
223*4882a593Smuzhiyun 
224*4882a593Smuzhiyun 			goto allocate_buffer;
225*4882a593Smuzhiyun 		}
226*4882a593Smuzhiyun 	} else {
227*4882a593Smuzhiyun allocate_buffer:
228*4882a593Smuzhiyun 		esas2r_buffered_ioctl_size = bi->length;
229*4882a593Smuzhiyun 		esas2r_buffered_ioctl_pcid = a->pcid;
230*4882a593Smuzhiyun 		esas2r_buffered_ioctl = dma_alloc_coherent(&a->pcid->dev,
231*4882a593Smuzhiyun 							   (size_t)
232*4882a593Smuzhiyun 							   esas2r_buffered_ioctl_size,
233*4882a593Smuzhiyun 							   &
234*4882a593Smuzhiyun 							   esas2r_buffered_ioctl_addr,
235*4882a593Smuzhiyun 							   GFP_KERNEL);
236*4882a593Smuzhiyun 	}
237*4882a593Smuzhiyun 
238*4882a593Smuzhiyun 	if (!esas2r_buffered_ioctl) {
239*4882a593Smuzhiyun 		esas2r_log(ESAS2R_LOG_CRIT,
240*4882a593Smuzhiyun 			   "could not allocate %d bytes of consistent memory "
241*4882a593Smuzhiyun 			   "for a buffered ioctl!",
242*4882a593Smuzhiyun 			   bi->length);
243*4882a593Smuzhiyun 
244*4882a593Smuzhiyun 		esas2r_debug("buffered ioctl alloc failure");
245*4882a593Smuzhiyun 		result = IOCTL_OUT_OF_RESOURCES;
246*4882a593Smuzhiyun 		goto exit_cleanly;
247*4882a593Smuzhiyun 	}
248*4882a593Smuzhiyun 
249*4882a593Smuzhiyun 	memcpy(esas2r_buffered_ioctl, bi->ioctl, bi->length);
250*4882a593Smuzhiyun 
251*4882a593Smuzhiyun 	rq = esas2r_alloc_request(a);
252*4882a593Smuzhiyun 	if (rq == NULL) {
253*4882a593Smuzhiyun 		esas2r_log(ESAS2R_LOG_CRIT,
254*4882a593Smuzhiyun 			   "could not allocate an internal request");
255*4882a593Smuzhiyun 
256*4882a593Smuzhiyun 		result = IOCTL_OUT_OF_RESOURCES;
257*4882a593Smuzhiyun 		esas2r_debug("buffered ioctl - no requests");
258*4882a593Smuzhiyun 		goto exit_cleanly;
259*4882a593Smuzhiyun 	}
260*4882a593Smuzhiyun 
261*4882a593Smuzhiyun 	a->buffered_ioctl_done = 0;
262*4882a593Smuzhiyun 	rq->comp_cb = complete_buffered_ioctl_req;
263*4882a593Smuzhiyun 	sgc.cur_offset = esas2r_buffered_ioctl + bi->offset;
264*4882a593Smuzhiyun 	sgc.get_phys_addr = (PGETPHYSADDR)get_physaddr_buffered_ioctl;
265*4882a593Smuzhiyun 	sgc.length = esas2r_buffered_ioctl_size;
266*4882a593Smuzhiyun 
267*4882a593Smuzhiyun 	if (!(*bi->callback)(a, rq, &sgc, bi->context)) {
268*4882a593Smuzhiyun 		/* completed immediately, no need to wait */
269*4882a593Smuzhiyun 		a->buffered_ioctl_done = 0;
270*4882a593Smuzhiyun 		goto free_andexit_cleanly;
271*4882a593Smuzhiyun 	}
272*4882a593Smuzhiyun 
273*4882a593Smuzhiyun 	/* now wait around for it to complete. */
274*4882a593Smuzhiyun 	while (!a->buffered_ioctl_done)
275*4882a593Smuzhiyun 		wait_event_interruptible(a->buffered_ioctl_waiter,
276*4882a593Smuzhiyun 					 a->buffered_ioctl_done);
277*4882a593Smuzhiyun 
278*4882a593Smuzhiyun free_andexit_cleanly:
279*4882a593Smuzhiyun 	if (result == IOCTL_SUCCESS && bi->done_callback)
280*4882a593Smuzhiyun 		(*bi->done_callback)(a, rq, bi->done_context);
281*4882a593Smuzhiyun 
282*4882a593Smuzhiyun 	esas2r_free_request(a, rq);
283*4882a593Smuzhiyun 
284*4882a593Smuzhiyun exit_cleanly:
285*4882a593Smuzhiyun 	if (result == IOCTL_SUCCESS)
286*4882a593Smuzhiyun 		memcpy(bi->ioctl, esas2r_buffered_ioctl, bi->length);
287*4882a593Smuzhiyun 
288*4882a593Smuzhiyun 	up(&buffered_ioctl_semaphore);
289*4882a593Smuzhiyun 	return result;
290*4882a593Smuzhiyun }
291*4882a593Smuzhiyun 
292*4882a593Smuzhiyun /* SMP ioctl support */
smp_ioctl_callback(struct esas2r_adapter * a,struct esas2r_request * rq,struct esas2r_sg_context * sgc,void * context)293*4882a593Smuzhiyun static int smp_ioctl_callback(struct esas2r_adapter *a,
294*4882a593Smuzhiyun 			      struct esas2r_request *rq,
295*4882a593Smuzhiyun 			      struct esas2r_sg_context *sgc, void *context)
296*4882a593Smuzhiyun {
297*4882a593Smuzhiyun 	struct atto_ioctl_smp *si =
298*4882a593Smuzhiyun 		(struct atto_ioctl_smp *)esas2r_buffered_ioctl;
299*4882a593Smuzhiyun 
300*4882a593Smuzhiyun 	esas2r_sgc_init(sgc, a, rq, rq->vrq->ioctl.sge);
301*4882a593Smuzhiyun 	esas2r_build_ioctl_req(a, rq, sgc->length, VDA_IOCTL_SMP);
302*4882a593Smuzhiyun 
303*4882a593Smuzhiyun 	if (!esas2r_build_sg_list(a, rq, sgc)) {
304*4882a593Smuzhiyun 		si->status = ATTO_STS_OUT_OF_RSRC;
305*4882a593Smuzhiyun 		return false;
306*4882a593Smuzhiyun 	}
307*4882a593Smuzhiyun 
308*4882a593Smuzhiyun 	esas2r_start_request(a, rq);
309*4882a593Smuzhiyun 	return true;
310*4882a593Smuzhiyun }
311*4882a593Smuzhiyun 
handle_smp_ioctl(struct esas2r_adapter * a,struct atto_ioctl_smp * si)312*4882a593Smuzhiyun static u8 handle_smp_ioctl(struct esas2r_adapter *a, struct atto_ioctl_smp *si)
313*4882a593Smuzhiyun {
314*4882a593Smuzhiyun 	struct esas2r_buffered_ioctl bi;
315*4882a593Smuzhiyun 
316*4882a593Smuzhiyun 	memset(&bi, 0, sizeof(bi));
317*4882a593Smuzhiyun 
318*4882a593Smuzhiyun 	bi.a = a;
319*4882a593Smuzhiyun 	bi.ioctl = si;
320*4882a593Smuzhiyun 	bi.length = sizeof(struct atto_ioctl_smp)
321*4882a593Smuzhiyun 		    + le32_to_cpu(si->req_length)
322*4882a593Smuzhiyun 		    + le32_to_cpu(si->rsp_length);
323*4882a593Smuzhiyun 	bi.offset = 0;
324*4882a593Smuzhiyun 	bi.callback = smp_ioctl_callback;
325*4882a593Smuzhiyun 	return handle_buffered_ioctl(&bi);
326*4882a593Smuzhiyun }
327*4882a593Smuzhiyun 
328*4882a593Smuzhiyun 
329*4882a593Smuzhiyun /* CSMI ioctl support */
esas2r_csmi_ioctl_tunnel_comp_cb(struct esas2r_adapter * a,struct esas2r_request * rq)330*4882a593Smuzhiyun static void esas2r_csmi_ioctl_tunnel_comp_cb(struct esas2r_adapter *a,
331*4882a593Smuzhiyun 					     struct esas2r_request *rq)
332*4882a593Smuzhiyun {
333*4882a593Smuzhiyun 	rq->target_id = le16_to_cpu(rq->func_rsp.ioctl_rsp.csmi.target_id);
334*4882a593Smuzhiyun 	rq->vrq->scsi.flags |= cpu_to_le32(rq->func_rsp.ioctl_rsp.csmi.lun);
335*4882a593Smuzhiyun 
336*4882a593Smuzhiyun 	/* Now call the original completion callback. */
337*4882a593Smuzhiyun 	(*rq->aux_req_cb)(a, rq);
338*4882a593Smuzhiyun }
339*4882a593Smuzhiyun 
340*4882a593Smuzhiyun /* Tunnel a CSMI IOCTL to the back end driver for processing. */
csmi_ioctl_tunnel(struct esas2r_adapter * a,union atto_ioctl_csmi * ci,struct esas2r_request * rq,struct esas2r_sg_context * sgc,u32 ctrl_code,u16 target_id)341*4882a593Smuzhiyun static bool csmi_ioctl_tunnel(struct esas2r_adapter *a,
342*4882a593Smuzhiyun 			      union atto_ioctl_csmi *ci,
343*4882a593Smuzhiyun 			      struct esas2r_request *rq,
344*4882a593Smuzhiyun 			      struct esas2r_sg_context *sgc,
345*4882a593Smuzhiyun 			      u32 ctrl_code,
346*4882a593Smuzhiyun 			      u16 target_id)
347*4882a593Smuzhiyun {
348*4882a593Smuzhiyun 	struct atto_vda_ioctl_req *ioctl = &rq->vrq->ioctl;
349*4882a593Smuzhiyun 
350*4882a593Smuzhiyun 	if (test_bit(AF_DEGRADED_MODE, &a->flags))
351*4882a593Smuzhiyun 		return false;
352*4882a593Smuzhiyun 
353*4882a593Smuzhiyun 	esas2r_sgc_init(sgc, a, rq, rq->vrq->ioctl.sge);
354*4882a593Smuzhiyun 	esas2r_build_ioctl_req(a, rq, sgc->length, VDA_IOCTL_CSMI);
355*4882a593Smuzhiyun 	ioctl->csmi.ctrl_code = cpu_to_le32(ctrl_code);
356*4882a593Smuzhiyun 	ioctl->csmi.target_id = cpu_to_le16(target_id);
357*4882a593Smuzhiyun 	ioctl->csmi.lun = (u8)le32_to_cpu(rq->vrq->scsi.flags);
358*4882a593Smuzhiyun 
359*4882a593Smuzhiyun 	/*
360*4882a593Smuzhiyun 	 * Always usurp the completion callback since the interrupt callback
361*4882a593Smuzhiyun 	 * mechanism may be used.
362*4882a593Smuzhiyun 	 */
363*4882a593Smuzhiyun 	rq->aux_req_cx = ci;
364*4882a593Smuzhiyun 	rq->aux_req_cb = rq->comp_cb;
365*4882a593Smuzhiyun 	rq->comp_cb = esas2r_csmi_ioctl_tunnel_comp_cb;
366*4882a593Smuzhiyun 
367*4882a593Smuzhiyun 	if (!esas2r_build_sg_list(a, rq, sgc))
368*4882a593Smuzhiyun 		return false;
369*4882a593Smuzhiyun 
370*4882a593Smuzhiyun 	esas2r_start_request(a, rq);
371*4882a593Smuzhiyun 	return true;
372*4882a593Smuzhiyun }
373*4882a593Smuzhiyun 
check_lun(struct scsi_lun lun)374*4882a593Smuzhiyun static bool check_lun(struct scsi_lun lun)
375*4882a593Smuzhiyun {
376*4882a593Smuzhiyun 	bool result;
377*4882a593Smuzhiyun 
378*4882a593Smuzhiyun 	result = ((lun.scsi_lun[7] == 0) &&
379*4882a593Smuzhiyun 		  (lun.scsi_lun[6] == 0) &&
380*4882a593Smuzhiyun 		  (lun.scsi_lun[5] == 0) &&
381*4882a593Smuzhiyun 		  (lun.scsi_lun[4] == 0) &&
382*4882a593Smuzhiyun 		  (lun.scsi_lun[3] == 0) &&
383*4882a593Smuzhiyun 		  (lun.scsi_lun[2] == 0) &&
384*4882a593Smuzhiyun /* Byte 1 is intentionally skipped */
385*4882a593Smuzhiyun 		  (lun.scsi_lun[0] == 0));
386*4882a593Smuzhiyun 
387*4882a593Smuzhiyun 	return result;
388*4882a593Smuzhiyun }
389*4882a593Smuzhiyun 
csmi_ioctl_callback(struct esas2r_adapter * a,struct esas2r_request * rq,struct esas2r_sg_context * sgc,void * context)390*4882a593Smuzhiyun static int csmi_ioctl_callback(struct esas2r_adapter *a,
391*4882a593Smuzhiyun 			       struct esas2r_request *rq,
392*4882a593Smuzhiyun 			       struct esas2r_sg_context *sgc, void *context)
393*4882a593Smuzhiyun {
394*4882a593Smuzhiyun 	struct atto_csmi *ci = (struct atto_csmi *)context;
395*4882a593Smuzhiyun 	union atto_ioctl_csmi *ioctl_csmi =
396*4882a593Smuzhiyun 		(union atto_ioctl_csmi *)esas2r_buffered_ioctl;
397*4882a593Smuzhiyun 	u8 path = 0;
398*4882a593Smuzhiyun 	u8 tid = 0;
399*4882a593Smuzhiyun 	u8 lun = 0;
400*4882a593Smuzhiyun 	u32 sts = CSMI_STS_SUCCESS;
401*4882a593Smuzhiyun 	struct esas2r_target *t;
402*4882a593Smuzhiyun 	unsigned long flags;
403*4882a593Smuzhiyun 
404*4882a593Smuzhiyun 	if (ci->control_code == CSMI_CC_GET_DEV_ADDR) {
405*4882a593Smuzhiyun 		struct atto_csmi_get_dev_addr *gda = &ci->data.dev_addr;
406*4882a593Smuzhiyun 
407*4882a593Smuzhiyun 		path = gda->path_id;
408*4882a593Smuzhiyun 		tid = gda->target_id;
409*4882a593Smuzhiyun 		lun = gda->lun;
410*4882a593Smuzhiyun 	} else if (ci->control_code == CSMI_CC_TASK_MGT) {
411*4882a593Smuzhiyun 		struct atto_csmi_task_mgmt *tm = &ci->data.tsk_mgt;
412*4882a593Smuzhiyun 
413*4882a593Smuzhiyun 		path = tm->path_id;
414*4882a593Smuzhiyun 		tid = tm->target_id;
415*4882a593Smuzhiyun 		lun = tm->lun;
416*4882a593Smuzhiyun 	}
417*4882a593Smuzhiyun 
418*4882a593Smuzhiyun 	if (path > 0) {
419*4882a593Smuzhiyun 		rq->func_rsp.ioctl_rsp.csmi.csmi_status = cpu_to_le32(
420*4882a593Smuzhiyun 			CSMI_STS_INV_PARAM);
421*4882a593Smuzhiyun 		return false;
422*4882a593Smuzhiyun 	}
423*4882a593Smuzhiyun 
424*4882a593Smuzhiyun 	rq->target_id = tid;
425*4882a593Smuzhiyun 	rq->vrq->scsi.flags |= cpu_to_le32(lun);
426*4882a593Smuzhiyun 
427*4882a593Smuzhiyun 	switch (ci->control_code) {
428*4882a593Smuzhiyun 	case CSMI_CC_GET_DRVR_INFO:
429*4882a593Smuzhiyun 	{
430*4882a593Smuzhiyun 		struct atto_csmi_get_driver_info *gdi = &ioctl_csmi->drvr_info;
431*4882a593Smuzhiyun 
432*4882a593Smuzhiyun 		strcpy(gdi->description, esas2r_get_model_name(a));
433*4882a593Smuzhiyun 		gdi->csmi_major_rev = CSMI_MAJOR_REV;
434*4882a593Smuzhiyun 		gdi->csmi_minor_rev = CSMI_MINOR_REV;
435*4882a593Smuzhiyun 		break;
436*4882a593Smuzhiyun 	}
437*4882a593Smuzhiyun 
438*4882a593Smuzhiyun 	case CSMI_CC_GET_CNTLR_CFG:
