nvmet-tcp: fix a crash in nvmet_req_complete()
[platform/kernel/linux-starfive.git] / drivers / nvme / target / tcp.c
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3  * NVMe over Fabrics TCP target.
4  * Copyright (c) 2018 Lightbits Labs. All rights reserved.
5  */
6 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
7 #include <linux/module.h>
8 #include <linux/init.h>
9 #include <linux/slab.h>
10 #include <linux/err.h>
11 #include <linux/nvme-tcp.h>
12 #include <net/sock.h>
13 #include <net/tcp.h>
14 #include <linux/inet.h>
15 #include <linux/llist.h>
16 #include <crypto/hash.h>
17 #include <trace/events/sock.h>
18
19 #include "nvmet.h"
20
21 #define NVMET_TCP_DEF_INLINE_DATA_SIZE  (4 * PAGE_SIZE)
22 #define NVMET_TCP_MAXH2CDATA            0x400000 /* 16M arbitrary limit */
23
24 static int param_store_val(const char *str, int *val, int min, int max)
25 {
26         int ret, new_val;
27
28         ret = kstrtoint(str, 10, &new_val);
29         if (ret)
30                 return -EINVAL;
31
32         if (new_val < min || new_val > max)
33                 return -EINVAL;
34
35         *val = new_val;
36         return 0;
37 }
38
39 static int set_params(const char *str, const struct kernel_param *kp)
40 {
41         return param_store_val(str, kp->arg, 0, INT_MAX);
42 }
43
44 static const struct kernel_param_ops set_param_ops = {
45         .set    = set_params,
46         .get    = param_get_int,
47 };
48
49 /* Define the socket priority to use for connections were it is desirable
50  * that the NIC consider performing optimized packet processing or filtering.
51  * A non-zero value being sufficient to indicate general consideration of any
52  * possible optimization.  Making it a module param allows for alternative
53  * values that may be unique for some NIC implementations.
54  */
55 static int so_priority;
56 device_param_cb(so_priority, &set_param_ops, &so_priority, 0644);
57 MODULE_PARM_DESC(so_priority, "nvmet tcp socket optimize priority: Default 0");
58
59 /* Define a time period (in usecs) that io_work() shall sample an activated
60  * queue before determining it to be idle.  This optional module behavior
61  * can enable NIC solutions that support socket optimized packet processing
62  * using advanced interrupt moderation techniques.
63  */
64 static int idle_poll_period_usecs;
65 device_param_cb(idle_poll_period_usecs, &set_param_ops,
66                 &idle_poll_period_usecs, 0644);
67 MODULE_PARM_DESC(idle_poll_period_usecs,
68                 "nvmet tcp io_work poll till idle time period in usecs: Default 0");
69
70 #define NVMET_TCP_RECV_BUDGET           8
71 #define NVMET_TCP_SEND_BUDGET           8
72 #define NVMET_TCP_IO_WORK_BUDGET        64
73
74 enum nvmet_tcp_send_state {
75         NVMET_TCP_SEND_DATA_PDU,
76         NVMET_TCP_SEND_DATA,
77         NVMET_TCP_SEND_R2T,
78         NVMET_TCP_SEND_DDGST,
79         NVMET_TCP_SEND_RESPONSE
80 };
81
82 enum nvmet_tcp_recv_state {
83         NVMET_TCP_RECV_PDU,
84         NVMET_TCP_RECV_DATA,
85         NVMET_TCP_RECV_DDGST,
86         NVMET_TCP_RECV_ERR,
87 };
88
89 enum {
90         NVMET_TCP_F_INIT_FAILED = (1 << 0),
91 };
92
93 struct nvmet_tcp_cmd {
94         struct nvmet_tcp_queue          *queue;
95         struct nvmet_req                req;
96
97         struct nvme_tcp_cmd_pdu         *cmd_pdu;
98         struct nvme_tcp_rsp_pdu         *rsp_pdu;
99         struct nvme_tcp_data_pdu        *data_pdu;
100         struct nvme_tcp_r2t_pdu         *r2t_pdu;
101
102         u32                             rbytes_done;
103         u32                             wbytes_done;
104
105         u32                             pdu_len;
106         u32                             pdu_recv;
107         int                             sg_idx;
108         struct msghdr                   recv_msg;
109         struct bio_vec                  *iov;
110         u32                             flags;
111
112         struct list_head                entry;
113         struct llist_node               lentry;
114
115         /* send state */
116         u32                             offset;
117         struct scatterlist              *cur_sg;
118         enum nvmet_tcp_send_state       state;
119
120         __le32                          exp_ddgst;
121         __le32                          recv_ddgst;
122 };
123
124 enum nvmet_tcp_queue_state {
125         NVMET_TCP_Q_CONNECTING,
126         NVMET_TCP_Q_LIVE,
127         NVMET_TCP_Q_DISCONNECTING,
128 };
129
130 struct nvmet_tcp_queue {
131         struct socket           *sock;
132         struct nvmet_tcp_port   *port;
133         struct work_struct      io_work;
134         struct nvmet_cq         nvme_cq;
135         struct nvmet_sq         nvme_sq;
136
137         /* send state */
138         struct nvmet_tcp_cmd    *cmds;
139         unsigned int            nr_cmds;
140         struct list_head        free_list;
141         struct llist_head       resp_list;
142         struct list_head        resp_send_list;
143         int                     send_list_len;
144         struct nvmet_tcp_cmd    *snd_cmd;
145
146         /* recv state */
147         int                     offset;
148         int                     left;
149         enum nvmet_tcp_recv_state rcv_state;
150         struct nvmet_tcp_cmd    *cmd;
151         union nvme_tcp_pdu      pdu;
152
153         /* digest state */
154         bool                    hdr_digest;
155         bool                    data_digest;
156         struct ahash_request    *snd_hash;
157         struct ahash_request    *rcv_hash;
158
159         unsigned long           poll_end;
160
161         spinlock_t              state_lock;
162         enum nvmet_tcp_queue_state state;
163
164         struct sockaddr_storage sockaddr;
165         struct sockaddr_storage sockaddr_peer;
166         struct work_struct      release_work;
167
168         int                     idx;
169         struct list_head        queue_list;
170
171         struct nvmet_tcp_cmd    connect;
172
173         struct page_frag_cache  pf_cache;
174
175         void (*data_ready)(struct sock *);
176         void (*state_change)(struct sock *);
177         void (*write_space)(struct sock *);
178 };
179
180 struct nvmet_tcp_port {
181         struct socket           *sock;
182         struct work_struct      accept_work;
183         struct nvmet_port       *nport;
184         struct sockaddr_storage addr;
185         void (*data_ready)(struct sock *);
186 };
187
188 static DEFINE_IDA(nvmet_tcp_queue_ida);
189 static LIST_HEAD(nvmet_tcp_queue_list);
190 static DEFINE_MUTEX(nvmet_tcp_queue_mutex);
191
192 static struct workqueue_struct *nvmet_tcp_wq;
193 static const struct nvmet_fabrics_ops nvmet_tcp_ops;
194 static void nvmet_tcp_free_cmd(struct nvmet_tcp_cmd *c);
195 static void nvmet_tcp_free_cmd_buffers(struct nvmet_tcp_cmd *cmd);
196
197 static inline u16 nvmet_tcp_cmd_tag(struct nvmet_tcp_queue *queue,
198                 struct nvmet_tcp_cmd *cmd)
199 {
200         if (unlikely(!queue->nr_cmds)) {
201                 /* We didn't allocate cmds yet, send 0xffff */
202                 return USHRT_MAX;
203         }
204
205         return cmd - queue->cmds;
206 }
207
208 static inline bool nvmet_tcp_has_data_in(struct nvmet_tcp_cmd *cmd)
209 {
210         return nvme_is_write(cmd->req.cmd) &&
211                 cmd->rbytes_done < cmd->req.transfer_len;
212 }
213
214 static inline bool nvmet_tcp_need_data_in(struct nvmet_tcp_cmd *cmd)
215 {
216         return nvmet_tcp_has_data_in(cmd) && !cmd->req.cqe->status;
