Home | History | Annotate | Line # | Download | only in usb
usbdi.c revision 1.182.4.3
      1 /*	$NetBSD: usbdi.c,v 1.182.4.3 2020/03/01 12:35:16 martin Exp $	*/
      2 
      3 /*
      4  * Copyright (c) 1998, 2012, 2015 The NetBSD Foundation, Inc.
      5  * All rights reserved.
      6  *
      7  * This code is derived from software contributed to The NetBSD Foundation
      8  * by Lennart Augustsson (lennart (at) augustsson.net) at
      9  * Carlstedt Research & Technology, Matthew R. Green (mrg (at) eterna.com.au),
     10  * and Nick Hudson.
     11  *
     12  * Redistribution and use in source and binary forms, with or without
     13  * modification, are permitted provided that the following conditions
     14  * are met:
     15  * 1. Redistributions of source code must retain the above copyright
     16  *    notice, this list of conditions and the following disclaimer.
     17  * 2. Redistributions in binary form must reproduce the above copyright
     18  *    notice, this list of conditions and the following disclaimer in the
     19  *    documentation and/or other materials provided with the distribution.
     20  *
     21  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     22  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     23  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     24  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     25  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     26  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     27  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     28  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     29  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     30  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     31  * POSSIBILITY OF SUCH DAMAGE.
     32  */
     33 
     34 #include <sys/cdefs.h>
     35 __KERNEL_RCSID(0, "$NetBSD: usbdi.c,v 1.182.4.3 2020/03/01 12:35:16 martin Exp $");
     36 
     37 #ifdef _KERNEL_OPT
     38 #include "opt_usb.h"
     39 #include "opt_compat_netbsd.h"
     40 #include "usb_dma.h"
     41 #endif
     42 
     43 #include <sys/param.h>
     44 #include <sys/systm.h>
     45 #include <sys/kernel.h>
     46 #include <sys/device.h>
     47 #include <sys/kmem.h>
     48 #include <sys/proc.h>
     49 #include <sys/bus.h>
     50 #include <sys/cpu.h>
     51 
     52 #include <dev/usb/usb.h>
     53 #include <dev/usb/usbdi.h>
     54 #include <dev/usb/usbdi_util.h>
     55 #include <dev/usb/usbdivar.h>
     56 #include <dev/usb/usb_mem.h>
     57 #include <dev/usb/usb_quirks.h>
     58 #include <dev/usb/usbhist.h>
     59 
     60 /* UTF-8 encoding stuff */
     61 #include <fs/unicode.h>
     62 
     63 extern int usbdebug;
     64 
     65 Static usbd_status usbd_ar_pipe(struct usbd_pipe *);
     66 Static void usbd_start_next(struct usbd_pipe *);
     67 Static usbd_status usbd_open_pipe_ival
     68 	(struct usbd_interface *, uint8_t, uint8_t, struct usbd_pipe **, int);
     69 static void *usbd_alloc_buffer(struct usbd_xfer *, uint32_t);
     70 static void usbd_free_buffer(struct usbd_xfer *);
     71 static struct usbd_xfer *usbd_alloc_xfer(struct usbd_device *, unsigned int);
     72 static usbd_status usbd_free_xfer(struct usbd_xfer *);
     73 static void usbd_request_async_cb(struct usbd_xfer *, void *, usbd_status);
     74 static void usbd_xfer_timeout(void *);
     75 static void usbd_xfer_timeout_task(void *);
     76 static bool usbd_xfer_probe_timeout(struct usbd_xfer *);
     77 static void usbd_xfer_cancel_timeout_async(struct usbd_xfer *);
     78 
     79 #if defined(USB_DEBUG)
     80 void
     81 usbd_dump_iface(struct usbd_interface *iface)
     82 {
     83 	USBHIST_FUNC();
     84 	USBHIST_CALLARGS(usbdebug, "iface %#jx", (uintptr_t)iface, 0, 0, 0);
     85 
     86 	if (iface == NULL)
     87 		return;
     88 	USBHIST_LOG(usbdebug, "     device = %#jx idesc = %#jx index = %d",
     89 	    (uintptr_t)iface->ui_dev, (uintptr_t)iface->ui_idesc,
     90 	    iface->ui_index, 0);
     91 	USBHIST_LOG(usbdebug, "     altindex=%d priv=%#jx",
     92 	    iface->ui_altindex, (uintptr_t)iface->ui_priv, 0, 0);
     93 }
     94 
     95 void
     96 usbd_dump_device(struct usbd_device *dev)
     97 {
     98 	USBHIST_FUNC();
     99 	USBHIST_CALLARGS(usbdebug, "dev = %#jx", (uintptr_t)dev, 0, 0, 0);
    100 
    101 	if (dev == NULL)
    102 		return;
    103 	USBHIST_LOG(usbdebug, "     bus = %#jx default_pipe = %#jx",
    104 	    (uintptr_t)dev->ud_bus, (uintptr_t)dev->ud_pipe0, 0, 0);
    105 	USBHIST_LOG(usbdebug, "     address = %jd config = %jd depth = %jd ",
    106 	    dev->ud_addr, dev->ud_config, dev->ud_depth, 0);
    107 	USBHIST_LOG(usbdebug, "     speed = %jd self_powered = %jd "
    108 	    "power = %jd langid = %jd",
    109 	    dev->ud_speed, dev->ud_selfpowered, dev->ud_power, dev->ud_langid);
    110 }
    111 
    112 void
    113 usbd_dump_endpoint(struct usbd_endpoint *endp)
    114 {
    115 	USBHIST_FUNC();
    116 	USBHIST_CALLARGS(usbdebug, "endp = %#jx", (uintptr_t)endp, 0, 0, 0);
    117 
    118 	if (endp == NULL)
    119 		return;
    120 	USBHIST_LOG(usbdebug, "    edesc = %#jx refcnt = %jd",
    121 	    (uintptr_t)endp->ue_edesc, endp->ue_refcnt, 0, 0);
    122 	if (endp->ue_edesc)
    123 		USBHIST_LOG(usbdebug, "     bEndpointAddress=0x%02x",
    124 		    endp->ue_edesc->bEndpointAddress, 0, 0, 0);
    125 }
    126 
    127 void
    128 usbd_dump_queue(struct usbd_pipe *pipe)
    129 {
    130 	struct usbd_xfer *xfer;
    131 
    132 	USBHIST_FUNC();
    133 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx", (uintptr_t)pipe, 0, 0, 0);
    134 
    135 	SIMPLEQ_FOREACH(xfer, &pipe->up_queue, ux_next) {
    136 		USBHIST_LOG(usbdebug, "     xfer = %#jx", (uintptr_t)xfer,
    137 		    0, 0, 0);
    138 	}
    139 }
    140 
    141 void
    142 usbd_dump_pipe(struct usbd_pipe *pipe)
    143 {
    144 	USBHIST_FUNC();
    145 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx", (uintptr_t)pipe, 0, 0, 0);
    146 
    147 	if (pipe == NULL)
    148 		return;
    149 	usbd_dump_iface(pipe->up_iface);
    150 	usbd_dump_device(pipe->up_dev);
    151 	usbd_dump_endpoint(pipe->up_endpoint);
    152 	USBHIST_LOG(usbdebug, "(usbd_dump_pipe)", 0, 0, 0, 0);
    153 	USBHIST_LOG(usbdebug, "     running = %jd aborting = %jd",
    154 	    pipe->up_running, pipe->up_aborting, 0, 0);
    155 	USBHIST_LOG(usbdebug, "     intrxfer = %#jx, repeat = %jd, "
    156 	    "interval = %jd", (uintptr_t)pipe->up_intrxfer, pipe->up_repeat,
    157 	    pipe->up_interval, 0);
    158 }
    159 #endif
    160 
    161 usbd_status
    162 usbd_open_pipe(struct usbd_interface *iface, uint8_t address,
    163 	       uint8_t flags, struct usbd_pipe **pipe)
    164 {
    165 	return (usbd_open_pipe_ival(iface, address, flags, pipe,
    166 				    USBD_DEFAULT_INTERVAL));
    167 }
    168 
    169 usbd_status
    170 usbd_open_pipe_ival(struct usbd_interface *iface, uint8_t address,
    171 		    uint8_t flags, struct usbd_pipe **pipe, int ival)
    172 {
    173 	struct usbd_pipe *p;
    174 	struct usbd_endpoint *ep;
    175 	usbd_status err;
    176 	int i;
    177 
    178 	USBHIST_FUNC();
    179 	USBHIST_CALLARGS(usbdebug, "iface = %#jx address = 0x%jx flags = 0x%jx",
    180 	    (uintptr_t)iface, address, flags, 0);
    181 
    182 	for (i = 0; i < iface->ui_idesc->bNumEndpoints; i++) {
    183 		ep = &iface->ui_endpoints[i];
    184 		if (ep->ue_edesc == NULL)
    185 			return USBD_IOERROR;
    186 		if (ep->ue_edesc->bEndpointAddress == address)
    187 			goto found;
    188 	}
    189 	return USBD_BAD_ADDRESS;
    190  found:
    191 	if ((flags & USBD_EXCLUSIVE_USE) && ep->ue_refcnt != 0)
    192 		return USBD_IN_USE;