439*4882a593Smuzhiyun 	{
440*4882a593Smuzhiyun 		struct atto_csmi_get_cntlr_cfg *gcc = &ioctl_csmi->cntlr_cfg;
441*4882a593Smuzhiyun 
442*4882a593Smuzhiyun 		gcc->base_io_addr = 0;
443*4882a593Smuzhiyun 		pci_read_config_dword(a->pcid, PCI_BASE_ADDRESS_2,
444*4882a593Smuzhiyun 				      &gcc->base_memaddr_lo);
445*4882a593Smuzhiyun 		pci_read_config_dword(a->pcid, PCI_BASE_ADDRESS_3,
446*4882a593Smuzhiyun 				      &gcc->base_memaddr_hi);
447*4882a593Smuzhiyun 		gcc->board_id = MAKEDWORD(a->pcid->subsystem_device,
448*4882a593Smuzhiyun 					  a->pcid->subsystem_vendor);
449*4882a593Smuzhiyun 		gcc->slot_num = CSMI_SLOT_NUM_UNKNOWN;
450*4882a593Smuzhiyun 		gcc->cntlr_class = CSMI_CNTLR_CLASS_HBA;
451*4882a593Smuzhiyun 		gcc->io_bus_type = CSMI_BUS_TYPE_PCI;
452*4882a593Smuzhiyun 		gcc->pci_addr.bus_num = a->pcid->bus->number;
453*4882a593Smuzhiyun 		gcc->pci_addr.device_num = PCI_SLOT(a->pcid->devfn);
454*4882a593Smuzhiyun 		gcc->pci_addr.function_num = PCI_FUNC(a->pcid->devfn);
455*4882a593Smuzhiyun 
456*4882a593Smuzhiyun 		memset(gcc->serial_num, 0, sizeof(gcc->serial_num));
457*4882a593Smuzhiyun 
458*4882a593Smuzhiyun 		gcc->major_rev = LOBYTE(LOWORD(a->fw_version));
459*4882a593Smuzhiyun 		gcc->minor_rev = HIBYTE(LOWORD(a->fw_version));
460*4882a593Smuzhiyun 		gcc->build_rev = LOBYTE(HIWORD(a->fw_version));
461*4882a593Smuzhiyun 		gcc->release_rev = HIBYTE(HIWORD(a->fw_version));
462*4882a593Smuzhiyun 		gcc->bios_major_rev = HIBYTE(HIWORD(a->flash_ver));
463*4882a593Smuzhiyun 		gcc->bios_minor_rev = LOBYTE(HIWORD(a->flash_ver));
464*4882a593Smuzhiyun 		gcc->bios_build_rev = LOWORD(a->flash_ver);
465*4882a593Smuzhiyun 
466*4882a593Smuzhiyun 		if (test_bit(AF2_THUNDERLINK, &a->flags2))
467*4882a593Smuzhiyun 			gcc->cntlr_flags = CSMI_CNTLRF_SAS_HBA
468*4882a593Smuzhiyun 					   | CSMI_CNTLRF_SATA_HBA;
469*4882a593Smuzhiyun 		else
470*4882a593Smuzhiyun 			gcc->cntlr_flags = CSMI_CNTLRF_SAS_RAID
471*4882a593Smuzhiyun 					   | CSMI_CNTLRF_SATA_RAID;
472*4882a593Smuzhiyun 
473*4882a593Smuzhiyun 		gcc->rrom_major_rev = 0;
474*4882a593Smuzhiyun 		gcc->rrom_minor_rev = 0;
475*4882a593Smuzhiyun 		gcc->rrom_build_rev = 0;
476*4882a593Smuzhiyun 		gcc->rrom_release_rev = 0;
477*4882a593Smuzhiyun 		gcc->rrom_biosmajor_rev = 0;
478*4882a593Smuzhiyun 		gcc->rrom_biosminor_rev = 0;
479*4882a593Smuzhiyun 		gcc->rrom_biosbuild_rev = 0;
480*4882a593Smuzhiyun 		gcc->rrom_biosrelease_rev = 0;
481*4882a593Smuzhiyun 		break;
482*4882a593Smuzhiyun 	}
483*4882a593Smuzhiyun 
484*4882a593Smuzhiyun 	case CSMI_CC_GET_CNTLR_STS:
485*4882a593Smuzhiyun 	{
486*4882a593Smuzhiyun 		struct atto_csmi_get_cntlr_sts *gcs = &ioctl_csmi->cntlr_sts;
487*4882a593Smuzhiyun 
488*4882a593Smuzhiyun 		if (test_bit(AF_DEGRADED_MODE, &a->flags))
489*4882a593Smuzhiyun 			gcs->status = CSMI_CNTLR_STS_FAILED;
490*4882a593Smuzhiyun 		else
491*4882a593Smuzhiyun 			gcs->status = CSMI_CNTLR_STS_GOOD;
492*4882a593Smuzhiyun 
493*4882a593Smuzhiyun 		gcs->offline_reason = CSMI_OFFLINE_NO_REASON;
494*4882a593Smuzhiyun 		break;
495*4882a593Smuzhiyun 	}
496*4882a593Smuzhiyun 
497*4882a593Smuzhiyun 	case CSMI_CC_FW_DOWNLOAD:
498*4882a593Smuzhiyun 	case CSMI_CC_GET_RAID_INFO:
499*4882a593Smuzhiyun 	case CSMI_CC_GET_RAID_CFG:
500*4882a593Smuzhiyun 
501*4882a593Smuzhiyun 		sts = CSMI_STS_BAD_CTRL_CODE;
502*4882a593Smuzhiyun 		break;
503*4882a593Smuzhiyun 
504*4882a593Smuzhiyun 	case CSMI_CC_SMP_PASSTHRU:
505*4882a593Smuzhiyun 	case CSMI_CC_SSP_PASSTHRU:
506*4882a593Smuzhiyun 	case CSMI_CC_STP_PASSTHRU:
507*4882a593Smuzhiyun 	case CSMI_CC_GET_PHY_INFO:
508*4882a593Smuzhiyun 	case CSMI_CC_SET_PHY_INFO:
509*4882a593Smuzhiyun 	case CSMI_CC_GET_LINK_ERRORS:
510*4882a593Smuzhiyun 	case CSMI_CC_GET_SATA_SIG:
511*4882a593Smuzhiyun 	case CSMI_CC_GET_CONN_INFO:
512*4882a593Smuzhiyun 	case CSMI_CC_PHY_CTRL:
513*4882a593Smuzhiyun 
514*4882a593Smuzhiyun 		if (!csmi_ioctl_tunnel(a, ioctl_csmi, rq, sgc,
515*4882a593Smuzhiyun 				       ci->control_code,
516*4882a593Smuzhiyun 				       ESAS2R_TARG_ID_INV)) {
517*4882a593Smuzhiyun 			sts = CSMI_STS_FAILED;
518*4882a593Smuzhiyun 			break;
519*4882a593Smuzhiyun 		}
520*4882a593Smuzhiyun 
521*4882a593Smuzhiyun 		return true;
522*4882a593Smuzhiyun 
523*4882a593Smuzhiyun 	case CSMI_CC_GET_SCSI_ADDR:
524*4882a593Smuzhiyun 	{
525*4882a593Smuzhiyun 		struct atto_csmi_get_scsi_addr *gsa = &ioctl_csmi->scsi_addr;
526*4882a593Smuzhiyun 
527*4882a593Smuzhiyun 		struct scsi_lun lun;
528*4882a593Smuzhiyun 
529*4882a593Smuzhiyun 		memcpy(&lun, gsa->sas_lun, sizeof(struct scsi_lun));
530*4882a593Smuzhiyun 
531*4882a593Smuzhiyun 		if (!check_lun(lun)) {
532*4882a593Smuzhiyun 			sts = CSMI_STS_NO_SCSI_ADDR;
533*4882a593Smuzhiyun 			break;
534*4882a593Smuzhiyun 		}
535*4882a593Smuzhiyun 
536*4882a593Smuzhiyun 		/* make sure the device is present */
537*4882a593Smuzhiyun 		spin_lock_irqsave(&a->mem_lock, flags);
538*4882a593Smuzhiyun 		t = esas2r_targ_db_find_by_sas_addr(a, (u64 *)gsa->sas_addr);
539*4882a593Smuzhiyun 		spin_unlock_irqrestore(&a->mem_lock, flags);
540*4882a593Smuzhiyun 
541*4882a593Smuzhiyun 		if (t == NULL) {
542*4882a593Smuzhiyun 			sts = CSMI_STS_NO_SCSI_ADDR;
543*4882a593Smuzhiyun 			break;
544*4882a593Smuzhiyun 		}
545*4882a593Smuzhiyun 
546*4882a593Smuzhiyun 		gsa->host_index = 0xFF;
547*4882a593Smuzhiyun 		gsa->lun = gsa->sas_lun[1];
548*4882a593Smuzhiyun 		rq->target_id = esas2r_targ_get_id(t, a);
549*4882a593Smuzhiyun 		break;
550*4882a593Smuzhiyun 	}
551*4882a593Smuzhiyun 
552*4882a593Smuzhiyun 	case CSMI_CC_GET_DEV_ADDR:
553*4882a593Smuzhiyun 	{
554*4882a593Smuzhiyun 		struct atto_csmi_get_dev_addr *gda = &ioctl_csmi->dev_addr;
555*4882a593Smuzhiyun 
556*4882a593Smuzhiyun 		/* make sure the target is present */
557*4882a593Smuzhiyun 		t = a->targetdb + rq->target_id;
558*4882a593Smuzhiyun 
559*4882a593Smuzhiyun 		if (t >= a->targetdb_end
560*4882a593Smuzhiyun 		    || t->target_state != TS_PRESENT
561*4882a593Smuzhiyun 		    || t->sas_addr == 0) {
562*4882a593Smuzhiyun 			sts = CSMI_STS_NO_DEV_ADDR;
563*4882a593Smuzhiyun 			break;
564*4882a593Smuzhiyun 		}
565*4882a593Smuzhiyun 
566*4882a593Smuzhiyun 		/* fill in the result */
567*4882a593Smuzhiyun 		*(u64 *)gda->sas_addr = t->sas_addr;
568*4882a593Smuzhiyun 		memset(gda->sas_lun, 0, sizeof(gda->sas_lun));
569*4882a593Smuzhiyun 		gda->sas_lun[1] = (u8)le32_to_cpu(rq->vrq->scsi.flags);
570*4882a593Smuzhiyun 		break;
571*4882a593Smuzhiyun 	}
572*4882a593Smuzhiyun 
573*4882a593Smuzhiyun 	case CSMI_CC_TASK_MGT:
574*4882a593Smuzhiyun 
575*4882a593Smuzhiyun 		/* make sure the target is present */
576*4882a593Smuzhiyun 		t = a->targetdb + rq->target_id;
577*4882a593Smuzhiyun 
578*4882a593Smuzhiyun 		if (t >= a->targetdb_end
579*4882a593Smuzhiyun 		    || t->target_state != TS_PRESENT
580*4882a593Smuzhiyun 		    || !(t->flags & TF_PASS_THRU)) {
581*4882a593Smuzhiyun 			sts = CSMI_STS_NO_DEV_ADDR;
582*4882a593Smuzhiyun 			break;
583*4882a593Smuzhiyun 		}
584*4882a593Smuzhiyun 
585*4882a593Smuzhiyun 		if (!csmi_ioctl_tunnel(a, ioctl_csmi, rq, sgc,
586*4882a593Smuzhiyun 				       ci->control_code,
587*4882a593Smuzhiyun 				       t->phys_targ_id)) {
588*4882a593Smuzhiyun 			sts = CSMI_STS_FAILED;
589*4882a593Smuzhiyun 			break;
590*4882a593Smuzhiyun 		}
591*4882a593Smuzhiyun 
592*4882a593Smuzhiyun 		return true;
593*4882a593Smuzhiyun 
594*4882a593Smuzhiyun 	default:
595*4882a593Smuzhiyun 
596*4882a593Smuzhiyun 		sts = CSMI_STS_BAD_CTRL_CODE;
597*4882a593Smuzhiyun 		break;
598*4882a593Smuzhiyun 	}
599*4882a593Smuzhiyun 
600*4882a593Smuzhiyun 	rq->func_rsp.ioctl_rsp.csmi.csmi_status = cpu_to_le32(sts);
601*4882a593Smuzhiyun 
602*4882a593Smuzhiyun 	return false;
603*4882a593Smuzhiyun }
604*4882a593Smuzhiyun 
605*4882a593Smuzhiyun 
csmi_ioctl_done_callback(struct esas2r_adapter * a,struct esas2r_request * rq,void * context)606*4882a593Smuzhiyun static void csmi_ioctl_done_callback(struct esas2r_adapter *a,
607*4882a593Smuzhiyun 				     struct esas2r_request *rq, void *context)
608*4882a593Smuzhiyun {
609*4882a593Smuzhiyun 	struct atto_csmi *ci = (struct atto_csmi *)context;
610*4882a593Smuzhiyun 	union atto_ioctl_csmi *ioctl_csmi =
611*4882a593Smuzhiyun 		(union atto_ioctl_csmi *)esas2r_buffered_ioctl;
612*4882a593Smuzhiyun 
613*4882a593Smuzhiyun 	switch (ci->control_code) {
614*4882a593Smuzhiyun 	case CSMI_CC_GET_DRVR_INFO:
615*4882a593Smuzhiyun 	{
616*4882a593Smuzhiyun 		struct atto_csmi_get_driver_info *gdi =
617*4882a593Smuzhiyun 			&ioctl_csmi->drvr_info;
618*4882a593Smuzhiyun 
619*4882a593Smuzhiyun 		strcpy(gdi->name, ESAS2R_VERSION_STR);
620*4882a593Smuzhiyun 
621*4882a593Smuzhiyun 		gdi->major_rev = ESAS2R_MAJOR_REV;
622*4882a593Smuzhiyun 		gdi->minor_rev = ESAS2R_MINOR_REV;
623*4882a593Smuzhiyun 		gdi->build_rev = 0;
624*4882a593Smuzhiyun 		gdi->release_rev = 0;
625*4882a593Smuzhiyun 		break;
626*4882a593Smuzhiyun 	}
627*4882a593Smuzhiyun 
628*4882a593Smuzhiyun 	case CSMI_CC_GET_SCSI_ADDR:
629*4882a593Smuzhiyun 	{
630*4882a593Smuzhiyun 		struct atto_csmi_get_scsi_addr *gsa = &ioctl_csmi->scsi_addr;
631*4882a593Smuzhiyun 
632*4882a593Smuzhiyun 		if (le32_to_cpu(rq->func_rsp.ioctl_rsp.csmi.csmi_status) ==
633*4882a593Smuzhiyun 		    CSMI_STS_SUCCESS) {
634*4882a593Smuzhiyun 			gsa->target_id = rq->target_id;
635*4882a593Smuzhiyun 			gsa->path_id = 0;
636*4882a593Smuzhiyun 		}
637*4882a593Smuzhiyun 
638*4882a593Smuzhiyun 		break;
639*4882a593Smuzhiyun 	}
640*4882a593Smuzhiyun 	}
641*4882a593Smuzhiyun 
642*4882a593Smuzhiyun 	ci->status = le32_to_cpu(rq->func_rsp.ioctl_rsp.csmi.csmi_status);
643*4882a593Smuzhiyun }
644*4882a593Smuzhiyun 
645*4882a593Smuzhiyun 
handle_csmi_ioctl(struct esas2r_adapter * a,struct atto_csmi * ci)646*4882a593Smuzhiyun static u8 handle_csmi_ioctl(struct esas2r_adapter *a, struct atto_csmi *ci)
647*4882a593Smuzhiyun {
648*4882a593Smuzhiyun 	struct esas2r_buffered_ioctl bi;
649*4882a593Smuzhiyun 
650*4882a593Smuzhiyun 	memset(&bi, 0, sizeof(bi));
651*4882a593Smuzhiyun 
652*4882a593Smuzhiyun 	bi.a = a;
653*4882a593Smuzhiyun 	bi.ioctl = &ci->data;
654*4882a593Smuzhiyun 	bi.length = sizeof(union atto_ioctl_csmi);
655*4882a593Smuzhiyun 	bi.offset = 0;
656*4882a593Smuzhiyun 	bi.callback = csmi_ioctl_callback;
657*4882a593Smuzhiyun 	bi.context = ci;
658*4882a593Smuzhiyun 	bi.done_callback = csmi_ioctl_done_callback;
659*4882a593Smuzhiyun 	bi.done_context = ci;
660*4882a593Smuzhiyun 
661*4882a593Smuzhiyun 	return handle_buffered_ioctl(&bi);
662*4882a593Smuzhiyun }
663*4882a593Smuzhiyun 
664*4882a593Smuzhiyun /* ATTO HBA ioctl support */
665*4882a593Smuzhiyun 
666*4882a593Smuzhiyun /* Tunnel an ATTO HBA IOCTL to the back end driver for processing. */
hba_ioctl_tunnel(struct esas2r_adapter * a,struct atto_ioctl * hi,struct esas2r_request * rq,struct esas2r_sg_context * sgc)667*4882a593Smuzhiyun static bool hba_ioctl_tunnel(struct esas2r_adapter *a,
668*4882a593Smuzhiyun 			     struct atto_ioctl *hi,
669*4882a593Smuzhiyun 			     struct esas2r_request *rq,
