xref: /freebsd-13.1/sys/cam/mmc/mmc_da.c (revision 6b3071c7)
1 /*-
2  * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
3  *
4  * Copyright (c) 2006 Bernd Walter <[email protected]> All rights reserved.
5  * Copyright (c) 2009 Alexander Motin <[email protected]> All rights reserved.
6  * Copyright (c) 2015-2017 Ilya Bakulin <[email protected]> All rights reserved.
7  * Copyright (c) 2006 M. Warner Losh <[email protected]>
8  *
9  * Redistribution and use in source and binary forms, with or without
10  * modification, are permitted provided that the following conditions
11  * are met:
12  * 1. Redistributions of source code must retain the above copyright
13  *    notice, this list of conditions and the following disclaimer,
14  *    without modification, immediately at the beginning of the file.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  *
19  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
20  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
21  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
22  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
23  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
24  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
25  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
26  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
27  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
28  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
29  *
30  * Some code derived from the sys/dev/mmc and sys/cam/ata
31  * Thanks to Warner Losh <[email protected]>, Alexander Motin <[email protected]>
32  * Bernd Walter <[email protected]>, and other authors.
33  */
34 
35 #include <sys/cdefs.h>
36 __FBSDID("$FreeBSD$");
37 
38 //#include "opt_sdda.h"
39 
40 #include <sys/param.h>
41 
42 #ifdef _KERNEL
43 #include <sys/systm.h>
44 #include <sys/kernel.h>
45 #include <sys/bio.h>
46 #include <sys/sysctl.h>
47 #include <sys/endian.h>
48 #include <sys/taskqueue.h>
49 #include <sys/lock.h>
50 #include <sys/mutex.h>
51 #include <sys/conf.h>
52 #include <sys/devicestat.h>
53 #include <sys/eventhandler.h>
54 #include <sys/malloc.h>
55 #include <sys/cons.h>
56 #include <sys/proc.h>
57 #include <sys/reboot.h>
58 #include <geom/geom_disk.h>
59 #include <machine/_inttypes.h>  /* for PRIu64 */
60 #endif /* _KERNEL */
61 
62 #ifndef _KERNEL
63 #include <stdio.h>
64 #include <string.h>
65 #endif /* _KERNEL */
66 
67 #include <cam/cam.h>
68 #include <cam/cam_ccb.h>
69 #include <cam/cam_queue.h>
70 #include <cam/cam_periph.h>
71 #include <cam/cam_sim.h>
72 #include <cam/cam_xpt.h>
73 #include <cam/cam_xpt_sim.h>
74 #include <cam/cam_xpt_periph.h>
75 #include <cam/cam_xpt_internal.h>
76 #include <cam/cam_debug.h>
77 
78 #include <cam/mmc/mmc_all.h>
79 
80 #ifdef _KERNEL
81 
82 typedef enum {
83 	SDDA_FLAG_OPEN		= 0x0002,
84 	SDDA_FLAG_DIRTY		= 0x0004
85 } sdda_flags;
86 
87 typedef enum {
88 	SDDA_STATE_INIT,
89 	SDDA_STATE_INVALID,
90 	SDDA_STATE_NORMAL,
91 	SDDA_STATE_PART_SWITCH,
92 } sdda_state;
93 
94 #define	SDDA_FMT_BOOT		"sdda%dboot"
95 #define	SDDA_FMT_GP		"sdda%dgp"
96 #define	SDDA_FMT_RPMB		"sdda%drpmb"
97 #define	SDDA_LABEL_ENH		"enh"
98 
99 #define	SDDA_PART_NAMELEN	(16 + 1)
100 
101 struct sdda_softc;
102 
103 struct sdda_part {
104 	struct disk *disk;
105 	struct bio_queue_head bio_queue;
106 	sdda_flags flags;
107 	struct sdda_softc *sc;
108 	u_int cnt;
109 	u_int type;
110 	bool ro;
111 	char name[SDDA_PART_NAMELEN];
112 };
113 
114 struct sdda_softc {
115 	int	 outstanding_cmds;	/* Number of active commands */
116 	int	 refcount;		/* Active xpt_action() calls */
117 	sdda_state state;
118 	struct mmc_data *mmcdata;
119 	struct cam_periph *periph;
120 //	sdda_quirks quirks;
121 	struct task start_init_task;
122 	uint32_t raw_csd[4];
123 	uint8_t raw_ext_csd[512]; /* MMC only? */
124 	struct mmc_csd csd;
125 	struct mmc_cid cid;
126 	struct mmc_scr scr;
127 	/* Calculated from CSD */
128 	uint64_t sector_count;
129 	uint64_t mediasize;
130 
131 	/* Calculated from CID */
132 	char card_id_string[64];/* Formatted CID info (serial, MFG, etc) */
133 	char card_sn_string[16];/* Formatted serial # for disk->d_ident */
134 	/* Determined from CSD + is highspeed card*/
135 	uint32_t card_f_max;
136 
137 	/* Generic switch timeout */
138 	uint32_t cmd6_time;
139 	uint32_t timings;	/* Mask of bus timings supported */
140 	uint32_t vccq_120;	/* Mask of bus timings at VCCQ of 1.2 V */
141 	uint32_t vccq_180;	/* Mask of bus timings at VCCQ of 1.8 V */
142 	/* MMC partitions support */
143 	struct sdda_part *part[MMC_PART_MAX];
144 	uint8_t part_curr;	/* Partition currently switched to */
145 	uint8_t part_requested; /* What partition we're currently switching to */
146 	uint32_t part_time;	/* Partition switch timeout [us] */
147 	off_t enh_base;		/* Enhanced user data area slice base ... */
148 	off_t enh_size;		/* ... and size [bytes] */
149 	int log_count;
150 	struct timeval log_time;
151 };
152 
153 static const char *mmc_errmsg[] =
154 {
155 	"None",
156 	"Timeout",
157 	"Bad CRC",
158 	"Fifo",
159 	"Failed",
160 	"Invalid",
161 	"NO MEMORY"
162 };
163 
164 #define ccb_bp		ppriv_ptr1
165 
166 static	disk_strategy_t	sddastrategy;
167 static	dumper_t	sddadump;
168 static	periph_init_t	sddainit;
169 static	void		sddaasync(void *callback_arg, u_int32_t code,
170 				struct cam_path *path, void *arg);
171 static	periph_ctor_t	sddaregister;
172 static	periph_dtor_t	sddacleanup;
173 static	periph_start_t	sddastart;
174 static	periph_oninv_t	sddaoninvalidate;
175 static	void		sddadone(struct cam_periph *periph,
176 			       union ccb *done_ccb);
177 static  int		sddaerror(union ccb *ccb, u_int32_t cam_flags,
178 				u_int32_t sense_flags);
179 
180 static int mmc_handle_reply(union ccb *ccb);
181 static uint16_t get_rca(struct cam_periph *periph);
182 static void sdda_start_init(void *context, union ccb *start_ccb);
183 static void sdda_start_init_task(void *context, int pending);
184 static void sdda_process_mmc_partitions(struct cam_periph *periph, union ccb *start_ccb);
185 static uint32_t sdda_get_host_caps(struct cam_periph *periph, union ccb *ccb);
186 static int mmc_select_card(struct cam_periph *periph, union ccb *ccb, uint32_t rca);
mmc_get_sector_size(struct cam_periph * periph)187 static inline uint32_t mmc_get_sector_size(struct cam_periph *periph) {return MMC_SECTOR_SIZE;}
188 
189 static SYSCTL_NODE(_kern_cam, OID_AUTO, sdda, CTLFLAG_RD | CTLFLAG_MPSAFE, 0,
190     "CAM Direct Access Disk driver");
191 
192 static int sdda_mmcsd_compat = 1;
193 SYSCTL_INT(_kern_cam_sdda, OID_AUTO, mmcsd_compat, CTLFLAG_RDTUN,
194     &sdda_mmcsd_compat, 1, "Enable creation of mmcsd aliases.");
195 
196 /* TODO: actually issue GET_TRAN_SETTINGS to get R/O status */
sdda_get_read_only(struct cam_periph * periph,union ccb * start_ccb)197 static inline bool sdda_get_read_only(struct cam_periph *periph, union ccb *start_ccb)
198 {
199 
200 	return (false);
201 }
202 
203 static uint32_t mmc_get_spec_vers(struct cam_periph *periph);
204 static uint64_t mmc_get_media_size(struct cam_periph *periph);
205 static uint32_t mmc_get_cmd6_timeout(struct cam_periph *periph);
206 static bool sdda_add_part(struct cam_periph *periph, u_int type,
207     const char *name, u_int cnt, off_t media_size, bool ro);
208 
209 static struct periph_driver sddadriver =
210 {
211 	sddainit, "sdda",
212 	TAILQ_HEAD_INITIALIZER(sddadriver.units), /* generation */ 0
213 };
214 
215 PERIPHDRIVER_DECLARE(sdda, sddadriver);
216 
217 static MALLOC_DEFINE(M_SDDA, "sd_da", "sd_da buffers");
218 
219 static const int exp[8] = {
220 	1, 10, 100, 1000, 10000, 100000, 1000000, 10000000
221 };
222 
223 static const int mant[16] = {
224 	0, 10, 12, 13, 15, 20, 25, 30, 35, 40, 45, 50, 55, 60, 70, 80
225 };
226 
227 static const int cur_min[8] = {
228 	500, 1000, 5000, 10000, 25000, 35000, 60000, 100000
229 };
230 
231 static const int cur_max[8] = {
232 	1000, 5000, 10000, 25000, 35000, 45000, 800000, 200000
233 };
234 
235 static uint16_t
get_rca(struct cam_periph * periph)236 get_rca(struct cam_periph *periph) {
237 	return periph->path->device->mmc_ident_data.card_rca;
238 }
239 
240 /*
241  * Figure out if CCB execution resulted in error.
242  * Look at both CAM-level errors and on MMC protocol errors.
243  *
244  * Return value is always MMC error.