    193 	err = usbd_setup_pipe_flags(iface->ui_dev, iface, ep, ival, &p, flags);
    194 	if (err)
    195 		return err;
    196 	LIST_INSERT_HEAD(&iface->ui_pipes, p, up_next);
    197 	*pipe = p;
    198 	return USBD_NORMAL_COMPLETION;
    199 }
    200 
    201 usbd_status
    202 usbd_open_pipe_intr(struct usbd_interface *iface, uint8_t address,
    203 		    uint8_t flags, struct usbd_pipe **pipe,
    204 		    void *priv, void *buffer, uint32_t len,
    205 		    usbd_callback cb, int ival)
    206 {
    207 	usbd_status err;
    208 	struct usbd_xfer *xfer;
    209 	struct usbd_pipe *ipipe;
    210 
    211 	USBHIST_FUNC();
    212 	USBHIST_CALLARGS(usbdebug, "address = 0x%jx flags = 0x%jx len = %jd",
    213 	    address, flags, len, 0);
    214 
    215 	err = usbd_open_pipe_ival(iface, address,
    216 				  USBD_EXCLUSIVE_USE | (flags & USBD_MPSAFE),
    217 				  &ipipe, ival);
    218 	if (err)
    219 		return err;
    220 	err = usbd_create_xfer(ipipe, len, flags, 0, &xfer);
    221 	if (err)
    222 		goto bad1;
    223 
    224 	usbd_setup_xfer(xfer, priv, buffer, len, flags, USBD_NO_TIMEOUT, cb);
    225 	ipipe->up_intrxfer = xfer;
    226 	ipipe->up_repeat = 1;
    227 	err = usbd_transfer(xfer);
    228 	*pipe = ipipe;
    229 	if (err != USBD_IN_PROGRESS)
    230 		goto bad3;
    231 	return USBD_NORMAL_COMPLETION;
    232 
    233  bad3:
    234 	ipipe->up_intrxfer = NULL;
    235 	ipipe->up_repeat = 0;
    236 
    237 	usbd_destroy_xfer(xfer);
    238  bad1:
    239 	usbd_close_pipe(ipipe);
    240 	return err;
    241 }
    242 
    243 usbd_status
    244 usbd_close_pipe(struct usbd_pipe *pipe)
    245 {
    246 	USBHIST_FUNC(); USBHIST_CALLED(usbdebug);
    247 
    248 	KASSERT(pipe != NULL);
    249 
    250 	usbd_lock_pipe(pipe);
    251 
    252 	if (!SIMPLEQ_EMPTY(&pipe->up_queue)) {
    253 		printf("WARNING: pipe closed with active xfers on addr %d\n",
    254 		    pipe->up_dev->ud_addr);
    255 		usbd_ar_pipe(pipe);
    256 	}
    257 
    258 	KASSERT(SIMPLEQ_EMPTY(&pipe->up_queue));
    259 
    260 	LIST_REMOVE(pipe, up_next);
    261 	pipe->up_endpoint->ue_refcnt--;
    262 
    263 	pipe->up_methods->upm_close(pipe);
    264 
    265 	if (pipe->up_intrxfer != NULL) {
    266 	    	usbd_unlock_pipe(pipe);
    267 		usbd_destroy_xfer(pipe->up_intrxfer);
    268 		usbd_lock_pipe(pipe);
    269 	}
    270 
    271 	usbd_unlock_pipe(pipe);
    272 	kmem_free(pipe, pipe->up_dev->ud_bus->ub_pipesize);
    273 
    274 	return USBD_NORMAL_COMPLETION;
    275 }
    276 
    277 usbd_status
    278 usbd_transfer(struct usbd_xfer *xfer)
    279 {
    280 	struct usbd_pipe *pipe = xfer->ux_pipe;
    281 	usbd_status err;
    282 	unsigned int size, flags;
    283 
    284 	USBHIST_FUNC(); USBHIST_CALLARGS(usbdebug,
    285 	    "xfer = %#jx, flags = %#jx, pipe = %#jx, running = %jd",
    286 	    (uintptr_t)xfer, xfer->ux_flags, (uintptr_t)pipe, pipe->up_running);
    287 	KASSERT(xfer->ux_status == USBD_NOT_STARTED);
    288 
    289 #ifdef USB_DEBUG
    290 	if (usbdebug > 5)
    291 		usbd_dump_queue(pipe);
    292 #endif
    293 	xfer->ux_done = 0;
    294 
    295 	if (pipe->up_aborting) {
    296 		USBHIST_LOG(usbdebug, "<- done xfer %#jx, aborting",
    297 		    (uintptr_t)xfer, 0, 0, 0);
    298 		return USBD_CANCELLED;
    299 	}
    300 
    301 	KASSERT(xfer->ux_length == 0 || xfer->ux_buf != NULL);
    302 
    303 	size = xfer->ux_length;
    304 	flags = xfer->ux_flags;
    305 
    306 	if (size != 0) {
    307 		/*
    308 		 * Use the xfer buffer if none specified in transfer setup.
    309 		 * isoc transfers always use the xfer buffer, i.e.
    310 		 * ux_buffer is always NULL for isoc.
    311 		 */
    312 		if (xfer->ux_buffer == NULL) {
    313 			xfer->ux_buffer = xfer->ux_buf;
    314 		}
    315 
    316 		/*
    317 		 * If not using the xfer buffer copy data to the
    318 		 * xfer buffer for OUT transfers of >0 length
    319 		 */
    320 		if (xfer->ux_buffer != xfer->ux_buf) {
    321 			KASSERT(xfer->ux_buf);
    322 			if (!usbd_xfer_isread(xfer)) {
    323 				memcpy(xfer->ux_buf, xfer->ux_buffer, size);
    324 			}
    325 		}
    326 	}
    327 
    328 	/* xfer is not valid after the transfer method unless synchronous */
    329 	err = pipe->up_methods->upm_transfer(xfer);
    330 
    331 	if (err != USBD_IN_PROGRESS && err) {
    332 		/*
    333 		 * The transfer made it onto the pipe queue, but didn't get
    334 		 * accepted by the HCD for some reason.  It needs removing
    335 		 * from the pipe queue.
    336 		 */
    337 		USBHIST_LOG(usbdebug, "xfer failed: %s, reinserting",
    338 		    err, 0, 0, 0);
    339 		usbd_lock_pipe(pipe);
    340 		SIMPLEQ_REMOVE_HEAD(&pipe->up_queue, ux_next);
    341 		if (pipe->up_serialise)
    342 			usbd_start_next(pipe);
    343 		usbd_unlock_pipe(pipe);
    344 	}
    345 
    346 	if (!(flags & USBD_SYNCHRONOUS)) {
    347 		USBHIST_LOG(usbdebug, "<- done xfer %#jx, not sync (err %jd)",
    348 		    (uintptr_t)xfer, err, 0, 0);
    349 		return err;
    350 	}
    351 
    352 	if (err != USBD_IN_PROGRESS) {
    353 		USBHIST_LOG(usbdebug, "<- done xfer %#jx, sync (err %jd)",
    354 		    (uintptr_t)xfer, err, 0, 0);
    355 		return err;
    356 	}
    357 
    358 	/* Sync transfer, wait for completion. */
    359 	usbd_lock_pipe(pipe);
    360 	while (!xfer->ux_done) {
    361 		if (pipe->up_dev->ud_bus->ub_usepolling)
    362 			panic("usbd_transfer: not done");
    363 		USBHIST_LOG(usbdebug, "<- sleeping on xfer %#jx",
    364 		    (uintptr_t)xfer, 0, 0, 0);
    365 
    366 		err = 0;
    367 		if ((flags & USBD_SYNCHRONOUS_SIG) != 0) {
    368 			err = cv_wait_sig(&xfer->ux_cv, pipe->up_dev->ud_bus->ub_lock);
    369 		} else {
    370 			cv_wait(&xfer->ux_cv, pipe->up_dev->ud_bus->ub_lock);
    371 		}
    372 		if (err) {
    373 			if (!xfer->ux_done)
    374 				pipe->up_methods->upm_abort(xfer);
    375 			break;
    376 		}
    377 	}
    378 	usbd_unlock_pipe(pipe);
    379 	return xfer->ux_status;
    380 }
    381 
    382 /* Like usbd_transfer(), but waits for completion. */
    383 usbd_status
    384 usbd_sync_transfer(struct usbd_xfer *xfer)
    385 {
    386 	xfer->ux_flags |= USBD_SYNCHRONOUS;
    387 	return usbd_transfer(xfer);
    388 }
    389 
    390 /* Like usbd_transfer(), but waits for completion and listens for signals. */
    391 usbd_status
    392 usbd_sync_transfer_sig(struct usbd_xfer *xfer)
    393 {
    394 	xfer->ux_flags |= USBD_SYNCHRONOUS | USBD_SYNCHRONOUS_SIG;
    395 	return usbd_transfer(xfer);
    396 }
    397 
    398 static void *
    399 usbd_alloc_buffer(struct usbd_xfer *xfer, uint32_t size)
    400 {
    401 	KASSERT(xfer->ux_buf == NULL);
    402 	KASSERT(size != 0);
    403 
    404 	xfer->ux_bufsize = 0;
    405 #if NUSB_DMA > 0
    406 	struct usbd_bus *bus = xfer->ux_bus;
    407 
    408 	if (bus->ub_usedma) {
    409 		usb_dma_t *dmap = &xfer->ux_dmabuf;
    410 
    411 		int err = usb_allocmem_flags(bus, size, 0, dmap, bus->ub_dmaflags);
    412 		if (err) {
    413 			return NULL;
    414 		}
    415 		xfer->ux_buf = KERNADDR(&xfer->ux_dmabuf, 0);
    416 		xfer->ux_bufsize = size;
    417 
    418 		return xfer->ux_buf;
    419 	}
    420 #endif
    421 	KASSERT(xfer->ux_bus->ub_usedma == false);
    422 	xfer->ux_buf = kmem_alloc(size, KM_SLEEP);
    423 	xfer->ux_bufsize = size;
    424 	return xfer->ux_buf;
    425 }
    426 
    427 static void
    428 usbd_free_buffer(struct usbd_xfer *xfer)
    429 {
    430 	KASSERT(xfer->ux_buf != NULL);
    431 	KASSERT(xfer->ux_bufsize != 0);
    432 
    433 	void *buf = xfer->ux_buf;
    434 	uint32_t size = xfer->ux_bufsize;
    435 
    436 	xfer->ux_buf = NULL;
    437 	xfer->ux_bufsize = 0;
