Home | History | Annotate | Line # | Download | only in usb
usbdi.c revision 1.192
      1 /*	$NetBSD: usbdi.c,v 1.192 2020/02/12 16:01:00 riastradh Exp $	*/
      2 
      3 /*
      4  * Copyright (c) 1998, 2012, 2015 The NetBSD Foundation, Inc.
      5  * All rights reserved.
      6  *
      7  * This code is derived from software contributed to The NetBSD Foundation
      8  * by Lennart Augustsson (lennart (at) augustsson.net) at
      9  * Carlstedt Research & Technology, Matthew R. Green (mrg (at) eterna.com.au),
     10  * and Nick Hudson.
     11  *
     12  * Redistribution and use in source and binary forms, with or without
     13  * modification, are permitted provided that the following conditions
     14  * are met:
     15  * 1. Redistributions of source code must retain the above copyright
     16  *    notice, this list of conditions and the following disclaimer.
     17  * 2. Redistributions in binary form must reproduce the above copyright
     18  *    notice, this list of conditions and the following disclaimer in the
     19  *    documentation and/or other materials provided with the distribution.
     20  *
     21  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     22  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     23  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     24  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     25  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     26  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     27  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     28  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     29  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     30  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     31  * POSSIBILITY OF SUCH DAMAGE.
     32  */
     33 
     34 #include <sys/cdefs.h>
     35 __KERNEL_RCSID(0, "$NetBSD: usbdi.c,v 1.192 2020/02/12 16:01:00 riastradh Exp $");
     36 
     37 #ifdef _KERNEL_OPT
     38 #include "opt_usb.h"
     39 #include "opt_compat_netbsd.h"
     40 #include "usb_dma.h"
     41 #endif
     42 
     43 #include <sys/param.h>
     44 #include <sys/systm.h>
     45 #include <sys/kernel.h>
     46 #include <sys/device.h>
     47 #include <sys/kmem.h>
     48 #include <sys/proc.h>
     49 #include <sys/bus.h>
     50 #include <sys/cpu.h>
     51 
     52 #include <dev/usb/usb.h>
     53 #include <dev/usb/usbdi.h>
     54 #include <dev/usb/usbdi_util.h>
     55 #include <dev/usb/usbdivar.h>
     56 #include <dev/usb/usb_mem.h>
     57 #include <dev/usb/usb_quirks.h>
     58 #include <dev/usb/usbhist.h>
     59 
     60 /* UTF-8 encoding stuff */
     61 #include <fs/unicode.h>
     62 
     63 extern int usbdebug;
     64 
     65 Static usbd_status usbd_ar_pipe(struct usbd_pipe *);
     66 Static void usbd_start_next(struct usbd_pipe *);
     67 Static usbd_status usbd_open_pipe_ival
     68 	(struct usbd_interface *, uint8_t, uint8_t, struct usbd_pipe **, int);
     69 static void *usbd_alloc_buffer(struct usbd_xfer *, uint32_t);
     70 static void usbd_free_buffer(struct usbd_xfer *);
     71 static struct usbd_xfer *usbd_alloc_xfer(struct usbd_device *, unsigned int);
     72 static usbd_status usbd_free_xfer(struct usbd_xfer *);
     73 static void usbd_request_async_cb(struct usbd_xfer *, void *, usbd_status);
     74 static void usbd_xfer_timeout(void *);
     75 static void usbd_xfer_timeout_task(void *);
     76 static bool usbd_xfer_probe_timeout(struct usbd_xfer *);
     77 static void usbd_xfer_cancel_timeout_async(struct usbd_xfer *);
     78 
     79 #if defined(USB_DEBUG)
     80 void
     81 usbd_dump_iface(struct usbd_interface *iface)
     82 {
     83 	USBHIST_FUNC();
     84 	USBHIST_CALLARGS(usbdebug, "iface %#jx", (uintptr_t)iface, 0, 0, 0);
     85 
     86 	if (iface == NULL)
     87 		return;
     88 	USBHIST_LOG(usbdebug, "     device = %#jx idesc = %#jx index = %d",
     89 	    (uintptr_t)iface->ui_dev, (uintptr_t)iface->ui_idesc,
     90 	    iface->ui_index, 0);
     91 	USBHIST_LOG(usbdebug, "     altindex=%d priv=%#jx",
     92 	    iface->ui_altindex, (uintptr_t)iface->ui_priv, 0, 0);
     93 }
     94 
     95 void
     96 usbd_dump_device(struct usbd_device *dev)
     97 {
     98 	USBHIST_FUNC();
     99 	USBHIST_CALLARGS(usbdebug, "dev = %#jx", (uintptr_t)dev, 0, 0, 0);
    100 
    101 	if (dev == NULL)
    102 		return;
    103 	USBHIST_LOG(usbdebug, "     bus = %#jx default_pipe = %#jx",
    104 	    (uintptr_t)dev->ud_bus, (uintptr_t)dev->ud_pipe0, 0, 0);
    105 	USBHIST_LOG(usbdebug, "     address = %jd config = %jd depth = %jd ",
    106 	    dev->ud_addr, dev->ud_config, dev->ud_depth, 0);
    107 	USBHIST_LOG(usbdebug, "     speed = %jd self_powered = %jd "
    108 	    "power = %jd langid = %jd",
    109 	    dev->ud_speed, dev->ud_selfpowered, dev->ud_power, dev->ud_langid);
    110 }
    111 
    112 void
    113 usbd_dump_endpoint(struct usbd_endpoint *endp)
    114 {
    115 	USBHIST_FUNC();
    116 	USBHIST_CALLARGS(usbdebug, "endp = %#jx", (uintptr_t)endp, 0, 0, 0);
    117 
    118 	if (endp == NULL)
    119 		return;
    120 	USBHIST_LOG(usbdebug, "    edesc = %#jx refcnt = %jd",
    121 	    (uintptr_t)endp->ue_edesc, endp->ue_refcnt, 0, 0);
    122 	if (endp->ue_edesc)
    123 		USBHIST_LOG(usbdebug, "     bEndpointAddress=0x%02x",
    124 		    endp->ue_edesc->bEndpointAddress, 0, 0, 0);
    125 }
    126 
    127 void
    128 usbd_dump_queue(struct usbd_pipe *pipe)
    129 {
    130 	struct usbd_xfer *xfer;
    131 
    132 	USBHIST_FUNC();
    133 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx", (uintptr_t)pipe, 0, 0, 0);
    134 
    135 	SIMPLEQ_FOREACH(xfer, &pipe->up_queue, ux_next) {
    136 		USBHIST_LOG(usbdebug, "     xfer = %#jx", (uintptr_t)xfer,
    137 		    0, 0, 0);
    138 	}
    139 }
    140 
    141 void
    142 usbd_dump_pipe(struct usbd_pipe *pipe)
    143 {
    144 	USBHIST_FUNC();
    145 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx", (uintptr_t)pipe, 0, 0, 0);
    146 
    147 	if (pipe == NULL)
    148 		return;
    149 	usbd_dump_iface(pipe->up_iface);
    150 	usbd_dump_device(pipe->up_dev);
    151 	usbd_dump_endpoint(pipe->up_endpoint);
    152 	USBHIST_LOG(usbdebug, "(usbd_dump_pipe)", 0, 0, 0, 0);
    153 	USBHIST_LOG(usbdebug, "     running = %jd aborting = %jd",
    154 	    pipe->up_running, pipe->up_aborting, 0, 0);
    155 	USBHIST_LOG(usbdebug, "     intrxfer = %#jx, repeat = %jd, "
    156 	    "interval = %jd", (uintptr_t)pipe->up_intrxfer, pipe->up_repeat,
    157 	    pipe->up_interval, 0);
    158 }
    159 #endif
    160 
    161 usbd_status
    162 usbd_open_pipe(struct usbd_interface *iface, uint8_t address,
    163 	       uint8_t flags, struct usbd_pipe **pipe)
    164 {
    165 	return (usbd_open_pipe_ival(iface, address, flags, pipe,
    166 				    USBD_DEFAULT_INTERVAL));
    167 }
    168 
    169 usbd_status
    170 usbd_open_pipe_ival(struct usbd_interface *iface, uint8_t address,
    171 		    uint8_t flags, struct usbd_pipe **pipe, int ival)
    172 {
    173 	struct usbd_pipe *p;
    174 	struct usbd_endpoint *ep;
    175 	usbd_status err;
    176 	int i;
    177 
    178 	USBHIST_FUNC();
    179 	USBHIST_CALLARGS(usbdebug, "iface = %#jx address = 0x%jx flags = 0x%jx",
    180 	    (uintptr_t)iface, address, flags, 0);
    181 
    182 	for (i = 0; i < iface->ui_idesc->bNumEndpoints; i++) {
    183 		ep = &iface->ui_endpoints[i];
    184 		if (ep->ue_edesc == NULL)
    185 			return USBD_IOERROR;
    186 		if (ep->ue_edesc->bEndpointAddress == address)
    187 			goto found;
    188 	}
    189 	return USBD_BAD_ADDRESS;
    190  found:
    191 	if ((flags & USBD_EXCLUSIVE_USE) && ep->ue_refcnt != 0)
    192 		return USBD_IN_USE;
