xref: /freebsd-12.1/sys/dev/aha/aha.c (revision d8dfc65f)
1 /*-
2  * Generic register and struct definitions for the Adaptech 154x
3  * SCSI host adapters. Product specific probe and attach routines can
4  * be found in:
5  *      aha 1542A/1542B/1542C/1542CF/1542CP	aha_isa.c
6  */
7 /*-
8  * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
9  *
10  * Copyright (c) 1998 M. Warner Losh.
11  * All Rights Reserved.
12  *
13  * Redistribution and use in source and binary forms, with or without
14  * modification, are permitted provided that the following conditions
15  * are met:
16  * 1. Redistributions of source code must retain the above copyright
17  *    notice, this list of conditions and the following disclaimer.
18  * 2. Redistributions in binary form must reproduce the above copyright
19  *    notice, this list of conditions and the following disclaimer in the
20  *    documentation and/or other materials provided with the distribution.
21  *
22  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
23  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
26  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32  * SUCH DAMAGE.
33  *
34  * Derived from bt.c written by:
35  *
36  * Copyright (c) 1998 Justin T. Gibbs.
37  * All rights reserved.
38  *
39  * Redistribution and use in source and binary forms, with or without
40  * modification, are permitted provided that the following conditions
41  * are met:
42  * 1. Redistributions of source code must retain the above copyright
43  *    notice, this list of conditions, and the following disclaimer,
44  *    without modification, immediately at the beginning of the file.
45  * 2. The name of the author may not be used to endorse or promote products
46  *    derived from this software without specific prior written permission.
47  *
48  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
49  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
50  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
51  * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR
52  * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
53  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
54  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
55  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
56  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
57  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
58  * SUCH DAMAGE.
59  */
60 
61 #include <sys/cdefs.h>
62 __FBSDID("$FreeBSD$");
63 
64 #include <sys/param.h>
65 #include <sys/conf.h>
66 #include <sys/bus.h>
67 #include <sys/systm.h>
68 #include <sys/malloc.h>
69 #include <sys/kernel.h>
70 #include <sys/lock.h>
71 #include <sys/module.h>
72 #include <sys/mutex.h>
73 #include <sys/rman.h>
74 
75 #include <machine/bus.h>
76 
77 #include <cam/cam.h>
78 #include <cam/cam_ccb.h>
79 #include <cam/cam_sim.h>
80 #include <cam/cam_xpt_sim.h>
81 #include <cam/cam_debug.h>
82 
83 #include <cam/scsi/scsi_message.h>
84 
85 #include <dev/aha/ahareg.h>
86 
87 #define	PRVERB(x) do { if (bootverbose) device_printf x; } while (0)
88 
89 /* Macro to determine that a rev is potentially a new valid one
90  * so that the driver doesn't keep breaking on new revs as it
91  * did for the CF and CP.
92  */
93 #define PROBABLY_NEW_BOARD(REV) (REV > 0x43 && REV < 0x56)
94 
95 /* MailBox Management functions */
96 static __inline void	ahanextinbox(struct aha_softc *aha);
97 static __inline void	ahanextoutbox(struct aha_softc *aha);
98 
99 #define aha_name(aha)	device_get_nameunit(aha->dev)
100 
101 static __inline void
102 ahanextinbox(struct aha_softc *aha)
103 {
104 	if (aha->cur_inbox == aha->last_inbox)
105 		aha->cur_inbox = aha->in_boxes;
106 	else
107 		aha->cur_inbox++;
108 }
109 
110 static __inline void
111 ahanextoutbox(struct aha_softc *aha)
112 {
113 	if (aha->cur_outbox == aha->last_outbox)
114 		aha->cur_outbox = aha->out_boxes;
115 	else
116 		aha->cur_outbox++;
117 }
118 
119 #define ahautoa24(u,s3)			\
120 	(s3)[0] = ((u) >> 16) & 0xff;	\
121 	(s3)[1] = ((u) >> 8) & 0xff;	\
122 	(s3)[2] = (u) & 0xff;
123 
124 #define aha_a24tou(s3) \
125 	(((s3)[0] << 16) | ((s3)[1] << 8) | (s3)[2])
126 
127 /* CCB Management functions */
128 static __inline uint32_t		ahaccbvtop(struct aha_softc *aha,
129 						  struct aha_ccb *accb);
130 static __inline struct aha_ccb*		ahaccbptov(struct aha_softc *aha,
131 						  uint32_t ccb_addr);
132 
133 static __inline uint32_t
134 ahaccbvtop(struct aha_softc *aha, struct aha_ccb *accb)
135 {
136 	return (aha->aha_ccb_physbase
137 	      + (uint32_t)((caddr_t)accb - (caddr_t)aha->aha_ccb_array));
138 }
139 static __inline struct aha_ccb *
140 ahaccbptov(struct aha_softc *aha, uint32_t ccb_addr)
141 {
142 	return (aha->aha_ccb_array +
143 	      + ((struct aha_ccb*)(uintptr_t)ccb_addr -
144 	         (struct aha_ccb*)(uintptr_t)aha->aha_ccb_physbase));
145 }
146 
147 static struct aha_ccb*	ahagetccb(struct aha_softc *aha);
148 static __inline void	ahafreeccb(struct aha_softc *aha, struct aha_ccb *accb);
149 static void		ahaallocccbs(struct aha_softc *aha);
150 static bus_dmamap_callback_t ahaexecuteccb;
151 static void		ahadone(struct aha_softc *aha, struct aha_ccb *accb,
152 			       aha_mbi_comp_code_t comp_code);
153 static void		aha_intr_locked(struct aha_softc *aha);
154 
155 /* Host adapter command functions */
156 static int	ahareset(struct aha_softc* aha, int hard_reset);
157 
158 /* Initialization functions */
159 static int			ahainitmboxes(struct aha_softc *aha);
160 static bus_dmamap_callback_t	ahamapmboxes;
161 static bus_dmamap_callback_t	ahamapccbs;
162 static bus_dmamap_callback_t	ahamapsgs;
163 
164 /* Transfer Negotiation Functions */
165 static void ahafetchtransinfo(struct aha_softc *aha,
166 			     struct ccb_trans_settings *cts);
167 
168 /* CAM SIM entry points */
169 #define ccb_accb_ptr spriv_ptr0
170 #define ccb_aha_ptr spriv_ptr1
171 static void	ahaaction(struct cam_sim *sim, union ccb *ccb);
172 static void	ahapoll(struct cam_sim *sim);
173 
174 /* Our timeout handler */
175 static void	ahatimeout(void *arg);
176 
177 /* Exported functions */
178 void
179 aha_alloc(struct aha_softc *aha)
180 {
181 
182 	SLIST_INIT(&aha->free_aha_ccbs);
183 	LIST_INIT(&aha->pending_ccbs);
184 	SLIST_INIT(&aha->sg_maps);
185 	aha->ccb_sg_opcode = INITIATOR_SG_CCB_WRESID;
186 	aha->ccb_ccb_opcode = INITIATOR_CCB_WRESID;
187 	mtx_init(&aha->lock, "aha", NULL, MTX_DEF);
188 }
189 
190 void
191 aha_free(struct aha_softc *aha)
192 {
193 	switch (aha->init_level) {
194 	default:
195 	case 8:
196 	{
197 		struct sg_map_node *sg_map;
198 
199 		while ((sg_map = SLIST_FIRST(&aha->sg_maps))!= NULL) {
200 			SLIST_REMOVE_HEAD(&aha->sg_maps, links);
201 			bus_dmamap_unload(aha->sg_dmat, sg_map->sg_dmamap);
202 			bus_dmamem_free(aha->sg_dmat, sg_map->sg_vaddr,
203 			    sg_map->sg_dmamap);
204 			free(sg_map, M_DEVBUF);
205 		}
206 		bus_dma_tag_destroy(aha->sg_dmat);
207 	}
208 	case 7:
209 		bus_dmamap_unload(aha->ccb_dmat, aha->ccb_dmamap);
210 	case 6:
211 		bus_dmamem_free(aha->ccb_dmat, aha->aha_ccb_array,
212 		    aha->ccb_dmamap);
213 	case 5:
214 		bus_dma_tag_destroy(aha->ccb_dmat);
215 	case 4:
216 		bus_dmamap_unload(aha->mailbox_dmat, aha->mailbox_dmamap);
217 	case 3:
218 		bus_dmamem_free(aha->mailbox_dmat, aha->in_boxes,
219 		    aha->mailbox_dmamap);
220 	case 2:
221 		bus_dma_tag_destroy(aha->buffer_dmat);
222 	case 1:
223 		bus_dma_tag_destroy(aha->mailbox_dmat);
224 	case 0:
225 		break;
226 	}
227 	mtx_destroy(&aha->lock);
228 }
229 
230 /*
231  * Probe the adapter and verify that the card is an Adaptec.
232  */
233 int
234 aha_probe(struct aha_softc* aha)
235 {
236 	u_int	 status;
237 	u_int	 intstat;
238 	int	 error;
239 	board_id_data_t	board_id;
240 
241 	/*
242 	 * See if the three I/O ports look reasonable.
243 	 * Touch the minimal number of registers in the
244 	 * failure case.
245 	 */
246 	status = aha_inb(aha, STATUS_REG);
247 	if ((status == 0) ||
248 	    (status & (DIAG_ACTIVE|CMD_REG_BUSY | STATUS_REG_RSVD)) != 0) {
249 		PRVERB((aha->dev, "status reg test failed %x\n", status));
250 		return (ENXIO);
251 	}
252 
253 	intstat = aha_inb(aha, INTSTAT_REG);
254 	if ((intstat & INTSTAT_REG_RSVD) != 0) {
255 		PRVERB((aha->dev, "Failed Intstat Reg Test\n"));
256 		return (ENXIO);
257 	}
258 
259 	/*
260 	 * Looking good so far.  Final test is to reset the
261 	 * adapter and fetch the board ID and ensure we aren't
262 	 * looking at a BusLogic.
