]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - drivers/infiniband/core/user_mad.c
mac80211_hwsim: Fix a possible sleep-in-atomic bug in hwsim_get_radio_nl
[mirror_ubuntu-bionic-kernel.git] / drivers / infiniband / core / user_mad.c
CommitLineData
1da177e4
LT
1/*
2 * Copyright (c) 2004 Topspin Communications. All rights reserved.
3cd96564 3 * Copyright (c) 2005 Voltaire, Inc. All rights reserved.
cb183a06 4 * Copyright (c) 2005 Sun Microsystems, Inc. All rights reserved.
2fe7e6f7 5 * Copyright (c) 2008 Cisco. All rights reserved.
1da177e4
LT
6 *
7 * This software is available to you under a choice of one of two
8 * licenses. You may choose to be licensed under the terms of the GNU
9 * General Public License (GPL) Version 2, available from the file
10 * COPYING in the main directory of this source tree, or the
11 * OpenIB.org BSD license below:
12 *
13 * Redistribution and use in source and binary forms, with or
14 * without modification, are permitted provided that the following
15 * conditions are met:
16 *
17 * - Redistributions of source code must retain the above
18 * copyright notice, this list of conditions and the following
19 * disclaimer.
20 *
21 * - Redistributions in binary form must reproduce the above
22 * copyright notice, this list of conditions and the following
23 * disclaimer in the documentation and/or other materials
24 * provided with the distribution.
25 *
26 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
27 * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
28 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
29 * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
30 * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
31 * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
32 * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
33 * SOFTWARE.
1da177e4
LT
34 */
35
f426a40e
IW
36#define pr_fmt(fmt) "user_mad: " fmt
37
1da177e4
LT
38#include <linux/module.h>
39#include <linux/init.h>
40#include <linux/device.h>
41#include <linux/err.h>
42#include <linux/fs.h>
43#include <linux/cdev.h>
1da177e4
LT
44#include <linux/dma-mapping.h>
45#include <linux/poll.h>
2fe7e6f7 46#include <linux/mutex.h>
1da177e4 47#include <linux/kref.h>
a394f83b 48#include <linux/compat.h>
a99bbaf5 49#include <linux/sched.h>
6188e10d 50#include <linux/semaphore.h>
5a0e3ad6 51#include <linux/slab.h>
1da177e4 52
7c0f6ba6 53#include <linux/uaccess.h>
1da177e4 54
a4d61e84
RD
55#include <rdma/ib_mad.h>
56#include <rdma/ib_user_mad.h>
1da177e4
LT
57
58MODULE_AUTHOR("Roland Dreier");
59MODULE_DESCRIPTION("InfiniBand userspace MAD packet access");
60MODULE_LICENSE("Dual BSD/GPL");
61
62enum {
63 IB_UMAD_MAX_PORTS = 64,
64 IB_UMAD_MAX_AGENTS = 32,
65
66 IB_UMAD_MAJOR = 231,
67 IB_UMAD_MINOR_BASE = 0
68};
69
a74968f8 70/*
6aa2a86e
AC
71 * Our lifetime rules for these structs are the following:
72 * device special file is opened, we take a reference on the
73 * ib_umad_port's struct ib_umad_device. We drop these
a74968f8
RD
74 * references in the corresponding close().
75 *
76 * In addition to references coming from open character devices, there
77 * is one more reference to each ib_umad_device representing the
78 * module's reference taken when allocating the ib_umad_device in
79 * ib_umad_add_one().
80 *
6aa2a86e 81 * When destroying an ib_umad_device, we drop the module's reference.
a74968f8
RD
82 */
83
1da177e4 84struct ib_umad_port {
2b937afc 85 struct cdev cdev;
f4e91eb4 86 struct device *dev;
1da177e4 87
2b937afc 88 struct cdev sm_cdev;
f4e91eb4 89 struct device *sm_dev;
1da177e4
LT
90 struct semaphore sm_sem;
91
2fe7e6f7 92 struct mutex file_mutex;
0c99cb6d
RD
93 struct list_head file_list;
94
1da177e4
LT
95 struct ib_device *ib_dev;
96 struct ib_umad_device *umad_dev;
a74968f8 97 int dev_num;
1da177e4
LT
98 u8 port_num;
99};
100
101struct ib_umad_device {
60e1751c 102 struct kobject kobj;
1da177e4
LT
103 struct ib_umad_port port[0];
104};
105
106struct ib_umad_file {
2fe7e6f7 107 struct mutex mutex;
94382f35
RD
108 struct ib_umad_port *port;
109 struct list_head recv_list;
2527e681 110 struct list_head send_list;
94382f35 111 struct list_head port_list;
2527e681 112 spinlock_t send_lock;
94382f35
RD
113 wait_queue_head_t recv_wait;
114 struct ib_mad_agent *agent[IB_UMAD_MAX_AGENTS];
115 int agents_dead;
2be8e3ee
RD
116 u8 use_pkey_index;
117 u8 already_used;
1da177e4
LT
118};
119
120struct ib_umad_packet {
cb183a06 121 struct ib_mad_send_buf *msg;
f36e1793 122 struct ib_mad_recv_wc *recv_wc;
1da177e4 123 struct list_head list;
cb183a06 124 int length;
cb183a06 125 struct ib_user_mad mad;
1da177e4
LT
126};
127
a74968f8
RD
128static struct class *umad_class;
129
1da177e4 130static const dev_t base_dev = MKDEV(IB_UMAD_MAJOR, IB_UMAD_MINOR_BASE);
a74968f8
RD
131
132static DEFINE_SPINLOCK(port_lock);
9a4b65e3 133static DECLARE_BITMAP(dev_map, IB_UMAD_MAX_PORTS);
1da177e4
LT
134
135static void ib_umad_add_one(struct ib_device *device);
7c1eb45a 136static void ib_umad_remove_one(struct ib_device *device, void *client_data);
1da177e4 137
60e1751c 138static void ib_umad_release_dev(struct kobject *kobj)
a74968f8
RD
139{
140 struct ib_umad_device *dev =
60e1751c 141 container_of(kobj, struct ib_umad_device, kobj);
a74968f8
RD
142
143 kfree(dev);
144}
145
60e1751c
BVA
146static struct kobj_type ib_umad_dev_ktype = {
147 .release = ib_umad_release_dev,
148};
149
2be8e3ee
RD
150static int hdr_size(struct ib_umad_file *file)
151{