    193 	err = usbd_setup_pipe_flags(iface->ui_dev, iface, ep, ival, &p, flags);
    194 	if (err)
    195 		return err;
    196 	LIST_INSERT_HEAD(&iface->ui_pipes, p, up_next);
    197 	*pipe = p;
    198 	return USBD_NORMAL_COMPLETION;
    199 }
    200 
    201 usbd_status
    202 usbd_open_pipe_intr(struct usbd_interface *iface, uint8_t address,
    203 		    uint8_t flags, struct usbd_pipe **pipe,
    204 		    void *priv, void *buffer, uint32_t len,
    205 		    usbd_callback cb, int ival)
    206 {
    207 	usbd_status err;
    208 	struct usbd_xfer *xfer;
    209 	struct usbd_pipe *ipipe;
    210 
    211 	USBHIST_FUNC();
    212 	USBHIST_CALLARGS(usbdebug, "address = 0x%jx flags = 0x%jx len = %jd",
    213 	    address, flags, len, 0);
    214 
    215 	err = usbd_open_pipe_ival(iface, address,
    216 				  USBD_EXCLUSIVE_USE | (flags & USBD_MPSAFE),
    217 				  &ipipe, ival);
    218 	if (err)
    219 		return err;
    220 	err = usbd_create_xfer(ipipe, len, flags, 0, &xfer);
    221 	if (err)
    222 		goto bad1;
    223 
    224 	usbd_setup_xfer(xfer, priv, buffer, len, flags, USBD_NO_TIMEOUT, cb);
    225 	ipipe->up_intrxfer = xfer;
    226 	ipipe->up_repeat = 1;
    227 	err = usbd_transfer(xfer);
    228 	*pipe = ipipe;
    229 	if (err != USBD_IN_PROGRESS)
    230 		goto bad3;
    231 	return USBD_NORMAL_COMPLETION;
    232 
    233  bad3:
    234 	ipipe->up_intrxfer = NULL;
    235 	ipipe->up_repeat = 0;
    236 
    237 	usbd_destroy_xfer(xfer);
    238  bad1:
    239 	usbd_close_pipe(ipipe);
    240 	return err;
    241 }
    242 
    243 usbd_status
    244 usbd_close_pipe(struct usbd_pipe *pipe)
    245 {
    246 	USBHIST_FUNC(); USBHIST_CALLED(usbdebug);
    247 
    248 	KASSERT(pipe != NULL);
    249 
    250 	usbd_lock_pipe(pipe);
    251 
    252 	if (!SIMPLEQ_EMPTY(&pipe->up_queue)) {
    253 		printf("WARNING: pipe closed with active xfers on addr %d\n",
    254 		    pipe->up_dev->ud_addr);
    255 		usbd_ar_pipe(pipe);
    256 	}
    257 
    258 	KASSERT(SIMPLEQ_EMPTY(&pipe->up_queue));
    259 
    260 	LIST_REMOVE(pipe, up_next);
    261 	pipe->up_endpoint->ue_refcnt--;
    262 
    263 	pipe->up_methods->upm_close(pipe);
    264 
    265 	if (pipe->up_intrxfer != NULL) {
    266 	    	usbd_unlock_pipe(pipe);
    267 		usbd_destroy_xfer(pipe->up_intrxfer);
    268 		usbd_lock_pipe(pipe);
    269 	}
    270 
    271 	usbd_unlock_pipe(pipe);
    272 	kmem_free(pipe, pipe->up_dev->ud_bus->ub_pipesize);
    273 
    274 	return USBD_NORMAL_COMPLETION;
    275 }
    276 
    277 usbd_status
    278 usbd_transfer(struct usbd_xfer *xfer)
    279 {
    280 	struct usbd_pipe *pipe = xfer->ux_pipe;
    281 	usbd_status err;
    282 	unsigned int size, flags;
    283 
    284 	USBHIST_FUNC(); USBHIST_CALLARGS(usbdebug,
    285 	    "xfer = %#jx, flags = %#jx, pipe = %#jx, running = %jd",
    286 	    (uintptr_t)xfer, xfer->ux_flags, (uintptr_t)pipe, pipe->up_running);
    287 	KASSERT(xfer->ux_status == USBD_NOT_STARTED);
    288 
    289 #ifdef USB_DEBUG
    290 	if (usbdebug > 5)
    291 		usbd_dump_queue(pipe);
    292 #endif
    293 	xfer->ux_done = 0;
    294 
    295 	if (pipe->up_aborting) {
    296 		USBHIST_LOG(usbdebug, "<- done xfer %#jx, aborting",
    297 		    (uintptr_t)xfer, 0, 0, 0);
    298 		return USBD_CANCELLED;
    299 	}
    300 
    301 	KASSERT(xfer->ux_length == 0 || xfer->ux_buf != NULL);
    302 
    303 	size = xfer->ux_length;
    304 	flags = xfer->ux_flags;
    305 
    306 	if (size != 0) {
    307 		/*
    308 		 * Use the xfer buffer if none specified in transfer setup.
    309 		 * isoc transfers always use the xfer buffer, i.e.
    310 		 * ux_buffer is always NULL for isoc.
    311 		 */
    312 		if (xfer->ux_buffer == NULL) {
    313 			xfer->ux_buffer = xfer->ux_buf;
    314 		}
    315 
    316 		/*
    317 		 * If not using the xfer buffer copy data to the
    318 		 * xfer buffer for OUT transfers of >0 length
    319 		 */
    320 		if (xfer->ux_buffer != xfer->ux_buf) {
    321 			KASSERT(xfer->ux_buf);
    322 			if (!usbd_xfer_isread(xfer)) {
    323 				memcpy(xfer->ux_buf, xfer->ux_buffer, size);
    324 			}
    325 		}
    326 	}
    327 
    328 	/* xfer is not valid after the transfer method unless synchronous */
    329 	err = pipe->up_methods->upm_transfer(xfer);
    330 
    331 	if (err != USBD_IN_PROGRESS && err) {
    332 		/*
    333 		 * The transfer made it onto the pipe queue, but didn't get
    334 		 * accepted by the HCD for some reason.  It needs removing
    335 		 * from the pipe queue.
    336 		 */
    337 		USBHIST_LOG(usbdebug, "xfer failed: %s, reinserting",
    338 		    err, 0, 0, 0);
    339 		usbd_lock_pipe(pipe);
    340 		SIMPLEQ_REMOVE_HEAD(&pipe->up_queue, ux_next);
    341 		if (pipe->up_serialise)
    342 			usbd_start_next(pipe);
    343 		usbd_unlock_pipe(pipe);
    344 	}
    345 
    346 	if (!(flags & USBD_SYNCHRONOUS)) {
    347 		USBHIST_LOG(usbdebug, "<- done xfer %#jx, not sync (err %jd)",
    348 		    (uintptr_t)xfer, err, 0, 0);
    349 		return err;
    350 	}
    351 
    352 	if (err != USBD_IN_PROGRESS) {
    353 		USBHIST_LOG(usbdebug, "<- done xfer %#jx, sync (err %jd)",
    354 		    (uintptr_t)xfer, err, 0, 0);
    355 		return err;
    356 	}
    357 
    358 	/* Sync transfer, wait for completion. */
    359 	usbd_lock_pipe(pipe);
    360 	while (!xfer->ux_done) {
    361 		if (pipe->up_dev->ud_bus->ub_usepolling)
    362 			panic("usbd_transfer: not done");
    363 		USBHIST_LOG(usbdebug, "<- sleeping on xfer %#jx",
    364 		    (uintptr_t)xfer, 0, 0, 0);
    365 
    366 		err = 0;
    367 		if ((flags & USBD_SYNCHRONOUS_SIG) != 0) {
    368 			err = cv_wait_sig(&xfer->ux_cv, pipe->up_dev->ud_bus->ub_lock);
    369 		} else {
    370 			cv_wait(&xfer->ux_cv, pipe->up_dev->ud_bus->ub_lock);
    371 		}
    372 		if (err) {
    373 			if (!xfer->ux_done)
    374 				pipe->up_methods->upm_abort(xfer);
    375 			break;
    376 		}
    377 	}
    378 	usbd_unlock_pipe(pipe);
    379 	return xfer->ux_status;
    380 }
    381 
    382 /* Like usbd_transfer(), but waits for completion. */
    383 usbd_status
    384 usbd_sync_transfer(struct usbd_xfer *xfer)
    385 {
    386 	xfer->ux_flags |= USBD_SYNCHRONOUS;
    387 	return usbd_transfer(xfer);
    388 }
    389 
    390 /* Like usbd_transfer(), but waits for completion and listens for signals. */
    391 usbd_status
    392 usbd_sync_transfer_sig(struct usbd_xfer *xfer)
    393 {
    394 	xfer->ux_flags |= USBD_SYNCHRONOUS | USBD_SYNCHRONOUS_SIG;
    395 	return usbd_transfer(xfer);
    396 }
    397 
    398 static void *
    399 usbd_alloc_buffer(struct usbd_xfer *xfer, uint32_t size)
    400 {
    401 	KASSERT(xfer->ux_buf == NULL);
    402 	KASSERT(size != 0);
    403 
    404 	xfer->ux_bufsize = 0;
    405 #if NUSB_DMA > 0
    406 	struct usbd_bus *bus = xfer->ux_bus;
    407 
    408 	if (bus->ub_usedma) {
    409 		usb_dma_t *dmap = &xfer->ux_dmabuf;
    410 
    411 		int err = usb_allocmem_flags(bus, size, 0, dmap, bus->ub_dmaflags);
    412 		if (err) {
    413 			return NULL;
    414 		}
    415 		xfer->ux_buf = KERNADDR(&xfer->ux_dmabuf, 0);
    416 		xfer->ux_bufsize = size;
    417 
    418 		return xfer->ux_buf;
    419 	}
    420 #endif
    421 	KASSERT(xfer->ux_bus->ub_usedma == false);
    422 	xfer->ux_buf = kmem_alloc(size, KM_SLEEP);
    423 	xfer->ux_bufsize = size;
    424 	return xfer->ux_buf;
    425 }
    426 
    427 static void
    428 usbd_free_buffer(struct usbd_xfer *xfer)
    429 {
    430 	KASSERT(xfer->ux_buf != NULL);
    431 	KASSERT(xfer->ux_bufsize != 0);
    432 
    433 	void *buf = xfer->ux_buf;
    434 	uint32_t size = xfer->ux_bufsize;
    435 
    436 	xfer->ux_buf = NULL;
