scsi_lib.c 69.2 KB
Newer Older
Linus Torvalds's avatar
Linus Torvalds committed
1 2 3 4 5 6 7 8 9 10
/*
 *  scsi_lib.c Copyright (C) 1999 Eric Youngdale
 *
 *  SCSI queueing library.
 *      Initial versions: Eric Youngdale (eric@andante.org).
 *                        Based upon conversations with large numbers
 *                        of people at Linux Expo.
 */

#include <linux/bio.h>
11
#include <linux/bitops.h>
Linus Torvalds's avatar
Linus Torvalds committed
12 13 14 15 16 17 18 19
#include <linux/blkdev.h>
#include <linux/completion.h>
#include <linux/kernel.h>
#include <linux/mempool.h>
#include <linux/slab.h>
#include <linux/init.h>
#include <linux/pci.h>
#include <linux/delay.h>
20
#include <linux/hardirq.h>
Jens Axboe's avatar
Jens Axboe committed
21
#include <linux/scatterlist.h>
Linus Torvalds's avatar
Linus Torvalds committed
22 23

#include <scsi/scsi.h>
24
#include <scsi/scsi_cmnd.h>
Linus Torvalds's avatar
Linus Torvalds committed
25 26 27 28 29 30 31 32 33 34
#include <scsi/scsi_dbg.h>
#include <scsi/scsi_device.h>
#include <scsi/scsi_driver.h>
#include <scsi/scsi_eh.h>
#include <scsi/scsi_host.h>

#include "scsi_priv.h"
#include "scsi_logging.h"


35
#define SG_MEMPOOL_NR		ARRAY_SIZE(scsi_sg_pools)
36
#define SG_MEMPOOL_SIZE		2
Linus Torvalds's avatar
Linus Torvalds committed
37 38 39

struct scsi_host_sg_pool {
	size_t		size;
40
	char		*name;
41
	struct kmem_cache	*slab;
Linus Torvalds's avatar
Linus Torvalds committed
42 43 44
	mempool_t	*pool;
};

45 46 47 48
#define SP(x) { x, "sgpool-" __stringify(x) }
#if (SCSI_MAX_SG_SEGMENTS < 32)
#error SCSI_MAX_SG_SEGMENTS is too small (must be 32 or greater)
#endif
49
static struct scsi_host_sg_pool scsi_sg_pools[] = {
Linus Torvalds's avatar
Linus Torvalds committed
50 51
	SP(8),
	SP(16),
52
#if (SCSI_MAX_SG_SEGMENTS > 32)
53
	SP(32),
54
#if (SCSI_MAX_SG_SEGMENTS > 64)
55 56
	SP(64),
#if (SCSI_MAX_SG_SEGMENTS > 128)
Linus Torvalds's avatar
Linus Torvalds committed
57
	SP(128),
58 59
#if (SCSI_MAX_SG_SEGMENTS > 256)
#error SCSI_MAX_SG_SEGMENTS is too large (256 MAX)
60 61 62
#endif
#endif
#endif
63 64
#endif
	SP(SCSI_MAX_SG_SEGMENTS)
65
};
Linus Torvalds's avatar
Linus Torvalds committed
66 67
#undef SP

68
struct kmem_cache *scsi_sdb_cache;
69

70
static void scsi_run_queue(struct request_queue *q);
71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87

/*
 * Function:	scsi_unprep_request()
 *
 * Purpose:	Remove all preparation done for a request, including its
 *		associated scsi_cmnd, so that it can be requeued.
 *
 * Arguments:	req	- request to unprepare
 *
 * Lock status:	Assumed that no locks are held upon entry.
 *
 * Returns:	Nothing.
 */
static void scsi_unprep_request(struct request *req)
{
	struct scsi_cmnd *cmd = req->special;

88
	req->cmd_flags &= ~REQ_DONTPREP;
89
	req->special = NULL;
90 91 92

	scsi_put_command(cmd);
}
93

94 95 96 97 98
/**
 * __scsi_queue_insert - private queue insertion
 * @cmd: The SCSI command being requeued
 * @reason:  The reason for the requeue
 * @unbusy: Whether the queue should be unbusied
Linus Torvalds's avatar
Linus Torvalds committed
99
 *
100 101 102 103 104
 * This is a private queue insertion.  The public interface
 * scsi_queue_insert() always assumes the queue should be unbusied
 * because it's always called before the completion.  This function is
 * for a requeue after completion, which should only occur in this
 * file.
Linus Torvalds's avatar
Linus Torvalds committed
105
 */
106
static int __scsi_queue_insert(struct scsi_cmnd *cmd, int reason, int unbusy)
Linus Torvalds's avatar
Linus Torvalds committed
107 108 109
{
	struct Scsi_Host *host = cmd->device->host;
	struct scsi_device *device = cmd->device;
110
	struct scsi_target *starget = scsi_target(device);
111 112
	struct request_queue *q = device->request_queue;
	unsigned long flags;
Linus Torvalds's avatar
Linus Torvalds committed
113 114 115 116 117

	SCSI_LOG_MLQUEUE(1,
		 printk("Inserting command %p into mlqueue\n", cmd));

