Implement SCSI WRITE(10), closing the graph's highest-leverage blocker

Direct mirror of the existing READ(10) implementation (FABRIC-3.md §F.1),
data direction flipped: new XHCI_XFER_BOT_DATA_OUT/XHCI_NEXT_ACTION_BOT_DATA_OUT
states, xhci_bot_send_write10()/xhci_bot_write_block()/xhci_bot_write_data_out()
in xhci.c, new SCSI_CMD_WRITE10 opcode and BOT_CMD_WRITE10/BOT_TUR_CHAIN_WRITE10
enum values. usb_blk_write() in blkio_usb.c is real now, no longer the
BLKIO_ENOSUP stub. read_only flips to 0 in blkio_info() now that it's proven.

Verified live end-to-end on all three architectures with a genuine cold-reboot
round-trip (not just a same-session read): BLK-CONFIRM-FORMAT's BAM/reloc
writes and an explicit block content write both completed via clean WRITE10
cycles (CSW PASS), and the written byte read back correctly after a full
kernel rebuild + fresh boot -- amd64=65, aarch64=170, riscv64=201, each at
LBN 32734 on a disposable usbwrite-test.img attached via QEMU usb-storage.

Added Makefile.starkernel's QEMU_EXTRA (empty by default, no behavior change)
to attach the disposable test image for this validation; the drive must be
hotplugged via QMP after boot reaches ok>, not attached at QEMU launch --
attaching before xhci_bringup()'s controller reset means no fresh Port
Status Change event fires (see project_xhci_milestone_2d_polling memory).

Found and reported, not fixed, during testing: EMPTY-BUFFERS
(empty_all_buffers(), block_words.c) does not implement standard Forth-79
semantics -- it force-writes zero to every block on every attached device
instead of discarding cache assignments. This corrupted disk/artemis.img
during an earlier test run; restored from git, confirmed byte-identical.
Avoided in the final validation runs (detach/reattach used instead to force
a fresh read).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019ZGkimpfyh63EZyRkNbkPD
This commit is contained in:
Robert Allan James
2026-08-28 07:19:31 -04:00
co-authored by Claude Sonnet 5
parent ff67bbdec3
commit 5e9802845a
15 changed files with 89095 additions and 21 deletions
+23 -8
View File
@@ -59,17 +59,29 @@ static int usb_blk_read(blkio_dev_t *dev, uint32_t fblock, void *dst) {
}
static int usb_blk_write(blkio_dev_t *dev, uint32_t fblock, const void *src) {
(void)dev;
(void)fblock;
(void)src;
/* No SCSI WRITE(10) in the xHCI driver yet — read-only this increment,
* see blkio_usb.h's own doc comment. */
return BLKIO_ENOSUP;
if (!dev || !src) return BLKIO_EINVAL;
BlkioUsbState *s = (BlkioUsbState *)dev->state;
if (fblock >= s->total_forth_blocks) return BLKIO_EINVAL;
memcpy(s->xdev->bot_data_buf, src, BLKIO_FORTH_BLOCK_SIZE);
uint32_t lba = fblock * s->scsi_blocks_per_fblock;
if (xhci_bot_write_block(s->xdev, s->slot_id, lba,
(uint16_t)s->scsi_blocks_per_fblock,
s->scsi_block_size) != 0) {