    437 	xfer->ux_bufsize = 0;
    438 
    439 #if NUSB_DMA > 0
    440 	struct usbd_bus *bus = xfer->ux_bus;
    441 
    442 	if (bus->ub_usedma) {
    443 		usb_dma_t *dmap = &xfer->ux_dmabuf;
    444 
    445 		usb_freemem(bus, dmap);
    446 		return;
    447 	}
    448 #endif
    449 	KASSERT(xfer->ux_bus->ub_usedma == false);
    450 
    451 	kmem_free(buf, size);
    452 }
    453 
    454 void *
    455 usbd_get_buffer(struct usbd_xfer *xfer)
    456 {
    457 	return xfer->ux_buf;
    458 }
    459 
    460 struct usbd_pipe *
    461 usbd_get_pipe0(struct usbd_device *dev)
    462 {
    463 
    464 	return dev->ud_pipe0;
    465 }
    466 
    467 static struct usbd_xfer *
    468 usbd_alloc_xfer(struct usbd_device *dev, unsigned int nframes)
    469 {
    470 	struct usbd_xfer *xfer;
    471 
    472 	USBHIST_FUNC();
    473 
    474 	ASSERT_SLEEPABLE();
    475 
    476 	xfer = dev->ud_bus->ub_methods->ubm_allocx(dev->ud_bus, nframes);
    477 	if (xfer == NULL)
    478 		goto out;
    479 	xfer->ux_bus = dev->ud_bus;
    480 	callout_init(&xfer->ux_callout, CALLOUT_MPSAFE);
    481 	callout_setfunc(&xfer->ux_callout, usbd_xfer_timeout, xfer);
    482 	cv_init(&xfer->ux_cv, "usbxfer");
    483 	usb_init_task(&xfer->ux_aborttask, usbd_xfer_timeout_task, xfer,
    484 	    USB_TASKQ_MPSAFE);
    485 
    486 out:
    487 	USBHIST_CALLARGS(usbdebug, "returns %#jx", (uintptr_t)xfer, 0, 0, 0);
    488 
    489 	return xfer;
    490 }
    491 
    492 static usbd_status
    493 usbd_free_xfer(struct usbd_xfer *xfer)
    494 {
    495 	USBHIST_FUNC();
    496 	USBHIST_CALLARGS(usbdebug, "%#jx", (uintptr_t)xfer, 0, 0, 0);
    497 
    498 	if (xfer->ux_buf) {
    499 		usbd_free_buffer(xfer);
    500 	}
    501 
    502 	/* Wait for any straggling timeout to complete. */
    503 	mutex_enter(xfer->ux_bus->ub_lock);
    504 	xfer->ux_timeout_reset = false; /* do not resuscitate */
    505 	callout_halt(&xfer->ux_callout, xfer->ux_bus->ub_lock);
    506 	usb_rem_task_wait(xfer->ux_pipe->up_dev, &xfer->ux_aborttask,
    507 	    USB_TASKQ_HC, xfer->ux_bus->ub_lock);
    508 	mutex_exit(xfer->ux_bus->ub_lock);
    509 
    510 	cv_destroy(&xfer->ux_cv);
    511 	xfer->ux_bus->ub_methods->ubm_freex(xfer->ux_bus, xfer);
    512 	return USBD_NORMAL_COMPLETION;
    513 }
    514 
    515 int
    516 usbd_create_xfer(struct usbd_pipe *pipe, size_t len, unsigned int flags,
    517     unsigned int nframes, struct usbd_xfer **xp)
    518 {
    519 	KASSERT(xp != NULL);
    520 	void *buf = NULL;
    521 
    522 	struct usbd_xfer *xfer = usbd_alloc_xfer(pipe->up_dev, nframes);
    523 	if (xfer == NULL)
    524 		return ENOMEM;
    525 
    526 	if (len) {
    527 		buf = usbd_alloc_buffer(xfer, len);
    528 		if (!buf) {
    529 			usbd_free_xfer(xfer);
    530 			return ENOMEM;
    531 		}
    532 	}
    533 	xfer->ux_pipe = pipe;
    534 	xfer->ux_flags = flags;
    535 	xfer->ux_nframes = nframes;
    536 	xfer->ux_methods = pipe->up_methods;
    537 
    538 	if (xfer->ux_methods->upm_init) {
    539 		int err = xfer->ux_methods->upm_init(xfer);
    540 		if (err) {
    541 			if (buf)
    542 				usbd_free_buffer(xfer);
    543 			usbd_free_xfer(xfer);
    544 			return err;
    545 		}
    546 	}
    547 
    548 	*xp = xfer;
    549 	return 0;
    550 }
    551 
    552 void
    553 usbd_destroy_xfer(struct usbd_xfer *xfer)
    554 {
    555 
    556 	if (xfer->ux_methods->upm_fini) {
    557 		xfer->ux_methods->upm_fini(xfer);
    558 	}
    559 
    560 	usbd_free_xfer(xfer);
    561 }
    562 
    563 void
    564 usbd_setup_xfer(struct usbd_xfer *xfer, void *priv, void *buffer,
    565     uint32_t length, uint16_t flags, uint32_t timeout, usbd_callback callback)
    566 {
    567 	KASSERT(xfer->ux_pipe);
    568 
    569 	xfer->ux_priv = priv;
    570 	xfer->ux_buffer = buffer;
    571 	xfer->ux_length = length;
    572 	xfer->ux_actlen = 0;
    573 	xfer->ux_flags = flags;
    574 	xfer->ux_timeout = timeout;
    575 	xfer->ux_status = USBD_NOT_STARTED;
    576 	xfer->ux_callback = callback;
    577 	xfer->ux_rqflags &= ~URQ_REQUEST;
    578 	xfer->ux_nframes = 0;
    579 }
    580 
    581 void
    582 usbd_setup_default_xfer(struct usbd_xfer *xfer, struct usbd_device *dev,
    583     void *priv, uint32_t timeout, usb_device_request_t *req, void *buffer,
    584     uint32_t length, uint16_t flags, usbd_callback callback)
    585 {
    586 	KASSERT(xfer->ux_pipe == dev->ud_pipe0);
    587 
    588 	xfer->ux_priv = priv;
    589 	xfer->ux_buffer = buffer;
    590 	xfer->ux_length = length;
    591 	xfer->ux_actlen = 0;
    592 	xfer->ux_flags = flags;
    593 	xfer->ux_timeout = timeout;
    594 	xfer->ux_status = USBD_NOT_STARTED;
    595 	xfer->ux_callback = callback;
    596 	xfer->ux_request = *req;
    597 	xfer->ux_rqflags |= URQ_REQUEST;
    598 	xfer->ux_nframes = 0;
    599 }
    600 
    601 void
    602 usbd_setup_isoc_xfer(struct usbd_xfer *xfer, void *priv, uint16_t *frlengths,
    603     uint32_t nframes, uint16_t flags, usbd_callback callback)
    604 {
    605 	xfer->ux_priv = priv;
    606 	xfer->ux_buffer = NULL;
    607 	xfer->ux_length = 0;
    608 	xfer->ux_actlen = 0;
    609 	xfer->ux_flags = flags;
    610 	xfer->ux_timeout = USBD_NO_TIMEOUT;
    611 	xfer->ux_status = USBD_NOT_STARTED;
    612 	xfer->ux_callback = callback;
    613 	xfer->ux_rqflags &= ~URQ_REQUEST;
    614 	xfer->ux_frlengths = frlengths;
    615 	xfer->ux_nframes = nframes;
    616 }
    617 
    618 void
    619 usbd_get_xfer_status(struct usbd_xfer *xfer, void **priv,
    620 		     void **buffer, uint32_t *count, usbd_status *status)
    621 {
    622 	if (priv != NULL)
    623 		*priv = xfer->ux_priv;
    624 	if (buffer != NULL)
    625 		*buffer = xfer->ux_buffer;
    626 	if (count != NULL)
    627 		*count = xfer->ux_actlen;
    628 	if (status != NULL)
    629 		*status = xfer->ux_status;
    630 }
    631 
    632 usb_config_descriptor_t *
    633 usbd_get_config_descriptor(struct usbd_device *dev)
    634 {
    635 	KASSERT(dev != NULL);
    636 
    637 	return dev->ud_cdesc;
    638 }
    639 
    640 usb_interface_descriptor_t *
    641 usbd_get_interface_descriptor(struct usbd_interface *iface)
    642 {
    643 	KASSERT(iface != NULL);
    644 
    645 	return iface->ui_idesc;
    646 }
    647 
    648 usb_device_descriptor_t *
    649 usbd_get_device_descriptor(struct usbd_device *dev)
    650 {
    651 	KASSERT(dev != NULL);
    652 
    653 	return &dev->ud_ddesc;
    654 }
    655 
    656 usb_endpoint_descriptor_t *
    657 usbd_interface2endpoint_descriptor(struct usbd_interface *iface, uint8_t index)
    658 {
    659 
    660 	if (index >= iface->ui_idesc->bNumEndpoints)
    661 		return NULL;
    662 	return iface->ui_endpoints[index].ue_edesc;
    663 }
    664 
    665 /* Some drivers may wish to abort requests on the default pipe, *
    666  * but there is no mechanism for getting a handle on it.        */
    667 usbd_status
    668 usbd_abort_default_pipe(struct usbd_device *device)
    669 {
    670 	return usbd_abort_pipe(device->ud_pipe0);
    671 }
    672 
    673 usbd_status
    674 usbd_abort_pipe(struct usbd_pipe *pipe)
    675 {
    676 	usbd_status err;
    677 
    678 	KASSERT(pipe != NULL);
    679 
    680 	usbd_lock_pipe(pipe);
    681 	err = usbd_ar_pipe(pipe);
    682 	usbd_unlock_pipe(pipe);
    683 	return err;
    684 }
    685 
    686 usbd_status
    687 usbd_clear_endpoint_stall(struct usbd_pipe *pipe)
    688 {
    689 	struct usbd_device *dev = pipe->up_dev;
    690 	usbd_status err;
    691 
    692 	USBHIST_FUNC(); USBHIST_CALLED(usbdebug);
    693 
    694 	/*
    695 	 * Clearing en endpoint stall resets the endpoint toggle, so
    696 	 * do the same to the HC toggle.
