]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blob - drivers/infiniband/core/mad.c
RDMA/mad: Convert BUG_ONs to error flows
[mirror_ubuntu-bionic-kernel.git] / drivers / infiniband / core / mad.c
1 /*
2 * Copyright (c) 2004-2007 Voltaire, Inc. All rights reserved.
3 * Copyright (c) 2005 Intel Corporation. All rights reserved.
4 * Copyright (c) 2005 Mellanox Technologies Ltd. All rights reserved.
5 * Copyright (c) 2009 HNR Consulting. All rights reserved.
6 * Copyright (c) 2014 Intel Corporation. All rights reserved.
7 *
8 * This software is available to you under a choice of one of two
9 * licenses. You may choose to be licensed under the terms of the GNU
10 * General Public License (GPL) Version 2, available from the file
11 * COPYING in the main directory of this source tree, or the
12 * OpenIB.org BSD license below:
13 *
14 * Redistribution and use in source and binary forms, with or
15 * without modification, are permitted provided that the following
16 * conditions are met:
17 *
18 * - Redistributions of source code must retain the above
19 * copyright notice, this list of conditions and the following
20 * disclaimer.
21 *
22 * - Redistributions in binary form must reproduce the above
23 * copyright notice, this list of conditions and the following
24 * disclaimer in the documentation and/or other materials
25 * provided with the distribution.
26 *
27 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
28 * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
29 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
30 * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
31 * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
32 * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
33 * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
34 * SOFTWARE.
35 *
36 */
37
38 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
39
40 #include <linux/dma-mapping.h>
41 #include <linux/slab.h>
42 #include <linux/module.h>
43 #include <linux/security.h>
44 #include <rdma/ib_cache.h>
45
46 #include "mad_priv.h"
47 #include "core_priv.h"
48 #include "mad_rmpp.h"
49 #include "smi.h"
50 #include "opa_smi.h"
51 #include "agent.h"
52 #include "core_priv.h"
53
54 static int mad_sendq_size = IB_MAD_QP_SEND_SIZE;
55 static int mad_recvq_size = IB_MAD_QP_RECV_SIZE;
56
57 module_param_named(send_queue_size, mad_sendq_size, int, 0444);
58 MODULE_PARM_DESC(send_queue_size, "Size of send queue in number of work requests");
59 module_param_named(recv_queue_size, mad_recvq_size, int, 0444);
60 MODULE_PARM_DESC(recv_queue_size, "Size of receive queue in number of work requests");
61
62 static struct list_head ib_mad_port_list;
63 static atomic_t ib_mad_client_id = ATOMIC_INIT(0);
64
65 /* Port list lock */
66 static DEFINE_SPINLOCK(ib_mad_port_list_lock);
67
68 /* Forward declarations */
69 static int method_in_use(struct ib_mad_mgmt_method_table **method,
70 struct ib_mad_reg_req *mad_reg_req);
71 static void remove_mad_reg_req(struct ib_mad_agent_private *priv);
72 static struct ib_mad_agent_private *find_mad_agent(
73 struct ib_mad_port_private *port_priv,
74 const struct ib_mad_hdr *mad);
75 static int ib_mad_post_receive_mads(struct ib_mad_qp_info *qp_info,
76 struct ib_mad_private *mad);
77 static void cancel_mads(struct ib_mad_agent_private *mad_agent_priv);
78 static void timeout_sends(struct work_struct *work);
79 static void local_completions(struct work_struct *work);
80 static int add_nonoui_reg_req(struct ib_mad_reg_req *mad_reg_req,
81 struct ib_mad_agent_private *agent_priv,
82 u8 mgmt_class);
83 static int add_oui_reg_req(struct ib_mad_reg_req *mad_reg_req,
84 struct ib_mad_agent_private *agent_priv);
85 static bool ib_mad_send_error(struct ib_mad_port_private *port_priv,
86 struct ib_wc *wc);
87 static void ib_mad_send_done(struct ib_cq *cq, struct ib_wc *wc);
88
89 /*
90 * Returns a ib_mad_port_private structure or NULL for a device/port
91 * Assumes ib_mad_port_list_lock is being held
92 */
93 static inline struct ib_mad_port_private *
94 __ib_get_mad_port(struct ib_device *device, int port_num)
95 {
96 struct ib_mad_port_private *entry;
97
98 list_for_each_entry(entry, &ib_mad_port_list, port_list) {
99 if (entry->device == device && entry->port_num == port_num)
100 return entry;
101 }
102 return NULL;
103 }
104
105 /*
106 * Wrapper function to return a ib_mad_port_private structure or NULL
107 * for a device/port
108 */
109 static inline struct ib_mad_port_private *
110 ib_get_mad_port(struct ib_device *device, int port_num)
111 {
112 struct ib_mad_port_private *entry;
113 unsigned long flags;
114
115 spin_lock_irqsave(&ib_mad_port_list_lock, flags);
116 entry = __ib_get_mad_port(device, port_num);
117 spin_unlock_irqrestore(&ib_mad_port_list_lock, flags);
118
119 return entry;
120 }
121
122 static inline u8 convert_mgmt_class(u8 mgmt_class)
123 {
124 /* Alias IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE to 0 */
125 return mgmt_class == IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE ?
126 0 : mgmt_class;
127 }
128
129 static int get_spl_qp_index(enum ib_qp_type qp_type)
130 {
131 switch (qp_type)
132 {
133 case IB_QPT_SMI:
134 return 0;
135 case IB_QPT_GSI:
136 return 1;
137 default:
138 return -1;
139 }
140 }
141
142 static int vendor_class_index(u8 mgmt_class)
143 {
144 return mgmt_class - IB_MGMT_CLASS_VENDOR_RANGE2_START;
145 }
146
147 static int is_vendor_class(u8 mgmt_class)
148 {
149 if ((mgmt_class < IB_MGMT_CLASS_VENDOR_RANGE2_START) ||
150 (mgmt_class > IB_MGMT_CLASS_VENDOR_RANGE2_END))
151 return 0;
152 return 1;
153 }
154
155 static int is_vendor_oui(char *oui)
156 {
157 if (oui[0] || oui[1] || oui[2])
158 return 1;
159 return 0;
160 }
161
162 static int is_vendor_method_in_use(
163 struct ib_mad_mgmt_vendor_class *vendor_class,
164 struct ib_mad_reg_req *mad_reg_req)
165 {
166 struct ib_mad_mgmt_method_table *method;
167 int i;
168
169 for (i = 0; i < MAX_MGMT_OUI; i++) {
170 if (!memcmp(vendor_class->oui[i], mad_reg_req->oui, 3)) {
171 method = vendor_class->method_table[i];
172 if (method) {
173 if (method_in_use(&method, mad_reg_req))
174 return 1;
175 else
176 break;
177 }
178 }
179 }
180 return 0;
181 }
182
183 int ib_response_mad(const struct ib_mad_hdr *hdr)
184 {
185 return ((hdr->method & IB_MGMT_METHOD_RESP) ||
186 (hdr->method == IB_MGMT_METHOD_TRAP_REPRESS) ||
187 ((hdr->mgmt_class == IB_MGMT_CLASS_BM) &&
188 (hdr->attr_mod & IB_BM_ATTR_MOD_RESP)));
189 }
190 EXPORT_SYMBOL(ib_response_mad);
191
192 /*
193 * ib_register_mad_agent - Register to send/receive MADs
194 */
195 struct ib_mad_agent *ib_register_mad_agent(struct ib_device *device,
196 u8 port_num,
197 enum ib_qp_type qp_type,
198 struct ib_mad_reg_req *mad_reg_req,
199 u8 rmpp_version,
200 ib_mad_send_handler send_handler,
201 ib_mad_recv_handler recv_handler,
202 void *context,
203 u32 registration_flags)
204 {
205 struct ib_mad_port_private *port_priv;
206 struct ib_mad_agent *ret = ERR_PTR(-EINVAL);
207 struct ib_mad_agent_private *mad_agent_priv;
208 struct ib_mad_reg_req *reg_req = NULL;
209 struct ib_mad_mgmt_class_table *class;
210 struct ib_mad_mgmt_vendor_class_table *vendor;
211 struct ib_mad_mgmt_vendor_class *vendor_class;
212 struct ib_mad_mgmt_method_table *method;
213 int ret2, qpn;
214 unsigned long flags;
215 u8 mgmt_class, vclass;
216
217 /* Validate parameters */
218 qpn = get_spl_qp_index(qp_type);
219 if (qpn == -1) {
220 dev_notice(&device->dev,
221 "ib_register_mad_agent: invalid QP Type %d\n",
222 qp_type);
223 goto error1;
224 }
225
226 if (rmpp_version && rmpp_version != IB_MGMT_RMPP_VERSION) {
227 dev_notice(&device->dev,
228 "ib_register_mad_agent: invalid RMPP Version %u\n",
229 rmpp_version);
230 goto error1;
231 }
232
233 /* Validate MAD registration request if supplied */
234 if (mad_reg_req) {
235 if (mad_reg_req->mgmt_class_version >= MAX_MGMT_VERSION) {
236 dev_notice(&device->dev,
237 "ib_register_mad_agent: invalid Class Version %u\n",
238 mad_reg_req->mgmt_class_version);
239 goto error1;
240 }
241 if (!recv_handler) {
242 dev_notice(&device->dev,
243 "ib_register_mad_agent: no recv_handler\n");
244 goto error1;
245 }
246 if (mad_reg_req->mgmt_class >= MAX_MGMT_CLASS) {
247 /*
248 * IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE is the only
249 * one in this range currently allowed
250 */
251 if (mad_reg_req->mgmt_class !=
252 IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE) {
253 dev_notice(&device->dev,
254 "ib_register_mad_agent: Invalid Mgmt Class 0x%x\n",
255 mad_reg_req->mgmt_class);
256 goto error1;
257 }
258 } else if (mad_reg_req->mgmt_class == 0) {
259 /*
260 * Class 0 is reserved in IBA and is used for
261 * aliasing of IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE
262 */
263 dev_notice(&device->dev,
264 "ib_register_mad_agent: Invalid Mgmt Class 0\n");
265 goto error1;
266 } else if (is_vendor_class(mad_reg_req->mgmt_class)) {
267 /*
268 * If class is in "new" vendor range,
269 * ensure supplied OUI is not zero
270 */
271 if (!is_vendor_oui(mad_reg_req->oui)) {
272 dev_notice(&device->dev,
273 "ib_register_mad_agent: No OUI specified for class 0x%x\n",
274 mad_reg_req->mgmt_class);
275 goto error1;
276 }
277 }
278 /* Make sure class supplied is consistent with RMPP */
279 if (!ib_is_mad_class_rmpp(mad_reg_req->mgmt_class)) {
280 if (rmpp_version) {
281 dev_notice(&device->dev,
282 "ib_register_mad_agent: RMPP version for non-RMPP class 0x%x\n",
283 mad_reg_req->mgmt_class);
284 goto error1;
285 }
286 }
287
288 /* Make sure class supplied is consistent with QP type */
289 if (qp_type == IB_QPT_SMI) {
290 if ((mad_reg_req->mgmt_class !=
291 IB_MGMT_CLASS_SUBN_LID_ROUTED) &&
292 (mad_reg_req->mgmt_class !=
293 IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE)) {
294 dev_notice(&device->dev,
295 "ib_register_mad_agent: Invalid SM QP type: class 0x%x\n",
296 mad_reg_req->mgmt_class);
297 goto error1;
298 }
299 } else {
300 if ((mad_reg_req->mgmt_class ==
301 IB_MGMT_CLASS_SUBN_LID_ROUTED) ||
302 (mad_reg_req->mgmt_class ==
303 IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE)) {
304 dev_notice(&device->dev,
305 "ib_register_mad_agent: Invalid GS QP type: class 0x%x\n",
306 mad_reg_req->mgmt_class);
307 goto error1;
308 }
309 }
310 } else {
311 /* No registration request supplied */
312 if (!send_handler)
313 goto error1;
314 if (registration_flags & IB_MAD_USER_RMPP)
315 goto error1;
316 }
317
318 /* Validate device and port */
319 port_priv = ib_get_mad_port(device, port_num);
320 if (!port_priv) {
321 dev_notice(&device->dev,
322 "ib_register_mad_agent: Invalid port %d\n",
323 port_num);
324 ret = ERR_PTR(-ENODEV);
325 goto error1;
326 }
327
328 /* Verify the QP requested is supported. For example, Ethernet devices
329 * will not have QP0 */
330 if (!port_priv->qp_info[qpn].qp) {
331 dev_notice(&device->dev,
332 "ib_register_mad_agent: QP %d not supported\n", qpn);
333 ret = ERR_PTR(-EPROTONOSUPPORT);
334 goto error1;
335 }
336
337 /* Allocate structures */
338 mad_agent_priv = kzalloc(sizeof *mad_agent_priv, GFP_KERNEL);
339 if (!mad_agent_priv) {
340 ret = ERR_PTR(-ENOMEM);
341 goto error1;
342 }
343
344 if (mad_reg_req) {
345 reg_req = kmemdup(mad_reg_req, sizeof *reg_req, GFP_KERNEL);
346 if (!reg_req) {
347 ret = ERR_PTR(-ENOMEM);
348 goto error3;
349 }
350 }
351
352 /* Now, fill in the various structures */
353 mad_agent_priv->qp_info = &port_priv->qp_info[qpn];
354 mad_agent_priv->reg_req = reg_req;
355 mad_agent_priv->agent.rmpp_version = rmpp_version;
356 mad_agent_priv->agent.device = device;
357 mad_agent_priv->agent.recv_handler = recv_handler;
358 mad_agent_priv->agent.send_handler = send_handler;
359 mad_agent_priv->agent.context = context;
360 mad_agent_priv->agent.qp = port_priv->qp_info[qpn].qp;
361 mad_agent_priv->agent.port_num = port_num;
362 mad_agent_priv->agent.flags = registration_flags;
363 spin_lock_init(&mad_agent_priv->lock);
364 INIT_LIST_HEAD(&mad_agent_priv->send_list);
365 INIT_LIST_HEAD(&mad_agent_priv->wait_list);
366 INIT_LIST_HEAD(&mad_agent_priv->done_list);
367 INIT_LIST_HEAD(&mad_agent_priv->rmpp_list);
368 INIT_DELAYED_WORK(&mad_agent_priv->timed_work, timeout_sends);
369 INIT_LIST_HEAD(&mad_agent_priv->local_list);
370 INIT_WORK(&mad_agent_priv->local_work, local_completions);
371 atomic_set(&mad_agent_priv->refcount, 1);
372 init_completion(&mad_agent_priv->comp);
373
374 ret2 = ib_mad_agent_security_setup(&mad_agent_priv->agent, qp_type);
375 if (ret2) {
376 ret = ERR_PTR(ret2);
377 goto error4;
378 }
379
380 spin_lock_irqsave(&port_priv->reg_lock, flags);
381 mad_agent_priv->agent.hi_tid = atomic_inc_return(&ib_mad_client_id);
382
383 /*
384 * Make sure MAD registration (if supplied)
385 * is non overlapping with any existing ones
386 */
387 if (mad_reg_req) {
388 mgmt_class = convert_mgmt_class(mad_reg_req->mgmt_class);
389 if (!is_vendor_class(mgmt_class)) {
390 class = port_priv->version[mad_reg_req->
391 mgmt_class_version].class;
392 if (class) {
393 method = class->method_table[mgmt_class];
394 if (method) {
395 if (method_in_use(&method,
396 mad_reg_req))
397 goto error5;
398 }
399 }
400 ret2 = add_nonoui_reg_req(mad_reg_req, mad_agent_priv,
401 mgmt_class);
402 } else {
403 /* "New" vendor class range */
404 vendor = port_priv->version[mad_reg_req->
405 mgmt_class_version].vendor;
406 if (vendor) {
407 vclass = vendor_class_index(mgmt_class);
408 vendor_class = vendor->vendor_class[vclass];
409 if (vendor_class) {
410 if (is_vendor_method_in_use(
411 vendor_class,
412 mad_reg_req))
413 goto error5;
414 }
415 }
416 ret2 = add_oui_reg_req(mad_reg_req, mad_agent_priv);
417 }
418 if (ret2) {
419 ret = ERR_PTR(ret2);
420 goto error5;
421 }
422 }
423
424 /* Add mad agent into port's agent list */
425 list_add_tail(&mad_agent_priv->agent_list, &port_priv->agent_list);
426 spin_unlock_irqrestore(&port_priv->reg_lock, flags);
427
428 return &mad_agent_priv->agent;
429 error5:
430 spin_unlock_irqrestore(&port_priv->reg_lock, flags);
431 ib_mad_agent_security_cleanup(&mad_agent_priv->agent);
432 error4:
433 kfree(reg_req);
434 error3:
435 kfree(mad_agent_priv);
436 error1:
437 return ret;
438 }
439 EXPORT_SYMBOL(ib_register_mad_agent);
440
441 static inline int is_snooping_sends(int mad_snoop_flags)
442 {