217 }
218
219 static inline bool nvmet_tcp_need_data_out(struct nvmet_tcp_cmd *cmd)
220 {
221         return !nvme_is_write(cmd->req.cmd) &&
222                 cmd->req.transfer_len > 0 &&
223                 !cmd->req.cqe->status;
224 }
225
226 static inline bool nvmet_tcp_has_inline_data(struct nvmet_tcp_cmd *cmd)
227 {
228         return nvme_is_write(cmd->req.cmd) && cmd->pdu_len &&
229                 !cmd->rbytes_done;
230 }
231
232 static inline struct nvmet_tcp_cmd *
233 nvmet_tcp_get_cmd(struct nvmet_tcp_queue *queue)
234 {
235         struct nvmet_tcp_cmd *cmd;
236
237         cmd = list_first_entry_or_null(&queue->free_list,
238                                 struct nvmet_tcp_cmd, entry);
239         if (!cmd)
240                 return NULL;
241         list_del_init(&cmd->entry);
242
243         cmd->rbytes_done = cmd->wbytes_done = 0;
244         cmd->pdu_len = 0;
245         cmd->pdu_recv = 0;
246         cmd->iov = NULL;
247         cmd->flags = 0;
248         return cmd;
249 }
250
251 static inline void nvmet_tcp_put_cmd(struct nvmet_tcp_cmd *cmd)
252 {
253         if (unlikely(cmd == &cmd->queue->connect))
254                 return;
255
256         list_add_tail(&cmd->entry, &cmd->queue->free_list);
257 }
258
259 static inline int queue_cpu(struct nvmet_tcp_queue *queue)
260 {
261         return queue->sock->sk->sk_incoming_cpu;
262 }
263
264 static inline u8 nvmet_tcp_hdgst_len(struct nvmet_tcp_queue *queue)
265 {
266         return queue->hdr_digest ? NVME_TCP_DIGEST_LENGTH : 0;
267 }
268
269 static inline u8 nvmet_tcp_ddgst_len(struct nvmet_tcp_queue *queue)
270 {
271         return queue->data_digest ? NVME_TCP_DIGEST_LENGTH : 0;
272 }
273
274 static inline void nvmet_tcp_hdgst(struct ahash_request *hash,
275                 void *pdu, size_t len)
276 {
277         struct scatterlist sg;
278
279         sg_init_one(&sg, pdu, len);
280         ahash_request_set_crypt(hash, &sg, pdu + len, len);
281         crypto_ahash_digest(hash);
282 }
283
284 static int nvmet_tcp_verify_hdgst(struct nvmet_tcp_queue *queue,
285         void *pdu, size_t len)
286 {
287         struct nvme_tcp_hdr *hdr = pdu;
288         __le32 recv_digest;
289         __le32 exp_digest;
290
291         if (unlikely(!(hdr->flags & NVME_TCP_F_HDGST))) {
292                 pr_err("queue %d: header digest enabled but no header digest\n",
293                         queue->idx);
294                 return -EPROTO;
295         }
296
297         recv_digest = *(__le32 *)(pdu + hdr->hlen);
298         nvmet_tcp_hdgst(queue->rcv_hash, pdu, len);
299         exp_digest = *(__le32 *)(pdu + hdr->hlen);
300         if (recv_digest != exp_digest) {
301                 pr_err("queue %d: header digest error: recv %#x expected %#x\n",
302                         queue->idx, le32_to_cpu(recv_digest),
303                         le32_to_cpu(exp_digest));
304                 return -EPROTO;
305         }
306
307         return 0;
308 }
309
310 static int nvmet_tcp_check_ddgst(struct nvmet_tcp_queue *queue, void *pdu)
311 {
312         struct nvme_tcp_hdr *hdr = pdu;
313         u8 digest_len = nvmet_tcp_hdgst_len(queue);
314         u32 len;
315
316         len = le32_to_cpu(hdr->plen) - hdr->hlen -
317                 (hdr->flags & NVME_TCP_F_HDGST ? digest_len : 0);
318
319         if (unlikely(len && !(hdr->flags & NVME_TCP_F_DDGST))) {
320                 pr_err("queue %d: data digest flag is cleared\n", queue->idx);
321                 return -EPROTO;
322         }
323
324         return 0;
325 }
326
327 static void nvmet_tcp_free_cmd_buffers(struct nvmet_tcp_cmd *cmd)
328 {
329         kfree(cmd->iov);
330         sgl_free(cmd->req.sg);
331         cmd->iov = NULL;
332         cmd->req.sg = NULL;
333 }
334
335 static void nvmet_tcp_build_pdu_iovec(struct nvmet_tcp_cmd *cmd)
336 {
337         struct bio_vec *iov = cmd->iov;
338         struct scatterlist *sg;
339         u32 length, offset, sg_offset;
340         int nr_pages;
341
342         length = cmd->pdu_len;
343         nr_pages = DIV_ROUND_UP(length, PAGE_SIZE);
344         offset = cmd->rbytes_done;
345         cmd->sg_idx = offset / PAGE_SIZE;
346         sg_offset = offset % PAGE_SIZE;
347         sg = &cmd->req.sg[cmd->sg_idx];
348
349         while (length) {
350                 u32 iov_len = min_t(u32, length, sg->length - sg_offset);
351
352                 bvec_set_page(iov, sg_page(sg), iov_len,
353                                 sg->offset + sg_offset);
354
355                 length -= iov_len;
356                 sg = sg_next(sg);
357                 iov++;
358                 sg_offset = 0;
359         }
360
361         iov_iter_bvec(&cmd->recv_msg.msg_iter, ITER_DEST, cmd->iov,
362                       nr_pages, cmd->pdu_len);
363 }
364
365 static void nvmet_tcp_fatal_error(struct nvmet_tcp_queue *queue)
366 {
367         queue->rcv_state = NVMET_TCP_RECV_ERR;
368         if (queue->nvme_sq.ctrl)
369                 nvmet_ctrl_fatal_error(queue->nvme_sq.ctrl);
370         else
371                 kernel_sock_shutdown(queue->sock, SHUT_RDWR);
372 }
373
374 static void nvmet_tcp_socket_error(struct nvmet_tcp_queue *queue, int status)
375 {
376         queue->rcv_state = NVMET_TCP_RECV_ERR;
377         if (status == -EPIPE || status == -ECONNRESET)
378                 kernel_sock_shutdown(queue->sock, SHUT_RDWR);
379         else
380                 nvmet_tcp_fatal_error(queue);
381 }
382
383 static int nvmet_tcp_map_data(struct nvmet_tcp_cmd *cmd)
384 {
385         struct nvme_sgl_desc *sgl = &cmd->req.cmd->common.dptr.sgl;
386         u32 len = le32_to_cpu(sgl->length);
387
388         if (!len)
389                 return 0;
390
391         if (sgl->type == ((NVME_SGL_FMT_DATA_DESC << 4) |
392                           NVME_SGL_FMT_OFFSET)) {
393                 if (!nvme_is_write(cmd->req.cmd))
394                         return NVME_SC_INVALID_FIELD | NVME_SC_DNR;
395
396                 if (len > cmd->req.port->inline_data_size)
397                         return NVME_SC_SGL_INVALID_OFFSET | NVME_SC_DNR;
398                 cmd->pdu_len = len;
399         }
400         cmd->req.transfer_len += len;
401
402         cmd->req.sg = sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt);
403         if (!cmd->req.sg)
404                 return NVME_SC_INTERNAL;
405         cmd->cur_sg = cmd->req.sg;
406
407         if (nvmet_tcp_has_data_in(cmd)) {
408                 cmd->iov = kmalloc_array(cmd->req.sg_cnt,
409                                 sizeof(*cmd->iov), GFP_KERNEL);
410                 if (!cmd->iov)
411                         goto err;
412         }
413
414         return 0;
415 err:
416         nvmet_tcp_free_cmd_buffers(cmd);
417         return NVME_SC_INTERNAL;
418 }
419
420 static void nvmet_tcp_calc_ddgst(struct ahash_request *hash,
421                 struct nvmet_tcp_cmd *cmd)
422 {
423         ahash_request_set_crypt(hash, cmd->req.sg,
424                 (void *)&cmd->exp_ddgst, cmd->req.transfer_len);
425         crypto_ahash_digest(hash);
426 }
427
428 static void nvmet_setup_c2h_data_pdu(struct nvmet_tcp_cmd *cmd)
429 {
430         struct nvme_tcp_data_pdu *pdu = cmd->data_pdu;
431         struct nvmet_tcp_queue *queue = cmd->queue;
432         u8 hdgst = nvmet_tcp_hdgst_len(cmd->queue);
433         u8 ddgst = nvmet_tcp_ddgst_len(cmd->queue);
434
435         cmd->offset = 0;
436         cmd->state = NVMET_TCP_SEND_DATA_PDU;
437
438         pdu->hdr.type = nvme_tcp_c2h_data;
439         pdu->hdr.flags = NVME_TCP_F_DATA_LAST | (queue->nvme_sq.sqhd_disabled ?