	/*
118
	 * Set the appropriate busy bit for the device/host.
Linus Torvalds's avatar
Linus Torvalds committed
119 120 121 122 123 124 125 126 127 128 129
	 *
	 * If the host/device isn't busy, assume that something actually
	 * completed, and that we should be able to queue a command now.
	 *
	 * Note that the prior mid-layer assumption that any host could
	 * always queue at least one command is now broken.  The mid-layer
	 * will implement a user specifiable stall (see
	 * scsi_host.max_host_blocked and scsi_device.max_device_blocked)
	 * if a command is requeued with no other commands outstanding
	 * either for the device or for the host.
	 */
130 131
	switch (reason) {
	case SCSI_MLQUEUE_HOST_BUSY:
Linus Torvalds's avatar
Linus Torvalds committed
132
		host->host_blocked = host->max_host_blocked;
133 134
		break;
	case SCSI_MLQUEUE_DEVICE_BUSY:
Linus Torvalds's avatar
Linus Torvalds committed
135
		device->device_blocked = device->max_device_blocked;
136 137 138 139 140
		break;
	case SCSI_MLQUEUE_TARGET_BUSY:
		starget->target_blocked = starget->max_target_blocked;
		break;
	}
Linus Torvalds's avatar
Linus Torvalds committed
141 142 143 144 145

	/*
	 * Decrement the counters, since these commands are no longer
	 * active on the host/device.
	 */
146 147
	if (unbusy)
		scsi_device_unbusy(device);
Linus Torvalds's avatar
Linus Torvalds committed
148 149

	/*
150 151
	 * Requeue this command.  It will go before all other commands
	 * that are already in the queue.
Linus Torvalds's avatar
Linus Torvalds committed
152 153 154 155
	 *
	 * NOTE: there is magic here about the way the queue is plugged if
	 * we have no outstanding commands.
	 * 
156
	 * Although we *don't* plug the queue, we call the request
Linus Torvalds's avatar
Linus Torvalds committed
157 158
	 * function.  The SCSI request function detects the blocked condition
	 * and plugs the queue appropriately.
159 160
         */
	spin_lock_irqsave(q->queue_lock, flags);
161
	blk_requeue_request(q, cmd->request);
162 163 164 165
	spin_unlock_irqrestore(q->queue_lock, flags);

	scsi_run_queue(q);

Linus Torvalds's avatar
Linus Torvalds committed
166 167 168
	return 0;
}

169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191
/*
 * Function:    scsi_queue_insert()
 *
 * Purpose:     Insert a command in the midlevel queue.
 *
 * Arguments:   cmd    - command that we are adding to queue.
 *              reason - why we are inserting command to queue.
 *
 * Lock status: Assumed that lock is not held upon entry.
 *
 * Returns:     Nothing.
 *
 * Notes:       We do this for one of two cases.  Either the host is busy
 *              and it cannot accept any more commands for the time being,
 *              or the device returned QUEUE_FULL and can accept no more
 *              commands.
 * Notes:       This could be called either from an interrupt context or a
 *              normal process context.
 */
int scsi_queue_insert(struct scsi_cmnd *cmd, int reason)
{
	return __scsi_queue_insert(cmd, reason, 1);
}
192
/**
193
 * scsi_execute - insert request and wait for the result
194 195 196 197 198 199 200 201
 * @sdev:	scsi device
 * @cmd:	scsi command
 * @data_direction: data direction
 * @buffer:	data buffer
 * @bufflen:	len of buffer
 * @sense:	optional sense buffer
 * @timeout:	request timeout in seconds
 * @retries:	number of times to retry request
202
 * @flags:	or into request flags;
203
 * @resid:	optional residual length
204
 *
205
 * returns the req->errors value which is the scsi_cmnd result
206
 * field.
207
 */
208 209
int scsi_execute(struct scsi_device *sdev, const unsigned char *cmd,
		 int data_direction, void *buffer, unsigned bufflen,
210 211
		 unsigned char *sense, int timeout, int retries, int flags,
		 int *resid)
212 213 214 215 216 217 218 219 220 221 222 223 224 225 226
{
	struct request *req;
	int write = (data_direction == DMA_TO_DEVICE);
	int ret = DRIVER_ERROR << 24;

	req = blk_get_request(sdev->request_queue, write, __GFP_WAIT);

	if (bufflen &&	blk_rq_map_kern(sdev->request_queue, req,
					buffer, bufflen, __GFP_WAIT))
		goto out;

	req->cmd_len = COMMAND_SIZE(cmd[0]);
	memcpy(req->cmd, cmd, req->cmd_len);
	req->sense = sense;
	req->sense_len = 0;
227
	req->retries = retries;
228
	req->timeout = timeout;
229 230
	req->cmd_type = REQ_TYPE_BLOCK_PC;
	req->cmd_flags |= flags | REQ_QUIET | REQ_PREEMPT;
231 232 233 234 235 236

	/*
	 * head injection *required* here otherwise quiesce won't work
	 */
	blk_execute_rq(req->q, NULL, req, 1);

237 238 239 240 241 242 243 244 245
	/*
	 * Some devices (USB mass-storage in particular) may transfer
	 * garbage data together with a residue indicating that the data
	 * is invalid.  Prevent the garbage from being misinterpreted
	 * and prevent security leaks by zeroing out the excess data.
	 */
	if (unlikely(req->data_len > 0 && req->data_len <= bufflen))
		memset(buffer + (bufflen - req->data_len), 0, req->data_len);

246 247
	if (resid)
		*resid = req->data_len;
248 249 250 251 252 253
	ret = req->errors;
 out:
	blk_put_request(req);

	return ret;
}
254
EXPORT_SYMBOL(scsi_execute);
255

256 257 258

int scsi_execute_req(struct scsi_device *sdev, const unsigned char *cmd,
		     int data_direction, void *buffer, unsigned bufflen,
259 260
		     struct scsi_sense_hdr *sshdr, int timeout, int retries,
		     int *resid)
261 262
{
	char *sense = NULL;
263 264
	int result;
	
265
	if (sshdr) {
266
		sense = kzalloc(SCSI_SENSE_BUFFERSIZE, GFP_NOIO);
267 268 269
		if (!sense)
			return DRIVER_ERROR << 24;
	}
270
	result = scsi_execute(sdev, cmd, data_direction, buffer, bufflen,
271
			      sense, timeout, retries, 0, resid);
272
	if (sshdr)
273
		scsi_normalize_sense(sense, SCSI_SENSE_BUFFERSIZE, sshdr);
274 275 276 277 278 279

	kfree(sense);
	return result;
}
EXPORT_SYMBOL(scsi_execute_req);