152 return file->use_pkey_index ? sizeof (struct ib_user_mad_hdr) :
153 sizeof (struct ib_user_mad_hdr_old);
154}
155
2fe7e6f7 156/* caller must hold file->mutex */
94382f35
RD
157static struct ib_mad_agent *__get_agent(struct ib_umad_file *file, int id)
158{
159 return file->agents_dead ? NULL : file->agent[id];
160}
161
1da177e4
LT
162static int queue_packet(struct ib_umad_file *file,
163 struct ib_mad_agent *agent,
164 struct ib_umad_packet *packet)
165{
166 int ret = 1;
167
2fe7e6f7 168 mutex_lock(&file->mutex);
94382f35 169
cb183a06
HR
170 for (packet->mad.hdr.id = 0;
171 packet->mad.hdr.id < IB_UMAD_MAX_AGENTS;
172 packet->mad.hdr.id++)
94382f35 173 if (agent == __get_agent(file, packet->mad.hdr.id)) {
1da177e4 174 list_add_tail(&packet->list, &file->recv_list);
1da177e4
LT
175 wake_up_interruptible(&file->recv_wait);
176 ret = 0;
177 break;
178 }
179
2fe7e6f7 180 mutex_unlock(&file->mutex);
1da177e4
LT
181
182 return ret;
183}
184
2527e681
SH
185static void dequeue_send(struct ib_umad_file *file,
186 struct ib_umad_packet *packet)
2fe7e6f7 187{
2527e681
SH
188 spin_lock_irq(&file->send_lock);
189 list_del(&packet->list);
190 spin_unlock_irq(&file->send_lock);
2fe7e6f7 191}
2527e681 192
1da177e4
LT
193static void send_handler(struct ib_mad_agent *agent,
194 struct ib_mad_send_wc *send_wc)
195{
196 struct ib_umad_file *file = agent->context;
34816ad9 197 struct ib_umad_packet *packet = send_wc->send_buf->context[0];
1da177e4 198
2527e681 199 dequeue_send(file, packet);
36523159 200 rdma_destroy_ah(packet->msg->ah);
cb183a06 201 ib_free_send_mad(packet->msg);
1da177e4
LT
202
203 if (send_wc->status == IB_WC_RESP_TIMEOUT_ERR) {
f36e1793
JM
204 packet->length = IB_MGMT_MAD_HDR;
205 packet->mad.hdr.status = ETIMEDOUT;
206 if (!queue_packet(file, agent, packet))
207 return;
cb183a06 208 }
1da177e4
LT
209 kfree(packet);
210}
211
212static void recv_handler(struct ib_mad_agent *agent,
ca281265 213 struct ib_mad_send_buf *send_buf,
1da177e4
LT
214 struct ib_mad_recv_wc *mad_recv_wc)
215{
216 struct ib_umad_file *file = agent->context;
217 struct ib_umad_packet *packet;
218
219 if (mad_recv_wc->wc->status != IB_WC_SUCCESS)
f36e1793 220 goto err1;
1da177e4 221
f36e1793 222 packet = kzalloc(sizeof *packet, GFP_KERNEL);
1da177e4 223 if (!packet)
f36e1793 224 goto err1;
1da177e4 225
f36e1793
JM
226 packet->length = mad_recv_wc->mad_len;
227 packet->recv_wc = mad_recv_wc;
1da177e4 228
2be8e3ee
RD
229 packet->mad.hdr.status = 0;
230 packet->mad.hdr.length = hdr_size(file) + mad_recv_wc->mad_len;
231 packet->mad.hdr.qpn = cpu_to_be32(mad_recv_wc->wc->src_qp);
6588e412
DH
232 /*
233 * On OPA devices it is okay to lose the upper 16 bits of LID as this
234 * information is obtained elsewhere. Mask off the upper 16 bits.
235 */
236 if (agent->device->port_immutable[agent->port_num].core_cap_flags &
237 RDMA_CORE_PORT_INTEL_OPA)
238 packet->mad.hdr.lid = ib_lid_be16(0xFFFF &
239 mad_recv_wc->wc->slid);
240 else
241 packet->mad.hdr.lid = ib_lid_be16(mad_recv_wc->wc->slid);
2be8e3ee
RD
242 packet->mad.hdr.sl = mad_recv_wc->wc->sl;
243 packet->mad.hdr.path_bits = mad_recv_wc->wc->dlid_path_bits;
244 packet->mad.hdr.pkey_index = mad_recv_wc->wc->pkey_index;
cb183a06
HR
245 packet->mad.hdr.grh_present = !!(mad_recv_wc->wc->wc_flags & IB_WC_GRH);
246 if (packet->mad.hdr.grh_present) {
90898850 247 struct rdma_ah_attr ah_attr;
d8966fcd 248 const struct ib_global_route *grh;
aeba84a9
SH
249
250 ib_init_ah_from_wc(agent->device, agent->port_num,
251 mad_recv_wc->wc, mad_recv_wc->recv_buf.grh,
252 &ah_attr);
253
d8966fcd
DC
254 grh = rdma_ah_read_grh(&ah_attr);
255 packet->mad.hdr.gid_index = grh->sgid_index;
256 packet->mad.hdr.hop_limit = grh->hop_limit;
257 packet->mad.hdr.traffic_class = grh->traffic_class;
258 memcpy(packet->mad.hdr.gid, &grh->dgid, 16);
259 packet->mad.hdr.flow_label = cpu_to_be32(grh->flow_label);
1da177e4
LT
260 }
261
262 if (queue_packet(file, agent, packet))
f36e1793
JM
263 goto err2;
264 return;
1da177e4 265
f36e1793
JM
266err2:
267 kfree(packet);
268err1:
1da177e4
LT
269 ib_free_recv_mad(mad_recv_wc);
270}
271
2be8e3ee
RD
272static ssize_t copy_recv_mad(struct ib_umad_file *file, char __user *buf,
273 struct ib_umad_packet *packet, size_t count)
f36e1793
JM
274{
275 struct ib_mad_recv_buf *recv_buf;
276 int left, seg_payload, offset, max_seg_payload;
8e4349d1 277 size_t seg_size;
f36e1793 278
f36e1793 279 recv_buf = &packet->recv_wc->recv_buf;
8e4349d1
IW
280 seg_size = packet->recv_wc->mad_seg_size;
281
282 /* We need enough room to copy the first (or only) MAD segment. */
283 if ((packet->length <= seg_size &&
2be8e3ee 284 count < hdr_size(file) + packet->length) ||
8e4349d1
IW
285 (packet->length > seg_size &&
286 count < hdr_size(file) + seg_size))
f36e1793
JM
287 return -EINVAL;
288
2be8e3ee 289 if (copy_to_user(buf, &packet->mad, hdr_size(file)))
f36e1793
JM
290 return -EFAULT;
291
2be8e3ee 292 buf += hdr_size(file);
8e4349d1 293 seg_payload = min_t(int, packet->length, seg_size);
f36e1793
JM
294 if (copy_to_user(buf, recv_buf->mad, seg_payload))
295 return -EFAULT;
296
297 if (seg_payload < packet->length) {
298 /*
299 * Multipacket RMPP MAD message. Copy remainder of message.
300 * Note that last segment may have a shorter payload.
301 */
2be8e3ee 302 if (count < hdr_size(file) + packet->length) {
f36e1793
JM
303 /*
304 * The buffer is too small, return the first RMPP segment,
305 * which includes the RMPP message length.