443 return (mad_snoop_flags &
444 (/*IB_MAD_SNOOP_POSTED_SENDS |
445 IB_MAD_SNOOP_RMPP_SENDS |*/
446 IB_MAD_SNOOP_SEND_COMPLETIONS /*|
447 IB_MAD_SNOOP_RMPP_SEND_COMPLETIONS*/));
448 }
449
450 static inline int is_snooping_recvs(int mad_snoop_flags)
451 {
452 return (mad_snoop_flags &
453 (IB_MAD_SNOOP_RECVS /*|
454 IB_MAD_SNOOP_RMPP_RECVS*/));
455 }
456
457 static int register_snoop_agent(struct ib_mad_qp_info *qp_info,
458 struct ib_mad_snoop_private *mad_snoop_priv)
459 {
460 struct ib_mad_snoop_private **new_snoop_table;
461 unsigned long flags;
462 int i;
463
464 spin_lock_irqsave(&qp_info->snoop_lock, flags);
465 /* Check for empty slot in array. */
466 for (i = 0; i < qp_info->snoop_table_size; i++)
467 if (!qp_info->snoop_table[i])
468 break;
469
470 if (i == qp_info->snoop_table_size) {
471 /* Grow table. */
472 new_snoop_table = krealloc(qp_info->snoop_table,
473 sizeof mad_snoop_priv *
474 (qp_info->snoop_table_size + 1),
475 GFP_ATOMIC);
476 if (!new_snoop_table) {
477 i = -ENOMEM;
478 goto out;
479 }
480
481 qp_info->snoop_table = new_snoop_table;
482 qp_info->snoop_table_size++;
483 }
484 qp_info->snoop_table[i] = mad_snoop_priv;
485 atomic_inc(&qp_info->snoop_count);
486 out:
487 spin_unlock_irqrestore(&qp_info->snoop_lock, flags);
488 return i;
489 }
490
491 struct ib_mad_agent *ib_register_mad_snoop(struct ib_device *device,
492 u8 port_num,
493 enum ib_qp_type qp_type,
494 int mad_snoop_flags,
495 ib_mad_snoop_handler snoop_handler,
496 ib_mad_recv_handler recv_handler,
497 void *context)
498 {
499 struct ib_mad_port_private *port_priv;
500 struct ib_mad_agent *ret;
501 struct ib_mad_snoop_private *mad_snoop_priv;
502 int qpn;
503 int err;
504
505 /* Validate parameters */
506 if ((is_snooping_sends(mad_snoop_flags) && !snoop_handler) ||
507 (is_snooping_recvs(mad_snoop_flags) && !recv_handler)) {
508 ret = ERR_PTR(-EINVAL);
509 goto error1;
510 }
511 qpn = get_spl_qp_index(qp_type);
512 if (qpn == -1) {
513 ret = ERR_PTR(-EINVAL);
514 goto error1;
515 }
516 port_priv = ib_get_mad_port(device, port_num);
517 if (!port_priv) {
518 ret = ERR_PTR(-ENODEV);
519 goto error1;
520 }
521 /* Allocate structures */
522 mad_snoop_priv = kzalloc(sizeof *mad_snoop_priv, GFP_KERNEL);
523 if (!mad_snoop_priv) {
524 ret = ERR_PTR(-ENOMEM);
525 goto error1;
526 }
527
528 /* Now, fill in the various structures */
529 mad_snoop_priv->qp_info = &port_priv->qp_info[qpn];
530 mad_snoop_priv->agent.device = device;
531 mad_snoop_priv->agent.recv_handler = recv_handler;
532 mad_snoop_priv->agent.snoop_handler = snoop_handler;
533 mad_snoop_priv->agent.context = context;
534 mad_snoop_priv->agent.qp = port_priv->qp_info[qpn].qp;
535 mad_snoop_priv->agent.port_num = port_num;
536 mad_snoop_priv->mad_snoop_flags = mad_snoop_flags;
537 init_completion(&mad_snoop_priv->comp);
538
539 err = ib_mad_agent_security_setup(&mad_snoop_priv->agent, qp_type);
540 if (err) {
541 ret = ERR_PTR(err);
542 goto error2;
543 }
544
545 mad_snoop_priv->snoop_index = register_snoop_agent(
546 &port_priv->qp_info[qpn],
547 mad_snoop_priv);
548 if (mad_snoop_priv->snoop_index < 0) {
549 ret = ERR_PTR(mad_snoop_priv->snoop_index);
550 goto error3;
551 }
552
553 atomic_set(&mad_snoop_priv->refcount, 1);
554 return &mad_snoop_priv->agent;
555 error3:
556 ib_mad_agent_security_cleanup(&mad_snoop_priv->agent);
557 error2:
558 kfree(mad_snoop_priv);
559 error1:
560 return ret;
561 }
562 EXPORT_SYMBOL(ib_register_mad_snoop);
563
564 static inline void deref_mad_agent(struct ib_mad_agent_private *mad_agent_priv)
565 {
566 if (atomic_dec_and_test(&mad_agent_priv->refcount))
567 complete(&mad_agent_priv->comp);
568 }
569
570 static inline void deref_snoop_agent(struct ib_mad_snoop_private *mad_snoop_priv)
571 {
572 if (atomic_dec_and_test(&mad_snoop_priv->refcount))
573 complete(&mad_snoop_priv->comp);
574 }
575
576 static void unregister_mad_agent(struct ib_mad_agent_private *mad_agent_priv)
577 {
578 struct ib_mad_port_private *port_priv;
579 unsigned long flags;
580
581 /* Note that we could still be handling received MADs */
582
583 /*
584 * Canceling all sends results in dropping received response
585 * MADs, preventing us from queuing additional work
586 */
587 cancel_mads(mad_agent_priv);
588 port_priv = mad_agent_priv->qp_info->port_priv;
589 cancel_delayed_work(&mad_agent_priv->timed_work);
590
591 spin_lock_irqsave(&port_priv->reg_lock, flags);
592 remove_mad_reg_req(mad_agent_priv);
593 list_del(&mad_agent_priv->agent_list);
594 spin_unlock_irqrestore(&port_priv->reg_lock, flags);
595
596 flush_workqueue(port_priv->wq);
597 ib_cancel_rmpp_recvs(mad_agent_priv);
598
599 deref_mad_agent(mad_agent_priv);
600 wait_for_completion(&mad_agent_priv->comp);
601
602 ib_mad_agent_security_cleanup(&mad_agent_priv->agent);
603
604 kfree(mad_agent_priv->reg_req);
605 kfree(mad_agent_priv);
606 }
607
608 static void unregister_mad_snoop(struct ib_mad_snoop_private *mad_snoop_priv)
609 {
610 struct ib_mad_qp_info *qp_info;
611 unsigned long flags;
612
613 qp_info = mad_snoop_priv->qp_info;
614 spin_lock_irqsave(&qp_info->snoop_lock, flags);
615 qp_info->snoop_table[mad_snoop_priv->snoop_index] = NULL;
616 atomic_dec(&qp_info->snoop_count);
617 spin_unlock_irqrestore(&qp_info->snoop_lock, flags);
618
619 deref_snoop_agent(mad_snoop_priv);
620 wait_for_completion(&mad_snoop_priv->comp);
621
622 ib_mad_agent_security_cleanup(&mad_snoop_priv->agent);
623
624 kfree(mad_snoop_priv);
625 }
626
627 /*
628 * ib_unregister_mad_agent - Unregisters a client from using MAD services
629 */
630 void ib_unregister_mad_agent(struct ib_mad_agent *mad_agent)
631 {
632 struct ib_mad_agent_private *mad_agent_priv;
633 struct ib_mad_snoop_private *mad_snoop_priv;
634
635 /* If the TID is zero, the agent can only snoop. */
636 if (mad_agent->hi_tid) {
637 mad_agent_priv = container_of(mad_agent,
638 struct ib_mad_agent_private,
639 agent);
640 unregister_mad_agent(mad_agent_priv);
641 } else {
642 mad_snoop_priv = container_of(mad_agent,
643 struct ib_mad_snoop_private,
644 agent);
645 unregister_mad_snoop(mad_snoop_priv);
646 }
647 }
648 EXPORT_SYMBOL(ib_unregister_mad_agent);
649
650 static void dequeue_mad(struct ib_mad_list_head *mad_list)
651 {
652 struct ib_mad_queue *mad_queue;
653 unsigned long flags;
654
655 BUG_ON(!mad_list->mad_queue);
656 mad_queue = mad_list->mad_queue;
657 spin_lock_irqsave(&mad_queue->lock, flags);
658 list_del(&mad_list->list);
659 mad_queue->count--;
660 spin_unlock_irqrestore(&mad_queue->lock, flags);
661 }
662
663 static void snoop_send(struct ib_mad_qp_info *qp_info,
664 struct ib_mad_send_buf *send_buf,
665 struct ib_mad_send_wc *mad_send_wc,
666 int mad_snoop_flags)
667 {
668 struct ib_mad_snoop_private *mad_snoop_priv;
669 unsigned long flags;
670 int i;
671
672 spin_lock_irqsave(&qp_info->snoop_lock, flags);
673 for (i = 0; i < qp_info->snoop_table_size; i++) {
674 mad_snoop_priv = qp_info->snoop_table[i];
675 if (!mad_snoop_priv ||
676 !(mad_snoop_priv->mad_snoop_flags & mad_snoop_flags))
677 continue;
678
679 atomic_inc(&mad_snoop_priv->refcount);
680 spin_unlock_irqrestore(&qp_info->snoop_lock, flags);
681 mad_snoop_priv->agent.snoop_handler(&mad_snoop_priv->agent,
682 send_buf, mad_send_wc);
683 deref_snoop_agent(mad_snoop_priv);
684 spin_lock_irqsave(&qp_info->snoop_lock, flags);
685 }
686 spin_unlock_irqrestore(&qp_info->snoop_lock, flags);
687 }
688
689 static void snoop_recv(struct ib_mad_qp_info *qp_info,
690 struct ib_mad_recv_wc *mad_recv_wc,
691 int mad_snoop_flags)
692 {
693 struct ib_mad_snoop_private *mad_snoop_priv;
694 unsigned long flags;
695 int i;
696
697 spin_lock_irqsave(&qp_info->snoop_lock, flags);
698 for (i = 0; i < qp_info->snoop_table_size; i++) {
699 mad_snoop_priv = qp_info->snoop_table[i];
700 if (!mad_snoop_priv ||
701 !(mad_snoop_priv->mad_snoop_flags & mad_snoop_flags))
702 continue;
703
704 atomic_inc(&mad_snoop_priv->refcount);
705 spin_unlock_irqrestore(&qp_info->snoop_lock, flags);
706 mad_snoop_priv->agent.recv_handler(&mad_snoop_priv->agent, NULL,
707 mad_recv_wc);
708 deref_snoop_agent(mad_snoop_priv);
709 spin_lock_irqsave(&qp_info->snoop_lock, flags);
710 }
711 spin_unlock_irqrestore(&qp_info->snoop_lock, flags);
712 }
713
714 static void build_smp_wc(struct ib_qp *qp, struct ib_cqe *cqe, u16 slid,
715 u16 pkey_index, u8 port_num, struct ib_wc *wc)
716 {
717 memset(wc, 0, sizeof *wc);
718 wc->wr_cqe = cqe;
719 wc->status = IB_WC_SUCCESS;
720 wc->opcode = IB_WC_RECV;
721 wc->pkey_index = pkey_index;
722 wc->byte_len = sizeof(struct ib_mad) + sizeof(struct ib_grh);
723 wc->src_qp = IB_QP0;
724 wc->qp = qp;
725 wc->slid = slid;
726 wc->sl = 0;
727 wc->dlid_path_bits = 0;
728 wc->port_num = port_num;
729 }
730
731 static size_t mad_priv_size(const struct ib_mad_private *mp)
732 {
733 return sizeof(struct ib_mad_private) + mp->mad_size;
734 }
735
736 static struct ib_mad_private *alloc_mad_private(size_t mad_size, gfp_t flags)
737 {
738 size_t size = sizeof(struct ib_mad_private) + mad_size;
739 struct ib_mad_private *ret = kzalloc(size, flags);
740
741 if (ret)
742 ret->mad_size = mad_size;
743
744 return ret;
745 }
746
747 static size_t port_mad_size(const struct ib_mad_port_private *port_priv)
748 {
749 return rdma_max_mad_size(port_priv->device, port_priv->port_num);
750 }
751
752 static size_t mad_priv_dma_size(const struct ib_mad_private *mp)
753 {
754 return sizeof(struct ib_grh) + mp->mad_size;
755 }
756
757 /*
758 * Return 0 if SMP is to be sent
759 * Return 1 if SMP was consumed locally (whether or not solicited)
760 * Return < 0 if error
761 */
762 static int handle_outgoing_dr_smp(struct ib_mad_agent_private *mad_agent_priv,
763 struct ib_mad_send_wr_private *mad_send_wr)
764 {
765 int ret = 0;
766 struct ib_smp *smp = mad_send_wr->send_buf.mad;
767 struct opa_smp *opa_smp = (struct opa_smp *)smp;
768 unsigned long flags;
769 struct ib_mad_local_private *local;
770 struct ib_mad_private *mad_priv;
771 struct ib_mad_port_private *port_priv;
772 struct ib_mad_agent_private *recv_mad_agent = NULL;
773 struct ib_device *device = mad_agent_priv->agent.device;
774 u8 port_num;
775 struct ib_wc mad_wc;
776 struct ib_ud_wr *send_wr = &mad_send_wr->send_wr;
777 size_t mad_size = port_mad_size(mad_agent_priv->qp_info->port_priv);
778 u16 out_mad_pkey_index = 0;
779 u16 drslid;
780 bool opa = rdma_cap_opa_mad(mad_agent_priv->qp_info->port_priv->device,
781 mad_agent_priv->qp_info->port_priv->port_num);
782
783 if (rdma_cap_ib_switch(device) &&
784 smp->mgmt_class == IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE)
785 port_num = send_wr->port_num;
786 else
787 port_num = mad_agent_priv->agent.port_num;
788
789 /*
790 * Directed route handling starts if the initial LID routed part of
791 * a request or the ending LID routed part of a response is empty.
792 * If we are at the start of the LID routed part, don't update the
793 * hop_ptr or hop_cnt. See section 14.2.2, Vol 1 IB spec.
794 */
795 if (opa && smp->class_version == OPA_SM_CLASS_VERSION) {
796 u32 opa_drslid;
797
798 if ((opa_get_smp_direction(opa_smp)
799 ? opa_smp->route.dr.dr_dlid : opa_smp->route.dr.dr_slid) ==
800 OPA_LID_PERMISSIVE &&
801 opa_smi_handle_dr_smp_send(opa_smp,
802 rdma_cap_ib_switch(device),
803 port_num) == IB_SMI_DISCARD) {
804 ret = -EINVAL;
805 dev_err(&device->dev, "OPA Invalid directed route\n");
806 goto out;
807 }
808 opa_drslid = be32_to_cpu(opa_smp->route.dr.dr_slid);
809 if (opa_drslid != be32_to_cpu(OPA_LID_PERMISSIVE) &&
810 opa_drslid & 0xffff0000) {
811 ret = -EINVAL;
812 dev_err(&device->dev, "OPA Invalid dr_slid 0x%x\n",
813 opa_drslid);
814 goto out;
815 }
816 drslid = (u16)(opa_drslid & 0x0000ffff);
817
818 /* Check to post send on QP or process locally */
819 if (opa_smi_check_local_smp(opa_smp, device) == IB_SMI_DISCARD &&
820 opa_smi_check_local_returning_smp(opa_smp, device) == IB_SMI_DISCARD)
821 goto out;
822 } else {
823 if ((ib_get_smp_direction(smp) ? smp->dr_dlid : smp->dr_slid) ==
824 IB_LID_PERMISSIVE &&
825 smi_handle_dr_smp_send(smp, rdma_cap_ib_switch(device), port_num) ==
826 IB_SMI_DISCARD) {
827 ret = -EINVAL;
828 dev_err(&device->dev, "Invalid directed route\n");
829 goto out;
830 }
831 drslid = be16_to_cpu(smp->dr_slid);
832
833 /* Check to post send on QP or process locally */
834 if (smi_check_local_smp(smp, device) == IB_SMI_DISCARD &&
835 smi_check_local_returning_smp(smp, device) == IB_SMI_DISCARD)
836 goto out;
837 }
838
839 local = kmalloc(sizeof *local, GFP_ATOMIC);
840 if (!local) {
841 ret = -ENOMEM;
842 goto out;
843 }
844 local->mad_priv = NULL;
845 local->recv_mad_agent = NULL;
846 mad_priv = alloc_mad_private(mad_size, GFP_ATOMIC);
847 if (!mad_priv) {
848 ret = -ENOMEM;
849 kfree(local);
850 goto out;
851 }
852
853 build_smp_wc(mad_agent_priv->agent.qp,
854 send_wr->wr.wr_cqe, drslid,
855 send_wr->pkey_index,
856 send_wr->port_num, &mad_wc);
857
858 if (opa && smp->base_version == OPA_MGMT_BASE_VERSION) {
859 mad_wc.byte_len = mad_send_wr->send_buf.hdr_len
860 + mad_send_wr->send_buf.data_len
861 + sizeof(struct ib_grh);
862 }
863
864 /* No GRH for DR SMP */
865 ret = device->process_mad(device, 0, port_num, &mad_wc, NULL,
866 (const struct ib_mad_hdr *)smp, mad_size,
867 (struct ib_mad_hdr *)mad_priv->mad,
868 &mad_size, &out_mad_pkey_index);
869 switch (ret)
870 {
871 case IB_MAD_RESULT_SUCCESS | IB_MAD_RESULT_REPLY:
872 if (ib_response_mad((const struct ib_mad_hdr *)mad_priv->mad) &&
873 mad_agent_priv->agent.recv_handler) {
874 local->mad_priv = mad_priv;
875 local->recv_mad_agent = mad_agent_priv;
876 /*
877 * Reference MAD agent until receive
878 * side of local completion handled
879 */
880 atomic_inc(&mad_agent_priv->refcount);
881 } else
882 kfree(mad_priv);
883 break;
884 case IB_MAD_RESULT_SUCCESS | IB_MAD_RESULT_CONSUMED:
885 kfree(mad_priv);
886 break;
887 case IB_MAD_RESULT_SUCCESS:
888 /* Treat like an incoming receive MAD */
889 port_priv = ib_get_mad_port(mad_agent_priv->agent.device,
890 mad_agent_priv->agent.port_num);
891 if (port_priv) {
892 memcpy(mad_priv->mad, smp, mad_priv->mad_size);
893 recv_mad_agent = find_mad_agent(port_priv,
894 (const struct ib_mad_hdr *)mad_priv->mad);
895 }
896 if (!port_priv || !recv_mad_agent) {
897 /*
898 * No receiving agent so drop packet and
899 * generate send completion.