280 281 282 283 284 285
struct scsi_io_context {
	void *data;
	void (*done)(void *data, char *sense, int result, int resid);
	char sense[SCSI_SENSE_BUFFERSIZE];
};

286
static struct kmem_cache *scsi_io_context_cache;
287

288
static void scsi_end_async(struct request *req, int uptodate)
289 290 291 292 293 294
{
	struct scsi_io_context *sioc = req->end_io_data;

	if (sioc->done)
		sioc->done(sioc->data, sioc->sense, req->errors, req->data_len);

295
	kmem_cache_free(scsi_io_context_cache, sioc);
296 297 298 299 300 301 302 303 304 305 306 307
	__blk_put_request(req->q, req);
}

static int scsi_merge_bio(struct request *rq, struct bio *bio)
{
	struct request_queue *q = rq->q;

	bio->bi_flags &= ~(1 << BIO_SEG_VALID);
	if (rq_data_dir(rq) == WRITE)
		bio->bi_rw |= (1 << BIO_RW);
	blk_queue_bounce(q, &bio);

NeilBrown's avatar
NeilBrown committed
308
	return blk_rq_append_bio(q, rq, bio);
309 310
}

311
static void scsi_bi_endio(struct bio *bio, int error)
312 313 314 315 316 317 318
{
	bio_put(bio);
}

/**
 * scsi_req_map_sg - map a scatterlist into a request
 * @rq:		request to fill
319
 * @sgl:	scatterlist
320 321 322 323 324 325 326 327 328 329 330 331
 * @nsegs:	number of elements
 * @bufflen:	len of buffer
 * @gfp:	memory allocation flags
 *
 * scsi_req_map_sg maps a scatterlist into a request so that the
 * request can be sent to the block layer. We do not trust the scatterlist
 * sent to use, as some ULDs use that struct to only organize the pages.
 */
static int scsi_req_map_sg(struct request *rq, struct scatterlist *sgl,
			   int nsegs, unsigned bufflen, gfp_t gfp)
{
	struct request_queue *q = rq->q;
332
	int nr_pages = (bufflen + sgl[0].offset + PAGE_SIZE - 1) >> PAGE_SHIFT;
333
	unsigned int data_len = bufflen, len, bytes, off;
Jens Axboe's avatar
Jens Axboe committed
334
	struct scatterlist *sg;
335 336 337 338
	struct page *page;
	struct bio *bio = NULL;
	int i, err, nr_vecs = 0;

Jens Axboe's avatar
Jens Axboe committed
339
	for_each_sg(sgl, sg, nsegs, i) {
340
		page = sg_page(sg);
Jens Axboe's avatar
Jens Axboe committed
341 342
		off = sg->offset;
		len = sg->length;
343

344 345 346 347 348 349
		while (len > 0 && data_len > 0) {
			/*
			 * sg sends a scatterlist that is larger than
			 * the data_len it wants transferred for certain
			 * IO sizes
			 */
350
			bytes = min_t(unsigned int, len, PAGE_SIZE - off);
351
			bytes = min(bytes, data_len);
352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374

			if (!bio) {
				nr_vecs = min_t(int, BIO_MAX_PAGES, nr_pages);
				nr_pages -= nr_vecs;

				bio = bio_alloc(gfp, nr_vecs);
				if (!bio) {
					err = -ENOMEM;
					goto free_bios;
				}
				bio->bi_end_io = scsi_bi_endio;
			}

			if (bio_add_pc_page(q, bio, page, bytes, off) !=
			    bytes) {
				bio_put(bio);
				err = -EINVAL;
				goto free_bios;
			}

			if (bio->bi_vcnt >= nr_vecs) {
				err = scsi_merge_bio(rq, bio);
				if (err) {
375
					bio_endio(bio, 0);
376 377 378 379 380 381 382
					goto free_bios;
				}
				bio = NULL;
			}

			page++;
			len -= bytes;
383
			data_len -=bytes;
384 385 386 387 388
			off = 0;
		}
	}

	rq->buffer = rq->data = NULL;
389
	rq->data_len = bufflen;
390 391 392 393 394 395 396 397
	return 0;

free_bios:
	while ((bio = rq->bio) != NULL) {
		rq->bio = bio->bi_next;
		/*
		 * call endio instead of bio_put incase it was bounced
		 */
398
		bio_endio(bio, 0);
399 400 401 402 403 404 405 406 407
	}

	return err;
}

/**
 * scsi_execute_async - insert request
 * @sdev:	scsi device
 * @cmd:	scsi command
408
 * @cmd_len:	length of scsi cdb
409
 * @data_direction: DMA_TO_DEVICE, DMA_FROM_DEVICE, or DMA_NONE
410 411 412 413 414
 * @buffer:	data buffer (this can be a kernel buffer or scatterlist)
 * @bufflen:	len of buffer
 * @use_sg:	if buffer is a scatterlist this is the number of elements
 * @timeout:	request timeout in seconds
 * @retries:	number of times to retry request
415 416 417 418
 * @privdata:	data passed to done()
 * @done:	callback function when done
 * @gfp:	memory allocation flags
 */
419
int scsi_execute_async(struct scsi_device *sdev, const unsigned char *cmd,
420
		       int cmd_len, int data_direction, void *buffer, unsigned bufflen,
421 422 423 424 425 426 427 428
		       int use_sg, int timeout, int retries, void *privdata,
		       void (*done)(void *, char *, int, int), gfp_t gfp)
{
	struct request *req;
	struct scsi_io_context *sioc;
	int err = 0;
	int write = (data_direction == DMA_TO_DEVICE);