440                                                 NVME_TCP_F_DATA_SUCCESS : 0);
441         pdu->hdr.hlen = sizeof(*pdu);
442         pdu->hdr.pdo = pdu->hdr.hlen + hdgst;
443         pdu->hdr.plen =
444                 cpu_to_le32(pdu->hdr.hlen + hdgst +
445                                 cmd->req.transfer_len + ddgst);
446         pdu->command_id = cmd->req.cqe->command_id;
447         pdu->data_length = cpu_to_le32(cmd->req.transfer_len);
448         pdu->data_offset = cpu_to_le32(cmd->wbytes_done);
449
450         if (queue->data_digest) {
451                 pdu->hdr.flags |= NVME_TCP_F_DDGST;
452                 nvmet_tcp_calc_ddgst(queue->snd_hash, cmd);
453         }
454
455         if (cmd->queue->hdr_digest) {
456                 pdu->hdr.flags |= NVME_TCP_F_HDGST;
457                 nvmet_tcp_hdgst(queue->snd_hash, pdu, sizeof(*pdu));
458         }
459 }
460
461 static void nvmet_setup_r2t_pdu(struct nvmet_tcp_cmd *cmd)
462 {
463         struct nvme_tcp_r2t_pdu *pdu = cmd->r2t_pdu;
464         struct nvmet_tcp_queue *queue = cmd->queue;
465         u8 hdgst = nvmet_tcp_hdgst_len(cmd->queue);
466
467         cmd->offset = 0;
468         cmd->state = NVMET_TCP_SEND_R2T;
469
470         pdu->hdr.type = nvme_tcp_r2t;
471         pdu->hdr.flags = 0;
472         pdu->hdr.hlen = sizeof(*pdu);
473         pdu->hdr.pdo = 0;
474         pdu->hdr.plen = cpu_to_le32(pdu->hdr.hlen + hdgst);
475
476         pdu->command_id = cmd->req.cmd->common.command_id;
477         pdu->ttag = nvmet_tcp_cmd_tag(cmd->queue, cmd);
478         pdu->r2t_length = cpu_to_le32(cmd->req.transfer_len - cmd->rbytes_done);
479         pdu->r2t_offset = cpu_to_le32(cmd->rbytes_done);
480         if (cmd->queue->hdr_digest) {
481                 pdu->hdr.flags |= NVME_TCP_F_HDGST;
482                 nvmet_tcp_hdgst(queue->snd_hash, pdu, sizeof(*pdu));
483         }
484 }
485
486 static void nvmet_setup_response_pdu(struct nvmet_tcp_cmd *cmd)
487 {
488         struct nvme_tcp_rsp_pdu *pdu = cmd->rsp_pdu;
489         struct nvmet_tcp_queue *queue = cmd->queue;
490         u8 hdgst = nvmet_tcp_hdgst_len(cmd->queue);
491
492         cmd->offset = 0;
493         cmd->state = NVMET_TCP_SEND_RESPONSE;
494
495         pdu->hdr.type = nvme_tcp_rsp;
496         pdu->hdr.flags = 0;
497         pdu->hdr.hlen = sizeof(*pdu);
498         pdu->hdr.pdo = 0;
499         pdu->hdr.plen = cpu_to_le32(pdu->hdr.hlen + hdgst);
500         if (cmd->queue->hdr_digest) {
501                 pdu->hdr.flags |= NVME_TCP_F_HDGST;
502                 nvmet_tcp_hdgst(queue->snd_hash, pdu, sizeof(*pdu));
503         }
504 }
505
506 static void nvmet_tcp_process_resp_list(struct nvmet_tcp_queue *queue)
507 {
508         struct llist_node *node;
509         struct nvmet_tcp_cmd *cmd;
510
511         for (node = llist_del_all(&queue->resp_list); node; node = node->next) {
512                 cmd = llist_entry(node, struct nvmet_tcp_cmd, lentry);
513                 list_add(&cmd->entry, &queue->resp_send_list);
514                 queue->send_list_len++;
515         }
516 }
517
518 static struct nvmet_tcp_cmd *nvmet_tcp_fetch_cmd(struct nvmet_tcp_queue *queue)
519 {
520         queue->snd_cmd = list_first_entry_or_null(&queue->resp_send_list,
521                                 struct nvmet_tcp_cmd, entry);
522         if (!queue->snd_cmd) {
523                 nvmet_tcp_process_resp_list(queue);
524                 queue->snd_cmd =
525                         list_first_entry_or_null(&queue->resp_send_list,
526                                         struct nvmet_tcp_cmd, entry);
527                 if (unlikely(!queue->snd_cmd))
528                         return NULL;
529         }
530
531         list_del_init(&queue->snd_cmd->entry);
532         queue->send_list_len--;
533
534         if (nvmet_tcp_need_data_out(queue->snd_cmd))
535                 nvmet_setup_c2h_data_pdu(queue->snd_cmd);
536         else if (nvmet_tcp_need_data_in(queue->snd_cmd))
537                 nvmet_setup_r2t_pdu(queue->snd_cmd);
538         else
539                 nvmet_setup_response_pdu(queue->snd_cmd);
540
541         return queue->snd_cmd;
542 }
543
544 static void nvmet_tcp_queue_response(struct nvmet_req *req)
545 {
546         struct nvmet_tcp_cmd *cmd =
547                 container_of(req, struct nvmet_tcp_cmd, req);
548         struct nvmet_tcp_queue  *queue = cmd->queue;
549         struct nvme_sgl_desc *sgl;
550         u32 len;
551
552         if (unlikely(cmd == queue->cmd)) {
553                 sgl = &cmd->req.cmd->common.dptr.sgl;
554                 len = le32_to_cpu(sgl->length);
555
556                 /*
557                  * Wait for inline data before processing the response.
558                  * Avoid using helpers, this might happen before
559                  * nvmet_req_init is completed.
560                  */
561                 if (queue->rcv_state == NVMET_TCP_RECV_PDU &&
562                     len && len <= cmd->req.port->inline_data_size &&
563                     nvme_is_write(cmd->req.cmd))
564                         return;
565         }
566
567         llist_add(&cmd->lentry, &queue->resp_list);
568         queue_work_on(queue_cpu(queue), nvmet_tcp_wq, &cmd->queue->io_work);
569 }
570
571 static void nvmet_tcp_execute_request(struct nvmet_tcp_cmd *cmd)
572 {
573         if (unlikely(cmd->flags & NVMET_TCP_F_INIT_FAILED))
574                 nvmet_tcp_queue_response(&cmd->req);
575         else
576                 cmd->req.execute(&cmd->req);
577 }
578
579 static int nvmet_try_send_data_pdu(struct nvmet_tcp_cmd *cmd)
580 {
581         struct msghdr msg = {
582                 .msg_flags = MSG_DONTWAIT | MSG_MORE | MSG_SPLICE_PAGES,
583         };
584         struct bio_vec bvec;
585         u8 hdgst = nvmet_tcp_hdgst_len(cmd->queue);
586         int left = sizeof(*cmd->data_pdu) - cmd->offset + hdgst;
587         int ret;
588
589         bvec_set_virt(&bvec, (void *)cmd->data_pdu + cmd->offset, left);
590         iov_iter_bvec(&msg.msg_iter, ITER_SOURCE, &bvec, 1, left);
591         ret = sock_sendmsg(cmd->queue->sock, &msg);
592         if (ret <= 0)
593                 return ret;
594
595         cmd->offset += ret;
596         left -= ret;
597
598         if (left)
599                 return -EAGAIN;
600
601         cmd->state = NVMET_TCP_SEND_DATA;
602         cmd->offset  = 0;
603         return 1;
604 }
605
606 static int nvmet_try_send_data(struct nvmet_tcp_cmd *cmd, bool last_in_batch)
607 {
608         struct nvmet_tcp_queue *queue = cmd->queue;
609         int ret;
610
611         while (cmd->cur_sg) {
612                 struct msghdr msg = {
613                         .msg_flags = MSG_DONTWAIT | MSG_SPLICE_PAGES,
614                 };
615                 struct page *page = sg_page(cmd->cur_sg);
616                 struct bio_vec bvec;
617                 u32 left = cmd->cur_sg->length - cmd->offset;
618
619                 if ((!last_in_batch && cmd->queue->send_list_len) ||
620                     cmd->wbytes_done + left < cmd->req.transfer_len ||
621                     queue->data_digest || !queue->nvme_sq.sqhd_disabled)
622                         msg.msg_flags |= MSG_MORE;
623
624                 bvec_set_page(&bvec, page, left, cmd->offset);
625                 iov_iter_bvec(&msg.msg_iter, ITER_SOURCE, &bvec, 1, left);
626                 ret = sock_sendmsg(cmd->queue->sock, &msg);
627                 if (ret <= 0)
628                         return ret;
629
630                 cmd->offset += ret;
631                 cmd->wbytes_done += ret;
632
633                 /* Done with sg?*/
634                 if (cmd->offset == cmd->cur_sg->length) {
635                         cmd->cur_sg = sg_next(cmd->cur_sg);
636                         cmd->offset = 0;
637                 }
638         }
639
640         if (queue->data_digest) {
641                 cmd->state = NVMET_TCP_SEND_DDGST;
642                 cmd->offset = 0;
643         } else {
644                 if (queue->nvme_sq.sqhd_disabled) {
645                         cmd->queue->snd_cmd = NULL;
646                         nvmet_tcp_put_cmd(cmd);
647                 } else {
648                         nvmet_setup_response_pdu(cmd);
649                 }
650         }
651
652         if (queue->nvme_sq.sqhd_disabled)
653                 nvmet_tcp_free_cmd_buffers(cmd);
654
655         return 1;
656
657 }
658
659 static int nvmet_try_send_response(struct nvmet_tcp_cmd *cmd,
660                 bool last_in_batch)
661 {
662         struct msghdr msg = { .msg_flags = MSG_DONTWAIT | MSG_SPLICE_PAGES, };
663         struct bio_vec bvec;
664         u8 hdgst = nvmet_tcp_hdgst_len(cmd->queue);
665         int left = sizeof(*cmd->rsp_pdu) - cmd->offset + hdgst;
666         int ret;
667
668         if (!last_in_batch && cmd->queue->send_list_len)
669                 msg.msg_flags |= MSG_MORE;
670         else
671                 msg.msg_flags |= MSG_EOR;
672
673         bvec_set_virt(&bvec, (void *)cmd->rsp_pdu + cmd->offset, left);
674         iov_iter_bvec(&msg.msg_iter, ITER_SOURCE, &bvec, 1, left);