245 */
246 static int
mmc_handle_reply(union ccb * ccb)247 mmc_handle_reply(union ccb *ccb)
248 {
249 	KASSERT(ccb->ccb_h.func_code == XPT_MMC_IO,
250 	    ("ccb %p: cannot handle non-XPT_MMC_IO errors, got func_code=%d",
251 		ccb, ccb->ccb_h.func_code));
252 
253 	/* CAM-level error should always correspond to MMC-level error */
254 	if (((ccb->ccb_h.status & CAM_STATUS_MASK) == CAM_REQ_CMP) &&
255 	  (ccb->mmcio.cmd.error != MMC_ERR_NONE))
256 		panic("CCB status is OK but MMC error != MMC_ERR_NONE");
257 
258 	if (ccb->mmcio.cmd.error != MMC_ERR_NONE) {
259 		xpt_print_path(ccb->ccb_h.path);
260 		printf("CMD%d failed, err %d (%s)\n",
261 		  ccb->mmcio.cmd.opcode,
262 		  ccb->mmcio.cmd.error,
263 		  mmc_errmsg[ccb->mmcio.cmd.error]);
264 	}
265 	return (ccb->mmcio.cmd.error);
266 }
267 
268 static uint32_t
mmc_get_bits(uint32_t * bits,int bit_len,int start,int size)269 mmc_get_bits(uint32_t *bits, int bit_len, int start, int size)
270 {
271 	const int i = (bit_len / 32) - (start / 32) - 1;
272 	const int shift = start & 31;
273 	uint32_t retval = bits[i] >> shift;
274 	if (size + shift > 32)
275 		retval |= bits[i - 1] << (32 - shift);
276 	return (retval & ((1llu << size) - 1));
277 }
278 
279 static void
mmc_decode_csd_sd(uint32_t * raw_csd,struct mmc_csd * csd)280 mmc_decode_csd_sd(uint32_t *raw_csd, struct mmc_csd *csd)
281 {
282 	int v;
283 	int m;
284 	int e;
285 
286 	memset(csd, 0, sizeof(*csd));
287 	csd->csd_structure = v = mmc_get_bits(raw_csd, 128, 126, 2);
288 
289 	/* Common members between 1.0 and 2.0 */
290 	m = mmc_get_bits(raw_csd, 128, 115, 4);
291 	e = mmc_get_bits(raw_csd, 128, 112, 3);
292 	csd->tacc = (exp[e] * mant[m] + 9) / 10;
293 	csd->nsac = mmc_get_bits(raw_csd, 128, 104, 8) * 100;
294 	m = mmc_get_bits(raw_csd, 128, 99, 4);
295 	e = mmc_get_bits(raw_csd, 128, 96, 3);
296 	csd->tran_speed = exp[e] * 10000 * mant[m];
297 	csd->ccc = mmc_get_bits(raw_csd, 128, 84, 12);
298 	csd->read_bl_len = 1 << mmc_get_bits(raw_csd, 128, 80, 4);
299 	csd->read_bl_partial = mmc_get_bits(raw_csd, 128, 79, 1);
300 	csd->write_blk_misalign = mmc_get_bits(raw_csd, 128, 78, 1);
301 	csd->read_blk_misalign = mmc_get_bits(raw_csd, 128, 77, 1);
302 	csd->dsr_imp = mmc_get_bits(raw_csd, 128, 76, 1);
303 	csd->erase_blk_en = mmc_get_bits(raw_csd, 128, 46, 1);
304 	csd->erase_sector = mmc_get_bits(raw_csd, 128, 39, 7) + 1;
305 	csd->wp_grp_size = mmc_get_bits(raw_csd, 128, 32, 7);
306 	csd->wp_grp_enable = mmc_get_bits(raw_csd, 128, 31, 1);
307 	csd->r2w_factor = 1 << mmc_get_bits(raw_csd, 128, 26, 3);
308 	csd->write_bl_len = 1 << mmc_get_bits(raw_csd, 128, 22, 4);
309 	csd->write_bl_partial = mmc_get_bits(raw_csd, 128, 21, 1);
310 
311 	if (v == 0) {
312 		csd->vdd_r_curr_min = cur_min[mmc_get_bits(raw_csd, 128, 59, 3)];
313 		csd->vdd_r_curr_max = cur_max[mmc_get_bits(raw_csd, 128, 56, 3)];
314 		csd->vdd_w_curr_min = cur_min[mmc_get_bits(raw_csd, 128, 53, 3)];
315 		csd->vdd_w_curr_max = cur_max[mmc_get_bits(raw_csd, 128, 50, 3)];
316 		m = mmc_get_bits(raw_csd, 128, 62, 12);
317 		e = mmc_get_bits(raw_csd, 128, 47, 3);
318 		csd->capacity = ((1 + m) << (e + 2)) * csd->read_bl_len;
319 	} else if (v == 1) {
320 		csd->capacity = ((uint64_t)mmc_get_bits(raw_csd, 128, 48, 22) + 1) *
321 		    512 * 1024;
322 	} else
323 		panic("unknown SD CSD version");
324 }
325 
326 static void
mmc_decode_csd_mmc(uint32_t * raw_csd,struct mmc_csd * csd)327 mmc_decode_csd_mmc(uint32_t *raw_csd, struct mmc_csd *csd)
328 {
329 	int m;
330 	int e;
331 
332 	memset(csd, 0, sizeof(*csd));
333 	csd->csd_structure = mmc_get_bits(raw_csd, 128, 126, 2);
334 	csd->spec_vers = mmc_get_bits(raw_csd, 128, 122, 4);
335 	m = mmc_get_bits(raw_csd, 128, 115, 4);
336 	e = mmc_get_bits(raw_csd, 128, 112, 3);
337 	csd->tacc = exp[e] * mant[m] + 9 / 10;
338 	csd->nsac = mmc_get_bits(raw_csd, 128, 104, 8) * 100;
339 	m = mmc_get_bits(raw_csd, 128, 99, 4);
340 	e = mmc_get_bits(raw_csd, 128, 96, 3);
341 	csd->tran_speed = exp[e] * 10000 * mant[m];
342 	csd->ccc = mmc_get_bits(raw_csd, 128, 84, 12);
343 	csd->read_bl_len = 1 << mmc_get_bits(raw_csd, 128, 80, 4);
344 	csd->read_bl_partial = mmc_get_bits(raw_csd, 128, 79, 1);
345 	csd->write_blk_misalign = mmc_get_bits(raw_csd, 128, 78, 1);
346 	csd->read_blk_misalign = mmc_get_bits(raw_csd, 128, 77, 1);
347 	csd->dsr_imp = mmc_get_bits(raw_csd, 128, 76, 1);
348 	csd->vdd_r_curr_min = cur_min[mmc_get_bits(raw_csd, 128, 59, 3)];
349 	csd->vdd_r_curr_max = cur_max[mmc_get_bits(raw_csd, 128, 56, 3)];
350 	csd->vdd_w_curr_min = cur_min[mmc_get_bits(raw_csd, 128, 53, 3)];
351 	csd->vdd_w_curr_max = cur_max[mmc_get_bits(raw_csd, 128, 50, 3)];
352 	m = mmc_get_bits(raw_csd, 128, 62, 12);
353 	e = mmc_get_bits(raw_csd, 128, 47, 3);
354 	csd->capacity = ((1 + m) << (e + 2)) * csd->read_bl_len;
355 	csd->erase_blk_en = 0;
356 	csd->erase_sector = (mmc_get_bits(raw_csd, 128, 42, 5) + 1) *
357 	    (mmc_get_bits(raw_csd, 128, 37, 5) + 1);
358 	csd->wp_grp_size = mmc_get_bits(raw_csd, 128, 32, 5);
359 	csd->wp_grp_enable = mmc_get_bits(raw_csd, 128, 31, 1);
360 	csd->r2w_factor = 1 << mmc_get_bits(raw_csd, 128, 26, 3);
361 	csd->write_bl_len = 1 << mmc_get_bits(raw_csd, 128, 22, 4);
362 	csd->write_bl_partial = mmc_get_bits(raw_csd, 128, 21, 1);
363 }
364 
365 static void
mmc_decode_cid_sd(uint32_t * raw_cid,struct mmc_cid * cid)366 mmc_decode_cid_sd(uint32_t *raw_cid, struct mmc_cid *cid)
367 {
368 	int i;
369 
370 	/* There's no version info, so we take it on faith */
371 	memset(cid, 0, sizeof(*cid));
372 	cid->mid = mmc_get_bits(raw_cid, 128, 120, 8);
373 	cid->oid = mmc_get_bits(raw_cid, 128, 104, 16);
374 	for (i = 0; i < 5; i++)
375 		cid->pnm[i] = mmc_get_bits(raw_cid, 128, 96 - i * 8, 8);
376 	cid->pnm[5] = 0;
377 	cid->prv = mmc_get_bits(raw_cid, 128, 56, 8);
378 	cid->psn = mmc_get_bits(raw_cid, 128, 24, 32);
379 	cid->mdt_year = mmc_get_bits(raw_cid, 128, 12, 8) + 2000;
380 	cid->mdt_month = mmc_get_bits(raw_cid, 128, 8, 4);
381 }
382 
383 static void
mmc_decode_cid_mmc(uint32_t * raw_cid,struct mmc_cid * cid)384 mmc_decode_cid_mmc(uint32_t *raw_cid, struct mmc_cid *cid)
385 {
386 	int i;
387 
388 	/* There's no version info, so we take it on faith */
389 	memset(cid, 0, sizeof(*cid));
390 	cid->mid = mmc_get_bits(raw_cid, 128, 120, 8);
391 	cid->oid = mmc_get_bits(raw_cid, 128, 104, 8);
392 	for (i = 0; i < 6; i++)
393 		cid->pnm[i] = mmc_get_bits(raw_cid, 128, 96 - i * 8, 8);
394 	cid->pnm[6] = 0;
395 	cid->prv = mmc_get_bits(raw_cid, 128, 48, 8);
396 	cid->psn = mmc_get_bits(raw_cid, 128, 16, 32);
397 	cid->mdt_month = mmc_get_bits(raw_cid, 128, 12, 4);
398 	cid->mdt_year = mmc_get_bits(raw_cid, 128, 8, 4) + 1997;
399 }
400 
401 static void
mmc_format_card_id_string(struct sdda_softc * sc,struct mmc_params * mmcp)402 mmc_format_card_id_string(struct sdda_softc *sc, struct mmc_params *mmcp)
403 {
404 	char oidstr[8];
405 	uint8_t c1;
406 	uint8_t c2;
407 
408 	/*
409 	 * Format a card ID string for use by the mmcsd driver, it's what
410 	 * appears between the <> in the following:
411 	 * mmcsd0: 968MB <SD SD01G 8.0 SN 2686905 Mfg 08/2008 by 3 TN> at mmc0
412 	 * 22.5MHz/4bit/128-block
413 	 *
414 	 * Also format just the card serial number, which the mmcsd driver will
415 	 * use as the disk->d_ident string.
416 	 *
417 	 * The card_id_string in mmc_ivars is currently allocated as 64 bytes,
418 	 * and our max formatted length is currently 55 bytes if every field
419 	 * contains the largest value.
420 	 *
421 	 * Sometimes the oid is two printable ascii chars; when it's not,
422 	 * format it as 0xnnnn instead.
423 	 */
424 	c1 = (sc->cid.oid >> 8) & 0x0ff;
425 	c2 = sc->cid.oid & 0x0ff;
426 	if (c1 > 0x1f && c1 < 0x7f && c2 > 0x1f && c2 < 0x7f)
427 		snprintf(oidstr, sizeof(oidstr), "%c%c", c1, c2);
428 	else
429 		snprintf(oidstr, sizeof(oidstr), "0x%04x", sc->cid.oid);
430 	snprintf(sc->card_sn_string, sizeof(sc->card_sn_string),
431 	    "%08X", sc->cid.psn);
432 	snprintf(sc->card_id_string, sizeof(sc->card_id_string),
433 		 "%s%s %s %d.%d SN %08X MFG %02d/%04d by %d %s",
434 		 mmcp->card_features & CARD_FEATURE_MMC ? "MMC" : "SD",
435 		 mmcp->card_features & CARD_FEATURE_SDHC ? "HC" : "",
436 		 sc->cid.pnm, sc->cid.prv >> 4, sc->cid.prv & 0x0f,
437 		 sc->cid.psn, sc->cid.mdt_month, sc->cid.mdt_year,
438 		 sc->cid.mid, oidstr);
439 }
440 
441 static int
sddaopen(struct disk * dp)442 sddaopen(struct disk *dp)
443 {
444 	struct sdda_part *part;
445 	struct cam_periph *periph;
446 	struct sdda_softc *softc;
447 	int error;
448 
449 	part = (struct sdda_part *)dp->d_drv1;
450 	softc = part->sc;
451 	periph = softc->periph;
452 	if (cam_periph_acquire(periph) != 0) {
453 		return(ENXIO);
454 	}
455 
456 	cam_periph_lock(periph);
457 	if ((error = cam_periph_hold(periph, PRIBIO|PCATCH)) != 0) {
458 		cam_periph_unlock(periph);
459 		cam_periph_release(periph);
460 		return (error);
461 	}
462 
463 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sddaopen\n"));
464 
465 	part->flags |= SDDA_FLAG_OPEN;
466 
467 	cam_periph_unhold(periph);
468 	cam_periph_unlock(periph);
469 	return (0);
470 }
471 
472 static int
sddaclose(struct disk * dp)473 sddaclose(struct disk *dp)
474 {
475 	struct sdda_part *part;
476 	struct	cam_periph *periph;
477 	struct	sdda_softc *softc;
478 
479 	part = (struct sdda_part *)dp->d_drv1;
480 	softc = part->sc;
481 	periph = softc->periph;
482 	part->flags &= ~SDDA_FLAG_OPEN;
483 
484 	cam_periph_lock(periph);
485 
486 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sddaclose\n"));
487 
488 	while (softc->refcount != 0)
489 		cam_periph_sleep(periph, &softc->refcount, PRIBIO, "sddaclose", 1);
490 	cam_periph_unlock(periph);
491 	cam_periph_release(periph);
492 	return (0);
493 }
494 
495 static void
sddaschedule(struct cam_periph * periph)496 sddaschedule(struct cam_periph *periph)
497 {
498 	struct sdda_softc *softc = (struct sdda_softc *)periph->softc;
499 	struct sdda_part *part;
500 	struct bio *bp;
501 	int i;
502 
503 	/* Check if we have more work to do. */
504 	/* Find partition that has outstanding commands. Prefer current partition. */
505 	bp = bioq_first(&softc->part[softc->part_curr]->bio_queue);
506 	if (bp == NULL) {
507 		for (i = 0; i < MMC_PART_MAX; i++) {
508 			if ((part = softc->part[i]) != NULL &&
509 			    (bp = bioq_first(&softc->part[i]->bio_queue)) != NULL)
510 				break;
511 		}
512 	}
513 	if (bp != NULL) {
514 		xpt_schedule(periph, CAM_PRIORITY_NORMAL);
515 	}
516 }
517 
518 /*
519  * Actually translate the requested transfer into one the physical driver
520  * can understand.  The transfer is described by a buf and will include
521  * only one physical transfer.
