usb: gadget: f_fs: Prevent panic due to failure of huge size buffer allocation
[platform/kernel/linux-rpi.git] / drivers / hv / channel_mgmt.c
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  * Copyright (c) 2009, Microsoft Corporation.
4  *
5  * Authors:
6  *   Haiyang Zhang <haiyangz@microsoft.com>
7  *   Hank Janssen  <hjanssen@microsoft.com>
8  */
9 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
10
11 #include <linux/kernel.h>
12 #include <linux/interrupt.h>
13 #include <linux/sched.h>
14 #include <linux/wait.h>
15 #include <linux/mm.h>
16 #include <linux/slab.h>
17 #include <linux/list.h>
18 #include <linux/module.h>
19 #include <linux/completion.h>
20 #include <linux/delay.h>
21 #include <linux/cpu.h>
22 #include <linux/hyperv.h>
23 #include <asm/mshyperv.h>
24
25 #include "hyperv_vmbus.h"
26
27 static void init_vp_index(struct vmbus_channel *channel);
28
29 const struct vmbus_device vmbus_devs[] = {
30         /* IDE */
31         { .dev_type = HV_IDE,
32           HV_IDE_GUID,
33           .perf_device = true,
34           .allowed_in_isolated = false,
35         },
36
37         /* SCSI */
38         { .dev_type = HV_SCSI,
39           HV_SCSI_GUID,
40           .perf_device = true,
41           .allowed_in_isolated = true,
42         },
43
44         /* Fibre Channel */
45         { .dev_type = HV_FC,
46           HV_SYNTHFC_GUID,
47           .perf_device = true,
48           .allowed_in_isolated = false,
49         },
50
51         /* Synthetic NIC */
52         { .dev_type = HV_NIC,
53           HV_NIC_GUID,
54           .perf_device = true,
55           .allowed_in_isolated = true,
56         },
57
58         /* Network Direct */
59         { .dev_type = HV_ND,
60           HV_ND_GUID,
61           .perf_device = true,
62           .allowed_in_isolated = false,
63         },
64
65         /* PCIE */
66         { .dev_type = HV_PCIE,
67           HV_PCIE_GUID,
68           .perf_device = false,
69           .allowed_in_isolated = false,
70         },
71
72         /* Synthetic Frame Buffer */
73         { .dev_type = HV_FB,
74           HV_SYNTHVID_GUID,
75           .perf_device = false,
76           .allowed_in_isolated = false,
77         },
78
79         /* Synthetic Keyboard */
80         { .dev_type = HV_KBD,
81           HV_KBD_GUID,
82           .perf_device = false,
83           .allowed_in_isolated = false,
84         },
85
86         /* Synthetic MOUSE */
87         { .dev_type = HV_MOUSE,
88           HV_MOUSE_GUID,
89           .perf_device = false,
90           .allowed_in_isolated = false,
91         },
92
93         /* KVP */
94         { .dev_type = HV_KVP,
95           HV_KVP_GUID,
96           .perf_device = false,
97           .allowed_in_isolated = false,
98         },
99
100         /* Time Synch */
101         { .dev_type = HV_TS,
102           HV_TS_GUID,
103           .perf_device = false,
104           .allowed_in_isolated = true,
105         },
106
107         /* Heartbeat */
108         { .dev_type = HV_HB,
109           HV_HEART_BEAT_GUID,
110           .perf_device = false,
111           .allowed_in_isolated = true,
112         },
113
114         /* Shutdown */
115         { .dev_type = HV_SHUTDOWN,
116           HV_SHUTDOWN_GUID,
117           .perf_device = false,
118           .allowed_in_isolated = true,
119         },
120
121         /* File copy */
122         { .dev_type = HV_FCOPY,
123           HV_FCOPY_GUID,
124           .perf_device = false,
125           .allowed_in_isolated = false,
126         },
127
128         /* Backup */
129         { .dev_type = HV_BACKUP,
130           HV_VSS_GUID,
131           .perf_device = false,
132           .allowed_in_isolated = false,
133         },
134
135         /* Dynamic Memory */
136         { .dev_type = HV_DM,
137           HV_DM_GUID,
138           .perf_device = false,
139           .allowed_in_isolated = false,
140         },
141
142         /* Unknown GUID */
143         { .dev_type = HV_UNKNOWN,
144           .perf_device = false,
145           .allowed_in_isolated = false,
146         },
147 };
148
149 static const struct {
150         guid_t guid;
151 } vmbus_unsupported_devs[] = {
152         { HV_AVMA1_GUID },
153         { HV_AVMA2_GUID },
154         { HV_RDV_GUID   },
155 };
156
157 /*
158  * The rescinded channel may be blocked waiting for a response from the host;
159  * take care of that.
160  */
161 static void vmbus_rescind_cleanup(struct vmbus_channel *channel)
162 {
163         struct vmbus_channel_msginfo *msginfo;
164         unsigned long flags;
165
166
167         spin_lock_irqsave(&vmbus_connection.channelmsg_lock, flags);
168         channel->rescind = true;
169         list_for_each_entry(msginfo, &vmbus_connection.chn_msg_list,
170                                 msglistentry) {
171
172                 if (msginfo->waiting_channel == channel) {
173                         complete(&msginfo->waitevent);
174                         break;
175                 }
176         }
177         spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
178 }
179
180 static bool is_unsupported_vmbus_devs(const guid_t *guid)
181 {
182         int i;
183
184         for (i = 0; i < ARRAY_SIZE(vmbus_unsupported_devs); i++)
185                 if (guid_equal(guid, &vmbus_unsupported_devs[i].guid))
186                         return true;
187         return false;
188 }
189
190 static u16 hv_get_dev_type(const struct vmbus_channel *channel)
191 {
192         const guid_t *guid = &channel->offermsg.offer.if_type;
193         u16 i;
194
195         if (is_hvsock_channel(channel) || is_unsupported_vmbus_devs(guid))
196                 return HV_UNKNOWN;
197
198         for (i = HV_IDE; i < HV_UNKNOWN; i++) {
199                 if (guid_equal(guid, &vmbus_devs[i].guid))
200                         return i;
201         }
202         pr_info("Unknown GUID: %pUl\n", guid);
203         return i;
204 }
205
206 /**
207  * vmbus_prep_negotiate_resp() - Create default response for Negotiate message
208  * @icmsghdrp: Pointer to msg header structure
209  * @buf: Raw buffer channel data
210  * @buflen: Length of the raw buffer channel data.
211  * @fw_version: The framework versions we can support.
212  * @fw_vercnt: The size of @fw_version.
213  * @srv_version: The service versions we can support.
214  * @srv_vercnt: The size of @srv_version.
215  * @nego_fw_version: The selected framework version.
216  * @nego_srv_version: The selected service version.
217  *
218  * Note: Versions are given in decreasing order.
219  *
220  * Set up and fill in default negotiate response message.
221  * Mainly used by Hyper-V drivers.