900 */
901 kfree(mad_priv);
902 break;
903 }
904 local->mad_priv = mad_priv;
905 local->recv_mad_agent = recv_mad_agent;
906 break;
907 default:
908 kfree(mad_priv);
909 kfree(local);
910 ret = -EINVAL;
911 goto out;
912 }
913
914 local->mad_send_wr = mad_send_wr;
915 if (opa) {
916 local->mad_send_wr->send_wr.pkey_index = out_mad_pkey_index;
917 local->return_wc_byte_len = mad_size;
918 }
919 /* Reference MAD agent until send side of local completion handled */
920 atomic_inc(&mad_agent_priv->refcount);
921 /* Queue local completion to local list */
922 spin_lock_irqsave(&mad_agent_priv->lock, flags);
923 list_add_tail(&local->completion_list, &mad_agent_priv->local_list);
924 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
925 queue_work(mad_agent_priv->qp_info->port_priv->wq,
926 &mad_agent_priv->local_work);
927 ret = 1;
928 out:
929 return ret;
930 }
931
932 static int get_pad_size(int hdr_len, int data_len, size_t mad_size)
933 {
934 int seg_size, pad;
935
936 seg_size = mad_size - hdr_len;
937 if (data_len && seg_size) {
938 pad = seg_size - data_len % seg_size;
939 return pad == seg_size ? 0 : pad;
940 } else
941 return seg_size;
942 }
943
944 static void free_send_rmpp_list(struct ib_mad_send_wr_private *mad_send_wr)
945 {
946 struct ib_rmpp_segment *s, *t;
947
948 list_for_each_entry_safe(s, t, &mad_send_wr->rmpp_list, list) {
949 list_del(&s->list);
950 kfree(s);
951 }
952 }
953
954 static int alloc_send_rmpp_list(struct ib_mad_send_wr_private *send_wr,
955 size_t mad_size, gfp_t gfp_mask)
956 {
957 struct ib_mad_send_buf *send_buf = &send_wr->send_buf;
958 struct ib_rmpp_mad *rmpp_mad = send_buf->mad;
959 struct ib_rmpp_segment *seg = NULL;
960 int left, seg_size, pad;
961
962 send_buf->seg_size = mad_size - send_buf->hdr_len;
963 send_buf->seg_rmpp_size = mad_size - IB_MGMT_RMPP_HDR;
964 seg_size = send_buf->seg_size;
965 pad = send_wr->pad;
966
967 /* Allocate data segments. */
968 for (left = send_buf->data_len + pad; left > 0; left -= seg_size) {
969 seg = kmalloc(sizeof (*seg) + seg_size, gfp_mask);
970 if (!seg) {
971 free_send_rmpp_list(send_wr);
972 return -ENOMEM;
973 }
974 seg->num = ++send_buf->seg_count;
975 list_add_tail(&seg->list, &send_wr->rmpp_list);
976 }
977
978 /* Zero any padding */
979 if (pad)
980 memset(seg->data + seg_size - pad, 0, pad);
981
982 rmpp_mad->rmpp_hdr.rmpp_version = send_wr->mad_agent_priv->
983 agent.rmpp_version;
984 rmpp_mad->rmpp_hdr.rmpp_type = IB_MGMT_RMPP_TYPE_DATA;
985 ib_set_rmpp_flags(&rmpp_mad->rmpp_hdr, IB_MGMT_RMPP_FLAG_ACTIVE);
986
987 send_wr->cur_seg = container_of(send_wr->rmpp_list.next,
988 struct ib_rmpp_segment, list);
989 send_wr->last_ack_seg = send_wr->cur_seg;
990 return 0;
991 }
992
993 int ib_mad_kernel_rmpp_agent(const struct ib_mad_agent *agent)
994 {
995 return agent->rmpp_version && !(agent->flags & IB_MAD_USER_RMPP);
996 }
997 EXPORT_SYMBOL(ib_mad_kernel_rmpp_agent);
998
999 struct ib_mad_send_buf * ib_create_send_mad(struct ib_mad_agent *mad_agent,
1000 u32 remote_qpn, u16 pkey_index,
1001 int rmpp_active,
1002 int hdr_len, int data_len,
1003 gfp_t gfp_mask,
1004 u8 base_version)
1005 {
1006 struct ib_mad_agent_private *mad_agent_priv;
1007 struct ib_mad_send_wr_private *mad_send_wr;
1008 int pad, message_size, ret, size;
1009 void *buf;
1010 size_t mad_size;
1011 bool opa;
1012
1013 mad_agent_priv = container_of(mad_agent, struct ib_mad_agent_private,
1014 agent);
1015
1016 opa = rdma_cap_opa_mad(mad_agent->device, mad_agent->port_num);
1017
1018 if (opa && base_version == OPA_MGMT_BASE_VERSION)
1019 mad_size = sizeof(struct opa_mad);
1020 else
1021 mad_size = sizeof(struct ib_mad);
1022
1023 pad = get_pad_size(hdr_len, data_len, mad_size);
1024 message_size = hdr_len + data_len + pad;
1025
1026 if (ib_mad_kernel_rmpp_agent(mad_agent)) {
1027 if (!rmpp_active && message_size > mad_size)
1028 return ERR_PTR(-EINVAL);
1029 } else
1030 if (rmpp_active || message_size > mad_size)
1031 return ERR_PTR(-EINVAL);
1032
1033 size = rmpp_active ? hdr_len : mad_size;
1034 buf = kzalloc(sizeof *mad_send_wr + size, gfp_mask);
1035 if (!buf)
1036 return ERR_PTR(-ENOMEM);
1037
1038 mad_send_wr = buf + size;
1039 INIT_LIST_HEAD(&mad_send_wr->rmpp_list);
1040 mad_send_wr->send_buf.mad = buf;
1041 mad_send_wr->send_buf.hdr_len = hdr_len;
1042 mad_send_wr->send_buf.data_len = data_len;
1043 mad_send_wr->pad = pad;
1044
1045 mad_send_wr->mad_agent_priv = mad_agent_priv;
1046 mad_send_wr->sg_list[0].length = hdr_len;
1047 mad_send_wr->sg_list[0].lkey = mad_agent->qp->pd->local_dma_lkey;
1048
1049 /* OPA MADs don't have to be the full 2048 bytes */
1050 if (opa && base_version == OPA_MGMT_BASE_VERSION &&
1051 data_len < mad_size - hdr_len)
1052 mad_send_wr->sg_list[1].length = data_len;
1053 else
1054 mad_send_wr->sg_list[1].length = mad_size - hdr_len;
1055
1056 mad_send_wr->sg_list[1].lkey = mad_agent->qp->pd->local_dma_lkey;
1057
1058 mad_send_wr->mad_list.cqe.done = ib_mad_send_done;
1059
1060 mad_send_wr->send_wr.wr.wr_cqe = &mad_send_wr->mad_list.cqe;
1061 mad_send_wr->send_wr.wr.sg_list = mad_send_wr->sg_list;
1062 mad_send_wr->send_wr.wr.num_sge = 2;
1063 mad_send_wr->send_wr.wr.opcode = IB_WR_SEND;
1064 mad_send_wr->send_wr.wr.send_flags = IB_SEND_SIGNALED;
1065 mad_send_wr->send_wr.remote_qpn = remote_qpn;
1066 mad_send_wr->send_wr.remote_qkey = IB_QP_SET_QKEY;
1067 mad_send_wr->send_wr.pkey_index = pkey_index;
1068
1069 if (rmpp_active) {
1070 ret = alloc_send_rmpp_list(mad_send_wr, mad_size, gfp_mask);
1071 if (ret) {
1072 kfree(buf);
1073 return ERR_PTR(ret);
1074 }
1075 }
1076
1077 mad_send_wr->send_buf.mad_agent = mad_agent;
1078 atomic_inc(&mad_agent_priv->refcount);
1079 return &mad_send_wr->send_buf;
1080 }
1081 EXPORT_SYMBOL(ib_create_send_mad);
1082
1083 int ib_get_mad_data_offset(u8 mgmt_class)
1084 {
1085 if (mgmt_class == IB_MGMT_CLASS_SUBN_ADM)
1086 return IB_MGMT_SA_HDR;
1087 else if ((mgmt_class == IB_MGMT_CLASS_DEVICE_MGMT) ||
1088 (mgmt_class == IB_MGMT_CLASS_DEVICE_ADM) ||
1089 (mgmt_class == IB_MGMT_CLASS_BIS))
1090 return IB_MGMT_DEVICE_HDR;
1091 else if ((mgmt_class >= IB_MGMT_CLASS_VENDOR_RANGE2_START) &&
1092 (mgmt_class <= IB_MGMT_CLASS_VENDOR_RANGE2_END))
1093 return IB_MGMT_VENDOR_HDR;
1094 else
1095 return IB_MGMT_MAD_HDR;
1096 }
1097 EXPORT_SYMBOL(ib_get_mad_data_offset);
1098
1099 int ib_is_mad_class_rmpp(u8 mgmt_class)
1100 {
1101 if ((mgmt_class == IB_MGMT_CLASS_SUBN_ADM) ||
1102 (mgmt_class == IB_MGMT_CLASS_DEVICE_MGMT) ||
1103 (mgmt_class == IB_MGMT_CLASS_DEVICE_ADM) ||
1104 (mgmt_class == IB_MGMT_CLASS_BIS) ||
1105 ((mgmt_class >= IB_MGMT_CLASS_VENDOR_RANGE2_START) &&
1106 (mgmt_class <= IB_MGMT_CLASS_VENDOR_RANGE2_END)))
1107 return 1;
1108 return 0;
1109 }
1110 EXPORT_SYMBOL(ib_is_mad_class_rmpp);
1111
1112 void *ib_get_rmpp_segment(struct ib_mad_send_buf *send_buf, int seg_num)
1113 {
1114 struct ib_mad_send_wr_private *mad_send_wr;
1115 struct list_head *list;
1116
1117 mad_send_wr = container_of(send_buf, struct ib_mad_send_wr_private,
1118 send_buf);
1119 list = &mad_send_wr->cur_seg->list;
1120
1121 if (mad_send_wr->cur_seg->num < seg_num) {
1122 list_for_each_entry(mad_send_wr->cur_seg, list, list)
1123 if (mad_send_wr->cur_seg->num == seg_num)
1124 break;
1125 } else if (mad_send_wr->cur_seg->num > seg_num) {
1126 list_for_each_entry_reverse(mad_send_wr->cur_seg, list, list)
1127 if (mad_send_wr->cur_seg->num == seg_num)
1128 break;
1129 }
1130 return mad_send_wr->cur_seg->data;
1131 }
1132 EXPORT_SYMBOL(ib_get_rmpp_segment);
1133
1134 static inline void *ib_get_payload(struct ib_mad_send_wr_private *mad_send_wr)
1135 {
1136 if (mad_send_wr->send_buf.seg_count)
1137 return ib_get_rmpp_segment(&mad_send_wr->send_buf,
1138 mad_send_wr->seg_num);
1139 else
1140 return mad_send_wr->send_buf.mad +
1141 mad_send_wr->send_buf.hdr_len;
1142 }
1143
1144 void ib_free_send_mad(struct ib_mad_send_buf *send_buf)
1145 {
1146 struct ib_mad_agent_private *mad_agent_priv;
1147 struct ib_mad_send_wr_private *mad_send_wr;
1148
1149 mad_agent_priv = container_of(send_buf->mad_agent,
1150 struct ib_mad_agent_private, agent);
1151 mad_send_wr = container_of(send_buf, struct ib_mad_send_wr_private,
1152 send_buf);
1153
1154 free_send_rmpp_list(mad_send_wr);
1155 kfree(send_buf->mad);
1156 deref_mad_agent(mad_agent_priv);
1157 }
1158 EXPORT_SYMBOL(ib_free_send_mad);
1159
1160 int ib_send_mad(struct ib_mad_send_wr_private *mad_send_wr)
1161 {
1162 struct ib_mad_qp_info *qp_info;
1163 struct list_head *list;
1164 struct ib_send_wr *bad_send_wr;
1165 struct ib_mad_agent *mad_agent;
1166 struct ib_sge *sge;
1167 unsigned long flags;
1168 int ret;
1169
1170 /* Set WR ID to find mad_send_wr upon completion */
1171 qp_info = mad_send_wr->mad_agent_priv->qp_info;
1172 mad_send_wr->mad_list.mad_queue = &qp_info->send_queue;
1173 mad_send_wr->mad_list.cqe.done = ib_mad_send_done;
1174 mad_send_wr->send_wr.wr.wr_cqe = &mad_send_wr->mad_list.cqe;
1175
1176 mad_agent = mad_send_wr->send_buf.mad_agent;
1177 sge = mad_send_wr->sg_list;
1178 sge[0].addr = ib_dma_map_single(mad_agent->device,
1179 mad_send_wr->send_buf.mad,
1180 sge[0].length,
1181 DMA_TO_DEVICE);
1182 if (unlikely(ib_dma_mapping_error(mad_agent->device, sge[0].addr)))
1183 return -ENOMEM;
1184
1185 mad_send_wr->header_mapping = sge[0].addr;
1186
1187 sge[1].addr = ib_dma_map_single(mad_agent->device,
1188 ib_get_payload(mad_send_wr),
1189 sge[1].length,
1190 DMA_TO_DEVICE);
1191 if (unlikely(ib_dma_mapping_error(mad_agent->device, sge[1].addr))) {
1192 ib_dma_unmap_single(mad_agent->device,
1193 mad_send_wr->header_mapping,
1194 sge[0].length, DMA_TO_DEVICE);
1195 return -ENOMEM;
1196 }
1197 mad_send_wr->payload_mapping = sge[1].addr;
1198
1199 spin_lock_irqsave(&qp_info->send_queue.lock, flags);
1200 if (qp_info->send_queue.count < qp_info->send_queue.max_active) {
1201 ret = ib_post_send(mad_agent->qp, &mad_send_wr->send_wr.wr,
1202 &bad_send_wr);
1203 list = &qp_info->send_queue.list;
1204 } else {
1205 ret = 0;
1206 list = &qp_info->overflow_list;
1207 }
1208
1209 if (!ret) {
1210 qp_info->send_queue.count++;
1211 list_add_tail(&mad_send_wr->mad_list.list, list);
1212 }
1213 spin_unlock_irqrestore(&qp_info->send_queue.lock, flags);
1214 if (ret) {
1215 ib_dma_unmap_single(mad_agent->device,
1216 mad_send_wr->header_mapping,
1217 sge[0].length, DMA_TO_DEVICE);
1218 ib_dma_unmap_single(mad_agent->device,
1219 mad_send_wr->payload_mapping,
1220 sge[1].length, DMA_TO_DEVICE);
1221 }
1222 return ret;
1223 }
1224
1225 /*
1226 * ib_post_send_mad - Posts MAD(s) to the send queue of the QP associated
1227 * with the registered client
1228 */
1229 int ib_post_send_mad(struct ib_mad_send_buf *send_buf,
1230 struct ib_mad_send_buf **bad_send_buf)
1231 {
1232 struct ib_mad_agent_private *mad_agent_priv;
1233 struct ib_mad_send_buf *next_send_buf;
1234 struct ib_mad_send_wr_private *mad_send_wr;
1235 unsigned long flags;
1236 int ret = -EINVAL;
1237
1238 /* Walk list of send WRs and post each on send list */
1239 for (; send_buf; send_buf = next_send_buf) {
1240 mad_send_wr = container_of(send_buf,
1241 struct ib_mad_send_wr_private,
1242 send_buf);
1243 mad_agent_priv = mad_send_wr->mad_agent_priv;
1244
1245 ret = ib_mad_enforce_security(mad_agent_priv,
1246 mad_send_wr->send_wr.pkey_index);
1247 if (ret)
1248 goto error;
1249
1250 if (!send_buf->mad_agent->send_handler ||
1251 (send_buf->timeout_ms &&
1252 !send_buf->mad_agent->recv_handler)) {
1253 ret = -EINVAL;
1254 goto error;
1255 }
1256
1257 if (!ib_is_mad_class_rmpp(((struct ib_mad_hdr *) send_buf->mad)->mgmt_class)) {
1258 if (mad_agent_priv->agent.rmpp_version) {
1259 ret = -EINVAL;
1260 goto error;
1261 }
1262 }
1263
1264 /*
1265 * Save pointer to next work request to post in case the
1266 * current one completes, and the user modifies the work
1267 * request associated with the completion
1268 */
1269 next_send_buf = send_buf->next;
1270 mad_send_wr->send_wr.ah = send_buf->ah;
1271
1272 if (((struct ib_mad_hdr *) send_buf->mad)->mgmt_class ==
1273 IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE) {
1274 ret = handle_outgoing_dr_smp(mad_agent_priv,
1275 mad_send_wr);
1276 if (ret < 0) /* error */
1277 goto error;
1278 else if (ret == 1) /* locally consumed */
1279 continue;
1280 }
1281
1282 mad_send_wr->tid = ((struct ib_mad_hdr *) send_buf->mad)->tid;
1283 /* Timeout will be updated after send completes */
1284 mad_send_wr->timeout = msecs_to_jiffies(send_buf->timeout_ms);
1285 mad_send_wr->max_retries = send_buf->retries;
1286 mad_send_wr->retries_left = send_buf->retries;