522  */
523 static void
sddastrategy(struct bio * bp)524 sddastrategy(struct bio *bp)
525 {
526 	struct cam_periph *periph;
527 	struct sdda_part *part;
528 	struct sdda_softc *softc;
529 
530 	part = (struct sdda_part *)bp->bio_disk->d_drv1;
531 	softc = part->sc;
532 	periph = softc->periph;
533 
534 	cam_periph_lock(periph);
535 
536 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sddastrategy(%p)\n", bp));
537 
538 	/*
539 	 * If the device has been made invalid, error out
540 	 */
541 	if ((periph->flags & CAM_PERIPH_INVALID) != 0) {
542 		cam_periph_unlock(periph);
543 		biofinish(bp, NULL, ENXIO);
544 		return;
545 	}
546 
547 	/*
548 	 * Place it in the queue of disk activities for this disk
549 	 */
550 	bioq_disksort(&part->bio_queue, bp);
551 
552 	/*
553 	 * Schedule ourselves for performing the work.
554 	 */
555 	sddaschedule(periph);
556 	cam_periph_unlock(periph);
557 
558 	return;
559 }
560 
561 static void
sddainit(void)562 sddainit(void)
563 {
564 	cam_status status;
565 
566 	/*
567 	 * Install a global async callback.  This callback will
568 	 * receive async callbacks like "new device found".
569 	 */
570 	status = xpt_register_async(AC_FOUND_DEVICE, sddaasync, NULL, NULL);
571 
572 	if (status != CAM_REQ_CMP) {
573 		printf("sdda: Failed to attach master async callback "
574 		       "due to status 0x%x!\n", status);
575 	}
576 }
577 
578 /*
579  * Callback from GEOM, called when it has finished cleaning up its
580  * resources.
581  */
582 static void
sddadiskgonecb(struct disk * dp)583 sddadiskgonecb(struct disk *dp)
584 {
585 	struct cam_periph *periph;
586 	struct sdda_part *part;
587 
588 	part = (struct sdda_part *)dp->d_drv1;
589 	periph = part->sc->periph;
590 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sddadiskgonecb\n"));
591 
592 	cam_periph_release(periph);
593 }
594 
595 static void
sddaoninvalidate(struct cam_periph * periph)596 sddaoninvalidate(struct cam_periph *periph)
597 {
598 	struct sdda_softc *softc;
599 	struct sdda_part *part;
600 
601 	softc = (struct sdda_softc *)periph->softc;
602 
603 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sddaoninvalidate\n"));
604 
605 	/*
606 	 * De-register any async callbacks.
607 	 */
608 	xpt_register_async(0, sddaasync, periph, periph->path);
609 
610 	/*
611 	 * Return all queued I/O with ENXIO.
612 	 * XXX Handle any transactions queued to the card
613 	 *     with XPT_ABORT_CCB.
614 	 */
615 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("bioq_flush start\n"));
616 	for (int i = 0; i < MMC_PART_MAX; i++) {
617 		if ((part = softc->part[i]) != NULL) {
618 			bioq_flush(&part->bio_queue, NULL, ENXIO);
619 			disk_gone(part->disk);
620 		}
621 	}
622 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("bioq_flush end\n"));
623 }
624 
625 static void
sddacleanup(struct cam_periph * periph)626 sddacleanup(struct cam_periph *periph)
627 {
628 	struct sdda_softc *softc;
629 	struct sdda_part *part;
630 	int i;
631 
632 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sddacleanup\n"));
633 	softc = (struct sdda_softc *)periph->softc;
634 
635 	cam_periph_unlock(periph);
636 
637 	for (i = 0; i < MMC_PART_MAX; i++) {
638 		if ((part = softc->part[i]) != NULL) {
639 			disk_destroy(part->disk);
640 			free(part, M_DEVBUF);
641 			softc->part[i] = NULL;
642 		}
643 	}
644 	free(softc, M_DEVBUF);
645 	cam_periph_lock(periph);
646 }
647 
648 static void
sddaasync(void * callback_arg,u_int32_t code,struct cam_path * path,void * arg)649 sddaasync(void *callback_arg, u_int32_t code,
650 	struct cam_path *path, void *arg)
651 {
652 	struct ccb_getdev cgd;
653 	struct cam_periph *periph;
654 
655 	periph = (struct cam_periph *)callback_arg;
656         CAM_DEBUG(path, CAM_DEBUG_TRACE, ("sddaasync(code=%d)\n", code));
657 	switch (code) {
658 	case AC_FOUND_DEVICE:
659 	{
660 		CAM_DEBUG(path, CAM_DEBUG_TRACE, ("=> AC_FOUND_DEVICE\n"));
661 		struct ccb_getdev *cgd;
662 		cam_status status;
663 
664 		cgd = (struct ccb_getdev *)arg;
665 		if (cgd == NULL)
666 			break;
667 
668 		if (cgd->protocol != PROTO_MMCSD)
669 			break;
670 
671 		if (!(path->device->mmc_ident_data.card_features & CARD_FEATURE_MEMORY)) {
672 			CAM_DEBUG(path, CAM_DEBUG_TRACE, ("No memory on the card!\n"));
673 			break;
674 		}
675 
676 		/*
677 		 * Allocate a peripheral instance for
678 		 * this device and start the probe
679 		 * process.
680 		 */
681 		status = cam_periph_alloc(sddaregister, sddaoninvalidate,
682 					  sddacleanup, sddastart,
683 					  "sdda", CAM_PERIPH_BIO,
684 					  path, sddaasync,
685 					  AC_FOUND_DEVICE, cgd);
686 
687 		if (status != CAM_REQ_CMP
688 		 && status != CAM_REQ_INPROG)
689 			printf("sddaasync: Unable to attach to new device "
690 				"due to status 0x%x\n", status);
691 		break;
692 	}
693 	case AC_GETDEV_CHANGED:
694 	{
695 		CAM_DEBUG(path, CAM_DEBUG_TRACE, ("=> AC_GETDEV_CHANGED\n"));
696 		xpt_setup_ccb(&cgd.ccb_h, periph->path, CAM_PRIORITY_NORMAL);
697 		cgd.ccb_h.func_code = XPT_GDEV_TYPE;
698 		xpt_action((union ccb *)&cgd);
699 		cam_periph_async(periph, code, path, arg);
700 		break;
701 	}
702 	case AC_ADVINFO_CHANGED:
703 	{
704 		uintptr_t buftype;
705 		int i;
706 
707 		CAM_DEBUG(path, CAM_DEBUG_TRACE, ("=> AC_ADVINFO_CHANGED\n"));
708 		buftype = (uintptr_t)arg;
709 		if (buftype == CDAI_TYPE_PHYS_PATH) {
710 			struct sdda_softc *softc;
711 			struct sdda_part *part;
712 
713 			softc = periph->softc;
714 			for (i = 0; i < MMC_PART_MAX; i++) {
715 				if ((part = softc->part[i]) != NULL) {
716 					disk_attr_changed(part->disk, "GEOM::physpath",
717 					    M_NOWAIT);
718 				}
719 			}
720 		}
721 		break;
722 	}
723 	default:
724 		CAM_DEBUG(path, CAM_DEBUG_TRACE, ("=> default?!\n"));
725 		cam_periph_async(periph, code, path, arg);
726 		break;
727 	}
728 }
729 
730 static int
sddagetattr(struct bio * bp)731 sddagetattr(struct bio *bp)
732 {
733 	struct cam_periph *periph;
734 	struct sdda_softc *softc;
735 	struct sdda_part *part;
736 	int ret;
737 
738 	part = (struct sdda_part *)bp->bio_disk->d_drv1;
739 	softc = part->sc;
740 	periph = softc->periph;
741 	cam_periph_lock(periph);
742 	ret = xpt_getattr(bp->bio_data, bp->bio_length, bp->bio_attribute,
743 	    periph->path);
744 	cam_periph_unlock(periph);
745 	if (ret == 0)
746 		bp->bio_completed = bp->bio_length;
747 	return (ret);
748 }
749 
750 static cam_status
sddaregister(struct cam_periph * periph,void * arg)751 sddaregister(struct cam_periph *periph, void *arg)
752 {
753 	struct sdda_softc *softc;
754 	struct ccb_getdev *cgd;
755 
756 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sddaregister\n"));
757 	cgd = (struct ccb_getdev *)arg;
758 	if (cgd == NULL) {
759 		printf("sddaregister: no getdev CCB, can't register device\n");
760 		return (CAM_REQ_CMP_ERR);
761 	}
762 
763 	softc = (struct sdda_softc *)malloc(sizeof(*softc), M_DEVBUF,
764 	    M_NOWAIT|M_ZERO);
765 	if (softc == NULL) {
766 		printf("sddaregister: Unable to probe new device. "
767 		    "Unable to allocate softc\n");
768 		return (CAM_REQ_CMP_ERR);
769 	}
770 
771 	softc->state = SDDA_STATE_INIT;
772 	softc->mmcdata =
773 		(struct mmc_data *)malloc(sizeof(struct mmc_data), M_DEVBUF, M_NOWAIT|M_ZERO);
774 	if (softc->mmcdata == NULL) {
775 		printf("sddaregister: Unable to probe new device. "
776 		    "Unable to allocate mmcdata\n");
777 		free(softc, M_DEVBUF);
778 		return (CAM_REQ_CMP_ERR);
779 	}
780 	periph->softc = softc;
781 	softc->periph = periph;
782 
783 	xpt_schedule(periph, CAM_PRIORITY_XPT);
784 	TASK_INIT(&softc->start_init_task, 0, sdda_start_init_task, periph);
785 	taskqueue_enqueue(taskqueue_thread, &softc->start_init_task);
786 
787 	return (CAM_REQ_CMP);
788 }
789 
790 static int
mmc_exec_app_cmd(struct cam_periph * periph,union ccb * ccb,struct mmc_command * cmd)791 mmc_exec_app_cmd(struct cam_periph *periph, union ccb *ccb,
792 	struct mmc_command *cmd) {
793 	int err;
794 
795 	/* Send APP_CMD first */
796 	memset(&ccb->mmcio.cmd, 0, sizeof(struct mmc_command));
797 	memset(&ccb->mmcio.stop, 0, sizeof(struct mmc_command));
798 	cam_fill_mmcio(&ccb->mmcio,
799 		       /*retries*/ 0,
800 		       /*cbfcnp*/ NULL,
801 		       /*flags*/ CAM_DIR_NONE,
802 		       /*mmc_opcode*/ MMC_APP_CMD,
803 		       /*mmc_arg*/ get_rca(periph) << 16,
804 		       /*mmc_flags*/ MMC_RSP_R1 | MMC_CMD_AC,
805 		       /*mmc_data*/ NULL,
806 		       /*timeout*/ 0);
807 
808 	cam_periph_runccb(ccb, sddaerror, CAM_FLAG_NONE, /*sense_flags*/0, NULL);
809 	err = mmc_handle_reply(ccb);
810 	if (err != 0)
811 		return (err);
812 	if (!(ccb->mmcio.cmd.resp[0] & R1_APP_CMD))
813 		return (EIO);
814 
815 	/* Now exec actual command */
816 	int flags = 0;
817 	if (cmd->data != NULL) {
818 		ccb->mmcio.cmd.data = cmd->data;
819 		if (cmd->data->flags & MMC_DATA_READ)
820 			flags |= CAM_DIR_IN;
821 		if (cmd->data->flags & MMC_DATA_WRITE)
822 			flags |= CAM_DIR_OUT;
823 	} else flags = CAM_DIR_NONE;
824 
825 	cam_fill_mmcio(&ccb->mmcio,
826 		       /*retries*/ 0,
827 		       /*cbfcnp*/ NULL,