222  */
223 bool vmbus_prep_negotiate_resp(struct icmsg_hdr *icmsghdrp, u8 *buf,
224                                 u32 buflen, const int *fw_version, int fw_vercnt,
225                                 const int *srv_version, int srv_vercnt,
226                                 int *nego_fw_version, int *nego_srv_version)
227 {
228         int icframe_major, icframe_minor;
229         int icmsg_major, icmsg_minor;
230         int fw_major, fw_minor;
231         int srv_major, srv_minor;
232         int i, j;
233         bool found_match = false;
234         struct icmsg_negotiate *negop;
235
236         /* Check that there's enough space for icframe_vercnt, icmsg_vercnt */
237         if (buflen < ICMSG_HDR + offsetof(struct icmsg_negotiate, reserved)) {
238                 pr_err_ratelimited("Invalid icmsg negotiate\n");
239                 return false;
240         }
241
242         icmsghdrp->icmsgsize = 0x10;
243         negop = (struct icmsg_negotiate *)&buf[ICMSG_HDR];
244
245         icframe_major = negop->icframe_vercnt;
246         icframe_minor = 0;
247
248         icmsg_major = negop->icmsg_vercnt;
249         icmsg_minor = 0;
250
251         /* Validate negop packet */
252         if (icframe_major > IC_VERSION_NEGOTIATION_MAX_VER_COUNT ||
253             icmsg_major > IC_VERSION_NEGOTIATION_MAX_VER_COUNT ||
254             ICMSG_NEGOTIATE_PKT_SIZE(icframe_major, icmsg_major) > buflen) {
255                 pr_err_ratelimited("Invalid icmsg negotiate - icframe_major: %u, icmsg_major: %u\n",
256                                    icframe_major, icmsg_major);
257                 goto fw_error;
258         }
259
260         /*
261          * Select the framework version number we will
262          * support.
263          */
264
265         for (i = 0; i < fw_vercnt; i++) {
266                 fw_major = (fw_version[i] >> 16);
267                 fw_minor = (fw_version[i] & 0xFFFF);
268
269                 for (j = 0; j < negop->icframe_vercnt; j++) {
270                         if ((negop->icversion_data[j].major == fw_major) &&
271                             (negop->icversion_data[j].minor == fw_minor)) {
272                                 icframe_major = negop->icversion_data[j].major;
273                                 icframe_minor = negop->icversion_data[j].minor;
274                                 found_match = true;
275                                 break;
276                         }
277                 }
278
279                 if (found_match)
280                         break;
281         }
282
283         if (!found_match)
284                 goto fw_error;
285
286         found_match = false;
287
288         for (i = 0; i < srv_vercnt; i++) {
289                 srv_major = (srv_version[i] >> 16);
290                 srv_minor = (srv_version[i] & 0xFFFF);
291
292                 for (j = negop->icframe_vercnt;
293                         (j < negop->icframe_vercnt + negop->icmsg_vercnt);
294                         j++) {
295
296                         if ((negop->icversion_data[j].major == srv_major) &&
297                                 (negop->icversion_data[j].minor == srv_minor)) {
298
299                                 icmsg_major = negop->icversion_data[j].major;
300                                 icmsg_minor = negop->icversion_data[j].minor;
301                                 found_match = true;
302                                 break;
303                         }
304                 }
305
306                 if (found_match)
307                         break;
308         }
309
310         /*
311          * Respond with the framework and service
312          * version numbers we can support.
313          */
314
315 fw_error:
316         if (!found_match) {
317                 negop->icframe_vercnt = 0;
318                 negop->icmsg_vercnt = 0;
319         } else {
320                 negop->icframe_vercnt = 1;
321                 negop->icmsg_vercnt = 1;
322         }
323
324         if (nego_fw_version)
325                 *nego_fw_version = (icframe_major << 16) | icframe_minor;
326
327         if (nego_srv_version)
328                 *nego_srv_version = (icmsg_major << 16) | icmsg_minor;
329
330         negop->icversion_data[0].major = icframe_major;
331         negop->icversion_data[0].minor = icframe_minor;
332         negop->icversion_data[1].major = icmsg_major;
333         negop->icversion_data[1].minor = icmsg_minor;
334         return found_match;
335 }
336 EXPORT_SYMBOL_GPL(vmbus_prep_negotiate_resp);
337
338 /*
339  * alloc_channel - Allocate and initialize a vmbus channel object
340  */
341 static struct vmbus_channel *alloc_channel(void)
342 {
343         struct vmbus_channel *channel;
344
345         channel = kzalloc(sizeof(*channel), GFP_ATOMIC);
346         if (!channel)
347                 return NULL;
348
349         spin_lock_init(&channel->sched_lock);
350         init_completion(&channel->rescind_event);
351
352         INIT_LIST_HEAD(&channel->sc_list);
353
354         tasklet_init(&channel->callback_event,
355                      vmbus_on_event, (unsigned long)channel);
356
357         hv_ringbuffer_pre_init(channel);
358
359         return channel;
360 }
361
362 /*
363  * free_channel - Release the resources used by the vmbus channel object
364  */
365 static void free_channel(struct vmbus_channel *channel)
366 {
367         tasklet_kill(&channel->callback_event);
368         vmbus_remove_channel_attr_group(channel);
369
370         kobject_put(&channel->kobj);
371 }
372
373 void vmbus_channel_map_relid(struct vmbus_channel *channel)
374 {
375         if (WARN_ON(channel->offermsg.child_relid >= MAX_CHANNEL_RELIDS))
376                 return;
377         /*
378          * The mapping of the channel's relid is visible from the CPUs that
379          * execute vmbus_chan_sched() by the time that vmbus_chan_sched() will
380          * execute:
381          *
382          *  (a) In the "normal (i.e., not resuming from hibernation)" path,
383          *      the full barrier in virt_store_mb() guarantees that the store
384          *      is propagated to all CPUs before the add_channel_work work
385          *      is queued.  In turn, add_channel_work is queued before the
386          *      channel's ring buffer is allocated/initialized and the
387          *      OPENCHANNEL message for the channel is sent in vmbus_open().
388          *      Hyper-V won't start sending the interrupts for the channel
389          *      before the OPENCHANNEL message is acked.  The memory barrier
390          *      in vmbus_chan_sched() -> sync_test_and_clear_bit() ensures
391          *      that vmbus_chan_sched() must find the channel's relid in
392          *      recv_int_page before retrieving the channel pointer from the
393          *      array of channels.
394          *
395          *  (b) In the "resuming from hibernation" path, the virt_store_mb()
396          *      guarantees that the store is propagated to all CPUs before
397          *      the VMBus connection is marked as ready for the resume event
398          *      (cf. check_ready_for_resume_event()).  The interrupt handler
399          *      of the VMBus driver and vmbus_chan_sched() can not run before
400          *      vmbus_bus_resume() has completed execution (cf. resume_noirq).
401          */
402         virt_store_mb(
403                 vmbus_connection.channels[channel->offermsg.child_relid],
404                 channel);
405 }
406
407 void vmbus_channel_unmap_relid(struct vmbus_channel *channel)
408 {
409         if (WARN_ON(channel->offermsg.child_relid >= MAX_CHANNEL_RELIDS))
410                 return;
411         WRITE_ONCE(
412                 vmbus_connection.channels[channel->offermsg.child_relid],
413                 NULL);
414 }
415
416 static void vmbus_release_relid(u32 relid)
417 {
418         struct vmbus_channel_relid_released msg;
419         int ret;
420
421         memset(&msg, 0, sizeof(struct vmbus_channel_relid_released));
422         msg.child_relid = relid;
423         msg.header.msgtype = CHANNELMSG_RELID_RELEASED;
424         ret = vmbus_post_msg(&msg, sizeof(struct vmbus_channel_relid_released),
425                              true);
426
427         trace_vmbus_release_relid(&msg, ret);
428 }
429
430 void hv_process_channel_removal(struct vmbus_channel *channel)
431 {
432         lockdep_assert_held(&vmbus_connection.channel_mutex);
433         BUG_ON(!channel->rescind);
434
435         /*
436          * hv_process_channel_removal() could find INVALID_RELID only for
437          * hv_sock channels.  See the inline comments in vmbus_onoffer().
438          */
439         WARN_ON(channel->offermsg.child_relid == INVALID_RELID &&
440                 !is_hvsock_channel(channel));
441
442         /*
443          * Upon suspend, an in-use hv_sock channel is removed from the array of
444          * channels and the relid is invalidated.  After hibernation, when the
445          * user-space appplication destroys the channel, it's unnecessary and
446          * unsafe to remove the channel from the array of channels.  See also
447          * the inline comments before the call of vmbus_release_relid() below.