429
	sioc = kmem_cache_zalloc(scsi_io_context_cache, gfp);
430 431 432 433 434 435
	if (!sioc)
		return DRIVER_ERROR << 24;

	req = blk_get_request(sdev->request_queue, write, gfp);
	if (!req)
		goto free_sense;
436 437
	req->cmd_type = REQ_TYPE_BLOCK_PC;
	req->cmd_flags |= REQ_QUIET;
438 439 440 441 442 443 444 445 446

	if (use_sg)
		err = scsi_req_map_sg(req, buffer, use_sg, bufflen, gfp);
	else if (bufflen)
		err = blk_rq_map_kern(req->q, req, buffer, bufflen, gfp);

	if (err)
		goto free_req;

447
	req->cmd_len = cmd_len;
448
	memset(req->cmd, 0, BLK_MAX_CDB); /* ATAPI hates garbage after CDB */
449 450 451 452
	memcpy(req->cmd, cmd, req->cmd_len);
	req->sense = sioc->sense;
	req->sense_len = 0;
	req->timeout = timeout;
453
	req->retries = retries;
454 455 456 457 458 459 460 461 462 463 464
	req->end_io_data = sioc;

	sioc->data = privdata;
	sioc->done = done;

	blk_execute_rq_nowait(req->q, NULL, req, 1, scsi_end_async);
	return 0;

free_req:
	blk_put_request(req);
free_sense:
465
	kmem_cache_free(scsi_io_context_cache, sioc);
466 467 468 469
	return DRIVER_ERROR << 24;
}
EXPORT_SYMBOL_GPL(scsi_execute_async);

Linus Torvalds's avatar
Linus Torvalds committed
470 471 472 473 474 475 476 477 478 479 480
/*
 * Function:    scsi_init_cmd_errh()
 *
 * Purpose:     Initialize cmd fields related to error handling.
 *
 * Arguments:   cmd	- command that is ready to be queued.
 *
 * Notes:       This function has the job of initializing a number of
 *              fields related to error handling.   Typically this will
 *              be called once for each command, as required.
 */
481
static void scsi_init_cmd_errh(struct scsi_cmnd *cmd)
Linus Torvalds's avatar
Linus Torvalds committed
482 483
{
	cmd->serial_number = 0;
484
	scsi_set_resid(cmd, 0);
485
	memset(cmd->sense_buffer, 0, SCSI_SENSE_BUFFERSIZE);
Linus Torvalds's avatar
Linus Torvalds committed
486
	if (cmd->cmd_len == 0)
487
		cmd->cmd_len = scsi_command_size(cmd->cmnd);
Linus Torvalds's avatar
Linus Torvalds committed
488 489 490 491 492
}

void scsi_device_unbusy(struct scsi_device *sdev)
{
	struct Scsi_Host *shost = sdev->host;
493
	struct scsi_target *starget = scsi_target(sdev);
Linus Torvalds's avatar
Linus Torvalds committed
494 495 496 497
	unsigned long flags;

	spin_lock_irqsave(shost->host_lock, flags);
	shost->host_busy--;
498
	starget->target_busy--;
499
	if (unlikely(scsi_host_in_recovery(shost) &&
500
		     (shost->host_failed || shost->host_eh_scheduled)))
Linus Torvalds's avatar
Linus Torvalds committed
501 502
		scsi_eh_wakeup(shost);
	spin_unlock(shost->host_lock);
's avatar
committed
503
	spin_lock(sdev->request_queue->queue_lock);
Linus Torvalds's avatar
Linus Torvalds committed
504
	sdev->device_busy--;
's avatar
committed
505
	spin_unlock_irqrestore(sdev->request_queue->queue_lock, flags);
Linus Torvalds's avatar
Linus Torvalds committed
506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553
}

/*
 * Called for single_lun devices on IO completion. Clear starget_sdev_user,
 * and call blk_run_queue for all the scsi_devices on the target -
 * including current_sdev first.
 *
 * Called with *no* scsi locks held.
 */
static void scsi_single_lun_run(struct scsi_device *current_sdev)
{
	struct Scsi_Host *shost = current_sdev->host;
	struct scsi_device *sdev, *tmp;
	struct scsi_target *starget = scsi_target(current_sdev);
	unsigned long flags;

	spin_lock_irqsave(shost->host_lock, flags);
	starget->starget_sdev_user = NULL;
	spin_unlock_irqrestore(shost->host_lock, flags);

	/*
	 * Call blk_run_queue for all LUNs on the target, starting with
	 * current_sdev. We race with others (to set starget_sdev_user),
	 * but in most cases, we will be first. Ideally, each LU on the
	 * target would get some limited time or requests on the target.
	 */
	blk_run_queue(current_sdev->request_queue);

	spin_lock_irqsave(shost->host_lock, flags);
	if (starget->starget_sdev_user)
		goto out;
	list_for_each_entry_safe(sdev, tmp, &starget->devices,
			same_target_siblings) {
		if (sdev == current_sdev)
			continue;
		if (scsi_device_get(sdev))
			continue;

		spin_unlock_irqrestore(shost->host_lock, flags);
		blk_run_queue(sdev->request_queue);
		spin_lock_irqsave(shost->host_lock, flags);
	
		scsi_device_put(sdev);
	}
 out:
	spin_unlock_irqrestore(shost->host_lock, flags);
}

554 555 556 557 558 559 560 561
static inline int scsi_device_is_busy(struct scsi_device *sdev)
{
	if (sdev->device_busy >= sdev->queue_depth || sdev->device_blocked)
		return 1;

	return 0;
}

562 563 564 565 566 567 568
static inline int scsi_target_is_busy(struct scsi_target *starget)
{
	return ((starget->can_queue > 0 &&
		 starget->target_busy >= starget->can_queue) ||
		 starget->target_blocked);
}