670*4882a593Smuzhiyun 			     struct esas2r_sg_context *sgc)
671*4882a593Smuzhiyun {
672*4882a593Smuzhiyun 	esas2r_sgc_init(sgc, a, rq, rq->vrq->ioctl.sge);
673*4882a593Smuzhiyun 
674*4882a593Smuzhiyun 	esas2r_build_ioctl_req(a, rq, sgc->length, VDA_IOCTL_HBA);
675*4882a593Smuzhiyun 
676*4882a593Smuzhiyun 	if (!esas2r_build_sg_list(a, rq, sgc)) {
677*4882a593Smuzhiyun 		hi->status = ATTO_STS_OUT_OF_RSRC;
678*4882a593Smuzhiyun 
679*4882a593Smuzhiyun 		return false;
680*4882a593Smuzhiyun 	}
681*4882a593Smuzhiyun 
682*4882a593Smuzhiyun 	esas2r_start_request(a, rq);
683*4882a593Smuzhiyun 
684*4882a593Smuzhiyun 	return true;
685*4882a593Smuzhiyun }
686*4882a593Smuzhiyun 
scsi_passthru_comp_cb(struct esas2r_adapter * a,struct esas2r_request * rq)687*4882a593Smuzhiyun static void scsi_passthru_comp_cb(struct esas2r_adapter *a,
688*4882a593Smuzhiyun 				  struct esas2r_request *rq)
689*4882a593Smuzhiyun {
690*4882a593Smuzhiyun 	struct atto_ioctl *hi = (struct atto_ioctl *)rq->aux_req_cx;
691*4882a593Smuzhiyun 	struct atto_hba_scsi_pass_thru *spt = &hi->data.scsi_pass_thru;
692*4882a593Smuzhiyun 	u8 sts = ATTO_SPT_RS_FAILED;
693*4882a593Smuzhiyun 
694*4882a593Smuzhiyun 	spt->scsi_status = rq->func_rsp.scsi_rsp.scsi_stat;
695*4882a593Smuzhiyun 	spt->sense_length = rq->sense_len;
696*4882a593Smuzhiyun 	spt->residual_length =
697*4882a593Smuzhiyun 		le32_to_cpu(rq->func_rsp.scsi_rsp.residual_length);
698*4882a593Smuzhiyun 
699*4882a593Smuzhiyun 	switch (rq->req_stat) {
700*4882a593Smuzhiyun 	case RS_SUCCESS:
701*4882a593Smuzhiyun 	case RS_SCSI_ERROR:
702*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_SUCCESS;
703*4882a593Smuzhiyun 		break;
704*4882a593Smuzhiyun 	case RS_UNDERRUN:
705*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_UNDERRUN;
706*4882a593Smuzhiyun 		break;
707*4882a593Smuzhiyun 	case RS_OVERRUN:
708*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_OVERRUN;
709*4882a593Smuzhiyun 		break;
710*4882a593Smuzhiyun 	case RS_SEL:
711*4882a593Smuzhiyun 	case RS_SEL2:
712*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_NO_DEVICE;
713*4882a593Smuzhiyun 		break;
714*4882a593Smuzhiyun 	case RS_NO_LUN:
715*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_NO_LUN;
716*4882a593Smuzhiyun 		break;
717*4882a593Smuzhiyun 	case RS_TIMEOUT:
718*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_TIMEOUT;
719*4882a593Smuzhiyun 		break;
720*4882a593Smuzhiyun 	case RS_DEGRADED:
721*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_DEGRADED;
722*4882a593Smuzhiyun 		break;
723*4882a593Smuzhiyun 	case RS_BUSY:
724*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_BUSY;
725*4882a593Smuzhiyun 		break;
726*4882a593Smuzhiyun 	case RS_ABORTED:
727*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_ABORTED;
728*4882a593Smuzhiyun 		break;
729*4882a593Smuzhiyun 	case RS_RESET:
730*4882a593Smuzhiyun 		sts = ATTO_SPT_RS_BUS_RESET;
731*4882a593Smuzhiyun 		break;
732*4882a593Smuzhiyun 	}
733*4882a593Smuzhiyun 
734*4882a593Smuzhiyun 	spt->req_status = sts;
735*4882a593Smuzhiyun 
736*4882a593Smuzhiyun 	/* Update the target ID to the next one present. */
737*4882a593Smuzhiyun 	spt->target_id =
738*4882a593Smuzhiyun 		esas2r_targ_db_find_next_present(a, (u16)spt->target_id);
739*4882a593Smuzhiyun 
740*4882a593Smuzhiyun 	/* Done, call the completion callback. */
741*4882a593Smuzhiyun 	(*rq->aux_req_cb)(a, rq);
742*4882a593Smuzhiyun }
743*4882a593Smuzhiyun 
hba_ioctl_callback(struct esas2r_adapter * a,struct esas2r_request * rq,struct esas2r_sg_context * sgc,void * context)744*4882a593Smuzhiyun static int hba_ioctl_callback(struct esas2r_adapter *a,
745*4882a593Smuzhiyun 			      struct esas2r_request *rq,
746*4882a593Smuzhiyun 			      struct esas2r_sg_context *sgc,
747*4882a593Smuzhiyun 			      void *context)
748*4882a593Smuzhiyun {
749*4882a593Smuzhiyun 	struct atto_ioctl *hi = (struct atto_ioctl *)esas2r_buffered_ioctl;
750*4882a593Smuzhiyun 
751*4882a593Smuzhiyun 	hi->status = ATTO_STS_SUCCESS;
752*4882a593Smuzhiyun 
753*4882a593Smuzhiyun 	switch (hi->function) {
754*4882a593Smuzhiyun 	case ATTO_FUNC_GET_ADAP_INFO:
755*4882a593Smuzhiyun 	{
756*4882a593Smuzhiyun 		u8 *class_code = (u8 *)&a->pcid->class;
757*4882a593Smuzhiyun 
758*4882a593Smuzhiyun 		struct atto_hba_get_adapter_info *gai =
759*4882a593Smuzhiyun 			&hi->data.get_adap_info;
760*4882a593Smuzhiyun 
761*4882a593Smuzhiyun 		if (hi->flags & HBAF_TUNNEL) {
762*4882a593Smuzhiyun 			hi->status = ATTO_STS_UNSUPPORTED;
763*4882a593Smuzhiyun 			break;
764*4882a593Smuzhiyun 		}
765*4882a593Smuzhiyun 
766*4882a593Smuzhiyun 		if (hi->version > ATTO_VER_GET_ADAP_INFO0) {
767*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_VERSION;
768*4882a593Smuzhiyun 			hi->version = ATTO_VER_GET_ADAP_INFO0;
769*4882a593Smuzhiyun 			break;
770*4882a593Smuzhiyun 		}
771*4882a593Smuzhiyun 
772*4882a593Smuzhiyun 		memset(gai, 0, sizeof(*gai));
773*4882a593Smuzhiyun 
774*4882a593Smuzhiyun 		gai->pci.vendor_id = a->pcid->vendor;
775*4882a593Smuzhiyun 		gai->pci.device_id = a->pcid->device;
776*4882a593Smuzhiyun 		gai->pci.ss_vendor_id = a->pcid->subsystem_vendor;
777*4882a593Smuzhiyun 		gai->pci.ss_device_id = a->pcid->subsystem_device;
778*4882a593Smuzhiyun 		gai->pci.class_code[0] = class_code[0];
779*4882a593Smuzhiyun 		gai->pci.class_code[1] = class_code[1];
780*4882a593Smuzhiyun 		gai->pci.class_code[2] = class_code[2];
781*4882a593Smuzhiyun 		gai->pci.rev_id = a->pcid->revision;
782*4882a593Smuzhiyun 		gai->pci.bus_num = a->pcid->bus->number;
783*4882a593Smuzhiyun 		gai->pci.dev_num = PCI_SLOT(a->pcid->devfn);
784*4882a593Smuzhiyun 		gai->pci.func_num = PCI_FUNC(a->pcid->devfn);
785*4882a593Smuzhiyun 
786*4882a593Smuzhiyun 		if (pci_is_pcie(a->pcid)) {
787*4882a593Smuzhiyun 			u16 stat;
788*4882a593Smuzhiyun 			u32 caps;
789*4882a593Smuzhiyun 
790*4882a593Smuzhiyun 			pcie_capability_read_word(a->pcid, PCI_EXP_LNKSTA,
791*4882a593Smuzhiyun 						  &stat);
792*4882a593Smuzhiyun 			pcie_capability_read_dword(a->pcid, PCI_EXP_LNKCAP,
793*4882a593Smuzhiyun 						   &caps);
794*4882a593Smuzhiyun 
795*4882a593Smuzhiyun 			gai->pci.link_speed_curr =
796*4882a593Smuzhiyun 				(u8)(stat & PCI_EXP_LNKSTA_CLS);
797*4882a593Smuzhiyun 			gai->pci.link_speed_max =
798*4882a593Smuzhiyun 				(u8)(caps & PCI_EXP_LNKCAP_SLS);
799*4882a593Smuzhiyun 			gai->pci.link_width_curr =
800*4882a593Smuzhiyun 				(u8)((stat & PCI_EXP_LNKSTA_NLW)
801*4882a593Smuzhiyun 				     >> PCI_EXP_LNKSTA_NLW_SHIFT);
802*4882a593Smuzhiyun 			gai->pci.link_width_max =
803*4882a593Smuzhiyun 				(u8)((caps & PCI_EXP_LNKCAP_MLW)
804*4882a593Smuzhiyun 				     >> 4);
805*4882a593Smuzhiyun 		}
806*4882a593Smuzhiyun 
807*4882a593Smuzhiyun 		gai->pci.msi_vector_cnt = 1;
808*4882a593Smuzhiyun 
809*4882a593Smuzhiyun 		if (a->pcid->msix_enabled)
810*4882a593Smuzhiyun 			gai->pci.interrupt_mode = ATTO_GAI_PCIIM_MSIX;
811*4882a593Smuzhiyun 		else if (a->pcid->msi_enabled)
812*4882a593Smuzhiyun 			gai->pci.interrupt_mode = ATTO_GAI_PCIIM_MSI;
813*4882a593Smuzhiyun 		else
814*4882a593Smuzhiyun 			gai->pci.interrupt_mode = ATTO_GAI_PCIIM_LEGACY;
815*4882a593Smuzhiyun 
816*4882a593Smuzhiyun 		gai->adap_type = ATTO_GAI_AT_ESASRAID2;
817*4882a593Smuzhiyun 
818*4882a593Smuzhiyun 		if (test_bit(AF2_THUNDERLINK, &a->flags2))
819*4882a593Smuzhiyun 			gai->adap_type = ATTO_GAI_AT_TLSASHBA;
820*4882a593Smuzhiyun 
821*4882a593Smuzhiyun 		if (test_bit(AF_DEGRADED_MODE, &a->flags))
822*4882a593Smuzhiyun 			gai->adap_flags |= ATTO_GAI_AF_DEGRADED;
823*4882a593Smuzhiyun 
824*4882a593Smuzhiyun 		gai->adap_flags |= ATTO_GAI_AF_SPT_SUPP |
825*4882a593Smuzhiyun 				   ATTO_GAI_AF_DEVADDR_SUPP;
826*4882a593Smuzhiyun 
827*4882a593Smuzhiyun 		if (a->pcid->subsystem_device == ATTO_ESAS_R60F
828*4882a593Smuzhiyun 		    || a->pcid->subsystem_device == ATTO_ESAS_R608
829*4882a593Smuzhiyun 		    || a->pcid->subsystem_device == ATTO_ESAS_R644
830*4882a593Smuzhiyun 		    || a->pcid->subsystem_device == ATTO_TSSC_3808E)
831*4882a593Smuzhiyun 			gai->adap_flags |= ATTO_GAI_AF_VIRT_SES;
832*4882a593Smuzhiyun 
833*4882a593Smuzhiyun 		gai->num_ports = ESAS2R_NUM_PHYS;
834*4882a593Smuzhiyun 		gai->num_phys = ESAS2R_NUM_PHYS;
835*4882a593Smuzhiyun 
836*4882a593Smuzhiyun 		strcpy(gai->firmware_rev, a->fw_rev);
837*4882a593Smuzhiyun 		strcpy(gai->flash_rev, a->flash_rev);
838*4882a593Smuzhiyun 		strcpy(gai->model_name_short, esas2r_get_model_name_short(a));
839*4882a593Smuzhiyun 		strcpy(gai->model_name, esas2r_get_model_name(a));
840*4882a593Smuzhiyun 
841*4882a593Smuzhiyun 		gai->num_targets = ESAS2R_MAX_TARGETS;
842*4882a593Smuzhiyun 
843*4882a593Smuzhiyun 		gai->num_busses = 1;
844*4882a593Smuzhiyun 		gai->num_targsper_bus = gai->num_targets;
845*4882a593Smuzhiyun 		gai->num_lunsper_targ = 256;
846*4882a593Smuzhiyun 
847*4882a593Smuzhiyun 		if (a->pcid->subsystem_device == ATTO_ESAS_R6F0
848*4882a593Smuzhiyun 		    || a->pcid->subsystem_device == ATTO_ESAS_R60F)
849*4882a593Smuzhiyun 			gai->num_connectors = 4;
850*4882a593Smuzhiyun 		else
851*4882a593Smuzhiyun 			gai->num_connectors = 2;
852*4882a593Smuzhiyun 
853*4882a593Smuzhiyun 		gai->adap_flags2 |= ATTO_GAI_AF2_ADAP_CTRL_SUPP;
854*4882a593Smuzhiyun 
855*4882a593Smuzhiyun 		gai->num_targets_backend = a->num_targets_backend;
856*4882a593Smuzhiyun 
857*4882a593Smuzhiyun 		gai->tunnel_flags = a->ioctl_tunnel
858*4882a593Smuzhiyun 				    & (ATTO_GAI_TF_MEM_RW
859*4882a593Smuzhiyun 				       | ATTO_GAI_TF_TRACE
860*4882a593Smuzhiyun 				       | ATTO_GAI_TF_SCSI_PASS_THRU
861*4882a593Smuzhiyun 				       | ATTO_GAI_TF_GET_DEV_ADDR
862*4882a593Smuzhiyun 				       | ATTO_GAI_TF_PHY_CTRL
863*4882a593Smuzhiyun 				       | ATTO_GAI_TF_CONN_CTRL
864*4882a593Smuzhiyun 				       | ATTO_GAI_TF_GET_DEV_INFO);
865*4882a593Smuzhiyun 		break;
866*4882a593Smuzhiyun 	}
867*4882a593Smuzhiyun 
868*4882a593Smuzhiyun 	case ATTO_FUNC_GET_ADAP_ADDR:
869*4882a593Smuzhiyun 	{
870*4882a593Smuzhiyun 		struct atto_hba_get_adapter_address *gaa =
871*4882a593Smuzhiyun 			&hi->data.get_adap_addr;
872*4882a593Smuzhiyun 
873*4882a593Smuzhiyun 		if (hi->flags & HBAF_TUNNEL) {
874*4882a593Smuzhiyun 			hi->status = ATTO_STS_UNSUPPORTED;
875*4882a593Smuzhiyun 			break;
876*4882a593Smuzhiyun 		}
877*4882a593Smuzhiyun 
878*4882a593Smuzhiyun 		if (hi->version > ATTO_VER_GET_ADAP_ADDR0) {
879*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_VERSION;
880*4882a593Smuzhiyun 			hi->version = ATTO_VER_GET_ADAP_ADDR0;
881*4882a593Smuzhiyun 		} else if (gaa->addr_type == ATTO_GAA_AT_PORT
882*4882a593Smuzhiyun 			   || gaa->addr_type == ATTO_GAA_AT_NODE) {
883*4882a593Smuzhiyun 			if (gaa->addr_type == ATTO_GAA_AT_PORT
884*4882a593Smuzhiyun 			    && gaa->port_id >= ESAS2R_NUM_PHYS) {
885*4882a593Smuzhiyun 				hi->status = ATTO_STS_NOT_APPL;
886*4882a593Smuzhiyun 			} else {
887*4882a593Smuzhiyun 				memcpy((u64 *)gaa->address,
888*4882a593Smuzhiyun 				       &a->nvram->sas_addr[0], sizeof(u64));
889*4882a593Smuzhiyun 				gaa->addr_len = sizeof(u64);