448          */
449         if (channel->offermsg.child_relid != INVALID_RELID)
450                 vmbus_channel_unmap_relid(channel);
451
452         if (channel->primary_channel == NULL)
453                 list_del(&channel->listentry);
454         else
455                 list_del(&channel->sc_list);
456
457         /*
458          * If this is a "perf" channel, updates the hv_numa_map[] masks so that
459          * init_vp_index() can (re-)use the CPU.
460          */
461         if (hv_is_perf_channel(channel))
462                 hv_clear_alloced_cpu(channel->target_cpu);
463
464         /*
465          * Upon suspend, an in-use hv_sock channel is marked as "rescinded" and
466          * the relid is invalidated; after hibernation, when the user-space app
467          * destroys the channel, the relid is INVALID_RELID, and in this case
468          * it's unnecessary and unsafe to release the old relid, since the same
469          * relid can refer to a completely different channel now.
470          */
471         if (channel->offermsg.child_relid != INVALID_RELID)
472                 vmbus_release_relid(channel->offermsg.child_relid);
473
474         free_channel(channel);
475 }
476
477 void vmbus_free_channels(void)
478 {
479         struct vmbus_channel *channel, *tmp;
480
481         list_for_each_entry_safe(channel, tmp, &vmbus_connection.chn_list,
482                 listentry) {
483                 /* hv_process_channel_removal() needs this */
484                 channel->rescind = true;
485
486                 vmbus_device_unregister(channel->device_obj);
487         }
488 }
489
490 /* Note: the function can run concurrently for primary/sub channels. */
491 static void vmbus_add_channel_work(struct work_struct *work)
492 {
493         struct vmbus_channel *newchannel =
494                 container_of(work, struct vmbus_channel, add_channel_work);
495         struct vmbus_channel *primary_channel = newchannel->primary_channel;
496         int ret;
497
498         /*
499          * This state is used to indicate a successful open
500          * so that when we do close the channel normally, we
501          * can cleanup properly.
502          */
503         newchannel->state = CHANNEL_OPEN_STATE;
504
505         if (primary_channel != NULL) {
506                 /* newchannel is a sub-channel. */
507                 struct hv_device *dev = primary_channel->device_obj;
508
509                 if (vmbus_add_channel_kobj(dev, newchannel))
510                         goto err_deq_chan;
511
512                 if (primary_channel->sc_creation_callback != NULL)
513                         primary_channel->sc_creation_callback(newchannel);
514
515                 newchannel->probe_done = true;
516                 return;
517         }
518
519         /*
520          * Start the process of binding the primary channel to the driver
521          */
522         newchannel->device_obj = vmbus_device_create(
523                 &newchannel->offermsg.offer.if_type,
524                 &newchannel->offermsg.offer.if_instance,
525                 newchannel);
526         if (!newchannel->device_obj)
527                 goto err_deq_chan;
528
529         newchannel->device_obj->device_id = newchannel->device_id;
530         /*
531          * Add the new device to the bus. This will kick off device-driver
532          * binding which eventually invokes the device driver's AddDevice()
533          * method.
534          */
535         ret = vmbus_device_register(newchannel->device_obj);
536
537         if (ret != 0) {
538                 pr_err("unable to add child device object (relid %d)\n",
539                         newchannel->offermsg.child_relid);
540                 kfree(newchannel->device_obj);
541                 goto err_deq_chan;
542         }
543
544         newchannel->probe_done = true;
545         return;
546
547 err_deq_chan:
548         mutex_lock(&vmbus_connection.channel_mutex);
549
550         /*
551          * We need to set the flag, otherwise
552          * vmbus_onoffer_rescind() can be blocked.
553          */
554         newchannel->probe_done = true;
555
556         if (primary_channel == NULL)
557                 list_del(&newchannel->listentry);
558         else
559                 list_del(&newchannel->sc_list);
560
561         /* vmbus_process_offer() has mapped the channel. */
562         vmbus_channel_unmap_relid(newchannel);
563
564         mutex_unlock(&vmbus_connection.channel_mutex);
565
566         vmbus_release_relid(newchannel->offermsg.child_relid);
567
568         free_channel(newchannel);
569 }
570
571 /*
572  * vmbus_process_offer - Process the offer by creating a channel/device
573  * associated with this offer
574  */
575 static void vmbus_process_offer(struct vmbus_channel *newchannel)
576 {
577         struct vmbus_channel *channel;
578         struct workqueue_struct *wq;
579         bool fnew = true;
580
581         /*
582          * Synchronize vmbus_process_offer() and CPU hotplugging:
583          *
584          * CPU1                         CPU2
585          *
586          * [vmbus_process_offer()]      [Hot removal of the CPU]
587          *
588          * CPU_READ_LOCK                CPUS_WRITE_LOCK
589          * LOAD cpu_online_mask         SEARCH chn_list
590          * STORE target_cpu             LOAD target_cpu
591          * INSERT chn_list              STORE cpu_online_mask
592          * CPUS_READ_UNLOCK             CPUS_WRITE_UNLOCK
593          *
594          * Forbids: CPU1's LOAD from *not* seing CPU2's STORE &&
595          *              CPU2's SEARCH from *not* seeing CPU1's INSERT
596          *
597          * Forbids: CPU2's SEARCH from seeing CPU1's INSERT &&
598          *              CPU2's LOAD from *not* seing CPU1's STORE
599          */
600         cpus_read_lock();
601
602         /*
603          * Serializes the modifications of the chn_list list as well as
604          * the accesses to next_numa_node_id in init_vp_index().
605          */
606         mutex_lock(&vmbus_connection.channel_mutex);
607
608         list_for_each_entry(channel, &vmbus_connection.chn_list, listentry) {
609                 if (guid_equal(&channel->offermsg.offer.if_type,
610                                &newchannel->offermsg.offer.if_type) &&
611                     guid_equal(&channel->offermsg.offer.if_instance,
612                                &newchannel->offermsg.offer.if_instance)) {
613                         fnew = false;
614                         newchannel->primary_channel = channel;
615                         break;
616                 }
617         }
618
619         init_vp_index(newchannel);
620
621         /* Remember the channels that should be cleaned up upon suspend. */
622         if (is_hvsock_channel(newchannel) || is_sub_channel(newchannel))
623                 atomic_inc(&vmbus_connection.nr_chan_close_on_suspend);
624
625         /*
626          * Now that we have acquired the channel_mutex,
627          * we can release the potentially racing rescind thread.
628          */
629         atomic_dec(&vmbus_connection.offer_in_progress);
630
631         if (fnew) {
632                 list_add_tail(&newchannel->listentry,
633                               &vmbus_connection.chn_list);
634         } else {
635                 /*
636                  * Check to see if this is a valid sub-channel.
637                  */
638                 if (newchannel->offermsg.offer.sub_channel_index == 0) {
639                         mutex_unlock(&vmbus_connection.channel_mutex);
640                         cpus_read_unlock();
641                         /*
642                          * Don't call free_channel(), because newchannel->kobj
643                          * is not initialized yet.
644                          */
645                         kfree(newchannel);
646                         WARN_ON_ONCE(1);
647                         return;
648                 }
649                 /*
650                  * Process the sub-channel.
651                  */
652                 list_add_tail(&newchannel->sc_list, &channel->sc_list);
653         }
654
655         vmbus_channel_map_relid(newchannel);
656
657         mutex_unlock(&vmbus_connection.channel_mutex);
658         cpus_read_unlock();
659
660         /*
661          * vmbus_process_offer() mustn't call channel->sc_creation_callback()
662          * directly for sub-channels, because sc_creation_callback() ->
663          * vmbus_open() may never get the host's response to the
664          * OPEN_CHANNEL message (the host may rescind a channel at any time,
665          * e.g. in the case of hot removing a NIC), and vmbus_onoffer_rescind()
666          * may not wake up the vmbus_open() as it's blocked due to a non-zero
667          * vmbus_connection.offer_in_progress, and finally we have a deadlock.