263 	 */
264 	if ((error = ahareset(aha, /*hard_reset*/TRUE)) != 0) {
265 		PRVERB((aha->dev, "Failed Reset\n"));
266 		return (ENXIO);
267 	}
268 
269 	/*
270 	 * Get the board ID.  We use this to see if we're dealing with
271 	 * a buslogic card or an aha card (or clone).
272 	 */
273 	error = aha_cmd(aha, AOP_INQUIRE_BOARD_ID, NULL, /*parmlen*/0,
274 	    (uint8_t*)&board_id, sizeof(board_id), DEFAULT_CMD_TIMEOUT);
275 	if (error != 0) {
276 		PRVERB((aha->dev, "INQUIRE failed %x\n", error));
277 		return (ENXIO);
278 	}
279 	aha->fw_major = board_id.firmware_rev_major;
280 	aha->fw_minor = board_id.firmware_rev_minor;
281 	aha->boardid = board_id.board_type;
282 
283 	/*
284 	 * The Buslogic cards have an id of either 0x41 or 0x42.  So
285 	 * if those come up in the probe, we test the geometry register
286 	 * of the board.  Adaptec boards that are this old will not have
287 	 * this register, and return 0xff, while buslogic cards will return
288 	 * something different.
289 	 *
290 	 * It appears that for reasons unknow, for the for the
291 	 * aha-1542B cards, we need to wait a little bit before trying
292 	 * to read the geometry register.  I picked 10ms since we have
293 	 * reports that a for loop to 1000 did the trick, and this
294 	 * errs on the side of conservatism.  Besides, no one will
295 	 * notice a 10mS delay here, even the 1542B card users :-)
296 	 *
297 	 * Some compatible cards return 0 here.  Some cards also
298 	 * seem to return 0x7f.
299 	 *
300 	 * XXX I'm not sure how this will impact other cloned cards
301 	 *
302 	 * This really should be replaced with the esetup command, since
303 	 * that appears to be more reliable.  This becomes more and more
304 	 * true over time as we discover more cards that don't read the
305 	 * geometry register consistently.
306 	 */
307 	if (aha->boardid <= 0x42) {
308 		/* Wait 10ms before reading */
309 		DELAY(10000);
310 		status = aha_inb(aha, GEOMETRY_REG);
311 		if (status != 0xff && status != 0x00 && status != 0x7f) {
312 			PRVERB((aha->dev, "Geometry Register test failed %#x\n",
313 				status));
314 			return (ENXIO);
315 		}
316 	}
317 
318 	return (0);
319 }
320 
321 /*
322  * Pull the boards setup information and record it in our softc.
323  */
324 int
325 aha_fetch_adapter_info(struct aha_softc *aha)
326 {
327 	setup_data_t	setup_info;
328 	config_data_t config_data;
329 	uint8_t length_param;
330 	int	 error;
331 	struct	aha_extbios extbios;
332 
333 	switch (aha->boardid) {
334 	case BOARD_1540_16HEAD_BIOS:
335 		snprintf(aha->model, sizeof(aha->model), "1540 16 head BIOS");
336 		break;
337 	case BOARD_1540_64HEAD_BIOS:
338 		snprintf(aha->model, sizeof(aha->model), "1540 64 head BIOS");
339 		break;
340 	case BOARD_1542:
341 		snprintf(aha->model, sizeof(aha->model), "1540/1542 64 head BIOS");
342 		break;
343 	case BOARD_1542C:
344 		snprintf(aha->model, sizeof(aha->model), "1542C");
345 		break;
346 	case BOARD_1542CF:
347 		snprintf(aha->model, sizeof(aha->model), "1542CF");
348 		break;
349 	case BOARD_1542CP:
350 		snprintf(aha->model, sizeof(aha->model), "1542CP");
351 		break;
352 	default:
353 		snprintf(aha->model, sizeof(aha->model), "Unknown");
354 		break;
355 	}
356 	/*
357 	 * If we are a new type of 1542 board (anything newer than a 1542C)
358 	 * then disable the extended bios so that the
359 	 * mailbox interface is unlocked.
360 	 * This is also true for the 1542B Version 3.20. First Adaptec
361 	 * board that supports >1Gb drives.
362 	 * No need to check the extended bios flags as some of the
363 	 * extensions that cause us problems are not flagged in that byte.
364 	 */
365 	if (PROBABLY_NEW_BOARD(aha->boardid) ||
366 		(aha->boardid == 0x41
367 		&& aha->fw_major == 0x31 &&
368 		aha->fw_minor >= 0x34)) {
369 		error = aha_cmd(aha, AOP_RETURN_EXT_BIOS_INFO, NULL,
370 		    /*paramlen*/0, (u_char *)&extbios, sizeof(extbios),
371 		    DEFAULT_CMD_TIMEOUT);
372 		if (error != 0) {
373 			device_printf(aha->dev,
374 			    "AOP_RETURN_EXT_BIOS_INFO - Failed.");
375 			return (error);
376 		}
377 		error = aha_cmd(aha, AOP_MBOX_IF_ENABLE, (uint8_t *)&extbios,
378 		    /*paramlen*/2, NULL, 0, DEFAULT_CMD_TIMEOUT);
379 		if (error != 0) {
380 			device_printf(aha->dev, "AOP_MBOX_IF_ENABLE - Failed.");
381 			return (error);
382 		}
383 	}
384 	if (aha->boardid < 0x41)
385 		device_printf(aha->dev, "Warning: aha-1542A won't work.\n");
386 
387 	aha->max_sg = 17;		/* Need >= 17 to do 64k I/O */
388 	aha->diff_bus = 0;
389 	aha->extended_lun = 0;
390 	aha->extended_trans = 0;
391 	aha->max_ccbs = 16;
392 	/* Determine Sync/Wide/Disc settings */
393 	length_param = sizeof(setup_info);
394 	error = aha_cmd(aha, AOP_INQUIRE_SETUP_INFO, &length_param,
395 	    /*paramlen*/1, (uint8_t*)&setup_info, sizeof(setup_info),
396 	    DEFAULT_CMD_TIMEOUT);
397 	if (error != 0) {
398 		device_printf(aha->dev, "aha_fetch_adapter_info - Failed "
399 		    "Get Setup Info\n");
400 		return (error);
401 	}
402 	if (setup_info.initiate_sync != 0) {
403 		aha->sync_permitted = ALL_TARGETS;
404 	}
405 	aha->disc_permitted = ALL_TARGETS;
406 
407 	/* We need as many mailboxes as we can have ccbs */
408 	aha->num_boxes = aha->max_ccbs;
409 
410 	/* Determine our SCSI ID */
411 	error = aha_cmd(aha, AOP_INQUIRE_CONFIG, NULL, /*parmlen*/0,
412 	    (uint8_t*)&config_data, sizeof(config_data), DEFAULT_CMD_TIMEOUT);
413 	if (error != 0) {
414 		device_printf(aha->dev,
415 		    "aha_fetch_adapter_info - Failed Get Config\n");
416 		return (error);
417 	}
418 	aha->scsi_id = config_data.scsi_id;
419 	return (0);
420 }
421 
422 /*
423  * Start the board, ready for normal operation
424  */
425 int
426 aha_init(struct aha_softc* aha)
427 {
428 	/* Announce the Adapter */
429 	device_printf(aha->dev, "AHA-%s FW Rev. %c.%c (ID=%x) ",
430 	    aha->model, aha->fw_major, aha->fw_minor, aha->boardid);
431 
432 	if (aha->diff_bus != 0)
433 		printf("Diff ");
434 
435 	printf("SCSI Host Adapter, SCSI ID %d, %d CCBs\n", aha->scsi_id,
436 	    aha->max_ccbs);
437 
438 	/*
439 	 * Create our DMA tags.  These tags define the kinds of device
440 	 * accessible memory allocations and memory mappings we will
441 	 * need to perform during normal operation.
442 	 *
443 	 * Unless we need to further restrict the allocation, we rely
444 	 * on the restrictions of the parent dmat, hence the common
445 	 * use of MAXADDR and MAXSIZE.