    438 
    439 #if NUSB_DMA > 0
    440 	struct usbd_bus *bus = xfer->ux_bus;
    441 
    442 	if (bus->ub_usedma) {
    443 		usb_dma_t *dmap = &xfer->ux_dmabuf;
    444 
    445 		usb_freemem(bus, dmap);
    446 		return;
    447 	}
    448 #endif
    449 	KASSERT(xfer->ux_bus->ub_usedma == false);
    450 
    451 	kmem_free(buf, size);
    452 }
    453 
    454 void *
    455 usbd_get_buffer(struct usbd_xfer *xfer)
    456 {
    457 	return xfer->ux_buf;
    458 }
    459 
    460 struct usbd_pipe *
    461 usbd_get_pipe0(struct usbd_device *dev)
    462 {
    463 
    464 	return dev->ud_pipe0;
    465 }
    466 
    467 static struct usbd_xfer *
    468 usbd_alloc_xfer(struct usbd_device *dev, unsigned int nframes)
    469 {
    470 	struct usbd_xfer *xfer;
    471 
    472 	USBHIST_FUNC();
    473 
    474 	ASSERT_SLEEPABLE();
    475 
    476 	xfer = dev->ud_bus->ub_methods->ubm_allocx(dev->ud_bus, nframes);
    477 	if (xfer == NULL)
    478 		goto out;
    479 	xfer->ux_bus = dev->ud_bus;
    480 	callout_init(&xfer->ux_callout, CALLOUT_MPSAFE);
    481 	callout_setfunc(&xfer->ux_callout, usbd_xfer_timeout, xfer);
    482 	cv_init(&xfer->ux_cv, "usbxfer");
    483 	usb_init_task(&xfer->ux_aborttask, usbd_xfer_timeout_task, xfer,
    484 	    USB_TASKQ_MPSAFE);
    485 
    486 out:
    487 	USBHIST_CALLARGS(usbdebug, "returns %#jx", (uintptr_t)xfer, 0, 0, 0);
    488 
    489 	return xfer;
    490 }
    491 
    492 static usbd_status
    493 usbd_free_xfer(struct usbd_xfer *xfer)
    494 {
    495 	USBHIST_FUNC();
    496 	USBHIST_CALLARGS(usbdebug, "%#jx", (uintptr_t)xfer, 0, 0, 0);
    497 
    498 	if (xfer->ux_buf) {
    499 		usbd_free_buffer(xfer);
    500 	}
    501 
    502 	/* Wait for any straggling timeout to complete. */
    503 	mutex_enter(xfer->ux_bus->ub_lock);
    504 	xfer->ux_timeout_reset = false; /* do not resuscitate */
    505 	callout_halt(&xfer->ux_callout, xfer->ux_bus->ub_lock);
    506 	usb_rem_task_wait(xfer->ux_pipe->up_dev, &xfer->ux_aborttask,
    507 	    USB_TASKQ_HC, xfer->ux_bus->ub_lock);
    508 	mutex_exit(xfer->ux_bus->ub_lock);
    509 
    510 	cv_destroy(&xfer->ux_cv);
    511 	xfer->ux_bus->ub_methods->ubm_freex(xfer->ux_bus, xfer);
    512 	return USBD_NORMAL_COMPLETION;
    513 }
    514 
    515 int
    516 usbd_create_xfer(struct usbd_pipe *pipe, size_t len, unsigned int flags,
    517     unsigned int nframes, struct usbd_xfer **xp)
    518 {
    519 	KASSERT(xp != NULL);
    520 	void *buf = NULL;
    521 
    522 	struct usbd_xfer *xfer = usbd_alloc_xfer(pipe->up_dev, nframes);
    523 	if (xfer == NULL)
    524 		return ENOMEM;
    525 
    526 	if (len) {
    527 		buf = usbd_alloc_buffer(xfer, len);
    528 		if (!buf) {
    529 			usbd_free_xfer(xfer);
    530 			return ENOMEM;
    531 		}
    532 	}
    533 	xfer->ux_pipe = pipe;
    534 	xfer->ux_flags = flags;
    535 	xfer->ux_nframes = nframes;
    536 	xfer->ux_methods = pipe->up_methods;
    537 
    538 	if (xfer->ux_methods->upm_init) {
    539 		int err = xfer->ux_methods->upm_init(xfer);
    540 		if (err) {
    541 			if (buf)
    542 				usbd_free_buffer(xfer);
    543 			usbd_free_xfer(xfer);
    544 			return err;
    545 		}
    546 	}
    547 
    548 	*xp = xfer;
    549 	return 0;
    550 }
    551 
    552 void
    553 usbd_destroy_xfer(struct usbd_xfer *xfer)
    554 {
    555 
    556 	if (xfer->ux_methods->upm_fini) {
    557 		xfer->ux_methods->upm_fini(xfer);
    558 	}
    559 
    560 	usbd_free_xfer(xfer);
    561 }
    562 
    563 void
    564 usbd_setup_xfer(struct usbd_xfer *xfer, void *priv, void *buffer,
    565     uint32_t length, uint16_t flags, uint32_t timeout, usbd_callback callback)
    566 {
    567 	KASSERT(xfer->ux_pipe);
    568 
    569 	xfer->ux_priv = priv;
    570 	xfer->ux_buffer = buffer;
    571 	xfer->ux_length = length;
    572 	xfer->ux_actlen = 0;
    573 	xfer->ux_flags = flags;
    574 	xfer->ux_timeout = timeout;
    575 	xfer->ux_status = USBD_NOT_STARTED;
    576 	xfer->ux_callback = callback;
    577 	xfer->ux_rqflags &= ~URQ_REQUEST;
    578 	xfer->ux_nframes = 0;
    579 }
    580 
    581 void
    582 usbd_setup_default_xfer(struct usbd_xfer *xfer, struct usbd_device *dev,
    583     void *priv, uint32_t timeout, usb_device_request_t *req, void *buffer,
    584     uint32_t length, uint16_t flags, usbd_callback callback)
    585 {
    586 	KASSERT(xfer->ux_pipe == dev->ud_pipe0);
    587 
    588 	xfer->ux_priv = priv;
    589 	xfer->ux_buffer = buffer;
    590 	xfer->ux_length = length;
    591 	xfer->ux_actlen = 0;
    592 	xfer->ux_flags = flags;
    593 	xfer->ux_timeout = timeout;
    594 	xfer->ux_status = USBD_NOT_STARTED;
    595 	xfer->ux_callback = callback;
    596 	xfer->ux_request = *req;
    597 	xfer->ux_rqflags |= URQ_REQUEST;
    598 	xfer->ux_nframes = 0;
    599 }
    600 
    601 void
    602 usbd_setup_isoc_xfer(struct usbd_xfer *xfer, void *priv, uint16_t *frlengths,
    603     uint32_t nframes, uint16_t flags, usbd_callback callback)
    604 {
    605 	xfer->ux_priv = priv;
    606 	xfer->ux_buffer = NULL;
    607 	xfer->ux_length = 0;
    608 	xfer->ux_actlen = 0;
    609 	xfer->ux_flags = flags;
    610 	xfer->ux_timeout = USBD_NO_TIMEOUT;
    611 	xfer->ux_status = USBD_NOT_STARTED;
    612 	xfer->ux_callback = callback;
    613 	xfer->ux_rqflags &= ~URQ_REQUEST;
    614 	xfer->ux_frlengths = frlengths;
    615 	xfer->ux_nframes = nframes;
    616 }
    617 
    618 void
    619 usbd_get_xfer_status(struct usbd_xfer *xfer, void **priv,
    620 		     void **buffer, uint32_t *count, usbd_status *status)
    621 {
    622 	if (priv != NULL)
    623 		*priv = xfer->ux_priv;
    624 	if (buffer != NULL)
    625 		*buffer = xfer->ux_buffer;
    626 	if (count != NULL)
    627 		*count = xfer->ux_actlen;
    628 	if (status != NULL)
    629 		*status = xfer->ux_status;
    630 }
    631 
    632 usb_config_descriptor_t *
    633 usbd_get_config_descriptor(struct usbd_device *dev)
    634 {
    635 	KASSERT(dev != NULL);
    636 
    637 	return dev->ud_cdesc;
    638 }
    639 
    640 usb_interface_descriptor_t *
    641 usbd_get_interface_descriptor(struct usbd_interface *iface)
    642 {
    643 	KASSERT(iface != NULL);
    644 
    645 	return iface->ui_idesc;
    646 }
    647 
    648 usb_device_descriptor_t *
    649 usbd_get_device_descriptor(struct usbd_device *dev)
    650 {
    651 	KASSERT(dev != NULL);
    652 
    653 	return &dev->ud_ddesc;
    654 }
    655 
    656 usb_endpoint_descriptor_t *
    657 usbd_interface2endpoint_descriptor(struct usbd_interface *iface, uint8_t index)
    658 {
    659 
    660 	if (index >= iface->ui_idesc->bNumEndpoints)
    661 		return NULL;
    662 	return iface->ui_endpoints[index].ue_edesc;
    663 }
    664 
    665 /* Some drivers may wish to abort requests on the default pipe, *
    666  * but there is no mechanism for getting a handle on it.        */
    667 usbd_status
    668 usbd_abort_default_pipe(struct usbd_device *device)
    669 {
    670 	return usbd_abort_pipe(device->ud_pipe0);
    671 }
    672 
    673 usbd_status
    674 usbd_abort_pipe(struct usbd_pipe *pipe)
    675 {
    676 	usbd_status err;
    677 
    678 	KASSERT(pipe != NULL);
    679 
    680 	usbd_lock_pipe(pipe);
    681 	err = usbd_ar_pipe(pipe);
    682 	usbd_unlock_pipe(pipe);
    683 	return err;
    684 }
    685 
    686 usbd_status
    687 usbd_clear_endpoint_stall(struct usbd_pipe *pipe)
    688 {
    689 	struct usbd_device *dev = pipe->up_dev;
    690 	usb_device_request_t req;
    691 	usbd_status err;
    692 
    693 	USBHIST_FUNC(); USBHIST_CALLED(usbdebug);
    694 
    695 	/*
    696 	 * Clearing en endpoint stall resets the endpoint toggle, so
    697 	 * do the same to the HC toggle.