    697 	 */
    698 	pipe->up_methods->upm_cleartoggle(pipe);
    699 
    700 	err = usbd_clear_endpoint_feature(dev,
    701 	    pipe->up_endpoint->ue_edesc->bEndpointAddress, UF_ENDPOINT_HALT);
    702 #if 0
    703 XXX should we do this?
    704 	if (!err) {
    705 		pipe->state = USBD_PIPE_ACTIVE;
    706 		/* XXX activate pipe */
    707 	}
    708 #endif
    709 	return err;
    710 }
    711 
    712 void
    713 usbd_clear_endpoint_stall_task(void *arg)
    714 {
    715 	struct usbd_pipe *pipe = arg;
    716 	struct usbd_device *dev = pipe->up_dev;
    717 
    718 	pipe->up_methods->upm_cleartoggle(pipe);
    719 
    720 	(void)usbd_clear_endpoint_feature(dev,
    721 	    pipe->up_endpoint->ue_edesc->bEndpointAddress, UF_ENDPOINT_HALT);
    722 }
    723 
    724 void
    725 usbd_clear_endpoint_stall_async(struct usbd_pipe *pipe)
    726 {
    727 	usb_add_task(pipe->up_dev, &pipe->up_async_task, USB_TASKQ_DRIVER);
    728 }
    729 
    730 void
    731 usbd_clear_endpoint_toggle(struct usbd_pipe *pipe)
    732 {
    733 
    734 	pipe->up_methods->upm_cleartoggle(pipe);
    735 }
    736 
    737 usbd_status
    738 usbd_endpoint_count(struct usbd_interface *iface, uint8_t *count)
    739 {
    740 	KASSERT(iface != NULL);
    741 	KASSERT(iface->ui_idesc != NULL);
    742 
    743 	*count = iface->ui_idesc->bNumEndpoints;
    744 	return USBD_NORMAL_COMPLETION;
    745 }
    746 
    747 usbd_status
    748 usbd_interface_count(struct usbd_device *dev, uint8_t *count)
    749 {
    750 
    751 	if (dev->ud_cdesc == NULL)
    752 		return USBD_NOT_CONFIGURED;
    753 	*count = dev->ud_cdesc->bNumInterface;
    754 	return USBD_NORMAL_COMPLETION;
    755 }
    756 
    757 void
    758 usbd_interface2device_handle(struct usbd_interface *iface,
    759 			     struct usbd_device **dev)
    760 {
    761 
    762 	*dev = iface->ui_dev;
    763 }
    764 
    765 usbd_status
    766 usbd_device2interface_handle(struct usbd_device *dev,
    767 			     uint8_t ifaceno, struct usbd_interface **iface)
    768 {
    769 
    770 	if (dev->ud_cdesc == NULL)
    771 		return USBD_NOT_CONFIGURED;
    772 	if (ifaceno >= dev->ud_cdesc->bNumInterface)
    773 		return USBD_INVAL;
    774 	*iface = &dev->ud_ifaces[ifaceno];
    775 	return USBD_NORMAL_COMPLETION;
    776 }
    777 
    778 struct usbd_device *
    779 usbd_pipe2device_handle(struct usbd_pipe *pipe)
    780 {
    781 	KASSERT(pipe != NULL);
    782 
    783 	return pipe->up_dev;
    784 }
    785 
    786 /* XXXX use altno */
    787 usbd_status
    788 usbd_set_interface(struct usbd_interface *iface, int altidx)
    789 {
    790 	usb_device_request_t req;
    791 	usbd_status err;
    792 	void *endpoints;
    793 
    794 	USBHIST_FUNC();
    795 
    796 	if (LIST_FIRST(&iface->ui_pipes) != NULL)
    797 		return USBD_IN_USE;
    798 
    799 	endpoints = iface->ui_endpoints;
    800 	int nendpt = iface->ui_idesc->bNumEndpoints;
    801 	USBHIST_CALLARGS(usbdebug, "iface %#jx endpoints = %#jx nendpt %jd",
    802 	    (uintptr_t)iface, (uintptr_t)endpoints,
    803 	    iface->ui_idesc->bNumEndpoints, 0);
    804 	err = usbd_fill_iface_data(iface->ui_dev, iface->ui_index, altidx);
    805 	if (err)
    806 		return err;
    807 
    808 	/* new setting works, we can free old endpoints */
    809 	if (endpoints != NULL) {
    810 		USBHIST_LOG(usbdebug, "iface %#jx endpoints = %#jx nendpt %jd",
    811 		    (uintptr_t)iface, (uintptr_t)endpoints, nendpt, 0);
    812 		kmem_free(endpoints, nendpt * sizeof(struct usbd_endpoint));
    813 	}
    814 	KASSERT(iface->ui_idesc != NULL);
    815 
    816 	req.bmRequestType = UT_WRITE_INTERFACE;
    817 	req.bRequest = UR_SET_INTERFACE;
    818 	USETW(req.wValue, iface->ui_idesc->bAlternateSetting);
    819 	USETW(req.wIndex, iface->ui_idesc->bInterfaceNumber);
    820 	USETW(req.wLength, 0);
    821 	return usbd_do_request(iface->ui_dev, &req, 0);
    822 }
    823 
    824 int
    825 usbd_get_no_alts(usb_config_descriptor_t *cdesc, int ifaceno)
    826 {
    827 	char *p = (char *)cdesc;
    828 	char *end = p + UGETW(cdesc->wTotalLength);
    829 	usb_interface_descriptor_t *d;
    830 	int n;
    831 
    832 	for (n = 0; p < end; p += d->bLength) {
    833 		d = (usb_interface_descriptor_t *)p;
    834 		if (p + d->bLength <= end &&
    835 		    d->bDescriptorType == UDESC_INTERFACE &&
    836 		    d->bInterfaceNumber == ifaceno)
    837 			n++;
    838 	}
    839 	return n;
    840 }
    841 
    842 int
    843 usbd_get_interface_altindex(struct usbd_interface *iface)
    844 {
    845 	return iface->ui_altindex;
    846 }
    847 
    848 usbd_status
    849 usbd_get_interface(struct usbd_interface *iface, uint8_t *aiface)
    850 {
    851 	usb_device_request_t req;
    852 
    853 	req.bmRequestType = UT_READ_INTERFACE;
    854 	req.bRequest = UR_GET_INTERFACE;
    855 	USETW(req.wValue, 0);
    856 	USETW(req.wIndex, iface->ui_idesc->bInterfaceNumber);
    857 	USETW(req.wLength, 1);
    858 	return usbd_do_request(iface->ui_dev, &req, aiface);
    859 }
    860 
    861 /*** Internal routines ***/
    862 
    863 /* Dequeue all pipe operations, called with bus lock held. */
    864 Static usbd_status
    865 usbd_ar_pipe(struct usbd_pipe *pipe)
    866 {
    867 	struct usbd_xfer *xfer;
    868 
    869 	USBHIST_FUNC();
    870 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx", (uintptr_t)pipe, 0, 0, 0);
    871 
    872 	KASSERT(mutex_owned(pipe->up_dev->ud_bus->ub_lock));
    873 
    874 #ifdef USB_DEBUG
    875 	if (usbdebug > 5)
    876 		usbd_dump_queue(pipe);
    877 #endif
    878 	pipe->up_repeat = 0;
    879 	pipe->up_aborting = 1;
    880 	while ((xfer = SIMPLEQ_FIRST(&pipe->up_queue)) != NULL) {
    881 		USBHIST_LOG(usbdebug, "pipe = %#jx xfer = %#jx "
    882 		    "(methods = %#jx)", (uintptr_t)pipe, (uintptr_t)xfer,
    883 		    (uintptr_t)pipe->up_methods, 0);
    884 		if (xfer->ux_status == USBD_NOT_STARTED) {
    885 			SIMPLEQ_REMOVE_HEAD(&pipe->up_queue, ux_next);
    886 		} else {
    887 			/* Make the HC abort it (and invoke the callback). */
    888 			pipe->up_methods->upm_abort(xfer);
    889 			/* XXX only for non-0 usbd_clear_endpoint_stall(pipe); */
    890 		}
    891 	}
    892 	pipe->up_aborting = 0;
    893 	return USBD_NORMAL_COMPLETION;
    894 }
    895 
    896 /* Called with USB lock held. */
    897 void
    898 usb_transfer_complete(struct usbd_xfer *xfer)
    899 {
    900 	struct usbd_pipe *pipe = xfer->ux_pipe;
    901 	struct usbd_bus *bus = pipe->up_dev->ud_bus;
    902 	int sync = xfer->ux_flags & USBD_SYNCHRONOUS;
    903 	int erred;
    904 	int polling = bus->ub_usepolling;
    905 	int repeat = pipe->up_repeat;
    906 
    907 	USBHIST_FUNC();
    908 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx xfer = %#jx status = %jd "
    909 	    "actlen = %jd", (uintptr_t)pipe, (uintptr_t)xfer, xfer->ux_status,
    910 	    xfer->ux_actlen);
    911 
    912 	KASSERT(polling || mutex_owned(pipe->up_dev->ud_bus->ub_lock));
    913 	KASSERTMSG(xfer->ux_state == XFER_ONQU, "xfer %p state is %x", xfer,
    914 	    xfer->ux_state);
    915 	KASSERT(pipe != NULL);
    916 
    917 	/*
    918 	 * If device is known to miss out ack, then pretend that
    919 	 * output timeout is a success. Userland should handle
    920 	 * the logic to verify that the operation succeeded.