828 		       /*flags*/ flags,
829 		       /*mmc_opcode*/ cmd->opcode,
830 		       /*mmc_arg*/ cmd->arg,
831 		       /*mmc_flags*/ cmd->flags,
832 		       /*mmc_data*/ cmd->data,
833 		       /*timeout*/ 0);
834 
835 	cam_periph_runccb(ccb, sddaerror, CAM_FLAG_NONE, /*sense_flags*/0, NULL);
836 	err = mmc_handle_reply(ccb);
837 	if (err != 0)
838 		return (err);
839 	memcpy(cmd->resp, ccb->mmcio.cmd.resp, sizeof(cmd->resp));
840 	cmd->error = ccb->mmcio.cmd.error;
841 
842 	return (0);
843 }
844 
845 static int
mmc_app_get_scr(struct cam_periph * periph,union ccb * ccb,uint32_t * rawscr)846 mmc_app_get_scr(struct cam_periph *periph, union ccb *ccb, uint32_t *rawscr) {
847 	int err;
848 	struct mmc_command cmd;
849 	struct mmc_data d;
850 
851 	memset(&cmd, 0, sizeof(cmd));
852 	memset(&d, 0, sizeof(d));
853 
854 	memset(rawscr, 0, 8);
855 	cmd.opcode = ACMD_SEND_SCR;
856 	cmd.flags = MMC_RSP_R1 | MMC_CMD_ADTC;
857 	cmd.arg = 0;
858 
859 	d.data = rawscr;
860 	d.len = 8;
861 	d.flags = MMC_DATA_READ;
862 	cmd.data = &d;
863 
864 	err = mmc_exec_app_cmd(periph, ccb, &cmd);
865 	rawscr[0] = be32toh(rawscr[0]);
866 	rawscr[1] = be32toh(rawscr[1]);
867 	return (err);
868 }
869 
870 static int
mmc_send_ext_csd(struct cam_periph * periph,union ccb * ccb,uint8_t * rawextcsd,size_t buf_len)871 mmc_send_ext_csd(struct cam_periph *periph, union ccb *ccb,
872 		 uint8_t *rawextcsd, size_t buf_len) {
873 	int err;
874 	struct mmc_data d;
875 
876 	KASSERT(buf_len == 512, ("Buffer for ext csd must be 512 bytes"));
877 	memset(&d, 0, sizeof(d));
878 	d.data = rawextcsd;
879 	d.len = buf_len;
880 	d.flags = MMC_DATA_READ;
881 	memset(d.data, 0, d.len);
882 
883 	cam_fill_mmcio(&ccb->mmcio,
884 		       /*retries*/ 0,
885 		       /*cbfcnp*/ NULL,
886 		       /*flags*/ CAM_DIR_IN,
887 		       /*mmc_opcode*/ MMC_SEND_EXT_CSD,
888 		       /*mmc_arg*/ 0,
889 		       /*mmc_flags*/ MMC_RSP_R1 | MMC_CMD_ADTC,
890 		       /*mmc_data*/ &d,
891 		       /*timeout*/ 0);
892 
893 	cam_periph_runccb(ccb, sddaerror, CAM_FLAG_NONE, /*sense_flags*/0, NULL);
894 	err = mmc_handle_reply(ccb);
895 	return (err);
896 }
897 
898 static void
mmc_app_decode_scr(uint32_t * raw_scr,struct mmc_scr * scr)899 mmc_app_decode_scr(uint32_t *raw_scr, struct mmc_scr *scr)
900 {
901 	unsigned int scr_struct;
902 
903 	memset(scr, 0, sizeof(*scr));
904 
905 	scr_struct = mmc_get_bits(raw_scr, 64, 60, 4);
906 	if (scr_struct != 0) {
907 		printf("Unrecognised SCR structure version %d\n",
908 		    scr_struct);
909 		return;
910 	}
911 	scr->sda_vsn = mmc_get_bits(raw_scr, 64, 56, 4);
912 	scr->bus_widths = mmc_get_bits(raw_scr, 64, 48, 4);
913 }
914 
915 static inline void
mmc_switch_fill_mmcio(union ccb * ccb,uint8_t set,uint8_t index,uint8_t value,u_int timeout)916 mmc_switch_fill_mmcio(union ccb *ccb,
917     uint8_t set, uint8_t index, uint8_t value, u_int timeout)
918 {
919 	int arg = (MMC_SWITCH_FUNC_WR << 24) |
920 	    (index << 16) |
921 	    (value << 8) |
922 	    set;
923 
924 	cam_fill_mmcio(&ccb->mmcio,
925 		       /*retries*/ 0,
926 		       /*cbfcnp*/ NULL,
927 		       /*flags*/ CAM_DIR_NONE,
928 		       /*mmc_opcode*/ MMC_SWITCH_FUNC,
929 		       /*mmc_arg*/ arg,
930 		       /*mmc_flags*/ MMC_RSP_R1B | MMC_CMD_AC,
931 		       /*mmc_data*/ NULL,
932 		       /*timeout*/ timeout);
933 }
934 
935 static int
mmc_select_card(struct cam_periph * periph,union ccb * ccb,uint32_t rca)936 mmc_select_card(struct cam_periph *periph, union ccb *ccb, uint32_t rca)
937 {
938 	int flags, err;
939 
940 	flags = (rca ? MMC_RSP_R1B : MMC_RSP_NONE) | MMC_CMD_AC;
941 	cam_fill_mmcio(&ccb->mmcio,
942 		       /*retries*/ 0,
943 		       /*cbfcnp*/ NULL,
944 		       /*flags*/ CAM_DIR_IN,
945 		       /*mmc_opcode*/ MMC_SELECT_CARD,
946 		       /*mmc_arg*/ rca << 16,
947 		       /*mmc_flags*/ flags,
948 		       /*mmc_data*/ NULL,
949 		       /*timeout*/ 0);
950 
951 	cam_periph_runccb(ccb, sddaerror, CAM_FLAG_NONE, /*sense_flags*/0, NULL);
952 	err = mmc_handle_reply(ccb);
953 	return (err);
954 }
955 
956 static int
mmc_switch(struct cam_periph * periph,union ccb * ccb,uint8_t set,uint8_t index,uint8_t value,u_int timeout)957 mmc_switch(struct cam_periph *periph, union ccb *ccb,
958     uint8_t set, uint8_t index, uint8_t value, u_int timeout)
959 {
960 	int err;
961 
962 	mmc_switch_fill_mmcio(ccb, set, index, value, timeout);
963 	cam_periph_runccb(ccb, sddaerror, CAM_FLAG_NONE, /*sense_flags*/0, NULL);
964 	err = mmc_handle_reply(ccb);
965 	return (err);
966 }
967 
968 static uint32_t
mmc_get_spec_vers(struct cam_periph * periph)969 mmc_get_spec_vers(struct cam_periph *periph) {
970 	struct sdda_softc *softc = (struct sdda_softc *)periph->softc;
971 
972 	return (softc->csd.spec_vers);
973 }
974 
975 static uint64_t
mmc_get_media_size(struct cam_periph * periph)976 mmc_get_media_size(struct cam_periph *periph) {
977 	struct sdda_softc *softc = (struct sdda_softc *)periph->softc;
978 
979 	return (softc->mediasize);
980 }
981 
982 static uint32_t
mmc_get_cmd6_timeout(struct cam_periph * periph)983 mmc_get_cmd6_timeout(struct cam_periph *periph)
984 {
985 	struct sdda_softc *softc = (struct sdda_softc *)periph->softc;
986 
987 	if (mmc_get_spec_vers(periph) >= 6)
988 		return (softc->raw_ext_csd[EXT_CSD_GEN_CMD6_TIME] * 10);
989 	return (500 * 1000);
990 }
991 
992 static int
mmc_sd_switch(struct cam_periph * periph,union ccb * ccb,uint8_t mode,uint8_t grp,uint8_t value,uint8_t * res)993 mmc_sd_switch(struct cam_periph *periph, union ccb *ccb,
994 	      uint8_t mode, uint8_t grp, uint8_t value,
995 	      uint8_t *res) {
996 	struct mmc_data mmc_d;
997 	uint32_t arg;
998 	int err;
999 
1000 	memset(res, 0, 64);
1001 	memset(&mmc_d, 0, sizeof(mmc_d));
1002 	mmc_d.len = 64;
1003 	mmc_d.data = res;
1004 	mmc_d.flags = MMC_DATA_READ;
1005 
1006 	arg = mode << 31;			/* 0 - check, 1 - set */
1007 	arg |= 0x00FFFFFF;
1008 	arg &= ~(0xF << (grp * 4));
1009 	arg |= value << (grp * 4);
1010 
1011 	cam_fill_mmcio(&ccb->mmcio,
1012 		       /*retries*/ 0,
1013 		       /*cbfcnp*/ NULL,
1014 		       /*flags*/ CAM_DIR_IN,
1015 		       /*mmc_opcode*/ SD_SWITCH_FUNC,
1016 		       /*mmc_arg*/ arg,
1017 		       /*mmc_flags*/ MMC_RSP_R1 | MMC_CMD_ADTC,
1018 		       /*mmc_data*/ &mmc_d,
1019 		       /*timeout*/ 0);
1020 
1021 	cam_periph_runccb(ccb, sddaerror, CAM_FLAG_NONE, /*sense_flags*/0, NULL);
1022 	err = mmc_handle_reply(ccb);
1023 	return (err);
1024 }
1025 
1026 static int
mmc_set_timing(struct cam_periph * periph,union ccb * ccb,enum mmc_bus_timing timing)1027 mmc_set_timing(struct cam_periph *periph,
1028 	       union ccb *ccb,
1029 	       enum mmc_bus_timing timing)
1030 {
1031 	u_char switch_res[64];
1032 	int err;
1033 	uint8_t	value;
1034 	struct sdda_softc *softc = (struct sdda_softc *)periph->softc;
1035 	struct mmc_params *mmcp = &periph->path->device->mmc_ident_data;
1036 
1037 	CAM_DEBUG(ccb->ccb_h.path, CAM_DEBUG_TRACE,
1038 		  ("mmc_set_timing(timing=%d)", timing));
1039 	switch (timing) {
1040 	case bus_timing_normal:
1041 		value = 0;
1042 		break;
1043 	case bus_timing_hs:
1044 		value = 1;
1045 		break;
1046 	default:
1047 		return (MMC_ERR_INVALID);
1048 	}
1049 	if (mmcp->card_features & CARD_FEATURE_MMC) {
1050 		err = mmc_switch(periph, ccb, EXT_CSD_CMD_SET_NORMAL,
1051 		    EXT_CSD_HS_TIMING, value, softc->cmd6_time);
1052 	} else {
1053 		err = mmc_sd_switch(periph, ccb, SD_SWITCH_MODE_SET, SD_SWITCH_GROUP1, value, switch_res);
1054 	}
1055 
1056 	/* Set high-speed timing on the host */
1057 	struct ccb_trans_settings_mmc *cts;
1058 	cts = &ccb->cts.proto_specific.mmc;
1059 	ccb->ccb_h.func_code = XPT_SET_TRAN_SETTINGS;
1060 	ccb->ccb_h.flags = CAM_DIR_NONE;
1061 	ccb->ccb_h.retry_count = 0;
1062 	ccb->ccb_h.timeout = 100;
1063 	ccb->ccb_h.cbfcnp = NULL;
1064 	cts->ios.timing = timing;
1065 	cts->ios_valid = MMC_BT;
1066 	xpt_action(ccb);
1067 
1068 	return (err);
1069 }
1070 
1071 static void
sdda_start_init_task(void * context,int pending)1072 sdda_start_init_task(void *context, int pending) {
1073 	union ccb *new_ccb;
1074 	struct cam_periph *periph;
1075 
1076 	periph = (struct cam_periph *)context;
1077 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sdda_start_init_task\n"));
1078 	new_ccb = xpt_alloc_ccb();
1079 	xpt_setup_ccb(&new_ccb->ccb_h, periph->path,
1080 		      CAM_PRIORITY_NONE);
1081 
1082 	cam_periph_lock(periph);
1083 	cam_periph_hold(periph, PRIBIO|PCATCH);
1084 	sdda_start_init(context, new_ccb);
1085 	cam_periph_unhold(periph);
1086 	cam_periph_unlock(periph);
1087 	xpt_free_ccb(new_ccb);
1088 }
1089 
1090 static void
sdda_set_bus_width(struct cam_periph * periph,union ccb * ccb,int width)1091 sdda_set_bus_width(struct cam_periph *periph, union ccb *ccb, int width) {
1092 	struct sdda_softc *softc = (struct sdda_softc *)periph->softc;
1093 	struct mmc_params *mmcp = &periph->path->device->mmc_ident_data;
1094 	int err;
1095 
1096 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sdda_set_bus_width\n"));
1097 
1098 	/* First set for the card, then for the host */