    698 	 */
    699 	pipe->up_methods->upm_cleartoggle(pipe);
    700 
    701 	req.bmRequestType = UT_WRITE_ENDPOINT;
    702 	req.bRequest = UR_CLEAR_FEATURE;
    703 	USETW(req.wValue, UF_ENDPOINT_HALT);
    704 	USETW(req.wIndex, pipe->up_endpoint->ue_edesc->bEndpointAddress);
    705 	USETW(req.wLength, 0);
    706 	err = usbd_do_request(dev, &req, 0);
    707 #if 0
    708 XXX should we do this?
    709 	if (!err) {
    710 		pipe->state = USBD_PIPE_ACTIVE;
    711 		/* XXX activate pipe */
    712 	}
    713 #endif
    714 	return err;
    715 }
    716 
    717 void
    718 usbd_clear_endpoint_stall_task(void *arg)
    719 {
    720 	struct usbd_pipe *pipe = arg;
    721 	struct usbd_device *dev = pipe->up_dev;
    722 	usb_device_request_t req;
    723 
    724 	pipe->up_methods->upm_cleartoggle(pipe);
    725 
    726 	req.bmRequestType = UT_WRITE_ENDPOINT;
    727 	req.bRequest = UR_CLEAR_FEATURE;
    728 	USETW(req.wValue, UF_ENDPOINT_HALT);
    729 	USETW(req.wIndex, pipe->up_endpoint->ue_edesc->bEndpointAddress);
    730 	USETW(req.wLength, 0);
    731 	(void)usbd_do_request(dev, &req, 0);
    732 }
    733 
    734 void
    735 usbd_clear_endpoint_stall_async(struct usbd_pipe *pipe)
    736 {
    737 	usb_add_task(pipe->up_dev, &pipe->up_async_task, USB_TASKQ_DRIVER);
    738 }
    739 
    740 void
    741 usbd_clear_endpoint_toggle(struct usbd_pipe *pipe)
    742 {
    743 
    744 	pipe->up_methods->upm_cleartoggle(pipe);
    745 }
    746 
    747 usbd_status
    748 usbd_endpoint_count(struct usbd_interface *iface, uint8_t *count)
    749 {
    750 	KASSERT(iface != NULL);
    751 	KASSERT(iface->ui_idesc != NULL);
    752 
    753 	*count = iface->ui_idesc->bNumEndpoints;
    754 	return USBD_NORMAL_COMPLETION;
    755 }
    756 
    757 usbd_status
    758 usbd_interface_count(struct usbd_device *dev, uint8_t *count)
    759 {
    760 
    761 	if (dev->ud_cdesc == NULL)
    762 		return USBD_NOT_CONFIGURED;
    763 	*count = dev->ud_cdesc->bNumInterface;
    764 	return USBD_NORMAL_COMPLETION;
    765 }
    766 
    767 void
    768 usbd_interface2device_handle(struct usbd_interface *iface,
    769 			     struct usbd_device **dev)
    770 {
    771 
    772 	*dev = iface->ui_dev;
    773 }
    774 
    775 usbd_status
    776 usbd_device2interface_handle(struct usbd_device *dev,
    777 			     uint8_t ifaceno, struct usbd_interface **iface)
    778 {
    779 
    780 	if (dev->ud_cdesc == NULL)
    781 		return USBD_NOT_CONFIGURED;
    782 	if (ifaceno >= dev->ud_cdesc->bNumInterface)
    783 		return USBD_INVAL;
    784 	*iface = &dev->ud_ifaces[ifaceno];
    785 	return USBD_NORMAL_COMPLETION;
    786 }
    787 
    788 struct usbd_device *
    789 usbd_pipe2device_handle(struct usbd_pipe *pipe)
    790 {
    791 	KASSERT(pipe != NULL);
    792 
    793 	return pipe->up_dev;
    794 }
    795 
    796 /* XXXX use altno */
    797 usbd_status
    798 usbd_set_interface(struct usbd_interface *iface, int altidx)
    799 {
    800 	usb_device_request_t req;
    801 	usbd_status err;
    802 	void *endpoints;
    803 
    804 	USBHIST_FUNC();
    805 
    806 	if (LIST_FIRST(&iface->ui_pipes) != NULL)
    807 		return USBD_IN_USE;
    808 
    809 	endpoints = iface->ui_endpoints;
    810 	int nendpt = iface->ui_idesc->bNumEndpoints;
    811 	USBHIST_CALLARGS(usbdebug, "iface %#jx endpoints = %#jx nendpt %jd",
    812 	    (uintptr_t)iface, (uintptr_t)endpoints,
    813 	    iface->ui_idesc->bNumEndpoints, 0);
    814 	err = usbd_fill_iface_data(iface->ui_dev, iface->ui_index, altidx);
    815 	if (err)
    816 		return err;
    817 
    818 	/* new setting works, we can free old endpoints */
    819 	if (endpoints != NULL) {
    820 		USBHIST_LOG(usbdebug, "iface %#jx endpoints = %#jx nendpt %jd",
    821 		    (uintptr_t)iface, (uintptr_t)endpoints, nendpt, 0);
    822 		kmem_free(endpoints, nendpt * sizeof(struct usbd_endpoint));
    823 	}
    824 	KASSERT(iface->ui_idesc != NULL);
    825 
    826 	req.bmRequestType = UT_WRITE_INTERFACE;
    827 	req.bRequest = UR_SET_INTERFACE;
    828 	USETW(req.wValue, iface->ui_idesc->bAlternateSetting);
    829 	USETW(req.wIndex, iface->ui_idesc->bInterfaceNumber);
    830 	USETW(req.wLength, 0);
    831 	return usbd_do_request(iface->ui_dev, &req, 0);
    832 }
    833 
    834 int
    835 usbd_get_no_alts(usb_config_descriptor_t *cdesc, int ifaceno)
    836 {
    837 	char *p = (char *)cdesc;
    838 	char *end = p + UGETW(cdesc->wTotalLength);
    839 	usb_interface_descriptor_t *d;
    840 	int n;
    841 
    842 	for (n = 0; p < end; p += d->bLength) {
    843 		d = (usb_interface_descriptor_t *)p;
    844 		if (p + d->bLength <= end &&
    845 		    d->bDescriptorType == UDESC_INTERFACE &&
    846 		    d->bInterfaceNumber == ifaceno)
    847 			n++;
    848 	}
    849 	return n;
    850 }
    851 
    852 int
    853 usbd_get_interface_altindex(struct usbd_interface *iface)
    854 {
    855 	return iface->ui_altindex;
    856 }
    857 
    858 usbd_status
    859 usbd_get_interface(struct usbd_interface *iface, uint8_t *aiface)
    860 {
    861 	usb_device_request_t req;
    862 
    863 	req.bmRequestType = UT_READ_INTERFACE;
    864 	req.bRequest = UR_GET_INTERFACE;
    865 	USETW(req.wValue, 0);
    866 	USETW(req.wIndex, iface->ui_idesc->bInterfaceNumber);
    867 	USETW(req.wLength, 1);
    868 	return usbd_do_request(iface->ui_dev, &req, aiface);
    869 }
    870 
    871 /*** Internal routines ***/
    872 
    873 /* Dequeue all pipe operations, called with bus lock held. */
    874 Static usbd_status
    875 usbd_ar_pipe(struct usbd_pipe *pipe)
    876 {
    877 	struct usbd_xfer *xfer;
    878 
    879 	USBHIST_FUNC();
    880 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx", (uintptr_t)pipe, 0, 0, 0);
    881 
    882 	KASSERT(mutex_owned(pipe->up_dev->ud_bus->ub_lock));
    883 
    884 #ifdef USB_DEBUG
    885 	if (usbdebug > 5)
    886 		usbd_dump_queue(pipe);
    887 #endif
    888 	pipe->up_repeat = 0;
    889 	pipe->up_running = 0;
    890 	pipe->up_aborting = 1;
    891 	while ((xfer = SIMPLEQ_FIRST(&pipe->up_queue)) != NULL) {
    892 		USBHIST_LOG(usbdebug, "pipe = %#jx xfer = %#jx "
    893 		    "(methods = %#jx)", (uintptr_t)pipe, (uintptr_t)xfer,
    894 		    (uintptr_t)pipe->up_methods, 0);
    895 		if (xfer->ux_status == USBD_NOT_STARTED) {
    896 			SIMPLEQ_REMOVE_HEAD(&pipe->up_queue, ux_next);
    897 		} else {
    898 			/* Make the HC abort it (and invoke the callback). */
    899 			pipe->up_methods->upm_abort(xfer);
    900 			/* XXX only for non-0 usbd_clear_endpoint_stall(pipe); */
    901 		}
    902 	}
    903 	pipe->up_aborting = 0;
    904 	return USBD_NORMAL_COMPLETION;
    905 }
    906 
    907 /* Called with USB lock held. */
    908 void
    909 usb_transfer_complete(struct usbd_xfer *xfer)
    910 {
    911 	struct usbd_pipe *pipe = xfer->ux_pipe;
    912 	struct usbd_bus *bus = pipe->up_dev->ud_bus;
    913 	int sync = xfer->ux_flags & USBD_SYNCHRONOUS;
    914 	int erred;
    915 	int polling = bus->ub_usepolling;
    916 	int repeat = pipe->up_repeat;
    917 
    918 	USBHIST_FUNC();
    919 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx xfer = %#jx status = %jd "
    920 	    "actlen = %jd", (uintptr_t)pipe, (uintptr_t)xfer, xfer->ux_status,
    921 	    xfer->ux_actlen);
    922 
    923 	KASSERT(polling || mutex_owned(pipe->up_dev->ud_bus->ub_lock));
    924 	KASSERTMSG(xfer->ux_state == XFER_ONQU, "xfer %p state is %x", xfer,
    925 	    xfer->ux_state);
    926 	KASSERT(pipe != NULL);
    927 
    928 	/*
    929 	 * If device is known to miss out ack, then pretend that
    930 	 * output timeout is a success. Userland should handle
    931 	 * the logic to verify that the operation succeeded.