668          *
669          * The above is also true for primary channels, if the related device
670          * drivers use sync probing mode by default.
671          *
672          * And, usually the handling of primary channels and sub-channels can
673          * depend on each other, so we should offload them to different
674          * workqueues to avoid possible deadlock, e.g. in sync-probing mode,
675          * NIC1's netvsc_subchan_work() can race with NIC2's netvsc_probe() ->
676          * rtnl_lock(), and causes deadlock: the former gets the rtnl_lock
677          * and waits for all the sub-channels to appear, but the latter
678          * can't get the rtnl_lock and this blocks the handling of
679          * sub-channels.
680          */
681         INIT_WORK(&newchannel->add_channel_work, vmbus_add_channel_work);
682         wq = fnew ? vmbus_connection.handle_primary_chan_wq :
683                     vmbus_connection.handle_sub_chan_wq;
684         queue_work(wq, &newchannel->add_channel_work);
685 }
686
687 /*
688  * Check if CPUs used by other channels of the same device.
689  * It should only be called by init_vp_index().
690  */
691 static bool hv_cpuself_used(u32 cpu, struct vmbus_channel *chn)
692 {
693         struct vmbus_channel *primary = chn->primary_channel;
694         struct vmbus_channel *sc;
695
696         lockdep_assert_held(&vmbus_connection.channel_mutex);
697
698         if (!primary)
699                 return false;
700
701         if (primary->target_cpu == cpu)
702                 return true;
703
704         list_for_each_entry(sc, &primary->sc_list, sc_list)
705                 if (sc != chn && sc->target_cpu == cpu)
706                         return true;
707
708         return false;
709 }
710
711 /*
712  * We use this state to statically distribute the channel interrupt load.
713  */
714 static int next_numa_node_id;
715
716 /*
717  * Starting with Win8, we can statically distribute the incoming
718  * channel interrupt load by binding a channel to VCPU.
719  *
720  * For pre-win8 hosts or non-performance critical channels we assign the
721  * VMBUS_CONNECT_CPU.
722  *
723  * Starting with win8, performance critical channels will be distributed
724  * evenly among all the available NUMA nodes.  Once the node is assigned,
725  * we will assign the CPU based on a simple round robin scheme.
726  */
727 static void init_vp_index(struct vmbus_channel *channel)
728 {
729         bool perf_chn = hv_is_perf_channel(channel);
730         u32 i, ncpu = num_online_cpus();
731         cpumask_var_t available_mask;
732         struct cpumask *alloced_mask;
733         u32 target_cpu;
734         int numa_node;
735
736         if ((vmbus_proto_version == VERSION_WS2008) ||
737             (vmbus_proto_version == VERSION_WIN7) || (!perf_chn) ||
738             !alloc_cpumask_var(&available_mask, GFP_KERNEL)) {
739                 /*
740                  * Prior to win8, all channel interrupts are
741                  * delivered on VMBUS_CONNECT_CPU.
742                  * Also if the channel is not a performance critical
743                  * channel, bind it to VMBUS_CONNECT_CPU.
744                  * In case alloc_cpumask_var() fails, bind it to
745                  * VMBUS_CONNECT_CPU.
746                  */
747                 channel->target_cpu = VMBUS_CONNECT_CPU;
748                 if (perf_chn)
749                         hv_set_alloced_cpu(VMBUS_CONNECT_CPU);
750                 return;
751         }
752
753         for (i = 1; i <= ncpu + 1; i++) {
754                 while (true) {
755                         numa_node = next_numa_node_id++;
756                         if (numa_node == nr_node_ids) {
757                                 next_numa_node_id = 0;
758                                 continue;
759                         }
760                         if (cpumask_empty(cpumask_of_node(numa_node)))
761                                 continue;
762                         break;
763                 }
764                 alloced_mask = &hv_context.hv_numa_map[numa_node];
765
766                 if (cpumask_weight(alloced_mask) ==
767                     cpumask_weight(cpumask_of_node(numa_node))) {
768                         /*
769                          * We have cycled through all the CPUs in the node;
770                          * reset the alloced map.
771                          */
772                         cpumask_clear(alloced_mask);
773                 }
774
775                 cpumask_xor(available_mask, alloced_mask,
776                             cpumask_of_node(numa_node));
777
778                 target_cpu = cpumask_first(available_mask);
779                 cpumask_set_cpu(target_cpu, alloced_mask);
780
781                 if (channel->offermsg.offer.sub_channel_index >= ncpu ||
782                     i > ncpu || !hv_cpuself_used(target_cpu, channel))
783                         break;
784         }
785
786         channel->target_cpu = target_cpu;
787
788         free_cpumask_var(available_mask);
789 }
790
791 #define UNLOAD_DELAY_UNIT_MS    10              /* 10 milliseconds */
792 #define UNLOAD_WAIT_MS          (100*1000)      /* 100 seconds */
793 #define UNLOAD_WAIT_LOOPS       (UNLOAD_WAIT_MS/UNLOAD_DELAY_UNIT_MS)
794 #define UNLOAD_MSG_MS           (5*1000)        /* Every 5 seconds */
795 #define UNLOAD_MSG_LOOPS        (UNLOAD_MSG_MS/UNLOAD_DELAY_UNIT_MS)
796
797 static void vmbus_wait_for_unload(void)
798 {
799         int cpu;
800         void *page_addr;
801         struct hv_message *msg;
802         struct vmbus_channel_message_header *hdr;
803         u32 message_type, i;
804
805         /*
806          * CHANNELMSG_UNLOAD_RESPONSE is always delivered to the CPU which was
807          * used for initial contact or to CPU0 depending on host version. When
808          * we're crashing on a different CPU let's hope that IRQ handler on
809          * the cpu which receives CHANNELMSG_UNLOAD_RESPONSE is still
810          * functional and vmbus_unload_response() will complete
811          * vmbus_connection.unload_event. If not, the last thing we can do is
812          * read message pages for all CPUs directly.
813          *
814          * Wait up to 100 seconds since an Azure host must writeback any dirty
815          * data in its disk cache before the VMbus UNLOAD request will
816          * complete. This flushing has been empirically observed to take up
817          * to 50 seconds in cases with a lot of dirty data, so allow additional
818          * leeway and for inaccuracies in mdelay(). But eventually time out so
819          * that the panic path can't get hung forever in case the response
820          * message isn't seen.
821          */
822         for (i = 1; i <= UNLOAD_WAIT_LOOPS; i++) {
823                 if (completion_done(&vmbus_connection.unload_event))
824                         goto completed;
825
826                 for_each_online_cpu(cpu) {
827                         struct hv_per_cpu_context *hv_cpu
828                                 = per_cpu_ptr(hv_context.cpu_context, cpu);
829
830                         page_addr = hv_cpu->synic_message_page;
831                         msg = (struct hv_message *)page_addr
832                                 + VMBUS_MESSAGE_SINT;
833
834                         message_type = READ_ONCE(msg->header.message_type);
835                         if (message_type == HVMSG_NONE)
836                                 continue;
837
838                         hdr = (struct vmbus_channel_message_header *)
839                                 msg->u.payload;
840
841                         if (hdr->msgtype == CHANNELMSG_UNLOAD_RESPONSE)
842                                 complete(&vmbus_connection.unload_event);
843
844                         vmbus_signal_eom(msg, message_type);
845                 }
846
847                 /*
848                  * Give a notice periodically so someone watching the
849                  * serial output won't think it is completely hung.