1099 	if (mmcp->card_features & CARD_FEATURE_MMC) {
1100 		uint8_t	value;
1101 		switch (width) {
1102 		case bus_width_1:
1103 			value = EXT_CSD_BUS_WIDTH_1;
1104 			break;
1105 		case bus_width_4:
1106 			value = EXT_CSD_BUS_WIDTH_4;
1107 			break;
1108 		case bus_width_8:
1109 			value = EXT_CSD_BUS_WIDTH_8;
1110 			break;
1111 		default:
1112 			panic("Invalid bus width %d", width);
1113 		}
1114 		err = mmc_switch(periph, ccb, EXT_CSD_CMD_SET_NORMAL,
1115 		    EXT_CSD_BUS_WIDTH, value, softc->cmd6_time);
1116 	} else {
1117 		/* For SD cards we send ACMD6 with the required bus width in arg */
1118 		struct mmc_command cmd;
1119 		memset(&cmd, 0, sizeof(struct mmc_command));
1120 		cmd.opcode = ACMD_SET_BUS_WIDTH;
1121 		cmd.arg = width;
1122 		cmd.flags = MMC_RSP_R1 | MMC_CMD_AC;
1123 		err = mmc_exec_app_cmd(periph, ccb, &cmd);
1124 	}
1125 
1126 	if (err != MMC_ERR_NONE) {
1127 		CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH, ("Error %d when setting bus width on the card\n", err));
1128 		return;
1129 	}
1130 	/* Now card is done, set the host to the same width */
1131 	struct ccb_trans_settings_mmc *cts;
1132 	cts = &ccb->cts.proto_specific.mmc;
1133 	ccb->ccb_h.func_code = XPT_SET_TRAN_SETTINGS;
1134 	ccb->ccb_h.flags = CAM_DIR_NONE;
1135 	ccb->ccb_h.retry_count = 0;
1136 	ccb->ccb_h.timeout = 100;
1137 	ccb->ccb_h.cbfcnp = NULL;
1138 	cts->ios.bus_width = width;
1139 	cts->ios_valid = MMC_BW;
1140 	xpt_action(ccb);
1141 }
1142 
1143 static inline const char
part_type(u_int type)1144 *part_type(u_int type)
1145 {
1146 
1147 	switch (type) {
1148 	case EXT_CSD_PART_CONFIG_ACC_RPMB:
1149 		return ("RPMB");
1150 	case EXT_CSD_PART_CONFIG_ACC_DEFAULT:
1151 		return ("default");
1152 	case EXT_CSD_PART_CONFIG_ACC_BOOT0:
1153 		return ("boot0");
1154 	case EXT_CSD_PART_CONFIG_ACC_BOOT1:
1155 		return ("boot1");
1156 	case EXT_CSD_PART_CONFIG_ACC_GP0:
1157 	case EXT_CSD_PART_CONFIG_ACC_GP1:
1158 	case EXT_CSD_PART_CONFIG_ACC_GP2:
1159 	case EXT_CSD_PART_CONFIG_ACC_GP3:
1160 		return ("general purpose");
1161 	default:
1162 		return ("(unknown type)");
1163 	}
1164 }
1165 
1166 static inline const char
bus_width_str(enum mmc_bus_width w)1167 *bus_width_str(enum mmc_bus_width w)
1168 {
1169 
1170 	switch (w) {
1171 	case bus_width_1:
1172 		return ("1-bit");
1173 	case bus_width_4:
1174 		return ("4-bit");
1175 	case bus_width_8:
1176 		return ("8-bit");
1177 	}
1178 }
1179 
1180 static uint32_t
sdda_get_host_caps(struct cam_periph * periph,union ccb * ccb)1181 sdda_get_host_caps(struct cam_periph *periph, union ccb *ccb)
1182 {
1183 	struct ccb_trans_settings_mmc *cts;
1184 
1185 	cts = &ccb->cts.proto_specific.mmc;
1186 
1187 	ccb->ccb_h.func_code = XPT_GET_TRAN_SETTINGS;
1188 	ccb->ccb_h.flags = CAM_DIR_NONE;
1189 	ccb->ccb_h.retry_count = 0;
1190 	ccb->ccb_h.timeout = 100;
1191 	ccb->ccb_h.cbfcnp = NULL;
1192 	xpt_action(ccb);
1193 
1194 	if (ccb->ccb_h.status != CAM_REQ_CMP)
1195 		panic("Cannot get host caps");
1196 	return (cts->host_caps);
1197 }
1198 
1199 static uint32_t
sdda_get_max_data(struct cam_periph * periph,union ccb * ccb)1200 sdda_get_max_data(struct cam_periph *periph, union ccb *ccb)
1201 {
1202 	struct ccb_trans_settings_mmc *cts;
1203 
1204 	cts = &ccb->cts.proto_specific.mmc;
1205 	memset(cts, 0, sizeof(struct ccb_trans_settings_mmc));
1206 
1207 	ccb->ccb_h.func_code = XPT_GET_TRAN_SETTINGS;
1208 	ccb->ccb_h.flags = CAM_DIR_NONE;
1209 	ccb->ccb_h.retry_count = 0;
1210 	ccb->ccb_h.timeout = 100;
1211 	ccb->ccb_h.cbfcnp = NULL;
1212 	xpt_action(ccb);
1213 
1214 	if (ccb->ccb_h.status != CAM_REQ_CMP)
1215 		panic("Cannot get host max data");
1216 	KASSERT(cts->host_max_data != 0, ("host_max_data == 0?!"));
1217 	return (cts->host_max_data);
1218 }
1219 
1220 static void
sdda_start_init(void * context,union ccb * start_ccb)1221 sdda_start_init(void *context, union ccb *start_ccb)
1222 {
1223 	struct cam_periph *periph = (struct cam_periph *)context;
1224 	struct ccb_trans_settings_mmc *cts;
1225 	uint32_t host_caps;
1226 	uint32_t sec_count;
1227 	int err;
1228 	int host_f_max;
1229 	uint8_t card_type;
1230 
1231 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sdda_start_init\n"));
1232 	/* periph was held for us when this task was enqueued */
1233 	if ((periph->flags & CAM_PERIPH_INVALID) != 0) {
1234 		cam_periph_release(periph);
1235 		return;
1236 	}
1237 
1238 	struct sdda_softc *softc = (struct sdda_softc *)periph->softc;
1239 	struct mmc_params *mmcp = &periph->path->device->mmc_ident_data;
1240 	struct cam_ed *device = periph->path->device;
1241 
1242 	if (mmcp->card_features & CARD_FEATURE_MMC) {
1243 		mmc_decode_csd_mmc(mmcp->card_csd, &softc->csd);
1244 		mmc_decode_cid_mmc(mmcp->card_cid, &softc->cid);
1245 		if (mmc_get_spec_vers(periph) >= 4) {
1246 			err = mmc_send_ext_csd(periph, start_ccb,
1247 					       (uint8_t *)&softc->raw_ext_csd,
1248 					       sizeof(softc->raw_ext_csd));
1249 			if (err != 0) {
1250 				CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH,
1251 				    ("Cannot read EXT_CSD, err %d", err));
1252 				return;
1253 			}
1254 		}
1255 	} else {
1256 		mmc_decode_csd_sd(mmcp->card_csd, &softc->csd);
1257 		mmc_decode_cid_sd(mmcp->card_cid, &softc->cid);
1258 	}
1259 
1260 	softc->sector_count = softc->csd.capacity / MMC_SECTOR_SIZE;
1261 	softc->mediasize = softc->csd.capacity;
1262 	softc->cmd6_time = mmc_get_cmd6_timeout(periph);
1263 
1264 	/* MMC >= 4.x have EXT_CSD that has its own opinion about capacity */
1265 	if (mmc_get_spec_vers(periph) >= 4) {
1266 		sec_count = softc->raw_ext_csd[EXT_CSD_SEC_CNT] +
1267 		    (softc->raw_ext_csd[EXT_CSD_SEC_CNT + 1] << 8) +
1268 		    (softc->raw_ext_csd[EXT_CSD_SEC_CNT + 2] << 16) +
1269 		    (softc->raw_ext_csd[EXT_CSD_SEC_CNT + 3] << 24);
1270 		if (sec_count != 0) {
1271 			softc->sector_count = sec_count;
1272 			softc->mediasize = softc->sector_count * MMC_SECTOR_SIZE;
1273 			/* FIXME: there should be a better name for this option...*/
1274 			mmcp->card_features |= CARD_FEATURE_SDHC;
1275 		}
1276 	}
1277 	CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH,
1278 	    ("Capacity: %"PRIu64", sectors: %"PRIu64"\n",
1279 		softc->mediasize,
1280 		softc->sector_count));
1281 	mmc_format_card_id_string(softc, mmcp);
1282 
1283 	/* Update info for CAM */
1284 	device->serial_num_len = strlen(softc->card_sn_string);
1285 	device->serial_num = (u_int8_t *)malloc((device->serial_num_len + 1),
1286 	    M_CAMXPT, M_NOWAIT);
1287 	strlcpy(device->serial_num, softc->card_sn_string, device->serial_num_len + 1);
1288 
1289 	device->device_id_len = strlen(softc->card_id_string);
1290 	device->device_id = (u_int8_t *)malloc((device->device_id_len + 1),
1291 	    M_CAMXPT, M_NOWAIT);
1292 	strlcpy(device->device_id, softc->card_id_string, device->device_id_len + 1);
1293 
1294 	strlcpy(mmcp->model, softc->card_id_string, sizeof(mmcp->model));
1295 
1296 	/* Set the clock frequency that the card can handle */
1297 	cts = &start_ccb->cts.proto_specific.mmc;
1298 
1299 	/* First, get the host's max freq */
1300 	start_ccb->ccb_h.func_code = XPT_GET_TRAN_SETTINGS;
1301 	start_ccb->ccb_h.flags = CAM_DIR_NONE;
1302 	start_ccb->ccb_h.retry_count = 0;
1303 	start_ccb->ccb_h.timeout = 100;
1304 	start_ccb->ccb_h.cbfcnp = NULL;
1305 	xpt_action(start_ccb);
1306 
1307 	if (start_ccb->ccb_h.status != CAM_REQ_CMP)
1308 		panic("Cannot get max host freq");
1309 	host_f_max = cts->host_f_max;
1310 	host_caps = cts->host_caps;
1311 	if (cts->ios.bus_width != bus_width_1)
1312 		panic("Bus width in ios is not 1-bit");
1313 
1314 	/* Now check if the card supports High-speed */
1315 	softc->card_f_max = softc->csd.tran_speed;
1316 
1317 	if (host_caps & MMC_CAP_HSPEED) {
1318 		/* Find out if the card supports High speed timing */
1319 		if (mmcp->card_features & CARD_FEATURE_SD20) {
1320 			/* Get and decode SCR */
1321 			uint32_t rawscr[2];
1322 			uint8_t res[64];
1323 			if (mmc_app_get_scr(periph, start_ccb, rawscr)) {
1324 				CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH, ("Cannot get SCR\n"));
1325 				goto finish_hs_tests;
1326 			}
1327 			mmc_app_decode_scr(rawscr, &softc->scr);
1328 
1329 			if ((softc->scr.sda_vsn >= 1) && (softc->csd.ccc & (1<<10))) {
1330 				mmc_sd_switch(periph, start_ccb, SD_SWITCH_MODE_CHECK,
1331 					      SD_SWITCH_GROUP1, SD_SWITCH_NOCHANGE, res);
1332 				if (res[13] & 2) {
1333 					CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH, ("Card supports HS\n"));
1334 					softc->card_f_max = SD_HS_MAX;
1335 				}
1336 
1337 				/*
1338 				 * We deselect then reselect the card here.  Some cards
1339 				 * become unselected and timeout with the above two
1340 				 * commands, although the state tables / diagrams in the
1341 				 * standard suggest they go back to the transfer state.
1342 				 * Other cards don't become deselected, and if we
1343 				 * attempt to blindly re-select them, we get timeout
1344 				 * errors from some controllers.  So we deselect then
1345 				 * reselect to handle all situations.