890*4882a593Smuzhiyun 			}
891*4882a593Smuzhiyun 		} else {
892*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_PARAM;
893*4882a593Smuzhiyun 		}
894*4882a593Smuzhiyun 
895*4882a593Smuzhiyun 		break;
896*4882a593Smuzhiyun 	}
897*4882a593Smuzhiyun 
898*4882a593Smuzhiyun 	case ATTO_FUNC_MEM_RW:
899*4882a593Smuzhiyun 	{
900*4882a593Smuzhiyun 		if (hi->flags & HBAF_TUNNEL) {
901*4882a593Smuzhiyun 			if (hba_ioctl_tunnel(a, hi, rq, sgc))
902*4882a593Smuzhiyun 				return true;
903*4882a593Smuzhiyun 
904*4882a593Smuzhiyun 			break;
905*4882a593Smuzhiyun 		}
906*4882a593Smuzhiyun 
907*4882a593Smuzhiyun 		hi->status = ATTO_STS_UNSUPPORTED;
908*4882a593Smuzhiyun 
909*4882a593Smuzhiyun 		break;
910*4882a593Smuzhiyun 	}
911*4882a593Smuzhiyun 
912*4882a593Smuzhiyun 	case ATTO_FUNC_TRACE:
913*4882a593Smuzhiyun 	{
914*4882a593Smuzhiyun 		struct atto_hba_trace *trc = &hi->data.trace;
915*4882a593Smuzhiyun 
916*4882a593Smuzhiyun 		if (hi->flags & HBAF_TUNNEL) {
917*4882a593Smuzhiyun 			if (hba_ioctl_tunnel(a, hi, rq, sgc))
918*4882a593Smuzhiyun 				return true;
919*4882a593Smuzhiyun 
920*4882a593Smuzhiyun 			break;
921*4882a593Smuzhiyun 		}
922*4882a593Smuzhiyun 
923*4882a593Smuzhiyun 		if (hi->version > ATTO_VER_TRACE1) {
924*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_VERSION;
925*4882a593Smuzhiyun 			hi->version = ATTO_VER_TRACE1;
926*4882a593Smuzhiyun 			break;
927*4882a593Smuzhiyun 		}
928*4882a593Smuzhiyun 
929*4882a593Smuzhiyun 		if (trc->trace_type == ATTO_TRC_TT_FWCOREDUMP
930*4882a593Smuzhiyun 		    && hi->version >= ATTO_VER_TRACE1) {
931*4882a593Smuzhiyun 			if (trc->trace_func == ATTO_TRC_TF_UPLOAD) {
932*4882a593Smuzhiyun 				u32 len = hi->data_length;
933*4882a593Smuzhiyun 				u32 offset = trc->current_offset;
934*4882a593Smuzhiyun 				u32 total_len = ESAS2R_FWCOREDUMP_SZ;
935*4882a593Smuzhiyun 
936*4882a593Smuzhiyun 				/* Size is zero if a core dump isn't present */
937*4882a593Smuzhiyun 				if (!test_bit(AF2_COREDUMP_SAVED, &a->flags2))
938*4882a593Smuzhiyun 					total_len = 0;
939*4882a593Smuzhiyun 
940*4882a593Smuzhiyun 				if (len > total_len)
941*4882a593Smuzhiyun 					len = total_len;
942*4882a593Smuzhiyun 
943*4882a593Smuzhiyun 				if (offset >= total_len
944*4882a593Smuzhiyun 				    || offset + len > total_len
945*4882a593Smuzhiyun 				    || len == 0) {
946*4882a593Smuzhiyun 					hi->status = ATTO_STS_INV_PARAM;
947*4882a593Smuzhiyun 					break;
948*4882a593Smuzhiyun 				}
949*4882a593Smuzhiyun 
950*4882a593Smuzhiyun 				memcpy(trc + 1,
951*4882a593Smuzhiyun 				       a->fw_coredump_buff + offset,
952*4882a593Smuzhiyun 				       len);
953*4882a593Smuzhiyun 
954*4882a593Smuzhiyun 				hi->data_length = len;
955*4882a593Smuzhiyun 			} else if (trc->trace_func == ATTO_TRC_TF_RESET) {
956*4882a593Smuzhiyun 				memset(a->fw_coredump_buff, 0,
957*4882a593Smuzhiyun 				       ESAS2R_FWCOREDUMP_SZ);
958*4882a593Smuzhiyun 
959*4882a593Smuzhiyun 				clear_bit(AF2_COREDUMP_SAVED, &a->flags2);
960*4882a593Smuzhiyun 			} else if (trc->trace_func != ATTO_TRC_TF_GET_INFO) {
961*4882a593Smuzhiyun 				hi->status = ATTO_STS_UNSUPPORTED;
962*4882a593Smuzhiyun 				break;
963*4882a593Smuzhiyun 			}
964*4882a593Smuzhiyun 
965*4882a593Smuzhiyun 			/* Always return all the info we can. */
966*4882a593Smuzhiyun 			trc->trace_mask = 0;
967*4882a593Smuzhiyun 			trc->current_offset = 0;
968*4882a593Smuzhiyun 			trc->total_length = ESAS2R_FWCOREDUMP_SZ;
969*4882a593Smuzhiyun 
970*4882a593Smuzhiyun 			/* Return zero length buffer if core dump not present */
971*4882a593Smuzhiyun 			if (!test_bit(AF2_COREDUMP_SAVED, &a->flags2))
972*4882a593Smuzhiyun 				trc->total_length = 0;
973*4882a593Smuzhiyun 		} else {
974*4882a593Smuzhiyun 			hi->status = ATTO_STS_UNSUPPORTED;
975*4882a593Smuzhiyun 		}
976*4882a593Smuzhiyun 
977*4882a593Smuzhiyun 		break;
978*4882a593Smuzhiyun 	}
979*4882a593Smuzhiyun 
980*4882a593Smuzhiyun 	case ATTO_FUNC_SCSI_PASS_THRU:
981*4882a593Smuzhiyun 	{
982*4882a593Smuzhiyun 		struct atto_hba_scsi_pass_thru *spt = &hi->data.scsi_pass_thru;
983*4882a593Smuzhiyun 		struct scsi_lun lun;
984*4882a593Smuzhiyun 
985*4882a593Smuzhiyun 		memcpy(&lun, spt->lun, sizeof(struct scsi_lun));
986*4882a593Smuzhiyun 
987*4882a593Smuzhiyun 		if (hi->flags & HBAF_TUNNEL) {
988*4882a593Smuzhiyun 			if (hba_ioctl_tunnel(a, hi, rq, sgc))
989*4882a593Smuzhiyun 				return true;
990*4882a593Smuzhiyun 
991*4882a593Smuzhiyun 			break;
992*4882a593Smuzhiyun 		}
993*4882a593Smuzhiyun 
994*4882a593Smuzhiyun 		if (hi->version > ATTO_VER_SCSI_PASS_THRU0) {
995*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_VERSION;
996*4882a593Smuzhiyun 			hi->version = ATTO_VER_SCSI_PASS_THRU0;
997*4882a593Smuzhiyun 			break;
998*4882a593Smuzhiyun 		}
999*4882a593Smuzhiyun 
1000*4882a593Smuzhiyun 		if (spt->target_id >= ESAS2R_MAX_TARGETS || !check_lun(lun)) {
1001*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_PARAM;
1002*4882a593Smuzhiyun 			break;
1003*4882a593Smuzhiyun 		}
1004*4882a593Smuzhiyun 
1005*4882a593Smuzhiyun 		esas2r_sgc_init(sgc, a, rq, NULL);
1006*4882a593Smuzhiyun 
1007*4882a593Smuzhiyun 		sgc->length = hi->data_length;
1008*4882a593Smuzhiyun 		sgc->cur_offset += offsetof(struct atto_ioctl, data.byte)
1009*4882a593Smuzhiyun 				   + sizeof(struct atto_hba_scsi_pass_thru);
1010*4882a593Smuzhiyun 
1011*4882a593Smuzhiyun 		/* Finish request initialization */
1012*4882a593Smuzhiyun 		rq->target_id = (u16)spt->target_id;
1013*4882a593Smuzhiyun 		rq->vrq->scsi.flags |= cpu_to_le32(spt->lun[1]);
1014*4882a593Smuzhiyun 		memcpy(rq->vrq->scsi.cdb, spt->cdb, 16);
1015*4882a593Smuzhiyun 		rq->vrq->scsi.length = cpu_to_le32(hi->data_length);
1016*4882a593Smuzhiyun 		rq->sense_len = spt->sense_length;
1017*4882a593Smuzhiyun 		rq->sense_buf = (u8 *)spt->sense_data;
1018*4882a593Smuzhiyun 		/* NOTE: we ignore spt->timeout */
1019*4882a593Smuzhiyun 
1020*4882a593Smuzhiyun 		/*
1021*4882a593Smuzhiyun 		 * always usurp the completion callback since the interrupt
1022*4882a593Smuzhiyun 		 * callback mechanism may be used.
1023*4882a593Smuzhiyun 		 */
1024*4882a593Smuzhiyun 
1025*4882a593Smuzhiyun 		rq->aux_req_cx = hi;
1026*4882a593Smuzhiyun 		rq->aux_req_cb = rq->comp_cb;
1027*4882a593Smuzhiyun 		rq->comp_cb = scsi_passthru_comp_cb;
1028*4882a593Smuzhiyun 
1029*4882a593Smuzhiyun 		if (spt->flags & ATTO_SPTF_DATA_IN) {
1030*4882a593Smuzhiyun 			rq->vrq->scsi.flags |= cpu_to_le32(FCP_CMND_RDD);
1031*4882a593Smuzhiyun 		} else if (spt->flags & ATTO_SPTF_DATA_OUT) {
1032*4882a593Smuzhiyun 			rq->vrq->scsi.flags |= cpu_to_le32(FCP_CMND_WRD);
1033*4882a593Smuzhiyun 		} else {
1034*4882a593Smuzhiyun 			if (sgc->length) {
1035*4882a593Smuzhiyun 				hi->status = ATTO_STS_INV_PARAM;
1036*4882a593Smuzhiyun 				break;
1037*4882a593Smuzhiyun 			}
1038*4882a593Smuzhiyun 		}
1039*4882a593Smuzhiyun 
1040*4882a593Smuzhiyun 		if (spt->flags & ATTO_SPTF_ORDERED_Q)
1041*4882a593Smuzhiyun 			rq->vrq->scsi.flags |=
1042*4882a593Smuzhiyun 				cpu_to_le32(FCP_CMND_TA_ORDRD_Q);
1043*4882a593Smuzhiyun 		else if (spt->flags & ATTO_SPTF_HEAD_OF_Q)
1044*4882a593Smuzhiyun 			rq->vrq->scsi.flags |= cpu_to_le32(FCP_CMND_TA_HEAD_Q);
1045*4882a593Smuzhiyun 
1046*4882a593Smuzhiyun 
1047*4882a593Smuzhiyun 		if (!esas2r_build_sg_list(a, rq, sgc)) {
1048*4882a593Smuzhiyun 			hi->status = ATTO_STS_OUT_OF_RSRC;
1049*4882a593Smuzhiyun 			break;
1050*4882a593Smuzhiyun 		}
1051*4882a593Smuzhiyun 
1052*4882a593Smuzhiyun 		esas2r_start_request(a, rq);
1053*4882a593Smuzhiyun 
1054*4882a593Smuzhiyun 		return true;
1055*4882a593Smuzhiyun 	}
1056*4882a593Smuzhiyun 
1057*4882a593Smuzhiyun 	case ATTO_FUNC_GET_DEV_ADDR:
1058*4882a593Smuzhiyun 	{
1059*4882a593Smuzhiyun 		struct atto_hba_get_device_address *gda =
1060*4882a593Smuzhiyun 			&hi->data.get_dev_addr;
1061*4882a593Smuzhiyun 		struct esas2r_target *t;
1062*4882a593Smuzhiyun 
1063*4882a593Smuzhiyun 		if (hi->flags & HBAF_TUNNEL) {
1064*4882a593Smuzhiyun 			if (hba_ioctl_tunnel(a, hi, rq, sgc))
1065*4882a593Smuzhiyun 				return true;
1066*4882a593Smuzhiyun 
1067*4882a593Smuzhiyun 			break;
1068*4882a593Smuzhiyun 		}
1069*4882a593Smuzhiyun 
1070*4882a593Smuzhiyun 		if (hi->version > ATTO_VER_GET_DEV_ADDR0) {
1071*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_VERSION;
1072*4882a593Smuzhiyun 			hi->version = ATTO_VER_GET_DEV_ADDR0;
1073*4882a593Smuzhiyun 			break;
1074*4882a593Smuzhiyun 		}
1075*4882a593Smuzhiyun 
1076*4882a593Smuzhiyun 		if (gda->target_id >= ESAS2R_MAX_TARGETS) {
1077*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_PARAM;
1078*4882a593Smuzhiyun 			break;
1079*4882a593Smuzhiyun 		}
1080*4882a593Smuzhiyun 
1081*4882a593Smuzhiyun 		t = a->targetdb + (u16)gda->target_id;
1082*4882a593Smuzhiyun 
1083*4882a593Smuzhiyun 		if (t->target_state != TS_PRESENT) {
1084*4882a593Smuzhiyun 			hi->status = ATTO_STS_FAILED;
1085*4882a593Smuzhiyun 		} else if (gda->addr_type == ATTO_GDA_AT_PORT) {
1086*4882a593Smuzhiyun 			if (t->sas_addr == 0) {
1087*4882a593Smuzhiyun 				hi->status = ATTO_STS_UNSUPPORTED;
1088*4882a593Smuzhiyun 			} else {
1089*4882a593Smuzhiyun 				*(u64 *)gda->address = t->sas_addr;
1090*4882a593Smuzhiyun 
1091*4882a593Smuzhiyun 				gda->addr_len = sizeof(u64);
1092*4882a593Smuzhiyun 			}
1093*4882a593Smuzhiyun 		} else if (gda->addr_type == ATTO_GDA_AT_NODE) {
1094*4882a593Smuzhiyun 			hi->status = ATTO_STS_NOT_APPL;
1095*4882a593Smuzhiyun 		} else {
1096*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_PARAM;
1097*4882a593Smuzhiyun 		}
1098*4882a593Smuzhiyun 
1099*4882a593Smuzhiyun 		/* update the target ID to the next one present. */
1100*4882a593Smuzhiyun 
1101*4882a593Smuzhiyun 		gda->target_id =
1102*4882a593Smuzhiyun 			esas2r_targ_db_find_next_present(a,
1103*4882a593Smuzhiyun 							 (u16)gda->target_id);
1104*4882a593Smuzhiyun 		break;
1105*4882a593Smuzhiyun 	}
1106*4882a593Smuzhiyun 
1107*4882a593Smuzhiyun 	case ATTO_FUNC_PHY_CTRL:
1108*4882a593Smuzhiyun 	case ATTO_FUNC_CONN_CTRL:
1109*4882a593Smuzhiyun 	{
1110*4882a593Smuzhiyun 		if (hba_ioctl_tunnel(a, hi, rq, sgc))
1111*4882a593Smuzhiyun 			return true;
1112*4882a593Smuzhiyun 
1113*4882a593Smuzhiyun 		break;
1114*4882a593Smuzhiyun 	}
1115*4882a593Smuzhiyun 
1116*4882a593Smuzhiyun 	case ATTO_FUNC_ADAP_CTRL:
1117*4882a593Smuzhiyun 	{
1118*4882a593Smuzhiyun 		struct atto_hba_adap_ctrl *ac = &hi->data.adap_ctrl;
1119*4882a593Smuzhiyun 
1120*4882a593Smuzhiyun 		if (hi->flags & HBAF_TUNNEL) {
1121*4882a593Smuzhiyun 			hi->status = ATTO_STS_UNSUPPORTED;
1122*4882a593Smuzhiyun 			break;
1123*4882a593Smuzhiyun 		}
1124*4882a593Smuzhiyun 
1125*4882a593Smuzhiyun 		if (hi->version > ATTO_VER_ADAP_CTRL0) {
1126*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_VERSION;
1127*4882a593Smuzhiyun 			hi->version = ATTO_VER_ADAP_CTRL0;
1128*4882a593Smuzhiyun 			break;
1129*4882a593Smuzhiyun 		}
1130*4882a593Smuzhiyun 
1131*4882a593Smuzhiyun 		if (ac->adap_func == ATTO_AC_AF_HARD_RST) {
