Target/iser: Fix iscsit_accept_np and rdma_cm racy flow
[platform/adaptation/renesas_rcar/renesas_kernel.git] / drivers / infiniband / ulp / isert / ib_isert.c
1 /*******************************************************************************
2  * This file contains iSCSI extentions for RDMA (iSER) Verbs
3  *
4  * (c) Copyright 2013 Datera, Inc.
5  *
6  * Nicholas A. Bellinger <nab@linux-iscsi.org>
7  *
8  * This program is free software; you can redistribute it and/or modify
9  * it under the terms of the GNU General Public License as published by
10  * the Free Software Foundation; either version 2 of the License, or
11  * (at your option) any later version.
12  *
13  * This program is distributed in the hope that it will be useful,
14  * but WITHOUT ANY WARRANTY; without even the implied warranty of
15  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16  * GNU General Public License for more details.
17  ****************************************************************************/
18
19 #include <linux/string.h>
20 #include <linux/module.h>
21 #include <linux/scatterlist.h>
22 #include <linux/socket.h>
23 #include <linux/in.h>
24 #include <linux/in6.h>
25 #include <linux/llist.h>
26 #include <rdma/ib_verbs.h>
27 #include <rdma/rdma_cm.h>
28 #include <target/target_core_base.h>
29 #include <target/target_core_fabric.h>
30 #include <target/iscsi/iscsi_transport.h>
31 #include <linux/semaphore.h>
32
33 #include "isert_proto.h"
34 #include "ib_isert.h"
35
36 #define ISERT_MAX_CONN          8
37 #define ISER_MAX_RX_CQ_LEN      (ISERT_QP_MAX_RECV_DTOS * ISERT_MAX_CONN)
38 #define ISER_MAX_TX_CQ_LEN      (ISERT_QP_MAX_REQ_DTOS  * ISERT_MAX_CONN)
39
40 static DEFINE_MUTEX(device_list_mutex);
41 static LIST_HEAD(device_list);
42 static struct workqueue_struct *isert_rx_wq;
43 static struct workqueue_struct *isert_comp_wq;
44
45 static void
46 isert_unmap_cmd(struct isert_cmd *isert_cmd, struct isert_conn *isert_conn);
47 static int
48 isert_map_rdma(struct iscsi_conn *conn, struct iscsi_cmd *cmd,
49                struct isert_rdma_wr *wr);
50 static void
51 isert_unreg_rdma(struct isert_cmd *isert_cmd, struct isert_conn *isert_conn);
52 static int
53 isert_reg_rdma(struct iscsi_conn *conn, struct iscsi_cmd *cmd,
54                struct isert_rdma_wr *wr);
55
56 static void
57 isert_qp_event_callback(struct ib_event *e, void *context)
58 {
59         struct isert_conn *isert_conn = (struct isert_conn *)context;
60
61         pr_err("isert_qp_event_callback event: %d\n", e->event);
62         switch (e->event) {
63         case IB_EVENT_COMM_EST:
64                 rdma_notify(isert_conn->conn_cm_id, IB_EVENT_COMM_EST);
65                 break;
66         case IB_EVENT_QP_LAST_WQE_REACHED:
67                 pr_warn("Reached TX IB_EVENT_QP_LAST_WQE_REACHED:\n");
68                 break;
69         default:
70                 break;
71         }
72 }
73
74 static int
75 isert_query_device(struct ib_device *ib_dev, struct ib_device_attr *devattr)
76 {
77         int ret;
78
79         ret = ib_query_device(ib_dev, devattr);
80         if (ret) {
81                 pr_err("ib_query_device() failed: %d\n", ret);
82                 return ret;
83         }
84         pr_debug("devattr->max_sge: %d\n", devattr->max_sge);
85         pr_debug("devattr->max_sge_rd: %d\n", devattr->max_sge_rd);
86
87         return 0;
88 }
89
90 static int
91 isert_conn_setup_qp(struct isert_conn *isert_conn, struct rdma_cm_id *cma_id)
92 {
93         struct isert_device *device = isert_conn->conn_device;
94         struct ib_qp_init_attr attr;
95         int ret, index, min_index = 0;
96
97         mutex_lock(&device_list_mutex);
98         for (index = 0; index < device->cqs_used; index++)
99                 if (device->cq_active_qps[index] <
100                     device->cq_active_qps[min_index])
101                         min_index = index;
102         device->cq_active_qps[min_index]++;
103         pr_debug("isert_conn_setup_qp: Using min_index: %d\n", min_index);
104         mutex_unlock(&device_list_mutex);
105
106         memset(&attr, 0, sizeof(struct ib_qp_init_attr));
107         attr.event_handler = isert_qp_event_callback;
108         attr.qp_context = isert_conn;
109         attr.send_cq = device->dev_tx_cq[min_index];
110         attr.recv_cq = device->dev_rx_cq[min_index];
111         attr.cap.max_send_wr = ISERT_QP_MAX_REQ_DTOS;
112         attr.cap.max_recv_wr = ISERT_QP_MAX_RECV_DTOS;
113         /*
114          * FIXME: Use devattr.max_sge - 2 for max_send_sge as
115          * work-around for RDMA_READ..
116          */
117         attr.cap.max_send_sge = device->dev_attr.max_sge - 2;
118         isert_conn->max_sge = attr.cap.max_send_sge;
119
120         attr.cap.max_recv_sge = 1;
121         attr.sq_sig_type = IB_SIGNAL_REQ_WR;
122         attr.qp_type = IB_QPT_RC;
123
124         pr_debug("isert_conn_setup_qp cma_id->device: %p\n",
125                  cma_id->device);
126         pr_debug("isert_conn_setup_qp conn_pd->device: %p\n",
127                  isert_conn->conn_pd->device);
128
129         ret = rdma_create_qp(cma_id, isert_conn->conn_pd, &attr);
130         if (ret) {
131                 pr_err("rdma_create_qp failed for cma_id %d\n", ret);
132                 return ret;
133         }
134         isert_conn->conn_qp = cma_id->qp;
135         pr_debug("rdma_create_qp() returned success >>>>>>>>>>>>>>>>>>>>>>>>>.\n");
136
137         return 0;
138 }
139
140 static void
141 isert_cq_event_callback(struct ib_event *e, void *context)
142 {
143         pr_debug("isert_cq_event_callback event: %d\n", e->event);
144 }
145
146 static int
147 isert_alloc_rx_descriptors(struct isert_conn *isert_conn)
148 {
149         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
150         struct iser_rx_desc *rx_desc;
151         struct ib_sge *rx_sg;
152         u64 dma_addr;
153         int i, j;
154
155         isert_conn->conn_rx_descs = kzalloc(ISERT_QP_MAX_RECV_DTOS *
156                                 sizeof(struct iser_rx_desc), GFP_KERNEL);
157         if (!isert_conn->conn_rx_descs)
158                 goto fail;
159
160         rx_desc = isert_conn->conn_rx_descs;
161
162         for (i = 0; i < ISERT_QP_MAX_RECV_DTOS; i++, rx_desc++)  {
163                 dma_addr = ib_dma_map_single(ib_dev, (void *)rx_desc,
164                                         ISER_RX_PAYLOAD_SIZE, DMA_FROM_DEVICE);
165                 if (ib_dma_mapping_error(ib_dev, dma_addr))
166                         goto dma_map_fail;
167
168                 rx_desc->dma_addr = dma_addr;
169
170                 rx_sg = &rx_desc->rx_sg;
171                 rx_sg->addr = rx_desc->dma_addr;
172                 rx_sg->length = ISER_RX_PAYLOAD_SIZE;
173                 rx_sg->lkey = isert_conn->conn_mr->lkey;
174         }
175
176         isert_conn->conn_rx_desc_head = 0;
177         return 0;
178
179 dma_map_fail:
180         rx_desc = isert_conn->conn_rx_descs;
181         for (j = 0; j < i; j++, rx_desc++) {
182                 ib_dma_unmap_single(ib_dev, rx_desc->dma_addr,
183                                     ISER_RX_PAYLOAD_SIZE, DMA_FROM_DEVICE);
184         }
185         kfree(isert_conn->conn_rx_descs);
186         isert_conn->conn_rx_descs = NULL;
187 fail:
188         return -ENOMEM;
189 }
190
191 static void
192 isert_free_rx_descriptors(struct isert_conn *isert_conn)
193 {
194         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
195         struct iser_rx_desc *rx_desc;
196         int i;
197
198         if (!isert_conn->conn_rx_descs)
199                 return;
200
201         rx_desc = isert_conn->conn_rx_descs;
202         for (i = 0; i < ISERT_QP_MAX_RECV_DTOS; i++, rx_desc++)  {
203                 ib_dma_unmap_single(ib_dev, rx_desc->dma_addr,
204                                     ISER_RX_PAYLOAD_SIZE, DMA_FROM_DEVICE);
205         }
206
207         kfree(isert_conn->conn_rx_descs);
208         isert_conn->conn_rx_descs = NULL;
209 }
210
211 static void isert_cq_tx_work(struct work_struct *);
212 static void isert_cq_tx_callback(struct ib_cq *, void *);
213 static void isert_cq_rx_work(struct work_struct *);
214 static void isert_cq_rx_callback(struct ib_cq *, void *);
215
216 static int
217 isert_create_device_ib_res(struct isert_device *device)
218 {
219         struct ib_device *ib_dev = device->ib_device;
220         struct isert_cq_desc *cq_desc;
221         struct ib_device_attr *dev_attr;
222         int ret = 0, i, j;
223
224         dev_attr = &device->dev_attr;
225         ret = isert_query_device(ib_dev, dev_attr);
226         if (ret)
227                 return ret;
228
229         /* asign function handlers */
230         if (dev_attr->device_cap_flags & IB_DEVICE_MEM_MGT_EXTENSIONS) {
231                 device->use_fastreg = 1;
232                 device->reg_rdma_mem = isert_reg_rdma;
233                 device->unreg_rdma_mem = isert_unreg_rdma;
234         } else {
235                 device->use_fastreg = 0;
236                 device->reg_rdma_mem = isert_map_rdma;
237                 device->unreg_rdma_mem = isert_unmap_cmd;
238         }
239
240         device->cqs_used = min_t(int, num_online_cpus(),
241                                  device->ib_device->num_comp_vectors);
242         device->cqs_used = min(ISERT_MAX_CQ, device->cqs_used);
243         pr_debug("Using %d CQs, device %s supports %d vectors support "
244                  "Fast registration %d\n",
245                  device->cqs_used, device->ib_device->name,
246                  device->ib_device->num_comp_vectors, device->use_fastreg);
247         device->cq_desc = kzalloc(sizeof(struct isert_cq_desc) *
248                                 device->cqs_used, GFP_KERNEL);
249         if (!device->cq_desc) {
250                 pr_err("Unable to allocate device->cq_desc\n");
251                 return -ENOMEM;
252         }
253         cq_desc = device->cq_desc;
254
255         for (i = 0; i < device->cqs_used; i++) {
256                 cq_desc[i].device = device;
257                 cq_desc[i].cq_index = i;
258
259                 INIT_WORK(&cq_desc[i].cq_rx_work, isert_cq_rx_work);
260                 device->dev_rx_cq[i] = ib_create_cq(device->ib_device,
261                                                 isert_cq_rx_callback,
262                                                 isert_cq_event_callback,
263                                                 (void *)&cq_desc[i],
264                                                 ISER_MAX_RX_CQ_LEN, i);
265                 if (IS_ERR(device->dev_rx_cq[i])) {
266                         ret = PTR_ERR(device->dev_rx_cq[i]);
267                         device->dev_rx_cq[i] = NULL;
268                         goto out_cq;
269                 }
270
271                 INIT_WORK(&cq_desc[i].cq_tx_work, isert_cq_tx_work);
272                 device->dev_tx_cq[i] = ib_create_cq(device->ib_device,
273                                                 isert_cq_tx_callback,
274                                                 isert_cq_event_callback,
275                                                 (void *)&cq_desc[i],
276                                                 ISER_MAX_TX_CQ_LEN, i);
277                 if (IS_ERR(device->dev_tx_cq[i])) {
278                         ret = PTR_ERR(device->dev_tx_cq[i]);
279                         device->dev_tx_cq[i] = NULL;
280                         goto out_cq;
281                 }
282
283                 ret = ib_req_notify_cq(device->dev_rx_cq[i], IB_CQ_NEXT_COMP);
284                 if (ret)
285                         goto out_cq;
286
287                 ret = ib_req_notify_cq(device->dev_tx_cq[i], IB_CQ_NEXT_COMP);
288                 if (ret)
289                         goto out_cq;
290         }
291
292         return 0;
293
294 out_cq:
295         for (j = 0; j < i; j++) {
296                 cq_desc = &device->cq_desc[j];
297
298                 if (device->dev_rx_cq[j]) {
299                         cancel_work_sync(&cq_desc->cq_rx_work);
300                         ib_destroy_cq(device->dev_rx_cq[j]);
301                 }
302                 if (device->dev_tx_cq[j]) {
303                         cancel_work_sync(&cq_desc->cq_tx_work);
304                         ib_destroy_cq(device->dev_tx_cq[j]);
305                 }
306         }
307         kfree(device->cq_desc);
308
309         return ret;
310 }
311
312 static void
313 isert_free_device_ib_res(struct isert_device *device)
314 {
315         struct isert_cq_desc *cq_desc;
316         int i;
317
318         for (i = 0; i < device->cqs_used; i++) {
319                 cq_desc = &device->cq_desc[i];
320
321                 cancel_work_sync(&cq_desc->cq_rx_work);
322                 cancel_work_sync(&cq_desc->cq_tx_work);
323                 ib_destroy_cq(device->dev_rx_cq[i]);
324                 ib_destroy_cq(device->dev_tx_cq[i]);
325                 device->dev_rx_cq[i] = NULL;
326                 device->dev_tx_cq[i] = NULL;
327         }
328
329         kfree(device->cq_desc);
330 }
331
332 static void
333 isert_device_try_release(struct isert_device *device)
334 {
335         mutex_lock(&device_list_mutex);
336         device->refcount--;
337         if (!device->refcount) {
338                 isert_free_device_ib_res(device);
339                 list_del(&device->dev_node);
340                 kfree(device);
341         }
342         mutex_unlock(&device_list_mutex);
343 }
344
345 static struct isert_device *
346 isert_device_find_by_ib_dev(struct rdma_cm_id *cma_id)
347 {
348         struct isert_device *device;
349         int ret;
350
351         mutex_lock(&device_list_mutex);
352         list_for_each_entry(device, &device_list, dev_node) {
353                 if (device->ib_device->node_guid == cma_id->device->node_guid) {
354                         device->refcount++;
355                         mutex_unlock(&device_list_mutex);
356                         return device;
357                 }
358         }
359
360         device = kzalloc(sizeof(struct isert_device), GFP_KERNEL);
361         if (!device) {
362                 mutex_unlock(&device_list_mutex);
363                 return ERR_PTR(-ENOMEM);
364         }
365
366         INIT_LIST_HEAD(&device->dev_node);
367
368         device->ib_device = cma_id->device;
369         ret = isert_create_device_ib_res(device);
370         if (ret) {
371                 kfree(device);
372                 mutex_unlock(&device_list_mutex);
373                 return ERR_PTR(ret);
374         }
375
376         device->refcount++;
377         list_add_tail(&device->dev_node, &device_list);
378         mutex_unlock(&device_list_mutex);
379
380         return device;
381 }
382
383 static void
384 isert_conn_free_fastreg_pool(struct isert_conn *isert_conn)
385 {
386         struct fast_reg_descriptor *fr_desc, *tmp;
387         int i = 0;
388
389         if (list_empty(&isert_conn->conn_fr_pool))
390                 return;
391
392         pr_debug("Freeing conn %p fastreg pool", isert_conn);
393
394         list_for_each_entry_safe(fr_desc, tmp,
395                                  &isert_conn->conn_fr_pool, list) {
396                 list_del(&fr_desc->list);
397                 ib_free_fast_reg_page_list(fr_desc->data_frpl);
398                 ib_dereg_mr(fr_desc->data_mr);
399                 kfree(fr_desc);
400                 ++i;
401         }
402
403         if (i < isert_conn->conn_fr_pool_size)
404                 pr_warn("Pool still has %d regions registered\n",
405                         isert_conn->conn_fr_pool_size - i);
406 }
407
408 static int
409 isert_create_fr_desc(struct ib_device *ib_device, struct ib_pd *pd,
410                      struct fast_reg_descriptor *fr_desc)
411 {
412         fr_desc->data_frpl = ib_alloc_fast_reg_page_list(ib_device,
413                                                          ISCSI_ISER_SG_TABLESIZE);
414         if (IS_ERR(fr_desc->data_frpl)) {
415                 pr_err("Failed to allocate data frpl err=%ld\n",
416                        PTR_ERR(fr_desc->data_frpl));
417                 return PTR_ERR(fr_desc->data_frpl);
418         }
419
420         fr_desc->data_mr = ib_alloc_fast_reg_mr(pd, ISCSI_ISER_SG_TABLESIZE);
421         if (IS_ERR(fr_desc->data_mr)) {
422                 pr_err("Failed to allocate data frmr err=%ld\n",
423                        PTR_ERR(fr_desc->data_mr));
424                 ib_free_fast_reg_page_list(fr_desc->data_frpl);
425                 return PTR_ERR(fr_desc->data_mr);
426         }
427         pr_debug("Create fr_desc %p page_list %p\n",
428                  fr_desc, fr_desc->data_frpl->page_list);
429
430         fr_desc->valid = true;
431
432         return 0;
433 }
434
435 static int
436 isert_conn_create_fastreg_pool(struct isert_conn *isert_conn)
437 {
438         struct fast_reg_descriptor *fr_desc;
439         struct isert_device *device = isert_conn->conn_device;
440         struct se_session *se_sess = isert_conn->conn->sess->se_sess;
441         struct se_node_acl *se_nacl = se_sess->se_node_acl;
442         int i, ret, tag_num;
443         /*
444          * Setup the number of FRMRs based upon the number of tags
445          * available to session in iscsi_target_locate_portal().