1287 send_buf->retries = 0;
1288 /* Reference for work request to QP + response */
1289 mad_send_wr->refcount = 1 + (mad_send_wr->timeout > 0);
1290 mad_send_wr->status = IB_WC_SUCCESS;
1291
1292 /* Reference MAD agent until send completes */
1293 atomic_inc(&mad_agent_priv->refcount);
1294 spin_lock_irqsave(&mad_agent_priv->lock, flags);
1295 list_add_tail(&mad_send_wr->agent_list,
1296 &mad_agent_priv->send_list);
1297 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
1298
1299 if (ib_mad_kernel_rmpp_agent(&mad_agent_priv->agent)) {
1300 ret = ib_send_rmpp_mad(mad_send_wr);
1301 if (ret >= 0 && ret != IB_RMPP_RESULT_CONSUMED)
1302 ret = ib_send_mad(mad_send_wr);
1303 } else
1304 ret = ib_send_mad(mad_send_wr);
1305 if (ret < 0) {
1306 /* Fail send request */
1307 spin_lock_irqsave(&mad_agent_priv->lock, flags);
1308 list_del(&mad_send_wr->agent_list);
1309 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
1310 atomic_dec(&mad_agent_priv->refcount);
1311 goto error;
1312 }
1313 }
1314 return 0;
1315 error:
1316 if (bad_send_buf)
1317 *bad_send_buf = send_buf;
1318 return ret;
1319 }
1320 EXPORT_SYMBOL(ib_post_send_mad);
1321
1322 /*
1323 * ib_free_recv_mad - Returns data buffers used to receive
1324 * a MAD to the access layer
1325 */
1326 void ib_free_recv_mad(struct ib_mad_recv_wc *mad_recv_wc)
1327 {
1328 struct ib_mad_recv_buf *mad_recv_buf, *temp_recv_buf;
1329 struct ib_mad_private_header *mad_priv_hdr;
1330 struct ib_mad_private *priv;
1331 struct list_head free_list;
1332
1333 INIT_LIST_HEAD(&free_list);
1334 list_splice_init(&mad_recv_wc->rmpp_list, &free_list);
1335
1336 list_for_each_entry_safe(mad_recv_buf, temp_recv_buf,
1337 &free_list, list) {
1338 mad_recv_wc = container_of(mad_recv_buf, struct ib_mad_recv_wc,
1339 recv_buf);
1340 mad_priv_hdr = container_of(mad_recv_wc,
1341 struct ib_mad_private_header,
1342 recv_wc);
1343 priv = container_of(mad_priv_hdr, struct ib_mad_private,
1344 header);
1345 kfree(priv);
1346 }
1347 }
1348 EXPORT_SYMBOL(ib_free_recv_mad);
1349
1350 struct ib_mad_agent *ib_redirect_mad_qp(struct ib_qp *qp,
1351 u8 rmpp_version,
1352 ib_mad_send_handler send_handler,
1353 ib_mad_recv_handler recv_handler,
1354 void *context)
1355 {
1356 return ERR_PTR(-EINVAL); /* XXX: for now */
1357 }
1358 EXPORT_SYMBOL(ib_redirect_mad_qp);
1359
1360 int ib_process_mad_wc(struct ib_mad_agent *mad_agent,
1361 struct ib_wc *wc)
1362 {
1363 dev_err(&mad_agent->device->dev,
1364 "ib_process_mad_wc() not implemented yet\n");
1365 return 0;
1366 }
1367 EXPORT_SYMBOL(ib_process_mad_wc);
1368
1369 static int method_in_use(struct ib_mad_mgmt_method_table **method,
1370 struct ib_mad_reg_req *mad_reg_req)
1371 {
1372 int i;
1373
1374 for_each_set_bit(i, mad_reg_req->method_mask, IB_MGMT_MAX_METHODS) {
1375 if ((*method)->agent[i]) {
1376 pr_err("Method %d already in use\n", i);
1377 return -EINVAL;
1378 }
1379 }
1380 return 0;
1381 }
1382
1383 static int allocate_method_table(struct ib_mad_mgmt_method_table **method)
1384 {
1385 /* Allocate management method table */
1386 *method = kzalloc(sizeof **method, GFP_ATOMIC);
1387 return (*method) ? 0 : (-ENOMEM);
1388 }
1389
1390 /*
1391 * Check to see if there are any methods still in use
1392 */
1393 static int check_method_table(struct ib_mad_mgmt_method_table *method)
1394 {
1395 int i;
1396
1397 for (i = 0; i < IB_MGMT_MAX_METHODS; i++)
1398 if (method->agent[i])
1399 return 1;
1400 return 0;
1401 }
1402
1403 /*
1404 * Check to see if there are any method tables for this class still in use
1405 */
1406 static int check_class_table(struct ib_mad_mgmt_class_table *class)
1407 {
1408 int i;
1409
1410 for (i = 0; i < MAX_MGMT_CLASS; i++)
1411 if (class->method_table[i])
1412 return 1;
1413 return 0;
1414 }
1415
1416 static int check_vendor_class(struct ib_mad_mgmt_vendor_class *vendor_class)
1417 {
1418 int i;
1419
1420 for (i = 0; i < MAX_MGMT_OUI; i++)
1421 if (vendor_class->method_table[i])
1422 return 1;
1423 return 0;
1424 }
1425
1426 static int find_vendor_oui(struct ib_mad_mgmt_vendor_class *vendor_class,
1427 const char *oui)
1428 {
1429 int i;
1430
1431 for (i = 0; i < MAX_MGMT_OUI; i++)
1432 /* Is there matching OUI for this vendor class ? */
1433 if (!memcmp(vendor_class->oui[i], oui, 3))
1434 return i;
1435
1436 return -1;
1437 }
1438
1439 static int check_vendor_table(struct ib_mad_mgmt_vendor_class_table *vendor)
1440 {
1441 int i;
1442
1443 for (i = 0; i < MAX_MGMT_VENDOR_RANGE2; i++)
1444 if (vendor->vendor_class[i])
1445 return 1;
1446
1447 return 0;
1448 }
1449
1450 static void remove_methods_mad_agent(struct ib_mad_mgmt_method_table *method,
1451 struct ib_mad_agent_private *agent)
1452 {
1453 int i;
1454
1455 /* Remove any methods for this mad agent */
1456 for (i = 0; i < IB_MGMT_MAX_METHODS; i++) {
1457 if (method->agent[i] == agent) {
1458 method->agent[i] = NULL;
1459 }
1460 }
1461 }
1462
1463 static int add_nonoui_reg_req(struct ib_mad_reg_req *mad_reg_req,
1464 struct ib_mad_agent_private *agent_priv,
1465 u8 mgmt_class)
1466 {
1467 struct ib_mad_port_private *port_priv;
1468 struct ib_mad_mgmt_class_table **class;
1469 struct ib_mad_mgmt_method_table **method;
1470 int i, ret;
1471
1472 port_priv = agent_priv->qp_info->port_priv;
1473 class = &port_priv->version[mad_reg_req->mgmt_class_version].class;
1474 if (!*class) {
1475 /* Allocate management class table for "new" class version */
1476 *class = kzalloc(sizeof **class, GFP_ATOMIC);
1477 if (!*class) {
1478 ret = -ENOMEM;
1479 goto error1;
1480 }
1481
1482 /* Allocate method table for this management class */
1483 method = &(*class)->method_table[mgmt_class];
1484 if ((ret = allocate_method_table(method)))
1485 goto error2;
1486 } else {
1487 method = &(*class)->method_table[mgmt_class];
1488 if (!*method) {
1489 /* Allocate method table for this management class */
1490 if ((ret = allocate_method_table(method)))
1491 goto error1;
1492 }
1493 }
1494
1495 /* Now, make sure methods are not already in use */
1496 if (method_in_use(method, mad_reg_req))
1497 goto error3;
1498
1499 /* Finally, add in methods being registered */
1500 for_each_set_bit(i, mad_reg_req->method_mask, IB_MGMT_MAX_METHODS)
1501 (*method)->agent[i] = agent_priv;
1502
1503 return 0;
1504
1505 error3:
1506 /* Remove any methods for this mad agent */
1507 remove_methods_mad_agent(*method, agent_priv);
1508 /* Now, check to see if there are any methods in use */
1509 if (!check_method_table(*method)) {
1510 /* If not, release management method table */
1511 kfree(*method);
1512 *method = NULL;
1513 }
1514 ret = -EINVAL;
1515 goto error1;
1516 error2:
1517 kfree(*class);
1518 *class = NULL;
1519 error1:
1520 return ret;
1521 }
1522
1523 static int add_oui_reg_req(struct ib_mad_reg_req *mad_reg_req,
1524 struct ib_mad_agent_private *agent_priv)
1525 {
1526 struct ib_mad_port_private *port_priv;
1527 struct ib_mad_mgmt_vendor_class_table **vendor_table;
1528 struct ib_mad_mgmt_vendor_class_table *vendor = NULL;
1529 struct ib_mad_mgmt_vendor_class *vendor_class = NULL;
1530 struct ib_mad_mgmt_method_table **method;
1531 int i, ret = -ENOMEM;
1532 u8 vclass;
1533
1534 /* "New" vendor (with OUI) class */
1535 vclass = vendor_class_index(mad_reg_req->mgmt_class);
1536 port_priv = agent_priv->qp_info->port_priv;
1537 vendor_table = &port_priv->version[
1538 mad_reg_req->mgmt_class_version].vendor;
1539 if (!*vendor_table) {
1540 /* Allocate mgmt vendor class table for "new" class version */
1541 vendor = kzalloc(sizeof *vendor, GFP_ATOMIC);
1542 if (!vendor)
1543 goto error1;
1544
1545 *vendor_table = vendor;
1546 }
1547 if (!(*vendor_table)->vendor_class[vclass]) {
1548 /* Allocate table for this management vendor class */
1549 vendor_class = kzalloc(sizeof *vendor_class, GFP_ATOMIC);
1550 if (!vendor_class)
1551 goto error2;
1552
1553 (*vendor_table)->vendor_class[vclass] = vendor_class;
1554 }
1555 for (i = 0; i < MAX_MGMT_OUI; i++) {
1556 /* Is there matching OUI for this vendor class ? */
1557 if (!memcmp((*vendor_table)->vendor_class[vclass]->oui[i],
1558 mad_reg_req->oui, 3)) {
1559 method = &(*vendor_table)->vendor_class[
1560 vclass]->method_table[i];
1561 if (!*method)
1562 goto error3;
1563 goto check_in_use;
1564 }
1565 }
1566 for (i = 0; i < MAX_MGMT_OUI; i++) {
1567 /* OUI slot available ? */
1568 if (!is_vendor_oui((*vendor_table)->vendor_class[
1569 vclass]->oui[i])) {
1570 method = &(*vendor_table)->vendor_class[
1571 vclass]->method_table[i];
1572 /* Allocate method table for this OUI */
1573 if (!*method) {
1574 ret = allocate_method_table(method);
1575 if (ret)
1576 goto error3;
1577 }
1578 memcpy((*vendor_table)->vendor_class[vclass]->oui[i],
1579 mad_reg_req->oui, 3);
1580 goto check_in_use;
1581 }
1582 }
1583 dev_err(&agent_priv->agent.device->dev, "All OUI slots in use\n");
1584 goto error3;
1585
1586 check_in_use:
1587 /* Now, make sure methods are not already in use */
1588 if (method_in_use(method, mad_reg_req))
1589 goto error4;
1590
1591 /* Finally, add in methods being registered */
1592 for_each_set_bit(i, mad_reg_req->method_mask, IB_MGMT_MAX_METHODS)
1593 (*method)->agent[i] = agent_priv;
1594
1595 return 0;
1596
1597 error4:
1598 /* Remove any methods for this mad agent */
1599 remove_methods_mad_agent(*method, agent_priv);
1600 /* Now, check to see if there are any methods in use */
1601 if (!check_method_table(*method)) {
1602 /* If not, release management method table */
1603 kfree(*method);
1604 *method = NULL;
1605 }
1606 ret = -EINVAL;
1607 error3:
1608 if (vendor_class) {
1609 (*vendor_table)->vendor_class[vclass] = NULL;
1610 kfree(vendor_class);
1611 }
1612 error2:
1613 if (vendor) {
1614 *vendor_table = NULL;
1615 kfree(vendor);
1616 }
1617 error1:
1618 return ret;
1619 }
1620
1621 static void remove_mad_reg_req(struct ib_mad_agent_private *agent_priv)
1622 {
1623 struct ib_mad_port_private *port_priv;
1624 struct ib_mad_mgmt_class_table *class;
1625 struct ib_mad_mgmt_method_table *method;
1626 struct ib_mad_mgmt_vendor_class_table *vendor;
1627 struct ib_mad_mgmt_vendor_class *vendor_class;
1628 int index;
1629 u8 mgmt_class;
1630
1631 /*
1632 * Was MAD registration request supplied
1633 * with original registration ?
1634 */
1635 if (!agent_priv->reg_req) {
1636 goto out;
1637 }
1638
1639 port_priv = agent_priv->qp_info->port_priv;
1640 mgmt_class = convert_mgmt_class(agent_priv->reg_req->mgmt_class);
1641 class = port_priv->version[
1642 agent_priv->reg_req->mgmt_class_version].class;
1643 if (!class)
1644 goto vendor_check;
1645
1646 method = class->method_table[mgmt_class];
1647 if (method) {
1648 /* Remove any methods for this mad agent */
1649 remove_methods_mad_agent(method, agent_priv);
1650 /* Now, check to see if there are any methods still in use */
1651 if (!check_method_table(method)) {
1652 /* If not, release management method table */
1653 kfree(method);
1654 class->method_table[mgmt_class] = NULL;
1655 /* Any management classes left ? */
1656 if (!check_class_table(class)) {
1657 /* If not, release management class table */
1658 kfree(class);
1659 port_priv->version[
1660 agent_priv->reg_req->
1661 mgmt_class_version].class = NULL;
1662 }
1663 }
1664 }
1665
1666 vendor_check:
1667 if (!is_vendor_class(mgmt_class))
1668 goto out;
1669
1670 /* normalize mgmt_class to vendor range 2 */
1671 mgmt_class = vendor_class_index(agent_priv->reg_req->mgmt_class);
1672 vendor = port_priv->version[
1673 agent_priv->reg_req->mgmt_class_version].vendor;
1674
1675 if (!vendor)
1676 goto out;
1677
1678 vendor_class = vendor->vendor_class[mgmt_class];
1679 if (vendor_class) {
1680 index = find_vendor_oui(vendor_class, agent_priv->reg_req->oui);
1681 if (index < 0)
1682 goto out;
1683 method = vendor_class->method_table[index];
1684 if (method) {
1685 /* Remove any methods for this mad agent */
1686 remove_methods_mad_agent(method, agent_priv);
1687 /*
1688 * Now, check to see if there are
1689 * any methods still in use
1690 */
1691 if (!check_method_table(method)) {
1692 /* If not, release management method table */
1693 kfree(method);
1694 vendor_class->method_table[index] = NULL;
1695 memset(vendor_class->oui[index], 0, 3);
1696 /* Any OUIs left ? */
1697 if (!check_vendor_class(vendor_class)) {
1698 /* If not, release vendor class table */
1699 kfree(vendor_class);
1700 vendor->vendor_class[mgmt_class] = NULL;
1701 /* Any other vendor classes left ? */
1702 if (!check_vendor_table(vendor)) {
1703 kfree(vendor);
1704 port_priv->version[
1705 agent_priv->reg_req->
1706 mgmt_class_version].