850                  */
851                 if (!(i % UNLOAD_MSG_LOOPS))
852                         pr_notice("Waiting for VMBus UNLOAD to complete\n");
853
854                 mdelay(UNLOAD_DELAY_UNIT_MS);
855         }
856         pr_err("Continuing even though VMBus UNLOAD did not complete\n");
857
858 completed:
859         /*
860          * We're crashing and already got the UNLOAD_RESPONSE, cleanup all
861          * maybe-pending messages on all CPUs to be able to receive new
862          * messages after we reconnect.
863          */
864         for_each_online_cpu(cpu) {
865                 struct hv_per_cpu_context *hv_cpu
866                         = per_cpu_ptr(hv_context.cpu_context, cpu);
867
868                 page_addr = hv_cpu->synic_message_page;
869                 msg = (struct hv_message *)page_addr + VMBUS_MESSAGE_SINT;
870                 msg->header.message_type = HVMSG_NONE;
871         }
872 }
873
874 /*
875  * vmbus_unload_response - Handler for the unload response.
876  */
877 static void vmbus_unload_response(struct vmbus_channel_message_header *hdr)
878 {
879         /*
880          * This is a global event; just wakeup the waiting thread.
881          * Once we successfully unload, we can cleanup the monitor state.
882          *
883          * NB.  A malicious or compromised Hyper-V could send a spurious
884          * message of type CHANNELMSG_UNLOAD_RESPONSE, and trigger a call
885          * of the complete() below.  Make sure that unload_event has been
886          * initialized by the time this complete() is executed.
887          */
888         complete(&vmbus_connection.unload_event);
889 }
890
891 void vmbus_initiate_unload(bool crash)
892 {
893         struct vmbus_channel_message_header hdr;
894
895         if (xchg(&vmbus_connection.conn_state, DISCONNECTED) == DISCONNECTED)
896                 return;
897
898         /* Pre-Win2012R2 hosts don't support reconnect */
899         if (vmbus_proto_version < VERSION_WIN8_1)
900                 return;
901
902         reinit_completion(&vmbus_connection.unload_event);
903         memset(&hdr, 0, sizeof(struct vmbus_channel_message_header));
904         hdr.msgtype = CHANNELMSG_UNLOAD;
905         vmbus_post_msg(&hdr, sizeof(struct vmbus_channel_message_header),
906                        !crash);
907
908         /*
909          * vmbus_initiate_unload() is also called on crash and the crash can be
910          * happening in an interrupt context, where scheduling is impossible.
911          */
912         if (!crash)
913                 wait_for_completion(&vmbus_connection.unload_event);
914         else
915                 vmbus_wait_for_unload();
916 }
917
918 static void check_ready_for_resume_event(void)
919 {
920         /*
921          * If all the old primary channels have been fixed up, then it's safe
922          * to resume.
923          */
924         if (atomic_dec_and_test(&vmbus_connection.nr_chan_fixup_on_resume))
925                 complete(&vmbus_connection.ready_for_resume_event);
926 }
927
928 static void vmbus_setup_channel_state(struct vmbus_channel *channel,
929                                       struct vmbus_channel_offer_channel *offer)
930 {
931         /*
932          * Setup state for signalling the host.
933          */
934         channel->sig_event = VMBUS_EVENT_CONNECTION_ID;
935
936         if (vmbus_proto_version != VERSION_WS2008) {
937                 channel->is_dedicated_interrupt =
938                                 (offer->is_dedicated_interrupt != 0);
939                 channel->sig_event = offer->connection_id;
940         }
941
942         memcpy(&channel->offermsg, offer,
943                sizeof(struct vmbus_channel_offer_channel));
944         channel->monitor_grp = (u8)offer->monitorid / 32;
945         channel->monitor_bit = (u8)offer->monitorid % 32;
946         channel->device_id = hv_get_dev_type(channel);
947 }
948
949 /*
950  * find_primary_channel_by_offer - Get the channel object given the new offer.
951  * This is only used in the resume path of hibernation.
952  */
953 static struct vmbus_channel *
954 find_primary_channel_by_offer(const struct vmbus_channel_offer_channel *offer)
955 {
956         struct vmbus_channel *channel = NULL, *iter;
957         const guid_t *inst1, *inst2;
958
959         /* Ignore sub-channel offers. */
960         if (offer->offer.sub_channel_index != 0)
961                 return NULL;
962
963         mutex_lock(&vmbus_connection.channel_mutex);
964
965         list_for_each_entry(iter, &vmbus_connection.chn_list, listentry) {
966                 inst1 = &iter->offermsg.offer.if_instance;
967                 inst2 = &offer->offer.if_instance;
968
969                 if (guid_equal(inst1, inst2)) {
970                         channel = iter;
971                         break;
972                 }
973         }
974
975         mutex_unlock(&vmbus_connection.channel_mutex);
976
977         return channel;
978 }
979
980 static bool vmbus_is_valid_device(const guid_t *guid)
981 {
982         u16 i;
983
984         if (!hv_is_isolation_supported())
985                 return true;
986
987         for (i = 0; i < ARRAY_SIZE(vmbus_devs); i++) {
988                 if (guid_equal(guid, &vmbus_devs[i].guid))
989                         return vmbus_devs[i].allowed_in_isolated;
990         }
991         return false;
992 }
993
994 /*
995  * vmbus_onoffer - Handler for channel offers from vmbus in parent partition.
996  *
997  */
998 static void vmbus_onoffer(struct vmbus_channel_message_header *hdr)
999 {
1000         struct vmbus_channel_offer_channel *offer;
1001         struct vmbus_channel *oldchannel, *newchannel;
1002         size_t offer_sz;
1003
1004         offer = (struct vmbus_channel_offer_channel *)hdr;
1005
1006         trace_vmbus_onoffer(offer);
1007
1008         if (!vmbus_is_valid_device(&offer->offer.if_type)) {
1009                 pr_err_ratelimited("Invalid offer %d from the host supporting isolation\n",
1010                                    offer->child_relid);
1011                 atomic_dec(&vmbus_connection.offer_in_progress);
1012                 return;
1013         }
1014
1015         oldchannel = find_primary_channel_by_offer(offer);
1016
1017         if (oldchannel != NULL) {
1018                 /*
1019                  * We're resuming from hibernation: all the sub-channel and
1020                  * hv_sock channels we had before the hibernation should have
1021                  * been cleaned up, and now we must be seeing a re-offered
1022                  * primary channel that we had before the hibernation.
1023                  */
1024
1025                 /*
1026                  * { Initially: channel relid = INVALID_RELID,
1027                  *              channels[valid_relid] = NULL }
1028                  *
1029                  * CPU1                                 CPU2
1030                  *
1031                  * [vmbus_onoffer()]                    [vmbus_device_release()]
1032                  *
1033                  * LOCK channel_mutex                   LOCK channel_mutex
1034                  * STORE channel relid = valid_relid    LOAD r1 = channel relid
1035                  * MAP_RELID channel                    if (r1 != INVALID_RELID)
1036                  * UNLOCK channel_mutex                   UNMAP_RELID channel
1037                  *                                      UNLOCK channel_mutex
1038                  *
1039                  * Forbids: r1 == valid_relid &&
1040                  *              channels[valid_relid] == channel
1041                  *
1042                  * Note.  r1 can be INVALID_RELID only for an hv_sock channel.
1043                  * None of the hv_sock channels which were present before the
1044                  * suspend are re-offered upon the resume.  See the WARN_ON()
1045                  * in hv_process_channel_removal().
1046                  */
1047                 mutex_lock(&vmbus_connection.channel_mutex);
1048
1049                 atomic_dec(&vmbus_connection.offer_in_progress);
1050
1051                 WARN_ON(oldchannel->offermsg.child_relid != INVALID_RELID);
1052                 /* Fix up the relid. */
1053                 oldchannel->offermsg.child_relid = offer->child_relid;
1054
1055                 offer_sz = sizeof(*offer);
1056                 if (memcmp(offer, &oldchannel->offermsg, offer_sz) != 0) {
1057                         /*
1058                          * This is not an error, since the host can also change
1059                          * the other field(s) of the offer, e.g. on WS RS5
1060                          * (Build 17763), the offer->connection_id of the
1061                          * Mellanox VF vmbus device can change when the host
1062                          * reoffers the device upon resume.