return BLKIO_EIO;
}
if (xhci_bot_wait_for_idle(s->xdev, 100000u) != BOT_STATUS_PASS) {
return BLKIO_EIO;
}
return BLKIO_OK;
}
static int usb_blk_flush(blkio_dev_t *dev) {
(void)dev;
return BLKIO_OK; /* nothing buffered to flush — read-only backend */
return BLKIO_OK; /* every write above is already synchronous -- see
* usb_blk_write()'s own xhci_bot_wait_for_idle()
* call -- nothing buffered here to flush. */
}
static int usb_blk_info(blkio_dev_t *dev, blkio_info_t *out) {
@@ -79,7 +91,10 @@ static int usb_blk_info(blkio_dev_t *dev, blkio_info_t *out) {
out->total_blocks = s->total_forth_blocks;
out->phys_sector_size = s->scsi_block_size;
out->phys_size_bytes = (uint64_t)s->total_forth_blocks * BLKIO_FORTH_BLOCK_SIZE;
out->read_only = 1;
out->read_only = 0; /* WRITE(10) verified live end-to-end on amd64,
* 2026-08-28 (FABRIC-3.md §F.1): BLK-CONFIRM-FORMAT's
* BAM/reloc writes and an explicit content write both
* survived a cold reboot and read back correctly. */
return BLKIO_OK;
}
+117 -5
View File
@@ -132,10 +132,13 @@ int xhci_cmd_address_device(xhci_dev_t *dev, uint32_t slot_id,
int xhci_cmd_configure_endpoint(xhci_dev_t *dev, uint32_t slot_id);
int xhci_bot_send_read10(xhci_dev_t *dev, uint32_t slot_id, uint32_t lba,
uint16_t num_blocks, uint32_t block_size);
int xhci_bot_send_write10(xhci_dev_t *dev, uint32_t slot_id, uint32_t lba,
uint16_t num_blocks, uint32_t block_size);
int xhci_bot_send_test_unit_ready(xhci_dev_t *dev, uint32_t slot_id);
int xhci_bot_send_read_capacity10(xhci_dev_t *dev, uint32_t slot_id);
int xhci_bot_get_capacity(xhci_dev_t *dev, uint32_t slot_id);
int xhci_bot_read_data_in(xhci_dev_t *dev, uint32_t slot_id);
int xhci_bot_write_data_out(xhci_dev_t *dev, uint32_t slot_id);
int xhci_bot_receive_csw(xhci_dev_t *dev, uint32_t slot_id);
int xhci_ep0_get_device_descriptor(xhci_dev_t *dev, uint32_t slot_id);
int xhci_ep0_get_config_descriptor(xhci_dev_t *dev, uint32_t slot_id, uint16_t length);
@@ -737,6 +740,54 @@ int xhci_bot_send_read10(xhci_dev_t *dev, uint32_t slot_id, uint32_t lba,
return 0;
}
int xhci_bot_send_write10(xhci_dev_t *dev, uint32_t slot_id, uint32_t lba,
uint16_t num_blocks, uint32_t block_size)
{
if (!dev || !dev->bulk_out_ring || !dev->bulk_in_ring) return -1;
if (dev->bulk_out_ep_addr == 0 || dev->bulk_in_ep_addr == 0) return -1;
uint32_t data_len = (uint32_t)num_blocks * block_size;
if (data_len > sizeof(dev->bot_data_buf)) return -1;
dev->bot_cmd_kind = BOT_CMD_WRITE10;
usb_bot_cbw_t *cbw = &dev->bot_cbw;
cbw->dCBWSignature = USB_BOT_CBW_SIGNATURE;
cbw->dCBWTag = dev->bot_next_tag++;
dev->bot_last_tag = cbw->dCBWTag;
dev->bot_expected_data_len = data_len;
cbw->dCBWDataTransferLength = data_len;
cbw->bmCBWFlags = 0; /* WRITE(10): host -> device data stage, unlike
* READ10's USB_BOT_CBW_FLAG_DATA_IN above */
cbw->bCBWLUN = USB_BOT_CBW_LUN_DEFAULT;