306 */
307 return -ENOSPC;
308 }
618a3c03 309 offset = ib_get_mad_data_offset(recv_buf->mad->mad_hdr.mgmt_class);
8e4349d1 310 max_seg_payload = seg_size - offset;
f36e1793
JM
311
312 for (left = packet->length - seg_payload, buf += seg_payload;
313 left; left -= seg_payload, buf += seg_payload) {
314 recv_buf = container_of(recv_buf->list.next,
315 struct ib_mad_recv_buf, list);
316 seg_payload = min(left, max_seg_payload);
317 if (copy_to_user(buf, ((void *) recv_buf->mad) + offset,
318 seg_payload))
319 return -EFAULT;
320 }
321 }
2be8e3ee 322 return hdr_size(file) + packet->length;
f36e1793
JM
323}
324
2be8e3ee
RD
325static ssize_t copy_send_mad(struct ib_umad_file *file, char __user *buf,
326 struct ib_umad_packet *packet, size_t count)
f36e1793 327{
2be8e3ee 328 ssize_t size = hdr_size(file) + packet->length;
f36e1793
JM
329
330 if (count < size)
331 return -EINVAL;
332
2be8e3ee
RD
333 if (copy_to_user(buf, &packet->mad, hdr_size(file)))
334 return -EFAULT;
335
336 buf += hdr_size(file);
337
338 if (copy_to_user(buf, packet->mad.data, packet->length))
f36e1793
JM
339 return -EFAULT;
340
341 return size;
342}
343
1da177e4
LT
344static ssize_t ib_umad_read(struct file *filp, char __user *buf,
345 size_t count, loff_t *pos)
346{
347 struct ib_umad_file *file = filp->private_data;
348 struct ib_umad_packet *packet;
349 ssize_t ret;
350
2be8e3ee 351 if (count < hdr_size(file))
1da177e4
LT
352 return -EINVAL;
353
2fe7e6f7 354 mutex_lock(&file->mutex);
1da177e4
LT
355
356 while (list_empty(&file->recv_list)) {
2fe7e6f7 357 mutex_unlock(&file->mutex);
1da177e4
LT
358
359 if (filp->f_flags & O_NONBLOCK)
360 return -EAGAIN;
361
362 if (wait_event_interruptible(file->recv_wait,
363 !list_empty(&file->recv_list)))
364 return -ERESTARTSYS;
365
2fe7e6f7 366 mutex_lock(&file->mutex);
1da177e4
LT
367 }
368
369 packet = list_entry(file->recv_list.next, struct ib_umad_packet, list);
370 list_del(&packet->list);
371
2fe7e6f7 372 mutex_unlock(&file->mutex);
1da177e4 373
f36e1793 374 if (packet->recv_wc)
2be8e3ee 375 ret = copy_recv_mad(file, buf, packet, count);
1da177e4 376 else
2be8e3ee 377 ret = copy_send_mad(file, buf, packet, count);
f36e1793 378
cb183a06
HR
379 if (ret < 0) {
380 /* Requeue packet */
2fe7e6f7 381 mutex_lock(&file->mutex);
cb183a06 382 list_add(&packet->list, &file->recv_list);
2fe7e6f7 383 mutex_unlock(&file->mutex);
f36e1793
JM
384 } else {
385 if (packet->recv_wc)
386 ib_free_recv_mad(packet->recv_wc);
cb183a06 387 kfree(packet);
f36e1793 388 }
1da177e4
LT
389 return ret;
390}
391
f36e1793
JM
392static int copy_rmpp_mad(struct ib_mad_send_buf *msg, const char __user *buf)
393{
394 int left, seg;
395
396 /* Copy class specific header */
397 if ((msg->hdr_len > IB_MGMT_RMPP_HDR) &&
398 copy_from_user(msg->mad + IB_MGMT_RMPP_HDR, buf + IB_MGMT_RMPP_HDR,
399 msg->hdr_len - IB_MGMT_RMPP_HDR))
400 return -EFAULT;
401
402 /* All headers are in place. Copy data segments. */
403 for (seg = 1, left = msg->data_len, buf += msg->hdr_len; left > 0;
404 seg++, left -= msg->seg_size, buf += msg->seg_size) {
405 if (copy_from_user(ib_get_rmpp_segment(msg, seg), buf,
406 min(left, msg->seg_size)))
407 return -EFAULT;
408 }
409 return 0;
410}
411
2527e681
SH
412static int same_destination(struct ib_user_mad_hdr *hdr1,
413 struct ib_user_mad_hdr *hdr2)
414{
415 if (!hdr1->grh_present && !hdr2->grh_present)
416 return (hdr1->lid == hdr2->lid);
417
418 if (hdr1->grh_present && hdr2->grh_present)
419 return !memcmp(hdr1->gid, hdr2->gid, 16);
420
421 return 0;
422}
423
424static int is_duplicate(struct ib_umad_file *file,
425 struct ib_umad_packet *packet)
426{
427 struct ib_umad_packet *sent_packet;
428 struct ib_mad_hdr *sent_hdr, *hdr;
429
430 hdr = (struct ib_mad_hdr *) packet->mad.data;
431 list_for_each_entry(sent_packet, &file->send_list, list) {
432 sent_hdr = (struct ib_mad_hdr *) sent_packet->mad.data;
433
434 if ((hdr->tid != sent_hdr->tid) ||
435 (hdr->mgmt_class != sent_hdr->mgmt_class))
436 continue;
437
438 /*
439 * No need to be overly clever here. If two new operations have
440 * the same TID, reject the second as a duplicate. This is more
441 * restrictive than required by the spec.
442 */
96909308
IW
443 if (!ib_response_mad(hdr)) {
444 if (!ib_response_mad(sent_hdr))
2527e681
SH
445 return 1;
446 continue;
96909308 447 } else if (!ib_response_mad(sent_hdr))
2527e681
SH
448 continue;
449
450 if (same_destination(&packet->mad.hdr, &sent_packet->mad.hdr))
451 return 1;
452 }
453
454 return 0;
455}
456
1da177e4
LT
457static ssize_t ib_umad_write(struct file *filp, const char __user *buf,
458 size_t count, loff_t *pos)
459{
460 struct ib_umad_file *file = filp->private_data;
461 struct ib_umad_packet *packet;
462 struct ib_mad_agent *agent;
90898850 463 struct rdma_ah_attr ah_attr;
34816ad9 464 struct ib_ah *ah;
cb183a06 465 struct ib_rmpp_mad *rmpp_mad;
97f52eb4 466 __be64 *tid;
f36e1793 467 int ret, data_len, hdr_len, copy_offset, rmpp_active;
8e4349d1 468 u8 base_version;
1da177e4 469
2be8e3ee 470 if (count < hdr_size(file) + IB_MGMT_RMPP_HDR)
1da177e4
LT
471 return -EINVAL;
472
f36e1793 473 packet = kzalloc(sizeof *packet + IB_MGMT_RMPP_HDR, GFP_KERNEL);
1da177e4
LT
474 if (!packet)
475 return -ENOMEM;
476
2be8e3ee 477 if (copy_from_user(&packet->mad, buf, hdr_size(file))) {
cb183a06
HR
478 ret = -EFAULT;
479 goto err;
1da177e4
LT
480 }
481
caf6e3f2 482 if (packet->mad.hdr.id >= IB_UMAD_MAX_AGENTS) {
1da177e4
LT
483 ret = -EINVAL;
484 goto err;
485 }
486
2be8e3ee
RD
487 buf += hdr_size(file);
488
489 if (copy_from_user(packet->mad.data, buf, IB_MGMT_RMPP_HDR)) {