675         ret = sock_sendmsg(cmd->queue->sock, &msg);
676         if (ret <= 0)
677                 return ret;
678         cmd->offset += ret;
679         left -= ret;
680
681         if (left)
682                 return -EAGAIN;
683
684         nvmet_tcp_free_cmd_buffers(cmd);
685         cmd->queue->snd_cmd = NULL;
686         nvmet_tcp_put_cmd(cmd);
687         return 1;
688 }
689
690 static int nvmet_try_send_r2t(struct nvmet_tcp_cmd *cmd, bool last_in_batch)
691 {
692         struct msghdr msg = { .msg_flags = MSG_DONTWAIT | MSG_SPLICE_PAGES, };
693         struct bio_vec bvec;
694         u8 hdgst = nvmet_tcp_hdgst_len(cmd->queue);
695         int left = sizeof(*cmd->r2t_pdu) - cmd->offset + hdgst;
696         int ret;
697
698         if (!last_in_batch && cmd->queue->send_list_len)
699                 msg.msg_flags |= MSG_MORE;
700         else
701                 msg.msg_flags |= MSG_EOR;
702
703         bvec_set_virt(&bvec, (void *)cmd->r2t_pdu + cmd->offset, left);
704         iov_iter_bvec(&msg.msg_iter, ITER_SOURCE, &bvec, 1, left);
705         ret = sock_sendmsg(cmd->queue->sock, &msg);
706         if (ret <= 0)
707                 return ret;
708         cmd->offset += ret;
709         left -= ret;
710
711         if (left)
712                 return -EAGAIN;
713
714         cmd->queue->snd_cmd = NULL;
715         return 1;
716 }
717
718 static int nvmet_try_send_ddgst(struct nvmet_tcp_cmd *cmd, bool last_in_batch)
719 {
720         struct nvmet_tcp_queue *queue = cmd->queue;
721         int left = NVME_TCP_DIGEST_LENGTH - cmd->offset;
722         struct msghdr msg = { .msg_flags = MSG_DONTWAIT };
723         struct kvec iov = {
724                 .iov_base = (u8 *)&cmd->exp_ddgst + cmd->offset,
725                 .iov_len = left
726         };
727         int ret;
728
729         if (!last_in_batch && cmd->queue->send_list_len)
730                 msg.msg_flags |= MSG_MORE;
731         else
732                 msg.msg_flags |= MSG_EOR;
733
734         ret = kernel_sendmsg(queue->sock, &msg, &iov, 1, iov.iov_len);
735         if (unlikely(ret <= 0))
736                 return ret;
737
738         cmd->offset += ret;
739         left -= ret;
740
741         if (left)
742                 return -EAGAIN;
743
744         if (queue->nvme_sq.sqhd_disabled) {
745                 cmd->queue->snd_cmd = NULL;
746                 nvmet_tcp_put_cmd(cmd);
747         } else {
748                 nvmet_setup_response_pdu(cmd);
749         }
750         return 1;
751 }
752
753 static int nvmet_tcp_try_send_one(struct nvmet_tcp_queue *queue,
754                 bool last_in_batch)
755 {
756         struct nvmet_tcp_cmd *cmd = queue->snd_cmd;
757         int ret = 0;
758
759         if (!cmd || queue->state == NVMET_TCP_Q_DISCONNECTING) {
760                 cmd = nvmet_tcp_fetch_cmd(queue);
761                 if (unlikely(!cmd))
762                         return 0;
763         }
764
765         if (cmd->state == NVMET_TCP_SEND_DATA_PDU) {
766                 ret = nvmet_try_send_data_pdu(cmd);
767                 if (ret <= 0)
768                         goto done_send;
769         }
770
771         if (cmd->state == NVMET_TCP_SEND_DATA) {
772                 ret = nvmet_try_send_data(cmd, last_in_batch);
773                 if (ret <= 0)
774                         goto done_send;
775         }
776
777         if (cmd->state == NVMET_TCP_SEND_DDGST) {
778                 ret = nvmet_try_send_ddgst(cmd, last_in_batch);
779                 if (ret <= 0)
780                         goto done_send;
781         }
782
783         if (cmd->state == NVMET_TCP_SEND_R2T) {
784                 ret = nvmet_try_send_r2t(cmd, last_in_batch);
785                 if (ret <= 0)
786                         goto done_send;
787         }
788
789         if (cmd->state == NVMET_TCP_SEND_RESPONSE)
790                 ret = nvmet_try_send_response(cmd, last_in_batch);
791
792 done_send:
793         if (ret < 0) {
794                 if (ret == -EAGAIN)
795                         return 0;
796                 return ret;
797         }
798
799         return 1;
800 }
801
802 static int nvmet_tcp_try_send(struct nvmet_tcp_queue *queue,
803                 int budget, int *sends)
804 {
805         int i, ret = 0;
806
807         for (i = 0; i < budget; i++) {
808                 ret = nvmet_tcp_try_send_one(queue, i == budget - 1);
809                 if (unlikely(ret < 0)) {
810                         nvmet_tcp_socket_error(queue, ret);
811                         goto done;
812                 } else if (ret == 0) {
813                         break;
814                 }
815                 (*sends)++;
816         }
817 done:
818         return ret;
819 }
820
821 static void nvmet_prepare_receive_pdu(struct nvmet_tcp_queue *queue)
822 {
823         queue->offset = 0;
824         queue->left = sizeof(struct nvme_tcp_hdr);
825         queue->cmd = NULL;
826         queue->rcv_state = NVMET_TCP_RECV_PDU;
827 }
828
829 static void nvmet_tcp_free_crypto(struct nvmet_tcp_queue *queue)
830 {
831         struct crypto_ahash *tfm = crypto_ahash_reqtfm(queue->rcv_hash);
832
833         ahash_request_free(queue->rcv_hash);
834         ahash_request_free(queue->snd_hash);
835         crypto_free_ahash(tfm);
836 }
837
838 static int nvmet_tcp_alloc_crypto(struct nvmet_tcp_queue *queue)
839 {
840         struct crypto_ahash *tfm;
841
842         tfm = crypto_alloc_ahash("crc32c", 0, CRYPTO_ALG_ASYNC);
843         if (IS_ERR(tfm))
844                 return PTR_ERR(tfm);
845
846         queue->snd_hash = ahash_request_alloc(tfm, GFP_KERNEL);
847         if (!queue->snd_hash)
848                 goto free_tfm;
849         ahash_request_set_callback(queue->snd_hash, 0, NULL, NULL);
850
851         queue->rcv_hash = ahash_request_alloc(tfm, GFP_KERNEL);
852         if (!queue->rcv_hash)
853                 goto free_snd_hash;
854         ahash_request_set_callback(queue->rcv_hash, 0, NULL, NULL);
855
856         return 0;
857 free_snd_hash:
858         ahash_request_free(queue->snd_hash);
859 free_tfm:
860         crypto_free_ahash(tfm);
861         return -ENOMEM;
862 }
863
864
865 static int nvmet_tcp_handle_icreq(struct nvmet_tcp_queue *queue)
866 {
867         struct nvme_tcp_icreq_pdu *icreq = &queue->pdu.icreq;
868         struct nvme_tcp_icresp_pdu *icresp = &queue->pdu.icresp;
869         struct msghdr msg = {};
870         struct kvec iov;
871         int ret;
872
873         if (le32_to_cpu(icreq->hdr.plen) != sizeof(struct nvme_tcp_icreq_pdu)) {
874                 pr_err("bad nvme-tcp pdu length (%d)\n",
875                         le32_to_cpu(icreq->hdr.plen));
876                 nvmet_tcp_fatal_error(queue);
877         }
878
879         if (icreq->pfv != NVME_TCP_PFV_1_0) {
880                 pr_err("queue %d: bad pfv %d\n", queue->idx, icreq->pfv);
881                 return -EPROTO;
882         }
883
884         if (icreq->hpda != 0) {
885                 pr_err("queue %d: unsupported hpda %d\n", queue->idx,
886                         icreq->hpda);
887                 return -EPROTO;
888         }
889
890         queue->hdr_digest = !!(icreq->digest & NVME_TCP_HDR_DIGEST_ENABLE);
891         queue->data_digest = !!(icreq->digest & NVME_TCP_DATA_DIGEST_ENABLE);
892         if (queue->hdr_digest || queue->data_digest) {
893                 ret = nvmet_tcp_alloc_crypto(queue);
894                 if (ret)
895                         return ret;
896         }
897
898         memset(icresp, 0, sizeof(*icresp));
899         icresp->hdr.type = nvme_tcp_icresp;
900         icresp->hdr.hlen = sizeof(*icresp);
901         icresp->hdr.pdo = 0;
902         icresp->hdr.plen = cpu_to_le32(icresp->hdr.hlen);
903         icresp->pfv = cpu_to_le16(NVME_TCP_PFV_1_0);
904         icresp->maxdata = cpu_to_le32(NVMET_TCP_MAXH2CDATA);
905         icresp->cpda = 0;
906         if (queue->hdr_digest)
907                 icresp->digest |= NVME_TCP_HDR_DIGEST_ENABLE;
908         if (queue->data_digest)
909                 icresp->digest |= NVME_TCP_DATA_DIGEST_ENABLE;
910
911         iov.iov_base = icresp;
912         iov.iov_len = sizeof(*icresp);
913         ret = kernel_sendmsg(queue->sock, &msg, &iov, 1, iov.iov_len);
914         if (ret < 0)
915                 return ret; /* queue removal will cleanup */
916
917         queue->state = NVMET_TCP_Q_LIVE;
918         nvmet_prepare_receive_pdu(queue);
919         return 0;
920 }
921
922 static void nvmet_tcp_handle_req_failure(struct nvmet_tcp_queue *queue,
923                 struct nvmet_tcp_cmd *cmd, struct nvmet_req *req)
924 {
925         size_t data_len = le32_to_cpu(req->cmd->common.dptr.sgl.length);
926         int ret;
927
928         /*
929          * This command has not been processed yet, hence we are trying to
930          * figure out if there is still pending data left to receive. If
931          * we don't, we can simply prepare for the next pdu and bail out,
932          * otherwise we will need to prepare a buffer and receive the
933          * stale data before continuing forward.