446          */
447         tag_num = max_t(u32, ISCSIT_MIN_TAGS, se_nacl->queue_depth);
448         tag_num = (tag_num * 2) + ISCSIT_EXTRA_TAGS;
449
450         isert_conn->conn_fr_pool_size = 0;
451         for (i = 0; i < tag_num; i++) {
452                 fr_desc = kzalloc(sizeof(*fr_desc), GFP_KERNEL);
453                 if (!fr_desc) {
454                         pr_err("Failed to allocate fast_reg descriptor\n");
455                         ret = -ENOMEM;
456                         goto err;
457                 }
458
459                 ret = isert_create_fr_desc(device->ib_device,
460                                            isert_conn->conn_pd, fr_desc);
461                 if (ret) {
462                         pr_err("Failed to create fastreg descriptor err=%d\n",
463                                ret);
464                         kfree(fr_desc);
465                         goto err;
466                 }
467
468                 list_add_tail(&fr_desc->list, &isert_conn->conn_fr_pool);
469                 isert_conn->conn_fr_pool_size++;
470         }
471
472         pr_debug("Creating conn %p fastreg pool size=%d",
473                  isert_conn, isert_conn->conn_fr_pool_size);
474
475         return 0;
476
477 err:
478         isert_conn_free_fastreg_pool(isert_conn);
479         return ret;
480 }
481
482 static int
483 isert_connect_request(struct rdma_cm_id *cma_id, struct rdma_cm_event *event)
484 {
485         struct iscsi_np *np = cma_id->context;
486         struct isert_np *isert_np = np->np_context;
487         struct isert_conn *isert_conn;
488         struct isert_device *device;
489         struct ib_device *ib_dev = cma_id->device;
490         int ret = 0;
491
492         pr_debug("Entering isert_connect_request cma_id: %p, context: %p\n",
493                  cma_id, cma_id->context);
494
495         isert_conn = kzalloc(sizeof(struct isert_conn), GFP_KERNEL);
496         if (!isert_conn) {
497                 pr_err("Unable to allocate isert_conn\n");
498                 return -ENOMEM;
499         }
500         isert_conn->state = ISER_CONN_INIT;
501         INIT_LIST_HEAD(&isert_conn->conn_accept_node);
502         init_completion(&isert_conn->conn_login_comp);
503         init_completion(&isert_conn->conn_wait);
504         init_completion(&isert_conn->conn_wait_comp_err);
505         kref_init(&isert_conn->conn_kref);
506         kref_get(&isert_conn->conn_kref);
507         mutex_init(&isert_conn->conn_mutex);
508         spin_lock_init(&isert_conn->conn_lock);
509         INIT_LIST_HEAD(&isert_conn->conn_fr_pool);
510
511         cma_id->context = isert_conn;
512         isert_conn->conn_cm_id = cma_id;
513         isert_conn->responder_resources = event->param.conn.responder_resources;
514         isert_conn->initiator_depth = event->param.conn.initiator_depth;
515         pr_debug("Using responder_resources: %u initiator_depth: %u\n",
516                  isert_conn->responder_resources, isert_conn->initiator_depth);
517
518         isert_conn->login_buf = kzalloc(ISCSI_DEF_MAX_RECV_SEG_LEN +
519                                         ISER_RX_LOGIN_SIZE, GFP_KERNEL);
520         if (!isert_conn->login_buf) {
521                 pr_err("Unable to allocate isert_conn->login_buf\n");
522                 ret = -ENOMEM;
523                 goto out;
524         }
525
526         isert_conn->login_req_buf = isert_conn->login_buf;
527         isert_conn->login_rsp_buf = isert_conn->login_buf +
528                                     ISCSI_DEF_MAX_RECV_SEG_LEN;
529         pr_debug("Set login_buf: %p login_req_buf: %p login_rsp_buf: %p\n",
530                  isert_conn->login_buf, isert_conn->login_req_buf,
531                  isert_conn->login_rsp_buf);
532
533         isert_conn->login_req_dma = ib_dma_map_single(ib_dev,
534                                 (void *)isert_conn->login_req_buf,
535                                 ISCSI_DEF_MAX_RECV_SEG_LEN, DMA_FROM_DEVICE);
536
537         ret = ib_dma_mapping_error(ib_dev, isert_conn->login_req_dma);
538         if (ret) {
539                 pr_err("ib_dma_mapping_error failed for login_req_dma: %d\n",
540                        ret);
541                 isert_conn->login_req_dma = 0;
542                 goto out_login_buf;
543         }
544
545         isert_conn->login_rsp_dma = ib_dma_map_single(ib_dev,
546                                         (void *)isert_conn->login_rsp_buf,
547                                         ISER_RX_LOGIN_SIZE, DMA_TO_DEVICE);
548
549         ret = ib_dma_mapping_error(ib_dev, isert_conn->login_rsp_dma);
550         if (ret) {
551                 pr_err("ib_dma_mapping_error failed for login_rsp_dma: %d\n",
552                        ret);
553                 isert_conn->login_rsp_dma = 0;
554                 goto out_req_dma_map;
555         }
556
557         device = isert_device_find_by_ib_dev(cma_id);
558         if (IS_ERR(device)) {
559                 ret = PTR_ERR(device);
560                 goto out_rsp_dma_map;
561         }
562
563         isert_conn->conn_device = device;
564         isert_conn->conn_pd = ib_alloc_pd(isert_conn->conn_device->ib_device);
565         if (IS_ERR(isert_conn->conn_pd)) {
566                 ret = PTR_ERR(isert_conn->conn_pd);
567                 pr_err("ib_alloc_pd failed for conn %p: ret=%d\n",
568                        isert_conn, ret);
569                 goto out_pd;
570         }
571
572         isert_conn->conn_mr = ib_get_dma_mr(isert_conn->conn_pd,
573                                            IB_ACCESS_LOCAL_WRITE);
574         if (IS_ERR(isert_conn->conn_mr)) {
575                 ret = PTR_ERR(isert_conn->conn_mr);
576                 pr_err("ib_get_dma_mr failed for conn %p: ret=%d\n",
577                        isert_conn, ret);
578                 goto out_mr;
579         }
580
581         ret = isert_conn_setup_qp(isert_conn, cma_id);
582         if (ret)
583                 goto out_conn_dev;
584
585         mutex_lock(&isert_np->np_accept_mutex);
586         list_add_tail(&isert_conn->conn_accept_node, &isert_np->np_accept_list);
587         mutex_unlock(&isert_np->np_accept_mutex);
588
589         pr_debug("isert_connect_request() up np_sem np: %p\n", np);
590         up(&isert_np->np_sem);
591         return 0;
592
593 out_conn_dev:
594         ib_dereg_mr(isert_conn->conn_mr);
595 out_mr:
596         ib_dealloc_pd(isert_conn->conn_pd);
597 out_pd:
598         isert_device_try_release(device);
599 out_rsp_dma_map:
600         ib_dma_unmap_single(ib_dev, isert_conn->login_rsp_dma,
601                             ISER_RX_LOGIN_SIZE, DMA_TO_DEVICE);
602 out_req_dma_map:
603         ib_dma_unmap_single(ib_dev, isert_conn->login_req_dma,
604                             ISCSI_DEF_MAX_RECV_SEG_LEN, DMA_FROM_DEVICE);
605 out_login_buf:
606         kfree(isert_conn->login_buf);
607 out:
608         kfree(isert_conn);
609         return ret;
610 }
611
612 static void
613 isert_connect_release(struct isert_conn *isert_conn)
614 {
615         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
616         struct isert_device *device = isert_conn->conn_device;
617         int cq_index;
618
619         pr_debug("Entering isert_connect_release(): >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>\n");
620
621         if (device && device->use_fastreg)
622                 isert_conn_free_fastreg_pool(isert_conn);
623
624         if (isert_conn->conn_qp) {
625                 cq_index = ((struct isert_cq_desc *)
626                         isert_conn->conn_qp->recv_cq->cq_context)->cq_index;
627                 pr_debug("isert_connect_release: cq_index: %d\n", cq_index);
628                 isert_conn->conn_device->cq_active_qps[cq_index]--;
629
630                 rdma_destroy_qp(isert_conn->conn_cm_id);
631         }
632
633         isert_free_rx_descriptors(isert_conn);
634         rdma_destroy_id(isert_conn->conn_cm_id);
635
636         ib_dereg_mr(isert_conn->conn_mr);
637         ib_dealloc_pd(isert_conn->conn_pd);
638
639         if (isert_conn->login_buf) {
640                 ib_dma_unmap_single(ib_dev, isert_conn->login_rsp_dma,
641                                     ISER_RX_LOGIN_SIZE, DMA_TO_DEVICE);
642                 ib_dma_unmap_single(ib_dev, isert_conn->login_req_dma,
643                                     ISCSI_DEF_MAX_RECV_SEG_LEN,
644                                     DMA_FROM_DEVICE);
645                 kfree(isert_conn->login_buf);
646         }
647         kfree(isert_conn);
648
649         if (device)
650                 isert_device_try_release(device);
651
652         pr_debug("Leaving isert_connect_release >>>>>>>>>>>>\n");
653 }
654
655 static void
656 isert_connected_handler(struct rdma_cm_id *cma_id)
657 {
658         return;
659 }
660
661 static void
662 isert_release_conn_kref(struct kref *kref)
663 {
664         struct isert_conn *isert_conn = container_of(kref,
665                                 struct isert_conn, conn_kref);
666
667         pr_debug("Calling isert_connect_release for final kref %s/%d\n",
668                  current->comm, current->pid);
669
670         isert_connect_release(isert_conn);
671 }
672
673 static void
674 isert_put_conn(struct isert_conn *isert_conn)
675 {
676         kref_put(&isert_conn->conn_kref, isert_release_conn_kref);
677 }
678
679 static void
680 isert_disconnect_work(struct work_struct *work)
681 {
682         struct isert_conn *isert_conn = container_of(work,
683                                 struct isert_conn, conn_logout_work);
684
685         pr_debug("isert_disconnect_work(): >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>\n");
686         mutex_lock(&isert_conn->conn_mutex);
687         if (isert_conn->state == ISER_CONN_UP)
688                 isert_conn->state = ISER_CONN_TERMINATING;
689
690         if (isert_conn->post_recv_buf_count == 0 &&
691             atomic_read(&isert_conn->post_send_buf_count) == 0) {
692                 mutex_unlock(&isert_conn->conn_mutex);
693                 goto wake_up;
694         }
695         if (!isert_conn->conn_cm_id) {
696                 mutex_unlock(&isert_conn->conn_mutex);
697                 isert_put_conn(isert_conn);
698                 return;
699         }
700         if (!isert_conn->logout_posted) {
701                 pr_debug("Calling rdma_disconnect for !logout_posted from"
702                          " isert_disconnect_work\n");
703                 rdma_disconnect(isert_conn->conn_cm_id);
704                 mutex_unlock(&isert_conn->conn_mutex);
705                 iscsit_cause_connection_reinstatement(isert_conn->conn, 0);
706                 goto wake_up;
707         }
708         mutex_unlock(&isert_conn->conn_mutex);
709
710 wake_up:
711         complete(&isert_conn->conn_wait);
712         isert_put_conn(isert_conn);
713 }
714
715 static void
716 isert_disconnected_handler(struct rdma_cm_id *cma_id)
717 {
718         struct isert_conn *isert_conn = (struct isert_conn *)cma_id->context;
719
720         INIT_WORK(&isert_conn->conn_logout_work, isert_disconnect_work);
721         schedule_work(&isert_conn->conn_logout_work);
722 }
723
724 static int
725 isert_cma_handler(struct rdma_cm_id *cma_id, struct rdma_cm_event *event)
726 {
727         int ret = 0;
728
729         pr_debug("isert_cma_handler: event %d status %d conn %p id %p\n",
730                  event->event, event->status, cma_id->context, cma_id);
731
732         switch (event->event) {
733         case RDMA_CM_EVENT_CONNECT_REQUEST:
734                 pr_debug("RDMA_CM_EVENT_CONNECT_REQUEST: >>>>>>>>>>>>>>>\n");
735                 ret = isert_connect_request(cma_id, event);
736                 break;
737         case RDMA_CM_EVENT_ESTABLISHED:
738                 pr_debug("RDMA_CM_EVENT_ESTABLISHED >>>>>>>>>>>>>>\n");
739                 isert_connected_handler(cma_id);
740                 break;
741         case RDMA_CM_EVENT_DISCONNECTED:
742                 pr_debug("RDMA_CM_EVENT_DISCONNECTED: >>>>>>>>>>>>>>\n");
743                 isert_disconnected_handler(cma_id);
744                 break;
745         case RDMA_CM_EVENT_DEVICE_REMOVAL:
746         case RDMA_CM_EVENT_ADDR_CHANGE:
747                 break;
748         case RDMA_CM_EVENT_CONNECT_ERROR:
749         default:
750                 pr_err("Unknown RDMA CMA event: %d\n", event->event);
751                 break;
752         }
753
754         if (ret != 0) {
755                 pr_err("isert_cma_handler failed RDMA_CM_EVENT: 0x%08x %d\n",
756                        event->event, ret);
757                 dump_stack();
758         }
759
760         return ret;
761 }
762
763 static int
764 isert_post_recv(struct isert_conn *isert_conn, u32 count)
765 {
766         struct ib_recv_wr *rx_wr, *rx_wr_failed;
767         int i, ret;
768         unsigned int rx_head = isert_conn->conn_rx_desc_head;
769         struct iser_rx_desc *rx_desc;
770
771         for (rx_wr = isert_conn->conn_rx_wr, i = 0; i < count; i++, rx_wr++) {
772                 rx_desc         = &isert_conn->conn_rx_descs[rx_head];
773                 rx_wr->wr_id    = (unsigned long)rx_desc;
774                 rx_wr->sg_list  = &rx_desc->rx_sg;
775                 rx_wr->num_sge  = 1;
776                 rx_wr->next     = rx_wr + 1;
777                 rx_head = (rx_head + 1) & (ISERT_QP_MAX_RECV_DTOS - 1);
778         }
779
780         rx_wr--;
781         rx_wr->next = NULL; /* mark end of work requests list */
782
783         isert_conn->post_recv_buf_count += count;
784         ret = ib_post_recv(isert_conn->conn_qp, isert_conn->conn_rx_wr,
785                                 &rx_wr_failed);
786         if (ret) {
787                 pr_err("ib_post_recv() failed with ret: %d\n", ret);
788                 isert_conn->post_recv_buf_count -= count;
789         } else {
790                 pr_debug("isert_post_recv(): Posted %d RX buffers\n", count);
791                 isert_conn->conn_rx_desc_head = rx_head;
792         }
793         return ret;
794 }
795
796 static int