1063                          */
1064                         pr_debug("vmbus offer changed: relid=%d\n",
1065                                  offer->child_relid);
1066
1067                         print_hex_dump_debug("Old vmbus offer: ",
1068                                              DUMP_PREFIX_OFFSET, 16, 4,
1069                                              &oldchannel->offermsg, offer_sz,
1070                                              false);
1071                         print_hex_dump_debug("New vmbus offer: ",
1072                                              DUMP_PREFIX_OFFSET, 16, 4,
1073                                              offer, offer_sz, false);
1074
1075                         /* Fix up the old channel. */
1076                         vmbus_setup_channel_state(oldchannel, offer);
1077                 }
1078
1079                 /* Add the channel back to the array of channels. */
1080                 vmbus_channel_map_relid(oldchannel);
1081                 check_ready_for_resume_event();
1082
1083                 mutex_unlock(&vmbus_connection.channel_mutex);
1084                 return;
1085         }
1086
1087         /* Allocate the channel object and save this offer. */
1088         newchannel = alloc_channel();
1089         if (!newchannel) {
1090                 vmbus_release_relid(offer->child_relid);
1091                 atomic_dec(&vmbus_connection.offer_in_progress);
1092                 pr_err("Unable to allocate channel object\n");
1093                 return;
1094         }
1095
1096         vmbus_setup_channel_state(newchannel, offer);
1097
1098         vmbus_process_offer(newchannel);
1099 }
1100
1101 static void check_ready_for_suspend_event(void)
1102 {
1103         /*
1104          * If all the sub-channels or hv_sock channels have been cleaned up,
1105          * then it's safe to suspend.
1106          */
1107         if (atomic_dec_and_test(&vmbus_connection.nr_chan_close_on_suspend))
1108                 complete(&vmbus_connection.ready_for_suspend_event);
1109 }
1110
1111 /*
1112  * vmbus_onoffer_rescind - Rescind offer handler.
1113  *
1114  * We queue a work item to process this offer synchronously
1115  */
1116 static void vmbus_onoffer_rescind(struct vmbus_channel_message_header *hdr)
1117 {
1118         struct vmbus_channel_rescind_offer *rescind;
1119         struct vmbus_channel *channel;
1120         struct device *dev;
1121         bool clean_up_chan_for_suspend;
1122
1123         rescind = (struct vmbus_channel_rescind_offer *)hdr;
1124
1125         trace_vmbus_onoffer_rescind(rescind);
1126
1127         /*
1128          * The offer msg and the corresponding rescind msg
1129          * from the host are guranteed to be ordered -
1130          * offer comes in first and then the rescind.
1131          * Since we process these events in work elements,
1132          * and with preemption, we may end up processing
1133          * the events out of order.  We rely on the synchronization
1134          * provided by offer_in_progress and by channel_mutex for
1135          * ordering these events:
1136          *
1137          * { Initially: offer_in_progress = 1 }
1138          *
1139          * CPU1                         CPU2
1140          *
1141          * [vmbus_onoffer()]            [vmbus_onoffer_rescind()]
1142          *
1143          * LOCK channel_mutex           WAIT_ON offer_in_progress == 0
1144          * DECREMENT offer_in_progress  LOCK channel_mutex
1145          * STORE channels[]             LOAD channels[]
1146          * UNLOCK channel_mutex         UNLOCK channel_mutex
1147          *
1148          * Forbids: CPU2's LOAD from *not* seeing CPU1's STORE
1149          */
1150
1151         while (atomic_read(&vmbus_connection.offer_in_progress) != 0) {
1152                 /*
1153                  * We wait here until any channel offer is currently
1154                  * being processed.
1155                  */
1156                 msleep(1);
1157         }
1158
1159         mutex_lock(&vmbus_connection.channel_mutex);
1160         channel = relid2channel(rescind->child_relid);
1161         if (channel != NULL) {
1162                 /*
1163                  * Guarantee that no other instance of vmbus_onoffer_rescind()
1164                  * has got a reference to the channel object.  Synchronize on
1165                  * &vmbus_connection.channel_mutex.
1166                  */
1167                 if (channel->rescind_ref) {
1168                         mutex_unlock(&vmbus_connection.channel_mutex);
1169                         return;
1170                 }
1171                 channel->rescind_ref = true;
1172         }
1173         mutex_unlock(&vmbus_connection.channel_mutex);
1174
1175         if (channel == NULL) {
1176                 /*
1177                  * We failed in processing the offer message;
1178                  * we would have cleaned up the relid in that
1179                  * failure path.
1180                  */
1181                 return;
1182         }
1183
1184         clean_up_chan_for_suspend = is_hvsock_channel(channel) ||
1185                                     is_sub_channel(channel);
1186         /*
1187          * Before setting channel->rescind in vmbus_rescind_cleanup(), we
1188          * should make sure the channel callback is not running any more.
1189          */
1190         vmbus_reset_channel_cb(channel);
1191
1192         /*
1193          * Now wait for offer handling to complete.
1194          */
1195         vmbus_rescind_cleanup(channel);
1196         while (READ_ONCE(channel->probe_done) == false) {
1197                 /*
1198                  * We wait here until any channel offer is currently
1199                  * being processed.
1200                  */
1201                 msleep(1);
1202         }
1203
1204         /*
1205          * At this point, the rescind handling can proceed safely.
1206          */
1207
1208         if (channel->device_obj) {
1209                 if (channel->chn_rescind_callback) {
1210                         channel->chn_rescind_callback(channel);
1211
1212                         if (clean_up_chan_for_suspend)
1213                                 check_ready_for_suspend_event();
1214
1215                         return;
1216                 }
1217                 /*
1218                  * We will have to unregister this device from the
1219                  * driver core.
1220                  */
1221                 dev = get_device(&channel->device_obj->device);
1222                 if (dev) {
1223                         vmbus_device_unregister(channel->device_obj);
1224                         put_device(dev);
1225                 }
1226         } else if (channel->primary_channel != NULL) {
1227                 /*
1228                  * Sub-channel is being rescinded. Following is the channel
1229                  * close sequence when initiated from the driveri (refer to
1230                  * vmbus_close() for details):
1231                  * 1. Close all sub-channels first
1232                  * 2. Then close the primary channel.
1233                  */
1234                 mutex_lock(&vmbus_connection.channel_mutex);
1235                 if (channel->state == CHANNEL_OPEN_STATE) {
1236                         /*
1237                          * The channel is currently not open;
1238                          * it is safe for us to cleanup the channel.
1239                          */
1240                         hv_process_channel_removal(channel);
1241                 } else {
1242                         complete(&channel->rescind_event);
1243                 }
1244                 mutex_unlock(&vmbus_connection.channel_mutex);
1245         }
1246
1247         /* The "channel" may have been freed. Do not access it any longer. */
1248
1249         if (clean_up_chan_for_suspend)
1250                 check_ready_for_suspend_event();
1251 }
1252
1253 void vmbus_hvsock_device_unregister(struct vmbus_channel *channel)
1254 {
1255         BUG_ON(!is_hvsock_channel(channel));
1256
1257         /* We always get a rescind msg when a connection is closed. */
1258         while (!READ_ONCE(channel->probe_done) || !READ_ONCE(channel->rescind))
1259                 msleep(1);
1260
1261         vmbus_device_unregister(channel->device_obj);
1262 }
1263 EXPORT_SYMBOL_GPL(vmbus_hvsock_device_unregister);
1264
1265
1266 /*
1267  * vmbus_onoffers_delivered -
1268  * This is invoked when all offers have been delivered.