    921 	 */
    922 	if (pipe->up_dev->ud_quirks &&
    923 	    pipe->up_dev->ud_quirks->uq_flags & UQ_MISS_OUT_ACK &&
    924 	    xfer->ux_status == USBD_TIMEOUT &&
    925 	    !usbd_xfer_isread(xfer)) {
    926 		USBHIST_LOG(usbdebug, "Possible output ack miss for xfer %#jx: "
    927 		    "hiding write timeout to %d.%s for %d bytes written",
    928 		    (uintptr_t)xfer, curlwp->l_proc->p_pid, curlwp->l_lid,
    929 		    xfer->ux_length);
    930 
    931 		xfer->ux_status = USBD_NORMAL_COMPLETION;
    932 		xfer->ux_actlen = xfer->ux_length;
    933 	}
    934 
    935 	erred = xfer->ux_status == USBD_CANCELLED ||
    936 	        xfer->ux_status == USBD_TIMEOUT;
    937 
    938 	if (!repeat) {
    939 		/* Remove request from queue. */
    940 
    941 		KASSERTMSG(!SIMPLEQ_EMPTY(&pipe->up_queue),
    942 		    "pipe %p is empty, but xfer %p wants to complete", pipe,
    943 		     xfer);
    944 		KASSERTMSG(xfer == SIMPLEQ_FIRST(&pipe->up_queue),
    945 		    "xfer %p is not start of queue (%p is at start)", xfer,
    946 		   SIMPLEQ_FIRST(&pipe->up_queue));
    947 
    948 #ifdef DIAGNOSTIC
    949 		xfer->ux_state = XFER_BUSY;
    950 #endif
    951 		SIMPLEQ_REMOVE_HEAD(&pipe->up_queue, ux_next);
    952 	}
    953 	USBHIST_LOG(usbdebug, "xfer %#jx: repeat %jd new head = %#jx",
    954 	    (uintptr_t)xfer, repeat, (uintptr_t)SIMPLEQ_FIRST(&pipe->up_queue),
    955 	    0);
    956 
    957 	/* Count completed transfers. */
    958 	++pipe->up_dev->ud_bus->ub_stats.uds_requests
    959 		[pipe->up_endpoint->ue_edesc->bmAttributes & UE_XFERTYPE];
    960 
    961 	xfer->ux_done = 1;
    962 	if (!xfer->ux_status && xfer->ux_actlen < xfer->ux_length &&
    963 	    !(xfer->ux_flags & USBD_SHORT_XFER_OK)) {
    964 		USBHIST_LOG(usbdebug, "short transfer %jd < %jd",
    965 		    xfer->ux_actlen, xfer->ux_length, 0, 0);
    966 		xfer->ux_status = USBD_SHORT_XFER;
    967 	}
    968 
    969 	USBHIST_LOG(usbdebug, "xfer %#jx doing done %#jx", (uintptr_t)xfer,
    970 	    (uintptr_t)pipe->up_methods->upm_done, 0, 0);
    971 	pipe->up_methods->upm_done(xfer);
    972 
    973 	if (xfer->ux_length != 0 && xfer->ux_buffer != xfer->ux_buf) {
    974 		KDASSERTMSG(xfer->ux_actlen <= xfer->ux_length,
    975 		    "actlen %d length %d",xfer->ux_actlen, xfer->ux_length);
    976 
    977 		/* Only if IN transfer */
    978 		if (usbd_xfer_isread(xfer)) {
    979 			memcpy(xfer->ux_buffer, xfer->ux_buf, xfer->ux_actlen);
    980 		}
    981 	}
    982 
    983 	USBHIST_LOG(usbdebug, "xfer %#jx doing callback %#jx status %jd",
    984 	    (uintptr_t)xfer, (uintptr_t)xfer->ux_callback, xfer->ux_status, 0);
    985 
    986 	if (xfer->ux_callback) {
    987 		if (!polling) {
    988 			mutex_exit(pipe->up_dev->ud_bus->ub_lock);
    989 			if (!(pipe->up_flags & USBD_MPSAFE))
    990 				KERNEL_LOCK(1, curlwp);
    991 		}
    992 
    993 		xfer->ux_callback(xfer, xfer->ux_priv, xfer->ux_status);
    994 
    995 		if (!polling) {
    996 			if (!(pipe->up_flags & USBD_MPSAFE))
    997 				KERNEL_UNLOCK_ONE(curlwp);
    998 			mutex_enter(pipe->up_dev->ud_bus->ub_lock);
    999 		}
   1000 	}
   1001 
   1002 	if (sync && !polling) {
   1003 		USBHIST_LOG(usbdebug, "<- done xfer %#jx, wakeup",
   1004 		    (uintptr_t)xfer, 0, 0, 0);
   1005 		cv_broadcast(&xfer->ux_cv);
   1006 	}
   1007 
   1008 	if (repeat) {
   1009 		xfer->ux_actlen = 0;
   1010 		xfer->ux_status = USBD_NOT_STARTED;
   1011 	} else {
   1012 		/* XXX should we stop the queue on all errors? */
   1013 		if (erred && pipe->up_iface != NULL)	/* not control pipe */
   1014 			pipe->up_running = 0;
   1015 	}
   1016 	if (pipe->up_running && pipe->up_serialise)
   1017 		usbd_start_next(pipe);
   1018 }
   1019 
   1020 /* Called with USB lock held. */
   1021 usbd_status
   1022 usb_insert_transfer(struct usbd_xfer *xfer)
   1023 {
   1024 	struct usbd_pipe *pipe = xfer->ux_pipe;
   1025 	usbd_status err;
   1026 
   1027 	USBHIST_FUNC(); USBHIST_CALLARGS(usbdebug,
   1028 	    "xfer = %#jx pipe = %#jx running = %jd timeout = %jd",
   1029 	    (uintptr_t)xfer, (uintptr_t)pipe,
   1030 	    pipe->up_running, xfer->ux_timeout);
   1031 
   1032 	KASSERT(mutex_owned(pipe->up_dev->ud_bus->ub_lock));
   1033 	KASSERTMSG(xfer->ux_state == XFER_BUSY, "xfer %p state is %x", xfer,
   1034 	    xfer->ux_state);
   1035 
   1036 #ifdef DIAGNOSTIC
   1037 	xfer->ux_state = XFER_ONQU;
   1038 #endif
   1039 	SIMPLEQ_INSERT_TAIL(&pipe->up_queue, xfer, ux_next);
   1040 	if (pipe->up_running && pipe->up_serialise)
   1041 		err = USBD_IN_PROGRESS;
   1042 	else {
   1043 		pipe->up_running = 1;
   1044 		err = USBD_NORMAL_COMPLETION;
   1045 	}
   1046 	USBHIST_LOG(usbdebug, "<- done xfer %#jx, err %jd", (uintptr_t)xfer,
   1047 	    err, 0, 0);
   1048 	return err;
   1049 }
   1050 
   1051 /* Called with USB lock held. */
   1052 void
   1053 usbd_start_next(struct usbd_pipe *pipe)
   1054 {
   1055 	struct usbd_xfer *xfer;
   1056 	usbd_status err;
   1057 
   1058 	USBHIST_FUNC();
   1059 
   1060 	KASSERT(pipe != NULL);
   1061 	KASSERT(pipe->up_methods != NULL);
   1062 	KASSERT(pipe->up_methods->upm_start != NULL);
   1063 	KASSERT(pipe->up_serialise == true);
   1064 
   1065 	int polling = pipe->up_dev->ud_bus->ub_usepolling;
   1066 	KASSERT(polling || mutex_owned(pipe->up_dev->ud_bus->ub_lock));
   1067 
   1068 	/* Get next request in queue. */
   1069 	xfer = SIMPLEQ_FIRST(&pipe->up_queue);
   1070 	USBHIST_CALLARGS(usbdebug, "pipe = %#jx, xfer = %#jx", (uintptr_t)pipe,
   1071 	    (uintptr_t)xfer, 0, 0);
   1072 	if (xfer == NULL) {
   1073 		pipe->up_running = 0;
   1074 	} else {
   1075 		if (!polling)
   1076 			mutex_exit(pipe->up_dev->ud_bus->ub_lock);
   1077 		err = pipe->up_methods->upm_start(xfer);
   1078 		if (!polling)
   1079 			mutex_enter(pipe->up_dev->ud_bus->ub_lock);
   1080 
   1081 		if (err != USBD_IN_PROGRESS) {
   1082 			USBHIST_LOG(usbdebug, "error = %jd", err, 0, 0, 0);
   1083 			pipe->up_running = 0;
   1084 			/* XXX do what? */
   1085 		}
   1086 	}
   1087 
   1088 	KASSERT(polling || mutex_owned(pipe->up_dev->ud_bus->ub_lock));
   1089 }
   1090 
   1091 usbd_status
   1092 usbd_do_request(struct usbd_device *dev, usb_device_request_t *req, void *data)
   1093 {
   1094 
   1095 	return usbd_do_request_flags(dev, req, data, 0, 0,
   1096 	    USBD_DEFAULT_TIMEOUT);
   1097 }
   1098 
   1099 usbd_status
   1100 usbd_do_request_flags(struct usbd_device *dev, usb_device_request_t *req,
   1101     void *data, uint16_t flags, int *actlen, uint32_t timeout)
   1102 {
   1103 	size_t len = UGETW(req->wLength);
   1104 
   1105 	return usbd_do_request_len(dev, req, len, data, flags, actlen, timeout);
   1106 }
   1107 
   1108 usbd_status
   1109 usbd_do_request_len(struct usbd_device *dev, usb_device_request_t *req,
   1110     size_t len, void *data, uint16_t flags, int *actlen, uint32_t timeout)
   1111 {
   1112 	struct usbd_xfer *xfer;
   1113 	usbd_status err;
   1114 
   1115 	KASSERT(len >= UGETW(req->wLength));
   1116 
   1117 	USBHIST_FUNC();
   1118 	USBHIST_CALLARGS(usbdebug, "dev=%#jx req=%jx flags=%jx len=%jx",
   1119 	    (uintptr_t)dev, (uintptr_t)req, flags, len);
   1120 
   1121 	ASSERT_SLEEPABLE();
   1122 
   1123 	int error = usbd_create_xfer(dev->ud_pipe0, len, 0, 0, &xfer);
   1124 	if (error)
   1125 		return error;
   1126 
   1127 	usbd_setup_default_xfer(xfer, dev, 0, timeout, req, data,
   1128 	    UGETW(req->wLength), flags, NULL);
   1129 	KASSERT(xfer->ux_pipe == dev->ud_pipe0);
   1130 	err = usbd_sync_transfer(xfer);
   1131 #if defined(USB_DEBUG) || defined(DIAGNOSTIC)
   1132 	if (xfer->ux_actlen > xfer->ux_length) {
   1133 		USBHIST_LOG(usbdebug, "overrun addr = %jd type = 0x%02jx",
   1134 		    dev->ud_addr, xfer->ux_request.bmRequestType, 0, 0);
   1135 		USBHIST_LOG(usbdebug, "     req = 0x%02jx val = %jd "
   1136 		    "index = %jd",
   1137 		    xfer->ux_request.bRequest, UGETW(xfer->ux_request.wValue),
   1138 		    UGETW(xfer->ux_request.wIndex), 0);
   1139 		USBHIST_LOG(usbdebug, "     rlen = %jd length = %jd "
   1140 		    "actlen = %jd",
   1141 		    UGETW(xfer->ux_request.wLength),
   1142 		    xfer->ux_length, xfer->ux_actlen, 0);
   1143 	}
   1144 #endif
   1145 	if (actlen != NULL)
   1146 		*actlen = xfer->ux_actlen;
   1147 
   1148 	usbd_destroy_xfer(xfer);
   1149 
   1150 	if (err) {
   1151 		USBHIST_LOG(usbdebug, "returning err = %jd", err, 0, 0, 0);
   1152 	}
   1153 	return err;
   1154 }
   1155 
   1156 static void
   1157 usbd_request_async_cb(struct usbd_xfer *xfer, void *priv, usbd_status status)
   1158 {
   1159 	usbd_free_xfer(xfer);
   1160 }
   1161 
   1162 /*
   1163  * Execute a request without waiting for completion.