1132*4882a593Smuzhiyun 			esas2r_reset_adapter(a);
1133*4882a593Smuzhiyun 		} else if (ac->adap_func != ATTO_AC_AF_GET_STATE) {
1134*4882a593Smuzhiyun 			hi->status = ATTO_STS_UNSUPPORTED;
1135*4882a593Smuzhiyun 			break;
1136*4882a593Smuzhiyun 		}
1137*4882a593Smuzhiyun 
1138*4882a593Smuzhiyun 		if (test_bit(AF_CHPRST_NEEDED, &a->flags))
1139*4882a593Smuzhiyun 			ac->adap_state = ATTO_AC_AS_RST_SCHED;
1140*4882a593Smuzhiyun 		else if (test_bit(AF_CHPRST_PENDING, &a->flags))
1141*4882a593Smuzhiyun 			ac->adap_state = ATTO_AC_AS_RST_IN_PROG;
1142*4882a593Smuzhiyun 		else if (test_bit(AF_DISC_PENDING, &a->flags))
1143*4882a593Smuzhiyun 			ac->adap_state = ATTO_AC_AS_RST_DISC;
1144*4882a593Smuzhiyun 		else if (test_bit(AF_DISABLED, &a->flags))
1145*4882a593Smuzhiyun 			ac->adap_state = ATTO_AC_AS_DISABLED;
1146*4882a593Smuzhiyun 		else if (test_bit(AF_DEGRADED_MODE, &a->flags))
1147*4882a593Smuzhiyun 			ac->adap_state = ATTO_AC_AS_DEGRADED;
1148*4882a593Smuzhiyun 		else
1149*4882a593Smuzhiyun 			ac->adap_state = ATTO_AC_AS_OK;
1150*4882a593Smuzhiyun 
1151*4882a593Smuzhiyun 		break;
1152*4882a593Smuzhiyun 	}
1153*4882a593Smuzhiyun 
1154*4882a593Smuzhiyun 	case ATTO_FUNC_GET_DEV_INFO:
1155*4882a593Smuzhiyun 	{
1156*4882a593Smuzhiyun 		struct atto_hba_get_device_info *gdi = &hi->data.get_dev_info;
1157*4882a593Smuzhiyun 		struct esas2r_target *t;
1158*4882a593Smuzhiyun 
1159*4882a593Smuzhiyun 		if (hi->flags & HBAF_TUNNEL) {
1160*4882a593Smuzhiyun 			if (hba_ioctl_tunnel(a, hi, rq, sgc))
1161*4882a593Smuzhiyun 				return true;
1162*4882a593Smuzhiyun 
1163*4882a593Smuzhiyun 			break;
1164*4882a593Smuzhiyun 		}
1165*4882a593Smuzhiyun 
1166*4882a593Smuzhiyun 		if (hi->version > ATTO_VER_GET_DEV_INFO0) {
1167*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_VERSION;
1168*4882a593Smuzhiyun 			hi->version = ATTO_VER_GET_DEV_INFO0;
1169*4882a593Smuzhiyun 			break;
1170*4882a593Smuzhiyun 		}
1171*4882a593Smuzhiyun 
1172*4882a593Smuzhiyun 		if (gdi->target_id >= ESAS2R_MAX_TARGETS) {
1173*4882a593Smuzhiyun 			hi->status = ATTO_STS_INV_PARAM;
1174*4882a593Smuzhiyun 			break;
1175*4882a593Smuzhiyun 		}
1176*4882a593Smuzhiyun 
1177*4882a593Smuzhiyun 		t = a->targetdb + (u16)gdi->target_id;
1178*4882a593Smuzhiyun 
1179*4882a593Smuzhiyun 		/* update the target ID to the next one present. */
1180*4882a593Smuzhiyun 
1181*4882a593Smuzhiyun 		gdi->target_id =
1182*4882a593Smuzhiyun 			esas2r_targ_db_find_next_present(a,
1183*4882a593Smuzhiyun 							 (u16)gdi->target_id);
1184*4882a593Smuzhiyun 
1185*4882a593Smuzhiyun 		if (t->target_state != TS_PRESENT) {
1186*4882a593Smuzhiyun 			hi->status = ATTO_STS_FAILED;
1187*4882a593Smuzhiyun 			break;
1188*4882a593Smuzhiyun 		}
1189*4882a593Smuzhiyun 
1190*4882a593Smuzhiyun 		hi->status = ATTO_STS_UNSUPPORTED;
1191*4882a593Smuzhiyun 		break;
1192*4882a593Smuzhiyun 	}
1193*4882a593Smuzhiyun 
1194*4882a593Smuzhiyun 	default:
1195*4882a593Smuzhiyun 
1196*4882a593Smuzhiyun 		hi->status = ATTO_STS_INV_FUNC;
1197*4882a593Smuzhiyun 		break;
1198*4882a593Smuzhiyun 	}
1199*4882a593Smuzhiyun 
1200*4882a593Smuzhiyun 	return false;
1201*4882a593Smuzhiyun }
1202*4882a593Smuzhiyun 
hba_ioctl_done_callback(struct esas2r_adapter * a,struct esas2r_request * rq,void * context)1203*4882a593Smuzhiyun static void hba_ioctl_done_callback(struct esas2r_adapter *a,
1204*4882a593Smuzhiyun 				    struct esas2r_request *rq, void *context)
1205*4882a593Smuzhiyun {
1206*4882a593Smuzhiyun 	struct atto_ioctl *ioctl_hba =
1207*4882a593Smuzhiyun 		(struct atto_ioctl *)esas2r_buffered_ioctl;
1208*4882a593Smuzhiyun 
1209*4882a593Smuzhiyun 	esas2r_debug("hba_ioctl_done_callback %d", a->index);
1210*4882a593Smuzhiyun 
1211*4882a593Smuzhiyun 	if (ioctl_hba->function == ATTO_FUNC_GET_ADAP_INFO) {
1212*4882a593Smuzhiyun 		struct atto_hba_get_adapter_info *gai =
1213*4882a593Smuzhiyun 			&ioctl_hba->data.get_adap_info;
1214*4882a593Smuzhiyun 
1215*4882a593Smuzhiyun 		esas2r_debug("ATTO_FUNC_GET_ADAP_INFO");
1216*4882a593Smuzhiyun 
1217*4882a593Smuzhiyun 		gai->drvr_rev_major = ESAS2R_MAJOR_REV;
1218*4882a593Smuzhiyun 		gai->drvr_rev_minor = ESAS2R_MINOR_REV;
1219*4882a593Smuzhiyun 
1220*4882a593Smuzhiyun 		strcpy(gai->drvr_rev_ascii, ESAS2R_VERSION_STR);
1221*4882a593Smuzhiyun 		strcpy(gai->drvr_name, ESAS2R_DRVR_NAME);
1222*4882a593Smuzhiyun 
1223*4882a593Smuzhiyun 		gai->num_busses = 1;
1224*4882a593Smuzhiyun 		gai->num_targsper_bus = ESAS2R_MAX_ID + 1;
1225*4882a593Smuzhiyun 		gai->num_lunsper_targ = 1;
1226*4882a593Smuzhiyun 	}
1227*4882a593Smuzhiyun }
1228*4882a593Smuzhiyun 
handle_hba_ioctl(struct esas2r_adapter * a,struct atto_ioctl * ioctl_hba)1229*4882a593Smuzhiyun u8 handle_hba_ioctl(struct esas2r_adapter *a,
1230*4882a593Smuzhiyun 		    struct atto_ioctl *ioctl_hba)
1231*4882a593Smuzhiyun {
1232*4882a593Smuzhiyun 	struct esas2r_buffered_ioctl bi;
1233*4882a593Smuzhiyun 
1234*4882a593Smuzhiyun 	memset(&bi, 0, sizeof(bi));
1235*4882a593Smuzhiyun 
1236*4882a593Smuzhiyun 	bi.a = a;
1237*4882a593Smuzhiyun 	bi.ioctl = ioctl_hba;
1238*4882a593Smuzhiyun 	bi.length = sizeof(struct atto_ioctl) + ioctl_hba->data_length;
1239*4882a593Smuzhiyun 	bi.callback = hba_ioctl_callback;
1240*4882a593Smuzhiyun 	bi.context = NULL;
1241*4882a593Smuzhiyun 	bi.done_callback = hba_ioctl_done_callback;
1242*4882a593Smuzhiyun 	bi.done_context = NULL;
1243*4882a593Smuzhiyun 	bi.offset = 0;
1244*4882a593Smuzhiyun 
1245*4882a593Smuzhiyun 	return handle_buffered_ioctl(&bi);
1246*4882a593Smuzhiyun }
1247*4882a593Smuzhiyun 
1248*4882a593Smuzhiyun 
esas2r_write_params(struct esas2r_adapter * a,struct esas2r_request * rq,struct esas2r_sas_nvram * data)1249*4882a593Smuzhiyun int esas2r_write_params(struct esas2r_adapter *a, struct esas2r_request *rq,
1250*4882a593Smuzhiyun 			struct esas2r_sas_nvram *data)
1251*4882a593Smuzhiyun {
1252*4882a593Smuzhiyun 	int result = 0;
1253*4882a593Smuzhiyun 
1254*4882a593Smuzhiyun 	a->nvram_command_done = 0;
1255*4882a593Smuzhiyun 	rq->comp_cb = complete_nvr_req;
1256*4882a593Smuzhiyun 
1257*4882a593Smuzhiyun 	if (esas2r_nvram_write(a, rq, data)) {
1258*4882a593Smuzhiyun 		/* now wait around for it to complete. */
1259*4882a593Smuzhiyun 		while (!a->nvram_command_done)
1260*4882a593Smuzhiyun 			wait_event_interruptible(a->nvram_waiter,
1261*4882a593Smuzhiyun 						 a->nvram_command_done);
1262*4882a593Smuzhiyun 		;
1263*4882a593Smuzhiyun 
1264*4882a593Smuzhiyun 		/* done, check the status. */
1265*4882a593Smuzhiyun 		if (rq->req_stat == RS_SUCCESS)
1266*4882a593Smuzhiyun 			result = 1;
1267*4882a593Smuzhiyun 	}
1268*4882a593Smuzhiyun 	return result;
1269*4882a593Smuzhiyun }
1270*4882a593Smuzhiyun 
1271*4882a593Smuzhiyun 
1272*4882a593Smuzhiyun /* This function only cares about ATTO-specific ioctls (atto_express_ioctl) */
esas2r_ioctl_handler(void * hostdata,unsigned int cmd,void __user * arg)1273*4882a593Smuzhiyun int esas2r_ioctl_handler(void *hostdata, unsigned int cmd, void __user *arg)
1274*4882a593Smuzhiyun {
1275*4882a593Smuzhiyun 	struct atto_express_ioctl *ioctl = NULL;
1276*4882a593Smuzhiyun 	struct esas2r_adapter *a;
1277*4882a593Smuzhiyun 	struct esas2r_request *rq;
1278*4882a593Smuzhiyun 	u16 code;
1279*4882a593Smuzhiyun 	int err;
1280*4882a593Smuzhiyun 
1281*4882a593Smuzhiyun 	esas2r_log(ESAS2R_LOG_DEBG, "ioctl (%p, %x, %p)", hostdata, cmd, arg);
1282*4882a593Smuzhiyun 
1283*4882a593Smuzhiyun 	if ((arg == NULL)
1284*4882a593Smuzhiyun 	    || (cmd < EXPRESS_IOCTL_MIN)
1285*4882a593Smuzhiyun 	    || (cmd > EXPRESS_IOCTL_MAX))
1286*4882a593Smuzhiyun 		return -ENOTSUPP;
1287*4882a593Smuzhiyun 
1288*4882a593Smuzhiyun 	ioctl = memdup_user(arg, sizeof(struct atto_express_ioctl));
1289*4882a593Smuzhiyun 	if (IS_ERR(ioctl)) {
1290*4882a593Smuzhiyun 		esas2r_log(ESAS2R_LOG_WARN,
1291*4882a593Smuzhiyun 			   "ioctl_handler access_ok failed for cmd %u, address %p",
1292*4882a593Smuzhiyun 			   cmd, arg);
1293*4882a593Smuzhiyun 		return PTR_ERR(ioctl);
1294*4882a593Smuzhiyun 	}
1295*4882a593Smuzhiyun 
1296*4882a593Smuzhiyun 	/* verify the signature */
1297*4882a593Smuzhiyun 
1298*4882a593Smuzhiyun 	if (memcmp(ioctl->header.signature,
1299*4882a593Smuzhiyun 		   EXPRESS_IOCTL_SIGNATURE,
1300*4882a593Smuzhiyun 		   EXPRESS_IOCTL_SIGNATURE_SIZE) != 0) {
1301*4882a593Smuzhiyun 		esas2r_log(ESAS2R_LOG_WARN, "invalid signature");
1302*4882a593Smuzhiyun 		kfree(ioctl);
1303*4882a593Smuzhiyun 
1304*4882a593Smuzhiyun 		return -ENOTSUPP;
1305*4882a593Smuzhiyun 	}
1306*4882a593Smuzhiyun 
1307*4882a593Smuzhiyun 	/* assume success */
1308*4882a593Smuzhiyun 
1309*4882a593Smuzhiyun 	ioctl->header.return_code = IOCTL_SUCCESS;
1310*4882a593Smuzhiyun 	err = 0;
1311*4882a593Smuzhiyun 
1312*4882a593Smuzhiyun 	/*
1313*4882a593Smuzhiyun 	 * handle EXPRESS_IOCTL_GET_CHANNELS
1314*4882a593Smuzhiyun 	 * without paying attention to channel
1315*4882a593Smuzhiyun 	 */
1316*4882a593Smuzhiyun 
1317*4882a593Smuzhiyun 	if (cmd == EXPRESS_IOCTL_GET_CHANNELS) {
1318*4882a593Smuzhiyun 		int i = 0, k = 0;
1319*4882a593Smuzhiyun 
1320*4882a593Smuzhiyun 		ioctl->data.chanlist.num_channels = 0;
1321*4882a593Smuzhiyun 
1322*4882a593Smuzhiyun 		while (i < MAX_ADAPTERS) {
1323*4882a593Smuzhiyun 			if (esas2r_adapters[i]) {
1324*4882a593Smuzhiyun 				ioctl->data.chanlist.num_channels++;
1325*4882a593Smuzhiyun 				ioctl->data.chanlist.channel[k] = i;
1326*4882a593Smuzhiyun 				k++;
1327*4882a593Smuzhiyun 			}
1328*4882a593Smuzhiyun 			i++;
1329*4882a593Smuzhiyun 		}
1330*4882a593Smuzhiyun 
1331*4882a593Smuzhiyun 		goto ioctl_done;
1332*4882a593Smuzhiyun 	}
1333*4882a593Smuzhiyun 
1334*4882a593Smuzhiyun 	/* get the channel */
1335*4882a593Smuzhiyun 
1336*4882a593Smuzhiyun 	if (ioctl->header.channel == 0xFF) {
1337*4882a593Smuzhiyun 		a = (struct esas2r_adapter *)hostdata;
1338*4882a593Smuzhiyun 	} else {
1339*4882a593Smuzhiyun 		if (ioctl->header.channel >= MAX_ADAPTERS ||
1340*4882a593Smuzhiyun 			esas2r_adapters[ioctl->header.channel] == NULL) {
1341*4882a593Smuzhiyun 			ioctl->header.return_code = IOCTL_BAD_CHANNEL;
1342*4882a593Smuzhiyun 			esas2r_log(ESAS2R_LOG_WARN, "bad channel value");
1343*4882a593Smuzhiyun 			kfree(ioctl);
1344*4882a593Smuzhiyun 
1345*4882a593Smuzhiyun 			return -ENOTSUPP;
1346*4882a593Smuzhiyun 		}
1347*4882a593Smuzhiyun 		a = esas2r_adapters[ioctl->header.channel];
1348*4882a593Smuzhiyun 	}
1349*4882a593Smuzhiyun 
1350*4882a593Smuzhiyun 	switch (cmd) {
1351*4882a593Smuzhiyun 	case EXPRESS_IOCTL_RW_FIRMWARE:
1352*4882a593Smuzhiyun 
1353*4882a593Smuzhiyun 		if (ioctl->data.fwrw.img_type == FW_IMG_FM_API) {
1354*4882a593Smuzhiyun 			err = esas2r_write_fw(a,
1355*4882a593Smuzhiyun 					      (char *)ioctl->data.fwrw.image,
1356*4882a593Smuzhiyun 					      0,
1357*4882a593Smuzhiyun 					      sizeof(struct
1358*4882a593Smuzhiyun 						     atto_express_ioctl));
1359*4882a593Smuzhiyun 
1360*4882a593Smuzhiyun 			if (err >= 0) {
1361*4882a593Smuzhiyun 				err = esas2r_read_fw(a,
1362*4882a593Smuzhiyun 						     (char *)ioctl->data.fwrw.