cbw->bCBWCBLength = SCSI_CDB_LEN_WRITE10;
for (uint32_t i = 0; i < sizeof(cbw->CBWCB); i++) cbw->CBWCB[i] = 0;
/* SCSI WRITE(10) CDB (SBC-3 section 5.32) -- identical layout to
* READ(10)'s CDB above, only the opcode differs. Same big-endian
* field packing, see xhci_bot_send_read10()'s own comment for why. */
cbw->CBWCB[0] = SCSI_CMD_WRITE10;
cbw->CBWCB[1] = 0; /* flags: no FUA/DPO for this increment */
cbw->CBWCB[2] = (uint8_t)(lba >> 24);
cbw->CBWCB[3] = (uint8_t)(lba >> 16);
cbw->CBWCB[4] = (uint8_t)(lba >> 8);
cbw->CBWCB[5] = (uint8_t)(lba);
cbw->CBWCB[6] = 0; /* group number */
cbw->CBWCB[7] = (uint8_t)(num_blocks >> 8);
cbw->CBWCB[8] = (uint8_t)(num_blocks);
cbw->CBWCB[9] = 0; /* control */
dev->transfer_purpose = XHCI_XFER_CBW_SENT;
dev->pending_transfer_slot_id = slot_id;
xhci_bulk_out_enqueue_and_ring(dev, slot_id, (uint64_t)(uintptr_t)cbw,
USB_BOT_CBW_LENGTH,
(XHCI_TRB_TYPE_NORMAL << XHCI_TRB_CONTROL_TYPE_SHIFT) |
XHCI_TRB_CONTROL_IOC);
console_println("xhci: CBW (WRITE10) submitted");
return 0;
}
int xhci_bot_send_test_unit_ready(xhci_dev_t *dev, uint32_t slot_id)
{
if (!dev || !dev->bulk_out_ring || !dev->bulk_in_ring) return -1;
@@ -817,6 +868,22 @@ int xhci_bot_read_block(xhci_dev_t *dev, uint32_t slot_id, uint32_t lba,
return xhci_bot_send_test_unit_ready(dev, slot_id);
}
int xhci_bot_write_block(xhci_dev_t *dev, uint32_t slot_id, uint32_t lba,
uint16_t num_blocks, uint32_t block_size)
{
if (!dev || !dev->bulk_out_ring || !dev->bulk_in_ring) return -1;
if (dev->bulk_out_ep_addr == 0 || dev->bulk_in_ep_addr == 0) return -1;
if ((uint32_t)num_blocks * block_size > sizeof(dev->bot_data_buf)) return -1;
dev->bot_write10_lba = lba;
dev->bot_write10_num_blocks = num_blocks;
dev->bot_write10_block_size = block_size;
dev->bot_tur_chain_target = BOT_TUR_CHAIN_WRITE10;
dev->bot_tur_retries = 0;
return xhci_bot_send_test_unit_ready(dev, slot_id);
}
int xhci_bot_get_capacity(xhci_dev_t *dev, uint32_t slot_id)
{
if (!dev || !dev->bulk_out_ring || !dev->bulk_in_ring) return -1;
@@ -879,6 +946,21 @@ int xhci_bot_read_data_in(xhci_dev_t *dev, uint32_t slot_id)
return 0;
}
int xhci_bot_write_data_out(xhci_dev_t *dev, uint32_t slot_id)
{
if (!dev || !dev->bulk_out_ring) return -1;
dev->transfer_purpose = XHCI_XFER_BOT_DATA_OUT;
dev->pending_transfer_slot_id = slot_id;
xhci_bulk_out_enqueue_and_ring(dev, slot_id, (uint64_t)(uintptr_t)dev->bot_data_buf,
dev->bot_expected_data_len,
(XHCI_TRB_TYPE_NORMAL << XHCI_TRB_CONTROL_TYPE_SHIFT) |
XHCI_TRB_CONTROL_IOC);
console_println("xhci: BOT Data-Out write submitted");
return 0;
}
int xhci_bot_receive_csw(xhci_dev_t *dev, uint32_t slot_id)
{
if (!dev || !dev->bulk_in_ring) return -1;
@@ -1432,11 +1514,17 @@ void xhci_poll_events(void)
* same doorbell-ordering hazard as every
* other chained request in this driver.