446 	 */
447 
448 	/* DMA tag for mapping buffers into device visible space. */
449 	if (bus_dma_tag_create( /* parent	*/ aha->parent_dmat,
450 				/* alignment	*/ 1,
451 				/* boundary	*/ 0,
452 				/* lowaddr	*/ BUS_SPACE_MAXADDR,
453 				/* highaddr	*/ BUS_SPACE_MAXADDR,
454 				/* filter	*/ NULL,
455 				/* filterarg	*/ NULL,
456 				/* maxsize	*/ DFLTPHYS,
457 				/* nsegments	*/ AHA_NSEG,
458 				/* maxsegsz	*/ BUS_SPACE_MAXSIZE_24BIT,
459 				/* flags	*/ BUS_DMA_ALLOCNOW,
460 				/* lockfunc	*/ busdma_lock_mutex,
461 				/* lockarg	*/ &aha->lock,
462 				&aha->buffer_dmat) != 0) {
463 		goto error_exit;
464 	}
465 
466 	aha->init_level++;
467 	/* DMA tag for our mailboxes */
468 	if (bus_dma_tag_create(	/* parent	*/ aha->parent_dmat,
469 				/* alignment	*/ 1,
470 				/* boundary	*/ 0,
471 				/* lowaddr	*/ BUS_SPACE_MAXADDR,
472 				/* highaddr	*/ BUS_SPACE_MAXADDR,
473 				/* filter	*/ NULL,
474 				/* filterarg	*/ NULL,
475 				/* maxsize	*/ aha->num_boxes *
476 						   (sizeof(aha_mbox_in_t) +
477 						    sizeof(aha_mbox_out_t)),
478 				/* nsegments	*/ 1,
479 				/* maxsegsz	*/ BUS_SPACE_MAXSIZE_24BIT,
480 				/* flags	*/ 0,
481 				/* lockfunc	*/ NULL,
482 				/* lockarg	*/ NULL,
483 				&aha->mailbox_dmat) != 0) {
484 		goto error_exit;
485         }
486 
487 	aha->init_level++;
488 
489 	/* Allocation for our mailboxes */
490 	if (bus_dmamem_alloc(aha->mailbox_dmat, (void **)&aha->out_boxes,
491 	    BUS_DMA_NOWAIT, &aha->mailbox_dmamap) != 0)
492 		goto error_exit;
493 
494 	aha->init_level++;
495 
496 	/* And permanently map them */
497 	bus_dmamap_load(aha->mailbox_dmat, aha->mailbox_dmamap,
498 	    aha->out_boxes, aha->num_boxes * (sizeof(aha_mbox_in_t) +
499 	    sizeof(aha_mbox_out_t)), ahamapmboxes, aha, /*flags*/0);
500 
501 	aha->init_level++;
502 
503 	aha->in_boxes = (aha_mbox_in_t *)&aha->out_boxes[aha->num_boxes];
504 
505 	ahainitmboxes(aha);
506 
507 	/* DMA tag for our ccb structures */
508 	if (bus_dma_tag_create(	/* parent	*/ aha->parent_dmat,
509 				/* alignment	*/ 1,
510 				/* boundary	*/ 0,
511 				/* lowaddr	*/ BUS_SPACE_MAXADDR,
512 				/* highaddr	*/ BUS_SPACE_MAXADDR,
513 				/* filter	*/ NULL,
514 				/* filterarg	*/ NULL,
515 				/* maxsize	*/ aha->max_ccbs *
516 						   sizeof(struct aha_ccb),
517 				/* nsegments	*/ 1,
518 				/* maxsegsz	*/ BUS_SPACE_MAXSIZE_24BIT,
519 				/* flags	*/ 0,
520 				/* lockfunc	*/ NULL,
521 				/* lockarg	*/ NULL,
522 				&aha->ccb_dmat) != 0) {
523 		goto error_exit;
524         }
525 
526 	aha->init_level++;
527 
528 	/* Allocation for our ccbs */
529 	if (bus_dmamem_alloc(aha->ccb_dmat, (void **)&aha->aha_ccb_array,
530 	    BUS_DMA_NOWAIT, &aha->ccb_dmamap) != 0)
531 		goto error_exit;
532 
533 	aha->init_level++;
534 
535 	/* And permanently map them */
536 	bus_dmamap_load(aha->ccb_dmat, aha->ccb_dmamap, aha->aha_ccb_array,
537 	    aha->max_ccbs * sizeof(struct aha_ccb), ahamapccbs, aha, /*flags*/0);
538 
539 	aha->init_level++;
540 
541 	/* DMA tag for our S/G structures.  We allocate in page sized chunks */
542 	if (bus_dma_tag_create(	/* parent	*/ aha->parent_dmat,
543 				/* alignment	*/ 1,
544 				/* boundary	*/ 0,
545 				/* lowaddr	*/ BUS_SPACE_MAXADDR,
546 				/* highaddr	*/ BUS_SPACE_MAXADDR,
547 				/* filter	*/ NULL,
548 				/* filterarg	*/ NULL,
549 				/* maxsize	*/ PAGE_SIZE,
550 				/* nsegments	*/ 1,
551 				/* maxsegsz	*/ BUS_SPACE_MAXSIZE_24BIT,
552 				/* flags	*/ 0,
553 				/* lockfunc	*/ NULL,
554 				/* lockarg	*/ NULL,
555 				&aha->sg_dmat) != 0)
556 		goto error_exit;
557 
558 	aha->init_level++;
559 
560 	/* Perform initial CCB allocation */
561 	bzero(aha->aha_ccb_array, aha->max_ccbs * sizeof(struct aha_ccb));
562 	ahaallocccbs(aha);
563 
564 	if (aha->num_ccbs == 0) {
565 		device_printf(aha->dev,
566 		    "aha_init - Unable to allocate initial ccbs\n");
567 		goto error_exit;
568 	}
569 
570 	/*
571 	 * Note that we are going and return (to probe)
572 	 */
573 	return (0);
574 
575 error_exit:
576 
577 	return (ENXIO);
578 }
579 
580 int
581 aha_attach(struct aha_softc *aha)
582 {
583 	int tagged_dev_openings;
584 	struct cam_devq *devq;
585 
586 	/*
587 	 * We don't do tagged queueing, since the aha cards don't
588 	 * support it.
589 	 */
590 	tagged_dev_openings = 0;
591 
592 	/*
593 	 * Create the device queue for our SIM.
594 	 */
595 	devq = cam_simq_alloc(aha->max_ccbs - 1);
596 	if (devq == NULL)
597 		return (ENOMEM);
598 
599 	/*
600 	 * Construct our SIM entry
601 	 */
602 	aha->sim = cam_sim_alloc(ahaaction, ahapoll, "aha", aha,
603 	    device_get_unit(aha->dev), &aha->lock, 2, tagged_dev_openings,
604 	    devq);
605 	if (aha->sim == NULL) {
606 		cam_simq_free(devq);
607 		return (ENOMEM);
608 	}
609 	mtx_lock(&aha->lock);
610 	if (xpt_bus_register(aha->sim, aha->dev, 0) != CAM_SUCCESS) {
611 		cam_sim_free(aha->sim, /*free_devq*/TRUE);
612 		mtx_unlock(&aha->lock);
613 		return (ENXIO);
614 	}
615 	if (xpt_create_path(&aha->path, /*periph*/NULL, cam_sim_path(aha->sim),
616 	    CAM_TARGET_WILDCARD, CAM_LUN_WILDCARD) != CAM_REQ_CMP) {
617 		xpt_bus_deregister(cam_sim_path(aha->sim));
618 		cam_sim_free(aha->sim, /*free_devq*/TRUE);
619 		mtx_unlock(&aha->lock);
620 		return (ENXIO);
621 	}
622 	mtx_unlock(&aha->lock);
623 
624 	return (0);
625 }
626 
627 static void
628 ahaallocccbs(struct aha_softc *aha)
629 {
630 	struct aha_ccb *next_ccb;
631 	struct sg_map_node *sg_map;
632 	bus_addr_t physaddr;
633 	aha_sg_t *segs;
634 	int newcount;
635 	int i;
636 
637 	next_ccb = &aha->aha_ccb_array[aha->num_ccbs];
638 
639 	sg_map = malloc(sizeof(*sg_map), M_DEVBUF, M_NOWAIT);
640 
641 	if (sg_map == NULL)
642 		return;
643 
644 	/* Allocate S/G space for the next batch of CCBS */
645 	if (bus_dmamem_alloc(aha->sg_dmat, (void **)&sg_map->sg_vaddr,
646 	    BUS_DMA_NOWAIT, &sg_map->sg_dmamap) != 0) {
647 		free(sg_map, M_DEVBUF);
648 		return;
649 	}
650 
651 	SLIST_INSERT_HEAD(&aha->sg_maps, sg_map, links);
652 
653 	bus_dmamap_load(aha->sg_dmat, sg_map->sg_dmamap, sg_map->sg_vaddr,
654 	    PAGE_SIZE, ahamapsgs, aha, /*flags*/0);
655 
656 	segs = sg_map->sg_vaddr;
657 	physaddr = sg_map->sg_physaddr;
658 
659 	newcount = (PAGE_SIZE / (AHA_NSEG * sizeof(aha_sg_t)));
660 	for (i = 0; aha->num_ccbs < aha->max_ccbs && i < newcount; i++) {
661 		int error;
662 
663 		next_ccb->sg_list = segs;
664 		next_ccb->sg_list_phys = physaddr;
665 		next_ccb->flags = ACCB_FREE;
666 		callout_init_mtx(&next_ccb->timer, &aha->lock, 0);
667 		error = bus_dmamap_create(aha->buffer_dmat, /*flags*/0,
668 		    &next_ccb->dmamap);
669 		if (error != 0)
670 			break;
671 		SLIST_INSERT_HEAD(&aha->free_aha_ccbs, next_ccb, links);
672 		segs += AHA_NSEG;
673 		physaddr += (AHA_NSEG * sizeof(aha_sg_t));
674 		next_ccb++;
675 		aha->num_ccbs++;
676 	}
677 
678 	/* Reserve a CCB for error recovery */
679 	if (aha->recovery_accb == NULL) {
680 		aha->recovery_accb = SLIST_FIRST(&aha->free_aha_ccbs);
681 		SLIST_REMOVE_HEAD(&aha->free_aha_ccbs, links);
682 	}
683 }
684 
685 static __inline void
686 ahafreeccb(struct aha_softc *aha, struct aha_ccb *accb)
687 {
688 
689 	if (!dumping)
690 		mtx_assert(&aha->lock, MA_OWNED);
691 	if ((accb->flags & ACCB_ACTIVE) != 0)
692 		LIST_REMOVE(&accb->ccb->ccb_h, sim_links.le);
693 	if (aha->resource_shortage != 0
694 	    && (accb->ccb->ccb_h.status & CAM_RELEASE_SIMQ) == 0) {
695 		accb->ccb->ccb_h.status |= CAM_RELEASE_SIMQ;
696 		aha->resource_shortage = FALSE;
697 	}
698 	accb->flags = ACCB_FREE;
699 	SLIST_INSERT_HEAD(&aha->free_aha_ccbs, accb, links);
700 	aha->active_ccbs--;
701 }
702 
703 static struct aha_ccb*
704 ahagetccb(struct aha_softc *aha)
705 {
706 	struct	aha_ccb* accb;
707 
708 	if (!dumping)
709 		mtx_assert(&aha->lock, MA_OWNED);
710 	if ((accb = SLIST_FIRST(&aha->free_aha_ccbs)) != NULL) {
711 		SLIST_REMOVE_HEAD(&aha->free_aha_ccbs, links);
712 		aha->active_ccbs++;
713 	} else if (aha->num_ccbs < aha->max_ccbs) {
714 		ahaallocccbs(aha);
715 		accb = SLIST_FIRST(&aha->free_aha_ccbs);
716 		if (accb == NULL)
717 			device_printf(aha->dev, "Can't malloc ACCB\n");
718 		else {
719 			SLIST_REMOVE_HEAD(&aha->free_aha_ccbs, links);
720 			aha->active_ccbs++;
721 		}
722 	}
723 
724 	return (accb);
725 }
726 
727 static void
728 ahaaction(struct cam_sim *sim, union ccb *ccb)
729 {
730 	struct	aha_softc *aha;
731 
732 	CAM_DEBUG(ccb->ccb_h.path, CAM_DEBUG_TRACE, ("ahaaction\n"));
733 
734 	aha = (struct aha_softc *)cam_sim_softc(sim);
735 	mtx_assert(&aha->lock, MA_OWNED);
736 
737 	switch (ccb->ccb_h.func_code) {
738 	/* Common cases first */
739 	case XPT_SCSI_IO:	/* Execute the requested I/O operation */
740 	case XPT_RESET_DEV:	/* Bus Device Reset the specified SCSI device */	{
741 		struct	aha_ccb	*accb;
742 		struct	aha_hccb *hccb;
743 
744 		/*
745 		 * Get an accb to use.