490 ret = -EFAULT;
491 goto err;
492 }
493
2fe7e6f7 494 mutex_lock(&file->mutex);
1da177e4 495
94382f35 496 agent = __get_agent(file, packet->mad.hdr.id);
1da177e4
LT
497 if (!agent) {
498 ret = -EINVAL;
499 goto err_up;
500 }
501
1da177e4 502 memset(&ah_attr, 0, sizeof ah_attr);
44c58487
DC
503 ah_attr.type = rdma_ah_find_type(file->port->ib_dev,
504 file->port->port_num);
d8966fcd
DC
505 rdma_ah_set_dlid(&ah_attr, be16_to_cpu(packet->mad.hdr.lid));
506 rdma_ah_set_sl(&ah_attr, packet->mad.hdr.sl);
507 rdma_ah_set_path_bits(&ah_attr, packet->mad.hdr.path_bits);
508 rdma_ah_set_port_num(&ah_attr, file->port->port_num);
cb183a06 509 if (packet->mad.hdr.grh_present) {
d8966fcd
DC
510 rdma_ah_set_grh(&ah_attr, NULL,
511 be32_to_cpu(packet->mad.hdr.flow_label),
512 packet->mad.hdr.gid_index,
513 packet->mad.hdr.hop_limit,
514 packet->mad.hdr.traffic_class);
515 rdma_ah_set_dgid_raw(&ah_attr, packet->mad.hdr.gid);
1da177e4
LT
516 }
517
5cda6587 518 ah = rdma_create_user_ah(agent->qp->pd, &ah_attr, NULL);
34816ad9
SH
519 if (IS_ERR(ah)) {
520 ret = PTR_ERR(ah);
1da177e4
LT
521 goto err_up;
522 }
523
cb183a06 524 rmpp_mad = (struct ib_rmpp_mad *) packet->mad.data;
618a3c03 525 hdr_len = ib_get_mad_data_offset(rmpp_mad->mad_hdr.mgmt_class);
1471cb6c
IW
526
527 if (ib_is_mad_class_rmpp(rmpp_mad->mad_hdr.mgmt_class)
528 && ib_mad_kernel_rmpp_agent(agent)) {
f36e1793
JM
529 copy_offset = IB_MGMT_RMPP_HDR;
530 rmpp_active = ib_get_rmpp_flags(&rmpp_mad->rmpp_hdr) &
1471cb6c
IW
531 IB_MGMT_RMPP_FLAG_ACTIVE;
532 } else {
533 copy_offset = IB_MGMT_MAD_HDR;
534 rmpp_active = 0;
cb183a06
HR
535 }
536
8e4349d1 537 base_version = ((struct ib_mad_hdr *)&packet->mad.data)->base_version;
2be8e3ee 538 data_len = count - hdr_size(file) - hdr_len;
cb183a06
HR
539 packet->msg = ib_create_send_mad(agent,
540 be32_to_cpu(packet->mad.hdr.qpn),
2be8e3ee 541 packet->mad.hdr.pkey_index, rmpp_active,
da2dfaa3 542 hdr_len, data_len, GFP_KERNEL,
8e4349d1 543 base_version);
cb183a06
HR
544 if (IS_ERR(packet->msg)) {
545 ret = PTR_ERR(packet->msg);
546 goto err_ah;
547 }
1da177e4 548
d3f2c67f 549 packet->msg->ah = ah;
34816ad9 550 packet->msg->timeout_ms = packet->mad.hdr.timeout_ms;
d3f2c67f 551 packet->msg->retries = packet->mad.hdr.retries;
34816ad9 552 packet->msg->context[0] = packet;
1da177e4 553
f36e1793 554 /* Copy MAD header. Any RMPP header is already in place. */
cb0f0910 555 memcpy(packet->msg->mad, packet->mad.data, IB_MGMT_MAD_HDR);
f36e1793
JM
556
557 if (!rmpp_active) {
558 if (copy_from_user(packet->msg->mad + copy_offset,
559 buf + copy_offset,
560 hdr_len + data_len - copy_offset)) {
561 ret = -EFAULT;
562 goto err_msg;
563 }
564 } else {
565 ret = copy_rmpp_mad(packet->msg, buf);
566 if (ret)
567 goto err_msg;
cb183a06
HR
568 }
569
570 /*
2527e681
SH
571 * Set the high-order part of the transaction ID to make MADs from
572 * different agents unique, and allow routing responses back to the
573 * original requestor.
cb183a06 574 */
2527e681 575 if (!ib_response_mad(packet->msg->mad)) {
089a1bed 576 tid = &((struct ib_mad_hdr *) packet->msg->mad)->tid;
cb183a06
HR
577 *tid = cpu_to_be64(((u64) agent->hi_tid) << 32 |
578 (be64_to_cpup(tid) & 0xffffffff));
2527e681
SH
579 rmpp_mad->mad_hdr.tid = *tid;
580 }
581
1471cb6c
IW
582 if (!ib_mad_kernel_rmpp_agent(agent)
583 && ib_is_mad_class_rmpp(rmpp_mad->mad_hdr.mgmt_class)
584 && (ib_get_rmpp_flags(&rmpp_mad->rmpp_hdr) & IB_MGMT_RMPP_FLAG_ACTIVE)) {
585 spin_lock_irq(&file->send_lock);
2527e681 586 list_add_tail(&packet->list, &file->send_list);
1471cb6c
IW
587 spin_unlock_irq(&file->send_lock);
588 } else {
589 spin_lock_irq(&file->send_lock);
590 ret = is_duplicate(file, packet);
591 if (!ret)
592 list_add_tail(&packet->list, &file->send_list);
593 spin_unlock_irq(&file->send_lock);
594 if (ret) {
595 ret = -EINVAL;
596 goto err_msg;
597 }
1da177e4
LT
598 }
599
34816ad9 600 ret = ib_post_send_mad(packet->msg, NULL);
cb183a06 601 if (ret)
2527e681 602 goto err_send;
cb183a06 603
2fe7e6f7 604 mutex_unlock(&file->mutex);
cb0f0910 605 return count;
cb183a06 606
2527e681
SH
607err_send:
608 dequeue_send(file, packet);
cb183a06
HR
609err_msg:
610 ib_free_send_mad(packet->msg);
cb183a06 611err_ah:
36523159 612 rdma_destroy_ah(ah);
1da177e4 613err_up:
2fe7e6f7 614 mutex_unlock(&file->mutex);
1da177e4
LT
615err:
616 kfree(packet);
617 return ret;
618}
619
620static unsigned int ib_umad_poll(struct file *filp, struct poll_table_struct *wait)
621{
622 struct ib_umad_file *file = filp->private_data;
623
624 /* we will always be able to post a MAD send */
625 unsigned int mask = POLLOUT | POLLWRNORM;
626
627 poll_wait(filp, &file->recv_wait, wait);
628
629 if (!list_empty(&file->recv_list))
630 mask |= POLLIN | POLLRDNORM;
631
632 return mask;
633}
634
a394f83b
RD
635static int ib_umad_reg_agent(struct ib_umad_file *file, void __user *arg,
636 int compat_method_mask)
1da177e4
LT
637{
638 struct ib_user_mad_reg_req ureq;
639 struct ib_mad_reg_req req;
2fe7e6f7 640 struct ib_mad_agent *agent = NULL;
1da177e4
LT
641 int agent_id;
642 int ret;
643
2fe7e6f7
RD
644 mutex_lock(&file->port->file_mutex);
645 mutex_lock(&file->mutex);
0c99cb6d
RD
646
647 if (!file->port->ib_dev) {
9ad13a42
IW
648 dev_notice(file->port->dev,
649 "ib_umad_reg_agent: invalid device\n");
0c99cb6d
RD
650 ret = -EPIPE;
651 goto out;
652 }
1da177e4 653
a394f83b 654 if (copy_from_user(&ureq, arg, sizeof ureq)) {
1da177e4
LT
655 ret = -EFAULT;
656 goto out;
657 }
658
659 if (ureq.qpn != 0 && ureq.qpn != 1) {
9ad13a42
IW
660 dev_notice(file->port->dev,
661 "ib_umad_reg_agent: invalid QPN %d specified\n",