* dCBWDataTransferLength == 0 (TEST UNIT
* READY) means no Data-In stage exists --
* BOT spec section 6.3 -- so skip straight to
* CSW receive. */
* READY) means no data stage exists -- BOT
* spec section 6.3 -- so skip straight to CSW
* receive. Otherwise the direction depends on
* which command this CBW was for: WRITE(10)
* needs a Data-Out stage (bulk_out_ring),
* every other data-bearing command here
* (READ10, READ CAPACITY10) needs Data-In. */
if (dev->bot_expected_data_len == 0) {
dev->next_action = XHCI_NEXT_ACTION_BOT_CSW_RECEIVE;
} else if (dev->bot_cmd_kind == BOT_CMD_WRITE10) {
dev->next_action = XHCI_NEXT_ACTION_BOT_DATA_OUT;
} else {
dev->next_action = XHCI_NEXT_ACTION_BOT_DATA_IN;
}
@@ -1449,6 +1537,12 @@ void xhci_poll_events(void)
dev->next_action_slot_id = xfer_slot_id;
break;
}
case XHCI_XFER_BOT_DATA_OUT: {
console_println("xhci: BOT Data-Out write completed");
dev->next_action = XHCI_NEXT_ACTION_BOT_CSW_RECEIVE;
dev->next_action_slot_id = xfer_slot_id;
break;
}
case XHCI_XFER_CSW_RECEIVED: {
/* USB Mass Storage Class BOT spec section 5.2:
* a valid CSW must have the right signature
@@ -1494,6 +1588,9 @@ void xhci_poll_events(void)
if (dev->bot_tur_chain_target == BOT_TUR_CHAIN_READ_CAPACITY10) {
console_println("xhci: unit ready -- issuing READ CAPACITY10");
dev->next_action = XHCI_NEXT_ACTION_BOT_SEND_READ_CAPACITY10;
} else if (dev->bot_tur_chain_target == BOT_TUR_CHAIN_WRITE10) {
console_println("xhci: unit ready -- issuing WRITE10");
dev->next_action = XHCI_NEXT_ACTION_BOT_SEND_WRITE10;
} else {
console_println("xhci: unit ready -- issuing READ10");
dev->next_action = XHCI_NEXT_ACTION_BOT_SEND_READ10;
@@ -1522,8 +1619,9 @@ void xhci_poll_events(void)
dev->bot_last_status = csw_pass ? BOT_STATUS_PASS : BOT_STATUS_FAILED;
dev->bot_cmd_kind = BOT_CMD_NONE;
} else {
/* BOT_CMD_READ10 (BOT_CMD_NONE shouldn't
* reach here) -- terminal either way. */
/* BOT_CMD_READ10 or BOT_CMD_WRITE10
* (BOT_CMD_NONE shouldn't reach here) --
* terminal either way. */
dev->bot_last_status = csw_pass ? BOT_STATUS_PASS : BOT_STATUS_FAILED;
dev->bot_cmd_kind = BOT_CMD_NONE;
}
@@ -1599,6 +1697,12 @@ void xhci_poll_events(void)
if (xhci_bot_read_data_in(dev, next_slot_id) != 0) {
console_println("xhci: deferred BOT Data-In read setup failed");
}
} else if (dev->next_action == XHCI_NEXT_ACTION_BOT_DATA_OUT) {
uint32_t next_slot_id = dev->next_action_slot_id;
dev->next_action = XHCI_NEXT_ACTION_NONE;
if (xhci_bot_write_data_out(dev, next_slot_id) != 0) {
console_println("xhci: deferred BOT Data-Out write setup failed");
}
} else if (dev->next_action == XHCI_NEXT_ACTION_BOT_CSW_RECEIVE) {
uint32_t next_slot_id = dev->next_action_slot_id;
dev->next_action = XHCI_NEXT_ACTION_NONE;
@@ -1625,5 +1729,13 @@ void xhci_poll_events(void)
if (xhci_bot_send_read_capacity10(dev, next_slot_id) != 0) {
console_println("xhci: deferred READ CAPACITY10 setup failed");
}
} else if (dev->next_action == XHCI_NEXT_ACTION_BOT_SEND_WRITE10) {
uint32_t next_slot_id = dev->next_action_slot_id;
dev->next_action = XHCI_NEXT_ACTION_NONE;
if (xhci_bot_send_write10(dev, next_slot_id, dev->bot_write10_lba,
dev->bot_write10_num_blocks,
dev->bot_write10_block_size) != 0) {
console_println("xhci: deferred WRITE10 setup failed");
}
}
}