746 		 */
747 		if ((accb = ahagetccb(aha)) == NULL) {
748 			aha->resource_shortage = TRUE;
749 			xpt_freeze_simq(aha->sim, /*count*/1);
750 			ccb->ccb_h.status = CAM_REQUEUE_REQ;
751 			xpt_done(ccb);
752 			return;
753 		}
754 		hccb = &accb->hccb;
755 
756 		/*
757 		 * So we can find the ACCB when an abort is requested
758 		 */
759 		accb->ccb = ccb;
760 		ccb->ccb_h.ccb_accb_ptr = accb;
761 		ccb->ccb_h.ccb_aha_ptr = aha;
762 
763 		/*
764 		 * Put all the arguments for the xfer in the accb
765 		 */
766 		hccb->target = ccb->ccb_h.target_id;
767 		hccb->lun = ccb->ccb_h.target_lun;
768 		hccb->ahastat = 0;
769 		hccb->sdstat = 0;
770 
771 		if (ccb->ccb_h.func_code == XPT_SCSI_IO) {
772 			struct ccb_scsiio *csio;
773 			struct ccb_hdr *ccbh;
774 			int error;
775 
776 			csio = &ccb->csio;
777 			ccbh = &csio->ccb_h;
778 			hccb->opcode = aha->ccb_ccb_opcode;
779 			hccb->datain = (ccb->ccb_h.flags & CAM_DIR_IN) != 0;
780 			hccb->dataout = (ccb->ccb_h.flags & CAM_DIR_OUT) != 0;
781 			hccb->cmd_len = csio->cdb_len;
782 			if (hccb->cmd_len > sizeof(hccb->scsi_cdb)) {
783 				ccb->ccb_h.status = CAM_REQ_INVALID;
784 				ahafreeccb(aha, accb);
785 				xpt_done(ccb);
786 				return;
787 			}
788 			hccb->sense_len = csio->sense_len;
789 			if ((ccbh->flags & CAM_CDB_POINTER) != 0) {
790 				if ((ccbh->flags & CAM_CDB_PHYS) == 0) {
791 					bcopy(csio->cdb_io.cdb_ptr,
792 					      hccb->scsi_cdb, hccb->cmd_len);
793 				} else {
794 					/* I guess I could map it in... */
795 					ccbh->status = CAM_REQ_INVALID;
796 					ahafreeccb(aha, accb);
797 					xpt_done(ccb);
798 					return;
799 				}
800 			} else {
801 				bcopy(csio->cdb_io.cdb_bytes,
802 				      hccb->scsi_cdb, hccb->cmd_len);
803 			}
804 			/*
805 			 * If we have any data to send with this command,
806 			 * map it into bus space.
807 			 */
808 
809 			error = bus_dmamap_load_ccb(
810 			    aha->buffer_dmat,
811 			    accb->dmamap,
812 			    ccb,
813 			    ahaexecuteccb,
814 			    accb,
815 			    /*flags*/0);
816 			if (error == EINPROGRESS) {
817 				/*
818 				 * So as to maintain ordering, freeze the
819 				 * controller queue until our mapping is
820 				 * returned.
821 				 */
822 				xpt_freeze_simq(aha->sim, 1);
823 				csio->ccb_h.status |= CAM_RELEASE_SIMQ;
824 			}
825 		} else {
826 			hccb->opcode = INITIATOR_BUS_DEV_RESET;
827 			/* No data transfer */
828 			hccb->datain = TRUE;
829 			hccb->dataout = TRUE;
830 			hccb->cmd_len = 0;
831 			hccb->sense_len = 0;
832 			ahaexecuteccb(accb, NULL, 0, 0);
833 		}
834 		break;
835 	}
836 	case XPT_ABORT:			/* Abort the specified CCB */
837 		/* XXX Implement */
838 		ccb->ccb_h.status = CAM_REQ_INVALID;
839 		xpt_done(ccb);
840 		break;
841 	case XPT_SET_TRAN_SETTINGS:
842 		/* XXX Implement */
843 		ccb->ccb_h.status = CAM_PROVIDE_FAIL;
844 		xpt_done(ccb);
845 		break;
846 	case XPT_GET_TRAN_SETTINGS:
847 	/* Get default/user set transfer settings for the target */
848 	{
849 		struct	ccb_trans_settings *cts = &ccb->cts;
850 		u_int	target_mask = 0x01 << ccb->ccb_h.target_id;
851 		struct ccb_trans_settings_scsi *scsi =
852 		    &cts->proto_specific.scsi;
853 		struct ccb_trans_settings_spi *spi =
854 		    &cts->xport_specific.spi;
855 
856 		cts->protocol = PROTO_SCSI;
857 		cts->protocol_version = SCSI_REV_2;
858 		cts->transport = XPORT_SPI;
859 		cts->transport_version = 2;
860 		if (cts->type == CTS_TYPE_USER_SETTINGS) {
861 			spi->flags = 0;
862 			if ((aha->disc_permitted & target_mask) != 0)
863 				spi->flags |= CTS_SPI_FLAGS_DISC_ENB;
864 			spi->bus_width = MSG_EXT_WDTR_BUS_8_BIT;
865 			if ((aha->sync_permitted & target_mask) != 0) {
866 				if (aha->boardid >= BOARD_1542CF)
867 					spi->sync_period = 25;
868 				else
869 					spi->sync_period = 50;
870 			} else {
871 				spi->sync_period = 0;
872 			}
873 
874 			if (spi->sync_period != 0)
875 				spi->sync_offset = 15;
876 
877 			spi->valid = CTS_SPI_VALID_SYNC_RATE
878 				   | CTS_SPI_VALID_SYNC_OFFSET
879 				   | CTS_SPI_VALID_BUS_WIDTH
880 				   | CTS_SPI_VALID_DISC;
881 			scsi->valid = CTS_SCSI_VALID_TQ;
882 		} else {
883 			ahafetchtransinfo(aha, cts);
884 		}
885 
886 		ccb->ccb_h.status = CAM_REQ_CMP;
887 		xpt_done(ccb);
888 		break;
889 	}
890 	case XPT_CALC_GEOMETRY:
891 	{
892 		struct	  ccb_calc_geometry *ccg;
893 		uint32_t size_mb;
894 		uint32_t secs_per_cylinder;
895 
896 		ccg = &ccb->ccg;
897 		size_mb = ccg->volume_size
898 			/ ((1024L * 1024L) / ccg->block_size);
899 		if (size_mb >= 1024 && (aha->extended_trans != 0)) {
900 			if (size_mb >= 2048) {
901 				ccg->heads = 255;
902 				ccg->secs_per_track = 63;
903 			} else {
904 				ccg->heads = 128;
905 				ccg->secs_per_track = 32;
906 			}
907 		} else {
908 			ccg->heads = 64;
909 			ccg->secs_per_track = 32;
910 		}
911 		secs_per_cylinder = ccg->heads * ccg->secs_per_track;
912 		ccg->cylinders = ccg->volume_size / secs_per_cylinder;
913 		ccb->ccb_h.status = CAM_REQ_CMP;
914 		xpt_done(ccb);
915 		break;
916 	}
917 	case XPT_RESET_BUS:		/* Reset the specified SCSI bus */
918 		ahareset(aha, /*hardreset*/TRUE);
919 		ccb->ccb_h.status = CAM_REQ_CMP;
920 		xpt_done(ccb);
921 		break;
922 	case XPT_TERM_IO:		/* Terminate the I/O process */
923 		/* XXX Implement */
924 		ccb->ccb_h.status = CAM_REQ_INVALID;
925 		xpt_done(ccb);
926 		break;
927 	case XPT_PATH_INQ:		/* Path routing inquiry */
928 	{
929 		struct ccb_pathinq *cpi = &ccb->cpi;
930 
931 		cpi->version_num = 1; /* XXX??? */
932 		cpi->hba_inquiry = PI_SDTR_ABLE;
933 		cpi->target_sprt = 0;
934 		cpi->hba_misc = 0;
935 		cpi->hba_eng_cnt = 0;
936 		cpi->max_target = 7;
937 		cpi->max_lun = 7;
938 		cpi->initiator_id = aha->scsi_id;
939 		cpi->bus_id = cam_sim_bus(sim);
940 		cpi->base_transfer_speed = 3300;
941 		strlcpy(cpi->sim_vid, "FreeBSD", SIM_IDLEN);
942 		strlcpy(cpi->hba_vid, "Adaptec", HBA_IDLEN);
943 		strlcpy(cpi->dev_name, cam_sim_name(sim), DEV_IDLEN);
944 		cpi->unit_number = cam_sim_unit(sim);