569 570 571 572 573 574 575 576 577
static inline int scsi_host_is_busy(struct Scsi_Host *shost)
{
	if ((shost->can_queue > 0 && shost->host_busy >= shost->can_queue) ||
	    shost->host_blocked || shost->host_self_blocked)
		return 1;

	return 0;
}

Linus Torvalds's avatar
Linus Torvalds committed
578 579 580 581 582 583 584 585 586 587 588 589 590 591
/*
 * Function:	scsi_run_queue()
 *
 * Purpose:	Select a proper request queue to serve next
 *
 * Arguments:	q	- last request's queue
 *
 * Returns:     Nothing
 *
 * Notes:	The previous command was completely finished, start
 *		a new one if possible.
 */
static void scsi_run_queue(struct request_queue *q)
{
592
	struct scsi_device *sdev = q->queuedata;
Linus Torvalds's avatar
Linus Torvalds committed
593
	struct Scsi_Host *shost = sdev->host;
594
	LIST_HEAD(starved_list);
Linus Torvalds's avatar
Linus Torvalds committed
595 596
	unsigned long flags;

597
	if (scsi_target(sdev)->single_lun)
Linus Torvalds's avatar
Linus Torvalds committed
598 599 600
		scsi_single_lun_run(sdev);

	spin_lock_irqsave(shost->host_lock, flags);
601 602 603
	list_splice_init(&shost->starved_list, &starved_list);

	while (!list_empty(&starved_list)) {
604 605
		int flagset;

Linus Torvalds's avatar
Linus Torvalds committed
606 607 608 609 610 611 612 613 614 615
		/*
		 * As long as shost is accepting commands and we have
		 * starved queues, call blk_run_queue. scsi_request_fn
		 * drops the queue_lock and can add us back to the
		 * starved_list.
		 *
		 * host_lock protects the starved_list and starved_entry.
		 * scsi_request_fn must get the host_lock before checking
		 * or modifying starved_list or starved_entry.
		 */
616
		if (scsi_host_is_busy(shost))
617 618
			break;

619 620 621
		sdev = list_entry(starved_list.next,
				  struct scsi_device, starved_entry);
		list_del_init(&sdev->starved_entry);
622 623 624 625 626 627
		if (scsi_target_is_busy(scsi_target(sdev))) {
			list_move_tail(&sdev->starved_entry,
				       &shost->starved_list);
			continue;
		}

628 629 630 631 632 633 634 635 636 637 638 639
		spin_unlock(shost->host_lock);

		spin_lock(sdev->request_queue->queue_lock);
		flagset = test_bit(QUEUE_FLAG_REENTER, &q->queue_flags) &&
				!test_bit(QUEUE_FLAG_REENTER,
					&sdev->request_queue->queue_flags);
		if (flagset)
			queue_flag_set(QUEUE_FLAG_REENTER, sdev->request_queue);
		__blk_run_queue(sdev->request_queue);
		if (flagset)
			queue_flag_clear(QUEUE_FLAG_REENTER, sdev->request_queue);
		spin_unlock(sdev->request_queue->queue_lock);
640

641
		spin_lock(shost->host_lock);
Linus Torvalds's avatar
Linus Torvalds committed
642
	}
643 644
	/* put any unprocessed entries back */
	list_splice(&starved_list, &shost->starved_list);
Linus Torvalds's avatar
Linus Torvalds committed
645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665
	spin_unlock_irqrestore(shost->host_lock, flags);

	blk_run_queue(q);
}

/*
 * Function:	scsi_requeue_command()
 *
 * Purpose:	Handle post-processing of completed commands.
 *
 * Arguments:	q	- queue to operate on
 *		cmd	- command that may need to be requeued.
 *
 * Returns:	Nothing
 *
 * Notes:	After command completion, there may be blocks left
 *		over which weren't finished by the previous command
 *		this can be for a number of reasons - the main one is
 *		I/O errors in the middle of the request, in which case
 *		we need to request the blocks that come after the bad
 *		sector.
666
 * Notes:	Upon return, cmd is a stale pointer.
Linus Torvalds's avatar
Linus Torvalds committed
667 668 669
 */
static void scsi_requeue_command(struct request_queue *q, struct scsi_cmnd *cmd)
{
670
	struct request *req = cmd->request;
671 672 673
	unsigned long flags;

	spin_lock_irqsave(q->queue_lock, flags);
674
	scsi_unprep_request(req);
675
	blk_requeue_request(q, req);
676
	spin_unlock_irqrestore(q->queue_lock, flags);
Linus Torvalds's avatar
Linus Torvalds committed
677 678 679 680 681 682

	scsi_run_queue(q);
}

void scsi_next_command(struct scsi_cmnd *cmd)
{
683 684 685 686 687
	struct scsi_device *sdev = cmd->device;
	struct request_queue *q = sdev->request_queue;