797 isert_post_send(struct isert_conn *isert_conn, struct iser_tx_desc *tx_desc)
798 {
799         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
800         struct ib_send_wr send_wr, *send_wr_failed;
801         int ret;
802
803         ib_dma_sync_single_for_device(ib_dev, tx_desc->dma_addr,
804                                       ISER_HEADERS_LEN, DMA_TO_DEVICE);
805
806         send_wr.next    = NULL;
807         send_wr.wr_id   = (unsigned long)tx_desc;
808         send_wr.sg_list = tx_desc->tx_sg;
809         send_wr.num_sge = tx_desc->num_sge;
810         send_wr.opcode  = IB_WR_SEND;
811         send_wr.send_flags = IB_SEND_SIGNALED;
812
813         atomic_inc(&isert_conn->post_send_buf_count);
814
815         ret = ib_post_send(isert_conn->conn_qp, &send_wr, &send_wr_failed);
816         if (ret) {
817                 pr_err("ib_post_send() failed, ret: %d\n", ret);
818                 atomic_dec(&isert_conn->post_send_buf_count);
819         }
820
821         return ret;
822 }
823
824 static void
825 isert_create_send_desc(struct isert_conn *isert_conn,
826                        struct isert_cmd *isert_cmd,
827                        struct iser_tx_desc *tx_desc)
828 {
829         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
830
831         ib_dma_sync_single_for_cpu(ib_dev, tx_desc->dma_addr,
832                                    ISER_HEADERS_LEN, DMA_TO_DEVICE);
833
834         memset(&tx_desc->iser_header, 0, sizeof(struct iser_hdr));
835         tx_desc->iser_header.flags = ISER_VER;
836
837         tx_desc->num_sge = 1;
838         tx_desc->isert_cmd = isert_cmd;
839
840         if (tx_desc->tx_sg[0].lkey != isert_conn->conn_mr->lkey) {
841                 tx_desc->tx_sg[0].lkey = isert_conn->conn_mr->lkey;
842                 pr_debug("tx_desc %p lkey mismatch, fixing\n", tx_desc);
843         }
844 }
845
846 static int
847 isert_init_tx_hdrs(struct isert_conn *isert_conn,
848                    struct iser_tx_desc *tx_desc)
849 {
850         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
851         u64 dma_addr;
852
853         dma_addr = ib_dma_map_single(ib_dev, (void *)tx_desc,
854                         ISER_HEADERS_LEN, DMA_TO_DEVICE);
855         if (ib_dma_mapping_error(ib_dev, dma_addr)) {
856                 pr_err("ib_dma_mapping_error() failed\n");
857                 return -ENOMEM;
858         }
859
860         tx_desc->dma_addr = dma_addr;
861         tx_desc->tx_sg[0].addr  = tx_desc->dma_addr;
862         tx_desc->tx_sg[0].length = ISER_HEADERS_LEN;
863         tx_desc->tx_sg[0].lkey = isert_conn->conn_mr->lkey;
864
865         pr_debug("isert_init_tx_hdrs: Setup tx_sg[0].addr: 0x%llx length: %u"
866                  " lkey: 0x%08x\n", tx_desc->tx_sg[0].addr,
867                  tx_desc->tx_sg[0].length, tx_desc->tx_sg[0].lkey);
868
869         return 0;
870 }
871
872 static void
873 isert_init_send_wr(struct isert_conn *isert_conn, struct isert_cmd *isert_cmd,
874                    struct ib_send_wr *send_wr, bool coalesce)
875 {
876         struct iser_tx_desc *tx_desc = &isert_cmd->tx_desc;
877
878         isert_cmd->rdma_wr.iser_ib_op = ISER_IB_SEND;
879         send_wr->wr_id = (unsigned long)&isert_cmd->tx_desc;
880         send_wr->opcode = IB_WR_SEND;
881         send_wr->sg_list = &tx_desc->tx_sg[0];
882         send_wr->num_sge = isert_cmd->tx_desc.num_sge;
883         /*
884          * Coalesce send completion interrupts by only setting IB_SEND_SIGNALED
885          * bit for every ISERT_COMP_BATCH_COUNT number of ib_post_send() calls.
886          */
887         mutex_lock(&isert_conn->conn_mutex);
888         if (coalesce && isert_conn->state == ISER_CONN_UP &&
889             ++isert_conn->conn_comp_batch < ISERT_COMP_BATCH_COUNT) {
890                 tx_desc->llnode_active = true;
891                 llist_add(&tx_desc->comp_llnode, &isert_conn->conn_comp_llist);
892                 mutex_unlock(&isert_conn->conn_mutex);
893                 return;
894         }
895         isert_conn->conn_comp_batch = 0;
896         tx_desc->comp_llnode_batch = llist_del_all(&isert_conn->conn_comp_llist);
897         mutex_unlock(&isert_conn->conn_mutex);
898
899         send_wr->send_flags = IB_SEND_SIGNALED;
900 }
901
902 static int
903 isert_rdma_post_recvl(struct isert_conn *isert_conn)
904 {
905         struct ib_recv_wr rx_wr, *rx_wr_fail;
906         struct ib_sge sge;
907         int ret;
908
909         memset(&sge, 0, sizeof(struct ib_sge));
910         sge.addr = isert_conn->login_req_dma;
911         sge.length = ISER_RX_LOGIN_SIZE;
912         sge.lkey = isert_conn->conn_mr->lkey;
913
914         pr_debug("Setup sge: addr: %llx length: %d 0x%08x\n",
915                 sge.addr, sge.length, sge.lkey);
916
917         memset(&rx_wr, 0, sizeof(struct ib_recv_wr));
918         rx_wr.wr_id = (unsigned long)isert_conn->login_req_buf;
919         rx_wr.sg_list = &sge;
920         rx_wr.num_sge = 1;
921
922         isert_conn->post_recv_buf_count++;
923         ret = ib_post_recv(isert_conn->conn_qp, &rx_wr, &rx_wr_fail);
924         if (ret) {
925                 pr_err("ib_post_recv() failed: %d\n", ret);
926                 isert_conn->post_recv_buf_count--;
927         }
928
929         pr_debug("ib_post_recv(): returned success >>>>>>>>>>>>>>>>>>>>>>>>\n");
930         return ret;
931 }
932
933 static int
934 isert_put_login_tx(struct iscsi_conn *conn, struct iscsi_login *login,
935                    u32 length)
936 {
937         struct isert_conn *isert_conn = conn->context;
938         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
939         struct iser_tx_desc *tx_desc = &isert_conn->conn_login_tx_desc;
940         int ret;
941
942         isert_create_send_desc(isert_conn, NULL, tx_desc);
943
944         memcpy(&tx_desc->iscsi_header, &login->rsp[0],
945                sizeof(struct iscsi_hdr));
946
947         isert_init_tx_hdrs(isert_conn, tx_desc);
948
949         if (length > 0) {
950                 struct ib_sge *tx_dsg = &tx_desc->tx_sg[1];
951
952                 ib_dma_sync_single_for_cpu(ib_dev, isert_conn->login_rsp_dma,
953                                            length, DMA_TO_DEVICE);
954
955                 memcpy(isert_conn->login_rsp_buf, login->rsp_buf, length);
956
957                 ib_dma_sync_single_for_device(ib_dev, isert_conn->login_rsp_dma,
958                                               length, DMA_TO_DEVICE);
959
960                 tx_dsg->addr    = isert_conn->login_rsp_dma;
961                 tx_dsg->length  = length;
962                 tx_dsg->lkey    = isert_conn->conn_mr->lkey;
963                 tx_desc->num_sge = 2;
964         }
965         if (!login->login_failed) {
966                 if (login->login_complete) {
967                         if (isert_conn->conn_device->use_fastreg) {
968                                 ret = isert_conn_create_fastreg_pool(isert_conn);
969                                 if (ret) {
970                                         pr_err("Conn: %p failed to create"
971                                                " fastreg pool\n", isert_conn);
972                                         return ret;
973                                 }
974                         }
975
976                         ret = isert_alloc_rx_descriptors(isert_conn);
977                         if (ret)
978                                 return ret;
979
980                         ret = isert_post_recv(isert_conn, ISERT_MIN_POSTED_RX);
981                         if (ret)
982                                 return ret;
983
984                         isert_conn->state = ISER_CONN_UP;
985                         goto post_send;
986                 }
987
988                 ret = isert_rdma_post_recvl(isert_conn);
989                 if (ret)
990                         return ret;
991         }
992 post_send:
993         ret = isert_post_send(isert_conn, tx_desc);
994         if (ret)
995                 return ret;
996
997         return 0;
998 }
999
1000 static void
1001 isert_rx_login_req(struct iser_rx_desc *rx_desc, int rx_buflen,
1002                    struct isert_conn *isert_conn)
1003 {
1004         struct iscsi_conn *conn = isert_conn->conn;
1005         struct iscsi_login *login = conn->conn_login;
1006         int size;
1007
1008         if (!login) {
1009                 pr_err("conn->conn_login is NULL\n");
1010                 dump_stack();
1011                 return;
1012         }
1013
1014         if (login->first_request) {
1015                 struct iscsi_login_req *login_req =
1016                         (struct iscsi_login_req *)&rx_desc->iscsi_header;
1017                 /*
1018                  * Setup the initial iscsi_login values from the leading
1019                  * login request PDU.
1020                  */
1021                 login->leading_connection = (!login_req->tsih) ? 1 : 0;
1022                 login->current_stage =
1023                         (login_req->flags & ISCSI_FLAG_LOGIN_CURRENT_STAGE_MASK)
1024                          >> 2;
1025                 login->version_min      = login_req->min_version;
1026                 login->version_max      = login_req->max_version;
1027                 memcpy(login->isid, login_req->isid, 6);
1028                 login->cmd_sn           = be32_to_cpu(login_req->cmdsn);
1029                 login->init_task_tag    = login_req->itt;
1030                 login->initial_exp_statsn = be32_to_cpu(login_req->exp_statsn);
1031                 login->cid              = be16_to_cpu(login_req->cid);
1032                 login->tsih             = be16_to_cpu(login_req->tsih);
1033         }
1034
1035         memcpy(&login->req[0], (void *)&rx_desc->iscsi_header, ISCSI_HDR_LEN);
1036
1037         size = min(rx_buflen, MAX_KEY_VALUE_PAIRS);
1038         pr_debug("Using login payload size: %d, rx_buflen: %d MAX_KEY_VALUE_PAIRS: %d\n",
1039                  size, rx_buflen, MAX_KEY_VALUE_PAIRS);
1040         memcpy(login->req_buf, &rx_desc->data[0], size);
1041
1042         if (login->first_request) {
1043                 complete(&isert_conn->conn_login_comp);
1044                 return;
1045         }
1046         schedule_delayed_work(&conn->login_work, 0);
1047 }
1048
1049 static struct iscsi_cmd
1050 *isert_allocate_cmd(struct iscsi_conn *conn)
1051 {
1052         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
1053         struct isert_cmd *isert_cmd;
1054         struct iscsi_cmd *cmd;
1055
1056         cmd = iscsit_allocate_cmd(conn, TASK_INTERRUPTIBLE);
1057         if (!cmd) {
1058                 pr_err("Unable to allocate iscsi_cmd + isert_cmd\n");
1059                 return NULL;
1060         }
1061         isert_cmd = iscsit_priv_cmd(cmd);
1062         isert_cmd->conn = isert_conn;
1063         isert_cmd->iscsi_cmd = cmd;
1064
1065         return cmd;
1066 }
1067
1068 static int
1069 isert_handle_scsi_cmd(struct isert_conn *isert_conn,
1070                       struct isert_cmd *isert_cmd, struct iscsi_cmd *cmd,
1071                       struct iser_rx_desc *rx_desc, unsigned char *buf)
1072 {
1073         struct iscsi_conn *conn = isert_conn->conn;
1074         struct iscsi_scsi_req *hdr = (struct iscsi_scsi_req *)buf;
1075         struct scatterlist *sg;
1076         int imm_data, imm_data_len, unsol_data, sg_nents, rc;
1077         bool dump_payload = false;
1078
1079         rc = iscsit_setup_scsi_cmd(conn, cmd, buf);
1080         if (rc < 0)
1081                 return rc;
1082
1083         imm_data = cmd->immediate_data;
1084         imm_data_len = cmd->first_burst_len;
1085         unsol_data = cmd->unsolicited_data;
1086
1087         rc = iscsit_process_scsi_cmd(conn, cmd, hdr);
1088         if (rc < 0) {
1089                 return 0;
1090         } else if (rc > 0) {
1091                 dump_payload = true;
1092                 goto sequence_cmd;
1093         }
1094
1095         if (!imm_data)
1096                 return 0;
1097
1098         sg = &cmd->se_cmd.t_data_sg[0];
1099         sg_nents = max(1UL, DIV_ROUND_UP(imm_data_len, PAGE_SIZE));
1100
1101         pr_debug("Copying Immediate SG: %p sg_nents: %u from %p imm_data_len: %d\n",
1102                  sg, sg_nents, &rx_desc->data[0], imm_data_len);
1103
1104         sg_copy_from_buffer(sg, sg_nents, &rx_desc->data[0], imm_data_len);
1105
1106         cmd->write_data_done += imm_data_len;
1107
1108         if (cmd->write_data_done == cmd->se_cmd.data_length) {
1109                 spin_lock_bh(&cmd->istate_lock);
1110                 cmd->cmd_flags |= ICF_GOT_LAST_DATAOUT;
1111                 cmd->i_state = ISTATE_RECEIVED_LAST_DATAOUT;
1112                 spin_unlock_bh(&cmd->istate_lock);
1113         }
1114
1115 sequence_cmd:
1116         rc = iscsit_sequence_cmd(conn, cmd, buf, hdr->cmdsn);
1117
1118         if (!rc && dump_payload == false && unsol_data)
1119                 iscsit_set_unsoliticed_dataout(cmd);
1120
1121         return 0;
1122 }
1123
1124 static int
1125 isert_handle_iscsi_dataout(struct isert_conn *isert_conn,
1126                            struct iser_rx_desc *rx_desc, unsigned char *buf)
1127 {
1128         struct scatterlist *sg_start;
1129         struct iscsi_conn *conn = isert_conn->conn;
1130         struct iscsi_cmd *cmd = NULL;
1131         struct iscsi_data *hdr = (struct iscsi_data *)buf;
1132         u32 unsol_data_len = ntoh24(hdr->dlength);
1133         int rc, sg_nents, sg_off, page_off;
1134
1135         rc = iscsit_check_dataout_hdr(conn, buf, &cmd);
1136         if (rc < 0)
1137                 return rc;
1138         else if (!cmd)
1139                 return 0;
1140         /*
1141          * FIXME: Unexpected unsolicited_data out
1142          */
1143         if (!cmd->unsolicited_data) {
1144                 pr_err("Received unexpected solicited data payload\n");
1145                 dump_stack();
1146                 return -1;
1147         }
1148
1149         pr_debug("Unsolicited DataOut unsol_data_len: %u, write_data_done: %u, data_length: %u\n",