945 		cpi->transport = XPORT_SPI;
946 		cpi->transport_version = 2;
947 		cpi->protocol = PROTO_SCSI;
948 		cpi->protocol_version = SCSI_REV_2;
949 		cpi->ccb_h.status = CAM_REQ_CMP;
950 		xpt_done(ccb);
951 		break;
952 	}
953 	default:
954 		ccb->ccb_h.status = CAM_REQ_INVALID;
955 		xpt_done(ccb);
956 		break;
957 	}
958 }
959 
960 static void
961 ahaexecuteccb(void *arg, bus_dma_segment_t *dm_segs, int nseg, int error)
962 {
963 	struct	 aha_ccb *accb;
964 	union	 ccb *ccb;
965 	struct	 aha_softc *aha;
966 	uint32_t paddr;
967 
968 	accb = (struct aha_ccb *)arg;
969 	ccb = accb->ccb;
970 	aha = (struct aha_softc *)ccb->ccb_h.ccb_aha_ptr;
971 
972 	if (error != 0) {
973 		if (error != EFBIG)
974 			device_printf(aha->dev,
975 			    "Unexepected error 0x%x returned from "
976 			    "bus_dmamap_load\n", error);
977 		if (ccb->ccb_h.status == CAM_REQ_INPROG) {
978 			xpt_freeze_devq(ccb->ccb_h.path, /*count*/1);
979 			ccb->ccb_h.status = CAM_REQ_TOO_BIG|CAM_DEV_QFRZN;
980 		}
981 		ahafreeccb(aha, accb);
982 		xpt_done(ccb);
983 		return;
984 	}
985 
986 	if (nseg != 0) {
987 		aha_sg_t *sg;
988 		bus_dma_segment_t *end_seg;
989 		bus_dmasync_op_t op;
990 
991 		end_seg = dm_segs + nseg;
992 
993 		/* Copy the segments into our SG list */
994 		sg = accb->sg_list;
995 		while (dm_segs < end_seg) {
996 			ahautoa24(dm_segs->ds_len, sg->len);
997 			ahautoa24(dm_segs->ds_addr, sg->addr);
998 			sg++;
999 			dm_segs++;
1000 		}
1001 
1002 		if (nseg > 1) {
1003 			accb->hccb.opcode = aha->ccb_sg_opcode;
1004 			ahautoa24((sizeof(aha_sg_t) * nseg),
1005 			    accb->hccb.data_len);
1006 			ahautoa24(accb->sg_list_phys, accb->hccb.data_addr);
1007 		} else {
1008 			bcopy(accb->sg_list->len, accb->hccb.data_len, 3);
1009 			bcopy(accb->sg_list->addr, accb->hccb.data_addr, 3);
1010 		}
1011 
1012 		if ((ccb->ccb_h.flags & CAM_DIR_MASK) == CAM_DIR_IN)
1013 			op = BUS_DMASYNC_PREREAD;
1014 		else
1015 			op = BUS_DMASYNC_PREWRITE;
1016 
1017 		bus_dmamap_sync(aha->buffer_dmat, accb->dmamap, op);
1018 
1019 	} else {
1020 		accb->hccb.opcode = INITIATOR_CCB;
1021 		ahautoa24(0, accb->hccb.data_len);
1022 		ahautoa24(0, accb->hccb.data_addr);
1023 	}
1024 
1025 	/*
1026 	 * Last time we need to check if this CCB needs to
1027 	 * be aborted.
1028 	 */
1029 	if (ccb->ccb_h.status != CAM_REQ_INPROG) {
1030 		if (nseg != 0)
1031 			bus_dmamap_unload(aha->buffer_dmat, accb->dmamap);
1032 		ahafreeccb(aha, accb);
1033 		xpt_done(ccb);
1034 		return;
1035 	}
1036 
1037 	accb->flags = ACCB_ACTIVE;
1038 	ccb->ccb_h.status |= CAM_SIM_QUEUED;
1039 	LIST_INSERT_HEAD(&aha->pending_ccbs, &ccb->ccb_h, sim_links.le);
1040 
1041 	callout_reset_sbt(&accb->timer, SBT_1MS * ccb->ccb_h.timeout, 0,
1042 	    ahatimeout, accb, 0);
1043 
1044 	/* Tell the adapter about this command */
1045 	if (aha->cur_outbox->action_code != AMBO_FREE) {
1046 		/*
1047 		 * We should never encounter a busy mailbox.
1048 		 * If we do, warn the user, and treat it as
1049 		 * a resource shortage.  If the controller is
1050 		 * hung, one of the pending transactions will
1051 		 * timeout causing us to start recovery operations.
1052 		 */
1053 		device_printf(aha->dev,
1054 		    "Encountered busy mailbox with %d out of %d "
1055 		    "commands active!!!", aha->active_ccbs, aha->max_ccbs);
1056 		callout_stop(&accb->timer);
1057 		if (nseg != 0)
1058 			bus_dmamap_unload(aha->buffer_dmat, accb->dmamap);
1059 		ahafreeccb(aha, accb);
1060 		aha->resource_shortage = TRUE;
1061 		xpt_freeze_simq(aha->sim, /*count*/1);
1062 		ccb->ccb_h.status = CAM_REQUEUE_REQ;
1063 		xpt_done(ccb);
1064 		return;
1065 	}
1066 	paddr = ahaccbvtop(aha, accb);
1067 	ahautoa24(paddr, aha->cur_outbox->ccb_addr);
1068 	aha->cur_outbox->action_code = AMBO_START;
1069 	aha_outb(aha, COMMAND_REG, AOP_START_MBOX);
1070 
1071 	ahanextoutbox(aha);
1072 }
1073 
1074 void
1075 aha_intr(void *arg)
1076 {
1077 	struct	aha_softc *aha;
1078 
1079 	aha = arg;
1080 	mtx_lock(&aha->lock);
1081 	aha_intr_locked(aha);
1082 	mtx_unlock(&aha->lock);
1083 }
1084 
1085 void
1086 aha_intr_locked(struct aha_softc *aha)
1087 {
1088 	u_int	intstat;
1089 	uint32_t paddr;
1090 
1091 	while (((intstat = aha_inb(aha, INTSTAT_REG)) & INTR_PENDING) != 0) {
1092 		if ((intstat & CMD_COMPLETE) != 0) {
1093 			aha->latched_status = aha_inb(aha, STATUS_REG);
1094 			aha->command_cmp = TRUE;
1095 		}
1096 
1097 		aha_outb(aha, CONTROL_REG, RESET_INTR);
1098 
1099 		if ((intstat & IMB_LOADED) != 0) {
1100 			while (aha->cur_inbox->comp_code != AMBI_FREE) {
1101 				paddr = aha_a24tou(aha->cur_inbox->ccb_addr);
1102 				ahadone(aha, ahaccbptov(aha, paddr),
1103 				    aha->cur_inbox->comp_code);
1104 				aha->cur_inbox->comp_code = AMBI_FREE;
1105 				ahanextinbox(aha);
1106 			}
1107 		}
1108 
1109 		if ((intstat & SCSI_BUS_RESET) != 0) {
1110 			ahareset(aha, /*hardreset*/FALSE);
1111 		}
1112 	}
1113 }
1114 
1115 static void
1116 ahadone(struct aha_softc *aha, struct aha_ccb *accb, aha_mbi_comp_code_t comp_code)
1117 {
1118 	union  ccb	  *ccb;
1119 	struct ccb_scsiio *csio;
1120 
1121 	ccb = accb->ccb;
1122 	csio = &accb->ccb->csio;
1123 
1124 	if ((accb->flags & ACCB_ACTIVE) == 0) {
1125 		device_printf(aha->dev,
1126 		    "ahadone - Attempt to free non-active ACCB %p\n",
1127 		    (void *)accb);
1128 		return;
1129 	}
1130 
1131 	if ((ccb->ccb_h.flags & CAM_DIR_MASK) != CAM_DIR_NONE) {
1132 		bus_dmasync_op_t op;
1133 
1134 		if ((ccb->ccb_h.flags & CAM_DIR_MASK) == CAM_DIR_IN)
1135 			op = BUS_DMASYNC_POSTREAD;
1136 		else
1137 			op = BUS_DMASYNC_POSTWRITE;
1138 		bus_dmamap_sync(aha->buffer_dmat, accb->dmamap, op);
1139 		bus_dmamap_unload(aha->buffer_dmat, accb->dmamap);
1140 	}
1141 
1142 	if (accb == aha->recovery_accb) {
1143 		/*
1144 		 * The recovery ACCB does not have a CCB associated
1145 		 * with it, so short circuit the normal error handling.
1146 		 * We now traverse our list of pending CCBs and process
1147 		 * any that were terminated by the recovery CCBs action.