934          */
935         if (!nvme_is_write(cmd->req.cmd) || !data_len ||
936             data_len > cmd->req.port->inline_data_size) {
937                 nvmet_prepare_receive_pdu(queue);
938                 return;
939         }
940
941         ret = nvmet_tcp_map_data(cmd);
942         if (unlikely(ret)) {
943                 pr_err("queue %d: failed to map data\n", queue->idx);
944                 nvmet_tcp_fatal_error(queue);
945                 return;
946         }
947
948         queue->rcv_state = NVMET_TCP_RECV_DATA;
949         nvmet_tcp_build_pdu_iovec(cmd);
950         cmd->flags |= NVMET_TCP_F_INIT_FAILED;
951 }
952
953 static int nvmet_tcp_handle_h2c_data_pdu(struct nvmet_tcp_queue *queue)
954 {
955         struct nvme_tcp_data_pdu *data = &queue->pdu.data;
956         struct nvmet_tcp_cmd *cmd;
957         unsigned int plen;
958
959         if (likely(queue->nr_cmds)) {
960                 if (unlikely(data->ttag >= queue->nr_cmds)) {
961                         pr_err("queue %d: received out of bound ttag %u, nr_cmds %u\n",
962                                 queue->idx, data->ttag, queue->nr_cmds);
963                         nvmet_tcp_fatal_error(queue);
964                         return -EPROTO;
965                 }
966                 cmd = &queue->cmds[data->ttag];
967         } else {
968                 cmd = &queue->connect;
969         }
970
971         if (le32_to_cpu(data->data_offset) != cmd->rbytes_done) {
972                 pr_err("ttag %u unexpected data offset %u (expected %u)\n",
973                         data->ttag, le32_to_cpu(data->data_offset),
974                         cmd->rbytes_done);
975                 /* FIXME: use path and transport errors */
976                 nvmet_tcp_fatal_error(queue);
977                 return -EPROTO;
978         }
979
980         plen = le32_to_cpu(data->hdr.plen);
981         cmd->pdu_len = le32_to_cpu(data->data_length);
982         if (unlikely(cmd->pdu_len != (plen - sizeof(*data)) ||
983                      cmd->pdu_len == 0 ||
984                      cmd->pdu_len > NVMET_TCP_MAXH2CDATA)) {
985                 pr_err("H2CData PDU len %u is invalid\n", cmd->pdu_len);
986                 /* FIXME: use proper transport errors */
987                 nvmet_tcp_fatal_error(queue);
988                 return -EPROTO;
989         }
990         cmd->pdu_recv = 0;
991         nvmet_tcp_build_pdu_iovec(cmd);
992         queue->cmd = cmd;
993         queue->rcv_state = NVMET_TCP_RECV_DATA;
994
995         return 0;
996 }
997
998 static int nvmet_tcp_done_recv_pdu(struct nvmet_tcp_queue *queue)
999 {
1000         struct nvme_tcp_hdr *hdr = &queue->pdu.cmd.hdr;
1001         struct nvme_command *nvme_cmd = &queue->pdu.cmd.cmd;
1002         struct nvmet_req *req;
1003         int ret;
1004
1005         if (unlikely(queue->state == NVMET_TCP_Q_CONNECTING)) {
1006                 if (hdr->type != nvme_tcp_icreq) {
1007                         pr_err("unexpected pdu type (%d) before icreq\n",
1008                                 hdr->type);
1009                         nvmet_tcp_fatal_error(queue);
1010                         return -EPROTO;
1011                 }
1012                 return nvmet_tcp_handle_icreq(queue);
1013         }
1014
1015         if (unlikely(hdr->type == nvme_tcp_icreq)) {
1016                 pr_err("queue %d: received icreq pdu in state %d\n",
1017                         queue->idx, queue->state);
1018                 nvmet_tcp_fatal_error(queue);
1019                 return -EPROTO;
1020         }
1021
1022         if (hdr->type == nvme_tcp_h2c_data) {
1023                 ret = nvmet_tcp_handle_h2c_data_pdu(queue);
1024                 if (unlikely(ret))
1025                         return ret;
1026                 return 0;
1027         }
1028
1029         queue->cmd = nvmet_tcp_get_cmd(queue);
1030         if (unlikely(!queue->cmd)) {
1031                 /* This should never happen */
1032                 pr_err("queue %d: out of commands (%d) send_list_len: %d, opcode: %d",
1033                         queue->idx, queue->nr_cmds, queue->send_list_len,
1034                         nvme_cmd->common.opcode);
1035                 nvmet_tcp_fatal_error(queue);
1036                 return -ENOMEM;
1037         }
1038
1039         req = &queue->cmd->req;
1040         memcpy(req->cmd, nvme_cmd, sizeof(*nvme_cmd));
1041
1042         if (unlikely(!nvmet_req_init(req, &queue->nvme_cq,
1043                         &queue->nvme_sq, &nvmet_tcp_ops))) {
1044                 pr_err("failed cmd %p id %d opcode %d, data_len: %d\n",
1045                         req->cmd, req->cmd->common.command_id,
1046                         req->cmd->common.opcode,
1047                         le32_to_cpu(req->cmd->common.dptr.sgl.length));
1048
1049                 nvmet_tcp_handle_req_failure(queue, queue->cmd, req);
1050                 return 0;
1051         }
1052
1053         ret = nvmet_tcp_map_data(queue->cmd);
1054         if (unlikely(ret)) {
1055                 pr_err("queue %d: failed to map data\n", queue->idx);
1056                 if (nvmet_tcp_has_inline_data(queue->cmd))
1057                         nvmet_tcp_fatal_error(queue);
1058                 else
1059                         nvmet_req_complete(req, ret);
1060                 ret = -EAGAIN;
1061                 goto out;
1062         }
1063
1064         if (nvmet_tcp_need_data_in(queue->cmd)) {
1065                 if (nvmet_tcp_has_inline_data(queue->cmd)) {
1066                         queue->rcv_state = NVMET_TCP_RECV_DATA;
1067                         nvmet_tcp_build_pdu_iovec(queue->cmd);
1068                         return 0;
1069                 }
1070                 /* send back R2T */
1071                 nvmet_tcp_queue_response(&queue->cmd->req);
1072                 goto out;
1073         }
1074
1075         queue->cmd->req.execute(&queue->cmd->req);
1076 out:
1077         nvmet_prepare_receive_pdu(queue);
1078         return ret;
1079 }
1080
1081 static const u8 nvme_tcp_pdu_sizes[] = {
1082         [nvme_tcp_icreq]        = sizeof(struct nvme_tcp_icreq_pdu),
1083         [nvme_tcp_cmd]          = sizeof(struct nvme_tcp_cmd_pdu),
1084         [nvme_tcp_h2c_data]     = sizeof(struct nvme_tcp_data_pdu),
1085 };
1086
1087 static inline u8 nvmet_tcp_pdu_size(u8 type)
1088 {
1089         size_t idx = type;
1090
1091         return (idx < ARRAY_SIZE(nvme_tcp_pdu_sizes) &&
1092                 nvme_tcp_pdu_sizes[idx]) ?
1093                         nvme_tcp_pdu_sizes[idx] : 0;
1094 }
1095
1096 static inline bool nvmet_tcp_pdu_valid(u8 type)
1097 {
1098         switch (type) {
1099         case nvme_tcp_icreq:
1100         case nvme_tcp_cmd:
1101         case nvme_tcp_h2c_data:
1102                 /* fallthru */
1103                 return true;
1104         }
1105
1106         return false;
1107 }
1108
1109 static int nvmet_tcp_try_recv_pdu(struct nvmet_tcp_queue *queue)
1110 {
1111         struct nvme_tcp_hdr *hdr = &queue->pdu.cmd.hdr;
1112         int len;
1113         struct kvec iov;
1114         struct msghdr msg = { .msg_flags = MSG_DONTWAIT };
1115
1116 recv:
1117         iov.iov_base = (void *)&queue->pdu + queue->offset;
1118         iov.iov_len = queue->left;
1119         len = kernel_recvmsg(queue->sock, &msg, &iov, 1,
1120                         iov.iov_len, msg.msg_flags);
1121         if (unlikely(len < 0))
1122                 return len;
1123
1124         queue->offset += len;
1125         queue->left -= len;
1126         if (queue->left)
1127                 return -EAGAIN;
1128
1129         if (queue->offset == sizeof(struct nvme_tcp_hdr)) {
1130                 u8 hdgst = nvmet_tcp_hdgst_len(queue);
1131
1132                 if (unlikely(!nvmet_tcp_pdu_valid(hdr->type))) {
1133                         pr_err("unexpected pdu type %d\n", hdr->type);
1134                         nvmet_tcp_fatal_error(queue);
1135                         return -EIO;
1136                 }
1137
1138                 if (unlikely(hdr->hlen != nvmet_tcp_pdu_size(hdr->type))) {
1139                         pr_err("pdu %d bad hlen %d\n", hdr->type, hdr->hlen);
1140                         return -EIO;
1141                 }
1142
1143                 queue->left = hdr->hlen - queue->offset + hdgst;
1144                 goto recv;
1145         }
1146
1147         if (queue->hdr_digest &&
1148             nvmet_tcp_verify_hdgst(queue, &queue->pdu, hdr->hlen)) {
1149                 nvmet_tcp_fatal_error(queue); /* fatal */
1150                 return -EPROTO;
1151         }
1152
1153         if (queue->data_digest &&
1154             nvmet_tcp_check_ddgst(queue, &queue->pdu)) {
1155                 nvmet_tcp_fatal_error(queue); /* fatal */
1156                 return -EPROTO;
1157         }
1158
1159         return nvmet_tcp_done_recv_pdu(queue);
1160 }
1161
1162 static void nvmet_tcp_prep_recv_ddgst(struct nvmet_tcp_cmd *cmd)
1163 {
1164         struct nvmet_tcp_queue *queue = cmd->queue;
1165
1166         nvmet_tcp_calc_ddgst(queue->rcv_hash, cmd);
1167         queue->offset = 0;