	/* need to hold a reference on the device before we let go of the cmd */
	get_device(&sdev->sdev_gendev);
Linus Torvalds's avatar
Linus Torvalds committed
688 689 690

	scsi_put_command(cmd);
	scsi_run_queue(q);
691 692 693

	/* ok to remove device now */
	put_device(&sdev->sdev_gendev);
Linus Torvalds's avatar
Linus Torvalds committed
694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710
}

void scsi_run_host_queues(struct Scsi_Host *shost)
{
	struct scsi_device *sdev;

	shost_for_each_device(sdev, shost)
		scsi_run_queue(sdev->request_queue);
}

/*
 * Function:    scsi_end_request()
 *
 * Purpose:     Post-processing of completed commands (usually invoked at end
 *		of upper level post-processing and scsi_io_completion).
 *
 * Arguments:   cmd	 - command that is complete.
711
 *              error    - 0 if I/O indicates success, < 0 for I/O error.
Linus Torvalds's avatar
Linus Torvalds committed
712 713 714 715 716
 *              bytes    - number of bytes of completed I/O
 *		requeue  - indicates whether we should requeue leftovers.
 *
 * Lock status: Assumed that lock is not held upon entry.
 *
717
 * Returns:     cmd if requeue required, NULL otherwise.
Linus Torvalds's avatar
Linus Torvalds committed
718 719 720 721 722 723
 *
 * Notes:       This is called for block device requests in order to
 *              mark some number of sectors as complete.
 * 
 *		We are guaranteeing that the request queue will be goosed
 *		at some point during this call.
724
 * Notes:	If cmd was requeued, upon return it will be a stale pointer.
Linus Torvalds's avatar
Linus Torvalds committed
725
 */
726
static struct scsi_cmnd *scsi_end_request(struct scsi_cmnd *cmd, int error,
Linus Torvalds's avatar
Linus Torvalds committed
727 728
					  int bytes, int requeue)
{
729
	struct request_queue *q = cmd->device->request_queue;
Linus Torvalds's avatar
Linus Torvalds committed
730 731 732 733 734 735
	struct request *req = cmd->request;

	/*
	 * If there are blocks left over at the end, set up the command
	 * to queue the remainder of them.
	 */
736
	if (blk_end_request(req, error, bytes)) {
Linus Torvalds's avatar
Linus Torvalds committed
737 738 739 740 741 742
		int leftover = (req->hard_nr_sectors << 9);

		if (blk_pc_request(req))
			leftover = req->data_len;

		/* kill remainder if no retrys */
743
		if (error && scsi_noretry_cmd(cmd))
744
			blk_end_request(req, error, leftover);
Linus Torvalds's avatar
Linus Torvalds committed
745
		else {
746
			if (requeue) {
Linus Torvalds's avatar
Linus Torvalds committed
747 748 749 750 751 752
				/*
				 * Bleah.  Leftovers again.  Stick the
				 * leftovers in the front of the
				 * queue, and goose the queue again.
				 */
				scsi_requeue_command(q, cmd);
753 754
				cmd = NULL;
			}
Linus Torvalds's avatar
Linus Torvalds committed
755 756 757 758 759 760 761 762 763 764 765 766
			return cmd;
		}
	}

	/*
	 * This will goose the queue request function at the end, so we don't
	 * need to worry about launching another command.
	 */
	scsi_next_command(cmd);
	return NULL;
}

767 768 769 770
static inline unsigned int scsi_sgtable_index(unsigned short nents)
{
	unsigned int index;

771 772 773
	BUG_ON(nents > SCSI_MAX_SG_SEGMENTS);

	if (nents <= 8)
774
		index = 0;
775 776
	else
		index = get_count_order(nents) - 3;
Linus Torvalds's avatar
Linus Torvalds committed
777

778 779 780
	return index;
}

781
static void scsi_sg_free(struct scatterlist *sgl, unsigned int nents)
782 783 784
{
	struct scsi_host_sg_pool *sgp;

785 786 787
	sgp = scsi_sg_pools + scsi_sgtable_index(nents);
	mempool_free(sgl, sgp->pool);
}
788

789 790 791
static struct scatterlist *scsi_sg_alloc(unsigned int nents, gfp_t gfp_mask)
{
	struct scsi_host_sg_pool *sgp;
792

793 794 795
	sgp = scsi_sg_pools + scsi_sgtable_index(nents);
	return mempool_alloc(sgp->pool, gfp_mask);
}
796

797 798
static int scsi_alloc_sgtable(struct scsi_data_buffer *sdb, int nents,
			      gfp_t gfp_mask)
799 800
{
	int ret;
801

802
	BUG_ON(!nents);
803

804 805
	ret = __sg_alloc_table(&sdb->table, nents, SCSI_MAX_SG_SEGMENTS,
			       gfp_mask, scsi_sg_alloc);
806
	if (unlikely(ret))
807
		__sg_free_table(&sdb->table, SCSI_MAX_SG_SEGMENTS,
808
				scsi_sg_free);
809

810
	return ret;
Linus Torvalds's avatar
Linus Torvalds committed
811 812
}

813
static void scsi_free_sgtable(struct scsi_data_buffer *sdb)
Linus Torvalds's avatar
Linus Torvalds committed
814
{
815
	__sg_free_table(&sdb->table, SCSI_MAX_SG_SEGMENTS, scsi_sg_free);
Linus Torvalds's avatar
Linus Torvalds committed
816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834
}

/*
 * Function:    scsi_release_buffers()
 *
 * Purpose:     Completion processing for block device I/O requests.
 *
 * Arguments:   cmd	- command that we are bailing.
 *
 * Lock status: Assumed that no lock is held upon entry.
 *
 * Returns:     Nothing
 *
 * Notes:       In the event that an upper level driver rejects a
 *		command, we must release resources allocated during
 *		the __init_io() function.  Primarily this would involve
 *		the scatter-gather table, and potentially any bounce
 *		buffers.
 */
835
void scsi_release_buffers(struct scsi_cmnd *cmd)
Linus Torvalds's avatar
Linus Torvalds committed
836
{
837 838
	if (cmd->sdb.table.nents)
		scsi_free_sgtable(&cmd->sdb);
Linus Torvalds's avatar
Linus Torvalds committed
839