1346 				 */
1347 				mmc_select_card(periph, start_ccb, 0);
1348 				mmc_select_card(periph, start_ccb, get_rca(periph));
1349 			} else {
1350 				CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH, ("Not trying the switch\n"));
1351 				goto finish_hs_tests;
1352 			}
1353 		}
1354 
1355 		if (mmcp->card_features & CARD_FEATURE_MMC && mmc_get_spec_vers(periph) >= 4) {
1356 			card_type = softc->raw_ext_csd[EXT_CSD_CARD_TYPE];
1357 			if (card_type & EXT_CSD_CARD_TYPE_HS_52)
1358 				softc->card_f_max = MMC_TYPE_HS_52_MAX;
1359 			else if (card_type & EXT_CSD_CARD_TYPE_HS_26)
1360 				softc->card_f_max = MMC_TYPE_HS_26_MAX;
1361 			if ((card_type & EXT_CSD_CARD_TYPE_DDR_52_1_2V) != 0 &&
1362 			    (host_caps & MMC_CAP_SIGNALING_120) != 0) {
1363 				setbit(&softc->timings, bus_timing_mmc_ddr52);
1364 				setbit(&softc->vccq_120, bus_timing_mmc_ddr52);
1365 				CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH, ("Card supports DDR52 at 1.2V\n"));
1366 			}
1367 			if ((card_type & EXT_CSD_CARD_TYPE_DDR_52_1_8V) != 0 &&
1368 			    (host_caps & MMC_CAP_SIGNALING_180) != 0) {
1369 				setbit(&softc->timings, bus_timing_mmc_ddr52);
1370 				setbit(&softc->vccq_180, bus_timing_mmc_ddr52);
1371 				CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH, ("Card supports DDR52 at 1.8V\n"));
1372 			}
1373 			if ((card_type & EXT_CSD_CARD_TYPE_HS200_1_2V) != 0 &&
1374 			    (host_caps & MMC_CAP_SIGNALING_120) != 0) {
1375 				setbit(&softc->timings, bus_timing_mmc_hs200);
1376 				setbit(&softc->vccq_120, bus_timing_mmc_hs200);
1377 				CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH, ("Card supports HS200 at 1.2V\n"));
1378 			}
1379 			if ((card_type & EXT_CSD_CARD_TYPE_HS200_1_8V) != 0 &&
1380 			    (host_caps & MMC_CAP_SIGNALING_180) != 0) {
1381 				setbit(&softc->timings, bus_timing_mmc_hs200);
1382 				setbit(&softc->vccq_180, bus_timing_mmc_hs200);
1383 				CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH, ("Card supports HS200 at 1.8V\n"));
1384 			}
1385 		}
1386 	}
1387 	int f_max;
1388 finish_hs_tests:
1389 	f_max = min(host_f_max, softc->card_f_max);
1390 	CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH, ("Set SD freq to %d MHz (min out of host f=%d MHz and card f=%d MHz)\n", f_max  / 1000000, host_f_max / 1000000, softc->card_f_max / 1000000));
1391 
1392 	/* Enable high-speed timing on the card */
1393 	if (f_max > 25000000) {
1394 		err = mmc_set_timing(periph, start_ccb, bus_timing_hs);
1395 		if (err != MMC_ERR_NONE) {
1396 			CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("Cannot switch card to high-speed mode"));
1397 			f_max = 25000000;
1398 		}
1399 	}
1400 	/* If possible, set lower-level signaling */
1401 	enum mmc_bus_timing timing;
1402 	/* FIXME: MMCCAM supports max. bus_timing_mmc_ddr52 at the moment. */
1403 	for (timing = bus_timing_mmc_ddr52; timing > bus_timing_normal; timing--) {
1404 		if (isset(&softc->vccq_120, timing)) {
1405 			/* Set VCCQ = 1.2V */
1406 			start_ccb->ccb_h.func_code = XPT_SET_TRAN_SETTINGS;
1407 			start_ccb->ccb_h.flags = CAM_DIR_NONE;
1408 			start_ccb->ccb_h.retry_count = 0;
1409 			start_ccb->ccb_h.timeout = 100;
1410 			start_ccb->ccb_h.cbfcnp = NULL;
1411 			cts->ios.vccq = vccq_120;
1412 			cts->ios_valid = MMC_VCCQ;
1413 			xpt_action(start_ccb);
1414 			break;
1415 		} else if (isset(&softc->vccq_180, timing)) {
1416 			/* Set VCCQ = 1.8V */
1417 			start_ccb->ccb_h.func_code = XPT_SET_TRAN_SETTINGS;
1418 			start_ccb->ccb_h.flags = CAM_DIR_NONE;
1419 			start_ccb->ccb_h.retry_count = 0;
1420 			start_ccb->ccb_h.timeout = 100;
1421 			start_ccb->ccb_h.cbfcnp = NULL;
1422 			cts->ios.vccq = vccq_180;
1423 			cts->ios_valid = MMC_VCCQ;
1424 			xpt_action(start_ccb);
1425 			break;
1426 		} else {
1427 			/* Set VCCQ = 3.3V */
1428 			start_ccb->ccb_h.func_code = XPT_SET_TRAN_SETTINGS;
1429 			start_ccb->ccb_h.flags = CAM_DIR_NONE;
1430 			start_ccb->ccb_h.retry_count = 0;
1431 			start_ccb->ccb_h.timeout = 100;
1432 			start_ccb->ccb_h.cbfcnp = NULL;
1433 			cts->ios.vccq = vccq_330;
1434 			cts->ios_valid = MMC_VCCQ;
1435 			xpt_action(start_ccb);
1436 			break;
1437 		}
1438 	}
1439 
1440 	/* Set frequency on the controller */
1441 	start_ccb->ccb_h.func_code = XPT_SET_TRAN_SETTINGS;
1442 	start_ccb->ccb_h.flags = CAM_DIR_NONE;
1443 	start_ccb->ccb_h.retry_count = 0;
1444 	start_ccb->ccb_h.timeout = 100;
1445 	start_ccb->ccb_h.cbfcnp = NULL;
1446 	cts->ios.clock = f_max;
1447 	cts->ios_valid = MMC_CLK;
1448 	xpt_action(start_ccb);
1449 
1450 	/* Set bus width */
1451 	enum mmc_bus_width desired_bus_width = bus_width_1;
1452 	enum mmc_bus_width max_host_bus_width =
1453 		(host_caps & MMC_CAP_8_BIT_DATA ? bus_width_8 :
1454 		 host_caps & MMC_CAP_4_BIT_DATA ? bus_width_4 : bus_width_1);
1455 	enum mmc_bus_width max_card_bus_width = bus_width_1;
1456 	if (mmcp->card_features & CARD_FEATURE_SD20 &&
1457 	    softc->scr.bus_widths & SD_SCR_BUS_WIDTH_4)
1458 		max_card_bus_width = bus_width_4;
1459 	/*
1460 	 * Unlike SD, MMC cards don't have any information about supported bus width...
1461 	 * So we need to perform read/write test to find out the width.
1462 	 */
1463 	/* TODO: figure out bus width for MMC; use 8-bit for now (to test on BBB) */
1464 	if (mmcp->card_features & CARD_FEATURE_MMC)
1465 		max_card_bus_width = bus_width_8;
1466 
1467 	desired_bus_width = min(max_host_bus_width, max_card_bus_width);
1468 	CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH,
1469 		  ("Set bus width to %s (min of host %s and card %s)\n",
1470 		   bus_width_str(desired_bus_width),
1471 		   bus_width_str(max_host_bus_width),
1472 		   bus_width_str(max_card_bus_width)));
1473 	sdda_set_bus_width(periph, start_ccb, desired_bus_width);
1474 
1475 	softc->state = SDDA_STATE_NORMAL;
1476 
1477 	cam_periph_unhold(periph);
1478 	/* MMC partitions support */
1479 	if (mmcp->card_features & CARD_FEATURE_MMC && mmc_get_spec_vers(periph) >= 4) {
1480 		sdda_process_mmc_partitions(periph, start_ccb);
1481 	} else if (mmcp->card_features & CARD_FEATURE_MEMORY) {
1482 		/* For SD[HC] cards, just add one partition that is the whole card */
1483 		if (sdda_add_part(periph, 0, "sdda",
1484 		    periph->unit_number,
1485 		    mmc_get_media_size(periph),
1486 		    sdda_get_read_only(periph, start_ccb)) == false)
1487 			return;
1488 		softc->part_curr = 0;
1489 	}
1490 	cam_periph_hold(periph, PRIBIO|PCATCH);
1491 
1492 	xpt_announce_periph(periph, softc->card_id_string);
1493 	/*
1494 	 * Add async callbacks for bus reset and bus device reset calls.
1495 	 * I don't bother checking if this fails as, in most cases,
1496 	 * the system will function just fine without them and the only
1497 	 * alternative would be to not attach the device on failure.
1498 	 */
1499 	xpt_register_async(AC_LOST_DEVICE | AC_GETDEV_CHANGED |
1500 	    AC_ADVINFO_CHANGED, sddaasync, periph, periph->path);
1501 }
1502 
1503 static bool
sdda_add_part(struct cam_periph * periph,u_int type,const char * name,u_int cnt,off_t media_size,bool ro)1504 sdda_add_part(struct cam_periph *periph, u_int type, const char *name,
1505     u_int cnt, off_t media_size, bool ro)
1506 {
1507 	struct sdda_softc *sc = (struct sdda_softc *)periph->softc;
1508 	struct sdda_part *part;
1509 	struct ccb_pathinq cpi;
1510 
1511 	CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH,
1512 	    ("Partition type '%s', size %ju %s\n",
1513 	    part_type(type),
1514 	    media_size,
1515 	    ro ? "(read-only)" : ""));
1516 
1517 	part = sc->part[type] = malloc(sizeof(*part), M_DEVBUF,
1518 	    M_NOWAIT | M_ZERO);
1519 	if (part == NULL) {
1520 		printf("Cannot add partition for sdda\n");
1521 		return (false);
1522 	}
1523 
1524 	part->cnt = cnt;
1525 	part->type = type;
1526 	part->ro = ro;
1527 	part->sc = sc;
1528 	snprintf(part->name, sizeof(part->name), name, periph->unit_number);
1529 
1530 	/*
1531 	 * Due to the nature of RPMB partition it doesn't make much sense
1532 	 * to add it as a disk. It would be more appropriate to create a
1533 	 * userland tool to operate on the partition or leverage the existing
1534 	 * tools from sysutils/mmc-utils.
1535 	 */
1536 	if (type == EXT_CSD_PART_CONFIG_ACC_RPMB) {
1537 		/* TODO: Create device, assign IOCTL handler */
1538 		CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH,
1539 		    ("Don't know what to do with RPMB partitions yet\n"));
1540 		return (false);
1541 	}
1542 
1543 	bioq_init(&part->bio_queue);
1544 
1545 	bzero(&cpi, sizeof(cpi));
1546 	xpt_setup_ccb(&cpi.ccb_h, periph->path, CAM_PRIORITY_NONE);
1547 	cpi.ccb_h.func_code = XPT_PATH_INQ;
1548 	xpt_action((union ccb *)&cpi);
1549 
1550 	/*
1551 	 * Register this media as a disk
1552 	 */
1553 	(void)cam_periph_hold(periph, PRIBIO);
1554 	cam_periph_unlock(periph);
1555 
1556 	part->disk = disk_alloc();
1557 	part->disk->d_rotation_rate = DISK_RR_NON_ROTATING;
1558 	part->disk->d_devstat = devstat_new_entry(part->name,
1559 	    cnt, MMC_SECTOR_SIZE,
1560 	    DEVSTAT_ALL_SUPPORTED,
1561 	    DEVSTAT_TYPE_DIRECT | XPORT_DEVSTAT_TYPE(cpi.transport),
1562 	    DEVSTAT_PRIORITY_DISK);
1563 
1564 	part->disk->d_open = sddaopen;
1565 	part->disk->d_close = sddaclose;
1566 	part->disk->d_strategy = sddastrategy;
1567 	if (cam_sim_pollable(periph->sim))
1568 		part->disk->d_dump = sddadump;
1569 	part->disk->d_getattr = sddagetattr;
1570 	part->disk->d_gone = sddadiskgonecb;
1571 	part->disk->d_name = part->name;
1572 	part->disk->d_drv1 = part;
1573 	part->disk->d_maxsize =
1574 	    MIN(maxphys, sdda_get_max_data(periph,
1575 		    (union ccb *)&cpi) * mmc_get_sector_size(periph));
1576 	part->disk->d_unit = cnt;
1577 	part->disk->d_flags = 0;
1578 	strlcpy(part->disk->d_descr, sc->card_id_string,
1579 	    MIN(sizeof(part->disk->d_descr), sizeof(sc->card_id_string)));
1580 	strlcpy(part->disk->d_ident, sc->card_sn_string,
1581 	    MIN(sizeof(part->disk->d_ident), sizeof(sc->card_sn_string)));
1582 	part->disk->d_hba_vendor = cpi.hba_vendor;
1583 	part->disk->d_hba_device = cpi.hba_device;
1584 	part->disk->d_hba_subvendor = cpi.hba_subvendor;
1585 	part->disk->d_hba_subdevice = cpi.hba_subdevice;
1586 	snprintf(part->disk->d_attachment, sizeof(part->disk->d_attachment),
1587 	    "%s%d", cpi.dev_name, cpi.unit_number);
1588 
1589 	part->disk->d_sectorsize = mmc_get_sector_size(periph);
1590 	part->disk->d_mediasize = media_size;
1591 	part->disk->d_stripesize = 0;
1592 	part->disk->d_fwsectors = 0;
1593 	part->disk->d_fwheads = 0;
1594 
1595 	if (sdda_mmcsd_compat)
1596 		disk_add_alias(part->disk, "mmcsd");
1597 
1598 	/*
1599 	 * Acquire a reference to the periph before we register with GEOM.