662 ureq.qpn);
1da177e4
LT
663 ret = -EINVAL;
664 goto out;
665 }
666
667 for (agent_id = 0; agent_id < IB_UMAD_MAX_AGENTS; ++agent_id)
94382f35 668 if (!__get_agent(file, agent_id))
1da177e4
LT
669 goto found;
670
9ad13a42
IW
671 dev_notice(file->port->dev,
672 "ib_umad_reg_agent: Max Agents (%u) reached\n",
673 IB_UMAD_MAX_AGENTS);
1da177e4
LT
674 ret = -ENOMEM;
675 goto out;
676
677found:
0df3bb13 678 if (ureq.mgmt_class) {
0f29b46d 679 memset(&req, 0, sizeof(req));
0df3bb13
RD
680 req.mgmt_class = ureq.mgmt_class;
681 req.mgmt_class_version = ureq.mgmt_class_version;
a394f83b
RD
682 memcpy(req.oui, ureq.oui, sizeof req.oui);
683
684 if (compat_method_mask) {
685 u32 *umm = (u32 *) ureq.method_mask;
686 int i;
687
688 for (i = 0; i < BITS_TO_LONGS(IB_MGMT_MAX_METHODS); ++i)
689 req.method_mask[i] =
690 umm[i * 2] | ((u64) umm[i * 2 + 1] << 32);
691 } else
692 memcpy(req.method_mask, ureq.method_mask,
693 sizeof req.method_mask);
0df3bb13 694 }
1da177e4
LT
695
696 agent = ib_register_mad_agent(file->port->ib_dev, file->port->port_num,
697 ureq.qpn ? IB_QPT_GSI : IB_QPT_SMI,
0df3bb13 698 ureq.mgmt_class ? &req : NULL,
cb183a06 699 ureq.rmpp_version,
0f29b46d 700 send_handler, recv_handler, file, 0);
1da177e4
LT
701 if (IS_ERR(agent)) {
702 ret = PTR_ERR(agent);
2fe7e6f7 703 agent = NULL;
1da177e4
LT
704 goto out;
705 }
706
1da177e4
LT
707 if (put_user(agent_id,
708 (u32 __user *) (arg + offsetof(struct ib_user_mad_reg_req, id)))) {
709 ret = -EFAULT;
ec914c52 710 goto out;
1da177e4
LT
711 }
712
2be8e3ee
RD
713 if (!file->already_used) {
714 file->already_used = 1;
715 if (!file->use_pkey_index) {
f426a40e
IW
716 dev_warn(file->port->dev,
717 "process %s did not enable P_Key index support.\n",
718 current->comm);
719 dev_warn(file->port->dev,
720 " Documentation/infiniband/user_mad.txt has info on the new ABI.\n");
2be8e3ee
RD
721 }
722 }
723
2f76e829 724 file->agent[agent_id] = agent;
1da177e4 725 ret = 0;
2f76e829 726
1da177e4 727out:
2fe7e6f7
RD
728 mutex_unlock(&file->mutex);
729
730 if (ret && agent)
731 ib_unregister_mad_agent(agent);
732
733 mutex_unlock(&file->port->file_mutex);
734
1da177e4
LT
735 return ret;
736}
737
0f29b46d
IW
738static int ib_umad_reg_agent2(struct ib_umad_file *file, void __user *arg)
739{
740 struct ib_user_mad_reg_req2 ureq;
741 struct ib_mad_reg_req req;
742 struct ib_mad_agent *agent = NULL;
743 int agent_id;
744 int ret;
745
746 mutex_lock(&file->port->file_mutex);
747 mutex_lock(&file->mutex);
748
749 if (!file->port->ib_dev) {
750 dev_notice(file->port->dev,
751 "ib_umad_reg_agent2: invalid device\n");
752 ret = -EPIPE;
753 goto out;
754 }
755
756 if (copy_from_user(&ureq, arg, sizeof(ureq))) {
757 ret = -EFAULT;
758 goto out;
759 }
760
761 if (ureq.qpn != 0 && ureq.qpn != 1) {
762 dev_notice(file->port->dev,
763 "ib_umad_reg_agent2: invalid QPN %d specified\n",
764 ureq.qpn);
765 ret = -EINVAL;
766 goto out;
767 }
768
769 if (ureq.flags & ~IB_USER_MAD_REG_FLAGS_CAP) {
770 dev_notice(file->port->dev,
771 "ib_umad_reg_agent2 failed: invalid registration flags specified 0x%x; supported 0x%x\n",
772 ureq.flags, IB_USER_MAD_REG_FLAGS_CAP);
773 ret = -EINVAL;
774
775 if (put_user((u32)IB_USER_MAD_REG_FLAGS_CAP,
776 (u32 __user *) (arg + offsetof(struct
777 ib_user_mad_reg_req2, flags))))
778 ret = -EFAULT;
779
780 goto out;
781 }
782
783 for (agent_id = 0; agent_id < IB_UMAD_MAX_AGENTS; ++agent_id)
784 if (!__get_agent(file, agent_id))
785 goto found;
786
787 dev_notice(file->port->dev,
788 "ib_umad_reg_agent2: Max Agents (%u) reached\n",
789 IB_UMAD_MAX_AGENTS);
790 ret = -ENOMEM;
791 goto out;
792
793found:
794 if (ureq.mgmt_class) {
795 memset(&req, 0, sizeof(req));
796 req.mgmt_class = ureq.mgmt_class;
797 req.mgmt_class_version = ureq.mgmt_class_version;
798 if (ureq.oui & 0xff000000) {
799 dev_notice(file->port->dev,
800 "ib_umad_reg_agent2 failed: oui invalid 0x%08x\n",
801 ureq.oui);
802 ret = -EINVAL;
803 goto out;
804 }
805 req.oui[2] = ureq.oui & 0x0000ff;
806 req.oui[1] = (ureq.oui & 0x00ff00) >> 8;
807 req.oui[0] = (ureq.oui & 0xff0000) >> 16;
808 memcpy(req.method_mask, ureq.method_mask,
809 sizeof(req.method_mask));
810 }
811
812 agent = ib_register_mad_agent(file->port->ib_dev, file->port->port_num,
813 ureq.qpn ? IB_QPT_GSI : IB_QPT_SMI,
814 ureq.mgmt_class ? &req : NULL,
815 ureq.rmpp_version,
816 send_handler, recv_handler, file,
817 ureq.flags);
818 if (IS_ERR(agent)) {
819 ret = PTR_ERR(agent);
820 agent = NULL;
821 goto out;
822 }
823
824 if (put_user(agent_id,
825 (u32 __user *)(arg +
826 offsetof(struct ib_user_mad_reg_req2, id)))) {
827 ret = -EFAULT;
828 goto out;
829 }
830
831 if (!file->already_used) {
832 file->already_used = 1;
833 file->use_pkey_index = 1;
834 }
835
836 file->agent[agent_id] = agent;
837 ret = 0;
838
839out:
840 mutex_unlock(&file->mutex);
841
842 if (ret && agent)
843 ib_unregister_mad_agent(agent);
844
845 mutex_unlock(&file->port->file_mutex);
846
847 return ret;
848}
849
850
a394f83b 851static int ib_umad_unreg_agent(struct ib_umad_file *file, u32 __user *arg)
1da177e4 852{
2f76e829 853 struct ib_mad_agent *agent = NULL;
1da177e4
LT
854 u32 id;
855 int ret = 0;
856
a394f83b 857 if (get_user(id, arg))
2f76e829 858 return -EFAULT;
1da177e4 859
2fe7e6f7
RD
860 mutex_lock(&file->port->file_mutex);
861 mutex_lock(&file->mutex);
1da177e4 862
caf6e3f2 863 if (id >= IB_UMAD_MAX_AGENTS || !__get_agent(file, id)) {
1da177e4
LT
864 ret = -EINVAL;
865 goto out;
866 }
867
2f76e829 868 agent = file->agent[id];
1da177e4
LT
869 file->agent[id] = NULL;
870
871out:
2fe7e6f7 872 mutex_unlock(&file->mutex);