   1164  * Can be used from interrupt context.
   1165  */
   1166 usbd_status
   1167 usbd_request_async(struct usbd_device *dev, struct usbd_xfer *xfer,
   1168     usb_device_request_t *req, void *priv, usbd_callback callback)
   1169 {
   1170 	usbd_status err;
   1171 
   1172 	if (callback == NULL)
   1173 		callback = usbd_request_async_cb;
   1174 
   1175 	usbd_setup_default_xfer(xfer, dev, priv,
   1176 	    USBD_DEFAULT_TIMEOUT, req, NULL, UGETW(req->wLength), 0,
   1177 	    callback);
   1178 	err = usbd_transfer(xfer);
   1179 	if (err != USBD_IN_PROGRESS) {
   1180 		usbd_free_xfer(xfer);
   1181 		return (err);
   1182 	}
   1183 	return (USBD_NORMAL_COMPLETION);
   1184 }
   1185 
   1186 const struct usbd_quirks *
   1187 usbd_get_quirks(struct usbd_device *dev)
   1188 {
   1189 #ifdef DIAGNOSTIC
   1190 	if (dev == NULL) {
   1191 		printf("usbd_get_quirks: dev == NULL\n");
   1192 		return 0;
   1193 	}
   1194 #endif
   1195 	return dev->ud_quirks;
   1196 }
   1197 
   1198 /* XXX do periodic free() of free list */
   1199 
   1200 /*
   1201  * Called from keyboard driver when in polling mode.
   1202  */
   1203 void
   1204 usbd_dopoll(struct usbd_interface *iface)
   1205 {
   1206 	iface->ui_dev->ud_bus->ub_methods->ubm_dopoll(iface->ui_dev->ud_bus);
   1207 }
   1208 
   1209 /*
   1210  * This is for keyboard driver as well, which only operates in polling
   1211  * mode from the ask root, etc., prompt and from DDB.
   1212  */
   1213 void
   1214 usbd_set_polling(struct usbd_device *dev, int on)
   1215 {
   1216 	if (on)
   1217 		dev->ud_bus->ub_usepolling++;
   1218 	else
   1219 		dev->ud_bus->ub_usepolling--;
   1220 
   1221 	/* Kick the host controller when switching modes */
   1222 	mutex_enter(dev->ud_bus->ub_lock);
   1223 	dev->ud_bus->ub_methods->ubm_softint(dev->ud_bus);
   1224 	mutex_exit(dev->ud_bus->ub_lock);
   1225 }
   1226 
   1227 
   1228 usb_endpoint_descriptor_t *
   1229 usbd_get_endpoint_descriptor(struct usbd_interface *iface, uint8_t address)
   1230 {
   1231 	struct usbd_endpoint *ep;
   1232 	int i;
   1233 
   1234 	for (i = 0; i < iface->ui_idesc->bNumEndpoints; i++) {
   1235 		ep = &iface->ui_endpoints[i];
   1236 		if (ep->ue_edesc->bEndpointAddress == address)
   1237 			return iface->ui_endpoints[i].ue_edesc;
   1238 	}
   1239 	return NULL;
   1240 }
   1241 
   1242 /*
   1243  * usbd_ratecheck() can limit the number of error messages that occurs.
   1244  * When a device is unplugged it may take up to 0.25s for the hub driver
   1245  * to notice it.  If the driver continuously tries to do I/O operations
   1246  * this can generate a large number of messages.
   1247  */
   1248 int
   1249 usbd_ratecheck(struct timeval *last)
   1250 {
   1251 	static struct timeval errinterval = { 0, 250000 }; /* 0.25 s*/
   1252 
   1253 	return ratecheck(last, &errinterval);
   1254 }
   1255 
   1256 /*
   1257  * Search for a vendor/product pair in an array.  The item size is
   1258  * given as an argument.
   1259  */
   1260 const struct usb_devno *
   1261 usb_match_device(const struct usb_devno *tbl, u_int nentries, u_int sz,
   1262 		 uint16_t vendor, uint16_t product)
   1263 {
   1264 	while (nentries-- > 0) {
   1265 		uint16_t tproduct = tbl->ud_product;
   1266 		if (tbl->ud_vendor == vendor &&
   1267 		    (tproduct == product || tproduct == USB_PRODUCT_ANY))
   1268 			return tbl;
   1269 		tbl = (const struct usb_devno *)((const char *)tbl + sz);
   1270 	}
   1271 	return NULL;
   1272 }
   1273 
   1274 
   1275 void
   1276 usb_desc_iter_init(struct usbd_device *dev, usbd_desc_iter_t *iter)
   1277 {
   1278 	const usb_config_descriptor_t *cd = usbd_get_config_descriptor(dev);
   1279 
   1280 	iter->cur = (const uByte *)cd;
   1281 	iter->end = (const uByte *)cd + UGETW(cd->wTotalLength);
   1282 }
   1283 
   1284 const usb_descriptor_t *
   1285 usb_desc_iter_peek(usbd_desc_iter_t *iter)
   1286 {
   1287 	const usb_descriptor_t *desc;
   1288 
   1289 	if (iter->cur + sizeof(usb_descriptor_t) >= iter->end) {
   1290 		if (iter->cur != iter->end)
   1291 			printf("%s: bad descriptor\n", __func__);
   1292 		return NULL;
   1293 	}
   1294 	desc = (const usb_descriptor_t *)iter->cur;
   1295 	if (desc->bLength == 0) {
   1296 		printf("%s: descriptor length = 0\n", __func__);
   1297 		return NULL;
   1298 	}
   1299 	if (iter->cur + desc->bLength > iter->end) {
   1300 		printf("%s: descriptor length too large\n", __func__);
   1301 		return NULL;
   1302 	}
   1303 	return desc;
   1304 }
   1305 
   1306 const usb_descriptor_t *
   1307 usb_desc_iter_next(usbd_desc_iter_t *iter)
   1308 {
   1309 	const usb_descriptor_t *desc = usb_desc_iter_peek(iter);
   1310 	if (desc == NULL)
   1311 		return NULL;
   1312 	iter->cur += desc->bLength;
   1313 	return desc;
   1314 }
   1315 
   1316 /* Return the next interface descriptor, skipping over any other
   1317  * descriptors.  Returns NULL at the end or on error. */
   1318 const usb_interface_descriptor_t *
   1319 usb_desc_iter_next_interface(usbd_desc_iter_t *iter)
   1320 {
   1321 	const usb_descriptor_t *desc;
   1322 
   1323 	while ((desc = usb_desc_iter_peek(iter)) != NULL &&
   1324 	       desc->bDescriptorType != UDESC_INTERFACE)
   1325 	{
   1326 		usb_desc_iter_next(iter);
   1327 	}
   1328 
   1329 	return (const usb_interface_descriptor_t *)usb_desc_iter_next(iter);
   1330 }
   1331 
   1332 /* Returns the next non-interface descriptor, returning NULL when the
   1333  * next descriptor would be an interface descriptor. */
   1334 const usb_descriptor_t *
   1335 usb_desc_iter_next_non_interface(usbd_desc_iter_t *iter)
   1336 {
   1337 	const usb_descriptor_t *desc;
   1338 
   1339 	if ((desc = usb_desc_iter_peek(iter)) != NULL &&
   1340 	    desc->bDescriptorType != UDESC_INTERFACE)
   1341 	{
   1342 		return usb_desc_iter_next(iter);
   1343 	} else {
   1344 		return NULL;
   1345 	}
   1346 }
   1347 
   1348 usbd_status
   1349 usbd_get_string(struct usbd_device *dev, int si, char *buf)
   1350 {
   1351 	return usbd_get_string0(dev, si, buf, 1);
   1352 }
   1353 
   1354 usbd_status
   1355 usbd_get_string0(struct usbd_device *dev, int si, char *buf, int unicode)
   1356 {
   1357 	int swap = dev->ud_quirks->uq_flags & UQ_SWAP_UNICODE;
   1358 	usb_string_descriptor_t us;
   1359 	char *s;
   1360 	int i, n;
   1361 	uint16_t c;
   1362 	usbd_status err;
   1363 	int size;
   1364 
   1365 	USBHIST_FUNC(); USBHIST_CALLED(usbdebug);
   1366 
   1367 	buf[0] = '\0';
   1368 	if (si == 0)
   1369 		return USBD_INVAL;
   1370 	if (dev->ud_quirks->uq_flags & UQ_NO_STRINGS)
   1371 		return USBD_STALLED;
   1372 	if (dev->ud_langid == USBD_NOLANG) {
   1373 		/* Set up default language */
   1374 		err = usbd_get_string_desc(dev, USB_LANGUAGE_TABLE, 0, &us,