1168         queue->left = NVME_TCP_DIGEST_LENGTH;
1169         queue->rcv_state = NVMET_TCP_RECV_DDGST;
1170 }
1171
1172 static int nvmet_tcp_try_recv_data(struct nvmet_tcp_queue *queue)
1173 {
1174         struct nvmet_tcp_cmd  *cmd = queue->cmd;
1175         int ret;
1176
1177         while (msg_data_left(&cmd->recv_msg)) {
1178                 ret = sock_recvmsg(cmd->queue->sock, &cmd->recv_msg,
1179                         cmd->recv_msg.msg_flags);
1180                 if (ret <= 0)
1181                         return ret;
1182
1183                 cmd->pdu_recv += ret;
1184                 cmd->rbytes_done += ret;
1185         }
1186
1187         if (queue->data_digest) {
1188                 nvmet_tcp_prep_recv_ddgst(cmd);
1189                 return 0;
1190         }
1191
1192         if (cmd->rbytes_done == cmd->req.transfer_len)
1193                 nvmet_tcp_execute_request(cmd);
1194
1195         nvmet_prepare_receive_pdu(queue);
1196         return 0;
1197 }
1198
1199 static int nvmet_tcp_try_recv_ddgst(struct nvmet_tcp_queue *queue)
1200 {
1201         struct nvmet_tcp_cmd *cmd = queue->cmd;
1202         int ret;
1203         struct msghdr msg = { .msg_flags = MSG_DONTWAIT };
1204         struct kvec iov = {
1205                 .iov_base = (void *)&cmd->recv_ddgst + queue->offset,
1206                 .iov_len = queue->left
1207         };
1208
1209         ret = kernel_recvmsg(queue->sock, &msg, &iov, 1,
1210                         iov.iov_len, msg.msg_flags);
1211         if (unlikely(ret < 0))
1212                 return ret;
1213
1214         queue->offset += ret;
1215         queue->left -= ret;
1216         if (queue->left)
1217                 return -EAGAIN;
1218
1219         if (queue->data_digest && cmd->exp_ddgst != cmd->recv_ddgst) {
1220                 pr_err("queue %d: cmd %d pdu (%d) data digest error: recv %#x expected %#x\n",
1221                         queue->idx, cmd->req.cmd->common.command_id,
1222                         queue->pdu.cmd.hdr.type, le32_to_cpu(cmd->recv_ddgst),
1223                         le32_to_cpu(cmd->exp_ddgst));
1224                 nvmet_req_uninit(&cmd->req);
1225                 nvmet_tcp_free_cmd_buffers(cmd);
1226                 nvmet_tcp_fatal_error(queue);
1227                 ret = -EPROTO;
1228                 goto out;
1229         }
1230
1231         if (cmd->rbytes_done == cmd->req.transfer_len)
1232                 nvmet_tcp_execute_request(cmd);
1233
1234         ret = 0;
1235 out:
1236         nvmet_prepare_receive_pdu(queue);
1237         return ret;
1238 }
1239
1240 static int nvmet_tcp_try_recv_one(struct nvmet_tcp_queue *queue)
1241 {
1242         int result = 0;
1243
1244         if (unlikely(queue->rcv_state == NVMET_TCP_RECV_ERR))
1245                 return 0;
1246
1247         if (queue->rcv_state == NVMET_TCP_RECV_PDU) {
1248                 result = nvmet_tcp_try_recv_pdu(queue);
1249                 if (result != 0)
1250                         goto done_recv;
1251         }
1252
1253         if (queue->rcv_state == NVMET_TCP_RECV_DATA) {
1254                 result = nvmet_tcp_try_recv_data(queue);
1255                 if (result != 0)
1256                         goto done_recv;
1257         }
1258
1259         if (queue->rcv_state == NVMET_TCP_RECV_DDGST) {
1260                 result = nvmet_tcp_try_recv_ddgst(queue);
1261                 if (result != 0)
1262                         goto done_recv;
1263         }
1264
1265 done_recv:
1266         if (result < 0) {
1267                 if (result == -EAGAIN)
1268                         return 0;
1269                 return result;
1270         }
1271         return 1;
1272 }
1273
1274 static int nvmet_tcp_try_recv(struct nvmet_tcp_queue *queue,
1275                 int budget, int *recvs)
1276 {
1277         int i, ret = 0;
1278
1279         for (i = 0; i < budget; i++) {
1280                 ret = nvmet_tcp_try_recv_one(queue);
1281                 if (unlikely(ret < 0)) {
1282                         nvmet_tcp_socket_error(queue, ret);
1283                         goto done;
1284                 } else if (ret == 0) {
1285                         break;
1286                 }
1287                 (*recvs)++;
1288         }
1289 done:
1290         return ret;
1291 }
1292
1293 static void nvmet_tcp_schedule_release_queue(struct nvmet_tcp_queue *queue)
1294 {
1295         spin_lock(&queue->state_lock);
1296         if (queue->state != NVMET_TCP_Q_DISCONNECTING) {
1297                 queue->state = NVMET_TCP_Q_DISCONNECTING;
1298                 queue_work(nvmet_wq, &queue->release_work);
1299         }
1300         spin_unlock(&queue->state_lock);
1301 }
1302
1303 static inline void nvmet_tcp_arm_queue_deadline(struct nvmet_tcp_queue *queue)
1304 {
1305         queue->poll_end = jiffies + usecs_to_jiffies(idle_poll_period_usecs);
1306 }
1307
1308 static bool nvmet_tcp_check_queue_deadline(struct nvmet_tcp_queue *queue,
1309                 int ops)
1310 {
1311         if (!idle_poll_period_usecs)
1312                 return false;
1313
1314         if (ops)
1315                 nvmet_tcp_arm_queue_deadline(queue);
1316
1317         return !time_after(jiffies, queue->poll_end);
1318 }
1319
1320 static void nvmet_tcp_io_work(struct work_struct *w)
1321 {
1322         struct nvmet_tcp_queue *queue =
1323                 container_of(w, struct nvmet_tcp_queue, io_work);
1324         bool pending;
1325         int ret, ops = 0;
1326
1327         do {
1328                 pending = false;
1329
1330                 ret = nvmet_tcp_try_recv(queue, NVMET_TCP_RECV_BUDGET, &ops);
1331                 if (ret > 0)
1332                         pending = true;
1333                 else if (ret < 0)
1334                         return;
1335
1336                 ret = nvmet_tcp_try_send(queue, NVMET_TCP_SEND_BUDGET, &ops);
1337                 if (ret > 0)
1338                         pending = true;
1339                 else if (ret < 0)
1340                         return;
1341
1342         } while (pending && ops < NVMET_TCP_IO_WORK_BUDGET);
1343
1344         /*
1345          * Requeue the worker if idle deadline period is in progress or any
1346          * ops activity was recorded during the do-while loop above.
1347          */
1348         if (nvmet_tcp_check_queue_deadline(queue, ops) || pending)
1349                 queue_work_on(queue_cpu(queue), nvmet_tcp_wq, &queue->io_work);
1350 }
1351
1352 static int nvmet_tcp_alloc_cmd(struct nvmet_tcp_queue *queue,
1353                 struct nvmet_tcp_cmd *c)
1354 {
1355         u8 hdgst = nvmet_tcp_hdgst_len(queue);
1356
1357         c->queue = queue;
1358         c->req.port = queue->port->nport;
1359
1360         c->cmd_pdu = page_frag_alloc(&queue->pf_cache,
1361                         sizeof(*c->cmd_pdu) + hdgst, GFP_KERNEL | __GFP_ZERO);
1362         if (!c->cmd_pdu)
1363                 return -ENOMEM;
1364         c->req.cmd = &c->cmd_pdu->cmd;
1365
1366         c->rsp_pdu = page_frag_alloc(&queue->pf_cache,
1367                         sizeof(*c->rsp_pdu) + hdgst, GFP_KERNEL | __GFP_ZERO);
1368         if (!c->rsp_pdu)
1369                 goto out_free_cmd;
1370         c->req.cqe = &c->rsp_pdu->cqe;
1371
1372         c->data_pdu = page_frag_alloc(&queue->pf_cache,
1373                         sizeof(*c->data_pdu) + hdgst, GFP_KERNEL | __GFP_ZERO);
1374         if (!c->data_pdu)
1375                 goto out_free_rsp;
1376
1377         c->r2t_pdu = page_frag_alloc(&queue->pf_cache,
1378                         sizeof(*c->r2t_pdu) + hdgst, GFP_KERNEL | __GFP_ZERO);
1379         if (!c->r2t_pdu)
1380                 goto out_free_data;
1381
1382         c->recv_msg.msg_flags = MSG_DONTWAIT | MSG_NOSIGNAL;
1383
1384         list_add_tail(&c->entry, &queue->free_list);
1385
1386         return 0;
1387 out_free_data:
1388         page_frag_free(c->data_pdu);
1389 out_free_rsp:
1390         page_frag_free(c->rsp_pdu);
1391 out_free_cmd:
1392         page_frag_free(c->cmd_pdu);
1393         return -ENOMEM;
1394 }
1395
1396 static void nvmet_tcp_free_cmd(struct nvmet_tcp_cmd *c)
1397 {
1398         page_frag_free(c->r2t_pdu);
1399         page_frag_free(c->data_pdu);
1400         page_frag_free(c->rsp_pdu);
1401         page_frag_free(c->cmd_pdu);
1402 }
1403
1404 static int nvmet_tcp_alloc_cmds(struct nvmet_tcp_queue *queue)
1405 {
1406         struct nvmet_tcp_cmd *cmds;
1407         int i, ret = -EINVAL, nr_cmds = queue->nr_cmds;
1408
1409         cmds = kcalloc(nr_cmds, sizeof(struct nvmet_tcp_cmd), GFP_KERNEL);
1410         if (!cmds)
1411                 goto out;
1412
1413         for (i = 0; i < nr_cmds; i++) {
1414                 ret = nvmet_tcp_alloc_cmd(queue, cmds + i);
1415                 if (ret)
1416                         goto out_free;
1417         }
1418
1419         queue->cmds = cmds;
1420
1421         return 0;
1422 out_free:
1423         while (--i >= 0)
1424                 nvmet_tcp_free_cmd(cmds + i);
1425         kfree(cmds);
1426 out:
1427         return ret;
1428 }
1429
1430 static void nvmet_tcp_free_cmds(struct nvmet_tcp_queue *queue)
1431 {