2f76e829 873
ec914c52 874 if (agent)
2f76e829 875 ib_unregister_mad_agent(agent);
2f76e829 876
2fe7e6f7
RD
877 mutex_unlock(&file->port->file_mutex);
878
1da177e4
LT
879 return ret;
880}
881
2be8e3ee
RD
882static long ib_umad_enable_pkey(struct ib_umad_file *file)
883{
884 int ret = 0;
885
2fe7e6f7 886 mutex_lock(&file->mutex);
2be8e3ee
RD
887 if (file->already_used)
888 ret = -EINVAL;
889 else
890 file->use_pkey_index = 1;
2fe7e6f7 891 mutex_unlock(&file->mutex);
2be8e3ee
RD
892
893 return ret;
894}
895
cb183a06
HR
896static long ib_umad_ioctl(struct file *filp, unsigned int cmd,
897 unsigned long arg)
1da177e4
LT
898{
899 switch (cmd) {
900 case IB_USER_MAD_REGISTER_AGENT:
a394f83b 901 return ib_umad_reg_agent(filp->private_data, (void __user *) arg, 0);
1da177e4 902 case IB_USER_MAD_UNREGISTER_AGENT:
a394f83b 903 return ib_umad_unreg_agent(filp->private_data, (__u32 __user *) arg);
2be8e3ee
RD
904 case IB_USER_MAD_ENABLE_PKEY:
905 return ib_umad_enable_pkey(filp->private_data);
0f29b46d
IW
906 case IB_USER_MAD_REGISTER_AGENT2:
907 return ib_umad_reg_agent2(filp->private_data, (void __user *) arg);
1da177e4
LT
908 default:
909 return -ENOIOCTLCMD;
910 }
911}
912
a394f83b
RD
913#ifdef CONFIG_COMPAT
914static long ib_umad_compat_ioctl(struct file *filp, unsigned int cmd,
915 unsigned long arg)
916{
917 switch (cmd) {
918 case IB_USER_MAD_REGISTER_AGENT:
919 return ib_umad_reg_agent(filp->private_data, compat_ptr(arg), 1);
920 case IB_USER_MAD_UNREGISTER_AGENT:
921 return ib_umad_unreg_agent(filp->private_data, compat_ptr(arg));
922 case IB_USER_MAD_ENABLE_PKEY:
923 return ib_umad_enable_pkey(filp->private_data);
0f29b46d
IW
924 case IB_USER_MAD_REGISTER_AGENT2:
925 return ib_umad_reg_agent2(filp->private_data, compat_ptr(arg));
a394f83b
RD
926 default:
927 return -ENOIOCTLCMD;
928 }
929}
930#endif
931
feae1ef1
RD
932/*
933 * ib_umad_open() does not need the BKL:
934 *
6aa2a86e 935 * - the ib_umad_port structures are properly reference counted, and
feae1ef1
RD
936 * everything else is purely local to the file being created, so
937 * races against other open calls are not a problem;
938 * - the ioctl method does not affect any global state outside of the
939 * file structure being operated on;
feae1ef1 940 */
1da177e4
LT
941static int ib_umad_open(struct inode *inode, struct file *filp)
942{
a74968f8 943 struct ib_umad_port *port;
1da177e4 944 struct ib_umad_file *file;
8ec0a0e6 945 int ret = -ENXIO;
1da177e4 946
6aa2a86e 947 port = container_of(inode->i_cdev, struct ib_umad_port, cdev);
a74968f8 948
2fe7e6f7 949 mutex_lock(&port->file_mutex);
0c99cb6d 950
8ec0a0e6 951 if (!port->ib_dev)
0c99cb6d 952 goto out;
0c99cb6d 953
8ec0a0e6 954 ret = -ENOMEM;
cb0f0910 955 file = kzalloc(sizeof *file, GFP_KERNEL);
8ec0a0e6 956 if (!file)
0c99cb6d 957 goto out;
1da177e4 958
2fe7e6f7 959 mutex_init(&file->mutex);
2527e681 960 spin_lock_init(&file->send_lock);
1da177e4 961 INIT_LIST_HEAD(&file->recv_list);
2527e681 962 INIT_LIST_HEAD(&file->send_list);
1da177e4
LT
963 init_waitqueue_head(&file->recv_wait);
964
965 file->port = port;
966 filp->private_data = file;
967
0c99cb6d
RD
968 list_add_tail(&file->port_list, &port->file_list);
969
bc1db9af 970 ret = nonseekable_open(inode, filp);
8ec0a0e6
BVA
971 if (ret) {
972 list_del(&file->port_list);
973 kfree(file);
974 goto out;
975 }
976
60e1751c 977 kobject_get(&port->umad_dev->kobj);
bc1db9af 978
0c99cb6d 979out:
2fe7e6f7 980 mutex_unlock(&port->file_mutex);
0c99cb6d 981 return ret;
1da177e4
LT
982}
983
984static int ib_umad_close(struct inode *inode, struct file *filp)
985{
986 struct ib_umad_file *file = filp->private_data;
a74968f8 987 struct ib_umad_device *dev = file->port->umad_dev;
561e148e 988 struct ib_umad_packet *packet, *tmp;
94382f35 989 int already_dead;
1da177e4
LT
990 int i;
991
2fe7e6f7
RD
992 mutex_lock(&file->port->file_mutex);
993 mutex_lock(&file->mutex);
94382f35
RD
994
995 already_dead = file->agents_dead;
996 file->agents_dead = 1;
1da177e4 997
f36e1793
JM
998 list_for_each_entry_safe(packet, tmp, &file->recv_list, list) {
999 if (packet->recv_wc)
1000 ib_free_recv_mad(packet->recv_wc);
561e148e 1001 kfree(packet);
f36e1793 1002 }
561e148e 1003
0c99cb6d 1004 list_del(&file->port_list);
0c99cb6d 1005
2fe7e6f7 1006 mutex_unlock(&file->mutex);
94382f35
RD
1007
1008 if (!already_dead)
1009 for (i = 0; i < IB_UMAD_MAX_AGENTS; ++i)
1010 if (file->agent[i])
1011 ib_unregister_mad_agent(file->agent[i]);
1da177e4 1012
2fe7e6f7 1013 mutex_unlock(&file->port->file_mutex);
94382f35
RD
1014
1015 kfree(file);
60e1751c 1016 kobject_put(&dev->kobj);
a74968f8 1017
1da177e4
LT
1018 return 0;
1019}
1020
2b8693c0 1021static const struct file_operations umad_fops = {
d3f2c67f
AC
1022 .owner = THIS_MODULE,
1023 .read = ib_umad_read,
1024 .write = ib_umad_write,
1025 .poll = ib_umad_poll,
1da177e4 1026 .unlocked_ioctl = ib_umad_ioctl,
a394f83b 1027#ifdef CONFIG_COMPAT
d3f2c67f 1028 .compat_ioctl = ib_umad_compat_ioctl,
a394f83b 1029#endif
d3f2c67f 1030 .open = ib_umad_open,
bc1db9af
RD
1031 .release = ib_umad_close,
1032 .llseek = no_llseek,
1da177e4
LT
1033};
1034
1035static int ib_umad_sm_open(struct inode *inode, struct file *filp)
1036{
a74968f8 1037 struct ib_umad_port *port;
1da177e4
LT
1038 struct ib_port_modify props = {
1039 .set_port_cap_mask = IB_PORT_SM
1040 };
1041 int ret;
1042
6aa2a86e 1043 port = container_of(inode->i_cdev, struct ib_umad_port, sm_cdev);
a74968f8 1044
1da177e4 1045 if (filp->f_flags & O_NONBLOCK) {
a74968f8
RD
1046 if (down_trylock(&port->sm_sem)) {
1047 ret = -EAGAIN;
1048 goto fail;
1049 }
1da177e4 1050 } else {