1150                  unsol_data_len, cmd->write_data_done, cmd->se_cmd.data_length);
1151
1152         sg_off = cmd->write_data_done / PAGE_SIZE;
1153         sg_start = &cmd->se_cmd.t_data_sg[sg_off];
1154         sg_nents = max(1UL, DIV_ROUND_UP(unsol_data_len, PAGE_SIZE));
1155         page_off = cmd->write_data_done % PAGE_SIZE;
1156         /*
1157          * FIXME: Non page-aligned unsolicited_data out
1158          */
1159         if (page_off) {
1160                 pr_err("Received unexpected non-page aligned data payload\n");
1161                 dump_stack();
1162                 return -1;
1163         }
1164         pr_debug("Copying DataOut: sg_start: %p, sg_off: %u sg_nents: %u from %p %u\n",
1165                  sg_start, sg_off, sg_nents, &rx_desc->data[0], unsol_data_len);
1166
1167         sg_copy_from_buffer(sg_start, sg_nents, &rx_desc->data[0],
1168                             unsol_data_len);
1169
1170         rc = iscsit_check_dataout_payload(cmd, hdr, false);
1171         if (rc < 0)
1172                 return rc;
1173
1174         return 0;
1175 }
1176
1177 static int
1178 isert_handle_nop_out(struct isert_conn *isert_conn, struct isert_cmd *isert_cmd,
1179                      struct iscsi_cmd *cmd, struct iser_rx_desc *rx_desc,
1180                      unsigned char *buf)
1181 {
1182         struct iscsi_conn *conn = isert_conn->conn;
1183         struct iscsi_nopout *hdr = (struct iscsi_nopout *)buf;
1184         int rc;
1185
1186         rc = iscsit_setup_nop_out(conn, cmd, hdr);
1187         if (rc < 0)
1188                 return rc;
1189         /*
1190          * FIXME: Add support for NOPOUT payload using unsolicited RDMA payload
1191          */
1192
1193         return iscsit_process_nop_out(conn, cmd, hdr);
1194 }
1195
1196 static int
1197 isert_handle_text_cmd(struct isert_conn *isert_conn, struct isert_cmd *isert_cmd,
1198                       struct iscsi_cmd *cmd, struct iser_rx_desc *rx_desc,
1199                       struct iscsi_text *hdr)
1200 {
1201         struct iscsi_conn *conn = isert_conn->conn;
1202         u32 payload_length = ntoh24(hdr->dlength);
1203         int rc;
1204         unsigned char *text_in;
1205
1206         rc = iscsit_setup_text_cmd(conn, cmd, hdr);
1207         if (rc < 0)
1208                 return rc;
1209
1210         text_in = kzalloc(payload_length, GFP_KERNEL);
1211         if (!text_in) {
1212                 pr_err("Unable to allocate text_in of payload_length: %u\n",
1213                        payload_length);
1214                 return -ENOMEM;
1215         }
1216         cmd->text_in_ptr = text_in;
1217
1218         memcpy(cmd->text_in_ptr, &rx_desc->data[0], payload_length);
1219
1220         return iscsit_process_text_cmd(conn, cmd, hdr);
1221 }
1222
1223 static int
1224 isert_rx_opcode(struct isert_conn *isert_conn, struct iser_rx_desc *rx_desc,
1225                 uint32_t read_stag, uint64_t read_va,
1226                 uint32_t write_stag, uint64_t write_va)
1227 {
1228         struct iscsi_hdr *hdr = &rx_desc->iscsi_header;
1229         struct iscsi_conn *conn = isert_conn->conn;
1230         struct iscsi_session *sess = conn->sess;
1231         struct iscsi_cmd *cmd;
1232         struct isert_cmd *isert_cmd;
1233         int ret = -EINVAL;
1234         u8 opcode = (hdr->opcode & ISCSI_OPCODE_MASK);
1235
1236         if (sess->sess_ops->SessionType &&
1237            (!(opcode & ISCSI_OP_TEXT) || !(opcode & ISCSI_OP_LOGOUT))) {
1238                 pr_err("Got illegal opcode: 0x%02x in SessionType=Discovery,"
1239                        " ignoring\n", opcode);
1240                 return 0;
1241         }
1242
1243         switch (opcode) {
1244         case ISCSI_OP_SCSI_CMD:
1245                 cmd = isert_allocate_cmd(conn);
1246                 if (!cmd)
1247                         break;
1248
1249                 isert_cmd = iscsit_priv_cmd(cmd);
1250                 isert_cmd->read_stag = read_stag;
1251                 isert_cmd->read_va = read_va;
1252                 isert_cmd->write_stag = write_stag;
1253                 isert_cmd->write_va = write_va;
1254
1255                 ret = isert_handle_scsi_cmd(isert_conn, isert_cmd, cmd,
1256                                         rx_desc, (unsigned char *)hdr);
1257                 break;
1258         case ISCSI_OP_NOOP_OUT:
1259                 cmd = isert_allocate_cmd(conn);
1260                 if (!cmd)
1261                         break;
1262
1263                 isert_cmd = iscsit_priv_cmd(cmd);
1264                 ret = isert_handle_nop_out(isert_conn, isert_cmd, cmd,
1265                                            rx_desc, (unsigned char *)hdr);
1266                 break;
1267         case ISCSI_OP_SCSI_DATA_OUT:
1268                 ret = isert_handle_iscsi_dataout(isert_conn, rx_desc,
1269                                                 (unsigned char *)hdr);
1270                 break;
1271         case ISCSI_OP_SCSI_TMFUNC:
1272                 cmd = isert_allocate_cmd(conn);
1273                 if (!cmd)
1274                         break;
1275
1276                 ret = iscsit_handle_task_mgt_cmd(conn, cmd,
1277                                                 (unsigned char *)hdr);
1278                 break;
1279         case ISCSI_OP_LOGOUT:
1280                 cmd = isert_allocate_cmd(conn);
1281                 if (!cmd)
1282                         break;
1283
1284                 ret = iscsit_handle_logout_cmd(conn, cmd, (unsigned char *)hdr);
1285                 if (ret > 0)
1286                         wait_for_completion_timeout(&conn->conn_logout_comp,
1287                                                     SECONDS_FOR_LOGOUT_COMP *
1288                                                     HZ);
1289                 break;
1290         case ISCSI_OP_TEXT:
1291                 cmd = isert_allocate_cmd(conn);
1292                 if (!cmd)
1293                         break;
1294
1295                 isert_cmd = iscsit_priv_cmd(cmd);
1296                 ret = isert_handle_text_cmd(isert_conn, isert_cmd, cmd,
1297                                             rx_desc, (struct iscsi_text *)hdr);
1298                 break;
1299         default:
1300                 pr_err("Got unknown iSCSI OpCode: 0x%02x\n", opcode);
1301                 dump_stack();
1302                 break;
1303         }
1304
1305         return ret;
1306 }
1307
1308 static void
1309 isert_rx_do_work(struct iser_rx_desc *rx_desc, struct isert_conn *isert_conn)
1310 {
1311         struct iser_hdr *iser_hdr = &rx_desc->iser_header;
1312         uint64_t read_va = 0, write_va = 0;
1313         uint32_t read_stag = 0, write_stag = 0;
1314         int rc;
1315
1316         switch (iser_hdr->flags & 0xF0) {
1317         case ISCSI_CTRL:
1318                 if (iser_hdr->flags & ISER_RSV) {
1319                         read_stag = be32_to_cpu(iser_hdr->read_stag);
1320                         read_va = be64_to_cpu(iser_hdr->read_va);
1321                         pr_debug("ISER_RSV: read_stag: 0x%08x read_va: 0x%16llx\n",
1322                                  read_stag, (unsigned long long)read_va);
1323                 }
1324                 if (iser_hdr->flags & ISER_WSV) {
1325                         write_stag = be32_to_cpu(iser_hdr->write_stag);
1326                         write_va = be64_to_cpu(iser_hdr->write_va);
1327                         pr_debug("ISER_WSV: write__stag: 0x%08x write_va: 0x%16llx\n",
1328                                  write_stag, (unsigned long long)write_va);
1329                 }
1330
1331                 pr_debug("ISER ISCSI_CTRL PDU\n");
1332                 break;
1333         case ISER_HELLO:
1334                 pr_err("iSER Hello message\n");
1335                 break;
1336         default:
1337                 pr_warn("Unknown iSER hdr flags: 0x%02x\n", iser_hdr->flags);
1338                 break;
1339         }
1340
1341         rc = isert_rx_opcode(isert_conn, rx_desc,
1342                              read_stag, read_va, write_stag, write_va);
1343 }
1344
1345 static void
1346 isert_rx_completion(struct iser_rx_desc *desc, struct isert_conn *isert_conn,
1347                     unsigned long xfer_len)
1348 {
1349         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
1350         struct iscsi_hdr *hdr;
1351         u64 rx_dma;
1352         int rx_buflen, outstanding;
1353
1354         if ((char *)desc == isert_conn->login_req_buf) {
1355                 rx_dma = isert_conn->login_req_dma;
1356                 rx_buflen = ISER_RX_LOGIN_SIZE;
1357                 pr_debug("ISER login_buf: Using rx_dma: 0x%llx, rx_buflen: %d\n",
1358                          rx_dma, rx_buflen);
1359         } else {
1360                 rx_dma = desc->dma_addr;
1361                 rx_buflen = ISER_RX_PAYLOAD_SIZE;
1362                 pr_debug("ISER req_buf: Using rx_dma: 0x%llx, rx_buflen: %d\n",
1363                          rx_dma, rx_buflen);
1364         }
1365
1366         ib_dma_sync_single_for_cpu(ib_dev, rx_dma, rx_buflen, DMA_FROM_DEVICE);
1367
1368         hdr = &desc->iscsi_header;
1369         pr_debug("iSCSI opcode: 0x%02x, ITT: 0x%08x, flags: 0x%02x dlen: %d\n",
1370                  hdr->opcode, hdr->itt, hdr->flags,
1371                  (int)(xfer_len - ISER_HEADERS_LEN));
1372
1373         if ((char *)desc == isert_conn->login_req_buf)
1374                 isert_rx_login_req(desc, xfer_len - ISER_HEADERS_LEN,
1375                                    isert_conn);
1376         else
1377                 isert_rx_do_work(desc, isert_conn);
1378
1379         ib_dma_sync_single_for_device(ib_dev, rx_dma, rx_buflen,
1380                                       DMA_FROM_DEVICE);
1381
1382         isert_conn->post_recv_buf_count--;
1383         pr_debug("iSERT: Decremented post_recv_buf_count: %d\n",
1384                  isert_conn->post_recv_buf_count);
1385
1386         if ((char *)desc == isert_conn->login_req_buf)
1387                 return;
1388
1389         outstanding = isert_conn->post_recv_buf_count;
1390         if (outstanding + ISERT_MIN_POSTED_RX <= ISERT_QP_MAX_RECV_DTOS) {
1391                 int err, count = min(ISERT_QP_MAX_RECV_DTOS - outstanding,
1392                                 ISERT_MIN_POSTED_RX);
1393                 err = isert_post_recv(isert_conn, count);
1394                 if (err) {
1395                         pr_err("isert_post_recv() count: %d failed, %d\n",
1396                                count, err);
1397                 }
1398         }
1399 }
1400
1401 static void
1402 isert_unmap_cmd(struct isert_cmd *isert_cmd, struct isert_conn *isert_conn)
1403 {
1404         struct isert_rdma_wr *wr = &isert_cmd->rdma_wr;
1405         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
1406
1407         pr_debug("isert_unmap_cmd: %p\n", isert_cmd);
1408         if (wr->sge) {
1409                 pr_debug("isert_unmap_cmd: %p unmap_sg op\n", isert_cmd);
1410                 ib_dma_unmap_sg(ib_dev, wr->sge, wr->num_sge,
1411                                 (wr->iser_ib_op == ISER_IB_RDMA_WRITE) ?
1412                                 DMA_TO_DEVICE : DMA_FROM_DEVICE);
1413                 wr->sge = NULL;
1414         }
1415
1416         if (wr->send_wr) {
1417                 pr_debug("isert_unmap_cmd: %p free send_wr\n", isert_cmd);
1418                 kfree(wr->send_wr);
1419                 wr->send_wr = NULL;
1420         }
1421
1422         if (wr->ib_sge) {
1423                 pr_debug("isert_unmap_cmd: %p free ib_sge\n", isert_cmd);
1424                 kfree(wr->ib_sge);
1425                 wr->ib_sge = NULL;
1426         }
1427 }
1428
1429 static void
1430 isert_unreg_rdma(struct isert_cmd *isert_cmd, struct isert_conn *isert_conn)
1431 {
1432         struct isert_rdma_wr *wr = &isert_cmd->rdma_wr;
1433         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
1434         LIST_HEAD(unmap_list);
1435
1436         pr_debug("unreg_fastreg_cmd: %p\n", isert_cmd);
1437
1438         if (wr->fr_desc) {
1439                 pr_debug("unreg_fastreg_cmd: %p free fr_desc %p\n",
1440                          isert_cmd, wr->fr_desc);
1441                 spin_lock_bh(&isert_conn->conn_lock);
1442                 list_add_tail(&wr->fr_desc->list, &isert_conn->conn_fr_pool);
1443                 spin_unlock_bh(&isert_conn->conn_lock);
1444                 wr->fr_desc = NULL;
1445         }
1446
1447         if (wr->sge) {
1448                 pr_debug("unreg_fastreg_cmd: %p unmap_sg op\n", isert_cmd);
1449                 ib_dma_unmap_sg(ib_dev, wr->sge, wr->num_sge,
1450                                 (wr->iser_ib_op == ISER_IB_RDMA_WRITE) ?
1451                                 DMA_TO_DEVICE : DMA_FROM_DEVICE);
1452                 wr->sge = NULL;
1453         }
1454
1455         wr->ib_sge = NULL;
1456         wr->send_wr = NULL;
1457 }
1458
1459 static void
1460 isert_put_cmd(struct isert_cmd *isert_cmd, bool comp_err)
1461 {
1462         struct iscsi_cmd *cmd = isert_cmd->iscsi_cmd;
1463         struct isert_conn *isert_conn = isert_cmd->conn;
1464         struct iscsi_conn *conn = isert_conn->conn;
1465         struct isert_device *device = isert_conn->conn_device;
1466
1467         pr_debug("Entering isert_put_cmd: %p\n", isert_cmd);
1468
1469         switch (cmd->iscsi_opcode) {
1470         case ISCSI_OP_SCSI_CMD:
1471                 spin_lock_bh(&conn->cmd_lock);
1472                 if (!list_empty(&cmd->i_conn_node))
1473                         list_del_init(&cmd->i_conn_node);
1474                 spin_unlock_bh(&conn->cmd_lock);
1475
1476                 if (cmd->data_direction == DMA_TO_DEVICE) {
1477                         iscsit_stop_dataout_timer(cmd);
1478                         /*
1479                          * Check for special case during comp_err where
1480                          * WRITE_PENDING has been handed off from core,
1481                          * but requires an extra target_put_sess_cmd()
1482                          * before transport_generic_free_cmd() below.