   1375 		    &size);
   1376 		if (err || size < 4) {
   1377 			USBHIST_LOG(usbdebug, "getting lang failed, using 0",
   1378 			    0, 0, 0, 0);
   1379 			dev->ud_langid = 0; /* Well, just pick something then */
   1380 		} else {
   1381 			/* Pick the first language as the default. */
   1382 			dev->ud_langid = UGETW(us.bString[0]);
   1383 		}
   1384 	}
   1385 	err = usbd_get_string_desc(dev, si, dev->ud_langid, &us, &size);
   1386 	if (err)
   1387 		return err;
   1388 	s = buf;
   1389 	n = size / 2 - 1;
   1390 	if (unicode) {
   1391 		for (i = 0; i < n; i++) {
   1392 			c = UGETW(us.bString[i]);
   1393 			if (swap)
   1394 				c = (c >> 8) | (c << 8);
   1395 			s += wput_utf8(s, 3, c);
   1396 		}
   1397 		*s++ = 0;
   1398 	}
   1399 #ifdef COMPAT_30
   1400 	else {
   1401 		for (i = 0; i < n; i++) {
   1402 			c = UGETW(us.bString[i]);
   1403 			if (swap)
   1404 				c = (c >> 8) | (c << 8);
   1405 			*s++ = (c < 0x80) ? c : '?';
   1406 		}
   1407 		*s++ = 0;
   1408 	}
   1409 #endif
   1410 	return USBD_NORMAL_COMPLETION;
   1411 }
   1412 
   1413 /*
   1414  * usbd_xfer_trycomplete(xfer)
   1415  *
   1416  *	Try to claim xfer for completion.  Return true if successful,
   1417  *	false if the xfer has been synchronously aborted or has timed
   1418  *	out.
   1419  *
   1420  *	If this returns true, caller is responsible for setting
   1421  *	xfer->ux_status and calling usb_transfer_complete.  To be used
   1422  *	in a host controller interrupt handler.
   1423  *
   1424  *	Caller must either hold the bus lock or have the bus in polling
   1425  *	mode.
   1426  */
   1427 bool
   1428 usbd_xfer_trycomplete(struct usbd_xfer *xfer)
   1429 {
   1430 	struct usbd_bus *bus __diagused = xfer->ux_bus;
   1431 
   1432 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1433 
   1434 	/*
   1435 	 * If software has completed it, either by synchronous abort or
   1436 	 * by timeout, too late.
   1437 	 */
   1438 	if (xfer->ux_status != USBD_IN_PROGRESS)
   1439 		return false;
   1440 
   1441 	/*
   1442 	 * We are completing the xfer.  Cancel the timeout if we can,
   1443 	 * but only asynchronously.  See usbd_xfer_cancel_timeout_async
   1444 	 * for why we need not wait for the callout or task here.
   1445 	 */
   1446 	usbd_xfer_cancel_timeout_async(xfer);
   1447 
   1448 	/* Success!  Note: Caller must set xfer->ux_status afterwar.  */
   1449 	return true;
   1450 }
   1451 
   1452 /*
   1453  * usbd_xfer_abort(xfer)
   1454  *
   1455  *	Try to claim xfer to abort.  If successful, mark it completed
   1456  *	with USBD_CANCELLED and call the bus-specific method to abort
   1457  *	at the hardware level.
   1458  *
   1459  *	To be called in thread context from struct
   1460  *	usbd_pipe_methods::upm_abort.
   1461  *
   1462  *	Caller must hold the bus lock.
   1463  */
   1464 void
   1465 usbd_xfer_abort(struct usbd_xfer *xfer)
   1466 {
   1467 	struct usbd_bus *bus = xfer->ux_bus;
   1468 
   1469 	KASSERT(mutex_owned(bus->ub_lock));
   1470 
   1471 	/*
   1472 	 * If host controller interrupt or timer interrupt has
   1473 	 * completed it, too late.  But the xfer cannot be
   1474 	 * cancelled already -- only one caller can synchronously
   1475 	 * abort.
   1476 	 */
   1477 	KASSERT(xfer->ux_status != USBD_CANCELLED);
   1478 	if (xfer->ux_status != USBD_IN_PROGRESS)
   1479 		return;
   1480 
   1481 	/*
   1482 	 * Cancel the timeout if we can, but only asynchronously; see
   1483 	 * usbd_xfer_cancel_timeout_async for why we need not wait for
   1484 	 * the callout or task here.
   1485 	 */
   1486 	usbd_xfer_cancel_timeout_async(xfer);
   1487 
   1488 	/*
   1489 	 * We beat everyone else.  Claim the status as cancelled and do
   1490 	 * the bus-specific dance to abort the hardware.
   1491 	 */
   1492 	xfer->ux_status = USBD_CANCELLED;
   1493 	bus->ub_methods->ubm_abortx(xfer);
   1494 }
   1495 
   1496 /*
   1497  * usbd_xfer_timeout(xfer)
   1498  *
   1499  *	Called at IPL_SOFTCLOCK when too much time has elapsed waiting
   1500  *	for xfer to complete.  Since we can't abort the xfer at
   1501  *	IPL_SOFTCLOCK, defer to a usb_task to run it in thread context,
   1502  *	unless the xfer has completed or aborted concurrently -- and if
   1503  *	the xfer has also been resubmitted, take care of rescheduling
   1504  *	the callout.
   1505  */
   1506 static void
   1507 usbd_xfer_timeout(void *cookie)
   1508 {
   1509 	struct usbd_xfer *xfer = cookie;
   1510 	struct usbd_bus *bus = xfer->ux_bus;
   1511 	struct usbd_device *dev = xfer->ux_pipe->up_dev;
   1512 
   1513 	/* Acquire the lock so we can transition the timeout state.  */
   1514 	mutex_enter(bus->ub_lock);
   1515 
   1516 	/*
   1517 	 * Use usbd_xfer_probe_timeout to check whether the timeout is
   1518 	 * still valid, or to reschedule the callout if necessary.  If
   1519 	 * it is still valid, schedule the task.
   1520 	 */
   1521 	if (usbd_xfer_probe_timeout(xfer))
   1522 		usb_add_task(dev, &xfer->ux_aborttask, USB_TASKQ_HC);
   1523 
   1524 	/*
   1525 	 * Notify usbd_xfer_cancel_timeout_async that we may have
   1526 	 * scheduled the task.  This causes callout_invoking to return
   1527 	 * false in usbd_xfer_cancel_timeout_async so that it can tell
   1528 	 * which stage in the callout->task->abort process we're at.
   1529 	 */
   1530 	callout_ack(&xfer->ux_callout);
   1531 
   1532 	/* All done -- release the lock.  */
   1533 	mutex_exit(bus->ub_lock);
   1534 }
   1535 
   1536 /*
   1537  * usbd_xfer_timeout_task(xfer)
   1538  *
   1539  *	Called in thread context when too much time has elapsed waiting
   1540  *	for xfer to complete.  Abort the xfer with USBD_TIMEOUT, unless
   1541  *	it has completed or aborted concurrently -- and if the xfer has
   1542  *	also been resubmitted, take care of rescheduling the callout.
   1543  */
   1544 static void
   1545 usbd_xfer_timeout_task(void *cookie)
   1546 {
   1547 	struct usbd_xfer *xfer = cookie;
   1548 	struct usbd_bus *bus = xfer->ux_bus;
   1549 
   1550 	/* Acquire the lock so we can transition the timeout state.  */
   1551 	mutex_enter(bus->ub_lock);
   1552 
   1553 	/*
   1554 	 * Use usbd_xfer_probe_timeout to check whether the timeout is
   1555 	 * still valid, or to reschedule the callout if necessary.  If
   1556 	 * it is not valid -- the timeout has been asynchronously
   1557 	 * cancelled, or the xfer has already been resubmitted -- then
   1558 	 * we're done here.
   1559 	 */
   1560 	if (!usbd_xfer_probe_timeout(xfer))
   1561 		goto out;
   1562 
   1563 	/*
   1564 	 * May have completed or been aborted, but we're the only one
   1565 	 * who can time it out.  If it has completed or been aborted,
   1566 	 * no need to timeout.