1600 	 * We'll release this reference once GEOM calls us back (via
1601 	 * sddadiskgonecb()) telling us that our provider has been freed.
1602 	 */
1603 	if (cam_periph_acquire(periph) != 0) {
1604 		xpt_print(periph->path, "%s: lost periph during "
1605 		    "registration!\n", __func__);
1606 		cam_periph_lock(periph);
1607 		return (false);
1608 	}
1609 	disk_create(part->disk, DISK_VERSION);
1610 	cam_periph_lock(periph);
1611 	cam_periph_unhold(periph);
1612 
1613 	return (true);
1614 }
1615 
1616 /*
1617  * For MMC cards, process EXT_CSD and add partitions that are supported by
1618  * this device.
1619  */
1620 static void
sdda_process_mmc_partitions(struct cam_periph * periph,union ccb * ccb)1621 sdda_process_mmc_partitions(struct cam_periph *periph, union ccb *ccb)
1622 {
1623 	struct sdda_softc *sc = (struct sdda_softc *)periph->softc;
1624 	struct mmc_params *mmcp = &periph->path->device->mmc_ident_data;
1625 	off_t erase_size, sector_size, size, wp_size;
1626 	int i;
1627 	const uint8_t *ext_csd;
1628 	uint8_t rev;
1629 	bool comp, ro;
1630 
1631 	ext_csd = sc->raw_ext_csd;
1632 
1633 	/*
1634 	 * Enhanced user data area and general purpose partitions are only
1635 	 * supported in revision 1.4 (EXT_CSD_REV == 4) and later, the RPMB
1636 	 * partition in revision 1.5 (MMC v4.41, EXT_CSD_REV == 5) and later.
1637 	 */
1638 	rev = ext_csd[EXT_CSD_REV];
1639 
1640 	/*
1641 	 * Ignore user-creatable enhanced user data area and general purpose
1642 	 * partitions partitions as long as partitioning hasn't been finished.
1643 	 */
1644 	comp = (ext_csd[EXT_CSD_PART_SET] & EXT_CSD_PART_SET_COMPLETED) != 0;
1645 
1646 	/*
1647 	 * Add enhanced user data area slice, unless it spans the entirety of
1648 	 * the user data area.  The enhanced area is of a multiple of high
1649 	 * capacity write protect groups ((ERASE_GRP_SIZE + HC_WP_GRP_SIZE) *
1650 	 * 512 KB) and its offset given in either sectors or bytes, depending
1651 	 * on whether it's a high capacity device or not.
1652 	 * NB: The slicer and its slices need to be registered before adding
1653 	 *     the disk for the corresponding user data area as re-tasting is
1654 	 *     racy.
1655 	 */
1656 	sector_size = mmc_get_sector_size(periph);
1657 	size = ext_csd[EXT_CSD_ENH_SIZE_MULT] +
1658 		(ext_csd[EXT_CSD_ENH_SIZE_MULT + 1] << 8) +
1659 		(ext_csd[EXT_CSD_ENH_SIZE_MULT + 2] << 16);
1660 	if (rev >= 4 && comp == TRUE && size > 0 &&
1661 	    (ext_csd[EXT_CSD_PART_SUPPORT] &
1662 		EXT_CSD_PART_SUPPORT_ENH_ATTR_EN) != 0 &&
1663 	    (ext_csd[EXT_CSD_PART_ATTR] & (EXT_CSD_PART_ATTR_ENH_USR)) != 0) {
1664 		erase_size = ext_csd[EXT_CSD_ERASE_GRP_SIZE] * 1024 *
1665 			MMC_SECTOR_SIZE;
1666 		wp_size = ext_csd[EXT_CSD_HC_WP_GRP_SIZE];
1667 		size *= erase_size * wp_size;
1668 		if (size != mmc_get_media_size(periph) * sector_size) {
1669 			sc->enh_size = size;
1670 			sc->enh_base = (ext_csd[EXT_CSD_ENH_START_ADDR] +
1671 			    (ext_csd[EXT_CSD_ENH_START_ADDR + 1] << 8) +
1672 			    (ext_csd[EXT_CSD_ENH_START_ADDR + 2] << 16) +
1673 			    (ext_csd[EXT_CSD_ENH_START_ADDR + 3] << 24)) *
1674 				((mmcp->card_features & CARD_FEATURE_SDHC) ? 1: MMC_SECTOR_SIZE);
1675 		} else
1676 			CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH,
1677 			    ("enhanced user data area spans entire device"));
1678 	}
1679 
1680 	/*
1681 	 * Add default partition.  This may be the only one or the user
1682 	 * data area in case partitions are supported.
1683 	 */
1684 	ro = sdda_get_read_only(periph, ccb);
1685 	sdda_add_part(periph, EXT_CSD_PART_CONFIG_ACC_DEFAULT, "sdda",
1686 	    periph->unit_number, mmc_get_media_size(periph), ro);
1687 	sc->part_curr = EXT_CSD_PART_CONFIG_ACC_DEFAULT;
1688 
1689 	if (mmc_get_spec_vers(periph) < 3)
1690 		return;
1691 
1692 	/* Belatedly announce enhanced user data slice. */
1693 	if (sc->enh_size != 0) {
1694 		CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH,
1695 		    ("enhanced user data area off 0x%jx size %ju bytes\n",
1696 			sc->enh_base, sc->enh_size));
1697 	}
1698 
1699 	/*
1700 	 * Determine partition switch timeout (provided in units of 10 ms)
1701 	 * and ensure it's at least 300 ms as some eMMC chips lie.
1702 	 */
1703 	sc->part_time = max(ext_csd[EXT_CSD_PART_SWITCH_TO] * 10 * 1000,
1704 	    300 * 1000);
1705 
1706 	/* Add boot partitions, which are of a fixed multiple of 128 KB. */
1707 	size = ext_csd[EXT_CSD_BOOT_SIZE_MULT] * MMC_BOOT_RPMB_BLOCK_SIZE;
1708 	if (size > 0 && (sdda_get_host_caps(periph, ccb) & MMC_CAP_BOOT_NOACC) == 0) {
1709 		sdda_add_part(periph, EXT_CSD_PART_CONFIG_ACC_BOOT0,
1710 		    SDDA_FMT_BOOT, 0, size,
1711 		    ro | ((ext_csd[EXT_CSD_BOOT_WP_STATUS] &
1712 		    EXT_CSD_BOOT_WP_STATUS_BOOT0_MASK) != 0));
1713 		sdda_add_part(periph, EXT_CSD_PART_CONFIG_ACC_BOOT1,
1714 		    SDDA_FMT_BOOT, 1, size,
1715 		    ro | ((ext_csd[EXT_CSD_BOOT_WP_STATUS] &
1716 		    EXT_CSD_BOOT_WP_STATUS_BOOT1_MASK) != 0));
1717 	}
1718 
1719 	/* Add RPMB partition, which also is of a fixed multiple of 128 KB. */
1720 	size = ext_csd[EXT_CSD_RPMB_MULT] * MMC_BOOT_RPMB_BLOCK_SIZE;
1721 	if (rev >= 5 && size > 0)
1722 		sdda_add_part(periph, EXT_CSD_PART_CONFIG_ACC_RPMB,
1723 		    SDDA_FMT_RPMB, 0, size, ro);
1724 
1725 	if (rev <= 3 || comp == FALSE)
1726 		return;
1727 
1728 	/*
1729 	 * Add general purpose partitions, which are of a multiple of high
1730 	 * capacity write protect groups, too.
1731 	 */
1732 	if ((ext_csd[EXT_CSD_PART_SUPPORT] & EXT_CSD_PART_SUPPORT_EN) != 0) {
1733 		erase_size = ext_csd[EXT_CSD_ERASE_GRP_SIZE] * 1024 *
1734 			MMC_SECTOR_SIZE;
1735 		wp_size = ext_csd[EXT_CSD_HC_WP_GRP_SIZE];
1736 		for (i = 0; i < MMC_PART_GP_MAX; i++) {
1737 			size = ext_csd[EXT_CSD_GP_SIZE_MULT + i * 3] +
1738 				(ext_csd[EXT_CSD_GP_SIZE_MULT + i * 3 + 1] << 8) +
1739 				(ext_csd[EXT_CSD_GP_SIZE_MULT + i * 3 + 2] << 16);
1740 			if (size == 0)
1741 				continue;
1742 			sdda_add_part(periph, EXT_CSD_PART_CONFIG_ACC_GP0 + i,
1743 			    SDDA_FMT_GP, i, size * erase_size * wp_size, ro);
1744 		}
1745 	}
1746 }
1747 
1748 /*
1749  * We cannot just call mmc_switch() since it will sleep, and we are in
1750  * GEOM context and cannot sleep. Instead, create an MMCIO request to switch
1751  * partitions and send it to h/w, and upon completion resume processing
1752  * the I/O queue.
1753  * This function cannot fail, instead check switch errors in sddadone().
1754  */
1755 static void
sdda_init_switch_part(struct cam_periph * periph,union ccb * start_ccb,uint8_t part)1756 sdda_init_switch_part(struct cam_periph *periph, union ccb *start_ccb,
1757     uint8_t part)
1758 {
1759 	struct sdda_softc *sc = (struct sdda_softc *)periph->softc;
1760 	uint8_t value;
1761 
1762 	KASSERT(part < MMC_PART_MAX, ("%s: invalid partition index", __func__));
1763 	sc->part_requested = part;
1764 
1765 	value = (sc->raw_ext_csd[EXT_CSD_PART_CONFIG] &
1766 	    ~EXT_CSD_PART_CONFIG_ACC_MASK) | part;
1767 
1768 	mmc_switch_fill_mmcio(start_ccb, EXT_CSD_CMD_SET_NORMAL,
1769 	    EXT_CSD_PART_CONFIG, value, sc->part_time);
1770 	start_ccb->ccb_h.cbfcnp = sddadone;
1771 
1772 	sc->outstanding_cmds++;
1773 	cam_periph_unlock(periph);
1774 	xpt_action(start_ccb);
1775 	cam_periph_lock(periph);
1776 }
1777 
1778 /* Called with periph lock held! */
1779 static void
sddastart(struct cam_periph * periph,union ccb * start_ccb)1780 sddastart(struct cam_periph *periph, union ccb *start_ccb)
1781 {
1782 	struct bio *bp;
1783 	struct sdda_softc *softc = (struct sdda_softc *)periph->softc;
1784 	struct sdda_part *part;
1785 	struct mmc_params *mmcp = &periph->path->device->mmc_ident_data;
1786 	uint8_t part_index;
1787 
1788 	CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("sddastart\n"));
1789 
1790 	if (softc->state != SDDA_STATE_NORMAL) {
1791 		CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("device is not in SDDA_STATE_NORMAL yet\n"));
1792 		xpt_release_ccb(start_ccb);
1793 		return;
1794 	}
1795 
1796 	/* Find partition that has outstanding commands.  Prefer current partition. */
1797 	part_index = softc->part_curr;
1798 	part = softc->part[softc->part_curr];
1799 	bp = bioq_first(&part->bio_queue);
1800 	if (bp == NULL) {
1801 		for (part_index = 0; part_index < MMC_PART_MAX; part_index++) {
1802 			if ((part = softc->part[part_index]) != NULL &&
1803 			    (bp = bioq_first(&softc->part[part_index]->bio_queue)) != NULL)
1804 				break;
1805 		}
1806 	}
1807 	if (bp == NULL) {
1808 		xpt_release_ccb(start_ccb);
1809 		return;
1810 	}
1811 	if (part_index != softc->part_curr) {
1812 		CAM_DEBUG(periph->path, CAM_DEBUG_PERIPH,
1813 		    ("Partition  %d -> %d\n", softc->part_curr, part_index));
1814 		/*
1815 		 * According to section "6.2.2 Command restrictions" of the eMMC
1816 		 * specification v5.1, CMD19/CMD21 aren't allowed to be used with
1817 		 * RPMB partitions.  So we pause re-tuning along with triggering
1818 		 * it up-front to decrease the likelihood of re-tuning becoming
1819 		 * necessary while accessing an RPMB partition.  Consequently, an
1820 		 * RPMB partition should immediately be switched away from again
1821 		 * after an access in order to allow for re-tuning to take place
1822 		 * anew.