1363*4882a593Smuzhiyun 						     image,
1364*4882a593Smuzhiyun 						     0,
1365*4882a593Smuzhiyun 						     sizeof(struct
1366*4882a593Smuzhiyun 							    atto_express_ioctl));
1367*4882a593Smuzhiyun 			}
1368*4882a593Smuzhiyun 		} else if (ioctl->data.fwrw.img_type == FW_IMG_FS_API) {
1369*4882a593Smuzhiyun 			err = esas2r_write_fs(a,
1370*4882a593Smuzhiyun 					      (char *)ioctl->data.fwrw.image,
1371*4882a593Smuzhiyun 					      0,
1372*4882a593Smuzhiyun 					      sizeof(struct
1373*4882a593Smuzhiyun 						     atto_express_ioctl));
1374*4882a593Smuzhiyun 
1375*4882a593Smuzhiyun 			if (err >= 0) {
1376*4882a593Smuzhiyun 				err = esas2r_read_fs(a,
1377*4882a593Smuzhiyun 						     (char *)ioctl->data.fwrw.
1378*4882a593Smuzhiyun 						     image,
1379*4882a593Smuzhiyun 						     0,
1380*4882a593Smuzhiyun 						     sizeof(struct
1381*4882a593Smuzhiyun 							    atto_express_ioctl));
1382*4882a593Smuzhiyun 			}
1383*4882a593Smuzhiyun 		} else {
1384*4882a593Smuzhiyun 			ioctl->header.return_code = IOCTL_BAD_FLASH_IMGTYPE;
1385*4882a593Smuzhiyun 		}
1386*4882a593Smuzhiyun 
1387*4882a593Smuzhiyun 		break;
1388*4882a593Smuzhiyun 
1389*4882a593Smuzhiyun 	case EXPRESS_IOCTL_READ_PARAMS:
1390*4882a593Smuzhiyun 
1391*4882a593Smuzhiyun 		memcpy(ioctl->data.prw.data_buffer, a->nvram,
1392*4882a593Smuzhiyun 		       sizeof(struct esas2r_sas_nvram));
1393*4882a593Smuzhiyun 		ioctl->data.prw.code = 1;
1394*4882a593Smuzhiyun 		break;
1395*4882a593Smuzhiyun 
1396*4882a593Smuzhiyun 	case EXPRESS_IOCTL_WRITE_PARAMS:
1397*4882a593Smuzhiyun 
1398*4882a593Smuzhiyun 		rq = esas2r_alloc_request(a);
1399*4882a593Smuzhiyun 		if (rq == NULL) {
1400*4882a593Smuzhiyun 			kfree(ioctl);
1401*4882a593Smuzhiyun 			esas2r_log(ESAS2R_LOG_WARN,
1402*4882a593Smuzhiyun 			   "could not allocate an internal request");
1403*4882a593Smuzhiyun 			return -ENOMEM;
1404*4882a593Smuzhiyun 		}
1405*4882a593Smuzhiyun 
1406*4882a593Smuzhiyun 		code = esas2r_write_params(a, rq,
1407*4882a593Smuzhiyun 					   (struct esas2r_sas_nvram *)ioctl->data.prw.data_buffer);
1408*4882a593Smuzhiyun 		ioctl->data.prw.code = code;
1409*4882a593Smuzhiyun 
1410*4882a593Smuzhiyun 		esas2r_free_request(a, rq);
1411*4882a593Smuzhiyun 
1412*4882a593Smuzhiyun 		break;
1413*4882a593Smuzhiyun 
1414*4882a593Smuzhiyun 	case EXPRESS_IOCTL_DEFAULT_PARAMS:
1415*4882a593Smuzhiyun 
1416*4882a593Smuzhiyun 		esas2r_nvram_get_defaults(a,
1417*4882a593Smuzhiyun 					  (struct esas2r_sas_nvram *)ioctl->data.prw.data_buffer);
1418*4882a593Smuzhiyun 		ioctl->data.prw.code = 1;
1419*4882a593Smuzhiyun 		break;
1420*4882a593Smuzhiyun 
1421*4882a593Smuzhiyun 	case EXPRESS_IOCTL_CHAN_INFO:
1422*4882a593Smuzhiyun 
1423*4882a593Smuzhiyun 		ioctl->data.chaninfo.major_rev = ESAS2R_MAJOR_REV;
1424*4882a593Smuzhiyun 		ioctl->data.chaninfo.minor_rev = ESAS2R_MINOR_REV;
1425*4882a593Smuzhiyun 		ioctl->data.chaninfo.IRQ = a->pcid->irq;
1426*4882a593Smuzhiyun 		ioctl->data.chaninfo.device_id = a->pcid->device;
1427*4882a593Smuzhiyun 		ioctl->data.chaninfo.vendor_id = a->pcid->vendor;
1428*4882a593Smuzhiyun 		ioctl->data.chaninfo.ven_dev_id = a->pcid->subsystem_device;
1429*4882a593Smuzhiyun 		ioctl->data.chaninfo.revision_id = a->pcid->revision;
1430*4882a593Smuzhiyun 		ioctl->data.chaninfo.pci_bus = a->pcid->bus->number;
1431*4882a593Smuzhiyun 		ioctl->data.chaninfo.pci_dev_func = a->pcid->devfn;
1432*4882a593Smuzhiyun 		ioctl->data.chaninfo.core_rev = 0;
1433*4882a593Smuzhiyun 		ioctl->data.chaninfo.host_no = a->host->host_no;
1434*4882a593Smuzhiyun 		ioctl->data.chaninfo.hbaapi_rev = 0;
1435*4882a593Smuzhiyun 		break;
1436*4882a593Smuzhiyun 
1437*4882a593Smuzhiyun 	case EXPRESS_IOCTL_SMP:
1438*4882a593Smuzhiyun 		ioctl->header.return_code = handle_smp_ioctl(a,
1439*4882a593Smuzhiyun 							     &ioctl->data.
1440*4882a593Smuzhiyun 							     ioctl_smp);
1441*4882a593Smuzhiyun 		break;
1442*4882a593Smuzhiyun 
1443*4882a593Smuzhiyun 	case EXPRESS_CSMI:
1444*4882a593Smuzhiyun 		ioctl->header.return_code =
1445*4882a593Smuzhiyun 			handle_csmi_ioctl(a, &ioctl->data.csmi);
1446*4882a593Smuzhiyun 		break;
1447*4882a593Smuzhiyun 
1448*4882a593Smuzhiyun 	case EXPRESS_IOCTL_HBA:
1449*4882a593Smuzhiyun 		ioctl->header.return_code = handle_hba_ioctl(a,
1450*4882a593Smuzhiyun 							     &ioctl->data.
1451*4882a593Smuzhiyun 							     ioctl_hba);
1452*4882a593Smuzhiyun 		break;
1453*4882a593Smuzhiyun 
1454*4882a593Smuzhiyun 	case EXPRESS_IOCTL_VDA:
1455*4882a593Smuzhiyun 		err = esas2r_write_vda(a,
1456*4882a593Smuzhiyun 				       (char *)&ioctl->data.ioctl_vda,
1457*4882a593Smuzhiyun 				       0,
1458*4882a593Smuzhiyun 				       sizeof(struct atto_ioctl_vda) +
1459*4882a593Smuzhiyun 				       ioctl->data.ioctl_vda.data_length);
1460*4882a593Smuzhiyun 
1461*4882a593Smuzhiyun 		if (err >= 0) {
1462*4882a593Smuzhiyun 			err = esas2r_read_vda(a,
1463*4882a593Smuzhiyun 					      (char *)&ioctl->data.ioctl_vda,
1464*4882a593Smuzhiyun 					      0,
1465*4882a593Smuzhiyun 					      sizeof(struct atto_ioctl_vda) +
1466*4882a593Smuzhiyun 					      ioctl->data.ioctl_vda.data_length);
1467*4882a593Smuzhiyun 		}
1468*4882a593Smuzhiyun 
1469*4882a593Smuzhiyun 
1470*4882a593Smuzhiyun 
1471*4882a593Smuzhiyun 
1472*4882a593Smuzhiyun 		break;
1473*4882a593Smuzhiyun 
1474*4882a593Smuzhiyun 	case EXPRESS_IOCTL_GET_MOD_INFO:
1475*4882a593Smuzhiyun 
1476*4882a593Smuzhiyun 		ioctl->data.modinfo.adapter = a;
1477*4882a593Smuzhiyun 		ioctl->data.modinfo.pci_dev = a->pcid;
1478*4882a593Smuzhiyun 		ioctl->data.modinfo.scsi_host = a->host;
1479*4882a593Smuzhiyun 		ioctl->data.modinfo.host_no = a->host->host_no;
1480*4882a593Smuzhiyun 
1481*4882a593Smuzhiyun 		break;
1482*4882a593Smuzhiyun 
1483*4882a593Smuzhiyun 	default:
1484*4882a593Smuzhiyun 		esas2r_debug("esas2r_ioctl invalid cmd %p!", cmd);
1485*4882a593Smuzhiyun 		ioctl->header.return_code = IOCTL_ERR_INVCMD;
1486*4882a593Smuzhiyun 	}
1487*4882a593Smuzhiyun 
1488*4882a593Smuzhiyun ioctl_done:
1489*4882a593Smuzhiyun 
1490*4882a593Smuzhiyun 	if (err < 0) {
1491*4882a593Smuzhiyun 		esas2r_log(ESAS2R_LOG_WARN, "err %d on ioctl cmd %u", err,
1492*4882a593Smuzhiyun 			   cmd);
1493*4882a593Smuzhiyun 
1494*4882a593Smuzhiyun 		switch (err) {
1495*4882a593Smuzhiyun 		case -ENOMEM:
1496*4882a593Smuzhiyun 		case -EBUSY:
1497*4882a593Smuzhiyun 			ioctl->header.return_code = IOCTL_OUT_OF_RESOURCES;
1498*4882a593Smuzhiyun 			break;
1499*4882a593Smuzhiyun 
1500*4882a593Smuzhiyun 		case -ENOSYS:
1501*4882a593Smuzhiyun 		case -EINVAL:
1502*4882a593Smuzhiyun 			ioctl->header.return_code = IOCTL_INVALID_PARAM;
1503*4882a593Smuzhiyun 			break;
1504*4882a593Smuzhiyun 
1505*4882a593Smuzhiyun 		default:
1506*4882a593Smuzhiyun 			ioctl->header.return_code = IOCTL_GENERAL_ERROR;
1507*4882a593Smuzhiyun 			break;
1508*4882a593Smuzhiyun 		}
1509*4882a593Smuzhiyun 
1510*4882a593Smuzhiyun 	}
1511*4882a593Smuzhiyun 
1512*4882a593Smuzhiyun 	/* Always copy the buffer back, if only to pick up the status */
1513*4882a593Smuzhiyun 	err = copy_to_user(arg, ioctl, sizeof(struct atto_express_ioctl));
1514*4882a593Smuzhiyun 	if (err != 0) {
1515*4882a593Smuzhiyun 		esas2r_log(ESAS2R_LOG_WARN,
1516*4882a593Smuzhiyun 			   "ioctl_handler copy_to_user didn't copy everything (err %d, cmd %u)",
1517*4882a593Smuzhiyun 			   err, cmd);
1518*4882a593Smuzhiyun 		kfree(ioctl);
1519*4882a593Smuzhiyun 
1520*4882a593Smuzhiyun 		return -EFAULT;
1521*4882a593Smuzhiyun 	}
1522*4882a593Smuzhiyun 
1523*4882a593Smuzhiyun 	kfree(ioctl);
1524*4882a593Smuzhiyun 
1525*4882a593Smuzhiyun 	return 0;
1526*4882a593Smuzhiyun }
1527*4882a593Smuzhiyun 
esas2r_ioctl(struct scsi_device * sd,unsigned int cmd,void __user * arg)1528*4882a593Smuzhiyun int esas2r_ioctl(struct scsi_device *sd, unsigned int cmd, void __user *arg)
1529*4882a593Smuzhiyun {
1530*4882a593Smuzhiyun 	return esas2r_ioctl_handler(sd->host->hostdata, cmd, arg);
1531*4882a593Smuzhiyun }
1532*4882a593Smuzhiyun 
free_fw_buffers(struct esas2r_adapter * a)1533*4882a593Smuzhiyun static void free_fw_buffers(struct esas2r_adapter *a)
1534*4882a593Smuzhiyun {
1535*4882a593Smuzhiyun 	if (a->firmware.data) {
1536*4882a593Smuzhiyun 		dma_free_coherent(&a->pcid->dev,
1537*4882a593Smuzhiyun 				  (size_t)a->firmware.orig_len,
1538*4882a593Smuzhiyun 				  a->firmware.data,
1539*4882a593Smuzhiyun 				  (dma_addr_t)a->firmware.phys);
1540*4882a593Smuzhiyun 
1541*4882a593Smuzhiyun 		a->firmware.data = NULL;
1542*4882a593Smuzhiyun 	}
1543*4882a593Smuzhiyun }
1544*4882a593Smuzhiyun 
allocate_fw_buffers(struct esas2r_adapter * a,u32 length)1545*4882a593Smuzhiyun static int allocate_fw_buffers(struct esas2r_adapter *a, u32 length)
1546*4882a593Smuzhiyun {
1547*4882a593Smuzhiyun 	free_fw_buffers(a);
1548*4882a593Smuzhiyun 
1549*4882a593Smuzhiyun 	a->firmware.orig_len = length;
1550*4882a593Smuzhiyun 
1551*4882a593Smuzhiyun 	a->firmware.data = dma_alloc_coherent(&a->pcid->dev,
1552*4882a593Smuzhiyun 					      (size_t)length,
1553*4882a593Smuzhiyun 					      (dma_addr_t *)&a->firmware.phys,
1554*4882a593Smuzhiyun 					      GFP_KERNEL);
1555*4882a593Smuzhiyun 
1556*4882a593Smuzhiyun 	if (!a->firmware.data) {
1557*4882a593Smuzhiyun 		esas2r_debug("buffer alloc failed!");
1558*4882a593Smuzhiyun 		return 0;
1559*4882a593Smuzhiyun 	}
1560*4882a593Smuzhiyun 
1561*4882a593Smuzhiyun 	return 1;
1562*4882a593Smuzhiyun }
1563*4882a593Smuzhiyun 
1564*4882a593Smuzhiyun /* Handle a call to read firmware. */
esas2r_read_fw(struct esas2r_adapter * a,char * buf,long off,int count)1565*4882a593Smuzhiyun int esas2r_read_fw(struct esas2r_adapter *a, char *buf, long off, int count)
1566*4882a593Smuzhiyun {
1567*4882a593Smuzhiyun 	esas2r_trace_enter();
1568*4882a593Smuzhiyun 	/* if the cached header is a status, simply copy it over and return. */
1569*4882a593Smuzhiyun 	if (a->firmware.state == FW_STATUS_ST) {
1570*4882a593Smuzhiyun 		int size = min_t(int, count, sizeof(a->firmware.header));
1571*4882a593Smuzhiyun 		esas2r_trace_exit();
1572*4882a593Smuzhiyun 		memcpy(buf, &a->firmware.header, size);
1573*4882a593Smuzhiyun 		esas2r_debug("esas2r_read_fw: STATUS size %d", size);
1574*4882a593Smuzhiyun 		return size;
1575*4882a593Smuzhiyun 	}
1576*4882a593Smuzhiyun 
1577*4882a593Smuzhiyun 	/*
1578*4882a593Smuzhiyun 	 * if the cached header is a command, do it if at
1579*4882a593Smuzhiyun 	 * offset 0, otherwise copy the pieces.