1432         struct nvmet_tcp_cmd *cmds = queue->cmds;
1433         int i;
1434
1435         for (i = 0; i < queue->nr_cmds; i++)
1436                 nvmet_tcp_free_cmd(cmds + i);
1437
1438         nvmet_tcp_free_cmd(&queue->connect);
1439         kfree(cmds);
1440 }
1441
1442 static void nvmet_tcp_restore_socket_callbacks(struct nvmet_tcp_queue *queue)
1443 {
1444         struct socket *sock = queue->sock;
1445
1446         write_lock_bh(&sock->sk->sk_callback_lock);
1447         sock->sk->sk_data_ready =  queue->data_ready;
1448         sock->sk->sk_state_change = queue->state_change;
1449         sock->sk->sk_write_space = queue->write_space;
1450         sock->sk->sk_user_data = NULL;
1451         write_unlock_bh(&sock->sk->sk_callback_lock);
1452 }
1453
1454 static void nvmet_tcp_uninit_data_in_cmds(struct nvmet_tcp_queue *queue)
1455 {
1456         struct nvmet_tcp_cmd *cmd = queue->cmds;
1457         int i;
1458
1459         for (i = 0; i < queue->nr_cmds; i++, cmd++) {
1460                 if (nvmet_tcp_need_data_in(cmd))
1461                         nvmet_req_uninit(&cmd->req);
1462         }
1463
1464         if (!queue->nr_cmds && nvmet_tcp_need_data_in(&queue->connect)) {
1465                 /* failed in connect */
1466                 nvmet_req_uninit(&queue->connect.req);
1467         }
1468 }
1469
1470 static void nvmet_tcp_free_cmd_data_in_buffers(struct nvmet_tcp_queue *queue)
1471 {
1472         struct nvmet_tcp_cmd *cmd = queue->cmds;
1473         int i;
1474
1475         for (i = 0; i < queue->nr_cmds; i++, cmd++) {
1476                 if (nvmet_tcp_need_data_in(cmd))
1477                         nvmet_tcp_free_cmd_buffers(cmd);
1478         }
1479
1480         if (!queue->nr_cmds && nvmet_tcp_need_data_in(&queue->connect))
1481                 nvmet_tcp_free_cmd_buffers(&queue->connect);
1482 }
1483
1484 static void nvmet_tcp_release_queue_work(struct work_struct *w)
1485 {
1486         struct page *page;
1487         struct nvmet_tcp_queue *queue =
1488                 container_of(w, struct nvmet_tcp_queue, release_work);
1489
1490         mutex_lock(&nvmet_tcp_queue_mutex);
1491         list_del_init(&queue->queue_list);
1492         mutex_unlock(&nvmet_tcp_queue_mutex);
1493
1494         nvmet_tcp_restore_socket_callbacks(queue);
1495         cancel_work_sync(&queue->io_work);
1496         /* stop accepting incoming data */
1497         queue->rcv_state = NVMET_TCP_RECV_ERR;
1498
1499         nvmet_tcp_uninit_data_in_cmds(queue);
1500         nvmet_sq_destroy(&queue->nvme_sq);
1501         cancel_work_sync(&queue->io_work);
1502         nvmet_tcp_free_cmd_data_in_buffers(queue);
1503         sock_release(queue->sock);
1504         nvmet_tcp_free_cmds(queue);
1505         if (queue->hdr_digest || queue->data_digest)
1506                 nvmet_tcp_free_crypto(queue);
1507         ida_free(&nvmet_tcp_queue_ida, queue->idx);
1508
1509         page = virt_to_head_page(queue->pf_cache.va);
1510         __page_frag_cache_drain(page, queue->pf_cache.pagecnt_bias);
1511         kfree(queue);
1512 }
1513
1514 static void nvmet_tcp_data_ready(struct sock *sk)
1515 {
1516         struct nvmet_tcp_queue *queue;
1517
1518         trace_sk_data_ready(sk);
1519
1520         read_lock_bh(&sk->sk_callback_lock);
1521         queue = sk->sk_user_data;
1522         if (likely(queue))
1523                 queue_work_on(queue_cpu(queue), nvmet_tcp_wq, &queue->io_work);
1524         read_unlock_bh(&sk->sk_callback_lock);
1525 }
1526
1527 static void nvmet_tcp_write_space(struct sock *sk)
1528 {
1529         struct nvmet_tcp_queue *queue;
1530
1531         read_lock_bh(&sk->sk_callback_lock);
1532         queue = sk->sk_user_data;
1533         if (unlikely(!queue))
1534                 goto out;
1535
1536         if (unlikely(queue->state == NVMET_TCP_Q_CONNECTING)) {
1537                 queue->write_space(sk);
1538                 goto out;
1539         }
1540
1541         if (sk_stream_is_writeable(sk)) {
1542                 clear_bit(SOCK_NOSPACE, &sk->sk_socket->flags);
1543                 queue_work_on(queue_cpu(queue), nvmet_tcp_wq, &queue->io_work);
1544         }
1545 out:
1546         read_unlock_bh(&sk->sk_callback_lock);
1547 }
1548
1549 static void nvmet_tcp_state_change(struct sock *sk)
1550 {
1551         struct nvmet_tcp_queue *queue;
1552
1553         read_lock_bh(&sk->sk_callback_lock);
1554         queue = sk->sk_user_data;
1555         if (!queue)
1556                 goto done;
1557
1558         switch (sk->sk_state) {
1559         case TCP_FIN_WAIT2:
1560         case TCP_LAST_ACK:
1561                 break;
1562         case TCP_FIN_WAIT1:
1563         case TCP_CLOSE_WAIT:
1564         case TCP_CLOSE:
1565                 /* FALLTHRU */
1566                 nvmet_tcp_schedule_release_queue(queue);
1567                 break;
1568         default:
1569                 pr_warn("queue %d unhandled state %d\n",
1570                         queue->idx, sk->sk_state);
1571         }
1572 done:
1573         read_unlock_bh(&sk->sk_callback_lock);
1574 }
1575
1576 static int nvmet_tcp_set_queue_sock(struct nvmet_tcp_queue *queue)
1577 {
1578         struct socket *sock = queue->sock;
1579         struct inet_sock *inet = inet_sk(sock->sk);
1580         int ret;
1581
1582         ret = kernel_getsockname(sock,
1583                 (struct sockaddr *)&queue->sockaddr);
1584         if (ret < 0)
1585                 return ret;
1586
1587         ret = kernel_getpeername(sock,
1588                 (struct sockaddr *)&queue->sockaddr_peer);
1589         if (ret < 0)
1590                 return ret;
1591
1592         /*
1593          * Cleanup whatever is sitting in the TCP transmit queue on socket
1594          * close. This is done to prevent stale data from being sent should
1595          * the network connection be restored before TCP times out.
1596          */
1597         sock_no_linger(sock->sk);
1598
1599         if (so_priority > 0)
1600                 sock_set_priority(sock->sk, so_priority);
1601
1602         /* Set socket type of service */
1603         if (inet->rcv_tos > 0)
1604                 ip_sock_set_tos(sock->sk, inet->rcv_tos);
1605
1606         ret = 0;
1607         write_lock_bh(&sock->sk->sk_callback_lock);
1608         if (sock->sk->sk_state != TCP_ESTABLISHED) {
1609                 /*
1610                  * If the socket is already closing, don't even start
1611                  * consuming it
1612                  */
1613                 ret = -ENOTCONN;
1614         } else {
1615                 sock->sk->sk_user_data = queue;
1616                 queue->data_ready = sock->sk->sk_data_ready;
1617                 sock->sk->sk_data_ready = nvmet_tcp_data_ready;
1618                 queue->state_change = sock->sk->sk_state_change;
1619                 sock->sk->sk_state_change = nvmet_tcp_state_change;
1620                 queue->write_space = sock->sk->sk_write_space;
1621                 sock->sk->sk_write_space = nvmet_tcp_write_space;
1622                 if (idle_poll_period_usecs)
1623                         nvmet_tcp_arm_queue_deadline(queue);
1624                 queue_work_on(queue_cpu(queue), nvmet_tcp_wq, &queue->io_work);
1625         }
1626         write_unlock_bh(&sock->sk->sk_callback_lock);
1627
1628         return ret;
1629 }
1630
1631 static int nvmet_tcp_alloc_queue(struct nvmet_tcp_port *port,
1632                 struct socket *newsock)
1633 {
1634         struct nvmet_tcp_queue *queue;
1635         int ret;
1636
1637         queue = kzalloc(sizeof(*queue), GFP_KERNEL);
1638         if (!queue)
1639                 return -ENOMEM;
1640
1641         INIT_WORK(&queue->release_work, nvmet_tcp_release_queue_work);
1642         INIT_WORK(&queue->io_work, nvmet_tcp_io_work);
1643         queue->sock = newsock;
1644         queue->port = port;
1645         queue->nr_cmds = 0;
1646         spin_lock_init(&queue->state_lock);
1647         queue->state = NVMET_TCP_Q_CONNECTING;
1648         INIT_LIST_HEAD(&queue->free_list);
1649         init_llist_head(&queue->resp_list);
1650         INIT_LIST_HEAD(&queue->resp_send_list);
1651
1652         queue->idx = ida_alloc(&nvmet_tcp_queue_ida, GFP_KERNEL);
1653         if (queue->idx < 0) {
1654                 ret = queue->idx;
1655                 goto out_free_queue;
1656         }
1657
1658         ret = nvmet_tcp_alloc_cmd(queue, &queue->connect);
1659         if (ret)
1660                 goto out_ida_remove;
1661
1662         ret = nvmet_sq_init(&queue->nvme_sq);
1663         if (ret)
1664                 goto out_free_connect;
1665
1666         nvmet_prepare_receive_pdu(queue);
1667
1668         mutex_lock(&nvmet_tcp_queue_mutex);
1669         list_add_tail(&queue->queue_list, &nvmet_tcp_queue_list);
1670         mutex_unlock(&nvmet_tcp_queue_mutex);
1671
1672         ret = nvmet_tcp_set_queue_sock(queue);
1673         if (ret)
1674                 goto out_destroy_sq;
1675
1676         return 0;
1677 out_destroy_sq:
1678         mutex_lock(&nvmet_tcp_queue_mutex);
1679         list_del_init(&queue->queue_list);
1680         mutex_unlock(&nvmet_tcp_queue_mutex);