1707 vendor = NULL;
1708 }
1709 }
1710 }
1711 }
1712 }
1713
1714 out:
1715 return;
1716 }
1717
1718 static struct ib_mad_agent_private *
1719 find_mad_agent(struct ib_mad_port_private *port_priv,
1720 const struct ib_mad_hdr *mad_hdr)
1721 {
1722 struct ib_mad_agent_private *mad_agent = NULL;
1723 unsigned long flags;
1724
1725 spin_lock_irqsave(&port_priv->reg_lock, flags);
1726 if (ib_response_mad(mad_hdr)) {
1727 u32 hi_tid;
1728 struct ib_mad_agent_private *entry;
1729
1730 /*
1731 * Routing is based on high 32 bits of transaction ID
1732 * of MAD.
1733 */
1734 hi_tid = be64_to_cpu(mad_hdr->tid) >> 32;
1735 list_for_each_entry(entry, &port_priv->agent_list, agent_list) {
1736 if (entry->agent.hi_tid == hi_tid) {
1737 mad_agent = entry;
1738 break;
1739 }
1740 }
1741 } else {
1742 struct ib_mad_mgmt_class_table *class;
1743 struct ib_mad_mgmt_method_table *method;
1744 struct ib_mad_mgmt_vendor_class_table *vendor;
1745 struct ib_mad_mgmt_vendor_class *vendor_class;
1746 const struct ib_vendor_mad *vendor_mad;
1747 int index;
1748
1749 /*
1750 * Routing is based on version, class, and method
1751 * For "newer" vendor MADs, also based on OUI
1752 */
1753 if (mad_hdr->class_version >= MAX_MGMT_VERSION)
1754 goto out;
1755 if (!is_vendor_class(mad_hdr->mgmt_class)) {
1756 class = port_priv->version[
1757 mad_hdr->class_version].class;
1758 if (!class)
1759 goto out;
1760 if (convert_mgmt_class(mad_hdr->mgmt_class) >=
1761 ARRAY_SIZE(class->method_table))
1762 goto out;
1763 method = class->method_table[convert_mgmt_class(
1764 mad_hdr->mgmt_class)];
1765 if (method)
1766 mad_agent = method->agent[mad_hdr->method &
1767 ~IB_MGMT_METHOD_RESP];
1768 } else {
1769 vendor = port_priv->version[
1770 mad_hdr->class_version].vendor;
1771 if (!vendor)
1772 goto out;
1773 vendor_class = vendor->vendor_class[vendor_class_index(
1774 mad_hdr->mgmt_class)];
1775 if (!vendor_class)
1776 goto out;
1777 /* Find matching OUI */
1778 vendor_mad = (const struct ib_vendor_mad *)mad_hdr;
1779 index = find_vendor_oui(vendor_class, vendor_mad->oui);
1780 if (index == -1)
1781 goto out;
1782 method = vendor_class->method_table[index];
1783 if (method) {
1784 mad_agent = method->agent[mad_hdr->method &
1785 ~IB_MGMT_METHOD_RESP];
1786 }
1787 }
1788 }
1789
1790 if (mad_agent) {
1791 if (mad_agent->agent.recv_handler)
1792 atomic_inc(&mad_agent->refcount);
1793 else {
1794 dev_notice(&port_priv->device->dev,
1795 "No receive handler for client %p on port %d\n",
1796 &mad_agent->agent, port_priv->port_num);
1797 mad_agent = NULL;
1798 }
1799 }
1800 out:
1801 spin_unlock_irqrestore(&port_priv->reg_lock, flags);
1802
1803 return mad_agent;
1804 }
1805
1806 static int validate_mad(const struct ib_mad_hdr *mad_hdr,
1807 const struct ib_mad_qp_info *qp_info,
1808 bool opa)
1809 {
1810 int valid = 0;
1811 u32 qp_num = qp_info->qp->qp_num;
1812
1813 /* Make sure MAD base version is understood */
1814 if (mad_hdr->base_version != IB_MGMT_BASE_VERSION &&
1815 (!opa || mad_hdr->base_version != OPA_MGMT_BASE_VERSION)) {
1816 pr_err("MAD received with unsupported base version %d %s\n",
1817 mad_hdr->base_version, opa ? "(opa)" : "");
1818 goto out;
1819 }
1820
1821 /* Filter SMI packets sent to other than QP0 */
1822 if ((mad_hdr->mgmt_class == IB_MGMT_CLASS_SUBN_LID_ROUTED) ||
1823 (mad_hdr->mgmt_class == IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE)) {
1824 if (qp_num == 0)
1825 valid = 1;
1826 } else {
1827 /* CM attributes other than ClassPortInfo only use Send method */
1828 if ((mad_hdr->mgmt_class == IB_MGMT_CLASS_CM) &&
1829 (mad_hdr->attr_id != IB_MGMT_CLASSPORTINFO_ATTR_ID) &&
1830 (mad_hdr->method != IB_MGMT_METHOD_SEND))
1831 goto out;
1832 /* Filter GSI packets sent to QP0 */
1833 if (qp_num != 0)
1834 valid = 1;
1835 }
1836
1837 out:
1838 return valid;
1839 }
1840
1841 static int is_rmpp_data_mad(const struct ib_mad_agent_private *mad_agent_priv,
1842 const struct ib_mad_hdr *mad_hdr)
1843 {
1844 struct ib_rmpp_mad *rmpp_mad;
1845
1846 rmpp_mad = (struct ib_rmpp_mad *)mad_hdr;
1847 return !mad_agent_priv->agent.rmpp_version ||
1848 !ib_mad_kernel_rmpp_agent(&mad_agent_priv->agent) ||
1849 !(ib_get_rmpp_flags(&rmpp_mad->rmpp_hdr) &
1850 IB_MGMT_RMPP_FLAG_ACTIVE) ||
1851 (rmpp_mad->rmpp_hdr.rmpp_type == IB_MGMT_RMPP_TYPE_DATA);
1852 }
1853
1854 static inline int rcv_has_same_class(const struct ib_mad_send_wr_private *wr,
1855 const struct ib_mad_recv_wc *rwc)
1856 {
1857 return ((struct ib_mad_hdr *)(wr->send_buf.mad))->mgmt_class ==
1858 rwc->recv_buf.mad->mad_hdr.mgmt_class;
1859 }
1860
1861 static inline int rcv_has_same_gid(const struct ib_mad_agent_private *mad_agent_priv,
1862 const struct ib_mad_send_wr_private *wr,
1863 const struct ib_mad_recv_wc *rwc )
1864 {
1865 struct rdma_ah_attr attr;
1866 u8 send_resp, rcv_resp;
1867 union ib_gid sgid;
1868 struct ib_device *device = mad_agent_priv->agent.device;
1869 u8 port_num = mad_agent_priv->agent.port_num;
1870 u8 lmc;
1871 bool has_grh;
1872
1873 send_resp = ib_response_mad((struct ib_mad_hdr *)wr->send_buf.mad);
1874 rcv_resp = ib_response_mad(&rwc->recv_buf.mad->mad_hdr);
1875
1876 if (send_resp == rcv_resp)
1877 /* both requests, or both responses. GIDs different */
1878 return 0;
1879
1880 if (rdma_query_ah(wr->send_buf.ah, &attr))
1881 /* Assume not equal, to avoid false positives. */
1882 return 0;
1883
1884 has_grh = !!(rdma_ah_get_ah_flags(&attr) & IB_AH_GRH);
1885 if (has_grh != !!(rwc->wc->wc_flags & IB_WC_GRH))
1886 /* one has GID, other does not. Assume different */
1887 return 0;
1888
1889 if (!send_resp && rcv_resp) {
1890 /* is request/response. */
1891 if (!has_grh) {
1892 if (ib_get_cached_lmc(device, port_num, &lmc))
1893 return 0;
1894 return (!lmc || !((rdma_ah_get_path_bits(&attr) ^
1895 rwc->wc->dlid_path_bits) &
1896 ((1 << lmc) - 1)));
1897 } else {
1898 const struct ib_global_route *grh =
1899 rdma_ah_read_grh(&attr);
1900
1901 if (ib_get_cached_gid(device, port_num,
1902 grh->sgid_index, &sgid, NULL))
1903 return 0;
1904 return !memcmp(sgid.raw, rwc->recv_buf.grh->dgid.raw,
1905 16);
1906 }
1907 }
1908
1909 if (!has_grh)
1910 return rdma_ah_get_dlid(&attr) == rwc->wc->slid;
1911 else
1912 return !memcmp(rdma_ah_read_grh(&attr)->dgid.raw,
1913 rwc->recv_buf.grh->sgid.raw,
1914 16);
1915 }
1916
1917 static inline int is_direct(u8 class)
1918 {
1919 return (class == IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE);
1920 }
1921
1922 struct ib_mad_send_wr_private*
1923 ib_find_send_mad(const struct ib_mad_agent_private *mad_agent_priv,
1924 const struct ib_mad_recv_wc *wc)
1925 {
1926 struct ib_mad_send_wr_private *wr;
1927 const struct ib_mad_hdr *mad_hdr;
1928
1929 mad_hdr = &wc->recv_buf.mad->mad_hdr;
1930
1931 list_for_each_entry(wr, &mad_agent_priv->wait_list, agent_list) {
1932 if ((wr->tid == mad_hdr->tid) &&
1933 rcv_has_same_class(wr, wc) &&
1934 /*
1935 * Don't check GID for direct routed MADs.
1936 * These might have permissive LIDs.
1937 */
1938 (is_direct(mad_hdr->mgmt_class) ||
1939 rcv_has_same_gid(mad_agent_priv, wr, wc)))
1940 return (wr->status == IB_WC_SUCCESS) ? wr : NULL;
1941 }
1942
1943 /*
1944 * It's possible to receive the response before we've
1945 * been notified that the send has completed
1946 */
1947 list_for_each_entry(wr, &mad_agent_priv->send_list, agent_list) {
1948 if (is_rmpp_data_mad(mad_agent_priv, wr->send_buf.mad) &&
1949 wr->tid == mad_hdr->tid &&
1950 wr->timeout &&
1951 rcv_has_same_class(wr, wc) &&
1952 /*
1953 * Don't check GID for direct routed MADs.
1954 * These might have permissive LIDs.
1955 */
1956 (is_direct(mad_hdr->mgmt_class) ||
1957 rcv_has_same_gid(mad_agent_priv, wr, wc)))
1958 /* Verify request has not been canceled */
1959 return (wr->status == IB_WC_SUCCESS) ? wr : NULL;
1960 }
1961 return NULL;
1962 }
1963
1964 void ib_mark_mad_done(struct ib_mad_send_wr_private *mad_send_wr)
1965 {
1966 mad_send_wr->timeout = 0;
1967 if (mad_send_wr->refcount == 1)
1968 list_move_tail(&mad_send_wr->agent_list,
1969 &mad_send_wr->mad_agent_priv->done_list);
1970 }
1971
1972 static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
1973 struct ib_mad_recv_wc *mad_recv_wc)
1974 {
1975 struct ib_mad_send_wr_private *mad_send_wr;
1976 struct ib_mad_send_wc mad_send_wc;
1977 unsigned long flags;
1978 int ret;
1979
1980 INIT_LIST_HEAD(&mad_recv_wc->rmpp_list);
1981 ret = ib_mad_enforce_security(mad_agent_priv,
1982 mad_recv_wc->wc->pkey_index);
1983 if (ret) {
1984 ib_free_recv_mad(mad_recv_wc);
1985 deref_mad_agent(mad_agent_priv);
1986 return;
1987 }
1988
1989 list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
1990 if (ib_mad_kernel_rmpp_agent(&mad_agent_priv->agent)) {
1991 mad_recv_wc = ib_process_rmpp_recv_wc(mad_agent_priv,
1992 mad_recv_wc);
1993 if (!mad_recv_wc) {
1994 deref_mad_agent(mad_agent_priv);
1995 return;
1996 }
1997 }
1998
1999 /* Complete corresponding request */
2000 if (ib_response_mad(&mad_recv_wc->recv_buf.mad->mad_hdr)) {
2001 spin_lock_irqsave(&mad_agent_priv->lock, flags);
2002 mad_send_wr = ib_find_send_mad(mad_agent_priv, mad_recv_wc);
2003 if (!mad_send_wr) {
2004 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2005 if (!ib_mad_kernel_rmpp_agent(&mad_agent_priv->agent)
2006 && ib_is_mad_class_rmpp(mad_recv_wc->recv_buf.mad->mad_hdr.mgmt_class)
2007 && (ib_get_rmpp_flags(&((struct ib_rmpp_mad *)mad_recv_wc->recv_buf.mad)->rmpp_hdr)
2008 & IB_MGMT_RMPP_FLAG_ACTIVE)) {
2009 /* user rmpp is in effect
2010 * and this is an active RMPP MAD
2011 */
2012 mad_agent_priv->agent.recv_handler(
2013 &mad_agent_priv->agent, NULL,
2014 mad_recv_wc);
2015 atomic_dec(&mad_agent_priv->refcount);
2016 } else {
2017 /* not user rmpp, revert to normal behavior and
2018 * drop the mad */
2019 ib_free_recv_mad(mad_recv_wc);
2020 deref_mad_agent(mad_agent_priv);
2021 return;
2022 }
2023 } else {
2024 ib_mark_mad_done(mad_send_wr);
2025 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2026
2027 /* Defined behavior is to complete response before request */
2028 mad_agent_priv->agent.recv_handler(
2029 &mad_agent_priv->agent,
2030 &mad_send_wr->send_buf,
2031 mad_recv_wc);
2032 atomic_dec(&mad_agent_priv->refcount);
2033
2034 mad_send_wc.status = IB_WC_SUCCESS;
2035 mad_send_wc.vendor_err = 0;
2036 mad_send_wc.send_buf = &mad_send_wr->send_buf;
2037 ib_mad_complete_send_wr(mad_send_wr, &mad_send_wc);
2038 }
2039 } else {
2040 mad_agent_priv->agent.recv_handler(&mad_agent_priv->agent, NULL,
2041 mad_recv_wc);
2042 deref_mad_agent(mad_agent_priv);
2043 }
2044
2045 return;
2046 }
2047
2048 static enum smi_action handle_ib_smi(const struct ib_mad_port_private *port_priv,
2049 const struct ib_mad_qp_info *qp_info,
2050 const struct ib_wc *wc,
2051 int port_num,
2052 struct ib_mad_private *recv,
2053 struct ib_mad_private *response)
2054 {
2055 enum smi_forward_action retsmi;
2056 struct ib_smp *smp = (struct ib_smp *)recv->mad;
2057
2058 if (smi_handle_dr_smp_recv(smp,
2059 rdma_cap_ib_switch(port_priv->device),
2060 port_num,
2061 port_priv->device->phys_port_cnt) ==
2062 IB_SMI_DISCARD)
2063 return IB_SMI_DISCARD;
2064
2065 retsmi = smi_check_forward_dr_smp(smp);
2066 if (retsmi == IB_SMI_LOCAL)
2067 return IB_SMI_HANDLE;
2068
2069 if (retsmi == IB_SMI_SEND) { /* don't forward */
2070 if (smi_handle_dr_smp_send(smp,
2071 rdma_cap_ib_switch(port_priv->device),
2072 port_num) == IB_SMI_DISCARD)
2073 return IB_SMI_DISCARD;
2074
2075 if (smi_check_local_smp(smp, port_priv->device) == IB_SMI_DISCARD)
2076 return IB_SMI_DISCARD;
2077 } else if (rdma_cap_ib_switch(port_priv->device)) {
2078 /* forward case for switches */
2079 memcpy(response, recv, mad_priv_size(response));
2080 response->header.recv_wc.wc = &response->header.wc;
2081 response->header.recv_wc.recv_buf.mad = (struct ib_mad *)response->mad;
2082 response->header.recv_wc.recv_buf.grh = &response->grh;
2083
2084 agent_send_response((const struct ib_mad_hdr *)response->mad,
2085 &response->grh, wc,
2086 port_priv->device,
2087 smi_get_fwd_port(smp),
2088 qp_info->qp->qp_num,
2089 response->mad_size,
2090 false);
2091
2092 return IB_SMI_DISCARD;
2093 }
2094 return IB_SMI_HANDLE;
2095 }
2096
2097 static bool generate_unmatched_resp(const struct ib_mad_private *recv,
2098 struct ib_mad_private *response,
2099 size_t *resp_len, bool opa)
2100 {
2101 const struct ib_mad_hdr *recv_hdr = (const struct ib_mad_hdr *)recv->mad;
2102 struct ib_mad_hdr *resp_hdr = (struct ib_mad_hdr *)response->mad;
2103
2104 if (recv_hdr->method == IB_MGMT_METHOD_GET ||
2105 recv_hdr->method == IB_MGMT_METHOD_SET) {
2106 memcpy(response, recv, mad_priv_size(response));
2107 response->header.recv_wc.wc = &response->header.wc;
2108 response->header.recv_wc.recv_buf.mad = (struct ib_mad *)response->mad;
2109 response->header.recv_wc.recv_buf.grh = &response->grh;
2110 resp_hdr->method = IB_MGMT_METHOD_GET_RESP;
2111 resp_hdr->status = cpu_to_be16(IB_MGMT_MAD_STATUS_UNSUPPORTED_METHOD_ATTRIB);