1823 		 */
1824 		/* TODO: pause retune if switching to RPMB partition */
1825 		softc->state = SDDA_STATE_PART_SWITCH;
1826 		sdda_init_switch_part(periph, start_ccb, part_index);
1827 		return;
1828 	}
1829 
1830 	bioq_remove(&part->bio_queue, bp);
1831 
1832 	switch (bp->bio_cmd) {
1833 	case BIO_WRITE:
1834 		CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("BIO_WRITE\n"));
1835 		part->flags |= SDDA_FLAG_DIRTY;
1836 		/* FALLTHROUGH */
1837 	case BIO_READ:
1838 	{
1839 		struct ccb_mmcio *mmcio;
1840 		uint64_t blockno = bp->bio_pblkno;
1841 		uint16_t count = bp->bio_bcount / MMC_SECTOR_SIZE;
1842 		uint16_t opcode;
1843 
1844 		if (bp->bio_cmd == BIO_READ)
1845 			CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("BIO_READ\n"));
1846 		CAM_DEBUG(periph->path, CAM_DEBUG_TRACE,
1847 		    ("Block %"PRIu64" cnt %u\n", blockno, count));
1848 
1849 		/* Construct new MMC command */
1850 		if (bp->bio_cmd == BIO_READ) {
1851 			if (count > 1)
1852 				opcode = MMC_READ_MULTIPLE_BLOCK;
1853 			else
1854 				opcode = MMC_READ_SINGLE_BLOCK;
1855 		} else {
1856 			if (count > 1)
1857 				opcode = MMC_WRITE_MULTIPLE_BLOCK;
1858 			else
1859 				opcode = MMC_WRITE_BLOCK;
1860 		}
1861 
1862 		start_ccb->ccb_h.func_code = XPT_MMC_IO;
1863 		start_ccb->ccb_h.flags = (bp->bio_cmd == BIO_READ ? CAM_DIR_IN : CAM_DIR_OUT);
1864 		start_ccb->ccb_h.retry_count = 0;
1865 		start_ccb->ccb_h.timeout = 15 * 1000;
1866 		start_ccb->ccb_h.cbfcnp = sddadone;
1867 
1868 		mmcio = &start_ccb->mmcio;
1869 		mmcio->cmd.opcode = opcode;
1870 		mmcio->cmd.arg = blockno;
1871 		if (!(mmcp->card_features & CARD_FEATURE_SDHC))
1872 			mmcio->cmd.arg <<= 9;
1873 
1874 		mmcio->cmd.flags = MMC_RSP_R1 | MMC_CMD_ADTC;
1875 		mmcio->cmd.data = softc->mmcdata;
1876 		memset(mmcio->cmd.data, 0, sizeof(struct mmc_data));
1877 		mmcio->cmd.data->data = bp->bio_data;
1878 		mmcio->cmd.data->len = MMC_SECTOR_SIZE * count;
1879 		mmcio->cmd.data->flags = (bp->bio_cmd == BIO_READ ? MMC_DATA_READ : MMC_DATA_WRITE);
1880 		/* Direct h/w to issue CMD12 upon completion */
1881 		if (count > 1) {
1882 			mmcio->cmd.data->flags |= MMC_DATA_MULTI;
1883 			mmcio->stop.opcode = MMC_STOP_TRANSMISSION;
1884 			mmcio->stop.flags = MMC_RSP_R1B | MMC_CMD_AC;
1885 			mmcio->stop.arg = 0;
1886 		}
1887 
1888 		break;
1889 	}
1890 	case BIO_FLUSH:
1891 		CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("BIO_FLUSH\n"));
1892 		sddaschedule(periph);
1893 		break;
1894 	case BIO_DELETE:
1895 		CAM_DEBUG(periph->path, CAM_DEBUG_TRACE, ("BIO_DELETE\n"));
1896 		sddaschedule(periph);
1897 		break;
1898 	default:
1899 		biofinish(bp, NULL, EOPNOTSUPP);
1900 		xpt_release_ccb(start_ccb);
1901 		return;
1902 	}
1903 	start_ccb->ccb_h.ccb_bp = bp;
1904 	softc->outstanding_cmds++;
1905 	softc->refcount++;
1906 	cam_periph_unlock(periph);
1907 	xpt_action(start_ccb);
1908 	cam_periph_lock(periph);
1909 
1910 	/* May have more work to do, so ensure we stay scheduled */
1911 	sddaschedule(periph);
1912 }
1913 
1914 static void
sddadone(struct cam_periph * periph,union ccb * done_ccb)1915 sddadone(struct cam_periph *periph, union ccb *done_ccb)
1916 {
1917 	struct bio *bp;
1918 	struct sdda_softc *softc;
1919 	struct ccb_mmcio *mmcio;
1920 	struct cam_path *path;
1921 	uint32_t card_status;
1922 	int error = 0;
1923 
1924 	softc = (struct sdda_softc *)periph->softc;
1925 	mmcio = &done_ccb->mmcio;
1926 	path = done_ccb->ccb_h.path;
1927 
1928 	CAM_DEBUG(path, CAM_DEBUG_TRACE, ("sddadone\n"));
1929 	if ((done_ccb->ccb_h.status & CAM_STATUS_MASK) != CAM_REQ_CMP) {
1930 		CAM_DEBUG(path, CAM_DEBUG_TRACE, ("Error!!!\n"));
1931 		if ((done_ccb->ccb_h.status & CAM_DEV_QFRZN) != 0)
1932 			cam_release_devq(path,
1933 			    /*relsim_flags*/0,
1934 			    /*reduction*/0,
1935 			    /*timeout*/0,
1936 			    /*getcount_only*/0);
1937 		error = EIO;
1938 	} else {
1939 		if ((done_ccb->ccb_h.status & CAM_DEV_QFRZN) != 0)
1940 			panic("REQ_CMP with QFRZN");
1941 		error = 0;
1942 	}
1943 
1944 	card_status = mmcio->cmd.resp[0];
1945 	CAM_DEBUG(path, CAM_DEBUG_TRACE,
1946 	    ("Card status: %08x\n", R1_STATUS(card_status)));
1947 	CAM_DEBUG(path, CAM_DEBUG_TRACE,
1948 	    ("Current state: %d\n", R1_CURRENT_STATE(card_status)));
1949 
1950 	/* Process result of switching MMC partitions */
1951 	if (softc->state == SDDA_STATE_PART_SWITCH) {
1952 		CAM_DEBUG(path, CAM_DEBUG_TRACE,
1953 		    ("Completing partition switch to %d\n",
1954 		    softc->part_requested));
1955 		softc->outstanding_cmds--;
1956 		/* Complete partition switch */
1957 		softc->state = SDDA_STATE_NORMAL;
1958 		if (error != 0) {
1959 			/* TODO: Unpause retune if accessing RPMB */
1960 			xpt_release_ccb(done_ccb);
1961 			xpt_schedule(periph, CAM_PRIORITY_NORMAL);
1962 			return;
1963 		}
1964 
1965 		softc->raw_ext_csd[EXT_CSD_PART_CONFIG] =
1966 		    (softc->raw_ext_csd[EXT_CSD_PART_CONFIG] &
1967 			~EXT_CSD_PART_CONFIG_ACC_MASK) | softc->part_requested;
1968 		/* TODO: Unpause retune if accessing RPMB */
1969 		softc->part_curr = softc->part_requested;
1970 		xpt_release_ccb(done_ccb);
1971 
1972 		/* Return to processing BIO requests */
1973 		xpt_schedule(periph, CAM_PRIORITY_NORMAL);
1974 		return;
1975 	}
1976 
1977 	bp = (struct bio *)done_ccb->ccb_h.ccb_bp;
1978 	bp->bio_error = error;
1979 	if (error != 0) {
1980 		bp->bio_resid = bp->bio_bcount;
1981 		bp->bio_flags |= BIO_ERROR;
1982 	} else {
1983 		/* XXX: How many bytes remaining? */
1984 		bp->bio_resid = 0;
1985 		if (bp->bio_resid > 0)
1986 			bp->bio_flags |= BIO_ERROR;
1987 	}
1988 
1989 	softc->outstanding_cmds--;
1990 	xpt_release_ccb(done_ccb);
1991 	/*
1992 	 * Release the periph refcount taken in sddastart() for each CCB.
1993 	 */
1994 	KASSERT(softc->refcount >= 1, ("sddadone softc %p refcount %d", softc, softc->refcount));
1995 	softc->refcount--;
1996 	biodone(bp);
1997 }
1998 
1999 static int
sddaerror(union ccb * ccb,u_int32_t cam_flags,u_int32_t sense_flags)2000 sddaerror(union ccb *ccb, u_int32_t cam_flags, u_int32_t sense_flags)
2001 {
2002 	return(cam_periph_error(ccb, cam_flags, sense_flags));
2003 }
2004 
2005 static int
sddadump(void * arg,void * virtual,vm_offset_t physical,off_t offset,size_t length)2006 sddadump(void *arg, void *virtual, vm_offset_t physical, off_t offset,
2007     size_t length)
2008 {
2009 	struct ccb_mmcio mmcio;
2010 	struct disk *dp;
2011 	struct sdda_part *part;
2012 	struct sdda_softc *softc;
2013 	struct cam_periph *periph;
2014 	struct mmc_params *mmcp;
2015 	uint16_t count;
2016 	uint16_t opcode;
2017 	int error;
2018 
2019 	dp = arg;
2020 	part = dp->d_drv1;
2021 	softc = part->sc;
2022 	periph = softc->periph;
2023 	mmcp = &periph->path->device->mmc_ident_data;
2024 
2025 	if (softc->state != SDDA_STATE_NORMAL)
2026 		return (ENXIO);
2027 
2028 	count = length / MMC_SECTOR_SIZE;
2029 	if (count == 0)
2030 		return (0);
2031 
2032 	if (softc->part[softc->part_curr] != part)
2033 		return (EIO);	/* TODO implement polled partition switch */
2034 
2035 	memset(&mmcio, 0, sizeof(mmcio));
2036 	xpt_setup_ccb(&mmcio.ccb_h, periph->path, CAM_PRIORITY_NORMAL); /* XXX needed? */
2037 
2038 	mmcio.ccb_h.func_code = XPT_MMC_IO;
2039 	mmcio.ccb_h.flags = CAM_DIR_OUT;
2040 	mmcio.ccb_h.retry_count = 0;
2041 	mmcio.ccb_h.timeout = 15 * 1000;
2042 
2043 	if (count > 1)
2044 		opcode = MMC_WRITE_MULTIPLE_BLOCK;
2045 	else
2046 		opcode = MMC_WRITE_BLOCK;
2047 	mmcio.cmd.opcode = opcode;
2048 	mmcio.cmd.arg = offset / MMC_SECTOR_SIZE;
2049 	if (!(mmcp->card_features & CARD_FEATURE_SDHC))
2050 		mmcio.cmd.arg <<= 9;
2051 
2052 	mmcio.cmd.flags = MMC_RSP_R1 | MMC_CMD_ADTC;
2053 	mmcio.cmd.data = softc->mmcdata;
2054 	memset(mmcio.cmd.data, 0, sizeof(struct mmc_data));
2055 	mmcio.cmd.data->data = virtual;
2056 	mmcio.cmd.data->len = MMC_SECTOR_SIZE * count;
2057 	mmcio.cmd.data->flags = MMC_DATA_WRITE;
2058 
2059 	/* Direct h/w to issue CMD12 upon completion */
2060 	if (count > 1) {
2061 		mmcio.cmd.data->flags |= MMC_DATA_MULTI;
2062 		mmcio.stop.opcode = MMC_STOP_TRANSMISSION;
2063 		mmcio.stop.flags = MMC_RSP_R1B | MMC_CMD_AC;
2064 		mmcio.stop.arg = 0;
2065 	}
2066 
2067 	error = cam_periph_runccb((union ccb *)&mmcio, cam_periph_error,
2068 	    0, SF_NO_RECOVERY | SF_NO_RETRY, NULL);
2069 	if (error != 0)
2070 		printf("Aborting dump due to I/O error.\n");
2071 	return (error);
2072 }
2073 
2074 #endif /* _KERNEL */
2075