1681         nvmet_sq_destroy(&queue->nvme_sq);
1682 out_free_connect:
1683         nvmet_tcp_free_cmd(&queue->connect);
1684 out_ida_remove:
1685         ida_free(&nvmet_tcp_queue_ida, queue->idx);
1686 out_free_queue:
1687         kfree(queue);
1688         return ret;
1689 }
1690
1691 static void nvmet_tcp_accept_work(struct work_struct *w)
1692 {
1693         struct nvmet_tcp_port *port =
1694                 container_of(w, struct nvmet_tcp_port, accept_work);
1695         struct socket *newsock;
1696         int ret;
1697
1698         while (true) {
1699                 ret = kernel_accept(port->sock, &newsock, O_NONBLOCK);
1700                 if (ret < 0) {
1701                         if (ret != -EAGAIN)
1702                                 pr_warn("failed to accept err=%d\n", ret);
1703                         return;
1704                 }
1705                 ret = nvmet_tcp_alloc_queue(port, newsock);
1706                 if (ret) {
1707                         pr_err("failed to allocate queue\n");
1708                         sock_release(newsock);
1709                 }
1710         }
1711 }
1712
1713 static void nvmet_tcp_listen_data_ready(struct sock *sk)
1714 {
1715         struct nvmet_tcp_port *port;
1716
1717         trace_sk_data_ready(sk);
1718
1719         read_lock_bh(&sk->sk_callback_lock);
1720         port = sk->sk_user_data;
1721         if (!port)
1722                 goto out;
1723
1724         if (sk->sk_state == TCP_LISTEN)
1725                 queue_work(nvmet_wq, &port->accept_work);
1726 out:
1727         read_unlock_bh(&sk->sk_callback_lock);
1728 }
1729
1730 static int nvmet_tcp_add_port(struct nvmet_port *nport)
1731 {
1732         struct nvmet_tcp_port *port;
1733         __kernel_sa_family_t af;
1734         int ret;
1735
1736         port = kzalloc(sizeof(*port), GFP_KERNEL);
1737         if (!port)
1738                 return -ENOMEM;
1739
1740         switch (nport->disc_addr.adrfam) {
1741         case NVMF_ADDR_FAMILY_IP4:
1742                 af = AF_INET;
1743                 break;
1744         case NVMF_ADDR_FAMILY_IP6:
1745                 af = AF_INET6;
1746                 break;
1747         default:
1748                 pr_err("address family %d not supported\n",
1749                                 nport->disc_addr.adrfam);
1750                 ret = -EINVAL;
1751                 goto err_port;
1752         }
1753
1754         ret = inet_pton_with_scope(&init_net, af, nport->disc_addr.traddr,
1755                         nport->disc_addr.trsvcid, &port->addr);
1756         if (ret) {
1757                 pr_err("malformed ip/port passed: %s:%s\n",
1758                         nport->disc_addr.traddr, nport->disc_addr.trsvcid);
1759                 goto err_port;
1760         }
1761
1762         port->nport = nport;
1763         INIT_WORK(&port->accept_work, nvmet_tcp_accept_work);
1764         if (port->nport->inline_data_size < 0)
1765                 port->nport->inline_data_size = NVMET_TCP_DEF_INLINE_DATA_SIZE;
1766
1767         ret = sock_create(port->addr.ss_family, SOCK_STREAM,
1768                                 IPPROTO_TCP, &port->sock);
1769         if (ret) {
1770                 pr_err("failed to create a socket\n");
1771                 goto err_port;
1772         }
1773
1774         port->sock->sk->sk_user_data = port;
1775         port->data_ready = port->sock->sk->sk_data_ready;
1776         port->sock->sk->sk_data_ready = nvmet_tcp_listen_data_ready;
1777         sock_set_reuseaddr(port->sock->sk);
1778         tcp_sock_set_nodelay(port->sock->sk);
1779         if (so_priority > 0)
1780                 sock_set_priority(port->sock->sk, so_priority);
1781
1782         ret = kernel_bind(port->sock, (struct sockaddr *)&port->addr,
1783                         sizeof(port->addr));
1784         if (ret) {
1785                 pr_err("failed to bind port socket %d\n", ret);
1786                 goto err_sock;
1787         }
1788
1789         ret = kernel_listen(port->sock, 128);
1790         if (ret) {
1791                 pr_err("failed to listen %d on port sock\n", ret);
1792                 goto err_sock;
1793         }
1794
1795         nport->priv = port;
1796         pr_info("enabling port %d (%pISpc)\n",
1797                 le16_to_cpu(nport->disc_addr.portid), &port->addr);
1798
1799         return 0;
1800
1801 err_sock:
1802         sock_release(port->sock);
1803 err_port:
1804         kfree(port);
1805         return ret;
1806 }
1807
1808 static void nvmet_tcp_destroy_port_queues(struct nvmet_tcp_port *port)
1809 {
1810         struct nvmet_tcp_queue *queue;
1811
1812         mutex_lock(&nvmet_tcp_queue_mutex);
1813         list_for_each_entry(queue, &nvmet_tcp_queue_list, queue_list)
1814                 if (queue->port == port)
1815                         kernel_sock_shutdown(queue->sock, SHUT_RDWR);
1816         mutex_unlock(&nvmet_tcp_queue_mutex);
1817 }
1818
1819 static void nvmet_tcp_remove_port(struct nvmet_port *nport)
1820 {
1821         struct nvmet_tcp_port *port = nport->priv;
1822
1823         write_lock_bh(&port->sock->sk->sk_callback_lock);
1824         port->sock->sk->sk_data_ready = port->data_ready;
1825         port->sock->sk->sk_user_data = NULL;
1826         write_unlock_bh(&port->sock->sk->sk_callback_lock);
1827         cancel_work_sync(&port->accept_work);
1828         /*
1829          * Destroy the remaining queues, which are not belong to any
1830          * controller yet.
1831          */
1832         nvmet_tcp_destroy_port_queues(port);
1833
1834         sock_release(port->sock);
1835         kfree(port);
1836 }
1837
1838 static void nvmet_tcp_delete_ctrl(struct nvmet_ctrl *ctrl)
1839 {
1840         struct nvmet_tcp_queue *queue;
1841
1842         mutex_lock(&nvmet_tcp_queue_mutex);
1843         list_for_each_entry(queue, &nvmet_tcp_queue_list, queue_list)
1844                 if (queue->nvme_sq.ctrl == ctrl)
1845                         kernel_sock_shutdown(queue->sock, SHUT_RDWR);
1846         mutex_unlock(&nvmet_tcp_queue_mutex);
1847 }
1848
1849 static u16 nvmet_tcp_install_queue(struct nvmet_sq *sq)
1850 {
1851         struct nvmet_tcp_queue *queue =
1852                 container_of(sq, struct nvmet_tcp_queue, nvme_sq);
1853
1854         if (sq->qid == 0) {
1855                 /* Let inflight controller teardown complete */
1856                 flush_workqueue(nvmet_wq);
1857         }
1858
1859         queue->nr_cmds = sq->size * 2;
1860         if (nvmet_tcp_alloc_cmds(queue))
1861                 return NVME_SC_INTERNAL;
1862         return 0;
1863 }
1864
1865 static void nvmet_tcp_disc_port_addr(struct nvmet_req *req,
1866                 struct nvmet_port *nport, char *traddr)
1867 {
1868         struct nvmet_tcp_port *port = nport->priv;
1869
1870         if (inet_addr_is_any((struct sockaddr *)&port->addr)) {
1871                 struct nvmet_tcp_cmd *cmd =
1872                         container_of(req, struct nvmet_tcp_cmd, req);
1873                 struct nvmet_tcp_queue *queue = cmd->queue;
1874
1875                 sprintf(traddr, "%pISc", (struct sockaddr *)&queue->sockaddr);
1876         } else {
1877                 memcpy(traddr, nport->disc_addr.traddr, NVMF_TRADDR_SIZE);
1878         }
1879 }
1880
1881 static const struct nvmet_fabrics_ops nvmet_tcp_ops = {
1882         .owner                  = THIS_MODULE,
1883         .type                   = NVMF_TRTYPE_TCP,
1884         .msdbd                  = 1,
1885         .add_port               = nvmet_tcp_add_port,
1886         .remove_port            = nvmet_tcp_remove_port,
1887         .queue_response         = nvmet_tcp_queue_response,
1888         .delete_ctrl            = nvmet_tcp_delete_ctrl,
1889         .install_queue          = nvmet_tcp_install_queue,
1890         .disc_traddr            = nvmet_tcp_disc_port_addr,
1891 };
1892
1893 static int __init nvmet_tcp_init(void)
1894 {
1895         int ret;
1896
1897         nvmet_tcp_wq = alloc_workqueue("nvmet_tcp_wq",
1898                                 WQ_MEM_RECLAIM | WQ_HIGHPRI, 0);
1899         if (!nvmet_tcp_wq)
1900                 return -ENOMEM;
1901
1902         ret = nvmet_register_transport(&nvmet_tcp_ops);
1903         if (ret)
1904                 goto err;
1905
1906         return 0;
1907 err:
1908         destroy_workqueue(nvmet_tcp_wq);
1909         return ret;
1910 }
1911
1912 static void __exit nvmet_tcp_exit(void)
1913 {
1914         struct nvmet_tcp_queue *queue;
1915
1916         nvmet_unregister_transport(&nvmet_tcp_ops);
1917
1918         flush_workqueue(nvmet_wq);
1919         mutex_lock(&nvmet_tcp_queue_mutex);
1920         list_for_each_entry(queue, &nvmet_tcp_queue_list, queue_list)
1921                 kernel_sock_shutdown(queue->sock, SHUT_RDWR);
1922         mutex_unlock(&nvmet_tcp_queue_mutex);
1923         flush_workqueue(nvmet_wq);
1924
1925         destroy_workqueue(nvmet_tcp_wq);
1926 }
1927
1928 module_init(nvmet_tcp_init);
1929 module_exit(nvmet_tcp_exit);
1930
1931 MODULE_LICENSE("GPL v2");
1932 MODULE_ALIAS("nvmet-transport-3"); /* 3 == NVMF_TRTYPE_TCP */