   1567 	 */
   1568 	KASSERT(xfer->ux_status != USBD_TIMEOUT);
   1569 	if (xfer->ux_status != USBD_IN_PROGRESS)
   1570 		goto out;
   1571 
   1572 	/*
   1573 	 * We beat everyone else.  Claim the status as timed out and do
   1574 	 * the bus-specific dance to abort the hardware.
   1575 	 */
   1576 	xfer->ux_status = USBD_TIMEOUT;
   1577 	bus->ub_methods->ubm_abortx(xfer);
   1578 
   1579 out:	/* All done -- release the lock.  */
   1580 	mutex_exit(bus->ub_lock);
   1581 }
   1582 
   1583 /*
   1584  * usbd_xfer_probe_timeout(xfer)
   1585  *
   1586  *	Probe the status of xfer's timeout.  Acknowledge and process a
   1587  *	request to reschedule.  Return true if the timeout is still
   1588  *	valid and the caller should take further action (queueing a
   1589  *	task or aborting the xfer), false if it must stop here.
   1590  */
   1591 static bool
   1592 usbd_xfer_probe_timeout(struct usbd_xfer *xfer)
   1593 {
   1594 	struct usbd_bus *bus = xfer->ux_bus;
   1595 	bool valid;
   1596 
   1597 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1598 
   1599 	/* The timeout must be set.  */
   1600 	KASSERT(xfer->ux_timeout_set);
   1601 
   1602 	/*
   1603 	 * Neither callout nor task may be pending; they execute
   1604 	 * alternately in lock step.
   1605 	 */
   1606 	KASSERT(!callout_pending(&xfer->ux_callout));
   1607 	KASSERT(!usb_task_pending(xfer->ux_pipe->up_dev, &xfer->ux_aborttask));
   1608 
   1609 	/* There are a few cases... */
   1610 	if (bus->ub_methods->ubm_dying(bus)) {
   1611 		/* Host controller dying.  Drop it all on the floor.  */
   1612 		xfer->ux_timeout_set = false;
   1613 		xfer->ux_timeout_reset = false;
   1614 		valid = false;
   1615 	} else if (xfer->ux_timeout_reset) {
   1616 		/*
   1617 		 * The xfer completed _and_ got resubmitted while we
   1618 		 * waited for the lock.  Acknowledge the request to
   1619 		 * reschedule, and reschedule it if there is a timeout
   1620 		 * and the bus is not polling.
   1621 		 */
   1622 		xfer->ux_timeout_reset = false;
   1623 		if (xfer->ux_timeout && !bus->ub_usepolling) {
   1624 			KASSERT(xfer->ux_timeout_set);
   1625 			callout_schedule(&xfer->ux_callout,
   1626 			    mstohz(xfer->ux_timeout));
   1627 		} else {
   1628 			/* No more callout or task scheduled.  */
   1629 			xfer->ux_timeout_set = false;
   1630 		}
   1631 		valid = false;
   1632 	} else if (xfer->ux_status != USBD_IN_PROGRESS) {
   1633 		/*
   1634 		 * The xfer has completed by hardware completion or by
   1635 		 * software abort, and has not been resubmitted, so the
   1636 		 * timeout must be unset, and is no longer valid for
   1637 		 * the caller.
   1638 		 */
   1639 		xfer->ux_timeout_set = false;
   1640 		valid = false;
   1641 	} else {
   1642 		/*
   1643 		 * The xfer has not yet completed, so the timeout is
   1644 		 * valid.
   1645 		 */
   1646 		valid = true;
   1647 	}
   1648 
   1649 	/* Any reset must have been processed.  */
   1650 	KASSERT(!xfer->ux_timeout_reset);
   1651 
   1652 	/*
   1653 	 * Either we claim the timeout is set, or the callout is idle.
   1654 	 * If the timeout is still set, we may be handing off to the
   1655 	 * task instead, so this is an if but not an iff.
   1656 	 */
   1657 	KASSERT(xfer->ux_timeout_set || !callout_pending(&xfer->ux_callout));
   1658 
   1659 	/*
   1660 	 * The task must be idle now.
   1661 	 *
   1662 	 * - If the caller is the callout, _and_ the timeout is still
   1663 	 *   valid, the caller will schedule it, but it hasn't been
   1664 	 *   scheduled yet.  (If the timeout is not valid, the task
   1665 	 *   should not be scheduled.)
   1666 	 *
   1667 	 * - If the caller is the task, it cannot be scheduled again
   1668 	 *   until the callout runs again, which won't happen until we
   1669 	 *   next release the lock.
   1670 	 */
   1671 	KASSERT(!usb_task_pending(xfer->ux_pipe->up_dev, &xfer->ux_aborttask));
   1672 
   1673 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1674 
   1675 	return valid;
   1676 }
   1677 
   1678 /*
   1679  * usbd_xfer_schedule_timeout(xfer)
   1680  *
   1681  *	Ensure that xfer has a timeout.  If the callout is already
   1682  *	queued or the task is already running, request that they
   1683  *	reschedule the callout.  If not, and if we're not polling,
   1684  *	schedule the callout anew.
   1685  *
   1686  *	To be called in thread context from struct
   1687  *	usbd_pipe_methods::upm_start.
   1688  */
   1689 void
   1690 usbd_xfer_schedule_timeout(struct usbd_xfer *xfer)
   1691 {
   1692 	struct usbd_bus *bus = xfer->ux_bus;
   1693 
   1694 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1695 
   1696 	if (xfer->ux_timeout_set) {
   1697 		/*
   1698 		 * Callout or task has fired from a prior completed
   1699 		 * xfer but has not yet noticed that the xfer is done.
   1700 		 * Ask it to reschedule itself to ux_timeout.
   1701 		 */
   1702 		xfer->ux_timeout_reset = true;
   1703 	} else if (xfer->ux_timeout && !bus->ub_usepolling) {
   1704 		/* Callout is not scheduled.  Schedule it.  */
   1705 		KASSERT(!callout_pending(&xfer->ux_callout));
   1706 		callout_schedule(&xfer->ux_callout, mstohz(xfer->ux_timeout));
   1707 		xfer->ux_timeout_set = true;
   1708 	}
   1709 
   1710 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1711 }
   1712 
   1713 /*
   1714  * usbd_xfer_cancel_timeout_async(xfer)
   1715  *
   1716  *	Cancel the callout and the task of xfer, which have not yet run
   1717  *	to completion, but don't wait for the callout or task to finish
   1718  *	running.
   1719  *
   1720  *	If they have already fired, at worst they are waiting for the
   1721  *	bus lock.  They will see that the xfer is no longer in progress
   1722  *	and give up, or they will see that the xfer has been
   1723  *	resubmitted with a new timeout and reschedule the callout.
   1724  *
   1725  *	If a resubmitted request completed so fast that the callout
   1726  *	didn't have time to process a timer reset, just cancel the
   1727  *	timer reset.
   1728  */
   1729 static void
   1730 usbd_xfer_cancel_timeout_async(struct usbd_xfer *xfer)
   1731 {
   1732 	struct usbd_bus *bus __diagused = xfer->ux_bus;
   1733 
   1734 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1735 
   1736 	/*
   1737 	 * If the timer wasn't running anyway, forget about it.  This
   1738 	 * can happen if we are completing an isochronous transfer
   1739 	 * which doesn't use the same timeout logic.
   1740 	 */
   1741 	if (!xfer->ux_timeout_set)
   1742 		return;
   1743 
   1744 	xfer->ux_timeout_reset = false;
   1745 	if (!callout_stop(&xfer->ux_callout)) {
   1746 		/*
   1747 		 * We stopped the callout before it ran.  The timeout
   1748 		 * is no longer set.
   1749 		 */
   1750 		xfer->ux_timeout_set = false;
   1751 	} else if (callout_invoking(&xfer->ux_callout)) {
   1752 		/*
   1753 		 * The callout has begun to run but it has not yet
   1754 		 * acquired the lock and called callout_ack.  The task
   1755 		 * cannot be queued yet, and the callout cannot have
   1756 		 * been rescheduled yet.
   1757 		 *
   1758 		 * By the time the callout acquires the lock, we will
   1759 		 * have transitioned from USBD_IN_PROGRESS to a
   1760 		 * completed status, and possibly also resubmitted the
   1761 		 * xfer and set xfer->ux_timeout_reset = true.  In both
   1762 		 * cases, the callout will DTRT, so no further action
   1763 		 * is needed here.
   1764 		 */
   1765 	} else if (usb_rem_task(xfer->ux_pipe->up_dev, &xfer->ux_aborttask)) {
   1766 		/*
   1767 		 * The callout had fired and scheduled the task, but we
   1768 		 * stopped the task before it could run.  The timeout
   1769 		 * is therefore no longer set -- the next resubmission
   1770 		 * of the xfer must schedule a new timeout.
   1771 		 *
   1772 		 * The callout should not be be pending at this point:
   1773 		 * it is scheduled only under the lock, and only when
   1774 		 * xfer->ux_timeout_set is false, or by the callout or
   1775 		 * task itself when xfer->ux_timeout_reset is true.
   1776 		 */
   1777 		xfer->ux_timeout_set = false;
   1778 	}
   1779 
   1780 	/*
   1781 	 * The callout cannot be scheduled and the task cannot be
   1782 	 * queued at this point.  Either we cancelled them, or they are
   1783 	 * already running and waiting for the bus lock.
   1784 	 */
   1785 	KASSERT(!callout_pending(&xfer->ux_callout));
   1786 	KASSERT(!usb_task_pending(xfer->ux_pipe->up_dev, &xfer->ux_aborttask));
   1787 
   1788 	KASSERT(bus->ub_usepolling || mutex_owned(bus->ub_lock));
   1789 }
   1790