a74968f8
RD
1051 if (down_interruptible(&port->sm_sem)) {
1052 ret = -ERESTARTSYS;
1053 goto fail;
1054 }
1da177e4
LT
1055 }
1056
1057 ret = ib_modify_port(port->ib_dev, port->port_num, 0, &props);
8ec0a0e6
BVA
1058 if (ret)
1059 goto err_up_sem;
1da177e4
LT
1060
1061 filp->private_data = port;
1062
8ec0a0e6
BVA
1063 ret = nonseekable_open(inode, filp);
1064 if (ret)
1065 goto err_clr_sm_cap;
1066
60e1751c 1067 kobject_get(&port->umad_dev->kobj);
8ec0a0e6
BVA
1068
1069 return 0;
1070
1071err_clr_sm_cap:
1072 swap(props.set_port_cap_mask, props.clr_port_cap_mask);
1073 ib_modify_port(port->ib_dev, port->port_num, 0, &props);
1074
1075err_up_sem:
1076 up(&port->sm_sem);
a74968f8
RD
1077
1078fail:
a74968f8 1079 return ret;
1da177e4
LT
1080}
1081
1082static int ib_umad_sm_close(struct inode *inode, struct file *filp)
1083{
1084 struct ib_umad_port *port = filp->private_data;
1085 struct ib_port_modify props = {
1086 .clr_port_cap_mask = IB_PORT_SM
1087 };
0c99cb6d
RD
1088 int ret = 0;
1089
2fe7e6f7 1090 mutex_lock(&port->file_mutex);
0c99cb6d
RD
1091 if (port->ib_dev)
1092 ret = ib_modify_port(port->ib_dev, port->port_num, 0, &props);
2fe7e6f7 1093 mutex_unlock(&port->file_mutex);
1da177e4 1094
1da177e4
LT
1095 up(&port->sm_sem);
1096
60e1751c 1097 kobject_put(&port->umad_dev->kobj);
a74968f8 1098
1da177e4
LT
1099 return ret;
1100}
1101
2b8693c0 1102static const struct file_operations umad_sm_fops = {
d3f2c67f
AC
1103 .owner = THIS_MODULE,
1104 .open = ib_umad_sm_open,
bc1db9af
RD
1105 .release = ib_umad_sm_close,
1106 .llseek = no_llseek,
1da177e4
LT
1107};
1108
1109static struct ib_client umad_client = {
1110 .name = "umad",
1111 .add = ib_umad_add_one,
1112 .remove = ib_umad_remove_one
1113};
1114
f4e91eb4
TJ
1115static ssize_t show_ibdev(struct device *dev, struct device_attribute *attr,
1116 char *buf)
1da177e4 1117{
f4e91eb4 1118 struct ib_umad_port *port = dev_get_drvdata(dev);
1da177e4 1119
a74968f8
RD
1120 if (!port)
1121 return -ENODEV;
1122
1da177e4
LT
1123 return sprintf(buf, "%s\n", port->ib_dev->name);
1124}
f4e91eb4 1125static DEVICE_ATTR(ibdev, S_IRUGO, show_ibdev, NULL);
1da177e4 1126
f4e91eb4
TJ
1127static ssize_t show_port(struct device *dev, struct device_attribute *attr,
1128 char *buf)
1da177e4 1129{
f4e91eb4 1130 struct ib_umad_port *port = dev_get_drvdata(dev);
1da177e4 1131
a74968f8
RD
1132 if (!port)
1133 return -ENODEV;
1134
1da177e4
LT
1135 return sprintf(buf, "%d\n", port->port_num);
1136}
f4e91eb4 1137static DEVICE_ATTR(port, S_IRUGO, show_port, NULL);
1da177e4 1138
0933e2d9
AK
1139static CLASS_ATTR_STRING(abi_version, S_IRUGO,
1140 __stringify(IB_USER_MAD_ABI_VERSION));
1da177e4 1141
8698d3fe
AC
1142static dev_t overflow_maj;
1143static DECLARE_BITMAP(overflow_map, IB_UMAD_MAX_PORTS);
f426a40e 1144static int find_overflow_devnum(struct ib_device *device)
8698d3fe
AC
1145{
1146 int ret;
1147
1148 if (!overflow_maj) {
1149 ret = alloc_chrdev_region(&overflow_maj, 0, IB_UMAD_MAX_PORTS * 2,
1150 "infiniband_mad");
1151 if (ret) {
f426a40e
IW
1152 dev_err(&device->dev,
1153 "couldn't register dynamic device number\n");
8698d3fe
AC
1154 return ret;
1155 }
1156 }
1157
1158 ret = find_first_zero_bit(overflow_map, IB_UMAD_MAX_PORTS);
1159 if (ret >= IB_UMAD_MAX_PORTS)
1160 return -1;
1161
1162 return ret;
1163}
1164
1da177e4 1165static int ib_umad_init_port(struct ib_device *device, int port_num,
60e1751c 1166 struct ib_umad_device *umad_dev,
1da177e4
LT
1167 struct ib_umad_port *port)
1168{
d451b8df 1169 int devnum;
dc2ed5e3 1170 dev_t base;
d451b8df 1171
a74968f8 1172 spin_lock(&port_lock);
d451b8df
AC
1173 devnum = find_first_zero_bit(dev_map, IB_UMAD_MAX_PORTS);
1174 if (devnum >= IB_UMAD_MAX_PORTS) {
a74968f8 1175 spin_unlock(&port_lock);
f426a40e 1176 devnum = find_overflow_devnum(device);
8698d3fe
AC
1177 if (devnum < 0)
1178 return -1;
1179
1180 spin_lock(&port_lock);
1181 port->dev_num = devnum + IB_UMAD_MAX_PORTS;
1182 base = devnum + overflow_maj;
1183 set_bit(devnum, overflow_map);
1184 } else {
1185 port->dev_num = devnum;
1186 base = devnum + base_dev;
1187 set_bit(devnum, dev_map);
1da177e4 1188 }
a74968f8 1189 spin_unlock(&port_lock);
1da177e4
LT
1190
1191 port->ib_dev = device;
1192 port->port_num = port_num;
557d0540 1193 sema_init(&port->sm_sem, 1);
2fe7e6f7 1194 mutex_init(&port->file_mutex);
0c99cb6d 1195 INIT_LIST_HEAD(&port->file_list);
1da177e4 1196
2b937afc
AC
1197 cdev_init(&port->cdev, &umad_fops);
1198 port->cdev.owner = THIS_MODULE;
98508715 1199 cdev_set_parent(&port->cdev, &umad_dev->kobj);
2b937afc 1200 kobject_set_name(&port->cdev.kobj, "umad%d", port->dev_num);
dc2ed5e3 1201 if (cdev_add(&port->cdev, base, 1))
1da177e4
LT
1202 goto err_cdev;
1203
1e35a088 1204 port->dev = device_create(umad_class, device->dev.parent,
2b937afc 1205 port->cdev.dev, port,
91bd418f 1206 "umad%d", port->dev_num);
f4e91eb4 1207 if (IS_ERR(port->dev))
a74968f8 1208 goto err_cdev;
1da177e4 1209
f4e91eb4
TJ
1210 if (device_create_file(port->dev, &dev_attr_ibdev))
1211 goto err_dev;
1212 if (device_create_file(port->dev, &dev_attr_port))
1213 goto err_dev;
1214
dc2ed5e3 1215 base += IB_UMAD_MAX_PORTS;
2b937afc
AC
1216 cdev_init(&port->sm_cdev, &umad_sm_fops);
1217 port->sm_cdev.owner = THIS_MODULE;
98508715 1218 cdev_set_parent(&port->sm_cdev, &umad_dev->kobj);
2b937afc 1219 kobject_set_name(&port->sm_cdev.kobj, "issm%d", port->dev_num);
dc2ed5e3 1220 if (cdev_add(&port->sm_cdev, base, 1))
a74968f8 1221 goto err_sm_cdev;
1da177e4 1222
1e35a088 1223 port->sm_dev = device_create(umad_class, device->dev.parent,
2b937afc 1224 port->sm_cdev.dev, port,