1269  *
1270  * Nothing to do here.
1271  */
1272 static void vmbus_onoffers_delivered(
1273                         struct vmbus_channel_message_header *hdr)
1274 {
1275 }
1276
1277 /*
1278  * vmbus_onopen_result - Open result handler.
1279  *
1280  * This is invoked when we received a response to our channel open request.
1281  * Find the matching request, copy the response and signal the requesting
1282  * thread.
1283  */
1284 static void vmbus_onopen_result(struct vmbus_channel_message_header *hdr)
1285 {
1286         struct vmbus_channel_open_result *result;
1287         struct vmbus_channel_msginfo *msginfo;
1288         struct vmbus_channel_message_header *requestheader;
1289         struct vmbus_channel_open_channel *openmsg;
1290         unsigned long flags;
1291
1292         result = (struct vmbus_channel_open_result *)hdr;
1293
1294         trace_vmbus_onopen_result(result);
1295
1296         /*
1297          * Find the open msg, copy the result and signal/unblock the wait event
1298          */
1299         spin_lock_irqsave(&vmbus_connection.channelmsg_lock, flags);
1300
1301         list_for_each_entry(msginfo, &vmbus_connection.chn_msg_list,
1302                                 msglistentry) {
1303                 requestheader =
1304                         (struct vmbus_channel_message_header *)msginfo->msg;
1305
1306                 if (requestheader->msgtype == CHANNELMSG_OPENCHANNEL) {
1307                         openmsg =
1308                         (struct vmbus_channel_open_channel *)msginfo->msg;
1309                         if (openmsg->child_relid == result->child_relid &&
1310                             openmsg->openid == result->openid) {
1311                                 memcpy(&msginfo->response.open_result,
1312                                        result,
1313                                        sizeof(
1314                                         struct vmbus_channel_open_result));
1315                                 complete(&msginfo->waitevent);
1316                                 break;
1317                         }
1318                 }
1319         }
1320         spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
1321 }
1322
1323 /*
1324  * vmbus_ongpadl_created - GPADL created handler.
1325  *
1326  * This is invoked when we received a response to our gpadl create request.
1327  * Find the matching request, copy the response and signal the requesting
1328  * thread.
1329  */
1330 static void vmbus_ongpadl_created(struct vmbus_channel_message_header *hdr)
1331 {
1332         struct vmbus_channel_gpadl_created *gpadlcreated;
1333         struct vmbus_channel_msginfo *msginfo;
1334         struct vmbus_channel_message_header *requestheader;
1335         struct vmbus_channel_gpadl_header *gpadlheader;
1336         unsigned long flags;
1337
1338         gpadlcreated = (struct vmbus_channel_gpadl_created *)hdr;
1339
1340         trace_vmbus_ongpadl_created(gpadlcreated);
1341
1342         /*
1343          * Find the establish msg, copy the result and signal/unblock the wait
1344          * event
1345          */
1346         spin_lock_irqsave(&vmbus_connection.channelmsg_lock, flags);
1347
1348         list_for_each_entry(msginfo, &vmbus_connection.chn_msg_list,
1349                                 msglistentry) {
1350                 requestheader =
1351                         (struct vmbus_channel_message_header *)msginfo->msg;
1352
1353                 if (requestheader->msgtype == CHANNELMSG_GPADL_HEADER) {
1354                         gpadlheader =
1355                         (struct vmbus_channel_gpadl_header *)requestheader;
1356
1357                         if ((gpadlcreated->child_relid ==
1358                              gpadlheader->child_relid) &&
1359                             (gpadlcreated->gpadl == gpadlheader->gpadl)) {
1360                                 memcpy(&msginfo->response.gpadl_created,
1361                                        gpadlcreated,
1362                                        sizeof(
1363                                         struct vmbus_channel_gpadl_created));
1364                                 complete(&msginfo->waitevent);
1365                                 break;
1366                         }
1367                 }
1368         }
1369         spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
1370 }
1371
1372 /*
1373  * vmbus_onmodifychannel_response - Modify Channel response handler.
1374  *
1375  * This is invoked when we received a response to our channel modify request.
1376  * Find the matching request, copy the response and signal the requesting thread.
1377  */
1378 static void vmbus_onmodifychannel_response(struct vmbus_channel_message_header *hdr)
1379 {
1380         struct vmbus_channel_modifychannel_response *response;
1381         struct vmbus_channel_msginfo *msginfo;
1382         unsigned long flags;
1383
1384         response = (struct vmbus_channel_modifychannel_response *)hdr;
1385
1386         trace_vmbus_onmodifychannel_response(response);
1387
1388         /*
1389          * Find the modify msg, copy the response and signal/unblock the wait event.
1390          */
1391         spin_lock_irqsave(&vmbus_connection.channelmsg_lock, flags);
1392
1393         list_for_each_entry(msginfo, &vmbus_connection.chn_msg_list, msglistentry) {
1394                 struct vmbus_channel_message_header *responseheader =
1395                                 (struct vmbus_channel_message_header *)msginfo->msg;
1396
1397                 if (responseheader->msgtype == CHANNELMSG_MODIFYCHANNEL) {
1398                         struct vmbus_channel_modifychannel *modifymsg;
1399
1400                         modifymsg = (struct vmbus_channel_modifychannel *)msginfo->msg;
1401                         if (modifymsg->child_relid == response->child_relid) {
1402                                 memcpy(&msginfo->response.modify_response, response,
1403                                        sizeof(*response));
1404                                 complete(&msginfo->waitevent);
1405                                 break;
1406                         }
1407                 }
1408         }
1409         spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
1410 }
1411
1412 /*
1413  * vmbus_ongpadl_torndown - GPADL torndown handler.
1414  *
1415  * This is invoked when we received a response to our gpadl teardown request.
1416  * Find the matching request, copy the response and signal the requesting
1417  * thread.
1418  */
1419 static void vmbus_ongpadl_torndown(
1420                         struct vmbus_channel_message_header *hdr)
1421 {
1422         struct vmbus_channel_gpadl_torndown *gpadl_torndown;
1423         struct vmbus_channel_msginfo *msginfo;
1424         struct vmbus_channel_message_header *requestheader;
1425         struct vmbus_channel_gpadl_teardown *gpadl_teardown;
1426         unsigned long flags;
1427
1428         gpadl_torndown = (struct vmbus_channel_gpadl_torndown *)hdr;
1429
1430         trace_vmbus_ongpadl_torndown(gpadl_torndown);
1431
1432         /*
1433          * Find the open msg, copy the result and signal/unblock the wait event
1434          */
1435         spin_lock_irqsave(&vmbus_connection.channelmsg_lock, flags);
1436
1437         list_for_each_entry(msginfo, &vmbus_connection.chn_msg_list,
1438                                 msglistentry) {
1439                 requestheader =
1440                         (struct vmbus_channel_message_header *)msginfo->msg;
1441
1442                 if (requestheader->msgtype == CHANNELMSG_GPADL_TEARDOWN) {
1443                         gpadl_teardown =
1444                         (struct vmbus_channel_gpadl_teardown *)requestheader;
1445
1446                         if (gpadl_torndown->gpadl == gpadl_teardown->gpadl) {
1447                                 memcpy(&msginfo->response.gpadl_torndown,
1448                                        gpadl_torndown,
1449                                        sizeof(
1450                                         struct vmbus_channel_gpadl_torndown));
1451                                 complete(&msginfo->waitevent);
1452                                 break;
1453                         }
1454                 }
1455         }
1456         spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
1457 }
1458
1459 /*
1460  * vmbus_onversion_response - Version response handler
1461  *
1462  * This is invoked when we received a response to our initiate contact request.