2112 if (recv_hdr->mgmt_class == IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE)
2113 resp_hdr->status |= IB_SMP_DIRECTION;
2114
2115 if (opa && recv_hdr->base_version == OPA_MGMT_BASE_VERSION) {
2116 if (recv_hdr->mgmt_class ==
2117 IB_MGMT_CLASS_SUBN_LID_ROUTED ||
2118 recv_hdr->mgmt_class ==
2119 IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE)
2120 *resp_len = opa_get_smp_header_size(
2121 (struct opa_smp *)recv->mad);
2122 else
2123 *resp_len = sizeof(struct ib_mad_hdr);
2124 }
2125
2126 return true;
2127 } else {
2128 return false;
2129 }
2130 }
2131
2132 static enum smi_action
2133 handle_opa_smi(struct ib_mad_port_private *port_priv,
2134 struct ib_mad_qp_info *qp_info,
2135 struct ib_wc *wc,
2136 int port_num,
2137 struct ib_mad_private *recv,
2138 struct ib_mad_private *response)
2139 {
2140 enum smi_forward_action retsmi;
2141 struct opa_smp *smp = (struct opa_smp *)recv->mad;
2142
2143 if (opa_smi_handle_dr_smp_recv(smp,
2144 rdma_cap_ib_switch(port_priv->device),
2145 port_num,
2146 port_priv->device->phys_port_cnt) ==
2147 IB_SMI_DISCARD)
2148 return IB_SMI_DISCARD;
2149
2150 retsmi = opa_smi_check_forward_dr_smp(smp);
2151 if (retsmi == IB_SMI_LOCAL)
2152 return IB_SMI_HANDLE;
2153
2154 if (retsmi == IB_SMI_SEND) { /* don't forward */
2155 if (opa_smi_handle_dr_smp_send(smp,
2156 rdma_cap_ib_switch(port_priv->device),
2157 port_num) == IB_SMI_DISCARD)
2158 return IB_SMI_DISCARD;
2159
2160 if (opa_smi_check_local_smp(smp, port_priv->device) ==
2161 IB_SMI_DISCARD)
2162 return IB_SMI_DISCARD;
2163
2164 } else if (rdma_cap_ib_switch(port_priv->device)) {
2165 /* forward case for switches */
2166 memcpy(response, recv, mad_priv_size(response));
2167 response->header.recv_wc.wc = &response->header.wc;
2168 response->header.recv_wc.recv_buf.opa_mad =
2169 (struct opa_mad *)response->mad;
2170 response->header.recv_wc.recv_buf.grh = &response->grh;
2171
2172 agent_send_response((const struct ib_mad_hdr *)response->mad,
2173 &response->grh, wc,
2174 port_priv->device,
2175 opa_smi_get_fwd_port(smp),
2176 qp_info->qp->qp_num,
2177 recv->header.wc.byte_len,
2178 true);
2179
2180 return IB_SMI_DISCARD;
2181 }
2182
2183 return IB_SMI_HANDLE;
2184 }
2185
2186 static enum smi_action
2187 handle_smi(struct ib_mad_port_private *port_priv,
2188 struct ib_mad_qp_info *qp_info,
2189 struct ib_wc *wc,
2190 int port_num,
2191 struct ib_mad_private *recv,
2192 struct ib_mad_private *response,
2193 bool opa)
2194 {
2195 struct ib_mad_hdr *mad_hdr = (struct ib_mad_hdr *)recv->mad;
2196
2197 if (opa && mad_hdr->base_version == OPA_MGMT_BASE_VERSION &&
2198 mad_hdr->class_version == OPA_SM_CLASS_VERSION)
2199 return handle_opa_smi(port_priv, qp_info, wc, port_num, recv,
2200 response);
2201
2202 return handle_ib_smi(port_priv, qp_info, wc, port_num, recv, response);
2203 }
2204
2205 static void ib_mad_recv_done(struct ib_cq *cq, struct ib_wc *wc)
2206 {
2207 struct ib_mad_port_private *port_priv = cq->cq_context;
2208 struct ib_mad_list_head *mad_list =
2209 container_of(wc->wr_cqe, struct ib_mad_list_head, cqe);
2210 struct ib_mad_qp_info *qp_info;
2211 struct ib_mad_private_header *mad_priv_hdr;
2212 struct ib_mad_private *recv, *response = NULL;
2213 struct ib_mad_agent_private *mad_agent;
2214 int port_num;
2215 int ret = IB_MAD_RESULT_SUCCESS;
2216 size_t mad_size;
2217 u16 resp_mad_pkey_index = 0;
2218 bool opa;
2219
2220 if (list_empty_careful(&port_priv->port_list))
2221 return;
2222
2223 if (wc->status != IB_WC_SUCCESS) {
2224 /*
2225 * Receive errors indicate that the QP has entered the error
2226 * state - error handling/shutdown code will cleanup
2227 */
2228 return;
2229 }
2230
2231 qp_info = mad_list->mad_queue->qp_info;
2232 dequeue_mad(mad_list);
2233
2234 opa = rdma_cap_opa_mad(qp_info->port_priv->device,
2235 qp_info->port_priv->port_num);
2236
2237 mad_priv_hdr = container_of(mad_list, struct ib_mad_private_header,
2238 mad_list);
2239 recv = container_of(mad_priv_hdr, struct ib_mad_private, header);
2240 ib_dma_unmap_single(port_priv->device,
2241 recv->header.mapping,
2242 mad_priv_dma_size(recv),
2243 DMA_FROM_DEVICE);
2244
2245 /* Setup MAD receive work completion from "normal" work completion */
2246 recv->header.wc = *wc;
2247 recv->header.recv_wc.wc = &recv->header.wc;
2248
2249 if (opa && ((struct ib_mad_hdr *)(recv->mad))->base_version == OPA_MGMT_BASE_VERSION) {
2250 recv->header.recv_wc.mad_len = wc->byte_len - sizeof(struct ib_grh);
2251 recv->header.recv_wc.mad_seg_size = sizeof(struct opa_mad);
2252 } else {
2253 recv->header.recv_wc.mad_len = sizeof(struct ib_mad);
2254 recv->header.recv_wc.mad_seg_size = sizeof(struct ib_mad);
2255 }
2256
2257 recv->header.recv_wc.recv_buf.mad = (struct ib_mad *)recv->mad;
2258 recv->header.recv_wc.recv_buf.grh = &recv->grh;
2259
2260 if (atomic_read(&qp_info->snoop_count))
2261 snoop_recv(qp_info, &recv->header.recv_wc, IB_MAD_SNOOP_RECVS);
2262
2263 /* Validate MAD */
2264 if (!validate_mad((const struct ib_mad_hdr *)recv->mad, qp_info, opa))
2265 goto out;
2266
2267 mad_size = recv->mad_size;
2268 response = alloc_mad_private(mad_size, GFP_KERNEL);
2269 if (!response)
2270 goto out;
2271
2272 if (rdma_cap_ib_switch(port_priv->device))
2273 port_num = wc->port_num;
2274 else
2275 port_num = port_priv->port_num;
2276
2277 if (((struct ib_mad_hdr *)recv->mad)->mgmt_class ==
2278 IB_MGMT_CLASS_SUBN_DIRECTED_ROUTE) {
2279 if (handle_smi(port_priv, qp_info, wc, port_num, recv,
2280 response, opa)
2281 == IB_SMI_DISCARD)
2282 goto out;
2283 }
2284
2285 /* Give driver "right of first refusal" on incoming MAD */
2286 if (port_priv->device->process_mad) {
2287 ret = port_priv->device->process_mad(port_priv->device, 0,
2288 port_priv->port_num,
2289 wc, &recv->grh,
2290 (const struct ib_mad_hdr *)recv->mad,
2291 recv->mad_size,
2292 (struct ib_mad_hdr *)response->mad,
2293 &mad_size, &resp_mad_pkey_index);
2294
2295 if (opa)
2296 wc->pkey_index = resp_mad_pkey_index;
2297
2298 if (ret & IB_MAD_RESULT_SUCCESS) {
2299 if (ret & IB_MAD_RESULT_CONSUMED)
2300 goto out;
2301 if (ret & IB_MAD_RESULT_REPLY) {
2302 agent_send_response((const struct ib_mad_hdr *)response->mad,
2303 &recv->grh, wc,
2304 port_priv->device,
2305 port_num,
2306 qp_info->qp->qp_num,
2307 mad_size, opa);
2308 goto out;
2309 }
2310 }
2311 }
2312
2313 mad_agent = find_mad_agent(port_priv, (const struct ib_mad_hdr *)recv->mad);
2314 if (mad_agent) {
2315 ib_mad_complete_recv(mad_agent, &recv->header.recv_wc);
2316 /*
2317 * recv is freed up in error cases in ib_mad_complete_recv
2318 * or via recv_handler in ib_mad_complete_recv()
2319 */
2320 recv = NULL;
2321 } else if ((ret & IB_MAD_RESULT_SUCCESS) &&
2322 generate_unmatched_resp(recv, response, &mad_size, opa)) {
2323 agent_send_response((const struct ib_mad_hdr *)response->mad, &recv->grh, wc,
2324 port_priv->device, port_num,
2325 qp_info->qp->qp_num, mad_size, opa);
2326 }
2327
2328 out:
2329 /* Post another receive request for this QP */
2330 if (response) {
2331 ib_mad_post_receive_mads(qp_info, response);
2332 kfree(recv);
2333 } else
2334 ib_mad_post_receive_mads(qp_info, recv);
2335 }
2336
2337 static void adjust_timeout(struct ib_mad_agent_private *mad_agent_priv)
2338 {
2339 struct ib_mad_send_wr_private *mad_send_wr;
2340 unsigned long delay;
2341
2342 if (list_empty(&mad_agent_priv->wait_list)) {
2343 cancel_delayed_work(&mad_agent_priv->timed_work);
2344 } else {
2345 mad_send_wr = list_entry(mad_agent_priv->wait_list.next,
2346 struct ib_mad_send_wr_private,
2347 agent_list);
2348
2349 if (time_after(mad_agent_priv->timeout,
2350 mad_send_wr->timeout)) {
2351 mad_agent_priv->timeout = mad_send_wr->timeout;
2352 delay = mad_send_wr->timeout - jiffies;
2353 if ((long)delay <= 0)
2354 delay = 1;
2355 mod_delayed_work(mad_agent_priv->qp_info->port_priv->wq,
2356 &mad_agent_priv->timed_work, delay);
2357 }
2358 }
2359 }
2360
2361 static void wait_for_response(struct ib_mad_send_wr_private *mad_send_wr)
2362 {
2363 struct ib_mad_agent_private *mad_agent_priv;
2364 struct ib_mad_send_wr_private *temp_mad_send_wr;
2365 struct list_head *list_item;
2366 unsigned long delay;
2367
2368 mad_agent_priv = mad_send_wr->mad_agent_priv;
2369 list_del(&mad_send_wr->agent_list);
2370
2371 delay = mad_send_wr->timeout;
2372 mad_send_wr->timeout += jiffies;
2373
2374 if (delay) {
2375 list_for_each_prev(list_item, &mad_agent_priv->wait_list) {
2376 temp_mad_send_wr = list_entry(list_item,
2377 struct ib_mad_send_wr_private,
2378 agent_list);
2379 if (time_after(mad_send_wr->timeout,
2380 temp_mad_send_wr->timeout))
2381 break;
2382 }
2383 }
2384 else
2385 list_item = &mad_agent_priv->wait_list;
2386 list_add(&mad_send_wr->agent_list, list_item);
2387
2388 /* Reschedule a work item if we have a shorter timeout */
2389 if (mad_agent_priv->wait_list.next == &mad_send_wr->agent_list)
2390 mod_delayed_work(mad_agent_priv->qp_info->port_priv->wq,
2391 &mad_agent_priv->timed_work, delay);
2392 }
2393
2394 void ib_reset_mad_timeout(struct ib_mad_send_wr_private *mad_send_wr,
2395 int timeout_ms)
2396 {
2397 mad_send_wr->timeout = msecs_to_jiffies(timeout_ms);
2398 wait_for_response(mad_send_wr);
2399 }
2400
2401 /*
2402 * Process a send work completion
2403 */
2404 void ib_mad_complete_send_wr(struct ib_mad_send_wr_private *mad_send_wr,
2405 struct ib_mad_send_wc *mad_send_wc)
2406 {
2407 struct ib_mad_agent_private *mad_agent_priv;
2408 unsigned long flags;
2409 int ret;
2410
2411 mad_agent_priv = mad_send_wr->mad_agent_priv;
2412 spin_lock_irqsave(&mad_agent_priv->lock, flags);
2413 if (ib_mad_kernel_rmpp_agent(&mad_agent_priv->agent)) {
2414 ret = ib_process_rmpp_send_wc(mad_send_wr, mad_send_wc);
2415 if (ret == IB_RMPP_RESULT_CONSUMED)
2416 goto done;
2417 } else
2418 ret = IB_RMPP_RESULT_UNHANDLED;
2419
2420 if (mad_send_wc->status != IB_WC_SUCCESS &&
2421 mad_send_wr->status == IB_WC_SUCCESS) {
2422 mad_send_wr->status = mad_send_wc->status;
2423 mad_send_wr->refcount -= (mad_send_wr->timeout > 0);
2424 }
2425
2426 if (--mad_send_wr->refcount > 0) {
2427 if (mad_send_wr->refcount == 1 && mad_send_wr->timeout &&
2428 mad_send_wr->status == IB_WC_SUCCESS) {
2429 wait_for_response(mad_send_wr);
2430 }
2431 goto done;
2432 }
2433
2434 /* Remove send from MAD agent and notify client of completion */
2435 list_del(&mad_send_wr->agent_list);
2436 adjust_timeout(mad_agent_priv);
2437 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2438
2439 if (mad_send_wr->status != IB_WC_SUCCESS )
2440 mad_send_wc->status = mad_send_wr->status;
2441 if (ret == IB_RMPP_RESULT_INTERNAL)
2442 ib_rmpp_send_handler(mad_send_wc);
2443 else
2444 mad_agent_priv->agent.send_handler(&mad_agent_priv->agent,
2445 mad_send_wc);
2446
2447 /* Release reference on agent taken when sending */
2448 deref_mad_agent(mad_agent_priv);
2449 return;
2450 done:
2451 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2452 }
2453
2454 static void ib_mad_send_done(struct ib_cq *cq, struct ib_wc *wc)
2455 {
2456 struct ib_mad_port_private *port_priv = cq->cq_context;
2457 struct ib_mad_list_head *mad_list =
2458 container_of(wc->wr_cqe, struct ib_mad_list_head, cqe);
2459 struct ib_mad_send_wr_private *mad_send_wr, *queued_send_wr;
2460 struct ib_mad_qp_info *qp_info;
2461 struct ib_mad_queue *send_queue;
2462 struct ib_send_wr *bad_send_wr;
2463 struct ib_mad_send_wc mad_send_wc;
2464 unsigned long flags;
2465 int ret;
2466
2467 if (list_empty_careful(&port_priv->port_list))
2468 return;
2469
2470 if (wc->status != IB_WC_SUCCESS) {
2471 if (!ib_mad_send_error(port_priv, wc))
2472 return;
2473 }
2474
2475 mad_send_wr = container_of(mad_list, struct ib_mad_send_wr_private,
2476 mad_list);
2477 send_queue = mad_list->mad_queue;
2478 qp_info = send_queue->qp_info;
2479
2480 retry:
2481 ib_dma_unmap_single(mad_send_wr->send_buf.mad_agent->device,
2482 mad_send_wr->header_mapping,
2483 mad_send_wr->sg_list[0].length, DMA_TO_DEVICE);
2484 ib_dma_unmap_single(mad_send_wr->send_buf.mad_agent->device,
2485 mad_send_wr->payload_mapping,
2486 mad_send_wr->sg_list[1].length, DMA_TO_DEVICE);
2487 queued_send_wr = NULL;
2488 spin_lock_irqsave(&send_queue->lock, flags);
2489 list_del(&mad_list->list);
2490
2491 /* Move queued send to the send queue */
2492 if (send_queue->count-- > send_queue->max_active) {
2493 mad_list = container_of(qp_info->overflow_list.next,
2494 struct ib_mad_list_head, list);
2495 queued_send_wr = container_of(mad_list,
2496 struct ib_mad_send_wr_private,
2497 mad_list);
2498 list_move_tail(&mad_list->list, &send_queue->list);
2499 }
2500 spin_unlock_irqrestore(&send_queue->lock, flags);
2501
2502 mad_send_wc.send_buf = &mad_send_wr->send_buf;
2503 mad_send_wc.status = wc->status;
2504 mad_send_wc.vendor_err = wc->vendor_err;
2505 if (atomic_read(&qp_info->snoop_count))
2506 snoop_send(qp_info, &mad_send_wr->send_buf, &mad_send_wc,