1483                          */
1484                         if (comp_err &&
1485                             cmd->se_cmd.t_state == TRANSPORT_WRITE_PENDING) {
1486                                 struct se_cmd *se_cmd = &cmd->se_cmd;
1487
1488                                 target_put_sess_cmd(se_cmd->se_sess, se_cmd);
1489                         }
1490                 }
1491
1492                 device->unreg_rdma_mem(isert_cmd, isert_conn);
1493                 transport_generic_free_cmd(&cmd->se_cmd, 0);
1494                 break;
1495         case ISCSI_OP_SCSI_TMFUNC:
1496                 spin_lock_bh(&conn->cmd_lock);
1497                 if (!list_empty(&cmd->i_conn_node))
1498                         list_del_init(&cmd->i_conn_node);
1499                 spin_unlock_bh(&conn->cmd_lock);
1500
1501                 transport_generic_free_cmd(&cmd->se_cmd, 0);
1502                 break;
1503         case ISCSI_OP_REJECT:
1504         case ISCSI_OP_NOOP_OUT:
1505         case ISCSI_OP_TEXT:
1506                 spin_lock_bh(&conn->cmd_lock);
1507                 if (!list_empty(&cmd->i_conn_node))
1508                         list_del_init(&cmd->i_conn_node);
1509                 spin_unlock_bh(&conn->cmd_lock);
1510
1511                 /*
1512                  * Handle special case for REJECT when iscsi_add_reject*() has
1513                  * overwritten the original iscsi_opcode assignment, and the
1514                  * associated cmd->se_cmd needs to be released.
1515                  */
1516                 if (cmd->se_cmd.se_tfo != NULL) {
1517                         pr_debug("Calling transport_generic_free_cmd from"
1518                                  " isert_put_cmd for 0x%02x\n",
1519                                  cmd->iscsi_opcode);
1520                         transport_generic_free_cmd(&cmd->se_cmd, 0);
1521                         break;
1522                 }
1523                 /*
1524                  * Fall-through
1525                  */
1526         default:
1527                 iscsit_release_cmd(cmd);
1528                 break;
1529         }
1530 }
1531
1532 static void
1533 isert_unmap_tx_desc(struct iser_tx_desc *tx_desc, struct ib_device *ib_dev)
1534 {
1535         if (tx_desc->dma_addr != 0) {
1536                 pr_debug("Calling ib_dma_unmap_single for tx_desc->dma_addr\n");
1537                 ib_dma_unmap_single(ib_dev, tx_desc->dma_addr,
1538                                     ISER_HEADERS_LEN, DMA_TO_DEVICE);
1539                 tx_desc->dma_addr = 0;
1540         }
1541 }
1542
1543 static void
1544 isert_completion_put(struct iser_tx_desc *tx_desc, struct isert_cmd *isert_cmd,
1545                      struct ib_device *ib_dev, bool comp_err)
1546 {
1547         if (isert_cmd->pdu_buf_dma != 0) {
1548                 pr_debug("Calling ib_dma_unmap_single for isert_cmd->pdu_buf_dma\n");
1549                 ib_dma_unmap_single(ib_dev, isert_cmd->pdu_buf_dma,
1550                                     isert_cmd->pdu_buf_len, DMA_TO_DEVICE);
1551                 isert_cmd->pdu_buf_dma = 0;
1552         }
1553
1554         isert_unmap_tx_desc(tx_desc, ib_dev);
1555         isert_put_cmd(isert_cmd, comp_err);
1556 }
1557
1558 static void
1559 isert_completion_rdma_read(struct iser_tx_desc *tx_desc,
1560                            struct isert_cmd *isert_cmd)
1561 {
1562         struct isert_rdma_wr *wr = &isert_cmd->rdma_wr;
1563         struct iscsi_cmd *cmd = isert_cmd->iscsi_cmd;
1564         struct se_cmd *se_cmd = &cmd->se_cmd;
1565         struct isert_conn *isert_conn = isert_cmd->conn;
1566         struct isert_device *device = isert_conn->conn_device;
1567
1568         iscsit_stop_dataout_timer(cmd);
1569         device->unreg_rdma_mem(isert_cmd, isert_conn);
1570         cmd->write_data_done = wr->cur_rdma_length;
1571         wr->send_wr_num = 0;
1572
1573         pr_debug("Cmd: %p RDMA_READ comp calling execute_cmd\n", isert_cmd);
1574         spin_lock_bh(&cmd->istate_lock);
1575         cmd->cmd_flags |= ICF_GOT_LAST_DATAOUT;
1576         cmd->i_state = ISTATE_RECEIVED_LAST_DATAOUT;
1577         spin_unlock_bh(&cmd->istate_lock);
1578
1579         target_execute_cmd(se_cmd);
1580 }
1581
1582 static void
1583 isert_do_control_comp(struct work_struct *work)
1584 {
1585         struct isert_cmd *isert_cmd = container_of(work,
1586                         struct isert_cmd, comp_work);
1587         struct isert_conn *isert_conn = isert_cmd->conn;
1588         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
1589         struct iscsi_cmd *cmd = isert_cmd->iscsi_cmd;
1590
1591         switch (cmd->i_state) {
1592         case ISTATE_SEND_TASKMGTRSP:
1593                 pr_debug("Calling iscsit_tmr_post_handler >>>>>>>>>>>>>>>>>\n");
1594
1595                 atomic_dec(&isert_conn->post_send_buf_count);
1596                 iscsit_tmr_post_handler(cmd, cmd->conn);
1597
1598                 cmd->i_state = ISTATE_SENT_STATUS;
1599                 isert_completion_put(&isert_cmd->tx_desc, isert_cmd, ib_dev, false);
1600                 break;
1601         case ISTATE_SEND_REJECT:
1602                 pr_debug("Got isert_do_control_comp ISTATE_SEND_REJECT: >>>\n");
1603                 atomic_dec(&isert_conn->post_send_buf_count);
1604
1605                 cmd->i_state = ISTATE_SENT_STATUS;
1606                 isert_completion_put(&isert_cmd->tx_desc, isert_cmd, ib_dev, false);
1607                 break;
1608         case ISTATE_SEND_LOGOUTRSP:
1609                 pr_debug("Calling iscsit_logout_post_handler >>>>>>>>>>>>>>\n");
1610                 /*
1611                  * Call atomic_dec(&isert_conn->post_send_buf_count)
1612                  * from isert_wait_conn()
1613                  */
1614                 isert_conn->logout_posted = true;
1615                 iscsit_logout_post_handler(cmd, cmd->conn);
1616                 break;
1617         case ISTATE_SEND_TEXTRSP:
1618                 atomic_dec(&isert_conn->post_send_buf_count);
1619                 cmd->i_state = ISTATE_SENT_STATUS;
1620                 isert_completion_put(&isert_cmd->tx_desc, isert_cmd, ib_dev, false);
1621                 break;
1622         default:
1623                 pr_err("Unknown do_control_comp i_state %d\n", cmd->i_state);
1624                 dump_stack();
1625                 break;
1626         }
1627 }
1628
1629 static void
1630 isert_response_completion(struct iser_tx_desc *tx_desc,
1631                           struct isert_cmd *isert_cmd,
1632                           struct isert_conn *isert_conn,
1633                           struct ib_device *ib_dev)
1634 {
1635         struct iscsi_cmd *cmd = isert_cmd->iscsi_cmd;
1636         struct isert_rdma_wr *wr = &isert_cmd->rdma_wr;
1637
1638         if (cmd->i_state == ISTATE_SEND_TASKMGTRSP ||
1639             cmd->i_state == ISTATE_SEND_LOGOUTRSP ||
1640             cmd->i_state == ISTATE_SEND_REJECT ||
1641             cmd->i_state == ISTATE_SEND_TEXTRSP) {
1642                 isert_unmap_tx_desc(tx_desc, ib_dev);
1643
1644                 INIT_WORK(&isert_cmd->comp_work, isert_do_control_comp);
1645                 queue_work(isert_comp_wq, &isert_cmd->comp_work);
1646                 return;
1647         }
1648         atomic_sub(wr->send_wr_num + 1, &isert_conn->post_send_buf_count);
1649
1650         cmd->i_state = ISTATE_SENT_STATUS;
1651         isert_completion_put(tx_desc, isert_cmd, ib_dev, false);
1652 }
1653
1654 static void
1655 __isert_send_completion(struct iser_tx_desc *tx_desc,
1656                         struct isert_conn *isert_conn)
1657 {
1658         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
1659         struct isert_cmd *isert_cmd = tx_desc->isert_cmd;
1660         struct isert_rdma_wr *wr;
1661
1662         if (!isert_cmd) {
1663                 atomic_dec(&isert_conn->post_send_buf_count);
1664                 isert_unmap_tx_desc(tx_desc, ib_dev);
1665                 return;
1666         }
1667         wr = &isert_cmd->rdma_wr;
1668
1669         switch (wr->iser_ib_op) {
1670         case ISER_IB_RECV:
1671                 pr_err("isert_send_completion: Got ISER_IB_RECV\n");
1672                 dump_stack();
1673                 break;
1674         case ISER_IB_SEND:
1675                 pr_debug("isert_send_completion: Got ISER_IB_SEND\n");
1676                 isert_response_completion(tx_desc, isert_cmd,
1677                                           isert_conn, ib_dev);
1678                 break;
1679         case ISER_IB_RDMA_WRITE:
1680                 pr_err("isert_send_completion: Got ISER_IB_RDMA_WRITE\n");
1681                 dump_stack();
1682                 break;
1683         case ISER_IB_RDMA_READ:
1684                 pr_debug("isert_send_completion: Got ISER_IB_RDMA_READ:\n");
1685
1686                 atomic_sub(wr->send_wr_num, &isert_conn->post_send_buf_count);
1687                 isert_completion_rdma_read(tx_desc, isert_cmd);
1688                 break;
1689         default:
1690                 pr_err("Unknown wr->iser_ib_op: 0x%02x\n", wr->iser_ib_op);
1691                 dump_stack();
1692                 break;
1693         }
1694 }
1695
1696 static void
1697 isert_send_completion(struct iser_tx_desc *tx_desc,
1698                       struct isert_conn *isert_conn)
1699 {
1700         struct llist_node *llnode = tx_desc->comp_llnode_batch;
1701         struct iser_tx_desc *t;
1702         /*
1703          * Drain coalesced completion llist starting from comp_llnode_batch
1704          * setup in isert_init_send_wr(), and then complete trailing tx_desc.
1705          */
1706         while (llnode) {
1707                 t = llist_entry(llnode, struct iser_tx_desc, comp_llnode);
1708                 llnode = llist_next(llnode);
1709                 __isert_send_completion(t, isert_conn);
1710         }
1711         __isert_send_completion(tx_desc, isert_conn);
1712 }
1713
1714 static void
1715 isert_cq_drain_comp_llist(struct isert_conn *isert_conn, struct ib_device *ib_dev)
1716 {
1717         struct llist_node *llnode;
1718         struct isert_rdma_wr *wr;
1719         struct iser_tx_desc *t;
1720
1721         mutex_lock(&isert_conn->conn_mutex);
1722         llnode = llist_del_all(&isert_conn->conn_comp_llist);
1723         isert_conn->conn_comp_batch = 0;
1724         mutex_unlock(&isert_conn->conn_mutex);
1725
1726         while (llnode) {
1727                 t = llist_entry(llnode, struct iser_tx_desc, comp_llnode);
1728                 llnode = llist_next(llnode);
1729                 wr = &t->isert_cmd->rdma_wr;
1730
1731                 atomic_sub(wr->send_wr_num + 1, &isert_conn->post_send_buf_count);
1732                 isert_completion_put(t, t->isert_cmd, ib_dev, true);
1733         }
1734 }
1735
1736 static void
1737 isert_cq_tx_comp_err(struct iser_tx_desc *tx_desc, struct isert_conn *isert_conn)
1738 {
1739         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
1740         struct isert_cmd *isert_cmd = tx_desc->isert_cmd;
1741         struct llist_node *llnode = tx_desc->comp_llnode_batch;
1742         struct isert_rdma_wr *wr;
1743         struct iser_tx_desc *t;
1744
1745         while (llnode) {
1746                 t = llist_entry(llnode, struct iser_tx_desc, comp_llnode);
1747                 llnode = llist_next(llnode);
1748                 wr = &t->isert_cmd->rdma_wr;
1749
1750                 atomic_sub(wr->send_wr_num + 1, &isert_conn->post_send_buf_count);
1751                 isert_completion_put(t, t->isert_cmd, ib_dev, true);
1752         }
1753         tx_desc->comp_llnode_batch = NULL;
1754
1755         if (!isert_cmd)
1756                 isert_unmap_tx_desc(tx_desc, ib_dev);
1757         else
1758                 isert_completion_put(tx_desc, isert_cmd, ib_dev, true);
1759 }
1760
1761 static void
1762 isert_cq_rx_comp_err(struct isert_conn *isert_conn)
1763 {
1764         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
1765         struct iscsi_conn *conn = isert_conn->conn;
1766
1767         if (isert_conn->post_recv_buf_count)
1768                 return;
1769
1770         isert_cq_drain_comp_llist(isert_conn, ib_dev);
1771
1772         if (conn->sess) {
1773                 target_sess_cmd_list_set_waiting(conn->sess->se_sess);
1774                 target_wait_for_sess_cmds(conn->sess->se_sess);
1775         }
1776
1777         while (atomic_read(&isert_conn->post_send_buf_count))
1778                 msleep(3000);
1779
1780         mutex_lock(&isert_conn->conn_mutex);
1781         isert_conn->state = ISER_CONN_DOWN;
1782         mutex_unlock(&isert_conn->conn_mutex);
1783
1784         complete(&isert_conn->conn_wait_comp_err);
1785 }
1786
1787 static void
1788 isert_cq_tx_work(struct work_struct *work)
1789 {
1790         struct isert_cq_desc *cq_desc = container_of(work,
1791                                 struct isert_cq_desc, cq_tx_work);
1792         struct isert_device *device = cq_desc->device;
1793         int cq_index = cq_desc->cq_index;
1794         struct ib_cq *tx_cq = device->dev_tx_cq[cq_index];
1795         struct isert_conn *isert_conn;
1796         struct iser_tx_desc *tx_desc;
1797         struct ib_wc wc;
1798
1799         while (ib_poll_cq(tx_cq, 1, &wc) == 1) {
1800                 tx_desc = (struct iser_tx_desc *)(unsigned long)wc.wr_id;
1801                 isert_conn = wc.qp->qp_context;
1802
1803                 if (wc.status == IB_WC_SUCCESS) {
1804                         isert_send_completion(tx_desc, isert_conn);
1805                 } else {
1806                         pr_debug("TX wc.status != IB_WC_SUCCESS >>>>>>>>>>>>>>\n");
1807                         pr_debug("TX wc.status: 0x%08x\n", wc.status);
1808                         pr_debug("TX wc.vendor_err: 0x%08x\n", wc.vendor_err);
1809
1810                         if (wc.wr_id != ISER_FASTREG_LI_WRID) {
1811                                 if (tx_desc->llnode_active)
1812                                         continue;
1813
1814                                 atomic_dec(&isert_conn->post_send_buf_count);
1815                                 isert_cq_tx_comp_err(tx_desc, isert_conn);
1816                         }
1817                 }
1818         }
1819
1820         ib_req_notify_cq(tx_cq, IB_CQ_NEXT_COMP);
1821 }