1148 		 * We also reinstate timeouts for all remaining, pending,
1149 		 * CCBs.
1150 		 */
1151 		struct cam_path *path;
1152 		struct ccb_hdr *ccb_h;
1153 		cam_status error;
1154 
1155 		/* Notify all clients that a BDR occurred */
1156 		error = xpt_create_path(&path, /*periph*/NULL,
1157 		    cam_sim_path(aha->sim), accb->hccb.target,
1158 		    CAM_LUN_WILDCARD);
1159 
1160 		if (error == CAM_REQ_CMP) {
1161 			xpt_async(AC_SENT_BDR, path, NULL);
1162 			xpt_free_path(path);
1163 		}
1164 
1165 		ccb_h = LIST_FIRST(&aha->pending_ccbs);
1166 		while (ccb_h != NULL) {
1167 			struct aha_ccb *pending_accb;
1168 
1169 			pending_accb = (struct aha_ccb *)ccb_h->ccb_accb_ptr;
1170 			if (pending_accb->hccb.target == accb->hccb.target) {
1171 				pending_accb->hccb.ahastat = AHASTAT_HA_BDR;
1172 				ccb_h = LIST_NEXT(ccb_h, sim_links.le);
1173 				ahadone(aha, pending_accb, AMBI_ERROR);
1174 			} else {
1175 				callout_reset_sbt(&pending_accb->timer,
1176 				    SBT_1MS * ccb_h->timeout, 0, ahatimeout,
1177 				    pending_accb, 0);
1178 				ccb_h = LIST_NEXT(ccb_h, sim_links.le);
1179 			}
1180 		}
1181 		device_printf(aha->dev, "No longer in timeout\n");
1182 		return;
1183 	}
1184 
1185 	callout_stop(&accb->timer);
1186 
1187 	switch (comp_code) {
1188 	case AMBI_FREE:
1189 		device_printf(aha->dev,
1190 		    "ahadone - CCB completed with free status!\n");
1191 		break;
1192 	case AMBI_NOT_FOUND:
1193 		device_printf(aha->dev,
1194 		    "ahadone - CCB Abort failed to find CCB\n");
1195 		break;
1196 	case AMBI_ABORT:
1197 	case AMBI_ERROR:
1198 		/* An error occurred */
1199 		if (accb->hccb.opcode < INITIATOR_CCB_WRESID)
1200 			csio->resid = 0;
1201 		else
1202 			csio->resid = aha_a24tou(accb->hccb.data_len);
1203 		switch(accb->hccb.ahastat) {
1204 		case AHASTAT_DATARUN_ERROR:
1205 		{
1206 			if (csio->resid <= 0) {
1207 				csio->ccb_h.status = CAM_DATA_RUN_ERR;
1208 				break;
1209 			}
1210 			/* FALLTHROUGH */
1211 		}
1212 		case AHASTAT_NOERROR:
1213 			csio->scsi_status = accb->hccb.sdstat;
1214 			csio->ccb_h.status |= CAM_SCSI_STATUS_ERROR;
1215 			switch(csio->scsi_status) {
1216 			case SCSI_STATUS_CHECK_COND:
1217 			case SCSI_STATUS_CMD_TERMINATED:
1218 				csio->ccb_h.status |= CAM_AUTOSNS_VALID;
1219 				/*
1220 				 * The aha writes the sense data at different
1221 				 * offsets based on the scsi cmd len
1222 				 */
1223 				bcopy((caddr_t) &accb->hccb.scsi_cdb +
1224 				    accb->hccb.cmd_len,
1225 				    (caddr_t) &csio->sense_data,
1226 				    accb->hccb.sense_len);
1227 				break;
1228 			default:
1229 				break;
1230 			case SCSI_STATUS_OK:
1231 				csio->ccb_h.status = CAM_REQ_CMP;
1232 				break;
1233 			}
1234 			break;
1235 		case AHASTAT_SELTIMEOUT:
1236 			csio->ccb_h.status = CAM_SEL_TIMEOUT;
1237 			break;
1238 		case AHASTAT_UNEXPECTED_BUSFREE:
1239 			csio->ccb_h.status = CAM_UNEXP_BUSFREE;
1240 			break;
1241 		case AHASTAT_INVALID_PHASE:
1242 			csio->ccb_h.status = CAM_SEQUENCE_FAIL;
1243 			break;
1244 		case AHASTAT_INVALID_ACTION_CODE:
1245 			panic("%s: Inavlid Action code", aha_name(aha));
1246 			break;
1247 		case AHASTAT_INVALID_OPCODE:
1248 			if (accb->hccb.opcode < INITIATOR_CCB_WRESID)
1249 				panic("%s: Invalid CCB Opcode %x hccb = %p",
1250 				    aha_name(aha), accb->hccb.opcode,
1251 				    &accb->hccb);
1252 			device_printf(aha->dev,
1253 			    "AHA-1540A compensation failed\n");
1254 			xpt_freeze_devq(ccb->ccb_h.path, /*count*/1);
1255 			csio->ccb_h.status = CAM_REQUEUE_REQ;
1256 			break;
1257 		case AHASTAT_LINKED_CCB_LUN_MISMATCH:
1258 			/* We don't even support linked commands... */
1259 			panic("%s: Linked CCB Lun Mismatch", aha_name(aha));
1260 			break;
1261 		case AHASTAT_INVALID_CCB_OR_SG_PARAM:
1262 			panic("%s: Invalid CCB or SG list", aha_name(aha));
1263 			break;
1264 		case AHASTAT_HA_SCSI_BUS_RESET:
1265 			if ((csio->ccb_h.status & CAM_STATUS_MASK)
1266 			    != CAM_CMD_TIMEOUT)
1267 				csio->ccb_h.status = CAM_SCSI_BUS_RESET;
1268 			break;
1269 		case AHASTAT_HA_BDR:
1270 			if ((accb->flags & ACCB_DEVICE_RESET) == 0)
1271 				csio->ccb_h.status = CAM_BDR_SENT;
1272 			else
1273 				csio->ccb_h.status = CAM_CMD_TIMEOUT;
1274 			break;
1275 		}
1276 		if (csio->ccb_h.status != CAM_REQ_CMP) {
1277 			xpt_freeze_devq(csio->ccb_h.path, /*count*/1);
1278 			csio->ccb_h.status |= CAM_DEV_QFRZN;
1279 		}
1280 		if ((accb->flags & ACCB_RELEASE_SIMQ) != 0)
1281 			ccb->ccb_h.status |= CAM_RELEASE_SIMQ;
1282 		ahafreeccb(aha, accb);
1283 		xpt_done(ccb);
1284 		break;
1285 	case AMBI_OK:
1286 		/* All completed without incident */
1287 		/* XXX DO WE NEED TO COPY SENSE BYTES HERE???? XXX */
1288 		/* I don't think so since it works???? */
1289 		ccb->ccb_h.status |= CAM_REQ_CMP;
1290 		if ((accb->flags & ACCB_RELEASE_SIMQ) != 0)
1291 			ccb->ccb_h.status |= CAM_RELEASE_SIMQ;
1292 		ahafreeccb(aha, accb);
1293 		xpt_done(ccb);
1294 		break;
1295 	}
1296 }
1297 
1298 static int
1299 ahareset(struct aha_softc* aha, int hard_reset)
1300 {
1301 	struct	 ccb_hdr *ccb_h;
1302 	u_int	 status;
1303 	u_int	 timeout;
1304 	uint8_t reset_type;
1305 
1306 	if (hard_reset != 0)
1307 		reset_type = HARD_RESET;
1308 	else
1309 		reset_type = SOFT_RESET;
1310 	aha_outb(aha, CONTROL_REG, reset_type);
1311 
1312 	/* Wait 5sec. for Diagnostic start */
1313 	timeout = 5 * 10000;
1314 	while (--timeout) {
1315 		status = aha_inb(aha, STATUS_REG);
1316 		if ((status & DIAG_ACTIVE) != 0)
1317 			break;
1318 		DELAY(100);
1319 	}
1320 	if (timeout == 0) {
1321 		PRVERB((aha->dev, "ahareset - Diagnostic Active failed to "
1322 		    "assert. status = %#x\n", status));
1323 		return (ETIMEDOUT);
1324 	}
1325 
1326 	/* Wait 10sec. for Diagnostic end */
1327 	timeout = 10 * 10000;
1328 	while (--timeout) {
1329 		status = aha_inb(aha, STATUS_REG);
1330 		if ((status & DIAG_ACTIVE) == 0)
1331 			break;
1332 		DELAY(100);
1333 	}
1334 	if (timeout == 0) {
1335 		panic("%s: ahareset - Diagnostic Active failed to drop. "
1336 		    "status = 0x%x\n", aha_name(aha), status);
1337 		return (ETIMEDOUT);
1338 	}
1339 
1340 	/* Wait for the host adapter to become ready or report a failure */
1341 	timeout = 10000;
1342 	while (--timeout) {
1343 		status = aha_inb(aha, STATUS_REG);
1344 		if ((status & (DIAG_FAIL|HA_READY|DATAIN_REG_READY)) != 0)
1345 			break;
1346 		DELAY(100);
1347 	}
1348 	if (timeout == 0) {
1349 		device_printf(aha->dev, "ahareset - Host adapter failed to "
1350 		    "come ready. status = 0x%x\n", status);
1351 		return (ETIMEDOUT);
1352 	}
1353 
1354 	/* If the diagnostics failed, tell the user */
1355 	if ((status & DIAG_FAIL) != 0
1356 	 || (status & HA_READY) == 0) {
1357 		device_printf(aha->dev, "ahareset - Adapter failed diag\n");
1358 
1359 		if ((status & DATAIN_REG_READY) != 0)
1360 			device_printf(aha->dev, "ahareset - Host Adapter "
1361 			    "Error code = 0x%x\n", aha_inb(aha, DATAIN_REG));
1362 		return (ENXIO);
1363 	}
1364 
1365 	/* If we've attached to the XPT, tell it about the event */
1366 	if (aha->path != NULL)
1367 		xpt_async(AC_BUS_RESET, aha->path, NULL);
1368 
1369 	/*
1370 	 * Perform completion processing for all outstanding CCBs.