2507 IB_MAD_SNOOP_SEND_COMPLETIONS);
2508 ib_mad_complete_send_wr(mad_send_wr, &mad_send_wc);
2509
2510 if (queued_send_wr) {
2511 ret = ib_post_send(qp_info->qp, &queued_send_wr->send_wr.wr,
2512 &bad_send_wr);
2513 if (ret) {
2514 dev_err(&port_priv->device->dev,
2515 "ib_post_send failed: %d\n", ret);
2516 mad_send_wr = queued_send_wr;
2517 wc->status = IB_WC_LOC_QP_OP_ERR;
2518 goto retry;
2519 }
2520 }
2521 }
2522
2523 static void mark_sends_for_retry(struct ib_mad_qp_info *qp_info)
2524 {
2525 struct ib_mad_send_wr_private *mad_send_wr;
2526 struct ib_mad_list_head *mad_list;
2527 unsigned long flags;
2528
2529 spin_lock_irqsave(&qp_info->send_queue.lock, flags);
2530 list_for_each_entry(mad_list, &qp_info->send_queue.list, list) {
2531 mad_send_wr = container_of(mad_list,
2532 struct ib_mad_send_wr_private,
2533 mad_list);
2534 mad_send_wr->retry = 1;
2535 }
2536 spin_unlock_irqrestore(&qp_info->send_queue.lock, flags);
2537 }
2538
2539 static bool ib_mad_send_error(struct ib_mad_port_private *port_priv,
2540 struct ib_wc *wc)
2541 {
2542 struct ib_mad_list_head *mad_list =
2543 container_of(wc->wr_cqe, struct ib_mad_list_head, cqe);
2544 struct ib_mad_qp_info *qp_info = mad_list->mad_queue->qp_info;
2545 struct ib_mad_send_wr_private *mad_send_wr;
2546 int ret;
2547
2548 /*
2549 * Send errors will transition the QP to SQE - move
2550 * QP to RTS and repost flushed work requests
2551 */
2552 mad_send_wr = container_of(mad_list, struct ib_mad_send_wr_private,
2553 mad_list);
2554 if (wc->status == IB_WC_WR_FLUSH_ERR) {
2555 if (mad_send_wr->retry) {
2556 /* Repost send */
2557 struct ib_send_wr *bad_send_wr;
2558
2559 mad_send_wr->retry = 0;
2560 ret = ib_post_send(qp_info->qp, &mad_send_wr->send_wr.wr,
2561 &bad_send_wr);
2562 if (!ret)
2563 return false;
2564 }
2565 } else {
2566 struct ib_qp_attr *attr;
2567
2568 /* Transition QP to RTS and fail offending send */
2569 attr = kmalloc(sizeof *attr, GFP_KERNEL);
2570 if (attr) {
2571 attr->qp_state = IB_QPS_RTS;
2572 attr->cur_qp_state = IB_QPS_SQE;
2573 ret = ib_modify_qp(qp_info->qp, attr,
2574 IB_QP_STATE | IB_QP_CUR_STATE);
2575 kfree(attr);
2576 if (ret)
2577 dev_err(&port_priv->device->dev,
2578 "%s - ib_modify_qp to RTS: %d\n",
2579 __func__, ret);
2580 else
2581 mark_sends_for_retry(qp_info);
2582 }
2583 }
2584
2585 return true;
2586 }
2587
2588 static void cancel_mads(struct ib_mad_agent_private *mad_agent_priv)
2589 {
2590 unsigned long flags;
2591 struct ib_mad_send_wr_private *mad_send_wr, *temp_mad_send_wr;
2592 struct ib_mad_send_wc mad_send_wc;
2593 struct list_head cancel_list;
2594
2595 INIT_LIST_HEAD(&cancel_list);
2596
2597 spin_lock_irqsave(&mad_agent_priv->lock, flags);
2598 list_for_each_entry_safe(mad_send_wr, temp_mad_send_wr,
2599 &mad_agent_priv->send_list, agent_list) {
2600 if (mad_send_wr->status == IB_WC_SUCCESS) {
2601 mad_send_wr->status = IB_WC_WR_FLUSH_ERR;
2602 mad_send_wr->refcount -= (mad_send_wr->timeout > 0);
2603 }
2604 }
2605
2606 /* Empty wait list to prevent receives from finding a request */
2607 list_splice_init(&mad_agent_priv->wait_list, &cancel_list);
2608 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2609
2610 /* Report all cancelled requests */
2611 mad_send_wc.status = IB_WC_WR_FLUSH_ERR;
2612 mad_send_wc.vendor_err = 0;
2613
2614 list_for_each_entry_safe(mad_send_wr, temp_mad_send_wr,
2615 &cancel_list, agent_list) {
2616 mad_send_wc.send_buf = &mad_send_wr->send_buf;
2617 list_del(&mad_send_wr->agent_list);
2618 mad_agent_priv->agent.send_handler(&mad_agent_priv->agent,
2619 &mad_send_wc);
2620 atomic_dec(&mad_agent_priv->refcount);
2621 }
2622 }
2623
2624 static struct ib_mad_send_wr_private*
2625 find_send_wr(struct ib_mad_agent_private *mad_agent_priv,
2626 struct ib_mad_send_buf *send_buf)
2627 {
2628 struct ib_mad_send_wr_private *mad_send_wr;
2629
2630 list_for_each_entry(mad_send_wr, &mad_agent_priv->wait_list,
2631 agent_list) {
2632 if (&mad_send_wr->send_buf == send_buf)
2633 return mad_send_wr;
2634 }
2635
2636 list_for_each_entry(mad_send_wr, &mad_agent_priv->send_list,
2637 agent_list) {
2638 if (is_rmpp_data_mad(mad_agent_priv,
2639 mad_send_wr->send_buf.mad) &&
2640 &mad_send_wr->send_buf == send_buf)
2641 return mad_send_wr;
2642 }
2643 return NULL;
2644 }
2645
2646 int ib_modify_mad(struct ib_mad_agent *mad_agent,
2647 struct ib_mad_send_buf *send_buf, u32 timeout_ms)
2648 {
2649 struct ib_mad_agent_private *mad_agent_priv;
2650 struct ib_mad_send_wr_private *mad_send_wr;
2651 unsigned long flags;
2652 int active;
2653
2654 mad_agent_priv = container_of(mad_agent, struct ib_mad_agent_private,
2655 agent);
2656 spin_lock_irqsave(&mad_agent_priv->lock, flags);
2657 mad_send_wr = find_send_wr(mad_agent_priv, send_buf);
2658 if (!mad_send_wr || mad_send_wr->status != IB_WC_SUCCESS) {
2659 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2660 return -EINVAL;
2661 }
2662
2663 active = (!mad_send_wr->timeout || mad_send_wr->refcount > 1);
2664 if (!timeout_ms) {
2665 mad_send_wr->status = IB_WC_WR_FLUSH_ERR;
2666 mad_send_wr->refcount -= (mad_send_wr->timeout > 0);
2667 }
2668
2669 mad_send_wr->send_buf.timeout_ms = timeout_ms;
2670 if (active)
2671 mad_send_wr->timeout = msecs_to_jiffies(timeout_ms);
2672 else
2673 ib_reset_mad_timeout(mad_send_wr, timeout_ms);
2674
2675 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2676 return 0;
2677 }
2678 EXPORT_SYMBOL(ib_modify_mad);
2679
2680 void ib_cancel_mad(struct ib_mad_agent *mad_agent,
2681 struct ib_mad_send_buf *send_buf)
2682 {
2683 ib_modify_mad(mad_agent, send_buf, 0);
2684 }
2685 EXPORT_SYMBOL(ib_cancel_mad);
2686
2687 static void local_completions(struct work_struct *work)
2688 {
2689 struct ib_mad_agent_private *mad_agent_priv;
2690 struct ib_mad_local_private *local;
2691 struct ib_mad_agent_private *recv_mad_agent;
2692 unsigned long flags;
2693 int free_mad;
2694 struct ib_wc wc;
2695 struct ib_mad_send_wc mad_send_wc;
2696 bool opa;
2697
2698 mad_agent_priv =
2699 container_of(work, struct ib_mad_agent_private, local_work);
2700
2701 opa = rdma_cap_opa_mad(mad_agent_priv->qp_info->port_priv->device,
2702 mad_agent_priv->qp_info->port_priv->port_num);
2703
2704 spin_lock_irqsave(&mad_agent_priv->lock, flags);
2705 while (!list_empty(&mad_agent_priv->local_list)) {
2706 local = list_entry(mad_agent_priv->local_list.next,
2707 struct ib_mad_local_private,
2708 completion_list);
2709 list_del(&local->completion_list);
2710 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2711 free_mad = 0;
2712 if (local->mad_priv) {
2713 u8 base_version;
2714 recv_mad_agent = local->recv_mad_agent;
2715 if (!recv_mad_agent) {
2716 dev_err(&mad_agent_priv->agent.device->dev,
2717 "No receive MAD agent for local completion\n");
2718 free_mad = 1;
2719 goto local_send_completion;
2720 }
2721
2722 /*
2723 * Defined behavior is to complete response
2724 * before request
2725 */
2726 build_smp_wc(recv_mad_agent->agent.qp,
2727 local->mad_send_wr->send_wr.wr.wr_cqe,
2728 be16_to_cpu(IB_LID_PERMISSIVE),
2729 local->mad_send_wr->send_wr.pkey_index,
2730 recv_mad_agent->agent.port_num, &wc);
2731
2732 local->mad_priv->header.recv_wc.wc = &wc;
2733
2734 base_version = ((struct ib_mad_hdr *)(local->mad_priv->mad))->base_version;
2735 if (opa && base_version == OPA_MGMT_BASE_VERSION) {
2736 local->mad_priv->header.recv_wc.mad_len = local->return_wc_byte_len;
2737 local->mad_priv->header.recv_wc.mad_seg_size = sizeof(struct opa_mad);
2738 } else {
2739 local->mad_priv->header.recv_wc.mad_len = sizeof(struct ib_mad);
2740 local->mad_priv->header.recv_wc.mad_seg_size = sizeof(struct ib_mad);
2741 }
2742
2743 INIT_LIST_HEAD(&local->mad_priv->header.recv_wc.rmpp_list);
2744 list_add(&local->mad_priv->header.recv_wc.recv_buf.list,
2745 &local->mad_priv->header.recv_wc.rmpp_list);
2746 local->mad_priv->header.recv_wc.recv_buf.grh = NULL;
2747 local->mad_priv->header.recv_wc.recv_buf.mad =
2748 (struct ib_mad *)local->mad_priv->mad;
2749 if (atomic_read(&recv_mad_agent->qp_info->snoop_count))
2750 snoop_recv(recv_mad_agent->qp_info,
2751 &local->mad_priv->header.recv_wc,
2752 IB_MAD_SNOOP_RECVS);
2753 recv_mad_agent->agent.recv_handler(
2754 &recv_mad_agent->agent,
2755 &local->mad_send_wr->send_buf,
2756 &local->mad_priv->header.recv_wc);
2757 spin_lock_irqsave(&recv_mad_agent->lock, flags);
2758 atomic_dec(&recv_mad_agent->refcount);
2759 spin_unlock_irqrestore(&recv_mad_agent->lock, flags);
2760 }
2761
2762 local_send_completion:
2763 /* Complete send */
2764 mad_send_wc.status = IB_WC_SUCCESS;
2765 mad_send_wc.vendor_err = 0;
2766 mad_send_wc.send_buf = &local->mad_send_wr->send_buf;
2767 if (atomic_read(&mad_agent_priv->qp_info->snoop_count))
2768 snoop_send(mad_agent_priv->qp_info,
2769 &local->mad_send_wr->send_buf,
2770 &mad_send_wc, IB_MAD_SNOOP_SEND_COMPLETIONS);
2771 mad_agent_priv->agent.send_handler(&mad_agent_priv->agent,
2772 &mad_send_wc);
2773
2774 spin_lock_irqsave(&mad_agent_priv->lock, flags);
2775 atomic_dec(&mad_agent_priv->refcount);
2776 if (free_mad)
2777 kfree(local->mad_priv);
2778 kfree(local);
2779 }
2780 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2781 }
2782
2783 static int retry_send(struct ib_mad_send_wr_private *mad_send_wr)
2784 {
2785 int ret;
2786
2787 if (!mad_send_wr->retries_left)
2788 return -ETIMEDOUT;
2789
2790 mad_send_wr->retries_left--;
2791 mad_send_wr->send_buf.retries++;
2792
2793 mad_send_wr->timeout = msecs_to_jiffies(mad_send_wr->send_buf.timeout_ms);
2794
2795 if (ib_mad_kernel_rmpp_agent(&mad_send_wr->mad_agent_priv->agent)) {
2796 ret = ib_retry_rmpp(mad_send_wr);
2797 switch (ret) {
2798 case IB_RMPP_RESULT_UNHANDLED:
2799 ret = ib_send_mad(mad_send_wr);
2800 break;
2801 case IB_RMPP_RESULT_CONSUMED:
2802 ret = 0;
2803 break;
2804 default:
2805 ret = -ECOMM;
2806 break;
2807 }
2808 } else
2809 ret = ib_send_mad(mad_send_wr);
2810
2811 if (!ret) {
2812 mad_send_wr->refcount++;
2813 list_add_tail(&mad_send_wr->agent_list,
2814 &mad_send_wr->mad_agent_priv->send_list);
2815 }
2816 return ret;
2817 }
2818
2819 static void timeout_sends(struct work_struct *work)
2820 {
2821 struct ib_mad_agent_private *mad_agent_priv;
2822 struct ib_mad_send_wr_private *mad_send_wr;
2823 struct ib_mad_send_wc mad_send_wc;
2824 unsigned long flags, delay;
2825
2826 mad_agent_priv = container_of(work, struct ib_mad_agent_private,
2827 timed_work.work);
2828 mad_send_wc.vendor_err = 0;
2829
2830 spin_lock_irqsave(&mad_agent_priv->lock, flags);
2831 while (!list_empty(&mad_agent_priv->wait_list)) {
2832 mad_send_wr = list_entry(mad_agent_priv->wait_list.next,
2833 struct ib_mad_send_wr_private,
2834 agent_list);
2835
2836 if (time_after(mad_send_wr->timeout, jiffies)) {
2837 delay = mad_send_wr->timeout - jiffies;
2838 if ((long)delay <= 0)
2839 delay = 1;
2840 queue_delayed_work(mad_agent_priv->qp_info->
2841 port_priv->wq,
2842 &mad_agent_priv->timed_work, delay);
2843 break;
2844 }
2845
2846 list_del(&mad_send_wr->agent_list);
2847 if (mad_send_wr->status == IB_WC_SUCCESS &&
2848 !retry_send(mad_send_wr))
2849 continue;
2850
2851 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2852
2853 if (mad_send_wr->status == IB_WC_SUCCESS)
2854 mad_send_wc.status = IB_WC_RESP_TIMEOUT_ERR;
2855 else
2856 mad_send_wc.status = mad_send_wr->status;
2857 mad_send_wc.send_buf = &mad_send_wr->send_buf;
2858 mad_agent_priv->agent.send_handler(&mad_agent_priv->agent,
2859 &mad_send_wc);
2860
2861 atomic_dec(&mad_agent_priv->refcount);
2862 spin_lock_irqsave(&mad_agent_priv->lock, flags);
2863 }
2864 spin_unlock_irqrestore(&mad_agent_priv->lock, flags);
2865 }
2866
2867 /*
2868 * Allocate receive MADs and post receive WRs for them
2869 */
2870 static int ib_mad_post_receive_mads(struct ib_mad_qp_info *qp_info,
2871 struct ib_mad_private *mad)
2872 {
2873 unsigned long flags;
2874 int post, ret;
2875 struct ib_mad_private *mad_priv;
2876 struct ib_sge sg_list;
2877 struct ib_recv_wr recv_wr, *bad_recv_wr;
2878 struct ib_mad_queue *recv_queue = &qp_info->recv_queue;
2879
2880 /* Initialize common scatter list fields */
2881 sg_list.lkey = qp_info->port_priv->pd->local_dma_lkey;
2882
2883 /* Initialize common receive WR fields */
2884 recv_wr.next = NULL;
2885 recv_wr.sg_list = &sg_list;
2886 recv_wr.num_sge = 1;
2887
2888 do {
2889 /* Allocate and map receive buffer */
2890 if (mad) {
2891 mad_priv = mad;
2892 mad = NULL;
2893 } else {
2894 mad_priv = alloc_mad_private(port_mad_size(qp_info->port_priv),
2895 GFP_ATOMIC);
2896 if (!mad_priv) {
2897 ret = -ENOMEM;
2898 break;
2899 }
2900 }
2901 sg_list.length = mad_priv_dma_size(mad_priv);
2902 sg_list.addr = ib_dma_map_single(qp_info->port_priv->device,
2903 &mad_priv->grh,
2904 mad_priv_dma_size(mad_priv),
2905 DMA_FROM_DEVICE);
2906 if (unlikely(ib_dma_mapping_error(qp_info->port_priv->device,
2907 sg_list.addr))) {
2908 ret = -ENOMEM;
2909 break;
2910 }
2911 mad_priv->header.mapping = sg_list.addr;