840
	memset(&cmd->sdb, 0, sizeof(cmd->sdb));
841 842 843 844 845

	if (scsi_bidi_cmnd(cmd)) {
		struct scsi_data_buffer *bidi_sdb =
			cmd->request->next_rq->special;
		scsi_free_sgtable(bidi_sdb);
846
		kmem_cache_free(scsi_sdb_cache, bidi_sdb);
847 848
		cmd->request->next_rq->special = NULL;
	}
849 850 851

	if (scsi_prot_sg_count(cmd))
		scsi_free_sgtable(cmd->prot_sdb);
Linus Torvalds's avatar
Linus Torvalds committed
852
}
853
EXPORT_SYMBOL(scsi_release_buffers);
Linus Torvalds's avatar
Linus Torvalds committed
854

855 856 857 858 859 860 861
/*
 * Bidi commands Must be complete as a whole, both sides at once.
 * If part of the bytes were written and lld returned
 * scsi_in()->resid and/or scsi_out()->resid this information will be left
 * in req->data_len and req->next_rq->data_len. The upper-layer driver can
 * decide what to do with this information.
 */
862
static void scsi_end_bidi_request(struct scsi_cmnd *cmd)
863
{
864 865 866 867 868 869 870 871 872 873
	struct request *req = cmd->request;
	unsigned int dlen = req->data_len;
	unsigned int next_dlen = req->next_rq->data_len;

	req->data_len = scsi_out(cmd)->resid;
	req->next_rq->data_len = scsi_in(cmd)->resid;

	/* The req and req->next_rq have not been completed */
	BUG_ON(blk_end_bidi_request(req, 0, dlen, next_dlen));

874 875 876 877 878 879 880 881 882
	scsi_release_buffers(cmd);

	/*
	 * This will goose the queue request function at the end, so we don't
	 * need to worry about launching another command.
	 */
	scsi_next_command(cmd);
}

Linus Torvalds's avatar
Linus Torvalds committed
883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899
/*
 * Function:    scsi_io_completion()
 *
 * Purpose:     Completion processing for block device I/O requests.
 *
 * Arguments:   cmd   - command that is finished.
 *
 * Lock status: Assumed that no lock is held upon entry.
 *
 * Returns:     Nothing
 *
 * Notes:       This function is matched in terms of capabilities to
 *              the function that created the scatter-gather list.
 *              In other words, if there are no bounce buffers
 *              (the normal case for most drivers), we don't need
 *              the logic to deal with cleaning up afterwards.
 *
900 901 902 903 904
 *		We must call scsi_end_request().  This will finish off
 *		the specified number of sectors.  If we are done, the
 *		command block will be released and the queue function
 *		will be goosed.  If we are not done then we have to
 *		figure out what to do next:
Linus Torvalds's avatar
Linus Torvalds committed
905
 *
906 907 908 909 910
 *		a) We can call scsi_requeue_command().  The request
 *		   will be unprepared and put back on the queue.  Then
 *		   a new command will be created for it.  This should
 *		   be used if we made forward progress, or if we want
 *		   to switch from READ(10) to READ(6) for example.
Linus Torvalds's avatar
Linus Torvalds committed
911
 *
912 913 914 915 916 917
 *		b) We can call scsi_queue_insert().  The request will
 *		   be put back on the queue and retried using the same
 *		   command as before, possibly after a delay.
 *
 *		c) We can call blk_end_request() with -EIO to fail
 *		   the remainder of the request.
Linus Torvalds's avatar
Linus Torvalds committed
918
 */
919
void scsi_io_completion(struct scsi_cmnd *cmd, unsigned int good_bytes)
Linus Torvalds's avatar
Linus Torvalds committed
920 921
{
	int result = cmd->result;
922
	int this_count;
923
	struct request_queue *q = cmd->device->request_queue;
Linus Torvalds's avatar
Linus Torvalds committed
924
	struct request *req = cmd->request;
925
	int error = 0;
Linus Torvalds's avatar
Linus Torvalds committed
926 927 928
	struct scsi_sense_hdr sshdr;
	int sense_valid = 0;
	int sense_deferred = 0;
929 930 931
	enum {ACTION_FAIL, ACTION_REPREP, ACTION_RETRY,
	      ACTION_DELAYED_RETRY} action;
	char *description = NULL;
Linus Torvalds's avatar
Linus Torvalds committed
932 933 934 935 936 937

	if (result) {
		sense_valid = scsi_command_normalize_sense(cmd, &sshdr);
		if (sense_valid)
			sense_deferred = scsi_sense_is_deferred(&sshdr);
	}
938

Linus Torvalds's avatar
Linus Torvalds committed
939 940 941 942 943 944 945 946 947 948 949 950 951 952
	if (blk_pc_request(req)) { /* SG_IO ioctl from block level */
		req->errors = result;
		if (result) {
			if (sense_valid && req->sense) {
				/*
				 * SG_IO wants current and deferred errors
				 */
				int len = 8 + cmd->sense_buffer[7];

				if (len > SCSI_SENSE_BUFFERSIZE)
					len = SCSI_SENSE_BUFFERSIZE;
				memcpy(req->sense, cmd->sense_buffer,  len);
				req->sense_len = len;
			}
953 954
			if (!sense_deferred)
				error = -EIO;
955
		}
956 957 958 959 960
		if (scsi_bidi_cmnd(cmd)) {
			/* will also release_buffers */
			scsi_end_bidi_request(cmd);
			return;
		}
961
		req->data_len = scsi_get_resid(cmd);
Linus Torvalds's avatar
Linus Torvalds committed
962 963
	}

964
	BUG_ON(blk_bidi_rq(req)); /* bidi not support for !blk_pc_request yet */
965 966
	scsi_release_buffers(cmd);

Linus Torvalds's avatar
Linus Torvalds committed
967 968 969 970
	/*
	 * Next deal with any sectors which we were able to correctly
	 * handle.
	 */
971 972 973 974 975 976 977 978
	SCSI_LOG_HLCOMPLETE(1, printk("%ld sectors total, "
				      "%d bytes done.\n",
				      req->nr_sectors, good_bytes));