1371 	 */
1372 	while ((ccb_h = LIST_FIRST(&aha->pending_ccbs)) != NULL) {
1373 		struct aha_ccb *pending_accb;
1374 
1375 		pending_accb = (struct aha_ccb *)ccb_h->ccb_accb_ptr;
1376 		pending_accb->hccb.ahastat = AHASTAT_HA_SCSI_BUS_RESET;
1377 		ahadone(aha, pending_accb, AMBI_ERROR);
1378 	}
1379 
1380 	/* If we've allocated mailboxes, initialize them */
1381 	/* Must be done after we've aborted our queue, or aha_cmd fails */
1382 	if (aha->init_level > 4)
1383 		ahainitmboxes(aha);
1384 
1385 	return (0);
1386 }
1387 
1388 /*
1389  * Send a command to the adapter.
1390  */
1391 int
1392 aha_cmd(struct aha_softc *aha, aha_op_t opcode, uint8_t *params,
1393 	u_int param_len, uint8_t *reply_data, u_int reply_len,
1394 	u_int cmd_timeout)
1395 {
1396 	u_int	timeout;
1397 	u_int	status;
1398 	u_int	saved_status;
1399 	u_int	intstat;
1400 	u_int	reply_buf_size;
1401 	int	cmd_complete;
1402 	int	error;
1403 
1404 	/* No data returned to start */
1405 	reply_buf_size = reply_len;
1406 	reply_len = 0;
1407 	intstat = 0;
1408 	cmd_complete = 0;
1409 	saved_status = 0;
1410 	error = 0;
1411 
1412 	/*
1413 	 * All commands except for the "start mailbox" and the "enable
1414 	 * outgoing mailbox read interrupt" commands cannot be issued
1415 	 * while there are pending transactions.  Freeze our SIMQ
1416 	 * and wait for all completions to occur if necessary.
1417 	 */
1418 	timeout = 10000;
1419 	while (LIST_FIRST(&aha->pending_ccbs) != NULL && --timeout) {
1420 		/* Fire the interrupt handler in case interrupts are blocked */
1421 		aha_intr(aha);
1422 		DELAY(10);
1423 	}
1424 
1425 	if (timeout == 0) {
1426 		device_printf(aha->dev,
1427 		    "aha_cmd: Timeout waiting for adapter idle\n");
1428 		return (ETIMEDOUT);
1429 	}
1430 	aha->command_cmp = 0;
1431 	/*
1432 	 * Wait up to 10 sec. for the adapter to become
1433 	 * ready to accept commands.
1434 	 */
1435 	timeout = 100000;
1436 	while (--timeout) {
1437 		status = aha_inb(aha, STATUS_REG);
1438 		if ((status & HA_READY) != 0 && (status & CMD_REG_BUSY) == 0)
1439 			break;
1440 		/*
1441 		 * Throw away any pending data which may be
1442 		 * left over from earlier commands that we
1443 		 * timedout on.
1444 		 */
1445 		if ((status & DATAIN_REG_READY) != 0)
1446 			(void)aha_inb(aha, DATAIN_REG);
1447 		DELAY(100);
1448 	}
1449 	if (timeout == 0) {
1450 		device_printf(aha->dev, "aha_cmd: Timeout waiting for adapter"
1451 		    " ready, status = 0x%x\n", status);
1452 		return (ETIMEDOUT);
1453 	}
1454 
1455 	/*
1456 	 * Send the opcode followed by any necessary parameter bytes.
1457 	 */
1458 	aha_outb(aha, COMMAND_REG, opcode);
1459 
1460 	/*
1461 	 * Wait for up to 1sec to get the parameter list sent
1462 	 */
1463 	timeout = 10000;
1464 	while (param_len && --timeout) {
1465 		DELAY(100);
1466 		status = aha_inb(aha, STATUS_REG);
1467 		intstat = aha_inb(aha, INTSTAT_REG);
1468 
1469 		if ((intstat & (INTR_PENDING|CMD_COMPLETE))
1470 		 == (INTR_PENDING|CMD_COMPLETE)) {
1471 			saved_status = status;
1472 			cmd_complete = 1;
1473 			break;
1474 		}
1475 
1476 		if (aha->command_cmp != 0) {
1477 			saved_status = aha->latched_status;
1478 			cmd_complete = 1;
1479 			break;
1480 		}
1481 		if ((status & DATAIN_REG_READY) != 0)
1482 			break;
1483 		if ((status & CMD_REG_BUSY) == 0) {
1484 			aha_outb(aha, COMMAND_REG, *params++);
1485 			param_len--;
1486 			timeout = 10000;
1487 		}
1488 	}
1489 	if (timeout == 0) {
1490 		device_printf(aha->dev, "aha_cmd: Timeout sending parameters, "
1491 		    "status = 0x%x\n", status);
1492 		error = ETIMEDOUT;
1493 	}
1494 
1495 	/*
1496 	 * For all other commands, we wait for any output data
1497 	 * and the final comand completion interrupt.
1498 	 */
1499 	while (cmd_complete == 0 && --cmd_timeout) {
1500 
1501 		status = aha_inb(aha, STATUS_REG);
1502 		intstat = aha_inb(aha, INTSTAT_REG);
1503 
1504 		if (aha->command_cmp != 0) {
1505 			cmd_complete = 1;
1506 			saved_status = aha->latched_status;
1507 		} else if ((intstat & (INTR_PENDING|CMD_COMPLETE))
1508 			== (INTR_PENDING|CMD_COMPLETE)) {
1509 			/*
1510 			 * Our poll (in case interrupts are blocked)
1511 			 * saw the CMD_COMPLETE interrupt.
1512 			 */
1513 			cmd_complete = 1;
1514 			saved_status = status;
1515 		}
1516 		if ((status & DATAIN_REG_READY) != 0) {
1517 			uint8_t data;
1518 
1519 			data = aha_inb(aha, DATAIN_REG);
1520 			if (reply_len < reply_buf_size) {
1521 				*reply_data++ = data;
1522 			} else {
1523 				device_printf(aha->dev,
1524 				    "aha_cmd - Discarded reply data "
1525 				    "byte for opcode 0x%x\n", opcode);
1526 			}
1527 			/*
1528 			 * Reset timeout to ensure at least a second
1529 			 * between response bytes.
1530 			 */
1531 			cmd_timeout = MAX(cmd_timeout, 10000);
1532 			reply_len++;
1533 		}
1534 		DELAY(100);
1535 	}
1536 	if (cmd_timeout == 0) {
1537 		device_printf(aha->dev, "aha_cmd: Timeout: status = 0x%x, "
1538 		    "intstat = 0x%x, reply_len = %d\n", status, intstat,
1539 		    reply_len);
1540 		return (ETIMEDOUT);
1541 	}
1542 
1543 	/*
1544 	 * Clear any pending interrupts.  Block interrupts so our
1545 	 * interrupt handler is not re-entered.
1546 	 */
1547 	aha_intr(aha);
1548 
1549 	if (error != 0)
1550 		return (error);
1551 
1552 	/*
1553 	 * If the command was rejected by the controller, tell the caller.
1554 	 */
1555 	if ((saved_status & CMD_INVALID) != 0) {
1556 		PRVERB((aha->dev, "Invalid Command 0x%x\n", opcode));
1557 		/*
1558 		 * Some early adapters may not recover properly from
1559 		 * an invalid command.  If it appears that the controller
1560 		 * has wedged (i.e. status was not cleared by our interrupt
1561 		 * reset above), perform a soft reset.
1562       		 */
1563 		DELAY(1000);
1564 		status = aha_inb(aha, STATUS_REG);
1565 		if ((status & (CMD_INVALID|STATUS_REG_RSVD|DATAIN_REG_READY|
1566 			      CMD_REG_BUSY|DIAG_FAIL|DIAG_ACTIVE)) != 0
1567 		 || (status & (HA_READY|INIT_REQUIRED))
1568 		  != (HA_READY|INIT_REQUIRED))
1569 			ahareset(aha, /*hard_reset*/FALSE);
1570 		return (EINVAL);
1571 	}
1572 
1573 	if (param_len > 0) {
1574 		/* The controller did not accept the full argument list */
1575 		PRVERB((aha->dev, "Controller did not accept full argument "
1576 		    "list (%d > 0)\n", param_len));
1577 	 	return (E2BIG);
1578 	}
1579 
1580 	if (reply_len != reply_buf_size) {
1581 		/* Too much or too little data received */
1582 		PRVERB((aha->dev, "data received mismatch (%d != %d)\n",
1583 		    reply_len, reply_buf_size));
1584 		return (EMSGSIZE);
1585 	}
1586 
1587 	/* We were successful */
1588 	return (0);
1589 }
1590 
1591 static int
1592 ahainitmboxes(struct aha_softc *aha)
1593 {
1594 	int error;
1595 	init_24b_mbox_params_t init_mbox;
1596 
1597 	bzero(aha->in_boxes, sizeof(aha_mbox_in_t) * aha->num_boxes);
1598 	bzero(aha->out_boxes, sizeof(aha_mbox_out_t) * aha->num_boxes);
1599 	aha->cur_inbox = aha->in_boxes;
1600 	aha->last_inbox = aha->in_boxes + aha->num_boxes - 1;
1601 	aha->cur_outbox = aha->out_boxes;
1602 	aha->last_outbox = aha->out_boxes + aha->num_boxes - 1;
1603 
1604 	/* Tell the adapter about them */
1605 	init_mbox.num_mboxes = aha->num_boxes;
1606 	ahautoa24(aha->mailbox_physbase, init_mbox.base_addr);
1607 	error = aha_cmd(aha, AOP_INITIALIZE_MBOX, (uint8_t *)&init_mbox,
1608 	    /*parmlen*/sizeof(init_mbox), /*reply_buf*/NULL,
1609 	    /*reply_len*/0, DEFAULT_CMD_TIMEOUT);
1610 
1611 	if (error != 0)
1612 		printf("ahainitmboxes: Initialization command failed\n");
1613 	return (error);
1614 }
1615 
1616 /*
1617  * Update the XPT's idea of the negotiated transfer
1618  * parameters for a particular target.