2912 mad_priv->header.mad_list.mad_queue = recv_queue;
2913 mad_priv->header.mad_list.cqe.done = ib_mad_recv_done;
2914 recv_wr.wr_cqe = &mad_priv->header.mad_list.cqe;
2915
2916 /* Post receive WR */
2917 spin_lock_irqsave(&recv_queue->lock, flags);
2918 post = (++recv_queue->count < recv_queue->max_active);
2919 list_add_tail(&mad_priv->header.mad_list.list, &recv_queue->list);
2920 spin_unlock_irqrestore(&recv_queue->lock, flags);
2921 ret = ib_post_recv(qp_info->qp, &recv_wr, &bad_recv_wr);
2922 if (ret) {
2923 spin_lock_irqsave(&recv_queue->lock, flags);
2924 list_del(&mad_priv->header.mad_list.list);
2925 recv_queue->count--;
2926 spin_unlock_irqrestore(&recv_queue->lock, flags);
2927 ib_dma_unmap_single(qp_info->port_priv->device,
2928 mad_priv->header.mapping,
2929 mad_priv_dma_size(mad_priv),
2930 DMA_FROM_DEVICE);
2931 kfree(mad_priv);
2932 dev_err(&qp_info->port_priv->device->dev,
2933 "ib_post_recv failed: %d\n", ret);
2934 break;
2935 }
2936 } while (post);
2937
2938 return ret;
2939 }
2940
2941 /*
2942 * Return all the posted receive MADs
2943 */
2944 static void cleanup_recv_queue(struct ib_mad_qp_info *qp_info)
2945 {
2946 struct ib_mad_private_header *mad_priv_hdr;
2947 struct ib_mad_private *recv;
2948 struct ib_mad_list_head *mad_list;
2949
2950 if (!qp_info->qp)
2951 return;
2952
2953 while (!list_empty(&qp_info->recv_queue.list)) {
2954
2955 mad_list = list_entry(qp_info->recv_queue.list.next,
2956 struct ib_mad_list_head, list);
2957 mad_priv_hdr = container_of(mad_list,
2958 struct ib_mad_private_header,
2959 mad_list);
2960 recv = container_of(mad_priv_hdr, struct ib_mad_private,
2961 header);
2962
2963 /* Remove from posted receive MAD list */
2964 list_del(&mad_list->list);
2965
2966 ib_dma_unmap_single(qp_info->port_priv->device,
2967 recv->header.mapping,
2968 mad_priv_dma_size(recv),
2969 DMA_FROM_DEVICE);
2970 kfree(recv);
2971 }
2972
2973 qp_info->recv_queue.count = 0;
2974 }
2975
2976 /*
2977 * Start the port
2978 */
2979 static int ib_mad_port_start(struct ib_mad_port_private *port_priv)
2980 {
2981 int ret, i;
2982 struct ib_qp_attr *attr;
2983 struct ib_qp *qp;
2984 u16 pkey_index;
2985
2986 attr = kmalloc(sizeof *attr, GFP_KERNEL);
2987 if (!attr)
2988 return -ENOMEM;
2989
2990 ret = ib_find_pkey(port_priv->device, port_priv->port_num,
2991 IB_DEFAULT_PKEY_FULL, &pkey_index);
2992 if (ret)
2993 pkey_index = 0;
2994
2995 for (i = 0; i < IB_MAD_QPS_CORE; i++) {
2996 qp = port_priv->qp_info[i].qp;
2997 if (!qp)
2998 continue;
2999
3000 /*
3001 * PKey index for QP1 is irrelevant but
3002 * one is needed for the Reset to Init transition
3003 */
3004 attr->qp_state = IB_QPS_INIT;
3005 attr->pkey_index = pkey_index;
3006 attr->qkey = (qp->qp_num == 0) ? 0 : IB_QP1_QKEY;
3007 ret = ib_modify_qp(qp, attr, IB_QP_STATE |
3008 IB_QP_PKEY_INDEX | IB_QP_QKEY);
3009 if (ret) {
3010 dev_err(&port_priv->device->dev,
3011 "Couldn't change QP%d state to INIT: %d\n",
3012 i, ret);
3013 goto out;
3014 }
3015
3016 attr->qp_state = IB_QPS_RTR;
3017 ret = ib_modify_qp(qp, attr, IB_QP_STATE);
3018 if (ret) {
3019 dev_err(&port_priv->device->dev,
3020 "Couldn't change QP%d state to RTR: %d\n",
3021 i, ret);
3022 goto out;
3023 }
3024
3025 attr->qp_state = IB_QPS_RTS;
3026 attr->sq_psn = IB_MAD_SEND_Q_PSN;
3027 ret = ib_modify_qp(qp, attr, IB_QP_STATE | IB_QP_SQ_PSN);
3028 if (ret) {
3029 dev_err(&port_priv->device->dev,
3030 "Couldn't change QP%d state to RTS: %d\n",
3031 i, ret);
3032 goto out;
3033 }
3034 }
3035
3036 ret = ib_req_notify_cq(port_priv->cq, IB_CQ_NEXT_COMP);
3037 if (ret) {
3038 dev_err(&port_priv->device->dev,
3039 "Failed to request completion notification: %d\n",
3040 ret);
3041 goto out;
3042 }
3043
3044 for (i = 0; i < IB_MAD_QPS_CORE; i++) {
3045 if (!port_priv->qp_info[i].qp)
3046 continue;
3047
3048 ret = ib_mad_post_receive_mads(&port_priv->qp_info[i], NULL);
3049 if (ret) {
3050 dev_err(&port_priv->device->dev,
3051 "Couldn't post receive WRs\n");
3052 goto out;
3053 }
3054 }
3055 out:
3056 kfree(attr);
3057 return ret;
3058 }
3059
3060 static void qp_event_handler(struct ib_event *event, void *qp_context)
3061 {
3062 struct ib_mad_qp_info *qp_info = qp_context;
3063
3064 /* It's worse than that! He's dead, Jim! */
3065 dev_err(&qp_info->port_priv->device->dev,
3066 "Fatal error (%d) on MAD QP (%d)\n",
3067 event->event, qp_info->qp->qp_num);
3068 }
3069
3070 static void init_mad_queue(struct ib_mad_qp_info *qp_info,
3071 struct ib_mad_queue *mad_queue)
3072 {
3073 mad_queue->qp_info = qp_info;
3074 mad_queue->count = 0;
3075 spin_lock_init(&mad_queue->lock);
3076 INIT_LIST_HEAD(&mad_queue->list);
3077 }
3078
3079 static void init_mad_qp(struct ib_mad_port_private *port_priv,
3080 struct ib_mad_qp_info *qp_info)
3081 {
3082 qp_info->port_priv = port_priv;
3083 init_mad_queue(qp_info, &qp_info->send_queue);
3084 init_mad_queue(qp_info, &qp_info->recv_queue);
3085 INIT_LIST_HEAD(&qp_info->overflow_list);
3086 spin_lock_init(&qp_info->snoop_lock);
3087 qp_info->snoop_table = NULL;
3088 qp_info->snoop_table_size = 0;
3089 atomic_set(&qp_info->snoop_count, 0);
3090 }
3091
3092 static int create_mad_qp(struct ib_mad_qp_info *qp_info,
3093 enum ib_qp_type qp_type)
3094 {
3095 struct ib_qp_init_attr qp_init_attr;
3096 int ret;
3097
3098 memset(&qp_init_attr, 0, sizeof qp_init_attr);
3099 qp_init_attr.send_cq = qp_info->port_priv->cq;
3100 qp_init_attr.recv_cq = qp_info->port_priv->cq;
3101 qp_init_attr.sq_sig_type = IB_SIGNAL_ALL_WR;
3102 qp_init_attr.cap.max_send_wr = mad_sendq_size;
3103 qp_init_attr.cap.max_recv_wr = mad_recvq_size;
3104 qp_init_attr.cap.max_send_sge = IB_MAD_SEND_REQ_MAX_SG;
3105 qp_init_attr.cap.max_recv_sge = IB_MAD_RECV_REQ_MAX_SG;
3106 qp_init_attr.qp_type = qp_type;
3107 qp_init_attr.port_num = qp_info->port_priv->port_num;
3108 qp_init_attr.qp_context = qp_info;
3109 qp_init_attr.event_handler = qp_event_handler;
3110 qp_info->qp = ib_create_qp(qp_info->port_priv->pd, &qp_init_attr);
3111 if (IS_ERR(qp_info->qp)) {
3112 dev_err(&qp_info->port_priv->device->dev,
3113 "Couldn't create ib_mad QP%d\n",
3114 get_spl_qp_index(qp_type));
3115 ret = PTR_ERR(qp_info->qp);
3116 goto error;
3117 }
3118 /* Use minimum queue sizes unless the CQ is resized */
3119 qp_info->send_queue.max_active = mad_sendq_size;
3120 qp_info->recv_queue.max_active = mad_recvq_size;
3121 return 0;
3122
3123 error:
3124 return ret;
3125 }
3126
3127 static void destroy_mad_qp(struct ib_mad_qp_info *qp_info)
3128 {
3129 if (!qp_info->qp)
3130 return;
3131
3132 ib_destroy_qp(qp_info->qp);
3133 kfree(qp_info->snoop_table);
3134 }
3135
3136 /*
3137 * Open the port
3138 * Create the QP, PD, MR, and CQ if needed
3139 */
3140 static int ib_mad_port_open(struct ib_device *device,
3141 int port_num)
3142 {
3143 int ret, cq_size;
3144 struct ib_mad_port_private *port_priv;
3145 unsigned long flags;
3146 char name[sizeof "ib_mad123"];
3147 int has_smi;
3148
3149 if (WARN_ON(rdma_max_mad_size(device, port_num) < IB_MGMT_MAD_SIZE))
3150 return -EFAULT;
3151
3152 if (WARN_ON(rdma_cap_opa_mad(device, port_num) &&
3153 rdma_max_mad_size(device, port_num) < OPA_MGMT_MAD_SIZE))
3154 return -EFAULT;
3155
3156 /* Create new device info */
3157 port_priv = kzalloc(sizeof *port_priv, GFP_KERNEL);
3158 if (!port_priv)
3159 return -ENOMEM;
3160
3161 port_priv->device = device;
3162 port_priv->port_num = port_num;
3163 spin_lock_init(&port_priv->reg_lock);
3164 INIT_LIST_HEAD(&port_priv->agent_list);
3165 init_mad_qp(port_priv, &port_priv->qp_info[0]);
3166 init_mad_qp(port_priv, &port_priv->qp_info[1]);
3167
3168 cq_size = mad_sendq_size + mad_recvq_size;
3169 has_smi = rdma_cap_ib_smi(device, port_num);
3170 if (has_smi)
3171 cq_size *= 2;
3172
3173 port_priv->cq = ib_alloc_cq(port_priv->device, port_priv, cq_size, 0,
3174 IB_POLL_WORKQUEUE);
3175 if (IS_ERR(port_priv->cq)) {
3176 dev_err(&device->dev, "Couldn't create ib_mad CQ\n");
3177 ret = PTR_ERR(port_priv->cq);
3178 goto error3;
3179 }
3180
3181 port_priv->pd = ib_alloc_pd(device, 0);
3182 if (IS_ERR(port_priv->pd)) {
3183 dev_err(&device->dev, "Couldn't create ib_mad PD\n");
3184 ret = PTR_ERR(port_priv->pd);
3185 goto error4;
3186 }
3187
3188 if (has_smi) {
3189 ret = create_mad_qp(&port_priv->qp_info[0], IB_QPT_SMI);
3190 if (ret)
3191 goto error6;
3192 }
3193 ret = create_mad_qp(&port_priv->qp_info[1], IB_QPT_GSI);
3194 if (ret)
3195 goto error7;
3196
3197 snprintf(name, sizeof name, "ib_mad%d", port_num);
3198 port_priv->wq = alloc_ordered_workqueue(name, WQ_MEM_RECLAIM);
3199 if (!port_priv->wq) {
3200 ret = -ENOMEM;
3201 goto error8;
3202 }
3203
3204 spin_lock_irqsave(&ib_mad_port_list_lock, flags);
3205 list_add_tail(&port_priv->port_list, &ib_mad_port_list);
3206 spin_unlock_irqrestore(&ib_mad_port_list_lock, flags);
3207
3208 ret = ib_mad_port_start(port_priv);
3209 if (ret) {
3210 dev_err(&device->dev, "Couldn't start port\n");
3211 goto error9;
3212 }
3213
3214 return 0;
3215
3216 error9:
3217 spin_lock_irqsave(&ib_mad_port_list_lock, flags);
3218 list_del_init(&port_priv->port_list);
3219 spin_unlock_irqrestore(&ib_mad_port_list_lock, flags);
3220
3221 destroy_workqueue(port_priv->wq);
3222 error8:
3223 destroy_mad_qp(&port_priv->qp_info[1]);
3224 error7:
3225 destroy_mad_qp(&port_priv->qp_info[0]);
3226 error6:
3227 ib_dealloc_pd(port_priv->pd);
3228 error4:
3229 ib_free_cq(port_priv->cq);
3230 cleanup_recv_queue(&port_priv->qp_info[1]);
3231 cleanup_recv_queue(&port_priv->qp_info[0]);
3232 error3:
3233 kfree(port_priv);
3234
3235 return ret;
3236 }
3237
3238 /*
3239 * Close the port
3240 * If there are no classes using the port, free the port
3241 * resources (CQ, MR, PD, QP) and remove the port's info structure
3242 */
3243 static int ib_mad_port_close(struct ib_device *device, int port_num)
3244 {
3245 struct ib_mad_port_private *port_priv;
3246 unsigned long flags;
3247
3248 spin_lock_irqsave(&ib_mad_port_list_lock, flags);
3249 port_priv = __ib_get_mad_port(device, port_num);
3250 if (port_priv == NULL) {
3251 spin_unlock_irqrestore(&ib_mad_port_list_lock, flags);
3252 dev_err(&device->dev, "Port %d not found\n", port_num);
3253 return -ENODEV;
3254 }
3255 list_del_init(&port_priv->port_list);
3256 spin_unlock_irqrestore(&ib_mad_port_list_lock, flags);
3257
3258 destroy_workqueue(port_priv->wq);
3259 destroy_mad_qp(&port_priv->qp_info[1]);
3260 destroy_mad_qp(&port_priv->qp_info[0]);
3261 ib_dealloc_pd(port_priv->pd);
3262 ib_free_cq(port_priv->cq);
3263 cleanup_recv_queue(&port_priv->qp_info[1]);
3264 cleanup_recv_queue(&port_priv->qp_info[0]);
3265 /* XXX: Handle deallocation of MAD registration tables */
3266
3267 kfree(port_priv);
3268
3269 return 0;
3270 }
3271
3272 static void ib_mad_init_device(struct ib_device *device)
3273 {
3274 int start, i;
3275
3276 start = rdma_start_port(device);
3277
3278 for (i = start; i <= rdma_end_port(device); i++) {
3279 if (!rdma_cap_ib_mad(device, i))
3280 continue;
3281
3282 if (ib_mad_port_open(device, i)) {
3283 dev_err(&device->dev, "Couldn't open port %d\n", i);
3284 goto error;
3285 }
3286 if (ib_agent_port_open(device, i)) {
3287 dev_err(&device->dev,
3288 "Couldn't open port %d for agents\n", i);
3289 goto error_agent;
3290 }
3291 }
3292 return;
3293
3294 error_agent:
3295 if (ib_mad_port_close(device, i))
3296 dev_err(&device->dev, "Couldn't close port %d\n", i);
3297
3298 error:
3299 while (--i >= start) {
3300 if (!rdma_cap_ib_mad(device, i))
3301 continue;
3302
3303 if (ib_agent_port_close(device, i))
3304 dev_err(&device->dev,
3305 "Couldn't close port %d for agents\n", i);
3306 if (ib_mad_port_close(device, i))
3307 dev_err(&device->dev, "Couldn't close port %d\n", i);
3308 }
3309 }
3310
3311 static void ib_mad_remove_device(struct ib_device *device, void *client_data)
3312 {
3313 int i;
3314
3315 for (i = rdma_start_port(device); i <= rdma_end_port(device); i++) {
3316 if (!rdma_cap_ib_mad(device, i))
3317 continue;
3318
3319 if (ib_agent_port_close(device, i))
3320 dev_err(&device->dev,
3321 "Couldn't close port %d for agents\n", i);
3322 if (ib_mad_port_close(device, i))
3323 dev_err(&device->dev, "Couldn't close port %d\n", i);
3324 }
3325 }
3326
3327 static struct ib_client mad_client = {
3328 .name = "mad",
3329 .add = ib_mad_init_device,
3330 .remove = ib_mad_remove_device
3331 };
3332
3333 int ib_mad_init(void)
3334 {
3335 mad_recvq_size = min(mad_recvq_size, IB_MAD_QP_MAX_SIZE);
3336 mad_recvq_size = max(mad_recvq_size, IB_MAD_QP_MIN_SIZE);
3337
3338 mad_sendq_size = min(mad_sendq_size, IB_MAD_QP_MAX_SIZE);
3339 mad_sendq_size = max(mad_sendq_size, IB_MAD_QP_MIN_SIZE);
3340
3341 INIT_LIST_HEAD(&ib_mad_port_list);
3342
3343 if (ib_register_client(&mad_client)) {
3344 pr_err("Couldn't register ib_mad client\n");
3345 return -EINVAL;
3346 }
3347
3348 return 0;
3349 }
3350
3351 void ib_mad_cleanup(void)
3352 {
3353 ib_unregister_client(&mad_client);
3354 }