1580*4882a593Smuzhiyun 	 */
1581*4882a593Smuzhiyun 
1582*4882a593Smuzhiyun 	if (a->firmware.state == FW_COMMAND_ST) {
1583*4882a593Smuzhiyun 		u32 length = a->firmware.header.length;
1584*4882a593Smuzhiyun 		esas2r_trace_exit();
1585*4882a593Smuzhiyun 
1586*4882a593Smuzhiyun 		esas2r_debug("esas2r_read_fw: COMMAND length %d off %d",
1587*4882a593Smuzhiyun 			     length,
1588*4882a593Smuzhiyun 			     off);
1589*4882a593Smuzhiyun 
1590*4882a593Smuzhiyun 		if (off == 0) {
1591*4882a593Smuzhiyun 			if (a->firmware.header.action == FI_ACT_UP) {
1592*4882a593Smuzhiyun 				if (!allocate_fw_buffers(a, length))
1593*4882a593Smuzhiyun 					return -ENOMEM;
1594*4882a593Smuzhiyun 
1595*4882a593Smuzhiyun 
1596*4882a593Smuzhiyun 				/* copy header over */
1597*4882a593Smuzhiyun 
1598*4882a593Smuzhiyun 				memcpy(a->firmware.data,
1599*4882a593Smuzhiyun 				       &a->firmware.header,
1600*4882a593Smuzhiyun 				       sizeof(a->firmware.header));
1601*4882a593Smuzhiyun 
1602*4882a593Smuzhiyun 				do_fm_api(a,
1603*4882a593Smuzhiyun 					  (struct esas2r_flash_img *)a->firmware.data);
1604*4882a593Smuzhiyun 			} else if (a->firmware.header.action == FI_ACT_UPSZ) {
1605*4882a593Smuzhiyun 				int size =
1606*4882a593Smuzhiyun 					min((int)count,
1607*4882a593Smuzhiyun 					    (int)sizeof(a->firmware.header));
1608*4882a593Smuzhiyun 				do_fm_api(a, &a->firmware.header);
1609*4882a593Smuzhiyun 				memcpy(buf, &a->firmware.header, size);
1610*4882a593Smuzhiyun 				esas2r_debug("FI_ACT_UPSZ size %d", size);
1611*4882a593Smuzhiyun 				return size;
1612*4882a593Smuzhiyun 			} else {
1613*4882a593Smuzhiyun 				esas2r_debug("invalid action %d",
1614*4882a593Smuzhiyun 					     a->firmware.header.action);
1615*4882a593Smuzhiyun 				return -ENOSYS;
1616*4882a593Smuzhiyun 			}
1617*4882a593Smuzhiyun 		}
1618*4882a593Smuzhiyun 
1619*4882a593Smuzhiyun 		if (count + off > length)
1620*4882a593Smuzhiyun 			count = length - off;
1621*4882a593Smuzhiyun 
1622*4882a593Smuzhiyun 		if (count < 0)
1623*4882a593Smuzhiyun 			return 0;
1624*4882a593Smuzhiyun 
1625*4882a593Smuzhiyun 		if (!a->firmware.data) {
1626*4882a593Smuzhiyun 			esas2r_debug(
1627*4882a593Smuzhiyun 				"read: nonzero offset but no buffer available!");
1628*4882a593Smuzhiyun 			return -ENOMEM;
1629*4882a593Smuzhiyun 		}
1630*4882a593Smuzhiyun 
1631*4882a593Smuzhiyun 		esas2r_debug("esas2r_read_fw: off %d count %d length %d ", off,
1632*4882a593Smuzhiyun 			     count,
1633*4882a593Smuzhiyun 			     length);
1634*4882a593Smuzhiyun 
1635*4882a593Smuzhiyun 		memcpy(buf, &a->firmware.data[off], count);
1636*4882a593Smuzhiyun 
1637*4882a593Smuzhiyun 		/* when done, release the buffer */
1638*4882a593Smuzhiyun 
1639*4882a593Smuzhiyun 		if (length <= off + count) {
1640*4882a593Smuzhiyun 			esas2r_debug("esas2r_read_fw: freeing buffer!");
1641*4882a593Smuzhiyun 
1642*4882a593Smuzhiyun 			free_fw_buffers(a);
1643*4882a593Smuzhiyun 		}
1644*4882a593Smuzhiyun 
1645*4882a593Smuzhiyun 		return count;
1646*4882a593Smuzhiyun 	}
1647*4882a593Smuzhiyun 
1648*4882a593Smuzhiyun 	esas2r_trace_exit();
1649*4882a593Smuzhiyun 	esas2r_debug("esas2r_read_fw: invalid firmware state %d",
1650*4882a593Smuzhiyun 		     a->firmware.state);
1651*4882a593Smuzhiyun 
1652*4882a593Smuzhiyun 	return -EINVAL;
1653*4882a593Smuzhiyun }
1654*4882a593Smuzhiyun 
1655*4882a593Smuzhiyun /* Handle a call to write firmware. */
esas2r_write_fw(struct esas2r_adapter * a,const char * buf,long off,int count)1656*4882a593Smuzhiyun int esas2r_write_fw(struct esas2r_adapter *a, const char *buf, long off,
1657*4882a593Smuzhiyun 		    int count)
1658*4882a593Smuzhiyun {
1659*4882a593Smuzhiyun 	u32 length;
1660*4882a593Smuzhiyun 
1661*4882a593Smuzhiyun 	if (off == 0) {
1662*4882a593Smuzhiyun 		struct esas2r_flash_img *header =
1663*4882a593Smuzhiyun 			(struct esas2r_flash_img *)buf;
1664*4882a593Smuzhiyun 
1665*4882a593Smuzhiyun 		/* assume version 0 flash image */
1666*4882a593Smuzhiyun 
1667*4882a593Smuzhiyun 		int min_size = sizeof(struct esas2r_flash_img_v0);
1668*4882a593Smuzhiyun 
1669*4882a593Smuzhiyun 		a->firmware.state = FW_INVALID_ST;
1670*4882a593Smuzhiyun 
1671*4882a593Smuzhiyun 		/* validate the version field first */
1672*4882a593Smuzhiyun 
1673*4882a593Smuzhiyun 		if (count < 4
1674*4882a593Smuzhiyun 		    ||  header->fi_version > FI_VERSION_1) {
1675*4882a593Smuzhiyun 			esas2r_debug(
1676*4882a593Smuzhiyun 				"esas2r_write_fw: short header or invalid version");
1677*4882a593Smuzhiyun 			return -EINVAL;
1678*4882a593Smuzhiyun 		}
1679*4882a593Smuzhiyun 
1680*4882a593Smuzhiyun 		/* See if its a version 1 flash image */
1681*4882a593Smuzhiyun 
1682*4882a593Smuzhiyun 		if (header->fi_version == FI_VERSION_1)
1683*4882a593Smuzhiyun 			min_size = sizeof(struct esas2r_flash_img);
1684*4882a593Smuzhiyun 
1685*4882a593Smuzhiyun 		/* If this is the start, the header must be full and valid. */
1686*4882a593Smuzhiyun 		if (count < min_size) {
1687*4882a593Smuzhiyun 			esas2r_debug("esas2r_write_fw: short header, aborting");
1688*4882a593Smuzhiyun 			return -EINVAL;
1689*4882a593Smuzhiyun 		}
1690*4882a593Smuzhiyun 
1691*4882a593Smuzhiyun 		/* Make sure the size is reasonable. */
1692*4882a593Smuzhiyun 		length = header->length;
1693*4882a593Smuzhiyun 
1694*4882a593Smuzhiyun 		if (length > 1024 * 1024) {
1695*4882a593Smuzhiyun 			esas2r_debug(
1696*4882a593Smuzhiyun 				"esas2r_write_fw: hosed, length %d  fi_version %d",
1697*4882a593Smuzhiyun 				length, header->fi_version);
1698*4882a593Smuzhiyun 			return -EINVAL;
1699*4882a593Smuzhiyun 		}
1700*4882a593Smuzhiyun 
1701*4882a593Smuzhiyun 		/*
1702*4882a593Smuzhiyun 		 * If this is a write command, allocate memory because
1703*4882a593Smuzhiyun 		 * we have to cache everything. otherwise, just cache
1704*4882a593Smuzhiyun 		 * the header, because the read op will do the command.
1705*4882a593Smuzhiyun 		 */
1706*4882a593Smuzhiyun 
1707*4882a593Smuzhiyun 		if (header->action == FI_ACT_DOWN) {
1708*4882a593Smuzhiyun 			if (!allocate_fw_buffers(a, length))
1709*4882a593Smuzhiyun 				return -ENOMEM;
1710*4882a593Smuzhiyun 
1711*4882a593Smuzhiyun 			/*
1712*4882a593Smuzhiyun 			 * Store the command, so there is context on subsequent
1713*4882a593Smuzhiyun 			 * calls.
1714*4882a593Smuzhiyun 			 */
1715*4882a593Smuzhiyun 			memcpy(&a->firmware.header,
1716*4882a593Smuzhiyun 			       buf,
1717*4882a593Smuzhiyun 			       sizeof(*header));
1718*4882a593Smuzhiyun 		} else if (header->action == FI_ACT_UP
1719*4882a593Smuzhiyun 			   ||  header->action == FI_ACT_UPSZ) {
1720*4882a593Smuzhiyun 			/* Save the command, result will be picked up on read */
1721*4882a593Smuzhiyun 			memcpy(&a->firmware.header,
1722*4882a593Smuzhiyun 			       buf,
1723*4882a593Smuzhiyun 			       sizeof(*header));
1724*4882a593Smuzhiyun 
1725*4882a593Smuzhiyun 			a->firmware.state = FW_COMMAND_ST;
1726*4882a593Smuzhiyun 
1727*4882a593Smuzhiyun 			esas2r_debug(
1728*4882a593Smuzhiyun 				"esas2r_write_fw: COMMAND, count %d, action %d ",
1729*4882a593Smuzhiyun 				count, header->action);
1730*4882a593Smuzhiyun 
1731*4882a593Smuzhiyun 			/*
1732*4882a593Smuzhiyun 			 * Pretend we took the whole buffer,
1733*4882a593Smuzhiyun 			 * so we don't get bothered again.
1734*4882a593Smuzhiyun 			 */
1735*4882a593Smuzhiyun 
1736*4882a593Smuzhiyun 			return count;
1737*4882a593Smuzhiyun 		} else {
1738*4882a593Smuzhiyun 			esas2r_debug("esas2r_write_fw: invalid action %d ",
1739*4882a593Smuzhiyun 				     a->firmware.header.action);
1740*4882a593Smuzhiyun 			return -ENOSYS;
1741*4882a593Smuzhiyun 		}
1742*4882a593Smuzhiyun 	} else {
1743*4882a593Smuzhiyun 		length = a->firmware.header.length;
1744*4882a593Smuzhiyun 	}
1745*4882a593Smuzhiyun 
1746*4882a593Smuzhiyun 	/*
1747*4882a593Smuzhiyun 	 * We only get here on a download command, regardless of offset.
1748*4882a593Smuzhiyun 	 * the chunks written by the system need to be cached, and when
1749*4882a593Smuzhiyun 	 * the final one arrives, issue the fmapi command.
1750*4882a593Smuzhiyun 	 */
1751*4882a593Smuzhiyun 
1752*4882a593Smuzhiyun 	if (off + count > length)
1753*4882a593Smuzhiyun 		count = length - off;
1754*4882a593Smuzhiyun 
1755*4882a593Smuzhiyun 	if (count > 0) {
1756*4882a593Smuzhiyun 		esas2r_debug("esas2r_write_fw: off %d count %d length %d", off,
1757*4882a593Smuzhiyun 			     count,
1758*4882a593Smuzhiyun 			     length);
1759*4882a593Smuzhiyun 
1760*4882a593Smuzhiyun 		/*
1761*4882a593Smuzhiyun 		 * On a full upload, the system tries sending the whole buffer.
1762*4882a593Smuzhiyun 		 * there's nothing to do with it, so just drop it here, before
1763*4882a593Smuzhiyun 		 * trying to copy over into unallocated memory!
1764*4882a593Smuzhiyun 		 */
1765*4882a593Smuzhiyun 		if (a->firmware.header.action == FI_ACT_UP)
1766*4882a593Smuzhiyun 			return count;
1767*4882a593Smuzhiyun 
1768*4882a593Smuzhiyun 		if (!a->firmware.data) {
1769*4882a593Smuzhiyun 			esas2r_debug(
1770*4882a593Smuzhiyun 				"write: nonzero offset but no buffer available!");
1771*4882a593Smuzhiyun 			return -ENOMEM;
1772*4882a593Smuzhiyun 		}
1773*4882a593Smuzhiyun 
1774*4882a593Smuzhiyun 		memcpy(&a->firmware.data[off], buf, count);
1775*4882a593Smuzhiyun 
1776*4882a593Smuzhiyun 		if (length == off + count) {
1777*4882a593Smuzhiyun 			do_fm_api(a,
1778*4882a593Smuzhiyun 				  (struct esas2r_flash_img *)a->firmware.data);
1779*4882a593Smuzhiyun 
1780*4882a593Smuzhiyun 			/*
1781*4882a593Smuzhiyun 			 * Now copy the header result to be picked up by the
1782*4882a593Smuzhiyun 			 * next read
1783*4882a593Smuzhiyun 			 */
1784*4882a593Smuzhiyun 			memcpy(&a->firmware.header,
1785*4882a593Smuzhiyun 			       a->firmware.data,
1786*4882a593Smuzhiyun 			       sizeof(a->firmware.header));
1787*4882a593Smuzhiyun 
1788*4882a593Smuzhiyun 			a->firmware.state = FW_STATUS_ST;
1789*4882a593Smuzhiyun 
1790*4882a593Smuzhiyun 			esas2r_debug("write completed");
1791*4882a593Smuzhiyun 
1792*4882a593Smuzhiyun 			/*
1793*4882a593Smuzhiyun 			 * Since the system has the data buffered, the only way
1794*4882a593Smuzhiyun 			 * this can leak is if a root user writes a program
1795*4882a593Smuzhiyun 			 * that writes a shorter buffer than it claims, and the
1796*4882a593Smuzhiyun 			 * copyin fails.
1797*4882a593Smuzhiyun 			 */
1798*4882a593Smuzhiyun 			free_fw_buffers(a);
1799*4882a593Smuzhiyun 		}
1800*4882a593Smuzhiyun 	}
1801*4882a593Smuzhiyun 
1802*4882a593Smuzhiyun 	return count;
1803*4882a593Smuzhiyun }
1804*4882a593Smuzhiyun 
1805*4882a593Smuzhiyun /* Callback for the completion of a VDA request. */
vda_complete_req(struct esas2r_adapter * a,struct esas2r_request * rq)1806*4882a593Smuzhiyun static void vda_complete_req(struct esas2r_adapter *a,
1807*4882a593Smuzhiyun 			     struct esas2r_request *rq)
1808*4882a593Smuzhiyun {
1809*4882a593Smuzhiyun 	a->vda_command_done = 1;
1810*4882a593Smuzhiyun 	wake_up_interruptible(&a->vda_waiter);
1811*4882a593Smuzhiyun }
1812*4882a593Smuzhiyun 
1813*4882a593Smuzhiyun /* Scatter/gather callback for VDA requests */
get_physaddr_vda(struct esas2r_sg_context * sgc,u64 * addr)1814*4882a593Smuzhiyun static u32 get_physaddr_vda(struct esas2r_sg_context *sgc, u64 *addr)
1815*4882a593Smuzhiyun {
1816*4882a593Smuzhiyun 	struct esas2r_adapter *a = (struct esas2r_adapter *)sgc->adapter;
1817*4882a593Smuzhiyun 	int offset = (u8 *)sgc->cur_offset - (u8 *)a->vda_buffer;
1818*4882a593Smuzhiyun 
1819*4882a593Smuzhiyun 	(*addr) = a->ppvda_buffer + offset;
1820*4882a593Smuzhiyun 	return VDA_MAX_BUFFER_SIZE - offset;
1821*4882a593Smuzhiyun }
1822*4882a593Smuzhiyun 
1823*4882a593Smuzhiyun /* Handle a call to read a VDA command. */
esas2r_read_vda(struct esas2r_adapter * a,char * buf,long off,int count)1824*4882a593Smuzhiyun int esas2r_read_vda(struct esas2r_adapter *a, char *buf, long off, int count)
1825*4882a593Smuzhiyun {
1826*4882a593Smuzhiyun 	if (!a->vda_buffer)
1827*4882a593Smuzhiyun 		return -ENOMEM;
1828*4882a593Smuzhiyun 
1829*4882a593Smuzhiyun 	if (off == 0) {
1830*4882a593Smuzhiyun 		struct esas2r_request *rq;
1831*4882a593Smuzhiyun 		struct atto_ioctl_vda *vi =
1832*4882a593Smuzhiyun 			(struct atto_ioctl_vda *)a->vda_buffer;
1833*4882a593Smuzhiyun 		struct esas2r_sg_context sgc;
1834*4882a593Smuzhiyun 		bool wait_for_completion;
1835*4882a593Smuzhiyun 
1836*4882a593Smuzhiyun 		/*
1837*4882a593Smuzhiyun 		 * Presumeably, someone has already written to the vda_buffer,
1838*4882a593Smuzhiyun 		 * and now they are reading the node the response, so now we
1839*4882a593Smuzhiyun 		 * will actually issue the request to the chip and reply.