1619  */
1620 static void
1621 ahafetchtransinfo(struct aha_softc *aha, struct ccb_trans_settings* cts)
1622 {
1623 	setup_data_t	setup_info;
1624 	u_int		target;
1625 	u_int		targ_offset;
1626 	u_int		sync_period;
1627 	int		error;
1628 	uint8_t	param;
1629 	targ_syncinfo_t	sync_info;
1630 	struct ccb_trans_settings_spi *spi = &cts->xport_specific.spi;
1631 
1632 	target = cts->ccb_h.target_id;
1633 	targ_offset = (target & 0x7);
1634 
1635 	/*
1636 	 * Inquire Setup Information.  This command retreives
1637 	 * the sync info for older models.
1638 	 */
1639 	param = sizeof(setup_info);
1640 	error = aha_cmd(aha, AOP_INQUIRE_SETUP_INFO, &param, /*paramlen*/1,
1641 	    (uint8_t*)&setup_info, sizeof(setup_info), DEFAULT_CMD_TIMEOUT);
1642 
1643 	if (error != 0) {
1644 		device_printf(aha->dev,
1645 		    "ahafetchtransinfo - Inquire Setup Info Failed %d\n",
1646 		    error);
1647 		return;
1648 	}
1649 
1650 	sync_info = setup_info.syncinfo[targ_offset];
1651 
1652 	if (sync_info.sync == 0)
1653 		spi->sync_offset = 0;
1654 	else
1655 		spi->sync_offset = sync_info.offset;
1656 
1657 	spi->bus_width = MSG_EXT_WDTR_BUS_8_BIT;
1658 
1659 	if (aha->boardid >= BOARD_1542CF)
1660 		sync_period = 1000;
1661 	else
1662 		sync_period = 2000;
1663 	sync_period += 500 * sync_info.period;
1664 
1665 	/* Convert ns value to standard SCSI sync rate */
1666 	if (spi->sync_offset != 0)
1667 		spi->sync_period = scsi_calc_syncparam(sync_period);
1668 	else
1669 		spi->sync_period = 0;
1670 
1671 	spi->valid = CTS_SPI_VALID_SYNC_RATE
1672 		   | CTS_SPI_VALID_SYNC_OFFSET
1673 		   | CTS_SPI_VALID_BUS_WIDTH;
1674         xpt_async(AC_TRANSFER_NEG, cts->ccb_h.path, cts);
1675 }
1676 
1677 static void
1678 ahamapmboxes(void *arg, bus_dma_segment_t *segs, int nseg, int error)
1679 {
1680 	struct aha_softc* aha;
1681 
1682 	aha = (struct aha_softc*)arg;
1683 	aha->mailbox_physbase = segs->ds_addr;
1684 }
1685 
1686 static void
1687 ahamapccbs(void *arg, bus_dma_segment_t *segs, int nseg, int error)
1688 {
1689 	struct aha_softc* aha;
1690 
1691 	aha = (struct aha_softc*)arg;
1692 	aha->aha_ccb_physbase = segs->ds_addr;
1693 }
1694 
1695 static void
1696 ahamapsgs(void *arg, bus_dma_segment_t *segs, int nseg, int error)
1697 {
1698 
1699 	struct aha_softc* aha;
1700 
1701 	aha = (struct aha_softc*)arg;
1702 	SLIST_FIRST(&aha->sg_maps)->sg_physaddr = segs->ds_addr;
1703 }
1704 
1705 static void
1706 ahapoll(struct cam_sim *sim)
1707 {
1708 	aha_intr_locked(cam_sim_softc(sim));
1709 }
1710 
1711 static void
1712 ahatimeout(void *arg)
1713 {
1714 	struct aha_ccb	*accb;
1715 	union  ccb	*ccb;
1716 	struct aha_softc *aha;
1717 	uint32_t	paddr;
1718 	struct ccb_hdr *ccb_h;
1719 
1720 	accb = (struct aha_ccb *)arg;
1721 	ccb = accb->ccb;
1722 	aha = (struct aha_softc *)ccb->ccb_h.ccb_aha_ptr;
1723 	mtx_assert(&aha->lock, MA_OWNED);
1724 	xpt_print_path(ccb->ccb_h.path);
1725 	printf("CCB %p - timed out\n", (void *)accb);
1726 
1727 	if ((accb->flags & ACCB_ACTIVE) == 0) {
1728 		xpt_print_path(ccb->ccb_h.path);
1729 		printf("CCB %p - timed out CCB already completed\n",
1730 		    (void *)accb);
1731 		return;
1732 	}
1733 
1734 	/*
1735 	 * In order to simplify the recovery process, we ask the XPT
1736 	 * layer to halt the queue of new transactions and we traverse
1737 	 * the list of pending CCBs and remove their timeouts. This
1738 	 * means that the driver attempts to clear only one error
1739 	 * condition at a time.  In general, timeouts that occur
1740 	 * close together are related anyway, so there is no benefit
1741 	 * in attempting to handle errors in parallel.  Timeouts will
1742 	 * be reinstated when the recovery process ends.
1743 	 */
1744 	if ((accb->flags & ACCB_DEVICE_RESET) == 0) {
1745 		if ((accb->flags & ACCB_RELEASE_SIMQ) == 0) {
1746 			xpt_freeze_simq(aha->sim, /*count*/1);
1747 			accb->flags |= ACCB_RELEASE_SIMQ;
1748 		}
1749 
1750 		ccb_h = LIST_FIRST(&aha->pending_ccbs);
1751 		while (ccb_h != NULL) {
1752 			struct aha_ccb *pending_accb;
1753 
1754 			pending_accb = (struct aha_ccb *)ccb_h->ccb_accb_ptr;
1755 			callout_stop(&pending_accb->timer);
1756 			ccb_h = LIST_NEXT(ccb_h, sim_links.le);
1757 		}
1758 	}
1759 
1760 	if ((accb->flags & ACCB_DEVICE_RESET) != 0
1761 	 || aha->cur_outbox->action_code != AMBO_FREE) {
1762 		/*
1763 		 * Try a full host adapter/SCSI bus reset.
1764 		 * We do this only if we have already attempted
1765 		 * to clear the condition with a BDR, or we cannot
1766 		 * attempt a BDR for lack of mailbox resources.
1767 		 */
1768 		ccb->ccb_h.status = CAM_CMD_TIMEOUT;
1769 		ahareset(aha, /*hardreset*/TRUE);
1770 		device_printf(aha->dev, "No longer in timeout\n");
1771 	} else {
1772 		/*
1773 		 * Send a Bus Device Reset message:
1774 		 * The target that is holding up the bus may not
1775 		 * be the same as the one that triggered this timeout
1776 		 * (different commands have different timeout lengths),
1777 		 * but we have no way of determining this from our
1778 		 * timeout handler.  Our strategy here is to queue a
1779 		 * BDR message to the target of the timed out command.
1780 		 * If this fails, we'll get another timeout 2 seconds
1781 		 * later which will attempt a bus reset.
1782 		 */
1783 		accb->flags |= ACCB_DEVICE_RESET;
1784 		callout_reset(&accb->timer, 2 * hz, ahatimeout, accb);
1785 		aha->recovery_accb->hccb.opcode = INITIATOR_BUS_DEV_RESET;
1786 
1787 		/* No Data Transfer */
1788 		aha->recovery_accb->hccb.datain = TRUE;
1789 		aha->recovery_accb->hccb.dataout = TRUE;
1790 		aha->recovery_accb->hccb.ahastat = 0;
1791 		aha->recovery_accb->hccb.sdstat = 0;
1792 		aha->recovery_accb->hccb.target = ccb->ccb_h.target_id;
1793 
1794 		/* Tell the adapter about this command */
1795 		paddr = ahaccbvtop(aha, aha->recovery_accb);
1796 		ahautoa24(paddr, aha->cur_outbox->ccb_addr);
1797 		aha->cur_outbox->action_code = AMBO_START;
1798 		aha_outb(aha, COMMAND_REG, AOP_START_MBOX);
1799 		ahanextoutbox(aha);
1800 	}
1801 }
1802 
1803 int
1804 aha_detach(struct aha_softc *aha)
1805 {
1806 	mtx_lock(&aha->lock);
1807 	xpt_async(AC_LOST_DEVICE, aha->path, NULL);
1808 	xpt_free_path(aha->path);
1809 	xpt_bus_deregister(cam_sim_path(aha->sim));
1810 	cam_sim_free(aha->sim, /*free_devq*/TRUE);
1811 	mtx_unlock(&aha->lock);
1812 	/* XXX: Drain all timers? */
1813 	return (0);
1814 }
1815 MODULE_DEPEND(aha, cam, 1, 1, 1);
1816