    932 	 */
    933 	if (pipe->up_dev->ud_quirks &&
    934 	    pipe->up_dev->ud_quirks->uq_flags & UQ_MISS_OUT_ACK &&
    935 	    xfer->ux_status == USBD_TIMEOUT &&
    936 	    !usbd_xfer_isread(xfer)) {
    937 		USBHIST_LOG(usbdebug, "Possible output ack miss for xfer %#jx: "
    938 		    "hiding write timeout to %d.%s for %d bytes written",
    939 		    (uintptr_t)xfer, curlwp->l_proc->p_pid, curlwp->l_lid,
    940 		    xfer->ux_length);
    941 
    942 		xfer->ux_status = USBD_NORMAL_COMPLETION;
    943 		xfer->ux_actlen = xfer->ux_length;
    944 	}
    945 
    946 	erred = xfer->ux_status == USBD_CANCELLED ||
    947 	        xfer->ux_status == USBD_TIMEOUT;
    948 
    949 	if (!repeat) {
    950 		/* Remove request from queue. */
    951 
    952 		KASSERTMSG(!SIMPLEQ_EMPTY(&pipe->up_queue),
    953 		    "pipe %p is empty, but xfer %p wants to complete", pipe,
    954 		     xfer);
    955 		KASSERTMSG(xfer == SIMPLEQ_FIRST(&pipe->up_queue),
    956 		    "xfer %p is not start of queue (%p is at start)", xfer,
    957 		   SIMPLEQ_FIRST(&pipe->up_queue));
    958 
    959 #ifdef DIAGNOSTIC
    960 		xfer->ux_state = XFER_BUSY;
    961 #endif
    962 		SIMPLEQ_REMOVE_HEAD(&pipe->up_queue, ux_next);
    963 	}
    964 	USBHIST_LOG(usbdebug, "xfer %#jx: repeat %jd new head = %#jx",
    965 	    (uintptr_t)xfer, repeat, (uintptr_t)SIMPLEQ_FIRST(&pipe->up_queue),
    966 	    0);
    967 
    968 	/* Count completed transfers. */
    969 	++pipe->up_dev->ud_bus->ub_stats.uds_requests
    970 		[pipe->up_endpoint->ue_edesc->bmAttributes & UE_XFERTYPE];
    971 
    972 	xfer->ux_done = 1;
    973 	if (!xfer->ux_status && xfer->ux_actlen < xfer->ux_length &&
    974 	    !(xfer->ux_flags & USBD_SHORT_XFER_OK)) {
    975 		USBHIST_LOG(usbdebug, "short transfer %jd < %jd",
    976 		    xfer->ux_actlen, xfer->ux_length, 0, 0);
    977 		xfer->ux_status = USBD_SHORT_XFER;
    978 	}
    979 
    980 	USBHIST_LOG(usbdebug, "xfer %#jx doing done %#jx", (uintptr_t)xfer,
    981 	    (uintptr_t)pipe->up_methods->upm_done, 0, 0);
    982 	pipe->up_methods->upm_done(xfer);
    983 
    984 	if (xfer->ux_length != 0 && xfer->ux_buffer != xfer->ux_buf) {
    985 		KDASSERTMSG(xfer->ux_actlen <= xfer->ux_length,
    986 		    "actlen %d length %d",xfer->ux_actlen, xfer->ux_length);
    987 
    988 		/* Only if IN transfer */
    989 		if (usbd_xfer_isread(xfer)) {
    990 			memcpy(xfer->ux_buffer, xfer->ux_buf, xfer->ux_actlen);
    991 		}
    992 	}
    993 
    994 	USBHIST_LOG(usbdebug, "xfer %#jx doing callback %#jx status %jd",
    995 	    (uintptr_t)xfer, (uintptr_t)xfer->ux_callback, xfer->ux_status, 0);
    996 
    997 	if (xfer->ux_callback) {
    998 		if (!polling) {
    999 			mutex_exit(pipe->up_dev->ud_bus->ub_lock);
   1000 			if (!(pipe->up_flags & USBD_MPSAFE))
   1001 				KERNEL_LOCK(1, curlwp);
   1002 		}
   1003 
   1004 		xfer->ux_callback(xfer, xfer->ux_priv, xfer->ux_status);
   1005 
   1006 		if (!polling) {
   1007 			if (!(pipe->up_flags & USBD_MPSAFE))
   1008 				KERNEL_UNLOCK_ONE(curlwp);
   1009 			mutex_enter(pipe->up_dev->ud_bus->ub_lock);
   1010 		}
   1011 	}
   1012 
   1013 	if (sync && !polling) {
   1014 		USBHIST_LOG(usbdebug, "<- done xfer %#jx, wakeup",
   1015 		    (uintptr_t)xfer, 0, 0, 0);
   1016 		cv_broadcast(&xfer->ux_cv);
   1017 	}
   1018 
   1019 	if (repeat) {
   1020 		xfer->ux_actlen = 0;
   1021 		xfer->ux_status = USBD_NOT_STARTED;
   1022 	} else {
   1023 		/* XXX should we stop the queue on all errors? */
   1024 		if (erred && pipe->up_iface != NULL)	/* not control pipe */
   1025 			pipe->up_running = 0;
   1026 	}
   1027 	if (pipe->up_running && pipe->up_serialise)
   1028 		usbd_start_next(pipe);
   1029 }
   1030 
   1031 /* Called with USB lock held. */
   1032 usbd_status
   1033 usb_insert_transfer(struct usbd_xfer *xfer)
   1034 {
   1035 	struct usbd_pipe *pipe = xfer->ux_pipe;
   1036 	usbd_status err;
   1037 
   1038 	USBHIST_FUNC(); USBHIST_CALLARGS(usbdebug,
   1039 	    "xfer = %#jx pipe = %#jx running = %jd timeout = %jd",
   1040 	    (uintptr_t)xfer, (uintptr_t)pipe,
   1041 	    pipe->up_running, xfer->ux_timeout);
   1042 
   1043 	KASSERT(mutex_owned(pipe->up_dev->ud_bus->ub_lock));
   1044 	KASSERTMSG(xfer->ux_state == XFER_BUSY, "xfer %p state is %x", xfer,
   1045 	    xfer->ux_state);
   1046 
   1047 #ifdef DIAGNOSTIC
   1048 	xfer->ux_state = XFER_ONQU;
   1049 #endif
   1050 	SIMPLEQ_INSERT_TAIL(&pipe->up_queue, xfer, ux_next);
   1051 	if (pipe->up_running && pipe->up_serialise)
   1052 		err = USBD_IN_PROGRESS;
   1053 	else {
   1054 		pipe->up_running = 1;
   1055 		err = USBD_NORMAL_COMPLETION;
   1056 	}
   1057 	USBHIST_LOG(usbdebug, "<- done xfer %#jx, err %jd", (uintptr_t)xfer,
   1058 	    err, 0, 0);
   1059 	return err;
   1060 }
   1061 
   1062 /* Called with USB lock held. */
   1063 void
   1064 usbd_start_next(struct usbd_pipe *pipe)
   1065 {
   1066 	struct usbd_xfer *xfer;
   1067 	usbd_status err;
   1068 
   1069 	USBHIST_FUNC();
   1070 
   1071 	KASSERT(pipe != NULL);
   1072 	KASSERT(pipe->up_methods != NULL);
   1073 	KASSERT(pipe->up_methods->upm_start != NULL);
   1074 	KASSERT(pipe->up_serialise == true);
   1075 
   1076 	int polling = pipe->up_dev->ud_bus->ub_usepolling;
   1077 	KASSERT(polling || mutex_owned(pipe->up_dev->ud_bus->ub_lock));
   1078 
   1079 	/* Get next request in queue. */
   1080 	xfer = SIMPLEQ_FIRST(&pipe->up_queue);
   1081 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx, xfer = %#jx", (uintptr_t)pipe,
   1082 	    (uintptr_t)xfer, 0, 0);
   1083 	if (xfer == NULL) {
   1084 		pipe->up_running = 0;
   1085 	} else {
   1086 		if (!polling)
   1087 			mutex_exit(pipe->up_dev->ud_bus->ub_lock);
   1088 		err = pipe->up_methods->upm_start(xfer);
   1089 		if (!polling)
   1090 			mutex_enter(pipe->up_dev->ud_bus->ub_lock);
   1091 