1840*4882a593Smuzhiyun 		 */
1841*4882a593Smuzhiyun 
1842*4882a593Smuzhiyun 		/* allocate a request */
1843*4882a593Smuzhiyun 		rq = esas2r_alloc_request(a);
1844*4882a593Smuzhiyun 		if (rq == NULL) {
1845*4882a593Smuzhiyun 			esas2r_debug("esas2r_read_vda: out of requests");
1846*4882a593Smuzhiyun 			return -EBUSY;
1847*4882a593Smuzhiyun 		}
1848*4882a593Smuzhiyun 
1849*4882a593Smuzhiyun 		rq->comp_cb = vda_complete_req;
1850*4882a593Smuzhiyun 
1851*4882a593Smuzhiyun 		sgc.first_req = rq;
1852*4882a593Smuzhiyun 		sgc.adapter = a;
1853*4882a593Smuzhiyun 		sgc.cur_offset = a->vda_buffer + VDA_BUFFER_HEADER_SZ;
1854*4882a593Smuzhiyun 		sgc.get_phys_addr = (PGETPHYSADDR)get_physaddr_vda;
1855*4882a593Smuzhiyun 
1856*4882a593Smuzhiyun 		a->vda_command_done = 0;
1857*4882a593Smuzhiyun 
1858*4882a593Smuzhiyun 		wait_for_completion =
1859*4882a593Smuzhiyun 			esas2r_process_vda_ioctl(a, vi, rq, &sgc);
1860*4882a593Smuzhiyun 
1861*4882a593Smuzhiyun 		if (wait_for_completion) {
1862*4882a593Smuzhiyun 			/* now wait around for it to complete. */
1863*4882a593Smuzhiyun 
1864*4882a593Smuzhiyun 			while (!a->vda_command_done)
1865*4882a593Smuzhiyun 				wait_event_interruptible(a->vda_waiter,
1866*4882a593Smuzhiyun 							 a->vda_command_done);
1867*4882a593Smuzhiyun 		}
1868*4882a593Smuzhiyun 
1869*4882a593Smuzhiyun 		esas2r_free_request(a, (struct esas2r_request *)rq);
1870*4882a593Smuzhiyun 	}
1871*4882a593Smuzhiyun 
1872*4882a593Smuzhiyun 	if (off > VDA_MAX_BUFFER_SIZE)
1873*4882a593Smuzhiyun 		return 0;
1874*4882a593Smuzhiyun 
1875*4882a593Smuzhiyun 	if (count + off > VDA_MAX_BUFFER_SIZE)
1876*4882a593Smuzhiyun 		count = VDA_MAX_BUFFER_SIZE - off;
1877*4882a593Smuzhiyun 
1878*4882a593Smuzhiyun 	if (count < 0)
1879*4882a593Smuzhiyun 		return 0;
1880*4882a593Smuzhiyun 
1881*4882a593Smuzhiyun 	memcpy(buf, a->vda_buffer + off, count);
1882*4882a593Smuzhiyun 
1883*4882a593Smuzhiyun 	return count;
1884*4882a593Smuzhiyun }
1885*4882a593Smuzhiyun 
1886*4882a593Smuzhiyun /* Handle a call to write a VDA command. */
esas2r_write_vda(struct esas2r_adapter * a,const char * buf,long off,int count)1887*4882a593Smuzhiyun int esas2r_write_vda(struct esas2r_adapter *a, const char *buf, long off,
1888*4882a593Smuzhiyun 		     int count)
1889*4882a593Smuzhiyun {
1890*4882a593Smuzhiyun 	/*
1891*4882a593Smuzhiyun 	 * allocate memory for it, if not already done.  once allocated,
1892*4882a593Smuzhiyun 	 * we will keep it around until the driver is unloaded.
1893*4882a593Smuzhiyun 	 */
1894*4882a593Smuzhiyun 
1895*4882a593Smuzhiyun 	if (!a->vda_buffer) {
1896*4882a593Smuzhiyun 		dma_addr_t dma_addr;
1897*4882a593Smuzhiyun 		a->vda_buffer = dma_alloc_coherent(&a->pcid->dev,
1898*4882a593Smuzhiyun 						   (size_t)
1899*4882a593Smuzhiyun 						   VDA_MAX_BUFFER_SIZE,
1900*4882a593Smuzhiyun 						   &dma_addr,
1901*4882a593Smuzhiyun 						   GFP_KERNEL);
1902*4882a593Smuzhiyun 
1903*4882a593Smuzhiyun 		a->ppvda_buffer = dma_addr;
1904*4882a593Smuzhiyun 	}
1905*4882a593Smuzhiyun 
1906*4882a593Smuzhiyun 	if (!a->vda_buffer)
1907*4882a593Smuzhiyun 		return -ENOMEM;
1908*4882a593Smuzhiyun 
1909*4882a593Smuzhiyun 	if (off > VDA_MAX_BUFFER_SIZE)
1910*4882a593Smuzhiyun 		return 0;
1911*4882a593Smuzhiyun 
1912*4882a593Smuzhiyun 	if (count + off > VDA_MAX_BUFFER_SIZE)
1913*4882a593Smuzhiyun 		count = VDA_MAX_BUFFER_SIZE - off;
1914*4882a593Smuzhiyun 
1915*4882a593Smuzhiyun 	if (count < 1)
1916*4882a593Smuzhiyun 		return 0;
1917*4882a593Smuzhiyun 
1918*4882a593Smuzhiyun 	memcpy(a->vda_buffer + off, buf, count);
1919*4882a593Smuzhiyun 
1920*4882a593Smuzhiyun 	return count;
1921*4882a593Smuzhiyun }
1922*4882a593Smuzhiyun 
1923*4882a593Smuzhiyun /* Callback for the completion of an FS_API request.*/
fs_api_complete_req(struct esas2r_adapter * a,struct esas2r_request * rq)1924*4882a593Smuzhiyun static void fs_api_complete_req(struct esas2r_adapter *a,
1925*4882a593Smuzhiyun 				struct esas2r_request *rq)
1926*4882a593Smuzhiyun {
1927*4882a593Smuzhiyun 	a->fs_api_command_done = 1;
1928*4882a593Smuzhiyun 
1929*4882a593Smuzhiyun 	wake_up_interruptible(&a->fs_api_waiter);
1930*4882a593Smuzhiyun }
1931*4882a593Smuzhiyun 
1932*4882a593Smuzhiyun /* Scatter/gather callback for VDA requests */
get_physaddr_fs_api(struct esas2r_sg_context * sgc,u64 * addr)1933*4882a593Smuzhiyun static u32 get_physaddr_fs_api(struct esas2r_sg_context *sgc, u64 *addr)
1934*4882a593Smuzhiyun {
1935*4882a593Smuzhiyun 	struct esas2r_adapter *a = (struct esas2r_adapter *)sgc->adapter;
1936*4882a593Smuzhiyun 	struct esas2r_ioctl_fs *fs =
1937*4882a593Smuzhiyun 		(struct esas2r_ioctl_fs *)a->fs_api_buffer;
1938*4882a593Smuzhiyun 	u32 offset = (u8 *)sgc->cur_offset - (u8 *)fs;
1939*4882a593Smuzhiyun 
1940*4882a593Smuzhiyun 	(*addr) = a->ppfs_api_buffer + offset;
1941*4882a593Smuzhiyun 
1942*4882a593Smuzhiyun 	return a->fs_api_buffer_size - offset;
1943*4882a593Smuzhiyun }
1944*4882a593Smuzhiyun 
1945*4882a593Smuzhiyun /* Handle a call to read firmware via FS_API. */
esas2r_read_fs(struct esas2r_adapter * a,char * buf,long off,int count)1946*4882a593Smuzhiyun int esas2r_read_fs(struct esas2r_adapter *a, char *buf, long off, int count)
1947*4882a593Smuzhiyun {
1948*4882a593Smuzhiyun 	if (!a->fs_api_buffer)
1949*4882a593Smuzhiyun 		return -ENOMEM;
1950*4882a593Smuzhiyun 
1951*4882a593Smuzhiyun 	if (off == 0) {
1952*4882a593Smuzhiyun 		struct esas2r_request *rq;
1953*4882a593Smuzhiyun 		struct esas2r_sg_context sgc;
1954*4882a593Smuzhiyun 		struct esas2r_ioctl_fs *fs =
1955*4882a593Smuzhiyun 			(struct esas2r_ioctl_fs *)a->fs_api_buffer;
1956*4882a593Smuzhiyun 
1957*4882a593Smuzhiyun 		/* If another flash request is already in progress, return. */
1958*4882a593Smuzhiyun 		if (mutex_lock_interruptible(&a->fs_api_mutex)) {
1959*4882a593Smuzhiyun busy:
1960*4882a593Smuzhiyun 			fs->status = ATTO_STS_OUT_OF_RSRC;
1961*4882a593Smuzhiyun 			return -EBUSY;
1962*4882a593Smuzhiyun 		}
1963*4882a593Smuzhiyun 
1964*4882a593Smuzhiyun 		/*
1965*4882a593Smuzhiyun 		 * Presumeably, someone has already written to the
1966*4882a593Smuzhiyun 		 * fs_api_buffer, and now they are reading the node the
1967*4882a593Smuzhiyun 		 * response, so now we will actually issue the request to the
1968*4882a593Smuzhiyun 		 * chip and reply. Allocate a request
1969*4882a593Smuzhiyun 		 */
1970*4882a593Smuzhiyun 
1971*4882a593Smuzhiyun 		rq = esas2r_alloc_request(a);
1972*4882a593Smuzhiyun 		if (rq == NULL) {
1973*4882a593Smuzhiyun 			esas2r_debug("esas2r_read_fs: out of requests");
1974*4882a593Smuzhiyun 			mutex_unlock(&a->fs_api_mutex);
1975*4882a593Smuzhiyun 			goto busy;
1976*4882a593Smuzhiyun 		}
1977*4882a593Smuzhiyun 
1978*4882a593Smuzhiyun 		rq->comp_cb = fs_api_complete_req;
1979*4882a593Smuzhiyun 
1980*4882a593Smuzhiyun 		/* Set up the SGCONTEXT for to build the s/g table */
1981*4882a593Smuzhiyun 
1982*4882a593Smuzhiyun 		sgc.cur_offset = fs->data;
1983*4882a593Smuzhiyun 		sgc.get_phys_addr = (PGETPHYSADDR)get_physaddr_fs_api;
1984*4882a593Smuzhiyun 
1985*4882a593Smuzhiyun 		a->fs_api_command_done = 0;
1986*4882a593Smuzhiyun 
1987*4882a593Smuzhiyun 		if (!esas2r_process_fs_ioctl(a, fs, rq, &sgc)) {
1988*4882a593Smuzhiyun 			if (fs->status == ATTO_STS_OUT_OF_RSRC)
1989*4882a593Smuzhiyun 				count = -EBUSY;
1990*4882a593Smuzhiyun 
1991*4882a593Smuzhiyun 			goto dont_wait;
1992*4882a593Smuzhiyun 		}
1993*4882a593Smuzhiyun 
1994*4882a593Smuzhiyun 		/* Now wait around for it to complete. */
1995*4882a593Smuzhiyun 
1996*4882a593Smuzhiyun 		while (!a->fs_api_command_done)
1997*4882a593Smuzhiyun 			wait_event_interruptible(a->fs_api_waiter,
1998*4882a593Smuzhiyun 						 a->fs_api_command_done);
1999*4882a593Smuzhiyun 		;
2000*4882a593Smuzhiyun dont_wait:
2001*4882a593Smuzhiyun 		/* Free the request and keep going */
2002*4882a593Smuzhiyun 		mutex_unlock(&a->fs_api_mutex);
2003*4882a593Smuzhiyun 		esas2r_free_request(a, (struct esas2r_request *)rq);
2004*4882a593Smuzhiyun 
2005*4882a593Smuzhiyun 		/* Pick up possible error code from above */
2006*4882a593Smuzhiyun 		if (count < 0)
2007*4882a593Smuzhiyun 			return count;
2008*4882a593Smuzhiyun 	}
2009*4882a593Smuzhiyun 
2010*4882a593Smuzhiyun 	if (off > a->fs_api_buffer_size)
2011*4882a593Smuzhiyun 		return 0;
2012*4882a593Smuzhiyun 
2013*4882a593Smuzhiyun 	if (count + off > a->fs_api_buffer_size)
2014*4882a593Smuzhiyun 		count = a->fs_api_buffer_size - off;
2015*4882a593Smuzhiyun 
2016*4882a593Smuzhiyun 	if (count < 0)
2017*4882a593Smuzhiyun 		return 0;
2018*4882a593Smuzhiyun 
2019*4882a593Smuzhiyun 	memcpy(buf, a->fs_api_buffer + off, count);
2020*4882a593Smuzhiyun 
2021*4882a593Smuzhiyun 	return count;
2022*4882a593Smuzhiyun }
2023*4882a593Smuzhiyun 
2024*4882a593Smuzhiyun /* Handle a call to write firmware via FS_API. */
esas2r_write_fs(struct esas2r_adapter * a,const char * buf,long off,int count)2025*4882a593Smuzhiyun int esas2r_write_fs(struct esas2r_adapter *a, const char *buf, long off,
2026*4882a593Smuzhiyun 		    int count)
2027*4882a593Smuzhiyun {
2028*4882a593Smuzhiyun 	if (off == 0) {
2029*4882a593Smuzhiyun 		struct esas2r_ioctl_fs *fs = (struct esas2r_ioctl_fs *)buf;
2030*4882a593Smuzhiyun 		u32 length = fs->command.length + offsetof(
2031*4882a593Smuzhiyun 			struct esas2r_ioctl_fs,
2032*4882a593Smuzhiyun 			data);
2033*4882a593Smuzhiyun 
2034*4882a593Smuzhiyun 		/*
2035*4882a593Smuzhiyun 		 * Special case, for BEGIN commands, the length field
2036*4882a593Smuzhiyun 		 * is lying to us, so just get enough for the header.
2037*4882a593Smuzhiyun 		 */
2038*4882a593Smuzhiyun 
2039*4882a593Smuzhiyun 		if (fs->command.command == ESAS2R_FS_CMD_BEGINW)
2040*4882a593Smuzhiyun 			length = offsetof(struct esas2r_ioctl_fs, data);
2041*4882a593Smuzhiyun 
2042*4882a593Smuzhiyun 		/*
2043*4882a593Smuzhiyun 		 * Beginning a command.  We assume we'll get at least
2044*4882a593Smuzhiyun 		 * enough in the first write so we can look at the
2045*4882a593Smuzhiyun 		 * header and see how much we need to alloc.
2046*4882a593Smuzhiyun 		 */
2047*4882a593Smuzhiyun 
2048*4882a593Smuzhiyun 		if (count < offsetof(struct esas2r_ioctl_fs, data))
2049*4882a593Smuzhiyun 			return -EINVAL;
2050*4882a593Smuzhiyun 
2051*4882a593Smuzhiyun 		/* Allocate a buffer or use the existing buffer. */
2052*4882a593Smuzhiyun 		if (a->fs_api_buffer) {
2053*4882a593Smuzhiyun 			if (a->fs_api_buffer_size < length) {
2054*4882a593Smuzhiyun 				/* Free too-small buffer and get a new one */
2055*4882a593Smuzhiyun 				dma_free_coherent(&a->pcid->dev,
2056*4882a593Smuzhiyun 						  (size_t)a->fs_api_buffer_size,
2057*4882a593Smuzhiyun 						  a->fs_api_buffer,
2058*4882a593Smuzhiyun 						  (dma_addr_t)a->ppfs_api_buffer);
2059*4882a593Smuzhiyun 
2060*4882a593Smuzhiyun 				goto re_allocate_buffer;
2061*4882a593Smuzhiyun 			}
2062*4882a593Smuzhiyun 		} else {
2063*4882a593Smuzhiyun re_allocate_buffer:
2064*4882a593Smuzhiyun 			a->fs_api_buffer_size = length;
2065*4882a593Smuzhiyun 
2066*4882a593Smuzhiyun 			a->fs_api_buffer = dma_alloc_coherent(&a->pcid->dev,
2067*4882a593Smuzhiyun 							      (size_t)a->fs_api_buffer_size,
2068*4882a593Smuzhiyun 							      (dma_addr_t *)&a->ppfs_api_buffer,
2069*4882a593Smuzhiyun 							      GFP_KERNEL);
2070*4882a593Smuzhiyun 		}
2071*4882a593Smuzhiyun 	}
2072*4882a593Smuzhiyun 
2073*4882a593Smuzhiyun 	if (!a->fs_api_buffer)
2074*4882a593Smuzhiyun 		return -ENOMEM;
2075*4882a593Smuzhiyun 
2076*4882a593Smuzhiyun 	if (off > a->fs_api_buffer_size)
2077*4882a593Smuzhiyun 		return 0;
2078*4882a593Smuzhiyun 
2079*4882a593Smuzhiyun 	if (count + off > a->fs_api_buffer_size)
2080*4882a593Smuzhiyun 		count = a->fs_api_buffer_size - off;
2081*4882a593Smuzhiyun 
2082*4882a593Smuzhiyun 	if (count < 1)
2083*4882a593Smuzhiyun 		return 0;
2084*4882a593Smuzhiyun 
2085*4882a593Smuzhiyun 	memcpy(a->fs_api_buffer + off, buf, count);
2086*4882a593Smuzhiyun 
2087*4882a593Smuzhiyun 	return count;
2088*4882a593Smuzhiyun }
2089