	/* A number of bytes were successfully read.  If there
	 * are leftovers and there is some kind of error
	 * (result != 0), retry the rest.
	 */
979
	if (scsi_end_request(cmd, error, good_bytes, result == 0) == NULL)
980
		return;
981
	this_count = blk_rq_bytes(req);
982

983 984
	error = -EIO;

985 986 987 988 989 990 991
	if (host_byte(result) == DID_RESET) {
		/* Third party bus reset or reset for error recovery
		 * reasons.  Just retry the command and see what
		 * happens.
		 */
		action = ACTION_RETRY;
	} else if (sense_valid && !sense_deferred) {
Linus Torvalds's avatar
Linus Torvalds committed
992 993 994
		switch (sshdr.sense_key) {
		case UNIT_ATTENTION:
			if (cmd->device->removable) {
995
				/* Detected disc change.  Set a bit
Linus Torvalds's avatar
Linus Torvalds committed
996 997 998
				 * and quietly refuse further access.
				 */
				cmd->device->changed = 1;
999 1000
				description = "Media Changed";
				action = ACTION_FAIL;
Linus Torvalds's avatar
Linus Torvalds committed
1001
			} else {
1002 1003 1004
				/* Must have been a power glitch, or a
				 * bus reset.  Could not have been a
				 * media change, so we just retry the
1005
				 * command and see what happens.
1006
				 */
1007
				action = ACTION_RETRY;
Linus Torvalds's avatar
Linus Torvalds committed
1008 1009 1010
			}
			break;
		case ILLEGAL_REQUEST:
1011 1012 1013 1014 1015 1016 1017 1018
			/* If we had an ILLEGAL REQUEST returned, then
			 * we may have performed an unsupported
			 * command.  The only thing this should be
			 * would be a ten byte read where only a six
			 * byte read was supported.  Also, on a system
			 * where READ CAPACITY failed, we may have
			 * read past the end of the disk.
			 */
1019 1020
			if ((cmd->device->use_10_for_rw &&
			    sshdr.asc == 0x20 && sshdr.ascq == 0x00) &&
Linus Torvalds's avatar
Linus Torvalds committed
1021 1022
			    (cmd->cmnd[0] == READ_10 ||
			     cmd->cmnd[0] == WRITE_10)) {
1023
				/* This will issue a new 6-byte command. */
Linus Torvalds's avatar
Linus Torvalds committed
1024
				cmd->device->use_10_for_rw = 0;
1025
				action = ACTION_REPREP;
1026 1027 1028 1029
			} else if (sshdr.asc == 0x10) /* DIX */ {
				description = "Host Data Integrity Failure";
				action = ACTION_FAIL;
				error = -EILSEQ;
1030 1031 1032
			} else
				action = ACTION_FAIL;
			break;
1033 1034
		case ABORTED_COMMAND:
			if (sshdr.asc == 0x10) { /* DIF */
1035
				description = "Target Data Integrity Failure";
1036
				action = ACTION_FAIL;
1037
				error = -EILSEQ;
1038 1039
			} else
				action = ACTION_RETRY;
Linus Torvalds's avatar
Linus Torvalds committed
1040 1041
			break;
		case NOT_READY:
1042
			/* If the device is in the process of becoming
1043
			 * ready, or has a temporary blockage, retry.
Linus Torvalds's avatar
Linus Torvalds committed
1044
			 */
1045 1046 1047 1048 1049 1050 1051 1052 1053
			if (sshdr.asc == 0x04) {
				switch (sshdr.ascq) {
				case 0x01: /* becoming ready */
				case 0x04: /* format in progress */
				case 0x05: /* rebuild in progress */
				case 0x06: /* recalculation in progress */
				case 0x07: /* operation in progress */
				case 0x08: /* Long write in progress */
				case 0x09: /* self test in progress */
1054
					action = ACTION_DELAYED_RETRY;
1055
					break;
1056 1057 1058 1059
				default:
					description = "Device not ready";
					action = ACTION_FAIL;
					break;
1060
				}
1061 1062 1063
			} else {
				description = "Device not ready";
				action = ACTION_FAIL;
Linus Torvalds's avatar
Linus Torvalds committed
1064
			}
1065
			break;
Linus Torvalds's avatar
Linus Torvalds committed
1066
		case VOLUME_OVERFLOW:
1067
			/* See SSC3rXX or current. */
1068 1069
			action = ACTION_FAIL;
			break;
Linus Torvalds's avatar
Linus Torvalds committed
1070
		default:
1071 1072
			description = "Unhandled sense code";
			action = ACTION_FAIL;
Linus Torvalds's avatar
Linus Torvalds committed
1073 1074
			break;
		}
1075 1076 1077
	} else {
		description = "Unhandled error code";
		action = ACTION_FAIL;
1078
	}
1079 1080 1081 1082

	switch (action) {
	case ACTION_FAIL:
		/* Give up and fail the remainder of the request */
1083
		if (!(req->cmd_flags & REQ_QUIET)) {
1084
			if (description)
1085
				scmd_printk(KERN_INFO, cmd, "%s\n",
1086
					    description);
1087
			scsi_print_result(cmd);
1088 1089 1090
			if (driver_byte(result) & DRIVER_SENSE)
				scsi_print_sense("", cmd);
		}
1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101
		blk_end_request(req, -EIO, blk_rq_bytes(req));
		scsi_next_command(cmd);
		break;
	case ACTION_REPREP:
		/* Unprep the request and put it back at the head of the queue.
		 * A new command will be prepared and issued.
		 */
		scsi_requeue_command(q, cmd);
		break;
	case ACTION_RETRY:
		/* Retry the same command immediately */
1102
		__scsi_queue_insert(cmd, SCSI_MLQUEUE_EH_RETRY, 0);