   1092 		if (err != USBD_IN_PROGRESS) {
   1093 			USBHIST_LOG(usbdebug, "error = %jd", err, 0, 0, 0);
   1094 			pipe->up_running = 0;
   1095 			/* XXX do what? */
   1096 		}
   1097 	}
   1098 
   1099 	KASSERT(polling || mutex_owned(pipe->up_dev->ud_bus->ub_lock));
   1100 }
   1101 
   1102 usbd_status
   1103 usbd_do_request(struct usbd_device *dev, usb_device_request_t *req, void *data)
   1104 {
   1105 
   1106 	return usbd_do_request_flags(dev, req, data, 0, 0,
   1107 	    USBD_DEFAULT_TIMEOUT);
   1108 }
   1109 
   1110 usbd_status
   1111 usbd_do_request_flags(struct usbd_device *dev, usb_device_request_t *req,
   1112     void *data, uint16_t flags, int *actlen, uint32_t timeout)
   1113 {
   1114 	size_t len = UGETW(req->wLength);
   1115 
   1116 	return usbd_do_request_len(dev, req, len, data, flags, actlen, timeout);
   1117 }
   1118 
   1119 usbd_status
   1120 usbd_do_request_len(struct usbd_device *dev, usb_device_request_t *req,
   1121     size_t len, void *data, uint16_t flags, int *actlen, uint32_t timeout)
   1122 {
   1123 	struct usbd_xfer *xfer;
   1124 	usbd_status err;
   1125 
   1126 	KASSERT(len >= UGETW(req->wLength));
   1127 
   1128 	USBHIST_FUNC();
   1129 	USBHIST_CALLARGS(usbdebug, "dev=%#jx req=%jx flags=%jx len=%jx",
   1130 	    (uintptr_t)dev, (uintptr_t)req, flags, len);
   1131 
   1132 	ASSERT_SLEEPABLE();
   1133 
   1134 	int error = usbd_create_xfer(dev->ud_pipe0, len, 0, 0, &xfer);
   1135 	if (error)
   1136 		return error;
   1137 
   1138 	usbd_setup_default_xfer(xfer, dev, 0, timeout, req, data,
   1139 	    UGETW(req->wLength), flags, NULL);
   1140 	KASSERT(xfer->ux_pipe == dev->ud_pipe0);
   1141 	err = usbd_sync_transfer(xfer);
   1142 #if defined(USB_DEBUG) || defined(DIAGNOSTIC)
   1143 	if (xfer->ux_actlen > xfer->ux_length) {
   1144 		USBHIST_LOG(usbdebug, "overrun addr = %jd type = 0x%02jx",
   1145 		    dev->ud_addr, xfer->ux_request.bmRequestType, 0, 0);
   1146 		USBHIST_LOG(usbdebug, "     req = 0x%02jx val = %jd "
   1147 		    "index = %jd",
   1148 		    xfer->ux_request.bRequest, UGETW(xfer->ux_request.wValue),
   1149 		    UGETW(xfer->ux_request.wIndex), 0);
   1150 		USBHIST_LOG(usbdebug, "     rlen = %jd length = %jd "
   1151 		    "actlen = %jd",
   1152 		    UGETW(xfer->ux_request.wLength),
   1153 		    xfer->ux_length, xfer->ux_actlen, 0);
   1154 	}
   1155 #endif
   1156 	if (actlen != NULL)
   1157 		*actlen = xfer->ux_actlen;
   1158 
   1159 	usbd_destroy_xfer(xfer);
   1160 
   1161 	if (err) {
   1162 		USBHIST_LOG(usbdebug, "returning err = %jd", err, 0, 0, 0);
   1163 	}
   1164 	return err;
   1165 }
   1166 
   1167 static void
   1168 usbd_request_async_cb(struct usbd_xfer *xfer, void *priv, usbd_status status)
   1169 {
   1170 	usbd_free_xfer(xfer);
   1171 }
   1172 
   1173 /*
   1174  * Execute a request without waiting for completion.
   1175  * Can be used from interrupt context.
   1176  */
   1177 usbd_status
   1178 usbd_request_async(struct usbd_device *dev, struct usbd_xfer *xfer,
   1179     usb_device_request_t *req, void *priv, usbd_callback callback)
   1180 {
   1181 	usbd_status err;
   1182 
   1183 	if (callback == NULL)
   1184 		callback = usbd_request_async_cb;
   1185 
   1186 	usbd_setup_default_xfer(xfer, dev, priv,
   1187 	    USBD_DEFAULT_TIMEOUT, req, NULL, UGETW(req->wLength), 0,
   1188 	    callback);
   1189 	err = usbd_transfer(xfer);
   1190 	if (err != USBD_IN_PROGRESS) {
   1191 		usbd_free_xfer(xfer);
   1192 		return (err);
   1193 	}
   1194 	return (USBD_NORMAL_COMPLETION);
   1195 }
   1196 
   1197 const struct usbd_quirks *
   1198 usbd_get_quirks(struct usbd_device *dev)
   1199 {
   1200 #ifdef DIAGNOSTIC
   1201 	if (dev == NULL) {
   1202 		printf("usbd_get_quirks: dev == NULL\n");
   1203 		return 0;
   1204 	}
   1205 #endif
   1206 	return dev->ud_quirks;
   1207 }
   1208 
   1209 /* XXX do periodic free() of free list */
   1210 
   1211 /*
   1212  * Called from keyboard driver when in polling mode.
   1213  */
   1214 void
   1215 usbd_dopoll(struct usbd_interface *iface)
   1216 {
   1217 	iface->ui_dev->ud_bus->ub_methods->ubm_dopoll(iface->ui_dev->ud_bus);
   1218 }
   1219 
   1220 /*
   1221  * This is for keyboard driver as well, which only operates in polling
   1222  * mode from the ask root, etc., prompt and from DDB.
   1223  */
   1224 void
   1225 usbd_set_polling(struct usbd_device *dev, int on)
   1226 {
   1227 	if (on)
   1228 		dev->ud_bus->ub_usepolling++;
   1229 	else
   1230 		dev->ud_bus->ub_usepolling--;
   1231 
   1232 	/* Kick the host controller when switching modes */
   1233 	mutex_enter(dev->ud_bus->ub_lock);
   1234 	dev->ud_bus->ub_methods->ubm_softint(dev->ud_bus);
   1235 	mutex_exit(dev->ud_bus->ub_lock);
   1236 }
   1237 
   1238 
   1239 usb_endpoint_descriptor_t *
   1240 usbd_get_endpoint_descriptor(struct usbd_interface *iface, uint8_t address)
   1241 {
   1242 	struct usbd_endpoint *ep;
   1243 	int i;
   1244 
   1245 	for (i = 0; i < iface->ui_idesc->bNumEndpoints; i++) {
   1246 		ep = &iface->ui_endpoints[i];
   1247 		if (ep->ue_edesc->bEndpointAddress == address)
   1248 			return iface->ui_endpoints[i].ue_edesc;
   1249 	}
   1250 	return NULL;
   1251 }
   1252 
   1253 /*
   1254  * usbd_ratecheck() can limit the number of error messages that occurs.
   1255  * When a device is unplugged it may take up to 0.25s for the hub driver
   1256  * to notice it.  If the driver continuously tries to do I/O operations
   1257  * this can generate a large number of messages.
   1258  */
   1259 int
   1260 usbd_ratecheck(struct timeval *last)
   1261 {
   1262 	static struct timeval errinterval = { 0, 250000 }; /* 0.25 s*/
   1263 
   1264 	return ratecheck(last, &errinterval);
   1265 }
   1266 
   1267 /*
   1268  * Search for a vendor/product pair in an array.  The item size is
   1269  * given as an argument.