1822
1823 static void
1824 isert_cq_tx_callback(struct ib_cq *cq, void *context)
1825 {
1826         struct isert_cq_desc *cq_desc = (struct isert_cq_desc *)context;
1827
1828         queue_work(isert_comp_wq, &cq_desc->cq_tx_work);
1829 }
1830
1831 static void
1832 isert_cq_rx_work(struct work_struct *work)
1833 {
1834         struct isert_cq_desc *cq_desc = container_of(work,
1835                         struct isert_cq_desc, cq_rx_work);
1836         struct isert_device *device = cq_desc->device;
1837         int cq_index = cq_desc->cq_index;
1838         struct ib_cq *rx_cq = device->dev_rx_cq[cq_index];
1839         struct isert_conn *isert_conn;
1840         struct iser_rx_desc *rx_desc;
1841         struct ib_wc wc;
1842         unsigned long xfer_len;
1843
1844         while (ib_poll_cq(rx_cq, 1, &wc) == 1) {
1845                 rx_desc = (struct iser_rx_desc *)(unsigned long)wc.wr_id;
1846                 isert_conn = wc.qp->qp_context;
1847
1848                 if (wc.status == IB_WC_SUCCESS) {
1849                         xfer_len = (unsigned long)wc.byte_len;
1850                         isert_rx_completion(rx_desc, isert_conn, xfer_len);
1851                 } else {
1852                         pr_debug("RX wc.status != IB_WC_SUCCESS >>>>>>>>>>>>>>\n");
1853                         if (wc.status != IB_WC_WR_FLUSH_ERR) {
1854                                 pr_debug("RX wc.status: 0x%08x\n", wc.status);
1855                                 pr_debug("RX wc.vendor_err: 0x%08x\n",
1856                                          wc.vendor_err);
1857                         }
1858                         isert_conn->post_recv_buf_count--;
1859                         isert_cq_rx_comp_err(isert_conn);
1860                 }
1861         }
1862
1863         ib_req_notify_cq(rx_cq, IB_CQ_NEXT_COMP);
1864 }
1865
1866 static void
1867 isert_cq_rx_callback(struct ib_cq *cq, void *context)
1868 {
1869         struct isert_cq_desc *cq_desc = (struct isert_cq_desc *)context;
1870
1871         queue_work(isert_rx_wq, &cq_desc->cq_rx_work);
1872 }
1873
1874 static int
1875 isert_post_response(struct isert_conn *isert_conn, struct isert_cmd *isert_cmd)
1876 {
1877         struct ib_send_wr *wr_failed;
1878         int ret;
1879
1880         atomic_inc(&isert_conn->post_send_buf_count);
1881
1882         ret = ib_post_send(isert_conn->conn_qp, &isert_cmd->tx_desc.send_wr,
1883                            &wr_failed);
1884         if (ret) {
1885                 pr_err("ib_post_send failed with %d\n", ret);
1886                 atomic_dec(&isert_conn->post_send_buf_count);
1887                 return ret;
1888         }
1889         return ret;
1890 }
1891
1892 static int
1893 isert_put_response(struct iscsi_conn *conn, struct iscsi_cmd *cmd)
1894 {
1895         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
1896         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
1897         struct ib_send_wr *send_wr = &isert_cmd->tx_desc.send_wr;
1898         struct iscsi_scsi_rsp *hdr = (struct iscsi_scsi_rsp *)
1899                                 &isert_cmd->tx_desc.iscsi_header;
1900
1901         isert_create_send_desc(isert_conn, isert_cmd, &isert_cmd->tx_desc);
1902         iscsit_build_rsp_pdu(cmd, conn, true, hdr);
1903         isert_init_tx_hdrs(isert_conn, &isert_cmd->tx_desc);
1904         /*
1905          * Attach SENSE DATA payload to iSCSI Response PDU
1906          */
1907         if (cmd->se_cmd.sense_buffer &&
1908             ((cmd->se_cmd.se_cmd_flags & SCF_TRANSPORT_TASK_SENSE) ||
1909             (cmd->se_cmd.se_cmd_flags & SCF_EMULATED_TASK_SENSE))) {
1910                 struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
1911                 struct ib_sge *tx_dsg = &isert_cmd->tx_desc.tx_sg[1];
1912                 u32 padding, pdu_len;
1913
1914                 put_unaligned_be16(cmd->se_cmd.scsi_sense_length,
1915                                    cmd->sense_buffer);
1916                 cmd->se_cmd.scsi_sense_length += sizeof(__be16);
1917
1918                 padding = -(cmd->se_cmd.scsi_sense_length) & 3;
1919                 hton24(hdr->dlength, (u32)cmd->se_cmd.scsi_sense_length);
1920                 pdu_len = cmd->se_cmd.scsi_sense_length + padding;
1921
1922                 isert_cmd->pdu_buf_dma = ib_dma_map_single(ib_dev,
1923                                 (void *)cmd->sense_buffer, pdu_len,
1924                                 DMA_TO_DEVICE);
1925
1926                 isert_cmd->pdu_buf_len = pdu_len;
1927                 tx_dsg->addr    = isert_cmd->pdu_buf_dma;
1928                 tx_dsg->length  = pdu_len;
1929                 tx_dsg->lkey    = isert_conn->conn_mr->lkey;
1930                 isert_cmd->tx_desc.num_sge = 2;
1931         }
1932
1933         isert_init_send_wr(isert_conn, isert_cmd, send_wr, true);
1934
1935         pr_debug("Posting SCSI Response IB_WR_SEND >>>>>>>>>>>>>>>>>>>>>>\n");
1936
1937         return isert_post_response(isert_conn, isert_cmd);
1938 }
1939
1940 static int
1941 isert_put_nopin(struct iscsi_cmd *cmd, struct iscsi_conn *conn,
1942                 bool nopout_response)
1943 {
1944         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
1945         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
1946         struct ib_send_wr *send_wr = &isert_cmd->tx_desc.send_wr;
1947
1948         isert_create_send_desc(isert_conn, isert_cmd, &isert_cmd->tx_desc);
1949         iscsit_build_nopin_rsp(cmd, conn, (struct iscsi_nopin *)
1950                                &isert_cmd->tx_desc.iscsi_header,
1951                                nopout_response);
1952         isert_init_tx_hdrs(isert_conn, &isert_cmd->tx_desc);
1953         isert_init_send_wr(isert_conn, isert_cmd, send_wr, false);
1954
1955         pr_debug("Posting NOPIN Response IB_WR_SEND >>>>>>>>>>>>>>>>>>>>>>\n");
1956
1957         return isert_post_response(isert_conn, isert_cmd);
1958 }
1959
1960 static int
1961 isert_put_logout_rsp(struct iscsi_cmd *cmd, struct iscsi_conn *conn)
1962 {
1963         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
1964         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
1965         struct ib_send_wr *send_wr = &isert_cmd->tx_desc.send_wr;
1966
1967         isert_create_send_desc(isert_conn, isert_cmd, &isert_cmd->tx_desc);
1968         iscsit_build_logout_rsp(cmd, conn, (struct iscsi_logout_rsp *)
1969                                 &isert_cmd->tx_desc.iscsi_header);
1970         isert_init_tx_hdrs(isert_conn, &isert_cmd->tx_desc);
1971         isert_init_send_wr(isert_conn, isert_cmd, send_wr, false);
1972
1973         pr_debug("Posting Logout Response IB_WR_SEND >>>>>>>>>>>>>>>>>>>>>>\n");
1974
1975         return isert_post_response(isert_conn, isert_cmd);
1976 }
1977
1978 static int
1979 isert_put_tm_rsp(struct iscsi_cmd *cmd, struct iscsi_conn *conn)
1980 {
1981         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
1982         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
1983         struct ib_send_wr *send_wr = &isert_cmd->tx_desc.send_wr;
1984
1985         isert_create_send_desc(isert_conn, isert_cmd, &isert_cmd->tx_desc);
1986         iscsit_build_task_mgt_rsp(cmd, conn, (struct iscsi_tm_rsp *)
1987                                   &isert_cmd->tx_desc.iscsi_header);
1988         isert_init_tx_hdrs(isert_conn, &isert_cmd->tx_desc);
1989         isert_init_send_wr(isert_conn, isert_cmd, send_wr, false);
1990
1991         pr_debug("Posting Task Management Response IB_WR_SEND >>>>>>>>>>>>>>>>>>>>>>\n");
1992
1993         return isert_post_response(isert_conn, isert_cmd);
1994 }
1995
1996 static int
1997 isert_put_reject(struct iscsi_cmd *cmd, struct iscsi_conn *conn)
1998 {
1999         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
2000         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
2001         struct ib_send_wr *send_wr = &isert_cmd->tx_desc.send_wr;
2002         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
2003         struct ib_sge *tx_dsg = &isert_cmd->tx_desc.tx_sg[1];
2004         struct iscsi_reject *hdr =
2005                 (struct iscsi_reject *)&isert_cmd->tx_desc.iscsi_header;
2006
2007         isert_create_send_desc(isert_conn, isert_cmd, &isert_cmd->tx_desc);
2008         iscsit_build_reject(cmd, conn, hdr);
2009         isert_init_tx_hdrs(isert_conn, &isert_cmd->tx_desc);
2010
2011         hton24(hdr->dlength, ISCSI_HDR_LEN);
2012         isert_cmd->pdu_buf_dma = ib_dma_map_single(ib_dev,
2013                         (void *)cmd->buf_ptr, ISCSI_HDR_LEN,
2014                         DMA_TO_DEVICE);
2015         isert_cmd->pdu_buf_len = ISCSI_HDR_LEN;
2016         tx_dsg->addr    = isert_cmd->pdu_buf_dma;
2017         tx_dsg->length  = ISCSI_HDR_LEN;
2018         tx_dsg->lkey    = isert_conn->conn_mr->lkey;
2019         isert_cmd->tx_desc.num_sge = 2;
2020
2021         isert_init_send_wr(isert_conn, isert_cmd, send_wr, false);
2022
2023         pr_debug("Posting Reject IB_WR_SEND >>>>>>>>>>>>>>>>>>>>>>\n");
2024
2025         return isert_post_response(isert_conn, isert_cmd);
2026 }
2027
2028 static int
2029 isert_put_text_rsp(struct iscsi_cmd *cmd, struct iscsi_conn *conn)
2030 {
2031         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
2032         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
2033         struct ib_send_wr *send_wr = &isert_cmd->tx_desc.send_wr;
2034         struct iscsi_text_rsp *hdr =
2035                 (struct iscsi_text_rsp *)&isert_cmd->tx_desc.iscsi_header;
2036         u32 txt_rsp_len;
2037         int rc;
2038
2039         isert_create_send_desc(isert_conn, isert_cmd, &isert_cmd->tx_desc);
2040         rc = iscsit_build_text_rsp(cmd, conn, hdr);
2041         if (rc < 0)
2042                 return rc;
2043
2044         txt_rsp_len = rc;
2045         isert_init_tx_hdrs(isert_conn, &isert_cmd->tx_desc);
2046
2047         if (txt_rsp_len) {
2048                 struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
2049                 struct ib_sge *tx_dsg = &isert_cmd->tx_desc.tx_sg[1];
2050                 void *txt_rsp_buf = cmd->buf_ptr;
2051
2052                 isert_cmd->pdu_buf_dma = ib_dma_map_single(ib_dev,
2053                                 txt_rsp_buf, txt_rsp_len, DMA_TO_DEVICE);
2054
2055                 isert_cmd->pdu_buf_len = txt_rsp_len;
2056                 tx_dsg->addr    = isert_cmd->pdu_buf_dma;
2057                 tx_dsg->length  = txt_rsp_len;
2058                 tx_dsg->lkey    = isert_conn->conn_mr->lkey;
2059                 isert_cmd->tx_desc.num_sge = 2;
2060         }
2061         isert_init_send_wr(isert_conn, isert_cmd, send_wr, false);
2062
2063         pr_debug("Posting Text Response IB_WR_SEND >>>>>>>>>>>>>>>>>>>>>>\n");
2064
2065         return isert_post_response(isert_conn, isert_cmd);
2066 }
2067
2068 static int
2069 isert_build_rdma_wr(struct isert_conn *isert_conn, struct isert_cmd *isert_cmd,
2070                     struct ib_sge *ib_sge, struct ib_send_wr *send_wr,
2071                     u32 data_left, u32 offset)
2072 {
2073         struct iscsi_cmd *cmd = isert_cmd->iscsi_cmd;
2074         struct scatterlist *sg_start, *tmp_sg;
2075         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
2076         u32 sg_off, page_off;
2077         int i = 0, sg_nents;
2078
2079         sg_off = offset / PAGE_SIZE;
2080         sg_start = &cmd->se_cmd.t_data_sg[sg_off];
2081         sg_nents = min(cmd->se_cmd.t_data_nents - sg_off, isert_conn->max_sge);
2082         page_off = offset % PAGE_SIZE;
2083
2084         send_wr->sg_list = ib_sge;
2085         send_wr->num_sge = sg_nents;
2086         send_wr->wr_id = (unsigned long)&isert_cmd->tx_desc;
2087         /*
2088          * Perform mapping of TCM scatterlist memory ib_sge dma_addr.
2089          */
2090         for_each_sg(sg_start, tmp_sg, sg_nents, i) {
2091                 pr_debug("ISER RDMA from SGL dma_addr: 0x%16llx dma_len: %u, page_off: %u\n",
2092                          (unsigned long long)tmp_sg->dma_address,
2093                          tmp_sg->length, page_off);
2094
2095                 ib_sge->addr = ib_sg_dma_address(ib_dev, tmp_sg) + page_off;
2096                 ib_sge->length = min_t(u32, data_left,
2097                                 ib_sg_dma_len(ib_dev, tmp_sg) - page_off);
2098                 ib_sge->lkey = isert_conn->conn_mr->lkey;
2099
2100                 pr_debug("RDMA ib_sge: addr: 0x%16llx  length: %u lkey: %08x\n",
2101                          ib_sge->addr, ib_sge->length, ib_sge->lkey);
2102                 page_off = 0;
2103                 data_left -= ib_sge->length;
2104                 ib_sge++;
2105                 pr_debug("Incrementing ib_sge pointer to %p\n", ib_sge);
2106         }
2107
2108         pr_debug("Set outgoing sg_list: %p num_sg: %u from TCM SGLs\n",
2109                  send_wr->sg_list, send_wr->num_sge);
2110
2111         return sg_nents;
2112 }
2113
2114 static int
2115 isert_map_rdma(struct iscsi_conn *conn, struct iscsi_cmd *cmd,
2116                struct isert_rdma_wr *wr)
2117 {
2118         struct se_cmd *se_cmd = &cmd->se_cmd;
2119         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
2120         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
2121         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
2122         struct ib_send_wr *send_wr;
2123         struct ib_sge *ib_sge;
2124         struct scatterlist *sg_start;
2125         u32 sg_off = 0, sg_nents;
2126         u32 offset = 0, data_len, data_left, rdma_write_max, va_offset = 0;
2127         int ret = 0, count, i, ib_sge_cnt;
2128
2129         if (wr->iser_ib_op == ISER_IB_RDMA_WRITE) {
2130                 data_left = se_cmd->data_length;
2131         } else {
2132                 sg_off = cmd->write_data_done / PAGE_SIZE;
2133                 data_left = se_cmd->data_length - cmd->write_data_done;
2134                 offset = cmd->write_data_done;
2135                 isert_cmd->tx_desc.isert_cmd = isert_cmd;
2136         }
2137
2138         sg_start = &cmd->se_cmd.t_data_sg[sg_off];
2139         sg_nents = se_cmd->t_data_nents - sg_off;
2140
2141         count = ib_dma_map_sg(ib_dev, sg_start, sg_nents,
2142                               (wr->iser_ib_op == ISER_IB_RDMA_WRITE) ?