1463  * Find the matching request, copy the response and signal the requesting
1464  * thread.
1465  */
1466 static void vmbus_onversion_response(
1467                 struct vmbus_channel_message_header *hdr)
1468 {
1469         struct vmbus_channel_msginfo *msginfo;
1470         struct vmbus_channel_message_header *requestheader;
1471         struct vmbus_channel_version_response *version_response;
1472         unsigned long flags;
1473
1474         version_response = (struct vmbus_channel_version_response *)hdr;
1475
1476         trace_vmbus_onversion_response(version_response);
1477
1478         spin_lock_irqsave(&vmbus_connection.channelmsg_lock, flags);
1479
1480         list_for_each_entry(msginfo, &vmbus_connection.chn_msg_list,
1481                                 msglistentry) {
1482                 requestheader =
1483                         (struct vmbus_channel_message_header *)msginfo->msg;
1484
1485                 if (requestheader->msgtype ==
1486                     CHANNELMSG_INITIATE_CONTACT) {
1487                         memcpy(&msginfo->response.version_response,
1488                               version_response,
1489                               sizeof(struct vmbus_channel_version_response));
1490                         complete(&msginfo->waitevent);
1491                 }
1492         }
1493         spin_unlock_irqrestore(&vmbus_connection.channelmsg_lock, flags);
1494 }
1495
1496 /* Channel message dispatch table */
1497 const struct vmbus_channel_message_table_entry
1498 channel_message_table[CHANNELMSG_COUNT] = {
1499         { CHANNELMSG_INVALID,                   0, NULL, 0},
1500         { CHANNELMSG_OFFERCHANNEL,              0, vmbus_onoffer,
1501                 sizeof(struct vmbus_channel_offer_channel)},
1502         { CHANNELMSG_RESCIND_CHANNELOFFER,      0, vmbus_onoffer_rescind,
1503                 sizeof(struct vmbus_channel_rescind_offer) },
1504         { CHANNELMSG_REQUESTOFFERS,             0, NULL, 0},
1505         { CHANNELMSG_ALLOFFERS_DELIVERED,       1, vmbus_onoffers_delivered, 0},
1506         { CHANNELMSG_OPENCHANNEL,               0, NULL, 0},
1507         { CHANNELMSG_OPENCHANNEL_RESULT,        1, vmbus_onopen_result,
1508                 sizeof(struct vmbus_channel_open_result)},
1509         { CHANNELMSG_CLOSECHANNEL,              0, NULL, 0},
1510         { CHANNELMSG_GPADL_HEADER,              0, NULL, 0},
1511         { CHANNELMSG_GPADL_BODY,                0, NULL, 0},
1512         { CHANNELMSG_GPADL_CREATED,             1, vmbus_ongpadl_created,
1513                 sizeof(struct vmbus_channel_gpadl_created)},
1514         { CHANNELMSG_GPADL_TEARDOWN,            0, NULL, 0},
1515         { CHANNELMSG_GPADL_TORNDOWN,            1, vmbus_ongpadl_torndown,
1516                 sizeof(struct vmbus_channel_gpadl_torndown) },
1517         { CHANNELMSG_RELID_RELEASED,            0, NULL, 0},
1518         { CHANNELMSG_INITIATE_CONTACT,          0, NULL, 0},
1519         { CHANNELMSG_VERSION_RESPONSE,          1, vmbus_onversion_response,
1520                 sizeof(struct vmbus_channel_version_response)},
1521         { CHANNELMSG_UNLOAD,                    0, NULL, 0},
1522         { CHANNELMSG_UNLOAD_RESPONSE,           1, vmbus_unload_response, 0},
1523         { CHANNELMSG_18,                        0, NULL, 0},
1524         { CHANNELMSG_19,                        0, NULL, 0},
1525         { CHANNELMSG_20,                        0, NULL, 0},
1526         { CHANNELMSG_TL_CONNECT_REQUEST,        0, NULL, 0},
1527         { CHANNELMSG_MODIFYCHANNEL,             0, NULL, 0},
1528         { CHANNELMSG_TL_CONNECT_RESULT,         0, NULL, 0},
1529         { CHANNELMSG_MODIFYCHANNEL_RESPONSE,    1, vmbus_onmodifychannel_response,
1530                 sizeof(struct vmbus_channel_modifychannel_response)},
1531 };
1532
1533 /*
1534  * vmbus_onmessage - Handler for channel protocol messages.
1535  *
1536  * This is invoked in the vmbus worker thread context.
1537  */
1538 void vmbus_onmessage(struct vmbus_channel_message_header *hdr)
1539 {
1540         trace_vmbus_on_message(hdr);
1541
1542         /*
1543          * vmbus_on_msg_dpc() makes sure the hdr->msgtype here can not go
1544          * out of bound and the message_handler pointer can not be NULL.
1545          */
1546         channel_message_table[hdr->msgtype].message_handler(hdr);
1547 }
1548
1549 /*
1550  * vmbus_request_offers - Send a request to get all our pending offers.
1551  */
1552 int vmbus_request_offers(void)
1553 {
1554         struct vmbus_channel_message_header *msg;
1555         struct vmbus_channel_msginfo *msginfo;
1556         int ret;
1557
1558         msginfo = kmalloc(sizeof(*msginfo) +
1559                           sizeof(struct vmbus_channel_message_header),
1560                           GFP_KERNEL);
1561         if (!msginfo)
1562                 return -ENOMEM;
1563
1564         msg = (struct vmbus_channel_message_header *)msginfo->msg;
1565
1566         msg->msgtype = CHANNELMSG_REQUESTOFFERS;
1567
1568         ret = vmbus_post_msg(msg, sizeof(struct vmbus_channel_message_header),
1569                              true);
1570
1571         trace_vmbus_request_offers(ret);
1572
1573         if (ret != 0) {
1574                 pr_err("Unable to request offers - %d\n", ret);
1575
1576                 goto cleanup;
1577         }
1578
1579 cleanup:
1580         kfree(msginfo);
1581
1582         return ret;
1583 }
1584
1585 static void invoke_sc_cb(struct vmbus_channel *primary_channel)
1586 {
1587         struct list_head *cur, *tmp;
1588         struct vmbus_channel *cur_channel;
1589
1590         if (primary_channel->sc_creation_callback == NULL)
1591                 return;
1592
1593         list_for_each_safe(cur, tmp, &primary_channel->sc_list) {
1594                 cur_channel = list_entry(cur, struct vmbus_channel, sc_list);
1595
1596                 primary_channel->sc_creation_callback(cur_channel);
1597         }
1598 }
1599
1600 void vmbus_set_sc_create_callback(struct vmbus_channel *primary_channel,
1601                                 void (*sc_cr_cb)(struct vmbus_channel *new_sc))
1602 {
1603         primary_channel->sc_creation_callback = sc_cr_cb;
1604 }
1605 EXPORT_SYMBOL_GPL(vmbus_set_sc_create_callback);
1606
1607 bool vmbus_are_subchannels_present(struct vmbus_channel *primary)
1608 {
1609         bool ret;
1610
1611         ret = !list_empty(&primary->sc_list);
1612
1613         if (ret) {
1614                 /*
1615                  * Invoke the callback on sub-channel creation.
1616                  * This will present a uniform interface to the
1617                  * clients.
1618                  */
1619                 invoke_sc_cb(primary);
1620         }
1621
1622         return ret;
1623 }
1624 EXPORT_SYMBOL_GPL(vmbus_are_subchannels_present);
1625
1626 void vmbus_set_chn_rescind_callback(struct vmbus_channel *channel,
1627                 void (*chn_rescind_cb)(struct vmbus_channel *))
1628 {
1629         channel->chn_rescind_callback = chn_rescind_cb;
1630 }
1631 EXPORT_SYMBOL_GPL(vmbus_set_chn_rescind_callback);