   1270  */
   1271 const struct usb_devno *
   1272 usb_match_device(const struct usb_devno *tbl, u_int nentries, u_int sz,
   1273 		 uint16_t vendor, uint16_t product)
   1274 {
   1275 	while (nentries-- > 0) {
   1276 		uint16_t tproduct = tbl->ud_product;
   1277 		if (tbl->ud_vendor == vendor &&
   1278 		    (tproduct == product || tproduct == USB_PRODUCT_ANY))
   1279 			return tbl;
   1280 		tbl = (const struct usb_devno *)((const char *)tbl + sz);
   1281 	}
   1282 	return NULL;
   1283 }
   1284 
   1285 
   1286 void
   1287 usb_desc_iter_init(struct usbd_device *dev, usbd_desc_iter_t *iter)
   1288 {
   1289 	const usb_config_descriptor_t *cd = usbd_get_config_descriptor(dev);
   1290 
   1291 	iter->cur = (const uByte *)cd;
   1292 	iter->end = (const uByte *)cd + UGETW(cd->wTotalLength);
   1293 }
   1294 
   1295 const usb_descriptor_t *
   1296 usb_desc_iter_next(usbd_desc_iter_t *iter)
   1297 {
   1298 	const usb_descriptor_t *desc;
   1299 
   1300 	if (iter->cur + sizeof(usb_descriptor_t) >= iter->end) {
   1301 		if (iter->cur != iter->end)
   1302 			printf("usb_desc_iter_next: bad descriptor\n");
   1303 		return NULL;
   1304 	}
   1305 	desc = (const usb_descriptor_t *)iter->cur;
   1306 	if (desc->bLength == 0) {
   1307 		printf("usb_desc_iter_next: descriptor length = 0\n");
   1308 		return NULL;
   1309 	}
   1310 	iter->cur += desc->bLength;
   1311 	if (iter->cur > iter->end) {
   1312 		printf("usb_desc_iter_next: descriptor length too large\n");
   1313 		return NULL;
   1314 	}
   1315 	return desc;
   1316 }
   1317 
   1318 usbd_status
   1319 usbd_get_string(struct usbd_device *dev, int si, char *buf)
   1320 {
   1321 	return usbd_get_string0(dev, si, buf, 1);
   1322 }
   1323 
   1324 usbd_status
   1325 usbd_get_string0(struct usbd_device *dev, int si, char *buf, int unicode)
   1326 {
   1327 	int swap = dev->ud_quirks->uq_flags & UQ_SWAP_UNICODE;
   1328 	usb_string_descriptor_t us;
   1329 	char *s;
   1330 	int i, n;
   1331 	uint16_t c;
   1332 	usbd_status err;
   1333 	int size;
   1334 
   1335 	USBHIST_FUNC(); USBHIST_CALLED(usbdebug);
   1336 
   1337 	buf[0] = '\0';
   1338 	if (si == 0)
   1339 		return USBD_INVAL;
   1340 	if (dev->ud_quirks->uq_flags & UQ_NO_STRINGS)
   1341 		return USBD_STALLED;
   1342 	if (dev->ud_langid == USBD_NOLANG) {
   1343 		/* Set up default language */
   1344 		err = usbd_get_string_desc(dev, USB_LANGUAGE_TABLE, 0, &us,
   1345 		    &size);
   1346 		if (err || size < 4) {
   1347 			USBHIST_LOG(usbdebug, "getting lang failed, using 0",
   1348 			    0, 0, 0, 0);
   1349 			dev->ud_langid = 0; /* Well, just pick something then */
   1350 		} else {
   1351 			/* Pick the first language as the default. */
   1352 			dev->ud_langid = UGETW(us.bString[0]);
   1353 		}
   1354 	}
   1355 	err = usbd_get_string_desc(dev, si, dev->ud_langid, &us, &size);
   1356 	if (err)
   1357 		return err;
   1358 	s = buf;
   1359 	n = size / 2 - 1;
   1360 	if (unicode) {
   1361 		for (i = 0; i < n; i++) {
   1362 			c = UGETW(us.bString[i]);
   1363 			if (swap)
   1364 				c = (c >> 8) | (c << 8);
   1365 			s += wput_utf8(s, 3, c);
   1366 		}
   1367 		*s++ = 0;
   1368 	}
   1369 #ifdef COMPAT_30
   1370 	else {
   1371 		for (i = 0; i < n; i++) {
   1372 			c = UGETW(us.bString[i]);
   1373 			if (swap)
   1374 				c = (c >> 8) | (c << 8);
   1375 			*s++ = (c < 0x80) ? c : '?';
   1376 		}
   1377 		*s++ = 0;
   1378 	}
   1379 #endif
   1380 	return USBD_NORMAL_COMPLETION;
   1381 }
   1382 
   1383 /*
   1384  * usbd_xfer_trycomplete(xfer)
   1385  *
   1386  *	Try to claim xfer for completion.  Return true if successful,
   1387  *	false if the xfer has been synchronously aborted or has timed
   1388  *	out.
   1389  *
   1390  *	If this returns true, caller is responsible for setting
   1391  *	xfer->ux_status and calling usb_transfer_complete.  To be used
   1392  *	in a host controller interrupt handler.
   1393  *
   1394  *	Caller must either hold the bus lock or have the bus in polling
   1395  *	mode.
   1396  */
   1397 bool
   1398 usbd_xfer_trycomplete(struct usbd_xfer *xfer)
   1399 {
   1400 	struct usbd_bus *bus __diagused = xfer->ux_bus;
   1401 
   1402 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1403 
   1404 	/*
   1405 	 * If software has completed it, either by synchronous abort or
   1406 	 * by timeout, too late.
   1407 	 */
   1408 	if (xfer->ux_status != USBD_IN_PROGRESS)
   1409 		return false;
   1410 
   1411 	/*
   1412 	 * We are completing the xfer.  Cancel the timeout if we can,
   1413 	 * but only asynchronously.  See usbd_xfer_cancel_timeout_async
   1414 	 * for why we need not wait for the callout or task here.
   1415 	 */
   1416 	usbd_xfer_cancel_timeout_async(xfer);
   1417 
   1418 	/* Success!  Note: Caller must set xfer->ux_status afterwar.  */
   1419 	return true;
   1420 }
   1421 
   1422 /*
   1423  * usbd_xfer_abort(xfer)
   1424  *
   1425  *	Try to claim xfer to abort.  If successful, mark it completed
   1426  *	with USBD_CANCELLED and call the bus-specific method to abort
   1427  *	at the hardware level.
   1428  *
   1429  *	To be called in thread context from struct
   1430  *	usbd_pipe_methods::upm_abort.
   1431  *
   1432  *	Caller must hold the bus lock.
   1433  */
   1434 void
   1435 usbd_xfer_abort(struct usbd_xfer *xfer)
   1436 {
   1437 	struct usbd_bus *bus = xfer->ux_bus;
   1438 
   1439 	KASSERT(mutex_owned(bus->ub_lock));
   1440 
   1441 	/*
   1442 	 * If host controller interrupt or timer interrupt has
   1443 	 * completed it, too late.  But the xfer cannot be
   1444 	 * cancelled already -- only one caller can synchronously
   1445 	 * abort.
   1446 	 */
   1447 	KASSERT(xfer->ux_status != USBD_CANCELLED);
   1448 	if (xfer->ux_status != USBD_IN_PROGRESS)
   1449 		return;
   1450 
   1451 	/*
   1452 	 * Cancel the timeout if we can, but only asynchronously; see
   1453 	 * usbd_xfer_cancel_timeout_async for why we need not wait for
   1454 	 * the callout or task here.
   1455 	 */
   1456 	usbd_xfer_cancel_timeout_async(xfer);
   1457 
   1458 	/*
   1459 	 * We beat everyone else.  Claim the status as cancelled and do
   1460 	 * the bus-specific dance to abort the hardware.
   1461 	 */
   1462 	xfer->ux_status = USBD_CANCELLED;
   1463 	bus->ub_methods->ubm_abortx(xfer);
   1464 }
   1465 
   1466 /*
   1467  * usbd_xfer_timeout(xfer)
   1468  *
   1469  *	Called at IPL_SOFTCLOCK when too much time has elapsed waiting
   1470  *	for xfer to complete.  Since we can't abort the xfer at
   1471  *	IPL_SOFTCLOCK, defer to a usb_task to run it in thread context,
   1472  *	unless the xfer has completed or aborted concurrently -- and if
   1473  *	the xfer has also been resubmitted, take care of rescheduling
   1474  *	the callout.
   1475  */
   1476 static void
   1477 usbd_xfer_timeout(void *cookie)
   1478 {
   1479 	struct usbd_xfer *xfer = cookie;
   1480 	struct usbd_bus *bus = xfer->ux_bus;
   1481 	struct usbd_device *dev = xfer->ux_pipe->up_dev;
   1482 
   1483 	/* Acquire the lock so we can transition the timeout state.  */
   1484 	mutex_enter(bus->ub_lock);
   1485 
   1486 	/*
   1487 	 * Use usbd_xfer_probe_timeout to check whether the timeout is
   1488 	 * still valid, or to reschedule the callout if necessary.  If
   1489 	 * it is still valid, schedule the task.
   1490 	 */
   1491 	if (usbd_xfer_probe_timeout(xfer))
   1492 		usb_add_task(dev, &xfer->ux_aborttask, USB_TASKQ_HC);
   1493 
   1494 	/*
   1495 	 * Notify usbd_xfer_cancel_timeout_async that we may have
   1496 	 * scheduled the task.  This causes callout_invoking to return
   1497 	 * false in usbd_xfer_cancel_timeout_async so that it can tell
   1498 	 * which stage in the callout->task->abort process we're at.
   1499 	 */
   1500 	callout_ack(&xfer->ux_callout);
   1501 
   1502 	/* All done -- release the lock.  */
   1503 	mutex_exit(bus->ub_lock);
   1504 }
   1505 
   1506 /*
   1507  * usbd_xfer_timeout_task(xfer)
   1508  *
   1509  *	Called in thread context when too much time has elapsed waiting
   1510  *	for xfer to complete.  Abort the xfer with USBD_TIMEOUT, unless
   1511  *	it has completed or aborted concurrently -- and if the xfer has
   1512  *	also been resubmitted, take care of rescheduling the callout.
   1513  */
   1514 static void
   1515 usbd_xfer_timeout_task(void *cookie)
   1516 {
   1517 	struct usbd_xfer *xfer = cookie;
   1518 	struct usbd_bus *bus = xfer->ux_bus;
   1519 
   1520 	/* Acquire the lock so we can transition the timeout state.  */
   1521 	mutex_enter(bus->ub_lock);
   1522 
   1523 	/*
   1524 	 * Use usbd_xfer_probe_timeout to check whether the timeout is
   1525 	 * still valid, or to reschedule the callout if necessary.  If
   1526 	 * it is not valid -- the timeout has been asynchronously
   1527 	 * cancelled, or the xfer has already been resubmitted -- then
   1528 	 * we're done here.
   1529 	 */
   1530 	if (!usbd_xfer_probe_timeout(xfer))
   1531 		goto out;
   1532 
   1533 	/*
   1534 	 * May have completed or been aborted, but we're the only one
   1535 	 * who can time it out.  If it has completed or been aborted,
   1536 	 * no need to timeout.
