On certain Broadcom MPI-3 controllers (such as the SAS5116 family),
under heavy workloads, operational reply queues can experience severe
congestion. If an operational reply queue fills up completely, the
hardware controller cannot post completion descriptors, resulting in
missed completions, I/O timeouts, and fatal controller lockups.
To prevent this condition, firmware advertises whether the controller
requires a request limit per reply queue via the
MPI3_IOCFACTS_FLAGS_MAX_REQ_PER_REPLY_QUEUE_LIMIT flag in IOCFacts.
Implement a driver-level throttling workaround when this flag is set:
- Calculate a congestion watermark for each operational reply queue (num_replies - (MPI3MR_THRESHOLD_REPLY_COUNT * 2)).
- In mpi3mr_submit_io(), check the number of pending I/Os against the reply queue watermark. If the queue is nearing capacity, push back I/O submission by returning EAGAIN, allowing CAM to set CAM_RESRC_UNAVAIL and requeue the CCB until in-flight completions drain.
- Expose the dev.mpi3mr.X.reply_qfull_count sysctl so administrators and developers can monitor queue throttling events.