2143                               DMA_TO_DEVICE : DMA_FROM_DEVICE);
2144         if (unlikely(!count)) {
2145                 pr_err("Cmd: %p unrable to map SGs\n", isert_cmd);
2146                 return -EINVAL;
2147         }
2148         wr->sge = sg_start;
2149         wr->num_sge = sg_nents;
2150         wr->cur_rdma_length = data_left;
2151         pr_debug("Mapped cmd: %p count: %u sg: %p sg_nents: %u rdma_len %d\n",
2152                  isert_cmd, count, sg_start, sg_nents, data_left);
2153
2154         ib_sge = kzalloc(sizeof(struct ib_sge) * sg_nents, GFP_KERNEL);
2155         if (!ib_sge) {
2156                 pr_warn("Unable to allocate ib_sge\n");
2157                 ret = -ENOMEM;
2158                 goto unmap_sg;
2159         }
2160         wr->ib_sge = ib_sge;
2161
2162         wr->send_wr_num = DIV_ROUND_UP(sg_nents, isert_conn->max_sge);
2163         wr->send_wr = kzalloc(sizeof(struct ib_send_wr) * wr->send_wr_num,
2164                                 GFP_KERNEL);
2165         if (!wr->send_wr) {
2166                 pr_debug("Unable to allocate wr->send_wr\n");
2167                 ret = -ENOMEM;
2168                 goto unmap_sg;
2169         }
2170
2171         wr->isert_cmd = isert_cmd;
2172         rdma_write_max = isert_conn->max_sge * PAGE_SIZE;
2173
2174         for (i = 0; i < wr->send_wr_num; i++) {
2175                 send_wr = &isert_cmd->rdma_wr.send_wr[i];
2176                 data_len = min(data_left, rdma_write_max);
2177
2178                 send_wr->send_flags = 0;
2179                 if (wr->iser_ib_op == ISER_IB_RDMA_WRITE) {
2180                         send_wr->opcode = IB_WR_RDMA_WRITE;
2181                         send_wr->wr.rdma.remote_addr = isert_cmd->read_va + offset;
2182                         send_wr->wr.rdma.rkey = isert_cmd->read_stag;
2183                         if (i + 1 == wr->send_wr_num)
2184                                 send_wr->next = &isert_cmd->tx_desc.send_wr;
2185                         else
2186                                 send_wr->next = &wr->send_wr[i + 1];
2187                 } else {
2188                         send_wr->opcode = IB_WR_RDMA_READ;
2189                         send_wr->wr.rdma.remote_addr = isert_cmd->write_va + va_offset;
2190                         send_wr->wr.rdma.rkey = isert_cmd->write_stag;
2191                         if (i + 1 == wr->send_wr_num)
2192                                 send_wr->send_flags = IB_SEND_SIGNALED;
2193                         else
2194                                 send_wr->next = &wr->send_wr[i + 1];
2195                 }
2196
2197                 ib_sge_cnt = isert_build_rdma_wr(isert_conn, isert_cmd, ib_sge,
2198                                         send_wr, data_len, offset);
2199                 ib_sge += ib_sge_cnt;
2200
2201                 offset += data_len;
2202                 va_offset += data_len;
2203                 data_left -= data_len;
2204         }
2205
2206         return 0;
2207 unmap_sg:
2208         ib_dma_unmap_sg(ib_dev, sg_start, sg_nents,
2209                         (wr->iser_ib_op == ISER_IB_RDMA_WRITE) ?
2210                         DMA_TO_DEVICE : DMA_FROM_DEVICE);
2211         return ret;
2212 }
2213
2214 static int
2215 isert_map_fr_pagelist(struct ib_device *ib_dev,
2216                       struct scatterlist *sg_start, int sg_nents, u64 *fr_pl)
2217 {
2218         u64 start_addr, end_addr, page, chunk_start = 0;
2219         struct scatterlist *tmp_sg;
2220         int i = 0, new_chunk, last_ent, n_pages;
2221
2222         n_pages = 0;
2223         new_chunk = 1;
2224         last_ent = sg_nents - 1;
2225         for_each_sg(sg_start, tmp_sg, sg_nents, i) {
2226                 start_addr = ib_sg_dma_address(ib_dev, tmp_sg);
2227                 if (new_chunk)
2228                         chunk_start = start_addr;
2229                 end_addr = start_addr + ib_sg_dma_len(ib_dev, tmp_sg);
2230
2231                 pr_debug("SGL[%d] dma_addr: 0x%16llx len: %u\n",
2232                          i, (unsigned long long)tmp_sg->dma_address,
2233                          tmp_sg->length);
2234
2235                 if ((end_addr & ~PAGE_MASK) && i < last_ent) {
2236                         new_chunk = 0;
2237                         continue;
2238                 }
2239                 new_chunk = 1;
2240
2241                 page = chunk_start & PAGE_MASK;
2242                 do {
2243                         fr_pl[n_pages++] = page;
2244                         pr_debug("Mapped page_list[%d] page_addr: 0x%16llx\n",
2245                                  n_pages - 1, page);
2246                         page += PAGE_SIZE;
2247                 } while (page < end_addr);
2248         }
2249
2250         return n_pages;
2251 }
2252
2253 static int
2254 isert_fast_reg_mr(struct fast_reg_descriptor *fr_desc,
2255                   struct isert_conn *isert_conn, struct scatterlist *sg_start,
2256                   struct ib_sge *ib_sge, u32 sg_nents, u32 offset,
2257                   unsigned int data_len)
2258 {
2259         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
2260         struct ib_send_wr fr_wr, inv_wr;
2261         struct ib_send_wr *bad_wr, *wr = NULL;
2262         int ret, pagelist_len;
2263         u32 page_off;
2264         u8 key;
2265
2266         sg_nents = min_t(unsigned int, sg_nents, ISCSI_ISER_SG_TABLESIZE);
2267         page_off = offset % PAGE_SIZE;
2268
2269         pr_debug("Use fr_desc %p sg_nents %d offset %u\n",
2270                  fr_desc, sg_nents, offset);
2271
2272         pagelist_len = isert_map_fr_pagelist(ib_dev, sg_start, sg_nents,
2273                                              &fr_desc->data_frpl->page_list[0]);
2274
2275         if (!fr_desc->valid) {
2276                 memset(&inv_wr, 0, sizeof(inv_wr));
2277                 inv_wr.wr_id = ISER_FASTREG_LI_WRID;
2278                 inv_wr.opcode = IB_WR_LOCAL_INV;
2279                 inv_wr.ex.invalidate_rkey = fr_desc->data_mr->rkey;
2280                 wr = &inv_wr;
2281                 /* Bump the key */
2282                 key = (u8)(fr_desc->data_mr->rkey & 0x000000FF);
2283                 ib_update_fast_reg_key(fr_desc->data_mr, ++key);
2284         }
2285
2286         /* Prepare FASTREG WR */
2287         memset(&fr_wr, 0, sizeof(fr_wr));
2288         fr_wr.wr_id = ISER_FASTREG_LI_WRID;
2289         fr_wr.opcode = IB_WR_FAST_REG_MR;
2290         fr_wr.wr.fast_reg.iova_start =
2291                 fr_desc->data_frpl->page_list[0] + page_off;
2292         fr_wr.wr.fast_reg.page_list = fr_desc->data_frpl;
2293         fr_wr.wr.fast_reg.page_list_len = pagelist_len;
2294         fr_wr.wr.fast_reg.page_shift = PAGE_SHIFT;
2295         fr_wr.wr.fast_reg.length = data_len;
2296         fr_wr.wr.fast_reg.rkey = fr_desc->data_mr->rkey;
2297         fr_wr.wr.fast_reg.access_flags = IB_ACCESS_LOCAL_WRITE;
2298
2299         if (!wr)
2300                 wr = &fr_wr;
2301         else
2302                 wr->next = &fr_wr;
2303
2304         ret = ib_post_send(isert_conn->conn_qp, wr, &bad_wr);
2305         if (ret) {
2306                 pr_err("fast registration failed, ret:%d\n", ret);
2307                 return ret;
2308         }
2309         fr_desc->valid = false;
2310
2311         ib_sge->lkey = fr_desc->data_mr->lkey;
2312         ib_sge->addr = fr_desc->data_frpl->page_list[0] + page_off;
2313         ib_sge->length = data_len;
2314
2315         pr_debug("RDMA ib_sge: addr: 0x%16llx  length: %u lkey: %08x\n",
2316                  ib_sge->addr, ib_sge->length, ib_sge->lkey);
2317
2318         return ret;
2319 }
2320
2321 static int
2322 isert_reg_rdma(struct iscsi_conn *conn, struct iscsi_cmd *cmd,
2323                struct isert_rdma_wr *wr)
2324 {
2325         struct se_cmd *se_cmd = &cmd->se_cmd;
2326         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
2327         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
2328         struct ib_device *ib_dev = isert_conn->conn_cm_id->device;
2329         struct ib_send_wr *send_wr;
2330         struct ib_sge *ib_sge;
2331         struct scatterlist *sg_start;
2332         struct fast_reg_descriptor *fr_desc;
2333         u32 sg_off = 0, sg_nents;
2334         u32 offset = 0, data_len, data_left, rdma_write_max;
2335         int ret = 0, count;
2336         unsigned long flags;
2337
2338         if (wr->iser_ib_op == ISER_IB_RDMA_WRITE) {
2339                 data_left = se_cmd->data_length;
2340         } else {
2341                 offset = cmd->write_data_done;
2342                 sg_off = offset / PAGE_SIZE;
2343                 data_left = se_cmd->data_length - cmd->write_data_done;
2344                 isert_cmd->tx_desc.isert_cmd = isert_cmd;
2345         }
2346
2347         sg_start = &cmd->se_cmd.t_data_sg[sg_off];
2348         sg_nents = se_cmd->t_data_nents - sg_off;
2349
2350         count = ib_dma_map_sg(ib_dev, sg_start, sg_nents,
2351                               (wr->iser_ib_op == ISER_IB_RDMA_WRITE) ?
2352                               DMA_TO_DEVICE : DMA_FROM_DEVICE);
2353         if (unlikely(!count)) {
2354                 pr_err("Cmd: %p unrable to map SGs\n", isert_cmd);
2355                 return -EINVAL;
2356         }
2357         wr->sge = sg_start;
2358         wr->num_sge = sg_nents;
2359         pr_debug("Mapped cmd: %p count: %u sg: %p sg_nents: %u rdma_len %d\n",
2360                  isert_cmd, count, sg_start, sg_nents, data_left);
2361
2362         memset(&wr->s_ib_sge, 0, sizeof(*ib_sge));
2363         ib_sge = &wr->s_ib_sge;
2364         wr->ib_sge = ib_sge;
2365
2366         wr->send_wr_num = 1;
2367         memset(&wr->s_send_wr, 0, sizeof(*send_wr));
2368         wr->send_wr = &wr->s_send_wr;
2369
2370         wr->isert_cmd = isert_cmd;
2371         rdma_write_max = ISCSI_ISER_SG_TABLESIZE * PAGE_SIZE;
2372
2373         send_wr = &isert_cmd->rdma_wr.s_send_wr;
2374         send_wr->sg_list = ib_sge;
2375         send_wr->num_sge = 1;
2376         send_wr->wr_id = (unsigned long)&isert_cmd->tx_desc;
2377         if (wr->iser_ib_op == ISER_IB_RDMA_WRITE) {
2378                 send_wr->opcode = IB_WR_RDMA_WRITE;
2379                 send_wr->wr.rdma.remote_addr = isert_cmd->read_va;
2380                 send_wr->wr.rdma.rkey = isert_cmd->read_stag;
2381                 send_wr->send_flags = 0;
2382                 send_wr->next = &isert_cmd->tx_desc.send_wr;
2383         } else {
2384                 send_wr->opcode = IB_WR_RDMA_READ;
2385                 send_wr->wr.rdma.remote_addr = isert_cmd->write_va;
2386                 send_wr->wr.rdma.rkey = isert_cmd->write_stag;
2387                 send_wr->send_flags = IB_SEND_SIGNALED;
2388         }
2389
2390         data_len = min(data_left, rdma_write_max);
2391         wr->cur_rdma_length = data_len;
2392
2393         /* if there is a single dma entry, dma mr is sufficient */
2394         if (count == 1) {
2395                 ib_sge->addr = ib_sg_dma_address(ib_dev, &sg_start[0]);
2396                 ib_sge->length = ib_sg_dma_len(ib_dev, &sg_start[0]);
2397                 ib_sge->lkey = isert_conn->conn_mr->lkey;
2398                 wr->fr_desc = NULL;
2399         } else {
2400                 spin_lock_irqsave(&isert_conn->conn_lock, flags);
2401                 fr_desc = list_first_entry(&isert_conn->conn_fr_pool,
2402                                            struct fast_reg_descriptor, list);
2403                 list_del(&fr_desc->list);
2404                 spin_unlock_irqrestore(&isert_conn->conn_lock, flags);
2405                 wr->fr_desc = fr_desc;
2406
2407                 ret = isert_fast_reg_mr(fr_desc, isert_conn, sg_start,
2408                                         ib_sge, sg_nents, offset, data_len);
2409                 if (ret) {
2410                         list_add_tail(&fr_desc->list, &isert_conn->conn_fr_pool);
2411                         goto unmap_sg;
2412                 }
2413         }
2414
2415         return 0;
2416
2417 unmap_sg:
2418         ib_dma_unmap_sg(ib_dev, sg_start, sg_nents,
2419                         (wr->iser_ib_op == ISER_IB_RDMA_WRITE) ?
2420                         DMA_TO_DEVICE : DMA_FROM_DEVICE);
2421         return ret;
2422 }
2423
2424 static int
2425 isert_put_datain(struct iscsi_conn *conn, struct iscsi_cmd *cmd)
2426 {
2427         struct se_cmd *se_cmd = &cmd->se_cmd;
2428         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
2429         struct isert_rdma_wr *wr = &isert_cmd->rdma_wr;
2430         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
2431         struct isert_device *device = isert_conn->conn_device;
2432         struct ib_send_wr *wr_failed;
2433         int rc;
2434
2435         pr_debug("Cmd: %p RDMA_WRITE data_length: %u\n",
2436                  isert_cmd, se_cmd->data_length);
2437         wr->iser_ib_op = ISER_IB_RDMA_WRITE;
2438         rc = device->reg_rdma_mem(conn, cmd, wr);
2439         if (rc) {
2440                 pr_err("Cmd: %p failed to prepare RDMA res\n", isert_cmd);
2441                 return rc;
2442         }
2443
2444         /*
2445          * Build isert_conn->tx_desc for iSCSI response PDU and attach
2446          */
2447         isert_create_send_desc(isert_conn, isert_cmd, &isert_cmd->tx_desc);
2448         iscsit_build_rsp_pdu(cmd, conn, true, (struct iscsi_scsi_rsp *)
2449                              &isert_cmd->tx_desc.iscsi_header);
2450         isert_init_tx_hdrs(isert_conn, &isert_cmd->tx_desc);
2451         isert_init_send_wr(isert_conn, isert_cmd,
2452                            &isert_cmd->tx_desc.send_wr, true);
2453
2454         atomic_add(wr->send_wr_num + 1, &isert_conn->post_send_buf_count);
2455
2456         rc = ib_post_send(isert_conn->conn_qp, wr->send_wr, &wr_failed);
2457         if (rc) {
2458                 pr_warn("ib_post_send() failed for IB_WR_RDMA_WRITE\n");
2459                 atomic_sub(wr->send_wr_num + 1, &isert_conn->post_send_buf_count);
2460         }
2461         pr_debug("Cmd: %p posted RDMA_WRITE + Response for iSER Data READ\n",
2462                  isert_cmd);
2463
2464         return 1;
2465 }
2466
2467 static int
2468 isert_get_dataout(struct iscsi_conn *conn, struct iscsi_cmd *cmd, bool recovery)
2469 {
2470         struct se_cmd *se_cmd = &cmd->se_cmd;
2471         struct isert_cmd *isert_cmd = iscsit_priv_cmd(cmd);
2472         struct isert_rdma_wr *wr = &isert_cmd->rdma_wr;
2473         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
2474         struct isert_device *device = isert_conn->conn_device;
2475         struct ib_send_wr *wr_failed;
2476         int rc;
2477
2478         pr_debug("Cmd: %p RDMA_READ data_length: %u write_data_done: %u\n",
2479                  isert_cmd, se_cmd->data_length, cmd->write_data_done);
2480         wr->iser_ib_op = ISER_IB_RDMA_READ;
2481         rc = device->reg_rdma_mem(conn, cmd, wr);
2482         if (rc) {
2483                 pr_err("Cmd: %p failed to prepare RDMA res\n", isert_cmd);
2484                 return rc;
2485         }
2486
2487         atomic_add(wr->send_wr_num, &isert_conn->post_send_buf_count);
2488
2489         rc = ib_post_send(isert_conn->conn_qp, wr->send_wr, &wr_failed);
2490         if (rc) {
2491                 pr_warn("ib_post_send() failed for IB_WR_RDMA_READ\n");
2492                 atomic_sub(wr->send_wr_num, &isert_conn->post_send_buf_count);
2493         }
2494         pr_debug("Cmd: %p posted RDMA_READ memory for ISER Data WRITE\n",
2495                  isert_cmd);
2496
2497         return 0;
2498 }
2499
2500 static int
2501 isert_immediate_queue(struct iscsi_conn *conn, struct iscsi_cmd *cmd, int state)
2502 {
2503         int ret;
2504
2505         switch (state) {
2506         case ISTATE_SEND_NOPIN_WANT_RESPONSE:
2507                 ret = isert_put_nopin(cmd, conn, false);
2508                 break;
2509         default:
2510                 pr_err("Unknown immediate state: 0x%02x\n", state);
2511                 ret = -EINVAL;
2512                 break;
2513         }
2514
2515         return ret;
2516 }
2517
2518 static int
2519 isert_response_queue(struct iscsi_conn *conn, struct iscsi_cmd *cmd, int state)
2520 {
2521         int ret;
2522
2523         switch (state) {
2524         case ISTATE_SEND_LOGOUTRSP:
2525                 ret = isert_put_logout_rsp(cmd, conn);
2526                 if (!ret) {
2527                         pr_debug("Returning iSER Logout -EAGAIN\n");
2528                         ret = -EAGAIN;
2529                 }
2530                 break;
2531         case ISTATE_SEND_NOPIN:
2532                 ret = isert_put_nopin(cmd, conn, true);
2533                 break;
2534         case ISTATE_SEND_TASKMGTRSP:
2535                 ret = isert_put_tm_rsp(cmd, conn);
2536                 break;
2537         case ISTATE_SEND_REJECT:
2538                 ret = isert_put_reject(cmd, conn);
2539                 break;
2540         case ISTATE_SEND_TEXTRSP:
2541                 ret = isert_put_text_rsp(cmd, conn);
2542                 break;
2543         case ISTATE_SEND_STATUS:
2544                 /*
2545                  * Special case for sending non GOOD SCSI status from TX thread
2546                  * context during pre se_cmd excecution failure.