91bd418f 1225 "issm%d", port->dev_num);
f4e91eb4 1226 if (IS_ERR(port->sm_dev))
1da177e4
LT
1227 goto err_sm_cdev;
1228
f4e91eb4
TJ
1229 if (device_create_file(port->sm_dev, &dev_attr_ibdev))
1230 goto err_sm_dev;
1231 if (device_create_file(port->sm_dev, &dev_attr_port))
1232 goto err_sm_dev;
1da177e4
LT
1233
1234 return 0;
1235
f4e91eb4 1236err_sm_dev:
2b937afc 1237 device_destroy(umad_class, port->sm_cdev.dev);
1da177e4
LT
1238
1239err_sm_cdev:
2b937afc 1240 cdev_del(&port->sm_cdev);
1da177e4 1241
f4e91eb4 1242err_dev:
2b937afc 1243 device_destroy(umad_class, port->cdev.dev);
1da177e4
LT
1244
1245err_cdev:
2b937afc 1246 cdev_del(&port->cdev);
8698d3fe
AC
1247 if (port->dev_num < IB_UMAD_MAX_PORTS)
1248 clear_bit(devnum, dev_map);
1249 else
1250 clear_bit(devnum, overflow_map);
1da177e4
LT
1251
1252 return -1;
1253}
1254
a74968f8
RD
1255static void ib_umad_kill_port(struct ib_umad_port *port)
1256{
0c99cb6d
RD
1257 struct ib_umad_file *file;
1258 int id;
1259
f4e91eb4
TJ
1260 dev_set_drvdata(port->dev, NULL);
1261 dev_set_drvdata(port->sm_dev, NULL);
a74968f8 1262
2b937afc
AC
1263 device_destroy(umad_class, port->cdev.dev);
1264 device_destroy(umad_class, port->sm_cdev.dev);
a74968f8 1265
2b937afc
AC
1266 cdev_del(&port->cdev);
1267 cdev_del(&port->sm_cdev);
a74968f8 1268
2fe7e6f7 1269 mutex_lock(&port->file_mutex);
0c99cb6d
RD
1270
1271 port->ib_dev = NULL;
1272
2fe7e6f7
RD
1273 list_for_each_entry(file, &port->file_list, port_list) {
1274 mutex_lock(&file->mutex);
94382f35 1275 file->agents_dead = 1;
2fe7e6f7 1276 mutex_unlock(&file->mutex);
94382f35
RD
1277
1278 for (id = 0; id < IB_UMAD_MAX_AGENTS; ++id)
1279 if (file->agent[id])
1280 ib_unregister_mad_agent(file->agent[id]);
94382f35 1281 }
0c99cb6d 1282
2fe7e6f7 1283 mutex_unlock(&port->file_mutex);
0c99cb6d 1284
8698d3fe
AC
1285 if (port->dev_num < IB_UMAD_MAX_PORTS)
1286 clear_bit(port->dev_num, dev_map);
1287 else
1288 clear_bit(port->dev_num - IB_UMAD_MAX_PORTS, overflow_map);
a74968f8
RD
1289}
1290
1da177e4
LT
1291static void ib_umad_add_one(struct ib_device *device)
1292{
1293 struct ib_umad_device *umad_dev;
1294 int s, e, i;
827f2a8b 1295 int count = 0;
1da177e4 1296
ab8be619
IW
1297 s = rdma_start_port(device);
1298 e = rdma_end_port(device);
1da177e4 1299
cb0f0910 1300 umad_dev = kzalloc(sizeof *umad_dev +
1da177e4
LT
1301 (e - s + 1) * sizeof (struct ib_umad_port),
1302 GFP_KERNEL);
1303 if (!umad_dev)
1304 return;
1305
60e1751c 1306 kobject_init(&umad_dev->kobj, &ib_umad_dev_ktype);
1da177e4 1307
1da177e4 1308 for (i = s; i <= e; ++i) {
c757dea8 1309 if (!rdma_cap_ib_mad(device, i))
827f2a8b
MW
1310 continue;
1311
1da177e4
LT
1312 umad_dev->port[i - s].umad_dev = umad_dev;
1313
60e1751c
BVA
1314 if (ib_umad_init_port(device, i, umad_dev,
1315 &umad_dev->port[i - s]))
1da177e4 1316 goto err;
827f2a8b
MW
1317
1318 count++;
1da177e4
LT
1319 }
1320
827f2a8b
MW
1321 if (!count)
1322 goto free;
1323
1da177e4
LT
1324 ib_set_client_data(device, &umad_client, umad_dev);
1325
1326 return;
1327
1328err:
827f2a8b 1329 while (--i >= s) {
c757dea8 1330 if (!rdma_cap_ib_mad(device, i))
827f2a8b 1331 continue;
1da177e4 1332
827f2a8b
MW
1333 ib_umad_kill_port(&umad_dev->port[i - s]);
1334 }
1335free:
60e1751c 1336 kobject_put(&umad_dev->kobj);
1da177e4
LT
1337}
1338
7c1eb45a 1339static void ib_umad_remove_one(struct ib_device *device, void *client_data)
1da177e4 1340{
7c1eb45a 1341 struct ib_umad_device *umad_dev = client_data;
1da177e4
LT
1342 int i;
1343
1344 if (!umad_dev)
1345 return;
1346
ab8be619 1347 for (i = 0; i <= rdma_end_port(device) - rdma_start_port(device); ++i) {
26c45428 1348 if (rdma_cap_ib_mad(device, i + rdma_start_port(device)))
827f2a8b
MW
1349 ib_umad_kill_port(&umad_dev->port[i]);
1350 }
1da177e4 1351
60e1751c 1352 kobject_put(&umad_dev->kobj);
1da177e4
LT
1353}
1354
2c9ede55 1355static char *umad_devnode(struct device *dev, umode_t *mode)
c3af0980
RD
1356{
1357 return kasprintf(GFP_KERNEL, "infiniband/%s", dev_name(dev));
1358}
1359
1da177e4
LT
1360static int __init ib_umad_init(void)
1361{
1362 int ret;
1363
1da177e4
LT
1364 ret = register_chrdev_region(base_dev, IB_UMAD_MAX_PORTS * 2,
1365 "infiniband_mad");
1366 if (ret) {
f426a40e 1367 pr_err("couldn't register device number\n");
1da177e4
LT
1368 goto out;
1369 }
1370
a74968f8
RD
1371 umad_class = class_create(THIS_MODULE, "infiniband_mad");
1372 if (IS_ERR(umad_class)) {
1373 ret = PTR_ERR(umad_class);
f426a40e 1374 pr_err("couldn't create class infiniband_mad\n");
1da177e4
LT
1375 goto out_chrdev;
1376 }
1377
c3af0980
RD
1378 umad_class->devnode = umad_devnode;
1379
0933e2d9 1380 ret = class_create_file(umad_class, &class_attr_abi_version.attr);
1da177e4 1381 if (ret) {
f426a40e 1382 pr_err("couldn't create abi_version attribute\n");
1da177e4
LT
1383 goto out_class;
1384 }
1385
1386 ret = ib_register_client(&umad_client);
1387 if (ret) {
f426a40e 1388 pr_err("couldn't register ib_umad client\n");
1da177e4
LT
1389 goto out_class;
1390 }
1391
1392 return 0;
1393
1394out_class:
a74968f8 1395 class_destroy(umad_class);
1da177e4
LT
1396
1397out_chrdev:
1398 unregister_chrdev_region(base_dev, IB_UMAD_MAX_PORTS * 2);
1399
1400out:
1401 return ret;
1402}
1403
1404static void __exit ib_umad_cleanup(void)
1405{
1406 ib_unregister_client(&umad_client);
a74968f8 1407 class_destroy(umad_class);
1da177e4 1408 unregister_chrdev_region(base_dev, IB_UMAD_MAX_PORTS * 2);
8698d3fe
AC
1409 if (overflow_maj)
1410 unregister_chrdev_region(overflow_maj, IB_UMAD_MAX_PORTS * 2);
1da177e4
LT
1411}
1412
1413module_init(ib_umad_init);
1414module_exit(ib_umad_cleanup);