   1537 	 */
   1538 	KASSERT(xfer->ux_status != USBD_TIMEOUT);
   1539 	if (xfer->ux_status != USBD_IN_PROGRESS)
   1540 		goto out;
   1541 
   1542 	/*
   1543 	 * We beat everyone else.  Claim the status as timed out and do
   1544 	 * the bus-specific dance to abort the hardware.
   1545 	 */
   1546 	xfer->ux_status = USBD_TIMEOUT;
   1547 	bus->ub_methods->ubm_abortx(xfer);
   1548 
   1549 out:	/* All done -- release the lock.  */
   1550 	mutex_exit(bus->ub_lock);
   1551 }
   1552 
   1553 /*
   1554  * usbd_xfer_probe_timeout(xfer)
   1555  *
   1556  *	Probe the status of xfer's timeout.  Acknowledge and process a
   1557  *	request to reschedule.  Return true if the timeout is still
   1558  *	valid and the caller should take further action (queueing a
   1559  *	task or aborting the xfer), false if it must stop here.
   1560  */
   1561 static bool
   1562 usbd_xfer_probe_timeout(struct usbd_xfer *xfer)
   1563 {
   1564 	struct usbd_bus *bus = xfer->ux_bus;
   1565 	bool valid;
   1566 
   1567 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1568 
   1569 	/* The timeout must be set.  */
   1570 	KASSERT(xfer->ux_timeout_set);
   1571 
   1572 	/*
   1573 	 * Neither callout nor task may be pending; they execute
   1574 	 * alternately in lock step.
   1575 	 */
   1576 	KASSERT(!callout_pending(&xfer->ux_callout));
   1577 	KASSERT(!usb_task_pending(xfer->ux_pipe->up_dev, &xfer->ux_aborttask));
   1578 
   1579 	/* There are a few cases... */
   1580 	if (bus->ub_methods->ubm_dying(bus)) {
   1581 		/* Host controller dying.  Drop it all on the floor.  */
   1582 		xfer->ux_timeout_set = false;
   1583 		xfer->ux_timeout_reset = false;
   1584 		valid = false;
   1585 	} else if (xfer->ux_timeout_reset) {
   1586 		/*
   1587 		 * The xfer completed _and_ got resubmitted while we
   1588 		 * waited for the lock.  Acknowledge the request to
   1589 		 * reschedule, and reschedule it if there is a timeout
   1590 		 * and the bus is not polling.
   1591 		 */
   1592 		xfer->ux_timeout_reset = false;
   1593 		if (xfer->ux_timeout && !bus->ub_usepolling) {
   1594 			KASSERT(xfer->ux_timeout_set);
   1595 			callout_schedule(&xfer->ux_callout,
   1596 			    mstohz(xfer->ux_timeout));
   1597 		} else {
   1598 			/* No more callout or task scheduled.  */
   1599 			xfer->ux_timeout_set = false;
   1600 		}
   1601 		valid = false;
   1602 	} else if (xfer->ux_status != USBD_IN_PROGRESS) {
   1603 		/*
   1604 		 * The xfer has completed by hardware completion or by
   1605 		 * software abort, and has not been resubmitted, so the
   1606 		 * timeout must be unset, and is no longer valid for
   1607 		 * the caller.
   1608 		 */
   1609 		xfer->ux_timeout_set = false;
   1610 		valid = false;
   1611 	} else {
   1612 		/*
   1613 		 * The xfer has not yet completed, so the timeout is
   1614 		 * valid.
   1615 		 */
   1616 		valid = true;
   1617 	}
   1618 
   1619 	/* Any reset must have been processed.  */
   1620 	KASSERT(!xfer->ux_timeout_reset);
   1621 
   1622 	/*
   1623 	 * Either we claim the timeout is set, or the callout is idle.
   1624 	 * If the timeout is still set, we may be handing off to the
   1625 	 * task instead, so this is an if but not an iff.
   1626 	 */
   1627 	KASSERT(xfer->ux_timeout_set || !callout_pending(&xfer->ux_callout));
   1628 
   1629 	/*
   1630 	 * The task must be idle now.
   1631 	 *
   1632 	 * - If the caller is the callout, _and_ the timeout is still
   1633 	 *   valid, the caller will schedule it, but it hasn't been
   1634 	 *   scheduled yet.  (If the timeout is not valid, the task
   1635 	 *   should not be scheduled.)
   1636 	 *
   1637 	 * - If the caller is the task, it cannot be scheduled again
   1638 	 *   until the callout runs again, which won't happen until we
   1639 	 *   next release the lock.
   1640 	 */
   1641 	KASSERT(!usb_task_pending(xfer->ux_pipe->up_dev, &xfer->ux_aborttask));
   1642 
   1643 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1644 
   1645 	return valid;
   1646 }
   1647 
   1648 /*
   1649  * usbd_xfer_schedule_timeout(xfer)
   1650  *
   1651  *	Ensure that xfer has a timeout.  If the callout is already
   1652  *	queued or the task is already running, request that they
   1653  *	reschedule the callout.  If not, and if we're not polling,
   1654  *	schedule the callout anew.
   1655  *
   1656  *	To be called in thread context from struct
   1657  *	usbd_pipe_methods::upm_start.
   1658  */
   1659 void
   1660 usbd_xfer_schedule_timeout(struct usbd_xfer *xfer)
   1661 {
   1662 	struct usbd_bus *bus = xfer->ux_bus;
   1663 
   1664 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1665 
   1666 	if (xfer->ux_timeout_set) {
   1667 		/*
   1668 		 * Callout or task has fired from a prior completed
   1669 		 * xfer but has not yet noticed that the xfer is done.
   1670 		 * Ask it to reschedule itself to ux_timeout.
   1671 		 */
   1672 		xfer->ux_timeout_reset = true;
   1673 	} else if (xfer->ux_timeout && !bus->ub_usepolling) {
   1674 		/* Callout is not scheduled.  Schedule it.  */
   1675 		KASSERT(!callout_pending(&xfer->ux_callout));
   1676 		callout_schedule(&xfer->ux_callout, mstohz(xfer->ux_timeout));
   1677 		xfer->ux_timeout_set = true;
   1678 	}
   1679 
   1680 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1681 }
   1682 
   1683 /*
   1684  * usbd_xfer_cancel_timeout_async(xfer)
   1685  *
   1686  *	Cancel the callout and the task of xfer, which have not yet run
   1687  *	to completion, but don't wait for the callout or task to finish
   1688  *	running.
   1689  *
   1690  *	If they have already fired, at worst they are waiting for the
   1691  *	bus lock.  They will see that the xfer is no longer in progress
   1692  *	and give up, or they will see that the xfer has been
   1693  *	resubmitted with a new timeout and reschedule the callout.
   1694  *
   1695  *	If a resubmitted request completed so fast that the callout
   1696  *	didn't have time to process a timer reset, just cancel the
   1697  *	timer reset.
   1698  */
   1699 static void
   1700 usbd_xfer_cancel_timeout_async(struct usbd_xfer *xfer)
   1701 {
   1702 	struct usbd_bus *bus __diagused = xfer->ux_bus;
   1703 
   1704 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1705 
   1706 	/*
   1707 	 * If the timer wasn't running anyway, forget about it.  This
   1708 	 * can happen if we are completing an isochronous transfer
   1709 	 * which doesn't use the same timeout logic.
   1710 	 */
   1711 	if (!xfer->ux_timeout_set)
   1712 		return;
   1713 
   1714 	xfer->ux_timeout_reset = false;
   1715 	if (!callout_stop(&xfer->ux_callout)) {
   1716 		/*
   1717 		 * We stopped the callout before it ran.  The timeout
   1718 		 * is no longer set.
   1719 		 */
   1720 		xfer->ux_timeout_set = false;
   1721 	} else if (callout_invoking(&xfer->ux_callout)) {
   1722 		/*
   1723 		 * The callout has begun to run but it has not yet
   1724 		 * acquired the lock and called callout_ack.  The task
   1725 		 * cannot be queued yet, and the callout cannot have
   1726 		 * been rescheduled yet.
   1727 		 *
   1728 		 * By the time the callout acquires the lock, we will
   1729 		 * have transitioned from USBD_IN_PROGRESS to a
   1730 		 * completed status, and possibly also resubmitted the
   1731 		 * xfer and set xfer->ux_timeout_reset = true.  In both
   1732 		 * cases, the callout will DTRT, so no further action
   1733 		 * is needed here.
   1734 		 */
   1735 	} else if (usb_rem_task(xfer->ux_pipe->up_dev, &xfer->ux_aborttask)) {
   1736 		/*
   1737 		 * The callout had fired and scheduled the task, but we
   1738 		 * stopped the task before it could run.  The timeout
   1739 		 * is therefore no longer set -- the next resubmission
   1740 		 * of the xfer must schedule a new timeout.
   1741 		 *
   1742 		 * The callout should not be be pending at this point:
   1743 		 * it is scheduled only under the lock, and only when
   1744 		 * xfer->ux_timeout_set is false, or by the callout or
   1745 		 * task itself when xfer->ux_timeout_reset is true.
   1746 		 */
   1747 		xfer->ux_timeout_set = false;
   1748 	}
   1749 
   1750 	/*
   1751 	 * The callout cannot be scheduled and the task cannot be
   1752 	 * queued at this point.  Either we cancelled them, or they are
   1753 	 * already running and waiting for the bus lock.
   1754 	 */
   1755 	KASSERT(!callout_pending(&xfer->ux_callout));
   1756 	KASSERT(!usb_task_pending(xfer->ux_pipe->up_dev, &xfer->ux_aborttask));
   1757 
   1758 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1759 }
   1760