2547                  */
2548                 ret = isert_put_response(conn, cmd);
2549                 break;
2550         default:
2551                 pr_err("Unknown response state: 0x%02x\n", state);
2552                 ret = -EINVAL;
2553                 break;
2554         }
2555
2556         return ret;
2557 }
2558
2559 static int
2560 isert_setup_np(struct iscsi_np *np,
2561                struct __kernel_sockaddr_storage *ksockaddr)
2562 {
2563         struct isert_np *isert_np;
2564         struct rdma_cm_id *isert_lid;
2565         struct sockaddr *sa;
2566         int ret;
2567
2568         isert_np = kzalloc(sizeof(struct isert_np), GFP_KERNEL);
2569         if (!isert_np) {
2570                 pr_err("Unable to allocate struct isert_np\n");
2571                 return -ENOMEM;
2572         }
2573         sema_init(&isert_np->np_sem, 0);
2574         mutex_init(&isert_np->np_accept_mutex);
2575         INIT_LIST_HEAD(&isert_np->np_accept_list);
2576         init_completion(&isert_np->np_login_comp);
2577
2578         sa = (struct sockaddr *)ksockaddr;
2579         pr_debug("ksockaddr: %p, sa: %p\n", ksockaddr, sa);
2580         /*
2581          * Setup the np->np_sockaddr from the passed sockaddr setup
2582          * in iscsi_target_configfs.c code..
2583          */
2584         memcpy(&np->np_sockaddr, ksockaddr,
2585                sizeof(struct __kernel_sockaddr_storage));
2586
2587         isert_lid = rdma_create_id(isert_cma_handler, np, RDMA_PS_TCP,
2588                                 IB_QPT_RC);
2589         if (IS_ERR(isert_lid)) {
2590                 pr_err("rdma_create_id() for isert_listen_handler failed: %ld\n",
2591                        PTR_ERR(isert_lid));
2592                 ret = PTR_ERR(isert_lid);
2593                 goto out;
2594         }
2595
2596         ret = rdma_bind_addr(isert_lid, sa);
2597         if (ret) {
2598                 pr_err("rdma_bind_addr() for isert_lid failed: %d\n", ret);
2599                 goto out_lid;
2600         }
2601
2602         ret = rdma_listen(isert_lid, ISERT_RDMA_LISTEN_BACKLOG);
2603         if (ret) {
2604                 pr_err("rdma_listen() for isert_lid failed: %d\n", ret);
2605                 goto out_lid;
2606         }
2607
2608         isert_np->np_cm_id = isert_lid;
2609         np->np_context = isert_np;
2610         pr_debug("Setup isert_lid->context: %p\n", isert_lid->context);
2611
2612         return 0;
2613
2614 out_lid:
2615         rdma_destroy_id(isert_lid);
2616 out:
2617         kfree(isert_np);
2618         return ret;
2619 }
2620
2621 static int
2622 isert_rdma_accept(struct isert_conn *isert_conn)
2623 {
2624         struct rdma_cm_id *cm_id = isert_conn->conn_cm_id;
2625         struct rdma_conn_param cp;
2626         int ret;
2627
2628         memset(&cp, 0, sizeof(struct rdma_conn_param));
2629         cp.responder_resources = isert_conn->responder_resources;
2630         cp.initiator_depth = isert_conn->initiator_depth;
2631         cp.retry_count = 7;
2632         cp.rnr_retry_count = 7;
2633
2634         pr_debug("Before rdma_accept >>>>>>>>>>>>>>>>>>>>.\n");
2635
2636         ret = rdma_accept(cm_id, &cp);
2637         if (ret) {
2638                 pr_err("rdma_accept() failed with: %d\n", ret);
2639                 return ret;
2640         }
2641
2642         pr_debug("After rdma_accept >>>>>>>>>>>>>>>>>>>>>.\n");
2643
2644         return 0;
2645 }
2646
2647 static int
2648 isert_get_login_rx(struct iscsi_conn *conn, struct iscsi_login *login)
2649 {
2650         struct isert_conn *isert_conn = (struct isert_conn *)conn->context;
2651         int ret;
2652
2653         pr_debug("isert_get_login_rx before conn_login_comp conn: %p\n", conn);
2654         /*
2655          * For login requests after the first PDU, isert_rx_login_req() will
2656          * kick schedule_delayed_work(&conn->login_work) as the packet is
2657          * received, which turns this callback from iscsi_target_do_login_rx()
2658          * into a NOP.
2659          */
2660         if (!login->first_request)
2661                 return 0;
2662
2663         ret = wait_for_completion_interruptible(&isert_conn->conn_login_comp);
2664         if (ret)
2665                 return ret;
2666
2667         pr_debug("isert_get_login_rx processing login->req: %p\n", login->req);
2668         return 0;
2669 }
2670
2671 static void
2672 isert_set_conn_info(struct iscsi_np *np, struct iscsi_conn *conn,
2673                     struct isert_conn *isert_conn)
2674 {
2675         struct rdma_cm_id *cm_id = isert_conn->conn_cm_id;
2676         struct rdma_route *cm_route = &cm_id->route;
2677         struct sockaddr_in *sock_in;
2678         struct sockaddr_in6 *sock_in6;
2679
2680         conn->login_family = np->np_sockaddr.ss_family;
2681
2682         if (np->np_sockaddr.ss_family == AF_INET6) {
2683                 sock_in6 = (struct sockaddr_in6 *)&cm_route->addr.dst_addr;
2684                 snprintf(conn->login_ip, sizeof(conn->login_ip), "%pI6c",
2685                          &sock_in6->sin6_addr.in6_u);
2686                 conn->login_port = ntohs(sock_in6->sin6_port);
2687
2688                 sock_in6 = (struct sockaddr_in6 *)&cm_route->addr.src_addr;
2689                 snprintf(conn->local_ip, sizeof(conn->local_ip), "%pI6c",
2690                          &sock_in6->sin6_addr.in6_u);
2691                 conn->local_port = ntohs(sock_in6->sin6_port);
2692         } else {
2693                 sock_in = (struct sockaddr_in *)&cm_route->addr.dst_addr;
2694                 sprintf(conn->login_ip, "%pI4",
2695                         &sock_in->sin_addr.s_addr);
2696                 conn->login_port = ntohs(sock_in->sin_port);
2697
2698                 sock_in = (struct sockaddr_in *)&cm_route->addr.src_addr;
2699                 sprintf(conn->local_ip, "%pI4",
2700                         &sock_in->sin_addr.s_addr);
2701                 conn->local_port = ntohs(sock_in->sin_port);
2702         }
2703 }
2704
2705 static int
2706 isert_accept_np(struct iscsi_np *np, struct iscsi_conn *conn)
2707 {
2708         struct isert_np *isert_np = (struct isert_np *)np->np_context;
2709         struct isert_conn *isert_conn;
2710         int max_accept = 0, ret;
2711
2712 accept_wait:
2713         ret = down_interruptible(&isert_np->np_sem);
2714         if (max_accept > 5)
2715                 return -ENODEV;
2716
2717         spin_lock_bh(&np->np_thread_lock);
2718         if (np->np_thread_state == ISCSI_NP_THREAD_RESET) {
2719                 spin_unlock_bh(&np->np_thread_lock);
2720                 pr_debug("ISCSI_NP_THREAD_RESET for isert_accept_np\n");
2721                 return -ENODEV;
2722         }
2723         spin_unlock_bh(&np->np_thread_lock);
2724
2725         mutex_lock(&isert_np->np_accept_mutex);
2726         if (list_empty(&isert_np->np_accept_list)) {
2727                 mutex_unlock(&isert_np->np_accept_mutex);
2728                 max_accept++;
2729                 goto accept_wait;
2730         }
2731         isert_conn = list_first_entry(&isert_np->np_accept_list,
2732                         struct isert_conn, conn_accept_node);
2733         list_del_init(&isert_conn->conn_accept_node);
2734         mutex_unlock(&isert_np->np_accept_mutex);
2735
2736         conn->context = isert_conn;
2737         isert_conn->conn = conn;
2738         max_accept = 0;
2739
2740         ret = isert_rdma_post_recvl(isert_conn);
2741         if (ret)
2742                 return ret;
2743
2744         ret = isert_rdma_accept(isert_conn);
2745         if (ret)
2746                 return ret;
2747
2748         isert_set_conn_info(np, conn, isert_conn);
2749
2750         pr_debug("Processing isert_accept_np: isert_conn: %p\n", isert_conn);
2751         return 0;
2752 }
2753
2754 static void
2755 isert_free_np(struct iscsi_np *np)
2756 {
2757         struct isert_np *isert_np = (struct isert_np *)np->np_context;
2758
2759         rdma_destroy_id(isert_np->np_cm_id);
2760
2761         np->np_context = NULL;
2762         kfree(isert_np);
2763 }
2764
2765 static void isert_wait_conn(struct iscsi_conn *conn)
2766 {
2767         struct isert_conn *isert_conn = conn->context;
2768
2769         pr_debug("isert_wait_conn: Starting \n");
2770         /*
2771          * Decrement post_send_buf_count for special case when called
2772          * from isert_do_control_comp() -> iscsit_logout_post_handler()
2773          */
2774         mutex_lock(&isert_conn->conn_mutex);
2775         if (isert_conn->logout_posted)
2776                 atomic_dec(&isert_conn->post_send_buf_count);
2777
2778         if (isert_conn->conn_cm_id && isert_conn->state != ISER_CONN_DOWN) {
2779                 pr_debug("Calling rdma_disconnect from isert_wait_conn\n");
2780                 rdma_disconnect(isert_conn->conn_cm_id);
2781         }
2782         /*
2783          * Only wait for conn_wait_comp_err if the isert_conn made it
2784          * into full feature phase..
2785          */
2786         if (isert_conn->state == ISER_CONN_INIT) {
2787                 mutex_unlock(&isert_conn->conn_mutex);
2788                 return;
2789         }
2790         if (isert_conn->state == ISER_CONN_UP)
2791                 isert_conn->state = ISER_CONN_TERMINATING;
2792         mutex_unlock(&isert_conn->conn_mutex);
2793
2794         wait_for_completion(&isert_conn->conn_wait_comp_err);
2795
2796         wait_for_completion(&isert_conn->conn_wait);
2797 }
2798
2799 static void isert_free_conn(struct iscsi_conn *conn)
2800 {
2801         struct isert_conn *isert_conn = conn->context;
2802
2803         isert_put_conn(isert_conn);
2804 }
2805
2806 static struct iscsit_transport iser_target_transport = {
2807         .name                   = "IB/iSER",
2808         .transport_type         = ISCSI_INFINIBAND,
2809         .priv_size              = sizeof(struct isert_cmd),
2810         .owner                  = THIS_MODULE,
2811         .iscsit_setup_np        = isert_setup_np,
2812         .iscsit_accept_np       = isert_accept_np,
2813         .iscsit_free_np         = isert_free_np,
2814         .iscsit_wait_conn       = isert_wait_conn,
2815         .iscsit_free_conn       = isert_free_conn,
2816         .iscsit_get_login_rx    = isert_get_login_rx,
2817         .iscsit_put_login_tx    = isert_put_login_tx,
2818         .iscsit_immediate_queue = isert_immediate_queue,
2819         .iscsit_response_queue  = isert_response_queue,
2820         .iscsit_get_dataout     = isert_get_dataout,
2821         .iscsit_queue_data_in   = isert_put_datain,
2822         .iscsit_queue_status    = isert_put_response,
2823 };
2824
2825 static int __init isert_init(void)
2826 {
2827         int ret;
2828
2829         isert_rx_wq = alloc_workqueue("isert_rx_wq", 0, 0);
2830         if (!isert_rx_wq) {
2831                 pr_err("Unable to allocate isert_rx_wq\n");
2832                 return -ENOMEM;
2833         }
2834
2835         isert_comp_wq = alloc_workqueue("isert_comp_wq", 0, 0);
2836         if (!isert_comp_wq) {
2837                 pr_err("Unable to allocate isert_comp_wq\n");
2838                 ret = -ENOMEM;
2839                 goto destroy_rx_wq;
2840         }
2841
2842         iscsit_register_transport(&iser_target_transport);
2843         pr_debug("iSER_TARGET[0] - Loaded iser_target_transport\n");
2844         return 0;
2845
2846 destroy_rx_wq:
2847         destroy_workqueue(isert_rx_wq);
2848         return ret;
2849 }
2850
2851 static void __exit isert_exit(void)
2852 {
2853         destroy_workqueue(isert_comp_wq);
2854         destroy_workqueue(isert_rx_wq);
2855         iscsit_unregister_transport(&iser_target_transport);
2856         pr_debug("iSER_TARGET[0] - Released iser_target_transport\n");
2857 }
2858
2859 MODULE_DESCRIPTION("iSER-Target for mainline target infrastructure");
2860 MODULE_VERSION("0.1");
2861 MODULE_AUTHOR("nab@Linux-iSCSI.org");
2862 MODULE_LICENSE("GPL");
2863
2864 module_init(isert_init);
2865 module_exit(isert_exit);